{"ERROR":false,"response":[{"nid":806,"title":"Action Required to Secure the Cisco IOS and IOS XE Smart Install Feature","uuid":"0cb3bfbc-ec9a-46d5-a474-2e5f1f11a732","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:55Z","date_created":"2018-06-08T17:55:40Z","summary":null,"body":["<article data-history-node-id=\"806\" about=\"\/en\/alerts-advisories\/action-required-secure-cisco-ios-and-ios-xe-smart-install-feature\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: IN18-001<br \/>\nDate: 14 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this Information Note is to bring attention to an Advisory released by Cisco regarding the Cisco IOS and IOS XE Smart Install feature.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has released an Advisory that provides consolidated information on the Cisco Smart Install feature, how to properly secure devices that may be exposed as well as mitigates the disclosed vulnerabilities.<\/p>\n\n<p>The following table lists published Cisco Advisories that identify the Smart Install feature as being vulnerable and whether each vulnerability is being actively exploited:<\/p>\n\n<table class=\"table table-bordered\"><caption class=\"wb-inv\">Table<\/caption>\n\t<tbody><tr><th><em>Advisory Name<\/em><\/th>\n\t\t\t<th><em>CVE ID<\/em><\/th>\n\t\t\t<th><em>Description<\/em><\/th>\n\t\t\t<th><em>Client\/Director<\/em><\/th>\n\t\t\t<th><em>Publication Date<\/em><\/th>\n\t\t\t<th><em>Actively Exploited?<\/em><\/th>\n\t\t<\/tr><tr><td>Cisco Smart Install Protocol Misuse<\/td>\n\t\t\t<td>N\/A<\/td>\n\t\t\t<td>Widespread scanning for devices with the Smart Install feature enabled and without proper security controls<\/td>\n\t\t\t<td>N\/A<\/td>\n\t\t\t<td>14-Feb-17<\/td>\n\t\t\t<td>Yes<\/td>\n\t\t<\/tr><tr><td>Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability<\/td>\n\t\t\t<td>CVE-2018-0171<\/td>\n\t\t\t<td>Reload, denial of service, remote code execution<\/td>\n\t\t\t<td>Client Only<\/td>\n\t\t\t<td>28-Mar-18<\/td>\n\t\t\t<td>No<\/td>\n\t\t<\/tr><tr><td>Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability<\/td>\n\t\t\t<td>CVE-2018-0156<\/td>\n\t\t\t<td>Reload, denial of service<\/td>\n\t\t\t<td>Client Only<\/td>\n\t\t\t<td>28-Mar-18<\/td>\n\t\t\t<td>No<\/td>\n\t\t<\/tr><tr><td>Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability<\/td>\n\t\t\t<td>CVE-2016-6385<\/td>\n\t\t\t<td>Memory leak, eventual denial of service<\/td>\n\t\t\t<td>Client Only<\/td>\n\t\t\t<td>28-Sep-16<\/td>\n\t\t\t<td>No<\/td>\n\t\t<\/tr><tr><td>Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability<\/td>\n\t\t\t<td>CVE-2016-1349<\/td>\n\t\t\t<td>Denial of service<\/td>\n\t\t\t<td>Client Only<\/td>\n\t\t\t<td>23-Mar-16<\/td>\n\t\t\t<td>No<\/td>\n\t\t<\/tr><tr><td>Cisco IOS Software Smart Install Denial of Service Vulnerability<\/td>\n\t\t\t<td>CVE-2013-1146<\/td>\n\t\t\t<td>Denial of service<\/td>\n\t\t\t<td>Client Only<\/td>\n\t\t\t<td>11-Apr-13<\/td>\n\t\t\t<td>No<\/td>\n\t\t<\/tr><tr><td>Cisco IOS Software Smart Install Denial of Service Vulnerability<\/td>\n\t\t\t<td>CVE-2012-0385<\/td>\n\t\t\t<td>Malformed SMI packet causes reload<\/td>\n\t\t\t<td>Client &amp; Director<\/td>\n\t\t\t<td>28-Mar-12<\/td>\n\t\t\t<td>No<\/td>\n\t\t<\/tr><tr><td>Cisco IOS Software Smart Install Remote Code Execution Vulnerability<\/td>\n\t\t\t<td>CVE-2011-3271<\/td>\n\t\t\t<td>Remote code execution<\/td>\n\t\t\t<td>Client &amp; Director<\/td>\n\t\t\t<td>28-Sep-11<\/td>\n\t\t\t<td>No<\/td>\n\t\t<\/tr><\/tbody><\/table><h2>Suggested Action<\/h2>\n\n<p>CCIRC encourages organizations to review the CISCO Advisory and system administrators test and deploy the vendor-released updates to affected applications accordingly. Cisco recommends that customers who are not actively using Smart Install disable the feature. For those who do use the feature \u2013 and need to leave it enabled \u2013 use ACLs to block incoming traffic on TCP port 4786 (the proper security control). Additionally, patches for known security vulnerabilities should be applied as part of standard network security management.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Action Required to Secure the Cisco IOS and IOS XE Smart Install Feature<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180409-smi\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180409-smi<\/a><\/p>\n\n<p>Cisco Security Updates<\/p>\n\n<p><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2018\/av18-052-en.aspx\">https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2018\/av18-052-en.aspx<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/action-required-secure-cisco-ios-and-ios-xe-smart-install-feature","alert_type":null,"serial_number":"IN18-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":890,"title":"Active Exploitation of a Vulnerability in Microsoft Silverlight","uuid":"bc7b4741-d0da-428a-9ac2-dbc5df132614","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-15T18:03:19Z","summary":null,"body":["<article data-history-node-id=\"890\" about=\"\/en\/alerts-advisories\/active-exploitation-vulnerability-microsoft-silverlight\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-001<br \/>\nDate: 13 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in Microsoft Silverlight that is under active exploitation.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of attacks exploiting a recently patched critical vulnerability in Microsoft Silverlight. Identified as CVE-2016-0034, this vulnerability can allow for remote code execution if a user visits a webpage containing a specially crafted Silverlight application.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the elevated risk presented by this vulnerability, CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. CCIRC recommends that priority is given to this patch.<\/p>\n\n<h2>References<\/h2>\n\n<p>CCIRC Advisory AV15-006: Microsoft Critical Security Bulletins Summary for January Microsoft Critical Security Bulletins Summary for January 2016<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/av16-005-en.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/av16-005-en.aspx<\/font><\/a><\/p>\n\n<p>Microsoft Security Bulletin MS16-006 - Security Update for Silverlight to Address Remote Code Execution (3126036):<br \/><a href=\"https:\/\/technet.microsoft.com\/library\/security\/MS16-006\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/library\/security\/MS16-006<\/font><\/a><\/p>\n\n<p>SecureList: The Mysterious Case of CVE-2016-0034: the hunt for a Microsoft Silverlight 0-day<br \/><a href=\"https:\/\/securelist.com\/blog\/research\/73255\/the-mysterious-case-of-cve-2016-0034-the-hunt-for-a-microsoft-silverlight-0-day\/\"><font color=\"#0066cc\">https:\/\/securelist.com\/blog\/research\/73255\/the-mysterious-case-of-cve-2016-0034-the-hunt-for-a-microsoft-silverlight-0-day\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vulnerability-microsoft-silverlight","alert_type":397,"serial_number":"AL16-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1071,"title":"Linux Kernel Vulnerability","uuid":"94af7047-01dc-4fbc-9099-30cb3327d408","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-15T18:19:44Z","summary":null,"body":["<article data-history-node-id=\"1071\" about=\"\/en\/alerts-advisories\/linux-kernel-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-002<br \/>\nDate: 19 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in the Linux kernel.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in the Linux kernel. Identified as CVE-2016-0728, this vulnerability can allow privilege escalation in the Linux kernel environment.<\/p>\n\n<p>CVE Reference: CVE-2016-0728<br \/>\nAffected Kernel Version: 3.8 and higher<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators watch for vendor-released updates of affected Linux kernel versions.<\/p>\n\n<h2>References<\/h2>\n\n<p>Proof of Concept:<br \/><a href=\"http:\/\/perception-point.io\/2016\/01\/14\/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728\/\"><font color=\"#0066cc\">http:\/\/perception-point.io\/2016\/01\/14\/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728\/<\/font><\/a><\/p>\n\n<p>CVE:<br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-0728\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-0728<\/font><\/a><\/p>\n\n<p>Red Hat Bug Report:<br \/><a href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1297475\"><font color=\"#0066cc\">https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1297475<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-kernel-vulnerability","alert_type":396,"serial_number":"AV16-002","subject":"other","moderation_state":"archived","external_url":null},{"nid":1032,"title":"Cisco Default Credentials Vulnerability and Remote Code Execution Vulnerability","uuid":"b36691ea-8ad6-4827-ab87-b406cfff95cc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-06-15T19:22:33Z","summary":null,"body":["<article data-history-node-id=\"1032\" about=\"\/en\/alerts-advisories\/cisco-default-credentials-vulnerability-and-remote-code-execution-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-003<br \/>\nDate: 20 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to critical software updates recently made available that address disclosed vulnerabilities in two Cisco products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of recently disclosed vulnerabilities in following two Cisco products.<\/p>\n\n<p>CVE-2015-6412: Cisco Modular Encoding Platform D9036 Software Default Credentials Vulnerability<br \/>\nA vulnerability in Cisco Modular Encoding Platform D9036 Software could allow an unauthenticated, remote attacker to log in to the system shell with the privileges of the root user.<\/p>\n\n<p>CVE-2015-6435: Cisco Unified Computing System Manager and Cisco Firepower 9000 Remote Command Execution Vulnerability<\/p>\n\n<p>A vulnerability in a CGI script in the Cisco UCS Manager and the Cisco Firepower 9000 Series appliance could allow an unauthenticated, remote attacker to execute arbitrary commands on the Cisco Unified Computing System (UCS) Manager or the Cisco Firepower 9000 Series appliance.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the elevated risk presented by these vulnerabilities, CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. CCIRC recommends that priority is given to these patches.<\/p>\n\n<h2>References<\/h2>\n\n<p>Cisco Modular Encoding Platform D9036 Software Default Credentials Vulnerability<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160120-d9036\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160120-d9036<\/font><\/a><\/p>\n\n<p>Cisco Unified Computing System Manager and Cisco Firepower 9000 Remote Command Execution Vulnerability<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160120-ucsm\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160120-ucsm<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-default-credentials-vulnerability-and-remote-code-execution-vulnerability","alert_type":397,"serial_number":"AL16-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":1156,"title":"Scammers Impersonate Internet Service Providers (ISP) in Fraudulent Technical Support Campaign","uuid":"744a0250-3761-43f4-a3d8-9aff0025d024","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-18T15:03:13Z","summary":null,"body":["<article data-history-node-id=\"1156\" about=\"\/en\/alerts-advisories\/scammers-impersonate-internet-service-providers-isp-fraudulent-technical-support-campaign\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-004<br \/>\nDate: 24 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this Alert is to bring attention to a fraudulent technical support campaign impersonating ISPs.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Through open source reporting, CCIRC is aware of a technical support scam that impersonates ISPs in order to convince users to give the scammers remote access to their machines and remove allegedly malicious files for a fee.\u00a0 The scammers identify the target\u2019s ISP through their client IP address, and then display a legitimate looking technical support page, mimicking that of the legitimate ISP, that urges the intended victim to call for immediate assistance. Once the victim contacts the number provided, the fraudulent technician takes remote control of the machine to convince the victim that they are infected with several malicious files, and that they should make a payment to the technician to remove the allegedly malicious files. The fraudulent technician will perform simple file searches on the system in an attempt to add credibility to their activities. The scammers rely on the fact that some people may not be able to distinguish between malicious and non-malicious files. The scammers also use custom audio messages impersonating the individual victim\u2019s ISPs, giving more credibility to the scam.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Anyone experiencing this type of behaviour should not establish contact with the number provided.<\/p>\n\n<ul><li>Report the fraudulent call to the Canadian Anti-Fraud Centre at the following link <a href=\"http:\/\/www.antifraudcentre-centreantifraude.ca\/reportincident-signalerincident\/index-eng.htm\"><font color=\"#0066cc\">http:\/\/www.antifraudcentre-centreantifraude.ca\/reportincident-signalerincident\/index-eng.htm<\/font><\/a>.<\/li>\n\t<li>If the consumer has allowed remote access to their computer, then the system is likely compromised or open to further remote abuse. Affected consumers should consider reinstalling their operating system using the computers built-in back-up feature. Alternatively, take the system to a reputable computer support service to have the system reinstated to assure complete protection of their system and information.<\/li>\n<\/ul><p>References:<\/p>\n\n<p>More information on this scam can be found at the following link:<\/p>\n\n<p>Scammers Impersonate ISPs in New Tech Support Campaign<br \/><a href=\"https:\/\/blog.malwarebytes.org\/fraud-scam\/2016\/03\/scammers-impersonate-isps-in-new-tech-support-campaign\/\"><font color=\"#0066cc\">https:\/\/blog.malwarebytes.org\/fraud-scam\/2016\/03\/scammers-impersonate-isps-in-new-tech-support-campaign\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/scammers-impersonate-internet-service-providers-isp-fraudulent-technical-support-campaign","alert_type":397,"serial_number":"AL16-004","subject":null,"moderation_state":"archived","external_url":null},{"nid":1200,"title":"Recent Ransomware Variant - Locky","uuid":"fd956c04-8574-417f-8747-fb6a90a950ec","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-18T17:05:39Z","summary":null,"body":["<article data-history-node-id=\"1200\" about=\"\/en\/alerts-advisories\/recent-ransomware-variant-locky\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-005<br \/>\nDate: 1 April 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The Canadian Cyber Incident Response Centre (CCIRC), in collaboration with the United States Department of Homeland Security (DHS) Computer Emergency Readiness Team (US-CERT) is releasing this Alert to provide further information on a recent ransomware variant named Locky. Since early 2016, Locky has been observed infecting computers belonging to individuals and businesses, including healthcare facilities and hospitals worldwide.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a destructive ransomware variant named Locky which has been observed since early 2016. This form of destructive ransomware attempts to extort money from victims by displaying an on-screen alert. Typically, these alerts state that the user's computer has been locked or that all of the user's files have been encrypted. Users are then told that unless a ransom is paid, access will not be restored.<\/p>\n\n<p>Locky ransomware propagates through spam emails that include malicious Microsoft Office documents or compressed archive attachments, such as .zip and .rar.\u00a0 The malicious attachments contain macros or JavaScript files to download Ransomware-Locky files. Locky has affected computers belonging to individuals and businesses, including healthcare facilities and hospitals in the United States, New Zealand, Germany, and Canada. Other destructive ransomware variants have also emerged in 2016, such as Samas, which is used to compromise the networks of healthcare facilities. See the reference section below for more information.<\/p>\n\n<p>Ransomware is typically spread either through phishing emails that contain malicious attachments or through drive-by downloading. Drive-by downloading occurs when a user unknowingly visits an infected website. Malware is downloaded and installed without the user's knowledge. Crypto ransomware, a malware variant that encrypts files, is spread through similar methods and also has been spread through Web-based instant messaging applications.<\/p>\n\n<p>Ransomware not only targets home users; businesses can also become infected with ransomware, which can have negative consequences, including:<\/p>\n\n<ul><li>Temporary or permanent loss of sensitive or proprietary information;<\/li>\n\t<li>Disruption to regular operations;<\/li>\n\t<li>Financial losses incurred to restore systems and files; and<\/li>\n\t<li>Potential harm to an organization's reputation.<\/li>\n<\/ul><p>Paying the ransom does not guarantee the encrypted files will be released; it only guarantees that the malicious actors receive the victim's money, and in some cases, their banking information as well. In addition, decrypting files does not mean the malware infection itself has been removed.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information\/preventive mesures and consider their implementation in the context of their network environment:<\/p>\n\n<ul><li>Employ a data backup and recovery plan for all critical information. Perform and test regular backups to limit the impact of data or system loss and to expedite the recovery process. Since network storage can also be affected, this data should be kept on a separate device, and backups should be stored offline.<\/li>\n\t<li>Use application whitelisting to help prevent malicious software and unapproved programs from running. Application whitelisting is one of the best security strategies as it allows only specified programs to run, while blocking all others, including malicious software.<\/li>\n\t<li>Keep your operating system and software up-to-date with the latest patches. Vulnerable applications and operating systems are the target of most attacks. Ensuring these are patched with the latest updates greatly reduces the number of exploitable entry points available to an attacker.<\/li>\n\t<li>Maintain up-to-date anti-virus software, and scan all software downloaded from the internet prior to executing.<\/li>\n\t<li>Restrict users\u2019 ability (permissions) to install and run unwanted software applications, and apply the principle of \u201cLeast Privilege\u201d to all systems and services. Restricting these privileges may prevent malware from running or limit its capability to spread through the network.<\/li>\n\t<li>Avoid enabling macros from email attachments. If a user opens the attachment and enables macros, embedded code will execute the malware on the machine. For enterprises or organizations, it may be best to block email messages with attachments from suspicious sources.<\/li>\n\t<li>Follow safe practices when browsing the Web.<\/li>\n\t<li>Do not follow unsolicited Web links in emails.<\/li>\n<\/ul><p>It is important to note that infections can be devastating to an individual or organization, and that recovery can be a difficult process which may require the services of a reputable data recovery specialist.<\/p>\n\n<h2>References<\/h2>\n\n<p>US-CERT Alert (TA16-091A)<br \/><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA16-091A\"><font color=\"#0066cc\">https:\/\/www.us-cert.gov\/ncas\/alerts\/TA16-091A<\/font><\/a><\/p>\n\n<p>CCIRC Cyber Safe Guide<br \/><a href=\"http:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx\"><font color=\"#0066cc\">http:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx<\/font><\/a><\/p>\n\n<p>McAfee Labs Threat Advisory: Ransomware - Locky<br \/><a href=\"https:\/\/kc.mcafee.com\/resources\/sites\/MCAFEE\/content\/live\/PRODUCT_DOCUMENTATION\/26000\/PD26383\/en_US\/McAfee_Labs_Threat_Advisory-Ransomware-Locky.pdf\"><font color=\"#0066cc\">https:\/\/kc.mcafee.com\/resources\/sites\/MCAFEE\/content\/live\/PRODUCT_DOCUMENTATION\/26000\/PD26383\/en_US\/McAfee_Labs_Threat_Advisory-Ransomware-Locky.pdf<\/font><\/a><\/p>\n\n<p>Sophos \/ Naked Security, \u201cLocky\u201d ransomware \u2013 what you need to know<br \/><a href=\"https:\/\/nakedsecurity.sophos.com\/2016\/02\/17\/locky-ransomware-what-you-need-to-know\"><font color=\"#0066cc\">https:\/\/nakedsecurity.sophos.com\/2016\/02\/17\/locky-ransomware-what-you-need-to-know<\/font><\/a><\/p>\n\n<p>Symantec Article - Cryptolocker: A Thriving Menace<br \/><a href=\"http:\/\/www.symantec.com\/connect\/blogs\/cryptolocker-thriving-menace\"><font color=\"#0066cc\">http:\/\/www.symantec.com\/connect\/blogs\/cryptolocker-thriving-menace<\/font><\/a><\/p>\n\n<p>Samas - SamSam: The Doctor Will See You, After He Pays The Ransom<br \/><a href=\"http:\/\/blog.talosintel.com\/2016\/03\/samsam-ransomware.html\"><font color=\"#0066cc\">http:\/\/blog.talosintel.com\/2016\/03\/samsam-ransomware.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/recent-ransomware-variant-locky","alert_type":397,"serial_number":"AL16-005","subject":null,"moderation_state":"archived","external_url":null},{"nid":1309,"title":"Active Exploitation of Vulnerability in Adobe Flash Player","uuid":"c8d94399-c26e-4c22-b7a9-1e50f13ea036","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-18T19:40:02Z","summary":null,"body":["<article data-history-node-id=\"1309\" about=\"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-006<br \/>\nDate: 6 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the active exploitation of a recently disclosed vulnerability in Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of attacks exploiting a previously unknown vulnerability in Adobe Flash Player.\u00a0 The vulnerability exists in version 20.0.0.306 and earlier for Windows, Mac OS X, Linux and Chrome OS.\u00a0\u00a0 Identified as CVE-2016-1019, exploitation of this vulnerability can allow for an attacker to take control of the affected system after causing a crash.<\/p>\n\n<p>Mitigation for this vulnerability exists for Adobe Flash Player since version 21.0.0.182, however the vulnerable source code still exists. Adobe is planning to provide a patch as early as 7 April 2016.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends system administrators test and deploy the latest version of Adobe Flash Player to affected systems accordingly to aid with mitigation for this vulnerability, and to consider disabling Adobe Flash until the patch is available to install.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa16-01.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa16-01.html<\/font><\/a> \u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player","alert_type":397,"serial_number":"AL16-006","subject":null,"moderation_state":"archived","external_url":null},{"nid":902,"title":"Vulnerability in ImageMagick","uuid":"b0ed034d-e6de-4e1e-b3dd-a184efa8820c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-06-19T12:36:28Z","summary":null,"body":["<article data-history-node-id=\"902\" about=\"\/en\/alerts-advisories\/vulnerability-imagemagick\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-007<br \/>\nDate: May 4, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in ImageMagick.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Through open source reporting, CCIRC has been made aware of a recently disclosed vulnerability in ImageMagick, that when exploited, can allow an attacker to remotely execute code without authentication.<\/p>\n\n<p>ImageMagick is a popular image processing library that is leveraged by many websites. Websites that allow users to upload images, such as blogs, forums and social media, are especially vulnerable to exploitation.<\/p>\n\n<p>Proof-of-concept exploit code has been released publicly, and the developer has indicated that a security fix will be released in the near future.<\/p>\n\n<p>CVE Reference: CVE-2016\u20133714<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for the developer released security fix. In the meantime, to aid with mitigation for this vulnerability, the developer and security researcher have released workarounds.<\/p>\n\n<h2>References<\/h2>\n\n<p>Security Researcher:<br \/><a href=\"https:\/\/imagetragick.com\/\"><font color=\"#0066cc\">https:\/\/imagetragick.com\/<\/font><\/a><\/p>\n\n<p>Developer Acknowledgement:<br \/><a href=\"https:\/\/www.imagemagick.org\/discourse-server\/viewtopic.php?f=4&amp;t=29588\"><font color=\"#0066cc\">https:\/\/www.imagemagick.org\/discourse-server\/viewtopic.php?f=4&amp;t=29588<\/font><\/a><\/p>\n\n<p>Arstechnica - Huge number of sites imperiled by critical image-processing vulnerability:<br \/><a href=\"http:\/\/arstechnica.com\/security\/2016\/05\/easily-exploited-bug-exposes-huge-number-of-sites-to-code-execution-attacks\/\"><font color=\"#0066cc\">http:\/\/arstechnica.com\/security\/2016\/05\/easily-exploited-bug-exposes-huge-number-of-sites-to-code-execution-attacks\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-imagemagick","alert_type":397,"serial_number":"AL16-007","subject":null,"moderation_state":"archived","external_url":null},{"nid":860,"title":"Active Exploitation of Vulnerability in Adobe Flash Player","uuid":"fa323041-4712-4b22-92c4-603b4591abb8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-19T12:48:55Z","summary":null,"body":["<article data-history-node-id=\"860\" about=\"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-008<br \/>\nDate: May 11, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the active exploitation of a recently disclosed vulnerability in Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of attacks exploiting a previously unknown critical vulnerability in Adobe Flash Player.\u00a0 The vulnerability exists in version 21.0.0.226 and earlier versions for Windows, Macintosh, Linux, and Chrome OS.\u00a0\u00a0 Identified as CVE-2016-4117, exploitation of this vulnerability could allow an attacker to take control of the affected system after having caused a deliberate crash.<\/p>\n\n<p>Adobe is planning to provide a patch as early as 12 May 2016.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends system administrators test and deploy the latest version of Adobe Flash Player to affected systems accordingly in an effort to mitigate this vulnerability. Operators may also consider disabling Adobe Flash until a permanent patch has been released.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa16-02.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa16-02.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player-0","alert_type":397,"serial_number":"AL16-008","subject":null,"moderation_state":"archived","external_url":null},{"nid":1118,"title":"Active Exploitation of Vulnerability in SAP Business Applications","uuid":"00cc0809-e97c-47db-bffd-53937d66dcb0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-19T13:24:15Z","summary":null,"body":["<article data-history-node-id=\"1118\" about=\"\/en\/alerts-advisories\/active-exploitation-vulnerability-sap-business-applications\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-009<br \/>\nDate: 12 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the active exploitation of a disclosed vulnerability affecting SAP business applications.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has been made aware of the exploitation of a vulnerability affecting SAP business applications which can allow an unauthenticated remote attacker full access to the SAP Java platform.<\/p>\n\n<p>The vulnerability exists in the Invoker Servlet, a built-in component of SAP\u2019s NetWeaver Application Server Java systems (SAP Java platforms). \u00a0A security update addressing this vulnerability was released by SAP in 2010, however many systems remain outdated and\/or misconfigured. The vulnerability may continue to affect SAP systems.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators scan their infrastructure for potentially vulnerable systems and follow the vendor recommendations outlined in their Security Note.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>SAP Security Note 1445998:<br \/><a href=\"https:\/\/service.sap.com\/sap\/support\/notes\/1445998\"><font color=\"#0066cc\">https:\/\/service.sap.com\/sap\/support\/notes\/1445998<\/font><\/a><\/li>\n\t<li>US-CERT Alert TA16-132A:<br \/><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA16-132A\"><font color=\"#0066cc\">https:\/\/www.us-cert.gov\/ncas\/alerts\/TA16-132A<\/font><\/a><\/li>\n\t<li>Onapsis Threat Report:<br \/><a href=\"https:\/\/www.onapsis.com\/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applications\"><font color=\"#0066cc\">https:\/\/www.onapsis.com\/threat-report-tip-iceberg-wild-exploitation-cyber-attacks-sap-business-applications<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vulnerability-sap-business-applications","alert_type":397,"serial_number":"AL16-009","subject":null,"moderation_state":"archived","external_url":null},{"nid":1173,"title":"Active Exploitation of Vulnerability in Ubiquiti airOS Devices","uuid":"fc676a0c-4090-487a-8fea-fa1fb33327c2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-19T13:34:18Z","summary":null,"body":["<article data-history-node-id=\"1173\" about=\"\/en\/alerts-advisories\/active-exploitation-vulnerability-ubiquiti-airos-devices\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-010<br \/>\nDate: 20 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a disclosed vulnerability in Ubiquiti airOS devices that is being actively exploited.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of attacks exploiting a critical vulnerability in Ubiquiti airOS. \u00a0A patch addressing this vulnerability was released by Ubiquiti in 2015.<\/p>\n\n<p>Unauthenticated access to a vulnerable airOS device's HTTP\/HTTPS web interface (generally enabled by default) is required for exploitation.\u00a0 Devices with this web interface accessible from the internet are especially susceptible to exploitation, however it appears that exploited devices are able to compromise other vulnerable devices within the same network.<\/p>\n\n<p>Exploitation of this vulnerability could allow an attacker to have root privilege on a device.<\/p>\n\n<p>Affected products:<br \/>\nairMAX M (including airRouter)<br \/>\nairMAX AC<br \/>\nairOS 802.11G<br \/>\nToughSwitch<br \/>\nairGateway<br \/>\nairFiber<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators scan their infrastructure for potentially vulnerable systems and follow the vendor recommendations outlined in their Security Notice.<\/p>\n\n<h2>References<\/h2>\n\n<p>Symantec article:<br \/><a href=\"http:\/\/www.symantec.com\/connect\/blogs\/thousands-ubiquiti-airos-routers-hit-worm-attacks\"><font color=\"#0066cc\">http:\/\/www.symantec.com\/connect\/blogs\/thousands-ubiquiti-airos-routers-hit-worm-attacks<\/font><\/a><\/p>\n\n<p>Ubiquiti Notice:<br \/><a href=\"http:\/\/community.ubnt.com\/t5\/airMAX-Updates-Blog\/Important-Security-Notice-and-airOS-5-6-5-Release\/ba-p\/1565949\"><font color=\"#0066cc\">http:\/\/community.ubnt.com\/t5\/airMAX-Updates-Blog\/Important-Security-Notice-and-airOS-5-6-5-Release\/ba-p\/1565949<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vulnerability-ubiquiti-airos-devices","alert_type":397,"serial_number":"AL16-010","subject":null,"moderation_state":"archived","external_url":null},{"nid":797,"title":"ESC 8832 SCADA System Vulnerabilities","uuid":"3f8960eb-18fe-4168-9769-8289b889959f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:10Z","date_created":"2018-06-19T13:44:50Z","summary":null,"body":["<article data-history-node-id=\"797\" about=\"\/en\/alerts-advisories\/esc-8832-scada-system-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-011<br \/>\nDate: 31 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to vulnerabilities in the Environmental Systems Corporation (ESC) 8832 Data Controller.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of critical vulnerabilities in the Environmental Systems Corporation (ESC) 8832 Data Controller unit.\u00a0 These vulnerabilities are remotely exploitable and can allow an attacker to gain administrator level control of the device.<\/p>\n\n<p>ESC has stated that firmware security updates will not be issued due to hardware limitations in the 8832 Data Controller.\u00a0\u00a0 This is despite the official 1 January 2019 end of life for the 8832 Data Controller.\u00a0 As a result, the vulnerabilities will not be resolved.<\/p>\n\n<p>CVE References: CVE-2016-4501, CVE-2016-4502<\/p>\n\n<p>Affected Versions:<br \/>\n- ESC 8832 Data Controller Version 3.02 and earlier<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system owners enact their organization\u2019s life-cycle process for affected devices, and test\/deploy replacement solutions. \u00a0To aid with mitigation of the vulnerabilities, network access to affected devices should be controlled, isolated and protected.\u00a0 In particular, access to port 80 on affected devices should be restricted.<\/p>\n\n<h2>References<\/h2>\n\n<p>ICS-CERT Advisory - <a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-147-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-147-01<\/font><\/a><br \/>\nESC Model Description - <a href=\"http:\/\/pine-environmental.com\/product\/instruments\/esc_8832_controller\/\"><font color=\"#0066cc\">http:\/\/pine-environmental.com\/product\/instruments\/esc_8832_controller\/<\/font><\/a><br \/>\nESC \u00a0Presentation - <a href=\"https:\/\/www.envirosys.com\/media\/p\/3662\/download.aspx\"><font color=\"#0066cc\">https:\/\/www.envirosys.com\/media\/p\/3662\/download.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/esc-8832-scada-system-vulnerabilities","alert_type":397,"serial_number":"AL16-011","subject":null,"moderation_state":"archived","external_url":null},{"nid":1269,"title":"Active Exploitation of Vulnerability in Adobe Flash Player","uuid":"94d98069-1f85-49d1-8b99-e9bccbea3340","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:29Z","date_created":"2018-06-19T13:55:27Z","summary":null,"body":["<article data-history-node-id=\"1269\" about=\"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-012<br \/>\nDate: 14 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the active exploitation of a recently disclosed vulnerability in Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of attacks exploiting a previously unknown critical vulnerability in Adobe Flash Player. The vulnerability exists in version 21.0.0.242 and earlier versions for Windows, Macintosh, Linux, and Chrome OS. Identified as CVE-2016-4171, exploitation of this vulnerability could allow an attacker to take control of the affected system after having caused a deliberate crash.<\/p>\n\n<p>Adobe is planning to provide a patch as early as 16 June 2016.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends system administrators test and deploy the latest version of Adobe Flash Player to affected systems accordingly in an effort to mitigate this vulnerability.<\/p>\n\n<p>Operators may also consider disabling Adobe Flash until a permanent patch has been released.<\/p>\n\n<p>Organizations should consider installing Microsoft's Experience Mitigation Toolkit (EMET). The Enhanced Mitigation Experience Toolkit helps mitigate the exploitation of vulnerabilities by adding additional protection layers that make them harder to exploit.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa16-03.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa16-03.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player-1","alert_type":397,"serial_number":"AL16-012","subject":null,"moderation_state":"archived","external_url":null},{"nid":1089,"title":"OpenSSL Vulnerability","uuid":"b3f24934-317e-47a6-bf60-1a060a1ef66f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-19T14:21:39Z","summary":null,"body":["<article data-history-node-id=\"1089\" about=\"\/en\/alerts-advisories\/openssl-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-013<br \/>\nDate: 22 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in OpenSSL.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in OpenSSL.\u00a0 Identified as CVE-2016-2177, this vulnerability can allow a remote unauthenticated attacker to cause denial of service conditions.\u00a0 Proof-of-concept exploit code has been released publicly.<\/p>\n\n<p>CVE Reference: CVE-2016-2177<\/p>\n\n<p>Affected Versions: OpenSSL 1.0.2h and prior<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for the developer released security fix.<\/p>\n\n<h2>References<\/h2>\n\n<p>NIST National Vulnerability Database:<br \/><a href=\"http:\/\/nvd.nist.gov\/nvd.cfm?cvename=CVE-2016-2177\"><font color=\"#0066cc\">http:\/\/nvd.nist.gov\/nvd.cfm?cvename=CVE-2016-2177<\/font><\/a>\u00a0\u00a0<\/p>\n\n<p>OpenSSL:<br \/><a href=\"https:\/\/www.openssl.org\/\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-vulnerability","alert_type":397,"serial_number":"AL16-013","subject":null,"moderation_state":"archived","external_url":null},{"nid":920,"title":"Sierra Wireless AirLink Raven XE Industrial 3G Gateway - Multiple Vulnerabilities Reported (UPDATE)","uuid":"fa725b98-726c-44cb-b56e-b952c211ee40","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-19T14:32:00Z","summary":null,"body":["<article data-history-node-id=\"920\" about=\"\/en\/alerts-advisories\/sierra-wireless-airlink-raven-xe-industrial-3g-gateway-multiple-vulnerabilities-reported\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-014<br \/>\nDate: 29 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<div class=\"alert alert-info\">\n<p>CORRECTION: The vendor has not yet published or registered an official vulnerability report. As this vulnerability has already been published, it is provided herein for awareness and mitigation if necessary.<\/p>\n<\/div>\n\n<p>The purpose of this advisory is to bring attention to vulnerabilities in the Sierra Wireless AirLink Raven XE Industrial 3G Gateway.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of critical vulnerabilities in the Sierra Wireless AirLink Raven XE Industrial 3G Gateway.\u00a0 These vulnerabilities are remotely exploitable and could allow an attacker to gain privileged access to the device or cause other issues detailed in the reference below.<\/p>\n\n<p>Vulnerability - Affected Version(s):<\/p>\n\n<ul><li>Weak Credential Management - Raven XE HSPA, GX400<\/li>\n\t<li>CSRF Vulnerability \u2013 All Raven XE\/XT models<\/li>\n\t<li>Sensitive Information Leakage \u2013 Ace Manager All Raven XE\/XT models<\/li>\n\t<li>Unauthenticated Access \u2013 All Raven XE\/XT models<\/li>\n<\/ul><p>Note: The Raven XE\/XT devices are past end of life and will not receive firmware updates to address these issues.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system owners enact their organization's life-cycle process for affected devices, and test\/deploy replacement solutions. \u00a0To aid with mitigation of the vulnerabilities, the recommendations from Sierra Wireless below should be followed.<\/p>\n\n<p>Sierra Wireless recommends:<\/p>\n\n<ol><li>Customers should change all the default passwords on equipment they purchase, especially for interfaces that are enabled on public networks. They also recommend that customers use the firewall configuration options to disable these interfaces on the cellular WAN interface.<\/li>\n\t<li>Port forwarding should never be enabled to unauthenticated or otherwise insecure interfaces on the LAN side of the gateway.<\/li>\n\t<li>The Ace Manager interface should be disabled on the cellular WAN connection.<\/li>\n<\/ol><h2>References<\/h2>\n\n<p>Seclists.org \u2013 <a href=\"http:\/\/seclists.org\/fulldisclosure\/2016\/Jun\/60\"><font color=\"#0066cc\">http:\/\/seclists.org\/fulldisclosure\/2016\/Jun\/60<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sierra-wireless-airlink-raven-xe-industrial-3g-gateway-multiple-vulnerabilities-reported","alert_type":397,"serial_number":"AL16-014","subject":null,"moderation_state":"archived","external_url":null},{"nid":1196,"title":"Vulnerability in Objective Systems ASN1C C\/C++ Compiler","uuid":"2a8258ea-b95b-46c4-bd13-44b9f18ef475","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-06-19T15:00:44Z","summary":null,"body":["<article data-history-node-id=\"1196\" about=\"\/en\/alerts-advisories\/vulnerability-objective-systems-asn1c-cc-compiler\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-015<br \/>\nDate: 22 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in the Objective Systems ASN1C C\/C++ compiler.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in the ASN1C C\/C++compiler. \u00a0Exploitation of this vulnerability could potentially allow a remote unauthenticated attacker to execute arbitrary code on an affected system.<\/p>\n\n<p>CVE Reference: CVE-2016-5080<\/p>\n\n<p>Affected Versions: ASN1C C\/C++ compiler 7.0 and earlier.<\/p>\n\n<p>Affected Systems: Any systems with resources compiled by affected versions of the ASN1C C\/C++ compiler.<\/p>\n\n<p>ASN1C is a compiler for the ASN.1 specification, which is used and referenced by multiple telecommunication protocols including GSM, UMTS, LTE, X.509, SNMP, and voice-over-IP.\u00a0\u00a0 As a result, the ASN1C compiler is leveraged by several hardware and software products.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services. As updates become available, their organization\u2019s patch management process should be actioned accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>CERT\/CC Vulnerability Note #790839 - Objective Systems ASN1C generates code that contains a heap overflow vulnerability:<br \/><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/790839\"><font color=\"#0066cc\">http:\/\/www.kb.cert.org\/vuls\/id\/790839<\/font><\/a><\/li>\n\t<li>Security Researcher Advisory:<br \/><a href=\"https:\/\/github.com\/programa-stic\/security-advisories\/tree\/master\/ObjSys\/CVE-2016-5080\"><font color=\"#0066cc\">https:\/\/github.com\/programa-stic\/security-advisories\/tree\/master\/ObjSys\/CVE-2016-5080<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-objective-systems-asn1c-cc-compiler","alert_type":397,"serial_number":"AL16-015","subject":null,"moderation_state":"archived","external_url":null},{"nid":808,"title":"Cisco ASA SNMP Remote Code Execution Vulnerability","uuid":"24289bc1-e54a-44a3-b9f1-06cdd3cc5f1c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:55Z","date_created":"2018-06-19T15:15:00Z","summary":null,"body":["<article data-history-node-id=\"808\" about=\"\/en\/alerts-advisories\/cisco-asa-snmp-remote-code-execution-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-016<br \/>\nDate: 18 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in Cisco\u2019s Adaptive Security Appliance.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in Cisco\u2019s Adaptive Security Appliance.\u00a0 Identified as CVE-2016-6366, this vulnerability in the SNMP code can allow a remote unauthenticated attacker to cause a reload of the affected system or to remotely execute code.\u00a0 Exploit code has been released publicly.<\/p>\n\n<p>A crafted IPv4 SNMP packet could cause a buffer overflow and the attacker must know the community string of the affected system in order to successfully exploit this vulnerability.<\/p>\n\n<p>All versions of SNMP are affected by this vulnerability and software running on the following devices:<\/p>\n\n<ul><li>Cisco ASA 5500 Series Adaptive Security Appliances<\/li>\n\t<li>Cisco ASA 5500-X Series Next-Generation Firewalls<\/li>\n\t<li>Cisco ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers<\/li>\n\t<li>Cisco ASA 1000V Cloud Firewall<\/li>\n\t<li>Cisco Adaptive Security Virtual Appliance (ASAv)<\/li>\n\t<li>Cisco Firepower 9300 ASA Security Module<\/li>\n\t<li>Cisco PIX Firewalls<\/li>\n\t<li>Cisco Firewall Services Module (FWSM)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for the developer released security fix. Workarounds have been published by the vendor.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-asa-snmp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-asa-snmp<\/font><\/a>\u00a0\u00a0\u00a0<\/li>\n\t<li><a href=\"http:\/\/blogs.cisco.com\/security\/shadow-brokers\"><font color=\"#0066cc\">http:\/\/blogs.cisco.com\/security\/shadow-brokers<\/font><\/a>\u00a0\u00a0\u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-asa-snmp-remote-code-execution-vulnerability","alert_type":397,"serial_number":"AL16-016","subject":null,"moderation_state":"archived","external_url":null},{"nid":892,"title":"Fortinet Cookie Parser Buffer Overflow Vulnerability","uuid":"15f6023a-a1ce-4331-8e29-ede0153e32ab","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-19T15:23:35Z","summary":null,"body":["<article data-history-node-id=\"892\" about=\"\/en\/alerts-advisories\/fortinet-cookie-parser-buffer-overflow-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-017<br \/>\nDate: 18 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the FortiGate Cookie Parser Buffer Overflow Vulnerability.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in FortiGate firmware (FOS).\u00a0 This vulnerability, when exploited by a specially crafted HTTP request, can allow a malicious actor to gain remote administrative access.<\/p>\n\n<p>Affected firmware versions:<br \/>\nFortiGate versions 4.3.8 and prior<br \/>\nFortiGate versions 4.2.12 and prior<br \/>\nFortiGate versions 4.1.10 and prior<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<p>Upgrade to release 5.x.<br \/>\nUpgrade to release 4.3.9 or above for models not compatible with FortiOS 5.x.<\/p>\n\n<p>References:<\/p>\n\n<p>Fortinet Advisory<br \/><a href=\"http:\/\/fortiguard.com\/advisory\/FG-IR-16-023\"><font color=\"#0066cc\">http:\/\/fortiguard.com\/advisory\/FG-IR-16-023<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-cookie-parser-buffer-overflow-vulnerability","alert_type":397,"serial_number":"AL16-017","subject":null,"moderation_state":"archived","external_url":null},{"nid":1072,"title":"Default credentials in some Sierra Wireless Devices may be leveraged by Malware","uuid":"db0ee726-2de6-4e3a-ad80-346338534773","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-19T16:22:57Z","summary":null,"body":["<article data-history-node-id=\"1072\" about=\"\/en\/alerts-advisories\/default-credentials-some-sierra-wireless-devices-may-be-leveraged-malware\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-018<br \/>\nDate: 14 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to potential exploitation of default credentials on Sierra Wireless devices.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a potential leveraging of Sierra Wireless devices by the \u201cMirai\u201d malware for DDOS activities. The malware could gain access to the AirLink Cellular gateway using the default ACEmanager credentials publicly available, if the device is reachable on the internet. Using the firmware update function, the malware will be able to run a copy of itself.<\/p>\n\n<p>Once the malware is running on the gateway it deletes itself and resides only in memory.<\/p>\n\n<p>Abnormal traffic on TCP port 23 and 48101 and large amount of outbound traffic are strong indicators of malware presence. Port 23 is used by the malware to scan for other vulnerable devices while port 48101 is used for Command and control traffic.<\/p>\n\n<p>Affected Sierra Wireless products: LS300, GX400, GX\/ES440, GX\/ES450 and RV50.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>The vendor strongly suggests that customers do the following steps for each of their gateway:<\/p>\n\n<ul><li>Reboot the gateway to eliminate the possibility of in-memory malware.<\/li>\n\t<li>Set the ACEmanager password to one that is secure and unique.<\/li>\n<\/ul><p>A detailed description of the risk and a list of recommendations to protect your device and attached network from infection can be found in Sierra Wireless technical bulletin linked in the references section.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/source.sierrawireless.com\/resources\/airlink\/software_reference_docs\/technical-bulletin\/sierra-wireless-technical-bulletin---mirai\/\"><font color=\"#0066cc\">http:\/\/source.sierrawireless.com\/resources\/airlink\/software_reference_docs\/technical-bulletin\/sierra-wireless-technical-bulletin---mirai\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/default-credentials-some-sierra-wireless-devices-may-be-leveraged-malware","alert_type":397,"serial_number":"AL16-018","subject":null,"moderation_state":"archived","external_url":null},{"nid":1040,"title":"Linux Kernel Vulnerability","uuid":"e690b18d-e9ee-4bdc-a08f-bf29c2cf7ecc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-06-19T16:31:05Z","summary":null,"body":["<article data-history-node-id=\"1040\" about=\"\/en\/alerts-advisories\/linux-kernel-vulnerability-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-019<br \/>\nDate: 21 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in the Linux kernel.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in the Linux kernel. Identified as CVE-2016-5195, this vulnerability can allow root privilege escalation in the Linux kernel environment.<\/p>\n\n<p>CVE Reference: CVE-2016-5195<br \/>\nAffected Kernel Version: 3.9 and higher<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators watch for vendor-released updates of affected Linux kernel versions.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/git.kernel.org\/cgit\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619\"><font color=\"#0066cc\">https:\/\/git.kernel.org\/cgit\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=19be0eaffa3ac7d8eb6784ad9bdbc7d67ed8e619<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2016-5195\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/cve\/CVE-2016-5195<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-kernel-vulnerability-0","alert_type":397,"serial_number":"AL16-019","subject":null,"moderation_state":"archived","external_url":null},{"nid":1157,"title":"Active Exploitation of Vulnerability in Adobe Flash Player","uuid":"ccd84e23-2f59-4179-be9e-fa34d1cf65ea","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-19T16:38:28Z","summary":null,"body":["<article data-history-node-id=\"1157\" about=\"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-020<br \/>\nDate: 27 October 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the active exploitation of a recently disclosed vulnerability in Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of attacks exploiting a previously unknown critical vulnerability in Adobe Flash Player. The vulnerability exists in: versions 23.0.0.185 and earlier of Adobe Flash Player Desktop Runtime, Adobe Flash Player for Google Chrome, and Adobe Flash Player for Microsoft Edge and Internet Explorer 11; and version 11.2.202.637 of Adobe Flash Player for Linux. Identified as CVE-2016-7855, exploitation of this vulnerability could allow an attacker to take control of the affected system.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the elevated risk presented by this vulnerability, CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. CCIRC recommends that priority is given to this patch.<\/p>\n\n<p>Organizations should consider installing Microsoft's Experience Mitigation Toolkit (EMET). The Enhanced Mitigation Experience Toolkit helps mitigate the exploitation of vulnerabilities by adding additional protection layers that make them harder to exploit.<\/p>\n\n<h2>References<\/h2>\n\n<p>CCIRC Advisory AV16-174: Security Update for Adobe Flash Player: <a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/av16-174-en.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/av16-174-en.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vulnerability-adobe-flash-player-2","alert_type":397,"serial_number":"AL16-020","subject":null,"moderation_state":"archived","external_url":null},{"nid":1202,"title":"Multiple Vulnerabilities in Moodle Version 3.1.2","uuid":"c55a9c6f-c5d1-4a14-9635-3657d3525ce7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-19T16:51:49Z","summary":null,"body":["<article data-history-node-id=\"1202\" about=\"\/en\/alerts-advisories\/multiple-vulnerabilities-moodle-version-312\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-022<br \/>\nDate: 05 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to multiple vulnerabilities in Moodle Version 3.1.2.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Moodle is an open sourced platform widely used for learning and training in educational facilities across Canada. CCIRC is aware of vulnerabilities in Moodle 3.1.2 or prior, that, if left unpatched, could either allow remote attackers to inject arbitrary web script or HTML and\/or execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors<\/p>\n\n<p>CVE References:<br \/>\nCVE-2016-9186, CVE-2016-9187, CVE-2016-9188<br \/><a href=\"https:\/\/www.cvedetails.com\/cve\/CVE-2016-9186\/\"><font color=\"#0066cc\">https:\/\/www.cvedetails.com\/cve\/CVE-2016-9186\/<\/font><\/a><br \/><a href=\"https:\/\/www.cvedetails.com\/cve\/CVE-2016-9187\/\"><font color=\"#0066cc\">https:\/\/www.cvedetails.com\/cve\/CVE-2016-9187\/<\/font><\/a><br \/><a href=\"https:\/\/www.cvedetails.com\/cve\/CVE-2016-9188\/\"><font color=\"#0066cc\">https:\/\/www.cvedetails.com\/cve\/CVE-2016-9188\/<\/font><\/a><\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-vulnerabilities-moodle-version-312","alert_type":397,"serial_number":"AL16-022","subject":null,"moderation_state":"archived","external_url":null},{"nid":1311,"title":"Avalanche Botnet Takedown","uuid":"6dbf73dd-d13f-4008-bead-e4120066a0b0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-19T16:59:53Z","summary":null,"body":["<article data-history-node-id=\"1311\" about=\"\/en\/alerts-advisories\/avalanche-botnet-takedown\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-023<br \/>\nDate: 1 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the recent \u201cAvalanche\u201d botnet takedown operation.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>On November 30th, 2016, a worldwide cooperative takedown of the Avalanche botnet took place.\u00a0 \u201cAvalanche\u201d refers to a worldwide crimeware-as-a-service (CaaS) network infrastructure operated by cyber criminals to conduct malicious activities, including: denial-of-service attacks, malware distribution; and phishing and money-mule operations.<\/p>\n\n<p>The global cooperative effort to disrupt Avalanche network infrastructure involved one of the largest-ever sinkholing operations, with over 800,000 domains blocked\/seized\/sinkholed.\u00a0 Avalanche utilized the double fast-flux DNS technique to attempt to hide itself, acting as command-and-control infrastructure for multiple malware families, including:<\/p>\n\n<ul><li>Windows-encryption Trojan horse (WVT) (aka Matsnu, Injector,Rannoh,Ransomlock.P)<\/li>\n\t<li>URLzone (aka Bebloh)<\/li>\n\t<li>Citadel<\/li>\n\t<li>VM-ZeuS (aka KINS)<\/li>\n\t<li>Bugat (aka Feodo, Geodo, Cridex, Dridex, Emotet)<\/li>\n\t<li>newGOZ (aka GameOverZeuS)<\/li>\n\t<li>Tinba (aka TinyBanker)<\/li>\n\t<li>Nymaim\/GozNym<\/li>\n\t<li>Vawtrak (aka Neverquest)<\/li>\n\t<li>Marcher<\/li>\n\t<li>Pandabanker<\/li>\n\t<li>Ranbyus<\/li>\n\t<li>Smart App<\/li>\n\t<li>TeslaCrypt<\/li>\n\t<li>Trusteer App<\/li>\n\t<li>Xswkit<\/li>\n\t<li>TeslaCrypt<\/li>\n\t<li>Corebot<\/li>\n\t<li>GetTiny<\/li>\n\t<li>Rovnix<\/li>\n\t<li>QakBot (aka Qbot, PinkSlip Bot)<\/li>\n<\/ul><p>The Royal Canadian Mounted Police led the law enforcement effort in Canada, with the Canadian Cyber Incident Response Centre assisting with Canadian victim notification and remediation.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>As the Avalanche botnet is associated with several malware families and a variety of malicious activity, identifying compromises and\/or infections may require thorough and varying action.<\/p>\n\n<p>CCIRC recommends that organizations review the following mitigation information\/preventive measures and consider their implementation in the context of their network environment:<\/p>\n\n<ul><li>Employ anti-malware tools on your assets and\/or infrastructure.\u00a0 Tools which can both detect\/identify and remediate\/remove infections should be sought.\u00a0 CCIRC does not endorse or support any specific product\/vendor.\u00a0 Anti-malware tools should be maintained and kept up-to-date, with all data\/software downloaded to your infrastructure scanned before executing\/opening.<\/li>\n\t<li>Employ a data backup and recovery plan for all critical information. Perform and test regular backups to limit the impact of data or system loss and to expedite the recovery process. Since network storage can also be affected, this data should be kept on a separate device, and backups should be stored offline.<\/li>\n\t<li>Use application whitelisting to help prevent malicious software and unapproved programs from running. Application whitelisting is one of the best security strategies as it allows only specified programs to run, while blocking all others, including malicious software.<\/li>\n\t<li>Keep your operating system and software up-to-date with the latest patches. Vulnerable applications and operating systems are the target of most attacks. Ensuring these are patched with the latest updates greatly reduces the number of exploitable entry points available to an attacker.<\/li>\n\t<li>Restrict users\u2019 ability (permissions) to install and run unwanted software applications, and apply the principle of \u201cLeast Privilege\u201d to all systems and services. Restricting these privileges may prevent malware from running or limit its capability to spread through the network.<\/li>\n\t<li>Avoid enabling macros from email attachments. If a user opens the attachment and enables macros, embedded code will execute the malware on the machine. For enterprises or organizations, it may be best to block email messages with attachments from suspicious sources.<\/li>\n\t<li>Follow safe practices when browsing the Web.<\/li>\n\t<li>Do not follow unsolicited Web links in emails.<\/li>\n<\/ul><p>It is important to note that infections can be devastating to an individual or organization, and that recovery can be a difficult process which may require the services of a reputable data recovery specialist.<\/p>\n\n<p>References:<\/p>\n\n<p>Europol Press Release:<br \/><a href=\"https:\/\/www.europol.europa.eu\/newsroom\/news\/%E2%80%98avalanche%E2%80%99-network-dismantled-in-international-cyber-operation\"><font color=\"#0066cc\">https:\/\/www.europol.europa.eu\/newsroom\/news\/%E2%80%98avalanche%E2%80%99-network-dismantled-in-international-cyber-operation<\/font><\/a><\/p>\n\n<p>US-CERT Avalanche Information:<br \/><a href=\"http:\/\/us-cert.gov\/avalanche\"><font color=\"#0066cc\">http:\/\/us-cert.gov\/avalanche<\/font><\/a><\/p>\n\n<p>Shadowserver Avalanche Information:<br \/><a href=\"http:\/\/blog.shadowserver.org\/2016\/12\/01\/avalanche\/\"><font color=\"#0066cc\">http:\/\/blog.shadowserver.org\/2016\/12\/01\/avalanche\/<\/font><\/a><\/p>\n\n<p>CCIRC Technical Report TR11-001 (Malware Infection Recovery Guide):<br \/><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-en.aspx\"><font color=\"#0066cc\">https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-en.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/avalanche-botnet-takedown","alert_type":397,"serial_number":"AL16-023","subject":null,"moderation_state":"archived","external_url":null},{"nid":903,"title":"Yahoo User Account Compromise","uuid":"25ce9805-2467-4354-a101-10f247615474","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-06-19T17:25:17Z","summary":null,"body":["<article data-history-node-id=\"903\" about=\"\/en\/alerts-advisories\/yahoo-user-account-compromise\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL16-024<br \/>\nDate: 15 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently acknowledged compromise of Yahoo user accounts.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC would like to raise awareness to the potential risks caused by the compromise of a large number of Yahoo accounts.\u00a0 Yahoo recently acknowledged that up to one billion user accounts may have been compromised from as far back as August 2013.\u00a0 While Yahoo has stated that they are in the process of notifying owners of affected accounts, it is possible that these accounts will be used by malicious actors in phishing and other campaigns.\u00a0 CCIRC partners have recently reported an uptick in phishing email utilizing Yahoo mail accounts.\u00a0 Yahoo account holders should also be aware that personal and password information may have been obtained by malicious actors and that they should take appropriate measures.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this account compromise, CCIRC recommends that Yahoo account holders follow the risk mitigation measures recommended by Yahoo and that stakeholders raise awareness of potentially malicious activity resulting from the use of compromised Yahoo user accounts.<\/p>\n\n<p>CCIRC observes that passwords associated with Yahoo accounts that users may have reused for other non-Yahoo services (banking, social media, etc.) should also be changed to protect the integrity of other accounts.<\/p>\n\n<h2>References<\/h2>\n\n<p>Get CyberSafe Guide for Small and Medium Businesses:<br \/><a href=\"https:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx%20-%20s6-2\"><font color=\"#0066cc\">https:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx%20-%20s6-2<\/font><\/a><\/p>\n\n<p>Using Passwords:<br \/><a href=\"https:\/\/www.getcybersafe.gc.ca\/cnt\/prtct-yrslf\/prtctn-dntty\/usng-psswrds-en.aspx\"><font color=\"#0066cc\">https:\/\/www.getcybersafe.gc.ca\/cnt\/prtct-yrslf\/prtctn-dntty\/usng-psswrds-en.aspx<\/font><\/a><\/p>\n\n<p>Spotting Malicious E-mail Messages:<br \/><a href=\"https:\/\/www.cse-cst.gc.ca\/en\/node\/237\/html\/2998\"><font color=\"#0066cc\">https:\/\/www.cse-cst.gc.ca\/en\/node\/237\/html\/2998<\/font><\/a><\/p>\n\n<p>Recognize and Secure a Hacked Yahoo Mail Account:<br \/><a href=\"https:\/\/help.yahoo.com\/kb\/account\/recognize-secure-hacked-yahoo-mail-account-sln3417.html?impressions=true\"><font color=\"#0066cc\">https:\/\/help.yahoo.com\/kb\/account\/recognize-secure-hacked-yahoo-mail-account-sln3417.html?impressions=truea<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/yahoo-user-account-compromise","alert_type":397,"serial_number":"AL16-024","subject":null,"moderation_state":"archived","external_url":null},{"nid":862,"title":"IBM security bulletin","uuid":"a248c5fe-1445-4542-b504-6736060c7d15","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-19T17:41:39Z","summary":null,"body":["<article data-history-node-id=\"862\" about=\"\/en\/alerts-advisories\/ibm-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-001<br \/>\nDate: 02 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently published security bulletin by IBM.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>IBM has addressed a vulnerability in IBM Data Protection Extension in the VMware GUI component of IBM Tivoli Storage Manager for Virtual Environments.\u00a0 This privilege escalation vulnerability could allow an authenticated malicious actor, with lower privilege right, to restore an existing virtual machine. \u00a0<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Tivoli Storage Manager for Virtual Environments: Data Protection for VMware 7.1.0.0 through 7.1.3.x<\/li>\n\t<li>Tivoli Storage FlashCopy Manger for VMware 4.1.0 through 4.1.3.x<\/li>\n<\/ul><p>CVE Reference:<br \/>\nCVE-2015-7429<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>IBM has provided fixes to address this vulnerability.<\/p>\n\n<p>References:<\/p>\n\n<p>IBM:<br \/><a href=\"http:\/\/www-01.ibm.com\/support\/docview.wss?uid=swg21973087\"><font color=\"#0066cc\">http:\/\/www-01.ibm.com\/support\/docview.wss?uid=swg21973087<\/font><\/a><\/p>\n\n<p>CVE Reference:<br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2015-7429\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2015-7429<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-bulletin","alert_type":396,"serial_number":"AV16-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1120,"title":"Android security bulletin \u2013 January 2016","uuid":"7a35e01b-db7b-491f-89ab-fdd1e7f0ed7f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-19T17:51:41Z","summary":null,"body":["<article data-history-node-id=\"1120\" about=\"\/en\/alerts-advisories\/android-security-bulletin-january-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-002<br \/>\nDate: 8 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for January.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses a security update for 12 vulnerabilities (5 Critical, 2 High, and 6 Moderate) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2015-6636, CVE-2015-6637, CVE-2015-6638, CVE-2015-6639, CVE-2015-6640, CVE-2015-6641, CVE-2015-6642, CVE-2015-6643, CVE-2015-5310, CVE-2015-6644, CVE-2015-6645, CVE-2015-6646<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>Android web site: <a href=\"http:\/\/source.android.com\/security\/bulletin\/2016-01-01.html\"><font color=\"#0066cc\">http:\/\/source.android.com\/security\/bulletin\/2016-01-01.html<\/font><\/a><\/li>\n\t<li>CVE web site: <a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2015-6647\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2015-6647<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-january-2016","alert_type":null,"serial_number":"AV16-002","subject":null,"moderation_state":"archived","external_url":null},{"nid":1175,"title":"WordPress Security Release","uuid":"458a9874-9dfa-4324-aacb-e536d3b27c3d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-19T18:00:22Z","summary":null,"body":["<article data-history-node-id=\"1175\" about=\"\/en\/alerts-advisories\/wordpress-security-release\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-003<br \/>\nDate: 8 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a WordPress Security Release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress versions previous to 4.4 are affected by a critical cross-site scripting (XSS) vulnerability which could allow a site to be compromised.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>WordPress versions previous to 4.4 are affected by a critical cross-site scripting (XSS) vulnerability which could allow a site to be compromised.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/wordpress.org\/news\/2016\/01\/wordpress-4-4-1-security-and-maintenance-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2016\/01\/wordpress-4-4-1-security-and-maintenance-release\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/codex.wordpress.org\/Version_4.4.1\"><font color=\"#0066cc\">https:\/\/codex.wordpress.org\/Version_4.4.1<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-release","alert_type":396,"serial_number":"AV16-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":769,"title":"PHP security updates","uuid":"79f41837-3b85-4dfe-b22d-9f50726aa685","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-19T18:38:26Z","summary":null,"body":["<article data-history-node-id=\"769\" about=\"\/en\/alerts-advisories\/php-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-004<br \/>\nDate: 11 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple PHP security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>PHP has released multiple security updates covering vulnerabilities in versions prior to 7.0.2, 5.6.16, and 5.5.31. \u00a0Those updates include patches to address vulnerabilities which could potentially allow an attacker to perform remote code execution.<\/p>\n\n<p>Additionally as of July 10, 2016, PHP 5.5 will have reached its end of life and will no longer be supported.\u00a0<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends organizations consult with vendors for confirmation on whether their products and\/or service providers are utilizing vulnerable versions of PHP.\u00a0 As vendor-released updates become available, organizations should test and deploy updates to affected applications\/platforms accordingly.<\/p>\n\n<p>Migration to an updated development platform can present unique challenges and it is critical that organizations operating PHP 5.5 plan and test a migration solution before the deadline.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>PHP Download: <a href=\"http:\/\/www.php.net\/downloads.php\"><font color=\"#0066cc\">http:\/\/www.php.net\/downloads.php<\/font><\/a><\/li>\n\t<li>PHP 5 Changelog: <a href=\"http:\/\/php.net\/ChangeLog-5.php\"><font color=\"#0066cc\">http:\/\/php.net\/ChangeLog-5.php<\/font><\/a><\/li>\n\t<li>PHP 7 Changelog: <a href=\"http:\/\/php.net\/ChangeLog-7.php\"><font color=\"#0066cc\">http:\/\/php.net\/ChangeLog-7.php<\/font><\/a><\/li>\n\t<li>Infoworld: <a href=\"http:\/\/www.infoworld.com\/article\/3020451\/application-development\/patch-your-php-security-fixes-released-for-all-branches.html\"><font color=\"#0066cc\">http:\/\/www.infoworld.com\/article\/3020451\/application-development\/patch-your-php-security-fixes-released-for-all-branches.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-updates","alert_type":396,"serial_number":"AV16-004","subject":null,"moderation_state":"archived","external_url":null},{"nid":1091,"title":"Microsoft Critical security bulletins Summary for January 2016","uuid":"7ef9fbf2-ff2d-4a16-a5f3-a55820b6498a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-19T19:06:02Z","summary":null,"body":["<article data-history-node-id=\"1091\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-january-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-005<br \/>\nDate: 12 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for January 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 9 bulletins (6 Critical and 3 Important), which addresses multiple vulnerabilities in Internet Explorer, Microsoft Edge, Jscript, VBScript, Silverlight, Microsoft Office, Microsoft Windows, Microsoft Exchange Server, and Windows Kernel-Mode Drivers.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS16-001 Cumulative Security Update for Internet Explorer (3124903)\u00a0<\/li>\n\t<li>MS16-002 Cumulative Security Update for Microsoft Edge (3124904)\u00a0<\/li>\n\t<li>MS16-003 Cumulative Security Update for JScript and VBScript to Address Remote Code Execution (3125540)<\/li>\n\t<li>MS16-004 Security Update for Microsoft Office to Address Remote Code Execution (3124585)<\/li>\n\t<li>MS16-005 Security Update for Windows Kernel-Mode Drivers to Address Remote Code Execution (3124584)\u00a0<\/li>\n\t<li>MS16-006 Security Update for Silverlight to Address Remote Code Execution (3126036)<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS16-007 Security Update for Microsoft Windows to Address Remote Code Execution (3124901)<\/li>\n\t<li>MS16-008 Security Update for Windows Kernel to Address Elevation of Privilege (3124605)<\/li>\n\t<li>MS16-010 Security Update in Microsoft Exchange Server to Address Spoofing (3124557)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-jan.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-jan.aspx<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-january-2016","alert_type":null,"serial_number":"AV16-005","subject":null,"moderation_state":"archived","external_url":null},{"nid":1286,"title":"security updates for Adobe Acrobat and Reader","uuid":"4d0b43f2-26ff-47ff-84a9-7aa76942df2a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:34Z","date_created":"2018-06-19T19:14:41Z","summary":null,"body":["<article data-history-node-id=\"1286\" about=\"\/en\/alerts-advisories\/security-updates-adobe-acrobat-and-reader\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-006<br \/>\nDate: 12 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Adobe Acrobat and Reader.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-02 to address critical vulnerabilities that could allow an attacker to take control of the affected system.\u00a0 All Platforms are reported as affected.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Acrobat DC 15.009.20077 and earlier versions<\/li>\n\t<li>Acrobat Reader DC 15.009.20077 and earlier versions<\/li>\n\t<li>Acrobat DC 15.006.30097 and earlier versions<\/li>\n\t<li>Acrobat Reader DC 15.006.30097 and earlier versions<\/li>\n\t<li>Acrobat XI 11.0.13 and earlier versions<\/li>\n\t<li>Reader XI 11.0.13 and earlier versions<\/li>\n<\/ul><p>CVE References: CVE-2016-0931, CVE-2016-0932, CVE-2016-0933, CVE-2016-0934, CVE-2016-0935, CVE-2016-0936, CVE-2016-0937, CVE-2016-0938, CVE-2016-0939, CVE-2016-0940, CVE-2016-0941, CVE-2016-0942, CVE-2016-0943, CVE-2016-0944, CVE-2016-0945, CVE-2016-0946, CVE-2016-0947<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/reader\/apsb16-02.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/reader\/apsb16-02.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-adobe-acrobat-and-reader","alert_type":null,"serial_number":"AV16-006","subject":null,"moderation_state":"archived","external_url":null},{"nid":921,"title":"Multiple Cisco Security Advisories","uuid":"1fa3e3c7-a13b-4ae9-9005-76ffa44f7c79","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-20T16:24:19Z","summary":null,"body":["<article data-history-node-id=\"921\" about=\"\/en\/alerts-advisories\/multiple-cisco-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-007<br \/>\nDate: 13 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released security updates to address multiple vulnerabilities (2 Critical, 2 High) affecting the following products:<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>Cisco 2500 Series Wireless Controllers<\/li>\n\t<li>Cisco 5500 Series Wireless Controllers<\/li>\n\t<li>Cisco 8500 Series Wireless Controllers\u00a0<\/li>\n\t<li>Cisco Flex 750 Series Wireless Controllers<\/li>\n\t<li>Cisco Virtual Wireless Controllers<\/li>\n\t<li>Cisco Application Deployment Engine OS Release 2.2<\/li>\n\t<li>ADE-OS Build Version 2.2.0.162<\/li>\n\t<li>ADE-OS System Architecture: x86_64<\/li>\n<\/ul><p>***High***<\/p>\n\n<ul><li>Cisco Aironet 1830e Series Access Point<\/li>\n\t<li>Cisco Aironet 1830i Series Access Point<\/li>\n\t<li>Cisco Aironet 1850e Series Access PointCisco Aironet 1850i Series Access Point<\/li>\n<\/ul><p>CVE References: CVE-2015-6314, CVE-2015-6323<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Cisco Advisories:<\/p>\n\n<ul><li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-wlc\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-wlc<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-ise\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-ise<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-air\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-air<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-aironet\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-aironet<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-cisco-security-advisories","alert_type":null,"serial_number":"AV16-007","subject":null,"moderation_state":"archived","external_url":null},{"nid":1198,"title":"security update for OpenSSH","uuid":"3f990d08-ed68-44a4-9c5e-756501c1623c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-06-20T16:33:41Z","summary":null,"body":["<article data-history-node-id=\"1198\" about=\"\/en\/alerts-advisories\/security-update-openssh\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-008<br \/>\nDate: 14 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for OpenSSH (client).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>OpenSSH has released version 7.1p2, which addresses multiple vulnerabilities affecting the client version of its software.\u00a0 Notably, one of these vulnerabilities could allow an attacker obtain data residing in client memory (including private user keys) when it communicates with a malicious server.<\/p>\n\n<p>CVE References: CVE-2016-0777, CVE-2016-0778<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/www.openssh.com\/txt\/release-7.1p2\"><font color=\"#0066cc\">http:\/\/www.openssh.com\/txt\/release-7.1p2<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-openssh","alert_type":396,"serial_number":"AV16-008","subject":null,"moderation_state":"archived","external_url":null},{"nid":810,"title":"Advantech WebAccess - Multiple Vulnerabilities","uuid":"7d93be39-5182-4eef-8d17-8d02036a868d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:07Z","date_created":"2018-06-20T16:41:57Z","summary":null,"body":["<article data-history-node-id=\"810\" about=\"\/en\/alerts-advisories\/advantech-webaccess-multiple-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-009<br \/>\nDate: January 18 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple vulnerabilities in Advantech's WebAccess application.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Advantech's WebAccess is a web based application used with SCADA and human machine interfaces (HMI). CCIRC is aware of 15 disclosed vulnerabilities in Advantech WebAccess application. The exploitation of these vulnerabilities could allow an attacker to upload, create, or delete random files on a target system, deny access to valid users or remotely execute arbitrary code. Affected Versions: WebAccess Version 8 and prior versions.<\/p>\n\n<p>Vulnerability Overview and Associated CVEs:<\/p>\n\n<ol><li>Access of Memory Location After End of Buffer: CVE-2016-0851<\/li>\n\t<li>Improper Access Control: CVE-2016-0852<\/li>\n\t<li>Unrestricted Upload of File With Dangerous Type: CVE-2016-0854<\/li>\n\t<li>Path Traversal: CVE-2016-0855<\/li>\n\t<li>Stack-Based Buffer Overflow: CVE-2016-0856<\/li>\n\t<li>Heap-Based Buffer Overflow: CVE-2016-0857<\/li>\n\t<li>Race Condition: CVE-2016-0858<\/li>\n\t<li>Integer Overflow to Buffer Overflow: CVE-2016-0859<\/li>\n\t<li>Improper Restriction of Operations Within Bounds of Memory Buffer: CVE-2016-0860<\/li>\n\t<li>Improper Input Validation: CVE-2016-0853<\/li>\n\t<li>Cross-Site Scripting: CVE-2015-3948<\/li>\n\t<li>SQL Injection: CVE-2015-3947<\/li>\n\t<li>Cross Site Request Forgery: CVE- 2015-3946<\/li>\n\t<li>External Control of File Name or Path: CVE-2015-6467<\/li>\n\t<li>Clear Text Storage of Sensitive Information : CVE-2015-3943<\/li>\n<\/ol><h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy version 8.1 of WebAccess the newly released version that is designed to address the reported vulnerabilities.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-014-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-014-01<\/font><\/a><br \/><a href=\"http:\/\/www.advantech.com\/industrial-automation\/webaccess\/download\"><font color=\"#0066cc\">http:\/\/www.advantech.com\/industrial-automation\/webaccess\/download<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/advantech-webaccess-multiple-vulnerabilities","alert_type":396,"serial_number":"AV16-009","subject":null,"moderation_state":"archived","external_url":null},{"nid":894,"title":"Apple security updates for OS X, Safari, iOS","uuid":"25164cb0-036f-4737-bd98-806c0ef21db1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-20T16:51:26Z","summary":null,"body":["<article data-history-node-id=\"894\" about=\"\/en\/alerts-advisories\/apple-security-updates-os-x-safari-ios\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-010<br \/>\nDate: 19 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Apple operating system updates for OS X, Safari and iOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<ul><li>HT205730 \u2013 Safari 9.0.3<\/li>\n\t<li>HT205731 - OS X<\/li>\n\t<li>HT205732 - iOS 9.2.1<\/li>\n<\/ul><p>Details: These updates address multiple vulnerabilities that could allow remote attackers to execute arbitrary commands.<\/p>\n\n<p>CVE References:\u00a0 Multiple CVEs are referenced; please refer to Apple\u2019s advisory for specific details.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Articles; HT205730, HT205731 and HT205732.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/kb\/HT205730\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT205730<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/kb\/HT205731\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT205731<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/kb\/HT205732\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT205732<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-os-x-safari-ios","alert_type":396,"serial_number":"AV16-010","subject":null,"moderation_state":"archived","external_url":null},{"nid":1073,"title":"Oracle Critical Patch update Advisory \u2013 January 2016","uuid":"212cec8a-592e-4c89-870b-733c5d2840ac","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-20T17:14:10Z","summary":null,"body":["<article data-history-node-id=\"1073\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-january-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-011<br \/>\nDate: 19 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following critical patch updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update (CPU) which addresses 248 new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Application Mgmt Pack for EBusiness Suite, version(s) 12.1, 12.2<\/li>\n\t<li>Enterprise Manager Base Platform, version(s) 11.1.0.1, 11.2.0.4, 12.1.0.4, 12.1.0.5<\/li>\n\t<li>Enterprise Manager Ops Center, version(s) prior to 12.1.4, 12.2.0, 12.2.1, 12.3.0<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version(s) 9.1, 9.2<\/li>\n\t<li>MICROS CWDirect, version(s) 12.5, 13.0, 14.0, 15.0, 16.0, 17.0 18.0<\/li>\n\t<li>MySQL Server, version(s) 5.5.46 and prior, 5.6.27 and prior, 5.7.9<\/li>\n\t<li>Oracle Agile Engineering Data Management, version(s) 6.1.2.2, 6.1.3.0, 6.2.0.0<\/li>\n\t<li>Oracle Agile PLM, version(s) 9.3.1.1, 9.3.1.2, 9.3.2, 9.3.3<\/li>\n\t<li>Oracle Application Testing Suite, version(s) 12.4.0.2, 12.5.0.2<\/li>\n\t<li>Oracle BI Publisher, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.2.1.0.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, version(s) 11.1.1.7.0, 11.1.1.9.0<\/li>\n\t<li>Oracle Communications Converged Application Server Service Controller, version(s) 6.1<\/li>\n\t<li>Oracle Communications EAGLE LNP Application Processor, version(s) 10.0<\/li>\n\t<li>Oracle Communications Online Mediation Controller, version(s) 6.1<\/li>\n\t<li>Oracle Communications Service Broker Engineered System Edition, version(s) 6.0<\/li>\n\t<li>Oracle Communications Service Broker, version(s) 6.0, 6.1<\/li>\n\t<li>Oracle Configurator, version(s) 11.5.10.2, 12.1, 12.2<\/li>\n\t<li>Oracle Database Server, version(s) 11.2.0.4, 12.1.0.1, 12.1.0.2<\/li>\n\t<li>Oracle EBusiness Suite, version(s) 11.5.10.2, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.2, 12.2.3, 12.2.4, 12.2.5<\/li>\n\t<li>Oracle Endeca Server, version(s) 7.3.0.0, 7.4.0.0, 7.5.0.0, 7.6.0.0<\/li>\n\t<li>Oracle Fusion Applications, version(s) 11.1.2 through 11.1.10<\/li>\n\t<li>Oracle Fusion Middleware, version(s) 10.1.3.5, 11.1.1.7, 11.1.1.8, 11.1.1.9, 11.1.2.2, 11.1.2.3, 12.1.2.0, 12.1.3.0, 12.2.1<\/li>\n\t<li>Oracle GlassFish Server, version(s) 3.1.2<\/li>\n\t<li>Oracle GoldenGate, version(s) 11.2, 12.1.2<\/li>\n\t<li>Oracle Identity Federation, version(s) 11.1.1.7, 11.1.2.2<\/li>\n\t<li>Oracle iLearning, version(s) 6.0, 6.1<\/li>\n\t<li>Oracle Java SE Embedded, version(s) 8u65<\/li>\n\t<li>Oracle Java SE, version(s) 6u105, 7u91, 8u66<\/li>\n\t<li>Oracle JRockit, version(s) R28.3.8<\/li>\n\t<li>Oracle Outside In Technology, version(s) 8.5.0, 8.5.1, 8.5.2<\/li>\n\t<li>Oracle Retail Open Commerce Platform Cloud Service, version(s) 3.5, 4.5, 4.7, 5.0<\/li>\n\t<li>Oracle Retail Order Broker Cloud Service, version(s) 4.0, 4.1.<\/li>\n\t<li>Oracle Retail Order Management System Cloud Service, version(s) 3.5, 4.5, 4.7, 5.0, 15.0<\/li>\n\t<li>Oracle Retail PointofService, version(s) 13.4, 14.0, 14.1<\/li>\n\t<li>Oracle Secure Global Desktop, version(s) 4.63, 4.71, 5.2<\/li>\n\t<li>Oracle Switch ES124, version(s) prior to 1.3.1.13<\/li>\n\t<li>Oracle Tuxedo, version(s) 12.1.1.0<\/li>\n\t<li>Oracle VM VirtualBox, version(s) prior to 4.0.36, prior to 4.1.44, prior to 4.2.36, prior to 4.3.36, prior to 5.0.14<\/li>\n\t<li>Oracle Web Cache, version(s) 11.1.1.7.0, 11.1.1.9.0<\/li>\n\t<li>Oracle WebCenter Sites, version(s) 7.6.2, 11.1.1.8.0<\/li>\n\t<li>Oracle WebLogic Portal, version(s) 10.3.6<\/li>\n\t<li>Oracle WebLogic Server, version(s) 10.3.6, 12.1.2, 12.1.3, 12.2.1<\/li>\n\t<li>PeopleSoft Enterprise HCM Global Payroll Switzerland, version(s) 9.1, 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, version(s) 8.53, 8.54, 8.55<\/li>\n\t<li>PeopleSoft Enterprise SCM eProcurement, version(s) 9.1, 9.2<\/li>\n\t<li>PeopleSoft Enterprise SCM Order Management, version(s) 9.1, 9.2<\/li>\n\t<li>PeopleSoft Enterprise SCM Purchasing, version(s) 9.1, 9.2<\/li>\n\t<li>Solaris Cluster, version(s) 3.3, 4, 4.2<\/li>\n\t<li>Solaris, version(s) 10, 11<\/li>\n\t<li>Sun Blade 6000 Ethernet Switched NEM 24P 10GE, version(s) prior to 1.2.2.13<\/li>\n\t<li>Sun Network 10GE Switch 72p, version(s) prior to 1.2.2.15<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/cpujan2016-2367955.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/topics\/security\/cpujan2016-2367955.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-january-2016","alert_type":396,"serial_number":"AV16-011","subject":null,"moderation_state":"archived","external_url":null},{"nid":1042,"title":"Security fixes released for BIND","uuid":"3ed0ec1b-94ea-429e-8532-5f1c74bcf3df","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-20T17:23:05Z","summary":null,"body":["<article data-history-node-id=\"1042\" about=\"\/en\/alerts-advisories\/security-fixes-released-bind\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-012<br \/>\nDate: 20 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Internet Systems Consortium (ISC) has released security fixes to address multiple vulnerabilities in BIND. A remote attacker can exploit those vulnerabilities to potentially cause a denial-of-service condition.<\/p>\n\n<p>Versions affected: BIND 9.3.0-&gt;9.8.8, 9.9.0-&gt;9.9.8-P2, 9.9.3-S1-&gt;9.9.8-S3, 9.10.0-&gt;9.10.3-P2<\/p>\n\n<p>CVE References: CVE-2015-8704, CVE-2015-8705<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/kb.isc.org\/article\/AA-01335\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01335<\/font><\/a> \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/article\/AA-01336\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01336<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-released-bind","alert_type":396,"serial_number":"AV16-012","subject":null,"moderation_state":"archived","external_url":null},{"nid":1159,"title":"Google Releases security update for Chrome","uuid":"61830776-8bf5-4525-b9b4-eb8e0a9c7061","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-20T17:29:57Z","summary":null,"body":["<article data-history-node-id=\"1159\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-013<br \/>\nDate: 21 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 48.0.2564.82 for Windows, Mac and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2016-1612, CVE-2016-1613, CVE-2016-1614, CVE-2016-1615, CVE-2016-1616, CVE-2016-1617, CVE-2016-1618, CVE-2016-1619, CVE-2016-1620<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/01\/stable-channel-update_20.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/01\/stable-channel-update_20.html<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome","alert_type":396,"serial_number":"AV16-013","subject":null,"moderation_state":"archived","external_url":null},{"nid":1204,"title":"Magento security update and Patch","uuid":"f9954cd5-387f-4981-ab4e-641b4b0c2cf4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-20T17:37:19Z","summary":null,"body":["<article data-history-node-id=\"1204\" about=\"\/en\/alerts-advisories\/magento-security-update-and-patch\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-014<br \/>\nDate: 22 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a new release of Magento Community Edition and Enterprise Edition that includes multiple security patches.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Magento has released a patch and an update to address multiple vulnerabilities in several of its digital commerce software packages.<\/p>\n\n<p>A security update is available for Magento Community Edition (CE), Magento Enterprise Edition (EE), Magento 2 Community Edition (CE) and Magento 2 Enterprise Edition (EE). \u00a0A security patch is available for affected Magento CE and Magento EE for customers who do not wish to migrate to Magento 2.<\/p>\n\n<p>Affected Versions:<br \/>\nMagento Community Edition version 1.9.2.3 and prior versions<br \/>\nMagento Enterprise Edition version 1.14.2.3 and prior versions<br \/>\nMagento 2 Community Edition version 2.0.1 and prior versions<br \/>\nMagento 2 Enterprise Edition version 2.0.1 and prior versions<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Security Update: <a href=\"https:\/\/magento.com\/security\/patches\/magento-201-security-update\"><font color=\"#0066cc\">https:\/\/magento.com\/security\/patches\/magento-201-security-update<\/font><\/a><br \/>\nSecurity Patch: <a href=\"https:\/\/magento.com\/security\/patches\/supee-7405\"><font color=\"#0066cc\">https:\/\/magento.com\/security\/patches\/supee-7405<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/magento-security-update-and-patch","alert_type":null,"serial_number":"AV16-014","subject":null,"moderation_state":"archived","external_url":null},{"nid":1313,"title":"Multiple Vulnerabilities in Mozilla Firefox","uuid":"edcae694-d08d-4933-aaab-4005ecc42922","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-20T17:45:23Z","summary":null,"body":["<article data-history-node-id=\"1313\" about=\"\/en\/alerts-advisories\/multiple-vulnerabilities-mozilla-firefox\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-015<br \/>\nDate: 26 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of critical vulnerabilities in Mozilla Firefox and Firefox ESR for which upgrades are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>On 26 January 2016, Mozilla released security updates to address multiple vulnerabilities in Firefox. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox prior to version 44<br \/>\nFirefox ESR prior to 38.6<\/p>\n\n<p>CVE References: CVE-2016-1948, CVE-2016-1947, CVE-2016-1946, CVE-2016-1945, CVE-2016-1944, CVE-2016-1943, CVE-2016-1942, CVE-2016-1941, CVE-2016-1940, CVE-2016-1939, CE15-7208, CVE-2016-1935, CVE-2016-1933, CVE-2016-1931, CVE-2016-1930.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that systems administrators identify affected products in their environment and follow their patch management process accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-01\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-01\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-02\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-02\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-03\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-03\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-04\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-04\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-05\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-05\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-06\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-06\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-08\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-08\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-09\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-09\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-10\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-10\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-11\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-11\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-12\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-12\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-vulnerabilities-mozilla-firefox","alert_type":396,"serial_number":"AV16-015","subject":null,"moderation_state":"archived","external_url":null},{"nid":904,"title":"Cisco Management Authentication Bypass Vulnerability","uuid":"26b56789-948c-44b4-a39d-8c6c4bd45845","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-06-20T17:53:54Z","summary":null,"body":["<article data-history-node-id=\"904\" about=\"\/en\/alerts-advisories\/cisco-management-authentication-bypass-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-016<br \/>\nDate: 27 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to recent critical software updates that address a disclosed vulnerability in Cisco RV220W product.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in Cisco RV220W product.<\/p>\n\n<p>Cisco RV220W Wireless Security Firewall devices could allow an unauthenticated remote attacker to bypass authentication and gain administrative privileges on a targeted device. This vulnerability could be exploited by sending a crafted HTTP request containing malicious SQL statement to the management interface of the targeted device.<\/p>\n\n<p>Affected Product Versions:<br \/>\nCisco RV220W running firmware releases prior to 1.0.7.2<\/p>\n\n<p>NON Affected Product Versions:<br \/>\nCisco RV120W Wireless-N VPN Firewall<br \/>\nCisco RV180 VPN-Router<br \/>\nCisco RV180W Wireless-N Multifunction VPN Router<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>Due to the elevated risk presented by this vulnerability, CCIRC recommends that system administrators test and deploy the vendor-released firmware update to affected versions accordingly. CCIRC recommends that priority is given to these patches.<\/p>\n\n<h2>References<\/h2>\n\n<p>Cisco RV220W Management Authentication Bypass Vulnerability<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160127-rv220\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160127-rv220<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-management-authentication-bypass-vulnerability","alert_type":null,"serial_number":"AV16-016","subject":null,"moderation_state":"archived","external_url":null},{"nid":854,"title":"OpenSSL Advisory \u2013 Multiple Vulnerabilities","uuid":"3c84d0b5-86c5-4c60-836d-4d7f6b68670e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-20T18:24:10Z","summary":null,"body":["<article data-history-node-id=\"854\" about=\"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-017<br \/>\nDate: 28 January 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security advisories released by OpenSSL.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of five disclosed vulnerabilities in OpenSSL.<\/p>\n\n<p>Affected versions: OpenSSL 1.0.2f and prior<\/p>\n\n<p>CVE References: CVE-2016-0701, CVE-2015-3197<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p>OpenSSL 1.0.2f for 1.0.2 users<br \/>\nOpenSSL 1.0.1r for 1.0.1 users<\/p>\n\n<p>References:<\/p>\n\n<p>OpenSSL Advisory: <a href=\"https:\/\/mta.openssl.org\/pipermail\/openssl-announce\/2016-January\/000061.html\"><font color=\"#0066cc\">https:\/\/mta.openssl.org\/pipermail\/openssl-announce\/2016-January\/000061.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities","alert_type":396,"serial_number":"AV16-017","subject":null,"moderation_state":"archived","external_url":null},{"nid":1114,"title":"Rockwell Automation MicroLogix 1100 PLC Overflow Vulnerability","uuid":"7883b3be-9352-4f8b-a143-5f16e340eccd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-20T18:34:12Z","summary":null,"body":["<article data-history-node-id=\"1114\" about=\"\/en\/alerts-advisories\/rockwell-automation-micrologix-1100-plc-overflow-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-018<br \/>\nDate: 27 January 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a stack-based buffer overflow vulnerability in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable logic controller (PLC) systems.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation has released a new firmware version to address the stack-based buffer overflow vulnerability in Rockwell Automation Allen-Bradley MicroLogix 1100 PLC systems.<\/p>\n\n<p>Affected products:<br \/>\n-1763-L16AWA, Series B, Version 15.000 and prior versions<br \/>\n-1763-L16BBB, Series B, Version 15.000 and prior versions<br \/>\n-1763-L16BWA, Series B, Version 15.000 and prior versions<br \/>\n-1763-L16DWD, Series B, Version 15.000 and prior versions<br \/>\n-1763-L16AWA, Series A, Version 15.000 and prior versions<br \/>\n-1763-L16BBB, Series A, Version 15.000 and prior versions<br \/>\n-1763-L16BWA, Series A, Version 15.000 and prior versions<br \/>\n-1763-L16DWD, Series A, Version 15.000 and prior versions<\/p>\n\n<p>Successful exploitation of the stack-based buffer overflow vulnerability may allow an attacker to remotely execute arbitrary code on the affected device.<\/p>\n\n<p>CVE References: CVE-2016-0868<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test, assess impact and deploy the vendor-released updates to affected products at your earliest convenience.<\/p>\n\n<p>Rockwell Automation's new firmware version for the MicroLogix 1100 controller, hardware Series B, firmware Version 15.002, is available at the following URL:<\/p>\n\n<p><a href=\"http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?famID=30\"><font color=\"#0066cc\">http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?famID=30<\/font><\/a><\/p>\n\n<p>Rockwell Automation's security notification is available at the following URL, with a valid account:<\/p>\n\n<p><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/765050\"><font color=\"#0066cc\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/765050<\/font><\/a><\/p>\n\n<p>Rockwell Automation recommends evaluating the impact of the identified vulnerability within the host environment, and applying the following suggested mitigations, which are applicable.<br \/>\n-Update supported products with appropriate firmware updates.<br \/>\n-Disable the web server on the MicroLogix 1100, as it is enabled by default. See the knowledgebase article, KB: 732398, for detailed instructions on disabling the web server for each controller platform. The KB: 732398 is available at the following URL, with a valid account:<\/p>\n\n<p><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/732398\"><font color=\"#0066cc\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/732398<\/font><\/a><\/p>\n\n<p>-Set the key switch to RUN to prohibit re-enabling of the web server via RSLogix 500.<br \/>\n-Rockwell Automation recommends subscribing to the Security Advisory Index (KB54102), which provides the most up-to-date information about security matters that affect Rockwell Automation products. The Knowledgebase article is available at the following URL, with a valid account:<\/p>\n\n<p><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/54102\"><font color=\"#0066cc\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/54102<\/font><\/a><\/p>\n\n<h2>References<\/h2>\n\n<p>ICS-CERT Advisory (ICSA-16-026-02)<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-026-02\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-026-02<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rockwell-automation-micrologix-1100-plc-overflow-vulnerability","alert_type":396,"serial_number":"AV16-018","subject":null,"moderation_state":"archived","external_url":null},{"nid":1177,"title":"WordPress Security Release","uuid":"39ca736b-2412-40c7-b3cc-4eea5940271a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-20T18:44:08Z","summary":null,"body":["<article data-history-node-id=\"1177\" about=\"\/en\/alerts-advisories\/wordpress-security-release-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-019<br \/>\nDate: 02 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a WordPress 4.4.2 Security Release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress versions previous to 4.4.1 are affected by two security issues: a possible cross-site scripting (XSS) vulnerability and an open redirect attack.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2016\/02\/wordpress-4-4-2-security-and-maintenance-release\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2016\/02\/wordpress-4-4-2-security-and-maintenance-release<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-release-0","alert_type":396,"serial_number":"AV16-019","subject":null,"moderation_state":"archived","external_url":null},{"nid":771,"title":"Android security bulletin \u2013 February 2016","uuid":"9e0adda5-6720-4a49-932d-64693fe2ccbc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-20T18:52:31Z","summary":null,"body":["<article data-history-node-id=\"771\" about=\"\/en\/alerts-advisories\/android-security-bulletin-february-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-020<br \/>\nDate: 3 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for February.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses a security update for 10 vulnerabilities (5 Critical, 4 High, and 1 Moderate) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2016-0801, CVE-2016-0802, CVE-2016-0803, CVE-2016-0804, CVE-2016-0805, CVE-2016-0806, CVE-2016-0807, CVE-2016-0808, CVE-2016-0809, CVE-2016-0810, CVE-2016-0811, CVE-2016-0812, CVE-2016-0813<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Nexus Security Bulletin: <a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-02-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-02-01.html<\/font><\/a> \u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-february-2016","alert_type":396,"serial_number":"AV16-020","subject":null,"moderation_state":"archived","external_url":null},{"nid":1271,"title":"Graphite (Libgraphite) Vulnerabilities","uuid":"5113c530-8174-46fd-86da-ba605940a1d6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:29Z","date_created":"2018-06-20T19:01:58Z","summary":null,"body":["<article data-history-node-id=\"1271\" about=\"\/en\/alerts-advisories\/graphite-libgraphite-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-021<br \/>\nDate: 8 February 2015<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple vulnerabilities in the Graphite (Libgraphite) library.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of four critical vulnerabilities in the Graphite library which could allow a remote attacker to execute arbitrary code. Graphite is a font processing library leveraged by several popular Linux applications (including Mozilla Firefox, LibreOffice and OpenOffice).<\/p>\n\n<p>Affected versions: Graphite 2 - 1.3.4 and prior<\/p>\n\n<p>CVE References: CVE-2016-1521, CVE-2016-1522, CVE-2016-1523, CVE-2016-1526<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators with environments using software that leverage the Graphite 2 library to check with software developers for patch availability. Vendor-released updates should be tested and deployed to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Cisco Talos Report<br \/><a href=\"http:\/\/blog.talosintel.com\/2016\/02\/vulnerability-spotlight-libgraphite.html\"><font color=\"#0066cc\">http:\/\/blog.talosintel.com\/2016\/02\/vulnerability-spotlight-libgraphite.html<\/font><\/a>\u00a0<\/p>\n\n<p>Graphite Github Repository<br \/><a href=\"https:\/\/github.com\/silnrsi\/graphite\"><font color=\"#0066cc\">https:\/\/github.com\/silnrsi\/graphite<\/font><\/a><\/p>\n\n<p>Applications supporting Graphite (developer page)<br \/><a href=\"http:\/\/scripts.sil.org\/cms\/scripts\/page.php?site_id=projects&amp;item_id=graphite_apps\"><font color=\"#0066cc\">http:\/\/scripts.sil.org\/cms\/scripts\/page.php?site_id=projects&amp;item_id=graphite_apps<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/graphite-libgraphite-vulnerabilities","alert_type":396,"serial_number":"AV16-021","subject":null,"moderation_state":"archived","external_url":null},{"nid":1099,"title":"security update for Oracle Java SE","uuid":"4394fa48-b096-419c-b1fe-14f45a267214","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-20T19:09:22Z","summary":null,"body":["<article data-history-node-id=\"1099\" about=\"\/en\/alerts-advisories\/security-update-oracle-java-se\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-022<br \/>\nDate: 9 February 2015<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent Oracle Java SE security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a critical vulnerability in Oracle Java SE which could allow a remote attacker to execute arbitrary code without authentication.<\/p>\n\n<p>Affected versions: Java SE prior to 6u113, 7u97 or 8u73<\/p>\n\n<p>CVE Reference: CVE-2016-0603<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/alert-cve-2016-0603-2874360.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/topics\/security\/alert-cve-2016-0603-2874360.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-oracle-java-se","alert_type":396,"serial_number":"AV16-022","subject":null,"moderation_state":"archived","external_url":null},{"nid":1348,"title":"security update for Adobe Flash Player","uuid":"12de2a59-7086-4b34-9cce-4d07eec34ba3","banner":null,"lang":"en","date_modified":"2018-09-30","date_modified_ts":"2018-09-30T16:46:11Z","date_created":"2018-06-20T19:18:08Z","summary":null,"body":["<article data-history-node-id=\"1348\" about=\"\/en\/alerts-advisories\/security-update-adobe-flash-player\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-023<br \/>\nDate: 9 February 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security update for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-04 to address critical vulnerabilities that could allow an attacker to take control of the affected system.\u00a0<\/p>\n\n<p>Affected software versions:<\/p>\n\n<p>- Adobe Flash Player Desktop Runtime 20.0.0.286 and earlier versions for Windows and Macintosh<br \/>\n- Adobe Flash Player Extended Support Release 18.0.0.326 and earlier for Windows and Macintosh<br \/>\n- Adobe Flash Player for Google Chrome 20.0.0.286 and earlier versions for Windows, Macintosh, Linux and ChromeOS<br \/>\n- Adobe Flash Player for Microsoft Edge and Internet Explorer 11 20.0.0.272 and earlier versions for Windows 10<br \/>\n- Adobe Flash Player for Internet Explorer 11 and 20.0.0.272 and earlier versions for Windows 8.1<br \/>\n- Adobe Flash Player for Linux 11.2.202.559 and earlier versions for Linux<br \/>\n- AIR Desktop Runtime 20.0.0.233 and earlier versions for Windows and Macintosh<br \/>\n- AIR SDK 20.0.0.233 and earlier versions for Windows, Macintosh, Android and iOS<br \/>\n- AIR SDK &amp; Compiler 20.0.0.233 and earlier versions for Windows, Macintosh, Android and iOS<\/p>\n\n<p>CVE References: CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0971, CVE-2016-0972, CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, CVE-2016-0981, CVE-2016-0982, CVE-2016-0983, CVE-2016-0984, CVE-2016-0985<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-04.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-04.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-adobe-flash-player","alert_type":396,"serial_number":"AV16-023","subject":null,"moderation_state":"archived","external_url":null},{"nid":1191,"title":"Microsoft Critical security bulletins Summary for February 2016","uuid":"1eb6f08b-bcb1-4200-9c8e-f1993bd3f756","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-20T19:25:31Z","summary":null,"body":["<article data-history-node-id=\"1191\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-february-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-024<br \/>\nDate: 9 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for February 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 13 bulletins (6 Critical and 7 Important), which addresses multiple vulnerabilities in Internet Explorer, Microsoft Edge, Microsoft Office Services and Web Apps, Microsoft Office, Microsoft Windows, Microsoft Server, Microsoft Windows , Adobe Flash Player and Microsoft .NET Framework.<\/p>\n\n<p>***Critical***<br \/>\nMS16-009 Cumulative Security Update for Internet Explorer (3134220)<br \/>\nMS16-011 Cumulative Security Update for Microsoft Edge (3134225)<strong>\u00a0<\/strong><br \/>\nMS16-012 Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3138938)<br \/>\nMS16-013 Security Update for Windows Journal to Address Remote Code Execution (3134811)<br \/>\nMS16-015 Security Update for Microsoft Office to Address Remote Code Execution (3134226)\u00a0<br \/>\nMS16-022 Security Update for Adobe Flash Player (3135782)<\/p>\n\n<p>***Important***<br \/>\nMS16-014 Security Update for Microsoft Windows to Address Remote Code Execution (3134228)\u00a0<br \/>\nMS16-016 Security Update for WebDAV to Address Elevation of Privilege (3136041)<br \/>\nMS16-017 Security Update for Remote Desktop Display Driver to Address Elevation of Privilege (3134700)\u00a0<br \/>\nMS16-018 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3136082)\u00a0<br \/>\nMS16-019 Security Update for .NET Framework to Address Denial of Service (3137893)<strong>\u00a0<\/strong><br \/>\nMS16-020 Security Update for Active Directory Federation Services to Address Denial of Service (3134222)<br \/>\nMS16-021 Security Update for NPS RADIUS Server to Address Denial of Service\u00a0(3133043)\u00a0<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-feb.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-feb.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-february-2016","alert_type":396,"serial_number":"AV16-024","subject":null,"moderation_state":"archived","external_url":null},{"nid":812,"title":"Vulnerabilities in ASP.NET Templates","uuid":"e8e1fc4b-8c4d-4403-9ae0-d36bc7ffdb88","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-20T19:34:48Z","summary":null,"body":["<article data-history-node-id=\"812\" about=\"\/en\/alerts-advisories\/vulnerabilities-aspnet-templates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-025<br \/>\nDate: 9 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple vulnerabilities in ASP.NET templates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Microsoft has released an update to address the vulnerabilities in the public version of Visual Studio 2013, Visual Studio 2015, and ASP.NET project templates for MVC5 and MVC6. The update addresses vulnerabilities which could potentially allow an attacker to perform cross-site request forgery (CSRF) against web applications built using the affected ASP.NET project templates.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Microsoft Advisory\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/3137909.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/3137909.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-aspnet-templates","alert_type":396,"serial_number":"AV16-025","subject":null,"moderation_state":"archived","external_url":null},{"nid":886,"title":"Google Releases security update for Chrome","uuid":"bdc30cbd-0253-4337-b28a-59f4dea985ee","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-20T19:42:32Z","summary":null,"body":["<article data-history-node-id=\"886\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-026<br \/>\nDate:9 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 48.0.2564.109 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference: CVE-2016-1622, CVE-2016-1623, CVE-2016-1624, CVE-2016-1625, CVE-2016-1626, CVE-2016-1627<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/02\/stable-channel-update_9.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/02\/stable-channel-update_9.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-0","alert_type":396,"serial_number":"AV16-026","subject":null,"moderation_state":"archived","external_url":null},{"nid":1078,"title":"SAP Security Notes - February 2016","uuid":"829f5a65-f8b5-49fa-9a61-7d219895bbb3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-20T19:52:21Z","summary":null,"body":["<article data-history-node-id=\"1078\" about=\"\/en\/alerts-advisories\/sap-security-notes-february-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-027<br \/>\nDate: 10 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published security notes by SAP.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>SAP has released a monthly critical patch update consisting of multiple security notes. These security notes include patches to address multiple vulnerabilities in several SAP products: HANA, Java Proxy Runtime, SAPSSOEXT, TREX, UDDI, Universal Worklist Configuration and xMII (Manufacturing Integration and Intelligence).<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released update to affected applications accordingly.<\/p>\n\n<p>References:<br \/><a href=\"http:\/\/scn.sap.com\/community\/security\/blog\/2016\/02\/10\/sap-security-notes-february-2016--review\"><font color=\"#0066cc\">http:\/\/scn.sap.com\/community\/security\/blog\/2016\/02\/10\/sap-security-notes-february-2016--review<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-notes-february-2016","alert_type":396,"serial_number":"AV16-027","subject":null,"moderation_state":"archived","external_url":null},{"nid":1044,"title":"Cisco ASA Software Vulnerability - UPDATE","uuid":"dd958361-d77b-4f68-8a7e-b9ab7b245142","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-21T13:12:25Z","summary":null,"body":["<article data-history-node-id=\"1044\" about=\"\/en\/alerts-advisories\/cisco-asa-software-vulnerability-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>Purpose<\/p>\n\n<p>CCIRC is releasing this Advisory UPDATE that contains additional information related to this vulnerability.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The detection signatures referenced below are provided to aid organizations in detecting and mitigating malicious exploitation of this vulnerability.<\/p>\n\n<p>IPS Sigs:<br \/>\nCisco IPS : 7169-0 , Snort Sig: 36903\u00a0<br \/>\nCisco IPS Signature is available in update S908<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the elevated risk presented by this vulnerability, CCIRC recommends that system administrators test and deploy the vendor-released firmware updates to affected versions accordingly. CCIRC recommends that priority is given to these patches.<\/p>\n\n<h2>References:<\/h2>\n\n<p>Cisco ASA Software IKEv1 and IKEv2 Vulnerability Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160210-asa-ike\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160210-asa-ike<\/font><\/a><\/p>\n\n<p>Exodus: Execute My Packet<br \/><a href=\"https:\/\/blog.exodusintel.com\/2016\/02\/10\/firewall-hacking\/\"><font color=\"#0066cc\">https:\/\/blog.exodusintel.com\/2016\/02\/10\/firewall-hacking\/<\/font><\/a><\/p>\n\n<h1>Cisco ASA Software Vulnerability<\/h1>\n\n<p><strong>Number: AV16-028<br \/>\nDate: 10 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recent critical software update that addresses a disclosed vulnerability in Cisco ASA IKEv1 and IKEv2.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in Cisco ASA software IKEv1 and IKEv2.<\/p>\n\n<p>This vulnerability could allow an unauthenticated remote attacker to execute code or cause a reload of the affected system. This is due to a buffer overflow that could be triggered in the current version of the software.<\/p>\n\n<p>Affected Product :<\/p>\n\n<ul><li>Cisco ASA 5500 Series Adaptive Security Appliances<\/li>\n\t<li>Cisco ASA 5500-X Series Next-Generation Firewalls<\/li>\n\t<li>Cisco ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers<\/li>\n\t<li>Cisco ASA 1000V Cloud Firewall<\/li>\n\t<li>Cisco Adaptive Security Virtual Applicate (ASAv)<\/li>\n\t<li>Cisco Firepower 9300 ASA Security Module<\/li>\n\t<li>Cisco ISA 3000 Industrial Security Appliance<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>Due to the elevated risk presented by this vulnerability, CCIRC recommends that system administrators test and deploy the vendor-released firmware updates to affected versions accordingly. CCIRC recommends that priority is given to these patches.<\/p>\n\n<p>References:<\/p>\n\n<p>Cisco ASA Software IKEv1 and IKEv2 Vulnerability Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160210-asa-ike\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160210-asa-ike<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-asa-software-vulnerability-update","alert_type":396,"serial_number":"AV16-028","subject":null,"moderation_state":"archived","external_url":null},{"nid":1161,"title":"Multiple Vulnerabilities in Mozilla Firefox","uuid":"8a09d74b-fc70-401b-bde4-d6801a587415","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-21T13:21:01Z","summary":null,"body":["<article data-history-node-id=\"1161\" about=\"\/en\/alerts-advisories\/multiple-vulnerabilities-mozilla-firefox-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-029<br \/>\nDate: 12 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of critical vulnerabilities in Mozilla Firefox and Firefox ESR for which upgrades are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>On 11 February 2016, Mozilla released security updates to address multiple vulnerabilities in Firefox. The severity of these issues is critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox prior to version 44.0.2<br \/>\nFirefox ESR prior to 38.6.1<\/p>\n\n<p>CVE References: CVE-2016-1948 and CVE-2016-1523.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that systems administrators identify affected products in their environment and follow their patch management process accordingly.<\/p>\n\n<p>References:<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-13\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-13\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-14\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-14\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-vulnerabilities-mozilla-firefox-0","alert_type":396,"serial_number":"AV16-029","subject":null,"moderation_state":"archived","external_url":null},{"nid":1206,"title":"VMware vCenter and ESXi \u2013 UPDATE","uuid":"ba2813ce-2cf7-4d52-a869-74f4c416f67d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-21T14:11:27Z","summary":null,"body":["<article data-history-node-id=\"1206\" about=\"\/en\/alerts-advisories\/vmware-vcenter-and-esxi-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-030<br \/>\nDate: 15 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released updates to address critical security issues for VMware vCenter Server and ESXi.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released security updates to address multiple security vulnerabilities in vCenter and ESXi. Exploitation of one of these vulnerabilities may allow a remote attacker to execute code remotely on an ESXi host, execute arbitrary code on a vCenter server or allow an unauthenticated attacker to create a denial-of-service condition in the vpxd service.<\/p>\n\n<p>Affected versions are:<\/p>\n\n<p>-VMware ESXi 5.5 without patch ESXi550-201509101-SG<br \/>\n-VMware ESXi 5.1 without patch ESXi510-201510101-SG<br \/>\n-VMware ESXi 5.0 without patch ESXi500-201510101-SG<\/p>\n\n<p>\u00a0-VMware vCenter Server 6.0 prior to version 6.0.0b<br \/>\n-VMware vCenter Server 5.5 prior to version 5.5 update 3<br \/>\n-VMware vCenter Server 5.1 prior to version 5.1 update u3b<br \/>\n-VMware vCenter Server 5.0 prior to version 5.0 update u3e<\/p>\n\n<p>CVE References: CVE-2015-5177, CVE-2015-2342, CVE-2015-1047<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p>VMWare: <a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2015-0007.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2015-0007.html<\/font><\/a><br \/>\nUS-CERT: <a href=\"https:\/\/www.us-cert.gov\/ncas\/current-activity\/2015\/10\/01\/VMware-Releases-Security-Advisory\"><font color=\"#0066cc\">https:\/\/www.us-cert.gov\/ncas\/current-activity\/2015\/10\/01\/VMware-Releases-Security-Advisory<\/font><\/a><br \/>\nCVE-2015-5177: <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-5177\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-5177<\/font><\/a><br \/>\nCVE-2015-2342: <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-2342\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-2342<\/font><\/a><br \/>\nCVE-2015-1047: <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-1047\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-1047<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-vcenter-and-esxi-update","alert_type":396,"serial_number":"AV16-030","subject":null,"moderation_state":"archived","external_url":null},{"nid":1315,"title":"glibc Library - Stack-Based Buffer Overflow Vulnerability","uuid":"a18084c6-2561-4f3a-bac5-a50930d77532","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-21T14:29:05Z","summary":null,"body":["<article data-history-node-id=\"1315\" about=\"\/en\/alerts-advisories\/glibc-library-stack-based-buffer-overflow-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-031<br \/>\nDate: 18 February 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a vulnerability discovered in the glibc library of code, a key component of most Linux distributions.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>GNU C Library (glibc) is a collection of open source code that powers standalone applications and most Linux distributions.<\/p>\n\n<p>The vulnerability in glibc relates to a stack-based buffer overflow in the glibc DNS client-side resolver that puts Linux machines at risk for remote code execution. The flaw is triggered when the getaddrinfo() library function, which is responsible for performing domain-name lookups, is used.<\/p>\n\n<p>Affected Software:\u00a0 All versions of glibc Version 2.9 to 2.22 are vulnerable.<\/p>\n\n<p>CVE Reference: CVE-2015-7547<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/457759\"><font color=\"#0066cc\">https:\/\/www.kb.cert.org\/vuls\/id\/457759<\/font><\/a><\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ncas\/current-activity\/2016\/02\/17\/GNU-glibc-Vulnerability\"><font color=\"#0066cc\">https:\/\/www.us-cert.gov\/ncas\/current-activity\/2016\/02\/17\/GNU-glibc-Vulnerability<\/font><\/a><\/p>\n\n<p><a href=\"https:\/\/rhn.redhat.com\/errata\/RHSA-2016-0175.html\"><font color=\"#0066cc\">https:\/\/rhn.redhat.com\/errata\/RHSA-2016-0175.html<\/font><\/a><\/p>\n\n<p><a href=\"https:\/\/sourceware.org\/ml\/libc-alpha\/2016-02\/msg00416.html\"><font color=\"#0066cc\">https:\/\/sourceware.org\/ml\/libc-alpha\/2016-02\/msg00416.html<\/font><\/a><\/p>\n\n<p><a href=\"http:\/\/arstechnica.com\/security\/2016\/02\/extremely-severe-bug-leaves-dizzying-number-of-apps-and-devices-vulnerable\/\"><font color=\"#0066cc\">http:\/\/arstechnica.com\/security\/2016\/02\/extremely-severe-bug-leaves-dizzying-number-of-apps-and-devices-vulnerable\/<\/font><\/a><\/p>\n\n<p><a href=\"http:\/\/www.zdnet.com\/article\/patch-linux-now-google-red-hat-warn-over-critical-glibc-bug\/\"><font color=\"#0066cc\">http:\/\/www.zdnet.com\/article\/patch-linux-now-google-red-hat-warn-over-critical-glibc-bug\/<\/font><\/a><\/p>\n\n<p><a href=\"https:\/\/threatpost.com\/critical-glibc-vulnerability-puts-all-linux-machines-at-risk\/116261\/\"><font color=\"#0066cc\">https:\/\/threatpost.com\/critical-glibc-vulnerability-puts-all-linux-machines-at-risk\/116261\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/glibc-library-stack-based-buffer-overflow-vulnerability","alert_type":396,"serial_number":"AV16-031","subject":null,"moderation_state":"archived","external_url":null},{"nid":901,"title":"Google Releases security update for Chrome","uuid":"f84fdb41-8f65-4db6-a239-7f4c1c4bdd9b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-06-21T14:47:33Z","summary":null,"body":["<article data-history-node-id=\"901\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-032<br \/>\nDate: 19 February 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 48.0.2564.116 for Windows, Mac and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2016-1629<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.com\/2016\/02\/stable-channel-update_18.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.com\/2016\/02\/stable-channel-update_18.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-1","alert_type":396,"serial_number":"AV16-032","subject":null,"moderation_state":"archived","external_url":null},{"nid":856,"title":"AMX Multiple Products Credential Management Vulnerabilities","uuid":"646f28d4-c205-4286-881f-5f2fa80811d0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-21T15:31:46Z","summary":null,"body":["<article data-history-node-id=\"856\" about=\"\/en\/alerts-advisories\/amx-multiple-products-credential-management-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-033<br \/>\nDate: 19 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>AMX has confirmed the existence of hard-coded passwords in multiple products. AMX has produced patches and new product versions to mitigate one of the vulnerabilities in the affected products.<\/p>\n\n<p>These vulnerabilities could be exploited remotely. Exploits that target these vulnerabilities are known to be publicly available.<br \/>\nCVE References: CVE-2015-8362, CVE-2016-1984<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-049-02\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-049-02<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/www.amx.com\/techcenter\/\"><font color=\"#0066cc\">http:\/\/www.amx.com\/techcenter<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amx-multiple-products-credential-management-vulnerabilities","alert_type":396,"serial_number":"AV16-033","subject":null,"moderation_state":"archived","external_url":null},{"nid":1115,"title":"Microsoft Releases update for EMET","uuid":"e14a4180-b8ac-4c18-aec3-a2b04d5521e8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-21T15:37:39Z","summary":null,"body":["<article data-history-node-id=\"1115\" about=\"\/en\/alerts-advisories\/microsoft-releases-update-emet\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-034<br \/>\nDate: 23 February 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent update to Microsoft EMET.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a vulnerability in the Microsoft Enhanced Mitigation Experience Toolkit (EMET) version prior to 5.5. Exploitation of this vulnerability may allow a remote attacker to bypass or disable EMET and take control of an affected system.<\/p>\n\n<p>EMET is a project that adds security mitigations to user mode programs beyond those built into the operating system. It runs inside \"protected\" programs as a Dynamic Link Library (DLL), and makes various changes in order to make exploitation more difficult.<\/p>\n\n<p>Affected Versions:<br \/>\nEMET prior to version 5.5<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Microsoft EMET<br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/security\/jj653751\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/security\/jj653751<\/font><\/a><\/p>\n\n<p>FireEye Research<br \/><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2016\/02\/using_emet_to_disabl.html\"><font color=\"#0066cc\">https:\/\/www.fireeye.com\/blog\/threat-research\/2016\/02\/using_emet_to_disabl.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-releases-update-emet","alert_type":396,"serial_number":"AV16-034","subject":null,"moderation_state":"archived","external_url":null},{"nid":1181,"title":"Drupal security updates","uuid":"b0e29af5-24e8-4fb2-ac07-1db3ab0a9e21","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-21T15:44:28Z","summary":null,"body":["<article data-history-node-id=\"1181\" about=\"\/en\/alerts-advisories\/drupal-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-035<br \/>\nDate: 25 February 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Drupal Security Release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple security vulnerabilities. Some of these vulnerabilities can allow a remote attacker to take control of an affected system.<\/p>\n\n<p>Affected Versions:<br \/>\nDrupal core 6.x versions prior to 6.38<br \/>\nDrupal core 7.x versions prior to 7.43<br \/>\nDrupal core 8.0.x versions prior to 8.0.4<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Drupal: <a href=\"https:\/\/www.drupal.org\/SA-CORE-2016-001\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/SA-CORE-2016-001<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-updates","alert_type":396,"serial_number":"AV16-035","subject":null,"moderation_state":"archived","external_url":null},{"nid":773,"title":"OpenSSL Advisory \u2013 Multiple Vulnerabilities","uuid":"0665e7fc-4a0f-49be-ae86-a5d77ae725ac","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-21T16:28:53Z","summary":null,"body":["<article data-history-node-id=\"773\" about=\"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-036<br \/>\nDate: 1 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security advisories released by OpenSSL.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of eight recently disclosed vulnerabilities in OpenSSL, two of which are rated as high.<\/p>\n\n<p>Affected versions: OpenSSL 0.9.8, 1.0.0, 1.0.1, 1.0.2<\/p>\n\n<p>CVE References: CVE-2015-0293, CVE-2015-3197, CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-0800<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates to affected platforms accordingly.<\/p>\n\n<p>OpenSSL 1.0.1 users should upgrade to 1.0.1s<br \/>\nOpenSSL 1.0.2 users should upgrade to 1.0.2g<\/p>\n\n<h2>References:<\/h2>\n\n<ul><li><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20160301.txt\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/news\/secadv\/20160301.txt<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/drownattack.com\/\"><font color=\"#0066cc\">http:\/\/drownattack.com<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/blog.cryptographyengineering.com\/2016\/03\/attack-of-week-drown.html\"><font color=\"#0066cc\">http:\/\/blog.cryptographyengineering.com\/2016\/03\/attack-of-week-drown.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-0","alert_type":396,"serial_number":"AV16-036","subject":null,"moderation_state":"archived","external_url":null},{"nid":1273,"title":"Cisco Multiple Security Advisories","uuid":"10dfd464-1f76-4dc4-aaf4-eb072dc1c677","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:29Z","date_created":"2018-06-21T16:37:28Z","summary":null,"body":["<article data-history-node-id=\"1273\" about=\"\/en\/alerts-advisories\/cisco-multiple-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-037<br \/>\nDate: 02 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address critical vulnerabilities in the following software\/hardware:\u00a0<\/p>\n\n<p><strong>Critical<\/strong><\/p>\n\n<ul><li>Insecure Default Credential Vulnerability in Cisco Nexus 3000 Series and 3500 Platform Switches.<\/li>\n<\/ul><p><strong>High<\/strong><\/p>\n\n<ul><li>Cisco Web Security Appliance HTTPS Packet Processing Denial of Service Vulnerability.<\/li>\n\t<li>Cisco NX-OS Software SNMP Packet Denial of Service Vulnerability.<\/li>\n\t<li>Cisco NX-OS Software TCP Netstack Denial of Service Vulnerability.<\/li>\n\t<li>Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products.<\/li>\n<\/ul><p><strong>Medium<\/strong><\/p>\n\n<ul><li>Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016.<\/li>\n\t<li>Cisco Unified Communications Domain Manager Cross-Site Scripting Vulnerability.<\/li>\n\t<li>Cisco FireSIGHT System Software Device Management UI Cross-Site Scripting Vulnerability.<\/li>\n\t<li>Cisco FireSIGHT System Software Convert Timing Channel Vulnerability.<\/li>\n<\/ul><p>CVE-2016-1288, CVE-2015-6260, CVE-2016-1329, CVE-2015-0718, CVE-2015-3197, CVE-2015-7973, CVE-2016-1354, CVE-2016-1355, CVE-2016-1356.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-multiple-security-advisories","alert_type":396,"serial_number":"AV16-037","subject":null,"moderation_state":"archived","external_url":null},{"nid":1101,"title":"Google Releases security update for Chrome","uuid":"de6f9467-6087-43cc-a723-f7edb5abe38f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-21T17:05:27Z","summary":null,"body":["<article data-history-node-id=\"1101\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-038<br \/>\nDate: 03 March 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 49.0.2623.75 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference:<br \/>\nCVE-2016-1630, CVE-2016-1631, CVE-2016-1632, CVE-2016-1633, CVE-2016-1634, CVE-2016-1635, CVE-2016-1636, CVE-2016-1637, CVE-2016-1638, CVE-2016-1639, CVE-2016-1640, CVE-2016-1641, CVE-2015-8126<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/03\/stable-channel-update.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/03\/stable-channel-update.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-2","alert_type":396,"serial_number":"AV16-038","subject":null,"moderation_state":"archived","external_url":null},{"nid":925,"title":"SSL\/TLS Vulnerability \u201cDROWN\u201d","uuid":"5aa6479f-e0a2-48f1-8f6f-67feabaede60","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-21T17:12:43Z","summary":null,"body":["<article data-history-node-id=\"925\" about=\"\/en\/alerts-advisories\/ssltls-vulnerability-drown\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-039<br \/>\nDate: 03 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an SSL\/TLS vulnerability, <strong>D<\/strong>ecrypting <strong>R<\/strong>SA with <strong>O<\/strong>bsolete and <strong>W<\/strong>eakened e<strong>N<\/strong>cryption, \u201cDROWN\u201d.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The DROWN vulnerability can be leveraged by attackers to decrypt SSL\/TLS connections between a client and server allowing SSLv2.\u00a0 Any type of server with SSLv2 enabled is vulnerable (including HTTPS, IMAP, POP and SMTP).\u00a0 A successful attacker would be capable of obtaining a single session key for a captured TLS handshake through brute-force decryption, which would allow the captured session to be decrypted (in a timeframe of hours using cloud computing services).<\/p>\n\n<p>In conjunction, a vulnerability in OpenSSL 1.0.2 and 1.0.11 (and earlier) would allow an attacker to reduce the brute-force decryption timeframe for a session key to minutes using commodity computer hardware.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly or consider applying the workarounds.<\/p>\n\n<p>It is recommended to use unique private keys when applicable for different servers and\/or services.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>DROWN Vulnerability (researcher website):<br \/><a href=\"https:\/\/drownattack.com\/\"><font color=\"#0066cc\">https:\/\/drownattack.com<\/font><\/a> \u00a0<\/li>\n\t<li>CCIRC AV16-036: OpenSSL Advisory \u2013 Multiple Vulnerabilities:<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/av16-036-en.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/av16-036-en.aspx<\/font><\/a><\/li>\n\t<li>NVD:<br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-0800\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-0800<\/font><\/a> \u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ssltls-vulnerability-drown","alert_type":396,"serial_number":"AV16-039","subject":null,"moderation_state":"archived","external_url":null},{"nid":1193,"title":"Vulnerabilities in Palo Alto PAN-OS","uuid":"2327e0b1-33cd-4f58-b175-79ae0deaee91","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-21T17:19:59Z","summary":null,"body":["<article data-history-node-id=\"1193\" about=\"\/en\/alerts-advisories\/vulnerabilities-palo-alto-pan-os\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-040<br \/>\nDate: 3 March 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple vulnerabilities in the Palo Alto PAN-OS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Palo Alto has released multiple security advisories to address a range of vulnerabilities in the following software\/hardware:<\/p>\n\n<p><strong>Critical<\/strong><br \/>\nUnauthenticated Buffer Overflow in GlobalProtect\/SSL VPN Web Interface.<br \/>\nAffected Versions: PAN-OS releases 5.0.17 and prior, 6.0.12 and prior, 6.1.9 and prior, 7.0.4 and prior.<\/p>\n\n<p><strong>High<\/strong><br \/>\nUnauthenticated Command Injection in Management Web Interface.<br \/>\nAffected Versions: PAN-OS releases 5.0.17 and prior, 6.0.12 and prior, 6.1.9 and prior, 7.0.4 and prior.<\/p>\n\n<p><strong>Medium<\/strong><br \/>\nUnauthenticated Stack Exhaustion in GlobalProtect\/SSL VPN Web Interface.<br \/>\nAffected Versions: \u00a0PAN-OS releases 5.0.17 and prior, 6.0.12 and prior, 6.1.9 and prior, 7.0.5 and prior.<\/p>\n\n<p>ESM Console XSS vulnerability (CVE-2015-2223).<br \/>\nAffected Versions: \u00a0Traps ESM Console version 3.2.1 and earlier.<\/p>\n\n<p><strong>Low<\/strong><br \/>\nCommand Injection in Command Line Interface<br \/>\nAffected Versions:\u00a0 PAN-OS releases 5.0.17 and prior, 5.1.10 and prior, 6.0.12 and prior, 6.1.9 and prior, 7.0.5 and prior.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/?AspxAutoDetectCookieSupport=1\"><font color=\"#0066cc\">https:\/\/securityadvisories.paloaltonetworks.com\/?AspxAutoDetectCookieSupport=1<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-palo-alto-pan-os","alert_type":396,"serial_number":"AV16-040 ","subject":null,"moderation_state":"archived","external_url":null},{"nid":804,"title":"Android security bulletin \u2013 March 2016","uuid":"dbddc0cc-3ed3-40fe-afcd-f3a6ff376367","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-21T17:30:16Z","summary":null,"body":["<article data-history-node-id=\"804\" about=\"\/en\/alerts-advisories\/android-security-bulletin-march-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-041<br \/>\nDate: 7 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for March.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulleting addresses a security update for 16 vulnerabilities (6 Critical, 8 High, and 2 Moderate) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2016-0728, CVE-2016-0815, CVE-2016-0816, CVE-2016-0818, CVE-2016-0819, CVE-2016-0820, CVE-2016-0821, CVE-2016-0822, CVE-2016-0823, CVE-2016-0824, CVE-2016-0825, CVE-2016-0826, CVE-2016-0827, CVE-2016-0828, CVE-2016-0829, CVE-2016-0830, CVE-2016-0831, CVE-2016-0832, CVE-2016-1621<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Android web site: <a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-03-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-03-01.html<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-march-2016","alert_type":396,"serial_number":"AV16-041","subject":null,"moderation_state":"archived","external_url":null},{"nid":888,"title":"Adobe security bulletin Summary for March 2016","uuid":"4d2d6a8d-9e24-493c-8a57-186e0d63c8dd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-21T17:43:21Z","summary":null,"body":["<article data-history-node-id=\"888\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-summary-march-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-042<br \/>\nDate: 8 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Adobe Security Bulletin Summary for March.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletin:<\/p>\n\n<p>APSB16-09 \u2013 Security updates available for Adobe Acrobat and Reader<\/p>\n\n<p>Details: Theses updates address critical vulnerabilities that could potentially allow an attacker to take control of the affected system.<\/p>\n\n<p>Affected Products:<\/p>\n\n<p>Adobe Acrobat DC 15.010.20059 and earlier versions, Adobe Acrobat Reader DC 15.010.20059 and earlier version, Adobe Acrobat DC 15.006.30119 and earlier versions, Adobe Acrobat Reader DC 15.006.30119 and earlier versions, Adobe Acrobat XI 11.0.14 and earlier versions, Adobe Reader XI 11.0.14 and earlier versions.<\/p>\n\n<p>CVE References: CVE-2016-1007, CVE-2016-1008, CVE-2016-1009,<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Adobe Security Bulletin: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-09.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-09.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-summary-march-2016","alert_type":396,"serial_number":"AV16-042","subject":null,"moderation_state":"archived","external_url":null},{"nid":841,"title":"Microsoft Critical security bulletins Summary for March 2016","uuid":"defa6a05-b928-4881-b601-0fc7fd21ac72","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:07Z","date_created":"2018-06-21T17:57:53Z","summary":null,"body":["<article data-history-node-id=\"841\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-march-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-043<br \/>\nDate: 8 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for March 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 13 bulletins (5 Critical and 8 Important), which addresses multiple vulnerabilities in Microsoft .NET Framework, Microsoft Internet Explorer, Microsoft Edge, Microsoft Office, Microsoft Windows PDF Library, Windows USB Mass Storage Class Driver, Windows Kernel-Mode Drivers, Secondary Logon, and Windows Media.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS16-023 Cumulative Security Update for Internet Explorer (3142015)<\/li>\n\t<li>MS16-024 Cumulative Security Update for Microsoft Edge (3142019)<\/li>\n\t<li>MS16-026 Security Update for Graphic Fonts to Address Remote Code Execution (3143148)<\/li>\n\t<li>MS16-027 Security Update for Windows Media to Address Remote Code Execution (3143146)<\/li>\n\t<li>MS16-028 Security Update for Microsoft Windows PDF Library to Address Remote Code Execution (3143081)<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS16-025 Security Update for Windows Library Loading to Address Remote Code Execution (3140709)<\/li>\n\t<li>MS16-029 Security Update for Microsoft Office to Address Remote Code Execution (3141806)<\/li>\n\t<li>MS16-030 Security Update for Windows OLE to Address Remote Code Execution (3143136)<\/li>\n\t<li>MS16-031 Security Update for Microsoft Windows to Address Elevation of Privilege (3140410)<\/li>\n\t<li>MS16-032 Security Update for Secondary Logon to Address Elevation of Privilege (3143141)<\/li>\n\t<li>MS16-033 Security Update for Windows USB Mass Storage Class Driver to Address Elevation of Privilege (3143142)<\/li>\n\t<li>MS16-034 Security Update for Windows Kernel-Mode Drivers to Address Elevation of Privilege (3143145)<\/li>\n\t<li>MS16-035 Security Update for .NET Framework to Address Security Feature Bypass (3141780)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-mar.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-mar.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-march-2016","alert_type":396,"serial_number":"AV16-043","subject":null,"moderation_state":"archived","external_url":null},{"nid":1036,"title":"Google Releases security update for Chrome","uuid":"78681e4d-4de5-4f27-8343-251b9e2e9048","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-21T18:06:10Z","summary":null,"body":["<article data-history-node-id=\"1036\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-044<br \/>\nDate: 09 March 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 49.0.2623.87 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference: CVE-2016-1643, CVE-2016-1644, CVE-2016-1645<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/03\/stable-channel-update_8.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/03\/stable-channel-update_8.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-3","alert_type":396,"serial_number":"AV16-044","subject":null,"moderation_state":"archived","external_url":null},{"nid":1154,"title":"Mozilla Releases security updates","uuid":"c8c505f6-ded5-45e1-abf0-d18785e370fb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-21T18:13:12Z","summary":null,"body":["<article data-history-node-id=\"1154\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-045<br \/>\nDate: 09 March 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which upgrades are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address multiple vulnerabilities in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 45.0<br \/>\nESR versions prior to 38.7<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/#firefox45\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/#firefox45<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates","alert_type":396,"serial_number":"AV16-045","subject":null,"moderation_state":"archived","external_url":null},{"nid":1208,"title":"Cisco Multiple Security Advisories","uuid":"ecbd316f-81f9-4164-9da1-197078b4775a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-21T18:19:57Z","summary":null,"body":["<article data-history-node-id=\"1208\" about=\"\/en\/alerts-advisories\/cisco-multiple-security-advisories-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-046<br \/>\nDate: 9 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address critical vulnerabilities in the following software:<\/p>\n\n<p><strong>High<\/strong><\/p>\n\n<ul><li>Cisco Cable Modem with Digital Voice Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco Wireless Residential Gateway Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Wireless Residential Gateway with EDVA Denial of Service Vulnerability<\/li>\n\t<li>Cisco ASA Content Security and Control Security Services Module Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2016-1312, CVE-2016-1326, CVE-2016-1325, CVE-2016-1327<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-cmre\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-cmre<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-rgid\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-rgid<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-cmdos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-cmdos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-csc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160309-csc<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-multiple-security-advisories-0","alert_type":396,"serial_number":"AV16-046","subject":null,"moderation_state":"archived","external_url":null},{"nid":1316,"title":"Security fixes released for BIND","uuid":"a67bd7ad-b9a0-4047-ae9f-5048afe73788","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-21T18:34:08Z","summary":null,"body":["<article data-history-node-id=\"1316\" about=\"\/en\/alerts-advisories\/security-fixes-released-bind-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-047<br \/>\nDate: 10 March 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released updates that address three vulnerabilities in BIND. Exploitation of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.<\/p>\n\n<p>Versions affected: BIND 9.0.0 -&gt; 9.8.8, 9.9.0 -&gt; 9.9.8-P3, 9.9.3-S1 -&gt; 9.9.8-S5, 9.10.0 -&gt; 9.10.3-P3.<\/p>\n\n<p>CVE References: CVE-2016-1285, CVE-2016-1286, CVE-2016-2088<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01351\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01351<\/font><\/a><br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01352\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01352<\/font><\/a><br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01353\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01353<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-released-bind-0","alert_type":396,"serial_number":"AV16-047","subject":null,"moderation_state":"archived","external_url":null},{"nid":906,"title":"Citrix security updates","uuid":"e1ccf28e-9645-40a3-91b2-4f53e41ec952","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-21T18:41:49Z","summary":null,"body":["<article data-history-node-id=\"906\" about=\"\/en\/alerts-advisories\/citrix-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-048<br \/>\nDate: 11 March 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of the advisory is to bring attention to the recently released security updates for Citrix.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Citrix Licensing has released security updates to address CVE-2015-8277 that could allow a remote, unauthenticated attacker to crash the License Server and potentially execute arbitrary code on the server.<\/p>\n\n<p>Affected Version:<\/p>\n\n<ul><li>Citrix License Server 11.13.12 and earlier for Windows<\/li>\n\t<li>Citrix License Server VPX 11.13.12 and earlier<\/li>\n<\/ul><p>CVE Reference: CVE-2015-8277<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/support.citrix.com\/article\/CTX207824\"><font color=\"#0066cc\">http:\/\/support.citrix.com\/article\/CTX207824<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-updates","alert_type":396,"serial_number":"AV16-048","subject":null,"moderation_state":"archived","external_url":null},{"nid":858,"title":"security updates for Adobe Flash Player","uuid":"f92c9925-1316-4ad0-ae8a-313065597e43","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-21T18:50:19Z","summary":null,"body":["<article data-history-node-id=\"858\" about=\"\/en\/alerts-advisories\/security-updates-adobe-flash-player\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-049<br \/>\nDate: 11 March 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-08 to address critical vulnerabilities that could allow an attacker to take control of the affected system.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime 20.0.0.306 and earlier for Windows and Macintosh<\/li>\n\t<li>Adobe Flash Player Extended Support Release 18.0.0.329 and earlier for Windows and Macintosh<\/li>\n\t<li>Adobe Flash Player for Google Chrome 20.0.0.306 and earlier for Windows, Macintosh, Linux, and ChromeOS<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 20.0.0.306 and earlier for Windows 10<\/li>\n\t<li>Adobe Flash Player for Internet Explorer 11 20.0.0.306 and earlier for Windows 8.1<\/li>\n\t<li>Adobe Flash Player for Linux 11.2.202.569 and earlier for Linux<\/li>\n\t<li>AIR Desktop Runtime 20.0.0.260 and earlier for Windows and Macintosh<\/li>\n\t<li>AIR SDK 20.0.0.260 and earlier for Windows, Macintosh, Android, and iOS<\/li>\n\t<li>AIR SDK &amp; Compiler 20.0.0.260 and earlier for Windows, Macintosh, Android, and iOS<\/li>\n\t<li>AIR for Android 20.0.0.233 and earlier for Android<\/li>\n<\/ul><p>CVE References: CVE-2016-0960, CVE-2016-0961, CVE-2016-0962, CVE-2016-0963, CVE-2016-0986, CVE-2016-0987, CVE-2016-0988, CVE-2016-0989, CVE-2016-0990, CVE-2016-0991, CVE-2016-0992, CVE-2016-0993, CVE-2016-0994, CVE-2016-0995, CVE-2016-0996, CVE-2016-0997, CVE-2016-0998, CVE-2016-0999, CVE-2016-1000, CVE-2016-1001, CVE-2016-1002, CVE-2016-1005, CVE-2016-1010<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-08.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-08.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-adobe-flash-player","alert_type":null,"serial_number":"AV16-049","subject":null,"moderation_state":"archived","external_url":null},{"nid":1116,"title":"VMware Security Advisories","uuid":"7adbc2b1-3991-47f8-a3d6-e3b35b58844a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-21T18:58:54Z","summary":null,"body":["<article data-history-node-id=\"1116\" about=\"\/en\/alerts-advisories\/vmware-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-050<br \/>\nDate: 17 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware released security updates to address vulnerabilities in the following software\/hardware:<\/p>\n\n<ul><li>VMware vRealize Automation and vRealize Business Advanced and Enterprise address Cross-Site Scripting (XSS) issues.<\/li>\n<\/ul><p>Affected Versions:<br \/>\nVMware vRealize Automation 6.x prior to 6.2.4, VMware vRealize Business Advanced and Enterprise 8.x prior to 8.2.5<\/p>\n\n<p>CVE Reference: CVE-2015-2344, CVE-2016-2075<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0003.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0003.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisories","alert_type":null,"serial_number":"AV16-050","subject":null,"moderation_state":"archived","external_url":null},{"nid":1183,"title":"Symantec Releases security update","uuid":"915ca31d-9f15-4a8e-ba1f-1a4d56dc5cf6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-21T19:07:10Z","summary":null,"body":["<article data-history-node-id=\"1183\" about=\"\/en\/alerts-advisories\/symantec-releases-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-051<br \/>\nDate: 18 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Symantec Endpoint Protection.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Symantec has released a Security Advisory to address critical vulnerabilities that could allow an attacker to gain unauthorized elevated access to the affected system.\u00a0<\/p>\n\n<p>Affected software versions:<\/p>\n\n<p>- Symantec Endpoint Protection Manager version 12.1<br \/>\n- Symantec Endpoint Protection Client version 12.1<\/p>\n\n<p>CVE References: CVE-2015-8152, CVE-2015-8153, CVE-2015-8154<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=&amp;suid=20160317_00\"><font color=\"#0066cc\">https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=&amp;suid=20160317_00<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/symantec-releases-security-update","alert_type":396,"serial_number":"AV16-051","subject":null,"moderation_state":"archived","external_url":null},{"nid":775,"title":"Multiple Apple security updates","uuid":"e5fed46f-abf2-4aca-b553-371cc60bf6be","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-21T19:23:11Z","summary":null,"body":["<article data-history-node-id=\"775\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-052<br \/>\nDate: 22 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system updates for iOS, watchOS, tvOS, Xcode, OS X El Capitan, OS X Server, and Safari.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<br \/>\nHT206166 \u2013 iOS 9.3<br \/>\nHT206167 \u2013 OS X El Capitan v10.11.4<br \/>\nHT206168 \u2013 watchOS 2.2<br \/>\nHT206169 \u2013 tvOS 9.2<br \/>\nHT206171 \u2013 Safari 9.1<br \/>\nHT206172 \u2013 Xcode 7.3<br \/>\nHT206173 \u2013 OS X Server 5.1<\/p>\n\n<p>Details: These updates address multiple vulnerabilities, including arbitrary remote code execution.<\/p>\n\n<p>Multiple CVEs are referenced; please refer to Apple's advisory for specific details.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Articles HT206166, HT206167, HT206168, HT206169, HT206171, HT206172, and HT206173.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT206166\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206166<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT206167\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206167<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT206168\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206168<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT206169\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206169<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT206171\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206171<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT206172\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206172<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT206173\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206173<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates","alert_type":396,"serial_number":"AV16-052","subject":null,"moderation_state":"archived","external_url":null},{"nid":1279,"title":"Cisco Multiple Security Advisories","uuid":"45a22e24-8b63-490a-81d2-0f5309cb82b9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:34Z","date_created":"2018-06-21T19:37:19Z","summary":null,"body":["<article data-history-node-id=\"1279\" about=\"\/en\/alerts-advisories\/cisco-multiple-security-advisories-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-053<br \/>\nDate: 24 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address critical vulnerabilities in the following software:<\/p>\n\n<p>High<\/p>\n\n<ul><li>Cisco IOS and IOS XE Software Internet Key Exchange Version 2 Fragmentation Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE and Cisco Unified Communications Manager Software Session Initiation Protocol Memory Leak Vulnerability<\/li>\n\t<li>Cisco IOS and NX-OS Software Locator\/ID Separation Protocol Packet Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software DHCPv6 Relay Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS Software Wide Area Application Services Express Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2016-1344, CVE-2016-1350, CVE-2016-1351, CVE-2016-1348, CVE-2016-1349, CVE-2016-1347<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-ios-ikev2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-ios-ikev2<\/font><\/a>\u00a0 \u00a0<\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-sip\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-sip<\/font><\/a> \u00a0<\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-lisp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-lisp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-dhcpv6\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-dhcpv6<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-smi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-smi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-l4f\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160323-l4f<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-multiple-security-advisories-1","alert_type":396,"serial_number":"AV16-053","subject":null,"moderation_state":"archived","external_url":null},{"nid":1103,"title":"Oracle Security Alert for CVE-2016-0636","uuid":"18b26a2d-104a-49ef-bd34-b76cdc37ec02","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-21T19:55:02Z","summary":null,"body":["<article data-history-node-id=\"1103\" about=\"\/en\/alerts-advisories\/oracle-security-alert-cve-2016-0636\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-054<br \/>\nDate: 24 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Oracle Security Alert for CVE-2016-0636.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle released a security update to address vulnerability in JAVA SE that may allow an attacker to remote exploit the affected user\u2019s system.<\/p>\n\n<p>Affected software version:<\/p>\n\n<ul><li>Oracle Java SE 7 Update 97, and 8 Update 73 and 74 for Windows, Solaris, Linux, and Mac OS X<\/li>\n<\/ul><p>CVE References: CVE-2016-0636<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/alert-cve-2016-0636-2949497.html?elq_mid=43101&amp;sh=912132615235269202681513122031&amp;cmid=WWMK14064193MPP032C045\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/topics\/security\/alert-cve-2016-0636-2949497.html?elq_mid=43101&amp;sh=912132615235269202681513122031&amp;cmid=WWMK14064193MPP032C045<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-alert-cve-2016-0636","alert_type":null,"serial_number":"AV16-054","subject":null,"moderation_state":"archived","external_url":null},{"nid":927,"title":"Google Releases security update for Chrome","uuid":"1660059d-0600-459c-9b17-4e9e7a8190ba","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-22T12:44:16Z","summary":null,"body":["<article data-history-node-id=\"927\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-055<br \/>\nDate: 25 March 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 49.0.2623.108 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference:<br \/>\nCVE-2016-1646, CVE-2016-1647, CVE-2016-1648, CVE-2016-1649, CVE-2016-1650<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/03\/stable-channel-update_24.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/03\/stable-channel-update_24.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-4","alert_type":396,"serial_number":"AV16-055","subject":null,"moderation_state":"archived","external_url":null},{"nid":1194,"title":"Android security bulletin \u2013 April 2016","uuid":"45b152f9-be28-4550-88f3-e8590d2474a1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-22T12:50:59Z","summary":null,"body":["<article data-history-node-id=\"1194\" about=\"\/en\/alerts-advisories\/android-security-bulletin-april-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-056<br \/>\nDate: 6 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for April.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulleting addresses a security update for 39 vulnerabilities (15 Critical, 16 High, and 8 Moderate) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2014-6060, CVE-2015-1805, CVE-2016-0834, CVE-2016-0835, CVE-2016-0836, CVE-2016-0837, CVE-2016-0838, CVE-2016-0839, CVE-2016-0840, CVE-2016-0841, CVE-2016-0842, CVE-2016-0843, CVE-2016-0844, CVE-2014-9322, CVE-2016-0846, CVE-2016-0847, CVE-2016-0848, CVE-2016-0849, CVE-2016-0850, CVE-2016-1503, CVE-2016-2409, CVE-2016-2410, CVE-2016-2411, CVE-2016-2412, CVE-2016-2413, CVE-2016-2414, CVE-2016-2415, CVE-2016-2416, CVE-2016-2417, CVE-2016-2418, CVE-2016-2419, CVE-2016-2420, CVE-2016-2421, CVE-2016-2422, CVE-2016-2423, CVE-2016-2424, CVE-2016-2425, CVE-2016-2426, CVE-2016-2427<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look to their respective Android phone vendor and wireless carrier for when the updates will be available, then test and deploy the vendor-released updates to affected applications and devices accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Android web site: <a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-04-02.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-04-02.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-april-2016","alert_type":396,"serial_number":"AV16-056","subject":null,"moderation_state":"archived","external_url":null},{"nid":805,"title":"Cisco Multiple Security Advisories","uuid":"d5cffda0-d89d-4abe-909d-74a5bf89cb68","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-22T12:58:56Z","summary":null,"body":["<article data-history-node-id=\"805\" about=\"\/en\/alerts-advisories\/cisco-multiple-security-advisories-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-057<br \/>\nDate: 7 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address critical vulnerabilities in the following software\/hardware:\u00a0<\/p>\n\n<h3>Critical<\/h3>\n\n<ul><li>Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco UCS Invicta Default SSH Key Vulnerability<\/li>\n<\/ul><h3>High<\/h3>\n\n<ul><li>Cisco Prime Infrastructure and Evolved Programmable Network Manager Privilege Escalation API Vulnerability<\/li>\n\t<li>Cisco TelePresence Server Crafted IPv6 Packet Handling Denial of Service Vulnerability<\/li>\n\t<li>Cisco TelePresence Server Crafted URL Handling Denial of Service Vulnerability<\/li>\n\t<li>Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability<\/li>\n\t<li>Vulnerability in GNU glibc Affecting Cisco Products: February 2016<\/li>\n<\/ul><h3>Medium<\/h3>\n\n<ul><li>Cisco IOS XR Software SCP and SFTP Modules Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE-2016-1366, CVE-2016-1290, CVE-2016-1346, CVE-2016-1291, CVE-2016-1313, CVE-2015-6313, CVE-2015-6312, CVE-2015-7547<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-multiple-security-advisories-2","alert_type":396,"serial_number":"AV16-057","subject":null,"moderation_state":"archived","external_url":null},{"nid":889,"title":"BlackBerry powered by Android security bulletin \u2013 April 2016","uuid":"bcef424d-d3c1-4d46-a39c-dd6ed87758fe","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-22T13:06:19Z","summary":null,"body":["<article data-history-node-id=\"889\" about=\"\/en\/alerts-advisories\/blackberry-powered-android-security-bulletin-april-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-058<br \/>\nDate: 6 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update to address multiple vulnerabilities in BlackBerry powered by Android smartphones.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Blackberry powered by Android Security Bulletin addresses a security update for 26 vulnerabilities that could potentially enable remote code execution, elevation of privilege and data access on affected devices.<\/p>\n\n<p>CVE References: CVE-2015-1805, CVE-2016-0837, CVE-2016-0838, \u00a0CVE-2016-0841, CVE-2016-0844, CVE-2016-0846, CVE-2016-0847, CVE-2016-0848, CVE-2016-0849, CVE-2016-0850, CVE-2016-1503, CVE-2016-2410, CVE-2016-2411, CVE-2016-2412,CVE-2016-2413, CVE-2016-2414, CVE-2016-2415, CVE-2016-2416, CVE-2016-2417, CVE-2016-2421, CVE-2016-2422, CVE-2016-2423, CVE-2016-2424, CVE-2016-2426, CVE-2016-2427<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>An updated software version is available immediately for BlackBerry Powered by Android smartphones that have been purchased from ShopBlackBerry.com. The updated software version can be identified with the build ID \u2018Build AAE298\u2019. If your devices were purchased from a source other than ShopBlackBerry.com, contact that retailer or carrier directly for security maintenance release availability information.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/support.blackberry.com\/kb\/articleDetail?articleNumber=000038099\"><font color=\"#0066cc\">http:\/\/support.blackberry.com\/kb\/articleDetail?articleNumber=000038099<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/blackberry-powered-android-security-bulletin-april-2016","alert_type":396,"serial_number":"AV16-058","subject":null,"moderation_state":"archived","external_url":null},{"nid":1080,"title":"security updates for Adobe Flash Player","uuid":"8d1b0de2-71f8-4bcf-94be-4f39774dbf72","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-22T13:15:04Z","summary":null,"body":["<article data-history-node-id=\"1080\" about=\"\/en\/alerts-advisories\/security-updates-adobe-flash-player-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-059<br \/>\nDate: 8 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-10 to address critical vulnerabilities that could allow an attacker to take control of the affected system.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime 21.0.0.197 and earlier for Windows and Macintosh<\/li>\n\t<li>Adobe Flash Player Extended Support Release 18.0.0.333 and earlier for Windows and Macintosh<\/li>\n\t<li>Adobe Flash Player for Google Chrome 21.0.0.197 and earlier for Windows, Macintosh, Linux, and ChromeOS<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 21.0.0.197 \u00a0and earlier for Windows 10<\/li>\n\t<li>Adobe Flash Player for Internet Explorer 11 21.0.0.197 and earlier for Windows 8.1<\/li>\n\t<li>Adobe Flash Player for Linux 11.2.202.577 and earlier for Linux<\/li>\n<\/ul><p>CVE References: CVE-2016-1006, CVE-2016-1011, CVE-2016-1012, CVE-2016-1013, CVE-2016-1014, CVE-2016-1015, CVE-2016-1016, CVE-2016-1017, CVE-2016-1018, CVE-2016-1019*, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1030, CVE-2016-1031, CVE-2016-1032, CVE-2016-1033<\/p>\n\n<p>*Adobe is aware that CVE-2016-1019 is being actively exploited in the wild on systems running Windows 10 and earlier with Flash Player version 20.0.0.306 and earlier. Please refer to CCIRC Alert AL16-006 for details.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-10.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-10.html<\/font><\/a> \u00a0<\/li>\n\t<li><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/al16-006-en.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/al16-006-en.aspx<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-adobe-flash-player-0","alert_type":396,"serial_number":"AV16-059","subject":null,"moderation_state":"archived","external_url":null},{"nid":1038,"title":"Samba (smbd) Vulnerability","uuid":"be25a81a-118d-433e-aa25-b6185119ee78","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-22T13:23:55Z","summary":null,"body":["<article data-history-node-id=\"1038\" about=\"\/en\/alerts-advisories\/samba-smbd-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-060<br \/>\nDate: 12 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to vulnerabilities in Samba (smbd).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of vulnerabilities in Samba (smbd) which could allow a malicious actor to perform man-in-the-middle and denial-of-service attacks.\u00a0 Security fixes for these vulnerabilities have been made available for Samba versions 4.2, 4.3 and 4.4.\u00a0 Earlier versions of Samba have been discontinued and will not receive security fixes.<\/p>\n\n<p>Affected versions: 4.4.0, 4.3.0-4.3.6, 4.2.0-4.2.9, 4.1.x, 4.0.x, 3.6.x<\/p>\n\n<p>CVE References: CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112, CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly or consider applying the work-arounds.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>Badlock Vulnerability: <a href=\"http:\/\/www.badlock.org\/\"><font color=\"#0066cc\">http:\/\/www.badlock.org<\/font><\/a><\/li>\n\t<li>Samba Security Releases: <a href=\"http:\/\/samba.org\/samba\/history\/security.html\"><font color=\"#0066cc\">http:\/\/samba.org\/samba\/history\/security.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-smbd-vulnerability","alert_type":396,"serial_number":"AV16-060","subject":null,"moderation_state":"archived","external_url":null},{"nid":1163,"title":"Microsoft Critical security bulletins Summary for April 2016","uuid":"f2b578f8-9eae-4036-a33d-26841f33b242","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-22T13:30:50Z","summary":null,"body":["<article data-history-node-id=\"1163\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-april-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-061<br \/>\nDate: 12 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for March 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 13 bulletins (6 Critical and 7 Important), which addresses multiple vulnerabilities in Microsoft .NET Framework, Microsoft Internet Explorer, Microsoft Edge, Microsoft Office, Microsoft Graphic Component, Microsoft XML Core Services, Windows OLE, Windows Hyper-V, Secondary Logon, SAM and LSAD Remote Protocols, CSRSS, and Adobe Flash Player.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS16-037 Cumulative Security Update for Internet Explorer (3148531)<\/li>\n\t<li>MS16-038 Cumulative Security Update for Microsoft Edge (3148532)<\/li>\n\t<li>MS16-039 Security Update for Microsoft Graphics Component (3148522)<\/li>\n\t<li>MS16-040 Security Update for Microsoft XML Core Services (3148541)<\/li>\n\t<li>MS16-042 Security Update for Microsoft Office (3148775)<\/li>\n\t<li>MS16-050 Security Update for Adobe Flash Player (3135782)<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS16-041 Security Update for .NET Framework (3148789)<\/li>\n\t<li>MS16-044 Security Update for Windows OLE (3146706)<\/li>\n\t<li>MS16-045 Security Update for Windows Hyper-V (3143118)<\/li>\n\t<li>MS16-046 Security Update for Secondary Logon (3148538)<\/li>\n\t<li>MS16-047 Security Update for SAM and LSAD Remote Protocols (3148527)<\/li>\n\t<li>MS16-048 Security Update for CSRSS (3148528)<\/li>\n\t<li>MS16-049 Security Update for HTTP.sys (3148795)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-ca\/library\/security\/ms16-apr\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-ca\/library\/security\/ms16-apr<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-april-2016","alert_type":396,"serial_number":"AV16-061","subject":null,"moderation_state":"archived","external_url":null},{"nid":1199,"title":"Cisco security advisory","uuid":"8ae02b25-d289-40ee-89d4-b27711462cc0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-22T13:38:02Z","summary":null,"body":["<article data-history-node-id=\"1199\" about=\"\/en\/alerts-advisories\/cisco-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-062<br \/>\nDate: 13 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released Cisco Security Advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released security update to address vulnerability in the web framework of Cisco Unified Computing System (UCS) Central Software that could allow an unauthenticated, remote attacker to execute arbitrary commands on a targeted system.<\/p>\n\n<p>Affected Version:<\/p>\n\n<ul><li>UCS Central Software releases 1.3(1b) and prior<\/li>\n<\/ul><p>CVE References: CVE-2016-1352<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160413-ucs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160413-ucs<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory","alert_type":396,"serial_number":"AV16-062","subject":null,"moderation_state":"archived","external_url":null},{"nid":1308,"title":"Google Releases security update for Chrome","uuid":"ada2a88f-e0a6-48e8-b85a-0070f706535e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-22T13:56:03Z","summary":null,"body":["<article data-history-node-id=\"1308\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-063<br \/>\nDate: 13 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 50.0.2661.75 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference:<br \/>\nCVE-2016-1652, CVE-2016-1653, CVE-2016-1651, CVE-2016-1654, CVE-2016-1655, CVE-2016-1656, CVE-2016-1657, CVE-2016-1658, CVE-2015-1659<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/04\/stable-channel-update_13.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/04\/stable-channel-update_13.html<\/font><\/a>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-5","alert_type":396,"serial_number":"AV16-063","subject":null,"moderation_state":"archived","external_url":null},{"nid":908,"title":"VMware security advisory","uuid":"a92555e7-80f4-4b91-9afa-1573af12ebcb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-22T14:22:48Z","summary":null,"body":["<article data-history-node-id=\"908\" about=\"\/en\/alerts-advisories\/vmware-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-064<br \/>\nDate: 15 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware product update addresses a critical security issue in the VMware Client Integration Plugin:<\/p>\n\n<p>Affected Products:\u00a0\u00a0<\/p>\n\n<ul><li>VMware vCenter Server 5.5 U3a, U3b, U3c and 6.0 prior to 6.0 U2<\/li>\n\t<li>vCloud Director (vCD) 5.5.5 \u00a0<\/li>\n\t<li>vRealize Automation (vRA)\u00a0 Identity Appliance 6.2.4<\/li>\n<\/ul><p>CVE Reference: CVE-2016-2076<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory","alert_type":396,"serial_number":"AV16-064","subject":null,"moderation_state":"archived","external_url":null},{"nid":919,"title":"Oracle Critical Patch update Advisory \u2013 April 2016","uuid":"192b4dcc-fb05-4c3d-9869-dedbdc78fbc3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-22T14:29:56Z","summary":null,"body":["<article data-history-node-id=\"919\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-april-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-065<br \/>\nDate: 19 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following critical patch updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update (CPU) which addresses 136 new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Fujitsu M10-1, M10-4, M10-4S Servers, version(s) prior to XCP 2290<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version(s) 9.1, 9.2<\/li>\n\t<li>MySQL Enterprise Monitor, version(s) 3.0.25 and prior, 3.1.2 and prior<\/li>\n\t<li>MySQL Server, version(s) 5.5.48 and prior, 5.6.29 and prior, 5.7.11 and prior<\/li>\n\t<li>Oracle Agile Engineering Data Management, version(s) 6.1.3.0, 6.2.0.0<\/li>\n\t<li>Oracle Agile PLM, version(s) 9.3.1.1, 9.3.1.2, 9.3.2, 9.3.3<\/li>\n\t<li>Oracle API Gateway, version(s) 11.1.2.3.0, 11.1.2.4.0<\/li>\n\t<li>Oracle Application Testing Suite, version(s) 12.4.0.2, 12.5.0.2<\/li>\n\t<li>Oracle Berkeley DB, version(s) 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, 12.1.6.1.26<\/li>\n\t<li>Oracle BI Publisher, version(s) 12.2.1.0.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.2.1.0.0<\/li>\n\t<li>Oracle Communications User Data Repository, version(s) 10.0.1<\/li>\n\t<li>Oracle Complex Maintenance, Repair, and Overhaul, version(s) 11.5.10.2, 12.1.1, 12.1.2, 12.1.3<\/li>\n\t<li>Oracle Configurator, version(s) 12.0.6, 12.1, 12.2<\/li>\n\t<li>Oracle Database Server, version(s) 11.2.0.4, 12.1.0.1, 12.1.0.2<\/li>\n\t<li>Oracle E-Business Suite, version(s) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5<\/li>\n\t<li>Oracle Ethernet Switch ES2-72, Oracle Ethernet Switch ES2-64, version(s) prior to 2.0.0.6<\/li>\n\t<li>Oracle Exalogic Infrastructure, version(s) 1.0, 2.0<\/li>\n\t<li>Oracle FLEXCUBE Direct Banking, version(s) 12.0.2, 12.0.3<\/li>\n\t<li>Oracle GlassFish Server, version(s) 2.1.1<\/li>\n\t<li>Oracle HTTP Server, version(s) 12.1.2.0, 12.1.3.0<\/li>\n\t<li>Oracle iPlanet Web Proxy Server, version(s) 4.0<\/li>\n\t<li>Oracle iPlanet Web Server, version(s) 7.0<\/li>\n\t<li>Oracle Java SE Embedded, version(s) 8u77<\/li>\n\t<li>Oracle Java SE, version(s) 6u113, 7u99, 8u77<\/li>\n\t<li>Oracle JRockit, version(s) R28.3.9<\/li>\n\t<li>Oracle Life Sciences Data Hub, version(s) 2.1<\/li>\n\t<li>Oracle OpenSSO, version(s) 3.0-0.7<\/li>\n\t<li>Oracle Outside In Technology, version(s) 8.5.0, 8.5.1, 8.5.2<\/li>\n\t<li>Oracle Retail MICROS ARS POS, version(s) 1.5<\/li>\n\t<li>Oracle Retail MICROS C2, version(s) 9.89.0.0<\/li>\n\t<li>Oracle Retail Xstore Point of Service, version(s) 5.0, 5.5, 6.0, 6.5, 7.0, 7.1<\/li>\n\t<li>Oracle Traffic Director, version(s) 11.1.1.7.0, 11.1.1.9.0<\/li>\n\t<li>Oracle Transportation Management, version(s) 6.1, 6.2<\/li>\n\t<li>Oracle Tuxedo, version(s) 12.1.1.0<\/li>\n\t<li>Oracle VM VirtualBox, version(s) prior to 4.3.36, prior to 5.0.18<\/li>\n\t<li>Oracle WebCenter Sites, version(s) 11.1.1.8.0, 12.2.1<\/li>\n\t<li>Oracle WebLogic Server, version(s) 10.3.6, 12.1.2, 12.1.3, 12.2.1<\/li>\n\t<li>OSS Support Tools Oracle Explorer, version(s) 10<\/li>\n\t<li>PeopleSoft Enterprise HCM ePerformance, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise HCM, version(s) 9.1, 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, version(s) 8, 8.53, 8.54, 8.55, 54<\/li>\n\t<li>PeopleSoft Enterprise SCM, version(s) 9.1, 9.2<\/li>\n\t<li>Siebel Applications, version(s) 8.1.1, 8.2.2<\/li>\n\t<li>Solaris Cluster, version(s) 4.2<\/li>\n\t<li>Solaris, version(s) 10, 11.3<\/li>\n\t<li>SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers, version(s) prior to XCP 1121<\/li>\n\t<li>Sun Ray Software, version(s) 11.1<\/li>\n\t<li>Sun Storage Common Array Manager, version(s) 6.9.0<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2016v3-2985753.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2016v3-2985753.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-april-2016","alert_type":396,"serial_number":"AV16-065","subject":null,"moderation_state":"archived","external_url":null},{"nid":1117,"title":"Cisco Multiple Security Advisories","uuid":"f792dbdd-11e4-4ae2-8f62-3924b4366511","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-22T14:36:32Z","summary":null,"body":["<article data-history-node-id=\"1117\" about=\"\/en\/alerts-advisories\/cisco-multiple-security-advisories-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-066<br \/>\nDate: 21 April 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address critical and high vulnerabilities in the following software:<\/p>\n\n<p>Critical<\/p>\n\n<ul><li>Cisco Wireless LAN Controller HTTP Parsing Denial of Service Vulnerability<\/li>\n<\/ul><p>High<\/p>\n\n<ul><li>Multiple Cisco Products libSRTP Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller Management Interface Denial of Service Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE Reference: CVE-2016-1363, CVE-2015-6360, CVE-2016-1362, CVE-2016-1367, CVE-2016-1364<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-htrd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-htrd<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-libsrtp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-libsrtp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-wlc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-wlc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-asa-dhcpv6\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-asa-dhcpv6<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-bdos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160420-bdos<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-multiple-security-advisories-3","alert_type":null,"serial_number":"AV16-066","subject":null,"moderation_state":"archived","external_url":null},{"nid":1185,"title":"Mozilla Releases security updates","uuid":"c0d80906-447d-45ec-a1fe-5ff09a36b305","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-22T14:43:19Z","summary":null,"body":["<article data-history-node-id=\"1185\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-067<br \/>\nDate: 26 April 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which upgrades are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address multiple vulnerabilities in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 46.0<br \/>\nESR versions 45.x prior to 45.1<br \/>\nESR versions 38.x prior to 38.8<\/p>\n\n<p>CVE Reference:\u00a0 CVE-2016-2820, CVE-2016-2816, CVE-2016-2814, CVE-2016-2813, CVE-2016-2812, CVE-2016-2811, CVE-2016-2810, CVE-2016-2809, CVE-2016-2808, CVE-2016-2807, CVE-2016-2806, CVE-2016-2805, CVE-2016-2804<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/#firefox46\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/#firefox46<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox-esr\/#firefoxesr45.1\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox-esr\/#firefoxesr45.1<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-0","alert_type":396,"serial_number":"AV16-067","subject":null,"moderation_state":"archived","external_url":null},{"nid":767,"title":"HP security bulletin","uuid":"07262a1a-f719-475e-aa77-78117229eb99","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-22T14:50:40Z","summary":null,"body":["<article data-history-node-id=\"767\" about=\"\/en\/alerts-advisories\/hp-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-068<br \/>\nDate: 28 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to HP security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HP released multiple updates to address vulnerabilities in HP Data Protector which could allow the remote execution of code or the unauthorized disclosure of information.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>HP Data Protector 7.x before 7.03_108<\/li>\n\t<li>HP Data Protector 8.x before 8.15<\/li>\n\t<li>HP Data Protector 9.x before 9.06<\/li>\n<\/ul><p>CVE Reference: CVE-2016-2004, CVE-2016-2005, CVE-2016-2006, CVE-2016-2007, CVE-2015-2808, CVE-2016-2008<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/h20564.www2.hpe.com\/hpsc\/doc\/public\/display?docId=emr_na-c05085988\"><font color=\"#0066cc\">http:\/\/h20564.www2.hpe.com\/hpsc\/doc\/public\/display?docId=emr_na-c05085988<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hp-security-bulletin","alert_type":396,"serial_number":"AV16-068","subject":null,"moderation_state":"archived","external_url":null},{"nid":1257,"title":"Google Releases security update for Chrome","uuid":"a0911912-9408-43ca-ae00-7fcef2c05a51","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:14Z","date_created":"2018-06-22T14:57:33Z","summary":null,"body":["<article data-history-node-id=\"1257\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-069<br \/>\nDate: 29 April 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 50.0.2661.94 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference:<br \/>\nCVE-2016-1660, CVE-2016-1661, CVE-2016-1662, CVE-2016-1663, CVE-2016-1664, CVE-2016-1665, CVE-2016-1666<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/04\/stable-channel-update_28.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/04\/stable-channel-update_28.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-6","alert_type":396,"serial_number":"AV16-069","subject":null,"moderation_state":"archived","external_url":null},{"nid":1095,"title":"Android security bulletin \u2013 May 2016","uuid":"c8ea5179-5e37-41b1-94bd-fec2dcfe551a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-22T15:04:49Z","summary":null,"body":["<article data-history-node-id=\"1095\" about=\"\/en\/alerts-advisories\/android-security-bulletin-may-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-070<br \/>\nDate: 3 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for May.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulleting addresses a security update for 40 vulnerabilities (12 Critical, 19 High, 8 Moderate and 1 Low) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2015-0569, CVE-2015-0570, CVE-2015-0571, CVE-2015-1805, CVE-2016-0705, CVE-2016-0774, CVE-2016-2060, CVE-2016-2428, CVE-2016-2429, CVE-2016-2430, CVE-2016-2431, CVE-2016-2432, CVE-2016-2434, CVE-2016-2435, CVE-2016-2436, CVE-2016-2437, CVE-2016-2438, CVE-2016-2439, CVE-2016-2440, CVE-2016-2441, CVE-2016-2442, CVE-2016-2443, CVE-2016-2444, CVE-2016-2445, CVE-2016-2446, CVE-2016-2447, CVE-2016-2448, CVE-2016-2449, CVE-2016-2450, CVE-2016-2451, CVE-2016-2452, CVE-2016-2453, CVE-2016-2454, CVE-2016-2456, CVE-2016-2457, CVE-2016-2458, CVE-2016-2459, CVE-2016-2460,CVE-2016-2461, CVE-2016-2462<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Android web site: <a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-05-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-05-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-may-2016","alert_type":396,"serial_number":"AV16-070","subject":null,"moderation_state":"archived","external_url":null},{"nid":929,"title":"OpenSSL Advisory \u2013 Multiple Vulnerabilities","uuid":"8f631610-0adc-47db-b89e-d68e9e6c55d5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-22T15:12:02Z","summary":null,"body":["<article data-history-node-id=\"929\" about=\"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-071<br \/>\nDate: 3 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security updates released by OpenSSL.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of six (2 high and 4 low) disclosed vulnerabilities in OpenSSL for which updates are available.<\/p>\n\n<p>Affected Versions: 1.0.1 and 1.0.2<\/p>\n\n<p>CVE References: CVE-2016-2176, CVE-2016-2109, CVE-2016-2108, CVE-2016-2107, CVE-2016-2106, CVE-2016-2105<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p>OpenSSL 1.0.1 users should upgrade to 1.0.1t.<br \/>\nOpenSSL 1.0.2 users should upgrade to 1.0.2h.<\/p>\n\n<h2>References<\/h2>\n\n<p>OpenSSL Advisory: <a href=\"https:\/\/www.openssl.org\/news\/secadv\/20160503.txt\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/news\/secadv\/20160503.txt<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-1","alert_type":396,"serial_number":"AV16-071","subject":null,"moderation_state":"archived","external_url":null},{"nid":1195,"title":"Apple security update for Xcode","uuid":"10c973e4-9aec-4400-8fa2-75b1a391e6c6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-22T15:18:53Z","summary":null,"body":["<article data-history-node-id=\"1195\" about=\"\/en\/alerts-advisories\/apple-security-update-xcode\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-072<br \/>\nDate: 4 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple security update for Xcode.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support article:<br \/>\nHT206338 \u2013 Xcode 7.3.1<\/p>\n\n<p>Details: This update addresses multiple vulnerabilities that could allow remote attackers to execute arbitrary code.<\/p>\n\n<p>CVE Reference:\u00a0 CVE-2016-2315, CVE-2016-2324<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in the Apple Support Article: HT206338.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT206338\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206338<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-update-xcode","alert_type":396,"serial_number":"AV16-072","subject":null,"moderation_state":"archived","external_url":null},{"nid":807,"title":"WordPress Security update Release","uuid":"7fffb946-d00e-4b10-893c-eb22ab737864","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-22T16:31:44Z","summary":null,"body":["<article data-history-node-id=\"807\" about=\"\/en\/alerts-advisories\/wordpress-security-update-release\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-074<br \/>\nDate: 6 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a WordPress 4.5.2 Security Release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress versions 4.5.1 and previous are affected by a SOME vulnerability through Plupload, the third party library used by Wordpress to upload files.<\/p>\n\n<p>WordPress versions 4.2 through 4.5.1 are affected by a XSS vulnerability using specially crafted URIs through MediaElement.js, the third party library for media used by Wordpress.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2016\/05\/wordpress-4-5-2\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2016\/05\/wordpress-4-5-2\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-release","alert_type":396,"serial_number":"AV16-074","subject":null,"moderation_state":"archived","external_url":null},{"nid":891,"title":"security updates for Adobe Acrobat and Reader","uuid":"f848c9cb-f921-4a3e-b14b-0c07d2d854f6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-22T16:39:02Z","summary":null,"body":["<article data-history-node-id=\"891\" about=\"\/en\/alerts-advisories\/security-updates-adobe-acrobat-and-reader-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-075<br \/>\nDate: 10 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Adobe Acrobat, Reader and Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-14 to address critical vulnerabilities that could allow an attacker to take control of vulnerable systems. All OS platforms are reported as being impacted.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<p>- Adobe Acrobat DC 15.010.20060 and earlier versions<br \/>\n- Adobe Acrobat Reader DC 15.010.20060 and earlier versions<br \/>\n- Adobe Acrobat DC 15.006.30121 and earlier versions<br \/>\n- Adobe Acrobat Reader DC 15.006.30121 and earlier versions<br \/>\n- Adobe Acrobat XI 11.0.15 and earlier versions<br \/>\n- Adobe Reader XI 11.0.15 and earlier versions<\/p>\n\n<p>CVE References: CVE-2016-1037, CVE-2016-1038, CVE-2016-1039, CVE-2016-1040, CVE-2016-1041, CVE-2016-1042, CVE-2016-1043, CVE-2016-1044, CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1062, CVE-2016-1063, CVE-2016-1064, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1075, CVE-2016-1076, CVE-2016-1077, CVE-2016-1078, CVE-2016-1079, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1087, CVE-2016-1088, CVE-2016-1090, CVE-2016-1092, CVE-2016-1093, CVE-2016-1094, CVE-2016-1095, CVE-2016-1112, CVE-2016-1116, CVE-2016-1117, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1121, CVE-2016-1122, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4091, CVE-2016-4092, CVE-2016-4093, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4102, CVE-2016-4103, CVE-2016-4104, CVE-2016-4105, CVE-2016-4106, CVE-2016-4107<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p>Adobe Security Bulletin: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-14.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-14.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-adobe-acrobat-and-reader-0","alert_type":396,"serial_number":"AV16-075","subject":null,"moderation_state":"archived","external_url":null},{"nid":1074,"title":"Microsoft Critical security bulletins Summary for May 2016","uuid":"78f1aa5b-a4ee-466b-b03f-b0ca1738cd8f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-22T16:45:32Z","summary":null,"body":["<article data-history-node-id=\"1074\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-may-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-076<br \/>\nDate: 10 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for May 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 16 bulletins (8 Critical and\u00a0 8 Important), which addresses multiple vulnerabilitiesin Microsoft .NET Framework, Microsoft Internet Explorer, Microsoft Edge, Microsoft Office, Jscript, VBScript, Microsoft Graphics Component, Windows Journal, Windows Shell, Windows IIS, Windows Media Center, Windows Kernel, Microsoft RPC, Windows Kernel-Mode Drivers, Adobe Flash Player, Virtual Security Mode, and Volume Manager Driver.<\/p>\n\n<p>***Critical***<\/p>\n\n<p>MS16-051 Cumulative Security Update for Internet Explorer (3155533)<br \/>\nMS16-052 Cumulative Security Update for Microsoft Edge (3155538)<br \/>\nMS16-053 Cumulative Security Update for JScript and VBScript (3156764)<br \/>\nMS16-054 Security Update for Microsoft Office (3155544)<br \/>\nMS16-055 Security Update for Microsoft Graphics Component (3156754)<br \/>\nMS16-056 Security Update for Windows Journal (3156761)<br \/>\nMS16-057 Security Update for Windows Shell (3156987)<br \/>\nMS16-064 Security Update for Adobe Flash Player (3157993)<\/p>\n\n<p>***Important***<\/p>\n\n<p>MS16-058 Security Update for Windows IIS (3141083)<br \/>\nMS16-059 Security Update for Windows Media Center (3150220)<br \/>\nMS16-060 Security Update for Windows Kernel (3154846)<br \/>\nMS16-061 Security Update for Microsoft RPC (3155520)<br \/>\nMS16-062 Security Update for Windows Kernel-Mode Drivers (3158222)<br \/>\nMS16-065 Security Update for .NET Framework (3156757)<br \/>\nMS16-066 Security Update for Virtual Secure Mode (3155451)<br \/>\nMS16-067 Security Update for Volume Manager Driver (3155784)<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-May\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-May<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-may-2016","alert_type":396,"serial_number":"AV16-076","subject":null,"moderation_state":"archived","external_url":null},{"nid":1039,"title":"ImageMagick security update","uuid":"4c22f550-e1cf-43fa-bc6c-67ce34155c65","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-22T17:09:03Z","summary":null,"body":["<article data-history-node-id=\"1039\" about=\"\/en\/alerts-advisories\/imagemagick-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-073<br \/>\nDate: 6 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for ImageMagick.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>ImageMagick Studio has released a security update for a critical vulnerability in ImageMagick. Exploitation of this vulnerability may allow for arbitrary remote code execution.<\/p>\n\n<p>Affected versions:<\/p>\n\n<ul><li>ImageMagick versions 6.9.x prior to 6.9.3-10<\/li>\n\t<li>ImageMagick versions 7.0.x prior to 7.0.1-1<\/li>\n<\/ul><p>CVE Reference: CVE-2016-3714<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>ImageMagick Security Update Download Page:<br \/><a href=\"http:\/\/www.imagemagick.org\/script\/download.php\"><font color=\"#0066cc\">http:\/\/www.imagemagick.org\/script\/download.php<\/font><\/a><\/p>\n\n<p>CCIRC Alert AL16-007:<br \/><a href=\"\/al\/al16-007\">al\/al16-007-en.aspx<\/a>.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/imagemagick-security-update","alert_type":396,"serial_number":"AV16-073","subject":null,"moderation_state":"archived","external_url":null},{"nid":1164,"title":"Google Releases security update for Chrome","uuid":"21814d08-15d9-4d70-a8a4-2acb840fea39","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-22T17:39:41Z","summary":null,"body":["<article data-history-node-id=\"1164\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-077<br \/>\nDate: 12 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 50.0.2661.102 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference:<br \/>\nCVE-2016-1667, CVE-2016-1668, CVE-2016-1669, CVE-2016-1670, CVE-2016-1671<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/05\/stable-channel-update.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/05\/stable-channel-update.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-7","alert_type":396,"serial_number":"AV16-077","subject":null,"moderation_state":"archived","external_url":null},{"nid":1211,"title":"7-Zip security update","uuid":"8b45dcc3-b12c-43d7-af4c-ae169b943388","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-22T17:50:04Z","summary":null,"body":["<article data-history-node-id=\"1211\" about=\"\/en\/alerts-advisories\/7-zip-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-078<br \/>\nDate: 12 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a 7-Zip security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A security update was released for 7-Zip which addresses multiple vulnerabilities. \u00a0Exploitation of these vulnerabilities may allow for arbitrary remote code execution.<\/p>\n\n<p>These vulnerabilities also affect the 7-Zip library, which is included with and leveraged by several hardware and software products.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>Cisco Talos (vulnerability report):<br \/><a href=\"http:\/\/blog.talosintel.com\/2016\/05\/multiple-7-zip-vulnerabilities.html\"><font color=\"#0066cc\">http:\/\/blog.talosintel.com\/2016\/05\/multiple-7-zip-vulnerabilities.html<\/font><\/a>\u00a0<\/li>\n\t<li>7-Zip:<br \/><a href=\"http:\/\/7-zip.org\/download.html\"><font color=\"#0066cc\">http:\/\/7-zip.org\/download.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/7-zip-security-update","alert_type":396,"serial_number":"AV16-078","subject":null,"moderation_state":"archived","external_url":null},{"nid":1318,"title":"security updates for Adobe Flash Player","uuid":"78051f56-cf46-434b-b895-1ce0c3aad456","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-22T17:56:30Z","summary":null,"body":["<article data-history-node-id=\"1318\" about=\"\/en\/alerts-advisories\/security-updates-adobe-flash-player-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-079<br \/>\nDate: 13 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-15 to address critical vulnerabilities that could allow an attacker to take control of vulnerable systems. All OS platforms are reported as being impacted.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime 21.0.0.226 and earlier versions<\/li>\n\t<li>Adobe Flash Player Extended Support Release 18.0.0.343 and earlier versions<\/li>\n\t<li>Adobe Flash Player for Google Chrome 21.0.0.216 and earlier versions<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 21.0.0.213 and earlier versions<\/li>\n\t<li>Adobe Flash Player for Internet Explorer 11 21.0.0.213 and earlier\u00a0 versions<\/li>\n\t<li>Adobe Flash Player for Linux 11.2.202.616 and earlier versions<\/li>\n\t<li>AIR Desktop Runtime 21.0.0.198 and earlier versions\u00a0<\/li>\n\t<li>AIR SDK 21.0.0.198 and earlier versions<\/li>\n\t<li>AIR SDK &amp; Compiler 21.0.0.198 and earlier versions<\/li>\n<\/ul><p>CVE References: CVE-2016-1096, CVE-2016-1097, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1101, CVE-2016-1102, CVE-2016-1103, CVE-2016-1104, CVE-2016-1105, CVE-2016-1106, CVE-2016-1107, CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016-4108, CVE-2016-4109, CVE-2016-4110, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4116, CVE-2016-4117.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Adobe Security Bulletin: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-15.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-15.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-adobe-flash-player-1","alert_type":396,"serial_number":"AV16-079","subject":null,"moderation_state":"archived","external_url":null},{"nid":910,"title":"HP security bulletin","uuid":"f63f6012-b382-44b2-a5eb-5b5c157a1aca","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-22T18:04:57Z","summary":null,"body":["<article data-history-node-id=\"910\" about=\"\/en\/alerts-advisories\/hp-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-080<br \/>\nDate: 13 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to HP security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HP released multiple updates to address vulnerabilities in HPE Systems Insight Manager (SIM) on Windows and Linux which could be exploited remotely resulting in Denial of Service (DoS), execution of arbitrary code, disclosure of information, Cross-site Request Forgery (CSRF), and Cross-site scripting (XSS).<\/p>\n\n<p>Affected Versions:<br \/>\nHP Systems Insight Manager prior to 7.5.1<\/p>\n\n<p>CVE References: CVE-2015-3194, CVE-2015-3195, CVE-2016-0705, CVE-2016-0799, CVE-2016-2842, CVE-2015-6565<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/h20564.www2.hpe.com\/hpsc\/doc\/public\/display?docId=emr_na-c05131085\"><font color=\"#0066cc\">https:\/\/h20564.www2.hpe.com\/hpsc\/doc\/public\/display?docId=emr_na-c05131085<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hp-security-bulletin-0","alert_type":396,"serial_number":"AV16-080","subject":null,"moderation_state":"archived","external_url":null},{"nid":915,"title":"Multiple Apple security updates","uuid":"4a2eca04-1300-4db8-a069-2c80a61e8772","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-22T18:12:17Z","summary":null,"body":["<article data-history-node-id=\"915\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-081<br \/>\nDate: 17 May 2016\u00a0 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system updates for iOS, watchOS, OS X El Capitan, Safari and iTunes.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<ul><li>HT206568 \u2013 iOS 9.3.2<\/li>\n\t<li>HT206566 \u2013 watchOS 2.2.1<\/li>\n\t<li>HT206567 \u2013 OS X El Capitan v10.11.5<\/li>\n\t<li>HT206565 \u2013 Safari 9.1.1<\/li>\n\t<li>HT206379 \u2013 iTunes 12.4<\/li>\n<\/ul><p>Details: These updates address multiple vulnerabilities, including arbitrary remote code execution.<\/p>\n\n<p>Multiple CVEs are referenced; please refer to Apple's advisory for specific details.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Articles HT206568, HT206566, HT206567, HT206565 and HT206379.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-us\/HT206568\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206568<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT206566\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206566<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT206567\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206567<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT206565\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206565<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT206379\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT206379<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-0","alert_type":null,"serial_number":"AV16-081","subject":null,"moderation_state":"archived","external_url":null},{"nid":1130,"title":"Symantec Releases security update","uuid":"89dfdd50-b2b5-41fe-b137-795339e87742","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:29Z","date_created":"2018-06-22T18:21:28Z","summary":null,"body":["<article data-history-node-id=\"1130\" about=\"\/en\/alerts-advisories\/symantec-releases-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-082<br \/>\nDate: 17 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Symantec Antivirus Engine.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Symantec has released a Security Advisory to address critical vulnerabilities that could allow a remote attacker to execute arbitrary code with root\/system privileges on affected systems.<\/p>\n\n<p>Affected software versions:<br \/>\n- Symantec Anti-Virus Engine version 20151.1.0.32<\/p>\n\n<p>CVE Reference\u00a0: CVE-2016-2208<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2016&amp;suid=20160516_00\"><font color=\"#0066cc\">https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2016&amp;suid=20160516_00<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/symantec-releases-security-update-0","alert_type":396,"serial_number":"AV16-082","subject":null,"moderation_state":"archived","external_url":null},{"nid":1187,"title":"Magento security update","uuid":"205f6d00-5f2e-48b1-b848-08208f172346","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-22T18:46:21Z","summary":null,"body":["<article data-history-node-id=\"1187\" about=\"\/en\/alerts-advisories\/magento-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-083<br \/>\nDate: 18 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a new release of Magento Community Edition and Enterprise Edition that includes multiple security patches.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Magento Community Edition version 2.0.6 and Enterprise Edition version 2.0.6 contains security patches for vulnerabilities including customer information leaks and remote code execution.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/magento.com\/security\/patches\/magento-206-security-update\"><font color=\"#0066cc\">https:\/\/magento.com\/security\/patches\/magento-206-security-update<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/magento-security-update","alert_type":396,"serial_number":"AV16-083","subject":null,"moderation_state":"archived","external_url":null},{"nid":768,"title":"Cisco Multiple Security Advisories","uuid":"65016f67-96d3-4935-b9cc-eeac864a0c61","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-22T18:52:54Z","summary":null,"body":["<article data-history-node-id=\"768\" about=\"\/en\/alerts-advisories\/cisco-multiple-security-advisories-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-084<br \/>\nDate: 19 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address critical and high vulnerabilities in the following software:<\/p>\n\n<p>Critical<\/p>\n\n<ul><li>Cisco ASA Software IKEv1 and IKEv2 Buffer Overflow Vulnerability (Updated)<\/li>\n<\/ul><p>High<\/p>\n\n<ul><li>Cisco Web Security Appliance HTTP POST Denial of Service Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance Cached Range Request Denial of Service Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance Connection Denial of Service Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance HTTP Length Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE Reference: CVE-2016-1287, CVE-2016-1380, CVE-2016-1381, CVE-2016-1383, CVE-2016-1382<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160210-asa-ike\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160210-asa-ike<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa4<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160518-wsa3<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-multiple-security-advisories-4","alert_type":396,"serial_number":"AV16-084","subject":null,"moderation_state":"archived","external_url":null},{"nid":1258,"title":"Google Releases security update for Chrome","uuid":"61bad07e-7ae0-4324-bca0-5d9188995be3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:14Z","date_created":"2018-06-22T18:59:41Z","summary":null,"body":["<article data-history-node-id=\"1258\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-085<br \/>\nDate: 26 May 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 51.0.2704.63 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference:<br \/>\nCVE-2016-1672, CVE-2016-1673, CVE-2016-1674, CVE-2016-1675, CVE-2016-1676, CVE-2016-1677, CVE-2016-1678, CVE-2016-1679, CVE-2016-1680, CVE-2016-1681, CVE-2016-1682, CVE-2016-1683, CVE-2016-1684, CVE-2016-1685, CVE-2016-1686, CVE-2016-1687, CVE-2016-1688, CVE-2016-1689, CVE-2016-1690, CVE-2016-1691, CVE-2016-1692, CVE-2016-1693, CVE-2016-1694, CVE-2016-1695<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/05\/stable-channel-update_25.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/05\/stable-channel-update_25.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-8","alert_type":396,"serial_number":"AV16-085","subject":null,"moderation_state":"archived","external_url":null},{"nid":1097,"title":"Sixnet BT Series Firmware and Software security update","uuid":"fa0277d1-f490-4ccb-97ae-b4fd7e40b754","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-22T19:06:59Z","summary":null,"body":["<article data-history-node-id=\"1097\" about=\"\/en\/alerts-advisories\/sixnet-bt-series-firmware-and-software-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-086<br \/>\nDate: 29 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Sixnet BT Series firmware and software security update released by Red Lion Controls.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Red Lion Controls released a firmware and software security update for Sixnet BT series M2M cellular routers to address a hard-coded credentials vulnerability.\u00a0 An attacker could remotely exploit this vulnerability by using the hard-coded factory password to gain full access to affected devices.<\/p>\n\n<p>Affected versions:<br \/>\nSixnet BT-5xxx and BT-6xxx series M2M cellular routers versions prior to 3.8.21.<\/p>\n\n<p>CVE Reference: CVE-2016-4521<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>ICS-CERT Advisory (ICSA-16-147-02)<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-147-02\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-147-02<\/font><\/a><\/p>\n\n<p>Sixnet Industrial Wireless Software and Firmware<br \/><a href=\"http:\/\/www.redlion.net\/resources\/software\/sixnet-software\/industrial-wireless-software-firmware\"><font color=\"#0066cc\">http:\/\/www.redlion.net\/resources\/software\/sixnet-software\/industrial-wireless-software-firmware<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sixnet-bt-series-firmware-and-software-security-update","alert_type":396,"serial_number":"AV16-086","subject":null,"moderation_state":"archived","external_url":null},{"nid":931,"title":"PHP security updates","uuid":"ac8df5fd-c341-4019-a4ed-fd5a22e1a06c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-22T19:15:23Z","summary":null,"body":["<article data-history-node-id=\"931\" about=\"\/en\/alerts-advisories\/php-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-087<br \/>\nDate: 30 May 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple PHP security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>PHP has released multiple security updates for vulnerabilities in versions prior to 7.0.7, 5.6.22, and 5.5.36. Those updates include patches to address vulnerabilities which could potentially allow an attacker to perform arbitrary code execution.<\/p>\n\n<p>Additionally as of July 10, 2016, PHP 5.5 will have reached its end of life and will no longer be supported.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends organizations consult with vendors for confirmation on whether their products and\/or service providers are utilizing vulnerable versions of PHP. As vendor-released updates become available, organizations should test and deploy updates to affected applications\/platforms accordingly.<br \/>\nMigration to an updated development platform can present unique challenges and it is critical that organizations operating PHP 5.5 plan and test a migration solution before the deadline.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>PHP 5 Changelog - <a href=\"http:\/\/php.net\/ChangeLog-5.php\"><font color=\"#0066cc\">http:\/\/php.net\/ChangeLog-5.php<\/font><\/a><\/li>\n\t<li>PHP 7 Changelog - <a href=\"http:\/\/php.net\/ChangeLog-7.php\"><font color=\"#0066cc\">http:\/\/php.net\/ChangeLog-7.php<\/font><\/a><\/li>\n\t<li>PHP Supported Versions - <a href=\"http:\/\/php.net\/supported-versions.php\"><font color=\"#0066cc\">http:\/\/php.net\/supported-versions.php<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-updates-0","alert_type":396,"serial_number":"AV16-087","subject":null,"moderation_state":"archived","external_url":null},{"nid":1201,"title":"Google Releases security update for Chrome","uuid":"74bd8e8c-9448-45e1-b2c8-ab54d1179ab1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-22T19:22:45Z","summary":null,"body":["<article data-history-node-id=\"1201\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-088<br \/>\nDate: 02 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 51.0.2704.79 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References:<br \/>\nCVE-2016-1696, CVE-2016-1697, CVE-2016-1698, CVE-2016-1699, CVE-2016-1700, CVE-2016-1701, CVE-2016-1702, CVE-2016-1703<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/06\/stable-channel-update.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/06\/stable-channel-update.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-9","alert_type":396,"serial_number":"AV16-088","subject":null,"moderation_state":"archived","external_url":null},{"nid":809,"title":"Cisco Prime Network Analysis Module Security Advisories","uuid":"60c1dfa9-aa25-4706-920f-0d3b21d299a2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-22T19:29:16Z","summary":null,"body":["<article data-history-node-id=\"809\" about=\"\/en\/alerts-advisories\/cisco-prime-network-analysis-module-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-089<br \/>\nDate: 02 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address multiple vulnerabilities:<\/p>\n\n<ul><li>Cisco Prime Network Analysis Module Unauthenticated Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco Prime Network Analysis Module IPv6 Denial of Service Vulnerability<\/li>\n\t<li>Cisco Prime Network Analysis Module Authenticated Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco Prime Network Analysis Module Local Command Injection Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2016-1370, CVE-2016-1388, CVE-2016-1390, CVE-2016-1391<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime1<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime2<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime3\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160601-prime3<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-prime-network-analysis-module-security-advisories","alert_type":396,"serial_number":"AV16-089","subject":null,"moderation_state":"archived","external_url":null},{"nid":893,"title":"GE MultiLink Series Switch security updates","uuid":"7b34e9cc-6a3d-4d33-bd61-46a09fffced4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-22T19:36:39Z","summary":null,"body":["<article data-history-node-id=\"893\" about=\"\/en\/alerts-advisories\/ge-multilink-series-switch-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-090<br \/>\nDate: 3 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Multilink Series firmware security updates released by General Electric.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>General Electric released firmware security updates for GE MultiLink Series switches to address a hard-coded credentials vulnerability.\u00a0 An attacker could remotely exploit this vulnerability by using the hard-coded factory password to gain full access to affected devices.<\/p>\n\n<p>Affected versions:<\/p>\n\n<p>GE ML800 Switch, firmware versions prior to Version 5.5.0,<br \/>\nGE ML810 Switch, firmware versions prior to Version 5.5.0k,<br \/>\nGE ML1200 Switch, firmware versions prior to Version 5.5.0,<br \/>\nGE ML1600 Switch, firmware versions prior to Version 5.5.0,<br \/>\nGE ML2400 Switch, firmware versions prior to Version 5.5.0,<br \/>\nGE ML3000 Switch, firmware versions prior to Version 5.5.0k, and<br \/>\nGE ML3100 Switch, firmware versions prior to Version 5.5.0k.<\/p>\n\n<p>CVE Reference: CVE-2016-2310<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>ICS-CERT Advisory (ICSA-16-147-02)<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-154-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-154-01<\/font><\/a><\/p>\n\n<p>ML800 switch firmware update:<br \/><a href=\"https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml800&amp;type=7\"><font color=\"#0066cc\">https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml800&amp;type=7<\/font><\/a><\/p>\n\n<p>ML810 switch firmware update:<br \/><a href=\"https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml810&amp;type=7\"><font color=\"#0066cc\">https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml810&amp;type=7<\/font><\/a><\/p>\n\n<p>ML1200 switch firmware update:<br \/><a href=\"https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml1200&amp;type=7\"><font color=\"#0066cc\">https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml1200&amp;type=7<\/font><\/a><\/p>\n\n<p>ML1600 switch firmware update:<br \/><a href=\"https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml1600&amp;type=7\"><font color=\"#0066cc\">https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml1600&amp;type=7<\/font><\/a><\/p>\n\n<p>ML2400 switch firmware update:<br \/><a href=\"https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml2400&amp;type=7\"><font color=\"#0066cc\">https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml2400&amp;type=7<\/font><\/a><\/p>\n\n<p>ML3000 and ML3100 firmware update:<br \/><a href=\"https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml3000&amp;type=7\"><font color=\"#0066cc\">https:\/\/www.gegridsolutions.com\/app\/Resources.aspx?prod=ml3000&amp;type=7<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ge-multilink-series-switch-security-updates","alert_type":396,"serial_number":"AV16-090","subject":null,"moderation_state":"archived","external_url":null},{"nid":1075,"title":"Network Time Protocol Daemon (ntpd) Security Notice","uuid":"2db9bfd6-a263-4a1b-ad8a-81adbed0b796","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-25T13:28:33Z","summary":null,"body":["<article data-history-node-id=\"1075\" about=\"\/en\/alerts-advisories\/network-time-protocol-daemon-ntpd-security-notice\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-091<br \/>\nDate: 3 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Security Notice for Network Time Protocol Daemon (ntpd).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of vulnerabilities (1 high, 4 low) in the Network Time Protocol Daemon (ntpd) which if exploited, could allow a remote unauthenticated attacker to cause a denial-of-service condition in ntpd.<\/p>\n\n<p>Affected versions: ntpd versions prior to 4.2.8p8<\/p>\n\n<p>CVE References:\u00a0 CVE-2016-4953, CVE-2016-4954, CVE-2016-4955, CVE-2016-4956, CVE-2016-4957<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly or consider applying the workarounds.<\/p>\n\n<p>References:<\/p>\n\n<p>NTP Security Notice - June 2016 ntp-4.2.8p8 NTP:<br \/><a href=\"http:\/\/support.ntp.org\/bin\/view\/Main\/SecurityNotice\"><font color=\"#0066cc\">http:\/\/support.ntp.org\/bin\/view\/Main\/SecurityNotice<\/font><\/a><\/p>\n\n<p>CERT\/CC Vulnerability Note 321640:<br \/><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/321640\"><font color=\"#0066cc\">https:\/\/www.kb.cert.org\/vuls\/id\/321640<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/network-time-protocol-daemon-ntpd-security-notice","alert_type":396,"serial_number":"AV16-091","subject":null,"moderation_state":"archived","external_url":null},{"nid":1041,"title":"Mozilla Releases security updates","uuid":"1701939d-1c9a-4622-9cce-53c5dccf52f4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-25T13:46:35Z","summary":null,"body":["<article data-history-node-id=\"1041\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-092<br \/>\nDate: 8 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which upgrades are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address multiple vulnerabilities in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 47.0<br \/>\nESR versions 45.x prior to 45.2<\/p>\n\n<p>CVE Reference: CVE-2016-2815, CVE-2016-2818, CVE-2016-2819, CVE-2016-2821, CVE-2016-2822, CVE-2016-2824, CVE-2016-2825, CVE-2016-2826, CVE-2016-2828, CVE-2016-2829, CVE-2016-2831, CVE-2016-2832, CVE-2016-2833, CVE-2016-2834<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/#firefox47\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/#firefox47<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox-esr\/#firefoxesr45.2\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox-esr\/#firefoxesr45.2<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-1","alert_type":396,"serial_number":"AV16-092","subject":null,"moderation_state":"archived","external_url":null},{"nid":1166,"title":"Trihedral VTScada Software security update","uuid":"d0ee0bae-a8cf-4c46-b5bf-94c4f9787f0a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-25T13:53:08Z","summary":null,"body":["<article data-history-node-id=\"1166\" about=\"\/en\/alerts-advisories\/trihedral-vtscada-software-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-093<br \/>\nDate: 9 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a VTScada security update released by Trihedral Engineering.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Trihedral Engineering released a security update for VTScada software to address multiple vulnerabilities (high to critical).\u00a0 An attacker could remotely exploit these vulnerabilities to read arbitrary files or cause denial-of-service conditions.<\/p>\n\n<p>Affected versions:<br \/>\nVTScada after version 8 and prior to version 11.2.02<\/p>\n\n<p>CVE References: CVE-2016-4510, CVE-2016-4523, CVE-2016-4532<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>ICS-CERT Advisory (ICSA-16-159-01):<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-159-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-159-01<\/font><\/a><\/p>\n\n<p>Trihedral VTScada Security Updates (FTP):<br \/><a href=\"ftp:\/\/ftp.trihedral.com\/VTS\/\"><font color=\"#0066cc\">ftp:\/\/ftp.trihedral.com\/VTS\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trihedral-vtscada-software-security-update","alert_type":396,"serial_number":"AV16-093","subject":null,"moderation_state":"archived","external_url":null},{"nid":1213,"title":"VMware security advisory","uuid":"b75e2cfc-4dea-4259-af4a-57aa652f8ca4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-25T14:01:24Z","summary":null,"body":["<article data-history-node-id=\"1213\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-094<br \/>\nDate: 11 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware product update addresses a critical security issue in VMware NSX and vCNS:<\/p>\n\n<p>Affected Products:<br \/>\nNSX 6.2 prior to 6.2.3<br \/>\nNSX 6.1 prior to 6.1.7<br \/>\nvCNS 5.5.4 prior to 5.5.4.3<\/p>\n\n<p>CVE Reference: CVE-2016-2079<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0007.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0007.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-0","alert_type":396,"serial_number":"AV16-094","subject":null,"moderation_state":"archived","external_url":null},{"nid":1319,"title":"Siemens SIMATIC S7-300 Firmware security update","uuid":"c0f737be-7d3e-4c0f-90ad-29b2493908df","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-25T14:07:55Z","summary":null,"body":["<article data-history-node-id=\"1319\" about=\"\/en\/alerts-advisories\/siemens-simatic-s7-300-firmware-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-095<br \/>\nDate: 11 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a SIMATIC S7-300 security update released by Siemens.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Siemens released a security update for the SIMATIC S7-300 to address a critical vulnerability.\u00a0 An attacker could remotely exploit these vulnerabilities to cause denial-of-service conditions.<\/p>\n\n<p>Affected versions:<br \/>\nSiemens SIMATIC S7-300 with Profinet support prior to version 3.2.12<br \/>\nSiemens SIMATIC S7-300 without Profinet support prior to version 3.3.12<\/p>\n\n<p>CVE References: CVE-2016-3949<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Siemens Advisory SSA-818183:<br \/><a href=\"http:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-818183.pdf\"><font color=\"#0066cc\">http:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-818183.pdf<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/siemens-simatic-s7-300-firmware-security-update","alert_type":396,"serial_number":"AV16-095","subject":null,"moderation_state":"archived","external_url":null},{"nid":912,"title":"Android security bulletin \u2013 June 2016","uuid":"0fdb8e90-f358-467c-bce0-959e3f598664","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-25T14:15:26Z","summary":null,"body":["<article data-history-node-id=\"912\" about=\"\/en\/alerts-advisories\/android-security-bulletin-june-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-096<br \/>\nDate: June 14, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for June.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulleting addresses a security update for 21 vulnerabilities (6 Critical, 11 High, 4 Moderate) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2016-2061, CVE-2016-2062, CVE-2016-2066, CVE-2016-2463, CVE-2016-2464, CVE-2016-2465, CVE-2016-2466, CVE-2016-2467, CVE-2016-2468, CVE-2016-2469, CVE-2016-2470, CVE-2016-2471, CVE-2016-2472, CVE-2016-2473, CVE-2016-2474, CVE-2016-2475, CVE-2016-2476, CVE-2016-2477, CVE-2016-2478, CVE-2016-2479, CVE-2016-2480, CVE-2016-2481, CVE-2016-2482, CVE-2016-2483, CVE-2016-2484, CVE-2016-2485, CVE-2016-2486, CVE-2016-2487, CVE-2016-2488, CVE-2016-2489, CVE-2016-2490, CVE-2016-2491, CVE-2016-2492, CVE-2016-2493, CVE-2016-2494, CVE-2016-2495, CVE-2016-2496, CVE-2016-2498, CVE-2016-2499, CVE-2016-2500<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Android web site: <a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-06-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-06-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-june-2016","alert_type":396,"serial_number":"AV16-096","subject":null,"moderation_state":"archived","external_url":null},{"nid":916,"title":"Microsoft Critical security bulletins Summary for June 2016","uuid":"7d112833-e25c-4374-b0a7-d607910022bc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-25T14:39:36Z","summary":null,"body":["<article data-history-node-id=\"916\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-june-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-097<br \/>\nDate: 14 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for June 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 16 bulletins (5 Critical and\u00a011 Important), which addresses multiple vulnerabilities<br \/>\nin Internet Explorer, Microsoft Edge, JScript and VBScript, Microsoft Office, Windows DNS Server, Group Policy, Windows Kernel-Mode Drivers, Microsoft Graphics Component, Windows SMB Server, Netlogon, WPAD, Windows Diagnostic Hub, Microsoft Exchange Server, Windows PDF, Active Directory and Windows Search Component.<\/p>\n\n<p>***Critical***<br \/>\nMS16-063\u00a0\u00a0Cumulative Security Update for Internet Explorer (3163649)<br \/>\nMS16-068\u00a0\u00a0Cumulative Security Update for Microsoft Edge (3163656)<br \/>\nMS16-069\u00a0\u00a0Cumulative Security Update for JScript and VBScript (3163640)<br \/>\nMS16-070\u00a0\u00a0Security Update for Microsoft Office (3163610)<br \/>\nMS16-071\u00a0\u00a0Security Update for Microsoft Windows DNS Server (3164065)<\/p>\n\n<p>***Important***<br \/>\nMS16-072\u00a0\u00a0Security Update for Group Policy (3163622)<br \/>\nMS16-073\u00a0\u00a0Security Update for Windows Kernel-Mode Drivers (3164028)<br \/>\nMS16-074\u00a0\u00a0Security Update for Microsoft Graphics Component (3164036)<br \/>\nMS16-075\u00a0\u00a0Security Update for Windows SMB Server (3164038)<br \/>\nMS16-076\u00a0\u00a0Security Update for Netlogon (3167691)<br \/>\nMS16-077\u00a0\u00a0Security Update for WPAD (3165191)<br \/>\nMS16-078\u00a0\u00a0Security Update for Windows Diagnostic Hub (3165479)<br \/>\nMS16-079\u00a0\u00a0Security Update for Microsoft Exchange Server (3160339)<br \/>\nMS16-080\u00a0\u00a0Security Update for Microsoft Windows PDF (3164302)<br \/>\nMS16-081\u00a0\u00a0Security Update for Active Directory (3160352)<br \/>\nMS16-082\u00a0\u00a0Security Update for Microsoft Windows Search Component (3165270)<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/library\/security\/ms16-jun\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/library\/security\/ms16-jun<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-june-2016","alert_type":396,"serial_number":"AV16-097","subject":null,"moderation_state":"archived","external_url":null},{"nid":1122,"title":"Adobe security bulletins and Advisories","uuid":"613f423c-fceb-4693-8721-64324b0f5714","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:29Z","date_created":"2018-06-25T14:46:43Z","summary":null,"body":["<article data-history-node-id=\"1122\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-and-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-098<br \/>\nDate: 14 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Adobe security bulletins and advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released 5 Security Bulletins, addressing security vulnerabilities in 5 specific Adobe products. \u00a0<\/p>\n\n<p>APSA16-03: Security Advisory for Adobe Flash Player \u2013 Versions 21.0.0.242 and earlier.<br \/>\nCVE Reference: CVE-2016-4171.<\/p>\n\n<p>APSB16-19: Security Updates available for Adobe DNG SDK - 1.4 (2012 release) and earlier versions.<br \/>\nCVE Reference: CVE-2016-4167.<\/p>\n\n<p>APSB16-20: Security Update for Adobe Brackets \u2013 Versions 1.6 and earlier.<br \/>\nCVE References: CVE-2016-4164, CVE-2016-4165.<\/p>\n\n<p>APSB16-21: Security Update for Creative Cloud Desktop Application for Windows \u2013 Versions 3.6.0.248\u00a0\u00a0\u00a0<br \/>\nCVE References: CVE-2016-4157, CVE-2016-4158.<\/p>\n\n<p>APSB16-22: Security Update: Hotfixes available for ColdFusion, versions 10, 11 and the 2016 release.<br \/>\nCVE Reference: CVE-2016-4159.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-and-advisories","alert_type":396,"serial_number":"AV16-098","subject":null,"moderation_state":"archived","external_url":null},{"nid":1189,"title":"SAP Security Notes - June 2016","uuid":"4f54acef-4c66-49ef-8e07-714ee00f0345","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-25T14:55:20Z","summary":null,"body":["<article data-history-node-id=\"1189\" about=\"\/en\/alerts-advisories\/sap-security-notes-june-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-099<br \/>\nDate: 15 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Security Notes by SAP.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>SAP has released 13 Security Notes as part of their June Security Patch Day designed to address multiple vulnerabilities (including 1 critical, 3 high) in several SAP products. Two updates are also available relating to previously released Patch Day Security Notes. Vulnerabilities addressed in the June Security Patch Day Security Notes include: Cross Site Scripting, Missing Authorization Check, Denial of Service, Information Disclosure, and Code Injection.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released update to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"http:\/\/scn.sap.com\/community\/security\/blog\/2016\/06\/14\/sap-security-patch-day--june-2016\"><font color=\"#0066cc\">http:\/\/scn.sap.com\/community\/security\/blog\/2016\/06\/14\/sap-security-patch-day--june-2016<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/scn.sap.com\/community\/security\/blog\/2016\/06\/15\/sap-security-notes-june-2016--review\"><font color=\"#0066cc\">http:\/\/scn.sap.com\/community\/security\/blog\/2016\/06\/15\/sap-security-notes-june-2016--review<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-notes-june-2016","alert_type":396,"serial_number":"AV16-099","subject":null,"moderation_state":"archived","external_url":null},{"nid":770,"title":"Cisco Releases security update","uuid":"81928a3c-d42f-4c3e-8f94-77f0468ea567","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-25T15:04:56Z","summary":null,"body":["<article data-history-node-id=\"770\" about=\"\/en\/alerts-advisories\/cisco-releases-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-100<br \/>\nDate: 16 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Cisco security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address a critical vulnerability in the web interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and the Cisco RV215W Wireless-N VPN Router. This vulnerability could allow an authenticated, remote attacker to execute arbitrary code as root on a targeted system.<\/p>\n\n<p>CVE Reference: CVE-2016-1395<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160615-rv\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160615-rv<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-update","alert_type":396,"serial_number":"AV16-100","subject":null,"moderation_state":"archived","external_url":null},{"nid":1252,"title":"security updates for Adobe Flash and AIR","uuid":"6b5415e7-3bd3-4d06-965d-d02b75de23d5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:14Z","date_created":"2018-06-25T15:11:25Z","summary":null,"body":["<article data-history-node-id=\"1252\" about=\"\/en\/alerts-advisories\/security-updates-adobe-flash-and-air\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-101<br \/>\nDate: 16 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Adobe Flash Player and AIR.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-18 and Security Bulletin APSB16-23 to address critical vulnerabilities that could allow an attacker to take control of vulnerable systems. All OS platform are reported as being impacted by APSB16-18, while Windows platform is affected in APSB16-23.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime 21.0.0.242 and earlier<\/li>\n\t<li>Adobe Flash Player Extended Support Release 18.0.0.352 and earlier<\/li>\n\t<li>Adobe Flash Player for Google Chrome 21.0.0.242 and earlier<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 21.0.0.242 and earlier<\/li>\n\t<li>Adobe Flash Player for Linux 11.2.202.621 and earlier<\/li>\n\t<li>Adobe AIR Desktop Runtime 21.0.0.215 and earlier<\/li>\n<\/ul><p>CVE References: CVE-2016-4116, CVE-2016-4122, CVE-2016-4123, CVE-2016-4124, CVE-2016-4125, CVE-2016-4127, CVE-2016-4128, CVE-2016-4129, CVE-2016-4130, CVE-2016-4131, CVE-2016-4132, CVE-2016-4133, CVE-2016-4134, CVE-2016-4135, CVE-2016-4136, CVE-2016-4137, CVE-2016-4138, CVE-2016-4139, CVE-2016-4140, CVE-2016-4141, CVE-2016-4142, CVE-2016-4143, CVE-2016-4144, CVE-2016-4145, CVE-2016-4146, CVE-2016-4147, CVE-2016-4148, CVE-2016-4149, CVE-2016-4150, CVE-2016-4151, CVE-2016-4152, CVE-2016-4153, CVE-2016-4154, CVE-2016-4155, CVE-2016-4156, CVE-2016-4166, CVE-2016-4171<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>Adobe Security Bulletin - Adobe Flash Player (APSB16-18):<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-18.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-18.html<\/font><\/a><\/li>\n\t<li>Adobe Security Bulletin - Adobe AIR (APSB16-23):<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/air\/apsb16-23.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/air\/apsb16-23.html<\/font><\/a><\/li>\n\t<li>CCIRC Alert AL16-012: Active Exploitation of Vulnerability in Adobe Flash Player:<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/al16-012-en.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2016\/al16-012-en.aspx<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-adobe-flash-and-air","alert_type":396,"serial_number":"AV16-101","subject":null,"moderation_state":"archived","external_url":null},{"nid":1098,"title":"Google Releases security update for Chrome","uuid":"11536d50-cb12-4bcc-98a7-8a94292e48d8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-25T15:18:02Z","summary":null,"body":["<article data-history-node-id=\"1098\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-102<br \/>\nDate: 20 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 51.0.2704.103 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References:<br \/>\nCVE-2016-1704<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/06\/stable-channel-update_16.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/06\/stable-channel-update_16.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-10","alert_type":396,"serial_number":"AV16-102","subject":null,"moderation_state":"archived","external_url":null},{"nid":933,"title":"WordPress Security Release","uuid":"48c42cc8-5868-45ea-9d0b-884b38646702","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-25T15:23:12Z","summary":null,"body":["<article data-history-node-id=\"933\" about=\"\/en\/alerts-advisories\/wordpress-security-release-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-103<br \/>\nDate: 21 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the WordPress 4.5.3 Security Release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress versions 4.5.2 and previous are affected by multiple security issues:<\/p>\n\n<ul><li>Redirect bypass in the customizer<\/li>\n\t<li>Two different XSS problems via attachment names<\/li>\n\t<li>Revision history information disclosure<\/li>\n\t<li>oEmbed denial of service<\/li>\n\t<li>Unauthorized category removal from a post<\/li>\n\t<li>Password change via stolen cookie<\/li>\n<\/ul><p>In addition to the security issues above,\u00a0WordPress 4.5.3 fixes 17 bugs from 4.5, 4.5.1 and 4.5.2.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2016\/06\/wordpress-4-5-3\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2016\/06\/wordpress-4-5-3\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-release-1","alert_type":396,"serial_number":"AV16-103","subject":null,"moderation_state":"archived","external_url":null},{"nid":1203,"title":"libarchive security update","uuid":"7307c486-9bf8-4bb3-b31d-d9ba5b1d2400","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-25T16:26:23Z","summary":null,"body":["<article data-history-node-id=\"1203\" about=\"\/en\/alerts-advisories\/libarchive-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-104<br \/>\nDate: 21 June 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a libarchive security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A security update was released for libarchive which addresses multiple vulnerabilities.\u00a0 Exploitation of these vulnerabilities may allow for arbitrary remote code execution.\u00a0 The libarchive library is included with and leveraged by several hardware and software products.<\/p>\n\n<p>Affected Versions: libarchive versions prior to 3.2.1<\/p>\n\n<p>CVE References: CVE-2016-4300, CVE-2016-4301, CVE-2016-4302<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization's critical services, and follow their patch management process accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Cisco Talos (vulnerability report):<br \/><a href=\"http:\/\/blog.talosintel.com\/2016\/06\/the-poisoned-archives.html\"><font color=\"#0066cc\">http:\/\/blog.talosintel.com\/2016\/06\/the-poisoned-archives.html<\/font><\/a>\u00a0<\/p>\n\n<p>libarchive:<br \/><a href=\"http:\/\/libarchive.org\/\"><font color=\"#0066cc\">http:\/\/libarchive.org\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/libarchive-security-update","alert_type":396,"serial_number":"AV16-104","subject":null,"moderation_state":"archived","external_url":null},{"nid":811,"title":"Fonality security update","uuid":"860f90d2-47d8-4681-ba1e-4d48e2b563a2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-25T16:33:42Z","summary":null,"body":["<article data-history-node-id=\"811\" about=\"\/en\/alerts-advisories\/fonality-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-105<br \/>\nDate: 22 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Fonality security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A security update was released for Fonality (previously trixbox Pro) which addresses multiple critical vulnerabilities.\u00a0 Exploitation of these vulnerabilities may allow a malicious attacker to perform remote code execution with root user privilege, and allow for the unauthorized disclosure of encrypted data.<\/p>\n\n<p>Affected Versions: Fonality versions prior to 12.6<\/p>\n\n<p>CVE References: CVE-2016-2362, CVE-2016-2363, CVE-2016-2364<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>NIST National Vulnerability Database:<\/p>\n\n<ul><li><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-2362\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-2362<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-2363\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-2363<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-2364\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-2364<\/font><\/a><\/li>\n<\/ul><p>CERT\/CC Vulnerability Note VU#754056:<\/p>\n\n<ul><li><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/754056\"><font color=\"#0066cc\">http:\/\/www.kb.cert.org\/vuls\/id\/754056<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fonality-security-update","alert_type":396,"serial_number":"AV16-105","subject":null,"moderation_state":"archived","external_url":null},{"nid":885,"title":"Symantec Releases security update","uuid":"93b1df3f-5f4e-4ff3-9f0e-ce98dcdee22f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-25T16:42:34Z","summary":null,"body":["<article data-history-node-id=\"885\" about=\"\/en\/alerts-advisories\/symantec-releases-security-update-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-106<br \/>\nDate: 29 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released Symantec security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Symantec has released a Security Advisory to address critical vulnerabilities that could allow a remote attacker to execute arbitrary code on affected systems.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Advanced Threat Protection (ATP)<\/li>\n\t<li>Symantec Data Center Server (SDCS:SA) versions 6.5 MP1 and 6.6 MP1<\/li>\n\t<li>Symantec Critical System Protection (SCSP) version 5.2.9 MP6<\/li>\n\t<li>Symantec Embedded Systems Critical System Protection (SES:CSP) versions 1.0 MP5 and 6.5.0 MP1<\/li>\n\t<li>Symantec Web Security .Cloud<\/li>\n\t<li>Email Security Server .Cloud (ESS)<\/li>\n\t<li>Symantec Web Gateway<\/li>\n\t<li>Symantec Endpoint Protection (SEP) versions 12.1.6 MP4 and prior<\/li>\n\t<li>Symantec Endpoint Protection for Mac (SEP for Mac) versions 12.1.6 MP4 and prior<\/li>\n\t<li>Symantec Endpoint Protection for Mac (SEP for Mac) versions 12.1.6 MP4 and prior<\/li>\n\t<li>Symantec Endpoint Protection for Linux (SEP for Linux) versions 12.1.6 MP4 and prior<\/li>\n\t<li>Symantec Protection Engine (SPE) versions 7.0.5 and prior, and 7.5.4 and prior (AWS platform)<\/li>\n\t<li>Symantec Protection for SharePoint Servers (SPSS) versions 6.03 to 6.05, and 6.0.6 and prior<\/li>\n\t<li>Symantec Mail Security for Microsoft Exchange (SMSMSE) versions 7.0.4 and prior, and 7.5.4 and prior<\/li>\n\t<li>Symantec Mail Security for Domino (SMSDOM) versions 8.0.9 and prior, and 8.1.3 and prior<\/li>\n\t<li>CSAPI versions 10.0.4 and prior<\/li>\n\t<li>Symantec Message Gateway (SMG) versions 10.6.1-3 and prior<\/li>\n\t<li>Symantec Message Gateway for Service Providers (SMG-SP) versions 10.5 and 10.6<\/li>\n\t<li>Norton AntiVirus prior to NGC 22.7<\/li>\n\t<li>Norton Security prior to NGC 22.7<\/li>\n\t<li>Norton Security with Backup prior to NGC 22.7<\/li>\n\t<li>Norton Internet Security prior to NGC 22.7<\/li>\n\t<li>Norton 360 prior to NGC 22.7<\/li>\n\t<li>Norton Security for Mac prior to 13.0.2<\/li>\n\t<li>Norton Power Eraser (NPE) prior to 5.1<\/li>\n\t<li>Norton Bootable Removal Tool (NBRT) prior 2016.1<\/li>\n<\/ul><p>CVE References: CVE-2016-2207, CVE-2016-2209, CVE-2016-2210, CVE-2016-2211, CVE-2016-3644, CVE-2016-3645, CVE-2016-3646<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=&amp;suid=20160628_00\"><font color=\"#0066cc\">https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=&amp;suid=20160628_00<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/symantec-releases-security-update-1","alert_type":396,"serial_number":"AV16-106","subject":null,"moderation_state":"archived","external_url":null},{"nid":1076,"title":"Multiple Cisco Security Advisories","uuid":"0ce4537e-bf54-4d99-8bf0-9aeada0e99c2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-25T16:56:16Z","summary":null,"body":["<article data-history-node-id=\"1076\" about=\"\/en\/alerts-advisories\/multiple-cisco-security-advisories-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-107<br \/>\nDate: 30 June 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address multiple vulnerabilities:<\/p>\n\n<ul><li>Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco Prime Infrastructure and Evolved Programmable Network Manager Authentication Bypass API Vulnerability<\/li>\n\t<li>Cisco Firepower System Software Static Credential Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Lightweight Directory Access Protocol Authentication Bypass Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2016-1289, CVE-2016-1394, CVE-2016-1408, CVE-2016-1416<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-pi-epnm\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-pi-epnm<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-piauthbypass\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-piauthbypass<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-fp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-fp<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-cpcpauthbypass\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160629-cpcpauthbypass<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-cisco-security-advisories-0","alert_type":396,"serial_number":"AV16-107","subject":null,"moderation_state":"archived","external_url":null},{"nid":1043,"title":"Apache Releases update for HTTPD","uuid":"4fff9fe2-a93f-4bd8-bc7e-ebccf20e042e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-25T17:02:45Z","summary":null,"body":["<article data-history-node-id=\"1043\" about=\"\/en\/alerts-advisories\/apache-releases-update-httpd\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-108<br \/>\nDate: 05 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the newest release of the Apache HTTPD Server, Version 2.4.23.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apache has released its newest version of the HTTPD Web Server. Version 2.4.23 is considered to be a feature and bug fix release with many improvements and enhancements over the previous 2.X versions. Specifically, Version 2.4.23 addresses an issue whereby a third party could gain access to resources on the web server with a bypass of the TLS certificate Authentication if http\/2 is enabled.<br \/>\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\nApache HTTPD Server 2.4.23 is currently available for download.<\/p>\n\n<p>CVE References: CVE-2016-4979<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to available documentation with regards to testing and deploying the newest Apache version.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>Release Info: <a href=\"http:\/\/www.apache.org\/dist\/httpd\/Announcement2.4.html\"><font color=\"#0066cc\">http:\/\/www.apache.org\/dist\/httpd\/Announcement2.4.html<\/font><\/a><\/li>\n\t<li>Changes Made in Release: <a href=\"http:\/\/www.apache.org\/dist\/httpd\/CHANGES_2.4.23\"><font color=\"#0066cc\">http:\/\/www.apache.org\/dist\/httpd\/CHANGES_2.4.23<\/font><\/a> \u00a0<\/li>\n\t<li>Features Description: <a href=\"http:\/\/httpd.apache.org\/docs\/2.4\/new_features_2_4.html\"><font color=\"#0066cc\">http:\/\/httpd.apache.org\/docs\/2.4\/new_features_2_4.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-releases-update-httpd","alert_type":396,"serial_number":"AV16-108","subject":null,"moderation_state":"archived","external_url":null},{"nid":1168,"title":"Android security bulletin \u2013 July 2016","uuid":"57c290fe-a4d8-4353-9e8c-953fa0c5dd13","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-25T17:17:40Z","summary":null,"body":["<article data-history-node-id=\"1168\" about=\"\/en\/alerts-advisories\/android-security-bulletin-july-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-109<br \/>\nDate: July 07, 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for July.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulleting addresses a security update for 108 vulnerabilities (9 Critical, 29 High, 16 Moderate) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2016-2506, CVE-2016-2505, CVE-2016-2507, CVE-2016-2508, CVE-2016-3741,<br \/>\nCVE-2016-3742, CVE-2016-3743, CVE-2016-2108, CVE-2016-2503, CVE-2016-2067, CVE-2016-3767,<br \/>\nCVE-2016-3768, CVE-2016-3769, CVE-2016-3770, CVE-2016-3771, CVE-2016-3772, CVE-2016-3773,<br \/>\nCVE-2016-3774, CVE-2016-3775, CVE-2015-8816, CVE-2016-3744, CVE-2016-3751, CVE-2016-3745,<br \/>\nCVE-2016-3746, CVE-2016-3747, CVE-2016-3748, CVE-2016-3749, CVE-2016-3750, CVE-2016-3752,<br \/>\nCVE-2016-3753, CVE-2016-2107, CVE-2016-3754, CVE-2016-3755, CVE-2016-3756, CVE-2016-3818,<br \/>\nCVE-2014-9794, CVE-2014-9795, CVE-2015-8892, CVE-2013-7457, CVE-2014-9781, CVE-2014-9786,<br \/>\nCVE-2014-9788, CVE-2014-9779, CVE-2014-9780, CVE-2014-9789, CVE-2014-9793, CVE-2014-9782,<br \/>\nCVE-2014-9783, CVE-2014-9785, CVE-2014-9787, CVE-2014-9784, CVE-2014-9777, CVE-2014-9778,<br \/>\nCVE-2014-9790, CVE-2014-9792, CVE-2014-9797, CVE-2014-9791, CVE-2014-9796, CVE-2014-9800,<br \/>\nCVE-2014-9799, CVE-2014-9801, CVE-2014-9802, CVE-2015-8891, CVE-2015-8888, CVE-2015-8889,<br \/>\nCVE-2015-8890, CVE-2016-2502, CVE-2016-3792, CVE-2016-2501, CVE-2016-3793, CVE-2016-3794,<br \/>\nCVE-2016-3795, CVE-2016-3796, CVE-2016-3797, CVE-2016-3798, CVE-2016-3799, CVE-2016-3800,<br \/>\nCVE-2016-3801, CVE-2016-3802, CVE-2016-3803, CVE-2016-3804, CVE-2016-3805, CVE-2016-3806,<br \/>\nCVE-2016-3807, CVE-2016-3808, CVE-2016-2068, CVE-2014-9803, CVE-2016-3809, CVE-2016-3810,<br \/>\nCVE-2016-3757, CVE-2016-3758, CVE-2016-3759, CVE-2016-3760, CVE-2016-3761, CVE-2016-3762,<br \/>\nCVE-2016-3763, CVE-2016-3764, CVE-2016-3765, CVE-2016-3766, CVE-2016-3811, CVE-2016-3812,<br \/>\nCVE-2016-3813, CVE-2016-3814, CVE-2016-3815, CVE-2016-3816, CVE-2016-0723, CVE-2014-9798,<br \/>\nCVE-2015-8893<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Android web site: <a href=\"http:\/\/source.android.com\/security\/bulletin\/2016-07-01.html\"><font color=\"#0066cc\">http:\/\/source.android.com\/security\/bulletin\/2016-07-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-july-2016","alert_type":396,"serial_number":"AV16-109","subject":null,"moderation_state":"archived","external_url":null},{"nid":1215,"title":"Meinberg NTP Time Server security updates","uuid":"5ffae4e3-9a11-49da-b78f-321399664def","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-25T17:24:45Z","summary":null,"body":["<article data-history-node-id=\"1215\" about=\"\/en\/alerts-advisories\/meinberg-ntp-time-server-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-110<br \/>\nDate: 7 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>This advisory is to bring attention to a recently released Meinberg NTP firmware update addressing multiple vulnerabilities.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A firmware update was released for Meinberg NTP Time Server to address multiple vulnerabilities (high).\u00a0 Exploitation of these vulnerabilities may permit a malicious attacker to write to unspecified scripts with root user privilege, which can allow for the unauthorized disclosure and\/or modification of sensitive data.<\/p>\n\n<p>CVE References: CVE-2016-3962, CVE-2016-3988, CVE-2016-3989<\/p>\n\n<p>Versions affected:<\/p>\n\n<ul><li>IMS-LANTIME M3000 versions 6.0 and earlier<\/li>\n\t<li>IMS-LANTIME M1000 versions 6.0 and earlier<\/li>\n\t<li>IMS-LANTIME M500 versions 6.0 and earlier<\/li>\n\t<li>LANTIME M900 versions 6.0 and earlier<\/li>\n\t<li>LANTIME M600 versions 6.0 and earlier<\/li>\n\t<li>LANTIME M400 versions 6.0 and earlier<\/li>\n\t<li>LANTIME M300 versions 6.0 and earlier<\/li>\n\t<li>LANTIME M200 versions 6.0 and earlier<\/li>\n\t<li>LANTIME M100 versions 6.0 and earlier<\/li>\n\t<li>LCES versions 6.0 and earlier<\/li>\n\t<li>SyncFire 1100 versions 6.0 and earlier<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Meinberg Security Advisory:<br \/><a href=\"https:\/\/www.meinbergglobal.com\/english\/sw\/mbgsecurityadvisory.htm#mbgsa_363\"><font color=\"#0066cc\">https:\/\/www.meinbergglobal.com\/english\/sw\/mbgsecurityadvisory.htm#mbgsa_363<\/font><\/a><\/p>\n\n<p>Meinberg Firmware Updates:<br \/><a href=\"https:\/\/www.meinbergglobal.com\/english\/sw\/firmware.htm\"><font color=\"#0066cc\">https:\/\/www.meinbergglobal.com\/english\/sw\/firmware.htm<\/font><\/a><\/p>\n\n<p>ICS-CERT Advisory (ICSA-16-175-03):<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-175-03\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-175-03<\/font><\/a><\/p>\n\n<p>NIST Vulnerability Database:<br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-3962\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-3962<\/font><\/a><br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-3988\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-3988<\/font><\/a><br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-3989\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-3989<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/meinberg-ntp-time-server-security-updates","alert_type":396,"serial_number":"AV16-110","subject":null,"moderation_state":"archived","external_url":null},{"nid":1320,"title":"security updates for Multiple Adobe Products","uuid":"2b260720-efcc-4621-80f9-840e514c622a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-25T17:44:42Z","summary":null,"body":["<article data-history-node-id=\"1320\" about=\"\/en\/alerts-advisories\/security-updates-multiple-adobe-products\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-111<br \/>\nDate: 12 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for multiple Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletins APSB16-24, APSB16-25, and APSB16-26 to address critical vulnerabilities that could allow an attacker to take control of vulnerable systems. All OS platforms are reported as being impacted.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul type=\"disc\"><li>Acrobat DC 15.016.20045 and earlier versions<\/li>\n\t<li>Acrobat DC Classic 15.006.30174 and earlier versions<\/li>\n\t<li>Acrobat Reader DC 15.016.20045 and earlier versions\u00a0\u00a0\u00a0<\/li>\n\t<li>Acrobat Reader DC Classic 15.006.30174 and earlier versions<\/li>\n\t<li>Acrobat XI Desktop 11.0.16 and earlier versions<\/li>\n\t<li>Adobe Flash Player Desktop Runtime 22.0.0.192 and earlier versions<\/li>\n\t<li>Adobe Flash Player Extended Support Release 18.0.0.360 and earlier versions<\/li>\n\t<li>Adobe Flash Player for Google Chrome 22.0.0.192 and earlier versions<\/li>\n\t<li>Adobe Flash Player for Linux 11.2.202.626 and earlier versions<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 22.0.0.192 and earlier versions<\/li>\n\t<li>Adobe XMP Toolkit for Java 5.1.2 and earlier versions<\/li>\n\t<li>Reader XI Desktop 11.0.16 and earlier versions<\/li>\n<\/ul><p>CVE References: CVE-2016-4172, CVE-2016-4173, CVE-2016-4174, CVE-2016-4175,\u00a0 CVE-2016-4176, CVE-2016-4177, CVE-2016-4178,\u00a0 CVE-2016-4179, CVE-2016-4180,\u00a0 CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4185,\u00a0 CVE-2016-4186,\u00a0 CVE-2016-4187, CVE-2016-4188,\u00a0 CVE-2016-4189, CVE-2016-4190, CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4209,\u00a0 CVE-2016-4210, CVE-2016-4211,\u00a0 CVE-2016-4212,\u00a0 CVE-2016-4213,\u00a0 CVE-2016-4214,\u00a0 CVE-2016-4215, CVE-2016-4216, CVE-2016-4217,\u00a0 CVE-2016-4218,\u00a0 CVE-2016-4219, CVE-2016-4220, CVE-2016-4221,\u00a0 CVE-2016-4222, CVE-2016-4223,\u00a0 CVE-2016-4224, CVE-2016-4225, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-4230, CVE-2016-4231, CVE-2016-4232,\u00a0 CVE-2016-4233,\u00a0 CVE-2016-4234,\u00a0 CVE-2016-4235,\u00a0 CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4243, CVE-2016-4244, CVE-2016-4245, CVE-2016-4246, CVE-2016-4247, CVE-2016-4248, CVE-2016-4249, CVE-2016-4250, \u00a0CVE-2016-4251, CVE-2016-4252<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Adobe Security Bulletin:<\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/xmpcore\/apsb16-24.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/xmpcore\/apsb16-24.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-25.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-25.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-26.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-26.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-multiple-adobe-products","alert_type":396,"serial_number":"AV16-111","subject":null,"moderation_state":"archived","external_url":null},{"nid":914,"title":"Microsoft Critical security bulletins Summary - July 2016","uuid":"c8eb4053-1f17-45a8-b8db-bba879a91786","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-25T17:51:41Z","summary":null,"body":["<article data-history-node-id=\"914\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-july-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-112<br \/>\nDate: 12 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for July 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 11 bulletins (6 Critical and 5 Important), which address multiple vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office Services and Web Apps, and Microsoft Office.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS16-084\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for Internet Explorer (3169991)<\/li>\n\t<li>MS16-085\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for Microsoft Edge (3169999)<\/li>\n\t<li>MS16-086\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for JScript and VBScript (3169996)<\/li>\n\t<li>MS16-087\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Print Spooler Components (3170005)<\/li>\n\t<li>MS16-088\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Microsoft Office (3170008)<\/li>\n\t<li>MS16-093\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Adobe Flash Player (3174060)<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS16-089\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Secure Kernel Mode (3170050)<\/li>\n\t<li>MS16-090\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Kernel-Mode Drivers (3171481)<\/li>\n\t<li>MS16-091\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for .NET Framework (3170048)<\/li>\n\t<li>MS16-092\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Kernel (3171910)<\/li>\n\t<li>MS16-094\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Secure Boot (3177404)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-ca\/library\/security\/ms16-jul.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-ca\/library\/security\/ms16-jul.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-july-2016","alert_type":396,"serial_number":"AV16-112","subject":null,"moderation_state":"archived","external_url":null},{"nid":917,"title":"Drupal security updates \u2013 July 2016","uuid":"13e81af7-1d84-4f26-a539-5ae9c6922995","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-25T18:00:23Z","summary":null,"body":["<article data-history-node-id=\"917\" about=\"\/en\/alerts-advisories\/drupal-security-updates-july-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-113<br \/>\nDate: 13 July 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Drupal security releases.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple security vulnerabilities. Exploitation of these vulnerabilities may allow an unauthorized attacker to perform arbitrary remote code execution.<\/p>\n\n<p>Affected Versions:<br \/>\nWebform Multifile 7.x-1.x versions prior to 7.x-1.4<br \/>\nCoder module 7.x-1.x versions prior to 7.x-1.3<br \/>\nCoder module 7.x-2.x versions prior to 7.x-2.6<br \/>\nRESTful Web Services 7.x-2.x versions prior to 7.x-2.6<br \/>\nRESTful Web Services 7.x-1.x versions prior to 7.x-1.7<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Drupal Advisory:<br \/><a href=\"https:\/\/www.drupal.org\/psa-2016-001\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/psa-2016-001<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-updates-july-2016","alert_type":null,"serial_number":"AV16-113","subject":null,"moderation_state":"archived","external_url":null},{"nid":1124,"title":"Philips Xper-IM Connect Software updates","uuid":"05573306-d742-4bce-a132-98df9a72a8c0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:29Z","date_created":"2018-06-25T18:11:01Z","summary":null,"body":["<article data-history-node-id=\"1124\" about=\"\/en\/alerts-advisories\/philips-xper-im-connect-software-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-114<br \/>\nDate: 15 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a software update for the Xper-IM Connect system by Philips.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Philips released a software update for the Xper-IM Connect system to address multiple vulnerabilities (critical to high).\u00a0 Successful exploitation of these vulnerabilities may allow a remote attacker to compromise the Xper-IM Connect system.\u00a0 These vulnerabilities may include, but are not limited to, arbitrary code execution, code injection and information disclosure.<\/p>\n\n<p>Affected versions:<br \/><br \/>\nXper-IM Connect systems on Windows XP versions 1.5.12 and prior<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0 For more information, please refer to the ICS-CERT reference.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSMA-16-196-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSMA-16-196-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/philips-xper-im-connect-software-updates","alert_type":396,"serial_number":"AV16-114","subject":null,"moderation_state":"archived","external_url":null},{"nid":1180,"title":"Cisco Releases security updates","uuid":"1fad2d5b-00e3-4bf6-b6a1-c1716d516a19","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-25T18:20:25Z","summary":null,"body":["<article data-history-node-id=\"1180\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-115<br \/>\nDate: 15 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to high) in Cisco IOS XR and Cisco ASR 5000 Series SNMP.<\/p>\n\n<p>CVE Reference: CVE-2016-1426, CVE-2016-1452, CVE-2016-1456<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160713-ncs6k\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160713-ncs6k<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160714-ios-xr\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160714-ios-xr<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160713-asr\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160713-asr<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates","alert_type":396,"serial_number":"AV16-115","subject":null,"moderation_state":"archived","external_url":null},{"nid":772,"title":"CGI Web Server Vulnerability","uuid":"f2905e5b-b4ac-431c-b6fa-4bfe4991534d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-25T18:27:59Z","summary":null,"body":["<article data-history-node-id=\"772\" about=\"\/en\/alerts-advisories\/cgi-web-server-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-116<br \/>\nDate: 18 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security advisories released concerning various web servers running Common Gateway Interface (CGI).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of multiple vulnerabilities affecting web server hosts running CGI (or allowing the execution of CGI scripts).\u00a0 Exploitation of these vulnerabilities may allow an attacker to conduct man-in-the-middle (MITM) attacks and\/or create denial of service conditions.<\/p>\n\n<p>These vulnerabilities may be exploitable on any web server allowing execution of CGI and\/or CGI-like scripts, with permission to use the variable \u201cHTTP_PROXY\u201d.<\/p>\n\n<p>CVE References: CVE-2016-5385, CVE-2016-5386, CVE-2016-5387, CVE-2016-5388, CVE-2016-1000109, CVE-2016-1000110<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly or consider applying the workarounds.<\/p>\n\n<p>References:<\/p>\n\n<p>CERT\/CC Vulnerability Note VU#797896 - CGI web servers assign Proxy header values from client requests to internal HTTP_PROXY environment variables:<br \/><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/797896\"><font color=\"#0066cc\">http:\/\/www.kb.cert.org\/vuls\/id\/797896<\/font><\/a><\/p>\n\n<p>Security Researcher Website \u2013 httpoxy:<\/p>\n\n<p><a href=\"https:\/\/httpoxy.org\/\"><font color=\"#0066cc\">https:\/\/httpoxy.org<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cgi-web-server-vulnerability","alert_type":396,"serial_number":"AV16-116","subject":null,"moderation_state":"archived","external_url":null},{"nid":1254,"title":"Multiple Apple security updates","uuid":"367ccd78-5ead-4108-9754-e430b90958fb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:14Z","date_created":"2018-06-25T18:37:04Z","summary":null,"body":["<article data-history-node-id=\"1254\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-117<br \/>\nDate: 19 July 2016\u00a0 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system updates for iCloud for Windows, iTunes for Windows, Safari, tvOS, watchOS, iOS, and OS X El Capitan.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<br \/>\nHT206899 - iCloud for Windows 5.2.1 Windows 7 and later<br \/>\nHT206901 - iTunes 12.4.2 for Windows Windows 7 and later<br \/>\nHT206900 - Safari 9.1.2 OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, and OS X El Capitan v10.11.6<br \/>\nHT206905 - tvOS 9.2.2 Apple TV (4th generation)<br \/>\nHT206904 - watchOS 2.2.2 Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes<br \/>\nHT206902 - iOS 9.3.3 iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later<br \/>\nHT206903 - OS X El Capitan v10.11.6 and Security Update 2016-004 OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, and OS X El Capitan v10.11 and later<\/p>\n\n<p>Details: These updates address multiple vulnerabilities, including arbitrary remote code execution.<\/p>\n\n<p>Multiple CVEs are referenced; please refer to Apple's advisory for specific details.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Articles HT206899, HT206901, HT206900, HT206905, HT206904, HT206902, and HT206903.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT206899\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206899<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT206901\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206901<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT206900\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206900<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT206905\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206905<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT206904\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206904<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT206902\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206902<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT206903\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT206903<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-1","alert_type":null,"serial_number":"AV16-117","subject":null,"moderation_state":"archived","external_url":null},{"nid":1100,"title":"Oracle Critical Patch update Advisory \u2013 July 2016","uuid":"5af7e620-e7e8-4ef9-9f4a-ffbbb0128ca1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-25T19:17:02Z","summary":null,"body":["<article data-history-node-id=\"1100\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-july-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-118<br \/>\nDate: 20 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following July 2016 critical patch updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update (CPU) which addresses 276 new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Application Express, version(s) 5.0.4 and prior.<\/li>\n\t<li>Oracle Database Server, version(s) 11.2.0.4, 12.1.0.1, 12.1.0.2\u00a0<\/li>\n\t<li>Oracle Access Manager, version(s) 10.1.4.x, 11.1.1.7<\/li>\n\t<li>Oracle BI Publisher, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.2.1.0.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, version(s) 11.1.1.7.0, 11.1.1.9.0, 11.2.1.0.0<\/li>\n\t<li>Oracle Directory Server Enterprise Edition, version(s) 7.0, 11.1.1.7.0<\/li>\n\t<li>Oracle Exalogic Infrastructure, version(s) 1.x, 2.x<\/li>\n\t<li>Oracle Fusion Middleware, version(s) 11.1.1.7, 11.1.1.8, 11.1.1.9, 11.1.2.2, 11.1.2.3, 12.1.3.0, 12.2.1.0<\/li>\n\t<li>Oracle GlassFish Server, version(s) 2.1.1, 3.0.1, 3.1.2<\/li>\n\t<li>Oracle HTTP Server, version(s) 11.1.1.9, 12.1.3.0<\/li>\n\t<li>Oracle JDeveloper, version(s) 11.1.1.7.0, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0, 12.2.1.0.0<\/li>\n\t<li>Oracle Portal, version(s) 11.1.1.6<\/li>\n\t<li>Oracle TopLink, version(s) 12.1.3.0, 12.2.1.0, 12.2.1.1<\/li>\n\t<li>Oracle WebCenter Sites, version(s) 11.1.1.8, 12.2.1.0<\/li>\n\t<li>Oracle WebLogic Server, version(s) 10.3.6.0, 12.1.3.0, 12.2.1.0<\/li>\n\t<li>Outside In Technology, version(s) 8.5.0, 8.5.1, 8.5.2<\/li>\n\t<li>Hyperion Financial Reporting, version(s) 11.1.2.4<\/li>\n\t<li>Enterprise Manager Base Platform, version(s) 12.1.0.5, 13.1.0.0\u00a0<\/li>\n\t<li>Enterprise Manager for Fusion Middleware, version(s) 11.1.1.7, 11.1.1.9\u00a0<\/li>\n\t<li>Enterprise Manager Ops Center, version(s) 12.1.4, 12.2.2, 12.3.2\u00a0<\/li>\n\t<li>Oracle E-Business Suite, version(s) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5\u00a0<\/li>\n\t<li>Oracle Agile Engineering Data Management, version(s) 6.1.3.0, 6.2.0.0 Oracle<\/li>\n\t<li>Oracle Agile PLM, version(s) 9.3.4, 9.3.5 Oracle<\/li>\n\t<li>Oracle Demand Planning, version(s) 12.1, 12.2 Oracle\u00a0<\/li>\n\t<li>Oracle Transportation Management, version(s) 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, 6.4.1\u00a0<\/li>\n\t<li>PeopleSoft Enterprise FSCM, version(s) 9.1, 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, version(s) 8.53, 8.54, 8.55<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version(s) 9.2.0.5<\/li>\n\t<li>Oracle Knowledge, version(s) 8.5.x\u00a0<\/li>\n\t<li>Siebel Applications, version(s) 8.1.1, 8.2.2, IP2014, IP2015, IP2016<\/li>\n\t<li>Oracle Fusion Applications, version(s) 11.1.2 through 11.1.10<\/li>\n\t<li>Oracle Communications ASAP, version(s) 7.0, 7.2, 7.3\u00a0<\/li>\n\t<li>Oracle Communications Core Session Manager, version(s) 7.2.5, 7.3.5<\/li>\n\t<li>Oracle Communications EAGLE Application Processor, version(s) 16.0<\/li>\n\t<li>Oracle Communications Messaging Server, version(s) 6.3, 7.0, 8.0, Prior to 7.0.5.37.0 et 8.0.1.1.0<\/li>\n\t<li>Oracle Communications Network Charging and Control, version(s) 4.4.1.5.0, 5.0.0.1.0, 5.0.0.2.0, 5.0.1.0.0, 5.0.2.0.0 O<\/li>\n\t<li>Oracle Communications Operations Monitor, version(s) 3.3.92.0.0 and prior.<\/li>\n\t<li>Oracle Communications Policy Management, version(s) 9.9.2 and prior.<\/li>\n\t<li>Oracle Communications Session Border Controller, version(s) 7.2.0, 7.3.0\u00a0<\/li>\n\t<li>Oracle Communications Unified Session Manager, version(s) 7.2.5, 7.3.5<\/li>\n\t<li>Oracle Enterprise Communications Broker, version(s) PCz 2.0.0m4p1 and prior.<\/li>\n\t<li>Oracle Banking Platform, version(s) 2.3.0, 2.4.0, 2.4.1, 2.5.0 Oracle<\/li>\n\t<li>Oracle Financial Services Lending and Leasing, version(s) 14.1, 14.2<\/li>\n\t<li>Oracle FLEXCUBE Direct Banking, version(s) 12.0.1, 12.0.2, 12.0.3<\/li>\n\t<li>Oracle Health Sciences Clinical Development Center, version(s) 3.1.1.x, 3.1.2.x\u00a0<\/li>\n\t<li>Oracle Health Sciences Information Manager, version(s) 1.2.8.3, 2.0.2.3, 3.0.1.0\u00a0<\/li>\n\t<li>Oracle Healthcare Analytics Data Integration, version(s) 3.1.0.0.0<\/li>\n\t<li>Oracle Healthcare Master Person Index, version(s) 2.0.12, 3.0.0, 4.0.1<\/li>\n\t<li>Oracle Documaker, version(s) Prior to 12.5<\/li>\n\t<li>Oracle Insurance Calculation Engine, version(s) 9.7.1, 10.1.2, 10.2.2 Oracle<\/li>\n\t<li>Oracle Insurance Policy Administration J2EE, version(s) 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, 10.2.2<\/li>\n\t<li>Oracle Insurance Rules Palette, version(s) 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, 10.2.2<\/li>\n\t<li>MICROS Retail XBRi Loss Prevention, version(s) 10.0.1, 10.5.0, 10.6.0, 10.7.0, 10.8.0, 10.8.1\u00a0\u00a0<\/li>\n\t<li>Oracle Retail Central, Back Office, Returns Management, version(s) 13.1, 13.2, 13.3, 13.4, 14.0, 14.1, 12.0 13.0<\/li>\n\t<li>Oracle Retail Integration Bus, version(s) 13.0, 13.1, 13.2, 14.0, 14.1, 15.0<\/li>\n\t<li>Oracle Retail Order Broker, version(s) 4.1, 5.1, 5.2, 15.0\u00a0<\/li>\n\t<li>Oracle Retail Service Backbone, version(s) 13.0, 13.1, 13.2, 14.0, 14.1, 15.0<\/li>\n\t<li>Oracle Retail Store Inventory Management, version(s) 12.0, 13.0, 13.1, 13.2, 14.0, 14.1\u00a0\u00a0<\/li>\n\t<li>Oracle Utilities Framework, version(s) 2.2.0.0.0, 4.1.0.1.0, 4.1.0.2.0, 4.2.0.1.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0, 4.3.0.2.0<\/li>\n\t<li>Oracle Utilities Network Management System, version(s) 1.10.0.6.27, 1.11.0.4.41, 1.11.0.5.4, 1.12.0.1.16, 1.12.0.2.12. 1.12.0.3.5<\/li>\n\t<li>Oracle Utilities Work and Asset Management, version(s) 1.9.1.2.8 Oracle Utilities Applications<\/li>\n\t<li>Oracle In-Memory Policy Analytics, version(s) 12.0.1 Oracle Policy Automation\u00a0<\/li>\n\t<li>Oracle Policy Automation, version(s) 10.3.0, 10.3.1, 10.4.0, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 12.1.0, 12.1.1<\/li>\n\t<li>Oracle Policy Automation Connector pour Siebel, version(s) 10.3.0, 10.4.0, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6<\/li>\n\t<li>Oracle Policy Automation pour Mobile Devices, version(s) 12.1.1<\/li>\n\t<li>Primavera Contract Management, version(s) 14.2<\/li>\n\t<li>Primavera P6 Enterprise Project Portfolio Management, version(s) 8.2, 8.3, 8.4, 15.1, 15.2, 16.1<\/li>\n\t<li>Oracle Java SE, version(s) 6u115, 7u101, 8u92<\/li>\n\t<li>Oracle Java SE Embedded, version(s) 8u91<\/li>\n\t<li>Oracle JRockit, version(s) R28.3.10\u00a0<\/li>\n\t<li>40G 10G 72\/64 Ethernet Switch, version(s) 2.0.0<\/li>\n\t<li>Fujitsu M10-1, M10-4, M10-4S Servers, version(s) prior to XCP 2320<\/li>\n\t<li>ILOM, version(s) 3.0, 3.1, 3.2<\/li>\n\t<li>Oracle Switch ES1-24, version(s) 1.3<\/li>\n\t<li>Solaris, version(s) 10, 11.3<\/li>\n\t<li>Solaris Cluster, version(s) 3.3, 4.3<\/li>\n\t<li>SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers, version(s) prior to XCP 1121<\/li>\n\t<li>Sun Blade 6000 Ethernet Switched NEM 24P 10GE, version(s) 1.2<\/li>\n\t<li>Sun Data Center InfiniBand Switch 36, version(s) prior to 2.2.2<\/li>\n\t<li>Sun Network 10GE Switch 72p, version(s) 1.2<\/li>\n\t<li>Sun Network QDR InfiniBand Gateway Switch, version(s) prior to 2.2.2<\/li>\n\t<li>Oracle Secure Global Desktop, version(s) 4.63, 4.71, 5.2<\/li>\n\t<li>Oracle VM VirtualBox, version(s) prior to 5.0.26<\/li>\n\t<li>MySQL Server, version(s) 5.5.49 and prior, 5.6.30 and prior, 5.7.12 and prior.<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2016-2881720.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2016-2881720.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-july-2016","alert_type":396,"serial_number":"AV16-118","subject":null,"moderation_state":"archived","external_url":null},{"nid":924,"title":"Cisco security advisory","uuid":"a28f7f10-db0d-436c-953d-b57ef6203362","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-25T19:25:19Z","summary":null,"body":["<article data-history-node-id=\"924\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-119<br \/>\nDate: 21 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released Cisco Security Advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released a security update to address a critical vulnerability in Cisco Unified Computing System (UCS) Performance Manager that could allow an authenticated, remote attacker to execute arbitrary commands on a targeted system.<\/p>\n\n<p>CVE Reference: CVE-2016-1374<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160720-ucsperf\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160720-ucsperf<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-0","alert_type":396,"serial_number":"AV16-119","subject":null,"moderation_state":"archived","external_url":null},{"nid":1205,"title":"Google Releases security update for Chrome","uuid":"1a870270-d9b8-487c-b72d-617922bff5f0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-25T19:31:23Z","summary":null,"body":["<article data-history-node-id=\"1205\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-120<br \/>\nDate: 21 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 52.0.2743.82 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References:<br \/>\nCVE-2016-1706, CVE-2016-1707, CVE-2016-1708, CVE-2016-1709, CVE-2016-1710, CVE-2016-1711, CVE-2016-5127, CVE-2016-5128, CVE-2016-5129, CVE-2016-5130, CVE-2016-5131, CVE-2016-5132, CVE-2016-5133, CVE-2016-5134, CVE-2016-5135, CVE-2016-5136, CVE-2016-5137, CVE-2016-1705<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/07\/stable-channel-update.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/07\/stable-channel-update.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-11","alert_type":396,"serial_number":"AV16-120","subject":null,"moderation_state":"archived","external_url":null},{"nid":813,"title":"SAP Security Notes - July 2016","uuid":"19f5fea6-804e-4f4f-a40e-9e84f7c347dd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-25T19:39:10Z","summary":null,"body":["<article data-history-node-id=\"813\" about=\"\/en\/alerts-advisories\/sap-security-notes-july-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-121<br \/>\nDate: 22 July 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Security Notes by SAP.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>SAP has released 10 Security Notes as part of their July Security Patch Day designed to address multiple vulnerabilities in several SAP products. Vulnerabilities addressed in the July Security Patch Day Security Notes include: Clickjacking, Cross Site Scripting, Missing Authorization Check, Denial of Service, SQL Injection, Code Injection and Buffer Overflow.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released update to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/scn.sap.com\/community\/security\/blog\/2016\/07\/12\/sap-security-patch-day--july-2016\"><font color=\"#0066cc\">http:\/\/scn.sap.com\/community\/security\/blog\/2016\/07\/12\/sap-security-patch-day--july-2016<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-notes-july-2016","alert_type":396,"serial_number":"AV16-121","subject":null,"moderation_state":"archived","external_url":null},{"nid":887,"title":"Siemens security updates \u2013 July 2016","uuid":"911d7059-8a8b-4ad1-bf0d-f53142b77398","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-25T19:46:34Z","summary":null,"body":["<article data-history-node-id=\"887\" about=\"\/en\/alerts-advisories\/siemens-security-updates-july-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-122<br \/>\nDate: July 28, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a SIMATIC security update for NET PC-Software, PCS 7, WinCC and WinCC Runtime Professional released by Siemens.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Siemens released security updates for SIMATIC NET PC-Software, PCS 7, WinCC and WinCC Runtime Professional to address multiple vulnerabilities. A remote attacker could potentially exploit these vulnerabilities to perform arbitrary code execution or create denial of service conditions.<\/p>\n\n<p>Affected versions:<br \/>\nSIMATIC NET PC-Software prior to V13 SP2<br \/>\nSIMATIC PCS v7.1 SP4 and earlier versions<br \/>\nSIMATIC PCS v8.0<br \/>\nSIMATIC PCS v8.1<br \/>\nSIMATIC PCS v8.2<br \/>\nSIMATIC WinCC v7.0 SP 2 and earlier versions<br \/>\nSIMATIC WinCC v7.0 SP 3<br \/>\nSIMATIC WinCC v7.2<br \/>\nSIMATIC WinCC v7.3 prior to Update 10,<br \/>\nSIMATIC WinCC v7.4 prior to Update 1<br \/>\nSIMATIC WinCC Runtime Professional prior to v13 SP 1 Update 9.<\/p>\n\n<p>CVE References: CVE-2016-5743, CVE-2016-5744, CVE-2016-5874<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. For more information, please refer to the ICS-CERT references.<\/p>\n\n<h2>References<\/h2>\n\n<p>SIEMENS Security Advisory SSA-378531:<br \/><a href=\"http:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-378531.pdf\"><font color=\"#0066cc\">http:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-378531.pdf<\/font><\/a><br \/><br \/>\nICS-CERT Advisory (ICSA-16-208-01):<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-208-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-208-01<\/font><\/a><\/p>\n\n<p>ICS-CERT Advisory (ICSA-16-208-02):<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-208-02\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-208-02<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/siemens-security-updates-july-2016","alert_type":396,"serial_number":"AV16-122","subject":null,"moderation_state":"archived","external_url":null},{"nid":1077,"title":"Android security bulletin \u2013 August 2016","uuid":"e446855f-7395-4d1f-b949-a7b3d0c99b47","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-26T12:40:12Z","summary":null,"body":["<article data-history-node-id=\"1077\" about=\"\/en\/alerts-advisories\/android-security-bulletin-august-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-123<br \/>\nDate: Aug 2, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for August.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulleting addresses a security update for 42 vulnerabilities (8 Critical, 21 High, 13 Moderate). The most critical ones, could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.<\/p>\n\n<p>CVE References: CVE-2012-6701, CVE-2014-9863, CVE-2014-9864, CVE-2014-9865, CVE-2014-9866, CVE-2014-9867, CVE-2014-9868, CVE-2014-9869, CVE-2014-9870, CVE-2014-9871, CVE-2014-9872, CVE-2014-9873, CVE-2014-9874, CVE-2014-9875, CVE-2014-9876, CVE-2014-9877, CVE-2014-9878, CVE-2014-9879, CVE-2014-9880, CVE-2014-9881, CVE-2014-9882, CVE-2014-9883, CVE-2014-9884, CVE-2014-9885, CVE-2014-9886, CVE-2014-9887, CVE-2014-9888, CVE-2014-9889, CVE-2014-9890, CVE-2014-9891, CVE-2014-9892, CVE-2014-9893, CVE-2014-9894, CVE-2014-9895, CVE-2014-9896, CVE-2014-9897, CVE-2014-9898, CVE-2014-9899, CVE-2014-9900, CVE-2014-9901, CVE-2014-9902, CVE-2014-9903, CVE-2014-9904, CVE-2015-1593, CVE-2015-2686, CVE-2015-8937, CVE-2015-8938, CVE-2015-8939, CVE-2015-8940, CVE-2015-8941, CVE-2015-8942, CVE-2015-8943, CVE-2015-8944, CVE-2016-2497, CVE-2016-2504, CVE-2016-2544, CVE-2016-2546, CVE-2016-2842, CVE-2016-3672, CVE-2016-3819, CVE-2016-3820, CVE-2016-3821, CVE-2016-3822, CVE-2016-3823, CVE-2016-3824, CVE-2016-3825, CVE-2016-3826, CVE-2016-3827, CVE-2016-3828, CVE-2016-3829, CVE-2016-3830, CVE-2016-3831, CVE-2016-3832, CVE-2016-3833, CVE-2016-3834, CVE-2016-3835, CVE-2016-3836, CVE-2016-3837, CVE-2016-3838, CVE-2016-3839, CVE-2016-3840, CVE-2016-3841, CVE-2016-3842, CVE-2016-3843, CVE-2016-3844, CVE-2016-3845, CVE-2016-3846, CVE-2016-3847, CVE-2016-3848, CVE-2016-3849, CVE-2016-3850, CVE-2016-3851, CVE-2016-3852, CVE-2016-3853, CVE-2016-3854, CVE-2016-3855, CVE-2016-3856, CVE-2016-3857, CVE-2016-4482, CVE-2016-4569, CVE-2016-4578<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Android web site: <a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-08-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-08-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-august-2016","alert_type":396,"serial_number":"AV16-123","subject":null,"moderation_state":"archived","external_url":null},{"nid":1035,"title":"Creston Electronics security updates","uuid":"c0562265-a90e-4a07-ae52-6b00ad9ee798","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-26T12:47:08Z","summary":null,"body":["<article data-history-node-id=\"1035\" about=\"\/en\/alerts-advisories\/creston-electronics-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-124<br \/>\nDate: Aug 4, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security updates available for DM-TXRX-100-STR web management interface by Creston Electronics.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Creston Electronics released a security update to address 5 critical vulnerabilities in the DM-TXRX-100-STR web interface. \u00a0Exploitation of these vulnerabilities can allow for authentication bypass, unauthorized access and cross-site request forgery. \u00a0Vulnerable devices also contain hard-coded administrative credentials and a publicly known cryptographic key.\u00a0<\/p>\n\n<p>Affected versions:<br \/>\nDM-TXRX-100-STR versions prior to 1.3039.00040<\/p>\n\n<p>CVE References: CVE-2016-5666, CVE-2016-5667, CVE-2016-5668, CVE-2016-5669, CVE-2016-5670, CVE-2016-5671<\/p>\n\n<p>One vulnerability (CVE-2016-5671) remains unpatched, with a firmware update forthcoming from the manufacturer.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0 For the vulnerability without a released update, system administrators should monitor for its release then their organization's patch management process should be actioned accordingly.\u00a0 Any default device passwords should be reset, then changed regularly using a strong password policy.<\/p>\n\n<h2>References<\/h2>\n\n<p>Vendor Download:\u00a0\u00a0\u00a0<br \/><a href=\"https:\/\/www.crestron.com\/resources\/resource-library\/firmware\"><font color=\"#0066cc\">https:\/\/www.crestron.com\/resources\/resource-library\/firmware<\/font><\/a><\/p>\n\n<p>Advisories:<br \/><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/974424\"><font color=\"#0066cc\">http:\/\/www.kb.cert.org\/vuls\/id\/974424<\/font><\/a><br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5666\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5666<\/font><\/a><br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5667\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5667<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5668\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5668<\/font><\/a><br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5669\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5669<\/font><\/a><br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5670\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5670<\/font><\/a><br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5671\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-5671<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/creston-electronics-security-updates","alert_type":396,"serial_number":"AV16-124","subject":null,"moderation_state":"archived","external_url":null},{"nid":1170,"title":"Multiple Cisco Security Advisories","uuid":"49222b32-c5d1-40a3-ae31-471d7535d9c3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-26T12:54:02Z","summary":null,"body":["<article data-history-node-id=\"1170\" about=\"\/en\/alerts-advisories\/multiple-cisco-security-advisories-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-125<br \/>\nDate: Aug 4, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released a security update to address critical 7 vulnerabilities (2 Critical, 2 High, and 3 Moderate) in various Cisco products.<\/p>\n\n<p>Affected Products:<br \/>\nRV110W Wireless-N VPN Firewall prior to version 1.2.1.7<br \/>\nRV130W Wireless-N Multifunction VPN Router prior to version 1.0.3.16<br \/>\nRV215W Wireless-N VPN Router prior to version 1.3.0.8<br \/>\nCisco Unified Communications Manager IM and Presence Service versions 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1)<br \/>\nCisco TelePresence Video Communication Server version X8.5.2<br \/>\nCisco Prime Infrastructure version 2.2(2)<br \/>\nCisco RV180W Wireless-N Multifunction VPN and RV180 VPN Routers are at End-of-Life and will remain vulnerable.<\/p>\n\n<p>CVE References: \u00a0CVE-2016-1429, CVE-2016-1430, CVE-2016-1466, CVE-2016-1468, CVE-2016-1474, CVE-2015-6396, CVE-2015-6397<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Cisco RV180 VPN and RV180W Wireless-N Multifunction VPN Routers Unauthorized Access Vulnerability:<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv180_1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv180_1<\/font><\/a><\/p>\n\n<p>Cisco Unified Communications Manager IM and Presence Service SIP Packet Processing Denial of Service Vulnerability:<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-ucm\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-ucm<\/font><\/a><\/p>\n\n<p>Cisco RV180 VPN and RV180W Wireless-N Multifunction VPN Routers Remote Code Execution Vulnerability:<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv180_2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv180_2<\/font><\/a><\/p>\n\n<p>Cisco RV110W, RV130W, and RV215W Routers Static Credential Vulnerability:<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv110_130w2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv110_130w2<\/font><\/a><\/p>\n\n<p>Cisco Prime Infrastructure Cross-Frame Scripting Vulnerability:<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-cpi\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-cpi<\/font><\/a><\/p>\n\n<p>Cisco RV110W, RV130W, and RV215W Routers Command Shell Injection Vulnerability:<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv110_130w1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160803-rv110_130w1<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-cisco-security-advisories-1","alert_type":396,"serial_number":"AV16-125","subject":null,"moderation_state":"archived","external_url":null},{"nid":1217,"title":"Moxa SoftCMS security update","uuid":"d7af00cb-c823-4239-bb25-6f3550ca462a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-26T12:59:56Z","summary":null,"body":["<article data-history-node-id=\"1217\" about=\"\/en\/alerts-advisories\/moxa-softcms-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-126<br \/>\nDate: Aug 4, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of a SQL injection vulnerability in Moxa SoftCMS which an update is available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Moxa released a security update to address a critical SQL injection vulnerability in SoftCMS. Exploitation of this vulnerability may allow for arbitrary remote code execution.<\/p>\n\n<p>Version affected: Moxa SoftCMS prior to version 1.5<\/p>\n\n<p>CVE Reference: CVE-2016-5792<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=11362\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=11362<\/font><\/a><br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-215-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-215-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moxa-softcms-security-update","alert_type":396,"serial_number":"AV16-126","subject":null,"moderation_state":"archived","external_url":null},{"nid":1321,"title":"Mozilla Releases security updates","uuid":"7c9ab16e-ef3d-4b2a-87e5-05f493855a7b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-26T13:07:24Z","summary":null,"body":["<article data-history-node-id=\"1321\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-127<br \/>\nDate: Aug 4, 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 24 vulnerabilities (3 Critical, 8 High, 11 Moderate and 2 Low) in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 48.0<br \/>\nESR versions prior to 45.3<\/p>\n\n<p>CVE References: CVE-2016-0718, CVE-2016-2830, CVE-2016-2835, CVE-2016-2836, CVE-2016-2837, CVE-2016-2838, CVE-2016-2839, CVE-2016-5250, CVE-2016-5251, CVE-2016-5252, CVE-2016-5253, CVE-2016-5254, CVE-2016-5255, CVE-2016-5258, CVE-2016-5259, CVE-2016-5260, CVE-2016-5261, CVE-2016-5262, CVE-2016-5263, CVE-2016-5264, CVE-2016-5265, CVE-2016-5266, CVE-2016-5267, CVE-2016-5268<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox-esr\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/known-vulnerabilities\/firefox-esr\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-2","alert_type":396,"serial_number":"AV16-127","subject":null,"moderation_state":"archived","external_url":null},{"nid":905,"title":"VMware security advisory","uuid":"ecbd69fe-5321-4f72-a17b-729c424f04e1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-26T13:15:58Z","summary":null,"body":["<article data-history-node-id=\"905\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-128<br \/>\nDate: 06 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware product update addresses multiple security issues in different VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware vCenter Server prior to version 6.0<\/li>\n\t<li>VMware vSphere Hypervisor (ESXi) prior to version 6.0<\/li>\n\t<li>VMware Workstation Pro prior to version 12.1.x<\/li>\n\t<li>VMware Workstation Player prior to version 12.1.x<\/li>\n\t<li>VMware Fusion prior to version 8.1.x<\/li>\n\t<li>VMware Tools prior to version 10.0.5<\/li>\n<\/ul><p>CVE Reference: CVE-2016-5330, CVE-2016-5331<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References<\/p>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0010.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0010.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-1","alert_type":396,"serial_number":"AV16-128","subject":null,"moderation_state":"archived","external_url":null},{"nid":918,"title":"Apple security update for iOS","uuid":"3b3c9e7e-987b-4c31-b14d-002a9dbb8963","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-06-26T13:23:14Z","summary":null,"body":["<article data-history-node-id=\"918\" about=\"\/en\/alerts-advisories\/apple-security-update-ios\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-129<br \/>\nDate: 09 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple security update for iOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support article:<\/p>\n\n<p>HT207026 - iOS 9.3.4 iPhone 4s and later, iPad 2 and later, iPod touch (5th generation) and later<\/p>\n\n<p>Details: This update addresses a memory corruption vulnerability that could grant an application ability to execute arbitrary code with kernel privileges.<\/p>\n\n<p>CVE Reference: CVE-2016-4654<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Article HT207026.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT207026\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207026<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-update-ios","alert_type":396,"serial_number":"AV16-129","subject":null,"moderation_state":"archived","external_url":null},{"nid":1126,"title":"Microsoft Critical security bulletins Summary - August 2016","uuid":"cf021ab5-7571-401d-aa8f-4b8079d2144d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:29Z","date_created":"2018-06-26T13:29:30Z","summary":null,"body":["<article data-history-node-id=\"1126\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-august-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-130<br \/>\nDate: 09 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for August 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 9 bulletins (5 Critical and 4 Important), which addresses multiple vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Microsoft Communications Platforms and Software, and Microsoft Office Services and Web Apps.<\/p>\n\n<p>***Critical***<br \/>\nMS16-095\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for Internet Explorer (3177356)<br \/>\nMS16-096\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for Microsoft Edge (3177358)<br \/>\nMS16-097\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for Microsoft Graphic Component (3177393)<br \/>\nMS16-099\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Microsoft Office (3177451)<br \/>\nMS16-102\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Microsoft Windows PDF Library (3182248)<\/p>\n\n<p>***Important***<br \/>\nMS16-098\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Kernel-Mode Drivers (3178466)<br \/>\nMS16-100\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Secure Boot (3179577)<br \/>\nMS16-101\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Authentication Methods (3178465)<br \/>\nMS16-103\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for ActiveSyncProvider (3182332)<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-aug.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-aug.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-august-2016","alert_type":396,"serial_number":"AV16-130","subject":null,"moderation_state":"archived","external_url":null},{"nid":1182,"title":"Multiple Cisco Security Advisories","uuid":"e896ad28-9584-410d-9b0a-0d6ad8b5ef75","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-26T13:53:46Z","summary":null,"body":["<article data-history-node-id=\"1182\" about=\"\/en\/alerts-advisories\/multiple-cisco-security-advisories-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-131<br \/>\nDate: 19 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has released multiple security advisories addressing vulnerabilities affecting several of their products.\u00a0 The severity of these vulnerabilities range from medium to critical.<\/p>\n\n<p><strong>Critical<\/strong><br \/>\nCisco Firepower Management Center Remote Command Execution Vulnerability (cisco-sa-20160817-fmc)<br \/>\nCisco Firepower Management Center Privilege Escalation Vulnerability (cisco-sa-20160817-firepower)<\/p>\n\n<p><strong>High<\/strong><br \/>\nCisco Application Policy Infrastructure Controller Enterprise Module Remote Code Execution Vulnerability (cisco-sa-20160817-apic)<\/p>\n\n<p><strong>Medium<\/strong><br \/>\nCisco WebEx Meetings Server Information Disclosure Vulnerability (cisco-sa-20160817-wms1)<br \/>\nCisco Unified Communications Manager Information Disclosure Vulnerability (cisco-sa-20160817-ucm)<br \/>\nCisco Smart Call Home Transport Gateway Cross-Site Scripting Vulnerability (cisco-sa-20160817-sch)<br \/>\nCisco Identity Services Engine Admin Dashboard Page Cross-Site Scripting Vulnerability (cisco-sa-20160817-ise)<br \/>\nCisco IP Phone 8800 Series Denial of Service Vulnerability (cisco-sa-20160817-ipp)<br \/>\nCisco Firepower Management Center Cross-Site Scripting Vulnerability (cisco-sa-20160817-firepowermc)<br \/>\nCisco Aironet 1800, 2800, and 3800 Series Access Point Platforms CLI Privilege Escalation Vulnerability (cisco-sa-20160817-aap1)<br \/>\nCisco Aironet 1800, 2800, and 3800 Series Access Point Platforms AMPDU Denial of Service Vulnerability (cisco-sa-20160817-aap)<\/p>\n\n<p>CVE References: CVE-2016-1457, CVE-2016-1458, CVE-2016-1365, CVE-2016-1479, CVE-2016-1484, CVE-2016-1485, CVE-2016-6359, CVE-2016-6361, CVE-2016-6362, CVE-2016-6363, CVE-2016-6364, CVE-2016-6365<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-fmc\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-fmc<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-firepower\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-firepower<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-apic\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-apic<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-wms1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-wms1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-ucm\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-ucm<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-sch\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-sch<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-ise\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-ise<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-ipp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-ipp<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-firepowermc\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-firepowermc<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-aap1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-aap1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-aap\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160817-aap <\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-cisco-security-advisories-2","alert_type":396,"serial_number":"AV16-131","subject":null,"moderation_state":"archived","external_url":null},{"nid":774,"title":"VMware security advisory","uuid":"1462d388-3e75-43ad-844e-99ba7a132927","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-26T14:00:50Z","summary":null,"body":["<article data-history-node-id=\"774\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-132<br \/>\nDate: 25 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware product update addresses multiple security issues in different VMware products. A workaround is also available.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware vRealize Automation prior to version 7.1\n\t<ul><li>VMware vRealize Automation version 6.x is not affected.<\/li>\n\t<\/ul><\/li>\n\t<li>VMware VMware Identity Manager prior to version 2.7<\/li>\n<\/ul><p>CVE Reference: CVE-2016-5335, CVE-2016-5336<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>VMware Advisory<br \/><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0013.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0013.html<\/font><\/a><\/p>\n\n<p>VMware Workaround<br \/><a href=\"https:\/\/kb.vmware.com\/kb\/2146585\"><font color=\"#0066cc\">https:\/\/kb.vmware.com\/kb\/2146585<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-2","alert_type":396,"serial_number":"AV16-132","subject":null,"moderation_state":"archived","external_url":null},{"nid":1268,"title":"security updates for Moxa OnCell","uuid":"be42fabe-0830-4f24-86a9-1850df691d9b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-06-26T14:07:10Z","summary":null,"body":["<article data-history-node-id=\"1268\" about=\"\/en\/alerts-advisories\/security-updates-moxa-oncell\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-133<br \/>\nDate: 25 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following security updates for Moxa OnCell.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Moxa has issued a firmware update to their OnCell products that fix multiple security vulnerabilities. One of those vulnerabilities could allow an attacker to use brute force attack against authentication system.<\/p>\n\n<p>Versions Affected:<br \/>\nOnCell G3100V2 Series, prior to version 2.8<br \/>\nOnCell G3111\/G3151\/G3211\/G3251 Series, prior to version 1.7<\/p>\n\n<p>CVE Reference: CVE-2016-5799, CVE-2016-5812<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0 For more information, please refer to the ICS-CERT reference.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-236-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-236-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-moxa-oncell","alert_type":396,"serial_number":"AV16-133","subject":null,"moderation_state":"archived","external_url":null},{"nid":1102,"title":"Apple security update for iOS","uuid":"ebb3637b-faed-48fd-8acc-9cce9ad1ce8e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-26T14:12:46Z","summary":null,"body":["<article data-history-node-id=\"1102\" about=\"\/en\/alerts-advisories\/apple-security-update-ios-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-134<br \/>\nDate: 25 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple security update for iOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support article:<br \/>\nHT207107 \u2013 iOS 9.3.5<\/p>\n\n<p>Details:\u00a0 This update addresses multiple vulnerabilities that could allow a malicious attacker to disclose kernel memory, execute arbitrary code with kernel privileges, and arbitrary code execution when visiting a maliciously crafted website.<\/p>\n\n<p>CVE Reference: CVE-2016-4655, CVE-2016-4656, CVE-2016-4657<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in the Apple Support Article: HT207107.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT207107\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207107<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-update-ios-0","alert_type":396,"serial_number":"AV16-134","subject":null,"moderation_state":"archived","external_url":null},{"nid":926,"title":"security updates for Adobe ColdFusion","uuid":"11c05bcf-3075-4058-ae10-aaace973e436","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-26T14:19:14Z","summary":null,"body":["<article data-history-node-id=\"926\" about=\"\/en\/alerts-advisories\/security-updates-adobe-coldfusion\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-135<br \/>\nDate: 31 August 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Adobe ColdFusion.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-30 to address critical vulnerabilities that could lead to information disclosure.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>ColdFusion 10<\/li>\n\t<li>ColdFusion 11<\/li>\n<\/ul><p>CVE Reference: CVE-2016-4264<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb16-30.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb16-30.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-adobe-coldfusion","alert_type":396,"serial_number":"AV16-135","subject":null,"moderation_state":"archived","external_url":null},{"nid":1207,"title":"Google Releases security update for Chrome","uuid":"ce0807d3-5568-4143-b09d-62bff0c60b0b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-26T14:25:50Z","summary":null,"body":["<article data-history-node-id=\"1207\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-136<br \/>\nDate: 1 September 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 53.0.2785.89 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References:<\/p>\n\n<p>CVE-2016-5147, CVE-2016-5148, CVE-2016-5149, CVE-2016-5150, CVE-2016-5151, CVE-2016-5152, CVE-2016-5153, CVE-2016-5154, CVE-2016-5155, CVE-2016-5156, CVE-2016-5157, CVE-2016-5158, CVE-2016-5159, CVE-2016-5160, CVE-2016-5161, CVE-2016-5162, CVE-2016-5163, CVE-2016-5164, CVE-2016-5165, CVE-2016-5166, CVE-2016-5167.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"http:\/\/googlechromereleases.blogspot.ca\/2016\/08\/stable-channel-update-for-desktop_31.html\"><font color=\"#0066cc\">http:\/\/googlechromereleases.blogspot.ca\/2016\/08\/stable-channel-update-for-desktop_31.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-12","alert_type":396,"serial_number":"AV16-136","subject":null,"moderation_state":"archived","external_url":null},{"nid":815,"title":"Cisco Releases security updates","uuid":"bd058f74-6f31-40c3-aec0-80e3594d0567","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-26T15:03:42Z","summary":null,"body":["<article data-history-node-id=\"815\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-137<br \/>\nDate: 1 September 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco Wireless LAN Controller , Cisco WebEx Meetings Player, Cisco Virtual Media Packager, Cisco Small Business 220 Series Smart Plus Switches, Cisco Small Business SPA3x\/5x and Cisco Hosted Collaboration Mediation Fulfillment.<\/p>\n\n<p>CVE Reference: CVE-2016-6376, CVE-2016-6375, CVE-2016-1415, CVE-2016-6377, CVE-2016-1473, CVE-2016-1472, CVE-2016-1471, CVE-2016-1470, CVE-2016-1469, CVE-2016-1464, CVE-2016-6371 and CVE-2016-6370.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-wlc-2\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-wlc-2<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-wlc-1\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-wlc-1<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-webex\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-webex<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-vmp\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-vmp<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps3\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps3<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps2\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps2<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps1\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps1<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-sps<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-spa\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-spa<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-meetings-player\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-meetings-player<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-hcmf\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-hcmf<\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-hcm\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-hcm<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-0","alert_type":396,"serial_number":"AV16-137","subject":null,"moderation_state":"archived","external_url":null},{"nid":898,"title":"Multiple Apple security updates","uuid":"5870bd3a-1928-4d7a-a8d5-f2dc3bde110a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-26T15:09:53Z","summary":null,"body":["<article data-history-node-id=\"898\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-138<br \/>\nDate: 1 September 2016\u00a0 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple security updates for OS X El Capitan, OS X Yosemite and Safari.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<br \/>\nHT207130 - Security Update 2016-001 El Capitan and Security Update 2016-005 Yosemite<br \/>\nHT207131 - Safari 9.1.3<\/p>\n\n<p>These updates address multiple vulnerabilities, including arbitrary remote code execution.<\/p>\n\n<p>CVE References: CVE-2016-4654, CVE-2016-4655, CVE-2016-4656<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Articles HT207130 and HT207131.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT207130\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207130<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207131\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207131<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-2","alert_type":396,"serial_number":"AV16-138","subject":null,"moderation_state":"archived","external_url":null},{"nid":1079,"title":"Android security bulletin \u2013 September 2016","uuid":"291ec56f-3ff0-446f-9223-bcfe5f40a0d0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-26T15:15:52Z","summary":null,"body":["<article data-history-node-id=\"1079\" about=\"\/en\/alerts-advisories\/android-security-bulletin-september-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-139<br \/>\nDate: September 07 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for September.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for 47 vulnerabilities (7 Critical, 23 High, 17 Moderate). Those viewed Critical are so given the possibility of remote code execution vulnerabilities and\/or elevation of privilege vulnerabilities.<\/p>\n\n<p>CVE References: CVE-2016-3861, CVE-2016-3862, CVE-2016-3863, CVE-2016-3870, CVE-2016-3871, CVE-2016-3872, CVE-2016-3875, CVE-2016-3876, CVE-2016-3899, CVE-2016-3878, CVE-2016-3879, CVE-2016-3880, CVE-2016-3881, CVE-2016-3883, CVE-2016-3884, CVE-2016-3885, CVE-2016-3886, CVE-2016-3887, CVE-2016-3888, CVE-2016-3889, CVE-2016-3890, CVE-2016-3895, CVE-2016-3896, CVE-2016-3897, CVE-2016-3898, CVE-2014-9529, CVE-2016-4470, CVE-2013-7446, CVE-2016-3134, CVE-2016-3951, CVE-2014-4655, CVE-2016-2053, CVE-2016-3864, CVE-2016-3858, CVE-2016-4805, CVE-2016-4805, CVE-2016-3865, CVE-2016-3859, CVE-2016-3866, CVE-2016-3867, CVE-2016-3868, CVE-2016-3869, CVE-2016-1583, CVE-2016-3873, CVE-2016-3874, CVE-2015-1465, CVE-2015-5364, CVE-2015-8839, CVE-2016-3892, CVE-2016-3893, CVE-2016-3894, CVE-2016-4998, CVE-2015-2922, CVE-2016-5340, CVE-2016-2059.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Android web site: <a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-09-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-09-01.html<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-september-2016","alert_type":396,"serial_number":"AV16-139","subject":null,"moderation_state":"archived","external_url":null},{"nid":1037,"title":"WordPress Security Release","uuid":"30a314ad-66e5-4ee1-8131-6fb13a5e259d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-26T15:22:40Z","summary":null,"body":["<article data-history-node-id=\"1037\" about=\"\/en\/alerts-advisories\/wordpress-security-release-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-140<br \/>\nDate: 7 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the WordPress 4.6.1 Security Release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress versions 4.6 and earlier are affected by two security issues:<\/p>\n\n<ul><li>\u00a0Cross-site scripting (XSS) vulnerability via image filename; and<\/li>\n\t<li>\u00a0Path traversal vulnerability in the upgrade package uploader.<\/li>\n<\/ul><p>In addition to the security issues above, WordPress 4.6.1 fixes 15 bugs from version 4.6.\u00a0<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2016\/09\/wordpress-4-6-1-security-and-maintenance-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2016\/09\/wordpress-4-6-1-security-and-maintenance-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-release-2","alert_type":null,"serial_number":"AV16-140","subject":null,"moderation_state":"archived","external_url":null},{"nid":1162,"title":"security updates for Multiple Adobe Products","uuid":"4ccd5191-d423-4859-8a36-5f410f621cca","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-26T15:28:41Z","summary":null,"body":["<article data-history-node-id=\"1162\" about=\"\/en\/alerts-advisories\/security-updates-multiple-adobe-products-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-141<br \/>\nDate: 13 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for multiple Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletins APSB16-28, APSB16-29, and APSB16-30 to address critical vulnerabilities that could allow an attacker to take control of vulnerable systems. All OS platforms are reported as being impacted.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul type=\"disc\"><li>Adobe Digital Editions 4.5.1 and earlier versions<\/li>\n\t<li>Adobe Flash Player Desktop Runtime 22.0.0.211 and earlier (Windows and Macintosh)<\/li>\n\t<li>Adobe Flash Player Extended Support Release 18.0.0.366 and earlier (Windows and Macintosh)<\/li>\n\t<li>Adobe Flash Player for Google Chrome 22.0.0.211 and earlier (Windows, Macintosh, Linux and ChromeOS)<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 22.0.0.211 and earlier (Windows 10 and 8.1)<\/li>\n\t<li>Adobe Flash Player for Linux 11.2.202.632 and earlier<\/li>\n\t<li>Adobe AIR SDK &amp; Compiler 22.0.0.153 and earlier<\/li>\n<\/ul><p>CVE References: CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, CVE-2016-4262, CVE-2016-4263, CVE-2016-4182, CVE-2016-4237, CVE-2016-4238, CVE-2016-4271, CVE-2016-4272, CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4277, CVE-2016-4278, CVE-2016-4279, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CVE-2016-4283, CVE-2016-4284, CVE-2016-4285, CVE-2016-4287, CVE-2016-6921, CVE-2016-6922, CVE-2016-6923, CVE-2016-6924, CVE-2016-6925, CVE-2016-6926, CVE-2016-6927, CVE-2016-6929, CVE-2016-6930, CVE-2016-6931, CVE-2016-6932, CVE-2016-6936<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Adobe Security Bulletin:<\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/content\/help\/en\/security\/products\/Digital-Editions\/apsb16-28.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/content\/help\/en\/security\/products\/Digital-Editions\/apsb16-28.html<\/font><\/a> \u00a0<\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/content\/help\/en\/security\/products\/flash-player\/apsb16-29.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/content\/help\/en\/security\/products\/flash-player\/apsb16-29.html<\/font><\/a> \u00a0<\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/content\/help\/en\/security\/products\/air\/apsb16-31.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/content\/help\/en\/security\/products\/air\/apsb16-31.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-multiple-adobe-products-0","alert_type":null,"serial_number":"AV16-141","subject":null,"moderation_state":"archived","external_url":null},{"nid":1209,"title":"Microsoft Critical security bulletins Summary \u2013 September 2016","uuid":"b992c64e-7b05-4c54-8cd1-cf1ba7dedfd8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-26T15:46:01Z","summary":null,"body":["<article data-history-node-id=\"1209\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-september-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-142<br \/>\nDate: 13 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for September 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 14 bulletins (7 Critical and 7 Important), which addresses multiple vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Microsoft Communications Platforms and Software, and Microsoft Office Services and Web Apps.<\/p>\n\n<p>***Critical***<br \/>\nMS16-104 ; Cumulative Security Update for Internet Explorer (3183038)<br \/>\nMS16-105;; Cumulative Security Update for Microsoft Edge (3183043)<br \/>\nMS16-106;; Security Update for Microsoft Graphics Component (3185848)<br \/>\nMS16-107;; Security Update for Microsoft Office (3185852)<br \/>\nMS16-108;; Security Update for Microsoft Exchange Server (3185883)<br \/>\nMS16-116 ;;Security Update in OLE Automation for VBScript Scripting Engine (3188724)<br \/>\nMS16-117 ;;Security Update for Adobe Flash Player (3188128)<\/p>\n\n<p>***Important***<br \/>\nMS16-109;; Security Update for Silverlight (3182373)<br \/>\nMS16-110;; Security Update for Windows (3178467)<br \/>\nMS16-111;; Security Update for Windows Kernel (3186973)<br \/>\nMS16-112;; Security Update for Windows Lock Screen (3178469)<br \/>\nMS16-113 ;;Security Update for Windows Secure Kernel Mode (3185876)<br \/>\nMS16-114; ;Security Update for SMBv1 Server (3185879)<br \/>\nMS16-115 ;;Security Update for Microsoft Windows PDF Library (3188733)<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References:<\/h2>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-sep\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-sep<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-september-2016","alert_type":396,"serial_number":"AV16-142","subject":null,"moderation_state":"archived","external_url":null},{"nid":1317,"title":"Multiple Apple security updates","uuid":"e1e43b08-37fd-4404-ae6b-a1b8ee6d3bfd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:04Z","date_created":"2018-06-26T16:42:29Z","summary":null,"body":["<article data-history-node-id=\"1317\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-143<br \/>\nDate: 14 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple security updates for; iOS 10, iOS 10.0.1, Xcode 8 and watchOS 3.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles;<\/p>\n\n<p>HT207143 - Security Update: iOS 10 - iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later<br \/>\nHT207145 - Security Update: iOS 10.0.1 - iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later<br \/>\nHT207140 - Security Update: Xcode 8 - OS X El Capitan v10.11.5 and later<br \/>\nHT207141 - Security Update: watchOS3 - All Apple Watch models<\/p>\n\n<p>These updates address multiple vulnerabilities, including, termination of application, arbitrary code execution, exposure of sensitive information on devices and the blocking of updates on devices.<\/p>\n\n<p>CVE References: CVE-2016-4741, CVE-2016-4719, CVE-2016-4746, CVE-2016-4747, CVE-2016-4740, CVE-2016-4749, CVE-2016-4620, CVE-2016-4655, CVE-2016-4704, CVE-2016-4705, CVE-2016-4719.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in the Apple Support Articles (see below)<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT207143\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207143<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207145\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207145<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207140\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207140<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207141\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207141<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-3","alert_type":396,"serial_number":"AV16-143","subject":null,"moderation_state":"archived","external_url":null},{"nid":907,"title":"Cisco Releases security updates","uuid":"b634bfb4-c062-47ed-b507-005384823889","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-26T16:50:34Z","summary":null,"body":["<article data-history-node-id=\"907\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-144<br \/>\nDate: 15 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco Web Security Appliance, Cisco WebEx Meeting Server, Cisco Unified Computing System, Cisco Fog Director for IOx, Cisco IOS XR, Cisco IOS and IOS XE Software Data, and Cisco Carrier Routing System IPv6.<\/p>\n\n<p>CVE Reference: CVE-2016-1433, CVE-2016-1482, CVE-2016-1483, CVE-2016-6401, CVE-2016-6402, CVE-2016-6403, CVE-2016-6404, CVE-2016-6405, CVE-2016-6407<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-wms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-wms<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-wsa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-wsa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-wem\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-wem<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ucs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ucs<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ioxfd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ioxfd<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-iosxr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-iosxr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ios-xe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ios-xe<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ios\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-ios<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-crs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160914-crs<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-1","alert_type":396,"serial_number":"AV16-144","subject":null,"moderation_state":"archived","external_url":null},{"nid":883,"title":"VMware security advisory \u2013 September 2016","uuid":"19fd4c9a-2be6-41c1-8f7c-0b8725c3d8dc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-06-26T16:56:32Z","summary":null,"body":["<article data-history-node-id=\"883\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-september-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-145<br \/>\nDate: 16 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware product update addresses multiple security issues in different VMware products<br \/>\nAffected Products:<\/p>\n\n<ul><li>ESXi prior to versions 6.0 and 5.5<\/li>\n\t<li>VMware Workstation Pro prior to version 12.5.0<\/li>\n\t<li>VMware Workstation Player prior to version 12.5.0<\/li>\n\t<li>VMware Fusion prior to version 8.5.0<\/li>\n\t<li>VMware Tools versions 10.x and 9.x<\/li>\n<\/ul><p>CVE Reference: CVE-2016-7079, CVE-2016-7080, CVE-2016-7081, CVE-2016-7082, CVE-2016-7083, CVE-2016-7084, CVE-2016-7085, CVE-2016-7086<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>VMware Advisory<br \/><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0014.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0014.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-september-2016","alert_type":396,"serial_number":"AV16-145","subject":null,"moderation_state":"archived","external_url":null},{"nid":1051,"title":"Mozilla Releases security updates","uuid":"62593106-a847-4a77-917c-01e1deb4ab51","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-06-26T17:04:00Z","summary":null,"body":["<article data-history-node-id=\"1051\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-146<br \/>\nDate: 21 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 30 vulnerabilities (6 Critical, 19 High, 3 Moderate and 2 Low) in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 49.0<br \/>\nESR versions prior to 45.4<\/p>\n\n<p>CVE References: CVE-2016-2827, CVE-2016-5250, CVE-2016-5256, CVE-2016-5257, CVE-2016-5261, CVE-2016-5270, CVE-2016-5271, CVE-2016-5272, CVE-2016-5273, CVE-2016-5274, CVE-2016-5275, CVE-2016-5276, CVE-2016-5277, CVE-2016-5278, CVE-2016-5279, CVE-2016-5280, CVE-2016-5281, CVE-2016-5282, CVE-2016-5283, and CVE-2016-5284.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-85\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-85\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-86\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-86\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-3","alert_type":396,"serial_number":"AV16-146","subject":null,"moderation_state":"archived","external_url":null},{"nid":1165,"title":"Multiple Apple security updates","uuid":"fd1766af-3da9-4fba-8400-883e5a534860","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:44Z","date_created":"2018-06-26T17:10:58Z","summary":null,"body":["<article data-history-node-id=\"1165\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-147<br \/>\nDate: 21 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iCloud for Windows, macOS Server, Safari and macOS Sierra.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<br \/>\nHT207147 - iCloud for Windows 6.0 (Windows 7 and later)<br \/>\nHT207171 - macOS Server 5.2 (macOS Sierra 10.12)<br \/>\nHT207157 - Safari 10 (OS X Yosemite v10.10.5, OS X El Capitan v10.11.6, and macOS Sierra 10.12)<br \/>\nHT207170 - macOS Sierra 10.12 (OS X El Capitan v10.11.6)<\/p>\n\n<p>Details: These updates address multiple vulnerabilities, including arbitrary remote code execution, cross-site scripting and proxy traffic through an arbitrary server.<\/p>\n\n<p>Multiple CVEs are referenced; please refer to Apple's advisory for specific details.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Articles HT207147, HT207171, HT207157, and HT207170.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT207147\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207147<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207171\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207171<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207157\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207157<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207170\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207170<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-4","alert_type":396,"serial_number":"AV16-147","subject":null,"moderation_state":"archived","external_url":null},{"nid":777,"title":"Moxa Active OPC Server Vulnerability","uuid":"8625ca8e-3e9a-4fac-9b22-02900e7f72c4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-26T17:17:37Z","summary":null,"body":["<article data-history-node-id=\"777\" about=\"\/en\/alerts-advisories\/moxa-active-opc-server-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-148<br \/>\nDate: 21 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an identified unquoted service path escalation vulnerability in Moxa Active OPC Server.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Successful exploitation of this vulnerability could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. The most recent version (2.4.19) serves to mitigate this vulnerability.<\/p>\n\n<p>Version affected: Active OPC Server versions older than Version 2.4.19<\/p>\n\n<p>CVE Reference: CVE-2016-5793<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released installations in accordance with the vendor's documentation. Active OPC Server is nearing end of life by the end of 2016, and no further updates will be issue.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.moxa.com\/support\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support (link is external)<\/font><\/a><br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-264-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-264-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moxa-active-opc-server-vulnerability","alert_type":396,"serial_number":"AV16-148","subject":null,"moderation_state":"archived","external_url":null},{"nid":1070,"title":"OpenSSL Advisory \u2013 Multiple Vulnerabilities","uuid":"356cdb4a-5220-4418-aff1-27880e0a3024","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:24Z","date_created":"2018-06-26T17:25:18Z","summary":null,"body":["<article data-history-node-id=\"1070\" about=\"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-149<br \/>\nDate: 22 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security updates released by OpenSSL.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of fourteen (1 high, 1 moderate and 12 low) disclosed vulnerabilities in OpenSSL for which updates are available.<\/p>\n\n<p>Affected Versions: 1.1.0, 1.0.1 and 1.0.2<\/p>\n\n<p>CVE References: CVE-2016-6304, CVE-2016-6305, CVE-2016-2183, CVE-2016-6303, CVE-2016-6302, CVE-2016-2182, CVE-2016-2180, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2181, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<br \/>\nOpenSSL 1.1.0 users should upgrade to 1.1.0a<br \/>\nOpenSSL 1.0.2 users should upgrade to 1.0.2i<br \/>\nOpenSSL 1.0.1 users should upgrade to 1.0.1u<\/p>\n\n<h2>References<\/h2>\n\n<p>OpenSSL Advisory - <a href=\"https:\/\/www.openssl.org\/news\/secadv\/20160922.txt\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/news\/secadv\/20160922.txt<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-2","alert_type":396,"serial_number":"AV16-149","subject":null,"moderation_state":"archived","external_url":null},{"nid":1094,"title":"Drupal security updates \u2013 September 2016","uuid":"a3fb399f-e412-4944-aaf7-6894b6d4e41b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-26T17:38:12Z","summary":null,"body":["<article data-history-node-id=\"1094\" about=\"\/en\/alerts-advisories\/drupal-security-updates-september-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-150<br \/>\nDate: 22 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Drupal security releases.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple security vulnerabilities. Exploitation of these vulnerabilities may allow an unauthorized attacker to perform arbitrary remote code execution.<\/p>\n\n<p>Affected Versions:<br \/>\nDrupal Core - versions 8.x<br \/>\nFlag Lists - 7.x-3.x versions prior to 7.x-3.1, and 7.x-1.x versions prior to 7.x-1.3<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Drupal Advisory:<br \/><a href=\"https:\/\/www.drupal.org\/SA-CORE-2016-004\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/SA-CORE-2016-004<\/font><\/a><br \/><a href=\"https:\/\/www.drupal.org\/node\/2796651\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/node\/2796651<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-updates-september-2016","alert_type":396,"serial_number":"AV16-150","subject":null,"moderation_state":"archived","external_url":null},{"nid":928,"title":"Cisco Releases security updates","uuid":"57536fef-b2d8-46b1-b5fd-408d347ba4cc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-26T17:45:11Z","summary":null,"body":["<article data-history-node-id=\"928\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-151<br \/>\nDate: 22 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco Cloud Services Platform 2100, Cisco IOS and IOS XE, Cisco Firepower Management Center and FireSIGHT System Software, Cisco Prime Home Web-Based User Interface, Cisco Application-Hosting Framework, and Cisco Application Policy Infrastructure Controller.<\/p>\n\n<p>CVE References: CVE-2016-6373, CVE-2016-6374, CVE-2016-6414, CVE-2016-6411, CVE-2016-6409, CVE-2016-6408, CVE-2016-6412, CVE-2016-6413, CVE-2015-6358<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-csp2100-1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-csp2100-1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-csp2100-2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-csp2100-2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-iox\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-iox<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-fmc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-fmc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-dmo\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-dmo<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-cph\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-cph<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-caf1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-caf1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-apic\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160921-apic<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20151125-ci\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20151125-ci<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-2","alert_type":396,"serial_number":"AV16-151","subject":null,"moderation_state":"archived","external_url":null},{"nid":1184,"title":"Fortinet FortiWan Multiple Vulnerabilities","uuid":"375dcfed-3a8b-4841-8d62-d976ddc104e9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-26T17:51:01Z","summary":null,"body":["<article data-history-node-id=\"1184\" about=\"\/en\/alerts-advisories\/fortinet-fortiwan-multiple-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-152<br \/>\nDate: 22 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple vulnerabilities in Fortinet's FortiWan appliance.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Fortinet has announced vulnerabilities in its FortiWan appliances. Impacted versions include FortiWan 4.2.4 and below. Vulnerabilities include; exposure to cross site scripting, information leaks and escalation of privilege.<\/p>\n\n<p>CVE References: CVE-2016-4965, CVE-2016-4966, CVE-2016-4967, CVE-2016-4968, CVE-2016-4969<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. Fortinet recommends upgrading appliances to 4.2.5 or above.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/fortiguard.com\/advisory\/fortiwan-multiple-vulnerabilities\"><font color=\"#0066cc\">http:\/\/fortiguard.com\/advisory\/fortiwan-multiple-vulnerabilities<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4965\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4965<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4966\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4966<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4967\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4967<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4968\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4968<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4969\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2016-4969<\/font><\/a>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-fortiwan-multiple-vulnerabilities","alert_type":396,"serial_number":"AV16-152","subject":null,"moderation_state":"archived","external_url":null},{"nid":817,"title":"OpenSSL Advisory \u2013 security updates","uuid":"053ca19a-f1ea-4a7e-88cf-2951ee433769","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-26T17:56:49Z","summary":null,"body":["<article data-history-node-id=\"817\" about=\"\/en\/alerts-advisories\/openssl-advisory-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-153<br \/>\nDate: 26 September 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to OpenSSL security updates, \u00a0intended to fix issues caused by patches released in OpenSSL\u2019s previous security update (September 22 2016).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Two specific vulnerability issues are addressed in this update; 1 critical and 1 moderate in severity.<\/p>\n\n<p>Affected Versions:\u00a0 OpenSSL versions 1.1.0 and 1.0.2i.<\/p>\n\n<p>CVE References: CVE-2016-6309, CVE-2016-7052.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p>OpenSSL 1.1.0 users should upgrade to 1.1.0b<br \/>\nOpenSSL 1.0.2i users should upgrade to 1.0.2j\u00a0\u00a0\u00a0<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20160926.txt\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/news\/secadv\/20160926.txt<\/font><\/a>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0\u00a0<br \/><a href=\"https:\/\/www.openssl.org\/policies\/secpolicy.html\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/policies\/secpolicy.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-security-updates","alert_type":396,"serial_number":"AV16-153","subject":null,"moderation_state":"archived","external_url":null},{"nid":899,"title":"Security Fix Released for BIND","uuid":"8a32fc1e-48db-42d1-b2b8-cba5b0596b9a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:43Z","date_created":"2018-06-26T18:03:54Z","summary":null,"body":["<article data-history-node-id=\"899\" about=\"\/en\/alerts-advisories\/security-fix-released-bind\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-154<br \/>\nDate: 28 September 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Internet Security Consortium (ISC) has released a security fix to address a vulnerability in BIND. A parser function in BIND could cause a failure in the rendering of the message of a specially crafted request. \u00a0<\/p>\n\n<p>Versions affected: BIND 9.0.x -&gt; 9.8.x, 9.9.0-&gt;9.9.9-P2, 9.9.3-S1-&gt;9.9.9-S3, 9.10.0-&gt;9.10.4-P2, 9.11.0a1-&gt;9.11.0rc1<\/p>\n\n<p>CVE Reference: CVE-2016-2776<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01419\/0\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01419\/0<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fix-released-bind","alert_type":396,"serial_number":"AV16-154","subject":null,"moderation_state":"archived","external_url":null},{"nid":1322,"title":"Cisco Releases security updates","uuid":"7fd3d500-a208-4bbd-a5ee-8988e895534c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-26T18:15:20Z","summary":null,"body":["<article data-history-node-id=\"1322\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-155<br \/>\nDate: 29 September 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco Email Security Appliance, Cisco Videoscape Distribution Suite Service Manager, Cisco IOS and IOS XE Software, Cisco IOS XR Software, Cisco Firepower Management Center and FireSIGHT System Software and Cisco AsyncOS.<\/p>\n\n<p>CVE References: CVE-2016-1384, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6378, CVE-2016-6379, CVE-2016-6380, CVE-2016-6381, CVE-2016-6382, CVE-2016-6384, CVE-2016-6385, CVE-2016-6386, CVE-2016-6391, CVE-2016-6392, CVE-2016-6393, CVE-2016-6406, CVE-2016-6416, CVE-2016-6417, CVE-2016-6418, CVE-2016-6419, CVE-2016-6420, CVE-2016-6421, CVE-2016-7052<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected<br \/>\napplications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160922-esa\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160922-esa<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-vds\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-vds<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-smi\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-smi<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-ospf\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-ospf<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-msdp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-msdp<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-ipdr\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-ipdr<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-ios-ikev1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-ios-ikev1<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-h323\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-h323<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-frag\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-frag<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-fpmc\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-fpmc<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-fmc1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-fmc1<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-fmc\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-fmc<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-esp-nat\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-esp-nat<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-dns\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-dns<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-cip\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-cip<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-aos\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-aos<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-aaados\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160928-aaados<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160419-ios\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160419-ios<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-3","alert_type":396,"serial_number":"AV16-155","subject":null,"moderation_state":"archived","external_url":null},{"nid":1022,"title":"Google Releases security update for Chrome","uuid":"d2943d6b-8bed-49da-8415-7f7c3c227207","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:09Z","date_created":"2018-06-26T18:21:38Z","summary":null,"body":["<article data-history-node-id=\"1022\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-156<br \/>\nDate: 30 September 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 53.0.2785.143 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2016-5177, CVE-2016-5178<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/googlechromereleases.blogspot.ca\/2016\/09\/stable-channel-update-for-desktop_29.html\"><font color=\"#0066cc\">https:\/\/googlechromereleases.blogspot.ca\/2016\/09\/stable-channel-update-for-desktop_29.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-13","alert_type":396,"serial_number":"AV16-156","subject":null,"moderation_state":"archived","external_url":null},{"nid":1153,"title":"Oracle MySQL security update","uuid":"90a5ba29-2d55-466b-b836-13612b5c4224","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-06-26T18:29:35Z","summary":null,"body":["<article data-history-node-id=\"1153\" about=\"\/en\/alerts-advisories\/oracle-mysql-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-157<br \/>\nDate: 01 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>This advisory is to bring attention to recently released Oracle MySQL security updates addressing a critical vulnerability.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has released security updates to address a critical vulnerability in MySQL. Exploitation of this vulnerability may allow for arbitrary remote code execution.\u00a0 This vulnerability also affects some projects forked from the main MySQL branch, including MariaDB and Percona Server.<\/p>\n\n<p>Versions affected:<\/p>\n\n<ul><li>Oracle MySQL 5.5.x prior to version 5.5.52<\/li>\n\t<li>Oracle MySQL 5.6.x prior to version 5.5.33<\/li>\n\t<li>Oracle MySQL 5.7.x prior to version 5.7.15<\/li>\n\t<li>MariaDB (see references for more information)<\/li>\n\t<li>Percona Server and XtraDB Cluster (see references for more information)<\/li>\n<\/ul><p>CVE Reference: CVE-2016-6662<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>=================\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\nNational Vulnerability Database:<br \/><a href=\"https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-6662\"><font color=\"#0066cc\">https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2016-6662<\/font><\/a><\/p>\n\n<p>Security Researcher:<br \/><a href=\"http:\/\/legalhackers.com\/advisories\/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.html\"><font color=\"#0066cc\">http:\/\/legalhackers.com\/advisories\/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.html<\/font><\/a><\/p>\n\n<p>Oracle MySQL Release Notes:<br \/><a href=\"https:\/\/dev.mysql.com\/doc\/relnotes\/mysql\/5.5\/en\/news-5-5-52.html\"><font color=\"#0066cc\">https:\/\/dev.mysql.com\/doc\/relnotes\/mysql\/5.5\/en\/news-5-5-52.html<\/font><\/a><br \/><a href=\"https:\/\/dev.mysql.com\/doc\/relnotes\/mysql\/5.6\/en\/news-5-6-33.html\"><font color=\"#0066cc\">https:\/\/dev.mysql.com\/doc\/relnotes\/mysql\/5.6\/en\/news-5-6-33.html<\/font><\/a><br \/><a href=\"https:\/\/dev.mysql.com\/doc\/relnotes\/mysql\/5.7\/en\/news-5-7-15.html\"><font color=\"#0066cc\">https:\/\/dev.mysql.com\/doc\/relnotes\/mysql\/5.7\/en\/news-5-7-15.html<\/font><\/a><\/p>\n\n<p>MariaDB Security Announcement:<br \/><a href=\"https:\/\/mariadb.org\/mariadb-server-versions-remote-root-code-execution-vulnerability-cve-2016-6662\/\"><font color=\"#0066cc\">https:\/\/mariadb.org\/mariadb-server-versions-remote-root-code-execution-vulnerability-cve-2016-6662\/<\/font><\/a><\/p>\n\n<p>Percona Server Critical Update:<br \/><a href=\"https:\/\/www.percona.com\/blog\/2016\/09\/12\/percona-server-critical-update-cve-2016-6662\/\"><font color=\"#0066cc\">https:\/\/www.percona.com\/blog\/2016\/09\/12\/percona-server-critical-update-cve-2016-6662\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-mysql-security-update","alert_type":396,"serial_number":"AV16-157","subject":null,"moderation_state":"archived","external_url":null},{"nid":1210,"title":"Android security bulletin \u2013 October 2016","uuid":"67a80d7e-af8d-4745-9b24-25864bf64abb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-26T18:35:46Z","summary":null,"body":["<article data-history-node-id=\"1210\" about=\"\/en\/alerts-advisories\/android-security-bulletin-october-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-158<br \/>\nDate: 04 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for October.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for 48 vulnerabilities (5 Critical, 29 High, 13 Moderate, 1 Low). Those viewed Critical are so given the possibility of remote code execution vulnerabilities and\/or elevation of privilege vulnerabilities.<\/p>\n\n<p>CVE References: CVE-2015-0572, CVE-2015-8950, CVE-2015-8951, CVE-2015-8955, CVE-2015-8956, CVE-2016-0758, CVE-2016-2059, CVE-2016-3860, CVE-2016-3882, CVE-2016-3900, CVE-2016-3901, CVE-2016-3902, CVE-2016-3903, CVE-2016-3905, CVE-2016-3908, CVE-2016-3909, CVE-2016-3910, CVE-2016-3911, CVE-2016-3912, CVE-2016-3913, CVE-2016-3914, CVE-2016-3915, CVE-2016-3916, CVE-2016-3917, CVE-2016-3918, CVE-2016-3920, CVE-2016-3921, CVE-2016-3922, CVE-2016-3923, CVE-2016-3924, CVE-2016-3925, CVE-2016-3926, CVE-2016-3927, CVE-2016-3928, CVE-2016-3929, CVE-2016-3930, CVE-2016-3931, CVE-2016-3932, CVE-2016-3933, CVE-2016-3934, CVE-2016-3935, CVE-2016-3936, CVE-2016-3937, CVE-2016-3938, CVE-2016-3939, CVE-2016-3940, CVE-2016-5340, CVE-2016-5342, CVE-2016-5343, CVE-2016-5344, CVE-2016-5348, CVE-2016-5696, CVE-2016-6672, CVE-2016-6673, CVE-2016-6674, CVE-2016-6675, CVE-2016-6676, CVE-2016-6677, CVE-2016-6678, CVE-2016-6679, CVE-2016-6680, CVE-2016-6681, CVE-2016-6682, CVE-2016-6683, CVE-2016-6684, CVE-2016-6685, CVE-2016-6686, CVE-2016-6687, CVE-2016-6688, CVE-2016-6689, CVE-2016-6690, CVE-2016-6691, CVE-2016-6692, CVE-2016-6693, CVE-2016-6694, CVE-2016-6695, CVE-2016-6696, CVE-2016-7117.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Android Security Bulletin:<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-10-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-10-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-october-2016","alert_type":396,"serial_number":"AV16-158","subject":null,"moderation_state":"archived","external_url":null},{"nid":1298,"title":"F5 security advisory for BIG-IP","uuid":"5bdea83b-cbc9-47fe-8683-ee0b67034cd1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-06-26T18:42:13Z","summary":null,"body":["<article data-history-node-id=\"1298\" about=\"\/en\/alerts-advisories\/f5-security-advisory-big-ip\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-159<br \/>\nDate: 05 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Security Advisory released by F5 for its BIG-IP products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A recently released F5 Security Advisory has announced a critical vulnerability affecting some of its BIG-IP products. Exploitation of this vulnerability could allow an unauthenticated remote attacker to modify system configurations, extract sensitive system files and\/or perform arbitrary command execution.<\/p>\n\n<p>For a list of affected products, please see reference for more information.<\/p>\n\n<p>CVE Reference: CVE-2016-5700<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.f5.com\/kb\/en-us\/solutions\/public\/k\/35\/sol35520031.html\"><font color=\"#0066cc\">https:\/\/support.f5.com\/kb\/en-us\/solutions\/public\/k\/35\/sol35520031.html<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-big-ip","alert_type":396,"serial_number":"AV16-159","subject":null,"moderation_state":"archived","external_url":null},{"nid":909,"title":"Cisco Releases security updates","uuid":"91881ace-d8e3-467f-bd69-6aa7a02c3c46","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-26T19:01:44Z","summary":null,"body":["<article data-history-node-id=\"909\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-160<br \/>\nDate: 06 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco Unified Intelligence Center (CUIC), Cisco Nexus 7000 and 7700 Series Switches, Cisco NX-OS Software Based Products, Cisco Nexus 9000, Cisco IOS XR Software, Cisco IOS and IOS XE, Cisco Firepower, Cisco IOS Software for Cisco Catalyst 6500 Series Switches and 7600 Series Routers, Cisco ASA Software and Cisco Email.<\/p>\n\n<p>CVE References: CVE-2015-0721, CVE-2015-6289, CVE-2015-6392, CVE-2015-6393, CVE-2016-1453, CVE-2016-1454, CVE-2016-1455, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6406, CVE-2016-6415, CVE-2016-6422, CVE-2016-6423, CVE-2016-6424, CVE-2016-6425, CVE-2016-6426, CVE-2016-6427, CVE-2016-6428, CVE-2016-6433, CVE-2016-6434, CVE-2016-6435, CVE-2016-6436, CVE-2016-7052<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ucis3\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ucis3<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ucis2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ucis2<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ucis1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ucis1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-otv\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-otv<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-nxaaa\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-nxaaa<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-n9kinfo\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-n9kinfo<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-iosxr\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-iosxr<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ios-ikev\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ios-ikev<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ftmc2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ftmc2<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ftmc1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ftmc1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ftmc\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-ftmc<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-dhcp2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-dhcp2<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-dhcp1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-dhcp1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-chs\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-chs<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-catalyst\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-catalyst<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-bgp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-bgp<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-asa-dhcp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161005-asa-dhcp<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160916-ikev1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160916-ikev1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160922-esa\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160922-esa<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160620-isr\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160620-isr<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-4","alert_type":396,"serial_number":"AV16-160","subject":null,"moderation_state":"archived","external_url":null},{"nid":884,"title":"Moxa ioLogik Multiple Vulnerabilities","uuid":"07abb3ad-6767-45d3-952e-4b544b7b6969","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-06-26T19:08:00Z","summary":null,"body":["<article data-history-node-id=\"884\" about=\"\/en\/alerts-advisories\/moxa-iologik-multiple-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-161<br \/>\nDate: 06 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple vulnerabilities in the Moxa ioLogik series of Ethernet remote I\/O devices.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Successful exploitation of this vulnerability could potentially allow an attacker to gain access to the device, change settings and data on the target device.<\/p>\n\n<p>Versions affected: ioLogik E2210, ioLogik E2212, ioLogik E2240, ioLogik E2262, ioLogik E1262 ,ioLogik E2260, ioLogik E2242, ioLogik E2214, ioLogik E1211, ioLogik E1212, ioLogik E1241, ioLogik E1242, ioLogik E1260, ioLogik E1210, ioLogik E1214, ioLogik E1240, ioLogik E1213, ioLogik E1261W-T, ioLogik E1261H-T and ioLogik E1263H-T<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates in accordance with the vendor\u2019s documentation.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.moxa.com\/support\/faq\/faq_detail.aspx?id=2703\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/faq\/faq_detail.aspx?id=2703<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moxa-iologik-multiple-vulnerabilities","alert_type":396,"serial_number":"AV16-161","subject":null,"moderation_state":"archived","external_url":null},{"nid":1053,"title":"security updates for Multiple Adobe Products","uuid":"5325e883-aaee-4af8-a848-8911b7221e46","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-06-26T19:15:53Z","summary":null,"body":["<article data-history-node-id=\"1053\" about=\"\/en\/alerts-advisories\/security-updates-multiple-adobe-products-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-162<br \/>\nDate: 11 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for multiple Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletins APSB16-32, APSB16-33, and APSB16-34 to address critical, important and moderate vulnerabilities that could allow an attacker to take control of vulnerable systems. All OS platforms are reported as being impacted.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime 23.0.0.162 and earlier (Windows and Macintosh)<\/li>\n\t<li>Adobe Flash Player Extended Support Release 18.0.0.375 and earlier (Windows and Macintosh)<\/li>\n\t<li>Adobe Flash Player for Google Chrome 23.0.0.162 and earlier (Windows, Macintosh, Linux and ChromeOS)<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 23.0.0.162 and earlier (Windows 10 and 8.1)<\/li>\n\t<li>Adobe Flash Player for Linux 11.2.202.635 and earlier (Linux)<\/li>\n\t<li>Acrobat DC 15.017.20053 and earlier versions (Windows and Macintosh)<\/li>\n\t<li>Acrobat Reader DC 15.017.20053 and earlier versions (Windows and Macintosh)<\/li>\n\t<li>Acrobat DC 15.006.30201 and earlier versions (Windows and Macintosh)<\/li>\n\t<li>Acrobat Reader DC 15.006.30201 and earlier versions (Windows and Macintosh)<\/li>\n\t<li>Acrobat XI 11.0.17 and earlier versions (Windows and Macintosh)<\/li>\n\t<li>Reader XI 11.0.17 and earlier versions (Windows and Macintosh)<\/li>\n\t<li>Creative Cloud Desktop Application Creative Cloud 3.7.0.272 and earlier versions (Windows)<\/li>\n<\/ul><p>CVE References: CVE-2016-4273, CVE-2016-4286, CVE-2016-6981, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6987, CVE-2016-6989, CVE-2016-6990, CVE-2016-6992, CVE-2016-1089, CVE-2016-1091, CVE-2016-6939, CVE-2016-6940, CVE-2016-6941, CVE-2016-6942, CVE-2016-6943, CVE-2016-6944, CVE-2016-6945, CVE-2016-6946, CVE-2016-6947, CVE-2016-6948, CVE-2016-6949, CVE-2016-6950, CVE-2016-6951, CVE-2016-6952, CVE-2016-6953, CVE-2016-6954, CVE-2016-6955, CVE-2016-6956, CVE-2016-6957, CVE-2016-6958, CVE-2016-6959, CVE-2016-6960, CVE-2016-6961, CVE-2016-6962, CVE-2016-6963, CVE-2016-6964, CVE-2016-6965, CVE-2016-6966, CVE-2016-6967, CVE-2016-6968, CVE-2016-6969, CVE-2016-6970, CVE-2016-6971, CVE-2016-6972, CVE-2016-6973, CVE-2016-6974, CVE-2016-6975, CVE-2016-6976, CVE-2016-6977, CVE-2016-6978, CVE-2016-6979, CVE-2016-6988, CVE-2016-6993, CVE-2016-6994, CVE-2016-6995, CVE-2016-6996, CVE-2016-6997, CVE-2016-6998, CVE-2016-6999, CVE-2016-7000, CVE-2016-7001, CVE-2016-7002, CVE-2016-7003, CVE-2016-7004, CVE-2016-7005, CVE-2016-7006, CVE-2016-7007, CVE-2016-7008, CVE-2016-7009, CVE-2016-7010, CVE-2016-7011, CVE-2016-7012, CVE-2016-7013, CVE-2016-7014, CVE-2016-7015, CVE-2016-7016, CVE-2016-7017, CVE-2016-7018, CVE-2016-7019, CVE-2016-6935<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Adobe Security Bulletin:<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-32.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-32.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-33.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb16-33.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb16-34.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb16-34.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-updates-multiple-adobe-products-1","alert_type":396,"serial_number":"AV16-162","subject":null,"moderation_state":"archived","external_url":null},{"nid":1167,"title":"Microsoft Critical security bulletins Summary \u2013 October 2016","uuid":"b84f0464-f34f-4ac5-bb20-f0137b4e42b9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:44Z","date_created":"2018-06-26T19:23:21Z","summary":null,"body":["<article data-history-node-id=\"1167\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-october-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-163<br \/>\nDate: 11 October 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for October 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 10 bulletins (5 Critical, 4 Important and 1 Moderate), which addresses multiple vulnerabilities in Microsoft Internet Explorer, Microsoft Edge, Microsoft Office, Microsoft Graphics Component, Microsoft Video Control, Adobe Flash Player, Windows Kernel-Mode Drivers, Windows Registry,\u00a0 Diagnostics Hub, and Microsoft Internet Messaging API.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS16-118 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for Internet Explorer (3192887)<\/li>\n\t<li>MS16-119 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cumulative Security Update for Microsoft Edge (3192890)<\/li>\n\t<li>MS16-120 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Microsoft Graphics Component (3192884)<\/li>\n\t<li>MS16-122 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Microsoft Video Control (3195360)<\/li>\n\t<li>MS16-127 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Adobe Flash Player (3194343)<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS16-121 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Microsoft Office (3194063)<\/li>\n\t<li>MS16-123 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Kernel-Mode Drivers (3192892)<\/li>\n\t<li>MS16-124 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Windows Registry (3193227)<\/li>\n\t<li>MS16-125 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Diagnostics Hub (3193229)<\/li>\n<\/ul><p>***Moderate***<\/p>\n\n<ul><li>MS16-126 \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Security Update for Microsoft Internet Messaging API (3196067)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-oct.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-oct.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-october-2016","alert_type":396,"serial_number":"AV16-163","subject":null,"moderation_state":"archived","external_url":null},{"nid":779,"title":"Cisco Releases security updates","uuid":"a6793a86-692c-48ee-b2de-bf036ba07f37","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-26T19:29:46Z","summary":null,"body":["<article data-history-node-id=\"779\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-164<br \/>\nDate: 13 October 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco Meeting Server Client, Cisco Wide Area Application Services Central Manager, Cisco Unified Communications Manager, Cisco Prime Infrastructure and Evolved Programmable Network Manager, Cisco Finesse and Cisco cBR-8 Converged Broadband Router.<\/p>\n\n<p>CVE References:<\/p>\n\n<p>Critical Impact CVE: CVE-2016-6445<br \/>\nMedium Impact CVE: CVE-2016-6437, CVE-2016-6438, CVE-2016-6440, CVE-2016-6442, CVE-2016-6443<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-msc\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-msc<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-waas\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-waas<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-cbr-8\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-cbr-8<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-ucm\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-ucm<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-fin\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-fin<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-prime\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161012-prime<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-5","alert_type":396,"serial_number":"AV16-164","subject":null,"moderation_state":"archived","external_url":null},{"nid":1261,"title":"Google Releases security update for Chrome","uuid":"6bcb1695-6d26-4550-a426-5361c3d24099","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-06-26T19:36:09Z","summary":null,"body":["<article data-history-node-id=\"1261\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-14\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-165<br \/>\nDate: 13 October 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 54.0.2840.59 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2016-5181, CVE-2016-5182, CVE-2016-5183, CVE-2016-5184, CVE-2016-5185, CVE-2016-5187, CVE-2016-5188, CVE-2016-5192, CVE-2016-5189, CVE-2016-5186, CVE-2016-5191, CVE-2016-5190, CVE-2016-5193, CVE-2016-5194<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/googlechromereleases.blogspot.ca\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/googlechromereleases.blogspot.ca\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-14","alert_type":null,"serial_number":"AV16-165","subject":null,"moderation_state":"archived","external_url":null},{"nid":1096,"title":"Oracle Critical Patch update Advisory \u2013 October 2016","uuid":"ea645df9-ea4e-4241-b0bf-1f12508b7271","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-06-26T19:43:01Z","summary":null,"body":["<article data-history-node-id=\"1096\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-october-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-166<br \/>\nDate: 19 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following critical patch updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update (CPU) which addresses 253 new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Application Express, version(s) prior to 5.0.4.0.7<\/li>\n\t<li>Oracle Database Server, version(s) 11.2.0.4, 12.1.0.2<\/li>\n\t<li>Oracle Secure Backup, version(s) prior to 10.4.0.4.0, prior to 12.1.0.2.0<\/li>\n\t<li>Big Data Graph, version(s) prior to 1.2<\/li>\n\t<li>NetBeans, version(s) 8.1<\/li>\n\t<li>Oracle BI Publisher, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.2.1.0.0<\/li>\n\t<li>Oracle Big Data Discovery, version(s) 1.1.1, 1.1.3, 1.2.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.1.1.0.0, 12.2.1.1.0<\/li>\n\t<li>Oracle Data Integrator, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.1.2.0.0, 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0<\/li>\n\t<li>Oracle Discoverer, version(s) 11.1.1.7.0<\/li>\n\t<li>Oracle Fusion Middleware, version(s) 11.1.1.7, 11.1.1.9, 11.1.2.3, 11.1.2.4, 12.1.3.0, 12.2.1.0, 12.2.1.1<\/li>\n\t<li>Oracle GlassFish Server, version(s) 2.1.1, 3.0.1, 3.1.2<\/li>\n\t<li>Oracle Identity Manager, version(s) -<\/li>\n\t<li>Oracle iPlanet Web Proxy Server, version(s) 4.0<\/li>\n\t<li>Oracle iPlanet Web Server, version(s) 7.0<\/li>\n\t<li>Oracle Outside In Technology, version(s) 8.4.0, 8.5.1, 8.5.2, 8.5.3<\/li>\n\t<li>Oracle Platform Security for Java, version(s) 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0<\/li>\n\t<li>Oracle Web Services, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.0.0<\/li>\n\t<li>Oracle WebCenter Sites, version(s) 12.2.1.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle WebLogic Server, version(s) 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1<\/li>\n\t<li>Enterprise Manager, version(s) 12.1.4, 12.2.2, 12.3.2<\/li>\n\t<li>Enterprise Manager Base Platform, version(s) 12.1.0.5<\/li>\n\t<li>Oracle Application Testing Suite, version(s) 12.5.0.1, 12.5.0.2, 12.5.0.3<\/li>\n\t<li>Oracle E-Business Suite, version(s) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6<\/li>\n\t<li>Oracle Advanced Supply Chain Planning, version(s) 12.2.3, 12.2.4, 12.2.5<\/li>\n\t<li>Oracle Agile Engineering Data Management, version(s) 6.1.3.0, 6.2.0.0<\/li>\n\t<li>Oracle Agile PLM, version(s) 9.3.4, 9.3.5<\/li>\n\t<li>Oracle Agile Product Lifecycle Management for Process, version(s) 6.1.0.4, 6.1.1.6, 6.2.0.0<\/li>\n\t<li>Oracle Transportation Management, version(s) 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7<\/li>\n\t<li>PeopleSoft Enterprise HCM, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, version(s) 8.54, 8.55<\/li>\n\t<li>PeopleSoft Enterprise SCM Services Procurement, version(s) 9.1, 9.2<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version(s) 9.1<\/li>\n\t<li>JD Edwards World Security, version(s) A9.4<\/li>\n\t<li>Siebel Applications, version(s) 7.1, 16.1<\/li>\n\t<li>Oracle Commerce Guided Search, version(s) 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1, 6.5.2<\/li>\n\t<li>Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager, version(s) 3.1.1, 3.1.2, 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1, 6.5.2, 11.0, 11.1, 11.2<\/li>\n\t<li>Oracle Commerce Platform, version(s) 10.0.3.5, 10.2.0.5, 11.2.0.1<\/li>\n\t<li>Oracle Commerce Service Center, version(s) 10.0.3.5, 10.2.0.5<\/li>\n\t<li>Oracle Fusion Applications, version(s) 11.1.2 through 11.1.9<\/li>\n\t<li>Oracle Communications Policy Management, version(s) 9.7.3, 9.9.1, 10.4.1, 12.1.1 and prior<\/li>\n\t<li>Oracle Enterprise Communications Broker, version(s) Pcz2.0.0m4p5 and earlier<\/li>\n\t<li>Oracle Enterprise Session Border Controller, version(s) Ecz7.3m2p2 and earlier<\/li>\n\t<li>Oracle Banking Digital Experience, version(s) 15.1<\/li>\n\t<li>Oracle Financial Services Analytical Applications Infrastructure, version(s) 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 8.0.0, 8.0.1, 8.0.2, 8.0.3<\/li>\n\t<li>Oracle Financial Services Lending and Leasing, version(s) 14.1.0, 14.2.0<\/li>\n\t<li>Oracle FLEXCUBE Core Banking, version(s) 11.5.0.0.0, 11.6.0.0.0<\/li>\n\t<li>Oracle FLEXCUBE Enterprise Limits and Collateral Management, version(s) 12.0.0, 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Investor Servicing, version(s) 12.0.1<\/li>\n\t<li>Oracle FLEXCUBE Private Banking, version(s) 2.0.0, 2.0.1, 2.2.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Universal Banking, version(s) 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.87.1, 12.87.2<\/li>\n\t<li>Oracle Life Sciences Data Hub, version(s) 2.x<\/li>\n\t<li>Oracle Hospitality OPERA 5 Property Services, version(s) 5.4.0.0, 5.4.1.0, 5.4.2.0, 5.4.3.0, 5.5.0.0, 5.5.1.0<\/li>\n\t<li>Oracle Insurance IStream, version(s) 4.3.2<\/li>\n\t<li>MICROS XBR, version(s) 7.0.2, 7.0.4<\/li>\n\t<li>Oracle Retail Back Office, version(s) 13.0, 13.1, 13.2, 13.3, 13.4, 14.0, 14.1<\/li>\n\t<li>Oracle Retail Central Office, version(s) 13.0, 13.1, 13.2, 13.3, 13.4, 14.0, 14.1<\/li>\n\t<li>Oracle Retail Clearance Optimization Engine, version(s) 13.2, 13.3, 13.4, 14.0<\/li>\n\t<li>Oracle Retail Customer Insights, version(s) 15.0<\/li>\n\t<li>Oracle Retail Merchandising Insights, version(s) 15.0<\/li>\n\t<li>Oracle Retail Returns Management, version(s) 13.0, 13.1, 13.2, 13.3, 13.4, 14.0, 14.1<\/li>\n\t<li>Oracle Retail Xstore Payment, version(s) 1.x<\/li>\n\t<li>Oracle Retail Xstore Point of Service, version(s) 5.0, 5.5, 6.0, 6.5, 7.0, 7.1<\/li>\n\t<li>Primavera P6 Enterprise Project Portfolio Management, version(s) 8.4, 15.x, 16.x<\/li>\n\t<li>Primavera P6 Professional Project Management, version(s) 8.3, 8.4, 15.x, 16.x<\/li>\n\t<li>Oracle Java SE, version(s) 6u121, 7u111, 8u102<\/li>\n\t<li>Oracle Java SE Embedded, version(s) 8u101<\/li>\n\t<li>Solaris, version(s) 10, 11.3<\/li>\n\t<li>Solaris Cluster, version(s) 3.3, 4.3<\/li>\n\t<li>Sun ZFS Storage Appliance Kit (AK), version(s) AK 2013<\/li>\n\t<li>Oracle VM VirtualBox, version(s) prior to 5.0.28, prior to 5.1.8<\/li>\n\t<li>Secure Global Desktop, version(s) 4.7, 5.2<\/li>\n\t<li>Sun Ray Operating Software, version(s) prior to 11.1.7<\/li>\n\t<li>Virtual Desktop Infrastructure, version(s) prior to 3.5.3<\/li>\n\t<li>MySQL Connector, version(s) 2.0.4 and prior, 2.1.3 and prior<\/li>\n\t<li>MySQL Server, version(s) 5.5.52 and prior, 5.6.33 and prior, 5.7.15 and prior<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2016-2881722.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2016-2881722.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-october-2016","alert_type":396,"serial_number":"AV16-166","subject":null,"moderation_state":"archived","external_url":null},{"nid":930,"title":"Multiple Juniper security updates","uuid":"34986187-a5ce-4ac6-a672-7dc91a4c9626","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-27T13:01:40Z","summary":null,"body":["<article data-history-node-id=\"930\" about=\"\/en\/alerts-advisories\/multiple-juniper-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-167<br \/>\nDate: 19 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Juniper system security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Juniper has released security updates to address multiple vulnerabilities in Juniper products. The exploitation of these vulnerabilities could result in the remote execution of arbitrary code, denial of service, affect the integrity of files and folders.<\/p>\n\n<p>Impacted products:<\/p>\n\n<ul><li>Juniper Juno OS<\/li>\n\t<li>vMX (Virtual MX Series router)<\/li>\n\t<li>JUNOSe with IPv6 enabled<\/li>\n\t<li>Junos OS with J-Web enabled<\/li>\n\t<li>Junos OS with IPv6 enabled<\/li>\n\t<li>CTPView prior to 7.1R3, 7.3R1<\/li>\n\t<li>Junos Space before 15.2R2<\/li>\n<\/ul><p>CVE Numbers:<\/p>\n\n<p>CVE-2013-0169, CVE-2016-4926, CVE-2016-4927, CVE-2016-4928, CVE-2016-4929, CVE-2016-4930, CVE-2016-4931, CVE-2011-0997, CVE-2011-2748, CVE-2011-2749, CVE-2012-3571, CVE-2013-0791, CVE-2013-1620, CVE-2013-1739, CVE-2013-1741, CVE-2013-2596, CVE-2013-5605, CVE-2013-5606, CVE-2013-5607, CVE-2014-1490, CVE-2014-1491, CVE-2014-1492, CVE-2014-1545, CVE-2014-1568, CVE-2015-1794, CVE-2015-2151, CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-5364, CVE-2015-5366, CVE-2016-4921, CVE-2016-4923, CVE-2016-4925, CVE-2016-4924, CVE-2016-4922<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Juniper Security Bulletins<\/p>\n\n<ul><li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10763&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10763&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><u> <\/u><\/li>\n\t<li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10766&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10766&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><u> <\/u><\/li>\n\t<li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10767&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10767&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10764&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10764&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><u> <\/u><\/li>\n\t<li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10762&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10762&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><u> <\/u><\/li>\n\t<li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10761&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10761&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><u> <\/u><\/li>\n\t<li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10760&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10760&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-juniper-security-updates","alert_type":396,"serial_number":"AV16-167","subject":null,"moderation_state":"archived","external_url":null},{"nid":1186,"title":"Security fixes released for BIND","uuid":"199ea82a-3a1f-45e2-b91d-98ef3313bcdf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:57Z","date_created":"2018-06-27T13:08:42Z","summary":null,"body":["<article data-history-node-id=\"1186\" about=\"\/en\/alerts-advisories\/security-fixes-released-bind-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-168<br \/>\nDate: 21 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released updates that address multiple vulnerabilities in BIND. Exploitation of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.<\/p>\n\n<p>Versions affected: BIND 9.1.0 -&gt; 9.8.4-P2, 9.9.0 -&gt; 9.9.2-P2.<\/p>\n\n<p>CVE Reference: CVE-2016-2848<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>Reference<\/h2>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01433\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01433<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-released-bind-1","alert_type":396,"serial_number":"AV16-168","subject":null,"moderation_state":"archived","external_url":null},{"nid":819,"title":"Mozilla Releases security updates","uuid":"1393c75f-d370-4039-8af9-b6b352236c4a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:18Z","date_created":"2018-06-27T13:15:58Z","summary":null,"body":["<article data-history-node-id=\"819\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-169<br \/>\nDate: 21 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 2 vulnerabilities in Firefox rated high.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions 48 and 49<\/p>\n\n<p>CVE References: CVE-2016-5287 and CVE-2016-5288<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>Reference<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-87\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-87\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-4","alert_type":396,"serial_number":"AV16-169","subject":null,"moderation_state":"archived","external_url":null},{"nid":900,"title":"Cisco Releases security updates","uuid":"3a3020c2-ba92-4ce2-8660-3f70436bd45a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:43Z","date_created":"2018-06-27T13:21:43Z","summary":null,"body":["<article data-history-node-id=\"900\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-170<br \/>\nDate: 21 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco ASA Software Identity Firewall, Cisco Unified Communications Manager, Cisco Firepower Detection Engine, Cisco ASA Software Local Certificate Authority and Cisco Meeting Server.<\/p>\n\n<p>CVE References:<\/p>\n\n<p>Critical Impact CVE: CVE-2016-6432<br \/>\nHigh Impact CVE: CVE-2016-6431, CVE-2016-6439<\/p>\n\n<p>Medium Impact CVE: CVE-2016-6444, CVE-2016-6446<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-asa-idfw\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-asa-idfw<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-fpsnort\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-fpsnort<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-asa-ca\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-asa-ca<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-cms\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-cms<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-cms1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161019-cms1<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-6","alert_type":396,"serial_number":"AV16-170","subject":null,"moderation_state":"archived","external_url":null},{"nid":1323,"title":"Multiple Apple security updates","uuid":"ddab0565-68fd-4b7c-8386-16e7b7872cee","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-27T13:30:56Z","summary":null,"body":["<article data-history-node-id=\"1323\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-171<br \/>\nDate: 25 October 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for watchOS, tvOS, Safari, macOS Sierra, and iOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<br \/>\nHT207269 - watchOS 3.1 (All Apple Watch models)<br \/>\nHT207270 - tvOS 10.0.1 (Apple TV (4th generation))<br \/>\nHT207272 - Safari 10.0.1 (OS X Yosemite v10.10.5, OS X El Capitan v10.11.6, and macOS Sierra 10.12)<br \/>\nHT207275 - macOS Sierra 10.12.1 (OS X Yosemite v10.10.5, OS X El Capitan v10.11.6, and macOS Sierra)<br \/>\nHT207271 - iOS 10.1 (iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later)<\/p>\n\n<p>Details: These updates address multiple vulnerabilities, including arbitrary code execution, denial of service, cause a relayed call to continue transmitting audio while appearing as if the call terminated, cause an unexpected system termination or arbitrary code execution in the kernel, disclose kernel memory, disclose sensitive user information, disclosure of process memory, disclosure of user information, elevate privileges, execute arbitrary code with additional privileges, execute arbitrary code with kernel privileges, execute arbitrary code with root privileges, leak sensitive user information, observe the length of a login password when a user logs in, overwrite arbitrary files, relayed call to continue transmitting audio while appearing as if the call terminated, retrieve metadata of audio recording directories and retrieve metadata of photo directories.<\/p>\n\n<p>Multiple CVEs are referenced, please review Apple's advisory for specific details.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners and operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Articles HT207269, HT207270, HT207272, HT207275 and HT207271.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT207269\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207269<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207270\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207270<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207272\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207272<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207275\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207275<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207271\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207271<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-5","alert_type":396,"serial_number":"AV16-171","subject":null,"moderation_state":"archived","external_url":null},{"nid":1014,"title":"Cisco security advisory","uuid":"1f6933dd-355c-4c19-8570-51f62d821780","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-06-27T13:36:29Z","summary":null,"body":["<article data-history-node-id=\"1014\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-172<br \/>\nDate: 25 October 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released Cisco Security Advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released a security update to address a critical vulnerability in Cisco WebEx Meetings Player that could allow an unauthenticated, remote attacker to execute arbitrary commands.<\/p>\n\n<p>CVE Reference: CVE-2016-1464<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-meetings-player\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160831-meetings-player<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-1","alert_type":396,"serial_number":"AV16-172","subject":null,"moderation_state":"archived","external_url":null},{"nid":1147,"title":"Joomla! 3.6.4 Released","uuid":"d945c439-0c92-4d4b-b4fb-9056253a3f54","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-06-27T13:42:26Z","summary":null,"body":["<article data-history-node-id=\"1147\" about=\"\/en\/alerts-advisories\/joomla-364-released\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-173<br \/>\nDate: 26 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released a new version that contains security fixes to address the following vulnerabilities in Joomla!:<\/p>\n\n<ul><li>Account Creation<\/li>\n\t<li>Elevated Privileges<\/li>\n<\/ul><p>Versions affected: Joomla! 3.4.4 through 3.6.3<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5678-joomla-3-6-4-released.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5678-joomla-3-6-4-released.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-364-released","alert_type":396,"serial_number":"AV16-173","subject":null,"moderation_state":"archived","external_url":null},{"nid":1212,"title":"security update for Adobe Flash Player","uuid":"4534c34d-9f30-48e8-98a3-e864e8d8206d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-27T13:48:05Z","summary":null,"body":["<article data-history-node-id=\"1212\" about=\"\/en\/alerts-advisories\/security-update-adobe-flash-player-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-174<br \/>\nDate: October 26 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-36 to address critical vulnerabilities that could allow an attacker to take control of the affected system.\u00a0<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Adobe Flash Desktop Runtime 23.0.0.185 and earlier versions for Windows and Macintosh.<\/li>\n\t<li>Adobe Flash Player for Google Chrome 23.0.0.185 and earlier versions of Windows, Macintosh, Linux and Chrome.<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 23.0.0.185 and earlier for Windows 10 and 8.1.<\/li>\n\t<li>Adobe Flash Player for Linux versions 11.2.202.637 and earlier.<\/li>\n<\/ul><p>CVE References: CVE-2016-7855<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-36.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-36.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-adobe-flash-player-0","alert_type":396,"serial_number":"AV16-174","subject":null,"moderation_state":"archived","external_url":null},{"nid":1300,"title":"Cisco Releases security updates","uuid":"b8450c23-8b01-429e-b0ea-551823267c15","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-06-27T13:53:52Z","summary":null,"body":["<article data-history-node-id=\"1300\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-175<br \/>\nDate: 27 October 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco IP Interoperability and Collaboration System, Cisco Firepower System Software, Cisco Email Security Appliances, Cisco Web Security Appliances, Cisco Prime Collaboration Provisioning, Cisco Hosted Collaboration Mediation Fulfillment, Cisco Identity Services Engine, and some Cisco products utilizing the Linux Kernel.<\/p>\n\n<p>CVE References:<br \/>\nCritical Impact CVE: CVE-2016-6397<br \/>\nHigh Impact CVEs: CVE-2016-1481, CVE-2016-1486, CVE-2016-6356, CVE-2016-6399<br \/>\nMedium Impact CVEs: CVE-2016-1423, CVE-2016-1480, CVE-2016-5195, CVE-2016-6360, CVE-2016-6372, CVE-2016-6453, CVE-2016-6357, CVE-2016-6358, CVE-2016-6429, CVE-2016-6430, CVE-2016-6451, CVE-2016-6454<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ipics\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ipics<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa2<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa3\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa3<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa4\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa4<\/font><\/a>\u00a0<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa5\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa5<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa6\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esa6<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-pcp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-pcp<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ipics1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ipics1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ipics2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ipics2<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-hcmf\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-hcmf<\/font><\/a>\u00a0<br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esawsa1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esawsa1<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esawsa2\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esawsa2<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esawsa3\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-esawsa3<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-linux\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-linux<\/font><\/a><br \/><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ise\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-ise<\/font><\/a>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-7","alert_type":396,"serial_number":"AV16-175","subject":null,"moderation_state":"archived","external_url":null},{"nid":911,"title":"LibTIFF Security Patches","uuid":"e6e54181-0f5f-47d5-849b-0007c903f00e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-27T14:01:20Z","summary":null,"body":["<article data-history-node-id=\"911\" about=\"\/en\/alerts-advisories\/libtiff-security-patches\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-176<br \/>\nDate: 31 October 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to LibTIFF security patches.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Security patches released for LibTIFF which address multiple vulnerabilities.\u00a0 Exploitation of these vulnerabilities may allow for arbitrary remote code execution.\u00a0 The LibTIFF library is included with and leveraged by several hardware and software products. Please note, CVE-2016-8331 remains unpatched.<\/p>\n\n<p>Affected Versions: LibTIFF 4.0.6 and prior<\/p>\n\n<p>CVE References: CVE-2016-5652, CVE-2016-5875, CVE-2016-8331<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Cisco Talos (vulnerability report):<br \/><a href=\"http:\/\/blog.talosintel.com\/2016\/10\/LibTIFF-Code-Execution.html\"><font color=\"#0066cc\">http:\/\/blog.talosintel.com\/2016\/10\/LibTIFF-Code-Execution.html<\/font><\/a>\u00a0\u00a0<\/p>\n\n<p>LibTIFF:<br \/><a href=\"http:\/\/www.simplesystems.org\/libtiff\/\"><font color=\"#0066cc\">http:\/\/www.simplesystems.org\/libtiff\/<\/font><\/a><\/p>\n\n<p>LibTIFF Git Repository:<br \/><a href=\"https:\/\/github.com\/vadz\/libtiff\"><font color=\"#0066cc\">https:\/\/github.com\/vadz\/libtiff<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/libtiff-security-patches","alert_type":396,"serial_number":"AV16-176","subject":null,"moderation_state":"archived","external_url":null},{"nid":877,"title":"Security fix released for BIND","uuid":"ace5682f-2a82-45bc-b357-6bacaf317d22","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-06-27T14:07:41Z","summary":null,"body":["<article data-history-node-id=\"877\" about=\"\/en\/alerts-advisories\/security-fix-released-bind-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-177<br \/>\nDate: 2 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fix for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released an update to address a vulnerability in BIND. Exploitation of this vulnerability may allow a remote attacker to cause a denial-of-service condition.<\/p>\n\n<p>Versions affected: BIND 9.0.x -&gt; 9.8.x, 9.9.0 -&gt; 9.9.9-P3, 9.9.3-S1 -&gt; 9.9.9-S5, 9.10.0 -&gt; 9.10.4-P3, 9.11.0<\/p>\n\n<p>CVE Reference: CVE-2016-8864<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01434\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01434<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fix-released-bind-0","alert_type":396,"serial_number":"AV16-177","subject":null,"moderation_state":"archived","external_url":null},{"nid":1045,"title":"IBHsoftec S7-SoftPLC CPX43 Buffer Overflow Vulnerability","uuid":"78a78839-3713-482e-a40a-f434d81af03a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-06-27T14:18:00Z","summary":null,"body":["<article data-history-node-id=\"1045\" about=\"\/en\/alerts-advisories\/ibhsoftec-s7-softplc-cpx43-buffer-overflow-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-179<br \/>\nDate: 2 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently disclosed vulnerability in IBHsoftec S7-SoftPLC CPX43.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A heap-based buffer overflow vulnerability was identified in IBHsoftec S7-SoftPLC CPX43. Exploitation of this vulnerability could allow an attacker to affect the integrity, confidentiality, and availability of the device.<\/p>\n\n<p>Affected Product:<\/p>\n\n<ul><li>S7-SoftPLC versions prior to 4.12b<\/li>\n<\/ul><p>CVE Reference: CVE-2016-8364<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-306-02\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-306-02<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibhsoftec-s7-softplc-cpx43-buffer-overflow-vulnerability","alert_type":396,"serial_number":"AV16-179","subject":null,"moderation_state":"archived","external_url":null},{"nid":1169,"title":"SAP Security Notes - October 2016","uuid":"de3125f0-9ccc-4de6-a599-c7908adab456","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:44Z","date_created":"2018-06-27T14:25:47Z","summary":null,"body":["<article data-history-node-id=\"1169\" about=\"\/en\/alerts-advisories\/sap-security-notes-october-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-180<br \/>\nDate: 04 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Security Notes by SAP.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>SAP has released 47 SAP Security Patch Day Notes and 1 Support Package Notes as part of their October Security Patch Day designed to address multiple vulnerabilities in several SAP products. Vulnerabilities addressed in the July Security Patch Day Security Notes include: Web Channel, CRM, Commodity Risk Management, E-commerce ERP, Financial Accounting, Supply Chain Management, Service Basis Components, Product Catalog, SAP Portal, Cross-Application Components and Business intelligence.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released update to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/erpscan.com\/press-center\/blog\/sap-security-notes-october-2016\/\"><font color=\"#0066cc\">https:\/\/erpscan.com\/press-center\/blog\/sap-security-notes-october-2016\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-notes-october-2016","alert_type":null,"serial_number":"AV16-180","subject":null,"moderation_state":"archived","external_url":null},{"nid":781,"title":"Cisco Releases security updates","uuid":"79d9b79a-95c4-4180-ae42-0d55070ef21b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-27T14:31:25Z","summary":null,"body":["<article data-history-node-id=\"781\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-181<br \/>\nDate: 7 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in Cisco ASR 900 Series Aggregation Services Routers, Cisco Prime Home, Cisco Meeting Server, Cisco Meeting App, Cisco ASR 5500 Series Routers, Cisco Email Security Appliance and Cisco TelePresence Endpoints.<\/p>\n\n<p>CVE References:<br \/>\nCritical Impact CVEs: CVE-2016-6441, CVE-2016-6452<br \/>\nHigh Impact CVEs: CVE-2016-6447, CVE-2016-6448<br \/>\nMedium Impact CVEs: CVE-2016-6455, CVE-2016-6457, CVE-2016-6458, CVE-2016-6459<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-tl1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-tl1<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-cph\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-cph<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-cms1\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-cms1<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-cms\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-cms<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-asr\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-asr<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-esa\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-esa<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-n9kapic\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-n9kapic<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-tp\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161102-tp<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-8","alert_type":null,"serial_number":"AV16-181","subject":null,"moderation_state":"archived","external_url":null},{"nid":1263,"title":"Android security bulletin \u2013 November 2016","uuid":"31dad43d-ae03-4210-b5b1-341b1bdd678a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-06-27T14:37:09Z","summary":null,"body":["<article data-history-node-id=\"1263\" about=\"\/en\/alerts-advisories\/android-security-bulletin-november-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-182<br \/>\nDate: 8 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for November.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for 48 vulnerabilities (15 Critical, 23 High, and 10 Moderate). The 15 vulnerabilities tagged as critical have the possibility of remote code execution and\/or privilege escalation.<\/p>\n\n<p>CVE References: CVE-2012-6702, CVE-2014-9675, CVE-2014-9908, CVE-2015-0410, CVE-2015-1283, CVE-2015-8961, CVE-2015-8962, CVE-2015-8963, CVE-2015-8964, CVE-2016-0718, CVE-2016-2184, CVE-2016-3904, CVE-2016-3906, CVE-2016-3907, CVE-2016-5195, CVE-2016-5300, CVE-2016-6136, CVE-2016-6698, CVE-2016-6699, CVE-2016-6700, CVE-2016-6701, CVE-2016-6702, CVE-2016-6703, CVE-2016-6704, CVE-2016-6705, CVE-2016-6706, CVE-2016-6707, CVE-2016-6708, CVE-2016-6709, CVE-2016-6710, CVE-2016-6711, CVE-2016-6712, CVE-2016-6713, CVE-2016-6714, CVE-2016-6715, CVE-2016-6716, CVE-2016-6717, CVE-2016-6718, CVE-2016-6719, CVE-2016-6720, CVE-2016-6721, CVE-2016-6722, CVE-2016-6723, CVE-2016-6724, CVE-2016-6725, CVE-2016-6726, CVE-2016-6727, CVE-2016-6728, CVE-2016-6729, CVE-2016-6730, CVE-2016-6731, CVE-2016-6732, CVE-2016-6733, CVE-2016-6734, CVE-2016-6735, CVE-2016-6736, CVE-2016-6737, CVE-2016-6738, CVE-2016-6739, CVE-2016-6740, CVE-2016-6741, CVE-2016-6742, CVE-2016-6743, CVE-2016-6744, CVE-2016-6745, CVE-2016-6746, CVE-2016-6747, CVE-2016-6748, CVE-2016-6749, CVE-2016-6750, CVE-2016-6751, CVE-2016-6752, CVE-2016-6753, CVE-2016-6754, CVE-2016-6828, CVE-2016-7910, CVE-2016-7911, CVE-2016-7912, CVE-2016-7913, CVE-2016-7914, CVE-2016-7915, CVE-2016-7916, CVE-2016-7917<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Android Security Bulletin:<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-11-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-11-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-november-2016","alert_type":396,"serial_number":"AV16-182","subject":null,"moderation_state":"archived","external_url":null},{"nid":1108,"title":"security update for Adobe Flash Player","uuid":"9026c1b0-383e-45b9-a7e0-21bac6a22a45","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-27T15:17:58Z","summary":null,"body":["<article data-history-node-id=\"1108\" about=\"\/en\/alerts-advisories\/security-update-adobe-flash-player-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-183<br \/>\nDate: 8 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB16-37 to address critical vulnerabilities that could allow an attacker to take control of the affected system.\u00a0<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Adobe Flash Desktop Runtime 23.0.0.205 and earlier versions for Windows and Macintosh.<\/li>\n\t<li>Adobe Flash Player for Google Chrome 23.0.0.205 and earlier versions of Windows, Macintosh, Linux and Chrome.<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 23.0.0.205 and earlier for Windows 10 and 8.1.<\/li>\n\t<li>Adobe Flash Player for Linux versions 11.2.202.643 and earlier.<\/li>\n<\/ul><p>CVE References: CVE-2016-7857, CVE-2016-7858, CVE-2016-7859, CVE-2016-7860, CVE-2016-7861, CVE-2016-7862, CVE-2016-7863, CVE-2016-7864, CVE-2016-7865<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-37.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-37.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-adobe-flash-player-1","alert_type":396,"serial_number":"AV16-183","subject":null,"moderation_state":"archived","external_url":null},{"nid":932,"title":"Microsoft Critical security bulletins Summary \u2013 November 2016","uuid":"0255971b-1aba-48df-8d27-4787810fcfef","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-06-27T15:26:38Z","summary":null,"body":["<article data-history-node-id=\"932\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-november-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-184<br \/>\nDate: 8 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for November 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 14 bulletins (6 Critical and 8 Important), which addresses multiple vulnerabilities in; Microsoft Internet Explorer, Microsoft Boot Manager, Microsoft Edge, Microsoft Office, Microsoft Graphics Component, Microsoft Video Control, Adobe Flash Player, Windows Kernel-Mode Drivers, Windows Common Log File System Driver, Microsoft Virtual Hard Disk Driver and Microsoft SQL Server.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS16-129 Cumulative Security Update for Microsoft Edge (3199057)<\/li>\n\t<li>MS16-130 Security Update for Microsoft Windows (3199172)<\/li>\n\t<li>MS16-131 Security Update for Microsoft Video Control (3199151)<\/li>\n\t<li>MS16-132 Security Update for Microsoft Graphics Component (3199120)<\/li>\n\t<li>MS16-141 Security Update for Adobe Flash Player (3202790)<\/li>\n\t<li>MS16-142 Cumulative Security Update for Internet Explorer (3198467)<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS16-133 Security Update for Microsoft Office (3199168)<\/li>\n\t<li>MS16-134 Security Update for Common Log File System Driver (3193706)<\/li>\n\t<li>MS16-135 Security Update for Windows Kernel-Mode Drivers (3199135)<\/li>\n\t<li>MS16-136 Security Update for SQL Server (3199641)<\/li>\n\t<li>MS16-137 Security Update for Windows Authentication Methods (3199173)<\/li>\n\t<li>MS16-138 Security Update for Microsoft Virtual Hard Disk Driver (3199647)<\/li>\n\t<li>MS16-139 Security Update for Windows Kernel (3199720)<\/li>\n\t<li>MS16-140 Security Update for Boot Manager (3193479)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-nov.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-nov.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-november-2016","alert_type":396,"serial_number":"AV16-184","subject":null,"moderation_state":"archived","external_url":null},{"nid":1188,"title":"OpenSSL Advisory \u2013 Multiple Vulnerabilities","uuid":"a7433ae9-218c-4e57-9575-cfcd1ce48996","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-27T15:33:21Z","summary":null,"body":["<article data-history-node-id=\"1188\" about=\"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-185<br \/>\nDate: 10 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security updates released by OpenSSL.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of three (1 high, 1 moderate and 1 low) disclosed vulnerabilities in OpenSSL for which updates are available.<\/p>\n\n<p>Affected Versions: 1.0.2 and 1.1.0<\/p>\n\n<p>CVE References: CVE-2016-7053, CVE-2016-7054, CVE-2016-7055<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>OpenSSL Advisory - <a href=\"https:\/\/www.openssl.org\/news\/secadv\/20161110.txt\">https:\/\/www.openssl.org\/news\/secadv\/20161110.txt<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-multiple-vulnerabilities-3","alert_type":396,"serial_number":"AV16-185","subject":null,"moderation_state":"archived","external_url":null},{"nid":821,"title":"Google Releases security update for Chrome","uuid":"2e0af81d-fe10-4665-8a33-4b0ef5b2943f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:52Z","date_created":"2018-06-27T15:39:10Z","summary":null,"body":["<article data-history-node-id=\"821\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-15\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-186<br \/>\nDate: 11 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 54.0.2840.99 for Windows, 54.0.2840.98 for Mac, and 54.0.2840.100 on Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2016-5199, CVE-2016-5200, CVE-2016-5201, 2016-5202<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References<\/p>\n\n<p><a href=\"https:\/\/googlechromereleases.blogspot.ca\/2016\/11\/stable-channel-update-for-desktop_9.html\"><font color=\"#0066cc\">https:\/\/googlechromereleases.blogspot.ca\/2016\/11\/stable-channel-update-for-desktop_9.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-15","alert_type":396,"serial_number":"AV16-186","subject":null,"moderation_state":"archived","external_url":null},{"nid":895,"title":"VMware Workstation and Fusion security updates","uuid":"9c932f27-c016-4a7a-83b4-cac9ab2ea012","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:43Z","date_created":"2018-06-27T15:44:08Z","summary":null,"body":["<article data-history-node-id=\"895\" about=\"\/en\/alerts-advisories\/vmware-workstation-and-fusion-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-187<br \/>\nDate: 14 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security updates released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has release security updates for the VMware Workstation and Workstation Fusion products. The severities of the vulnerabilities addressed with these updates are critical. The drag and drop function of the below mentioned products may allow a guest to execute code on the host operating system via an out-of-bound memory access vulnerability.<\/p>\n\n<p>Affected Products:<\/p>\n\n<p>VMware Workstation Pro 12.x \/ Player 12.x<br \/>\nVMware Fusion Pro 8.x \/ Fusion 8.x<\/p>\n\n<p>CVE References: CVE-2016-7461<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0019.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0019.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-workstation-and-fusion-security-updates","alert_type":396,"serial_number":"AV16-187","subject":null,"moderation_state":"archived","external_url":null},{"nid":1324,"title":"Mozilla Releases security updates","uuid":"0cf59f18-936c-42d9-b309-eb4f9cebe3b7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:44Z","date_created":"2018-06-27T15:50:11Z","summary":null,"body":["<article data-history-node-id=\"1324\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-188<br \/>\nDate: 16 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which upgrades are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address multiple vulnerabilities in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 50.0<br \/>\nESR versions prior to 45.5<\/p>\n\n<p>CVE References:<br \/>\nCVE-2016-5289, CVE-2016-5290, CVE-2016-5291, CVE-2016-5292, CVE-2016-5293, CVE-2016-5294,<br \/>\nCVE-2016-9062, CVE-2016-9063, CVE-2016-9064, CVE-2016-9065, CVE-2016-9066, CVE-2016-9067,<br \/>\nCVE-2016-9068, CVE-2016-9070, CVE-2016-9071, CVE-2016-9072, CVE-2016-9073, CVE-2016-9074,<br \/>\nCVE-2016-9075, CVE-2016-9076, CVE-2016-9077<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-89\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-89\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-90\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-90\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-5","alert_type":396,"serial_number":"AV16-188","subject":null,"moderation_state":"archived","external_url":null},{"nid":1016,"title":"Symantec Releases security update","uuid":"817d827f-920c-47b2-9066-604dc7a2c121","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-06-27T15:55:44Z","summary":null,"body":["<article data-history-node-id=\"1016\" about=\"\/en\/alerts-advisories\/symantec-releases-security-update-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-189<br \/>\nDate: 16 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released Symantec security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Symantec has released a Security Advisory to address critical vulnerabilities that could allow an attacker to execute arbitrary code with elevated privileges on affected systems.<\/p>\n\n<p>Affected Products:<br \/>\n- Symantec IT Management Suite version 8.0<br \/>\n- Symantec Ghost Solution Suite version 3.1<br \/>\n- Symantec Endpoint Virtualization version 7.x<\/p>\n\n<p>CVE References: CVE-2016-6590<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=&amp;suid=20161115_00\"><font color=\"#0066cc\">https:\/\/www.symantec.com\/security_response\/securityupdates\/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=&amp;suid=20161115_00<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/symantec-releases-security-update-2","alert_type":396,"serial_number":"AV16-189","subject":null,"moderation_state":"archived","external_url":null},{"nid":1149,"title":"VMWare vRealize Operations security update","uuid":"ee6ccb84-db63-4a5b-98d9-258e06586bf6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-06-28T13:02:26Z","summary":null,"body":["<article data-history-node-id=\"1149\" about=\"\/en\/alerts-advisories\/vmware-vrealize-operations-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-190<br \/>\nDate: 17 November 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security updates released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released security updates for the vRealize Operations product. The severity of the vulnerability addressed in this update is rated important. The deserialization vulnerability in the REST API implementation may result in a Denial of Service as it allows for the writing of files with arbitrary content and the moving of existing files into certain folders.<\/p>\n\n<p>Affected Product:<br \/>\nVMWare vRealize Operations 6.x<\/p>\n\n<p>CVE Reference: CVE-2016-7462<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0020.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0020.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-vrealize-operations-security-update","alert_type":null,"serial_number":"AV16-190","subject":null,"moderation_state":"archived","external_url":null},{"nid":1214,"title":"Network Time Protocol Daemon (ntpd) Security Notice","uuid":"bbba2481-70f4-4647-9349-96bb4f2d2679","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-28T13:07:52Z","summary":null,"body":["<article data-history-node-id=\"1214\" about=\"\/en\/alerts-advisories\/network-time-protocol-daemon-ntpd-security-notice-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-191<br \/>\nDate: 22 November 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a multiple NTP vulnerabilities security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The NTP project has released version ntp-4.2.8p9, which fixed 10 vulnerabilities and 28 bugs in their software.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/633847\"><font color=\"#0066cc\">http:\/\/www.kb.cert.org\/vuls\/id\/633847<\/font><\/a><br \/><a href=\"http:\/\/support.ntp.org\/bin\/view\/Main\/SecurityNotice#Recent_Vulnerabilities\"><font color=\"#0066cc\">http:\/\/support.ntp.org\/bin\/view\/Main\/SecurityNotice#Recent_Vulnerabilities<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/network-time-protocol-daemon-ntpd-security-notice-0","alert_type":396,"serial_number":"AV16-191","subject":null,"moderation_state":"archived","external_url":null},{"nid":1302,"title":"Palo Alto Networks PAN-OS Security Advisories","uuid":"aa89ea61-8e51-401b-bb84-babc7831a5a9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-06-28T13:13:09Z","summary":null,"body":["<article data-history-node-id=\"1302\" about=\"\/en\/alerts-advisories\/palo-alto-networks-pan-os-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-192<br \/>\nDate: 22 November 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple security advisories for Palo Alto Networks PAN-OS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Palo Alto Networks has released multiple security advisories to address a range of vulnerabilities in PAN-OS. The severity of these issues ranges from low to critical.<\/p>\n\n<p><strong>Critical<\/strong><br \/>\nPAN-SA-2016-0035 - Buffer Overflow in the Management Web Interface<\/p>\n\n<p><strong>Medium<\/strong><br \/>\nPAN-SA-2016-0034 - Local Privilege Escalation<\/p>\n\n<p><strong>Low<\/strong><br \/>\nPAN-SA-2016-0036 - OpenSSH Vulnerability<br \/>\nPAN-SA-2016-0037 - XPath Injection<\/p>\n\n<p>CVE References: CVE-2016-6210, CVE-2016-9149, CVE-2016-9150, CVE-2016-9151<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>PAN-SA-2016-0034:<br \/><a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/67\"><font color=\"#0066cc\">https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/67<\/font><\/a><\/p>\n\n<p>PAN-SA-2016-0035:<br \/><a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/68\"><font color=\"#0066cc\">https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/68<\/font><\/a><\/p>\n\n<p>PAN-SA-2016-0036:<br \/><a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/69\"><font color=\"#0066cc\">https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/69<\/font><\/a><\/p>\n\n<p>PAN-SA-2016-0037:<br \/><a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/70\"><font color=\"#0066cc\">https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/70<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-pan-os-security-advisories","alert_type":396,"serial_number":"AV16-192","subject":null,"moderation_state":"archived","external_url":null},{"nid":913,"title":"Mozilla Releases security updates","uuid":"bddc5a40-6540-4555-82f0-7b2424ce809a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:01Z","date_created":"2018-06-28T13:18:16Z","summary":null,"body":["<article data-history-node-id=\"913\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-193<br \/>\nDate: 29 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 2 vulnerabilities in Firefox rated high.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions 49 and 50<\/p>\n\n<p>CVE References: N\/A<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-91\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-91\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-6","alert_type":396,"serial_number":"AV16-193","subject":null,"moderation_state":"archived","external_url":null},{"nid":879,"title":"Mozilla Critical Patch update Advisory","uuid":"b38a04b2-9328-4698-8608-bf9d4069ba85","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-06-28T13:23:13Z","summary":null,"body":["<article data-history-node-id=\"879\" about=\"\/en\/alerts-advisories\/mozilla-critical-patch-update-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-194<br \/>\nDate: 1 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following critical patch updates released for Mozilla Firefox, Firefox ESR and Thunderbird for which an update is now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address a critical vulnerability Mozilla Firefox, Firefox ESR and Thunderbird.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 50.0.2<br \/>\nESR versions prior to 45.5.1<br \/>\nThunderbird versions prior to 45.5.1<\/p>\n\n<p>CVE References: CVE-2016-9079<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-92\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-92\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-critical-patch-update-advisory","alert_type":396,"serial_number":"AV16-194","subject":null,"moderation_state":"archived","external_url":null},{"nid":1047,"title":"Google Releases security update for Chrome","uuid":"3ca707fd-fd74-48b8-96f7-04568a05e6be","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-06-28T13:28:53Z","summary":null,"body":["<article data-history-node-id=\"1047\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-16\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-195<br \/>\nDate: 02 December 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 55.0.2883.75 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2016-5203, CVE-2016-5204, CVE-2016-5205, CVE-2016-5206, CVE-2016-5207, CVE-2016-5208, CVE-2016-5209, CVE-2016-5210, CVE-2016-5211, CVE-2016-5212, CVE-2016-5213, CVE-2016-5214, CVE-2016-5215, CVE-2016-5216, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219, CVE-2016-5220, CVE-2016-5221, CVE-2016-5222, CVE-2016-5223, CVE-2016-5224, CVE-2016-5225, CVE-2016-5226, CVE-2016-9650, CVE-2016-9651<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/googlechromereleases.blogspot.ca\/2016\/12\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/googlechromereleases.blogspot.ca\/2016\/12\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-16","alert_type":null,"serial_number":"AV16-195","subject":null,"moderation_state":"archived","external_url":null},{"nid":1171,"title":"Android security bulletin \u2013 December 2016","uuid":"455856c2-6a5f-4f01-b80f-ff0b76e21981","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:44Z","date_created":"2018-06-28T13:35:16Z","summary":null,"body":["<article data-history-node-id=\"1171\" about=\"\/en\/alerts-advisories\/android-security-bulletin-december-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-196<br \/>\nDate: 5 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for December.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for 74 vulnerabilities (11 Critical, 43 High, and 20 Moderate). The 11 vulnerabilities tagged as critical have the possibility of remote code execution, privilege escalation and\/or permanent device compromise.<\/p>\n\n<p>CVE References: CVE-2016-4794, CVE-2016-5195, CVE-2016-6775, CVE-2016-6776, CVE-2016-6777, CVE-2015-8966, CVE-2016-6915, CVE-2016-6916, CVE-2016-6917, CVE-2016-9120, CVE-2016-8411, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-6762 CVE-2016-6763, CVE-2016-6766, CVE-2016-6765, CVE-2016-6764, CVE-2016-6767, CVE-2016-6768, CVE-2014-4014, CVE-2015-8967, CVE-2016-6778, CVE-2016-6779, CVE-2016-6780, CVE-2016-6492, CVE-2016-6781, CVE-2016-6782, CVE-2016-6783, CVE-2016-6784, CVE-2016-6785, CVE-2016-6761, CVE-2016-6760, CVE-2016-6759, CVE-2016-6758, CVE-2016-6755, CVE-2016-6786, CVE-2016-6787, CVE-2016-6788, CVE-2016-6789, CVE-2016-6790, CVE-2016-6791, CVE-2016-8391, CVE-2016-8392, CVE-2015-7872, CVE-2016-8393, CVE-2016-8394, CVE-2014-9909, CVE-2014-9910, CVE-2016-8396, CVE-2016-8397, CVE-2016-5341, CVE-2016-8395, CVE-2016-6769, CVE-2016-6770, CVE-2016-6771, CVE-2016-6772, CVE-2016-6773, CVE-2016-6774, CVE-2016-8399, CVE-2016-6756, CVE-2016-6757, CVE-2016-8400, CVE-2016-8401, CVE-2016-8402, CVE-2016-8403, CVE-2016-8404, CVE-2016-8405, CVE-2016-8406, CVE-2016-8407, CVE-2016-8408, CVE-2016-8409, CVE-2016-8410<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators check with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected devices accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Android Security Bulletin:<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2016-12-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2016-12-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-december-2016","alert_type":396,"serial_number":"AV16-196","subject":null,"moderation_state":"archived","external_url":null},{"nid":783,"title":"McAfee VirusScan Enterprise for Linux updates","uuid":"a5d5321b-7aeb-455a-8bd3-60b97298355d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-28T13:41:25Z","summary":null,"body":["<article data-history-node-id=\"783\" about=\"\/en\/alerts-advisories\/mcafee-virusscan-enterprise-linux-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-197<br \/>\nDate: 12 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security updates for McAfee VirusScan Enterprise for Linux.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Intel \u2013 McAfee has released a security bulletin concerning an update to McAfee VirusScan Enterprise for Linux that fixes multiple vulnerabilities. The severity of these vulnerabilities range from high to medium and could allow an attacker to take control of a system.<\/p>\n\n<p>Version affected: 2.03 and earlier<\/p>\n\n<p>CVE References: CVE-2016-8016, CVE-2016-8017, CVE-2016-8018, CVE-2016-8019, CVE-2016-8020, CVE-2016-8021, CVE-2016-8022, CVE-2016-8023, CVE-2016-8024, CVE-2016-8025<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators review the security bulletin in the context of their infrastructure and deploy the vendor-released updates to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p>Intel\/McAfee Security Bulletin:<\/p>\n\n<p><a href=\"https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10181\"><font color=\"#0066cc\">https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10181<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mcafee-virusscan-enterprise-linux-updates","alert_type":396,"serial_number":"AV16-197","subject":null,"moderation_state":"archived","external_url":null},{"nid":1344,"title":"Multiple Apple security updates","uuid":"a53d3774-3f5e-48c3-9ecb-87d52b12bf78","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-06-28T13:53:31Z","summary":null,"body":["<article data-history-node-id=\"1344\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-198<br \/>\nDate: 13 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iOS, tvOS and watchOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<p>HT207422 \u2013 iOS 10.2 iPhone 5 and later, iPad 4 and later, iPod touch 6 and later.<br \/>\nHT207425 \u2013 tvOS 10.1 Apple TV 4<br \/>\nHT207426 \u2013 watchOS 3.1.1 All Apple Watch models<\/p>\n\n<p>This update addresses multiple vulnerabilities on the systems listed above.<\/p>\n\n<p>CVE Reference: CVE-2016-4689, CVE-2016-4690, CVE-2016-4781, CVE-2016-7597, CVE-2016-7601, CVE-2016-7626, CVE-2016-7634, CVE-2016-7638, CVE-2016-7651, CVE-2016-7653, CVE-2016-7664, CVE-2016-7665<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Article HT207422, HT207425, HT207426.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT207422\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT207422<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT207425\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT207425<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT207426\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT207426<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-6","alert_type":396,"serial_number":"AV16-198","subject":null,"moderation_state":"archived","external_url":null},{"nid":1110,"title":"Moxa NPort Device Vulnerabilities","uuid":"5a3cbd14-2e58-4e9b-9969-251db7875e93","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-28T14:01:19Z","summary":null,"body":["<article data-history-node-id=\"1110\" about=\"\/en\/alerts-advisories\/moxa-nport-device-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-199<br \/>\nDate: 13 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple vulnerabilities in Moxa NPort Devices.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Moxa NPort devices are serial to ethernet device servers and industrial controllers. This industrial grade class of device is used to control legacy serial devices on modern IP networks. They can be found in various locations including remote field locations and perform various common administrative functions. Successful exploitation of these vulnerabilities can include denial of service, authentication bypass and complete compromise of an affected system.<\/p>\n\n<p>CVE References: CVE-2016-9361, CVE-2016-9369, CVE-2016-9363, CVE-2016-9371, CVE-2016-9365, CVE-2016-9366, CVE-2016-9348 &amp; CVE-2016-9367<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>NPort 5110 Version 2.6:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=882\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=882<\/font><\/a><br \/><br \/>\nNPort 5130\/5150 Series Version 3.6:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=356\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=356<\/font><\/a><br \/><br \/>\nNPort 5200 Series Version 2.8:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=904\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=904<\/font><\/a><br \/><br \/>\nNPort 5400 Series Version 3.11:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=925\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=925<\/font><\/a><br \/>\nNPort 5600 Series Version 3.7:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=905\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=905<\/font><\/a><br \/><br \/>\nNPort 5100A Series &amp; NPort P5150A Version 1.3:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1403\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1403<\/font><\/a><br \/><br \/>\nNPort 5200A Series Version 1.3:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1462\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1462<\/font><\/a><br \/><br \/>\nNPort 5150AI-M12 Series Version 1.2:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=2206\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=2206<\/font><\/a><br \/><br \/>\nNPort 5250AI-M12 Series Version 1.2:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=2207\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=2207<\/font><\/a><br \/><br \/>\nNPort 5450AI-M12 Series Version 1.2:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=2208\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=2208<\/font><\/a><br \/><br \/>\nNPort 5600-8-DT Series Version 2.4:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=938\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=938<\/font><\/a><br \/><br \/>\nNPort 5600-8-DTL Series Version 1.3:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1819\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1819<\/font><\/a><br \/><br \/>\nNPort 6x50 Series Version 1.14:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=733\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=733<\/font><\/a><br \/><br \/>\nNPort IA5450A Version 1.4:<br \/><a href=\"http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1469\"><font color=\"#0066cc\">http:\/\/www.moxa.com\/support\/download.aspx?type=support&amp;id=1469<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moxa-nport-device-vulnerabilities","alert_type":396,"serial_number":"AV16-199","subject":null,"moderation_state":"archived","external_url":null},{"nid":936,"title":"Microsoft Critical security bulletins Summary \u2013 December 2016","uuid":"f0bef929-7c80-4b18-a030-176c64515dd5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:45Z","date_created":"2018-06-28T14:07:00Z","summary":null,"body":["<article data-history-node-id=\"936\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-december-2016\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-200<br \/>\nDate: 14 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for December 2016.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 12 bulletins (6 Critical and 6 Important), which addresses multiple vulnerabilities in; Microsoft Internet Explorer, Microsoft Windows, Microsoft Edge, Microsoft Office, Adobe Flash Player, Microsoft .NET Framework, Services and Web Apps.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS16-144 Cumulative Security Update for Internet Explorer (3204059)<\/li>\n\t<li>MS16-145 Cumulative Security Update for Microsoft Edge (3204062)<\/li>\n\t<li>MS16-146 Security Update for Microsoft Graphics Component (3204066)<\/li>\n\t<li>MS16-147 Security Update for Microsoft Uniscribe (3204063)<\/li>\n\t<li>MS16-148 Security Update for Microsoft Office (3204068)<\/li>\n\t<li>MS16-154 Security Update for Adobe Flash Player (3209498)<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS16-149 Security Update for Microsoft Windows (3205655)<\/li>\n\t<li>MS16-150 Security Update for Secure Kernel Mode (3205642)<\/li>\n\t<li>MS16-151 Security Update for Windows Kernel-Mode Drivers (3205651)<\/li>\n\t<li>MS16-152 Security Update for Windows Kernel (3199709)<\/li>\n\t<li>MS16-153 Security Update for Common Log File System Driver (3207328)<\/li>\n\t<li>MS16-155 Security Update for .NET Framework (3205640)<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-dec\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms16-dec<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-december-2016","alert_type":396,"serial_number":"AV16-200","subject":null,"moderation_state":"archived","external_url":null},{"nid":1197,"title":"Adobe Multiple security updates","uuid":"1e93efc4-bea5-4e44-ab1d-fd6bceae34e1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-28T14:12:48Z","summary":null,"body":["<article data-history-node-id=\"1197\" about=\"\/en\/alerts-advisories\/adobe-multiple-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-201<br \/>\nDate: 14 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Adobe Security updates for various products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<\/p>\n\n<ul><li>APSB16-38 - Security update available for Adobe Animate<\/li>\n\t<li>APSB16-39 - Security updates available for Adobe Flash Player<\/li>\n\t<li>APSB16-40 - Security updates available for Adobe Experience Manager Forms<\/li>\n\t<li>APSB16-41 - Security update available for the Adobe DNG Converter<\/li>\n\t<li>APSB16-42 - Security updates available for Adobe Experience Manager<\/li>\n\t<li>APSB16-43 - Security updates available for InDesign<\/li>\n\t<li>APSB16-44 - Security update available for ColdFusion Builder<\/li>\n\t<li>APSB16-45 - Security update available for Adobe Digital Editions<\/li>\n\t<li>APSB16-46 - Security update available for Adobe Robohelp<\/li>\n<\/ul><p>CVE References:\u00a0<br \/>\nCVE-2016-6933, CVE-2016-6934, CVE-2016-7856, CVE-2016-7866, CVE-2016-7867, CVE-2016-7868, CVE-2016-7869, CVE-2016-7870, CVE-2016-7871, CVE-2016-7872, CVE-2016-7873, CVE-2016-7874, CVE-2016-7875, CVE-2016-7876, CVE-2016-7877, CVE-2016-7878, CVE-2016-7879, CVE-2016-7880, CVE-2016-7881, CVE-2016-7882, CVE-2016-7883, CVE-2016-7884, CVE-2016-7885, CVE-2016-7886, CVE-2016-7887, CVE-2016-7889, CVE-2016-7890, CVE-2016-7891, CVE-2016-7892<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li>APSB16-38: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/animate\/apsb16-38.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/animate\/apsb16-38.html<\/font><\/a><\/li>\n\t<li>APSB16-39: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-39.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb16-39.html<\/font><\/a><\/li>\n\t<li>APSB16-40: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/aem-forms\/apsb16-40.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/aem-forms\/apsb16-40.html<\/font><\/a><\/li>\n\t<li>APSB16-41: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/dng-converter\/apsb16-41.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/dng-converter\/apsb16-41.html<\/font><\/a><\/li>\n\t<li>APSB16-42: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb16-42.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb16-42.html<\/font><\/a><\/li>\n\t<li>APSB16-43: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb16-43.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb16-43.html<\/font><\/a><\/li>\n\t<li>APSB16-44: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb16-44.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb16-44.html<\/font><\/a><\/li>\n\t<li>APSB16-45: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb16-45.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb16-45.html<\/font><\/a><\/li>\n\t<li>APSB16-46: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/robohelp\/apsb16-46.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/robohelp\/apsb16-46.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-multiple-security-updates","alert_type":396,"serial_number":"AV16-201","subject":null,"moderation_state":"archived","external_url":null},{"nid":822,"title":"Joomla! Security Release 3.6.5","uuid":"019b9aac-5e65-493c-a060-f30c9494bcc7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:52Z","date_created":"2018-06-28T14:31:57Z","summary":null,"body":["<article data-history-node-id=\"822\" about=\"\/en\/alerts-advisories\/joomla-security-release-365\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-202<br \/>\nDate: 14 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released a new version that contains security fixes to address the following vulnerabilities in Joomla!:<\/p>\n\n<ul><li>Elevated Privileges<\/li>\n\t<li>Shell Upload<\/li>\n\t<li>Security hardening of configuration tools for user account settings<\/li>\n<\/ul><p>Versions affected: Joomla! 1.6.0 through 3.6.4<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5693-joomla-3-6-5-released.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5693-joomla-3-6-5-released.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-release-365","alert_type":396,"serial_number":"AV16-202","subject":null,"moderation_state":"archived","external_url":null},{"nid":896,"title":"Mozilla Releases security updates","uuid":"aaf2762d-2916-4642-97bd-e399b62975d0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-28T15:18:16Z","summary":null,"body":["<article data-history-node-id=\"896\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-203<br \/>\nDate: 15 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 14 vulnerabilities (4 Critical, 7 High, and 3 Moderate) in Firefox and Firefox ESR. The severity of these issues ranges from moderate to critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 50.1<br \/>\nESR versions prior to 45.6<\/p>\n\n<p>CVE references:<\/p>\n\n<p>CVE-2016-9893, CVE-2016-9894, CVE-2016-9895, CVE-2016-9896, CVE-2016-9897, CVE-2016-9898, CVE-2016-9899, CVE-2016-9900, CVE-2016-9901, CVE-2016-9902, CVE-2016-9903, CVE-2016-9904, CVE-2016-9905, CVE-2016-9980<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-95\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-95\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-94\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-94\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-7","alert_type":396,"serial_number":"AV16-203","subject":null,"moderation_state":"archived","external_url":null},{"nid":1325,"title":"Multiple Apple security updates","uuid":"b23608a3-7ba2-4afd-8a9f-6a6d0e2b4fa5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:46Z","date_created":"2018-06-28T15:24:42Z","summary":null,"body":["<article data-history-node-id=\"1325\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-204<br \/>\nDate: 15 December 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iCloud, iTunes, macOS (Sierra, El Capitan, Yosemite) and Safari.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<p>HT207421 \u2013 Safari 10.0.2<br \/>\nHT207423 \u2013 macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite<br \/>\nHT207424 \u2013 iCloud for Windows 6.1<br \/>\nHT207427 \u2013 iTunes 12.5.4 for Windows<\/p>\n\n<p>This update addresses multiple vulnerabilities on the systems listed above.<\/p>\n\n<p>CVE Reference: CVE-2016-1777, CVE-2016-1823, CVE-2016-4688, CVE-2016-4691, CVE-2016-4692, CVE-2016-4693, CVE-2016-4743, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-6303, CVE-2016-6304, CVE-2016-7141, CVE-2016-7167, CVE-2016-7411, CVE-2016-7412, CVE-2016-7413, CVE-2016-7414, CVE-2016-7416, CVE-2016-7417, CVE-2016-7418, CVE-2016-7636, CVE-2016-7586, CVE-2016-7587, CVE-2016-7588, CVE-2016-7589, CVE-2016-7591, CVE-2016-7592, CVE-2016-7594, CVE-2016-7595, CVE-2016-7596, CVE-2016-7598, CVE-2016-7599, CVE-2016-7600, CVE-2016-7602, CVE-2016-7603, CVE-2016-7604, CVE-2016-7605, CVE-2016-7606, CVE-2016-7607, CVE-2016-7608, CVE-2016-7609, CVE-2016-7610, CVE-2016-7611, CVE-2016-7612, CVE-2016-7615, CVE-2016-7616, CVE-2016-7617, CVE-2016-7618, CVE-2016-7619, CVE-2016-7620, CVE-2016-7621, CVE-2016-7622, CVE-2016-7624, CVE-2016-7625, CVE-2016-7627, CVE-2016-7628, CVE-2016-7629, CVE-2016-7632, CVE-2016-7633, CVE-2016-7635, CVE-2016-7637, CVE-2016-7639, CVE-2016-7640, CVE-2016-7641, CVE-2016-7642, CVE-2016-7643, CVE-2016-7644, CVE-2016-7645, CVE-2016-7646, CVE-2016-7648, CVE-2016-7649, CVE-2016-7652, CVE-2016-7654, CVE-2016-7656, CVE-2016-7657, CVE-2016-7658, CVE-2016-7659, CVE-2016-7660, CVE-2016-7661, CVE-2016-7662, CVE-2016-7663, CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8620, CVE-2016-8621, CVE-2016-8622, CVE-2016-8623, CVE-2016-8624, CVE-2016-8625<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Article HT207421, HT207422, HT207424 and HT207427.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT207421\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207421<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207423\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207423<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207424\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207424<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207427\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207427<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-7","alert_type":396,"serial_number":"AV16-204","subject":null,"moderation_state":"archived","external_url":null},{"nid":1018,"title":"Nagios Core security updates","uuid":"d23e064e-3fa0-40be-ad0b-d68f7686537f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-06-28T15:30:31Z","summary":null,"body":["<article data-history-node-id=\"1018\" about=\"\/en\/alerts-advisories\/nagios-core-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-205<br \/>\nDate: 16 December 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security updates for Nagios Core.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Nagios has recently published updates to their Nagios Core software. The latest updates contained security fixes for various vulnerabilities; including arbitrary code execution, cross-site request forgery attacks, and root privilege escalation.<\/p>\n\n<p>Version affected: 4.2.3 and earlier<\/p>\n\n<p>CVE References: CVE-2008-4796, CVE-2013-4214, CVE-2016-8641, CVE-2016-9565, CVE-2016-9566<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators review the change log in the context of their infrastructure and deploy the vendor-released updates to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/www.nagios.org\/projects\/nagios-core\/history\/4x\/\"><font color=\"#0066cc\">https:\/\/www.nagios.org\/projects\/nagios-core\/history\/4x\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nagios-core-security-updates","alert_type":396,"serial_number":"AV16-205","subject":null,"moderation_state":"archived","external_url":null},{"nid":1151,"title":"VMware Security Advisories","uuid":"8f4afe9b-9ea2-411d-937d-288326e514f8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-06-28T15:36:27Z","summary":null,"body":["<article data-history-node-id=\"1151\" about=\"\/en\/alerts-advisories\/vmware-security-advisories-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-206<br \/>\nDate: 22 December 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for 2 VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware vSphere Hypervisor (ESXi) \u2013 this update addresses a cross-site scripting vulnerability found in Versions 5.5 and Version 6.0 of ESXi and has a severity rating of \"Important\".<\/li>\n\t<li>vSphere Data Protection (VDP) \u2013 this update addresses an SSH Key-Based authentication vulnerability found in Versions 6.1,6.0,5.8,5.5 and has a severity rating of \"Critical\".<\/li>\n<\/ul><p>CVE References: CVE-2016-7456, CVE-2016-7463<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>VMware Advisories<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0023.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0023.html<\/font><\/a><br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0024.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2016-0024.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisories-0","alert_type":396,"serial_number":"AV16-206","subject":null,"moderation_state":"archived","external_url":null},{"nid":1216,"title":"FFmpeg security update","uuid":"b471f9c4-aa54-4ef8-b21f-f2ad0e663409","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-28T15:42:21Z","summary":null,"body":["<article data-history-node-id=\"1216\" about=\"\/en\/alerts-advisories\/ffmpeg-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-207<br \/>\nDate: 23 December 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A security update was released for FFmpeg which addresses multiple vulnerabilities.\u00a0 Exploitation of these vulnerabilities may allow for arbitrary remote code execution.<\/p>\n\n<p>FFmpeg is an open source software project including libraries and tools focused on the handling of multimedia data.\u00a0 It is included with and widely leveraged by several hardware and software products.<\/p>\n\n<p>Affected versions:<br \/>\nFFmpeg versions prior to 3.2<\/p>\n\n<p>CVE References: CVE-2016-5199, CVE-2016-7122, CVE-2016-7450, CVE-2016-7502, CVE-2016-7555, CVE-2016-7562, CVE-2016-7785, CVE-2016-7905, CVE-2016-8595<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/ffmpeg.org\/security.html\"><font color=\"#0066cc\">http:\/\/ffmpeg.org\/security.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ffmpeg-security-update","alert_type":396,"serial_number":"AV16-207","subject":null,"moderation_state":"archived","external_url":null},{"nid":1304,"title":"Cisco Releases security updates","uuid":"1d4fa875-1c06-4695-83ba-35820ad4581e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-06-28T15:49:06Z","summary":null,"body":["<article data-history-node-id=\"1304\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-208<br \/>\nDate: 24 December 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in the following products.\u00a0<\/p>\n\n<ul><li>Cisco IOS XE Software Directory Traversal Vulnerability<\/li>\n\t<li>Cisco ASA Input Validation File Injection Vulnerability<\/li>\n\t<li>Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability<\/li>\n\t<li>Cisco Email Security Appliance MIME Header Processing Filter Bypass Vulnerability<\/li>\n\t<li>Cisco Firepower System Software FTP Malware Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability<\/li>\n\t<li>Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016\u00a0<\/li>\n\t<li>Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016<\/li>\n\t<li>Cisco AnyConnect Secure Mobility Client Local Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco ASR 5000 Series IPv6 Packet Processing Denial of Service Vulnerability<\/li>\n\t<li>Cisco ASR 5000 Series IKEv2 Denial of Service Vulnerability<\/li>\n\t<li>Cisco Security Appliances AsyncOS Software Update Server Certificate Validation Vulnerability<\/li>\n\t<li>Cisco IOx Application-Hosting Framework Directory Traversal Vulnerability<\/li>\n\t<li>Cisco Emergency Responder Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Emergency Responder Directory Traversal Vulnerability<\/li>\n\t<li>Cisco ONS 15454 Series Multiservice Provisioning Platforms TCP Port Management Denial of Service Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Administration Page Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Unified Reporting Upload Tool Directory Traversal Vulnerability<\/li>\n\t<li>Cisco Email Security Appliance SMTP Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco FireAMP Connector Endpoint Software Denial of Service Vulnerability<\/li>\n\t<li>Cisco Firepower Management Center and Cisco FireSIGHT System Software Malicious Software Detection Bypass Vulnerability<\/li>\n\t<li>Cisco FirePOWER Malware Protection Bypass Vulnerability<\/li>\n\t<li>Cisco Hybrid Media Service Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Intercloud Fabric Director Static Credentials Vulnerability<\/li>\n\t<li>Cisco IOS Frame Forwarding Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software SSH X.509 Authentication Bypass Vulnerability<\/li>\n\t<li>Cisco IOS XR Software HTTP 2.0 Request Handling Event Service Daemon Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and Cisco IOS XE Software Zone-Based Firewall Feature Bypass Vulnerability<\/li>\n\t<li>Cisco IOS XR Software Default Credentials Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine Active Directory Integration Component Denial of Service Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Assurance Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Firepower Management Center Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance HTTP URL Denial of Service Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance Drop Decrypt Policy Bypass Vulnerability<\/li>\n\t<li>Cisco IOS Software and IOS XE Software Internet Key Exchange Version 2 Denial of Service Vulnerabilities<\/li>\n\t<li>Vulnerability in Linux Kernel Affecting Cisco Products: October 2016<\/li>\n\t<li>Cisco Email Security Appliance Content Filter Bypass Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software IPv6 First Hop Security Denial of Service Vulnerabilities<\/li>\n\t<li>Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016<\/li>\n\t<li>Cisco Expressway Series Software Security Bypass Vulnerability<\/li>\n\t<li>Cisco Intercloud Fabric Database Static Credentials Vulnerability<\/li>\n\t<li>Cisco Jabber Guest Server HTTP URL Redirection Vulnerability<\/li>\n\t<li>Cisco CloudCenter Orchestrator Docker Engine Privilege Escalation Vulnerability<\/li>\n<\/ul><p>CVE References:<br \/>\nCritical Impact CVE: CVE-2016-9223\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\nHigh Impact CVEs: CVE-2015-0642, CVE-2015-0643, CVE-2015-6278, CVE-2015-6279<br \/>\nMedium Impact CVEs: CVE-2016-6450, CVE-2016-6461, CVE-2016-6466, CVE-2016-6462, CVE-2016-6463, CVE-2016-6460, CVE-2016-6472, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-7052, CVE-2016-7053, CVE-2016-7054, CVE-2016-7055, CVE-2016-9192, CVE-2016-6467, CVE-2016-9203, CVE-2016-1411, CVE-2016-9199, CVE-2016-6468, CVE-2016-9208, CVE-2016-9211, CVE-2016-9206, CVE-2016-9210, CVE-2016-9202, CVE-2016-6449, CVE-2016-9193, CVE-2016-9209, CVE-2016-6470, CVE-2016-9204, CVE-2016-6473, CVE-2016-6474, CVE-2016-9205, CVE-2016-9201, CVE-2016-9215, CVE-2016-9198, CVE-2016-9214, CVE-2016-9200, CVE-2016-6464, CVE-2016-6471, CVE-2016-6469, CVE-2016-9212, CVE-2016-5195, CVE-2016-6465, CVE-2015-8138, CVE-2016-7426, CVE-2016-7427, CVE-2016-9207, CVE-2016-9217, CVE-2016-9224<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161115-iosxe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161115-iosxe<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-asa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-asa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-esa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-esa1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-esa2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-esa2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-fss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-fss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161116-ucm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161114-openssl\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161114-openssl<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-anyconnect1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-anyconnect1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-asr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-asr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-asr1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-asr1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-asyncos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-asyncos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-caf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-caf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cer\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cer<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cer1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cer1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cons\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cons<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cucm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cur\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-cur<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-esa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-esa1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-fireamp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-fireamp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-firepower\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-firepower<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-fpwr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-fpwr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-hms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-hms<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-icf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-icf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios-xe-x509\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios-xe-x509<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios-xr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios-xr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios-zbf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ios-zbf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-iosxr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-iosxr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ise<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ise1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ise1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-pca\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-pca<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-ucm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-vdc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-vdc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-wsa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-wsa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-wsa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-wsa1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20150325-ikev2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20150325-ikev2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-linux\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-linux<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-esa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-esa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20150923-fhs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20150923-fhs<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161123-ntpd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161123-ntpd<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-expressway\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-expressway<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161221-icf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161221-icf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161221-jabber\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161221-jabber<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161221-cco\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161221-cco<\/font><\/a> \u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-9","alert_type":396,"serial_number":"AV16-208","subject":null,"moderation_state":"archived","external_url":null},{"nid":1066,"title":"Security fix released for PHPMailer","uuid":"dc432b17-fa4a-4e69-9a79-5061d8b973d8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:38Z","date_created":"2018-06-28T17:00:09Z","summary":null,"body":["<article data-history-node-id=\"1066\" about=\"\/en\/alerts-advisories\/security-fix-released-phpmailer\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-209<br \/>\nDate: 27 December 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released security fix for PHPMailer.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The PHPMailer team has released an update to address a vulnerability in PHPMailer. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on web servers and remotely compromise target web applications.<\/p>\n\n<p>Versions affected: PHPMailer 5.2.18<\/p>\n\n<p>CVE Reference: CVE-2016-10033<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/github.com\/PHPMailer\/PHPMailer\/blob\/master\/changelog.md#version-5219-december-26th-2016\"><font color=\"#0066cc\">https:\/\/github.com\/PHPMailer\/PHPMailer\/blob\/master\/changelog.md#version-5219-december-26th-2016<\/font><\/a> \u00a0\u00a0<br \/><a href=\"https:\/\/github.com\/PHPMailer\/PHPMailer\"><font color=\"#0066cc\">https:\/\/github.com\/PHPMailer\/PHPMailer<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fix-released-phpmailer","alert_type":396,"serial_number":"AV16-209","subject":null,"moderation_state":"archived","external_url":null},{"nid":881,"title":"Mozilla ThunderBird security update","uuid":"695ea691-ebb1-4192-a2d6-6607b6f077b9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-06-28T17:05:38Z","summary":null,"body":["<article data-history-node-id=\"881\" about=\"\/en\/alerts-advisories\/mozilla-thunderbird-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-210<br \/>\nDate: 29 December 2016<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla ThunderBird for which an upgrade his now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released a security update to address multiple vulnerabilities in ThunderBird. The severity of these issues ranges from high to critical.<\/p>\n\n<p>Version affected:<br \/>\nThunderBird version prior to 45.6<\/p>\n\n<p>CVE References:<br \/>\nCritical: CVE-2016-9893, CVE-2016-9899<br \/>\nHigh: CVE-2016-9895, CVE-2016-9897, CVE-2016-9898, CVE-2016-9900, CVE-2016-9904, CVE-2016-9905<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-96\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2016-96\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-thunderbird-security-update","alert_type":396,"serial_number":"AV16-210","subject":null,"moderation_state":"archived","external_url":null},{"nid":1049,"title":"Active Exploitation of Database Services using Default Installation Configurations","uuid":"4dc4edd1-e0c2-42a0-9932-e292b49557e7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-06-28T17:13:25Z","summary":null,"body":["<article data-history-node-id=\"1049\" about=\"\/en\/alerts-advisories\/active-exploitation-database-services-using-default-installation-configurations\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-001<br \/>\nDate: 06 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to the active exploitation of database services through default installation configurations.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of malicious attackers leveraging knowledge of default installation configurations for database services.\u00a0 Open source news articles have indicated that these actors have been observed scanning for and accessing MongoDB installations with default configurations, exporting the data to their host, wiping the contents from the database, then holding the data for ransom.<\/p>\n\n<p>With default installation configurations, several database software packages are easily susceptible to this type of exploitation and attack as they either do not require any authentication (ex. MongoDB), or they employ publicly available default credentials.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC strongly discourages the paying of any ransom.\u00a0 Paying a ransom does not guarantee you will get your data back and it encourages further criminal activity.<\/p>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<p>\u2022 Enable access control and require authentication (with a robust password policy).<br \/>\n\u2022 Limit network exposure to what is minimally necessary (ex. trusted hosts\/interfaces).<br \/>\n\u2022 Employ a data backup policy.<br \/>\n\u2022 Deploy security solutions as applicable.<br \/>\n\u2022 Ensure systems are patched and updated.<\/p>\n\n<p>Several developers\/vendors of database software packages provide software specific security documents (ex. best practices, checklists, guides, manuals, etc.) which should be reviewed and actioned as deemed required.<\/p>\n\n<h2>References<\/h2>\n\n<p>MongoDB Security Checklist:<br \/><a href=\"https:\/\/docs.mongodb.com\/manual\/administration\/security-checklist\/\"><font color=\"#0066cc\">https:\/\/docs.mongodb.com\/manual\/administration\/security-checklist\/<\/font><\/a><\/p>\n\n<p>News: Number of Hijacked MongoDB Databases Is Going Up as More Hackers Are Flocking In<br \/><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/number-of-hijacked-mongodb-databases-is-going-up-as-more-hackers-are-flocking-in\/\"><font color=\"#0066cc\">https:\/\/www.bleepingcomputer.com\/news\/security\/number-of-hijacked-mongodb-databases-is-going-up-as-more-hackers-are-flocking-in\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-database-services-using-default-installation-configurations","alert_type":397,"serial_number":"AL17-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1179,"title":"Cisco IOS and IOS XE Software Cluster Management Protocol Vulnerability","uuid":"c55574ca-acd8-438c-a425-8a6caf706e96","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-28T17:19:45Z","summary":null,"body":["<article data-history-node-id=\"1179\" about=\"\/en\/alerts-advisories\/cisco-ios-and-ios-xe-software-cluster-management-protocol-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-002<br \/>\nDate: 20 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in Cisco\u2019s IOS and IOS XE Software Cluster Management Protocol (CMP).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a recently disclosed vulnerability in Cisco\u2019s IOS and IOS XE Software CMP.\u00a0 Identified as CVE-2017-3881, this vulnerability code can allow a remote unauthenticated attacker to cause a reload of the affected system or to remotely execute code.\u00a0<\/p>\n\n<p>The vulnerability could be successfully exploited by sending malformed CMP-specific Telnet options while establishing a Telnet session with a CISCO device configured to accept Telnet connections.<\/p>\n\n<p>There are over 300 models of Cisco switches that may be affected by this vulnerability. For an extensive list of devices please visit the vendor\u2019s Advisory (listed below).<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for the developer released security fix. Additional mitigation advise has been published by the vendor.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170317-cmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170317-cmp<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-ios-and-ios-xe-software-cluster-management-protocol-vulnerability","alert_type":397,"serial_number":"AL17-002","subject":null,"moderation_state":"archived","external_url":null},{"nid":785,"title":"Widespread Brute Force Login Attempts","uuid":"1238579c-918c-4219-bb98-947d18ce7e4e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-28T17:31:33Z","summary":null,"body":["<article data-history-node-id=\"785\" about=\"\/en\/alerts-advisories\/widespread-brute-force-login-attempts\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-003<br \/>\nDate: 16 February 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to ongoing and widespread brute force login attempt activity observed targeting retail organizations.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has received reports from several retail sector companies concerning ongoing brute force login activity against their customer portals.\u00a0 The malicious actors appear to be targeting retail organizations that have a customer reward or loyalty programs and are using compromised customer account credentials from other sources to steal earned rewards or points.\u00a0 Customer rewards have a translatable cash-value, as they can typically be exchanged for gift cards and\/or other merchandise\/services or sold to a third party.<\/p>\n\n<p>Malicious actors have leveraged several strategies and tactics in their malicious activities, including:<\/p>\n\n<ul><li>utilizing multiple credential-set lists harvested from past publicly disclosed third-party service\/website compromises<\/li>\n\t<li>password-spraying using\u00a0 public email address lists and password dictionaries of commonly used passwords<\/li>\n\t<li>rate-limiting login attempts to remain below detection thresholds<\/li>\n\t<li>using multiple different malicious hosts simultaneously to avoid detection<\/li>\n\t<li>utilizing proxy servers and VPNs to hide the source of the malicious traffic<\/li>\n<\/ul><p>Access to customer accounts and customer data could also potentially facilitate the malicious actors to perform other fraudulent activities including phishing.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<ul><li>Utilize a CAPTCHA (Completely Automated Public Turing Test to tell Computers and Humans Apart) test on login forms.<\/li>\n\t<li>Employ geo-blocking against website visitors outside of your typical customer area.<\/li>\n\t<li>Implement multi-factor authentication methods.<\/li>\n\t<li>Review logs for any suspicious activity and\/or traffic which may indicate potential brute force login attempts.\u00a0 CCIRC suggests investigating any non-typical network\/webserver activity or usage metrics including:\n\t<ul><li>Extended periods of high load\/traffic\/usage.<\/li>\n\t\t<li>High volume of account login failures including accounts that don\u2019t exist, or conform to your username and password convention<\/li>\n\t\t<li>Multiple login attempts for different users from the same IP.<\/li>\n\t\t<li>High volume of account login attempts from outside your typical customer demographic.<\/li>\n\t<\/ul><\/li>\n\t<li>Disallowing redemption of customer rewards for items with direct monetary value (eg. gift cards or vouchers).<\/li>\n\t<li>Cross referencing customer email addresses with those of publicly known compromised credential sets.<\/li>\n\t<li>Employ a strong password policy, and disallow use of commonly used passwords.<\/li>\n<\/ul><p>References:<\/p>\n\n<p>Get CyberSafe Guide for Small and Medium Businesses:<br \/><a href=\"https:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx%20-%20s6-2\"><font color=\"#0066cc\">https:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx%20-%20s6-2<\/font><\/a><\/p>\n\n<p>Using Passwords:<br \/><a href=\"https:\/\/www.getcybersafe.gc.ca\/cnt\/prtct-yrslf\/prtctn-dntty\/usng-psswrds-en.aspx\"><font color=\"#0066cc\">https:\/\/www.getcybersafe.gc.ca\/cnt\/prtct-yrslf\/prtctn-dntty\/usng-psswrds-en.aspx<\/font><\/a><\/p>\n\n<p>Spotting Malicious E-mail Messages:<br \/><a href=\"https:\/\/www.cse-cst.gc.ca\/en\/node\/237\/html\/2998\"><font color=\"#0066cc\">https:\/\/www.cse-cst.gc.ca\/en\/node\/237\/html\/2998<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/widespread-brute-force-login-attempts","alert_type":397,"serial_number":"AL17-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":1266,"title":"Software Compromised with Backdoor Trojan","uuid":"4b2319ef-1a16-4c40-a36e-fe1811297a0c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-06-28T18:43:47Z","summary":null,"body":["<article data-history-node-id=\"1266\" about=\"\/en\/alerts-advisories\/software-compromised-backdoor-trojan\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-009<br \/>\nDate: 17 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed compromised software update by NetSarang.\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has received a report of a software developer (NetSarang) which was compromised, which led to the embedding of malicious code (ShadowPad backdoor trojan) in some of their distributed software packages.<\/p>\n\n<p>The affected software was distributed by NetSarang through their website and in-application update utilities between the dates of 18 July to 4 August 2017.<\/p>\n\n<p>The identified malicious software from the developer (NetSarang) are identified below.\u00a0 File compilation dates for the install packages are all 17 July 2017.<\/p>\n\n<ul><li>Xmanager Enterprise 5 Build 1232<\/li>\n\t<li>Xmanager 5 Build 1045<\/li>\n\t<li>Xshell 5 Build 1322<\/li>\n\t<li>Xftp 5 Build 1218<\/li>\n\t<li>Xlpd 5 Build 1220<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<ul><li>Hosts with confirmed installations of compromised versions of the software should be removed from the network for forensic analysis. If re-imaging is to be performed on a compromised host, it is important that the reinstallation fully removes all digital artifacts, including disk partitions and the master boot record.<\/li>\n\t<li>Collect relevant logs pertaining to the connection attempts of the host(s) involved.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n<\/ul><p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.netsarang.com\/news\/security_exploit_in_july_18_2017_build.html\" target=\"_blank\"><font color=\"#0066cc\">http:\/\/www.netsarang.com\/news\/security_exploit_in_july_18_2017_build.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/software-compromised-backdoor-trojan","alert_type":397,"serial_number":"AL17-009","subject":null,"moderation_state":"archived","external_url":null},{"nid":1112,"title":"Bluetooth Critical Vulnerabilities","uuid":"892f4d85-3948-411b-9737-f8b417d04615","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-28T18:55:15Z","summary":null,"body":["<article data-history-node-id=\"1112\" about=\"\/en\/alerts-advisories\/bluetooth-critical-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-011<br \/>\nDate: 13 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to, and to provide guidance and mitigation advice for multiple critical vulnerabilities affecting a broad range of Bluetooth enabled devices. Security researchers have named this group of Bluetooth vulnerabilities \"BlueBorne\".<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has become aware of multiple critical vulnerabilities in the implementation of the Bluetooth stack in multiple versions of Android, Apple iOS, Microsoft Windows and Linux based products, among others. The vulnerabilities could allow for a malicious threat actor to execute code, intercept wireless communications, abuse device functionality and\/or perform man-in-the-middle attacks. While no known active exploitation has been reported, a working proof of concept is available.<\/p>\n\n<p>Open source reporting describing the vulnerabilities suggests that exploitation does not require the targeted device to be set on discoverable mode or paired to the threat actor's device; furthermore, authorization is not required by the end user nor does it require authentication for the connection to be made.<\/p>\n\n<p>CCIRC recommends information security teams to monitor for future vendor supplied updates and apply relevant security patches as they become available. Below is a list of the potentially affected products and their relevant versions:<\/p>\n\n<p><strong>Android<\/strong><br \/>\nAndroid phones, tablets, and wearables of all versions are affected by the four following vulnerabilities:<\/p>\n\n<ul><li>CVE-2017-0781: Android Remote Code Execution Vulnerability<\/li>\n\t<li>CVE-2017-0782: Android Remote Code Execution Vulnerability<\/li>\n\t<li>CVE-2017-0783: Android Potential Man in the Middle Attack<\/li>\n\t<li>CVE-2017-0785: Android Bluetooth Information Leak Vulnerability<\/li>\n<\/ul><p>Android devices using Bluetooth Low Energy only are not affected.<\/p>\n\n<p>The vulnerabilities affecting Marshmallow (6.0) and Nougat (7.0) Android devices were addressed in Google's Android Security Bulletin released September 12th, 2017.<\/p>\n\n<p><strong>Apple<\/strong><br \/>\nThe following vulnerability affecting iPhone, iPad and iPod touch devices with iOS 7 through 9 and Apple TV devices with version 7.2.2 and lower:<\/p>\n\n<ul><li>CVE-2017-14315: Apple Low Energy Audio Remote Code Execution Vulnerability<\/li>\n<\/ul><p>The vulnerability affecting Apple devices has been resolved in iOS 10, released in September 2016.<\/p>\n\n<p><strong>Microsoft<\/strong><br \/>\nWindows versions 10, 8.1, 7, Server 2016 and Server 2008 are affected by the following vulnerability:<\/p>\n\n<ul><li>CVE-2017-8628: Microsoft Bluetooth Driver Spoofing Vulnerability<\/li>\n<\/ul><p>The vulnerability affecting Microsoft devices has been resolved by a security update released September 12, 2017.<br \/><br \/><strong>Linux<\/strong><br \/>\nLinux devices running BlueZ 5.46 and earlier are affected by:<\/p>\n\n<ul><li>CVE-2017-1000250: Linux Bluetooth Information Leak Vulnerability<\/li>\n<\/ul><p>The vulnerability affecting Red Hat Enterprise Linux 7 and 6 devices has been resolved by a security update released by Red Hat on September 12, 2017.<\/p>\n\n<p>Linux kernel versions 3.3-rc1 and up to and including 4.13.1 are affected by the following:<\/p>\n\n<ul><li>CVE-2017-1000251: Linux Remote Code Execution Vulnerability<\/li>\n<\/ul><p>Red Hat Enterprise Linux 5 is not affected.<\/p>\n\n<p>The vulnerability affecting Red Hat Enterprise Linux 7, 6 and MRG 2 devices has been resolved by a security update released by Red Hat on September 12, 2017.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends those utilizing Bluetooth enabled products to consult the vendor for specific risk mitigation advice and patches available. In non-critical applications, CCIRC recommends considering disabling Bluetooth wireless communications. In mission critical or life sustaining applications, the potential consequences of disabling Bluetooth needs to be assessed along with an assessment of risk based on the environment in which the Bluetooth enabled device is being used. In addition, the Bluetooth protocol has a peer to peer wireless transmission range of 10-100 meters in many common mobile devices; this aspect should be taken into account when applying mitigation measures.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/240311\"><font color=\"#0066cc\">https:\/\/www.kb.cert.org\/vuls\/id\/240311<\/font><\/a><br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2017-09-01\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2017-09-01<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-14315\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-14315<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8628\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8628<\/font><\/a><br \/><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/blueborne\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/vulnerabilities\/blueborne<\/font><\/a><br \/><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2017-1000250\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/cve\/CVE-2017-1000250<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-1000250\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-1000250<\/font><\/a><br \/><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2017-1000251\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/cve\/CVE-2017-1000251<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-1000251\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-1000251<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/bluetooth-critical-vulnerabilities","alert_type":397,"serial_number":"AL17-011","subject":null,"moderation_state":"archived","external_url":null},{"nid":938,"title":"Wi-Fi Protected Access II (WPA2) Handshake Vulnerabilities","uuid":"1a80708e-28e3-46af-9b90-f5cde4578ee3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:45Z","date_created":"2018-06-28T19:05:04Z","summary":null,"body":["<article data-history-node-id=\"938\" about=\"\/en\/alerts-advisories\/wi-fi-protected-access-ii-wpa2-handshake-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-012<br \/>\nDate: 16 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to multiple critical vulnerabilities in WPA2, a protocol that secures all modern protected Wi-Fi networks.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has become aware of multiple critical vulnerabilities in WPA2 handshake traffic. These vulnerabilities can be manipulated to induce nonce and session key reuse which could result in key reinstallation by a wireless access point or client. This could then enable arbitrary packet decryption and injection, TCP connection hijacking, HTTP content injection, or the replay of unicast, broadcast, and multicast frames.<\/p>\n\n<p>As these vulnerabilities are in the Wi-Fi standard, they are not related to individual products or their implementation. However, the correct implementation of the WPA2 protocol is likely affected.<\/p>\n\n<p>The WPA2 protocol is affected by the following vulnerabilities:<\/p>\n\n<ul><li>CVE-2017-13077: Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake.<\/li>\n\t<li>CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake.<\/li>\n\t<li>CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way handshake.<\/li>\n\t<li>CVE-2017-13080: Reinstallation of the group key (GTK) in the group key handshake.<\/li>\n\t<li>CVE-2017-13081: Reinstallation of the integrity group key (IGTK) in the group key handshake.<\/li>\n\t<li>CVE-2017-13082: Accepting a retransmitted Fast BSS Transition (FT) Reassociation Request and reinstalling the pairwise encryption key (PTK-TK) while processing it.<\/li>\n\t<li>CVE-2017-13084: Reinstallation of the STK key in the PeerKey handshake.<\/li>\n\t<li>CVE-2017-13086: Reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey (TPK) key in the TDLS handshake.<\/li>\n\t<li>CVE-2017-13087: Reinstallation of the group key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame.<\/li>\n\t<li>CVE-2017-13088: Reinstallation of the integrity group key (IGTK) when processing a Wireless Network management (WNM) Sleep Mode Response frame<\/li>\n<\/ul><h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that network administrators install updates to affected products as they become available and to consult the vendor for specific risk mitigation advice.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/228519\"><font color=\"#0066cc\">https:\/\/www.kb.cert.org\/vuls\/id\/228519<\/font><\/a><br \/><a href=\"https:\/\/papers.mathyvanhoef.com\/ccs2017.pdf\"><font color=\"#0066cc\">https:\/\/papers.mathyvanhoef.com\/ccs2017.pdf<\/font><\/a><br \/><a href=\"https:\/\/www.krackattacks.com\/\"><font color=\"#0066cc\">https:\/\/www.krackattacks.com<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wi-fi-protected-access-ii-wpa2-handshake-vulnerabilities","alert_type":397,"serial_number":"AL17-012","subject":null,"moderation_state":"archived","external_url":null},{"nid":1190,"title":"Exim Internet Mail Vulnerabilities","uuid":"ffb198b5-4486-494f-bea5-1aa742232a78","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:02Z","date_created":"2018-06-28T19:10:49Z","summary":null,"body":["<article data-history-node-id=\"1190\" about=\"\/en\/alerts-advisories\/exim-internet-mail-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-013<br \/>\nDate: 28 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to recently disclosed vulnerabilities in Exim Internet Mailer.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has become aware of two vulnerabilities in Exim Internet Mailer version 4.88 and 4.89 that allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for the developer released security fix. Additional mitigation advice has been published by the vendor.<\/p>\n\n<p>Furthermore, CCIRC is providing a Suricata rule to detect BDAT command that attempt to exploit those vulnerabilities.<\/p>\n\n<p>alert smtp any any -&gt; $HOME_NET any (msg: \"[PT OPEN] Exim 4.88, 4.89 UAF RCE Attempt (CVE-2017-16943)\"; flow: established, to_server; content: \"BDAT\"; content: \"BDAT\"; within: 10; pcre: \"\/BDAT\\s*\\D[^\\n\\r]*[\\n\\r][^\\n\\r]{100}\/\"; reference: cve, 2017-16943; reference: url, bugs.exim.org\/show_bug.cgi?id=2199; classtype: attempted-admin; sid: 10002280; rev: 2; )<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/git.exim.org\/exim.git\/commitdiff\/4e6ae6235c68de243b1c2419027472d7659aa2b4\"><font color=\"#0066cc\">https:\/\/git.exim.org\/exim.git\/commitdiff\/4e6ae6235c68de243b1c2419027472d7659aa2b4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/bugs.exim.org\/show_bug.cgi?id=2199\"><font color=\"#0066cc\">https:\/\/bugs.exim.org\/show_bug.cgi?id=2199<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=cve-2017-16943\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=cve-2017-16943<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-internet-mail-vulnerabilities","alert_type":397,"serial_number":"AL17-013","subject":null,"moderation_state":"archived","external_url":null},{"nid":814,"title":"Transport Layer Security (TLS) Vulnerability","uuid":"2a9a8259-d18c-4357-813c-244b5886d02c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:52Z","date_created":"2018-06-28T19:17:00Z","summary":null,"body":["<article data-history-node-id=\"814\" about=\"\/en\/alerts-advisories\/transport-layer-security-tls-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-014<br \/>\nDate: 13 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed Transport Layer Security (TLS) vulnerability.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has become aware of a Transport Layer Security (TLS) vulnerability, also known as Return of Bleichenbacher's Oracle Threat (ROBOT). ROBOT allows an attacker to obtain the RSA key necessary to decrypt TLS traffic under certain conditions.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for a vendor released security fix, refer to your product's documentation or contact the vendor's customer service for more information.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/robotattack.org\/\"><font color=\"#0066cc\">https:\/\/robotattack.org<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/144389\"><font color=\"#0066cc\">http:\/\/www.kb.cert.org\/vuls\/id\/144389<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/transport-layer-security-tls-vulnerability","alert_type":397,"serial_number":"AL17-014","subject":null,"moderation_state":"archived","external_url":null},{"nid":897,"title":"Malcode affecting Triconex Industrial Safety Controllers","uuid":"f0d28dc7-daa4-440b-8661-e87d82403f62","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-06-28T19:25:40Z","summary":null,"body":["<article data-history-node-id=\"897\" about=\"\/en\/alerts-advisories\/malcode-affecting-triconex-industrial-safety-controllers\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-015<br \/>\nDate: 21 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recent and publicly disclosed incident involving an unexpected shutdown of an industrial processing plant.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The incident has revealed an instance of malcode specifically crafted to compromise the operation of Schneider-Electric branded Triconex industrial safety controller devices. Publicly available sources and media reports indicate that this malicious code has been identified under the names TRITON, TRISIS and HatMan.<\/p>\n\n<p>While there is currently no information that would indicate that the activity associated with this incident is widespread, access into to the industrial safety network could allow the deployment of malicious code and its execution. The application of security guidance from the manufacturer should sufficiently mitigate this risk.<\/p>\n\n<p>Network segmentation and strict authentication and access controls should be in place wherever process controls and their safety systems are deployed. The same applies to automation and other types of controls as their communication protocols often lack the necessary authentication and integrity controls needed to prevent network replay attacks and counterfeit messages from occurring.<\/p>\n\n<p>ICS-CERT has released a Malware Analysis Report (MAR-17-352-01 HATMAN) which outlines the tactics, techniques and procedures associated with the malicious code. ICS-CERT notes that although the malicious code \u201cdoes not do anything catastrophic\u2014safety systems do not directly control the process, so a degraded safety system will not cause a correctly functioning process to misbehave\u2014it could be very damaging when combined with malware that impacts the process in tandem.\u201d<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Schneider Security Recommendations<\/p>\n\n<p>Schneider Electric recommends customers follow the instructions contained in the \u201cSecurity Considerations\u201d section within the Planning and Installation Guide for each respective Triconex controller (Tricon, Trident, Tri-GP), which include the following:<\/p>\n\n<ul><li>Safety systems must always be deployed on isolated networks using zones and conduits as defined in IEC-62443.<\/li>\n\t<li>Physical controls should be in place so no unauthorized person has access to the plant, equipment rooms, safety controllers, safety peripheral equipment or the safety network.<\/li>\n\t<li>All controllers should reside in locked cabinets and never be left in the \u201cProgram\u201d mode.<\/li>\n\t<li>All TriStation terminals (Triconex programming software) should be kept in locked cabinets and should never be connected to any network other than the safety network.<\/li>\n\t<li>All methods of mobile data exchange with the isolated safety network, such as CDs, USB drives, etc., should be scanned before use in the TriStation terminals or any node connected to this network.<\/li>\n\t<li>Laptops that are connected to any other network-- beside the safety network-- should never be allowed to connect to the safety network without proper sanitation.<\/li>\n\t<li>Operator stations should be configured to display an alarm whenever the Tricon keyswitch is in the \u201cProgram Mode\u201d; key removed and secured.<\/li>\n\t<li>Enhanced security features in TriStation, as well as the Triconex communication modules, should be enabled.<\/li>\n<\/ul><p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.schneider-electric.com\/en\/download\/document\/SEVD-2017-347-01\/\"><font color=\"#0066cc\">https:\/\/www.schneider-electric.com\/en\/download\/document\/SEVD-2017-347-01\/<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/ics-cert.us-cert.gov\/MAR-17-352-01-HatMan%E2%80%94Safety-System-Targeted-Malware\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/MAR-17-352-01-HatMan%E2%80%94Safety-System-Targeted-Malware<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2017\/12\/attackers-deploy-new-ics-attack-framework-triton.html\"><font color=\"#0066cc\">https:\/\/www.fireeye.com\/blog\/threat-research\/2017\/12\/attackers-deploy-new-ics-attack-framework-triton.html<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/dragos.com\/blog\/trisis\/TRISIS-01.pdf\"><font color=\"#0066cc\">https:\/\/dragos.com\/blog\/trisis\/TRISIS-01.pdf<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/dragos.com\/blog\/trisis\/index.html?optin=no\"><font color=\"#0066cc\">https:\/\/dragos.com\/blog\/trisis\/index.html?optin=no<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/malcode-affecting-triconex-industrial-safety-controllers","alert_type":397,"serial_number":"AL17-015","subject":null,"moderation_state":"archived","external_url":null},{"nid":1326,"title":"Android security bulletin \u2013 January 2017","uuid":"db90a8fe-6fbc-4ef9-a76a-9d1b24b3d191","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:46Z","date_created":"2018-06-28T19:38:03Z","summary":null,"body":["<article data-history-node-id=\"1326\" about=\"\/en\/alerts-advisories\/android-security-bulletin-january-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-001<br \/>\nDate: 04 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for January.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for 51 vulnerabilities (7 Critical, 28 High, 16 Moderate). Those viewed Critical are so given the possibility of remote code execution vulnerabilities and\/or elevation of privilege vulnerabilities.<\/p>\n\n<p>CVE References: CVE-2016-5180, CVE-2016-5345, CVE-2016-7042, CVE-2016-8412, CVE-2016-8444, CVE-2016-8415, CVE-2016-8445, CVE-2016-8446, CVE-2016-8447, CVE-2016-8448, CVE-2016-8449, CVE-2016-8450, CVE-2016-8451, CVE-2016-8452, CVE-2016-8453, CVE-2016-8454, CVE-2016-8455, CVE-2016-8456, CVE-2016-8457, CVE-2016-8458, CVE-2016-8460, CVE-2016-8461, CVE-2016-8462, CVE-2016-8463, CVE-2016-8467, CVE-2016-9754, CVE-2017-0382, CVE-2017-0383, CVE-2017-0384, CVE-2017-0385, CVE-2017-0386, CVE-2017-0387, CVE-2017-0388, CVE-2017-0389, CVE-2017-0390, CVE-2017-0391, CVE-2017-0392, CVE-2017-0393, CVE-2017-0394, CVE-2017-0403, CVE-2017-0404<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Android Security Bulletin:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2017-01-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2017-01-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-january-2017","alert_type":396,"serial_number":"AV17-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1020,"title":"Control System: Rockwell Automation Logix5000 Controller Vulnerability","uuid":"4deaa3d0-9404-455c-a62d-9adc91ec6d18","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-06-28T19:51:37Z","summary":null,"body":["<article data-history-node-id=\"1020\" about=\"\/en\/alerts-advisories\/control-system-rockwell-automation-logix5000-controller-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-002<br \/>\nDate: 10 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a critical vulnerability affecting Rockwell Automation's Logix5000 Controller product line.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation's Logix5000 Controller product line consists of industrial control system devices leveraging Logix5000 control software. The Logix5000 Controller product line is used in a variety of industrial applications and sectors, including but not limited to: agriculture\/food, manufacturing and water\/wastewater systems.<\/p>\n\n<p>Successful exploitation of this critical vulnerability could potentially allow a remote attacker to cause denial of service conditions or execute arbitrary code.<\/p>\n\n<p>Affected Logix5000 Controller devices include those utilizing firmware versions FRN 16.00 - 21.00 (specific details can be found in ICS-CERT's advisory).<\/p>\n\n<p>CVE Reference: CVE-2016-9343<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>ICS-CERT: ICSA-16-343-05 - Rockwell Automation Logix5000 Programmable Automation Controller Buffer Overflow Vulnerability:<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-343-05\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-343-05<\/font><\/a><\/p>\n\n<p>Rockwell Automation Firmware Downloads:<br \/><a href=\"http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx\"><font color=\"#0066cc\">http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-system-rockwell-automation-logix5000-controller-vulnerability","alert_type":398,"serial_number":"AV17-002","subject":null,"moderation_state":"archived","external_url":null},{"nid":1155,"title":"Adobe Multiple security updates","uuid":"81597a3d-772d-4357-98e6-2a98130ce460","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-06-29T12:57:51Z","summary":null,"body":["<article data-history-node-id=\"1155\" about=\"\/en\/alerts-advisories\/adobe-multiple-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-003<br \/>\nDate: 10 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Adobe Security updates for various products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<\/p>\n\n<p>APSB17-01 - Security updates available for Adobe Acrobat and Reader<br \/>\nAPSB17-02 - Security updates available for Adobe Flash Player<\/p>\n\n<p>CVE References:\u00a0<br \/>\nCVE-2017-2925, CVE-2017-2926, CVE-2017-2927, CVE-2017-2928, CVE-2017-2930, CVE-2017-2931,<br \/>\nCVE-2017-2932, CVE-2017-2933, CVE-2017-2934, CVE-2017-2935, CVE-2017-2936, CVE-2017-2937,<br \/>\nCVE-2017-2938, CVE-2017-2939, CVE-2017-2940, CVE-2017-2941, CVE-2017-2942, CVE-2017-2943,<br \/>\nCVE-2017-2944, CVE-2017-2945, CVE-2017-2946, CVE-2017-2947, CVE-2017-2948, CVE-2017-2949,<br \/>\nCVE-2017-2950, CVE-2017-2951, CVE-2017-2952, CVE-2017-2953, CVE-2017-2954, CVE-2017-2955,<br \/>\nCVE-2017-2956, CVE-2017-2957, CVE-2017-2958, CVE-2017-2959, CVE-2017-2960, CVE-2017-2961,<br \/>\nCVE-2017-2962, CVE-2017-2963, CVE-2017-2964, CVE-2017-2965, CVE-2017-2966, CVE-2017-2967<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>APSB17-01: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-01.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-01.html<\/font><\/a><br \/>\nAPSB17-02: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-02.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-02.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-multiple-security-updates-0","alert_type":396,"serial_number":"AV17-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":1218,"title":"Microsoft Critical security bulletins Summary \u2013 January 2017","uuid":"c3b62bc3-1fc1-480e-977f-1e29661bcd65","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:29Z","date_created":"2018-06-29T13:12:11Z","summary":null,"body":["<article data-history-node-id=\"1218\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-january-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-004<br \/>\nDate: 10 January 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for January 2017.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 4 bulletins (2 Critical, 2 Important), which addresses multiple vulnerabilities in: LSASS, Microsoft Office, Adobe Flash Player for Internet Explorer, and Microsoft Edge.<\/p>\n\n<p>***Critical***<\/p>\n\n<ul><li>MS17-003 Security Update for Adobe Flash Player<\/li>\n\t<li>MS17-002 Security Update for Microsoft Office<\/li>\n<\/ul><p>***Important***<\/p>\n\n<ul><li>MS17-004 Security Update for Local Security Authority Subsystems Service<\/li>\n\t<li>MS17-001 Security Update for Microsoft Edge<\/li>\n<\/ul><p>CVE Reference: CVE-2017-0002, CVE-2017-0003, CVE-2017-0004, CVE-2017-2925, CVE-2017-2926, CVE-2017-2927, CVE-2017-2928, CVE-2017-2930, CVE-2017-2931, CVE-2017-2932, CVE-2017-2933, CVE-2017-2934, CVE-2017-2935, CVE-2017-2936, CVE-2017-2937<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-001\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-001<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-002\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-002<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-003\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-003<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-january-2017","alert_type":396,"serial_number":"AV17-004","subject":null,"moderation_state":"archived","external_url":null},{"nid":1306,"title":"Ansible security updates","uuid":"78372b11-5a8b-40e1-b2d4-f56a650ae745","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-06-29T13:18:26Z","summary":null,"body":["<article data-history-node-id=\"1306\" about=\"\/en\/alerts-advisories\/ansible-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-005<br \/>\nDate: 11 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Ansible.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Security updates were released for Ansible to address a vulnerability (high). Exploitation of this vulnerability could allow a malicious attacker to execute commands on a host's associated Ansible controller. This ability could be leveraged to compromise other hosts managed by an exploited Ansible controller.<\/p>\n\n<p>Ansible is an open-source IT infrastructure automation engine. It automates application deployment\/management, configuration management and cloud provisioning.<\/p>\n\n<p>Affected versions:<br \/>\nAnsible versions 2.1.x prior to 2.1.4 RC1<br \/>\nAnsible versions 2.2.x prior to 2.2.1 RC3<\/p>\n\n<p>CVE Reference: CVE-2016-9587<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Ansible Security Advisory:<br \/><a href=\"https:\/\/groups.google.com\/forum\/#!topic\/ansible-devel\/SyrgcUySAIQ\"><font color=\"#0066cc\">https:\/\/groups.google.com\/forum\/#!topic\/ansible-devel\/SyrgcUySAIQ<\/font><\/a><\/p>\n\n<p>Security Researcher \u2013 Computest Advisory:<br \/><a href=\"https:\/\/www.computest.nl\/advisories\/CT-2017-0109_Ansible.txt\"><font color=\"#0066cc\">https:\/\/www.computest.nl\/advisories\/CT-2017-0109_Ansible.txt<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ansible-security-updates","alert_type":396,"serial_number":"AV17-005","subject":null,"moderation_state":"archived","external_url":null},{"nid":1067,"title":"Security fix released for BIND","uuid":"02220ffc-c51a-43c1-9db1-4ce5d9d98b27","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:38Z","date_created":"2018-06-29T13:25:00Z","summary":null,"body":["<article data-history-node-id=\"1067\" about=\"\/en\/alerts-advisories\/security-fix-released-bind-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-006<br \/>\nDate: 12 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fix for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released an update to address vulnerabilities in BIND. Exploitation of any of these vulnerabilities may allow a remote attacker to cause a denial-of-service condition.<\/p>\n\n<p>Versions affected:<br \/>\nBIND versions 9.4.0 to 9.6-ESV-R11-W1, 9.8.5 to 9.8.8, 9.9.3 to 9.9.9-P4, 9.9.8-S1 to 9.9.8-S3, 9.9.9-S1 to 9.9.9-S6, 9.10.0 to 9.10.4-P4, and 9.11.0 to 9.11.0-P1<\/p>\n\n<p>CVE References: CVE-2016-9131, CVE-2016-9147, CVE-2016-9444, CVE-2016-9778<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01439\/0\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01439\/0<\/font><\/a> \u00a0\u00a0\u00a0<br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01440\/0\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01440\/0<\/font><\/a>\u00a0\u00a0\u00a0\u00a0<br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01441\/0\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01441\/0<\/font><\/a>\u00a0\u00a0\u00a0\u00a0<br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01442\/0\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01442\/0<\/font><\/a> \u00a0\u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fix-released-bind-1","alert_type":null,"serial_number":"AV17-006","subject":null,"moderation_state":"archived","external_url":null},{"nid":882,"title":"Oracle Critical Patch update Advisory \u2013 January 2017","uuid":"fcd1159e-a1c8-429d-bc1f-5174aca9c6a9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-06-29T13:32:30Z","summary":null,"body":["<article data-history-node-id=\"882\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-january-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-007<br \/>\nDate: 19 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following critical patch updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update (CPU) which addresses 270 new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Oracle Database Server, version(s) 11.2.0.4, 12.1.0.2<\/li>\n\t<li>Oracle Secure Backup, version(s) prior to 12.1.0.3<\/li>\n\t<li>Spatial, version(s) prior to 1.2<\/li>\n\t<li>Oracle Fusion Middleware, version(s) 11.1.1.7, 11.1.1.9, 11.1.2.3, 11.1.2.4, 12.1.3.0, 12.2.1.0, 12.2.1.1<\/li>\n\t<li>Oracle GlassFish Server, version(s) 2.1.1, 3.0.1, 3.1.2<\/li>\n\t<li>Oracle JDeveloper, version(s) 11.1.1.7.0, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Outside In Technology, version(s) 8.5.2, 8.5.3<\/li>\n\t<li>Oracle Tuxedo, version(s) 12.1.1<\/li>\n\t<li>Oracle WebLogic Server, version(s) 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1<\/li>\n\t<li>Application Testing Suite, version(s) 12.4.0.2, 12.5.0.2, 12.5.0.3<\/li>\n\t<li>Enterprise Manager Base Platform, version(s) 12.1.0.5, 13.1, 13.2<\/li>\n\t<li>Enterprise Manager Ops Center, version(s) 12.1.4, 12.2.2, 12.3.2<\/li>\n\t<li>Oracle E-Business Suite, version(s) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6<\/li>\n\t<li>Oracle Transportation Management, version(s) 6.1, 6.2<\/li>\n\t<li>PeolpeSoft Enterprise HCM ePerformance, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, version(s) 8.54, 8.55<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version(s) 9.2<\/li>\n\t<li>Siebel Applications, version(s) 16.1<\/li>\n\t<li>Oracle Commerce Platform, version(s) 10.0.3.5, 10.2.0.5, 11.2.0.2<\/li>\n\t<li>Oracle Fusion Applications, version(s) 11.1.2 through 11.1.9<\/li>\n\t<li>Oracle Communications Indexing and Search Service, version(s) prior to 1.0.5.28.0<\/li>\n\t<li>Oracle Communications Network Charging and Control, version(s) 4.4.1.5, 5.0.0.1, 5.0.0.2, 5.0.1.0, 5.0.2.0<\/li>\n\t<li>Oracle Communications Network Intelligence, version(s) 7.3.0.0<\/li>\n\t<li>Oracle FLEXCUBE Core Banking, version(s) 5.1.0, 5.2.0, 11.5.0<\/li>\n\t<li>Oracle FLEXCUBE Direct Banking, version(s) 12.0.0, 12.0.1, 12.0.2, 12.0.3<\/li>\n\t<li>Oracle FLEXCUBE Enterprise Limits and Collateral Management, version(s) 12.0.0, 12.0.2<\/li>\n\t<li>Oracle FLEXCUBE Investor Servicing, version(s) 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0<\/li>\n\t<li>Oracle FLEXCUBE Private Banking, version(s) 2.0.1, 2.2.0, 12.0.1<\/li>\n\t<li>Oracle FLEXCUBE Universal Banking, version(s) 11.3.0, 11.4.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0<\/li>\n\t<li>MICROS Lucas, version(s) 2.9.1, 2.9.2, 2.9.3, 2.9.4, 2.9.5<\/li>\n\t<li>Oracle Retail Allocation, version(s) 12.0, 13.0, 13.1, 13.2, 13.3, 14.0, 14.1<\/li>\n\t<li>Oracle Retail Assortment Planning, version(s) 14.1, 15.0<\/li>\n\t<li>Oracle Retail Order Broker, version(s) 4.1, 5.1, 5.2, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Predictive Application Server, version(s) 13.1, 13.2, 13.3, 13.4, 14.0, 14.1, 15.0<\/li>\n\t<li>Oracle Retail Price Management, version(s) 13.1, 13.2, 14.0, 14.1<\/li>\n\t<li>Primavera P6 Enterprise Project Portfolio Management, version(s) 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, 16.2<\/li>\n\t<li>Oracle Java SE, version(s) 6u131, 7u121, 8u112<\/li>\n\t<li>Oracle Java SE Embedded, version(s) 8u111<\/li>\n\t<li>Oracle JRockit, version(s) R28.3.12<\/li>\n\t<li>Oracle VM Server for Sparc, version(s) 3.2, 3.4<\/li>\n\t<li>Solaris, version(s) 11.3<\/li>\n\t<li>Oracle VM VirtualBox, version(s) prior to 5.0.32, prior to 5.1.14<\/li>\n\t<li>MySQL Cluster, version(s) 7.2.26 and prior, 7.3.14 and prior, 7.4.12 and prior<\/li>\n\t<li>MySQL Enterprise Monitor, version(s) 3.1.3.7856 and prior, 3.1.4.7895 and prior, 3.1.5.7958 and prior, 3.2.1.1049 and prior, 3.2.4.1102 and prior, 3.3.0.1098 and prior<\/li>\n\t<li>MySQL Server, version(s) 5.5.53 and prior, 5.6.34 and prior, 5.7.16 and prior<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2015-0250, CVE-2015-1791, CVE-2015-3237, CVE-2015-3253, CVE-2015-5505, CVE-2015-7501,<br \/>\nCVE-2015-7940, CVE-2016-6304, CVE-2016-0635, CVE-2016-0714, CVE-2016-0734, CVE-2016-1182,<br \/>\nCVE-2016-1903, CVE-2016-2183, CVE-2016-5000, CVE-2016-5019, CVE-2016-5509, CVE-2016-5528,<br \/>\nCVE-2016-5541, CVE-2016-5545, CVE-2016-5546, CVE-2016-5547, CVE-2016-5548, CVE-2016-5549,<br \/>\nCVE-2016-5552, CVE-2016-5590, CVE-2016-5614, CVE-2016-5623, CVE-2016-6303, CVE-2016-6304,<br \/>\nCVE-2016-7052, CVE-2016-8282, CVE-2016-8297, CVE-2016-8298, CVE-2016-8299, CVE-2016-8300,<br \/>\nCVE-2016-8301, CVE-2016-8302, CVE-2016-8303, CVE-2016-8304, CVE-2016-8305, CVE-2016-8306,<br \/>\nCVE-2016-8307, CVE-2016-8308, CVE-2016-8309, CVE-2016-8310, CVE-2016-8311, CVE-2016-8312,<br \/>\nCVE-2016-8313, CVE-2016-8314, CVE-2016-8315, CVE-2016-8316, CVE-2016-8317, CVE-2016-8318,<br \/>\nCVE-2016-8319, CVE-2016-8320, CVE-2016-8322, CVE-2016-8323, CVE-2016-8324, CVE-2016-8325,<br \/>\nCVE-2016-8327, CVE-2016-8328, CVE-2016-8329, CVE-2016-8330, CVE-2017-3231, CVE-2017-3235,<br \/>\nCVE-2017-3236, CVE-2017-3238, CVE-2017-3239, CVE-2017-3240, CVE-2017-3241, CVE-2017-3242,<br \/>\nCVE-2017-3243, CVE-2017-3244, CVE-2017-3245, CVE-2017-3246, CVE-2017-3247, CVE-2017-3248,<br \/>\nCVE-2017-3249, CVE-2017-3250, CVE-2017-3251, CVE-2017-3252, CVE-2017-3253, CVE-2017-3255,<br \/>\nCVE-2017-3256, CVE-2017-3257, CVE-2017-3258, CVE-2017-3259, CVE-2017-3260, CVE-2017-3261,<br \/>\nCVE-2017-3262, CVE-2017-3263, CVE-2017-3264, CVE-2017-3265, CVE-2017-3266, CVE-2017-3267,<br \/>\nCVE-2017-3268, CVE-2017-3269, CVE-2017-3270, CVE-2017-3271, CVE-2017-3272, CVE-2017-3273,<br \/>\nCVE-2017-3274, CVE-2017-3275, CVE-2017-3276, CVE-2017-3277, CVE-2017-3278, CVE-2017-3279,<br \/>\nCVE-2017-3280, CVE-2017-3281, CVE-2017-3282, CVE-2017-3283, CVE-2017-3284, CVE-2017-3285,<br \/>\nCVE-2017-3286, CVE-2017-3287, CVE-2017-3289, CVE-2017-3290, CVE-2017-3291, CVE-2017-3292,<br \/>\nCVE-2017-3293, CVE-2017-3294, CVE-2017-3295, CVE-2017-3296, CVE-2017-3297, CVE-2017-3298,<br \/>\nCVE-2017-3299, CVE-2017-3300, CVE-2017-3301, CVE-2017-3303, CVE-2017-3310, CVE-2017-3311,<br \/>\nCVE-2017-3312, CVE-2017-3313, CVE-2017-3314, CVE-2017-3315, CVE-2017-3316, CVE-2017-3317,<br \/>\nCVE-2017-3318, CVE-2017-3319, CVE-2017-3320, CVE-2017-3321, CVE-2017-3322, CVE-2017-3323,<br \/>\nCVE-2017-3324, CVE-2017-3325, CVE-2017-3326, CVE-2017-3327, CVE-2017-3328, CVE-2017-3330,<br \/>\nCVE-2017-3332, CVE-2017-3333, CVE-2017-3359, CVE-2017-3361, CVE-2017-3362, CVE-2017-3368,<br \/>\nCVE-2017-3369, CVE-2017-3372, CVE-2017-3373, CVE-2017-3415, CVE-2017-3418, CVE-2017-3421,<br \/>\nCVE-2017-3440, CVE-2017-3443<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujan2017-2881727.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujan2017-2881727.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-january-2017","alert_type":396,"serial_number":"AV17-007","subject":null,"moderation_state":"archived","external_url":null},{"nid":1050,"title":"security update for mGuard Software","uuid":"c1bd1305-5e46-4675-9705-a6cca003f81b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-06-29T13:39:44Z","summary":null,"body":["<article data-history-node-id=\"1050\" about=\"\/en\/alerts-advisories\/security-update-mguard-software\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-008<br \/>\nDate: 19 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently discovered vulnerability in Phoenix Contact\u2019s mGuard software.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The most recent software update provided by Phoenix Contact for its mGuard product, changes the password to factory default during installation. This vulnerability allows for low skill level remote exploitation.<\/p>\n\n<p>CVE Reference: CVE-2017-5159<\/p>\n\n<p>Versions affected:<\/p>\n\n<p>Only devices that have been updated to Version 8.4.0 are affected.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor-released update to the affected application accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-017-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-017-01<\/font><\/a><br \/><a href=\"https:\/\/www.phoenixcontact.com\/online\/portal\/pc\"><font color=\"#0066cc\">https:\/\/www.phoenixcontact.com\/online\/portal\/pc<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-mguard-software","alert_type":396,"serial_number":"AV17-008","subject":null,"moderation_state":"archived","external_url":null},{"nid":1172,"title":"Software Compromised with Backdoor Trojan","uuid":"45646a4b-e60c-46d2-9d03-fe8a29ef5696","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:48Z","date_created":"2018-06-29T13:46:57Z","summary":null,"body":["<article data-history-node-id=\"1172\" about=\"\/en\/alerts-advisories\/software-compromised-backdoor-trojan-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-009<br \/>\nDate: 17 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed compromised software update by NetSarang.\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has received a report of a software developer (NetSarang) which was compromised, which led to the embedding of malicious code (ShadowPad backdoor trojan) in some of their distributed software packages.<\/p>\n\n<p>The affected software was distributed by NetSarang through their website and in-application update utilities between the dates of 18 July to 4 August 2017.<\/p>\n\n<p>The identified malicious software from the developer (NetSarang) are identified below.\u00a0 File compilation dates for the install packages are all 17 July 2017.<\/p>\n\n<p>- Xmanager Enterprise 5 Build 1232<br \/>\n- Xmanager 5 Build 1045<br \/>\n- Xshell 5 Build 1322<br \/>\n- Xftp 5 Build 1218<br \/>\n- Xlpd 5 Build 1220<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<p>\u2022 Hosts with confirmed installations of compromised versions of the software should be removed from the network for forensic analysis. If re-imaging is to be performed on a compromised host, it is important that the reinstallation fully removes all digital artifacts, including disk partitions and the master boot record.<\/p>\n\n<p>\u2022 Collect relevant logs pertaining to the connection attempts of the host(s) involved.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.netsarang.com\/news\/security_exploit_in_july_18_2017_build.html\" target=\"_blank\"><font color=\"#0066cc\">http:\/\/www.netsarang.com\/news\/security_exploit_in_july_18_2017_build.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/software-compromised-backdoor-trojan-0","alert_type":396,"serial_number":"AV17-009","subject":null,"moderation_state":"archived","external_url":null},{"nid":776,"title":"Multiple Apple security updates","uuid":"8a3c89c6-fae4-407b-9ff4-84cf5dbad39d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-29T13:57:42Z","summary":null,"body":["<article data-history-node-id=\"776\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-010<br \/>\nDate: January 24, 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iTunes, Safari, iCloud, macOS Sierra, iOS, tvOS and watchOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<ul><li>HT207481 - iCloud for Windows 6.1.1<\/li>\n\t<li>HT207482 - iOS 10.2.1<\/li>\n\t<li>HT207483 - macOS Sierra 10.12.3<\/li>\n\t<li>HT207484 - Safari 10.0.3<\/li>\n\t<li>HT207485 - tvOS 10.1.1<\/li>\n\t<li>HT207486 - iTunes 12.5.5 for Windows<\/li>\n\t<li>HT207487 - watchOS 3.1.3<\/li>\n<\/ul><p>This update addresses multiple vulnerabilities on the systems listed above.<\/p>\n\n<p>CVE References: \u00a0CVE-2016-1248,CVE-2016-4688,CVE-2016-4691,CVE-2016-4693,CVE-2016-7588,CVE-2016-7589,CVE-2016-7591,CVE-2016-7594,CVE-2016-7595,CVE-2016-7606,CVE-2016-7607,CVE-2016-7612,CVE-2016-7615,CVE-2016-7616,CVE-2016-7619,CVE-2016-7621,CVE-2016-7626,CVE-2016-7627,CVE-2016-7636,CVE-2016-7637,CVE-2016-7644,CVE-2016-7651,CVE-2016-7657,CVE-2016-7658,CVE-2016-7659,CVE-2016-7660,CVE-2016-7662,CVE-2016-7663,CVE-2016-8670,CVE-2016-8687,CVE-2016-9933,CVE-2016-9934,CVE-2017-2350,CVE-2017-2351,CVE-2017-2352,CVE-2017-2353,CVE-2017-2354,CVE-2017-2355,CVE-2017-2356,CVE-2017-2357,CVE-2017-2358,CVE-2017-2359,CVE-2017-2360,CVE-2017-2361,CVE-2017-2362,CVE-2017-2363,CVE-2017-2364,CVE-2017-2365,CVE-2017-2366,CVE-2017-2368,CVE-2017-2369,CVE-2017-2370,CVE-2017-2371,CVE-2017-2373<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms referred to in Apple Support Article HT207481, HT207482, HT207483, HT207484, HT207485, HT207486 and HT207487.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT207481\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207481<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT207482\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207482<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT207483\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207483<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT207484\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207484<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT207485\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207485<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT207486\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207486<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT207487\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207487<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-8","alert_type":396,"serial_number":"AV17-010","subject":null,"moderation_state":"archived","external_url":null},{"nid":1267,"title":"Cisco Releases security updates","uuid":"2b6884b8-d1e5-4f5e-805d-aa0db5a63575","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-06-29T14:04:47Z","summary":null,"body":["<article data-history-node-id=\"1267\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-011<br \/>\nDate: 25 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in the following products.<\/p>\n\n<ul><li>Cisco Hybrid Meeting Server Web Interface Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco IOS and Cisco IOx Software Information Disclosure Vulnerability<\/li>\n\t<li>Cisco IOS for Catalyst 2960X and 3750X Switches Denial of Service Vulnerability<\/li>\n\t<li>Cisco Mobility Express 2800 and 3800 802.11 Denial of Service Vulnerability<\/li>\n\t<li>Cisco Mobility Express 2800 and 3800 Denial of Service Vulnerability<\/li>\n\t<li>Cisco NetFlow Generation Appliance Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Nexus 5000, 6000, and 7000 Series Switches Software IS-IS Packet Processing Denial of Service Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco WebEx Browser Extension Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco WebEx Meeting Center Site Redirection Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Arbitrary Password Change Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Command Bypass Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Information Disclosure Vulnerability<\/li>\n<\/ul><p>CVE References:<br \/>\nCritical Impact CVE: CVE-2017-3823<br \/>\nMedium Impact CVEs: CVE-2016-9218, CVE-2016-9220, CVE-2016-9221, CVE-2016-9222, CVE-2017-3794, CVE-2017-3795, CVE-2017-3796, CVE-2017-3797, CVE-2017-3798, CVE-2017-3799, CVE-2017-3803, CVE-2017-3804, CVE-2017-3805<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-hms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-hms<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-ios\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-ios<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-catalyst\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-catalyst<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-cme1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-cme1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-cme2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-cme2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-nga\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-nga<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-nexus\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-nexus<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-cucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-cucm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170124-webex\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170124-webex<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms4<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170118-wms3<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-10","alert_type":396,"serial_number":"AV17-011","subject":null,"moderation_state":"archived","external_url":null},{"nid":1105,"title":"security update Available for the Adobe Acrobat extension for Chrome","uuid":"91756fa2-6dc6-4980-a176-7abc3c6f6ce3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-29T14:11:49Z","summary":null,"body":["<article data-history-node-id=\"1105\" about=\"\/en\/alerts-advisories\/security-update-available-adobe-acrobat-extension-chrome\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-012<br \/>\nDate: 25 January 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Adobe Security update for the Adobe Acrobat extension for Chrome.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletin to address a cross-site scripting vulnerability in the Adobe Acrobat extension for Chrome.<\/p>\n\n<p>APSB17-03 - Security Update Available for the Adobe Acrobat extension for Chrome - 15.1.0.3 and earlier versions.<br \/><br \/>\nCVE References:\u00a0 CVE-2017-2929<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-03.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-03.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-available-adobe-acrobat-extension-chrome","alert_type":396,"serial_number":"AV17-012","subject":null,"moderation_state":"archived","external_url":null},{"nid":940,"title":"Mozilla Releases security updates","uuid":"b7aa23b0-7e55-4d4c-9a5b-95660a5201f8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:45Z","date_created":"2018-06-29T14:17:06Z","summary":null,"body":["<article data-history-node-id=\"940\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-013<br \/>\nDate: 25 January 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 24 vulnerabilities in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 51<br \/>\nESR versions prior to 45.7<\/p>\n\n<p>CVE References: CVE-2017-5373, CVE-2017-5374, CVE-2017-5375, CVE-2017-5376, CVE-2017-5377, CVE-2017-5378, CVE-2017-5379, CVE-2017-5380, CVE-2017-5381, CVE-2017-5382, CVE-2017-5383, CVE-2017-5384, CVE-2017-5385, CVE-2017-5386, CVE-2017-5387, CVE-2017-5388, CVE-2017-5389, CVE-2017-5390, CVE-2017-5391, CVE-2017-5392, CVE-2017-5393, CVE-2017-5394, CVE-2017-5395,<br \/>\nCVE-2017-5396<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-01\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-01\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-02\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-02\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-8","alert_type":396,"serial_number":"AV17-013","subject":null,"moderation_state":"archived","external_url":null},{"nid":1192,"title":"Google Releases security update for Chrome","uuid":"1a758457-1cbc-47f0-b7c2-dc8b8eb1eddd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:09Z","date_created":"2018-06-29T14:23:44Z","summary":null,"body":["<article data-history-node-id=\"1192\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-17\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-014<br \/>\nDate: 26 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated 56.0.2924.76 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2017-5013, CVE-2017-5015, CVE-2017-5022, CVE-2017-5024, CVE-2017-5025, CVE-2017-5014, CVE-2017-5012, CVE-2017-5009, CVE-2017-5023, CVE-2017-5026, CVE-2017-5016, CVE-2017-5011, CVE-2017-5017, CVE-2017-5007, CVE-2017-5006, CVE-2017-5008, CVE-2017-5010, CVE-2017-5018, CVE-2017-5020, CVE-2017-5021, CVE-2017-5019<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/01\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/01\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-17","alert_type":396,"serial_number":"AV17-014","subject":null,"moderation_state":"archived","external_url":null},{"nid":816,"title":"Mozilla ThunderBird security update","uuid":"25fd1828-f0b8-4b2e-a4af-c34f64543706","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-06-29T15:12:34Z","summary":null,"body":["<article data-history-node-id=\"816\" about=\"\/en\/alerts-advisories\/mozilla-thunderbird-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-015<br \/>\nDate: 27 January 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Thunderbird for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 8 vulnerabilities in Thunderbird. The severity of these issues ranges from moderate to critical.<\/p>\n\n<p>Version affected:<br \/>\nThunderbird version prior to 45.7<\/p>\n\n<p>CVE References: CVE-2017-5373, CVE-2017-5375, CVE-2017-5376, CVE-2017-5378, CVE-2017-5380, CVE-2017-5383, CVE-2017-5390, CVE-2017-5396<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-03\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-03\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-thunderbird-security-update-0","alert_type":396,"serial_number":"AV17-015","subject":null,"moderation_state":"archived","external_url":null},{"nid":1295,"title":"WordPress security update","uuid":"603092ce-9803-42f3-b675-99f50a9f73f5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:52Z","date_created":"2018-06-29T15:24:21Z","summary":null,"body":["<article data-history-node-id=\"1295\" about=\"\/en\/alerts-advisories\/wordpress-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-016<br \/>\nDate: 27 January 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.7.2 that contains security fixes to address multiple vulnerabilities including SQL injection and XSS.<\/p>\n\n<p>Versions affected: WordPress 4.7.1 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2017\/01\/wordpress-4-7-2-security-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2017\/01\/wordpress-4-7-2-security-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update","alert_type":396,"serial_number":"AV17-016","subject":null,"moderation_state":"archived","external_url":null},{"nid":964,"title":"Cisco Releases security updates","uuid":"6a43555f-590e-4520-8c88-2c7c0ec35f42","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-06-29T15:30:06Z","summary":null,"body":["<article data-history-node-id=\"964\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-017<br \/>\nDate: 01 February 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in the following products.<br \/><br \/>\nCritical:<\/p>\n\n<ul><li>Cisco Prime Home Authentication Bypass Vulnerability<\/li>\n<\/ul><p>Medium:<\/p>\n\n<ul><li>Cisco Industrial Ethernet 2000 Series Switches CIP Denial of Service Vulnerability<\/li>\n\t<li>Cisco Prime Service Catalog URL Redirect Attack Vulnerability<\/li>\n\t<li>Cisco Firepower Device Manager Arbitrary Audit Log Entry Vulnerability\u00a0<\/li>\n\t<li>Cisco Firepower URL Bypass Vulnerability<\/li>\n\t<li>Cisco Firepower 4100 Series NGFW and Firepower 9300 Security Appliance Command Shell Injection Vulnerability<\/li>\n\t<li>Cisco Firepower Management Center Incomplete Rule Set Vulnerability<\/li>\n\t<li>Cisco Email Security Appliance Malformed MIME Header Filtering Bypass Vulnerability<\/li>\n\t<li>Cisco cBR Series Converged Broadband Routers List Headers Denial of Service Vulnerability<\/li>\n\t<li>Cisco ASR 1000 Series Aggregation Services Routers SNMP High CPU Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References:<br \/>\nCritical Impact CVE: CVE-2017-3791<\/p>\n\n<p>Medium Impact CVE: CVE-2017-3806, CVE-2017-3809, CVE-2017-3810, CVE-2017-3812, CVE-2017-3814, CVE-2017-3818, CVE-2017-3820, CVE-2017-3822, CVE-2017-3824<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-psc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-psc1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-psc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-psc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-prime-home\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-prime-home<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fpw2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fpw2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fpw1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fpw1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fpw\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fpw<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fmc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-fmc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-esa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-esa1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-cbr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-cbr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-asrsnmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170201-asrsnmp<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-11","alert_type":396,"serial_number":"AV17-017","subject":null,"moderation_state":"archived","external_url":null},{"nid":1333,"title":"Android security bulletin \u2013 February 2017","uuid":"d10247eb-4cdd-4675-becf-6a38ba35999c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:46Z","date_created":"2018-06-29T15:35:49Z","summary":null,"body":["<article data-history-node-id=\"1333\" about=\"\/en\/alerts-advisories\/android-security-bulletin-february-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-018<br \/>\nDate: 07 February 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for February 2017.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for 35 vulnerabilities (8 Critical, 18 High, and 9 Moderate). The vulnerabilities that are regarded as Critical could possibly be exploited through remote code execution on affected devices using multiple methods such as email, web browsing, and MMS when processing media files.<\/p>\n\n<p>CVE References: CVE-2016-5552, CVE-2016-8414, CVE-2016-8418, CVE-2016-8480, CVE-2016-8481, CVE-2014-9914, CVE-2016-10044, CVE-2017-0405, CVE-2017-0406, CVE-2017-0407, CVE-2017-0408, CVE-2017-0409, CVE-2017-0410, CVE-2017-0411, CVE-2017-0412, CVE-2017-0413, CVE-2017-0414, CVE-2017-0415, CVE-2017-0416, CVE-2017-0417, CVE-2017-0418, CVE-2017-0419, CVE-2017-0420, CVE-2017-0421, CVE-2017-0422, CVE-2017-0423, CVE-2017-0424, CVE-2017-0425, CVE-2017-0426, CVE-2017-0427, CVE-2017-0428, CVE-2017-0429, CVE-2017-0430, CVE-2017-0431, CVE-2017-0432, CVE-2017-0433, CVE-2017-0434, CVE-2017-0435, CVE-2017-0436, CVE-2017-0437, CVE-2017-0438, CVE-2017-0439CVE-2017-0440, CVE-2017-0441, CVE-2017-0442, CVE-2017-0443, CVE-2017-0444, CVE-2017-0445, CVE-2017-0446, CVE-2017-0447, CVE-2017-0448, CVE-2017-0449, CVE-2017-0450, CVE-2017-0451.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>Android Security Bulletin:<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2017-02-01.html\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2017-02-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-february-2017","alert_type":396,"serial_number":"AV17-018","subject":null,"moderation_state":"archived","external_url":null},{"nid":1021,"title":"Security fixes released for BIND","uuid":"a0c4d52b-2089-4ed7-91e1-f8497a5e722e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-06-29T15:41:57Z","summary":null,"body":["<article data-history-node-id=\"1021\" about=\"\/en\/alerts-advisories\/security-fixes-released-bind-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-019<br \/>\nDate: 10 February 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released updates that address three vulnerabilities in BIND. Exploitation of these vulnerabilities may allow a remote attacker to cause inconsistent state of query processing.<\/p>\n\n<p>Version Affected: 9.8.8, 9.9.3-S1 -&gt; 9.9.9-S7, 9.9.3 -&gt; 9.9.9-P5, 9.9.10b1, 9.10.0 -&gt; 9.10.4-P5, 9.10.5b1, 9.11.0 -&gt; 9.11.0-P2, 9.11.1b1<\/p>\n\n<p>CVE References: CVE-2017-3135<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01453\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01453<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-released-bind-2","alert_type":396,"serial_number":"AV17-019","subject":null,"moderation_state":"archived","external_url":null},{"nid":1134,"title":"F5 security advisory for BIG-IP","uuid":"66c0ff68-bd36-4791-94ac-dd065cc42628","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-06-29T15:48:44Z","summary":null,"body":["<article data-history-node-id=\"1134\" about=\"\/en\/alerts-advisories\/f5-security-advisory-big-ip-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-020<br \/>\nDate: 10 February 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Security Advisory released by F5 for its BIG-IP virtual server series of products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>F5 has released an update to address a vulnerability in its BIG-IP virtual server series of products. Exploitation of this vulnerability may allow a remote unauthenticated attacker to obtain SSL session IDs and\/or other potentially sensitive data.<\/p>\n\n<p>Versions affected:<br \/>\nBIG-IP virtual server products versions 11.4.0-11.6.1 and 12.0.0-12.1.2<\/p>\n\n<p>CVE Reference: CVE-2016-9244<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K05121675\"><font color=\"#0066cc\">https:\/\/support.f5.com\/csp\/article\/K05121675<\/font><\/a> \u00a0\u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-big-ip-0","alert_type":396,"serial_number":"AV17-020","subject":null,"moderation_state":"archived","external_url":null},{"nid":1225,"title":"Mozilla Releases security update","uuid":"e49ccee6-3620-4a3e-a032-ef037c6ca060","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:31Z","date_created":"2018-06-29T15:56:20Z","summary":null,"body":["<article data-history-node-id=\"1225\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-021<br \/>\nDate: 14 February 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of a vulnerability in Mozilla Firefox for Android devices for which an update is now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla has released a security update for Firefox for Android devices which address an issue where the cache directory is world writable. The severity of this issue is considered to be critical.<\/p>\n\n<p>This vulnerability has been fixed in version 51.0.3 of Firefox.<\/p>\n\n<p>CVE References: CVE-2017-5397<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released update to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-04\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-04\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-update","alert_type":396,"serial_number":"AV17-021","subject":null,"moderation_state":"archived","external_url":null},{"nid":1307,"title":"Cisco Releases security updates","uuid":"1abba7a5-e6b8-49d3-ab4a-90203f1667a1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-06-29T16:02:07Z","summary":null,"body":["<article data-history-node-id=\"1307\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-022<br \/>\nDate: 14 February 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in the following products.<\/p>\n\n<ul><li>Cisco WebEx Browser Extension Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco AnyConnect Secure Mobility Client for Windows SBL Privileges Escalation Vulnerability<\/li>\n\t<li>Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability<\/li>\n\t<li>Vulnerability in GNU glibc Affecting Cisco Products: February 2016<\/li>\n\t<li>Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016<\/li>\n\t<li>Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January 2017<\/li>\n\t<li>OSPF LSA Manipulation Vulnerability in Multiple Cisco Products<\/li>\n<\/ul><p>CVE References :<br \/>\nCritical Impact CVE: CVE-2017-3823<br \/>\nHigh Impact CVE: CVE-2015-7547, CVE-2017-3807, CVE-2017-3813<br \/>\nMedium Impact CVE: CVE-2013-0149, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-7052, CVE-2017-3730, CVE-2017-3731, CVE-2017-3732<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20130801-lsaospf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20130801-lsaospf<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160218-glibc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160218-glibc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160927-openssl<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170124-webex\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170124-webex<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170130-openssl\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170130-openssl<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170208-asa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170208-asa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170208-anyconnect\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170208-anyconnect<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-12","alert_type":396,"serial_number":"AV17-022","subject":null,"moderation_state":"archived","external_url":null},{"nid":1092,"title":"Adobe security bulletins and Advisories","uuid":"1532fb14-bbe9-4eef-9a1f-efbc86c6a29d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:38Z","date_created":"2018-06-29T16:57:10Z","summary":null,"body":["<article data-history-node-id=\"1092\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-and-advisories-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-023<br \/>\nDate: 14 February 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Adobe Security updates for various products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released 3 Security Bulletins and advisories for Flash Player, Digital Editions and Campaign.<\/p>\n\n<p>CVE References: CVE-2017-2982,CVE-2017-2984, CVE-2017-2985, CVE-2017-2986, CVE-2017-2987, CVE-2017-2988, CVE-2017-2990, CVE-2017-2991, CVE-2017-2992, CVE-2017-2993, CVE-2017-2994, CVE-2017-2995, CVE-2017-2996, CVE-2017-2973, CVE-2017-2974, CVE-2017-2975, CVE-2017-2976, CVE-2017-2977, CVE-2017-2978, CVE-2017-2979, CVE-2017-2980, CVE-2017-2981, CVE-2017-2968, CVE-2017-2969<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected applications accordingly.<\/p>\n\n<p>References<\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-04.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-04.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-05.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-05.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb17-06.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb17-06.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-and-advisories-0","alert_type":396,"serial_number":"AV17-023","subject":null,"moderation_state":"archived","external_url":null},{"nid":843,"title":"OpenSSL Advisory - security update","uuid":"1aa27b54-a180-4aa2-b345-77da9a6e2e93","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-06-29T17:02:38Z","summary":null,"body":["<article data-history-node-id=\"843\" about=\"\/en\/alerts-advisories\/openssl-advisory-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-024<br \/>\nDate: 17 February 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the OpenSSL security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a vulnerability rated as \u201chigh\u201d in OpenSSL for which an update is available.<\/p>\n\n<p>Affected version:\u00a0 1.1.0<\/p>\n\n<p>CVE Reference: CVE-2017-3733<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<br \/>\nOpenSSL 1.1.0 users should upgrade to 1.1.0e<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20170216.txt\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/news\/secadv\/20170216.txt<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-security-update","alert_type":396,"serial_number":"AV17-024","subject":null,"moderation_state":"archived","external_url":null},{"nid":1052,"title":"Citrix security updates","uuid":"bdfd8868-caeb-4ba4-bab9-04071bb32fe5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-06-29T17:08:32Z","summary":null,"body":["<article data-history-node-id=\"1052\" about=\"\/en\/alerts-advisories\/citrix-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-025<br \/>\nDate: 23 February 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of the advisory is to bring attention to the recently released security updates for Citrix.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Citrix has released security updates to address two (2) High vulnerabilities that could allow the administrator of an HVM guest VM to compromise the host.<\/p>\n\n<p>Affected Version:<\/p>\n\n<ul><li>Citrix XenServer 6.0.2 Common Criteria<\/li>\n\t<li>Citrix XenServer 6.2 SP1<\/li>\n\t<li>Citrix XenServer 6.5 SP1<\/li>\n\t<li>Citrix XenServer 7.0<\/li>\n<\/ul><p>CVE Reference: CVE-2017-2615, CVE-2017-2620<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/support.citrix.com\/article\/CTX220757\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX220757<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX220758\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX220758<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX220759\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX220759<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX220760\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX220760<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-updates-0","alert_type":396,"serial_number":"AV17-025","subject":null,"moderation_state":"archived","external_url":null},{"nid":778,"title":"WordPress security update","uuid":"6cbaa3ee-d8e2-46d7-bf79-83413c8d4672","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-06-29T17:19:07Z","summary":null,"body":["<article data-history-node-id=\"778\" about=\"\/en\/alerts-advisories\/wordpress-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-026<br \/>\nDate: 07 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.7.3 that contains security fixes to address multiple vulnerabilities including XSS and CSRF.<\/p>\n\n<p>Versions affected: WordPress 4.7.2 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2017\/03\/wordpress-4-7-3-security-and-maintenance-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2017\/03\/wordpress-4-7-3-security-and-maintenance-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-0","alert_type":396,"serial_number":"AV17-026","subject":null,"moderation_state":"archived","external_url":null},{"nid":1241,"title":"Mozilla Releases security updates","uuid":"469a68ed-232b-4445-878e-3a4e2443653a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:39Z","date_created":"2018-06-29T17:25:22Z","summary":null,"body":["<article data-history-node-id=\"1241\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-027<br \/>\nDate: 07 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 28 vulnerabilities in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 52<br \/>\nESR versions prior to 45.8<\/p>\n\n<p>CVE References: \u00a0<br \/>\nCVE-2017-5398, CVE-2017-5399, CVE-2017-5400, CVE-2017-5401, CVE-2017-5402, CVE-2017-5403,<br \/>\nCVE-2017-5404, CVE-2017-5405, CVE-2017-5406, CVE-2017-5407, CVE-2017-5408, CVE-2017-5409,<br \/>\nCVE-2017-5410, CVE-2017-5411, CVE-2017-5412, CVE-2017-5413, CVE-2017-5414, CVE-2017-5415,<br \/>\nCVE-2017-5416, CVE-2017-5417, CVE-2017-5418, CVE-2017-5419, CVE-2017-5420, CVE-2017-5421,<br \/>\nCVE-2017-5422, CVE-2017-5425, CVE-2017-5426, CVE-2017-5427<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-05\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-05\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-9","alert_type":396,"serial_number":"AV17-027","subject":null,"moderation_state":"archived","external_url":null},{"nid":1260,"title":"Security Fixes for Apache Struts Jakarta Multipart Parser","uuid":"5089e9fa-eecb-4a9b-ab6a-d427ed0f500f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-06-29T17:32:14Z","summary":null,"body":["<article data-history-node-id=\"1260\" about=\"\/en\/alerts-advisories\/security-fixes-apache-struts-jakarta-multipart-parser\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-028<br \/>\nDate: 10 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of Security Fixes for Apache Struts Jakarta Multipart Parser. A software upgrade and a work around are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Security fixes and a workaround to address a vulnerability in Apache Struts Jakarta Multipart Parser has been released. The vulnerability could allow an attacker to achieve a remote code execution. The severity of the issue is critical.<\/p>\n\n<p>Versions affected:<\/p>\n\n<ul><li>Struts 2.3.5 - Struts 2.3.31<\/li>\n\t<li>Struts 2.5 - Struts 2.5.10<\/li>\n<\/ul><h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates or work around to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>CVE: CVE-2017-5638<br \/><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-045\"><font color=\"#0066cc\">https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-045<\/font><\/a><\/p>\n\n<p>7 March 2017 - Struts 2.5.10.1 General Availability<br \/><a href=\"https:\/\/struts.apache.org\/announce.html\"><font color=\"#0066cc\">https:\/\/struts.apache.org\/announce.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-apache-struts-jakarta-multipart-parser","alert_type":396,"serial_number":"AV17-028","subject":null,"moderation_state":"archived","external_url":null},{"nid":1106,"title":"Google Releases security update for Chrome","uuid":"7a2a8df6-37b2-4e18-afe2-301cef3a428d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-06-29T17:43:13Z","summary":null,"body":["<article data-history-node-id=\"1106\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-18\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-029<br \/>\nDate: 13 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 57.0.2987.98 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2017-5030, CVE-2017-5031, CVE-2017-5032, CVE-2017-5029, CVE-2017-5034, CVE-2017-5035, CVE-2017-5036,\u00a0 CVE-2017-5037, CVE-2017-5039, CVE-2017-5040, CVE-2017-5041, CVE-2017-5033, CVE-2017-5042, CVE-2017-5038, CVE-2017-5043, CVE-2017-5044, CVE-2017-5045, CVE-2017-5046<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/03\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/03\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-18","alert_type":396,"serial_number":"AV17-029","subject":null,"moderation_state":"archived","external_url":null},{"nid":942,"title":"VMware security updates","uuid":"b2ef61c9-1828-4814-a874-60002c742a25","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:45Z","date_created":"2018-06-29T17:50:03Z","summary":null,"body":["<article data-history-node-id=\"942\" about=\"\/en\/alerts-advisories\/vmware-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-030<br \/>\nDate: 14 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware Horizon Desktop as-a-Service Platform 6.x and 7.x<\/li>\n\t<li>VMware vCenter Server 5.5, 6.0 and 6.5<\/li>\n\t<li>VMware vRealize Operations Manager 6.x<\/li>\n\t<li>VMware vRealize Hyperic Server 5.x<\/li>\n\t<li>VMware Workstation Pro \/ Player 12.x<\/li>\n\t<li>VMware Fusion Pro \/ Fusion 8.x<\/li>\n<\/ul><p>CVE References: CVE-2017-4901, CVE-2017-5638<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0004.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0004.html<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0005.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0005.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates","alert_type":396,"serial_number":"AV17-030","subject":null,"moderation_state":"archived","external_url":null},{"nid":818,"title":"Adobe security updates","uuid":"f75d9580-9cd0-46e1-8a9b-cc53608e4515","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:22Z","date_created":"2018-06-29T17:56:54Z","summary":null,"body":["<article data-history-node-id=\"818\" about=\"\/en\/alerts-advisories\/adobe-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-031<br \/>\nDate: 14 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<\/p>\n\n<p>APSB17-07 - Security updates available for Adobe Flash Player<br \/>\nAPSB17-08 - Security update available for Adobe Shockwave Player<\/p>\n\n<p>CVE References:\u00a0<br \/>\nCVE-2017-2983, CVE-2017-2997, CVE-2017-2998, CVE-2017-2999, CVE-2017-3000, CVE-2017-3001, CVE-2017-3002, CVE-2017-3003<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>APSB17-07: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-07.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-07.html<\/font><\/a><br \/>\nAPSB17-08: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/shockwave\/apsb17-08.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/shockwave\/apsb17-08.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates","alert_type":396,"serial_number":"AV17-031","subject":null,"moderation_state":"archived","external_url":null},{"nid":1297,"title":"Microsoft Critical security bulletins Summary \u2013 March 2017","uuid":"0f05b7e2-28a2-47dc-8a39-554c29f5be6e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:52Z","date_created":"2018-06-29T18:04:01Z","summary":null,"body":["<article data-history-node-id=\"1297\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-march-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-032<br \/>\nDate: 14 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for March 2017.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers 18 bulletins (7 Critical and 11 Important), which addresses multiple vulnerabilities in; Microsoft Internet Explorer, Microsoft Windows, Microsoft Edge, Microsoft Office, Microsoft Uniscribe, Microsoft Graphics Component, Microsoft Exchange Server, Active Directory, Microsoft XML Core Services, Adobe Flash Player.<\/p>\n\n<p>***Critical***<br \/>\nMS17-006 Cumulative Security Update for Internet Explorer (4013073)<br \/>\nMS17-007 Cumulative Security Update for Microsoft Edge (4013071)<br \/>\nMS17-008 Security Update for Windows Hyper-V (4013082)<br \/>\nMS17-009 Security Update for Microsoft Windows PDF Library (4010319)<br \/>\nMS17-010 Security Update for Microsoft Windows SMB Server (4013389)<br \/>\nMS17-013 Security Update for Microsoft Graphics Component (4013075)<br \/>\nMS17-023 Security Update for Adobe Flash Player (4014329)<\/p>\n\n<p>***Important***<br \/>\nMS17-011 Security Update for Microsoft Uniscribe (4013076)<br \/>\nMS17-012 Security Update for Microsoft Windows (4013078)<br \/>\nMS17-014 Security Update for Microsoft Office (4013241)<br \/>\nMS17-015 Security Update for Microsoft Exchange Server (4013242)<br \/>\nMS17-016 Security Update for Windows IIS (4013074)<br \/>\nMS17-017 Security Update for Windows Kernel (4013081)<br \/>\nMS17-018 Security Update for Windows Kernel-Mode Drivers (4013083)<br \/>\nMS17-019 Security Update for Active Directory Federation Services (4010320)<br \/>\nMS17-020 Security Update for Windows DVD Maker (3208223)<br \/>\nMS17-021 Security Update for Windows DirectShow (4010318)<br \/>\nMS17-022 Security Update for Microsoft XML Core Services (4010321)<\/p>\n\n<p>CVE References: CVE-2017-0001, CVE-2017-0005, CVE-2017-0006, CVE-2017-0007, CVE-2017-0008, CVE-2017-0009, CVE-2017-0010, CVE-2017-0011, CVE-2017-0012, CVE-2017-0014, CVE-2017-0015, CVE-2017-0016, CVE-2017-0017, CVE-2017-0019, CVE-2017-0020, CVE-2017-0021, CVE-2017-0022, CVE-2017-0023, CVE-2017-0024, CVE-2017-0025, CVE-2017-0026, CVE-2017-0027, CVE-2017-0029, CVE-2017-0030, CVE-2017-0031, CVE-2017-0032, CVE-2017-0033, CVE-2017-0034, CVE-2017-0035, CVE-2017-0037, CVE-2017-0038, CVE-2017-0039, CVE-2017-0042, CVE-2017-0043, CVE-2017-0045, CVE-2017-0047, CVE-2017-0050, CVE-2017-0051, CVE-2017-0052, CVE-2017-0053, CVE-2017-0055, CVE-2017-0056, CVE-2017-0057, CVE-2017-0060, CVE-2017-0061, CVE-2017-0062, CVE-2017-0063, CVE-2017-0065, CVE-2017-0066, CVE-2017-0067, CVE-2017-0068, CVE-2017-0069, CVE-2017-0070, CVE-2017-0071, CVE-2017-0072, CVE-2017-0073, CVE-2017-0074, CVE-2017-0075, CVE-2017-0076, CVE-2017-0078, CVE-2017-0079, CVE-2017-0080, CVE-2017-0081, CVE-2017-0082, CVE-2017-0083, CVE-2017-0084, CVE-2017-0085, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, CVE-2017-0090, CVE-2017-0091, CVE-2017-0092, CVE-2017-0094, CVE-2017-0095, CVE-2017-0096, CVE-2017-0097, CVE-2017-0098, CVE-2017-0099, CVE-2017-0100, CVE-2017-0101, CVE-2017-0102, CVE-2017-0103, CVE-2017-0104, CVE-2017-0105, CVE-2017-0107, CVE-2017-0108, CVE-2017-0109, CVE-2017-0110, CVE-2017-0111, CVE-2017-0112, CVE-2017-0113, CVE-2017-0114, CVE-2017-0115, CVE-2017-0116, CVE-2017-0117, CVE-2017-0118, CVE-2017-0119, CVE-2017-0120, CVE-2017-0121, CVE-2017-0122, CVE-2017-0123, CVE-2017-0124, CVE-2017-0125, CVE-2017-0126, CVE-2017-0127, CVE-2017-0128, CVE-2017-0129, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0135, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0140, CVE-2017-0141, CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148, CVE-2017-0150, CVE-2017-0151, CVE-2017-2997, CVE-2017-2998, CVE-2017-2999, CVE-2017-3000, CVE-2017-3001, CVE-2017-3002, CVE-2017-3003<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-006\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-006<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-007\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-007<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-008\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-008<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-009\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-009<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-010\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-010<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-011\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-011<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-012\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-012<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-013\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-013<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-014\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-014<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-015\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-015<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-016\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-016<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-017\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-017<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-018\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-018<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-019\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-019<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-020\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-020<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-021\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-021<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-022\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-022<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-023\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-023<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-march-2017","alert_type":396,"serial_number":"AV17-032","subject":null,"moderation_state":"archived","external_url":null},{"nid":958,"title":"Drupal security updates","uuid":"aef092c4-8197-4e26-bbc1-7ab89febaabd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-03T13:32:49Z","summary":null,"body":["<article data-history-node-id=\"958\" about=\"\/en\/alerts-advisories\/drupal-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-033<br \/>\nDate: 16 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Drupal security release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple security vulnerabilities. \u00a0Exploitation of these vulnerabilities may allow an attacker to perform arbitrary remote code execution.<\/p>\n\n<p>Affected Versions:<br \/>\nDrupal core 8.x versions prior to 8.2.7<\/p>\n\n<p>CVE References:\u00a0<\/p>\n\n<p>CVE-2017-6377, CVE-2017-6379, CVE-2017-6381<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.drupal.org\/SA-2017-001\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/SA-2017-001<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-updates-0","alert_type":396,"serial_number":"AV17-033","subject":null,"moderation_state":"archived","external_url":null},{"nid":1335,"title":"Cisco Releases security updates","uuid":"17d5705f-167f-4313-8771-11e12a2a9c1f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:46Z","date_created":"2018-07-03T13:45:36Z","summary":null,"body":["<article data-history-node-id=\"1335\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-034<br \/>\nDate: 16 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in the following products.<\/p>\n\n<ul><li>Apache Struts2 Jakarta Multipart Parser File Upload Code Execution Vulnerability Affecting Cisco Products<\/li>\n\t<li>Cisco Web Security Appliance URL Filtering Bypass Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server XML External Entity Vulnerability<\/li>\n\t<li>Cisco Meshed Wireless LAN Controller Impersonation Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Authentication Bypass Vulnerability<\/li>\n\t<li>Cisco UCS Director Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco TelePresence Server API Privilege Vulnerability<\/li>\n\t<li>Cisco Workload Automation and Tidal Enterprise Scheduler Client Manager Server Arbitrary File Read Vulnerability<\/li>\n\t<li>Cisco Prime Service Catalog Multiple Cross-Site Scripting Vulnerabilities<\/li>\n\t<li>Cisco Nexus 9000 Series Switches Remote Login Denial of Service Vulnerability<\/li>\n\t<li>Cisco Nexus 9000 Series Switches Telnet Login Denial of Service Vulnerability\u00a0<\/li>\n\t<li>Cisco Prime Optical for Service Providers RADIUS Secret Disclosure Vulnerability<\/li>\n\t<li>Cisco Prime Infrastructure API Credentials Management Vulnerability\u00a0<\/li>\n\t<li>Cisco Nexus 7000 Series Switches Access-Control Filtering Mechanisms Bypass Vulnerability<\/li>\n\t<li>Cisco StarOS SSH Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance BGP Bidirectional Forwarding Detection ACL Bypass Vulnerability<\/li>\n\t<li>Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability<\/li>\n<\/ul><p>CVE References:<br \/>\nCritical: CVE-2017-3831, CVE-2017-5638<br \/>\nHigh: CVE-2017-3846, CVE-2017-3854<br \/>\nMedium: \u00a0CVE-2017-3811, CVE-2017-3815, CVE-2017-3819, CVE-2017-3866, CVE-2017-3867, CVE-2017-3868, CVE-2017-3869, CVE-2017-3870, CVE-2017-3871, CVE-2017-3872, CVE-2017-3874, CVE-2017-3875, CVE-2017-3877, CVE-2017-3878, CVE-2017-3879, CVE-2017-3880<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170310-struts2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170310-struts2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-wsa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-wsa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-wms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-wms<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-wlc-mesh\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-wlc-mesh<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-webex\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-webex<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucs<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucm2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucm2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucm1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucm1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ucm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-tps\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-tps<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-tes\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-tes<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-psc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-psc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-nss1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-nss1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-nss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-nss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-cpo\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-cpo<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-cpi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-cpi<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-cns\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-cns<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-asr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-asr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-asa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-asa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ap1800\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ap1800<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-13","alert_type":null,"serial_number":"AV17-034","subject":null,"moderation_state":"archived","external_url":null},{"nid":1023,"title":"Mozilla Releases security updates","uuid":"fa2f6cca-9150-40e6-8fb4-2c6a2f79828a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-03T13:55:00Z","summary":null,"body":["<article data-history-node-id=\"1023\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-035<br \/>\nDate: 21 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to raise awareness of a vulnerability in Mozilla Firefox and Firefox ESR for which updates are now available.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address integer overflow vulnerability in Firefox and Firefox ESR. The severity of the issue is critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox: versions prior to 52.0.1<br \/>\nFirefox ESR: versions prior to 52.0.1<\/p>\n\n<p>CVE Reference:\u00a0 CVE-2017-5428<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-08\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-08\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-10","alert_type":396,"serial_number":"AV17-035","subject":null,"moderation_state":"archived","external_url":null},{"nid":1136,"title":"Moodle security updates","uuid":"3f21b6ea-7d4c-4b7a-a9ff-6a9f453623c3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-03T14:26:24Z","summary":null,"body":["<article data-history-node-id=\"1136\" about=\"\/en\/alerts-advisories\/moodle-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-036<br \/>\nDate: March 21 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Moodle security vulnerabilities.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Moodle has released the following support articles:<\/p>\n\n<p>MSA-17-0005 - SQL injection via user preferences<br \/>\nMSA-17-0007 - Global search displays user names for unauthenticated users<br \/>\nMSA-17-0008 - XSS in evidence of prior learning<br \/>\nMSA-17-0009 - XSS in attachments to evidence of prior learning<\/p>\n\n<p>Versions Affected: 3.2 to 3.2.1, 3.1 to 3.1.4, 3.0 to 3.0.8, 2.7.0 to 2.7.18 and other unsupported versions<\/p>\n\n<p>CVE References: CVE-2017-2641, CVE-2017-2643, CVE-2017-2644, CVE-2017-2645<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349419\"><font color=\"#0066cc\">https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349419<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349420\"><font color=\"#0066cc\">https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349420<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349421\"><font color=\"#0066cc\">https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349421<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349422\"><font color=\"#0066cc\">https:\/\/moodle.org\/mod\/forum\/discuss.php?d=349422<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moodle-security-updates","alert_type":396,"serial_number":"AV17-036","subject":null,"moderation_state":"archived","external_url":null},{"nid":1227,"title":"Network Time Protocol Daemon (ntpd) Security Notice","uuid":"7611a1f3-27b4-433b-adc4-17cce2487729","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:31Z","date_created":"2018-07-03T14:39:49Z","summary":null,"body":["<article data-history-node-id=\"1227\" about=\"\/en\/alerts-advisories\/network-time-protocol-daemon-ntpd-security-notice-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-037<br \/>\nDate: March 22 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a multiple NTP vulnerabilities security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The NTP project has released version ntp-4.2.8p10, which fixed 15 vulnerabilities and 15 bugs in their software.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/633847\"><font color=\"#0066cc\">http:\/\/www.kb.cert.org\/vuls\/id\/633847<\/font><\/a>\u00a0\u00a0<\/p>\n\n<p><a href=\"http:\/\/support.ntp.org\/bin\/view\/Main\/SecurityNotice#Recent_Vulnerabilities\"><font color=\"#0066cc\">http:\/\/support.ntp.org\/bin\/view\/Main\/SecurityNotice#Recent_Vulnerabilities<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/network-time-protocol-daemon-ntpd-security-notice-1","alert_type":396,"serial_number":"AV17-037","subject":null,"moderation_state":"archived","external_url":null},{"nid":1299,"title":"Cisco Releases security updates","uuid":"91789fba-23f0-4a54-8542-18251247a46d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-07-03T14:46:40Z","summary":null,"body":["<article data-history-node-id=\"1299\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-14\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-038<br \/>\nDate: 23 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco IOx Data in Motion Stack Overflow Vulnerability<\/li>\n\t<li>Apache Struts2 Jakarta Multipart Parser File Upload Code Execution Vulnerability Affecting Cisco Products<\/li>\n\t<li>Cisco IOS XE Software for Cisco ASR 920 Series Routers Zero Touch Provisioning Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS XE Software HTTP Command Injection Vulnerability<\/li>\n\t<li>Cisco IOS XE Software Web User Interface Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software Layer 2 Tunneling Protocol Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software DHCP Client Denial of Service Vulnerability<\/li>\n\t<li>Cisco Application-Hosting Framework Arbitrary File Creation Vulnerability<\/li>\n\t<li>Cisco Application-Hosting Framework Directory Traversal Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software IPv6 Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Registrar Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References:<br \/>\nCritical: CVE-2017-3853, CVE-2017-5638<br \/>\nHigh: CVE-2017-3849, CVE-2017-3850, CVE-2017-3851, CVE-2017-3852, CVE-2017-3856, CVE-2017-3857, CVE-2017-3858, CVE-2017-3859, CVE-2017-3864<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-iox\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-iox<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-ztp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-ztp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-xeci\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-xeci<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-webui\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-webui<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-l2tp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-l2tp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-dhcpc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-dhcpc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-caf2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-caf2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-caf1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170322-caf1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170310-struts2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170310-struts2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170320-aniipv6\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170320-aniipv6<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170320-ani\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170320-ani<\/font><\/a> \u00a0\u00a0\u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-14","alert_type":396,"serial_number":"AV17-038","subject":null,"moderation_state":"archived","external_url":null},{"nid":1084,"title":"Multiple Apple security updates","uuid":"d3b439ed-f830-495e-9f0b-2f4d58ff9811","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:38Z","date_created":"2018-07-03T14:55:52Z","summary":null,"body":["<article data-history-node-id=\"1084\" about=\"\/en\/alerts-advisories\/multiple-apple-security-updates-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-039<br \/>\nDate: 28 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iOS, macOS (Server, Sierra, El Capitan, Yosemite), Safari and more.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<ul><li>HT207595 - macOS 10.12 or later, iOS 10.0 or later<\/li>\n\t<li>HT207600 - Safari 10.1<\/li>\n\t<li>HT207601 - tvOS 10.2<\/li>\n\t<li>HT207602 - watchOS 3.2<\/li>\n\t<li>HT207604 - macOS Server 5.3<\/li>\n\t<li>HT207615 - macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite<\/li>\n\t<li>HT207617 - iOS 10.3<\/li>\n<\/ul><p>This update addresses multiple vulnerabilities on the systems listed above.<\/p>\n\n<p>CVE Reference: CVE-2007-6750, CVE-2016-0736, CVE-2016-0751, CVE-2016-2161, CVE-2016-3619, CVE-2016-5387, CVE-2016-5636, CVE-2016-7056, CVE-2016-7585, CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925, CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929, CVE-2016-7930, CVE-2016-7931, CVE-2016-7932, CVE-2016-7933, CVE-2016-7934, CVE-2016-7935, CVE-2016-7936, CVE-2016-7937, CVE-2016-7938, CVE-2016-7939, CVE-2016-7940, CVE-2016-7973, CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984, CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993, CVE-2016-8574, CVE-2016-8575, CVE-2016-8740, CVE-2016-8743, CVE-2016-9533, CVE-2016-9535, CVE-2016-9536, CVE-2016-9537, CVE-2016-9538, CVE-2016-9539, CVE-2016-9540, CVE-2016-9586, CVE-2016-9642, CVE-2016-9643, CVE-2016-9935, CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-10158, CVE-2016-10159, CVE-2016-10160, CVE-2016-10161, CVE-2017-2364, CVE-2017-2367, CVE-2017-2376, CVE-2017-2377, CVE-2017-2378, CVE-2017-2379, CVE-2017-2380, CVE-2017-2381, CVE-2017-2382, CVE-2017-2384, CVE-2017-2385, CVE-2017-2386, CVE-2017-2389, CVE-2017-2390, CVE-2017-2391, CVE-2017-2392, CVE-2017-2393, CVE-2017-2394, CVE-2017-2395, CVE-2017-2396, CVE-2017-2397, CVE-2017-2398, CVE-2017-2399, CVE-2017-2400, CVE-2017-2401, CVE-2017-2402, CVE-2017-2403, CVE-2017-2404, CVE-2017-2405, CVE-2017-2406, CVE-2017-2407, CVE-2017-2408, CVE-2017-2409, CVE-2017-2410, CVE-2017-2412, CVE-2017-2413, CVE-2017-2414, CVE-2017-2415, CVE-2017-2416, CVE-2017-2417, CVE-2017-2418, CVE-2017-2419, CVE-2017-2420, CVE-2017-2421, CVE-2017-2422, CVE-2017-2423, CVE-2017-2424, CVE-2017-2425, CVE-2017-2426, CVE-2017-2427, CVE-2017-2428, CVE-2017-2429, CVE-2017-2430, CVE-2017-2431, CVE-2017-2432, CVE-2017-2433, CVE-2017-2434, CVE-2017-2435, CVE-2017-2436, CVE-2017-2437, CVE-2017-2438, CVE-2017-2439, CVE-2017-2440, CVE-2017-2441, CVE-2017-2442, CVE-2017-2443, CVE-2017-2444, CVE-2017-2445, CVE-2017-2446, CVE-2017-2447, CVE-2017-2448, CVE-2017-2449, CVE-2017-2450, CVE-2017-2451, CVE-2017-2452, CVE-2017-2453, CVE-2017-2454, CVE-2017-2455, CVE-2017-2456, CVE-2017-2457, CVE-2017-2458, CVE-2017-2459, CVE-2017-2460, CVE-2017-2461, CVE-2017-2462, CVE-2017-2464, CVE-2017-2465, CVE-2017-2466, CVE-2017-2467, CVE-2017-2468, CVE-2017-2469, CVE-2017-2470, CVE-2017-2471, CVE-2017-2472, CVE-2017-2473, CVE-2017-2474, CVE-2017-2475, CVE-2017-2476, CVE-2017-2478, CVE-2017-2481, CVE-2017-2482, CVE-2017-2483, CVE-2017-2484, CVE-2017-2485, CVE-2017-2486, CVE-2017-2487, CVE-2017-5202, CVE-2017-5203, CVE-2017-5204, CVE-2017-5205, CVE-2017-5341, CVE-2017-5342, CVE-2017-5482, CVE-2017-5483, CVE-2017-5484, CVE-2017-5485, CVE-2017-5486, CVE-2017-6974<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT207595\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207595<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207600\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207600<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207601\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207601<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207602\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207602<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207604\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207604<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207615\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207615<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207617\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207617<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-apple-security-updates-9","alert_type":396,"serial_number":"AV17-039","subject":null,"moderation_state":"archived","external_url":null},{"nid":844,"title":"VMware security updates","uuid":"437599d7-8dda-477f-8c65-ee830c21fef2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-07-03T15:05:11Z","summary":null,"body":["<article data-history-node-id=\"844\" about=\"\/en\/alerts-advisories\/vmware-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-040<br \/>\nDate: March 29 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware ESXi (ESXi)\u00a0 Version 5.5, 6.0 U1, 6.0 U2, 6.0 U3, 6.5<\/li>\n\t<li>VMware Workstation Pro \/ Player (Workstation) Version 12.x<\/li>\n\t<li>VMware Fusion Pro, Fusion (Fusion) Version 8.x<\/li>\n<\/ul><p>CVE References: CVE-2017-4902, CVE-2017-4903, CVE-2017-4904, CVE-2017-4905<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0006.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0006.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-0","alert_type":396,"serial_number":"AV17-040","subject":null,"moderation_state":"archived","external_url":null},{"nid":1054,"title":"Google Releases security update for Chrome","uuid":"a7fa15a3-f434-4548-81f5-33adb057264f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-07-03T15:14:02Z","summary":null,"body":["<article data-history-node-id=\"1054\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-19\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-041<br \/>\nDate: 30 March 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated 57.0.2987.133 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2017-5052, CVE-2017-5053, CVE-2017-5054, CVE-2017-5055, CVE-2017-5056<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/03\/stable-channel-update-for-desktop_29.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/03\/stable-channel-update-for-desktop_29.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-19","alert_type":396,"serial_number":"AV17-041","subject":null,"moderation_state":"archived","external_url":null},{"nid":780,"title":"Cisco Releases security updates","uuid":"12838771-e7f0-43bb-b54a-d6a34cf6f868","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-07-03T15:21:41Z","summary":null,"body":["<article data-history-node-id=\"780\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-15\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-042<br \/>\nDate: 6 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms Shell Bypass Vulnerability<\/li>\n\t<li>Cisco Aironet 1830 Series and 1850 Series Access Points Mobility Express Default Credential Vulnerability<\/li>\n\t<li>Cisco ASR 903 and ASR 920 Series Devices IPv6 Packet Processing Denial of Service Vulnerability<\/li>\n\t<li>Cisco Firepower Detection Engine SSL Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS XE Software Startup Script Local Command Execution Vulnerability<\/li>\n\t<li>Cisco IOS XR Software Denial of Service Vulnerability<\/li>\n\t<li>Cisco Integrated Management Controller Redirection Vulnerability<\/li>\n\t<li>Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers Shell Bypass Vulnerability<\/li>\n\t<li>Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Web Interface Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Registered Envelope Service Open Redirect Vulnerability<\/li>\n\t<li>Cisco UCS Director Virtual Machine Information Disclosure Vulnerability<\/li>\n\t<li>Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance Debug Plug-in Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance local-mgmt CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager SQL Injection Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller IPv6 UDP Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller Management GUI Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller RADIUS Change of Authorization Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller 802.11 WME Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References:<\/p>\n\n<p>Critical: CVE-2017-3834<\/p>\n\n<p>High: CVE-2016-9194, CVE-2016-9219, CVE-2017-3832<\/p>\n\n<p>Medium:<br \/>\nCVE-2016-9195, CVE-2016-9196, CVE-2016-9197, CVE-2017-3817, CVE-2017-3884, CVE-2017-3885,<br \/>\nCVE-2017-3886, CVE-2017-3887, CVE-2017-3888, CVE-2017-3889, CVE-2017-6597, CVE-2017-6598,<br \/>\nCVE-2017-6599, CVE-2017-6600, CVE-2017-6601, CVE-2017-6602, CVE-2017-6603, CVE-2017-6604,<br \/>\nCVE-2017-6606\u00a0\u00a0<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-aironet\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-aironet<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ame\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ame<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-asr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-asr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cpi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cpi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cme\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cme<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cli1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cli1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cli2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cli2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cimc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cimc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cfpw\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cfpw<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cfpw1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-cfpw1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ios\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ios<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-iosxe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-iosxe<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-res\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-res<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucs1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucs1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucs-director\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucs-director<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucm1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-ucm1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170405-wlc3<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-15","alert_type":396,"serial_number":"AV17-042","subject":null,"moderation_state":"archived","external_url":null},{"nid":1243,"title":"Adobe security updates","uuid":"37ea9b10-fa3a-4fd3-84b6-c3e61a90a51f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:39Z","date_created":"2018-07-03T15:28:25Z","summary":null,"body":["<article data-history-node-id=\"1243\" about=\"\/en\/alerts-advisories\/adobe-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-043<br \/>\nDate: 11 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security updates for various Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<\/p>\n\n<p>APSB17-09 Security update available for Adobe Campaign<br \/>\nAPSB17-10 Security updates available for Adobe Flash Player<br \/>\nAPSB17-11 Security updates available for Adobe Acrobat and Reader<br \/>\nAPSB17-12 Security update available for Adobe Photoshop CC<br \/>\nAPSB17-13 Security update available for the Creative Cloud Desktop Application<\/p>\n\n<p>CVE References:\u00a0<\/p>\n\n<p>CVE-2017-2989, CVE-2017-3004, CVE-2017-3005, CVE-2017-3006, CVE-2017-3007, CVE-2017-3011, CVE-2017-3012, CVE-2017-3013, CVE-2017-3014, CVE-2017-3015, CVE- 2017-3017, CVE-2017-3018, CVE-2017-3019, CVE-2017-3020, CVE-2017-3021, CVE-2017-3022, CVE- 2017-3023, CVE-2017-3024, CVE-2017-3025, CVE-2017-3026, CVE-2017-3027, CVE-2017-3028, CVE- 2017-3029, CVE-2017-3030, CVE-2017-3031, CVE-2017-3032, CVE-2017-3033, CVE-2017-3034, CVE- 2017-3035, CVE-2017-3036, CVE-2017-3037, CVE-2017-3038, CVE-2017-3039, CVE-2017-3040, CVE- 2017-3041, CVE-2017-3042, CVE-2017-3043, CVE-2017-3044, CVE-2017-3045, CVE-2017-3046, CVE- 2017-3047, CVE-2017-3048, CVE-2017-3049, CVE-2017-3050, CVE-2017-3051, CVE-2017-3052, CVE- 2017-3053, CVE-2017-3054, CVE-2017-3055, CVE-2017-3056, CVE-2017-3057, CVE-2017-3058, CVE-2017-3059, CVE-2017-3060, CVE-2017-3061, CVE-2017-3062, CVE-2017-3063, CVE-2017-3064, CVE-2017-3065<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>APSB17-09: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb17-09.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb17-09.html<\/font><\/a><br \/>\nAPSB17-10: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-10.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-10.html<\/font><\/a><br \/>\nAPSB17-11: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-11.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-11.html<\/font><\/a><br \/>\nAPSB17-12: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb17-12.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb17-12.html<\/font><\/a><br \/>\nAPSB17-13: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb17-13.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb17-13.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates-0","alert_type":396,"serial_number":"AV17-043","subject":null,"moderation_state":"archived","external_url":null},{"nid":1262,"title":"Microsoft security updates","uuid":"aaa0bf89-1979-48c7-9fb4-b3faf67db622","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-07-03T15:36:00Z","summary":null,"body":["<article data-history-node-id=\"1262\" about=\"\/en\/alerts-advisories\/microsoft-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-044<br \/>\nDate: 12 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products (including Adobe Flash Player, Edge, Hyper-V, Internet Explorer, .NET Framework, Office, Silverlight, Visual Studio for Mac and Windows).<\/p>\n\n<p>CVE References: CVE-2013-6629, CVE-2017-0058, CVE-2017-0093, CVE-2017-0106, CVE-2017-0155, CVE-2017-0156, CVE-2017-0158, CVE-2017-0159, CVE-2017-0160, CVE-2017-0162, CVE-2017-0163, CVE-2017-0164, CVE-2017-0165, CVE-2017-0166, CVE-2017-0167, CVE-2017-0168, CVE-2017-0169, CVE-2017-0178, CVE-2017-0179, CVE-2017-0180, CVE-2017-0181, CVE-2017-0182, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, CVE-2017-0186, CVE-2017-0188, CVE-2017-0189, CVE-2017-0191, CVE-2017-0192, CVE-2017-0194, CVE-2017-0195, CVE-2017-0197, CVE-2017-0199, CVE-2017-0200, CVE-2017-0201, CVE-2017-0202, CVE-2017-0203, CVE-2017-0204, CVE-2017-0205, CVE-2017-0207, CVE-2017-0208, CVE-2017-0210, CVE-2017-0211<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/20170411\/security-update-deployment-information-april-11-2017\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/20170411\/security-update-deployment-information-april-11-2017<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/42b8fa28-9d09-e711-80d9-000d3a32fc99\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/42b8fa28-9d09-e711-80d9-000d3a32fc99<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates","alert_type":396,"serial_number":"AV17-044","subject":null,"moderation_state":"archived","external_url":null},{"nid":1107,"title":"SAP Security Notes - April 2017","uuid":"45651663-ddd1-4287-9064-dafe379901e4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-07-03T15:43:42Z","summary":null,"body":["<article data-history-node-id=\"1107\" about=\"\/en\/alerts-advisories\/sap-security-notes-april-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-045<br \/>\nDate: 13 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Security Notes by SAP.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>SAP has released 12 Security Notes as part of their April Security Patch Day designed to address multiple vulnerabilities in several SAP products as well as a Security Note 2419592 of Very High priority.<\/p>\n\n<p>Vulnerabilities addressed in the April Security Patch Day Security Notes include: Remote Code Execution, Incorrect Authorization Checks, Cross Site Scripting, Missing Authorization Check, Missing XML Validation vulnerability, Information Disclosure in DBISQL affecting SAP SQL Anywhere and others.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released update to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/blogs.sap.com\/2017\/04\/11\/sap-security-patch-day-april-2017\/\"><font color=\"#0066cc\">https:\/\/blogs.sap.com\/2017\/04\/11\/sap-security-patch-day-april-2017\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-notes-april-2017","alert_type":396,"serial_number":"AV17-045","subject":null,"moderation_state":"archived","external_url":null},{"nid":934,"title":"Security fixes released for BIND","uuid":"9590454c-9a8a-4a8b-803f-c35d468e84b8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:45Z","date_created":"2018-07-03T15:50:26Z","summary":null,"body":["<article data-history-node-id=\"934\" about=\"\/en\/alerts-advisories\/security-fixes-released-bind-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-046<br \/>\nDate: 13 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released updates that address three vulnerabilities in BIND. Exploitation of these vulnerabilities may allow a remote attacker to cause inconsistent state of query processing and denial of service.<\/p>\n\n<p>Version Affected: 9.8.0 -&gt; 9.8.8-P1, 9.9.0 -&gt; 9.9.9-P6, 9.9.9 -&gt; 9.9.9-P7, 9.9.10b1 -&gt; 9.9.10rc2, 9.10.0 -&gt; 9.10.4-P6, 9.10.4 -&gt; 9.10.4-P7, 9.10.5b1 -&gt; 9.10.5rc2, 9.11.0 -&gt; 9.11.0-P4, 9.11.1b1 -&gt; 9.11.1rc2, 9.9.3-S1 -&gt; 9.9.9-S8, 9.9.9-S1 -&gt; 9.9.9-S9<\/p>\n\n<p>CVE References: CVE-2017-3136, CVE-2017-3137, CVE-2017-3138<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01465\/74\/CVE-2017-3136\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01465\/74\/CVE-2017-3136<\/font><\/a><br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01466\/74\/CVE-2017-3137\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01466\/74\/CVE-2017-3137<\/font><\/a><br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01471\/74\/CVE-2017-3138\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01471\/74\/CVE-2017-3138<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-released-bind-3","alert_type":396,"serial_number":"AV17-046","subject":null,"moderation_state":"archived","external_url":null},{"nid":820,"title":"VMware security updates","uuid":"19466441-bc11-43ae-ad46-af1c55f37dbe","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:22Z","date_created":"2018-07-03T15:57:00Z","summary":null,"body":["<article data-history-node-id=\"820\" about=\"\/en\/alerts-advisories\/vmware-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-047<br \/>\nDate: 14 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>vCenter Server Version 6.5, 6.0 and 5.5<\/li>\n<\/ul><p>CVE Reference: CVE-2017-5641<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0007.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0007.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-1","alert_type":396,"serial_number":"AV17-047","subject":null,"moderation_state":"archived","external_url":null},{"nid":1350,"title":"Oracle Critical Patch update Advisory \u2013 April 2017","uuid":"387b191d-6ced-453d-802a-030087998632","banner":null,"lang":"en","date_modified":"2018-10-03","date_modified_ts":"2018-10-03T15:26:33Z","date_created":"2018-07-03T17:26:32Z","summary":null,"body":["<article data-history-node-id=\"1350\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-april-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-048<br \/>\nDate: 19 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following critical patch updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update (CPU) which addresses 299 new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Automatic Service Request (ASR), version(s) prior to 5.7<\/li>\n\t<li>Enterprise Manager Base Platform, version(s) 12.1.0, 13.1.0, 13.2.0<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version(s) 9.2<\/li>\n\t<li>MICROS Lucas, version(s) 2.9.5.1, 2.9.5.2, 2.9.5.3, 2.9.5.4, 2.9.5.5<\/li>\n\t<li>MICROS Relate CRM Software, version(s) 10.0, 10.5, 10.8, 11.0, 11.1, 11.4, 15.0<\/li>\n\t<li>MICROS XBR, version(s) 10.0.1, 10.5.0, 10.6.0, 10.7.7, 10.8.0, 10.8.1<\/li>\n\t<li>MICROS Xstore Payment, version(s) 5.5, 6.0, 6.5, 7.0, 7.1, 15.0, 16.0<\/li>\n\t<li>MySQL Cluster, version(s) 7.2.27 and prior, 7.3.16 and prior, 7.4.14 and prior, 7.5.5 and prior<\/li>\n\t<li>MySQL Connectors, version(s) 2.1.5 and prior, 5.1.41 and prior<\/li>\n\t<li>MySQL Enterprise Backup, version(s) 3.12.3 and prior, 4.0.3 and prior<\/li>\n\t<li>MySQL Enterprise Monitor, version(s) 3.1.6.8003 and prior, 3.2.1182 and prior, 3.3.2.1162 and prior<\/li>\n\t<li>MySQL Server, version(s) 5.5.54 and prior, 5.6.35 and prior, 5.7.17 and prior, 5.7.11 to 5.7.17<\/li>\n\t<li>MySQL Workbench, version(s) 6.3.8 and prior<\/li>\n\t<li>Oracle Advanced Support Gateway, version(s) prior to 7.2<\/li>\n\t<li>Oracle API Gateway, version(s) 11.1.2.4.0<\/li>\n\t<li>Oracle Berkeley DB, version(s) prior to 6.2.32<\/li>\n\t<li>Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager, version(s) 6.1.4, 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1, 6.5.2, 11.0, 11.1, 11.2<\/li>\n\t<li>Oracle Communications ASAP, version(s) 7.0, 7.2, 7.3<\/li>\n\t<li>Oracle Communications Network Integrity, version(s) 7.2.4, 7.3.0<\/li>\n\t<li>Oracle Communications Policy Management, version(s) 12.2<\/li>\n\t<li>Oracle Communications Security Gateway, version(s) 3.0.0<\/li>\n\t<li>Oracle Communications Service Broker Engineered System Edition, version(s) 6.0, 6.1<\/li>\n\t<li>Oracle Communications Session Border Controller, version(s) SCZ7.3.0, SCZ7.4.0<\/li>\n\t<li>Oracle Database Server, version(s) 11.2.0.4, 12.1.0.2<\/li>\n\t<li>Oracle E-Business Suite, version(s) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6<\/li>\n\t<li>Oracle Financial Services Analytical Applications Infrastructure, version(s) 7.3.3, 7.3.4, 7.3.5<\/li>\n\t<li>Oracle Financial Services Asset Liability Management, version(s) 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Financial Services Basel Regulatory Capital Basic, version(s) 6.1.2, 6.1.3, 8.0.2, 8.0.3<\/li>\n\t<li>Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach, version(s) 6.1.2, 6.1.3, 8.0.2, 8.0.3<\/li>\n\t<li>Oracle Financial Services Data Foundation, version(s) 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Financial Services Data Integration Hub, version(s) 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Financial Services Enterprise Financial Performance Analytics, version(s) 8.0.0 to 8.0.4<\/li>\n\t<li>Oracle Financial Services Funds Transfer Pricing, version(s) 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Financial Services Hedge Management and IFRS Valuations, version(s) 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Financial Services Institutional Performance Analytics, version(s) 8.0.0 to 8.0.4<\/li>\n\t<li>Oracle Financial Services Liquidity Risk Management, version(s) 8.0.1, 8.0.2, 8.0.4<\/li>\n\t<li>Oracle Financial Services Loan Loss Forecasting and Provisioning, version(s) 1.5.0, 1.5.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Financial Services Pricing Management\/Transfer Pricing Component, version(s) 8.0.0 to 8.0.4<\/li>\n\t<li>Oracle Financial Services Profitability Management, version(s) 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Financial Services Reconciliation Framework, version(s) 8.0.0, 8.0.1, 8.0.2<\/li>\n\t<li>Oracle Financial Services Retail Customer Analytics, version(s) 8.0.0 to 8.0.3<\/li>\n\t<li>Oracle Financial Services Retail Performance Analytics, version(s) 8.0.0 to 8.0.4<\/li>\n\t<li>Oracle FLEXCUBE Direct Banking, version(s) 12.0.2, 12.0.3<\/li>\n\t<li>Oracle FLEXCUBE Enterprise Limits and Collateral Management, version(s) 12.0.0, 12.0.1, 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Investor Servicing, version(s) 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0, 12.3.0<\/li>\n\t<li>Oracle FLEXCUBE Private Banking, version(s) 2.0.0, 2.0.1, 2.2.0.1, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Universal Banking, version(s) 11.3.0, 11.4.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0<\/li>\n\t<li>Oracle Fusion Applications, version(s) 11.1.2 through 11.1.9<\/li>\n\t<li>Oracle Fusion Middleware MapViewer, version(s) 11.1.1.9, 12.2.1.1, 12.2.1.2<\/li>\n\t<li>Oracle Fusion Middleware, version(s) 11.1.1.7, 11.1.1.9, 11.1.2.2, 11.1.2.3, 12.1.3.0, 12.2.1.0, 12.2.1.1<\/li>\n\t<li>Oracle GlassFish Server, version(s) 3.1.2<\/li>\n\t<li>Oracle Healthcare Master Person Index, version(s) 3.0.0.x and 4.0.1.x, prior to and 2.0.1.x<\/li>\n\t<li>Oracle Hospitality OPERA 5 Property Services, version(s) 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x, 5.5.1.x<\/li>\n\t<li>Oracle Hyperion Essbase, version(s) 11.1.2.2<\/li>\n\t<li>Oracle Identity Manager, version(s) 11.1.2.3.0<\/li>\n\t<li>Oracle Insurance Data Foundation, version(s) 8.0.1, 8.0.2, 8.0.3, 8.0.4<\/li>\n\t<li>Oracle Insurance Istream, version(s) 4.3.2 and prior<\/li>\n\t<li>Oracle Java SE Embedded, version(s) 8u121<\/li>\n\t<li>Oracle Java SE, version(s) 6u141, 7u131, 8u121<\/li>\n\t<li>Oracle JRockit, version(s) R28.3.13<\/li>\n\t<li>Oracle Real-Time Scheduler, version(s) 2.2.0.3.13, 2.3.0.0, 2.3.0.1<\/li>\n\t<li>Oracle Retail Advanced Inventory Planning, version(s) 14.1, 15.0<\/li>\n\t<li>Oracle Retail Advanced Science Engine, version(s) 14.1<\/li>\n\t<li>Oracle Retail Analytic Parameter Calculator - RO, version(s) 15.0<\/li>\n\t<li>Oracle Retail Analytics, version(s) 14.0, 14.1, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Assortment Planning, version(s) 14.1.3, 15.0.1, 16.0.0<\/li>\n\t<li>Oracle Retail Back Office, version(s) 14.1<\/li>\n\t<li>Oracle Retail Category Management Planning &amp; Optimization, version(s) 15.0<\/li>\n\t<li>Oracle Retail Category Management, version(s) 13.2, 13.3, 14.0, 14.1<\/li>\n\t<li>Oracle Retail Customer Insights, version(s) 15.0<\/li>\n\t<li>Oracle Retail Customer Management and Segmentation Foundation, version(s) 15.0<\/li>\n\t<li>Oracle Retail Demand Forecasting, version(s) 14.1.3, 15.0.2<\/li>\n\t<li>Oracle Retail Invoice Matching, version(s) 12.0, 13.0, 13.1, 13.2, 14.0, 14.1<\/li>\n\t<li>Oracle Retail Item Planning, version(s) 14.1.3, 15.0.2<\/li>\n\t<li>Oracle Retail Macro Space Optimization, version(s) 15.0.2<\/li>\n\t<li>Oracle Retail Merchandise Financial Planning, version(s) 14.1.3, 15.0.2<\/li>\n\t<li>Oracle Retail Merchandising Insights, version(s) 15.0<\/li>\n\t<li>Oracle Retail Open Commerce Platform, version(s) 4.0, 5.0, 5.1, 5.3, 6.0, 6.1, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Order Broker, version(s) 5.1, 5.2, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Point-of-Service, version(s) 14.1.3<\/li>\n\t<li>Oracle Retail Predictive Application Server, version(s) 13.1, 13.2, 13.3, 13.3.3, 13.4, 13.4.3, 14.0, 14.0.3, 14.1, 14.1.3, 15.0, 15.0.2, 16.0.0<\/li>\n\t<li>Oracle Retail Regular Price Optimization, version(s) 14.1.3, 15.0.2<\/li>\n\t<li>Oracle Retail Replenishment Optimization, version(s) 14.1.3, 15.0.2<\/li>\n\t<li>Oracle Retail Returns Management, version(s) 14.1<\/li>\n\t<li>Oracle Retail Size Profile Optimization, version(s) 14.1.3, 15.0.2<\/li>\n\t<li>Oracle Retail Store Inventory, version(s) 14.1, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Warehouse Management System, version(s) 13.2, 14.0, 15.0<\/li>\n\t<li>Oracle Retail XBRi Loss Prevention, version(s) 10.0.1, 10.5.0, 10.6.0, 10.7.0, 10.8.0, 10.8.1<\/li>\n\t<li>Oracle Retail Xstore Point of Service, version(s) 5.5, 6.0, 6.5, 7.0, 7.1, 15.0, 16.0<\/li>\n\t<li>Oracle Secure Backup, version(s) prior to 12.1.0.3.0<\/li>\n\t<li>Oracle Service Bus, version(s) 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Social Network, version(s) prior to 11.1.12.0.0 (17019101)<\/li>\n\t<li>Oracle SuperCluster Specific Software, version(s) 2.3.8, 2.3.13<\/li>\n\t<li>Oracle Trace File Analyzer (TFA), version(s) prior to 12.1.2.8.4<\/li>\n\t<li>Oracle Transportation Manager, version(s) 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, 6.4.1, 6.4.2<\/li>\n\t<li>Oracle Utilities Customer Self Service, version(s) 2.1.0.2.0<\/li>\n\t<li>Oracle Utilities Framework, version(s) 2.2.0.0.0, 4.1.0.1.0, 4.1.0.2.0, 4.2.0.1.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0, 4.3.0.2.0, 4.3.0.3.0<\/li>\n\t<li>Oracle Utilities Work and Asset Management, version(s) 1.9.1.2.11<\/li>\n\t<li>Oracle VM VirtualBox, version(s) prior to 5.0.38, prior to 5.1.20<\/li>\n\t<li>Oracle WebCenter Content, version(s) 11.1.1.7, 11.1.1.9, 12.2.1.0, 12.2.1.1, 12.2.1.2<\/li>\n\t<li>Oracle WebCenter Sites, version(s) 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle WebLogic Server, version(s) 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, 12.2.1.2<\/li>\n\t<li>OSS Support Tools, version(s) prior to RDA 8.15.17.3.14<\/li>\n\t<li>PeopleSoft Enterprise CS Campus Community, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise FIN Receivables, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise FSCM, version(s) 9.1<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, version(s) 8.54, 8.55<\/li>\n\t<li>PeopleSoft Enterprise SCM eBill Payment, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise SCM eSupplier Connection, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise SCM Purchasing, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise SCM Service Procurement, version(s) 9.2<\/li>\n\t<li>PeopleSoft Enterprise SCM Strategic Sourcing, version(s) 9.2<\/li>\n\t<li>Primavera Gateway, version(s) 1.0, 1.1, 14.2, 15.1, 15.2, 16.1, 16.2<\/li>\n\t<li>Primavera P6 Enterprise Project Portfolio Management, version(s) 8.3, 8.4, 15.1, 15.2, 16.1, 16.2<\/li>\n\t<li>Primavera Unifier, version(s) 9.13, 9.14, 10.0, 10.1, 15.1, 15.2<\/li>\n\t<li>Secure Global Desktop, version(s) 4.71, 5.2, 5.3<\/li>\n\t<li>Siebel Applications, version(s) 6.1, 6.2, 7.0, 7.1<\/li>\n\t<li>Solaris Cluster, version(s) 4.3<\/li>\n\t<li>Solaris, version(s) 10, 11.3<\/li>\n\t<li>StorageTek Tape Analytics SW Tool, version(s) prior to 2.2.1<\/li>\n\t<li>Sun ZFS Storage Appliance Kit (AK), version(s) AK 2013<\/li>\n<\/ul><p>CVE References:<\/p>\n\n<p>CVE-2004-2761, CVE-2012-0920, CVE-2012-1007, CVE-2012-5881, CVE-2012-5882, CVE-2012-5883, CVE-2013-1982, CVE-2013-1983, CVE-2013-1984, CVE-2013-1985, CVE-2013-1986, CVE-2013-1987, CVE-2013-1995, CVE-2013-1998, CVE-2013-2002, CVE-2013-2003, CVE-2013-2005, CVE-2013-2566, CVE-2013-5209, CVE-2014-0114, CVE-2014-3571, CVE-2014-3596, CVE-2015-0204, CVE-2015-0286, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-3195, CVE-2015-3236, CVE-2015-3237, CVE-2015-4852, CVE-2015-5252, CVE-2015-5351, CVE-2015-7501, CVE-2015-7940, CVE-2016-0635, CVE-2016-0706, CVE-2016-0714, CVE-2016-0729, CVE-2016-0762, CVE-2016-0763, CVE-2016-1181, CVE-2016-1182, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-2510, CVE-2016-3092, CVE-2016-3504, CVE-2016-3506, CVE-2016-3607, CVE-2016-3674, CVE-2016-3739, CVE-2016-4430, CVE-2016-4431, CVE-2016-4433, CVE-2016-4436, CVE-2016-4802, CVE-2016-5018, CVE-2016-5019, CVE-2016-5407, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-5551, CVE-2016-6288, CVE-2016-6289, CVE-2016-6290, CVE-2016-6291, CVE-2016-6292, CVE-2016-6294, CVE-2016-6295, CVE-2016-6296, CVE-2016-6297, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6794, CVE-2016-6796, CVE-2016-6797, CVE-2016-6816, CVE-2016-6817, CVE-2016-7052, CVE-2016-7055, CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8620, CVE-2016-8621, CVE-2016-8622, CVE-2016-8623, CVE-2016-8624, CVE-2016-8625, CVE-2016-8735, CVE-2016-8743, CVE-2017-3230, CVE-2017-3232, CVE-2017-3233, CVE-2017-3234, CVE-2017-3237, CVE-2017-3254, CVE-2017-3288, CVE-2017-3302, CVE-2017-3304, CVE-2017-3305, CVE-2017-3306, CVE-2017-3307, CVE-2017-3308, CVE-2017-3309, CVE-2017-3329, CVE-2017-3331, CVE-2017-3337, CVE-2017-3342, CVE-2017-3345, CVE-2017-3347, CVE-2017-3355, CVE-2017-3356, CVE-2017-3393, CVE-2017-3432, CVE-2017-3434, CVE-2017-3450, CVE-2017-3451, CVE-2017-3452, CVE-2017-3453, CVE-2017-3454, CVE-2017-3455, CVE-2017-3456, CVE-2017-3457, CVE-2017-3458, CVE-2017-3459, CVE-2017-3460, CVE-2017-3461, CVE-2017-3462, CVE-2017-3463, CVE-2017-3464, CVE-2017-3465, CVE-2017-3467, CVE-2017-3468, CVE-2017-3469, CVE-2017-3470, CVE-2017-3471, CVE-2017-3472, CVE-2017-3473, CVE-2017-3474, CVE-2017-3475, CVE-2017-3476, CVE-2017-3477, CVE-2017-3478, CVE-2017-3479, CVE-2017-3480, CVE-2017-3481, CVE-2017-3482, CVE-2017-3483, CVE-2017-3484, CVE-2017-3485, CVE-2017-3486, CVE-2017-3487, CVE-2017-3488, CVE-2017-3489, CVE-2017-3490, CVE-2017-3491, CVE-2017-3492, CVE-2017-3493, CVE-2017-3494, CVE-2017-3495, CVE-2017-3496, CVE-2017-3497, CVE-2017-3498, CVE-2017-3499, CVE-2017-3500, CVE-2017-3501, CVE-2017-3502, CVE-2017-3503, CVE-2017-3504, CVE-2017-3505, CVE-2017-3506, CVE-2017-3507, CVE-2017-3508, CVE-2017-3509, CVE-2017-3510, CVE-2017-3511, CVE-2017-3512, CVE-2017-3513, CVE-2017-3514, CVE-2017-3515, CVE-2017-3516, CVE-2017-3517, CVE-2017-3518, CVE-2017-3519, CVE-2017-3520, CVE-2017-3521, CVE-2017-3522, CVE-2017-3524, CVE-2017-3525, CVE-2017-3526, CVE-2017-3527, CVE-2017-3528, CVE-2017-3530, CVE-2017-3531, CVE-2017-3532, CVE-2017-3533, CVE-2017-3534, CVE-2017-3535, CVE-2017-3536, CVE-2017-3537, CVE-2017-3538, CVE-2017-3539, CVE-2017-3540, CVE-2017-3541, CVE-2017-3542, CVE-2017-3543, CVE-2017-3544, CVE-2017-3545, CVE-2017-3546, CVE-2017-3547, CVE-2017-3548, CVE-2017-3549, CVE-2017-3550, CVE-2017-3551, CVE-2017-3552, CVE-2017-3553, CVE-2017-3554, CVE-2017-3555, CVE-2017-3556, CVE-2017-3557, CVE-2017-3558, CVE-2017-3559, CVE-2017-3560, CVE-2017-3561, CVE-2017-3563, CVE-2017-3564, CVE-2017-3565, CVE-2017-3567, CVE-2017-3568, CVE-2017-3569, CVE-2017-3570, CVE-2017-3571, CVE-2017-3572, CVE-2017-3573, CVE-2017-3574, CVE-2017-3575, CVE-2017-3576, CVE-2017-3577, CVE-2017-3578, CVE-2017-3579, CVE-2017-3580, CVE-2017-3581, CVE-2017-3582, CVE-2017-3583, CVE-2017-3584, CVE-2017-3585, CVE-2017-3586, CVE-2017-3587, CVE-2017-3589, CVE-2017-3590, CVE-2017-3591, CVE-2017-3592, CVE-2017-3593, CVE-2017-3594, CVE-2017-3595, CVE-2017-3596, CVE-2017-3597, CVE-2017-3598, CVE-2017-3599, CVE-2017-3600, CVE-2017-3601, CVE-2017-3602, CVE-2017-3603, CVE-2017-3604, CVE-2017-3605, CVE-2017-3606, CVE-2017-3607, CVE-2017-3608, CVE-2017-3609, CVE-2017-3610, CVE-2017-3611, CVE-2017-3612, CVE-2017-3613, CVE-2017-3614, CVE-2017-3615, CVE-2017-3616, CVE-2017-3617, CVE-2017-3618, CVE-2017-3619, CVE-2017-3620, CVE-2017-3621, CVE-2017-3622, CVE-2017-3623, CVE-2017-3625, CVE-2017-3626, CVE-2017-3730, CVE-2017-3731, CVE-2017-3732, CVE-2017-5638<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2017-3236618.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2017-3236618.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-april-2017","alert_type":396,"serial_number":"AV17-048","subject":null,"moderation_state":"archived","external_url":null},{"nid":965,"title":"VMware security updates","uuid":"a1525f91-e955-42aa-af20-3f3d97f1816c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:19Z","date_created":"2018-07-03T17:35:06Z","summary":null,"body":["<article data-history-node-id=\"965\" about=\"\/en\/alerts-advisories\/vmware-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-049<br \/>\nDate: 19 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<br \/>\n\u2022 VMware Unified Access Gateway<br \/>\n\u2022 VMware Horizon View\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n\u2022 VMware Horizon View Client for Windows<br \/>\n\u2022 VMware Workstation Pro \/ Player (Workstation)<\/p>\n\n<p>CVE Reference: CVE-2017-4907, CVE-2017-4908, CVE-2017-4909, CVE-2017-4910, CVE-2017-4911, CVE-2017-4912, CVE-2017-4913<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0008.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0008.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-2","alert_type":396,"serial_number":"AV17-049","subject":null,"moderation_state":"archived","external_url":null},{"nid":1327,"title":"Juniper Networks Security Advisories","uuid":"749ba4e4-1cf9-4666-9467-28b1bc309c62","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:46Z","date_created":"2018-07-03T17:47:36Z","summary":null,"body":["<article data-history-node-id=\"1327\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-050<br \/>\nDate: 19 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by Juniper Networks.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Juniper Networks has released product updates addressing security issues for multiple products.<\/p>\n\n<p>Affected Products:<br \/>\n\u2022 Juniper EX Series<br \/>\n\u2022 Juniper SRX, vSRX and J-Series<br \/>\n\u2022 Junos OS<br \/>\n\u2022 NorthStar Controller Application<\/p>\n\n<p>CVE References: CVE-2015-1349, CVE-2015-2808, CVE-2015-3209, CVE-2015-3456, CVE-2015-4620, CVE-2015-5307, CVE-2015-5477, CVE-2015-7973, CVE-2015-7979, CVE-2015-8104, CVE-2015-8138, CVE-2015-8158, CVE-2016-7427, CVE-2016-7429, CVE-2016-7431, CVE-2016-8864, CVE-2016-9131, CVE-2016-9147, CVE-2016-9310, CVE-2016-9311, CVE-2016-9444, CVE-2017-2312, CVE-2017-2313, CVE-2017-2315, CVE-2017-2316, CVE-2017-2317, CVE-2017-2318, CVE-2017-2319, CVE-2017-2320, CVE-2017-2321, CVE-2017-2322, CVE-2017-2323, CVE-2017-2324, CVE-2017-2325, CVE-2017-2326, CVE-2017-2327, CVE-2017-2328, , CVE-2017-2329, CVE-2017-2330, CVE-2017-2331, CVE-2017-2332, CVE-2017-2333, CVE-2017-2334, CVE-2017-2340<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10776\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10776<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10777\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10777<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10778\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10778<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10780\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10780<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10781\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10781<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10783\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10783<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10784\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10784<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10785\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10785<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10786\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10786<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisories","alert_type":396,"serial_number":"AV17-050","subject":null,"moderation_state":"archived","external_url":null},{"nid":1015,"title":"Blue Coat security advisory","uuid":"033a3ac4-8b6b-4eb9-86e8-df8b24a854c3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-03T17:53:54Z","summary":null,"body":["<article data-history-node-id=\"1015\" about=\"\/en\/alerts-advisories\/blue-coat-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-051<br \/>\nDate: 19 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by Blue Coat.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Blue Coat has released a product advisory addressing vulnerabilities within its Advanced Secure Gateway and Content Analysis System products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<p>Advanced Secure Gateway<br \/>\nASG 6.6 prior to 6.6.5.4<\/p>\n\n<p>Content Analysis System<br \/>\nCAS 1.3 prior to 1.3.7.4<\/p>\n\n<p>CVE Reference: CVE-2016-9091<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/bto.bluecoat.com\/security-advisory\/sa138\"><font color=\"#0066cc\">https:\/\/bto.bluecoat.com\/security-advisory\/sa138<\/font><\/a><br \/><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-9091\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-9091<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/blue-coat-security-advisory","alert_type":396,"serial_number":"AV17-051","subject":null,"moderation_state":"archived","external_url":null},{"nid":1138,"title":"Mozilla Releases security updates","uuid":"59de94f8-9856-41f7-bfb1-d016e533450d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-03T18:00:29Z","summary":null,"body":["<article data-history-node-id=\"1138\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-052<br \/>\nDate: 20 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Mozilla Firefox and Firefox ESR.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 39 vulnerabilities in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 53<br \/>\nESR versions 45.x prior to 45.9<br \/>\nESR versions 52.x prior to 52.1<\/p>\n\n<p>CVE References:\u00a0 CVE-2017-5429, CVE-2017-5430, CVE-2017-5432, CVE-2017-5433, CVE-2017-5434, CVE-2017-5435, CVE-2017-5436, CVE-2017-5437, CVE-2017-5438, CVE-2017-5439, CVE-2017-5440, CVE-2017-5441, CVE-2017-5442, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445, CVE-2017-5446, CVE-2017-5447, CVE-2017-5448, CVE-2017-5449, CVE-2017-5450, CVE-2017-5451, CVE-2017-5452, CVE-2017-5453, CVE-2017-5454, CVE-2017-5455, CVE-2017-5456, CVE-2017-5458, CVE-2017-5459, CVE-2017-5460, CVE-2017-5461, CVE-2017-5462, CVE-2017-5463, CVE-2017-5464, CVE-2017-5465, CVE-2017-5466, CVE-2017-5467, CVE-2017-5468, CVE-2017-5469<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-10\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-10\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-11\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-11\/<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-12\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-12\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-11","alert_type":396,"serial_number":"AV17-052","subject":null,"moderation_state":"archived","external_url":null},{"nid":1219,"title":"Google Releases security update for Chrome","uuid":"9b72b47d-7bec-47a5-84d6-905ecf7b716a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:31Z","date_created":"2018-07-03T18:07:30Z","summary":null,"body":["<article data-history-node-id=\"1219\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-20\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-053<br \/>\nDate: 20 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 58.0.3029.81 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/04\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/04\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-20","alert_type":396,"serial_number":"AV17-053","subject":null,"moderation_state":"archived","external_url":null},{"nid":1301,"title":"Cisco Releases security updates","uuid":"add1da99-57ac-42e2-beea-87bb790ffe19","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-07-03T18:14:44Z","summary":null,"body":["<article data-history-node-id=\"1301\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-16\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-054<br \/>\nDate: 20 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco Unified Communications Manager Denial of Service Vulnerability<\/li>\n\t<li>Cisco Firepower Detection Engine Pragmatic General Multicast Protocol Decoding Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software EnergyWise Denial of Service Vulnerabilities<\/li>\n\t<li>Cisco ASA Software Internet Key Exchange Version 1 XAUTH Denial of Service Vulnerability<\/li>\n\t<li>Cisco ASA Software SSL\/TLS Denial of Service Vulnerability<\/li>\n\t<li>Cisco ASA Software IPsec Denial of Service Vulnerability<\/li>\n\t<li>Cisco ASA Software DNS Denial of Service Vulnerability.<\/li>\n<\/ul><p>CVE References:<\/p>\n\n<p>Critical: CVE-2017-5638<\/p>\n\n<p>High: CVE-2017-3860, CVE-2017-3861, CVE-2017-3862, CVE-2017-3863, CVE-2017-3808, CVE-2016-6368, CVE-2017-6607, CVE-2017-6608, CVE-2017-6609, CVE-2017-6610<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-16","alert_type":396,"serial_number":"AV17-054","subject":null,"moderation_state":"archived","external_url":null},{"nid":1086,"title":"Drupal Security Advisories","uuid":"12b27c27-1316-4a7d-9814-d30e12c01e3a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:38Z","date_created":"2018-07-03T18:24:31Z","summary":null,"body":["<article data-history-node-id=\"1086\" about=\"\/en\/alerts-advisories\/drupal-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-055<br \/>\nDate: 20 April 2017<\/strong><\/p>\n\n<p>The purpose of this advisory is to bring attention to Drupal security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released an update to address a security vulnerability. Successful exploitation of this vulnerability could allow a user to bypass access controls if certain conditions are met.<\/p>\n\n<p>Affected Versions:<br \/>\nDrupal 8 prior to 8.2.8 and 8.3.1<br \/>\nDrupal 7.x is not affected.<\/p>\n\n<p>CVE Reference: CVE-2017-6919<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/SA-CORE-2017-002\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/SA-CORE-2017-002<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-6919\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-6919<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisories","alert_type":396,"serial_number":"AV17-055","subject":null,"moderation_state":"archived","external_url":null},{"nid":845,"title":"Sophos Vulnerability","uuid":"902f3e22-982c-4786-ace1-f015828f4dbd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-07-03T18:51:55Z","summary":null,"body":["<article data-history-node-id=\"845\" about=\"\/en\/alerts-advisories\/sophos-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-056<br \/>\nDate: 20 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a vulnerability in the Sophos \u00a0Cyberoam UTM CR25iNG 10.6.3 MR-5 product.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This vulnerability allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp.<\/p>\n\n<p>Affected Product:<br \/>\nSophos Cyberoam UTM CR25iNG 10.6.3 MR-5<br \/>\nThis vulnerability is addressed in Version 10.6.5.<\/p>\n\n<p>CVE Reference: CVE-2016-7786<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-7786\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-7786<\/font><\/a> (en anglais)<br \/><a href=\"http:\/\/www.cvedetails.com\/cve\/CVE-2016-7786\/\"><font color=\"#0066cc\">http:\/\/www.cvedetails.com\/cve\/CVE-2016-7786\/<\/font><\/a> \u00a0(en anglais)<br \/><a href=\"https:\/\/docs.cyberoam.com\/default.asp?id=2585&amp;Lang=1&amp;SID\"><font color=\"#0066cc\">https:\/\/docs.cyberoam.com\/default.asp?id=2585&amp;Lang=1&amp;SID<\/font><\/a> (en anglais)<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sophos-vulnerability","alert_type":396,"serial_number":"AV17-056","subject":null,"moderation_state":"archived","external_url":null},{"nid":1046,"title":"Trend Micro Threat Discovery Appliance Vulnerability","uuid":"e45aa02b-5736-4a46-94b7-cf7b8e03826b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-07-03T18:59:07Z","summary":null,"body":["<article data-history-node-id=\"1046\" about=\"\/en\/alerts-advisories\/trend-micro-threat-discovery-appliance-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-057<br \/>\nDate: 20 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a vulnerability in Trend Micro\u2019s Threat Discovery Appliance.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Trend Micro Threat Discovery Appliance 2.6.1062r1 is prone to directory traversal when processing a session_id cookie that could allow a remote, unauthenticated user to delete arbitrary files with root privileges. This could be used to bypass authentication or cause a denial of service (DoS).<\/p>\n\n<p>CVE Reference: CVE-2016-7552<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.securityfocus.com\/bid\/97599\"><font color=\"#0066cc\">http:\/\/www.securityfocus.com\/bid\/97599<\/font><\/a><br \/><a href=\"http:\/\/www.cvedetails.com\/cve\/CVE-2016-7552\/\"><font color=\"#0066cc\">http:\/\/www.cvedetails.com\/cve\/CVE-2016-7552\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-threat-discovery-appliance-vulnerability","alert_type":396,"serial_number":"AV17-057","subject":null,"moderation_state":"archived","external_url":null},{"nid":782,"title":"Adobe security update","uuid":"f0135f8d-7e02-467a-8840-9d584acc3d73","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-07-03T19:22:45Z","summary":null,"body":["<article data-history-node-id=\"782\" about=\"\/en\/alerts-advisories\/adobe-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-058<br \/>\nDate: 27 April 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released security update for Adobe ColdFusion.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released Security Bulletin APSB17-14 to address critical vulnerabilities that could potentially be exploited using cross-site scripting and java deserialization.\u00a0<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>ColdFusion (2016 release) Update 3 and earlier versions\u00a0<\/li>\n\t<li>ColdFusion 11 Update 11 and earlier versions<\/li>\n\t<li>ColdFusion 10 Update 22 and earlier versions<\/li>\n<\/ul><p>CVE References: CVE-2017-3008 and CVE-2017-3066.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>APSB17-14: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb17-14.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb17-14.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-update","alert_type":396,"serial_number":"AV17-058","subject":null,"moderation_state":"archived","external_url":null},{"nid":1237,"title":"Google Releases security update for Chrome","uuid":"f308d64f-8d98-47b9-8227-810753152305","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:39Z","date_created":"2018-07-03T19:29:17Z","summary":null,"body":["<article data-history-node-id=\"1237\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-21\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-059<br \/>\nDate: 3 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 58.0.3029.96 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference: CVE-2017-5068<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/05\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/05\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-21","alert_type":396,"serial_number":"AV17-059","subject":null,"moderation_state":"archived","external_url":null},{"nid":1264,"title":"Intel\u00ae Active Management Technology (AMT) - Escalation of Privilege Vulnerability","uuid":"8b35c620-b880-4c9b-87de-3b31765bca35","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-07-03T19:35:36Z","summary":null,"body":["<article data-history-node-id=\"1264\" about=\"\/en\/alerts-advisories\/intelr-active-management-technology-amt-escalation-privilege-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-060<br \/>\nDate: 3 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a vulnerability in Intel\u00ae Active Management Technology, Intel\u00ae Small Business Technology, and Intel\u00ae Standard.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of an escalation of privilege vulnerability in Intel\u00ae Active Management Technology (AMT), Intel\u00ae Standard Manageability (ISM), and Intel\u00ae Small Business Technology versions firmware versions 6.x, 7.x, 8.x 9.x, 10.x, 11.0, 11.5, and 11.6. This vulnerability can allow an unprivileged attacker to gain control of the manageability features provided by these products. This vulnerability does not exist on Intel-based consumer PCs.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>INTEL-SA-00075: Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Escalation of Privilege<br \/><a href=\"https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00075&amp;languageid=en-fr\"><font color=\"#0066cc\">https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00075&amp;languageid=en-fr<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intelr-active-management-technology-amt-escalation-privilege-vulnerability","alert_type":396,"serial_number":"AV17-060","subject":null,"moderation_state":"archived","external_url":null},{"nid":1109,"title":"Cisco Releases security updates","uuid":"d037fdd4-ddd3-419c-922e-8bfa4eb089f3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-07-03T19:42:40Z","summary":null,"body":["<article data-history-node-id=\"1109\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-17\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-061<br \/>\nDate: 04 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco CVR100W Wireless-N VPN Router Universal Plug-and-Play Buffer Overflow Vulnerability<\/li>\n\t<li>Cisco IOS XR Software Denial of Service Vulnerability<\/li>\n\t<li>Cisco TelePresence ICMP Denial of Service Vulnerability<\/li>\n\t<li>Cisco Aironet 1800, 2800, and 3800 Series Access Points Plug-and-Play Arbitrary Code Execution Vulnerability<\/li>\n\t<li>Cisco Wide Area Application Services SMART-SSL Accelerator Denial of Service VulnerabilityCisco Wide Area Application Services<\/li>\n\t<li>Cisco Firepower Threat Defense and Cisco ASA with FirePOWER Module Denial of Service Vulnerability<\/li>\n\t<li>Cisco Finesse for Cisco Unified Contact Center Enterprise Information Disclosure Vulnerability<\/li>\n\t<li>Cisco CVR100W Wireless-N VPN Router Remote Management Security Bypass Vulnerability<\/li>\n\t<li>Cisco Unity Connection ImageID Parameter Unauthorized Access Vulnerability<\/li>\n\t<li>Cisco CallManager Express Unauthorized Access Vulnerability<\/li>\n<\/ul><p>CVE References:<\/p>\n\n<p>Critical: CVE-2017-3882.\u00a0<\/p>\n\n<p>High: CVE-2017-3825, CVE-2017-3873, CVE-2017-3876.<\/p>\n\n<p>Medium:\u00a0 CVE-2017-6620, CVE-2017-6624, CVE-2017-6625, CVE-2017-6626, CVE-2017-6628, CVE-2017-6629.\u00a0\u00a0\u00a0<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cvr100w1\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cvr100w1<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-ios-xr\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-ios-xr<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-ctp\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-ctp<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cme\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cme<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-waas\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-waas<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-ftd\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-ftd<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-finesse-ucce\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-finesse-ucce<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cvr100w2\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cvr100w2<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cucc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cucc<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cme1\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170503-cme1<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-17","alert_type":396,"serial_number":"AV17-061","subject":null,"moderation_state":"archived","external_url":null},{"nid":935,"title":"Mozilla Releases security updates","uuid":"2c74694a-5ec3-4834-96e1-c0707a5e513b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:45Z","date_created":"2018-07-03T19:48:58Z","summary":null,"body":["<article data-history-node-id=\"935\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-062<br \/>\nDate: 08 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Mozilla Firefox and Firefox ESR.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address a use after free vulnerability in the ANGLE graphics library, used for WebGL content in Firefox and Firefox ESR. \u00a0The severity of the issue is high.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 53.0.2<br \/>\nESR versions prior to 52.1.1<\/p>\n\n<p>CVE Reference:\u00a0 CVE-2017-5031<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-14\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-14\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-12","alert_type":396,"serial_number":"AV17-062","subject":null,"moderation_state":"archived","external_url":null},{"nid":823,"title":"Microsoft security updates","uuid":"493d3f17-189c-4f4e-8514-ef14130f93b8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:22Z","date_created":"2018-07-04T13:04:33Z","summary":null,"body":["<article data-history-node-id=\"823\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-063<br \/>\nDate: 9 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products (including Internet Explorer, Microsoft Edge, Microsoft Windows, Microsoft Office and Microsoft Office Services and Web Apps, NET Framework, Adobe Flash Player).<\/p>\n\n<p>CVE References: CVE-2017-0190, CVE-2017-0224, CVE-2017-0077, CVE-2017-0242, CVE-2017-0243, CVE-2017-0244, CVE-2017-0245, CVE-2017-0246, CVE-2017-0248, CVE-2017-0254, CVE-2017-0255, CVE-2017-0258, CVE-2017-0259, CVE-2017-0261, CVE-2017-0262, CVE-2017-0263, CVE-2017-0064, CVE-2017-0171, CVE-2017-0175, CVE-2017-0212, CVE-2017-0213, CVE-2017-0214, CVE-2017-0220, CVE-2017-0221, CVE-2017-0222, CVE-2017-0226, CVE-2017-0227, CVE-2017-0229, CVE-2017-0228, CVE-2017-0230, CVE-2017-0231, CVE-2017-0233, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, CVE-2017-0238, CVE-2017-0240, CVE-2017-0241, CVE-2017-0264, CVE-2017-0265, CVE-2017-0266, CVE-2017-0267, CVE-2017-0268, CVE-2017-0269, CVE-2017-0270, CVE-2017-0271, CVE-2017-0272, CVE-2017-0273, CVE-2017-0274, CVE-2017-0275, CVE-2017-0276, CVE-2017-0277, CVE-2017-0278, CVE-2017-0279, CVE-2017-0280, CVE-2017-0281.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/bc365363-f51e-e711-80da-000d3a32fc99\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/bc365363-f51e-e711-80da-000d3a32fc99<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-0","alert_type":396,"serial_number":"AV17-063","subject":null,"moderation_state":"archived","external_url":null},{"nid":1292,"title":"Microsoft Malware Protection Engine security update","uuid":"2592320d-fac5-4e7f-bcc1-1ce164f1c53b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:52Z","date_created":"2018-07-04T13:11:52Z","summary":null,"body":["<article data-history-node-id=\"1292\" about=\"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-064<br \/>\nDate: 9 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent security update to Microsoft Malware Protection Engine.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a critical vulnerability in the Microsoft Malware Protection Engine.\u00a0 Exploitation of this vulnerability may allow for remote code execution with elevated privileges.<\/p>\n\n<p>Affected Versions:<br \/>\nMicrosoft Malware Protection Engine version 1.1.13701.0 and prior<\/p>\n\n<p>CVE Reference:\u00a0 CVE-2017-0290<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/4022344\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/4022344<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1252&amp;desc=5\"><font color=\"#0066cc\">https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1252&amp;desc=5<\/font><\/a>\u00a0 \u00a0<\/li>\n\t<li><a href=\"https:\/\/arstechnica.com\/information-technology\/2017\/05\/windows-defender-nscript-remote-vulnerability\/\"><font color=\"#0066cc\">https:\/\/arstechnica.com\/information-technology\/2017\/05\/windows-defender-nscript-remote-vulnerability\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update","alert_type":396,"serial_number":"AV17-064","subject":null,"moderation_state":"archived","external_url":null},{"nid":967,"title":"Adobe security updates","uuid":"c03bc73a-982a-4a63-ae3b-710cd36e2d08","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:19Z","date_created":"2018-07-04T13:17:17Z","summary":null,"body":["<article data-history-node-id=\"967\" about=\"\/en\/alerts-advisories\/adobe-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-065<br \/>\nDate: 9 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released security update for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletin:<br \/>\nAPSB17-15 Security updates available for Adobe Flash Player<\/p>\n\n<p>CVE References:\u00a0<br \/>\nCVE-2017-3068, CVE-2017-3069, CVE-2017-3070, CVE-2017-3071, CVE-2017-3072, CVE-2017-3073, CVE-2017-3074<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Adobe Security Bulletin:<br \/>\nAPSB17-15: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-15.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-15.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates-1","alert_type":396,"serial_number":"AV17-065","subject":null,"moderation_state":"archived","external_url":null},{"nid":1329,"title":"Cisco security advisory","uuid":"773ca3a9-93c4-45ac-9db2-9481a5ca943b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:46Z","date_created":"2018-07-04T13:23:37Z","summary":null,"body":["<article data-history-node-id=\"1329\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-066<br \/>\nDate: 11 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released Cisco Security Advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has released a Security Advisory to address a critical vulnerability in its Cluster Management Protocol (CMP) processing code which exists in Cisco IOS and Cisco IOS XE Software. \u00a0Exploitation could allow a remote unauthenticated attacker to execute code and gain full control of an affected device.<\/p>\n\n<p>A full list of affected devices can be found in Cisco\u2019s Security Advisory.<\/p>\n\n<p>CVE Reference: CVE-2017-3881<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170317-cmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170317-cmp<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-2","alert_type":396,"serial_number":"AV17-066","subject":null,"moderation_state":"archived","external_url":null},{"nid":1026,"title":"Rockwell Automation Stratix 5900 security update","uuid":"241dc632-5d3a-437e-8511-26f7656ce2b2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-04T13:29:25Z","summary":null,"body":["<article data-history-node-id=\"1026\" about=\"\/en\/alerts-advisories\/rockwell-automation-stratix-5900-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-067<br \/>\nDate: 11 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released security update for the Stratix 5900.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation has released security updates to address 41 vulnerabilities in its Stratix 5900 industrial router products. The severity of the vulnerabilities range from high to critical, and exploitation could allow an unprivileged attacker to remotely execute code and\/or create denial of service conditions.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Stratix 5900 version 15.6.3 EA and earlier<\/li>\n<\/ul><p>CVE References: CVE-2016-6380, CVE-2016-6393, CVE-2016-6384, CVE-2016-6381, CVE-2016-6382,<br \/>\nCVE-2016-6415, CVE-2016-1409, CVE-2016-1350, CVE-2016-1344, CVE-2015-7691, CVE-2015-7692,<br \/>\nCVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7704, CVE-2015-7705, CVE-2015-7848,<br \/>\nCVE-2015-7849, CVE-2015-7850, CVE-2015-7851, CVE-2015-7852, CVE-2015-7853, CVE-2015-7854,<br \/>\nCVE-2015-7855, CVE-2015-7871, CVE-2015-1798,\u00a0CVE-2015-0642, CVE-2015-0643, CVE-2015-0646,<br \/>\nCVE-2015-0207, CVE-2015-0209, CVE-2015-0285, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289,<br \/>\nCVE-2015-0290, CVE-2015-0291, CVE-2015-0292, CVE-2015-0293, CVE-2015-1787, CVE-2014-3566,<br \/>\nCVE-2014-3359, CVE-2014-3355, CVE-2014-3361, CVE-2014-3354, CVE-2014-3360, CVE-2014-3299,<br \/>\nCVE-2010-5298, CVE-2014-0076, CVE-2014-0195, CVE-2014-0198, CVE-2014-0221, CVE-2014-0224,<br \/>\nCVE-2014-3470, CVE-2014-2113, CVE-2014-2108, CVE-2014-2109, CVE-2014-2111, CVE-2014-2106,<br \/>\nCVE-2014-2112<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected devices per your change management policies.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-094-04\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-094-04<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?famID=15\"><font color=\"#0066cc\">http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?famID=15<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/942592\"><font color=\"#0066cc\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/942592<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rockwell-automation-stratix-5900-security-update","alert_type":396,"serial_number":"AV17-067","subject":null,"moderation_state":"archived","external_url":null},{"nid":1140,"title":"Microsoft security updates MS17-010 - (SMBv1)","uuid":"cee011d6-9fca-408a-baab-cb5fa8e48523","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-04T13:36:00Z","summary":null,"body":["<article data-history-node-id=\"1140\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-ms17-010-smbv1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-068<br \/>\nDate: 13 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the release of a patch by Microsoft for end-of-life products recently impacted by a ransomware campaign known as \u201cWCry\u201d, \u201cWana\u201d, \u201cWCrypt\u201d, \u201cWanaDecryptor\u201d or \u201cWanaCry\u201d.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Over the past 48 hours this ransomware campaign has been exploiting vulnerabilities in what are considered to be Microsoft \u201ccustom support only\u201d products worldwide. \u00a0Microsoft has released a security update for all customers to protect the following vulnerable Windows platforms;<\/p>\n\n<ul><li>Windows XP,<\/li>\n\t<li>Windows 8<\/li>\n\t<li>Windows Server 2003<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Microsoft: Customer Guidance for WannaCrypt attacks<br \/><a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\/\"><font color=\"#0066cc\">https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\/<\/font><\/a><\/p>\n\n<p>Microsoft Security Bulletin MS17-010 - Critical<br \/>\nSecurity Update for Microsoft Windows SMB Server (4013389)<br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx<\/font><\/a><\/p>\n\n<p>Microsoft Malware Protection Center<br \/><a href=\"https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/Entry.aspx?Name=Ransom:Win32\/WannaCrypt\"><font color=\"#0066cc\">https:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/Entry.aspx?Name=Ransom:Win32\/WannaCrypt<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-ms17-010-smbv1","alert_type":396,"serial_number":"AV17-068","subject":null,"moderation_state":"archived","external_url":null},{"nid":1221,"title":"Apple security updates","uuid":"7d15b18b-d943-43e1-bb7b-d5c82d4e9a3d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:31Z","date_created":"2018-07-04T13:42:24Z","summary":null,"body":["<article data-history-node-id=\"1221\" about=\"\/en\/alerts-advisories\/apple-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-069<br \/>\nDate: 16 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iOS, macOS (Sierra, El Capitan, Yosemite) and Safari.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<ul><li>HT207595 - Safari 10.1.1<\/li>\n\t<li>HT207797 - macOS Sierra 10.12.4, OS X El Capitan 10.11.6, and OS X Yosemite 10.10.5<\/li>\n\t<li>HT207798 - iOS 10.3.2<\/li>\n<\/ul><p>This update addresses multiple vulnerabilities on the systems listed above.<\/p>\n\n<p>CVE Reference: CVE-2017-2494, CVE-2017-2495, CVE-2017-2496, CVE-2017-2497, CVE-2017-2498, CVE-2017-2499, CVE-2017-2501, CVE-2017-2502, CVE-2017-2503, CVE-2017-2504, CVE-2017-2505, CVE-2017-2506, CVE-2017-2507, CVE-2017-2508, CVE-2017-2509, CVE-2017-2510, CVE-2017-2512, CVE-2017-2513, CVE-2017-2514, CVE-2017-2515, CVE-2017-2516, CVE-2017-2518, CVE-2017-2519, CVE-2017-2520, CVE-2017-2521, CVE-2017-2524, CVE-2017-2525, CVE-2017-2526, CVE-2017-2527, CVE-2017-2528, CVE-2017-2530, CVE-2017-2531, CVE-2017-2533, CVE-2017-2534, CVE-2017-2535, CVE-2017-2536, CVE-2017-2537, CVE-2017-2538, CVE-2017-2539, CVE-2017-2540, CVE-2017-2541, CVE-2017-2542, CVE-2017-2543, CVE-2017-2544, CVE-2017-2545, CVE-2017-2546, CVE-2017-2547, CVE-2017-2548, CVE-2017-2549, CVE-2017-6977, CVE-2017-6978, CVE-2017-6979, CVE-2017-6980, CVE-2017-6981, CVE-2017-6982, CVE-2017-6983, CVE-2017-6984, CVE-2017-6985, CVE-2017-6986, CVE-2017-6987, CVE-2017-6988, CVE-2017-6989, CVE-2017-6990, CVE-2017-6991<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT207595\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207595<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207797\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207797<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT207798\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT207798<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates","alert_type":396,"serial_number":"AV17-069","subject":null,"moderation_state":"archived","external_url":null},{"nid":1303,"title":"WordPress security update","uuid":"e8760cf2-1977-439a-89ee-1a399bf7d2a4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-07-04T13:47:51Z","summary":null,"body":["<article data-history-node-id=\"1303\" about=\"\/en\/alerts-advisories\/wordpress-security-update-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-070<br \/>\nDate: 17 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.7.5 that contains security fixes to address multiple vulnerabilities including XSS and CSRF.<\/p>\n\n<p>Versions affected: WordPress 4.7.4 and earlier<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2017\/05\/wordpress-4-7-5\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2017\/05\/wordpress-4-7-5\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-1","alert_type":396,"serial_number":"AV17-070","subject":null,"moderation_state":"archived","external_url":null},{"nid":1088,"title":"Joomla! security update","uuid":"eac75f4a-3048-4ad9-b1ef-1d3cd1a1ec61","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:38Z","date_created":"2018-07-04T13:54:13Z","summary":null,"body":["<article data-history-node-id=\"1088\" about=\"\/en\/alerts-advisories\/joomla-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-071<br \/>\nDate: 18 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>Joomla! has released a new version that contains security fixes to address vulnerabilities in Joomla!<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.7.1 of its web content management system that contains a security fix to address a critical vulnerability.<\/p>\n\n<p>Versions affected: Joomla! 3.7.0 and earlier<\/p>\n\n<p>CVE Reference: CVE-2017-8917<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5705-joomla-3-7-1-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5705-joomla-3-7-1-release.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update","alert_type":396,"serial_number":"AV17-071","subject":null,"moderation_state":"archived","external_url":null},{"nid":846,"title":"Cisco Releases security updates","uuid":"d0766668-f639-4469-8ed8-b2d38faf7bb7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-07-04T14:00:25Z","summary":null,"body":["<article data-history-node-id=\"846\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-18\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-072<br \/>\nDate: 20 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (critical to medium) in the following products.\u00a0<\/p>\n\n<ul><li>Cisco Identity Services Engine GUI Denial of Service Vulnerability<\/li>\n\t<li>Cisco Industrial Ethernet 1000 Series Switches Device Manager Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Authentication Bypass Vulnerability<\/li>\n\t<li>Cisco Policy Suite Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability<\/li>\n\t<li>Cisco TelePresence IX5000 Series Directory Traversal Vulnerability<\/li>\n\t<li>Cisco FirePOWER System Software SSL Logging Denial of Service Vulnerability<\/li>\n\t<li>Cisco Snort++ Protocol Decoder Denial of Service Vulnerabilities<\/li>\n\t<li>Cisco Nexus 5000 Series Switches CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco Nexus 5000 Series Switches Telnet CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Directory Traversal Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Directory Traversal Arbitrary File Deletion Vulnerability<\/li>\n\t<li>Cisco Remote Expert Manager Denial of Service Vulnerability<\/li>\n\t<li>Cisco Remote Expert Manager Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Remote Expert Manager Virtual Directory Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Remote Expert Manager Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Remote Expert Manager Virtual Temporary Directory Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Remote Expert Manager Order Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Remote Expert Manager Temporary File Information Disclosure Vulnerability<\/li>\n\t<li>Cisco IP Phone 8851 Session Initiation Protocol Denial of Service Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco UCS C-Series Rack Servers TCP Port Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References:<br \/>\nCritical Impact CVE: CVE-2017-6622<br \/>\nHigh Impact CVE: CVE-2017-6623, CVE-2017-6621, CVE-2017-6652<br \/>\nMedium Impact CVEs: CVE-2017-6634, CVE-2017-6632, CVE-2017-6653, CVE-2017-6657, CVE-2017-6658, CVE-2017-6649, CVE-2017-6650, CVE-2017-6635, CVE-2017-6636, CVE-2017-6637, CVE-2017-6641, CVE-2017-6642, CVE-2017-6643, CVE-2017-6644, CVE-2017-6645, CVE-2017-6646, CVE-2017-6647, CVE-2017-6630, CVE-2017-6654, CVE-2017-6633<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-cps\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-cps<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-telepresence-ix5000\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-telepresence-ix5000<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ie1000csrf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ie1000csrf<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ise<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-fpwr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-fpwr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170515-snort\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170515-snort<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-nss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-nss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp5\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-pcp5<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem5\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem5<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem6\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem6<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem7\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-rem7<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-sip\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-sip<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ucsc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-ucsc<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-18","alert_type":396,"serial_number":"AV17-072","subject":null,"moderation_state":"archived","external_url":null},{"nid":1048,"title":"Samba security update","uuid":"d688d5b3-fea3-450f-acbc-e3d6cb9571ac","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-07-04T14:34:56Z","summary":null,"body":["<article data-history-node-id=\"1048\" about=\"\/en\/alerts-advisories\/samba-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-073<br \/>\nDate: 25 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Samba.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Samba has released version 4.7.5 that contains security fixes to address a vulnerability.\u00a0 Exploitation of this vulnerability could allow a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Samba 3.5.0 to 4.6.3 (for versions 4.6.x)<\/li>\n\t<li>Samba 3.5.0 to 4.5.9 (for versions 4.5.x)<\/li>\n\t<li>Samba 3.5.0 to 4.4.13 (for versions 4.4.x)<\/li>\n<\/ul><p>CVE Reference: CVE-2017-7494<\/p>\n\n<p>Special consideration and review should be conducted for internet connected devices which may be leveraging vulnerable versions of Samba, including but not limited to: DVRs, routers and IP cameras.\u00a0 These types of devices typically can only be updated via vendor released firmware updates.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/lists.samba.org\/archive\/samba-announce\/2017\/000406.html\"><font color=\"#0066cc\">https:\/\/lists.samba.org\/archive\/samba-announce\/2017\/000406.html<\/font><\/a><br \/><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2017-7494.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2017-7494.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-update","alert_type":396,"serial_number":"AV17-073","subject":null,"moderation_state":"archived","external_url":null},{"nid":784,"title":"Rockwell Automation AllenBradley MicroLogix security update","uuid":"b9a3de8e-ba67-4b39-9169-1b814faa96f6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:35Z","date_created":"2018-07-04T14:42:12Z","summary":null,"body":["<article data-history-node-id=\"784\" about=\"\/en\/alerts-advisories\/rockwell-automation-allenbradley-micrologix-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-074<br \/>\nDate: 25 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released security update for the AllenBradley MicroLogix 1100 and 1400 programmablelogic controller products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation has released a security update to address 5 vulnerabilities in its AllenBradley MicroLogix 1100 and 1400 programmablelogic controller products. The severity of the vulnerabilities in range from medium to critical, and exploitation could allow an unprivileged attacker to remotely execute code and\/or create denial of service conditions.<\/p>\n\n<p>Affected software versions (AllenBradley MicroLogix 1100):<\/p>\n\n<ul><li>1763L16AWA, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1763L16BBB, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1763L16BWA, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1763L16DWD, Series A and B, Version 16.00 and prior versions<\/li>\n<\/ul><p>Affected software versions (AllenBradley MicroLogix 1400):<\/p>\n\n<ul><li>1766L32AWA, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1766L32BWA, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1766L32BWAA, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1766L32BXB, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1766L32BXBA, Series A and B, Version 16.00 and prior versions<\/li>\n\t<li>1766L32AWAA, Series A and B, Version 16.00 and prior versions<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE20177898, CVE20177899, CVE20177901, CVE20177902, CVE20177903<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendorreleased updates to affected devices per your change management policies.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-115-04\"><font color=\"#0066cc\">https:\/\/icscert.uscert.gov\/advisories\/ICSA1711504<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=1766-Lxx&amp;crumb=112\"><font color=\"#0066cc\">http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=1766Lxx&amp;crumb=112<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/732398\"><font color=\"#0066cc\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/732398<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rockwell-automation-allenbradley-micrologix-security-update","alert_type":396,"serial_number":"AV17-074","subject":null,"moderation_state":"archived","external_url":null},{"nid":1238,"title":"Microsoft Malware Protection Engine security update","uuid":"9bd783ba-035c-485d-b8b8-78af97e8cd99","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:39Z","date_created":"2018-07-04T14:48:59Z","summary":null,"body":["<article data-history-node-id=\"1238\" about=\"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-075<br \/>\nDate: 30 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent security update to Microsoft Malware Protection Engine.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a critical vulnerability in the Microsoft Malware Protection Engine.\u00a0 Exploitation of this vulnerability may allow for remote code execution with elevated privileges and\/or create denial of service conditions.<\/p>\n\n<p>Affected Versions: \u00a0Microsoft Malware Protection Engine version 1.1.13704.0 and prior<\/p>\n\n<p>CVE References: CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, CVE-2017-8538, CVE-2017-8539,<br \/>\nCVE-2017-8540, CVE-2017-8541, CVE-2017-8542<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8535\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8535<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8536\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8536<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8537\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8537<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8538\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8538<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8539\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8539<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8540\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8540<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8541\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8541<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8542\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8542<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update-0","alert_type":396,"serial_number":"AV17-075","subject":null,"moderation_state":"archived","external_url":null},{"nid":1265,"title":"Wireshark Releases security updates","uuid":"527136e2-b06e-4551-a63c-a44f80be637d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:27Z","date_created":"2018-07-04T14:54:53Z","summary":null,"body":["<article data-history-node-id=\"1265\" about=\"\/en\/alerts-advisories\/wireshark-releases-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-076<br \/>\nDate: 06 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Wireshark.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The current stable release of Wireshark has been updated to version 2.2.7 and old stable release to version 2.0.13. Those updates address multiple vulnerabilities in Wireshark.<\/p>\n\n<p>Affected Versions:<br \/>\nWireshark versions 2.2.0 to 2.2.12 and 2.0.0 to 2.0.12<\/p>\n\n<p>CVE References:<br \/>\nCVE-2017-9343, CVE-2017-9344, CVE-2017-9345, CVE-2017-9346, CVE-2017-9347, CVE-2017-9348,<br \/>\nCVE-2017-9349, CVE-2017-9350, CVE-2017-9351, CVE-2017-9352, CVE-2017-9353, CVE-2017-9354<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-22.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-22.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-23.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-23.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-24.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-24.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-25.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-25.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-26.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-26.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-27.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-27.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-28.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-28.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-29.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-29.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-30.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-30.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-31.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-31.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-32.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-32.html<\/font><\/a><br \/><a href=\"https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-33.html\"><font color=\"#0066cc\">https:\/\/www.wireshark.org\/security\/wnpa-sec-2017-33.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wireshark-releases-security-updates","alert_type":396,"serial_number":"AV17-076","subject":null,"moderation_state":"archived","external_url":null},{"nid":1111,"title":"Google Releases security update for Chrome","uuid":"3cd07a8b-706d-42ef-b537-48de40a9a7be","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-07-04T15:00:48Z","summary":null,"body":["<article data-history-node-id=\"1111\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-22\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-077<br \/>\nDate: 06 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 59.0.3071.86 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: \u00a0CVE-2017-5070, CVE-2017-5071, CVE-2017-5072, CVE-2017-5073, CVE-2017-5074, CVE-2017-5075, CVE-2017-5086, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078, CVE-2017-5079, CVE-2017-5080, CVE-2017-5081, CVE-2017-5082, CVE-2017-5083, CVE-2017-5085<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/06\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/06\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-22","alert_type":396,"serial_number":"AV17-077","subject":null,"moderation_state":"archived","external_url":null},{"nid":937,"title":"[Control systems] Rockwell Automation Security Vulnerability","uuid":"fcb5da33-a7d9-4e35-9fb8-68c153cacbf1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:45Z","date_created":"2018-07-04T15:08:20Z","summary":null,"body":["<article data-history-node-id=\"937\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-078<br \/>\nDate: 08 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently discovered vulnerability to Rockwell Automation PanelView Plus 6 700-1500 graphic terminals and logic module products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation has issued a security advisory concerning its PanelView Plus 6 700-1500 graphic terminals and logic module products. Rockwell Automation PanelView Plus terminals and logic module products do not perform an authorization check on connection requests to TCP port 44818 and UDP 2222. This may allow remote retrieval of data and potential disruption of service.<\/p>\n\n<p>Affected versions of PanelView Plus 6 700-1500:<\/p>\n\n<ul><li>6.00.04,<\/li>\n\t<li>6.00.05,<\/li>\n\t<li>6.00.42,<\/li>\n\t<li>6.00-20140306,<\/li>\n\t<li>6.10.20121012,<\/li>\n\t<li>6.10-20140122,<\/li>\n\t<li>7.00-20121012,<\/li>\n\t<li>7.00-20130108,<\/li>\n\t<li>7.00-20130325,<\/li>\n\t<li>7.00-20130619,<\/li>\n\t<li>7.00-20140128,<\/li>\n\t<li>7.00-20140310,<\/li>\n\t<li>7.00-20140429,<\/li>\n\t<li>7.00-20140621,<\/li>\n\t<li>7.00-20140729,<\/li>\n\t<li>7.00-20141022,<\/li>\n\t<li>8.00-20140730,<\/li>\n\t<li>8.00-20141023<\/li>\n<\/ul><p>This vulnerability does not affect graphic terminals running OS 2.31 or greater.<\/p>\n\n<p>CVE Reference: CVE-2017-7914<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released firmware updates that address this vulnerability at your earliest convenience:<\/p>\n\n<ul><li>V7.00: Apply V7.00-20150209<\/li>\n\t<li>V8.00: Apply V8.00-20160418<\/li>\n\t<li>V8.10: Apply V8.10-20151026 or later<\/li>\n\t<li>V8.20: Apply V8.20-20160308 or later<\/li>\n\t<li>V9.00: Apply V9.00-20170328 or later<\/li>\n<\/ul><p>Please consult ICS-CERT and manufacturer advisories for additional mitigation advice.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-157-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-157-01<\/font><\/a><br \/><a href=\"http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=2711P&amp;crumb=112\"><font color=\"#0066cc\">http:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=2711P&amp;crumb=112<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-vulnerability","alert_type":398,"serial_number":"AV17-078","subject":null,"moderation_state":"archived","external_url":null},{"nid":825,"title":"VMware security updates","uuid":"309c81da-f14e-4e59-aedc-5c0df8b44788","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:22Z","date_created":"2018-07-04T15:14:28Z","summary":null,"body":["<article data-history-node-id=\"825\" about=\"\/en\/alerts-advisories\/vmware-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-079<br \/>\nDate: 08 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for VMware vSphere Data Protection.<\/p>\n\n<p>Affected Products:<br \/>\nvSphere Data Protection Versions:\u00a0 5.5.x; 5.8.x; 6.0.x; 6.1.x<\/p>\n\n<p>CVE Reference: CVE-2017-4914, CVE-2017-4917<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0010.html\"><font color=\"#0066cc\">http:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0010.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-3","alert_type":396,"serial_number":"AV17-079","subject":null,"moderation_state":"archived","external_url":null},{"nid":1294,"title":"Adobe security updates","uuid":"058de5b6-b63a-4836-8d8a-31a70ce01a05","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:00:52Z","date_created":"2018-07-04T15:26:08Z","summary":null,"body":["<article data-history-node-id=\"1294\" about=\"\/en\/alerts-advisories\/adobe-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-080<br \/>\nDate: 13 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security updates for various Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<\/p>\n\n<p>APSB17-17 Security updates available for Adobe Flash Player<br \/>\nAPSB17-18 Security updates available for Adobe Shockwave Player<br \/>\nAPSB17-19 Security updates available for Adobe Captivate<br \/>\nAPSB17-20 Security update available for Adobe Digital Editions<\/p>\n\n<p>CVE References:\u00a0<br \/>\nCVE-2017-3075, CVE-2017-3081, CVE-2017-3083, CVE-2017-3084, CVE-2017-3076, CVE-2017-3077, CVE-2017-3078, CVE-2017-3079, CVE-2017-3082, CVE-2017-3086, CVE-2017-3087, CVE-2017-3088, CVE-2017-3089, CVE-2017-3093, CVE-2017-3096, CVE-2017-3090, CVE-2017-3092, CVE-2017-3097, CVE-2017-3094, CVE-2017-3095<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>APSB17-17: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-17.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-17.html<\/font><\/a><br \/>\nAPSB17-18: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/shockwave\/apsb17-18.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/shockwave\/apsb17-18.html<\/font><\/a><br \/>\nAPSB17-19: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/captivate\/apsb17-19.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/captivate\/apsb17-19.html<\/font><\/a><br \/>\nAPSB17-20: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-20.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-20.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates-2","alert_type":396,"serial_number":"AV17-080","subject":null,"moderation_state":"archived","external_url":null},{"nid":969,"title":"Microsoft security updates","uuid":"4bed1e93-da7f-4880-ab6d-9b3a63f6eebe","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:19Z","date_created":"2018-07-04T15:32:58Z","summary":null,"body":["<article data-history-node-id=\"969\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-081<br \/>\nDate: 13 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products (including Internet Explorer, Microsoft Edge, Microsoft Windows, Microsoft Office and Microsoft Office Services and Web Apps, Silverlight, Skype for Business and Lync, Adobe Flash Player).<\/p>\n\n<p>As part of this set of security updates, Microsoft has also released updates addressing critical vulnerabilities in some older unsupported versions of Windows.\u00a0 This is due to an increased threat of exploitation based on recent attacks and disclosures.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/library\/security\/4025685.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/library\/security\/4025685.aspx<\/font><\/a><br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4025686\/microsoft-security-advisory-4025685-guidance-for-supported-platforms\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4025686\/microsoft-security-advisory-4025685-guidance-for-supported-platforms<\/font><\/a><br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4025687\/microsoft-security-advisory-4025685-guidance-for-older-platforms\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4025687\/microsoft-security-advisory-4025685-guidance-for-older-platforms<\/font><\/a><br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4025688\/microsoft-security-advisory-4025685-guidance-for-embedded-platforms\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4025688\/microsoft-security-advisory-4025685-guidance-for-embedded-platforms<\/font><\/a><br \/><a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/06\/13\/june-2017-security-update-release\/\"><font color=\"#0066cc\">https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/06\/13\/june-2017-security-update-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-1","alert_type":396,"serial_number":"AV17-081","subject":null,"moderation_state":"archived","external_url":null},{"nid":1331,"title":"Mozilla Releases security updates","uuid":"a1c57dab-9bd1-4a20-8c82-e87fbe95441a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:46Z","date_created":"2018-07-04T15:41:20Z","summary":null,"body":["<article data-history-node-id=\"1331\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-updates-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-082<br \/>\nDate: 14 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Mozilla Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 24 vulnerabilities in Firefox. The severity of these issues ranges from moderate to critical.<\/p>\n\n<p>Version affected:<br \/>\nFirefox versions prior to 54<\/p>\n\n<p>CVE References:\u00a0 CVE-2017-5472, CVE-2017-5470, CVE-2017-7749, CVE-2017-7750, CVE-2017-7751, CVE-2017-7752, CVE-2017-7754, CVE-2017-7755, CVE-2017-7756, CVE-2017-7757, CVE-2017-7758, CVE-2017-7759, CVE-2017-7760, CVE-2017-7761, CVE-2017-7762, CVE-2017-7763, CVE-2017-7764, CVE-2017-7765, CVE-2017-7766, CVE-2017-7767, CVE-2017-7768, CVE-2017-7770, CVE-2017-7771, CVE-2017-7778.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-15\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-15<\/font><\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/firefox\/54.0\/releasenotes\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/firefox\/54.0\/releasenotes\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-updates-13","alert_type":396,"serial_number":"AV17-082","subject":null,"moderation_state":"archived","external_url":null},{"nid":1028,"title":"Security fixes released for BIND","uuid":"99b53f7f-9b3e-4e4e-8720-925861acd00d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-04T15:47:19Z","summary":null,"body":["<article data-history-node-id=\"1028\" about=\"\/en\/alerts-advisories\/security-fixes-released-bind-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-083<br \/>\nDate: 15 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released updates that address two vulnerabilities in BIND and an Operational Notification. The vulnerabilities have a severity between Medium and Critical.<\/p>\n\n<p>Version Affected:<br \/>\n9.2.6-P2-&gt;9.2.9, 9.3.2-P1-&gt;9.3.6, 9.4.0-&gt;9.8.8, 9.9.0-&gt;9.9.10, 9.10.0-&gt;9.10.5, 9.11.0-&gt;9.11.1, 9.9.3-S1-&gt;9.9.10-S1<\/p>\n\n<p>CVE References: CVE-2017-3141, CVE-2017-3140<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01497\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01497<\/font><\/a><br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01496\/74\/CVE-2017-3141\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01496\/74\/CVE-2017-3141<\/font><\/a><br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01495\/74\/CVE-2017-3140\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01495\/74\/CVE-2017-3140<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-released-bind-4","alert_type":396,"serial_number":"AV17-083","subject":null,"moderation_state":"archived","external_url":null},{"nid":1141,"title":"Cambium Networks ePMP security update","uuid":"a413926b-e8cd-443a-9f1f-b66c4fccd832","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-04T15:52:55Z","summary":null,"body":["<article data-history-node-id=\"1141\" about=\"\/en\/alerts-advisories\/cambium-networks-epmp-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-084<br \/>\nDate: 16 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Cambium Networks ePMP security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cambium Networks has released a product update addressing security issues for ePMP products. Successful exploitation of these vulnerabilities may allow an attacker to gain unauthorized access to and modify a device\u2019s configuration.<\/p>\n\n<p>Affected Products: ePMP Network Access Control products (all models) version 3.4-RC6 and earlier<\/p>\n\n<p>CVE References: CVE-2017-7918, CVE-2017-7922<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-166-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-166-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cambium-networks-epmp-security-update","alert_type":396,"serial_number":"AV17-084","subject":null,"moderation_state":"archived","external_url":null},{"nid":1223,"title":"OpenVPN security updates","uuid":"6abc9922-c5a6-43b8-9c1b-40e8a535aef1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:31Z","date_created":"2018-07-04T15:58:19Z","summary":null,"body":["<article data-history-node-id=\"1223\" about=\"\/en\/alerts-advisories\/openvpn-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-085<br \/>\nDate: 21 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for OpenVPN.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>OpenVPN has released the new versions 2.4.3 and 2.3.17 that contain security updates to address multiple vulnerabilities.<\/p>\n\n<p>Affected Versions:<br \/>\n- OpenVPN versions 2.3.16 and prior<br \/>\n- OpenVPN versions 2.4.2 and prior<\/p>\n\n<p>CVE References:<\/p>\n\n<p>CVE-2017-7508, CVE-2017-7512, CVE-2017-7520, CVE-2017-7521, CVE-2017-7522<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/forums.openvpn.net\/viewtopic.php?f=20&amp;t=24347\"><font color=\"#0066cc\">https:\/\/forums.openvpn.net\/viewtopic.php?f=20&amp;t=24347<\/font><\/a><br \/><a href=\"https:\/\/community.openvpn.net\/openvpn\/wiki\/VulnerabilitiesFixedInOpenVPN243\"><font color=\"#0066cc\">https:\/\/community.openvpn.net\/openvpn\/wiki\/VulnerabilitiesFixedInOpenVPN243<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openvpn-security-updates","alert_type":396,"serial_number":"AV17-085","subject":null,"moderation_state":"archived","external_url":null},{"nid":1305,"title":"Drupal security updates","uuid":"e91474b3-f40b-4c58-802d-d7f4ace65ea4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-07-04T17:16:33Z","summary":null,"body":["<article data-history-node-id=\"1305\" about=\"\/en\/alerts-advisories\/drupal-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-086<br \/>\nDate: 22 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Drupal security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple security vulnerabilities. An attacker can exploit those vulnerabilities to execute arbitrary code in the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Drupal core 7.x versions prior to 7.56<\/li>\n\t<li>Drupal core 8.x versions prior to 8.3.4<\/li>\n<\/ul><p>CVE Reference: CVE-2017-6920, CVE-2017-6921, CVE-2017-6922<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/SA-CORE-2017-003\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/SA-CORE-2017-003<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-updates-1","alert_type":396,"serial_number":"AV17-086","subject":null,"moderation_state":"archived","external_url":null},{"nid":1090,"title":"VMware Horizon View security update","uuid":"7bd14dd8-25f0-4400-b91a-a9cc361d1d27","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:38Z","date_created":"2018-07-04T17:22:24Z","summary":null,"body":["<article data-history-node-id=\"1090\" about=\"\/en\/alerts-advisories\/vmware-horizon-view-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-087<br \/>\nDate: 22 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released a security update for Horizon View Client for Mac to address a command injection vulnerability.\u00a0 Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed.<\/p>\n\n<p>Affected Product:<br \/>\nVMware Horizon View Client (Mac OSX) versions prior to 4.5<\/p>\n\n<p>CVE Reference: CVE-2017-4918<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0011.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0011.html<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-4918\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-4918<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-horizon-view-security-update","alert_type":396,"serial_number":"AV17-087","subject":null,"moderation_state":"archived","external_url":null},{"nid":842,"title":"Cisco Releases security updates","uuid":"fac0f9b0-f186-42c5-92a2-37b056f8e68f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:36Z","date_created":"2018-07-04T17:47:12Z","summary":null,"body":["<article data-history-node-id=\"842\" about=\"\/en\/alerts-advisories\/cisco-releases-security-updates-19\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-088<br \/>\nDate: 22 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (High Impact) in the following products. \u00a0In each instance, a remote attacker could exploit one of these vulnerabilities and take control of a system.<\/p>\n\n<ul><li>Cisco Prime Infrastructure: Versions 1.1 through 3.1.6<\/li>\n\t<li>Cisco WebEx Business Suite (WBS29) client builds prior to T29.13.130<\/li>\n\t<li>Cisco WebEx Business Suite (WBS30) client builds prior to T30.17<\/li>\n\t<li>Cisco WebEx Business Suite (WBS31) client builds prior to T31.10<\/li>\n\t<li>Cisco Virtualized Packet Core\u2212Distributed Instance (VPC\u2212DI) Software<\/li>\n<\/ul><p>CVE References:<\/p>\n\n<p>CVE-2017-6662, CVE-2017-6669, CVE-2017-6678<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170621-piepnm1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170621-piepnm1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170621-wnrp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170621-wnrp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170621-vpc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170621-vpc<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-releases-security-updates-19","alert_type":396,"serial_number":"AV17-088","subject":null,"moderation_state":"archived","external_url":null},{"nid":1060,"title":"Microsoft Malware Protection Engine security update","uuid":"e9587d94-5d8f-4d9b-84d1-a7dec9e086c1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:18:06Z","date_created":"2018-07-04T17:52:19Z","summary":null,"body":["<article data-history-node-id=\"1060\" about=\"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-089<br \/>\nDate: 26 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent security update to Microsoft Malware Protection Engine.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a critical vulnerability in the Microsoft Malware Protection Engine.\u00a0 Exploitation of this vulnerability may allow for remote code execution.<\/p>\n\n<p>Affected Versions:\u00a0 Microsoft Malware Protection Engine version 1.1.13804.0 and prior<\/p>\n\n<p>CVE Reference: CVE-2017-8558<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8558\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-8558<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update-1","alert_type":396,"serial_number":"AV17-089","subject":null,"moderation_state":"archived","external_url":null},{"nid":786,"title":"Cisco Product Vulnerabilities","uuid":"346fda0c-0d27-42b4-8782-93c9000207ab","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:39Z","date_created":"2018-07-04T17:57:13Z","summary":null,"body":["<article data-history-node-id=\"786\" about=\"\/en\/alerts-advisories\/cisco-product-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-090<br \/>\nDate: 29 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Cisco security vulnerabilities.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released advisories to notify on vulnerabilities discovered in the following products.\u00a0 In these instances a remote attacker could execute code and take control of the system.<\/p>\n\n<p>-\u00a0 SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software<br \/>\n-\u00a0 Cisco Context Service software development kit<\/p>\n\n<p>CVE References: CVE-2017-6667, CVE-2017-6736, CVE-2017-6737, CVE-2017-6738, CVE-2017-6739, CVE-2017-6740, CVE-2017-6741, CVE-2017-6742, CVE-2017-6743, CVE-2017-6744<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly to remediate this vulnerability.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170607-ccs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170607-ccs<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170629-snmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170629-snmp<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-product-vulnerabilities","alert_type":396,"serial_number":"AV17-090","subject":null,"moderation_state":"archived","external_url":null},{"nid":1239,"title":"Security fixes released for BIND","uuid":"eeab19fc-1053-4452-9d1d-060c077b25fb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:39Z","date_created":"2018-07-04T18:02:33Z","summary":null,"body":["<article data-history-node-id=\"1239\" about=\"\/en\/alerts-advisories\/security-fixes-released-bind-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-091<br \/>\nDate: 30 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security fixes for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released updates addressing two vulnerabilities in BIND. Exploitation of these vulnerabilities may allow a remote attacker to gain unauthorized dynamic updates and zone transfers.<\/p>\n\n<p>Version Affected: 9.4.0-&gt;9.8.8, 9.9.0-&gt;9.9.10-P1, 9.10.0-&gt;9.10.5-P1, 9.11.0-&gt;9.11.1-P1, 9.9.3-S1-&gt;9.9.10-S2, 9.10.5-S1-&gt;9.10.5-S2<\/p>\n\n<p>CVE References: CVE-2017-3142, CVE-2017-3143<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01504\/74\/CVE-2017-3142\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01504\/74\/CVE-2017-3142<\/font><\/a><br \/><a href=\"https:\/\/kb.isc.org\/article\/AA-01503\/74\/CVE-2017-3143\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01503\/74\/CVE-2017-3143<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fixes-released-bind-5","alert_type":396,"serial_number":"AV17-091","subject":null,"moderation_state":"archived","external_url":null},{"nid":1275,"title":"[Control systems] Siemens security updates","uuid":"8dde5de1-2fa9-4e15-9518-a3d0e7f5db7f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:23:29Z","date_created":"2018-07-04T18:08:31Z","summary":null,"body":["<article data-history-node-id=\"1275\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-092<br \/>\nDate: 30 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Siemens released security updates for Viewport for Web Office Portal and, SIMATIC Industrial PCs, SINUMERIK Panel Control Unit, and SIMOTION P320 to address multiple vulnerabilities.\u00a0 A remote attacker could potentially exploit these vulnerabilities to upload and execute arbitrary code and gain system privileges.<\/p>\n\n<p>Affected versions:<\/p>\n\n<ul><li>ViewPort for Web Office Portal: versions prior to revision number 1453<\/li>\n\t<li>SIMATIC Industrial PCs<\/li>\n\t<li>SINUMERIK Panel Control Unit (PCU)<\/li>\n\t<li>SIMOTION P320<\/li>\n<\/ul><p>Please see Siemens Security Advisory SSA-874235 for the full list of affected versions.<\/p>\n\n<p>CVE References: CVE-2017-5689, CVE-2017-6869<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. For more information, please refer to the ICS-CERT references.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>SIEMENS Security Advisory SSA-545214:<br \/><a href=\"https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-545214.pdf\"><font color=\"#0066cc\">https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-545214.pdf<\/font><\/a><\/p>\n\n<p>Siemens Security Advisory SSA-874235:<br \/><a href=\"https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-874235.pdf\"><font color=\"#0066cc\">https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-874235.pdf<\/font><\/a> \u00a0<br \/><br \/>\nICS-CERT Advisory (ICSA-17-180-03):<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-180-03\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-180-03<\/font><\/a> \u00a0<\/p>\n\n<p>ICS-CERT Advisory (ICSA-17-180-01):<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-180-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-180-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-updates","alert_type":398,"serial_number":"AV17-092","subject":null,"moderation_state":"archived","external_url":null},{"nid":1113,"title":"Cisco security updates","uuid":"ccb38910-22ef-47d6-a3e2-3dcd05943e0e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:20Z","date_created":"2018-07-04T18:21:40Z","summary":null,"body":["<article data-history-node-id=\"1113\" about=\"\/en\/alerts-advisories\/cisco-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-094<br \/>\nDate: 6 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<ul><li>Cisco Elastic Services Controller<\/li>\n\t<li>Cisco FireSIGHT System Software<\/li>\n\t<li>Cisco Identity Services Engine<\/li>\n\t<li>Cisco IOS XR Software<\/li>\n\t<li>Cisco Nexus Series Switches<\/li>\n\t<li>Cisco Prime Network<\/li>\n\t<li>Cisco StarOS Border Gateway Protocol<\/li>\n\t<li>Cisco Ultra Services Framework<\/li>\n\t<li>Cisco Wide Area Application Services<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE20176649, CVE20176650, CVE20176707, CVE20176708, CVE20176709, CVE20176711,<br \/>\nCVE20176712, CVE20176713, CVE20176714, CVE20176726, CVE20176727, CVE20176728,<br \/>\nCVE20176729, CVE20176730, CVE20176731, CVE20176732, CVE20176733, CVE20176734,<br \/>\nCVE20176735<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendorreleased updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-esc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705esc1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-esc2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705esc2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-FireSIGHT\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705FireSIGHT<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-ise1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705ise1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-ise2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705ise2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-ios\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705ios<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-iosxr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705iosxr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-nss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170517nss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-nss1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170517nss1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-prime\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705prime<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-cpn\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705cpn<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-asrcmd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705asrcmd<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-staros\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705staros<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-uas\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705uas<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-usf1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705usf1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-usf2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705usf2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-usf3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705usf3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-waas\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705waas<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170705-waas1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/ciscosa20170705waas1<\/font><\/a> \u00a0\u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates","alert_type":396,"serial_number":"AV17-094","subject":null,"moderation_state":"archived","external_url":null},{"nid":939,"title":"Joomla! security update","uuid":"1072dfb8-40cb-4f4d-9d0c-0f2102a437de","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:01Z","date_created":"2018-07-04T18:30:29Z","summary":null,"body":["<article data-history-node-id=\"939\" about=\"\/en\/alerts-advisories\/joomla-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-095<br \/>\nDate: 06 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.7.3 of its web content management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected: Joomla! 3.7.x versions 3.7.2 and earlier<\/p>\n\n<p>CVE References: CVE-2017-7985, CVE-2017-9933, CVE-2017-9934<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5709-joomla-3-7-3-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5709-joomla-3-7-3-release.html<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update-0","alert_type":396,"serial_number":"AV17-095","subject":null,"moderation_state":"archived","external_url":null},{"nid":750,"title":"PHP security updates","uuid":"352a6936-3d6d-43c5-8511-dcee31a7ff2c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:16Z","date_created":"2018-07-04T18:35:58Z","summary":null,"body":["<article data-history-node-id=\"750\" about=\"\/en\/alerts-advisories\/php-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-096<br \/>\nDate: 7 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple PHP security updates<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>PHP has released multiple security updates covering various vulnerabilities.\u00a0 Those updates include patches to address vulnerabilities which could potentially allow an attacker to perform remote code execution.<\/p>\n\n<p>Versions affected:<br \/>\nPHP 5.6.x versions 5.6.30 and earlier<br \/>\nPHP 7.0.x versions 7.0.20 and earlier<br \/>\nPHP 7.1.x versions 7.1.7 and earlier<\/p>\n\n<p>CVE References: CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends organizations consult with vendors for confirmation on whether their products and\/or service providers are utilizing vulnerable versions of PHP.\u00a0 As vendor-released updates become available, organizations should test and deploy updates to affected applications\/platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/php.net\/ChangeLog-5.php\"><font color=\"#0066cc\">http:\/\/php.net\/ChangeLog-5.php<\/font><\/a> \u00a0\u00a0<br \/><a href=\"http:\/\/php.net\/ChangeLog-7.php\"><font color=\"#0066cc\">http:\/\/php.net\/ChangeLog-7.php<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-updates-1","alert_type":396,"serial_number":"AV17-096","subject":null,"moderation_state":"archived","external_url":null},{"nid":828,"title":"[Control systems] Siemens SIPROTEC 4 and SIPROTEC Compact Vulnerability","uuid":"5973b994-0730-4808-b32c-24585bd75cc2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-04T18:54:18Z","summary":null,"body":["<article data-history-node-id=\"828\" about=\"\/en\/alerts-advisories\/control-systems-siemens-siprotec-4-and-siprotec-compact-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-097<br \/>\nDate: 10 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently disclosed vulnerability in Siemens SIPROTEC 4 and SIPROTEC Compact products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Multiple vulnerabilities were identified in Siemens SIPROTEC 4 and SIPROTEC Compact products. Exploitation of these vulnerabilities could allow an attacker to perform a denial-of-service attack under certain conditions.<\/p>\n\n<p>Affected Products:<br \/>\nFirmware versions for EN100 Ethernet modules as optional for SIPROTEC 4 and SIPROTEC Compact:<\/p>\n\n<ul><li>Firmware version PROFINET IO version V1.04.01 and earlier<\/li>\n\t<li>Firmware version Modbus TCP<\/li>\n\t<li>Firmware version DNP3 TCP<\/li>\n\t<li>Firmware version IEC 104<\/li>\n<\/ul><p>EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 version V1.02.02 and earlier<br \/>\nSIPROTEC 7SJ66 version V4.23 and earlier<br \/>\nSIPROTEC 7SJ686 version V4.86 and earlier<br \/>\nSIPROTEC 7UT686 version V4.01 and earlier<br \/>\nSIPROTEC 7SD686 version V4.04 and earlier<br \/>\nSIPROTEC 7SJ66, 7SD686, 7SJ686 and 7UT686<\/p>\n\n<p>CVE References: CVE-2015-5374, CVE-2016-4784, CVE-2016-4785, CVE-2016-7112, CVE-2016-7113, CVE-2016-7114<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-323211.pdf\"><font color=\"#0066cc\">https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-323211.pdf<\/font><\/a><br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-187-03\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-187-03<\/font><\/a><br \/><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2012\/tr12-002-en.aspx\"><font color=\"#0066cc\">https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2012\/tr12-002-en.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-siprotec-4-and-siprotec-compact-vulnerability","alert_type":398,"serial_number":"AV17-097","subject":null,"moderation_state":"archived","external_url":null},{"nid":1296,"title":"security advisory for Apache Struts 2","uuid":"c05852e9-77f3-4b1a-90bc-00aaf19b0cc3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-07-04T19:00:23Z","summary":null,"body":["<article data-history-node-id=\"1296\" about=\"\/en\/alerts-advisories\/security-advisory-apache-struts-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-098<br \/>\nDate: 11 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security bulletin regarding a vulnerability in Apache Struts 2.3.x with Struts 1 plugin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apache has released a security bulletin outlining the possibility to perform a remote code execution attack in Apache Struts 2.3.x with the Struts 1 plugin by using a malicious field containing a Struts 1 action.<\/p>\n\n<p>CVE Reference: CVE-2017-9791<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to the linked security bulletin where Apache outlines a solution to avoid exploitation of this vulnerability.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/struts.apache.org\/docs\/s2-048.html\"><font color=\"#0066cc\">http:\/\/struts.apache.org\/docs\/s2-048.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-advisory-apache-struts-2","alert_type":396,"serial_number":"AV17-098","subject":null,"moderation_state":"archived","external_url":null},{"nid":1081,"title":"Adobe security updates","uuid":"402621c6-114a-4219-b5c4-e90f5aaa90c5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-04T19:07:47Z","summary":null,"body":["<article data-history-node-id=\"1081\" about=\"\/en\/alerts-advisories\/adobe-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-099<br \/>\nDate: 11 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security update for various Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<br \/>\nAPSB17-21 Security updates available for Adobe Flash Player<br \/>\nAPSB17-22 Security updates available for Adobe Connect<br \/>\nCVE References: CVE<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>APSB17-21: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-21.html\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-21.html<\/a><br \/>\nAPSB17-22: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb17-22.html\">https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb17-22.html<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates-3","alert_type":396,"serial_number":"AV17-099","subject":null,"moderation_state":"archived","external_url":null},{"nid":1334,"title":"Microsoft security updates","uuid":"d552fe08-317c-417b-b498-5f54b61926a7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-04T19:13:27Z","summary":null,"body":["<article data-history-node-id=\"1334\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-100<br \/>\nDate: 11 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products including Internet Explorer, Microsoft Edge, Microsoft Windows, Microsoft Office and Microsoft Office Services and Web Apps, .NET Framework, Adobe Flash Player, Microsoft Exchange Server.<\/p>\n\n<p>CVE References:\u00a0<\/p>\n\n<p>CVE-2017-0170, CVE-2017-0243, CVE-2017-8463, CVE-2017-8467, CVE-2017-8486, CVE-2017-8495, CVE-2017-8501, CVE-2017-8502, CVE-2017-8556, CVE-2017-8557, CVE-2017-8559, CVE-2017-8560, CVE-2017-8561, CVE-2017-8562, CVE-2017-8563, CVE-2017-8564, CVE-2017-8565, CVE-2017-8566, CVE-2017-8569, CVE-2017-8570, CVE-2017-8573, CVE-2017-8574, CVE-2017-8577, CVE-2017-8578, CVE-2017-8580, CVE-2017-8581, CVE-2017-8582, CVE-2017-8584, CVE-2017-8585, CVE-2017-8587, CVE-2017-8588, CVE-2017-8589, CVE-2017-8590, CVE-2017-8592, CVE-2017-8594, CVE-2017-8595, CVE-2017-8596, CVE-2017-8598, CVE-2017-8599, CVE-2017-8601, CVE-2017-8602, CVE-2017-8603, CVE-2017-8604, CVE-2017-8605, CVE-2017-8606, CVE-2017-8607, CVE-2017-8608, CVE-2017-8609, CVE-2017-8610, CVE-2017-8611, CVE-2017-8617, CVE-2017-8618, CVE-2017-8619, CVE-2017-8621<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/f2b16606-4945-e711-80dc-000d3a32fc99\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/f2b16606-4945-e711-80dc-000d3a32fc99<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-2","alert_type":396,"serial_number":"AV17-100","subject":null,"moderation_state":"archived","external_url":null},{"nid":1133,"title":"Samba security update","uuid":"6906e12c-f209-444d-8433-1cfc096183d0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-04T19:20:08Z","summary":null,"body":["<article data-history-node-id=\"1133\" about=\"\/en\/alerts-advisories\/samba-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-102<br \/>\nDate: 13 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Samba.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Samba has released a security patch in Samba versions: 4.6.6, 4.5.12 and 4.4.15 to correct the security issue.\u00a0 Exploitation of this vulnerability could allow a MITM (Man in the Middle) attacker to impersonate a trusted server and gain elevated access to the domain.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>All versions of Samba from 4.0.0 onward using embedded Heimdal Kerberos.<\/li>\n<\/ul><p>Not Affected Versions:<\/p>\n\n<ul><li>Samba versions 4.6.6, 4.5.12 and 4.4.15<\/li>\n<\/ul><p>CVE Reference: CVE-2017-11103<\/p>\n\n<p>Special consideration and review should be conducted for internet connected devices which may be leveraging vulnerable versions of Samba, including but not limited to: DVRs, routers and IP cameras. These types of devices typically can only be updated via vendor released firmware updates.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2017-11103.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2017-11103.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11103\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11103<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/www.h5l.org\/advisories.html?show=2017-07-11\"><font color=\"#0066cc\">http:\/\/www.h5l.org\/advisories.html?show=2017-07-11<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-update-0","alert_type":396,"serial_number":"AV17-102","subject":null,"moderation_state":"archived","external_url":null},{"nid":1224,"title":"Cisco WebEx Browser Extension Software updates","uuid":"af668fd8-2368-4ab0-bda2-c45931772e64","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-04T19:26:10Z","summary":null,"body":["<article data-history-node-id=\"1224\" about=\"\/en\/alerts-advisories\/cisco-webex-browser-extension-software-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-103<br \/>\nDate: 17 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released Cisco Security Advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has released a security advisory to address a critical vulnerability in its WebEx browser extensions for Google Chrome and Mozilla Firefox. Successful exploitation could allow a remote unauthenticated attacker to execute code and gain full control of an affected device.<\/p>\n\n<p>\u00a0The following versions of the Cisco WebEx browser extensions are affected by the vulnerability:<\/p>\n\n<ul><li>Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome<\/li>\n\t<li>Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox<\/li>\n<\/ul><p>CVE Reference: CVE-2017-6753<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170717-webex\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170717-webex<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-webex-browser-extension-software-updates","alert_type":396,"serial_number":"AV17-103","subject":null,"moderation_state":"archived","external_url":null},{"nid":1310,"title":"FreeRADIUS security bulletin","uuid":"4309a572-4c73-49a2-b739-4c131471bcf4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:01:05Z","date_created":"2018-07-04T19:33:22Z","summary":null,"body":["<article data-history-node-id=\"1310\" about=\"\/en\/alerts-advisories\/freeradius-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-104<br \/>\nDate: 18 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security bulletin released by FreeRADIUS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>FreeRADIUS has released fixes to address vulnerabilities in their RADIUS server. Exploitation of these vulnerabilities may allow remote code execution and denial of service.<\/p>\n\n<p>Versions affected:<br \/>\nFreeRADIUS 2.2.x versions 2.2.9 and earlier<br \/>\nFreeRADIUS 3.0.x versions 3.0.14 and earlier<\/p>\n\n<p>CVE Reference: CVE-2017-10978, CVE-2017-10979, CVE-2017-10981, CVE-2017-10983, CVE-2017-10984, CVE-2017-10985, CVE-2017-10987<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/freeradius.org\/security\/fuzzer-2017.html\"><font color=\"#0066cc\">http:\/\/freeradius.org\/security\/fuzzer-2017.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freeradius-security-bulletin","alert_type":396,"serial_number":"AV17-104","subject":null,"moderation_state":"archived","external_url":null},{"nid":1068,"title":"Oracle Critical Patch update Advisory \u2013 July 2017","uuid":"ebe88dca-cc55-49df-b148-ddbc28346fa8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:14Z","date_created":"2018-07-04T19:41:13Z","summary":null,"body":["<article data-history-node-id=\"1068\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-july-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-105<br \/>\nDate: 18 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following critical patch updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update (CPU) which addresses 308 new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Application Management Pack for Oracle E-Business Suite, versions AMP 12.1.0.4.0, AMP 13.1.1.1.0<\/li>\n\t<li>Enterprise Manager Base Platform, versions 12.1.0, 13.1.0, 13.2.0<\/li>\n\t<li>Enterprise Manager Ops Center, versions 12.2.2, 12.3.2<\/li>\n\t<li>Financial Services Behavior Detection Platform, versions 8.0.1, 8.0.2<\/li>\n\t<li>Hospitality Hotel Mobile, versions 1.01, 1.05, 1.1<\/li>\n\t<li>Hospitality Property Interfaces, version 8.10.x<\/li>\n\t<li>Hospitality Suite8, version 8.10.x<\/li>\n\t<li>Hospitality WebSuite8 Cloud Service, versions 8.9.6, 8.10.x<\/li>\n\t<li>Hyperion Essbase, version 12.2.1.1<\/li>\n\t<li>Java Advanced Management Console, version 2.6<\/li>\n\t<li>MICROS BellaVita, version 2.7.x<\/li>\n\t<li>MICROS PC Workstation 2015, versions Prior to O1302h<\/li>\n\t<li>MICROS Workstation 650, versions Prior to E1500n<\/li>\n\t<li>MySQL Cluster, versions 7.3.5 and prior<\/li>\n\t<li>MySQL Connectors, versions 5.3.7 and prior, 6.1.10 and prior<\/li>\n\t<li>MySQL Enterprise Monitor, versions 3.1.5.7958 and prior, 3.2.5.1141 and prior, 3.2.7.1204 and prior, 3.3.2.1162 and prior, 3.3.3.1199 and prior<\/li>\n\t<li>MySQL Server, versions 5.5.56 and prior, 5.6.36 and prior, 5.7.18 and prior<\/li>\n\t<li>Oracle Agile PLM, versions 9.3.5, 9.3.6<\/li>\n\t<li>Oracle API Gateway, version 11.1.2.4.0<\/li>\n\t<li>Oracle Application Testing Suite, versions 12.5.0.2, 12.5.0.3<\/li>\n\t<li>Oracle Banking Platform, versions 2.3, 2.4, 2.4.1, 2.5<\/li>\n\t<li>Oracle BI Publisher, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, versions 11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Business Transaction Management, versions 11.1.x, 12.1.x<\/li>\n\t<li>Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager, versions 6.1.4, 11.0, 11.1, 11.2<\/li>\n\t<li>Oracle Communications BRM, versions 11.2.0.0.0, 11.3.0.0.0<\/li>\n\t<li>Oracle Communications Convergence, versions 3.0, 3.0.1<\/li>\n\t<li>Oracle Communications EAGLE LNP Application Processor, version 10.0<\/li>\n\t<li>Oracle Communications Network Charging and Control, versions 4.4.1.5, 5.0.0.1, 5.0.0.2, 5.0.1.0, 5.0.2.0<\/li>\n\t<li>Oracle Communications Policy Management, version 11.5<\/li>\n\t<li>Oracle Communications Session Router, versions ECZ730, SCZ730, SCZ740<\/li>\n\t<li>Oracle Configuration Manager, versions prior to 12.1.2.0.4<\/li>\n\t<li>Oracle Data Integrator, versions 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.0.0<\/li>\n\t<li>Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1<\/li>\n\t<li>Oracle E-Business Suite, versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6<\/li>\n\t<li>Oracle Endeca Server, versions 7.3.0.0, 7.4.0.0, 7.5.0.0, 7.5.1.0, 7.6.0.0, 7.6.1.0, 7.7.0.0<\/li>\n\t<li>Oracle Enterprise Communications Broker, version PCZ210<\/li>\n\t<li>Oracle Enterprise Data Quality, version 8.1.13.0.0<\/li>\n\t<li>Oracle Enterprise Repository, versions 11.1.1.7.0, 12.1.3.0.0<\/li>\n\t<li>Oracle Enterprise Session Border Controller, version ECZ7.3.0<\/li>\n\t<li>Oracle Explorer, versions prior to 8.16<\/li>\n\t<li>Oracle FLEXCUBE Direct Banking, versions 12.0.2, 12.0.3<\/li>\n\t<li>Oracle FLEXCUBE Private Banking, versions 2.0.0, 2.0.1, 2.2.0, 12.0.1<\/li>\n\t<li>Oracle FLEXCUBE Universal Banking, versions 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0<\/li>\n\t<li>Oracle Fusion Applications, versions 11.1.2 through 11.1.9<\/li>\n\t<li>Oracle Fusion Middleware, versions 11.1.1.7, 11.1.1.9, 11.1.2.2, 11.1.2.3, 12.1.3.0, 12.2.1.1, 12.2.1.2<\/li>\n\t<li>Oracle Hospitality 9700, version 4.0<\/li>\n\t<li>Oracle Hospitality Cruise AffairWhere, version 2.2.05.062<\/li>\n\t<li>Oracle Hospitality Cruise Dining Room Management, version 8.0.75<\/li>\n\t<li>Oracle Hospitality Cruise Fleet Management, version 9.0<\/li>\n\t<li>Oracle Hospitality Cruise Materials Management, version 7.30.562<\/li>\n\t<li>Oracle Hospitality Cruise Shipboard Property Management System, version 8.0.0.0<\/li>\n\t<li>Oracle Hospitality e7, version 4.2.1<\/li>\n\t<li>Oracle Hospitality Guest Access, versions 4.2.0.0, 4.2.1.0<\/li>\n\t<li>Oracle Hospitality Inventory Management, versions 8.5.1, 9.0.0<\/li>\n\t<li>Oracle Hospitality Materials Control, version 8.31.4, 8.32.0<\/li>\n\t<li>Oracle Hospitality OPERA 5 Property Services, versions 5.4.0.x, 5.4.1.x, 5.4.3.x<\/li>\n\t<li>Oracle Hospitality Reporting and Analytics, versions 8.5.1, 9.0.0<\/li>\n\t<li>Oracle Hospitality RES 3700, version 5.5<\/li>\n\t<li>Oracle Hospitality Simphony First Edition Venue Management, version 3.9<\/li>\n\t<li>Oracle Hospitality Simphony First Edition, version 1.7.1<\/li>\n\t<li>Oracle Hospitality Simphony, versions 2.8, 2.9<\/li>\n\t<li>Oracle Hospitality Suites Management, version 3.7<\/li>\n\t<li>Oracle iLearning, version 6.2<\/li>\n\t<li>Oracle Java SE Embedded, version 8u131<\/li>\n\t<li>Oracle Java SE, versions 6u151, 7u141, 8u131<\/li>\n\t<li>Oracle JRockit, version R28.3.14<\/li>\n\t<li>Oracle OpenSSO, version 3.0.0.8<\/li>\n\t<li>Oracle Outside In Technology, version 8.5.3.0<\/li>\n\t<li>Oracle Payment Interface, version 6.1.1<\/li>\n\t<li>Oracle Policy Automation, versions 12.1.0, 12.1.1, 12.2.0, 12.2.1, 12.2.2, 12.2.3<\/li>\n\t<li>Oracle REST Data Services, versions prior to 3.0.10.25.02.36<\/li>\n\t<li>Oracle Retail Allocation, versions 13.3.1, 14.0.4, 14.1.3, 15.0.1, 16.0.1<\/li>\n\t<li>Oracle Retail Customer Insights, versions 15.0, 16.0<\/li>\n\t<li>Oracle Retail Open Commerce Platform, versions 5.0, 5.1, 5.2, 5.3, 6.0, 6.1, 15.0, 15.1<\/li>\n\t<li>Oracle Retail Warehouse Management System, versions 14.0.4, 14.1.3, 15.0.1<\/li>\n\t<li>Oracle Retail Workforce Management, versions 1.60.7, 1.64.0<\/li>\n\t<li>Oracle Retail Xstore Point of Service, versions 6.0.x, 6.5.x, 7.0.x, 7.1.x, 15.0.x, 16.0.0<\/li>\n\t<li>Oracle Secure Enterprise Search, version 11.2.2.2.0<\/li>\n\t<li>Oracle Service Bus, version 11.1.1.9.0<\/li>\n\t<li>Oracle Traffic Director, versions 11.1.1.7.0, 11.1.1.9.0<\/li>\n\t<li>Oracle Transportation Management, versions 6.1, 6.2, 6.3.4.1, 6.3.5.1, 6.3.6.1, 6.3.7.1, 6.4.0, 6.4.1, 6.4.2<\/li>\n\t<li>Oracle Tuxedo System and Applications Monitor, versions 11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.2, 12.1.1.1.0, 12.1.3.0.0, 12.2.2.0.0<\/li>\n\t<li>Oracle Tuxedo, version 12.1.1<\/li>\n\t<li>Oracle VM VirtualBox, versions prior to 5.1.24<\/li>\n\t<li>Oracle WebCenter Content, versions 11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle WebLogic Server, versions 10.3.6.0, 12.1.3.0, 12.2.1.1, 12.2.1.2<\/li>\n\t<li>PeopleSoft Enterprise FSCM, version 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, versions 8.54, 8.55<\/li>\n\t<li>PeopleSoft Enterprise PRTL Interaction Hub, version 9.1.0<\/li>\n\t<li>Primavera Gateway, versions 1.0, 1.1, 14.2, 15.1, 15.2, 16.1, 16.2<\/li>\n\t<li>Primavera P6 Enterprise Project Portfolio Management, versions 8.3, 8.4, 15.1, 15.2, 16.1, 16.2<\/li>\n\t<li>Primavera Unifier, versions 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1, 16.2<\/li>\n\t<li>Siebel Applications, versions 16.0, 17.0<\/li>\n\t<li>Solaris Cluster, version 4<\/li>\n\t<li>Solaris, versions 10, 11<\/li>\n\t<li>Sun ZFS Storage Appliance Kit (AK), version AK 2013<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2013-2027, CVE-2014-0224, CVE-2014-1912, CVE-2014-3566, CVE-2014-3571, CVE-2015-0235, CVE-2015-0254, CVE-2015-0286, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-3195, CVE-2015-3197, CVE-2015-3253, CVE-2015-5254, CVE-2015-7501, CVE-2015-7940, CVE-2015-8607, CVE-2015-8608, CVE-2016-0635, CVE-2016-1181, CVE-2016-1950, CVE-2016-1979, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-2381, CVE-2016-2834, CVE-2016-3092, CVE-2016-3506, CVE-2016-4430, CVE-2016-4431, CVE-2016-4433, CVE-2016-4436, CVE-2016-4438, CVE-2016-4465, CVE-2016-5019, CVE-2016-5385, CVE-2016-5386, CVE-2016-5387, CVE-2016-5388, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6814, CVE-2016-7052, CVE-2016-7055, CVE-2017-3529, CVE-2017-3562, CVE-2017-3632, CVE-2017-3633, CVE-2017-3634, CVE-2017-3635, CVE-2017-3636, CVE-2017-3637, CVE-2017-3638, CVE-2017-3639, CVE-2017-3640, CVE-2017-3641, CVE-2017-3642, CVE-2017-3643, CVE-2017-3644, CVE-2017-3645, CVE-2017-3646, CVE-2017-3647, CVE-2017-3648, CVE-2017-3649, CVE-2017-3650, CVE-2017-3651, CVE-2017-3652, CVE-2017-3653, CVE-2017-3731, CVE-2017-3732, CVE-2017-5638, CVE-2017-5647, CVE-2017-5650, CVE-2017-5651, CVE-2017-5689, CVE-2017-10000, CVE-2017-10001, CVE-2017-10002, CVE-2017-10003, CVE-2017-10004, CVE-2017-10005, CVE-2017-10006, CVE-2017-10007, CVE-2017-10008, CVE-2017-10009, CVE-2017-10010, CVE-2017-10011, CVE-2017-10012, CVE-2017-10013, CVE-2017-10015, CVE-2017-10016, CVE-2017-10017, CVE-2017-10018, CVE-2017-10019, CVE-2017-10020, CVE-2017-10021, CVE-2017-10022, CVE-2017-10023, CVE-2017-10024, CVE-2017-10025, CVE-2017-10027, CVE-2017-10028, CVE-2017-10029, CVE-2017-10030, CVE-2017-10031, CVE-2017-10032, CVE-2017-10035, CVE-2017-10036, CVE-2017-10038, CVE-2017-10039, CVE-2017-10040, CVE-2017-10041, CVE-2017-10042, CVE-2017-10043, CVE-2017-10044, CVE-2017-10045, CVE-2017-10046, CVE-2017-10047, CVE-2017-10048, CVE-2017-10049, CVE-2017-10052, CVE-2017-10053, CVE-2017-10056, CVE-2017-10057, CVE-2017-10058, CVE-2017-10059, CVE-2017-10061, CVE-2017-10062, CVE-2017-10063, CVE-2017-10064, CVE-2017-10067, CVE-2017-10069, CVE-2017-10070, CVE-2017-10071, CVE-2017-10072, CVE-2017-10073, CVE-2017-10074, CVE-2017-10075, CVE-2017-10076, CVE-2017-10078, CVE-2017-10079, CVE-2017-10080, CVE-2017-10081, CVE-2017-10082, CVE-2017-10083, CVE-2017-10084, CVE-2017-10085, CVE-2017-10086, CVE-2017-10087, CVE-2017-10088, CVE-2017-10089, CVE-2017-10090, CVE-2017-10091, CVE-2017-10092, CVE-2017-10093, CVE-2017-10094, CVE-2017-10095, CVE-2017-10096, CVE-2017-10097, CVE-2017-10098, CVE-2017-10100, CVE-2017-10101, CVE-2017-10102, CVE-2017-10103, CVE-2017-10104, CVE-2017-10105, CVE-2017-10106, CVE-2017-10107, CVE-2017-10108, CVE-2017-10109, CVE-2017-10110, CVE-2017-10111, CVE-2017-10112, CVE-2017-10113, CVE-2017-10114, CVE-2017-10115, CVE-2017-10116, CVE-2017-10117, CVE-2017-10118, CVE-2017-10119, CVE-2017-10120, CVE-2017-10121, CVE-2017-10122, CVE-2017-10123, CVE-2017-10125, CVE-2017-10126, CVE-2017-10128, CVE-2017-10129, CVE-2017-10130, CVE-2017-10131, CVE-2017-10132, CVE-2017-10133, CVE-2017-10134, CVE-2017-10135, CVE-2017-10136, CVE-2017-10137, CVE-2017-10141, CVE-2017-10142, CVE-2017-10143, CVE-2017-10144, CVE-2017-10145, CVE-2017-10146, CVE-2017-10147, CVE-2017-10148, CVE-2017-10149, CVE-2017-10150, CVE-2017-10156, CVE-2017-10157, CVE-2017-10160, CVE-2017-10168, CVE-2017-10169, CVE-2017-10170, CVE-2017-10171, CVE-2017-10172, CVE-2017-10173, CVE-2017-10174, CVE-2017-10175, CVE-2017-10176, CVE-2017-10177, CVE-2017-10178, CVE-2017-10179, CVE-2017-10180, CVE-2017-10181, CVE-2017-10182, CVE-2017-10183, CVE-2017-10184, CVE-2017-10185, CVE-2017-10186, CVE-2017-10187, CVE-2017-10188, CVE-2017-10189, CVE-2017-10191, CVE-2017-10192, CVE-2017-10193, CVE-2017-10195, CVE-2017-10196, CVE-2017-10198, CVE-2017-10199, CVE-2017-10200, CVE-2017-10201, CVE-2017-10202, CVE-2017-10204, CVE-2017-10205, CVE-2017-10206, CVE-2017-10207, CVE-2017-10208, CVE-2017-10209, CVE-2017-10210, CVE-2017-10211, CVE-2017-10212, CVE-2017-10213, CVE-2017-10214, CVE-2017-10215, CVE-2017-10216, CVE-2017-10217, CVE-2017-10218, CVE-2017-10219, CVE-2017-10220, CVE-2017-10221, CVE-2017-10222, CVE-2017-10223, CVE-2017-10224, CVE-2017-10225, CVE-2017-10226, CVE-2017-10228, CVE-2017-10229, CVE-2017-10230, CVE-2017-10231, CVE-2017-10232, CVE-2017-10233, CVE-2017-10234, CVE-2017-10235, CVE-2017-10236, CVE-2017-10237, CVE-2017-10238, CVE-2017-10239, CVE-2017-10240, CVE-2017-10241, CVE-2017-10242, CVE-2017-10243, CVE-2017-10244, CVE-2017-10245, CVE-2017-10246, CVE-2017-10247, CVE-2017-10248, CVE-2017-10249, CVE-2017-10250, CVE-2017-10251, CVE-2017-10252, CVE-2017-10253, CVE-2017-10254, CVE-2017-10255, CVE-2017-10256, CVE-2017-10257, CVE-2017-10258<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization's critical services, and follow their patch management process accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2017-3236622.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2017-3236622.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-july-2017","alert_type":396,"serial_number":"AV17-105","subject":null,"moderation_state":"archived","external_url":null},{"nid":1093,"title":"Apple security updates","uuid":"ea2ce9e8-5bda-4e3f-88c3-fe2015738a9d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-07-04T19:47:48Z","summary":null,"body":["<article data-history-node-id=\"1093\" about=\"\/en\/alerts-advisories\/apple-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-106<br \/>\nDate: 20 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for macOS (Sierra, El Capitan, Yosemite), Safari, iOS, iCloud for Windows, iTunes for Windows, tvOS and watchOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles:<\/p>\n\n<ul><li>HT207921- Safari 10.1.2<\/li>\n\t<li>HT207922 - macOS Sierra 10.12.6, Security Update 2017-003 El Capitan, and Security Update 2017-003 Yosemite<\/li>\n\t<li>HT207923 - iOS 10.3.3<\/li>\n\t<li>HT207924 - tvOS 10.2.2<\/li>\n\t<li>HT207925 - watchOS 3.2.3<\/li>\n\t<li>HT207927 - iCloud for Windows 6.2.2<\/li>\n\t<li>HT207928 - iTunes 12.6.2 for Windows<\/li>\n<\/ul><p>This update addresses multiple vulnerabilities on the systems listed above.<\/p>\n\n<p>CVE Reference: CVE-2016-9586, CVE-2016-9594, CVE-2017-2517, CVE-2017-2629, CVE-2017-7006, CVE-2017-7007, CVE-2017-7008, CVE-2017-7009, CVE-2017-7010, CVE-2017-7011, CVE-2017-7012, CVE-2017-7013, CVE-2017-7014, CVE-2017-7015, CVE-2017-7016, CVE-2017-7017, CVE-2017-7018, CVE-2017-7019, CVE-2017-7020, CVE-2017-7021, CVE-2017-7022, CVE-2017-7023, CVE-2017-7024, CVE-2017-7025, CVE-2017-7026, CVE-2017-7027, CVE-2017-7028, CVE-2017-7029, CVE-2017-7030, CVE-2017-7031, CVE-2017-7032, CVE-2017-7033, CVE-2017-7034, CVE-2017-7035, CVE-2017-7036, CVE-2017-7037, CVE-2017-7038, CVE-2017-7039, CVE-2017-7040, CVE-2017-7041, CVE-2017-7042, CVE-2017-7043, CVE-2017-7044, CVE-2017-7045, CVE-2017-7046, CVE-2017-7047, CVE-2017-7048, CVE-2017-7049, CVE-2017-7050, CVE-2017-7051, CVE-2017-7052, CVE-2017-7053, CVE-2017-7054, CVE-2017-7055, CVE-2017-7056, CVE-2017-7058, CVE-2017-7059, CVE-2017-7060, CVE-2017-7061, CVE-2017-7062, CVE-2017-7063, CVE-2017-7064, CVE-2017-7067, CVE-2017-7068, CVE-2017-7069, CVE-2017-7468, CVE-2017-8248, CVE-2017-9417<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT207921\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207921<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207922\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207922<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207923\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207923<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207924\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207924<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207925\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207925<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207927\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207927<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT207928\"><font color=\"#0066cc\">https:\/\/support.apple.com\/kb\/HT207928<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-0","alert_type":396,"serial_number":"AV17-106","subject":null,"moderation_state":"archived","external_url":null},{"nid":1062,"title":"Cisco security updates","uuid":"1687c5b3-f5d2-4324-8bde-a2ddffae2b10","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-05T12:33:42Z","summary":null,"body":["<article data-history-node-id=\"1062\" about=\"\/en\/alerts-advisories\/cisco-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-107<br \/>\nDate: 21 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (high to medium) in the following products.<\/p>\n\n<ul><li>Cisco ASR 5000 Series Aggregation Services Routers: \u00a0GGSN Gateway Redirect Vulnerability<\/li>\n\t<li>Cisco ASR 5000 Series Aggregation Services Routers: \u00a0Access Control List Security Bypass Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Tool Web Portal: \u00a0Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance: \u00a0Authenticated Command Injection and Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance: \u00a0Stored Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance: \u00a0Static Credentials Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance: \u00a0Administrative Interface Access Control Bypass Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance: \u00a0Command Injection and Privilege Escalation Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2017-6612, CVE-2017-6672, CVE-2017-6746, CVE-2017-6748, CVE-2017-6749, CVE-2017-6750, CVE-2017-6751, CVE-2017-6755<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-asr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-asr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-asr1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-asr1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-pcpt\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-pcpt<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa3<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa4<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa5\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170719-wsa5<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-0","alert_type":396,"serial_number":"AV17-107","subject":null,"moderation_state":"archived","external_url":null},{"nid":788,"title":"IBM Cisco security update","uuid":"70ff4b8b-ea37-42e2-967e-8421420ee848","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-05T12:38:58Z","summary":null,"body":["<article data-history-node-id=\"788\" about=\"\/en\/alerts-advisories\/ibm-cisco-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-108<br \/>\nDate: 21 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an IBM Cisco security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>IBM Cisco released multiple security updates to address vulnerabilities (critical) in the following products:\u00a0<\/p>\n\n<ul><li>IBM Cisco DCNM Software Versions:\u00a0 DCNM\u00a0 10.1(1), DCNM 10.1(2)<\/li>\n<\/ul><p>CVE References:\u00a0 CVE-2017-6639, CVE-2017-6640<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/ibm-security-bulletin-ibm-cisco-mds-series-switches-dcnm-is-affected-by-unauthenticated-remote-attacker-vulnerability-cve-2017-6639-cve-2017-6640\"><font color=\"#0066cc\">https:\/\/www.ibm.com\/blogs\/psirt\/ibm-security-bulletin-ibm-cisco-mds-series-switches-dcnm-is-affected-by-unauthenticated-remote-attacker-vulnerability-cve-2017-6639-cve-2017-6640<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170607-dcnm1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170607-dcnm1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170607-dcnm2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170607-dcnm2<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-cisco-security-update","alert_type":396,"serial_number":"AV17-108","subject":null,"moderation_state":"archived","external_url":null},{"nid":1240,"title":"Google Releases security update for Chrome","uuid":"db2dd92a-32c5-4d61-8a82-dd3d98d1e50b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-05T12:58:24Z","summary":null,"body":["<article data-history-node-id=\"1240\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-23\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-109<br \/>\nDate: 26 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 60.0.3112.78 for Windows, Mac and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References:\u00a0 CVE-2017-5091, CVE-2017-5092, CVE-2017-5093, CVE-2017-5094, CVE-2017-5095, CVE-2017-5096, CVE-2017-5097, CVE-2017-5098, CVE-2017-5099, CVE-2017-5100, CVE-2017-5101, CVE-2017-5102, CVE-2017-5103, CVE-2017-5104, CVE-2017-5105, CVE-2017-5106, CVE-2017-5107, CVE-2017-5108, CVE-2017-5109, CVE-2017-5110, CVE-2017-7000<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/07\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/07\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-23","alert_type":396,"serial_number":"AV17-109","subject":null,"moderation_state":"archived","external_url":null},{"nid":1277,"title":"Joomla! security update","uuid":"d4f40a04-3374-452c-bfe3-d8a65c01b466","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-05T13:03:24Z","summary":null,"body":["<article data-history-node-id=\"1277\" about=\"\/en\/alerts-advisories\/joomla-security-update-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-110<br \/>\nDate: 26 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.7.4 of its web content management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected: Joomla! 1.0.0 through 3.7.3<\/p>\n\n<p>CVE References: CVE-2017-11364, CVE-2017-11612<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5710-joomla-3-7-4-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5710-joomla-3-7-4-release.html<\/font><\/a>\u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update-1","alert_type":396,"serial_number":"AV17-110","subject":null,"moderation_state":"archived","external_url":null},{"nid":1104,"title":"Citrix security updates","uuid":"a9b5ac89-e1e8-4724-8f69-cc74f369436b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-05T13:09:31Z","summary":null,"body":["<article data-history-node-id=\"1104\" about=\"\/en\/alerts-advisories\/citrix-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-111<br \/>\nDate: 26 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Citrix security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Citrix has released product updates to address a critical vulnerability that when exploited, may allow for arbitrary remote code execution.<\/p>\n\n<p>Affected Version:<\/p>\n\n<ul><li>All versions of Citrix SD-WAN 9.x Enterprise and Standard Edition earlier than version 9.2.1-1001<\/li>\n\t<li>All versions of Citrix CloudBridge 8.x Virtual WAN Edition<\/li>\n<\/ul><p>CVE Reference: CVE-2017-6316<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX225990\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX225990<\/font><\/a><br \/><a href=\"https:\/\/www.citrix.com\/downloads\/netscaler-sd-wan\/?_ga=2.213724636.938177760.1501091545-2104810666.1501091545\"><font color=\"#0066cc\">https:\/\/www.citrix.com\/downloads\/netscaler-sd-wan\/<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-6316\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-6316<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-updates-1","alert_type":396,"serial_number":"AV17-111","subject":null,"moderation_state":"archived","external_url":null},{"nid":941,"title":"Juniper Networks security bulletins","uuid":"32a7f6d5-7f05-408d-8fb7-690d91a31f74","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:01Z","date_created":"2018-07-05T13:14:51Z","summary":null,"body":["<article data-history-node-id=\"941\" about=\"\/en\/alerts-advisories\/juniper-networks-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-112<br \/>\nDate: July 27 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security bulletins released by Juniper Networks.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Juniper Networks has released product updates addressing a security issue with Junos OS. If successful, a remote unauthenticated user could fully compromise the device.<\/p>\n\n<p>Affected Products:<br \/>\nJunos OS 12.3, 12.3X48, 13.2, 13.3, 14.1, 14.1X53, 14.2, 15.1 on all products and platforms.<br \/>\nJunos OS 12.3X48, 15.1X49. Affected platforms: SRX series.<\/p>\n\n<p>CVE References: CVE-2017-10601, CVE-2017-2343<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10802\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10802<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10791\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10791<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-bulletins","alert_type":396,"serial_number":"AV17-112","subject":null,"moderation_state":"archived","external_url":null},{"nid":751,"title":"Cisco security updates","uuid":"91627578-6fbe-4e21-b60c-a1517f80e8e0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:16Z","date_created":"2018-07-05T13:21:21Z","summary":null,"body":["<article data-history-node-id=\"751\" about=\"\/en\/alerts-advisories\/cisco-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-113<br \/>\nDate: 27 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS and IOS XE Software Autonomic Control Plane Channel Information Disclosure Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2017-6663, 2017-6665<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170726-anidos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170726-anidos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170726-aniacp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170726-aniacp<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-1","alert_type":396,"serial_number":"AV17-113","subject":null,"moderation_state":"archived","external_url":null},{"nid":830,"title":"Microsoft security updates \u2013 Out-of-Band","uuid":"c9122d90-70da-49d8-b7fd-8203a123f7a1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-05T13:27:03Z","summary":null,"body":["<article data-history-node-id=\"830\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-out-band\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-114<br \/>\nDate: 28 July 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates. This update resolves vulnerabilities that could allow remote code execution if a user opens a specially crafted Office file.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple out-of-band support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Microsoft Outlook 2007 Service Pack 3\u00a0\u00a0<\/li>\n\t<li>Microsoft Office 2010 Click-to-Run (C2R) for 64-bit editions<\/li>\n\t<li>Microsoft Office 2010 Click-to-Run (C2R) for 32-bit editions\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Microsoft Outlook 2013 Service Pack 1 (32-bit editions)<\/li>\n\t<li>Microsoft Outlook 2013 Service Pack 1 (64-bit editions)\u00a0<\/li>\n\t<li>Microsoft Office 2013 Click-to-Run (C2R) for 64-bit editions\u00a0\u00a0<\/li>\n\t<li>Microsoft Office 2013 Click-to-Run (C2R) for 32-bit editions\u00a0\u00a0\u00a0<\/li>\n\t<li>Microsoft Office 2016 Click-to-Run (C2R) for 64-bit editions<\/li>\n\t<li>Microsoft Office 2016 Click-to-Run (C2R) for 32-bit editions\u00a0\u00a0<\/li>\n\t<li>Microsoft Outlook 2016 (64-bit edition)\u00a0\u00a0 \u00a0<\/li>\n\t<li>Microsoft Outlook 2016 (32-bit edition)\u00a0<\/li>\n<\/ul><p>CVE References: CVE-2017-8571, CVE-2017-8572, CVE-2017-8663<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/3213643\/description-of-the-security-update-for-outlook-2007-july-27-2017\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/3213643\/description-of-the-security-update-for-outlook-2007-july-27-2017<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-out-band","alert_type":396,"serial_number":"AV17-114","subject":null,"moderation_state":"archived","external_url":null},{"nid":1289,"title":"Cisco security updates","uuid":"e1962cd2-c25c-4322-b3ec-df4499217114","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-07-05T13:32:47Z","summary":null,"body":["<article data-history-node-id=\"1289\" about=\"\/en\/alerts-advisories\/cisco-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-115<br \/>\nDate: 2 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco Identity Services Engine Authentication Bypass Vulnerability<\/li>\n\t<li>Cisco Videoscape Distribution Suite Cache Server Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2017-6745, CVE-2017-6747<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170802-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170802-ise<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170802-vds\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170802-vds<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-2","alert_type":396,"serial_number":"AV17-115","subject":null,"moderation_state":"archived","external_url":null},{"nid":1082,"title":"Google Releases security update for Chrome OS","uuid":"5bfc02e6-6e58-4473-9524-2d07b0ca4bbf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-05T13:37:55Z","summary":null,"body":["<article data-history-node-id=\"1082\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-os\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-116<br \/>\nDate: 4 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome OS stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 60.0.3112.90.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome OS.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/08\/stable-channel-update-for-chrome-os.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/08\/stable-channel-update-for-chrome-os.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-os","alert_type":396,"serial_number":"AV17-116","subject":null,"moderation_state":"archived","external_url":null},{"nid":1336,"title":"VMware security updates","uuid":"fb529057-dadd-43c2-aba7-fc272638f526","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-05T13:42:52Z","summary":null,"body":["<article data-history-node-id=\"1336\" about=\"\/en\/alerts-advisories\/vmware-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-117<br \/>\nDate: 4 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware VIX API VM Direct Access Function<\/li>\n\t<li>VMware vCenter Server versions 5.5, 6.0, 6.5<\/li>\n\t<li>VMware Tools\u00a0\u00a0<\/li>\n<\/ul><p>CVE References: CVE-2017-4919, CVE-2017-4921, CVE-2017-4922, CVE-2017-4923, CVE-2015-5191<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0013.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0013.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0012.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0012.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-4","alert_type":396,"serial_number":"AV17-117","subject":null,"moderation_state":"archived","external_url":null},{"nid":1135,"title":"HP security bulletin","uuid":"fa2f4613-c930-4632-9b17-982daaa9f813","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-05T13:48:47Z","summary":null,"body":["<article data-history-node-id=\"1135\" about=\"\/en\/alerts-advisories\/hp-security-bulletin-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-118<br \/>\nDate: 04 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to HP security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HP has released a security update to address a potential security problem that has been identified in HPE Proliant ML10 Gen9 server using Intel Xeon E3-1200M v5 and 6th Generation Intel Core Processors. The vulnerability could allow a remote unauthorized attacker to write to file systems.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>HPE ProLiant ML10 Gen9 E3-1225 v5 4GB-R 1TB Non-hot Plug 4LFF SATA 300W Svr\/S-Buy SP<\/li>\n\t<li>HPE ProLiant ML10 Gen9 E3-1225 v5 8GB-R 1TB Non-hot Plug 4LFF SATA 300W Perf Svr SP<\/li>\n\t<li>HPE ProLiant ML10 Gen9 E3-1225 v5 8GB-R 2TB Non-hot Plug 4LFF SATA 300W Svr\/GO SP<\/li>\n\t<li>HPE ProLiant ML10 Gen9 E3-1225 v5 8GB-R 2TB Non-hot Plug 4LFF SATA 300W Svr\/TV SP<\/li>\n\t<li>HPE ProLiant ML10 Gen9 G4400 4GB-R Non-hot Plug 4LFF SATA 300W Entry Svr SP<\/li>\n\t<li>HPE ProLiant ML10 Gen9 E3-1225 v5 3.3GHz 4-core 8GB-R 1TB Non-hot Plug 4LFF SATA 300W AP Svr\/Promo SP<\/li>\n<\/ul><p>CVE Reference: CVE-2017-5691<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/h20564.www2.hpe.com\/hpsc\/doc\/public\/display?docId=emr_na-hpesb3p03767en_us\"><font color=\"#0066cc\">http:\/\/h20564.www2.hpe.com\/hpsc\/doc\/public\/display?docId=emr_na-hpesb3p03767en_us<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hp-security-bulletin-1","alert_type":396,"serial_number":"AV17-118","subject":null,"moderation_state":"archived","external_url":null},{"nid":1226,"title":"Intel\u00ae Software Guard Extensions (SGX) \u2013 Incorrect Check Vulnerability","uuid":"a3b36e97-710f-4646-b6fb-3d78f8f2027a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-05T13:53:55Z","summary":null,"body":["<article data-history-node-id=\"1226\" about=\"\/en\/alerts-advisories\/intelr-software-guard-extensions-sgx-incorrect-check-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-119<br \/>\nDate: 09 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a vulnerability in Intel\u00ae Software Guard Extensions (SGX).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of an incorrect check vulnerability in Intel\u00ae Software Guard Extensions (SGX) in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families. This privilege escalation vulnerability could allow an unprivileged user to compromise system firmware via incorrect early system state.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Intel\u00ae Software Guard Extensions (SGX) Incorrect Check Vulnerability<br \/><a href=\"https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00076&amp;languageid=en-fr\"><font color=\"#0066cc\">https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00076&amp;languageid=en-fr<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intelr-software-guard-extensions-sgx-incorrect-check-vulnerability","alert_type":396,"serial_number":"AV17-119","subject":null,"moderation_state":"archived","external_url":null},{"nid":1312,"title":"Microsoft security updates","uuid":"f3dc5fc1-12af-4a73-8239-cc32a71ba879","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:01:05Z","date_created":"2018-07-05T14:06:07Z","summary":null,"body":["<article data-history-node-id=\"1312\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-120<br \/>\nDate: 08 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products including Internet Explorer, Edge, Windows, SharePoint, Adobe Flash Player, and SQL Server.<\/p>\n\n<p>CVE References: CVE-2017-0174, CVE-2017-0250, CVE-2017-0293, CVE-2017-8503, CVE-2017-8516, CVE-2017-8591, CVE-2017-8593, CVE-2017-8620, CVE-2017-8622, CVE-2017-8623, CVE-2017-8624, CVE-2017-8625, CVE-2017-8627, CVE-2017-8633, CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8637, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8642, CVE-2017-8644, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8650, CVE-2017-8651, CVE-2017-8652, CVE-2017-8653, CVE-2017-8654, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8659, CVE-2017-8661, CVE-2017-8662, CVE-2017-8664, CVE-2017-8666, CVE-2017-8668, CVE-2017-8669, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, CVE-2017-8673, CVE-2017-8674, CVE-2017-8691<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/b3d96835-f651-e711-80dd-000d3a32fc99\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/b3d96835-f651-e711-80dd-000d3a32fc99<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-3","alert_type":396,"serial_number":"AV17-120","subject":null,"moderation_state":"archived","external_url":null},{"nid":1069,"title":"Mozilla security updates","uuid":"0540480c-2ec4-45e3-b889-88927c3a175a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-05T14:12:20Z","summary":null,"body":["<article data-history-node-id=\"1069\" about=\"\/en\/alerts-advisories\/mozilla-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-121<br \/>\nDate: 9 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Mozilla Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address multiple vulnerabilities in Firefox. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Version affected: Firefox 55<\/p>\n\n<p>CVE References:\u00a0 CVE-2017-7753, CVE-2017-7779, CVE-2017-7780 , CVE-2017-7781, CVE-2017-7782, CVE-2017-7783, CVE-2017-7784, CVE-2017-7785, CVE-2017-7786, CVE-2017-7787, CVE-2017-7788,CVE-2017-7789, CVE-2017-7790, CVE-2017-7791, CVE-2017-7792, CVE-2017-7794, CVE-2017-7796, CVE-2017-7797, CVE-2017-7798, CVE-2017-7799, CVE-2017-7800, CVE-2017-7801, CVE-2017-7802, CVE-2017-7803, CVE-2017-7804, CVE-2017-7806, CVE-2017-7807,CVE-2017-7808<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-18\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-18\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates","alert_type":396,"serial_number":"AV17-121","subject":null,"moderation_state":"archived","external_url":null},{"nid":1085,"title":"Adobe security updates","uuid":"14a9d109-f73d-4e30-bb1d-0903ab728758","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-07-05T14:20:27Z","summary":null,"body":["<article data-history-node-id=\"1085\" about=\"\/en\/alerts-advisories\/adobe-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-122<br \/>\nDate: 9 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security updates for various Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<\/p>\n\n<ul><li>APSB17-23: Security Updates Available for Adobe Flash Player<\/li>\n\t<li>APSB17-24: Security Update Available for Adobe Acrobat and Reader<\/li>\n\t<li>APSB17-26: Security Updates Available for Adobe Experience Manager<\/li>\n\t<li>APSB17-27: Security Updates Available for Adobe Digital Editions<\/li>\n<\/ul><p>CVE References:<\/p>\n\n<p>CVE-2017-3016, CVE-2017-3038, CVE-2017-3113, CVE-2017-3115, CVE-2017-3116, CVE-2017-3117, CVE-2017-3118, CVE-2017-3119, CVE-2017-3120, CVE-2017-3121, CVE-2017-3122, CVE-2017-3123, CVE-2017-3124, CVE-2017-11209, CVE-2017-11210, CVE-2017-11211, CVE-2017-11212, CVE-2017-11214, CVE-2017-11216, CVE-2017-11217, CVE-2017-11218, CVE-2017-11219, CVE-2017-11220, CVE-2017-11221, CVE-2017-11222, CVE-2017-11223, CVE-2017-11224, CVE-2017-11226, CVE-2017-11227, CVE-2017-11228, CVE-2017-11229, CVE-2017-11230, CVE-2017-11231, CVE-2017-11232, CVE-2017-11233, CVE-2017-11234, CVE-2017-11235, CVE-2017-11236, CVE-2017-11237, CVE-2017-11238, CVE-2017-11239, CVE-2017-11241, CVE-2017-11242, CVE-2017-11243, CVE-2017-11244, CVE-2017-11245, CVE-2017-11246, CVE-2017-11248, CVE-2017-11249, CVE-2017-11251, CVE-2017-11252, CVE-2017-11254, CVE-2017-11255, CVE-2017-11256, CVE-2017-11257, CVE-2017-11258, CVE-2017-11259, CVE-2017-11260, CVE-2017-11261, CVE-2017-11262, CVE-2017-11263, CVE-2017-11265, CVE-2017-11267, CVE-2017-11268, CVE-2017-11269, CVE-2017-11270, CVE-2017-11271, CVE-2016-7855, CVE-2017-3107, CVE-2017-3108, CVE-2017-3110, CVE-2017-11274,CVE-2017-3091, CVE-2017-11275, CVE-2017-11276, CVE-2017-11277, CVE-2017-11278, CVE-2017-11279, CVE-2017-11280, CVE-2017-11272<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-23.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-23.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-24.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-24.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb17-26.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb17-26.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-27.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-27.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates-4","alert_type":396,"serial_number":"AV17-122","subject":null,"moderation_state":"archived","external_url":null},{"nid":1064,"title":"[Control systems] OSIsoft PI Integrator security update","uuid":"a8406ba5-9a5f-4e8d-989e-497459282677","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-05T14:25:58Z","summary":null,"body":["<article data-history-node-id=\"1064\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-pi-integrator-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-123<br \/>\nDate: 9 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates to address input validation and authentication vulnerabilities in various versions of OSIsoft\u2019s PI Integrator products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Successful exploitation of these vulnerabilities could allow an unauthorized user to gain privileged access to the system. An unauthorized user may also be able to store a malicious script in the application database.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>PI Integrator for SAP HANA 2016,<\/li>\n\t<li>PI Integrator for Business Analytics 2016 - Data Warehouse (All Editions),<\/li>\n\t<li>PI Integrator for Business Analytics 2016 - Business Intelligence (All Editions),<\/li>\n\t<li>PI Integrator for Business Analytics and SAP HANA SQL Utility 2016, and<\/li>\n\t<li>PI Integrator for Microsoft Azure 2016<\/li>\n<\/ul><p>CVE References: CVE-2017-9653, CVE-2017-9655<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications at their earliest convenience. Consider and assess the risk should you have to delay updates and mitigate accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/techsupport.osisoft.com\/Troubleshooting\/Alerts\/AL00324\"><font color=\"#0066cc\">https:\/\/techsupport.osisoft.com\/Troubleshooting\/Alerts\/AL00324<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/techsupport.osisoft.com\/Troubleshooting\/Releases\/RL01195\"><font color=\"#0066cc\">https:\/\/techsupport.osisoft.com\/Troubleshooting\/Releases\/RL01195<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-220-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-220-01<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-pi-integrator-security-update","alert_type":398,"serial_number":"AV17-123","subject":null,"moderation_state":"archived","external_url":null},{"nid":790,"title":"SAP Security Patches","uuid":"7f2cf8c5-7f6c-482b-b612-4629af385a37","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-05T14:32:39Z","summary":null,"body":["<article data-history-node-id=\"790\" about=\"\/en\/alerts-advisories\/sap-security-patches\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-124<br \/>\nDate: 10 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Security Notes by SAP.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>SAP has released 16 Security Notes as part of their August Security Patch Day designed to address multiple vulnerabilities in several SAP products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>Point of Sale (POS) Retail Xpress Server<\/li>\n\t<li>NetWeaver AS Java Web Container<\/li>\n\t<li>Visual Composer 04s iviews<\/li>\n\t<li>BusinessObjects<\/li>\n\t<li>NetWeaver Java Server\u00a0<\/li>\n\t<li>Sybase<\/li>\n\t<li>CRM WebClient User Interface<\/li>\n\t<li>CRM IPC Pricing<\/li>\n\t<li>CRM WebClient UI<\/li>\n\t<li>NetWeaver Business Client for HTML<\/li>\n\t<li>SRM Live Auction Application<\/li>\n\t<li>Adobe Document Services<\/li>\n\t<li>Web Intelligence<\/li>\n\t<li>NetWeaver<\/li>\n\t<li>NetWeaver Logon Application<\/li>\n\t<li>NetWeaver K.M. Web Page Composer<\/li>\n\t<li>ABAP Workbench<\/li>\n<\/ul><p>SAP Security Note References: 2486657, 2376081, 2381071, 2499109, 2494184, 2450979, 2481262, 2425744, 2417020, 2493099, 2392719, 2428512, 2453642, 2423540, 2394536, 2463354.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released update to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/blogs.sap.com\/2017\/08\/08\/sap-security-patch-day-august-2017\/\"><font color=\"#0066cc\">https:\/\/blogs.sap.com\/2017\/08\/08\/sap-security-patch-day-august-2017\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-patches","alert_type":396,"serial_number":"AV17-124","subject":null,"moderation_state":"archived","external_url":null},{"nid":1242,"title":"Juniper Networks security bulletins","uuid":"d89d5a05-eb84-4651-a40e-dd049f96fea6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-05T14:39:02Z","summary":null,"body":["<article data-history-node-id=\"1242\" about=\"\/en\/alerts-advisories\/juniper-networks-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-125<br \/>\nDate: 10 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security bulletins released by Juniper Networks.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Juniper Networks has released product updates addressing vulnerabilities in the Junos OS. Successful exploitation could result in either a heap overflow or an extended denial of service condition for the device.<\/p>\n\n<p>Affected Products:<br \/>\nJunos OS 12.1X46, 12.3X48, 15.1X49, 14.2, 15.1, 15.1X53, 16.1, 16.2.<br \/>\nJunos OS 12.3X48, 13.3, 14.1, 14.1X53, 14.2, 15.1, 15.1X49, 15.1X53, 16.1.<\/p>\n\n<p>CVE References: CVE-2017-2347, CVE-2016-3074.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10795&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10795&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10798&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10798&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-bulletins-0","alert_type":396,"serial_number":"AV17-125","subject":null,"moderation_state":"archived","external_url":null},{"nid":954,"title":"PostgreSQL security update","uuid":"4faabcd2-e489-4419-9b37-d2ea3fabf13f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-05T14:45:00Z","summary":null,"body":["<article data-history-node-id=\"954\" about=\"\/en\/alerts-advisories\/postgresql-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-126<br \/>\nDate: 16 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for PostgreSQL.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The PostgreSQL Global Development Group has released an update to all supported versions of their database system, including 9.6.4, 9.5.8, 9.4.13, 9.3.18, and 9.2.22. This release fixes three vulnerabilities that could be exploited to bypass authentication mechanisms, to gain access to sensitive information or to cause a denial-of-service condition.<\/p>\n\n<p>CVE References: CVE-2017-7546, CVE-2017-7547, CVE-2017-7548<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.postgresql.org\/about\/news\/1772\/\"><font color=\"#0066cc\">https:\/\/www.postgresql.org\/about\/news\/1772\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2017-7546\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/cve\/CVE-2017-7546<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2017-7547\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/cve\/CVE-2017-7547<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2017-7548\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/cve\/CVE-2017-7548<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/postgresql-security-update","alert_type":396,"serial_number":"AV17-126","subject":null,"moderation_state":"archived","external_url":null},{"nid":1119,"title":"Cisco security updates","uuid":"ddefcb42-385d-4f1b-8e66-acc510344bc7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-05T14:51:01Z","summary":null,"body":["<article data-history-node-id=\"1119\" about=\"\/en\/alerts-advisories\/cisco-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-127<br \/>\nDate: 16 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<p>- Cisco Virtual Network Function Element Manager Arbitrary Command Execution Vulnerability<br \/>\n- Cisco Application Policy Infrastructure Controller Custom Binary Privilege Escalation Vulnerability<br \/>\n- Cisco Application Policy Infrastructure Controller SSH Privilege Escalation Vulnerability<br \/>\n- Cisco TelePresence Video Communication Server Denial of Service Vulnerability<br \/>\n- Cisco Ultra Services Platform Deployment Configuration Information Disclosure Vulnerability<br \/>\n- Cisco Unified Communications Manager Horizontal Privilege Escalation Vulnerability<br \/>\n- Cisco StarOS for ASR 5000 Series Routers Privilege Escalation Vulnerability<br \/>\n- Cisco StarOS for ASR 5000 Series Routers FTP Configuration File Modification Vulnerability<br \/>\n- Cisco StarOS for ASR 5000 Series Routers Command-Line Interface Security Bypass Vulnerability<br \/>\n- Cisco Elastic Services Controller Sensitive Log Information Disclosure Vulnerability<br \/>\n- Cisco Elastic Services Controller Configuration Parameters Information Disclosure Vulnerability<br \/>\n- Cisco Elastic Services Controller Cross-Site Scripting Vulnerability<br \/>\n- Cisco Elastic Services Controller Configuration Files Information Disclosure Vulnerability<br \/>\n- Cisco Security Appliances SNMP Polling Information Disclosure Vulnerability<br \/>\n- Cisco RV340, RV345, and RV345P Dual WAN Gigabit VPN Routers Information Disclosure Vulnerability<br \/>\n- Cisco Policy Suite Privilege Escalation Vulnerability<br \/>\n- Cisco Prime Infrastructure HTML Injection Vulnerability<br \/>\n- Cisco AnyConnect WebLaunch Cross-Site Scripting Vulnerability<\/p>\n\n<p>CVE References:<br \/>\nCVE-2017-6710, CVE-2017-6767, CVE-2017-6768, CVE-2017-6772, CVE-2017-6773, CVE-2017-6774,<br \/>\nCVE-2017-6775, CVE-2017-6776, CVE-2017-6777, CVE-2017-6778, CVE-2017-6781, CVE-2017-6783,<br \/>\nCVE-2017-6782, CVE-2017-6784, CVE-2017-6785, CVE-2017-6786, CVE-2017-6788, CVE-2017-6790<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-em\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-em<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-apic2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-apic2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-apic1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-apic1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-vcs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-vcs<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-usp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-usp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-usf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-usf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-ucm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-staros3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-staros3<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-staros2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-staros2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-staros1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-staros1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc4<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc3<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc2<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-esc1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-csa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-csa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-crr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-crr<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-cps\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-cps<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-cpi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-cpi<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-caw\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170816-caw<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-3","alert_type":396,"serial_number":"AV17-127","subject":null,"moderation_state":"archived","external_url":null},{"nid":943,"title":"Drupal security updates","uuid":"21bed345-0dec-4b21-9b68-b8152342c3cf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:01Z","date_created":"2018-07-05T14:58:20Z","summary":null,"body":["<article data-history-node-id=\"943\" about=\"\/en\/alerts-advisories\/drupal-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-128<br \/>\nDate: 17 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Drupal security release.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple security vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to bypass certain security restrictions and perform unauthorized actions.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Drupal 7 Views module<\/li>\n\t<li>Drupal core 8.x versions prior to 8.3.7<\/li>\n<\/ul><p>CVE References: CVE-2017-6923, CVE-2017-6924, CVE-2017-6925<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/SA-CORE-2017-004\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/SA-CORE-2017-004<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-updates-2","alert_type":null,"serial_number":"AV17-128","subject":null,"moderation_state":"archived","external_url":null},{"nid":752,"title":"HP security bulletin","uuid":"8ad28614-04ef-4b2f-a7aa-9e15acc8cdf1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:16Z","date_created":"2018-07-05T15:08:01Z","summary":null,"body":["<article data-history-node-id=\"752\" about=\"\/en\/alerts-advisories\/hp-security-bulletin-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-129<br \/>\nDate: 25 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an HP security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HP has released a security update to address a potential security vulnerability that has been identified in HPE Integrated Lights-out (iLO 4) which could be exploited remotely to allow authentication bypass and execution of code.<\/p>\n\n<p>Affected software versions:<br \/>\n- HP Integrated Lights-Out 4 (iLO 4), Prior to 2.53<\/p>\n\n<p>CVE Reference: CVE-2017-12542<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/h20565.www2.hpe.com\/hpsc\/doc\/public\/display?docId=hpesbhf03769en_us\"><font color=\"#0066cc\">http:\/\/h20565.www2.hpe.com\/hpsc\/doc\/public\/display?docId=hpesbhf03769en_us<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hp-security-bulletin-2","alert_type":396,"serial_number":"AV17-129","subject":null,"moderation_state":"archived","external_url":null},{"nid":832,"title":"[Control systems] Rockwell Automation Allen-Bradley Stratix and ArmoStratix security advisory","uuid":"4cf109df-2a0e-4a23-8b27-818879259f90","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-05T15:14:28Z","summary":null,"body":["<article data-history-node-id=\"832\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-allen-bradley-stratix-and-armostratix-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-130<br \/>\nDate: August 28, 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released security advisory for Allen-Bradley Stratix and ArmoStratix products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation has released a security advisory to address vulnerabilities in its Allen-Bradley\u00a0 Stratix and ArmoStratix products. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to execute code on an affected system or cause an affected system to crash and reload.<\/p>\n\n<p>Affected versions:<\/p>\n\n<ul><li>All versions 15.2(5)EA.fc4 and earlier\n\t<ul><li>Allen-Bradley Stratix 5400 Industrial Ethernet Switches<\/li>\n\t\t<li>Allen-Bradley Stratix 5410 Industrial Distribution Switches<\/li>\n\t\t<li>Allen-Bradley Stratix 5700 and ArmorStratix\u2122 5700 Industrial Managed Ethernet Switches<\/li>\n\t\t<li>Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches<\/li>\n\t<\/ul><\/li>\n\t<li>Allen-Bradley Stratix 5900 Services Router - all versions 15.6(3)M1 and earlier<\/li>\n\t<li>Stratix 8300 Modular Managed Ethernet Switches - all versions 15.2(4)EA and earlier<\/li>\n<\/ul><p>CVE References: CVE-2017-6736, CVE-2017-6737, CVE-2017-6738, CVE-2017-6739, CVE-2017-6740, CVE-2017-6741, CVE-2017-6742, CVE-2017-6743, CVE-2017-6744<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected devices per your change management policies.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-208-04\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-208-04<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170629-snmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170629-snmp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/1055133\"><font color=\"#0066cc\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/1055133<\/font><\/a> (login required)<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-allen-bradley-stratix-and-armostratix-security-advisory","alert_type":398,"serial_number":"AV17-130","subject":null,"moderation_state":"archived","external_url":null},{"nid":1290,"title":"[Control systems] Siemens security updates","uuid":"c9faa160-d0c4-45f7-9cdb-e655205418d3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:24:00Z","date_created":"2018-07-05T15:21:04Z","summary":null,"body":["<article data-history-node-id=\"1290\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-131<br \/>\nDate: September 5, 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Siemens security updates for products using the Discovery Service of the OPC UA protocol stack by the OPC foundation.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Siemens released security updates for the Discovery Service of the OPC UA protocol stack to address an Improper Restriction of XML External Entity Reference. A low skilled remote user could potentially exploit this vulnerability by sending specially crafted packets to the OPC Discovery Server at Port 4840\/TCP and access various resources.<\/p>\n\n<p>Affected products:<\/p>\n\n<p>\u2022 SIMATIC PCS 7 - V7.1 and earlier versions, V8.0: All versions, V8.1: All versions.<br \/>\n\u2022 SIMATIC WinCC - V7.0: All versions, V7.2: All versions, V7.3: All versions, V7.4: All versions prior to V7.4\u00a0\u00a0 SP1.<br \/>\n\u2022 SIMATIC WinCC Runtime Professional - V13: All versions, V14: All versions prior to V14 SP1.<br \/>\n\u2022 SIMATIC NET PC Software: All versions.<br \/>\n\u2022 SIMATIC IT Production Suite: All versions.<\/p>\n\n<p>CVE Reference: CVE-2017-12069<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. For more information, please refer to the ICS-CERT references.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>SIEMENS Security Advisory SSA-535640:<br \/><a href=\"https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-535640.pdf\"><font color=\"#0066cc\">https:\/\/www.siemens.com\/cert\/pool\/cert\/siemens_security_advisory_ssa-535640.pdf<\/font><\/a><br \/><br \/>\nICS-CERT Advisory (ICSA-17-243-01):<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-243-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-243-01<\/font><\/a> \u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-updates-0","alert_type":398,"serial_number":"AV17-131","subject":null,"moderation_state":"archived","external_url":null},{"nid":1083,"title":"Google Releases security update for Chrome","uuid":"390b76fc-814f-4ea5-90de-fa76b25c1fbb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-05T15:26:46Z","summary":null,"body":["<article data-history-node-id=\"1083\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-24\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-132<br \/>\nDate: 06 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 61.0.3163.79 for Windows, Mac and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References:\u00a0 CVE-2017-5111, CVE-2017-5112, CVE-2017-5113, CVE-2017-5114, CVE-2017-5115, CVE-2017-5116, CVE-2017-5117, CVE-2017-5118, CVE-2017-5119, CVE-2017-5120<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/09\/stable-channel-update-for-desktop.html?m=1\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/09\/stable-channel-update-for-desktop.html?m=1<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-24","alert_type":396,"serial_number":"AV17-132","subject":null,"moderation_state":"archived","external_url":null},{"nid":1328,"title":"Apache Struts security update","uuid":"717de62a-e920-4766-811b-c161fc18634d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-05T15:33:02Z","summary":null,"body":["<article data-history-node-id=\"1328\" about=\"\/en\/alerts-advisories\/apache-struts-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-133<br \/>\nDate: 06 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released critical security updates for Apache Struts.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apache has released Struts 2.3.34 and 2.5.13 which contains security fixes to address critical vulnerabilities and other vulnerabilities in their software.<\/p>\n\n<p>Versions affected:<br \/>\nApache Struts 2.3.x, versions 2.1.2 to 2.3.33<br \/>\nApache Struts 2.5.x, versions 2.5 to 2.5.12<\/p>\n\n<p>CVE References: CVE-2017-9793, CVE-2017-9804, CVE-2017-9805<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to the linked security bulletin where Apache outlines the updates that remediate these vulnerabilities.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/struts.apache.org\/announce.html\"><font color=\"#0066cc\">https:\/\/struts.apache.org\/announce.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/struts.apache.org\/docs\/s2-050.html\"><font color=\"#0066cc\">https:\/\/struts.apache.org\/docs\/s2-050.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/struts.apache.org\/docs\/s2-051.html\"><font color=\"#0066cc\">https:\/\/struts.apache.org\/docs\/s2-051.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/struts.apache.org\/docs\/s2-052.html\"><font color=\"#0066cc\">https:\/\/struts.apache.org\/docs\/s2-052.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/cwiki.apache.org\/confluence\/pages\/viewpage.action?pageId=73634784\"><font color=\"#0066cc\">https:\/\/cwiki.apache.org\/confluence\/pages\/viewpage.action?pageId=73634784<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-struts-security-update","alert_type":396,"serial_number":"AV17-133","subject":null,"moderation_state":"archived","external_url":null},{"nid":1137,"title":"Adobe security updates","uuid":"72debdac-5af3-43ce-a381-aa53dbb3e131","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-05T15:38:33Z","summary":null,"body":["<article data-history-node-id=\"1137\" about=\"\/en\/alerts-advisories\/adobe-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-134<br \/>\nDate: 12 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security updates for various Adobe products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<br \/>\nAPSB17-25: Security Updates Available for RoboHelp<br \/>\nAPSB17-28: Security Updates Available for Adobe Flash Player<br \/>\nAPSB17-30: Security Update for ColdFusion<\/p>\n\n<p>CVE References: CVE-2017-3104, CVE-2017-3105, CVE-2017-11281, CVE-2017-11282, CVE-2017-11283, CVE-2017-11284, CVE-2017-11285, CVE-2017-11286<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/robohelp\/apsb17-25.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/robohelp\/apsb17-25.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-28.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-28.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb17-30.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb17-30.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates-5","alert_type":396,"serial_number":"AV17-134","subject":null,"moderation_state":"archived","external_url":null},{"nid":1228,"title":"Microsoft security updates","uuid":"a034c4d9-cec4-4cf5-95a3-ce4423859ac6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-05T15:44:38Z","summary":null,"body":["<article data-history-node-id=\"1228\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-135<br \/>\nDate: 13 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products including Internet Explorer, Edge, Windows, Office, Office Services and Web Apps, Adobe Flash Player, Skype for Business, Lync, .NET Framework and Exchange Server.<\/p>\n\n<p>CVE References: CVE-2017-0161, CVE-2017-8567, CVE-2017-8597, CVE-2017-8628, CVE-2017-8629, CVE-2017-8630, CVE-2017-8631, CVE-2017-8632, CVE-2017-8643, CVE-2017-8648, CVE-2017-8649, CVE-2017-8660, CVE-2017-8675, CVE-2017-8676, CVE-2017-8677, CVE-2017-8678, CVE-2017-8679, CVE-2017-8680, CVE-2017-8681, CVE-2017-8682, CVE-2017-8683, CVE-2017-8684, CVE-2017-8685, CVE-2017-8686, CVE-2017-8687, CVE-2017-8688, CVE-2017-8692, CVE-2017-8695, CVE-2017-8696, CVE-2017-8699, CVE-2017-8702, CVE-2017-8704, CVE-2017-8706, CVE-2017-8707, CVE-2017-8708, CVE-2017-8709, CVE-2017-8710, CVE-2017-8711, CVE-2017-8712, CVE-2017-8713, CVE-2017-8714, CVE-2017-8716, CVE-2017-8719, CVE-2017-8720, CVE-2017-8723, CVE-2017-8724, CVE-2017-8725, CVE-2017-8728, CVE-2017-8729, CVE-2017-8731, CVE-2017-8733, CVE-2017-8734, CVE-2017-8735, CVE-2017-8736, CVE-2017-8737, CVE-2017-8738, CVE-2017-8739, CVE-2017-8740, CVE-2017-8741, CVE-2017-8742, CVE-2017-8743, CVE-2017-8744, CVE-2017-8745, CVE-2017-8746, CVE-2017-8747, CVE-2017-8748, CVE-2017-8749, CVE-2017-8750, CVE-2017-8751, CVE-2017-8752, CVE-2017-8753, CVE-2017-8754, CVE-2017-8755, CVE-2017-8756, CVE-2017-8757, CVE-2017-8758, CVE-2017-8759, CVE-2017-9417, CVE-2017-11761, CVE-2017-11764, CVE-2017-11766<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/5984735e-f651-e711-80dd-000d3a32fc99\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/5984735e-f651-e711-80dd-000d3a32fc99<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-4","alert_type":396,"serial_number":"AV17-135","subject":null,"moderation_state":"archived","external_url":null},{"nid":1314,"title":"VMware security updates","uuid":"d1ff6771-8868-4245-82f1-45280e8b5137","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:01:05Z","date_created":"2018-07-05T15:52:01Z","summary":null,"body":["<article data-history-node-id=\"1314\" about=\"\/en\/alerts-advisories\/vmware-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-136<br \/>\nDate: 15 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<br \/>\n-VMware ESXi<br \/>\n-VMware vCenter Server<br \/>\n-VMware Workstation Player and Workstation Pro<br \/>\n-VMware Fusion and Fusion Pro<\/p>\n\n<p>CVE References: CVE-2017-4924, CVE-2017-4925, CVE-2017-4926<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0015.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0015.html<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-5","alert_type":396,"serial_number":"AV17-136","subject":null,"moderation_state":"archived","external_url":null},{"nid":1065,"title":"Apache Tomcat security updates","uuid":"e96a7f55-c749-48b5-9539-d4f8a78a3a0b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-05T17:01:18Z","summary":null,"body":["<article data-history-node-id=\"1065\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-137<br \/>\nDate: 19 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates for Apache Tomcat.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Apache Foundation has released security updates to address vulnerabilities in Apache Tomcat. Exploitation of this vulnerability may allow a remote attacker to take control of a vulnerable server.<\/p>\n\n<p>Affected Products:<br \/>\n- Apache Tomcat 7.0.0 to 7.0.79<\/p>\n\n<p>CVE References: CVE-2017-12515, CVE-2017-12616<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"http:\/\/tomcat.apache.org\/security-7.html\"><font color=\"#0066cc\">http:\/\/tomcat.apache.org\/security-7.html<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-updates","alert_type":396,"serial_number":"AV17-137","subject":null,"moderation_state":"archived","external_url":null},{"nid":1087,"title":"Apple security updates","uuid":"32f756ea-8302-43c0-a820-995d5dcb693c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:18Z","date_created":"2018-07-05T17:06:36Z","summary":null,"body":["<article data-history-node-id=\"1087\" about=\"\/en\/alerts-advisories\/apple-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-138<br \/>\nDate: 20 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iOS 11, Safari 11, Xcode 9, tvOS 11, watchOS 4 and iTunes 12.7.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles regarding security vulnerabilities in their products:<\/p>\n\n<ul><li>HT208103 - Xcode 9<\/li>\n\t<li>HT208112 - iOS 11<\/li>\n\t<li>HT208116 - Safari 11<\/li>\n<\/ul><p>This update addresses multiple vulnerabilities on the systems listed above.<\/p>\n\n<p>Apple will release further details shortly for iTunes 12.7, tvOS 11 and watchOS 4.<\/p>\n\n<p>CVE Reference: CVE-2017-1000117, CVE-2017-7072, CVE-2017-7076, CVE-2017-7085, CVE-2017-7088, CVE-2017-7089, CVE-2017-7097, CVE-2017-7106, CVE-2017-7118, CVE-2017-7134, CVE-2017-7135, CVE-2017-7136, CVE-2017-7137, CVE-2017-9800<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT201222<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208112\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208112<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208116\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208116<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208103\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208103<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-1","alert_type":396,"serial_number":"AV17-138","subject":null,"moderation_state":"archived","external_url":null},{"nid":1056,"title":"WordPress security update","uuid":"57c1ab08-44cd-455f-9d46-fa8e266cffd4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-05T17:12:14Z","summary":null,"body":["<article data-history-node-id=\"1056\" about=\"\/en\/alerts-advisories\/wordpress-security-update-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-139<br \/>\nDate: 20 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.8.2 that contains security fixes to address multiple vulnerabilities including SQLi, XSS and path traversal.<\/p>\n\n<p>Versions affected: WordPress 4.8.2 and earlier<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2017\/09\/wordpress-4-8-2-security-and-maintenance-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2017\/09\/wordpress-4-8-2-security-and-maintenance-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-2","alert_type":396,"serial_number":"AV17-139","subject":null,"moderation_state":"archived","external_url":null},{"nid":792,"title":"Joomla! security update","uuid":"fa656f42-409c-438a-97a1-e7177baeaf80","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-05T17:17:59Z","summary":null,"body":["<article data-history-node-id=\"792\" about=\"\/en\/alerts-advisories\/joomla-security-update-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-140<br \/>\nDate: 22 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.8.0 of its web content management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected: Joomla! 1.5.0 - 3.7.5<\/p>\n\n<p>CVE References: CVE-2017-14595, CVE-2017-14596<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5713-joomla-3-8-0-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5713-joomla-3-8-0-release.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update-2","alert_type":396,"serial_number":"AV17-140","subject":null,"moderation_state":"archived","external_url":null},{"nid":1244,"title":"Samba security update","uuid":"81b26a51-33d2-4555-9a7e-998e3d06f0d6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-05T17:24:51Z","summary":null,"body":["<article data-history-node-id=\"1244\" about=\"\/en\/alerts-advisories\/samba-security-update-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-141<br \/>\nDate: 22 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Samba.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Samba has released security patches to address vulnerabilities which could allow a malicious actor to perform man-in-the-middle (MITM) attacks and\/or exploit server memory leaks.<\/p>\n\n<p>Affected Versions: All versions are affected.<\/p>\n\n<p>CVE References:<br \/>\nCVE-2017-12150, CVE-2017-12151, CVE-2017-12163<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2017-12150.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2017-12150.html<\/font><\/a><br \/><a href=\"http:\/\/www.samba.org\/samba\/security\/CVE-2017-12151.html\"><font color=\"#0066cc\">http:\/\/www.samba.org\/samba\/security\/CVE-2017-12151.html<\/font><\/a><br \/><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2017-12163.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2017-12163.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-update-1","alert_type":396,"serial_number":"AV17-141","subject":null,"moderation_state":"archived","external_url":null},{"nid":955,"title":"Google Releases security update for Chrome","uuid":"e7afacfc-d05e-4570-b1ca-fe39f219a059","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-05T17:34:46Z","summary":null,"body":["<article data-history-node-id=\"955\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-25\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-142<br \/>\nDate: 22 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to 61.0.3163.100 for Windows, Mac and Linux. This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2017-5121, CVE-2017-5122<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/09\/stable-channel-update-for-desktop_21.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/09\/stable-channel-update-for-desktop_21.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-25","alert_type":396,"serial_number":"AV17-142","subject":null,"moderation_state":"archived","external_url":null},{"nid":1121,"title":"Apple security updates","uuid":"4f071439-2ddb-468f-bc05-2fec1ddeffd0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-05T17:40:43Z","summary":null,"body":["<article data-history-node-id=\"1121\" about=\"\/en\/alerts-advisories\/apple-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-143<br \/>\nDate: 26 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iCloud for Windows, macOS High Sierra and macOS Server.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles addressing security vulnerabilities in various products:<\/p>\n\n<ul><li>iCloud for Windows 7.0<\/li>\n\t<li>macOS High Sierra 10.13<\/li>\n\t<li>macOS Server 5.4<\/li>\n<\/ul><p>CVE Reference: CVE-2017-6451,\u00a0 CVE-2017-7080,\u00a0 CVE-2017-7092,\u00a0 CVE-2017-7130, CVE-2016-9042, CVE-2016-9063, CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843, CVE-2017-0381, CVE-2017-6452, CVE-2017-6455, CVE-2017-6458, CVE-2017-6459, CVE-2017-6460, CVE-2017-6462, CVE-2017-6463, CVE-2017-6464, CVE-2017-7074, CVE-2017-7077, CVE-2017-7078, CVE-2017-7081, CVE-2017-7082, CVE-2017-7083, CVE-2017-7084, CVE-2017-7087, CVE-2017-7090, CVE-2017-7091, CVE-2017-7093, CVE-2017-7094, CVE-2017-7095, CVE-2017-7096, CVE-2017-7097, CVE-2017-7098, CVE-2017-7099, CVE-2017-7100, CVE-2017-7102, CVE-2017-7104, CVE-2017-7106, CVE-2017-7107, CVE-2017-7109, CVE-2017-7111, CVE-2017-7114; CVE-2017-7086, CVE-2017-7117, CVE-2017-7119, CVE-2017-7120, CVE-2017-7121, CVE-2017-7122, CVE-2017-7123, CVE-2017-7124, CVE-2017-7125, CVE-2017-7126, CVE-2017-7127, CVE-2017-7128, CVE-2017-7129, CVE-2017-7141, CVE-2017-7143, CVE-2017-9233, CVE-2017-10978, CVE-2017-10979, CVE-2017-10989, CVE-2017-11103, CVE-2017-1000373<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-us\/HT208142\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208142<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208144\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208144<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208102\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208102<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-2","alert_type":396,"serial_number":"AV17-143","subject":null,"moderation_state":"archived","external_url":null},{"nid":953,"title":"Cisco security updates","uuid":"bfc08e00-66af-415e-9b95-23fe5229e8fc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-05T17:46:34Z","summary":null,"body":["<article data-history-node-id=\"953\" about=\"\/en\/alerts-advisories\/cisco-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-144<br \/>\nDate: 27 September 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<p>-Cisco IOS XE Software Web UI REST API Authentication Bypass Vulnerability<br \/>\n-Cisco IOS XE Software Web UI Privilege Escalation Vulnerability<br \/>\n-Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability<br \/>\n-Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability<br \/>\n-Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability<br \/>\n-Cisco IOS Software for Cisco Integrated Services Routers Generation 2 Denial of Service Vulnerability<br \/>\n-Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Plug-and-Play PKI API Certificate Validation Vulnerability<br \/>\n-Cisco IOS XE Software for Cisco 5760 WLC, Cisco Catalyst 4500E Supervisor Engine 8-E, and Cisco NGWC 3850 GUI Privilege Escalation Vulnerability<br \/>\n-Cisco IOS Software Network Address Translation Denial of Service Vulnerability<br \/>\n-Cisco IOS XE Software Locator\/ID Separation Protocol Authentication Bypass Vulnerability<br \/>\n-Cisco IOS XE Wireless Controller Manager Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Internet Key Exchange Denial of Service Vulnerability<br \/>\n-Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities<br \/>\n-Cisco IOS XE Software for Cisco ASR 1000 Series and cBR-8 Routers Line Card Console Access Vulnerability<\/p>\n\n<p>CVE References: CVE-2017-3831, CVE-2017-12222, CVE-2017-12226, CVE-2017-12228, CVE-2017-12229, CVE-2017-12230, CVE-2017-12231, CVE-2017-12232, CVE-2017-12233, CVE-2017-12234, CVE-2017-12235, CVE-2017-12236, CVE-2017-12237, CVE-2017-12238, CVE-2017-12239, CVE-2017-12240<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-restapi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-restapi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-privesc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-privesc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-dhcp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-dhcp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ap1800\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170315-ap1800<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-vpls\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-vpls<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-rbip-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-rbip-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-profinet\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-profinet<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-pnp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-pnp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-ngwc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-ngwc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-nat\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-nat<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-lisp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-lisp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-ios-xe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-ios-xe<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-ike\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-ike<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-cip\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-cip<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-cc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-cc<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-4","alert_type":396,"serial_number":"AV17-144","subject":null,"moderation_state":"archived","external_url":null},{"nid":998,"title":"Apache Tomcat security update","uuid":"bac205e5-8b49-4116-a162-67b7829dc680","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:01Z","date_created":"2018-07-05T17:51:47Z","summary":null,"body":["<article data-history-node-id=\"998\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-145<br \/>\nDate: 04 October 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates for Apache Tomcat.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Apache Foundation has released security update to address vulnerability in Apache Tomcat. Exploitation of this vulnerability may allow a remote user to perform remote code execution.<\/p>\n\n<p>Affected Versions:<br \/>\nApache Tomcat 9.0.0.M1 to 9.0.0<br \/>\nApache Tomcat 8.5.0 to 8.5.22<br \/>\nApache Tomcat 8.0.0.RC1 to 8.0.46<br \/>\nApache Tomcat 7.0.0 to 7.0.81<\/p>\n\n<p>CVE Reference: CVE-2017-12617<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>Reference:<\/strong><\/p>\n\n<ul><li><a href=\"http:\/\/tomcat.apache.org\/security.html\"><font color=\"#0066cc\">http:\/\/tomcat.apache.org\/security.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-update","alert_type":396,"serial_number":"AV17-145","subject":null,"moderation_state":"archived","external_url":null},{"nid":755,"title":"Mozilla security updates","uuid":"ee4ae902-3fd1-433b-9876-9de60cc4d473","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-05T17:58:22Z","summary":null,"body":["<article data-history-node-id=\"755\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-146<br \/>\nDate: 04 October 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Mozilla Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address multiple vulnerabilities in Firefox. A remote user could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>Versions Affected<\/p>\n\n<p>-Firefox prior to 56 and Firefox ESR 52.4<\/p>\n\n<p>CVE References: CVE-2017-7793, CVE-2017-7805, CVE-2017-7810, CVE-2017-7814, CVE-2017-7818, CVE-2017-7819, CVE-2017-7823, CVE-2017-7824<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>Reference:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-21\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-21\/<\/font><\/a><\/p>\n\t<\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-22\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-22\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-0","alert_type":396,"serial_number":"AV17-146","subject":null,"moderation_state":"archived","external_url":null},{"nid":824,"title":"GNU dnsmasq security updates","uuid":"1b3ece65-37f5-4da6-b10b-cb30dd7c8775","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-05T18:06:09Z","summary":null,"body":["<article data-history-node-id=\"824\" about=\"\/en\/alerts-advisories\/gnu-dnsmasq-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-147<br \/>\nDate: 04 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple dnsmasq security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>GNU dnsmasq released security updates to address multiple vulnerabilities in dnsmasq. A remote user could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>Versions Affected:<\/p>\n\n<p>GNU dnsmasq 2.62 to 2.77<\/p>\n\n<p>CVE References: CVE-2017-13704, CVE-2017-14491,CVE-2017-14492,CVE-2017-14493,CVE-2017-14494,CVE-2017-14495,CVE-2017-14496<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"http:\/\/www.vuxml.org\/freebsd\/b77b5646-a778-11e7-ac58-b499baebfeaf.html\"><font color=\"#0066cc\">http:\/\/www.vuxml.org\/freebsd\/b77b5646-a778-11e7-ac58-b499baebfeaf.html<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/lists.thekelleys.org.uk\/pipermail\/dnsmasq-discuss\/2017q4\/011771.html\"><font color=\"#0066cc\">http:\/\/lists.thekelleys.org.uk\/pipermail\/dnsmasq-discuss\/2017q4\/011771.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gnu-dnsmasq-security-updates","alert_type":396,"serial_number":"AV17-147","subject":null,"moderation_state":"archived","external_url":null},{"nid":966,"title":"HPE security updates","uuid":"97e0c421-d2c8-475b-9e70-2d6221c4c3e6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-05T18:12:09Z","summary":null,"body":["<article data-history-node-id=\"966\" about=\"\/en\/alerts-advisories\/hpe-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-148<br \/>\nDate: 04 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates by HPE.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HPE released security updates to address multiple vulnerabilities in the Intelligent Management Center (iMC) PLAT. Exploitation of these vulnerabilities could lead to execution of arbitrary code or denial of service. \u00a0<\/p>\n\n<p>Versions Affected<\/p>\n\n<p>- HPE Intelligent Management Center (iMC) iMC Plat 7.3 E0504P4 and earlier<br \/>\n- HPE Intelligent Management Center (iMC) iMC Plat 7.3 E0504P2 and earlier<\/p>\n\n<p>CVE References: CVE-2017-12559, CVE-2017-12560, CVE-2017-12561<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"http:\/\/h20566.www2.hpe.com\/hpsc\/doc\/public\/display?docId=hpesbhf03781en_us\"><font color=\"#0066cc\">http:\/\/h20566.www2.hpe.com\/hpsc\/doc\/public\/display?docId=hpesbhf03781en_us<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"http:\/\/h20566.www2.hpe.com\/hpsc\/doc\/public\/display?docId=hpesbhf03777en_us\"><font color=\"#0066cc\">http:\/\/h20566.www2.hpe.com\/hpsc\/doc\/public\/display?docId=hpesbhf03777en_us<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-updates","alert_type":396,"serial_number":"AV17-148","subject":null,"moderation_state":"archived","external_url":null},{"nid":865,"title":"Cisco security updates","uuid":"e5566a4c-f741-4ae7-a75a-0b17414e7b27","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-05T18:18:19Z","summary":null,"body":["<article data-history-node-id=\"865\" about=\"\/en\/alerts-advisories\/cisco-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-149<br \/>\nDate: 05 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<p>Cisco Firepower Detection Engine SSL Decryption<br \/>\nCisco Firepower Detection Engine<br \/>\nCisco License Manager<br \/>\nCisco Adaptive Security Appliance<br \/>\nCisco Web Security Appliance<br \/>\nCisco Adaptive Security Appliance<br \/>\nCisco WebEx Meetings<br \/>\nCisco Wide Area Application Services ICA<br \/>\nCisco Wide Area Application Services<br \/>\nCisco Unified Communications Manager<br \/>\nCisco Spark Messaging Stored<br \/>\nCisco IOS XR Software<br \/>\nCisco Meeting Server<br \/>\nCisco Meeting App<br \/>\nCisco AnyConnect Network Access Manager<br \/>\nCisco Integrated Management Controller<br \/>\nCisco Integrated Management Controller<br \/>\nCisco IOS Software for Cisco Industrial Ethernet Switches PROFINET<\/p>\n\n<p>CVE References: \u00a0CVE-2017-12268, CVE-2017-12266, CVE-2017-12264, CVE-2017-12270, CVE-2017-12269, CVE-2017-12258, CVE-2017-12256, CVE-2017-12267, CVE-2017-12257, CVE-2017-12265, CVE-2016-9212, CVE-2017-12246, CVE-2017-12263,\u00a0 CVE-2017-12244, CVE-2017-12245, CVE-2017-6616, CVE-2017-9793, CVE-2017-9804, CVE-2017-12611, CVE-2017-6619, CVE-2017-12235<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-ftd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-ftd<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-fpsnort\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-fpsnort<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-clm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-clm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-asa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-asa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-wsa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161207-wsa1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-asa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-asa1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-wms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-wms<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-waas1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-waas1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-waas\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-waas<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-ucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-sprk\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-sprk<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-ncs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-ncs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-cms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-cms<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-cma\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-cma<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-anam\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171004-anam<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170419-cimc3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170419-cimc3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170909-struts2-rce\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170909-struts2-rce<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170419-cimc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170419-cimc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-dhcp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-dhcp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-profinet\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170927-profinet<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-5","alert_type":396,"serial_number":"AV17-149","subject":null,"moderation_state":"archived","external_url":null},{"nid":1330,"title":"HPE security updates","uuid":"736b5cdc-9b60-4f69-a147-0c838d5dc630","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-05T18:39:53Z","summary":null,"body":["<article data-history-node-id=\"1330\" about=\"\/en\/alerts-advisories\/hpe-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-150<br \/>\nDate: 06 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates by HPE.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HPE released security updates to address multiple vulnerabilities in HPE BSM Platform Application Performance Management System Health. Exploitation of these vulnerabilities could allow remote users to bypass authentication and perform directory traversal, arbitrary file deletion, unrestricted file upload and information disclosure.<br \/><br \/>\nVersions Affected:<\/p>\n\n<ul><li>HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40<\/li>\n<\/ul><p>CVE References: CVE-2017-13982, CVE-2017-13983<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-13982\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-13982<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-13983\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-13983<\/font><\/a><\/p>\n\t<\/li>\n\t<li><a href=\"https:\/\/softwaresupport.hpe.com\/km\/KM02942065\"><font color=\"#0066cc\">https:\/\/softwaresupport.hpe.com\/km\/KM02942065<\/font><\/a> (Requires Login)<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-updates-0","alert_type":396,"serial_number":"AV17-150","subject":null,"moderation_state":"archived","external_url":null},{"nid":1027,"title":"Microsoft security updates","uuid":"4bf7108a-8671-4f68-aa96-548225309fba","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-05T18:46:30Z","summary":null,"body":["<article data-history-node-id=\"1027\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-151<br \/>\nDate: 10 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products including Windows 10 and Windows Server 2016 (including Microsoft Edge), Windows 8.1 and Windows Server 2012 R2, Windows Server 2012, Windows RT 8.1, Windows 7 and Windows Server 2008 R2, Windows Server 2008, Microsoft Office-related software, Internet Explorer, Microsoft SharePoint Enterprise Server, Microsoft Lync and Skype for Business and ChakraCore.<\/p>\n\n<p>CVE References:\u00a0 CVE-2017-11762, CVE-2017-11771, CVE-2017-11777, CVE-2017-11779, CVE-2017-11780, CVE-2017-11796, CVE-2017-11826<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/313ae481-3088-e711-80e2-000d3a32fc99\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/313ae481-3088-e711-80e2-000d3a32fc99<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-5","alert_type":396,"serial_number":"AV17-151","subject":null,"moderation_state":"archived","external_url":null},{"nid":1220,"title":"Apple security updates","uuid":"a8f8a355-5904-47bf-8073-ff8cb79e0840","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-05T18:53:01Z","summary":null,"body":["<article data-history-node-id=\"1220\" about=\"\/en\/alerts-advisories\/apple-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-152<br \/>\nDate: 11 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple security updates for macOS High Sierra 10.13.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released a support article regarding security vulnerabilities in their products and the relevant macOS High Sierra update.<\/p>\n\n<ul><li>StorageKit: A local attacker may gain access to an encrypted APFS volume<\/li>\n\t<li>macOS Security : A malicious application can extract keychain passwords<\/li>\n<\/ul><p>CVE References: CVE-2017-7149, CVE-2017-7150<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-us\/HT208165\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208165<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-7149\"><font color=\"#0066cc\">https:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-7149<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-7150\"><font color=\"#0066cc\">https:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-7150<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-3","alert_type":396,"serial_number":"AV17-152","subject":null,"moderation_state":"archived","external_url":null},{"nid":1347,"title":"Mozilla security updates","uuid":"a2f97e07-7cba-40c2-8189-fe916ade5e36","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-07-05T18:58:46Z","summary":null,"body":["<article data-history-node-id=\"1347\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-153<br \/>\nDate: 11 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Thunderbird.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 9 vulnerabilities in Thunderbird.<br \/>\nThe severity of these issues ranges from moderate to critical.<\/p>\n\n<p>Versions affected:<br \/>\nThunderbird versions prior to 52.4<\/p>\n\n<p>CVE References: CVE-2017-7793, CVE-2017-7818, CVE-2017-7819, CVE-2017-7824, CVE-2017-7805, CVE-2017-7814, CVE-2017-7825, CVE-2017-7823, CVE-2017-7810<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-23\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-23\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-1","alert_type":396,"serial_number":"AV17-153","subject":null,"moderation_state":"archived","external_url":null},{"nid":849,"title":"Adobe security bulletin","uuid":"31a8b8fa-0605-4f53-abf9-f5c8ed1a1c4b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-05T19:05:28Z","summary":null,"body":["<article data-history-node-id=\"849\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-154<br \/>\nDate: 16 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security bulletin for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security update, APSB17-32 to resolve a critical vulnerability in Adobe Flash Player.<\/p>\n\n<p>Affected Software:<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime 27.0.0.159 for Windows and Macintosh<\/li>\n\t<li>Adobe Flash Player for Google Chrome 27.0.0.159 on Windows, Macintosh, Linux and Chrome OS<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 27.0.0.130 on Windows 10 and 8.1<\/li>\n\t<li>Adobe Flash Player Desktop Runtime 27.0.0.159 for Linux<\/li>\n<\/ul><p>CVE Reference: CVE-2017-11292<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-32.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-32.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin","alert_type":396,"serial_number":"AV17-154","subject":null,"moderation_state":"archived","external_url":null},{"nid":992,"title":"Google Releases security update for Chrome","uuid":"c8053b4a-dd66-4570-aec4-cd436fa8da10","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:15Z","date_created":"2018-07-05T19:11:51Z","summary":null,"body":["<article data-history-node-id=\"992\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-26\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-155<br \/>\nDate: 18 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 62.0.3202.62 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference: CVE-2017-15386, CVE-2017-15387, CVE-2017-15388, CVE-2017-15389, CVE-2017-15390, CVE-2017-15391, CVE-2017-15392, CVE-2017-15393, CVE-2017-15394, CVE-2017-15395, CVE-2017-5124, CVE-2017-5125, CVE-2017-5126, CVE-2017-5127, CVE-2017-5128, CVE-2017-5129, CVE-2017-5130, CVE-2017-5131, CVE-2017-5132, CVE-2017-5133<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/10\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/10\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-26","alert_type":396,"serial_number":"AV17-155","subject":null,"moderation_state":"archived","external_url":null},{"nid":1058,"title":"Oracle Critical Patch updates","uuid":"9da7c292-5923-4ddd-97c5-21f8431b75a8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-05T19:18:07Z","summary":null,"body":["<article data-history-node-id=\"1058\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-156<br \/>\nDate: 18 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the quarterly updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update which addresses multiple new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Affected Product Versions:<\/p>\n\n<ul><li>Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers, versions prior to XCP2340 and prior to XCP3030<\/li>\n\t<li>Java Advanced Management Console, version 2.7<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version 9.2<\/li>\n\t<li>JD Edwards World Security, versions A9.1, A9.2, A9.3, A9.4<\/li>\n\t<li>Management Pack for Oracle GoldenGate, version 11.2.1.0.12<\/li>\n\t<li>MICROS Retail XBRi Loss Prevention, versions 10.0.1, 10.5.0, 10.6.0, 10.7.7, 10.8.0, 10.8.1<\/li>\n\t<li>MySQL Connectors, versions 6.9.9 and prior<\/li>\n\t<li>MySQL Enterprise Monitor, versions 3.2.8.2223 and prior, 3.3.4.3247 and prior, 3.4.2.4181 and prior<\/li>\n\t<li>MySQL Server, versions 5.5.57 and prior, 5.6.37 and prior, 5.7.19 and prior<\/li>\n\t<li>Oracle Access Manager, version 11.1.2.3.0<\/li>\n\t<li>Oracle Agile Engineering Data Management, versions 6.1.3, 6.2.0<\/li>\n\t<li>Oracle Agile PLM, versions 9.3.5, 9.3.6<\/li>\n\t<li>Oracle API Gateway, version 11.1.2.4.0<\/li>\n\t<li>Oracle BI Publisher, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Business Process Management Suite, versions 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Communications Billing and Revenue Management, version 7.5<\/li>\n\t<li>Oracle Communications Diameter Signaling Router (DSR), version 7.x<\/li>\n\t<li>Oracle Communications EAGLE LNP Application Processor, version 10.x<\/li>\n\t<li>Oracle Communications Messaging Server, version 8.x<\/li>\n\t<li>Oracle Communications Order and Service Management, versions 7.2.4.x.x, 7.3.0.x.x, 7.3.1.x.x, 7.3.5.x.x<\/li>\n\t<li>Oracle Communications Policy Management, versions 11.5, 12.x<\/li>\n\t<li>Oracle Communications Services Gatekeeper, versions 5.1, 6.0<\/li>\n\t<li>Oracle Communications Unified Session Manager, version SCz 7.x<\/li>\n\t<li>Oracle Communications User Data Repository, version 10.x<\/li>\n\t<li>Oracle Communications WebRTC Session Controller, versions 7.0, 7.1, 7.2<\/li>\n\t<li>Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1<\/li>\n\t<li>Oracle Directory Server Enterprise Edition, version 11.1.1.7.0<\/li>\n\t<li>Oracle E-Business Suite, versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7<\/li>\n\t<li>Oracle Endeca Information Discovery Integrator, versions 2.4, 3.0, 3.1, 3.2<\/li>\n\t<li>Oracle Engineering Data Management, versions 6.1.3.0, 6.2.2.0<\/li>\n\t<li>Oracle Enterprise Manager Ops Center, versions 12.2.2, 12.3.2<\/li>\n\t<li>Oracle FLEXCUBE Universal Banking, versions 11.3, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0<\/li>\n\t<li>Oracle Fusion Applications, versions 11.1.2 through 11.1.9<\/li>\n\t<li>Oracle Fusion Middleware, versions 11.1.1.7, 11.1.1.9, 11.1.2.2, 11.1.2.3, 12.1.3.0, 12.2.1.1, 12.2.1.2, 12.2.1.3<\/li>\n\t<li>Oracle GlassFish Server, versions 3.0.1, 3.1.2<\/li>\n\t<li>Oracle Healthcare Master Person Index, version 4.x<\/li>\n\t<li>Oracle Hospitality Cruise AffairWhere, versions 2.2.5.0, 2.2.6.0, 2.2.7.0<\/li>\n\t<li>Oracle Hospitality Cruise Fleet Management, version 9.0.2.0<\/li>\n\t<li>Oracle Hospitality Cruise Materials Management, version 7.30.564.0<\/li>\n\t<li>Oracle Hospitality Cruise Shipboard Property Management System, version 8.0.2.0<\/li>\n\t<li>Oracle Hospitality Guest Access, versions 4.2.0, 4.2.1<\/li>\n\t<li>Oracle Hospitality Hotel Mobile, version 1.1<\/li>\n\t<li>Oracle Hospitality OPERA 5 Property Services, versions 5.4.2.x through 5.5.1.x<\/li>\n\t<li>Oracle Hospitality Reporting and Analytics, versions 8.5.1, 9.0.0<\/li>\n\t<li>Oracle Hospitality Simphony, versions 2.6, 2.7, 2.8, 2.9<\/li>\n\t<li>Oracle Hospitality Suite8, versions 8.10.1, 8.10.2<\/li>\n\t<li>Oracle HTTP Server, versions 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Hyperion BI+, version 11.1.2.4<\/li>\n\t<li>Oracle Hyperion Financial Reporting, version 11.1.2<\/li>\n\t<li>Oracle Identity Manager, version 11.1.2.3.0<\/li>\n\t<li>Oracle Identity Manager Connector, version 9.1.1.5.0<\/li>\n\t<li>Oracle Integrated Lights Out Manager (ILOM), versions prior to 3.2.6<\/li>\n\t<li>Oracle iPlanet Web Server, version 7.0<\/li>\n\t<li>Oracle Java SE, versions 6u161, 7u151, 8u144, 9<\/li>\n\t<li>Oracle Java SE Embedded, version 8u144<\/li>\n\t<li>Oracle JDeveloper, versions 12.1.3.0.0, 12.2.1.2.0<\/li>\n\t<li>Oracle JRockit, version R28.3.15<\/li>\n\t<li>Oracle Managed File Transfer, versions 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Outside In Technology, version 8.5.3.0<\/li>\n\t<li>Oracle Retail Back Office, versions 13.2, 13.3, 13.4, 14.0, 14.1<\/li>\n\t<li>Oracle Retail Clearance Optimization Engine, version 13.4<\/li>\n\t<li>Oracle Retail Convenience and Fuel POS Software, version 2.1.132<\/li>\n\t<li>Oracle Retail Markdown Optimization, versions 13.4, 14.0<\/li>\n\t<li>Oracle Retail Point-of-Service, versions 6.0.x, 6.5.x, 7.0.x, 7.1.x, 15.0.x, 16.0.0<\/li>\n\t<li>Oracle Retail Store Inventory Management, versions 13.2.9, 14.0.4, 14.1.3, 15.0.1, 16.0.1<\/li>\n\t<li>Oracle Retail Xstore Point of Service, versions 6.0.11, 6.5.11, 7.0.6, 7.1.6, 15.0.1<\/li>\n\t<li>Oracle Secure Global Desktop (SGD), version 5.3<\/li>\n\t<li>Oracle SOA Suite, version 11.1.1.7.0<\/li>\n\t<li>Oracle Transportation Management, versions 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.1, 6.4.2<\/li>\n\t<li>Oracle Virtual Directory, versions 11.1.1.7.0, 11.1.1.9.0<\/li>\n\t<li>Oracle VM VirtualBox, versions prior to 5.1.30<\/li>\n\t<li>Oracle WebCenter Content, versions 11.1.1.9.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>Oracle WebCenter Sites, versions 11.1.1.8.0, 12.2.1.2.0<\/li>\n\t<li>Oracle WebLogic Server, versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0<\/li>\n\t<li>PeopleSoft Enterprise FSCM, version 9.2<\/li>\n\t<li>PeopleSoft Enterprise HCM, version 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, versions 8.54, 8.55, 8.56<\/li>\n\t<li>PeopleSoft Enterprise PRTL Interaction Hub, version 9.1.00<\/li>\n\t<li>PeopleSoft Enterprise PT PeopleTools, versions 8.54, 8.55, 8.56<\/li>\n\t<li>PeopleSoft Enterprise SCM eProcurement, versions 9.1.00, 9.2.00<\/li>\n\t<li>Primavera Unifier, versions 9.13, 9.14, 10.x, 15.x, 16.x<\/li>\n\t<li>Siebel Applications, versions 16.0, 17.0<\/li>\n\t<li>Solaris Cluster, versions 3.3, 4.3<\/li>\n\t<li>SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers, versions prior to XCP 1123<\/li>\n\t<li>SPARC M7, T7, S7 based Servers, versions prior to 9.7.6.b<\/li>\n\t<li>Sun ZFS Storage Appliance Kit (AK), version AK 2013<\/li>\n\t<li>Tekelec HLR Router, version 4.x<\/li>\n<\/ul><p>CVE References:<\/p>\n\n<p>CVE-2003-1418, CVE-2013-1903, CVE-2014-0062, CVE-2014-0107, CVE-2014-0114, CVE-2014-0224, CVE-2014-3538, CVE-2014-3707, CVE-2014-4345, CVE-2014-8714, CVE-2015-0235, CVE-2015-2808, CVE-2015-3253, CVE-2015-5254, CVE-2015-7501, CVE-2015-7940, CVE-2016-0635, CVE-2016-0714, CVE-2016-10165, CVE-2016-1181, CVE-2016-2107, CVE-2016-2183, CVE-2016-2381, CVE-2016-2834, CVE-2016-3092, CVE-2016-3506, CVE-2016-5019, CVE-2016-6304, CVE-2016-6814, CVE-2016-7052, CVE-2016-7431, CVE-2016-8735, CVE-2016-9841, CVE-2017-10014, CVE-2017-10026, CVE-2017-10033, CVE-2017-10034, CVE-2017-10037, CVE-2017-10050, CVE-2017-10051, CVE-2017-10054, CVE-2017-10055, CVE-2017-10060, CVE-2017-10065, CVE-2017-10066, CVE-2017-10077, CVE-2017-10099, CVE-2017-10152, CVE-2017-10153, CVE-2017-10154, CVE-2017-10155, CVE-2017-10158, CVE-2017-10159, CVE-2017-10161, CVE-2017-10162, CVE-2017-10163, CVE-2017-10164, CVE-2017-10165, CVE-2017-10166, CVE-2017-10167, CVE-2017-10190, CVE-2017-10194, CVE-2017-10197, CVE-2017-10203, CVE-2017-10227, CVE-2017-10259, CVE-2017-10260, CVE-2017-10261, CVE-2017-10263, CVE-2017-10264, CVE-2017-10265, CVE-2017-10268, CVE-2017-10270, CVE-2017-10271, CVE-2017-10274, CVE-2017-10275, CVE-2017-10276, CVE-2017-10277, CVE-2017-10279, CVE-2017-10280, CVE-2017-10281, CVE-2017-10283, CVE-2017-10284, CVE-2017-10285, CVE-2017-10286, CVE-2017-10287, CVE-2017-10292, CVE-2017-10293, CVE-2017-10294, CVE-2017-10295, CVE-2017-10296, CVE-2017-10299, CVE-2017-10300, CVE-2017-10302, CVE-2017-10303, CVE-2017-10304, CVE-2017-10306, CVE-2017-10308, CVE-2017-10309, CVE-2017-10310, CVE-2017-10311, CVE-2017-10312, CVE-2017-10313, CVE-2017-10314, CVE-2017-10315, CVE-2017-10316, CVE-2017-10317, CVE-2017-10318, CVE-2017-10319, CVE-2017-10320, CVE-2017-10321, CVE-2017-10322, CVE-2017-10323, CVE-2017-10324, CVE-2017-10325, CVE-2017-10326, CVE-2017-10327, CVE-2017-10328, CVE-2017-10329, CVE-2017-10330, CVE-2017-10331, CVE-2017-10332, CVE-2017-10333, CVE-2017-10334, CVE-2017-10335, CVE-2017-10336, CVE-2017-10337, CVE-2017-10338, CVE-2017-10339, CVE-2017-10340, CVE-2017-10341, CVE-2017-10342, CVE-2017-10343, CVE-2017-10344, CVE-2017-10345, CVE-2017-10346, CVE-2017-10347, CVE-2017-10348, CVE-2017-10349, CVE-2017-10350, CVE-2017-10351, CVE-2017-10352, CVE-2017-10353, CVE-2017-10354, CVE-2017-10355, CVE-2017-10356, CVE-2017-10357, CVE-2017-10358, CVE-2017-10359, CVE-2017-10360, CVE-2017-10361, CVE-2017-10362, CVE-2017-10363, CVE-2017-10364, CVE-2017-10365, CVE-2017-10366, CVE-2017-10367, CVE-2017-10368, CVE-2017-10369, CVE-2017-10370, CVE-2017-10372, CVE-2017-10373, CVE-2017-10375, CVE-2017-10378, CVE-2017-10379, CVE-2017-10380, CVE-2017-10381, CVE-2017-10382, CVE-2017-10383, CVE-2017-10384, CVE-2017-10385, CVE-2017-10386, CVE-2017-10387, CVE-2017-10388, CVE-2017-10389, CVE-2017-10391, CVE-2017-10392, CVE-2017-10393, CVE-2017-10394, CVE-2017-10395, CVE-2017-10396, CVE-2017-10397, CVE-2017-10398, CVE-2017-10399, CVE-2017-10400, CVE-2017-10401, CVE-2017-10402, CVE-2017-10403, CVE-2017-10404, CVE-2017-10405, CVE-2017-10406, CVE-2017-10407, CVE-2017-10408, CVE-2017-10409, CVE-2017-10410, CVE-2017-10411, CVE-2017-10412, CVE-201,7-10413, CVE-2017-10414, CVE-2017-10415, CVE-2017-10416, CVE-2017-10417, CVE-2017-10418, CVE-2017-10419, CVE-2017-10420, CVE-2017-10421, CVE-2017-10422, CVE-2017-10423, CVE-2017-10424, CVE-2017-10425, CVE-2017-10426, CVE-2017-10427, CVE-2017-10428, CVE-2017-3167, CVE-2017-3444, CVE-2017-3445, CVE-2017-3446, CVE-2017-3588, CVE-2017-3731, CVE-2017-3732, CVE-2017-3733, CVE-2017-5461, CVE-2017-5662, CVE-2017-5664<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2017-3236626.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2017-3236626.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-updates","alert_type":396,"serial_number":"AV17-156","subject":null,"moderation_state":"archived","external_url":null},{"nid":794,"title":"Cisco security updates","uuid":"55c6018d-dd67-4930-8876-75936b0fa432","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-05T19:25:21Z","summary":null,"body":["<article data-history-node-id=\"794\" about=\"\/en\/alerts-advisories\/cisco-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-157<br \/>\nDate: 18 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<ul><li>Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II,<\/li>\n\t<li>Cisco IOS XE Software Web Framework Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco IOS XE Software Verbose Debug Logging Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Expressway Series and Cisco TelePresence Video Communication Server REST API Denial of\u00a0\u00a0\u00a0\u00a0 Service Vulnerability<\/li>\n\t<li>Cisco Jabber for Windows Client Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Jabber Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Network Analysis Module Parameter Directory Traversal Arbitrary File Deletion Vulnerability,<\/li>\n\t<li>Cisco NX-OS Software Python Parser Escape Vulnerability<\/li>\n\t<li>Cisco SPA300 and SPA500 Series IP Phones Cross-Site Request Forgery Vulnerability,<\/li>\n\t<li>Cisco Unified Contact Center Express Cross-Site Scripting Vulnerability,<\/li>\n\t<li>Cisco WebEx Meeting Center Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Denial of Service Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco FXOS and NX-OS System Software Authentication, Authorization, and Accounting Denial of\u00a0\u00a0 Service Vulnerability<\/li>\n\t<li>Cisco Small Business SPA51x Series IP Phones SIP Denial of Service Vulnerability<\/li>\n\t<li>Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones SIP Denial of Service Vulnerability,<\/li>\n\t<li>Cisco Cloud Services Platform 2100 Unauthorized Access Vulnerability.<\/li>\n<\/ul><p>CVE References: \u00a0CVE-2017-13077, CVE-2017-13078, \u00a0CVE-2017-13079, CVE-2017-12272, CVE-2017-12289, CVE-2017-12287, CVE-2017-12284, CVE-2017-12286, CVE-2017-12285, CVE-2017-12301, CVE-2017-12271, \u00a0CVE-2017-12288, CVE-2017-12298, CVE-2017-12293, CVE-2017-12296, CVE-2017-3883, CVE-2017-12259, CVE-2017-12260, CVE-2017-12251\u00a0<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171016-wpa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171016-wpa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-cisco-ios-xe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-cisco-ios-xe<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-cisco-ios-xe1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-cisco-ios-xe1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-expressway-tp-vcs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-expressway-tp-vcs<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-jab\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-jab<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-jab1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-jab1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-nam\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-nam<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-ppe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-ppe<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-spa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-spa<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-ucce\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-ucce<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-wmc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-wmc1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-wms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-wms<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-wms1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-wms1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-aaavty\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-aaavty<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-sip\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-sip<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-sip1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-sip1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-ccs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-ccs<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-6","alert_type":396,"serial_number":"AV17-157","subject":null,"moderation_state":"archived","external_url":null},{"nid":1280,"title":"Google Releases security update for Chrome","uuid":"09485047-8da0-4d52-b03f-3c7826e0777d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-05T19:32:01Z","summary":null,"body":["<article data-history-node-id=\"1280\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-27\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-158<br \/>\nDate: 27 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 62.0.3202.75 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference: CVE-2017-15396<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/10\/stable-channel-update-for-desktop_26.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/10\/stable-channel-update-for-desktop_26.html<\/font><\/a>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-27","alert_type":396,"serial_number":"AV17-158","subject":null,"moderation_state":"archived","external_url":null},{"nid":3158,"title":"Oracle security updates","uuid":"ac61da80-536d-4cd5-bd4f-b25ea6683c5c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-05T19:39:51Z","summary":null,"body":["<article data-history-node-id=\"3158\" about=\"\/en\/alerts-advisories\/oracle-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-159<br \/>\nDate: 30 October 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following Security Advisory affecting Oracle Identity Manager.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued an advisory which highlights a critical vulnerability in Oracle Identity Manager which could result in a complete compromise of their product via a remote unauthenticated network attack.<\/p>\n\n<p>Products affected:<\/p>\n\n<ul><li>Identity Manager Version 11.1.1.7 (P-1980V-11.1.1.7)<\/li>\n\t<li>Identity Manager Version 11.1.1.9 (P-1980V-11.1.1.9)<\/li>\n\t<li>Identity Manager Version 11.1.2.1.0 (P-1980V-11.1.2.1.0)<\/li>\n\t<li>Identity Manager Version 11.1.2.2.0 (P-1980V-11.1.2.2.0)<\/li>\n\t<li>Identity Manager Version 11.1.2.3.0 (P-1980V-11.1.2.3.0)<\/li>\n\t<li>Identity Manager Version 12.2.1.3.0 (P-1980V-12.2.1.3.0)<\/li>\n<\/ul><p>CVE Reference(s):<\/p>\n\n<p>CVE-2017-10151<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2017-10151-4016513.html\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2017-10151-4016513.html<\/a><br \/><a href=\"http:\/\/www.oracle.com\/ocom\/groups\/public\/@otn\/documents\/webcontent\/4016515.xml\">http:\/\/www.oracle.com\/ocom\/groups\/public\/@otn\/documents\/webcontent\/4016515.xml<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-updates","alert_type":396,"serial_number":"AV17-159","subject":null,"moderation_state":"archived","external_url":null},{"nid":945,"title":"WordPress security update","uuid":"64b61cf4-77c2-445e-a33b-91e288c83ebb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-05T19:48:01Z","summary":null,"body":["<article data-history-node-id=\"945\" about=\"\/en\/alerts-advisories\/wordpress-security-update-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-160<br \/>\nDate: 1 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.8.3 that contains security fixes to address an SQL injection vulnerability.<\/p>\n\n<p>Versions affected: WordPress 4.8.2 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2017\/10\/wordpress-4-8-3-security-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2017\/10\/wordpress-4-8-3-security-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-3","alert_type":396,"serial_number":"AV17-160","subject":null,"moderation_state":"archived","external_url":null},{"nid":1006,"title":"Apple security updates","uuid":"79c404de-6bc1-4e94-be01-fc85caa83c7d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:01Z","date_created":"2018-07-06T13:07:13Z","summary":null,"body":["<article data-history-node-id=\"1006\" about=\"\/en\/alerts-advisories\/apple-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-161<br \/>\nDate: 1 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iCloud for Windows, iOS, iTunes for Windows, macOS High Sierra, macOS Sierra, macOS El Capitan, Safari, tvOS and watchOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support articles addressing security vulnerabilities in various products:<\/p>\n\n<p>-iCloud for Windows 7.1<br \/>\n-iOS 11.1<br \/>\n-iTunes 12.7.1 for Windows<br \/>\n-macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan<br \/>\n-Safari 11.1<br \/>\n-tvOS 11.1<br \/>\n-watchOS 4.1<\/p>\n\n<p>CVE Reference: CVE-2016-2161, CVE-2016-4736, CVE-2016-5387, CVE-2016-736, CVE-2016-8740, CVE-2016-8743, CVE-2017-1000100, CVE-2017-1000101, CVE-2017-11103, CVE-2017-11108, CVE-2017-11541, CVE-2017-11542, CVE-2017-11543, CVE-2017-12893, CVE-2017-12894, CVE-2017-12895, CVE-2017-12896, CVE-2017-12897, CVE-2017-12898, CVE-2017-12899, CVE-2017-12900, CVE-2017-12901, CVE-2017-12902, CVE-2017-12985, CVE-2017-12986, CVE-2017-12987, CVE-2017-12988, CVE-2017-12989, CVE-2017-12990, CVE-2017-12991, CVE-2017-12992, CVE-2017-12993, CVE-2017-12994, CVE-2017-12995, CVE-2017-12996, CVE-2017-12997, CVE-2017-12998, CVE-2017-12999, CVE-2017-13000, CVE-2017-13001, CVE-2017-13002, CVE-2017-13003, CVE-2017-13004, CVE-2017-13005, CVE-2017-13006, CVE-2017-13007, CVE-2017-13008, CVE-2017-13009, CVE-2017-13010, CVE-2017-13011, CVE-2017-13012, CVE-2017-13013, CVE-2017-13014, CVE-2017-13015, CVE-2017-13016, CVE-2017-13017, CVE-2017-13018, CVE-2017-13019, CVE-2017-13020, CVE-2017-13021, CVE-2017-13022, CVE-2017-13023, CVE-2017-13024, CVE-2017-13025, CVE-2017-13026, CVE-2017-13027, CVE-2017-13028, CVE-2017-13029, CVE-2017-13030, CVE-2017-13031, CVE-2017-13032, CVE-2017-13033, CVE-2017-13034, CVE-2017-13035, CVE-2017-13036, CVE-2017-13037, CVE-2017-13038, CVE-2017-13039, CVE-2017-13040, CVE-2017-13041, CVE-2017-13042, CVE-2017-13043, CVE-2017-13044, CVE-2017-13045, CVE-2017-13046, CVE-2017-13047, CVE-2017-13048, CVE-2017-13049, CVE-2017-13050, CVE-2017-13051, CVE-2017-13052, CVE-2017-13053, CVE-2017-13054, CVE-2017-13055, CVE-2017-13077, CVE-2017-13078, CVE-2017-13080, CVE-2017-13687, CVE-2017-13688, CVE-2017-13689, CVE-2017-13690, CVE-2017-13725, CVE-2017-13782, CVE-2017-13783, CVE-2017-13784, CVE-2017-13785, CVE-2017-13786, CVE-2017-13788, CVE-2017-13789, CVE-2017-13790, CVE-2017-13791, CVE-2017-13792, CVE-2017-13793, CVE-2017-13794, CVE-2017-13795, CVE-2017-13796, CVE-2017-13798, CVE-2017-13799, CVE-2017-13800, CVE-2017-13801, CVE-2017-13802, CVE-2017-13803, CVE-2017-13804, CVE-2017-13805, CVE-2017-13807, CVE-2017-13808, CVE-2017-13809, CVE-2017-13810, CVE-2017-13811, CVE-2017-13812, CVE-2017-13813, CVE-2017-13814, CVE-2017-13815, CVE-2017-13816, CVE-2017-13817, CVE-2017-13818, CVE-2017-13819, CVE-2017-13820, CVE-2017-13821, CVE-2017-13822, CVE-2017-13823, CVE-2017-13824, CVE-2017-13825, CVE-2017-13826, CVE-2017-13828, CVE-2017-13830, CVE-2017-13831, CVE-2017-13832, CVE-2017-13834, CVE-2017-13836, CVE-2017-13838, CVE-2017-13840, CVE-2017-13841, CVE-2017-13842, CVE-2017-13844, CVE-2017-13846, CVE-2017-13849, CVE-2017-3167, CVE-2017-3169, CVE-2017-7113, CVE-2017-7132, CVE-2017-7659, CVE-2017-7668, CVE-2017-7679, CVE-2017-9788, CVE-2017-9789<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT208225\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208225<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208224\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208224<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208223\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208223<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208219\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208219<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208221\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208221<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208222\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208222<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208220\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208220<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-4","alert_type":396,"serial_number":"AV17-161","subject":null,"moderation_state":"archived","external_url":null},{"nid":757,"title":"Cisco security updates","uuid":"5f508b95-6fb7-4fad-b79c-8c2b8f188997","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-06T13:17:13Z","summary":null,"body":["<article data-history-node-id=\"757\" about=\"\/en\/alerts-advisories\/cisco-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-162<br \/>\nDate: 1 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<ul><li>Cisco FXOS and NX-OS System Software Authentication, Authorization, and Accounting Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller 802.11v Basic Service Set Transition Management Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller Simple Network Management Protocol Memory Leak Denial of Service Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Firepower 4100 Series NGFW and Firepower 9300 Security Appliance Smart Licensing Command Injection Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Authenticated SQL Injection Vulnerability<\/li>\n\t<li>Cisco Application Policy Infrastructure Controller Enterprise Module Unauthorized Access Vulnerability<\/li>\n\t<li>Cisco Aironet 1560, 2800, and 3800 Series Access Point Platforms Extensible Authentication Protocol Denial of Service Vulnerability<\/li>\n\t<li>Cisco Aironet 1560, 2800, and 3800 Series Access Point Platforms 802.11 Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller Access Network Query Protocol Denial of Service Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller CAPWAP Discovery Request Denial of Service Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Information Disclosure Vulnerability<\/li>\n\t<li>Cisco WebEx Meeting Center Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco IOS Software for Cisco Aironet Access Points Information Disclosure Vulnerability<\/li>\n\t<li>Cisco UCS Manager, Cisco Firepower 4100 Series NGFW, and Cisco Firepower 9300 Security Appliance \u00a0\u00a0Command Injection Vulnerability<\/li>\n\t<li>Cisco Aironet 3800 Series Access Points Protected Management Frames User Denial of Service Vulnerability<\/li>\n\t<li>Cisco Aironet 1800, 2800, and 3800 Series Access Points MAC Authentication Bypass Vulnerability<\/li>\n\t<li>Cisco Expressway Series, Cisco TelePresence Video Communication Server, and Cisco TelePresence Conductor REST API Denial of Service Vulnerability<\/li>\n\t<li>Cisco Smart Install Protocol Misuse<\/li>\n\t<li>Cisco Integrated Management Controller Remote Code Execution Vulnerability<\/li>\n\t<li>Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II<\/li>\n\t<li>Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017<\/li>\n\t<li>Apache Struts 2 Remote Code Execution Vulnerability Affecting Multiple Cisco Products: September 2017<\/li>\n\t<li>Cisco NX-OS Software TCP Netstack Denial of Service Vulnerability<\/li>\n\t<li>Cisco Spark Hybrid Calendar Service Information Disclosure Vulnerability<\/li>\n\t<li>Cisco AMP for Endpoints Static Key Vulnerability<\/li>\n\t<li>Cisco Nexus Series Switches CLI Command Injection Vulnerability<\/li>\n<\/ul><p>CVE References:\u00a0 \u00a0CVE-2017-3883, CVE-2017-12275,\u00a0\u00a0 CVE-2017-12278, CVE-2017-12261,\u00a0 CVE-2017-12277, CVE-2017-12276, CVE-2017-12262, CVE-2017-12274, CVE-2017-12273, CVE-2017-12282, CVE-2017-12280, CVE-2017-12295, CVE-2017-12294, CVE-2017-12279, CVE-2017-12243,\u00a0 CVE-2017-12283, CVE-2017-12281,\u00a0 CVE-2017-12287, CVE-2017-6616, \u00a0CVE-2017-13077, CVE-2017-13078,\u00a0 CVE-2017-9793, CVE-2017-9804, CVE-2017-12611, CVE-2015-0718,\u00a0 CVE-2017-12310, \u00a0CVE-2017-12317, CVE-2017-6649.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-aaavty\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-aaavty<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-ise<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-fpwr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-fpwr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-cpcp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-cpcp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-apicem\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-apicem<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-wlc3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-webex2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-webex2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-webex1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-webex1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-iosap\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-iosap<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-arce\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-arce<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-aironet3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-expressway-tp-vcs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171018-expressway-tp-vcs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityResponse\/cisco-sr-20170214-smi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityResponse\/cisco-sr-20170214-smi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170419-cimc3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170419-cimc3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171016-wpa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171016-wpa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170907-struts2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170907-struts2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170909-struts2-rce\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170909-struts2-rce<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160302-netstack\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160302-netstack<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171023-spark\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171023-spark<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171020-ampfe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171020-ampfe<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-nss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170517-nss<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-7","alert_type":null,"serial_number":"AV17-162","subject":null,"moderation_state":"archived","external_url":null},{"nid":826,"title":"OpenSSL Advisory - security update","uuid":"0d3ad242-65e8-4a23-9f55-77cca40bdecf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-06T13:25:26Z","summary":null,"body":["<article data-history-node-id=\"826\" about=\"\/en\/alerts-advisories\/openssl-advisory-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-163<br \/>\nDate: 6 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent \u00a0OpenSSL security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>OpenSSL has released security updates that affect vulnerabilities (Low to Moderate) in the following products:<\/p>\n\n<p>Affected version:\u00a0 OpenSSL 1.1.0 and OpenSSL 1.0.2<\/p>\n\n<p>CVE Reference: CVE-2017-3735, CVE-2017-3736<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<br \/>\nOpenSSL 1.1.0 users should upgrade to 1.1.0g<br \/>\nOpenSSL 1.0.2 users should upgrade to 1.0.2m<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20171102.txt\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/news\/secadv\/20171102.txt<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-advisory-security-update-0","alert_type":396,"serial_number":"AV17-163","subject":null,"moderation_state":"archived","external_url":null},{"nid":968,"title":"Google Releases security update for Chrome","uuid":"c8655857-9f4d-48b4-825e-d3faed8128bf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-06T13:36:18Z","summary":null,"body":["<article data-history-node-id=\"968\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-28\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-164<br \/>\nDate: 06 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 62.0.3202.89 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE Reference: CVE-2017-15398, CVE-2017-15399<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/11\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/11\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-28","alert_type":396,"serial_number":"AV17-164","subject":null,"moderation_state":"archived","external_url":null},{"nid":871,"title":"Joomla! security update","uuid":"836ae8aa-0148-4620-80a0-8bbcbf683c1a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-06T13:43:14Z","summary":null,"body":["<article data-history-node-id=\"871\" about=\"\/en\/alerts-advisories\/joomla-security-update-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-165<br \/>\nDate: 07 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.8.2 of its web content management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected: Joomla! 3.8.1 and earlier.<\/p>\n\n<p>CVE References: CVE-2017-14596, CVE-2017-16634, CVE-2017-16633<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5716-joomla-3-8-2-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5716-joomla-3-8-2-release.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update-3","alert_type":396,"serial_number":"AV17-165","subject":null,"moderation_state":"archived","external_url":null},{"nid":1332,"title":"VMware security updates","uuid":"3c7426c2-6ed3-4b03-bfda-0adacc177ee6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-06T13:50:34Z","summary":null,"body":["<article data-history-node-id=\"1332\" about=\"\/en\/alerts-advisories\/vmware-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-166<br \/>\nDate: 14 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<br \/>\n- VMware vCenter Server<br \/>\n- VMware AirWatch Console (AWC)<br \/>\n- VMware AirWatch Launcher for Android (AWL)<\/p>\n\n<p>CVE References: CVE-2017-4927, CVE-2017-4928, CVE-2017-4930, CVE-2017-4931, CVE-2017-4932<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0017.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0017.html<\/font><\/a><br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0016.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0016.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-6","alert_type":396,"serial_number":"AV17-166","subject":null,"moderation_state":"archived","external_url":null},{"nid":1029,"title":"Apple security updates","uuid":"b27f821c-19fa-43ea-8fc5-f8f011dd4558","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-06T13:56:46Z","summary":null,"body":["<article data-history-node-id=\"1029\" about=\"\/en\/alerts-advisories\/apple-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-167<br \/>\nDate: 14 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Apple system security updates for iOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released the following support article:<\/p>\n\n<p>\u2022\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 HT208255 - iOS 11.1.1 \u00a0\u00a0\u00a0<\/p>\n\n<p>This update addresses multiple vulnerabilities on the system listed above.<\/p>\n\n<p>CVE Reference: CVE-2017-13849, CVE-2017-13799, CVE-2017-13852, CVE-2017-13844, CVE-2017-13805, CVE-2017-13804, CVE-2017-7113, CVE-2017-13783, CVE-2017-13784, CVE-2017-13785, CVE-2017-13788, CVE-2017-13791, CVE-2017-13792, CVE-2017-13793, CVE-2017-13794, CVE-2017-13795, CVE-2017-13796 , CVE-2017-13797 , CVE-2017-13798, CVE-2017-13802, CVE-2017-13803, CVE-2017-13077 , CVE-2017-13078, CVE-2017-13080<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT208222\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208222<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-5","alert_type":396,"serial_number":"AV17-167","subject":null,"moderation_state":"archived","external_url":null},{"nid":1222,"title":"Adobe security updates","uuid":"eab51b0d-d08b-4127-8fc2-348cd5bc0386","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-06T14:03:18Z","summary":null,"body":["<article data-history-node-id=\"1222\" about=\"\/en\/alerts-advisories\/adobe-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-168<br \/>\nDate: 14 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Adobe Security updates for various products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released the following security bulletins:<\/p>\n\n<p>APSB17-33 - Adobe Flash Player<br \/>\nAPSB17-34 - Photoshop CC<br \/>\nAPSB17-35 - Adobe Connect<br \/>\nAPSB17-36 - Adobe Acrobat and Reader<br \/>\nAPSB17-37 - Adobe DNG Converter<br \/>\nAPSB17-38 - InDesign<br \/>\nAPSB17-39 - Adobe Digital Editions<br \/>\nAPSB17-40 - Adobe Shockwave Player<br \/>\nAPSB17-41 - Adobe Experience Manager<\/p>\n\n<p>CVE References:\u00a0<\/p>\n\n<p>CVE-2017-3112, CVE-2017-3114, CVE-2017-11213, CVE-2017-11215, CVE-2017-11225, CVE-2017-11303, CVE-2017-11304, CVE-2017-11291, CVE-2017-11287, CVE-2017-11288, CVE-2017-11289, CVE-2017-11290, CVE-2017-16377, CVE-2017-16378, CVE-2017-16360, CVE-2017-16388, CVE-2017-16389, CVE-2017-16390, CVE-2017-16393, CVE-2017-16398, CVE-2017-16381, CVE-2017-16385, CVE-2017-16392, CVE-2017-16395, CVE-2017-16396, CVE-2017-16363, CVE-2017-16365, CVE-2017-16374, CVE-2017-16384, CVE-2017-16386, CVE-2017-16387, CVE-2017-16368, CVE-2017-16383, CVE-2017-16391, CVE-2017-16410, CVE-2017-16362, CVE-2017-16370, CVE-2017-16376, CVE-2017-16382, CVE-2017-16394, CVE-2017-16397, CVE-2017-16399, CVE-2017-16400, CVE-2017-16401, CVE-2017-16402, CVE-2017-16403, CVE-2017-16404, CVE-2017-16405, CVE-2017-16408, CVE-2017-16409, CVE-2017-16412, CVE-2017-16414, CVE-2017-16417, CVE-2017-16418, CVE-2017-16420, CVE-2017-11293, CVE-2017-16407, CVE-2017-16413, CVE-2017-16415, CVE-2017-16416, CVE-2017-16361, CVE-2017-16366, CVE-2017-16369, CVE-2017-16380, CVE-2017-16419, CVE-2017-16367, CVE-2017-16379, CVE-2017-16406, CVE-2017-16364, CVE-2017-16371, CVE-2017-16372, CVE-2017-16373, CVE-2017-16375, CVE-2017-16411, CVE-2017-11295, CVE-2017-11302, CVE-2017-11273, CVE-2017-11297, CVE-2017-11298, CVE-2017-11299, CVE-2017-11300, CVE-2017-11301, CVE-2017-11294, CVE-2017-3109<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-33.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-33.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb17-34.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb17-34.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb17-35.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb17-35.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-36.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb17-36.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/dng-converter\/apsb17-37.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/dng-converter\/apsb17-37.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb17-38.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb17-38.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-39.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb17-39.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/shockwave\/apsb17-40.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/shockwave\/apsb17-40.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb17-41.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb17-41.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-updates-6","alert_type":396,"serial_number":"AV17-168","subject":null,"moderation_state":"archived","external_url":null},{"nid":1245,"title":"Microsoft Critical security bulletins Summary \u2013 November 2017","uuid":"57f9d6d1-f5be-4b4a-8f12-0d17651be2aa","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:49Z","date_created":"2018-07-06T14:09:32Z","summary":null,"body":["<article data-history-node-id=\"1245\" about=\"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-november-2017\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-169<br \/>\nDate: 14 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the monthly Microsoft Security Bulletin Summary for November 2017.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>CVE Reference: CVE-2017-11827, CVE-2017-11848, CVE-2017-11882, CVE-2017-11876, CVE-2017-11879<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-001\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-001<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-002\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-002<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-003\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-003<\/font><\/a><br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-004\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/MS17-004<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-critical-security-bulletins-summary-november-2017","alert_type":396,"serial_number":"AV17-169","subject":null,"moderation_state":"archived","external_url":null},{"nid":851,"title":"Mozilla security updates","uuid":"324c02e1-4ad7-4400-b6b8-682458cbc68f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-06T14:16:33Z","summary":null,"body":["<article data-history-node-id=\"851\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-170<br \/>\nDate: 14 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address 15 vulnerabilities in Firefox. The severity of these issues ranges from low to critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 57<\/p>\n\n<p>CVE References: CVE-2017-7828, CVE-2017-7830, CVE-2017-7831, CVE-2017-7832, CVE-2017-7833, CVE-2017-7834, CVE-2017-7835, CVE-2017-7836, CVE-2017-7837, CVE-2017-7838, CVE-2017-7839, CVE-2017-7840, CVE-2017-7842, CVE-2017-7827, CVE-2017-7826<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-24\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-24\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-2","alert_type":396,"serial_number":"AV17-170","subject":null,"moderation_state":"archived","external_url":null},{"nid":994,"title":"Oracle security updates","uuid":"1351a662-05e9-4b98-b2af-c95d65f9a97b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:40Z","date_created":"2018-07-06T14:22:25Z","summary":null,"body":["<article data-history-node-id=\"994\" about=\"\/en\/alerts-advisories\/oracle-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-171<br \/>\nDate: 15 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the following Security Advisory affecting Oracle Tuxedo.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued an advisory which highlights critical vulnerabilities in Oracle Tuxedo. Some of these vulnerabilities can be exploited on a network without the need for authentication. Oracle PeopleSoft products include and use Oracle Tuxedo in their distributions, therefore, PeopleSoft customers should apply the Tuxedo patches referenced below.<\/p>\n\n<p>Products affected: Oracle Tuxedo versions 11.1.1, 12.1.1, 12.1.3, 12.2.2<\/p>\n\n<p>CVE Reference(s): CVE-2017-10267, CVE-2017-10269, CVE-2017-10272, CVE-2017-10266, CVE-2017-10278<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p><strong>Reference(s):<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2017-10269-4021872.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2017-10269-4021872.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-updates-0","alert_type":396,"serial_number":"AV17-171","subject":null,"moderation_state":"archived","external_url":null},{"nid":1059,"title":"Cisco security updates","uuid":"f50fe919-2873-4031-834d-ca417410aa49","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-06T14:29:30Z","summary":null,"body":["<article data-history-node-id=\"1059\" about=\"\/en\/alerts-advisories\/cisco-security-updates-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-172<br \/>\nDate: 15 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<ul><li>Multiple Vulnerabilities in Wi-Fi Protected Access and Wi-Fi Protected Access II<\/li>\n\t<li>Cisco Web Security Appliance Advanced Malware Protection File Bypass Vulnerability<\/li>\n\t<li>Cisco Voice Operating System-Based Products Unauthorized Access Vulnerability<\/li>\n\t<li>Cisco Umbrella Insights Virtual Appliance Static Credentials Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager SQL Injection Vulnerability<\/li>\n\t<li>Cisco Spark Board Upgrade Signature Verification Bypass Vulnerability<\/li>\n\t<li>Cisco RF Gateway 1 TCP Connection Denial of Service Vulnerability<\/li>\n\t<li>Cisco Registered Envelope Service Cross-Site Scripting Vulnerabilities<\/li>\n\t<li>Cisco Identity Services Engine Guest Portal Login Limit Bypass Vulnerability<\/li>\n\t<li>Cisco IP Phone 8800 Series Command Injection Vulnerability in Debug Shell<\/li>\n\t<li>Cisco IOS and IOS XE Software IOS daemon Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Immunet Antimalware Installer DLL Preloading Vulnerability<\/li>\n\t<li>Cisco HyperFlex System Authenticated Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Firepower System Software Server Message Block Version 2 File Policy Bypass Vulnerability<\/li>\n\t<li>Cisco ASA Next-Generation Firewall Services Local Management Filtering Bypass Vulnerability<\/li>\n\t<li>Cisco FindIT Discovery Utility Insecure Library Loading Vulnerability<\/li>\n\t<li>Cisco Email Security Appliance HTTP Response Splitting Vulnerability<\/li>\n\t<li>Cisco Network Academy Packet Tracer DLL Preload Vulnerability<\/li>\n\t<li>Cisco Meeting Server H.264 Decoding Denial of Service Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2017-13077,CVE-2017-13078,CVE-2017-13079,CVE-2017-13080,CVE-2017-13081,CVE-2017-13082,CVE-2017-13084,CVE-2017-13086,CVE-2017-13087,CVE-2017-13088,CVE-2017-12303,CVE-2017-12337,CVE-2017-12350,CVE-2017-12302,CVE-2017-12306,CVE-2017-12318,CVE-2017-12290,CVE-2017-12290,CVE-2017-12291,CVE-2017-12292,CVE-2017-12320,CVE-2017-12321,CVE-2017-12322,CVE-2017-12323,CVE-2017-12316,CVE-2017-12305,CVE-2017-12304,CVE-2017-12312,CVE-2017-12315,CVE-2017-12300,CVE-2017-12299,CVE-2017-12314,CVE-2017-12309,CVE-2017-12313,CVE-2017-12311<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171016-wpa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171016-wpa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-wsa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-wsa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-vos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-vo<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-uva\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-uva<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-spark\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-spark<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-rf-gateway-1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-rf-gateway-1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-res\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-res<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ise<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ipp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ipp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ios\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-ios<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-iami\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-iami<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-hyperflex\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-hyperflex<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-firepower2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-firepower2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-firepower1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-firepower1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-findit\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-findit<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-esa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-es<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-cpt\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-cp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-cms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171115-cms<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-8","alert_type":396,"serial_number":"AV17-172","subject":null,"moderation_state":"archived","external_url":null},{"nid":795,"title":"Intel\u00ae security update","uuid":"458115fb-630d-48b2-8f5e-2f19e5db1401","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-06T14:36:56Z","summary":null,"body":["<article data-history-node-id=\"795\" about=\"\/en\/alerts-advisories\/intelr-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-173<br \/>\nDate: 21 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published security update by Intel\u00ae.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Intel\u00ae has released a security update to address multiple vulnerabilities in Intel\u00ae Management Engine (ME), Intel\u00ae Server Platform Services (SPS), and Intel\u00ae Trusted Execution Engine (TXE) products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>6th, 7th &amp; 8th Generation Intel\u00ae Core\u2122 Processor Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E3-1200 v5 &amp; v6 Product Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor Scalable Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor W Family<\/li>\n\t<li>Intel\u00ae Atom\u00ae C3000 Processor Family<\/li>\n\t<li>Apollo Lake Intel\u00ae Atom Processor E3900 series<\/li>\n\t<li>Apollo Lake Intel\u00ae Pentium\u2122<\/li>\n\t<li>Celeron\u2122 N and J series Processors<\/li>\n<\/ul><p>CVE References: CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5708, CVE-2017-5709, CVE-2017-5710, CVE-2017-5711, CVE-2017-5712<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Intel Q3\u201917 ME 11.x, SPS 4.0, and TXE 3.0 Security Review Cumulative Update<br \/><a href=\"https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00086&amp;languageid=en-fr\"><font color=\"#0066cc\">https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00086&amp;languageid=en-fr<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intelr-security-update","alert_type":396,"serial_number":"AV17-173","subject":null,"moderation_state":"archived","external_url":null},{"nid":1282,"title":"VMware security updates","uuid":"c26d7308-f21d-4a1c-9e86-18110046837b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-06T14:43:23Z","summary":null,"body":["<article data-history-node-id=\"1282\" about=\"\/en\/alerts-advisories\/vmware-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-174<br \/>\nDate: 21 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing security issues for multiple VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware Workstation<\/li>\n\t<li>Fusion<\/li>\n\t<li>Horizon View<\/li>\n\t<li>NSX for vSphere<\/li>\n<\/ul><p>CVE References: CVE-2017-4934, CVE-2017-4935, CVE-2017-4936, CVE-2017-4937, CVE-2017-4938, CVE-2017-4939, CVE-2017-4929<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/us\/security\/advisories\/VMSA-2017-0018.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/us\/security\/advisories\/VMSA-2017-0018.html<\/font><\/a><br \/><a href=\"https:\/\/www.vmware.com\/us\/security\/advisories\/VMSA-2017-0019.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/us\/security\/advisories\/VMSA-2017-0019.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-updates-7","alert_type":396,"serial_number":"AV17-174","subject":null,"moderation_state":"archived","external_url":null},{"nid":956,"title":"Samba security updates","uuid":"fd135f2b-2129-4980-b405-2d38cc45c3b5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-06T14:49:02Z","summary":null,"body":["<article data-history-node-id=\"956\" about=\"\/en\/alerts-advisories\/samba-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-175<br \/>\nDate: 21 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for Samba.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Samba has released security patches to address vulnerabilities which could allow a malicious actor to compromise a system\/or exploit memory leaks.<\/p>\n\n<p>Affected Versions:<br \/>\nCVE-2017-14746: All versions of Samba from 4.0.0 and up.<br \/>\nCVE-2017-15275: All versions of Samba from 3.6.0 and up.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2017-14746.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2017-14746.html<\/font><\/a><br \/><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2017-15275.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2017-15275.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-updates","alert_type":396,"serial_number":"AV17-175","subject":null,"moderation_state":"archived","external_url":null},{"nid":947,"title":"HP security updates","uuid":"fa55dcac-32c7-4fd6-9c9b-afde3f303b05","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-06T14:55:07Z","summary":null,"body":["<article data-history-node-id=\"947\" about=\"\/en\/alerts-advisories\/hp-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-176<br \/>\nDate: 27 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for HP Enterprise printers.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HP has released security patches to address a vulnerability of Insufficient Solution DLL Signature Validation which could allow potential execution of arbitrary code in multiple HP enterprise printers.<\/p>\n\n<p>Affected Versions:<br \/><br \/>\nHP Color LaserJet Enterprise; M652, M653, M577, M552, M553<br \/>\nHP Color LaserJet; M680<br \/>\nHP Color LaserJet Managed; E65050, E65060<br \/>\nHP LaserJet Enterprise 500 color; MFP; M575<br \/>\nHP LaserJet Enterprise 500; MFP, M525<br \/>\nHP LaserJet Enterprise 700 color; MFP, M775<br \/>\nHP LaserJet Enterprise 800 color; MFP, M880, M855<br \/>\nHP LaserJet Enterprise color flow MFP; M575<br \/>\nHP LaserJet Enterprise flow; M830z, MFP, M525, M630, M631, M632, M632, M633<br \/>\nHP LaserJet Enterprise; MFP M630, M631, M632, M633, M725, M806<br \/>\nHP LaserJet Managed; E60055, E60065, E60075<br \/>\nHP LaserJet Managed Flow MFP; E62555, E62565, E62575<br \/>\nHP LaserJet Managed MFP; E62555, E62565<br \/>\nHP OfficeJet Enterprise Color Flow MFP; X585<br \/>\nHP OfficeJet Enterprise Color MFP; X585<br \/>\nHP PageWide Enterprise Color MFP; 586, 765, 780, 785, X556<br \/>\nHP PageWide Managed Color; E55650, E75160<br \/>\nHP PageWide Managed Color Flow; MFP, 586, E77650, E77660, E77650<br \/>\nHP ScanJet Enterprise Flow N9120 Doc Flatbed Scanner<br \/>\nHP Digital Sender Flow 8500 fn2 Doc Capture Workstation<\/p>\n\n<p>CVE Reference: CVE-2017-2750<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.hp.com\/nz-en\/document\/c05839270\"><font color=\"#0066cc\">https:\/\/support.hp.com\/nz-en\/document\/c05839270<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hp-security-updates","alert_type":396,"serial_number":"AV17-176","subject":null,"moderation_state":"archived","external_url":null},{"nid":1008,"title":"Microsoft Office security update","uuid":"c97fe66f-9ba6-472c-809a-70e6946485e9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:01Z","date_created":"2018-07-06T15:01:34Z","summary":null,"body":["<article data-history-node-id=\"1008\" about=\"\/en\/alerts-advisories\/microsoft-office-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-177<br \/>\nDate: 29 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent security update for Microsoft Office.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a critical vulnerability in Microsoft Office.\u00a0 Exploitation of this vulnerability may allow for remote code execution.<\/p>\n\n<p>Affected Versions:\u00a0<\/p>\n\n<ul><li>Microsoft Office 2010 Service Pack 2 (32-bit editions)\u00a0<\/li>\n\t<li>Microsoft Office 2010 Service Pack 2 (64-bit editions)\u00a0<\/li>\n\t<li>Microsoft Office 2013 Service Pack 1 (32-bit editions)\u00a0<\/li>\n\t<li>Microsoft Office 2013 Service Pack 1 (64-bit editions)\u00a0\u00a0<\/li>\n\t<li>Microsoft Office 2016 (32-bit edition)<\/li>\n\t<li>Microsoft Office 2016 (64-bit edition)\u00a0<\/li>\n\t<li>Microsoft Office 2007 Service Pack 3<\/li>\n<\/ul><p>CVE Reference: CVE-2017-11882<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-11882\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-11882<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-office-security-update","alert_type":396,"serial_number":"AV17-177","subject":null,"moderation_state":"archived","external_url":null},{"nid":759,"title":"Apple security update","uuid":"5b00c594-8635-4fb0-995a-4c5b61bea3b9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-06T15:19:30Z","summary":null,"body":["<article data-history-node-id=\"759\" about=\"\/en\/alerts-advisories\/apple-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-178<br \/>\nDate: 29 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple system security update for macOS High Sierra.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A flaw in macOS High Sierra allows a user to log in to the root account of a computer that uses this operating system. A user may be able to bypass administrator authentication without supplying the administrator\u2019s password.<\/p>\n\n<p>Apple has released the following support article:<\/p>\n\n<ul><li>macOS High Sierra 10.13.1<\/li>\n\t<li>Not impacted versions: macOS Sierra 10.12.6 and earlier<\/li>\n<\/ul><p>This update addresses vulnerabilities on the system listed above.<\/p>\n\n<p>CVE Reference: CVE-2017-13872<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT208315\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208315<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-update","alert_type":396,"serial_number":"AV17-178","subject":null,"moderation_state":"archived","external_url":null},{"nid":827,"title":"EXIM Mailer security update","uuid":"bf537b8c-b31a-4a74-99eb-76572ea20222","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-06T15:28:54Z","summary":null,"body":["<article data-history-node-id=\"827\" about=\"\/en\/alerts-advisories\/exim-mailer-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-179<br \/>\nDate: 29 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for EXIM internet mail server.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>EXIM has released a security patch to address a use-after-free (UAF) vulnerability in Exim Internet Mailer which could lead to the execution of arbitrary code or DoS.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Versions 4.88 and 4.89<\/li>\n<\/ul><p>CVE Reference: CVE-2017-16943<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released update version 4.89.1 on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/exim.org\/\"><font color=\"#0066cc\">http:\/\/exim.org\/<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=cve-2017-16943\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=cve-2017-16943<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-mailer-security-update","alert_type":396,"serial_number":"AV17-179","subject":null,"moderation_state":"archived","external_url":null},{"nid":970,"title":"WordPress security update","uuid":"e26f309d-8261-4066-ab02-60a9f5311619","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-06T15:36:03Z","summary":null,"body":["<article data-history-node-id=\"970\" about=\"\/en\/alerts-advisories\/wordpress-security-update-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-180<br \/>\nDate: 29 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.9.1 that contains fixes to address four security issues which could potentially be exploited as part of a multi-vector compromise.<\/p>\n\n<p>Versions affected: WordPress 4.9.0 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2017\/11\/wordpress-4-9-1-security-and-maintenance-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2017\/11\/wordpress-4-9-1-security-and-maintenance-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-4","alert_type":396,"serial_number":"AV17-180","subject":null,"moderation_state":"archived","external_url":null},{"nid":873,"title":"Cisco security updates","uuid":"ddf0f0a0-bbcb-463c-93e4-0b67b8301471","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-06T15:42:02Z","summary":null,"body":["<article data-history-node-id=\"873\" about=\"\/en\/alerts-advisories\/cisco-security-updates-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-181<br \/>\nDate: 30 November 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<ul><li>Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players<\/li>\n\t<li>Multiple Vulnerabilities in Cisco Data Center Network Manager Software<\/li>\n\t<li>Cisco WebEx Network Recording Player Buffer Overflow Vulnerability<\/li>\n\t<li>Cisco WebEx Meeting Center Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco WebEx Meeting Center URL Redirection Vulnerability<\/li>\n\t<li>Cisco WebEx Event Center Information Disclosure Vulnerability<\/li>\n\t<li>Cisco WebEx Meeting Server Unauthorized Welcome Message Modification Vulnerability<\/li>\n\t<li>Cisco WebEx Network Recording Player Denial of Service Vulnerability<\/li>\n\t<li>Multiple Vulnerabilities in Cisco UCS Central Software<\/li>\n\t<li>Cisco Multilayer Director, Nexus 7181 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability<\/li>\n\t<li>Cisco Prime Service Catalog SQL Injection Vulnerability<\/li>\n\t<li>Cisco Nexus Series Switches Open Agent Container Code Execution Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software Patch Installation Command Injection Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software CLI Arbitrary File Read Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software Interactive TCL Shell Escape Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software Image Signature Bypass Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software Guest Shell Unauthorized Internal Interface Access Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2017-12367,CVE-2017-12368,CVE-2017-12367,CVE-2017-12368,CVE-2017-12369,CVE-2017-12370,CVE-2017-12371,CVE-2017-12372,CVE-2017-12367,CVE-2017-12368,CVE-2017-12369,CVE-2017-12370,CVE-2017-12371,CVE-2017-12372,CVE-2017-12343,CVE-2017-12344,CVE-2017-12343,CVE-2017-12344,CVE-2017-12345,CVE-2017-12346,CVE-2017-12347,CVE-2017-12343,CVE-2017-12344,CVE-2017-12345,CVE-2017-12346,CVE-2017-12347,CVE-2017-12359,CVE-2017-12366,CVE-2017-12297,CVE-2017-12365,CVE-2017-12363,CVE-2017-12360,CVE-2017-12348,CVE-2017-12349,CVE-2017-12340,CVE-2017-12364,CVE-2017-12342,CVE-2017-12341,CVE-2017-12339,CVE-2017-12338,CVE-2017-12336,CVE-2017-12335,CVE-2017-12334,CVE-2017-12333,CVE-2017-12351<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex-players\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex-players<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-dcnm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-dcnm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex5\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex5<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-wmc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-wmc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-webex1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-ucs-central\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-ucs-central<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-switch\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-switch<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-prime\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-prime<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos9\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos9<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos8\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos8<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos7\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos7<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos6\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos6<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos5\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos5<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos10\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171129-nxos10<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-9","alert_type":396,"serial_number":"AV17-181","subject":null,"moderation_state":"archived","external_url":null},{"nid":986,"title":"Apache Struts security update","uuid":"744cfc49-2d4a-4c48-b291-24c6e6163129","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-06T15:48:34Z","summary":null,"body":["<article data-history-node-id=\"986\" about=\"\/en\/alerts-advisories\/apache-struts-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-182<br \/>\nDate: 5 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released critical security updates for Apache Struts and Apache CouchDB.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apache has released Struts 2.5.14.1 which contains security fixes to address a critical vulnerabilities in their software. Additionally, the vulnerability in Apache CouchDB could be used to give administrator level privileges to non-admin users.<\/p>\n\n<p>Versions Affected:<\/p>\n\n<ul><li>Apache Struts 2.5 to Struts 2.5.14<\/li>\n\t<li>Apache CouchDB before 1.7.0 and 2.x before 2.1.1<\/li>\n<\/ul><p>CVE References: CVE-2017-7525, CVE-2017-15707, CVE-2017-12635, CVE-2017-12636<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to the linked security bulletin where Apache outlines the updates that remediate these vulnerabilities.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-054\"><font color=\"#0066cc\">https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-054<\/font><\/a><br \/><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-055\"><font color=\"#0066cc\">https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-055<\/font><\/a><br \/><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12635\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12635<\/font><\/a><br \/><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12636\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12636<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-struts-security-update-0","alert_type":396,"serial_number":"AV17-182","subject":null,"moderation_state":"archived","external_url":null},{"nid":1030,"title":"Mozilla security updates","uuid":"55ed3e35-c30d-44cc-be0f-624fc7e3aeec","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-06T16:01:38Z","summary":null,"body":["<article data-history-node-id=\"1030\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-183<br \/>\nDate: 5 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address two vulnerabilities in Firefox. The severity of these issues ranges from high to critical.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 57.0.1<\/p>\n\n<p>CVE References: CVE-2017-7843, CVE-2017-7844<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-27\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-27\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-3","alert_type":396,"serial_number":"AV17-183","subject":null,"moderation_state":"archived","external_url":null},{"nid":1234,"title":"Google Releases security update for Chrome","uuid":"72e393d9-b7d3-4979-b3e4-29b2316f8fad","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-06T16:16:16Z","summary":null,"body":["<article data-history-node-id=\"1234\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-29\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-184<br \/>\nDate: 7 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 63.0.3239.84 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2017-15407,CVE-2017-15408,CVE-2017-15409, CVE-2017-15410, CVE-2017-15411, CVE-2017-15412, CVE-2017-15413, CVE-2017-15415, CVE-2017-15416, CVE-2017-15417, CVE-2017-15418, CVE-2017-15419, CVE-2017-15420, CVE-2017-15422, CVE-2017-15423, CVE-2017-15424, CVE-2017-15425, CVE-2017-15426, CVE-2017-15427<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2017\/12\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2017\/12\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-29","alert_type":396,"serial_number":"AV17-184","subject":null,"moderation_state":"archived","external_url":null},{"nid":1247,"title":"Apple security update","uuid":"935ddc4b-c134-4a2f-8b90-14df8aeb8296","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-06T16:23:47Z","summary":null,"body":["<article data-history-node-id=\"1247\" about=\"\/en\/alerts-advisories\/apple-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-185<br \/>\nDate: 07 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple system security update for, iOS, macOS High Sierra, tvOS, watchOS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released a support article regarding security vulnerabilities in their products and the relevant iOS, macOS High Sierra, tvOS, watchOS.<\/p>\n\n<ul><li>iOS 11.2<\/li>\n\t<li>macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan<\/li>\n\t<li>tvOS 11.2<\/li>\n\t<li>watchOS 4.2<\/li>\n<\/ul><p>This update addresses vulnerabilities on the system listed above.<\/p>\n\n<p>CVE Reference: CVE-2017-13847,CVE-2017-13879,CVE-2017-13861,CVE-2017-13862,CVE-2017-13876,CVE-2017-13833,CVE-2017-13855,CVE-2017-13867,CVE-2017-13865,CVE-2017-13868,CVE-2017-13869,CVE-2017-13874,CVE-2017-13860,CVE-2017-13080,CVE-2017-9798,CVE-2017-1000254,CVE-2017-13872,CVE-2017-13883,CVE-2017-13878,CVE-2017-13875,CVE-2017-13844,CVE-2017-13848,CVE-2017-13858,CVE-2017-13871,CVE-2017-3735,CVE-2017-13826,CVE-2017-13080<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-us\/HT208334\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208334<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208331\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208331<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208327\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208327<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208325\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208325<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-update-0","alert_type":396,"serial_number":"AV17-185","subject":null,"moderation_state":"archived","external_url":null},{"nid":852,"title":"Microsoft Malware Protection Engine security update","uuid":"53014ce5-4d9d-450c-97e8-e63532a45c74","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-06T17:12:45Z","summary":null,"body":["<article data-history-node-id=\"852\" about=\"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-186<br \/>\nDate: 07 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Microsoft security update for Malware Protection Engine.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a critical vulnerability in the Microsoft Malware Protection Engine.\u00a0 Exploitation of this vulnerability may allow for remote code execution with elevated privileges and\/or create denial of service conditions.<\/p>\n\n<p>Affected Versions:\u00a0 Microsoft Malware Protection Engine version prior to 1.1.14405.2<\/p>\n\n<p>CVE reference: CVE-2017-11937<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-11937\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-11937<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-malware-protection-engine-security-update-2","alert_type":396,"serial_number":"AV17-186","subject":null,"moderation_state":"archived","external_url":null},{"nid":995,"title":"Mozilla security updates","uuid":"d47ac37b-f96f-4cd0-a774-6a0a9606ecb3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:40Z","date_created":"2018-07-06T17:19:29Z","summary":null,"body":["<article data-history-node-id=\"995\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-187<br \/>\nDate: 08 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Versions affected:<br \/>\nFirefox versions prior to 57.0.2<br \/>\nFirefox ESR versions prior to 52.5.2<\/p>\n\n<p>CVE References: CVE-2017-7843, CVE-2017-7845<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-29\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-29\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-28\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2017-28\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-4","alert_type":396,"serial_number":"AV17-187","subject":null,"moderation_state":"archived","external_url":null},{"nid":1061,"title":"security update for Adobe Flash Player","uuid":"0571b95c-9895-48f6-b54e-3fc8a7d35bcf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-06T17:27:47Z","summary":null,"body":["<article data-history-node-id=\"1061\" about=\"\/en\/alerts-advisories\/security-update-adobe-flash-player-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-188<br \/>\nDate: 12 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security update for Adobe Flash Player.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for Adobe Flash Player for Windows, Macintosh, Linux and Chrome OS. These updates address a regression that could lead to the unintended reset of the global settings preference file.<\/p>\n\n<p>Affected software versions:<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime 27.0.0.187 and earlier versions Windows, Macintosh<\/li>\n\t<li>Adobe Flash Player for Google Chrome 27.0.0.187 and earlier versions Windows, Macintosh, Linux and Chrome OS\u00a0<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 27.0.0.187 and earlier versions Windows 10 and 8.1<\/li>\n\t<li>Adobe Flash Player Desktop Runtime 27.0.0.187 and earlier versions Linux<\/li>\n<\/ul><p>CVE Reference:\u00a0 CV-2017-11305<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-42.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb17-42.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-update-adobe-flash-player-2","alert_type":396,"serial_number":"AV17-188","subject":null,"moderation_state":"archived","external_url":null},{"nid":787,"title":"Microsoft security updates","uuid":"2e360df5-977d-443d-8048-90290c810a36","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-06T17:33:47Z","summary":null,"body":["<article data-history-node-id=\"787\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-189<br \/>\nDate: 12 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products including Internet Explorer, Microsoft Edge, Microsoft Windows, Microsoft Office and Microsoft Office Services and Web Apps, Microsoft Exchange Server, ChakraCore and Microsoft Malware Protection Engine.<\/p>\n\n<p>CVE References: CVE-2017-11885, CVE-2017-11886, CVE-2017-11887, CVE-2017-11888, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11899, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11906, CVE-2017-11907, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, CVE-2017-11919, CVE-2017-11927, CVE-2017-11930, CVE-2017-11932, CVE-2017-11934, CVE-2017-11935, CVE-2017-11936, CVE-2017-11939, CVE-2017-11940<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/c383fa60-b852-e711-80dd-000d3a32f9b6\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/c383fa60-b852-e711-80dd-000d3a32f9b6<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-6","alert_type":396,"serial_number":"AV17-189","subject":null,"moderation_state":"archived","external_url":null},{"nid":1284,"title":"SAP Security Patches","uuid":"5910b4da-17ca-441b-ab85-ee8a880ad4a2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-06T17:39:26Z","summary":null,"body":["<article data-history-node-id=\"1284\" about=\"\/en\/alerts-advisories\/sap-security-patches-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-190<br \/>\nDate: 12 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a series of security updates that resolve numerous vulnerabilities with various SAP applications.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>SAP's security advisory outlines numerous patches that resolve vulnerabilities in their products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>SAP Netweaver Documentation and Translation tools<\/li>\n\t<li>Trusted RFC connection<\/li>\n\t<li>SAP Business Objects Enterprise<\/li>\n\t<li>SAP BI Promotion Management Application<\/li>\n\t<li>SAP Business Warehouse Universal Data Integration<\/li>\n\t<li>SAP NetWeaver Knowledge Management Configuration Service<\/li>\n\t<li>SAP Business Intelligence Promotion Management Application<\/li>\n\t<li>SAP Business Objects Platform<\/li>\n\t<li>SAP Note Assistant<\/li>\n\t<li>SAP Startup Service<\/li>\n\t<li>SAP HANA extended application services<\/li>\n\t<li>SAP Netweaver Internet Transaction Server (ITS)<\/li>\n\t<li>SAP Plant Connectivity (PCo)<\/li>\n<\/ul><p>\u00a0<\/p>\n\n<p>SAP Security Note References: 2357141, 2449757, 2026174, 253712, 2537545, 2457562, 2531656, 2523913, 2408073, 2520995, 2522510, 2549983, 2546220, 2526781, 25294080.<\/p>\n\n<p>CVE References\u00a0: CVE-2014-0094, CVE-2017-16678, CVE-2017-16679, CVE-2017-16680, CVE-2017-16681, CVE-2017-16682, CVE-2017-16683, CVE-2017-16684, CVE-2017-16685, CVE-2017-16687, CVE-2017-16689, CVE-2017-16690, CVE-2017-16691<\/p>\n\n<p>Please note that SAP credentials are required to access these references on the link provided below.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to the linked security note where SAP expands on the details of the vulnerabilities of each of the security notes and provides a patch to resolve the issues on each respective product.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/blogs.sap.com\/2017\/12\/12\/sap-security-patch-day-december-2017\/\"><font color=\"#0066cc\">https:\/\/blogs.sap.com\/2017\/12\/12\/sap-security-patch-day-december-2017\/<\/font><\/a><br \/><a href=\"https:\/\/support.sap.com\/kb-incidents\/notifications\/security-notes.html\"><font color=\"#0066cc\">https:\/\/support.sap.com\/kb-incidents\/notifications\/security-notes.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-patches-0","alert_type":396,"serial_number":"AV17-190","subject":null,"moderation_state":"archived","external_url":null},{"nid":960,"title":"Apple security updates","uuid":"d4c219da-7f20-48cb-946c-bb11664a4e88","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-06T17:45:08Z","summary":null,"body":["<article data-history-node-id=\"960\" about=\"\/en\/alerts-advisories\/apple-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-191<br \/>\nDate: 13 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple system security updates for iOS, tvOS and AirPort Base Station.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released support articles regarding recent security vulnerabilities in their products and the relevant iOS, tvOS and AirPort Base Station.<\/p>\n\n<ul><li>AirPort Base Station Firmware Update 7.6.9<\/li>\n\t<li>AirPort Base Station Firmware Update 7.7.9<\/li>\n\t<li>iOS 11.2.1<\/li>\n\t<li>tvOS 11.2.1<\/li>\n<\/ul><p>\u00a0<\/p>\n\n<p>This update addresses vulnerabilities on the system listed above.<\/p>\n\n<p>CVE Reference: CVE-2017-9417, CVE-2017-13077, CVE-2017-13078, CVE-2017-13080, CVE-2017-13903<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT208354\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208354<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208258\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208258<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208357\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208357<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT208359\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208359<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-6","alert_type":396,"serial_number":"AV17-191","subject":null,"moderation_state":"archived","external_url":null},{"nid":949,"title":"Palo Alto Networks security advisory","uuid":"c9bf3ae5-4fab-465a-b304-46b2d9cb4638","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-06T17:50:39Z","summary":null,"body":["<article data-history-node-id=\"949\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-192<br \/>\nDate: 14 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory for Palo Alto Networks PAN-OS.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Palo Alto Networks has released a security advisory to address a remote code execution vulnerability in PAN-OS. The severity of this issue is critical.<\/p>\n\n<p><strong>Critical<\/strong><\/p>\n\n<ul><li>PAN-SA-2017-0027 - Vulnerability in PAN-OS on Management Interface<\/li>\n<\/ul><p>CVE References: CVE-2017-15944<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/102\"><font color=\"#0066cc\">PAN-SA-2017-0027<\/font><\/a><br \/><a href=\"http:\/\/seclists.org\/fulldisclosure\/2017\/Dec\/38\"><font color=\"#0066cc\">Full Disclosure<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory","alert_type":396,"serial_number":"AV17-192","subject":null,"moderation_state":"archived","external_url":null},{"nid":1010,"title":"Fortinet Forticlient security update","uuid":"90e8a1fd-50b5-44f1-b3b9-b2ffdc0b338b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-06T17:56:48Z","summary":null,"body":["<article data-history-node-id=\"1010\" about=\"\/en\/alerts-advisories\/fortinet-forticlient-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-193<br \/>\nDate: 14 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an update for Fortinet\u2019s FortiClient endpoint protection.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a critical information disclosure vulnerability in Fortinet\u2019s FortiClient.\u00a0 Exploitation of this vulnerability may allow for unwanted disclosure of VPN authentication credentials, allowing a regular user to harvest other user\u2019s encrypted credentials and decrypt them into plaintext using a hard coded key.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>FortiClient for Windows: 5.6.0 and versions below<\/li>\n\t<li>FortiClient for Mac OSX 5.6.0 and versions below<\/li>\n\t<li>FortiClient SSLVPN Client for Linux 4.4.2334 and versions below<\/li>\n<\/ul><p>CVE reference: CVE-2017-14184<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<ul><li>FortiClient for Windows: Upgrade to 5.6.1<\/li>\n\t<li>FortiClient for Mac OSX: Upgrade to 5.6.1<\/li>\n\t<li>FortiClient SSLVPN Client for Linux: Upgrade to 4.4.2335 released together with FortiOS 5.4.7<\/li>\n<\/ul><p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-17-214\"><font color=\"#0066cc\">https:\/\/fortiguard.com\/psirt\/FG-IR-17-214<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/seclists.org\/fulldisclosure\/2017\/Dec\/43\"><font color=\"#0066cc\">http:\/\/seclists.org\/fulldisclosure\/2017\/Dec\/43<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.sec-consult.com\/en\/blog\/advisories\/vpn-credentials-disclosure-in-fortinet-forticlient\/index.html\"><font color=\"#0066cc\">https:\/\/www.sec-consult.com\/en\/blog\/advisories\/vpn-credentials-disclosure-in-fortinet-forticlient\/index.html<\/font><\/a> \u00a0<\/li>\n\t<li><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2017-14184\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2017-14184<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-forticlient-security-update","alert_type":396,"serial_number":"AV17-193","subject":null,"moderation_state":"archived","external_url":null},{"nid":761,"title":"Google Releases security update for Chrome","uuid":"ded2336c-5a32-43f1-8415-7ce2cbae5a2d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-06T18:02:43Z","summary":null,"body":["<article data-history-node-id=\"761\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-30\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-194<br \/>\nDate: 15 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 63.0.3239.108 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2017-15429<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-30","alert_type":396,"serial_number":"AV17-194","subject":null,"moderation_state":"archived","external_url":null},{"nid":829,"title":"VMware security advisory","uuid":"e4318116-2e69-452c-ad19-78928e54e555","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-06T18:19:03Z","summary":null,"body":["<article data-history-node-id=\"829\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV17-195<br \/>\nDate: 21 December 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing multiple security vulnerabilities for multiple products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware ESXi (ESXi)<\/li>\n\t<li>VMware vCenter Server Appliance (vCSA)<\/li>\n\t<li>VMware Workstation Pro \/ Player (Workstation)<\/li>\n\t<li>VMware Fusion Pro, Fusion (Fusion)<\/li>\n<\/ul><p>CVE Reference: CVE-2017-4933, CVE-2017-4940, CVE-2017-4941, CVE-2017-4943<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0021.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2017-0021.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-3","alert_type":396,"serial_number":"AV17-195","subject":null,"moderation_state":"archived","external_url":null},{"nid":971,"title":"Meltdown and Spectre Side-Channel Vulnerabilities","uuid":"51821447-8344-4921-907b-ba162b626403","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-06T18:27:30Z","summary":null,"body":["<article data-history-node-id=\"971\" about=\"\/en\/alerts-advisories\/meltdown-and-spectre-side-channel-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL18-001<br \/>\nDate: 4 January 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to side-channel vulnerabilities, which affect many modern computer processors. There are three known variants of this issue. Variant 1: CVE-2017-5753, Variant 2: CVE-2017-5715, Variant 3: CVE-2017-5754. Variants 1 and 2 are referred to as Spectre. Variant 3 is referred to as Meltdown.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>These hardware vulnerabilities work on personal computers, mobile devices, and in the cloud. Every Intel processor which implements out-of-order execution is potentially affected by Meltdown. Spectre affects Intel, AMD and ARM processors.<\/p>\n\n<p>Both Meltdown and Spectre use side-channel to obtain the information from the accessed memory location, termed \u201cKernel-memory-leaking\u201d. While Meltdown breaks the mechanism that keeps applications from accessing arbitrary system memory, Spectre tricks other applications into accessing arbitrary locations in their memory. Leaked information could include passwords stored in a password manager or browser, personal photos, emails, instant messages and documents.<\/p>\n\n<p>The exploitation does not leave any traces and it is unlikely that the intrusion would be detected. However, the antivirus may detect malware used in the intrusion. There has not been a confirmation of any active exploitation at this time.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends consulting the operating system vendor or system manufacturer for specific risk mitigation advice. It is recommended to apply software and firmware updates as soon as they are available. In case of unsuccessful mitigation organizations may consider a replacement of CPU hardware.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/newsroom.intel.com\/news\/intel-responds-to-security-research-findings\/\"><font color=\"#0066cc\">https:\/\/newsroom.intel.com\/news\/intel-responds-to-security-research-findings\/<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/www.us-cert.gov\/ncas\/current-activity\/2018\/01\/03\/Meltdown-and-Spectre-Side-Channel-Vulnerabilities\"><font color=\"#0066cc\">https:\/\/www.us-cert.gov\/ncas\/current-activity\/2018\/01\/03\/Meltdown-and-Spectre-Side-Channel-Vulnerabilities<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/584653\"><font color=\"#0066cc\">https:\/\/www.kb.cert.org\/vuls\/id\/584653<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/spectreattack.com\/\"><font color=\"#0066cc\">https:\/\/spectreattack.com<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/meltdownattack.com\/\"><font color=\"#0066cc\">https:\/\/meltdownattack.com\/<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV180002#\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV180002#<\/font><\/a><\/li>\n<\/ul><p><strong>CVE References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5753\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5753<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5715\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5715<\/font><\/a><\/li>\n\t<br \/><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5754\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5754<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/meltdown-and-spectre-side-channel-vulnerabilities","alert_type":397,"serial_number":"AL18-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":875,"title":"Adobe Flash Critical Vulnerability","uuid":"23248eff-9a6b-4ada-96c1-18cf503c896f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-06T18:35:13Z","summary":null,"body":["<article data-history-node-id=\"875\" about=\"\/en\/alerts-advisories\/adobe-flash-critical-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL18-002<br \/>\nDate: 1 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed critical vulnerability (CVE-2018-4878) that exists in Adobe Flash Player 28.0.0.137 and earlier versions.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of an exploit for CVE-2018-4878 existing in the wild, and is being used in limited, targeted attacks against Windows users. These attacks leverage Office documents with embedded malicious Flash content distributed via email. Successful exploitation could potentially allow an attacker to take control of the affected system.<\/p>\n\n<p>Affected Products (28.0.0.137 and earlier versions) :<\/p>\n\n<ul><li>Adobe Flash Player Desktop Runtime for Windows, Macintosh and Linux<\/li>\n\t<li>Adobe Flash Player for Google Chrome for Windows, Macintosh, Linux and Chrome OS<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11 for Windows 8.1 and Windows 10<\/li>\n<\/ul><h2>Suggested action<\/h2>\n\n<p>Adobe will address this vulnerability in a release planned for the week of February 5.<\/p>\n\n<p>Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for the developer released security fix.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa18-01.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsa18-01.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-flash-critical-vulnerability","alert_type":397,"serial_number":"AL18-002","subject":null,"moderation_state":"archived","external_url":null},{"nid":980,"title":"Drupal Security Vulnerability","uuid":"c950821c-0424-48e2-8823-1ca8fd3a832a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-06T18:41:55Z","summary":null,"body":["<article data-history-node-id=\"980\" about=\"\/en\/alerts-advisories\/drupal-security-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL18-003<br \/>\nDate: 29 March 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed highly critical remote code vulnerability (CVE-2018-7600) that exists in multiple subversions of Drupal 7.x, 8.x and 6.x.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal is an open source platform widely used for content management software across multiple organizations.\u00a0 CCIRC is not aware of exploit activity affecting organizations at this time.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Drupal 6.x all versions<\/li>\n\t<li>Drupal 7.x versions prior to 7.58<\/li>\n\t<li>Drupal 8.x versions prior to 8.5.1<\/li>\n<\/ul><p>Certain subversions, such as 8.3.x and 8.4.x, are no longer supported, however, given the potential severity of this issue, Drupal has release fixes.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2018-002\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/sa-core-2018-002<\/font><\/a><br \/><a href=\"https:\/\/groups.drupal.org\/security\/faq-2018-002\"><font color=\"#0066cc\">https:\/\/groups.drupal.org\/security\/faq-2018-002<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-vulnerability","alert_type":397,"serial_number":"AL18-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":1024,"title":"VMware security advisory","uuid":"9f5a87bc-aa6f-4144-a30a-d8427cf43546","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-06T18:47:56Z","summary":null,"body":["<article data-history-node-id=\"1024\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-001<br \/>\nDate: 3 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing multiple security vulnerabilities for vSphere Data Protection (VDP).<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware vSphere Data Protection (VDP)<\/li>\n<\/ul><p>CVE Reference: CVE-2017-15548, CVE-2017-15549, CVE-2017-15550<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0001.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0001.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-4","alert_type":396,"serial_number":"AV18-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1236,"title":"Microsoft security updates \u2013 Out-of-Band","uuid":"e86f0840-eabb-4374-b162-9f1cb32b9069","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-06T18:54:28Z","summary":null,"body":["<article data-history-node-id=\"1236\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-out-band-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-002<br \/>\nDate: 04 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates. This update resolves vulnerabilities that could be used to read the content of memory across a trusted boundary and can therefore lead to information disclosure.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers multiple out-of-band support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Windows Server 2016<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n\t<li>Windows Server 2008 R2 for x64-based Systems Service Pack 1<\/li>\n\t<li>Windows 8.1 for x64-based systems<\/li>\n\t<li>Windows 8.1 for 32-bit systems<\/li>\n\t<li>Windows 7 for x64-based Systems Service Pack 1<\/li>\n\t<li>Windows 7 for 32-bit Systems Service Pack 1<\/li>\n\t<li>Windows 10 Version 1709 for 64-based Systems<\/li>\n\t<li>Windows 10 Version 1709 for 32-bit Systems<\/li>\n\t<li>Windows 10 Version 1703 for x64-based Systems<\/li>\n\t<li>Windows 10 Version 1703 for 32-bit Systems<\/li>\n\t<li>Windows 10 Version 1607 for x64-based Systems<\/li>\n\t<li>Windows 10 Version 1607 for 32-bit Systems<\/li>\n\t<li>Windows 10 Version 1511 for x64-based Systems<\/li>\n\t<li>Windows 10 Version 1511 for 32-bit Systems<\/li>\n\t<li>Windows 10 for x64-based Systems<\/li>\n\t<li>Windows 10 for 32-bit Systems<\/li>\n<\/ul><p>CVE References: CVE-2017-5754, CVE-2017-5753, CVE-2017-5715, CVE-2018-0818, CVE-2018-0788, CVE-2018-0754, CVE-2018-0750, CVE-2018-0741, CVE-2018-0753, CVE-2018-0746, CVE-2018-0747, CVE-2018-0748, CVE-2018-0751, CVE-2018-0752, CVE-2018-0744, CVE-2018-0745, CVE-2018-0749, CVE-2018-0743, CVE-2018-0762, CVE-2018-0772, CVE-2018-0766, CVE-2018-0773, CVE-2018-0774, CVE-2018-0781, CVE-2018-0800, CVE-2018-0758, CVE-2018-0767, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, CVE-2018-0780, CVE-2018-0803<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180002\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180002<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4072699\/important-information-regarding-the-windows-security-updates-released\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4072699\/important-information-regarding-the-windows-security-updates-released<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4056892\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4056892<\/font><\/a>\u00a0<\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4056891\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4056891<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4056890\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4056890<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4056893\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4056893<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4056888\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4056888<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/help\/4073119\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/help\/4073119<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/help\/4072698\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/help\/4072698<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/help\/4072699\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/help\/4072699<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/help\/4073225\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/help\/4073225<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/help\/4073235\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/help\/4073235<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/securing-azure-customers-from-cpu-vulnerability\/\"><font color=\"#0066cc\">https:\/\/azure.microsoft.com\/en-us\/blog\/securing-azure-customers-from-cpu-vulnerability\/<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/aka.ms\/securityupdateguide\"><font color=\"#0066cc\">http:\/\/aka.ms\/securityupdateguide<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-out-band-0","alert_type":396,"serial_number":"AV18-002","subject":null,"moderation_state":"archived","external_url":null},{"nid":1248,"title":"VMware security advisory","uuid":"488d0332-2135-4817-906d-6681a4b2a36c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-06T19:00:39Z","summary":null,"body":["<article data-history-node-id=\"1248\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-003<br \/>\nDate: 05 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing multiple security vulnerabilities in vRealize Operations for Horizon, vRealize Operations for Published Applications, Workstation, Horizon View Client and Tools.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>vRealize Operations for Horizon (V4H)<\/li>\n\t<li>vRealize Operations for Published Applications (V4PA)<\/li>\n\t<li>VMware Workstation Pro \/ Player (Workstation)<\/li>\n\t<li>VMware Fusion Pro \/ Fusion (Fusion)<\/li>\n\t<li>Horizon View Client for Windows<\/li>\n<\/ul><p>CVE References: CVE-2017-4945, CVE-2017-4946, CVE-2017-4948<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0003.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0003.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-5","alert_type":396,"serial_number":"AV18-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":853,"title":"Apple security updates","uuid":"871ef09b-e840-4d8a-9f7e-c6c35ad988ae","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-06T19:07:09Z","summary":null,"body":["<article data-history-node-id=\"853\" about=\"\/en\/alerts-advisories\/apple-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-004<br \/>\nDate: 09 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple system security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released a support article regarding security vulnerabilities in their products and the relevant iOS, macOS High Sierra, Safari, tvOS, watchOS.<\/p>\n\n<p>- iOS versions prior to 11.2.2<br \/>\n- macOS versions prior to 10.13.2.<br \/>\n- tvOS versions prior to 11.2.1.<br \/>\n- watchOS versions prior to 4.2.<br \/>\n- Safari versions prior to 11.0.2.<\/p>\n\n<p>CVE Reference: CVE-2017-5753, CVE-2017-5715<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT208397\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208397<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT208403\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208403<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT208401\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT208401<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-7","alert_type":396,"serial_number":"AV18-004","subject":null,"moderation_state":"archived","external_url":null},{"nid":987,"title":"Microsoft security updates","uuid":"66a941ea-c6b4-408a-b259-c21633a788f5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:40Z","date_created":"2018-07-06T19:12:59Z","summary":null,"body":["<article data-history-node-id=\"987\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-005<br \/>\nDate: 09 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products including Internet Explorer, Microsoft Edge, Microsoft Windows, Microsoft Office and Microsoft Office Services and Web Apps, SQL Server, ChakraCore, .NET Framework, .NET Core, ASP.NET Core and Adobe Flash.<\/p>\n\n<p>CVE References: ADV180001,ADV180002,ADV180003,CVE-2018-0741,CVE-2018-0743,CVE-2018-0744,CVE-2018-0745,CVE-2018-0746,CVE-2018-0747,CVE-2018-0748,CVE-2018-0749,CVE-2018-0750,CVE-2018-0751,CVE-2018-0752,CVE-2018-0753,CVE-2018-0754,CVE-2018-0758,CVE-2018-0762,CVE-2018-0764,CVE-2018-0766,CVE-2018-0767,CVE-2018-0768,CVE-2018-0769,CVE-2018-0770,CVE-2018-0772,CVE-2018-0773,CVE-2018-0774,CVE-2018-0775,CVE-2018-0776,CVE-2018-0777,CVE-2018-0778,CVE-2018-0780,CVE-2018-0781,CVE-2018-0784,CVE-2018-0785,CVE-2018-0786,CVE-2018-0788,CVE-2018-0789,CVE-2018-0790,CVE-2018-0791,CVE-2018-0792,CVE-2018-0793,CVE-2018-0794,CVE-2018-0795,CVE-2018-0796,CVE-2018-0797,CVE-2018-0798,CVE-2018-0799,CVE-2018-0800,CVE-2018-0801,CVE-2018-0802,CVE-2018-0803,CVE-2018-0804,CVE-2018-0805,CVE-2018-0806,CVE-2018-0807,CVE-2018-0812,CVE-2018-0818,CVE-2018-0819<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/858123b8-25ca-e711-a957-000d3a33cf99\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/858123b8-25ca-e711-a957-000d3a33cf99<\/font><\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-7","alert_type":396,"serial_number":"AV18-005","subject":null,"moderation_state":"archived","external_url":null},{"nid":1063,"title":"SierraWireless ALEOS update 4.4.5 for AirLink devices","uuid":"8a849db1-e3fa-4856-be3b-6fc4a05460f8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-06T19:19:28Z","summary":null,"body":["<article data-history-node-id=\"1063\" about=\"\/en\/alerts-advisories\/sierrawireless-aleos-update-445-airlink-devices\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-006<br \/>\nDate: 09 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent ALEOS software release that addresses a number configuration and third party vulnerabilities.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>ALEOS has released product updates addressing multiple security vulnerabilities for multiple ALEOS products.<\/p>\n\n<p>Among the changes in this release: certain default account settings which will reduce security risks when exposed to untrusted networks; the ACEmanager viewer account has been removed (1); firmware updates are now authenticated; DMZ will be disabled when \u201cHost Connection Mode\u201d is not set to \u201cEthernet Uses Public IP\u201d and \u201cDMZ Enabled\u201d is set to \u201cAutomatic\u201d; and a user space monitor has been added to the flash memory file system.<\/p>\n\n<p>Affected Products:<br \/>\nAirLink GX400, GX440, ES440, and LS300 running software prior to 4.4.5.<\/p>\n\n<p>CVE References:<\/p>\n\n<p>User input validation: CVE-2017-15043<br \/>\nOpenSSL: CVE-2016-0701, CVE-2017-3731, CVE-2016-2181, CVE-2016-0702, CVE-2017-3732, CVE-2016-2182, CVE-2016-0705, CVE-2016-2105, CVE-2016-2183, CVE-2016-0797, CVE-2016-2106, CVE-2016-6302, CVE-2016-0798, CVE-2016-2107, CVE-2016-6303, CVE-2016-0799, CVE-2016-2109, CVE-2016-6304, CVE-2016-0800, CVE-2016-2176, CVE-2016-6306, CVE-2016-2842, CVE-2016-2177, CVE-2015-3195, CVE-2015-1794, CVE-2016-2178, CVE-2015-3197, CVE-2015-3193, CVE-2016-2179, CVE-2015-3194, CVE-2016-2180<br \/>\nDropbear: CVE-2017-9078 and CVE-2017-9079<br \/>\nTcpdump and Libpcap: CVE-2014-8769 and CVE-2014-8767<br \/>\nLinux kernel: CVE-2017-14106, CVE-2014-7822, CVE-2014-9888, CVE-2015-3288<br \/>\nOpenVPN: CVE-2017-7520 and CVE-2017-7479<br \/>\nSNMP: CVE-2015-5621<br \/>\nLibcurl: CVE-2016-5421<\/p>\n\n<p>Dnsmasq: CVE-2017-14496, CVE-2017-14491, CVE-2017-14492, CVE-2017-14493, CVE-2017-14494, CVE-2017-14495<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p>CCIRC recommends confirming if your remote access, mobile or off-site solutions include this type of cellular gateway. Contact your integrator or service provider for more information on how to properly test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Release Notes:<\/p>\n\n<ul><li><a href=\"https:\/\/source.sierrawireless.com\/resources\/airlink\/software_reference_docs\/release-notes\/aleos-4,-d-,4,-d-,5-release-notes\/\"><font color=\"#0066cc\">https:\/\/source.sierrawireless.com\/resources\/airlink\/software_reference_docs\/release-notes\/aleos-4,-d-,4,-d-,5-release-notes\/<\/font><\/a> \u00a0<\/li>\n\t<li>(1) Products: AirLink\u00ae Gateways running ALEOS 4.5.2 or older using default user or viewer password - <a href=\"https:\/\/source.sierrawireless.com\/~\/media\/support_downloads\/airlink\/docs\/technical%20bulletin\/technical%20bulletin%20-%20malware%20threat%20-%2011sep2017%20-%20release.ashx?la=en\"><font color=\"#0066cc\">https:\/\/source.sierrawireless.com\/~\/media\/support_downloads\/airlink\/docs\/technical%20bulletin\/technical%20bulletin%20-%20malware%20threat%20-%2011sep2017%20-%20release.ashx?la=en<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/search\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/search<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sierrawireless-aleos-update-445-airlink-devices","alert_type":396,"serial_number":"AV18-006","subject":null,"moderation_state":"archived","external_url":null},{"nid":789,"title":"Intel updates for Linux","uuid":"66539bb8-b879-4ae8-b8fa-98eb34d6bd14","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-06T19:25:21Z","summary":null,"body":["<article data-history-node-id=\"789\" about=\"\/en\/alerts-advisories\/intel-updates-linux\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-007<br \/>\nDate: 10 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released updates by Intel.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Intel has released Processor Microcode Data Files for specific Linux distributions to address vulnerabilities in the chipset instructions.<\/p>\n\n<p>Affected platforms:<\/p>\n\n<ul><li>Red Hat Enterprise Linux<\/li>\n\t<li>Red Hat Linux<\/li>\n\t<li>SUSE Linux<\/li>\n\t<li>SUSE Linux Enterprise Server<\/li>\n\t<li>CentOS 7.4<\/li>\n\t<li>Chromium OS<\/li>\n\t<li>Debian<\/li>\n\t<li>Fedora 24<\/li>\n\t<li>Google Chrome OS<\/li>\n\t<li>Linux<\/li>\n\t<li>OpenDesktop<\/li>\n\t<li>Ubuntu<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/downloadcenter.intel.com\/download\/27431\/Linux-Processor-Microcode-Data-File\"><font color=\"#0066cc\">https:\/\/downloadcenter.intel.com\/download\/27431\/Linux-Processor-Microcode-Data-File<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-updates-linux","alert_type":396,"serial_number":"AV18-007","subject":null,"moderation_state":"archived","external_url":null},{"nid":1285,"title":"NVIDIA security advisory","uuid":"33721d4b-747d-4fe1-bf98-63ce71263582","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-06T19:30:27Z","summary":null,"body":["<article data-history-node-id=\"1285\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-008<br \/>\nDate: 10 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by NVIDIA.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>NVIDIA has released product updates addressing multiple security vulnerabilities for multiple products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>GeForce (All versions)<\/li>\n\t<li>Quadro, NVS (All versions)<\/li>\n\t<li>Tesla (All versions)<\/li>\n\t<li>GRID (All versions)<\/li>\n<\/ul><p>CVE Reference: CVE-2017-5753, CVE-2017-5715, CVE-2017-5754<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4611\"><font color=\"#0066cc\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4611<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory","alert_type":396,"serial_number":"AV18-008","subject":null,"moderation_state":"archived","external_url":null},{"nid":961,"title":"VMware security advisory","uuid":"421f81ee-db84-4d6c-bdfb-72fef2f00da8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-06T19:35:38Z","summary":null,"body":["<article data-history-node-id=\"961\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-009<br \/>\nDate: 10 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing multiple security vulnerabilities in VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware vCenter Server (VC)<\/li>\n\t<li>VMware vSphere ESXi (ESXi)<\/li>\n\t<li>VMware Workstation Pro \/ Player (Workstation)<\/li>\n\t<li>VMware Fusion Pro \/ Fusion (Fusion)<\/li>\n<\/ul><p>CVE Reference: CVE-2017-5715<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0004.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0004.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-6","alert_type":396,"serial_number":"AV18-009","subject":null,"moderation_state":"archived","external_url":null},{"nid":951,"title":"Lenovo security advisory","uuid":"1bf0baca-4ba8-463d-93ed-6a53a60c485e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-06T19:41:25Z","summary":null,"body":["<article data-history-node-id=\"951\" about=\"\/en\/alerts-advisories\/lenovo-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-010<br \/>\nDate: 16 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Lenovo has released a security advisory to address a vulnerability known as \u201cHP Backdoor\u201d which could allow an unauthenticated remote user to bypass authentication and gain administrative privileges on a targeted device.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Lenovo Flex System Fabric CN4093 10Gb Converged Scalable Switch\u00a0<\/li>\n\t<li>Lenovo Flex System Fabric EN4093R 10Gb Scalable Switch\u00a0<\/li>\n\t<li>Lenovo Flex System Fabric SI4093 10Gb System Interconnect Module\u00a0<\/li>\n\t<li>Lenovo Flex System SI4091 System Interconnect Module\u00a0<\/li>\n\t<li>Lenovo Rack Switch G8272-CNOS\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8332-CNOS\u00a0<\/li>\n\t<li>Lenovo RackSwitch G7028 (ThinkAgile CX2200)\u00a0<\/li>\n\t<li>Lenovo RackSwitch G7052 (ThinkAgile CX4200\/CX4600)\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8052\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8124E (ThinkAgile CX2200)\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8264\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8264CS\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8272 (ThinkAgile CX4200\/CX4600)\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8296\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8296-CNOS\u00a0<\/li>\n\t<li>Lenovo RackSwitch G8332\u00a0<\/li>\n\t<li>IBM Flex System\u2122 Fabric EN4093\/EN4093R 10Gb Scalable Switch\u00a0<\/li>\n\t<li>IBM Flex System\u2122 Fabric CN4093 10Gb Converged Scalable Switch\u00a0<\/li>\n\t<li>IBM Flex System\u2122 Fabric SI4093 10Gb System Interconnect Module\u00a0<\/li>\n\t<li>IBM Flex System EN2092 1Gb Ethernet Scalable Switch\u00a0<\/li>\n\t<li>IBM 1G L2-7 SLB switch for Bladecenter\u00a0<\/li>\n\t<li>IBM BladeCenter Virtual Fabric 10Gb Switch Module\u00a0<\/li>\n\t<li>IBM Bladecenter 1:10G Uplink Ethernet switch Module\u00a0<\/li>\n\t<li>IBM BladeCenter Layer 2\/3 Copper Ethernet Switch Module\u00a0<\/li>\n\t<li>IBM RackSwitch G8264CS\u00a0<\/li>\n\t<li>IBM RackSwitch G8264\u00a0<\/li>\n\t<li>IBM RackSwitch G8052\u00a0<\/li>\n\t<li>IBM Rackswitch G8332\u00a0<\/li>\n\t<li>IBM RackSwitch G8124E\u00a0<\/li>\n\t<li>IBM RackSwitch G8264T\u00a0<\/li>\n\t<li>IBM RackSwitch G8316\u00a0<\/li>\n\t<li>IBM RackSwitch G8124\u00a0<\/li>\n<\/ul><p>CVE Reference: CVE-2017-3765<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.lenovo.com\/ca\/en\/product_security\/len-16095\"><font color=\"#0066cc\">https:\/\/support.lenovo.com\/ca\/en\/product_security\/len-16095<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/lenovo-security-advisory","alert_type":396,"serial_number":"AV18-010","subject":null,"moderation_state":"archived","external_url":null},{"nid":1012,"title":"Juniper Networks security bulletins","uuid":"39334887-8cf3-4e0f-945a-3b9a9fd5d1c4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-09T13:19:23Z","summary":null,"body":["<article data-history-node-id=\"1012\" about=\"\/en\/alerts-advisories\/juniper-networks-security-bulletins-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-011<br \/>\nDate: 16 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security bulletins released by Juniper Networks.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Juniper Networks has released product updates addressing vulnerabilities in Junos OS, CTPView, Junos Space, ScreenOS, Security Director and Log Collector. Successful exploitation of these vulnerabilities could result in remote arbitrary code execution, remote denial of service, and bypass of the security policy.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Junos OS versions 12.1X46 prior to 12.1X46-D71<\/li>\n\t<li>Junos OS versions 12.1X46 prior to 12.1X46-D71 on SRX<\/li>\n\t<li>Junos OS versions 12.3R12 prior to 12.3R12-S7<\/li>\n\t<li>Junos OS versions 12.3R prior to 12.3R12-S7<\/li>\n\t<li>Junos OS versions 12.3 prior to 12.3R12-S7<\/li>\n\t<li>Junos OS versions 12.3X48 versions 12.3X48-D55 and above but before 12.3X48-D65<\/li>\n\t<li>Junos OS versions 12.3X48 prior to 12.3X48-D55<\/li>\n\t<li>Junos OS versions 12.3X48 prior to 12.3X48-D55 on SRX<\/li>\n\t<li>Junos OS versions 14.1 prior to 14.1R8-S5, 14.1R9<\/li>\n\t<li>Junos OS versions 14.1 prior to 14.1R9 on MX series<\/li>\n\t<li>Junos OS versions 14.1X53 prior to 14.1X53-D40 on QFX, EX<\/li>\n\t<li>Junos OS versions 14.1X53 prior to 14.1X53-D46, 14.1X53-D50 and 14.1X53-D107<\/li>\n\t<li>Junos OS versions 14.2 prior to 14.2R7-S9, 14.2R8<\/li>\n\t<li>Junos OS versions 14.2 prior to 14.2R8<\/li>\n\t<li>Junos OS versions 14.2 prior to 14.2R8 on MX series<\/li>\n\t<li>Junos OS versions 15.1R5-S4, 15.1R5-S5 and 15.1R6<\/li>\n\t<li>Junos OS versions 15.1 prior to 15.1F2-S17, 15.1F5-S8, 15.1F6-S8, 15.1R5-S7, 15.1R7<\/li>\n\t<li>Junos OS versions 15.1 prior to 15.1F5-S8, 15.1F6-S8, 15.1R5-S6, 15.1R6-S3, 15.1R7, 15.1F6, 15.1R3<\/li>\n\t<li>Junos OS versions 15.1 prior to 15.1R5-S8, 15.1F6-S9, 15.1R6-S4, 15.1R7 on MX series<\/li>\n\t<li>Junos OS versions 15.1 prior to 15.1R6-S2, 15.1R7<\/li>\n\t<li>Junos OS versions 15.1X49 versions 15.1X49-D100 and above but before 15.1X49-D121<\/li>\n\t<li>Junos OS versions 15.1X49 prior to 15.1X49-D110 on SRX<\/li>\n\t<li>Junos OS versions 15.1X53 prior to 15.1X53-D232 on QFX5200 \/ 5110<\/li>\n\t<li>Junos OS versions 15.1X53 prior to 15.1X53-D49, 15.1X53-D470 on NFX<\/li>\n\t<li>Junos OS versions 15.1X53 prior to 15.1X53-D65 on QFX10K<\/li>\n\t<li>Junos OS versions 15.1X53 prior to 15.1X53-D70, 15.1X53-D231<\/li>\n\t<li>Junos OS versions 16.1 prior to 16.1R3-S6, 16.1R4-S6 and 16.1R5<\/li>\n\t<li>Junos OS versions 16.1 prior to 16.1R5-S1, 16.1R6<\/li>\n\t<li>Junos OS versions 16.1 prior to 16.1R6 on MX series<\/li>\n\t<li>Junos OS versions 16.1X65 prior to 16.1X65-D45<\/li>\n\t<li>Junos OS versions 16.2 prior to 16.2R2, 16.2R2-S2, 16.2R3<\/li>\n\t<li>Junos OS versions 16.2 prior to 16.2R3 on MX series<\/li>\n\t<li>Junos OS versions 17.1 prior to 17.1R2-S5, 17.1R3 and 17.1R3 on MX series<\/li>\n\t<li>Junos OS versions 17.2X75 prior to 17.2X75-D50<\/li>\n\t<li>CTPView versions 7.1, 7.2 and 7.3.<\/li>\n\t<li>Junos Space prior to 17.2R1<\/li>\n\t<li>Security Director and Log Collector prior to 17.2R1<\/li>\n\t<li>ScreenOS all versions without the latest security patch<\/li>\n<\/ul><p>CVE Reference: CVE-2015-5174, CVE-2015-5188, CVE-2015-5220, CVE-2015-5304, CVE-2015-5600, CVE-2015-6563, CVE-2015-6564, CVE-2015-7236, CVE-2015-7501, CVE-2016-2141, CVE-2016-8655, CVE-2016-8743, CVE-2016-8858, CVE-2017-1000111, CVE-2017-1000112, CVE-2017-14106, CVE-2017-2634, CVE-2017-3167, CVE-2017-3169, CVE-2017-5645, CVE-2017-5664, CVE-2017-6074, CVE-2017-7668, CVE-2017-7679, CVE-2017-9788, CVE-2017-9798, CVE-2018-0001, CVE-2018-0002, CVE-2018-0003, CVE-2018-0004, CVE-2018-0005, CVE-2018-0006, CVE-2018-0007, CVE-2018-0008, CVE-2018-0009, CVE-2018-0010, CVE-2018-0011, CVE-2018-0012, CVE-2018-0013, CVE-2018-0014<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10828&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10828&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10829&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10829&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10830&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10830&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10831&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10831&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10832&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10832&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10833&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10833&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10834&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10834&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10835&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10835&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10836&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10836&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10837&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10837&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10838&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10838&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10839&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10839&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10840&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10840&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a> \u00a0<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10841&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10841&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-bulletins-1","alert_type":396,"serial_number":"AV18-011","subject":null,"moderation_state":"archived","external_url":null},{"nid":753,"title":"Oracle Critical Patch updates","uuid":"5100a55a-b189-4570-ad5c-bbdbf378ba95","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-09T13:25:26Z","summary":null,"body":["<article data-history-node-id=\"753\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-012<br \/>\nDate: 17 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the quarterly updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update which addresses multiple new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Affected Product Versions:<\/p>\n\n<ul><li>Agile Material and Equipment Management for Pharmaceuticals, versions 9.3.3, 9.3.4\u00a0\u00a0\u00a0<\/li>\n\t<li>Application Express, versions prior to 5.1.4.00.08<\/li>\n\t<li>Converged Commerce, version 16.0.1<\/li>\n\t<li>Hyperion BI+, version 11.1.2.4<\/li>\n\t<li>Hyperion Data Relationship Management, version 11.1.2.4.330<\/li>\n\t<li>Integrated Lights Out Manager (ILOM), versions 3.x, 4.x\u00a0\u00a0\u00a0<\/li>\n\t<li>Java Advanced Management Console, version 2.8\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Java ME SDK, version 8.3\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version 9.2\u00a0\u00a0\u00a0<\/li>\n\t<li>MICROS Handheld Terminal, versions Prior to BSP 02.13.0701 (070116)\u00a0<\/li>\n\t<li>MICROS Relate CRM Software, versions 10.8.x, 11.4.x, 15.0.x\u00a0\u00a0<\/li>\n\t<li>MICROS Retail XBRi Loss Prevention, versions 10.0.1, 10.5.0, 10.6.0, 10.7.0, 10.8.0, 10.8.1<\/li>\n\t<li>MySQL Connectors, versions 5.3.9 and prior, 6.9.9 and prior, 6.10.4 and prior\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>MySQL Enterprise Monitor, versions 3.3.6.3293 and prior, 3.4.4.4226 and prior, 4.0.0.5135 and prior\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>MySQL Server, versions 5.5.58 and prior, 5.6.38 and prior, 5.7.20 and prior\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Access Manager, versions 10.1.4.3.0, 11.1.2.3.0<\/li>\n\t<li>Oracle Agile Engineering Data Management, versions 6.1.3, 6.2.0, 6.2.1<\/li>\n\t<li>Oracle Agile PLM, versions 9.3.3, 9.3.4, 9.3.5, 9.3.6\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Agile PLM MCAD Connector, versions 3.3, 3.4, 3.5, 3.6\u00a0\u00a0<\/li>\n\t<li>Oracle Argus Safety, versions 7.x, 8.0.x, 8.1\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Autovue for Agile Product Lifecycle Management, versions 21.0.0, 21.0.1\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Banking Corporate Lending, versions 12.3.0, 12.4.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Banking Payments, versions 12.3.0, 12.4.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.2.0, 12.2.1.3.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Communications Application Session Controller, version 3.x\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Communications BRM - Elastic Charging Engine, version 7.5\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Communications Convergent Charging Controller, version 6.0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Communications Network Charging and Control, version 6.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Communications Order and Service Management, versions 7.2.4.1.x, 7.2.4.2.x, 7.3.0.1.x, 7.3.0.x.x\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Communications Services Gatekeeper, versions 5.1, 6.0<\/li>\n\t<li>Oracle Communications Unified Inventory Management, versions 7.2.4.2.x, 7.3<\/li>\n\t<li>Oracle Communications User Data Repository, versions 10.x, 12.x\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Directory Server Enterprise Edition, version 11.1.1.7.0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle E-Business Suite, versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Endeca Information Discovery Integrator, versions 3.1.0, 3.2.0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Analytical Applications Infrastructure, versions 7.3.5.x, 8.0.x\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Analytical Applications Reconciliation Framework, version 8.0.x\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Asset Liability Management, versions 6.1.x, 8.0.x<\/li>\n\t<li>Oracle Financial Services Balance Sheet Planning, version 8.0.x\u00a0<\/li>\n\t<li>Oracle Financial Services Funds Transfer Pricing, versions 6.1.x, 8.0.x\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Hedge Management and IFRS Valuations, version 8.0.x<\/li>\n\t<li>Oracle Financial Services Liquidity Risk Management, version 8.0.x\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Loan Loss Forecasting and Provisioning, version 8.0.x\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Market Risk, version 8.0.x\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Market Risk Measurement and Management, version 8.0.5\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Price Creation and Discovery, version 8.0.5\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Financial Services Profitability Management, versions 6.1.x, 8.0.x\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle FLEXCUBE Direct Banking, versions 12.0.2, 12.0.3\u00a0<\/li>\n\t<li>Oracle FLEXCUBE Universal Banking, versions 11.3.0, 11.4.0, 11.5.0, 11.6.0, 11.7.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Fusion Applications, versions 11.1.2 through 11.1.9\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Fusion Middleware, versions 11.1.1.7, 11.1.1.9, 11.1.2.3, 12.1.3.0, 12.2.1.2, 12.2.1.3\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Health Sciences Empirica Inspections, version 1.0.1.1\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Health Sciences Empirica Signal, version 8.0.1.0<\/li>\n\t<li>Oracle Hospitality Cruise Dining Room Management, version 8.0.78\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Hospitality Cruise Fleet Management, version 9.0.4.0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Hospitality Cruise Shipboard Property Management System, version 7.3.874\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Hospitality Guest Access, versions 4.2.0, 4.2.1\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Hospitality Labor Management, versions 8.5.1, 9.0.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Hospitality Reporting and Analytics, versions 8.5.1, 9.0.0<\/li>\n\t<li>Oracle Hospitality Simphony, versions 2.7, 2.8, 2.9\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle HTTP Server, versions 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0, 12.2.1.3.0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Hyperion Planning, version 11.1.2.4.007<\/li>\n\t<li>Oracle Identity Manager, version 11.1.2.3.0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Identity Manager Connector, versions 9.0.4.20.6, 9.0.4.21.0, 9.0.4.25.4\u00a0<\/li>\n\t<li>Oracle Internet Directory, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.3.0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle iPlanet Web Server, version 7.0Oracle Java SE, versions 6u171, 7u161, 8u152, 9.0.1<\/li>\n\t<li>Oracle Java SE Embedded, version 8u151<\/li>\n\t<li>Oracle JDeveloper, versions 11.1.1.2.4, 11.1.1.7.0, 11.1.1.7.1, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0, 12.2.1.2.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle JRockit, version R28.3.16<\/li>\n\t<li>Oracle Mobile Security Suite, version 3.0.1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Retail Assortment Planning, versions 14.1.3, 15.0.3, 16.0.1<\/li>\n\t<li>Oracle Retail Convenience and Fuel POS Software, version 2.1.132\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Retail Customer Management and Segmentation Foundation, versions 10.8.x, 11.4.x, 15.0.x, 16.0.x\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Retail Fiscal Management, version 14.1<\/li>\n\t<li>Oracle Retail Merchandising System, version 16.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Retail Workforce Management, versions 1.60.7, 1.64.0\u00a0<\/li>\n\t<li>Oracle Secure Global Desktop (SGD), version 5.3\u00a0\u00a0<\/li>\n\t<li>Oracle Transportation Management, versions 6.2.11, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.1, 6.4.2, 6.4.3\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle Tuxedo System and Applications Monitor, version 12.1.3.0.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle VM VirtualBox, versions prior to 5.1.32, prior to 5.2.6\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle WebCenter Content, versions 11.1.1.9.0, 12.2.1.2.0, 12.2.1.3.0\u00a0<\/li>\n\t<li>Oracle WebCenter Portal, versions 11.1.1.9.0, 12.2.1.2.0, 12.2.1.3.0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle WebCenter Sites, version 11.1.1.8.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Oracle WebLogic Server, versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.2.0, 12.2.1.3.0\u00a0<\/li>\n\t<li>Oracle X86 Servers, versions SW 1.x, SW 2.x\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>OSS Support Tools, versions prior to 2.11.33\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>PeopleSoft Enterprise FIN Supply Chain Portal Pack Argentina, version 9.1\u00a0<\/li>\n\t<li>PeopleSoft Enterprise FIN Supply Chain Portal Pack Brazil, version 9.1\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>PeopleSoft Enterprise FSCM, version 9.2\u00a0<\/li>\n\t<li>PeopleSoft Enterprise HCM Human Resources, versions 9.1, 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, versions 8.54, 8.55, 8.56\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>PeopleSoft Enterprise PRTL Interaction Hub, version 9.1.00\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>PeopleSoft Enterprise SCM eProcurement, versions 9.1, 9.2\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>PeopleSoft Enterprise SCM Purchasing, version 9.2\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Primavera Unifier, versions 10.x, 15.x, 16.x, 17.x\u00a0<\/li>\n\t<li>Siebel Applications, versions 16.0, 17.0<\/li>\n\t<li>Solaris, versions 10, 11.3\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Sun ZFS Storage Appliance Kit (AK), versions prior to 8.7.13\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n<\/ul><p>CVE References: CVE-2013-2566, CVE-2014-0114, CVE-2014-7817, CVE-2014-9402, CVE-2015-0293, CVE-2015-1472, CVE-2015-2808, CVE-2015-3195, CVE-2015-3253, CVE-2015-4852, CVE-2015-7501, CVE-2015-7547, CVE-2015-7940, CVE-2016-0635, CVE-2016-0703, CVE-2016-0704, CVE-2016-0800, CVE-2016-1181, CVE-2016-1182, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-2518, CVE-2016-2550, CVE-2016-4449, CVE-2016-5385, CVE-2016-5387, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6814, CVE-2016-7052, CVE-2016-7055, CVE-2016-7977, CVE-2016-8735, CVE-2016-9878, CVE-2017-0781, CVE-2017-0782, CVE-2017-0783, CVE-2017-0785, CVE-2017-3730, CVE-2017-3731, CVE-2017-3732, CVE-2017-3733, CVE-2017-3735, CVE-2017-3736, CVE-2017-3737, CVE-2017-3738, CVE-2017-5461, CVE-2017-5645, CVE-2017-5664, CVE-2017-5715, CVE-2017-9072, CVE-2017-9798, CVE-2017-10068, CVE-2017-10262, CVE-2017-10273, CVE-2017-10282, CVE-2017-10301, CVE-2017-10352, CVE-2017-12617, CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2018-2560, CVE-2018-2561, CVE-2018-2562, CVE-2018-2564, CVE-2018-2565, CVE-2018-2566, CVE-2018-2567, CVE-2018-2568, CVE-2018-2569, CVE-2018-2570, CVE-2018-2571, CVE-2018-2573, CVE-2018-2574, CVE-2018-2575, CVE-2018-2576, CVE-2018-2577, CVE-2018-2578, CVE-2018-2579, CVE-2018-2580, CVE-2018-2581, CVE-2018-2582, CVE-2018-2583, CVE-2018-2584, CVE-2018-2585, CVE-2018-2586, CVE-2018-2588, CVE-2018-2589, CVE-2018-2590, CVE-2018-2591, CVE-2018-2592, CVE-2018-2593, CVE-2018-2594, CVE-2018-2595, CVE-2018-2596, CVE-2018-2597, CVE-2018-2599, CVE-2018-2600, CVE-2018-2601, CVE-2018-2602, CVE-2018-2603, CVE-2018-2604, CVE-2018-2605, CVE-2018-2606, CVE-2018-2607, CVE-2018-2608, CVE-2018-2609, CVE-2018-2610, CVE-2018-2611, CVE-2018-2612, CVE-2018-2613, CVE-2018-2614, CVE-2018-2615, CVE-2018-2616, CVE-2018-2617, CVE-2018-2618, CVE-2018-2619, CVE-2018-2620, CVE-2018-2621, CVE-2018-2622, CVE-2018-2623, CVE-2018-2624, CVE-2018-2625, CVE-2018-2626, CVE-2018-2627, CVE-2018-2629, CVE-2018-2630, CVE-2018-2631, CVE-2018-2632, CVE-2018-2633, CVE-2018-2634, CVE-2018-2635, CVE-2018-2636, CVE-2018-2637, CVE-2018-2638, CVE-2018-2639, CVE-2018-2640, CVE-2018-2641, CVE-2018-2642, CVE-2018-2643, CVE-2018-2644, CVE-2018-2645, CVE-2018-2646, CVE-2018-2647, CVE-2018-2648, CVE-2018-2649, CVE-2018-2650, CVE-2018-2651, CVE-2018-2652, CVE-2018-2653, CVE-2018-2654, CVE-2018-2655, CVE-2018-2656, CVE-2018-2657, CVE-2018-2658, CVE-2018-2659, CVE-2018-2660, CVE-2018-2661, CVE-2018-2662, CVE-2018-2663, CVE-2018-2664, CVE-2018-2665, CVE-2018-2666, CVE-2018-2667, CVE-2018-2668, CVE-2018-2669, CVE-2018-2670, CVE-2018-2671, CVE-2018-2672, CVE-2018-2673, CVE-2018-2674, CVE-2018-2675, CVE-2018-2676, CVE-2018-2677, CVE-2018-2678, CVE-2018-2679, CVE-2018-2680, CVE-2018-2681, CVE-2018-2682, CVE-2018-2683, CVE-2018-2684, CVE-2018-2685, CVE-2018-2686, CVE-2018-2687, CVE-2018-2688, CVE-2018-2689, CVE-2018-2690, CVE-2018-2691, CVE-2018-2692, CVE-2018-2693, CVE-2018-2694, CVE-2018-2695, CVE-2018-2696, CVE-2018-2697, CVE-2018-2698, CVE-2018-2699, CVE-2018-2700, CVE-2018-2701, CVE-2018-2702, CVE-2018-2703, CVE-2018-2704, CVE-2018-2705, CVE-2018-2706, CVE-2018-2707, CVE-2018-2708, CVE-2018-2709, CVE-2018-2710, CVE-2018-2711, CVE-2018-2712, CVE-2018-2713, CVE-2018-2714, CVE-2018-2715, CVE-2018-2716, CVE-2018-2717, CVE-2018-2719, CVE-2018-2720, CVE-2018-2721, CVE-2018-2722, CVE-2018-2723, CVE-2018-2724, CVE-2018-2725, CVE-2018-2726, CVE-2018-2727, CVE-2018-2728, CVE-2018-2729, CVE-2018-2730, CVE-2018-2731, CVE-2018-2732, CVE-2018-2733<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujan2018-3236628.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujan2018-3236628.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-updates-0","alert_type":396,"serial_number":"AV18-012","subject":null,"moderation_state":"archived","external_url":null},{"nid":831,"title":"Security Fix Released For BIND","uuid":"599f9056-93fe-44d8-85fd-17e50a54bd7d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:19Z","date_created":"2018-07-09T13:32:03Z","summary":null,"body":["<article data-history-node-id=\"831\" about=\"\/en\/alerts-advisories\/security-fix-released-bind-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-013<br \/>\nDate: 17 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security fixes for BIND. Improper sequencing during cleanup can lead to a \u201cuse-after-free\u201d error, triggering an assertion failure and crash in named.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released an update addressing vulnerabilities in BIND.<\/p>\n\n<p>Versions affected:\u00a09.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1<\/p>\n\n<p>CVE Reference: CVE-2017-3145<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01542\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01542<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-fix-released-bind-2","alert_type":396,"serial_number":"AV18-013","subject":null,"moderation_state":"archived","external_url":null},{"nid":973,"title":"Cisco security updates","uuid":"ea8d1c39-ef14-4d64-a76c-934df3973b5c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-09T13:37:38Z","summary":null,"body":["<article data-history-node-id=\"973\" about=\"\/en\/alerts-advisories\/cisco-security-updates-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-014<br \/>\nDate: 17 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco NX-OS Software Pong Packet Denial of Service Vulnerability<\/li>\n\t<li>Cisco AnyConnect Profile Editor XML External Entity Injection Vulnerability<\/li>\n\t<li>Cisco D9800 Network Transport Receiver OS Command Injection Vulnerability<\/li>\n\t<li>Cisco Elastic Services Controller Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Email Security and Content Security Management Appliance Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine DOM Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco IOS Software for Industrial Ethernet 4010 Series Switches Test Command Arbitrary Code Execution and Denial of Service Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software Management Interface Denial of Service Vulnerability<\/li>\n\t<li>Cisco NX-OS System Software Unauthorized User Account Deletion Vulnerability<\/li>\n\t<li>Cisco Policy Suite Unauthenticated Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Prime Infrastructure Open Redirect Vulnerability<\/li>\n\t<li>Cisco Prime Infrastructure Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Prime Service Catalog Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Small Business 300 and 500 Series Managed Switches Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Small Business 300 and 500 Series Managed Switches HTTP Response Splitting Vulnerability<\/li>\n\t<li>Cisco StarOS CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco UCS Central Software IPv6 Denial of Service Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Unified Customer Voice Portal Denial of Service Vulnerability<\/li>\n\t<li>Cisco WAP150 Wireless Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance Reflected Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Information Disclosure Vulnerability<\/li>\n\t<li>Cisco WebEx Meetings Server Remote Account Disabling Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2017-12307, CVE-2017-12308, CVE-2018-0086, CVE-2018-0088, CVE-2018-0089, CVE-2018-0090, CVE-2018-0091, CVE-2018-0092, CVE-2018-0093, CVE-2018-0094, CVE-2018-0095, CVE-2018-0096, CVE-2018-0097, CVE-2018-0098, CVE-2018-0099, CVE-2018-0100, CVE-2018-0102, CVE-2018-0105, CVE-2018-0106, CVE-2018-0107, CVE-2018-0108, CVE-2018-0109, CVE-2018-0110, CVE-2018-0111, CVE-2018-0115<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-nx-os\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-nx-os<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-esasma\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-esasma<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-cvp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-cvp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wsa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wsa1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wms<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wap\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-wap<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ucs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ucs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-staros\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-staros<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-psc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-psc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-prime-infrastructure\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-prime-infrastructure<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-nxos1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-nxos1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-nxos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-nxos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ntr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ntr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-ise<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-iess\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-iess<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-esc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-esc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-cps\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-cps<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-cpi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-cpi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-acpe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-acpe<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-300-500-smb2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-300-500-smb2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-300-500-smb1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180117-300-500-smb1<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-10","alert_type":396,"serial_number":"AV18-014","subject":null,"moderation_state":"archived","external_url":null},{"nid":867,"title":"WordPress security update","uuid":"966f60ae-108a-44cf-8982-f41b4160f05c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-09T13:43:58Z","summary":null,"body":["<article data-history-node-id=\"867\" about=\"\/en\/alerts-advisories\/wordpress-security-update-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-015<br \/>\nDate: 22 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.9.2 that contains fixes to address a critical cross-site scripting (XSS) vulnerability.<\/p>\n\n<p>Versions affected: WordPress 4.9.1 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2018\/01\/wordpress-4-9-2-security-and-maintenance-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2018\/01\/wordpress-4-9-2-security-and-maintenance-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-5","alert_type":396,"serial_number":"AV18-015","subject":null,"moderation_state":"archived","external_url":null},{"nid":982,"title":"Apple security updates","uuid":"9d12b2c8-d4ee-413d-a84f-33a73807dc60","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-09T13:51:22Z","summary":null,"body":["<article data-history-node-id=\"982\" about=\"\/en\/alerts-advisories\/apple-security-updates-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-016<br \/>\nDate: 24 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apple system security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released a support article regarding security vulnerabilities in their products Safari, macOS High Sierra, iOS, tvOS and watchOS.<\/p>\n\n<ul><li>Safari 11.0.3<\/li>\n\t<li>watchOS 4.2.2<\/li>\n\t<li>iOS 11.2.5<\/li>\n\t<li>macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan<\/li>\n\t<li>tvOS 11.2.5<\/li>\n<\/ul><p>CVE Reference: CVE-2017-5754, CVE-2017-8817, CVE-2018-4082, CVE-2018-4084, CVE-2018-4085, CVE-2018-4086, CVE-2018-4087, CVE-2018-4088, CVE-2018-4089, CVE-2018-4090, CVE-2018-4091, CVE-2018-4092, CVE-2018-4093, CVE-2018-4094, CVE-2018-4095, CVE-2018-4096, CVE-2018-4097, CVE-2018-4098, CVE-2018-4100<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-us\/HT208475\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208475<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208464\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208464<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208463\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208463<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208465\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208465<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208462\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208462<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-8","alert_type":396,"serial_number":"AV18-016","subject":null,"moderation_state":"archived","external_url":null},{"nid":1025,"title":"Mozilla security updates","uuid":"cd46d330-70c0-4421-aba1-efe9d82c5b3d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-09T13:58:14Z","summary":null,"body":["<article data-history-node-id=\"1025\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-017<br \/>\nDate: 24 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Mozilla Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla have released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Versions:<br \/>\n\u2022 Firefox ESR versions prior to 52.6\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n\u2022 Firefox versions prior to 58<\/p>\n\n<p>CVE References: CVE-2018-5089, CVE-2018-5090, CVE-2018-5091, CVE-2018-5093, CVE-2018-5094, CVE-2018-5095, CVE-2018-5096, CVE-2018-5097, CVE-2018-5098, CVE-2018-5099, CVE-2018-5101, CVE-2018-5102, CVE-2018-5103, CVE-2018-5104, CVE-2018-5105, CVE-2018-5106, CVE-2018-5107, CVE-2018-5108, CVE-2018-5109, CVE-2018-5110, CVE-2018-5111, CVE-2018-5112, CVE-2018-5113, CVE-2018-5114, CVE-2018-5115, CVE-2018-5116, CVE-2018-5117, CVE-2018-5118, CVE-2018-5119, CVE-2018-5121, CVE-2018-5122<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-03\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-03\/<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-02\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-02\/<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-5","alert_type":396,"serial_number":"AV18-017","subject":null,"moderation_state":"archived","external_url":null},{"nid":1229,"title":"Google Releases security update for Chrome","uuid":"2003d75a-0dc5-4f0c-870f-a33c3206da40","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-09T14:28:55Z","summary":null,"body":["<article data-history-node-id=\"1229\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-31\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-018<br \/>\nDate: 25 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 64.0.3282.119 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2018-6031, CVE-2018-6032, CVE-2018-6033, CVE-2018-6034, CVE-2018-6035, CVE-2018-6036, CVE-2018-6037, CVE-2018-6038, CVE-2018-6039, CVE-2018-6040, CVE-2018-6041, CVE-2018-6042, CVE-2018-6043, CVE-2018-6045, CVE-2018-6046, CVE-2018-6047, CVE-2018-6048, CVE-2017-15420, CVE-2018-6049, CVE-2018-6050, CVE-2018-6051, CVE-2018-6052, CVE-2018-6053, CVE-2018-6054.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-31","alert_type":396,"serial_number":"AV18-018","subject":null,"moderation_state":"archived","external_url":null},{"nid":1250,"title":"VMware security advisory","uuid":"17b20d03-c823-42df-9835-0d6d47529f9d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-09T14:36:13Z","summary":null,"body":["<article data-history-node-id=\"1250\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-019<br \/>\nDate: 29 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing multiple security vulnerabilities in VMware products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>vRealize Automation<\/li>\n\t<li>vSphere Integrated Containers<\/li>\n\t<li>AirWatch Console<\/li>\n<\/ul><p>CVE References: CVE-2017-4947, CVE-2017-4951<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0006.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0006.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-7","alert_type":396,"serial_number":"AV18-019","subject":null,"moderation_state":"archived","external_url":null},{"nid":847,"title":"Microsoft security update \u2013 Out-of-Band","uuid":"f63d6318-56f3-4d86-af0d-5fedb124be44","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-09T14:40:54Z","summary":null,"body":["<article data-history-node-id=\"847\" about=\"\/en\/alerts-advisories\/microsoft-security-update-out-band\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-020<br \/>\nDate: 29 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Microsoft Security Update to Disable Mitigation against Spectre, Variant 2.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The summary covers an out-of-band support package deployment addressing issues with recently released microcode meant to address Spectre vulnerability variant 2.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Windows 7 Service Pack 1<\/li>\n\t<li>Windows 8.1<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 10 Version 1511<\/li>\n\t<li>Windows 10 Version 1607<\/li>\n\t<li>Windows 10 Version 1703<\/li>\n\t<li>Windows 10 version 1709<\/li>\n\t<li>Windows Server 2008 R2 Standard<\/li>\n\t<li>Windows Server 2012 R2 Standard<\/li>\n<\/ul><p>CVE References: CVE-2017-5715<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4078130\/update-to-disable-mitigation-against-spectre-variant-2\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4078130\/update-to-disable-mitigation-against-spectre-variant-2<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-update-out-band","alert_type":396,"serial_number":"AV18-020","subject":null,"moderation_state":"archived","external_url":null},{"nid":989,"title":"Cisco security advisory","uuid":"85faee81-ce94-41e0-bdb4-ed54851c508d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-07-09T14:45:47Z","summary":null,"body":["<article data-history-node-id=\"989\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-021<br \/>\nDate: 29 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Cisco security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released a security advisory to address vulnerabilities in the following products.<\/p>\n\n<ul><li>3000 Series Industrial Security Appliance (ISA)\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>ASA 5500 Series Adaptive Security Appliances\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>ASA 5500-X Series Next-Generation Firewalls\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>ASA 1000V Cloud Firewall\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Adaptive Security Virtual Appliance (ASAv)\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Firepower 2100 Series Security Appliance\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Firepower 4110 Security Appliance \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Firepower 9300 ASA Security Module\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Firepower Threat Defense Software (FTD)\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n<\/ul><p>CVE References: CVE-2018-0101<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180129-asa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180129-asa1<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-3","alert_type":396,"serial_number":"AV18-021","subject":null,"moderation_state":"archived","external_url":null},{"nid":1055,"title":"Joomla! security update","uuid":"49f63344-0712-42aa-adff-3f23365507ac","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-09T14:50:21Z","summary":null,"body":["<article data-history-node-id=\"1055\" about=\"\/en\/alerts-advisories\/joomla-security-update-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-022<br \/>\nDate: 30 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.8.4 of its web content management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected: Joomla! 3.8.3 and earlier.<\/p>\n\n<p>CVE References: CVE-2018-6376, CVE18-6377, CVE18-6379, CVE-2018-6380<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5723-joomla-3-8-4-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5723-joomla-3-8-4-release.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update-4","alert_type":396,"serial_number":"AV18-022","subject":null,"moderation_state":"archived","external_url":null},{"nid":791,"title":"[Control systems] PHOENIX CONTACT mGuard security update","uuid":"b5a7c8dd-b355-45e7-8681-c95dcda9edda","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-09T14:55:09Z","summary":null,"body":["<article data-history-node-id=\"791\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-mguard-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-023<br \/>\nDate: 31 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a PHOENIX CONTACT security update for mGuard.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>PHOENIX CONTACT released a security updates for mGuard to address an improper validation of integrity check value. Successful exploitation of this vulnerability could allow for a malicious actor to modify firmware update packages.<\/p>\n\n<p>Affected products:<\/p>\n\n<p>- mGuard firmware versions 7.2 to 8.6.0<\/p>\n\n<p>CVE Reference: CVE-2018-5441<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. For more information, please refer to the ICS-CERT references.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-030-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-030-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-mguard-security-update","alert_type":398,"serial_number":"AV18-023","subject":null,"moderation_state":"archived","external_url":null},{"nid":1287,"title":"Cisco security advisory","uuid":"7e6673dd-22e9-40a6-aa5f-cc493d61c7c3","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-09T15:00:20Z","summary":null,"body":["<article data-history-node-id=\"1287\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-024<br \/>\nDate: 31 January 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published Cisco security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has released a security advisory to address vulnerabilities in the following products.<\/p>\n\n<p>Cisco Aggregation Services Router (ASR) 9000 running<\/p>\n\n<ul><li>Cisco IOS XR Software Release 5.3.4<\/li>\n\t<li>Trident-based line cards with IPv6 configured\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n<\/ul><p>CVE References: CVE-2018-0136<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180131-ipv6\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180131-ipv6<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-4","alert_type":396,"serial_number":"AV18-024","subject":null,"moderation_state":"archived","external_url":null},{"nid":962,"title":"Cisco security advisory","uuid":"a81c30e9-ab80-4ec4-9659-a869443603c1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-09T15:17:42Z","summary":null,"body":["<article data-history-node-id=\"962\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-025<br \/>\nDate: 5 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently updated Cisco security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has modified a security advisory to address a critical vulnerability in Cisco Adaptive Security Appliance (ASA) Software that could allow an unauthenticated remote attacker to cause a reload of the affected system and\/or to remotely execute code.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>3000 Series Industrial Security Appliance (ISA)<\/li>\n\t<li>ASA 5500 Series Adaptive Security Appliances<\/li>\n\t<li>ASA 5500-X Series Next-Generation Firewalls<\/li>\n\t<li>ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers<\/li>\n\t<li>ASA 1000V Cloud Firewall<\/li>\n\t<li>Adaptive Security Virtual Appliance (ASAv)<\/li>\n\t<li>Firepower 2100 Series Security Appliance<\/li>\n\t<li>Firepower 4110 Security Appliance<\/li>\n\t<li>Firepower 4120 Security Appliance<\/li>\n\t<li>Firepower 4140 Security Appliance<\/li>\n\t<li>Firepower 4150 Security Appliance<\/li>\n\t<li>Firepower 9300 ASA Security Module<\/li>\n\t<li>Firepower Threat Defense Software (FTD)<\/li>\n\t<li>FTD Virtual<\/li>\n<\/ul><p>CVE References: CVE-2018-0101<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180129-asa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180129-asa1<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-5","alert_type":396,"serial_number":"AV18-025","subject":null,"moderation_state":"archived","external_url":null},{"nid":952,"title":"Adobe security bulletin","uuid":"a39e4ed7-a514-4080-9569-c81689578a4d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-09T15:22:55Z","summary":null,"body":["<article data-history-node-id=\"952\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-026<br \/>\nDate: 6 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published Adobe security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released an update that fixes a vulnerability in Flash Player. A remote user could exploit this vulnerability and cause the execution of arbitrary code.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<p>- Adobe Flash Player Desktop Runtime 28.0.0.137 and earlier<br \/>\n- Adobe Flash Player for Google Chrome 28.0.0.137 and earlier<br \/>\n- Adobe Flash Player for Microsoft Edge and Internet Explorer 11 28.0.0.137 and earlier<\/p>\n\n<p>CVE References: CVE-2018-4877, CVE-2018-4878<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-03.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-03.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-0","alert_type":396,"serial_number":"AV18-026","subject":null,"moderation_state":"archived","external_url":null},{"nid":1004,"title":"Cisco security advisory","uuid":"d13854b6-d081-467b-a4e1-c4674b53f0e2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-09T15:28:03Z","summary":null,"body":["<article data-history-node-id=\"1004\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-027<br \/>\nDate: 7 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published Cisco security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has released a security advisory to address vulnerabilities found in multiple products.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers<\/li>\n\t<li>Cisco Virtualized Packet Core-Distributed Instance<\/li>\n\t<li>Cisco UCS Central<\/li>\n\t<li>Cisco Policy Suite RADIUS<\/li>\n\t<li>Cisco Unified Communications Manager<\/li>\n\t<li>Cisco Spark<\/li>\n\t<li>Cisco IOS XR Software<\/li>\n\t<li>Cisco IOS and IOS XE Software Diagnostic Shell<\/li>\n\t<li>Cisco Firepower System Software BitTorrent File Policy<\/li>\n\t<li>Cisco Email Security Appliance and Cisco Content Security Management Appliance Spam Quarantine<\/li>\n\t<li>Cisco Data Center Analytics Framework<\/li>\n\t<li>Cisco Unified Communications Manager<\/li>\n\t<li>Cisco Policy Suite<\/li>\n\t<li>Cisco Prime Network<\/li>\n\t<li>Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers<\/li>\n\t<li>Cisco RV132W and RV134W Wireless VPN Routers<\/li>\n<\/ul><p>CVE References:\u00a0 CVE-2018-0125, CVE-2018-0117, CVE-2018-0113, CVE-2018-0116, CVE-2018-0198, CVE-2018-0135, CVE-2018-0119, CVE-2018-0127, CVE-2018-0132, CVE-2018-0123, CVE-2018-0138, CVE-2018-0140, CVE-2018-0129, CVE-2018-0128, CVE-2018-0120, CVE-2018-0134, CVE-2018-0137, CVE-2018-0122<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-rv13x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-rv13x<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-vpcdi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-vpcdi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ucsc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ucsc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cps\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cps<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ucm1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ucm1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-spark\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-spark<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-iosxr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-iosxr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ios\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-ios<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-fss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-fss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-esacsm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-esacsm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-dcaf1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-dcaf1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-dcaf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-dcaf<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cps1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cps1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cpn\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-cpn<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-asr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-asr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-rv13x_2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180207-rv13x_2<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-6","alert_type":396,"serial_number":"AV18-027","subject":null,"moderation_state":"archived","external_url":null},{"nid":754,"title":"WordPress security update","uuid":"464cf9c2-1db0-4c87-8724-5742a752b867","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-09T15:33:32Z","summary":null,"body":["<article data-history-node-id=\"754\" about=\"\/en\/alerts-advisories\/wordpress-security-update-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-028<br \/>\nDate: 08 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.9.4 that fixes a severe bug in 4.9.3, which will cause sites that support automatic background updates to fail to update automatically, and will require action from you (or your host) for it to be updated to 4.9.4.<\/p>\n\n<p>Versions affected: WordPress 4.9.3 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2018\/02\/wordpress-4-9-4-maintenance-release\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2018\/02\/wordpress-4-9-4-maintenance-release<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-6","alert_type":null,"serial_number":"AV18-028","subject":null,"moderation_state":"archived","external_url":null},{"nid":838,"title":"NETGEAR security advisory","uuid":"5c526956-97b3-4d29-8764-682673b64a16","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-07-09T15:38:48Z","summary":null,"body":["<article data-history-node-id=\"838\" about=\"\/en\/alerts-advisories\/netgear-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-029<br \/>\nDate: 09 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published NETGEAR security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>NETGEAR has released a security advisory to address a vulnerability found in routers affected by a remote authentication bypass that could be exploited by a remote user\u00a0 to access target networks without having to provide a password.<\/p>\n\n<p>Affected Products:<\/p>\n\n<p>- D8500 running firmware versions 1.0.3.27 and earlier<br \/>\n- DGN2200v4 running firmware versions 1.0.0.82 and earlier<br \/>\n- R6300v2 running firmware versions 1.0.4.06 and earlier<br \/>\n- R6400 running firmware versions 1.0.1.20 and earlier<br \/>\n- R6400v2 running firmware versions 1.0.2.18 and earlier<br \/>\n- R6700 running firmware versions 1.0.1.22 and earlier<br \/>\n- R6900 running firmware versions 1.0.1.20 and earlier<br \/>\n- R7000 running firmware versions 1.0.7.10 and earlier<br \/>\n- R7000P running firmware versions 1.0.0.58 and earlier<br \/>\n- R7100LG running firmware versions 1.0.0.28 and earlier<br \/>\n- R7300DST running firmware versions 1.0.0.52 and earlier<br \/>\n- R7900 running firmware versions 1.0.1.12 and earlier<br \/>\n- R8000 running firmware versions 1.0.3.46 and earlier<br \/>\n- R8300 running firmware versions 1.0.2.86 and earlier<br \/>\n- R8500 running firmware versions 1.0.2.86 and earlier<br \/>\n- WNDR3400v3 running firmware versions 1.0.1.8 and earlier<br \/>\n- WNDR4500v2 running firmware versions 1.0.0.62 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/kb.netgear.com\/000045848\/Security-Advisory-for-Password-Recovery-and-File-Access-on-Some-Routers-and-Modem-Routers-PSV-2017-0677\"><font color=\"#0066cc\">https:\/\/kb.NETGEAR.com\/000045848\/Security-Advisory-for-Password-Recovery-and-File-Access-on-Some-Routers-and-Modem-Routers-PSV-2017-0677<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/netgear-security-advisory","alert_type":396,"serial_number":"AV18-029","subject":null,"moderation_state":"archived","external_url":null},{"nid":975,"title":"Microsoft security updates","uuid":"e28c096b-afb3-4ab1-9dfa-f28c263a7f12","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-09T15:44:52Z","summary":null,"body":["<article data-history-node-id=\"975\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-030<br \/>\nDate: 13 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>Internet Explorer<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Windows<\/li>\n\t<li>Microsoft Office and Microsoft Office Services and Web Apps<\/li>\n\t<li>ChakraCore<\/li>\n\t<li>Adobe Flash<\/li>\n<\/ul><p>CVE References: CVE-2018-0742, CVE-2018-0755, CVE-2018-0756, CVE-2018-0757, CVE-2018-0760, CVE-2018-0761, CVE-2018-0763, CVE-2018-0771, CVE-2018-0809, CVE-2018-0810, CVE-2018-0820, CVE-2018-0821, CVE-2018-0822, CVE-2018-0823, CVE-2018-0825, CVE-2018-0826, CVE-2018-0827, CVE-2018-0828, CVE-2018-0829, CVE-2018-0830, CVE-2018-0831, CVE-2018-0832, CVE-2018-0840, CVE-2018-0841, CVE-2018-0842, CVE-2018-0843, CVE-2018-0844, CVE-2018-0846, CVE-2018-0847, CVE-2018-0860, CVE-2018-0861, CVE-2018-0864, CVE-2018-0866, CVE-2018-0869<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-8","alert_type":396,"serial_number":"AV18-030","subject":null,"moderation_state":"archived","external_url":null},{"nid":869,"title":"Adobe security bulletins","uuid":"f0282717-e18e-4f70-b8e1-cf81abc922f6","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-09T15:50:56Z","summary":null,"body":["<article data-history-node-id=\"869\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-031<br \/>\nDate: 13 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for Adobe Acrobat and Reader. These updates address critical vulnerabilities that could lead to code execution. Furthermore, Adobe has released security updates for Adobe Experience Manager. These updates resolve a reflected cross-site scripting vulnerability rated moderate, and a cross-site scripting vulnerability in Apache Sling.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Acrobat DC (Continuous Track) version 2018.009.20050 and earlier (Windows and Macintosh)<\/li>\n\t<li>Acrobat Reader DC (Continuous Track) version 2018.009.20050 and earlier (Windows and Macintosh)<\/li>\n\t<li>Acrobat 2017 version 2017.011.30070 and earlier (Windows and Macintosh)<\/li>\n\t<li>Acrobat Reader 2017 version 2017.011.30070 and earlier (Windows and Macintosh)<\/li>\n\t<li>Acrobat DC (Classic Track) version 2015.006.30394 and earlier (Windows and Macintosh)<\/li>\n\t<li>Acrobat Reader DC (Classic Track) version 2015.006.30394 and earlier (Windows and Macintosh)<\/li>\n\t<li>Adobe Experience Manager versions 6.3, 6.2, 6.1, 6.0<\/li>\n<\/ul><p>CVE References: CVE-2018-4872, CVE-2018-4875, CVE-2018-4876, CVE-2018-4879, CVE-2018-4880, CVE-2018-4888, CVE-2018-4890, CVE-2018-4904, CVE-2018-4907, CVE-2018-4910, CVE-2018-4881, CVE-2018-4882, CVE-2018-4883, CVE-2018-4884, CVE-2018-4885, CVE-2018-4886, CVE-2018-4887, CVE-2018-4889, CVE-2018-4891, CVE-2018-4892, CVE-2018-4893, CVE-2018-4894, CVE-2018-4895, CVE-2018-4896, CVE-2018-4897, CVE-2018-4898, CVE-2018-4899, CVE-2018-4900, CVE-2018-4901, CVE-2018-4902, CVE-2018-4903, CVE-2018-4905, CVE-2018-4906<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-02.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-02.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-04.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-04.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins","alert_type":396,"serial_number":"AV18-031","subject":null,"moderation_state":"archived","external_url":null},{"nid":983,"title":"Cisco security advisory","uuid":"2bb4971b-69b7-4141-8037-8ce1ae6aafde","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-09T16:51:40Z","summary":null,"body":["<article data-history-node-id=\"983\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-032<br \/>\nDate: 22 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in the following products.<\/p>\n\n<ul><li>Cisco Unified Communications Domain Manager Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco Elastic Services Controller Service Portal Authentication Bypass Vulnerability<\/li>\n\t<li>Cisco Elastic Services Controller Service Portal Unauthorized Access Vulnerability<\/li>\n\t<li>Cisco Unified Customer Voice Portal Interactive Voice Response Connection Denial of Service Vulnerability<\/li>\n\t<li>Cisco UCS Director and Cisco Integrated Management Controller Supervisor Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Reflected Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Prime Service Catalog Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Tool User Provisioning Tab Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Tool Web Portal Repeated Bad Login Attempts Denial of Service Vulnerability<\/li>\n\t<li>Cisco Jabber Client Framework for Windows and Mac Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Jabber Client Framework for Windows and Mac Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Data Center Analytics Framework Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Data Center Analytics Framework Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unity Connection Mail Relay Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2018-0121, CVE-2018-0124, CVE-2018-0130, CVE-2018-0139, CVE-2018-0145, CVE-2018-0146, CVE-2018-0148, CVE-2018-0199, CVE-2018-0200, CVE-2018-0201, CVE-2018-0203, CVE-2018-0204, CVE-2018-0205, CVE-2018-0206<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-ucsd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-ucsd<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-ucdm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-ucdm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-ucm<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-psc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-psc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-pcpt\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-pcpt<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-pcpt1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-pcpt1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-jcf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-jcf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-jcf1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-jcf1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-esc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-esc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-esc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-esc1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-dcaf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-dcaf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-dcaf1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-dcaf1<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-cvp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-cvp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-cuc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180221-cuc<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-7","alert_type":396,"serial_number":"AV18-032","subject":null,"moderation_state":"archived","external_url":null},{"nid":1033,"title":"Drupal security advisory","uuid":"ac5bde70-e0bf-4dc4-b865-38d326a3d38e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-09T17:00:11Z","summary":null,"body":["<article data-history-node-id=\"1033\" about=\"\/en\/alerts-advisories\/drupal-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-033<br \/>\nDate: 22 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Drupal security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple security vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to bypass certain security restrictions and perform unauthorized actions.<\/p>\n\n<p>Affected Versions:<br \/>\n- Drupal 7.x versions prior to 7.57<br \/>\n- Drupal 8.x versions prior to 8.4.5<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2018-001\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/sa-core-2018-001<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory","alert_type":396,"serial_number":"AV18-033","subject":null,"moderation_state":"archived","external_url":null},{"nid":1231,"title":"Intel security update","uuid":"13bb0c66-686b-4bc1-8e5b-6118e255051c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-09T17:06:47Z","summary":null,"body":["<article data-history-node-id=\"1231\" about=\"\/en\/alerts-advisories\/intel-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-034<br \/>\nDate: 22 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published security update by Intel.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Intel has released a security update to address vulnerabilities in Intel-based platforms with microprocessors utilizing speculative execution and indirect branch prediction which may allow unauthorized disclosure of information to a user with local user access via a side-channel analysis.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>Intel\u00ae Core\u2122 i3 processor (45nm and 32nm)<\/li>\n\t<li>Intel\u00ae Core\u2122 i5 processor (45nm and 32nm)<\/li>\n\t<li>Intel\u00ae Core\u2122 i7 processor (45nm and 32nm)<\/li>\n\t<li>Intel\u00ae Core\u2122 M processor family (45nm and 32nm)<\/li>\n\t<li>2nd generation Intel\u00ae Core\u2122 processors<\/li>\n\t<li>3rd generation Intel\u00ae Core\u2122 processors<\/li>\n\t<li>4th generation Intel\u00ae Core\u2122 processors<\/li>\n\t<li>5th generation Intel\u00ae Core\u2122 processors<\/li>\n\t<li>6th generation Intel\u00ae Core\u2122 processors<\/li>\n\t<li>7th generation Intel\u00ae Core\u2122 processors<\/li>\n\t<li>8th generation Intel\u00ae Core\u2122 processors<\/li>\n\t<li>Intel\u00ae Core\u2122 X-series Processor Family for Intel\u00ae X99 platforms<\/li>\n\t<li>Intel\u00ae Core\u2122 X-series Processor Family for Intel\u00ae X299 platforms<\/li>\n\t<li>Intel\u00ae Xeon\u00ae processor 3400 series<\/li>\n\t<li>Intel\u00ae Xeon\u00ae processor 3600 series<\/li>\n\t<li>Intel\u00ae Xeon\u00ae processor 5500 series<\/li>\n\t<li>Intel\u00ae Xeon\u00ae processor 5600 series<\/li>\n\t<li>Intel\u00ae Xeon\u00ae processor 6500 series<\/li>\n\t<li>Intel\u00ae Xeon\u00ae processor 7500 series<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E3 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E3 v2 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E3 v3 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E3 v4 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E3 v5 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E3 v6 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E5 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E5 v2 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E5 v3 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E5 v4 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E7 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E7 v2 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E7 v3 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor E7 v4 Family<\/li>\n\t<li>Intel\u00ae Xeon\u00ae Processor Scalable Family<\/li>\n\t<li>Intel\u00ae Xeon Phi\u2122 Processor 3200, 5200, 7200 Series<\/li>\n\t<li>Intel\u00ae Atom\u2122 Processor C Series<\/li>\n\t<li>Intel\u00ae Atom\u2122 Processor E Series<\/li>\n\t<li>Intel\u00ae Atom\u2122 Processor A Series<\/li>\n\t<li>Intel\u00ae Atom\u2122 Processor x3 Series<\/li>\n\t<li>Intel\u00ae Atom\u2122 Processor Z Series<\/li>\n\t<li>Intel\u00ae Celeron\u00ae Processor J Series<\/li>\n\t<li>Intel\u00ae Celeron\u00ae Processor N Series<\/li>\n\t<li>Intel\u00ae Pentium\u00ae Processor J Series<\/li>\n\t<li>Intel\u00ae Pentium\u00ae Processor N Series<\/li>\n<\/ul><p>CVE References: CVE-2017-5715, CVE-2017-5753, CVE-2017-5754<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00088&amp;languageid=en-fr\"><font color=\"#0066cc\">https:\/\/security-center.intel.com\/advisory.aspx?intelid=INTEL-SA-00088&amp;languageid=en-fr<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-update","alert_type":396,"serial_number":"AV18-034","subject":null,"moderation_state":"archived","external_url":null},{"nid":1343,"title":"Trend Micro security bulletin","uuid":"a9776d20-e663-4ddc-9ed5-95d1d0c0486a","banner":null,"lang":"en","date_modified":"2018-09-29","date_modified_ts":"2018-09-29T13:43:08Z","date_created":"2018-07-09T17:30:15Z","summary":null,"body":["<article data-history-node-id=\"1343\" about=\"\/en\/alerts-advisories\/trend-micro-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-035<br \/>\nDate: 23 February 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Trend Micro security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Trend Micro has released a security bulletin to address multiple vulnerabilities in their Email Encryption Gateway 5.5. Exploitation of these vulnerabilities could allow a remote unauthenticated user to gain permission as root on the device.<\/p>\n\n<p>Affected versions;<br \/>\nEmail Encryption Gateway Version 5.5 Build 1111 and below<\/p>\n\n<p>CVE References: CVE-2018-6219, CVE-2018-6220, CVE-2018-6221, CVE-2018-6222, CVE-2018-6223, CVE-2018-6224 , CVE-2018-6225, CVE-2018-6226, CVE-2018-6227, CVE-2018-6228, CVE-2018-6229, CVE-2018-6230<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/success.trendmicro.com\/solution\/1119349-security-bulletin-trend-micro-email-encryption-gateway-5-5-multiple-vulnerabilities\/\"><font color=\"#0066cc\">https:\/\/success.trendmicro.com\/solution\/1119349-security-bulletin-trend-micro-email-encryption-gateway-5-5-multiple-vulnerabilities\/<\/font><\/a><\/p>\n\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6219\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6219<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6220\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6220<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6221\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6221<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6222\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6222<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6223\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6223<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6225\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6225<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6226\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6226<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6227\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6227<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6228\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6228<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6229\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-6229<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-bulletin","alert_type":396,"serial_number":"AV18-035","subject":null,"moderation_state":"archived","external_url":null},{"nid":848,"title":"Moxa OnCell security update","uuid":"2c995926-67df-4963-b3e1-329a61956b72","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-09T17:36:40Z","summary":null,"body":["<article data-history-node-id=\"848\" about=\"\/en\/alerts-advisories\/moxa-oncell-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-036<br \/>\nDate: 01 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Moxa OnCell security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Moxa has released a security bulletin to address multiple vulnerabilities in their OnCell G3100-HSPA Series. \u00a0Exploitation of this vulnerability may allow for remote code execution.<\/p>\n\n<p>Affected versions:<br \/>\nOnCell G3100-HSPA Series version 1.4 Build 16062919 and prior.<\/p>\n\n<p>CVE References: CVE-2018-5455, CVE-2018-5453, CVE-2018-5449<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-060-02\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-060-02<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moxa-oncell-security-update","alert_type":396,"serial_number":"AV18-036","subject":null,"moderation_state":"archived","external_url":null},{"nid":991,"title":"Pivotal Spring security update","uuid":"4a85795f-fa75-42ca-af79-2b8f30bf4ed8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-07-09T17:41:28Z","summary":null,"body":["<article data-history-node-id=\"991\" about=\"\/en\/alerts-advisories\/pivotal-spring-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-037<br \/>\nDate: 06 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Pivotal Spring Security Update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Pivotal Spring has released updates to address security vulnerabilities in various Spring web application products. Exploitation of these vulnerabilities may allow execution of arbitrary commands on web applications built using Spring Data REST.<\/p>\n\n<p>Affected Versions:<br \/>\n- Spring Data REST versions prior to 2.5.12, 2.6.7, 3.0 RC3<br \/>\n- Spring Boot versions prior to 2.0.0M4<br \/>\n- Spring Data release trains prior to Kay-RC3<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/pivotal.io\/security\/cve-2017-8046%0dhttps:\/lgtm.com\/blog\/spring_data_rest_CVE-2017-8046\"><font color=\"#0066cc\">https:\/\/pivotal.io\/security\/cve-2017-8046<\/font><\/a><br \/><a href=\"https:\/\/pivotal.io\/security\/cve-2017-8046%0dhttps:\/lgtm.com\/blog\/spring_data_rest_CVE-2017-8046\"><font color=\"#0066cc\">https:\/\/lgtm.com\/blog\/spring_data_rest_CVE-2017-8046<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/pivotal-spring-security-update","alert_type":396,"serial_number":"AV18-037","subject":null,"moderation_state":"archived","external_url":null},{"nid":1057,"title":"Exim security advisory","uuid":"97862ee9-3127-4904-a22b-e5f6dfe15a57","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-09T17:46:47Z","summary":null,"body":["<article data-history-node-id=\"1057\" about=\"\/en\/alerts-advisories\/exim-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-038<br \/>\nDate: 07 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory for Exim.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Exim has released a security advisory to address vulnerability in the SMTP listener before version 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>All Exim versions below 4.90.1<\/li>\n<\/ul><p>CVE Reference: CVE-2018-6789<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.exim.org\/\"><font color=\"#0066cc\">https:\/\/www.exim.org\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/devco.re\/blog\/2018\/03\/06\/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en\/\"><font color=\"#0066cc\">https:\/\/devco.re\/blog\/2018\/03\/06\/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-6789\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-6789<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory","alert_type":396,"serial_number":"AV18-038","subject":null,"moderation_state":"archived","external_url":null},{"nid":793,"title":"Google Releases security update for Chrome","uuid":"3005ad48-f438-4a32-9fb3-710b7baa5d70","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-09T17:52:33Z","summary":null,"body":["<article data-history-node-id=\"793\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-32\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-039<br \/>\nDate: 7 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 65.0.3325.146 for Windows, Mac, and Linux.<\/p>\n\n<p>CVE References: CVE-2017-11215, CVE-2017-11225, CVE-2018-6057, CVE-2018-6060, CVE-2018-6061, CVE-2018-6062, CVE-2018-6063, CVE-2018-6064, CVE-2018-6065, CVE-2018-6066, CVE-2018-6067, CVE-2018-6068, CVE-2018-6069, CVE-2018-6070, CVE-2018-6071, CVE-2018-6072, CVE-2018-6073, CVE-2018-6074, CVE-2018-6075, CVE-2018-6076, CVE-2018-6077, CVE-2018-6078, CVE-2018-6079, CVE-2018-6080, CVE-2018-6081, CVE-2018-6082, CVE-2018-6083<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2018\/03\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2018\/03\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-32","alert_type":396,"serial_number":"AV18-039","subject":null,"moderation_state":"archived","external_url":null},{"nid":1288,"title":"Cisco security advisory","uuid":"7ba1e81b-c5ba-4054-a948-cc724fd3f818","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-09T17:58:02Z","summary":null,"body":["<article data-history-node-id=\"1288\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-040<br \/>\nDate: 8 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<ul><li>Cisco Prime Collaboration Provisioning Hard Coded Password Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Secure Access Control System Java Deserialization Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Web Security Appliance FTP Authentication Bypass Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Videoscape AnyRes Live Cross Site Scripting Vulnerability\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco UCS Director Cross Site Scripting Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco StarOS CLI Command Injection Vulnerability \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Security Manager DesktopServlet Reflected Cross Site Scripting Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Registered Envelope Service Cross Site Scripting Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Prime Data Center Network Manager Cross Site Scripting Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Identity Services Engine Command Injection to Underlying Operating System Vulnerability\u00a0<\/li>\n\t<li>Cisco Identity Services Engine Cross Site Request Forgery Vulnerability \u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Identity Services Engine Local Command Injection Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Identity Services Engine Cross Site Scripting Vulnerability\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Identity Services Engine Authenticated CLI Denial of Service Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Data Center Network Manager Cross Site Request Forgery Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco Secure Access Control Server XML External Entity Injection Vulnerability \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Cisco 550X Series Stackable Managed Switches SNMP Denial of Service Vulnerability\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n<\/ul><p>CVE References: CVE 2018 0087, CVE 2018 0141, CVE 2018 0144, CVE 2018 0147, CVE 2018 0207, CVE 2018 0208, CVE 2018 0209, CVE 2018 0210, CVE 2018 0211, CVE 2018 0212, CVE 2018 0213, CVE 2018 0214, CVE 2018 0215, CVE 2018 0216, CVE 2018 0217, CVE 2018 0218, CVE 2018 0219, CVE 2018 0220, CVE 2018 0221, CVE 2018 0223, CVE 2018 0224\u00a0\u00a0<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-cpcp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-cpcp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-acs2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-acs2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-wsa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-wsa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-val\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-val<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ucs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ucs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-staros1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-staros1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-staros\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-staros<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-sm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-sm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-res\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-res<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-pdcnm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-pdcnm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise6\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise6<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise5\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise5<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise4<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-ise<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-dcnm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-dcnm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-acs1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-acs1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-acs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-acs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-550x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180307-550x<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-8","alert_type":396,"serial_number":"AV18-040","subject":null,"moderation_state":"archived","external_url":null},{"nid":963,"title":"Samba security updates","uuid":"66611215-568a-4f55-968e-fb5149b20caa","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-09T18:03:55Z","summary":null,"body":["<article data-history-node-id=\"963\" about=\"\/en\/alerts-advisories\/samba-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-041<br \/>\nDate: 13 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent Samba security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Samba has released updates to address multiple security vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to bypass certain security restrictions and perform unauthorized actions. Such actions may include modifying passwords from other users and causing denial of service.<\/p>\n\n<p>Affected Versions:<br \/>\n- Samba 4.7.5 and prior versions<br \/>\n- Samba 4.6.13 and prior versions<br \/>\n- Samba 4.5.15 and prior versions<\/p>\n\n<p>CVE References: CVE-2018-1050 and CVE-2018-1057<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-1050.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-1050.html<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-1057.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-1057.html<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/www.samba.org\/samba\/history\/samba-4.7.6.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/history\/samba-4.7.6.html<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/www.samba.org\/samba\/history\/samba-4.6.14.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/history\/samba-4.6.14.html <\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/www.samba.org\/samba\/history\/samba-4.5.16.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/history\/samba-4.5.16.html<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-updates-0","alert_type":396,"serial_number":"AV18-041","subject":null,"moderation_state":"archived","external_url":null},{"nid":944,"title":"Microsoft security updates","uuid":"9e7633d1-040d-4651-ab9a-ea45b4be4bb1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-09T18:10:41Z","summary":null,"body":["<article data-history-node-id=\"944\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-042<br \/>\nDate: 13 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<p>- Internet Explorer<br \/>\n- Microsoft Edge<br \/>\n- Microsoft Windows<br \/>\n- Microsoft Office and Microsoft Office Services and Web Apps<br \/>\n- Microsoft Exchange Server<br \/>\n- ASP.NET Core<br \/>\n- NET Core<br \/>\n- PowerShell Core<br \/>\n- ChakraCore<br \/>\n- Adobe Flash<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-9","alert_type":396,"serial_number":"AV18-042","subject":null,"moderation_state":"archived","external_url":null},{"nid":1005,"title":"Adobe security bulletins","uuid":"b47992e2-a542-4439-9a57-75c3dee5ccab","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-09T18:16:58Z","summary":null,"body":["<article data-history-node-id=\"1005\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-043<br \/>\nDate: 14 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for Adobe Flash Player, Connect and Dreamweaver CC.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Flash Player Desktop Runtime for Windows and Macintosh, versions 28.0.0.161 and earlier<\/li>\n\t<li>Flash Player Desktop Runtime for Linux, versions 28.0.0.161 and earlier<\/li>\n\t<li>Flash Player for Chrome, versions 28.0.0.161 and earlier<\/li>\n\t<li>Flash Player for Edge and Internet Explorer 11, versions 28.0.0.161 and earlier<\/li>\n\t<li>Connect, versions 9.7 and earlier<\/li>\n\t<li>Dreamweaver CC, versions 18.0 and earlier<\/li>\n<\/ul><p>CVE References: CVE-2018-4919, CVE-2018-4920, CVE-2018-4921, CVE-2018-4923, CVE-2018-4924<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-05.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-05.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb18-06.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb18-06.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/dreamweaver\/apsb18-07.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/dreamweaver\/apsb18-07.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-0","alert_type":396,"serial_number":"AV18-043","subject":null,"moderation_state":"archived","external_url":null},{"nid":756,"title":"Mozilla security updates","uuid":"02f80cd1-7197-4655-8b10-60930249bb34","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-09T18:22:23Z","summary":null,"body":["<article data-history-node-id=\"756\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-044<br \/>\nDate: 14 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Mozilla Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Versions:<br \/>\n\u2022 Firefox ESR versions prior to 52.7\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n\u2022 Firefox versions prior to 59<\/p>\n\n<p>CVE References: CVE-2018-5125, CVE-2018-5126, CVE-2018-5127, CVE-2018-5128, CVE-2018-5129, CVE-2018-5130, CVE-2018-5131, CVE-2018-5132, CVE-2018-5133, CVE-2018-5134, CVE-2018-5135, CVE-2018-5136, CVE-2018-5137, CVE-2018-5138, CVE-2018-5140, CVE-2018-5141, CVE-2018-5142, CVE-2018-5143, CVE-2018-5144, CVE-2018-5145<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-06\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-06\/<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-07\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-07\/<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-6","alert_type":396,"serial_number":"AV18-044","subject":null,"moderation_state":"archived","external_url":null},{"nid":840,"title":"[Control systems] Siemens SIMATIC, SIMOTION and SINUMERIK Vulnerabilities","uuid":"96e6af4e-3c62-42ef-af14-55cc05929ffd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-07-09T18:28:46Z","summary":null,"body":["<article data-history-node-id=\"840\" about=\"\/en\/alerts-advisories\/control-systems-siemens-simatic-simotion-and-sinumerik-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-045<br \/>\nDate: 15 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently disclosed vulnerabilities in Siemens SIMATIC, SIMOTION and SINUMERIK products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Multiple vulnerabilities were identified in Siemens SIMATIC, SIMOTION and SINUMERIK products. Exploitation of these vulnerabilities could allow a user to remotely execute arbitrary code, elevate privileges, gain unauthenticated access to sensitive data, abuse cryptographic functions and cause a denial of service under certain conditions.<\/p>\n\n<p>Affected Products:<\/p>\n\n<p>Siemens reports that the vulnerabilities affect the following Industrial PCs and BIOS versions:<br \/>\n-SIMATIC Field-PG M3: ME prior to V6.2.61.3535,<br \/>\n-SIMATIC Field-PG M4: BIOS prior to V18.01.06,<br \/>\n-SIMATIC Field-PG M5: BIOS prior to V22.01.04,<br \/>\n-SIMATIC HMI IPC677C: ME prior to V6.2.61.3535,<br \/>\n-SIMATIC IPC427D: BIOS prior to V17.0?.10,<br \/>\n-SIMATIC IPC427E: BIOS prior to V21.01.07,<br \/>\n-SIMATIC IPC477D: BIOS prior to V17.0?.10,<br \/>\n-SIMATIC IPC477D PRO: BIOS prior to V17.0?.10,<br \/>\n-SIMATIC IPC477E: BIOS prior to V21.01.07,<br \/>\n-SIMATIC IPC547D: ME prior to V7.1.91.3272,<br \/>\n-SIMATIC IPC547E: ME prior to V9.1.41.3024,<br \/>\n-SIMATIC IPC547G: ME prior to V11.8.50.3425 and BIOS &lt; R1.21.0,<br \/>\n-SIMATIC IPC627C: ME prior to V6.2.61.3535,<br \/>\n-SIMATIC IPC627D: ME prior to V9.1.41.3024,<br \/>\n-SIMATIC IPC647C: ME prior to V6.2.61.3535,<br \/>\n-SIMATIC IPC647D: ME prior to V9.1.41.3024,<br \/>\n-SIMATIC IPC677D: ME prior to V9.1.41.3024,<br \/>\n-SIMATIC IPC827C: ME prior to V6.2.61.3535,<br \/>\n-SIMATIC IPC827D: ME prior to V9.1.41.3024,<br \/>\n-SIMATIC IPC847C: ME prior to V6.2.61.3535,<br \/>\n-SIMATIC IPC847D: ME prior to V9.1.41.3024,<br \/>\n-SIMATIC ITP1000: BIOS prior to V23.01.03,<br \/>\n-SINUMERIK PCU50.5-C, WIN7: ME prior to V6.2.61.3535,<br \/>\n-SINUMERIK PCU50.5-C, WINXP: ME prior to V6.2.61.3535,<br \/>\n-SINUMERIK PCU50.5-P, WIN7: ME prior to V6.2.61.3535,<br \/>\n-SINUMERIK PCU50.5-P, WINXP: ME prior to V6.2.61.3535, and<br \/>\n-SIMOTION P320-4S: BIOS &lt; S17.02.06.83.1<\/p>\n\n<p>Siemens reports that the vulnerability affects the following versions of SIMATIC Industrial PCs using a version of Infineon\u2019s Trusted Platform Module (TPM):<br \/>\n-SIMATIC Field-PG M5 all versions prior to v22.01.04,<br \/>\n-SIMATIC IPC227E all versions prior to v20.01.10,<br \/>\n-SIMATIC IPC277E all versions prior to v20.01.10,<br \/>\n-SIMATIC IPC427E all versions prior to v21.01.07,<br \/>\n-SIMATIC IPC477E all versions prior to v21.01.07,<br \/>\n-SIMATIC IPC547G all versions, and<br \/>\n-SIMATIC ITP1000 all versions prior to v23.01.03<\/p>\n\n<p>Siemens reports that the vulnerabilities affect the following versions of SIMATIC WinCC Add-On:<br \/>\n-SIMATIC WinCC Add-On Historian CONNECT ALARM all versions prior to and including v5.x,<br \/>\n-SIMATIC WinCC Add-On PI CONNECT ALARM all versions prior to and including v2.x,<br \/>\n-SIMATIC WinCC Add-On PI CONNECT AUDIT TRAIL all versions prior to and including v1.x,<br \/>\n-SIMATIC WinCC Add-On PM-AGENT all versions prior to and including v5.x,<br \/>\n-SIMATIC WinCC Add-On PM-ANALYZE all versions prior to and including v7.x,<br \/>\n-SIMATIC WinCC Add-On PM-CONTROL all versions prior to and including v10.x,<br \/>\n-SIMATIC WinCC Add-On PM-MAINT all versions prior to and including v9.x,<br \/>\n-SIMATIC WinCC Add-On PM-OPEN EXPORT all versions prior to and including v7.x,<br \/>\n-SIMATIC WinCC Add-On PM-OPEN HOST-S all versions prior to and including v7.x,<br \/>\n-SIMATIC WinCC Add-On PM-OPEN IMPORT all versions prior to and including v6.x,<br \/>\n-SIMATIC WinCC Add-On PM-OPEN PI all versions prior to and including v7.x,<br \/>\n-SIMATIC WinCC Add-On PM-OPEN PV02 all versions prior to and including v1.x,<br \/>\n-SIMATIC WinCC Add-On PM-OPEN TCP\/IP all versions prior to and including v8.x,<br \/>\n-SIMATIC WinCC Add-On PM-QUALITY all versions prior to and including v9.x,<br \/>\n-SIMATIC WinCC Add-On SICEMENT IT MIS all versions prior to and including v7.x, and<br \/>\n-SIMATIC WinCC Add-On SIPAPER IT MIS all versions prior to and including v7.x<\/p>\n\n<p>Siemens reports the vulnerability affects the following industrial products:<br \/>\n-SIMATIC S7-200 Smart: All versions prior to V2.03.01,<br \/>\n-SIMATIC S7-400 PN V6: All versions prior to V6.0.6,<br \/>\n-SIMATIC S7-400 H V6: All versions prior to V6.0.8,<br \/>\n-SIMATIC S7-400 PN\/DP V7: All versions prior to V7.0.2,<br \/>\n-SIMATIC S7-410 V8: All versions,<br \/>\n-SIMATIC S7-300: All versions,<br \/>\n-SIMATIC S7-1200: All versions,<br \/>\n-SIMATIC S7-1500: All versions prior to V2.0,<br \/>\n-SIMATIC S7-1500 Software Controller: All versions prior to V2.0,<br \/>\n-SIMATIC WinAC RTX 2010 incl. F: All versions,<br \/>\n-SIMATIC ET 200 Interface modules for PROFINET IO:-SIMATIC ET 200AL: All versions,<br \/>\n-SIMATIC ET 200ecoPN: All versions,<br \/>\n-SIMATIC ET 200M: All versions,<br \/>\n-SIMATIC ET 200MP IM155-5 PN BA: All versions prior to V4.0.2,<br \/>\n-SIMATIC ET 200MP IM155-5 PN ST: All versions prior to V4.1,<br \/>\n-SIMATIC ET 200MP (except IM155-5 PN BA and IM155-5 PN ST): All versions,<br \/>\n-SIMATIC ET 200pro: All versions,<br \/>\n-SIMATIC ET 200S: All versions, and<br \/>\n-SIMATIC ET 200SP: All versions.<\/p>\n\n<p>-Development\/Evaluation Kits for PROFINET IO:-DK Standard Ethernet Controller: All versions prior to V4.1.1 Patch 05,<br \/>\n-EK-ERTEC 200P: All versions prior to V4.5, and<br \/>\n-EK-ERTEC 200 PN IO: All versions prior to V4.5<\/p>\n\n<p>-SIMOTION Firmware:-SIMOTION D: All versions prior to V5.1 HF1,<br \/>\n-SIMOTION C: All versions prior to V5.1 HF1,<br \/>\n-SIMOTION P V4.4 and V4.5: All versions prior to V4.5 HF5, and<br \/>\n-SIMOTION P V5: All versions prior to V5.1 HF1<\/p>\n\n<p>-SINAMICS:-SINAMICS DCM: All versions,<br \/>\n-SINAMICS DCP: All versions,<br \/>\n-SINAMICS G110M \/ G120(C\/P\/D) w. PN: All versions prior to V4.7 SP9 HF1,<br \/>\n-SINAMICS G130 and G150 w. PN: All versions,<br \/>\n-SINAMICS S110 w. PN: All versions prior to V4.4 SP3 HF6,<br \/>\n-SINAMICS S120 w. PN: All versions prior to V4.8 HF5,<br \/>\n-SINAMICS S150 w. PN:-V4.7: All versions, and<br \/>\n-V4.8: All versions.<\/p>\n\n<p>-SINAMICS V90 w. PN: All versions prior to V1.02<\/p>\n\n<p>-SINUMERIK 840D sl: All versions,<br \/>\n-SIMATIC Compact Field Unit: All versions,<br \/>\n-SIMATIC PN\/PN Coupler: All versions,<br \/>\n-SIMOCODE pro V PROFINET: All versions, and<br \/>\n-SIRIUS Soft starter 3RW44 PN: All versions.<\/p>\n\n<p>CVE References: CVE-2017-5705, CVE-2017-5706, CVE-2017-5707, CVE-2017-5708, CVE-2017-5709, CVE-2017-5710, CVE-2017-5711, CVE-2017-5712, CVE-2017-15361, CVE-2017-12741<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<ul><li>Download software and updates strictly from trusted sources using authenticated access and cryptographically verify the integrity of the downloaded content.<\/li>\n\t<li>Apply industrial control systems (ICS) patches in consultation with the vendor.<\/li>\n\t<li>Evaluate patches and updates in a test environment in order to assess the risks of deployment.<\/li>\n\t<li>Use a dedicated patch manager and an anti-virus server which is located in the ICS DMZ.<\/li>\n\t<li>Mitigate residual vulnerabilities that could be exploited by an intruder with additional safeguards.<\/li>\n\t<li>Keep your antivirus signatures and engines up-to-date.<\/li>\n\t<li>Minimize network exposure for all control system devices. Control system devices must not directly face the Internet.<\/li>\n\t<li>If remote access is required, use a secure method such as a Virtual Private Network (VPN), implement strong authentication, control the access and monitor your logs.<\/li>\n\t<li>Ensure that your firewall is blocking outbound traffic and has the minimum number of ports opened.<\/li>\n\t<li>Isolate your ICS devices from the business network with proper firewall rules. If data flows are necessary, consider data diodes or unidirectional gateways.<\/li>\n\t<li>Update your incident response plans to include cyber security scenarios. Be prepared to respond. Exercise your plans regularly.<\/li>\n<\/ul><p>Please also reference the mitigation advice specific to your product and situation.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-060-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-060-01<\/font><\/a><br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-058-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-058-01<\/font><\/a><br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-018-01A\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-018-01A<\/font><\/a><br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-339-01D\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-17-339-01D<\/font><\/a><br \/><a href=\"https:\/\/www.siemens.com\/global\/en\/home\/products\/services\/cert.html\"><font color=\"#0066cc\">https:\/\/www.siemens.com\/global\/en\/home\/products\/services\/cert.html<\/font><\/a><\/p>\n\n<p>CCIRC Industrial Control System (ICS) Cyber Security: Recommended Best Practices<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2012\/tr12-002-eng.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2012\/tr12-002-eng.aspx<\/font><\/a><\/p>\n\n<p>Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies<\/p>\n\n<p><a href=\"https:\/\/ics-cert.us-cert.gov\/sites\/default\/files\/recommended_practices\/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/sites\/default\/files\/recommended_practices\/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-simatic-simotion-and-sinumerik-vulnerabilities","alert_type":398,"serial_number":"AV18-045","subject":null,"moderation_state":"archived","external_url":null},{"nid":977,"title":"Joomla! security update","uuid":"85602f01-f344-45ab-96e5-8dc3497983ff","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-09T18:34:45Z","summary":null,"body":["<article data-history-node-id=\"977\" about=\"\/en\/alerts-advisories\/joomla-security-update-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-046<br \/>\nDate: 15 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.8.6 \u00a0of its web content management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected:<\/p>\n\n<ul><li>Joomla! 3.8.5 and earlier.<\/li>\n<\/ul><p>CVE References: \u00a0CVE-2018-8045<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5725-joomla-3-8-6-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5725-joomla-3-8-6-release.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update-5","alert_type":null,"serial_number":"AV18-046","subject":null,"moderation_state":"archived","external_url":null},{"nid":870,"title":"VMware security advisory","uuid":"3445ded4-44bd-4d84-bbe3-e7b366644fda","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-09T18:43:36Z","summary":null,"body":["<article data-history-node-id=\"870\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-047<br \/>\nDate: 16 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing multiple security vulnerabilities for VMware Workstation and Fusion.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware Workstation Pro \/ Player<\/li>\n\t<li>VMware Fusion Pro \/ Fusion<\/li>\n<\/ul><p>CVE Reference: CVE-2018-6957<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0008.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0008.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-8","alert_type":396,"serial_number":"AV18-047","subject":null,"moderation_state":"archived","external_url":null},{"nid":984,"title":"Mozilla security updates","uuid":"0f2c644f-2b75-472d-8ff7-56840aecac68","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-09T18:48:58Z","summary":null,"body":["<article data-history-node-id=\"984\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-048<br \/>\nDate: 20 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Mozilla security updates addressing multiple vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Firefox versions prior to 59.0.1<\/li>\n\t<li>Firefox ESR versions prior to 52.7.2<\/li>\n<\/ul><p>CVE Reference: CVE-2018-5146, CVE-2018-5147<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-08\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-08\/<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-5146\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-5146<\/font><\/a><br \/><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-5147\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-5147<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-7","alert_type":396,"serial_number":"AV18-048","subject":null,"moderation_state":"archived","external_url":null},{"nid":1034,"title":"Citrix security updates","uuid":"1c7e1301-3a4a-43ee-a293-717278a296fd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-09T18:55:48Z","summary":null,"body":["<article data-history-node-id=\"1034\" about=\"\/en\/alerts-advisories\/citrix-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-049<br \/>\nDate: 22 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Citrix security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Citrix has released security updates to address vulnerabilities in its XenServer. A remote user could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>Affected Version:<\/p>\n\n<ul><li>XenServer 7.3<\/li>\n\t<li>XenServer 7.2<\/li>\n\t<li>XenServer 7.1 LTSR Cumulative Update 1<\/li>\n\t<li>XenServer 7.0\u00a0<\/li>\n<\/ul><p>CVE References: CVE-2016-2074, CVE-2018-7540, CVE-2018-7541<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX232655\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX232655<\/font><\/a><br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX233368\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX233368<\/font><\/a><br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX233366\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX233366<\/font><\/a><br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX233363\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX233363<\/font><\/a><br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX233365\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX233365<\/font><\/a><br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX233362\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX233362<\/font><\/a><br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX233364\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX233364<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-updates-2","alert_type":396,"serial_number":"AV18-049","subject":null,"moderation_state":"archived","external_url":null},{"nid":1232,"title":"Mozilla security updates","uuid":"bf79fffa-98ef-4222-9d01-3d4c59236f96","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-09T19:01:07Z","summary":null,"body":["<article data-history-node-id=\"1232\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-050<br \/>\nDate: 27 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Mozilla security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla has released security updates to address the \u201cUse-after-free in compositor\u201d vulnerability in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Firefox versions prior to 59.0.2<\/li>\n\t<li>Firefox ESR versions prior to 52.7.3<\/li>\n<\/ul><p>CVE Reference: CVE-2018-5148<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-10\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-10\/<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-5148\"><font color=\"#0066cc\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-5148<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-8","alert_type":396,"serial_number":"AV18-050","subject":null,"moderation_state":"archived","external_url":null},{"nid":1251,"title":"OpenSSL security updates","uuid":"da6bd8a6-cb16-48b3-8576-7943b4a0ff37","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-09T19:06:51Z","summary":null,"body":["<article data-history-node-id=\"1251\" about=\"\/en\/alerts-advisories\/openssl-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-051<br \/>\nDate: 28 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recent OpenSSL security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>OpenSSL has released security updates that affect vulnerabilities in the following products:<\/p>\n\n<p>Affected versions:\u00a0<br \/>\nOpenSSL version 1.1.0<br \/>\nOpenSSL version 1.0.2<\/p>\n\n<p>CVE Reference: CVE-2018-0733, CVE-2017-3738, CVE-2018-0739<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p>OpenSSL 1.1.0 users should upgrade to 1.1.0h<br \/>\nOpenSSL 1.0.2 users should upgrade to 1.0.2o<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20180327.txt\"><font color=\"#0066cc\">https:\/\/www.openssl.org\/news\/secadv\/20180327.txt<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-updates","alert_type":null,"serial_number":"AV18-051","subject":null,"moderation_state":"archived","external_url":null},{"nid":850,"title":"Cisco security updates","uuid":"f007ae5c-2ee6-496f-adf5-7bccb2a27d18","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-09T19:14:29Z","summary":null,"body":["<article data-history-node-id=\"850\" about=\"\/en\/alerts-advisories\/cisco-security-updates-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-052<br \/>\nDate: 28 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<p>-Cisco IOS XE Software Static Credential Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Quality of Service Remote Code Execution Vulnerability<br \/>\n-Cisco IOS XE Software Web UI Remote Access Privilege Escalation Vulnerability<br \/>\n-Cisco IOS XE Software Simple Network Management Protocol Double-Free Denial of Service Vulnerability<br \/>\n-Cisco IOS Software Simple Network Management Protocol GET MIB Object ID Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability<br \/>\n-Cisco IOS XE Software User EXEC Mode Root Shell Access Vulnerabilities<br \/>\n-Cisco IOS XE Software with Cisco Umbrella Integration Denial of Service Vulnerability<br \/>\n-Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities<br \/>\n-Cisco IOS XE Software for Cisco Catalyst Switches IPv4 Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Internet Key Exchange Version 1 Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Internet Key Exchange Memory Leak Vulnerability<br \/>\n-Cisco IOS XE Software Internet Group Management Protocol Memory Leak Vulnerability<br \/>\n-Cisco IOS XE Software Zone-Based Firewall IP Fragmentation Denial of Service Vulnerability<br \/>\n-Cisco IOS Software Integrated Services Module for VPN Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software DHCP Version 4 Relay Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software DHCP Version 4 Relay Reply Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software DHCP Version 4 Relay Heap Overflow Denial of Service Vulnerability<br \/>\n-Cisco IOS and IOS XE Software Bidirectional Forwarding Detection Denial of Service Vulnerability<br \/>\n-Cisco IOS XE Software Arbitrary File Write Vulnerability<br \/>\n-Cisco IOS XE Software Web UI Cross-Site Scripting Vulnerabilities<br \/>\n-Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities<br \/>\n-Cisco IOS XE Software Switch Integrated Security Features IPv6 Denial of Service Vulnerability<br \/>\n-Cisco IOS XE Software REST API Authorization Bypass Vulnerability<br \/>\n-Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers Privileged EXEC Mode Root Shell Access Vulnerability<br \/>\n-Cisco IOS XE Software Privileged EXEC Mode Root Shell Access Vulnerability<br \/>\n-Cisco IOS Software 802.1x Multiple-Authentication Port Authentication Bypass Vulnerability<br \/>\n-Cisco IOS XE Software CLI Command Injection Vulnerabilities<br \/>\n-Cisco IOS and IOS XE Software Forwarding Information Base Denial of Service Vulnerability<\/p>\n\n<p>CVE References: \u00a0CVE-2018-0150, CVE-2018-0151, CVE-2018-0152, CVE-2018-0154, CVE-2018-0155, CVE-2018-0156, CVE-2018-0157, CVE-2018-0158, CVE-2018-0159, CVE-2018-0160, CVE-2018-0161, CVE-2018-0163, CVE-2018-0164, CVE-2018-0165, CVE-2018-0167, CVE-2018-0169, CVE-2018-0170, CVE-2018-0171, CVE-2018-0172, CVE-2018-0173, CVE-2018-0174, CVE-2018-0175, CVE-2018-0176, CVE-2018-0177, CVE-2018-0179, CVE-2018-0180, CVE-2018-0182, CVE-2018-0183, CVE-2018-0184, CVE-2018-0185, CVE-2018-0186, CVE-2018-0188, CVE-2018-0189, CVE-2018-0190, CVE-2018-0193, CVE-2018-0195, CVE-2018-0196<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-xesc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-xesc<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-smi2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-smi2<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-qos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-qos<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-xepriv\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-xepriv<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-snmp-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-snmp-dos<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-snmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-snmp<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-smi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-smi<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-privesc1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-privesc1<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-opendns-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-opendns-dos<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-lldp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-lldp<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-ipv4\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-ipv4<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-ike-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-ike-dos<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-ike\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-ike<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-igmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-igmp<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-fwip\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-fwip<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dos<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dhcpr3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dhcpr3<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dhcpr2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dhcpr2<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dhcpr1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dhcpr1<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-bfd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-bfd<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-wfw\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-wfw<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-webuixss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-webuixss<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-slogin\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-slogin<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-sisf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-sisf<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-rest\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-rest<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-privesc3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-privesc3<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-privesc2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-privesc2<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dot1x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-dot1x<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-cmdinj\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-cmdinj<\/font><\/a><\/p>\n\t<\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-FIB-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-FIB-dos<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-11","alert_type":396,"serial_number":"AV18-052","subject":null,"moderation_state":"archived","external_url":null},{"nid":993,"title":"PHP security updates","uuid":"8933fc30-3808-4135-8725-5011ad31decb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-07-09T19:22:55Z","summary":null,"body":["<article data-history-node-id=\"993\" about=\"\/en\/alerts-advisories\/php-security-updates-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-053<br \/>\nDate: 29 March 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple PHP security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>PHP has released multiple security updates covering various vulnerabilities.\u00a0<\/p>\n\n<p>Versions affected:<br \/>\nPHP 7.0.x versions 7.0.28 and earlier<\/p>\n\n<p>PHP 7.2.x versions 7.2.3 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends organizations consult with vendors for confirmation on whether their products and\/or service providers are utilizing vulnerable versions of PHP.\u00a0 As vendor-released updates become available, organizations should test and deploy updates to affected applications\/platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"http:\/\/www.php.net\/ChangeLog-7.php#7.2.4\"><font color=\"#0066cc\">http:\/\/www.php.net\/ChangeLog-7.php#7.2.4<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"http:\/\/www.php.net\/ChangeLog-7.php#7.0.29\"><font color=\"#0066cc\">http:\/\/www.php.net\/ChangeLog-7.php#7.0.29<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-updates-2","alert_type":396,"serial_number":"AV18-053","subject":null,"moderation_state":"archived","external_url":null},{"nid":1128,"title":"Microsoft security update \u2013 Out-of-Band","uuid":"0472423f-5813-470f-97b9-5066c2cf9d0d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-09T19:28:11Z","summary":null,"body":["<article data-history-node-id=\"1128\" about=\"\/en\/alerts-advisories\/microsoft-security-update-out-band-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-054<br \/>\nDate: 30 March 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Microsoft Security Update to which addresses failure to protect kernel memory when the Microsoft patch for the vulnerability known as Meltdown is installed.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory addresses the vulnerability by correcting how the Windows kernel handles objects in memory in various Microsoft products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Windows 7 for x64-based Systems Service Pack 1<\/li>\n\t<li>Windows Server 2008 R2 for x64-based Systems Service Pack 1<\/li>\n\t<li>Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)<\/li>\n<\/ul><p>CVE References: CVE-2018-1038<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-1038\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-1038<\/font><\/a><br \/><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/277400\"><font color=\"#0066cc\">https:\/\/www.kb.cert.org\/vuls\/id\/277400<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-update-out-band-0","alert_type":396,"serial_number":"AV18-054","subject":null,"moderation_state":"archived","external_url":null},{"nid":799,"title":"Apple security updates","uuid":"50212251-7662-499b-9685-9f17a91d71cd","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-09T19:33:59Z","summary":null,"body":["<article data-history-node-id=\"799\" about=\"\/en\/alerts-advisories\/apple-security-updates-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-055<br \/>\nDate: 03 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to Apple system security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released security updates for vulnerabilities in various Apple products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>iOS 11.3<\/li>\n\t<li>macOS El Capitan,<\/li>\n\t<li>macOS Sierra,<\/li>\n\t<li>macOS High Sierra, versions previous to 10.13.4<\/li>\n\t<li>iCloud pour Windows, versions previous to 7.4<\/li>\n\t<li>Safari 11.1<\/li>\n\t<li>Xcode, versions previous to 9.3<\/li>\n<\/ul><p>CVE Reference: CVE-2017-13890, CVE-2017-8816, CVE-2018-4101, CVE-2018-4102,CVE-2018-4104, CVE-2018-4105, CVE-2018-4106, CVE-2018-4107, CVE-2018-4108, CVE-2018-4110, CVE-2018-4111, CVE-2018-4112, CVE-2018-4113, CVE-2018-4114, CVE-2018-4115, CVE-2018-4116, CVE-2018-4117, CVE-2018-4118, CVE-2018-4119, CVE-2018-4120, CVE-2018-4121, CVE-2018-4122, CVE-2018-4123, CVE-2018-4125, CVE-2018-4127, CVE-2018-4128, CVE-2018-4129, CVE-2018-4130, CVE-2018-4131, CVE-2018-4132, CVE-2018-4133, CVE-2018-4134, CVE-2018-4135, CVE-2018-4137, CVE-2018-4138, CVE-2018-4139, CVE-2018-4140, CVE-2018-4142, CVE-2018-4143, CVE-2018-4144, CVE-2018-4146, CVE-2018-4148, CVE-2018-4149, CVE-2018-4150, CVE-2018-4151, CVE-2018-4152, CVE-2018-4154, CVE-2018-4155, CVE-2018-4156, CVE-2018-4157, CVE-2018-4158, CVE-2018-4160, CVE-2018-4161, CVE-2018-4162, CVE-2018-4163, CVE-2018-4164, CVE-2018-4165, CVE-2018-4166, CVE-2018-4167, CVE-2018-4168, CVE-2018-4170, CVE-2018-4172, CVE-2018-4174, CVE-2018-4175, CVE-2018-4176<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT201222<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-9","alert_type":396,"serial_number":"AV18-055","subject":null,"moderation_state":"archived","external_url":null},{"nid":1281,"title":"Microsoft security update \u2013 Out-of-Band","uuid":"953dd090-7ad5-44bc-9174-dac440ddca3c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:05Z","date_created":"2018-07-10T12:50:24Z","summary":null,"body":["<article data-history-node-id=\"1281\" about=\"\/en\/alerts-advisories\/microsoft-security-update-out-band-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-056<br \/>\nDate: 4 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Microsoft Security Update which addresses failure to properly scan a specially crafted file, leading to memory corruption and remote code execution in the Microsoft Malware Protection Engine.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory addresses the vulnerability by correcting how the Microsoft Malware Protection Engine scans specially crafted files.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Microsoft Exchange Server 2013 and 2016<\/li>\n\t<li>Microsoft Forefront Endpoint Protection 2010<\/li>\n\t<li>Microsoft Security Essentials<\/li>\n\t<li>Windows Defender<\/li>\n\t<li>Windows Intune Endpoint Protection<\/li>\n<\/ul><p>CVE References: CVE-2018-0986<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>No action is required as the Microsoft Malware Protection Engine as a built-in and automatic updates feature. Update should be applied within forty-eight (48) hours of release by vendor.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-0986\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-0986<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-update-out-band-1","alert_type":396,"serial_number":"AV18-056","subject":null,"moderation_state":"archived","external_url":null},{"nid":957,"title":"Android security bulletin \u2013 March 2018","uuid":"4feaf0b6-899d-424b-8159-46c9d2f4fb38","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-10T12:55:54Z","summary":null,"body":["<article data-history-node-id=\"957\" about=\"\/en\/alerts-advisories\/android-security-bulletin-march-2018\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-057<br \/>\nDate: 06 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for March 2018.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for multiple vulnerabilities. Successful exploitation could result in remote code execution.<\/p>\n\n<p>CVE References: CVE-2016-10393, CVE-2017-13248, CVE-2017-13249, CVE-2017-13250, CVE-2017-13251, CVE-2017-13252, CVE-2017-13253, CVE-2017-14878, CVE-2017-14882, CVE-2017-14885, CVE-2017-15815, CVE-2017-15821, CVE-2017-16525, CVE-2017-16529, CVE-2017-16530, CVE-2017-16531, CVE-2017-16533, CVE-2017-16535, CVE-2017-17773, CVE-2017-18056, CVE-2017-18063, CVE-2017-18064, CVE-2017-18067, CVE-2017-18068, CVE-2017-18069, CVE-2017-6281, CVE-2017-6286<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2018-03-01\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2018-03-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-march-2018","alert_type":396,"serial_number":"AV18-057","subject":null,"moderation_state":"archived","external_url":null},{"nid":946,"title":"NVIDIA security updates","uuid":"01e000e7-ea6d-4e9a-962d-d187d1520d75","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-10T13:00:27Z","summary":null,"body":["<article data-history-node-id=\"946\" about=\"\/en\/alerts-advisories\/nvidia-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-058<br \/>\nDate: 06 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple NVIDIA security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>NVIDIA has released multiple security updates covering vulnerabilities which may lead to denial of service, possible escalation of privileges or potential code execution.<\/p>\n\n<p>Software Products Affected:<\/p>\n\n<ul><li>GeForce (Windows)<\/li>\n\t<li>Quadro (Windows, Linux)<\/li>\n\t<li>NVS (Windows, FreeBSD)<\/li>\n\t<li>Tesla (Windows, Solaris)<\/li>\n<\/ul><p>CVE References: CVE-2018-6247, CVE-2018-6248, CVE-2018-6249, CVE-2018-6250, CVE-2018-6251, CVE-2018-6252, CVE-2018-6253<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4649\"><font color=\"#0066cc\">http:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4649<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-updates","alert_type":396,"serial_number":"AV18-058","subject":null,"moderation_state":"archived","external_url":null},{"nid":1007,"title":"Microsoft security updates","uuid":"2bbbb3d1-d613-4b5b-811f-ad4f6a71c925","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-10T13:05:46Z","summary":null,"body":["<article data-history-node-id=\"1007\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-059<br \/>\nDate: 10 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Products Affected:<br \/>\n- Internet Explorer<br \/>\n-Microsoft Edge<br \/>\n-Microsoft Windows<br \/>\n-Microsoft Office and Microsoft Office Services and Web Apps<br \/>\n-ChakraCore<br \/>\n-Adobe Flash Player<br \/>\n-Microsoft Malware Protection Engine<br \/>\n-Microsoft Visual Studio<br \/>\n-Microsoft Azure IoT SDK<\/p>\n\n<p>CVE References: ADV180007, CVE-2018-0870, CVE-2018-0887, CVE-2018-0890, CVE-2018-0892, CVE-2018-0920, CVE-2018-0950, CVE-2018-0956, CVE-2018-0957, CVE-2018-0960, CVE-2018-0963, CVE-2018-0964, CVE-2018-0966, CVE-2018-0967, CVE-2018-0968, CVE-2018-0969, CVE-2018-0970, CVE-2018-0971, CVE-2018-0972, CVE-2018-0973, CVE-2018-0974, CVE-2018-0975, CVE-2018-0976, CVE-2018-0979, CVE-2018-0980, CVE-2018-0981, CVE-2018-0987, CVE-2018-0988, CVE-2018-0989, CVE-2018-0990, CVE-2018-0991, CVE-2018-0993, CVE-2018-0994, CVE-2018-0995, CVE-2018-0996, CVE-2018-0997, CVE-2018-0998, CVE-2018-1000, CVE-2018-1001, CVE-2018-1003, CVE-2018-1004, CVE-2018-1005, CVE-2018-1007, CVE-2018-1008, CVE-2018-1009, CVE-2018-1010, CVE-2018-1011, CVE-2018-1012, CVE-2018-1013, CVE-2018-1014, CVE-2018-1015, CVE-2018-1016, CVE-2018-1018, CVE-2018-1019, CVE-2018-1020, CVE-2018-1023, CVE-2018-1026, CVE-2018-1027, CVE-2018-1028, CVE-2018-1029, CVE-2018-1030, CVE-2018-1032, CVE-2018-1034, CVE-2018-1037, CVE-2018-8116, CVE-2018-8117<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-10","alert_type":396,"serial_number":"AV18-059","subject":null,"moderation_state":"archived","external_url":null},{"nid":758,"title":"Adobe security bulletins","uuid":"8cf964c7-7b9a-468b-9662-b0f70fe8270a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-10T13:10:43Z","summary":null,"body":["<article data-history-node-id=\"758\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-060<br \/>\nDate: 10 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for Adobe Flash Player, Experience Manager, InDesign, Digital Editions, ColdFusion and PhoneGap Push Plugin.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Flash Player Desktop Runtime for Windows and Macintosh, versions 29.0.0.140 and earlier -Flash Player Desktop Runtime for Linux, versions 29.0.0.140 and earlier -Flash Player for Chrome, versions 29.0.0.140 and earlier -Flash Player for Edge and Internet Explorer 11, versions 29.0.0.140 and earlier.<\/li>\n\t<li>Experience Manager Version 6.3, 6.2, 6.1 and 6.0<\/li>\n\t<li>InDesign version 13.0 and below<\/li>\n\t<li>Digital Editions version 4.5.7 and below<\/li>\n\t<li>ColdFusion 2016 Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions<\/li>\n\t<li>PhoneGap Push Plugin version 1.8.0 and earlier versions.<\/li>\n<\/ul><p>CVE References: CVE-2018-4925, CVE-2018-4926, CVE-2018-4927,CVE-2018-4928, CVE-2018-4929, CVE-2018-4930, CVE-2018-4931, CVE-2018-4932, CVE-2018-4933, CVE-2018-4934, CVE-2018-4935, CVE-2018-4936, CVE-2018-4937, CVE-2018-4938, CVE-2018-4939, CVE-2018-4940, CVE-2018-4941, CVE-2018-4942, CVE-2018-4943<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-08.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-08.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-10.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-10.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb18-11.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb18-11.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb18-13.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb18-13.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb18-14.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb18-14.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/phonegap\/apsb18-15.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/phonegap\/apsb18-15.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-1","alert_type":396,"serial_number":"AV18-060","subject":null,"moderation_state":"archived","external_url":null},{"nid":834,"title":"SAP security updates","uuid":"e997322c-e5a4-46db-9358-ebb43ecb82c0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-07-10T13:15:30Z","summary":null,"body":["<article data-history-node-id=\"834\" about=\"\/en\/alerts-advisories\/sap-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-061<br \/>\nDate: 11 April 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a series of security updates that resolve numerous vulnerabilities with various SAP applications.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This SAP security advisory outlines numerous patches that resolve vulnerabilities in their products which range from medium to critical.<\/p>\n\n<p>Products Affected:<\/p>\n\n<p>- SAP Business Client, Version 6.5<br \/>\n- SAP Business One, Versions 9.2, 9.3<br \/>\n- SAP Visual Composer, Versions 7.00, 7.01, 7.02, 7.30, 7.31<br \/>\n- SAP Business Objects, Versions 4.0, from 4.10, from 4.20, 4.30<br \/>\n- SAP Cloud Platform Connector, Version - 2.0<br \/>\n- SAP Disclosure Management, Version 10.1<br \/>\n- SAP Solution Manager, Versions 7.10, 7.20<br \/>\n- Sybase PowerBuilder, Version 12.6<br \/>\n- SMP, Version 2.3<br \/>\n- Agentry, Version 6.0<br \/>\n- SAP Open Switch, Version 15.1<br \/>\n- SAP Open Server, Versions 15.7, 16.0<br \/>\n- SDK for SAP ASE, Version 16.0<br \/>\n- SYBASE SOFTWARE DEV KIT, Version 15.7<br \/>\n- SYBASE IQ, Version 15.4<br \/>\n- SAP IQ, Version 16.0<br \/>\n- Sybase SQL Anywhere, Versions 12.0.1, 16.0<br \/>\n- SAP SQL Anywhere, Version 17.0<br \/>\n- SAP SQL Anywhere OnDemand, Version 1.0<br \/>\n- SAP ASE, Versions 15.7, 16.0<br \/>\n- SAP Replication Server, Version 15.7<br \/>\n- SYBASE ECDA, Version 15.7<br \/>\n- SAP HANA Smart Data Streaming, Version 1.0<br \/>\n- SAP Complex Assembly Manufacturing, Version 7.2<br \/>\n- SAP Data Services, Version 4.2<br \/>\n- SAP Crystal Reports Server, OEM Edition, Versions 4.0, 4.10, 4.20, 4.30<br \/>\n- SAP Control Center and SAP Cockpit Framework<\/p>\n\n<p>CVE References:\u00a0 CVE-2018-2403, CVE-2018-2404, CVE-2018-2405, CVE-2018-2406, CVE-2018-2408, CVE-2018-2409, CVE-2018-2410, CVE-2018-2412, CVE-2018-2413<\/p>\n\n<p>Please note that SAP credentials are required to access these references on the link provided below.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to the linked security note where SAP expands on the details of the vulnerabilities of each of the security notes and provides a patch to resolve the issues on each respective product.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/blogs.sap.com\/2018\/04\/10\/sap-security-patch-day-april-2018\/\"><font color=\"#0066cc\">https:\/\/blogs.sap.com\/2018\/04\/10\/sap-security-patch-day-april-2018\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-updates","alert_type":396,"serial_number":"AV18-061","subject":null,"moderation_state":"archived","external_url":null},{"nid":978,"title":"AMD security update - Microcode for Spectre v2","uuid":"943e42b9-22ed-4a4e-8d0a-2137ce4445f7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-10T13:20:10Z","summary":null,"body":["<article data-history-node-id=\"978\" about=\"\/en\/alerts-advisories\/amd-security-update-microcode-spectre-v2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-062<br \/>\nDate: 11 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released AMD Microcode update to mitigate against Spectre, Variant 2.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>An operating system update released by Microsoft contains Variant 2 (Spectre) mitigations for AMD users running Windows 10 (version 1709).<\/p>\n\n<p>Affected Products:<br \/>\n- Windows 10 version 1709<\/p>\n\n<p>CVE References: CVE-2017-5715<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/www.amd.com\/en\/corporate\/security-updates\"><font color=\"#0066cc\">https:\/\/www.amd.com\/en\/corporate\/security-updates<\/font><\/a><\/p>\n\t<\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4093112\/windows-10-update-kb4093112\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/4093112\/windows-10-update-kb4093112<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-update-microcode-spectre-v2","alert_type":null,"serial_number":"AV18-062","subject":null,"moderation_state":"archived","external_url":null},{"nid":872,"title":"Juniper security bulletins","uuid":"5e529f40-a48c-487e-962b-336fd754c27e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-10T13:25:36Z","summary":null,"body":["<article data-history-node-id=\"872\" about=\"\/en\/alerts-advisories\/juniper-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-063<br \/>\nDate: 12 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security bulletins released by Juniper.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Juniper has released multiple security bulletins to address multiple vulnerabilities in their products. Successful exploitation could result in denial of service, information disclosure and possible \u201cman in the middle\u201d exploitation.<\/p>\n\n<p>CVE References: CVE-2018-0023, CVE-2018-0022, CVE-2018-0021, CVE-2017-1000385, CVE-2015-2080, CVE-2018-0020, CVE-2018-0019, CVE-2018-0018, CVE-2018-0017, CVE-2018-0016<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-bulletins","alert_type":396,"serial_number":"AV18-063","subject":null,"moderation_state":"archived","external_url":null},{"nid":985,"title":"VMware security advisory","uuid":"c6cc6564-8776-491f-9ece-f27a34be6781","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-10T13:29:55Z","summary":null,"body":["<article data-history-node-id=\"985\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-064<br \/>\nDate: 14 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates addressing multiple security vulnerabilities for vRealize Automation (vRA).<\/p>\n\n<p>Affected Product:<br \/>\n- vRealize Automation (vRA)<\/p>\n\n<p>CVE Reference: CVE-2018-6958, CVE-2018-6959<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0009.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0009.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-9","alert_type":396,"serial_number":"AV18-064","subject":null,"moderation_state":"archived","external_url":null},{"nid":1031,"title":"Oracle Critical Patch update Advisory - April 2018","uuid":"e0a28795-37b1-48a4-85f2-dd9a33c2276b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-10T13:35:56Z","summary":null,"body":["<article data-history-node-id=\"1031\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-april-2018\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-065<br \/>\nDate: 18 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the quarterly updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update Advisory which addresses multiple new security fixes across multiple Oracle products and versions.<\/p>\n\n<p>Affected Product Versions:<\/p>\n\n<ul><li>Enterprise Manager Base Platform, versions 12.1.0.5, 13.2.0.0<\/li>\n\t<li>Enterprise Manager for MySQL Database, version 12.1.0.4<\/li>\n\t<li>Enterprise Manager for Virtualization, version 13.2<\/li>\n\t<li>Enterprise Manager Ops Center, versions 12.2.2, 12.3.3<\/li>\n\t<li>Hardware Management Pack, versions prior to 2.4.3<\/li>\n\t<li>Instantis EnterpriseTrack, versions 17.1, 17.2<\/li>\n\t<li>Integrated Lights Out Manager (ILOM), versions 3.x, 4.x<\/li>\n\t<li>JD Edwards EnterpriseOne Tools, version 9.2.2<\/li>\n\t<li>JD Edwards World Security, versions A9.2, A9.3, A9.4<\/li>\n\t<li>Management Pack for Oracle GoldenGate, version 11.2.1.0.13<\/li>\n\t<li>MICROS Handheld Terminal, versions Prior to Fusion 2.03.0.0.021R<\/li>\n\t<li>MICROS Lucas, version 2.9.5<\/li>\n\t<li>MySQL Cluster, versions 7.2.27 and prior, 7.3.16 and prior, 7.4.14 and prior, 7.5.5 and prior<\/li>\n\t<li>MySQL Enterprise Monitor, versions 3.3.7.3306 and prior, 3.4.5.4248 and prior, 4.0.2.5168 and prior<\/li>\n\t<li>MySQL Server, versions 5.5.59 and prior, 5.6.39 and prior, 5.7.21 and prior<\/li>\n\t<li>Oracle Access Manager, versions 10.1.4.3.0, 11.1.2.3.0, 12.2.1.3.0<\/li>\n\t<li>Oracle Adaptive Access Manager, version 11.1.2.3.0<\/li>\n\t<li>Oracle Agile Engineering Data Management, versions 6.1.3, 6.2.0, 6.2.1<\/li>\n\t<li>Oracle Agile PLM Framework, version 9.3.6<\/li>\n\t<li>Oracle Agile Product Lifecycle Management for Process, versions 6.1.1.6, 6.2.0.0, 6.2.1.0<\/li>\n\t<li>Oracle Application Testing Suite, versions 12.5.0.3, 13.1.0.1, 13.2.0.1<\/li>\n\t<li>Oracle Banking Corporate Lending, versions 12.3.0, 12.4.0, 12.5.0, 14.0.0<\/li>\n\t<li>Oracle Banking Enterprise Collections, version 2.6<\/li>\n\t<li>Oracle Banking Enterprise Originations, version 2.6<\/li>\n\t<li>Oracle Banking Enterprise Product Manufacturing, version 2.6<\/li>\n\t<li>Oracle Banking Payments, versions 12.3.0, 12.4.0, 12.5.0, 14.0.0<\/li>\n\t<li>Oracle Banking Platform, versions 2.4, 2.5, 2.6<\/li>\n\t<li>Oracle Big Data Discovery, version 1.6.0<\/li>\n\t<li>Oracle Business Intelligence Data Warehouse Administration Console, version 11.1.1.6.4<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.2.0, 12.2.1.3.0<\/li>\n\t<li>Oracle Communications Calendar Server, version 8.x<\/li>\n\t<li>Oracle Communications Contacts Server, version 8.x<\/li>\n\t<li>Oracle Communications EAGLE LNP Application Processor, versions 10.1.0.0.0 and prior<\/li>\n\t<li>Oracle Communications Messaging Server, version 8.x<\/li>\n\t<li>Oracle Communications MetaSolv Solution, version 6.3.0<\/li>\n\t<li>Oracle Communications Network Charging and Control, versions 4.4.1.5.0, 5.0.0.1.0, 5.0.0.2.0, 5.0.1.0.0, 5.0.2.0.0<\/li>\n\t<li>Oracle Communications Network Intelligence, version 7.3.x<\/li>\n\t<li>Oracle Communications Order and Service Management, versions 7.2.4.3.0, 7.3.0.1.x, 7.3.1.0.7, 7.3.5.0.x<\/li>\n\t<li>Oracle Communications Unified Inventory Management, version 7.x<\/li>\n\t<li>Oracle Data Visualization Desktop, version 12.2.4.1.1<\/li>\n\t<li>Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1.0.0<\/li>\n\t<li>Oracle E-Business Suite, versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7<\/li>\n\t<li>Oracle Endeca Information Discovery Integrator, versions 3.1, 3.2<\/li>\n\t<li>Oracle Endeca Information Discovery Studio, versions 7.6.1.0.0, 7.7.0.0.0<\/li>\n\t<li>Oracle Endeca Server, version 7.7<\/li>\n\t<li>Oracle Enterprise Repository, versions 11.1.1.7.0, 12.1.3.0.0<\/li>\n\t<li>Oracle Financial Services Analytical Applications Infrastructure, versions 7.3.x, 8.0.x<\/li>\n\t<li>Oracle Financial Services Basel Regulatory Capital Basic, version 8.0.x<\/li>\n\t<li>Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach, version 8.0.x<\/li>\n\t<li>Oracle Financial Services Hedge Management and IFRS Valuations, versions 8.0.4, 8.0.5<\/li>\n\t<li>Oracle Financial Services Market Risk Measurement and Management, version 8.0.5<\/li>\n\t<li>Oracle FLEXCUBE Core Banking, versions 11.5.0, 11.6.0, 11.7.0<\/li>\n\t<li>Oracle FLEXCUBE Enterprise Limits and Collateral Management, versions 12.3.0, 14.0.0<\/li>\n\t<li>Oracle FLEXCUBE Investor Servicing, versions 12.0.4, 12.1.0, 12.3.0, 12.4.0<\/li>\n\t<li>Oracle FLEXCUBE Private Banking, versions 12.0.0, 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Universal Banking, versions 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0<\/li>\n\t<li>Oracle Fusion Applications , versions 11.1.2 through 11.1.9<\/li>\n\t<li>Oracle Fusion Middleware, versions 11.1.1.7, 11.1.1.9, 11.1.2.3, 12.1.3.0, 12.2.1.2, 12.2.1.3<\/li>\n\t<li>Oracle Fusion Middleware MapViewer, versions 11.1.1.7.0, 11.1.1.9.0<\/li>\n\t<li>Oracle GoldenGate, version 12.2.0.1<\/li>\n\t<li>Oracle GoldenGate Veridata, versions 11.2.0.1.2, 12.1.3.0.0<\/li>\n\t<li>Oracle Hospitality Cruise Fleet Management System, version 9.x<\/li>\n\t<li>Oracle Hospitality Guest Access, versions 4.2.0, 4.2.1<\/li>\n\t<li>Oracle Hospitality Reporting and Analytics, version 9.0<\/li>\n\t<li>Oracle Hospitality Simphony, versions 2.7, 2.8, 2.9, 2.10<\/li>\n\t<li>Oracle Hospitality Simphony First Edition, versions 1.6, 1.7<\/li>\n\t<li>Oracle Hospitality Suite8, version 8.x<\/li>\n\t<li>Oracle HTTP Server, versions 12.1.3, 12.2.1.2<\/li>\n\t<li>Oracle Java SE, versions 6u181, 7u161, 7u171, 8u152, 8u162, 10<\/li>\n\t<li>Oracle Java SE Embedded, versions 8u152, 8u161<\/li>\n\t<li>Oracle JRockit, version R28.3.17<\/li>\n\t<li>Oracle Managed File Transfer, versions 12.1.3.0.0, 12.2.1.2.0, 12.2.1.3.0<\/li>\n\t<li>Oracle Mobile Security Suite, version 3.0.1<\/li>\n\t<li>Oracle Outside In Technology, version 8.5.3<\/li>\n\t<li>Oracle Retail Advanced Inventory Planning, versions 13.2, 13.4, 14.1, 15.0<\/li>\n\t<li>Oracle Retail Back Office, versions 13.4.9, 14.0.4, 14.1.3<\/li>\n\t<li>Oracle Retail Central Office, versions 13.4.9, 14.0.4, 14.1.3<\/li>\n\t<li>Oracle Retail Customer Engagement, version 16.0<\/li>\n\t<li>Oracle Retail EFTLink, versions 1.1.125, 15.0.2, 16.0.3<\/li>\n\t<li>Oracle Retail Insights, versions 14.0, 14.1, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Integration Bus, version 13.2<\/li>\n\t<li>Oracle Retail Invoice Matching, versions 12.0, 13.0, 13.1, 13.2, 14.0, 14.1, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Merchandising System, version 16.0<\/li>\n\t<li>Oracle Retail Order Broker, versions 5.0, 5.1, 5.2, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Order Management System, versions 4.0, 4.5, 4.7, 5.0<\/li>\n\t<li>Oracle Retail Point-of-Service, versions 13.3.8, 13.4.9, 14.0.4, 14.1.3<\/li>\n\t<li>Oracle Retail Predictive Application Server, versions 13.4.3, 14.0.3, 14.1.3<\/li>\n\t<li>Oracle Retail Price Management, versions 12.0, 13.0, 13.1, 13.2, 14.0, 14.1, 15.0, 16.0<\/li>\n\t<li>Oracle Retail Returns Management, versions 2.3.8, 2.4.9, 14.0.4, 14.1.3<\/li>\n\t<li>Oracle Retail Store Inventory Management, versions 12.0.12, 13.0.7, 13.1.9, 13.2.9, 14.0.4, 14.1.3, 15.0.2, 16.0.1<\/li>\n\t<li>Oracle Retail Xstore Point of Service, versions 6.0, 6.0.12, 6.5, 6.5.12, 7.0, 7.0.7, 7.1, 7.1.7, 15.0, 15.0.2, 16.0, 16.0.3<\/li>\n\t<li>Oracle Secure Global Desktop (SGD), version 5.3<\/li>\n\t<li>Oracle Security Service, versions 12.1.3.0.0, 12.2.1.2.0<\/li>\n\t<li>Oracle Transportation Management, versions 6.2, 6.4.3<\/li>\n\t<li>Oracle Tuxedo, version 12.1.1.0.0<\/li>\n\t<li>Oracle Utilities Framework, versions 2.2.0, 4.2.0, 4.3.0<\/li>\n\t<li>Oracle VM VirtualBox, versions prior to 5.1.36, prior to 5.2.10<\/li>\n\t<li>Oracle WebCenter Content, versions 11.1.1.9.0, 12.2.1.2.0, 12.2.1.3.0<\/li>\n\t<li>Oracle WebCenter Portal, versions 12.2.1.2.0, 12.2.1.3.0<\/li>\n\t<li>Oracle WebCenter Sites, versions 11.1.1.8.0, 12.2.1.2.0, 12.2.1.3.0<\/li>\n\t<li>Oracle WebLogic Portal, version 10.3.6.0.0<\/li>\n\t<li>Oracle WebLogic Server, versions 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3<\/li>\n\t<li>OSS Support Tools, versions prior to 18.2<\/li>\n\t<li>PeopleSoft Enterprise HCM, version 9.2<\/li>\n\t<li>PeopleSoft Enterprise HCM Shared Components, version 9.2<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools, versions 8.54, 8.55, 8.56<\/li>\n\t<li>PeopleSoft Enterprise PRTL Interaction Hub, version 9.1<\/li>\n\t<li>PeopleSoft Enterprise PT PeopleTools, versions 8.54, 8.55, 8.56<\/li>\n\t<li>Primavera P6 Enterprise Project Portfolio Management, versions 16.2, 17.1 \u2013 17.12<\/li>\n\t<li>Primavera Unifier, versions 16.x, 17.x<\/li>\n\t<li>Real-Time Decisions (RTD) Solutions, version 3.2.0.0.0<\/li>\n\t<li>Siebel Applications, version 17.0<\/li>\n\t<li>Solaris, versions 10, 11.3<\/li>\n\t<li>Solaris Cluster, version 4.3<\/li>\n\t<li>Sun ZFS Storage Appliance Kit (AK), versions prior to 8.7.17<\/li>\n<\/ul><p>CVE References: CVE-2013-1768, CVE-2014-0054, CVE-2015-7501, CVE-2015-7940, CVE-2016-0635, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-3092, CVE-2016-3506, CVE-2016-5007, CVE-2016-5019, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6814, CVE-2016-7052, CVE-2016-8745, CVE-2016-9878, CVE-2017-1039, CVE-2017-1040, CVE-2017-1261, CVE-2017-1307, CVE-2017-1308, CVE-2017-1509, CVE-2017-1570, CVE-2017-1756, CVE-2017-3735, CVE-2017-3736, CVE-2017-3737, CVE-2017-3738, CVE-2017-5645, CVE-2017-5662, CVE-2017-5664, CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2017-7525, CVE-2017-7674, CVE-2017-7805, CVE-2017-9798, CVE-2018-0739, CVE-2018-2563, CVE-2018-2572, CVE-2018-2587, CVE-2018-2628, CVE-2018-2718, CVE-2018-2737, CVE-2018-2738, CVE-2018-2739, CVE-2018-2742, CVE-2018-2746, CVE-2018-2747, CVE-2018-2748, CVE-2018-2749, CVE-2018-2750, CVE-2018-2752, CVE-2018-2753, CVE-2018-2754, CVE-2018-2755, CVE-2018-2756, CVE-2018-2758, CVE-2018-2759, CVE-2018-2760, CVE-2018-2761, CVE-2018-2762, CVE-2018-2763, CVE-2018-2764, CVE-2018-2765, CVE-2018-2766, CVE-2018-2768, CVE-2018-2769, CVE-2018-2770, CVE-2018-2771, CVE-2018-2772, CVE-2018-2773, CVE-2018-2774, CVE-2018-2775, CVE-2018-2776, CVE-2018-2777, CVE-2018-2778, CVE-2018-2779, CVE-2018-2780, CVE-2018-2781, CVE-2018-2782, CVE-2018-2783, CVE-2018-2784, CVE-2018-2785, CVE-2018-2786, CVE-2018-2787, CVE-2018-2788, CVE-2018-2789, CVE-2018-2790, CVE-2018-2791, CVE-2018-2792, CVE-2018-2793, CVE-2018-2794, CVE-2018-2795, CVE-2018-2796, CVE-2018-2797, CVE-2018-2798, CVE-2018-2799, CVE-2018-2800, CVE-2018-2801, CVE-2018-2802, CVE-2018-2803, CVE-2018-2804, CVE-2018-2805, CVE-2018-2806, CVE-2018-2807, CVE-2018-2808, CVE-2018-2809, CVE-2018-2810, CVE-2018-2811, CVE-2018-2812, CVE-2018-2813, CVE-2018-2814, CVE-2018-2815, CVE-2018-2816, CVE-2018-2817, CVE-2018-2818, CVE-2018-2819, CVE-2018-2820, CVE-2018-2821, CVE-2018-2822, CVE-2018-2823, CVE-2018-2824, CVE-2018-2825, CVE-2018-2826, CVE-2018-2827, CVE-2018-2828, CVE-2018-2829, CVE-2018-2830, CVE-2018-2831, CVE-2018-2832, CVE-2018-2833, CVE-2018-2834, CVE-2018-2835, CVE-2018-2836, CVE-2018-2837, CVE-2018-2838, CVE-2018-2839, CVE-2018-2840, CVE-2018-2841, CVE-2018-2842, CVE-2018-2843, CVE-2018-2844, CVE-2018-2845, CVE-2018-2846, CVE-2018-2847, CVE-2018-2848, CVE-2018-2849, CVE-2018-2850, CVE-2018-2851, CVE-2018-2852, CVE-2018-2853, CVE-2018-2854, CVE-2018-2855, CVE-2018-2856, CVE-2018-2857, CVE-2018-2858, CVE-2018-2859, CVE-2018-2860, CVE-2018-2861, CVE-2018-2862, CVE-2018-2863, CVE-2018-2864, CVE-2018-2865, CVE-2018-2866, CVE-2018-2867, CVE-2018-2868, CVE-2018-2869, CVE-2018-2870, CVE-2018-2871, CVE-2018-2872, CVE-2018-2873, CVE-2018-2874, CVE-2018-2876, CVE-2018-2877, CVE-2018-2878, CVE-2018-2879, CVE-2018-7489<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2018-3678067.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2018-3678067.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory-april-2018","alert_type":396,"serial_number":"AV18-065","subject":null,"moderation_state":"archived","external_url":null},{"nid":1233,"title":"Google Releases security update for Chrome","uuid":"2259a236-8735-48eb-9191-1fdb24fb3111","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-10T14:01:18Z","summary":null,"body":["<article data-history-node-id=\"1233\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-33\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-066<br \/>\nDate: 19 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 66.0.3359.117 for Windows, Mac, and Linux.<\/p>\n\n<p>CVE References: CVE-2018-6084, CVE-2018-6085, CVE-2018-6086, CVE-2018-6087, CVE-2018-6088, CVE-2018-6089, CVE-2018-6090, CVE-2018-6091, CVE-2018-6092, CVE-2018-6093, CVE-2018-6094, CVE-2018-6095, CVE-2018-6096, CVE-2018-6097, CVE-2018-6098, CVE-2018-6099, CVE-2018-6100, CVE-2018-6101, CVE-2018-6102, CVE-2018-6103, CVE-2018-6104, CVE-2018-6105, CVE-2018-6106, CVE-2018-6107, CVE-2018-6108, CVE-2018-6109, CVE-2018-6110, CVE-2018-6111, CVE-2018-6112, CVE-2018-6113, CVE-2018-6114, CVE-2018-6115, CVE-2018-6116, CVE-2018-6117<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2018\/04\/stable-channel-update-for-desktop.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2018\/04\/stable-channel-update-for-desktop.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-33","alert_type":396,"serial_number":"AV18-066","subject":null,"moderation_state":"archived","external_url":null},{"nid":1246,"title":"Cisco security updates","uuid":"aeae2d85-d242-4400-be1c-64c60338de80","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-10T14:22:33Z","summary":null,"body":["<article data-history-node-id=\"1246\" about=\"\/en\/alerts-advisories\/cisco-security-updates-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-067<br \/>\nDate: 19 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in the following products.<\/p>\n\n<ul><li>Cisco WebEx Clients Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco UCS Director Virtual Machine Information Disclosure Vulnerability for End User Portal<\/li>\n\t<li>Cisco StarOS Interface Forwarding Denial of Service Vulnerability<\/li>\n\t<li>Cisco IOS XR Software UDP Broadcast Forwarding Denial of Service Vulnerability<\/li>\n\t<li>Cisco Firepower Detection Engine Secure Sockets Layer Denial of Service Vulnerability<\/li>\n\t<li>Cisco Firepower 2100 Series Security Appliances IP Fragmentation Denial of Service Vulnerability<\/li>\n\t<li>Cisco ASA Software, FTD Software, and AnyConnect Secure Mobility Client SAML Authentication Session Fixation Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities<\/li>\n\t<li>Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance Flow Creation Denial of Service Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability<\/li>\n\t<li>Cisco WebEx Connect IM Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager LDAP Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager HTTP Interface Information Disclosure Vulnerability<\/li>\n\t<li>Cisco StarOS IPsec Manager Denial of Service Vulnerability<\/li>\n\t<li>Cisco Packet Data Network Gateway Peer-to-Peer Message Processing Denial of Service Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine Shell Access Vulnerability<\/li>\n\t<li>Cisco Industrial Ethernet Switches Device Manager Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Firepower System Software Intelligent Application Bypass Vulnerability<\/li>\n\t<li>Cisco Firepower System Software Server Message Block File Policy Bypass Vulnerability<\/li>\n\t<li>Cisco Firepower System Software Server Message Block File Policy Bypass Vulnerability<\/li>\n\t<li>Cisco Firepower Threat Defense SSL Engine High CPU Denial of Service Vulnerability<\/li>\n\t<li>Cisco DNA Center Cross Origin Resource Sharing Vulnerability<\/li>\n\t<li>Cisco cBR Series Converged Broadband Routers High CPU Usage Denial of Service Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance Clientless SSL VPN Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance WebVPN Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco AMP for Endpoints macOS Connector DMG File Malware Bypass Vulnerability<\/li>\n\t<li>Cisco MATE Live Directory Information Disclosure Vulnerability<\/li>\n\t<li>Cisco MATE Collector Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Wireless LAN Controller Default Simple Network Management Protocol Community Strings<\/li>\n<\/ul><p>CVE References:\u00a0 CVE-2018-0112, CVE-2018-0238, CVE-2018-0239, CVE-2018-0241 , CVE-2018-0233, CVE-2018-0230, CVE-2018-0229, CVE-2018-0240, CVE-2018-0231, CVE-2018-0228, CVE-2018-0227, CVE-2018-0276, CVE-2018-0267, CVE-2018-0267, CVE-2018-0266, CVE-2018-0273, CVE-2018-0256, CVE-2018-0275, CVE-2018-0255, CVE-2018-0254, CVE-2018-0244, CVE-2018-0243, CVE-2018-0272, CVE-2018-0269, CVE-2018-0257, CVE-2018-0251, CVE-2018-0242, CVE-2018-0237, CVE-2018-0260, CVE-2018-0259<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-wbs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-wbs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-uscd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-uscd<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-staros\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-staros<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-iosxr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-iosxr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fpsnort\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fpsnort<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fp2100\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fp2100<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asaanyconnect\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asaanyconnect<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa_inspect\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa_inspect<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa3<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asa1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-webcon\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-webcon<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-ucm1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-ucm1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-ucm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-ucm<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-starosasr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-starosasr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-pdng\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-pdng<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-ise<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-iess\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-iess<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fss2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fss2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fss1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fss1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-fss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-firepower\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-firepower<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-dna1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-dna1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-cbr8\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-cbr8<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asawvpn2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asawvpn2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asawvpn\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-asawvpn<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-amp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-amp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-MATE1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-MATE1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-MATE\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-MATE<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-wlc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180418-wlc<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-12","alert_type":396,"serial_number":"AV18-067","subject":null,"moderation_state":"archived","external_url":null},{"nid":1351,"title":"Drupal security advisory","uuid":"70f8c5ac-de6c-4334-a0ac-67d1a65f83b2","banner":null,"lang":"en","date_modified":"2018-10-03","date_modified_ts":"2018-10-03T15:27:29Z","date_created":"2018-07-10T14:27:10Z","summary":null,"body":["<article data-history-node-id=\"1351\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-068<br \/>\nDate: 19 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Drupal security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released an update to address a cross-site scripting (XSS) vulnerability. Exploitation of this vulnerability makes it possible to execute XSS inside CKEditor when using the image2 plugin that is used by Drupal 8 core.<\/p>\n\n<p>Affected Version:<\/p>\n\n<ul><li>Drupal 8<\/li>\n\t<li>CKEditor versions 4.5.11 and later<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.drupal.org\/sa-core-2018-003\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/sa-core-2018-003<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/ckeditor.com\/blog\/CKEditor-4.9.2-with-a-security-patch-released\/\"><font color=\"#0066cc\">https:\/\/ckeditor.com\/blog\/CKEditor-4.9.2-with-a-security-patch-released\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-0","alert_type":396,"serial_number":"AV18-068","subject":null,"moderation_state":"archived","external_url":null},{"nid":1000,"title":"Apple security updates","uuid":"181e68df-ed71-42be-8a65-2b7c37f783e2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:43Z","date_created":"2018-07-10T14:31:34Z","summary":null,"body":["<article data-history-node-id=\"1000\" about=\"\/en\/alerts-advisories\/apple-security-updates-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-069<br \/>\nDate: 25 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates by Apple.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released security updates for vulnerabilities in various Apple products.<\/p>\n\n<p>Affected Products:<br \/>\n- iOS 11.3<br \/>\n- macOS High Sierra, versions previous to 10.13.4<br \/>\n- Safari 11.1<\/p>\n\n<p>CVE Reference: CVE-2018-4200, CVE-2018-4204, CVE-2018-4206, CVE-2018-4187<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT201222<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-10","alert_type":396,"serial_number":"AV18-069","subject":null,"moderation_state":"archived","external_url":null},{"nid":1129,"title":"Drupal security advisory","uuid":"710f4290-3845-43c1-b218-df570432a44e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-10T14:35:47Z","summary":null,"body":["<article data-history-node-id=\"1129\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-070<br \/>\nDate: 25 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Critical Drupal security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released updates to address multiple vulnerabilities in their software.<\/p>\n\n<p>Affected Version:<\/p>\n\n<ul><li>7.x<\/li>\n\t<li>8.5.x<\/li>\n\t<li>8.4.x<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2018-004\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/sa-core-2018-004<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-1","alert_type":396,"serial_number":"AV18-070","subject":null,"moderation_state":"archived","external_url":null},{"nid":801,"title":"Microsoft security updates for Spectre v2","uuid":"257ba826-f5c3-4b5d-8a1b-4f8265a14092","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-10T14:40:23Z","summary":null,"body":["<article data-history-node-id=\"801\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-spectre-v2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-071<br \/>\nDate: 27 April 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft updates in regards to mitigation towards Spectre Variant 2.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Two updates have been released by Microsoft in regards to mitigation towards the Spectre Variant 2 \u201cBranch Target Injection\u201d vulnerability. KB4078407 is software-based OS-level mitigation, whereas KB4091666 is for Intel processors only and includes Intel microcode updates needed to mitigate at the hardware level.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Windows 10 version 1709\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Windows Server 2016 Version 1709\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Windows 10 Version 1703\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Windows 10 Version 1607\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Windows Server 2016\u00a0\u00a0<\/li>\n\t<li>Windows Server 2016 Datacenter\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Windows Server 2016 Essentials\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Windows Server 2016 Standard<\/li>\n\t<li>Windows 10 with Intel CPU<\/li>\n<\/ul><p>CVE References: CVE-2017-5715<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/support.microsoft.com\/en-sg\/help\/4078407\/update-to-enable-mitigation-against-spectre-variant-2\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-sg\/help\/4078407\/update-to-enable-mitigation-against-spectre-variant-2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-sg\/help\/4091666\/kb4091666-intel-microcode-updates\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-sg\/help\/4091666\/kb4091666-intel-microcode-updates<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-spectre-v2","alert_type":396,"serial_number":"AV18-071","subject":null,"moderation_state":"archived","external_url":null},{"nid":1283,"title":"Apache CouchDB security updates","uuid":"e868b379-ffc3-4628-91e7-22f68b1f5422","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:07Z","date_created":"2018-07-10T14:45:20Z","summary":null,"body":["<article data-history-node-id=\"1283\" about=\"\/en\/alerts-advisories\/apache-couchdb-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-072<br \/>\nDate: 01 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to critical security updates release by Apache CouchDB.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apache CouchDB has released critical security updates to address vulnerabilities in their products.<\/p>\n\n<p>CVE References: CVE-2017-12635 and CVE-2017-12636<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/lists.apache.org\/thread.html\/6c405bf3f8358e6314076be9f48c89a2e0ddf00539906291ebdf0c67@%3Cdev.couchdb.apache.org%3E\"><font color=\"#0066cc\">https:\/\/lists.apache.org\/thread.html\/6c405bf3f8358e6314076be9f48c89a2e0ddf00539906291ebdf0c67@%3Cdev.couchdb.apache.org%3E<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12635\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-12635<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-couchdb-security-updates","alert_type":396,"serial_number":"AV18-072","subject":null,"moderation_state":"archived","external_url":null},{"nid":959,"title":"Schneider Electric ConneXium Buffer Overflow Vulnerability","uuid":"533a41e4-a3b6-4757-af92-46f27c3725cf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-07-10T17:15:01Z","summary":null,"body":["<article data-history-node-id=\"959\" about=\"\/en\/alerts-advisories\/schneider-electric-connexium-buffer-overflow-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV16-178<br \/>\nDate: 2 November 2016 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently disclosed vulnerability in Schneider Electric ConneXium.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A buffer overflow vulnerability was identified in Schneider Electric\u2019s ConneXium firewall product. Exploitation of this vulnerability could allow an attacker to execute code during the login authentication process with SNMP. Schneider Electric is currently developing a firmware update to mitigate this vulnerability.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>TCSEFEC23F3F20 all versions<\/li>\n\t<li>TCSEFEC23F3F21 all versions<\/li>\n\t<li>TCSEFEC23FCF20 all versions<\/li>\n\t<li>TCSEFEC23FCF21 all versions<\/li>\n\t<li>TCSEFEC2CF3F20 all versions.<\/li>\n<\/ul><p>CVE Reference: CVE-2016-8352<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p>References:<\/p>\n\n<ul><li><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-306-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-16-306-01<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2012\/tr12-002-en.aspx\"><font color=\"#0066cc\">https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2012\/tr12-002-en.aspx<\/font><\/a> (ISC Best Practices)<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/schneider-electric-connexium-buffer-overflow-vulnerability","alert_type":396,"serial_number":"AV16-178","subject":null,"moderation_state":"archived","external_url":null},{"nid":948,"title":"Vulnerabilities in Foxit Reader","uuid":"235dd486-e53f-40cd-966a-ab18a6a35cf0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-10T19:22:21Z","summary":null,"body":["<article data-history-node-id=\"948\" about=\"\/en\/alerts-advisories\/vulnerabilities-foxit-reader\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-010<br \/>\nDate: 18 August 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to two recently disclosed zero-day vulnerabilities in Foxit Reader.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Through open source reporting, CCIRC has been made aware of two recently disclosed zero-day vulnerabilities in Foxit Reader software that, when exploited though the JavaScript API in Foxit Reader, can allow remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. However, user interaction is required to exploit both vulnerabilities in that the target must visit a malicious page or open a malicious file.<\/p>\n\n<p>Foxit Reader is a popular free PDF reader that is distributed by many websites. There are also Foxit Reader plugins for Microsoft Office programs including Word, Excel and PowerPoint.<\/p>\n\n<p>According to the security firm who has discovered the vulnerabilities, the vendor has decided to not fix the vulnerabilities because an attacker would need to bypass safe reading mode. \u00a0This potentially however leaves the user exposed to high-impact vulnerabilities should a new technique arise allowing malicious actors to bypass the safe reading mode.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the risks that those vulnerabilities present, CCIRC recommends that system administrators restrain or limit the interactions with Foxit Reader and\/or make sure that the safe reading mode is always activated.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2017\/8\/17\/busting-myths-in-foxit-reader\"><font color=\"#0066cc\">https:\/\/www.zerodayinitiative.com\/blog\/2017\/8\/17\/busting-myths-in-foxit-reader<\/font><\/a><br \/><a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/ZDI-17-691\/\"><font color=\"#0066cc\">http:\/\/www.zerodayinitiative.com\/advisories\/ZDI-17-691\/<\/font><\/a><br \/><a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/ZDI-17-692\/\"><font color=\"#0066cc\">http:\/\/www.zerodayinitiative.com\/advisories\/ZDI-17-692\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-foxit-reader","alert_type":397,"serial_number":"AL17-010","subject":null,"moderation_state":"archived","external_url":null},{"nid":1009,"title":"Malicious Cyber Activity Targeting Managed Service Providers","uuid":"78328f01-b365-4bb2-9582-5001dfcc7150","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-07-17T18:00:16Z","summary":null,"body":["<article data-history-node-id=\"1009\" about=\"\/en\/alerts-advisories\/malicious-cyber-activity-targeting-managed-service-providers\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-004<br \/>\nDate: 04 April 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to ongoing malicious cyber activity targeting managed service providers (MSP).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of ongoing malicious cyber activity targeting managed service providers (MSPs) internationally. The level of sophistication associated with this activity requires a heightened level of awareness from organizations in order to detect possible compromises. A variety of organizations rely on MSPs to provide a wide range of infrastructure support to client organisations such as: security and specialized consulting, software, hardware and cloud hosting solutions.<\/p>\n\n<p>Mitigating the risks associated with using service providers is a responsibility shared between the organization (referred to as the \u201ctenant\u201d) and the MSP or CSP. However, organizations are ultimately responsible for protecting their systems and ensuring the confidentiality, integrity and availability of their data. Organizations that outsource IT infrastructure are recommended to have an open dialogue with their provider and to understand what model they use to manage clients\u2019 services.<\/p>\n\n<p>The actors behind this activity are leveraging MSPs as conduits in attempts to acquire sensitive client information. This is facilitated by the necessarily close relationship between MSPs\u2019 networks and those of their clients. This makes MSPs an attractive target for malicious actors, as the compromise of one MSP network could offer access to multiple client networks. Ultimately, the client, which could be in the public or private sector, is the likely target of the compromise attempts.<\/p>\n\n<p>Given the apparent sophistication of the cyber activity and the potential extent of the compromise, it is possible that this activity has given the malicious actor access to companies around the world in a variety of critical infrastructure sectors. No evidence suggests the general public or small to medium enterprises are being targeted. CCIRC is currently working with international partners and the private sector to establish the scale and determine any impact on Canadian organizations. Reporting of any suspected activity to CCIRC will greatly help in understanding the nature and scope of this activity.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<ul><li>Consider implementing a strong password policy.<\/li>\n\t<li>Keep your operating system and software up-to-date with the latest patches.<\/li>\n\t<li>Consider limiting administrative and other privileges to those accounts which require them for business purposes.<\/li>\n\t<li>Monitor antivirus scan results and other network logs for suspicious activity on a regular basis.<\/li>\n\t<li>Employ a data backup and recovery plan for all critical information.<\/li>\n\t<li>When engaging an MSP, consider factors such as ownership of the data, where the data is stored, how it is backed up and what security measures are in place. A MSP solution should satisfy organizational security, privacy and legislative requirements.<\/li>\n\t<li>Organizations using Managed Services Providers are encouraged to contact their service provider to discuss risks.<\/li>\n\t<li>For additional mitigation information and best practices on managing relationships with MSPs, please see CCIRC\u2019s Information Note IN17-003 \u2013 Cyber Security Best Practices: Contracting with Managed Service Providers.<\/li>\n<\/ul><p><strong>References:<\/strong><\/p>\n\n<p>CCIRC \u2013 Information Note IN17-003 \u2013 Cyber Security Best Practices: Contracting with Managed Service Providers<br \/><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2017\/in17-003-en.aspx\"><font color=\"#0066cc\">https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/in\/in17-003-en.aspx<\/font><\/a><\/p>\n\n<p>International Partners<br \/><a href=\"https:\/\/acsc.gov.au\/global-targeting-enterprises-managed-service-providers.html\"><font color=\"#0066cc\">https:\/\/acsc.gov.au\/global-targeting-enterprises-managed-service-providers.html<\/font><\/a><\/p>\n\n<p><a href=\"https:\/\/www.ncsc.gov.uk\/news\/advice-managing-enterprise-security-published-after-major-cyber-campaign-detected\"><font color=\"#0066cc\">https:\/\/www.ncsc.gov.uk\/news\/advice-managing-enterprise-security-published-after-major-cyber-campaign-detected<\/font><\/a><\/p>\n\n<p>Get CyberSafe Guide for Small and Medium Businesses:<br \/><a href=\"https:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx%20-%20s6-2\"><font color=\"#0066cc\">https:\/\/www.getcybersafe.gc.ca\/cnt\/rsrcs\/pblctns\/smll-bsnss-gd\/index-en.aspx%20-%20s6-2<\/font><\/a><\/p>\n\n<p>Using Passwords:<br \/><a href=\"https:\/\/www.getcybersafe.gc.ca\/cnt\/prtct-yrslf\/prtctn-dntty\/usng-psswrds-en.aspx\"><font color=\"#0066cc\">https:\/\/www.getcybersafe.gc.ca\/cnt\/prtct-yrslf\/prtctn-dntty\/usng-psswrds-en.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/malicious-cyber-activity-targeting-managed-service-providers","alert_type":397,"serial_number":"AL17-004","subject":null,"moderation_state":"archived","external_url":null},{"nid":760,"title":"Exploitation of Recently Disclosed Vulnerability - Microsoft Office","uuid":"23184576-b9a0-470a-83d1-4dbfc27cbc9e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-17T18:37:53Z","summary":null,"body":["<article data-history-node-id=\"760\" about=\"\/en\/alerts-advisories\/exploitation-recently-disclosed-vulnerability-microsoft-office\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-005<br \/>\nDate: 13 April 2017 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to a recently disclosed vulnerability in the Encapsulated PostScript filter of Microsoft Office and its exploitation.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of attacks exploiting recently patched zero-day vulnerabilities. As a result, CCIRC would like to raise awareness concerning this potentially serious vulnerability, as it may be exploited by malicious actors to perform a range of fraudulent activities, such as accessing sensitive information and installing malware.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>Due to the elevated risk that this vulnerability presents, CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. CCIRC recommends that priority is given to that patch.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Microsoft Guidance Advisory<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/2017-2605\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/2017-2605<\/font><\/a><\/p>\n\n<p>Microsoft Knowledge Based<br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/2479871\/security-settings-for-graphic-filters-for-microsoft-office-365\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/2479871\/security-settings-for-graphic-filters-for-microsoft-office-365<\/font><\/a><\/p>\n\n<p>TR11-001 Malware Infection Recovery Guide<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-eng.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-eng.aspx<\/font><\/a>\u00a0\u00a0<\/p>\n\n<p>TR15-004 Top 30 Targeted High Risk Vulnerabilities<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2015\/tr15-004-eng.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2015\/tr15-004-eng.aspx<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exploitation-recently-disclosed-vulnerability-microsoft-office","alert_type":397,"serial_number":"AL17-005","subject":null,"moderation_state":"archived","external_url":null},{"nid":836,"title":"Ransomware - WannaCry","uuid":"96de2138-3a3f-4353-9426-fa929a216efa","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-07-17T18:48:41Z","summary":null,"body":["<article data-history-node-id=\"836\" about=\"\/en\/alerts-advisories\/ransomware-wannacry\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-006<br \/>\nDate: 15 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to, and to provide guidance and mitigation advice for a large scale ransomware campaign.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a large scale ransomware campaign known as \u201cWCry\u201d, \u201cWana\u201d, \u201cWCrypt\u201d, \u201cwannacrypt\u201d, \u201cWanaDecryptor\u201d or \u201cWanaCry\u201d that has affected numerous organizations worldwide. \u00a0CCIRC continues to work with domestic and international partners to assess the impact to Canada and to provide mitigation guidance and advice.<\/p>\n\n<p>Ransomware can have an overwhelming on individuals, businesses, critical infrastructure and government.\u00a0 Not only can it lead to the loss of access to sensitive or proprietary information, but the disruption to regular operations, the financial loss and the potential harm to an organization\u2019s reputation can be devastating.<\/p>\n\n<p>The WannaCry ransomware campaign appears to be using the vulnerability addressed by Microsoft Security Bulletin MS17-010 to propagate through the network using the SMBv1 protocol. This enables the malware to infect additional devices connected to the same network if they are unpatched.<\/p>\n\n<p>CCIRC strongly discourages paying the ransom as it does not guarantee that your data will be decrypted. In addition, decrypting files does not mean the malware infection itself has been removed.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment. Furthermore, indicators of compromise, including a yara signature, and analysis are available from US-CERT (available in reference).<\/p>\n\n<p>Advice specific to propagation via SMBv1:<\/p>\n\n<ul><li>Apply the Microsoft patch for the MS17-010 SMB vulnerability dated March 14, 2017.<\/li>\n\t<li>A new patch has been made available for some\u00a0 Microsoft legacy platforms, and is available here:<br \/><a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\"><font color=\"#0066cc\">https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks<\/font><\/a><\/li>\n<\/ul><ul><li>If it is not possible to apply the patches, consider disabling SMBv1 and\/or block SMBv1 ports on network devices [UDP 137, 138 and TCP 139, 445].\u00a0 Guidance available here: <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/2696547\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/2696547<\/font><\/a><\/li>\n\t<li>To prevent inbound Internet connections by infected hosts, block SMBv1 ports at your network perimeter.<\/li>\n\t<li>To prevent your own infected hosts from infecting other external networks, block outbound SMBv1 connections at your network perimeter.<\/li>\n\t<li>Execute daily backups of all critical systems, maintain offline and offsite copies of backup media and periodically execute a practice data restoration from backups, including key databases to ensure integrity of existing backups and processes.<\/li>\n\t<li>NCSC UK has shared DNS based mitigation advice concerning WannaCry in a post titled \u201cRansomware: Latest NCSC Guidance\u201d. (See link provided below)<\/li>\n\t<li>Ensure antivirus and gateway protections are up to date.<\/li>\n<\/ul><p>General advice to mitigate common email infection vectors:<\/p>\n\n<ul><li>Scan all incoming and outgoing e-mails to detect threats and prevent executable files from reaching the end users.<\/li>\n\t<li>Don\u2019t open links or attachments in emails from untrusted or unknown sources. Inspect the sender address carefully as the address text may differ from the real address.<\/li>\n\t<li>Most often, attacks of this type are detected by diligent and well-informed users. CCIRC recommends that organizations ensure users receive current situational awareness and training, including instructions on how to report unusual or suspicious emails to their IT Security Branch. Reviewing departmental policies, requirements and security education and awareness training can help reduce this threat.<\/li>\n<\/ul><h2>References:<\/h2>\n\n<ul><li>CCIRC Advisory AV17-068 Microsoft Security Updates MS17-010 - (SMBv1)<br \/><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2017\/av17-068-en.aspx\"><font color=\"#0066cc\">https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2017\/av17-068-en.aspx<\/font><\/a><\/li>\n\t<li>CCIRC AV17-032 Microsoft Critical Security Bulletins Summary \u2013 March 2017<br \/><a href=\"https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2017\/av17-032-en.aspx\"><font color=\"#0066cc\">https:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2017\/av17-032-en.aspx<\/font><\/a><\/li>\n\t<li>Ransomware: Latest NCSC Guidance<br \/><a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/ransomware-latest-ncsc-guidance\"><font color=\"#0066cc\">https:\/\/www.ncsc.gov.uk\/guidance\/ransomware-latest-ncsc-guidance<\/font><\/a><\/li>\n\t<li>Latest statement on international ransomware cyber attack<br \/><a href=\"https:\/\/www.ncsc.gov.uk\/news\/latest-statement-international-ransomware-cyber-attack-0\"><font color=\"#0066cc\">https:\/\/www.ncsc.gov.uk\/news\/latest-statement-international-ransomware-cyber-attack-0<\/font><\/a><\/li>\n\t<li>Alert (TA17-132A) Indicators Associated With WannaCry Ransomware<br \/><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA17-132A\"><font color=\"#0066cc\">https:\/\/www.us-cert.gov\/ncas\/alerts\/TA17-132A<\/font><\/a><\/li>\n\t<li>Customer Guidance for WannaCrypt attacks<br \/><a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\/\"><font color=\"#0066cc\">https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\/<\/font><\/a><\/li>\n\t<li>Microsoft Security Bulletin MS17-010 - Critical<br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx<\/font><\/a><\/li>\n\t<li>CCIRC IN13-004 Ransomware<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2013\/in13-004-eng.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2013\/in13-004-eng.aspx<\/font><\/a><\/li>\n\t<li>CCIRC TR11-001 Malware Infection Recovery Guide<\/li>\n\t<li><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-eng.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-eng.aspx<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ransomware-wannacry","alert_type":397,"serial_number":"AL17-006","subject":null,"moderation_state":"archived","external_url":null},{"nid":972,"title":"Adylkuzz Cryptocurrency Miner Distribution Campaign","uuid":"bda888f0-8b95-427b-81d5-c0e754b6a6f8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-07-17T18:58:40Z","summary":null,"body":["<article data-history-node-id=\"972\" about=\"\/en\/alerts-advisories\/adylkuzz-cryptocurrency-miner-distribution-campaign\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-007<br \/>\nDate: 18 May 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to, as well as provide guidance and mitigation advice for a Cryptocurrency Miner Distribution Campaign.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC is aware of a cryptocurrency miner campaign, called Adylkuzz, which is spreading in a similar way to the recent WannaCry Ransomware campaign. Open source reports indicate that this malware predates the WannaCry campaign and is being spread using the EternalBlue exploit and DoublePulsar backdoor to typically install the cryptocurrency miner Adylkuzz. Please note that the DoublePulsar backdoor could be used to install other malware and is not limited to the cryptocurrency miner.<\/p>\n\n<p>Symptoms of compromise may include loss of access to shared Windows resources and possible degradation of PC and server performance. Open source reports also indicate that this activity may be larger in scale than WannaCry, affecting hundreds of thousands of PCs and servers worldwide. For this reason, CCIRC highly recommends applying the SMB patches to prevent further exploitation.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<ul><li>Apply the Microsoft patch for the MS17-010 SMB vulnerability dated March 14, 2017.<\/li>\n\t<li>A new patch has been made available for some\u00a0 Microsoft legacy platforms, and is available here: <a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\"><font color=\"#0066cc\">https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks<\/font><\/a><\/li>\n\t<li>If it is not possible to apply the patches, consider disabling SMBv1 and\/or block SMBv1 ports on network devices [UDP 137, 138 and TCP 139, 445].\u00a0 Guidance available here: <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/2696547\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/2696547<\/font><\/a><\/li>\n\t<li>To prevent inbound Internet connections by infected hosts, block SMBv1 ports at your network perimeter.<\/li>\n\t<li>To prevent your own infected hosts from infecting other external networks, block outbound SMBv1 connections at your network perimeter.<\/li>\n\t<li>Ensure antivirus and gateway protections are up to date.<\/li>\n<\/ul><p>Most often, attacks of this type are detected by diligent and well-informed users. CCIRC recommends that organizations ensure users receive current situational awareness and training, including instructions on how to report unusual or suspicious emails to their IT Security Branch. Reviewing departmental policies, requirements and security education and awareness training can help reduce this threat.<\/p>\n\n<h2>References<\/h2>\n\n<ul><li>\n\t<p><a href=\"\/en\/al\/al17-006\">AL17-006 Ransomware \u2013 WannaCry<\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p>Proofpoint:\u00a0 Adylkuzz Cryptocurrency Mining Malware Spreading for Weeks Via EternalBlue\/DoublePulsar<br \/><a href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/adylkuzz-cryptocurrency-mining-malware-spreading-for-weeks-via-eternalblue-doublepulsar\"><font color=\"#0066cc\">https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/adylkuzz-cryptocurrency-mining-malware-spreading-for-weeks-via-eternalblue-doublepulsar<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p>Adylkuzz cryptominer is worse than WannaCry now on the loose<br \/><a href=\"http:\/\/itincanadaonline.ca\/index.php\/security\/2158-adylkuzz-cryptominer-is-worse-than-wannacry-now-on-the-loose\"><font color=\"#0066cc\">http:\/\/itincanadaonline.ca\/index.php\/security\/2158-adylkuzz-cryptominer-is-worse-than-wannacry-now-on-the-loose<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><div class=\"clearfix\">\u00a0<\/div>\n\n<dl id=\"wb-dtmd\"><dt>Date modified:<\/dt>\n\t<dd><time property=\"dateModified\">2017-05-23 <\/time><\/dd>\n<\/dl><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adylkuzz-cryptocurrency-miner-distribution-campaign","alert_type":397,"serial_number":"AL17-007","subject":null,"moderation_state":"archived","external_url":null},{"nid":874,"title":"Ransomware - Petya","uuid":"5df17383-c5e4-4e18-ae19-bf5427267154","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-17T19:09:35Z","summary":null,"body":["<article data-history-node-id=\"874\" about=\"\/en\/alerts-advisories\/ransomware-petya\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL17-008<br \/>\nDate: 27 June 2017<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this alert is to bring attention to, and to provide guidance and mitigation advice for a large scale ransomware campaign.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>CCIRC has become aware of a large ransomware campaign affecting multiple organizations worldwide.\u00a0 While complete details of the campaign are being analyzed, CCIRC is working with domestic and international partners to gain accurate awareness and knowledge of the campaign\u2019s impact to provide the best detection and mitigation information possible.<\/p>\n\n<p>This campaign appears to be distributing a variant of Petya ransomware.\u00a0 The initial infection vector remains unknown at this time.\u00a0 However, exploitation of the SMBv1 vulnerability described and patched in Microsoft Security Bulletin MS17-010 (links provided below) has been noted.<\/p>\n\n<p>Ransomware can have an overwhelming effect on a network, whether it\u2019s a home user, businesses, critical infrastructure or governments.\u00a0 Not only can it lead to loss of sensitive or proprietary information, but the disruption to regular operations, the financial loss and the potential harm to an organization\u2019s reputation can be devastating.<\/p>\n\n<p>CCIRC strongly discourages paying the ransom as it does not guarantee that your data will be decrypted and may encourage further criminal activity. In addition, decrypting files does not mean the malware infection itself has been removed.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that organizations review the following mitigation information and consider their implementation in the context of their network environment.<\/p>\n\n<ul><li>Microsoft released patches in Support Bulletin MS17-010 to address the SMBv1 vulnerability dated March 14, 2017, with more details available in CCIRC Advisory AV17-068.<\/li>\n\t<li>Microsoft released for certain\u00a0 legacy\/unsupported Windows versions, with more details available here: <a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\"><font color=\"#0066cc\">https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks<\/font><\/a><\/li>\n\t<li>Consider disabling SMBv1 and\/or block SMBv1 ports on network devices [UDP 137, 138 and TCP 139, 445].\u00a0 Developer guidance available here: <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/2696547\"><font color=\"#0066cc\">https:\/\/support.microsoft.com\/en-us\/help\/2696547<\/font><\/a><\/li>\n\t<li>Minimize the number of users with administrative privileges and revalidate frequently the requirement for users to have a privileged account.<\/li>\n\t<li>Consider enabling UAC (User Account Control) on Windows hosts throughout your network.<\/li>\n\t<li>Execute daily backups of all critical systems, maintain offline and offsite copies of backup media and periodically execute a practice data restoration from backups, including key databases to ensure integrity of existing backups and processes.<\/li>\n\t<li>Ensure antivirus and gateway protections are up to date.<\/li>\n\t<li>Scan all incoming and outgoing e-mails to detect threats and prevent executable files from reaching the end users.<\/li>\n\t<li>Don\u2019t open links or attachments in emails from untrusted or unknown sources. Inspect the sender address carefully as the address text may differ from the real address.<\/li>\n\t<li>CCIRC recommends that organizations ensure users receive current situational awareness and training, including instructions on how to report unusual or suspicious emails to their IT Security Branch. Reviewing departmental policies, requirements and security education and awareness training can help reduce this threat.<\/li>\n<\/ul><h2>References<\/h2>\n\n<ul><li>\n\t<p><a href=\"\/en\/av\/av17-068\">CCIRC Advisory AV17-068: Microsoft Security Updates MS17-010 (SMBv1)<\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p>Microsoft Security Bulletin MS17-010<br \/><a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx\"><font color=\"#0066cc\">https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p>CCIRC Information Note IN13-004: Ransomware<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2013\/in13-004-eng.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2013\/in13-004-eng.aspx<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p>CCIRC Technical Report TR11-001: Malware Infection Recovery Guide<br \/><a href=\"http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-eng.aspx\"><font color=\"#0066cc\">http:\/\/www.publicsafety.gc.ca\/cnt\/rsrcs\/cybr-ctr\/2011\/tr11-001-eng.aspx<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p>CSE: <a href=\"\/en\/publications\/top-10-it-security-actions-protect-government-canada-internet-connected-networks-and\">Top 10 IT Security Actions to Protect Government of Canada Internet-Connected Networks and Information<\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ransomware-petya","alert_type":397,"serial_number":"AL17-008","subject":null,"moderation_state":"archived","external_url":null},{"nid":1011,"title":"Cisco security updates","uuid":"bf58d148-ceba-49c7-9f64-e1c97db46f69","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-23T14:04:29Z","summary":null,"body":["<article data-history-node-id=\"1011\" about=\"\/en\/alerts-advisories\/cisco-security-updates-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-073<br \/>\nDate: 02 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in various Cisco products.<\/p>\n\n<p>Affected Products:<br \/>\n- Cisco WebEx Advanced Recording Format Remote Code Execution Vulnerability<br \/>\n- Cisco Prime File Upload Servlet Path Traversal and Remote Code Execution Vulnerability<br \/>\n- Cisco Secure Access Control System Remote Code Execution Vulnerability<br \/>\n- Cisco Wireless LAN Controller 802.11 Management Frame Denial of Service Vulnerability<br \/>\n- Cisco Wireless LAN Controller IP Fragment Reassembly Denial of Service Vulnerability<br \/>\n- Cisco Meeting Server Remote Code Execution Vulnerability<br \/>\n- Cisco Aironet 1810, 1830, and 1850 Series Access Points Point-to-Point Tunneling Protocol Denial of Service Vulnerability<br \/>\n- Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability<br \/>\n- Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities<br \/>\n- Cisco 5500 and 8500 Series Wireless LAN Controller Information Disclosure Vulnerability<br \/>\n- Cisco WebEx Advanced Recording Format Player Remote Code Execution Vulnerability<br \/>\n- Cisco WebEx Recording Format Player Information Disclosure Vulnerability<br \/>\n- Cisco Prime Service Catalog User Interface Denial of Service Vulnerability<br \/>\n- Cisco IOS XR Software netconf Denial of Service Vulnerability<br \/>\n- Cisco Firepower System Software Transport Layer Security Extensions Denial of Service Vulnerability<br \/>\n- Cisco Firepower System Software Cross-Origin Domain Protection Vulnerability<br \/>\n- Cisco Firepower System Software Transport Layer Security Denial of Service Vulnerability<br \/>\n- Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability<br \/>\n- Cisco Aironet 1800 Series Access Point 802.11 Denial of Service Vulnerability<br \/>\n- Cisco Wireless LAN Controller and Aironet Access Points IOS WebAuth Client Authentication Bypass Vulnerability<\/p>\n\n<p>CVE References: CVE-2018-0167, CVE-2018-0175, CVE-2018-0226, CVE-2018-0234, CVE-2018-0235, CVE-2018-0245, CVE-2018-0247, CVE-2018-0249, CVE-2018-0250, CVE-2018-0252, CVE-2018-0253, CVE-2018-0258, CVE-2018-0262, CVE-2018-0264, CVE-2018-0278, CVE-2018-0281, CVE-2018-0283, CVE-2018-0285, CVE-2018-0286, CVE-2018-0287, CVE-2018-0288<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-war\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-war<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-prime-upload\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-prime-upload<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-acs1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-acs1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-wlc-mfdos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-wlc-mfdos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-wlc-ip\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-wlc-ip<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-cms-cx\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-cms-cx<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-ap-ptp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-ap-ptp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-aironet-ssh\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-aironet-ssh<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-lldp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180328-lldp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-wlc-id\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-wlc-id<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-webex-rce\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-webex-rce<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-webex-id\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-webex-id<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-psc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-psc<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-iosxr\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-iosxr<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-fpwr-txdos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-fpwr-txdos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-fpwr-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-fpwr-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-fpwr-codp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-fpwr-codp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-ap-acl\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-ap-acl<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-aironet-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-aironet-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-aironet-auth\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180502-aironet-auth<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-13","alert_type":396,"serial_number":"AV18-073","subject":null,"moderation_state":"archived","external_url":null},{"nid":1146,"title":"Microsoft security update \u2013 Out-of-Band","uuid":"2ebc6700-2568-49cb-9ad8-ec0e787c595b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-23T14:28:32Z","summary":null,"body":["<article data-history-node-id=\"1146\" about=\"\/en\/alerts-advisories\/microsoft-security-update-out-band-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-074<br \/>\nDate: 3 May 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Microsoft Security Critical Update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The advisory covers an out-of-band support package deployment addressing a remote code execution vulnerability when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image.<\/p>\n\n<p>Affected Products:<br \/>\n- Windows Host Compute Service Shim<\/p>\n\n<p>CVE References: CVE-2018-8115<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8115\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8115<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-update-out-band-2","alert_type":396,"serial_number":"AV18-074","subject":null,"moderation_state":"archived","external_url":null},{"nid":762,"title":"Microsoft security updates","uuid":"b04cf71f-6959-4652-ba3d-2f5592e771c8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-23T14:38:00Z","summary":null,"body":["<article data-history-node-id=\"762\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-075<br \/>\nDate: 8 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Products Affected:<br \/>\n-Internet Explorer<br \/>\n-Microsoft Edge<br \/>\n-Microsoft Windows<br \/>\n-Microsoft Office and Microsoft Office Services and Web Apps \u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n-ChakraCore\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n-Adobe Flash Player\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n-.NET Framework\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n-Microsoft Exchange Server\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n-Windows Host Compute Service Shim\u00a0\u00a0\u00a0\u00a0\u00a0<\/p>\n\n<p>CVE References: ADV180008, CVE-2018-0765, CVE-2018-0824, CVE-2018-0854, CVE-2018-0943, CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-0958, CVE-2018-0959, CVE-2018-0961, CVE-2018-1021, CVE-2018-1022, CVE-2018-1025, CVE-2018-1039, CVE-2018-8112, CVE-2018-8114, CVE-2018-8119, CVE-2018-8120, CVE-2018-8122, CVE-2018-8123, CVE-2018-8124, CVE-2018-8126, CVE-2018-8127, CVE-2018-8128, CVE-2018-8129, CVE-2018-8130, CVE-2018-8132, CVE-2018-8133, CVE-2018-8134, CVE-2018-8136, CVE-2018-8137, CVE-2018-8139, CVE-2018-8141, CVE-2018-8142, CVE-2018-8145, CVE-2018-8147, CVE-2018-8148, CVE-2018-8149, CVE-2018-8150, CVE-2018-8151, CVE-2018-8152, CVE-2018-8153, CVE-2018-8154, CVE-2018-8155, CVE-2018-8156, CVE-2018-8157, CVE-2018-8158, CVE-2018-8159, CVE-2018-8160, CVE-2018-8161, CVE-2018-8162, CVE-2018-8163, CVE-2018-8164, CVE-2018-8165, CVE-2018-8166, CVE-2018-8167, CVE-2018-8168, CVE-2018-8170, CVE-2018-8173, CVE-2018-8174, CVE-2018-8177, CVE-2018-8178, CVE-2018-8179, CVE-2018-8897 SUGGESTED ACTION<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-11","alert_type":396,"serial_number":"AV18-075","subject":null,"moderation_state":"archived","external_url":null},{"nid":837,"title":"Adobe security bulletins","uuid":"e15562d2-593e-4dd3-ae40-3ee114e615ed","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-07-23T15:02:26Z","summary":null,"body":["<article data-history-node-id=\"837\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-076<br \/>\nDate: 08 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for Creative Cloud Desktop Application, Adobe Flash Player, Adobe Connect.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Creative Cloud Desktop Application - version 4.4.1.298 and earlier<\/li>\n\t<li>Adobe Flash Player - version 29.0.0.140 and earlier<\/li>\n\t<li>Adobe Connect - version 9.7.5 and earlier<\/li>\n<\/ul><p>CVE References: CVE-2018-4992, CVE-2018-4991, CVE-2018-4873, CVE-2018-4944, CVE-2018-4994<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb18-12.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb18-12.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-16.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-16.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb18-18.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb18-18.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-2","alert_type":396,"serial_number":"AV18-076","subject":null,"moderation_state":"archived","external_url":null},{"nid":866,"title":"Mozilla security updates","uuid":"49f5496d-5f98-491f-a082-c5ac951f992f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-23T15:09:19Z","summary":null,"body":["<article data-history-node-id=\"866\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-077<br \/>\nDate: 09 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update addressing multiple vulnerabilities in Mozilla Firefox.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla have released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Firefox ESR versions prior to 52.8\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/li>\n\t<li>Firefox versions prior to 60<\/li>\n<\/ul><p>CVE References:\u00a0 CVE-2018-5154, CVE-2018-5155, CVE-2018-5157, CVE-2018-5158, CVE-2018-5159, CVE-2018-5160, CVE-2018-5152, CVE-2018-5153, CVE-2018-5163, CVE-2018-5164, CVE-2018-5166, CVE-2018-5167, CVE-2018-5168, CVE-2018-5169, CVE-2018-5172, CVE-2018-5173, CVE-2018-5174,<br \/>\nCVE-2018-5175, CVE-2018-5176, CVE-2018-5177, CVE-2018-5165, CVE-2018-5180, CVE-2018-5181, CVE-2018-5182, CVE-2018-5151, CVE-2018-5150, CVE-2018-5183, CVE-2018-5154, CVE-2018-5155, CVE-2018-5157, CVE-2018-5158, CVE-2018-5159, CVE-2018-5168, CVE-2018-5174, CVE-2018-5178, CVE-2018-5150<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-12\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-12\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-11\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-11\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-9","alert_type":396,"serial_number":"AV18-077","subject":null,"moderation_state":"archived","external_url":null},{"nid":979,"title":"7-Zip security update","uuid":"9854d78f-ba1d-4b85-b1d9-4e2dab38071d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-23T15:15:36Z","summary":null,"body":["<article data-history-node-id=\"979\" about=\"\/en\/alerts-advisories\/7-zip-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-078<br \/>\nDate: 11 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security update released by 7-Zip.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>7-Zip has released a product update addressing a security vulnerability where a remote user can create a file that, when processed by the target user or application, will execute arbitrary code on the target system.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>7-Zip versions prior to 18.05<\/li>\n<\/ul><p>CVE References: CVE-2018-10115<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2018-10115\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2018-10115<\/font><\/a><br \/><a href=\"https:\/\/nakedsecurity.sophos.com\/2018\/05\/09\/critical-bug-in-7-zip-make-sure-youre-up-to-date\/\"><font color=\"#0066cc\">https:\/\/nakedsecurity.sophos.com\/2018\/05\/09\/critical-bug-in-7-zip-make-sure-youre-up-to-date\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/7-zip-security-update-0","alert_type":396,"serial_number":"AV18-078","subject":null,"moderation_state":"archived","external_url":null},{"nid":1139,"title":"Google Releases security update for Chrome","uuid":"d56247bd-dce4-441e-81c1-da7cbb6326a4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-23T15:21:19Z","summary":null,"body":["<article data-history-node-id=\"1139\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-34\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-079<br \/>\nDate: 11 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 66.0.3359.170 for Windows, Mac, and Linux.<\/p>\n\n<p>CVE References: CVE-2018-6120, CVE-2018-6121, CVE-2018-122<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-34","alert_type":396,"serial_number":"AV18-079","subject":null,"moderation_state":"archived","external_url":null},{"nid":1158,"title":"Android security bulletin \u2013 May 2018","uuid":"f2ff647e-bad2-47eb-8321-83b72520a20a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:44Z","date_created":"2018-07-23T15:26:50Z","summary":null,"body":["<article data-history-node-id=\"1158\" about=\"\/en\/alerts-advisories\/android-security-bulletin-may-2018\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-080<br \/>\nDate: 11 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the Android Security Bulletin for May.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for 23 vulnerabilities (2 Critical and 21 High). Successful exploitation could allow for a remote unauthenticated user to gain privilege escalation and allow remote code execution.<\/p>\n\n<p>CVE References: CVE-2018-3562, CVE-2018-3565, CVE-2018-3578, CVE-2018-3580, CVE-2017-5715, CVE-2017-5754, CVE-2018-5840, CVE-2018-5841, CVE-2018-5845, CVE-2018-5846, CVE-2018-5850, CVE-2017-6289, CVE-2017-6293, CVE-2017-13077, CVE-2017-13309, CVE-2017-13310, CVE-2017-13311, CVE-2017-13312, CVE-2017-13313, CVE-2017-13314, CVE-2017-13315, CVE-2017-16643, CVE-2017-18154<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators check with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected devices accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p>Android Security Bulletin:<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2018-05-01\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2018-05-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-may-2018","alert_type":396,"serial_number":"AV18-080","subject":null,"moderation_state":"archived","external_url":null},{"nid":1249,"title":"Adobe security bulletins","uuid":"33a6d685-7cac-435a-962c-f419c29ff34c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-23T15:38:08Z","summary":null,"body":["<article data-history-node-id=\"1249\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-081<br \/>\nDate: 14 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for Adobe Photoshop, Adobe Acrobat and Acrobat Reader for Windows and MacOS.<\/p>\n\n<p>Affected products:<br \/>\n- Acrobat DC &amp; 2017<br \/>\n- Acrobat Reader DC &amp; 2017<br \/>\n- Photoshop CC 2017 &amp; 2018<\/p>\n\n<p>CVE References: CVE-2018-4990, CVE-2018-4947, CVE-2018-4948, CVE-2018-4966, CVE-2018-4968, CVE-2018-4978, CVE-2018-4982, CVE-2018-4984, CVE-2018-4946, CVE-2018-4952, CVE-2018-4954, CVE-2018-4958, CVE-2018-4959, CVE-2018-4961, CVE-2018-4971, CVE-2018-4974, CVE-2018-4977, CVE-2018-4980, CVE-2018-4983, CVE-2018-4988, CVE-2018-4989, CVE-2018-4950, CVE-2018-4979, CVE-2018-4949, CVE-2018-4951, CVE-2018-4955, CVE-2018-4956, CVE-2018-4957, CVE-2018-4960, CVE-2018-4962, CVE-2018-4963, CVE-2018-4964, CVE-2018-4967, CVE-2018-4969, CVE-2018-4970, CVE-2018-4972, CVE-2018-4973, CVE-2018-4975, CVE-2018-4976, CVE-2018-4981, CVE-2018-4986, CVE-2018-4985, CVE-2018-4953, CVE-2018-4987, CVE-2018-4965, CVE-2018-4993, CVE-2018-4994, CVE-2018-4946<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-09.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-09.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb18-17.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb18-17.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-3","alert_type":396,"serial_number":"AV18-081","subject":null,"moderation_state":"archived","external_url":null},{"nid":859,"title":"[Control System] Rockwell Automation security update","uuid":"ea885e41-e35d-4893-9590-d75e4e702525","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-23T15:46:03Z","summary":null,"body":["<article data-history-node-id=\"859\" about=\"\/en\/alerts-advisories\/control-system-rockwell-automation-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-082<br \/>\nDate: 15 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to vulnerabilities affecting Rockwell Automation\u2019s FactoryTalk Activation Manager Products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation has released a security advisory to address vulnerabilities in products which use the FactoryTalk Activation Manager, including Cross-Site Scripting (XSS) and improper bounds checking on incoming data. Successful exploitation of these vulnerabilities could allow a remote attacker to access sensitive information, rewrite content, or cause a buffer overflow that could result in remote code execution.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>FactoryTalk Activation Manager v4.00 and v4.01 (Ships with Wibu-Systems CodeMeter v6.50b and earlier)<\/li>\n\t<li>FactoryTalk Activation Manager v4.00 and earlier(Ships with FlexNet Publisher v11.11.1.1 and earlier)<\/li>\n<\/ul><p>The following products require FactoryTalk Activation Manager to store and keep track of Rockwell Automation software products and activation files. Users who recognize products from the following list are using FactoryTalk Activation Manager:<\/p>\n\n<ul><li>Arena<\/li>\n\t<li>Emonitor<\/li>\n\t<li>FactoryTalk AssetCentre<\/li>\n\t<li>FactoryTalk Batch<\/li>\n\t<li>FactoryTalk EnergyMetrix<\/li>\n\t<li>FactoryTalk eProcedure<\/li>\n\t<li>FactoryTalk Gateway<\/li>\n\t<li>FactoryTalk Historian Classic<\/li>\n\t<li>FactoryTalk Historian Site Edition (SE)<\/li>\n\t<li>FactoryTalk Information Server<\/li>\n\t<li>FactoryTalk Metrics<\/li>\n\t<li>FactoryTalk Transaction Manager<\/li>\n\t<li>FactoryTalk VantagePoint<\/li>\n\t<li>FactoryTalk View Machine Edition (ME)<\/li>\n\t<li>FactoryTalk View Site Edition (SE)<\/li>\n\t<li>FactoryTalk ViewPoint<\/li>\n\t<li>RSFieldBus<\/li>\n\t<li>RSLinx Classic<\/li>\n\t<li>RSLogix 500<\/li>\n\t<li>RSLogix 5000<\/li>\n\t<li>RSLogix5<\/li>\n\t<li>RSLogix Emulate 5000<\/li>\n\t<li>RSNetWorx<\/li>\n\t<li>RSView32<\/li>\n\t<li>SoftLogix 5800<\/li>\n\t<li>Studio 5000 Architect<\/li>\n\t<li>Studio 5000 Logix Designer<\/li>\n\t<li>Studio 5000 Logix Emulate<\/li>\n\t<li>Studio 5000 View Designer<\/li>\n<\/ul><p>CVE References: CVE-2015-8277, CVE-2017-13754<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly. Rockwell Automation also encourages users to combine the updates above with these general security guidelines to employ multiple strategies simultaneously.<\/p>\n\n<ul><li>Block all traffic to EtherNet\/IP or other CIP protocol-based devices from outside the Manufacturing Zone by blocking or restricting access to Port 2222\/TCP and UDP and Port 44818\/TCP and UDP, using proper network infrastructure controls, such as firewalls, UTM devices, or other security appliances. For more information on TCP\/UDP ports used by Rockwell Automation Products, see Knowledgebase Article ID 898270 available at: <a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/898270\/page\/1\"><font color=\"#0066cc\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/898270\/page\/1<\/font><\/a> (Login required)<\/li>\n\t<li>Minimize network exposure for all control system devices and\/or systems, and ensure they are not accessible from the Internet.<\/li>\n\t<li>Locate control system networks and devices behind firewalls and isolate them from the business network.<\/li>\n\t<li>When remote access is required, use secure methods such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. VPN is only as secure as the connected devices.<\/li>\n<\/ul><p><strong>References:<\/strong><\/p>\n\n<p>ICS-CERT: ICSA-18-102-02 - Rockwell Automation FactoryTalk Activation Manager: <a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-102-02\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-102-02<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-system-rockwell-automation-security-update","alert_type":398,"serial_number":"AV18-082","subject":null,"moderation_state":"archived","external_url":null},{"nid":1001,"title":"RedHat DHCP Client security update","uuid":"5aef9f32-597b-450d-ac7d-67ee424c6e9c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-23T15:52:32Z","summary":null,"body":["<article data-history-node-id=\"1001\" about=\"\/en\/alerts-advisories\/redhat-dhcp-client-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-083<br \/>\nDate: 16 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a RedHat DHCP Client Security Update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>RedHat has released updates to address code execution vulnerability in the DHCP client. Exploitation of these vulnerabilities may allow an attacker to bypass certain security restrictions and perform unauthorized actions.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Red Hat Enterprise Linux 6 and 7<\/li>\n<\/ul><h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1567974\"><font color=\"#0066cc\">https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1567974<\/font><\/a><br \/><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/3442151\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/vulnerabilities\/3442151<\/font><\/a><br \/><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2018-1111\"><font color=\"#0066cc\">https:\/\/access.redhat.com\/security\/cve\/cve-2018-1111<\/font><\/a>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/redhat-dhcp-client-security-update","alert_type":396,"serial_number":"AV18-083","subject":null,"moderation_state":"archived","external_url":null},{"nid":1131,"title":"Cisco security updates","uuid":"a40a8b1f-c500-45f0-a898-a23dd3e1064b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:22Z","date_created":"2018-07-23T17:47:24Z","summary":null,"body":["<article data-history-node-id=\"1131\" about=\"\/en\/alerts-advisories\/cisco-security-updates-14\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-084<br \/>\nDate: 17 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in various Cisco products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Cisco Enterprise NFV Infrastructure Software CLI Command Injection Vulnerability<\/li>\n\t<li>Cisco Digital Network Architecture Center Authentication Bypass Vulnerability<\/li>\n\t<li>Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability<\/li>\n\t<li>Cisco Enterprise NFV Infrastructure Software Web Management Interface Path Traversal Vulnerability<\/li>\n\t<li>Cisco IP Phone 7800 Series and 8800 Series Denial of Service Vulnerability<\/li>\n\t<li>Cisco Firepower Threat Defense Software Policy Bypass Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine EAP TLS Certificate Denial of Service Vulnerability<\/li>\n\t<li>Cisco IoT Field Network Director Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine Logs Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Digital Network Architecture Center Unauthorized Access Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine Logs Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco IoT Field Network Director Cross-Site Request Forgery Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine EAP TLS Certificate Denial of Service Vulnerability<\/li>\n\t<li>Cisco SocialMiner Notification System Denial of Service Vulnerability<\/li>\n\t<li>Cisco TelePresence Server Cross-Frame Scripting Vulnerability<\/li>\n\t<li>Cisco Meeting Server Media Services Denial of Service Vulnerability<\/li>\n\t<li>CPU Side-Channel Information Disclosure Vulnerabilities<\/li>\n<\/ul><p>CVE References: CVE-2018-0222, CVE-2018-0268, CVE-2018-0270, CVE-2018-0271, CVE-2018-0277, CVE-2018-0279, CVE-2018-0289, CVE-2018-0290, CVE-2018-0297, CVE-2018-0323, CVE-2018-0324, CVE-2018-0325, CVE-2018-0327, CVE-2018-0328, CVE-2017-5715, CVE-2017-5753, CVE-2017-5754<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-nfvis-cli-command-injection\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-nfvis-cli-command-injection<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-dna2\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-dna2<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-nfvis\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-nfvis<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-nfvis-path-traversal\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-nfvis-path-traversal<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ip-phone-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ip-phone-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-firepwr-pb\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-firepwr-pb<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-iseeap\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-iseeap<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-fnd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-fnd<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ise-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ise-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-dna\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-dna<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ise-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ise-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-iseeap\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-iseeap<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-firepwr-pb\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-firepwr-pb<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ip-phone-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-ip-phone-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-telepres-xfs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-telepres-xfs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-msms\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-msms<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180104-cpusidechannel\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180104-cpusidechannel<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-14","alert_type":396,"serial_number":"AV18-084","subject":null,"moderation_state":"archived","external_url":null},{"nid":1174,"title":"[Control System] Advantech WebAccess security update","uuid":"c1ee2448-06ae-4fb8-a5ad-8cf6c36274ff","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-23T17:53:26Z","summary":null,"body":["<article data-history-node-id=\"1174\" about=\"\/en\/alerts-advisories\/control-system-advantech-webaccess-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-085<br \/>\nDate: 17 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>Advantech WebAccess Security Update<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Advantech has released updates to address eight vulnerabilities, including but not limited to, SQL injection, improper authorization, and path traversal in the WebAccess products.<br \/>\nExploitation of these vulnerabilities may allow a remote unauthenticated user to disclose sensitive information from the host, execute arbitrary code, or delete files.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>WebAccess versions V8.2_20170817 and prior<\/li>\n\t<li>WebAccess versions V8.3.0 and prior<\/li>\n\t<li>WebAccess Dashboard versions V.2.0.15 and prior<\/li>\n\t<li>WebAccess Scada Node versions prior to 8.3.1<\/li>\n\t<li>WebAccess\/NMS 2.0.3 and prior<\/li>\n<\/ul><h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"http:\/\/support.advantech.com\/support\/DownloadSRDetail_New.aspx?SR_ID=1-MS9MJV&amp;Doc_Source=Download\"><font color=\"#0066cc\">http:\/\/support.advantech.com\/support\/DownloadSRDetail_New.aspx?SR_ID=1-MS9MJV&amp;Doc_Source=Download<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-135-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-135-01<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-system-advantech-webaccess-security-update","alert_type":398,"serial_number":"AV18-085","subject":null,"moderation_state":"archived","external_url":null},{"nid":803,"title":"Joomla! security update","uuid":"b4ce32b8-847c-4856-9655-33e805a0f439","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-23T18:01:19Z","summary":null,"body":["<article data-history-node-id=\"803\" about=\"\/en\/alerts-advisories\/joomla-security-update-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-086<br \/>\nDate: 23 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for Joomla!.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Joomla! has released version 3.8.8\u00a0 of its web content management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected:<br \/>\n- Joomla! 3.8.7 and earlier.<\/p>\n\n<p>CVE References:\u00a0 CVE-2018-6378, CVE-2018-11321, CVE-2018-11322, CVE-2018-11323, CVE-2018-11324, CVE-2018-11325, CVE-2018-11326, CVE-2018-11327, CVE-2018-11328<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5730-joomla-3-8-8-release.html\"><font color=\"#0066cc\">https:\/\/www.joomla.org\/announcements\/release-news\/5730-joomla-3-8-8-release.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/joomla-security-update-6","alert_type":396,"serial_number":"AV18-086","subject":null,"moderation_state":"archived","external_url":null},{"nid":1278,"title":"Google Releases security update for Chrome","uuid":"baf09b4a-8d6e-456b-ba65-9dc3fb4b2024","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:07Z","date_created":"2018-07-23T18:07:20Z","summary":null,"body":["<article data-history-node-id=\"1278\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-35\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-087<br \/>\nDate: 30 May 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update 67.0.3396.62.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 67.0.3396.62 for Windows, Mac, and Linux.<\/p>\n\n<p>CVE References: \u00a0CVE-2018-6123, CVE-2018-6124, CVE-2018-6125, CVE-2018-6126, CVE-2018-6127, CVE-2018-6128, CVE-2018-6129, CVE-2018-6130, CVE-2018-6131, CVE-2018-6132, CVE-2018-6133, CVE-2018-6134, CVE-2018-6135, CVE-2018-6136, CVE-2018-6137, CVE-2018-6138, CVE-2018-6139, CVE-2018-6140, CVE-2018-6141, CVE-2018-6142, CVE-2018-6143, CVE-2018-6144, CVE-2018-6145, CVE-2018-6147<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. Guidance on recommended deployment timeframes is available in CSE IT Security Bulletin ITSB-96, \"Assessing Security Vulnerabilities and Patches - Guidance for the Government of Canada\", available at: <a href=\"https:\/\/www.cse-cst.gc.ca\/en\/publication\/itsb-96\"><font color=\"#0066cc\">https:\/\/www.cse-cst.gc.ca\/en\/publication\/itsb-96<\/font><\/a><\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-35","alert_type":396,"serial_number":"AV18-087","subject":null,"moderation_state":"archived","external_url":null},{"nid":864,"title":"Apple security updates","uuid":"6efbfb47-f796-4d2c-a28e-8e28024d593d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-07-23T18:16:37Z","summary":null,"body":["<article data-history-node-id=\"864\" about=\"\/en\/alerts-advisories\/apple-security-updates-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-088<br \/>\nDate: 04 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates by Apple.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released security updates for vulnerabilities in various Apple products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>iCloud for Windows<\/li>\n\t<li>Safari<\/li>\n\t<li>macOS El Capitan<\/li>\n\t<li>Sierra<\/li>\n\t<li>macOS High Sierra<\/li>\n<\/ul><p>CVE Reference: \u00a0CVE-2018-4141, CVE-2018-4159, CVE-2018-4171, CVE-2018-4184, CVE-2018-4188, CVE-2018-4190, CVE-2018-4192, CVE-2018-4193, CVE-2018-4196, CVE-2018-4198, CVE-2018-4199, CVE-2018-4200, CVE-2018-4201, CVE-2018-4202, CVE-2018-4204, CVE-2018-4205, CVE-2018-4211, CVE-2018-4214, CVE-2018-4218, CVE-2018-4219, CVE-2018-4221, CVE-2018-4222, CVE-2018-4223, CVE-2018-4224, CVE-2018-4225, CVE-2018-4226, CVE-2018-4227, CVE-2018-4228, CVE-2018-4229, CVE-2018-4230, CVE-2018-4232, CVE-2018-4233, CVE-2018-4234, CVE-2018-4235, CVE-2018-4236, CVE-2018-4237, CVE-2018-4240, CVE-2018-4241, CVE-2018-4242, CVE-2018-4243, CVE-2018-4246, CVE-2018-4247, CVE-2018-4249, CVE-2018-4251, CVE-2018-4253, CVE-2018-7584, CVE-2018-8897<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT201222<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-11","alert_type":396,"serial_number":"AV18-088","subject":null,"moderation_state":"archived","external_url":null},{"nid":1013,"title":"Cisco security updates","uuid":"6c4b7ee3-4f42-44cf-bb49-3cdc52334656","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-24T12:44:37Z","summary":null,"body":["<article data-history-node-id=\"1013\" about=\"\/en\/alerts-advisories\/cisco-security-updates-15\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-089<br \/>\nDate: 6 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities (medium to critical) in various Cisco products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Cisco Prime Collaboration Provisioning Unauthenticated Remote Method Invocation Vulnerability<\/li>\n\t<li>Cisco IOS XE Software Authentication, Authorization, and Accounting Login Authentication Remote Code Execution Vulnerability<\/li>\n\t<li>Cisco Web Security Appliance Layer 4 Traffic Monitor Security Bypass Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning SQL Injection Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Unauthorized Password Reset Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Unauthorized Password Recovery Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Access Control Bypass Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Access Control Vulnerability<\/li>\n\t<li>Cisco Network Services Orchestrator Arbitrary Command Execution Vulnerability<\/li>\n\t<li>Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Session Initiation Protocol Denial of Service Vulnerability<\/li>\n\t<li>Cisco Products Disk Utilization Denial of Service Vulnerability<\/li>\n\t<li>Cisco Meeting Server Information Disclosure Vulnerability<\/li>\n\t<li>Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability<\/li>\n\t<li>Cisco WebEx Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Wide Area Application Services Software Static SNMP Credentials Vulnerability<\/li>\n\t<li>Cisco Wide Area Application Services Software Disk Check Tool Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Integrated Management Controller Supervisor and Cisco UCS Director DOM Stored Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified Computing System Role-Based Access Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Access Control Deficiency in Batch Function Privilege Escalation Vulnerability<\/li>\n\t<li>Cisco Identity Services Engine Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Unified IP Phone Software Denial of Service Vulnerability<\/li>\n\t<li>Cisco Unified Communications Manager Cross-Frame Scripting Vulnerability<\/li>\n\t<li>Cisco Unity Connection Cross-Site Scripting Vulnerability<\/li>\n\t<li>Cisco Prime Collaboration Provisioning Cleartext Passwords Written to World-Readable File Vulnerability<\/li>\n\t<li>Cisco FireSIGHT System VPN Policy Bypass Vulnerability<\/li>\n\t<li>Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability<\/li>\n<\/ul><p>CVE References: CVE-2018-0149,CVE-2018-0263,CVE-2018-0274,CVE-2018-0296,CVE-2018-0315,CVE-2018-0316,CVE-2018-0317,CVE-2018-0318,CVE-2018-0319,CVE-2018-0320,CVE-2018-0321,CVE-2018-0322,CVE-2018-0329,CVE-2018-0332,CVE-2018-0333,CVE-2018-0334,CVE-2018-0335,CVE-2018-0336,CVE-2018-0338,CVE-2018-0339,CVE-2018-0340,CVE-2018-0352,CVE-2018-0353,CVE-2018-0354,CVE-2018-0355,CVE-2018-0356,CVE-2018-0357<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-rmi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-rmi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-aaa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-aaa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-wsa\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-wsa<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-sql\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-sql<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-password-reset\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-password-reset<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-password-recovery\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-password-recovery<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-bypass\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-bypass<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-access\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-access<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-nso\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-nso<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-multiplatform-sip\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-multiplatform-sip<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-diskdos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-diskdos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cms-id\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cms-id<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-asaftd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-asaftd<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-webex-xss1\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-webex-xss1<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-webex-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-webex-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-waas-snmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-waas-snmp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-waas-priv-escalation\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-waas-priv-escalation<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ucsdimcs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ucsdimcs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ucs-access\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ucs-access<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ucm-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ucm-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-escalation\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-prime-escalation<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ise-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ise-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ip-phone-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-ip-phone-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cucm-xfs\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cucm-xfs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cuc-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cuc-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cpcp-id\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-cpcp-id<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-FireSIGHT-vpn-bypass\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-FireSIGHT-vpn-bypass<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-AnyConnect-cert-bypass\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-AnyConnect-cert-bypass<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-15","alert_type":396,"serial_number":"AV18-089","subject":null,"moderation_state":"archived","external_url":null},{"nid":1148,"title":"VMware security advisory","uuid":"035d5a08-ae0f-40b6-af25-02f8f6eaf0a1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-24T13:21:21Z","summary":null,"body":["<article data-history-node-id=\"1148\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-090<br \/>\nDate: 7 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released a product update for Horizon Client for Linux to address a privilege escalation vulnerability. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed.<\/p>\n\n<p>Affected Product:<br \/>\n- Horizon Client for Linux versions 4.x and prior<\/p>\n\n<p>CVE Reference: CVE-2018-6964<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>Reference:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0014.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0014.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-10","alert_type":396,"serial_number":"AV18-090","subject":null,"moderation_state":"archived","external_url":null},{"nid":764,"title":"Adobe security bulletins","uuid":"4b58d605-b72e-4652-a820-5d8bc3dcbcf4","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-24T13:27:03Z","summary":null,"body":["<article data-history-node-id=\"764\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-091<br \/>\nDate: 7 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for Adobe Flash Player for Windows, MacOS, Linux and Chrome OS.<\/p>\n\n<p>Affected products:<br \/>\nAdobe Flash Player 29.0.0.171 and earlier.<\/p>\n\n<p>CVE References: CVE-2018-4945, CVE-2018-5000, CVE-2018-5001, CVE-2018-5002<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-19.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-19.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-4","alert_type":396,"serial_number":"AV18-091","subject":null,"moderation_state":"archived","external_url":null},{"nid":839,"title":"Mozilla Releases security update","uuid":"d7a35dae-a03c-4057-b262-0274097ae1ab","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-07-24T13:34:08Z","summary":null,"body":["<article data-history-node-id=\"839\" about=\"\/en\/alerts-advisories\/mozilla-releases-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-092<br \/>\nDate: 07 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>Mozilla Releases Security Update<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla have released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Firefox 60.0.2 and prior versions<\/li>\n\t<li>Firefox ESR 52.8.1<\/li>\n\t<li>Firefox ESR 60.0.2<\/li>\n<\/ul><p>CVE Reference: CVE-2018-6126<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-14\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-14\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-releases-security-update-0","alert_type":396,"serial_number":"AV18-092","subject":null,"moderation_state":"archived","external_url":null},{"nid":868,"title":"Google Releases security update for Chrome","uuid":"71824448-0ba6-41ff-860c-6cfc7bd5c7a2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-24T13:39:26Z","summary":null,"body":["<article data-history-node-id=\"868\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-36\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-093<br \/>\nDate: 08 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 67.0.3396.79 for Windows, Mac, and Linux.<\/p>\n\n<p>CVE Reference:\u00a0 CVE-2018-6148<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-36","alert_type":396,"serial_number":"AV18-093","subject":null,"moderation_state":"archived","external_url":null},{"nid":981,"title":"Android security bulletin","uuid":"cc13c337-c5e5-489c-91a3-e6ca6bca96ec","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-24T13:47:18Z","summary":null,"body":["<article data-history-node-id=\"981\" about=\"\/en\/alerts-advisories\/android-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-094<br \/>\nDate: 12 June 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Android Security Bulletin for June 2018.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Android Security Bulletin addresses security updates for multiple vulnerabilities. Successful exploitation could result in remote code execution.<\/p>\n\n<p>CVE References: CVE-2017-13077, CVE-2017-13227, CVE-2017-13230, CVE-2017-17558, CVE-2017-17806, CVE-2017-17807, CVE-2017-18155, CVE-2017-18156, CVE-2017-18157, CVE-2017-18158, CVE-2017-18158, CVE-2017-18159, CVE-2017-6290, CVE-2017-6292, CVE-2017-6294, CVE-2018-3569, CVE-2018-5146, CVE-2018-5829, CVE-2018-5830, CVE-2018-5831, CVE-2018-5834, CVE-2018-5835, CVE-2018-5854, CVE-2018-5884, CVE-2018-5885, CVE-2018-5891, CVE-2018-5892, CVE-2018-5894, CVE-2018-5896, CVE-2018-9339, CVE-2018-9340, CVE-2018-9341, CVE-2018-9344, CVE-2018-9345, CVE-2018-9346, CVE-2018-9347, CVE-2018-9348, CVE-2018-9355, CVE-2018-9356, CVE-2018-9357, CVE-2018-9358, CVE-2018-9359, CVE-2018-9360, CVE-2018-9361, CVE-2018-9362, CVE-2018-9363, CVE-2018-9364, CVE-2018-9366, CVE-2018-9367, CVE-2018-9368, CVE-2018-9369, CVE-2018-9370, CVE-2018-9371, CVE-2018-9372, CVE-2018-9373, CVE-2018-9409, CVE-2018-9338<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2018-06-01\"><font color=\"#0066cc\">https:\/\/source.android.com\/security\/bulletin\/2018-06-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin","alert_type":396,"serial_number":"AV18-094","subject":null,"moderation_state":"archived","external_url":null},{"nid":1143,"title":"Microsoft security updates","uuid":"463ef329-f008-43ec-88cc-cf48c5cbd8e9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-24T13:55:25Z","summary":null,"body":["<article data-history-node-id=\"1143\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-095<br \/>\nDate: 12 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft Security Updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>Internet Explorer<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Windows<\/li>\n\t<li>Microsoft Office and Microsoft Office Services and Web Apps<\/li>\n\t<li>ChakraCore<\/li>\n\t<li>Adobe Flash Player<\/li>\n\t<li>Microsoft guidance for CBC Symmetric Encryption Security Feature Bypass<\/li>\n<\/ul><p>CVE References: CVE-2018-0871, CVE-2018-0978, CVE-2018-0982, CVE-2018-1036, CVE-2018-1040, CVE-2018-8110, CVE-2018-8111, CVE-2018-8113, CVE-2018-8121, CVE-2018-8140, CVE-2018-8169, CVE-2018-8175, CVE-2018-8201, CVE-2018-8205, CVE-2018-8207, CVE-2018-8208, CVE-2018-8209, CVE-2018-8210, CVE-2018-8211, CVE-2018-8212, CVE-2018-8213, CVE-2018-8214, CVE-2018-8215, CVE-2018-8216, CVE-2018-8217, CVE-2018-8218, CVE-2018-8219, CVE-2018-8221, CVE-2018-8224, CVE-2018-8225, CVE-2018-8226, CVE-2018-8227, CVE-2018-8229, CVE-2018-8231, CVE-2018-8233, CVE-2018-8234, CVE-2018-8235, CVE-2018-8236, CVE-2018-8239, CVE-2018-8243, CVE-2018-8244, CVE-2018-8245, CVE-2018-8246, CVE-2018-8247, CVE-2018-8248, CVE-2018-8249, CVE-2018-8251, CVE-2018-8252, CVE-2018-8254, CVE-2018-8267<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a>\u00a0\u00a0<\/li>\n\t<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/security-updates\/securityadvisories\/2018\/4338110\"><font color=\"#0066cc\">https:\/\/docs.microsoft.com\/en-us\/security-updates\/securityadvisories\/2018\/4338110<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-12","alert_type":396,"serial_number":"AV18-095","subject":null,"moderation_state":"archived","external_url":null},{"nid":1160,"title":"VMware security advisory","uuid":"49f94fea-9f2d-4167-a8e5-43cbb6fd4637","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:44Z","date_created":"2018-07-24T14:26:44Z","summary":null,"body":["<article data-history-node-id=\"1160\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-096<br \/>\nDate:12 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released a product update for VMware AirWatch Agent updates to address remote code execution vulnerability.<\/p>\n\n<p>Affected Product:<\/p>\n\n<ul><li>VMWare AirWatch Agent for Android version 8.2 and prior<\/li>\n\t<li>VMWare AirWatch Agent for Windows Mobile version 6.5.2 and prior<\/li>\n<\/ul><p>CVE Reference: CVE-2018-6968<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0015.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0015.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-11","alert_type":396,"serial_number":"AV18-096","subject":null,"moderation_state":"archived","external_url":null},{"nid":1255,"title":"Fortinet security advisory","uuid":"96e6668f-894c-49c6-b7c6-c18f5c9567c7","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-24T14:36:52Z","summary":null,"body":["<article data-history-node-id=\"1255\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-097<br \/>\nDate: 13 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by Fortinet.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Fortinet has released a product update for FortiWLC which addresses a Hardcoded credential critical vulnerability.<\/p>\n\n<p>Affected Product:<\/p>\n\n<ul><li>FortiWLC 7.0.11 and lower in the 7.x branch<\/li>\n\t<li>FortiWLC 8.3.3 and lower in the 8.x branch<\/li>\n<\/ul><p>CVE References: CVE-2018-17539, CVE-2018-17540<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-17-274\"><font color=\"#0066cc\">https:\/\/fortiguard.com\/psirt\/FG-IR-17-274<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2017-17539\"><font color=\"#0066cc\">http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2017-17539<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2017-17540\"><font color=\"#0066cc\">http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2017-17540<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory","alert_type":396,"serial_number":"AV18-097","subject":null,"moderation_state":"archived","external_url":null},{"nid":861,"title":"Moodle security advisory","uuid":"9df7db41-1739-401f-9ef1-2724b9995941","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-24T14:46:25Z","summary":null,"body":["<article data-history-node-id=\"861\" about=\"\/en\/alerts-advisories\/moodle-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-098<br \/>\nDate: 13 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by Moodle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Moodle has released a product update to address remote code execution vulnerability.<\/p>\n\n<p>Affected Product:<br \/>\nMoodle versions prior to 3.5.0<\/p>\n\n<p>CVE Reference: CVE-2018-1133<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/blog.ripstech.com\/2018\/moodle-remote-code-execution\/\"><font color=\"#0066cc\">https:\/\/blog.ripstech.com\/2018\/moodle-remote-code-execution\/<\/font><\/a><br \/><a href=\"https:\/\/github.com\/moodle\/moodle\/releases\/tag\/v3.5.0\"><font color=\"#0066cc\">https:\/\/github.com\/moodle\/moodle\/releases\/tag\/v3.5.0<\/font><\/a><br \/><a href=\"https:\/\/moodle.org\/mod\/forum\/discuss.php?d=371199#p1496353\"><font color=\"#0066cc\">https:\/\/moodle.org\/mod\/forum\/discuss.php?d=371199#p1496353<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moodle-security-advisory","alert_type":396,"serial_number":"AV18-098","subject":null,"moderation_state":"archived","external_url":null},{"nid":997,"title":"Google Releases security update for Chrome","uuid":"a6f694c3-2da3-455e-aa20-7e7d8a11631d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-24T14:51:50Z","summary":null,"body":["<article data-history-node-id=\"997\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-37\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-099<br \/>\nDate: 13 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 67.0.3396.87 for Windows, Mac, and Linux.<\/p>\n\n<p>CVE Reference:\u00a0 CVE-2018-6149<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-37","alert_type":396,"serial_number":"AV18-099","subject":null,"moderation_state":"archived","external_url":null},{"nid":1123,"title":"Intel Releases security advisory for Microprocessors","uuid":"bbb06325-3a7a-45da-bfb1-53f02fd357c5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:22Z","date_created":"2018-07-24T15:00:31Z","summary":null,"body":["<article data-history-node-id=\"1123\" about=\"\/en\/alerts-advisories\/intel-releases-security-advisory-microprocessors\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-100<br \/>\nDate: 14 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Intel security advisory regarding the Lazy FP state restore vulnerability affecting Intel Core-based microprocessors.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>System software may opt to utilize Lazy FP which is potentially vulnerable to exploits<br \/>\nwhere one process may infer register values of other processes through a speculative<br \/>\nexecution side channel that infers their value. Unauthenticated actors could take advantage of this vulnerability and acquire sensitive encryption keys.\u00a0<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Intel\u00ae Core-based microprocessors<\/li>\n<\/ul><p>CVE Reference:\u00a0 CVE-2018-3665<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00145.html\"><font color=\"#0066cc\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00145.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-releases-security-advisory-microprocessors","alert_type":null,"serial_number":"AV18-100","subject":null,"moderation_state":"archived","external_url":null},{"nid":1176,"title":"Apple security updates","uuid":"696a0aa7-7cce-4059-861e-897f985d7689","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-24T15:06:07Z","summary":null,"body":["<article data-history-node-id=\"1176\" about=\"\/en\/alerts-advisories\/apple-security-updates-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-101<br \/>\nDate: 14 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates by Apple.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released a security update for Xcode which addresses multiple issues in git, the most significant of which may lead to arbitrary code execution.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Xcode<\/li>\n\t<li>git<\/li>\n<\/ul><p>CVE Reference:\u00a0 CVE-2018-11233, CVE-2018-11235<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT208895\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208895<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-12","alert_type":396,"serial_number":"AV18-101","subject":null,"moderation_state":"archived","external_url":null},{"nid":796,"title":"Microsoft security update \u2013 Out-of-Band","uuid":"8831d5c6-daf5-4f68-a092-e367b917babc","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-24T15:26:54Z","summary":null,"body":["<article data-history-node-id=\"796\" about=\"\/en\/alerts-advisories\/microsoft-security-update-out-band-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-102<br \/>\nDate: 19 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Microsoft Security Critical Update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory contains software updates that address vulnerabilities in some elements of \u201cOracle Outside In\u201d libraries that are contained within Microsoft Exchange Server.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Microsoft Exchange Server 2010 Service Pack 3<\/li>\n\t<li>Microsoft Exchange Server 2013<\/li>\n\t<li>Microsoft Exchange Server 2016<\/li>\n<\/ul><p>CVE References: CVE-2018-2768, CVE-2018-2806, CVE-2018-2801.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180010\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180010<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2018-3678067.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2018-3678067.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-update-out-band-3","alert_type":396,"serial_number":"AV18-102","subject":null,"moderation_state":"archived","external_url":null},{"nid":1270,"title":"Cisco security updates","uuid":"4ff383bb-5735-48de-bf87-496871660fe8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:07Z","date_created":"2018-07-24T15:32:52Z","summary":null,"body":["<article data-history-node-id=\"1270\" about=\"\/en\/alerts-advisories\/cisco-security-updates-16\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-103<br \/>\nDate: 21 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various Cisco products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Firepower 2100 Series<\/li>\n\t<li>Firepower 4100 Series Next-Generation Firewalls<\/li>\n\t<li>Firepower 9300 Security Appliance<\/li>\n\t<li>MDS 9000 Series Multilayer Switches<\/li>\n\t<li>MDS 9000 Series Multilayer Director Switches<\/li>\n\t<li>Nexus 1000V Series Switches<\/li>\n\t<li>Nexus 1100 Series Cloud Services Platforms<\/li>\n\t<li>Nexus 2000 Series Fabric Extenders<\/li>\n\t<li>Nexus 3000 Series Switches<\/li>\n\t<li>Nexus 3500 Platform Switches<\/li>\n\t<li>Nexus 3600 Platform Switches<\/li>\n\t<li>Nexus 5500 Platform Switches<\/li>\n\t<li>Nexus 5600 Platform Switches<\/li>\n\t<li>Nexus 6000 Series Switches<\/li>\n\t<li>Nexus 7000 Series Switches<\/li>\n\t<li>Nexus 7700 Series Switches<\/li>\n\t<li>Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode<\/li>\n\t<li>Nexus 9000 Series Switches in standalone NX-OS mode<\/li>\n\t<li>Nexus 9500 R-Series Line Cards and Fabric Modules<\/li>\n\t<li>UCS 6100 Series Fabric Interconnects<\/li>\n\t<li>UCS 6200 Series Fabric Interconnects<\/li>\n\t<li>UCS 6300 Series Fabric Interconnects<\/li>\n\t<li>TelePresence Video Communication Server (VCS) Expressway<\/li>\n\t<li>Unified Communications Manager IM &amp; Presence Service<\/li>\n\t<li>Unified Communications Domain Manager<\/li>\n\t<li>NX-OS Software<\/li>\n\t<li>NVIDIA TX1<\/li>\n\t<li>Web Admin Interface of Cisco Meeting Server<\/li>\n\t<li>Firepower Management Center<\/li>\n\t<li>AnyConnect Secure Mobility Client for Windows Desktop<\/li>\n<\/ul><p>CVE References: CVE-2018-0301, CVE-2018-0308, CVE-2018-0304, CVE-2018-0314, CVE-2018-0312, CVE-2018-0307, CVE-2018-0291, CVE-2018-0293, CVE-2018-0292, CVE-2018-0295, CVE-2018-0294, CVE-2018-0294, CVE-2018-0331, CVE-2018-0311, CVE-2018-0310, CVE-2018-0306, CVE-2018-0313, CVE-2018-0299, CVE-2018-0309, CVE-2018-0298, CVE-2018-0302, CVE-2018-0303, CVE-2018-0305, CVE-2018-0300, CVE-2018-0358, CVE-2018-0363, CVE-2018-0364, CVE-2018-0337, CVE-2018-6242, CVE-2018-0371, CVE-2018-0365, CVE-2018-0362, CVE-2018-0359, CVE-2018-0373, CVE-2018-0330<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-bo\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-bo<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fxnxos-fab-ace\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fxnxos-fab-ace<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fx-os-fabric-execution\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fx-os-fabric-execution<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fx-os-cli-execution\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fx-os-cli-execution<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-cli-injection\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-cli-injection<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxossnmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxossnmp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosrbac\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosrbac<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosigmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosigmp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosbgp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosbgp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosadmin\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxosadmin<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-nxapi\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-nxapi<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-cdp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-cdp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-fabric-services-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-fabric-services-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-cli-execution\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-cli-execution<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-api-execution\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nx-os-api-execution<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-n4k-snmp-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-n4k-snmp-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-n3k-n9k-clisnmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-n3k-n9k-clisnmp<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fxos-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fxos-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fxos-ace\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fxos-ace<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fx-os-fabric-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-fx-os-fabric-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-firepwr-pt\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-firepwr-pt<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-vcse-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-vcse-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-ucmim-ps-csrf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-ucmim-ps-csrf<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-ucdm-csrf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-ucdm-csrf<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-rbaccess\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nxos-rbaccess<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nvidia-tx1-rom\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-nvidia-tx1-rom<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-meeting-server-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-meeting-server-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-firepower-csrf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-firepower-csrf<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-encs-ucs-bios-auth-bypass\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-encs-ucs-bios-auth-bypass<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-cms-sf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-cms-sf<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-anyconnect-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180620-anyconnect-dos<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-16","alert_type":396,"serial_number":"AV18-103","subject":null,"moderation_state":"archived","external_url":null},{"nid":950,"title":"Mozilla security updates","uuid":"4de8111e-ad19-49e3-b148-1768d0464801","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-07-24T15:43:14Z","summary":null,"body":["<article data-history-node-id=\"950\" about=\"\/en\/alerts-advisories\/mozilla-security-updates-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-104<br \/>\nDate: 28 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently released Mozilla Security Update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Firefox versions prior to 61<\/li>\n\t<li>Firefox ESR versions prior to 60.1<\/li>\n\t<li>Firefox ESR versions prior to 52.9<\/li>\n<\/ul><p>CVE Reference: CVE-2018-12358, CVE-2018-12359, CVE-2018-12360, CVE-2018-12361, CVE-2018-12362, CVE-2018-12363, CVE-2018-12364, CVE-2018-12365 , CVE-2018-12366, CVE-2018-12367, CVE-2018-12368, CVE-2018-12369, CVE-2018-12370, CVE-2018-12371, CVE-2018-5156, CVE-2018-5186, CVE-2018-5187, CVE-2018-5188<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-15\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-15\/<\/font><\/a>\u00a0<\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-16\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-16\/<\/font><\/a>\u00a0\u00a0<\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-17\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-17\/<\/font><\/a> \u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-updates-10","alert_type":396,"serial_number":"AV18-104","subject":null,"moderation_state":"archived","external_url":null},{"nid":1017,"title":"Apache Tomcat security update","uuid":"41e06662-787d-436d-b1d1-fcc59d83964a","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-07-24T15:49:21Z","summary":null,"body":["<article data-history-node-id=\"1017\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-105<br \/>\nDate: 29 June 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to an Apache Tomcat security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A vulnerability in the Cross-Origin Resource Sharing (CORS) filter feature of Apache Tomcat could allow an unauthenticated, remote user to bypass security restrictions on a targeted system.<\/p>\n\n<p>CVE References: CVE-2018-8014<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-8014\"><font color=\"#0066cc\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-8014<\/font><\/a><\/p>\n\n<p><a href=\"https:\/\/lists.apache.org\/thread.html\/fbfb713e4f8a4c0f81089b89450828011343593800cae3fb629192b1@%3Cannounce.tomcat.apache.org%3E\"><font color=\"#0066cc\">https:\/\/lists.apache.org\/thread.html\/fbfb713e4f8a4c0f81089b89450828011343593800cae3fb629192b1@%3Cannounce.tomcat.apache.org%3E<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-update-0","alert_type":396,"serial_number":"AV18-105","subject":null,"moderation_state":"archived","external_url":null},{"nid":1150,"title":"VMware security advisory","uuid":"25042550-4dc7-4be6-bd1e-e648ba643197","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-24T17:17:36Z","summary":null,"body":["<article data-history-node-id=\"1150\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-106<br \/>\nDate: 03 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released product updates for VMware ESXi, Workstation, and Fusion to address multiple out-of-bounds read vulnerabilities.<\/p>\n\n<p>Affected Products:<br \/>\n- VMware vSphere ESXi (ESXi)\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n- VMware Workstation Pro \/ Player (Workstation)\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<br \/>\n- VMware Fusion Pro, Fusion (Fusion)\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/p>\n\n<p>CVE References: CVE-2018-6965, CVE-2018-6966, CVE-2018-6967<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0016.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0016.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-12","alert_type":396,"serial_number":"AV18-106","subject":null,"moderation_state":"archived","external_url":null},{"nid":765,"title":"[Control System] Rockwell Automation security update","uuid":"ef437099-80b1-48f6-8911-e4acdab8ddf5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-24T17:23:34Z","summary":null,"body":["<article data-history-node-id=\"765\" about=\"\/en\/alerts-advisories\/control-system-rockwell-automation-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-107<br \/>\nDate: 04 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to vulnerabilities affecting Rockwell Automation Allen-Bradley Stratix 5950.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Rockwell Automation has released a security advisory to address vulnerabilities in products which use the Rockwell Automation Allen-Bradley Stratix 5950, including: Improper Input Validation, Improper Certificate Validation and Resource Management Errors. Successful exploitation of these vulnerabilities could allow an attacker to bypass client certification to create connections to the affected device or cause the device to crash.<\/p>\n\n<p>Affected Products:<br \/>\nAllen-Bradley Stratix 5950 Security Appliances, running the Cisco ASA v9.6.2 and earlier, are affected:<\/p>\n\n<ul><li>1783-SAD4T0SBK9<\/li>\n\t<li>1783-SAD4T0SPK9<\/li>\n\t<li>1783-SAD2T2SBK9<\/li>\n\t<li>1783-SAD2T2SPK9<\/li>\n<\/ul><p>CVE References: \u00a0CVE-2018-0228, CVE-2018-0227, CVE-2018-0231, CVE-2018-0240, CVE-2018-0296<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p>ICS-CERT : ICSA-18-184-01 \u2013 Rockwell Automation Allen-Bradley Stratix 5950:<br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-184-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-184-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-system-rockwell-automation-security-update-0","alert_type":398,"serial_number":"AV18-107","subject":null,"moderation_state":"archived","external_url":null},{"nid":833,"title":"Mozilla security update","uuid":"b9533178-2a1f-498d-8a99-3cc87beef56c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-07-24T17:29:16Z","summary":null,"body":["<article data-history-node-id=\"833\" about=\"\/en\/alerts-advisories\/mozilla-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-108<br \/>\nDate: 04 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent Mozilla Thunderbird security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla have released a security update to address various vulnerabilities in Thunderbird.<\/p>\n\n<p>Affected Versions:<br \/>\n- Thunderbird 52.9<\/p>\n\n<p>CVE References: CVE-2018-5188, CVE-2018-12359, CVE-2018-12360, CVE-2018-12362, CVE-2018-12363, CVE-2018-12364, CVE-2018-12365, CVE-2018-12366, CVE-2018-12368, CVE-2018-12372, CVE-2018-12373, CVE-2018-12374<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-18\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-18\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-update","alert_type":396,"serial_number":"AV18-108","subject":null,"moderation_state":"archived","external_url":null},{"nid":876,"title":"WordPress security update","uuid":"653a0219-419f-420e-ab78-d2c5a4f7603d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-07-24T17:34:47Z","summary":null,"body":["<article data-history-node-id=\"876\" about=\"\/en\/alerts-advisories\/wordpress-security-update-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-109<br \/>\nDate: 06 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for WordPress.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>WordPress has released version 4.9.7 that contains fixes to address a media issue that could potentially allow a user with certain capabilities to attempt to delete files outside of the uploads directory.<\/p>\n\n<p>Versions affected: WordPress 4.9.6 and earlier<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2018\/07\/wordpress-4-9-7-security-and-maintenance-release\/\"><font color=\"#0066cc\">https:\/\/wordpress.org\/news\/2018\/07\/wordpress-4-9-7-security-and-maintenance-release\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-update-7","alert_type":396,"serial_number":"AV18-109","subject":null,"moderation_state":"archived","external_url":null},{"nid":996,"title":"Apple security updates","uuid":"9a5ad934-8199-4c88-989e-fbd6cfe70f38","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-07-24T17:42:10Z","summary":null,"body":["<article data-history-node-id=\"996\" about=\"\/en\/alerts-advisories\/apple-security-updates-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-110<br \/>\nDate: 09 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates by Apple.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released a security update for Boot Camp 6.4.0 which addresses a Wi-Fi vulnerability which could allow a remote unauthenticated user to obtain sensitive information.<\/p>\n\n<p>Affected products using Boot Camp 6.4.0:<\/p>\n\n<ul><li>MacBook (Late 2009 and later)<\/li>\n\t<li>MacBook Pro (Mid 2010 and later)<\/li>\n\t<li>MacBook Air (Late 2010 and later)<\/li>\n\t<li>Mac mini (Mid 2010 and later)<\/li>\n\t<li>iMac (Late 2009 and later)<\/li>\n\t<li>Mac Pro (Mid 2010 and later)<\/li>\n<\/ul><p>CVE References: CVE-2017-13077, CVE-2017-13078, CVE-2017-13080<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>Reference:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT208847\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT208847<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-13","alert_type":396,"serial_number":"AV18-110","subject":null,"moderation_state":"archived","external_url":null},{"nid":1144,"title":"Apple security updates","uuid":"77b57233-de0e-407a-86ba-c4a71e17f25c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-07-24T18:24:44Z","summary":null,"body":["<article data-history-node-id=\"1144\" about=\"\/en\/alerts-advisories\/apple-security-updates-14\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-111<br \/>\nDate: 10 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released security updates by Apple.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released security updates for vulnerabilities in various products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>iTunes 12.8 for Windows<\/li>\n\t<li>iCloud for Windows 7.6<\/li>\n\t<li>Safari 11.1.2<\/li>\n\t<li>macOS High Sierra 10.13.6, Security Update 2018-004 Sierra, Security Update 2018-004 El Capitan<\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT208935\"><font color=\"#0066cc\">watchOS 4.3.2<\/font><\/a><\/li>\n\t<li>tvOS 11.4.1<\/li>\n\t<li>iOS 11.4.1<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-3665, CVE-2018-4178, CVE-2018-4248, CVE-2018-4260, CVE-2018-4261, CVE-2018-4262,<br \/>\nCVE-2018-4263, CVE-2018-4264, CVE-2018-4265, CVE-2018-4266, CVE-2018-4267, CVE-2018-4268,<br \/>\nCVE-2018-4269, CVE-2018-4270, CVE-2018-4271, CVE-2018-4272, CVE-2018-4273, CVE-2018-4274,<br \/>\nCVE-2018-4275, CVE-2018-4277, CVE-2018-4278, CVE-2018-4279, CVE-2018-4280, CVE-2018-4282,<br \/>\nCVE-2018-4283, CVE-2018-4284, CVE-2018-4285, CVE-2018-4289, CVE-2018-4290, CVE-2018-4293<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT201222<\/font><\/a><br \/><a href=\"https:\/\/www.us-cert.gov\/ncas\/current-activity\/2018\/07\/09\/Apple-Releases-Multiple-Security-Updates\"><font color=\"#0066cc\">https:\/\/www.us-cert.gov\/ncas\/current-activity\/2018\/07\/09\/Apple-Releases-Multiple-Security-Updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-14","alert_type":396,"serial_number":"AV18-111","subject":null,"moderation_state":"archived","external_url":null},{"nid":1235,"title":"Microsoft security updates","uuid":"727aefd2-cedf-4032-86bf-cc21986a8219","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:20:44Z","date_created":"2018-07-24T18:33:33Z","summary":null,"body":["<article data-history-node-id=\"1235\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-112<br \/>\nDate: 10 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>Adobe Flash Player<\/li>\n\t<li>ASP.NET<\/li>\n\t<li>ChakraCore<\/li>\n\t<li>Internet Explorer<\/li>\n\t<li>PowerShell Editor Services<\/li>\n\t<li>PowerShell Extension for Visual Studio Code<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Lync<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Microsoft Office Services and Web Apps<\/li>\n\t<li>Microsoft Research JavaScript Cryptography Library<\/li>\n\t<li>Microsoft Visual Studio<\/li>\n\t<li>Microsoft Windows<\/li>\n\t<li>Microsoft Wireless Display Adapter V2 Software<\/li>\n\t<li>Microsoft .NET Framework<\/li>\n\t<li>Skype for Business<\/li>\n\t<li>Web Customizations for Active Directory Federation Services<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-8260, CVE-2018-8281, CVE-2018-8282, CVE-2018-8282, CVE-2018-8299, CVE-2018-8300,<br \/>\nCVE-2018-8310, CVE-2018-8323, CVE-2018-8326, CVE-2018-8327<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180002\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180002<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180012\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180012<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-13","alert_type":396,"serial_number":"AV18-112","subject":null,"moderation_state":"archived","external_url":null},{"nid":1256,"title":"Intel security update","uuid":"df42d400-6b15-4cb2-9f8c-86e17aaec1a8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-07-24T18:39:48Z","summary":null,"body":["<article data-history-node-id=\"1256\" about=\"\/en\/alerts-advisories\/intel-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-113<br \/>\nDate: 10 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published security update by Intel.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Intel has released firmware updates to improve System Management Mode (SMM) protection. Incorrect handling of memory types in Tianocore firmware could potentially allow a local attacker to bypass SMM protections on memory.<\/p>\n\n<p>Products Affected:<\/p>\n\n<p>Firmware based on Tianocore<\/p>\n\n<ul><li>MdePkg<\/li>\n\t<li>UefiCpuPkg<\/li>\n\t<li>MdeModulePkg<\/li>\n<\/ul><p>CVE Reference: CVE-2018-3614<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00159.html\"><font color=\"#0066cc\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00159.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-update-0","alert_type":396,"serial_number":"AV18-113","subject":null,"moderation_state":"archived","external_url":null},{"nid":863,"title":"Adobe security bulletins","uuid":"94430d6c-9de3-458d-ab5f-0dab61e77eee","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:52Z","date_created":"2018-07-24T18:45:03Z","summary":null,"body":["<article data-history-node-id=\"863\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-114<br \/>\nDate: 11 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for various Adobe products.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Acrobat DC<\/li>\n\t<li>Acrobat Reader DC<\/li>\n\t<li>Acrobat 2017<\/li>\n\t<li>Acrobat Reader 2017<\/li>\n\t<li>Adobe Flash Player Desktop Runtime<\/li>\n\t<li>Adobe Flash Player for Google Chrome<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11<\/li>\n\t<li>Adobe Connect<\/li>\n\t<li>Adobe Experience Manager<\/li>\n<\/ul><p>CVE References: CVE-2018-4994, CVE-2018-5004, CVE-2018-5006, CVE-2018-5007, CVE-2018-5008, CVE-2018-5009, CVE-2018-5010, CVE-2018-5011, CVE-2018-5012, CVE-2018-5014, CVE-2018-5015, CVE-2018-5016, CVE-2018-5017, CVE-2018-5018, CVE-2018-5019, CVE-2018-5020, CVE-2018-5021, CVE-2018-5022, CVE-2018-5023, CVE-2018-5024, CVE-2018-5025, CVE-2018-5026, CVE-2018-5027, CVE-2018-5028, CVE-2018-5029, CVE-2018-5030, CVE-2018-5031, CVE-2018-5032, CVE-2018-5033, CVE-2018-5034, CVE-2018-5035, CVE-2018-5036, CVE-2018-5037, CVE-2018-5038, CVE-2018-5039, CVE-2018-5040, CVE-2018-5041, CVE-2018-5042, CVE-2018-5043, CVE-2018-5044, CVE-2018-5045, CVE-2018-5046, CVE-2018-5047, CVE-2018-5048, CVE-2018-5049, CVE-2018-5050, CVE-2018-5051, CVE-2018-5052, CVE-2018-5053, CVE-2018-5054, CVE-2018-5055, CVE-2018-5056, CVE-2018-5057, CVE-2018-5058, CVE-2018-5059, CVE-2018-5060, CVE-2018-5061, CVE-2018-5062, CVE-2018-5063, CVE-2018-5064, CVE-2018-5065, CVE-2018-5066, CVE-2018-5067, CVE-2018-5068, CVE-2018-5069, CVE-2018-5070, CVE-2018-12754, CVE-2018-12755, CVE-2018-12756, CVE-2018-12757, CVE-2018-12758, CVE-2018-12760, CVE-2018-12761, CVE-2018-12762, CVE-2018-12763, CVE-2018-12764, CVE-2018-12765, CVE-2018-12766, CVE-2018-12767, CVE-2018-12768, CVE-2018-12770, CVE-2018-12771, CVE-2018-12772, CVE-2018-12773, CVE-2018-12774, CVE-2018-12776, CVE-2018-12777, CVE-2018-12779, CVE-2018-12780, CVE-2018-12781, CVE-2018-12782, CVE-2018-12783, CVE-2018-12784, CVE-2018-12785, CVE-2018-12786, CVE-2018-12787, CVE-2018-12788, CVE-2018-12789, CVE-2018-12790, CVE-2018-12791, CVE-2018-12792, CVE-2018-12793, CVE-2018-12794, CVE-2018-12795, CVE-2018-12796, CVE-2018-12797, CVE-2018-12798, CVE-2018-12802, CVE-2018-12803, CVE-2018-12804, CVE-2018-12805, CVE-2018-12809<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-21.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-21.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb18-22.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb18-22.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-23.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-23.html<\/font><\/a><br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-24.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-24.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-5","alert_type":396,"serial_number":"AV18-114","subject":null,"moderation_state":"archived","external_url":null},{"nid":999,"title":"Cisco security updates","uuid":"3b9460c6-3fab-4298-bb46-d9708a7e5bee","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-07-24T18:51:10Z","summary":null,"body":["<article data-history-node-id=\"999\" about=\"\/en\/alerts-advisories\/cisco-security-updates-17\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-115<br \/>\nDate: 11 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various Cisco products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Cisco StarOS<\/li>\n\t<li>Cisco IP Phone 6800, 7800, and 8800<\/li>\n\t<li>Cisco Digital Network Architecture (DNA) Center<\/li>\n\t<li>Cisco Firepower System Software Detection Engine<\/li>\n\t<li>Cisco Firepower System Software<\/li>\n\t<li>Cisco FireSIGHT System Software<\/li>\n\t<li>Cisco Web Security Appliance<\/li>\n<\/ul><p>CVE References: CVE-2018-0369, CVE-2018-0341, CVE-2018-0366, CVE-2018-0384, CVE-2018-0383, CVE-2018-0385, CVE-2018-0370, CVE-2018-0368<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-staros-dos\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-staros-dos<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-phone-webui-inject\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-phone-webui-inject<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-dnac-id\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-dnac-id<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firepower-dos\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firepower-dos<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firepwr-ssl-dos\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firepwr-ssl-dos<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firesight-file-bypass\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firesight-file-bypass<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firesight-url-bypass\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-firesight-url-bypass<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-wsa-xss\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180711-wsa-xss<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-17","alert_type":396,"serial_number":"AV18-115","subject":null,"moderation_state":"archived","external_url":null},{"nid":1125,"title":"Juniper security bulletins","uuid":"26f0d481-494a-40fd-b71f-020ff30a5e2f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:22Z","date_created":"2018-07-24T19:09:39Z","summary":null,"body":["<article data-history-node-id=\"1125\" about=\"\/en\/alerts-advisories\/juniper-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-116<br \/>\nDate: 13 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security bulletins released by Juniper.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Juniper has released multiple security bulletins to address vulnerabilities in their products. Exploitation of these vulnerabilities allows code execution, elevation of privilege, denial of service conditions, circumvention of security measures, or access to sensitive information<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>cURL and libcurl<\/li>\n\t<li>Junos Space<\/li>\n\t<li>Junos OS<\/li>\n\t<li>Junos OS, SRX series<\/li>\n<\/ul><p>CVE References: \u00a0CVE-2017-3145, CVE-2017-3143, CVE-2017-3142, CVE-2017-3138, CVE-2000-0973, CVE-2016-5421, CVE-2016-7167, CVE-2016-9953, CVE-2017-8816, CVE-2017-8817, CVE-2017-8818, CVE-2018-1000120, CVE-2016-4802, CVE-2013-2174, CVE-2016-9586, CVE-2016-9952, CVE-2014-0138, CVE-2017-1000257, CVE-2018-1000005, CVE-2018-1000122, CVE-2014-0139, CVE-2013-1944, CVE-2014-3613, CVE-2015-3143, CVE-2015-3148, CVE-2015-3153, CVE-2016-0754, CVE-2016-0755, CVE-2016-5419, CVE-2016-5420, CVE-2016-7141, CVE-2017-1000254, CVE-2017-9502, CVE-2018-1000007, CVE-2018-1000121, CVE-2013-4545, CVE-2014-3707, CVE-2014-8150, CVE-2017-1000099, CVE-2017-1000100, CVE-2017-1000101, CVE-2013-6422, CVE-2014-0015, CVE-2016-3739, CVE-2017-7407, CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8620, CVE-2016-8621, CVE-2016-8622, CVE-2016-8623, CVE-2016-8624, CVE-2016-8625, CVE-2017-3145, CVE-2018-2579, CVE-2018-2588, CVE-2018-2599, CVE-2018-2603, CVE-2018-2618, CVE-2018-2629, CVE-2018-2633, CVE-2018-2637, CVE-2018-2663, CVE-2018-2678, CVE-2017-12613, CVE-2017-10198, 2017-10281, CVE-2017-10295, CVE-2017-10345, CVE-2017-10355, CVE-2017-10356, CVE-2017-10388, CVE-2017-15896, CVE-2017-5753, CVE-2017-5715, CVE-2017-5754, CVE-2018-0039, CVE-2018-0040, CVE-2018-0042, CVE-2018-0038, CVE-2018-0041, CVE-2018-1000115, CVE-2018-0037, CVE-2018-0034, CVE-2018-0035, CVE-2018-0032, CVE-2018-0031, CVE-2018-0030, CVE-2018-0029, CVE-2018-0027, CVE-2018-0026, CVE-2018-0025, CVE-2018-0024, CVE-2015-7236<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10803&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10803&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10857&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10857&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10858&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10858&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10859&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10859&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10860&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10860&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10861&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10861&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10863&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10863&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10864&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10864&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10865&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10865&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10866&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10866&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10868&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10868&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10869&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10869&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10871&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10871&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10873&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10873&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10874&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10874&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10875&amp;cat=SIRT_1&amp;actp=LIST\"><font color=\"#0066cc\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10875&amp;cat=SIRT_1&amp;actp=LIST<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-bulletins-0","alert_type":396,"serial_number":"AV18-116","subject":null,"moderation_state":"archived","external_url":null},{"nid":1178,"title":"VMware security advisory","uuid":"6aacc6d8-dd08-4bd4-8eb9-8af4dc9c2577","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-07-24T19:31:56Z","summary":null,"body":["<article data-history-node-id=\"1178\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-117<br \/>\nDate: 16 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released a product update addressing a security vulnerability for VMware Tools.<\/p>\n\n<p>Affected Product:<br \/>\n- VMware Tools<\/p>\n\n<p>CVE Reference: CVE-2018-6969<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0017.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0017.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-13","alert_type":396,"serial_number":"AV18-117","subject":null,"moderation_state":"archived","external_url":null},{"nid":798,"title":"Oracle Critical Patch update Advisory","uuid":"befee84d-24df-4fd2-8a26-69864aa05f84","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:17Z","date_created":"2018-07-24T19:37:45Z","summary":null,"body":["<article data-history-node-id=\"798\" about=\"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-118<br \/>\nDate: 18 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the quarterly updates released for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a Critical Patch Update Advisory which addresses multiple new security fixes across multiple Oracle products.<\/p>\n\n<p>Affected Products:<br \/>\nAgile Recipe Management for Pharmaceuticals, version 9.3.4<br \/>\n- Enterprise Manager Base Platform, versions 12.1.0.5, 13.2.x<br \/>\n- Enterprise Manager for Fusion Middleware, versions 12.1.0.5, 13.2.x<br \/>\n- Enterprise Manager for MySQL Database, versions 13.2.2.0.0 and prior<br \/>\n- Enterprise Manager for Oracle Database, versions 12.1.0.8, 13.2.2<br \/>\n- Enterprise Manager for Peoplesoft, versions 13.1.1.1, 13.2.1.1<br \/>\n- Enterprise Manager for Virtualization, versions 13.2.2, 13.2.3<br \/>\n- Enterprise Manager Ops Center, versions 12.2.2, 12.3.3<br \/>\n- FMW Platform, versions 12.2.1.2.0, 12.2.1.3.0<br \/>\n- Hardware Management Pack, version 11.3<br \/>\n- Hyperion Data Relationship Management, version 11.1.2.4.330<br \/>\n- Hyperion Financial Reporting, version 11.1.2<br \/>\n- JD Edwards EnterpriseOne Tools, version 9.2<br \/>\n- JD Edwards World Security, versions A9.3, A9.3.1, A9.4<br \/>\n- MICROS 700 Series Tablet, versions Prior to BIOS 0.00.13ORC, Prior to BIOS 0.01.25ORC<br \/>\n- MICROS Handheld Terminal, versions 2018, Android 4.4.4 Security Patch Bulletin prior to February 1<br \/>\n- MICROS Kitchen Display Controller, versions Prior to BIOS 0.00.16ORC<br \/>\n- MICROS Lucas, versions 2.9.5.3, 2.9.5.4, 2.9.5.5, 2.9.5.6<br \/>\n- MICROS Relate CRM Software, versions 10.8.x, 11.4.x<br \/>\n- MICROS Retail-J, versions 10.2.x, 11.0.x, 12.0.x, 12.1.x, 12.1.1.x, 12.1.2.x, 13.1.x<br \/>\n- MICROS Workstation 6, versions prior to BIOS 1.3.1.0, prior to BIOS 1.5.2.0, prior to BIOS 2.3.1.0<br \/>\n- MICROS XBR, versions 7.0.2, 7.0.4<br \/>\n- MySQL Client, versions 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior, 8.0.11 and prior<br \/>\n- MySQL Connectors, versions 5.3.10 and prior, 8.0.11 and prior<br \/>\n- MySQL Enterprise Monitor, versions 3.4.7.4297 and prior, 4.0.4.5235 and prior, 8.0.0.8131 and prior<br \/>\n- MySQL Server, versions 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior, 8.0.11 and prior<br \/>\n- MySQL Workbench, versions 6.3.10 and prior, 8.0.11 and prior<br \/>\n- Oracle Agile Engineering Data Management, versions 6.1.3, 6.2.0, 6.2.1<br \/>\n- Oracle Agile PLM, versions 9.3.3, 9.3.4, 9.3.5, 9.3.6<br \/>\n- Oracle Agile PLM MCAD Connector, versions 3.3, 3.4, 3.5, 3.6<br \/>\n- Oracle Agile Product Lifecycle Management for Process, version 6.2.0.0<br \/>\n- Oracle API Gateway, version 11.1.2.4.0<br \/>\n- Oracle Application Testing Suite, version 10.1<br \/>\n- Oracle AutoVue VueLink Integration, versions 21.0.0, 21.0.1<br \/>\n- Oracle Banking Corporate Lending, versions 12.3.0, 12.4.0, 12.5.0, 14.0.0, 14.1.0<br \/>\n- Oracle Banking Payments, versions 12.2.0, 12.3.0, 12.4.0, 12.5.0, 14.1.0<br \/>\n- Oracle Banking Platform, versions 2.6.0, 2.6.1, 2.6.2<br \/>\n- Oracle BI Publisher, versions 11.1.1.7.0, 11.1.1.9.0, 12.2.1.2.0, 12.2.1.3.0<br \/>\n- Oracle Business Process Management Suite, versions 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0, 12.2.1.3.0<br \/>\n- Oracle Communications Diameter Signaling Router (DSR), versions 7.x, 8.x<br \/>\n- Oracle Communications EAGLE LNP Application Processor, version 10.x<br \/>\n- Oracle Communications Interactive Session Recorder, versions 5.x, 6.x<br \/>\n- Oracle Communications Messaging Server, version 3.x<br \/>\n- Oracle Communications Network Charging and Control, versions 4.4.1.5.0, 5.0.0.1.0, 5.0.0.2.0, 5.0.1.0.0, 5.0.2.0.0<br \/>\n- Oracle Communications Policy Management, version 12.x<br \/>\n- Oracle Communications Session Border Controller, versions ECz7.x, ECz8.x<br \/>\n- Oracle Communications User Data Repository, versions 10.x, 12.x<br \/>\n- Oracle Database Server, versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1, 18.2<br \/>\n- Oracle E-Business Suite, versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7<br \/>\n- Oracle Endeca Information Discovery Studio, versions 3.1, 3.2<br \/>\n- Oracle Enterprise Data Quality, version 12.2.1.3.0<br \/>\n- Oracle Enterprise Repository, versions 11.1.1.7.0, 12.1.3.0.0<br \/>\n- Oracle Financial Services Analytical Applications Infrastructure, versions 7.3.3.x, 8.0.x<br \/>\n- Oracle Financial Services Behavior Detection Platform, version 8.0.x<br \/>\n- Oracle Financial Services Funds Transfer Pricing, versions 6.1.1, 8.0.x<br \/>\n- Oracle Financial Services Hedge Management and IFRS Valuations, versions 8.0.4, 8.0.5<br \/>\n- Oracle Financial Services Loan Loss Forecasting and Provisioning, versions 8.0.4, 8.0.5<br \/>\n- Oracle Financial Services Profitability Management, versions 6.1.1, 8.0.x<br \/>\n- Oracle Financial Services Revenue Management and Billing, versions 2.3.0.2.0, 2.4.0.0.0, 2.4.0.1.0, 2.5.0.1.0, 2.5.0.2.0, 2.5.0.3.0<br \/>\n- Oracle FLEXCUBE Enterprise Limits and Collateral Management, versions 12.3.0, 14.0.0, 14.1.0<br \/>\n- Oracle FLEXCUBE Investor Servicing, versions 12.0.4, 12.1.0, 12.3.0, 12.4.0<br \/>\n- Oracle FLEXCUBE Universal Banking, versions 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0, 14.1.0<br \/>\n- Oracle Fusion Middleware, versions 12.2.1.2, 12.2.1.3<br \/>\n- Oracle Fusion Middleware MapViewer, versions 12.2.1.2, 12.2.1.3<br \/>\n- Oracle Global Lifecycle Management OPatchAuto, version All<br \/>\n- Oracle Hospitality Cruise Fleet Management System, version 9.x<br \/>\n- Oracle Hospitality Cruise Shipboard Property Management System, version 8.x<br \/>\n- Oracle Hospitality Gift and Loyalty, version 9.0.0<br \/>\n- Oracle Hospitality OPERA 5 Property Services, version 5.5.x<br \/>\n- Oracle Hospitality Reporting and Analytics, version 9.0.0<br \/>\n- Oracle Hospitality Simphony, versions 2.8, 2.9, 2.10<br \/>\n- Oracle iLearning, version 6.2<br \/>\n- Oracle Insurance Policy Administration, versions 10.0, 10.1, 10.2, 11.0<br \/>\n- Oracle Internet Directory, version 11.1.1.9.0<br \/>\n- Oracle Java SE, versions 6u191, 7u181, 8u172, 10.0.1<br \/>\n- Oracle Java SE Embedded, version 8u171<br \/>\n- Oracle JDeveloper, versions 12.1.3.0.0, 12.2.1.2.0, 12.2.1.3.0<br \/>\n- Oracle JRockit, version R28.3.18<br \/>\n- Oracle Outside In Technology, version 8.5.3<br \/>\n- Oracle Policy Automation, versions 10.4.7, 12.1.0, 12.1.1, 12.2.0, 12.2.1, 12.2.2, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10<br \/>\n- Oracle Policy Automation Connector for Siebel, version 10.4.6<br \/>\n- Oracle Policy Automation for Mobile Devices, versions 10.4.7, 12.1.0, 12.1.1, 12.2.0, 12.2.1, 12.2.2, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10<br \/>\n- Oracle Retail Back Office, versions 14.0, 14.1<br \/>\n- Oracle Retail Bulk Data Integration, version 16.0<br \/>\n- Oracle Retail Central Office, versions 14.0, 14.1<br \/>\n- Oracle Retail Clearance Optimization Engine, version 14.0.5<br \/>\n- Oracle Retail Convenience and Fuel POS Software, version 2.1.132<br \/>\n- Oracle Retail Customer Management and Segmentation Foundation, versions 16.x, 17.x<br \/>\n- Oracle Retail Financial Integration, versions 13.2.x, 14.0.x, 14.1.x, 15.0.x, 16.0.x<br \/>\n- Oracle Retail Integration Bus, versions 12.0.x, 13.0.x, 13.1.x, 13.2.x, 14.0.0 14.1.0, 14.0.x, 14.1.x, 15.0, 15.0.x, 16.0, 16.0.x<br \/>\n- Oracle Retail Order Broker, versions 5.2, 15.0, 16.0<br \/>\n- Oracle Retail Point-of-Sale, versions 14.0, 14.1<br \/>\n- Oracle Retail Point-of-Service, versions 14.0, 14.1<br \/>\n- Oracle Retail Predictive Application Server, version 15.0.3<br \/>\n- Oracle Retail Returns Management, versions 14.0, 14.1<br \/>\n- Oracle Retail Service Backbone, versions 14.0.x, 14.1.x, 15.0.x, 16.0.x<br \/>\n- Oracle Retail Service Layer, versions 12.0.x, 13.0.x, 13.1.x, 13.2.x, 14.0.x<br \/>\n- Oracle Secure Global Desktop, versions 5.3, 5.4<br \/>\n- Oracle SOA Suite, versions 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0, 12.2.1.3.0<br \/>\n- Oracle SuperCluster Specific Software, versions prior to 2.5.0<br \/>\n- Oracle Transportation Management, versions 6.2, 6.3.7, 6.4.1<br \/>\n- Oracle Tuxedo, versions 12.1.1, 12.1.3, 12.2.2<br \/>\n- Oracle Utilities Framework, version 4.3.x<br \/>\n- Oracle Utilities Network Management System, versions 1.12.x, 2.3.x<br \/>\n- Oracle Utilities Work and Asset Management, version 1.9.1.2.12<br \/>\n- Oracle VM VirtualBox, versions prior to 5.2.16<br \/>\n- Oracle WebCenter Portal, versions 11.1.1.9.0, 12.2.1.2.0, 12.2.1.3.0<br \/>\n- Oracle WebLogic Server, versions 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3<br \/>\n- OSS Support Tools, versions prior to 18.3<br \/>\n- PeopleSoft Enterprise CS Financial Aid, versions 9.0, 9.2<br \/>\n- PeopleSoft Enterprise FIN Install, version 9.2<br \/>\n- PeopleSoft Enterprise HCM Human Resources, version 9.2<br \/>\n- PeopleSoft Enterprise PeopleTools, versions 8.55, 8.56<br \/>\n- PeopleSoft HRMS, version 9.2<br \/>\n- Primavera P6 Enterprise Project Portfolio Management, versions 8.4, 15.x, 16.x, 17.x<br \/>\n- Primavera Unifier, versions 16.x, 17.x, 18.x<br \/>\n- Siebel Applications, version 18.0<br \/>\n- Solaris, versions 10, 11.2, 11.3<br \/>\n- Solaris Cluster, versions 3.3, 4.3<br \/>\n- Sun ZFS Storage Appliance Kit (AK), versions prior to 8.7.20<br \/>\n- Tape Library ACSLS, versions Prior to ACSLS 8.4.0-3<\/p>\n\n<p>CVE References:<br \/>\nCVE-2018-0733, CVE-2018-0739, CVE-2018-1171, CVE-2018-1258, CVE-2018-1270, CVE-2018-1271, CVE-2018-1272, CVE-2018-1275, CVE-2018-1304, CVE-2018-1305, CVE-2018-1327, CVE-2018-2598, CVE-2018-2767, CVE-2018-2881, CVE-2018-2882, CVE-2018-2888, CVE-2018-2891, CVE-2018-2892, CVE-2018-2893, CVE-2018-2894, CVE-2018-2895, CVE-2018-2896, CVE-2018-2897, CVE-2018-2898, CVE-2018-2899, CVE-2018-2900, CVE-2018-2901, CVE-2018-2903, CVE-2018-2904, CVE-2018-2905, CVE-2018-2906, CVE-2018-2907, CVE-2018-2908, CVE-2018-2915, CVE-2018-2916, CVE-2018-2917, CVE-2018-2918, CVE-2018-2919, CVE-2018-2920, CVE-2018-2921, CVE-2018-2923, CVE-2018-2924, CVE-2018-2925, CVE-2018-2926, CVE-2018-2927, CVE-2018-2928, CVE-2018-2929, CVE-2018-2930, CVE-2018-2932, CVE-2018-2933, CVE-2018-2934, CVE-2018-2935, CVE-2018-2936, CVE-2018-2937, CVE-2018-2938, CVE-2018-2939, CVE-2018-2940, CVE-2018-2941, CVE-2018-2942, CVE-2018-2943, CVE-2018-2944, CVE-2018-2945, CVE-2018-2946, CVE-2018-2947, CVE-2018-2948, CVE-2018-2949, CVE-2018-2950, CVE-2018-2951, CVE-2018-2952, CVE-2018-2953, CVE-2018-2954, CVE-2018-2955, CVE-2018-2956, CVE-2018-2957, CVE-2018-2958, CVE-2018-2959, CVE-2018-2960, CVE-2018-2961, CVE-2018-2962, CVE-2018-2963, CVE-2018-2964, CVE-2018-2965, CVE-2018-2966, CVE-2018-2967, CVE-2018-2968, CVE-2018-2969, CVE-2018-2970, CVE-2018-2972, CVE-2018-2973, CVE-2018-2974, CVE-2018-2975, CVE-2018-2976, CVE-2018-2977, CVE-2018-2978, CVE-2018-2979, CVE-2018-2980, CVE-2018-2981, CVE-2018-2982, CVE-2018-2984, CVE-2018-2985, CVE-2018-2986, CVE-2018-2987, CVE-2018-2988, CVE-2018-2989, CVE-2018-2990, CVE-2018-2991, CVE-2018-2992, CVE-2018-2993, CVE-2018-2994, CVE-2018-2995, CVE-2018-2996, CVE-2018-2997, CVE-2018-2998, CVE-2018-2999, CVE-2018-3000, CVE-2018-3001, CVE-2018-3002, CVE-2018-3003, CVE-2018-3004, CVE-2018-3005, CVE-2018-3006, CVE-2018-3007, CVE-2018-3008, CVE-2018-3009, CVE-2018-3010, CVE-2018-3012, CVE-2018-3013, CVE-2018-3014, CVE-2018-3015, CVE-2018-3016, CVE-2018-3017, CVE-2018-3018, CVE-2018-3019, CVE-2018-3020, CVE-2018-3021, CVE-2018-3022, CVE-2018-3023, CVE-2018-3024, CVE-2018-3025, CVE-2018-3026, CVE-2018-3027, CVE-2018-3028, CVE-2018-3029, CVE-2018-3030, CVE-2018-3031, CVE-2018-3032, CVE-2018-3033, CVE-2018-3034, CVE-2018-3035, CVE-2018-3036, CVE-2018-3037, CVE-2018-3038, CVE-2018-3039, CVE-2018-3040, CVE-2018-3041, CVE-2018-3042, CVE-2018-3043, CVE-2018-3044, CVE-2018-3045, CVE-2018-3046, CVE-2018-3047, CVE-2018-3048, CVE-2018-3049, CVE-2018-3050, CVE-2018-3051, CVE-2018-3052, CVE-2018-3053, CVE-2018-3054, CVE-2018-3055, CVE-2018-3056, CVE-2018-3057, CVE-2018-3058, CVE-2018-3060, CVE-2018-3061, CVE-2018-3062, CVE-2018-3063, CVE-2018-3064, CVE-2018-3065, CVE-2018-3066, CVE-2018-3067, CVE-2018-3068, CVE-2018-3069, CVE-2018-3070, CVE-2018-3071, CVE-2018-3072, CVE-2018-3073, CVE-2018-3074, CVE-2018-3075, CVE-2018-3076, CVE-2018-3077, CVE-2018-3078, CVE-2018-3079, CVE-2018-3080, CVE-2018-3081, CVE-2018-3082, CVE-2018-3084, CVE-2018-3085, CVE-2018-3086, CVE-2018-3087, CVE-2018-3088, CVE-2018-3089, CVE-2018-3090, CVE-2018-3091, CVE-2018-3092, CVE-2018-3093, CVE-2018-3094, CVE-2018-3095, CVE-2018-3096, CVE-2018-3097, CVE-2018-3098, CVE-2018-3099, CVE-2018-3100, CVE-2018-3101, CVE-2018-3102, CVE-2018-3103, CVE-2018-3104, CVE-2018-3105, CVE-2018-3108, CVE-2018-3109, CVE-2018-3639, CVE-2018-3640, CVE-2018-7489, CVE-2018-8013, CVE-2018-1000120, CVE-2018-1000121, CVE-2018-1000122, CVE-2018-1000300, CVE-2018-1000<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators identify their affected assets and potential interdependencies with their organization\u2019s critical services, and follow their patch management process accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2018-4258247.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2018-4258247.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-critical-patch-update-advisory","alert_type":396,"serial_number":"AV18-118","subject":null,"moderation_state":"archived","external_url":null},{"nid":1272,"title":"Cisco security updates","uuid":"69a7867d-e9db-483a-961d-efe2fd6bab9e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:07Z","date_created":"2018-07-24T19:45:50Z","summary":null,"body":["<article data-history-node-id=\"1272\" about=\"\/en\/alerts-advisories\/cisco-security-updates-18\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-119<br \/>\nDate: 18 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various Cisco products.<\/p>\n\n<p>Affected Products:<br \/>\n- Cisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode DHCP Version 6 Denial of Service Vulnerability<br \/>\n- Cisco Policy Suite Cluster Manager Default Password Vulnerability<br \/>\n- Cisco Policy Suite OSGi Interface Unauthenticated Access Vulnerability<br \/>\n- Cisco Policy Suite Policy Builder Database Unauthenticated Access Vulnerability<br \/>\n- Cisco SD-WAN Solution Arbitrary File Overwrite Vulnerability<br \/>\n- Cisco SD-WAN Solution CLI Command Injection Vulnerability<br \/>\n- Cisco SD-WAN Solution Command Injection Vulnerability<br \/>\n- Cisco SD-WAN Solution Command Injection Vulnerability<br \/>\n- Cisco SD-WAN Solution Configuration and Management Database Remote Code Execution Vulnerability<br \/>\n- Multiple Vulnerabilities in Cisco Finesse<br \/>\n- Cisco SD-WAN Solution Remote Code Execution Vulnerability<br \/>\n- Cisco SD-WAN Solution VPN Subsystem Command Injection Vulnerability<br \/>\n- Cisco FXOS and NX-OS Software Cisco Fabric Services Arbitrary Code Execution Vulnerability<br \/>\n- Cisco SD-WAN Solution Zero Touch Provisioning Command Injection Vulnerability<br \/>\n- Cisco SD-WAN Solution Zero Touch Provisioning Denial of Service Vulnerability<br \/>\n- Cisco Unified Communications Manager IM And Presence Service Cross-Site Scripting Vulnerability<br \/>\n- Cisco Webex DOM-Based Cross-Site Scripting Vulnerability<br \/>\n- Cisco Webex Network Recording Players Denial of Service Vulnerabilities<br \/>\n- Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities<br \/>\n- Cisco Webex Teams Remote Code Execution Vulnerability<br \/>\n- Multiple Vulnerabilities in Cisco Unified Contact Center Express<br \/>\n- Cisco Policy Suite Policy Builder Unauthenticated Access Vulnerability<br \/>\n- Cisco Cloud Services Platform 2100 Web Upload Function Code Injection Vulnerability<br \/>\n- Cisco Policy Suite Read-Only User Effect Change Vulnerability<br \/>\n- Cisco Policy Suite World-Readable Sensitive Data Vulnerability<br \/>\n- Cisco SD-WAN Solution Local Buffer Overflow Vulnerability<\/p>\n\n<p>CVE References: CVE-2018-0342, CVE-2018-0343, CVE-2018-0344, CVE-2018-0345, CVE-2018-0346, CVE-2018-0347, CVE-2018-0348, CVE-2018-0349, CVE-2018-0350, CVE-2018-0351, CVE-2018-0372, CVE-2018-0374, CVE-2018-0375, CVE-2018-0376, CVE-2018-0377, CVE-2018-0379, CVE-2018-0380, CVE-2018-0387, CVE-2018-0390, CVE-2018-0392, CVE-2018-0393, CVE-2018-0394, CVE-2018-0396, CVE-2018-0398, CVE-2018-0399, CVE-2018-0400, CVE-2018-0401, CVE-2018-0402, CVE-2018-0403<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sd-wan-bo\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sd-wan-bo<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-suite-data\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-suite-data<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-suite-change\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-suite-change<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-finesse\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-finesse<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-csp2100-injection\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-csp2100-injection<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sd-wan-cmd-inject\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sd-wan-cmd-inject<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sd-wan-code-ex\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sd-wan-code-ex<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-uccx\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-uccx<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-ucmim-ps-xss\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-ucmim-ps-xss<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-DOM-xss\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-DOM-xss<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-dos\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-dos<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-teams-rce\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-teams-rce<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-20180718-nexus-9000-dos\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-20180718-nexus-9000-dos<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-ci\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-ci<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-cmdinj\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-cmdinj<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-cmdnjct\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-cmdnjct<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-coinj\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-coinj<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-cx\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-cx<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-fo\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-fo<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-rce\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-webex-rce<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-cm-default-psswrd\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-cm-default-psswrd<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-unauth-access\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-policy-unauth-access<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-ps-osgi-unauth-access\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-ps-osgi-unauth-access<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-pspb-unauth-access\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-pspb-unauth-access<\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-dos\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180718-sdwan-dos<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-18","alert_type":396,"serial_number":"AV18-119","subject":null,"moderation_state":"archived","external_url":null},{"nid":922,"title":"PHP security updates","uuid":"25ec9c55-96e8-4c04-9e2e-85b8380d0227","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:06Z","date_created":"2018-07-24T19:52:15Z","summary":null,"body":["<article data-history-node-id=\"922\" about=\"\/en\/alerts-advisories\/php-security-updates-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-120<br \/>\nDate: 24 July 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released PHP security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>PHP has released multiple security updates addressing various vulnerabilities in their products.\u00a0<\/p>\n\n<p>Versions affected:<\/p>\n\n<ul><li>PHP 7.0.x versions 7.0.30 and earlier<\/li>\n\t<li>PHP 7.1.x versions 7.1.19 and earlier<\/li>\n\t<li>PHP 7.2.x versions 7.2.7 and earlier<\/li>\n\t<li>PHP 5.6.x versions 5.6.36 and earlier<\/li>\n<\/ul><h2>Suggested action<\/h2>\n\n<p>CCIRC recommends organizations consult with vendors for confirmation on whether their products and\/or service providers are utilizing vulnerable versions of PHP. As vendor-released updates become available, organizations should test and deploy updates to affected applications\/platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/secure.php.net\/archive\/2018.php#id2018-07-19-2\"><font color=\"#0066cc\">https:\/\/secure.php.net\/archive\/2018.php#id2018-07-19-2<\/font><\/a><br \/><a href=\"https:\/\/secure.php.net\/archive\/2018.php#id2018-07-20-1\"><font color=\"#0066cc\">https:\/\/secure.php.net\/archive\/2018.php#id2018-07-20-1<\/font><\/a><br \/><a href=\"https:\/\/secure.php.net\/archive\/2018.php#id2018-07-20-2\"><font color=\"#0066cc\">https:\/\/secure.php.net\/archive\/2018.php#id2018-07-20-2<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-updates-3","alert_type":396,"serial_number":"AV18-120","subject":null,"moderation_state":"archived","external_url":null},{"nid":1152,"title":"Apache Tomcat security update","uuid":"75fbe174-c85e-4b6c-ad7d-4b0878e04f2c","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:19:55Z","date_created":"2018-07-25T13:59:46Z","summary":null,"body":["<article data-history-node-id=\"1152\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-update-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-121<br \/>\nDate: 24 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to critical security updates released for Apache Tomcat.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apache has released critical security updates to address vulnerabilities in their Tomcat product.<\/p>\n\n<p>Versions affected: 9.0.0.M9 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.<\/p>\n\n<p>CVE References: CVE-2018-1336, CVE-2018-8037, CVE-2018-8034<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/lists.apache.org\/list.html?dev@tomcat.apache.org\"><font color=\"#0066cc\">https:\/\/lists.apache.org\/list.html?dev@tomcat.apache.org<\/font><\/a><\/p>\n\n<p><a href=\"http:\/\/tomcat.apache.org\/security-9.html\"><font color=\"#0066cc\">http:\/\/tomcat.apache.org\/security-9.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-update-1","alert_type":396,"serial_number":"AV18-121","subject":null,"moderation_state":"archived","external_url":null},{"nid":766,"title":"Google Releases security update for Chrome","uuid":"b8fad750-6adc-4048-a57e-d034f587ddc8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-07-27T18:49:50Z","summary":null,"body":["<article data-history-node-id=\"766\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-38\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-122<br \/>\nDate: 25 July 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 68.0.3440.75 for Windows, Mac, and Linux.<\/p>\n\n<p>CVE References: \u00a0CVE-2018-6153, CVE-2018-6154, CVE-2018-6155 , CVE-2018-6156, CVE-2018-6157, CVE-2018-6158,\u00a0 CVE-2018-6159,\u00a0 CVE-2018-6160, CVE-2018-6161,\u00a0 CVE-2018-6162, CVE-2018-6163,\u00a0 CVE-2018-6164, CVE-2018-6165, CVE-2018-6166, CVE-2018-6167,\u00a0 CVE-2018-6168,\u00a0 CVE-2018-6169, CVE-2018-6170, CVE-2018-6171, CVE-2018-6172, CVE-2018-6173, CVE-2018-6174,\u00a0 CVE-2018-6175, CVE-2018-6176, CVE-2018-6177, CVE-2018-6178,\u00a0 CVE-2018-6179,\u00a0 CVE-2018-6044,\u00a0 CVE-2018-4117,\u00a0 CVE-2018-6150, CVE-2018-6151, CVE-2018-6152<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-38","alert_type":396,"serial_number":"AV18-122","subject":null,"moderation_state":"archived","external_url":null},{"nid":974,"title":"Cisco security updates","uuid":"3660f093-452f-4d63-95db-010a56861058","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-09-07T19:07:54Z","summary":null,"body":["<article data-history-node-id=\"974\" about=\"\/en\/alerts-advisories\/cisco-security-updates-19\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-123<br \/>\nDate: 1 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various Cisco products.<\/p>\n\n<p>Affected Products:<br \/>\n- Cisco Prime Collaboration Provisioning (PCP) Releases 12.2 and prior<br \/>\n- Cisco Web Security Appliance<br \/>\n- Cisco Unified Communications Manager<br \/>\n- Cisco Small Business 300 Series (Sx300) Managed Switches<br \/>\n- Cisco Identity Services Engine (ISE)<br \/>\n- Cisco AMP for Endpoints Mac Connector Software running on Apple macOS 10.12<\/p>\n\n<p>CVE References: \u00a0CVE-2018-0391, CVE-2018-0397, CVE-2018-0406, CVE-2018-0407, CVE-2018-0408, CVE-2018-0411, CVE-2018-0413<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-pcp-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-pcp-dos<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-wsa-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-wsa-xss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-ucm-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-ucm-xss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-sb-rxss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-sb-rxss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-sb-pxss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-sb-pxss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-ise-csrf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-ise-csrf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-fampmac\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180801-fampmac<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-19","alert_type":396,"serial_number":"AV18-123","subject":"cisco","moderation_state":"archived","external_url":null},{"nid":878,"title":"Drupal security advisory","uuid":"8ca43115-9938-4c3b-95d8-86c67bfdf39d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-09-07T19:14:15Z","summary":null,"body":["<article data-history-node-id=\"878\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-124<br \/>\nDate: 3 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Drupal security advisory.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Drupal has released a product update addressing security vulnerability in the Symfony library used in Drupal Core.<\/p>\n\n<p>Affected Versions:<br \/>\n- Drupal 8.x versions prior to 8.5.6<\/p>\n\n<p>Reference CVE: CVE-2018-14773<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.drupal.org\/SA-CORE-2018-005\"><font color=\"#0066cc\">https:\/\/www.drupal.org\/SA-CORE-2018-005<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-2","alert_type":396,"serial_number":"AV18-124","subject":null,"moderation_state":"archived","external_url":null},{"nid":988,"title":"Linux and FreeBSD Kernel Vulnerability","uuid":"c8a5524a-6864-406f-86b4-74b150026900","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-09-07T19:29:33Z","summary":null,"body":["<article data-history-node-id=\"988\" about=\"\/en\/alerts-advisories\/linux-and-freebsd-kernel-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-125<br \/>\nDate: 07 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Linux and FreeBSD kernel TCP vulnerability.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Vulnerability in the implementation of the TCP protocol has been discovered in the kernel of Linux and FreeBSD that may lead to system resource exhaustion.\u00a0 A remote attacker may be able to trigger a denial-of-service condition against a system with an available open port.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Linux kernel versions 4.9 and greater<\/li>\n\t<li>All supported versions of FreeBSD<\/li>\n<\/ul><p>CVE References: CVE-2018-5390, CVE-2018-6922<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/962459\"><font color=\"#0066cc\">https:\/\/www.kb.cert.org\/vuls\/id\/962459<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-18:08.tcp.asc\"><font color=\"#0066cc\">https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-18:08.tcp.asc<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-and-freebsd-kernel-vulnerability","alert_type":396,"serial_number":"AV18-125","subject":null,"moderation_state":"archived","external_url":null},{"nid":1145,"title":"Mozilla security update","uuid":"c79a7cb7-3a95-457a-8608-3c676b605b29","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-09-07T19:36:52Z","summary":null,"body":["<article data-history-node-id=\"1145\" about=\"\/en\/alerts-advisories\/mozilla-security-update-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-126<br \/>\nDate: 08 AUG 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent Mozilla Thunderbird security update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla have released a security update to address various vulnerabilities in Thunderbird.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Thunderbird 60<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-5187, CVE-2018-5188, CVE-2018-12359, CVE-2018-12360, CVE-2018-12361, CVE-2018-12362, CVE-2018-5156, CVE-2018-12363, CVE-2018-12364, CVE-2018-12365, CVE-2018-12371, CVE-2018-12366, CVE-2018-12367, CVE-2018-12368,<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-19\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-19\/<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-update-0","alert_type":396,"serial_number":"AV18-126","subject":null,"moderation_state":"archived","external_url":null},{"nid":1349,"title":"[Control systems] Delta Electronics CNCSoft and ScreenEditor Vulnerabilities","uuid":"e0afd963-bc85-4a25-b978-366f5c1f38e5","banner":null,"lang":"en","date_modified":"2018-09-30","date_modified_ts":"2018-09-30T16:49:07Z","date_created":"2018-09-07T20:01:05Z","summary":null,"body":["<article data-history-node-id=\"1349\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-cncsoft-and-screeneditor-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-127<br \/>\nDate: 08 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to vulnerabilities affecting Delta Electronics CNCSoft and ScreenEditor.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>A security update has been released to address vulnerabilities in CNCSoft and ScreenEditor. Successful exploitation of these vulnerabilities could allow an attacker to gain administrator privileges and perform remote code execution.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>CNCSoft Version 1.00.83 and prior<\/li>\n\t<li>ScreenEditor Version 1.00.54<\/li>\n<\/ul><p>CVE References: CVE-2018-10598, CVE-2018-10636<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly. For more information, please refer to the ICS-CERT references.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2018-10598\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2018-10598<\/font><\/a><br \/><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2018-10636\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2018-10636<\/font><\/a><br \/><a href=\"https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-219-01\"><font color=\"#0066cc\">https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-18-219-01<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-cncsoft-and-screeneditor-vulnerabilities","alert_type":398,"serial_number":"AV18-127","subject":null,"moderation_state":"archived","external_url":null},{"nid":1259,"title":"HP security updates","uuid":"fe56b602-a0be-418e-9b06-f041480f02f0","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:39Z","date_created":"2018-09-07T20:07:48Z","summary":null,"body":["<article data-history-node-id=\"1259\" about=\"\/en\/alerts-advisories\/hp-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-128<br \/>\nDate: 08 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security updates for HP Enterprise printers.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>HP has released security patches to address a vulnerability of Remote Code Execution which could allow potential execution of arbitrary code in multiple HP Inkjet printers.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>HP PageWide 352dw:\u00a0 J6U57B<\/li>\n\t<li>HP PageWide Managed MFP P57750dw: J9V82A, J9V82B, J9V82C, J9V82D<\/li>\n\t<li>HP PageWide Managed MFP P77740dn: Y3Z57<\/li>\n\t<li>HP PageWide Managed MFP P77740dw: W1B33<\/li>\n\t<li>HP PageWide Managed MFP P77740z: W1B39<\/li>\n\t<li>HP PageWide Managed MFP P77750z: W1B37<\/li>\n\t<li>HP PageWide Managed MFP P77760z: W1B38<\/li>\n\t<li>HP PageWide Managed P55250dw: J6U55A, J6U55B, J6U55C, J6U55D<\/li>\n\t<li>HP PageWide Managed P75050dn: Y3Z45<\/li>\n\t<li>HP PageWide Managed P75050dw: Y3Z47<\/li>\n\t<li>HP PageWide MFP 377dw: J9V80A, J9V80B<\/li>\n\t<li>HP PageWide Pro 452dn: D3Q15A, D3Q15B, D3Q15D<\/li>\n\t<li>HP PageWide Pro 552dw: D3Q17A, D3Q17C, D3Q17D<\/li>\n\t<li>HP PageWide Pro 750dn: Y3Z46<\/li>\n\t<li>HP PageWide Pro 750dw: Y3Z44<\/li>\n\t<li>HP PageWide Pro MFP 477dn: D3Q19A, D3Q19D<\/li>\n\t<li>HP PageWide Pro MFP 477dw: D3Q20A, D3Q20B, D3Q20C, D3Q20D<\/li>\n\t<li>HP PageWide Pro MFP 577dw: D3Q21A, D3Q21C, D3Q21D<\/li>\n\t<li>HP PageWide Pro MFP 577z: K9Z76A, K9Z76D<\/li>\n\t<li>HP PageWide Pro MFP 772dn: W1B31<\/li>\n\t<li>HP PageWide Pro MFP 772dw: Y3Z54<\/li>\n\t<li>HP PageWide Pro 452dw: D3Q16A, D3Q16B, D3Q16C, D3Q16D<\/li>\n\t<li>HP DesignJet rugged case: N9M07A<\/li>\n\t<li>HP Designjet T120 24-in ePrinter: CQ891A<\/li>\n\t<li>HP Designjet T120 24-in Printer: CQ891B<\/li>\n\t<li>HP Designjet T120 24-in Printer (2018 edition): CQ891C<\/li>\n\t<li>HP Designjet T120 24-in Rmkt ePrinter: CQ891AR<\/li>\n\t<li>HP Designjet T520 24-in ePrinter: CQ890A<\/li>\n\t<li>HP Designjet T520 24-in Printer: CQ890B<\/li>\n\t<li>HP Designjet T520 24-in Printer (2018 edition): CQ890C<\/li>\n\t<li>HP Designjet T520 24-in Printer (2018 edition): CQ890D<\/li>\n\t<li>HP Designjet T520 24-in Printer (2018 edition, legless): CQ890E<\/li>\n\t<li>HP Designjet T520 24-in Rmkt ePrinter: CQ890AR<\/li>\n\t<li>HP Designjet T520 36-in ePrinter: CQ893A<\/li>\n\t<li>HP Designjet T520 36-in Printer: CQ893B<\/li>\n\t<li>HP Designjet T520 36-in Printer (2018 edition): CQ893C<\/li>\n\t<li>HP Designjet T520 36-in Printer (2018 edition, legless): CQ893E<\/li>\n\t<li>HP Designjet T520 36-in Rmkt ePrinter: CQ893AR<\/li>\n\t<li>HP DesignJet T730 36in Printer: F9A29A<\/li>\n\t<li>HP DesignJet T730 36in Printer: F9A29B<\/li>\n\t<li>HP Designjet T730 with Rugged Case: T5D66A<\/li>\n\t<li>HP DesignJet T830 24in eMFP Printer: F9A28A<\/li>\n\t<li>HP DesignJet T830 24-in MFP Printer: F9A28B<\/li>\n\t<li>HP DesignJet T830 MFP with Armor Case: 1JL02B<\/li>\n\t<li>HP DesignJet T830 MFP with Armour Case: 1JL02A<\/li>\n\t<li>HP DesignJet T830 MFP with Rugged Case: T5D67A<\/li>\n\t<li>HP Officejet, HP Deskjet and HP Envy<\/li>\n\t<li>HP AMP 1xx Printer series: T8X39 - T8X44: 1SH08, 3AW44A - 3AW51A<\/li>\n\t<li>HP Deskjet 2540 All-in-One: A9U19A - A9U28B, D3A78B - D3A82A<\/li>\n\t<li>HP DeskJet 2600 All-in-One Printer: 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A<\/li>\n\t<li>HP DeskJet 2600 All-in-One Printer: CZ992A, L9D57A, N4L17A<\/li>\n\t<li>HP Deskjet 2620 Ink Advantage series: D4H22A - D4H24B<\/li>\n\t<li>HP Deskjet 3540 series: A9T81A, A9T81C, A9T83B<\/li>\n\t<li>HP DeskJet 3630 series: F5S43A - F5S57A, K4T93A - K4T99B, K4U00B - K4U04B<\/li>\n\t<li>HP DeskJet 3700 All-in-One Printer series: J9V86A<\/li>\n\t<li>HP DeskJet 3700 All-in-One Printer series: J9V86A - J9V96A, T8W51A - T8W73A<\/li>\n\t<li>HP Deskjet 4510 series: A9J41 - A9J43<\/li>\n\t<li>HP DeskJet 4530 series: F0V64 - F0V66, J6U63, W3U23 - W3U24<\/li>\n\t<li>HP DeskJet 4720 series: F5S65A - F5S66A, L8L91A<\/li>\n\t<li>HP DeskJet 5000 series: M2U86 - M2U90<\/li>\n\t<li>HP DeskJet 5275 All-in-One Printer:\u00a0 M2U76 - M2U80<\/li>\n\t<li>HP DeskJet 5640 series: B9S57C<\/li>\n\t<li>HP DeskJet 5730 series: F5S60A - F5S61A, T0A23A - T0A25A<\/li>\n\t<li>HP DeskJet GT 5820 All-in-One Printer series: M2Q28A, P0R21A, X3B09A, 2ND31A<\/li>\n\t<li>HP Deskjet Ink Advantage 2540 All-in-One: A9U23 - A9U28<\/li>\n\t<li>HP DeskJet Ink Advantage 2600 All-in-One Printer:\u00a0 V1N02A - V1N02C<\/li>\n\t<li>HP DeskJet Ink Advantage 2600 All-in-One Printer:\u00a0 Y5Z00A - Y5Z07B<\/li>\n\t<li>HP DeskJet Ink Advantage 3630 All-in-One Printer: F5S43 - F5S57, K9U05B<\/li>\n\t<li>HP DeskJet Ink Advantage 3700 All-in-One Printer series: 1DT61A - 1DT62A, 3YZ74A - 3YZ75A, 4SC29A - 4SC30A, J9V87A - J9V89B, T8W35A - T8W50C<\/li>\n\t<li>HP Deskjet Ink Advantage 3830 e-All-in-One Printer: F5R96A - F5R98B, K7V42C - K7V43C<\/li>\n\t<li>HP Deskjet Ink Advantage 4615 All-in-One Printer: CZ283A - CZ283C<\/li>\n\t<li>HP Deskjet Ink Advantage 4625 e-All-in-One: CZ284A - CZ284C<\/li>\n\t<li>HP Deskjet Ink Advantage 4640 e-All-in-One Printer series: B4L08A - B4L10A<\/li>\n\t<li>HP DeskJet Ink Advantage 4670 All-in-One Printer: F1H97 - F1H199<\/li>\n\t<li>HP Deskjet Ink Advantage 5525 e-All-in-One: CZ282A - CZ282C<\/li>\n\t<li>HP DeskJet Ink Advantage 5570 All-in-One printer: G0V48B, G0V48C<\/li>\n\t<li>HP Deskjet Ink Advantage 6525 e-All-in-One: CZ276A - CZ76C<\/li>\n\t<li>HP Envy 120 Series: CQ176 - CQ190<\/li>\n\t<li>HP ENVY 4500 series: A9T80A, A9T80B, A9T89A, D3P93A<\/li>\n\t<li>HP ENVY 4510 All-in-One Printer: K9H48 - K9H57<\/li>\n\t<li>HP ENVY 4520 series: F0V63, F0V67 - F0V74, K9T01 - K9T10, J6U59 - J6U62, J6U69 - J6U70, K9H57,<\/li>\n\t<li>W3U25 - W3U27<\/li>\n\t<li>HP ENVY 5000 series: M2U85, M2U91-M2U94, Z4A54 - Z4A78<\/li>\n\t<li>HP ENVY 5530 series: A9J40A - A9J48B, D4J85B - D4J86B<\/li>\n\t<li>HP ENVY 5540 All-in-One Printer: G0V47, G0450 - G0V56, K7C84 - K7C93, K7G86 - K7G90<\/li>\n\t<li>HP ENVY 5640 series: B9S56A, B9S58A - B9S65A, F8B05A, F8B13A<\/li>\n\t<li>HP ENVY 5660 series: F8B04A, F8B06A - F8B08A, F8B12A<\/li>\n\t<li>HP ENVY 7640 series: E4W43-E4W48<\/li>\n\t<li>HP ENVY Photo 6200 All-in-One Printer series: K7G18A-K7G29A<\/li>\n\t<li>HP ENVY Photo 7100 All-in-One Printer series: K7G93A-K7G99<\/li>\n\t<li>HP ENVY Photo 7100 All-in-One Printer series: K7S00A<\/li>\n\t<li>HP Ink Tank 310: Z6Z11A<\/li>\n\t<li>HP Ink Tank Wireless 410: Z4B53A - Z4B55A, Z6Z95A, Z6Z97A<\/li>\n\t<li>HP Officejet Pro X451dn Printer: CN459A<\/li>\n\t<li>HP Officejet Pro X451dw Printer: CN463A<\/li>\n\t<li>HP Officejet Pro X476dn MFP: CN460A<\/li>\n\t<li>HP Officejet Pro X476dw MFP: CN461A<\/li>\n\t<li>HP Officejet Pro X551dw Printer: CV037A<\/li>\n\t<li>HP Officejet Pro X576dn MFP: CN462A<\/li>\n\t<li>HP Officejet Pro X576dw MFP: C598A<\/li>\n\t<li>HP OfficeJet 200 Mobile series: CZ993A, L9B95A<\/li>\n\t<li>HP OfficeJet 202 Mobile series: N4L14C, N4K99C<\/li>\n\t<li>HP OfficeJet 252 Mobile All-in-One: N4L18C<\/li>\n\t<li>HP Officejet 2620 series: D4H21A - D4H21B, D4H25A - D4H29B<\/li>\n\t<li>HP Officejet 3830 e-All-in-One Printer: F5R95, F5S00 - F5S04, K7V35 - K7V49<\/li>\n\t<li>HP Officejet 4610 e-All-in-One Printer: CR771A<\/li>\n\t<li>HP Officejet 4620 e-All-in-One Printer: CZ152A - CZ152C<\/li>\n\t<li>HP Officejet 4622 e-All-in-One Printer: CZ294A - CZ296B<\/li>\n\t<li>HP Officejet 4630 e-All-in-One Printer series: B4L03 - B4L07A, D4J74 - D4J78<\/li>\n\t<li>HP OfficeJet 4650 All-in-One Printer: F1H96, F1J00 - F1J07, F9D36 - F9D38, K9V76 - K9V85, V6D27- V6D32<\/li>\n\t<li>HP OfficeJet 5200 AlI-in-One Printer: M2U75, M2U81-M2U84, Z4B12 - Z4B36<\/li>\n\t<li>HP Officejet 5740 series: B9S76-B9S85, F8B09-F8B11, T1P36-T1P38<\/li>\n\t<li>HP Officejet 6220 \/ HP Officejet Pro 6230 ePrinter: E3E03A, C9S13A<\/li>\n\t<li>HP OfficeJet 6600 e-All-in-One: CN581A<\/li>\n\t<li>HP OfficeJet 6700 Premium e-All-in-One: CN583A<\/li>\n\t<li>HP Officejet 6810\/6820 e-All-in-One Printer: F0M65A, G1W52A<\/li>\n\t<li>HP OfficeJet 6950 All-in-One: P4C78A - P4C87A, T3P03A, T3P04A<\/li>\n\t<li>HP OfficeJet Pro 6960 All-in-One: J7K33A - J7K39A, T0F28A - T0F38A, T0G25A - T0G26A<\/li>\n\t<li>HP Officejet 7110 Wide Format ePrinter: CR768A<\/li>\n\t<li>HP Officejet 7510 Wide Format All-in-One Printer: G3J47A<\/li>\n\t<li>HP Officejet 7610 series Wide Format e-All-in-One Printer: CR769A<\/li>\n\t<li>HP Officejet 7612 Wide Format e-All-in-One: G1X85A<\/li>\n\t<li>HP Officejet Pro 251dw Printer: CV136A<\/li>\n\t<li>HP Officejet Pro 276dw Multifunction Printer: CR7770A<\/li>\n\t<li>HP Officejet Pro 3610 Black and White Printer: CZ292A<\/li>\n\t<li>HP Officejet Pro 3620 Black and White Printer: CZ293A<\/li>\n\t<li>HP Officejet Pro 6830 e-All-in-One Printer: E3E02A, J2D37A<\/li>\n\t<li>HP OfficeJet Pro 6970 All-in-One Printer: J7K34A - J7K42A, T0F29A - T0F40A<\/li>\n\t<li>HP OfficeJet Pro 7720 Wide Format All-in-One: Y0S18A<\/li>\n\t<li>HP OfficeJet Pro 7730 Wide Format All-in-One: Y0S19A<\/li>\n\t<li>HP OfficeJet Pro 7740 Wide Format All-in-One: G5J38A, T1P99, T1Q00 - T1Q02<\/li>\n\t<li>HP OfficeJet Pro 8210 Printer<\/li>\n\t<li>HP OfficeJet Pro 8216: D9L63A, D9L64A, T0G70A, J3P68A<\/li>\n\t<li>HP OfficeJet Pro 8600A e-All-in-One: CM749A<\/li>\n\t<li>HP OfficeJet Pro 8600A Plus e-All-in-One: CM750A<\/li>\n\t<li>HP OfficeJet Pro 8600A Premium e-All-in-One: CN577A<\/li>\n\t<li>HP Officejet Pro 8610 e-All-in-One Printer: A7F64A, D7Z36A, E1D34A, J5T77A, T0K98A<\/li>\n\t<li>HP Officejet Pro 8620 e-All-in-One Printer: A7F65A, D7Z37A<\/li>\n\t<li>HP Officejet Pro 8630 e-All-in-One Printer: A7F66A<\/li>\n\t<li>HP Officejet Pro 8640 e-All-in-One Printer: E2D42A<\/li>\n\t<li>HP Officejet Pro 8660 e-All-in-One Printer: E1D36A<\/li>\n\t<li>HP OfficeJet Pro 8710 All-in-One Printer: D9L18A, J6X76A - J6X78A, J6X80A - J6X81A, K7S37A - K7S38A, M9L65A - M9L66A, M9L70A, M9L81A, T0G45A - T0G49A<\/li>\n\t<li>HP OfficeJet Pro 8720 All-in-One Printer : D9L19A, J7A28A, J7A31A, K7S34A - K7S36A, M9L73A - M9L75A, M9L80A, T0G50A - T0G51A,T0G54A,<\/li>\n\t<li>T6T77A<\/li>\n\t<li>HP OfficeJet Pro 8730: D9L20A<\/li>\n\t<li>HP OfficeJet Pro 8732M All-in-One Printer: T0G56A - T0G59A<\/li>\n\t<li>HP OfficeJet Pro 8740: K7S42A<\/li>\n\t<li>HP Photosmart 5510 series: CQ176-CQ190<\/li>\n\t<li>HP Photosmart 5510d series: CQ761-CQ769<\/li>\n\t<li>HP Photosmart 5520 series e-All-in-One<\/li>\n\t<li>HP Photosmart 5521 e-All-in-One<\/li>\n\t<li>HP Photosmart 5522 e-All-in-One<\/li>\n\t<li>HP Photosmart 5524 e-All-in-One<\/li>\n\t<li>HP Photosmart 5525 e-All-in-One: CX042 - CX049<\/li>\n\t<li>HP Photosmart 6510 series: CQ761-CQ769<\/li>\n\t<li>HP Photosmart 6520 e-All-in-One: CX017A - CX021C<\/li>\n\t<li>HP Photosmart 7520 series: CZ025A, CZ045A - CZ046A<\/li>\n\t<li>HP Photosmart Plus All-in-One B210 series: B210<\/li>\n\t<li>HP Smart Tank Wireless 450: Z4B07A, Z4B56A<\/li>\n<\/ul><p>CVE Reference: CVE-2018-5924, CVE-2018-5925<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.hp.com\/us-en\/document\/c06097712\"><font color=\"#0066cc\">https:\/\/support.hp.com\/us-en\/document\/c06097712<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hp-security-updates-0","alert_type":396,"serial_number":"AV18-128","subject":null,"moderation_state":"archived","external_url":null},{"nid":855,"title":"VMware security advisory","uuid":"5aec276d-a018-42ff-bc68-1da92c96bd2f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-09-07T20:14:41Z","summary":null,"body":["<article data-history-node-id=\"855\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-14\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-129<br \/>\nDate: 08 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware has released multiple security updates addressing various vulnerabilities in their products.\u00a0<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware Horizon 6<\/li>\n\t<li>VMware Horizon 7\u00a0<\/li>\n\t<li>VMware Horizon Client for Windows<\/li>\n<\/ul><p>CVE Reference: CVE-2018-6970<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0019.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0019.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-14","alert_type":396,"serial_number":"AV18-129","subject":null,"moderation_state":"archived","external_url":null},{"nid":1002,"title":"ISC Releases security advisory for BIND","uuid":"4dec9f15-37f2-42de-ad0f-8547fc230d31","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:40Z","date_created":"2018-09-07T20:30:09Z","summary":null,"body":["<article data-history-node-id=\"1002\" about=\"\/en\/alerts-advisories\/isc-releases-security-advisory-bind\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-130<br \/>\nDate: 09 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this Advisory is to bring attention ISC's recent security advisory for BIND.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released a security advisory that addresses a vulnerability affecting multiple versions of ISC Berkeley Internet Name Domain (BIND). A remote attacker could exploit this vulnerability to cause a denial-of-service condition.<\/p>\n\n<p>Affected versions:<\/p>\n\n<ul><li>9.7.0 to 9.8.8<\/li>\n\t<li>9.9.0 to 9.9.13<\/li>\n\t<li>9.10.0 to 9.10.8<\/li>\n\t<li>9.11.0 to 9.11.4<\/li>\n\t<li>9.12.0 to 9.12.2<\/li>\n\t<li>9.13.0 to 9.13.2<\/li>\n<\/ul><p>CVE Reference: CVE-2018-5740<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.isc.org\/article\/AA-01639\/0\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/article\/AA-01639\/0<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-releases-security-advisory-bind","alert_type":396,"serial_number":"AV18-130","subject":null,"moderation_state":"archived","external_url":null},{"nid":1127,"title":"Oracle Security Alert","uuid":"0ad30824-2f75-45de-8ce9-47b3bb9ee885","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-09-07T20:38:03Z","summary":null,"body":["<article data-history-node-id=\"1127\" about=\"\/en\/alerts-advisories\/oracle-security-alert\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-131<br \/>\nDate: \u00a014 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent security alert for Oracle.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has issued a security alert advisory that addresses a vulnerability in Oracle Database. A successful exploitation of that vulnerability can result in complete compromise of the Oracle Database and shell access to the underlying server.<\/p>\n\n<p>Versions Affected:<br \/>\n- Oracle Database versions 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18<\/p>\n\n<p>CVE Reference: CVE-2018-3110<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0\u00a0\u00a0<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2018-3110-5032149.html\"><font color=\"#0066cc\">http:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2018-3110-5032149.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-alert","alert_type":396,"serial_number":"AV18-131","subject":null,"moderation_state":"archived","external_url":null},{"nid":800,"title":"Microsoft security updates","uuid":"38a0ad7b-8755-4b80-8f8b-47fb22c37e0d","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:22Z","date_created":"2018-09-07T20:44:48Z","summary":null,"body":["<article data-history-node-id=\"800\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-14\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-132<br \/>\nDate: 15 August 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>Adobe Flash Player<\/li>\n\t<li>ChakraCore<\/li>\n\t<li>Internet Explorer<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Exchange Server<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Microsoft Office Services and Web Apps<\/li>\n\t<li>Microsoft SQL Server<\/li>\n\t<li>Microsoft Visual Studio<\/li>\n\t<li>Microsoft Windows<\/li>\n\t<li>Microsoft .NET Framework<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-3615, CVE-2018-3620, CVE-2018-3646, CVE-2018-3665, CVE-2018-8273, CVE-2018-8341,<br \/>\nCVE-2018-8348, CVE-2018-8351, CVE-2018-8360, CVE-2018-8370, CVE-2018-8378, CVE-2018-8382,<br \/>\nCVE-2018-8394, CVE-2018-8396, CVE-2018-8398, CVE-2018-12824, CVE-2018-12825, CVE-2018-12826,<br \/>\nCVE-2018-12827, CVE-2018-12828<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/ecb26425-583f-e811-a96f-000d3a33c573\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/ecb26425-583f-e811-a96f-000d3a33c573<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180016\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180016<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180018\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180018<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180020\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180020<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-14","alert_type":396,"serial_number":"AV18-132","subject":null,"moderation_state":"archived","external_url":null},{"nid":1291,"title":"Intel security advisory","uuid":"0b963e39-0955-47c5-8958-607f4b4819a9","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:07Z","date_created":"2018-09-11T14:32:23Z","summary":null,"body":["<article data-history-node-id=\"1291\" about=\"\/en\/alerts-advisories\/intel-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-133<br \/>\nDate: 15 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recent public security advisory from Intel.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Intel has issued a security advisory that addresses vulnerabilities in a speculative execution side-channel method called L1 Terminal Fault (L1TF). This method impacts select microprocessor products supporting Intel Software Guard Extensions (Intel SGX). A successful exploitation of this class of vulnerability may allow unauthorized disclosure of information residing in the L1 data cache.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Intel Core i3 processor (45nm and 32nm)<\/li>\n\t<li>Intel Core i5 processor (45nm and 32nm)<\/li>\n\t<li>Intel Core i7 processor (45nm and 32nm)<\/li>\n\t<li>Intel Core M processor family (45nm and 32nm)<\/li>\n\t<li>2nd generation Intel Core processors<\/li>\n\t<li>3rd generation Intel Core processors<\/li>\n\t<li>4th generation Intel Core processors<\/li>\n\t<li>5th generation Intel Core processors<\/li>\n\t<li>6th generation Intel Core processors<\/li>\n\t<li>7th generation Intel Core processors<\/li>\n\t<li>8th generation Intel Core processors<\/li>\n\t<li>Intel Core X-series Processor Family for Intel X99 platforms<\/li>\n\t<li>Intel Core X-series Processor Family for Intel X299 platforms<\/li>\n\t<li>Intel Xeon processor 3400 series<\/li>\n\t<li>Intel Xeon processor 3600 series<\/li>\n\t<li>Intel Xeon processor 5500 series<\/li>\n\t<li>Intel Xeon processor 5600 series<\/li>\n\t<li>Intel Xeon processor 6500 series<\/li>\n\t<li>Intel Xeon processor 7500 series<\/li>\n\t<li>Intel Xeon Processor E3 Family<\/li>\n\t<li>Intel Xeon Processor E3 v2 Family<\/li>\n\t<li>Intel Xeon Processor E3 v3 Family<\/li>\n\t<li>Intel Xeon Processor E3 v4 Family<\/li>\n\t<li>Intel Xeon Processor E3 v5 Family<\/li>\n\t<li>Intel Xeon Processor E3 v6 Family<\/li>\n\t<li>Intel Xeon Processor E5 Family<\/li>\n\t<li>Intel Xeon Processor E5 v2 Family<\/li>\n\t<li>Intel Xeon Processor E5 v3 Family<\/li>\n\t<li>Intel Xeon Processor E5 v4 Family<\/li>\n\t<li>Intel Xeon Processor E7 Family<\/li>\n\t<li>Intel Xeon Processor E7 v2 Family<\/li>\n\t<li>Intel Xeon Processor E7 v3 Family<\/li>\n\t<li>Intel Xeon Processor E7 v4 Family<\/li>\n\t<li>Intel Xeon Processor Scalable Family<\/li>\n\t<li>Intel Xeon Processor D (1500, 2100)<\/li>\n<\/ul><p>CVE References: CVE-2018-3615, CVE-2018-3620, CVE-2018-3646<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00161.html\"><font color=\"#0066cc\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00161.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory","alert_type":396,"serial_number":"AV18-133","subject":null,"moderation_state":"archived","external_url":null},{"nid":1274,"title":"VMware Security Advisories","uuid":"dbac8435-4230-49b7-ba0a-25da70fe4c1b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-09-11T14:42:20Z","summary":null,"body":["<article data-history-node-id=\"1274\" about=\"\/en\/alerts-advisories\/vmware-security-advisories-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-134<br \/>\nDate: 15 August 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to security advisories released by VMware.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>VMware released a security update to address several vulnerabilities in various products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>VMware vCenter Server (VC)<\/li>\n\t<li>VMware vSphere ESXi (ESXi)<\/li>\n\t<li>VMware Workstation Pro \/ Player (WS)<\/li>\n\t<li>VMware Fusion Pro \/ Fusion (Fusion)<\/li>\n\t<li>VMware vCloud Usage Meter (UM)<\/li>\n\t<li>VMware Identity Manager (vIDM)<\/li>\n\t<li>VMware vSphere Data Protection (VDP)<\/li>\n\t<li>VMware vSphere Integrated Containers (VIC)<\/li>\n\t<li>VMware vRealize Automation (vRA)<\/li>\n<\/ul><p>CVE References: CVE-2018-3620, CVE-2018-3646, CVE-2018-6973<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0020.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0020.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0021.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0021.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0022.html\"><font color=\"#0066cc\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0022.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisories-1","alert_type":396,"serial_number":"AV18-134","subject":null,"moderation_state":"archived","external_url":null},{"nid":923,"title":"Samba security updates","uuid":"5706df8b-7a99-46db-907c-fccd624b9568","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-09-11T14:50:35Z","summary":null,"body":["<article data-history-node-id=\"923\" about=\"\/en\/alerts-advisories\/samba-security-updates-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-135<br \/>\nDate: 15 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recent Samba security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Samba has released updates to address multiple security vulnerabilities.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Samba 4.8.3 and prior versions<\/li>\n\t<li>Samba 4.7.8 and prior versions<\/li>\n\t<li>Samba 4.5.16 and prior versions<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-10858, CVE-2018-10918, CVE-2018-10919, CVE-2018-1139, CVE-2018-1140<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owners\/operators test and deploy the vendor released update or workaround to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/history\/security.html<\/font><\/a>\u00a0<\/li>\n\t<li><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-10858.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-10858.html<\/font><\/a>\u00a0<\/li>\n\t<li><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-10918.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-10918.html<\/font><\/a>\u00a0<\/li>\n\t<li><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-10919.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-10919.html<\/font><\/a>\u00a0\u00a0<\/li>\n\t<li><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-1139.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-1139.html<\/font><\/a>\u00a0\u00a0\u00a0<\/li>\n\t<li><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-1140.html\"><font color=\"#0066cc\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-1140.html<\/font><\/a>\u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-updates-1","alert_type":396,"serial_number":"AV18-135","subject":null,"moderation_state":"archived","external_url":null},{"nid":1019,"title":"SAP security updates","uuid":"ce55b2a0-1d8f-464b-9e60-183c65e28395","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:04Z","date_created":"2018-09-11T15:01:42Z","summary":null,"body":["<article data-history-node-id=\"1019\" about=\"\/en\/alerts-advisories\/sap-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-136<br \/>\nDate: 15 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a series of security updates that resolve numerous vulnerabilities with various SAP applications.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This SAP security advisory outlines numerous patches that resolve vulnerabilities in their products which range from medium to critical.<\/p>\n\n<p>Products Affected:<\/p>\n\n<ul><li>Agentry<\/li>\n\t<li>Infrastructure for UI add-on for SAP NetWeaver (UI_Infra)<\/li>\n\t<li>SAP ABAP Change and Transport System (CTS)<\/li>\n\t<li>SAP ASE<\/li>\n\t<li>SAP BusinessObjects Business Intelligence<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform<\/li>\n\t<li>SAP BusinessObjects Financial Consolidation<\/li>\n\t<li>SAP Complex Assembly Manufacturing<\/li>\n\t<li>SAP Data Services<\/li>\n\t<li>SAP Hana Extended Application Services<\/li>\n\t<li>SAP Hana Smart Data Streaming<\/li>\n\t<li>SAP Identity Management<\/li>\n\t<li>SAP Internet Graphics Server (IGS)<\/li>\n\t<li>SAP IQ<\/li>\n\t<li>SAP Open Server<\/li>\n\t<li>SAP Open Switch<\/li>\n\t<li>SAP Replication Server<\/li>\n\t<li>SAP SQL Anywhere OnDemand<\/li>\n\t<li>SAP Supplier Relationship Management Master Data Management Catalog<\/li>\n\t<li>SAP MaxDB (liveCache)<\/li>\n\t<li>SAP UI Implementation for Decoupled Innovations (UI_700)<\/li>\n\t<li>SAP User Interface Technology (SAP_UI)<\/li>\n\t<li>SDK for SAP ASE<\/li>\n\t<li>SMP<\/li>\n\t<li>Sybase ECDA<\/li>\n\t<li>Sybase IQ<\/li>\n\t<li>Sybase PowerBuilder<\/li>\n\t<li>Sybase Software Dev Kit<\/li>\n\t<li>Sybase SQL Anywhere<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-2416, CVE-2018-2434, CVE-2018-2441, CVE-2018-2442, CVE-2018-2444, CVE-2018-2445, CVE-2018-2446, CVE-2018-2447, CVE-2018-2448, CVE-2018-2449, CVE-2018-2450, CVE-2018-2451<\/p>\n\n<p>Please note that SAP credentials are required to access these references on the link provided below.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to the linked security note where SAP expands on the details of the vulnerabilities of each of the security notes and provides a patch to resolve the issues on each respective product.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=499352742\"><font color=\"#0066cc\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=499352742<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-updates-0","alert_type":396,"serial_number":"AV18-136","subject":null,"moderation_state":"archived","external_url":null},{"nid":763,"title":"Adobe security bulletins","uuid":"1628ef8e-9cd4-4a79-85b7-14790f5998f8","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:02:08Z","date_created":"2018-09-11T16:00:36Z","summary":null,"body":["<article data-history-node-id=\"763\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-137<br \/>\nDate: 15 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently published Adobe security bulletins.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for various Adobe products.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Acrobat DC\u00a0<\/li>\n\t<li>Acrobat Reader DC<\/li>\n\t<li>Acrobat 2017<\/li>\n\t<li>Acrobat Reader 2017<\/li>\n\t<li>Adobe Experience Manager<\/li>\n\t<li>Adobe Flash Player Desktop Runtime<\/li>\n\t<li>Adobe Flash Player for Google Chrome<\/li>\n\t<li>Adobe Flash Player for Microsoft Edge and Internet Explorer 11<\/li>\n\t<li>Creative Cloud Desktop Application (installer)<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-5003, CVE-2018-5005, CVE-2018-12799, CVE-2018-12806, CVE-2018-12807, CVE-2018-12808,<br \/>\nCVE-2018-12824, CVE-2018-12825, CVE-2018-12826, CVE-2018-12827, CVE-2018-12828<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-29.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-29.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-26.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb18-26.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-25.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-25.html<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb18-20.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb18-20.html<\/font><\/a> \u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-6","alert_type":396,"serial_number":"AV18-137","subject":null,"moderation_state":"archived","external_url":null},{"nid":835,"title":"Cisco Security Advisories","uuid":"0238d4d1-2138-4ea8-8639-72dd7f661035","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:10:23Z","date_created":"2018-09-11T16:08:27Z","summary":null,"body":["<article data-history-node-id=\"835\" about=\"\/en\/alerts-advisories\/cisco-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-138<br \/>\nDate: 15 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various products.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Cisco Adaptive Security Appliance Web Services<\/li>\n\t<li>Cisco Web Security Appliance Web Proxy<\/li>\n\t<li>Cisco Unified Communications Manager IM &amp; Presence Service<\/li>\n\t<li>Cisco Web Security Appliance Web Proxy<\/li>\n\t<li>Cisco Small Business 100 Series and 300 Series Wireless Access Points<\/li>\n\t<li>Cisco Registered Envelope Service<\/li>\n\t<li>Cisco Email Security Appliance<\/li>\n\t<li>Cisco Digital Network Architecture Center<\/li>\n\t<li>Cisco Unified Communications Domain Manager<\/li>\n\t<li>Cisco Small Business 100 Series and 300 Series<\/li>\n\t<li>Cisco ASR 9000 Series Aggregation Services Routers<\/li>\n\t<li>Cisco Products Linux Kernel<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2016-5195, CVE-2018-0296, CVE-2018-0367, CVE-2018-0386, CVE-2018-0409, CVE-2018-0410, CVE-2018-0412, CVE-2018-0415, CVE-2018-0418, CVE-2018-0419, CVE-2018-0427, CVE-2018-0428<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-asaftd\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180606-asaftd<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-wsa-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-wsa-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-ucmimps-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-ucmimps-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-wsa-escalation\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-wsa-escalation<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-sb-wap-encrypt\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-sb-wap-encrypt<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-res-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-res-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-esa-file-bypass\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-esa-file-bypass<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-dna-injection\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-dna-injection<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-cucdm-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-cucdm-xss<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-csb-wap-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-csb-wap-dos<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-asr-ptp-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-asr-ptp-dos<\/font><\/a><\/li>\n\t<li><a href=\"http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-linux\"><font color=\"#0066cc\">http:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20161026-linux<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisories","alert_type":396,"serial_number":"AV18-138","subject":null,"moderation_state":"archived","external_url":null},{"nid":976,"title":"Citrix XenServer Multiple security updates","uuid":"8a5bd0d4-298c-484f-858f-baaa91d2278f","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:14:57Z","date_created":"2018-09-11T16:16:19Z","summary":null,"body":["<article data-history-node-id=\"976\" about=\"\/en\/alerts-advisories\/citrix-xenserver-multiple-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-139<br \/>\nDate: 16 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recent security updates for Citrix XenServer.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The following updates are following up on Intel\u2019s recent Security Advisory and addresses vulnerabilities in a speculative execution side-channel method called L1 Terminal Fault (L1TF). These vulnerabilities, if exploited, could allow malicious unprivileged code in guest VMs to read arbitrary host memory, including memory allocated to other guests.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Citrix XenServer 7.5<\/li>\n\t<li>Citrix XenServer 7.4<\/li>\n\t<li>Citrix XenServer 7.1 LTSR CU1<\/li>\n\t<li>Citrix XenServer 7.0<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-3620, CVE-2018-3646, CVE-2018-14007, CVE-2018-TBA1, CVE-2018-TBA2<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX236548\"><font color=\"#0066cc\">https:\/\/support.citrix.com\/article\/CTX236548<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-xenserver-multiple-security-updates","alert_type":396,"serial_number":"AV18-139","subject":null,"moderation_state":"archived","external_url":null},{"nid":880,"title":"Apache Tomcat security updates","uuid":"c82adbed-1ddf-4234-a94f-7d88e3399e07","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:13:34Z","date_created":"2018-09-11T16:21:59Z","summary":null,"body":["<article data-history-node-id=\"880\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-updates-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-140<br \/>\nDate: 21 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this Advisory is to bring attention to Apache Tomcat security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Vulnerabilities in Apache Tomcat's Native Connector could allow an unauthenticated, remote user to obtain sensitive information or cause a denial of service condition.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Fixed in Apache Tomcat Native Connector 1.2.17<\/li>\n\t<li>Fixed in Apache Tomcat Native Connector 1.2.16<\/li>\n<\/ul><p>CVE References: CVE-2018-8019, CVE-2017-15698<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"http:\/\/tomcat.apache.org\/security-native.html\"><font color=\"#0066cc\">http:\/\/tomcat.apache.org\/security-native.html<\/font><\/a>\u00a0<br \/><a href=\"https:\/\/tomcat.apache.org\/download-native.cgi\"><font color=\"#0066cc\">https:\/\/tomcat.apache.org\/download-native.cgi<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-updates-0","alert_type":396,"serial_number":"AV18-140","subject":null,"moderation_state":"archived","external_url":null},{"nid":990,"title":"Apache Struts security update","uuid":"67714d13-1a88-4c1c-afa4-aac4deec9908","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:14Z","date_created":"2018-09-11T16:28:08Z","summary":null,"body":["<article data-history-node-id=\"990\" about=\"\/en\/alerts-advisories\/apache-struts-security-update-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-141<br \/>\nDate: 22 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released critical security updates for Apache Struts.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Apache Foundation has released Struts 2.3.35 and 2.5.17 which contains security fixes to address critical vulnerabilities.<\/p>\n\n<p>Versions affected: Struts 2.3 - Struts 2.3.34, Struts 2.5 - Struts 2.5.16<\/p>\n\n<p>CVE Reference: CVE-2018-11776<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators refer to the linked security bulletin where Apache outlines the updates that remediate these vulnerabilities.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-057\"><font color=\"#0066cc\">https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-057<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-11776\"><font color=\"#0066cc\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-11776<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/semmle.com\/news\/apache-struts-CVE-2018-11776\"><font color=\"#0066cc\">https:\/\/semmle.com\/news\/apache-struts-CVE-2018-11776<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/lgtm.com\/blog\/apache_struts_CVE-2018-11776\"><font color=\"#0066cc\">https:\/\/lgtm.com\/blog\/apache_struts_CVE-2018-11776<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-struts-security-update-1","alert_type":396,"serial_number":"AV18-141","subject":null,"moderation_state":"archived","external_url":null},{"nid":1142,"title":"Adobe security bulletin","uuid":"90e53519-04c3-41c7-bc3b-b5ce34c4219e","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:17:58Z","date_created":"2018-09-11T18:18:24Z","summary":null,"body":["<article data-history-node-id=\"1142\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-142<br \/>\nDate: 22 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>\u00a0<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for various Adobe products.<\/p>\n\n<p>Affected products:<br \/>\n- Photoshop CC 2018, 19.1.5\u00a0and earlier<br \/>\n- Photoshop CC 2017, 18.1.5\u00a0and earlier<\/p>\n\n<p>CVE References: CVE-2018-12810, CVE-2018-12811<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb18-28.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb18-28.html<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-1","alert_type":396,"serial_number":"AV18-142","subject":null,"moderation_state":"archived","external_url":null},{"nid":1230,"title":"Cisco security advisory","uuid":"ea80a3f1-eb2f-4ed9-8ccb-3d88f7c335f1","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:09:24Z","date_created":"2018-09-11T18:24:31Z","summary":null,"body":["<article data-history-node-id=\"1230\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-9\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-143<br \/>\nDate: 29 August 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Cisco Identity Services Engine (ISE)<\/li>\n\t<li>Cisco Unified Intelligence Center<\/li>\n\t<li>Cisco Emergency Responder<\/li>\n\t<li>Cisco Hosted Collaboration Solution for Contact Center<\/li>\n\t<li>Cisco Unified Communications Manager IM &amp; Presence Service (formerly CUPS)<\/li>\n\t<li>Cisco Unified Communications Manager<\/li>\n\t<li>Cisco Unified Contact Center Enterprise<\/li>\n\t<li>Cisco Unified Intelligent Contact Management Enterprise<\/li>\n\t<li>Cisco Unified SIP Proxy Software<\/li>\n\t<li>Cisco Unified Survivable Remote Site Telephony Manager<\/li>\n\t<li>Cisco Unity Connection<\/li>\n\t<li>Cisco Video Distribution Suite for Internet Streaming (VDS-IS)<\/li>\n\t<li>Cisco Network Performance Analysis<\/li>\n\t<li>Cisco Data Center Network Manager (DCNM) software releases prior to 11.0(1)<\/li>\n\t<li>Cisco Tetration Analytics<\/li>\n\t<li>Cisco Firepower Threat Defense (FTD) Software<\/li>\n\t<li>Cisco Identity Services Engine (ISE)<\/li>\n\t<li>Cisco Prime Collaboration Assurance<\/li>\n\t<li>Cisco Prime Collaboration Deployment<\/li>\n\t<li>Cisco Prime Collaboration Provisioning<\/li>\n\t<li>Cisco Prime Infrastructure<\/li>\n\t<li>Cisco IOS XE Software<\/li>\n\t<li>Cisco Network Assurance Engine<\/li>\n\t<li>Cisco Nexus 3000 Series Switches<\/li>\n\t<li>Cisco Nexus 9000 Series Switches - Standalone, NX-OS mode<\/li>\n\t<li>Cisco UCS Standalone C-Series Rack Server - Integrated Management Controller<\/li>\n\t<li>Cisco Emergency Responder<\/li>\n\t<li>Cisco IP Phone 7800 Series<\/li>\n\t<li>Cisco Paging Server<\/li>\n\t<li>Cisco Unity Connection<\/li>\n\t<li>Cisco TelePresence Conductor<\/li>\n\t<li>Cisco Video Surveillance 8000 Series IP Cameras<\/li>\n\t<li>Cisco Aironet 1560 Series Access Points<\/li>\n\t<li>Cisco Aironet 1815 Series Access Points<\/li>\n\t<li>Cisco Aironet 2800 Series Access Points<\/li>\n\t<li>Cisco Aironet 3800 Series Access Points<\/li>\n\t<li>Cisco 4000 Series Integrated Services Routers (IOS XE Open Service Containers)<\/li>\n\t<li>Cisco ASR 1000 Series Aggregation Services Router with RP2 or RP3 (IOS XE Open Service Containers)<\/li>\n\t<li>Cisco ASR 1001-HX Series Aggregation Services Routers (IOS XE Open Service Containers)<\/li>\n\t<li>Cisco ASR 1001-X Series Aggregation Services Routers (IOS XE Open Service Containers)<\/li>\n\t<li>Cisco ASR 1002-HX Series Aggregation Services Routers (IOS XE Open Service Containers)<\/li>\n\t<li>Cisco ASR 1002-X Series Aggregation Services Routers (IOS XE Open Service Containers)<\/li>\n\t<li>Cisco Cloud Services Router 1000V Series (IOS XE Open Service Containers)<\/li>\n\t<li>Cisco Nexus 3000 Series Switches<\/li>\n\t<li>Cisco Nexus 3500 Series Switches<\/li>\n\t<li>Cisco Nexus 5000 Series Switches<\/li>\n\t<li>Cisco Nexus 7000 Series Switches<\/li>\n\t<li>Cisco Nexus 9000 Series Switches - Standalone, NX-OS mode<\/li>\n\t<li>Cisco C880 M4 Server<\/li>\n\t<li>Cisco C880 M5 Server<\/li>\n\t<li>Cisco Enterprise NFV Infrastructure Software (NFVIS)<\/li>\n\t<li>Cisco UCS B-Series M2 Blade Servers<\/li>\n\t<li>Cisco UCS B-Series M3 Blade Servers - Managed<\/li>\n\t<li>Cisco UCS B-Series M4 Blade Servers (except B260, B460)<\/li>\n\t<li>Cisco UCS B-Series M5 Blade Servers<\/li>\n\t<li>Cisco UCS C-Series M2 Rack Servers<\/li>\n\t<li>Cisco UCS C-Series M3 Rack Servers - Managed<\/li>\n\t<li>Cisco UCS C-Series M3 Rack Servers - Standalone<\/li>\n\t<li>Cisco UCS C-Series M4 Rack Servers (except C460) - Standalone 1<\/li>\n\t<li>Cisco UCS C-Series M4 Rack Servers (except C460) -Managed 1<\/li>\n\t<li>Cisco UCS C-Series M5 Rack Servers - Managed 1<\/li>\n\t<li>Cisco UCS C-Series M5 Rack Servers -Standalone 1<\/li>\n\t<li>Cisco UCS E-Series Servers<\/li>\n\t<li>Cisco UCS S3260 M4 Storage Server<\/li>\n\t<li>Cisco Remote Expert Mobile<\/li>\n\t<li>Cisco Video Surveillance Media Server<\/li>\n\t<li>Cisco Metacloud<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-0464, CVE-2018-3615, CVE-2018-3620, CVE-2018-3646, CVE-2018-5391, CVE-2018-11776<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180823-apache-struts\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180823-apache-struts<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180828-dcnm-traversal\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180828-dcnm-traversal<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180824-linux-ip-fragment\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180824-linux-ip-fragment<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180814-cpusidechannel\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180814-cpusidechannel<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-9","alert_type":396,"serial_number":"AV18-143","subject":null,"moderation_state":"archived","external_url":null},{"nid":1253,"title":"Cisco security updates","uuid":"c5a67414-c70c-4dfd-ba1b-99f977693ba5","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:21:39Z","date_created":"2018-09-11T18:31:24Z","summary":null,"body":["<article data-history-node-id=\"1253\" about=\"\/en\/alerts-advisories\/cisco-security-updates-20\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-144<br \/>\nDate: 05 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recent security updates published by Cisco.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Cisco Umbrella<\/li>\n\t<li>RV110W Wireless-N VPN Firewall<\/li>\n\t<li>RV130W Wireless-N Multifunction VPN Router<\/li>\n\t<li>RV215W Wireless-N VPN Router<\/li>\n\t<li>Cisco Webex Meetings Suite (WBS31)<\/li>\n\t<li>Cisco Webex Meetings Suite (WBS32)<\/li>\n\t<li>Cisco Webex Meetings Suite (WBS33)<\/li>\n\t<li>Cisco Webex Meetings<\/li>\n\t<li>Cisco Webex Meetings Server<\/li>\n\t<li>Cisco Webex Teams<\/li>\n\t<li>Cisco Umbrella ERC<\/li>\n\t<li>vEdge 100 Series Routers<\/li>\n\t<li>vEdge 1000 Series Routers<\/li>\n\t<li>vEdge 2000 Series Routers<\/li>\n\t<li>vEdge 5000 Series Routers<\/li>\n\t<li>vManage Network Management System<\/li>\n\t<li>vEdge Cloud Router Platform<\/li>\n\t<li>vSmart Controller Software<\/li>\n\t<li>vBond Orchestrator Software<\/li>\n\t<li>Cisco Integrated Management Controller<\/li>\n\t<li>Cisco Prime Access Registrar<\/li>\n\t<li>Cisco Prime Access Registrar Jumpstart<\/li>\n\t<li>Cisco Data Center Network Manager<\/li>\n<\/ul><p>For more information, please visit:\u00a0 <a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/font><\/a><\/p>\n\n<p>CVE References:<br \/>\nCVE-2018-11776, CVE-2018-0435, CVE-2018-0423, CVE-2018-0422, CVE-2018-0436, CVE-2018-0437, CVE-2018-0438, CVE-2018-0434, CVE-2018-0433, CVE-2018-0432, CVE-2018-0426, CVE-2018-0424, CVE-2018-0425, CVE-2018-0421, CVE-2018-0430, CVE-2018-0431, CVE-2018-0440, CVE-2018-0457, CVE-2018-0452, CVE-2018-0451, CVE-2018-0444, CVE-2018-0445, CVE-2018-0458, CVE-2018-0463, CVE-2018-0460, CVE-2018-0462, CVE-2018-0459, CVE-2018-0439, CVE-2018-0447, CVE-2018-0450, CVE-2018-0454, CVE-2018-0414, CVE-2018-5391, CVE-2018-5390, CVE-2018-6922, CVE-2018-0409<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180823-apache-struts\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180823-apache-struts<\/font><\/a>\u00a0\u00a0<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-umbrella-api\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-umbrella-api<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-overflow\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-overflow<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-pe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-pe<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-id-mod\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-id-mod<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-umbrella-priv\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-umbrella-priv<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-sd-wan-validation\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-sd-wan-validation<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-sd-wan-injection\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-sd-wan-injection<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-sd-wan-escalation\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-sd-wan-escalation<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-traversal\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-traversal<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-injection\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-injection<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-disclosure\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-rv-routers-disclosure<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-cpar-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-cpar-dos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-cimc-injection\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-cimc-injection<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-cdcnm-escalation\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-cdcnm-escalation<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-player-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-player-dos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-tetration-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-tetration-xss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-tetration-vulns\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-tetration-vulns<\/font><\/a>\u00a0\u00a0<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-pcce\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-pcce<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-pca-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-pca-xss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-nso-infodis\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-nso-infodis<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-nfvis-infodis\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-nfvis-infodis<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-nfvis-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-nfvis-dos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-meeting-csrf\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-meeting-csrf<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-esa-url-bypass\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-esa-url-bypass<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-dcnm-xss\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-dcnm-xss<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-csp2100-injection\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-csp2100-injection<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-acsxxe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-acsxxe<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180824-linux-ip-fragment\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180824-linux-ip-fragment<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180824-linux-tcp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180824-linux-tcp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-ucmimps-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180815-ucmimps-dos<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-20","alert_type":396,"serial_number":"AV18-144","subject":null,"moderation_state":"archived","external_url":null},{"nid":857,"title":"Google Releases security update for Chrome","uuid":"2137aae0-e105-44b4-82b5-8b2ceecb4cba","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:08:06Z","date_created":"2018-09-11T18:37:36Z","summary":null,"body":["<article data-history-node-id=\"857\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-39\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-145<br \/>\nDate: 05 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to version 69.0.3497.81 for Windows, Mac, and Linux.<\/p>\n\n<p>This update addresses vulnerabilities in Google Chrome.<\/p>\n\n<p>CVE References: CVE-2018-16065, CVE-2018-16066, CVE-2018-16067, CVE-2018-16068, CVE-2018-16069, CVE-2018-16070, CVE-2018-16071, CVE-2018-16072, CVE-2018-16073, CVE-2018-16074, CVE-2018-16075, CVE-2018-16076, CVE-2018-16077, CVE-2018-16078, CVE-2018-16079, CVE-2018-16080, CVE-2018-16081, CVE-2018-16082, CVE-2018-16083, CVE-2018-16084, CVE-2018-16085, CVE-2018-16086, CVE-2018-16087, CVE-2018-16088<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-39","alert_type":396,"serial_number":"AV18-145","subject":null,"moderation_state":"archived","external_url":null},{"nid":1003,"title":"Mozilla security advisory","uuid":"29ddb8df-c067-42a5-9145-e2598ef40cbb","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:15:40Z","date_created":"2018-09-11T18:43:28Z","summary":null,"body":["<article data-history-node-id=\"1003\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-146<br \/>\nDate: 07 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to two security advisories recently released by Mozilla.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR.<\/p>\n\n<p>Affected Versions:<\/p>\n\n<ul><li>Firefox versions prior to 62<\/li>\n\t<li>Firefox ESR versions prior to 60.2<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2018-12375, CVE-2018-12376, CVE-2018-12377, CVE-2018-12378, CVE-2018-12379, CVE-2018-12381, CVE-2018-12382, CVE-2018-12383, CVE-2018-16541<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates to the affected platforms in accordance with their risk mitigation framework.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-20\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-20\/<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-21\/\"><font color=\"#0066cc\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-21\/<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory","alert_type":396,"serial_number":"AV18-146","subject":null,"moderation_state":"archived","external_url":null},{"nid":1132,"title":"Adobe security bulletins","uuid":"d04f9f68-0f6f-491d-9b1d-b8a94e5d21e2","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:06:49Z","date_created":"2018-09-19T16:19:06Z","summary":null,"body":["<article data-history-node-id=\"1132\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-147<br \/>\nDate: 12 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published Adobe security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for various Adobe products.<\/p>\n\n<p>Affected products:<br \/>\n- Flash Player Desktop Runtime 30.0.0.154 and earlier<br \/>\n- Flash Player for Google Chrome 30.0.0.154 and earlier<br \/>\n- Flash Player for Microsoft Edge and Internet Explorer 11 30.0.0.154 and earlier<br \/>\n- ColdFusion, version 2018.0.0.310739<br \/>\n- ColdFusion, update 6 and earlier<br \/>\n- ColdFusion, version 11, Update 14 and earlier<\/p>\n\n<p>CVE References: CVE-2018-15967, CVE-2018-15965, CVE-2018-15957, CVE-2018-15958, CVE-2018-15959, CVE-2018-15964, CVE-2018-15963, CVE-2018-15962, CVE-2018-15961, CVE-2018-15960<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li>\n\t<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-31.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-31.html<\/font><\/a><\/p>\n\t<\/li>\n\t<li>\n\t<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb18-33.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb18-33.html<\/font><\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-7","alert_type":396,"serial_number":"AV18-147","subject":null,"moderation_state":"archived","external_url":null},{"nid":802,"title":"Google Releases security update for Chrome","uuid":"02276de6-3cb9-4c20-af6b-15812c83c3ee","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:03:22Z","date_created":"2018-09-19T17:55:55Z","summary":null,"body":["<article data-history-node-id=\"802\" about=\"\/en\/alerts-advisories\/google-releases-security-update-chrome-40\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-148<br \/>\nDate: 12 September 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 69.0.3497.92 for Windows, Mac, and Linux.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/font><\/a> \u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-releases-security-update-chrome-40","alert_type":396,"serial_number":"AV18-148","subject":null,"moderation_state":"archived","external_url":null},{"nid":1293,"title":"Microsoft security updates","uuid":"9470088c-2b55-4141-9033-0b3e2169fcbf","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T11:59:07Z","date_created":"2018-09-19T18:03:16Z","summary":null,"body":["<article data-history-node-id=\"1293\" about=\"\/en\/alerts-advisories\/microsoft-security-updates-15\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-149<br \/>\nDate: 12 September 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Microsoft security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>This advisory covers multiple support package deployments addressing multiple vulnerabilities in various Microsoft products.<\/p>\n\n<ul><li>Internet Explorer<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Windows<\/li>\n\t<li>Microsoft Office and Microsoft Office Services and Web Apps<\/li>\n\t<li>ChakraCore<\/li>\n\t<li>Adobe Flash Player<\/li>\n\t<li>.NET Framework<\/li>\n\t<li>Microsoft.Data.OData<\/li>\n\t<li>ASP.NET<\/li>\n<\/ul><p>CVE References: ADV180022, ADV180023, CVE-2018-8315, CVE-2018-8331, CVE-2018-8336, CVE-2018-8419, CVE-2018-8424, CVE-2018-8429, CVE-2018-8430, CVE-2018-8433, CVE-2018-8434, CVE-2018-8442, CVE-2018-8443, CVE-2018-8444, CVE-2018-8445, CVE-2018-8446, CVE-2018-8452, CVE-2018-8474<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<ul><li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/498f2484-a096-e811-a978-000d3a33c573\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/498f2484-a096-e811-a978-000d3a33c573<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180022\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180022<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV188474\"><font color=\"#0066cc\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV188474<\/font><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-updates-15","alert_type":396,"serial_number":"AV18-149","subject":null,"moderation_state":"archived","external_url":null},{"nid":1276,"title":"Apple security updates","uuid":"06c8d52a-68db-430e-9bd2-9e50931bb95b","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:16:16Z","date_created":"2018-09-19T18:13:21Z","summary":null,"body":["<article data-history-node-id=\"1276\" about=\"\/en\/alerts-advisories\/apple-security-updates-15\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-150<br \/>\nDate: 18 September 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Apple security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released security updates for vulnerabilities in various products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Apple Support 2.4 for iOS 11.0 and later<\/li>\n\t<li>Safari 12 for macOS Sierra 10.12.6 and macOS High Sierra 10.13.6<\/li>\n\t<li>watchOS 5 for Apple Watch Series 1 and later<\/li>\n\t<li>tvOS 12 for Apple TV 4th generation and Apple TV 4K<\/li>\n\t<li>iOS12 for iPhone 5s and later, iPad Air and later, and iPod touch 6th generation<\/li>\n<\/ul><p>CVE References:<br \/>\nCVE-2016-1777, CVE-2018-4195, CVE-2018-4305, CVE-2018-4307, CVE-2018-4313, CVE-2018-4322, CVE-2018-4325, CVE-2018-4329, CVE-2018-4330, CVE-2018-4335, CVE-2018-4338, CVE-2018-4352, CVE-2018-4356, CVE-2018-4362, CVE-2018-4363, CVE-2018-4397, CVE-2018-5383<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected products accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT209106\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT209106<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT209107\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT209107<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT209108\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT209108<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT209109\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT209109<\/font><\/a><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT209117\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-us\/HT209117<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-15","alert_type":396,"serial_number":"AV18-150","subject":null,"moderation_state":"archived","external_url":null},{"nid":1346,"title":"NUUO NVRMini2 security update","uuid":"cd976c66-1960-494a-8f95-0b0fab2f3b43","banner":null,"lang":"en","date_modified":"2018-09-26","date_modified_ts":"2018-09-26T12:04:04Z","date_created":"2018-09-19T18:20:59Z","summary":null,"body":["<article data-history-node-id=\"1346\" about=\"\/en\/alerts-advisories\/nuuo-nvrmini2-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-151<br \/>\nDate: 18 September 2018 <\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to the recently released security update for NUUO NVRMini2.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>NUUO has released version 3.9.1 of its camera management system that contains security fixes to address multiple vulnerabilities.<\/p>\n\n<p>Versions affected:<\/p>\n\n<ul><li>NUUO NVRMini2 versions 3.9.0 and earlier<\/li>\n<\/ul><p>CVE References: CVE-2018-1149, CVE-2018-1150, CVE-2018-11523<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that owner\/operators test and deploy the vendor released updates or workarounds to affected platforms accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"http:\/\/ftp.nuuo.com\/NUUO\/NVRmini2\/V3.9.1_DOC\/7_Release_Note\/NUUO_NVRmini2_v3.9.1_Release%20note.pdf\"><font color=\"#0066cc\">http:\/\/ftp.nuuo.com\/NUUO\/NVRmini2\/V3.9.1_DOC\/7_Release_Note\/NUUO_NVRmini2_v3.9.1_Release%20note.pdf<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nuuo-nvrmini2-security-update","alert_type":396,"serial_number":"AV18-151","subject":null,"moderation_state":"archived","external_url":null},{"nid":1337,"title":"Cisco security updates","uuid":"46c3f555-4d38-4834-914d-8e93f53e4497","banner":null,"lang":"en","date_modified":"2018-09-27","date_modified_ts":"2018-09-27T17:34:13Z","date_created":"2018-09-27T17:30:35Z","summary":null,"body":["<article data-history-node-id=\"1337\" about=\"\/en\/alerts-advisories\/cisco-security-updates-21\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-152<br \/>\nDate: 20 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recent security updates published by Cisco.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address several vulnerabilities in various products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Cisco Webex Meetings Suite (WBS32) - Webex Network Recording Player<\/li>\n\t<li>Cisco Webex Meetings Suite (WBS33) - Webex Network Recording Player<\/li>\n\t<li>Cisco Webex Meetings Online - Webex Network Recording Player<\/li>\n\t<li>Cisco Webex Meetings Server - Webex Network Recording Player<\/li>\n<\/ul><p>For more information, please visit:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/font><\/a><\/p>\n\n<p>CVE References:\u00a0<br \/>\nCVE-2018-15414, CVE-2018-15421, CVE-2018-15422<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180919-webex\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180919-webex<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-21","alert_type":396,"serial_number":"AV18-152","subject":null,"moderation_state":"archived","external_url":null},{"nid":1338,"title":"Adobe security bulletins","uuid":"2a97485d-b671-4737-9463-3363ed1e568c","banner":null,"lang":"en","date_modified":"2018-09-27","date_modified_ts":"2018-09-27T18:21:40Z","date_created":"2018-09-27T18:17:45Z","summary":null,"body":["<article data-history-node-id=\"1338\" about=\"\/en\/alerts-advisories\/adobe-security-bulletins-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-153<br \/>\nDate: 20 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a recently published Adobe security bulletin.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Adobe has released security updates for various Adobe products.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>Acrobat DC for Windows and macOS version 2018.011.20058 and earlier<\/li>\n\t<li>Acrobat Reader DC for Windows and macOS version 2018.011.20058 and earlier<\/li>\n\t<li>Acrobat 2017 for Windows and macOS version 2017.011.30099 and earlier<\/li>\n\t<li>Acrobat Reader 2017 for Windows and macOS version 2017.011.30099 and earlier<\/li>\n\t<li>Acrobat DC Classic 2015 for Windows and macOS version 2015.006.30448 and earlier<\/li>\n\t<li>Acrobat Reader DC Classic 2015 for Windows and macOS version 2015.006.30448 and earlier<\/li>\n<\/ul><p>CVE References: CVE-2018-12848, CVE-2018-12849, CVE-2018-12850, CVE-2018-12801, CVE-2018-12840, CVE-2018-12778, CVE-2018-12775<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-34.html\"><font color=\"#0066cc\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-34.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletins-8","alert_type":396,"serial_number":"AV18-153","subject":null,"moderation_state":"archived","external_url":null},{"nid":1339,"title":"ICS security advisory for BIND","uuid":"493cdd9a-a8af-4cbc-b6dd-aa384c8224c4","banner":null,"lang":"en","date_modified":"2018-09-27","date_modified_ts":"2018-09-27T18:28:45Z","date_created":"2018-09-27T18:28:14Z","summary":null,"body":["<article data-history-node-id=\"1339\" about=\"\/en\/alerts-advisories\/ics-security-advisory-bind\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-154<br \/>\nDate: 21 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory recently released by the Internet Systems Consortium (ISC).<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Internet Systems Consortium (ISC) has released a security advisory that addresses a vulnerability affecting multiple versions of ISC Berkeley Internet Name Domain (BIND). A successful exploitation of this vulnerability by an authenticated remote attacker may allow the modification of records on the server for versions of BIND that contain the krb-5-subdomain and ms-subdomain update policies.<\/p>\n\n<p>Affected product:<br \/>\nAll versions of BIND 9 prior to maintenance releases, BIND 9.11.5 and 9.12.3.<\/p>\n\n<p>CVE Reference: CVE-2018-5741<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators review the ISC advisory and apply the solution on affected products accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/kb.isc.org\/docs\/cve-2018-5741\"><font color=\"#0066cc\">https:\/\/kb.isc.org\/docs\/cve-2018-5741<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ics-security-advisory-bind","alert_type":396,"serial_number":"AV18-154","subject":null,"moderation_state":"archived","external_url":null},{"nid":1340,"title":"Google Chrome security update","uuid":"b93cdca4-6f72-4e57-a557-f4f21ba7d85e","banner":null,"lang":"en","date_modified":"2018-09-27","date_modified_ts":"2018-09-27T18:35:36Z","date_created":"2018-09-27T18:34:47Z","summary":null,"body":["<article data-history-node-id=\"1340\" about=\"\/en\/alerts-advisories\/google-chrome-security-update\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-155<br \/>\nDate: 21 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a Google Chrome stable channel update.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The stable channel has been updated to Chrome 69.0.3497.100 for Windows, Mac, and Linux.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2018\/09\/stable-channel-update-for-desktop_17.html\"><font color=\"#0066cc\">https:\/\/chromereleases.googleblog.com\/2018\/09\/stable-channel-update-for-desktop_17.html<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-update","alert_type":396,"serial_number":"AV18-155","subject":null,"moderation_state":"archived","external_url":null},{"nid":1341,"title":"Cisco security advisory","uuid":"480f3af9-6927-4ebe-90e8-10b3f921e9d6","banner":null,"lang":"en","date_modified":"2018-09-27","date_modified_ts":"2018-09-27T18:42:27Z","date_created":"2018-09-27T18:41:59Z","summary":null,"body":["<article data-history-node-id=\"1341\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-10\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-156<br \/>\nDate: 21 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to a security advisory released by Cisco.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco has released a security update to address a vulnerability in Cisco Video Surveillance Manager. A successful exploitation of that vulnerability could allow an unauthenticated remote attacker to log in to an affected system by using the root account, which has default, static user credentials.<\/p>\n\n<p>Affected products:<br \/>\n- Cisco Video Surveillance Manager (VSM) Software Releases 7.10, 7.11, and 7.11.1 if the software was preinstalled by Cisco and is running on the following Cisco Connected Safety and Security Unified Computing System (UCS) platforms:<\/p>\n\n<ul><li>CPS-UCSM4-1RU-K9<\/li>\n\t<li>CPS-UCSM4-2RU-K9<\/li>\n\t<li>KIN-UCSM5-1RU-K9<\/li>\n\t<li>KIN-UCSM5-2RU-K9<\/li>\n<\/ul><p>CVE Reference: CVE-2018-15427<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180921-vsm\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180921-vsm<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-10","alert_type":396,"serial_number":"AV18-156","subject":null,"moderation_state":"archived","external_url":null},{"nid":1342,"title":"Apple security updates","uuid":"c67b17ec-a3bd-4ff2-8966-971a85bf0e74","banner":null,"lang":"en","date_modified":"2018-09-27","date_modified_ts":"2018-09-27T18:49:54Z","date_created":"2018-09-27T18:49:18Z","summary":null,"body":["<article data-history-node-id=\"1342\" about=\"\/en\/alerts-advisories\/apple-security-updates-16\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-157<br \/>\nDate: 25 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to recently released Apple security updates.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Apple has released security updates for vulnerabilities in various products using macOS Mojave 10.14.<\/p>\n\n<p>Affected products:\u00a0<\/p>\n\n<p>-MacBook (Early 2015 and later),<br \/>\n-MacBook Air (Mid 2012 and later),<br \/>\n-MacBook Pro (Mid 2012 and later),<br \/>\n-Mac mini (Late 2012 and later),<br \/>\n-iMac (Late 2012 and later),<br \/>\n-iMac Pro (all models),<br \/>\n-Mac Pro (Late 2013, Mid 2010, and Mid 2012 models with recommended Metal-capable graphics processor, including MSI Gaming Radeon RX 560 and Sapphire Radeon PULSE RX 580)<\/p>\n\n<p>CVE References: CVE-2018-5383, CVE-2018-4324, CVE-2018-4353, CVE-2018-4321, CVE-2018-4333, CVE-2018-4336, CVE-2018-4344, CVE-2016-1777<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><strong>References:<\/strong><\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT209139\"><font color=\"#0066cc\">https:\/\/support.apple.com\/en-ca\/HT209139<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-updates-16","alert_type":396,"serial_number":"AV18-157","subject":null,"moderation_state":"archived","external_url":null},{"nid":1345,"title":"Cisco security updates","uuid":"7fbce340-e1c4-4aa3-8e3c-47fa27ab353c","banner":null,"lang":"en","date_modified":"2018-09-27","date_modified_ts":"2018-09-27T18:57:13Z","date_created":"2018-09-27T18:56:44Z","summary":null,"body":["<article data-history-node-id=\"1345\" about=\"\/en\/alerts-advisories\/cisco-security-updates-22\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-158<br \/>\nDate: 27 September 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this advisory is to bring attention to multiple Cisco security advisories.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Cisco released multiple security updates to address vulnerabilities in various Cisco products.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>Cisco ASA 5500-X Series Adaptive Security Appliance IPsec<\/li>\n\t<li>Cisco Catalyst 6800 Series Switches ROM Monitor Software<\/li>\n\t<li>Cisco Identity Services<\/li>\n\t<li>Cisco IOS XE Software<\/li>\n\t<li>Cisco Webex Meetings Client for Windows<\/li>\n\t<li>Cisco products with Linux Kernel<\/li>\n<\/ul><p>CVE References: CVE-2018-0472, CVE-2018-0466,\u00a0 CVE-2018-0469, CVE-2018-0470, CVE-2018-0485, CVE-2018-0476, CVE-2018-0473, CVE-2018-0467, CVE-2018-0477, CVE-2018-0481, CVE-2018-0480, CVE-2018-0475, CVE-2018-0471, CVE-2018-0422, CVE-2018-0197, CVE-2018-15369, CVE-2018-15371, CVE-2018-15368, CVE-2018-15377, CVE-2018-15372, CVE-2018-15375, CVE-2018-15376, CVE-2018-15374, CVE-2018-15373, CVE-2018-15370, CVE-2015-6323, CVE-2013-5530, CVE-2013-5531, CVE-2018-0277, CVE-2017-6747, CVE-2017-12261, CVE-2018-5391<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<h2>References<\/h2>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20131023-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20131023-ise<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20160113-ise<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170802-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20170802-ise<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-ise\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20171101-ise<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-iseeap\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180516-iseeap<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-pe\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180905-webex-pe<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-catalyst6800\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-catalyst6800<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-cdp-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-cdp-dos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-cdp-memleak\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-cdp-memleak<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-cmp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-cmp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-digsig\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-digsig<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-errdisable\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-errdisable<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-iosxe-cmdinj\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-iosxe-cmdinj<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ipsec\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ipsec<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ipv6hbh\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ipv6hbh<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ir800-memwrite\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ir800-memwrite<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-macsec\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-macsec<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ospfv3-dos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ospfv3-dos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-pnp-memleak\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-pnp-memleak<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-privesc\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-privesc<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ptp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-ptp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-shell-access\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-shell-access<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-sip-alg\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-sip-alg<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-sm1t3e3\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-sm1t3e3<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-tacplus\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-tacplus<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-vtp\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-vtp<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-webdos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-webdos<\/font><\/a><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-webuidos\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20180926-webuidos<\/font><\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-22","alert_type":396,"serial_number":"AV18-158","subject":null,"moderation_state":"archived","external_url":null},{"nid":1360,"title":"Adobe security bulletin \u2013 October 2018","uuid":"c6c33589-e04b-46a0-a8c1-01c7d6964c46","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:37:45Z","date_created":"2018-10-05T19:20:33Z","summary":null,"body":["<article data-history-node-id=\"1360\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-october-2018\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-160<\/strong><br \/><strong>Date: 5 October 2018<\/strong><\/p>\n\n<p>Adobe has released security updates to address multiple vulnerabilities affecting Adobe Acrobat and Reader for Windows and MacOS. A remote attacker could exploit some of these vulnerabilities to execute arbitrary code.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-30.html\">Adobe Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-october-2018","alert_type":396,"serial_number":"AV18-160","subject":null,"moderation_state":"archived","external_url":null},{"nid":1359,"title":"Cisco security updates","uuid":"dfca7a90-3050-45d4-ba1c-d8e8a802dd76","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:33:19Z","date_created":"2018-10-05T19:37:43Z","summary":null,"body":["<article data-history-node-id=\"1359\" about=\"\/en\/alerts-advisories\/cisco-security-updates-23\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-161<\/strong><br \/><strong>Date: 5 October 2018<\/strong><\/p>\n\n<p>Cisco has released security updates to address multiple vulnerabilities affecting multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-updates-23","alert_type":396,"serial_number":"AV18-161","subject":null,"moderation_state":"archived","external_url":null},{"nid":1358,"title":"Apache security updates for Apache Tomcat","uuid":"85d27cba-3739-41a8-b84d-7b44e979a0b6","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:29:00Z","date_created":"2018-10-05T20:02:54Z","summary":null,"body":["<article data-history-node-id=\"1358\" about=\"\/en\/alerts-advisories\/apache-security-updates-apache-tomcat\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-162<\/strong><br \/><strong>Date: 5 October 2018<\/strong><\/p>\n\n<p>Apache has released security updates to address multiple vulnerabilities affecting Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to obtain sensitive information.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"http:\/\/mail-archives.us.apache.org\/mod_mbox\/www-announce\/201810.mbox\/%3c4cf697b0-db03-9eab-f2aa-54c2026d0e88@apache.org%3e\">Apache Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-updates-apache-tomcat","alert_type":396,"serial_number":"AV18-162","subject":null,"moderation_state":"archived","external_url":null},{"nid":1361,"title":"Mozilla security update for Thunderbird","uuid":"57d7ec20-87fa-4eda-bd05-d45191465b43","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:42:11Z","date_created":"2018-10-05T20:13:05Z","summary":null,"body":["<article data-history-node-id=\"1361\" about=\"\/en\/alerts-advisories\/mozilla-security-update-thunderbird\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-159<\/strong><br \/><strong>Date: 5 October 2018<\/strong><\/p>\n\n<p>Mozilla has released security updates to address multiple vulnerabilities affecting Thunderbird. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-25\/\">Mozilla Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-update-thunderbird","alert_type":396,"serial_number":"AV18-159","subject":null,"moderation_state":"archived","external_url":null},{"nid":1357,"title":"VMWare security update for AirWatch Console","uuid":"fcbb5dfa-bda6-4138-8ea9-db2d7fc84631","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:24:11Z","date_created":"2018-10-05T20:21:46Z","summary":null,"body":["<article data-history-node-id=\"1357\" about=\"\/en\/alerts-advisories\/vmware-security-update-airwatch-console\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-163<\/strong><br \/><strong>Date: 5 October 2018<\/strong><\/p>\n\n<p>VMWare has released security updates to address multiple vulnerabilities affecting AirWatch Console. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0024.html\">VMWare Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-update-airwatch-console","alert_type":396,"serial_number":"AV18-163","subject":null,"moderation_state":"archived","external_url":null},{"nid":1353,"title":"VMware Releases security updates","uuid":"b02aa3c4-9204-44b7-91da-96884c0536fa","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T17:38:38Z","date_created":"2018-10-10T19:08:22Z","summary":null,"body":["<article data-history-node-id=\"1353\" about=\"\/en\/alerts-advisories\/vmware-releases-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-167<\/strong><br \/><strong>Date: 10 October 2018<\/strong><\/p>\n\n<p>VMware has released security updates to address multiple vulnerabilities affecting VMware products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0025.html\">VMware Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-releases-security-updates","alert_type":396,"serial_number":"AV18-167","subject":null,"moderation_state":"archived","external_url":null},{"nid":1355,"title":"Microsoft security bulletin Summary for October 2018","uuid":"8986f36d-e18e-4947-9cc7-cbb3639bcfad","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:06:32Z","date_created":"2018-10-10T19:12:36Z","summary":null,"body":["<article data-history-node-id=\"1355\" about=\"\/en\/alerts-advisories\/microsoft-security-bulletin-summary-october-2018\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-165<\/strong><br \/><strong>Date: 10 October 2018<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities affecting Microsoft products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/aa99ba28-e99f-e811-a978-000d3a33c573\">Microsoft Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-bulletin-summary-october-2018","alert_type":396,"serial_number":"AV18-165","subject":null,"moderation_state":"archived","external_url":null},{"nid":1354,"title":"Adobe security bulletin \u2013 October 2018","uuid":"8ec16fab-6c2e-4dc5-90f9-f04f10fa82e4","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:01:42Z","date_created":"2018-10-10T19:19:43Z","summary":null,"body":["<article data-history-node-id=\"1354\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-october-2018-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-166<\/strong><br \/><strong>Date: 10 October 2018<\/strong><\/p>\n\n<p>Adobe has released security updates to address multiple vulnerabilities affecting Adobe products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<ul><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb18-27.html\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb18-27.html<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb18-37.html\">https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb18-37.html<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/techcommsuite\/apsb18-38.html\">https:\/\/helpx.adobe.com\/security\/products\/techcommsuite\/apsb18-38.html<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-october-2018-0","alert_type":396,"serial_number":"AV18-166","subject":null,"moderation_state":"archived","external_url":null},{"nid":1356,"title":"Apple Releases security updates","uuid":"f75d3e13-972b-45f2-b888-ae94b1345052","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T18:14:56Z","date_created":"2018-10-10T19:25:56Z","summary":null,"body":["<article data-history-node-id=\"1356\" about=\"\/en\/alerts-advisories\/apple-releases-security-updates\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-164<\/strong><br \/><strong>Date: 10 October 2018<\/strong><\/p>\n\n<p>Apple has released security updates to address multiple vulnerabilities affecting Apple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<ul><li><a href=\"https:\/\/support.apple.com\/en-us\/HT209141\">https:\/\/support.apple.com\/en-us\/HT209141<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT209162\">https:\/\/support.apple.com\/en-us\/HT209162<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-releases-security-updates","alert_type":396,"serial_number":"AV18-164","subject":null,"moderation_state":"archived","external_url":null},{"nid":1352,"title":"Juniper security bulletins","uuid":"f2b093bc-6121-4a9e-b21f-5669955203c0","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T17:33:04Z","date_created":"2018-10-11T17:31:11Z","summary":null,"body":["<article data-history-node-id=\"1352\" about=\"\/en\/alerts-advisories\/juniper-security-bulletins-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-168<\/strong><br \/><strong>Date: 11 October 2018<\/strong><\/p>\n\n<p>Juniper has released security updates to address multiple vulnerabilities affecting Juniper products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the <a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">Juniper Security Advisories and Alerts webpage<\/a> and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-bulletins-1","alert_type":396,"serial_number":"AV18-168","subject":null,"moderation_state":"archived","external_url":null},{"nid":1362,"title":"Chrome security bulletins","uuid":"2115804d-f4ec-43f4-8c6a-c1e87ebad321","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T20:24:11Z","date_created":"2018-10-17T20:24:11Z","summary":null,"body":["<article data-history-node-id=\"1362\" about=\"\/en\/alerts-advisories\/chrome-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-169<\/strong><br \/><strong>Date: 17 October 2018<\/strong><\/p>\n\n<p>Google Releases Security Update for Chrome. The stable channel has been updated to Chrome 70.0.3538.67 for Windows, Mac, and Linux.<\/p>\n\n<p>CCCS encourages that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2018\/10\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2018\/10\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/chrome-security-bulletins","alert_type":396,"serial_number":"AV18-169","subject":null,"moderation_state":"archived","external_url":null},{"nid":1363,"title":"libssh security bulletins","uuid":"c401fbd8-b663-4f71-9cdf-d957777c72e4","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T20:29:15Z","date_created":"2018-10-17T20:29:15Z","summary":null,"body":["<article data-history-node-id=\"1363\" about=\"\/en\/alerts-advisories\/libssh-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-170<\/strong><br \/><strong>Date: 17 October 2018<\/strong><\/p>\n\n<p>libssh has released a security update to address a vulnerability affecting the libssh library. A remote attacker could exploit this vulnerability and execute commands on the affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the libssh news release and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.libssh.org\/2018\/10\/16\/libssh-0-8-4-and-0-7-6-security-and-bugfix-release\">https:\/\/www.libssh.org\/2018\/10\/16\/libssh-0-8-4-and-0-7-6-security-and-bugfix-release<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/libssh-security-bulletins","alert_type":396,"serial_number":"AV18-170","subject":null,"moderation_state":"archived","external_url":null},{"nid":1364,"title":"Oracle security bulletins","uuid":"ac95e9b5-0046-4b6a-9c49-668bebdb7d48","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T20:32:44Z","date_created":"2018-10-17T20:32:44Z","summary":null,"body":["<article data-history-node-id=\"1364\" about=\"\/en\/alerts-advisories\/oracle-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-171<\/strong><br \/><strong>Date: 17 October 2018<\/strong><\/p>\n\n<p>Oracle has released security updates to address multiple vulnerabilities affecting Oracle products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Oracle Critical Patch Update and Security Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2018-4428296.html\">https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2018-4428296.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-bulletins","alert_type":396,"serial_number":"AV18-171","subject":null,"moderation_state":"archived","external_url":null},{"nid":1365,"title":"VMWare security bulletins","uuid":"3c81a65e-20fe-4048-b324-c6de814a0048","banner":null,"lang":"en","date_modified":"2018-10-17","date_modified_ts":"2018-10-17T20:36:00Z","date_created":"2018-10-17T20:36:00Z","summary":null,"body":["<article data-history-node-id=\"1365\" about=\"\/en\/alerts-advisories\/vmware-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-172<\/strong><br \/><strong>Date: 17 October 2018<\/strong><\/p>\n\n<p>VMWare has released security updates to address multiple vulnerabilities affecting VMWare products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the VMWare Security Advisories webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0026.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0026.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletins","alert_type":396,"serial_number":"AV18-172","subject":null,"moderation_state":"archived","external_url":null},{"nid":1366,"title":"Cisco security bulletins","uuid":"669a865a-58eb-4097-a6bc-faffcd854b92","banner":null,"lang":"en","date_modified":"2018-10-18","date_modified_ts":"2018-10-18T14:57:22Z","date_created":"2018-10-18T14:57:22Z","summary":null,"body":["<article data-history-node-id=\"1366\" about=\"\/en\/alerts-advisories\/cisco-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-173<\/strong><br \/><strong>Date: 18 October 2018<\/strong><\/p>\n\n<p>Cisco has released security updates to address multiple vulnerabilities affecting Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletins","alert_type":396,"serial_number":"AV18-173","subject":null,"moderation_state":"archived","external_url":null},{"nid":1367,"title":"Drupal security bulletins","uuid":"6ff94b0b-20d6-4069-8d1f-238901582044","banner":null,"lang":"en","date_modified":"2018-10-19","date_modified_ts":"2018-10-19T17:34:13Z","date_created":"2018-10-19T17:34:13Z","summary":null,"body":["<article data-history-node-id=\"1367\" about=\"\/en\/alerts-advisories\/drupal-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-174<\/strong><br \/><strong>Date: 19 October 2018<\/strong><\/p>\n\n<p>Drupal has released security updates to address multiple vulnerabilities affecting Drupal products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Drupal Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2018-006\">https:\/\/www.drupal.org\/sa-core-2018-006<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-bulletins","alert_type":396,"serial_number":"AV18-174","subject":null,"moderation_state":"archived","external_url":null},{"nid":1368,"title":"Cisco security bulletins","uuid":"ec249e61-611d-452e-955c-38443ba2642f","banner":null,"lang":"en","date_modified":"2018-10-19","date_modified_ts":"2018-10-19T20:05:54Z","date_created":"2018-10-19T20:05:54Z","summary":null,"body":["<article data-history-node-id=\"1368\" about=\"\/en\/alerts-advisories\/cisco-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-175<\/strong><br \/><strong>Date: 19 October 2018<\/strong><\/p>\n\n<p>Cisco has released a security advisory to address a vulnerability potentially affecting Cisco products. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates as they become available.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181019-libssh\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181019-libssh<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletins-0","alert_type":396,"serial_number":"AV18-175","subject":null,"moderation_state":"archived","external_url":null},{"nid":1369,"title":"F5 Networks security bulletins","uuid":"ec276d75-e482-4829-8971-66be48b73f16","banner":null,"lang":"en","date_modified":"2018-10-23","date_modified_ts":"2018-10-23T15:36:35Z","date_created":"2018-10-23T15:36:35Z","summary":null,"body":["<article data-history-node-id=\"1369\" about=\"\/en\/alerts-advisories\/f5-networks-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-176<\/strong><br \/><strong>Date: 23 October 2018<\/strong><\/p>\n\n<p>F5 Networks has released a security advisory to address a vulnerability affecting F5 Network products. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to monitor the F5 Networks Security Advisory webpage and apply the necessary updates as they become available.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K52868493\">https:\/\/support.f5.com\/csp\/article\/K52868493<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u201d<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-networks-security-bulletins","alert_type":396,"serial_number":"AV18-176","subject":null,"moderation_state":"archived","external_url":null},{"nid":1370,"title":"Mozilla security bulletins","uuid":"684779fe-66e8-4937-a80b-1fec307d20fa","banner":null,"lang":"en","date_modified":"2018-10-25","date_modified_ts":"2018-10-25T17:44:12Z","date_created":"2018-10-25T17:44:12Z","summary":null,"body":["<article data-history-node-id=\"1370\" about=\"\/en\/alerts-advisories\/mozilla-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-177<\/strong><br \/><strong>Date: 24 October 2018<\/strong><\/p>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-26\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-26<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u201d<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-bulletins","alert_type":396,"serial_number":"AV18-177","subject":null,"moderation_state":"archived","external_url":null},{"nid":1371,"title":"Cisco security bulletins","uuid":"8b1c92b9-5d2f-454e-bad2-e73fb0f02969","banner":null,"lang":"en","date_modified":"2018-10-25","date_modified_ts":"2018-10-25T17:48:06Z","date_created":"2018-10-25T17:48:06Z","summary":null,"body":["<article data-history-node-id=\"1371\" about=\"\/en\/alerts-advisories\/cisco-security-bulletins-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-178<\/strong><br \/><strong>Date: 24 October 2018<\/strong><\/p>\n\n<p>Cisco has released a security advisory to address a vulnerability affecting Cisco products. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181024-webex-injection\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181024-webex-injection<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletins-1","alert_type":396,"serial_number":"AV18-178","subject":null,"moderation_state":"archived","external_url":null},{"nid":1372,"title":"Citrix security bulletins","uuid":"a1b1d8e0-ea8c-4da0-a436-109a3b8062fc","banner":null,"lang":"en","date_modified":"2018-10-25","date_modified_ts":"2018-10-25T17:53:54Z","date_created":"2018-10-25T17:53:54Z","summary":null,"body":["<article data-history-node-id=\"1372\" about=\"\/en\/alerts-advisories\/citrix-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-179<\/strong><br \/><strong>Date: 24 October 2018<\/strong><\/p>\n\n<p>Citrix has released a security advisory to address vulnerabilities affecting Citrix products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Citrix Security Updates webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX236992\">https:\/\/support.citrix.com\/article\/CTX236992<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-bulletins","alert_type":396,"serial_number":"AV18-179","subject":null,"moderation_state":"archived","external_url":null},{"nid":1375,"title":"Apple security bulletins","uuid":"888d1e70-4807-4c03-bf7b-4d51bcd6b7e1","banner":null,"lang":"en","date_modified":"2018-10-30","date_modified_ts":"2018-10-30T20:26:55Z","date_created":"2018-10-30T20:26:55Z","summary":null,"body":["<article data-history-node-id=\"1375\" about=\"\/en\/alerts-advisories\/apple-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-180<\/strong><br \/><strong>Date: 30 October 2018<\/strong><\/p>\n\n<p>Apple has released security updates to address multiple vulnerabilities affecting Apple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Updates webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-bulletins","alert_type":396,"serial_number":"AV18-180","subject":null,"moderation_state":"archived","external_url":null},{"nid":1373,"title":"Apache security bulletins","uuid":"ed6a262a-04ee-4bff-920c-490cc04c9f2d","banner":null,"lang":"en","date_modified":"2018-11-01","date_modified_ts":"2018-11-01T18:23:05Z","date_created":"2018-11-01T18:23:05Z","summary":null,"body":["<article data-history-node-id=\"1373\" about=\"\/en\/alerts-advisories\/apache-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-181<\/strong><br \/><strong>Date: 1 November 2018<\/strong><\/p>\n\n<p>Apache has released a security update to address a vulnerability affecting the Apache Tomcat JK Connector product. A remote attacker could exploit this vulnerability to access restricted parts of the filesystem.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apache Tomcat JK Connector vulnerabilities webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"http:\/\/tomcat.apache.org\/security-jk.html\">http:\/\/tomcat.apache.org\/security-jk.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-bulletins","alert_type":396,"serial_number":"AV18-181","subject":null,"moderation_state":"archived","external_url":null},{"nid":1374,"title":"Cisco security bulletins","uuid":"50db6310-71dc-4839-998f-2f056c841147","banner":null,"lang":"en","date_modified":"2018-11-01","date_modified_ts":"2018-11-01T18:50:14Z","date_created":"2018-11-01T18:50:14Z","summary":null,"body":["<article data-history-node-id=\"1374\" about=\"\/en\/alerts-advisories\/cisco-security-bulletins-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-182<\/strong><br \/><strong>Date: 1 November 2018<\/strong><\/p>\n\n<p>Cisco has released a security update to address a vulnerability affecting some Cisco products. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181101-ap\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181101-ap<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletins-2","alert_type":396,"serial_number":"AV18-182","subject":null,"moderation_state":"archived","external_url":null},{"nid":1376,"title":"Apache Struts security bulletin","uuid":"8b1f1586-3a24-401b-83c7-387bfbd3878f","banner":null,"lang":"en","date_modified":"2018-11-06","date_modified_ts":"2018-11-06T15:38:37Z","date_created":"2018-11-06T15:38:37Z","summary":null,"body":["<article data-history-node-id=\"1376\" about=\"\/en\/alerts-advisories\/apache-struts-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-183<\/strong><br \/><strong>Date: 5 November 2018<\/strong><\/p>\n\n<p>Apache has released a security update to address a vulnerability affecting the commons-fileupload library used in certain Apache Struts versions. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apache security advisory for CVE-2016-1000031 and upgrade to the latest released version of commons-fileupload library.<\/p>\n\n<p><a href=\"http:\/\/mail-archives.us.apache.org\/mod_mbox\/www-announce\/201811.mbox\/%3CCAMopvkMo8WiP%3DfqVQuZ1Fyx%3D6CGz0Epzfe0gG5XAqP1wdJCoBQ%40mail.gmail.com%3E\">http:\/\/mail-archives.us.apache.org\/mod_mbox\/www-announce\/201811.mbox\/%3CCAMopvkMo8WiP%3DfqVQuZ1Fyx%3D6CGz0Epzfe0gG5XAqP1wdJCoBQ%40mail.gmail.com%3E<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-struts-security-bulletin","alert_type":396,"serial_number":"AV18-183","subject":null,"moderation_state":"archived","external_url":null},{"nid":1377,"title":"Android security bulletins","uuid":"e3c4210d-0e68-49e8-b145-3571e532d283","banner":null,"lang":"en","date_modified":"2018-11-06","date_modified_ts":"2018-11-06T19:17:49Z","date_created":"2018-11-06T19:17:49Z","summary":null,"body":["<article data-history-node-id=\"1377\" about=\"\/en\/alerts-advisories\/android-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-184<\/strong><br \/><strong>Date: 6 November 2018<\/strong><\/p>\n\n<p>Google has released security updates to address multiple vulnerabilities affecting Android products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users to review the Android Security Bulletin and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2018-11-01\">https:\/\/source.android.com\/security\/bulletin\/2018-11-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletins","alert_type":396,"serial_number":"AV18-184","subject":null,"moderation_state":"archived","external_url":null},{"nid":1379,"title":"Self-Encrypting Drive security bulletin","uuid":"001865eb-badd-4c9a-956b-7d0073c8b225","banner":null,"lang":"en","date_modified":"2018-11-07","date_modified_ts":"2018-11-07T16:39:29Z","date_created":"2018-11-07T16:39:29Z","summary":null,"body":["<article data-history-node-id=\"1379\" about=\"\/en\/alerts-advisories\/self-encrypting-drive-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-185<\/strong><br \/><strong>Date: 7 November 2018<\/strong><\/p>\n\n<p>Vulnerabilities with certain self-encrypting drives were recently disclosed which could allow an attacker with physical access to the drive to obtain unencrypted data.<\/p>\n\n<p>CCCS encourages users and administrators to review the Vulnerability Note, Microsoft\u2019s Advisory for Bitlocker users, and Samsung\u2019s Customer Notice.<\/p>\n\n<p>Vulnerability Note: <a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/395981\">https:\/\/www.kb.cert.org\/vuls\/id\/395981<\/a><\/p>\n\n<p>Microsoft Advisory: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180028\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV180028<\/a><\/p>\n\n<p>Samsung Notice: <a href=\"https:\/\/www.samsung.com\/semiconductor\/minisite\/ssd\/support\/consumer-notice\/\">https:\/\/www.samsung.com\/semiconductor\/minisite\/ssd\/support\/consumer-notice\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/self-encrypting-drive-security-bulletin","alert_type":396,"serial_number":"AV18-185","subject":null,"moderation_state":"archived","external_url":null},{"nid":1378,"title":"Cisco security bulletin","uuid":"2781ee65-b398-4de3-b3e8-959febe4bf7d","banner":null,"lang":"en","date_modified":"2018-11-07","date_modified_ts":"2018-11-07T21:44:03Z","date_created":"2018-11-07T21:44:03Z","summary":null,"body":["<article data-history-node-id=\"1378\" about=\"\/en\/alerts-advisories\/cisco-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-186<\/strong><br \/><strong>Date: 7 November 2018<\/strong><\/p>\n\n<p>Cisco has released security updates to address vulnerabilities affecting some Cisco products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletin","alert_type":396,"serial_number":"AV18-186","subject":null,"moderation_state":"archived","external_url":null},{"nid":1380,"title":"VMware security bulletin","uuid":"c13a9bdb-640a-4598-a291-71b38b92d00f","banner":null,"lang":"en","date_modified":"2018-11-09","date_modified_ts":"2018-11-09T20:01:25Z","date_created":"2018-11-09T20:01:25Z","summary":null,"body":["<article data-history-node-id=\"1380\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-187<\/strong><br \/><strong>Date: 9 November 2018<\/strong><\/p>\n\n<p>VMware has released security updates to address vulnerabilities affecting some VMware products. An attacker with access to a virtual machine on the affected host could exploit these vulnerabilities to take control of the host.<\/p>\n\n<p>CCCS encourages users and administrators to review the VMware Security Advisories webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0027.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0027.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin","alert_type":396,"serial_number":"AV18-187","subject":null,"moderation_state":"archived","external_url":null},{"nid":1381,"title":"Microsoft security bulletin","uuid":"b4a574a3-a3fc-48ce-b298-95bacd74b397","banner":null,"lang":"en","date_modified":"2018-11-14","date_modified_ts":"2018-11-14T19:40:07Z","date_created":"2018-11-14T19:40:07Z","summary":null,"body":["<article data-history-node-id=\"1381\" about=\"\/en\/alerts-advisories\/microsoft-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-188<\/strong><br \/><strong>Date: 14 November 2018<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities affecting Microsoft products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft November 2018 Security Updates and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/ff746aa5-06a0-e811-a978-000d3a33c573\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/ff746aa5-06a0-e811-a978-000d3a33c573<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-bulletin","alert_type":396,"serial_number":"AV18-188","subject":null,"moderation_state":"archived","external_url":null},{"nid":1382,"title":"SAP security bulletin","uuid":"74783e70-bbba-47f9-bbc2-da7dff9ffe49","banner":null,"lang":"en","date_modified":"2018-11-14","date_modified_ts":"2018-11-14T19:44:42Z","date_created":"2018-11-14T19:44:42Z","summary":null,"body":["<article data-history-node-id=\"1382\" about=\"\/en\/alerts-advisories\/sap-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-189<\/strong><br \/><strong>Date: 14 November 2018<\/strong><\/p>\n\n<p>SAP has released security updates to address vulnerabilities affecting some SAP products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the SAP Security Patch Day webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=503809832<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-bulletin","alert_type":396,"serial_number":"AV18-189","subject":null,"moderation_state":"archived","external_url":null},{"nid":1383,"title":"Adobe security bulletin","uuid":"d25ccb3d-6cc9-4eac-9b2a-a71382cfcb0c","banner":null,"lang":"en","date_modified":"2018-11-14","date_modified_ts":"2018-11-14T19:50:18Z","date_created":"2018-11-14T19:50:18Z","summary":null,"body":["<article data-history-node-id=\"1383\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-190<\/strong><br \/><strong>Date: 14 November 2018<\/strong><\/p>\n\n<p>Adobe has released security updates to address vulnerabilities affecting some Adobe products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-2","alert_type":396,"serial_number":"AV18-190","subject":null,"moderation_state":"archived","external_url":null},{"nid":1384,"title":"Google security bulletin","uuid":"f527e992-5853-487f-a10c-b97c6bfe7172","banner":null,"lang":"en","date_modified":"2018-11-20","date_modified_ts":"2018-11-20T18:32:27Z","date_created":"2018-11-20T18:32:27Z","summary":null,"body":["<article data-history-node-id=\"1384\" about=\"\/en\/alerts-advisories\/google-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-191<\/strong><br \/><strong>Date: 20 November 2018<\/strong><\/p>\n\n<p>Google has released a security update to address a vulnerability affecting its Google Chrome product. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users to review the Chrome Releases webpage for details about the vulnerability:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/a><\/p>\n\n<p>The latest version of Google Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-bulletin","alert_type":396,"serial_number":"AV18-191","subject":null,"moderation_state":"archived","external_url":null},{"nid":1385,"title":"VMware security bulletin","uuid":"10511ab6-2590-4204-8b07-9acbd4169158","banner":null,"lang":"en","date_modified":"2018-11-21","date_modified_ts":"2018-11-21T16:37:46Z","date_created":"2018-11-21T16:37:46Z","summary":null,"body":["<article data-history-node-id=\"1385\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-193<\/strong><br \/><strong>Date: 21 November 2018<\/strong><\/p>\n\n<p>VMware has released security updates to address vulnerabilities affecting some VMware products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the VMware Security Advisories webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0029.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0029.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin-0","alert_type":396,"serial_number":"AV18-193","subject":null,"moderation_state":"archived","external_url":null},{"nid":1386,"title":"Adobe security bulletin","uuid":"bd3c5cf0-f5e9-47bb-a005-40185f0abed9","banner":null,"lang":"en","date_modified":"2018-11-21","date_modified_ts":"2018-11-21T20:42:21Z","date_created":"2018-11-21T20:41:51Z","summary":null,"body":["<article data-history-node-id=\"1386\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-192<\/strong><br \/><strong>Date: 20 November 2018<\/strong><\/p>\n\n<p>Adobe has released security updates to address vulnerabilities affecting Adobe Flash Player. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p>For the latest version of Adobe Flash:<\/p>\n\n<p><a href=\"https:\/\/get.adobe.com\/flashplayer\/\">https:\/\/get.adobe.com\/flashplayer\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-3","alert_type":396,"serial_number":"AV18-192","subject":null,"moderation_state":"archived","external_url":null},{"nid":1387,"title":"VMware security bulletin","uuid":"3f908a2e-fe9d-4ddf-84d8-21cee4a75400","banner":null,"lang":"en","date_modified":"2018-11-27","date_modified_ts":"2018-11-27T15:20:29Z","date_created":"2018-11-27T15:20:29Z","summary":null,"body":["<article data-history-node-id=\"1387\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-194<\/strong><br \/><strong>Date: 23 November 2018<\/strong><\/p>\n\n<p>VMware has released security updates to address vulnerabilities affecting some VMware products. An attacker with access to a virtual machine on the affected host could exploit these vulnerabilities to execute code on the host.<\/p>\n\n<p>CCCS encourages users and administrators to review the VMware Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0030.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0030.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin-1","alert_type":396,"serial_number":"AV18-194","subject":null,"moderation_state":"archived","external_url":null},{"nid":1388,"title":"Samba security bulletin","uuid":"4271ab68-564c-412f-9a24-5bb0b34aba2c","banner":null,"lang":"en","date_modified":"2018-11-28","date_modified_ts":"2018-11-28T16:30:07Z","date_created":"2018-11-28T16:30:07Z","summary":null,"body":["<article data-history-node-id=\"1388\" about=\"\/en\/alerts-advisories\/samba-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-195<\/strong><br \/><strong>Date: 27 November 2018<\/strong><\/p>\n\n<p>Samba has released security updates to address multiple vulnerabilities affecting Samba products. An attacker could exploit one of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Samba Security Releases webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">https:\/\/www.samba.org\/samba\/history\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-bulletin","alert_type":396,"serial_number":"AV18-195","subject":null,"moderation_state":"archived","external_url":null},{"nid":1389,"title":"Cisco security bulletin","uuid":"5891d090-e414-4f6b-b1b0-a0d76edf6a07","banner":null,"lang":"en","date_modified":"2018-11-28","date_modified_ts":"2018-11-28T16:34:15Z","date_created":"2018-11-28T16:34:15Z","summary":null,"body":["<article data-history-node-id=\"1389\" about=\"\/en\/alerts-advisories\/cisco-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-196<\/strong><br \/><strong>Date: 27 November 2018<\/strong><\/p>\n\n<p>Cisco has released an update to a previously published security advisory, to address vulnerabilities affecting some Cisco products. A remote attacker could exploit these vulnerabilities to take control of an affected system. This is an update to advisory AV18-178.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181024-webex-injection\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181024-webex-injection<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletin-0","alert_type":396,"serial_number":"AV18-196","subject":null,"moderation_state":"archived","external_url":null},{"nid":1390,"title":"Cisco security bulletin","uuid":"88ff6371-089c-4347-ba29-33854eb41dec","banner":null,"lang":"en","date_modified":"2018-11-29","date_modified_ts":"2018-11-29T20:07:34Z","date_created":"2018-11-29T20:07:34Z","summary":null,"body":["<article data-history-node-id=\"1390\" about=\"\/en\/alerts-advisories\/cisco-security-bulletin-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-197<\/strong><br \/><strong>Date: 29 November 2018<\/strong><\/p>\n\n<p>Cisco has released a security update to address a vulnerability affecting a Cisco product. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisory and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181128-plm-sql-inject\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181128-plm-sql-inject<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletin-1","alert_type":396,"serial_number":"AV18-197","subject":null,"moderation_state":"archived","external_url":null},{"nid":1391,"title":"Kubernetes security bulletin","uuid":"34eb77b8-8759-4996-ac60-a5671dcaf221","banner":null,"lang":"en","date_modified":"2018-12-05","date_modified_ts":"2018-12-05T15:44:58Z","date_created":"2018-12-05T15:44:58Z","summary":null,"body":["<article data-history-node-id=\"1391\" about=\"\/en\/alerts-advisories\/kubernetes-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-198<\/strong><br \/><strong>Date: 4 December 2018<\/strong><\/p>\n\n<p>Kubernetes has released a security update to address a vulnerability affecting Kubernetes and OpenShift products. A remote attacker could exploit this vulnerability, which allows privilege escalation and access to sensitive information in products and services.<\/p>\n\n<p>CCCS encourages users and administrators to review the Kubernetes Security Advisory and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/github.com\/kubernetes\/kubernetes\/issues\/71411\">https:\/\/github.com\/kubernetes\/kubernetes\/issues\/71411<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/kubernetes-security-bulletin","alert_type":396,"serial_number":"AV18-198","subject":null,"moderation_state":"archived","external_url":null},{"nid":1392,"title":"Android security bulletin","uuid":"66ea02a8-caf0-4d97-ab44-8700c2301f24","banner":null,"lang":"en","date_modified":"2018-12-07","date_modified_ts":"2018-12-07T15:14:02Z","date_created":"2018-12-07T15:14:02Z","summary":null,"body":["<article data-history-node-id=\"1392\" about=\"\/en\/alerts-advisories\/android-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-199<\/strong><br \/><strong>Date: 6 December 2018<\/strong><\/p>\n\n<p>Android has released security updates to address multiple vulnerabilities affecting Android products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users to review the Android Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2018-12-01\">https:\/\/source.android.com\/security\/bulletin\/2018-12-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-0","alert_type":396,"serial_number":"AV18-199","subject":null,"moderation_state":"archived","external_url":null},{"nid":1393,"title":"Adobe Security Alert","uuid":"d4f8a6a1-fca2-4779-a1a1-8723a8b84089","banner":null,"lang":"en","date_modified":"2018-12-07","date_modified_ts":"2018-12-07T19:13:53Z","date_created":"2018-12-07T19:13:53Z","summary":null,"body":["<article data-history-node-id=\"1393\" about=\"\/en\/alerts-advisories\/adobe-security-alert\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL18-016<\/strong><br \/><strong>Date: 7 December 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An ALERT is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. (The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this ALERT to recipients as requested.)<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The goal of this Alert is to bring heightened attention to a vulnerability in Adobe Flash for which there is currently a patch available. The vulnerability can be exploited by deceiving an end user into opening a maliciously-crafted Microsoft Office document file. This can lead to remote code execution on the affected computer. There are reports of spear phishing campaigns in the wild with such payloads attached to emails.<\/p>\n\n<p>Adobe Flash Player 31.0.0.153 and earlier are affected.<\/p>\n\n<p>CVE reference: CVE-2018-15982<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<ul><li>The Cyber Centre recommends that organizations update Adobe Flash at their earliest convenience.<\/li>\n\t<li>Remain vigilant for unsolicited emails with attachments from people unknown to you. In such cases, do not open attachments before consulting an IT professional.<\/li>\n\t<li>If the email purports to come from a known sender, ensure that the \u2018from\u2019 email address is correct.<\/li>\n<\/ul><p><strong>References<\/strong><\/p>\n\n<p>Adobe Security Bulletin: <a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-42.html\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb18-42.html<\/a><\/p>\n\n<p>Article: <a href=\"https:\/\/atr-blog.gigamon.com\/2018\/12\/05\/adobe-flash-zero-day-exploited-in-the-wild\/\">https:\/\/atr-blog.gigamon.com\/2018\/12\/05\/adobe-flash-zero-day-exploited-in-the-wild\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-alert","alert_type":397,"serial_number":"AL18-016","subject":null,"moderation_state":"archived","external_url":null},{"nid":1394,"title":"phpMyAdmin security bulletin","uuid":"21b089bd-dbf8-404b-a242-f25415b0a607","banner":null,"lang":"en","date_modified":"2018-12-12","date_modified_ts":"2018-12-12T15:58:26Z","date_created":"2018-12-12T15:58:26Z","summary":null,"body":["<article data-history-node-id=\"1394\" about=\"\/en\/alerts-advisories\/phpmyadmin-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-201<\/strong><br \/><strong>Date: 11 December 2018<\/strong><\/p>\n\n<p>Developers of phpMyAdmin have released security updates to address multiple vulnerabilities affecting phpMyAdmin. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the phpMyAdmin Security Fix webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.phpmyadmin.net\/news\/2018\/12\/11\/security-fix-phpmyadmin-484-released\/\">https:\/\/www.phpmyadmin.net\/news\/2018\/12\/11\/security-fix-phpmyadmin-484-released\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/phpmyadmin-security-bulletin","alert_type":396,"serial_number":"AV18-201","subject":null,"moderation_state":"archived","external_url":null},{"nid":1395,"title":"Adobe security bulletin","uuid":"3e233b59-d9d8-448d-a671-ed7fe8904fc1","banner":null,"lang":"en","date_modified":"2018-12-12","date_modified_ts":"2018-12-12T16:04:14Z","date_created":"2018-12-12T16:04:14Z","summary":null,"body":["<article data-history-node-id=\"1395\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-202<\/strong><br \/><strong>Date: 11 December 2018<\/strong><\/p>\n\n<p>Adobe has released security updates to address vulnerabilities affecting the Adobe Acrobat and Adobe Reader products for Windows and MacOS. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-41.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb18-41.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-4","alert_type":396,"serial_number":"AV18-202","subject":null,"moderation_state":"archived","external_url":null},{"nid":1396,"title":"Mozilla security bulletin","uuid":"bd0941af-a8c1-4d86-a797-10012725e6b4","banner":null,"lang":"en","date_modified":"2018-12-12","date_modified_ts":"2018-12-12T16:08:44Z","date_created":"2018-12-12T16:08:44Z","summary":null,"body":["<article data-history-node-id=\"1396\" about=\"\/en\/alerts-advisories\/mozilla-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-203<\/strong><br \/><strong>Date: 11 December 2018<\/strong><\/p>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-29\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2018-29\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-bulletin","alert_type":396,"serial_number":"AV18-203","subject":null,"moderation_state":"archived","external_url":null},{"nid":1397,"title":"Microsoft security bulletin","uuid":"89fb4a0c-d2ae-4808-8ea0-cd6774011493","banner":null,"lang":"en","date_modified":"2018-12-12","date_modified_ts":"2018-12-12T16:15:28Z","date_created":"2018-12-12T16:15:28Z","summary":null,"body":["<article data-history-node-id=\"1397\" about=\"\/en\/alerts-advisories\/microsoft-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-204<\/strong><br \/><strong>Date: 11 December 2018<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities affecting Microsoft products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft December 2018 Security Updates and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/6c54acc6-2ed2-e811-a980-000d3a33a34d\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/6c54acc6-2ed2-e811-a980-000d3a33a34d<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-bulletin-0","alert_type":396,"serial_number":"AV18-204","subject":null,"moderation_state":"archived","external_url":null},{"nid":1398,"title":"Google security bulletin","uuid":"d6b7ed73-59b0-48d6-9ff9-493847bbc955","banner":null,"lang":"en","date_modified":"2018-12-14","date_modified_ts":"2018-12-14T14:44:47Z","date_created":"2018-12-14T14:44:47Z","summary":null,"body":["<article data-history-node-id=\"1398\" about=\"\/en\/alerts-advisories\/google-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-205<\/strong><br \/><strong>Date: 13 December 2018<\/strong><\/p>\n\n<p>Google has released a security update to address a vulnerability affecting its Google Chrome product. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users to review the Chrome Releases webpage for details about the vulnerability:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates\">https:\/\/chromereleases.googleblog.com\/search\/label\/Stable%20updates<\/a><\/p>\n\n<p>The latest version of Google Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-bulletin-0","alert_type":396,"serial_number":"AV18-205","subject":null,"moderation_state":"archived","external_url":null},{"nid":1399,"title":"Wordpress security bulletin","uuid":"8344a904-bde0-49ba-92d1-fe1a48d3a19b","banner":null,"lang":"en","date_modified":"2018-12-18","date_modified_ts":"2018-12-18T18:46:22Z","date_created":"2018-12-18T18:46:22Z","summary":null,"body":["<article data-history-node-id=\"1399\" about=\"\/en\/alerts-advisories\/wordpress-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-207<\/strong><br \/><strong>Date: 18 December 2018<\/strong><\/p>\n\n<p>Wordpress has released a security update to address a vulnerability affecting the Wordpress Blogging Platform. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users to review the latest Wordpress Security Release webpage for details about the vulnerability and apply the appropriate patches:<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2018\/12\/wordpress-5-0-1-security-release\/\">https:\/\/wordpress.org\/news\/2018\/12\/wordpress-5-0-1-security-release\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-bulletin","alert_type":396,"serial_number":"AV18-207","subject":null,"moderation_state":"archived","external_url":null},{"nid":1400,"title":"SQLite security bulletin","uuid":"00d3d848-0bb3-4218-9f5f-18a5e25a7652","banner":null,"lang":"en","date_modified":"2018-12-18","date_modified_ts":"2018-12-18T19:31:09Z","date_created":"2018-12-18T19:31:09Z","summary":null,"body":["<article data-history-node-id=\"1400\" about=\"\/en\/alerts-advisories\/sqlite-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-206<\/strong><br \/><strong>Date: 18 December 2018<\/strong><\/p>\n\n<p>SQLite has released a security update to address a vulnerability affecting its SQLite database product. It should be noted that SQLite is only exposed to this vulnerability in the context of an attacker being able to run arbitrary commands on the database (SQL injection).<\/p>\n\n<p>CCCS encourages users to review the SQLite webpage to download the latest patched version of the database:<\/p>\n\n<p><a href=\"https:\/\/www.sqlite.org\/index.html\">https:\/\/www.sqlite.org\/index.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sqlite-security-bulletin","alert_type":396,"serial_number":"AV18-206","subject":null,"moderation_state":"archived","external_url":null},{"nid":1401,"title":"VMware security bulletin","uuid":"91d14654-c0c4-4974-b570-b15ba38a7405","banner":null,"lang":"en","date_modified":"2018-12-19","date_modified_ts":"2018-12-19T18:42:24Z","date_created":"2018-12-19T18:42:24Z","summary":null,"body":["<article data-history-node-id=\"1401\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-208<\/strong><br \/><strong>Date: 19 December 2018<\/strong><\/p>\n\n<p>VMware has released a security update to address a vulnerability affecting the VMware vRealize Operations Manager. A local attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users to review the latest VMware Security Advisories webpage for details about the vulnerability and apply the appropriate patches:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0031.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2018-0031.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin-2","alert_type":396,"serial_number":"AV18-208","subject":null,"moderation_state":"archived","external_url":null},{"nid":1411,"title":"Internet Explorer Security Alert","uuid":"44e0bc91-e802-4443-be16-93f3999a8973","banner":null,"lang":"en","date_modified":"2019-01-11","date_modified_ts":"2019-01-11T16:44:46Z","date_created":"2018-12-20T15:09:03Z","summary":null,"body":["<article data-history-node-id=\"1411\" about=\"\/en\/alerts-advisories\/internet-explorer-security-alert\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL18-17<\/strong><br \/><strong>Date: 19 December 2018<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An ALERT is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. (The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this ALERT to recipients as requested.)<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The goal of this Alert is to bring heightened attention to a vulnerability in Internet Explorer for which there is currently a patch available. The vulnerability can be exploited by deceiving an end user into opening a maliciously-crafted website. Exploitation can lead to remote code execution on the affected computer. There are reports of this exploit currently being used in the wild.<\/p>\n\n<p>Internet Explorer 9 to 11 on Windows 7 to 10, Server 2008 to 2019, and RT 8.1 are affected. Server editions which run IE in restricted (Enhanced Security Configuration) mode will not allow this vulnerability to be exploited unless the server website is added to the Internet Explorer Trusted sites zone.<\/p>\n\n<p>CVE reference: CVE-2018-8653<\/p>\n\n<h2>Suggested action<\/h2>\n\n<ul><li>The Cyber Centre recommends that organizations update Internet Explorer as soon as possible.<\/li>\n\t<li>Do not open links to unknown websites.<\/li>\n\t<li>Do not browse the internet while logged in with a high privilege account such as Administrator.<\/li>\n\t<li>Do not disable Enhanced Security Configuration mode in Internet Explorer on Windows Servers.<\/li>\n\t<li>Ensure only validated, necessary sites are added to the Internet Explorer Trusted sites zone.<\/li>\n<\/ul><h2>References<\/h2>\n\n<p>Microsoft Security Bulletin: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8653\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8653<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/internet-explorer-security-alert","alert_type":397,"serial_number":"AL18-17","subject":null,"moderation_state":"archived","external_url":null},{"nid":1402,"title":"Cisco security bulletin","uuid":"fe35c305-39a2-4e59-a370-1b6f452edba8","banner":null,"lang":"en","date_modified":"2018-12-20","date_modified_ts":"2018-12-20T16:42:57Z","date_created":"2018-12-20T16:42:57Z","summary":null,"body":["<article data-history-node-id=\"1402\" about=\"\/en\/alerts-advisories\/cisco-security-bulletin-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-209<\/strong><br \/><strong>Date: 20 December 2018<\/strong><\/p>\n\n<p>Cisco has released a security update to address a vulnerability affecting their Adaptive Security Appliance (ASA) Software product. An authenticated remote attacker could exploit this vulnerability to take control of the affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Update details and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181219-asa-privesc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181219-asa-privesc<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletin-2","alert_type":396,"serial_number":"AV18-209","subject":null,"moderation_state":"archived","external_url":null},{"nid":1403,"title":"Fortinet security bulletin","uuid":"fefd2dbb-ec0e-4e2a-9571-795ccf6eb673","banner":null,"lang":"en","date_modified":"2019-01-02","date_modified_ts":"2019-01-02T14:55:23Z","date_created":"2019-01-02T14:55:23Z","summary":null,"body":["<article data-history-node-id=\"1403\" about=\"\/en\/alerts-advisories\/fortinet-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV18-210<\/strong><br \/><strong>Date: 24 December 2018<\/strong><\/p>\n\n<p>Fortinet has released a security update to address vulnerabilities affecting FortiClient software. An attacker could exploit these vulnerabilities to take control of the affected system. CCCS encourages users and administrators to review the Fortinet PSIRT Advisory and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-108\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-108<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-bulletin","alert_type":396,"serial_number":"AV18-210","subject":null,"moderation_state":"archived","external_url":null},{"nid":1404,"title":"Adobe security bulletin","uuid":"c378f29c-8c42-4d71-9312-82aa2ace2fc4","banner":null,"lang":"en","date_modified":"2019-01-03","date_modified_ts":"2019-01-03T19:49:45Z","date_created":"2019-01-03T19:49:45Z","summary":null,"body":["<article data-history-node-id=\"1404\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-5\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-001<\/strong><br \/><strong>Date: 3 January 2019<\/strong><\/p>\n\n<p>Adobe has released security updates to address vulnerabilities affecting the Adobe Acrobat and Adobe Reader products for Windows and MacOS. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-02.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-02.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-5","alert_type":396,"serial_number":"AV19-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1405,"title":"Microsoft security bulletin","uuid":"98f898a4-165e-4b37-a8cd-c9e0392ca24f","banner":null,"lang":"en","date_modified":"2019-01-08","date_modified_ts":"2019-01-08T20:12:21Z","date_created":"2019-01-08T20:10:14Z","summary":null,"body":["<article data-history-node-id=\"1405\" about=\"\/en\/alerts-advisories\/microsoft-security-bulletin-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-002<\/strong><br \/><strong>Date: 8 January 2019<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities affecting Microsoft products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft January 2019 Security Updates and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/b4384b95-e6d2-e811-a983-000d3a33c573\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/b4384b95-e6d2-e811-a983-000d3a33c573<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-bulletin-1","alert_type":396,"serial_number":"AV19-002","subject":null,"moderation_state":"archived","external_url":null},{"nid":1406,"title":"SAP security bulletin","uuid":"83a4e4a7-d7ab-4893-9e2f-ab07061595b8","banner":null,"lang":"en","date_modified":"2019-01-09","date_modified_ts":"2019-01-09T20:32:19Z","date_created":"2019-01-09T20:30:23Z","summary":null,"body":["<article data-history-node-id=\"1406\" about=\"\/en\/alerts-advisories\/sap-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-003<\/strong><br \/><strong>Date: 9 January 2019<\/strong><\/p>\n\n<p>SAP Software Solutions has released security updates to address multiple vulnerabilities affecting SAP products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the SAP Security Patch Day \u2013 January 2019 Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=509151985\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=509151985<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-bulletin-0","alert_type":396,"serial_number":"AV19-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":1407,"title":"Android security bulletin","uuid":"d00c606b-6725-4c40-95d6-cb7251c32e46","banner":null,"lang":"en","date_modified":"2019-01-09","date_modified_ts":"2019-01-09T20:35:59Z","date_created":"2019-01-09T20:34:25Z","summary":null,"body":["<article data-history-node-id=\"1407\" about=\"\/en\/alerts-advisories\/android-security-bulletin-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-004<\/strong><br \/><strong>Date: 9 January 2019<\/strong><\/p>\n\n<p>Google has released security updates to address multiple vulnerabilities affecting Android devices. A remote attacker could exploit some of these vulnerabilities to take control of an affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Android security bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-01-01.html\">https:\/\/source.android.com\/security\/bulletin\/2019-01-01.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-1","alert_type":396,"serial_number":"AV19-004","subject":null,"moderation_state":"archived","external_url":null},{"nid":1408,"title":"Intel security bulletin","uuid":"8a8ef9b3-f137-4f31-9681-84aea808b82a","banner":null,"lang":"en","date_modified":"2019-01-09","date_modified_ts":"2019-01-09T20:40:27Z","date_created":"2019-01-09T20:39:00Z","summary":null,"body":["<article data-history-node-id=\"1408\" about=\"\/en\/alerts-advisories\/intel-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-005<\/strong><br \/><strong>Date: 9 January 2019<\/strong><\/p>\n\n<p>Intel has released security updates to address multiple vulnerabilities affecting their products. A local attacker could exploit some of these vulnerabilities to take control of an affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Intel Security Bulletins for January 2019 and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-bulletin","alert_type":396,"serial_number":"AV19-005","subject":null,"moderation_state":"archived","external_url":null},{"nid":1409,"title":"Cisco security bulletin","uuid":"1acda96f-dffd-4f21-8ef2-06a2ef176175","banner":null,"lang":"en","date_modified":"2019-01-09","date_modified_ts":"2019-01-09T20:55:55Z","date_created":"2019-01-09T20:42:56Z","summary":null,"body":["<article data-history-node-id=\"1409\" about=\"\/en\/alerts-advisories\/cisco-security-bulletin-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-006<\/strong><br \/><strong>Date: 9 January 2019<\/strong><\/p>\n\n<p>Cisco has released security updates to address multiple vulnerabilities affecting some of their products. A local attacker could exploit some of these vulnerabilities to take control of an affected device, expose sensitive data or cause a Denial of Service Attack.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletin-3","alert_type":396,"serial_number":"AV19-006","subject":null,"moderation_state":"archived","external_url":null},{"nid":1410,"title":"Juniper Security Advisories","uuid":"2105e334-aac2-48f0-ab72-31e4706945a3","banner":null,"lang":"en","date_modified":"2019-01-11","date_modified_ts":"2019-01-11T16:36:50Z","date_created":"2019-01-11T16:35:04Z","summary":null,"body":["<article data-history-node-id=\"1410\" about=\"\/en\/alerts-advisories\/juniper-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-007<\/strong><br \/><strong>Date: 10 January 2019<\/strong><\/p>\n\n<p>Juniper has released security updates to address multiple vulnerabilities affecting some of their products. A local attacker could exploit some of these vulnerabilities to take control of an affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Juniper Security Advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-advisories","alert_type":396,"serial_number":"AV19-007","subject":null,"moderation_state":"archived","external_url":null},{"nid":1412,"title":"Critical Microsoft Patches","uuid":"3cc34530-a579-40ff-9a2a-90af683e934c","banner":null,"lang":"en","date_modified":"2019-01-11","date_modified_ts":"2019-01-11T16:51:11Z","date_created":"2019-01-11T16:47:08Z","summary":null,"body":["<article data-history-node-id=\"1412\" about=\"\/en\/alerts-advisories\/critical-microsoft-patches\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-001<\/strong><br \/><strong>Date: 10 January 2019<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An ALERT is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. (The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this ALERT to recipients as requested.)<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The goal of this Alert is to bring heightened attention to two vulnerabilities in Microsoft products for which there are currently patches available. The first vulnerability is CVE-2019-0547 \u2013 Windows DHCP Client Remote Code Execution Vulnerability. This vulnerability in the DHCP client could allow attackers to execute code on affected systems by sending a specially crafted DHCP responses to a client. Code execution through a widely available listening service, such as DHCP, means this is a wormable vulnerability. Microsoft has listed this patch as \u00abCritical\u00bb.<\/p>\n\n<p>The second vulnerability is CVE-2019-0586 \u2013 Microsoft Exchange Memory Corruption Vulnerability. This vulnerability in Exchange could allow an attacker to take control of an Exchange server just by sending it a specially crafted email. Microsoft has listed this patch as \u00abImportant\u00bb, however the Cyber Centre assesses this as a Critical patch.<\/p>\n\n<p>CVE references: CVE-2019-0547, CVE-2019-0586<\/p>\n\n<h2>Suggested action<\/h2>\n\n<ul><li>The Cyber Centre recommends that organizations deploy Microsoft patches as soon as possible.<\/li>\n\t<li>Where immediate full patch deployment is not possible, special attention should be given to the two patches listed in the References section.<\/li>\n\t<li>A mail filtering gateway should be in place to prevent malicious emails from reaching the Exchange server.<\/li>\n<\/ul><h2>References<\/h2>\n\n<p><strong>Microsoft Security Bulletins:<\/strong><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0586\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0586<\/a><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0547\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0547<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/critical-microsoft-patches","alert_type":397,"serial_number":"AL19-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1413,"title":"Fortinet security bulletin","uuid":"34e855af-f9ae-4aa1-b40b-f90ffca380ca","banner":null,"lang":"en","date_modified":"2019-01-11","date_modified_ts":"2019-01-11T20:55:52Z","date_created":"2019-01-11T20:53:27Z","summary":null,"body":["<article data-history-node-id=\"1413\" about=\"\/en\/alerts-advisories\/fortinet-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-008<\/strong><br \/><strong>Date: 11 January 2019<\/strong><\/p>\n\n<p>Fortinet has released an advisory to address a vulnerability affecting its FortiOS product. This vulnerability affects FortiOS version 5.6.0 and below. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Fortinet advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-018\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-018<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-bulletin-0","alert_type":396,"serial_number":"AV19-008","subject":null,"moderation_state":"archived","external_url":null},{"nid":1414,"title":"Microsoft security bulletin","uuid":"9b6614dd-b6d6-4139-af55-c763f710b5c9","banner":null,"lang":"en","date_modified":"2019-01-16","date_modified_ts":"2019-01-16T16:49:45Z","date_created":"2019-01-16T16:48:32Z","summary":null,"body":["<article data-history-node-id=\"1414\" about=\"\/en\/alerts-advisories\/microsoft-security-bulletin-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-009<\/strong><br \/><strong>Date: 16 January 2019<\/strong><\/p>\n\n<p>Microsoft has released an out-of-band advisory to address vulnerabilities affecting certain Microsoft products, namely Team Foundation Server 2017, Team Foundation Server 2018, and Skype for Business Server 2015. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft Security Update Guide and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-bulletin-2","alert_type":396,"serial_number":"AV19-009","subject":null,"moderation_state":"archived","external_url":null},{"nid":1415,"title":"Oracle security bulletins","uuid":"f147b200-41d1-4c02-b10e-65b6524cdb7f","banner":null,"lang":"en","date_modified":"2019-01-16","date_modified_ts":"2019-01-16T16:53:01Z","date_created":"2019-01-16T16:51:15Z","summary":null,"body":["<article data-history-node-id=\"1415\" about=\"\/en\/alerts-advisories\/oracle-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-010<\/strong><br \/><strong>Date: 16 January 2019<\/strong><\/p>\n\n<p>Oracle has released security updates to address multiple vulnerabilities affecting Oracle products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Oracle Critical Patch Update and Security Alerts webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujan2019-5072801.html\">https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujan2019-5072801.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-bulletins-0","alert_type":396,"serial_number":"AV19-010","subject":null,"moderation_state":"archived","external_url":null},{"nid":1416,"title":"Drupal  security bulletins","uuid":"9165a6b4-fa37-4b55-be9e-e92e2e528abd","banner":null,"lang":"en","date_modified":"2019-01-17","date_modified_ts":"2019-01-17T15:48:57Z","date_created":"2019-01-17T15:46:49Z","summary":null,"body":["<article data-history-node-id=\"1416\" about=\"\/en\/alerts-advisories\/drupal-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-011<\/strong><br \/><strong>Date: 17 January 2019<\/strong><\/p>\n\n<p>Drupal has released security updates to address multiple vulnerabilities affecting the Drupal product. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Drupal Critical Patch Update and Security Alerts webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2019-002\">https:\/\/www.drupal.org\/sa-core-2019-002<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-bulletins-0","alert_type":396,"serial_number":"AV19-011","subject":null,"moderation_state":"archived","external_url":null},{"nid":1417,"title":"Cisco security bulletin","uuid":"75f5c4d7-6614-47b7-8d8c-28012e9e5f81","banner":null,"lang":"en","date_modified":"2019-01-22","date_modified_ts":"2019-01-22T15:38:28Z","date_created":"2019-01-22T15:35:55Z","summary":null,"body":["<article data-history-node-id=\"1417\" about=\"\/en\/alerts-advisories\/cisco-security-bulletin-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-012<\/strong><br \/><strong>Date: 21 January 2019<\/strong><\/p>\n\n<p>Cisco has released a security advisory to address a vulnerability affecting Cisco products. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisory webpage and apply the necessary workaround:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181107-sbsw-privacc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20181107-sbsw-privacc<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-bulletin-4","alert_type":396,"serial_number":"AV19-012","subject":null,"moderation_state":"archived","external_url":null},{"nid":1418,"title":"Linux security bulletin","uuid":"bca418ce-3085-47e5-8bc3-ee3968bb7594","banner":null,"lang":"en","date_modified":"2019-01-22","date_modified_ts":"2019-01-22T21:05:05Z","date_created":"2019-01-22T21:03:50Z","summary":null,"body":["<article data-history-node-id=\"1418\" about=\"\/en\/alerts-advisories\/linux-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-013<\/strong><br \/><strong>Date: 22 January 2019<\/strong><\/p>\n\n<p>Debian and Ubuntu have released security advisories to address a vulnerability affecting the Advanced Packaging Tool (APT). A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Debian and Ubuntu Security Advisory webpages and apply the necessary patches:<\/p>\n\n<p><a href=\"https:\/\/security-tracker.debian.org\/tracker\/source-package\/apt\">https:\/\/security-tracker.debian.org\/tracker\/source-package\/apt<\/a><\/p>\n\n<p><a href=\"https:\/\/usn.ubuntu.com\/3863-1\/\">https:\/\/usn.ubuntu.com\/3863-1\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-security-bulletin","alert_type":396,"serial_number":"AV19-013","subject":null,"moderation_state":"archived","external_url":null},{"nid":1419,"title":"Apple security bulletins","uuid":"5d4c7edb-3555-4b70-9a73-3aae28ba9baf","banner":null,"lang":"en","date_modified":"2019-01-22","date_modified_ts":"2019-01-22T21:09:56Z","date_created":"2019-01-22T21:07:39Z","summary":null,"body":["<article data-history-node-id=\"1419\" about=\"\/en\/alerts-advisories\/apple-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-014<\/strong><br \/><strong>Date: 22 January 2019<\/strong><\/p>\n\n<p>Apple has released security updates to address multiple vulnerabilities affecting Apple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-bulletins-0","alert_type":396,"serial_number":"AV19-014","subject":null,"moderation_state":"archived","external_url":null},{"nid":1420,"title":"Cisco Security Advisories","uuid":"747ed97a-5491-47c3-b359-1f1bf95c427d","banner":null,"lang":"en","date_modified":"2019-01-24","date_modified_ts":"2019-01-24T15:11:27Z","date_created":"2019-01-24T15:09:53Z","summary":null,"body":["<article data-history-node-id=\"1420\" about=\"\/en\/alerts-advisories\/cisco-security-advisories-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-015<\/strong><br \/><strong>Date: 24 January 2019<\/strong><\/p>\n\n<p>Cisco has released security updates to address multiple vulnerabilities affecting some of their products. An attacker could exploit some of these vulnerabilities to take control of an affected device, expose sensitive data or cause a Denial of Service Attack.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisories-0","alert_type":396,"serial_number":"AV19-015","subject":null,"moderation_state":"archived","external_url":null},{"nid":1421,"title":"Cisco Security Advisories","uuid":"1e9a657a-9cf9-4978-b680-619f29616632","banner":null,"lang":"en","date_modified":"2019-01-28","date_modified_ts":"2019-01-28T19:48:27Z","date_created":"2019-01-28T19:45:56Z","summary":null,"body":["<article data-history-node-id=\"1421\" about=\"\/en\/alerts-advisories\/cisco-security-advisories-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-016<\/strong><br \/><strong>Date: 28 January 2019<\/strong><\/p>\n\n<p>On 25 January 2019, Cisco released security updates to address multiple vulnerabilities affecting some of their products. An attacker could exploit some of these vulnerabilities to take control of an affected device, expose sensitive data or cause a Denial of Service Attack.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisories-1","alert_type":396,"serial_number":"AV19-016","subject":null,"moderation_state":"archived","external_url":null},{"nid":1422,"title":"Mozilla Firefox security bulletins","uuid":"0fec1bff-7101-4cf2-bf74-d886fa8bbfd2","banner":null,"lang":"en","date_modified":"2019-01-30","date_modified_ts":"2019-01-30T21:12:57Z","date_created":"2019-01-30T21:11:24Z","summary":null,"body":["<article data-history-node-id=\"1422\" about=\"\/en\/alerts-advisories\/mozilla-firefox-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-017<\/strong><br \/><strong>Date: 30 January 2019<\/strong><\/p>\n\n<p>Mozilla has released security updates to address multiple vulnerabilities affecting Mozilla Products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage for January 29th 2019 and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-firefox-security-bulletins","alert_type":396,"serial_number":"AV19-017","subject":null,"moderation_state":"archived","external_url":null},{"nid":1423,"title":"Google security bulletin","uuid":"9c8041ac-daa4-4709-903b-1a5c5070687c","banner":null,"lang":"en","date_modified":"2019-01-30","date_modified_ts":"2019-01-30T21:17:07Z","date_created":"2019-01-30T21:15:31Z","summary":null,"body":["<article data-history-node-id=\"1423\" about=\"\/en\/alerts-advisories\/google-security-bulletin-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-018<\/strong><br \/><strong>Date: 30 January 2019<\/strong><\/p>\n\n<p>On 30 January 2019, Google released security updates to address vulnerabilities affecting its Google Chrome product. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users to review the Chrome Releases webpage for details about the vulnerability:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/\">https:\/\/chromereleases.googleblog.com\/<\/a><\/p>\n\n<p>The latest version of Google Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-bulletin-1","alert_type":396,"serial_number":"AV19-018","subject":null,"moderation_state":"archived","external_url":null},{"nid":1424,"title":"Microsoft Exchange Privilege Escalation","uuid":"e9a8f079-578d-40b0-bca0-d64792748b04","banner":null,"lang":"en","date_modified":"2019-01-30","date_modified_ts":"2019-01-30T21:21:38Z","date_created":"2019-01-30T21:19:29Z","summary":null,"body":["<article data-history-node-id=\"1424\" about=\"\/en\/alerts-advisories\/microsoft-exchange-privilege-escalation\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-004<\/strong><br \/><strong>Date: 30 January 2019<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An ALERT is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. (The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this ALERT to recipients as requested.)<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The goal of this Alert is to bring heightened attention to a Microsoft Exchange Privilege Escalation vulnerability disclosed on 21 January 2019, affecting Exchange 2013 through 2016 versions. There is currently no patch available.<\/p>\n\n<p>Using stolen credentials, a malicious actor who has the ability to communicate with both a Microsoft Exchange server and a Windows Domain Controller on the same domain may be able to gain domain administrator privileges. It is also reported that a malicious actor may be able to exploit the same vulnerability by using an SMB to HTTP relay attack as long as they are in the same network segment as the Exchange server, even if they only have a valid login credential without a password.<\/p>\n\n<p>This vulnerability is a combination of three (default) settings and mechanisms that a malicious actor can abuse to escalate privileges from any email account to a domain administrator.<\/p>\n\n<p>The three issues are as follows:<\/p>\n\n<ul><li>Exchange servers have high privileges by default in a domain.<\/li>\n\t<li>NTLM authentication can be relayed.<\/li>\n\t<li>Exchange servers can be asked to authenticate to an arbitrary IP using the EWS (Exchange Web Services) PushSubscription feature.<\/li>\n<\/ul><h2>Suggested action<\/h2>\n\n<ul><li>Consider disabling EWS push\/pull subscriptions if they are not required.<\/li>\n\t<li>Enable LDAP signing and LDAP channel binding to prevent relaying to LDAP and LDAPS respectively.<\/li>\n\t<li>Use an internal firewall to prevent Exchange from connecting to workstations - typically workstations should connect to Exchange, not the opposite. This makes exploitation more difficult to accomplish.<\/li>\n\t<li>Enable Extended Protection for Authentication on the Exchange endpoints in IIS. This will verify the channel binding parameters in the NTLM authentication, which ties NTLM authentication to a TLS connection and prevent relaying to Exchange web services.<\/li>\n\t<li>Remove the registry key which makes relaying back to the Exchange server possible, as discussed in Microsoft mitigation for CVE-2018-8518.<\/li>\n\t<li>Enforce SMB signing on Exchange servers (and preferable all other servers and workstations in the domain) to prevent cross-protocol relay attacks to SMB.<\/li>\n\t<li>Remove unnecessary high privileges that Exchange may have on Domain object (this is not supported by Microsoft and may break some instances).<\/li>\n\t<li>Monitor the Domain Controllers logs for event 5136 and search for the following GUID:\n\t<ul><li>1131f6aa-9c07-11d1-f79f-00c04fc2dcd2 (DS-Replication-Get-Changes)<\/li>\n\t\t<li>1131f6ad-9c07-11d1-f79f-00c04fc2dcd2 (DS-Replication-Get-Changes-All)<\/li>\n\t\t<li>89e95b76-444d-4c62-991a-0facbeda640c (DS-Replication-Get-Changes-In-Filtered-Set)<\/li>\n\t<\/ul><\/li>\n\t<li>Monitor the Domain Controllers logs for the following event to detect NTLM relay attacks where Exchange server's credentials were used. The Source Network Address field will show the IP address of the attacker:\n\t<ul><li>EventCode=4624<\/li>\n\t\t<li>LogonType=3<\/li>\n\t\t<li>Authentication Package=NTLM<\/li>\n\t\t<li>Account Name = <em>YOUREXCHANGESERVER$<\/em><\/li>\n\t<\/ul><\/li>\n<\/ul><h2>References<\/h2>\n\n<p><a href=\"https:\/\/dirkjanm.io\/abusing-exchange-one-api-call-away-from-domain-admin\/\">https:\/\/dirkjanm.io\/abusing-exchange-one-api-call-away-from-domain-admin\/<\/a><\/p>\n\n<p><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4034879\/how-to-add-the-ldapenforcechannelbinding-registry-entry\">https:\/\/support.microsoft.com\/en-us\/help\/4034879\/how-to-add-the-ldapenforcechannelbinding-registry-entry<\/a><\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/previous-versions\/dotnet\/netframework-3.5\/dd767318(v=vs.90)\">https:\/\/docs.microsoft.com\/en-us\/previous-versions\/dotnet\/netframework-3.5\/dd767318(v=vs.90)<\/a><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8581\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2018-8581<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-exchange-privilege-escalation","alert_type":397,"serial_number":"AL19-004","subject":null,"moderation_state":"archived","external_url":null},{"nid":1425,"title":"Linux security bulletin","uuid":"2bfffa43-57b8-4003-9f23-726bcef8db76","banner":null,"lang":"en","date_modified":"2019-01-31","date_modified_ts":"2019-01-31T16:45:27Z","date_created":"2019-01-31T16:37:23Z","summary":null,"body":["<article data-history-node-id=\"1425\" about=\"\/en\/alerts-advisories\/linux-security-bulletin-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-019<\/strong><br \/><strong>Date: 31 January 2019<\/strong><\/p>\n\n<p>On 29 January 2019, Debian, Ubuntu, Red Hat and SUSE released security advisories to address multiple Linux Kernel vulnerabilities. A local attacker could exploit these vulnerabilities to take control of an affected system. Please note that other versions of Linux with the same kernel may also be affected.<\/p>\n\n<p>The vulnerabilities are identified by the following CVE\u2019s:<\/p>\n\n<p>CVE-2018-9516, CVE-2018-10876, CVE-2018-10878, CVE-2018-10879, CVE-2018-10880, CVE-2018-10882, CVE-2018-10883, CVE-2018-14625, CVE-2018-16882, CVE-2018-17972, CVE-2018-18281, CVE-2018-19407<\/p>\n\n<p>CCCS encourages users and administrators to review the following Security Advisory webpages and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/usn.ubuntu.com\/3871-1\/\">https:\/\/usn.ubuntu.com\/3871-1\/<\/a><\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories\">https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories<\/a><\/p>\n\n<p><a href=\"https:\/\/www.suse.com\/support\/update\/announcement\/2019\/suse-su-20190196-1\/\">https:\/\/www.suse.com\/support\/update\/announcement\/2019\/suse-su-20190196-1\/<\/a><\/p>\n\n<p><a href=\"https:\/\/security-tracker.debian.org\/tracker\/status\/release\/stable\">https:\/\/security-tracker.debian.org\/tracker\/status\/release\/stable<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-security-bulletin-0","alert_type":396,"serial_number":"AV19-019","subject":null,"moderation_state":"archived","external_url":null},{"nid":1426,"title":"Android security bulletin","uuid":"6afc548b-cb30-434c-b96d-869bef0b40af","banner":null,"lang":"en","date_modified":"2019-02-06","date_modified_ts":"2019-02-06T14:48:43Z","date_created":"2019-02-06T14:46:20Z","summary":null,"body":["<article data-history-node-id=\"1426\" about=\"\/en\/alerts-advisories\/android-security-bulletin-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-020<\/strong><br \/><strong>Date: 5 February 2019<\/strong><\/p>\n\n<p>Google has released security updates to address multiple vulnerabilities affecting Android devices. A remote attacker could exploit some of these vulnerabilities to take control of an affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Android security bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-02-01.html\">https:\/\/source.android.com\/security\/bulletin\/2019-02-01.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-bulletin-2","alert_type":396,"serial_number":"AV19-020","subject":null,"moderation_state":"archived","external_url":null},{"nid":1427,"title":"Apple security bulletins","uuid":"2ebfa0ae-c39e-4b4a-9c79-e04bbb393d88","banner":null,"lang":"en","date_modified":"2019-02-07","date_modified_ts":"2019-02-07T20:53:17Z","date_created":"2019-02-07T20:51:39Z","summary":null,"body":["<article data-history-node-id=\"1427\" about=\"\/en\/alerts-advisories\/apple-security-bulletins-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-021<\/strong><br \/><strong>Date: 7 February 2019<\/strong><\/p>\n\n<p>Apple has released security updates to address multiple vulnerabilities affecting Apple products. The updates include an iOS and macOS fix for the Facetime group chat eavesdropping bug. It should be noted that Facetime group chat will only be enabled on the end user\u2019s phone once the software has been updated.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-bulletins-1","alert_type":396,"serial_number":"AV19-021","subject":null,"moderation_state":"archived","external_url":null},{"nid":1428,"title":"Adobe security bulletin","uuid":"f39c318d-8edd-4661-85b1-ec6a2cac4a49","banner":null,"lang":"en","date_modified":"2019-02-12","date_modified_ts":"2019-02-12T18:56:58Z","date_created":"2019-02-12T18:54:55Z","summary":null,"body":["<article data-history-node-id=\"1428\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-6\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-022<\/strong><br \/><strong>Date: 12 February 2019<\/strong><\/p>\n\n<p>Adobe has released security updates to address vulnerabilities affecting multiple Adobe products. A remote attacker could exploit some of these vulnerabilities to run arbitrary code in the context of the current user.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-6","alert_type":396,"serial_number":"AV19-022","subject":null,"moderation_state":"archived","external_url":null},{"nid":1429,"title":"runc open-source container security bulletin","uuid":"e5b54dd3-080e-447d-aa16-21f2cb6da0dc","banner":null,"lang":"en","date_modified":"2019-02-14","date_modified_ts":"2019-02-14T18:47:48Z","date_created":"2019-02-14T18:45:44Z","summary":null,"body":["<article data-history-node-id=\"1429\" about=\"\/en\/alerts-advisories\/runc-open-source-container-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-023<\/strong><br \/><strong>Date: 13 February 2019<\/strong><\/p>\n\n<p>On 12 February 2019, Red Hat, Ubuntu, Debian and Amazon web Services released security advisories to address a vulnerability in <em>runc<\/em>. This is the underlying container management tool used by multiple containerization software such as Docker, Kubernetes and others. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS recommends verifying OS and application vendors for patches as they become available. CCCS also encourages users and administrators to review the following Security Advisory webpages and apply the necessary patches:<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/runcescape\">https:\/\/access.redhat.com\/security\/vulnerabilities\/runcescape<\/a><\/p>\n\n<p><a href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-5736.html\">https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-5736.html<\/a><\/p>\n\n<p><a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-5736\">https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-5736<\/a><\/p>\n\n<p><a href=\"https:\/\/aws.amazon.com\/security\/security-bulletins\/AWS-2019-002\/v1\/\">https:\/\/aws.amazon.com\/security\/security-bulletins\/AWS-2019-002\/v1\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/runc-open-source-container-security-bulletin","alert_type":396,"serial_number":"AV19-023","subject":null,"moderation_state":"archived","external_url":null},{"nid":1430,"title":"Cisco Security Advisories","uuid":"f9d8fa75-84fd-4c12-8548-5858790dda37","banner":null,"lang":"en","date_modified":"2019-02-15","date_modified_ts":"2019-02-15T18:56:04Z","date_created":"2019-02-15T18:53:54Z","summary":null,"body":["<article data-history-node-id=\"1430\" about=\"\/en\/alerts-advisories\/cisco-security-advisories-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-024<\/strong><br \/><strong>Date: 15 February 2019<\/strong><\/p>\n\n<p>On 12 February 2019, Cisco released a security update to address a vulnerability affecting the Network Assurance Engine product. A local, unauthenticated attacker could exploit this vulnerability to gain access to the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisories-2","alert_type":396,"serial_number":"AV19-024","subject":null,"moderation_state":"archived","external_url":null},{"nid":1431,"title":"Microsoft security bulletin","uuid":"63e85b5a-1589-4224-883b-da9f2eb1fed0","banner":null,"lang":"en","date_modified":"2019-02-15","date_modified_ts":"2019-02-15T19:00:55Z","date_created":"2019-02-15T18:57:56Z","summary":null,"body":["<article data-history-node-id=\"1431\" about=\"\/en\/alerts-advisories\/microsoft-security-bulletin-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-025<\/strong><br \/><strong>Date: 15 February 2019<\/strong><\/p>\n\n<p>Microsoft has released an advisory to address multiple vulnerabilities affecting some Microsoft products. Of note is a patch for the recently disclosed Microsoft Exchange privilege escalation vulnerability, as described in Alert <a href=\"\/en\/alerts\/microsoft-exchange-privilege-escalation\">AL19-004<\/a>.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft January 2019 Security Updates webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/51503ac5-e6d2-e811-a983-000d3a33c573\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/51503ac5-e6d2-e811-a983-000d3a33c573<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-bulletin-3","alert_type":396,"serial_number":"AV19-025","subject":null,"moderation_state":"archived","external_url":null},{"nid":1432,"title":"Mozilla security bulletins","uuid":"44469413-7778-425f-ab64-34b01435ca09","banner":null,"lang":"en","date_modified":"2019-02-15","date_modified_ts":"2019-02-15T19:05:35Z","date_created":"2019-02-15T19:03:28Z","summary":null,"body":["<article data-history-node-id=\"1432\" about=\"\/en\/alerts-advisories\/mozilla-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-026<\/strong><br \/><strong>Date: 15 February 2019<\/strong><\/p>\n\n<p>On 12 February 2019, Mozilla released security updates to address vulnerabilities in Firefox and Firefox ESR. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-bulletins-0","alert_type":396,"serial_number":"AV19-026","subject":null,"moderation_state":"archived","external_url":null},{"nid":1433,"title":"SAP security bulletins","uuid":"4589e146-ff3c-4052-8fd0-dd0100a80132","banner":null,"lang":"en","date_modified":"2019-02-15","date_modified_ts":"2019-02-15T19:09:11Z","date_created":"2019-02-15T19:07:43Z","summary":null,"body":["<article data-history-node-id=\"1433\" about=\"\/en\/alerts-advisories\/sap-security-bulletins\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-027<\/strong><br \/><strong>Date: 15 February 2019<\/strong><\/p>\n\n<p>SAP has released security updates to address vulnerabilities affecting some SAP products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the SAP Security Patch Day webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=510922943\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=510922943<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-bulletins","alert_type":396,"serial_number":"AV19-027","subject":null,"moderation_state":"archived","external_url":null},{"nid":1434,"title":"Ubuntu security bulletin","uuid":"97d2c083-a762-40fc-a584-00547fba6605","banner":null,"lang":"en","date_modified":"2019-02-15","date_modified_ts":"2019-02-15T19:13:17Z","date_created":"2019-02-15T19:11:35Z","summary":null,"body":["<article data-history-node-id=\"1434\" about=\"\/en\/alerts-advisories\/ubuntu-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-028<\/strong><br \/><strong>Date: 15 February 2019<\/strong><\/p>\n\n<p>Canonical has released security updates to address a vulnerability affecting both its Desktop and Server implementations of Ubuntu prior to version 19.04. The issue lies with <em>snapd<\/em>, Canonical\u2019s toolkit used to package and run applications in Ubuntu. A local attacker could exploit this vulnerability to elevate their privileges on the machine. It should be noted that other implementations of Linux similar to Ubuntu could use <em>snapd<\/em> and thus would be affected.<\/p>\n\n<p>CCCS encourages users and administrators to review the Ubuntu Security Notices webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/usn.ubuntu.com\/3887-1\/\">https:\/\/usn.ubuntu.com\/3887-1\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-bulletin","alert_type":396,"serial_number":"AV19-028","subject":null,"moderation_state":"archived","external_url":null},{"nid":1435,"title":"Siemens Security Advisories","uuid":"5d6e4097-d7bb-4e38-8b5b-e58a02034302","banner":null,"lang":"en","date_modified":"2019-02-15","date_modified_ts":"2019-02-15T19:17:38Z","date_created":"2019-02-15T19:16:09Z","summary":null,"body":["<article data-history-node-id=\"1435\" about=\"\/en\/alerts-advisories\/siemens-security-advisories\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-029<\/strong><br \/><strong>Date: 15 February 2019<\/strong><\/p>\n\n<p>On 12 February 2019, Siemens has released security updates to address multiple vulnerabilities affecting some of their industrial control and utility products. An attacker could exploit some of these vulnerabilities to take control of an affected device, expose sensitive data or cause a Denial of Service Attack.<\/p>\n\n<p>CCCS encourages users and administrators to review the Siemens Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/siemens-security-advisories","alert_type":396,"serial_number":"AV19-029","subject":null,"moderation_state":"archived","external_url":null},{"nid":1436,"title":"VMware security bulletins","uuid":"6b4d590c-adfc-4882-8228-95de56f02afd","banner":null,"lang":"en","date_modified":"2019-02-19","date_modified_ts":"2019-02-19T15:30:30Z","date_created":"2019-02-19T15:28:29Z","summary":null,"body":["<article data-history-node-id=\"1436\" about=\"\/en\/alerts-advisories\/vmware-security-bulletins-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-030<\/strong><br \/><strong>Date: 18 February 2019<\/strong><\/p>\n\n<p>VMware has released a security update to address a vulnerability affecting <em>runc<\/em> container runtime. An attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the VMware Security Advisory webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0001.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0001.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletins-0","alert_type":396,"serial_number":"AV19-030","subject":null,"moderation_state":"archived","external_url":null},{"nid":1437,"title":"Antidote security bulletin","uuid":"42f0c907-5eeb-4ffd-877b-784823e5bc34","banner":null,"lang":"en","date_modified":"2019-02-20","date_modified_ts":"2019-02-20T19:19:02Z","date_created":"2019-02-20T19:16:57Z","summary":null,"body":["<article data-history-node-id=\"1437\" about=\"\/en\/alerts-advisories\/antidote-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-031<\/strong><br \/><strong>Date: 20 February 2019<\/strong><\/p>\n\n<p>Antidote has released updates to address vulnerabilities affecting Antidote 8, 9, and 10. A remote attacker could exploit these vulnerabilities to steal credentials including those of the domain administrator\u2019s. This could lead to the compromise of an entire domain.<\/p>\n\n<p>CCCS encourages users and administrators to review the Antidote updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/antidote.info\/en\/assistance\/mises-a-jour\">https:\/\/antidote.info\/en\/assistance\/mises-a-jour<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/antidote-security-bulletin","alert_type":396,"serial_number":"AV19-031","subject":null,"moderation_state":"archived","external_url":null},{"nid":1438,"title":"Cisco Security Advisories","uuid":"f883fc3a-897a-4bd0-8baa-6f769e3b82c8","banner":null,"lang":"en","date_modified":"2019-02-21","date_modified_ts":"2019-02-21T12:42:23Z","date_created":"2019-02-21T12:40:56Z","summary":null,"body":["<article data-history-node-id=\"1438\" about=\"\/en\/alerts-advisories\/cisco-security-advisories-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-032<\/strong><br \/><strong>Date: 20 February 2019<\/strong><\/p>\n\n<p>On 20 February 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products. A local, unauthenticated attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisories-3","alert_type":396,"serial_number":"AV19-032","subject":null,"moderation_state":"archived","external_url":null},{"nid":1439,"title":"Drupal security bulletin","uuid":"19ed751c-5336-487c-a892-a74efd768593","banner":null,"lang":"en","date_modified":"2019-02-21","date_modified_ts":"2019-02-21T12:47:28Z","date_created":"2019-02-21T12:45:16Z","summary":null,"body":["<article data-history-node-id=\"1439\" about=\"\/en\/alerts-advisories\/drupal-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-033<\/strong><br \/><strong>Date: 20 February 2019<\/strong><\/p>\n\n<p>Drupal has released security updates to address multiple vulnerabilities affecting the Drupal product. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Drupal security advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2019-003\">https:\/\/www.drupal.org\/sa-core-2019-003<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-bulletin","alert_type":396,"serial_number":"AV19-033","subject":null,"moderation_state":"archived","external_url":null},{"nid":1440,"title":"Adobe security bulletin","uuid":"094441c4-8265-4ef4-a11c-9caa46eb0fc6","banner":null,"lang":"en","date_modified":"2019-02-22","date_modified_ts":"2019-02-22T14:43:51Z","date_created":"2019-02-22T14:41:46Z","summary":null,"body":["<article data-history-node-id=\"1440\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-7\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-034<\/strong><br \/><strong>Date: 22 February 2019<\/strong><\/p>\n\n<p>Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. Successful exploitation could lead to sensitive information disclosure in the context of the current user.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-13.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-13.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-7","alert_type":396,"serial_number":"AV19-034","subject":null,"moderation_state":"archived","external_url":null},{"nid":1441,"title":"WinRAR security advisory","uuid":"1145ed13-c333-44bc-ba2c-6d1bf5e39c5f","banner":null,"lang":"en","date_modified":"2019-02-26","date_modified_ts":"2019-02-26T19:48:37Z","date_created":"2019-02-26T19:45:24Z","summary":null,"body":["<article data-history-node-id=\"1441\" about=\"\/en\/alerts-advisories\/winrar-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-035<\/strong><br \/><strong>Date: 26 February 2019<\/strong><\/p>\n\n<p>WinRAR has released security updates to address a vulnerability affecting its software. A remote attacker could exploit this vulnerability to run arbitrary code on the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to download the latest stable release of WinRAR:<\/p>\n\n<p><a href=\"https:\/\/www.win-rar.com\/download.html\">https:\/\/www.win-rar.com\/download.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/winrar-security-advisory","alert_type":396,"serial_number":"AV19-035","subject":null,"moderation_state":"archived","external_url":null},{"nid":1442,"title":"NVIDIA security advisory","uuid":"4c134115-3be7-4a26-bae1-effb1ef36dbf","banner":null,"lang":"en","date_modified":"2019-02-26","date_modified_ts":"2019-02-26T20:43:47Z","date_created":"2019-02-26T20:41:59Z","summary":null,"body":["<article data-history-node-id=\"1442\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-036<\/strong><br \/><strong>Date: 26 February 2019<\/strong><\/p>\n\n<p>NVIDIA has released security updates to address vulnerabilities affecting its Graphics Processing Unit (GPU) display driver. A local, authenticated attacker could exploit some of these vulnerabilities to run arbitrary commands or to escalate privileges on the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4772\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4772<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-0","alert_type":396,"serial_number":"AV19-036","subject":null,"moderation_state":"archived","external_url":null},{"nid":1443,"title":"Cisco security advisory","uuid":"67fc042c-364e-41e9-8e7a-9b0510a9eb89","banner":null,"lang":"en","date_modified":"2019-02-27","date_modified_ts":"2019-02-27T20:02:10Z","date_created":"2019-02-27T20:00:21Z","summary":null,"body":["<article data-history-node-id=\"1443\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-11\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-037<\/strong><br \/><strong>Date: 27 February 2019<\/strong><\/p>\n\n<p>On 27 February 2019, Cisco released security updates to address vulnerabilities affecting some of its products. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-11","alert_type":396,"serial_number":"AV19-037","subject":null,"moderation_state":"archived","external_url":null},{"nid":1444,"title":"Adobe security advisory","uuid":"55c75e29-ef7c-44d5-b138-fca6e60b1438","banner":null,"lang":"en","date_modified":"2019-03-04","date_modified_ts":"2019-03-04T16:46:53Z","date_created":"2019-03-04T16:45:19Z","summary":null,"body":["<article data-history-node-id=\"1444\" about=\"\/en\/alerts-advisories\/adobe-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-038<\/strong><br \/><strong>Date: 4 March 2019<\/strong><\/p>\n\n<p>Adobe has released a security update to address a vulnerability affecting Adobe ColdFusion versions 2018, 2016 and 11. A remote attacker could exploit this vulnerability to run arbitrary code in the context of the running ColdFusion service.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb19-14.html\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb19-14.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory","alert_type":396,"serial_number":"AV19-038","subject":null,"moderation_state":"archived","external_url":null},{"nid":1445,"title":"Google Chrome security advisory","uuid":"2c8e23c8-cd8b-48a8-b2b0-4182db51fb1e","banner":null,"lang":"en","date_modified":"2019-03-06","date_modified_ts":"2019-03-06T18:30:42Z","date_created":"2019-03-06T18:29:00Z","summary":null,"body":["<article data-history-node-id=\"1445\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-039<\/strong><br \/><strong>Date: 6 March 2019<\/strong><\/p>\n\n<p>Google has released a security update to address a vulnerability affecting its Chrome browser. A remote attacker could exploit this vulnerability to run arbitrary commands on the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Chrome Releases webpage and apply the necessary update:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/03\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2019\/03\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory","alert_type":396,"serial_number":"AV19-039","subject":null,"moderation_state":"archived","external_url":null},{"nid":1446,"title":"Cisco security advisory","uuid":"100ee8b5-da33-4a30-8416-dfa5cf78d045","banner":null,"lang":"en","date_modified":"2019-03-07","date_modified_ts":"2019-03-07T15:28:01Z","date_created":"2019-03-07T15:25:48Z","summary":null,"body":["<article data-history-node-id=\"1446\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-12\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-040<\/strong><br \/><strong>Date: 7 March 2019<\/strong><\/p>\n\n<p>On 7 March 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-12","alert_type":396,"serial_number":"AV19-040","subject":null,"moderation_state":"archived","external_url":null},{"nid":1447,"title":"RedHat security bulletin","uuid":"8021aef6-ff1a-4d65-b30d-8359500112a3","banner":null,"lang":"en","date_modified":"2019-03-07","date_modified_ts":"2019-03-07T19:33:34Z","date_created":"2019-03-07T19:31:45Z","summary":null,"body":["<article data-history-node-id=\"1447\" about=\"\/en\/alerts-advisories\/redhat-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-041<\/strong><br \/><strong>Date: 7 March 2019<\/strong><\/p>\n\n<p>RedHat has released a security advisory to address multiple vulnerabilities affecting RedHat enterprise Linux 6. A remote attacker could exploit these vulnerabilities to run arbitrary commands on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the RedHat Security Advisory webpage and apply the necessary patches:<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2019:0469\">https:\/\/access.redhat.com\/errata\/RHSA-2019:0469<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/redhat-security-bulletin","alert_type":396,"serial_number":"AV19-041","subject":null,"moderation_state":"archived","external_url":null},{"nid":1448,"title":"Android security advisory","uuid":"a4fb9577-2dd3-45cc-9691-3d6550dc0538","banner":null,"lang":"en","date_modified":"2019-03-11","date_modified_ts":"2019-03-11T20:26:55Z","date_created":"2019-03-11T20:25:25Z","summary":null,"body":["<article data-history-node-id=\"1448\" about=\"\/en\/alerts-advisories\/android-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-042<\/strong><br \/><strong>Date: 11 March 2019<\/strong><\/p>\n\n<p>Google has released security updates to address multiple vulnerabilities affecting Android devices. A remote attacker could exploit some of these vulnerabilities to take control of an affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Android security bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-03-01\">https:\/\/source.android.com\/security\/bulletin\/2019-03-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory","alert_type":396,"serial_number":"AV19-042","subject":null,"moderation_state":"archived","external_url":null},{"nid":1449,"title":"Adobe security bulletin","uuid":"fb2af917-9a4c-41ff-9d6f-3ffac4f3bea5","banner":null,"lang":"en","date_modified":"2019-03-12","date_modified_ts":"2019-03-12T15:47:44Z","date_created":"2019-03-12T15:46:26Z","summary":null,"body":["<article data-history-node-id=\"1449\" about=\"\/en\/alerts-advisories\/adobe-security-bulletin-8\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-043<\/strong><br \/><strong>Date: 12 March 2019<\/strong><\/p>\n\n<p>On 12 March 2019, Adobe released security updates to address vulnerabilities affecting Adobe Photoshop CC and Adobe Digital Editions. A remote attacker could exploit some of these vulnerabilities to run arbitrary code in the context of the current user.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-bulletin-8","alert_type":396,"serial_number":"AV19-043","subject":null,"moderation_state":"archived","external_url":null},{"nid":1450,"title":"Windows Server 2008 end of support","uuid":"1dcde6ff-e04f-402b-a86d-b804991e232b","banner":null,"lang":"en","date_modified":"2019-03-12","date_modified_ts":"2019-03-12T18:50:37Z","date_created":"2019-03-12T18:47:21Z","summary":null,"body":["<article data-history-node-id=\"1450\" about=\"\/en\/alerts-advisories\/windows-server-2008-end-support\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: IN19-001<\/strong><br \/><strong>Date: 12 March 2019<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this Information Note is to draw attention to the end of life for Microsoft Windows Server 2008 and Windows Server 2008 R2 product lines. Effective 14 January 2020 Microsoft will no longer provide automatic fixes, security updates, or online technical assistance for these products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>As of 14 January 2020, Microsoft will no longer support the Windows Server 2008 and 2008 R2 family of operating systems. Organizations running these operating systems after the end of support date will no longer receive security updates, and may be exposed to outage, compliance and security risks. Hardware and software compatibility issues may also arise when implementing current technologies which may not have been designed for use with the Windows Server 2008 or Server 2008 R2 operating systems.<\/p>\n\n<p>Migration to newer versions of Windows Server can present unique challenges and it is critical that those organizations operating Windows Server 2008 and\/or Server 2008 R2 plan and test a migration solution before the deadline. Applications may have compatibility issues with more recent versions of Windows Server and\/or alternate operating systems. Organizations will need to ensure that their critical applications are compatible with the operating system chosen for migration.<\/p>\n\n<p>CCCS recommends that the planning process for the migration of Server operating systems include the following:<\/p>\n\n<ul><li>Have an accurate inventory of which servers with operating systems reaching end of life.<\/li>\n\t<li>Prioritize the servers to be upgraded or migrated.<\/li>\n\t<li>Decide whether the servers will be upgraded, migrated or cloud hosted.<\/li>\n\t<li>Decide on a destination for systems being migrated.<\/li>\n\t<li>Decide on a supported server operating system.<\/li>\n<\/ul><p>Organizations will need to identify all infrastructure, application and hardware dependencies when planning a Windows Server migration. The Microsoft Assessment and Planning Toolkit (MAP) can be used to discover Windows Server instances within an organization\u2019s network and assess readiness.<\/p>\n\n<p>Options are available to purchase Extended Security Updates for up to 3 years for operating systems environments that cannot be migrated by 14 January 2020. These updates will only cover security vulnerabilities deemed to be \u201ccritical\u201d by Microsoft.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCCS strongly encourages Information Technology owners and operators relying on Windows Server 2008 and\/or Server 2008 R2 to begin planning their migration to an updated operating system as soon as possible.<\/p>\n\n<h2>References<\/h2>\n\n<ul><li><a href=\"https:\/\/www.microsoft.com\/en-ca\/cloud-platform\/windows-server-2008\">Prepare for Windows Server 2008\/Windows Server 2008 R2 End of Support<\/a><\/li>\n\t<li><a href=\"https:\/\/social.technet.microsoft.com\/wiki\/contents\/articles\/1640.microsoft-assessment-and-planning-toolkit.aspx\">Microsoft Assessment and Planning Toolkit<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-ca\/cloud-platform\/extended-security-updates\">FAQ for Extended Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/lifecycle\/search?sort=PN&amp;alpha=Microsoft%20SQL%20Server%202005&amp;Filter=FilterNO\">Microsoft Product Lifecycle<\/a><\/li>\n\t<li><a href=\"http:\/\/support2.microsoft.com\/gp\/lifepolicy\">Microsoft Support Lifecycle Policy FAQ<\/a><\/li>\n<\/ul><h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/windows-server-2008-end-support","alert_type":396,"serial_number":"IN19-001","subject":null,"moderation_state":"archived","external_url":null},{"nid":1451,"title":"SQL Server 2008 end of support","uuid":"69cc5360-e331-4ab6-a460-39d0d68b6800","banner":null,"lang":"en","date_modified":"2019-03-12","date_modified_ts":"2019-03-12T18:55:56Z","date_created":"2019-03-12T18:53:40Z","summary":null,"body":["<article data-history-node-id=\"1451\" about=\"\/en\/alerts-advisories\/sql-server-2008-end-support\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: IN19-002<\/strong><br \/><strong>Date: 12 March 2019<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this Information Note is to draw attention to the end of life for Microsoft SQL Server 2008 and Microsoft SQL Server 2008 R2. Effective 9 July 2019 Microsoft will no longer provide automatic fixes, security updates, or online technical assistance for these products.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>As of 9 July 2019, Microsoft will no longer support SQL Server 2008. Organizations running this software after the end of support date will no longer receive security updates, and may be exposed to outage, compliance and security risks. Hardware and software compatibility issues may also arise when implementing current technologies which may not have been designed for use with Microsoft SQL Server 2008 or SQL Server 2008 R2.<\/p>\n\n<p>Migration to newer versions of Microsoft SQL Server can present unique challenges and it is critical that those organizations operating Microsoft SQL Server 2008 and\/or SQL Server 2008 R2 plan and test a migration solution before the deadline. Applications may have compatibility issues with more recent versions of SQL Server.<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) recommends that the planning for the migration of databases include the following:<\/p>\n\n<ul><li>Have an accurate inventory of which SQL Databases will need to be migrated.<\/li>\n\t<li>Decide whether the databases will be upgraded, migrated or cloud hosted.<\/li>\n\t<li>Decide on a destination for these databases.<\/li>\n\t<li>Decide on a supported SQL Server version<\/li>\n<\/ul><p>Organizations will need to identify all infrastructure, application and hardware dependencies when planning SQL Server database migration. The Microsoft Assessment and Planning Toolkit (MAP) can be used to discover Microsoft SQL Server instances within an organization\u2019s network and assess readiness. The Microsoft SQL Server Upgrade Advisor has the ability to perform a detailed analysis of Microsoft SQL Server installations and their respective configurations to identify possible known issues that may affect the upgrade process.<\/p>\n\n<p>Options are available to purchase Extended Security Updates for up to 3 years for database environments that cannot be migrated by 9 July 9 2019. These updates will only cover security vulnerabilities deemed to be \u201ccritical\u201d by Microsoft.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCCS strongly encourages Information Technology owners and operators to begin planning their migration to an updated SQL Server database system as soon as possible.<\/p>\n\n<h2>References<\/h2>\n\n<ul><li><a href=\"https:\/\/www.microsoft.com\/en-ca\/sql-server\/sql-server-2008\">Prepare for SQL Server 2008 End of Support<\/a><\/li>\n\t<li><a href=\"https:\/\/social.technet.microsoft.com\/wiki\/contents\/articles\/1640.microsoft-assessment-and-planning-toolkit.aspx\">Microsoft Assessment and Planning Toolkit<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/sql\/sql-server\/install\/use-upgrade-advisor-to-prepare-for-upgrades?view=sql-server-2014\">SQL Server Upgrade Advisor<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-ca\/cloud-platform\/extended-security-updates\">FAQ for Extended Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/lifecycle\/search?sort=PN&amp;alpha=Microsoft%20SQL%20Server%202005&amp;Filter=FilterNO\">Microsoft Product Lifecycle<\/a><\/li>\n\t<li><a href=\"http:\/\/support2.microsoft.com\/gp\/lifepolicy\">Microsoft Support Lifecycle Policy FAQ<\/a><\/li>\n<\/ul><h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sql-server-2008-end-support","alert_type":396,"serial_number":"IN19-002","subject":null,"moderation_state":"archived","external_url":null},{"nid":1452,"title":"Microsoft security advisory","uuid":"ab128306-2b37-4946-851b-b9598ff8e6a2","banner":null,"lang":"en","date_modified":"2019-03-12","date_modified_ts":"2019-03-12T19:44:24Z","date_created":"2019-03-12T19:42:45Z","summary":null,"body":["<article data-history-node-id=\"1452\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-044<\/strong><br \/><strong>Date: 12 March 2019<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities affecting some Microsoft products.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft March 2019 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/ac45e477-1019-e911-a98b-000d3a33a34d\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/ac45e477-1019-e911-a98b-000d3a33a34d<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory","alert_type":396,"serial_number":"AV19-044","subject":null,"moderation_state":"archived","external_url":null},{"nid":1453,"title":"WordPress security advisory","uuid":"f948fc04-986a-4a85-ba2d-923060a18591","banner":null,"lang":"en","date_modified":"2019-03-13","date_modified_ts":"2019-03-13T19:11:39Z","date_created":"2019-03-13T19:08:52Z","summary":null,"body":["<article data-history-node-id=\"1453\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-045<\/strong><br \/><strong>Date: 13 March 2019<\/strong><\/p>\n\n<p>WordPress has released security updates to address a vulnerability affecting its product. A remote, unauthenticated attacker could exploit this vulnerability to run arbitrary code on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to install the latest version of WordPress:<\/p>\n\n<p><a href=\"https:\/\/en-ca.wordpress.org\/download\/\">https:\/\/en-ca.wordpress.org\/download\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory","alert_type":396,"serial_number":"AV19-045","subject":null,"moderation_state":"archived","external_url":null},{"nid":1454,"title":"Google Chrome security advisory","uuid":"18b64a30-3cbb-4006-8019-cfa106a9a804","banner":null,"lang":"en","date_modified":"2019-03-14","date_modified_ts":"2019-03-14T17:21:57Z","date_created":"2019-03-14T17:20:21Z","summary":null,"body":["<article data-history-node-id=\"1454\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-046<\/strong><br \/><strong>Date: 14 March 2019<\/strong><\/p>\n\n<p>Google has released security updates to address vulnerabilities affecting its Chrome browser. A remote attacker could exploit some of these vulnerabilities to run arbitrary commands on the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/03\/stable-channel-update-for-desktop_12.html\">https:\/\/chromereleases.googleblog.com\/2019\/03\/stable-channel-update-for-desktop_12.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-0","alert_type":396,"serial_number":"AV19-046","subject":null,"moderation_state":"archived","external_url":null},{"nid":1455,"title":"Cisco security advisory","uuid":"84db1b93-13f4-434b-a01a-7f9c60dd8bda","banner":null,"lang":"en","date_modified":"2019-03-14","date_modified_ts":"2019-03-14T19:58:53Z","date_created":"2019-03-14T19:57:43Z","summary":null,"body":["<article data-history-node-id=\"1455\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-13\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-047<\/strong><br \/><strong>Date: 14 March 2019<\/strong><\/p>\n\n<p>On 13 March 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products. A remote attacker could exploit one of these vulnerabilities to cause a denial-of-service condition or log into a system with default credentials.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-13","alert_type":396,"serial_number":"AV19-047","subject":null,"moderation_state":"archived","external_url":null},{"nid":1456,"title":"Intel security advisory","uuid":"b78a4df1-6b85-4c2d-b465-a17aa85f6d5b","banner":null,"lang":"en","date_modified":"2019-03-14","date_modified_ts":"2019-03-14T20:02:10Z","date_created":"2019-03-14T20:00:45Z","summary":null,"body":["<article data-history-node-id=\"1456\" about=\"\/en\/alerts-advisories\/intel-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-048<\/strong><br \/><strong>Date: 14 March 2019<\/strong><\/p>\n\n<p>Intel has released security updates to address vulnerabilities affecting some of its products. Noteworthy disclosures include:<\/p>\n\n<ul><li>an Intel Graphics Driver for Windows vulnerability that could allow a local, authenticated attacker to escalate privileges; and<\/li>\n\t<li>an Intel Matrix Storage Manager vulnerability that could allow a local, authenticated attacker to escalate privileges.<\/li>\n<\/ul><p>CCCS encourages users and administrators to review the Intel Product Security Center Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p>CCCS also encourages users and administrators to uninstall Intel Matrix Storage Manager as per Intel\u2019s recommendations as it is no longer supported.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-0","alert_type":396,"serial_number":"AV19-048","subject":null,"moderation_state":"archived","external_url":null},{"nid":1457,"title":"Windows 7 end of support","uuid":"09125e51-09cf-4e39-b6a8-3d9055a38a18","banner":null,"lang":"en","date_modified":"2019-03-19","date_modified_ts":"2019-03-19T15:07:42Z","date_created":"2019-03-19T15:04:55Z","summary":null,"body":["<article data-history-node-id=\"1457\" about=\"\/en\/alerts-advisories\/windows-7-end-support\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: IN19-003<\/strong><br \/><strong>Date: 15 March 2019<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>The purpose of this Information Note is to draw attention to the end of support for Microsoft Windows 7. Effective 14 January 2020 Microsoft will no longer provide automatic fixes, security updates, or online technical assistance for this product.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Effective 14 January 2020, Microsoft will no longer support the Windows 7 operating system. Organizations and individuals running this operating system after the end of support date will no longer receive security updates or support, and may be exposed to future security risks. Hardware and software compatibility issues may also arise when implementing current technologies which may not have been designed for use with a Windows 7 operating system.<\/p>\n\n<p>Migration to a newer operating system can present unique challenges and it is critical that organizations and individuals currently running Windows 7 plan and test a migration solution before the deadline. Applications and hardware designed for Windows 7 may have compatibility issues with more recent Windows products and\/or alternate operating systems. Organizations will need to ensure that their critical applications are compatible with the operating system chosen for migration. Support for Internet Explorer 10 will also be discontinued on 14 January 2020.<\/p>\n\n<p>For issues regarding application compatibility with newer Windows operating systems, it is possible to utilize Microsoft\u2019s Desktop App Assure service for assistance with migration and compatibility. Organizations will need to identify all infrastructure, application and hardware dependencies when planning an operating system migration. The Microsoft Assessment and Planning Toolkit (MAP) can be used to enumerate Windows 7 instances and assess hardware compatibility for newer Windows operating systems.<\/p>\n\n<p>CCCS recommends that the planning process for the migration of Windows 7 operating systems include the following:<\/p>\n\n<ul><li>Have an accurate inventory of systems with operating systems reaching end of life.<\/li>\n\t<li>Prioritize the systems to be migrated.<\/li>\n\t<li>Decide on a destination for systems being migrated.<\/li>\n\t<li>Decide on a supported operating system.<\/li>\n<\/ul><p>Options are available to purchase Extended Security Updates for up to 3 years for operating systems environments that cannot be migrated by 14 January 2020. These updates will only cover security vulnerabilities deemed to be \u201ccritical\u201d by Microsoft.<\/p>\n\n<h2>Suggested Action<\/h2>\n\n<p>CCCS strongly encourages Information Technology owners and operators relying on Windows 7 to begin planning their migration to a supported operating system as soon as possible.<\/p>\n\n<h2>References<\/h2>\n\n<ul><li><a href=\"https:\/\/www.microsoft.com\/en-us\/windowsforbusiness\/end-of-windows-7-support\">Prepare for Windows 7 End of Support<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-us\/fasttrack\/microsoft-365\/desktop-app-assure\">Microsoft Desktop App Assure service<\/a><\/li>\n\t<li><a href=\"https:\/\/support.microsoft.com\/en-us\/hub\/4095338\/microsoft-lifecycle-policy\">Microsoft Product Lifecycle<\/a><\/li>\n<\/ul><h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/windows-7-end-support","alert_type":396,"serial_number":"IN19-003","subject":null,"moderation_state":"archived","external_url":null},{"nid":1458,"title":"VMware security bulletin","uuid":"e40a6556-0c18-428d-8b81-d84a8d4103e1","banner":null,"lang":"en","date_modified":"2019-03-19","date_modified_ts":"2019-03-19T15:12:57Z","date_created":"2019-03-19T15:10:15Z","summary":null,"body":["<article data-history-node-id=\"1458\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin-3\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-049<\/strong><br \/><strong>Date: 15 March 2019<\/strong><\/p>\n\n<p>On 14 March 2019, VMware released security updates to address vulnerabilities affecting VMware Workstation and VMware Horizon. A local attacker could exploit these vulnerabilities leading to an escalation of privilege.<\/p>\n\n<p>CCCS encourages users to review the latest VMware Security Advisories webpage for details about the vulnerabilities and apply the appropriate patches:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">https:\/\/www.vmware.com\/security\/advisories.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin-3","alert_type":396,"serial_number":"AV19-049","subject":null,"moderation_state":"archived","external_url":null},{"nid":1459,"title":"Mozilla security bulletins","uuid":"ca0d8669-17ed-4cb8-aaba-5af27fffc6d0","banner":null,"lang":"en","date_modified":"2019-03-19","date_modified_ts":"2019-03-19T19:54:44Z","date_created":"2019-03-19T19:52:39Z","summary":null,"body":["<article data-history-node-id=\"1459\" about=\"\/en\/alerts-advisories\/mozilla-security-bulletins-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-050<\/strong><br \/><strong>Date: 15 March 2019<\/strong><\/p>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR. A remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\">https:\/\/www.mozilla.org\/en-US\/security\/advisories<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-bulletins-1","alert_type":396,"serial_number":"AV19-050","subject":null,"moderation_state":"archived","external_url":null},{"nid":1460,"title":"Cisco security advisory","uuid":"d6c58554-84bb-4ce6-b34e-84722ea00ff9","banner":null,"lang":"en","date_modified":"2019-03-20","date_modified_ts":"2019-03-20T19:39:48Z","date_created":"2019-03-20T19:37:55Z","summary":null,"body":["<article data-history-node-id=\"1460\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-14\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-051<\/strong><br \/><strong>Date: 20 March 2019<\/strong><\/p>\n\n<p>On 20 March 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products. A remote attacker could exploit one of these vulnerabilities to run arbitrary code on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-14","alert_type":396,"serial_number":"AV19-051","subject":null,"moderation_state":"archived","external_url":null},{"nid":1461,"title":"Medtronic security advisory","uuid":"fd2175f1-7e6a-4bd6-aa51-b99546276c80","banner":null,"lang":"en","date_modified":"2019-03-22","date_modified_ts":"2019-03-22T17:10:43Z","date_created":"2019-03-22T17:09:16Z","summary":null,"body":["<article data-history-node-id=\"1461\" about=\"\/en\/alerts-advisories\/medtronic-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-052<\/strong><br \/><strong>Date: 22 March 2019<\/strong><\/p>\n\n<p>On 21 March 2019, Medtronic released a security bulletin to address vulnerabilities affecting the Medtronic Conexus radio frequency wireless telemetry protocol used by some Medtronic ICDs (implantable cardioverter defibrillators) and CRT-Ds (cardiac resynchronization therapy defibrillators). This vulnerability could allow an unauthorized individual to access and potentially change the settings of an implantable device, home monitor or clinic programmer.<\/p>\n\n<p>CCCS encourages users and administrators to review the Medtronic Security Bulletin and follow the recommended mitigation steps:<\/p>\n\n<p><a href=\"https:\/\/www.medtronic.com\/content\/dam\/medtronic-com\/us-en\/corporate\/documents\/Medtronic-security-bulletin_CRHF_Tel_C_FNL.pdf\">https:\/\/www.medtronic.com\/content\/dam\/medtronic-com\/us-en\/corporate\/documents\/Medtronic-security-bulletin_CRHF_Tel_C_FNL.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/medtronic-security-advisory","alert_type":396,"serial_number":"AV19-052","subject":null,"moderation_state":"archived","external_url":null},{"nid":1462,"title":"Mozilla security advisory","uuid":"70046104-0eb5-41d0-87f9-54b22ab46168","banner":null,"lang":"en","date_modified":"2019-03-25","date_modified_ts":"2019-03-25T19:11:03Z","date_created":"2019-03-25T19:07:51Z","summary":null,"body":["<article data-history-node-id=\"1462\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-053<\/strong><br \/><strong>Date: 25 March 2019<\/strong><\/p>\n\n<p>Mozilla has released security updates to address vulnerabilities in Firefox. A remote attacker could exploit one of these vulnerabilities to take control of an affected system through a buffer overflow attack. A buffer overflow is when, as the name implies, a program writes data to a buffer in memory for which there is no bounds checking, thus allowing data to be written past the buffer into adjacent memory locations. This could, in turn, allow the attacker to execute arbitrary code, potentially leading to remote control of the machine.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\">https:\/\/www.mozilla.org\/en-US\/security\/advisories<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-0","alert_type":396,"serial_number":"AV19-053","subject":null,"moderation_state":"archived","external_url":null},{"nid":1463,"title":"Apple security advisory","uuid":"a20a5ff1-1660-4d78-a657-cc7205b81ea5","banner":null,"lang":"en","date_modified":"2019-03-26","date_modified_ts":"2019-03-26T15:42:10Z","date_created":"2019-03-26T15:40:34Z","summary":null,"body":["<article data-history-node-id=\"1463\" about=\"\/en\/alerts-advisories\/apple-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-054<\/strong><br \/><strong>Date: 26 March 2019<\/strong><\/p>\n\n<p>Apple has released security updates to address vulnerabilities affecting some Apple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system through a buffer overflow attack. A buffer overflow is when, as the name implies, a program writes data to a buffer in memory for which there is no bounds checking, thus allowing data to be written past the buffer into adjacent memory locations. This could, in turn, allow the attacker to execute arbitrary code, potentially leading to remote control of the machine.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory","alert_type":396,"serial_number":"AV19-054","subject":null,"moderation_state":"archived","external_url":null},{"nid":1464,"title":"Mozilla security bulletins","uuid":"1fe397d0-6a75-4b05-a60e-94111499d1de","banner":null,"lang":"en","date_modified":"2019-03-26","date_modified_ts":"2019-03-26T19:39:06Z","date_created":"2019-03-26T19:37:24Z","summary":null,"body":["<article data-history-node-id=\"1464\" about=\"\/en\/alerts-advisories\/mozilla-security-bulletins-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-055<\/strong><br \/><strong>Date: 26 March 2019<\/strong><\/p>\n\n<p>On 25 March 2019, Mozilla released security updates to address vulnerabilities in Thunderbird. A remote attacker could exploit one of these vulnerabilities to take control of an affected system through a buffer overflow attack. A buffer overflow is when, as the name implies, a program writes data to a buffer in memory for which there is no bounds checking, thus allowing data to be written past the buffer into adjacent memory locations. This could, in turn, allow the attacker to execute arbitrary code, potentially leading to remote control of the machine.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-bulletins-2","alert_type":396,"serial_number":"AV19-055","subject":null,"moderation_state":"archived","external_url":null},{"nid":1465,"title":"NVIDIA security advisory","uuid":"d439069a-fc40-415a-8089-1de478f0d270","banner":null,"lang":"en","date_modified":"2019-03-27","date_modified_ts":"2019-03-27T15:19:29Z","date_created":"2019-03-27T15:18:10Z","summary":null,"body":["<article data-history-node-id=\"1465\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-056<\/strong><br \/><strong>Date: 27 March 2019<\/strong><\/p>\n\n<p>NVIDIA has released a security update to address a vulnerability affecting its GeForce Experience software. A local, authenticated attacker could exploit this vulnerability to run arbitrary commands or to escalate privileges on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4784\/kw\/Security%20Bulletin\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4784\/kw\/Security%20Bulletin<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-1","alert_type":396,"serial_number":"AV19-056","subject":null,"moderation_state":"archived","external_url":null},{"nid":1466,"title":"ASUS security advisory","uuid":"34e388a9-c267-4b80-8875-fac3f3c0b2dc","banner":null,"lang":"en","date_modified":"2019-03-27","date_modified_ts":"2019-03-27T15:23:06Z","date_created":"2019-03-27T15:21:36Z","summary":null,"body":["<article data-history-node-id=\"1466\" about=\"\/en\/alerts-advisories\/asus-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-057<\/strong><br \/><strong>Date: 27 March 2019<\/strong><\/p>\n\n<p>ASUS has released security updates to its proprietary Live Update tool. This tool is installed on ASUS notebooks to facilitate the download of the latest ASUS firmware and drivers. It was recently disclosed that malicious actors were able to compromise Live Update servers and plant malicious code masquerading as valid updates, which in turn propagated to ASUS notebooks connecting to these servers. Fixes for the Live Update tool include more stringent security measures with regard to vetting the integrity of the updates, enhanced encryption between the Live Update servers and the client notebooks, and the bolstering of the Live Update software infrastructure as a whole.<\/p>\n\n<p>CCCS encourages users and administrators to review the ASUS webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.asus.com\/News\/hqfgVUyZ6uyAyJe1\">https:\/\/www.asus.com\/News\/hqfgVUyZ6uyAyJe1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/asus-security-advisory","alert_type":396,"serial_number":"AV19-057","subject":null,"moderation_state":"archived","external_url":null},{"nid":1467,"title":"Phoenix Contact security advisory","uuid":"dee29f7a-a407-4cae-964d-c0e141c1aa09","banner":null,"lang":"en","date_modified":"2019-03-27","date_modified_ts":"2019-03-27T15:27:02Z","date_created":"2019-03-27T15:25:18Z","summary":null,"body":["<article data-history-node-id=\"1467\" about=\"\/en\/alerts-advisories\/phoenix-contact-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-058<\/strong><br \/><strong>Date: 27 March 2019<\/strong><\/p>\n\n<p>On 20 March 2019, Phoenix Contact has released a security advisory to address a vulnerability affecting some of their industrial control products. An attacker could exploit this vulnerability to execute system level commands with administrative privileges.<\/p>\n\n<p>CCCS encourages users and administrators to review the Phoenix Contact Security Advisory and follow the recommended mitigation steps:<\/p>\n\n<p><a href=\"https:\/\/dam-mdc.phoenixcontact.com\/asset\/156443151564\/9fb2cbfca1a136a5e0a33f38632d8cc0\/Security_Advisory_for_RAD-80211-XD_RAD80211_XDHPBUS.pdf\">https:\/\/dam-mdc.phoenixcontact.com\/asset\/156443151564\/9fb2cbfca1a136a5e0a33f38632d8cc0\/Security_Advisory_for_RAD-80211-XD_RAD80211_XDHPBUS.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/phoenix-contact-security-advisory","alert_type":396,"serial_number":"AV19-058","subject":null,"moderation_state":"archived","external_url":null},{"nid":1468,"title":"Cisco security advisory","uuid":"6af07f68-dbb6-4278-a960-8d5bed40a802","banner":null,"lang":"en","date_modified":"2019-03-28","date_modified_ts":"2019-03-28T19:43:57Z","date_created":"2019-03-28T19:36:36Z","summary":null,"body":["<article data-history-node-id=\"1468\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-15\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-059<\/strong><br \/><strong>Date: 28 March 2019<\/strong><\/p>\n\n<p>On 27 March 2019, Cisco released security updates to address vulnerabilities affecting certain Cisco products, notably Cisco IOS XE Software. An authenticated, remote attacker could exploit these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing\">https:\/\/tools.cisco.com\/security\/center\/publicationListing<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-15","alert_type":396,"serial_number":"AV19-059","subject":null,"moderation_state":"archived","external_url":null},{"nid":1469,"title":"Rockwell Automation security advisory","uuid":"b0384500-1ef8-442d-8fd4-0987f9197304","banner":null,"lang":"en","date_modified":"2019-03-29","date_modified_ts":"2019-03-29T19:39:19Z","date_created":"2019-03-29T19:37:14Z","summary":null,"body":["<article data-history-node-id=\"1469\" about=\"\/en\/alerts-advisories\/rockwell-automation-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-060<\/strong><br \/><strong>Date: 29 March 2019<\/strong><\/p>\n\n<p>Rockwell Automation has released a security advisory to address a vulnerability affecting its PowerFlex 525 AC industrial control product. A remote, unauthenticated attacker could exploit this vulnerability and cause resource exhaustion, denial of service, and\/or memory corruption.<\/p>\n\n<p>CCCS encourages users and administrators to review the Rockwell Automation advisory and download the latest firmware:<\/p>\n\n<p><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/1082684\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/1082684<\/a> (login required)<\/p>\n\n<p><a href=\"https:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=25B&amp;crumb=112\">https:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=25B&amp;crumb=112<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rockwell-automation-security-advisory","alert_type":396,"serial_number":"AV19-060","subject":null,"moderation_state":"archived","external_url":null},{"nid":1470,"title":"VMware security bulletin","uuid":"cb2733c2-fb82-4c72-8a8f-86d49e30aa25","banner":null,"lang":"en","date_modified":"2019-03-29","date_modified_ts":"2019-03-29T19:44:48Z","date_created":"2019-03-29T19:42:17Z","summary":null,"body":["<article data-history-node-id=\"1470\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-061<\/strong><br \/><strong>Date: 29 March 2019<\/strong><\/p>\n\n<p>On 28 March 2019 VMware has released security updates to address vulnerabilities affecting VMware Workstation, ESXi, Fusion and its VMware vCloud Director for Service Providers product. Successful exploitation of these vulnerabilities could result in a Remote Session Hijack, or may allow a guest to execute code on the host.<\/p>\n\n<p>CCCS encourages users to review the following VMware Security Advisory for details about the vulnerabilities and apply the appropriate patches:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">https:\/\/www.vmware.com\/security\/advisories.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin-4","alert_type":396,"serial_number":"AV19-061","subject":null,"moderation_state":"archived","external_url":null},{"nid":1471,"title":"Android security advisory","uuid":"43416d1d-92de-4fc5-bcab-cc078c208bf0","banner":null,"lang":"en","date_modified":"2019-04-02","date_modified_ts":"2019-04-02T17:58:17Z","date_created":"2019-04-02T17:56:23Z","summary":null,"body":["<article data-history-node-id=\"1471\" about=\"\/en\/alerts-advisories\/android-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-062<\/strong><br \/><strong>Date: 2 April 2019<\/strong><\/p>\n\n<p>Google has released security updates to address multiple vulnerabilities affecting Android devices. A remote attacker could exploit some of these vulnerabilities using a specially crafted file to execute arbitrary code within the context of a privileged process.<\/p>\n\n<p>CCCS encourages users and administrators to review the Android security bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-04-01#2019-04-01-details\">https:\/\/source.android.com\/security\/bulletin\/2019-04-01#2019-04-01-details<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-0","alert_type":396,"serial_number":"AV19-062","subject":null,"moderation_state":"archived","external_url":null},{"nid":1472,"title":"Advantech security bulletin","uuid":"c610cb67-224d-4456-8ac4-493b8f1ac484","banner":null,"lang":"en","date_modified":"2019-04-03","date_modified_ts":"2019-04-03T17:29:33Z","date_created":"2019-04-03T17:27:22Z","summary":null,"body":["<article data-history-node-id=\"1472\" about=\"\/en\/alerts-advisories\/advantech-security-bulletin\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-063<\/strong><br \/><strong>Date: 3 April 2019<\/strong><\/p>\n\n<p>On 1 April 2019 Advantech released security updates to address three vulnerabilities, including but not limited to, stack buffer overflow, remote code execution and denial of service in the WebAccess product. Successful exploitation of these vulnerabilities may allow a remote unauthenticated user to execute arbitrary code, or cause a denial of service condition.<\/p>\n\n<p>The following version is affected:<\/p>\n\n<p>WebAccess\/SCADA - All Versions prior to 8.4.0<\/p>\n\n<p>CCCS encourages owners\/operators test and deploy the vendor released update:<\/p>\n\n<p><a href=\"https:\/\/support.advantech.com\/support\/DownloadSRDetail_New.aspx?SR_ID=1-MS9MJV&amp;Doc_Source=Download\">https:\/\/support.advantech.com\/support\/DownloadSRDetail_New.aspx?SR_ID=1-MS9MJV&amp;Doc_Source=Download<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/advantech-security-bulletin","alert_type":396,"serial_number":"AV19-063","subject":null,"moderation_state":"archived","external_url":null},{"nid":1473,"title":"Fortinet security advisory","uuid":"4ecfd73d-2dab-4af7-a5ae-ca8706331ef8","banner":null,"lang":"en","date_modified":"2019-04-03","date_modified_ts":"2019-04-03T18:55:01Z","date_created":"2019-04-03T18:53:03Z","summary":null,"body":["<article data-history-node-id=\"1473\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-064<\/strong><br \/><strong>Date: 3 April 2019<\/strong><\/p>\n\n<p>Fortinet has released updates to address vulnerabilities affecting some Fortinet products. One of the vulnerabilities includes exposure of the LDAP server password via the admin portal of the FortiSIEM product, exposing sensitive data or allowing manipulation of the database if the attacker were able to gain access to the LDAP server. An attacker would have to possess the FortiSIEM admin credentials in order to exploit this vulnerability.<\/p>\n\n<p>CCCS encourages users and administrators to review the Fortinet advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/fortiguard.com\/psirt\">https:\/\/fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-0","alert_type":396,"serial_number":"AV19-064","subject":null,"moderation_state":"archived","external_url":null},{"nid":1474,"title":"Apache HTTP Server security advisory","uuid":"e62a377f-4f0b-47c8-ab62-60e2a13e4d6b","banner":null,"lang":"en","date_modified":"2019-04-03","date_modified_ts":"2019-04-03T18:59:55Z","date_created":"2019-04-03T18:58:19Z","summary":null,"body":["<article data-history-node-id=\"1474\" about=\"\/en\/alerts-advisories\/apache-http-server-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-065<\/strong><br \/><strong>Date: 3 April 2019<\/strong><\/p>\n\n<p>On 1 April 2019, Apache Software Foundation released security updates to address vulnerabilities affecting certain versions of Apache HTTP Server. A local authenticated attacker could exploit these vulnerabilities to elevate their privileges and execute arbitrary code with root privileges.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apache HTTP Server 2.4 vulnerabilities webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html\">https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-http-server-security-advisory","alert_type":396,"serial_number":"AV19-065","subject":null,"moderation_state":"archived","external_url":null},{"nid":1475,"title":"NVIDIA security advisory","uuid":"ce4b551d-74bf-4bd2-840b-fded4d0312ea","banner":null,"lang":"en","date_modified":"2019-04-05","date_modified_ts":"2019-04-05T17:49:37Z","date_created":"2019-04-05T17:48:01Z","summary":null,"body":["<article data-history-node-id=\"1475\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-2\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-066<\/strong><br \/><strong>Date: 5 April 2019<\/strong><\/p>\n\n<p>NVIDIA has released security updates to address vulnerabilities affecting its NVIDIA Jetson TX1 and TX2 low-power computing boards. More specifically, these vulnerabilities reside in the kernel drivers for the processor, an NVIDIA Tegra, which is present on both of these board models. The Jetson TX1 and TX2 are typically used in battery operated, portable devices such as drones, smart cameras, and personal medical devices. A local attacker could exploit some of these vulnerabilities to run arbitrary commands or to escalate privileges on an affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4787\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4787<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-2","alert_type":396,"serial_number":"AV19-066","subject":null,"moderation_state":"archived","external_url":null},{"nid":1476,"title":"Magento security advisory","uuid":"68d85722-4c25-40ee-a4e6-f2b38edae5f9","banner":null,"lang":"en","date_modified":"2019-04-05","date_modified_ts":"2019-04-05T17:58:19Z","date_created":"2019-04-05T17:52:12Z","summary":null,"body":["<article data-history-node-id=\"1476\" about=\"\/en\/alerts-advisories\/magento-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-067<\/strong><br \/><strong>Date: 5 April 2019<\/strong><\/p>\n\n<p>Magento has released security updates to address multiple vulnerabilities affecting versions of their Magento Commerce and Open Source platforms. An authenticated remote attacker could exploit some of these vulnerabilities to execute arbitrary code through crafted newsletter or email template code.<\/p>\n\n<p>CCCS encourages users and administrators to review the following Magento Security Update and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/magento.com\/security\/patches\/magento-2.3.1-2.2.8-and-2.1.17-security-update\">https:\/\/magento.com\/security\/patches\/magento-2.3.1-2.2.8-and-2.1.17-security-update<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/magento-security-advisory","alert_type":396,"serial_number":"AV19-067","subject":null,"moderation_state":"archived","external_url":null},{"nid":1477,"title":"Rockwell Automation security advisory","uuid":"20b731c6-db4e-4361-a66a-a91c4c3e422f","banner":null,"lang":"en","date_modified":"2019-04-05","date_modified_ts":"2019-04-05T18:14:24Z","date_created":"2019-04-05T18:13:04Z","summary":null,"body":["<article data-history-node-id=\"1477\" about=\"\/en\/alerts-advisories\/rockwell-automation-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-068<\/strong><br \/><strong>Date: 5 April 2019<\/strong><\/p>\n\n<p>Rockwell Automation has released security updates to address vulnerabilities affecting some of its Stratix industrial switches (listed below). A remote, unauthenticated attacker could exploit some of these vulnerabilities to cause a denial of service condition on the device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Rockwell Automation updates and download the latest firmware:<\/p>\n\n<p><a href=\"https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/1082684\">https:\/\/rockwellautomation.custhelp.com\/app\/answers\/detail\/a_id\/1082684<\/a> (login required)<\/p>\n\n<p><a href=\"https:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=25B&amp;crumb=112\">https:\/\/compatibility.rockwellautomation.com\/Pages\/MultiProductDownload.aspx?Keyword=25B&amp;crumb=112<\/a><\/p>\n\n<p>Affected products:<\/p>\n\n<p>Stratix 5400, 5410, 5700, 8000, 8300, 5950, and ArmorStratix 5700 switches<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rockwell-automation-security-advisory-0","alert_type":396,"serial_number":"AV19-068","subject":null,"moderation_state":"archived","external_url":null},{"nid":1478,"title":"Cisco Security Advisories","uuid":"f09df360-5936-417c-9dac-5bf557b00919","banner":null,"lang":"en","date_modified":"2019-04-05","date_modified_ts":"2019-04-05T19:45:35Z","date_created":"2019-04-05T19:43:11Z","summary":null,"body":["<article data-history-node-id=\"1478\" about=\"\/en\/alerts-advisories\/cisco-security-advisories-4\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-069<\/strong><br \/><strong>Date: 5 April 2019<\/strong><\/p>\n\n<p>On 4 April 2019, Cisco released amended security advisories to address vulnerabilities affecting their Cisco Small Business RV320 and RV325 Routers. An attacker could exploit some of these vulnerabilities to take control of an affected device or expose sensitive data.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisories-4","alert_type":396,"serial_number":"AV19-069","subject":null,"moderation_state":"archived","external_url":null},{"nid":1479,"title":"Apple security advisory","uuid":"2de04f34-8b85-4a95-b70d-223f49a9c83b","banner":null,"lang":"en","date_modified":"2019-04-09","date_modified_ts":"2019-04-09T14:39:16Z","date_created":"2019-04-09T14:37:14Z","summary":null,"body":["<article data-history-node-id=\"1479\" about=\"\/en\/alerts-advisories\/apple-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-070<\/strong><br \/><strong>Date: 8 April 2019<\/strong><\/p>\n\n<p>Apple has released security updates to address vulnerabilities affecting macOS. A remote attacker could exploit some of these vulnerabilities to take control of an affected system through a buffer overflow attack. A buffer overflow is when, as the name implies, a program writes data to a buffer in memory for which there is no bounds checking, thus allowing data to be written past the buffer into adjacent memory locations. This could, in turn, allow the attacker to execute arbitrary code, potentially leading to remote control of the machine.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ph\/HT209600\">https:\/\/support.apple.com\/en-ph\/HT209600<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-0","alert_type":396,"serial_number":"AV19-070","subject":null,"moderation_state":"archived","external_url":null},{"nid":1480,"title":"Samba security advisory","uuid":"b2565ea5-aa6e-4bfa-9921-f55ca97dc28e","banner":null,"lang":"en","date_modified":"2019-04-09","date_modified_ts":"2019-04-09T15:38:21Z","date_created":"2019-04-09T15:37:03Z","summary":null,"body":["<article data-history-node-id=\"1480\" about=\"\/en\/alerts-advisories\/samba-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-071<\/strong><br \/><strong>Date: 9 April 2019<\/strong><\/p>\n\n<p>On 8 April 2019, Samba released security advisories to address vulnerabilities affecting certain versions of their Samba software. An authenticated attacker with write privileges could exploit some of these vulnerabilities to detect and write files beyond the scope of their permissions.<\/p>\n\n<p>CCCS encourages users and administrators to review the Samba Security Releases webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">https:\/\/www.samba.org\/samba\/history\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-advisory","alert_type":396,"serial_number":"AV19-071","subject":null,"moderation_state":"archived","external_url":null},{"nid":1481,"title":"Adobe security advisory","uuid":"b2f9102a-3550-454b-b780-c86f4e813e3d","banner":null,"lang":"en","date_modified":"2019-04-09","date_modified_ts":"2019-04-09T18:12:04Z","date_created":"2019-04-09T17:44:31Z","summary":null,"body":["<article data-history-node-id=\"1481\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-072<\/strong><br \/><strong>Date: 9 April 2019<\/strong><\/p>\n\n<p>On 9 April 2019, Adobe released security advisories to address vulnerabilities affecting certain versions of Acrobat and Reader, Flash Player, Shockwave Player, Dreamweaver, XD CC, InDesign, Experience Manager Forms, and Bridge CC. An attacker could exploit some of these vulnerabilities to execute arbitrary code with the privileges of the current user.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-17.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-17.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-0","alert_type":396,"serial_number":"AV19-072","subject":null,"moderation_state":"archived","external_url":null},{"nid":1482,"title":"TP-Link security advisory","uuid":"f5a65d55-9942-40a1-9685-23ee59e87628","banner":null,"lang":"en","date_modified":"2019-04-10","date_modified_ts":"2019-04-10T18:09:29Z","date_created":"2019-04-10T18:08:02Z","summary":null,"body":["<article data-history-node-id=\"1482\" about=\"\/en\/alerts-advisories\/tp-link-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-073<\/strong><br \/><strong>Date: 10 April 2019<\/strong><\/p>\n\n<p>TP-Link has released firmware updates to address a vulnerability affecting two of its routers: TL-WR940N and TL-WR941ND. A remote attacker could exploit this vulnerability by sending specially-crafted Internet Control Message Protocol echo requests (ping requests) to the affected system, resulting in a buffer overflow and thus possible control of the system. A buffer overflow is when, as the name implies, a program writes data to a buffer in memory for which there is no bounds checking, thus allowing data to be written past the buffer into adjacent memory locations. This could, in turn, allow the attacker to execute arbitrary code, potentially leading to remote control of the machine.<\/p>\n\n<p>CCCS encourages users and administrators to review the TP-Link download pages for the affected routers and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.tp-link.com\/en\/support\/download\/tl-wr940n\">https:\/\/www.tp-link.com\/en\/support\/download\/tl-wr940n<\/a> (TL-WR940N)<\/p>\n\n<p><a href=\"https:\/\/www.tp-link.com\/en\/support\/download\/tl-wr941nd\">https:\/\/www.tp-link.com\/en\/support\/download\/tl-wr941nd<\/a> (TL-WR941ND)<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tp-link-security-advisory","alert_type":396,"serial_number":"AV19-073","subject":null,"moderation_state":"archived","external_url":null},{"nid":1483,"title":"Microsoft security advisory","uuid":"30014611-744f-40b2-9eac-220fcaad2541","banner":null,"lang":"en","date_modified":"2019-04-10","date_modified_ts":"2019-04-10T18:13:22Z","date_created":"2019-04-10T18:11:25Z","summary":null,"body":["<article data-history-node-id=\"1483\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-074<\/strong><br \/><strong>Date: 10 April 2019<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities affecting some Microsoft products. This includes updates to patch vulnerabilities for which active exploitations have been reported, allowing remote attackers to run arbitrary code on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft April 2019 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/18306ed5-1019-e911-a98b-000d3a33a34d\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/18306ed5-1019-e911-a98b-000d3a33a34d<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-0","alert_type":396,"serial_number":"AV19-074","subject":null,"moderation_state":"archived","external_url":null},{"nid":1484,"title":"Intel security advisory","uuid":"61445eb6-e32b-4138-8745-d2ee83337f59","banner":null,"lang":"en","date_modified":"2019-04-10","date_modified_ts":"2019-04-10T18:17:48Z","date_created":"2019-04-10T18:16:17Z","summary":null,"body":["<article data-history-node-id=\"1484\" about=\"\/en\/alerts-advisories\/intel-security-advisory-1\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-075<\/strong><br \/><strong>Date: 10 April 2019<\/strong><\/p>\n\n<p>Intel has released security updates to address vulnerabilities affecting some of its products. Of note is a patch for Intel\u2019s Media SDK software which is vulnerable due to improper directory permissions in the installer. A local, authenticated malicious actor could exploit this vulnerability to escalate privileges.<\/p>\n\n<p>CCCS encourages users and administrators to review the Intel Product Security Center Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-1","alert_type":396,"serial_number":"AV19-075","subject":null,"moderation_state":"archived","external_url":null},{"nid":1485,"title":"Siemens Security Advisories","uuid":"9ba9d149-2933-4e37-9a43-f8ca7c47d93d","banner":null,"lang":"en","date_modified":"2019-04-11","date_modified_ts":"2019-04-11T14:30:11Z","date_created":"2019-04-11T14:28:00Z","summary":null,"body":["<article data-history-node-id=\"1485\" about=\"\/en\/alerts-advisories\/siemens-security-advisories-0\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-076<\/strong><br \/><strong>Date: 11 April 2019<\/strong><\/p>\n\n<p>On 9 April 2019 Siemens released security updates to address vulnerabilities in various products. Successful exploitation of these vulnerabilities may allow a remote unauthenticated malicious actor to circumvent the system authorization for certain functionalities, execute privileged functions or remote code, or cause a denial-of-service condition leading to a restart of the webserver.<\/p>\n\n<p>The following devices and software are affected:<\/p>\n\n<ul><li>Siemens CP, SIAMTIC, SIMOCODE, SINAMICS, SITOP, and TIM<\/li>\n\t<li>RUGGEDCOM ROX II<\/li>\n\t<li>SINEMA Remote Connect (Client and Server)<\/li>\n\t<li>SIMATIC, SINEC-NMS, SINEMA, SINEMURIK Industrial Control Products with OPC UA<\/li>\n\t<li>Spectrum Power 4.7<\/li>\n\t<li>SIMOCODE pro V EIP<\/li>\n<\/ul><p>CCCS encourages owners\/operators test and deploy the vendor released mitigations and updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-480230.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-480230.pdf<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-451142.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-451142.pdf<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-436177.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-436177.pdf<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-307392.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-307392.pdf<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-324467.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-324467.pdf<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-141614.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-141614.pdf<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/siemens-security-advisories-0","alert_type":396,"serial_number":"AV19-076","subject":null,"moderation_state":"archived","external_url":null},{"nid":1486,"title":"Unpatched Edge and IE Vulnerabilities","uuid":"101c32a1-312d-47f6-b898-fcbe89a24fba","banner":null,"lang":"en","date_modified":"2019-04-11","date_modified_ts":"2019-04-11T19:31:54Z","date_created":"2019-04-11T19:30:02Z","summary":null,"body":["<article data-history-node-id=\"1486\" about=\"\/en\/alerts-advisories\/unpatched-edge-and-ie-vulnerabilities\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-077<\/strong><br \/><strong>Date: 11 April 2019<\/strong><\/p>\n\n<p>Proof of Concept code has been released for a vulnerability that allows JavaScript embedded in a malicious web page to gather information about other web pages the user has visited. Microsoft has not released any patches to address the vulnerability.<\/p>\n\n<p>This vulnerability can be exploited by a malicious website opened in Internet Explorer or Edge to collect potentially sensitive information from other sites visited by the targeted user. The malicious actor would have to convince the victim to visit a malicious website while an open session to other websites exists in the target user's browser. Examples of vulnerable information that might be stored in the URL includes cookies, session IDs, usernames, passwords, and OAUTH tokens, either in plaintext or hash form. Most properly configured websites would not store credentials in a session cookie or URLs and would not be susceptible to this type of information disclosure.<\/p>\n\n<p>Microsoft has responded to industry requests with the following statement:<\/p>\n\n<p><em>\"The issue described does not meet our criteria for servicing and requires an attacker to convince a victim to visit a malicious website. We encourage our customers to practice good computing habits online, including exercising caution when clicking on links to web pages, opening unknown files, or accepting file transfers.\u201d<\/em><\/p>\n\n<p>Microsoft has also pointed users who may be concerned about these vulnerabilities to its online safety resources.<\/p>\n\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/digital-skills\/online-safety-resources\">https:\/\/www.microsoft.com\/en-us\/digital-skills\/online-safety-resources<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/unpatched-edge-and-ie-vulnerabilities","alert_type":396,"serial_number":"AV19-077","subject":null,"moderation_state":"archived","external_url":null},{"nid":1487,"title":"SAP security advisory","uuid":"876e9a5b-b1c6-4435-9804-c1f8df06b714","banner":null,"lang":"en","date_modified":"2019-04-11","date_modified_ts":"2019-04-11T19:36:39Z","date_created":"2019-04-11T19:34:44Z","summary":null,"body":["<article data-history-node-id=\"1487\" about=\"\/en\/alerts-advisories\/sap-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-078<\/strong><br \/><strong>Date: 11 April 2019<\/strong><\/p>\n\n<p>SAP has released security updates to address vulnerabilities affecting some of its products. Of note is a patch for a vulnerability in SAP Crystal Reports which could lead to the disclosure of sensitive information such as debugging data and system information.<\/p>\n\n<p>CCCS encourages users and administrators to review the SAP Security Patch Day webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=517899114\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=517899114<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory","alert_type":396,"serial_number":"AV19-078","subject":null,"moderation_state":"archived","external_url":null},{"nid":1488,"title":"Juniper Networks security advisory","uuid":"95907583-6e01-42a3-a61e-707916bf6c6b","banner":null,"lang":"en","date_modified":"2019-04-12","date_modified_ts":"2019-04-12T18:45:01Z","date_created":"2019-04-12T15:38:07Z","summary":null,"body":["<article data-history-node-id=\"1488\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-079<\/strong><br \/><strong>Date: 12 April 2019<\/strong><\/p>\n\n<p>Juniper Networks has released security updates to address vulnerabilities affecting some of its products. A remote attacker could exploit some of these vulnerabilities to cause a denial of service condition on the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Juniper Networks Security Advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/advisory.juniper.net\/\">https:\/\/advisory.juniper.net\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory","alert_type":396,"serial_number":"AV19-079","subject":null,"moderation_state":"archived","external_url":null},{"nid":1489,"title":"Oracle security advisory","uuid":"80693ced-4bf5-4aa4-897c-e51eb4b36951","banner":null,"lang":"en","date_modified":"2019-04-16","date_modified_ts":"2019-04-16T20:17:54Z","date_created":"2019-04-16T20:16:35Z","summary":null,"body":["<article data-history-node-id=\"1489\" about=\"\/en\/alerts-advisories\/oracle-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-080<\/strong><br \/><strong>Date: 16 April 2019<\/strong><\/p>\n\n<p>Oracle have released their Critical Patch Update Advisory for April 2019. The security updates address multiple vulnerabilities affecting various Oracle products. A remote, malicious actor could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the following Oracle Critical Patch Update Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2019-5072813.html\">https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuapr2019-5072813.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory","alert_type":396,"serial_number":"AV19-080","subject":null,"moderation_state":"archived","external_url":null},{"nid":1490,"title":"Apache Tomcat security advisory","uuid":"ad88c4f1-b9e7-4aac-805c-65e764a4deff","banner":null,"lang":"en","date_modified":"2019-04-16","date_modified_ts":"2019-04-16T20:24:26Z","date_created":"2019-04-16T20:22:11Z","summary":null,"body":["<article data-history-node-id=\"1490\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-081<\/strong><br \/><strong>Date: 16 April 2019<\/strong><\/p>\n\n<p>The Apache Software Foundation has released security updates to address vulnerabilities affecting its Apache Tomcat software (Tomcat Server). Specific conditions must be met in order for the vulnerability to be exploitable, namely, Tomcat Server must be running on Windows and the \u201cenableCmdLineArguments\u201d Tomcat environment parameter must be set. A remote attacker could exploit this vulnerability to take control of an affected system.<\/p>\n\n<p>This vulnerability affects the following versions of Apache Tomcat:<\/p>\n\n<ul><li>Apache Tomcat 9.0.0.M1 to 9.0.17<\/li>\n\t<li>Apache Tomcat 8.5.0 to 8.5.39<\/li>\n\t<li>Apache Tomcat 7.0.0 to 7.0.93<\/li>\n<\/ul><p>CCCS encourages users and administrators to review the Apache Tomcat webpage for the respective major versions and apply the necessary updates:<\/p>\n\n<ul><li><a href=\"http:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.18\">http:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.18<\/a> (Tomcat 9)<\/li>\n\t<li><a href=\"http:\/\/tomcat.apache.org\/security-8.html#Fixed_in_Apache_Tomcat_8.5.40\">http:\/\/tomcat.apache.org\/security-8.html#Fixed_in_Apache_Tomcat_8.5.40<\/a> (Tomcat 8)<\/li>\n\t<li><a href=\"http:\/\/tomcat.apache.org\/security-7.html#Fixed_in_Apache_Tomcat_7.0.94\">http:\/\/tomcat.apache.org\/security-7.html#Fixed_in_Apache_Tomcat_7.0.94<\/a> (Tomcat 7)<\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-advisory","alert_type":396,"serial_number":"AV19-081","subject":null,"moderation_state":"archived","external_url":null},{"nid":1491,"title":"Cisco security advisory","uuid":"2fd86eab-5670-492f-a674-b5407db87d06","banner":null,"lang":"en","date_modified":"2019-04-18","date_modified_ts":"2019-04-18T17:39:36Z","date_created":"2019-04-18T17:37:43Z","summary":null,"body":["<article data-history-node-id=\"1491\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-16\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-082<\/strong><br \/><strong>Date: 18 April 2019<\/strong><\/p>\n\n<p>On 17 April 2019, Cisco released security updates to address vulnerabilities affecting multiple Cisco products, notably Cisco IOS, IOS XE and IOS XR software. A remote, malicious actor could exploit these vulnerabilities to take control of an affected system with elevated privileges.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing\">https:\/\/tools.cisco.com\/security\/center\/publicationListing<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-16","alert_type":396,"serial_number":"AV19-082","subject":null,"moderation_state":"archived","external_url":null},{"nid":1492,"title":"WAGO security advisory","uuid":"ef779670-48ee-4d7b-b8e8-3034b1a45cbc","banner":null,"lang":"en","date_modified":"2019-04-18","date_modified_ts":"2019-04-18T20:06:49Z","date_created":"2019-04-18T20:04:22Z","summary":null,"body":["<article data-history-node-id=\"1492\" about=\"\/en\/alerts-advisories\/wago-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-083<\/strong><br \/><strong>Date: 18 April 2019<\/strong><\/p>\n\n<p>WAGO has released security updates to address vulnerabilities affecting its Series 750-88x and 750-87x, programmable logic controllers. These devices are susceptible to compromise using hard-coded credentials. A malicious remote actor could exploit this vulnerability to take control of the devices and change settings or alter the programming of the devices.<\/p>\n\n<p>The following versions of Series 750-88x and 750-87x, programmable logic controllers, are affected:<\/p>\n\n<ul><li>Series 750-88x\n\t<ul><li>750-330 firmware versions prior to FW14<\/li>\n\t\t<li>750-352 firmware versions prior to FW14<\/li>\n\t\t<li>750-829 firmware versions prior to FW14<\/li>\n\t\t<li>750-831 firmware versions prior to FW14<\/li>\n\t\t<li>750-852 firmware versions prior to FW14<\/li>\n\t\t<li>750-880 firmware versions prior to FW14<\/li>\n\t\t<li>750-881 firmware versions prior to FW14<\/li>\n\t\t<li>750-882 firmware versions prior to FW14<\/li>\n\t\t<li>750-884 firmware versions prior to FW14<\/li>\n\t\t<li>750-885 firmware versions prior to FW14<\/li>\n\t\t<li>750-889 firmware versions prior to FW14<\/li>\n\t<\/ul><\/li>\n\t<li>\u00a0<\/li>\n\t<li>Series 750-87x\n\t<ul><li>750-830 firmware versions prior to FW06<\/li>\n\t\t<li>750-849 firmware versions prior to FW08<\/li>\n\t\t<li>750-871 firmware versions prior to FW11<\/li>\n\t\t<li>750-872 firmware versions prior to FW07<\/li>\n\t\t<li>750-873 firmware versions prior to FW07<\/li>\n\t<\/ul><\/li>\n<\/ul><p>CCCS encourages users and administrators to review the WAGO Security Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.wago.com\/de\/download\/public\/Sicherheitshinweis-SA-SYS-2019-001\/SA-SYS-2019-001.pdf\">https:\/\/www.wago.com\/de\/download\/public\/Sicherheitshinweis-SA-SYS-2019-001\/SA-SYS-2019-001.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wago-security-advisory","alert_type":396,"serial_number":"AV19-083","subject":null,"moderation_state":"archived","external_url":null},{"nid":1493,"title":"China Chopper Malware affecting SharePoint Servers","uuid":"03be503a-1277-4f31-90cf-0d523ec6822d","banner":null,"lang":"en","date_modified":"2019-04-25","date_modified_ts":"2019-04-25T19:11:45Z","date_created":"2019-04-25T18:56:17Z","summary":null,"body":["<article data-history-node-id=\"1493\" about=\"\/en\/alerts-advisories\/china-chopper-malware-affecting-sharepoint-servers\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-006<\/strong><br \/><strong>Date: 23 April 2019<\/strong><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may only redistribute it within their respective organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Cyber Centre is aware of a campaign that is currently compromising several versions of Microsoft SharePoint Server in order to deploy the China Chopper web shell. Trusted researchers have identified compromised systems belonging to the academic, utility, heavy industry, manufacturing and technology sectors. The following versions of Microsoft SharePoint are known to be affected:<\/p>\n\n<ul><li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Foundation 2013 SP1<\/li>\n\t<li>Microsoft SharePoint Server 2010 SP2<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n<\/ul><p>It is likely that the current campaign is leveraging CVE-2019-0604 in order to deploy the web shell. Microsoft released security updates addressing this vulnerability in February and March 2019; however, many systems remain outdated.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<ul><li>All Microsoft SharePoint Server installations should be patched with the latest security update, dated 12 March 2019, using Microsoft Update, the Microsoft Update Catalog or the Microsoft Download Center.<\/li>\n\t<li>If a SharePoint instance serves strictly as an on-premises solution, ensure that the server has no exposure to the Internet.<\/li>\n<\/ul><h2>Indicators of compromise<\/h2>\n\n<h3>HASH Values<\/h3>\n\n<p>MD5 Hash: b814532d73c7e5ffd1a2533adc6cfcf8<br \/>\nSHA1 Hash: dc8e7b7de41cac9ded920c41b272c885e1aec279<br \/>\nSHA256 Hash: 05108ac3c3d708977f2d679bfa6d2eaf63b371e66428018a68efce4b6a45b4b4<br \/>\nFilename: pay.aspx<\/p>\n\n<p>MD5 Hash: 708544104809ef2776ddc56e04d27ab1<br \/>\nSHA1 Hash: f0fb0f7553390f203669e53abc16b15e729e5c6f<br \/>\nSHA256 Hash: b560c3b9b672f42a005bdeae79eb91dfb0dec8dc04bea51f38731692bc995688<\/p>\n\n<p>MD5 Hash: 0eebeef32a8f676a1717f134f114c8bd<br \/>\nSHA1 Hash: 4c3b262b4134366ad0a67b1a2d6378da428d712b<br \/>\nSHA256 Hash: 7d6812947e7eafa8a4cce84b531f8077f7434dbed4ccdaca64225d1b6a0e8604<br \/>\nFilename: stylecss.aspx<\/p>\n\n<h3>IP Address<\/h3>\n\n<p>114.25.219.100<\/p>\n\n<h2>References<\/h2>\n\n<p>Microsoft advisory: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0604\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0604<\/a><\/p>\n\n<p>ZDI article: <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2019\/3\/13\/cve-2019-0604-details-of-a-microsoft-sharepoint-rce-vulnerability\">https:\/\/www.zerodayinitiative.com\/blog\/2019\/3\/13\/cve-2019-0604-details-of-a-microsoft-sharepoint-rce-vulnerability<\/a><\/p>\n\n<p>Chine Chopper information: <a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/web-shells-china-chopper\">https:\/\/cyber.gc.ca\/en\/guidance\/web-shells-china-chopper<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/china-chopper-malware-affecting-sharepoint-servers","alert_type":397,"serial_number":"AL19-006","subject":null,"moderation_state":"archived","external_url":null},{"nid":1494,"title":"Critical Vulnerabilities in Atlassian Confluence Servers","uuid":"0a5a8393-c571-4019-9c9d-95a9296090c4","banner":null,"lang":"en","date_modified":"2019-04-30","date_modified_ts":"2019-04-30T17:50:05Z","date_created":"2019-04-30T17:47:09Z","summary":null,"body":["<article data-history-node-id=\"1494\" about=\"\/en\/alerts-advisories\/critical-vulnerabilities-atlassian-confluence-servers\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-007<\/strong><br \/><strong>Date: 29 April 2019<\/strong><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers. Recipients of this information may redistribute it with no restrictions.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An ALERT is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this ALERT to recipients as requested.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Cyber Centre is aware of the active exploitation of Atlassian Confluence Servers and Confluence Data Centers in recent weeks. Trusted researchers have identified targeted campaigns against Government Facilities Sectors that leverage multiple vulnerabilities.<\/p>\n\n<p>The exploitations are believed to be leveraging the following known vulnerabilities:<\/p>\n\n<p>CVE-2019-3395: A malicious actor is able to remotely exploit a Server-Side Request Forgery (SSRF) vulnerability in the WebDAV plugin to send arbitrary HTTP and WebDAV requests.<\/p>\n\n<p>CVE-2019-3396: A server-side template injection vulnerability in the Widget Connector Macro allows a malicious actor to remotely execute arbitrary code.<\/p>\n\n<p>CVE-2019-3398: A path traversal vulnerability in the \u201cdownloadallattachments\u201d resource allows a malicious actor with specific permissions to remotely write files to arbitrary locations, which in turn could lead to remote code execution. An authenticated user would require one of the below permissions in order to execute this vulnerability:<\/p>\n\n<ul><li>Add attachments to pages and\/or blogs<\/li>\n\t<li>Create a new space or a personal space<\/li>\n\t<li>\u2018Admin\u2019 privileges for a space<\/li>\n<\/ul><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that Confluence Server and\/or Data Center be patched to one of the below versions or higher:<\/p>\n\n<ul><li>6.6.13<\/li>\n\t<li>6.12.4<\/li>\n\t<li>6.13.4<\/li>\n\t<li>6.14.3<\/li>\n\t<li>6.15.2<\/li>\n<\/ul><p>If it is not possible to patch an instance of Confluence Server, The Cyber Centre recommends that the additional mitigation steps provided by Atlassian, provided below, be taken as soon as possible.<\/p>\n\n<h2>References<\/h2>\n\n<p>Atlassian Security Advisory for CVE-2019-3395 and CVE -2019-3396: <a href=\"https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2019-03-20-966660264.html\">https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2019-03-20-966660264.html<\/a><\/p>\n\n<p>Atlassian Security Advisory for CVE-2019-3398: <a href=\"https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2019-04-17-968660855.html\">https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2019-04-17-968660855.html<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/critical-vulnerabilities-atlassian-confluence-servers","alert_type":397,"serial_number":"AL19-007","subject":null,"moderation_state":"archived","external_url":null},{"nid":1495,"title":"Oracle WebLogic Deserialization RCE Vulnerability","uuid":"c24558d4-1220-45e5-8cd2-22f6a806ae08","banner":null,"lang":"en","date_modified":"2019-05-01","date_modified_ts":"2019-05-01T18:54:14Z","date_created":"2019-05-01T18:48:22Z","summary":null,"body":["<article data-history-node-id=\"1495\" about=\"\/en\/alerts-advisories\/oracle-weblogic-deserialization-rce-vulnerability\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-008<\/strong><br \/><strong>Date: 30 April 2019<\/strong><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This ALERT is intended for IT professionals and managers. Recipients of this information may redistribute it with no restrictions.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An ALERT is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this ALERT to recipients as requested.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>Oracle has released an out-of-band patch to update its WebLogic Server product. The patch addresses a vulnerability (CVE-2019-2725) in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) that allows a remote, unauthenticated malicious actor to run arbitrary commands via HTTP on the server.<\/p>\n\n<p>The vulnerability affects Oracle WebLogic versions 10.3.6 and 12.1.3 and has been observed being actively exploited.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations apply the updates released 26 April 2019, as part of the Oracle Security Alert Advisory regarding CVE-2019-2725 (see References for link).<\/p>\n\n<p>If the updates cannot be immediately applied, firewall rules could be put in place to prevent requests being made to two URL paths exposed by this vulnerability ( \/_async\/* and \/wls-wsat\/*). Alternatively, organizations could choose to remove the vulnerable components (wls9_async_response.war and wls-wsat.war) and restart the WebLogic service.<\/p>\n\n<h2>References<\/h2>\n\n<p>Oracle Security Alert Advisory: <a href=\"https:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2019-2725-5466295.html\">https:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2019-2725-5466295.html<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-weblogic-deserialization-rce-vulnerability","alert_type":397,"serial_number":"AL19-008","subject":null,"moderation_state":"archived","external_url":null},{"nid":1496,"title":"Dell security advisory","uuid":"743b79c9-a4f3-4826-b4d5-666302ba17ff","banner":null,"lang":"en","date_modified":"2019-05-03","date_modified_ts":"2019-05-03T14:10:21Z","date_created":"2019-05-03T14:07:35Z","summary":null,"body":["<article data-history-node-id=\"1496\" about=\"\/en\/alerts-advisories\/dell-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-084<\/strong><br \/><strong>Date: 2 May 2019<\/strong><\/p>\n\n<p>Dell has released security updates to address vulnerabilities affecting its SupportAssist Client software. This software comes preinstalled on most Dell devices that are running the Windows operating system. A remote, unauthenticated malicious actor with local network access could exploit one of these vulnerabilities to remotely run arbitrary executables on an affected device. All versions of the SupportAssist software prior to 3.2.0.90 are affected.<\/p>\n\n<p>CCCS encourages users and administrators to review the Dell Support webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/article\/ca\/en\/cadhs1\/sln316857\/dsa-2019-051-dell-supportassist-client-multiple-vulnerabilities?lang=en\">https:\/\/www.dell.com\/support\/article\/ca\/en\/cadhs1\/sln316857\/dsa-2019-051-dell-supportassist-client-multiple-vulnerabilities?lang=en<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory","alert_type":396,"serial_number":"AV19-084","subject":null,"moderation_state":"archived","external_url":null},{"nid":1497,"title":"Cisco security advisory","uuid":"4d929645-72b7-4f9d-8d81-74aee89e4c1d","banner":null,"lang":"en","date_modified":"2019-05-03","date_modified_ts":"2019-05-03T14:16:27Z","date_created":"2019-05-03T14:13:15Z","summary":null,"body":["<article data-history-node-id=\"1497\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-17\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-085<\/strong><br \/><strong>Date: 2 May 2019<\/strong><\/p>\n\n<p>On 1 May 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products. Of note is a critical vulnerability in the Cisco Nexus 9000 Series switch that could allow a remote, unauthenticated malicious actor to run arbitrary commands on an exposed switch with root privileges due to the presence of a default SSH key pair on the server. The vulnerability is only exploitable with SSH connections over Internet Protocol version 6 (IPv6), as opposed to IPv4.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-17","alert_type":396,"serial_number":"AV19-085","subject":null,"moderation_state":"archived","external_url":null},{"nid":1498,"title":"PrinterLogic security advisory","uuid":"72560e6b-ce06-4f71-86c5-9715d375913a","banner":null,"lang":"en","date_modified":"2019-05-07","date_modified_ts":"2019-05-07T19:09:21Z","date_created":"2019-05-07T19:07:33Z","summary":null,"body":["<article data-history-node-id=\"1498\" about=\"\/en\/alerts-advisories\/printerlogic-security-advisory\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-086<\/strong><br \/><strong>Date: 7 May 2019<\/strong><\/p>\n\n<p>Several vulnerabilities have been found in PrinterLogic\u2019s Print Management software. As a result of these vulnerabilities, the software may fail to validate or may improperly validate the PrinterLogic Management Portal\u2019s SSL certificate. The software may also not sufficiently verify the integrity and source of PrinterLogic updates. An additional vulnerability exists in which the software does not properly sanitize special characters, allowing for code insertion that could result in unauthorized modification to system configuration files. These vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code with SYSTEM privileges.<\/p>\n\n<p>CCCS encourages users and administrators to monitor the PrinterLogic Security Vulnerability Notice for updates as a patch is currently in development:<\/p>\n\n<p><a href=\"https:\/\/www.printerlogic.com\/security-bulletin\/\">https:\/\/www.printerlogic.com\/security-bulletin\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/printerlogic-security-advisory","alert_type":396,"serial_number":"AV19-086","subject":null,"moderation_state":"archived","external_url":null},{"nid":1499,"title":"Cisco security advisory","uuid":"dcc667f0-1d06-489e-b713-ed79fa657b22","banner":null,"lang":"en","date_modified":"2019-05-09","date_modified_ts":"2019-05-09T13:46:18Z","date_created":"2019-05-09T13:44:15Z","summary":null,"body":["<article data-history-node-id=\"1499\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-18\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-087<\/strong><br \/><strong>Date: 8 May 2019<\/strong><\/p>\n\n<p>On 7 May 2019, Cisco released security updates to address a critical vulnerability affecting the Cisco Elastic Services Controller (ESC) product. The vulnerability stems from improper validation of requests made to the product\u2019s REST API, which is a programmatic interface on the server allowing a remote client to query and run commands on the server. A remote, unauthenticated malicious actor could exploit this vulnerability by sending crafted requests to the REST API, which could then be executed on the server with administrative privileges. The vulnerability affects ESC running software release 4.1, 4.2, 4.3, and 4.4 in conjunction with the REST API being enabled. Administrators can run the following command on the ESC to determine if the REST API is enabled:<\/p>\n\n<p><code><strong>sudo netstat -tlnup | grep '8443|8080'<\/strong><\/code><\/p>\n\n<p>Output after running the command indicates that the REST API is enabled.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190507-esc-authbypass\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190507-esc-authbypass<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-18","alert_type":396,"serial_number":"AV19-087","subject":null,"moderation_state":"archived","external_url":null},{"nid":1500,"title":"SQLite security advisory","uuid":"6220feec-cf38-43a5-a2fe-c5fb94846530","banner":null,"lang":"en","date_modified":"2019-05-13","date_modified_ts":"2019-05-13T17:08:30Z","date_created":"2019-05-13T17:06:44Z","summary":null,"body":["<article data-history-node-id=\"1500\" about=\"\/en\/alerts-advisories\/sqlite-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-088<\/strong><br \/><strong>Date: 13 May 2019<\/strong><\/p>\n\n<p>An exploitable Use After Free vulnerability exists in the window function of SQLite versions 3.26.0 and 3.27.0. A maliciously crafted SQL command can cause a Use After Free vulnerability, potentially resulting in remote code execution.<\/p>\n\n<p>Use After Free vulnerabilities refer to attempted memory access after it has recently been freed. This may cause a program to crash, use unexpected values, or execute code.<\/p>\n\n<p>SQLite released a fix for this vulnerability in version 3.28.0.<\/p>\n\n<p>CCCS encourages users and administrators to review the SQLite news page and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sqlite.org\/news.html\">https:\/\/www.sqlite.org\/news.html<\/a><\/li>\n\t<li><a href=\"https:\/\/www.sqlite.org\/download.html\">https:\/\/www.sqlite.org\/download.html<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sqlite-security-advisory","alert_type":396,"serial_number":"AV19-088","subject":null,"moderation_state":"published","external_url":null},{"nid":1501,"title":"NVIDIA security advisory","uuid":"b794b994-339e-48ee-81e7-83f18c2773e1","banner":null,"lang":"en","date_modified":"2019-05-13","date_modified_ts":"2019-05-13T19:01:23Z","date_created":"2019-05-13T18:59:51Z","summary":null,"body":["<article data-history-node-id=\"1501\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-089<\/strong><br \/><strong>Date: 13 May 2019<\/strong><\/p>\n\n<p>NVIDIA has released security updates to address vulnerabilities affecting its NVIDIA GPU Display Driver. These updates address issues that may lead to denial of service, escalation of privileges, code execution, or information disclosure.<\/p>\n\n<p>CCCS encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4797\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4797<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-3","alert_type":396,"serial_number":"AV19-089","subject":null,"moderation_state":"published","external_url":null},{"nid":1503,"title":"WhatsApp security advisory","uuid":"31c128cd-01bd-45c6-a59b-41f7affe7c4e","banner":null,"lang":"en","date_modified":"2019-05-14","date_modified_ts":"2019-05-14T20:49:58Z","date_created":"2019-05-14T20:23:14Z","summary":null,"body":["<article data-history-node-id=\"1503\" about=\"\/en\/alerts-advisories\/whatsapp-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-090<\/strong><br \/><strong>Date: 14 May 2019<\/strong><\/p>\n\n<p>WhatsApp has released a security update to address a vulnerability that could allow a remote actor to install arbitrary software on a user\u2019s mobile device. This vulnerability affects mobile versions of the software and does not affect desktop or browser-based versions. The Cyber Centre encourages users and administrators to update WhatsApp to the latest version:<\/p>\n\n<p><strong>iOS<\/strong><br \/>\nIn App Store &gt; Updates, tap Update next to WhatsApp to update to the latest version of WhatsApp for iOS (2.19.51). If WhatsApp is up to date, the button will say Open instead of Update. To check the version of WhatsApp, within the app go to Settings &gt; Help. Please note that if application auto-updates are enabled, the iOS device will automatically update WhatsApp to the latest version.<\/p>\n\n<p><strong>Android<\/strong><br \/>\nIn Google Play store &gt; My Apps and Games, tap Update next to WhatsApp to update to the latest version of WhatsApp for Android (2.19.134). If WhatsApp is up to date, the button will say Open instead of Update. To check the version of WhatsApp, within the app go to Settings &gt; Help &gt; App Info. Please note that if application auto-updates are enabled, the Android device will automatically update WhatsApp to the latest version.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/whatsapp-security-advisory","alert_type":396,"serial_number":"AV19-090","subject":null,"moderation_state":"published","external_url":null},{"nid":1502,"title":"Cisco security advisory","uuid":"be0c3ba8-f919-49cb-84ca-83d4594709d0","banner":null,"lang":"en","date_modified":"2019-05-14","date_modified_ts":"2019-05-14T20:46:08Z","date_created":"2019-05-14T20:30:57Z","summary":null,"body":["<article data-history-node-id=\"1502\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-091<br \/>\nDate: 14 May 2019<\/strong><\/p>\n\n<p>On 13 May 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products. Of note is a vulnerability in the web user interface of Cisco\u2019s IOS XE software which could allow a remote, authenticated malicious actor to run arbitrary commands with root privileges on the underlying Linux shell.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates: <a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-19","alert_type":396,"serial_number":"AV19-091","subject":null,"moderation_state":"published","external_url":null},{"nid":1505,"title":"Microsoft security advisory","uuid":"b7aca9ee-d99f-46b1-8492-35cc782c08b4","banner":null,"lang":"en","date_modified":"2019-05-14","date_modified_ts":"2019-05-14T21:32:14Z","date_created":"2019-05-14T20:37:19Z","summary":null,"body":["<article data-history-node-id=\"1505\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-092<br \/>\nDate: 14 May 2019<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities affecting some Microsoft products. This includes updates to patch vulnerabilities for which active exploitations have been reported, allowing remote attackers to run arbitrary code on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft May 2019 Security Updates webpage and apply the necessary updates: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/e5989c8b-7046-e911-a98e-000d3a33a34d\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/e5989c8b-7046-e911-a98e-000d3a33a34d<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-1","alert_type":396,"serial_number":"AV19-092","subject":null,"moderation_state":"published","external_url":null},{"nid":1504,"title":"Critical Microsoft Remote Desktop Vulnerability","uuid":"f34929b3-20af-4118-8f48-c1a2960c0ad5","banner":null,"lang":"en","date_modified":"2019-05-14","date_modified_ts":"2019-05-14T21:22:59Z","date_created":"2019-05-14T21:12:49Z","summary":null,"body":["<article data-history-node-id=\"1504\" about=\"\/en\/alerts-advisories\/critical-microsoft-remote-desktop-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-009<br \/>\nDate: 14 May 2019<\/strong><\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently disclosed Remote Code Execution vulnerability in the Microsoft Remote Desktop Services platform.<\/p>\n\n<h2>ASSESSMENT<\/h2>\n\n<p>Microsoft has released patches for a critical vulnerability in Microsoft Remote Desktop Services (RDS). The vulnerability allows a remote, unauthenticated actor to run arbitrary code on some Microsoft operating systems running RDS. This vulnerability is \u2018wormable\u2019, meaning that exploits of this vulnerability could automatically propagate from one vulnerable system to another.<\/p>\n\n<p>The vulnerable operating systems are:<\/p>\n\n<ul><li>Windows 7 for 32-bit Systems Service Pack 1<\/li>\n\t<li>Windows 7 for x64-based Systems Service Pack 1<\/li>\n\t<li>Windows Server 2008 for 32-bit Systems Service Pack 2<\/li>\n\t<li>Windows Server 2008 for 32-bit Systems Service Pack 2<\/li>\n\t<li>Windows Server 2008 for Itanium-Based Systems Service Pack 2<\/li>\n\t<li>Windows Server 2008 for x64-based Systems Service Pack 2<\/li>\n\t<li>Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)<\/li>\n\t<li>Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1<\/li>\n\t<li>Windows Server 2008 R2 for x64-based Systems Service Pack 1<\/li>\n\t<li>Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)<\/li>\n\t<li>Windows XP SP3 x86<\/li>\n\t<li>Windows XP Professional x64 Edition SP2<\/li>\n\t<li>Windows XP Embedded SP3 x86<\/li>\n\t<li>Windows Server 2003 SP2 x86<\/li>\n\t<li>Windows Server 2003 x64 Edition SP2<\/li>\n<\/ul><h2>SUGGESTED ACTION<\/h2>\n\n<ul><li>Install the latest updates for the vulnerable operating systems.<\/li>\n\t<li>Disable Remote Desktop Services if not required. If required, closely monitor network traffic and the logs of any vulnerable systems for suspicious activity.<\/li>\n\t<li>Enable Network Level Authentication (NLA) on systems running Windows 7, Windows Server 2008, and Windows Server 2008 R2. This is a partial mitigation which will prevent the spread of the malware.<\/li>\n\t<li>Block TCP port 3389 on the firewall, if possible. This will prevent unauthorized access from the Internet.<\/li>\n<\/ul><h2>REFERENCES<\/h2>\n\n<p>Microsoft advisory: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0708\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0708<\/a><\/p>\n\n<p>Microsoft advisory for legacy operating systems (Windows XP and Server 2003): <a href=\"https:\/\/support.microsoft.com\/en-ca\/help\/4500705\/customer-guidance-for-cve-2019-0708\">https:\/\/support.microsoft.com\/en-ca\/help\/4500705\/customer-guidance-for-cve-2019-0708<\/a><\/p>\n\n<p>Microsoft blog post: <a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2019\/05\/14\/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708\/\">https:\/\/blogs.technet.microsoft.com\/msrc\/2019\/05\/14\/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708\/<\/a><\/p>\n\n<h2><strong>NOTE TO READERS<\/strong><\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the<br \/>\nCyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information<br \/>\nsharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/critical-microsoft-remote-desktop-vulnerability","alert_type":397,"serial_number":"AL19-009","subject":null,"moderation_state":"published","external_url":null},{"nid":1506,"title":"Intel Security Advisories","uuid":"b24452b2-56f1-4a9d-a692-d0e35bdca979","banner":null,"lang":"en","date_modified":"2019-05-14","date_modified_ts":"2019-05-14T21:34:57Z","date_created":"2019-05-14T21:24:35Z","summary":null,"body":["<article data-history-node-id=\"1506\" about=\"\/en\/alerts-advisories\/intel-security-advisories\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-093<br \/>\nDate: 14 May 2019<\/strong><\/p>\n\n<p>On 14 May 2019, Intel has released security advisories to address vulnerabilities affecting various Intel products.\u00a0 One vulnerability of note is the new class of side channel vulnerabilities impacting all modern Intel chips, which can use speculative execution to potentially leak sensitive data from a system\u2019s CPU.\u00a0 This new vulnerability is known as \u201czombieload\u201d.\u00a0 Successful exploitation may allow an authenticated user to potentially enable sensitive information disclosure.<\/p>\n\n<p>CCCS encourages users and administrators to review the Intel Advisories webpage for the respective products and apply the necessary updates: <a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisories","alert_type":396,"serial_number":"AV19-093","subject":null,"moderation_state":"published","external_url":null},{"nid":1507,"title":"Samba security advisory","uuid":"a4f02915-b1f3-44be-a0a1-707b729d5804","banner":null,"lang":"en","date_modified":"2019-05-15","date_modified_ts":"2019-05-15T17:31:28Z","date_created":"2019-05-15T17:24:37Z","summary":null,"body":["<article data-history-node-id=\"1507\" about=\"\/en\/alerts-advisories\/samba-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-094<\/strong><br \/><strong>Date: 15 May 2019<\/strong><\/p>\n\n<p>The Samba Team has released a security advisory to address a vulnerability in their Samba software. A man-in-the-middle attack could allow for control of the affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Samba Security Releases webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2018-16860.html\">https:\/\/www.samba.org\/samba\/security\/CVE-2018-16860.html<\/a><\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">https:\/\/www.samba.org\/samba\/history\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-advisory-0","alert_type":396,"serial_number":"AV19-094","subject":null,"moderation_state":"published","external_url":null},{"nid":1508,"title":"Siemens Security Advisories","uuid":"6e08ba99-fcea-48ae-95a1-856c4bba6523","banner":null,"lang":"en","date_modified":"2019-05-15","date_modified_ts":"2019-05-15T18:44:58Z","date_created":"2019-05-15T18:43:02Z","summary":null,"body":["<article data-history-node-id=\"1508\" about=\"\/en\/alerts-advisories\/siemens-security-advisories-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-095<\/strong><br \/><strong>Date: 15 May 2019<\/strong><\/p>\n\n<p>On 14 May 2019, Siemens has released security updates to address multiple vulnerabilities affecting some of their industrial control and utility products. An attacker could exploit some of these vulnerabilities to take control of an affected device, expose sensitive data or cause a Denial of Service Attack.<\/p>\n\n<p>CCCS encourages users and administrators to review the Siemens Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublication\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/siemens-security-advisories-1","alert_type":396,"serial_number":"AV19-095","subject":null,"moderation_state":"published","external_url":null},{"nid":1509,"title":"Adobe security advisory","uuid":"61e9c68d-5cfd-47cd-84aa-265f5353836b","banner":null,"lang":"en","date_modified":"2019-05-15","date_modified_ts":"2019-05-15T18:49:07Z","date_created":"2019-05-15T18:47:34Z","summary":null,"body":["<article data-history-node-id=\"1509\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-096<\/strong><br \/><strong>Date: 15 May 2019<\/strong><\/p>\n\n<p>On 14 May 2019, Adobe released security advisories to address vulnerabilities affecting a variety of Adobe products. An attacker could exploit some of these vulnerabilities to execute arbitrary code with the privileges of the current user.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Advisories webpage and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb19-29.html\">https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb19-29.html<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-18.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-18.html<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb19-26.html\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb19-26.html<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-1","alert_type":396,"serial_number":"AV19-096","subject":null,"moderation_state":"published","external_url":null},{"nid":1510,"title":"Citrix security advisory","uuid":"50816cc5-0dec-4ae7-8b1b-82484659c50f","banner":null,"lang":"en","date_modified":"2019-05-15","date_modified_ts":"2019-05-15T18:52:56Z","date_created":"2019-05-15T18:51:13Z","summary":null,"body":["<article data-history-node-id=\"1510\" about=\"\/en\/alerts-advisories\/citrix-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-097<\/strong><br \/><strong>Date: 15 May 2019<\/strong><\/p>\n\n<p>Citrix has released a security bulletin to address a vulnerability in the Citrix Workspace app and Receiver for Windows that could allow for Remote Code Execution on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Citrix Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX251986\">https:\/\/support.citrix.com\/article\/CTX251986<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory","alert_type":396,"serial_number":"AV19-097","subject":null,"moderation_state":"published","external_url":null},{"nid":1511,"title":"Apple security advisory","uuid":"1736a8ca-c4f2-4710-9921-747d8e49a5c9","banner":null,"lang":"en","date_modified":"2019-05-15","date_modified_ts":"2019-05-15T18:57:14Z","date_created":"2019-05-15T18:55:40Z","summary":null,"body":["<article data-history-node-id=\"1511\" about=\"\/en\/alerts-advisories\/apple-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-098<\/strong><br \/><strong>Date: 15 May 2019<\/strong><\/p>\n\n<p>Apple has released security updates to address vulnerabilities affecting some of its products. Software included in this patch cycle are iOS, macOS, watchOS, Safari web browser, and Apple TV. Some of the vulnerabilities could allow for a remote, unauthenticated actor to execute arbitrary code on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-1","alert_type":396,"serial_number":"AV19-098","subject":null,"moderation_state":"published","external_url":null},{"nid":1512,"title":"VMware Security Advisories","uuid":"4f597dfd-450c-4ff7-be60-de1b07ff2dcf","banner":null,"lang":"en","date_modified":"2019-05-15","date_modified_ts":"2019-05-15T19:32:41Z","date_created":"2019-05-15T19:31:17Z","summary":null,"body":["<article data-history-node-id=\"1512\" about=\"\/en\/alerts-advisories\/vmware-security-advisories-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-099<\/strong><br \/><strong>Date: 15 May 2019<\/strong><\/p>\n\n<p>VMware has released security advisories to address vulnerabilities affecting VMware Workstation Pro \/ Player (Workstation) and the Microarchitectural Data Sampling (MDS) vulnerabilities in Intel CPUs addressed in Advisory AV19-093 (Zombieload). Successful exploitation may allow an authenticated user to potentially enable sensitive information disclosure.<\/p>\n\n<p>CCCS encourages users and administrators to review the VMware Advisories webpage for the respective products and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0007.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0007.html<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0008.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0008.html<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisories-2","alert_type":396,"serial_number":"AV19-099","subject":null,"moderation_state":"published","external_url":null},{"nid":1513,"title":"Microsoft recommended block rules","uuid":"f9e5d9c4-f1b1-4227-b9fb-803b234a95c9","banner":null,"lang":"en","date_modified":"2019-05-15","date_modified_ts":"2019-05-15T19:45:01Z","date_created":"2019-05-15T19:35:42Z","summary":null,"body":["<article data-history-node-id=\"1513\" about=\"\/en\/alerts-advisories\/microsoft-recommended-block-rules\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-100<\/strong><br \/><strong>Date: 15 May 2019<\/strong><\/p>\n\n<p>Microsoft recently published a list of applications that an actor could use to bypass or circumvent whitelisting policies, including Windows Defender Application Control. Application whitelisting is a common technique used to prevent execution of unknown or potentially malicious applications.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft recommended block rules webpage and test and apply blocking rules for processes or applications that are not being used:<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-application-control\/microsoft-recommended-block-rules\">https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-application-control\/microsoft-recommended-block-rules<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-recommended-block-rules","alert_type":396,"serial_number":"AV19-100","subject":null,"moderation_state":"published","external_url":null},{"nid":1514,"title":"Drupal security advisory","uuid":"6f099a37-0f22-416e-a27e-12ad210bcb2f","banner":null,"lang":"en","date_modified":"2019-05-16","date_modified_ts":"2019-05-16T20:42:12Z","date_created":"2019-05-16T20:40:54Z","summary":null,"body":["<article data-history-node-id=\"1514\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-101<\/strong><br \/><strong>Date: 16 May 2019<\/strong><\/p>\n\n<p>Drupal has released Core versions 8.7.1 and versions 7.67 to address multiple vulnerabilities affecting the Drupal product. A remote actor could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Drupal Release Webpages and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/SA-CORE-2019-007\">https:\/\/www.drupal.org\/SA-CORE-2019-007<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/project\/drupal\/releases\/8.7.1\">https:\/\/www.drupal.org\/project\/drupal\/releases\/8.7.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/project\/drupal\/releases\/7.67\">https:\/\/www.drupal.org\/project\/drupal\/releases\/7.67<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-3","alert_type":396,"serial_number":"AV19-101","subject":null,"moderation_state":"published","external_url":null},{"nid":1515,"title":"Linux security advisory","uuid":"3a4fb1aa-c692-43b6-8954-e94130078da4","banner":null,"lang":"en","date_modified":"2019-05-16","date_modified_ts":"2019-05-16T20:45:26Z","date_created":"2019-05-16T20:43:56Z","summary":null,"body":["<article data-history-node-id=\"1515\" about=\"\/en\/alerts-advisories\/linux-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-102<\/strong><br \/><strong>Date: 16 May 2019<\/strong><\/p>\n\n<p>On May 15, 2019, FreeBSD, Debian, and Linux Core released security advisories to address multiple Linux Kernel vulnerabilities. A local attacker could exploit these vulnerabilities to take control of an affected system. Please note that other versions of Linux with the same kernel may also be affected.<\/p>\n\n<p>The vulnerabilities are identified by the following CVE\u2019s:<\/p>\n\n<p>CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497, CVE-2019-9498, CVE-2019-9499, CVE-2019-11555, CVE-2019-8936, CVE-2019-5597, CVE-2019-5598, CVE2018-12126, CVE2018-12127, CVE-2018-12130, CVE-2019-11091.<\/p>\n\n<p>CCCS encourages users and administrators to review the following Security Advisory webpages and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.freebsd.org\/security\/advisories.html\">https:\/\/www.freebsd.org\/security\/advisories.html<\/a><\/li>\n\t<li><a href=\"https:\/\/security-tracker.debian.org\/tracker\/source-package\/intel-microcode\">https:\/\/security-tracker.debian.org\/tracker\/source-package\/intel-microcode<\/a><\/li>\n\t<li><a href=\"https:\/\/www.kernel.org\/doc\/html\/latest\/admin-guide\/hw-vuln\/mds.html\">https:\/\/www.kernel.org\/doc\/html\/latest\/admin-guide\/hw-vuln\/mds.html<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-security-advisory","alert_type":396,"serial_number":"AV19-102","subject":null,"moderation_state":"published","external_url":null},{"nid":1516,"title":"Schneider security advisory","uuid":"0e62ed97-8e24-43b5-854d-b82b97ed50d3","banner":null,"lang":"en","date_modified":"2019-05-17","date_modified_ts":"2019-05-17T17:32:07Z","date_created":"2019-05-17T17:30:42Z","summary":null,"body":["<article data-history-node-id=\"1516\" about=\"\/en\/alerts-advisories\/schneider-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-103<\/strong><br \/><strong>Date: 17 May 2019<\/strong><\/p>\n\n<p>On 14 May 2019, Schneider has released security updates to address multiple vulnerabilities affecting some of their industrial control and utility products. The following products are affected:<\/p>\n\n<ul><li>Modicon M580 firmware versions prior to Version 2.30<\/li>\n\t<li>Modicon M340 firmware, all versions<\/li>\n\t<li>Modicon Premium, all firmware versions<\/li>\n\t<li>Modicon Quantum, all firmware versions<\/li>\n<\/ul><p>An actor could exploit some of these vulnerabilities to hijack TCP connections or cause information leakage.<\/p>\n\n<p>CCCS encourages users and administrators to review the Schneider Security Advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.schneider-electric.com\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.schneider-electric.com\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/schneider-security-advisory","alert_type":396,"serial_number":"AV19-103","subject":null,"moderation_state":"published","external_url":null},{"nid":1517,"title":"Cisco security advisory","uuid":"bdf25d74-c9ba-45b2-85ae-5ca94dbfcf50","banner":null,"lang":"en","date_modified":"2019-05-17","date_modified_ts":"2019-05-17T17:36:06Z","date_created":"2019-05-17T17:34:46Z","summary":null,"body":["<article data-history-node-id=\"1517\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-104<\/strong><br \/><strong>Date: 17 May 2019<\/strong><\/p>\n\n<p>On 15 May 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-20","alert_type":396,"serial_number":"AV19-104","subject":null,"moderation_state":"published","external_url":null},{"nid":1518,"title":"Mozilla security advisory","uuid":"654a2d0d-37d8-4293-a23f-a6ca980434c3","banner":null,"lang":"en","date_modified":"2019-05-22","date_modified_ts":"2019-05-22T17:16:40Z","date_created":"2019-05-22T17:14:39Z","summary":null,"body":["<article data-history-node-id=\"1518\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-105<\/strong><br \/><strong>Date: 22 May 2019<\/strong><\/p>\n\n<p>On 21 May 2019, Mozilla has released security updates to address vulnerabilities in Firefox and Firefox ESR. Some of the vulnerabilities could allow a remote, unauthenticated actor to execute arbitrary code on an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\">https:\/\/www.mozilla.org\/en-US\/security\/advisories<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-1","alert_type":396,"serial_number":"AV19-105","subject":null,"moderation_state":"published","external_url":null},{"nid":1519,"title":"Microsoft Zero Day Proof of Concept Code Advisory","uuid":"4733d3aa-0225-454d-af03-1be48d0ce78e","banner":null,"lang":"en","date_modified":"2019-05-27","date_modified_ts":"2019-05-27T14:38:55Z","date_created":"2019-05-27T14:36:40Z","summary":null,"body":["<article data-history-node-id=\"1519\" about=\"\/en\/alerts-advisories\/microsoft-zero-day-proof-concept-code-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-106<\/strong><br \/><strong>Date: 27 May 2019<\/strong><\/p>\n\n<p>The Cyber Centre is aware of recently published Proof of Concepts that expose four new Zero Day vulnerabilities affecting Microsoft Windows (Primarily Windows 10 and Windows Server 2016\/2019). The exploitability of these vulnerabilities vary in complexity, though all would require authenticated access to the target system in order to be successful. Nevertheless, a malicious actor could use these as part of an exploitation chain to escalate their privileges after gaining low-privileged access to a system. The four vulnerabilities, along with names they have been given in GitHub and a brief description, are:<\/p>\n\n<ol><li>Microsoft Windows Task Scheduler Privilege Escalation Vulnerability (bearlpe): A vulnerability in Microsoft Windows Task Scheduler has been found to allow a low-privileged user to arbitrarily modify files that they do not have authorization to access, including SYSTEM level files<\/li>\n\t<li>Internet Explorer 11 Sandbox Escape Vulnerability (sandboxescape): The Internet Explorer 11 vulnerability can be exploited, via .dll injection, to allow for code execution (at the medium integrity access level) via the Internet Explorer process.<\/li>\n\t<li>CVE-2019-0841-Bypass: CVE-2019-0841, a Windows AppX Deployment Services privilege escalation vulnerability, was previously patched by Microsoft in May 2019. This Proof of Concept bypasses the patch.<\/li>\n\t<li>Windows Installer Bypass (InstallerBypass): The Windows Installer process can be exploited to write files to unauthorized areas by taking advantage of a particular race condition. This Proof of Concept requires user interaction at a precise moment during the installation process, indicating that the vulnerability is difficult to successfully exploit.<\/li>\n<\/ol><p>Microsoft has not yet announced security updates for these vulnerabilities. CCCS advises that security updates be applied once they are available.<\/p>\n\n<p>A fifth Zero Day Proof of Concept code vulnerability (angrypolarbearbug2) was later determined to have been already fixed as part of the May 2019 Patch Tuesday security updates (CVE-2019-0863).<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-zero-day-proof-concept-code-advisory","alert_type":396,"serial_number":"AV19-106","subject":null,"moderation_state":"published","external_url":null},{"nid":1521,"title":"Active Exploitation of the Telerik UI for ASP.NET AJAX","uuid":"4b4a9cf0-f91d-4c34-bc6a-d6231bba6930","banner":null,"lang":"en","date_modified":"2019-06-06","date_modified_ts":"2019-06-06T19:14:12Z","date_created":"2019-05-30T19:37:19Z","summary":null,"body":["<article data-history-node-id=\"1521\" about=\"\/en\/alerts-advisories\/active-exploitation-telerik-ui-aspnet-ajax\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-010<\/strong><br \/><strong>Date: 29 May 2019<\/strong><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Cyber Centre is currently aware of publicly available exploits being leveraged against websites that use the Telerik UI for ASP.NET AJAX. The Telerik UI is used to add User Interface elements to websites and web applications. The vulnerability is the result of a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to the disclosure of encryption keys. The successful exploitation of this vulnerability could result in cross-site-scripting (XSS) compromises, the leak of cryptographic MachineKeys, the compromise of the ASP.NET ViewState, and could allow arbitrary file uploads and downloads. This vulnerability can be referenced by CVE-2017-9248, CVE-2017-11317, and CVE-2017-11357. The vulnerable versions of Telerik UI for ASP.NET AJAX are any versions published between 2007 and 2017. Telerik has issued a patch to address this vulnerability.<\/p>\n\n<p>It should be noted that Telerik is sometimes installed as a third party component and thus it may be present unbeknownst to the administrator. Administrators may need to manually check for the presence of this .dll, as outlined in the suggested actions below.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<ul><li>Identify devices with Telerik installed. As the vulnerability is specific to the Telerik.Web.UI.dll file, searching for this file in the web application root directory can be helpful in determining whether Telerik is being used and, if so, what version. The Australian Cyber Security Centre has provided a sample PowerShell script (see APPENDIX A) that may prove useful in determining the existence of vulnerable Telerik.Web.UI.dll files within a given directory.<\/li>\n\t<li>An alternative or complement to the suggested action above is to scrutinize web server and\/or web application logs for Telerik resources being requested. Specifically, the following resources are requested through HTTP GET and POST requests when using the publically available exploitation technique: Telerik.Web.UI.DialogHandler.aspx and Telerik.Web.UI.WebResource.axd.<\/li>\n\t<li>Once devices with Telerik installed have been identified, system administrators are encouraged to review the following Telerik Knowledgebase Article and apply the necessary updates, including generating new encryption keys for the UI and MachineKey: <a href=\"https:\/\/www.telerik.com\/support\/kb\/aspnet-ajax\/details\/cryptographic-weakness\">https:\/\/www.telerik.com\/support\/kb\/aspnet-ajax\/details\/cryptographic-weakness<\/a><\/li>\n<\/ul><h2>Appendix A - PowerShell script to locate Telerik.Web.UI.dll files<\/h2>\n\n<pre>\n[CmdletBinding()]\nparam(\n[Parameter(Mandatory=$true)]\n[String]$searchDir\n)\n# Vulnerable versions listed in Burp Suite extension Telewreck.py\n# Available at https:\/\/github.com\/capt-meelo\/Telewreck\/blob\/master\/telewreck.py\n$VULN_VERSIONS = @(\n'2007.1423', '2007.1521', '2007.1626', '2007.2918', '2007.21010', '2007.21107', '2007.31218', '2007.31314', '2007.31425',\n'2008.1415', '2008.1515', '2008.1619', '2008.2723', '2008.2826',\n'2008.21001', '2008.31105', '2008.31125', '2008.31314',\n'2009.1311', '2009.1402', '2009.1527', '2009.2701', '2009.2826', '2009.31103', '2009.31208', '2009.31314',\n'2010.1309', '2010.1415', '2010.1519', '2010.2713', '2010.2826',\n'2010.2929', '2010.31109', '2010.31215', '2010.31317',\n'2011.1315', '2011.1413', '2011.1519', '2011.2712', '2011.2915', '2011.31115', '2011.3.1305',\n'2012.1.215', '2012.1.411', '2012.2.607', '2012.2.724', '2012.2.912',\n'2012.3.1016', '2012.3.1205', '2012.3.1308',\n'2013.1.220', '2013.1.403', '2013.1.417', '2013.2.611', '2013.2.717',\n'2013.3.1015', '2013.3.1114', '2013.3.1324',\n'2014.1.225', '2014.1.403', '2014.2.618', '2014.2.724', '2014.3.1024',\n'2015.1.204', '2015.1.225', '2015.1.401', '2015.2.604', '2015.2.623',\n'2015.2.729', '2015.2.826', '2015.3.930', '2015.3.1111',\n'2016.1.113', '2016.1.225', '2016.2.504', '2016.2.607', '2016.3.914',\n'2016.3.1018', '2016.3.1027',\n'2017.1.118', '2017.1.228', '2017.2.503', '2017.2.621', '2017.2.711',\n'2017.3.913'\n)\nGet-ChildItem -Path $searchDir -Filter Telerik.Web.UI.dll -Recurse -ErrorAction SilentlyContinue -Force | foreach-object {\n# In ACSC samples of the Telerik.Web.UI.dll the version number is 4 \"octets\" (e.g. '2014.2.724.45'), PowerShell reports this as \"Major\".\"Minor\".\"Build\".\"Revision\".\n# Telewreck crafts requests using version numbers between 2 and 3 octets long, it is assumed that all revisions are vulnerable.\nif ($_.VersionInfo.FileMajorPart -lt 2012) {\n$SimplifiedFileVersion = ($_.VersionInfo.FileVersion | Select-String -Pattern \"\\d{4}\\.\\d{4,5}\").Matches.Value\n} else {\n$SimplifiedFileVersion = ($_.VersionInfo.FileVersion | Select-String -Pattern \"\\d{4}\\.\\d{1}\\.\\d{3,4}\").Matches.Value\n}\nif ($VULN_VERSIONS -contains $SimplifiedFileVersion) {\nWrite-Host -ForegroundColor Red \"Vulnerable Telerik.Web.UI.dll identified at '$($_.FullName)'. Version number $($_.VersionInfo.FileVersion)' matches version '$($SimplifiedFileVersion)' in Telewreck.\"\n} else {\nif ($_.VersionInfo.FileMajorPart -lt 2018) {\nWrite-Host -ForegroundColor Yellow \"Potentially vulnerable Telerik.Web.UI.dll identified at '$($_.FullName)'. Version number '$($_.VersionInfo.FileVersion)' is not included in the Telewreck \nvulnerable versions, but falls within timeframe of vulnerable versions.\"\n} else {\nWrite-Host -ForegroundColor Green \"Telerik.Web.UI.dll identified at '$($_.FullName)'. Version number '$($_.VersionInfo.FileVersion)' is not included in the Telewreck vulnerable versions and falls outside of the vulnerability timeframes.\"\n}\n}\n}\n<\/pre>\n\n<h2>References<\/h2>\n\n<p>Telerik Security Alert: <a href=\"https:\/\/www.telerik.com\/blogs\/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinity\">https:\/\/www.telerik.com\/blogs\/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinity<\/a><\/p>\n\n<p>Australian Cyber Security Centre Advisory 2019-126: <a href=\"https:\/\/www.cyber.gov.au\/publications\/Advisory-2019-126\">https:\/\/www.cyber.gov.au\/publications\/Advisory-2019-126<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-telerik-ui-aspnet-ajax","alert_type":397,"serial_number":"AL19-010","subject":null,"moderation_state":"published","external_url":null},{"nid":1520,"title":"Active Spam Campaigns Leveraging EMOTET Malware","uuid":"51a6358e-3a60-4f59-8fd6-f5533cca9c78","banner":null,"lang":"en","date_modified":"2019-06-06","date_modified_ts":"2019-06-06T19:08:32Z","date_created":"2019-06-05T17:38:32Z","summary":null,"body":["<article data-history-node-id=\"1520\" about=\"\/en\/alerts-advisories\/active-spam-campaigns-leveraging-emotet-malware\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-011<\/strong><br \/><strong>Date: 4 June 2019<\/strong><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Cyber Centre is aware of an ongoing email phishing campaign affecting Canadians and Canadian Industry that is leveraging the EMOTET malware. EMOTET is an advanced botnet that has infected hundreds of thousands of systems worldwide. Once a system is infected by EMOTET, additional malware may be implanted on the system, or data may be exfiltrated.<\/p>\n\n<p>Emotet phishing emails are particularly effective because they appear to come from a trusted source, often from someone with whom the email recipient has recently been in communication with. The subject and body of the email may appear to be a continuation from a previous authentic email conversation that had occurred between the sender and recipient. This creates a very convincing communication that the recipient believes to be trustworthy, leading the recipient to open the malware by opening a macro-enabled Microsoft Word document, PDF, or by clicking a malicious download link. Once the recipient has been infected, Emotet may exfiltrate e-mail messages from that system which may then be used to craft targeted phishing e-mails for existing e-mail contacts, thereby propagating the malware further and expanding the botnet. EMOTET has been seen harvesting email conversations from infected accounts since late 2018.<\/p>\n\n<p>In addition to email, EMOTET can spread laterally through the network by brute force cracking passwords. This activity will result in a large number of failed login attempts and account lockouts.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<ul><li>Always exercise caution when receiving an unexpected email or email reply containing an attachment or URL, even when from a trusted source. If the email seems unusual, contact the sender to confirm the authenticity of the attachment<\/li>\n\t<li>Avoid enabling macros within a document received via email<\/li>\n\t<li>Follow the Cyber Centre\u2019s guidance to stay CyberSafe<\/li>\n<\/ul><h2>References<\/h2>\n\n<p>US-CERT EMOTET Alert: <a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA18-201A\">https:\/\/www.us-cert.gov\/ncas\/alerts\/TA18-201A<\/a><\/p>\n\n<p>Open Source: <a href=\"https:\/\/www.zdnet.com\/article\/emotet-hijacks-email-conversation-threads-to-insert-links-to-malware\/\">https:\/\/www.zdnet.com\/article\/emotet-hijacks-email-conversation-threads-to-insert-links-to-malware\/<\/a><\/p>\n\n<p>Five Practical Ways to Make Yourself CyberSafe: <a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/five-practical-ways-make-yourself-cybersafe\">https:\/\/cyber.gc.ca\/en\/guidance\/five-practical-ways-make-yourself-cybersafe<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-spam-campaigns-leveraging-emotet-malware","alert_type":397,"serial_number":"AL19-011","subject":null,"moderation_state":"published","external_url":null},{"nid":1522,"title":"Google Chrome security advisory","uuid":"06b9ecd2-2413-4b8a-b76f-924293ef3ff2","banner":null,"lang":"en","date_modified":"2019-06-10","date_modified_ts":"2019-06-10T14:33:27Z","date_created":"2019-06-10T14:32:08Z","summary":null,"body":["<article data-history-node-id=\"1522\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-107<\/strong><br \/><strong>Date: 7 June 2019<\/strong><\/p>\n\n<p>On 4 June 2019 Google released security updates to address vulnerabilities affecting its Chrome browser. A remote actor could exploit some of these vulnerabilities to run arbitrary commands on the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/06\/\">https:\/\/chromereleases.googleblog.com\/2019\/06\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-1","alert_type":396,"serial_number":"AV19-107","subject":null,"moderation_state":"published","external_url":null},{"nid":1523,"title":"Android security advisory","uuid":"f34a9fe1-278c-4a88-aa05-7304ac71b03c","banner":null,"lang":"en","date_modified":"2019-06-10","date_modified_ts":"2019-06-10T14:36:22Z","date_created":"2019-06-10T14:35:07Z","summary":null,"body":["<article data-history-node-id=\"1523\" about=\"\/en\/alerts-advisories\/android-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-108<\/strong><br \/><strong>Date: 7 June 2019<\/strong><\/p>\n\n<p>Google has released security updates to address multiple vulnerabilities affecting Android devices. A remote actor could exploit some of these vulnerabilities to take control of an affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Android security bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-06-01.html\">https:\/\/source.android.com\/security\/bulletin\/2019-06-01.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-1","alert_type":396,"serial_number":"AV19-108","subject":null,"moderation_state":"published","external_url":null},{"nid":1524,"title":"EXIM security advisory","uuid":"9a22d8b8-5e3f-46b0-869b-6ec129f2150d","banner":null,"lang":"en","date_modified":"2019-06-10","date_modified_ts":"2019-06-10T14:39:36Z","date_created":"2019-06-10T14:38:11Z","summary":null,"body":["<article data-history-node-id=\"1524\" about=\"\/en\/alerts-advisories\/exim-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-109<\/strong><br \/><strong>Date: 7 June 2019<\/strong><\/p>\n\n<p>EXIM has released a security advisory to address a critical remote command execution vulnerability affecting versions 4.87 to 4.91 (inclusive) of its Mail Transfer Agent.<\/p>\n\n<p>CCCS encourages users and administrators to review the EXIM Security Advisory and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.exim.org\/static\/doc\/security\/CVE-2019-10149.txt\">https:\/\/www.exim.org\/static\/doc\/security\/CVE-2019-10149.txt<\/a><\/li>\n\t<li><a href=\"https:\/\/www.exim.org\/\">https:\/\/www.exim.org\/<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-0","alert_type":396,"serial_number":"AV19-109","subject":null,"moderation_state":"published","external_url":null},{"nid":1525,"title":"Cisco security advisory","uuid":"45fb4cae-0269-409a-bea3-42edd7e97740","banner":null,"lang":"en","date_modified":"2019-06-10","date_modified_ts":"2019-06-10T14:42:52Z","date_created":"2019-06-10T14:41:21Z","summary":null,"body":["<article data-history-node-id=\"1525\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-110<\/strong><br \/><strong>Date: 7 June 2019<\/strong><\/p>\n\n<p>On 5 June 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-21","alert_type":396,"serial_number":"AV19-110","subject":null,"moderation_state":"published","external_url":null},{"nid":1526,"title":"VMware security bulletin","uuid":"31dd1ea5-b301-4783-8f8c-0c64b9379a1c","banner":null,"lang":"en","date_modified":"2019-06-10","date_modified_ts":"2019-06-10T14:46:15Z","date_created":"2019-06-10T14:44:54Z","summary":null,"body":["<article data-history-node-id=\"1526\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-111<\/strong><br \/><strong>Date: 7 June 2019<\/strong><\/p>\n\n<p>VMware released security updates to address vulnerabilities affecting VMware Tools 10 and VMware Workstation 15.<\/p>\n\n<p>CCCS encourages users to review the latest VMware Security Advisories webpage for details about the vulnerabilities and apply the appropriate patches:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0009.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0009.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin-5","alert_type":396,"serial_number":"AV19-111","subject":null,"moderation_state":"published","external_url":null},{"nid":1527,"title":"Intel security advisory","uuid":"65636877-c7e5-48a1-91be-69c1213cda1b","banner":null,"lang":"en","date_modified":"2019-06-11","date_modified_ts":"2019-06-11T20:28:24Z","date_created":"2019-06-11T20:26:10Z","summary":null,"body":["<article data-history-node-id=\"1527\" about=\"\/en\/alerts-advisories\/intel-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-112<\/strong><br \/><strong>Date: 11 June 2019<\/strong><\/p>\n\n<p>Intel has released security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Intel RAID Web Console 3 (RWC3) for Windows<\/li>\n\t<li>Intel NUC system firmware<\/li>\n\t<li>Intel Accelerated Storage Manager in Intel Rapid Storage Technology Enterprise<\/li>\n<\/ul><p>These vulnerabilities could result in escalation of privilege, denial of service, or information disclosure. Noteworthy disclosures include:<\/p>\n\n<ul><li>Insufficient session validation in the service API for Intel RWC3 version 4.186 and before may allow an unauthenticated user to potentially enable escalation of privilege via network access.<\/li>\n\t<li>Buffer overflow in system firmware for Intel NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and\/or information disclosure via local access.<\/li>\n\t<li>Insufficient input validation in system firmware for Intel NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and\/or information disclosure via local access.<\/li>\n<\/ul><p>CCCS encourages users and administrators to review the Intel Product Security Center Advisories and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00259.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00259.html<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00264.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00264.html<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00226.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00226.html<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-2","alert_type":396,"serial_number":"AV19-112","subject":null,"moderation_state":"published","external_url":null},{"nid":1528,"title":"Vim and Neovim security advisory","uuid":"93c683fd-d8a0-408f-8c1a-9b7d48e00c31","banner":null,"lang":"en","date_modified":"2019-06-12","date_modified_ts":"2019-06-12T19:30:53Z","date_created":"2019-06-12T19:29:36Z","summary":null,"body":["<article data-history-node-id=\"1528\" about=\"\/en\/alerts-advisories\/vim-and-neovim-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-113<\/strong><br \/><strong>Date: 12 June 2019<\/strong><\/p>\n\n<p>Two Linux command-line text editors are vulnerable to arbitrary code execution via a specially crafted file. Vim versions before 8.1.1365 and Neovim versions before 0.3.6 contain the vulnerable code.<\/p>\n\n<p>CCCS encourages users and administrators to apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/vim\/vim\/releases\/tag\/v8.1.1365\">https:\/\/github.com\/vim\/vim\/releases\/tag\/v8.1.1365<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/neovim\/neovim\/releases\/tag\/v0.3.6\">https:\/\/github.com\/neovim\/neovim\/releases\/tag\/v0.3.6<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vim-and-neovim-security-advisory","alert_type":396,"serial_number":"AV19-113","subject":null,"moderation_state":"published","external_url":null},{"nid":1529,"title":"Adobe security advisory","uuid":"89c40e6a-59a4-4523-bad9-b6bae5cbde40","banner":null,"lang":"en","date_modified":"2019-06-12","date_modified_ts":"2019-06-12T20:02:06Z","date_created":"2019-06-12T20:00:54Z","summary":null,"body":["<article data-history-node-id=\"1529\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-114<\/strong><br \/><strong>Date: 12 June 2019<\/strong><\/p>\n\n<p>Adobe has released security updates to address vulnerabilities affecting some of its products. A remote actor could exploit some of these vulnerabilities to run arbitrary code on an affected system. Of note are security updates for Adobe ColdFusion 11, 2016, and 2018. In addition, Adobe has released updates for Flash Player.<\/p>\n\n<p>CCCS encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-2","alert_type":396,"serial_number":"AV19-114","subject":null,"moderation_state":"published","external_url":null},{"nid":1530,"title":"Microsoft security advisory","uuid":"0072c4d6-cfec-40b5-b968-905e8c017beb","banner":null,"lang":"en","date_modified":"2019-06-12","date_modified_ts":"2019-06-12T20:07:20Z","date_created":"2019-06-12T20:03:46Z","summary":null,"body":["<article data-history-node-id=\"1530\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-115<\/strong><br \/><strong>Date: 12 June 2019<\/strong><\/p>\n\n<p>Microsoft has released security updates to address multiple vulnerabilities, including 21 critical vulnerabilities, affecting some Microsoft products. Of note are two vulnerabilities in Microsoft\u2019s NT LAN Manager (NTLM) authentication protocol that affect all versions of Windows. In the first vulnerability, researchers were able to bypass several security features of the protocol to allow an actor to relay NTLM authentication requests to any computer on the domain, allowing for remote code execution in the context of the signed NTLM session. This flaw could prove to be especially dangerous if the actor were able to relay the authentication of a privileged user. The second vulnerability allows an actor to relay NTLM messages to secure web (TLS) sessions. An actor could leverage this flaw to authenticate to online Microsoft services such as Outlook Web Access, in the context of the relayed NTLM session.<\/p>\n\n<p>CCCS encourages users and administrators to review the Microsoft June 2019 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/253dc509-9a5b-e911-a98e-000d3a33c573\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/253dc509-9a5b-e911-a98e-000d3a33c573<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-2","alert_type":396,"serial_number":"AV19-115","subject":null,"moderation_state":"published","external_url":null},{"nid":1531,"title":"Becton Dickinson (BD) Security Advisories","uuid":"f842c0e0-e9da-49b4-b404-56c6c863029b","banner":null,"lang":"en","date_modified":"2019-06-14","date_modified_ts":"2019-06-14T13:50:57Z","date_created":"2019-06-14T13:49:14Z","summary":null,"body":["<article data-history-node-id=\"1531\" about=\"\/en\/alerts-advisories\/becton-dickinson-bd-security-advisories\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-116<\/strong><br \/><strong>Date: 14 June 2019<\/strong><\/p>\n\n<p>On 13 June 2019 BD released security updates to address multiple vulnerabilities affecting the Alaris Gateway Workstation infusion pump products. An actor could adjust specific commands on the pump \u2014 including the infusion rate \u2014 on certain versions of the device by installing modified firmware. Additionally, the infusion pump could be disabled completely.<\/p>\n\n<p>CCCS encourages users and administrators to review the BD Product Security Bulletins and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.bd.com\/en-us\/support\/product-security-and-privacy\/product-security-bulletins\/alaris-gateway-workstation-unauthorized-firmware\">https:\/\/www.bd.com\/en-us\/support\/product-security-and-privacy\/product-security-bulletins\/alaris-gateway-workstation-unauthorized-firmware<\/a><\/li>\n\t<li><a href=\"https:\/\/www.bd.com\/en-us\/support\/product-security-and-privacy\/product-security-bulletins\/alaris-gateway-workstation-web-browser-user-interface-lack-of-authentication-\">https:\/\/www.bd.com\/en-us\/support\/product-security-and-privacy\/product-security-bulletins\/alaris-gateway-workstation-web-browser-user-interface-lack-of-authentication-<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/becton-dickinson-bd-security-advisories","alert_type":396,"serial_number":"AV19-116","subject":null,"moderation_state":"published","external_url":null},{"nid":1532,"title":"Mozilla Thunderbird security advisory","uuid":"f13f2d58-4aee-46e6-ab59-98f1e07049f3","banner":null,"lang":"en","date_modified":"2019-06-14","date_modified_ts":"2019-06-14T19:42:01Z","date_created":"2019-06-14T19:40:46Z","summary":null,"body":["<article data-history-node-id=\"1532\" about=\"\/en\/alerts-advisories\/mozilla-thunderbird-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-117<\/strong><br \/><strong>Date: 14 June 2019<\/strong><\/p>\n\n<p>Mozilla has released Thunderbird 60.7.1 which addresses a number of buffer overflow vulnerabilities that may allow an actor to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisory 2019-17 and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-17\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-17\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-thunderbird-security-advisory","alert_type":396,"serial_number":"AV19-117","subject":null,"moderation_state":"published","external_url":null},{"nid":1533,"title":"Google Chrome security advisory","uuid":"479e72b0-2863-4b7a-8fc5-5093e383209f","banner":null,"lang":"en","date_modified":"2019-06-14","date_modified_ts":"2019-06-14T19:44:40Z","date_created":"2019-06-14T19:43:37Z","summary":null,"body":["<article data-history-node-id=\"1533\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-118<\/strong><br \/><strong>Date: 14 June 2019<\/strong><\/p>\n\n<p>Google has announced Chrome 75.0.3770.90 for Windows, Mac, and Linux. This version addresses a remote use-after-free vulnerability that may allow an actor to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Chrome Releases webpage and apply the necessary update when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/06\/stable-channel-update-for-desktop_13.html\">https:\/\/chromereleases.googleblog.com\/2019\/06\/stable-channel-update-for-desktop_13.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-2","alert_type":396,"serial_number":"AV19-118","subject":null,"moderation_state":"published","external_url":null},{"nid":1534,"title":"Active exploitation of EXIM vulnerability observed in the wild","uuid":"f28b1b01-dcf9-4bb6-9ab0-04f55e16ae2d","banner":null,"lang":"en","date_modified":"2019-06-14","date_modified_ts":"2019-06-14T20:48:45Z","date_created":"2019-06-14T20:46:23Z","summary":null,"body":["<article data-history-node-id=\"1534\" about=\"\/en\/alerts-advisories\/active-exploitation-exim-vulnerability-observed-wild\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-012<\/strong><br \/><strong>Date: 14 June 2019<\/strong><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The Cyber Centre is aware of active exploitation of the EXIM vulnerability highlighted in Advisory AV19-109 published on 7 June 2019. There appears to be a \u201cwormable\u201d component which would spread this exploit to other vulnerable EXIM instances.<\/p>\n\n<p>There are two waves of exploitations. In the first wave, a remote actor will send malicious emails to a vulnerable Exim server which, in turn, allows them to run malicious code under the Exim process' access level (in most instances this is \u2018root\u2019). This will download additional malware from a Command and Control server owned by the actor.<\/p>\n\n<p>In the second wave, the actor will create a cron job to maintain persistence and download other components of the exploit chain. One of these components is a python script which actively searches for other vulnerable instances of EXIM server on the internet, connects to them and exploits the vulnerability on those targets (this is the wormable portion).<\/p>\n\n<p>Additionally, the actor adds an RSA authentication key to the SSH server which allows them to connect to the server as root. To help evade detection, the actor uses TOR nodes to deliver the malicious code and connect over SSH.<\/p>\n\n<h2>Analytic comment<\/h2>\n\n<p>The Cyber Centre notes that the EXIM exploitations are evolving over time and that the type of malware and scripts which are downloaded are not consistent amongst exploitations. This may indicate that the actor is still experimenting with the exploitation chain, and that their final goal is not known, or it may indicate that multiple actors are making use of similar exploitations for different purposes.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<ul><li>Patch the vulnerable version of EXIM to the latest supported version.<\/li>\n\t<li>Examine logs for unusual or unauthorized activity.<\/li>\n\t<li>Examine all cron jobs for any unauthorized entries and remove these if detected.<\/li>\n\t<li>Examine locally installed RSA authentication keys to the SSH server for any unauthorised keys.<\/li>\n\t<li>Monitor for any unusual SSH connections to the Exim server, specially from unknown IP addresses.<\/li>\n<\/ul><h2>References<\/h2>\n\n<p>EXIM CCCS Advisory on Exim vulnerability: <a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/exim-security-advisory-0\">https:\/\/www.cyber.gc.ca\/en\/alerts\/exim-security-advisory-0<\/a><\/p>\n\n<h2>Indicators of compromise<\/h2>\n\n<h3>HASH Values<\/h3>\n\n<p>Filename: certificate.crt<br \/>\nMD5 Hash: certificate.crt|ff534af3104bc9a2030c9599bcd9a4b5<br \/>\nSHA1 Hash: certificate.crt|d135675da359304f60e3711f1993f36f267e1800<br \/>\nSHA256 Hash: certificate.crt|3a9459472329585e384a7e32af277844468d5b1fccda6d80285549f92ee67f07<\/p>\n\n<p>Filename: se<br \/>\nMD5 Hash: se|a6823231d6bc5e7afda3c6e10f855956<br \/>\nSHA1 Hash: se|5797fe2ea08e627478777f2ede28bda2780707cf<br \/>\nSHA256 Hash: se|d8a787dc774748bf26e3dce1b079e9bef071c0327b6adcd8cc71ed956365201c<\/p>\n\n<p>Filename: se<br \/>\nMD5 Hash: se|03fb0990ef6a33cc863d0c1a4568689c<br \/>\nSHA1 Hash: se|f8c6ae6fa828ccdc97d79c541c5e1b3d65d6653b<br \/>\nSHA256 Hash: se|b4bae03ab71439208b79edfc5eaec42babacee982231dce001b70ec42835063a<\/p>\n\n<p>Filename: atd<br \/>\nMD5 Hash: atd|a6823231d6bc5e7afda3c6e10f855956<br \/>\nSHA1 Hash: atd|5797fe2ea08e627478777f2ede28bda2780707cf<br \/>\nSHA256 Hash: atd|d8a787dc774748bf26e3dce1b079e9bef071c0327b6adcd8cc71ed956365201c<\/p>\n\n<p>Filename: s<br \/>\nMD5 Hash: s|8c7efb0493b6fb805b2c2f0593de0ab1<br \/>\nSHA1 Hash: s|d754163b369e4c27330cef03d6736779a699e5d9<br \/>\nSHA256 Hash: s|1c8f184c3cf902bafc9df23b13a5d51cf801026bc3bde9d6b05cf047523ac6ed<\/p>\n\n<h3>IP Indicator(s)<\/h3>\n\n<p>85[.]25[.]84[.]99<br \/>\n173[.]212[.]214[.]137<\/p>\n\n<h3>URL Indicator(s)<\/h3>\n\n<p>hxxps:\/\/85[.]25[.]84[.]99\/up[.]php<br \/>\nhxxp:\/\/173[.]212[.]214[.]137\/se<br \/>\nhxxp:\/\/173[.]212[.]214[.]137\/icantgetit<\/p>\n\n<h3>URI Indicator(s)<\/h3>\n\n<p>\/se<br \/>\n\/icantgetit<\/p>\n\n<h3>Domain Indicator(s)<\/h3>\n\n<p>orion1709[.]startdedicated[.]de<\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-exim-vulnerability-observed-wild","alert_type":397,"serial_number":"AL19-012","subject":null,"moderation_state":"published","external_url":null},{"nid":1535,"title":"Mozilla security advisory","uuid":"4794a58e-fe73-4da7-b656-bf45d69cdbd2","banner":null,"lang":"en","date_modified":"2019-06-20","date_modified_ts":"2019-06-20T13:54:53Z","date_created":"2019-06-20T13:53:06Z","summary":null,"body":["<article data-history-node-id=\"1535\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-119<\/strong><br \/><strong>Date: 19 June 2019<\/strong><\/p>\n\n<p>On 18 June 2019 Mozilla released security updates to address a vulnerability in Firefox and Firefox ESR. The vulnerability, tracked as CVE-2019-11707, could allow a remote actor to take control of the affected system. Active exploitation of this vulnerability has been reported.<\/p>\n\n<p>CCCS encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-18\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-18<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-2","alert_type":396,"serial_number":"AV19-119","subject":null,"moderation_state":"published","external_url":null},{"nid":1536,"title":"Oracle security advisory","uuid":"11ef7ce6-d870-4bc4-8ce9-8a509ef10f6b","banner":null,"lang":"en","date_modified":"2019-06-20","date_modified_ts":"2019-06-20T13:59:50Z","date_created":"2019-06-20T13:58:15Z","summary":null,"body":["<article data-history-node-id=\"1536\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-120<\/strong><br \/><strong>Date: 19 June 2019<\/strong><\/p>\n\n<p>On 18 June 2019 Oracle released emergency patches for a critical remote code execution vulnerability affecting WebLogic Server. This vulnerability, tracked as CVE-2019-2729, could allow a remote unauthenticated actor to take control of an affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the following Oracle security advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2019-2729-5570780.html\">https:\/\/www.oracle.com\/technetwork\/security-advisory\/alert-cve-2019-2729-5570780.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-0","alert_type":396,"serial_number":"AV19-120","subject":null,"moderation_state":"published","external_url":null},{"nid":1537,"title":"Cisco security advisory","uuid":"7966a21a-c21f-4d80-bcdc-b83d237ae422","banner":null,"lang":"en","date_modified":"2019-06-21","date_modified_ts":"2019-06-21T13:56:33Z","date_created":"2019-06-21T13:51:15Z","summary":null,"body":["<article data-history-node-id=\"1537\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-121<\/strong><br \/><strong>Date: 21 June 2019<\/strong><\/p>\n\n<p>On 20 June 2019, Cisco released security updated to address vulnerabilities affecting some of their products. Of note, Cisco released an update and patch for a critical remote command execution vulnerability affecting web-based management interface of multiple networking products. This vulnerability, tracked as CVE-2019-1663, could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability leverages a weakness in input validation in the web-based management interface. An attacker could send specially crafted HTTP request code to a targeted device to exploit this vulnerability. A successful exploit could allow the attacker to execute code on the underlying operating system as a high-privilege user.<\/p>\n\n<p>CCCS highly encourages users and administrators to review the following Cisco security advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190227-rmi-cmd-ex\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190227-rmi-cmd-ex<\/a><\/p>\n\n<p>CCCS further encourages users and administrators to review all the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-22","alert_type":396,"serial_number":"AV19-121","subject":null,"moderation_state":"published","external_url":null},{"nid":1538,"title":"Dell security advisory","uuid":"5bf03ce5-7878-4c66-a3a5-c8a4f9226d13","banner":null,"lang":"en","date_modified":"2019-06-21","date_modified_ts":"2019-06-21T18:32:46Z","date_created":"2019-06-21T18:30:51Z","summary":null,"body":["<article data-history-node-id=\"1538\" about=\"\/en\/alerts-advisories\/dell-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-122<\/strong><br \/><strong>Date: 21 June 2019<\/strong><\/p>\n\n<p>Dell has released security updates to address a vulnerability affecting a component of its SupportAssist software. This software comes preinstalled on most Dell laptops and computers that are running the Windows 10 operating system. An actor could exploit this vulnerability to escalate privileges on the affected device. Dell has released new versions of SupportAssist to address this issue, SupportAssist for Business 2.0.1 and SupportAssist for Home 3.2.2. All prior versions of the software are affected by this vulnerability.<\/p>\n\n<p>CCCS encourages users and administrators to review the Dell Support webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/article\/ca\/en\/cadhs1\/sln317291\/dsa-2019-084-dell-supportassist-for-business-pcs-and-dell-supportassist-for-home-pcs-security-update-for-pc-doctor-vulnerability?lang=en\">https:\/\/www.dell.com\/support\/article\/ca\/en\/cadhs1\/sln317291\/dsa-2019-084-dell-supportassist-for-business-pcs-and-dell-supportassist-for-home-pcs-security-update-for-pc-doctor-vulnerability?lang=en<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-0","alert_type":396,"serial_number":"AV19-122","subject":null,"moderation_state":"published","external_url":null},{"nid":1539,"title":"Mozilla security advisory","uuid":"9f8f399c-bcaa-45d4-a5c7-3678f2f074f9","banner":null,"lang":"en","date_modified":"2019-06-24","date_modified_ts":"2019-06-24T18:12:21Z","date_created":"2019-06-24T18:10:13Z","summary":null,"body":["<article data-history-node-id=\"1539\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-123<\/strong><br \/><strong>Date: 24 June 2019<\/strong><\/p>\n\n<p>On 20 June 2019, Mozilla released a security update to address a vulnerability affecting Mozilla products. A new vulnerability, tracked as CVE-2019-11708, when combined with additional vulnerabilities could be exploited with a specially crafted Prompt:Open IPC message.<\/p>\n\n<p>CCCS encourages users and administrators to review all the Mozilla Security Advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-20\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-20\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-3","alert_type":396,"serial_number":"AV19-123","subject":null,"moderation_state":"published","external_url":null},{"nid":1540,"title":"Apple security advisory","uuid":"cf421445-159c-4300-9336-956e03feb25e","banner":null,"lang":"en","date_modified":"2019-06-25","date_modified_ts":"2019-06-25T19:52:54Z","date_created":"2019-06-25T19:51:30Z","summary":null,"body":["<article data-history-node-id=\"1540\" about=\"\/en\/alerts-advisories\/apple-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-124<\/strong><br \/><strong>Date: 25 June 2019<\/strong><\/p>\n\n<p>On 20 June 2019, Apple published a security advisory to address a number of vulnerabilities affecting some of their AirPort Base Station products. Some of the fixes improve input validation, memory management and memory handling.<\/p>\n\n<p>CCCS encourages users and administrators to review the Apple Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT210091\">https:\/\/support.apple.com\/en-ca\/HT210091<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-2","alert_type":396,"serial_number":"AV19-124","subject":null,"moderation_state":"published","external_url":null},{"nid":1541,"title":"Cisco security advisory","uuid":"8ae4f85b-988f-41ad-b784-e85dd9b28d08","banner":null,"lang":"en","date_modified":"2019-06-25","date_modified_ts":"2019-06-25T19:57:23Z","date_created":"2019-06-25T19:54:54Z","summary":null,"body":["<article data-history-node-id=\"1541\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-125<\/strong><br \/><strong>Date: 25 June 2019<\/strong><\/p>\n\n<p>On 24 June 2019, Cisco updated a security advisory to address a vulnerability affecting some of their products. This vulnerability, tracked as CVE-2019-1845, could allow an unauthenticated, remote attacker to cause an outage in the authentication service, resulting in a denial of service condition for users trying to authenticate. The exploit leverages inadequate controls for specific memory operations within the product.<\/p>\n\n<p>CCCS further encourages users and administrators to review all the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-23","alert_type":396,"serial_number":"AV19-125","subject":null,"moderation_state":"published","external_url":null},{"nid":1542,"title":"Phoenix Contact security advisory","uuid":"40540abe-d108-4e8a-b4fd-bd2d7f8d1871","banner":null,"lang":"en","date_modified":"2019-06-26","date_modified_ts":"2019-06-26T14:23:30Z","date_created":"2019-06-26T14:20:16Z","summary":null,"body":["<article data-history-node-id=\"1542\" about=\"\/en\/alerts-advisories\/phoenix-contact-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-126<\/strong><br \/><strong>Date: 26 June 2019<\/strong><\/p>\n\n<p>On 18 June 2019 Phoenix Contact released a security advisory to address vulnerabilities affecting the Automation Worx Software Suite product. An actor could exploit these vulnerabilities to remotely execute code on the affected system.<\/p>\n\n<p>CCCS encourages users and administrators to review the Phoenix Contact Security Advisory and follow the recommended mitigation steps:<\/p>\n\n<p><a href=\"https:\/\/dam-mdc.phoenixcontact.com\/asset\/156443151564\/5fb7e8f696c4f9f9d893846d561b0bb6\/Security_Advisory_Automation-Worx_CVE-2019-12869-12871.pdf\">https:\/\/dam-mdc.phoenixcontact.com\/asset\/156443151564\/5fb7e8f696c4f9f9d893846d561b0bb6\/Security_Advisory_Automation-Worx_CVE-2019-12869-12871.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/phoenix-contact-security-advisory-0","alert_type":396,"serial_number":"AV19-126","subject":null,"moderation_state":"published","external_url":null},{"nid":1543,"title":"ABB security advisory","uuid":"a2f2608b-d05c-46f0-b971-da34c87c10b1","banner":null,"lang":"en","date_modified":"2019-06-26","date_modified_ts":"2019-06-26T14:27:28Z","date_created":"2019-06-26T14:25:30Z","summary":null,"body":["<article data-history-node-id=\"1543\" about=\"\/en\/alerts-advisories\/abb-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-127<\/strong><br \/><strong>Date: 26 June 2019<\/strong><\/p>\n\n<p>On 5 June 2019 ABB released security advisories to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>CP635 HMI<\/li>\n\t<li>PB610<\/li>\n\t<li>CP651 HMI<\/li>\n<\/ul><p>An actor could exploit these vulnerabilities to bypass authentication, execute arbitrary code, and gain access to information on the affected devices.<\/p>\n\n<p>CCCS encourages users and administrators to review the ABB Security Advisories and follow the recommended mitigation steps:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010376&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010376&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010377&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010377&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010402&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010402&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/abb-security-advisory","alert_type":396,"serial_number":"AV19-127","subject":null,"moderation_state":"published","external_url":null},{"nid":1544,"title":"Cisco security advisory","uuid":"9b00f8aa-38c9-4352-b938-6dc6f140c0b0","banner":null,"lang":"en","date_modified":"2019-06-26","date_modified_ts":"2019-06-26T20:09:56Z","date_created":"2019-06-26T20:07:25Z","summary":null,"body":["<article data-history-node-id=\"1544\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-128<\/strong><br \/><strong>Date: 26 June 2019<\/strong><\/p>\n\n<p>On 25 June 2019, Cisco published an update to a security advisory that addresses a vulnerability affecting some of their Cisco TelePresence products. This vulnerability, tracked as CVE-2019-1878, could allow an unauthenticated, adjacent actor to inject arbitrary shell commands or scripts to be executed. The exploit leverages insufficient input validation of received CDP packets.<\/p>\n\n<p>CCCS further encourages users and administrators to review all the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-24","alert_type":396,"serial_number":"AV19-128","subject":null,"moderation_state":"published","external_url":null},{"nid":1545,"title":"Ryuk ransomware targeting organizations globally (NCSC report)","uuid":"e9ad331d-421a-4daf-8fc5-52eab9b6c1b7","banner":null,"lang":"en","date_modified":"2019-06-27","date_modified_ts":"2019-06-27T15:15:14Z","date_created":"2019-06-27T15:12:03Z","summary":null,"body":["<article data-history-node-id=\"1545\" about=\"\/en\/alerts-advisories\/ryuk-ransomware-targeting-organizations-globally-ncsc-report\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-013<\/strong>\n  <br \/><strong>Date: 25 June 2019<\/strong>\n<\/p>\n<h2>Audience\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>Purpose\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>Assessment\n<\/h2>\n<p>The National Cyber Security Centre (NCSC), the United Kingdom\u2019s independent authority on Cyber Security, has produced a report regarding their ongoing investigation of Ryuk ransomware and related malware, dated 22 June 2019. The Cyber Centre would like to highlight this report as it provides valuable information to system owners and operators responsible for defending their systems and networks from ransomware attack.\n<\/p>\n<p>The NCSC report can be found at: <a href=\"https:\/\/www.ncsc.gov.uk\/news\/ryuk-advisory\">https:\/\/www.ncsc.gov.uk\/news\/ryuk-advisory<\/a>\n<\/p>\n<p>Should activity matching the content of the NCSC Advisory be discovered, the Cyber Centre encourages recipients of this Alert to contact us at: <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a> or by telephone at (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>Note to readers\n<\/h2>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ryuk-ransomware-targeting-organizations-globally-ncsc-report","alert_type":397,"serial_number":"AL19-013","subject":null,"moderation_state":"published","external_url":null},{"nid":1546,"title":"Cisco security advisory","uuid":"a3ff0e97-671e-4ce9-995a-f648e5256678","banner":null,"lang":"en","date_modified":"2019-06-28","date_modified_ts":"2019-06-28T14:38:55Z","date_created":"2019-06-28T14:37:36Z","summary":null,"body":["<article data-history-node-id=\"1546\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-129<\/strong><br \/><strong>Date: 28 June 2019<\/strong><\/p>\n\n<p>On 26 June 2019, Cisco released security updates to address vulnerabilities affecting some Cisco products. Of note are two critical vulnerabilities in the Cisco Data Center Network Manager. The first vulnerability, due to improper session management, could allow a remote actor to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The second vulnerability, due to incorrect permission settings, could allow a remote, unauthenticated actor to upload arbitrary files on the filesystem and execute code with root privileges on the affected device.<\/p>\n\n<p>CCCS encourages users and administrators to review the Cisco Security Advisories and Alerts and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-25","alert_type":396,"serial_number":"AV19-129","subject":null,"moderation_state":"published","external_url":null},{"nid":1547,"title":"RSA security advisory","uuid":"c703b152-3b52-417f-b849-2352628dbc9a","banner":null,"lang":"en","date_modified":"2019-06-28","date_modified_ts":"2019-06-28T14:42:37Z","date_created":"2019-06-28T14:41:30Z","summary":null,"body":["<article data-history-node-id=\"1547\" about=\"\/en\/alerts-advisories\/rsa-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-130<\/strong><br \/><strong>Date: 28 June 2019<\/strong><\/p>\n\n<p>On 25 June 2019, RSA published a security advisory that addresses a series of vulnerabilities that affected multiple embedded components within certain versions of the RSA Authentication Manager. The severity of the vulnerability varies from medium to critical.<\/p>\n\n<p>Affected Products:<\/p>\n\n<ul><li>RSA Authentication Manager 8.4 Patch 3 and earlier<\/li>\n\t<li>RSA Authentication Manager web-tier server 8.4 Patch 3 and earlier<\/li>\n<\/ul><p>CCCS encourages users and administrators to review the RSA Security Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/community.rsa.com\/docs\/DOC-105598\">https:\/\/community.rsa.com\/docs\/DOC-105598<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rsa-security-advisory","alert_type":396,"serial_number":"AV19-130","subject":null,"moderation_state":"published","external_url":null},{"nid":1548,"title":"Medtronic security advisory","uuid":"e0f662b8-15b6-4a67-9524-3bfc6224ab6a","banner":null,"lang":"en","date_modified":"2019-06-28","date_modified_ts":"2019-06-28T15:32:17Z","date_created":"2019-06-28T15:30:39Z","summary":null,"body":["<article data-history-node-id=\"1548\" about=\"\/en\/alerts-advisories\/medtronic-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-131<\/strong><br \/><strong>Date: 28 June 2019<\/strong><\/p>\n\n<p>Medtronic has released a safety notification to address vulnerabilities affecting some Medtronic products. The Medtronic MiniMed 508 and MiniMed Paradigm series insulin pumps are vulnerable to unauthorized, remote connections by a nearby actor with the correct radio frequency equipment. This may give the actor the ability to change settings and control insulin delivery, posing a direct threat to the health of the insulin pump user.<\/p>\n\n<p>CCCS encourages users of the affected Medtronic insulin pumps to review the Medtronic safety notification:<\/p>\n\n<p><a href=\"https:\/\/www.medtronicdiabetes.com\/customer-support\/product-and-service-updates\/notice11-letter\">https:\/\/www.medtronicdiabetes.com\/customer-support\/product-and-service-updates\/notice11-letter<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/medtronic-security-advisory-0","alert_type":396,"serial_number":"AV19-131","subject":null,"moderation_state":"published","external_url":null},{"nid":1549,"title":"Django security advisory","uuid":"4ce0a036-e512-4479-b264-b5c33e634aa6","banner":null,"lang":"en","date_modified":"2019-07-03","date_modified_ts":"2019-07-03T18:31:01Z","date_created":"2019-07-03T18:27:07Z","summary":null,"body":["<article data-history-node-id=\"1549\" about=\"\/en\/alerts-advisories\/django-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-132<\/strong><br \/><strong>Date: 2 July 2019<\/strong><\/p>\n\n<p>On 1 July 2019 Django issued several patches to address a vulnerability, being tracked as CVE-2019-12781, affecting multiple Django Web Framework releases. The new versions address a design flaw that could mishandle certain HTTP client requests.<\/p>\n\n<p>Affected versions:<\/p>\n\n<ul><li>Django 2.2 before version 2.2.3<\/li>\n\t<li>Django 2.1 before version 2.1.10<\/li>\n\t<li>Django 1.11 before version 1.11.22<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Django Security Updates webpage and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.djangoproject.com\/en\/dev\/releases\/2.2.3\/\">https:\/\/docs.djangoproject.com\/en\/dev\/releases\/2.2.3\/<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.djangoproject.com\/en\/dev\/releases\/2.1.10\/\">https:\/\/docs.djangoproject.com\/en\/dev\/releases\/2.1.10\/<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.djangoproject.com\/en\/dev\/releases\/1.11.22\/\">https:\/\/docs.djangoproject.com\/en\/dev\/releases\/1.11.22\/<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/django-security-advisory","alert_type":396,"serial_number":"AV19-132","subject":null,"moderation_state":"published","external_url":null},{"nid":1550,"title":"Android security advisory","uuid":"9aec4280-0345-4b80-8ee0-2b8c83b3e363","banner":null,"lang":"en","date_modified":"2019-07-03","date_modified_ts":"2019-07-03T19:51:38Z","date_created":"2019-07-03T19:50:12Z","summary":null,"body":["<article data-history-node-id=\"1550\" about=\"\/en\/alerts-advisories\/android-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-133<\/strong><br \/><strong>Date: 2 July 2019<\/strong><\/p>\n\n<p>Google has released security updates to address multiple vulnerabilities affecting Android devices. A remote actor could exploit some of these vulnerabilities to take control of an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Android security advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-07-01\">https:\/\/source.android.com\/security\/bulletin\/2019-07-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-2","alert_type":396,"serial_number":"AV19-133","subject":null,"moderation_state":"published","external_url":null},{"nid":1551,"title":"The FreeBSD Project security advisory","uuid":"6e293737-f7a4-493f-8e3a-04b5a313ed77","banner":null,"lang":"en","date_modified":"2019-07-03","date_modified_ts":"2019-07-03T19:55:51Z","date_created":"2019-07-03T19:53:09Z","summary":null,"body":["<article data-history-node-id=\"1551\" about=\"\/en\/alerts-advisories\/freebsd-project-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-134<\/strong><br \/><strong>Date: 3 July 2019<\/strong><\/p>\n\n<p>On 2 July 2019 The FreeBSD Project released security updates to address multiple vulnerabilities (CVE-2019-5600, CVE-2019-5601 and CVE-2019-5602) affecting multiple core components of all supported versions of the FreeBSD operating system. A remote actor could exploit these vulnerabilities to take control of an affected system and\/or interact with the kernel memory of the operating system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the FreeBSD Security Updates webpage and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-19:09.iconv.asc\">https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-19:09.iconv.asc<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-19:10.ufs.asc\">https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-19:10.ufs.asc<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-19:11.cd_ioctl.asc\">https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-19:11.cd_ioctl.asc<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freebsd-project-security-advisory","alert_type":396,"serial_number":"AV19-134","subject":null,"moderation_state":"published","external_url":null},{"nid":1552,"title":"Red Hat security advisory","uuid":"12b9fa53-e326-4cc4-b0b4-f47696232e9b","banner":null,"lang":"en","date_modified":"2019-07-03","date_modified_ts":"2019-07-03T20:01:47Z","date_created":"2019-07-03T19:59:50Z","summary":null,"body":["<article data-history-node-id=\"1552\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-135<\/strong><br \/><strong>Date: 3 July 2019<\/strong><\/p>\n\n<p>On 3 July 2019, Red Hat released several fixes to address vulnerabilities in a library used in Red Hat Enterprise Linux 6. The updates correct several integer overflow weaknesses in the libssh2 packages that implement the SSH2 protocol. When exploiting the flaws, a remote actor that has compromised a SSH server could execute code on a client system.<\/p>\n\n<p>CVEs:<\/p>\n\n<ul><li>CVE-2019-3855<\/li>\n\t<li>CVE-2019-3856<\/li>\n\t<li>CVE-2019-3857<\/li>\n\t<li>CVE-2019-3863<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Red Hat Security webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2019:1652\">https:\/\/access.redhat.com\/errata\/RHSA-2019:1652<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory","alert_type":396,"serial_number":"AV19-135","subject":null,"moderation_state":"published","external_url":null},{"nid":1553,"title":" IBM security advisory","uuid":"2e43fde1-1950-4cff-be3b-f40320b112ed","banner":null,"lang":"en","date_modified":"2019-07-04","date_modified_ts":"2019-07-04T14:45:42Z","date_created":"2019-07-04T14:39:34Z","summary":null,"body":["<article data-history-node-id=\"1553\" about=\"\/en\/alerts-advisories\/ibm-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-136<\/strong><br \/><strong>Date: 4 July 2019<\/strong><\/p>\n\n<p>IBM has published Security Bulletins to address vulnerabilities that affect multiple IBM products. The severity of the vulnerability varies from medium to critical.<\/p>\n\n<p>Affected products include:<\/p>\n\n<ul><li>IBM Power Hardware Management Console<\/li>\n\t<li>IBM Security Guardium<\/li>\n\t<li>IBM Security Identity Governance and Intelligence<\/li>\n\t<li>IBM Security AppScan Standard<\/li>\n\t<li>IBM Security Privileged Identity Manager<\/li>\n\t<li>IBM Flex System<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the IBM Security Bulletins and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10956425\">https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10956425<\/a><\/li>\n\t<li><a href=\"https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10958035\">https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10958035<\/a><\/li>\n\t<li><a href=\"https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10957973\">https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10957973<\/a><\/li>\n\t<li><a href=\"https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10958059\">https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10958059<\/a><\/li>\n\t<li><a href=\"https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10884416\">https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10884416<\/a><\/li>\n\t<li><a href=\"https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10957781\">https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10957781<\/a><\/li>\n\t<li><a href=\"https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10888177\">https:\/\/www-01.ibm.com\/support\/docview.wss?uid=ibm10888177<\/a><\/li>\n<\/ul><p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory","alert_type":396,"serial_number":"AV19-136","subject":null,"moderation_state":"published","external_url":null},{"nid":1554,"title":"Cisco security advisory","uuid":"6947f363-eabb-4f42-aa3c-16b3563cd9e4","banner":null,"lang":"en","date_modified":"2019-07-04","date_modified_ts":"2019-07-04T18:05:39Z","date_created":"2019-07-04T18:05:39Z","summary":null,"body":["<article data-history-node-id=\"1554\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-137<\/strong><br \/><strong>Date: 4 July 2019<\/strong><\/p>\n\n<p>On 3 July 2019, Cisco released several security advisories to address multiple vulnerabilities affecting Cisco products. A sample of the products and software of note are listed below:<\/p>\n\n<p>Cisco Small Business Managed Switches <strong>(CVE-2019-1891)<\/strong><\/p>\n\n<ul><li>Weakness: Improper validation of HTTP requests<\/li>\n\t<li>Impact: Could allow an unauthenticated remote actor to cause a denial of service condition<\/li>\n<\/ul><p>Cisco Email Security Appliance <strong>(CVE-2019-1933)<\/strong><\/p>\n\n<ul><li>Weakness: Improper input validation of email fields<\/li>\n\t<li>Impact: Could allow an unauthenticated, remote actor to bypass configure filters on the device<\/li>\n<\/ul><p>Cisco Web Security Appliance Web Proxy <strong>(CVE-2019-1884)<\/strong><\/p>\n\n<ul><li>Weakness: Insufficient input validation<\/li>\n\t<li>Impact: Could allow an unauthenticated, remote actor to cause a denial of service condition<\/li>\n<\/ul><p>Cisco Jabber <strong>(CVE-2019-1855)<\/strong><\/p>\n\n<ul><li>Weakness: Insufficient validation of resources<\/li>\n\t<li>Impact: Could allow an authenticated, local actor to perform a DLL preloading attack<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Cisco Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-26","alert_type":396,"serial_number":"AV19-137","subject":null,"moderation_state":"published","external_url":null},{"nid":1555,"title":"VMware security advisory","uuid":"bef38e93-28b5-46b2-870a-354739847211","banner":null,"lang":"en","date_modified":"2019-07-04","date_modified_ts":"2019-07-04T18:27:11Z","date_created":"2019-07-04T18:27:11Z","summary":null,"body":["<article data-history-node-id=\"1555\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-138<\/strong><br \/><strong>Date: 4 July 2019<\/strong><\/p>\n\n<p>On 2 July 2019, VMware released security updates to address vulnerabilities affecting some VMware products. The updates address the recently disclosed vulnerabilities in the Linux kernel implementation of the Transmission Control Protocol (TCP) stack, specifically as to how it handles the TCP Selective Acknowledgement (SACK). The most serious of the four vulnerabilities, tracked as CVE-2019-11477, could allow an unauthenticated, remote actor to cause a denial-of-service condition on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the VMware security advisory and apply the necessary updates, when available:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0010.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0010.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-15","alert_type":396,"serial_number":"AV19-138","subject":null,"moderation_state":"published","external_url":null},{"nid":1556,"title":"Adobe security advisory","uuid":"2a606143-f686-4932-9c8c-bd62cb4787cd","banner":null,"lang":"en","date_modified":"2019-07-10","date_modified_ts":"2019-07-10T20:03:03Z","date_created":"2019-07-10T20:01:51Z","summary":null,"body":["<article data-history-node-id=\"1556\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-139<\/strong><br \/><strong>Date: 10 July 2019<\/strong><\/p>\n\n<p>On 9 July 2019 Adobe released security updates to address vulnerabilities affecting some of its products. These vulnerabilities could result in privilege escalation or information disclosure on the affected system.<\/p>\n\n<p>Affected products include:<\/p>\n\n<ul><li>Adobe Bridge CC<\/li>\n\t<li>Adobe Experience Manager<\/li>\n\t<li>Adobe Dreamweaver<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-3","alert_type":396,"serial_number":"AV19-139","subject":null,"moderation_state":"published","external_url":null},{"nid":1557,"title":"Mozilla security advisory","uuid":"0c41066a-5899-41ba-b78f-0b48e7aab691","banner":null,"lang":"en","date_modified":"2019-07-10","date_modified_ts":"2019-07-10T20:06:25Z","date_created":"2019-07-10T20:05:27Z","summary":null,"body":["<article data-history-node-id=\"1557\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-140<\/strong><br \/><strong>Date: 10 July 2019<\/strong><\/p>\n\n<p>On 9 July 2019 Mozilla released security updates to address vulnerabilities in Firefox and Firefox ESR. A remote actor could exploit some of these vulnerabilities to take control of the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-21\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-21\/<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-22\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-22\/<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-4","alert_type":396,"serial_number":"AV19-140","subject":null,"moderation_state":"published","external_url":null},{"nid":1558,"title":"Intel security advisory","uuid":"c1f54213-c7b1-4a60-8420-530ae1ecd817","banner":null,"lang":"en","date_modified":"2019-07-10","date_modified_ts":"2019-07-10T20:09:33Z","date_created":"2019-07-10T20:08:31Z","summary":null,"body":["<article data-history-node-id=\"1558\" about=\"\/en\/alerts-advisories\/intel-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-141<\/strong><br \/><strong>Date: 10 July 2019<\/strong><\/p>\n\n<p>On 9 July 2019, Intel released two security updates to address vulnerabilities affecting Intel products.<\/p>\n\n<p>Of note, the vulnerability currently tracked as CVE-2019-11133 could allow an actor with physical access to a vulnerable device to exploit weaknesses in a diagnostic tool. After a successful exploit, the actor could take control of an affected system and elevate their access, gain access to unauthorized information and\/or cause a denial of service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Intel Security Updates webpage and apply the necessary updates:<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00268.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00268.html<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00267.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00267.html<\/a><\/li>\n<\/ul><p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-3","alert_type":396,"serial_number":"AV19-141","subject":null,"moderation_state":"published","external_url":null},{"nid":1559,"title":"Microsoft security advisory \u2013 July 2019 monthly rollup","uuid":"25e753f8-bbad-4278-b865-9814dfc65978","banner":null,"lang":"en","date_modified":"2019-07-10","date_modified_ts":"2019-07-10T20:13:36Z","date_created":"2019-07-10T20:11:26Z","summary":null,"body":["<article data-history-node-id=\"1559\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2019-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-142<\/strong><br \/><strong>Date: 10 July 2019<\/strong><\/p>\n\n<p>On 9 July 2019 Microsoft has released security updates to address almost 80 vulnerabilities affecting Windows and Office products. This rollup provides fixes for 15 critical vulnerabilities, including a vulnerability in the Windows Server DHCP service, identified as CVE-2019-0785, that can be exploited by using a specially crafted packet. Successful exploitation could lead to remote code execution on the affected system. Importantly, the DHCP server must be set to failover mode for the attack to succeed.<\/p>\n\n<p>Additionally, there have been active exploitations reported for the following two elevation of privilege vulnerabilities that are addressed in this rollup:<\/p>\n\n<ul><li><strong>CVE-2019-1132<\/strong> - The Win32k component could be exploited to run arbitrary code in kernel mode due to improper handling of objects in memory.<\/li>\n\t<li><strong>CVE-2019-0880<\/strong> - splwow64.exe could be exploited to elevate privileges from low-integrity to medium integrity. This could allow an actor to leverage other vulnerabilities to gain further control of the affected system.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Microsoft July 2019 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2019-monthly-rollup","alert_type":396,"serial_number":"AV19-142","subject":null,"moderation_state":"published","external_url":null},{"nid":1560,"title":"Atlassian Confluence security advisory","uuid":"f3533549-0f6f-4573-8d29-c43a12afd395","banner":null,"lang":"en","date_modified":"2019-07-11","date_modified_ts":"2019-07-11T18:27:20Z","date_created":"2019-07-11T18:19:54Z","summary":null,"body":["<article data-history-node-id=\"1560\" about=\"\/en\/alerts-advisories\/atlassian-confluence-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-143<\/strong><br \/><strong>Date: 11 July 2019<\/strong><\/p>\n\n<p>On 10 July 2019 Atlassian Confluence released a security advisory to address a critical vulnerability affecting multiple Jira Server and Jira Data Center products. In some configurations, a remote actor could exploit the vulnerability, currently tracked as CVE-2019-11581, to remotely execute code on systems without authentication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Atlassian Confluence Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/confluence.atlassian.com\/jira\/jira-security-advisory-2019-07-10-973486595.html\">https:\/\/confluence.atlassian.com\/jira\/jira-security-advisory-2019-07-10-973486595.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-confluence-security-advisory","alert_type":396,"serial_number":"AV19-143","subject":null,"moderation_state":"published","external_url":null},{"nid":1561,"title":"Cisco security advisory","uuid":"02cbbf2b-3e20-416c-b38e-b7dd421152be","banner":null,"lang":"en","date_modified":"2019-07-11","date_modified_ts":"2019-07-11T18:33:43Z","date_created":"2019-07-11T18:33:43Z","summary":null,"body":["<article data-history-node-id=\"1561\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-144<\/strong><br \/><strong>Date: 11 July 2019<\/strong><\/p>\n\n<p>On 10 July 2019 Cisco released security updates to address a vulnerability affecting the cryptographic driver of some Cisco products. An unauthenticated, remote actor could exploit the vulnerability, currently tracked as CVE-2019-1873, and cause the affected device to reload, which may lead to a denial of service condition. The vulnerability only affects certain system configurations and requires a valid SSL or TLS session prior to attempting an exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190710-asa-ftd-dos\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190710-asa-ftd-dos<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-27","alert_type":396,"serial_number":"AV19-144","subject":"cisco","moderation_state":"published","external_url":null},{"nid":1562,"title":"Juniper Networks security advisory","uuid":"ff4ab6b8-ce1d-4dd4-9334-96c38edb8f48","banner":null,"lang":"en","date_modified":"2019-07-11","date_modified_ts":"2019-07-11T18:52:17Z","date_created":"2019-07-11T18:52:17Z","summary":null,"body":["<article data-history-node-id=\"1562\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-145<\/strong><br \/><strong>Date: 11 July 2019<\/strong><\/p>\n\n<p>On 10 July 2019 Juniper Networks released several security bulletins to address multiple vulnerabilities affecting its products and the third party software included with them. Most of the bulletins address vulnerabilities that range between medium and high risk level. One bulletin of note is JSA10951, which resolves multiple vulnerabilities in third party software included with Junos Space and affects all releases prior to 19.2R1.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Juniper Networks Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=contentalt&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-0","alert_type":396,"serial_number":"AV19-145","subject":null,"moderation_state":"published","external_url":null},{"nid":1563,"title":"Siemens security advisory","uuid":"ff25061f-f0b0-4c36-9b94-59fc667af551","banner":null,"lang":"en","date_modified":"2019-07-12","date_modified_ts":"2019-07-12T13:46:33Z","date_created":"2019-07-12T13:44:44Z","summary":null,"body":["<article data-history-node-id=\"1563\" about=\"\/en\/alerts-advisories\/siemens-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-146<\/strong><br \/><strong>Date: 11 July 2019<\/strong><\/p>\n\n<p>On 9 July 2019 Siemens released security updates to address a vulnerability affecting its TIA Administrator product. A remote, unauthenticated actor could exploit this vulnerability to take actions on the affected product. Actions could include elevating privileges, changing proxy settings, or specifying malicious firmware updates.<\/p>\n\n<p>The Cyber Centre encourages users to review the Siemens security advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-721298.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-721298.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/siemens-security-advisory","alert_type":396,"serial_number":"AV19-146","subject":null,"moderation_state":"published","external_url":null},{"nid":1564,"title":"Dell security advisory","uuid":"923f0f14-ce3d-43c0-b56b-87b497237852","banner":null,"lang":"en","date_modified":"2019-07-15","date_modified_ts":"2019-07-15T17:15:30Z","date_created":"2019-07-15T17:13:41Z","summary":null,"body":["<article data-history-node-id=\"1564\" about=\"\/en\/alerts-advisories\/dell-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-147<\/strong><br \/><strong>Date: 12 July 2019<\/strong><\/p>\n\n<p>On 12 July 2019 Dell released a security update to address a vulnerability affecting a third party component that is implemented by Dell Isilon OneFS products. The vulnerability could allow an actor to use specially crafted HTTP requests to cause a stack-based buffer overflow.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Dell Security Advisories and Notices webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/ca\/en\/cabsdt1\/\">https:\/\/www.dell.com\/support\/security\/ca\/en\/cabsdt1\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-1","alert_type":396,"serial_number":"AV19-147","subject":null,"moderation_state":"published","external_url":null},{"nid":1565,"title":"Google Chrome security advisory","uuid":"8a72a29e-637b-4a0b-b827-deba7f780d62","banner":null,"lang":"en","date_modified":"2019-07-17","date_modified_ts":"2019-07-17T18:55:08Z","date_created":"2019-07-17T18:53:46Z","summary":null,"body":["<article data-history-node-id=\"1565\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-148<\/strong><br \/><strong>Date: 17 July 2019<\/strong><\/p>\n\n<p>On 15 July 2019 Google announced the release of Chrome 75.0.3770.142 for Windows, Mac, and Linux. This release will address vulnerabilities that can lead to denial of service conditions, or leaking of sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary update when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/07\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2019\/07\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-3","alert_type":396,"serial_number":"AV19-148","subject":null,"moderation_state":"published","external_url":null},{"nid":1566,"title":"Oracle security advisory \u2013 July 2019 Critical Patch update","uuid":"fa953c6f-5ad9-4842-b434-d067f5eb756a","banner":null,"lang":"en","date_modified":"2019-07-17","date_modified_ts":"2019-07-17T20:50:25Z","date_created":"2019-07-17T20:49:20Z","summary":null,"body":["<article data-history-node-id=\"1566\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-july-2019-critical-patch-update\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-149<\/strong><br \/><strong>Date: 17 July 2019<\/strong><\/p>\n\n<p>On 16 July 2019 Oracle released their Critical Patch Update containing 319 security fixes affecting various Oracle products. A remote, unauthenticated actor could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Oracle Critical Patch Update Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2019-5072835.html\">https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpujul2019-5072835.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-july-2019-critical-patch-update","alert_type":396,"serial_number":"AV19-149","subject":null,"moderation_state":"published","external_url":null},{"nid":1567,"title":"Microsoft security advisory","uuid":"888d5171-6d22-4cd1-a687-e7d74567ec00","banner":null,"lang":"en","date_modified":"2019-07-17","date_modified_ts":"2019-07-17T20:53:32Z","date_created":"2019-07-17T20:51:59Z","summary":null,"body":["<article data-history-node-id=\"1567\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-150<\/strong><br \/><strong>Date: 17 July 2019<\/strong><\/p>\n\n<p>On 16 July 2019 Microsoft released a security update to address a vulnerability which could allow an actor to bypass a security feature in the Windows Defender Application Control. Successful exploitation of this vulnerability could circumvent PowerShell Core Constrained Language Mode on the affected system.<\/p>\n\n<p>This vulnerability affects PowerShell Core 6.0 and PowerShell Core versions prior to 6.1.5 and 6.2.2.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft Security Advisory webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1167\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1167<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-3","alert_type":396,"serial_number":"AV19-150","subject":null,"moderation_state":"published","external_url":null},{"nid":1568,"title":"Fileless Malware Advisory","uuid":"35ef7c52-e0de-4b9a-8909-30decbde10fc","banner":null,"lang":"en","date_modified":"2019-07-17","date_modified_ts":"2019-07-17T20:56:54Z","date_created":"2019-07-17T20:55:28Z","summary":null,"body":["<article data-history-node-id=\"1568\" about=\"\/en\/alerts-advisories\/fileless-malware-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-151<\/strong><br \/><strong>Date: 17 July 2019<\/strong><\/p>\n\n<h2>Introduction<\/h2>\n\n<p>The Cyber Centre has become aware of a fileless malware campaign affecting Microsoft Windows users that is currently gaining traction. The Astaroth malware, a notorious info-stealing malware known for stealing sensitive information like credentials, keystrokes, and other data, resides solely in memory and is much more difficult to detect than traditional malware.<\/p>\n\n<p>The purpose of this advisory is to bring heightened awareness to the increase in the detection and identification of fileless malware, including Astaroth. The advisory provides an overview of fileless malware, the commonly used infection vectors and potential mitigations.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>Fileless malware was first discovered in the wild in the early 2000s and multiple security researchers are reporting that it remains popular method of attack by cyber adversaries. They use the malware because it has low observable characteristics (LOC) and it evades common security methods. The malware usually takes advantage of default applications to mask its malicious activity. Furthermore, the original infecting executable typically does not remain on the system\u2019s hard-drive. Although it is unlikely to prevent all infections, these attacks can be prevented by organizations implementing strong IT Security practices that, when used together, will minimize the risk of fileless malware attacks.<\/p>\n\n<h2>Analysis of Infection<\/h2>\n\n<p>The initial infection usually involves tricking the user into opening an infected file or visiting a malicious website. Although this is typical from malware attacks, the payload will not create files on the device\u2019s hard-drive but instead it will reside only in memory. The next stage of the attack varies but often includes attempting to create entries in the device\u2019s registry for persistency or attempting to load commonly used processes such as PowerShell or Windows Management Instrumentation (WMI). Afterwards, the infected machine may attempt to propagate on other connected devices, attempt to download additional malware on the infected device, and attempt to download and execute scripts.<\/p>\n\n<h2>Potential Infection Vectors<\/h2>\n\n<ol><li><strong>Physical transfer<\/strong><br \/><strong>Attack vector:<\/strong> A user connects an infected device or media into a device.<\/li>\n\t<li><strong>Social Engineering (Phishing)<\/strong>\n\t<ol class=\"lst-lwr-alph\"><li><strong>Infected links<\/strong><br \/><strong>Attack vector:<\/strong> A user interacts with a link to a malicious website in an email.<\/li>\n\t\t<li><strong>Infected attachments<\/strong><br \/><strong>Attack vector:<\/strong> A user interacts with a link to a malicious website in a document.<\/li>\n\t<\/ol><\/li>\n\t<li><strong>Web application<\/strong><br \/><strong>Attack vector:<\/strong> A malicious actor leverages a weakness in a website to inject and execute code on any user that happens to visit the website.<\/li>\n<\/ol><h2>Potential Mitigations<\/h2>\n\n<ol><li>Patch and upgrade management, including staying up to date with vendor issued security advisories and application releases.<\/li>\n\t<li>Architect a layered IT defense environment including hardening of end points and disabling non-essential applications and services.<\/li>\n\t<li>Strong user awareness including encouraging users to report suspicious activity and implementing cyber security training.<\/li>\n\t<li>Log management including regular reviews of system logs, server logs and performing regular audits.<\/li>\n<\/ol><h2>Additional Resources<\/h2>\n\n<p><strong>For more information on baseline cyber security controls:<\/strong><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/sites\/default\/files\/publications\/Baseline%20Cyber%20Security%20Controls%20for%20Small%20and%20Medium%20Organizations.pdf\">https:\/\/cyber.gc.ca\/sites\/default\/files\/publications\/Baseline%20Cyber%20Security%20Controls%20for%20Small%20and%20Medium%20Organizations.pdf<\/a><\/p>\n\n<p><strong>For more information on protection of your data:<\/strong><\/p>\n\n<p><a href=\"https:\/\/cse-cst.gc.ca\/en\/top10\">https:\/\/cse-cst.gc.ca\/en\/top10<\/a><\/p>\n\n<h2>Disclaimer<\/h2>\n\n<p>Readers should not consider any advice and guidance contained within this report as comprehensive and\/or all encompassing. All risks related to the cyber security of information technology systems are the responsibility of system owners.<\/p>\n\n<h2>Note to Readers:<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fileless-malware-advisory","alert_type":396,"serial_number":"AV19-151","subject":null,"moderation_state":"published","external_url":null},{"nid":1569,"title":"Lenovo security advisory","uuid":"79a813c6-2d65-4a5d-aebc-fcf344f99d51","banner":null,"lang":"en","date_modified":"2019-07-17","date_modified_ts":"2019-07-17T21:00:16Z","date_created":"2019-07-17T20:59:23Z","summary":null,"body":["<article data-history-node-id=\"1569\" about=\"\/en\/alerts-advisories\/lenovo-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-152<\/strong><br \/><strong>Date: 17 July 2019<\/strong><\/p>\n\n<p>On 16 July 2019 Lenovo released security updates to address a vulnerability, currently tracked as CVE-2019-6160, affecting Iomega and LenovoEMC NAS products. An unauthenticated remote actor could exploit the vulnerability to gain access to NAS shares.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Lenovo Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.lenovo.com\/ca\/en\/product_security\/len-25557\">https:\/\/support.lenovo.com\/ca\/en\/product_security\/len-25557<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/lenovo-security-advisory-0","alert_type":396,"serial_number":"AV19-152","subject":null,"moderation_state":"published","external_url":null},{"nid":1570,"title":"Drupal security advisory","uuid":"d4e2d4ab-c834-4e54-bd68-3f19a11c44a3","banner":null,"lang":"en","date_modified":"2019-07-19","date_modified_ts":"2019-07-19T15:47:33Z","date_created":"2019-07-19T13:14:24Z","summary":null,"body":["<article data-history-node-id=\"1570\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-153<\/strong><br \/><strong>Date: 19 July 2019<\/strong><\/p>\n\n<p>On 17 July 2019 Drupal released Core version 8.7.5 to address an access bypass vulnerability, identified as CVE-2019-6342. The conditions for this vulnerability exist when the experimental Workspaces module is enabled in Core version 8.7.4. Other versions of Drupal Core are unaffected.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Drupal Security Advisory webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2019-008\">https:\/\/www.drupal.org\/sa-core-2019-008<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-4","alert_type":396,"serial_number":"AV19-153","subject":null,"moderation_state":"published","external_url":null},{"nid":1571,"title":"Cisco security advisory","uuid":"d89deffa-f9ea-4742-a564-ef13320dd4bb","banner":null,"lang":"en","date_modified":"2019-07-19","date_modified_ts":"2019-07-19T13:37:40Z","date_created":"2019-07-19T13:37:17Z","summary":null,"body":["<article data-history-node-id=\"1571\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-154<\/strong><br \/><strong>Date: 19 July 2019<\/strong><\/p>\n\n<p>On 17 July 2019 Cisco released several security advisories to address multiple vulnerabilities affecting Cisco products. Of note is a critical vulnerability, identified as CVE-2019-1917, in the REST API interface of the Cisco Vision Dynamic Signage Director which could allow a remote, unauthenticated actor to execute arbitrary actions with administrative privileges on the affected system. This vulnerability could be exploited by sending a specially crafted HTTP request through the REST API.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-28","alert_type":396,"serial_number":"AV19-154","subject":null,"moderation_state":"published","external_url":null},{"nid":1572,"title":"Apple security advisory","uuid":"54ddc08e-ecee-4f62-9b35-719b96762482","banner":null,"lang":"en","date_modified":"2019-07-23","date_modified_ts":"2019-07-23T19:52:09Z","date_created":"2019-07-23T19:49:42Z","summary":null,"body":["<article data-history-node-id=\"1572\" about=\"\/en\/alerts-advisories\/apple-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-155<\/strong><br \/><strong>Date: 23 July 2019<\/strong><\/p>\n\n<p>On 22 July 2019 Apple released security updates to address vulnerabilities affecting some of its products. Of note are several vulnerabilities in iOS WebKit, allowing for the execution of arbitrary code on an affected device viewing a web page with specially-crafted web content.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-3","alert_type":396,"serial_number":"AV19-155","subject":null,"moderation_state":"published","external_url":null},{"nid":1573,"title":"Fortinet security advisory","uuid":"0ee2b73b-e202-4c2f-bb5d-d182f7f9ddba","banner":null,"lang":"en","date_modified":"2019-07-23","date_modified_ts":"2019-07-23T20:03:42Z","date_created":"2019-07-23T19:53:47Z","summary":null,"body":["<article data-history-node-id=\"1573\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-156<\/strong><br \/><strong>Date: 23 July 2019<\/strong><\/p>\n\n<p>On 17 July 2019 Fortinet released security updates to address a certificate revocation vulnerability affecting the following products:<\/p>\n\n<ul><li>FortiOS 6.2.0<\/li>\n\t<li>FortiOS 6.0.5 and below<\/li>\n\t<li>FortiOS 5.6.9 and below<\/li>\n\t<li>FortiOS 5.4.11 and below<\/li>\n\t<li>FortiOS 5.2.13 and below<\/li>\n\t<li>FortiManager 6.2.0<\/li>\n\t<li>FortiManager 6.0.5 and below<\/li>\n\t<li>FortiManager 5.6.8 and below<\/li>\n\t<li>FortiManager 5.4.6 and below<\/li>\n\t<li>FortiAnalyzer 6.2.0<\/li>\n\t<li>FortiAnalyzer 6.0.5 and below<\/li>\n\t<li>FortiAnalyzer 5.6.8 and below<\/li>\n\t<li>FortiAnalyzer 5.4.6 and below<\/li>\n<\/ul><p>This vulnerability affects validation of the Certificate Revocation List and could allow an actor to use expired or revoked certificates.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Fortinet security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-19-144\">https:\/\/fortiguard.com\/psirt\/FG-IR-19-144<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-1","alert_type":396,"serial_number":"AV19-156","subject":null,"moderation_state":"published","external_url":null},{"nid":1574,"title":"Palo Alto Networks security advisory","uuid":"2cfc2325-fb8c-4ceb-9b4f-870e096de1b3","banner":null,"lang":"en","date_modified":"2019-07-24","date_modified_ts":"2019-07-24T16:09:48Z","date_created":"2019-07-24T16:09:48Z","summary":null,"body":["<article data-history-node-id=\"1574\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-157<\/strong><br \/><strong>Date: 24 July 2019<\/strong><\/p>\n\n<p>On 22 July 2019 it was publicly disclosed that there is a vulnerability affecting some Palo Alto Networks products. Tracked as CVE-2019-1579, the vulnerability lies with the PAN-OS software, which in turn affects the GlobalProtect Portal and GlobalProtect Gateway products. The vulnerability could allow a remote, unauthenticated actor to send specially-crafted packets to an affected device and execute arbitrary code. The affected versions of PAN-OS include:<\/p>\n\n<ul><li>PAN-OS 7.1.18 and earlier<\/li>\n\t<li>PAN-OS 8.0.11 and earlier<\/li>\n\t<li>PAN-OS 8.1.2 and earlier<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Palo Alto Networks bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/158\">https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/158<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-0","alert_type":396,"serial_number":"AV19-157","subject":null,"moderation_state":"published","external_url":null},{"nid":1575,"title":"The FreeBSD Project security advisory","uuid":"492971d7-a166-444e-94ed-ffb53fde1ad7","banner":null,"lang":"en","date_modified":"2019-07-24","date_modified_ts":"2019-07-24T19:45:12Z","date_created":"2019-07-24T19:45:12Z","summary":null,"body":["<article data-history-node-id=\"1575\" about=\"\/en\/alerts-advisories\/freebsd-project-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-158<\/strong><br \/><strong>Date: 24 July 2019<\/strong><\/p>\n\n<p>On 24 July 2019 The FreeBSD Project released security advisories to address multiple vulnerabilities affecting FreeBSD products and their components. An actor could exploit some of these vulnerabilities to cause denial of service conditions, elevate privilege or gain access to sensitive information. The Cyber Centre recommends that administrators review the vendor\u2019s documentation and assess if automatic compiles and installation of patches are appropriate for their systems.<\/p>\n\n<p>Otherwise, users and administrators are encouraged to review the FreeBSD Project Security Advisories webpage and apply the necessary updates manually and individually:<\/p>\n\n<p><a href=\"https:\/\/www.freebsd.org\/security\/advisories.html\">https:\/\/www.freebsd.org\/security\/advisories.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freebsd-project-security-advisory-0","alert_type":396,"serial_number":"AV19-158","subject":null,"moderation_state":"published","external_url":null},{"nid":1576,"title":"Wind River VxWorks IPnet TCP\/IP Stack Vulnerabilities","uuid":"83d1aec0-48ad-4435-b529-3358c8884f79","banner":null,"lang":"en","date_modified":"2019-07-29","date_modified_ts":"2019-07-29T16:35:00Z","date_created":"2019-07-29T16:19:35Z","summary":null,"body":["<article data-history-node-id=\"1576\" about=\"\/en\/alerts-advisories\/wind-river-vxworks-ipnet-tcpip-stack-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-015<\/strong><br \/><strong>Date: 29 July 2019<\/strong><\/p>\n\n<p><strong>AUDIENCE<\/strong><\/p>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<p><strong>PURPOSE<\/strong><\/p>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<p><strong>OVERVIEW<\/strong><\/p>\n\n<p>Wind River VxWorks Platform is a real-time operating system widely used in ICS-related devices and deployed across several sectors, including Communications, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems, and others.<\/p>\n\n<p>Multiple vulnerabilities exist in the VxWorks default TCP\/IP Stack (called IPnet). These vulnerabilities are present in all recent versions of non-certified VxWorks. Some of these vulnerabilities can lead to remote code execution, denial of service and information leaks.<\/p>\n\n<p><strong>ASSESSMENT<\/strong><\/p>\n\n<p>The following vulnerabilities exist in the VxWorks TCP\/IP Stack:<\/p>\n\n<ul><li>CVE-2019-12255 - TCP Urgent Pointer = 0 leads to integer underflow.<\/li>\n\t<li>CVE-2019-12256 - Stack overflow in the parsing of IPv4 packets\u2019 IP options.<\/li>\n\t<li>CVE-2019-12257 - Heap overflow in DHCP Offer\/Ack parsing inside ipdhcpc.<\/li>\n\t<li>CVE-2019-12258 - DoS of TCP connection via malformed TCP options.<\/li>\n\t<li>CVE-2019-12259 - DoS via NULL dereference in IGMP parsing.<\/li>\n\t<li>CVE-2019-12260 - TCP Urgent Pointer state confusion caused by malformed TCP AO option.<\/li>\n\t<li>CVE-2019-12261 - TCP Urgent Pointer state confusion during connect() to a remote host.<\/li>\n\t<li>CVE-2019-12262 - Handling of unsolicited Reverse ARP replies (logic flaw).<\/li>\n\t<li>CVE-2019-12263 - TCP Urgent Pointer state confusion due to a race condition.<\/li>\n\t<li>CVE-2019-12264 - Logic flaw in IPv4 assignment by ipdhcpc DHCP client.<\/li>\n\t<li>CVE-2019-12265 - IGMP information leak via IGMPv3 specific membership report.<\/li>\n<\/ul><p>Devices using the following VxWorks versions that use the TCP\/IP stack may be affected by one or more of these CVEs:<\/p>\n\n<ul><li>All currently-supported versions of VxWorks (6.9.4.11, Vx7 SR540, Vx7 SR610).<\/li>\n\t<li>Previous versions of VxWorks from 6.5 onwards.<\/li>\n\t<li>All versions of the discontinued product Advanced Networking Technology (ANT).<\/li>\n\t<li>IPnet used as a standalone TCP\/IP network stack (prior to 2006).<\/li>\n\t<li>The VxWorks bootrom network stack.<\/li>\n<\/ul><p>WindRiver VxWorks products not affected:<\/p>\n\n<ul><li>VxWorks 5.3 through 6.4 inclusive.<\/li>\n\t<li>All VxWorks Cert versions.<\/li>\n\t<li>VxWorks 653 versions 2.x and earlier.<\/li>\n\t<li>VxWorks 653 MCE 3.x CertEdition and later.<\/li>\n\t<li>VxWorks 653 MCE 3.x may be affected.<\/li>\n<\/ul><p><strong>SUGGESTED ACTION<\/strong><\/p>\n\n<ul><li>Wind River has released a new version of the VxWorks real-time operating system (VxWorks 7 SR620) which includes patched code to address these vulnerabilities. If possible, upgrade to the latest version of VxWorks.<\/li>\n\t<li>Effectively segment networks and implement demilitarized zones (DMZs) with properly configured firewalls to selectively control and monitor traffic passed between zones.<\/li>\n\t<li>Minimize network exposure for all control system devices and\/or systems, and ensure that they are not accessible from the Internet.<\/li>\n\t<li>Locate control system networks and remote devices behind firewalls, and isolate them from the business network.<\/li>\n\t<li>When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.<\/li>\n<\/ul><p>Please be aware that additional mitigations or patches may be released by ICS device manufacturers and vendors.<\/p>\n\n<p><strong>REFERENCES<\/strong><\/p>\n\n<p>WindRiver Security Bulletin: <a href=\"https:\/\/www.windriver.com\/security\/announcements\/tcp-ip-network-stack-ipnet-urgent11\/\">https:\/\/www.windriver.com\/security\/announcements\/tcp-ip-network-stack-ipnet-urgent11\/<\/a><\/p>\n\n<p>Armis Security Bulletin: <a href=\"https:\/\/armis.com\/urgent11\/\">https:\/\/armis.com\/urgent11\/<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wind-river-vxworks-ipnet-tcpip-stack-vulnerabilities","alert_type":397,"serial_number":"AL19-015","subject":null,"moderation_state":"published","external_url":null},{"nid":1577,"title":"Google Chrome security advisory","uuid":"7f431242-feda-41de-a94c-fb743c09bcfd","banner":null,"lang":"en","date_modified":"2019-07-31","date_modified_ts":"2019-07-31T18:50:44Z","date_created":"2019-07-31T18:50:44Z","summary":null,"body":["<article data-history-node-id=\"1577\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-159<\/strong><br \/><strong>Date: 31 July 2019<\/strong><\/p>\n\n<p>On 30 July 2019 Google released security updates to address vulnerabilities affecting its Chrome browser for desktop and Android. A remote actor could exploit some of these vulnerabilities to run arbitrary commands on the affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/07\">https:\/\/chromereleases.googleblog.com\/2019\/07<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-4","alert_type":396,"serial_number":"AV19-159","subject":null,"moderation_state":"published","external_url":null},{"nid":1578,"title":"Cisco security advisory","uuid":"dbd08d57-6850-4c56-b406-e3ec4472ac0b","banner":null,"lang":"en","date_modified":"2019-08-02","date_modified_ts":"2019-08-02T20:04:43Z","date_created":"2019-08-02T20:03:59Z","summary":null,"body":["<article data-history-node-id=\"1578\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-160<\/strong><br \/><strong>Date: 2 August 2019<\/strong><\/p>\n\n<p>On 31 July 2019 Cisco released a security advisory to address a vulnerability affecting its Nexus 9000 Series Fabric Switches. The vulnerability, rated high, affects these switches if they are running in ACI mode and have a software version prior to 13.2(7f) or any 14.x release. The vulnerability could allow an unauthenticated actor on the same network as the switch to cause a denial of service condition or to execute arbitrary code with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-29","alert_type":396,"serial_number":"AV19-160","subject":null,"moderation_state":"published","external_url":null},{"nid":1579,"title":"NVIDIA security advisory","uuid":"2dc81443-2089-462d-88c9-f34c18a50a26","banner":null,"lang":"en","date_modified":"2019-08-07","date_modified_ts":"2019-08-07T15:52:38Z","date_created":"2019-08-07T15:52:38Z","summary":null,"body":["<article data-history-node-id=\"1579\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-161<\/strong><br \/><strong>Date: 7 August 2019<\/strong><\/p>\n\n<p>On 2 August 2019 NVIDIA released security updates to address vulnerabilities affecting its NVIDIA GPU Display Driver. These updates address issues that may lead to denial of service, escalation of privileges, or local code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4841\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4841<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-4","alert_type":396,"serial_number":"AV19-161","subject":null,"moderation_state":"published","external_url":null},{"nid":1580,"title":"VMware security advisory","uuid":"b4700dc0-aedb-43ce-bfe4-04cfc1f0fc7d","banner":null,"lang":"en","date_modified":"2019-08-08","date_modified_ts":"2019-08-08T12:05:06Z","date_created":"2019-08-08T12:02:25Z","summary":null,"body":["<article data-history-node-id=\"1580\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-162<\/strong><br \/><strong>Date:\u00a08 August 2019<\/strong><\/p>\n\n<p>On 2 August 2019 VMware released security updates to address vulnerabilities affecting VMware vSphere ESXi, VMware Workstation, and VMware Fusion. These updates address issues that may lead to information disclosure, denial of service, escalation of privileges, or local code execution. The most serious vulnerability, identified as CVE-2019-5684, can be exploited only if the host has an affected NVIDIA graphics driver.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the VMware Security Advisory webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0012.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0012.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-16","alert_type":396,"serial_number":"AV19-162","subject":null,"moderation_state":"published","external_url":null},{"nid":1581,"title":"Android security advisory","uuid":"177334ce-9333-40c7-8609-ee0c304ba78d","banner":null,"lang":"en","date_modified":"2019-08-08","date_modified_ts":"2019-08-08T12:16:32Z","date_created":"2019-08-08T12:16:32Z","summary":null,"body":["<article data-history-node-id=\"1581\" about=\"\/en\/alerts-advisories\/android-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-163<\/strong><br \/><strong>Date: 8 August 2019<\/strong><\/p>\n\n<p>On 5 August 2019 Google released security updates to address multiple vulnerabilities affecting Android devices. A remote actor could exploit one of these vulnerabilities to execute arbitrary code in the context of a privileged process by sending a specially crafted file. In addition, Google has released Android patches to address critical vulnerabilities found in certain Qualcomm chipsets, which are used in many Android phones.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Android security bulletin and apply the necessary updates, when available:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-08-01\">https:\/\/source.android.com\/security\/bulletin\/2019-08-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-3","alert_type":396,"serial_number":"AV19-163","subject":null,"moderation_state":"published","external_url":null},{"nid":1582,"title":"Cisco security advisory","uuid":"8588a8be-7ad4-4ca9-bdd5-75173f6c3eed","banner":null,"lang":"en","date_modified":"2019-08-08","date_modified_ts":"2019-08-08T17:13:28Z","date_created":"2019-08-08T17:11:35Z","summary":null,"body":["<article data-history-node-id=\"1582\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-164<\/strong><br \/><strong>Date: 8 August 2019<\/strong><\/p>\n\n<p>On 6 and 7 August 2019 Cisco released several security updates to address multiple vulnerabilities affecting Cisco products. These updates address issues that may lead to information disclosure, denial of service, escalation of privileges, or execution of arbitrary code with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-30","alert_type":396,"serial_number":"AV19-164","subject":null,"moderation_state":"published","external_url":null},{"nid":1583,"title":"KDE security advisory","uuid":"1cbfd339-43fe-4f40-a2d1-c048f0c35962","banner":null,"lang":"en","date_modified":"2019-08-08","date_modified_ts":"2019-08-08T18:55:15Z","date_created":"2019-08-08T18:55:15Z","summary":null,"body":["<article data-history-node-id=\"1583\" about=\"\/en\/alerts-advisories\/kde-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-165<\/strong><br \/><strong>Date: 8 August 2019<\/strong><\/p>\n\n<p>On 7 August 2019 the KDE Project released a security update to address a vulnerability affecting its KDE desktop environment. Viewing a specially-crafted file using the KDE GUI file manager could inadvertently cause the execution of arbitrary code without the need to interact with the file.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the KDE Project Security Advisory and apply the necessary update:<\/p>\n<p><a href=\"https:\/\/kde.org\/info\/security\/advisory-20190807-1.txt\"> https:\/\/kde.org\/info\/security\/advisory-20190807-1.txt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/kde-security-advisory","alert_type":396,"serial_number":"AV19-165","subject":null,"moderation_state":"published","external_url":null},{"nid":1584,"title":"Intel security advisory","uuid":"7f3ad2b8-fe71-4e50-b06e-7c11db6f493a","banner":null,"lang":"en","date_modified":"2019-08-13","date_modified_ts":"2019-08-13T20:51:55Z","date_created":"2019-08-13T20:51:55Z","summary":null,"body":["<article data-history-node-id=\"1584\" about=\"\/en\/alerts-advisories\/intel-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-166<\/strong><br \/><strong>Date: 13 August 2019<\/strong><\/p>\n\n<p>On 13 August 2019 Intel released security updates to address vulnerabilities affecting some of its products, namely, Intel Computing Improvement Program, Intel Processor Identification Utility for Windows, and several Intel NUC models. These vulnerabilities could be exploited by an authenticated, local actor to obtain escalation of privileges, denial of service, or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft Security Updates webpage and apply the necessary updates:<\/p>\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\"> https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p> \n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-4","alert_type":396,"serial_number":"AV19-166","subject":null,"moderation_state":"published","external_url":null},{"nid":1585,"title":"Microsoft security advisory \u2013 August 2019 monthly rollup","uuid":"6de23892-a712-40c3-bf37-8ede9faec3f5","banner":null,"lang":"en","date_modified":"2019-08-13","date_modified_ts":"2019-08-13T20:55:27Z","date_created":"2019-08-13T20:55:27Z","summary":null,"body":["<article data-history-node-id=\"1585\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2019-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-167<\/strong><br \/><strong>Date: 13 August 2019<\/strong><\/p>\n\n<p>On 13 August 2019 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for several critical vulnerabilities, including new vulnerabilities in its Remote Desktop Protocol that are similar to the previously-disclosed \u2018Bluekeep\u2019 vulnerabilities. Successful exploitation could lead to unauthenticated remote code execution on the affected system, in addition to the possibility of exploits being able to self-propagate to other affected systems.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft Security Updates webpage and apply the necessary updates:<\/p>\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/312890cc-3673-e911-a991-000d3a33a34d\"> https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/312890cc-3673-e911-a991-000d3a33a34d<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p> \n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2019-monthly-rollup","alert_type":396,"serial_number":"AV19-167","subject":null,"moderation_state":"published","external_url":null},{"nid":1586,"title":"Siemens security advisory","uuid":"d2a60910-e244-4dfa-a84e-112f42ea20c4","banner":null,"lang":"en","date_modified":"2019-08-13","date_modified_ts":"2019-08-13T20:57:46Z","date_created":"2019-08-13T20:57:46Z","summary":null,"body":["<article data-history-node-id=\"1586\" about=\"\/en\/alerts-advisories\/siemens-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-168<\/strong><br \/><strong>Date: 13 August 2019<\/strong><\/p>\n\n<p>On 13 August 2019 Siemens released security updates to address vulnerabilities affecting various products. A remote, unauthenticated actor could cause a denial of service, execute arbitrary commands, upload and download files as well as change network data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft Security Updates webpage and apply the necessary updates:<\/p>\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\"> https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p> \n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/siemens-security-advisory-0","alert_type":396,"serial_number":"AV19-168","subject":null,"moderation_state":"published","external_url":null},{"nid":1627,"title":"Adobe security advisory","uuid":"4aa965ac-f657-468a-9fac-1adfad6cb0e7","banner":null,"lang":"en","date_modified":"2019-09-20","date_modified_ts":"2019-09-20T16:34:23Z","date_created":"2019-08-14T13:52:35Z","summary":null,"body":["<article data-history-node-id=\"1627\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-169<\/strong><br \/><strong>Date: 14 August 2019<\/strong><\/p>\n\n<p>On 13 August 2019 Adobe released several security updates to address 118 vulnerabilities affecting Adobe products, including Adobe Acrobat and Reader.<\/p>\n\n<p>These updates address issues that may lead to denial of service, escalation of privileges, or local code execution conditions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Updates webpage and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-4","alert_type":396,"serial_number":"AV19-169","subject":null,"moderation_state":"published","external_url":null},{"nid":1626,"title":"Dell security advisory","uuid":"c2e73f18-3326-4bd6-b8fa-ab09a85577e9","banner":null,"lang":"en","date_modified":"2019-09-20","date_modified_ts":"2019-09-20T15:52:20Z","date_created":"2019-08-15T14:32:24Z","summary":null,"body":["<article data-history-node-id=\"1626\" about=\"\/en\/alerts-advisories\/dell-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-170<\/strong><br \/><strong>Date: 15 August 2019<\/strong><\/p>\n\n<p>On 14 August 2019 Dell released security updates to address vulnerabilities affecting several versions of its Dell EMC Cyber Recovery product. The security update addresses vulnerabilities in multiple third party components within Dell EMC Cyber Recovery.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Dell Security Advisories and Notices webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/ca\/en\/cabsdt1\/details\/536445\/DSA-2019-121-Dell-EMC-Cyber-Recovery-Security-Update-for-Multiple-Third-Party-Components-Vulnerab\">https:\/\/www.dell.com\/support\/security\/ca\/en\/cabsdt1\/details\/536445\/DSA-2019-121-Dell-EMC-Cyber-Recovery-Security-Update-for-Multiple-Third-Party-Components-Vulnerab<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-2","alert_type":396,"serial_number":"AV19-170","subject":null,"moderation_state":"published","external_url":null},{"nid":1588,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"2f005ae1-c0f4-4bc8-a24c-6bd232047f0d","banner":null,"lang":"en","date_modified":"2019-08-15","date_modified_ts":"2019-08-15T14:44:48Z","date_created":"2019-08-15T14:44:48Z","summary":null,"body":["<article data-history-node-id=\"1588\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-173<\/strong><br \/><strong>Date: 15 August 2019<\/strong><\/p>\n\n<p>On 13 August 2019 a public report was published highlighting vulnerabilities with proof-of-concept (PoC) exploit code affecting smartRTU (Versions 2.02 and prior) and INEA ME-RTU (Versions 3.0 and prior) remote terminal unit products.<\/p>\n<p>Successful exploitation of these vulnerabilities may allow an actor to perform remote code execution and gain root access to the devices. <\/p>\n<p>The Cyber Centre encourages users and administrators to review the ICS-CERT Alert (ICS-ALERT-19-255-01) for recommended mitigations and contact their local Mitsubishi Electric representative for more information.<\/p>\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/alerts\/ics-alert-19-255-01\"> https:\/\/www.us-cert.gov\/ics\/alerts\/ics-alert-19-255-01<\/a><\/p>\n<p><a href=\"https:\/\/us.mitsubishielectric.com\/fa\/en\/about-us\/distributors\"> https:\/\/us.mitsubishielectric.com\/fa\/en\/about-us\/distributors<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p> \n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory","alert_type":398,"serial_number":"AV19-173","subject":null,"moderation_state":"published","external_url":null},{"nid":1625,"title":"[Control systems] OSIsoft security advisory","uuid":"c17ee9a6-5a60-4b39-a31c-00a4bc9d4bac","banner":null,"lang":"en","date_modified":"2019-09-20","date_modified_ts":"2019-09-20T15:50:32Z","date_created":"2019-08-15T14:52:12Z","summary":null,"body":["<article data-history-node-id=\"1625\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-171<\/strong><br \/><strong>Date: 15 August 2019<\/strong><\/p>\n\n<p>On 13 August 2019 OSIsoft released security updates to address vulnerabilities affecting OSIsoft PI Web API RESTful services. Successful exploitation of these vulnerabilities may allow an actor to disclose sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the ICS-CERT Advisory (ICSA-17-243-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-225-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-225-02<\/a><\/p>\n\n<p><a href=\"https:\/\/customers.osisoft.com\/s\/knowledgearticle?knowledgeArticleUrl=PI-Web-API-Multiple-security-vulnerabilities-resolved \">https:\/\/customers.osisoft.com\/s\/knowledgearticle?knowledgeArticleUrl=PI-Web-API-Multiple-security-vulnerabilities-resolved<\/a> (login required)<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory","alert_type":398,"serial_number":"AV19-171","subject":null,"moderation_state":"published","external_url":null},{"nid":1587,"title":"[Control systems] Delta Electronics security advisory","uuid":"4b80a715-2dbd-480e-9f0f-dc3a8c7f448b","banner":null,"lang":"en","date_modified":"2019-08-15","date_modified_ts":"2019-08-15T14:55:12Z","date_created":"2019-08-15T14:55:12Z","summary":null,"body":["<article data-history-node-id=\"1587\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-172<\/strong><br \/><strong>Date: 13 August 2019<\/strong><\/p>\n\n<p>On 13 August 2019 Delta Electronics released security updates to address vulnerabilities affecting Delta Industrial Automation DOPSoft.  Successful exploitation of these vulnerabilities may allow an actor to disclose sensitive information, perform remote code execution, or crash the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the ICS-CERT Advisory (ICSA-19-225-01) and apply the necessary manufacturer updates:<\/p>\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-225-01\"> https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-225-01 <\/a><\/p>\n<p><a href=\"http:\/\/www.deltaww.com\/services\/DownloadCenter2.aspx?secID=8&amp;pid=2&amp;tid=0&amp;CID=06&amp;itemID=060302&amp;typeID=1&amp;downloadID=&amp;title=&amp;dataType=8;&amp;check=1&amp;hl=en-US\"> http:\/\/www.deltaww.com\/services\/DownloadCenter2.aspx?secID=8&amp;pid=2&amp;tid=0&amp;CID=06&amp;itemID=060302&amp;typeID=1&amp;downloadID=&amp;title=&amp;dataType=8;&amp;check=1&amp;hl=en-US <\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p> \n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory","alert_type":398,"serial_number":"AV19-172","subject":null,"moderation_state":"published","external_url":null},{"nid":1624,"title":"[Control systems] Fuji Electric security advisory","uuid":"d8475422-b548-40df-9822-25cfd35e3907","banner":null,"lang":"en","date_modified":"2019-08-16","date_modified_ts":"2019-08-16T14:40:50Z","date_created":"2019-08-16T14:40:34Z","summary":null,"body":["<article data-history-node-id=\"1624\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-174<\/strong><br \/><strong>Date: 16 August 2019<\/strong><\/p>\n\n<p>On 15 August 2019 Fuji Electric released security updates to address vulnerabilities affecting the Alpha5 Smart Loader (versions prior to 4.2). Successful exploitation of these vulnerabilities may allow an actor to execute code under the privileges of the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the ICS-CERT Advisory (ICS Advisory (ICSA-19-227-02)) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-227-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-227-02<\/a><\/p>\n\n<p><a href=\"https:\/\/felib.fujielectric.co.jp\/download\/search2.htm?dosearch=1&amp;site=global&amp;lang=en&amp;documentGroup=software\">https:\/\/felib.fujielectric.co.jp\/download\/search2.htm?dosearch=1&amp;site=global&amp;lang=en&amp;documentGroup=software<\/a> (login required)<\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory","alert_type":398,"serial_number":"AV19-174","subject":null,"moderation_state":"published","external_url":null},{"nid":1589,"title":"Webmin security advisory","uuid":"459ca2f8-16b9-43e3-a407-c1abb24cfb40","banner":null,"lang":"en","date_modified":"2019-08-20","date_modified_ts":"2019-08-20T19:14:22Z","date_created":"2019-08-20T19:14:22Z","summary":null,"body":["<article data-history-node-id=\"1589\" about=\"\/en\/alerts-advisories\/webmin-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-175<\/strong><br \/><strong>Date: 20 August 2019<\/strong><\/p>\n\n<p>On 17 August 2019 Webmin released security updates to address a vulnerability that allows remote command execution in its Webmin product (versions 1.882 to 1.921) and Usermin product (versions prior to 1.780).<\/p>\n<p>The Cyber Centre encourages users and administrators to review the Webmin security updates webpage and apply the necessary updates: <\/p>\n<p><a href=\"http:\/\/webmin.com\/security.html\"> http:\/\/webmin.com\/security.html<\/a><\/p>\n\n\n<p><strong>Note to Readers<\/strong><\/p> \n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webmin-security-advisory","alert_type":396,"serial_number":"AV19-175","subject":null,"moderation_state":"published","external_url":null},{"nid":1623,"title":"VLC security advisory","uuid":"10e433e0-b8ed-4454-9124-0118ccbd4703","banner":null,"lang":"en","date_modified":"2019-08-21","date_modified_ts":"2019-08-21T18:34:08Z","date_created":"2019-08-21T14:58:08Z","summary":null,"body":["<article data-history-node-id=\"1623\" about=\"\/en\/alerts-advisories\/vlc-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-176<\/strong><br \/><strong>Date: 21 August 2019<\/strong><\/p>\n\n<p>On 19 August 2019 VideoLAN released security updates to address vulnerabilities affecting its VLC media player. One of these vulnerabilities could be exploited by a remote actor to execute arbitrary code with the privilege levels of the user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the VideoLAN security bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.videolan.org\/security\/sb-vlc308.html\">https:\/\/www.videolan.org\/security\/sb-vlc308.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vlc-security-advisory","alert_type":396,"serial_number":"AV19-176","subject":null,"moderation_state":"published","external_url":null},{"nid":1629,"title":"Cisco security advisory","uuid":"78b41742-7403-44ad-bfa4-25606e4cef6a","banner":null,"lang":"en","date_modified":"2019-08-21","date_modified_ts":"2019-08-21T19:07:01Z","date_created":"2019-08-21T19:07:01Z","summary":null,"body":["<article data-history-node-id=\"1629\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-177<\/strong><br \/><strong>Date: 21 August 2019<\/strong><\/p>\n\n<p>On 21 August 2019 Cisco released several security updates to address multiple vulnerabilities affecting Cisco products. These updates address issues that may lead to information disclosure, denial of service, escalation of privileges, or execution of arbitrary code with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-31","alert_type":396,"serial_number":"AV19-177","subject":null,"moderation_state":"published","external_url":null},{"nid":1590,"title":"Apple security advisory","uuid":"75ac35b3-251b-4425-95d5-f7549e626c40","banner":null,"lang":"en","date_modified":"2019-08-27","date_modified_ts":"2019-08-27T17:53:07Z","date_created":"2019-08-27T17:53:07Z","summary":null,"body":["<article data-history-node-id=\"1590\" about=\"\/en\/alerts-advisories\/apple-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-178<\/strong><br \/><strong>Date: 27 August 2019<\/strong><\/p>\n\n<p>On 26 August 2019 Apple released security updates to address vulnerabilities affecting some of its products. Of note is a vulnerability in iOS, which could allow a maliciously-crafted application to execute arbitrary code with system privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-4","alert_type":396,"serial_number":"AV19-178","subject":null,"moderation_state":"published","external_url":null},{"nid":1591,"title":"Apache security advisory","uuid":"53ae0d11-6907-42fa-ad28-1e0f0b893164","banner":null,"lang":"en","date_modified":"2019-08-28","date_modified_ts":"2019-08-28T15:20:55Z","date_created":"2019-08-28T15:20:55Z","summary":null,"body":["<article data-history-node-id=\"1591\" about=\"\/en\/alerts-advisories\/apache-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-179<\/strong><br \/><strong>Date: 28 August 2019<\/strong><\/p>\n\n<p>On 26 August 2019 Debian released a security advisory to address multiple Apache vulnerabilities. A local actor could exploit these vulnerabilities to take control of an affected system. Please note that other versions of Linux may also be affected.<\/p>\n\n<p>The vulnerabilities are identified by the following CVE\u2019s:<\/p>\n\n<p>\u00a0<\/p>\n\n<ul><li>CVE-2019-9517<\/li>\n\t<li>CVE-2019-10081<\/li>\n\t<li>CVE-2019-10082<\/li>\n\t<li>CVE-2019-10092<\/li>\n\t<li>CVE-2019-10097<\/li>\n\t<li>CVE-2019-10098<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Webmin security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.debian.org\/security\/2019\/dsa-4509\">https:\/\/www.debian.org\/security\/2019\/dsa-4509<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory","alert_type":396,"serial_number":"AV19-179","subject":null,"moderation_state":"published","external_url":null},{"nid":1621,"title":"Google Chrome security advisory","uuid":"87b49522-6123-40b3-9af0-bdb3e6f98db3","banner":null,"lang":"en","date_modified":"2019-08-28","date_modified_ts":"2019-08-28T19:39:07Z","date_created":"2019-08-28T19:39:07Z","summary":null,"body":["<article data-history-node-id=\"1621\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-180<\/strong><br \/><strong>Date: 26 August 2019<\/strong><\/p>\n\n<p>On 26 August 2019 Google announced the release of Chrome 76.0.3809.132 for Windows, Mac, and Linux. This release will address vulnerabilities that could allow for arbitrary code execution in the context of the browser.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary update when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/08\/stable-channel-update-for-desktop_26.html\">https:\/\/chromereleases.googleblog.com\/2019\/08\/stable-channel-update-for-desktop_26.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-5","alert_type":396,"serial_number":"AV19-180","subject":null,"moderation_state":"published","external_url":null},{"nid":1598,"title":"Active exploitation of VPN vulnerabilities","uuid":"1d9b6965-428a-4692-b5a2-252b48d30ad1","banner":null,"lang":"en","date_modified":"2019-09-05","date_modified_ts":"2019-09-05T15:27:55Z","date_created":"2019-08-29T12:57:49Z","summary":null,"body":["<article data-history-node-id=\"1598\" about=\"\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-016<\/strong><br \/><strong>Date: 28 August 2019<\/strong><\/p>\n\n<h3><strong>Audience<\/strong><\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h3><strong>Purpose<\/strong><\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3><strong>Overview<\/strong><\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<p>Due to the fact that VPN devices are typically Internet-facing, it is of the utmost importance that they be kept up to date with the latest patches.<\/p>\n\n<h3><strong>Assessment<\/strong><\/h3>\n\n<p><strong>Fortinet Fortigate VPN<\/strong><\/p>\n\n<p>Several vulnerabilities in the Fortinet Fortigate SSL VPN were discovered by the Black Hat presenters, including a previously undisclosed \u201cback door\u201d in the VPN. These vulnerabilities could allow remote actors to view sensitive information including plaintext usernames and passwords, change user passwords, and execute arbitrary code on the VPN server, among other things. Details of the most critical vulnerabilities are as follows:<\/p>\n\n<ul><li>CVE-2018-13382: A backdoor could allow an unauthenticated user to change SSL VPN user passwords. A software tool which is allegedly able to exploit this vulnerability has been released publicly.<\/li>\n\t<li>CVE-2018-13379: A path traversal vulnerability could allow a remote, unauthenticated actor to view sensitive information, including plaintext usernames and passwords.<\/li>\n\t<li>CVE-2018-13380: A cross-site scripting vulnerability.<\/li>\n\t<li>CVE-2018-13383: A remote code execution vulnerability that could allow an authenticated user to execute code on the VPN server.<\/li>\n<\/ul><p>These vulnerabilities affect various versions of the underlying Fortinet FortiOS software. Patches have been released for all known affected versions. See each respective CVE article in the references section for details.<\/p>\n\n<p>Should administrators not be able to apply the security patches or upgrade their VPNs immediately, Fortinet advises administrators to disable the SSL VPN as an immediate mitigation step. This can be done by disabling any firewall policies tied to SSL VPN, and then disabling the SSL VPN itself using the following commands:<\/p>\n\n<p><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">For FortiOS 5.2 and above branches:<\/span><\/span><\/strong><\/p>\n\n<p><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/strong><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">config vpn ssl settings<\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">unset source-interface<\/span><\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">end<\/span><\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">For FortiOS 5.0 and below branches:<\/span><\/span><\/strong><\/p>\n\n<p><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/strong><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">config vpn ssl settings<\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">set sslvpn-enable disable<\/span><\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">end<\/span><\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">Palo Alto GlobalProtect VPN<\/span><\/strong><\/span><\/p>\n\n<p>A vulnerability in the Palo Alto GlobalProtect VPN allows a remote, unauthenticated actor to execute arbitrary code on the VPN server (CVE-2019-1579). Proof of concept code has been publicly released and this vulnerability is being actively exploited, as observed by third-party researchers. This vulnerability affects various versions of the underlying Palo Alto PAN-OS software. Patches have been released for all known affected versions.<\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/strong><\/span><\/p>\n\n<p><strong>Pulse Connect Secure and Pulse Policy Secure VPN<\/strong><br \/>\nMultiple vulnerabilities in the Pulse Connect Secure (PCS) and Pulse Policy Secure (PPS) products have been discovered, including an arbitrary file read vulnerability (CVE-2019-11510), which could allow a remote, unauthenticated actor to view cached plaintext user passwords and other sensitive information. These vulnerabilities affect multiple versions of the PCS and PPS products. Patches have been released for all known affected versions.<\/p>\n\n<h3>References<\/h3>\n\n<p>Black Hat 2019 \u201cInfiltrating Corporate Intranet Like NSA\u201d presentation: <a href=\"https:\/\/i.blackhat.com\/USA-19\/Wednesday\/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf\">https:\/\/i.blackhat.com\/USA-19\/Wednesday\/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf<\/a><br \/>\nFortinet security advisories: <a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-384\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-384<\/a> (CVE-2018-13379), <a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-383\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-383<\/a> (CVE-2018-13380), <a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-389\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-389<\/a> (CVE-2018-13382), <a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-388\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-388<\/a> (CVE-2018-13383)<br \/>\nPalo Alto security advisory: <a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/158\">https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/158<\/a><br \/>\nPulse Secure security advisory: <a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44101\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44101<\/a><\/p>\n\n<h3>Note to Readers<\/h3>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities","alert_type":397,"serial_number":"AL19-016","subject":null,"moderation_state":"published","external_url":null},{"nid":1628,"title":"Cisco security advisory","uuid":"a5edff7c-c44c-4472-80ce-58efca4e42c0","banner":null,"lang":"en","date_modified":"2019-08-29","date_modified_ts":"2019-08-29T19:25:27Z","date_created":"2019-08-29T19:25:27Z","summary":null,"body":["<article data-history-node-id=\"1628\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-181<\/strong><br \/><strong>Date: 29 August 2019<\/strong><\/p>\n\n<p>On 28 August 2019 Cisco released several security updates to address multiple vulnerabilities affecting Cisco products.  Of critical importance is the Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability (CVE-2019-12643).  This update addresses an issue that may allow a remote actor to bypass authentication on the managed Cisco IOS XE device.  The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates:<\/p>\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"> https:\/\/tools.cisco.com\/security\/center\/publicationListing.x <\/a><\/p>\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190828-iosxe-rest-auth-bypass\"> https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20190828-iosxe-rest-auth-bypass <\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p> \n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-32","alert_type":396,"serial_number":"AV19-181","subject":null,"moderation_state":"published","external_url":null},{"nid":1592,"title":"[Control systems] Datalogic security advisory","uuid":"c8c0b91e-b74e-43a1-ad0e-4b7b8b95b702","banner":null,"lang":"en","date_modified":"2019-08-30","date_modified_ts":"2019-08-30T16:49:22Z","date_created":"2019-08-30T16:49:22Z","summary":null,"body":["<article data-history-node-id=\"1592\" about=\"\/en\/alerts-advisories\/control-systems-datalogic-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-184<\/strong><br \/><strong>Date: 27 August 2019<\/strong><\/p>\n\n<p>On 27 August 2019 Datalogic released a security update to address a vulnerability affecting the AV7000 Linear Barcode Scanner (all versions prior to 4.6.0.0). Successful exploitation of this vulnerability may allow a remote actor to bypass authentication and remotely execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the ICS Advisory (ICSA-19-239-02) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-239-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-239-02<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-datalogic-security-advisory","alert_type":398,"serial_number":"AV19-184","subject":null,"moderation_state":"published","external_url":null},{"nid":1593,"title":"[Control systems] Change Healthcare security advisory","uuid":"59630fe2-9fef-42b9-b11b-619e836e27bb","banner":null,"lang":"en","date_modified":"2019-08-30","date_modified_ts":"2019-08-30T17:03:46Z","date_created":"2019-08-30T16:57:58Z","summary":null,"body":["<article data-history-node-id=\"1593\" about=\"\/en\/alerts-advisories\/control-systems-change-healthcare-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-182<\/strong><br \/><strong>Date: 29 August 2019<\/strong><\/p>\n\n<p>On 29 August 2019 Change Healthcare released security updates to address vulnerabilities affecting the following Change Healthcare Cardiology Devices:<\/p>\n\n<ul><li>Horizon Cardiology 11.x and earlier<\/li>\n\t<li>Horizon Cardiology 12.x<\/li>\n\t<li>McKesson Cardiology 13.x<\/li>\n\t<li>McKesson Cardiology 14.x<\/li>\n\t<li>Change Healthcare Cardiology 14.1.x<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow a local actor to execute unauthorized arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the ICS Medical Advisory (ICSMA-19-241-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-241-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-241-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-change-healthcare-security-advisory","alert_type":398,"serial_number":"AV19-182","subject":null,"moderation_state":"published","external_url":null},{"nid":1620,"title":"[Control systems] Delta Controls security advisory","uuid":"220d05d1-e1c2-45a8-8ed8-ebd8b1023e86","banner":null,"lang":"en","date_modified":"2019-08-30","date_modified_ts":"2019-08-30T17:06:50Z","date_created":"2019-08-30T17:06:50Z","summary":null,"body":["<article data-history-node-id=\"1620\" about=\"\/en\/alerts-advisories\/control-systems-delta-controls-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-183<\/strong><br \/><strong>Date: 27 August 2019<\/strong><\/p>\n\n<p>On 27 August 2019 Delta Controls released security updates to address vulnerabilities affecting the following Delta Controls enteliBUS Controllers:<\/p>\n\n<ul><li>enteliBUS Manager firmware Versions 3.40 R5 build 571848 and prior<\/li>\n\t<li>enteliBUS Manager Touch (eBMGR-TCH) firmware Versions 3.40 R5 build 571848 and prior<\/li>\n\t<li>enteliBUS Controller (eBCON) firmware Versions 3.40 R5 build 571848 and prior<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow a remote actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the ICS Advisory (ICSA-19-239-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-239-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-239-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-controls-security-advisory","alert_type":398,"serial_number":"AV19-183","subject":null,"moderation_state":"published","external_url":null},{"nid":1594,"title":"Mozilla security advisory","uuid":"8b5649c4-2e1f-4202-8401-d8474c7d6db3","banner":null,"lang":"en","date_modified":"2019-09-04","date_modified_ts":"2019-09-04T12:53:41Z","date_created":"2019-09-04T12:53:41Z","summary":null,"body":["<article data-history-node-id=\"1594\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-185<\/strong><br \/><strong>Date: 4 September 2019<\/strong><\/p>\n\n<p>On 3 September 2019 Mozilla released Firefox 69, Firefox ESR 68.1 and Firefox ESR 60.9. These releases include security updates to address vulnerabilities that may allow for arbitrary code execution when running on Windows operating systems.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-25\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-25\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-26\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-26\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-27\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-27\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-5","alert_type":396,"serial_number":"AV19-185","subject":null,"moderation_state":"published","external_url":null},{"nid":1595,"title":"Supermicro security advisory ","uuid":"e877a0b5-bf7f-4686-8a5c-a18af44e41c6","banner":null,"lang":"en","date_modified":"2019-09-04","date_modified_ts":"2019-09-04T19:16:23Z","date_created":"2019-09-04T19:16:23Z","summary":null,"body":["<article data-history-node-id=\"1595\" about=\"\/en\/alerts-advisories\/supermicro-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-186<\/strong><br \/><strong>Date : 3 September 2019<\/strong><\/p>\n\n<p>On 3 September 2019 Supermicro disclosed vulnerabilities in the Virtual Media function of their Baseboard Management Controller (BMC) found in the Supermicro X9, X10 and X11 platforms. Successful exploitation of these vulnerabilities may allow a remote actor to gain unauthorized access to the Virtual Media function.<\/p>\n\n<p>Administrators should ensure BMC access is restricted to only an isolated private network.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Supermicro Security Vulnerability webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/www.supermicro.com\/support\/security_BMC_virtual_media.cfm\">https:\/\/www.supermicro.com\/support\/security_BMC_virtual_media.cfm<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/supermicro-security-advisory","alert_type":396,"serial_number":"AV19-186","subject":null,"moderation_state":"published","external_url":null},{"nid":1596,"title":"[Control systems] EZAutomation security advisory","uuid":"5cc2084e-6b80-482a-947d-d2bf1be94708","banner":null,"lang":"en","date_modified":"2019-09-04","date_modified_ts":"2019-09-04T19:29:23Z","date_created":"2019-09-04T19:28:07Z","summary":null,"body":["<article data-history-node-id=\"1596\" about=\"\/en\/alerts-advisories\/control-systems-ezautomation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-187<\/strong><br \/><strong>Date : 3 September 2019<\/strong><\/p>\n\n<p>On 3 September 2019 EZAutomation released security updates to address vulnerabilities affecting the EZ Touch Editor and EZ PLC Editor software. Successful exploitation of these vulnerabilities may allow an actor to execute code under the privileges of the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review ICS Advisory (ICSA-19-246-01) and ICS Advisory (ICSA-19-246-02) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-246-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-246-01<\/a><\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-246-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-246-02<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ezautomation-security-advisory","alert_type":398,"serial_number":"AV19-187","subject":null,"moderation_state":"published","external_url":null},{"nid":1597,"title":"Samba security advisory","uuid":"00ad0a44-41a1-4b33-ac9c-36c05eecd207","banner":null,"lang":"en","date_modified":"2019-09-05","date_modified_ts":"2019-09-05T13:26:29Z","date_created":"2019-09-05T13:26:29Z","summary":null,"body":["<article data-history-node-id=\"1597\" about=\"\/en\/alerts-advisories\/samba-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-188<\/strong><br \/><strong>Date: 3 September 2019<\/strong><\/p>\n\n<p>On 3 September 2019 Samba released security updates to address vulnerabilities affecting the Samba Client (CVE-2019-10197). Successful exploitation of these vulnerabilities may allow an actor to escape from the share path definition and gain access to the parent or root folder.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Samba Security Releases webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">https:\/\/www.samba.org\/samba\/history\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-advisory-1","alert_type":396,"serial_number":"AV19-188","subject":null,"moderation_state":"published","external_url":null},{"nid":1599,"title":"Cisco security advisory","uuid":"581906b3-8372-4bd7-9e91-5b43209a9760","banner":null,"lang":"en","date_modified":"2019-09-05","date_modified_ts":"2019-09-05T16:07:55Z","date_created":"2019-09-05T16:07:55Z","summary":null,"body":["<article data-history-node-id=\"1599\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-189<\/strong><br \/><strong>Date: 4 September 2019<\/strong><\/p>\n\n<p>On 4 September 2019 Cisco released several security updates to address multiple vulnerabilities affecting Cisco products. These updates address issues that may lead to information disclosure, or execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-33","alert_type":396,"serial_number":"AV19-189","subject":null,"moderation_state":"published","external_url":null},{"nid":1612,"title":"Exim security advisory","uuid":"8e958b6b-b486-4fdf-bdcf-87758cae43bd","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T17:39:01Z","date_created":"2019-09-06T15:43:59Z","summary":null,"body":["<article data-history-node-id=\"1612\" about=\"\/en\/alerts-advisories\/exim-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-190<\/strong><br \/><strong>Date: 6 September 2019<\/strong><\/p>\n\n<p>On 6 September 2019 Exim released a critical security update to address a vulnerability which may allow a local or remote actor to execute arbitrary code with root privileges. All versions up to and including 4.92.1 are vulnerable if the Exim server accepts TLS connections.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Exim Security Advisory webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.exim.org\/static\/doc\/security\/CVE-2019-15846.txt\">https:\/\/www.exim.org\/static\/doc\/security\/CVE-2019-15846.txt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-1","alert_type":396,"serial_number":"AV19-190","subject":null,"moderation_state":"published","external_url":null},{"nid":1615,"title":"PHP security advisory","uuid":"1d839437-f3b0-4420-89e2-598cf626679c","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T18:09:05Z","date_created":"2019-09-06T19:45:27Z","summary":null,"body":["<article data-history-node-id=\"1615\" about=\"\/en\/alerts-advisories\/php-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-191<\/strong><br \/><strong>Date: 06 September 2019<\/strong><\/p>\n\n<p>On 29 August 2019 PHP released security updates to address vulnerabilities in its core and bundled libraries (version 7.3.9, 7.2.22 and 7.1.32). Successful exploitation of some of these vulnerabilities may allow a remote actor to execute arbitrary code and compromise targeted servers. The Cyber Centre encourages users and administrators to review the PHP ChangeLog webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.php.net\/ChangeLog-7.php\">https:\/\/www.php.net\/ChangeLog-7.php<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-advisory","alert_type":396,"serial_number":"AV19-191","subject":null,"moderation_state":"published","external_url":null},{"nid":1618,"title":"Android security advisory","uuid":"dbdbbb3b-fd8f-418b-bd02-bf72028832f2","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T18:35:00Z","date_created":"2019-09-06T19:51:04Z","summary":null,"body":["<article data-history-node-id=\"1618\" about=\"\/en\/alerts-advisories\/android-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-192<\/strong><br \/><strong>Date: 06 September 2019<\/strong><\/p>\n\n<p>On 3 September 2019 Android released security updates to address vulnerabilities in Android versions from 7.1.1 to Android 10. Successful exploitation of some of these vulnerabilities may allow a remote actor to execute arbitrary code and gain full control of the device. The Cyber Centre encourages users and administrators to review the Android security bulletin and apply the necessary updates, when available:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-09-01.html\">https:\/\/source.android.com\/security\/bulletin\/2019-09-01.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-4","alert_type":396,"serial_number":"AV19-192","subject":null,"moderation_state":"published","external_url":null},{"nid":1616,"title":"[Control systems] Becton, Dickinson and Company (BD)","uuid":"87ab0595-4416-44c3-9bfe-6059c5e58909","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T18:29:23Z","date_created":"2019-09-06T19:54:03Z","summary":null,"body":["<article data-history-node-id=\"1616\" about=\"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-bd\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-193<\/strong><br \/><strong>Date: 06 September 2019<\/strong><\/p>\n\n<p>On 5 September 2019 Becton, Dickinson and Company released security updates to address vulnerabilities affecting the following versions of BD Pyxis, a medication management platform:<\/p>\n\n<ul><li>Pyxis ES Versions 1.3.4 through to 1.6.1<\/li>\n\t<li>Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow an actor to gain access to a device using expired Active Directory credentials and access protected data. The Cyber Centre encourages users and administrators to review ICS Medical Advisory (ICSMA-19-248-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-248-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-248-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-bd","alert_type":398,"serial_number":"AV19-193","subject":null,"moderation_state":"published","external_url":null},{"nid":1617,"title":"[Control systems] Red Lion Controls","uuid":"0195fabf-7139-4d36-b8fc-24deb8f3f08a","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T18:32:40Z","date_created":"2019-09-06T20:00:51Z","summary":null,"body":["<article data-history-node-id=\"1617\" about=\"\/en\/alerts-advisories\/control-systems-red-lion-controls\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-194<\/strong><br \/><strong>Date: 06 September 2019<\/strong><\/p>\n\n<p>On 5 September 2019 Red Lion Controls released security updates to address vulnerabilities affecting the following versions of Crimson, windows configuration software:<\/p>\n\n<ul><li>Crimson Versions 3.0<\/li>\n\t<li>Crimson Versions 3.1 prior to release 3112.00<\/li>\n<\/ul><p>Additionally, Red Lion Controls released security updates to address vulnerabilities affecting BT5000 and BT6000 series cellular modems.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow an actor to execute code, crash the device, or view protected data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Red Lion Security Bulletins and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/support.redlion.net\/hc\/en-us\/articles\/360033077531\">https:\/\/support.redlion.net\/hc\/en-us\/articles\/360033077531<\/a><\/p>\n\n<p><a href=\"https:\/\/support.redlion.net\/hc\/en-us\/articles\/360033036052\">https:\/\/support.redlion.net\/hc\/en-us\/articles\/360033036052<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-red-lion-controls","alert_type":398,"serial_number":"AV19-194","subject":null,"moderation_state":"published","external_url":null},{"nid":1614,"title":"Adobe security advisory","uuid":"68a7e697-03fc-49c4-8fdf-7040cd4e2938","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T17:59:31Z","date_created":"2019-09-10T17:07:03Z","summary":null,"body":["<article data-history-node-id=\"1614\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-195<\/strong><br \/><strong>Date: 10 September 2019<\/strong><\/p>\n\n<p>On 10 September 2019 Adobe released security updates to address vulnerabilities affecting some of its products. A remote actor could exploit some of these vulnerabilities to run arbitrary code on an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-5","alert_type":396,"serial_number":"AV19-195","subject":null,"moderation_state":"published","external_url":null},{"nid":1600,"title":"Google Chrome security advisory","uuid":"a0f26979-c52b-4d70-9dd5-8909ff966ac1","banner":null,"lang":"en","date_modified":"2019-09-11","date_modified_ts":"2019-09-11T13:27:20Z","date_created":"2019-09-11T13:27:20Z","summary":null,"body":["<article data-history-node-id=\"1600\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-196<\/strong><br \/><strong>Date: 10 September 2019<\/strong><\/p>\n\n<p>On 10 September 2019 Google announced the release of Chrome 77.0.3865.75 for Windows, Mac, and Linux. This release will address vulnerabilities that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary update when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/09\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2019\/09\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-6","alert_type":396,"serial_number":"AV19-196","subject":null,"moderation_state":"published","external_url":null},{"nid":1613,"title":"[Control systems] Siemens security advisory","uuid":"38545535-c385-4810-b646-45e58ef655f9","banner":null,"lang":"en","date_modified":"2019-09-11","date_modified_ts":"2019-09-11T17:18:48Z","date_created":"2019-09-11T17:18:48Z","summary":null,"body":["<article data-history-node-id=\"1613\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-199<\/strong><br \/><strong>Date: 10 September 2019<\/strong><\/p>\n\n<p>On 10 September 2019 Siemens released security updates to address vulnerabilities affecting multiple Siemens Products.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to access confidential information, execute code or cause a denial of service. The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-19-253-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-19-253-03)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-03<\/a><\/p>\n\n<p>ICS Advisory (ICSA-19-253-04)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-04\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-04<\/a><\/p>\n\n<p>ICS Advisory (ICSA-19-253-05)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-05\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-05<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory","alert_type":398,"serial_number":"AV19-199","subject":null,"moderation_state":"published","external_url":null},{"nid":1619,"title":"[Control systems] OSIsoft LLC security advisory","uuid":"174cab13-8395-49b8-86f4-735d4f65776f","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T18:38:41Z","date_created":"2019-09-11T17:33:47Z","summary":null,"body":["<article data-history-node-id=\"1619\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-llc-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-198<\/strong><br \/><strong>Date: 10 september 2019<\/strong><\/p>\n\n<p>On 10 September 2019 OSIsoft LLC released security updates to address vulnerabilities affecting the PI SQL Client 2018 (PI SQL Client OLEDB 2018).<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to access, change or delete confidential information, execute code or cause a denial of service. The Cyber Centre encourages users and administrators to review ICS Advisory (ICSA-19-253-06) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-06\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-06<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-llc-security-advisory","alert_type":398,"serial_number":"AV19-198","subject":null,"moderation_state":"published","external_url":null},{"nid":1601,"title":"[Control systems] Delta Electronics security advisory","uuid":"b4203617-20e1-4fd7-84e1-00cf6dc6701c","banner":null,"lang":"en","date_modified":"2019-09-11","date_modified_ts":"2019-09-11T17:45:24Z","date_created":"2019-09-11T17:45:24Z","summary":null,"body":["<article data-history-node-id=\"1601\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-197<\/strong><br \/><strong>Date: 10 September 2019<\/strong><\/p>\n\n<p>On 10 September 2019 Delta Electronics released security updates to address vulnerabilities affecting TPEditor (Versions 1.94 and prior) programming software for Delta text panels.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to access confidential information, execute code or crash the application. The Cyber Centre encourages users and administrators to review ICS Advisory (ICSA-19-253-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-0","alert_type":398,"serial_number":"AV19-197","subject":null,"moderation_state":"published","external_url":null},{"nid":1602,"title":"Microsoft security advisory \u2013 September 2019 monthly rollup","uuid":"082d7794-fb42-44c0-a1d8-aaa4474c550f","banner":null,"lang":"en","date_modified":"2019-09-11","date_modified_ts":"2019-09-11T17:57:33Z","date_created":"2019-09-11T17:57:33Z","summary":null,"body":["<article data-history-node-id=\"1602\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2019-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-200<\/strong><br \/><strong>Date: 10 septembre 2019<\/strong><\/p>\n\n<p>On 10 September 2019 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for several critical vulnerabilities, including vulnerabilities in its Remote Desktop Client (RDC) and Microsoft SharePoint. <\/p>\n\n<p>The RDC vulnerabilities would allow for arbitrary code execution on the local machine if that machine was to connect to a compromised or malicious server using the RDC. There is no method of forcing a machine to connect to a server, although machines could be tricked into connecting through social engineering campaigns or man-in-the-middle attacks.<\/p>\n\n<p>Another critical vulnerability is in Microsoft SharePoint. This vulnerability could allow a remote actor to upload a specially crafted SharePoint application package to a vulnerable SharePoint server and run arbitrary code. <\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft Security Updates webpage and apply the necessary updates:<\/p>\n\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/24f46f0a-489c-e911-a994-000d3a33c573\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/24f46f0a-489c-e911-a994-000d3a33c573<\/a><\/p>\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2019-monthly-rollup","alert_type":396,"serial_number":"AV19-200","subject":null,"moderation_state":"published","external_url":null},{"nid":1603,"title":"SAP security advisory","uuid":"a26c4442-d913-4799-b968-70100112204f","banner":null,"lang":"en","date_modified":"2019-09-12","date_modified_ts":"2019-09-12T19:46:44Z","date_created":"2019-09-12T19:44:50Z","summary":null,"body":["<article data-history-node-id=\"1603\" about=\"\/en\/alerts-advisories\/sap-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-201<\/strong><br \/><strong>Date: 10 September 2019<\/strong><\/p>\n\n<p>On 10 September 2019 SAP released security updates to address vulnerabilities affecting some of its products. Of note is a code injection vulnerability in SAP NetWeaver AS for Java which could lead to denial of service, information disclosure, or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the SAP Security Patch Day webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=525962506\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=525962506<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-0","alert_type":396,"serial_number":"AV19-201","subject":null,"moderation_state":"published","external_url":null},{"nid":1604,"title":"[Control systems] Philips security advisory","uuid":"765c90b5-bb84-4c70-a017-8c87c8fca881","banner":null,"lang":"en","date_modified":"2019-09-13","date_modified_ts":"2019-09-13T13:53:43Z","date_created":"2019-09-13T13:53:43Z","summary":null,"body":["<article data-history-node-id=\"1604\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-202<\/strong><br \/><strong>Date: 12 September 2019<\/strong><\/p>\n\n<p>On 12 September 2019 Philips released security updates to address vulnerabilities affecting the following versions of Philips IntelliVue WLAN, portable patient monitors:<\/p>\n\n<ul><li>IntelliVue MP monitors MP20-MP90 (M8001A\/2A\/3A\/4A\/5A\/7A\/8A\/10A)\n\t<ul><li>WLAN Version A, Firmware A.03.09<\/li>\n\t<\/ul><\/li>\n\t<li>IntelliVue MP monitors MP5\/5SC (M8105A\/5AS)\n\t<ul><li>WLAN Version A, Firmware A.03.09, Part #: M8096-67501<\/li>\n\t<\/ul><\/li>\n\t<li>IntelliVue MP monitors MP2\/X2 (M8102A\/M3002A)\n\t<ul><li>WLAN Version B, Firmware A.01.09, Part #: N\/A (Replaced by Version C)<\/li>\n\t<\/ul><\/li>\n\t<li>IntelliVue MP monitors MX800\/700\/600 (865240\/41\/42)\n\t<ul><li>WLAN Version B, Firmware A.01.09, Part #: N\/A (Replaced by Version C)<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow an actor to cause corruption of the IntelliVue WLAN firmware and impact to the data flow of the wireless modules.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Philips Security Bulletin and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security\">https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory","alert_type":398,"serial_number":"AV19-202","subject":null,"moderation_state":"published","external_url":null},{"nid":1605,"title":"Active exploitation of VPN vulnerabilities","uuid":"cf6ccd62-5985-459e-8481-0de663fb682f","banner":null,"lang":"en","date_modified":"2019-09-17","date_modified_ts":"2019-09-17T22:20:59Z","date_created":"2019-09-17T22:19:13Z","summary":null,"body":["<article data-history-node-id=\"1605\" about=\"\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-016 UPDATE 1<\/strong><br \/><strong>Date: 17 September 2019<\/strong><\/p>\n\n<h3><strong>UPDATE 1<\/strong><\/h3>\n\n<p>The purpose of this update is to provide further information, including an \u2018Indication of a Compromise\u2019 section under each VPN product as well as a \u2018Suggested Action\u2019 section with more general methods of mitigating a possible compromise.<\/p>\n\n<h3><strong>AUDIENCE<\/strong><\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h3><strong>PURPOSE<\/strong><\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3><strong>OVERVIEW<\/strong><\/h3>\n\n<p>The Cyber Centre has become aware of widespread exploitation attempts being made against Virtual Private Networks (VPNs). A recent Black Hat 2019 presentation on VPN vulnerabilities has triggered heightened interest in exploiting vulnerabilities present in multiple VPN products, including Fortinet Fortigate, Palo Alto GlobalProtect, and Pulse Secure. In some cases, proof of concept code and exploitation tools have been published on the Internet. Due to the fact that VPN devices are typically Internet-facing, it is of the utmost importance that they be kept up to date with the latest patches.<\/p>\n\n<h3><strong><strong><strong>ASSESSMENT<\/strong><\/strong><\/strong><\/h3>\n\n<p><strong>Fortinet Fortigate VPN<\/strong><br \/>\nSeveral vulnerabilities in the Fortinet Fortigate SSL VPN were discovered by the Black Hat presenters, including a previously undisclosed \u201cback door\u201d in the VPN. These vulnerabilities could allow remote actors to view sensitive information including plaintext usernames and passwords, change user passwords, and execute arbitrary code on the VPN server, among other things. Details of the most critical vulnerabilities are as follows:<\/p>\n\n<ul><li>CVE-2018-13382: A backdoor could allow an unauthenticated user to change SSL VPN user passwords. A software tool which is allegedly able to exploit this vulnerability has been released publicly.<\/li>\n\t<li>CVE-2018-13379: A path traversal vulnerability could allow a remote, unauthenticated actor to view sensitive information, including plaintext usernames and passwords.<\/li>\n\t<li>CVE-2018-13380: A cross-site scripting vulnerability.<\/li>\n\t<li>CVE-2018-13383: A remote code execution vulnerability that could allow an authenticated user to execute code on the VPN server.<\/li>\n<\/ul><p>These vulnerabilities affect various versions of the underlying Fortinet FortiOS software. Patches have been released for all known affected versions. See each respective CVE article in the references section for details.<\/p>\n\n<p>Should administrators not be able to apply the security patches or upgrade their VPNs immediately, Fortinet advises administrators to disable the SSL VPN as an immediate mitigation step. This can be done by disabling any firewall policies tied to SSL VPN, and then disabling the SSL VPN itself using the following commands:<\/p>\n\n<p><strong><strong><strong><strong><strong><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">For FortiOS 5.2 and above branches:<\/span><\/span><\/strong> <\/strong><\/strong><\/strong><\/strong><\/strong><br \/><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><br \/>\nalign=\"LEFT\" dir=\"LTR\"<span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">config vpn ssl settings<\/span><br \/><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">unset source-interface<\/span><\/span><br \/><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">end<\/span><\/span><\/p>\n\n<p><strong><strong><strong><strong><strong><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">For FortiOS 5.0 and below branches:<\/span><\/span><\/strong> <\/strong><\/strong><\/strong><\/strong><\/strong><br \/><strong><strong><strong><strong><strong><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/strong> <\/strong><\/strong><\/strong><\/strong><\/strong><br \/>\nalign=\"LEFT\" dir=\"LTR\"<span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">config vpn ssl settings<\/span><br \/><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">set sslvpn-enable disable<\/span><\/span><br \/><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">end<\/span> <\/span><\/p>\n\n<p><strong><strong><strong><strong><strong>Indication of a Compromise: <\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n<ul><li>Checks device logs for HTTP GET requests to \/remote\/fgt_lang with the lang parameter set. A request of this nature could be attempting to exploit CVE-2018-13379. For example, an HTTP request which attempts to read a file called \u2018sslvpn_websessions\u2019, which can contain plaintext usernames and passwords, would appear as an HTTP request to the path \/remote\/fgt_lang?lang=\/..\/..\/..\/..\/\/\/\/\/\/\/\/\/\/dev\/cmdb\/sslvpn_websession.<\/li>\n\t<li>Check device logs for HTTP POST requests to \/remote\/logincheck with a \u2018magic\u2019 parameter set. A request of this nature is attempting to exploit CVE-2018-13382.<\/li>\n<\/ul><p align=\"LEFT\" dir=\"LTR\"><strong><strong><strong><strong><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">Palo Alto GlobalProtect VPN<\/span><\/strong><\/span> <\/strong><\/strong><\/strong><\/strong><\/strong><br \/>\nA vulnerability in the Palo Alto GlobalProtect VPN allows a remote, unauthenticated actor to execute arbitrary code on the VPN server (CVE-2019-1579). Proof of concept code has been publicly released and this vulnerability is being actively exploited, as observed by third-party researchers. This vulnerability affects various versions of the underlying Palo Alto PAN-OS software. Patches have been released for all known affected versions.<\/p>\n\n<p><strong><strong><strong><strong><strong>Indication of a Compromise: <\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n<ul><li>Check device logs for HTTP POST requests to \/sslmgr with the \u2018scep-profile-name' parameter set.<\/li>\n<\/ul><p><strong><strong><strong><strong><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/strong><\/span> <\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n<p><strong>Pulse Connect Secure and Pulse Policy Secure VPN<\/strong><br \/>\nMultiple vulnerabilities in the Pulse Connect Secure (PCS) and Pulse Policy Secure (PPS) products have been discovered, including an arbitrary file read vulnerability (CVE-2019-11510), which could allow a remote, unauthenticated actor to view cached plaintext user passwords and other sensitive information.<\/p>\n\n<p>These vulnerabilities affect multiple versions of the PCS and PPS products. Patches have been released for all known affected versions<\/p>\n\n<p><strong><strong><strong><strong><strong>Indication of a Compromise: <\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n<ul><li>Check device logs for HTTP GET requests containing \/dana\/html5acc\/guacamole\/, which is indicative of attempts to exploit CVE-2019-11510. For example, a request attempting to download the \/etc\/passwd file would appear as an HTTP request to the path \/dana-na\/..\/dana\/html5acc\/guacamole\/..\/..\/..\/..\/..\/..\/etc\/passwd?\/dana\/html5acc\/guacamole\/. It should be noted that logging for this vector of compromise may not be enabled by default. In order to enable it, an administrator must go to System -Log\/Monitoring -User Access -Settings and check [x] Unauthenticated Requests.<\/li>\n\t<li>The arbitrary file read vulnerability could allow for an actor to obtain a session ID for an active session and use it to connect to the VPN server, bypassing authentication in the process, including two-factor authentication, if enabled. Example log lines are provided below and could be indicative of multiple active users on a single session.<\/li>\n\t<li>2019-08-14 09:35:32 \u2013 PulseSecure \u2013 [1.2.3.4] DOMAIN\\username \u2013 Remote address for user DOMAIN\\username changed from 1.2.3.4 to 5.6.7.8.<\/li>\n\t<li>2019-08-14 09:38:56 \u2013 PulseSecure \u2013 [1.2.3.4] DOMAIN\\username \u2013 Remote address for user DOMAIN\\username changed from 5.6.7.8 to .<\/li>\n<\/ul><p>Please note that it is possible for the IP address to legitimately change for a single client. However, frequent occurrences of an IP address changing within a single session should be treated with suspicion and scrutiny. In addition, connections from suspicious IP addresses or different user sessions coming from the same IP address should be treated as suspect.<\/p>\n\n<p>If there is evidence of a compromise, administrators should, in addition to patching, reset all credentials for both local accounts on the VPN server as well as accounts which have access to the VPN service.<\/p>\n\n<h3><strong><strong><strong><strong><strong><strong>SUGGESTED ACTION<\/strong> <\/strong><\/strong><\/strong><\/strong><\/strong><\/h3>\n\n<p>In addition to the VPN-specific indicators in the Assessment section to be aware of, below are more general steps administrators should take toward hardening their VPN services, regardless of make:<\/p>\n\n<ul><li>Patch VPN servers as quickly as possible, and check for indication of a compromise using the information provided for each vulnerability.<\/li>\n\t<li>Reset all user and administrator passwords after these vulnerabilities have been patched.<\/li>\n\t<li>Employ multi-factor authentication for users connecting to VPN services.<\/li>\n<\/ul><h3><strong><strong><strong><strong><strong><strong>REFERENCES<\/strong> <\/strong><\/strong><\/strong><\/strong><\/strong><\/h3>\n\n<p>Black Hat 2019 \u201cInfiltrating Corporate Intranet Like NSA\u201d presentation:<a href=\"https:\/\/i.blackhat.com\/USA-19\/Wednesday\/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf\">https:\/\/i.blackhat.com\/USA-19\/Wednesday\/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf<\/a><br \/>\nFortinet security advisories:<a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-384\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-384<\/a> (CVE-2018-13379),<a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-383\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-383<\/a> (CVE-2018-13380),<a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-389\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-389<\/a>(CVE-2018-13382),<a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-18-388\">https:\/\/fortiguard.com\/psirt\/FG-IR-18-388<\/a>(CVE-2018-13383)<br \/>\nPalo Alto security advisory:<a href=\"https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/158\">https:\/\/securityadvisories.paloaltonetworks.com\/Home\/Detail\/158<\/a><br \/>\nPulse Secure security advisory:<a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44101\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44101<\/a><br \/>\nVolexity \u201cVulnerable Private Networks: Corporate VPNs Exploited in the Wild\u201d blog post:<a href=\"https:\/\/www.volexity.com\/blog\/2019\/09\/11\/vulnerable-private-networks-corporate-vpns-exploited-in-the-wild\/\">https:\/\/www.volexity.com\/blog\/2019\/09\/11\/vulnerable-private-networks-corporate-vpns-exploited-in-the-wild\/<\/a><\/p>\n\n<h3><strong><strong><strong><strong><strong><strong>NOTE TO READERS<\/strong> <\/strong><\/strong><\/strong><\/strong><\/strong><\/h3>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities-0","alert_type":397,"serial_number":"AL19-016","subject":null,"moderation_state":"published","external_url":null},{"nid":1606,"title":"AMD Radeon security advisory","uuid":"b30d747f-45f7-47bb-8b93-99f27549e2c0","banner":null,"lang":"en","date_modified":"2019-09-18","date_modified_ts":"2019-09-18T16:13:40Z","date_created":"2019-09-18T16:13:40Z","summary":null,"body":["<article data-history-node-id=\"1606\" about=\"\/en\/alerts-advisories\/amd-radeon-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-207<\/strong><br \/><strong>Date : 16 September 2019<\/strong><\/p>\n\n<p>On 16 September 2019 AMD released a security update to address an out-of-bounds memory write vulnerability affecting systems hosting VMWare virtual machines and using AMD Radeon graphics drivers. The vulnerability, tracked as CVE-2019-5049, affects the Radeon RX 550 and the 550 Series products using the AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. An actor could exploit this vulnerability by supplying a malformed pixel shader inside the VMware guest operating system to the driver, potentially leading to arbitrary code execution on the host machine.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the AMD Product Security webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.amd.com\/en\/corporate\/product-security\">https:\/\/www.amd.com\/en\/corporate\/product-security<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-radeon-security-advisory","alert_type":396,"serial_number":"AV19-207","subject":null,"moderation_state":"published","external_url":null},{"nid":1607,"title":"VMware security bulletin","uuid":"43baad86-7940-4984-a511-3691949dbdd7","banner":null,"lang":"en","date_modified":"2019-09-18","date_modified_ts":"2019-09-18T16:25:49Z","date_created":"2019-09-18T16:25:49Z","summary":null,"body":["<article data-history-node-id=\"1607\" about=\"\/en\/alerts-advisories\/vmware-security-bulletin-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-206<\/strong><br \/><strong>Date : 16 September 2019<\/strong><\/p>\n\n<p>On 16 September 2019 VMware released security updates to address the following vulnerabilities affecting the VMware vSphere ESXi (ESXi) and VMware vCenter Server (vCenter) products:<\/p>\n\n<ul><li>CVE-2017-16544: VMware ESXi command injection vulnerability.<\/li>\n\t<li>CVE-2019-5531: ESXi Host Client, vCenter vSphere Client and vCenter vSphere Web Client information disclosure vulnerability.<\/li>\n\t<li>CVE-2019-5532: VMware vCenter Server information disclosure vulnerability.<\/li>\n\t<li>CVE-2019-5534: VMware vCenter Server Information disclosure vulnerability in vAppConfig properties.<\/li>\n<\/ul><p>A remote actor could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users to review the VMware Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0013.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0013.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-bulletin-6","alert_type":396,"serial_number":"AV19-206","subject":null,"moderation_state":"published","external_url":null},{"nid":1608,"title":"[Control systems] Siemens security advisory","uuid":"168d899d-fa44-4f44-97c2-e5d0ad20f3b5","banner":null,"lang":"en","date_modified":"2019-09-18","date_modified_ts":"2019-09-18T16:38:39Z","date_created":"2019-09-18T16:38:39Z","summary":null,"body":["<article data-history-node-id=\"1608\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-205<\/strong><br \/><strong>Date : 17 September 2019<\/strong><\/p>\n\n<p>On 17 September 2019 Siemens released a security update to address a vulnerability affecting SINEMA Remote Connect Server versions prior to 2.0 SP1. Successful exploitation of this vulnerability may allow an actor to gain unauthorized access and read confidential information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following ICS Advisory (ICSA-19-260-02) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-260-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-260-02<\/a> <\/p>\n\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-0","alert_type":398,"serial_number":"AV19-205","subject":null,"moderation_state":"published","external_url":null},{"nid":1609,"title":"[Control systems] Honeywell security advisory","uuid":"968e6388-9545-4a21-8b91-f9243eced4c7","banner":null,"lang":"en","date_modified":"2019-09-18","date_modified_ts":"2019-09-18T16:54:10Z","date_created":"2019-09-18T16:54:10Z","summary":null,"body":["<article data-history-node-id=\"1609\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-204<\/strong><br \/><strong>Date : 13 September 2019<\/strong><\/p>\n\n<p>On 13 September 2019 Honeywell released security updates to address vulnerabilities affecting their equIP\u00ae Series and Performance Series IP Cameras and NVRs. Successful exploitation of these vulnerabilities may allow an actor to access confidential information or cause a denial of service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Honeywell Security Bulletins and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.security.honeywell.com\/-\/media\/Security\/Resources\/PDF\/Product-Warranty\/Security_Notification_SN_2019-09-04-01_V4-pdf.pdf?la=en-US&amp;hash=929A620154F2390954FB4C2A28AC8C1E3B37D008\">https:\/\/www.security.honeywell.com\/-\/media\/Security\/Resources\/PDF\/Product-Warranty\/Security_Notification_SN_2019-09-04-01_V4-pdf.pdf?la=en-US&amp;hash=929A620154F2390954FB4C2A28AC8C1E3B37D008<\/a><\/p>\n\n<p><a href=\"https:\/\/www.security.honeywell.com\/-\/media\/Security\/Resources\/PDF\/Product-Warranty\/Security_Notification_SN_2019-09-13-02_V4-pdf.pdf?la=en-US&amp;hash=7FDD915D188FB3257E0E712FC6A3E520B45560AB\">https:\/\/www.security.honeywell.com\/-\/media\/Security\/Resources\/PDF\/Product-Warranty\/Security_Notification_SN_2019-09-13-02_V4-pdf.pdf?la=en-US&amp;hash=7FDD915D188FB3257E0E712FC6A3E520B45560AB<\/a><\/p>\n\n<p><a href=\"https:\/\/www.security.honeywell.com\/-\/media\/Security\/Resources\/PDF\/Product-Warranty\/Security_Notification_SN_2019-09-13-01_V4-pdf.pdf?la=en-US&amp;hash=163378B6E8A4681AF8D753B8CB35F03F2DD147C6\">https:\/\/www.security.honeywell.com\/-\/media\/Security\/Resources\/PDF\/Product-Warranty\/Security_Notification_SN_2019-09-13-01_V4-pdf.pdf?la=en-US&amp;hash=163378B6E8A4681AF8D753B8CB35F03F2DD147C6<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory","alert_type":398,"serial_number":"AV19-204","subject":null,"moderation_state":"published","external_url":null},{"nid":1610,"title":"[Control systems] Advantech security advisory","uuid":"30592104-0a5e-4242-b012-1453b54473bd","banner":null,"lang":"en","date_modified":"2019-09-18","date_modified_ts":"2019-09-18T17:00:13Z","date_created":"2019-09-18T17:00:13Z","summary":null,"body":["<article data-history-node-id=\"1610\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-203<\/strong><br \/><strong>Date : 17 September 2019<\/strong><\/p>\n\n<p>On 17 September 2019 Advantech released a security update to address a vulnerability affecting WebAccess Versions 8.4.1 and prior. Successful exploitation of this vulnerability may allow an actor to execute arbitrary code, access files and perform actions at a privileged level, or delete files on the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following ICS Advisory (ICSA-19-260-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-260-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-260-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory","alert_type":398,"serial_number":"AV19-203","subject":null,"moderation_state":"published","external_url":null},{"nid":1611,"title":"Google Chrome security advisory","uuid":"16cf6aa1-90d9-46c3-85ef-42b2d100b765","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T15:21:36Z","date_created":"2019-09-19T15:20:19Z","summary":null,"body":["<article data-history-node-id=\"1611\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-208<\/strong><br \/><strong>Date: 19 September 2019<\/strong><\/p>\n\n<p>On 18 September 2019 Google announced the release of Chrome 77.0.3865.90 for Windows, Mac, and Linux. This release will address vulnerabilities that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary update when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/09\/stable-channel-update-for-desktop_18.html\">https:\/\/chromereleases.googleblog.com\/2019\/09\/stable-channel-update-for-desktop_18.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-7","alert_type":396,"serial_number":"AV19-208","subject":null,"moderation_state":"published","external_url":null},{"nid":1622,"title":"F5 security bulletin","uuid":"e9f0fab2-c3ef-4775-9847-acbd2e270331","banner":null,"lang":"en","date_modified":"2019-09-19","date_modified_ts":"2019-09-19T20:17:36Z","date_created":"2019-09-19T20:17:02Z","summary":null,"body":["<article data-history-node-id=\"1622\" about=\"\/en\/alerts-advisories\/f5-security-bulletin\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-209<\/strong><br \/><strong>Date: 19 September 2019<\/strong><\/p>\n\n<p>On 19 September 2019 F5 released security advisories to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)<\/li>\n\t<li>Enterprise Manager<\/li>\n<\/ul><p>A remote actor may be able to connect to the affected interface to extract and\/or modify sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users to review the F5 Security Advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K04280042\">https:\/\/support.f5.com\/csp\/article\/K04280042<\/a><\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K05123525\">https:\/\/support.f5.com\/csp\/article\/K05123525<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-bulletin","alert_type":396,"serial_number":"AV19-209","subject":null,"moderation_state":"published","external_url":null},{"nid":1630,"title":"VMware security advisory","uuid":"b79a6962-9fcd-4fb7-a8b2-b307ac33e717","banner":null,"lang":"en","date_modified":"2019-09-20","date_modified_ts":"2019-09-20T19:27:41Z","date_created":"2019-09-20T19:24:16Z","summary":null,"body":["<article data-history-node-id=\"1630\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-210<\/strong><br \/><strong>Date: 20 September 2019<\/strong><\/p>\n\n<p>On 19 September 2019 VMware released security updates to address vulnerabilities affecting some of its products. Of note is a vulnerability, tracked as CVE-2019-5527, affecting ESXi, Workstation, Fusion, VMRC and Horizon Client with a CVSSv3 score of 8.5. A local actor with non-administrative access on the guest machine could exploit the vulnerability to run arbitrary code on the host.<\/p>\n\n<p>The Cyber Centre encourages users to review the VMware Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0014.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0014.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-17","alert_type":396,"serial_number":"AV19-210","subject":null,"moderation_state":"published","external_url":null},{"nid":1636,"title":"TFlower Ransomware Campaign","uuid":"dbcbe60e-d188-4a5e-8bd9-e268ccef4cf1","banner":null,"lang":"en","date_modified":"2019-09-30","date_modified_ts":"2019-09-30T14:53:39Z","date_created":"2019-09-23T19:41:10Z","summary":null,"body":["<article data-history-node-id=\"1636\" about=\"\/en\/alerts-advisories\/tflower-ransomware-campaign\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-201<\/strong><br \/><strong>Date: 20 September 2019<\/strong><\/p>\n\n<h2>Purpose<\/h2>\n\n<p>On 30 July 2019 a new variant of ransomware named TFlower was discovered. The Cyber Centre has become aware of this ransomware recently affecting the Canadian public.<\/p>\n\n<h2>Assessment<\/h2>\n\n<p>The initial infection vector for this malware appears to be through Remote Desktop services, and other infection vectors may include email spam and malicious attachments, deceptive downloads, botnets, malicious ads, web injects, fake updates and repackaged and infected installers. Once a malicious actor infects a system, they may attempt to move laterally across the network through tools such as PowerShell Empire, PSExec, etc.<\/p>\n\n<p>The malware will initially contact a Command and Control(C2) server to indicate its readiness to encrypt the contents on the target system. It will then delete shadow copies and disable recovery features in Windows 10 and create persistence by adding a key in the logged in user's software registry hive. It will encrypt files and mark them by inserting the string \"*tflower\" at the beginning of the file but will not change the filename.<\/p>\n\n<p>Finally the malware will update the C2 server and leave a ransom note named \u201c!_Notice_!.txt\u201d placed throughout the computer and on the Windows Desktop.<\/p>\n\n<p>The Cyber Centre recommends that all system owners apply the latest security patches immediately, and that system users are reminded to be vigilant when following unsolicited links and opening unexpected document attachments in emails, even if they come from known contacts.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<ul><li>Install the latest updates for the vulnerable operating systems.<\/li>\n\t<li>Disable Remote Desktop Services if not required. If required, closely monitor network traffic and the logs of any vulnerable systems for suspicious activity.<\/li>\n\t<li>Enable Network Level Authentication (NLA) on all currently supported versions of Windows. This is a partial mitigation which will prevent the spread of the malware. With NLA enabled, an actor would first need to have credentials to an account on the target system.<\/li>\n\t<li>Block TCP port 3389 on the firewall, if possible. This will prevent unauthorized access from the Internet.<\/li>\n\t<li>Never open attachments from unknown or unverified sources.<\/li>\n\t<li>Whitelist applications to prevent unauthorized applications from running.<\/li>\n\t<li>Use antivirus and ensure that it is diligently kept up to date.<\/li>\n\t<li>Minimize the number of users with administrative privileges and ensure users do not have privileges to install software on their devices without the authorization of an administrator.<\/li>\n\t<li>Disable macros for documents received via email.<\/li>\n\t<li>Follow the Government of Canada\u2019s guidance to stay CyberSafe <a href=\"https:\/\/www.getcybersafe.gc.ca\/index-en.aspx.\">https:\/\/www.getcybersafe.gc.ca\/index-en.aspx<\/a><\/li>\n<\/ul><h2>References<\/h2>\n\n<p>CCCS Alert on Critical Remote Desktop Vulnerability: <a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/critical-microsoft-remote-desktop-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/critical-microsoft-remote-desktop-vulnerability<\/a><\/p>\n\n<h2>Note to readers<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tflower-ransomware-campaign","alert_type":397,"serial_number":"AL19-201","subject":null,"moderation_state":"published","external_url":null},{"nid":1631,"title":"Microsoft security advisory","uuid":"2fa6027b-8419-4444-af47-cada471dd690","banner":null,"lang":"en","date_modified":"2019-09-24","date_modified_ts":"2019-09-24T15:56:32Z","date_created":"2019-09-24T15:55:38Z","summary":null,"body":["<article data-history-node-id=\"1631\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-211<\/strong><br \/><strong>Date: 23 September 2019<\/strong><\/p>\n\n<p>On 23 September 2019 Microsoft released two out-of-band patches to address recently disclosed vulnerabilities in Internet Explorer and Windows Defender. These vulnerabilities are being tracked as CVE-2019-1367 and CVE-2019-1255, respectively.\n<\/p>\n<p>The vulnerability in Internet Explorer could allow a remote, unauthenticated actor to run arbitrary code with the same privileges as the user.\n<\/p>\n<p>The vulnerability in Windows Defender could allow an actor to cause a denial of service condition on the victim machine by preventing users from executing legitimate system binaries. It should be noted that the actor would first require execution privileges on the victim machine.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the appropriate Microsoft update webpages and apply the necessary updates:\n<\/p>\n<p>Internet Explorer:<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1367\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1367<\/a>\n<\/p>\n<p>Windows Defender:<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1367\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-1367<\/a>\n<\/p>\n<p><strong>Note to Readers<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-4","alert_type":396,"serial_number":"AV19-211","subject":null,"moderation_state":"published","external_url":null},{"nid":1633,"title":"Adobe security advisory","uuid":"d66f4595-c85c-4dde-bdfd-377e4ac0555f","banner":null,"lang":"en","date_modified":"2019-09-25","date_modified_ts":"2019-09-25T19:38:42Z","date_created":"2019-09-25T19:38:42Z","summary":null,"body":["<article data-history-node-id=\"1633\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-212<\/strong><br \/><strong>Date: 25 September 2019<\/strong><\/p>\n\n<p>On 24 September 2019 Adobe released security updates to address vulnerabilities affecting ColdFusion, including two critical vulnerabilities. The first critical vulnerability, tracked as CVE-2019-8073, could allow a remote actor to run arbitrary code on an affected system. The second critical vulnerability, tracked as CVE-2019-8074, is a path traversal vulnerability which could be exploited to bypass access controls and read arbitrary files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb19-47.html\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb19-47.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-6","alert_type":396,"serial_number":"AV19-212","subject":null,"moderation_state":"published","external_url":null},{"nid":1632,"title":"VMware security advisory ","uuid":"9a5b1682-b5d8-4377-88c2-012a450fad3d","banner":null,"lang":"en","date_modified":"2019-09-26","date_modified_ts":"2019-09-26T12:47:00Z","date_created":"2019-09-26T12:00:18Z","summary":null,"body":["<article data-history-node-id=\"1632\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-213<br \/>\nDate: 26 September 2019<\/strong><\/p>\n\n<p><br \/>\nOn 25 September 2019 VMware released a security advisory to address a remote escalation of privilege vulnerability affecting VMware Cloud Foundation and VMware Harbor Container Registry for PCF versions 1.7 and 1.8. VMware Cloud Foundation is only affected if the optional \u2018Harbor Registry\u2019 component has been deployed. An actor with access to a network could exploit this vulnerability to take control of an affected system.<br \/><br \/>\nThe Cyber Centre encourages users to review the following VMware Advisory and apply the necessary updates or workarounds:<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0015.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0015.html<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-18","alert_type":396,"serial_number":"AV19-213","subject":null,"moderation_state":"published","external_url":null},{"nid":1634,"title":"Apple security advisory","uuid":"6c348f2f-1ecb-41cf-87ed-d5950a7ad92b","banner":null,"lang":"en","date_modified":"2019-09-26","date_modified_ts":"2019-09-26T19:45:44Z","date_created":"2019-09-26T19:27:17Z","summary":null,"body":["<article data-history-node-id=\"1634\" about=\"\/en\/alerts-advisories\/apple-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-214<\/strong><br \/><strong>Date: 24 September 2019<\/strong><\/p>\n\n<p>On 24 September 2019 Apple released security updates to address unspecified vulnerabilities affecting some of its products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-5","alert_type":396,"serial_number":"AV19-214","subject":null,"moderation_state":"published","external_url":null},{"nid":1635,"title":"Cisco security advisory","uuid":"9963e428-8556-40c1-a94b-bf11bef6c431","banner":null,"lang":"en","date_modified":"2019-09-26","date_modified_ts":"2019-09-26T19:57:55Z","date_created":"2019-09-26T19:34:13Z","summary":null,"body":["<article data-history-node-id=\"1635\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-215<\/strong><br \/><strong>Date: 26 September 2019<\/strong><\/p>\n\n<p>On 26 September 2019 Cisco released security advisories to address vulnerabilities affecting some of its products. Of note is a vulnerability affecting Cisco\u2019s IOx for IOS Software. An authenticated, remote actor could gain unauthorized access to the Guest Operating System as a root user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-34","alert_type":396,"serial_number":"AV19-215","subject":null,"moderation_state":"published","external_url":null},{"nid":1637,"title":"Exim security advisory","uuid":"896b5a40-8915-460a-99ba-210685bd2b88","banner":null,"lang":"en","date_modified":"2019-09-30","date_modified_ts":"2019-09-30T15:55:31Z","date_created":"2019-09-30T15:55:31Z","summary":null,"body":["<article data-history-node-id=\"1637\" about=\"\/en\/alerts-advisories\/exim-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-216<\/strong><br \/><strong>Date: 30 September 2019<\/strong><\/p>\n\n<p>On 30 September 2019 Exim released version 4.92.3 of their message transfer agent (MTA) to address a vulnerability, tracked as CVE-2019-16928, which may allow for denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Exim Security Advisory webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.exim.org\/static\/doc\/security\/CVE-2019-16928.txt\">https:\/\/www.exim.org\/static\/doc\/security\/CVE-2019-16928.txt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-2","alert_type":396,"serial_number":"AV19-216","subject":null,"moderation_state":"published","external_url":null},{"nid":1638,"title":"Foxit security advisory","uuid":"cfd0d2bc-0f52-42dc-8df2-cb9c3f0158d6","banner":null,"lang":"en","date_modified":"2019-09-30","date_modified_ts":"2019-09-30T20:02:09Z","date_created":"2019-09-30T20:02:09Z","summary":null,"body":["<article data-history-node-id=\"1638\" about=\"\/en\/alerts-advisories\/foxit-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-217<\/strong><br \/><strong>Date: 30 September 2019<\/strong><\/p>\n\n<p>On 29 September 2019 Foxit released version 9.7 of their Foxit Reader product to address vulnerabilities that may allow for denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Foxit Security Bulletins webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.foxitsoftware.com\/support\/security-bulletins.php\">https:\/\/www.foxitsoftware.com\/support\/security-bulletins.php<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory","alert_type":396,"serial_number":"AV19-217","subject":null,"moderation_state":"published","external_url":null},{"nid":1640,"title":"[Control systems] Yokogawa security advisory","uuid":"410549d0-096a-4e66-a1d5-db97e8b3b08d","banner":null,"lang":"en","date_modified":"2019-10-02","date_modified_ts":"2019-10-02T23:01:59Z","date_created":"2019-10-02T18:49:00Z","summary":null,"body":["<article data-history-node-id=\"1640\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-219<\/strong><br \/><strong>Date: 2 October 2019<\/strong><\/p>\n\n<p>On 1 October 2019 Yokogawa released a security advisory to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>Exaopc (R1.01.00 - R3.77.00)<\/li>\n\t<li>Exaplog (R1.10.00 - R3.40.00)<\/li>\n\t<li>Exaquantum (R1.10.00 - R3.02.00)<\/li>\n\t<li>Exaquantum\/Batch (R1.01.00 - R2.50.40)<\/li>\n\t<li>Exasmoc (All Revisions)<\/li>\n\t<li>Exarqe (All Revisions)<\/li>\n\t<li>GA10 (R1.01.01 - R3.05.01)<\/li>\n\t<li>InsightSuiteAE (R1.01.00 - R1.06.00)<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow a local actor to execute malicious code using the privilege of the affected service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Yokogawa Security Advisory and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/web-material3.yokogawa.com\/1\/28032\/files\/YSAR-19-0003-E.pdf\">https:\/\/web-material3.yokogawa.com\/1\/28032\/files\/YSAR-19-0003-E.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory","alert_type":398,"serial_number":"AV19-219","subject":null,"moderation_state":"published","external_url":null},{"nid":1639,"title":"[Control systems] Moxa security advisory","uuid":"b4adf82b-2f38-460e-847e-a301efe2be71","banner":null,"lang":"en","date_modified":"2019-10-02","date_modified_ts":"2019-10-02T22:59:12Z","date_created":"2019-10-02T22:41:38Z","summary":null,"body":["<article data-history-node-id=\"1639\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-218<\/strong><br \/><strong>Date: 2 October 2019<\/strong><\/p>\n\n<p>On 1 October 2019 Moxa released a security advisory to address vulnerabilities affecting the EDR-810 router (all versions 5.1 and prior). Successful exploitation of these vulnerabilities may allow a remote actor to execute code or access sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Moxa Security Advisory and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/edr-810-series-secure-router-vulnerabilities-(1)\">https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/edr-810-series-secure-router-vulnerabilities-(1)<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory","alert_type":398,"serial_number":"AV19-218","subject":null,"moderation_state":"published","external_url":null},{"nid":1641,"title":"Vulnerabilities exploited in VPN products used worldwide (NCSC Alert)","uuid":"10d1ac48-115f-4029-9b44-82be1ce8b312","banner":null,"lang":"en","date_modified":"2019-10-04","date_modified_ts":"2019-10-04T13:24:12Z","date_created":"2019-10-04T13:11:13Z","summary":null,"body":["<article data-history-node-id=\"1641\" about=\"\/en\/alerts-advisories\/vulnerabilities-exploited-vpn-products-used-worldwide-ncsc-alert\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-017\n  <br \/>\n  Date: 3 October 2019<\/strong>\n<\/p>\n<p><strong>AUDIENCE<\/strong>\n<\/p>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<p><strong>PURPOSE<\/strong>\n<\/p>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<p><strong>ASSESSMENT<\/strong>\n<\/p>\n<p>The National Cyber Security Centre (NCSC), the United Kingdom\u2019s independent authority on Cyber Security, has produced an Alert regarding their ongoing investigation of known vulnerabilities affecting a number of VPN products, dated 2 October 2019. The Cyber Centre would like to highlight this Alert as it provides valuable information to system owners and operators responsible for defending their systems and networks from cyber threats. The Cyber Centre previously reported on these vulnerabilities in September 2019; the NCSC report contains additional and updated information.\n<\/p>\n<p>The NCSC Alert can be found at:\n<\/p>\n<p><a href=\"https:\/\/www.ncsc.gov.uk\/news\/alert-vpn-vulnerabilities\">https:\/\/www.ncsc.gov.uk\/news\/alert-vpn-vulnerabilities<\/a>\n<\/p>\n<p>Should activity matching the content of either of these Alerts be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<p><strong>REFERENCES<\/strong>\n<\/p>\n<p>Cyber Centre Alert on Active Exploitation of VPN Vulnerabilities (AL19-016):\n<\/p>\n<p><a href=\"\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities-0\">https:\/\/cyber.gc.ca\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities-0<\/a>\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-exploited-vpn-products-used-worldwide-ncsc-alert","alert_type":397,"serial_number":"AL19-017","subject":null,"moderation_state":"published","external_url":null},{"nid":1642,"title":"Cisco security advisory","uuid":"d8a2051e-c5e2-4010-aa67-62201c605714","banner":null,"lang":"en","date_modified":"2019-10-04","date_modified_ts":"2019-10-04T19:06:51Z","date_created":"2019-10-04T19:01:37Z","summary":null,"body":["<article data-history-node-id=\"1642\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>AV19-220<br \/>\n4 October 2019<\/strong><\/p>\n\n<p>On 2 October 2019 Cisco released a number of security advisories to address vulnerabilities affecting multiple products. Of note, the Cisco Firepower Management Center is affected by multiple issues that could allow a remote actor to gain unauthorized access, gain elevated privileges or execute arbitrary commands of their choice.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p>For immediate attention, the Cisco Event Response Page link below highlights those vulnerabilities with a Security Impact Rating (SIR) of High:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/viewErp.x?alertId=ERP-72541\">https:\/\/tools.cisco.com\/security\/center\/viewErp.x?alertId=ERP-72541<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-35","alert_type":396,"serial_number":"AV19-220","subject":null,"moderation_state":"published","external_url":null},{"nid":1643,"title":"Ryuk Ransomware Campaign","uuid":"efdb1c92-b05b-4ce4-8364-baab0080efe8","banner":null,"lang":"en","date_modified":"2019-10-07","date_modified_ts":"2019-10-07T16:07:54Z","date_created":"2019-10-04T22:59:58Z","summary":null,"body":["<article data-history-node-id=\"1643\" about=\"\/en\/alerts-advisories\/ryuk-ransomware-campaign\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-202<br \/>\nDate: 04 October 2019<\/strong><br \/><br \/><strong>PURPOSE<\/strong><\/p>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<p><strong>Overview<\/strong><\/p>\n\n<p>The Cyber Centre is aware of multiple recently reported, high profile instances of the Ryuk ransomware affecting multiple entities, including municipal governments and public health and safety organizations in Canada and abroad. These compromises are assessed to be part of a larger, international campaign by the operators of Ryuk ransomware which may target additional sectors.<\/p>\n\n<p>The Cyber Centre has assessed that the Ryuk ransomware is the final step in a possible three-stage process against of victim networks by an organized and prolific actor or group of actors. The deployment of the Ryuk ransomware appears to come after the victim has been compromised first by Emotet and Trickbot.<\/p>\n\n<p><strong>Assessment<\/strong><\/p>\n\n<p>An important element of the Ryuk ransomware campaign, and a factor that differentiates itself from other ransomware seen recently, is that Ryuk is not directly compromising the affected systems. Ryuk relies on an initial infection by the Emotet malware, followed by a secondary deployment of Trickbot malware. This three-stage pattern of activity allows the actor to move laterally and infiltrate the entire victim network, determine the value of the data to the system owner and to set a ransom value accordingly. The use of Emotet and Trickbot, which were both originally designed to steal financial information and harvest credentials, suggests that the entity behind the compromise may also exfiltrate information they find valuable before deploying the Ryuk ransomware. The Cyber Centre has seen no direct evidence of data exfiltration occurring, although it is aware of reports that compromises similar to the current Ryuk campaign have been used for data theft.<\/p>\n\n<p>Media reporting indicates that, in some cases, there have been no ransom demands and therefore it is possible that the ransomware was deployed for the purpose of removing access to information rather than obtaining a payment. The Cyber Centre cannot verify this information and currently assesses that these compromises may be failed infections where the ransom note was not properly placed on the system.<\/p>\n\n<p><strong>Infection<\/strong><\/p>\n\n<p>The primary compromise vectors for the current Ryuk ransomware campaign are through malware spam containing malicious links or attachments. Exposed Remote Desktop Services (RDS), accessed using stolen or otherwise compromised credentials, may be an additional vector.<\/p>\n\n<p>Upon the initial successful compromise, the Emotet Trojan is downloaded and installed on the infected system. This trojan was originally designed as a banking malware, but later versions of this malware saw the addition of spamming and malware delivery services. Emotet uses functionality that helps the software evade detection by anti-malware products and uses worm-like capabilities to move laterally and infect other connected computers and new areas of the network. Emotet may remain on an infected system for some time as the actor controlling the malware gains more access to the target network.<\/p>\n\n<p>Following the use of Emotet to establish a foothold and maintain persistence on the victim network, Trickbot malware is downloaded and distributed to the compromised systems. Trickbot\u2019s capabilities include harvesting emails and credentials using the Mimikatz tool, using the Eternal Blue exploit to move laterally across the network and using the PowerShell Empire modules for post exploitation.\u00a0 These capabilities allow Trickbot to map out the network and give the malicious actor a better understanding of the target, including the value of the data.\u00a0 This malware may also remain on an infected system for some time, usually until the actor is ready to deploy the final portion.<\/p>\n\n<p>Finally, the Ryuk ransomware is downloaded and launched against strategically important systems in order to maximize interruptions.\u00a0 The malware\u2019s installer will attempt to stop anti-malware software and will install the appropriate version of Ryuk depending on a target system\u2019s architecture.\u00a0 The ransomware does not have the ability to move laterally within a network, but it can enumerate network shares and encrypt files across those it can access. Additionally, the ransomware will attempt to manipulate the volume shadow copies and delete backups to further cause disruption and to hinder attempts at restoring data without paying the ransom. At this stage, Ryuk will encrypt all non-executable files and place a ransom note on the encrypted systems.<\/p>\n\n<p><strong>Command and Control<\/strong><\/p>\n\n<p>The malware strains for Emotet and Trickbot communicate to the entity controlling the malware through command and control (C2) servers, but Ryuk itself shows no evidence of using C2 servers: once deployed it does not communicate further. The Ryuk ransomware appears to be tailored to each victim, even if modifications to the ransomware are minor. For this reason, hash values for known Ryuk infections will likely not be useful for detecting additional infections.<\/p>\n\n<p><strong>Detection<\/strong><\/p>\n\n<p>It is important to note that the presence of Emotet and\/or Trickbot do not necessarily imply that a system is also infected with Ryuk, but the presence of either of these two (Emotet, Trickbot) should merit a search for Ryuk indicators.\u00a0 Additionally, simply removing the Ryuk infection may not be enough to ensure that the infection chain is still not on a target system.\u00a0 If Ryuk is detected, system owners should search for Emotet and Trickbot malware as well. These may be discovered on networked systems that were not initially affected by the ransomware.<\/p>\n\n<p><strong>Suggested Action<\/strong><\/p>\n\n<p>The Cyber Centre recommends that all system owners apply the latest security patches and operating system updates for computers and equipment on their systems immediately, maintain the latest anti-virus signatures and that system users are reminded to be vigilant when following unsolicited links and opening unexpected document attachments in emails, even if they come from known contacts. The Cyber Centre further recommends that all system owners consider the following mitigations and enact those that apply to their networks and systems. These mitigations will make infection more difficult but may not eliminate the risk completely.\u00a0<\/p>\n\n<ul><li>Disable Remote Desktop Services if not required. If required, closely monitor network traffic and the logs of any vulnerable systems for suspicious activity.<\/li>\n\t<li>Block TCP port 3389 on the firewall, if possible. This will prevent unauthorized access from the Internet.<\/li>\n\t<li>Scan all incoming and outgoing e-mails to detect threats and prevent executable files from reaching the end users.<\/li>\n\t<li>Don\u2019t open links or attachments in emails from untrusted or unknown sources. Inspect the sender address carefully as the address text may differ from the real address.<\/li>\n\t<li>Implement architectural controls for network segregation.<\/li>\n\t<li>Whitelist applications to prevent unauthorized applications from running.<\/li>\n\t<li>Use anti-virus protection and ensure that it is diligently kept up to date.<\/li>\n\t<li>Minimize the number of users with administrative privileges and ensure users do not have privileges to install software on their devices without the authorization of an administrator.<\/li>\n\t<li>Execute daily backups of all critical systems, maintain offline and offsite copies of backup media and periodically execute a practice data restoration from backups, including key databases to ensure integrity of existing backups and processes.<\/li>\n\t<li>Disable macros for documents received via email.<\/li>\n\t<li>Follow the Government of Canada\u2019s guidance to stay CyberSafe<br \/><a href=\"https:\/\/www.getcybersafe.gc.ca\/index-en.aspx\">https:\/\/www.getcybersafe.gc.ca\/index-en.aspx<\/a>).<\/li>\n<\/ul><p><br \/><strong>REFERENCES<\/strong><\/p>\n\n<p>US-CERT EMOTET Alert:<br \/><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA18-201A\">https:\/\/www.us-cert.gov\/ncas\/alerts\/TA18-201A<\/a><\/p>\n\n<p>US-MSISAC Security Primer \u2013 TrickBot:<br \/><a href=\"https:\/\/www.cisecurity.org\/white-papers\/security-primer-trickbot\/\">https:\/\/www.cisecurity.org\/white-papers\/security-primer-trickbot\/<\/a><\/p>\n\n<p>UK-NCSC Ryuk ransomware targeting organisations globally:<br \/><a href=\"https:\/\/www.ncsc.gov.uk\/news\/ryuk-advisory\">https:\/\/www.ncsc.gov.uk\/news\/ryuk-advisory<\/a><\/p>\n\n<p><br \/><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ryuk-ransomware-campaign","alert_type":397,"serial_number":"AL19-202 ","subject":null,"moderation_state":"published","external_url":null},{"nid":1644,"title":"Intel security advisory","uuid":"3818d87e-ad8c-4497-a39d-1bccd473ecaf","banner":null,"lang":"en","date_modified":"2019-10-09","date_modified_ts":"2019-10-09T11:47:18Z","date_created":"2019-10-09T11:11:23Z","summary":null,"body":["<article data-history-node-id=\"1644\" about=\"\/en\/alerts-advisories\/intel-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>AV19-221<br \/>\n9 October 2019<\/strong><\/p>\n\n<p>On 8 October 2019 Intel released security updates to address vulnerabilities affecting several Intel NUC models. These vulnerabilities could be exploited by an authenticated, local actor to obtain escalation of privileges, denial of service, and\/or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Intel Product Security Center Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-5","alert_type":396,"serial_number":"AV19-221","subject":null,"moderation_state":"published","external_url":null},{"nid":1645,"title":"Apple security advisory","uuid":"38077140-ed85-42e9-9eb7-042443966dd3","banner":null,"lang":"en","date_modified":"2019-10-09","date_modified_ts":"2019-10-09T11:45:17Z","date_created":"2019-10-09T11:28:09Z","summary":null,"body":["<article data-history-node-id=\"1645\" about=\"\/en\/alerts-advisories\/apple-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>AV19-222<br \/>\n9 October 2019<\/strong><\/p>\n\n<p>On 7 October 2019 Apple released security updates to address vulnerabilities affecting some of its products. Of note is a kernel vulnerability in macOS Catalina which is addressed in version 10.15. Exploitation of this vulnerability could allow an application to execute arbitrary code with kernel privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">https:\/\/support.apple.com\/en-ca\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-6","alert_type":396,"serial_number":"AV19-222","subject":null,"moderation_state":"published","external_url":null},{"nid":1649,"title":"Microsoft security advisory \u2013 October 2019 monthly rollup","uuid":"217bf90d-e251-4132-80e4-80d9ab6af8e3","banner":null,"lang":"en","date_modified":"2019-10-11","date_modified_ts":"2019-10-11T16:53:29Z","date_created":"2019-10-10T16:58:27Z","summary":null,"body":["<article data-history-node-id=\"1649\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2019-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-224<\/strong><br \/><strong>Date : 10 October 2019<\/strong><\/p>\n\n<p>On 8 October 2019 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for nine critical remote code execution vulnerabilities, including two that affect the Remote Desktop Client (RDC) and Microsoft XML Core Services products.<\/p>\n\n<p>The RDC vulnerability would allow for arbitrary code execution on the local machine if that machine was to connect to a compromised or malicious server using the RDC. There is no method of forcing a machine to connect to a server, although machines could be tricked into connecting through social engineering campaigns or man-in-the-middle attacks.<\/p>\n\n<p>In addition, a vulnerability in the Microsoft XML Core Services MSXML parser could lead to arbitrary code execution if the local machine accesses a specially crafted website. The local user could be convinced to open the website through use of social engineering techniques.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft October 2019 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/28ef0a64-489c-e911-a994-000d3a33c573\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/28ef0a64-489c-e911-a994-000d3a33c573<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-october-2019-monthly-rollup","alert_type":396,"serial_number":"AV19-224","subject":null,"moderation_state":"published","external_url":null},{"nid":1650,"title":"SAP security advisory","uuid":"82b58ad4-778c-4848-bfe4-f6444ac0f722","banner":null,"lang":"en","date_modified":"2019-10-11","date_modified_ts":"2019-10-11T16:55:02Z","date_created":"2019-10-10T17:08:16Z","summary":null,"body":["<article data-history-node-id=\"1650\" about=\"\/en\/alerts-advisories\/sap-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-225<\/strong><br \/><strong>Date : 10 October 2019<\/strong><\/p>\n\n<p>On 8 October 2019 SAP released security updates to address vulnerabilities affecting some of its products. Of note is a missing authentication check, tracked as CVE-2019-0379, found in the SAP NetWeaver Process Integration.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the SAP Security Patch Day webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=528123050\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=528123050<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-1","alert_type":396,"serial_number":"AV19-225","subject":null,"moderation_state":"published","external_url":null},{"nid":1646,"title":"Android security advisory","uuid":"80438c7d-6cf7-42a3-94e6-726bdc8c8dfd","banner":null,"lang":"en","date_modified":"2019-10-10","date_modified_ts":"2019-10-10T17:26:38Z","date_created":"2019-10-10T17:26:38Z","summary":null,"body":["<article data-history-node-id=\"1646\" about=\"\/en\/alerts-advisories\/android-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-223<\/strong><br \/><strong>Date : 07 October 2019<\/strong><\/p>\n\n<p>On October 7 2019 Android published a Security Bulletin to address multiple vulnerabilities affecting android devices. Within the Security Bulletin is an elevation of privilege vulnerability (CVE-2019-2215) which affects Android 8.x and later. This vulnerability may be exploitable either through the installation of an untrusted application or through a specially crafted website that leverages additional exploits. In the latter case, the additional exploits would rely on vulnerabilities that may have been patched in past security updates. Once exploited the vulnerability would allow an actor to fully compromise an affected device. The following devices are vulnerable; however, this list is not exhaustive:<\/p>\n\n<ul><li>Google - Pixel 1, Pixel 1 XL, Pixel 2, Pixel 2XL<\/li>\n\t<li>Samsung - S7, S8, S9<\/li>\n\t<li>LG - Oreo LG phones<\/li>\n\t<li>Motorola - Moto Z3<\/li>\n\t<li>Huawei - P20<\/li>\n\t<li>Xiaomi - Redmi Note 5, Redmi 5A, A1<\/li>\n\t<li>Oppo - A3<\/li>\n<\/ul><p>Android announced that Pixel 1 and Pixel 2 devices will receive at patch as part of their October update. Pixel 3 and 3a are not affected by this vulnerability:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/pixel\/2019-10-01 \">https:\/\/source.android.com\/security\/bulletin\/pixel\/2019-10-01 <\/a><\/p>\n\n<p>Other manufacturers affected by this vulnerability have not yet announced security updates. The Cyber Centre encourages users and administrators to review the Android Security Bulletins webpage and apply the necessary security updates once they become available:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-10-01 \">https:\/\/source.android.com\/security\/bulletin\/2019-10-01 <\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-5","alert_type":396,"serial_number":"AV19-223","subject":null,"moderation_state":"published","external_url":null},{"nid":1647,"title":"[Control systems] Schneider Electric security advisory","uuid":"dbdd6d17-458e-4c97-a5a7-85599e9f1b2e","banner":null,"lang":"en","date_modified":"2019-10-10","date_modified_ts":"2019-10-10T17:33:30Z","date_created":"2019-10-10T17:33:30Z","summary":null,"body":["<article data-history-node-id=\"1647\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-227<\/strong><br \/><strong>Date: 10 October 2019<\/strong><\/p>\n\n<p>On 8 October 2019 Schneider Electric released security updates to address vulnerabilities affecting some of its products. Of note is an information disclosure vulnerability, tracked as CVE-2019-6849, in several of Schneider Electric\u2019s programmable logic controllers.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Schneider Electric Cybersecurity Support Portal webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.schneider-electric.com\/en\/work\/support\/cybersecurity\/overview.jsp\">https:\/\/www.schneider-electric.com\/en\/work\/support\/cybersecurity\/overview.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory","alert_type":398,"serial_number":"AV19-227","subject":null,"moderation_state":"published","external_url":null},{"nid":1648,"title":"iTerm2 security advisory","uuid":"5a4c8eb4-5f5c-498e-8aa2-e0d1bee9eb31","banner":null,"lang":"en","date_modified":"2019-10-10","date_modified_ts":"2019-10-10T17:43:41Z","date_created":"2019-10-10T17:43:41Z","summary":null,"body":["<article data-history-node-id=\"1648\" about=\"\/en\/alerts-advisories\/iterm2-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-226<\/strong><br \/><strong>Date : 09 October 2019<\/strong><\/p>\n\n<p>On 9 October 2019 the Mozilla Open Source Support Program (MOSS) released an advisory to address a Critical vulnerability found while reviewing the source code of iTerm2, a macOS terminal emulation program. Exploitation of this vulnerability by a remote actor may allow them to execute commands of their choice on the host computer.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review this advisory on Mozilla\u2019s Security Blog:<\/p>\n\n<p><a href=\"https:\/\/blog.mozilla.org\/security\/2019\/10\/09\/iterm2-critical-issue-moss-audit\/\">https:\/\/blog.mozilla.org\/security\/2019\/10\/09\/iterm2-critical-issue-moss-audit\/<\/a><\/p>\n\n<p>An updated version of the iTerm2 program can be downloaded from the product website:<\/p>\n\n<p><a href=\"https:\/\/iterm2.com\/downloads.html\">https:\/\/iterm2.com\/downloads.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/iterm2-security-advisory","alert_type":396,"serial_number":"AV19-226","subject":null,"moderation_state":"published","external_url":null},{"nid":1652,"title":"Google Chrome security advisory","uuid":"a99a2600-503c-485e-adea-26cf396ae168","banner":null,"lang":"en","date_modified":"2019-10-11","date_modified_ts":"2019-10-11T16:29:40Z","date_created":"2019-10-11T16:29:40Z","summary":null,"body":["<article data-history-node-id=\"1652\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-228<\/strong><br \/><strong>Date: 11 October 2019<\/strong><\/p>\n\n<p>On 10 October 2019 Google announced the release of Chrome 77.0.3865.120 for Windows, Mac, and Linux. This release will address vulnerabilities that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary update when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/10\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2019\/10\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-8","alert_type":396,"serial_number":"AV19-228","subject":null,"moderation_state":"published","external_url":null},{"nid":1651,"title":"Juniper Networks security advisory","uuid":"d4bcd4fe-34d1-4f0f-ad9c-c1ef1e25cc51","banner":null,"lang":"en","date_modified":"2019-10-11","date_modified_ts":"2019-10-11T18:56:48Z","date_created":"2019-10-11T18:56:48Z","summary":null,"body":["<article data-history-node-id=\"1651\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-229<\/strong><br \/><strong>Date: 11 October 2019<\/strong><\/p>\n\n<p>On 9 October 2019 Juniper Networks released several security bulletins to address vulnerabilities affecting some of its products. One bulletin of note is JSA10956, a privilege escalation vulnerability that could allow a local, authenticated actor to gain full control of the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Juniper Networks Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-1","alert_type":396,"serial_number":"AV19-229","subject":null,"moderation_state":"published","external_url":null},{"nid":1656,"title":"Adobe security advisory","uuid":"e94c3899-395b-4520-b400-e9ee97eac20c","banner":null,"lang":"en","date_modified":"2019-10-16","date_modified_ts":"2019-10-16T14:57:27Z","date_created":"2019-10-16T13:57:55Z","summary":null,"body":["<article data-history-node-id=\"1656\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-230<\/strong><br \/><strong>Date : 16 October 2019<\/strong><\/p>\n\n<p>On 15 October 2019 Adobe released security updates to address vulnerabilities affecting multiple products. Successful exploitation could allow for arbitrary code execution with the privileges of the current user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-49.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb19-49.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-7","alert_type":396,"serial_number":"AV19-230","subject":null,"moderation_state":"published","external_url":null},{"nid":1655,"title":"Oracle security advisory \u2013 October 2019 Critical Patch update","uuid":"ae449cd4-08b0-4190-8f76-8e0e8e8a6701","banner":null,"lang":"en","date_modified":"2019-10-16","date_modified_ts":"2019-10-16T14:54:43Z","date_created":"2019-10-16T14:04:56Z","summary":null,"body":["<article data-history-node-id=\"1655\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-october-2019-critical-patch-update\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-231<\/strong><br \/><strong>Date: 16 October 2019<\/strong><\/p>\n\n<p>On 15 October 2019 Oracle released their Critical Patch Update containing 219 security fixes affecting various Oracle products. A remote, unauthenticated actor could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Oracle Critical Patch Update Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2019-5072832.html\">https:\/\/www.oracle.com\/technetwork\/security-advisory\/cpuoct2019-5072832.html\\<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-october-2019-critical-patch-update","alert_type":396,"serial_number":"AV19-231","subject":null,"moderation_state":"published","external_url":null},{"nid":1654,"title":"[Control systems] Siemens security advisory","uuid":"3cceb95e-f1d1-46ec-b8da-88d670031dbc","banner":null,"lang":"en","date_modified":"2019-10-16","date_modified_ts":"2019-10-16T14:54:00Z","date_created":"2019-10-16T14:18:01Z","summary":null,"body":["<article data-history-node-id=\"1654\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-232<\/strong><br \/><strong>Date: 16 October 2019<\/strong><\/p>\n\n<p>On 10 October 2019 Siemens released security updates to address vulnerabilities affecting multiple Siemens Industrial Real-Time (IRT) Devices and Siemens PROFINET Devices.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to cause a denial of service. The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-19-283-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-283-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-283-01<\/a><\/p>\n\n<p>ICS Advisory (ICSA-19-283-02)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-283-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-283-02<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-1","alert_type":398,"serial_number":"AV19-232","subject":null,"moderation_state":"published","external_url":null},{"nid":1653,"title":"WordPress security advisory","uuid":"d39be0f9-db39-4a66-9b1a-49e5380801cc","banner":null,"lang":"en","date_modified":"2019-10-16","date_modified_ts":"2019-10-16T14:52:00Z","date_created":"2019-10-16T14:48:35Z","summary":null,"body":["<article data-history-node-id=\"1653\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-233<\/strong><br \/><strong>Date: 16 October 2019<\/strong><\/p>\n\n<p>On 14 October 2019 WordPress released version 5.2.4 to address vulnerabilities related to version 5.2.3 and prior. Updated versions of WordPress 5.1 and earlier are also available for those not yet using version 5.2.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following WordPress Security Release and upgrade to the necessary version:<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/\">https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-0","alert_type":396,"serial_number":"AV19-233","subject":null,"moderation_state":"published","external_url":null},{"nid":1657,"title":"VMware security advisory","uuid":"f36fbbd0-d410-405a-a02a-7e85130d649b","banner":null,"lang":"en","date_modified":"2019-10-16","date_modified_ts":"2019-10-16T19:46:41Z","date_created":"2019-10-16T19:46:41Z","summary":null,"body":["<article data-history-node-id=\"1657\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-234<\/strong><br \/><strong>Date: 16 October 2019<\/strong><\/p>\n\n<p>On 15 October 2019 VMware released a security advisory to address an access control vulnerability affecting VMware Cloud Foundation and VMware Harbor Container Registry for PCF version 1.8. VMware Cloud Foundation is only affected if the optional \u2018Harbor Registry\u2019 component has been deployed. An actor with administrative access to a project could exploit this vulnerability to modify images in an adjacent project.<\/p>\n\n<p>The Cyber Centre encourages users to review the following VMware Advisory and apply the necessary updates or workarounds:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0016.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0016.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-19","alert_type":396,"serial_number":"AV19-234","subject":null,"moderation_state":"published","external_url":null},{"nid":1658,"title":"Cisco security advisory","uuid":"b6d56ce1-d5f2-4d03-86e2-261e5a53c4ec","banner":null,"lang":"en","date_modified":"2019-10-18","date_modified_ts":"2019-10-18T16:10:25Z","date_created":"2019-10-18T16:10:25Z","summary":null,"body":["<article data-history-node-id=\"1658\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-235<\/strong><br \/><strong>Date: 18 October 2019<\/strong><\/p>\n\n<p>On 16 October 2019 Cisco released a number of security advisories to address vulnerabilities affecting multiple products. Of note, a critical vulnerability in the Cisco Aironet Access Points software, tracked as CVE-2019-15260, could allow an unauthenticated, remote actor to gain unauthorized access to a targeted device with elevated privileges. Exploitation of this vulnerability could lead to sensitive information disclosure and administrative control of some configuration options, including the ability to disable the access point<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-36","alert_type":396,"serial_number":"AV19-235","subject":null,"moderation_state":"published","external_url":null},{"nid":1659,"title":"[Control systems] Horner Automation security advisory","uuid":"2a4e8e65-a134-4278-883a-3866d825e598","banner":null,"lang":"en","date_modified":"2019-10-18","date_modified_ts":"2019-10-18T16:42:38Z","date_created":"2019-10-18T16:42:38Z","summary":null,"body":["<article data-history-node-id=\"1659\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Num\u00e9ro : AV19-236<\/strong>\n  <br \/><strong>Date : 18 October 2019<\/strong>\n<\/p>\n<p>On 17 October 2019 Horner Automation released a security update to address a vulnerability affecting Cscape version 9.90 and prior. Successful exploitation of these vulnerabilities may allow a remote actor to cause the device being accessed to crash, which may allow unauthorized access to information and arbitrary code execution. The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:\n<\/p>\n<p>ICS Advisory (ICSA-19-290-02)\n<\/p>\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-290-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-290-02<\/a>\n<\/p>\n<p><strong>Note to Readers<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory","alert_type":398,"serial_number":"AV19-236","subject":null,"moderation_state":"published","external_url":null},{"nid":1660,"title":"[Control systems] AVEVA security advisory","uuid":"14a6203a-88c8-4f04-a0b5-7d9f6f4d155a","banner":null,"lang":"en","date_modified":"2019-10-18","date_modified_ts":"2019-10-18T17:05:57Z","date_created":"2019-10-18T17:01:07Z","summary":null,"body":["<article data-history-node-id=\"1660\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-237<\/strong>\n  <br \/><strong>Date: 18 October 2019<\/strong>\n<\/p>\n<p>On 17 October 2019 AVEVA released a security advisory to address a vulnerability affecting the IEC870IP driver (v4.14.02 and prior) used in Vijeo Citect and Citect SCADA. Successful exploitation of this vulnerability can cause a buffer overflow which would result in a server-side crash.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the following AVEVA Security Advisory and apply the necessary manufacturer update:\n<\/p>\n<p><a href=\"https:\/\/sw.aveva.com\/hubfs\/assets-2018\/pdf\/security-bulletin\/SecurityBulletin_LFSec139.pdf\">https:\/\/sw.aveva.com\/hubfs\/assets-2018\/pdf\/security-bulletin\/SecurityBulletin_LFSec139.pdf <\/a>\n<\/p>\n<p><strong>Note to Readers<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory","alert_type":398,"serial_number":"AV19-237","subject":null,"moderation_state":"published","external_url":null},{"nid":1661,"title":"Avast security advisory","uuid":"591b37bb-cf87-4bbd-b7c8-27babc6a8dc2","banner":null,"lang":"en","date_modified":"2019-10-21","date_modified_ts":"2019-10-21T19:16:20Z","date_created":"2019-10-21T19:16:20Z","summary":null,"body":["<article data-history-node-id=\"1661\" about=\"\/en\/alerts-advisories\/avast-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-238<\/strong><br \/><strong>Date: 21 October 2019<\/strong><\/p>\n\n<p>On 21 October 2019 Avast published a blog post discussing a recent compromise of their internal networks. It is believed that CCleaner was the likely target in an attempted supply chain attack. Avast reported that there were no malicious alterations observed in prior releases of CCleaner.<\/p>\n\n<p>On 15 October 2019 CCleaner version v5.63.7540 was released. This version contained a re-signed certificate for the product. Certificates for previous versions were then revoked.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to always stay up to date with the latest versions of software when available.<\/p>\n\n<p>Avast Blog:<\/p>\n\n<p><a href=\"https:\/\/blog.avast.com\/ccleaner-fights-off-cyberespionage-attempt-abiss\">https:\/\/blog.avast.com\/ccleaner-fights-off-cyberespionage-attempt-abiss<\/a><\/p>\n\n<p>CCleaner v5.63.7540 announcement:<\/p>\n\n<p><a href=\"https:\/\/forum.piriform.com\/topic\/55747-ccleaner-v5637540\/\">https:\/\/forum.piriform.com\/topic\/55747-ccleaner-v5637540\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/avast-security-advisory","alert_type":396,"serial_number":"AV19-238","subject":null,"moderation_state":"published","external_url":null},{"nid":1662,"title":"Fortinet security advisory","uuid":"a9e95340-83c1-479d-b06a-c8be67eac961","banner":null,"lang":"en","date_modified":"2019-10-21","date_modified_ts":"2019-10-21T19:28:48Z","date_created":"2019-10-21T19:28:48Z","summary":null,"body":["<article data-history-node-id=\"1662\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-239<\/strong><br \/><strong>Date: 21 October 2019<\/strong><\/p>\n\n<p>On 18 October 2019 Fortinet released updates to address vulnerabilities affecting the following Fortinet products:<\/p>\n\n<ul><li>FortiOS<\/li>\n\t<li>FortiMail<\/li>\n\t<li>FortiClient for Windows<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the Fortinet advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/fortiguard.com\/psirt\">https:\/\/fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-2","alert_type":396,"serial_number":"AV19-239","subject":null,"moderation_state":"published","external_url":null},{"nid":1663,"title":"Mozilla security advisory","uuid":"0b3097d9-c7e5-4547-89f1-24a677487d2e","banner":null,"lang":"en","date_modified":"2019-10-24","date_modified_ts":"2019-10-24T14:43:37Z","date_created":"2019-10-24T14:43:37Z","summary":null,"body":["<article data-history-node-id=\"1663\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-241<\/strong><br \/><strong>Date : 24 October 2019<\/strong><\/p>\n\n<p>On 22 October 2019 Mozilla released updates to address vulnerabilities in Firefox 70 and Firefox ESR 68.2. The updates address vulnerabilities that could allow for arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Mozilla Foundation Security Advisories and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-33\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-33\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-34\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-34\/<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-6","alert_type":396,"serial_number":"AV19-241","subject":null,"moderation_state":"published","external_url":null},{"nid":1664,"title":"Google Chrome security advisory","uuid":"1ddae460-ea45-4267-876c-57239589a186","banner":null,"lang":"en","date_modified":"2019-10-24","date_modified_ts":"2019-10-24T14:50:20Z","date_created":"2019-10-24T14:50:20Z","summary":null,"body":["<article data-history-node-id=\"1664\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-240<\/strong><br \/><strong>Date : 24 October 2019<\/strong><\/p>\n\n<p>On 22 October 2019 Google announced the release of Chrome 78.0.3904.70 for Windows, Mac, and Linux. This release will address vulnerabilities that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary update when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/10\">https:\/\/chromereleases.googleblog.com\/2019\/10<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-9","alert_type":396,"serial_number":"AV19-240","subject":null,"moderation_state":"published","external_url":null},{"nid":1665,"title":"Juniper Networks security advisory","uuid":"b54c2853-163f-4b83-aefb-a84b590e211a","banner":null,"lang":"en","date_modified":"2019-10-24","date_modified_ts":"2019-10-24T17:18:48Z","date_created":"2019-10-24T17:13:14Z","summary":null,"body":["<article data-history-node-id=\"1665\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Num\u00e9ro : AV19-242<\/strong><br \/><strong>Date : 24 October 2019<\/strong><\/p>\n\n<p>On 22 October 2019 Juniper published security updates to address vulnerabilities in Junos OS Evolved (EVO) platforms and Linux-based Junos Device Manager (JDM) products using the following Junos OS:<\/p>\n\n<ul><li>15.1X49 versions prior to 15.1X49-D171, 15.1X49-D180<\/li>\n\t<li>15.1X53 versions prior to 15.1X53-D496, 15.1X53-D69<\/li>\n\t<li>16.1 versions prior to 16.1R7-S4<\/li>\n\t<li>16.2 versions prior to 16.2R2-S9<\/li>\n\t<li>17.1 versions prior to 17.1R3<\/li>\n\t<li>17.2 versions prior to 17.2R1-S8, 17.2R2-S7, 17.2R3-S1<\/li>\n\t<li>17.3 versions prior to 17.3R3-S4<\/li>\n\t<li>17.4 versions prior to 17.4R1-S6, 17.4R1-S7, 17.4R2-S3, 17.4R3<\/li>\n\t<li>18.1 versions prior to 18.1R2-S4, 18.1R3-S4<\/li>\n\t<li>18.2 versions prior to 18.2R1-S5, 18.2R2-S2, 18.2R3<\/li>\n\t<li>18.3 versions prior to 18.3R1-S3, 18.3R2<\/li>\n\t<li>18.4 versions prior to 18.4R1-S2, 18.4R2<\/li>\n<\/ul><p>By exploiting these vulnerabilities, a local, authenticated user may be able to gain administrative privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Juniper Networks Security Bulletin and apply the necessary update:<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10960&amp;cat=SIRT_1&amp;actp=LIST\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA10960&amp;cat=SIRT_1&amp;actp=LIST<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-2","alert_type":396,"serial_number":"AV19-242","subject":null,"moderation_state":"published","external_url":null},{"nid":1666,"title":"Mozilla Thunderbird security advisory","uuid":"1c396520-c113-452b-8195-c347bcb0ba05","banner":null,"lang":"en","date_modified":"2019-10-25","date_modified_ts":"2019-10-25T15:16:08Z","date_created":"2019-10-25T15:16:08Z","summary":null,"body":["<article data-history-node-id=\"1666\" about=\"\/en\/alerts-advisories\/mozilla-thunderbird-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-243<\/strong><br \/><strong>Date: 25 October 2019<\/strong><\/p>\n\n<p>On 22 October 2019 Mozilla released updates to address vulnerabilities in Thunderbird. The updates address vulnerabilities that could allow for arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Mozilla Foundation security advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-35\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-35\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-thunderbird-security-advisory-0","alert_type":396,"serial_number":"AV19-243","subject":null,"moderation_state":"published","external_url":null},{"nid":1667,"title":"[Control systems] Rittal security advisory","uuid":"e2ca6d10-93f6-4153-8446-9d9741998b37","banner":null,"lang":"en","date_modified":"2019-10-25","date_modified_ts":"2019-10-25T16:59:28Z","date_created":"2019-10-25T16:59:28Z","summary":null,"body":["<article data-history-node-id=\"1667\" about=\"\/en\/alerts-advisories\/control-systems-rittal-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-244<\/strong><br \/><strong>Date: 25 October 2019<\/strong><\/p>\n\n<p>On 24 October 2019 Rittal released a security update to address a vulnerability affecting the Rittal Chiller SK 3232-Series. Successful exploitation of this vulnerability may allow a remote actor to disrupt the primary operations of the chiller, such as shutting off cooling to other equipment or allowing changes to the temperature set point to be made.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Advisory (ICSA-19-297-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-297-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-297-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rittal-security-advisory","alert_type":398,"serial_number":"AV19-244","subject":null,"moderation_state":"published","external_url":null},{"nid":1668,"title":"[Control systems] Philips security advisory","uuid":"f6fc543f-9f24-4e5b-a3e7-9fdb206412b7","banner":null,"lang":"en","date_modified":"2019-10-25","date_modified_ts":"2019-10-25T17:08:49Z","date_created":"2019-10-25T17:08:49Z","summary":null,"body":["<article data-history-node-id=\"1668\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-245<\/strong><br \/><strong>Date: 25 October 2019<\/strong><\/p>\n\n<p>On 24 October 2019 Philips released a security update to address a vulnerability affecting the IntelliSpace Perinatal (version K and older) obstetrics information management system. Successful exploitation of this vulnerability may allow a remote actor to access system resources, including access to execute software or to view\/update files, directories, system configuration and protected health information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Medical Advisory (ICSMA-19-297-01) \u00a0<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-297-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-297-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-0","alert_type":398,"serial_number":"AV19-245","subject":null,"moderation_state":"published","external_url":null},{"nid":1669,"title":"Foxit Reader and Foxit PhantomPDF security advisory","uuid":"ec520cc4-6b6a-47f9-a75e-24826085adca","banner":null,"lang":"en","date_modified":"2019-10-29","date_modified_ts":"2019-10-29T16:29:10Z","date_created":"2019-10-29T16:21:24Z","summary":null,"body":["<article data-history-node-id=\"1669\" about=\"\/en\/alerts-advisories\/foxit-reader-and-foxit-phantompdf-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><br \/><strong>Number: AV19-246<br \/>\nDate: 29 October 2019<\/strong><\/p>\n\n<p>On 16 October 2019 Foxit released updated version 9.7 of Foxit Reader and Foxit PhantomPDF to address several issues in version 9.6.0.25114 and older. Vulnerable versions of these packages are exploitable via a specially-crafted .PDF file, potentially allowing an actor to run code of their choice.<br \/>\nThe Cyber Centre encourages users and administrators to review the Foxit Security Bulletin below and download version 9.7 to remain protected:<\/p>\n\n<p><a href=\"https:\/\/www.foxitsoftware.com\/support\/security-bulletins.php\">https:\/\/www.foxitsoftware.com\/support\/security-bulletins.php<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-reader-and-foxit-phantompdf-security-advisory","alert_type":396,"serial_number":"AV19-246","subject":null,"moderation_state":"published","external_url":null},{"nid":1689,"title":"Apple security advisory","uuid":"25ed2352-7ef0-4b10-b86d-b7b688c6e9bc","banner":null,"lang":"en","date_modified":"2019-10-31","date_modified_ts":"2019-10-31T14:22:49Z","date_created":"2019-10-30T19:07:44Z","summary":null,"body":["<article data-history-node-id=\"1689\" about=\"\/en\/alerts-advisories\/apple-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-247<\/strong><br \/><strong>Date: 30 October 2019<\/strong><\/p>\n\n<p>On 29 October 2019 Apple released security updates to address vulnerabilities affecting macOS Catalina 10.15, macOS Mojave 10.14.6, and macOS High Sierra 10.13.6. Exploitation of these vulnerabilities could allow an application to execute arbitrary code with system level privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT210722\">https:\/\/support.apple.com\/en-ca\/HT210722<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-7","alert_type":396,"serial_number":"AV19-247","subject":null,"moderation_state":"published","external_url":null},{"nid":1688,"title":"[Control systems] Advantech security advisory","uuid":"13257212-dab7-4c8e-87a6-7f4f70bd4a5b","banner":null,"lang":"en","date_modified":"2019-10-31","date_modified_ts":"2019-10-31T19:55:56Z","date_created":"2019-10-31T19:55:56Z","summary":null,"body":["<article data-history-node-id=\"1688\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-248<\/strong><br \/><strong>Date: 31 October 2019<\/strong><\/p>\n\n<p>On 31 October 2019 Advantech released a security update to address a vulnerability affecting the WISE-PaaS\/RMM remote monitoring and management platform (Versions 3.3.29 and prior). Successful exploitation of this vulnerability may allow a remote actor to access protected information, execute remote code and compromise system availability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Advisory (ICSA-19-304-01<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-304-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-304-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-0","alert_type":398,"serial_number":"AV19-248","subject":null,"moderation_state":"published","external_url":null},{"nid":1670,"title":"Google Chrome Zero-day Vulnerability","uuid":"f5b18c5d-8bc0-4a3c-896e-17dfc8da605c","banner":null,"lang":"en","date_modified":"2019-11-04","date_modified_ts":"2019-11-04T18:23:00Z","date_created":"2019-11-04T18:22:23Z","summary":null,"body":["<article data-history-node-id=\"1670\" about=\"\/en\/alerts-advisories\/google-chrome-zero-day-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL19-019<\/strong><br \/><strong>Date: 4 November 2019<\/strong><\/p>\n\n<p>AUDIENCE<br \/>\n========<br \/>\nThis Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<p>PURPOSE<br \/>\n=======<br \/>\nAn Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<p>DETAILS<br \/>\n=======<br \/>\nThe Cyber Centre has become aware that exploits for CVE-2019-13720 have been observed. On 31 October 2019, Google released a patch for Google Chrome to address this high severity zero-day, which is tied to the audio component of Google Chrome. This \u2018use-after-free\u2019 vulnerability, which is when an application tries to reference memory that has since been freed or deleted, can lead to arbitrary code execution. An actor could exploit the vulnerability by crafting a malicious webpage that takes advantage of the vulnerable Chrome component and then lure users into visiting the webpage.<\/p>\n\n<p>A second high severity use-after-free vulnerability, CVE-2019-13721, has also been patched in the latest update. CVE-2019-13721 has not been observed as being actively exploited.<\/p>\n\n<p>SUGGESTED ACTIONS<br \/>\n=================<br \/>\n-\u00a0Update Google Chrome to the latest version, namely, 78.0.3904.87 at the time of publishing.<br \/>\n-\u00a0Always exercise caution when receiving an unexpected email or email reply containing an attachment or URL, even when from a trusted source. If the email seems unusual, contact the sender to confirm the authenticity of the attachment.<br \/>\n-\u00a0Follow the Cyber Centre\u2019s guidance to stay CyberSafe.<\/p>\n\n<p>REFERENCES<br \/>\n==========<br \/>\nGoogle Chrome Blog:<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/10\/stable-channel-update-for-desktop_31.html\">https:\/\/chromereleases.googleblog.com\/2019\/10\/stable-channel-update-for-desktop_31.html<\/a><\/p>\n\n<p>ZDNet Article:<br \/><a href=\"https:\/\/www.zdnet.com\/article\/halloween-scare-google-discloses-chrome-zero-day-exploited-in-the-wild\/\">https:\/\/www.zdnet.com\/article\/halloween-scare-google-discloses-chrome-zero-day-exploited-in-the-wild\/<\/a><\/p>\n\n<p>Five Practical Ways to Make Yourself CyberSafe:<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/five-practical-ways-make-yourself-cybersafe\">https:\/\/cyber.gc.ca\/en\/guidance\/five-practical-ways-make-yourself-cybersafe<\/a><\/p>\n\n<p>NOTE TO READERS<br \/>\n===============<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the<br \/>\nCyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information<br \/>\nsharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-zero-day-vulnerability","alert_type":397,"serial_number":"AL19-019","subject":null,"moderation_state":"published","external_url":null},{"nid":1687,"title":"PHP security advisory","uuid":"f9cffa6a-f86c-48c2-961c-c5879b3d75f3","banner":null,"lang":"en","date_modified":"2019-11-05","date_modified_ts":"2019-11-05T19:00:52Z","date_created":"2019-11-05T19:00:52Z","summary":null,"body":["<article data-history-node-id=\"1687\" about=\"\/en\/alerts-advisories\/php-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-249<\/strong><br \/><strong>Date: 05 November 2019<\/strong><\/p>\n\n<p>On 24 October 2019 PHP released security updates to address a vulnerability in its FastCGI Process Manager (FPM). This vulnerability affects PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup. Successful exploitation of this vulnerability may allow a remote actor to execute arbitrary code on the server. Multiple advisories from third-parties have been released and an aggregated list can be found at:<\/p>\n\n<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-11043\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-11043<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the PHP ChangeLog webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.php.net\/ChangeLog-7.php\">https:\/\/www.php.net\/ChangeLog-7.php<\/a><\/p>\n\n<p>Note to Readers<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-advisory-0","alert_type":396,"serial_number":"AV19-249","subject":null,"moderation_state":"published","external_url":null},{"nid":1671,"title":"[Control systems] Omron security advisory","uuid":"5c87c980-501b-4f99-93a0-b3a5af42cf6e","banner":null,"lang":"en","date_modified":"2019-11-05","date_modified_ts":"2019-11-05T19:50:42Z","date_created":"2019-11-05T19:40:57Z","summary":null,"body":["<article data-history-node-id=\"1671\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-250<\/strong><br \/><strong>Date: 5 November 2019<\/strong><\/p>\n\n<p>On 5 November 2019 Omron released a security update to address a vulnerability in Omron\u2019s SCADA and HMI package \u2018CX-Supervisor\u2019 (Versions 3.5 (12) and prior). Successful exploitation of this vulnerability may allow a remote actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<br \/>\nICS Advisory (ICSA-19-309-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-309-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-309-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory","alert_type":398,"serial_number":"AV19-250","subject":null,"moderation_state":"published","external_url":null},{"nid":1672,"title":"Android security advisory","uuid":"4ee589e1-503f-4831-b69a-0b1bb7f20ffd","banner":null,"lang":"en","date_modified":"2019-11-06","date_modified_ts":"2019-11-06T18:00:07Z","date_created":"2019-11-06T18:00:07Z","summary":null,"body":["<article data-history-node-id=\"1672\" about=\"\/en\/alerts-advisories\/android-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-251<br \/>\nDate:\u00a06\u00a0November 2019<\/strong><\/p>\n\n<p>On 4 November 2019 Android published a Security Bulletin to address multiple vulnerabilities affecting Android devices. A remote actor could exploit one of these vulnerabilities to take control of the affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Android Security Bulletin and apply the necessary updates, when available:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-11-01\">https:\/\/source.android.com\/security\/bulletin\/2019-11-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-6","alert_type":396,"serial_number":"AV19-251","subject":null,"moderation_state":"published","external_url":null},{"nid":1678,"title":"NVIDIA security advisory","uuid":"5a96e4eb-e7f1-4c58-a148-8dce9fa4d99b","banner":null,"lang":"en","date_modified":"2019-11-08","date_modified_ts":"2019-11-08T18:36:53Z","date_created":"2019-11-07T17:52:14Z","summary":null,"body":["<article data-history-node-id=\"1678\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-252<br \/>\nDate:\u00a07\u00a0November 2019<\/strong><\/p>\n\n<p>On 6 November 2019 NVIDIA released security updates to address vulnerabilities affecting its NVIDIA GPU Display Driver and its vGPU software. These updates address issues that may lead to denial of service, escalation of privileges, or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4907\/kw\/Security\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4907\/kw\/Security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-5","alert_type":396,"serial_number":"AV19-252","subject":null,"moderation_state":"published","external_url":null},{"nid":1673,"title":"Linux security advisory","uuid":"a6152315-57fb-4dbb-9ebb-d1f61dc919d0","banner":null,"lang":"en","date_modified":"2019-11-07","date_modified_ts":"2019-11-07T18:25:51Z","date_created":"2019-11-07T18:25:51Z","summary":null,"body":["<article data-history-node-id=\"1673\" about=\"\/en\/alerts-advisories\/linux-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-253<br \/>\nDate:\u00a07\u00a0November 2019<\/strong><\/p>\n\n<p>Several Linux distributions have released security updates to address vulnerabilities in their respective operating systems. Of note is a vulnerability in Libarchive that could allow an actor to execute arbitrary code on a system by deceiving a user to decompress a malicious archive file crafted to exploit the vulnerability. Some operating systems utilize Libarchive by default, including but not limited to Debian, Ubuntu, Gentoo, Arch Linux, FreeBSD, and NetBSD.<\/p>\n\n<p>Several security bulletins have been released and the Cyber Centre encourages users and administrators to review the applicable bulletins listed below and apply the necessary updates. Please note that other versions of Linux may also be affected.<\/p>\n\n<p>Debian: <a href=\"https:\/\/www.debian.org\/security\/2019\/dsa-4557\">https:\/\/www.debian.org\/security\/2019\/dsa-4557<\/a><br \/>\nUbuntu: <a href=\"https:\/\/usn.ubuntu.com\/4169-1\/\">https:\/\/usn.ubuntu.com\/4169-1\/<\/a><br \/>\nGentoo: <a href=\"https:\/\/bugs.gentoo.org\/show_bug.cgi?id=CVE-2019-18408\">https:\/\/bugs.gentoo.org\/show_bug.cgi?id=CVE-2019-18408<\/a><br \/>\nArch Linux: <a href=\"https:\/\/www.archlinux.org\/packages\/?sort=&amp;q=libarchive&amp;maintainer=&amp;flagged\">https:\/\/www.archlinux.org\/packages\/?sort=&amp;q=libarchive&amp;maintainer=&amp;flagged<\/a>=<\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-security-advisory-0","alert_type":396,"serial_number":"AV19-253","subject":null,"moderation_state":"published","external_url":null},{"nid":1674,"title":"Cisco security advisory","uuid":"820779d4-f988-430a-bd82-b396599543f0","banner":null,"lang":"en","date_modified":"2019-11-07","date_modified_ts":"2019-11-07T18:48:28Z","date_created":"2019-11-07T18:48:28Z","summary":null,"body":["<article data-history-node-id=\"1674\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-254<br \/>\nDate:\u00a07\u00a0November 2019<\/strong><\/p>\n\n<p>On 6 November 2019 Cisco released a number of security advisories to address vulnerabilities affecting multiple products. Of note, a vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers, tracked as CVE-2019-15271, could allow an authenticated, remote actor to execute arbitrary commands with root privileges by sending a malicious HTTP request to the targeted device.<\/p>\n\n<p>This vulnerability affects the following Cisco Small Business RV Series Routers if they are running a firmware release earlier than 4.2.3.10:<\/p>\n\n<p>\u2022\u00a0RV016 Multi-WAN VPN Router<br \/>\n\u2022\u00a0RV042 Dual WAN VPN Router<br \/>\n\u2022\u00a0RV042G Dual Gigabit WAN VPN Router<br \/>\n\u2022\u00a0RV082 Dual WAN VPN Router<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-37","alert_type":396,"serial_number":"AV19-254","subject":null,"moderation_state":"published","external_url":null},{"nid":1675,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"c70d9176-6062-4685-a3ff-c7b4e085c706","banner":null,"lang":"en","date_modified":"2019-11-08","date_modified_ts":"2019-11-08T17:48:48Z","date_created":"2019-11-08T17:48:48Z","summary":null,"body":["<article data-history-node-id=\"1675\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-257<\/strong><br \/><strong>Date: 08 November 2019<\/strong><\/p>\n\n<p>On 7 November 2019 Mitsubishi Electric released security updates to address multiple vulnerabilities in the following versions of MELSEC-Q Series and MELSEC-L Series CPU modules:<\/p>\n\n<p>\u2022\u00a0[MELSEC-Q Series]<br \/>\no\u00a0Q03\/04\/06\/13\/26UDVCPU: serial number 21081 and prior,<br \/>\no\u00a0Q04\/06\/13\/26UDPVCPU: serial number 21081 and prior, and<br \/>\no\u00a0Q03UDECPU, Q04\/06\/10\/13\/20\/26\/50\/100UDEHCPU: serial number 21081 and prior.<br \/>\n\u2022\u00a0[MELSEC-L Series]<br \/>\no\u00a0L02\/06\/26CPU, L26CPU-BT: serial number 21101 and prior,<br \/>\no\u00a0L02\/06\/26CPU-P, L26CPU-PBT: serial number 21101 and prior, and<br \/>\no\u00a0L02\/06\/26CPU-CM, L26CPU-BT-CM: serial number 21101 and prior.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<br \/>\nICS Advisory (ICSA-19-311-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-311-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-311-01<\/a><\/p>\n\n<p><br \/>\nNote to Readers<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-0","alert_type":398,"serial_number":"AV19-257","subject":null,"moderation_state":"published","external_url":null},{"nid":1676,"title":"[Control systems] Fuji Electric security advisory","uuid":"bc24b560-2d82-4d6b-a470-d6c5102e2ece","banner":null,"lang":"en","date_modified":"2019-11-08","date_modified_ts":"2019-11-08T17:58:34Z","date_created":"2019-11-08T17:58:34Z","summary":null,"body":["<article data-history-node-id=\"1676\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-256<\/strong><br \/><strong>Date: 08 November 2019<\/strong><\/p>\n\n<p>On 7 November 2019 Fuji Electric released a security update to address a vulnerability in V-Server data collection and management services (V-Server 4.0.6 and prior). Successful exploitation of this vulnerability may allow a remote actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<br \/>\nICS Advisory (ICSA-19-311-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-311-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-311-02<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p>Note to Readers<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-0","alert_type":398,"serial_number":"AV19-256","subject":null,"moderation_state":"published","external_url":null},{"nid":1677,"title":"[Control systems] Medtronic security advisory","uuid":"79c28c2e-28f0-4cfc-a4c0-4089a3547cdf","banner":null,"lang":"en","date_modified":"2019-11-08","date_modified_ts":"2019-11-08T18:10:33Z","date_created":"2019-11-08T18:10:33Z","summary":null,"body":["<article data-history-node-id=\"1677\" about=\"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-255<\/strong><br \/><strong>Date: 08 November 2019<\/strong><\/p>\n\n<p>On 7 November 2019 Medtronic released security updates to address multiple vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0Valleylab FT10 Energy Platform (VLFT10GEN)<br \/>\no\u00a0Version 2.1.0 and lower<br \/>\no\u00a0Version 2.0.3 and lower<br \/>\n\u2022\u00a0Valleylab LS10 Energy Platform (VLLS10GEN\u2014not available in the United States)<br \/>\no\u00a0Version 1.20.2 and lower<br \/>\n\u2022\u00a0Valleylab Exchange Client, Version 3.4 and below<br \/>\n\u2022\u00a0Valleylab FT10 Energy Platform (VLFT10GEN) software Version 4.0.0 and below<br \/>\n\u2022\u00a0Valleylab FX8 Energy Platform (VLFX8GEN) software Version 1.1.0 and below<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer update:<br \/>\nICS Medical Advisory (ICSMA-19-311-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-311-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-311-01<\/a><\/p>\n\n<p>ICS Medical Advisory (ICSMA-19-311-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-311-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-311-02<\/a><\/p>\n\n<p><br \/>\nNote to Readers<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory","alert_type":398,"serial_number":"AV19-255","subject":null,"moderation_state":"published","external_url":null},{"nid":1685,"title":"Adobe security advisory","uuid":"fb9ee64f-9091-48f7-9f58-a52b0430ca1c","banner":null,"lang":"en","date_modified":"2019-11-12","date_modified_ts":"2019-11-12T17:26:49Z","date_created":"2019-11-12T17:26:49Z","summary":null,"body":["<article data-history-node-id=\"1685\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-258<\/strong>\n  <br \/><strong>Date: 12 November 2019<\/strong>\n<\/p>\n<p>On 12 November 2019 Adobe released security updates to address vulnerabilities affecting multiple products, including critical vulnerabilities found in Adobe Media Encoder and Adobe Illustrator. Successful exploitation could allow for arbitrary code execution in the context of the current user.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:\n<\/p>\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a>\n<\/p>\n<p><strong>Note to Readers<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-8","alert_type":396,"serial_number":"AV19-258","subject":null,"moderation_state":"published","external_url":null},{"nid":1679,"title":"Intel security advisory","uuid":"69683e44-58eb-4cb7-8267-fe0a784be2f6","banner":null,"lang":"en","date_modified":"2019-11-12","date_modified_ts":"2019-11-12T21:12:48Z","date_created":"2019-11-12T21:12:48Z","summary":null,"body":["<article data-history-node-id=\"1679\" about=\"\/en\/alerts-advisories\/intel-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-259<\/strong><br \/><strong>Date: 12 November 2019<\/strong><\/p>\n\n<p>On 12 November 2019 Intel released security updates to address vulnerabilities affecting several Intel products. Of note is a critical vulnerability, CVE-2019-0169, that could potentially allow for escalation of privileges, information disclosure or denial of service via adjacent access. This vulnerability is present in:<\/p>\n\n<p>\u2022\u00a0Intel Converged Security and Manageability Engine (CSME)<br \/>\n\u2022\u00a0Intel Server Platform Services (SPS)<br \/>\n\u2022\u00a0Intel Trusted Execution Engine (TXE)<br \/>\n\u2022\u00a0Intel Active Management Technology (AMT)<br \/>\n\u2022\u00a0Intel Platform Trust Technology (PTT)<br \/>\n\u2022\u00a0Intel Dynamic Application Loader (DAL)<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Intel Product Security Center Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-6","alert_type":396,"serial_number":"AV19-259","subject":null,"moderation_state":"published","external_url":null},{"nid":1680,"title":"Microsoft security advisory \u2013 November 2019 monthly rollup","uuid":"8762e9a6-30ad-44c3-9108-2e664095f841","banner":null,"lang":"en","date_modified":"2019-11-12","date_modified_ts":"2019-11-12T21:17:48Z","date_created":"2019-11-12T21:17:48Z","summary":null,"body":["<article data-history-node-id=\"1680\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-november-2019-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-260<\/strong><br \/><strong>Date: 12 November 2019<\/strong><\/p>\n\n<p>On 12 November 2019 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for 13 critical remote code execution vulnerabilities, one of which includes a flaw in the way that the scripting engine handles objects in memory in Internet Explorer.<\/p>\n\n<p>This vulnerability, tracked as CVE-2019-1429, could corrupt memory in such a way that an actor could execute arbitrary code in the context of the current user. Microsoft reports that exploitation has been detected for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft November 2019 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/164aa83e-499c-e911-a994-000d3a33c573\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/164aa83e-499c-e911-a994-000d3a33c573<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-november-2019-monthly-rollup","alert_type":396,"serial_number":"AV19-260","subject":null,"moderation_state":"published","external_url":null},{"nid":1684,"title":"VMware security advisory ","uuid":"04404d8e-e95d-4ed3-bbbc-f891aec54a2d","banner":null,"lang":"en","date_modified":"2019-11-13","date_modified_ts":"2019-11-13T20:03:48Z","date_created":"2019-11-13T20:03:48Z","summary":null,"body":["<article data-history-node-id=\"1684\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-261<\/strong><br \/><strong>Date: 13 November 2019<\/strong><\/p>\n\n<p>On 12 November 2019 VMware released security updates to address vulnerabilities affecting VMware Workstation and VMware Fusion. Successful exploitation of these vulnerabilities could lead to a denial of service, the disclosure of sensitive information or code execution on the host.\u00a0<br \/>\nThe Cyber Centre encourages users to review the following VMware Advisory and apply the necessary updates or workarounds:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0021.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0021.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-20","alert_type":396,"serial_number":"AV19-261","subject":null,"moderation_state":"published","external_url":null},{"nid":1681,"title":"Google Chrome security advisory","uuid":"98d9de6a-4357-4cf9-bdbc-0a9bf69299a9","banner":null,"lang":"en","date_modified":"2019-11-20","date_modified_ts":"2019-11-20T14:56:31Z","date_created":"2019-11-20T14:56:31Z","summary":null,"body":["<article data-history-node-id=\"1681\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-262<\/strong><br \/><strong>Date:\u00a020 November 2019<\/strong><\/p>\n\n<p>On 18 November 2019 Google announced the release of Chrome 78.0.3904.108 for Windows, Mac, and Linux. This update addresses vulnerabilities within chrome that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/11\/stable-channel-update-for-desktop_18.html\">https:\/\/chromereleases.googleblog.com\/2019\/11\/stable-channel-update-for-desktop_18.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-10","alert_type":396,"serial_number":"AV19-262","subject":null,"moderation_state":"published","external_url":null},{"nid":1682,"title":"[Control systems] Siemens security advisory","uuid":"23adbf83-8c80-4c93-8a54-37416245220b","banner":null,"lang":"en","date_modified":"2019-11-26","date_modified_ts":"2019-11-26T20:17:43Z","date_created":"2019-11-26T20:17:43Z","summary":null,"body":["<article data-history-node-id=\"1682\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-265<\/strong><br \/><strong>Date: 26 November 2019<\/strong><\/p>\n\n<p>On 12 November 2019 Siemens released security updates to address vulnerabilities in the following products:<br \/>\nDesigo PX automation controllers:<br \/>\n\u2022\u00a0PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules<br \/>\n\u2022\u00a0PXA40-W0, PXA40-W1, PXA40-W2: All firmware versions prior to V6.00.320<br \/>\n\u2022\u00a0PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules<br \/>\n\u2022\u00a0PXA30-W0, PXA30-W1, PXA30-W2: All firmware versions prior to V6.00.320<br \/>\n\u2022\u00a0PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server: All firmware versions prior to V6.00.320<\/p>\n\n<p>Networking modules from Mentor Nucleus:<br \/>\n\u2022\u00a0Nucleus NET: All versions<br \/>\n\u2022\u00a0Nucleus RTOS: All versions<br \/>\n\u2022\u00a0Nucleus ReadyStart for ARM, MIPS, and PPC: All versions prior to v2017.02.2 with patch \u201cNucleus 2017.02.02 Nucleus NET Patch\u201d<br \/>\n\u2022\u00a0Nucleus SafetyCert: All versions<br \/>\n\u2022\u00a0Nucleus Source Code: All versions<br \/>\n\u2022\u00a0VSTAR: All versions<\/p>\n\n<p>Siemens hardware:<br \/>\n\u2022\u00a0S7-1200: all versions<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to cause a denial of service or compromise the integrity of the systems affected, or access protected information.<br \/>\nThe Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer update:<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-434032.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-434032.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-898181.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-898181.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-686531.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-686531.pdf<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-2","alert_type":398,"serial_number":"AV19-265","subject":null,"moderation_state":"published","external_url":null},{"nid":1683,"title":"[Control systems] Philips security advisory","uuid":"f5e1fcf9-ac94-401c-95b4-59802e6a3a64","banner":null,"lang":"en","date_modified":"2019-11-26","date_modified_ts":"2019-11-26T20:20:05Z","date_created":"2019-11-26T20:20:05Z","summary":null,"body":["<article data-history-node-id=\"1683\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-264<\/strong><br \/><strong>Date:\u00a026 November 2019<\/strong><\/p>\n\n<p>On 14 November 2019 Philips released a security update to address a vulnerability in the following versions of IntelliBridge:<\/p>\n\n<p>\u2022\u00a0IntelliBridge EC40 Hub<br \/>\n\u2022\u00a0IntelliBridge EC80 Hub<\/p>\n\n<p>Successful exploitation of this vulnerability may allow a remote actor to execute software, modify system configuration, or view\/update files, including protected patient data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Medical Advisory (ICSMA-19-318-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-318-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-318-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-1","alert_type":398,"serial_number":"AV19-264","subject":null,"moderation_state":"published","external_url":null},{"nid":1686,"title":"[Control systems] ABB security advisory","uuid":"c3c49eab-c677-49a7-8871-3385c0173724","banner":null,"lang":"en","date_modified":"2019-11-26","date_modified_ts":"2019-11-26T20:31:22Z","date_created":"2019-11-26T20:31:22Z","summary":null,"body":["<article data-history-node-id=\"1686\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-263<\/strong><br \/><strong>Date: 26 November 2019<\/strong><\/p>\n\n<p>On 1 November 2019, ABB released security updates to address multiple vulnerabilities in all versions of the Power Generation Information Manager (PGIM) and Plant Connect monitoring platforms. Successful exploitation of these vulnerabilities may allow a remote actor to bypass authentication and extract the user credentials used within the applications.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=8VZZ002158T0001&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=8VZZ002158T0001&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory","alert_type":398,"serial_number":"AV19-263","subject":null,"moderation_state":"published","external_url":null},{"nid":1690,"title":"Fortinet security advisory","uuid":"9e9da749-97fa-418f-8bed-3735fb3e253d","banner":null,"lang":"en","date_modified":"2019-11-27","date_modified_ts":"2019-11-27T14:00:51Z","date_created":"2019-11-27T14:00:51Z","summary":null,"body":["<article data-history-node-id=\"1690\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-266<\/strong><br \/><strong>Date: 27 November 2019<\/strong><\/p>\n\n<p>On 14 November 2019 Fortinet released a security update to address a vulnerability in FortiOS 6.2.1 and earlier versions. Successful exploitation of this vulnerability may allow a non-privileged user to obtain plain text private keys of the system's built-in local certificates or user-uploaded local certificates.<\/p>\n\n<p>Note: By restoring a backup copy of the configuration files to a vulnerable version of FortiOS, an actor could obtain the plain-text private keys.<\/p>\n\n<p>The Cyber Centre encourages users to review the following Fortinet Advisory and apply the necessary updates or workarounds:<\/p>\n\n<p><a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-19-134\">https:\/\/fortiguard.com\/psirt\/FG-IR-19-134<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-3","alert_type":396,"serial_number":"AV19-266","subject":null,"moderation_state":"published","external_url":null},{"nid":1691,"title":"Ubuntu security advisory","uuid":"9c688a6a-212d-4f4f-ac0e-b1ae66f24f7b","banner":null,"lang":"en","date_modified":"2019-12-03","date_modified_ts":"2019-12-03T19:52:25Z","date_created":"2019-12-03T19:52:25Z","summary":null,"body":["<article data-history-node-id=\"1691\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-267<\/strong><br \/><strong>Date:\u00a03 December 2019<\/strong><\/p>\n\n<p>On 2 December 2019 Ubuntu released security updates to address vulnerabilities affecting the Linux kernel. A local actor could exploit some of these vulnerabilities to execute arbitrary code or cause a denial of service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Ubuntu Security Notices webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/usn.ubuntu.com\/\">https:\/\/usn.ubuntu.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory","alert_type":396,"serial_number":"AV19-267","subject":null,"moderation_state":"published","external_url":null},{"nid":1692,"title":"[Control systems] Moxa security advisory","uuid":"1e3b1f05-b929-4cf5-b101-24ff87d9c973","banner":null,"lang":"en","date_modified":"2019-12-04","date_modified_ts":"2019-12-04T13:34:59Z","date_created":"2019-12-04T13:34:59Z","summary":null,"body":["<article data-history-node-id=\"1692\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-268<\/strong><br \/><strong>Date:\u00a04 December 2019<\/strong><\/p>\n\n<p>On 2 December 2019 Moxa released security updates to address vulnerabilities in the Moxa AWK-3121 Series Industrial AP\/Bridge\/Client.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow an actor to view sensitive information, cause availability issues, and execute remote code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p><a href=\"https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/awk-3121-series-industrial-ap-bridge-client-vulnerabilities\">https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/awk-3121-series-industrial-ap-bridge-client-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-0","alert_type":398,"serial_number":"AV19-268","subject":null,"moderation_state":"published","external_url":null},{"nid":1693,"title":"[Control systems] Reliable Controls security advisory","uuid":"92e69c62-af43-4b88-8526-ef9490c24ce9","banner":null,"lang":"en","date_modified":"2019-12-04","date_modified_ts":"2019-12-04T13:39:11Z","date_created":"2019-12-04T13:39:11Z","summary":null,"body":["<article data-history-node-id=\"1693\" about=\"\/en\/alerts-advisories\/control-systems-reliable-controls-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-269<\/strong><br \/><strong>Date:\u00a04 December 2019<\/strong><\/p>\n\n<p>On 3 December 2019 Reliable Controls released a security update to address a vulnerability in RC-LicenseManager (versions 3.4 and below).<\/p>\n\n<p>Successful exploitation of this vulnerability may allow an actor to crash the system, view sensitive data, or execute arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Advisory (ICSA-19-337-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-337-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-337-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-reliable-controls-security-advisory","alert_type":398,"serial_number":"AV19-269","subject":null,"moderation_state":"published","external_url":null},{"nid":1694,"title":"Android security advisory","uuid":"5a5e2aa1-6494-42e3-bad4-80bd51bf32bb","banner":null,"lang":"en","date_modified":"2019-12-04","date_modified_ts":"2019-12-04T13:43:07Z","date_created":"2019-12-04T13:43:07Z","summary":null,"body":["<article data-history-node-id=\"1694\" about=\"\/en\/alerts-advisories\/android-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\"><strong>Number: AV19-270<\/strong><br \/><strong>Date:\u00a04 December 2019<\/strong><\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\u00a0<\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\n<p>On 2 December 2019 Android published a Security Bulletin to address multiple vulnerabilities affecting Android devices. A remote actor could exploit one of these vulnerabilities to execute code on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Android Security Bulletin and apply the necessary updates, when available:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2019-12-01\">https:\/\/source.android.com\/security\/bulletin\/2019-12-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-7","alert_type":396,"serial_number":"AV19-270","subject":null,"moderation_state":"published","external_url":null},{"nid":1695,"title":"Mozilla security advisory","uuid":"23639f03-7851-488b-b96f-7d55fa0cd881","banner":null,"lang":"en","date_modified":"2019-12-04","date_modified_ts":"2019-12-04T18:26:10Z","date_created":"2019-12-04T18:22:47Z","summary":null,"body":["<article data-history-node-id=\"1695\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-271<\/strong><br \/><strong>Date: 04 December 2019<\/strong><\/p>\n\n<p>On 3 December 2019 Mozilla released Firefox 71 and Firefox ESR 68.3. These releases include security updates to address vulnerabilities that may allow arbitrary code execution when running on Windows operating systems.<br \/>\nThe Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-36\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-36\/<\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-37\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2019-37\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-7","alert_type":396,"serial_number":"AV19-271","subject":null,"moderation_state":"published","external_url":null},{"nid":1696,"title":"OpenBSD security advisory","uuid":"430a193c-c25a-4b21-8480-926bda61d36b","banner":null,"lang":"en","date_modified":"2019-12-06","date_modified_ts":"2019-12-06T14:43:58Z","date_created":"2019-12-06T14:43:20Z","summary":null,"body":["<article data-history-node-id=\"1696\" about=\"\/en\/alerts-advisories\/openbsd-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-272<\/strong><br \/><strong>Date: 06 December 2019<\/strong><\/p>\n\n<p>On 4 December 2019 OpenBSD released patches for a number of vulnerabilities in versions 6.5 and 6.6 of their operating system. Successful exploitation of these vulnerabilities could allow for local privilege escalation as well as authentication bypass.\u00a0 Of note is a vulnerability in libc, tracked as CVE-2019-19521, which could allow a remote actor to bypass the authentication mechanisms in smtpd, ldapd, and radius.<br \/>\nThe Cyber Centre encourages users and administrators to review the OpenBSD Security Advisories webpages and apply the necessary updates:<br \/>\nOpenBSD:\u00a0<a href=\"https:\/\/www.openbsd.org\/errata65.html\">https:\/\/www.openbsd.org\/errata65.html<\/a><br \/><a href=\"https:\/\/www.openbsd.org\/errata66.html\">https:\/\/www.openbsd.org\/errata66.html<\/a><br \/>\n\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openbsd-security-advisory","alert_type":396,"serial_number":"AV19-272","subject":null,"moderation_state":"published","external_url":null},{"nid":1697,"title":"[Control systems] Weidmueller security advisory","uuid":"318edb34-a02c-4c23-99b4-74f879f72d01","banner":null,"lang":"en","date_modified":"2019-12-06","date_modified_ts":"2019-12-06T14:48:43Z","date_created":"2019-12-06T14:48:43Z","summary":null,"body":["<article data-history-node-id=\"1697\" about=\"\/en\/alerts-advisories\/control-systems-weidmueller-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-273<\/strong><br \/><strong>Date: 06 December 2019<\/strong><\/p>\n\n<p>On 5 December 2019 Weidmueller released security updates to address vulnerabilities in a wide variety of their Industrial Ethernet Switches. Successful exploitation of these vulnerabilities may allow an actor to take complete control of the affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<br \/>\nICS Advisory (ICSA-19-339-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-339-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-339-02<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-weidmueller-security-advisory","alert_type":398,"serial_number":"AV19-273","subject":null,"moderation_state":"published","external_url":null},{"nid":1698,"title":"[Control systems] Thales DIS security advisory","uuid":"be3c4d07-3db4-4428-b48b-e34bda1b14a6","banner":null,"lang":"en","date_modified":"2019-12-06","date_modified_ts":"2019-12-06T14:53:12Z","date_created":"2019-12-06T14:53:12Z","summary":null,"body":["<article data-history-node-id=\"1698\" about=\"\/en\/alerts-advisories\/control-systems-thales-dis-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-274<\/strong><br \/><strong>Date: 06 December 2019<\/strong><\/p>\n\n<p>On 5 December 2019 Thales DIS released a security update to address a vulnerability in all Microsoft Windows versions of SafeNet Sentinel LDK License manager prior to 7.101. Successful exploitation of this vulnerability may allow a local actor to create, write, and\/or delete files in the system folder using symbolic links leading to a privilege escalation, or execute a malicious DLL.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<br \/>\nICS Advisory (ICSA-19-339-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-339-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-339-01<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-thales-dis-security-advisory","alert_type":398,"serial_number":"AV19-274","subject":null,"moderation_state":"published","external_url":null},{"nid":1699,"title":"NVIDIA security advisory","uuid":"988a5c8e-335b-479a-a7e5-807b55018a21","banner":null,"lang":"en","date_modified":"2019-12-06","date_modified_ts":"2019-12-06T20:58:14Z","date_created":"2019-12-06T20:58:14Z","summary":null,"body":["<article data-history-node-id=\"1699\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-275<\/strong><br \/><strong>Date: 06 December 2019<\/strong><\/p>\n\n<p>On 5 December 2019 NVIDIA released security updates to address vulnerabilities affecting the Tegra Linux Driver Package (L4T) for Jetson AGX Xavier, TK1, TX1, TX2, and Nano chip. These updates address issues that may lead to arbitrary code execution, escalation of privilege, denial-of-service (DoS), and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4910\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4910<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-6","alert_type":396,"serial_number":"AV19-275","subject":null,"moderation_state":"published","external_url":null},{"nid":1700,"title":"VMware security advisory ","uuid":"6f2fe2d3-dff3-41c7-850b-76d760a2b5e1","banner":null,"lang":"en","date_modified":"2019-12-06","date_modified_ts":"2019-12-06T21:03:59Z","date_created":"2019-12-06T21:03:59Z","summary":null,"body":["<article data-history-node-id=\"1700\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-276<\/strong><br \/><strong>Date: 06 December 2019<\/strong><\/p>\n\n<p>On 5 December 2019 VMware released security updates to address vulnerabilities affecting VMware ESXi and the Horizon DaaS appliances. Successful exploitation of these vulnerabilities could lead to remote code execution on the host.\u00a0<\/p>\n\n<p>The Cyber Centre encourages users to review the following VMware Advisory and apply the necessary updates or workarounds:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0022.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2019-0022.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-21","alert_type":396,"serial_number":"AV19-276","subject":null,"moderation_state":"published","external_url":null},{"nid":1701,"title":"Intel security advisory","uuid":"0d17df2e-ed46-49c3-b3f8-45763f829e7e","banner":null,"lang":"en","date_modified":"2019-12-10","date_modified_ts":"2019-12-10T18:21:32Z","date_created":"2019-12-10T18:21:32Z","summary":null,"body":["<article data-history-node-id=\"1701\" about=\"\/en\/alerts-advisories\/intel-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-277<\/strong><br \/><strong>Date:\u00a010 December 2019<\/strong><\/p>\n\n<p>On 10 December 2019 Intel released security updates to address vulnerabilities affecting several Intel products. Of note are vulnerabilities in Intel NUC firmware, which could allow an authenticated actor to enable escalation of privileges via local access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Intel Product Security Center Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-7","alert_type":396,"serial_number":"AV19-277","subject":null,"moderation_state":"published","external_url":null},{"nid":1702,"title":"[Control systems] Siemens security advisory","uuid":"1256e0e4-0628-46a9-adc4-923713997531","banner":null,"lang":"en","date_modified":"2019-12-10","date_modified_ts":"2019-12-10T18:26:24Z","date_created":"2019-12-10T18:26:24Z","summary":null,"body":["<article data-history-node-id=\"1702\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-278<\/strong><br \/><strong>Date:\u00a010 December 2019<\/strong><\/p>\n\n<p>On 10 December 2019 Siemens released security updates to address vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0SPPA-T3000 Application Server.<br \/>\n\u2022\u00a0SPPA-T3000 MS3000 Migration Server.<br \/>\n\u2022\u00a0SIMATIC S7-1200, SIMATIC S7-1500 and SIMATIC SoftwareController CPU families.<br \/>\n\u2022\u00a0XHQ Operations Intelligence product line.<br \/>\n\u2022\u00a0EN100 Ethernet communication modules.<br \/>\n\u2022\u00a0SiNVR 3 Central Control Server (CCS).<br \/>\n\u2022\u00a0SiNVR 3 Video Server.<br \/>\n\u2022\u00a0SCALANCE W1700.<br \/>\n\u2022\u00a0SCALANCE W700.<br \/>\n\u2022\u00a0RUGGEDCOM ROS devices.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to take control of an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-451445.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-451445.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-273799.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-273799.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-525454.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-525454.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-418979.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-418979.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-761617.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-761617.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-344983.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-344983.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-618620.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-618620.pdf<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-3","alert_type":398,"serial_number":"AV19-278","subject":null,"moderation_state":"published","external_url":null},{"nid":1703,"title":"Apple security advisory","uuid":"9e1f5e4c-7887-4999-b4c8-18b470185d69","banner":null,"lang":"en","date_modified":"2019-12-11","date_modified_ts":"2019-12-11T17:27:30Z","date_created":"2019-12-11T17:27:30Z","summary":null,"body":["<article data-history-node-id=\"1703\" about=\"\/en\/alerts-advisories\/apple-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-281<\/strong><br \/><strong>Date: 11 December 2019<\/strong><\/p>\n\n<p>On 10 December 2019 Apple released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<li>Xcode 11.3<\/li>\n<li>watchOS 5.3.4<\/li>\n<li>watchOS 6.1.1<\/li>\n<li>tvOS 13.3<\/li>\n<li>macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra<\/li>\n<li>Safari 13.0.4<\/li>\n<li>iOS 12.4.4<\/li>\n<li>iOS 13.3 and iPadOS 13.3<\/li>\n\n\n<p>Exploitation of these vulnerabilities could allow an application to execute arbitrary code with system level privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.  We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-8","alert_type":396,"serial_number":"AV19-281","subject":null,"moderation_state":"published","external_url":null},{"nid":1704,"title":"Adobe security advisory","uuid":"f8879f8d-1059-4e5a-9921-d116ce8ac725","banner":null,"lang":"en","date_modified":"2019-12-11","date_modified_ts":"2019-12-11T18:18:54Z","date_created":"2019-12-11T18:18:54Z","summary":null,"body":["<article data-history-node-id=\"1704\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-279<\/strong><br \/><strong>Date: 11 December 2019<\/strong><\/p>\n\n<p>On 10 December 2019 Adobe released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<p>\u2022\u00a0Adobe Acrobat and Reader<br \/>\n\u2022\u00a0Brackets<br \/>\n\u2022\u00a0Adobe Photoshop CC<br \/>\n\u2022\u00a0Adobe ColdFusion<\/p>\n\n<p>Some of these vulnerabilities could lead to arbitrary code execution in the context of the current user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p>Note to Readers<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-9","alert_type":396,"serial_number":"AV19-279","subject":null,"moderation_state":"published","external_url":null},{"nid":1705,"title":"Microsoft security advisory \u2013 December 2019 monthly rollup","uuid":"278fdda7-10af-4dd8-957d-de8888dafb66","banner":null,"lang":"en","date_modified":"2019-12-11","date_modified_ts":"2019-12-11T18:26:55Z","date_created":"2019-12-11T18:26:55Z","summary":null,"body":["<article data-history-node-id=\"1705\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-december-2019-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-280<\/strong><br \/><strong>Date:\u00a011 December 2019<\/strong><\/p>\n\n<p>On 10 December 2019 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for 7 critical remote code execution vulnerabilities, most of which result from improperly sanitized input when using Git for Visual Studio.<\/p>\n\n<p>Also of note is an elevation of privilege vulnerability, tracked as CVE-2019-1458, which may be exploited to run arbitrary code in kernel mode. Microsoft reports that exploitation has been detected for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft December 2019 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2019-Dec\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2019-Dec<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-december-2019-monthly-rollup","alert_type":396,"serial_number":"AV19-280","subject":null,"moderation_state":"published","external_url":null},{"nid":1706,"title":"Google Chrome security advisory","uuid":"473a4323-50f4-43cd-a273-b2243e0c1ddd","banner":null,"lang":"en","date_modified":"2019-12-11","date_modified_ts":"2019-12-11T18:28:02Z","date_created":"2019-12-11T18:28:02Z","summary":null,"body":["<article data-history-node-id=\"1706\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-282<\/strong><br \/><strong>Date: 11 December 2019<\/strong><\/p>\n\n<p>On 10 December 2019 Google announced the release of Chrome 79.0.3945.79 for Windows, Mac, and Linux. This update addresses vulnerabilities within Chrome that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2019\/12\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2019\/12\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-11","alert_type":396,"serial_number":"AV19-282","subject":null,"moderation_state":"published","external_url":null},{"nid":1707,"title":"[Control systems] Omron security advisory","uuid":"9c4f3c5c-1612-427b-8a8b-81528afe9d0b","banner":null,"lang":"en","date_modified":"2019-12-13","date_modified_ts":"2019-12-13T17:43:04Z","date_created":"2019-12-13T17:43:04Z","summary":null,"body":["<article data-history-node-id=\"1707\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-283<\/strong><br \/><strong>Date:\u00a013 December 2019<\/strong><\/p>\n\n<p>On 12 December 2019 Omron released security updates to address vulnerabilities in the following PLC devices:<\/p>\n\n<p>\u2022\u00a0Omron PLC CS series<br \/>\n\u2022\u00a0Omron PLC CJ series<br \/>\n\u2022\u00a0Omron PLC NJ series<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to obtain unauthorized access to the devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-19-346-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-346-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-346-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-19-346-03)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-346-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-346-03<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-0","alert_type":398,"serial_number":"AV19-283","subject":null,"moderation_state":"published","external_url":null},{"nid":1708,"title":"[Control systems] Advantech security advisory","uuid":"aaa9f710-8945-45e3-8531-ed3f0ac2b77e","banner":null,"lang":"en","date_modified":"2019-12-13","date_modified_ts":"2019-12-13T17:48:51Z","date_created":"2019-12-13T17:48:51Z","summary":null,"body":["<article data-history-node-id=\"1708\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-284<\/strong><br \/><strong>Date:\u00a013 December 2019<\/strong><\/p>\n\n<p>On 12 December 2019 Advantech released a security update to address a vulnerability in Advantech DiagAnywhere Server (Versions 3.07.11 and older). Successful exploitation of this vulnerability may allow for remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-19-346-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-346-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-346-01<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-1","alert_type":398,"serial_number":"AV19-284","subject":null,"moderation_state":"published","external_url":null},{"nid":1709,"title":"WordPress security advisory","uuid":"2349c49e-673c-4758-b927-2a4b93851e78","banner":null,"lang":"en","date_modified":"2019-12-13","date_modified_ts":"2019-12-13T19:46:28Z","date_created":"2019-12-13T19:46:28Z","summary":null,"body":["<article data-history-node-id=\"1709\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-284<\/strong><br \/><strong>Date:\u00a013 December 2019<\/strong><\/p>\n\n<p>On 13 December 2019 WordPress released version 5.3.1 to address vulnerabilities related to version 5.3 and prior.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following WordPress Security Release and upgrade to the necessary version:<\/p>\n\n<p><a href=\"https:\/\/wordpress.org\/news\/2019\/12\/wordpress-5-3-1-security-and-maintenance-release\/\">https:\/\/wordpress.org\/news\/2019\/12\/wordpress-5-3-1-security-and-maintenance-release\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-1","alert_type":396,"serial_number":"AV19-285","subject":null,"moderation_state":"published","external_url":null},{"nid":1710,"title":"Drupal security advisory","uuid":"84c19f93-8742-4270-b873-3967eb25a4bd","banner":null,"lang":"en","date_modified":"2019-12-19","date_modified_ts":"2019-12-19T19:34:53Z","date_created":"2019-12-19T19:34:53Z","summary":null,"body":["<article data-history-node-id=\"1710\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-286<\/strong><br \/><strong>Date:\u00a019 December 2019<\/strong><\/p>\n\n<p>On 18 December 2019 Drupal released updates to address vulnerabilities in its content management system (CMS). Of note is a vulnerability that could allow an actor to overwrite system files on the Drupal server by uploading maliciously-crafted .tar, .tar.gz, .bz2, or .tlz files. This only affects Drupal deployments that are configured to allow uploading of the aforementioned file types. It has been reported that an exploit for this vulnerability is available.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Drupal Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/security\">https:\/\/www.drupal.org\/security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-5","alert_type":396,"serial_number":"AV19-286","subject":null,"moderation_state":"published","external_url":null},{"nid":1712,"title":"[Control systems] Equinox security advisory","uuid":"0c116d79-90be-4aba-9171-73d213ab552a","banner":null,"lang":"en","date_modified":"2019-12-20","date_modified_ts":"2019-12-20T15:26:27Z","date_created":"2019-12-20T15:26:27Z","summary":null,"body":["<article data-history-node-id=\"1712\" about=\"\/en\/alerts-advisories\/control-systems-equinox-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-290<\/strong><br \/><strong>Date: 20 December 2019<\/strong><\/p>\n\n<p>On 19 December 2019 Equinox released a security update to address a vulnerability in their HMI\/SCADA management platform Control Expert. Successful exploitation of this vulnerability may allow a remote actor to execute code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Advisory (ICSA-19-353-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-353-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-353-02<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-equinox-security-advisory","alert_type":398,"serial_number":"AV19-290","subject":null,"moderation_state":"published","external_url":null},{"nid":1713,"title":"[Control systems] Wecon security advisory","uuid":"74a0ddd0-6183-4f0a-a5ec-b067d2e02e71","banner":null,"lang":"en","date_modified":"2019-12-20","date_modified_ts":"2019-12-20T15:33:17Z","date_created":"2019-12-20T15:33:17Z","summary":null,"body":["<article data-history-node-id=\"1713\" about=\"\/en\/alerts-advisories\/control-systems-wecon-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-289<\/strong><br \/><strong>Date: 20 December 2019<\/strong><\/p>\n\n<p>On 19 December 2019 Wecon released a security update to address a vulnerability in PLC Editor Version 1.3.5_20190129 (additional versions may also be vulnerable). Successful exploitation of this vulnerability may allow a remote actor to execute code under the privileges of the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Advisory (ICSA-19-353-03)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-353-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-353-03<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wecon-security-advisory","alert_type":398,"serial_number":"AV19-289","subject":null,"moderation_state":"published","external_url":null},{"nid":1714,"title":"[Control systems] Reliable Controls security advisory","uuid":"9621799e-6af5-4a83-822b-02113b6c0ad9","banner":null,"lang":"en","date_modified":"2019-12-20","date_modified_ts":"2019-12-20T15:40:07Z","date_created":"2019-12-20T15:40:07Z","summary":null,"body":["<article data-history-node-id=\"1714\" about=\"\/en\/alerts-advisories\/control-systems-reliable-controls-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-288<\/strong><br \/><strong>Date: 20 December 2019<\/strong><\/p>\n\n<p>On 19 December 2019 Reliable Controls released a security update to address a vulnerability in MACH ProWebCom\/Sys (versions 2.15 and lower(Firmware versions prior to 8.26.4)).<\/p>\n\n<p>Successful exploitation of this vulnerability may allow a remote actor to execute commands on behalf of the affected user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Advisory (ICSA-19-353-04)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-353-04\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-353-04<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-reliable-controls-security-advisory-0","alert_type":398,"serial_number":"AV19-288","subject":null,"moderation_state":"published","external_url":null},{"nid":1715,"title":"[Control systems] Philips security advisory","uuid":"a1e79372-17c2-46fa-b8fe-964661eadb1a","banner":null,"lang":"en","date_modified":"2019-12-20","date_modified_ts":"2019-12-20T15:51:21Z","date_created":"2019-12-20T15:49:54Z","summary":null,"body":["<article data-history-node-id=\"1715\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-287<\/strong><br \/><strong>Date: 20 December 2019<\/strong><\/p>\n\n<p>On 19 December 2019 Philips released a security update to address a vulnerability in the following products:<\/p>\n\n<ul><li>Veradius Unity (718132) with wireless option (shipped between 2016-August 2018)<\/li>\n\t<li>Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018)<\/li>\n\t<li>Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018)<\/li>\n\t<li>Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018)<\/li>\n<\/ul><p>Successful exploitation of this vulnerability may allow a remote actor to impact the availability of data transfer via wireless communication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Medical Advisory (ICSMA-19-353-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-353-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-19-353-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-2","alert_type":398,"serial_number":"AV19-287","subject":null,"moderation_state":"published","external_url":null},{"nid":1711,"title":"Citrix security advisory","uuid":"27b53827-ade6-49f0-a6c2-0b32439402ef","banner":null,"lang":"en","date_modified":"2019-12-23","date_modified_ts":"2019-12-23T19:38:27Z","date_created":"2019-12-23T19:38:27Z","summary":null,"body":["<article data-history-node-id=\"1711\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-291<\/strong><br \/><strong>Date: 23 December 2019<\/strong><\/p>\n\n<p>On 17 December 2019 Citrix released a security bulletin to address a critical vulnerability, tracked as CVE-2019-19781, for the following products:<\/p>\n\n<p>\u2022\u00a0Citrix ADC and Citrix Gateway version 13.0 all supported builds<br \/>\n\u2022\u00a0Citrix ADC and NetScaler Gateway version 12.1 all supported builds<br \/>\n\u2022\u00a0Citrix ADC and NetScaler Gateway version 12.0 all supported builds<br \/>\n\u2022\u00a0Citrix ADC and NetScaler Gateway version 11.1 all supported builds<br \/>\n\u2022\u00a0Citrix NetScaler ADC and NetScaler Gateway version 10.5 all supported builds<\/p>\n\n<p>Successful exploitation of this vulnerability may allow an unauthenticated remote actor to perform arbitrary code execution.<\/p>\n\n<p>Citrix has provided steps to mitigate the effect of this vulnerability until they are able to release an updated version of the firmware for affected devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Citrix publications and apply the necessary updates when available:<\/p>\n\n<p>Mitigation Steps<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX267679\">https:\/\/support.citrix.com\/article\/CTX267679<\/a><\/p>\n\n<p>Citrix Advisory<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX267027\">https:\/\/support.citrix.com\/article\/CTX267027<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-0","alert_type":396,"serial_number":"AV19-291","subject":null,"moderation_state":"published","external_url":null},{"nid":1716,"title":"NVIDIA security advisory","uuid":"8a3e32bf-36e0-4603-8ece-1ad3cb1ee0fb","banner":null,"lang":"en","date_modified":"2019-12-24","date_modified_ts":"2019-12-24T15:34:34Z","date_created":"2019-12-24T15:34:34Z","summary":null,"body":["<article data-history-node-id=\"1716\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV19-292<\/strong><br \/><strong>Date: 24 December 2019<\/strong><\/p>\n\n<p>On 23 December 2019 NVIDIA released a security update to address a vulnerability affecting GeForce Experience. Successful exploitation of this vulnerability may lead to denial of service or escalation of privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4954\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4954<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-7","alert_type":396,"serial_number":"AV19-292","subject":null,"moderation_state":"published","external_url":null},{"nid":1717,"title":"Cisco security advisory","uuid":"90d5db0d-1b5a-4adf-b501-8ee2892d8923","banner":null,"lang":"en","date_modified":"2020-01-03","date_modified_ts":"2020-01-03T13:10:57Z","date_created":"2020-01-03T13:10:57Z","summary":null,"body":["<article data-history-node-id=\"1717\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-001<\/strong><br \/><strong>Date:\u00a03\u00a0January 2019<\/strong><\/p>\n\n<p>On 2 January 2020 Cisco released a number of security advisories to address vulnerabilities affecting the Cisco Data Center Network Manager (DCNM).\u00a0 Some of these vulnerabilities could allow an unauthenticated, remote actor to execute arbitrary code with administrator privileges on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-38","alert_type":396,"serial_number":"AV20-001","subject":null,"moderation_state":"published","external_url":null},{"nid":1718,"title":"Mozilla security advisory","uuid":"62435ba4-ea79-4ba4-93da-5941c854cb69","banner":null,"lang":"en","date_modified":"2020-01-07","date_modified_ts":"2020-01-07T18:48:12Z","date_created":"2020-01-07T18:48:12Z","summary":null,"body":["<article data-history-node-id=\"1718\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-002<\/strong><br \/><strong>Date: 7 January 2020<\/strong><\/p>\n\n<p>On 7 January 2020 Mozilla released Firefox 72 and Firefox ESR 68.4. These releases include security updates to address vulnerabilities that may allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-01\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-01\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-02\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-02\/<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-8","alert_type":396,"serial_number":"AV20-002","subject":null,"moderation_state":"published","external_url":null},{"nid":1719,"title":"Android security advisory","uuid":"bf597075-e049-4626-ba9c-80969590eea9","banner":null,"lang":"en","date_modified":"2020-01-07","date_modified_ts":"2020-01-07T20:11:28Z","date_created":"2020-01-07T20:11:28Z","summary":null,"body":["<article data-history-node-id=\"1719\" about=\"\/en\/alerts-advisories\/android-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\"><strong>Number: AV20-003<\/strong><br \/><strong>Date: 7 January 2020<\/strong><\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\u00a0<\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\n<p>On 6 January 2020 Android published a Security Bulletin to address multiple vulnerabilities affecting Android devices. A remote actor could exploit one of these vulnerabilities to execute code on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Android Security Bulletin and apply the necessary updates, when available:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-01-01.html\">https:\/\/source.android.com\/security\/bulletin\/2020-01-01.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-8","alert_type":396,"serial_number":"AV20-003","subject":null,"moderation_state":"published","external_url":null},{"nid":1720,"title":"Google Chrome security advisory","uuid":"0b3b15c5-af1f-44f0-9113-f7d9c1ba271a","banner":null,"lang":"en","date_modified":"2020-01-08","date_modified_ts":"2020-01-08T16:49:32Z","date_created":"2020-01-08T16:49:32Z","summary":null,"body":["<article data-history-node-id=\"1720\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-004<\/strong><br \/><strong>Date: 8 January 2020<\/strong><\/p>\n\n<p>On 7 January 2020 Google announced the release of Chrome 79.0.3945.117 for Windows, Mac, and Linux. This update addresses vulnerabilities within Chrome that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/01\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/01\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-12","alert_type":396,"serial_number":"AV20-004","subject":null,"moderation_state":"published","external_url":null},{"nid":1721,"title":"Mozilla security advisory","uuid":"308bb136-223f-49d3-a42e-a2d64ff4be72","banner":null,"lang":"en","date_modified":"2020-01-09","date_modified_ts":"2020-01-09T15:11:43Z","date_created":"2020-01-09T15:11:43Z","summary":null,"body":["<article data-history-node-id=\"1721\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-005<\/strong><br \/><strong>Date: 09 January 2020<\/strong><\/p>\n\n<p>On 8 January 2020 Mozilla released Firefox 72.0.1 and Firefox ESR 68.4.1 to address a critical type confusion vulnerability which may allow for out-of-bounds memory access. This access may lead to arbitrary code execution.<br \/>\nMozilla reports that exploitation has been detected for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-03\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-03\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-9","alert_type":396,"serial_number":"AV20-005","subject":null,"moderation_state":"published","external_url":null},{"nid":1722,"title":"Cisco security advisory","uuid":"dcd53694-36d9-4ad3-a5fe-28768909226b","banner":null,"lang":"en","date_modified":"2020-01-09","date_modified_ts":"2020-01-09T20:23:55Z","date_created":"2020-01-09T20:23:55Z","summary":null,"body":["<article data-history-node-id=\"1722\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-39\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-006<\/strong><br \/><strong>Date: 09 January 2020<\/strong><\/p>\n\n<p>On 8 January 2020 Cisco released security advisories to address vulnerabilities affecting some of its products.\u00a0 One of these vulnerabilities affects the web UI of Cisco IOS and Cisco IOS XE Software and could allow an unauthenticated, remote actor to conduct cross-site request forgery (CSRF) on an affected system if the actor can convince a user of the IOS interface to follow a malicious link. Successful exploitation could allow an actor to perform arbitrary actions with the privilege level of the targeted user, such as altering the configuration or executing arbitrary commands on the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-39","alert_type":396,"serial_number":"AV20-006","subject":null,"moderation_state":"published","external_url":null},{"nid":1723,"title":"Juniper Networks security advisory","uuid":"cb872c37-b226-48fc-b12a-00136b0bfdbd","banner":null,"lang":"en","date_modified":"2020-01-09","date_modified_ts":"2020-01-09T20:55:16Z","date_created":"2020-01-09T20:55:16Z","summary":null,"body":["<article data-history-node-id=\"1723\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-007<\/strong><br \/><strong>Date: 09 January 2020<\/strong><\/p>\n\n<p>On 8 January 2020 Juniper Networks released several security bulletins to address vulnerabilities affecting some of its products. Two bulletins of note are JSA10981, which concerns vulnerabilities in Junos OS and Junos OS Evolved that could allow a remote actor to execute arbitrary commands on an affected system; and JSA10992, which describes a remote code execution vulnerability in the Conrail software defined networking platform.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Juniper Networks Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-3","alert_type":396,"serial_number":"AV20-007","subject":null,"moderation_state":"published","external_url":null},{"nid":1725,"title":"Adobe security advisory","uuid":"daac1506-b501-4edc-9bb2-fd4d00189a64","banner":null,"lang":"en","date_modified":"2020-01-14","date_modified_ts":"2020-01-14T17:40:44Z","date_created":"2020-01-14T17:40:44Z","summary":null,"body":["<article data-history-node-id=\"1725\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-009<\/strong><br \/><strong>Date: 14 January 2020<\/strong><\/p>\n\n<p>On 14 January 2020 Adobe released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>Adobe Experience Manager<\/li>\n\t<li>Adobe Illustrator CC<\/li>\n<\/ul><p>Some of these vulnerabilities could lead to arbitrary code execution in the context of the current user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-10","alert_type":396,"serial_number":"AV20-009","subject":null,"moderation_state":"published","external_url":null},{"nid":1724,"title":"[Control systems] Siemens security advisory","uuid":"6e2f4ec1-4b45-41d2-91ee-c7c6251eef1a","banner":null,"lang":"en","date_modified":"2020-01-14","date_modified_ts":"2020-01-14T18:08:21Z","date_created":"2020-01-14T18:08:21Z","summary":null,"body":["<article data-history-node-id=\"1724\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-008<br \/>\nDate: 14 January 2020<\/strong><\/p>\n\n<p>On 14 January 2020 Siemens released security updates to address vulnerabilities in multiple Siemens industrial products.\u00a0 Successful exploitation of these vulnerabilities may allow a remote actor to obtain sensitive information, change device configurations, disable security features, execute arbitrary code as SYSTEM or perform firmware updates.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssb-382508.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssb-382508.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-629512.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-629512.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-443566.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-443566.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-242353.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-242353.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-880233.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-880233.pdf<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-4","alert_type":398,"serial_number":"AV20-008","subject":null,"moderation_state":"published","external_url":null},{"nid":1727,"title":"Critical Microsoft Cryptographic Vulnerability","uuid":"36077c98-7907-4c57-af35-eea0c0fb05a4","banner":null,"lang":"en","date_modified":"2020-01-14","date_modified_ts":"2020-01-14T20:54:59Z","date_created":"2020-01-14T19:50:38Z","summary":null,"body":["<article data-history-node-id=\"1727\" about=\"\/en\/alerts-advisories\/critical-microsoft-cryptographic-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>Number: AL20-001<br \/>\nDate: 14 January 2020<\/p>\n\n<p><strong>AUDIENCE<\/strong><br \/>\n========<\/p>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<p><strong>PURPOSE<\/strong><br \/>\n=======<\/p>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<p><strong>DETAILS<\/strong><br \/>\n=======<\/p>\n\n<p>Microsoft has released security updates for critical vulnerabilities, including one affecting Microsoft Windows cryptographic functionality. This \u2018improper certificate validation\u2019 vulnerability, tracked as CVE-2020-0601, prevents Microsoft Windows from accurately verifying cryptographic trust and may allow an actor to impersonate a trusted entity. Exploitation of this vulnerability would defeat systems that rely on the use of valid certificates to ensure cryptographic trust, allowing full access to encrypted communications and for the ability to execute any code with permissions reserved for trusted software.<br \/>\nThe vulnerable operating systems are:<\/p>\n\n<p>-\u00a0Windows 10<br \/>\n-\u00a0Windows Server 2016<br \/>\n-\u00a0Windows Server 2019<\/p>\n\n<p><strong>SUGGESTED ACTION<\/strong><br \/>\n================<\/p>\n\n<p>The Cyber Centre recommends that organizations immediately install the latest security updates from Microsoft.<\/p>\n\n<p><strong>REFERENCES<\/strong><br \/>\n==========<\/p>\n\n<p>Microsoft Advisory:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0601\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0601<\/a><br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>NSA Advisory:<br \/><a href=\"https:\/\/media.defense.gov\/2020\/Jan\/14\/2002234275\/-1\/-1\/0\/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF\">https:\/\/media.defense.gov\/2020\/Jan\/14\/2002234275\/-1\/-1\/0\/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF<\/a><\/p>\n\n<p><br \/><strong>NOTE TO READERS<\/strong><br \/>\n===============<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the<br \/>\nCyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information<br \/>\nsharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/critical-microsoft-cryptographic-vulnerability","alert_type":397,"serial_number":"AL20-001","subject":null,"moderation_state":"published","external_url":null},{"nid":1726,"title":"Microsoft security advisory \u2013 January 2020 monthly rollup","uuid":"ca6d18d9-b6cf-4857-9bdd-ed5765b8499a","banner":null,"lang":"en","date_modified":"2020-01-14","date_modified_ts":"2020-01-14T20:54:03Z","date_created":"2020-01-14T20:54:03Z","summary":null,"body":["<article data-history-node-id=\"1726\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-010<\/strong><br \/><strong>Date: 14 January 2020<\/strong><\/p>\n\n<p>On 14 January 2020 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for seven critical remote code execution vulnerabilities.<\/p>\n\n<p>Of note is a critical remote code execution vulnerability, tracked as CVE-2020-0609 and CVE-2020-0610, which exists in Windows Remote Desktop Gateway. An unauthenticated, remote actor could send a specially crafted request which could lead to arbitrary code execution on the target system.<\/p>\n\n<p>Also of note is an improper certificate validation vulnerability, tracked as CVE-2020-0601, which may be exploited to undermine how Windows verifies cryptographic trust for Elliptic Curve Cryptography certificates (ECC). This may lead to a loss of trust for any application using ECC certificates which rely on Windows for cryptographic functionality. The vulnerability affects Windows 10 and Windows Server 2016\/2019.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft January 2020 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Jan\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Jan<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-january-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-010","subject":null,"moderation_state":"published","external_url":null},{"nid":1728,"title":"Oracle security advisory \u2013 January 2020 Critical Patch update","uuid":"4c17363c-51f1-4c10-b210-11a2edd0a725","banner":null,"lang":"en","date_modified":"2020-01-15","date_modified_ts":"2020-01-15T15:08:15Z","date_created":"2020-01-15T15:08:15Z","summary":null,"body":["<article data-history-node-id=\"1728\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-january-2020-critical-patch-update\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-011<br \/>\nDate: 15 January 2020<\/strong><\/p>\n\n<p>On 14 January 2020 Oracle released their Critical Patch Update containing 334 security fixes affecting various Oracle products. A remote, unauthenticated actor could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Oracle Critical Patch Update Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2020.html\">https:\/\/www.oracle.com\/security-alerts\/cpujan2020.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-january-2020-critical-patch-update","alert_type":396,"serial_number":"AV20-011","subject":null,"moderation_state":"published","external_url":null},{"nid":1729,"title":"Intel security advisory","uuid":"f998c8f9-5d7e-4f46-a7b8-037352ae6c03","banner":null,"lang":"en","date_modified":"2020-01-16","date_modified_ts":"2020-01-16T20:49:32Z","date_created":"2020-01-16T20:48:26Z","summary":null,"body":["<article data-history-node-id=\"1729\" about=\"\/en\/alerts-advisories\/intel-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-012<br \/>\nDate: 16 January 2020<\/strong><\/p>\n\n<p>On 14 January 2020 Intel published security advisories for the following products:<\/p>\n\n<p>\u2022\u00a0SNMP Subagent Stand-Alone for Windows.<br \/>\n\u2022\u00a0Intel Chipset Device Software INF Utility.<br \/>\n\u2022\u00a0RAID Web Console (RWC) 3 for Windows.<br \/>\n\u2022\u00a0Intel Processor Graphics.<br \/>\n\u2022\u00a0VTune Amplifier for Windows.<br \/>\n\u2022\u00a0Intel Data Analytics Acceleration Library (DAAL).<\/p>\n\n<p>These vulnerabilities may allow for information disclosure, denial of service conditions or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Intel Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00300.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00300.html<\/a><br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00306.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00306.html<\/a><br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00308.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00308.html<\/a><br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00314.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00314.html<\/a><br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00325.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00325.html<\/a><br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00332.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00332.html<\/a><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><strong><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">Note to Readers <\/span><\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-8","alert_type":396,"serial_number":"AV20-012","subject":null,"moderation_state":"published","external_url":null},{"nid":1730,"title":"SAP security advisory","uuid":"95e49d98-fa03-433e-9029-38b4cc3293e0","banner":null,"lang":"en","date_modified":"2020-01-16","date_modified_ts":"2020-01-16T20:54:42Z","date_created":"2020-01-16T20:54:42Z","summary":null,"body":["<article data-history-node-id=\"1730\" about=\"\/en\/alerts-advisories\/sap-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-013<br \/>\nDate: 16 January 2020<\/strong><\/p>\n\n<p>On 14 January 2020 SAP released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<p>\u2022\u00a0SAP Process Integration - Rest Adapter (SAP_XIAF)<br \/>\n\u2022\u00a0SAP NetWeaver Internet Communication Manager<br \/>\n\u2022\u00a0RTCISM<br \/>\n\u2022\u00a0SAP Disclosure Management<br \/>\n\u2022\u00a0Automated Note Search Tool (SAP Basis)<br \/>\n\u2022\u00a0SAP UI<br \/>\n\u2022\u00a0SAP Leasing<\/p>\n\n<p>These vulnerabilities may allow for unauthorized information access, denial of service, cross-site scripting or content spoofing.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the SAP Security Patch Day webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=533671771\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=533671771<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-2","alert_type":396,"serial_number":"AV20-013","subject":null,"moderation_state":"published","external_url":null},{"nid":1731,"title":"VMware security advisory ","uuid":"1e00ce7a-d14e-432a-bf83-0660b1cecac9","banner":null,"lang":"en","date_modified":"2020-01-16","date_modified_ts":"2020-01-16T21:01:23Z","date_created":"2020-01-16T21:01:23Z","summary":null,"body":["<article data-history-node-id=\"1731\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-014<br \/>\nDate: 16 January 2020<\/strong><\/p>\n\n<p>On 14 January 2020 VMware released a security update to address a vulnerability affecting VMware Tools 10 for Windows. Successful exploitation of this vulnerability could lead to privilege escalation on the guest VM.\u00a0<\/p>\n\n<p>The Cyber Centre encourages users to review the following VMware Advisory and apply the necessary update or workaround:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0002.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0002.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-22","alert_type":396,"serial_number":"AV20-014","subject":null,"moderation_state":"published","external_url":null},{"nid":1732,"title":"Google Chrome security advisory","uuid":"44073689-d086-44bd-8fe2-6caf9e523842","banner":null,"lang":"en","date_modified":"2020-01-17","date_modified_ts":"2020-01-17T18:32:09Z","date_created":"2020-01-17T18:32:09Z","summary":null,"body":["<article data-history-node-id=\"1732\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\"><strong>Number: AV20-015<br \/>\nDate: 17 January 2020<\/strong><\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\u00a0<\/div>\n\n<p>On 16 January 2020 Google announced the release of Chrome 79.0.3945.130 for Windows, Mac, and Linux. This update addresses vulnerabilities within Chrome that could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/01\/stable-channel-update-for-desktop_16.html\">https:\/\/chromereleases.googleblog.com\/2020\/01\/stable-channel-update-for-desktop_16.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-13","alert_type":396,"serial_number":"AV20-015","subject":null,"moderation_state":"published","external_url":null},{"nid":2126,"title":"Active Exploitation of Citrix Vulnerabilities","uuid":"7f456394-8914-4d6c-852b-ba298f5520c1","banner":null,"lang":"en","date_modified":"2020-03-18","date_modified_ts":"2020-03-18T16:39:31Z","date_created":"2020-01-17T23:11:17Z","summary":null,"body":["<article data-history-node-id=\"2126\" about=\"\/en\/alerts-advisories\/active-exploitation-citrix-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-003<br \/>\nDate: 17 January 2020<\/strong><\/p>\n\n<p><strong>AUDIENCE<\/strong><br \/>\n========<br \/>\nThis Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<p><strong>PURPOSE<\/strong><br \/>\n=======<br \/>\nAn Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<p><strong>OVERVIEW<\/strong><br \/>\n========<br \/>\nThe Cyber Centre is aware of recent compromises within Canada stemming from a previously reported vulnerability with the Citrix Application Delivery Controller (ADC), formerly known as NetScaler ADC, Citrix Gateway or NetScaler Gateway. Citrix has stated that patches for affected products will not be available until late January 2020. Citrix has provided recommended steps to mitigate the vulnerability in the interim: should it not be possible to implement these steps, the Cyber Centre recommends that vulnerable Citrix devices be disconnected from the Internet immediately.<\/p>\n\n<p><strong>DETAILS<\/strong><br \/>\n=======<br \/>\nThe Cyber Centre is aware that exploit code for an unpatched vulnerability (CVE-2019-19781) in Citrix Application Delivery Controller and Citrix Gateway products is available online, and exploitation activity has been widely reported online since early January. Open source reporting indicates that a number of different payloads have been uploaded to compromised devices. As of 16 January, the Metasploit penetration testing includes a module which exploits this specific vulnerability.<\/p>\n\n<p>In some reported exploitations, a threat actor has been observed uploading malware to vulnerable Citrix servers which adds an additional backdoor while preventing other actors from exploiting the vulnerability. In this scenario, the threat actor uses the curl command to fetch the backdoor from a server with IP address 95[.]179[.]163[.]186.<\/p>\n\n<p>CVE-2019-19781 can be exploited through a directory traversal attack against the \/vpn directory of a vulnerable system. Existing proofs of concept (POC) demonstrate that this can be followed by calling an existing Perl script to append custom XML data onto the vulnerable host: the custom XML data is then called to execute remote code.<\/p>\n\n<p>As patches for this vulnerability are not yet available, the Cyber Centre recommends that system owners refer to the Mitigation and Indicators of Compromise sections of this Alert to protect their networks.<\/p>\n\n<p>Due to the severity of this vulnerability and the amount of active exploitation being observed and reported in Canada and abroad, the Cyber Centre recommends that all vulnerable Citrix devices that cannot have mitigations applied to them be disconnected from the Internet.<\/p>\n\n<p>Affected Citrix products include:<br \/>\nCitrix ADC and Citrix Gateway version 13.0 all supported builds<br \/>\nCitrix ADC and NetScaler Gateway version 12.1 all supported builds<br \/>\nCitrix ADC and NetScaler Gateway version 12.0 all supported builds<br \/>\nCitrix ADC and NetScaler Gateway version 11.1 all supported builds<br \/>\nCitrix NetScaler ADC and NetScaler Gateway version 10.5 all supported builds<br \/>\nCitrix SD-WAN WANOP software and appliance models 4000, 4100, 5000,\u00a0 and 5100 all supported builds<\/p>\n\n<p>On 17 January, Citrix updated their advisory to indicate that a bug exists in Citrix ADC Release 12.1 builds prior to 51.16\/51.19 and 50.31 which prevents the recommended mitigation steps from being effective. The Cyber Centre recommends customers with these builds update to an unaffected build and then fully apply the mitigation steps.<\/p>\n\n<p>\u00a0<br \/><strong>MITIGATION<\/strong><br \/>\n==========<\/p>\n\n<p>The Cyber Centre recommends that until the security patches are released, system owners should apply the mitigation steps recommended by Citrix on their website. Note that all of the mitigation steps must be followed in order to ensure that vulnerable systems are protected. The Citrix recommended mitigations are described in this article: <a href=\"https:\/\/support.citrix.com\/article\/CTX267679\">https:\/\/support.citrix.com\/article\/CTX267679<\/a><\/p>\n\n<p>The Cyber Centre highly recommends that system owners verify the version of Citrix ADC software running on Citrix appliances to ensure that the mitigations will be effective on their version and build. In cases where appliances are found to be running Citrix ADC release version 12.1 with builds before 51.16\/51.19 and 50.31, The Cyber Centre highly recommends that system owners immediately update to a newer build and apply the mitigations as outlined above: the mitigations steps will not be effective when applied to these older builds.<\/p>\n\n<p>The Cybersecurity &amp; Infrastructure Security Agency (CISA) has published a tool to verify whether mitigations have been properly applied. The tool can be found in the CISA GIT repository: <a href=\"https:\/\/github.com\/cisagov\/check-cve-2019-19781\">https:\/\/github.com\/cisagov\/check-cve-2019-19781<\/a><\/p>\n\n<p>The Cyber Centre further recommends that system owners apply the relevant patches once they are available from Citrix. Please refer to this Citrix article for a list of versions being patched and the expected release dates, and carefully note the \u2018Additional Information\u2019 section at the end of the article: <a href=\"https:\/\/support.citrix.com\/article\/CTX267027\">https:\/\/support.citrix.com\/article\/CTX267027<\/a><\/p>\n\n<p>The Cyber Centre recommends that owners of vulnerable Citrix systems review Citrix web request logs for indication of attempted compromise. Indicators may include:<br \/>\nHTTP log entries indicating a directory traversal attacks with \/vpn (eg. \u201c\/vpn\/..\/vpns\/portal\/scripts\/newbm.pl\u201d)<br \/>\nDirect requests to \/vpns\/ without specifying an XML file<br \/>\nA POST followed by a GET to an XML file<br \/>\nA direct POST without a path traversal (eg. \u201cPOST \/vpns\/portal\/scripts\/newbm.pl HTTP\/1.1\u201d)<br \/>\nShould system owners suspect a possible compromise, the Cyber Centre recommends further analysis of local file systems and log files, particularly bash.log, sh.log, and notice.log. Suspicious activity may include:<br \/>\nProcesses spawned by httpd as \u2018nobody\u2019<br \/>\nSuspicious executables run by the user \u2018nobody\u2019 or \u2018null on\u2019<br \/>\nSuspicious or unusual CRON jobs, particularly those running under the user \u2018nobody\u2019<br \/>\nRecently created or suspicious XML files, particularly in locations which allow write or execute permissions, such as \/netscaler\/portal\/templates or \/var\/tmp\/netscaler\/portal\/templates<br \/>\nThe Cyber Centre additionally recommends checking for the following indicators that a vulnerable Citrix system has been compromised by a known backdoor:<br \/>\nA suspicious cron job running from the \/var\/nstmp\/.nscache\/httpd folder<br \/>\nFiles created in the \/netscaler\/portal\/scripts\/ folder or the\u00a0 \/netscaler\/portal\/templates\/ folder, with a filename resembling an MD5 hash (eg:64d4c2d3ee56af4f4ca8171556d50faa)<br \/>\nA background process that listens on UDP port 18634<br \/>\nAny traffic which responds from the Citrix device on UDP port 18634<br \/>\nThe following signatures may be used with a variety of security appliances to detect attempted exploitation activity:<\/p>\n\n<p>Snort:<\/p>\n\n<p>alert http any any -&gt; $HTTP_SERVERS any (msg:\"ET EXPLOIT Possible Citrix Application Delivery Controller Arbitrary Code Execution Attempt (CVE-2019-19781)\"; flow:established,to_server; content:\"\/vpns\/\"; http_uri; fast_pattern; content:\"\/..\/\"; http_uri; metadata: former_category EXPLOIT; reference:url,support.citrix.com\/article\/CTX267679; reference:cve,2019-19781; classtype:attempted-admin; sid:2029206; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, deployment Perimeter, deployment SSLDecrypt, signature_severity Major, created_at 2019_12_30, updated_at 2019_12_30;)<\/p>\n\n<p>Sigma:<\/p>\n\n<p>title: Citrix Netscaler Attack CVE-2019-19781<br \/>\ndescription: Detects CVE-2019-19781 exploitation attempt against Citrix Netscaler, Application Delivery Controller and Citrix Gateway Attack<br \/>\nid: ac5a6409-8c89-44c2-8d64-668c29a2d756<br \/>\nreferences:<br \/>\n\u00a0\u00a0\u00a0 - <a href=\"https:\/\/support.citrix.com\/article\/CTX267679\">https:\/\/support.citrix.com\/article\/CTX267679<\/a><br \/>\n\u00a0\u00a0\u00a0 - <a href=\"https:\/\/support.citrix.com\/article\/CTX267027\">https:\/\/support.citrix.com\/article\/CTX267027<\/a><br \/>\n\u00a0\u00a0\u00a0 - <a href=\"https:\/\/isc.sans.edu\/diary\/25686\">https:\/\/isc.sans.edu\/diary\/25686<\/a><br \/>\nauthor: Arnim Rupp, Florian Roth<br \/>\nstatus: experimental<br \/>\ndate: 2020\/01\/02<br \/>\nmodified: 2020\/01\/11<br \/>\nlogsource:<br \/>\n\u00a0\u00a0\u00a0 category: webserver<br \/>\n\u00a0\u00a0\u00a0 description: 'Make sure that your Netscaler appliance logs all kinds of attacks (test with <a href=\"http:\/\/your-citrix-gw.net\/robots.txt)'\">http:\/\/your-citrix-gw.net\/robots.txt)'<\/a><br \/>\ndetection:<br \/>\n\u00a0\u00a0\u00a0 selection:<br \/>\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 c-uri-path:<br \/>\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 - '*\/..\/vpns\/*'<br \/>\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 - '*\/vpns\/cfg\/smb.conf'<br \/>\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 - '*\/vpns\/portal\/scripts\/newbm.pl*'<br \/>\n\u00a0\u00a0\u00a0 condition: selection<br \/>\nfields:<br \/>\n\u00a0\u00a0\u00a0 - client_ip<br \/>\n\u00a0\u00a0\u00a0 - vhost<br \/>\n\u00a0\u00a0\u00a0 - url<br \/>\n\u00a0\u00a0\u00a0 - response<br \/>\nfalsepositives:<br \/>\n\u00a0\u00a0\u00a0 - Unknown<br \/>\nlevel: critical<\/p>\n\n<p>Yara:<\/p>\n\n<p>rule EXPL_Citrix_Exploit_Code_Jan20_1 {<br \/>\n\u00a0 meta:<br \/>\n\u00a0\u00a0\u00a0 description = \"Detects payloads used in Citrix exploitation CVE-2019-19781\"<br \/>\n\u00a0\u00a0\u00a0 author = \"Florian Roth\"<br \/>\n\u00a0\u00a0\u00a0 reference = \"<a href=\"https:\/\/isc.sans.edu\/forums\/diary\/Citrix+ADC+Exploits+Overview+of+Observed+Payloads\/25704\/\">https:\/\/isc.sans.edu\/forums\/diary\/Citrix+ADC+Exploits+Overview+of+Observed+Payloads\/25704\/<\/a>\"<br \/>\n\u00a0\u00a0\u00a0 date = \"2020-01-13\"<br \/>\n\u00a0\u00a0\u00a0 score = 70<br \/>\n\u00a0\u00a0\u00a0 type = \"file\"<br \/>\n\u00a0 strings:<br \/>\n\u00a0\u00a0\u00a0 $ = \"\/netscaler\/portal\/scripts\/rmpm.pl\" ascii<br \/>\n\u00a0\u00a0\u00a0 $ = \"tee \/netscaler\/portal\/templates\/\" ascii<br \/>\n\u00a0\u00a0\u00a0 $ = \"exec(<a href=\"file:\/\/\\\\'(wget\">\\\\'(wget<\/a> -q -O- http:\/\/\" ascii<br \/>\n\u00a0\u00a0\u00a0 $ = \"cd \/netscaler\/portal; ls\" ascii<br \/>\n\u00a0\u00a0\u00a0 $ = \"-H \\\"NSC_USER: \" ascii<br \/>\n\u00a0\u00a0\u00a0 $ = \"cat \/flash\/nsconfig\/ns.conf\" ascii<br \/>\n\u00a0\u00a0\u00a0 $ = \"\/netscaler\/portal\/scripts\/PersonalBookmak.pl\" ascii<br \/>\n\u00a0\u00a0\u00a0 $ = \"template.new({'BLOCK'='print readpipe(\" ascii \/* TrustedSec template *\/<br \/>\n\u00a0\u00a0\u00a0 $ = \"pwnpzi1337\" fullword ascii \/* PZI india static user name *\/<br \/>\n\u00a0\u00a0\u00a0 $ = \"template.new({'BLOCK'=\" \/* PZI exploit URL decoded form *\/<br \/>\n\u00a0\u00a0\u00a0 $ = \"template.new({'BLOCK'%3d\" \/* PZI exploit URl encoded form *\/<br \/>\n\u00a0\u00a0\u00a0 $ = \"my ($citrixmd, %FORM);\" \/* Perl backdoor *\/<br \/>\n\u00a0\u00a0\u00a0 $ = \"(CMD, \\\"($citrixmd) 2&gt;&amp;1\" \/* Perl backdoor *\/<br \/>\n\u00a0 condition:<br \/>\n\u00a0\u00a0\u00a0\u00a0\u00a0 1 of them<br \/>\n}<\/p>\n\n<p><strong>INDICATORS OF COMPROMISE (CITRIX COMPROMISE):<\/strong><br \/>\n---------------------------------------------<\/p>\n\n<p>URL Indicators:<\/p>\n\n<p>hxxp:\/\/185[.]178[.]45[.]221\/ci2.sh<br \/>\nhxxp:\/\/159[.]69[.]37[.]196\/sites\/default\/files\/test\/cmd.pl<br \/>\nhxxp:\/\/185[.]178[.]45[.]221\/ci3.sh<br \/>\nhxxp:\/\/stan[.]sh<br \/>\nhxxp:\/\/<a href=\"http:\/\/www.jdjd[.]com\/sks.rar\">www.jdjd[.]com\/sks.rar<\/a><br \/>\nhxxps:\/\/pastebin[.]com\/raw\/d3SY1erQ<br \/>\nhxxp:\/\/61[.]218[.]225[.]74\/snspam\/lurk\/shell\/am.txt<\/p>\n\n<p>IP Indicators:<\/p>\n\n<p>188[.]166[.]106[.]153<br \/>\n192[.]3[.]255[.]144<br \/>\n31[.]134[.]200[.]75<br \/>\n51[.]68[.]122[.]93<br \/>\n81[.]110[.]55[.]125<br \/>\n82[.]27[.]64[.]190<br \/>\n109[.]70[.]100[.]22<br \/>\n37[.]220[.]31[.]72<br \/>\n185[.]118[.]166[.]67<br \/>\n193[.]187[.]174[.]104<br \/>\n185[.]178[.]45[.]221<br \/>\n95[.]179[.]163[.]186<\/p>\n\n<p>Note: Some URL and IP indicators were provided by Didier Stevens and the Internet Storm Center. Detection rules were provided for use by their respective authors.<\/p>\n\n<p><br \/><strong>REFERENCES<\/strong><br \/>\n==========<br \/>\n17 December 2019 Citrix security bulletin CTX267027: <a href=\"https:\/\/support.citrix.com\/article\/CTX267027\">https:\/\/support.citrix.com\/article\/CTX267027<\/a><\/p>\n\n<p>Citrix article detailing pre-patch mitigation steps: <a href=\"https:\/\/support.citrix.com\/article\/CTX267679\">https:\/\/support.citrix.com\/article\/CTX267679<\/a><\/p>\n\n<p>CISA Python script to determine if a host is vulnerable to CVE-2019-19781: <a href=\"https:\/\/github.com\/cisagov\/check-cve-2019-19781\">https:\/\/github.com\/cisagov\/check-cve-2019-19781<\/a><\/p>\n\n<p>Internet Storm Center forum post \u201cCitrix ADC Exploits: Overview of Observed Payloads\u201d:<br \/><a href=\"https:\/\/isc.sans.edu\/forums\/diary\/Citrix+ADC+Exploits+Overview+of+Observed+Payloads\/25704\">https:\/\/isc.sans.edu\/forums\/diary\/Citrix+ADC+Exploits+Overview+of+Observed+Payloads\/25704<\/a><\/p>\n\n<p>FIREEYE Threat Research Blog describing backdoor malware:<br \/><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/01\/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/01\/vigilante-deploying-mitigation-for-citrix-netscaler-vulnerability-while-maintaining-backdoor.html<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><br \/>\n===============<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-citrix-vulnerabilities","alert_type":397,"serial_number":"AL20-003","subject":null,"moderation_state":"published","external_url":null},{"nid":1733,"title":"Citrix security advisory","uuid":"0d08719b-3410-4143-89f7-bb0c42d5d08a","banner":null,"lang":"en","date_modified":"2020-01-20","date_modified_ts":"2020-01-20T17:58:12Z","date_created":"2020-01-20T17:58:12Z","summary":null,"body":["<article data-history-node-id=\"1733\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-016<br \/>\nDate:\u00a020 January 2020<\/strong><\/p>\n\n<p>On 19 January 2020 Citrix released security updates to address a critical vulnerability, tracked as CVE-2019-19781, for the following products:<\/p>\n\n<p>\u2022\u00a0NetScaler ADC and NetScaler Gateway version 12.0 all supported builds before 12.0.63.13<br \/>\n\u2022\u00a0NetScaler ADC and NetScaler Gateway version 11.1 all supported builds before 11.1.63.15<\/p>\n\n<p>Successful exploitation of this vulnerability may allow an unauthenticated remote actor to perform arbitrary code execution.<\/p>\n\n<p>The remaining updates for Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP are expected to be released before the end of January 2020. Review the below Citrix Advisory for further information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Citrix publications and apply the necessary updates when available:<\/p>\n\n<p>Citrix Advisory<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX267027\">https:\/\/support.citrix.com\/article\/CTX267027<\/a><\/p>\n\n<p>Mitigation Steps<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX267679\">https:\/\/support.citrix.com\/article\/CTX267679<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-1","alert_type":396,"serial_number":"AV20-016","subject":null,"moderation_state":"published","external_url":null},{"nid":1734,"title":"Active Exploitation of Internet Explorer Vulnerability","uuid":"141eb0fb-53b1-4b15-8b13-3b77cb527221","banner":null,"lang":"en","date_modified":"2020-01-20","date_modified_ts":"2020-01-20T20:42:26Z","date_created":"2020-01-20T20:42:26Z","summary":null,"body":["<article data-history-node-id=\"1734\" about=\"\/en\/alerts-advisories\/active-exploitation-internet-explorer-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-004<br \/>\nDate: 20 January 2020<\/strong><\/p>\n\n<p><strong>AUDIENCE<\/strong><br \/>\n========<br \/>\nThis Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<p><strong>PURPOSE<\/strong><br \/>\n=======<br \/>\nAn Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<p><strong>OVERVIEW<\/strong><br \/>\n========<br \/>\nOn 17 January 2020 Microsoft released a security bulletin detailing a critical, remotely-exploitable vulnerability in Internet Explorer 9, 10 and 11. The vulnerability may allow an actor to execute arbitrary code in the context of the current user.<br \/>\nMicrosoft has assigned CVE-2020-0674 to this vulnerability and stated they are working on a fix to be released as part of their February 2020 patch cycle.<br \/>\nMicrosoft has stated this unpatched vulnerability is actively being abused to compromise exposed systems.<\/p>\n\n<p><strong>DETAILS<\/strong><br \/>\n=======<br \/>\nThe Cyber Centre is aware that a previously unknown, unpatched Internet Explorer vulnerability is actively being used to compromise vulnerable systems. Internet Explorer 9 through 11 on Microsoft Windows 7 through 10 and on Server 2008 through Server 2016 are all affected.<br \/>\nThis critical, remotely-exploitable vulnerability in the way the Internet Explorer scripting engine handles objects in memory may corrupt memory in such a way that an actor could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, this may lead to installation of programs; viewing, modifying, or deletion of data; or creation of new accounts with full user rights.<br \/>\nIn a web-based exploitation scenario, an actor could host a specially crafted website designed to exploit this vulnerability and then convince a user to view the website by sending an email with an embedded link.<\/p>\n\n<p>As patches for this vulnerability are not yet available, the Cyber Centre recommends that system owners refer to the Mitigation section of this Alert to protect their networks.<\/p>\n\n<p><br \/><strong>MITIGATION<\/strong><br \/>\n==========<\/p>\n\n<p>The Cyber Centre recommends that until the security patches are released, system owners should apply the mitigation steps to restrict access to jscript.dll as recommended by Microsoft. Note that implementing this might result in reduced functionality for components or features that rely on jscript.dll. These recommended workarounds are detailed on the Microsoft website:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200001\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200001<\/a><\/p>\n\n<p>Note: jscript.dll is a library that provides compatibility with a deprecated version of JScript that was released in 2009. Blocking access to this library can prevent exploitation of this and similar vulnerabilities that may be present in this old technology. When Internet Explorer is used to browse the modern web, jscript9.dll is used by default.<\/p>\n\n<p>The Cyber Centre further recommends that system owners apply the relevant patches once they are available from Microsoft in mid-February.<\/p>\n\n<p><strong>REFERENCES<\/strong><br \/>\n==========<br \/>\n17 January 2020 notice on the Microsoft website: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200001\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200001<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><br \/>\n===============<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-internet-explorer-vulnerability","alert_type":397,"serial_number":"AL20-004","subject":null,"moderation_state":"published","external_url":null},{"nid":1735,"title":"[Control systems] Honeywell security advisory","uuid":"7486015d-1874-4ec7-9b07-8babd492417c","banner":null,"lang":"en","date_modified":"2020-01-21","date_modified_ts":"2020-01-21T20:05:54Z","date_created":"2020-01-21T20:05:54Z","summary":null,"body":["<article data-history-node-id=\"1735\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-017<\/strong><br \/><strong>Date: 21 January 2020<\/strong><\/p>\n\n<p>On 21 January 2020 Honeywell released security updates to address vulnerabilities in the following MAXPRO VMS and NVR, video management system products:<\/p>\n\n<ul><li>HNMSWVMS prior to Version VMS560 Build 595 T2-Patch<\/li>\n\t<li>HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch<\/li>\n\t<li>MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch<\/li>\n\t<li>MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch<\/li>\n\t<li>MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch<\/li>\n\t<li>MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may lead to privilege escalation, denial-of-service conditions or unauthenticated remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory (ICSA-20-021-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-021-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-021-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-0","alert_type":398,"serial_number":"AV20-017","subject":null,"moderation_state":"published","external_url":null},{"nid":1736,"title":"Cisco security advisory","uuid":"c1d4725d-a545-41d1-ac89-5b3e68ea1f0e","banner":null,"lang":"en","date_modified":"2020-01-23","date_modified_ts":"2020-01-23T21:06:09Z","date_created":"2020-01-23T21:06:09Z","summary":null,"body":["<article data-history-node-id=\"1736\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-40\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-018<\/strong><br \/><strong>Date: 23 January 2020<\/strong><\/p>\n\n<p>On 22 January 2020 Cisco released a number of security advisories to address vulnerabilities affecting multiple products. Of note, a vulnerability in the Cisco Firepower Management Center tracked as CVE-2019-16028, a vulnerability in Cisco IOS XE SD-WAN Software tracked as CVE-2019-1950 and a vulnerability in Cisco IOS XR Software tracked as CVE-2019-16018.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to bypass authentication and execute arbitrary actions with administrative privileges on an affected device, log in using default credentials with elevated privileges and take complete control of the device or cause a denial of service (DoS) condition in the Border Gateway Protocol (BGP) service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-40","alert_type":396,"serial_number":"AV20-018","subject":null,"moderation_state":"published","external_url":null},{"nid":1737,"title":"[Control systems] GE security advisory","uuid":"ca372150-ccaf-4350-a62e-8f93b1a7c93d","banner":null,"lang":"en","date_modified":"2020-01-24","date_modified_ts":"2020-01-24T13:47:08Z","date_created":"2020-01-24T13:47:08Z","summary":null,"body":["<article data-history-node-id=\"1737\" about=\"\/en\/alerts-advisories\/control-systems-ge-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-019<\/strong><br \/><strong>Date: 24 January 2020<\/strong><\/p>\n\n<p>On 23 January 2020 GE released security updates to address vulnerabilities in the following Healthcare Monitoring platforms:<\/p>\n\n<ul><li>ApexPro Telemetry Server, Versions 4.2 and prior<\/li>\n\t<li>CARESCAPE Telemetry Server, Versions 4.2 and prior<\/li>\n\t<li>Clinical Information Center (CIC), Versions 4.X and 5.X<\/li>\n\t<li>CARESCAPE Telemetry Server, Version 4.3 (Impacted by CVE-2020- 6962 and CVE-2020-6961)<\/li>\n\t<li>CARESCAPE Central Station (CSCS), Versions 1.X<\/li>\n\t<li>CARESCAPE Central Station (CSCS), Versions 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6964)<\/li>\n\t<li>B450, Version 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6965)<\/li>\n\t<li>B650, Version 1.X (Impacted by CVE-2020- 6962 and CVE-2020-6965)<\/li>\n\t<li>B650, Version 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6965)<\/li>\n\t<li>B850, Version 1.X (Impacted by CVE-2020- 6962 and CVE-2020-6965)<\/li>\n\t<li>B850, Version 2.X (Impacted by CVE-2020- 6962 and CVE-2020-6965)<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow an actor to take over vulnerable patient monitors and\/or telemetry aggregation servers, and then silence alerts, putting patient lives at risk.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory (ICSMA-20-023-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-023-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-023-01<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-security-advisory","alert_type":398,"serial_number":"AV20-019","subject":null,"moderation_state":"published","external_url":null},{"nid":1742,"title":"Citrix security advisory","uuid":"16dea5fa-4816-447d-ac2e-401eedb74d8c","banner":null,"lang":"en","date_modified":"2020-01-29","date_modified_ts":"2020-01-29T20:28:46Z","date_created":"2020-01-24T19:45:28Z","summary":null,"body":["<article data-history-node-id=\"1742\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-020<br \/>\nDate:\u00a024 January 2020<\/strong><\/p>\n\n<p>On 24 January 2020 Citrix released the final security update to address a critical vulnerability, tracked as CVE-2019-19781, for the following products:<\/p>\n\n<ul><li>Citrix ADC and Citrix Gateway version 13.0 all supported builds before 13.0.47.24<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway version 12.1 all supported builds before 12.1.55.18<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway version 12.0 all supported builds before 12.0.63.13<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway version 11.1 all supported builds before 11.1.63.15<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway version 10.5 all supported builds before 10.5.70.12<\/li>\n\t<li>Citrix SD-WAN WANOP appliance models 4000-WO, 4100-WO, 5000-WO, and 5100-WO all supported software release builds before 10.2.6b and 11.0.3b<\/li>\n<\/ul><p>Successful exploitation of this vulnerability may allow an unauthenticated remote actor to perform arbitrary code execution.<\/p>\n\n<p>In addition to the above patches, Citrix has released an Indicator of Compromise utility that provides a best effort job at identifying existing compromises of<br \/>\nCitrix appliances related to CVE-2019-19781.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Citrix publications and apply the necessary updates:<\/p>\n\n<p>Citrix Advisory<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX267027\">https:\/\/support.citrix.com\/article\/CTX267027<\/a><\/p>\n\n<p>Mitigation Steps<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX267679\">https:\/\/support.citrix.com\/article\/CTX267679<\/a><\/p>\n\n<p>Citrix Indicator of Compromise utility<\/p>\n\n<p><a href=\"https:\/\/github.com\/citrix\/ioc-scanner-CVE-2019-19781\/\">https:\/\/github.com\/citrix\/ioc-scanner-CVE-2019-19781\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-2","alert_type":396,"serial_number":"AV20-020","subject":null,"moderation_state":"published","external_url":null},{"nid":1738,"title":"Red Hat security advisory","uuid":"10898ff7-f79f-4eaf-9ee5-4d7ebaf6cb45","banner":null,"lang":"en","date_modified":"2020-01-29","date_modified_ts":"2020-01-29T15:05:16Z","date_created":"2020-01-29T15:05:16Z","summary":null,"body":["<article data-history-node-id=\"1738\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Date: January\u00a029 2020<br \/>\nNumber: AV20-021<\/strong><\/p>\n\n<p>On 28 January 2020 Red Hat released a security advisory to address a vulnerability affecting openjpeg2 (an open source library for reading and writing image files in JPEG2000 format), which is used in its operating system. This buffer overflow vulnerability could allow a remote, unauthenticated actor to execute arbitrary code on the affected system.<\/p>\n\n<p><br \/>\nThe Cyber Centre encourages users and administrators to review the Red Hat Security Advisory webpage at the link below and apply the necessary updates:<\/p>\n\n<p><br \/><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2020:0262\">https:\/\/access.redhat.com\/errata\/RHSA-2020:0262<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-0","alert_type":396,"serial_number":"AV20-021","subject":null,"moderation_state":"published","external_url":null},{"nid":1739,"title":"Ubuntu security advisory","uuid":"519099ac-5574-4c53-9fa2-f17bccddd632","banner":null,"lang":"en","date_modified":"2020-01-29","date_modified_ts":"2020-01-29T16:18:25Z","date_created":"2020-01-29T16:18:25Z","summary":null,"body":["<article data-history-node-id=\"1739\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Date: January\u00a029 2020<br \/>\nNumber: AV20-022<\/strong><\/p>\n\n<p>On 29 January 2020 Ubuntu released security updates to address vulnerabilities affecting the Linux kernel. A local actor could exploit some of these vulnerabilities to escalate privileges or cause a denial of service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Ubuntu Security Notices webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/usn.ubuntu.com\/\">https:\/\/usn.ubuntu.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-0","alert_type":396,"serial_number":"AV20-022","subject":null,"moderation_state":"published","external_url":null},{"nid":1740,"title":"Apple security advisory","uuid":"23369396-9820-4d56-ba6b-1ce44f91c14f","banner":null,"lang":"en","date_modified":"2020-01-29","date_modified_ts":"2020-01-29T16:42:45Z","date_created":"2020-01-29T16:42:45Z","summary":null,"body":["<article data-history-node-id=\"1740\" about=\"\/en\/alerts-advisories\/apple-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Date: January\u00a029 2020<br \/>\nNumber: AV20-023<\/strong><\/p>\n\n<p>On 28 January 2020 Apple released security updates to address vulnerabilities affecting the following products:<br \/>\n-\u00a0iTunes 12.10.4 for Windows<br \/>\n-\u00a0tvOS 13.3.1<br \/>\n-\u00a0Safari 13.0.5<br \/>\n-\u00a0iOS 13.3.1 and iPadOS 13.3.1<br \/>\n-\u00a0iCloud for Windows 7.17<br \/>\n-\u00a0watchOS 6.1.2<br \/>\n-\u00a0macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra<\/p>\n\n<p>A number of these vulnerabilities could be exploited to allow an application to execute arbitrary code with system level privileges.<\/p>\n\n<p><br \/>\nThe Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<\/p>\n\n<p><br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-9","alert_type":396,"serial_number":"AV20-023","subject":null,"moderation_state":"published","external_url":null},{"nid":1741,"title":"Adobe security advisory ","uuid":"2e0c9506-61c7-4aec-9207-cf41109a06db","banner":null,"lang":"en","date_modified":"2020-01-29","date_modified_ts":"2020-01-29T20:17:03Z","date_created":"2020-01-29T20:12:54Z","summary":null,"body":["<article data-history-node-id=\"1741\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-024<br \/>\nDate:\u00a029 January 2020<\/strong><\/p>\n\n<p>On 28 January 2020 Adobe released security updates to address multiple vulnerabilities affecting versions of:<\/p>\n\n<p>-\u00a0Magento Commerce<br \/>\n-\u00a0Magento Community<br \/>\n-\u00a0Magento Enterprise<br \/>\n-\u00a0Magento Open Source<\/p>\n\n<p>An actor could exploit some of these vulnerabilities to execute arbitrary code or gain access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletin webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb20-02.html\">https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb20-02.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-11","alert_type":396,"serial_number":"AV20-024","subject":null,"moderation_state":"published","external_url":null},{"nid":1743,"title":"OpenSMTPD security advisory","uuid":"611290eb-783c-4e4d-bff2-a0191f938350","banner":null,"lang":"en","date_modified":"2020-01-29","date_modified_ts":"2020-01-29T20:33:57Z","date_created":"2020-01-29T20:33:57Z","summary":null,"body":["<article data-history-node-id=\"1743\" about=\"\/en\/alerts-advisories\/opensmtpd-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-025<br \/>\nDate:\u00a029 January 2020<\/strong><\/p>\n\n<p>On 28 January 2020 the OpenBSD Project released a security bulletin to address a remote code execution (RCE) vulnerability affecting its OpenSMTPD e-mail server software.\u00a0 By sending a specially-crafted email to an affected system, a remote actor can execute arbitrary shell commands as Root.<\/p>\n\n<p>The portable version of OpenSMTPD is also vulnerable to exploitation. This version runs on the following operating systems and has been incorporated into many of them:<\/p>\n\n<p>\u2022\u00a0FreeBSD;<br \/>\n\u2022\u00a0NetBSD;<br \/>\n\u2022\u00a0DragonFlyBSD;<br \/>\n\u2022\u00a0Mac OS X; and<br \/>\n\u2022\u00a0Various other Linux distributions.<\/p>\n\n<p>Proof of concept exploit code has been published.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the vendor announcement below and obtain an updated version of OpenSMTPD:<\/p>\n\n<p><a href=\"https:\/\/www.mail-archive.com\/misc@opensmtpd.org\/msg04850.html\">https:\/\/www.mail-archive.com\/misc@opensmtpd.org\/msg04850.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/opensmtpd-security-advisory","alert_type":396,"serial_number":"AV20-025","subject":null,"moderation_state":"published","external_url":null},{"nid":1744,"title":"Detecting Compromises relating to Citrix CVE-2019-19781","uuid":"f2597076-a5e8-438b-9d9a-d15b0b294ec5","banner":null,"lang":"en","date_modified":"2020-02-04","date_modified_ts":"2020-02-04T18:40:21Z","date_created":"2020-02-04T18:40:21Z","summary":null,"body":["<article data-history-node-id=\"1744\" about=\"\/en\/alerts-advisories\/detecting-compromises-relating-citrix-cve-2019-19781-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><strong>Number: AL20-005<br \/>\nDate: 4 February 2020<\/strong><\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) has produced an Alert regarding their ongoing investigation of the Citrix CVE-2019-19781 vulnerability. The Cyber Centre would like to highlight this Alert as it provides valuable information to system owners and operators responsible for defending their systems and networks from cyber threats. The Cyber Centre previously reported on these vulnerabilities over the past several weeks (see references); the CISA report contains additional detailed information.<\/p>\n\n<p>The CISA Alert can be found at:<br \/><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/aa20-031a\">https:\/\/www.us-cert.gov\/ncas\/alerts\/aa20-031a<\/a><\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n\n<h2>ASSESSMENT<\/h2>\n\n<p>Due to the severity of CVE-2019-19781 and the ease by which threat actors are currently able to access working code to compromise unpatched and unmitigated Citrix devices, the Cyber Centre advises organizations that have not yet applied mitigations or patches to assume that they have already been compromised. The Cyber Centre strongly advises system owners who have not yet applied patches or mitigations to immediately disconnect their Citrix appliance(s) from the Internet and begin a full forensic investigation. Please note that recently applied mitigations or patches will not negate an active compromise that may have occurred while the appliance was in a vulnerable state. The indicators of compromise and tools for detecting compromise provided by Citrix, the Cyber Centre, CISA and other security researchers are not exhaustive, and should be used as a starting point for a full forensic assessment.<\/p>\n\n<h2>INDICATORS OF COMPROMISE<\/h2>\n\n<p><br \/>\nBelow are IOC\u2019s reported in Open Source that have not yet been highlighted in Cyber Centre reporting:<\/p>\n\n<p>Monero Cryptominer<br \/>\n\/var\/tmp\/netscalerd<br \/>\nMD5: 5be9abbe208a1e03ef3def7f9fa816d3<br \/>\nMD5: 08f76eb3d62d53bff131d2cb0af2773d<\/p>\n\n<p>Backdoor (Written in GO)<br \/>\n\/var\/tmp\/nspps<br \/>\nMD5: 568f7b1d6c2239e208ba97886acc0b1e<br \/>\nMD5: 1c8c28e4db5ad7773da363146b10a340<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p><br \/>\nCitrix Security Advisory (AV19-291):<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/citrix-security-advisory-0\">https:\/\/cyber.gc.ca\/en\/alerts\/citrix-security-advisory-0<\/a><\/p>\n\n<p>Active Exploitation of Citrix Vulnerabilities (AL20-003):<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-citrix-vulnerabilities\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-citrix-vulnerabilities<\/a><\/p>\n\n<p>Citrix Security Advisory (AV20-016):<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/citrix-security-advisory-1\">https:\/\/cyber.gc.ca\/en\/alerts\/citrix-security-advisory-1<\/a><\/p>\n\n<p>Citrix Security Advisory (AV20-020):<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/citrix-security-advisory-2\">https:\/\/cyber.gc.ca\/en\/alerts\/citrix-security-advisory-2<\/a><\/p>\n\n<p>TrustedSec NetScaler Honeypot:<br \/><a href=\"https:\/\/www.trustedsec.com\/blog\/netscaler-honeypot\/\">https:\/\/www.trustedsec.com\/blog\/netscaler-honeypot\/<\/a><\/p>\n\n<p>Citrix - Indicator of Compromise Scanner (CVE-2019-19781)<br \/><a href=\"https:\/\/github.com\/citrix\/ioc-scanner-CVE-2019-19781\">https:\/\/github.com\/citrix\/ioc-scanner-CVE-2019-19781<\/a>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/detecting-compromises-relating-citrix-cve-2019-19781-0","alert_type":397,"serial_number":"AL20-005","subject":null,"moderation_state":"published","external_url":null},{"nid":1745,"title":"[Control systems] AutomationDirect security advisory","uuid":"d1954445-78bb-4938-9ba2-f6339b4468c7","banner":null,"lang":"en","date_modified":"2020-02-05","date_modified_ts":"2020-02-05T18:11:25Z","date_created":"2020-02-05T18:11:25Z","summary":null,"body":["<article data-history-node-id=\"1745\" about=\"\/en\/alerts-advisories\/control-systems-automationdirect-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-026<br \/>\nDate: 5 February 2020<\/strong><\/p>\n\n<p>On 4 February 2020 AutomationDirect released a security update to address a vulnerability in the C-More Touch Panels EA9 Series firmware versions prior to 6.53.\u00a0 Successful exploitation of this vulnerability may allow an actor to obtain usernames and passwords, obscure or manipulate process data, and lock out access to the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory (ICSA-20-035-01) and apply the necessary manufacturer updates:<\/p>\n\n<p><strong><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-035-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-035-01<\/a><\/strong><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-automationdirect-security-advisory","alert_type":398,"serial_number":"AV20-026","subject":null,"moderation_state":"published","external_url":null},{"nid":1746,"title":"Google Chrome security advisory","uuid":"5bcdc868-edca-4772-a61d-375d18f3f562","banner":null,"lang":"en","date_modified":"2020-02-06","date_modified_ts":"2020-02-06T19:14:39Z","date_created":"2020-02-06T19:05:05Z","summary":null,"body":["<article data-history-node-id=\"1746\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-029<br \/>\nDate:\u00a06 February 2020<\/strong><\/p>\n\n<p>On 4 February 2020 Google announced the release of Chrome 80.0.3987.87 for Windows, Mac, and Linux.<br \/>\nThe Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/02\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/02\/stable-channel-update-for-desktop.html<\/a><br \/>\nFor the latest version of Chrome:<br \/><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-14","alert_type":396,"serial_number":"AV20-029","subject":null,"moderation_state":"published","external_url":null},{"nid":1747,"title":"Cisco security advisory","uuid":"44a7984e-3de4-43e4-b9a8-7473d26da6b2","banner":null,"lang":"en","date_modified":"2020-02-06","date_modified_ts":"2020-02-06T19:20:32Z","date_created":"2020-02-06T19:20:21Z","summary":null,"body":["<article data-history-node-id=\"1747\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-41\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-028<br \/>\nDate:\u00a06 February 2020<\/strong><\/p>\n\n<p>On 5 February 2020 Cisco released security advisories to address vulnerabilities affecting a number of Cisco products. Of note is a vulnerability that involves the implementation of the proprietary Cisco Discovery Protocol (CDP) that is used to discover information about locally attached Cisco equipment. To exploit this vulnerability, an actor must be in the same broadcast domain as the affected device (Layer 2 adjacent).<br \/>\nSome of these vulnerabilities could allow an unauthenticated actor to execute arbitrary code with root privileges on an affected device.<br \/>\nThe Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-41","alert_type":396,"serial_number":"AV20-028","subject":null,"moderation_state":"published","external_url":null},{"nid":1748,"title":"Android security advisory","uuid":"d0843d0d-c01b-4481-be35-5b532a3c683d","banner":null,"lang":"en","date_modified":"2020-02-06","date_modified_ts":"2020-02-06T20:17:04Z","date_created":"2020-02-06T20:17:04Z","summary":null,"body":["<article data-history-node-id=\"1748\" about=\"\/en\/alerts-advisories\/android-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-027<br \/>\nDate:\u00a06 February 2020<\/strong><\/p>\n\n<p>On 3 February 2020 Android published a Security Bulletin to address multiple vulnerabilities affecting Android devices. A remote actor could exploit one of these vulnerabilities by sending a specially crafted transmission to the device to execute arbitrary code within the context of a privileged process.<br \/>\nThe Cyber Centre encourages users and administrators to review the Android Security Bulletin and apply the necessary updates, when available:<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-02-01.html\">https:\/\/source.android.com\/security\/bulletin\/2020-02-01.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-9","alert_type":396,"serial_number":"AV20-027","subject":null,"moderation_state":"published","external_url":null},{"nid":1749,"title":"Adobe security advisory","uuid":"36265f6f-bc17-47c4-a781-264e5b7cd178","banner":null,"lang":"en","date_modified":"2020-02-11","date_modified_ts":"2020-02-11T20:18:45Z","date_created":"2020-02-11T20:18:45Z","summary":null,"body":["<article data-history-node-id=\"1749\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-031<br \/>\nDate:\u00a011 February 2020<\/strong><\/p>\n\n<p>On 11 February 2020 Adobe released security updates to address vulnerabilities affecting several of its products. Some of these vulnerabilities could lead to arbitrary code execution in the context of the current user.<br \/>\nThe Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-12","alert_type":396,"serial_number":"AV20-031","subject":null,"moderation_state":"published","external_url":null},{"nid":1750,"title":"Intel security advisory","uuid":"07e460a9-75cf-4ca2-b11c-adef61778e26","banner":null,"lang":"en","date_modified":"2020-02-11","date_modified_ts":"2020-02-11T20:53:38Z","date_created":"2020-02-11T20:53:38Z","summary":null,"body":["<article data-history-node-id=\"1750\" about=\"\/en\/alerts-advisories\/intel-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-030<br \/>\nDate:\u00a011 February 2020<\/strong><\/p>\n\n<p>On 11 February 2020 Intel published a security advisory for an issue affecting the following Converged Security and Management Engine (CSME) products:<\/p>\n\n<p>\u2022\u00a0Versions before 12.0.49;<br \/>\n\u2022\u00a0Versions before 12.0.56 (Internet of Things (IOT) only);<br \/>\n\u2022\u00a0Versions before 13.0.21; and<br \/>\n\u2022\u00a0Versions before 14.0.11.<\/p>\n\n<p>Exploitation of this vulnerability may allow a privileged user with local access to perform escalation of privilege, denial of service or information disclosure. Intel has released firmware updates to mitigate this potential vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Intel Advisories webpage and apply the recommended firmware updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00307.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00307.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-9","alert_type":396,"serial_number":"AV20-030","subject":null,"moderation_state":"published","external_url":null},{"nid":1751,"title":"Microsoft security advisory \u2013 February 2020 monthly rollup","uuid":"86d840fe-798d-41f9-b799-5924a32e7b1c","banner":null,"lang":"en","date_modified":"2020-02-12","date_modified_ts":"2020-02-12T16:50:29Z","date_created":"2020-02-12T16:44:48Z","summary":null,"body":["<article data-history-node-id=\"1751\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-february-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-032<br \/>\nDate:\u00a012 February 2020<\/strong><\/p>\n\n<p>On 11 February 2020 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for 12 critical remote code execution vulnerabilities.<br \/>\nOf note is a previously reported critical remote code execution vulnerability, tracked as CVE-2020-0674, which exists in Internet Explorer 9, 10 and 11. Exploitation of this vulnerability may allow an actor to execute arbitrary code in the context of the current user. Microsoft recommends removal of the previously provided workaround (if applied) before installation of the current update. Review Microsoft Advisory ADV200001 for more information.<br \/>\nThe Cyber Centre encourages users and administrators to review the Microsoft February 2020 Security Updates webpage and apply the necessary updates:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><br \/>\nRelease Notes:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Feb\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Feb<\/a><br \/>\nADV200001 \u2013 Microsoft Guidance on CVE-2020-0674:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200001\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/ADV200001<\/a><br \/>\nCCCS AL20-004:<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-internet-explorer-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-internet-explorer-vulnerability<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-february-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-032","subject":null,"moderation_state":"published","external_url":null},{"nid":1752,"title":"[Control systems] Synergy Systems & Solutions security advisory","uuid":"5d711fcd-009f-4d4f-8e59-816ad02c5e54","banner":null,"lang":"en","date_modified":"2020-02-12","date_modified_ts":"2020-02-12T18:57:12Z","date_created":"2020-02-12T18:57:12Z","summary":null,"body":["<article data-history-node-id=\"1752\" about=\"\/en\/alerts-advisories\/control-systems-synergy-systems-solutions-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-033<br \/>\nDate:\u00a012 February 2020<\/strong><\/p>\n\n<p>On 11 February 2020 Synergy Systems &amp; Solutions released a security update to address a vulnerability in the HUSKY RTU 6049-E70 remote terminal unit with firmware Versions 5.0 and prior.\u00a0<br \/>\nSuccessful exploitation of this vulnerability may allow a remote actor to trigger a denial of service, access protected data or remotely execute code on an affected device.<br \/>\nThe Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<br \/>\nICS Advisory (ICSA-20-042-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-synergy-systems-solutions-security-advisory","alert_type":398,"serial_number":"AV20-033","subject":null,"moderation_state":"published","external_url":null},{"nid":1753,"title":"[Control systems] Siemens security advisory","uuid":"b4c70d71-5257-4ca3-bf1d-132c701b95e2","banner":null,"lang":"en","date_modified":"2020-02-12","date_modified_ts":"2020-02-12T19:01:57Z","date_created":"2020-02-12T19:01:57Z","summary":null,"body":["<article data-history-node-id=\"1753\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-034<br \/>\nDate:\u00a012 February 2020<\/strong><\/p>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\n<p>On 11 February 2020 Siemens released security updates to address vulnerabilities in the following products:<br \/>\n\u2022\u00a0SCALANCE S-600<br \/>\n\u2022\u00a0OZW Web Server<br \/>\n\u2022\u00a0SIPORT MP<br \/>\n\u2022\u00a0SCALANCE X Switches<br \/>\n\u2022\u00a0SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC<br \/>\n\u2022\u00a0SIMATIC S7<br \/>\n\u2022\u00a0PROFINET-IO Stack<br \/>\n\u2022\u00a0SIMATIC CP 1543-1<br \/>\n\u2022\u00a0Industrial Products SNMP (in SCALANCE, SIMATIC, SIPLUS products)<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to trigger a denial of service, access protected data or remotely execute code at the administrative level of an affected device.<br \/>\nThe Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<br \/>\nICS Advisory (ICSA-20-042-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-03)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-03<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-04)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-04\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-04<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-05)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-05\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-05<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-06)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-06\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-06<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-07)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-07\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-07<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-08)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-08\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-08<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-09)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-09\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-09<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-042-10)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-10\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-042-10<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-5","alert_type":398,"serial_number":"AV20-034","subject":null,"moderation_state":"published","external_url":null},{"nid":1754,"title":"Mozilla security advisory","uuid":"e572ee19-142d-41de-ae5f-87f2c50b4880","banner":null,"lang":"en","date_modified":"2020-02-13","date_modified_ts":"2020-02-13T13:42:42Z","date_created":"2020-02-13T13:42:09Z","summary":null,"body":["<article data-history-node-id=\"1754\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-035<br \/>\nDate:\u00a013 February 2020<\/strong><\/p>\n\n<p>On 11 February 2020 Mozilla released Firefox 73 and Firefox ESR 68.5 to address vulnerabilities that could lead to a potentially exploitable crash due to memory corruption.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-10","alert_type":396,"serial_number":"AV20-035","subject":null,"moderation_state":"published","external_url":null},{"nid":1755,"title":"[Control systems] Phoenix Contact security advisory","uuid":"f3027e4f-afd1-4d8e-b24e-7aa3d6fc7409","banner":null,"lang":"en","date_modified":"2020-02-18","date_modified_ts":"2020-02-18T14:54:59Z","date_created":"2020-02-18T14:54:59Z","summary":null,"body":["<article data-history-node-id=\"1755\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-036<br \/>\nDate:\u00a018 February 2020<\/strong><\/p>\n\n<p>On 13 February 2020 Phoenix Contact released a security update to address a vulnerability in the Emalytics Controllers ILC 2050 BI.\u00a0 Successful exploitation of this vulnerability may allow an unauthorized remote actor to change the device configuration and start or stop services.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>Security Advisory for ILC 2050 BI and ILC 2050 BI-L:<\/p>\n\n<p><a href=\"https:\/\/dam-mdc.phoenixcontact.com\/asset\/156443151564\/7f155583e174a54ee957bad77573ecd7\/Security_Advirory_CVE-2020-8768.pdf\">https:\/\/dam-mdc.phoenixcontact.com\/asset\/156443151564\/7f155583e174a54ee957bad77573ecd7\/Security_Advirory_CVE-2020-8768.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory","alert_type":398,"serial_number":"AV20-036","subject":null,"moderation_state":"published","external_url":null},{"nid":1756,"title":"[Control systems] Emerson security advisory","uuid":"83f93660-8a3f-4608-9cbd-36655f8d09a2","banner":null,"lang":"en","date_modified":"2020-02-19","date_modified_ts":"2020-02-19T20:19:21Z","date_created":"2020-02-19T20:10:57Z","summary":null,"body":["<article data-history-node-id=\"1756\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-037<br \/>\nDate: 19 February 2020<\/strong><\/p>\n\n<p>On 18 February 2020 Emerson released a security update to address a vulnerability in the following versions of OpenEnterprise SCADA Server:<\/p>\n\n<p>\u2022 OpenEnterprise Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use).<br \/>\n\u2022 OpenEnterprise 3.1 through 3.3.3, all versions.<\/p>\n\n<p>Successful exploitation of this vulnerability may allow a remote actor to execute code on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-049-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-049-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-049-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory","alert_type":398,"serial_number":"AV20-037","subject":null,"moderation_state":"published","external_url":null},{"nid":1757,"title":"[Control systems] Honeywell security advisory","uuid":"d3c4c5ed-9c35-467b-8c77-0a278050de88","banner":null,"lang":"en","date_modified":"2020-02-19","date_modified_ts":"2020-02-19T20:21:26Z","date_created":"2020-02-19T20:21:26Z","summary":null,"body":["<article data-history-node-id=\"1757\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-038<br \/>\nDate: 19 February 2020<\/strong><\/p>\n\n<p>On 18 February 2020 Honeywell released a security update to address a vulnerability in the INNCOM INNControl 3 energy management platform (Versions 3.21 and prior).<\/p>\n\n<p>Successful exploitation of this vulnerability may allow a remote actor to escalate user privileges within the INNControl application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-049-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-049-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-049-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-1","alert_type":398,"serial_number":"AV20-038","subject":null,"moderation_state":"published","external_url":null},{"nid":1758,"title":"VMware security advisory","uuid":"25c16cf1-f931-435e-b762-57c4be218f91","banner":null,"lang":"en","date_modified":"2020-02-20","date_modified_ts":"2020-02-20T15:17:22Z","date_created":"2020-02-20T15:12:33Z","summary":null,"body":["<article data-history-node-id=\"1758\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-039<br \/>\nDate: 20 February 2020<\/strong><\/p>\n\n<p>On 18 February 2020 VMware released a security advisory to address vulnerabilities affecting its vRealize Operations for Horizon Adapter. One of the vulnerabilities, tracked as CVE-2020-3943, could allow an unauthenticated remote actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users to review the following VMware advisory and apply the necessary updates:<br \/><a href=\"https:\/\/www.vmware.com\/ca\/security\/advisories\/VMSA-2020-0003.html\">https:\/\/www.vmware.com\/ca\/security\/advisories\/VMSA-2020-0003.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-23","alert_type":396,"serial_number":"AV20-039","subject":null,"moderation_state":"published","external_url":null},{"nid":1759,"title":"Adobe security advisory","uuid":"63062ae2-0cfe-4d58-bf37-46c17a36aafb","banner":null,"lang":"en","date_modified":"2020-02-20","date_modified_ts":"2020-02-20T15:49:09Z","date_created":"2020-02-20T15:49:09Z","summary":null,"body":["<article data-history-node-id=\"1759\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-040<br \/>\nDate: 20 February 2020<\/strong><\/p>\n\n<p>On 19 February 2020 Adobe released security updates to address vulnerabilities affecting several of its products. Some of these vulnerabilities could lead to arbitrary code execution in the context of the current user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-13","alert_type":396,"serial_number":"AV20-040","subject":null,"moderation_state":"published","external_url":null},{"nid":1760,"title":"Cisco security advisory","uuid":"aa9f0df0-e284-4572-ba65-4c46460be047","banner":null,"lang":"en","date_modified":"2020-02-21","date_modified_ts":"2020-02-21T12:04:08Z","date_created":"2020-02-21T12:04:08Z","summary":null,"body":["<article data-history-node-id=\"1760\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-42\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-041<br \/>\nDate: 21 February 2020<\/strong><\/p>\n\n<p>On 19 February 2020 Cisco released security advisories to address vulnerabilities affecting a number of their products. Of note is a critical vulnerability in the High Availability (HA) service of the Cisco Smart Software Manager On-Prem that could allow a remote, unauthenticated actor to gain read and write access to a portion of the system, including the device configuration. This vulnerability is due to a default system account password that cannot be changed.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><font color=\"#0066cc\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/font><\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-42","alert_type":396,"serial_number":"AV20-041","subject":null,"moderation_state":"published","external_url":null},{"nid":1761,"title":"Google Chrome security advisory","uuid":"addb25cc-3b2c-434f-b64b-145472a84e01","banner":null,"lang":"en","date_modified":"2020-02-21","date_modified_ts":"2020-02-21T19:30:39Z","date_created":"2020-02-21T19:30:39Z","summary":null,"body":["<article data-history-node-id=\"1761\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-042<br \/>\nDate: 21 February 2020<\/strong><\/p>\n\n<p>On 18 February 2020 Google announced the release of Chrome 80.0.3987.116 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/02\/stable-channel-update-for-desktop_18.html\">https:\/\/chromereleases.googleblog.com\/2020\/02\/stable-channel-update-for-desktop_18.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-15","alert_type":396,"serial_number":"AV20-042","subject":null,"moderation_state":"published","external_url":null},{"nid":1762,"title":"OpenSMTPD security advisory","uuid":"df8c01f4-402a-4357-9b8e-d1351e55acb0","banner":null,"lang":"en","date_modified":"2020-02-25","date_modified_ts":"2020-02-25T12:35:32Z","date_created":"2020-02-25T12:30:54Z","summary":null,"body":["<article data-history-node-id=\"1762\" about=\"\/en\/alerts-advisories\/opensmtpd-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-043<br \/>\nDate: 25 February 2020<\/strong><\/p>\n\n<p>On 24 Febuary 2020 the OpenBSD Project released a security bulletin to address a remote code execution (RCE) vulnerability affecting versions 6.6.3p1 and below of its OpenSMTPD e-mail server software.\u00a0 By sending a specially-crafted email to an affected system, a remote actor can execute arbitrary shell commands as Root.<\/p>\n\n<p>The portable version of OpenSMTPD is also vulnerable to exploitation. This version runs on the following operating systems and has been incorporated into many of them:<br \/>\n\u2022\u00a0FreeBSD;<br \/>\n\u2022\u00a0NetBSD;<br \/>\n\u2022\u00a0DragonFlyBSD;<br \/>\n\u2022\u00a0Mac OS X; and<br \/>\n\u2022\u00a0Various other Linux distributions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the vendor announcement below and obtain an updated version of OpenSMTPD: <a href=\"https:\/\/www.mail-archive.com\/misc@opensmtpd.org\/msg04888.html\">https:\/\/www.mail-archive.com\/misc@opensmtpd.org\/msg04888.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/opensmtpd-security-advisory-0","alert_type":396,"serial_number":"AV20-043","subject":null,"moderation_state":"published","external_url":null},{"nid":1763,"title":"Apache Tomcat security advisory","uuid":"286085a3-46a4-4daa-998c-f7a0570a703b","banner":null,"lang":"en","date_modified":"2020-02-25","date_modified_ts":"2020-02-25T16:07:03Z","date_created":"2020-02-25T16:07:03Z","summary":null,"body":["<article data-history-node-id=\"1763\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-044<br \/>\nDate: 25 February 2020<\/strong><\/p>\n\n<p>On 11 February 2020 the Apache Software Foundation released a security note to address vulnerabilities affecting its Apache Tomcat software (Tomcat Server). A remote actor could exploit this vulnerability to execute arbitrary code on the affected system.<\/p>\n\n<p>This vulnerability affects the following versions of Apache Tomcat:<\/p>\n\n<p>\u2022\u00a0Apache Tomcat 9 all supported builds below 9.0.31<br \/>\n\u2022\u00a0Apache Tomcat 8 all supported builds below 8.5.51<br \/>\n\u2022\u00a0Apache Tomcat 7 all supported builds below 7.0.100<br \/>\n\u2022\u00a0Apache Tomcat 6 all builds (no longer supported)<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apache Tomcat webpage for the respective major versions and apply the necessary updates:<br \/>\n\u2022\u00a0<a href=\"http:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.31\">http:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.31<\/a> (Tomcat 9)<br \/>\n\u2022\u00a0<a href=\"http:\/\/tomcat.apache.org\/security-8.html#Fixed_in_Apache_Tomcat_8.5.51\">http:\/\/tomcat.apache.org\/security-8.html#Fixed_in_Apache_Tomcat_8.5.51<\/a> (Tomcat 8)<br \/>\n\u2022\u00a0<a href=\"http:\/\/tomcat.apache.org\/security-7.html#Fixed_in_Apache_Tomcat_7.0.100\">http:\/\/tomcat.apache.org\/security-7.html#Fixed_in_Apache_Tomcat_7.0.100<\/a> (Tomcat 7)<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-advisory-0","alert_type":396,"serial_number":"AV20-044","subject":null,"moderation_state":"published","external_url":null},{"nid":1764,"title":"Google Chrome security advisory","uuid":"4d22df67-e8f6-45af-b76f-e2d4a5080577","banner":null,"lang":"en","date_modified":"2020-02-25","date_modified_ts":"2020-02-25T20:18:33Z","date_created":"2020-02-25T20:18:33Z","summary":null,"body":["<article data-history-node-id=\"1764\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-045<br \/>\nDate: 25 February 2020<\/strong><\/p>\n\n<p>On 24 February 2020 Google announced the release of Chrome 80.0.3987.122 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/02\/stable-channel-update-for-desktop_24.html\">https:\/\/chromereleases.googleblog.com\/2020\/02\/stable-channel-update-for-desktop_24.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-16","alert_type":396,"serial_number":"AV20-045","subject":null,"moderation_state":"published","external_url":null},{"nid":1765,"title":"[Control systems] Moxa security advisory","uuid":"b539b171-7985-4569-a409-b481b43dd2b9","banner":null,"lang":"en","date_modified":"2020-02-27","date_modified_ts":"2020-02-27T14:24:27Z","date_created":"2020-02-27T14:24:27Z","summary":null,"body":["<article data-history-node-id=\"1765\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-048<br \/>\nDate: 27 February 2020<\/strong><\/p>\n\n<p>On 24 February 2020 Moxa released a security update to address numerous vulnerabilities found in their AWK-3131A Series Industrial AP\/Bridge\/Client product (affecting firmware version 1.13 or lower)<\/p>\n\n<p>Successful exploitation of these vulnerabilities may lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Moxa security advisory and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/awk-3131a-series-industrial-ap-bridge-client-vulnerabilities\">https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/awk-3131a-series-industrial-ap-bridge-client-vulnerabilities<\/a>\u00a0\u00a0<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-1","alert_type":398,"serial_number":"AV20-048","subject":null,"moderation_state":"published","external_url":null},{"nid":1766,"title":"[Control systems] Honeywell security advisory","uuid":"23f77bb6-4646-42cc-b8f9-702b2b7bb040","banner":null,"lang":"en","date_modified":"2020-02-27","date_modified_ts":"2020-02-27T14:34:08Z","date_created":"2020-02-27T14:30:53Z","summary":null,"body":["<article data-history-node-id=\"1766\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-047<br \/>\nDate: 27 February 2020<\/strong><\/p>\n\n<p>On 4 February 2020 Honeywell released a security update to address a vulnerability in their NOTI-FIRE-NET Web Server product (versions 3.50 and prior). Successful exploitation of this vulnerability may allow a remote actor to bypass web server authentication methods.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<br \/>\nHoneywell Advisory<\/p>\n\n<p><a href=\"https:\/\/www.notifier.com.au\/notices\/Security_Notification_SN_2020-02-04_Rev_01_Notifier.pdf\">https:\/\/www.notifier.com.au\/notices\/Security_Notification_SN_2020-02-04_Rev_01_Notifier.pdf<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-051-03)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-051-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-051-03<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-2","alert_type":398,"serial_number":"AV20-047","subject":null,"moderation_state":"published","external_url":null},{"nid":1767,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"796cc46f-6709-4c8a-9244-dbb8af55d724","banner":null,"lang":"en","date_modified":"2020-02-27","date_modified_ts":"2020-02-27T14:38:29Z","date_created":"2020-02-27T14:38:29Z","summary":null,"body":["<article data-history-node-id=\"1767\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-046<br \/>\nDate: 27 February 2020<\/strong><\/p>\n\n<p>On 20 February 2020 B&amp;R Industrial Automation released a security update to address a vulnerability in their Automation Studio and Automation Runtime products. The following versions are affected:<\/p>\n\n<p>\u2022\u00a0Automation Studio Versions 2.7, 3.0.71, 3.0.80, 3.0.81, 3.0.90, 4.0.x to 4.6.4, and 4.7.2<br \/>\n\u2022\u00a0Automation Runtime Versions 2.96, 3.00, 3.01, 3.06, 3.07, 3.08 to 3.10, 4.00 to 4.03, 4.04 to 4.03, 4.04 to 4.63, 4.72 and above.<\/p>\n\n<p>Successful exploitation of a vulnerability found in the SNMP service may allow an unauthenticated actor to modify the configuration of these affected products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-051-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-051-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-051-01<\/a>\u00a0\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory","alert_type":398,"serial_number":"AV20-046","subject":null,"moderation_state":"published","external_url":null},{"nid":1768,"title":"[Control systems] Rockwell Automation security advisory","uuid":"69169a65-66fc-44d1-b2d5-e27340122699","banner":null,"lang":"en","date_modified":"2020-02-27","date_modified_ts":"2020-02-27T14:47:04Z","date_created":"2020-02-27T14:47:04Z","summary":null,"body":["<article data-history-node-id=\"1768\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-049<br \/>\nDate: 27 February 2020<\/strong><\/p>\n\n<p>On 20 February 2020 Rockwell Automation released a security update to address a vulnerability in their FactoryTalk Diagnostics software product (all versions affected).<br \/>\nSuccessful exploitation of this vulnerability may allow a remote unauthenticated actor to execute arbitrary code with system level privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-051-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-051-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-051-02<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory","alert_type":398,"serial_number":"AV20-049","subject":null,"moderation_state":"published","external_url":null},{"nid":1769,"title":"[Control systems] Honeywell security advisory","uuid":"5393fce2-e8ac-42ac-9684-8ad7b433cbfe","banner":null,"lang":"en","date_modified":"2020-03-02","date_modified_ts":"2020-03-02T13:55:42Z","date_created":"2020-02-27T15:12:46Z","summary":null,"body":["<article data-history-node-id=\"1769\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-050<br \/>\nDate: 27 February 2020<\/strong><\/p>\n\n<p>On 25 February 2020 Honeywell released a security update to address a vulnerability in their WIN-PAK monitoring platform (Win-Pak 4.7.2, Web and prior versions).<br \/>\nSuccessful exploitation of this vulnerability may allow a remote actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-056-05)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-056-05\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-056-05<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-3","alert_type":398,"serial_number":"AV20-050","subject":null,"moderation_state":"published","external_url":null},{"nid":1771,"title":"Cisco security advisory","uuid":"f019eb75-fb10-4009-a9cc-451b60c0f4dc","banner":null,"lang":"en","date_modified":"2020-03-02","date_modified_ts":"2020-03-02T14:13:14Z","date_created":"2020-03-02T14:13:14Z","summary":null,"body":["<article data-history-node-id=\"1771\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-43\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-051<br \/>\nDate:\u00a002 March\u00a02020<\/strong><\/p>\n\n<p>On 26 February 2020 Cisco released security advisories to address medium and high vulnerabilities affecting a number of their products. Of note is a high vulnerability in the Cisco Discovery Protocol feature of Cisco\u2019s FXOS Software and NX-OS Software that could allow an unauthenticated actor in the same layer 2 broadcast domain to execute code of their choice as root.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-43","alert_type":396,"serial_number":"AV20-051","subject":null,"moderation_state":"published","external_url":null},{"nid":1770,"title":"NVIDIA security advisory","uuid":"42173a42-e595-42d2-af9c-f4d57da3b433","banner":null,"lang":"en","date_modified":"2020-03-02","date_modified_ts":"2020-03-02T20:20:19Z","date_created":"2020-03-02T20:20:19Z","summary":null,"body":["<article data-history-node-id=\"1770\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-052<br \/>\nDate:\u00a002 March\u00a02020<\/strong><\/p>\n\n<p>On 28 February 2020 NVIDIA released a security bulletin to address vulnerabilities affecting their GPU Display Driver. Successful exploitation of these vulnerabilities may lead to denial of service, escalation of privileges, information disclosure or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the NVIDIA Security Bulletin and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4996\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/4996<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-8","alert_type":396,"serial_number":"AV20-052","subject":null,"moderation_state":"published","external_url":null},{"nid":1772,"title":"Let\u2019s Encrypt Certificate Advisory","uuid":"941f814c-d510-4101-8231-ef49c180f54e","banner":null,"lang":"en","date_modified":"2020-03-04","date_modified_ts":"2020-03-04T16:44:35Z","date_created":"2020-03-04T16:44:35Z","summary":null,"body":["<article data-history-node-id=\"1772\" about=\"\/en\/alerts-advisories\/lets-encrypt-certificate-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-053<br \/>\nDate:\u00a004 March\u00a02020<\/strong><\/p>\n\n<p>On 3 March 2020 Let\u2019s Encrypt announced that they would be revoking 3,048,289 TLS\/SSL certificates on 4 March 2020 at 3:00pm EST. The revocation was triggered by the discovery of a vulnerability in some certificates that would allow possible forged certificates to be issued under specific circumstances. Let\u2019s Encrypt is attempting to contact all registered owners of affected certificates through the contact information which was provided to Let\u2019s Encrypt upon registration. The number of certificates being revoked represents 2.6% of all certificates.\u00a0 Upon certificate revocation, an affected web site may become inaccessible to web browsers or may cause the web browser to display a security caution message.<\/p>\n\n<p>The Cyber Centre recommends that all users of Let\u2019s Encrypt TLS\/SSL certificates renew their certificates as soon as possible, whether or not Let\u2019s Encrypt has advised them of an issue with their individual certificate. For additional information, including tools to test if a certificate is affected, please refer to Let\u2019s Encrypt\u2019s official security advice:<\/p>\n\n<p><a href=\"https:\/\/community.letsencrypt.org\/t\/revoking-certain-certificates-on-march-4\/114864\">https:\/\/community.letsencrypt.org\/t\/revoking-certain-certificates-on-march-4\/114864<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/lets-encrypt-certificate-advisory","alert_type":396,"serial_number":"AV20-053","subject":null,"moderation_state":"published","external_url":null},{"nid":1773,"title":"[Control systems] Emerson security advisory","uuid":"12597bab-7943-40d0-a3d3-8cd947a0234b","banner":null,"lang":"en","date_modified":"2020-03-04","date_modified_ts":"2020-03-04T19:25:09Z","date_created":"2020-03-04T19:25:09Z","summary":null,"body":["<article data-history-node-id=\"1773\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-054<br \/>\nDate:\u00a004 March\u00a02020<\/strong><\/p>\n\n<p>On 3 March 2020 Emerson released security updates to address a vulnerability in its ValveLink digital valve controller software, affecting versions 12.0.264 to 13.4.118. Successful exploitation of this vulnerability may allow a local actor to execute arbitrary code on the affected computer.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-063-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-063-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-063-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-0","alert_type":398,"serial_number":"AV20-054","subject":null,"moderation_state":"published","external_url":null},{"nid":1774,"title":"[Control systems] Omron security advisory","uuid":"647ded6a-9bf8-4c85-9ccc-dccbc2fc62ce","banner":null,"lang":"en","date_modified":"2020-03-04","date_modified_ts":"2020-03-04T19:28:06Z","date_created":"2020-03-04T19:28:06Z","summary":null,"body":["<article data-history-node-id=\"1774\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-055<br \/>\nDate:\u00a004 March\u00a02020<\/strong><\/p>\n\n<p>On 3 March 2020 Omron released security updates to address a vulnerability in all Omron PLC CJ series devices. Successful exploitation of this vulnerability may allow a remote actor to cause a denial of service condition on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-063-03)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-063-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-063-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-1","alert_type":398,"serial_number":"AV20-055","subject":null,"moderation_state":"published","external_url":null},{"nid":1776,"title":"Linux security advisory","uuid":"1113aee6-4dff-4718-b129-caa983f7273a","banner":null,"lang":"en","date_modified":"2020-03-05","date_modified_ts":"2020-03-05T13:21:10Z","date_created":"2020-03-05T13:04:02Z","summary":null,"body":["<article data-history-node-id=\"1776\" about=\"\/en\/alerts-advisories\/linux-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-056<br \/>\nDate:\u00a005 March\u00a02020<\/strong><\/p>\n\n<p>Several Linux distributions have released security updates to address vulnerabilities in their respective operating systems. Of note is a vulnerability in the Point-to-Point Protocol Daemon (pppd) versions 2.4.2 through 2.4.8.\u00a0\u00a0<\/p>\n\n<p>Due to a flaw in the Extensible Authentication Protocol (EAP) packet processing in the Point-to-Point Protocol Daemon (pppd), an unauthenticated remote actor may be able to cause a stack buffer overflow, allowing for arbitrary code execution on the target system.<\/p>\n\n<p>Linux operating systems affected by this vulnerability include Debian, Ubuntu, Red Hat, and Suse. Please note that this is not an exhaustive list and that other versions of Linux may be affected. Several security bulletins have been released and the Cyber Centre encourages users and administrators to review the applicable bulletins listed below and apply the necessary updates.<\/p>\n\n<p>Debian: <a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-8597\">https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-8597<\/a><br \/>\nUbuntu: <a href=\"https:\/\/usn.ubuntu.com\/4288-1\/\">https:\/\/usn.ubuntu.com\/4288-1\/<\/a><br \/>\nRed Hat: <a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2020:0630\">https:\/\/access.redhat.com\/errata\/RHSA-2020:0630<\/a><br \/>\nSuse: <a href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2020-8597\/\">https:\/\/www.suse.com\/security\/cve\/CVE-2020-8597\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-security-advisory-1","alert_type":396,"serial_number":"AV20-056","subject":null,"moderation_state":"published","external_url":null},{"nid":1775,"title":"Google Chrome security advisory","uuid":"84977a01-1adf-4364-8168-e06950fba10f","banner":null,"lang":"en","date_modified":"2020-03-05","date_modified_ts":"2020-03-05T13:12:28Z","date_created":"2020-03-05T13:12:28Z","summary":null,"body":["<article data-history-node-id=\"1775\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-057<br \/><strong>Date:\u00a005 March\u00a02020<\/strong><\/strong><\/p>\n\n<p>On 3 March 2020 Google announced the release of Chrome 80.0.3987.132 for Windows, Mac, and Linux.<br \/>\nThe Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/03\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/03\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<br \/><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-17","alert_type":396,"serial_number":"AV20-057","subject":null,"moderation_state":"published","external_url":null},{"nid":1778,"title":"Android security advisory","uuid":"fc4cb759-2876-44ec-ab5f-8aa4f124b484","banner":null,"lang":"en","date_modified":"2020-03-06","date_modified_ts":"2020-03-06T18:32:40Z","date_created":"2020-03-05T19:02:23Z","summary":null,"body":["<article data-history-node-id=\"1778\" about=\"\/en\/alerts-advisories\/android-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-058<\/strong><br \/><strong>Date:\u00a005 March\u00a02020<\/strong><\/p>\n\n<p>On 2 March 2020 Android published a Security Bulletin to address multiple vulnerabilities affecting Android devices. A remote actor could exploit one of these vulnerabilities by convincing a user to download a specially-crafted Android application which could then execute arbitrary code within the context of a privileged process.<br \/>\nThe Cyber Centre encourages users and administrators to review the Android Security Bulletin and apply the necessary updates, when available:<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-03-01.html\">https:\/\/source.android.com\/security\/bulletin\/2020-03-01.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-10","alert_type":396,"serial_number":"AV20-058","subject":null,"moderation_state":"published","external_url":null},{"nid":1779,"title":"Cisco security advisory","uuid":"378787c4-cd7d-4b29-86ad-f520ef491349","banner":null,"lang":"en","date_modified":"2020-03-06","date_modified_ts":"2020-03-06T18:34:27Z","date_created":"2020-03-05T19:07:59Z","summary":null,"body":["<article data-history-node-id=\"1779\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-44\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-059<\/strong><br \/><strong>Date:\u00a005 March\u00a02020<\/strong><\/p>\n\n<p>On 04 March 2020 Cisco released a number of security advisories to address vulnerabilities affecting multiple products. Of note are vulnerabilities in the Cisco Webex video service tracked as CVE-2020-3127 and CVE-2020-3128.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to execute arbitrary code with the privileges of the targeted user. The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-44","alert_type":396,"serial_number":"AV20-059","subject":null,"moderation_state":"published","external_url":null},{"nid":1777,"title":"[Control systems] WAGO security advisory","uuid":"ebe2bdfd-292c-4220-b53b-2b55b0bf34a9","banner":null,"lang":"en","date_modified":"2020-03-06","date_modified_ts":"2020-03-06T18:23:23Z","date_created":"2020-03-06T18:23:23Z","summary":null,"body":["<article data-history-node-id=\"1777\" about=\"\/en\/alerts-advisories\/control-systems-wago-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-060<\/strong><br \/><strong>Date:\u00a006 March\u00a02020<\/strong><\/p>\n\n<p>On 05 March 2020 WAGO released security updates to address vulnerabilities in the following versions of I\/O-CHECK software:<\/p>\n\n<p>\u2022\u00a0Series PFC100 (750-81xx\/xxx-xxx)<br \/>\n\u2022\u00a0Series PFC200 (750-82xx\/xxx-xxx)<br \/>\n\u2022\u00a0750-852, 750-831\/xxx-xxx, 750-881, 750-880\/xxx-xxx, 750-889<br \/>\n\u2022\u00a0750-823, 750-832\/xxx-xxx, 750-862, 750-890\/xxx-xxx, 750-891<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to change settings, delete the application, run remote code, cause a system crash or cause a denial-of-service condition on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<br \/>\nICS Advisory (ICSA-20-065-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-065-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-065-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wago-security-advisory","alert_type":398,"serial_number":"AV20-060","subject":null,"moderation_state":"published","external_url":null},{"nid":1781,"title":"Intel security advisory","uuid":"be407754-cdc0-42cb-9b95-a7d9f94f7cc7","banner":null,"lang":"en","date_modified":"2020-03-10","date_modified_ts":"2020-03-10T15:02:01Z","date_created":"2020-03-10T15:02:01Z","summary":null,"body":["<article data-history-node-id=\"1781\" about=\"\/en\/alerts-advisories\/intel-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-061<\/strong><br \/><strong>Date:\u00a010 March\u00a02020<\/strong><\/p>\n\n<p>On 10 March 2020 Intel released security updates to address vulnerabilities affecting several Intel products. Of note are a number of security vulnerabilities in Intel\u00ae Graphics Drivers which may allow for escalation of privileges, denial of service or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Intel Product Security Center Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-10","alert_type":396,"serial_number":"AV20-061","subject":null,"moderation_state":"published","external_url":null},{"nid":1782,"title":"ManageEngine Desktop Central security advisory","uuid":"7b0af76b-62a3-4c41-8c13-84e029700267","banner":null,"lang":"en","date_modified":"2020-03-10","date_modified_ts":"2020-03-10T15:07:51Z","date_created":"2020-03-10T15:07:51Z","summary":null,"body":["<article data-history-node-id=\"1782\" about=\"\/en\/alerts-advisories\/manageengine-desktop-central-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-062<\/strong><br \/><strong>Date:\u00a010 March\u00a02020<\/strong><\/p>\n\n<p>On 7 March 2020 ManageEngine published a security update to address a vulnerability, tracked as CVE-2020-10189, affecting its Desktop Central endpoint management solution. An unauthenticated remote actor could exploit the vulnerability to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the ManageEngine security bulletin and apply the necessary updates:<br \/><a href=\"https:\/\/www.manageengine.com\/products\/desktop-central\/remote-code-execution-vulnerability.html\">https:\/\/www.manageengine.com\/products\/desktop-central\/remote-code-execution-vulnerability.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/manageengine-desktop-central-security-advisory","alert_type":396,"serial_number":"AV20-062","subject":null,"moderation_state":"published","external_url":null},{"nid":1790,"title":"[Control systems] Siemens security advisory","uuid":"cb6438e9-bff4-4ad8-be53-01d2ccc69b6f","banner":null,"lang":"en","date_modified":"2020-03-10","date_modified_ts":"2020-03-10T19:04:39Z","date_created":"2020-03-10T18:54:00Z","summary":null,"body":["<article data-history-node-id=\"1790\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-063<br \/>\nDate: 10 March 2020<\/strong><\/p>\n\n<p>On 10 March 2020 Siemens released security updates to address vulnerabilities in the SIMATIC S7-300 CPU family (incl. related ET200CPUs and SIPLUS variants) and the SINUMERIK 840D sl controller.\u00a0 Successful exploitation of these vulnerabilities may allow an actor to trigger a denial of service on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-508982.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-508982.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-6","alert_type":398,"serial_number":"AV20-063","subject":null,"moderation_state":"published","external_url":null},{"nid":1780,"title":"Microsoft security advisory \u2013 March 2020 Monthly","uuid":"fe1d5c61-f055-463c-8692-03522a72334a","banner":null,"lang":"en","date_modified":"2020-03-11","date_modified_ts":"2020-03-11T13:41:47Z","date_created":"2020-03-11T13:41:47Z","summary":null,"body":["<article data-history-node-id=\"1780\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-march-2020-monthly\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-064<\/strong><br \/><strong>Date:\u00a011 March\u00a02020<\/strong><\/p>\n\n<p>On 10 March 2020 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for 26 critical remote code execution vulnerabilities.<\/p>\n\n<p>Of note is a critical remote code execution vulnerability, tracked as CVE-2020-0684, which exists in the processing of shortcut LNK references. A maliciously crafted .LNK file could allow for arbitrary code execution using the same user rights as the local user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft March 2020 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Mar\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Mar<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-march-2020-monthly","alert_type":396,"serial_number":"AV20-064","subject":null,"moderation_state":"published","external_url":null},{"nid":1783,"title":"Microsoft Exchange Validation Key Remote Code Execution Vulnerability","uuid":"5f9bb6e7-d01d-4b81-8dee-35f18bb8bed1","banner":null,"lang":"en","date_modified":"2020-03-12","date_modified_ts":"2020-03-12T12:41:35Z","date_created":"2020-03-12T12:34:49Z","summary":null,"body":["<article data-history-node-id=\"1783\" about=\"\/en\/alerts-advisories\/microsoft-exchange-validation-key-remote-code-execution-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-006<br \/>\nDate: 12 March 2020<\/strong><\/p>\n\n<h2><strong>AUDIENCE<\/strong><\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2><strong>PURPOSE<\/strong><\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2><strong>DETAILS<\/strong><\/h2>\n\n<p>On 11 February 2020, Microsoft released a security update, tracked as CVE-2020-0688, to address an important vulnerability in Microsoft Exchange Server. A threat actor gaining any level of authenticated access to the web-based Exchange Configuration Panel (ECP) of an unpatched Exchange server can take advantage of published, fixed cryptographic keys found in the web.config file of all vulnerable Exchange servers. Using these keys, and additional parameters available to any user logged into ECP, the actor can specially craft an http(s) request that includes a signed, serialised ViewState request containing arbitrary code. The server will respond by de-serialising the request and running the embedded code as SYSTEM.<br \/>\nThe Cyber Centre is aware of public reporting that sophisticated threat actors are attempting to exploit this vulnerability. Public reporting further indicates that the vulnerability can be exploited even where two-factor authentication (2FA) is in place. The Cyber Centre has not been able to substantiate this latter claim.<br \/>\nThe vulnerable versions of Microsoft Exchange are:<\/p>\n\n<p>-\u00a0Exchange 2010<br \/>\n-\u00a0Exchange 2013<br \/>\n-\u00a0Exchange 2016<br \/>\n-\u00a0Exchange 2019<\/p>\n\n<h2><strong>SUGGESTED ACTION<\/strong><\/h2>\n\n<p>The Cyber Centre recommends that organizations immediately install the latest security updates from Microsoft and ensure that where ECP is accessible from the Internet, that it is protected by 2FA.<\/p>\n\n<p>The Cyber Centre further recommends that organizations running affected versions of Microsoft Exchange examine systems and logs for signs of compromise.<\/p>\n\n<p>Signs of compromise would include:<\/p>\n\n<p>-\u00a0IIS logs containing suspicious web requests for resources under &lt;FQDN&gt;\/ecp\/, particularly GET requests referencing __VIEWSTATE or a variant;<br \/>\n-\u00a0Unexpected Windows Application Log entries relating to the MSExchange Control Panel, particularly Event ID 4; and<br \/>\n-\u00a0Child executable processes spawned by w3wp.exe.\u00a0<\/p>\n\n<p>Should evidence of compromise be observed:<\/p>\n\n<p>-\u00a0Isolate the affected servers from the rest of the network;<br \/>\n-\u00a0Force Active Directory password resets for all Exchange users;<br \/>\n-\u00a0Scan affected servers for suspicious\/malicious files or processes;<br \/>\n-\u00a0Examine affected servers for persistence mechanisms, such as unexpected scheduled tasks or auto run entries in the Windows registry; and<br \/>\n-\u00a0Examine network traffic for signs of lateral movement from the affected system.<\/p>\n\n<h2><br \/><strong>REFERENCES<\/strong><\/h2>\n\n<p>Microsoft Advisory:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0688\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0688<\/a><\/p>\n\n<p>Further information:<br \/><a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2020\/2\/24\/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys\">https:\/\/www.zerodayinitiative.com\/blog\/2020\/2\/24\/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys<\/a><\/p>\n\n<p>Detection:<br \/><a href=\"https:\/\/www.trustedsec.com\/blog\/detecting-cve-20200688-remote-code-execution-vulnerability-on-microsoft-exchange-server\">https:\/\/www.trustedsec.com\/blog\/detecting-cve-20200688-remote-code-execution-vulnerability-on-microsoft-exchange-server<\/a><\/p>\n\n<p><br \/><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the<br \/>\nCyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information<br \/>\nsharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-exchange-validation-key-remote-code-execution-vulnerability","alert_type":397,"serial_number":"AL20-006","subject":null,"moderation_state":"published","external_url":null},{"nid":1784,"title":"SAP security advisory","uuid":"76ad6155-5c3c-4a33-a0a1-28e003016d4c","banner":null,"lang":"en","date_modified":"2020-03-12","date_modified_ts":"2020-03-12T19:52:57Z","date_created":"2020-03-12T19:52:57Z","summary":null,"body":["<article data-history-node-id=\"1784\" about=\"\/en\/alerts-advisories\/sap-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-065<\/strong><br \/><strong>Date:\u00a012 March\u00a02020<\/strong><\/p>\n\n<p>On 10 March 2020 SAP released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<p>\u2022\u00a0SAP Solution Manager (User Experience Monitoring)<br \/>\n\u2022\u00a0SAP Business Client<br \/>\n\u2022\u00a0SAP NetWeaver UDDI Server (Services Registry)<br \/>\n\u2022\u00a0SAP Business Objects Business Intelligence Platform (Crystal Reports)<br \/>\n\u2022\u00a0SAP MaxDB (liveCache)<br \/>\n\u2022\u00a0SAP Commerce Cloud (Testweb Extension)<br \/>\n\u2022\u00a0SAP NetWeaver AS ABAP Business Server Pages (Smart Forms)<br \/>\n\u2022\u00a0SAP NetWeaver Application Server Java (User Management Engine)<br \/>\n\u2022\u00a0SAP Commerce Cloud (SmartEdit Extension)<br \/>\n\u2022\u00a0SAP ERP (EAPPGLO)<br \/>\n\u2022\u00a0SAP Enable Now<br \/>\n\u2022\u00a0SAP Fiori Launchpad<br \/>\n\u2022\u00a0SAP Cloud Platform Integration for Data Services<br \/>\n\u2022\u00a0SAP Treasury and Risk Management (Transaction Management)<\/p>\n\n<p>These vulnerabilities may allow for unauthorized information access, remote code execution, denial of service, cross-site scripting or content spoofing.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the SAP Security Patch Day webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=540935305\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=540935305<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-3","alert_type":396,"serial_number":"AV20-065","subject":null,"moderation_state":"published","external_url":null},{"nid":1786,"title":"[Control systems] Rockwell Automation security advisory","uuid":"c5c5235f-dcd1-467a-854a-ac0e6f80b63f","banner":null,"lang":"en","date_modified":"2020-03-12","date_modified_ts":"2020-03-12T19:58:37Z","date_created":"2020-03-12T19:54:29Z","summary":null,"body":["<article data-history-node-id=\"1786\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-066<\/strong><br \/><strong>Date:\u00a012 March\u00a02020<\/strong><\/p>\n\n<p>On 10 March 2020 Rockwell Automation released security updates to address vulnerabilities in the MicroLogix Controllers and RSLogix 500 Software.\u00a0 Successful exploitation of these vulnerabilities may allow an actor to gain access to sensitive project file information including passwords.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-070-06)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-070-06\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-070-06<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-0","alert_type":398,"serial_number":"AV20-066","subject":null,"moderation_state":"published","external_url":null},{"nid":1785,"title":"[Control systems] Siemens security advisory","uuid":"233293d6-99d9-4f86-806b-407e2fd66bc9","banner":null,"lang":"en","date_modified":"2020-03-12","date_modified_ts":"2020-03-12T19:57:14Z","date_created":"2020-03-12T19:57:14Z","summary":null,"body":["<article data-history-node-id=\"1785\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-067<\/strong><br \/><strong>Date:\u00a012 March\u00a02020<\/strong><\/p>\n\n<p>On 10 March 2020 Siemens released security updates to address vulnerabilities in the Spectrum Power grid control system versions prior to 5.50 HF02, the SiNVR 3 Central Control Server (CCS) and SiNVR 3 Video Server.\u00a0 Successful exploitation of these vulnerabilities may allow an actor to trigger a denial of service or access confidential information or data and programming on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-938930.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-938930.pdf<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-844761.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-844761.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-7","alert_type":398,"serial_number":"AV20-067","subject":null,"moderation_state":"published","external_url":null},{"nid":1787,"title":"Mozilla security advisory","uuid":"f86ff976-849a-4972-baa8-962999c0e492","banner":null,"lang":"en","date_modified":"2020-03-12","date_modified_ts":"2020-03-12T20:00:29Z","date_created":"2020-03-12T20:00:29Z","summary":null,"body":["<article data-history-node-id=\"1787\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-069<\/strong><br \/><strong>Date:\u00a012 March\u00a02020<\/strong><\/p>\n\n<p>On 10 March 2020 Mozilla released Firefox 74 and Firefox ESR 68.6 to address vulnerabilities.\u00a0 By tricking a victim into visiting a specially crafted web page, a remote actor could trigger a memory corruption vulnerability and execute arbitrary code on the target system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-11","alert_type":396,"serial_number":"AV20-069","subject":null,"moderation_state":"published","external_url":null},{"nid":1788,"title":"[Control systems] Johnson Controls security advisory","uuid":"c1313d51-8437-4702-84e3-b5e9b2e16f33","banner":null,"lang":"en","date_modified":"2020-03-12","date_modified_ts":"2020-03-12T20:00:57Z","date_created":"2020-03-12T20:00:57Z","summary":null,"body":["<article data-history-node-id=\"1788\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-068<\/strong><br \/><strong>Date:\u00a012 March\u00a02020<\/strong><\/p>\n\n<p>On 10 March 2020 Johnson Controls released security updates to address vulnerabilities in the following versions of the Metasys products:<\/p>\n\n<p>\u2022\u00a0Application and Data Server (ADS, ADS-Lite): Release 10.1 and prior<br \/>\n\u2022\u00a0Extended Application and Data Server (ADX): Release 10.1 and prior<br \/>\n\u2022\u00a0Open Data Server (ODS): Release 10.1 and prior<br \/>\n\u2022\u00a0Open Application Server (OAS): Release 10.1<br \/>\n\u2022\u00a0Network Automation Engine (NAE55 only): Releases 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6<br \/>\n\u2022\u00a0Network Integration Engine (NIE55\/NIE59): Releases 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6<br \/>\n\u2022\u00a0NAE85 and NIE85: Release 10.1 and prior<br \/>\n\u2022\u00a0LonWorks Control Server (LCS): Release 10.1 and prior<br \/>\n\u2022\u00a0System Configuration Tool (SCT): Release 13.2 and prior<br \/>\n\u2022\u00a0Smoke Control Network Automation Engine (NAE55, UL 864 UUKL\/ORD-C100-13 UUKLC 10th Edition Listed) Release 8.1<\/p>\n\n<p>Additionally, the following versions of Kantech EntraPass security management software are affected:<\/p>\n\n<p>\u2022\u00a0Corporate Edition: All versions prior to v8.10<br \/>\n\u2022\u00a0Global Edition: All versions prior to v8.10<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow an actor to cause a denial of service, access sensitive information or execute code in the context of the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020_3-v1-microsoft_net-framework.pdf\">https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020_3-v1-microsoft_net-framework.pdf<\/a><\/p>\n\n<p><a href=\"https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020_2-v1-smartservice_api.pdf\">https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020_2-v1-smartservice_api.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory","alert_type":398,"serial_number":"AV20-068","subject":null,"moderation_state":"published","external_url":null},{"nid":1789,"title":"Microsoft SMBv3 Critical Vulnerability","uuid":"55b80f3d-e0b2-4336-8ec5-296074378c4b","banner":null,"lang":"en","date_modified":"2020-03-13","date_modified_ts":"2020-03-13T12:28:09Z","date_created":"2020-03-13T12:28:09Z","summary":null,"body":["<article data-history-node-id=\"1789\" about=\"\/en\/alerts-advisories\/microsoft-smbv3-critical-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-007<br \/>\nDate: 13 March 2020<\/strong><\/p>\n\n<h2><strong>AUDIENCE<\/strong><\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2><strong>OVERVIEW<\/strong><\/h2>\n\n<p>On 10 March 2020 Microsoft released a security bulletin detailing a critical, remotely-exploitable vulnerability in the way that Microsoft server message block (SMBv3) handles certain requests. This vulnerability may allow a remote, unauthenticated actor to execute arbitrary code on vulnerable SMB servers and SMB clients.<br \/>\nMicrosoft has assigned CVE-2020-0796 to this vulnerability and has released an out-of-band security patch to fix all affected products.<\/p>\n\n<h2><strong>DETAILS<\/strong><\/h2>\n\n<p>The Cyber Centre is aware of a remotely-exploitable vulnerability in the way that Microsoft server message block 3.1.1 (SMBv3) handles certain requests. The vulnerability may allow a remote, unauthenticated actor to execute arbitrary code on the target SMB server or SMB client.<\/p>\n\n<p>The following products are affected:<br \/>\n\u2022\u00a0Windows 10 Version 1903 for 32-bit Systems;<br \/>\n\u2022\u00a0Windows 10 Version 1903 for ARM64-based Systems;<br \/>\n\u2022\u00a0Windows 10 Version 1903 for x64-based Systems;<br \/>\n\u2022\u00a0Windows 10 Version 1909 for 32-bit Systems;<br \/>\n\u2022\u00a0Windows 10 Version 1909 for ARM64-based Systems;<br \/>\n\u2022\u00a0Windows 10 Version 1909 for x64-based Systems;<br \/>\n\u2022\u00a0Windows Server, version 1903 (Server Core installation); and<br \/>\n\u2022\u00a0Windows Server, version 1909 (Server Core installation).<\/p>\n\n<p>To exploit a vulnerable SMB server, an unauthenticated actor would need to send a specially crafted packet to the targeted system. To exploit a vulnerable SMB client, an actor would need to configure a malicious SMBv3 server and convince a user to connect to it.<\/p>\n\n<p>As out-of-band patches for this vulnerability have just been released by Microsoft, the Cyber Centre recommends that system owners refer to the Mitigation section of this Alert to protect their networks.<\/p>\n\n<h2><br \/>\nMITIGATION<\/h2>\n\n<p>The Cyber Centre recommends that system owners of vulnerable systems immediately apply the out-of-band security patches from Microsoft:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0796\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0796<\/a><\/p>\n\n<p>It is further recommended that restrictions on inbound \/ outbound TCP port 445 SMB traffic be implemented at the network border firewall.<\/p>\n\n<p>Servers that cannot be patched immediately for operational reasons should have SMBv3 compression disabled as a workaround in order to protect them from exploitation. Note that disabling SMBv3 compression does not protect vulnerable clients.<\/p>\n\n<p>To avoid potential interruption of service, recommended workarounds and patches should be tested with client systems before being deployed in a production environment. Detailed workaround instructions are available on the Microsoft website:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/adv200005\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/adv200005<\/a><\/p>\n\n<h2><br \/>\nREFERENCES<\/h2>\n\n<p>10 March 2020 notice on the Microsoft website: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/adv200005\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/adv200005<\/a><\/p>\n\n<p>Microsoft security patch:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0796\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0796<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-smbv3-critical-vulnerability","alert_type":397,"serial_number":"AL20-007","subject":null,"moderation_state":"published","external_url":null},{"nid":1791,"title":"[Control systems] ABB security advisory","uuid":"ae6ffe04-aec8-49f0-930d-856ea4e57d95","banner":null,"lang":"en","date_modified":"2020-03-13","date_modified_ts":"2020-03-13T17:18:33Z","date_created":"2020-03-13T17:15:13Z","summary":null,"body":["<article data-history-node-id=\"1791\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-070<br \/>\nDate: 13 March 2020<\/strong><\/p>\n\n<p>On 12 March 2020 ABB released security updates to address vulnerabilities in eSOMS version 6.0.3 and prior and Asset Suite Versions 9.6 and prior (excluding 9.4.2.6 and 9.5.3.2).\u00a0 Successful exploitation of these vulnerabilities may allow a malicious actor to take over a user\u2019s browser session, discover session-based information or access unauthorized information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisories and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-072-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-072-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-072-01<\/a><br \/>\nICS Advisory (ICSA-20-072-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-072-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-072-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-0","alert_type":398,"serial_number":"AV20-070","subject":null,"moderation_state":"published","external_url":null},{"nid":1792,"title":"[Control systems] Rockwell Automation security advisory","uuid":"9f759bb6-f713-4cc7-9712-824528bbd83d","banner":null,"lang":"en","date_modified":"2020-03-13","date_modified_ts":"2020-03-13T17:22:56Z","date_created":"2020-03-13T17:22:56Z","summary":null,"body":["<article data-history-node-id=\"1792\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-071<br \/>\nDate: 13 March 2020<\/strong><\/p>\n\n<p>On 12 March 2020 Rockwell Automation released security updates to address vulnerabilities in the following versions of the Allen-Bradley Stratix 5950 Security Appliance:<\/p>\n\n<p>\u2022\u00a01783-SAD4T0SBK9<br \/>\n\u2022\u00a01783-SAD4T0SPK9<br \/>\n\u2022\u00a01783-SAD2T2SBK9<br \/>\n\u2022\u00a01783-SAD2T2SPK9<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a malicious actor to write a modified image to the Appliance.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<br \/>\nICS Advisory (ICSA-20-072-03)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-072-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-072-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-1","alert_type":398,"serial_number":"AV20-071","subject":null,"moderation_state":"published","external_url":null},{"nid":1793,"title":"VMware security advisory","uuid":"756c2623-4211-4f9a-8f45-475bc1308d57","banner":null,"lang":"en","date_modified":"2020-03-13","date_modified_ts":"2020-03-13T19:57:34Z","date_created":"2020-03-13T19:57:34Z","summary":null,"body":["<article data-history-node-id=\"1793\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-072<br \/>\nDate: 13 March 2020<\/strong><\/p>\n\n<p>On 12 March 2020 VMware released a security update to address a vulnerability affecting the following VMware products:<\/p>\n\n<p>\u2022\u00a0VMware Workstation Pro \/ Player (Workstation)<br \/>\n\u2022\u00a0VMware Fusion Pro \/ Fusion (Fusion)<br \/>\n\u2022\u00a0VMware Horizon Client for Windows<br \/>\n\u2022\u00a0VMware Remote Console for Windows (VMRC for Windows)<\/p>\n\n<p>Successful exploitation of this vulnerability may lead to code execution on the host from the guest.\u00a0 The Cyber Centre encourages users to review the following VMware Advisory and apply the necessary update:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0004.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0004.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-24","alert_type":396,"serial_number":"AV20-072","subject":null,"moderation_state":"published","external_url":null},{"nid":2003,"title":"Cyber threats to Canadian health organizations","uuid":"273dca94-feda-4fff-8ef0-9d77430be396","banner":null,"lang":"en","date_modified":"2020-07-28","date_modified_ts":"2020-07-28T21:12:25Z","date_created":"2020-03-19T17:10:36Z","summary":null,"body":["<article data-history-node-id=\"2003\" about=\"\/en\/alerts-advisories\/cyber-threats-canadian-health-organizations\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-008 \u2013 Update 1\u00a0<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>The Cyber Centre assesses that the COVID-19 pandemic presents an elevated level of risk to the cyber security of Canadian health organizations involved in the national response to the pandemic. The Cyber Centre therefore recommends that these organizations remain vigilant and take the time to ensure that they are engaged in cyber defense best practices, including increased monitoring of network logs, reminding employees to practice phishing awareness and ensuring that servers and critical systems are patched for all known security vulnerabilities.<\/p>\n\n<p>While this Alert highlights risks to the medical and health communities in Canada during the COVID-19 crisis, the advice and guidance also applies to other Canadian businesses, particularly those with employees teleworking through VPNs. Suggested mitigations and best practices are outlined below.<\/p>\n\n<h2>UPDATE<\/h2>\n\n<p>This product has been updated to highlight additional patches and mitigations for critical vulnerabilities.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>The Cyber Centre assesses that the COVID-19 pandemic presents an elevated level of risk to the cyber security of Canadian health organizations involved in the national response to the pandemic, including but not limited to medical research, manufacturing, distribution and policy-making organizations. Specifically:<\/p>\n\n<p>-\u00a0Sophisticated threat actors may attempt to steal the intellectual property (IP) of organizations engaged in research and development related to COVID-19, or sensitive data related to Canada\u2019s response to COVID-19; and<\/p>\n\n<p>-\u00a0Cyber criminals may take advantage of the COVID-19 pandemic, using the increased pressure being placed on Canadian health organizations to extract ransom payments or mask other compromises.<\/p>\n\n<p>Sophisticated Threat Actors<br \/>\n---------------------------<br \/>\nSophisticated threat actors may choose to target Canadian organizations involved in supporting Canada\u2019s response to the pandemic including organizations within the medical research community. These actors may attempt to gain intelligence on COVID-19 response efforts and potential political responses to the crisis or to steal ongoing key research towards a vaccine or other medical remedies, or other topics of interest to the threat actor. Organizations should exercise increased monitoring in order to detect attempted compromises by sophisticated threat actors. Attempts to compromise an organization by a sophisticated threat actor may leverage social engineering, spear-phishing campaigns, critical vulnerabilities, compromised credentials or a combination of these and other threat vectors.<\/p>\n\n<p>Ransomware<br \/>\n----------<br \/>\nThe impact of a ransomware incident on Canadian organizations involved in supporting Canada\u2019s response to the COVID-19 pandemic could be more severe during the current pandemic than if it were to occur in a non-crisis environment. It is therefore recommended that organizations take extra care in identifying, as early as possible, vulnerabilities and possible compromises that may lead to ransomware being deployed. The Cyber Centre strongly advises that all organizations become familiar with and practice their business continuity plans, including restoring files from back-ups and moving key business elements to a back-up infrastructure.<\/p>\n\n<p>The Cyber Centre recommends that organizations review its existing ransomware advice, available here:<br \/><a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"d8d48a11-24bc-4ac2-831c-0a4a8f5dd6be\" href=\"\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099\">https:\/\/cyber.gc.ca\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099<\/a><\/p>\n\n<p>Critical Vulnerabilities<br \/>\n------------------------<br \/>\nThe Cyber Centre assesses that vulnerabilities related to telework are of particular concern during the current pandemic. As organizations rush to make more infrastructure available to remote users, configuration errors may be made and unpatched software may be deployed. Multiple critical vulnerabilities have been identified in VPN devices over the past year, and multiple successful exploitations in the past have led the Cyber Centre to assess that they are likely to be leveraged for renewed compromise attempts over the short term. Recently disclosed vulnerabilities in Microsoft Windows and Linux operating systems, particularly those affecting remote desktop usage and certificate authentication, are also likely to be targeted.<\/p>\n\n<p>The Cyber Centre particularly recommends applying patches and mitigations for the following critical vulnerabilities as soon as possible:<\/p>\n\n<p>AL19-009 Critical Microsoft Remote Desktop Vulnerability<br \/>\nAL19-010 Active Exploitation of the Telerik UI for ASP.NET AJAX<br \/>\nAV19-167 Microsoft Security Advisory - August 2019 Monthly Rollup<br \/>\nAL19-016 Active exploitation of VPN vulnerabilities<br \/>\nAL20-003 Citrix Exploitation<br \/>\nAL20-004 Microsoft Internet Explorer 0-Day<br \/>\nAL20-005 Detecting Compromises relating to Citrix CVE-2019-19781<br \/>\nAL20-006 Microsoft Exchange Validation Key RCE Vulnerability<br \/>\nAL20-007 Microsoft SMBv3 Vulnerability<br \/>\nAV20-010 Microsoft Security Advisory - January 2020 Monthly Rollup<br \/>\nAV20-032 Microsoft Security Advisory - February 2020 Monthly Rollup<br \/>\nAV20-044 Apache Tomcat Security Advisory<br \/>\nAV20-053 Lets Encrypt Certificate Advisory<br \/>\nAV20-064 Microsoft Security Advisory - March 2020 Monthly Rollup<\/p>\n\n<p>These Alerts and Advisories can be found on the Cyber Centre web site: <a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"a25f0b23-576d-4ceb-a26d-6ffce73335b2\" href=\"\/en\/alerts-advisories\">https:\/\/cyber.gc.ca\/en\/alerts-advisories<\/a><\/p>\n\n<h2><br \/>\nMITIGATION<\/h2>\n\n<p>In view of these risks, the Cyber Centre recommends that all Canadian health organizations involved in the national response to the pandemic take the time to ensure that they are actively engaged in cyber defense best practices.<\/p>\n\n<p>Special consideration should be given to the following areas:<br \/>\n\u00a0<br \/>\n-\u00a0Stay aware of ongoing phishing activities related to COVID-19:<br \/>\no\u00a0<a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"5e61bb89-9051-4587-a3e1-e015b249cec7\" href=\"\/en\/guidance\/cyber-security-advice-and-guidance-research-and-development-organizations-during-covid-19\">https:\/\/cyber.gc.ca\/en\/guidance\/cyber-hygiene-covid-19<\/a><br \/>\n\u00a0<br \/>\n-\u00a0Employees working from home could put a strain on telework services. Ensure appropriate security policies have been put in place, and monitor logs for malicious activity:<br \/>\no\u00a0<a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"8385e0bd-7bf8-47c6-8bad-6393e01b76b6\" href=\"\/en\/guidance\/telework-security-issues-itsap10016\">https:\/\/www.cyber.gc.ca\/en\/guidance\/telework-security-issues-itsap10016<\/a><br \/>\no\u00a0<a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"481aa714-81de-40f1-a235-4b363a33b5ed\" href=\"\/en\/guidance\/virtual-private-networks-itsap80101\">https:\/\/www.cyber.gc.ca\/en\/guidance\/virtual-private-networks-itsap80101<\/a><br \/>\n\u00a0<br \/>\n-\u00a0Always keep in mind these top 10 security actions:<br \/>\no\u00a0<a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"5e50da87-989b-44d8-95e9-e95dc89e2d94\" href=\"\/en\/guidance\/top-10-it-security-actions\">https:\/\/cyber.gc.ca\/en\/top-10-it-security-actions<\/a><br \/>\n\u00a0<br \/>\n-\u00a0Review recently published Alerts and Advisories highlighting vulnerabilities that may affect your environment:<br \/>\no\u00a0<a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"a25f0b23-576d-4ceb-a26d-6ffce73335b2\" href=\"\/en\/alerts-advisories\">https:\/\/cyber.gc.ca\/en\/alerts-advisories<\/a><\/p>\n\n<p>-\u00a0Organizations that do not have a robust cyber defense capability may wish to consider consulting with private vendors of such services.<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\nThe Cyber Centre can be contacted at:<br \/>\nEmail: <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a><br \/>\nToll Free: <a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> <a href=\"tel:+1-833-292-3788\">(1-833-292-3788)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cyber-threats-canadian-health-organizations","alert_type":397,"serial_number":"AL20-008","subject":null,"moderation_state":"published","external_url":null},{"nid":1794,"title":"Google Chrome security advisory","uuid":"25f6fa70-c893-4558-a1e0-ff53a3c6acb9","banner":null,"lang":"en","date_modified":"2020-03-19","date_modified_ts":"2020-03-19T18:41:33Z","date_created":"2020-03-19T18:41:33Z","summary":null,"body":["<article data-history-node-id=\"1794\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-073<br \/>\nDate: 19 March 2020<\/strong><\/p>\n\n<p>On 18 March 2020 Google announced the release of Chrome 80.0.3987.149 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/03\/stable-channel-update-for-desktop_18.html\">https:\/\/chromereleases.googleblog.com\/2020\/03\/stable-channel-update-for-desktop_18.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<br \/><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-18","alert_type":396,"serial_number":"AV20-073","subject":null,"moderation_state":"published","external_url":null},{"nid":1795,"title":"Active exploitation of Trend Micro vulnerabilities","uuid":"35fb3ac7-a48b-4975-a9a6-8827d75bfc40","banner":null,"lang":"en","date_modified":"2020-03-19","date_modified_ts":"2020-03-19T18:54:34Z","date_created":"2020-03-19T18:54:34Z","summary":null,"body":["<article data-history-node-id=\"1795\" about=\"\/en\/alerts-advisories\/active-exploitation-trend-micro-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-009<br \/>\nDate: 19 March 2020<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>The Cyber Centre has become aware of reported exploitation attempts against Trend Micro Apex One and OfficeScan XG products. Trend Micro has recently patched several critical vulnerabilities in these products, including two which have been exploited in the wild.\u00a0<\/p>\n\n<h2>ASSESSMENT<\/h2>\n\n<p>On 16 March 2020 Trend Micro disclosed several vulnerabilities in the Trend Micro Apex One and OfficeScan XG products.\u00a0 These vulnerabilities could allow a remote actor to execute arbitrary code, manipulate agent client components, write and delete files using SYSTEM privileges and bypass root authentication.\u00a0 Details of the vulnerabilities are as follows:<\/p>\n\n<p>-\u00a0CVE-2020-8467: A migration tool component of Trend Micro Apex One and OfficeScan contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.<\/p>\n\n<p>-\u00a0CVE-2020-8468: Trend Micro Apex One and OfficeScan agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.<\/p>\n\n<p>-\u00a0CVE-2020-8470: Trend Micro Apex One and OfficeScan server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.<\/p>\n\n<p>-\u00a0CVE-2020-8598: Trend Micro Apex One and OfficeScan server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.<\/p>\n\n<p>-\u00a0CVE-2020-8599: Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.<\/p>\n\n<p>While active exploitation has been reported against CVE-2020-8467 and CVE-2020-8468, the remaining three vulnerabilities also warrant urgent action as they do not require authentication to exploit.<\/p>\n\n<h2>SUGGESTED ACTION<\/h2>\n\n<p>-\u00a0Trend Micro has released updated versions of the Apex One and OfficeScan XG products.\u00a0 If possible, upgrade to the latest versions.<br \/>\n-\u00a0Effectively segment networks and implement demilitarized zones (DMZs) with properly configured firewalls to selectively control and monitor traffic passed between zones.<br \/>\n-\u00a0Minimize network exposure for all systems and ensure that they are not directly accessible from the Internet.<br \/>\n-\u00a0Ensure the product servers and management consoles are restricted to trusted networks and\/or users as appropriate.<br \/>\n-\u00a0Ensure timely application of patches and updated software.<br \/>\n-\u00a0Review remote access to critical systems and ensure policies and perimeter security is up to date.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p><a href=\"https:\/\/success.trendmicro.com\/solution\/000245571\">https:\/\/success.trendmicro.com\/solution\/000245571<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-trend-micro-vulnerabilities","alert_type":397,"serial_number":"AL20-009","subject":null,"moderation_state":"published","external_url":null},{"nid":1796,"title":"Adobe security advisory","uuid":"bebaf57b-baa2-46c9-a8c9-e93afa496425","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T12:23:56Z","date_created":"2020-03-20T12:23:56Z","summary":null,"body":["<article data-history-node-id=\"1796\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-074<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 17 March 2020 Adobe released security updates to address vulnerabilities affecting several of its products. Some of these vulnerabilities could lead to information disclosure, privilege escalation or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-14","alert_type":396,"serial_number":"AV20-074","subject":null,"moderation_state":"published","external_url":null},{"nid":1797,"title":"Cisco security advisory","uuid":"2f4772e0-960f-4052-8e43-0fac79a23b29","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T12:27:27Z","date_created":"2020-03-20T12:27:27Z","summary":null,"body":["<article data-history-node-id=\"1797\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-45\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-075<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 18 March 2020 Cisco released security advisories to address vulnerabilities affecting multiple products. Of note are vulnerabilities in the Cisco SD-WAN Solution software, one of which could allow an authenticated, local actor to run arbitrary commands with escalated (root) privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories and Alerts webpage at the link below and apply the necessary updates:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-45","alert_type":396,"serial_number":"AV20-075","subject":null,"moderation_state":"published","external_url":null},{"nid":1798,"title":"[Control systems] Delta Electronics security advisory","uuid":"0c7e502b-11b4-48ae-bacd-3b7a922c17ad","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T12:35:56Z","date_created":"2020-03-20T12:35:56Z","summary":null,"body":["<article data-history-node-id=\"1798\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-076<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 17 March 2020 Delta Electronics released a security update to address a vulnerability in the Industrial Automation CNCSoft ScreenEditor (v1.00.96 and prior) product.\u00a0 Successful exploitation of this vulnerability may allow a malicious actor to access unauthorized information, execute code or crash the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<br \/>\nICS Advisory (ICSA-20-077-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-077-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-077-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-1","alert_type":398,"serial_number":"AV20-076","subject":null,"moderation_state":"published","external_url":null},{"nid":1799,"title":"Red Hat security advisory","uuid":"f994777b-6940-4eed-98db-bd7c3a749f83","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T12:40:22Z","date_created":"2020-03-20T12:40:22Z","summary":null,"body":["<article data-history-node-id=\"1799\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-077<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 17 March 2020 Red Hat released security advisories to address vulnerabilities affecting its operating system. Of note is a security update to Red Hat\u2019s JBoss Web Server, which addresses vulnerabilities in a component of JBoss, namely, Apache Tomcat. The update includes a fix for the recently discovered \u2018Ghostcat\u2019 vulnerability, tracked as CVE-2020-1938.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Red Hat Security Advisory webpage at the link below and apply the necessary updates:<br \/><a href=\"https:\/\/access.redhat.com\/errata\">https:\/\/access.redhat.com\/errata<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-1","alert_type":396,"serial_number":"AV20-077","subject":null,"moderation_state":"published","external_url":null},{"nid":1800,"title":"Ubuntu security advisory","uuid":"7cd2db5c-c02f-45e4-accd-f1a92c65ac03","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T12:43:25Z","date_created":"2020-03-20T12:43:25Z","summary":null,"body":["<article data-history-node-id=\"1800\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-078<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 17 March 2020 Ubuntu released security updates to address vulnerabilities in its operating system. An actor could exploit some of these vulnerabilities in order to expose sensitive information, cause a denial of service condition or execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Ubuntu Security Notices webpage and apply the necessary updates:<br \/><a href=\"https:\/\/usn.ubuntu.com\/\">https:\/\/usn.ubuntu.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-1","alert_type":396,"serial_number":"AV20-078","subject":null,"moderation_state":"published","external_url":null},{"nid":1801,"title":"Drupal security advisory","uuid":"aadf04aa-4dbe-4667-9653-c9b56cd882c5","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T13:26:15Z","date_created":"2020-03-20T13:26:15Z","summary":null,"body":["<article data-history-node-id=\"1801\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-079<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 18 March 2020 Drupal released updates to address a vulnerability in a third-party component of Drupal core. Under specific circumstances, the Drupal CKEditor component may allow a user of a Drupal site to effect cross-site-scripting (XSS) activity against another user, including one with greater privilege. This may result in a privilege escalation scenario.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Drupal Security Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/www.drupal.org\/security\">https:\/\/www.drupal.org\/security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-6","alert_type":396,"serial_number":"AV20-079","subject":null,"moderation_state":"published","external_url":null},{"nid":1802,"title":"[Control systems] Insulet security advisory","uuid":"06910c07-6897-4d1a-9195-7b0927e5d4eb","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T13:29:16Z","date_created":"2020-03-20T13:29:16Z","summary":null,"body":["<article data-history-node-id=\"1802\" about=\"\/en\/alerts-advisories\/control-systems-insulet-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-080<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 19 March 2020 Insulet released a security bulletin to address a vulnerability in its Omnipod Insulin Management System. An actor could exploit the vulnerability to intercept, modify, or interfere with the wireless radio frequency communications to or from the product. This, in turn, could allow the actor to read sensitive data, change pump settings, or control insulin delivery. The following versions of the Omnipod Insulin Management System are affected:<\/p>\n\n<p>\u2022\u00a0Product ID\/Reorder number: 19191 and 40160<br \/>\n\u2022\u00a0UDI\/Model\/NDC number: ZXP425 (10-Pack) and ZXR425 (10-Pack Canada)<\/p>\n\n<p>The Cyber Centre encourages users to review the following bulletin and apply the necessary manufacturer recommendations:<br \/><a href=\"https:\/\/www.myomnipod.com\/security-bulletins\/march-18-2020\">https:\/\/www.myomnipod.com\/security-bulletins\/march-18-2020<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-insulet-security-advisory","alert_type":398,"serial_number":"AV20-080","subject":null,"moderation_state":"published","external_url":null},{"nid":1803,"title":"[Control systems] Systech Corporation security advisory","uuid":"79b99b25-5e79-444d-8682-e113ada0e4a7","banner":null,"lang":"en","date_modified":"2020-03-20","date_modified_ts":"2020-03-20T13:31:55Z","date_created":"2020-03-20T13:31:55Z","summary":null,"body":["<article data-history-node-id=\"1803\" about=\"\/en\/alerts-advisories\/control-systems-systech-corporation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-081<br \/>\nDate: 20 March 2020<\/strong><\/p>\n\n<p>On 19 March 2020 Systech Corporation released a security update to address a vulnerability in its NDS-5000 Terminal Server (NDS-5000 Terminal Server, NDS\/5008 (8 Port, RJ45), firmware Version 02D.30). Successful exploitation of the vulnerability (a stored cross-site scripting vulnerability) could allow an actor to perform privileged operations on behalf of the user, gain access to sensitive data belonging to the user, and remotely execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<br \/>\nICS Advisory (ICSA-20-079-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-079-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-079-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-systech-corporation-security-advisory","alert_type":398,"serial_number":"AV20-081","subject":null,"moderation_state":"published","external_url":null},{"nid":1805,"title":"Font-Parsing 0-Day affecting Microsoft Windows","uuid":"42716a6f-f85e-4815-9f00-c02e71f26d34","banner":null,"lang":"en","date_modified":"2020-03-25","date_modified_ts":"2020-03-25T18:42:15Z","date_created":"2020-03-24T16:41:31Z","summary":null,"body":["<article data-history-node-id=\"1805\" about=\"\/en\/alerts-advisories\/font-parsing-0-day-affecting-microsoft-windows\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-010 \u2013 UPDATE 1<br \/>\nDate: 24 March 2020<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>UPDATE<\/h2>\n\n<p>On 24 March 2020 Microsoft updated the advisory to provide additional information. In view of existing mitigations found in Windows 10, Microsoft no longer recommends that workarounds be applied to Windows 10 systems for this vulnerability. Microsoft further clarified that the previously referenced, limited attempts to exploit the vulnerability were carried out against systems running Windows 7.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>On 23 March 2020 Microsoft disclosed an unpatched, critical vulnerability in Microsoft Windows operating systems. Microsoft further advised that they are aware of limited attempts to exploit Windows 7 systems using this vulnerability.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>Microsoft published a Security Advisory on 23 March 2020 that describes a 0-day vulnerability, comprised of a pair of critical vulnerabilities in the Adobe Type Manager Library component of Microsoft Windows operating systems. A remote actor could leverage this vulnerability to perform remote code execution. The Microsoft Security Advisory states that limited and targeted attempts to exploit this vulnerability have been observed.<\/p>\n\n<p>Remote code execution can take place when the Adobe Type Manager Library improperly handles a specially-crafted multi-master font, Adobe Type 1 PostScript format, when a document is opened by an application or previewed in Windows. There are multiple ways an actor could exploit the vulnerabilities, such as convincing a user to open a specially-crafted document or if a user views the document using the Windows Explorer Preview Pane or Details Pane. The Microsoft Outlook Preview Pane is not a vector for exploiting this vulnerability.<\/p>\n\n<h2>SUGGESTED ACTION<\/h2>\n\n<p>Microsoft has not yet released patches for this issue. The Cyber Centre recommends that organizations review the \u201cWorkarounds\u201d section of the Microsoft Security Advisory, referenced below, which lists Microsoft\u2019s suggested mitigations. Microsoft notes that these mitigations are not required for Windows 10 systems.<\/p>\n\n<p>Recommended mitigations include:<br \/>\n-\u00a0Disable the Preview Pane and Details Pane in Windows Explorer.<br \/>\n-\u00a0Disable the WebClient service.<br \/>\n-\u00a0Rename or remove the Adobe Type Manager DLL (ATMFD.DLL)<\/p>\n\n<p>The Cyber Centre further recommends monitoring the Microsoft Support website and the Cyber Centre Alerts and Advisories webpage for notification of patches becoming available.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/adv200006\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/adv200006<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the<br \/>\nCyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/font-parsing-0-day-affecting-microsoft-windows","alert_type":397,"serial_number":"AL20-010","subject":null,"moderation_state":"published","external_url":null},{"nid":1804,"title":"Adobe security advisory","uuid":"3f6621b7-8b70-4e0e-808c-bfa19453ef03","banner":null,"lang":"en","date_modified":"2020-03-25","date_modified_ts":"2020-03-25T12:33:55Z","date_created":"2020-03-25T12:33:55Z","summary":null,"body":["<article data-history-node-id=\"1804\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-082<br \/>\nDate: 25 March 2020<\/strong><\/p>\n\n<p>On 24 March 2020 Adobe released a security update to address a vulnerability affecting Adobe Creative Cloud Desktop Application for Windows. Successful exploitation of this vulnerability could lead to arbitrary file deletion.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb20-11.html\">https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb20-11.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-15","alert_type":396,"serial_number":"AV20-082","subject":null,"moderation_state":"published","external_url":null},{"nid":1806,"title":"[Control systems] VISAM security advisory","uuid":"e86d3f9b-7b91-49c0-9500-8f2e5ce14711","banner":null,"lang":"en","date_modified":"2020-03-26","date_modified_ts":"2020-03-26T14:43:35Z","date_created":"2020-03-26T14:43:35Z","summary":null,"body":["<article data-history-node-id=\"1806\" about=\"\/en\/alerts-advisories\/control-systems-visam-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-083<br \/>\nDate: 26 March 2020<\/strong><\/p>\n\n<p>On 24 March 2020 VISAM released a security update to address a vulnerability in VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module products.\u00a0 Successful exploitation of this vulnerability may allow a malicious actor to access unauthorized information, execute code, bypass security mechanisms and discover the cryptographic key for the web login.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary mitigations and manufacturer updates as they become available:<br \/>\nICS Advisory (ICSA-20-084-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-084-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-084-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-visam-security-advisory","alert_type":398,"serial_number":"AV20-083","subject":null,"moderation_state":"published","external_url":null},{"nid":1807,"title":"[Control systems] Schneider Electric security advisory","uuid":"0541dcc5-c385-4972-b5bc-72949d062eac","banner":null,"lang":"en","date_modified":"2020-03-26","date_modified_ts":"2020-03-26T14:47:32Z","date_created":"2020-03-26T14:47:32Z","summary":null,"body":["<article data-history-node-id=\"1807\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-084<br \/>\nDate: 26 March 2020<\/strong><\/p>\n\n<p>On 24 March 2020 Schneider Electric released a security update to address a vulnerability in the IGSS (Interactive Graphical SCADA System) versions 14 and prior using the IGSSupdate service.\u00a0 Successful exploitation of this vulnerability may allow a malicious actor to access sensitive data and functions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<br \/>\nICS Advisory (ICSA-20-084-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-084-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-084-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-0","alert_type":398,"serial_number":"AV20-084","subject":null,"moderation_state":"published","external_url":null},{"nid":1808,"title":"Apple security advisory","uuid":"c7af417c-6f32-4ccf-b6e6-15157616dccf","banner":null,"lang":"en","date_modified":"2020-03-26","date_modified_ts":"2020-03-26T14:51:14Z","date_created":"2020-03-26T14:51:14Z","summary":null,"body":["<article data-history-node-id=\"1808\" about=\"\/en\/alerts-advisories\/apple-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-085<br \/>\nDate: 26 March 2020<\/strong><\/p>\n\n<p>On 24 March 2020 Apple released the following updated product versions to address multiple security vulnerabilities:<br \/>\n\u2022\u00a0iTunes 12.10.5 for Windows;<br \/>\n\u2022\u00a0iOS 13.4 and iPadOS 13.4;<br \/>\n\u2022\u00a0Safari 13.1;<br \/>\n\u2022\u00a0watchOS 6.2;<br \/>\n\u2022\u00a0tvOS 13.4;<br \/>\n\u2022\u00a0macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra; and<br \/>\n\u2022\u00a0Xcode 11.4.<\/p>\n\n<p>A number of these vulnerabilities could be exploited to allow an application to execute arbitrary code with system level privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Apple security updates webpage and apply the necessary updates:<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-10","alert_type":396,"serial_number":"AV20-085","subject":null,"moderation_state":"published","external_url":null},{"nid":1809,"title":"[Control systems] Advantech security advisory","uuid":"4b91737a-5a5a-469b-b11e-fee3fff099ff","banner":null,"lang":"en","date_modified":"2020-03-26","date_modified_ts":"2020-03-26T20:04:19Z","date_created":"2020-03-26T20:04:19Z","summary":null,"body":["<article data-history-node-id=\"1809\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-086<br \/>\nDate: 26 March 2020<\/strong><\/p>\n\n<p>On 26 March 2020 Advantech released a security update to address a vulnerability in WebAccess Versions 8.4.2 and prior.\u00a0 Successful exploitation of this vulnerability may allow a malicious actor to remotely execute code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<br \/>\nICS Advisory (ICSA-20-086-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-086-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-086-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-2","alert_type":398,"serial_number":"AV20-086","subject":null,"moderation_state":"published","external_url":null},{"nid":1810,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"603f4749-d210-4689-becc-b0891f26c2a7","banner":null,"lang":"en","date_modified":"2020-04-01","date_modified_ts":"2020-04-01T13:09:21Z","date_created":"2020-04-01T13:09:21Z","summary":null,"body":["<article data-history-node-id=\"1810\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-089<br \/>\nDate: 01 April 2020<\/strong><\/p>\n\n<p>On 31 March 2020 Mitsubishi Electric published a security bulletin highlighting vulnerabilities in all versions of the following MELSEC programmable controllers with the MELSOFT transmission port (UDP\/IP):<br \/>\n\u2022\u00a0MELSEC iQ-R Series<br \/>\n\u2022\u00a0MELSEC iQ-F Series<br \/>\n\u2022\u00a0MELSEC-Q Series<br \/>\n\u2022\u00a0MELSEC-L Series<br \/>\n\u2022\u00a0MELSEC-F Series<\/p>\n\n<p>An actor can send large amounts of data to the MELSOFT transmission port of an affected MELSEC product to cause a disruption in communication.<br \/>\nThe Cyber Centre encourages users and administrators to review the following Mitsubishi Electric security bulletin for recommended mitigations.<br \/><a href=\"https:\/\/www.mitsubishielectric.com\/en\/psirt\/vulnerability\/pdf\/2019-005_en.pdf\">https:\/\/www.mitsubishielectric.com\/en\/psirt\/vulnerability\/pdf\/2019-005_en.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-1","alert_type":398,"serial_number":"AV20-089","subject":null,"moderation_state":"published","external_url":null},{"nid":1812,"title":"[Control systems] Belden security advisory","uuid":"d3e92e71-7649-4fc2-8b8b-6933b83271fa","banner":null,"lang":"en","date_modified":"2020-04-01","date_modified_ts":"2020-04-01T13:24:45Z","date_created":"2020-04-01T13:14:53Z","summary":null,"body":["<article data-history-node-id=\"1812\" about=\"\/en\/alerts-advisories\/control-systems-belden-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-088<br \/>\nDate:01 April\u00a02020<\/strong><\/p>\n\n<p>On 24 March 2020 Belden released a security bulletin to address a vulnerability affecting their HiOS and HiSecOS devices. The HTTP(S) web server of HiOS and HiSecOS devices could allow an unauthenticated, remote actor to overflow a buffer and result in the execution of arbitrary code on the target device.<\/p>\n\n<p>The following product versions are affected:<br \/>\n-\u00a0Hirschmann HiOS RSP 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS RSPE 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS RSPS 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS RSPL 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS MSP 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS EES 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS EESX 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS GRS 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS OS 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiOS RED 07.0.02 or lower<br \/>\n-\u00a0Hirschmann HiSecOS EAGLE20\/30 03.2.00 or lower<\/p>\n\n<p>The Cyber Centre encourages users to review the following bulletin and apply the necessary manufacturer recommendations:<br \/><a href=\"https:\/\/www.belden.com\/hubfs\/support\/security\/bulletins\/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf\">https:\/\/www.belden.com\/hubfs\/support\/security\/bulletins\/Belden_Security_Bulletin_BSECV-2020-01_1v2_FINAL.pdf<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-belden-security-advisory","alert_type":398,"serial_number":"AV20-088","subject":null,"moderation_state":"published","external_url":null},{"nid":1811,"title":"[Control systems] Becton, Dickinson and Company security advisory","uuid":"3eb8ece0-519c-4ad0-a819-63ab74abfb75","banner":null,"lang":"en","date_modified":"2020-04-01","date_modified_ts":"2020-04-01T13:20:11Z","date_created":"2020-04-01T13:20:11Z","summary":null,"body":["<article data-history-node-id=\"1811\" about=\"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-087<br \/>\nDate: 01 April 2020<\/strong><\/p>\n\n<p>On 31 March 2020 Becton, Dickinson and Company (BD) advised that they are in the process of deploying a security update to address a vulnerability affecting two products:<br \/>\n\u2022\u00a0Pyxis MedStation ES System, v1.6.1<br \/>\n\u2022\u00a0Pyxis Anesthesia (PAS) ES System, v1.6.1<br \/>\nA malicious actor with physical access to an affected device could exploit the vulnerability to view and\/or modify sensitive data.<\/p>\n\n<p><br \/>\nThe Cyber Centre encourages users and administrators to review the following advisory, apply the mitigation steps outlined, and apply the security update when available:<\/p>\n\n<p><br \/>\nICS Advisory (ICSMA-20-091-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-091-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-091-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-security-advisory","alert_type":398,"serial_number":"AV20-087","subject":null,"moderation_state":"published","external_url":null},{"nid":1813,"title":"Google Chrome security advisory","uuid":"0aa9e368-40af-4045-a8c2-e692ff9f451e","banner":null,"lang":"en","date_modified":"2020-04-01","date_modified_ts":"2020-04-01T17:31:40Z","date_created":"2020-04-01T17:31:40Z","summary":null,"body":["<article data-history-node-id=\"1813\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-090<br \/>\nDate: 01 April 2020<\/strong><\/p>\n\n<p>On 31 March 2020 Google announced the release of Chrome 80.0.3987.162 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/03\/stable-channel-update-for-desktop_31.html\">https:\/\/chromereleases.googleblog.com\/2020\/03\/stable-channel-update-for-desktop_31.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<br \/><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-19","alert_type":396,"serial_number":"AV20-090","subject":null,"moderation_state":"published","external_url":null},{"nid":1814,"title":"OpenWrt security advisory","uuid":"51366db4-2208-4e8e-b266-6dc8b8cdbf6c","banner":null,"lang":"en","date_modified":"2020-04-01","date_modified_ts":"2020-04-01T19:48:14Z","date_created":"2020-04-01T19:48:14Z","summary":null,"body":["<article data-history-node-id=\"1814\" about=\"\/en\/alerts-advisories\/openwrt-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-091<br \/>\nDate: 01 April 2020<\/strong><\/p>\n\n<p>On 29 January 2020 the OpenWrt Project released an update to OpenWrt, a Linux-based operating system widely deployed on embedded devices, particularly consumer-grade networking equipment. A man-in-the-middle actor could cause a user to inadvertently install a specially-crafted package on the device, which would then run with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the OpenWrt security advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/openwrt.org\/advisory\/2020-01-31-1\">https:\/\/openwrt.org\/advisory\/2020-01-31-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openwrt-security-advisory","alert_type":396,"serial_number":"AV20-091","subject":null,"moderation_state":"published","external_url":null},{"nid":1824,"title":"Considerations when using video-teleconference products and services","uuid":"3f3f7a23-29fd-4aeb-bdbb-6317917c2012","banner":null,"lang":"en","date_modified":"2020-04-14","date_modified_ts":"2020-04-14T19:42:19Z","date_created":"2020-04-03T23:28:49Z","summary":null,"body":["<article data-history-node-id=\"1824\" about=\"\/en\/alerts-advisories\/considerations-when-using-video-teleconference-products-and-services\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-011\u00a0<br \/>\nDate: 03 April 2020<\/strong><\/p>\n\n<p><strong>Amended: 14 April 2020 to expand the PRODUCT GUIDANCE section<\/strong><\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>As organizations adapt to health policy measures associated with the COVID-19 pandemic, many are increasingly using video-teleconferencing (VTC) software products to facilitate business continuity. Care should be taken in the implementation and use of these to ensure that expected levels of integrity and confidentiality are maintained.<\/p>\n\n<h2><br \/>\nDETAILS<\/h2>\n\n<p>A significant increase in adoption of VTC software solutions as a method of business continuity during the current isolation requirements mandated to slow the COVID-19 pandemic has highlighted inherent vulnerabilities in this type of software. Recent media reports have noted vulnerabilities related to third-party infiltration or hijacking of VTC sessions. This is being done in order to disrupt business or attempt to compromise computer systems through social engineering. The Cyber Centre is aware of incidents in which Canadian organizations have had VTCs infiltrated and disrupted.<\/p>\n\n<p>Incidents include unexpected infiltration and disruption (so-called Zoom-bombing) of VTCs. Such infiltration is possible when meetings are configured without password protection or a \u201cwaiting room\u201d mechanism by which participants would be positively identified and granted entry. This situation can be exacerbated by publishing links to VTCs in open forums. Individuals determined to disrupt meetings have also been using applications designed specifically to locate and attempt to join unrestricted VTCs. Beyond the obvious risk to confidentiality, infiltrations of this sort can result in reputational damage, loss of credibility, disrupted business and the need to re-establish secure communications.<\/p>\n\n<p>The use of link and file sharing in VTC applications present a set of risks similar to those present when opening links or files from emails. If a conference has been infiltrated by a malicious actor, they may be able to convince meeting participants to click on a malicious link or open an infected document file that they provide. In the case of Zoom versions prior to 1 April 2020, under certain circumstances it was possible for a user to expose Windows password information (specifically the NTLM password hash) when clicking on a UNC link in the form <a href=\"file:\/\/\\\\&lt;computer&gt;\\&lt;share\">\\\\&lt;computer&gt;\\&lt;share<\/a>&gt;. This vulnerability has been patched in the latest version of Zoom.<\/p>\n\n<p>The Cyber Centre advises that organizations using (or planning to use) VTCs take the time to understand their associated risks and limitations, which usually can be managed by following general best practices and provider-specific guidance.<\/p>\n\n<h2><br \/>\nMITIGATIONS AND GUIDANCE<\/h2>\n\n<p><br \/>\nTreat remote work like you would treat the office in terms of security, and VTCs like you would treat an office meeting. The following practices are recommended:<\/p>\n\n<p>-\u00a0Use existing corporate solutions whenever possible.<\/p>\n\n<p>-\u00a0Choose a platform with appropriate security features. Factors to consider include the level of encryption, the ability to require passwords or other methods of authentication in order to join a VTC, etc.<\/p>\n\n<p>-\u00a0Set rules and expectations concerning the types of discussions that may take place on a given platform. (As an example, for Government of Canada users, classified material should never be shared on an unclassified network.)<\/p>\n\n<p>-\u00a0Use the right tool for the job. Don't be afraid to send sensitive documents via courier or secure email rather than sending them over a VTC shared files channel.<\/p>\n\n<p>-\u00a0Ensure that VTC organizers are aware of the security features available in the VTC software package and that they are used appropriately. For example: Keep meetings private by requiring a password for entry. If for some reason that is not feasible, control guest access from a waiting room, just like how we let visitors into our buildings: by having them registered and escorted.<\/p>\n\n<p><br \/>\n-\u00a0Ensure all parties using the VTC software are aware of and comfortable with any data sharing done by the software owner in order to realize a profit (i.e. Selling data analytics for marketing purposes.)<\/p>\n\n<p>-\u00a0Choose a solution that allows you to control how your data is handled. Some platforms may route data outside Canada or store shared data on servers they control.<\/p>\n\n<p>-\u00a0Do not post links or teleconference IDs in unmanaged or public forums.<\/p>\n\n<p>-\u00a0Consider using a solution that does not require participants to install a client unless necessary. Web versions of a VTC obviate the need to update client software.<\/p>\n\n<p>-\u00a0Patch all software to latest version. Always.<\/p>\n\n<h2><br \/>\nPRODUCT GUIDANCE<\/h2>\n\n<p>While the above practices are applicable to VTC products and services generally, Cyber Centre advice and guidance should always be evaluated and applied to an organization\u2019s unique cyber security context. The Cyber Centre does not make recommendations for or against specific products or services. For convenience, we have included below a non-exhaustive sampling of provider-supplied guidance for several well-known VTC products. Other VTC products may provide similar guidance.<\/p>\n\n<p><strong>Google Hangouts<\/strong><\/p>\n\n<p>Set up Meet to enable remote working for your organization:<br \/><a href=\"https:\/\/support.google.com\/a\/answer\/9784650?hl=en&amp;ref_topic=9784759\">https:\/\/support.google.com\/a\/answer\/9784650?hl=en&amp;ref_topic=9784759<\/a><\/p>\n\n<p><br \/><strong>Slack<\/strong><\/p>\n\n<p>Basic security tips for Slack workspace administrators: <a href=\"https:\/\/slack.com\/intl\/en-ca\/help\/articles\/115004155306-Security-tips-to-protect-your-workspace\">https:\/\/slack.com\/intl\/en-ca\/help\/articles\/115004155306-Security-tips-to-protect-your-workspace<\/a><\/p>\n\n<p>Best practices on security for users building internal Slack apps: <a href=\"https:\/\/api.slack.com\/authentication\/best-practices\">https:\/\/api.slack.com\/authentication\/best-practices<\/a><\/p>\n\n<p><br \/><strong>Microsoft Teams<\/strong><\/p>\n\n<p>Describes Teams\u2019 security features and how its security architecture holds up against different types of cyber-attacks:<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/teams-security-guide\">https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/teams-security-guide<\/a><\/p>\n\n<p><br \/><strong>Cisco Webex<\/strong><\/p>\n\n<p>Provides an overview of security best practices to employ before, during and at the conclusion of a Webex meeting:<br \/><a href=\"https:\/\/help.webex.com\/en-us\/8zi8tq\/Cisco-Webex-Best-Practices-for-Secure-Meetings-Hosts\">https:\/\/help.webex.com\/en-us\/8zi8tq\/Cisco-Webex-Best-Practices-for-Secure-Meetings-Hosts<\/a><\/p>\n\n<p><br \/><strong>Zoom<\/strong><\/p>\n\n<p>Some ways to manage attendee access for a Zoom meeting: <a href=\"https:\/\/blog.zoom.us\/wordpress\/2020\/03\/20\/keep-uninvited-guests-out-of-your-zoom-event\/\">https:\/\/blog.zoom.us\/wordpress\/2020\/03\/20\/keep-uninvited-guests-out-of-your-zoom-event\/<\/a><\/p>\n\n<p>Further information on how to use the waiting room feature in Zoom (this is beneficial for those hosting interviews): <a href=\"https:\/\/blog.zoom.us\/wordpress\/2020\/02\/14\/secure-your-meetings-zoom-waiting-rooms\/\">https:\/\/blog.zoom.us\/wordpress\/2020\/02\/14\/secure-your-meetings-zoom-waiting-rooms\/<\/a><\/p>\n\n<p>Additional information on securing your Zoom meeting, including password protection:<br \/><a href=\"https:\/\/blog.zoom.us\/wordpress\/2019\/12\/04\/hosts-admins-secure-zoom-meeting-experience\/?zcid=1231\">https:\/\/blog.zoom.us\/wordpress\/2019\/12\/04\/hosts-admins-secure-zoom-meeting-experience\/?zcid=1231<\/a><\/p>\n\n<p>The Cyber Centre recommends updating Zoom to the latest version before using Zoom. The current version patches multiple known vulnerabilities, including two local privilege escalation vulnerabilities in OSX version of Zoom software, one of which could give the user root access to the local computer.<\/p>\n\n<p><br \/><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\nThe Cyber Centre can be contacted at:<br \/>\nEmail: <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a><br \/>\nToll Free: <a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> <a href=\"tel:+1-833-292-3788\">(1-833-292-3788)<\/a><\/p>\n\n<p>\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/considerations-when-using-video-teleconference-products-and-services","alert_type":397,"serial_number":"AL20-011 ","subject":null,"moderation_state":"published","external_url":null},{"nid":1815,"title":"Mozilla security advisory","uuid":"c0b82e84-1b61-4d93-8fff-73d71ce02297","banner":null,"lang":"en","date_modified":"2020-04-06","date_modified_ts":"2020-04-06T16:55:06Z","date_created":"2020-04-06T14:41:15Z","summary":null,"body":["<article data-history-node-id=\"1815\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-093<br \/>\nDate: 06 April 2020<\/strong><\/p>\n\n<p>On 3 April 2020 Mozilla released Firefox 74.0.1 and Firefox ESR 68.6.1 to address critical vulnerabilities in the Windows, macOS and Linux versions of Firefox. Under certain circumstances, a remote actor could exploit these vulnerabilities to take control of an affected system. In a Security Advisory, Mozilla stated that it is aware of targeted exploitation of the vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-12","alert_type":396,"serial_number":"AV20-093","subject":null,"moderation_state":"published","external_url":null},{"nid":1816,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"be806089-d03a-43e3-a049-ea23cb586f7f","banner":null,"lang":"en","date_modified":"2020-04-06","date_modified_ts":"2020-04-06T17:09:15Z","date_created":"2020-04-06T17:05:28Z","summary":null,"body":["<article data-history-node-id=\"1816\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-092<br \/>\nDate: 06 April 2020<\/strong><\/p>\n\n<p>On 2 April 2020 B&amp;R Industrial Automation published a security bulletin highlighting vulnerabilities affecting the following versions of Automation Studio:<\/p>\n\n<p>\u2022\u00a0Automation Studio, Versions 4.0.x<br \/>\n\u2022\u00a0Automation Studio, Versions 4.1.x<br \/>\n\u2022\u00a0Automation Studio, Versions 4.2.x<br \/>\n\u2022\u00a0Automation Studio, versions prior to 4.3.11SP<br \/>\n\u2022\u00a0Automation Studio, versions prior to 4.4.9SP<br \/>\n\u2022\u00a0Automation Studio, versions prior to 4.5.4SP<br \/>\n\u2022\u00a0Automation Studio, versions prior to 4.6.3SP<br \/>\n\u2022\u00a0Automation Studio, versions prior to 4.7.2<br \/>\n\u2022\u00a0Automation Studio, versions prior to 4.8.1<\/p>\n\n<p>Successful exploitation of these vulnerabilities could allow an actor to read, write or delete arbitrary files from the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following security bulletin for recommended mitigations and apply the necessary manufacture updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-093-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-093-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-093-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-0","alert_type":398,"serial_number":"AV20-092","subject":null,"moderation_state":"published","external_url":null},{"nid":1817,"title":"Android security advisory","uuid":"32dd292c-8cc0-4c52-b333-9aea8972f5bf","banner":null,"lang":"en","date_modified":"2020-04-07","date_modified_ts":"2020-04-07T17:48:45Z","date_created":"2020-04-07T17:48:45Z","summary":null,"body":["<article data-history-node-id=\"1817\" about=\"\/en\/alerts-advisories\/android-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-094<br \/>\nDate: 07 April 2020<\/strong><\/p>\n\n<p>On 6 April 2020 Android published a Security Bulletin to address multiple vulnerabilities affecting Android devices. A remote actor could exploit some of these vulnerabilities to execute arbitrary code within the context of a privileged process or to gain access to additional permissions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Android Security Bulletin and apply the necessary updates, when available:<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-04-01\">https:\/\/source.android.com\/security\/bulletin\/2020-04-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-11","alert_type":396,"serial_number":"AV20-094","subject":null,"moderation_state":"published","external_url":null},{"nid":1818,"title":"[Control systems] Fuji Electric security advisory","uuid":"b47316b6-b93a-4fb9-a829-4d34cfe44066","banner":null,"lang":"en","date_modified":"2020-04-08","date_modified_ts":"2020-04-08T13:38:46Z","date_created":"2020-04-08T13:38:46Z","summary":null,"body":["<article data-history-node-id=\"1818\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-095<br \/>\nDate: 08 April 2020<\/strong><\/p>\n\n<p>On 7 April 2020 ICS-CERT published a security bulletin highlighting a heap-based buffer overflow vulnerability in Fuji Electric V-Server Lite (all versions prior to 4.0.9.0). Successful exploitation of this vulnerability could allow a remote actor to gain elevated privileges for remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer update:<\/p>\n\n<p>ICS Advisory (ICSA-20-098-04)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-04\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-1","alert_type":398,"serial_number":"AV20-095","subject":null,"moderation_state":"published","external_url":null},{"nid":1819,"title":"[Control systems] HMS Networks security advisory","uuid":"5d0bafc4-eb31-4456-a30c-0dfedb8da67a","banner":null,"lang":"en","date_modified":"2020-04-08","date_modified_ts":"2020-04-08T13:41:01Z","date_created":"2020-04-08T13:41:01Z","summary":null,"body":["<article data-history-node-id=\"1819\" about=\"\/en\/alerts-advisories\/control-systems-hms-networks-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-096<br \/>\nDate: 08 April 2020<\/strong><\/p>\n\n<p>On 6 February 2020 HMS Networks released firmware version 14.1s0 to fix a non-persistent cross-site scripting vulnerability which could initiate a password change for the affected device. The following Ewon products are affected:<\/p>\n\n<p>\u2022\u00a0Ewon Flexy: All firmware versions prior to 14.1s0<br \/>\n\u2022\u00a0Ewon Cosy: All firmware versions prior to 14.1s0<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following security bulletin for recommended mitigations and apply the necessary manufacture updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-098-03)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-03<\/a><\/p>\n\n<p>Ewon Firmware Release Notes<br \/><a href=\"https:\/\/ewon.biz\/technical-support\/pages\/firmware\">https:\/\/ewon.biz\/technical-support\/pages\/firmware<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hms-networks-security-advisory","alert_type":398,"serial_number":"AV20-096","subject":null,"moderation_state":"published","external_url":null},{"nid":1820,"title":"[Control systems] Advantech security advisory","uuid":"fa2e9c2b-3b96-43f5-b454-5c21105778ad","banner":null,"lang":"en","date_modified":"2020-04-08","date_modified_ts":"2020-04-08T13:44:31Z","date_created":"2020-04-08T13:43:21Z","summary":null,"body":["<article data-history-node-id=\"1820\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-097<br \/>\nDate: 08 April 2020<\/strong><\/p>\n\n<p>On 7 April 2020 ICS-CERT published a security bulletin highlighting several vulnerabilities in all Advantech WebAccess\/NMS (Network Management System) versions prior to 3.0.2.<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow an actor to gain remote code execution, upload files, delete files, cause a denial-of-service condition, and create an admin account for the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following security bulletin for recommended mitigations and apply the necessary manufacture updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-098-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-3","alert_type":398,"serial_number":"AV20-097","subject":null,"moderation_state":"published","external_url":null},{"nid":1821,"title":"[Control systems] GE Digital security advisory","uuid":"3c951004-0d19-41ee-86b3-3a6d47809247","banner":null,"lang":"en","date_modified":"2020-04-08","date_modified_ts":"2020-04-08T13:45:32Z","date_created":"2020-04-08T13:45:32Z","summary":null,"body":["<article data-history-node-id=\"1821\" about=\"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-098<br \/>\nDate: 08 April 2020<\/strong><\/p>\n\n<p>On 7 April 2020 ICS-CERT published a security bulletin to address a vulnerability affecting the GE Digital CIMPLICITY HMI\/SCADA product version 10.0 and prior. The vulnerability could allow a local, authenticated actor to escalate privileges and, in turn, execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following ICS-CERT bulletin and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSMA-20-098-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-098-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory","alert_type":398,"serial_number":"AV20-098","subject":null,"moderation_state":"published","external_url":null},{"nid":1822,"title":"Mozilla security advisory","uuid":"c5b2e75d-019e-47fa-9a0d-0744af82eb86","banner":null,"lang":"en","date_modified":"2020-04-09","date_modified_ts":"2020-04-09T12:56:32Z","date_created":"2020-04-09T12:56:32Z","summary":null,"body":["<article data-history-node-id=\"1822\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-099<br \/>\nDate: 09 April 2020<\/strong><\/p>\n\n<p>On 7 April 2020 Mozilla released Firefox 75 and Firefox ESR 68.7 to address various vulnerabilities. In one case, the absence of memory initialisation when a specific WebGL method is used, could lead to potentially sensitive data disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Mozilla Foundation Security Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-13","alert_type":396,"serial_number":"AV20-099","subject":null,"moderation_state":"published","external_url":null},{"nid":1823,"title":"Google Chrome security advisory","uuid":"457a336b-a82a-4ae0-8eea-856933659459","banner":null,"lang":"en","date_modified":"2020-04-09","date_modified_ts":"2020-04-09T12:59:41Z","date_created":"2020-04-09T12:59:41Z","summary":null,"body":["<article data-history-node-id=\"1823\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-100<br \/>\nDate: 09 April 2020<\/strong><\/p>\n\n<p>On 7 April 2020 Google announced the release of Chrome 81.0.4044.92 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_7.html\">https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_7.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<br \/><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-20","alert_type":396,"serial_number":"AV20-100","subject":null,"moderation_state":"published","external_url":null},{"nid":1825,"title":"Juniper Networks security advisory","uuid":"316f042c-a98c-44e2-a795-189feff5e3d3","banner":null,"lang":"en","date_modified":"2020-04-14","date_modified_ts":"2020-04-14T16:39:37Z","date_created":"2020-04-14T16:39:37Z","summary":null,"body":["<article data-history-node-id=\"1825\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-101<br \/>\nDate: 14 April 2020<\/strong><\/p>\n\n<p>On 9 April 2020 Juniper Networks released several security bulletins to address vulnerabilities affecting multiple networking products. Of note are bulletins JSA10997 regarding NFX250 Series devices and JSA10998 regarding the Junos OS. Both contain known, default credentials that can be utilized by an external actor to gain unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Juniper Networks Security Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-4","alert_type":396,"serial_number":"AV20-101","subject":null,"moderation_state":"published","external_url":null},{"nid":1826,"title":"Palo Alto Networks security advisory","uuid":"a4145649-56ea-40c7-96d1-93c24b8bfd5b","banner":null,"lang":"en","date_modified":"2020-04-14","date_modified_ts":"2020-04-14T20:05:41Z","date_created":"2020-04-14T20:05:41Z","summary":null,"body":["<article data-history-node-id=\"1826\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-102<br \/>\nDate: 14 April 2020<\/strong><\/p>\n\n<p>On 8 April 2020 Palo Alto Networks released security updates to address vulnerabilities in the following products:<br \/>\n\u2022\u00a0Palo Alto Networks PAN-OS PA-7000 series<br \/>\n\u2022\u00a0Palo Alto Networks PAN-OS 7.x<br \/>\n\u2022\u00a0Palo Alto Networks PAN-OS 8.x<br \/>\n\u2022\u00a0Palo Alto Networks PAN-OS 8.1.x<br \/>\n\u2022\u00a0Secdo all Windows versions<br \/>\n\u2022\u00a0Palo Alto Networks Traps versions 5.x for Windows<br \/>\n\u2022\u00a0Palo Alto Networks Traps versions 6.x for Windows<br \/>\n\u2022\u00a0Palo Alto Networks GlobalProtect Agent versions 5.x<br \/>\n\u2022\u00a0Palo Alto Networks GlobalProtect Agent versions 6.1.x<br \/>\n\u2022\u00a0Palo Alto Networks GlobalProtect Agent for Windows versions 4.1.x<br \/>\n\u2022\u00a0Palo Alto Networks VM Series firewalls for Microsoft Azure versions 1.0.8 and below<\/p>\n\n<p>Successful exploitation of these vulnerabilities by a remote actor could lead to the execution of arbitrary code, a denial of service condition or to allow bypassing security mechanisms.\u00a0<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Palo Alto Security Bulletins and Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-1","alert_type":396,"serial_number":"AV20-102","subject":null,"moderation_state":"published","external_url":null},{"nid":1827,"title":"[Control systems] Rockwell Automation security advisory","uuid":"e447652c-5864-4c29-823b-ee7226731a0b","banner":null,"lang":"en","date_modified":"2020-04-14","date_modified_ts":"2020-04-14T20:07:20Z","date_created":"2020-04-14T20:07:20Z","summary":null,"body":["<article data-history-node-id=\"1827\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-103<br \/>\nDate: 14 April 2020<\/strong><\/p>\n\n<p>On 9 April 2020 Rockwell Automation released security updates to address a vulnerability in the RSLinx (Versions 4.11.00 and prior) PLC communications software.\u00a0 Successful exploitation of this vulnerability may allow a malicious actor to execute code using system privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following advisory and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-100-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-100-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-100-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-2","alert_type":398,"serial_number":"AV20-103","subject":null,"moderation_state":"published","external_url":null},{"nid":1828,"title":"VMware security advisory","uuid":"c6345c99-2067-4be3-be2b-b655aedcd0e5","banner":null,"lang":"en","date_modified":"2020-04-15","date_modified_ts":"2020-04-15T12:57:23Z","date_created":"2020-04-15T12:57:23Z","summary":null,"body":["<article data-history-node-id=\"1828\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-105<br \/>\nDate: 15 April 2020<\/strong><\/p>\n\n<p>On 09 April 2020 VMware released a security advisory to address a critical vulnerability, tracked as CVE-2020-3952, affecting VMware vCenter Server. Successful exploitation could lead to disclosure of highly sensitive information which could be used to compromise vCenter Server or other services which are dependent upon the VMware Directory Service for authentication.<\/p>\n\n<p>VMware has created a KB article to aid in identification of vulnerable vCenter deployments. vCenter Server 6.7 (embedded or external PSC) prior to 6.7u3f is vulnerable if it was upgraded from a previous release line such as 6.0 or 6.5.<\/p>\n\n<p>The Cyber Centre encourages users to review the following VMware publications and apply the necessary update:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0006.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0006.html<\/a><br \/>\n\u00a0<br \/>\nVMware KB78543:<\/p>\n\n<p><a href=\"https:\/\/kb.vmware.com\/s\/article\/78543\">https:\/\/kb.vmware.com\/s\/article\/78543<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-25","alert_type":396,"serial_number":"AV20-105","subject":null,"moderation_state":"published","external_url":null},{"nid":1829,"title":"Microsoft security advisory \u2013 April 2020 monthly rollup","uuid":"fb0c3002-66c2-469d-991b-d94aa0c6c3f8","banner":null,"lang":"en","date_modified":"2020-04-15","date_modified_ts":"2020-04-15T14:50:20Z","date_created":"2020-04-15T13:00:43Z","summary":null,"body":["<article data-history-node-id=\"1829\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-104<br \/>\nDate: 15 April 2020<\/strong><\/p>\n\n<p>On 14 April 2020 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. This rollup provides fixes for 19 critical vulnerabilities.Of note are a pair of previously reported critical remote code execution vulnerabilities found in the Adobe Type Manager Library component of Microsoft Windows operating systems. These vulnerabilities, tracked as CVE-2020-0938 and CVE-2020-1020, have been patched as part of this rollup.<\/p>\n\n<p>Also of note is a critical remote code execution vulnerability, tracked as CVE-2020-0968, which exists in the way that the scripting engine handles objects in memory in Internet Explorer. Successful exploitation could allow an actor to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft April 2020 Security Updates webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Apr\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Apr<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-april-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-104","subject":null,"moderation_state":"published","external_url":null},{"nid":1830,"title":"[Control systems] Eaton security advisory","uuid":"428d235e-b756-444a-990f-4e46ce3cf324","banner":null,"lang":"en","date_modified":"2020-04-15","date_modified_ts":"2020-04-15T15:15:43Z","date_created":"2020-04-15T15:15:43Z","summary":null,"body":["<article data-history-node-id=\"1830\" about=\"\/en\/alerts-advisories\/control-systems-eaton-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-106<br \/>\nDate: 15 April 2020<\/strong><\/p>\n\n<p>On 14 April 2020 ICS-CERT released a security bulletin to address vulnerabilities affecting the Eaton HMiSoft VU3 version 3.00.23 and prior. Successful exploitation of these vulnerabilities could allow an actor to crash the device and may also allow for remote code execution or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users to review the following bulletin and apply the necessary manufacturer recommendations:<\/p>\n\n<p>ICS Advisory (ICSMA-20-105-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-105-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-105-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-eaton-security-advisory","alert_type":398,"serial_number":"AV20-106","subject":null,"moderation_state":"published","external_url":null},{"nid":1831,"title":"[Control systems] Triangle MicroWorks security advisory","uuid":"52c878ac-65e8-455f-8641-40bba9435dc7","banner":null,"lang":"en","date_modified":"2020-04-15","date_modified_ts":"2020-04-15T15:23:14Z","date_created":"2020-04-15T15:23:14Z","summary":null,"body":["<article data-history-node-id=\"1831\" about=\"\/en\/alerts-advisories\/control-systems-triangle-microworks-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-107<br \/>\nDate: 15 April 2020<\/strong><\/p>\n\n<p>On 14 April 2020 ICS-CERT published security bulletins highlighting several vulnerabilities in Triangle MicroWorks products. Successful exploitation of some of these vulnerabilities could allow a remote actor to execute arbitrary code on an affected device.<br \/>\n\u00a0<br \/>\nThe Cyber Centre encourages users and administrators to review the following ICS-CERT security bulletins and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSMA-20-105-02)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-105-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-105-02<\/a><\/p>\n\n<p>ICS Advisory (ICSMA-20-105-03)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-105-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-105-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-triangle-microworks-security-advisory","alert_type":398,"serial_number":"AV20-107","subject":null,"moderation_state":"published","external_url":null},{"nid":1832,"title":"Intel security advisory","uuid":"ecea140f-da7f-4893-a898-959a2c20389a","banner":null,"lang":"en","date_modified":"2020-04-15","date_modified_ts":"2020-04-15T15:41:09Z","date_created":"2020-04-15T15:41:09Z","summary":null,"body":["<article data-history-node-id=\"1832\" about=\"\/en\/alerts-advisories\/intel-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-108<br \/>\nDate: 15 April 2020<\/strong><\/p>\n\n<p>On 14 April 2020 Intel released security updates to address vulnerabilities affecting several Intel products. Of note is a security vulnerability in Intel NUC firmware which may allow an authenticated actor to enable escalation of privilege via local access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Intel Product Security Center Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-11","alert_type":396,"serial_number":"AV20-108","subject":null,"moderation_state":"published","external_url":null},{"nid":1833,"title":"[Control systems] Siemens security advisory","uuid":"a8e5c8cb-2de6-4eb5-965e-d68cba8b34cc","banner":null,"lang":"en","date_modified":"2020-04-15","date_modified_ts":"2020-04-15T17:53:06Z","date_created":"2020-04-15T17:53:06Z","summary":null,"body":["<article data-history-node-id=\"1833\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-109<br \/>\nDate: 15 April 2020<\/strong><\/p>\n\n<p>On 14 April 2020 Siemens published security bulletins to address vulnerabilities in multiple products. Successful exploitation of these vulnerbailities could allow an unauthenticated remote actor to execute arbitrary JavaScript code, affect the availability or gain full control over an affected device.\u00a0 Additionally a local actor could modify the IP address of an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Siemens Security Advisories and apply the necessary updates:<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-886514.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-886514.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-593272.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-593272.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-377115.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-377115.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-359303.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-359303.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-162506.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-162506.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-102233.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-102233.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-8","alert_type":398,"serial_number":"AV20-109","subject":null,"moderation_state":"published","external_url":null},{"nid":1834,"title":"SAP security advisory ","uuid":"955050d5-68b9-43cb-97fb-d3defa4c5b26","banner":null,"lang":"en","date_modified":"2020-04-16","date_modified_ts":"2020-04-16T15:35:21Z","date_created":"2020-04-16T15:35:21Z","summary":null,"body":["<article data-history-node-id=\"1834\" about=\"\/en\/alerts-advisories\/sap-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-110<br \/>\nDate: 16 April 2020<\/strong><\/p>\n\n<p>On 15 April 2020 SAP released security updates to address vulnerabilities affecting several of its products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following SAP webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=544214202\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=544214202<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-4","alert_type":396,"serial_number":"AV20-110","subject":null,"moderation_state":"published","external_url":null},{"nid":1835,"title":"Adobe security advisory","uuid":"eea7460e-3bef-428b-9240-0a61b41f3505","banner":null,"lang":"en","date_modified":"2020-04-16","date_modified_ts":"2020-04-16T17:06:44Z","date_created":"2020-04-16T17:06:44Z","summary":null,"body":["<article data-history-node-id=\"1835\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-111<br \/>\nDate: 16 April 2020<\/strong><\/p>\n\n<p>On 14 April 2020 Adobe released security updates to address vulnerabilities affecting several of its products. Some of these vulnerabilities could lead to information disclosure, privilege escalation or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-16","alert_type":396,"serial_number":"AV20-111","subject":null,"moderation_state":"published","external_url":null},{"nid":1836,"title":"Oracle security advisory \u2013 April 2020 Critical Patch update","uuid":"0dbc5b61-816d-4edc-b68d-917b513cfa5d","banner":null,"lang":"en","date_modified":"2020-04-16","date_modified_ts":"2020-04-16T17:28:30Z","date_created":"2020-04-16T17:09:27Z","summary":null,"body":["<article data-history-node-id=\"1836\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-april-2020-critical-patch-update\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-112<br \/>\nDate: 16 April 2020<\/strong><\/p>\n\n<p>On 14 April 2020 Oracle released their Critical Patch Update containing 397 security fixes affecting various Oracle products. A remote, unauthenticated actor could exploit some of these vulnerabilities to take control of an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following Oracle Critical Patch Update Advisory and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2020.html\">https:\/\/www.oracle.com\/security-alerts\/cpuapr2020.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-april-2020-critical-patch-update","alert_type":396,"serial_number":"AV20-112","subject":null,"moderation_state":"published","external_url":null},{"nid":1837,"title":"Cisco security advisory","uuid":"26ae3d9e-3506-4c2e-a2ed-47f65a7d64ef","banner":null,"lang":"en","date_modified":"2020-04-16","date_modified_ts":"2020-04-16T17:57:47Z","date_created":"2020-04-16T17:57:47Z","summary":null,"body":["<article data-history-node-id=\"1837\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-46\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-113<br \/>\nDate: 16 April 2020<\/strong><\/p>\n\n<p>On 15 April 2020 Cisco released security updates to address vulnerabilities affecting several Cisco products. Of note is a security vulnerability in certain Cisco IP phone products. A vulnerability in the web server for these phones could allow an unauthenticated, remote actor to execute code with root privileges or cause a denial of service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Cisco Security Advisories webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-46","alert_type":396,"serial_number":"AV20-113","subject":null,"moderation_state":"published","external_url":null},{"nid":1838,"title":"Google Chrome security advisory","uuid":"dfb0d6a5-160d-42f0-b6b8-416d7cd1a1e2","banner":null,"lang":"en","date_modified":"2020-04-16","date_modified_ts":"2020-04-16T18:02:49Z","date_created":"2020-04-16T18:02:49Z","summary":null,"body":["<article data-history-node-id=\"1838\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-114<br \/>\nDate: 16 April 2020<\/strong><\/p>\n\n<p>On 15 April 2020 Google announced the release of Chrome 81.0.4044.113 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_15.html\">https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_15.html<\/a><br \/>\n\u00a0<br \/>\nFor the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-21","alert_type":396,"serial_number":"AV20-114","subject":null,"moderation_state":"published","external_url":null},{"nid":1839,"title":"Continued threat actor exploitation post Pulse Secure VPN patching (CISA)","uuid":"f3d5b88f-bca2-471a-befd-97acc7fecb37","banner":null,"lang":"en","date_modified":"2020-04-17","date_modified_ts":"2020-04-17T12:43:48Z","date_created":"2020-04-17T12:39:47Z","summary":null,"body":["<article data-history-node-id=\"1839\" about=\"\/en\/alerts-advisories\/continued-threat-actor-exploitation-post-pulse-secure-vpn-patching-cisa\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-012\n  <br \/>\n  Date: 16 April 2020<\/strong>\n<\/p>\n<h2>ASSESSMENT\n<\/h2>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA), the United States\u2019 agency responsible for protecting its critical infrastructure from physical and cyber threats, has produced an update to its January 2020 Alert regarding CVE-2019-11510, an arbitrary file reading vulnerability affecting Pulse Secure virtual private network (VPN) appliances. The Cyber Centre would like to highlight the updated Alert, as it provides important new information to system owners and operators responsible for defending their systems and networks from cyber threats. The Cyber Centre previously reported on this vulnerability in September 2019; the updated CISA Alert contains additional information describing post-compromise activity, related IOCs, and a detection tool.\n<\/p>\n<p>The CISA Alert(AA20-107A) can be found at:\n  <br \/>\n  \u00a0\n  <br \/><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/aa20-107a\">https:\/\/www.us-cert.gov\/ncas\/alerts\/aa20-107a<\/a>\n<\/p>\n<p>Should activity matching the content of either of these Alerts be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>Initial CISA Alert on Pulse Secure VPN vulnerability (AA20-010A):\n<\/p>\n<p><a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/aa20-010a\">https:\/\/www.us-cert.gov\/ncas\/alerts\/aa20-010a<\/a>\n<\/p>\n<p>Vulnerabilities exploited in VPN products used worldwide (NCSC Alert):\n<\/p>\n<p><a href=\"\/en\/alerts-advisories\/vulnerabilities-exploited-vpn-products-used-worldwide-ncsc-alert\">https:\/\/cyber.gc.ca\/en\/alerts-advisories\/vulnerabilities-exploited-vpn-products-used-worldwide-ncsc-alert<\/a>\n  <br \/>\n  \u00a0\n  <br \/>\n  Cyber Centre Alert on Active Exploitation of VPN Vulnerabilities (AL19-016):\n<\/p>\n<p><a href=\"\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities-0\">https:\/\/cyber.gc.ca\/en\/alerts-advisories\/active-exploitation-vpn-vulnerabilities-0<\/a>\n<\/p>\n<p>\n  <br \/><strong>NOTE TO READERS<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/continued-threat-actor-exploitation-post-pulse-secure-vpn-patching-cisa","alert_type":397,"serial_number":"AL20-012","subject":null,"moderation_state":"published","external_url":null},{"nid":1840,"title":"Foxit security advisory","uuid":"092a08d7-fc5a-41fa-908b-5efbb22210d1","banner":null,"lang":"en","date_modified":"2020-04-21","date_modified_ts":"2020-04-21T14:55:42Z","date_created":"2020-04-21T14:55:42Z","summary":null,"body":["<article data-history-node-id=\"1840\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-115<br \/>\nDate:\u00a021 April 2020<\/strong><\/p>\n\n<p>On 16 April 2020 Foxit released version 9.7.2 of Foxit Reader and Foxit PhantomPDF to address several issues in version 9.7.1.29511 and earlier. Vulnerable versions of these packages are exploitable via a specially-crafted .PDF file, potentially allowing an actor to run code of their choice.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Foxit Security Bulletin and apply the necessary update:<\/p>\n\n<p><a href=\"https:\/\/www.foxitsoftware.com\/support\/security-bulletins.php\">https:\/\/www.foxitsoftware.com\/support\/security-bulletins.php<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-0","alert_type":396,"serial_number":"AV20-115","subject":null,"moderation_state":"published","external_url":null},{"nid":1841,"title":"Google Chrome security advisory","uuid":"268c98b3-cea6-440d-b32b-d1351a54ae8f","banner":null,"lang":"en","date_modified":"2020-04-23","date_modified_ts":"2020-04-23T12:22:45Z","date_created":"2020-04-23T12:18:03Z","summary":null,"body":["<article data-history-node-id=\"1841\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-116<br \/>\nDate: 23 April 2020<\/strong><\/p>\n\n<p>On 21 April 2020 Google announced the release of Chrome 81.0.4044.122 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_21.html\">https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_21.html<\/a>\u00a0<\/p>\n\n<p><br \/>\nFor the latest version of Chrome:<br \/><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-22","alert_type":396,"serial_number":"AV20-116","subject":null,"moderation_state":"published","external_url":null},{"nid":1842,"title":"Microsoft security advisory","uuid":"a6a11eb6-f187-4f37-a3ac-d983dc662f20","banner":null,"lang":"en","date_modified":"2020-04-23","date_modified_ts":"2020-04-23T15:05:05Z","date_created":"2020-04-23T15:05:05Z","summary":null,"body":["<article data-history-node-id=\"1842\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-117<br \/>\nDate: 23 April 2020<\/strong><\/p>\n\n<p>On 21 April 2020 Microsoft released a security advisory to address multiple vulnerabilities found in the Autodesk FBX library which is integrated into certain Microsoft applications.<\/p>\n\n<p>These vulnerabilities could be exploited by convincing a user to open a specially crafted file. Successful exploitation could lead to remote code execution with the same user rights as the local user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Microsoft Security Advisory and apply the necessary updates:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV200004\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV200004<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-5","alert_type":396,"serial_number":"AV20-117","subject":null,"moderation_state":"published","external_url":null},{"nid":1843,"title":"IBM security advisory","uuid":"73864102-9f3d-4f44-9df9-f56346ad68c6","banner":null,"lang":"en","date_modified":"2020-04-23","date_modified_ts":"2020-04-23T15:22:05Z","date_created":"2020-04-23T15:11:28Z","summary":null,"body":["<article data-history-node-id=\"1843\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-118<br \/>\nDate: 23 April 2020<\/strong><\/p>\n\n<p>On 21 April 2020 IBM released a security advisory to address reports of multiple zero-day vulnerabilities affecting IBM Data Risk Manager versions 2.0.1 to 2.0.3. These reported zero-day vulnerabilities had been published via GitHub earlier in the day and contained information on four vulnerabilities.<\/p>\n\n<p>IBM has identified that the Insecure Default Password is a known configuration and recommends it be reset as per the installation documentation.<\/p>\n\n<p>In addition, the following two vulnerabilities were previously identified and were addressed in version 2.0.4:<\/p>\n\n<p>-\u00a0Command Injection vulnerability affecting versions 2.0.1 to 2.0.3.<br \/>\n-\u00a0Arbitrary File Download vulnerability affecting versions 2.0.2 and 2.0.3.<\/p>\n\n<p>The final vulnerability, Authentication Bypass, is currently being investigated by IBM.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following IBM webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6195705\">https:\/\/www.ibm.com\/support\/pages\/node\/6195705<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-0","alert_type":396,"serial_number":"AV20-118","subject":null,"moderation_state":"published","external_url":null},{"nid":1844,"title":"[Control systems] Inductive Automation security advisory","uuid":"1eb93416-d029-436e-997f-b92dd22e58fa","banner":null,"lang":"en","date_modified":"2020-04-24","date_modified_ts":"2020-04-24T12:10:41Z","date_created":"2020-04-24T12:10:41Z","summary":null,"body":["<article data-history-node-id=\"1844\" about=\"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-119<br \/>\nDate: 24 April 2020<\/strong><\/p>\n\n<p>On 21 April 2020 US-CERT published a security bulletin to address an improper access control vulnerability in Inductive Automation\u2019s Ignition 8 Gateway product. Successful exploitation of this vulnerability could allow an unauthenticated remote actor to write endless log statements onto an affected device; consuming all available hard drive space and causing a denial-of service condition.<\/p>\n\n<p>The Cyber Centre encourages users to review the following bulletin and apply the necessary manufacturer recommendations:<\/p>\n\n<p>ICS Advisory (ICSMA-20-112-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-112-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-112-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory","alert_type":398,"serial_number":"AV20-119","subject":null,"moderation_state":"published","external_url":null},{"nid":1845,"title":"[Control systems] Sierra Wireless security advisory","uuid":"87709dc2-ef52-4bd1-a3ee-21c8dc2773a7","banner":null,"lang":"en","date_modified":"2020-04-24","date_modified_ts":"2020-04-24T18:17:29Z","date_created":"2020-04-24T18:15:08Z","summary":null,"body":["<article data-history-node-id=\"1845\" about=\"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-120<br \/>\nDate: 24 April 2020<\/strong><\/p>\n\n<p>On 23 April 2020 US-CERT published a security advisory to address multiple vulnerabilities affecting Sierra Wireless AirLink ALEOS. Successful exploitation of these vulnerabilities could allow an actor to remotely execute code, discover sensitive information, upload files or perform network reconnaissance. This advisory is a follow-up to the previously published ICSA-19-122-03 Sierra Wireless AirLink ALEOS (Update A) that was released on 20 August 2019.<\/p>\n\n<p>The Cyber Centre encourages users to review the following advisory and apply the necessary manufacturer recommendations:<\/p>\n\n<p>ICS Advisory (ICSA-19-122-03)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA-19-122-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA-19-122-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory","alert_type":398,"serial_number":"AV20-120","subject":null,"moderation_state":"published","external_url":null},{"nid":1846,"title":"OpenSSL security advisory","uuid":"8c58d2f3-f8f2-4248-9d16-9de8eb6aaad3","banner":null,"lang":"en","date_modified":"2020-04-27","date_modified_ts":"2020-04-27T12:37:33Z","date_created":"2020-04-27T12:37:33Z","summary":null,"body":["<article data-history-node-id=\"1846\" about=\"\/en\/alerts-advisories\/openssl-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-121<br \/>\nDate: 27 April 2020<\/strong><\/p>\n\n<p>On 21 April 2020 OpenSSL released a security advisory to address a vulnerability in the SSL_check_chain() function within the TLS extension of their client and server applications. Successful exploitation of this vulnerability may allow a remote peer to send an invalid or unrecognized signature; causing the software to crash and resulting in a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the OpenSSL advisory for their specific versions and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20200421.txt\">https:\/\/www.openssl.org\/news\/secadv\/20200421.txt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory","alert_type":396,"serial_number":"AV20-121","subject":null,"moderation_state":"published","external_url":null},{"nid":1847,"title":"Google Chrome security advisory","uuid":"fad95e9c-42f9-43bf-be8f-3eccf74b1ebc","banner":null,"lang":"en","date_modified":"2020-04-28","date_modified_ts":"2020-04-28T19:46:46Z","date_created":"2020-04-28T19:46:46Z","summary":null,"body":["<article data-history-node-id=\"1847\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-122<br \/>\nDate: 28 April 2020<\/strong><\/p>\n\n<p>On 27 April 2020 Google announced the release of Chrome 81.0.4044.129 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_27.html\">https:\/\/chromereleases.googleblog.com\/2020\/04\/stable-channel-update-for-desktop_27.html<\/a>\u00a0<\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-23","alert_type":396,"serial_number":"AV20-122","subject":null,"moderation_state":"published","external_url":null},{"nid":1848,"title":"Sophos XG Firewall Vulnerability - CVE-2020-12271 ","uuid":"07f993e1-1da5-4890-bb40-5de8bb2acfa1","banner":null,"lang":"en","date_modified":"2020-04-29","date_modified_ts":"2020-04-29T12:53:20Z","date_created":"2020-04-29T12:31:55Z","summary":null,"body":["<article data-history-node-id=\"1848\" about=\"\/en\/alerts-advisories\/sophos-xg-firewall-vulnerability-cve-2020-12271\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-013<br \/>\nDate: 29 April 2020 <\/strong><\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>On 22 April 2020 Sophos investigated an incident which lead to the discovery of a pre-authentication SQL Injection vulnerability, tracked as CVE-2020-12271, in its XG Firewall firmware. This vulnerability affects physical and virtual implementations of the XG Firewall and was seen by Sophos being actively exploited in the wild.<\/p>\n\n<p>Sophos has since released a hotfix to address the vulnerability for all supported versions (17.0, 17.1, 17.5, 18.0), and has published a report describing the malware (which Sophos calls \u201cAsnarok\u201d) that was used in the incident.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>Successful exploitation requires access to the administrative interface (HTTPS admin service) or the user portal of the XG Firewall. In addition, other firewall services that have been manually configured to run on the same ports as the admin or user portal may also be affected.<\/p>\n\n<p>The malware exfiltrates data from XG Firewall appliances. This may include all usernames and the hashed passwords of any local user accounts, including administrative user accounts. Passwords associated with external authentication systems such as Active Directory (AD) or LDAP were not compromised.<\/p>\n\n<h2>SUGGESTED ACTION<\/h2>\n\n<p>Administrators should verify that the hotfix has been applied by viewing the messages section of the Control Center within the XG management interface. Sophos reported that in some instances this message may provide an indication of compromise.<\/p>\n\n<p>For compromised XG Firewall devices that have received the hotfix, Sophos strongly recommends the following additional steps to fully remediate the issue:<\/p>\n\n<ul><li>\u00a0Reset device administrator accounts<\/li>\n\t<li>\u00a0Reboot the XG device(s)<\/li>\n\t<li>\u00a0Reset passwords for all local user accounts<\/li>\n<\/ul><p>Although the passwords were hashed, it is recommended that passwords are reset for any accounts where the XG credentials might have been reused<\/p>\n\n<p>Additionally, Sophos recommends disabling HTTPS admin services on the WAN interface. If the user portal is not being used, Sophos also recommends deactivating this service on the WAN as well.<\/p>\n\n<h2>INDICATORS OF COMPROMISE<\/h2>\n\n<p>For reported indicators of compromise, review the Detailed Sophos Analysis article which has been linked in the below REFERENCES section.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>Sophos Knowledge Base Article:<br \/><a href=\"https:\/\/community.sophos.com\/kb\/en-us\/135412\">https:\/\/community.sophos.com\/kb\/en-us\/135412<\/a>\u00a0<br \/>\n\u00a0<br \/>\nDetailed Sophos Analysis:<br \/><a href=\"https:\/\/news.sophos.com\/en-us\/2020\/04\/26\/asnarok\/\">https:\/\/news.sophos.com\/en-us\/2020\/04\/26\/asnarok\/<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>The Cyber Centre can be contacted at:<br \/>\nEmail: <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a><br \/>\nToll Free: <a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> <a href=\"tel:+1-833-292-3788\">(1-833-292-3788)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sophos-xg-firewall-vulnerability-cve-2020-12271","alert_type":397,"serial_number":"AL20-013","subject":null,"moderation_state":"published","external_url":null},{"nid":1849,"title":"Adobe security advisory","uuid":"15eccaff-e1c2-4445-845b-13a573bab557","banner":null,"lang":"en","date_modified":"2020-04-29","date_modified_ts":"2020-04-29T13:00:16Z","date_created":"2020-04-29T13:00:16Z","summary":null,"body":["<article data-history-node-id=\"1849\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-123<br \/>\nDate: 29 April 2020<\/strong><\/p>\n\n<p>On 28 April 2020 Adobe released security updates to address various vulnerabilities affecting:<br \/>\n\u2022\u00a0Magento<br \/>\n\u2022\u00a0Illustrator<br \/>\n\u2022\u00a0Adobe Bridge<\/p>\n\n<p>Some of these vulnerabilities could lead to arbitrary code execution.<br \/>\nThe Cyber Centre encourages users and administrators to review the Adobe Security Bulletins and Advisories webpage and apply the necessary updates:<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-17","alert_type":396,"serial_number":"AV20-123","subject":null,"moderation_state":"published","external_url":null},{"nid":1850,"title":"Juniper Networks security advisory","uuid":"8b199652-46de-49ea-975d-5d49792df25f","banner":null,"lang":"en","date_modified":"2020-04-29","date_modified_ts":"2020-04-29T14:25:30Z","date_created":"2020-04-29T14:25:30Z","summary":null,"body":["<article data-history-node-id=\"1850\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-124<br \/>\nDate: 29 April 2020<\/strong><\/p>\n\n<p>On 28 April 2020 Juniper Networks released an out of cycle security advisory to address a vulnerability, tracked as CVE-2020-1631, affecting the JUNOS OS J-Web and web-based HTTP\/HTTPS services. This vulnerability may lead to unauthenticated remote file inclusion, web traversal, command injection, unintended file access and privilege escalation where a remote actor can gain the same level of access as anyone currently logged into the device; including an administrator.<\/p>\n\n<p>This issue only affects Juniper Networks Junos OS devices with HTTP\/HTTPS services enabled. The impact of this vulnerability is further increased if J-Web is enabled in addition to the HTTP\/HTTPS services.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Juniper Networks Security Advisory apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA11021&amp;actp=METADATA\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA11021&amp;actp=METADATA<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-5","alert_type":396,"serial_number":"AV20-124","subject":null,"moderation_state":"published","external_url":null},{"nid":1851,"title":"Samba security advisory","uuid":"8ed096fb-119b-445c-b981-6884465d71f5","banner":null,"lang":"en","date_modified":"2020-04-29","date_modified_ts":"2020-04-29T14:32:50Z","date_created":"2020-04-29T14:32:50Z","summary":null,"body":["<article data-history-node-id=\"1851\" about=\"\/en\/alerts-advisories\/samba-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-125<br \/>\nDate: 29 April 2020<\/strong><\/p>\n\n<p>On 28 April 2020 Samba released security updates to address vulnerabilities affecting its product. Successful exploitation of one of these vulnerabilities, tracked as CVE-2020-10704, could allow an actor to cause a denial of service on the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Samba Security Releases webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">https:\/\/www.samba.org\/samba\/history\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-advisory-2","alert_type":396,"serial_number":"AV20-125","subject":null,"moderation_state":"published","external_url":null},{"nid":1852,"title":"VMware security advisory","uuid":"5c55383b-223e-4d52-a1b1-976bf2036652","banner":null,"lang":"en","date_modified":"2020-04-29","date_modified_ts":"2020-04-29T19:08:07Z","date_created":"2020-04-29T19:08:07Z","summary":null,"body":["<article data-history-node-id=\"1852\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-126<br \/>\nDate: 29 April 2020<\/strong><\/p>\n\n<p>On 28 April 2020 VMware released a security advisory to address an important vulnerability, tracked as CVE-2020-3955, affecting VMware ESXi v6.5 and v6.7. An actor with access to modify the system properties of a virtual machine from inside the guest os (such as changing the hostname of the virtual machine) may be able to inject a malicious script. This script may be executed by a victim's browser when viewing this virtual machine via the ESXi Host Client.<\/p>\n\n<p>The Cyber Centre encourages users to review the following VMware advisory and apply the necessary update:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0008.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0008.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-26","alert_type":396,"serial_number":"AV20-126","subject":null,"moderation_state":"published","external_url":null},{"nid":1853,"title":"Cisco security advisory","uuid":"0270ee47-08b2-46c5-a1ac-30f9d36e34b7","banner":null,"lang":"en","date_modified":"2020-04-30","date_modified_ts":"2020-04-30T19:45:13Z","date_created":"2020-04-30T19:44:59Z","summary":null,"body":["<article data-history-node-id=\"1853\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-47\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-127<br \/>\nDate: 30 April 2020<\/strong><\/p>\n\n<p>On 29 April 2020 Cisco released a security update to address a vulnerability affecting its Cisco IOS XE SD-WAN product. An authenticated, local actor could inject arbitrary commands that are executed with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-47","alert_type":396,"serial_number":"AV20-127","subject":null,"moderation_state":"published","external_url":null},{"nid":1856,"title":"[Control systems] ABB security advisory","uuid":"77219e9b-9c76-4891-9b93-e104f9fe206a","banner":null,"lang":"en","date_modified":"2020-05-01","date_modified_ts":"2020-05-01T13:55:05Z","date_created":"2020-05-01T13:06:42Z","summary":null,"body":["<article data-history-node-id=\"1856\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-128<br \/>\nDate: 01 May 2020<\/strong><\/p>\n\n<p>Between 2 April and 22 April 2020 ABB published multiple <em>Cybersecurity Advisories<\/em> highlighting vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0System 800xA<br \/>\n\u2022\u00a0ABB Central Licensing System<br \/>\n\u2022\u00a0UPS Adapter CS141<br \/>\n\u2022\u00a0Telephone Gateway TG\/S 3.2<\/p>\n\n<p>Successful exploitation of some of these vulnerabilities may allow an actor to halt or interfere with system functions, run arbitrary code, read arbitrary files or enable information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p>System 800xA:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121106&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121106&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121232&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121232&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121221&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121221&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121236&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121236&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>ABB Central Licensing System:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121231&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121231&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121230&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121230&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>UPS Adapter CS141:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107680A4579&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107680A4579&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>Telephone Gateway TG\/S 3.2:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107680A3921&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107680A3921&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-1","alert_type":398,"serial_number":"AV20-128","subject":null,"moderation_state":"published","external_url":null},{"nid":1854,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"51fe39ad-2c54-4536-9cd7-b8defb9f910b","banner":null,"lang":"en","date_modified":"2020-05-01","date_modified_ts":"2020-05-01T13:41:12Z","date_created":"2020-05-01T13:19:47Z","summary":null,"body":["<article data-history-node-id=\"1854\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-129<br \/>\nDate: 01 May 2020<\/strong><\/p>\n\n<p>On 27 March 2020 B&amp;R Industrial Automation published a <em>Cyber Security Advisory <\/em>highlighting an information disclosure vulnerability in the following products:<\/p>\n\n<p>\u2022\u00a0APC2200 BIOS version 1.13<br \/>\n\u2022\u00a0PPC2200 BIOS version 1.13<br \/>\n\u2022\u00a0APC3100 BIOS version 1.18<br \/>\n\u2022\u00a0PPC3100 BIOS version 1.18<br \/>\n\u2022\u00a0APC910 BIOS version 7.18 (Only for B&amp;R order number 5SWBIO.TS17-00)<\/p>\n\n<p>Successful exploitation of this Trusted Platform Module (TPM) vulnerability may allow an unauthenticated actor to enable information disclosure via network access. The <em>Cyber Security Advisory<\/em> indicates that proof-of-concept code has been published.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following for recommended mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p><a href=\"https:\/\/www.br-automation.com\/en\/downloads\/022020-tpm-fail\/\">https:\/\/www.br-automation.com\/en\/downloads\/022020-tpm-fail\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-1","alert_type":398,"serial_number":"AV20-129","subject":null,"moderation_state":"published","external_url":null},{"nid":1855,"title":"Fortinet security advisory","uuid":"25184d33-e583-4efe-83cf-d572439ff2e2","banner":null,"lang":"en","date_modified":"2020-05-01","date_modified_ts":"2020-05-01T13:48:05Z","date_created":"2020-05-01T13:48:05Z","summary":null,"body":["<article data-history-node-id=\"1855\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-130<br \/>\nDate: 01 May 2020<\/strong><\/p>\n\n<p>On 27 April 2020 Fortinet released a security update to address a vulnerability affecting its FortiMail and FortiVoice Enterprise products. An unauthenticated, remote actor could exploit a weakness in the password recovery function by submitting a specially crafted password change request. Successful exploitation would permit unauthorized access to user accounts.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/fortiguard.com\/psirt\/FG-IR-20-045\">https:\/\/fortiguard.com\/psirt\/FG-IR-20-045<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-4","alert_type":396,"serial_number":"AV20-130","subject":null,"moderation_state":"published","external_url":null},{"nid":1857,"title":"WordPress security advisory","uuid":"1ddd14fb-df9b-4444-8f68-e2ac5a620d63","banner":null,"lang":"en","date_modified":"2020-05-04","date_modified_ts":"2020-05-04T12:28:44Z","date_created":"2020-05-04T12:28:44Z","summary":null,"body":["<article data-history-node-id=\"1857\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-131<br \/>\nDate: 4 May 2020<\/strong><\/p>\n\n<p>On 29 April 2020 WordPress released version 5.4.1 to address multiple vulnerabilities affecting WordPress version 5.4 and earlier. A remote actor could exploit some of these vulnerabilities to expose sensitive information and\/or take control of an affected site.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<br \/><a href=\"https:\/\/wordpress.org\/news\/2020\/04\/wordpress-5-4-1\/\">https:\/\/wordpress.org\/news\/2020\/04\/wordpress-5-4-1\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-2","alert_type":396,"serial_number":"AV20-131","subject":null,"moderation_state":"published","external_url":null},{"nid":1858,"title":"Oracle WebLogic Server Remote Code Execution Vulnerability \u2013 CVE-2020-2883","uuid":"e038601c-375d-423e-a4d5-5260e99180de","banner":null,"lang":"en","date_modified":"2020-05-05","date_modified_ts":"2020-05-05T02:03:32Z","date_created":"2020-05-05T02:03:32Z","summary":null,"body":["<article data-history-node-id=\"1858\" about=\"\/en\/alerts-advisories\/oracle-weblogic-server-remote-code-execution-vulnerability-cve-2020-2883\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-014<br \/>\nDate: 4 May 2020<\/strong><\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>On 14 April 2020, Oracle released an update to address a remote code execution vulnerability, tracked as CVE-2020-2883, in the following versions of Oracle WebLogic Server:<br \/>\n- 10.3.6.0.0<br \/>\n- 12.1.3.0.0<br \/>\n- 12.2.1.3.0<br \/>\n- 12.2.1.4.0<\/p>\n\n<p>Oracle WebLogic is a middleware product that is typically situated between a front-facing application and a back-end database. A flaw exists in the way WebLogic de-serialises requests sent using T3, a proprietary protocol for communication between the WebLogic server and remote Java virtual machines. A remote actor could exploit this vulnerability by sending a specially crafted T3 request to the WebLogic server, resulting in arbitrary code contained within the request being executed in the context of the account running the service.<br \/>\nProof of concept code leveraging this vulnerability has been published, and Oracle has indicated that exploitation attempts have been observed.<\/p>\n\n<h2>SUGGESTED ACTION<\/h2>\n\n<p>The Cyber Centre recommends that organizations immediately install the latest security updates from Oracle.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>Cyber Centre Advisory (AV20-112):<br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/oracle-security-advisory-april-2020-critical-patch-update\">https:\/\/www.cyber.gc.ca\/en\/alerts\/oracle-security-advisory-april-2020-critical-patch-update<\/a><\/p>\n\n<p>Oracle Critical Patch Update Advisory - April 2020:<br \/><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2020.html\">https:\/\/www.oracle.com\/security-alerts\/cpuapr2020.html<\/a><\/p>\n\n<p>Oracle blog post:<br \/><a href=\"https:\/\/blogs.oracle.com\/security\/apply-april-2020-cpu\">https:\/\/blogs.oracle.com\/security\/apply-april-2020-cpu<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the<br \/>\nCyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information<br \/>\nsharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-weblogic-server-remote-code-execution-vulnerability-cve-2020-2883","alert_type":397,"serial_number":"AL20-014","subject":null,"moderation_state":"published","external_url":null},{"nid":1859,"title":"SaltStack Vulnerabilities Actively Exploited","uuid":"578fb78f-dbe1-4b7b-9875-e7f512bf36a7","banner":null,"lang":"en","date_modified":"2020-05-05","date_modified_ts":"2020-05-05T17:55:11Z","date_created":"2020-05-05T17:30:43Z","summary":null,"body":["<article data-history-node-id=\"1859\" about=\"\/en\/alerts-advisories\/saltstack-vulnerabilities-actively-exploited\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-015<br \/>\nDate: 5 May 2020 <\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it to appropriate audiences.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>On 1 May 2020 SaltStack released v3000.2 and v2019.2.4 of its open source Salt product to address two critical vulnerabilities that can result in remote command execution as root. Salt is a Python-based management framework often used in data centres and cloud servers to centrally monitor and update enterprise systems.<\/p>\n\n<p>There are reports of vulnerable Salt systems being actively exploited in the wild, including the malicious installation of unauthorized crypto-mining software.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>Servers being managed by Salt run a \u201cminion\u201d agent and connect back to a central \u201cmaster\u201d server to both report their status and retrieve update messages to act on. The master server listens for the status reports on TCP port 4505 and publishes tasking commands for the managed servers to process on TCP port 4506 (both default ports).<\/p>\n\n<p>Exploitation is possible because of two separate vulnerabilities. The first, CVE-2020-11651, is an authentication bypass that unintentionally allows unauthenticated network access. The second, CVE-2020-11652, is a directory traversal that permits access to the entire server filesystem.<\/p>\n\n<p>Successful exploitation of vulnerable systems is possible when the 2 ports used by the master server are exposed to the Internet and unauthorized actors can connect to them.<\/p>\n\n<h2>SUGGESTED ACTION<\/h2>\n\n<p>It is recommended that administrators update their installations to the latest, patched version. SaltStack also recommends installs be configured to automatically retrieve updates from the SaltStack repository server.<\/p>\n\n<p>Network configurations should be examined to ensure that administrative ports for the Salt servers are not exposed to the Internet. Additional hardening techniques are noted in the below references.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>SaltStack Announcement:<br \/><a href=\"https:\/\/help.saltstack.com\/hc\/en-us\/articles\/360043056331-New-SaltStack-Release-Critical-Vulnerability\">https:\/\/help.saltstack.com\/hc\/en-us\/articles\/360043056331-New-SaltStack-Release-Critical-Vulnerability<\/a><\/p>\n\n<p>Salt Hardening:<br \/><a href=\"https:\/\/docs.saltstack.com\/en\/latest\/topics\/hardening.html\">https:\/\/docs.saltstack.com\/en\/latest\/topics\/hardening.html<\/a><\/p>\n\n<p>F-Secure Labs Advisory:<br \/><a href=\"https:\/\/labs.f-secure.com\/advisories\/saltstack-authorization-bypass\">https:\/\/labs.f-secure.com\/advisories\/saltstack-authorization-bypass<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS <\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>The Cyber Centre can be contacted at:<br \/>\nEmail: <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a><br \/>\nToll Free: <a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> <a href=\"tel:+1-833-292-3788\">(1-833-292-3788)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/saltstack-vulnerabilities-actively-exploited","alert_type":397,"serial_number":"AL20-015","subject":null,"moderation_state":"published","external_url":null},{"nid":1860,"title":"[Control systems] LCDS security advisory","uuid":"f86461f3-a4a4-4949-8fd4-04a3b337e300","banner":null,"lang":"en","date_modified":"2020-05-06","date_modified_ts":"2020-05-06T13:35:47Z","date_created":"2020-05-06T13:35:47Z","summary":null,"body":["<article data-history-node-id=\"1860\" about=\"\/en\/alerts-advisories\/control-systems-lcds-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-132<br \/>\nDate: 5 May 2020<\/strong><\/p>\n\n<p>On 28 April 2020 US-CERT published an ICS advisory to address vulnerabilities related to LCDS LAquis SCADA. Successful exploitation of these vulnerabilities could allow unauthorized actors to view sensitive information and create files in arbitrary locations.<\/p>\n\n<p>The Cyber Centre encourages administrators to review the following ICS advisory and apply the necessary manufacturer recommendations:<\/p>\n\n<p>ICS Advisory (ICSA-20-119-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-119-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-119-01<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-lcds-security-advisory","alert_type":398,"serial_number":"AV20-132","subject":null,"moderation_state":"published","external_url":null},{"nid":1861,"title":"APT Groups Target Healthcare and Essential Services \u2013 CISA\/NCSC","uuid":"a2922dd4-0a4b-4a48-973d-a02710ac6247","banner":null,"lang":"en","date_modified":"2020-05-06","date_modified_ts":"2020-05-06T14:05:27Z","date_created":"2020-05-06T14:04:22Z","summary":null,"body":["<article data-history-node-id=\"1861\" about=\"\/en\/alerts-advisories\/apt-groups-target-healthcare-and-essential-services-cisancsc-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>\u00a0\n<\/p>\n<p><strong>Number: AL20-016<\/strong>\n  <br \/><strong>Date: 6 May 2020<\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>PURPOSE\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>ASSESSMENT\n<\/h2>\n<p>On 5 May 2020 the Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom\u2019s National Cyber Security Centre (NCSC) produced a joint alert highlighting the continued efforts of advanced persistent threat (APT) groups to target organizations involved in the response to COVID-19. The Cyber Centre would like to highlight the alert, as it provides important information to system owners and operators responsible for defending their systems and networks from cyber threats. Of note is the alert\u2019s emphasis on APT groups\u2019 use of password spraying in their attempts to infiltrate organizations. The Cyber Centre would like to underline the importance of general security best practices, particularly that of maintaining software applications to the latest patch level. Please refer to the references section, below, for more information related to the reported activity. Should organizations identify similar activity to that described in the referenced Alerts, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>CISA and NCSC joint alert (AA20-126A): <a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/AA20126A\">https:\/\/www.us-cert.gov\/ncas\/alerts\/AA20126A<\/a>\n<\/p>\n<p>Cyber threats to Canadian health organizations (AL20-008 UPDATE 1): <a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/cyber-threats-canadian-health-organizations\">https:\/\/cyber.gc.ca\/en\/alerts\/cyber-threats-canadian-health-organizations<\/a>\n<\/p>\n<p>Active exploitation of VPN vulnerabilities (AL19-016 UPDATE 1): <a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/active-exploitation-vpn-vulnerabilities-0\">https:\/\/www.cyber.gc.ca\/en\/alerts\/active-exploitation-vpn-vulnerabilities-0<\/a>\n<\/p>\n<p>\u00a0\n<\/p>\n<p><strong>NOTE TO READERS <\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apt-groups-target-healthcare-and-essential-services-cisancsc-0","alert_type":397,"serial_number":"AL20-016","subject":null,"moderation_state":"published","external_url":null},{"nid":1862,"title":"[Control systems] SAE IT-systems security advisory","uuid":"a605f22b-1259-4131-8772-07e0980ed2c6","banner":null,"lang":"en","date_modified":"2020-05-06","date_modified_ts":"2020-05-06T15:17:35Z","date_created":"2020-05-06T15:17:35Z","summary":null,"body":["<article data-history-node-id=\"1862\" about=\"\/en\/alerts-advisories\/control-systems-sae-it-systems-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-133<br \/>\nDate: 6 May 2020<\/strong><\/p>\n\n<p>On 5 May 2020 US-CERT published an ICS advisory to highlight vulnerabilities related to SAE IT-systems FW-50 Remote Telemetry Unit. Successful exploitation of these vulnerabilities may allow an actor to execute remote code, disclose sensitive information, or cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages administrators to review the following ICS advisory and apply the necessary manufacturer recommendations:<\/p>\n\n<p>ICS Advisory (ICSA-20-126-02)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA2012602\">https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA2012602<\/a>\u00a0\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sae-it-systems-security-advisory","alert_type":398,"serial_number":"AV20-133","subject":null,"moderation_state":"published","external_url":null},{"nid":1863,"title":"[Control systems] Fazecast security advisory","uuid":"c05f8e7e-95e1-49ed-b06f-72eb9e18499a","banner":null,"lang":"en","date_modified":"2020-05-06","date_modified_ts":"2020-05-06T15:22:37Z","date_created":"2020-05-06T15:22:37Z","summary":null,"body":["<article data-history-node-id=\"1863\" about=\"\/en\/alerts-advisories\/control-systems-fazecast-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-134<br \/>\nDate: 6 May 2020<\/strong><\/p>\n\n<p>On 5 May 2020 US-CERT published an ICS advisory to highlight a vulnerability related to Fazecast jSerialComm. Successful exploitation of this vulnerability could allow an unauthenticated actor to execute arbitrary code on a targeted system.<\/p>\n\n<p>The Cyber Centre encourages administrators to review the following ICS advisory and apply the necessary manufacturer recommendations:<\/p>\n\n<p>ICS Advisory (ICSA-20-126-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA2012601\">https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA2012601<\/a>\u00a0\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fazecast-security-advisory","alert_type":398,"serial_number":"AV20-134","subject":null,"moderation_state":"published","external_url":null},{"nid":1864,"title":"Mozilla security advisory","uuid":"daab7395-a608-4dd6-a709-9036e8d8aeee","banner":null,"lang":"en","date_modified":"2020-05-06","date_modified_ts":"2020-05-06T18:40:16Z","date_created":"2020-05-06T18:40:16Z","summary":null,"body":["<article data-history-node-id=\"1864\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-135<br \/>\nDate: 6 May 2020<\/strong><\/p>\n\n<p>On 5 May 2020 Mozilla released Firefox 76, Firefox ESR 68.8, and Thunderbird 68.8 to address various vulnerabilities. Of note are use-after-free vulnerabilities in all three products which could potentially lead to an exploitable crash.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-14","alert_type":396,"serial_number":"AV20-135","subject":null,"moderation_state":"published","external_url":null},{"nid":1865,"title":"Google Chrome security advisory","uuid":"abfa72c9-dd24-4118-b66a-0baa1e62e1b8","banner":null,"lang":"en","date_modified":"2020-05-07","date_modified_ts":"2020-05-07T12:09:29Z","date_created":"2020-05-07T12:09:29Z","summary":null,"body":["<article data-history-node-id=\"1865\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-136<br \/>\nDate: 7 May 2020<\/strong><\/p>\n\n<p>On 5 May 2020 Google announced the release of Chrome 81.0.4044.138 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the Chrome Releases webpage and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/05\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/05\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-24","alert_type":396,"serial_number":"AV20-136","subject":null,"moderation_state":"published","external_url":null},{"nid":1866,"title":"Citrix security advisory","uuid":"d6df99b0-57bd-4695-b53d-5c894984f2c4","banner":null,"lang":"en","date_modified":"2020-05-07","date_modified_ts":"2020-05-07T13:13:37Z","date_created":"2020-05-07T13:13:37Z","summary":null,"body":["<article data-history-node-id=\"1866\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-137<br \/>\nDate: 7 May 2020<\/strong><\/p>\n\n<p>On 5 May 2020 Citrix released a security bulletin regarding critical vulnerabilities in client-managed Citrix ShareFile storage zone controllers. If exploited, these vulnerabilities would allow an unauthenticated actor to compromise the storage zones controller and potentially gain access to ShareFile users\u2019 documents and folders.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX269106\">https:\/\/support.citrix.com\/article\/CTX269106<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-3","alert_type":396,"serial_number":"AV20-137","subject":null,"moderation_state":"published","external_url":null},{"nid":1867,"title":"Cisco security advisory","uuid":"a1515b75-bdff-49cc-b7df-edebc9ef212f","banner":null,"lang":"en","date_modified":"2020-05-08","date_modified_ts":"2020-05-08T12:10:00Z","date_created":"2020-05-08T12:10:00Z","summary":null,"body":["<article data-history-node-id=\"1867\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-48\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-138<br \/>\nDate: 8 May 2020<\/strong><\/p>\n\n<p>On 6 May 2020 Cisco released security updates to address vulnerabilities affecting its Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software. Successful exploitation of the vulnerabilities could allow an actor to cause a memory leak, disclose information, view and delete sensitive information, bypass authentication or create a denial of service (DoS) condition on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-48","alert_type":396,"serial_number":"AV20-138","subject":null,"moderation_state":"published","external_url":null},{"nid":1868,"title":"Samsung Mobile security advisory","uuid":"52acec94-1635-4d63-a144-9998dee852d7","banner":null,"lang":"en","date_modified":"2020-05-08","date_modified_ts":"2020-05-08T12:13:50Z","date_created":"2020-05-08T12:13:50Z","summary":null,"body":["<article data-history-node-id=\"1868\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-139<br \/>\nDate: 8 May 2020<\/strong><\/p>\n\n<p>On 6 May 2020 Samsung Mobile released its May 2020 security updates for major flagship models. Of note is a memory corruption vulnerability, tracked as CVE-2020-8899\/SVE-2020-16747, that may lead to unauthenticated remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb\">https:\/\/security.samsungmobile.com\/securityUpdate.smsb<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory","alert_type":396,"serial_number":"AV20-139","subject":null,"moderation_state":"published","external_url":null},{"nid":1869,"title":"[Control systems] Schneider Electric security advisory","uuid":"ec49222e-d8e2-456c-9153-8f0ae4fd14ed","banner":null,"lang":"en","date_modified":"2020-05-08","date_modified_ts":"2020-05-08T12:27:03Z","date_created":"2020-05-08T12:27:03Z","summary":null,"body":["<article data-history-node-id=\"1869\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-140<br \/>\nDate: 8 May 2020<\/strong><\/p>\n\n<p>On 14 April 2020 Schneider Electric published a security notification highlighting a DLL substitution vulnerability in the following products:<\/p>\n\n<p>\u2022\u00a0SoMachine Basic (all versions)<br \/>\n\u2022\u00a0EcoStruxure Machine Expert \u2013 Basic (all versions)<br \/>\n\u2022\u00a0Modicon M100 Logic Controller (all versions)<br \/>\n\u2022\u00a0Modicon M200 Logic Controller (all versions)<br \/>\n\u2022\u00a0Modicon M221 Logic Controller (all versions)<\/p>\n\n<p>Successful exploitation of this vulnerability may allow for malicious code to be transferred to vulnerable controllers.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following for recommended mitigations and apply the necessary manufacturer software and firmware updates:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-105-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-105-01\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-1","alert_type":398,"serial_number":"AV20-140","subject":null,"moderation_state":"published","external_url":null},{"nid":1870,"title":"[Control systems] Advantech security advisory","uuid":"d102cffe-8865-43be-9f92-9494a1b13267","banner":null,"lang":"en","date_modified":"2020-05-08","date_modified_ts":"2020-05-08T20:29:01Z","date_created":"2020-05-08T20:28:37Z","summary":null,"body":["<article data-history-node-id=\"1870\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>\u00a0<\/p>\n\n<p><strong>Number: AV20-141<br \/>\nDate: 8 May 2020<\/strong><\/p>\n\n<p>\u00a0<\/p>\n\n<p>On 7 May 2020 US-CERT published an ICS advisory to highlight several critical vulnerabilities related to Advantech WebAccess Node. Successful exploitation of these vulnerabilities may allow information disclosure, remote code execution, and compromise system availability<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following for recommended mitigations and apply the necessary manufacturer software and firmware updates:<br \/>\nICS Advisory (ICSA-20-128-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-128-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-128-01<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-4","alert_type":398,"serial_number":"AV20-141","subject":null,"moderation_state":"published","external_url":null},{"nid":1871,"title":"Adobe security advisory","uuid":"5ecfbc09-fff7-49b0-8535-7e1d72f5c158","banner":null,"lang":"en","date_modified":"2020-05-12","date_modified_ts":"2020-05-12T18:50:33Z","date_created":"2020-05-12T18:50:33Z","summary":null,"body":["<article data-history-node-id=\"1871\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-142<br \/>\nDate:\u00a012 May 2020<\/strong><\/p>\n\n<p>On 12 May 2020 Adobe released security updates to address vulnerabilities affecting some of its products. Of note are vulnerabilities in Adobe Acrobat and Reader for Windows and macOS. Successful exploitation of some of these vulnerabilities could lead to arbitrary code execution in the context of the current user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\">https:\/\/helpx.adobe.com\/security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-18","alert_type":396,"serial_number":"AV20-142","subject":null,"moderation_state":"published","external_url":null},{"nid":1872,"title":"Microsoft security advisory \u2013 May 2020 monthly rollup","uuid":"0b187905-4ebf-4f12-8076-a5636a7b3be1","banner":null,"lang":"en","date_modified":"2020-05-13","date_modified_ts":"2020-05-13T13:24:55Z","date_created":"2020-05-13T13:24:55Z","summary":null,"body":["<article data-history-node-id=\"1872\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-143<br \/>\nDate: 13 May 2020<\/strong><\/p>\n\n<p>On 12 May 2020 Microsoft released security updates to address multiple vulnerabilities affecting some of its products. Of note is a vulnerability in the Microsoft Edge PDF Reader which, if successfully exploited, could allow a remote malicious actor to execute arbitrary code within the context of the current user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following links and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-May\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-May<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-may-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-143","subject":null,"moderation_state":"published","external_url":null},{"nid":1873,"title":"[Control systems] Eaton security advisory","uuid":"3a832a32-9c21-4e91-ae31-502da57fc623","banner":null,"lang":"en","date_modified":"2020-05-13","date_modified_ts":"2020-05-13T19:59:25Z","date_created":"2020-05-13T19:59:25Z","summary":null,"body":["<article data-history-node-id=\"1873\" about=\"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-144<br \/>\nDate: 13 May 2020<\/strong><\/p>\n\n<p>On 12 May 2020 ICS-CERT released a security bulletin to address vulnerabilities affecting the Eaton Intelligent Power Manager v1.67 and prior. Successful exploitation of these vulnerabilities could allow an actor to perform command injection or code execution and allow non-administrator users to manipulate the system configurations.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-133-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-133-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-133-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-0","alert_type":398,"serial_number":"AV20-144","subject":null,"moderation_state":"published","external_url":null},{"nid":1874,"title":"[Control systems] OSIsoft security advisory","uuid":"5b8862c6-4c32-45b9-a511-561005dfa10a","banner":null,"lang":"en","date_modified":"2020-05-13","date_modified_ts":"2020-05-13T20:12:00Z","date_created":"2020-05-13T20:01:20Z","summary":null,"body":["<article data-history-node-id=\"1874\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-145<br \/>\nDate: 13 May 2020<\/strong><\/p>\n\n<p>On 12 May 2020 ICS-CERT published a security bulletin highlighting several vulnerabilities in OSIsoft PI System products. Successful exploitation of some of these vulnerabilities could allow a malicious actor to access unauthorized information, delete or modify local processes, and crash the affected device.<br \/>\nThe Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-133-02)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-133-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-133-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory-0","alert_type":398,"serial_number":"AV20-145","subject":null,"moderation_state":"published","external_url":null},{"nid":1875,"title":"[Control systems] Siemens security advisory","uuid":"2cce0cc6-1310-4f83-a29b-fc07049b464e","banner":null,"lang":"en","date_modified":"2020-05-14","date_modified_ts":"2020-05-14T12:14:37Z","date_created":"2020-05-14T12:14:37Z","summary":null,"body":["<article data-history-node-id=\"1875\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-146<br \/>\nDate: 14 May 2020<\/strong><\/p>\n\n<p>On 12 May 2020 Siemens published a<em> Siemens Security Advisory <\/em>to address vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0Siemens Power Meters Series 9410 (All versions before V2.2.1)<br \/>\n\u2022\u00a0Siemens Power Meters Series 9810 (All versions)<\/p>\n\n<p>The vulnerabilities, (commonly known as URGENT\/11) in the TCP\/IP stack of the devices\u2019 Wind River VxWorks real-time operating system, could allow an actor to execute a variety of exploits including denial-of-service, data extraction and remote code execution.<\/p>\n\n<p>For more information, the Cyber Centre has previously published an Alert on the VxWorks vulnerabilities:<\/p>\n\n<p>Wind River VxWorks IPnet TCP\/IP Stack Vulnerabilities (AL19-015)<\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/wind-river-vxworks-ipnet-tcpip-stack-vulnerabilities\">https:\/\/cyber.gc.ca\/en\/alerts\/wind-river-vxworks-ipnet-tcpip-stack-vulnerabilities<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>Siemens Security Advisory (SSA-352504)<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-352504.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-352504.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-9","alert_type":398,"serial_number":"AV20-146","subject":null,"moderation_state":"published","external_url":null},{"nid":1876,"title":"SAP security advisory","uuid":"7e0768d2-5b6e-48bc-a8b0-846c634e8153","banner":null,"lang":"en","date_modified":"2020-05-14","date_modified_ts":"2020-05-14T17:55:01Z","date_created":"2020-05-14T17:55:01Z","summary":null,"body":["<article data-history-node-id=\"1876\" about=\"\/en\/alerts-advisories\/sap-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-147<br \/>\nDate: 14 May 2020<\/strong><\/p>\n\n<p>On 12 May 2020 SAP released security updates to address vulnerabilities affecting several of its products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following SAP webpage and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=545396222\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=545396222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-5","alert_type":396,"serial_number":"AV20-147","subject":null,"moderation_state":"published","external_url":null},{"nid":1877,"title":"[Control systems] Emerson security advisory","uuid":"8d8421dc-0668-4819-852b-311b523683a7","banner":null,"lang":"en","date_modified":"2020-05-15","date_modified_ts":"2020-05-15T12:12:42Z","date_created":"2020-05-15T12:12:42Z","summary":null,"body":["<article data-history-node-id=\"1877\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-148<br \/>\nDate: 15 May 2020<\/strong><\/p>\n\n<p>On 14 May 2020 ICS-CERT released a security bulletin to address a vulnerability affecting Emerson WirelessHART Gateways (1410, 1420 and 1552WU). Successful exploitation of this vulnerability could allow an actor to disable the gateway\u2019s firewall, allowing the actor to issue specific commands to the end user\u2019s devices via the gateway.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-135-02)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-135-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-135-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-1","alert_type":398,"serial_number":"AV20-148","subject":null,"moderation_state":"published","external_url":null},{"nid":1878,"title":"[Control systems] Schneider Electric security advisory","uuid":"05a7d901-bcd7-444d-ab71-3654743d4bd4","banner":null,"lang":"en","date_modified":"2020-05-15","date_modified_ts":"2020-05-15T19:18:42Z","date_created":"2020-05-15T19:18:42Z","summary":null,"body":["<article data-history-node-id=\"1878\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-149<br \/>\nDate: 15 May 2020<\/strong><\/p>\n\n<p>On 12 May 2020 Schneider Electric published multiple Security Notifications highlighting vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0Pro-face GP-Pro EX Programming Software<br \/>\n\u2022\u00a0Vijeo Designer and Vijeo Designer Basic Software<br \/>\n\u2022\u00a0U.motion Servers and Touch Panels<br \/>\n\u2022\u00a0EcoStruxure Operator Terminal Expert (Vijeo XD)<br \/>\n\u2022\u00a0[various products employing] Wind River VxWorks<br \/>\n\u2022\u00a0Andover Continuum System<br \/>\n\u2022\u00a0Embedded Web Servers for Modicon<br \/>\n\u2022\u00a0Modicon Controllers<br \/>\n\u2022\u00a0Legacy Triconex Products<\/p>\n\n<p>Successful exploitation of some of these vulnerabilities may allow an actor to achieve unauthorized access, denial-of-service, information disclosure, code injection, SQL injection, path traversal and password discovery on affected systems.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>Pro-face GP-Pro EX Programming Software:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-01\/<\/a><\/p>\n\n<p>Vijeo Designer and Vijeo Designer Basic Software:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-02\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-02\/<\/a><\/p>\n\n<p>U.motion Servers and Touch Panels:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-03\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-03\/<\/a><\/p>\n\n<p>EcoStruxure Operator Terminal Expert (Vijeo XD):<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-04\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-04\/<\/a><\/p>\n\n<p>[various products employing] Wind River VxWorks:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2019-214-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2019-214-01\/<\/a><\/p>\n\n<p>Andover Continuum System:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-070-04\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-070-04\/<\/a><\/p>\n\n<p>Embedded Web Servers for Modicon:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2018-327-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2018-327-01\/<\/a><\/p>\n\n<p>Modicon Controllers:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2019-134-11\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2019-134-11\/<\/a><\/p>\n\n<p>Legacy Triconex Products:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2020-105-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2020-105-01\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-2","alert_type":398,"serial_number":"AV20-149","subject":null,"moderation_state":"published","external_url":null},{"nid":1879,"title":"Palo Alto Networks security advisory","uuid":"2be62e82-077e-4cf5-b896-2115179202f7","banner":null,"lang":"en","date_modified":"2020-05-15","date_modified_ts":"2020-05-15T19:33:21Z","date_created":"2020-05-15T19:33:21Z","summary":null,"body":["<article data-history-node-id=\"1879\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-150<br \/>\nDate: 15 May 2020<\/strong><\/p>\n\n<p>On 13 May 2020 Palo Alto Networks released security updates to address vulnerabilities in multiple versions of PAN-OS the software underlying the company\u2019s firewall products.<\/p>\n\n<p>Successful exploitation of some of these vulnerabilities could lead to authentication bypass, execution of arbitrary code, command injection and privilege escalation.\u00a0<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web link below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-2","alert_type":396,"serial_number":"AV20-150","subject":null,"moderation_state":"published","external_url":null},{"nid":1880,"title":"[Control systems] Opto 22 security advisory","uuid":"f0eaa9a7-28b9-416c-bda2-0eb53cf61d0a","banner":null,"lang":"en","date_modified":"2020-05-19","date_modified_ts":"2020-05-19T15:51:33Z","date_created":"2020-05-19T15:51:33Z","summary":null,"body":["<article data-history-node-id=\"1880\" about=\"\/en\/alerts-advisories\/control-systems-opto-22-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-151<br \/>\nDate: 19 May 2020<\/strong><\/p>\n\n<p>On 14 May 2020 ICS-CERT released a security bulletin to address vulnerabilities affecting Opto 22 SoftPAC Project version 9.6 and prior. Successful exploitation of these vulnerabilities could allow arbitrary file write access with system access, starting or stopping of the device service, remote code execution and limiting system availability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-135-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-135-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-135-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-opto-22-security-advisory","alert_type":398,"serial_number":"AV20-151","subject":null,"moderation_state":"published","external_url":null},{"nid":1882,"title":"[Control systems] ABB Cybersecurity Advisory","uuid":"7b49fb00-dc13-41d2-919e-031646bebdd4","banner":null,"lang":"en","date_modified":"2020-05-20","date_modified_ts":"2020-05-20T14:59:27Z","date_created":"2020-05-20T14:48:34Z","summary":null,"body":["<article data-history-node-id=\"1882\" about=\"\/en\/alerts-advisories\/control-systems-abb-cybersecurity-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-152<br \/>\nDate: 20 May 2020<\/strong><\/p>\n\n<p>On 14 May 2020 ABB published a <em>Cybersecurity Advisory <\/em>highlighting a vulnerability in the following product:<\/p>\n\n<p>\u2022\u00a0System800xA<\/p>\n\n<p>Successful exploitation of this vulnerability could result in the insertion and execution of arbitrary code on the Information Manager server.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>System800xA<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121232&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121232&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-cybersecurity-advisory","alert_type":398,"serial_number":"AV20-152","subject":null,"moderation_state":"published","external_url":null},{"nid":1881,"title":"[Control systems] Rockwell Automation EDS Subsystem security advisory","uuid":"2abd0bd5-0e16-4cdb-b38e-78aabd4e2cf7","banner":null,"lang":"en","date_modified":"2020-05-20","date_modified_ts":"2020-05-20T14:51:05Z","date_created":"2020-05-20T14:51:05Z","summary":null,"body":["<article data-history-node-id=\"1881\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-eds-subsystem-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-153<br \/>\nDate: 20 May 2020<\/strong><\/p>\n\n<p>On 19 May 2020 Rockwell Automation released security updates to address a vulnerability in the Automation EDS Subsystem, version 28.0.1 and prior, within the following products:<br \/>\n\u2022\u00a0FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11<br \/>\n\u2022\u00a0RSLinx Classic: Version 4.11.00 and prior<br \/>\n\u2022\u00a0RSNetWorx software: Version 28.00.00 and prior<br \/>\n\u2022\u00a0Studio 5000 Logix Designer software: Version 32 and prior<\/p>\n\n<p>A memory corruption vulnerability exists in the algorithm that matches square brackets in the EDS subsystem. This may allow an attacker to craft specialized EDS files to crash the EDSParser COM object, leading to denial-of-service conditions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-140-01)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-140-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-140-01<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-eds-subsystem-security-advisory","alert_type":398,"serial_number":"AV20-153","subject":null,"moderation_state":"published","external_url":null},{"nid":1883,"title":"Apache CouchDB security advisory","uuid":"f12cc364-b07f-456c-b8cd-3c932cbc7bf0","banner":null,"lang":"en","date_modified":"2020-05-20","date_modified_ts":"2020-05-20T16:57:26Z","date_created":"2020-05-20T16:57:26Z","summary":null,"body":["<article data-history-node-id=\"1883\" about=\"\/en\/alerts-advisories\/apache-couchdb-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-154<br \/>\nDate: 20 May 2020<\/strong><\/p>\n\n<p>On 19 May 2020 Apache released a security bulletin to address a vulnerability affecting version 3.0.0 of their CouchDB product. This version shipped with a new control that once enabled is intended to restrict unauthenticated (anonymous) database server access from all but the \u2018\/_up\u2019 endpoint.\u00a0 However, an error in the implementation of this control mistakenly allows unauthenticated access to the database server from all endpoints resulting in the potential for privilege escalation.<\/p>\n\n<p>Apache has released two new versions of CouchDB to resolve this issue; Version 3.0.1 being a bugfix release and version 3.1.0 being a feature release.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<br \/><a href=\"https:\/\/blog.couchdb.org\/\">https:\/\/blog.couchdb.org\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-couchdb-security-advisory","alert_type":396,"serial_number":"AV20-154","subject":null,"moderation_state":"published","external_url":null},{"nid":1884,"title":"Google Chrome security advisory","uuid":"c3ecb8ba-c7a0-49a4-be89-68c3352f288e","banner":null,"lang":"en","date_modified":"2020-05-20","date_modified_ts":"2020-05-20T18:34:38Z","date_created":"2020-05-20T18:34:38Z","summary":null,"body":["<article data-history-node-id=\"1884\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-155<br \/>\nDate: 20 May 2020<\/strong><\/p>\n\n<p>On 19 May 2020 Google announced the release of Chrome 83.0.4103.61 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/05\/stable-channel-update-for-desktop_19.html\">https:\/\/chromereleases.googleblog.com\/2020\/05\/stable-channel-update-for-desktop_19.html<\/a><\/p>\n\n<p>For the latest version of Chrome:<\/p>\n\n<p><a href=\"https:\/\/www.google.com\/chrome\/\">https:\/\/www.google.com\/chrome\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-25","alert_type":396,"serial_number":"AV20-155","subject":null,"moderation_state":"published","external_url":null},{"nid":1885,"title":"Cisco security advisory","uuid":"552635d0-bf62-441b-96e6-17baaeff7f23","banner":null,"lang":"en","date_modified":"2020-05-21","date_modified_ts":"2020-05-21T12:12:30Z","date_created":"2020-05-21T12:12:30Z","summary":null,"body":["<article data-history-node-id=\"1885\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-49\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-156<br \/>\nDate: 21 May 2020<\/strong><\/p>\n\n<p>On 20 May 2020 Cisco released security updates to address vulnerabilities affecting several Cisco products. Of note is a security vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) which could allow an unauthenticated, remote actor to execute arbitrary code on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-49","alert_type":396,"serial_number":"AV20-156","subject":null,"moderation_state":"published","external_url":null},{"nid":1886,"title":"ISC BIND DNS security advisory","uuid":"4465ce14-bcd6-41d9-ac2f-4ae4e4cf26be","banner":null,"lang":"en","date_modified":"2020-05-21","date_modified_ts":"2020-05-21T13:16:47Z","date_created":"2020-05-21T13:16:47Z","summary":null,"body":["<article data-history-node-id=\"1886\" about=\"\/en\/alerts-advisories\/isc-bind-dns-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-157<br \/>\nDate: 21 May 2020<\/strong><\/p>\n\n<p>On 19 May 2020 ISC released a security bulletin to address two high severity vulnerabilities affecting version 9 of their BIND DNS product. The first vulnerability only affects recursive resolvers and could allow a remote actor to use vulnerable systems as part of an amplification distributed denial of service (DDoS) attack. The second vulnerability affects both recursive resolvers and authoritative servers and could allow a remote actor to trigger an assertion error on vulnerable systems, causing them to operate in an inconsistent state and deny service to clients.<\/p>\n\n<p>ISC has released versions 9.16.3, 9.14.12 and 9.11.19 of BIND 9 to resolve these issues.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.isc.org\/blogs\/bind9-vulnerabilities-2020-05\/\">https:\/\/www.isc.org\/blogs\/bind9-vulnerabilities-2020-05\/<\/a><\/p>\n\n<p>Current versions of BIND are available for downloaded at the following link:<\/p>\n\n<p><a href=\"https:\/\/www.isc.org\/download\/\">https:\/\/www.isc.org\/download\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-dns-security-advisory","alert_type":396,"serial_number":"AV20-157","subject":null,"moderation_state":"published","external_url":null},{"nid":1887,"title":"Microsoft Windows DNS security advisory","uuid":"da913a7f-9bc6-4a8b-bfec-8a4d92cc077c","banner":null,"lang":"en","date_modified":"2020-05-21","date_modified_ts":"2020-05-21T13:21:26Z","date_created":"2020-05-21T13:21:26Z","summary":null,"body":["<article data-history-node-id=\"1887\" about=\"\/en\/alerts-advisories\/microsoft-windows-dns-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-158<br \/>\nDate: 21 May 2020<\/strong><\/p>\n\n<p>On 20 May 2020 Microsoft released a security bulletin to address a high severity vulnerability affecting all current versions of Windows DNS servers. Exploitation of this vulnerability could allow a remote actor to use vulnerable servers as part of an amplification distributed denial of service (DDoS) and cause the exploited DNS server to also become non-responsive.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and follow the recommended mitigations:<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV200009\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV200009<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-windows-dns-security-advisory","alert_type":396,"serial_number":"AV20-158","subject":null,"moderation_state":"published","external_url":null},{"nid":1888,"title":"VMware Advisory","uuid":"57100097-0ec0-44c4-aea8-cb12bd978616","banner":null,"lang":"en","date_modified":"2020-05-21","date_modified_ts":"2020-05-21T16:25:24Z","date_created":"2020-05-21T16:25:24Z","summary":null,"body":["<article data-history-node-id=\"1888\" about=\"\/en\/alerts-advisories\/vmware-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-159<br \/>\nDate: 21 May 2020<\/strong><\/p>\n\n<p>On 19 May 2020 VMware released security updates to address a vulnerability in the following versions of VMware Cloud Director (formerly known as vCloud Director):<\/p>\n\n<p>\u2022\u00a010.0.x (Linux, PhotonOS appliance)<br \/>\n\u2022\u00a09.7.x (Linux, PhotonOS appliance)<br \/>\n\u2022\u00a09.5.x (Linux, PhotonOS appliance)<br \/>\n\u2022\u00a09.1.x (Linux)<\/p>\n\n<p>A code injection vulnerability exists in affected versions of the product whereby an authenticated actor may be able to send malicious traffic to VMware Cloud Director, which may lead to arbitrary remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0010.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0010.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-advisory","alert_type":396,"serial_number":"AV20-159","subject":null,"moderation_state":"published","external_url":null},{"nid":1889,"title":"Drupal security advisory","uuid":"3dcab9bb-c91c-495e-9824-471f7d03722d","banner":null,"lang":"en","date_modified":"2020-05-22","date_modified_ts":"2020-05-22T14:44:07Z","date_created":"2020-05-22T14:44:07Z","summary":null,"body":["<article data-history-node-id=\"1889\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-160<br \/>\nDate: 22 May 2020<\/strong><\/p>\n\n<p>On 20 May 2020 Drupal released two updates to address vulnerabilities in Drupal core, including cross site scripting vulnerabilities in jQuery, a third-party component of Drupal core.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web links below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2020-002\">https:\/\/www.drupal.org\/sa-core-2020-002<\/a><\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2020-003\">https:\/\/www.drupal.org\/sa-core-2020-003<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-7","alert_type":396,"serial_number":"AV20-160","subject":null,"moderation_state":"published","external_url":null},{"nid":1890,"title":"Adobe security advisory","uuid":"bf426dd0-8f17-4a1d-8801-5f960c92fd34","banner":null,"lang":"en","date_modified":"2020-05-22","date_modified_ts":"2020-05-22T15:13:50Z","date_created":"2020-05-22T15:13:50Z","summary":null,"body":["<article data-history-node-id=\"1890\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-161<br \/>\nDate: 22 May 2020<\/strong><\/p>\n\n<p>On 19 May 2020 Adobe released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<p>\u2022\u00a0Adobe Premiere Rush<br \/>\n\u2022\u00a0Adobe Audition<br \/>\n\u2022\u00a0Adobe Premiere Pro<br \/>\n\u2022\u00a0Adobe Character Animator<\/p>\n\n<p>Of note is a vulnerability in Adobe Character Animator. Successful exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\">https:\/\/helpx.adobe.com\/security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-19","alert_type":396,"serial_number":"AV20-161","subject":null,"moderation_state":"published","external_url":null},{"nid":1891,"title":"[Control systems] Schneider Electric security advisory","uuid":"2096997a-9ece-4de8-a9d3-25eab7ad5ab7","banner":null,"lang":"en","date_modified":"2020-05-22","date_modified_ts":"2020-05-22T18:08:20Z","date_created":"2020-05-22T18:08:20Z","summary":null,"body":["<article data-history-node-id=\"1891\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-162<br \/>\nDate: 22 May 2020<\/strong><\/p>\n\n<p>On 21 May 2020 Schneider Electric published a Security Notification highlighting multiple vulnerabilities in the following product:<\/p>\n\n<p>\u2022\u00a0EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)<\/p>\n\n<p>Successful exploitation of some of these vulnerabilities may allow an actor to achieve unauthorized write access and remote code execution on affected systems.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-04\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-04\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-3","alert_type":398,"serial_number":"AV20-162","subject":null,"moderation_state":"published","external_url":null},{"nid":1892,"title":"VMware Advisory","uuid":"2a76026c-89f4-4c1e-9d53-8ea3fcdce95a","banner":null,"lang":"en","date_modified":"2020-05-26","date_modified_ts":"2020-05-26T13:59:01Z","date_created":"2020-05-26T13:59:01Z","summary":null,"body":["<article data-history-node-id=\"1892\" about=\"\/en\/alerts-advisories\/vmware-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-163<br \/>\nDate: 26 May 2020<\/strong><\/p>\n\n<p>On 8 May 2020 VMware released a security advisory that provided workarounds to mitigate vulnerabilities in SaltStack, a third party component of vRealize Operations Manager. Successful exploitation of the vulnerabilities could allow an actor to bypass authentication or traverse directories.<\/p>\n\n<p>On 15 May 2020 VMware released a security update to remediate the vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0009.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0009.html<\/a><\/p>\n\n<p>For more information on the SaltStack vulnerabilities, the Cyber Centre previously published an Alert on 5 May 2020:<\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/saltstack-vulnerabilities-actively-exploited\">https:\/\/cyber.gc.ca\/en\/alerts\/saltstack-vulnerabilities-actively-exploited<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-advisory-0","alert_type":396,"serial_number":"AV20-163","subject":null,"moderation_state":"published","external_url":null},{"nid":1893,"title":"[Control systems] Emerson security advisory","uuid":"861994e1-2633-4f81-8840-e88be1572e48","banner":null,"lang":"en","date_modified":"2020-05-26","date_modified_ts":"2020-05-26T19:36:31Z","date_created":"2020-05-26T19:36:31Z","summary":null,"body":["<article data-history-node-id=\"1893\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-164<br \/>\nDate: 26 May 2020<\/strong><\/p>\n\n<p>On 19 May 2020 ICS-CERT released a security bulletin to highlight vulnerabilities affecting Emerson OpenEnterprise SCADA Software (all versions through 3.3.4). Successful exploitation of these vulnerabilities could allow a malicious actor to perform remote code execution, modify important configuration files, and obtain OpenEnterprise user account passwords.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-140-02)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-140-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-140-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-2","alert_type":398,"serial_number":"AV20-164","subject":null,"moderation_state":"published","external_url":null},{"nid":1894,"title":"[Control systems] ABB security advisory","uuid":"68e6f87d-6490-4e0c-b7ae-36c416ad4038","banner":null,"lang":"en","date_modified":"2020-05-27","date_modified_ts":"2020-05-27T12:16:30Z","date_created":"2020-05-27T12:16:30Z","summary":null,"body":["<article data-history-node-id=\"1894\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-165<br \/>\nDate: 27 May 2020<\/strong><\/p>\n\n<p>Between 21 and 25 May 2020 ABB published multiple Cybersecurity Advisories to address vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0ABB Device Library Wizard<br \/>\n\u2022\u00a0FOX615 Multiservice-Multiplexer<br \/>\n\u2022\u00a0Relion 670, Relion 650, SAM600-IO Series<br \/>\n\u2022\u00a0AFS66x<br \/>\n\u2022\u00a0NSD570 Teleprotection Equipment<br \/>\n\u2022\u00a0ETL600 Power Line Carrier System<br \/>\n\u2022\u00a0REB500<br \/>\n\u2022\u00a0RTU500 series<\/p>\n\n<p>A low privileged actor logging into an affected ABB Device Library Wizard node could read confidential information written to an unprotected file and then take control of one or more system nodes.<\/p>\n\n<p>The other products listed above incorporate vulnerable versions of the Wind River VxWorks operating system, the successful exploitation of which could allow TCP session hijacking, packet injection and denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary manufacturer updates:<\/p>\n\n<p>ABB Device Library Wizard:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121681&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA121681&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>FOX615 Multiservice-Multiplexer:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHW003578&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHW003578&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>Relion 670, Relion 650, SAM600-IO Series:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRG035816&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRG035816&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>AFS66x:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRG000001&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRG000001&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>NSD570 Teleprotection Equipment:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHW003577&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHW003577&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>ETL600 Power Line Carrier System:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHW003576&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHW003576&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>REB500:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHL501885&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KHL501885&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>RTU500 series:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KGT090327&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1KGT090327&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-2","alert_type":398,"serial_number":"AV20-165","subject":null,"moderation_state":"published","external_url":null},{"nid":1895,"title":"Apple security advisory","uuid":"5010497a-a2a4-425f-9563-e48061e03bcb","banner":null,"lang":"en","date_modified":"2020-05-28","date_modified_ts":"2020-05-28T15:17:16Z","date_created":"2020-05-28T15:17:16Z","summary":null,"body":["<article data-history-node-id=\"1895\" about=\"\/en\/alerts-advisories\/apple-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-166<br \/>\nDate: 28 May 2020<\/strong><\/p>\n\n<p>On 26 May 2020 Apple released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<p>\u2022\u00a0macOS Catalina 10.15.5, Security Update 2020-003 Mojave and Security Update 2020-003 High Sierra<br \/>\n\u2022\u00a0Windows Migration Assistant 2.2.0.0 (v. 1A11)<br \/>\n\u2022\u00a0Safari 13.1.1<br \/>\n\u2022\u00a0iCloud for Windows 11.2<br \/>\n\u2022\u00a0iCloud for Windows 7.19<\/p>\n\n<p>Some of these vulnerabilities could be exploited to allow arbitrary code execution with kernel privileges, remote code execution, command execution, privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates:<\/p>\n\n<p>macOS Catalina 10.15.5, Security Update 2020-003 Mojave and Security Update 2020-003 High Sierra:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT211170\">https:\/\/support.apple.com\/kb\/HT211170<\/a><\/p>\n\n<p>Windows Migration Assistant 2.2.0.0 (v. 1A11):<\/p>\n\n<p><a href=\"http:\/\/support.apple.com\/kb\/HT211186\">http:\/\/support.apple.com\/kb\/HT211186<\/a><\/p>\n\n<p>Safari 13.1.1:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT211177\">https:\/\/support.apple.com\/kb\/HT211177<\/a><\/p>\n\n<p>iCloud for Windows 11.2:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT211179\">https:\/\/support.apple.com\/kb\/HT211179<\/a><\/p>\n\n<p>iCloud for Windows 7.19:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT211181\">https:\/\/support.apple.com\/kb\/HT211181<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-11","alert_type":396,"serial_number":"AV20-166","subject":null,"moderation_state":"published","external_url":null},{"nid":1896,"title":"[Control systems] Johnson Controls security advisory","uuid":"ea56c904-2979-4b99-8b5b-a9fb17b21ff4","banner":null,"lang":"en","date_modified":"2020-05-29","date_modified_ts":"2020-05-29T18:48:07Z","date_created":"2020-05-29T18:48:07Z","summary":null,"body":["<article data-history-node-id=\"1896\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-167<br \/>\nDate: 29 May 2020<\/strong><\/p>\n\n<p>Johnson Controls published security advisories to address vulnerabilities in some of its products. Successful exploitation of these vulnerabilities could allow a malicious actor to gain full system-level privileges or access credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>EntraPass Security Management Software<\/p>\n\n<p><a href=\"https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020-6-v1-kantech-entrapass-security-management-software.pdf\">https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020-6-v1-kantech-entrapass-security-management-software.pdf<\/a><\/p>\n\n<p>C\u2022CURE 9000\/victor<\/p>\n\n<p><a href=\"https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020_4-v2-software-house-ccure-9000-and-american-dynamics-victor.pdf\">https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020_4-v2-software-house-ccure-9000-and-american-dynamics-victor.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-0","alert_type":398,"serial_number":"AV20-167","subject":null,"moderation_state":"published","external_url":null},{"nid":1898,"title":"Cisco Advisory","uuid":"29c472d9-1a7d-4644-ae6c-3dab954a7ab3","banner":null,"lang":"en","date_modified":"2020-06-01","date_modified_ts":"2020-06-01T19:38:15Z","date_created":"2020-06-01T13:47:34Z","summary":null,"body":["<article data-history-node-id=\"1898\" about=\"\/en\/alerts-advisories\/cisco-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>\u00a0<\/p>\n\n<p><strong>Number: AV20-168<br \/>\nDate: 1 June 2020<\/strong><\/p>\n\n<p>On 28 May 2020 Cisco released a security update to address vulnerabilities in SaltStack, a third-party component of:<\/p>\n\n<ul><li>Cisco Modeling Labs Corporate Edition (CML)<\/li>\n\t<li>Cisco Virtual Internet Routing Lab Personal Edition (VIRL-PE)<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could allow an actor to bypass authentication or traverse directories.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-salt-2vx545AG\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-salt-2vx545AG<\/a><\/p>\n\n<p>For more information on the SaltStack vulnerabilities, please refer to the Cyber Centre\u2019s Alert of 5 May 2020:<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/saltstack-vulnerabilities-actively-exploited\">https:\/\/cyber.gc.ca\/en\/alerts\/saltstack-vulnerabilities-actively-exploited<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-advisory","alert_type":396,"serial_number":"AV20-168","subject":null,"moderation_state":"published","external_url":null},{"nid":1897,"title":"[Control systems] Inductive Automation security advisory","uuid":"e3b1d69e-f885-46a0-b6c6-7f2aa792aed5","banner":null,"lang":"en","date_modified":"2020-06-01","date_modified_ts":"2020-06-01T19:31:43Z","date_created":"2020-06-01T19:31:43Z","summary":null,"body":["<article data-history-node-id=\"1897\" about=\"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-169<br \/>\nDate: 1 June 2020<\/strong><\/p>\n\n<p>On 26 May 2020 US-CERT published a security bulletin to highlight several vulnerabilities in versions of Inductive Automation\u2019s Ignition 8 Gateway prior to 8.0.10. Successful exploitation of these vulnerabilities could allow an actor to obtain sensitive information and perform remote code execution with SYSTEM privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-147-01)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-147-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-147-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-0","alert_type":398,"serial_number":"AV20-169","subject":null,"moderation_state":"published","external_url":null},{"nid":1900,"title":"Cisco security advisory","uuid":"4a2f9129-b4a2-4c60-b4a3-e4b016834b09","banner":null,"lang":"en","date_modified":"2020-06-02","date_modified_ts":"2020-06-02T13:39:05Z","date_created":"2020-06-02T13:10:32Z","summary":null,"body":["<article data-history-node-id=\"1900\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-50\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-171 <\/strong><br \/><strong>Date:\u00a02 June 2020<\/strong><\/p>\n\n<p>On 1 June 2020 Cisco published multiple Security Advisories highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco NX-OS Software<\/li>\n\t<li>Cisco UCS C-Series Rack Servers<\/li>\n<\/ul><p>Successful exploitation of some of these vulnerabilities may allow an actor to cause a denial of service condition or load a compromised software image on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p>Cisco NX-OS Software:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-ipip-dos-kCT9X4\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-ipip-dos-kCT9X4<\/a><\/p>\n\n<p>Cisco UCS C-Series Rack Servers:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20200219-ucs-boot-bypass\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-20200219-ucs-boot-bypass<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-50","alert_type":396,"serial_number":"AV20-171","subject":null,"moderation_state":"published","external_url":null},{"nid":1899,"title":"[Control systems] ABB security advisory","uuid":"364f69ad-6893-4d19-b795-0bbb6788f5c7","banner":null,"lang":"en","date_modified":"2020-06-02","date_modified_ts":"2020-06-02T13:25:36Z","date_created":"2020-06-02T13:11:04Z","summary":null,"body":["<article data-history-node-id=\"1899\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-170<br \/>\nDate: 2 June 2020<\/strong><\/p>\n\n<p>ABB published a security advisory to address a vulnerability in its CI845 Ethernet Fieldbus Communication Interface Module which incorporates a vulnerable version of the Wind River VxWorks operating system. Successful exploitation of this vulnerability could allow a malicious actor to cause a denial of service condition on the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link, follow recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ABB Security Advisory<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA120777&amp;LanguageCode=en&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA120777&amp;LanguageCode=en&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-3","alert_type":398,"serial_number":"AV20-170","subject":null,"moderation_state":"published","external_url":null},{"nid":1901,"title":"Mozilla security advisory","uuid":"ba32a3eb-8a19-4ddc-8849-ec17f11e0dbd","banner":null,"lang":"en","date_modified":"2020-06-02","date_modified_ts":"2020-06-02T17:45:17Z","date_created":"2020-06-02T17:45:17Z","summary":null,"body":["<article data-history-node-id=\"1901\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-172<br \/>\nDate: 2 June 2020<\/strong><\/p>\n\n<p>On 2 June 2020 Mozilla published multiple <em>Cybersecurity Advisories <\/em>highlighting vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0Firefox ESR 68.9<br \/>\n\u2022\u00a0Firefox 77<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p>Firefox ESR 68.9<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-21\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-21\/<\/a><\/p>\n\n<p>Firefox 77<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-20\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-20\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-15","alert_type":396,"serial_number":"AV20-172","subject":null,"moderation_state":"published","external_url":null},{"nid":1903,"title":"Android security advisory","uuid":"5d32f6e0-63b4-4952-8f84-adc2a5ffd000","banner":null,"lang":"en","date_modified":"2020-06-03","date_modified_ts":"2020-06-03T16:30:28Z","date_created":"2020-06-03T16:30:28Z","summary":null,"body":["<article data-history-node-id=\"1903\" about=\"\/en\/alerts-advisories\/android-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-173<br \/>\nDate: 3 June 2020<\/strong><\/p>\n\n<p>On 1 June 2020 Android announced the release of updates to address multiple vulnerabilities affecting Android devices.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-06-01\">https:\/\/source.android.com\/security\/bulletin\/2020-06-01<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-12","alert_type":396,"serial_number":"AV20-173","subject":null,"moderation_state":"published","external_url":null},{"nid":1902,"title":"Apple security advisory","uuid":"67fcce15-973b-4fc1-ac2b-41ac5a532f31","banner":null,"lang":"en","date_modified":"2020-06-03","date_modified_ts":"2020-06-03T16:38:02Z","date_created":"2020-06-03T16:38:02Z","summary":null,"body":["<article data-history-node-id=\"1902\" about=\"\/en\/alerts-advisories\/apple-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-174<br \/>\nDate: 3 June 2020<\/strong><\/p>\n\n<p>On 1 June 2020 Apple released security updates to address multiple vulnerabilities affecting the following products:<\/p>\n\n<p>\u2022\u00a0macOS Catalina 10.15.5<br \/>\n\u2022\u00a0tvOS 13.4.6<br \/>\n\u2022\u00a0watchOS 6.2.6<br \/>\n\u2022\u00a0iOS 13.5.1 and iPadOS 13.5.1<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following and apply the necessary updates:<\/p>\n\n<p>macOS Catalina 10.15.5:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT211215\">https:\/\/support.apple.com\/en-us\/HT211215<\/a><\/p>\n\n<p>tvOS 13.4.6:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT211216\">https:\/\/support.apple.com\/en-us\/HT211216<\/a><\/p>\n\n<p>watchOS 6.2.6:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT211217\">https:\/\/support.apple.com\/en-us\/HT211217<\/a><\/p>\n\n<p>iOS 13.5.1 and iPadOS 13.5.1:<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT211214\">https:\/\/support.apple.com\/en-us\/HT211214<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-12","alert_type":396,"serial_number":"AV20-174","subject":null,"moderation_state":"published","external_url":null},{"nid":1904,"title":"Continued exploitation of Exim vulnerability","uuid":"220c2803-f966-4fa4-a96d-f517a8711129","banner":null,"lang":"en","date_modified":"2020-06-04","date_modified_ts":"2020-06-04T13:21:26Z","date_created":"2020-06-04T12:27:20Z","summary":null,"body":["<article data-history-node-id=\"1904\" about=\"\/en\/alerts-advisories\/continued-exploitation-exim-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>\u00a0\n<\/p>\n<p><strong>Number: AL20-017\n  <br \/>\n  Date:\u00a03 June 2020<\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2><strong>PURPOSE<\/strong>\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2><strong>ASSESSMENT<\/strong>\n<\/h2>\n<p>The Cyber Centre is aware of continued exploitation of the Exim vulnerability (CVE-2019-10149), described in Alert AL19-012, published on 14 June 2019. Activity as recent as May 2020 has reportedly resulted in the compromise of Canadian victims.\n<\/p>\n<p>\n  <br \/>\n  Exploitation is initiated when a local or remote actor sends a command within a specially crafted email to a vulnerable Exim mail server. If successful, the injected command will execute as the message transfer agent (MTA) process owner (in most instances this is the system root account).\n  <br \/>\n  Successful exploitation of the vulnerability could result in the compromise of additional Exim servers, the installation of malware such as crypto mining software [Reference 1] or further infiltration of an organization\u2019s network. The malicious commands may also attempt to gain persistence on the affected server by weakening security controls and adding additional user accounts to allow the actor remote access.\n<\/p>\n<h2><strong>RECOMMENDED ACTIONS<\/strong>\n<\/h2>\n<p>The Cyber Centre recommends investigating potentially vulnerable systems to identify any changes that could indicate a successful compromise such as:\n<\/p>\n<ul><li>Examine system logs for unusual or unauthorized activity.<\/li>\n  <li>Examine all cron jobs for any unauthorized entries.<\/li>\n  <li>If SSH is enabled on the server, ensure that the SSH server configuration file has not been edited to include unknown or suspicious changes and examine locally installed RSA authentication keys for any unauthorised additions.<\/li>\n  <li>Monitor for any unusual SSH connections to the server.<\/li>\n  <li>Check for recently added users with elevated privileges.<\/li>\n  <li>Ensure there are no new privileged database user accounts.<\/li>\n  <li>Ensure that firewall rules have not been modified in an effort to weaken security controls.<\/li>\n<\/ul><h2><strong>MITIGATION and MONITORING<\/strong>\n<\/h2>\n<p>The Cyber Centre recommends the following actions to defend and detect exploitation attempts of potentially vulnerable systems:\n<\/p>\n<ul><li>Retrieve the latest patches for vulnerable versions of Exim and upgrade to the latest supported version. [Reference 2]<\/li>\n  <li>Inspect mail logs to identify suspicious records within the \u201cRCPT TO or MAIL FROM\u201d fields.\u00a0 An example of patterns which would indicate attempts to compromise would resemble the following examples: [Reference 3 and 4]\n    <ul><li>MAIL FROM:&lt;${run{<\/li>\n      <li>RCPT TO:&lt;${run{<\/li>\n    <\/ul><\/li>\n  <li>ProofPoint Emerging Threats released a detection rule (SID: 2027442) for Suricata Intrusion Detection Systems (IDS) on 21 June 2019 to assist the detection of malicious activity matching the RCPT TO pattern. [Reference 5]<\/li>\n  <li>Review IOCs originally provided in CCCS Alert AL19-012 [Reference 6] and alternate methods of detection and mitigation included in referenced NSA publication. [Reference 4]<\/li>\n<\/ul><h2><strong>REFERENCES<\/strong>\n<\/h2>\n<p>[Reference 1] Reported compromise for the purpose of crypto-currency mining:\n  <br \/><a href=\"https:\/\/www.cybereason.com\/blog\/new-pervasive-worm-exploiting-linux-exim-server-vulnerability\">https:\/\/www.cybereason.com\/blog\/new-pervasive-worm-exploiting-linux-exim-server-vulnerability<\/a>\n<\/p>\n<p>[Reference 2] To download the latest Exim updates:\n  <br \/><a href=\"https:\/\/exim.org\/mirrors.html\">https:\/\/exim.org\/mirrors.html<\/a>\n<\/p>\n<p>[Reference 3] Early reporting of CVE-2019-10149\n  <br \/><a href=\"https:\/\/www.qualys.com\/2019\/06\/05\/cve-2019-10149\/return-wizard-rce-exim.txt\">https:\/\/www.qualys.com\/2019\/06\/05\/cve-2019-10149\/return-wizard-rce-exim.txt<\/a>\n<\/p>\n<p>[Reference 4] National Security Agency (US) Report describing CVE-2019-10149:\n  <br \/><a href=\"https:\/\/media.defense.gov\/2020\/May\/28\/2002306626\/-1\/-1\/0\/CSA%20Sandworm%20Actors%20Exploiting%20Vulnerability%20in%20Exim%20Transfer%20Agent%2020200528.pdf\">https:\/\/media.defense.gov\/2020\/May\/28\/2002306626\/-1\/-1\/0\/CSA%20Sandworm%20Actors%20Exploiting%20Vulnerability%20in%20Exim%20Transfer%20Agent%2020200528.pdf<\/a>\n<\/p>\n<p>[Reference 5] Emerging Threats Suricata signature for CVE-2019-10149:\n  <br \/><a href=\"https:\/\/doc.emergingthreats.net\/bin\/view\/Main\/2027442\">https:\/\/doc.emergingthreats.net\/bin\/view\/Main\/2027442<\/a>\n<\/p>\n<p>[Reference 6] CCCS Alert AL19-012 on Exim vulnerability:\n  <br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/active-exploitation-exim-vulnerability-observed-wild\">https:\/\/www.cyber.gc.ca\/en\/alerts\/active-exploitation-exim-vulnerability-observed-wild<\/a>\n<\/p>\n<p>\n  <br \/><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<p>The Cyber Centre can be contacted at:\n  <br \/>\n  Email: <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>\n  <br \/>\n  Toll Free: <a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> <a href=\"tel:+1-833-292-3788\">(1-833-292-3788)<\/a>\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/continued-exploitation-exim-vulnerability","alert_type":397,"serial_number":"AL20-017","subject":null,"moderation_state":"published","external_url":null},{"nid":1905,"title":"[Control systems] GE security advisory","uuid":"d68b1615-cb40-40d4-aa47-ee0cbbf49b20","banner":null,"lang":"en","date_modified":"2020-06-04","date_modified_ts":"2020-06-04T15:51:56Z","date_created":"2020-06-04T15:51:56Z","summary":null,"body":["<article data-history-node-id=\"1905\" about=\"\/en\/alerts-advisories\/control-systems-ge-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-175<br \/>\nDate:\u00a04 June 2020<\/strong><\/p>\n\n<p>On 2 June 2020 ICS-CERT published a security advisory to highlight a vulnerability in the GE Grid Solutions Reason RT Clocks.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-154-05\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-154-05<\/a><\/p>\n\n<p>The vulnerability, if successfully exploited, could allow a malicious actor to execute arbitrary code, change the configuration of the device or cause a denial of service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-security-advisory-0","alert_type":398,"serial_number":"AV20-175","subject":null,"moderation_state":"published","external_url":null},{"nid":1906,"title":"Google Chrome security advisory","uuid":"fa8fbc86-e374-4442-88e9-b88a0bbdeaa6","banner":null,"lang":"en","date_modified":"2020-06-04","date_modified_ts":"2020-06-04T15:55:52Z","date_created":"2020-06-04T15:55:52Z","summary":null,"body":["<article data-history-node-id=\"1906\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-176<br \/>\nDate:\u00a04 June 2020<\/strong><\/p>\n\n<p>On 3 June 2020 Google announced the release of Chrome 83.0.4103.97 for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/06\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/06\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-26","alert_type":396,"serial_number":"AV20-176","subject":null,"moderation_state":"published","external_url":null},{"nid":1907,"title":"Cisco security advisory","uuid":"a260a072-1a14-4252-842f-ad24a13268b2","banner":null,"lang":"en","date_modified":"2020-06-04","date_modified_ts":"2020-06-04T16:00:20Z","date_created":"2020-06-04T16:00:20Z","summary":null,"body":["<article data-history-node-id=\"1907\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-51\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-177<br \/>\nDate:\u00a04 June 2020<\/strong><\/p>\n\n<p>On 3 June 2020 Cisco released several security advisories to address vulnerabilities in several of its products.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p>Of note are critical vulnerabilities affecting Cisco IOS XE Software and Cisco IOS Software for Cisco Industrial Routers.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-51","alert_type":396,"serial_number":"AV20-177","subject":null,"moderation_state":"published","external_url":null},{"nid":1908,"title":"[Control systems] SWARCO security advisory","uuid":"1d769255-277a-4f50-8275-1343321cc5e0","banner":null,"lang":"en","date_modified":"2020-06-04","date_modified_ts":"2020-06-04T16:03:50Z","date_created":"2020-06-04T16:03:50Z","summary":null,"body":["<article data-history-node-id=\"1908\" about=\"\/en\/alerts-advisories\/control-systems-swarco-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-178<br \/>\nDate:\u00a04 June 2020<\/strong><\/p>\n\n<p>On 2 June 2020 ICS-CERT published a security advisory to highlight a vulnerability in the SWARCO CPU LS4000.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-154-06\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-154-06<\/a><\/p>\n\n<p>The vulnerability, if successfully exploited, could allow a remote malicious actor to gain root access to an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-swarco-security-advisory","alert_type":398,"serial_number":"AV20-178","subject":null,"moderation_state":"published","external_url":null},{"nid":1909,"title":"IBM security advisory","uuid":"7c86f2fc-b72e-4c63-be7e-f4805d613752","banner":null,"lang":"en","date_modified":"2020-06-09","date_modified_ts":"2020-06-09T13:16:27Z","date_created":"2020-06-09T13:16:27Z","summary":null,"body":["<article data-history-node-id=\"1909\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-179<br \/>\nDate: 9 June 2020<\/strong><\/p>\n\n<p>On 4 June 2020 IBM released security updates to address critical vulnerabilities in IBM products, including:<\/p>\n\n<p>\u2022\u00a0WebSphere Application Server ND<br \/>\n\u2022\u00a0WebSphere Virtual Enterprise<br \/>\n\u2022\u00a0WebSphere Application Server<\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow a remote actor to execute arbitrary code on the system with a specially crafted sequence of serialized objects from untrusted sources.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p>WebSphere Application Server ND and WebSphere Virtual Enterprise:<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6220336\">https:\/\/www.ibm.com\/support\/pages\/node\/6220336<\/a><\/p>\n\n<p>WebSphere Application Server:<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6220294\">https:\/\/www.ibm.com\/support\/pages\/node\/6220294<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-1","alert_type":396,"serial_number":"AV20-179","subject":null,"moderation_state":"published","external_url":null},{"nid":1910,"title":"[Control systems] SIEMENS security advisory","uuid":"d8ec80ab-91ec-4d26-b4e7-220f43232abd","banner":null,"lang":"en","date_modified":"2020-06-10","date_modified_ts":"2020-06-10T12:38:48Z","date_created":"2020-06-10T12:16:37Z","summary":null,"body":["<article data-history-node-id=\"1910\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-180<br \/>\nDate: 10 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 Siemens released security updates to address multiple vulnerabilities in Siemens products, including:<\/p>\n\n<ul><li>Siemens Windows-based Industrial Software Applications<\/li>\n\t<li>Multiple SIMATIC Software<\/li>\n\t<li>SIEMENS LOGO!<\/li>\n\t<li>SINUMERIK<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow for local privilege escalation, remote code execution, denial of service, access to and altering of device configuration and unintended information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p>Unquoted search path vulnerabilities in multiple Windows-based industrial software applications:<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-312271.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-312271.pdf<\/a><\/p>\n\n<p>Denial-of-Service and DLL hijacking vulnerabilities in multiple SIMATIC software products:<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-689942.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-689942.pdf<\/a><\/p>\n\n<p>Missing authentication vulnerability in SIEMENS LOGO!:<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-817401.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-817401.pdf<\/a><\/p>\n\n<p>UltraVNC vulnerabilities within SINUMERIK products:<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-927095.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-927095.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-10","alert_type":398,"serial_number":"AV20-180","subject":null,"moderation_state":"published","external_url":null},{"nid":1913,"title":"[Control systems] SIEMENS security advisory (update G)","uuid":"5e3e965f-e81b-4502-a124-f51b0fa19f00","banner":null,"lang":"en","date_modified":"2020-06-10","date_modified_ts":"2020-06-10T12:56:11Z","date_created":"2020-06-10T12:20:59Z","summary":null,"body":["<article data-history-node-id=\"1913\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-update-g\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-182 \n  <br \/>\n  Date: 10 June 2020<\/strong>\n<\/p>\n<p>On 9 June 2020 Siemens released an update to their previously released Industrial Products Advisory ICSA-19-253-03. Update G provides additional information on affected products and methods of exploitation.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:\n  <br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-19-253-03<\/a>\n<\/p>\n<p><strong>Note to Readers<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-update-g","alert_type":398,"serial_number":"AV20-182","subject":null,"moderation_state":"published","external_url":null},{"nid":1911,"title":"Adobe security advisory","uuid":"b07c351d-57b2-4d9a-b4d2-8e0b2d07951e","banner":null,"lang":"en","date_modified":"2020-06-10","date_modified_ts":"2020-06-10T12:40:30Z","date_created":"2020-06-10T12:22:55Z","summary":null,"body":["<article data-history-node-id=\"1911\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-181<br \/>\nDate: 10 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 Adobe published multiple Security Advisories highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Framemaker<\/li>\n\t<li>Adobe Experience Manager<\/li>\n\t<li>Adobe Flash Player<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following and apply the necessary manufacturer updates:<\/p>\n\n<p>Adobe Framemaker:<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb20-32.html\">https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb20-32.html<\/a><\/p>\n\n<p>Adobe Experience Manager:<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb20-31.html\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb20-31.html<\/a><\/p>\n\n<p>Adobe Flash Player:<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb20-30.html\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb20-30.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-20","alert_type":396,"serial_number":"AV20-181","subject":null,"moderation_state":"published","external_url":null},{"nid":1912,"title":"[Control systems] Advantech security advisory","uuid":"cb2da0b5-ad5e-4368-81bb-5413584d86d1","banner":null,"lang":"en","date_modified":"2020-06-10","date_modified_ts":"2020-06-10T12:56:41Z","date_created":"2020-06-10T12:25:48Z","summary":null,"body":["<article data-history-node-id=\"1912\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-183\n  <br \/>Date: 10 June 2020<\/strong>\n<\/p>\n<p>On 9 June 2020 US-CERT published an ICS advisory to highlight a critical vulnerability in Advantech WebAccess Node, Version 8.4.4 and prior.\n<\/p>\n<p>Successful exploitation of this vulnerability by a remote actor could crash the application and may allow remote code execution.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates:\n  <br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-161-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-161-01<\/a>\n<\/p>\n<p><strong>Note to Readers<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-5","alert_type":398,"serial_number":"AV20-183","subject":null,"moderation_state":"published","external_url":null},{"nid":1914,"title":"Microsoft security advisory \u2013 June 2020 monthly rollup","uuid":"bd5fdc2c-e09b-48a4-96e9-698729ed30ff","banner":null,"lang":"en","date_modified":"2020-06-10","date_modified_ts":"2020-06-10T13:26:30Z","date_created":"2020-06-10T13:26:30Z","summary":null,"body":["<article data-history-node-id=\"1914\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-june-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-184<br \/>\nDate: 10 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 Microsoft released security updates to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Adobe Flash Player<\/li>\n\t<li>ChakraCore<\/li>\n\t<li>Internet Explorer<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft SharePoint<\/li>\n\t<li>Windows Workstation and Server<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.\u00a0<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:\u00a0<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Jun\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Jun<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-june-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-184","subject":null,"moderation_state":"published","external_url":null},{"nid":1915,"title":"[Control systems] OSIsoft PI System security advisory (update A)","uuid":"d7a56faf-a096-49ae-940d-b38450e39c1c","banner":null,"lang":"en","date_modified":"2020-06-10","date_modified_ts":"2020-06-10T18:28:58Z","date_created":"2020-06-10T18:28:58Z","summary":null,"body":["<article data-history-node-id=\"1915\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-pi-system-security-advisory-update\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-185<br \/>\nDate: 10 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 US-CERT published an update to their previously released OSIsoft Industrial Products Advisory ICSA-20-133-02. Update A provides additional information on affected products and further action that should be taken after applying security updates.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-133-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-133-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-pi-system-security-advisory-update","alert_type":398,"serial_number":"AV20-185","subject":null,"moderation_state":"published","external_url":null},{"nid":1916,"title":"VMware security advisory","uuid":"85f6a544-bf55-425a-b7c8-5c1ce7b5892b","banner":null,"lang":"en","date_modified":"2020-06-11","date_modified_ts":"2020-06-11T12:10:09Z","date_created":"2020-06-11T12:10:09Z","summary":null,"body":["<article data-history-node-id=\"1916\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-186<br \/>\nDate: 11 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 VMware released security updates to address a vulnerability in the VMware Horizon Client for Windows.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0013.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0013.html<\/a><\/p>\n\n<p>The vulnerability, if successfully exploited, could allow a local malicious actor to escalate privileges and run commands as any user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-27","alert_type":396,"serial_number":"AV20-186","subject":null,"moderation_state":"published","external_url":null},{"nid":1917,"title":"SAP security advisory \u2013 June 2020 monthly rollup","uuid":"7bf5a0a0-2329-43aa-8131-c8b28036ff1b","banner":null,"lang":"en","date_modified":"2020-06-11","date_modified_ts":"2020-06-11T12:14:51Z","date_created":"2020-06-11T12:14:51Z","summary":null,"body":["<article data-history-node-id=\"1917\" about=\"\/en\/alerts-advisories\/sap-security-advisory-june-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-187<br \/>\nDate: 11 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 SAP released security updates to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>SAP Liquidity Management for Banking<\/li>\n\t<li>SAP Commerce<\/li>\n\t<li>SAP Commerce (Data Hub)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.\u00a0<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=547426775\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=547426775<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-june-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-187","subject":null,"moderation_state":"published","external_url":null},{"nid":1918,"title":"[Control systems] Schneider Electric security advisory","uuid":"3b41fe41-4d7c-48bf-a855-b654d2018738","banner":null,"lang":"en","date_modified":"2020-06-11","date_modified_ts":"2020-06-11T12:25:43Z","date_created":"2020-06-11T12:21:53Z","summary":null,"body":["<article data-history-node-id=\"1918\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-188<br \/>\nDate: 11 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 Schneider Electric published a Security Notification highlighting multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>Modicon M218 Logic Controller<\/li>\n\t<li>Unity Loader and OS Loader Software<\/li>\n\t<li>Modicon LMC078 Logic Controller<\/li>\n\t<li>Easergy T300<\/li>\n\t<li>Easergy Builder<\/li>\n\t<li>Wind River VxWorks (URGENT\/11)<\/li>\n\t<li>EcoStruxure\u2122 Operator Terminal Expert (Vijeo XD)<\/li>\n\t<li>GoAhead Web Server<\/li>\n<\/ul><p>Successful exploitation of some of these vulnerabilities may allow an actor to achieve unauthorized access via hard-coded credentials, remote code execution and denial of service on affected systems.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>Modicon M218 Logic Controller:<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-01\/<\/a><\/p>\n\n<p>Unity Loader and OS Loader Software:<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-02\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-02\/<\/a><\/p>\n\n<p>Modicon LMC078 Logic Controller:<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-03\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-03\/<\/a><\/p>\n\n<p>Easergy T300:<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-04\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-04\/<\/a><\/p>\n\n<p>Easergy Builder:<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-05\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-161-05\/<\/a><\/p>\n\n<p>Wind River VxWorks (URGENT\/11):<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2019-214-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2019-214-01\/<\/a><\/p>\n\n<p>EcoStruxure\u2122 Operator Terminal Expert (Vijeo XD):<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-04\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-133-04\/<\/a><\/p>\n\n<p>GoAhead Web Server:<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2015-344-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2015-344-01\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-4","alert_type":398,"serial_number":"AV20-188","subject":null,"moderation_state":"published","external_url":null},{"nid":1919,"title":"Intel security advisory","uuid":"ece2bd1a-c947-4d74-843d-0878e20d892d","banner":null,"lang":"en","date_modified":"2020-06-11","date_modified_ts":"2020-06-11T19:36:00Z","date_created":"2020-06-11T19:12:41Z","summary":null,"body":["<article data-history-node-id=\"1919\" about=\"\/en\/alerts-advisories\/intel-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-189\n  <br \/>\n  Date: 11 June 2020<\/strong>\n<\/p>\n<p>On 9 June 2020 Intel released security updates to multiple products. Included was 2020.1 Intel Product Update (IPU) which addresses vulnerabilities that Intel has rated as critical, affecting:\n<\/p>\n<ul><li>Intel Active Management Technology (AMT)<\/li>\n  <li>Intel Standard Manageability (ISM)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.\u00a0\n  <br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a>\n<\/p>\n<p><strong>Note to Readers<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-12","alert_type":396,"serial_number":"AV20-189","subject":null,"moderation_state":"published","external_url":null},{"nid":1920,"title":"Samsung Mobile security advisory \u2013 June 2020 monthly rollup","uuid":"5e95e32e-14fa-46be-835d-da82ba235c8e","banner":null,"lang":"en","date_modified":"2020-06-12","date_modified_ts":"2020-06-12T12:22:07Z","date_created":"2020-06-12T12:19:09Z","summary":null,"body":["<article data-history-node-id=\"1920\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-june-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-190<br \/>\nDate: 12 June 2020<\/strong><\/p>\n\n<p>On 11 June 2020 Samsung Mobile made a maintenance release available for its major flagship models as part of their Security Maintenance Release (SMR) process. This release contains security updates from both Samsung and Google\u2019s Android OS to address vulnerabilities in multiple products. Included was a critical patch for the following:<\/p>\n\n<ul><li>Samsung Kinibi<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following link and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb\">https:\/\/security.samsungmobile.com\/securityUpdate.smsb<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-june-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-190","subject":null,"moderation_state":"published","external_url":null},{"nid":1921,"title":"IBM security advisory","uuid":"b5e830d0-21d0-4995-be59-a2c3ed73a852","banner":null,"lang":"en","date_modified":"2020-06-12","date_modified_ts":"2020-06-12T16:32:16Z","date_created":"2020-06-12T16:32:16Z","summary":null,"body":["<article data-history-node-id=\"1921\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-191<br \/>\nDate: 12 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 IBM released a security update to address multiple vulnerabilities in a third-party component that ships with IBM Global Mailbox. By sending specially crafted input, a remote actor could exploit unsafe deserializations in the FasterXML Jackson databind library and execute arbitrary code on the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6221228\">https:\/\/www.ibm.com\/support\/pages\/node\/6221228<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-2","alert_type":396,"serial_number":"AV20-191","subject":null,"moderation_state":"published","external_url":null},{"nid":1922,"title":"WordPress security advisory","uuid":"a95250f7-5795-4476-b1c6-b4fbd0e6c832","banner":null,"lang":"en","date_modified":"2020-06-12","date_modified_ts":"2020-06-12T17:50:10Z","date_created":"2020-06-12T17:49:16Z","summary":null,"body":["<article data-history-node-id=\"1922\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>\n  <br \/><strong>Number: AV20-192\n  <br \/>\n  Date: 12 June 2020<\/strong>\n<\/p>\n<p>On 10 June 2020 WordPress released version 5.4.2, which includes several security fixes for privately disclosed vulnerabilities.\n  <br \/><a href=\"https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/\">https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/<\/a>\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n  <br \/><\/p>\n<p><strong>Note to Readers<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-3","alert_type":396,"serial_number":"AV20-192","subject":null,"moderation_state":"published","external_url":null},{"nid":1923,"title":"[Control systems] OSIsoft PI Web API 2019 security advisory","uuid":"4b32244f-10e2-4399-9d31-d818f265a162","banner":null,"lang":"en","date_modified":"2020-06-15","date_modified_ts":"2020-06-15T12:19:30Z","date_created":"2020-06-15T12:19:30Z","summary":null,"body":["<article data-history-node-id=\"1923\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-pi-web-api-2019-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-193<br \/>\nDate: 15 June 2020<\/strong><\/p>\n\n<p>On 11 June 2020 US-CERT published an OSIsoft Industrial Products Advisory ICSA-20-163-01 concerning a cross-site-scripting vulnerability in the PI Web API.<\/p>\n\n<p>Successful exploitation of this vulnerability by a remote authenticated actor with write access to a PI Server could convince a user to interact with a PI Web API endpoint and execute arbitrary JavaScript in the user\u2019s browser.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-163-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-163-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-pi-web-api-2019-security-advisory","alert_type":398,"serial_number":"AV20-193","subject":null,"moderation_state":"published","external_url":null},{"nid":1924,"title":"[Control systems] Rockwell Automation security advisory","uuid":"18ed9937-7a4f-4839-acb8-5fd7f645f77b","banner":null,"lang":"en","date_modified":"2020-06-15","date_modified_ts":"2020-06-15T12:24:58Z","date_created":"2020-06-15T12:24:58Z","summary":null,"body":["<article data-history-node-id=\"1924\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-194<br \/>\nDate: 15 June 2020<\/strong><\/p>\n\n<p>On 11 June 2020 US-CERT published an advisory for Rockwell Automation FactoryTalk Linx Software to address a vulnerability in an exposed API call allowing users to provide files to be processed without sanitation. This may allow an attacker to specify a filename to execute unauthorized code and modify files or data.<\/p>\n\n<p>The following products are affected:<\/p>\n\n<p>\u2022\u00a0FactoryTalk Linx versions 6.00, 6.10, and 6.11<br \/>\n\u2022\u00a0RSLinx Classic v4.11.00 and prior<\/p>\n\n<p>The following products that utilize FactoryTalk Linx Software are affected:<\/p>\n\n<p>\u2022\u00a0Connected Components Workbench: Version 12 and prior<br \/>\n\u2022\u00a0ControlFLASH: Version 14 and later<br \/>\n\u2022\u00a0ControlFLASH Plus: Version 1 and later<br \/>\n\u2022\u00a0FactoryTalk Asset Centre: Version 9 and later<br \/>\n\u2022\u00a0FactoryTalk Linx CommDTM: Version 1 and later<br \/>\n\u2022\u00a0Studio 5000 Launcher: Version 31 and later<br \/>\n\u2022\u00a0Studio 5000 Logix Designer software: Version 32 and prior<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-163-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-163-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-3","alert_type":398,"serial_number":"AV20-194","subject":null,"moderation_state":"published","external_url":null},{"nid":1925,"title":"IBM security advisory","uuid":"4576686a-1081-46b5-9852-e655d17f3659","banner":null,"lang":"en","date_modified":"2020-06-15","date_modified_ts":"2020-06-15T16:21:11Z","date_created":"2020-06-15T16:00:20Z","summary":null,"body":["<article data-history-node-id=\"1925\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-195<br \/>\nDate: 15 June 2020<\/strong><\/p>\n\n<p>On 11 and 12 June 2020 IBM released security updates to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Spectrum Protect Plus versions 10.1.0 - 10.1.5<\/li>\n\t<li>IBM Spectrum Protect Operations Center versions 8.1.0.000-8.1.9.000 &amp; 7.1.0.000-7.1.10.000<\/li>\n<\/ul><p>Vulnerabilities in third-party components, respectively Tomcat and Dojo, could allow a remote actor to execute or inject arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates:<\/p>\n\n<p>IBM Spectrum Protect Plus<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-apache-tomcat-affects-ibm-spectrum-protect-plus-cve-2020-1938\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-apache-tomcat-affects-ibm-spectrum-protect-plus-cve-2020-1938\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Operations Center<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-dojo-affect-ibm-spectrum-protect-operations-center-cve-2020-5259-cve-2020-5258\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-dojo-affect-ibm-spectrum-protect-operations-center-cve-2020-5259-cve-2020-5258\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-4","alert_type":396,"serial_number":"AV20-195","subject":null,"moderation_state":"published","external_url":null},{"nid":1926,"title":"[Control systems] Philips security advisory","uuid":"ea7d7c4a-e686-47ed-8a3c-5a1851abfda6","banner":null,"lang":"en","date_modified":"2020-06-15","date_modified_ts":"2020-06-15T16:28:26Z","date_created":"2020-06-15T16:07:17Z","summary":null,"body":["<article data-history-node-id=\"1926\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-196<br \/>\nDate: 15 June 2020<\/strong><\/p>\n\n<p>On 11 June 2020 Philips published a Security Advisory to address a vulnerability in IntelliBridge Enterprise IBE versions B.12 and prior.<\/p>\n\n<p>Successful exploitation of this vulnerability may allow an actor to gain access to credentials for a hospital\u2019s clinical information systems.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web link below, follow recommended mitigations and apply the necessary manufacturer update when available:<\/p>\n\n<p><a href=\"https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security\">https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-3","alert_type":398,"serial_number":"AV20-196","subject":null,"moderation_state":"published","external_url":null},{"nid":1927,"title":"Google Chrome security advisory","uuid":"fd983fd1-71ec-469d-9b9b-f4c2d92f606d","banner":null,"lang":"en","date_modified":"2020-06-16","date_modified_ts":"2020-06-16T12:06:28Z","date_created":"2020-06-16T12:06:28Z","summary":null,"body":["<article data-history-node-id=\"1927\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-197<br \/>\nDate: 16 June 2020<\/strong><\/p>\n\n<p>On 15 June 2020 Google announced the release of Chrome 83.0.4103.106 for Windows, Mac, and Linux.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/\">https:\/\/chromereleases.googleblog.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-27","alert_type":396,"serial_number":"AV20-197","subject":null,"moderation_state":"published","external_url":null},{"nid":1928,"title":"McAfee security advisory","uuid":"4e537709-032c-4efb-80aa-472622f9fa26","banner":null,"lang":"en","date_modified":"2020-06-16","date_modified_ts":"2020-06-16T12:17:28Z","date_created":"2020-06-16T12:17:28Z","summary":null,"body":["<article data-history-node-id=\"1928\" about=\"\/en\/alerts-advisories\/mcafee-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-198<br \/>\nDate: 16 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 McAfee released a security update to address multiple vulnerabilities in VirusScan Enterprise. The vulnerabilities, if successfully exploited, could allow privilege escalation and data leakage.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10302\">https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10302<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mcafee-security-advisory","alert_type":396,"serial_number":"AV20-198","subject":null,"moderation_state":"published","external_url":null},{"nid":1929,"title":"[Control systems] Treck security advisory","uuid":"bf9ece74-23e2-4926-84ac-2473049120f8","banner":null,"lang":"en","date_modified":"2020-06-17","date_modified_ts":"2020-06-17T14:52:34Z","date_created":"2020-06-17T14:52:34Z","summary":null,"body":["<article data-history-node-id=\"1929\" about=\"\/en\/alerts-advisories\/control-systems-treck-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-199<br \/>\nDate: 17 June 2020<\/strong><\/p>\n\n<p>On 16 June 2020 a security research lab publicly disclosed a research paper known as \u201cRipple20\u201d detailing vulnerabilities in Treck Incorporated\u2019s TCP\/IP stack implementation.<\/p>\n\n<p><a href=\"https:\/\/www.jsof-tech.com\/ripple20\">https:\/\/www.jsof-tech.com\/ripple20<\/a><\/p>\n\n<p>Among the 19 zero-day vulnerabilities are 4 which are rated as critical. Two of these critical vulnerabilities, CVE-2020-11896 and CVE-2020-11901, could result in remote code execution. The remaining critical vulnerabilities, CVE-2020-11897 and CVE-2020-11898, could result in an out-of-bounds write and an out-of-bounds read, respectively. As this low-level technology is used in numerous embedded systems, the vulnerabilities could affect a wide range of \u2018downstream\u2019 vendors who use Treck Incorporated\u2019s stack implementation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to apply the latest version of the affected products (Treck TCP\/IP 6.0.1.66 or later versions). For more detailed information on the vulnerabilities and the mitigating controls, please see the Treck advisory. Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products.<\/p>\n\n<p>For additional information, please refer to the following links:<\/p>\n\n<p>Treck Advisory:<br \/><a href=\"https:\/\/treck.com\/vulnerability-response-information\">https:\/\/treck.com\/vulnerability-response-information<\/a><\/p>\n\n<p>US-CERT Advisory:<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-168-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-168-01<\/a><\/p>\n\n<p>CERT-CC Vulnerability Note:<br \/><a href=\"https:\/\/kb.cert.org\/vuls\/id\/257161\">https:\/\/kb.cert.org\/vuls\/id\/257161<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-treck-security-advisory","alert_type":398,"serial_number":"AV20-199","subject":null,"moderation_state":"published","external_url":null},{"nid":1930,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"b74af788-d924-4282-863a-909495e18481","banner":null,"lang":"en","date_modified":"2020-06-17","date_modified_ts":"2020-06-17T16:23:58Z","date_created":"2020-06-17T16:23:58Z","summary":null,"body":["<article data-history-node-id=\"1930\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-200<br \/>\nDate: 17 June 2020<\/strong><\/p>\n\n<p>On 9 June 2020 ICS-CERT released an Advisory highlighting a vulnerability affecting the following Mitsubishi Electric MELSEC iQ-R series programable controllers:<\/p>\n\n<ul><li>R04\/08\/16\/32\/120CPU, R04\/08\/16\/32\/120ENCPU: Firmware Versions 39 or earlier<\/li>\n\t<li>R00\/01\/02CPU: Firmware Versions 7 or earlier<\/li>\n\t<li>R08\/16\/32\/120SFCPU: Firmware Versions 20 or earlier<\/li>\n\t<li>R08\/16\/32\/120PCPU: All versions<\/li>\n\t<li>R08\/16\/32\/120PSFCPU: All versions<\/li>\n\t<li>RJ71EN71: All versions<\/li>\n<\/ul><p>By sending large quantities of specially crafted packets in bursts over a short period, an actor could cause a denial-of-service condition on the Ethernet port of an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web link below, follow the recommended mitigations and apply the necessary updates:<\/p>\n\n<p>ICS Advisory (ICSA-20-161-02)<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-161-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-161-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-2","alert_type":398,"serial_number":"AV20-200","subject":null,"moderation_state":"published","external_url":null},{"nid":1931,"title":"Cisco security advisory","uuid":"c45db658-786e-427b-9466-3aee1e2d3572","banner":null,"lang":"en","date_modified":"2020-06-18","date_modified_ts":"2020-06-18T12:14:09Z","date_created":"2020-06-18T12:14:09Z","summary":null,"body":["<article data-history-node-id=\"1931\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-52\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-201<br \/>\nDate: 18 June 2020<\/strong><\/p>\n\n<p>On 17 June 2020 Cisco released several security advisories to address vulnerabilities in several of its products.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-52","alert_type":396,"serial_number":"AV20-201","subject":null,"moderation_state":"published","external_url":null},{"nid":1932,"title":"Adobe security advisory","uuid":"65905d4f-336b-458c-a12f-addea352ca22","banner":null,"lang":"en","date_modified":"2020-06-18","date_modified_ts":"2020-06-18T14:40:28Z","date_created":"2020-06-18T14:31:54Z","summary":null,"body":["<article data-history-node-id=\"1932\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-202<br \/>\nDate: 18 June 2020<\/strong><\/p>\n\n<p>On 16 June 2020 Adobe released several security advisories highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Audition<\/li>\n\t<li>Adobe Premiere Rush<\/li>\n\t<li>Adobe Premiere Pro<\/li>\n\t<li>Adobe Illustrator<\/li>\n\t<li>Adobe After Effects<\/li>\n\t<li>Adobe Campaign Classic<\/li>\n<\/ul><p>Successful exploitation of some of these vulnerabilities may allow an actor to execute arbitrary code or gain access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-21","alert_type":396,"serial_number":"AV20-202","subject":null,"moderation_state":"published","external_url":null},{"nid":1933,"title":"[Control systems] Schneider Electric security advisory","uuid":"25d254c6-9a1a-4f15-9a70-4069671f44c4","banner":null,"lang":"en","date_modified":"2020-06-18","date_modified_ts":"2020-06-18T14:42:21Z","date_created":"2020-06-18T14:42:21Z","summary":null,"body":["<article data-history-node-id=\"1933\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-203<br \/>\nDate: 18 June 2020<\/strong><\/p>\n\n<p>On 16 June 2020 Schneider Electric released a Security Bulletin stating it was in the process of assessing the impact of recently-disclosed Treck TCP\/IP stack vulnerabilities, commonly known as Ripple20, on its products.<\/p>\n\n<p>For information on vulnerabilities in the Treck TCP\/IP stack please refer to the following Advisory:<\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory\">https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and perform the suggested mitigations:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2020-168-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2020-168-01\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-5","alert_type":398,"serial_number":"AV20-203","subject":null,"moderation_state":"published","external_url":null},{"nid":1934,"title":"Drupal security advisory","uuid":"896f0d55-c25e-4e2f-b299-e5fd5df2bb9d","banner":null,"lang":"en","date_modified":"2020-06-19","date_modified_ts":"2020-06-19T14:52:09Z","date_created":"2020-06-19T14:52:09Z","summary":null,"body":["<article data-history-node-id=\"1934\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-204<br \/>\nDate: 19 June 2020<\/strong><\/p>\n\n<p>On 17 June 2020 Drupal released updates to address vulnerabilities in Drupal core. Drupal core versions 7, 8 and 9 do not properly handle certain form input from cross-site requests. Versions 8 and 9 are vulnerable to an arbitrary PHP code execution which could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web links below and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2020-004\">https:\/\/www.drupal.org\/sa-core-2020-004<\/a><\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/sa-core-2020-005\">https:\/\/www.drupal.org\/sa-core-2020-005<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-8","alert_type":396,"serial_number":"AV20-204","subject":null,"moderation_state":"published","external_url":null},{"nid":1935,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"b764fd9a-11ab-4204-a7dc-bc02948765c2","banner":null,"lang":"en","date_modified":"2020-06-19","date_modified_ts":"2020-06-19T15:06:09Z","date_created":"2020-06-19T15:06:09Z","summary":null,"body":["<article data-history-node-id=\"1935\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-205<br \/>\nDate: 19 June 2020<\/strong><\/p>\n\n<p>On 18 June 2020 Mitsubishi Electric released security updates to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions<\/li>\n\t<li>MC Works32 Version 3.00A (9.50.255.02)<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow remote code execution, a denial-of-service condition, information disclosure, or information tampering.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates:<\/p>\n\n<p>Mitsubishi Electric MC Works64 &amp; MC Works32<\/p>\n\n<p><a href=\"https:\/\/www.mitsubishielectric.com\/en\/psirt\/vulnerability\/pdf\/2020-002_en.pdf\">https:\/\/www.mitsubishielectric.com\/en\/psirt\/vulnerability\/pdf\/2020-002_en.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-3","alert_type":398,"serial_number":"AV20-205","subject":null,"moderation_state":"published","external_url":null},{"nid":1936,"title":"[Control systems] Rockwell Automation security advisory","uuid":"7288216d-5ef2-41cf-bb9a-a8b0058b058c","banner":null,"lang":"en","date_modified":"2020-06-19","date_modified_ts":"2020-06-19T15:23:34Z","date_created":"2020-06-19T15:23:34Z","summary":null,"body":["<article data-history-node-id=\"1936\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-206<br \/>\nDate: 19 June 2020<\/strong><\/p>\n\n<p>On 18 June 2020 US-CERT published advisories to highlight vulnerabilities in the following Rockwell Automation Products:<\/p>\n\n<ul><li>FactoryTalk Services Platform<\/li>\n\t<li>FactoryTalk View SE<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could allow an unauthenticated actor to execute remote COM objects with elevated privileges, or a remote authenticated actor to manipulate data of affected devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>FactoryTalk Services Platform<\/p>\n\n<p>ICS Advisory (ICSA-20-170-04)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-170-04\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-170-04<\/a><\/p>\n\n<p>FactoryTalk View SE<\/p>\n\n<p>ICS Advisory (ICSA-20-170-05)<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-170-05\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-170-05<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-4","alert_type":398,"serial_number":"AV20-206","subject":null,"moderation_state":"published","external_url":null},{"nid":1937,"title":"[Control systems] BD security advisory","uuid":"c5179c94-65c5-475e-9716-e195806ed6dc","banner":null,"lang":"en","date_modified":"2020-06-19","date_modified_ts":"2020-06-19T16:36:05Z","date_created":"2020-06-19T16:36:05Z","summary":null,"body":["<article data-history-node-id=\"1937\" about=\"\/en\/alerts-advisories\/control-systems-bd-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-207<br \/>\nDate: 19 June 2020<\/strong><\/p>\n\n<p>On 18 June 2020 BD released a security update to address a vulnerability in Linux kernel employed in the Laird Wireless Module WB40N, a sub-component optionally used in BD\u2019s Alaris PC Unit versions 9.13, 9.19, 9.33, and 12.1.<\/p>\n\n<p><a href=\"https:\/\/www.bd.com\/en-us\/support\/product-security-and-privacy\/product-security-bulletins\/third-party-product-security-bulletin-for-linux-kernel-vulnerability-within-wi-fi-module-in-alaris-pcu\">https:\/\/www.bd.com\/en-us\/support\/product-security-and-privacy\/product-security-bulletins\/third-party-product-security-bulletin-for-linux-kernel-vulnerability-within-wi-fi-module-in-alaris-pcu<\/a><\/p>\n\n<p>The vulnerability, if successfully exploited, could cause the Alaris PC Unit to become disconnected from the wireless network.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bd-security-advisory","alert_type":398,"serial_number":"AV20-207","subject":null,"moderation_state":"published","external_url":null},{"nid":1938,"title":"[Control systems] Johnson Controls security advisory","uuid":"af406939-a51c-49c2-a09d-121b23007b22","banner":null,"lang":"en","date_modified":"2020-06-19","date_modified_ts":"2020-06-19T16:41:59Z","date_created":"2020-06-19T16:41:59Z","summary":null,"body":["<article data-history-node-id=\"1938\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-208<br \/>\nDate: 19 June 2020<\/strong><\/p>\n\n<p>On 18 June 2020 Johnson Controls released security updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>exacqVision Web Service: All versions up to and including version 20.03.2.0<\/li>\n\t<li>exacqVision Enterprise Manager: All versions up to and including version 20.03.3.0<\/li>\n<\/ul><p>An actor with administrative privileges could potentially download and run a malicious executable that could allow the execution of operating system commands on the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates:<\/p>\n\n<p>exacqVision Web Service &amp; exacqVision Enterprise Manager<\/p>\n\n<p><a href=\"https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020-7-v1-exacqvision-web-service-and-enterprise-manager.pdf?la=en&amp;hash=704888A69F52AD699D6FA19A96C3B1B3104D3741\">https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020-7-v1-exacqvision-web-service-and-enterprise-manager.pdf?la=en&amp;hash=704888A69F52AD699D6FA19A96C3B1B3104D3741<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-1","alert_type":398,"serial_number":"AV20-208","subject":null,"moderation_state":"published","external_url":null},{"nid":1939,"title":"[Control systems] Baxter security advisory","uuid":"10a19a4b-6087-4d92-bda3-9ca9aed0fb3a","banner":null,"lang":"en","date_modified":"2020-06-19","date_modified_ts":"2020-06-19T17:07:53Z","date_created":"2020-06-19T16:59:27Z","summary":null,"body":["<article data-history-node-id=\"1939\" about=\"\/en\/alerts-advisories\/control-systems-baxter-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-209<br \/>\nDate: 19 June 2020<\/strong><\/p>\n\n<p>On 18 June 2020 US-CERT published advisories to highlight vulnerabilities in the following Baxter products:<\/p>\n\n<ul><li>\u00a0ExactaMix<\/li>\n\t<li>\u00a0PrismaFlex and PrisMax<\/li>\n\t<li>\u00a0Phoenix Hemodialysis Delivery System<\/li>\n\t<li>\u00a0Sigma Spectrum Infusion Pumps<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could allow access to sensitive data, alteration of system configuration, alteration of system resources and impact to system availability affected devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>Baxter ExactaMix<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-01<\/a><\/p>\n\n<p>Baxter PrismaFlex and PrisMax<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-02<\/a><\/p>\n\n<p>Baxter Phoenix Hemodialysis Delivery System<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-03<\/a><\/p>\n\n<p>Baxter Sigma Spectrum Infusion Pumps<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-04\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-04<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-baxter-security-advisory","alert_type":398,"serial_number":"AV20-209","subject":null,"moderation_state":"published","external_url":null},{"nid":1940,"title":"IBM security advisory","uuid":"226992d2-bf72-456e-824d-f270267192c7","banner":null,"lang":"en","date_modified":"2020-06-19","date_modified_ts":"2020-06-19T19:55:02Z","date_created":"2020-06-19T19:55:02Z","summary":null,"body":["<article data-history-node-id=\"1940\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\"><strong>Number: AV20-210<br \/>\nDate: 19 June 2020<\/strong><\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\u00a0<\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\n<p>Between 15 and 19 June IBM released several security updates to address vulnerabilities in multiple products. Included were critical patches for the following:\u00a0<\/p>\n\n<ul><li>\u00a0IBM HTTP Server and IBM WebSphere Application Server (Liberty versions 8.5 and 9)<\/li>\n\t<li>\u00a0IBM SDK for Node.js in IBM Cloud<\/li>\n\t<li>\u00a0IBM Jazz for Service Management<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM HTTP Server and IBM WebSphere Application Server<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6232876\">https:\/\/www.ibm.com\/support\/pages\/node\/6232876<\/a><br \/>\n\u00a0<br \/>\nIBM SDK for Node.js in IBM Cloud<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6232880\">https:\/\/www.ibm.com\/support\/pages\/node\/6232880<\/a><br \/>\n\u00a0<br \/>\nIBM Jazz for Service Management<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6232458\">https:\/\/www.ibm.com\/support\/pages\/node\/6232458<\/a><br \/>\n\u00a0<br \/>\nIBM Product Security Incident Response Blog<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><br \/>\n\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-5","alert_type":396,"serial_number":"AV20-210","subject":null,"moderation_state":"published","external_url":null},{"nid":1941,"title":"[Control systems] ICONICS security advisory","uuid":"c095bb82-147f-424e-9585-da3375b556f1","banner":null,"lang":"en","date_modified":"2020-06-23","date_modified_ts":"2020-06-23T12:11:56Z","date_created":"2020-06-23T12:11:56Z","summary":null,"body":["<article data-history-node-id=\"1941\" about=\"\/en\/alerts-advisories\/control-systems-iconics-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-211<br \/>\nDate: 23 June 2020<\/strong><\/p>\n\n<p>On 18 June 2020 ICONICS released security updates to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>GENESIS64 including Hyper Historian, AnalytiX and MobileHMI<\/li>\n\t<li>GENESIS32 including BizViz<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow remote code execution or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, follow the suggested mitigations and apply the necessary updates:<\/p>\n\n<p>GENESIS64<br \/><a href=\"https:\/\/iconics.com\/Production\/media\/SupportFiles\/CERT\/Whitepaper_Security_Vulnerabilities_V10_June_2020.pdf\">https:\/\/iconics.com\/Production\/media\/SupportFiles\/CERT\/Whitepaper_Security_Vulnerabilities_V10_June_2020.pdf<\/a><\/p>\n\n<p>GENESIS32<br \/><a href=\"https:\/\/iconics.com\/Production\/media\/SupportFiles\/CERT\/Whitepaper_Security_Vulnerabilities_V09_June_2020.pdf\">https:\/\/iconics.com\/Production\/media\/SupportFiles\/CERT\/Whitepaper_Security_Vulnerabilities_V09_June_2020.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-iconics-security-advisory","alert_type":398,"serial_number":"AV20-211","subject":null,"moderation_state":"published","external_url":null},{"nid":1942,"title":"[Control systems] BIOTRONIK security advisory","uuid":"2c3f82a8-1eeb-4d8a-a2ad-1e23e1c2daf7","banner":null,"lang":"en","date_modified":"2020-06-23","date_modified_ts":"2020-06-23T12:19:42Z","date_created":"2020-06-23T12:19:42Z","summary":null,"body":["<article data-history-node-id=\"1942\" about=\"\/en\/alerts-advisories\/control-systems-biotronik-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-212<br \/>\nDate: 23 June 2020<\/strong><\/p>\n\n<p>On 18 June 2020 US-CERT published an advisory to highlight vulnerabilities in BIOTRONIK CardioMessenger II-S (GSM T4APP 2.20 and T-Line T4APP 2.20).<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-05\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-170-05<\/a><\/p>\n\n<p>Successful exploitation of these vulnerabilities could allow an actor with physical access to the device to obtain sensitive data, obtain transmitted medical data from implanted cardiac devices or impact product functionality. An actor with adjacent access could influence communications between the device and the Access Point Name (APN) gateway network.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-biotronik-security-advisory","alert_type":398,"serial_number":"AV20-212","subject":null,"moderation_state":"published","external_url":null},{"nid":1943,"title":"Google Chrome security advisory","uuid":"d54e5dec-70d1-462b-8bdc-13d06dc36f54","banner":null,"lang":"en","date_modified":"2020-06-23","date_modified_ts":"2020-06-23T15:29:33Z","date_created":"2020-06-23T15:29:33Z","summary":null,"body":["<article data-history-node-id=\"1943\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-213<br \/>\nDate: 23 June 2020<\/strong><\/p>\n\n<p>On 22 June 2020 Google announced the release of Chrome 83.0.4103.116 for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/06\/stable-channel-update-for-desktop_22.html\">https:\/\/chromereleases.googleblog.com\/2020\/06\/stable-channel-update-for-desktop_22.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-28","alert_type":396,"serial_number":"AV20-213","subject":null,"moderation_state":"published","external_url":null},{"nid":1944,"title":"Schneider Electric security advisory","uuid":"b7296b99-1704-4aec-ac4d-9d5a166ec163","banner":null,"lang":"en","date_modified":"2020-06-23","date_modified_ts":"2020-06-23T18:16:02Z","date_created":"2020-06-23T18:16:02Z","summary":null,"body":["<article data-history-node-id=\"1944\" about=\"\/en\/alerts-advisories\/schneider-electric-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-214<br \/>\nDate: 23 June 2020<\/strong><\/p>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\n<p>On 22 June 2020 Schneider Electric released a Security Notification stating it has assessed the impact of recently disclosed Treck TCP\/IP stack vulnerabilities, commonly known as Ripple20, on its Network Management Card product.<\/p>\n\n<p>For information on vulnerabilities in the Treck TCP\/IP stack please refer to the following Advisory:<\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory\">https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and perform the suggested mitigations:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-174-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-174-01\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\u00a0<\/div>\n\n<p>\u00a0<\/p>\n\n<div class=\"field field--name-field-carousel-image field--type-image field--label-hidden field--item\">\u00a0<\/div>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/schneider-electric-security-advisory","alert_type":396,"serial_number":"AV20-214","subject":null,"moderation_state":"published","external_url":null},{"nid":1945,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"50e31722-3eae-4694-8388-39980c299ffd","banner":null,"lang":"en","date_modified":"2020-06-25","date_modified_ts":"2020-06-25T12:18:39Z","date_created":"2020-06-25T12:18:39Z","summary":null,"body":["<article data-history-node-id=\"1945\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-216<br \/>\nDate: 25 June 2020<\/strong><\/p>\n\n<p>On 23 June 2020 US-CERT published an advisory to highlight a vulnerability in Mitsubishi Electric\u2019s MELSEC iQ-R, iQ-F, Q, L and FX series CPU modules.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-175-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-175-01<\/a><\/p>\n\n<p>Successful exploitation of this vulnerability could allow information disclosure, information tampering, unauthorized operation, or a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-4","alert_type":398,"serial_number":"AV20-216","subject":null,"moderation_state":"published","external_url":null},{"nid":1946,"title":"[Control systems] ABB security advisory","uuid":"b66aeeff-bc94-4def-a891-e12b28780c7e","banner":null,"lang":"en","date_modified":"2020-06-25","date_modified_ts":"2020-06-25T13:09:37Z","date_created":"2020-06-25T13:09:37Z","summary":null,"body":["<article data-history-node-id=\"1946\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-215<br \/>\nDate: 25 June 2020<\/strong><\/p>\n\n<p>On 23 June 2020 US-CERT published an advisory to highlight a vulnerability in the ABB Device Library Wizard (versions 6.0.X, 6.0.3.1, and 6.0.3.2).<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-175-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-175-03<\/a><\/p>\n\n<p>Successful exploitation of this vulnerability could allow an authenticated user to escalate privileges and fully compromise the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-5","alert_type":398,"serial_number":"AV20-215","subject":null,"moderation_state":"published","external_url":null},{"nid":1947,"title":"Cisco security advisory","uuid":"0aefa12d-d50a-4155-8a41-576b80b30830","banner":null,"lang":"en","date_modified":"2020-06-25","date_modified_ts":"2020-06-25T15:06:15Z","date_created":"2020-06-25T14:51:11Z","summary":null,"body":["<article data-history-node-id=\"1947\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-53\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-217\n  <br \/>\n  Date: 25 June 2020<\/strong>\n<\/p>\n<p>On 24 June 2020 Cisco published a Security Advisory highlighting a vulnerability in the Cisco IOS XE Software.\n<\/p>\n<p>\n  <a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-telnetd-EFJrEzPx\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-telnetd-EFJrEzPx<\/a>\n<\/p>\n<p>The Cisco IOS XE Software is only vulnerable if configured with the persistent Telnet feature. The Telnet service that is used for TTY lines in Cisco IOS Software and Cisco IOS XE Software is not affected.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.\n<\/p>\n<p><strong>Note to Readers<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-53","alert_type":396,"serial_number":"AV20-217","subject":null,"moderation_state":"published","external_url":null},{"nid":1948,"title":"VMware security advisory","uuid":"16801691-7922-4126-a7c4-76a9fb13b18e","banner":null,"lang":"en","date_modified":"2020-06-25","date_modified_ts":"2020-06-25T15:14:21Z","date_created":"2020-06-25T15:11:46Z","summary":null,"body":["<article data-history-node-id=\"1948\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-218\n  <br \/>\n  Date: 25 June 2020<\/strong>\n<\/p>\n<p>On 23 June 2020 VMware published a Security Advisory highlighting vulnerabilities in the following products:\n<\/p>\n<ul><li>VMware ESXi<\/li>\n  <li>VMware Workstation Pro \/ Player<\/li>\n  <li>VMware Fusion Pro \/ Fusion<\/li>\n  <li>VMware Cloud Foundation<\/li>\n<\/ul><p>Successful exploitation of some of these vulnerabilities may allow an actor to execute arbitrary code on the hypervisor from the virtual machine, access privileged information in the hypervisor memory or cause a denial-of-service on the virtual machine.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0015.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0015.html<\/a>\n<\/p>\n<p> <br \/><strong>Note to Readers<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-28","alert_type":396,"serial_number":"AV20-218","subject":null,"moderation_state":"published","external_url":null},{"nid":1949,"title":"NVIDIA security advisory","uuid":"4d1a914d-6421-4c96-8ff3-6b9736a5721c","banner":null,"lang":"en","date_modified":"2020-06-26","date_modified_ts":"2020-06-26T14:09:37Z","date_created":"2020-06-26T13:45:47Z","summary":null,"body":["<article data-history-node-id=\"1949\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-219<br \/>\nDate: 26 June 2020<\/strong><\/p>\n\n<p>On 24 June 2020 NVIDIA published a Security Bulletin highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>NVIDIA GPU Display Driver (Windows and Linux)<\/li>\n\t<li>NVIDIA CUDA Driver<\/li>\n\t<li>NVIDIA Virtual GPU Manager<\/li>\n<\/ul><p>The vulnerabilities could allow an actor to cause a denial of service, escalation of privileges, code execution or information disclosure on the affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5031\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5031<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-9","alert_type":396,"serial_number":"AV20-219","subject":null,"moderation_state":"published","external_url":null},{"nid":1950,"title":"[Control systems] Philips security advisory","uuid":"3fbf20cd-a993-4ef2-b5ce-9c3218cde83a","banner":null,"lang":"en","date_modified":"2020-06-26","date_modified_ts":"2020-06-26T17:19:23Z","date_created":"2020-06-26T17:17:46Z","summary":null,"body":["<article data-history-node-id=\"1950\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-220<br \/>\nDate: 26 June 2020<\/strong><\/p>\n\n<p>On 25 June 2020 US-CERT published an advisory to highlight a vulnerability in the following products:<\/p>\n\n<p>\u2022\u00a0Ultrasound ClearVue Versions 3.2 and prior<br \/>\n\u2022\u00a0Ultrasound CX Versions 5.0.2 and prior<br \/>\n\u2022\u00a0Ultrasound EPIQ\/Affiniti Versions VM5.0 and prior<br \/>\n\u2022\u00a0Ultrasound Sparq Version 3.0.2 and prior and<br \/>\n\u2022\u00a0Ultrasound Xperius all versions<\/p>\n\n<p>Successful exploitation of this vulnerability could allow an actor to view or modify information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-177-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-177-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-4","alert_type":398,"serial_number":"AV20-220","subject":null,"moderation_state":"published","external_url":null},{"nid":1951,"title":"[Control systems] Rockwell Automation security advisory","uuid":"f9df8180-1013-48d8-ab6c-17da3794bb3c","banner":null,"lang":"en","date_modified":"2020-06-26","date_modified_ts":"2020-06-26T17:27:57Z","date_created":"2020-06-26T17:23:31Z","summary":null,"body":["<article data-history-node-id=\"1951\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-221<br \/>\nDate: 26 June 2020<\/strong><\/p>\n\n<p>On 25 June 2020 US-CERT published an advisory to highlight a vulnerability in the Rockwell Automation FactoryTalk Services Platform (versions 6.11.00 and earlier).<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-177-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-177-02<\/a><\/p>\n\n<p>A remote, unauthenticated actor could exploit this vulnerability to cause a denial of service or read any local file.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-5","alert_type":398,"serial_number":"AV20-221","subject":null,"moderation_state":"published","external_url":null},{"nid":1952,"title":"[Control systems] ENTTEC security advisory","uuid":"b27b9168-c71f-43b3-84dd-f0157cc9f38d","banner":null,"lang":"en","date_modified":"2020-06-26","date_modified_ts":"2020-06-26T17:26:32Z","date_created":"2020-06-26T17:26:32Z","summary":null,"body":["<article data-history-node-id=\"1952\" about=\"\/en\/alerts-advisories\/control-systems-enttec-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-222<br \/>\nDate: 26 June 2020<\/strong><\/p>\n\n<p>On 25 June 2020 US-CERT published an advisory to highlight vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0Datagate Mk2<br \/>\n\u2022\u00a0Storm 24<br \/>\n\u2022\u00a0Pixelator<br \/>\n\u2022\u00a0E-Streamer Mk2<\/p>\n\n<p>Successful exploitation of these vulnerabilities could allow an actor to gain unauthorized SSH\/SCP access to devices; inject malicious code; run commands with root privileges; and read, write, and execute files in system directories as any user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-177-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-177-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-enttec-security-advisory","alert_type":398,"serial_number":"AV20-222","subject":null,"moderation_state":"published","external_url":null},{"nid":1953,"title":"[Control systems] Rockwell Automation security advisory","uuid":"d14dd7ad-a84c-4675-807a-438bfd1a49cf","banner":null,"lang":"en","date_modified":"2020-06-26","date_modified_ts":"2020-06-26T17:32:51Z","date_created":"2020-06-26T17:32:51Z","summary":null,"body":["<article data-history-node-id=\"1953\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-223<br \/>\nDate: 26 June 2020<\/strong><\/p>\n\n<p>On 25 June 2020 US-CERT published an advisory to highlight vulnerabilities in the Rockwell Automation FactoryTalk View SE software.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-177-03\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-177-03<\/a><\/p>\n\n<p>A local, authenticated actor could exploit these vulnerabilities to gain access to cleartext or poorly encrypted credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-6","alert_type":398,"serial_number":"AV20-223","subject":null,"moderation_state":"published","external_url":null},{"nid":1954,"title":"Apache security advisory","uuid":"e8cabe47-cc53-41d6-aa5a-4e72df1266c9","banner":null,"lang":"en","date_modified":"2020-06-29","date_modified_ts":"2020-06-29T13:03:22Z","date_created":"2020-06-29T12:58:46Z","summary":null,"body":["<article data-history-node-id=\"1954\" about=\"\/en\/alerts-advisories\/apache-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-224<br \/>\nDate: 29 June 2020<\/strong><\/p>\n\n<p>Between 22 and 25 June Apache released security updates to address vulnerabilities in the following products:\u00a0<\/p>\n\n<ul><li>Tomcat (versions 8.5.0 to 8.5.559.0.0.M1, 9.0.35 and 10.0.0-M1 to 10.0.0-M5)<\/li>\n\t<li>Spark (version 2.4.5 and prior)<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could result in (respectively) denial-of-service and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Tomcat<br \/><a href=\"http:\/\/mail-archives.apache.org\/mod_mbox\/www-announce\/202006.mbox\/%3cfd56bc1d-1219-605b-99c7-946bf7bd8ad4@apache.org%3e\">http:\/\/mail-archives.apache.org\/mod_mbox\/www-announce\/202006.mbox\/%3cfd56bc1d-1219-605b-99c7-946bf7bd8ad4@apache.org%3e<\/a><\/p>\n\n<p>Spark<br \/><a href=\"https:\/\/spark.apache.org\/security.html#CVE-2020-9480\">https:\/\/spark.apache.org\/security.html#CVE-2020-9480<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-0","alert_type":396,"serial_number":"AV20-224","subject":null,"moderation_state":"published","external_url":null},{"nid":1955,"title":"IBM security advisory","uuid":"04f77635-268e-4990-b789-c1a6ddb5603c","banner":null,"lang":"en","date_modified":"2020-06-29","date_modified_ts":"2020-06-29T14:54:17Z","date_created":"2020-06-29T14:50:09Z","summary":null,"body":["<article data-history-node-id=\"1955\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-225<br \/>\nDate: 29 June 2020<\/strong><\/p>\n\n<p>Between 19 and 25 June IBM released several security updates to address vulnerabilities in multiple products. Included were critical patches for the following:\u00a0<\/p>\n\n<ul><li>IBM Security Guardium \u00a0(versions 10.6 &amp; 11.1)<\/li>\n\t<li>IBM Netezza Host Management (versions 5.4.9.0 to 5.4.26.0)<\/li>\n\t<li>IBM eDiscovery Manager (version 2.2.2)<\/li>\n\t<li>IBM Watson Discovery for IBM Cloud Pak for Data (versions 2.0.0 to 2.1.2)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Security Guardium<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-use-of-insufficiently-random-value-vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-use-of-insufficiently-random-value-vulnerability\/<\/a><\/p>\n\n<p>IBM Netezza Host Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-publicly-disclosed-vulnerabilities-from-kernel-affect-ibm-netezza-host-management\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-publicly-disclosed-vulnerabilities-from-kernel-affect-ibm-netezza-host-management\/<\/a><\/p>\n\n<p>IBM eDiscovery Manager<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-apache-commons-fileupload-publicly-disclosed-vulnerability-in-ibm-ediscovery-manager\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-apache-commons-fileupload-publicly-disclosed-vulnerability-in-ibm-ediscovery-manager\/<\/a><\/p>\n\n<p>IBM Watson Discovery for IBM Cloud Pak for Data<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-python\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-python\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-fasterxml-jackson-databind-6\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-fasterxml-jackson-databind-6\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response Blog<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-6","alert_type":396,"serial_number":"AV20-225","subject":null,"moderation_state":"published","external_url":null},{"nid":1956,"title":"Palo Alto Networks security advisory","uuid":"6c3796a3-eaff-4160-af7b-00900c2bccec","banner":null,"lang":"en","date_modified":"2020-06-29","date_modified_ts":"2020-06-29T19:39:49Z","date_created":"2020-06-29T19:39:49Z","summary":null,"body":["<article data-history-node-id=\"1956\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-226<br \/>\nDate: 29 June 2020<\/strong><\/p>\n\n<p>On 29 June 2020 Palo Alto Networks published a Security Advisory to highlight a critical authentication bypass vulnerability in PAN-OS SAML authentication. The vulnerability affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue does not affect PAN-OS 7.1. PAN-OS has been incorporated into several Palo Alto products:<\/p>\n\n<p>\u2022\u00a0GlobalProtect Gateway<br \/>\n\u2022\u00a0GlobalProtect Portal<br \/>\n\u2022\u00a0GlobalProtect Clientless VPN<br \/>\n\u2022\u00a0Authentication and Captive Portal<br \/>\n\u2022\u00a0PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces<br \/>\n\u2022\u00a0Prisma Access<\/p>\n\n<p>An unauthenticated actor with network access to a vulnerable device could exploit this vulnerability to gain access to access protected resources or perform administrative actions.<br \/>\n\u00a0<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2020-2021\">https:\/\/security.paloaltonetworks.com\/CVE-2020-2021<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-3","alert_type":396,"serial_number":"AV20-226","subject":null,"moderation_state":"published","external_url":null},{"nid":1957,"title":"NETGEAR security advisory","uuid":"96db5a2c-9d44-4aeb-bbb3-8b8e784a05c7","banner":null,"lang":"en","date_modified":"2020-06-30","date_modified_ts":"2020-06-30T16:53:57Z","date_created":"2020-06-30T16:53:57Z","summary":null,"body":["<article data-history-node-id=\"1957\" about=\"\/en\/alerts-advisories\/netgear-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-227<br \/>\nDate: 30 June 2020<\/strong><\/p>\n\n<p>On 19 June 2020 NETGEAR published a Security Advisory highlighting vulnerabilities affecting NETGEAR products. Since the original publication, several patches for affected products as well as mitigation and workarounds steps have been released.<\/p>\n\n<p><a href=\"https:\/\/kb.netgear.com\/000061982\/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Routers-Mobile-Routers-Modems-Gateways-and-Extenders\">https:\/\/kb.netgear.com\/000061982\/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Routers-Mobile-Routers-Modems-Gateways-and-Extenders<\/a><\/p>\n\n<p>The firmware updates address multiple vulnerabilities, one of which could allow a remote, unauthenticated actor to execute code on the affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/netgear-security-advisory-0","alert_type":396,"serial_number":"AV20-227","subject":null,"moderation_state":"published","external_url":null},{"nid":1958,"title":"Mozilla security advisory ","uuid":"9a9b4c63-77c6-49d9-bd8f-8696fd6d4dcb","banner":null,"lang":"en","date_modified":"2020-07-02","date_modified_ts":"2020-07-02T16:12:05Z","date_created":"2020-07-02T16:12:05Z","summary":null,"body":["<article data-history-node-id=\"1958\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-228<br \/>\nDate:\u00a02 July 2020<\/strong><\/p>\n\n<p>On 30 June 2020 Mozilla published multiple Cybersecurity Advisories highlighting vulnerabilities in the following products:\u00a0<\/p>\n\n<ul><li>\u00a0Firefox ESR 68.10<\/li>\n\t<li>\u00a0Firefox 78<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following, perform the suggested mitigations and apply the necessary manufacturer updates when available:<br \/>\n\u00a0<br \/>\nFirefox ESR 68.10<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-25\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-25\/<\/a><\/p>\n\n<p>Firefox 78<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-24\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-24\/<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-16","alert_type":396,"serial_number":"AV20-228","subject":null,"moderation_state":"published","external_url":null},{"nid":1959,"title":"[Control systems] Delta Industrial Automation security advisory","uuid":"4e2a6a18-a4b5-4926-bfe3-f09bb0622ec6","banner":null,"lang":"en","date_modified":"2020-07-02","date_modified_ts":"2020-07-02T16:35:27Z","date_created":"2020-07-02T16:35:27Z","summary":null,"body":["<article data-history-node-id=\"1959\" about=\"\/en\/alerts-advisories\/control-systems-delta-industrial-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-229<br \/>\nDate:\u00a02 July 2020<\/strong><\/p>\n\n<p>On 30 June 2020 US-CERT published an advisory to highlight vulnerabilities in Delta Industrial Automation\u2019s DOPSoft Human Machine Interface (HMI) editing software, versions 4.00.08.15 and prior.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-182-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-182-01<\/a><\/p>\n\n<p>Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an actor to read information and\/or crash the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-industrial-automation-security-advisory","alert_type":398,"serial_number":"AV20-229","subject":null,"moderation_state":"published","external_url":null},{"nid":1960,"title":"Apache security advisory","uuid":"7c3579ae-ff0d-421b-a2c5-9fbe1b6ea539","banner":null,"lang":"en","date_modified":"2020-07-02","date_modified_ts":"2020-07-02T19:42:38Z","date_created":"2020-07-02T19:42:38Z","summary":null,"body":["<article data-history-node-id=\"1960\" about=\"\/en\/alerts-advisories\/apache-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-230<br \/>\nDate:\u00a02 July 2020<\/strong><\/p>\n\n<p>On 2 July 2020 Apache released a Security Report highlighting vulnerabilities in Apache Guacamole versions 1.1.0 and prior.<\/p>\n\n<p><a href=\"https:\/\/guacamole.apache.org\/security\/\">https:\/\/guacamole.apache.org\/security\/<\/a><\/p>\n\n<p>The vulnerabilities, if successfully exploited, could lead to arbitrary code execution or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-1","alert_type":396,"serial_number":"AV20-230","subject":null,"moderation_state":"published","external_url":null},{"nid":1961,"title":"Cisco security advisory","uuid":"c16596d0-1d62-4a2f-aeaa-26a40153848e","banner":null,"lang":"en","date_modified":"2020-07-02","date_modified_ts":"2020-07-02T19:46:01Z","date_created":"2020-07-02T19:46:01Z","summary":null,"body":["<article data-history-node-id=\"1961\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-54\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-231<br \/>\nDate:\u00a02 July 2020<\/strong><\/p>\n\n<p>On 1 July 2020 Cisco released Security Advisories to address vulnerabilities in several of its products.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p>Of note is a vulnerability in Cisco Small Business Smart and Managed Switches which could allow an unauthenticated, remote actor to gain unauthorized access to the management interface of the switch.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-54","alert_type":396,"serial_number":"AV20-231","subject":null,"moderation_state":"published","external_url":null},{"nid":1962,"title":"Microsoft security advisory","uuid":"605fe588-6f9e-4c91-9470-aa162c27eceb","banner":null,"lang":"en","date_modified":"2020-07-02","date_modified_ts":"2020-07-02T20:07:26Z","date_created":"2020-07-02T19:46:10Z","summary":null,"body":["<article data-history-node-id=\"1962\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-232<br \/>\nDate:\u00a0<strong>2 July 2020<\/strong><\/strong><\/p>\n\n<p>On 30 June 2020 Microsoft released a security advisory to address multiple vulnerabilities found in the Windows Codecs library which is integrated into certain versions of Microsoft Windows.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Exploitation of the vulnerabilities could lead to programs processing a specially crafted image file which could lead to further compromise of a user\u2019s system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\n\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-6","alert_type":396,"serial_number":"AV20-232","subject":null,"moderation_state":"published","external_url":null},{"nid":1963,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"36ead757-ca68-471d-aa72-d8c84678da7b","banner":null,"lang":"en","date_modified":"2020-07-02","date_modified_ts":"2020-07-02T20:11:13Z","date_created":"2020-07-02T19:55:22Z","summary":null,"body":["<article data-history-node-id=\"1963\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-233<br \/>\nDate: 2 July 2020<\/strong><\/p>\n\n<p>On 30 June 2020 US-CERT published an advisory to highlight two vulnerabilities in several of Mitsubishi Factory Automation Engineering Software Products:<\/p>\n\n<ul><li>CPU Module Logging Configuration Tool, Versions 1.94Y and prior<\/li>\n\t<li>CW Configurator, Versions 1.010L and prior<\/li>\n\t<li>EM Software Development Kit (EM Configurator), Versions 1.010L and prior<\/li>\n\t<li>GT Designer3 (GOT2000), Versions 1.221F and prior<\/li>\n\t<li>GX LogViewer, Versions 1.96A and prior<\/li>\n\t<li>GX Works2, Versions 1.586L and prior<\/li>\n\t<li>GX Works3, Versions 1.058L and prior<\/li>\n\t<li>M_CommDTM-HART, Version 1.00A<\/li>\n\t<li>M_CommDTM-IO-Link, Versions 1.02C and prior<\/li>\n\t<li>MELFA-Works, Versions 4.3 and prior<\/li>\n\t<li>MELSEC-L Flexible High-Speed I\/O Control Module Configuration Tool, Versions 1.004E and prior<\/li>\n\t<li>MELSOFT FieldDeviceConfigurator, Versions 1.03D and prior<\/li>\n\t<li>MELSOFT iQ AppPortal, Versions 1.11M and prior<\/li>\n\t<li>MELSOFT Navigator, Versions 2.58L and prior<\/li>\n\t<li>MI Configurator, Versions 1.003D and prior<\/li>\n\t<li>Motion Control Setting, Versions 1.005F and prior<\/li>\n\t<li>MR Configurator2, Versions 1.72A and prior<\/li>\n\t<li>MT Works2, Versions 1.156N and prior<\/li>\n\t<li>RT ToolBox2, Versions 3.72A and prior<\/li>\n\t<li>RT ToolBox3, Versions 1.50C and prior<\/li>\n<\/ul><p>Successful exploitation of this vulnerability could allow exfiltration of system files or a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<br \/><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-182-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-182-02<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-5","alert_type":398,"serial_number":"AV20-233","subject":null,"moderation_state":"published","external_url":null},{"nid":1964,"title":"[Control systems] ABB security advisory","uuid":"1aa3690f-498f-4fb2-b3f7-ddc9c2a7d754","banner":null,"lang":"en","date_modified":"2020-07-03","date_modified_ts":"2020-07-03T17:18:46Z","date_created":"2020-07-03T17:18:46Z","summary":null,"body":["<article data-history-node-id=\"1964\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-234<br \/>\nDate: 3 July 2020<\/strong><\/p>\n\n<p>On 2 July 2020 US-CERT published an advisory to highlight a vulnerability in the ABB System 800xA Information Manager. The vulnerability affects versions prior to 5.1 Rev E\/5.1 FP4 Rev E TC6, versions prior to 6.0.3.3 RU1 and versions prior to 6.1 RU1.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-184-02\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-184-02<\/a><\/p>\n\n<p>Successful exploitation could allow an actor to execute arbitrary code on the information manager server.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<br \/>\n\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-4","alert_type":398,"serial_number":"AV20-234","subject":null,"moderation_state":"published","external_url":null},{"nid":1965,"title":"[Control systems] OpenClinic GA security advisory","uuid":"3ac8be93-5b17-4426-8d00-466d8227732d","banner":null,"lang":"en","date_modified":"2020-07-03","date_modified_ts":"2020-07-03T17:21:59Z","date_created":"2020-07-03T17:21:59Z","summary":null,"body":["<article data-history-node-id=\"1965\" about=\"\/en\/alerts-advisories\/control-systems-openclinic-ga-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-235<br \/>\nDate: 3 July 2020<\/strong><\/p>\n\n<p>On 2 July 2020 US-CERT published an advisory to highlight vulnerabilities in the OpenClinic GA hospital information management system. The vulnerabilities affect versions 5.09.02 and 5.89.05b.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-184-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsma-20-184-01<\/a><\/p>\n\n<p>Successful exploitation could allow an actor to bypass authentication, discover restricted information, view\/manipulate restricted database information, or execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<br \/>\n\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-openclinic-ga-security-advisory","alert_type":398,"serial_number":"AV20-235","subject":null,"moderation_state":"published","external_url":null},{"nid":1966,"title":"[Control systems] Nortek Security & Control security advisory","uuid":"a724eb05-447f-44ee-817c-547281636e6d","banner":null,"lang":"en","date_modified":"2020-07-03","date_modified_ts":"2020-07-03T17:24:33Z","date_created":"2020-07-03T17:24:33Z","summary":null,"body":["<article data-history-node-id=\"1966\" about=\"\/en\/alerts-advisories\/control-systems-nortek-security-control-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-236<br \/>\nDate: 3 July 2020<\/strong><\/p>\n\n<p>On 2 July 2020 US-CERT published an advisory to highlight vulnerabilities in Nortek Linear eMerge 50P\/5000P, versions 4.6.07 (revision 79330) and prior.<\/p>\n\n<p><a href=\"https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-184-01\">https:\/\/www.us-cert.gov\/ics\/advisories\/icsa-20-184-01<\/a><\/p>\n\n<p>The exploitation of these vulnerabilities could allow a remote actor to gain full access to the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates when available.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-nortek-security-control-security-advisory","alert_type":398,"serial_number":"AV20-236","subject":null,"moderation_state":"published","external_url":null},{"nid":1967,"title":"IBM security advisory","uuid":"fee7be83-71cc-429a-83f1-9eb1150e9c43","banner":null,"lang":"en","date_modified":"2020-07-03","date_modified_ts":"2020-07-03T18:54:28Z","date_created":"2020-07-03T18:54:28Z","summary":null,"body":["<article data-history-node-id=\"1967\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-237<br \/>\nDate: 3 July 2020<\/strong><\/p>\n\n<p>Between 26 June and 2 July IBM released several Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>\u00a0IBM Content Navigator \u00a0(version 3.0CD)<\/li>\n\t<li>\u00a0IBM Data Risk Manager (versions 2.0.6, 2.0.6.1, 2.0.6.2)<\/li>\n\t<li>\u00a0IBM Business Process Manager (versions 8.5, 8.6)<\/li>\n\t<li>\u00a0IBM Business Automation Workflow (versions 18.0, 19.0, 20.0)<\/li>\n\t<li>\u00a0IBM Tivoli Netcool (versions 7.1.0.0 to 7.1.0.18)<\/li>\n\t<li>\u00a0IBM Security QRadar Packet Capture (versions 7.3.0 to 7.3.3 Patch 1 &amp; version 7.4.0 GA)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Content Navigator<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-content-navigator-is-vulnerable-to-a-prototype-pollution-vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-content-navigator-is-vulnerable-to-a-prototype-pollution-vulnerability\/<\/a><\/p>\n\n<p>IBM Data Risk Manager<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-data-risk-manager-is-affected-by-multiple-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-data-risk-manager-is-affected-by-multiple-vulnerabilities\/<\/a><\/p>\n\n<p>IBM Business Process Manager and IBM Business Automation Workflow<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cross-site-scripting-vulnerability-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2020-4557-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cross-site-scripting-vulnerability-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2020-4557-2\/<\/a><\/p>\n\n<p>IBM Tivoli Netcool<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-tivoli-netcool-impact-is-affected-by-ibm-dojo-toolkit-vulnerabilities-cve-2020-5258-cve-2020-5259\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-tivoli-netcool-impact-is-affected-by-ibm-dojo-toolkit-vulnerabilities-cve-2020-5258-cve-2020-5259\/<\/a><\/p>\n\n<p>IBM Security QRadar Packet Capture<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-qradar-packet-capture-is-vulnerable-to-using-components-with-known-vulnerabilities-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-qradar-packet-capture-is-vulnerable-to-using-components-with-known-vulnerabilities-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response Blog<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-7","alert_type":396,"serial_number":"AV20-237","subject":null,"moderation_state":"published","external_url":null},{"nid":1974,"title":"Active Exploitation of F5 BIG-IP Vulnerability - update 1","uuid":"6628b9d8-e894-49c7-9d24-ff2d7b4e3efe","banner":null,"lang":"en","date_modified":"2020-07-10","date_modified_ts":"2020-07-10T00:46:18Z","date_created":"2020-07-05T18:40:42Z","summary":null,"body":["<article data-history-node-id=\"1974\" about=\"\/en\/alerts-advisories\/active-exploitation-f5-big-ip-vulnerability-update-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-018 Update 1<br \/>\nDate:\u00a05 July 2020<br \/>\nUpdated: 9 July 2020<\/strong><\/p>\n\n<h3>AUDIENCE<\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h3>PURPOSE<\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3>OVERVIEW<\/h3>\n\n<p>The Cyber Centre has become aware of reported exploitation attempts against the Traffic Management User Interface (TMUI) also known as the Configuration Utility for F5 BIG-IP products. Successful exploitation could result in remote code execution.<\/p>\n\n<p><strong>UPDATE<\/strong>: The Cyber Centre has become aware of exploitation attempts against the Traffic Management User Interface (TMUI) of F5 BIG-IP products in Canada. Successful exploitation could result in information disclosure or remote code execution which could lead to a full system compromise.<\/p>\n\n<h3>DETAILS<\/h3>\n\n<p>On 30 June 2020, F5 released several Security Advisories on vulnerabilities affecting BIG-IP products (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM). One of the published vulnerabilities (CVE-2020-5902), affects the TMUI. Successful exploitation could result in the execution of arbitrary system commands, create or delete files, disable services, and\/or execute arbitrary Java code.<\/p>\n\n<p>On 4 July 2020, open source research reported active exploitation of CVE-2020-5902 which if successful could result in a complete system compromise.<\/p>\n\n<p><strong>UPDATE<\/strong>: On 8 July 2020 F5 updated its mitigation advice for CVE-2020-5902 since the initial publication on 30 June 2020. Important updates include:<\/p>\n\n<ul><li>Revisions to the mitigation advice to address a bypass to the original mitigation advice.<\/li>\n\t<li>Additional mitigations to address a new avenue for exploitation.<\/li>\n<\/ul><h3>SUGGESTED ACTION<\/h3>\n\n<p>F5 has released software updates for CVE-2020-5902 as well as mitigation guidance for affected devices if patching is not immediately possible. F5 notes that authenticated users accessing the TMUI will still be able to exploit the vulnerability until the products have been successfully patched:<\/p>\n\n<ul><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254#all\">All network interfaces<\/a><\/li>\n\t<li><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254#self\">Self IPs<\/a><\/li>\n\t<li><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254#mgmt\">Management interface<\/a><\/li>\n<\/ul><p>CCCS would also recommend:<\/p>\n\n<ul><li>Ensure timely application of patches and updated software.<\/li>\n\t<li>Effectively segment networks and implement demilitarized zones (DMZs) with properly configured firewalls to selectively control and monitor traffic passed between zones.<\/li>\n\t<li>Minimize network exposure for all systems and ensure that they are not directly accessible from the Internet.<\/li>\n\t<li>Ensure the product servers and management consoles are restricted to trusted networks and\/or users as appropriate.<\/li>\n\t<li><strong>UPDATE<\/strong>:\u00a0Monitor for authenticated users connecting to potentially affected devices from unknown IP addresses.<\/li>\n<\/ul><h3>REFERENCES<\/h3>\n\n<p>K52145254: TMUI RCE vulnerability CVE-2020-5902<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254\">https:\/\/support.f5.com\/csp\/article\/K52145254<\/a><\/p>\n\n<p><strong>UPDATE<\/strong>: K11438344: Considerations and guidance when you suspect a security compromise on a BIG-IP system<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K11438344\">https:\/\/support.f5.com\/csp\/article\/K11438344<\/a><\/p>\n\n<p><strong>UPDATE<\/strong>: Proofpoint has released two <span lang=\"en-CA\" xml:lang=\"en-CA\" xml:lang=\"en-CA\">Suricata Intrusion Detection System (IDS) signatures <\/span> to assist in the identification of exploitation attempts with either method of exploitation<br \/><a href=\"https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules\">https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules<\/a><\/p>\n\n<ul><li>2030469 ET EXPLOIT F5 TMUI RCE vulnerability CVE-2020-5902 Attempt M1<\/li>\n\t<li>2030483 ET EXPLOIT F5 TMUI RCE vulnerability CVE-2020-5902 Attempt M2<\/li>\n<\/ul><p><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-f5-big-ip-vulnerability-update-1","alert_type":397,"serial_number":"AL20-018","subject":null,"moderation_state":"published","external_url":null},{"nid":1968,"title":"Samba security advisory","uuid":"8b72d762-2b75-4c42-a7fa-9b807e11cb3d","banner":null,"lang":"en","date_modified":"2020-07-06","date_modified_ts":"2020-07-06T14:44:16Z","date_created":"2020-07-06T14:28:05Z","summary":null,"body":["<article data-history-node-id=\"1968\" about=\"\/en\/alerts-advisories\/samba-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-238<br \/>\nDate: 6 July 2020<\/strong><\/p>\n\n<p>On 2 July 2020 Samba issued a Security Release highlighting vulnerabilities affecting several versions of its software.<\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">https:\/\/www.samba.org\/samba\/history\/security.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-advisory-3","alert_type":396,"serial_number":"AV20-238","subject":null,"moderation_state":"published","external_url":null},{"nid":1981,"title":"Citrix security advisory","uuid":"0ae41d81-6cdb-4deb-beb2-bef4f338e5bf","banner":null,"lang":"en","date_modified":"2020-07-14","date_modified_ts":"2020-07-14T12:10:03Z","date_created":"2020-07-07T16:48:54Z","summary":null,"body":["<article data-history-node-id=\"1981\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-239<br \/>\nDate:\u00a07 July 2020<\/strong><\/p>\n\n<p>On 7 July 2020 Citrix issued a Security Bulletin highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li class=\"MsoNormal\">Citrix ADC and NetScaler ADC<\/li>\n\t<li class=\"MsoNormal\">Citrix Gateway and NetScaler Gateway<\/li>\n\t<li class=\"MsoNormal\">Citrix SD-WAN WANOP<\/li>\n\t<li class=\"MsoNormal\">Citrix Gateway Plug-in for Linux<\/li>\n<\/ul><p>The successful exploitation of these vulnerabilities may allow an actor to achieve information disclosure, denial of service, cross site scripting, local privilege escalation, authorization bypass, or arbitrary code execution.<\/p>\n\n<p>Of note is a vulnerability in the Citrix Application Delivery Controller, Citrix Gateway and Citrix SD-WAN WANOP that could allow an unauthenticated actor, with access to the affected device\u2019s management interface, to bypass authentication barriers on the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\n\u00a0<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX276688\">https:\/\/support.citrix.com\/article\/CTX276688<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-4","alert_type":396,"serial_number":"AV20-239","subject":null,"moderation_state":"published","external_url":null},{"nid":1969,"title":"[Control systems] Grundfos Pumps Corporation security advisory","uuid":"a353a65f-a0c3-42cf-b6a3-c9cf143e62d6","banner":null,"lang":"en","date_modified":"2020-07-08","date_modified_ts":"2020-07-08T12:18:49Z","date_created":"2020-07-08T12:18:49Z","summary":null,"body":["<article data-history-node-id=\"1969\" about=\"\/en\/alerts-advisories\/control-systems-grundfos-pumps-corporation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-240<br \/>\nDate:\u00a08 July 2020<\/strong><\/p>\n\n<p>On 7 July 2020 US-CERT published an advisory to highlight vulnerabilities in the Grundfos CIM 500 product (all versions prior to v06.16.00).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-189-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-189-01<\/a><\/p>\n\n<p>Successful exploitation could allow an actor to access cleartext credential data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-grundfos-pumps-corporation-security-advisory","alert_type":398,"serial_number":"AV20-240","subject":null,"moderation_state":"published","external_url":null},{"nid":1970,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"08621fdf-9411-4ea1-a0c9-08be69da7341","banner":null,"lang":"en","date_modified":"2020-07-08","date_modified_ts":"2020-07-08T12:23:41Z","date_created":"2020-07-08T12:23:41Z","summary":null,"body":["<article data-history-node-id=\"1970\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-241<br \/>\nDate:\u00a08 July 2020<\/strong><\/p>\n\n<p>On 7 July 2020 US-CERT published an advisory to highlight vulnerabilities in the Mitsubishi Electric GOT2000 Series products. The following models of GOT2000 CoreOS Version -Y and earlier are affected:<\/p>\n\n<ul><li>\u00a0GT27 model<\/li>\n\t<li>\u00a0GT25 model<\/li>\n\t<li>\u00a0GT23 model<\/li>\n<\/ul><p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-189-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-189-02<\/a><\/p>\n\n<p>Successful exploitation of these vulnerabilities could allow a remote attacker to cause a denial-of-service condition or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-6","alert_type":398,"serial_number":"AV20-241","subject":null,"moderation_state":"published","external_url":null},{"nid":1971,"title":"VMware security advisory","uuid":"9940a772-c8d5-48e8-8999-aca05927f88b","banner":null,"lang":"en","date_modified":"2020-07-08","date_modified_ts":"2020-07-08T12:27:03Z","date_created":"2020-07-08T12:27:03Z","summary":null,"body":["<article data-history-node-id=\"1971\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-242<br \/>\nDate:\u00a08 July 2020<\/strong><\/p>\n\n<p>On 7 July 2020 VMware released a Security Advisory highlighting a vulnerability in its VMware SD-WAN by VeloCloud product.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0016.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0016.html<\/a><\/p>\n\n<p>Successful exploitation of this vulnerability could lead to information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-29","alert_type":396,"serial_number":"AV20-242","subject":null,"moderation_state":"published","external_url":null},{"nid":1972,"title":"Android security advisory","uuid":"058cd8f7-64d8-4901-9d78-bbe991f1373d","banner":null,"lang":"en","date_modified":"2020-07-08","date_modified_ts":"2020-07-08T19:06:36Z","date_created":"2020-07-08T19:06:36Z","summary":null,"body":["<article data-history-node-id=\"1972\" about=\"\/en\/alerts-advisories\/android-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-243<br \/>\nDate: 8 July 2020<\/strong><\/p>\n\n<p>On 6 July 2020 Android announced the release of updates to address vulnerabilities affecting Android devices.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-07-01\">https:\/\/source.android.com\/security\/bulletin\/2020-07-01<\/a><\/p>\n\n<p>Some of these vulnerabilities could allow a remote actor to use a specially crafted file to execute arbitrary code within the context of a privileged process.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\n\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-13","alert_type":396,"serial_number":"AV20-243","subject":null,"moderation_state":"published","external_url":null},{"nid":1973,"title":"Juniper security advisory","uuid":"908b1f1d-ce02-47ab-99fa-93d4d38614db","banner":null,"lang":"en","date_modified":"2020-07-09","date_modified_ts":"2020-07-09T17:12:34Z","date_created":"2020-07-09T17:11:30Z","summary":null,"body":["<article data-history-node-id=\"1973\" about=\"\/en\/alerts-advisories\/juniper-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-244<br \/>\nDate: 9 July 2020<\/strong><\/p>\n\n<p>On 8 July 2020 Juniper published multiple Security Bulletins to address vulnerabilities in several of its products.<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p>Of note are several vulnerabilities\u00a0 which under certain conditions may allow escalation of privilege, denial of service or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-advisory","alert_type":396,"serial_number":"AV20-244","subject":null,"moderation_state":"published","external_url":null},{"nid":1975,"title":"Smiths Medical security advisory","uuid":"831368b0-105f-4d6b-8b14-4bb8816b9547","banner":null,"lang":"en","date_modified":"2020-07-10","date_modified_ts":"2020-07-10T15:05:11Z","date_created":"2020-07-10T15:05:11Z","summary":null,"body":["<article data-history-node-id=\"1975\" about=\"\/en\/alerts-advisories\/smiths-medical-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-245<br \/>\nDate:\u00a010 July 2020<\/strong><\/p>\n\n<p>On 2 July 2020 Smiths Medical released a Cybersecurity Bulletin stating it has assessed and provided mitigation advice regarding the impact of recently disclosed Treck TCP\/IP stack vulnerabilities, commonly known as Ripple20, on its CADD-Solis Wireless Communication devices.<\/p>\n\n<p><a href=\"https:\/\/www.smiths-medical.com\/company-information\/news-and-events\/news\/2020\/july\/02\/smiths-medical-cybersecurity-bulletin\">https:\/\/www.smiths-medical.com\/company-information\/news-and-events\/news\/2020\/july\/02\/smiths-medical-cybersecurity-bulletin<\/a><\/p>\n\n<p>For information on vulnerabilities in the Treck TCP\/IP stack please refer to the following Advisory:<\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory\">https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and perform the suggested mitigations:<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/smiths-medical-security-advisory","alert_type":396,"serial_number":"AV20-245","subject":null,"moderation_state":"published","external_url":null},{"nid":1976,"title":"Palo Alto Networks security advisory","uuid":"baa1922b-5664-4003-9b7f-d3857e88f878","banner":null,"lang":"en","date_modified":"2020-07-10","date_modified_ts":"2020-07-10T16:34:35Z","date_created":"2020-07-10T16:34:35Z","summary":null,"body":["<article data-history-node-id=\"1976\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-246<br \/>\nDate: 10 July 2020<\/strong><\/p>\n\n<p>On 8 July 2020 Palo Alto Networks published multiple Security Advisories highlighting vulnerabilities in the PAN-OS operating system.<\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p>Successful exploitation of these vulnerabilities may allow an actor to execute arbitrary PAN-OS commands with root privileges or cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-4","alert_type":396,"serial_number":"AV20-246","subject":null,"moderation_state":"published","external_url":null},{"nid":1977,"title":"IBM security advisory","uuid":"9cdca689-3041-42fd-be40-eda7cd4ff0e7","banner":null,"lang":"en","date_modified":"2020-07-10","date_modified_ts":"2020-07-10T18:07:58Z","date_created":"2020-07-10T18:07:58Z","summary":null,"body":["<article data-history-node-id=\"1977\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-247<br \/>\nDate: 10 July 2020<\/strong><\/p>\n\n<p>Between 3 July and 9 July 2020 IBM released Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Security Guardium Insights \u00a0(version 2.0.0)<\/li>\n\t<li>IBM Engineering Lifecycle Optimization \u2013 Publishing (versions PUB 7.0, RPE 6.0.6.1 and 6.0.6)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Security Guardium Insights<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-insights-is-affected-by-a-netty-vulnerability-3\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-insights-is-affected-by-a-netty-vulnerability-3\/<\/a><\/p>\n\n<p>IBM Engineering Lifecycle Optimization \u2013 Publishing<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-third-party-vulnerable-library-jackson-databind-affects-ibm-engineering-lifecycle-optimization-publishing\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-third-party-vulnerable-library-jackson-databind-affects-ibm-engineering-lifecycle-optimization-publishing\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-8","alert_type":396,"serial_number":"AV20-247","subject":null,"moderation_state":"published","external_url":null},{"nid":1978,"title":"Phoenix Contact security advisory","uuid":"7be126aa-0681-40f4-97bd-0f555afb8860","banner":null,"lang":"en","date_modified":"2020-07-10","date_modified_ts":"2020-07-10T18:14:37Z","date_created":"2020-07-10T18:14:37Z","summary":null,"body":["<article data-history-node-id=\"1978\" about=\"\/en\/alerts-advisories\/phoenix-contact-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-248<br \/>\nDate: 10 July 2020<\/strong><\/p>\n\n<p>On 9 July 2020 US-CERT published an advisory to highlight multiple vulnerabilities in the Phoenix Contact Automation Worx Software Suite affecting:<\/p>\n\n<ul><li>PC Worx versions 1.87 and prior<\/li>\n\t<li>PC Worx Express versions 1.87 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, apply the necessary mitigation recommendations and update affected products when patching is available.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-191-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-191-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/phoenix-contact-security-advisory-1","alert_type":396,"serial_number":"AV20-248","subject":null,"moderation_state":"published","external_url":null},{"nid":1979,"title":"VMware security advisory","uuid":"c0551987-c47c-4a40-b009-b1eb32277001","banner":null,"lang":"en","date_modified":"2020-07-10","date_modified_ts":"2020-07-10T18:50:48Z","date_created":"2020-07-10T18:50:48Z","summary":null,"body":["<article data-history-node-id=\"1979\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-249<br \/>\nDate: 10 July 2020<\/strong><\/p>\n\n<p>On 9 July 2020 VMware published a Security Advisory highlighting a vulnerability in the following products:<\/p>\n\n<ul><li>VMware Fusion Pro \/ Fusion (Fusion)<\/li>\n\t<li>VMware Remote Console for Mac (VMRC for Mac)<\/li>\n\t<li>VMware Horizon Client for Mac<\/li>\n<\/ul><p>The successful exploitation of this vulnerability may allow an actor to escalate privileges to root on the system where the affected product is installed.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0017.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0017.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-30","alert_type":396,"serial_number":"AV20-249","subject":null,"moderation_state":"published","external_url":null},{"nid":1980,"title":"Active Exploitation of F5 BIG-IP Vulnerability","uuid":"36b6723d-b202-4f6f-96e1-e19fdefcb943","banner":null,"lang":"en","date_modified":"2020-07-13","date_modified_ts":"2020-07-13T19:52:34Z","date_created":"2020-07-13T19:15:24Z","summary":null,"body":["<article data-history-node-id=\"1980\" about=\"\/en\/alerts-advisories\/active-exploitation-f5-big-ip-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-018 Update 1<br \/>\nDate:\u00a05 July 2020<br \/>\nUpdated: 9 July 2020<\/strong><\/p>\n\n<h3>AUDIENCE<\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h3>PURPOSE<\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3>OVERVIEW<\/h3>\n\n<p>The Cyber Centre has become aware of reported exploitation attempts against the Traffic Management User Interface (TMUI) also known as the Configuration Utility for F5 BIG-IP products. Successful exploitation could result in remote code execution.<\/p>\n\n<p><strong>UPDATE<\/strong>: The Cyber Centre has become aware of exploitation attempts against the Traffic Management User Interface (TMUI) of F5 BIG-IP products in Canada. Successful exploitation could result in information disclosure or remote code execution which could lead to a full system compromise.<\/p>\n\n<h3>DETAILS<\/h3>\n\n<p>On 30 June 2020, F5 released several Security Advisories on vulnerabilities affecting BIG-IP products (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM). One of the published vulnerabilities (CVE-2020-5902), affects the TMUI. Successful exploitation could result in the execution of arbitrary system commands, create or delete files, disable services, and\/or execute arbitrary Java code.<\/p>\n\n<p>On 4 July 2020, open source research reported active exploitation of CVE-2020-5902 which if successful could result in a complete system compromise.<\/p>\n\n<p><strong>UPDATE<\/strong>: On 8 July 2020 F5 updated its mitigation advice for CVE-2020-5902 since the initial publication on 30 June 2020. Important updates include:<\/p>\n\n<ul><li>Revisions to the mitigation advice to address a bypass to the original mitigation advice.<\/li>\n\t<li>Additional mitigations to address a new avenue for exploitation.<\/li>\n<\/ul><h3>SUGGESTED ACTION<\/h3>\n\n<p>F5 has released software updates for CVE-2020-5902 as well as mitigation guidance for affected devices if patching is not immediately possible. F5 notes that authenticated users accessing the TMUI will still be able to exploit the vulnerability until the products have been successfully patched:<\/p>\n\n<ul><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254#all\"><font color=\"#0066cc\">All network interfaces<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254#self\"><font color=\"#0066cc\">Self IPs<\/font><\/a><\/li>\n\t<li><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254#mgmt\"><font color=\"#0066cc\">Management interface<\/font><\/a><\/li>\n<\/ul><p>CCCS would also recommend:<\/p>\n\n<ul><li>Ensure timely application of patches and updated software.<\/li>\n\t<li>Effectively segment networks and implement demilitarized zones (DMZs) with properly configured firewalls to selectively control and monitor traffic passed between zones.<\/li>\n\t<li>Minimize network exposure for all systems and ensure that they are not directly accessible from the Internet.<\/li>\n\t<li>Ensure the product servers and management consoles are restricted to trusted networks and\/or users as appropriate.<\/li>\n\t<li><strong>UPDATE<\/strong>:\u00a0Monitor for authenticated users connecting to potentially affected devices from unknown IP addresses.<\/li>\n<\/ul><h3>REFERENCES<\/h3>\n\n<p>K52145254: TMUI RCE vulnerability CVE-2020-5902<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K52145254\"><font color=\"#0066cc\">https:\/\/support.f5.com\/csp\/article\/K52145254<\/font><\/a><\/p>\n\n<p><strong>UPDATE<\/strong>: K11438344: Considerations and guidance when you suspect a security compromise on a BIG-IP system<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K11438344\"><font color=\"#0066cc\">https:\/\/support.f5.com\/csp\/article\/K11438344<\/font><\/a><\/p>\n\n<p><strong>UPDATE<\/strong>: Proofpoint has released two <span lang=\"en-CA\" xml:lang=\"en-CA\" xml:lang=\"en-CA\">Suricata Intrusion Detection System (IDS) signatures <\/span> to assist in the identification of exploitation attempts with either method of exploitation<br \/><a href=\"https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules\"><font color=\"#0066cc\">https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules<\/font><\/a><\/p>\n\n<ul><li>2030469 ET EXPLOIT F5 TMUI RCE vulnerability CVE-2020-5902 Attempt M1<\/li>\n\t<li>2030483 ET EXPLOIT F5 TMUI RCE vulnerability CVE-2020-5902 Attempt M2<\/li>\n<\/ul><p><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-f5-big-ip-vulnerability","alert_type":397,"serial_number":"AL20-018","subject":null,"moderation_state":"published","external_url":null},{"nid":1982,"title":"[Control systems] Capsule Technologies security advisory","uuid":"1e33270f-ba98-416b-a4a1-fd02096328fb","banner":null,"lang":"en","date_modified":"2020-07-14","date_modified_ts":"2020-07-14T15:52:54Z","date_created":"2020-07-14T15:52:54Z","summary":null,"body":["<article data-history-node-id=\"1982\" about=\"\/en\/alerts-advisories\/control-systems-capsule-technologies-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-250<br \/>\nDate: 14 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 US-CERT published an advisory to highlight a vulnerability in the Capsule Technologies SmartLinx Neuron 2 products (all versions prior to 9.0).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-196-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-196-01<\/a><\/p>\n\n<p>Successful exploitation of this vulnerability could allow an actor with physical access to an affected device to escape its restricted \u201ckiosk mode\u201d environment, resulting in full administrator access to the underlying operating system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-capsule-technologies-security-advisory","alert_type":398,"serial_number":"AV20-250","subject":null,"moderation_state":"published","external_url":null},{"nid":1983,"title":"[Control systems] Siemens security advisory","uuid":"e8aa3d0d-a96f-4ca3-8e72-aec24b398255","banner":null,"lang":"en","date_modified":"2020-07-14","date_modified_ts":"2020-07-14T16:17:09Z","date_created":"2020-07-14T16:17:09Z","summary":null,"body":["<article data-history-node-id=\"1983\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-251<br \/>\nDate: 14 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 Siemens released Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p>Of note are vulnerabilities in SICAM MMU, SICAM T and SICAM SGU, which could allow unauthenticated firmware installation, remote code execution and leakage of confidential data like passwords.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the recommended mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-11","alert_type":398,"serial_number":"AV20-251","subject":null,"moderation_state":"published","external_url":null},{"nid":1984,"title":"SAP security advisory","uuid":"388692ef-e24f-4cf2-a711-bb5d6670fb79","banner":null,"lang":"en","date_modified":"2020-07-14","date_modified_ts":"2020-07-14T18:10:54Z","date_created":"2020-07-14T18:06:28Z","summary":null,"body":["<article data-history-node-id=\"1984\" about=\"\/en\/alerts-advisories\/sap-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-252<br \/>\nDate: 14 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 SAP released security updates to address vulnerabilities in multiple products.<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=552599675\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=552599675<\/a><\/p>\n\n<p>Included were critical updates for the following:\u00a0\u00a0<\/p>\n\n<ul><li>\u00a0NetWeaver AS JAVA (LM Configuration Wizard) versions 7.30, 7.31, 7.40, 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-6","alert_type":396,"serial_number":"AV20-252","subject":null,"moderation_state":"published","external_url":null},{"nid":1985,"title":"SAP NetWeaver Java Vulnerability","uuid":"f57c6ec1-4a4c-4604-bd1f-1b5f38583f77","banner":null,"lang":"en","date_modified":"2020-07-14","date_modified_ts":"2020-07-14T22:22:56Z","date_created":"2020-07-14T21:57:07Z","summary":null,"body":["<article data-history-node-id=\"1985\" about=\"\/en\/alerts-advisories\/sap-netweaver-java-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-019<br \/>\nDate: 14 July 2020<\/strong><\/p>\n\n<h3>AUDIENCE<\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h3>PURPOSE<\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3>OVERVIEW<\/h3>\n\n<p>SAP NetWeaver Application Server Java, a core component of multiple SAP products, contains a vulnerability that could be exploited in order to gain full control of SAP applications.<\/p>\n\n<h3>DETAILS<\/h3>\n\n<p>On 14 July 2020 SAP released a security update to address a critical vulnerability, tracked as CVE-2020-6287, affecting the LM Configuration Wizard in SAP NetWeaver Application Server Java.\u00a0 An unauthenticated actor could exploit this vulnerability to take control of SAP applications by creating highly privileged SAP users able to view, modify or extract sensitive information, or interfere with business processes implemented by the system.<\/p>\n\n<p>The following SAP applications could be affected:<\/p>\n\n<ul><li>Enterprise Resource Planning;<\/li>\n\t<li>Product Lifecycle Management;<\/li>\n\t<li>Customer Relationship Management;<\/li>\n\t<li>Supply Chain Management;<\/li>\n\t<li>Supplier Relationship Management;<\/li>\n\t<li>NetWeaver Business Warehouse;<\/li>\n\t<li>Business Intelligence;<\/li>\n\t<li>NetWeaver Mobile Infrastructure;<\/li>\n\t<li>Enterprise Portal;<\/li>\n\t<li>Process Orchestration\/Process Integration;<\/li>\n\t<li>Solution Manager;<\/li>\n\t<li>NetWeaver Development Infrastructure;<\/li>\n\t<li>Central Process Scheduling;<\/li>\n\t<li>NetWeaver Composition Environment; and<\/li>\n\t<li>Landscape Manager.<\/li>\n<\/ul><p>Of particular concern are cases, confirmed by open source research, in which the NetWeaver Application Server web interface is exposed on an externally accessible interface.<\/p>\n\n<h3>SUGGESTED ACTION<\/h3>\n\n<p>The Cyber Centre encourages those organizations operating SAP environments to refer to SAP Security Note 2934135 (login required) and proceed as soon as possible with the specified patching of affected Internet-facing servers first, followed by affected internal servers.<br \/>\nIn addition, administrators should monitor systems closely for the presence of new, unexpected or unrecognized user accounts.<\/p>\n\n<h3>REFERENCES<\/h3>\n\n<p>Cyber Centre Advisory on SAP security patch day<br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/sap-security-advisory-6\">https:\/\/www.cyber.gc.ca\/en\/alerts\/sap-security-advisory-6<\/a><br \/>\n\u00a0<br \/>\nSAP software updates portal (login required)<br \/><a href=\"https:\/\/launchpad.support.sap.com\/\">https:\/\/launchpad.support.sap.com\/<\/a><br \/>\n\u00a0<br \/>\nOnapsis NetWeaver Application Server for Java vulnerability research \u201cRECON\u201d<br \/><a href=\"https:\/\/www.onapsis.com\/recon-sap-cyber-security-vulnerability\">https:\/\/www.onapsis.com\/recon-sap-cyber-security-vulnerability<\/a><br \/>\n\u00a0<br \/>\nCybersecurity &amp; Infrastructure Security Agency (US) Alert (AA20-195A)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-195a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-195a<\/a><br \/>\n\u00a0<br \/><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-netweaver-java-vulnerability","alert_type":397,"serial_number":"AL20-019","subject":null,"moderation_state":"published","external_url":null},{"nid":1986,"title":"Microsoft security advisory \u2013 July 2020 monthly rollup","uuid":"799356ce-3bdf-449b-8432-a6ccaa962c85","banner":null,"lang":"en","date_modified":"2020-07-15","date_modified_ts":"2020-07-15T13:12:29Z","date_created":"2020-07-15T13:12:29Z","summary":null,"body":["<article data-history-node-id=\"1986\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-253<br \/>\nDate: 15 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 Microsoft released security updates to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Microsoft Windows<\/li>\n\t<li>Microsoft Windows Server<\/li>\n\t<li>Internet Explorer<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Skype for Business<\/li>\n\t<li>Visual Studio<\/li>\n\t<li>.NET Framework<\/li>\n\t<li>Lync Server<\/li>\n<\/ul><p>Of note is a critical vulnerability, tracked as CVE-2020-1350, in all versions of Windows Server that are configured with the Domain Name System server role. This \u201cwormable\u201d vulnerability could allow a remote actor to run arbitrary code in the context of the Local System Account.<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-1350\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-1350<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates as soon as possible.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>Release Notes:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Jul\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Jul<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-253","subject":null,"moderation_state":"published","external_url":null},{"nid":1987,"title":"[Control systems] Schneider Electric security advisory","uuid":"c87c138e-3e3e-4dd4-9dd1-b1233d5c66c2","banner":null,"lang":"en","date_modified":"2020-07-15","date_modified_ts":"2020-07-15T16:25:36Z","date_created":"2020-07-15T16:25:36Z","summary":null,"body":["<article data-history-node-id=\"1987\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-254<br \/>\nDate: 15 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 Schneider Electric published Security Notifications highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Schneider Electric Software Update (SESU) version V2.4.0 and prior, affecting multiple products including, but not limited to:\n\t<ul><li>EcoStruxure Augmented Operator Advisor\u00a0<\/li>\n\t\t<li>EcoStruxure Control Expert (formerly known as Unity Pro)<\/li>\n\t\t<li>EcoStruxure Hybrid Distributed Control System (DCS)<\/li>\n\t\t<li>EcoStruxure Machine Expert (formerly known as SoMachine)<\/li>\n\t\t<li>EcoStruxure Machine Expert Basic<\/li>\n\t\t<li>EcoStruxure Operator Terminal Expert<\/li>\n\t\t<li>Eurotherm Data Reviewer<\/li>\n\t\t<li>Eurotherm iTools<\/li>\n\t\t<li>eXLhoist Configuration Software<\/li>\n\t\t<li>Schneider Electric Floating License Manager<\/li>\n\t\t<li>Schneider Electric License Manager<\/li>\n\t\t<li>Harmony XB5SSoft\u00a0<\/li>\n\t\t<li>SoMachine Motion<\/li>\n\t\t<li>SoMove<\/li>\n\t\t<li>Versatile Software BLUE<\/li>\n\t\t<li>Vijeo Designer<\/li>\n\t\t<li>OsiSense XX Configuration Software<\/li>\n\t\t<li>Zelio Soft 2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>\u00a0<\/p>\n\n<ul><li>Schneider Electric Floating License Manager version 2.4.0.0 and prior, affecting multiple products including:\n\t<ul><li>EcoStruxure Control Expert (only those with floating license)<\/li>\n\t\t<li>EcoStruxure Control Expert - Asset Link (only those with floating license)<\/li>\n\t\t<li>EcoStruxure Hybrid Distributed Control System (DCS) (formerly known as PlantStruxure PES)<\/li>\n\t\t<li>EcoStruxure Machine Expert (formerly known as SoMachine) (only those with floating license)<\/li>\n\t\t<li>EcoStruxure Machine Expert \u2013 Safety (only those with floating license)<\/li>\n\t\t<li>Facility Expert Online<\/li>\n\t\t<li>EcoStruxure Power Monitoring Expert<\/li>\n\t\t<li>EcoStruxure Power SCADA Operation (formerly known as PowerSCADA Expert and PowerLogic SCADA)<\/li>\n\t\t<li>SoMachine Motion Floating variant<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow an actor to achieve, respectively, remote code execution and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>Schneider Electric Software Update (SESU)<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-196-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-196-01\/<\/a><\/p>\n\n<p>Schneider Electric Floating License Manager<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-196-02\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-196-02\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-6","alert_type":398,"serial_number":"AV20-254","subject":null,"moderation_state":"published","external_url":null},{"nid":1988,"title":"Oracle security advisory","uuid":"dccd3602-5a87-4264-a616-239f22a6505a","banner":null,"lang":"en","date_modified":"2020-07-15","date_modified_ts":"2020-07-15T16:46:20Z","date_created":"2020-07-15T16:46:20Z","summary":null,"body":["<article data-history-node-id=\"1988\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-255<br \/>\nDate: 15 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 Oracle published a Critical Patch Update to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>\u00a0Oracle GoldenGate<\/li>\n\t<li>\u00a0Oracle SD-WAN Edge<\/li>\n\t<li>\u00a0Oracle Communications Analytics<\/li>\n\t<li>\u00a0Oracle Communications Billing and Revenue Management<\/li>\n\t<li>\u00a0Oracle Communications Contacts Server<\/li>\n\t<li>\u00a0Oracle Communications Element Manager<\/li>\n\t<li>\u00a0Oracle Communications Evolved Communications Application Server<\/li>\n\t<li>\u00a0Oracle Communications Instant Messaging Server<\/li>\n\t<li>\u00a0Oracle Communications IP Service Activator<\/li>\n\t<li>\u00a0Oracle Communications Network Charging and Control<\/li>\n\t<li>\u00a0Oracle Communications Network Integrity<\/li>\n\t<li>\u00a0Oracle Communications Diameter Signaling Router (DSR)<\/li>\n\t<li>\u00a0Oracle Communications MetaSolv Solution<\/li>\n\t<li>\u00a0Primavera Gateway<\/li>\n\t<li>\u00a0Primavera P6 Enterprise Project Portfolio Management<\/li>\n\t<li>\u00a0Primavera Unifier<\/li>\n\t<li>\u00a0Oracle CRM Gateway for Mobile Devices<\/li>\n\t<li>\u00a0Oracle Marketing<\/li>\n\t<li>\u00a0Oracle Trade Management<\/li>\n\t<li>\u00a0Enterprise Manager Base Platform<\/li>\n\t<li>\u00a0Oracle Application Testing Suite<\/li>\n\t<li>\u00a0Enterprise Manager Ops Center<\/li>\n\t<li>\u00a0Oracle Banking Payments<\/li>\n\t<li>\u00a0Oracle Banking Platform<\/li>\n\t<li>\u00a0Oracle Financial Services Lending and Leasing<\/li>\n\t<li>\u00a0Oracle Financial Services Market Risk Measurement and Management<\/li>\n\t<li>\u00a0Oracle FLEXCUBE Investor Servicing<\/li>\n\t<li>\u00a0Oracle FLEXCUBE Private Banking<\/li>\n\t<li>\u00a0Oracle Insurance Accounting Analyzer<\/li>\n\t<li>\u00a0Oracle Financial Services Analytical Applications Infrastructure<\/li>\n\t<li>\u00a0Oracle Endeca Information Discovery Studio<\/li>\n\t<li>\u00a0Oracle WebCenter Portal<\/li>\n\t<li>\u00a0Oracle WebLogic Server<\/li>\n\t<li>\u00a0Oracle Enterprise Repository<\/li>\n\t<li>\u00a0Oracle GraalVM Enterprise Edition<\/li>\n\t<li>\u00a0Oracle Health Sciences Empirica Inspections<\/li>\n\t<li>\u00a0Oracle Health Sciences Empirica Signal<\/li>\n\t<li>\u00a0Oracle Hospitality Guest Access<\/li>\n\t<li>\u00a0JD Edwards EnterpriseOne Orchestrator<\/li>\n\t<li>\u00a0JD Edwards EnterpriseOne Tools<\/li>\n\t<li>\u00a0MySQL Enterprise Monitor<\/li>\n\t<li>\u00a0Customer Management and Segmentation Foundation<\/li>\n\t<li>\u00a0Oracle Retail Extract Transform and Load<\/li>\n\t<li>\u00a0Oracle Retail Integration Bus<\/li>\n\t<li>\u00a0Oracle Retail Sales Audit<\/li>\n\t<li>\u00a0Oracle Retail Xstore Point of Service<\/li>\n\t<li>\u00a0Oracle Retail Bulk Data Integration<\/li>\n\t<li>\u00a0Oracle Retail Item Planning<\/li>\n\t<li>\u00a0Oracle Retail Regular Price Optimization<\/li>\n\t<li>\u00a0Oracle Retail Size Profile Optimization<\/li>\n\t<li>\u00a0Oracle Retail Store Inventory Management<\/li>\n\t<li>\u00a0Siebel Engineering - Installer &amp; Deployment<\/li>\n\t<li>\u00a0Siebel UI Framework<\/li>\n\t<li>\u00a0Oracle Rapid Planning<\/li>\n\t<li>\u00a0Oracle Transportation Management<\/li>\n\t<li>\u00a0Oracle Agile Engineering Data Management<\/li>\n\t<li>\u00a0Oracle ZFS Storage Appliance Kit<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2020.html\">https:\/\/www.oracle.com\/security-alerts\/cpujul2020.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-1","alert_type":396,"serial_number":"AV20-255","subject":null,"moderation_state":"published","external_url":null},{"nid":1989,"title":"Google Chrome security advisory","uuid":"863f5834-8cb5-4173-88ba-4dda66cec5b4","banner":null,"lang":"en","date_modified":"2020-07-15","date_modified_ts":"2020-07-15T16:52:38Z","date_created":"2020-07-15T16:52:38Z","summary":null,"body":["<article data-history-node-id=\"1989\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-256<br \/>\nDate: 15 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 Google announced the release of Chrome 84.0.4147.89 for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/07\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/07\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-29","alert_type":396,"serial_number":"AV20-256","subject":null,"moderation_state":"published","external_url":null},{"nid":1990,"title":"Adobe security advisory","uuid":"8a01dc14-583e-4823-bef8-25e4a764d7fa","banner":null,"lang":"en","date_modified":"2020-07-16","date_modified_ts":"2020-07-16T12:18:14Z","date_created":"2020-07-16T12:18:14Z","summary":null,"body":["<article data-history-node-id=\"1990\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-257<br \/>\nDate: 16 July 2020<\/strong><\/p>\n\n<p>On 14 July Adobe published multiple Security Bulletins highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Download Manager version 2.0.0.518<\/li>\n\t<li>Adobe ColdFusion versions 2016 update 15 and prior &amp; 2018 update 9 and prior<\/li>\n\t<li>Adobe Genuine Service version 6.6 and prior<\/li>\n\t<li>Adobe Media Encoder verion 14.2 and prior<\/li>\n\t<li>Adobe Creative Cloud Desktop Application verion 5.1 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in information disclosure, privilege escalation and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates:<\/p>\n\n<p>Adobe Download Manager<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/adm\/apsb20-49.html\">https:\/\/helpx.adobe.com\/security\/products\/adm\/apsb20-49.html<\/a><\/p>\n\n<p>Adobe ColdFusion<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb20-43.html\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb20-43.html<\/a><\/p>\n\n<p>Adobe Genuine Service<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/integrity_service\/apsb20-42.html\">https:\/\/helpx.adobe.com\/security\/products\/integrity_service\/apsb20-42.html<\/a><\/p>\n\n<p>Adobe Media Encoder<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb20-36.html\">https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb20-36.html<\/a><\/p>\n\n<p>Adobe Creative Cloud Desktop Application<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb20-33.html\">https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb20-33.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-22","alert_type":396,"serial_number":"AV20-257","subject":null,"moderation_state":"published","external_url":null},{"nid":1991,"title":"[Control systems] Advantech security advisory","uuid":"def11902-9929-4cc2-98b7-799b9f55dea7","banner":null,"lang":"en","date_modified":"2020-07-16","date_modified_ts":"2020-07-16T16:30:28Z","date_created":"2020-07-16T16:30:28Z","summary":null,"body":["<article data-history-node-id=\"1991\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-258<br \/>\nDate: 16 July 2020<\/strong><\/p>\n\n<p>On 14 July 2020 US-CERT published an advisory to highlight vulnerabilities in the Advantech iView product (versions 5.6 and prior).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-196-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-196-01<\/a><\/p>\n\n<p>Successful exploitation of this vulnerability could allow an actor to read\/modify information, execute arbitrary code, or cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-6","alert_type":398,"serial_number":"AV20-258","subject":null,"moderation_state":"published","external_url":null},{"nid":1992,"title":"Cisco security advisory","uuid":"9c1a75bf-c361-4873-8b24-8ba23f0043f7","banner":null,"lang":"en","date_modified":"2020-07-17","date_modified_ts":"2020-07-17T12:22:35Z","date_created":"2020-07-17T12:14:14Z","summary":null,"body":["<article data-history-node-id=\"1992\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-55\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-259<br \/>\nDate: 17 July 2020<\/strong><\/p>\n\n<p>On 15 July 2020 Cisco released Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco Small Business RV110W Wireless-N VPN Firewall versions prior to 1.2.2.8<\/li>\n\t<li>Cisco Small Business RV130 VPN Router versions prior to 1.0.3.55<\/li>\n\t<li>Cisco Small Business RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.55<\/li>\n\t<li>Cisco Small Business RV215W Wireless-N VPN Router versions prior to 1.3.1.7<\/li>\n\t<li>Cisco Prime License Manager versions 10.5(2)SU9 and prior &amp; 11.5(1)SU6 and prior<\/li>\n<\/ul><p>By exploiting some of these vulnerabilities, a remote actor could gain unauthorized access, run arbitrary code or take full control of an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-55","alert_type":396,"serial_number":"AV20-259","subject":null,"moderation_state":"published","external_url":null},{"nid":1993,"title":"Apple security advisory","uuid":"28cc2b4e-4e80-4994-bde6-6efd6cb9c72f","banner":null,"lang":"en","date_modified":"2020-07-17","date_modified_ts":"2020-07-17T15:47:05Z","date_created":"2020-07-17T15:47:05Z","summary":null,"body":["<article data-history-node-id=\"1993\" about=\"\/en\/alerts-advisories\/apple-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-260<br \/>\nDate: 17 July 2020<\/strong><\/p>\n\n<p>On 15 July 2020 Apple released security updates to address multiple vulnerabilities affecting the following products:<\/p>\n\n<ul><li>Safari for macOS Mojave and macOS High Sierra, and included in macOS Catalina<\/li>\n\t<li>IOS for iPhone 5s, iPhone 6 and 6 Plus, iPad Air, iPad mini 2 and 3, iPod touch (6th generation)<\/li>\n\t<li>WatchOS for Apple Watch Series 1, 2, 3, and 4<\/li>\n\t<li>Xcode for macOS Mojave 10.15.2 and later<\/li>\n\t<li>iOS and iPadOS for iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch 7th generation<\/li>\n\t<li>macOS Catalina, Mojave and High Sierra<\/li>\n<\/ul><p>The exploitation of some of these vulnerabilities could result in the disclosure of sensitive information, command injection and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Safari<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211292\">https:\/\/support.apple.com\/en-ca\/HT211292<\/a><\/p>\n\n<p>iOS &amp; iPadOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211288\">https:\/\/support.apple.com\/en-ca\/HT211288<\/a><\/p>\n\n<p>tvOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211290\">https:\/\/support.apple.com\/en-ca\/HT211290<\/a><\/p>\n\n<p>watchOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211291\">https:\/\/support.apple.com\/en-ca\/HT211291<\/a><\/p>\n\n<p>MacOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211289\">https:\/\/support.apple.com\/en-ca\/HT211289<\/a><\/p>\n\n<p>Apple security updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-13","alert_type":396,"serial_number":"AV20-260","subject":null,"moderation_state":"published","external_url":null},{"nid":1994,"title":"[Control systems] ABB security advisory","uuid":"62c12a02-7106-43bf-9507-9d856ffd2e5c","banner":null,"lang":"en","date_modified":"2020-07-17","date_modified_ts":"2020-07-17T16:39:40Z","date_created":"2020-07-17T16:39:40Z","summary":null,"body":["<article data-history-node-id=\"1994\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-261<br \/>\nDate: 17 July 2020<\/strong><\/p>\n\n<p>On 15 July 2020 ABB released a Cyber Security Notification stating it was currently assessing the impact of the recently-disclosed Treck TCP\/IP stack vulnerabilities, commonly known as Ripple20, on its products. ABB indicated that analysis was ongoing and has provided a preliminary list identifying the following protection relay products as vulnerable:<\/p>\n\n<ul><li>611 series<\/li>\n\t<li>615 series<\/li>\n\t<li>620 series<\/li>\n\t<li>RBX615<\/li>\n\t<li>REC615\/RER615<\/li>\n\t<li>3U REF615<\/li>\n\t<li>SMU615<\/li>\n\t<li>REX640<\/li>\n<\/ul><p>For information on vulnerabilities in the Treck TCP\/IP stack please refer to the following Advisory:<\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory\">https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and perform the suggested mitigations:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRS494936A&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRS494936A&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-6","alert_type":398,"serial_number":"AV20-261","subject":null,"moderation_state":"published","external_url":null},{"nid":1995,"title":"Mozilla security advisory","uuid":"93037a1a-a388-4a27-8166-4f25004e2741","banner":null,"lang":"en","date_modified":"2020-07-20","date_modified_ts":"2020-07-20T12:33:51Z","date_created":"2020-07-20T12:33:51Z","summary":null,"body":["<article data-history-node-id=\"1995\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-262<br \/>\nDate: 20 July 2020<\/strong><\/p>\n\n<p>On 16 July 2020 Mozilla published a Security Advisory to address vulnerabilities in Thunderbird.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-29\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-29\/<\/a><\/p>\n\n<p>Exploitation of some of these vulnerabilities could result in process memory leakage or memory corruption and a potentially exploitable crash.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-17","alert_type":396,"serial_number":"AV20-262","subject":null,"moderation_state":"published","external_url":null},{"nid":1996,"title":"IBM security advisory","uuid":"11662631-040a-4acf-97f3-20d9b3d0af70","banner":null,"lang":"en","date_modified":"2020-07-20","date_modified_ts":"2020-07-20T18:56:07Z","date_created":"2020-07-20T18:56:07Z","summary":null,"body":["<article data-history-node-id=\"1996\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-263<br \/>\nDate: 20 July 2020<\/strong><\/p>\n\n<p>Between 13 and 18 July 2020 IBM released Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<p>\u2022\u00a0IBM Watson Discovery for IBM Cloud Pak for Data (versions 2.0.0 to 2.1.2)<br \/>\n\u2022\u00a0IBM Spectrum Protect Plus (versions 10.1.0 to 10.1.5)<br \/>\n\u2022\u00a0IBM Spectrum Protect for Virtual Environments:<br \/>\no\u00a0Data Protection for VMware (versions 8.1.0.0 to 8.1.9.1 &amp; 7.1.0.0 to 7.1.8.8)<br \/>\no\u00a0Data Protection for Hyper-V (versions 8.1.0.0 to 8.1.9.1)<br \/>\n\u2022\u00a0IBM Netezza Platform Software (version 7.2.1.9 and prior)<br \/>\n\u2022\u00a0Netcool\/OMNIbus Probe DSL Factory Framework versions probe-dsl-framework-1_0 to probe-dsl-framework-6_0 (inclusive)<br \/>\n\u2022\u00a0IBM QRadar SIEM (7.4.0 to 7.4.0 Patch 2 &amp; 7.3.0 to 7.3.3 Patch 3)<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Watson Discovery for IBM Cloud Pak for Data<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-rails\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-rails\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Plus<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-databind-affect-ibm-spectrum-protect-plus-cve-2020-10673-cve-2020-1112-cve-2020-11113-cve-2020-10672-cve-2020-10968-cve-2020-10969-cve-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-databind-affect-ibm-spectrum-protect-plus-cve-2020-10673-cve-2020-1112-cve-2020-11113-cve-2020-10672-cve-2020-10968-cve-2020-10969-cve-2\/<\/a><\/p>\n\n<p>IBM Spectrum Protect for Virtual Environments<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-dojo-affect-ibm-spectrum-protect-for-virtual-environments-cve-2020-5259-cve-2020-5258\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-dojo-affect-ibm-spectrum-protect-for-virtual-environments-cve-2020-5259-cve-2020-5258\/<\/a><\/p>\n\n<p>IBM Netezza Platform Software<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-java-jre-8-0-1-1-affect-ibm-netezza-platform-software-clients\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-java-jre-8-0-1-1-affect-ibm-netezza-platform-software-clients\/<\/a><\/p>\n\n<p>Netcool\/OMNIbus Probe DSL Factory Framework<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-have-been-identified-in-apache-camel-shipped-with-ibm-netcool-omnibus-probe-dsl-factory-framework\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-have-been-identified-in-apache-camel-shipped-with-ibm-netcool-omnibus-probe-dsl-factory-framework\/<\/a><\/p>\n\n<p>IBM QRadar SIEM<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-qradar-siem-is-vulnerable-to-command-injection-cve-2020-4512\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-qradar-siem-is-vulnerable-to-command-injection-cve-2020-4512\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-9","alert_type":396,"serial_number":"AV20-263","subject":null,"moderation_state":"published","external_url":null},{"nid":1997,"title":"Adobe security advisory","uuid":"1de13a40-53a7-4849-b552-dec1fa9a7827","banner":null,"lang":"en","date_modified":"2020-07-21","date_modified_ts":"2020-07-21T19:12:52Z","date_created":"2020-07-21T19:12:52Z","summary":null,"body":["<article data-history-node-id=\"1997\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-264<br \/>\nDate: 21 July 2020<\/strong><\/p>\n\n<p>On 21 July 2020 Adobe published multiple Security Bulletins highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Bridge (version 10.0.3 and prior)<\/li>\n\t<li>Adobe Photoshop CC 2019 (version 20.0.9 and prior)<\/li>\n\t<li>Adobe Photoshop 2020 (version 21.2 and prior)<\/li>\n\t<li>Adobe Prelude (version 9.0 and prior)<\/li>\n\t<li>Adobe Reader Mobile (version 20.0.1 and prior)<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in information disclosure and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates:<\/p>\n\n<p>Adobe Bridge<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb20-44.html\">https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb20-44.html<\/a><\/p>\n\n<p>Adobe Photoshop<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb20-45.html\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb20-45.html<\/a><\/p>\n\n<p>Adobe Prelude<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/prelude\/apsb20-46.html\">https:\/\/helpx.adobe.com\/security\/products\/prelude\/apsb20-46.html<\/a><\/p>\n\n<p>Adobe Reader Mobile<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/reader-mobile\/apsb20-50.html\">https:\/\/helpx.adobe.com\/security\/products\/reader-mobile\/apsb20-50.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-23","alert_type":396,"serial_number":"AV20-264","subject":null,"moderation_state":"published","external_url":null},{"nid":1998,"title":"Citrix security advisory","uuid":"9207d9af-bb30-4200-8503-cf853f938f02","banner":null,"lang":"en","date_modified":"2020-07-24","date_modified_ts":"2020-07-24T13:48:26Z","date_created":"2020-07-24T13:45:34Z","summary":null,"body":["<article data-history-node-id=\"1998\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-265<br \/>\nDate: 24 July 2020<\/strong><\/p>\n\n<p>On 21 July 2020 Citrix released a Security Bulletin to address a vulnerability in the automatic update service for Citrix Workspace app for Windows.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX277662\">https:\/\/support.citrix.com\/article\/CTX277662<\/a><\/p>\n\n<p>Exploitation of this vulnerability could lead to privilege escalation or remote compromise of the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-5","alert_type":396,"serial_number":"AV20-265","subject":null,"moderation_state":"published","external_url":null},{"nid":1999,"title":"Cisco security advisory","uuid":"0d47f976-f49a-47bc-8459-1ca8f92deb9f","banner":null,"lang":"en","date_modified":"2020-07-24","date_modified_ts":"2020-07-24T13:51:41Z","date_created":"2020-07-24T13:51:41Z","summary":null,"body":["<article data-history-node-id=\"1999\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-56\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-266<br \/>\nDate: 24 July 2020<\/strong><\/p>\n\n<p>On 22 July 2020 Cisco released a Security Advisory to address a read-only path traversal vulnerability in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-ro-path-KJuQhB86\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-ro-path-KJuQhB86<\/a><\/p>\n\n<p>Only ASA and FTD devices with the CISCO AnyConnect or WebVPN features enabled are affected by this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-56","alert_type":396,"serial_number":"AV20-266","subject":null,"moderation_state":"published","external_url":null},{"nid":2000,"title":"[Control systems] Schneider Electric security advisory","uuid":"21acf1d1-4799-406d-9043-abebd75a6766","banner":null,"lang":"en","date_modified":"2020-07-27","date_modified_ts":"2020-07-27T13:10:43Z","date_created":"2020-07-27T13:10:43Z","summary":null,"body":["<article data-history-node-id=\"2000\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-267<br \/>\nDate: 27 July 2020<\/strong><\/p>\n\n<p>On 23 July 2020 ICS-CERT released an Advisory highlighting multiple vulnerabilities affecting legacy versions of the following Schneider Electric products:<\/p>\n\n<ul><li>Triconex TriStation<\/li>\n\t<li>Triconex Tricon Communication Module<\/li>\n<\/ul><p>Successful exploitation of some of these vulnerabilities may allow an actor to view clear text data on the network, cause a denial-of-service condition, or allow improper access on the affected systems.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>ICS-CERT Advisory:<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-205-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-205-01<\/a><\/p>\n\n<p>Schneider Electric Security Bulletin:<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2020-105-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SESB-2020-105-01\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-7","alert_type":398,"serial_number":"AV20-267","subject":null,"moderation_state":"published","external_url":null},{"nid":2001,"title":"IBM security advisory","uuid":"4c4e6c15-a313-4e18-b55b-2b15a4c5a14d","banner":null,"lang":"en","date_modified":"2020-07-27","date_modified_ts":"2020-07-27T19:17:40Z","date_created":"2020-07-27T19:17:40Z","summary":null,"body":["<article data-history-node-id=\"2001\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-268<br \/>\nDate: 27 July 2020<\/strong><\/p>\n\n<p>Between 19 and 26 July 2020 IBM released Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Sterling B2B Integrator (versions 5.2.6.2 to 5.2.6.5_1 &amp; 6.0.0.0 to 6.0.3.1)<\/li>\n\t<li>IBM Watson Machine Learning Community Edition (versions 1.6.2 &amp; 1.7.0)<\/li>\n\t<li>IBM Cloud Pak System (versions 2.3.0.1 &amp; 2.3.1.1)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Sterling B2B Integrator<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-in-jackson-databind-affect-b2b-api-of-ibm-sterling-b2b-integrator-3\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-in-jackson-databind-affect-b2b-api-of-ibm-sterling-b2b-integrator-3\/<\/a><\/p>\n\n<p>IBM Watson Machine Learning Community Edition<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-wml-ce-tensorflow-in-sqlite-before-3-32-3-select-c-mishandles-query-flattener-optimization\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-wml-ce-tensorflow-in-sqlite-before-3-32-3-select-c-mishandles-query-flattener-optimization\/<\/a><br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-wml-ce-sqlite-through-3-32-0-has-an-integer-overflow-in-sqlite3_str_vappendf-in-printf-c\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-wml-ce-sqlite-through-3-32-0-has-an-integer-overflow-in-sqlite3_str_vappendf-in-printf-c\/<\/a><\/p>\n\n<p>IBM Cloud Pak System<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-jackson-databind-shipped-with-ibm-cloud-pak-system\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-jackson-databind-shipped-with-ibm-cloud-pak-system\/<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-10","alert_type":396,"serial_number":"AV20-268","subject":null,"moderation_state":"published","external_url":null},{"nid":2002,"title":"Google Chrome security advisory","uuid":"bf929f37-0ba2-4818-af8f-17f746bc1978","banner":null,"lang":"en","date_modified":"2020-07-28","date_modified_ts":"2020-07-28T16:56:16Z","date_created":"2020-07-28T16:56:16Z","summary":null,"body":["<article data-history-node-id=\"2002\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-269<br \/>\nDate: 28 July 2020<\/strong><\/p>\n\n<p>On 27 July 2020 Google announced the release of Chrome 84.0.4147.105 for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/07\/stable-channel-update-for-desktop_27.html\">https:\/\/chromereleases.googleblog.com\/2020\/07\/stable-channel-update-for-desktop_27.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-30","alert_type":396,"serial_number":"AV20-269","subject":null,"moderation_state":"published","external_url":null},{"nid":2336,"title":"Canadian organizations exploited via unpatched devices and inadequate authentication ","uuid":"e18d010f-67e7-4139-a6c6-4183b146138a","banner":null,"lang":"en","date_modified":"2021-03-04","date_modified_ts":"2021-03-04T15:29:40Z","date_created":"2020-07-28T19:42:56Z","summary":null,"body":["<article data-history-node-id=\"2336\" about=\"\/en\/alerts-advisories\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-020<\/strong><br \/><strong>Date: July 28\u00a02020<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers. Recipients may redistribute this Alert.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>The Cyber Centre has become aware of recent and continuing exploitation of vulnerable network infrastructures in Canada. The Cyber Centre strongly recommends that organizations immediately patch critical infrastructure and implement two-factor authentication (2FA) where possible.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>In recent months, the Cyber Centre has been made aware of several compromises of computer networks in Canada. The compromises took advantage of vulnerable, less secure implementations of remote access services. <sup id=\"fn1-1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-1-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> In each case, a threat actor was able to compromise infrastructure exposed to the internet because it was not properly secured via 2FA and\/or because software running on an exposed server was not patched to the latest version.<\/p>\n\n<p>The malicious activities were reported to the Cyber Center in June and July 2020. Incidents included intensive reconnaissance-style scanning of target networks, followed by the successful compromise of vulnerable and improperly secured servers and network access devices. In some instances, malware was installed, and compromised infrastructure may have been used in attempts to compromise different networks and\/or other organizations. Threat actors may have remained active on compromised networks for a period of months before their activities were detected.<\/p>\n\n<p>The Cyber Centre has published numerous Advisories and Alerts related to significant vulnerabilities which could allow unauthenticated access to organizations\u2019 remote services and lead to remote code execution, or further exploitation of an organization\u2019s infrastructure. <sup id=\"fn3-1-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> It should be noted that even non-vulnerable systems exposed to the Internet may be subject to compromise should a threat actor obtain valid credentials with even limited system privileges.<\/p>\n\n<p>The Cyber Centre is urging Canadian organizations to apply all security updates to their internet-facing services and enable 2FA for all remote access accounts.<\/p>\n\n<p>Organizations failing to apply security updates in a timely manner and not using 2FA are exposing themselves to compromises such as information theft and ransomware.<\/p>\n\n<h2>SUGGESTED ACTION<\/h2>\n\n<p>The Cyber Centre recommends that system administrators:<\/p>\n\n<ul><li>Assess their networks for the presence of vulnerable software, particularly where it is installed on devices exposed to the internet, and patch as soon as possible to the latest version.<\/li>\n\t<li>Implement 2FA on all internet-facing remote access services, starting with perimeter security devices such as Firewalls and remote access gateways for teleworkers and administrators. <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/li>\n\t<li>Consider measures to limit the amount of sensitive information that malicious actors can collect about their networks by:\n\t<ul><li>Using open source tools to scan their networks for un-necessary or inadequately secured open ports.<\/li>\n\t\t<li>Implementing an intrusion protection system to reduce the effectiveness of malicious vulnerability scanning activities.<\/li>\n\t\t<li>Configuring internet-facing web servers with minimalist error pages that don\u2019t leak product and version information.<\/li>\n\t<\/ul><\/li>\n<\/ul><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">REFERENCES<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-exchange-validation-key-remote-code-execution-vulnerability\">Microsoft Exchange Validation Key Remote Code Execution Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-vpn-vulnerabilities-0\">Active exploitation of VPN vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts-advisories\">The Cyber Centre issues alerts and advisories on potential, imminent or actual cyber threats, vulnerabilities or incidents affecting Canada's critical infrastructure.<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote *<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/secure-your-accounts-and-devices-multi-factor-authentication-itsap30030\">Secure Your Accounts and Devices with Multi-Factor Authentication (ITSAP.30.030)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><p><br \/><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0","alert_type":397,"serial_number":"AL20-020","subject":null,"moderation_state":"published","external_url":null},{"nid":2004,"title":"Mozilla security advisory","uuid":"64574cc7-d1ba-4d10-a1a3-70820c025ec2","banner":null,"lang":"en","date_modified":"2020-07-29","date_modified_ts":"2020-07-29T12:21:23Z","date_created":"2020-07-29T12:21:23Z","summary":null,"body":["<article data-history-node-id=\"2004\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-270<br \/>\nDate: 29 July 2020<\/strong><\/p>\n\n<p>On 28 July 2020 Mozilla published a Security Advisory to address vulnerabilities in Firefox versions prior to 79.0.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-30\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-30\/<\/a><\/p>\n\n<p>Exploitation of some of these vulnerabilities could result in unexpected data leakage or memory corruption and a potentially exploitable crash.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-18","alert_type":396,"serial_number":"AV20-270","subject":null,"moderation_state":"published","external_url":null},{"nid":2005,"title":"Adobe security advisory","uuid":"89834ee9-70e5-46c4-9ebf-3c7451dc6f0e","banner":null,"lang":"en","date_modified":"2020-07-29","date_modified_ts":"2020-07-29T13:31:47Z","date_created":"2020-07-29T13:31:47Z","summary":null,"body":["<article data-history-node-id=\"2005\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-271<br \/>\nDate: 29 July 2020<\/strong><\/p>\n\n<p>On 28 July 2020 Adobe published a Security Bulletin highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Magento Commerce 2 (formerly known as Magento Enterprise Edition) versions 2.3.5-p1 and prior<\/li>\n\t<li>Adobe Magento Open Source 2 (formerly known as Magento Community Edition) versions 2.3.5-p1 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in signature verification bypass and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb20-47.html\">https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb20-47.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-24","alert_type":396,"serial_number":"AV20-271","subject":null,"moderation_state":"published","external_url":null},{"nid":2006,"title":"GRUB security advisory","uuid":"616ef68c-8ec6-4f45-ba78-76e7d07c9738","banner":null,"lang":"en","date_modified":"2020-07-29","date_modified_ts":"2020-07-29T19:12:27Z","date_created":"2020-07-29T19:12:27Z","summary":null,"body":["<article data-history-node-id=\"2006\" about=\"\/en\/alerts-advisories\/grub-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-272<br \/>\nDate: 29 July 2020<\/strong><\/p>\n\n<p>On 29 July 2020 security researchers publicly disclosed details of a vulnerability in GRUB bootloader. The vulnerability affects all signed versions of GRUB and bypasses UEFI Secure Boot. As GRUB is included in most Linux distributions, this vulnerability can impact most Linux systems.<\/p>\n\n<p>Exploitation of the vulnerability can be used to perform arbitrary code execution, which can be leveraged to install bootkits that are persistent and difficult to detect.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available:<\/p>\n\n<p>Microsoft<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV200011\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV200011<\/a><\/p>\n\n<p>UEFI Forum<br \/><a href=\"https:\/\/uefi.org\/revocationlistfile\">https:\/\/uefi.org\/revocationlistfile<\/a><\/p>\n\n<p>Debian<br \/><a href=\"https:\/\/www.debian.org\/security\/2020-GRUB-UEFI-SecureBoot\">https:\/\/www.debian.org\/security\/2020-GRUB-UEFI-SecureBoot<\/a><\/p>\n\n<p>Canonical<br \/><a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/KnowledgeBase\/GRUB2SecureBootBypass\">https:\/\/wiki.ubuntu.com\/SecurityTeam\/KnowledgeBase\/GRUB2SecureBootBypass<\/a><\/p>\n\n<p>Red Hat<br \/><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/grub2bootloader\">https:\/\/access.redhat.com\/security\/vulnerabilities\/grub2bootloader<\/a><\/p>\n\n<p>SUSE<br \/><a href=\"https:\/\/www.suse.com\/support\/kb\/doc\/?id=000019673\">https:\/\/www.suse.com\/support\/kb\/doc\/?id=000019673<\/a><\/p>\n\n<p>HP<br \/><a href=\"https:\/\/techhub.hpe.com\/eginfolib\/securityalerts\/Boot_Hole\/boot_hole.html\">https:\/\/techhub.hpe.com\/eginfolib\/securityalerts\/Boot_Hole\/boot_hole.html<\/a><\/p>\n\n<p>VMware<br \/><a href=\"https:\/\/kb.vmware.com\/s\/article\/80181\">https:\/\/kb.vmware.com\/s\/article\/80181<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grub-security-advisory","alert_type":396,"serial_number":"AV20-272","subject":null,"moderation_state":"published","external_url":null},{"nid":2007,"title":"[Control systems] Softing Industrial Automation security advisory","uuid":"1acebb8d-6803-451b-8524-a110e5c8b175","banner":null,"lang":"en","date_modified":"2020-07-29","date_modified_ts":"2020-07-29T19:16:21Z","date_created":"2020-07-29T19:16:21Z","summary":null,"body":["<article data-history-node-id=\"2007\" about=\"\/en\/alerts-advisories\/control-systems-softing-industrial-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-273<br \/>\nDate: 29 July 2020<\/strong><br \/>\n\u00a0<br \/>\nOn 28 July 2020 ICS-CERT published an advisory to highlight vulnerabilities in the Softing Industrial Automation OPC product (all versions prior to version 4.47.0).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-210-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-210-02<\/a><\/p>\n\n<p>Successful exploitation of these vulnerabilities could allow an actor to cause a denial of service or to execute arbitrary code on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-softing-industrial-automation-security-advisory","alert_type":398,"serial_number":"AV20-273","subject":null,"moderation_state":"published","external_url":null},{"nid":2008,"title":"[Control systems] HMS Industrial Networks security advisory","uuid":"989535f7-6661-49e8-93f8-9f621dce36c4","banner":null,"lang":"en","date_modified":"2020-07-29","date_modified_ts":"2020-07-29T19:19:25Z","date_created":"2020-07-29T19:19:25Z","summary":null,"body":["<article data-history-node-id=\"2008\" about=\"\/en\/alerts-advisories\/control-systems-hms-industrial-networks-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-274<br \/>\nDate: 29 July 2020<\/strong><\/p>\n\n<p>On 15 July 2020 HMS Industrial Networks published a Security Advisory to address a vulnerability in the HMS Industrial Networks eCatcher application (all versions prior to 6.5.5).<\/p>\n\n<p><a href=\"https:\/\/cdn.hms-networks.com\/docs\/librariesprovider6\/cybersecurity\/hms-security-advisory-2020-07-15-001---ewon-ecatcher.pdf\">https:\/\/cdn.hms-networks.com\/docs\/librariesprovider6\/cybersecurity\/hms-security-advisory-2020-07-15-001---ewon-ecatcher.pdf<\/a><\/p>\n\n<p>Successful exploitation of this vulnerability may allow an actor to remotely execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hms-industrial-networks-security-advisory","alert_type":398,"serial_number":"AV20-274","subject":null,"moderation_state":"published","external_url":null},{"nid":2009,"title":"[Control systems] Secomea security advisory","uuid":"25813ed9-8c2a-4594-8e9f-1e7ba2dbe666","banner":null,"lang":"en","date_modified":"2020-07-29","date_modified_ts":"2020-07-29T19:22:42Z","date_created":"2020-07-29T19:22:42Z","summary":null,"body":["<article data-history-node-id=\"2009\" about=\"\/en\/alerts-advisories\/control-systems-secomea-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-275<br \/>\nDate: 29 July 2020<\/strong><\/p>\n\n<p>On 27 July 2020 Secomea released updates to address critical vulnerabilities affecting the following products.<\/p>\n\n<ul><li>Secomea GateManager 4250\/4260\/9250 (prior to release 9.0i)<\/li>\n\t<li>Secomea GateManager 8250 (prior to release 9.2C)<\/li>\n<\/ul><p>Successful exploitation of some of these vulnerabilities may allow an actor to remotely execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates:<\/p>\n\n<p>Secomea GateManager 4250\/4260\/9250<br \/><a href=\"https:\/\/kb.secomea.com\/helpdesk\/KB\/View\/29329861-secomea-gatemanager--release-i\">https:\/\/kb.secomea.com\/helpdesk\/KB\/View\/29329861-secomea-gatemanager--release-i<\/a><\/p>\n\n<p>Secomea GateManager 8250<br \/><a href=\"https:\/\/kb.secomea.com\/helpdesk\/KB\/View\/29329790-secomea-gatemanager--release-c\">https:\/\/kb.secomea.com\/helpdesk\/KB\/View\/29329790-secomea-gatemanager--release-c<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-secomea-security-advisory","alert_type":398,"serial_number":"AV20-275","subject":null,"moderation_state":"published","external_url":null},{"nid":2010,"title":"Cisco security advisory","uuid":"4f7104e1-9fc7-4d35-9d5b-f5af41e9a952","banner":null,"lang":"en","date_modified":"2020-07-30","date_modified_ts":"2020-07-30T14:07:57Z","date_created":"2020-07-30T14:07:57Z","summary":null,"body":["<article data-history-node-id=\"2010\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-57\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-276<br \/>\nDate: 30 July 2020<\/strong><br \/>\n\u00a0<br \/>\nOn 29 July 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco SD-WAN vManage Software (multiple versions)<\/li>\n\t<li>Cisco Data Center Network Manager (versions prior to 11.4(1))<\/li>\n\t<li>Cisco SD-WAN Solution Software (multiple versions), running on:\n\t<ul><li>IOS XE SD-WAN Software<\/li>\n\t\t<li>SD-WAN vBond Orchestrator Software<\/li>\n\t\t<li>SD-WAN vEdge Cloud Routers<\/li>\n\t\t<li>SD-WAN vEdge Routers<\/li>\n\t\t<li>SD-WAN vManage Software<\/li>\n\t\t<li>SD-WAN vSmart Controller Software<\/li>\n\t<\/ul><\/li>\n<\/ul><p>By exploiting some of these vulnerabilities, a remote actor could gain unauthorized access, run arbitrary commands or take full control of an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-57","alert_type":396,"serial_number":"AV20-276","subject":null,"moderation_state":"published","external_url":null},{"nid":2011,"title":"[Control systems] Inductive Automation security advisory","uuid":"a04e78c4-69cd-43da-9d93-35481348ad38","banner":null,"lang":"en","date_modified":"2020-07-31","date_modified_ts":"2020-07-31T17:40:15Z","date_created":"2020-07-31T17:40:15Z","summary":null,"body":["<article data-history-node-id=\"2011\" about=\"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-277<br \/>\nDate: 31 July 2020<\/strong><\/p>\n\n<p>On 30 July 2020 ICS-CERT published an Advisory to highlight a vulnerability in Inductive Automation\u2019s Ignition 8 product (all versions prior to 8.0.13).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-01<\/a><\/p>\n\n<p>Successful exploitation of this vulnerability may allow a remote, unauthenticated actor to gain access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-1","alert_type":398,"serial_number":"AV20-277","subject":null,"moderation_state":"published","external_url":null},{"nid":2013,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"25157e1b-7af7-48e3-86fa-6a03857fd569","banner":null,"lang":"en","date_modified":"2020-08-04","date_modified_ts":"2020-08-04T12:29:57Z","date_created":"2020-08-04T12:29:57Z","summary":null,"body":["<article data-history-node-id=\"2013\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-278<br \/>\nDate: 4 August 2020<\/strong><\/p>\n\n<p>On 30 July 2020 US-CERT published Advisories to highlight vulnerabilities in multiple Mitsubishi Electric Products:<\/p>\n\n<ul><li>Mitsubishi Electric Factory Automation Engineering Products:\n\t<ul><li>C Controller Interface Module Utility, all versions<\/li>\n\t\t<li>C Controller Module Setting and Monitoring Tool, all versions<\/li>\n\t\t<li>CC-Link IE Control Network Data Collector, all versions<\/li>\n\t\t<li>CC-Link IE Field Network Data Collector, all versions<\/li>\n\t\t<li>CPU Module Logging Configuration Tool, Versions 1.100E and prior<\/li>\n\t\t<li>CW Configurator, Versions 1.010L and prior<\/li>\n\t\t<li>Data Transfer, all versions<\/li>\n\t\t<li>EZSocket, all versions<\/li>\n\t\t<li>FR Configurator SW3, all versions<\/li>\n\t\t<li>FR Configurator2, all versions<\/li>\n\t\t<li>GT Designer2 Classic, all versions<\/li>\n\t\t<li>GT Designer3 Version1 (GOT1000), all versions<\/li>\n\t\t<li>GT Designer3 Version1 (GOT2000), all versions<\/li>\n\t\t<li>GT SoftGOT1000 Version3, all versions<\/li>\n\t\t<li>GT SoftGOT2000 Version1, all versions<\/li>\n\t\t<li>GX Developer, Versions 8.504A and prior<\/li>\n\t\t<li>GX LogViewer, Versions 1.100E and prior<\/li>\n\t\t<li>GX Works2, all versions<\/li>\n\t\t<li>GX Works3, Versions 1.063R and prior<\/li>\n\t\t<li>M_CommDTM-IO-Link, all versions<\/li>\n\t\t<li>MELFA-Works, all versions<\/li>\n\t\t<li>MELSEC WinCPU Setting Utility, all versions<\/li>\n\t\t<li>MELSOFT Complete Clean Up Tool, all versions<\/li>\n\t\t<li>MELSOFT EM Software Development Kit, all versions<\/li>\n\t\t<li>MELSOFT iQ AppPortal, all versions<\/li>\n\t\t<li>MELSOFT Navigator, all versions<\/li>\n\t\t<li>MI Configurator, all versions<\/li>\n\t\t<li>Motion Control Setting, Versions 1.005F and prior<\/li>\n\t\t<li>Motorizer, Versions 1.005F and prior<\/li>\n\t\t<li>MR Configurator2, all versions<\/li>\n\t\t<li>MT Works2, all versions<\/li>\n\t\t<li>MTConnect Data Collector, all versions<\/li>\n\t\t<li>MX Component, all versions<\/li>\n\t\t<li>MX MESInterface, all versions<\/li>\n\t\t<li>MX MESInterface-R, all versions<\/li>\n\t\t<li>MX Sheet, all versions<\/li>\n\t\t<li>Network Interface Board CC IE Control Utility, all versions<\/li>\n\t\t<li>Network Interface Board CC IE Field Utility, all versions<\/li>\n\t\t<li>Network Interface Board CC-Link Ver.2 Utility, all versions<\/li>\n\t\t<li>Network Interface Board MNETH Utility, all versions<\/li>\n\t\t<li>Position Board utility 2, all versions<\/li>\n\t\t<li>PX Developer, all versions<\/li>\n\t\t<li>RT ToolBox2, all versions<\/li>\n\t\t<li>RT ToolBox3, all versions<\/li>\n\t\t<li>Setting\/monitoring tools for the C Controller module, all versions<\/li>\n\t\t<li>SLMP Data Collector, all versions<\/li>\n\t<\/ul><\/li>\n\t<li>Mitsubishi Electric Factory Automation Products:\n\t<ul><li>CW Configurator,Versions 1.010L and prior<\/li>\n\t\t<li>FR Configurator2, Versions 1.22Y and prior<\/li>\n\t\t<li>GX Works2, Versions 1.595V and prior<\/li>\n\t\t<li>GX Works3, Versions 1.063R and prior<\/li>\n\t\t<li>MELSEC iQ-R Series Motion Module, all versions<\/li>\n\t\t<li>MELSOFT iQ AppPortal, all versions<\/li>\n\t\t<li>MELSOFT Navigator, all versions<\/li>\n\t\t<li>MI Configurator, all versions<\/li>\n\t\t<li>MR Configurator2, all versions<\/li>\n\t\t<li>MT Works2, Versions 1.156N and prior<\/li>\n\t\t<li>MX Component, all versions<\/li>\n\t\t<li>RT ToolBox3, Versions 1.70Y and prior<\/li>\n\t<\/ul><\/li>\n\t<li>Mitsubishi Electric Multiple Factory Automation Engineering Software Products:\n\t<ul><li>CPU Module Logging Configuration Tool, versions 1.100E and prior<\/li>\n\t\t<li>CW Configurator, versions 1.010L and prior<\/li>\n\t\t<li>Data Transfer, versions 3.40S and prior<\/li>\n\t\t<li>EZSocket, versions 4.5 and prior<\/li>\n\t\t<li>FR Configurator2, versions 1.22Y and prior<\/li>\n\t\t<li>GT Designer3 Version1 (GOT2000), versions 1.235V and prior<\/li>\n\t\t<li>GT SoftGOT1000 Version3, all versions<\/li>\n\t\t<li>GT SoftGOT2000 Version1, versions 1.235V and prior<\/li>\n\t\t<li>GX LogViewer, versions 1.100E and prior<\/li>\n\t\t<li>GX Works2, versions 1.592S and prior<\/li>\n\t\t<li>GX Works3, versions 1.063R and prior<\/li>\n\t\t<li>M_CommDTM-HART, version 1.00A<\/li>\n\t\t<li>M_CommDTM-IO-Link, all versions<\/li>\n\t\t<li>MELFA-Works, versions 4.3 and prior<\/li>\n\t\t<li>MELSEC WinCPU Setting Utility, all versions<\/li>\n\t\t<li>MELSOFT EM Software Development Kit (EM Configurator), versions 1.010L and prior<\/li>\n\t\t<li>MELSOFT FieldDeviceConfigurator, versions 1.03D and prior<\/li>\n\t\t<li>MELSOFT Navigator, versions 2.62Q and prior<\/li>\n\t\t<li>MH11 SettingTool Version2, versions 2.002C and prior<\/li>\n\t\t<li>MI Configurator, all versions<\/li>\n\t\t<li>Motorizer, versions 1.005F and prior<\/li>\n\t\t<li>MR Configurator2, versions 1.105K and prior<\/li>\n\t\t<li>MT Works2, versions 1.156N and prior<\/li>\n\t\t<li>MX Component, versions 4.19V and prior<\/li>\n\t\t<li>Network Interface Board CC IE Control utility, all versions<\/li>\n\t\t<li>Network Interface Board CC IE Field Utility, all versions<\/li>\n\t\t<li>Network Interface Board CC-Link Ver.2 Utility, all versions<\/li>\n\t\t<li>Network Interface Board MNETH utility, all versions<\/li>\n\t\t<li>PX Developer, versions 1.52E and prior<\/li>\n\t\t<li>RT ToolBox2, versions 3.72A and prior<\/li>\n\t\t<li>RT ToolBox3, versions 1.70Y and prior<\/li>\n\t\t<li>Setting\/monitoring tools for the C Controller module, all versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to escalate privilege, execute malicious programs, cause a denial-of-service condition and disclose, tamper with or destroy information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>Mitsubishi Electric Factory Automation Engineering Products<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-04<\/a><\/p>\n\n<p>Mitsubishi Electric Factory Automation Products<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-03<\/a><\/p>\n\n<p>Mitsubishi Electric Multiple Factory Automation Engineering Software Products<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-212-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-7","alert_type":398,"serial_number":"AV20-278","subject":null,"moderation_state":"published","external_url":null},{"nid":2012,"title":"[Control systems] ABB security advisory","uuid":"9d42d97a-f2e3-4fed-8e38-428a40498fe2","banner":null,"lang":"en","date_modified":"2020-08-04","date_modified_ts":"2020-08-04T16:44:44Z","date_created":"2020-08-04T16:44:44Z","summary":null,"body":["<article data-history-node-id=\"2012\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-279<br \/>\nDate: 4 August 2020<\/strong><\/p>\n\n<p>On 31 July 2020 ABB released an updated Cyber Security Notification which expanded its list of products affected by the Treck TCP\/IP stack vulnerabilities, commonly known as Ripple20, to the following:<\/p>\n\n<ul><li>\u00a0611 series: All existing firmware versions<\/li>\n\t<li>\u00a0615 series: All existing firmware versions<\/li>\n\t<li>\u00a0620 series: All existing firmware versions<\/li>\n\t<li>\u00a0REX640: All existing firmware versions<\/li>\n\t<li>\u00a0REF615R: All existing firmware versions<\/li>\n\t<li>\u00a0RER615: All existing firmware versions<\/li>\n\t<li>\u00a0eVD4 equipped with RBX615: All existing firmware versions<\/li>\n\t<li>\u00a0REC615: All existing firmware versions<\/li>\n\t<li>\u00a0SMU615: All existing firmware versions<\/li>\n\t<li>\u00a0REF542pluswith option E or F communication module (1VCR009634001,1VCR009634002): All existing firmware versions<\/li>\n\t<li>\u00a0SPA-ZC 400rev C: Firmware version 2.0 and later<\/li>\n\t<li>\u00a0SPA-ZC 402 rev C: Firmware version 2.0and later<\/li>\n<\/ul><p>For information on vulnerabilities in the Treck TCP\/IP stack please refer to the following Advisory:<\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory\">https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-treck-security-advisory<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates when available.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRS494936A&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=1MRS494936A&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-7","alert_type":398,"serial_number":"AV20-279","subject":null,"moderation_state":"published","external_url":null},{"nid":2025,"title":"Red Hat security advisory","uuid":"1e02e63c-a674-41f2-b6ff-5f039a6bd6ab","banner":null,"lang":"en","date_modified":"2020-08-07","date_modified_ts":"2020-08-07T13:35:32Z","date_created":"2020-08-04T17:58:19Z","summary":null,"body":["<article data-history-node-id=\"2025\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-283<br \/>\nDate: 4 August 2020<\/strong><\/p>\n\n<p>On 3 August 2020 Red Hat released an update to address a vulnerability in Red Hat CloudForms.<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2020-14325\">https:\/\/access.redhat.com\/security\/cve\/cve-2020-14325<\/a><\/p>\n\n<p>Exploitation of this vulnerability could allow a malicious actor to impersonate any user or create non-existent users with any entitlement in the appliance.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-2","alert_type":396,"serial_number":"AV20-283","subject":null,"moderation_state":"published","external_url":null},{"nid":2014,"title":"IBM security advisory","uuid":"194ba700-f454-4655-a4b1-fd503c821d39","banner":null,"lang":"en","date_modified":"2020-08-04","date_modified_ts":"2020-08-04T17:58:56Z","date_created":"2020-08-04T17:58:56Z","summary":null,"body":["<article data-history-node-id=\"2014\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-281<br \/>\nDate: 4 August 2020<\/strong><\/p>\n\n<p>Between 27 July and 3 August 2020 IBM released Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Security Guardium (versions 10.5, 10.6 &amp; 11.1)<\/li>\n\t<li>IBM App connect Enterprise V11 (versions 11.0.0.0 - 11.0.0.8)<\/li>\n\t<li>IBM Spectrum Protect Plus (versions 10.1.0 - 10.1.6)<\/li>\n\t<li>IBM Jazz Foundation and Engineering (versions 6.0.2, 6.0.6, 6.0.6.1 &amp; 7.0.0)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Security Guardium<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-use-of-insufficiently-random-value-vulnerability-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-use-of-insufficiently-random-value-vulnerability-2\/<\/a><\/p>\n\n<p>IBM App connect Enterprise v11<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-in-node-js-affect-ibm-app-connect-enterprise-v11\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-in-node-js-affect-ibm-app-connect-enterprise-v11\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Plus<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-protect-plus-cve-2020-10531-cve-2020-8172-cve-2020-8174-cve-2020-11080\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-protect-plus-cve-2020-10531-cve-2020-8172-cve-2020-8174-cve-2020-11080\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openssh-vulnerability-affects-ibm-spectrum-protect-plus-cve-2020-15778\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openssh-vulnerability-affects-ibm-spectrum-protect-plus-cve-2020-15778\/<\/a><\/p>\n\n<p>IBM Jazz Foundation and Engineering<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affects-ibm-jazz-foundation-and-ibm-engineering-products\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affects-ibm-jazz-foundation-and-ibm-engineering-products\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-11","alert_type":396,"serial_number":"AV20-281","subject":null,"moderation_state":"published","external_url":null},{"nid":2015,"title":"Foxit security advisory","uuid":"8e16eecb-e2fd-428f-b6c5-4070efea86e5","banner":null,"lang":"en","date_modified":"2020-08-04","date_modified_ts":"2020-08-04T18:05:57Z","date_created":"2020-08-04T18:05:57Z","summary":null,"body":["<article data-history-node-id=\"2015\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-280<br \/>\nDate: 4 August 2020<\/strong><\/p>\n\n<p>On 31 July 2020 Foxit published a Security Bulletin to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Foxit Reader (versions 10.0.0.35798 and prior)<\/li>\n\t<li>Foxit PhantomPDF (versions 10.0.0.35798 and prior)<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to information disclosure or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<br \/><a href=\"https:\/\/www.foxitsoftware.com\/support\/security-bulletins.html\">https:\/\/www.foxitsoftware.com\/support\/security-bulletins.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-1","alert_type":396,"serial_number":"AV20-280","subject":null,"moderation_state":"published","external_url":null},{"nid":2016,"title":"Android security advisory","uuid":"79c6a1d4-31ba-4475-a6d6-3d66f468a67a","banner":null,"lang":"en","date_modified":"2020-08-04","date_modified_ts":"2020-08-04T18:07:55Z","date_created":"2020-08-04T18:07:55Z","summary":null,"body":["<article data-history-node-id=\"2016\" about=\"\/en\/alerts-advisories\/android-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-282<br \/>\nDate: 4 August 2020<\/strong><br \/>\n\u00a0<br \/>\nOn 3 August 2020 Android announced the release of updates to address vulnerabilities affecting Android devices.<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-08-01\">https:\/\/source.android.com\/security\/bulletin\/2020-08-01<\/a><\/p>\n\n<p>Exploitation of some of these vulnerabilities could enable a remote actor to use a specially crafted file to execute arbitrary code within the context of a privileged or unprivileged process, or enable a local application to bypass user interaction requirements to gain additional permissions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-14","alert_type":396,"serial_number":"AV20-282","subject":null,"moderation_state":"published","external_url":null},{"nid":2017,"title":"Apple security advisory","uuid":"4189eb28-56a8-4ccd-8919-0334b50cbbc9","banner":null,"lang":"en","date_modified":"2020-08-05","date_modified_ts":"2020-08-05T13:44:58Z","date_created":"2020-08-05T13:44:58Z","summary":null,"body":["<article data-history-node-id=\"2017\" about=\"\/en\/alerts-advisories\/apple-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-284<br \/>\nDate: 5 August 2020<\/strong><\/p>\n\n<p>On 30 July 2020 Apple released security updates to address multiple vulnerabilities affecting iTunes for Windows (versions prior to 12.10.8).<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT211293\">https:\/\/support.apple.com\/en-ca\/HT211293<\/a><\/p>\n\n<p>The exploitation of some of these vulnerabilities could result in unexpected application termination, command injection and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-14","alert_type":396,"serial_number":"AV20-284","subject":null,"moderation_state":"published","external_url":null},{"nid":2018,"title":"[Control systems] Delta security advisory","uuid":"c495ea51-b647-4695-a8ba-cdeceba29670","banner":null,"lang":"en","date_modified":"2020-08-06","date_modified_ts":"2020-08-06T12:30:16Z","date_created":"2020-08-06T12:30:16Z","summary":null,"body":["<article data-history-node-id=\"2018\" about=\"\/en\/alerts-advisories\/control-systems-delta-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-285<br \/>\nDate: 5 August 2020<\/strong><\/p>\n\n<p>On 4 August 2020 ICS-CERT published an Advisory to highlight vulnerabilities in Delta\u2019s CNCSoft ScreenEditor (versions 1.01.23 and prior).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-217-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-217-01<\/a><\/p>\n\n<p>Exploitation of these vulnerabilities could result in denial-of-service, information disclosure or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-security-advisory","alert_type":398,"serial_number":"AV20-285","subject":null,"moderation_state":"published","external_url":null},{"nid":2019,"title":"Cisco security advisory","uuid":"5dc2e7d2-297a-4e97-9fa7-988da2832ecd","banner":null,"lang":"en","date_modified":"2020-08-06","date_modified_ts":"2020-08-06T14:25:32Z","date_created":"2020-08-06T14:25:32Z","summary":null,"body":["<article data-history-node-id=\"2019\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-58\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-286<br \/>\nDate: 6 August 2020<\/strong><\/p>\n\n<p>On 5 August 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were high severity patches for the following:<\/p>\n\n<ul><li>Cisco Small Business Smart and Managed Switches (multiple versions\/series)<\/li>\n\t<li>Cisco Data Center (versions prior to 1.3.1.4)<\/li>\n\t<li>Cisco StarOS IPv6 (multiple versions) affecting the following products:\n\t<ul><li>Cisco ASR 5000 Series Aggregation Services Routers<\/li>\n\t\t<li>Cisco Virtualized Packet Core-Single Instance (VPC-SI)<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco AnyConnect Secure Mobility Client for Windows (versions prior to 4.9.00086)<\/li>\n<\/ul><p>By exploiting some of these vulnerabilities, an unauthenticated remote actor could cause a denial of service or gain access to sensitive information, or an authenticated local actor could perform DLL hijacking.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-58","alert_type":396,"serial_number":"AV20-286","subject":null,"moderation_state":"published","external_url":null},{"nid":2020,"title":"[Control systems] Robot Motion Servers (Multiple Vendors)","uuid":"85758c0b-1e98-4532-843d-c69286343c95","banner":null,"lang":"en","date_modified":"2020-08-06","date_modified_ts":"2020-08-06T14:28:30Z","date_created":"2020-08-06T14:28:30Z","summary":null,"body":["<article data-history-node-id=\"2020\" about=\"\/en\/alerts-advisories\/control-systems-robot-motion-servers-multiple-vendors\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-287<br \/>\nDate: 6 August 2020<\/strong><\/p>\n\n<p>On 4 August 2020 ICS-CERT published an Alert to highlight a vulnerability in robot motion servers across multiple vendors:<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/alerts\/ics-alert-20-217-01\">https:\/\/us-cert.cisa.gov\/ics\/alerts\/ics-alert-20-217-01<\/a><\/p>\n\n<p>The exploitation of this vulnerability could allow a malicious actor with network access and knowledge of industrial robotics to exfiltrate data, partially control the movements of the targeted device, or disrupt the availability of the targeted device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary manufacturer updates when available.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-robot-motion-servers-multiple-vendors","alert_type":398,"serial_number":"AV20-287","subject":null,"moderation_state":"published","external_url":null},{"nid":2021,"title":"[Control systems] Delta security advisory","uuid":"5b0cbff4-ea9c-410c-88cd-120f23a9ca7c","banner":null,"lang":"en","date_modified":"2020-08-06","date_modified_ts":"2020-08-06T19:51:47Z","date_created":"2020-08-06T19:51:47Z","summary":null,"body":["<article data-history-node-id=\"2021\" about=\"\/en\/alerts-advisories\/control-systems-delta-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-288<br \/>\nDate: 6 August 2020<\/strong><\/p>\n\n<p>On 6 August 2020 ICS-CERT published an Advisory to highlight vulnerabilities in Delta TPEditor (versions 1.97 and prior).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-04<\/a><\/p>\n\n<p>Exploitation of these vulnerabilities could result in denial-of-service, information disclosure or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-security-advisory-0","alert_type":398,"serial_number":"AV20-288","subject":null,"moderation_state":"published","external_url":null},{"nid":2023,"title":"[Control systems] Advantech security advisory","uuid":"be612c28-b9ce-4c03-8ed2-3efdc9e6e232","banner":null,"lang":"en","date_modified":"2020-08-07","date_modified_ts":"2020-08-07T12:06:54Z","date_created":"2020-08-07T12:06:54Z","summary":null,"body":["<article data-history-node-id=\"2023\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-289<br \/>\nDate: 7 August 2020<\/strong><\/p>\n\n<p>On 6 August 2020 ICS-CERT published an Advisory to highlight vulnerabilities in the Advantech WebAccess HMI Designer (versions 2.1.9.31 and prior).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-02<\/a><\/p>\n\n<p>Exploitation of these vulnerabilities could result in denial-of-service, information disclosure or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-7","alert_type":398,"serial_number":"AV20-289","subject":null,"moderation_state":"published","external_url":null},{"nid":2022,"title":"[Control systems] Trailer Power Line Communications security advisory","uuid":"e0fea843-233d-487f-be72-0786bdf6df17","banner":null,"lang":"en","date_modified":"2020-08-07","date_modified_ts":"2020-08-07T12:07:03Z","date_created":"2020-08-07T12:07:03Z","summary":null,"body":["<article data-history-node-id=\"2022\" about=\"\/en\/alerts-advisories\/control-systems-trailer-power-line-communications-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-290<br \/>\nDate:\u00a07 August 2020<\/strong><\/p>\n\n<p>On 6 August 2020 ICS-CERT published an Advisory to highlight an information disclosure vulnerability in the Power Line Communications (PLC) Bus of multiple trailer and brake manufacturers.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-01<\/a><\/p>\n\n<p>Exploitation of this vulnerability by an actor in close physical proximity with an active antenna could result in the exposure of sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-trailer-power-line-communications-security-advisory","alert_type":398,"serial_number":"AV20-290","subject":null,"moderation_state":"published","external_url":null},{"nid":2024,"title":"Control Systems] Geutebr\u00fcck security advisory ","uuid":"776e6029-45b9-48a6-a3ee-7b9f32bd9d6b","banner":null,"lang":"en","date_modified":"2020-08-07","date_modified_ts":"2020-08-07T12:11:55Z","date_created":"2020-08-07T12:11:55Z","summary":null,"body":["<article data-history-node-id=\"2024\" about=\"\/en\/alerts-advisories\/control-systems-geutebruck-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-291<br \/>\nDate:\u00a07 August 2020<\/strong><\/p>\n\n<p>On 6 August 2020 ICS-CERT published an Advisory to highlight a vulnerability in Geutebr\u00fcck G-Cam and G-Code (versions 1.12.13.2, 1.12.14.5, and 1.12.25 and prior).<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-219-03<\/a><\/p>\n\n<p>Exploitation of this vulnerability could result in a remote authenticated actor using a specially crafted URL to execute commands as root.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-geutebruck-security-advisory","alert_type":398,"serial_number":"AV20-291","subject":null,"moderation_state":"published","external_url":null},{"nid":2026,"title":"Google Chrome security advisory","uuid":"f2448780-942b-4e19-9095-92eb057077a0","banner":null,"lang":"en","date_modified":"2020-08-11","date_modified_ts":"2020-08-11T12:19:52Z","date_created":"2020-08-11T12:19:52Z","summary":null,"body":["<article data-history-node-id=\"2026\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-292<br \/>\nDate: 11 August 2020<\/strong><\/p>\n\n<p>On 10 August 2020 Google announced the release of Chrome 84.0.4147.125 for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/08\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/08\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-31","alert_type":396,"serial_number":"AV20-292","subject":null,"moderation_state":"published","external_url":null},{"nid":2027,"title":"IBM security advisory","uuid":"1f1f32a4-5313-403d-a197-346bfdc419b2","banner":null,"lang":"en","date_modified":"2020-08-11","date_modified_ts":"2020-08-11T13:25:10Z","date_created":"2020-08-11T13:25:10Z","summary":null,"body":["<article data-history-node-id=\"2027\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-293<br \/>\nDate: 11 August 2020<\/strong><\/p>\n\n<p>Between 3 and 10 August 2020 IBM released Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Netcool Operations Insight (versions 1.6.0.x)<\/li>\n\t<li>IBM Network Performance Insight (versions 1.3 &amp; 1.3.1)<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (versions 2.2.1, 3.1.0 &amp; 2020.2.1-0)<\/li>\n\t<li>Asset Repository in IBM Cloud Pak for Integration (versions 4.0.0 &amp; 2020.2.1-0)<\/li>\n\t<li>IBM Spectrum Protect Plus (versions 10.1.0-10.1.6)<\/li>\n\t<li>IBM Jazz Team Server based Applications (multiple versions)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Netcool Operations Insight<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-version-10-19-0-of-node-js-included-in-ibm-netcool-operations-insight-1-6-0-x-has-several-security-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-version-10-19-0-of-node-js-included-in-ibm-netcool-operations-insight-1-6-0-x-has-several-security-vulnerabilities\/<\/a><\/p>\n\n<p>IBM Network Performance Insight<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-jackson-databind-publicly-disclosed-vulnerability-found-in-network-performance-insight-cve-2019-14892-cve-2019-14893\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-jackson-databind-publicly-disclosed-vulnerability-found-in-network-performance-insight-cve-2019-14892-cve-2019-14893\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-jackson-databind-publicly-disclosed-vulnerability-found-in-network-performance-insight\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-jackson-databind-publicly-disclosed-vulnerability-found-in-network-performance-insight\/<\/a><\/p>\n\n<p>Platform Navigator and Asset Repository in IBM Cloud Pak for Integration<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-integration-is-affected-by-multiple-node-js-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-integration-is-affected-by-multiple-node-js-vulnerabilities\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Plus<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openssh-vulnerability-affects-ibm-spectrum-protect-plus-cve-2020-15778\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openssh-vulnerability-affects-ibm-spectrum-protect-plus-cve-2020-15778\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-protect-plus-cve-2020-10531-cve-2020-8172-cve-2020-8174-cve-2020-11080\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-protect-plus-cve-2020-10531-cve-2020-8172-cve-2020-8174-cve-2020-11080\/<\/a><\/p>\n\n<p>IBM Jazz Team Server based Applications<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affects-ibm-jazz-foundation-and-ibm-engineering-products\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affects-ibm-jazz-foundation-and-ibm-engineering-products\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-12","alert_type":396,"serial_number":"AV20-293","subject":null,"moderation_state":"published","external_url":null},{"nid":2028,"title":"Citrix security advisory","uuid":"e6ba24ac-5230-48eb-81f0-1dda7019eaee","banner":null,"lang":"en","date_modified":"2020-08-11","date_modified_ts":"2020-08-11T17:32:29Z","date_created":"2020-08-11T17:32:29Z","summary":null,"body":["<article data-history-node-id=\"2028\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-294<br \/>\nDate: 11 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 Citrix released a Security Bulletin to address vulnerabilities in Citrix Endpoint Management (CEM), also referred to as XenMobile. The following versions of CEM are affected by critical vulnerabilities:<\/p>\n\n<ul><li>XenMobile Server 10.12 prior to RP2<\/li>\n\t<li>XenMobile Server 10.11 prior to RP4<\/li>\n\t<li>XenMobile Server 10.10 prior to RP6<\/li>\n\t<li>XenMobile Server prior to 10.9 RP5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX277457\">https:\/\/support.citrix.com\/article\/CTX277457<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-6","alert_type":396,"serial_number":"AV20-294","subject":null,"moderation_state":"published","external_url":null},{"nid":2029,"title":"SAP security advisory","uuid":"98aa2ea5-e1b4-4831-9994-efaa31ea947d","banner":null,"lang":"en","date_modified":"2020-08-11","date_modified_ts":"2020-08-11T17:34:57Z","date_created":"2020-08-11T17:34:57Z","summary":null,"body":["<article data-history-node-id=\"2029\" about=\"\/en\/alerts-advisories\/sap-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-296<br \/>\nDate: 11 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 SAP released security updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>NetWeaver (Knowledge Management) versions 7.30, 7.31, 7.40, 7.50<\/li>\n<\/ul><p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=552603345\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=552603345<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-7","alert_type":396,"serial_number":"AV20-296","subject":null,"moderation_state":"published","external_url":null},{"nid":2030,"title":"Apple security advisory","uuid":"b89510e7-1961-40c2-a0c7-05693934496c","banner":null,"lang":"en","date_modified":"2020-08-11","date_modified_ts":"2020-08-11T18:00:17Z","date_created":"2020-08-11T17:38:40Z","summary":null,"body":["<article data-history-node-id=\"2030\" about=\"\/en\/alerts-advisories\/apple-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-295<br \/>\nDate: 11 August 2020<\/strong><\/p>\n\n<p>On 10 August 2020 Apple released security updates to address vulnerabilities affecting iCloud for Windows:<\/p>\n\n<ul><li>iCloud for Windows 11.3<\/li>\n\t<li>iCloud for Windows 7.20<\/li>\n<\/ul><p>The exploitation of these vulnerabilities could result in unexpected application termination, cross site scripting, arbitrary command injection or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>iCloud for Windows 11.3<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT211294\">https:\/\/support.apple.com\/kb\/HT211294<\/a><\/p>\n\n<p>iCloud for Windows 7.20<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/kb\/HT211295\">https:\/\/support.apple.com\/kb\/HT211295<\/a><\/p>\n\n<p>Apple security updates<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-15","alert_type":396,"serial_number":"AV20-295","subject":null,"moderation_state":"published","external_url":null},{"nid":2031,"title":"Adobe security advisory","uuid":"4606d29d-eb14-4089-aee5-8355004c42cd","banner":null,"lang":"en","date_modified":"2020-08-11","date_modified_ts":"2020-08-11T19:45:41Z","date_created":"2020-08-11T19:45:00Z","summary":null,"body":["<article data-history-node-id=\"2031\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-298<br \/>\nDate: 11 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 Adobe published multiple Security Bulletins highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Acrobat and Reader - multiple versions<\/li>\n\t<li>Adobe Lightroom - version 9.2.0.10 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure, denial of service, privilege escalation or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates:<\/p>\n\n<p>Adobe Acrobat and Reader<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb20-48.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb20-48.html<\/a><\/p>\n\n<p>Adobe Lightroom<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/lightroom\/apsb20-51.html\">https:\/\/helpx.adobe.com\/security\/products\/lightroom\/apsb20-51.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-25","alert_type":396,"serial_number":"AV20-298","subject":null,"moderation_state":"published","external_url":null},{"nid":2032,"title":"[Control systems] Siemens security advisory","uuid":"33ad3c06-2ff2-436b-b717-b9399d6116eb","banner":null,"lang":"en","date_modified":"2020-08-11","date_modified_ts":"2020-08-11T19:55:25Z","date_created":"2020-08-11T19:55:25Z","summary":null,"body":["<article data-history-node-id=\"2032\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-297<br \/>\nDate: 11 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 Siemens published Security Advisories highlighting vulnerabilities in several products. Included were critical updates for the following:<\/p>\n\n<p>\u2022\u00a0Desigo CC - versions 3.x and 4.x<br \/>\n\u2022\u00a0Desigo CC Compact - versions 3.x and 4.x<br \/>\n\u2022\u00a0RUGGEDCOM RM1224 - versions prior to 6.3<br \/>\n\u2022\u00a0SCALANCE M-800 \/ S615 - versions prior to 6.3<\/p>\n\n<p>Exploitation of these vulnerabilities could result in information disclosure, denial of service, privilege escalation or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-12","alert_type":398,"serial_number":"AV20-297","subject":null,"moderation_state":"published","external_url":null},{"nid":2033,"title":"[Control systems] Yokogawa security advisory","uuid":"7014b67a-07a0-42ba-8f35-b9b2bd504f5b","banner":null,"lang":"en","date_modified":"2020-08-12","date_modified_ts":"2020-08-12T15:54:58Z","date_created":"2020-08-12T15:54:58Z","summary":null,"body":["<article data-history-node-id=\"2033\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-299<br \/>\nDate: 12 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 ICS-CERT released an Advisory highlighting vulnerabilities affecting the following Yokogawa CENTUM products:<\/p>\n\n<ul><li>CENTUM (Including CENTUM CS 3000 Entry Class) CS 3000 - versions R3.08.10 to R3.09.50<\/li>\n\t<li>CENTUM VP (Including CENTUM VP Entry Class) - versions R4.01.00 to R6.07.00<\/li>\n\t<li>B\/M9000CS - versions R5.04.01 to R5.05.01<\/li>\n\t<li>B\/M9000 VP - versions R6.01.01 to R8.03.01<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a remote actor to send modified packets, create and overwrite files or execute arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates when available.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-224-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-224-01<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-0","alert_type":398,"serial_number":"AV20-299","subject":null,"moderation_state":"published","external_url":null},{"nid":2034,"title":"Microsoft security advisory \u2013 August 2020 monthly rollup","uuid":"6d49ba6f-aa13-47eb-a5be-726d0e088d5b","banner":null,"lang":"en","date_modified":"2020-08-12","date_modified_ts":"2020-08-12T16:20:24Z","date_created":"2020-08-12T16:20:24Z","summary":null,"body":["<article data-history-node-id=\"2034\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-300<br \/>\nDate: 12 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 Microsoft released security updates to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>ChakraCore<\/li>\n\t<li>Internet Explorer 11<\/li>\n\t<li>.NET Framework<\/li>\n\t<li>Microsoft Outlook<\/li>\n\t<li>Microsoft Edge (EdgeHTML-based)<\/li>\n\t<li>Microsoft Windows<\/li>\n\t<li>Microsoft Windows Server<\/li>\n<\/ul><p>Of note are two zero-day vulnerabilities that Microsoft has reported as being actively exploited and have since been patched. CVE-2020-1380 is a remote code execution vulnerability in Internet Explorer 11 that could allow a malicious actor to execute arbitrary code in the context of the current user. CVE-2020-1464 is the result of incorrect validation of file signatures in Windows and could allow a malicious actor to bypass security features and load improperly signed files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates as soon as possible.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>August 2020 Release Notes<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Aug\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Aug<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-300","subject":null,"moderation_state":"published","external_url":null},{"nid":2035,"title":"Intel security advisory","uuid":"d0047ef8-42b3-4126-9166-ae2b34551908","banner":null,"lang":"en","date_modified":"2020-08-12","date_modified_ts":"2020-08-12T18:52:33Z","date_created":"2020-08-12T18:52:33Z","summary":null,"body":["<article data-history-node-id=\"2035\" about=\"\/en\/alerts-advisories\/intel-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-302<br \/>\nDate: 12 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 Intel published Advisories to address vulnerabilities in multiple products. Included were critical updates for the following Intel Server Boards, Server Systems and Compute Modules:<\/p>\n\n<ul><li>Server System R1000WT and R2000WT Families<\/li>\n\t<li>Server Boards S2600WT Family<\/li>\n\t<li>Server Board S2600CW Family<\/li>\n\t<li>Compute Module HNS2600KP Family<\/li>\n\t<li>Server Board S2600KP Family<\/li>\n\t<li>Compute Module HNS2600TP Family<\/li>\n\t<li>Server Board S2600TP Family<\/li>\n\t<li>Server System R1000SP, LSVRP and LR1304SP Families<\/li>\n\t<li>Server Board S1200SP Family<\/li>\n\t<li>Server System R1000WF and R2000WF Families<\/li>\n\t<li>Server Board S2600WF Family<\/li>\n\t<li>Server Board S2600ST Family<\/li>\n\t<li>Compute Module HNS2600BP Family<\/li>\n\t<li>Server Board S2600BP Family<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p>Intel Server Boards, Server Systems and Compute Modules Advisory<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00384.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00384.html<\/a><\/p>\n\n<p>Intel Product Security Center Advisories<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-13","alert_type":396,"serial_number":"AV20-302","subject":null,"moderation_state":"published","external_url":null},{"nid":2037,"title":"[Control systems] Schneider Electric security advisory","uuid":"d0544f18-4874-4065-ba30-e7bd02246fb9","banner":null,"lang":"en","date_modified":"2020-08-13","date_modified_ts":"2020-08-13T13:22:10Z","date_created":"2020-08-12T19:01:37Z","summary":null,"body":["<article data-history-node-id=\"2037\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-301<br \/>\nDate: 12 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 Schneider Electric published Security Notifications highlighting vulnerabilities in the following products:<\/p>\n\n<ul><li>Schneider Electric Modbus Serial Driver (64 bits) - versions prior to V3.20 IE 30.<\/li>\n\t<li>Schneider Electric Modbus Serial Driver (32 bits) - versions prior to V2.20 IE 30.<\/li>\n\t<li>Schneider Electric Modbus Driver Suite - versions prior to V14.15.0.0.<\/li>\n<\/ul><p style=\"margin-left: 40px;\">These drivers are used in multiple products including, but not limited to:<\/p>\n\n<ul type=\"circle\"><li style=\"margin-left: 40px;\">Ecostruxure Control Expert (formerly known as Unity Pro)<\/li>\n\t<li style=\"margin-left: 40px;\">Unity Loader<\/li>\n\t<li style=\"margin-left: 40px;\">EcoStruxure Process Expert (formerly known as Hybrid DCS)<\/li>\n\t<li style=\"margin-left: 40px;\">EcoStruxure OPC UA Server Expert<\/li>\n\t<li style=\"margin-left: 40px;\">OPC Factory Server<\/li>\n\t<li style=\"margin-left: 40px;\">Advantys Configuration Software<\/li>\n\t<li style=\"margin-left: 40px;\">Modbus Communications DTM (Field Devices)<\/li>\n\t<li style=\"margin-left: 40px;\">SoMove<\/li>\n\t<li style=\"margin-left: 40px;\">Ecostruxure Machine Expert (formerly known as SoMachine)<\/li>\n\t<li style=\"margin-left: 40px;\">Ecostruxure Machine Expert Basic<\/li>\n\t<li style=\"margin-left: 40px;\">Harmony\u00ae eXLhoist<\/li>\n\t<li style=\"margin-left: 40px;\">EcoStruxure Power Commission<\/li>\n<\/ul><ul><li>Schneider Electric spaceLYnk &amp; Wiser for KNX (formerly homeLYnk) - versions prior to V2.5.1<\/li>\n\t<li>Schneider Electric Modicon M218 Logic Controller - versions prior to V5.0.0.7<\/li>\n\t<li>APC Easy UPS On-Line Software - versions prior to V2.0<\/li>\n\t<li>PowerChute Business Edition Software - versions prior to V9.0.x<\/li>\n\t<li>Schneider Electric Harmony\u00ae eXLhoist Base Stations - versions prior to V 04.00.02.00<\/li>\n\t<li>SoMove software - versions prior to V2.8.1<\/li>\n<\/ul><p><br \/>\nSuccessful exploitation of these vulnerabilities may allow an actor to achieve local privilege escalation, perform unrestricted brute-force password attacks, cause a denial of service, upload executable files and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links, perform the suggested mitigations and apply the necessary manufacturer updates:<\/p>\n\n<p>Schneider Electric Modbus Serial Driver<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-01\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-01\/<\/a><\/p>\n\n<p>Schneider Electric spaceLYnk &amp; Wiser for KNX (formerly homeLYnk)<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-02\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-02\/<\/a><\/p>\n\n<p>Schneider Electric Modicon M218 Logic Controller<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-03\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-03\/<\/a><\/p>\n\n<p>APC Easy UPS On-Line Software<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-04\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-04\/<\/a><\/p>\n\n<p>PowerChute Business Edition<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-05\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-05\/<\/a><\/p>\n\n<p>Schneider Electric Harmony\u00ae eXLhoist Base Stations<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-06\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-06\/<\/a><\/p>\n\n<p>Schneider Electric SoMove Software<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-07\/\">https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2020-224-07\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-8","alert_type":398,"serial_number":"AV20-301","subject":null,"moderation_state":"published","external_url":null},{"nid":2036,"title":"[Control systems] Tridium security advisory","uuid":"d23d4092-fd9c-4b55-88db-3b5a7192570b","banner":null,"lang":"en","date_modified":"2020-08-12","date_modified_ts":"2020-08-12T19:51:58Z","date_created":"2020-08-12T19:51:58Z","summary":null,"body":["<article data-history-node-id=\"2036\" about=\"\/en\/alerts-advisories\/control-systems-tridium-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-303<br \/>\nDate: 12 August 2020<\/strong><\/p>\n\n<p>On 11 August 2020 ICS-CERT released an Advisory to highlight a vulnerability affecting the following Tridium products:<\/p>\n\n<ul><li>Niagara - versions 4.6.96.28, 4.7.109.20, 4.7.110.32 and 4.8.0.110<\/li>\n\t<li>Enterprise Security (EntSec) - versions 2.4.31, 2.4.45 and 4.8.0.35<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-224-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-224-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-tridium-security-advisory","alert_type":398,"serial_number":"AV20-303","subject":null,"moderation_state":"published","external_url":null},{"nid":2038,"title":"Disclosure of Drovorub Malware \u2013 NSA\/FBI","uuid":"dcc9c015-7117-422e-b757-79844be7e80b","banner":null,"lang":"en","date_modified":"2020-08-14","date_modified_ts":"2020-08-14T19:07:13Z","date_created":"2020-08-14T19:07:13Z","summary":null,"body":["<article data-history-node-id=\"2038\" about=\"\/en\/alerts-advisories\/disclosure-drovorub-malware-nsafbi\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-021<\/strong>\n  <br \/><strong>Date:\u00a014 August\u00a02020<\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>PURPOSE\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>ASSESSMENT\n<\/h2>\n<p>On 13 August 2020 the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) produced a joint Cybersecurity Advisory exposing previously undisclosed malware known as Drovorub, designed to target systems running the Linux operating system. The Cyber Centre would like to highlight the Advisory, as it provides important prevention, detection and mitigation advice to system owners and operators responsible for defending their systems and networks from cyber threats.\n<\/p>\n<p>Should organizations identify similar activity to that described in the referenced Advisory, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>\n  <br \/>\n  Press Release:\n  <br \/><a href=\"https:\/\/www.nsa.gov\/news-features\/press-room\/Article\/2311407\/nsa-and-fbi-expose-russian-previously-undisclosed-malware-drovorub-in-cybersecu\/\">https:\/\/www.nsa.gov\/news-features\/press-room\/Article\/2311407\/nsa-and-fbi-expose-russian-previously-undisclosed-malware-drovorub-in-cybersecu\/<\/a>\n<\/p>\n<p>Technical Summary:\n  <br \/><a href=\"https:\/\/media.defense.gov\/2020\/Aug\/13\/2002476465\/-1\/-1\/0\/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF\">https:\/\/media.defense.gov\/2020\/Aug\/13\/2002476465\/-1\/-1\/0\/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF<\/a>\n<\/p>\n<p>\n  <br \/><strong>NOTE TO READERS<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/disclosure-drovorub-malware-nsafbi","alert_type":397,"serial_number":"AL20-021","subject":null,"moderation_state":"published","external_url":null},{"nid":2039,"title":"[Control systems] B&R security advisory","uuid":"dd7bc90d-b78c-45ee-a061-17f4bac28727","banner":null,"lang":"en","date_modified":"2020-08-17","date_modified_ts":"2020-08-17T15:11:15Z","date_created":"2020-08-17T15:09:09Z","summary":null,"body":["<article data-history-node-id=\"2039\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-304<br \/>\nDate: 17 August 2020<\/strong><br \/><br \/>\nOn 12 August 2020 B&amp;R published a Cyber Security Advisory to address a vulnerability in the following versions of its Automation Runtime:<\/p>\n\n<ul><li>4.2x prior to N4.26<\/li>\n\t<li>4.3x prior to N4.34<\/li>\n\t<li>4.4x prior to F4.45<\/li>\n\t<li>4.5x prior to E4.53<\/li>\n\t<li>4.6x prior to D4.63<\/li>\n\t<li>4.7x prior to A4.73<\/li>\n<\/ul><p><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1595163815396-de-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1595163815396-de-original-1.0.pdf<\/a><\/p>\n\n<p>Exploitation of this vulnerability could result in a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates when available.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory","alert_type":398,"serial_number":"AV20-304","subject":null,"moderation_state":"published","external_url":null},{"nid":2040,"title":"IBM security advisory","uuid":"32a099cd-6bda-497c-8ff2-98b1fc59aaac","banner":null,"lang":"en","date_modified":"2020-08-18","date_modified_ts":"2020-08-18T12:10:24Z","date_created":"2020-08-18T12:10:24Z","summary":null,"body":["<article data-history-node-id=\"2040\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-305<br \/>\nDate: 18 August 2020<\/strong><br \/>\n\u00a0<br \/>\nBetween 10 and 17 August 2020 IBM released Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Netezza Host Management - versions 5.4.17.0 to 5.4.27.0<\/li>\n\t<li>IBM Operations Analytics Predictive Insights - version 1.3.6<\/li>\n\t<li>IBM SAN Volume Controller<\/li>\n\t<li>IBM Storwize V7000, V5000, V5100, V3700 and V3500 - versions 7.8.x, 8.2.x and 8.3.x<\/li>\n\t<li>IBM Spectrum Virtualize for Public Cloud - versions 7.8.x, 8.2.x and 8.3.x<\/li>\n\t<li>IBM FlashSystem V9000 and 9100 family products - versions 7.8.x, 8.2.x and 8.3.x<\/li>\n\t<li>IBM Tivoli Application Dependency Discovery Manager - versions 7.3.0.0 to 7.3.0.7<\/li>\n\t<li>Netcool Operations Insight \u2013 Cloud Native Event Analytics - version 1.6.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Netezza Host Management<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-publicly-disclosed-vulnerability-from-qemu-affects-ibm-netezza-host-management\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-publicly-disclosed-vulnerability-from-qemu-affects-ibm-netezza-host-management\/<\/a><\/p>\n\n<p>IBM Operations Analytics Predictive Insights<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-apache-camels-jmx-apache-camel-rabbitmq-and-apache-camel-netty-affects-ibm-operations-analytics-predictive-insights-cve-2020-11971-cve-2020-11972-cve\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-apache-camels-jmx-apache-camel-rabbitmq-and-apache-camel-netty-affects-ibm-operations-analytics-predictive-insights-cve-2020-11971-cve-2020-11972-cve\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-databind-affects-ibm-operations-analytics-predictive-insights-cve-2019-14060-cve-2019-14661-cve-2019-14662\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-databind-affects-ibm-operations-analytics-predictive-insights-cve-2019-14060-cve-2019-14661-cve-2019-14662\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-vulnerability-in-faster-xml-jackson-databind-affects-ibm-operations-analytics-predictive-insights-cve-2019-144892-cve-2019-144893\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-vulnerability-in-faster-xml-jackson-databind-affects-ibm-operations-analytics-predictive-insights-cve-2019-144892-cve-2019-144893\/<\/a><\/p>\n\n<p>IBM SAN Volume Controller; IBM Storwize V7000, V5000, V5100, V3700 and V3500; IBM Spectrum Virtualize for Public Cloud; IBM FlashSystem V9000 and 9100 family products<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openslp-vulnerability-affects-ibm-san-volume-controller-ibm-storwize-ibm-spectrum-virtualize-and-ibm-flashsystem-products\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openslp-vulnerability-affects-ibm-san-volume-controller-ibm-storwize-ibm-spectrum-virtualize-and-ibm-flashsystem-products\/<\/a><\/p>\n\n<p>IBM Tivoli Application Dependency Discovery Manager<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-apache-log4j-publicly-disclosed-vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-apache-log4j-publicly-disclosed-vulnerability\/<\/a><\/p>\n\n<p>Netcool Operations Insight \u2013 Cloud Native Event Analytics<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-netcool-operations-insight-cloud-native-event-analytics-is-affected-by-a-international-components-for-unicode-icu-for-c-c-vulnerability-cve-2020-10531\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-netcool-operations-insight-cloud-native-event-analytics-is-affected-by-a-international-components-for-unicode-icu-for-c-c-vulnerability-cve-2020-10531\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-13","alert_type":396,"serial_number":"AV20-305","subject":null,"moderation_state":"published","external_url":null},{"nid":2041,"title":"Google Chrome security advisory","uuid":"5be8e39e-5065-4e24-85e4-aa3eba20a22c","banner":null,"lang":"en","date_modified":"2020-08-19","date_modified_ts":"2020-08-19T12:05:33Z","date_created":"2020-08-19T12:05:33Z","summary":null,"body":["<article data-history-node-id=\"2041\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-306<br \/>\nDate: 19 August 2020<\/strong><\/p>\n\n<p>On 18 August 2020 Google announced the release of Chrome 84.0.4147.135 for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/08\/stable-channel-update-for-desktop_18.html\">https:\/\/chromereleases.googleblog.com\/2020\/08\/stable-channel-update-for-desktop_18.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-32","alert_type":396,"serial_number":"AV20-306","subject":null,"moderation_state":"published","external_url":null},{"nid":2042,"title":"Cisco security advisory","uuid":"e6e23537-e045-4cad-a607-e5d442a9c8bd","banner":null,"lang":"en","date_modified":"2020-08-20","date_modified_ts":"2020-08-20T15:39:07Z","date_created":"2020-08-20T15:39:07Z","summary":null,"body":["<article data-history-node-id=\"2042\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-59\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-307<br \/>\nDate: 20 August 2020<\/strong><\/p>\n\n<p>On 19 August 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included was a critical severity patch for the following:<\/p>\n\n<ul><li>Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series with NFVIS-bundled image releases 6.4.5, or 6.4.3d and prior<\/li>\n<\/ul><p>The affected software has user accounts with default, static passwords. By exploiting this vulnerability, a remote actor could gain access to the Network Functions Virtualization Infrastructure Software (NFVIS) command line interface (CLI), with administrator privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-59","alert_type":396,"serial_number":"AV20-307","subject":null,"moderation_state":"published","external_url":null},{"nid":2043,"title":"Microsoft security advisory","uuid":"c15f2f5d-1dec-4bcb-a48f-d436aac7be99","banner":null,"lang":"en","date_modified":"2020-08-21","date_modified_ts":"2020-08-21T13:35:49Z","date_created":"2020-08-21T13:35:49Z","summary":null,"body":["<article data-history-node-id=\"2043\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-308<br \/>\nDate: 21 August 2020<\/strong><\/p>\n\n<p>On 19 August 2020 Microsoft released an out-of-band security update to address vulnerabilities in the following versions of Windows:<\/p>\n\n<ul><li>Windows 8.1<\/li>\n\t<li>Windows RT 8.1<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n<\/ul><p><a href=\"https:\/\/support.microsoft.com\/en-ca\/help\/4578013\/security-update-for-windows-8-1-rt-8-1-and-server-2012-r2\">https:\/\/support.microsoft.com\/en-ca\/help\/4578013\/security-update-for-windows-8-1-rt-8-1-and-server-2012-r2<\/a><\/p>\n\n<p>An actor with execution rights on affected systems could exploit a memory handling flaw in Windows Remote Access to escalate privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates as soon as possible.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-7","alert_type":396,"serial_number":"AV20-308","subject":null,"moderation_state":"published","external_url":null},{"nid":2044,"title":"[Control systems] Philips security advisory","uuid":"bd4d20db-326e-4d22-9945-35be81cfd366","banner":null,"lang":"en","date_modified":"2020-08-21","date_modified_ts":"2020-08-21T19:15:33Z","date_created":"2020-08-21T19:15:33Z","summary":null,"body":["<article data-history-node-id=\"2044\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-309<br \/>\nDate: 21 August 2020<\/strong><\/p>\n\n<p>On 20 August 2020 Philips published a Security Advisory to address multiple vulnerabilities in its SureSigns VS4 patient monitoring system - versions A.07.107 and prior.<\/p>\n\n<p><a href=\"https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security\">https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security<\/a><\/p>\n\n<p>Exploitation may allow an unauthorized user access to administrative controls and system configurations which could allow changes to system configuration items, causing patient data to be sent to a remote destination.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-5","alert_type":398,"serial_number":"AV20-309","subject":null,"moderation_state":"published","external_url":null},{"nid":2045,"title":"IBM security advisory","uuid":"2fe706ae-3d03-4391-8047-e0eb79b50bc8","banner":null,"lang":"en","date_modified":"2020-08-24","date_modified_ts":"2020-08-24T15:32:46Z","date_created":"2020-08-24T15:32:46Z","summary":null,"body":["<article data-history-node-id=\"2045\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-310<br \/>\nDate: 24 August 2020<\/strong><\/p>\n\n<p>Between 17 and 23 August 2020 IBM released Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Spectrum Protect Plus - versions 10.1.0 to 10.1.6<\/li>\n\t<li>IBM Cloud Pak System - versions 2.3.0.1 to 2.3.1.1<\/li>\n\t<li>IBM Spectrum Control - 5.3.1 to 5.3.7<\/li>\n\t<li>IBM Operations Analytics Predictive Insights - 1.3.6<\/li>\n\t<li>IBM Cloud Private - 3.2.1 CD to 3.2.2 CD<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Spectrum Protect Plus<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042-2\/<\/a><\/p>\n\n<p>IBM Cloud Pak System<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-identified-in-docker-for-red-hat-enterprise-linux\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-identified-in-docker-for-red-hat-enterprise-linux\/<\/a><\/p>\n\n<p>IBM Spectrum Control<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-control-cve-2020-8172-cve-2020-8174-cve-2020-11080\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-node-js-affect-ibm-spectrum-control-cve-2020-8172-cve-2020-8174-cve-2020-11080\/<\/a><\/p>\n\n<p>IBM Operations Analytics Predictive Insights<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-vulnerability-in-apache-spark-2-4-5-and-earlier-affects-ibm-operations-analytics-predictive-insights-cve-2020-9480\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-vulnerability-in-apache-spark-2-4-5-and-earlier-affects-ibm-operations-analytics-predictive-insights-cve-2020-9480\/<\/a><\/p>\n\n<p>IBM Cloud Private<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-private-is-vulnerable-to-multiple-node-js-vulnerabilities-cve-2020-11080-cve-2020-10531-cve-2020-8172-cve-2020-8174\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-private-is-vulnerable-to-multiple-node-js-vulnerabilities-cve-2020-11080-cve-2020-10531-cve-2020-8172-cve-2020-8174\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-14","alert_type":396,"serial_number":"AV20-310","subject":null,"moderation_state":"published","external_url":null},{"nid":2046,"title":"Mozilla security advisory","uuid":"ca9485af-d811-4425-88b1-14b84c224f75","banner":null,"lang":"en","date_modified":"2020-08-25","date_modified_ts":"2020-08-25T18:00:10Z","date_created":"2020-08-25T18:00:10Z","summary":null,"body":["<article data-history-node-id=\"2046\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-311<br \/>\nDate: 25 August 2020<\/strong><\/p>\n\n<p>On 25 August 2020 Mozilla released Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR 78.2<\/li>\n\t<li>Firefox ESR 68.12<\/li>\n\t<li>Firefox 80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Firefox ESR 78.2<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-38\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-38\/<\/a>\u00a0<\/p>\n\n<p>Firefox ESR 68.12<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-37\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-37\/<\/a>\u00a0<\/p>\n\n<p>Firefox 80<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-36\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-36\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-19","alert_type":396,"serial_number":"AV20-311","subject":null,"moderation_state":"published","external_url":null},{"nid":2047,"title":"Google Chrome security advisory","uuid":"158c7f42-243f-4f7b-9652-d9dbd7eafd33","banner":null,"lang":"en","date_modified":"2020-08-25","date_modified_ts":"2020-08-25T19:36:18Z","date_created":"2020-08-25T19:36:18Z","summary":null,"body":["<article data-history-node-id=\"2047\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-312<br \/>\nDate: 25 August 2020<\/strong><\/p>\n\n<p>On 25 August 2020 Google announced the release of Chrome 85.0.4183.83 for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/08\/stable-channel-update-for-desktop_25.html\">https:\/\/chromereleases.googleblog.com\/2020\/08\/stable-channel-update-for-desktop_25.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-33","alert_type":396,"serial_number":"AV20-312","subject":null,"moderation_state":"published","external_url":null},{"nid":2048,"title":"[Control systems] Advantech security advisory","uuid":"9a3fcb27-9237-41e9-80e2-8417063cf551","banner":null,"lang":"en","date_modified":"2020-08-26","date_modified_ts":"2020-08-26T14:04:26Z","date_created":"2020-08-26T14:04:26Z","summary":null,"body":["<article data-history-node-id=\"2048\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-313<br \/>\nDate: 26 August 2020<\/strong><\/p>\n\n<p>On 25 August 2020 ICS-CERT published an Advisory to highlight a vulnerability in the Advantech iView - version 5.7 and prior.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-238-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-238-01<\/a><\/p>\n\n<p>Exploitation of this vulnerability could result in denial-of-service, information disclosure or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-8","alert_type":398,"serial_number":"AV20-313","subject":null,"moderation_state":"published","external_url":null},{"nid":2049,"title":"[Control systems] WECON security advisory","uuid":"b9817eff-6fe0-48bf-8288-bc202454ce7a","banner":null,"lang":"en","date_modified":"2020-08-26","date_modified_ts":"2020-08-26T14:07:58Z","date_created":"2020-08-26T14:07:58Z","summary":null,"body":["<article data-history-node-id=\"2049\" about=\"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-314<br \/>\nDate: 26 August 2020<\/strong><\/p>\n\n<p>On 25 August 2020 ICS-CERT published an Advisory to highlight a vulnerability in the WECON LeviStudioU - version 2019-09-21 and prior.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-238-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-238-03<\/a>\u00a0<\/p>\n\n<p>Exploitation of this vulnerability could result in the execution of arbitrary code under the privileges of the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer update.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-0","alert_type":398,"serial_number":"AV20-314","subject":null,"moderation_state":"published","external_url":null},{"nid":2050,"title":"Pulse Secure security advisory","uuid":"1105ac90-004e-4826-baa6-13b7a3553378","banner":null,"lang":"en","date_modified":"2020-08-26","date_modified_ts":"2020-08-26T17:29:58Z","date_created":"2020-08-26T17:29:58Z","summary":null,"body":["<article data-history-node-id=\"2050\" about=\"\/en\/alerts-advisories\/pulse-secure-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-315<br \/>\nDate: 26 August 2020<\/strong><\/p>\n\n<p>On 27 July 2020 Pulse Secure released a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Pulse Connect Secure \u2013 prior to version 9.1R8<\/li>\n\t<li>Pulse Policy Secure \u2013 prior to version 9.1R8<\/li>\n<\/ul><p><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44516\/\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44516\/<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/pulse-secure-security-advisory","alert_type":396,"serial_number":"AV20-315","subject":null,"moderation_state":"published","external_url":null},{"nid":2051,"title":"Cisco security advisory","uuid":"2ad1ab27-5614-4ab3-a1d9-1257e673d8f2","banner":null,"lang":"en","date_modified":"2020-08-27","date_modified_ts":"2020-08-27T18:10:14Z","date_created":"2020-08-27T18:10:14Z","summary":null,"body":["<article data-history-node-id=\"2051\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-60\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-316<br \/>\nDate: 27 August 2020<\/strong><\/p>\n\n<p>On 26 August 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were high severity patches for the following:<\/p>\n\n<ul><li>Cisco FXOS Software<\/li>\n\t<li>Cisco NX-OS Software<\/li>\n\t<li>Cisco UCS Software<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a>\u00a0<\/p>\n\n<p>Cisco Event Response<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/viewErp.x?alertId=ERP-74239\">https:\/\/tools.cisco.com\/security\/center\/viewErp.x?alertId=ERP-74239<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-60","alert_type":396,"serial_number":"AV20-316","subject":null,"moderation_state":"published","external_url":null},{"nid":2052,"title":"[Control systems] Red Lion security advisory","uuid":"18097477-e6f0-4845-a731-7b0e6a3e7222","banner":null,"lang":"en","date_modified":"2020-08-28","date_modified_ts":"2020-08-28T15:00:35Z","date_created":"2020-08-28T15:00:35Z","summary":null,"body":["<article data-history-node-id=\"2052\" about=\"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-317<br \/>\nDate: 28 August 2020<\/strong><\/p>\n\n<p>On 27 August 2020 ICS-CERT published an Advisory to highlight multiple vulnerabilities in the following Red Lion products:<\/p>\n\n<ul><li>N-Tron 702-W - all versions<\/li>\n\t<li>N-Tron 702M12-W - all versions<\/li>\n<\/ul><p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-240-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-240-01<\/a>\u00a0\u00a0<\/p>\n\n<p>Exploitation of some of these vulnerabilities could result in the remote execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory","alert_type":398,"serial_number":"AV20-317","subject":null,"moderation_state":"published","external_url":null},{"nid":2053,"title":"IBM security advisory","uuid":"520d305a-1d36-4cd9-8c11-b9ed94d91aa0","banner":null,"lang":"en","date_modified":"2020-09-01","date_modified_ts":"2020-09-01T12:13:00Z","date_created":"2020-09-01T12:13:00Z","summary":null,"body":["<article data-history-node-id=\"2053\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-318<br \/>\nDate: 1 September 2020<\/strong><\/p>\n\n<p>Between 24 and 30 August 2020 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Watson Discovery for IBM Cloud Pak for Data - versions 2.0.0 to 2.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Watson Discovery for IBM Cloud Pak for Data<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-fasterxml-jackson-databind-7\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-fasterxml-jackson-databind-7\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-apache-spark\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-apache-spark\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-15","alert_type":396,"serial_number":"AV20-318","subject":null,"moderation_state":"published","external_url":null},{"nid":2054,"title":"[Control systems] Mitsubishi security advisory","uuid":"4b7a87a8-4ffe-4b41-a915-bd22b3a26f03","banner":null,"lang":"en","date_modified":"2020-09-02","date_modified_ts":"2020-09-02T14:03:16Z","date_created":"2020-09-02T14:03:16Z","summary":null,"body":["<article data-history-node-id=\"2054\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-319<br \/>\nDate: 2 September 2020<\/strong><\/p>\n\n<p>On 1 September 2020 ICS-CERT published an Advisory to highlight a vulnerability affecting the following Mitsubishi products:<\/p>\n\n<ul><li>\u00a0QJ71MES96 - all versions<\/li>\n\t<li>\u00a0QJ71WS96 - all versions<\/li>\n\t<li>\u00a0Q06CCPU-V - all versions<\/li>\n\t<li>\u00a0Q24DHCCPU-V - all versions<\/li>\n\t<li>\u00a0Q24DHCCPU-VG - all versions<\/li>\n\t<li>\u00a0R12CCPU-V - all versions<\/li>\n\t<li>\u00a0RD55UP06-V - all versions<\/li>\n\t<li>\u00a0RD55UP12-V - all versions<\/li>\n\t<li>\u00a0RJ71GN11-T2 - all versions<\/li>\n\t<li>\u00a0RJ71EN71 - all versions<\/li>\n\t<li>\u00a0QJ71E71-100 - all versions<\/li>\n\t<li>\u00a0LJ71E71-100 - all versions<\/li>\n\t<li>\u00a0QJ71MT91 - all versions<\/li>\n\t<li>\u00a0RD78Gn(n=4,8,16,32,64) - all versions<\/li>\n\t<li>\u00a0RD78GHV - all versions<\/li>\n\t<li>\u00a0RD78GHW - all versions<\/li>\n\t<li>\u00a0NZ2GACP620-60 - all versions<\/li>\n\t<li>\u00a0NZ2GACP620-300 - all versions<\/li>\n\t<li>\u00a0NZ2FT-MT - all versions<\/li>\n\t<li>\u00a0NZ2FT-EIP - all versions<\/li>\n\t<li>\u00a0Q03UDECPU - the first 5 digits of serial number 22081 and prior<\/li>\n\t<li>\u00a0QnUDEHCPU(n=04\/06\/10\/13\/20\/26\/50\/100) - the first 5 digits of serial number 22081 and prior<\/li>\n\t<li>\u00a0QnUDVCPU(n=03\/04\/06\/13\/26) - the first 5 digits of serial number 22031 and prior<\/li>\n\t<li>\u00a0QnUDPVCPU(n=04\/06\/13\/2) - the first 5 digits of serial number 22031 and prior<\/li>\n\t<li>\u00a0LnCPU(-P)(n=02\/06\/26) - the first 5 digits of serial number 22051 and prior<\/li>\n\t<li>\u00a0L26CPU-(P)BT - the first 5 digits of serial number 22051 and prior<\/li>\n\t<li>\u00a0RnCPU(n=00\/01\/02) - version 18 and prior<\/li>\n\t<li>\u00a0RnCPU(n=04\/08\/16\/32\/120) - version 50 and prior<\/li>\n\t<li>\u00a0RnENCPU(n=04\/08\/16\/32\/120) - version 50 and prior<\/li>\n\t<li>\u00a0RnSFCPU (n=08\/16\/32\/120) - all versions<\/li>\n\t<li>\u00a0RnPCPU(n=08\/16\/32\/120) - all versions<\/li>\n\t<li>\u00a0RnPSFCPU(n=08\/16\/32\/120) - all versions<\/li>\n\t<li>\u00a0FX5U(C)-**M*\/**\n\t<ul><li>\u00a0 Case1: Serial number 17X**** or later - version 1.210 and prior<\/li>\n\t\t<li>\u00a0 Case2: Serial number 179**** and prior - version 1.070 and prior<\/li>\n\t<\/ul><\/li>\n\t<li>\u00a0FX5UC-32M*\/**-TS - version 1.210 and prior<\/li>\n\t<li>\u00a0FX5UJ-**M*\/** - version 1.000<\/li>\n\t<li>\u00a0FX5-ENET - all versions<\/li>\n\t<li>\u00a0FX5-ENET\/IP - all versions<\/li>\n\t<li>\u00a0FX3U-ENET-ADP - all versions<\/li>\n\t<li>\u00a0FX3GE-**M*\/** - all versions<\/li>\n\t<li>\u00a0FX3U-ENET - all versions<\/li>\n\t<li>\u00a0FX3U-ENET-L - all versions<\/li>\n\t<li>\u00a0FX3U-ENET-P502 - all versions<\/li>\n\t<li>\u00a0FX5-CCLGN-MS - all versions<\/li>\n\t<li>\u00a0IU1-1M20-D - all versions<\/li>\n\t<li>\u00a0LE7-40GU-L - all versions<\/li>\n\t<li>\u00a0GOT2000 Series GT21 Model - all versions<\/li>\n\t<li>\u00a0GS Series - all versions<\/li>\n\t<li>\u00a0GOT1000 Series GT14 Model - all versions<\/li>\n\t<li>\u00a0GT25-J71GN13-T2 - all versions<\/li>\n\t<li>\u00a0FR-A800-E Series - all versions<\/li>\n\t<li>\u00a0FR-F800-E Series - all versions<\/li>\n\t<li>\u00a0FR-A8NCG - production date August 2020 and prior<\/li>\n\t<li>\u00a0FR-E800-EPA Series - production date July 2020 and prior<\/li>\n\t<li>\u00a0FR-E800-EPB Series - production date July 2020 and prior<\/li>\n\t<li>\u00a0Conveyor Tracking Application APR-nTR3FH, APR-nTR6FH, APR-nTR12FH, APR-nTR20FH(n=1,2) - all versions (Discontinued product)<\/li>\n\t<li>\u00a0MR-JE-C - all versions<\/li>\n\t<li>\u00a0MR-J4-TM - all versions<\/li>\n<\/ul><p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-245-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-245-01<\/a><\/p>\n\n<p>Exploitation of this vulnerability could allow a remote actor to hijack TCP sessions and execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the\u00a0 Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-security-advisory","alert_type":398,"serial_number":"AV20-319","subject":null,"moderation_state":"published","external_url":null},{"nid":2055,"title":"Cisco security advisory","uuid":"d9cf49f9-95fa-4303-ab6c-c5013062dcc6","banner":null,"lang":"en","date_modified":"2020-09-03","date_modified_ts":"2020-09-03T13:52:46Z","date_created":"2020-09-03T13:52:46Z","summary":null,"body":["<article data-history-node-id=\"2055\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-61\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-320<br \/>\nDate: 3 September 2020<\/strong><\/p>\n\n<p>On 2 September 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included was a critical severity patch for the following:<\/p>\n\n<ul><li>\u00a0Cisco Jabber for Windows - versions prior to 12.1.3, 12.5.2, 12.6.3, 12.7.2, 12.8.3, or 12.9.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated, remote actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-61","alert_type":396,"serial_number":"AV20-320","subject":null,"moderation_state":"published","external_url":null},{"nid":2057,"title":"Adobe security advisory","uuid":"f3bcb769-c80d-4e2e-88d5-eb1307996542","banner":null,"lang":"en","date_modified":"2020-09-08","date_modified_ts":"2020-09-08T19:51:35Z","date_created":"2020-09-08T19:50:57Z","summary":null,"body":["<article data-history-node-id=\"2057\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-321<br \/>\nDate: 8 September 2020<\/strong><br \/><br \/>\nOn 8 September 2020 Adobe published Security Bulletins to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Experience Manager - multiple versions<\/li>\n\t<li>Adobe Framemaker - version 2019.0.6\u202fand prior<\/li>\n\t<li>Adobe InDesign \u2013 version 15.1.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Adobe Experience Manager<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb20-56.html\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb20-56.html<\/a><\/p>\n\n<p>Adobe Framemaker<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb20-54.html\">https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb20-54.html<\/a><\/p>\n\n<p>Adobe InDesign<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb20-52.html\">https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb20-52.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-26","alert_type":396,"serial_number":"AV20-321","subject":null,"moderation_state":"published","external_url":null},{"nid":2056,"title":"Intel security advisory","uuid":"7fcee76b-c29b-4ae8-a6d3-6371402bc4f7","banner":null,"lang":"en","date_modified":"2020-09-08","date_modified_ts":"2020-09-08T19:58:44Z","date_created":"2020-09-08T19:54:06Z","summary":null,"body":["<article data-history-node-id=\"2056\" about=\"\/en\/alerts-advisories\/intel-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-322<br \/>\nDate: 8 September 2020<\/strong><br \/><br \/>\nOn 8 September 2020 Intel published Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Intel Active Management Technology (AMT)<\/li>\n\t<li>Intel Standard Manageability (ISM)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p>Intel AMT and Intel ISM Advisory<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00404.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00404.html<\/a><\/p>\n\n<p>Intel Product Security Center Advisories<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-14","alert_type":396,"serial_number":"AV20-322","subject":null,"moderation_state":"published","external_url":null},{"nid":2059,"title":"Microsoft security advisory \u2013 September 2020 monthly rollup","uuid":"8f76eb04-7435-460b-9c03-bcd3f278525c","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T14:04:53Z","date_created":"2020-09-09T13:49:49Z","summary":null,"body":["<article data-history-node-id=\"2059\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-323<br \/>\nDate:\u00a09 September 2020<\/strong><\/p>\n\n<p>On 8 September 2020 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>\u00a0ChakraCore<\/li>\n\t<li>\u00a0Dynamics 365 for Finance and Operations<\/li>\n\t<li>\u00a0Internet Explorer 11<\/li>\n\t<li>\u00a0Microsoft Business Productivity Servers 2010 Service Pack 2<\/li>\n\t<li>\u00a0Microsoft Dynamics 365 (on-premises) version 9.0<\/li>\n\t<li>\u00a0Microsoft Edge (EdgeHTML-based)<\/li>\n\t<li>\u00a0Microsoft Exchange Server - multiple versions<\/li>\n\t<li>\u00a0Microsoft SharePoint - multiple versions<\/li>\n\t<li>\u00a0Microsoft Visual Studio - multiple versions<\/li>\n\t<li>\u00a0Microsoft Windows - multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates as soon as possible.<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>September 2020 Release Notes<\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Sep\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Sep<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-323","subject":null,"moderation_state":"published","external_url":null},{"nid":2060,"title":"IBM security advisory","uuid":"bfc3eae8-8b53-4926-8ac9-d2ecd1d43140","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T14:07:12Z","date_created":"2020-09-09T13:56:07Z","summary":null,"body":["<article data-history-node-id=\"2060\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-324<br \/>\nDate:\u00a09 September 2020<\/strong><\/p>\n\n<p>Between 31 August 2020 and 7 September 2020 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>\u00a0IBM Operations Analytics Predictive Insights \u2013 version 1.3.6<\/li>\n\t<li>\u00a0IBM Security Guardium \u2013 multiple versions<\/li>\n\t<li>\u00a0IBM Security Guardium Insights \u2013 version 2.0.1<\/li>\n\t<li>\u00a0IBM Spectrum Protect Plus \u2013 versions 10.1.0 to 10.1.6<\/li>\n\t<li>\u00a0IBM Spectrum Protect Operations Center \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Operations Analytics Predictive Insights<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-affect-ibm-operations-analytics-predictive-insights-cve-2019-14060-cve-2019-14661-cve-2019-14662\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-affect-ibm-operations-analytics-predictive-insights-cve-2019-14060-cve-2019-14661-cve-2019-14662\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-databind-affect-ibm-operations-analytics-predictive-insights-4\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-faster-xml-jackson-databind-affect-ibm-operations-analytics-predictive-insights-4\/<\/a><\/p>\n\n<p>IBM Security Guardium<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-use-of-insufficiently-random-value-vulnerability-3\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-use-of-insufficiently-random-value-vulnerability-3\/<\/a><\/p>\n\n<p>IBM Security Guardium Insights<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-insights-is-affected-by-components-with-known-vulnerabilities-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-insights-is-affected-by-components-with-known-vulnerabilities-2\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Plus<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042-3\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-rsyslog-affect-ibm-spectrum-protect-plus-cve-2019-17041-cve-2019-17042-3\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Operations Center<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-code-injection-vulnerability-in-ibm-spectrum-protect-operations-center-cve-2020-4693\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-code-injection-vulnerability-in-ibm-spectrum-protect-operations-center-cve-2020-4693\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-16","alert_type":396,"serial_number":"AV20-324","subject":null,"moderation_state":"published","external_url":null},{"nid":2058,"title":"SAP security advisory","uuid":"b1fd842e-d6fb-43b7-9b50-44c3d580271e","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T14:04:19Z","date_created":"2020-09-09T14:01:40Z","summary":null,"body":["<article data-history-node-id=\"2058\" about=\"\/en\/alerts-advisories\/sap-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-325<br \/>\nDate:\u00a09 September 2020<\/strong><\/p>\n\n<p>On 8 September 2020 SAP published Security Advisories to highlight vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>\u00a0Marketing (Mobile Channel Servlet) - versions 130, 140, 150<\/li>\n\t<li>\u00a0NetWeaver (ABAP Server) and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755<\/li>\n<\/ul><p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=557449700\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=557449700<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-8","alert_type":396,"serial_number":"AV20-325","subject":null,"moderation_state":"published","external_url":null},{"nid":2061,"title":"[Control systems] Schneider Electric security advisory","uuid":"f4a554cf-fc83-4c62-88e9-0ff89706ed08","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T14:10:15Z","date_created":"2020-09-09T14:10:15Z","summary":null,"body":["<article data-history-node-id=\"2061\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-326<br \/>\nDate:\u00a09 September 2020<\/strong><br \/>\n\u00a0<br \/>\nOn 8 September 2020 Schneider Electric published a Security Notification to highlight vulnerabilities affecting the following products:<\/p>\n\n<ul><li>\u00a0SCADAPack 7x Remote Connect \u2013 versions 3.6.3.574 and prior<\/li>\n\t<li>\u00a0SCADAPack x70 Security Administrator \u2013 versions 1.2.0 and prior<\/li>\n<\/ul><p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-9","alert_type":398,"serial_number":"AV20-326","subject":null,"moderation_state":"published","external_url":null},{"nid":2062,"title":"[Control systems] Siemens security advisory","uuid":"0d49dceb-ec12-422e-ac36-c527dcc3fb29","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T14:33:10Z","date_created":"2020-09-09T14:25:53Z","summary":null,"body":["<article data-history-node-id=\"2062\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-327<br \/>\nDate:\u00a09 September 2020<\/strong><\/p>\n\n<p>On 8 September 2020 Siemens published Security Advisories to highlight vulnerabilities affecting the following products which included a critical update for the WIBU Systems CodeMeter Runtime:<\/p>\n\n<ul><li>\u00a0CloudConnect 712 \u2013 versions prior to 1.1.5<\/li>\n\t<li>\u00a0Development\/Evaluation Kits for PROFINET IO \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0Information Server \u2013 versions 2019 SP1 and prior<\/li>\n\t<li>\u00a0License Management Utility (LMU) \u2013 versions prior to 2.4<\/li>\n\t<li>\u00a0Opcenter \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0OpenPCS \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0Polarion Subversion Webclient \u2013 all versions<\/li>\n\t<li>\u00a0Process Historian (incl. Process Historian OPC UA Server) - versions 2019 and prior<\/li>\n\t<li>\u00a0PROFINET Driver for Controller \u2013 versions prior to 2.1<\/li>\n\t<li>\u00a0RFID 181EIP \u2013 all versions<\/li>\n\t<li>\u00a0ROX II \u2013 versions prior to 2.13.3<\/li>\n\t<li>\u00a0RUGGEDCOM \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SCALANCE \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SIMATIC \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SIMIT Simulation Platform \u2013 versions 10.0 and prior<\/li>\n\t<li>\u00a0SIMOCODE \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SIMOTION \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SINAMICS \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SINEC \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SINEMA \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SINUMERIK \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0SITOP \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0Siveillance Video Client \u2013 all versions<\/li>\n\t<li>\u00a0Soft Starter ES \u2013 all versions<\/li>\n\t<li>\u00a0SOFTNET-IE PNIO \u2013 all versions<\/li>\n\t<li>\u00a0Spectrum Power 4 \u2013 versions prior to 4.70 SP8<\/li>\n\t<li>\u00a0SPPA \u2013 multiple versions and platforms<\/li>\n\t<li>\u00a0TIM 1531 IRC (incl. SIPLUS NET variants) \u2013 versions prior to 2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-13","alert_type":398,"serial_number":"AV20-327","subject":null,"moderation_state":"published","external_url":null},{"nid":2065,"title":"Citrix security advisory","uuid":"0033ade3-a727-47f0-8114-16ab6830892c","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T16:19:23Z","date_created":"2020-09-09T15:53:12Z","summary":null,"body":["<article data-history-node-id=\"2065\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-328<br \/>\nDate:\u00a09 September 2020<\/strong><\/p>\n\n<p>On 8 September 2020 Citrix released a Security Update to address a vulnerability in Citrix StoreFront. The following versions of Citrix StoreFront are affected:<\/p>\n\n<ul><li>Citrix StoreFront \u2013 versions prior to 1909<\/li>\n\t<li>Citrix StoreFront 1912 LTSR \u2013 versions prior to CU1<\/li>\n\t<li>Citrix StoreFront 3.12 for 7.15 LTSR \u2013 versions prior to CU5 Hotfix<\/li>\n\t<li>Citrix StoreFront 3.0 for 7.6 LTSR \u2013 versions prior to CU8 Hotfix<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX277455\">https:\/\/support.citrix.com\/article\/CTX277455<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-7","alert_type":396,"serial_number":"AV20-328","subject":null,"moderation_state":"published","external_url":null},{"nid":2063,"title":"Google Chrome security advisory","uuid":"0125bc31-abcc-4d44-b097-72ea35f21d08","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T16:12:56Z","date_created":"2020-09-09T16:12:56Z","summary":null,"body":["<article data-history-node-id=\"2063\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-329<br \/>\nDate: 9 September 2020<\/strong><\/p>\n\n<p>On 8 September 2020 Google released a Security Update to address vulnerabilities in Chrome for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/09\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/09\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-34","alert_type":396,"serial_number":"AV20-329","subject":null,"moderation_state":"published","external_url":null},{"nid":2064,"title":"Android security advisory","uuid":"2538f1dd-5154-4f8d-b7c8-a62f7abf78ea","banner":null,"lang":"en","date_modified":"2020-09-09","date_modified_ts":"2020-09-09T16:15:35Z","date_created":"2020-09-09T16:15:35Z","summary":null,"body":["<article data-history-node-id=\"2064\" about=\"\/en\/alerts-advisories\/android-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-330<br \/>\nDate: 9 September 2020<\/strong><\/p>\n\n<p>On 8 September 2020 Android released Security Updates to address vulnerabilities in Android devices.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-09-01\">https:\/\/source.android.com\/security\/bulletin\/2020-09-01<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-15","alert_type":396,"serial_number":"AV20-330","subject":null,"moderation_state":"published","external_url":null},{"nid":2066,"title":"Palo Alto security advisory","uuid":"adbeb40a-70ea-45b6-a7af-a150a8cb6805","banner":null,"lang":"en","date_modified":"2020-09-10","date_modified_ts":"2020-09-10T14:05:04Z","date_created":"2020-09-10T14:04:13Z","summary":null,"body":["<article data-history-node-id=\"2066\" about=\"\/en\/alerts-advisories\/palo-alto-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-331<br \/>\nDate: 10 September 2020<\/strong><br \/><br \/>\nOn 9 September 2020 Palo Alto released Security Updates to address vulnerabilities in PAN-OS \u2013 versions 10.0, 9.1, 9.0, 8.1 and 8.0. Included were critical severity updates for the following:<\/p>\n\n<ul><li>PAN-OS 8.0 - all versions<\/li>\n\t<li>PAN-OS 8.1 - versions prior to 8.1.15<\/li>\n\t<li>PAN-OS 9.0 - versions prior to 9.0.9<\/li>\n\t<li>PAN-OS 9.1 - versions prior to 9.1.3<\/li>\n<\/ul><p>Exploitation of the critical vulnerability could allow an unauthenticated actor to disrupt system processes and potentially execute arbitrary code with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-security-advisory","alert_type":396,"serial_number":"AV20-331","subject":null,"moderation_state":"published","external_url":null},{"nid":2067,"title":"[Control systems] AVEVA security advisory","uuid":"eaa55d0b-7126-4302-9ead-95bef263fb63","banner":null,"lang":"en","date_modified":"2020-09-11","date_modified_ts":"2020-09-11T12:27:27Z","date_created":"2020-09-11T12:27:27Z","summary":null,"body":["<article data-history-node-id=\"2067\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-332<br \/>\nDate: 11 September 2020<\/strong><\/p>\n\n<p>On 10 September 2020, ICS-CERT published an Advisory to highlight a vulnerability in AVEVA Enterprise Data Management Web \u2013 versions 2019 and prior.<\/p>\n\n<p>Exploitation of this vulnerability could allow a remote malicious actor to execute arbitrary SQL commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-254-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-254-01<\/a><br \/>\n\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-0","alert_type":398,"serial_number":"AV20-332","subject":null,"moderation_state":"published","external_url":null},{"nid":2068,"title":"[Control systems] FATEK Automation security advisory","uuid":"64717818-c0e5-4e9b-a303-a0099f5a7e40","banner":null,"lang":"en","date_modified":"2020-09-11","date_modified_ts":"2020-09-11T12:30:41Z","date_created":"2020-09-11T12:30:41Z","summary":null,"body":["<article data-history-node-id=\"2068\" about=\"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-333<br \/>\nDate: 11 September 2020<\/strong><\/p>\n\n<p>On 10 September 2020, ICS-CERT published an Advisory to highlight a vulnerability in the following FATEK Automation products:<\/p>\n\n<ul><li>PLC WinProladder \u2013 versions prior to 3.28<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial-of-service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-254-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-254-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory","alert_type":398,"serial_number":"AV20-333","subject":null,"moderation_state":"published","external_url":null},{"nid":2069,"title":"[Control systems] Wibu-Systems AG security advisory","uuid":"bc859887-6507-4bcb-b76a-fbb723c6e975","banner":null,"lang":"en","date_modified":"2020-09-11","date_modified_ts":"2020-09-11T12:36:41Z","date_created":"2020-09-11T12:36:41Z","summary":null,"body":["<article data-history-node-id=\"2069\" about=\"\/en\/alerts-advisories\/control-systems-wibu-systems-ag-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-334<br \/>\nDate: 11 September 2020<\/strong><br \/><br \/>\nOn 8 September 2020, ICS-CERT published an Advisory to highlight vulnerabilities in Wibu-Systems AG CodeMeter Runtime \u2013 versions 7.10, 7.00, 6.81 and 6.90.<\/p>\n\n<p>Exploitation of these vulnerabilities could allow a malicious actor to alter and forge a license file, cause a denial-of-service, execute remote code, or expose sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-203-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-203-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wibu-systems-ag-security-advisory","alert_type":398,"serial_number":"AV20-334","subject":null,"moderation_state":"published","external_url":null},{"nid":2070,"title":"[Control systems] Philips security advisory","uuid":"3a0b330f-0e5f-4b15-b612-2f7df9e92976","banner":null,"lang":"en","date_modified":"2020-09-11","date_modified_ts":"2020-09-11T12:39:09Z","date_created":"2020-09-11T12:39:09Z","summary":null,"body":["<article data-history-node-id=\"2070\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-335<br \/>\nDate: 11 September 2020<\/strong><br \/><br \/>\nOn 10 September 2020, ICS-CERT published an Advisory to highlight vulnerabilities affecting the following Philips products:<\/p>\n\n<ul><li>Patient Information Center iX (PICiX) - versions B.02, C.02 and C.03<\/li>\n\t<li>PerformanceBridge Focal Point - version A.01<\/li>\n\t<li>IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 - versions N and prior<\/li>\n\t<li>IntelliVue X3 and X2 - versions N and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-254-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-254-01<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-6","alert_type":398,"serial_number":"AV20-335","subject":null,"moderation_state":"published","external_url":null},{"nid":2071,"title":"[Control systems] HMS Networks security advisory","uuid":"41b4d74c-9343-4ef3-8217-5985b696b620","banner":null,"lang":"en","date_modified":"2020-09-11","date_modified_ts":"2020-09-11T12:41:43Z","date_created":"2020-09-11T12:41:43Z","summary":null,"body":["<article data-history-node-id=\"2071\" about=\"\/en\/alerts-advisories\/control-systems-hms-networks-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-336<br \/>\nDate: 11 September 2020<\/strong><br \/><br \/>\nOn 10 September 2020, ICS-CERT published an Advisory to highlight a vulnerability in the following HMS Networks products:<\/p>\n\n<ul><li>Cosy - versions prior to 14.1<\/li>\n\t<li>Flexy - versions prior to 14.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow malicious actors to retrieve limited confidential information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-254-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-254-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hms-networks-security-advisory-0","alert_type":398,"serial_number":"AV20-336","subject":null,"moderation_state":"published","external_url":null},{"nid":2072,"title":"[Control systems] ABB security advisory","uuid":"0d50466f-48ca-49ff-8554-190b157fce31","banner":null,"lang":"en","date_modified":"2020-09-11","date_modified_ts":"2020-09-11T14:51:36Z","date_created":"2020-09-11T14:51:36Z","summary":null,"body":["<article data-history-node-id=\"2072\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-337<br \/>\nDate: 11 September 2020<\/strong><\/p>\n\n<p>On 10 September 2020 ABB released Security Updates to address multiple products affected by Wibu-Systems AG CodeMeter vulnerabilities:<\/p>\n\n<ul><li>ABB Ability Condition Monitoring for drives - versions 1.3.1 and prior<\/li>\n\t<li>ABB Ability Operations Data Management zenon - versions 8.10 and prior<\/li>\n\t<li>ABB Ability Virtual Commissioning for drives - versions 1.0.1 and prior<\/li>\n\t<li>AC 800PEC platform - versions 2.6.1.0 and prior<\/li>\n\t<li>Automation Builder - versions 2.3.0 and prior<\/li>\n\t<li>Automation Studio - versions 1.1.5 and prior<\/li>\n\t<li>Drive Application Builder - versions 1.1.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary manufacturer updates.<\/p>\n\n<p>ABB Security Advisory<br \/><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications<\/a><\/p>\n\n<p>[Control Systems] Wibu-Systems AG Security Advisory<br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-wibu-systems-ag-security-advisory\">https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-wibu-systems-ag-security-advisory<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-8","alert_type":398,"serial_number":"AV20-337","subject":null,"moderation_state":"published","external_url":null},{"nid":2073,"title":"IBM security advisory","uuid":"1b28db41-b883-48ac-9916-3f00dace78a0","banner":null,"lang":"en","date_modified":"2020-09-15","date_modified_ts":"2020-09-15T13:13:23Z","date_created":"2020-09-15T12:24:18Z","summary":null,"body":["<article data-history-node-id=\"2073\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-338<br \/>\nDate: 15 September 2020<\/strong><\/p>\n\n<p>Between 7 September 2020 and 13 September 2020 IBM published Security Bulletins to address vulnerabilities in multiple products including critical patches for IBM Cloud Pak System \u2013 versions 2.3.0.1 and 2.3.1.1.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Cloud Pak System<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-jackson-databind-shipped-with-ibm-cloud-pak-system\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-jackson-databind-shipped-with-ibm-cloud-pak-system\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-17","alert_type":396,"serial_number":"AV20-338","subject":null,"moderation_state":"published","external_url":null},{"nid":2074,"title":"Adobe security advisory","uuid":"78e475cd-5352-4f0f-b126-9b6f26ddcb63","banner":null,"lang":"en","date_modified":"2020-09-15","date_modified_ts":"2020-09-15T14:38:15Z","date_created":"2020-09-15T14:38:15Z","summary":null,"body":["<article data-history-node-id=\"2074\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-339<br \/>\nDate: 15 September 2020<\/strong><\/p>\n\n<p>On 15 September 2020 Adobe published a Security Bulletin to address vulnerabilities in Adobe Media Encoder \u2013 versions 14.3.2 and earlier.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb20-57.html\">https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb20-57.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-27","alert_type":396,"serial_number":"AV20-339","subject":null,"moderation_state":"published","external_url":null},{"nid":2086,"title":"Microsoft Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472 - update 1","uuid":"e89bb93c-7015-4132-b0a4-b35eae42d42a","banner":null,"lang":"en","date_modified":"2020-09-24","date_modified_ts":"2020-09-24T19:44:01Z","date_created":"2020-09-16T13:54:55Z","summary":null,"body":["<article data-history-node-id=\"2086\" about=\"\/en\/alerts-advisories\/microsoft-netlogon-elevation-privilege-vulnerability-cve-2020-1472\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-022 UPDATE 1<br \/>\nDate: 16 September 2020<br \/>\nUpdated: <strong>24 September 2020<\/strong><\/strong><\/p>\n\n<h3>AUDIENCE<\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h3>PURPOSE<\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3>OVERVIEW<\/h3>\n\n<p>The Cyber Centre has become aware of recently published proofs of concept exploit code related to CVE-2020-1472, a Netlogon elevation of privilege vulnerability. The Cyber Centre strongly recommends that organizations immediately patch vulnerable systems.<\/p>\n\n<h3>UPDATE<\/h3>\n\n<p>On 23 September 2020 Microsoft reported [<a href=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1308941504707063808\">4<\/a>] that CVE-2020-1472 is being actively exploited by malicious actors. Organizations that have not already updated affected systems should patch immediately and review for indicators of compromise (IOC). Several IOCs are supplied below in the INDICATORS OF COMPROMISE section.<\/p>\n\n<p>Proofpoint has released a Suricata Intrusion Detection System (IDS) signature [<a href=\"https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules\">5<\/a>] to assist in the identification of exploitation attempts.<\/p>\n\n<p>On 18 September 2020 the Samba Team published an advisory [<a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2020-1472.html\">6<\/a>] confirming that certain versions of Samba, when configured as a domain controller, are also vulnerable to CVE-2020-1472.<\/p>\n\n<h3>DETAILS<\/h3>\n\n<p>On 11 August 2020 Microsoft published Security Updates to address vulnerabilities in multiple products [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-september-2020-monthly-rollup \">1<\/a>], including an update for a critical privilege escalation vulnerability [<a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-1472\">2<\/a>]. Tracked as CVE-2020-1472 the exploit occurs when establishing a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol.<\/p>\n\n<p>Exploitation of this vulnerability could allow a malicious actor with local network access to escalate privileges to a domain administrator level.<\/p>\n\n<p>Microsoft is addressing this vulnerability using a two phased approach that is outlined in the below referenced Microsoft Guidelines [<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4557222\/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc\">3<\/a>].<\/p>\n\n<h3>SUGGESTED ACTION<\/h3>\n\n<p>The Cyber Centre recommends that organizations immediately install the latest security updates from Microsoft.<\/p>\n\n<h3>INDICATORS OF COMPROMISE<\/h3>\n\n<p>Microsoft has supplied the following sample exploit IOCs (SHA-256):<br \/><br \/>\nb9088bea916e1d2137805edeb0b6a549f876746999fbb1b4890fb66288a59f9d<br \/>\n24d425448e4a09e1e1f8daf56a1d893791347d029a7ba32ed8c43e88a2d06439<br \/>\nc4a97815d2167df4bdf9bfb8a9351f4ca9a175c3ef7c36993407c766b57c805b<\/p>\n\n<h3>REFERENCES<\/h3>\n\n<p>[1] Cyber Centre Advisory AV20-323:<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-september-2020-monthly-rollup\">https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-september-2020-monthly-rollup<\/a>\u00a0<\/p>\n\n<p>[2] Microsoft Advisory - CVE-2020-1472 Netlogon Elevation of Privilege Vulnerability:<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-1472\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-1472<\/a><\/p>\n\n<p>[3] Microsoft Guidelines - How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472:<br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4557222\/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc\">https:\/\/support.microsoft.com\/en-us\/help\/4557222\/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc<\/a><\/p>\n\n<p><strong>UPDATE:<\/strong> [4] Microsoft Security Intelligence (@MsftSecIntel):<br \/><a href=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1308941504707063808\">https:\/\/twitter.com\/MsftSecIntel\/status\/1308941504707063808<\/a><\/p>\n\n<p><strong>UPDATE: <\/strong>[5] 2030871 ET EXPLOIT Possible Zerologon NetrServerAuthenticate with 0x00 Client Credentials (CVE-2020-1472)<br \/><a href=\"https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules\">https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules<\/a><\/p>\n\n<p><strong>UPDATE: <\/strong>[6] Unauthenticated domain takeover via netlogon (\"ZeroLogon\"):<br \/><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2020-1472.html\">https:\/\/www.samba.org\/samba\/security\/CVE-2020-1472.html<\/a><br \/>\n\u00a0<br \/><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-netlogon-elevation-privilege-vulnerability-cve-2020-1472","alert_type":397,"serial_number":"AL20-022","subject":null,"moderation_state":"published","external_url":null},{"nid":2075,"title":"Citrix security advisory","uuid":"4750203a-e297-44ec-8367-4f464524060f","banner":null,"lang":"en","date_modified":"2020-09-17","date_modified_ts":"2020-09-17T17:08:06Z","date_created":"2020-09-17T17:08:06Z","summary":null,"body":["<article data-history-node-id=\"2075\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-340<br \/>\nDate: 17 September 2020<\/strong><\/p>\n\n<p>On 17 September 2020 Citrix released a Security Bulletin to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>\u00a0Citrix ADC and Citrix Gateway \u2013 releases prior to 13.0-64.35<\/li>\n\t<li>\u00a0Citrix ADC and NetScaler Gateway \u2013 releases prior to 12.1-58.15<\/li>\n\t<li>\u00a0Citrix ADC 12.1-FIPS \u2013 releases prior to 12.1-55.187<\/li>\n\t<li>\u00a0Citrix ADC and NetScaler Gateway \u2013 releases prior to 11.1-65.12<\/li>\n\t<li>\u00a0Citrix SD-WAN WANOP \u2013 releases prior to 11.2.1a<\/li>\n\t<li>\u00a0Citrix SD-WAN WANOP \u2013 releases prior to 11.1.2a<\/li>\n\t<li>\u00a0Citrix SD-WAN WANOP \u2013 releases prior to 11.0.3f<\/li>\n\t<li>\u00a0Citrix SD-WAN WANOP \u2013 releases prior to 10.2.7b<\/li>\n<\/ul><p>The exploitation of these vulnerabilities could result in HTML injection, denial-of-service and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX281474\">https:\/\/support.citrix.com\/article\/CTX281474<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-8","alert_type":396,"serial_number":"AV20-340","subject":null,"moderation_state":"published","external_url":null},{"nid":2076,"title":"Apple security advisory","uuid":"9a9a30c0-bc3f-4933-96d6-1cbcadcad56b","banner":null,"lang":"en","date_modified":"2020-09-17","date_modified_ts":"2020-09-17T17:12:58Z","date_created":"2020-09-17T17:12:58Z","summary":null,"body":["<article data-history-node-id=\"2076\" about=\"\/en\/alerts-advisories\/apple-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-341<br \/>\nDate: 17 September 2020<\/strong><\/p>\n\n<p>On 16 September 2020 Apple released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>\u00a0macOS Catalina and macOS Mojave<\/li>\n\t<li>\u00a0Apple TV 4K and Apple TV HD<\/li>\n\t<li>\u00a0Apple Watch Series 3 and later<\/li>\n\t<li>\u00a0iPhone 6s and later, iPod touch 7th generation, iPad Air 2 and later, and iPad mini 4 and later<\/li>\n<\/ul><p>The exploitation of these vulnerabilities could result in information disclosure, unauthorized file access, unexpected application termination, download of malicious content, cross site scripting and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Safari<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211845\">https:\/\/support.apple.com\/en-ca\/HT211845<\/a><\/p>\n\n<p>tvOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211843\">https:\/\/support.apple.com\/en-ca\/HT211843<\/a><\/p>\n\n<p>watchOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211844\">https:\/\/support.apple.com\/en-ca\/HT211844<\/a><\/p>\n\n<p>iOS and iPadOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211850\">https:\/\/support.apple.com\/en-ca\/HT211850<\/a><\/p>\n\n<p>Xcode<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211848\">https:\/\/support.apple.com\/en-ca\/HT211848<\/a><\/p>\n\n<p>Apple security updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-16","alert_type":396,"serial_number":"AV20-341","subject":null,"moderation_state":"published","external_url":null},{"nid":2077,"title":"[Control systems] ABB security advisory","uuid":"ba669f34-16e1-4de7-b973-8b59e6956803","banner":null,"lang":"en","date_modified":"2020-09-17","date_modified_ts":"2020-09-17T18:40:24Z","date_created":"2020-09-17T18:40:24Z","summary":null,"body":["<article data-history-node-id=\"2077\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-342<br \/>\nDate: 17 September 2020<\/strong><\/p>\n\n<p>On 17 September 2020 ABB released a Cyber Security Advisory to address Wibu-Systems AG CodeMeter vulnerabilities affecting Automation Builder - versions 2.3.0.835 and prior.<\/p>\n\n<p>For information on vulnerabilities in the Wibu-Systems AG CodeMeter please refer to the following Advisory:<\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-wibu-systems-ag-security-advisory\">https:\/\/www.cyber.gc.ca\/en\/alerts\/control-systems-wibu-systems-ag-security-advisory<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and perform the suggested mitigations:<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010586&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010586&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-9","alert_type":398,"serial_number":"AV20-342","subject":null,"moderation_state":"published","external_url":null},{"nid":2078,"title":"[Control systems] Advantech security advisory","uuid":"6a6f12d5-60e4-4ff4-b682-d22ad0588f2c","banner":null,"lang":"en","date_modified":"2020-09-18","date_modified_ts":"2020-09-18T13:10:45Z","date_created":"2020-09-18T13:10:45Z","summary":null,"body":["<article data-history-node-id=\"2078\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-343<br \/>\nDate: 18 September 2020<\/strong><\/p>\n\n<p>On 17 September 2020 ICS-CERT published an Advisory to highlight a vulnerability in Advantech WebAccess Node - versions prior to 9.0.1.<\/p>\n\n<p>Exploitation of this vulnerability could allow a malicious actor to execute code with system privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-261-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-261-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-9","alert_type":398,"serial_number":"AV20-343","subject":null,"moderation_state":"published","external_url":null},{"nid":2079,"title":"[Control systems] Philips security advisory","uuid":"816f6c4b-0781-445f-a0f9-c5c0361af2b3","banner":null,"lang":"en","date_modified":"2020-09-18","date_modified_ts":"2020-09-18T13:13:12Z","date_created":"2020-09-18T13:13:12Z","summary":null,"body":["<article data-history-node-id=\"2079\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-344<br \/>\nDate: 18 September 2020<\/strong><\/p>\n\n<p>On 17 September 2020 Philips published a Security Advisory to highlight vulnerabilities in Philips Clinical Collaboration Platform - versions 12.2.1 and prior.<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to information disclosure or allow a malicious actor to mislead a user into executing unauthorized actions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates:<br \/><a href=\"https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security\">https:\/\/www.usa.philips.com\/healthcare\/about\/customer-support\/product-security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-7","alert_type":398,"serial_number":"AV20-344","subject":null,"moderation_state":"published","external_url":null},{"nid":2080,"title":"Drupal security advisory","uuid":"e33f2351-58a7-49e3-aa7a-1a9f8ee86c00","banner":null,"lang":"en","date_modified":"2020-09-18","date_modified_ts":"2020-09-18T17:32:00Z","date_created":"2020-09-18T17:31:28Z","summary":null,"body":["<article data-history-node-id=\"2080\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-345<br \/>\nDate: 18 September 2020<\/strong><\/p>\n\n<p>On 16 September 2020 Drupal released Security Advisories to address vulnerabilities affecting the following versions of Drupal:<\/p>\n\n<ul><li>Drupal 7.x - versions prior to 7.73.<\/li>\n\t<li>Drupal 8.8.x - versions prior to 8.8.10.<\/li>\n\t<li>Drupal 8.9.x - versions prior to 8.9.6.<\/li>\n\t<li>Drupal 9.0.x - versions prior to 9.0.6.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.drupal.org\/security\">https:\/\/www.drupal.org\/security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-9","alert_type":396,"serial_number":"AV20-345","subject":null,"moderation_state":"published","external_url":null},{"nid":2081,"title":"IBM security advisory","uuid":"7c1a78c5-4961-4754-a863-5ce24b846395","banner":null,"lang":"en","date_modified":"2020-09-21","date_modified_ts":"2020-09-21T18:57:38Z","date_created":"2020-09-21T18:57:38Z","summary":null,"body":["<article data-history-node-id=\"2081\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-346<br \/>\nDate: 21 September 2020<\/strong><\/p>\n\n<p>Between 14 and 20 September 2020 IBM published Security Bulletins to address vulnerabilities in multiple products including critical patches for the following:<\/p>\n\n<ul><li>IBM Security Identity Manager Virtual Appliance \u2013 versions 7.0.1 and 7.0.2<\/li>\n\t<li>IBM Cloud Transformation Advisor \u2013 versions 2.1.1 and 2.2.0<\/li>\n\t<li>IBM eDiscovery Analyzer \u2013 version 2.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Security Identity Manager Virtual Appliance<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-have-been-fixed-in-ibm-security-identity-manager-virtual-appliance\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-have-been-fixed-in-ibm-security-identity-manager-virtual-appliance\/<\/a><\/p>\n\n<p>IBM Cloud Transformation Advisor<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-transformation-advisor-is-affected-by-multiple-node-js-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-transformation-advisor-is-affected-by-multiple-node-js-vulnerabilities\/<\/a><\/p>\n\n<p>IBM eDiscovery Analyzer<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-publicly-disclosed-vulnerability-found-by-vfinder-in-ibm-ediscovery-analyzer-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-publicly-disclosed-vulnerability-found-by-vfinder-in-ibm-ediscovery-analyzer-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-18","alert_type":396,"serial_number":"AV20-346","subject":null,"moderation_state":"published","external_url":null},{"nid":2082,"title":"Google Chrome security advisory","uuid":"d04eeb91-d091-4d72-a4d4-b358b590dfe2","banner":null,"lang":"en","date_modified":"2020-09-22","date_modified_ts":"2020-09-22T12:16:47Z","date_created":"2020-09-22T12:16:47Z","summary":null,"body":["<article data-history-node-id=\"2082\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-347<br \/>\nDate: 22 September 2020<\/strong><\/p>\n\n<p>On 21 September 2020 Google released a Security Update to address vulnerabilities in Chrome for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/09\/stable-channel-update-for-desktop_21.html\">https:\/\/chromereleases.googleblog.com\/2020\/09\/stable-channel-update-for-desktop_21.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-35","alert_type":396,"serial_number":"AV20-347","subject":null,"moderation_state":"published","external_url":null},{"nid":2083,"title":"MobileIron Critical Vulnerabilities \u2013 ACSC","uuid":"27f804b5-0582-4972-8465-d9d9d0364797","banner":null,"lang":"en","date_modified":"2020-09-22","date_modified_ts":"2020-09-22T15:36:12Z","date_created":"2020-09-22T14:01:40Z","summary":null,"body":["<article data-history-node-id=\"2083\" about=\"\/en\/alerts-advisories\/mobileiron-critical-vulnerabilities-acsc\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-023\n  <br \/>\n  Date: 22 September 2020<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>ASSESSMENT\n<\/h3>\n<p>On 18 September 2020 the Australian Cyber Security Centre (ACSC) issued an Alert highlighting the efforts of malicious cyber actors, including sophisticated state-based actors, to target critical vulnerabilities in several MobileIron products. These vulnerabilities, if exploited, could lead to remote code execution, authentication bypass and the reading of arbitrary files.\n<\/p>\n<p>The Cyber Centre would like to underline the importance of general security best practices, particularly that of maintaining software applications to the latest patch level.\n<\/p>\n<p>Should organizations identify activity similar to that described in this Alert, they are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>ACSC Alert:\n  <br \/><a href=\"https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/alerts\/active-exploitation-vulnerable-mobileiron-products\">https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/alerts\/active-exploitation-vulnerable-mobileiron-products<\/a>\n<\/p>\n<p>MobileIron Security Updates:\n  <br \/><a href=\"https:\/\/www.mobileiron.com\/en\/blog\/mobileiron-security-updates-available\">https:\/\/www.mobileiron.com\/en\/blog\/mobileiron-security-updates-available<\/a>\n<\/p>\n<p>\u00a0\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the  Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mobileiron-critical-vulnerabilities-acsc","alert_type":397,"serial_number":"AL20-023","subject":null,"moderation_state":"published","external_url":null},{"nid":2084,"title":"Mozilla security advisory","uuid":"4a0252b9-5f8f-4992-a8b4-a88516ca3f0c","banner":null,"lang":"en","date_modified":"2020-09-22","date_modified_ts":"2020-09-22T18:53:26Z","date_created":"2020-09-22T18:53:26Z","summary":null,"body":["<article data-history-node-id=\"2084\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-348<br \/>\nDate: 22 September 2020<\/strong><br \/><br \/>\nOn 22 September 2020 Mozilla released Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR \u2013 releases prior to 78.3<\/li>\n\t<li>Firefox \u2013 releases prior to 81<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Firefox ESR 78.3<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-43\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-43\/<\/a><\/p>\n\n<p>Firefox 81<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-42\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-42\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-20","alert_type":396,"serial_number":"AV20-348","subject":null,"moderation_state":"published","external_url":null},{"nid":2085,"title":"[Control systems] General Electric security advisory","uuid":"82f83acf-03ef-4328-8cb8-8a243d9dba3f","banner":null,"lang":"en","date_modified":"2020-09-23","date_modified_ts":"2020-09-23T19:01:11Z","date_created":"2020-09-23T19:01:11Z","summary":null,"body":["<article data-history-node-id=\"2085\" about=\"\/en\/alerts-advisories\/control-systems-general-electric-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-349<br \/>\nDate: 23 September 2020<\/strong><\/p>\n\n<p>On 22 September 2020 ICS-CERT released Security Advisories to highlight vulnerabilities in the following General Electric products:<\/p>\n\n<ul><li>Reason S20 managed ethernet switches - S2020 and S2024, firmware versions 07A06 and prior<\/li>\n\t<li>APM Classic - versions 84.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p>Reason S20 managed ethernet switches<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-266-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-266-02<\/a><\/p>\n\n<p>APM Classic<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-266-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-266-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-general-electric-security-advisory","alert_type":398,"serial_number":"AV20-349","subject":null,"moderation_state":"published","external_url":null},{"nid":2087,"title":"Ubuntu security advisory","uuid":"99c414f1-f88e-4516-a6fd-7fd44bb3db2d","banner":null,"lang":"en","date_modified":"2020-09-25","date_modified_ts":"2020-09-25T14:55:50Z","date_created":"2020-09-25T14:55:50Z","summary":null,"body":["<article data-history-node-id=\"2087\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-350<br \/>\nDate: 25 September 2020<\/strong><\/p>\n\n<p>On 23 September 2020 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>\u00a0Ubuntu 18.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 16.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The exploitation of these vulnerabilities could result in denial of service, disclosure of sensitive information and local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4526-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4526-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-2","alert_type":396,"serial_number":"AV20-350","subject":null,"moderation_state":"published","external_url":null},{"nid":2088,"title":"[Control systems] 3S-Smart Software Solutions","uuid":"405a4df5-9ea0-4295-9cc5-b24209a4b000","banner":null,"lang":"en","date_modified":"2020-09-25","date_modified_ts":"2020-09-25T15:00:22Z","date_created":"2020-09-25T15:00:22Z","summary":null,"body":["<article data-history-node-id=\"2088\" about=\"\/en\/alerts-advisories\/control-systems-3s-smart-software-solutions\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-351<br \/>\nDate: 25 September 2020<\/strong><\/p>\n\n<p>On 24 September 2020 ICS-CERT published an Advisory to highlight vulnerabilities in the following 3S-Smart Software Solutions CoDeSys products:<\/p>\n\n<ul><li>\u00a0CODESYS Control Runtime embedded - versions prior to 2.3.2.8<\/li>\n\t<li>\u00a0CODESYS Control Runtime full - versions prior to 2.4.7.40<\/li>\n\t<li>\u00a0CODESYS Control RTE - versions prior to 2.3.7.17<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a malicious actor to gain unauthorized access and obtain administrative privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/ICSA-13-011-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/ICSA-13-011-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-3s-smart-software-solutions","alert_type":398,"serial_number":"AV20-351","subject":null,"moderation_state":"published","external_url":null},{"nid":2089,"title":"Cisco security advisory","uuid":"9b1e80bb-95ec-4261-a794-89d4e0fd7dc0","banner":null,"lang":"en","date_modified":"2020-09-25","date_modified_ts":"2020-09-25T15:52:18Z","date_created":"2020-09-25T15:52:18Z","summary":null,"body":["<article data-history-node-id=\"2089\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-62\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-352<br \/>\nDate: 25 September 2020<\/strong><\/p>\n\n<p>On 24 September 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were high severity patches for the following:<\/p>\n\n<ul><li>\u00a0Cisco IOS Software<\/li>\n\t<li>\u00a0Cisco IOS XE Software<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p>Cisco Event Response Page<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/viewErp.x?alertId=ERP-74268\">https:\/\/tools.cisco.com\/security\/center\/viewErp.x?alertId=ERP-74268<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-62","alert_type":396,"serial_number":"AV20-352","subject":null,"moderation_state":"published","external_url":null},{"nid":2090,"title":"Fortinet security advisory","uuid":"f684d1b6-8e81-4639-94d0-cc45274313bd","banner":null,"lang":"en","date_modified":"2020-09-25","date_modified_ts":"2020-09-25T18:38:51Z","date_created":"2020-09-25T18:38:51Z","summary":null,"body":["<article data-history-node-id=\"2090\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-353<br \/>\nDate: 25 September 2020<\/strong><\/p>\n\n<p>On 24 September 2020 Fortinet released PSIRT Advisories to address vulnerabilities, including two vulnerabilities which were responsibility disclosed by the Communication Security Establishment (CSE), affecting the following products:<\/p>\n\n<ul><li>\u00a0FortiGate \u2013 versions 6.2.4 and below, version 6.4.0<\/li>\n\t<li>\u00a0FortiOS \u2013 various versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-5","alert_type":396,"serial_number":"AV20-353","subject":null,"moderation_state":"published","external_url":null},{"nid":2091,"title":"Mozilla security advisory","uuid":"72879062-635e-4051-ab6d-a5307e3af0e4","banner":null,"lang":"en","date_modified":"2020-09-25","date_modified_ts":"2020-09-25T19:19:21Z","date_created":"2020-09-25T19:19:21Z","summary":null,"body":["<article data-history-node-id=\"2091\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-354<br \/>\nDate: 25 September 2020<\/strong><\/p>\n\n<p>On 22 September 2020 Mozilla released Security Advisories to address vulnerabilities in Thunderbird version 78.2. Exploitation of these vulnerabilities may allow a malicious actor to run arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and update to the latest version.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-44\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-44\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-21","alert_type":396,"serial_number":"AV20-354","subject":null,"moderation_state":"published","external_url":null},{"nid":2092,"title":"Apple security advisory","uuid":"1d3b90b1-55b4-4c29-abfa-a98c01865beb","banner":null,"lang":"en","date_modified":"2020-09-28","date_modified_ts":"2020-09-28T12:13:12Z","date_created":"2020-09-28T12:13:12Z","summary":null,"body":["<article data-history-node-id=\"2092\" about=\"\/en\/alerts-advisories\/apple-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-355<br \/>\nDate: 25 September 2020<\/strong><\/p>\n\n<p>On 24 September 2020 Apple released security updates to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>\u00a0iCloud for Windows<\/li>\n\t<li>\u00a0macOS Catalina, macOS High Sierra and macOS Mojave<\/li>\n<\/ul><p>The exploitation of these vulnerabilities could result in information disclosure, unauthorized file access, unexpected application termination, cross site scripting and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>iCloud for Windows<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT211847\">https:\/\/support.apple.com\/en-us\/HT211847<\/a><\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT211846\">https:\/\/support.apple.com\/en-us\/HT211846<\/a><\/p>\n\n<p>macOS Catalina, macOS High Sierra and macOS Mojave<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT211849\">https:\/\/support.apple.com\/en-us\/HT211849<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-17","alert_type":396,"serial_number":"AV20-355","subject":null,"moderation_state":"published","external_url":null},{"nid":2093,"title":"IBM security advisory","uuid":"7364813b-d1b3-4951-a657-bfe0178fe09a","banner":null,"lang":"en","date_modified":"2020-09-28","date_modified_ts":"2020-09-28T17:45:30Z","date_created":"2020-09-28T17:45:30Z","summary":null,"body":["<article data-history-node-id=\"2093\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-356<br \/>\nDate: 28 September 2020<\/strong><\/p>\n\n<p>Between 21 and 27 September 2020 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Netezza Host Management \u2013 versions beginning 5.3.5.1<\/li>\n\t<li>IBM Tivoli Monitoring (ITM) portal server \u2013 version 6.3.0 Fix Pack 7 Service Pack 5<\/li>\n\t<li>IBM Tivoli Composite Application Manager for Transactions (Response Time) - versions 7.4.01 and 7.4.02<\/li>\n\t<li>IBM Cloud Application Performance Management \u2013 Response Time Monitoring Agent \u2013 version 8.1.4<\/li>\n\t<li>IBM Security Identity Manager Virtual Appliance (ISIM VA) - versions 7.0.1 and 7.0.2<\/li>\n\t<li>IBM Cloud Transformation Advisor - versions 2.1.1 and 2.2.0<\/li>\n\t<li>eDiscovery Analyzer \u2013 version 2.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-19","alert_type":396,"serial_number":"AV20-356","subject":null,"moderation_state":"published","external_url":null},{"nid":2094,"title":"[Control systems] Yokogawa security advisory","uuid":"a8bdbb2d-1bb4-4bef-8788-dc53f7760748","banner":null,"lang":"en","date_modified":"2020-09-30","date_modified_ts":"2020-09-30T12:18:30Z","date_created":"2020-09-30T12:12:24Z","summary":null,"body":["<article data-history-node-id=\"2094\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-357<br \/>\nDate:\u00a030 September 2020<\/strong><\/p>\n\n<p>On 25 September 2020 Yokogawa published a Security Advisory Report to address a vulnerability in WideField3 - versions R1.01 to R4.03.<\/p>\n\n<p>By loading malicious projects an actor could cause a buffer overflow and terminate the application abnormally.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer updates.<\/p>\n\n<p><a href=\"https:\/\/web-material3.yokogawa.com\/1\/30026\/files\/YSAR-20-0002-E.pdf\">https:\/\/web-material3.yokogawa.com\/1\/30026\/files\/YSAR-20-0002-E.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-1","alert_type":398,"serial_number":"AV20-357","subject":null,"moderation_state":"published","external_url":null},{"nid":2095,"title":"[Control systems] MB connect line security advisory","uuid":"1a28c7fd-5a50-4327-891d-b419aac02db6","banner":null,"lang":"en","date_modified":"2020-09-30","date_modified_ts":"2020-09-30T13:11:50Z","date_created":"2020-09-30T13:11:50Z","summary":null,"body":["<article data-history-node-id=\"2095\" about=\"\/en\/alerts-advisories\/control-systems-mb-connect-line-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-358<br \/>\nDate: 30 September 2020<\/strong><\/p>\n\n<p>On 18 September 2020 MB connect line published a Security Incident Management document to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>\u00a0mbCONNECT24 \u2013 verson 2.6.1 and prior<\/li>\n\t<li>\u00a0mymbCONNECT24 \u2013 verson 2.6.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p>mbCONNECT24 and mymbCONNECT24<\/p>\n\n<p><a href=\"https:\/\/www.mbconnectline.com\/fileadmin\/SIM_2020-04-1.pdf\">https:\/\/www.mbconnectline.com\/fileadmin\/SIM_2020-04-1.pdf<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mb-connect-line-security-advisory","alert_type":398,"serial_number":"AV20-358","subject":null,"moderation_state":"published","external_url":null},{"nid":2096,"title":"[Control systems] B&R Automation security advisory","uuid":"e82fd01c-3ce2-43c8-b027-e1abb02b5047","banner":null,"lang":"en","date_modified":"2020-09-30","date_modified_ts":"2020-09-30T20:02:05Z","date_created":"2020-09-30T20:00:02Z","summary":null,"body":["<article data-history-node-id=\"2096\" about=\"\/en\/alerts-advisories\/control-systems-br-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-359<br \/>\nDate: 30 September 2020<\/strong><\/p>\n\n<p>On 29 September B&amp;R Automation published Cyber Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SiteManager - versions prior to 9.2.620236042<\/li>\n\t<li>GateManager 4260 and 9250 - versions prior to 9.0.20276<\/li>\n\t<li>GateManager 8250 - versions prior to 9.2.620276048<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a remote actor to achieve remote code execution, remote command execution, user data disclosure or denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>SiteManager and GateManager<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1600003183751-de-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1600003183751-de-original-1.0.pdf<\/a><\/p>\n\n<p>GateManager<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1600003183756-de-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1600003183756-de-original-1.0.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-automation-security-advisory","alert_type":398,"serial_number":"AV20-359","subject":null,"moderation_state":"published","external_url":null},{"nid":2097,"title":"IBM security advisory","uuid":"ddd52a2d-1cc3-4406-826e-3fefc767b07c","banner":null,"lang":"en","date_modified":"2020-10-05","date_modified_ts":"2020-10-05T20:06:07Z","date_created":"2020-10-05T20:05:43Z","summary":null,"body":["<article data-history-node-id=\"2097\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-360<br \/>\nDate: 5 October 2020<\/strong><br \/><br \/>\nBetween 28 September 2020 and 4 October 2020 IBM published Security Bulletins to address vulnerabilities in multiple products including critical patches for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container \u2013 versions 1.0.0 to 1.0.2 with Operator<\/li>\n\t<li>IBM Maximo Asset Management \u2013 versions 7.6.0 and 7.6.1. Older versions of Maximo Asset Management may also be impacted.<\/li>\n\t<li>IBM Resilient SOAR<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>IBM App Connect Enterprise Certified Container<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-app-connect-enterprise-certified-container-is-affected-by-multiple-node-js-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-app-connect-enterprise-certified-container-is-affected-by-multiple-node-js-vulnerabilities\/<\/a><\/p>\n\n<p>IBM Maximo Asset Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-authentication-bypass-cve-2020-4493\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-authentication-bypass-cve-2020-4493\/<\/a><\/p>\n\n<p>IBM Resilient SOAR<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletinibm-resilient-soar-is-using-components-with-known-vulnerabilities-apache-camel-cve-2019-0188-cve-2020-11972-cve-2020-11973\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletinibm-resilient-soar-is-using-components-with-known-vulnerabilities-apache-camel-cve-2019-0188-cve-2020-11972-cve-2020-11973\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-resilient-soar-is-using-components-with-known-vulnerabilities-plexus-utils-cve-2017-1000487\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-resilient-soar-is-using-components-with-known-vulnerabilities-plexus-utils-cve-2017-1000487\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-20","alert_type":396,"serial_number":"AV20-360","subject":null,"moderation_state":"published","external_url":null},{"nid":2098,"title":"Android security advisory","uuid":"17841164-2f67-49eb-b5f7-e0682b1ea7c4","banner":null,"lang":"en","date_modified":"2020-10-05","date_modified_ts":"2020-10-05T20:10:56Z","date_created":"2020-10-05T20:10:23Z","summary":null,"body":["<article data-history-node-id=\"2098\" about=\"\/en\/alerts-advisories\/android-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-361<br \/>\nDate: 5 October 2020<\/strong><\/p>\n\n<p>On 5 October 2020 Android released Security Updates to address vulnerabilities in Android devices.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-10-01\">https:\/\/source.android.com\/security\/bulletin\/2020-10-01<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-16","alert_type":396,"serial_number":"AV20-361","subject":null,"moderation_state":"published","external_url":null},{"nid":2099,"title":"Google Chrome security advisory","uuid":"c79969e5-ceac-477c-b0b5-c22b13899e9b","banner":null,"lang":"en","date_modified":"2020-10-07","date_modified_ts":"2020-10-07T19:12:10Z","date_created":"2020-10-07T19:12:10Z","summary":null,"body":["<article data-history-node-id=\"2099\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-362<br \/>\nDate: 7 October 2020<\/strong><\/p>\n\n<p>On 6 October 2020 Google released a Security Update to address vulnerabilities in Chrome for Windows, Mac, and Linux.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/10\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/10\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-36","alert_type":396,"serial_number":"AV20-362","subject":null,"moderation_state":"published","external_url":null},{"nid":2100,"title":"Cisco security advisory","uuid":"39c1f890-82c3-4834-b9b7-f3e8af04c4a5","banner":null,"lang":"en","date_modified":"2020-10-07","date_modified_ts":"2020-10-07T19:15:05Z","date_created":"2020-10-07T19:15:05Z","summary":null,"body":["<article data-history-node-id=\"2100\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-63\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-363<br \/>\nDate: 7 October 2020<\/strong><\/p>\n\n<p>On 7 October 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were high severity patches for the following:<\/p>\n\n<ul><li>Cisco Webex Teams for Windows \u2013 versions 3.0.13464.0 to 3.0.16040.0<\/li>\n\t<li>Cisco Identity Services Engine \u2013 versions 2.3 to 2.7<\/li>\n\t<li>Cisco Video Surveillance 8000 Series IP Cameras \u2013 firmware prior to 1.0.9-5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Cisco Webex Teams for Windows<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-webex-teams-dll-drsnH5AN\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-webex-teams-dll-drsnH5AN<\/a><\/p>\n\n<p>Cisco Identity Services Engine<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-auth-bypass-uJWqLTZM\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-auth-bypass-uJWqLTZM<\/a><\/p>\n\n<p>Cisco Video Surveillance 8000 Series IP Cameras<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cdp-rcedos-mAHR8vNx\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cdp-rcedos-mAHR8vNx<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-63","alert_type":396,"serial_number":"AV20-363","subject":null,"moderation_state":"published","external_url":null},{"nid":2101,"title":"Renewed Emotet Activity","uuid":"cc64657a-506e-4ed3-a131-1db3343738dd","banner":null,"lang":"en","date_modified":"2020-10-08","date_modified_ts":"2020-10-08T14:31:40Z","date_created":"2020-10-08T14:31:40Z","summary":null,"body":["<article data-history-node-id=\"2101\" about=\"\/en\/alerts-advisories\/renewed-emotet-activity\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-024<br \/>\nDate: 8 October 2020<\/strong><\/p>\n\n<h3>AUDIENCE<\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h3>PURPOSE<\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3>OVERVIEW<\/h3>\n\n<p>Since July 2020 the Cyber Centre has been aware of an increase in malicious activity associated with Emotet malware campaigns. Emotet has been frequently observed working in tandem with Trickbot and Ryuk malware in a persistent attempt to compromise computer systems within Canada.<\/p>\n\n<h3>DETAILS<\/h3>\n\n<p>Throughout 2019 and 2020, the Cyber Centre has received reports in which hundreds of Canadian victims across a wide range of government and commercial sectors, police services, and education providers have been compromised by Emotet. In addition, both the Cybersecurity and Infrastructure Security Agency (CISA) [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-280a\">1<\/a>] and the Australian Cyber Security Centre (ACSC) [<a href=\"https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/advisories\/advisory-2020-017-resumption-emotet-malware-campaign\"><font color=\"#0066cc\">2<\/font><\/a>] have issued publications on Emotet malware, both noting similar observations and a recent increase in activity.<br \/>\n\u00a0<br \/>\nEmotet is an advanced botnet that has infected hundreds of thousands of systems worldwide. Once a system is infected by Emotet, additional malware, including Trickbot and Ryuk [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/ryuk-ransomware-campaign\">3<\/a>][<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-spam-campaigns-leveraging-emotet-malware\">4<\/a>] may be implanted on the system resulting in data exfiltration or attempts to extort the victim. Emotet malware can be spread through untargeted bulk spam emails (such as shipping notifications, or \u201cpast-due\u201d invoices), as well as what appear to be targeted malicious emails (spear phishing).<\/p>\n\n<p>Targeted emails are particularly effective as they appear to come from a trusted source, often from someone with whom the email recipient has recently been in communication. Furthermore, CCCS has received reports in which Emotet email campaigns have been observed to be leveraging both \u2018thread hijacking\u2019, a technique where malicious emails are inserted into existing email threads, and using password-protected zip files to avoid detection by network defenses [<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-double-blunder-fake-windows-10-mobile-and-outdated-messages\/\">5<\/a>]. These techniques result in convincing messages that an unaware recipient may believe to be trustworthy and encouraged to download malware by opening an attachment (a macro-enabled Microsoft Word document or PDF) or clicking a malicious link.<\/p>\n\n<h3>SUGGESTED ACTION<\/h3>\n\n<p>The Cyber Centre recommends that organizations and individuals:<\/p>\n\n<ul><li>Follow the Cyber Centre\u2019s guidance to stay cybef safe (<a href=\"https:\/\/www.getcybersafe.gc.ca\">https:\/\/www.getcybersafe.gc.ca<\/a>).<\/li>\n\t<li>Scan all incoming and outgoing e-mails to detect threats and prevent executable files or macro enabled documents from reaching end users.<\/li>\n\t<li>Always exercise caution when receiving an unexpected email or email reply containing an attachment or URL, even when from a trusted source. If the email seems unusual, contact the sender to confirm the authenticity of the attachment.<\/li>\n\t<li>Avoid enabling macros within a document received via email.<\/li>\n\t<li>Use anti-virus protection and ensure that it is diligently kept up to date.<\/li>\n\t<li>Implement architectural controls for network segregation and protection.<\/li>\n\t<li>Perform daily backups of all critical systems, maintain offline and offsite copies of backup media and periodically test data restoration processes from backups, including key databases to ensure integrity of existing backups and processes.<\/li>\n\t<li>Ensure operating systems receive the latest patches.<\/li>\n\t<li>Further advice and guidance is available within partner publications CISA Alert AA20-280A [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-280a\"><font color=\"#0066cc\">1<\/font><\/a>] and ACSC Advisory 2020-017 [<a href=\"https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/advisories\/advisory-2020-017-resumption-emotet-malware-campaign\">2<\/a>].<\/li>\n<\/ul><p>Should organizations identify associated activity to that described in the referenced Advisory, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n\n<h3>REFERENCES<\/h3>\n\n<p>[1] CISA Alert AA20-280A Emotet Malware:<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-280a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-280a<\/a><\/p>\n\n<p>[2] ACSC Advisory 2020-017 Resumption of Emotet malware campaign:<br \/><a href=\"https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/advisories\/advisory-2020-017-resumption-emotet-malware-campaign\">https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/advisories\/advisory-2020-017-resumption-emotet-malware-campaign<\/a><\/p>\n\n<p>[3] Cyber Centre Alert AL19-202:<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/ryuk-ransomware-campaign\">https:\/\/cyber.gc.ca\/en\/alerts\/ryuk-ransomware-campaign<\/a><\/p>\n\n<p>[4] Active Spam Campaigns Leveraging EMOTET Malware<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-spam-campaigns-leveraging-emotet-malware\">https:\/\/cyber.gc.ca\/en\/alerts\/active-spam-campaigns-leveraging-emotet-malware<\/a><\/p>\n\n<p>[5] Bleepingcomputer Emotet double blunder: fake \u2018Windows 10 Mobile\u2019 and outdated messages<br \/><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-double-blunder-fake-windows-10-mobile-and-outdated-messages\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-double-blunder-fake-windows-10-mobile-and-outdated-messages\/<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/renewed-emotet-activity","alert_type":397,"serial_number":"AL20-024","subject":null,"moderation_state":"published","external_url":null},{"nid":2102,"title":"[Control systems] Johnson Controls security advisory","uuid":"48977718-4ac0-4f96-9c24-ef9baeb27426","banner":null,"lang":"en","date_modified":"2020-10-13","date_modified_ts":"2020-10-13T12:19:51Z","date_created":"2020-10-13T12:19:51Z","summary":null,"body":["<article data-history-node-id=\"2102\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-364<br \/>\nDate: 13 October 2020<\/strong><\/p>\n\n<p>On 8 October 2020 Johnson Controls published a Security Advisory to highlight a vulnerability in their victor Web Client- versions v5.4.1 and prior.<\/p>\n\n<p>Successful exploitation of this vulnerability could allow a remote unauthenticated actor to delete arbitrary files on the system or render the system unusable by conducting a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates:<\/p>\n\n<p><a href=\"https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020-09-v1-victor-web-client.pdf?la=en&amp;hash=9FA57217EF5D2F3BA62A5749D24855D9819C7CBC\">https:\/\/www.johnsoncontrols.com\/-\/media\/jci\/cyber-solutions\/product-security-advisories\/2020\/jci-psa-2020-09-v1-victor-web-client.pdf?la=en&amp;hash=9FA57217EF5D2F3BA62A5749D24855D9819C7CBC<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-2","alert_type":398,"serial_number":"AV20-364","subject":null,"moderation_state":"published","external_url":null},{"nid":2103,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"9c0c70fc-ff81-434e-a4ab-93e1bf1c6ca3","banner":null,"lang":"en","date_modified":"2020-10-13","date_modified_ts":"2020-10-13T12:28:57Z","date_created":"2020-10-13T12:28:57Z","summary":null,"body":["<article data-history-node-id=\"2103\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-365<br \/>\nDate: 13 October 2020<\/strong><\/p>\n\n<p>On 8 October 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in Mitsubishi Electric MELSEC iQ-R Series modules. The following modules are affected:<\/p>\n\n<ul><li>R00\/01\/02CPU - all versions<\/li>\n\t<li>R04\/08\/16\/32\/120(EN)CPU - all versions<\/li>\n\t<li>R08\/16\/32\/120SFCPU - all versions<\/li>\n\t<li>R08\/16\/32\/120PCPU - all versions<\/li>\n\t<li>R16\/32\/64MTCPU - all versions<\/li>\n<\/ul><p>Successful exploitation of this vulnerability could allow a remote actor to cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available:<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-282-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-282-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-8","alert_type":398,"serial_number":"AV20-365","subject":null,"moderation_state":"published","external_url":null},{"nid":2104,"title":"IBM security advisory","uuid":"cfc9ec77-63bb-4f2e-9950-9be9aef7e4fb","banner":null,"lang":"en","date_modified":"2020-10-13","date_modified_ts":"2020-10-13T17:59:23Z","date_created":"2020-10-13T17:59:23Z","summary":null,"body":["<article data-history-node-id=\"2104\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-366<br \/>\nDate: 13 October 2020<\/strong><\/p>\n\n<p>Between 5 and 12 October 2020 IBM published Security Bulletins to address vulnerabilities in multiple products including critical patches for the following:<\/p>\n\n<ul><li>IBM Maximo Asset Management \u2013 versions 7.6.0 and 7.6.1. Older versions may also be impacted.<\/li>\n\t<li>IBM Cloud Pak System \u2013 versions v2.3.0.1 and v2.3.1.1<\/li>\n\t<li>IBM Cloud Pak for Data \u2013 versions 2.5 and 3.0.1<\/li>\n\t<li>IBM Security Guardium \u2013 version 10.6<\/li>\n\t<li>IBM Netezza Host Management \u2013 versions 5.4.9.0 to 5.4.28.0<\/li>\n\t<li>IBM Business Automation Workflow \u2013 versions v20.0, v19.0 and v18.0<\/li>\n\t<li>IBM Business Process Manager \u2013 versions v8.6 and v8.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-21","alert_type":396,"serial_number":"AV20-366","subject":null,"moderation_state":"published","external_url":null},{"nid":2105,"title":"SAP security advisory","uuid":"5a6c93e2-14e4-4927-b868-e4ebb67009f5","banner":null,"lang":"en","date_modified":"2020-10-13","date_modified_ts":"2020-10-13T18:02:06Z","date_created":"2020-10-13T18:02:06Z","summary":null,"body":["<article data-history-node-id=\"2105\" about=\"\/en\/alerts-advisories\/sap-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-367<br \/>\nDate: 13 October 2020<\/strong><\/p>\n\n<p>On 13 October 2020 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>SAP Solution Manager (CA Introscope Enterprise Manager) and SAP Focused Run (CA Introscope Enterprise Manager) - versions 9.7, 10.1, 10.5, 10.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>SAP Product Security Response<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=558632196\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=558632196<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-9","alert_type":396,"serial_number":"AV20-367","subject":null,"moderation_state":"published","external_url":null},{"nid":2106,"title":"[Control systems] Siemens security advisory","uuid":"2a3d579b-599c-4456-92d4-0128e0fa9ab9","banner":null,"lang":"en","date_modified":"2020-10-13","date_modified_ts":"2020-10-13T18:14:14Z","date_created":"2020-10-13T18:14:14Z","summary":null,"body":["<article data-history-node-id=\"2106\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-368<br \/>\nDate: 13 October 2020<\/strong><\/p>\n\n<p>On 13 October 2020 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were high severity patches for the following:<\/p>\n\n<ul><li>SIPORT MP - versions prior to 3.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the recommended mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-14","alert_type":398,"serial_number":"AV20-368","subject":null,"moderation_state":"published","external_url":null},{"nid":2107,"title":"Microsoft security advisory \u2013 October 2020 monthly rollup","uuid":"5cea31e6-df34-470f-9a65-990a81c44b65","banner":null,"lang":"en","date_modified":"2020-10-14","date_modified_ts":"2020-10-14T12:38:24Z","date_created":"2020-10-14T12:38:24Z","summary":null,"body":["<article data-history-node-id=\"2107\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-369<br \/>\nDate: 14 October 2020<\/strong><\/p>\n\n<p>On 13 October 2020 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>Adobe Flash Player<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Outlook 2016<\/li>\n\t<li>Microsoft SharePoint - multiple versions<\/li>\n\t<li>Microsoft Windows Workstation and Server - multiple versions<\/li>\n<\/ul><p>Of note is a remote code execution vulnerability, tracked as CVE-2020-16898 which exists when the Windows TCP\/IP stack improperly handles ICMPv6 Router Advertisement packets. An actor who successfully exploits this vulnerability could gain the ability to execute code on the target server or client. Microsoft has published updates which address the vulnerability by correcting how the Windows TCP\/IP stack handles ICMPv6 Router Advertisement packets.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates as soon as possible.<\/p>\n\n<p>CVE-2020-16898 | Windows TCP\/IP Remote Code Execution Vulnerability<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-16898\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-16898<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>October 2020 Release Notes<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Oct\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/2020-Oct<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-october-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-369","subject":null,"moderation_state":"published","external_url":null},{"nid":2108,"title":"Foxit security advisory","uuid":"3773c136-9f0a-44cc-8477-117f9c2f6fa9","banner":null,"lang":"en","date_modified":"2020-10-14","date_modified_ts":"2020-10-14T12:51:04Z","date_created":"2020-10-14T12:51:04Z","summary":null,"body":["<article data-history-node-id=\"2108\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-370<br \/>\nDate: 14 October 2020<\/strong><\/p>\n\n<p>On 28 September and 9 October 2020 Foxit published Security Bulletins to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit Reader \u2013 versions 10.0.1.35811 and prior<\/li>\n\t<li>Foxit PhantomPDF \u2013 versions 10.0.1.35811 and prior<\/li>\n\t<li>Foxit Reader Mac - versions 4.0.0.0430 and prior<\/li>\n\t<li>Foxit PhantomPDF Mac \u2013 versions 4.0.0.0430 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Foxit Security Bulletins<br \/><a href=\"https:\/\/www.foxitsoftware.com\/support\/security-bulletins.html\">https:\/\/www.foxitsoftware.com\/support\/security-bulletins.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-2","alert_type":396,"serial_number":"AV20-370","subject":null,"moderation_state":"published","external_url":null},{"nid":2109,"title":"Adobe security advisory","uuid":"9ae5fa17-fbc6-404e-91c3-fc5f67541e5a","banner":null,"lang":"en","date_modified":"2020-10-14","date_modified_ts":"2020-10-14T13:00:03Z","date_created":"2020-10-14T13:00:03Z","summary":null,"body":["<article data-history-node-id=\"2109\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-371<br \/>\nDate: 14 October 2020<\/strong><\/p>\n\n<p>On 13 October 2020 Adobe published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Adobe Flash Player \u2013 versions prior to 32.0.0.445<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Flash Player<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb20-58.html\">https:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb20-58.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-28","alert_type":396,"serial_number":"AV20-371","subject":null,"moderation_state":"published","external_url":null},{"nid":2110,"title":"[Control systems] Moxa security advisory","uuid":"55181499-407d-48f7-8e16-dba97265c0f2","banner":null,"lang":"en","date_modified":"2020-10-14","date_modified_ts":"2020-10-14T13:10:19Z","date_created":"2020-10-14T13:10:19Z","summary":null,"body":["<article data-history-node-id=\"2110\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-372<br \/>\nDate: 14 October 2020<\/strong><\/p>\n\n<p>On 8 October 2020 Moxa published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Moxa NPort IAW5000A-I\/O Series Serial Device Servers \u2013 versions 2.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Moxa Security Advisory<br \/><a href=\"https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/nport-iaw5000a-io-serial-device-servers-vulnerabilities\">https:\/\/www.moxa.com\/en\/support\/support\/security-advisory\/nport-iaw5000a-io-serial-device-servers-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-2","alert_type":398,"serial_number":"AV20-372","subject":null,"moderation_state":"published","external_url":null},{"nid":2111,"title":"[Control systems] FieldComm security advisory","uuid":"63c49538-c42c-4666-ba19-734f9b6e82ba","banner":null,"lang":"en","date_modified":"2020-10-14","date_modified_ts":"2020-10-14T13:14:14Z","date_created":"2020-10-14T13:14:14Z","summary":null,"body":["<article data-history-node-id=\"2111\" about=\"\/en\/alerts-advisories\/control-systems-fieldcomm-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-373<br \/>\nDate: 14 October 2020<\/strong><\/p>\n\n<p>On 6 October 2020 FieldComm published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>HART-IP Developer kit \u2013 version 1.0.0.0<\/li>\n\t<li>hipserver \u2013 versions prior to v3.7.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>FieldComm Security Advisory<br \/><a href=\"https:\/\/support.fieldcommgroup.org\/en\/support\/solutions\/articles\/8000088791-2020-10-06-vulnerability-in-hipserver-cve-2020-162090\">https:\/\/support.fieldcommgroup.org\/en\/support\/solutions\/articles\/8000088791-2020-10-06-vulnerability-in-hipserver-cve-2020-162090<\/a>-\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fieldcomm-security-advisory","alert_type":398,"serial_number":"AV20-373","subject":null,"moderation_state":"published","external_url":null},{"nid":2112,"title":"[Control systems] LCDS security advisory","uuid":"fe5aa487-713a-424f-9a26-41e0f2d544a4","banner":null,"lang":"en","date_modified":"2020-10-14","date_modified_ts":"2020-10-14T13:30:07Z","date_created":"2020-10-14T13:30:07Z","summary":null,"body":["<article data-history-node-id=\"2112\" about=\"\/en\/alerts-advisories\/control-systems-lcds-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-374<br \/>\nDate: 14 October 2020<\/strong><\/p>\n\n<p>On 13 October 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>LCDS LAquis SCADA - versions prior to 4.3.1.870.<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a malicious actor to execute code under the privileges of the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates:<\/p>\n\n<p>ICSA-20-287-02<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-287-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-287-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-lcds-security-advisory-0","alert_type":398,"serial_number":"AV20-374","subject":null,"moderation_state":"published","external_url":null},{"nid":2113,"title":"[Control systems] Schneider Electric security advisory","uuid":"f6554163-774e-405b-8659-96e8a412b636","banner":null,"lang":"en","date_modified":"2020-10-14","date_modified_ts":"2020-10-14T13:35:58Z","date_created":"2020-10-14T13:35:58Z","summary":null,"body":["<article data-history-node-id=\"2113\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-375<br \/>\nDate: 14 October 2020<\/strong><\/p>\n\n<p>On 13 October 2020 Schneider Electric published Security Notifications to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BMX P34x prior to firmware - version 3.20<\/li>\n\t<li>M340 Communication Ethernet modules \u2013 multiple versions and platforms<\/li>\n\t<li>Premium processors with integrated Ethernet COPRO \u2013 multiple versions and platforms<\/li>\n\t<li>Premium communication modules \u2013 multiple versions and platforms<\/li>\n\t<li>Quantum processors with integrated Ethernet COPRO \u2013 multiple versions and platforms<\/li>\n\t<li>Quantum communication modules \u2013 multiple versions and platforms<\/li>\n\t<li>Acti9 Smartlink \u2013 multiple versions and platforms<\/li>\n\t<li>Acti9 PowerTag Link \/ Link HD \u2013 versions prior to 001.008.0<\/li>\n\t<li>Wiser Link \u2013 versions prior to 1.5.0<\/li>\n\t<li>Wiser Energy \u2013 versions prior to 1.5.0<\/li>\n\t<li>EcoStruxure Power Monitoring Expert \u2013 versions 9.0, 8.x, 7.x<\/li>\n\t<li>EcoStruxure Energy Expert \u2013 version 2.0<\/li>\n\t<li>Power Manager \u2013 versions 1.1, 1.2, 1.3<\/li>\n\t<li>StruxureWare PowerSCADA Expert with Advanced Reporting and Dashboards Module \u2013 versions 8.x<\/li>\n\t<li>EcoStruxure Power SCADA Operation with Advanced Reporting and Dashboards Module \u2013 version 9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-10","alert_type":398,"serial_number":"AV20-375","subject":null,"moderation_state":"published","external_url":null},{"nid":2114,"title":"Citrix security advisory","uuid":"b7c8dde2-f5d8-4940-8e75-d8b36dede431","banner":null,"lang":"en","date_modified":"2020-10-15","date_modified_ts":"2020-10-15T14:57:03Z","date_created":"2020-10-15T14:57:03Z","summary":null,"body":["<article data-history-node-id=\"2114\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-376<br \/>\nDate: 15 October 2020<\/strong><\/p>\n\n<p>On 13 October 2020 Citrix published a Security Bulletin to address multiple vulnerabilities in:<\/p>\n\n<ul><li>Citrix ADC and Citrix Gateway 13.0 - versions prior to 64.35<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 12.1 \u2013 versions prior to 59.16<\/li>\n\t<li>Citrix ADC 12.1-FIPS \u2013 versions prior to 55.190<\/li>\n<\/ul><p>The exploitation of these vulnerabilities could result in a local user escalating their privilege level to SYSTEM.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX282684)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX282684\">https:\/\/support.citrix.com\/article\/CTX282684<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-9","alert_type":396,"serial_number":"AV20-376","subject":null,"moderation_state":"published","external_url":null},{"nid":2115,"title":"Juniper Networks security advisory","uuid":"caffe8dc-9e27-45a3-ade8-0e4b9502b1b0","banner":null,"lang":"en","date_modified":"2020-10-15","date_modified_ts":"2020-10-15T17:41:53Z","date_created":"2020-10-15T17:41:53Z","summary":null,"body":["<article data-history-node-id=\"2115\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-377<br \/>\nDate: 15 October 2020<\/strong><\/p>\n\n<p>On 14 October 2020 Juniper Networks published Security Bulletins to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Juniper Networks Security Advisories<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-7","alert_type":396,"serial_number":"AV20-377","subject":null,"moderation_state":"published","external_url":null},{"nid":2116,"title":"Sonicwall security advisory","uuid":"f5242030-2ddf-431b-a3ad-38707151cf50","banner":null,"lang":"en","date_modified":"2020-10-16","date_modified_ts":"2020-10-16T16:58:31Z","date_created":"2020-10-16T16:58:31Z","summary":null,"body":["<article data-history-node-id=\"2116\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-378<br \/>\nDate: 16 October 2020<\/strong><\/p>\n\n<p>On 12 October 2020 Sonicwall published Security Advisories to address vulnerabilities in multiple products. Included were critical severity updates for the following:<\/p>\n\n<ul><li>SonicOS \u2013 versions 6.5.4.7-79n and prior<\/li>\n\t<li>SonicOS \u2013 versions 6.5.1.11-4n and prior<\/li>\n\t<li>SonicOS \u2013 versions 6.0.5.3-93o and prior<\/li>\n\t<li>SonicOS \u2013 version 7.0.0.0-1<\/li>\n\t<li>SonicOSv \u2013 versions 6.5.4.4-44v-21-794 and prior<\/li>\n<\/ul><p>Exploitation of the vulnerability may allow a remote actor to cause a denial-of-service and potentially execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Sonicwall Security Advisory (SNWLID-2020-0010)<br \/><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2020-0010\">https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2020-0010<\/a>\u00a0<\/p>\n\n<p>Sonicwall Security Advisories<br \/><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">https:\/\/psirt.global.sonicwall.com\/vuln-list<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory","alert_type":396,"serial_number":"AV20-378","subject":null,"moderation_state":"published","external_url":null},{"nid":2117,"title":"Adobe security advisory","uuid":"397f05fe-88ba-4ef3-a996-c0d2578349a3","banner":null,"lang":"en","date_modified":"2020-10-16","date_modified_ts":"2020-10-16T17:00:22Z","date_created":"2020-10-16T17:00:22Z","summary":null,"body":["<article data-history-node-id=\"2117\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-379<br \/>\nDate: 16 October 2020<\/strong><\/p>\n\n<p>On 15 October 2020 Adobe published a Security Bulletin to address vulnerabilities in the following:<\/p>\n\n<ul><li>Magento Commerce \u2013 version 2.3.5-p1 and prior<\/li>\n\t<li>Magento Commerce \u2013 version 2.4.0 and prior<\/li>\n\t<li>Magento Open Source \u2013 version 2.3.5-p1 and prior<\/li>\n\t<li>Magento Open Source \u2013 version 2.4.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Advisory (APSB20-59)<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb20-59.html\">https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb20-59.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-29","alert_type":396,"serial_number":"AV20-379","subject":null,"moderation_state":"published","external_url":null},{"nid":2118,"title":"[Control systems] Advantech security advisory","uuid":"908c8953-8a72-459f-925b-64b716f09387","banner":null,"lang":"en","date_modified":"2020-10-19","date_modified_ts":"2020-10-19T12:40:16Z","date_created":"2020-10-19T12:40:16Z","summary":null,"body":["<article data-history-node-id=\"2118\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-380<br \/>\nDate: 19 October 2020<\/strong><\/p>\n\n<p>On 15 October 2020 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Advantech WebAccess\/SCADA \u2013 version 9.0 and prior<\/li>\n\t<li>Advantech R-SeeNet - versions 1.5.1 to 2.4.10<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution under the privileges of an administrator or access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates:<\/p>\n\n<p>ICSA-20-289-01<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-289-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-289-01<\/a><\/p>\n\n<p>ICSA-20-289-02<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-289-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-289-02<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-10","alert_type":398,"serial_number":"AV20-380","subject":null,"moderation_state":"published","external_url":null},{"nid":2119,"title":"Microsoft security advisory","uuid":"611a0c8f-4d2d-4ee1-bc86-5fcb4b57778b","banner":null,"lang":"en","date_modified":"2020-10-19","date_modified_ts":"2020-10-19T16:55:33Z","date_created":"2020-10-19T16:55:33Z","summary":null,"body":["<article data-history-node-id=\"2119\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-382<br \/>\nDate: 19 October 2020<\/strong><\/p>\n\n<p>On 15 October 2020 Microsoft published Security Updates to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Windows 10<\/li>\n\t<li>Visual Studio Code<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Visual Studio Code<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-17023\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2020-17023<\/a><\/p>\n\n<p>Windows 10<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-17022\">https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-17022<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-8","alert_type":396,"serial_number":"AV20-382","subject":null,"moderation_state":"published","external_url":null},{"nid":2120,"title":"IBM security advisory","uuid":"40902915-8836-442b-8d47-8127b7081002","banner":null,"lang":"en","date_modified":"2020-10-19","date_modified_ts":"2020-10-19T16:56:15Z","date_created":"2020-10-19T16:56:15Z","summary":null,"body":["<article data-history-node-id=\"2120\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-381<br \/>\nDate: 19 October 2020<\/strong><\/p>\n\n<p>Between 13 and 18 October 2020 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>\u00a0IBM Maximo Asset Management - versions 7.6.0 and 7.6.1<\/li>\n\t<li>\u00a0IBM Operations Analytics Predictive Insights - all versions<\/li>\n\t<li>\u00a0IBM Network Performance Insight - version 1.3.1<\/li>\n\t<li>\u00a0IBM Security Guardium - version 11.2<\/li>\n\t<li>\u00a0IBM Business Automation Workflow - versions V20.0, V19.0 and V18.0<\/li>\n\t<li>\u00a0IBM Business Process Manager - versions V8.6 and V8.5<\/li>\n\t<li>\u00a0IBM Netezza Host Management - versions 5.4.9.0 to 5.4.28.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-22","alert_type":396,"serial_number":"AV20-381","subject":null,"moderation_state":"published","external_url":null},{"nid":2121,"title":"Mozilla security advisory","uuid":"0992dfd5-7835-4ad5-b84f-a2e6cf29b366","banner":null,"lang":"en","date_modified":"2020-10-20","date_modified_ts":"2020-10-20T18:05:45Z","date_created":"2020-10-20T18:05:45Z","summary":null,"body":["<article data-history-node-id=\"2121\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-383<br \/>\nDate: 20 October 2020<\/strong><\/p>\n\n<p>On 20 October 2020 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR \u2013 versions prior to 78.4<\/li>\n\t<li>Firefox \u2013 versions prior to 82<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Mozilla Security Advisory (MFSA 2020-46)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-46\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-46\/<\/a><\/p>\n\n<p>Mozilla Security Advisory (MFSA 2020-45)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-45\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-45\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-22","alert_type":396,"serial_number":"AV20-383","subject":null,"moderation_state":"published","external_url":null},{"nid":2122,"title":"VMware security advisory","uuid":"d4be8a2a-6d23-4cf0-802f-ed08ca82d037","banner":null,"lang":"en","date_modified":"2020-10-20","date_modified_ts":"2020-10-20T18:17:16Z","date_created":"2020-10-20T18:17:16Z","summary":null,"body":["<article data-history-node-id=\"2122\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-384<br \/>\nDate: 20 October 2020<\/strong><\/p>\n\n<p>On 20 October 2020 VMware published a Security Advisory to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>VMware ESXi \u2013 versions 6.5, 6.7 and 7.0<\/li>\n\t<li>VMware Workstation Pro \/ Player (Workstation) - versions 15.x and 16.x<\/li>\n\t<li>VMware Fusion Pro \/ Fusion (Fusion) - versions 11.x and 12.x<\/li>\n\t<li>NSX-T \u2013 versions 2.5.x and 3.x<\/li>\n\t<li>VMware Cloud Foundation \u2013 versions 3.x and 4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2020-0023)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0023.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0023.html<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-31","alert_type":396,"serial_number":"AV20-384","subject":null,"moderation_state":"published","external_url":null},{"nid":2123,"title":"Adobe security advisory","uuid":"f8302714-ec5b-488d-b310-22414cf47ed5","banner":null,"lang":"en","date_modified":"2020-10-21","date_modified_ts":"2020-10-21T13:43:29Z","date_created":"2020-10-21T13:43:29Z","summary":null,"body":["<article data-history-node-id=\"2123\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-385<br \/>\nDate: 21 October 2020<\/strong><\/p>\n\n<p>On 20 October 2020 Adobe published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Creative Cloud Desktop Application \u2013 version 5.2 and prior<\/li>\n\t<li>Adobe Creative Cloud Desktop Application \u2013 version 2.1 and prior<\/li>\n\t<li>Adobe InDesign \u2013 version 15.1.2 and prior<\/li>\n\t<li>Adobe Media Encoder \u2013 version 14.4 and prior<\/li>\n\t<li>Adobe Premiere Pro \u2013 version 14.4 and prior<\/li>\n\t<li>Adobe Photoshop CC 2019 \u2013 version 20.0.10 and prior<\/li>\n\t<li>Adobe Photoshop 2020 \u2013 version 21.2.2 and prior<\/li>\n\t<li>Adobe After Effects \u2013 version 17.1.1 and prior<\/li>\n\t<li>Adobe Animate \u2013 version 20.5 and prior<\/li>\n\t<li>Adobe Marketo Sales Insight Salesforce package \u2013 version 1.4355 and prior<\/li>\n\t<li>Adobe Dreamweaver \u2013 version 20.2 and prior<\/li>\n\t<li>Adobe Illustrator 2020 \u2013 version 24.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-30","alert_type":396,"serial_number":"AV20-385","subject":null,"moderation_state":"published","external_url":null},{"nid":2124,"title":"[Control systems] Hitachi ABB Power Grids security advisory","uuid":"c8a5c9ee-18e8-4c97-90e1-0695463f9f13","banner":null,"lang":"en","date_modified":"2020-10-21","date_modified_ts":"2020-10-21T15:03:01Z","date_created":"2020-10-21T15:03:01Z","summary":null,"body":["<article data-history-node-id=\"2124\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-386<br \/>\nDate: 21 October 2020<\/strong><\/p>\n\n<p>On 20 October 2020 ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Hitachi ABB Power Grids XMC20 R4 using COGE5 - versions prior to co5ne_r1h07_12.esw<\/li>\n\t<li>Hitachi ABB Power Grids XMC20 R6 using COGE5 - versions prior to co5ne_r2d14_03.esw<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access to the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-294-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-294-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-294-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory","alert_type":398,"serial_number":"AV20-386","subject":null,"moderation_state":"published","external_url":null},{"nid":2125,"title":"[Control systems] Rockwell Automation security advisory","uuid":"56518cd3-fcd4-422d-bf6e-883925d5d564","banner":null,"lang":"en","date_modified":"2020-10-21","date_modified_ts":"2020-10-21T15:50:20Z","date_created":"2020-10-21T15:50:20Z","summary":null,"body":["<article data-history-node-id=\"2125\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-387<br \/>\nDate: 21 October 2020<\/strong><\/p>\n\n<p>On 20 October 2020 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Rockwell Automation 1794-AENT Flex I\/O Series B - versions 4.003 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial-of-service condition that may allow remote code execution on the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary manufacturer updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-294-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-294-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-294-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-7","alert_type":398,"serial_number":"AV20-387","subject":null,"moderation_state":"published","external_url":null},{"nid":2127,"title":"Continued Exploitation by APT Actors of Multiple Vulnerabilities","uuid":"0d1bd646-0d47-4b86-a016-62ad4d1a48fc","banner":null,"lang":"en","date_modified":"2020-10-21","date_modified_ts":"2020-10-21T19:30:26Z","date_created":"2020-10-21T19:30:26Z","summary":null,"body":["<article data-history-node-id=\"2127\" about=\"\/en\/alerts-advisories\/continued-exploitation-apt-actors-multiple-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-025\n  <br \/>\n  Date: 21 October 2020<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\u00a0\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of recent cyber threats that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>ASSESSMENT\n<\/h3>\n<p>On 20 October 2020 the National Security Agency (NSA) published a Cyber Security Advisory (U\/OO\/179811-20) [<a href=\"https:\/\/media.defense.gov\/2020\/Oct\/20\/2002519884\/-1\/-1\/0\/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF\">1<\/a>] detailing recent malicious activity targeting US information systems. The Cyber Centre is aware that many Canadian entities operate similar information systems in Canada. These information systems and the networks linking them are critical components in today\u2019s interconnected world. Relied upon by governments, utilities, small businesses and individuals worldwide, they require regular updates to secure them from malicious activity that targets known or recently discovered vulnerabilities. While manufacturers work hard to provide updates for vulnerabilities, these updates are not always applied in a timely manner by consumers.\n  <br \/>\n  \u00a0\n  <br \/>\n  The Cyber Centre continues to receive reports [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0\">2<\/a>] [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-citrix-vulnerabilities\">5<\/a>] [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-netlogon-elevation-privilege-vulnerability-cve-2020-1472\">6<\/a>] of persistent exploitation of known vulnerabilities. Much of the reported activity appears to be the result of well-coordinated Advanced Persistent Threat (APT) actors targeting systems such as unpatched remote access services, security appliances and application servers.\n  <br \/>\n  \u00a0\n  <br \/>\n  The Cyber Centre recommends that individuals and corporations review the following security guidance to better protect their information systems:\n<\/p>\n<ul><li>Cyber Centre Publications [<a href=\"https:\/\/cyber.gc.ca\/en\/publications\">3<\/a>]<\/li>\n  <li>Top 10 IT Security Actions to Protect Internet Connected Networks and Information (ITSM.10.189) [<a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10189\">4<\/a>]<\/li>\n  <li>NSA report U\/OO\/179811-20 [<a href=\"https:\/\/media.defense.gov\/2020\/Oct\/20\/2002519884\/-1\/-1\/0\/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF\">1<\/a>] - A comprehensive list of vulnerabilities impacting information systems as well as general and tailored recommendations.\u00a0\u00a0<\/li>\n<\/ul><p>Should organizations identify similar activity to that described in the referenced Advisories and Alerts, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>[1] NSA Cyber Security Advisory (U\/OO\/179811-20) <a href=\"https:\/\/media.defense.gov\/2020\/Oct\/20\/2002519884\/-1\/-1\/0\/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF\">https:\/\/media.defense.gov\/2020\/Oct\/20\/2002519884\/-1\/-1\/0\/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF<\/a>\n<\/p>\n<p>[2] AL20-020 - Canadian organizations exploited via unpatched devices and inadequate authentication\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0\">https:\/\/cyber.gc.ca\/en\/alerts\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0<\/a>\n  <br \/>\n  \u00a0\n  <br \/>\n  [3] Cyber Centre Publications\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/publications\">https:\/\/cyber.gc.ca\/en\/publications<\/a>\n  <br \/>\n  \u00a0\n  <br \/>\n  [4] Top 10 IT Security Actions to Protect Internet Connected Networks and Information (ITSM.10.189)\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10189\">https:\/\/cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10189<\/a>\n  <br \/>\n  \u00a0\n  <br \/>\n  [5] AL20-003 \u2013 Active Exploitation of Citrix Vulnerabilities\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-citrix-vulnerabilities\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-citrix-vulnerabilities<\/a>\n  <br \/>\n  \u00a0\n  <br \/>\n  [6] AL20-022 UPDATE 1 - Microsoft Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-netlogon-elevation-privilege-vulnerability-cve-2020-1472\">https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-netlogon-elevation-privilege-vulnerability-cve-2020-1472<\/a>\n  <br \/>\n  \u00a0\n  <br \/><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the\u00a0Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information\u00a0sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/continued-exploitation-apt-actors-multiple-vulnerabilities","alert_type":397,"serial_number":"AL20-025","subject":null,"moderation_state":"published","external_url":null},{"nid":2128,"title":"Google Chrome security advisory","uuid":"b0d7a2d9-3792-41f3-aa64-f7b8cac5e5a6","banner":null,"lang":"en","date_modified":"2020-10-21","date_modified_ts":"2020-10-21T19:50:23Z","date_created":"2020-10-21T19:50:23Z","summary":null,"body":["<article data-history-node-id=\"2128\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-388<br \/>\nDate: 21 October 2020<\/strong><\/p>\n\n<p>On 20 October 2020 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 86.0.4240.111<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/10\/stable-channel-update-for-desktop_20.html\">https:\/\/chromereleases.googleblog.com\/2020\/10\/stable-channel-update-for-desktop_20.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-37","alert_type":396,"serial_number":"AV20-388","subject":null,"moderation_state":"published","external_url":null},{"nid":2129,"title":"Cisco security advisory","uuid":"6a886574-c26e-4b01-85f3-13cf32588bbc","banner":null,"lang":"en","date_modified":"2020-10-22","date_modified_ts":"2020-10-22T11:56:47Z","date_created":"2020-10-22T11:56:47Z","summary":null,"body":["<article data-history-node-id=\"2129\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-64\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-389<br \/>\nDate: 22 October 2020<\/strong><\/p>\n\n<p>On 21 October 2020 Cisco published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-64","alert_type":396,"serial_number":"AV20-389","subject":null,"moderation_state":"published","external_url":null},{"nid":2130,"title":"Oracle security advisory \u2013 October 2020 Quarterly Rollup","uuid":"c7bd0cb6-0572-4c83-8f5e-7b189d18d234","banner":null,"lang":"en","date_modified":"2020-10-22","date_modified_ts":"2020-10-22T13:27:17Z","date_created":"2020-10-22T13:27:17Z","summary":null,"body":["<article data-history-node-id=\"2130\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-october-2020-quarterly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-390<br \/>\nDate: 22 October 2020<\/strong><\/p>\n\n<p>On 20 October 2020 Oracle published a Critical Patch Update Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>\u00a0Oracle Big Data Spatial and Graph \u2013 versions prior to 3.0<\/li>\n\t<li>\u00a0Oracle REST Data Services \u2013 multiple versions<\/li>\n\t<li>\u00a0Oracle TimesTen In-Memory Database \u2013 multiple versions<\/li>\n\t<li>\u00a0Oracle Communications Applications products<\/li>\n\t<li>\u00a0Oracle Communications products<\/li>\n\t<li>\u00a0Oracle Construction and Engineering products<\/li>\n\t<li>\u00a0Oracle E-Business Suite products<\/li>\n\t<li>\u00a0Oracle Enterprise Manager products<\/li>\n\t<li>\u00a0Oracle Financial Services products<\/li>\n\t<li>\u00a0Oracle Fusion Middleware products<\/li>\n\t<li>\u00a0Oracle Health Sciences products<\/li>\n\t<li>\u00a0Oracle Hospitality Guest Access \u2013 versions 4.2.0 and 4.2.1<\/li>\n\t<li>\u00a0Oracle Hyperion Essbase \u2013 version 11.1.2.4<\/li>\n\t<li>\u00a0Oracle Insurance Policy Administration J2EE \u2013 versions 11.0.2.25 and 11.1.0.15<\/li>\n\t<li>\u00a0Oracle MySQL Cluster \u2013 multiple versions<\/li>\n\t<li>\u00a0Oracle PeopleSoft Enterprise PeopleTools \u2013 versions 8.56, 8.57 and 8.58<\/li>\n\t<li>\u00a0Oracle Retail products<\/li>\n\t<li>\u00a0Oracle Siebel Apps Marketing \u2013 version 20.7<\/li>\n\t<li>\u00a0Oracle Agile PLM \u2013 versions 9.3.3, 9.3.5 and 9.3.6<\/li>\n\t<li>\u00a0Oracle Systems products<\/li>\n\t<li>\u00a0Oracle Utilities Framework \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Oracle Critical Patch Update Advisory - October 2020<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuoct2020.html\">https:\/\/www.oracle.com\/security-alerts\/cpuoct2020.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-october-2020-quarterly-rollup","alert_type":396,"serial_number":"AV20-390","subject":null,"moderation_state":"published","external_url":null},{"nid":2133,"title":"[Control systems] B. Braun security advisory","uuid":"1ab235ea-e0e2-4d55-af5f-7c61fa954313","banner":null,"lang":"en","date_modified":"2020-10-23","date_modified_ts":"2020-10-23T17:35:03Z","date_created":"2020-10-23T17:23:31Z","summary":null,"body":["<article data-history-node-id=\"2133\" about=\"\/en\/alerts-advisories\/control-systems-b-braun-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-391<br \/>\nDate: 23 October 2020<\/strong><\/p>\n\n<p>On 22 October 2020 B. Braun published Security Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>SpaceCom - versions U61 and prior (United States), L81 and prior (rest of world)<\/li>\n\t<li>Battery pack with Wi-Fi - versions U61 and earlier (United States), L81 and earlier (outside the United States)<\/li>\n\t<li>Data module compactplus - versions A10 and A11<\/li>\n\t<li>OnlineSuite \u2013 version AP 3.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a malicious actor to escalate privileges, access sensitive information, upload\/download arbitrary files and perform remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>B. Braun Security Advisories<br \/><a href=\"https:\/\/www.bbraun.com\/en\/products-and-therapies\/services\/b-braun-vulnerability-disclosure-policy\/security-advisory.html\">https:\/\/www.bbraun.com\/en\/products-and-therapies\/services\/b-braun-vulnerability-disclosure-policy\/security-advisory.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-b-braun-security-advisory","alert_type":398,"serial_number":"AV20-391","subject":null,"moderation_state":"published","external_url":null},{"nid":2131,"title":"Mozilla security advisory","uuid":"ca9c5fa5-0d2b-4399-9da7-eebefd5c2d0a","banner":null,"lang":"en","date_modified":"2020-10-23","date_modified_ts":"2020-10-23T17:34:27Z","date_created":"2020-10-23T17:27:41Z","summary":null,"body":["<article data-history-node-id=\"2131\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-392<br \/>\nDate: 23 October 2020<\/strong><\/p>\n\n<p>On 21 October 2020 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 78.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Mozilla Security Advisory (MFSA 2020-47)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-47\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-47\/<\/a><\/p>\n\n<p>Mozilla Security Advisories<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-23","alert_type":396,"serial_number":"AV20-392","subject":null,"moderation_state":"published","external_url":null},{"nid":2132,"title":"NVIDIA security advisory","uuid":"0e1c3587-4c70-47d6-a788-648da7023033","banner":null,"lang":"en","date_modified":"2020-10-23","date_modified_ts":"2020-10-23T17:36:37Z","date_created":"2020-10-23T17:36:37Z","summary":null,"body":["<article data-history-node-id=\"2132\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-393<br \/>\nDate: 23 October 2020<\/strong><\/p>\n\n<p>On 22 October 2020 NVIDIA published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>NVIDIA GeForce Experience - versions prior to 3.20.5.70<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in code execution, denial of service, escalation of privileges, and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>NVIDIA Security Bulletin<br \/><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5076\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5076<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-10","alert_type":396,"serial_number":"AV20-393","subject":null,"moderation_state":"published","external_url":null},{"nid":2134,"title":"Cisco security advisory","uuid":"757cef68-f87a-4a6f-bb5f-8c322dfa571f","banner":null,"lang":"en","date_modified":"2020-10-26","date_modified_ts":"2020-10-26T13:09:33Z","date_created":"2020-10-26T13:09:33Z","summary":null,"body":["<article data-history-node-id=\"2134\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-65\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-394<br \/>\nDate: 26 October 2020<\/strong><\/p>\n\n<p>Between 22 and 23 October 2020 Cisco published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-65","alert_type":396,"serial_number":"AV20-394","subject":null,"moderation_state":"published","external_url":null},{"nid":2135,"title":"IBM security advisory","uuid":"651085b2-5b67-42c8-b016-9db8e9d0d1b1","banner":null,"lang":"en","date_modified":"2020-10-26","date_modified_ts":"2020-10-26T15:44:49Z","date_created":"2020-10-26T15:44:49Z","summary":null,"body":["<article data-history-node-id=\"2135\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-395<br \/>\nDate: 26 October 2020<\/strong><\/p>\n\n<p>Between 19 and 25 October 2020 IBM published Security Bulletins to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-23","alert_type":396,"serial_number":"AV20-395","subject":null,"moderation_state":"published","external_url":null},{"nid":2136,"title":"HPE security advisory","uuid":"1c53c2ce-ee3c-4fbc-9e6a-2ac4f36c74c3","banner":null,"lang":"en","date_modified":"2020-10-27","date_modified_ts":"2020-10-27T17:51:16Z","date_created":"2020-10-27T17:43:23Z","summary":null,"body":["<article data-history-node-id=\"2136\" about=\"\/en\/alerts-advisories\/hpe-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-396<br \/>\nDate: 27 October 2020<\/strong><\/p>\n\n<p>Between 21 and 23 October 2020 HPE published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>HPE 3PAR StoreServ Management and Core Software Media - versions prior to 3.7.0.0<\/li>\n\t<li>Aruba Airwave Glass - versions prior to 1.3.2<\/li>\n\t<li>BlueData EPIC Software - version 4.0 and prior<\/li>\n\t<li>HPE Ezmeral Container Platform - version 5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE 3PAR StoreServ Management and Core Software Media<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04045en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04045en_us<\/a><\/p>\n\n<p>Aruba Airwave Glass<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04051en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04051en_us<\/a><\/p>\n\n<p>BlueData EPIC Software and HPE Ezmeral Container Platform<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04049en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04049en_us<\/a><\/p>\n\n<p>HPE Security Bulletin Library<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library\/\">https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory","alert_type":396,"serial_number":"AV20-396","subject":null,"moderation_state":"published","external_url":null},{"nid":2137,"title":"[Control systems] SHUN HU Technology security advisory","uuid":"269f31a0-8b05-4ea1-bb34-84e9e11a38b2","banner":null,"lang":"en","date_modified":"2020-10-28","date_modified_ts":"2020-10-28T12:41:28Z","date_created":"2020-10-28T12:41:28Z","summary":null,"body":["<article data-history-node-id=\"2137\" about=\"\/en\/alerts-advisories\/control-systems-shun-hu-technology-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-397<br \/>\nDate: 28 October 2020<\/strong><\/p>\n\n<p>On 27 October 2020 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>JUUKO K-800 and K-808 - versions prior to numbers ending ...9A, ...9B, ...9C, etc.<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a malicious actor to replay commands, control the device, view commands, cause the device to stop running, or execute arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-301-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-301-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-301-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-shun-hu-technology-security-advisory","alert_type":398,"serial_number":"AV20-397","subject":null,"moderation_state":"published","external_url":null},{"nid":2138,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"78a07f40-b9b9-437c-a3ba-1b7ee074e626","banner":null,"lang":"en","date_modified":"2020-10-30","date_modified_ts":"2020-10-30T15:22:49Z","date_created":"2020-10-30T15:19:29Z","summary":null,"body":["<article data-history-node-id=\"2138\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-398<br \/>\nDate: 30 October 2020<\/strong><\/p>\n\n<p>On 29 October 2020 ICS-CERT published ICS Advisories to highlight vulnerabilities in Mitsubishi Electric MELSEC iQ-R, Q and L Series modules. The following modules are affected:<\/p>\n\n<ul><li>\u00a0R 00\/01\/02 CPU - firmware versions 20 and prior<\/li>\n\t<li>\u00a0R 04\/08\/16\/32\/120 (EN) CPU - firmware versions 52 and prior<\/li>\n\t<li>\u00a0R 08\/16\/32\/120 SFCPU - firmware versions 22 and prior<\/li>\n\t<li>\u00a0R 08\/16\/32\/120 PCPU - all versions<\/li>\n\t<li>\u00a0R 08\/16\/32\/120 PSFCPU - all versions<\/li>\n\t<li>\u00a0R 16\/32\/64 MTCPU - all versions<\/li>\n\t<li>\u00a0Q03 UDECPU, Q 04\/06\/10\/13\/20\/26\/50\/100 UDEHCPU - serial number 22081 and prior<\/li>\n\t<li>\u00a0Q 03\/04\/06\/13\/26 UDVCPU - serial number 22031 and prior<\/li>\n\t<li>\u00a0Q 04\/06\/13\/26 UDPVCPU - serial number 22031 and prior<\/li>\n\t<li>\u00a0Q 172\/173 DCPU to Q 172\/173 DCPU-S1 - all versions<\/li>\n\t<li>\u00a0Q 172\/173 DSCPU - all versions<\/li>\n\t<li>\u00a0Q 170 MCPU - all versions<\/li>\n\t<li>\u00a0Q 170 MSCPU to Q 170 MSCPU (-S1) - all versions<\/li>\n\t<li>\u00a0MR-MQ100 - all versions<\/li>\n\t<li>\u00a0L 02\/06\/26 CPU (-P), L 26 CPU - (P) BT - all versions<\/li>\n\t<li>\u00a0EtherNet\/IP Network Interface Module, RJ71EIP91 - first 2 digits of serial number are 02 or prior<\/li>\n\t<li>\u00a0PROFINET IO Controller Module, RJ71PN92 - first 2 digits of serial number are 01 or prior<\/li>\n\t<li>\u00a0High Speed Data Logger Module, RD81DL96 -first 2 digits of serial number are 08 or prior<\/li>\n\t<li>\u00a0MES Interface Module, RD81MES96N - first 2 digits of serial number are 04 or prior<\/li>\n\t<li>\u00a0OPC UA Server Module, RD81OPC96 - first 2 digits of serial number are 04 or prior<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could allow a remote actor to cause a denial-of-service condition or execute an arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates when available:<\/p>\n\n<p>Mitsubishi Electric MELSEC iQ-R, Q and L Series<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-303-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-303-01<\/a><\/p>\n\n<p>Mitsubishi Electric MELSEC iQ-R<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-303-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-303-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-9","alert_type":398,"serial_number":"AV20-398","subject":null,"moderation_state":"published","external_url":null},{"nid":3160,"title":"Renewed Cyber Threats to Canadian Health Organizations","uuid":"ba1dab7b-6b66-4f2d-9da7-c89c589ccf7d","banner":null,"lang":"en","date_modified":"2020-10-30","date_modified_ts":"2020-10-30T21:55:41Z","date_created":"2020-10-30T21:26:29Z","summary":null,"body":["<article data-history-node-id=\"3160\" about=\"\/en\/alerts-advisories\/renewed-cyber-threats-canadian-health-organizations\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-026\n  <br \/>\n  Date: 30 October 2020<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>OVERVIEW\n<\/h3>\n<p>On 28 October 2020 the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS) issued a Joint Cybersecurity Advisory [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-302a\">1<\/a>] to highlight credible information regarding an imminent and increased threat to the United States healthcare and public health sectors. The Cyber Centre assesses that this threat extends to Canadian healthcare providers.\n<\/p>\n<h3>DETAILS\n<\/h3>\n<p>Coinciding with the Joint Cybersecurity Advisory was the publication on 28 October 2020, by FireEye, [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/10\/kegtap-and-singlemalt-with-a-ransomware-chaser.html\">2<\/a>] of information regarding campaigns against various organizations, including hospitals and medical centres. Specifically, the FireEye report highlighted tactics, techniques, and procedures employed by the threat actors in these campaigns, as well as campaign indicators.\n<\/p>\n<p>The COVID-19 pandemic presents an elevated level of risk to the cyber security of Canadian health organizations when involved in the national response to the pandemic, including but not limited to medical care, research, manufacturing, distribution and policy-making organizations. Specifically:\n<\/p>\n<ul><li>Sophisticated threat actors may attempt to steal the intellectual property (IP) of organizations engaged in research and development related to COVID-19, or sensitive data related to Canada\u2019s response to COVID-19; and<\/li>\n  <li>Cyber criminals may take advantage of the COVID-19 pandemic, using the increased pressure being placed on Canadian health organizations to extort ransom payments or mask other compromises.<\/li>\n<\/ul><h4>Ransomware\n<\/h4>\n<p>The impact of ransomware on Canadian organizations involved in supporting Canada\u2019s response to the COVID-19 pandemic could be more severe than in a non-crisis environment. It is therefore recommended that organizations take extra precautions in identifying, as early as possible, potential vulnerabilities and inadequate security controls that may lead to an infection resulting in ransomware being deployed. The Cyber Centre strongly advises that all organizations become familiar with and practice their business continuity plans, including restoring files from back-ups and moving key business elements to back-up infrastructure.\n<\/p>\n<h4>Malicious Actor Tool Evolution\n<\/h4>\n<p>On 4 October, the Cyber Centre reported on the deployment of Ryuk ransomware [<a href=\"\/en\/alerts\/ryuk-ransomware-campaign\">3<\/a>] within Canada, the final stage of exploitation after a victim\u2019s systems have been compromised of tools such as Trickbot. More recently, researchers have identified that malicious actors have begun using new tools and techniques in order to compromise victims more covertly and to deploy ransomware such as Conti, often cited as the successor of Ryuk ransomware.\n<\/p>\n<p>The first of these tools is BazarLoader, which plays a similar role as Trickbot while being more covert. Like Trickbot, BazarLoader has been observed being used for initial compromise, typically via a phishing email, and providing a backdoor through which additional malware is introduced to the network. BazarLoader appears to be the new preferred vector when a high-value target is being pursued, possibly due to the high detection rates of Trickbot.\n<\/p>\n<p>Once access to the network is established, Anchor is used to maintain a presence on the network. The Anchor project consists of a framework of tools that allows the actors to leverage multiple methods of malicious activity against higher-profile victims.\u00a0 This framework is designed to covertly upload tools, and, when complete, to remove evidence of malicious activity. Like BazarLoader, Anchor appears to have close ties to Trickbot.\n<\/p>\n<h3>MITIGATION\n<\/h3>\n<p>In view of these threats, the Cyber Centre recommends that all Canadian health organizations involved in the national response to the pandemic take appropriate measures to ensure that they are actively engaged in cyber defense best practices.\n<\/p>\n<p>Special consideration should be given to the following publications for guidance:\n<\/p>\n<ul><li>Always keep in mind these top 10 security actions:\n    <ul><li><a href=\"\/en\/top-10-it-security-actions\">https:\/\/cyber.gc.ca\/en\/top-10-it-security-actions<\/a>\n        <br \/>\n        \u00a0<\/li>\n    <\/ul><\/li>\n  <li>Technical Approaches to Uncovering and Remediating Malicious Activity:\n    <ul><li><a href=\"\/en\/guidance\/joint-cybersecurity-advisory\">https:\/\/cyber.gc.ca\/en\/guidance\/joint-cybersecurity-advisory<\/a>\n        <br \/>\n        \u00a0<\/li>\n    <\/ul><\/li>\n  <li>Stay aware of ongoing phishing activities related to COVID-19:\n    <ul><li><a href=\"\/en\/guidance\/cyber-hygiene-covid-19\">https:\/\/cyber.gc.ca\/en\/guidance\/cyber-hygiene-covid-19<\/a>\n        <br \/>\n        \u00a0<\/li>\n    <\/ul><\/li>\n  <li>Employees working from home could put a strain on telework services. Ensure appropriate security policies have been put in place, and monitor logs for malicious activity:\n    <ul><li><a href=\"\/en\/guidance\/telework-security-issues-itsap10016\">https:\/\/www.cyber.gc.ca\/en\/guidance\/telework-security-issues-itsap10016<\/a><\/li>\n      <li><a href=\"\/en\/guidance\/virtual-private-networks-itsap80101\">https:\/\/www.cyber.gc.ca\/en\/guidance\/virtual-private-networks-itsap80101<\/a>\n        <br \/>\n        \u00a0<\/li>\n    <\/ul><\/li>\n  <li>Review recently published Alerts and Advisories highlighting vulnerabilities that may affect your environment:\n    <ul><li><a href=\"\/en\/alerts-advisories\">https:\/\/cyber.gc.ca\/en\/alerts-advisories<\/a>\n        <br \/>\n        \u00a0<\/li>\n    <\/ul><\/li>\n  <li>Organizations that do not have a robust cyber defense capability and could be considered at high risk for this activity are strongly encouraged to consider consulting with private vendors to improve Cyber Defence such as those outlined in the Cyber Centre publication \u201cCyber Security for Healthcare Organizations: Protecting Yourself Against Common Cyber Attacks (ITSAP.00.131)\u201d:\n    <ul><li><a href=\"\/en\/guidance\/cyber-security-healthcare-organizations-protecting-yourself-against-common-cyber-attacks\">https:\/\/cyber.gc.ca\/en\/guidance\/cyber-security-healthcare-organizations-protecting-yourself-against-common-cyber-attacks<\/a><\/li>\n    <\/ul><\/li>\n<\/ul><h3>INDICATORS OF COMPROMISE\n<\/h3>\n<p>Joint US Cyber Security Alert AA20-302A IOCs [1]:\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/sites\/default\/files\/publications\/AA20-302A.stix.xml\">https:\/\/us-cert.cisa.gov\/sites\/default\/files\/publications\/AA20-302A.stix.xml<\/a>\n<\/p>\n<p>Abuse.CH Trickbot C2 tracker:\n  <br \/><a href=\"https:\/\/feodotracker.abuse.ch\/browse\/trickbot\">https:\/\/feodotracker.abuse.ch\/browse\/trickbot<\/a>\n<\/p>\n<p>Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser - UNC1878 Indicators [2]:\n  <br \/><a href=\"https:\/\/gist.github.com\/aaronst\/6aa7f61246f53a8dd4befea86e832456\">https:\/\/gist.github.com\/aaronst\/6aa7f61246f53a8dd4befea86e832456<\/a>\n<\/p>\n<p>Ryuk Ransomware: Extensive Attack Infrastructure Revealed:\n  <br \/><a href=\"https:\/\/community.riskiq.com\/article\/0bcefe76\">https:\/\/community.riskiq.com\/article\/0bcefe76<\/a>\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>[1] Joint Cybersecurity Advisory - Ransomware Activity Targeting the Healthcare and Public Health Sector (AA20-302A):\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-302a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-302a<\/a>\n<\/p>\n<p>[2] FireEye Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser:\n  <br \/><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/10\/kegtap-and-singlemalt-with-a-ransomware-chaser.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/10\/kegtap-and-singlemalt-with-a-ransomware-chaser.html<\/a>\n<\/p>\n<p>[3] Ryuk Ransomware Campaign:\n  <br \/><a href=\"\/en\/alerts\/ryuk-ransomware-campaign\">https:\/\/cyber.gc.ca\/en\/alerts\/ryuk-ransomware-campaign<\/a>\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n  <br \/><br \/>\n  Should organizations identify activity associated to that described in this Alert, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/renewed-cyber-threats-canadian-health-organizations","alert_type":397,"serial_number":"AL20-026","subject":null,"moderation_state":"published","external_url":null},{"nid":2139,"title":"Google Chrome security advisory","uuid":"0c801637-2a84-4a1c-b91b-32385ae0d574","banner":null,"lang":"en","date_modified":"2020-11-03","date_modified_ts":"2020-11-03T12:56:19Z","date_created":"2020-11-03T12:56:19Z","summary":null,"body":["<article data-history-node-id=\"2139\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-399<br \/>\nDate:\u00a0 3 November 2020<\/strong><\/p>\n\n<p>On 2 November 2020 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Chrome for Desktop \u2013 versions prior to 86.0.4240.183<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Google Chrome Security Advisory<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/11\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/11\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-38","alert_type":396,"serial_number":"AV20-399","subject":null,"moderation_state":"published","external_url":null},{"nid":2140,"title":"IBM security advisory","uuid":"ed593db8-f9b4-464c-8adb-c85fed1d79fe","banner":null,"lang":"en","date_modified":"2020-11-03","date_modified_ts":"2020-11-03T15:45:06Z","date_created":"2020-11-03T15:41:58Z","summary":null,"body":["<article data-history-node-id=\"2140\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-400<br \/>\nDate: 3 November 2020<\/strong><\/p>\n\n<p>Between 26 October and 1 November 2020 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Rational Build Forge - versions prior to 8.0.0.17<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management \u2013 version 2.0<\/li>\n\t<li>Bouncy Castle as used by IBM QRadar SIEM \u2013 versions 7.3 and 7.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Rational Build Forge<br \/><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6351395\">https:\/\/www.ibm.com\/support\/pages\/node\/6351395<\/a><\/p>\n\n<p>IBM Cloud Pak for Multicloud Management<br \/><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6356103\">https:\/\/www.ibm.com\/support\/pages\/node\/6356103<\/a><br \/><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6356101\">https:\/\/www.ibm.com\/support\/pages\/node\/6356101<\/a><\/p>\n\n<p>Bouncy Castle as used by IBM QRadar SIEM<br \/><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6356449\">https:\/\/www.ibm.com\/support\/pages\/node\/6356449<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-24","alert_type":396,"serial_number":"AV20-400","subject":null,"moderation_state":"published","external_url":null},{"nid":2141,"title":"Oracle security advisory","uuid":"d4a30097-014d-4915-9be7-f55b1a4cc8f1","banner":null,"lang":"en","date_modified":"2020-11-03","date_modified_ts":"2020-11-03T17:45:03Z","date_created":"2020-11-03T17:45:03Z","summary":null,"body":["<article data-history-node-id=\"2141\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-401<br \/>\nDate: 3 November 2020<\/strong><\/p>\n\n<p>On 2 November 2020 Oracle published an out-of-band Security Alert to address a critical vulnerability:<\/p>\n\n<ul><li>\u00a0 Oracle WebLogic Server - versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n<\/ul><p>Oracle has stated this vulnerability can be exploited by an unauthenticated, remote actor to take control of affected systems and that exploit code has been posted on various sites.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Oracle Security Alert Advisory \u2013 CVE-2020-14750.<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2020-14750.html\">https:\/\/www.oracle.com\/security-alerts\/alert-cve-2020-14750.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-2","alert_type":396,"serial_number":"AV20-401","subject":null,"moderation_state":"published","external_url":null},{"nid":2142,"title":"Adobe security advisory","uuid":"df7c2cf9-7680-4528-8fe9-edc40ba804a3","banner":null,"lang":"en","date_modified":"2020-11-03","date_modified_ts":"2020-11-03T19:55:01Z","date_created":"2020-11-03T19:55:01Z","summary":null,"body":["<article data-history-node-id=\"2142\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-402<br \/>\nDate: 3 November 2020<\/strong><\/p>\n\n<p>On 3 November 2020 Adobe published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Adobe Acrobat DC \u2013 versions 2020.012.20048 and prior<\/li>\n\t<li>\u00a0Adobe Acrobat Reader DC \u2013 versions 2020.012.20048 and prior<\/li>\n\t<li>\u00a0Adobe Acrobat 2020 \u2013 versions 2020.001.30005 and prior<\/li>\n\t<li>\u00a0Adobe Acrobat Reader 2020 \u2013 versions 2020.001.30005 and prior<\/li>\n\t<li>\u00a0Adobe Acrobat 2017 \u2013 versions 2017.011.30175 and prior<\/li>\n\t<li>\u00a0Adobe Acrobat Reader 2017 \u2013 versions 2017.011.30175 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Acrobat and Reader<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb20-67.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb20-67.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-31","alert_type":396,"serial_number":"AV20-402","subject":null,"moderation_state":"published","external_url":null},{"nid":2143,"title":"[Control systems] ARC Informatique security advisory","uuid":"93cbf047-a643-4f75-955b-bd473319e9af","banner":null,"lang":"en","date_modified":"2020-11-04","date_modified_ts":"2020-11-04T14:21:55Z","date_created":"2020-11-04T14:21:55Z","summary":null,"body":["<article data-history-node-id=\"2143\" about=\"\/en\/alerts-advisories\/control-systems-arc-informatique-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-403<br \/>\nDate: 4 November 2020<\/strong><\/p>\n\n<p>On 3 November 2020 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>PcVue - version 8.10 to versions prior to 12.0.17<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could allow a remote actor to execute arbitrary code, expose sensitive data, and prevent legitimate users from connecting to PcVue services.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available:<\/p>\n\n<p>ARC Informatique PcVue (ICSA-20-308-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-308-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-308-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-arc-informatique-security-advisory","alert_type":398,"serial_number":"AV20-403","subject":null,"moderation_state":"published","external_url":null},{"nid":2144,"title":"Android security advisory \u2013 November 2020 monthly rollup","uuid":"8db85152-e7b7-49e1-8ea8-9cd405531441","banner":null,"lang":"en","date_modified":"2020-11-04","date_modified_ts":"2020-11-04T18:00:26Z","date_created":"2020-11-04T18:00:26Z","summary":null,"body":["<article data-history-node-id=\"2144\" about=\"\/en\/alerts-advisories\/android-security-advisory-november-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-404<br \/>\nDate: 4 November 2020<\/strong><\/p>\n\n<p>On 2 November 2020 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-11-01\">https:\/\/source.android.com\/security\/bulletin\/2020-11-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-november-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-404","subject":null,"moderation_state":"published","external_url":null},{"nid":2145,"title":"[Control systems] NEXCOM security advisory","uuid":"033bbc1c-3e2b-4b18-a8a1-351e2fa485a2","banner":null,"lang":"en","date_modified":"2020-11-04","date_modified_ts":"2020-11-04T18:03:41Z","date_created":"2020-11-04T18:03:41Z","summary":null,"body":["<article data-history-node-id=\"2145\" about=\"\/en\/alerts-advisories\/control-systems-nexcom-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-405<br \/>\nDate: 4 November 2020<\/strong><\/p>\n\n<p>On 3 November 2020 ICS-CERT published an ICS Advisory to highlight multiple vulnerabilities in the following NEXCOM product:<\/p>\n\n<ul><li>NEXCOM NIO 50 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a remote actor to cause a denial-of-service condition or view sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the recommended mitigations and apply the necessary updates.<\/p>\n\n<p>NEXCOM NIO 50 Security Advisory (ICSA-20-308-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-308-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-308-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-nexcom-security-advisory","alert_type":398,"serial_number":"AV20-405","subject":null,"moderation_state":"published","external_url":null},{"nid":2146,"title":"[Control systems] WAGO security advisory","uuid":"6c8280a0-ddcf-448d-abb1-dbe0821da36d","banner":null,"lang":"en","date_modified":"2020-11-04","date_modified_ts":"2020-11-04T18:05:55Z","date_created":"2020-11-04T18:05:55Z","summary":null,"body":["<article data-history-node-id=\"2146\" about=\"\/en\/alerts-advisories\/control-systems-wago-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-406<br \/>\nDate: 4 November 2020<\/strong><\/p>\n\n<p>On 3 November 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in WAGO products. Firmware versions prior to FW11 of the following 750-88x and 750-352 series products are affected:<\/p>\n\n<ul><li>750-352 - versions prior to FW11<\/li>\n\t<li>750-831\/xxx-xxx<\/li>\n\t<li>750-852<\/li>\n\t<li>750-880\/xxx-xxx<\/li>\n\t<li>750-881<\/li>\n\t<li>750-889<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to crash affected devices, causing a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the recommended mitigations and apply the necessary updates.<\/p>\n\n<p>WAGO Security Advisory (ICSA-20-308-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-308-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-308-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wago-security-advisory-0","alert_type":398,"serial_number":"AV20-406","subject":null,"moderation_state":"published","external_url":null},{"nid":2147,"title":"Cisco security advisory","uuid":"77d077b2-8f24-43e5-83d7-211e571c1435","banner":null,"lang":"en","date_modified":"2020-11-04","date_modified_ts":"2020-11-04T19:56:01Z","date_created":"2020-11-04T19:56:01Z","summary":null,"body":["<article data-history-node-id=\"2147\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-66\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-407<br \/>\nDate: 4 November 2020<\/strong><\/p>\n\n<p>On 4 November 2020 Cisco published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-66","alert_type":396,"serial_number":"AV20-407","subject":null,"moderation_state":"published","external_url":null},{"nid":2148,"title":"F5 security advisory","uuid":"a494932f-5983-4f33-8ae8-25a17a58d228","banner":null,"lang":"en","date_modified":"2020-11-05","date_modified_ts":"2020-11-05T16:27:58Z","date_created":"2020-11-05T16:27:58Z","summary":null,"body":["<article data-history-node-id=\"2148\" about=\"\/en\/alerts-advisories\/f5-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-408<br \/>\nDate: 5 November 2020<\/strong><\/p>\n\n<p>On 2 November 2020 F5 published Security Advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0BIG-IP \u2013 versions 14.1.0 to 16.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>F5 Security Advisories<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/knowledge-center\/security\">https:\/\/support.f5.com\/csp\/knowledge-center\/security<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory","alert_type":396,"serial_number":"AV20-408","subject":null,"moderation_state":"published","external_url":null},{"nid":2149,"title":"SaltStack security advisory","uuid":"5ef5bf62-c2da-4732-bb33-6d14ced89195","banner":null,"lang":"en","date_modified":"2020-11-05","date_modified_ts":"2020-11-05T19:49:50Z","date_created":"2020-11-05T19:49:50Z","summary":null,"body":["<article data-history-node-id=\"2149\" about=\"\/en\/alerts-advisories\/saltstack-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-409<br \/>\nDate: 5 November 2020<\/strong><\/p>\n\n<p>On 3 November 2020 SaltStack published a Security Release to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Salt - versions 3002, 3001.1, 3001.2, 3000.3, 3000.4, 2019.2.5, 2019.2.6, 2018.3.5, 2017.7.4, 2017.7.8, 2016.11.3, 2016.11.6, 2016.11.10, 2016.3.4, 2016.3.6, 2016.3.8, 2015.8.10, 2015.8.13 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in code injection and authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>SaltStack Security Release<br \/><a href=\"https:\/\/www.saltstack.com\/blog\/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves\/\">https:\/\/www.saltstack.com\/blog\/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/saltstack-security-advisory","alert_type":396,"serial_number":"AV20-409","subject":null,"moderation_state":"published","external_url":null},{"nid":2150,"title":"Apple security advisory","uuid":"99643c74-29ac-49b5-bb02-58ed63e21b1b","banner":null,"lang":"en","date_modified":"2020-11-06","date_modified_ts":"2020-11-06T16:52:05Z","date_created":"2020-11-06T16:48:57Z","summary":null,"body":["<article data-history-node-id=\"2150\" about=\"\/en\/alerts-advisories\/apple-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-410<br \/>\nDate: 6 November 2020<\/strong><\/p>\n\n<p>On 5 November 2020 Apple published Security Updates to address vulnerabilities affecting the following products:<\/p>\n\n<ul><li>\u00a0watchOS<\/li>\n\t<li>\u00a0macOS Catalina<\/li>\n\t<li>\u00a0tvOS<\/li>\n\t<li>\u00a0iOS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in credential disclosure, unauthorized file access, unexpected application termination, elevation of privileges, cross site scripting and arbitrary code execution. Apple is aware of reports that exploits for some of these issues have been posted online.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>watchOS<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT211928\">https:\/\/support.apple.com\/kb\/HT211928<\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT211944\">https:\/\/support.apple.com\/kb\/HT211944<\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT211945\">https:\/\/support.apple.com\/kb\/HT211945<\/a><\/p>\n\n<p>macOS Catalina<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT211947\">https:\/\/support.apple.com\/kb\/HT211947<\/a><\/p>\n\n<p>tvOS<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT211930\">https:\/\/support.apple.com\/kb\/HT211930<\/a><\/p>\n\n<p>iOS<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT211929\">https:\/\/support.apple.com\/kb\/HT211929<\/a><br \/><a href=\"https:\/\/support.apple.com\/kb\/HT211940\">https:\/\/support.apple.com\/kb\/HT211940<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-18","alert_type":396,"serial_number":"AV20-410","subject":null,"moderation_state":"published","external_url":null},{"nid":2151,"title":"[Control systems] WECON security advisory","uuid":"9fcfca05-ce4c-44d5-8294-54886a1c2aad","banner":null,"lang":"en","date_modified":"2020-11-06","date_modified_ts":"2020-11-06T18:54:32Z","date_created":"2020-11-06T18:54:32Z","summary":null,"body":["<article data-history-node-id=\"2151\" about=\"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-411<br \/>\nDate: 6 November 2020<\/strong><\/p>\n\n<p>On 5 November 2020 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>PLC Editor - versions 1.3.8 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a malicious actor to execute code under the privileges of the application.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-310-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-310-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-310-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-1","alert_type":398,"serial_number":"AV20-411","subject":null,"moderation_state":"published","external_url":null},{"nid":2152,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"119a80e6-3b03-4943-b166-b4312b5c576f","banner":null,"lang":"en","date_modified":"2020-11-06","date_modified_ts":"2020-11-06T18:57:03Z","date_created":"2020-11-06T18:57:03Z","summary":null,"body":["<article data-history-node-id=\"2152\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-412<br \/>\nDate: 6 November 2020<\/strong><\/p>\n\n<p>On 5 November 2020 ICS-CERT published ICS Advisories to highlight vulnerabilities in Mitsubishi Electric\u00a0 GT14 Model of GOT1000 Series. The following models are affected:<\/p>\n\n<ul><li>GT1455-QTBDE - CoreOS version 05.65.00.BD and prior<\/li>\n\t<li>GT1450-QMBDE - CoreOS version 05.65.00.BD and prior<\/li>\n\t<li>GT1450-QLBDE - CoreOS version 05.65.00.BD and prior<\/li>\n\t<li>GT1455HS-QTBDE - CoreOS version 05.65.00.BD and prior<\/li>\n\t<li>GT1450HS-QMBDE - CoreOS version 05.65.00.BD and prior<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could allow a remote actor to cause a denial-of-service condition or execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates when available:<\/p>\n\n<p>ICS Advisory (ICSA-20-310-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-310-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-310-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-10","alert_type":398,"serial_number":"AV20-412","subject":null,"moderation_state":"published","external_url":null},{"nid":2153,"title":"Mozilla security advisory","uuid":"2737fe7c-6ab5-4878-8316-bfc1b372a0fa","banner":null,"lang":"en","date_modified":"2020-11-09","date_modified_ts":"2020-11-09T18:16:40Z","date_created":"2020-11-09T18:16:40Z","summary":null,"body":["<article data-history-node-id=\"2153\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-413<br \/>\nDate: 9 November 2020<\/strong><\/p>\n\n<p>On 9 November 2020 Mozilla published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 82.0.3<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.4.1\u00a0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Mozilla Security Advisory (MFSA 2020-49)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-49\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-49\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-24","alert_type":396,"serial_number":"AV20-413","subject":null,"moderation_state":"published","external_url":null},{"nid":2154,"title":"Google Chrome security advisory","uuid":"6b9ca0bd-2677-4304-9c8a-927061a078a8","banner":null,"lang":"en","date_modified":"2020-11-10","date_modified_ts":"2020-11-10T13:11:35Z","date_created":"2020-11-10T13:11:35Z","summary":null,"body":["<article data-history-node-id=\"2154\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-39\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-414<br \/>\nDate: 10 November 2020<\/strong><\/p>\n\n<p>On 9 November 2020 Google published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 86.0.4240.193<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/11\/stable-channel-update-for-desktop_9.html\">https:\/\/chromereleases.googleblog.com\/2020\/11\/stable-channel-update-for-desktop_9.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-39","alert_type":396,"serial_number":"AV20-414","subject":null,"moderation_state":"published","external_url":null},{"nid":2155,"title":"Intel security advisory","uuid":"6405d468-cb34-47c2-8e3f-c15f6b88880a","banner":null,"lang":"en","date_modified":"2020-11-10","date_modified_ts":"2020-11-10T19:29:47Z","date_created":"2020-11-10T19:29:47Z","summary":null,"body":["<article data-history-node-id=\"2155\" about=\"\/en\/alerts-advisories\/intel-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-415<br \/>\nDate: 10 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 Intel published Security Advisories to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>Intel Active Management Technology (AMT) - versions prior to 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45<\/li>\n\t<li>Intel Standard Manageability (ISM) - versions prior to 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45<\/li>\n\t<li>Intel Wireless Bluetooth \u2013 versions prior to 21.110<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Intel Product Security Center Advisories<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-15","alert_type":396,"serial_number":"AV20-415","subject":null,"moderation_state":"published","external_url":null},{"nid":2156,"title":"Cisco security advisory","uuid":"7a81948b-58ba-4ad2-8a78-86b921851010","banner":null,"lang":"en","date_modified":"2020-11-10","date_modified_ts":"2020-11-10T20:56:04Z","date_created":"2020-11-10T20:56:04Z","summary":null,"body":["<article data-history-node-id=\"2156\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-67\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-416<br \/>\nDate: 10 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 Cisco published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cisco ASR 9000 Series Aggregation Services Routers \u2013 versions prior to 6.7.2 or 7.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-xr-cp-dos-ej8VB9QY\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-xr-cp-dos-ej8VB9QY<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-67","alert_type":396,"serial_number":"AV20-416","subject":null,"moderation_state":"published","external_url":null},{"nid":2157,"title":"[Control systems] Schneider Electric security advisory","uuid":"fd03981d-0186-426d-94ed-7ea82aa1c9cc","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T13:23:55Z","date_created":"2020-11-12T13:23:55Z","summary":null,"body":["<article data-history-node-id=\"2157\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-417<br \/>\nDate: 12 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 Schneider Electric published Security Notifications to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Easergy T300 - versions 2.7 and prior<\/li>\n\t<li>EcoStruxure Control Expert \u2013 multiple versions and platforms<\/li>\n\t<li>EcoStruxure Building Operation (EBO) \u2013 multiple versions and platforms<\/li>\n\t<li>EcoStruxure Operator Terminal Expert (Vijeo XD) \u2013 multiple versions and platforms<\/li>\n\t<li>Interactive Graphical SCADA System (IGSS) - versions 14.0.0.20247 and prior<\/li>\n\t<li>Modicon Controllers \u2013 multiple versions and platforms<\/li>\n\t<li>Modicon Web Server \u2013 multiple versions and platforms<\/li>\n\t<li>Trio Q and J Data Radios<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/wo\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/wo\/cybersecurity\/security-notifications.jsp<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-11","alert_type":398,"serial_number":"AV20-417","subject":null,"moderation_state":"published","external_url":null},{"nid":2158,"title":"SAP security advisory \u2013 November 2020 monthly rollup","uuid":"b3617cc0-5acd-4e0d-a298-822fa747f523","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T13:27:40Z","date_created":"2020-11-12T13:27:40Z","summary":null,"body":["<article data-history-node-id=\"2158\" about=\"\/en\/alerts-advisories\/sap-security-advisory-november-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-418<br \/>\nDate: 12 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 SAP published Security Advisories to highlight vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>SAP Solution Manager (JAVA Stack and User Experience Monitoring) - version 7.2<\/li>\n\t<li>SAP Data Services - version 4.2<\/li>\n\t<li>SAP AS ABAP (DMIS) - versions 2011.1.620, 2011.1.640, 2011.1.700, 2011.1.710, 2011.1.730, 2011.1.731, 2011.1.752, 2020<\/li>\n\t<li>SAP S\/4 HANA (DMIS) - versions 101, 102, 103, 104, 105<\/li>\n\t<li>SAP NetWeaver AS JAVA - versions 7.20, 7.30, 7.31, 7.40, 7.50<\/li>\n\t<li>SAP NetWeaver (Knowledge Management) - versions 7.30, 7.31, 7.40, 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 November 2020<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=562725571\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=562725571<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-november-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-418","subject":null,"moderation_state":"published","external_url":null},{"nid":2159,"title":"Microsoft security advisory \u2013 November 2020 monthly rollup","uuid":"ef3cd55d-a3ac-42ed-9fb5-96dcdd22c7b3","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T13:30:56Z","date_created":"2020-11-12T13:30:56Z","summary":null,"body":["<article data-history-node-id=\"2159\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-november-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-419<br \/>\nDate: 12 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>Microsoft Windows<\/li>\n\t<li>Microsoft Windows Server<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>November 2020 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2020-Nov\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2020-Nov<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-november-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-419","subject":null,"moderation_state":"published","external_url":null},{"nid":2160,"title":"Citrix security advisory","uuid":"5df9e9ef-83ff-430b-abce-ef13fba3ddb2","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T15:05:25Z","date_created":"2020-11-12T15:05:25Z","summary":null,"body":["<article data-history-node-id=\"2160\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-420<br \/>\nDate: 12 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Virtual Apps and Desktops \u2013 versions 2006 and prior<\/li>\n\t<li>Citrix Virtual Apps and Desktops 1912 LTSR \u2013 versions CU1 and prior<\/li>\n\t<li>Citrix XenApp \/ XenDesktop 7.15 LTSR \u2013 versions CU6 and prior<\/li>\n\t<li>Citrix XenApp \/ XenDesktop 7.6 LTSR \u2013 versions CU8 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX285059)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX285059\">https:\/\/support.citrix.com\/article\/CTX285059<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-10","alert_type":396,"serial_number":"AV20-420","subject":null,"moderation_state":"published","external_url":null},{"nid":2161,"title":"Google Chrome security advisory","uuid":"ebecbb54-07f3-461b-81f0-5383d54f6917","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T15:09:12Z","date_created":"2020-11-12T15:09:12Z","summary":null,"body":["<article data-history-node-id=\"2161\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-40\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-421<br \/>\nDate: 12 November 2020<\/strong><\/p>\n\n<p>On 11 November 2020 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 86.0.4240.198<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/11\/stable-channel-update-for-desktop_11.html\">https:\/\/chromereleases.googleblog.com\/2020\/11\/stable-channel-update-for-desktop_11.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-40","alert_type":396,"serial_number":"AV20-421","subject":null,"moderation_state":"published","external_url":null},{"nid":2162,"title":"[Control systems] Siemens security advisory","uuid":"c3b674d8-cc81-4ce3-b6e8-03b93b27bf27","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T16:38:28Z","date_created":"2020-11-12T16:38:28Z","summary":null,"body":["<article data-history-node-id=\"2162\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-422<br \/>\nDate: 12 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Information Server<\/li>\n\t<li>Opcenter \u2013 multiple versions and platforms<\/li>\n\t<li>Process Historian (incl. Process Historian OPC UA Server)<\/li>\n\t<li>PSS CAPE Protection Simulation Platform<\/li>\n\t<li>SCALANCE W1750D<\/li>\n\t<li>SICAM 230<\/li>\n\t<li>SIMATIC \u2013 multiple versions and platforms<\/li>\n\t<li>SIMIT Simulation Platform \u2013 versions 10 and prior<\/li>\n\t<li>SIMOCODE ES \u2013 versions prior to V16 Update 1<\/li>\n\t<li>SINEC INS<\/li>\n\t<li>SINEMA Remote Connect<\/li>\n\t<li>SINUMERIK 840D sl<\/li>\n\t<li>Soft Starter ES<\/li>\n\t<li>SPPA \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-15","alert_type":398,"serial_number":"AV20-422","subject":null,"moderation_state":"published","external_url":null},{"nid":2163,"title":"[Control systems] OSIsoft security advisory","uuid":"5fc6a8a0-0000-49bd-a73f-644814420c78","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T16:43:56Z","date_created":"2020-11-12T16:43:56Z","summary":null,"body":["<article data-history-node-id=\"2163\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-423<br \/>\nDate: 12 November 2020<\/strong><\/p>\n\n<p>On 10 November 2020 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>OSIsoft PI Vision 2020 \u2013 versions prior to PI Vision 2020<\/li>\n\t<li>OSIsoft PI Interface for OPC XML-DA - versions prior to 1.7.3.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in information disclosure, code injection or code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates when available:<\/p>\n\n<p>ICS Advisory (ICSA-20-315-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-315-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-315-01<\/a><\/p>\n\n<p>ICS Advisory (ICSA-20-315-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-315-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-315-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory-1","alert_type":398,"serial_number":"AV20-423","subject":null,"moderation_state":"published","external_url":null},{"nid":2164,"title":"Palo Alto security advisory","uuid":"6c5658ad-4f1e-4977-add6-222b7f4d7d47","banner":null,"lang":"en","date_modified":"2020-11-12","date_modified_ts":"2020-11-12T18:44:55Z","date_created":"2020-11-12T18:44:55Z","summary":null,"body":["<article data-history-node-id=\"2164\" about=\"\/en\/alerts-advisories\/palo-alto-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-424<br \/>\nDate: 12 November 2020<\/strong><br \/>\n\u00a0<br \/>\nOn 11 November 2020 Palo Alto published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PAN-OS \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>PAN-OS: Authentication bypass<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2020-2050\">https:\/\/security.paloaltonetworks.com\/CVE-2020-2050<\/a><\/p>\n\n<p>PAN-OS: Panorama session disclosure<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2020-2022\">https:\/\/security.paloaltonetworks.com\/CVE-2020-2022<\/a><\/p>\n\n<p>Palo Alto Networks Security Advisories<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-security-advisory-0","alert_type":396,"serial_number":"AV20-424","subject":null,"moderation_state":"published","external_url":null},{"nid":2165,"title":"Apple security advisory","uuid":"16e35ad0-69c7-402b-aeb9-3f7a63efcfd3","banner":null,"lang":"en","date_modified":"2020-11-13","date_modified_ts":"2020-11-13T13:44:08Z","date_created":"2020-11-13T13:40:00Z","summary":null,"body":["<article data-history-node-id=\"2165\" about=\"\/en\/alerts-advisories\/apple-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-425<br \/>\nDate: 13 November 2020<\/strong><\/p>\n\n<p>On 12 November 2020 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Big Sur<\/li>\n\t<li>macOS High Sierra<\/li>\n\t<li>macOS Mojave<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>macOS Big Sur<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211931\">https:\/\/support.apple.com\/en-ca\/HT211931<\/a><\/p>\n\n<p>macOS High Sierra \/ macOS Mojave<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211946\">https:\/\/support.apple.com\/en-ca\/HT211946<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><font face=\"Calibri\" size=\"3\"><font face=\"Calibri\" size=\"3\"><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\"><\/span><\/font><\/font><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\">\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-19","alert_type":396,"serial_number":"AV20-425","subject":null,"moderation_state":"published","external_url":null},{"nid":2166,"title":"[Control systems] Becton, Dickinson and Company security advisory","uuid":"eff56553-ae77-42e8-88b5-8ce472651b50","banner":null,"lang":"en","date_modified":"2020-11-13","date_modified_ts":"2020-11-13T14:40:36Z","date_created":"2020-11-13T14:40:36Z","summary":null,"body":["<article data-history-node-id=\"2166\" about=\"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-426<br \/>\nDate: 13 November 2020<\/strong><\/p>\n\n<p>On 12 November 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>BD Alaris PC Unit, Model 8015 - versions 9.33.1 and prior<\/li>\n\t<li>BD Alaris Systems Manager - versions 4.33 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available:<\/p>\n\n<p>ICS Advisory (ICSMA-20-317-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-317-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-317-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-security-advisory-0","alert_type":398,"serial_number":"AV20-426","subject":null,"moderation_state":"published","external_url":null},{"nid":2167,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"31d7bd65-5808-4bfe-8db7-b9946140aec1","banner":null,"lang":"en","date_modified":"2020-11-13","date_modified_ts":"2020-11-13T14:42:29Z","date_created":"2020-11-13T14:42:29Z","summary":null,"body":["<article data-history-node-id=\"2167\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-427<br \/>\nDate: 13 November 2020<\/strong><\/p>\n\n<p>On 12 November 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in Mitsubishi Electric MELSEC iQ-R series of products. The following CPU modules are affected:<\/p>\n\n<ul><li>R00\/01\/02 CPU Firmware - versions 05 to 19<\/li>\n\t<li>R04\/08\/16\/32\/120(EN) CPU Firmware - versions 35 to 51<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-20-317-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-317-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-317-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-11","alert_type":398,"serial_number":"AV20-427","subject":null,"moderation_state":"published","external_url":null},{"nid":2168,"title":"A10 Networks security advisory","uuid":"fc173445-18bb-4a3f-9b91-5f3dea78c54c","banner":null,"lang":"en","date_modified":"2020-11-13","date_modified_ts":"2020-11-13T16:05:24Z","date_created":"2020-11-13T16:05:24Z","summary":null,"body":["<article data-history-node-id=\"2168\" about=\"\/en\/alerts-advisories\/a10-networks-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-428<br \/>\nDate: 13 November 2020<\/strong><\/p>\n\n<p>On 9 November 2020 A10 Networks published a Security Advisory to address a critical vulnerability affecting the following products :<\/p>\n\n<ul><li>ACOS \u2013 multiple versions<\/li>\n\t<li>aGalaxy TPS \u2013 multiple versions<\/li>\n\t<li>aGalaxy ADC \u2013 versions 3.0.1 to 3.0.4-P3<\/li>\n<\/ul><p>An unauthenticated remote actor with access to the management interface could exploit this vulnerability to execute arbitrary code resulting in partial or complete compromise of the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>ACOS\/aGalaxy GUI RCE Vulnerability<br \/><a href=\"https:\/\/support.a10networks.com\/support\/security_advisory\/acos-agalaxy-gui-rce-vulnerability-cve-2020-24384\">https:\/\/support.a10networks.com\/support\/security_advisory\/acos-agalaxy-gui-rce-vulnerability-cve-2020-24384<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/a10-networks-security-advisory","alert_type":396,"serial_number":"AV20-428","subject":null,"moderation_state":"published","external_url":null},{"nid":2169,"title":"Citrix security advisory","uuid":"2b55e111-f086-479b-98e2-cfff546cfe8b","banner":null,"lang":"en","date_modified":"2020-11-13","date_modified_ts":"2020-11-13T18:16:09Z","date_created":"2020-11-13T18:16:09Z","summary":null,"body":["<article data-history-node-id=\"2169\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-429<br \/>\nDate: 13 November 2020<\/strong><\/p>\n\n<p>On 12 November 2020 Citrix published a Security Bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>Citrix Hypervisor 8.2 LTSR<\/li>\n\t<li>Citrix Hypervisor 8.1<\/li>\n\t<li>Citrix XenServer 7.1 LTSR CU2<\/li>\n\t<li>Citrix XenServer 7.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Hypervisor 8.2 LTSR (CTX28517)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX285172\">https:\/\/support.citrix.com\/article\/CTX285172<\/a><\/p>\n\n<p>Citrix Hypervisor 8.1 (CTX285171)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX285171\">https:\/\/support.citrix.com\/article\/CTX285171<\/a><\/p>\n\n<p>Citrix XenServer 7.1 LTSR CU2 (CTX285170)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX285170\">https:\/\/support.citrix.com\/article\/CTX285170<\/a><\/p>\n\n<p>Citrix XenServer 7.0 (CTX285169)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX285169\">https:\/\/support.citrix.com\/article\/CTX285169<\/a><\/p>\n\n<p>Citrix Security Bulletin (CTX285937)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX285937\">https:\/\/support.citrix.com\/article\/CTX285937<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-11","alert_type":396,"serial_number":"AV20-429","subject":null,"moderation_state":"published","external_url":null},{"nid":2170,"title":"IBM security advisory","uuid":"fa8220df-74dd-4f83-ac64-699d05cbce96","banner":null,"lang":"en","date_modified":"2020-11-16","date_modified_ts":"2020-11-16T18:11:56Z","date_created":"2020-11-16T18:11:56Z","summary":null,"body":["<article data-history-node-id=\"2170\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-430<br \/>\nDate: 16 November 2020<\/strong><\/p>\n\n<p>Between 2 and 15 November 2020 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Planning Analytics Workspace Release 57 and prior<\/li>\n\t<li>IBM Operations Analytics \u2013 Log Analysis \u2013 version 1.3.5.3<\/li>\n\t<li>App Connect Enterprise Certified Container \u2013 versions 1.04 with Operator and prior<\/li>\n\t<li>Power Hardware Management Console (HMC) - versions 9.1.910.0 and prior<\/li>\n\t<li>IBM Watson Machine Learning Community Edition \u2013 versions 1.6.2 and 1.7.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-25","alert_type":396,"serial_number":"AV20-430","subject":null,"moderation_state":"published","external_url":null},{"nid":2171,"title":"Cisco security advisory","uuid":"40bf6015-5a26-4f07-9a9c-f79fade0ed70","banner":null,"lang":"en","date_modified":"2020-11-17","date_modified_ts":"2020-11-17T17:46:33Z","date_created":"2020-11-17T17:46:33Z","summary":null,"body":["<article data-history-node-id=\"2171\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-68\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-431<br \/>\nDate: 17 November 2020<\/strong><\/p>\n\n<p>On 16 November 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Cisco Security Manager \u2013 releases 4.21 and prior<\/li>\n<\/ul><p>Exploitation of this directory traversal vulnerability could allow an unauthenticated remote actor to gain access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Cisco Security Manager Path Traversal Vulnerability<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-csm-path-trav-NgeRnqgR\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-csm-path-trav-NgeRnqgR<\/a><\/p>\n\n<p>Cisco Security Advisories<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-68","alert_type":396,"serial_number":"AV20-431","subject":null,"moderation_state":"published","external_url":null},{"nid":2172,"title":"HPE security advisory","uuid":"265b9e72-6aee-4d09-8ae5-b93764b7cc60","banner":null,"lang":"en","date_modified":"2020-11-17","date_modified_ts":"2020-11-17T20:17:23Z","date_created":"2020-11-17T20:17:23Z","summary":null,"body":["<article data-history-node-id=\"2172\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-432<br \/>\nDate: 17 November 2020<\/strong><\/p>\n\n<p>On 16 November 2020 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0HPE Apollo 4200 Gen10 Server - System ROM prior to v2.40<\/li>\n\t<li>\u00a0HPE ProLiant Gen10 Servers \u2013 multiple models with System ROM prior to v2.40<\/li>\n\t<li>\u00a0HPE ProLiant Gen10 Servers \u2013 multiple models with System ROM prior to v2.20<\/li>\n\t<li>\u00a0HPE ProLiant BL460c Gen10 Server Blade \u2013 System ROM prior to v2.40<\/li>\n\t<li>\u00a0HPE Synergy 480 Gen10 Plus Compute Module - System ROM prior to v2.40<\/li>\n\t<li>\u00a0HPE Synergy 660 Gen10 Compute Module - System ROM prior to v2.40<\/li>\n\t<li>\u00a0HPE ProLiant e910 Server Blade - System ROM prior to v1.84<\/li>\n\t<li>\u00a0HPE ProLiant m750 Server Blade \u2013 System ROM prior to v2.40<\/li>\n\t<li>\u00a0HPE ProLiant MicroServer Gen10 Prior to System ROM to v2.40<\/li>\n\t<li>\u00a0HPE StoreEasy 1000 Storage Gen10 - System ROM prior to v2.40<\/li>\n\t<li>\u00a0HPE ProLiant BL460c Gen9 Server Blade - System ROM prior to v2.80<\/li>\n\t<li>\u00a0HPE ProLiant BL660c Gen9 Server Blade - System ROM prior to v2.80<\/li>\n\t<li>\u00a0HPE ProLiant Gen9 Servers \u2013 multiple models with System ROM prior to v2.80<\/li>\n\t<li>\u00a0HPE StoreEasy 1000 Storage Gen9 - System ROM prior to v2.80<\/li>\n\t<li>\u00a0HPE Synergy 620 Gen9 Compute Module - System ROM prior to v2.80<\/li>\n\t<li>\u00a0HPE Synergy 680 Gen9 Compute Module - System ROM prior to v2.80<\/li>\n\t<li>\u00a0HPE Superdome Flex Server TBS<\/li>\n\t<li>\u00a0HPE ProLiant m510 Server Cartridge - System ROM prior to v1.84<\/li>\n\t<li>\u00a0HPE Apollo 4200 Gen9 Server - System ROM prior to v2.80<\/li>\n<\/ul><p>Exploitation of some of the vulnerabilities could allow local privilege escalation on affected devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04058en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04058en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-0","alert_type":396,"serial_number":"AV20-432","subject":null,"moderation_state":"published","external_url":null},{"nid":2175,"title":"Mozilla security advisory","uuid":"d5ca42f8-5600-4bd7-a36b-fce7e54b71de","banner":null,"lang":"en","date_modified":"2020-11-17","date_modified_ts":"2020-11-17T20:24:38Z","date_created":"2020-11-17T20:24:38Z","summary":null,"body":["<article data-history-node-id=\"2175\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-433<br \/>\nDate: 17 November 2020<\/strong><\/p>\n\n<p>On 17 November 2020 Mozilla published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Firefox \u2013 versions prior to 83<\/li>\n\t<li>\u00a0Firefox ESR \u2013 versions prior to 78.5<\/li>\n\t<li>\u00a0Thunderbird \u2013 versions prior to 78.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Mozilla Security Advisory: Firefox (MFSA 2020-50)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-50\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-50\/<\/a><\/p>\n\n<p>Mozilla Security Advisory: Firefox ESR (MFSA 2020-51)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-51\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-51\/<\/a><\/p>\n\n<p>Mozilla Security Advisory: Thunderbird (MFSA 2020-52)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-52\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-52\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<font face=\"Calibri\" size=\"3\"><font color=\"#0066cc\" face=\"Calibri\" size=\"3\"><span lang=\"FR-CA\" xml:lang=\"FR-CA\" xml:lang=\"FR-CA\"><\/span><\/font><\/font><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-25","alert_type":396,"serial_number":"AV20-433","subject":null,"moderation_state":"published","external_url":null},{"nid":2173,"title":"[Control systems] Real Time Automation security advisory","uuid":"f7dca122-a992-46ae-9f0e-33d2c3274f11","banner":null,"lang":"en","date_modified":"2020-11-18","date_modified_ts":"2020-11-18T14:43:22Z","date_created":"2020-11-18T14:43:22Z","summary":null,"body":["<article data-history-node-id=\"2173\" about=\"\/en\/alerts-advisories\/control-systems-real-time-automation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-434<br \/>\nDate: 18 November 2020<\/strong><\/p>\n\n<p>On 17 November 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>499ES EtherNet\/IP Adaptor Source Code \u2013 all versions prior to 2.28<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to cause a denial-of-service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-20-324-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-324-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-324-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-real-time-automation-security-advisory","alert_type":398,"serial_number":"AV20-434","subject":null,"moderation_state":"published","external_url":null},{"nid":2174,"title":"[Control systems] Paradox security advisory","uuid":"1e87256a-6509-4ed0-a771-46ddd49d0b9f","banner":null,"lang":"en","date_modified":"2020-11-18","date_modified_ts":"2020-11-18T14:49:03Z","date_created":"2020-11-18T14:49:03Z","summary":null,"body":["<article data-history-node-id=\"2174\" about=\"\/en\/alerts-advisories\/control-systems-paradox-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-435<br \/>\nDate: 18 November 2020<\/strong><\/p>\n\n<p>On 17 November 2020 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Paradox IP150 firmware \u2013 version 5.02.09<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow a remote actor to execute arbitrary code, which could result in the termination of the physical security system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-20-324-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-324-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-324-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-paradox-security-advisory","alert_type":398,"serial_number":"AV20-435","subject":null,"moderation_state":"published","external_url":null},{"nid":2176,"title":"[Control systems] Johnson Controls security advisory","uuid":"a2e78639-ead6-411f-88cf-2677ee9c9e8e","banner":null,"lang":"en","date_modified":"2020-11-18","date_modified_ts":"2020-11-18T15:16:59Z","date_created":"2020-11-18T15:16:59Z","summary":null,"body":["<article data-history-node-id=\"2176\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-436<br \/>\nDate: 18 November 2020<\/strong><\/p>\n\n<p>On 17 November 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>American Dynamics victor Web Client - versions v5.6 and prior<\/li>\n\t<li>Software House C\u2022CURE Web Client \u2013 versions v2.90 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote, unauthenticated actor to cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-324-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-324-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-324-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-3","alert_type":398,"serial_number":"AV20-436","subject":null,"moderation_state":"published","external_url":null},{"nid":2177,"title":"Apple security advisory","uuid":"d32ff21c-c232-464c-aef5-5692534c25d0","banner":null,"lang":"en","date_modified":"2020-11-19","date_modified_ts":"2020-11-19T13:43:08Z","date_created":"2020-11-19T13:43:08Z","summary":null,"body":["<article data-history-node-id=\"2177\" about=\"\/en\/alerts-advisories\/apple-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-437<br \/>\nDate: 19 November 2020<\/strong><\/p>\n\n<p>On 17 November 2020 Apple published Security Updates to address vulnerabilities in the following product:<\/p>\n\n<ul><li>iTunes for Windows - versions prior to 12.11<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in information disclosure, arbitrary code execution or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>iTunes for Windows<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211933\">https:\/\/support.apple.com\/en-ca\/HT211933<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-20","alert_type":396,"serial_number":"AV20-437","subject":null,"moderation_state":"published","external_url":null},{"nid":2178,"title":"Cisco security advisory","uuid":"c567c3c4-2c17-4c56-8de2-293b7289b23b","banner":null,"lang":"en","date_modified":"2020-11-19","date_modified_ts":"2020-11-19T13:52:24Z","date_created":"2020-11-19T13:52:24Z","summary":null,"body":["<article data-history-node-id=\"2178\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-69\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-438<br \/>\nDate: 19 November 2020<\/strong><\/p>\n\n<p>On 18 November 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco IoT Field Network Director \u2013 versions prior to 4.6.1<\/li>\n\t<li>Cisco DNA Spaces Connector \u2013 version 2.2 and prior<\/li>\n\t<li>Cisco Integrated Management Controller (multiple products and versions)<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an unauthenticated, remote actor to gain unauthorized system access, run arbitrary commands, and execute arbitrary code with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco IoT Field Network Director<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-FND-BCK-GHkPNZ5F\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-FND-BCK-GHkPNZ5F<\/a><\/p>\n\n<p>Cisco DNA Spaces Connector<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-dna-cmd-injection-rrAYzOwc\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-dna-cmd-injection-rrAYzOwc<\/a><\/p>\n\n<p>Cisco Integrated Management Controller<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ucs-api-rce-UXwpeDHd\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ucs-api-rce-UXwpeDHd<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-69","alert_type":396,"serial_number":"AV20-438","subject":null,"moderation_state":"published","external_url":null},{"nid":2179,"title":"Drupal security advisory","uuid":"30fb7f14-cb80-41b4-b98f-7602548d656b","banner":null,"lang":"en","date_modified":"2020-11-19","date_modified_ts":"2020-11-19T17:43:36Z","date_created":"2020-11-19T17:43:36Z","summary":null,"body":["<article data-history-node-id=\"2179\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-439<br \/>\nDate: 19 November 2020<\/strong><\/p>\n\n<p>On 18 November 2020 Drupal published a Security Advisory to address a vulnerability in the following versions of Drupal core:<\/p>\n\n<ul><li>Drupal 7 - versions prior to 7.74<\/li>\n\t<li>Drupal 8.8 - versions prior to 8.8.11<\/li>\n\t<li>Drupal 8.9 - versions prior to 8.9.9<\/li>\n\t<li>Drupal 9.0 - versions prior to 9.0.8<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update:<\/p>\n\n<p>Drupal Security Advisory<br \/><a href=\"https:\/\/www.drupal.org\/sa-core-2020-012\">https:\/\/www.drupal.org\/sa-core-2020-012<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-10","alert_type":396,"serial_number":"AV20-439","subject":null,"moderation_state":"published","external_url":null},{"nid":2180,"title":"VMware security advisory","uuid":"c233340e-20df-4ebe-a401-a83974acd6b0","banner":null,"lang":"en","date_modified":"2020-11-19","date_modified_ts":"2020-11-19T20:54:54Z","date_created":"2020-11-19T20:54:43Z","summary":null,"body":["<article data-history-node-id=\"2180\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-440<br \/>\nDate: 19 November 2020<\/strong><\/p>\n\n<p>On 18 November 2020 VMware published a Security Advisory to address vulnerabilities in:<\/p>\n\n<ul><li>VMware SD-WAN Orchestrator - versions 3.x and 4.x<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to unauthorized access, privilege escalation, information disclosure or code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>VMware Security Advisory (VMSA-2020-0025)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0025.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0025.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-32","alert_type":396,"serial_number":"AV20-440","subject":null,"moderation_state":"published","external_url":null},{"nid":2181,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"c42b7bfd-5c14-4fd6-b1b7-474dbedd443b","banner":null,"lang":"en","date_modified":"2020-11-20","date_modified_ts":"2020-11-20T19:50:24Z","date_created":"2020-11-20T19:50:24Z","summary":null,"body":["<article data-history-node-id=\"2181\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-441<br \/>\nDate: 20 November 2020<\/strong><\/p>\n\n<p>On 19 November 2020 Mitsubishi Electric published an advisory to address a vulnerability in the following MELSEC iQ-R series products:<\/p>\n\n<ul><li>\u00a0\u00a0\u00a0\u00a0 R00\/01\/02CPU - firmware version 19 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 R04\/08\/16\/32\/120(EN)CPU - firmware version 51 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 R08\/16\/32\/120SFCPU - firmware version 22 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 R08\/16\/32\/120PCPU - all versions<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 R08\/16\/32\/120PSFCPU - all versions<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RJ71EN71 - firmware version 47 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RJ71GF11-T2 - firmware version 47 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RJ72GF15-T2 - firmware version 07 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RJ71GP21-SX - firmware version 47 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RJ71GP21S-SX - firmware version 47 and prior<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RJ71C24(-R2\/R4) - all versions<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RJ71GN11-T2 - all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>Mitsubishi Electric advisory (2020-016)<\/p>\n\n<p><a href=\"https:\/\/www.mitsubishielectric.com\/en\/psirt\/vulnerability\/pdf\/2020-016_en.pdf\">https:\/\/www.mitsubishielectric.com\/en\/psirt\/vulnerability\/pdf\/2020-016_en.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-12","alert_type":398,"serial_number":"AV20-441","subject":null,"moderation_state":"published","external_url":null},{"nid":2182,"title":"VMware security advisory","uuid":"b68b777f-8a15-40c6-852a-3b884125d795","banner":null,"lang":"en","date_modified":"2020-11-23","date_modified_ts":"2020-11-23T13:19:32Z","date_created":"2020-11-23T13:19:32Z","summary":null,"body":["<article data-history-node-id=\"2182\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-442<br \/>\nDate: 23 November 2020<\/strong><\/p>\n\n<p>On 19 November 2020 VMware published a Security Advisory to address vulnerabilities in:<\/p>\n\n<ul><li>VMware ESXi - versions 6.5, 6.7 and 7.0<\/li>\n\t<li>VMware Workstation Pro \/ Player - version 15.x<\/li>\n\t<li>VMware Fusion Pro \/ Fusion - version 11.x<\/li>\n\t<li>VMware Cloud Foundation - versions 3.x and 4.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to unauthorized code execution or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>VMware Security Advisory (VMSA-2020-0026)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0026.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0026.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-33","alert_type":396,"serial_number":"AV20-442","subject":null,"moderation_state":"published","external_url":null},{"nid":2183,"title":"IBM security advisory","uuid":"22e2439b-5f84-425d-a118-c311a824b7b3","banner":null,"lang":"en","date_modified":"2020-11-23","date_modified_ts":"2020-11-23T21:00:04Z","date_created":"2020-11-23T21:00:04Z","summary":null,"body":["<article data-history-node-id=\"2183\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-443<br \/>\nDate: 23 November 2020<\/strong><\/p>\n\n<p>Between 16 and 22 November 2020 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>UCD \u2013 IBM UrbanCode Deploy - all versions<\/li>\n\t<li>IBM Maximo Asset Management - versions 7.6.0 and 7.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>UCD \u2013 IBM UrbanCode Deploy<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cve-2019-17638-jetty-double-release-of-a-byte-buffer\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cve-2019-17638-jetty-double-release-of-a-byte-buffer\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cve-2019-10173cve-2019-10173-xstream-api-if-the-security-framework-has-not-been-initialized-it-may-allow-a-remote-attacker-to-run-arbitrary-shell-commands\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cve-2019-10173cve-2019-10173-xstream-api-if-the-security-framework-has-not-been-initialized-it-may-allow-a-remote-attacker-to-run-arbitrary-shell-commands\/<\/a><\/p>\n\n<p>IBM Maximo Asset Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-multiple-jackson-databind-cves-february-2020-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-multiple-jackson-databind-cves-february-2020-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-26","alert_type":396,"serial_number":"AV20-443","subject":null,"moderation_state":"published","external_url":null},{"nid":2184,"title":"VMware security advisory","uuid":"a43573f9-23db-4b6b-b60f-ca88e99914fc","banner":null,"lang":"en","date_modified":"2020-11-24","date_modified_ts":"2020-11-24T16:19:39Z","date_created":"2020-11-24T16:19:39Z","summary":null,"body":["<article data-history-node-id=\"2184\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-444<br \/>\nDate: 24 November 2020<\/strong><\/p>\n\n<p>On 23 November 2020 VMware published a Security Advisory to address a vulnerability in:<\/p>\n\n<ul><li>VMware Workspace One Access (Access) - versions 20.01 and 20.10 (Linux only)<\/li>\n\t<li>VMware Identity Manager (vIDM) - versions 3.3.1 to 3.3.3 (Linux only)<\/li>\n\t<li>VMware Identity Manager Connector (vIDM Connector) - versions 3.3.1 to 3.3.3<\/li>\n\t<li>VMware Cloud Foundation - version 4.x<\/li>\n\t<li>vRealize Suite Lifecycle Manager - version 8.x<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to execute commands with unrestricted privileges on the underlying operating system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>VMware Security Advisory (VMSA-2020-0027)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0027.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0027.html<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-34","alert_type":396,"serial_number":"AV20-444","subject":null,"moderation_state":"published","external_url":null},{"nid":2185,"title":"Citrix security advisory","uuid":"194d1fff-3508-4d8b-95f3-3914aadbd381","banner":null,"lang":"en","date_modified":"2020-11-24","date_modified_ts":"2020-11-24T17:50:24Z","date_created":"2020-11-24T17:50:24Z","summary":null,"body":["<article data-history-node-id=\"2185\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-445<br \/>\nDate: 24 November 2020<\/strong><\/p>\n\n<p>On 24 November 2020 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Hypervisor \u2013 versions 8.1 and 8.2 LTSR<\/li>\n\t<li>Citrix XenServer \u2013 versions 7.0 and 7.1 Cumulative Update 2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX286511)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX286511\">https:\/\/support.citrix.com\/article\/CTX286511<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-12","alert_type":396,"serial_number":"AV20-445","subject":null,"moderation_state":"published","external_url":null},{"nid":2186,"title":"[Control systems] Fuji Electric security advisory","uuid":"abf5f56b-45e3-4c1b-a024-f2ca6e736496","banner":null,"lang":"en","date_modified":"2020-11-25","date_modified_ts":"2020-11-25T14:43:47Z","date_created":"2020-11-25T14:43:47Z","summary":null,"body":["<article data-history-node-id=\"2186\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-446<br \/>\nDate: 25 November 2020<\/strong><\/p>\n\n<p>On 24 November 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>V-Server Lite - versions prior to 3.3.24.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-20-329-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-329-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-329-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-2","alert_type":398,"serial_number":"AV20-446","subject":null,"moderation_state":"published","external_url":null},{"nid":2187,"title":"[Control systems] Rockwell Automation security advisory","uuid":"f51604f3-094a-4e38-aec0-568bbd5e8f35","banner":null,"lang":"en","date_modified":"2020-11-25","date_modified_ts":"2020-11-25T16:37:56Z","date_created":"2020-11-25T16:37:56Z","summary":null,"body":["<article data-history-node-id=\"2187\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-447<br \/>\nDate: 25 November 2020<\/strong><\/p>\n\n<p>On 24 November 2020 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Rockwell Automation FactoryTalk Linx - version 6.11 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, information disclosure and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-20-329-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-329-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-329-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-8","alert_type":398,"serial_number":"AV20-447","subject":null,"moderation_state":"published","external_url":null},{"nid":2188,"title":"Drupal security advisory","uuid":"31371a88-d2c3-4b37-9ba3-7d55d07e627b","banner":null,"lang":"en","date_modified":"2020-11-26","date_modified_ts":"2020-11-26T16:48:22Z","date_created":"2020-11-26T16:48:22Z","summary":null,"body":["<article data-history-node-id=\"2188\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-448<br \/>\nDate: 26 November 2020<\/strong><\/p>\n\n<p>On 25 November 2020 Drupal published a Security Advisory to address vulnerabilities in the following versions of Drupal core:<\/p>\n\n<ul><li>\u00a0Drupal 7 - versions prior to 7.75<\/li>\n\t<li>\u00a0Drupal 8.8 - versions prior to 8.8.12<\/li>\n\t<li>\u00a0Drupal 8.9 - versions prior to 8.9.10<\/li>\n\t<li>\u00a0Drupal 9.0 - versions prior to 9.0.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update:<\/p>\n\n<p>Drupal Security Advisory (SA-CORE-2020-013)<br \/><a href=\"https:\/\/www.drupal.org\/sa-core-2020-013\">https:\/\/www.drupal.org\/sa-core-2020-013<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-11","alert_type":396,"serial_number":"AV20-448","subject":null,"moderation_state":"published","external_url":null},{"nid":2189,"title":"IBM security advisory","uuid":"d8713255-4aa5-439f-ba83-70692e04cc90","banner":null,"lang":"en","date_modified":"2020-11-30","date_modified_ts":"2020-11-30T16:11:29Z","date_created":"2020-11-30T16:11:29Z","summary":null,"body":["<article data-history-node-id=\"2189\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-449<br \/>\nDate: 30 November 2020<\/strong><\/p>\n\n<p>Between 23 and 29 November 2020 IBM published Security Bulletins to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>IBM Cloud Automation Manager \u2013 version 4.2.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Cloud Automation Manager<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-jison-affectsi-bm-cloud-automation-manager\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-jison-affectsi-bm-cloud-automation-manager\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-node-forge-module-affects-ibm-cloud-automation-manager\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-node-forge-module-affects-ibm-cloud-automation-manager\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-27","alert_type":396,"serial_number":"AV20-449","subject":null,"moderation_state":"published","external_url":null},{"nid":2190,"title":"HPE security advisory","uuid":"ab819c2f-4d99-49a1-a476-857b71246daf","banner":null,"lang":"en","date_modified":"2020-12-01","date_modified_ts":"2020-12-01T16:13:57Z","date_created":"2020-12-01T16:13:57Z","summary":null,"body":["<article data-history-node-id=\"2190\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-450<br \/>\nDate: 1 December 2020<\/strong><\/p>\n\n<p>On 30 November 2020 HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE HP-UX Perl Software - version E.5.28.0.A<\/li>\n\t<li>HPE Edgeline Infrastructure Manager \u2013 versions prior to 1.21<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>HPE HP-UX Perl Software<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04065en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04065en_us<\/a><\/p>\n\n<p>HPE Edgeline Infrastructure Manager<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04063en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04063en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-1","alert_type":396,"serial_number":"AV20-450","subject":null,"moderation_state":"published","external_url":null},{"nid":2191,"title":"HPE security advisory","uuid":"fb367a2b-c479-4e38-b943-b6691ffb17f3","banner":null,"lang":"en","date_modified":"2020-12-02","date_modified_ts":"2020-12-02T13:25:16Z","date_created":"2020-12-02T13:25:16Z","summary":null,"body":["<article data-history-node-id=\"2191\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-451<br \/>\nDate: 2 December 2020<\/strong><\/p>\n\n<p>On 1 December 2020 HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Web Server Suite running Apache on HP-UX 11iv3 - versions 2.4.18.05 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HP-UX Web Server Suite running Apache on HP-UX 11iv3<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04050en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04050en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-2","alert_type":396,"serial_number":"AV20-451","subject":null,"moderation_state":"published","external_url":null},{"nid":2192,"title":"Mozilla security advisory","uuid":"2c189475-a6e3-42c4-affc-d146c61414f0","banner":null,"lang":"en","date_modified":"2020-12-02","date_modified_ts":"2020-12-02T17:18:22Z","date_created":"2020-12-02T17:18:22Z","summary":null,"body":["<article data-history-node-id=\"2192\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-452<br \/>\nDate: 2 December 2020<\/strong><\/p>\n\n<p>On 1 December 2020 Mozilla published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 78.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Mozilla Security Advisory (MFSA 2020-53)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-53\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-53\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-26","alert_type":396,"serial_number":"AV20-452","subject":null,"moderation_state":"published","external_url":null},{"nid":2193,"title":"Apple security advisory","uuid":"62e2cd5f-2e58-4430-9ac2-3596d650fca7","banner":null,"lang":"en","date_modified":"2020-12-03","date_modified_ts":"2020-12-03T13:54:37Z","date_created":"2020-12-03T13:54:37Z","summary":null,"body":["<article data-history-node-id=\"2193\" about=\"\/en\/alerts-advisories\/apple-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-453<br \/>\nDate: 3 December 2020<\/strong><\/p>\n\n<p>On 2 December 2020 Apple published Security Updates to address vulnerabilities in the following product:<\/p>\n\n<ul><li>iCloud for Windows - versions prior to 11.5<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution, arbitrary file reading, unexpected application termination, denial of service, memory leaking, or data corruption.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>iCloud for Windows<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT211935\">https:\/\/support.apple.com\/en-ca\/HT211935<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-21","alert_type":396,"serial_number":"AV20-453","subject":null,"moderation_state":"published","external_url":null},{"nid":2194,"title":"Google Chrome security advisory","uuid":"13f8636c-3f99-4e23-a61d-bfa63ed98e64","banner":null,"lang":"en","date_modified":"2020-12-03","date_modified_ts":"2020-12-03T16:31:25Z","date_created":"2020-12-03T16:31:25Z","summary":null,"body":["<article data-history-node-id=\"2194\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-41\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-454<br \/>\nDate: 3 December 2020<\/strong><\/p>\n\n<p>On 2 December 2020 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 87.0.4280.88<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2020\/12\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2020\/12\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-41","alert_type":396,"serial_number":"AV20-454","subject":null,"moderation_state":"published","external_url":null},{"nid":2195,"title":"[Control systems] National Instruments security advisory","uuid":"3b501e41-4cb0-48b9-be97-374743169f08","banner":null,"lang":"en","date_modified":"2020-12-03","date_modified_ts":"2020-12-03T19:28:56Z","date_created":"2020-12-03T19:28:56Z","summary":null,"body":["<article data-history-node-id=\"2195\" about=\"\/en\/alerts-advisories\/control-systems-national-instruments-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-455<br \/>\nDate: 3 December 2020<\/strong><\/p>\n\n<p>On 3 December 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>National Instruments Corp. CompactRIO \u2013 driver versions prior to 20.5<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to reboot the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-338-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-338-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-338-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-national-instruments-security-advisory","alert_type":398,"serial_number":"AV20-455","subject":null,"moderation_state":"published","external_url":null},{"nid":2196,"title":"HPE security advisory","uuid":"68d8bd9c-9463-41bd-af84-51dded5c6a10","banner":null,"lang":"en","date_modified":"2020-12-04","date_modified_ts":"2020-12-04T19:30:09Z","date_created":"2020-12-04T18:44:28Z","summary":null,"body":["<article data-history-node-id=\"2196\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-456<br \/>\nDate: 4 December 2020<\/strong><\/p>\n\n<p>On 3 December 2020 HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Web Server Suite Software HP-UX PHP \u2013 version 7.2.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HP-UX Web Server Suite Software HP-UX PHP<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04071en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04071en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-3","alert_type":396,"serial_number":"AV20-456","subject":null,"moderation_state":"published","external_url":null},{"nid":2197,"title":"Active exploitation of VMware vulnerability","uuid":"bcfbf2db-5e7b-4e6d-8bb9-08c1541b0612","banner":null,"lang":"en","date_modified":"2020-12-07","date_modified_ts":"2020-12-07T20:19:17Z","date_created":"2020-12-07T20:08:02Z","summary":null,"body":["<article data-history-node-id=\"2197\" about=\"\/en\/alerts-advisories\/active-exploitation-vmware-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-027<br \/>\nDate: 7 December 2020<\/strong><\/p>\n\n<h3>AUDIENCE<\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h3>PURPOSE<\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3>ASSESSMENT<\/h3>\n\n<p>On 7 December the Cyber Centre was made aware of active exploitation of a VMware command injection vulnerability (CVE-2020-4006) using stolen credentials [<a href=\"https:\/\/media.defense.gov\/2020\/Dec\/07\/2002547071\/-1\/-1\/0\/CSA_VMWARE%20ACCESS_U_OO_195076_20.PDF\">1<\/a>], which are frequently used to exploit systems [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0\">2<\/a>]. A malicious actor with network access to the administrative configurator on port 8443 and a valid password for the configurator admin account can execute commands with unrestricted privileges on the underlying operating system [<a href=\"https:\/\/www.VMware.com\/security\/advisories\/VMSA-2020-0027.html\">3<\/a>]. The list of vulnerable products includes VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector.<\/p>\n\n<h3>RECOMMENDED ACTIONS<\/h3>\n\n<p>The Cyber Centre recommends the following actions to detect potentially malicious activity against vulnerable systems:<\/p>\n\n<dir><\/dir><dir><\/dir><ul><li>Monitor for any unusual connections to the administrative configurator on port 8443;<\/li>\n\t<li>Examine system logs for unusual or unauthorized activity;<\/li>\n\t<li>Check for recently added users with elevated privileges.<\/li>\n<\/ul><h3>MITIGATION<\/h3>\n\n<p>The Cyber Centre recommends that organizations follow mitigation and patching recommendations for any impacted products:<\/p>\n\n<dir><\/dir><dir><\/dir><ul><li>Apply recommended patches for affected products [<a href=\"https:\/\/kb.VMware.com\/s\/article\/81754\">4<\/a>];<\/li>\n\t<li>Ensure the administrative configurator is not accessible to external interfaces;<\/li>\n\t<li>Enable Two-Factor Authentication [<a href=\"https:\/\/docs.VMware.com\/en\/VMware-Workspace-ONE-Access\/3.3\/idm-administrator\/GUID-FE8A5B1C-BC17-4A5C-BC8D-614C5EE4057A.html\">5<\/a>];<\/li>\n\t<li>Apply workaround solutions as a temporary measure for CVE-2020-4006 [<a href=\"https:\/\/kb.VMware.com\/s\/article\/81731\">6<\/a>] until patching is completed.<\/li>\n<\/ul><p>Should organizations identify associated activity to that described in this Alert, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n\n<h3>REFERENCES<\/h3>\n\n<p>[1] Russian State-Sponsored Malicious Cyber Actors Exploit Known Vulnerability in Virtual Workspaces<\/p>\n\n<p><a href=\"https:\/\/media.defense.gov\/2020\/Dec\/07\/2002547071\/-1\/-1\/0\/CSA_VMWARE%20ACCESS_U_OO_195076_20.PDF\">https:\/\/media.defense.gov\/2020\/Dec\/07\/2002547071\/-1\/-1\/0\/CSA_VMWARE%20ACCESS_U_OO_195076_20.PDF<\/a><\/p>\n\n<p>[2] Canadian organizations exploited via unpatched devices and inadequate authentication<\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0\">https:\/\/cyber.gc.ca\/en\/alerts\/canadian-organizations-exploited-unpatched-devices-and-inadequate-authentication-0<\/a><\/p>\n\n<p>[3] VMware Advisory ID: VMSA-2020-0027.2<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2020-0027.html\">https:\/\/www.VMware.com\/security\/advisories\/VMSA-2020-0027.html<\/a><\/p>\n\n<p>[4] HW-128524: CVE-2020-4006 Patches for Workspace ONE Access, Identity Manager and Connector (81754)<\/p>\n\n<p><a href=\"https:\/\/kb.vmware.com\/s\/article\/81754\">https:\/\/kb.VMware.com\/s\/article\/81754<\/a><\/p>\n\n<p>[5] VMware Workspace ONE Access: Configuring VMware Verify for Two-Factor Authentication<\/p>\n\n<p><a href=\"https:\/\/docs.vmware.com\/en\/VMware-Workspace-ONE-Access\/3.3\/idm-administrator\/GUID-FE8A5B1C-BC17-4A5C-BC8D-614C5EE4057A.html\">https:\/\/docs.VMware.com\/en\/VMware-Workspace-ONE-Access\/3.3\/idm-administrator\/GUID-FE8A5B1C-BC17-4A5C-BC8D-614C5EE4057A.html<\/a><\/p>\n\n<p>[6] VMware Workspace ONE Access, VMware Identity Manager, VMware Identity Manager Connector Workaround Instructions for CVE-2020-4006 (81731)<\/p>\n\n<p><a href=\"https:\/\/kb.vmware.com\/s\/article\/81731\">https:\/\/kb.VMware.com\/s\/article\/81731<\/a><\/p>\n\n<p>[7] VMware Security Advisory<\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/vmware-security-advisory-34\">https:\/\/cyber.gc.ca\/en\/alerts\/vmware-security-advisory-34<\/a><\/p>\n\n<p><br \/><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p><br \/>\nThe Cyber Centre can be contacted at:<\/p>\n\n<p>Email: <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a><\/p>\n\n<p>Toll Free: <a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> <a href=\"tel:+1-833-292-3788\">(1-833-292-3788)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-vmware-vulnerability","alert_type":397,"serial_number":"AL20-027","subject":null,"moderation_state":"published","external_url":null},{"nid":2198,"title":"IBM security advisory","uuid":"a8fa7627-c3b3-4512-bbba-2656755b6327","banner":null,"lang":"en","date_modified":"2020-12-07","date_modified_ts":"2020-12-07T21:01:44Z","date_created":"2020-12-07T21:01:44Z","summary":null,"body":["<article data-history-node-id=\"2198\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-457<br \/>\nDate: 7 December 2020<\/strong><\/p>\n\n<p>Between 30 November and 6 December 2020 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM InfoSphere Information Server \u2013 versions 11.5 and 11.7<\/li>\n\t<li>IBM Spectrum Protect Plus \u2013 versions 10.1.5 to 10.1.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM InfoSphere Information Server<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-bypass-vulnerability-in-apache-solr-lucene-affects-ibm-infosphere-information-server\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-bypass-vulnerability-in-apache-solr-lucene-affects-ibm-infosphere-information-server\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Plus<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-pyyaml-affects-ibm-spectrum-protect-plus-container-and-microsoft-file-systems-agents-cve-2020-1747-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-pyyaml-affects-ibm-spectrum-protect-plus-container-and-microsoft-file-systems-agents-cve-2020-1747-2\/<\/a>\u00a0<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-28","alert_type":396,"serial_number":"AV20-457","subject":null,"moderation_state":"published","external_url":null},{"nid":2199,"title":"Cisco security advisory","uuid":"0f762e77-5c5c-4441-82e1-8b56c55da4e9","banner":null,"lang":"en","date_modified":"2020-12-08","date_modified_ts":"2020-12-08T14:55:55Z","date_created":"2020-12-08T14:55:55Z","summary":null,"body":["<article data-history-node-id=\"2199\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-70\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-458<br \/>\nDate: 8 December 2020<\/strong><\/p>\n\n<p>On 7 December 2020 Cisco updated a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Cisco Security Manager \u2013 version 4.22 and prior<\/li>\n<\/ul><p>Exploitation could allow an unauthenticated, remote actor to execute arbitrary commands on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Security Manager<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-csm-java-rce-mWJEedcD\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-csm-java-rce-mWJEedcD<\/a><\/p>\n\n<p>Cisco Security Advisories<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-70","alert_type":396,"serial_number":"AV20-458","subject":null,"moderation_state":"published","external_url":null},{"nid":2200,"title":"Android security advisory \u2013 December 2020 monthly rollup","uuid":"78df78ed-f6c9-499d-95e3-e7935459b89c","banner":null,"lang":"en","date_modified":"2020-12-08","date_modified_ts":"2020-12-08T18:05:33Z","date_created":"2020-12-08T18:05:33Z","summary":null,"body":["<article data-history-node-id=\"2200\" about=\"\/en\/alerts-advisories\/android-security-advisory-december-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-459<br \/>\nDate: 8 December 2020<\/strong><\/p>\n\n<p>On 7 December 2020 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2020-12-01\">https:\/\/source.android.com\/security\/bulletin\/2020-12-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-december-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-459","subject":null,"moderation_state":"published","external_url":null},{"nid":2201,"title":"SAP security advisory \u2013 December 2020 monthly rollup","uuid":"73a13a35-5115-4ea4-95e2-992dfe75a0e4","banner":null,"lang":"en","date_modified":"2020-12-08","date_modified_ts":"2020-12-08T18:08:08Z","date_created":"2020-12-08T18:08:08Z","summary":null,"body":["<article data-history-node-id=\"2201\" about=\"\/en\/alerts-advisories\/sap-security-advisory-december-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-460<br \/>\nDate: 8 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 SAP published Security Advisories to highlight vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>SAP NetWeaver AS JAVA (P2P Cluster Communication) \u2013 versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50<\/li>\n\t<li>SAP BusinessObjects BI Platform (Crystal Report) \u2013 versions 4.1, 4.2, 4.3<\/li>\n\t<li>SAP Business Warehouse \u2013 versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782<\/li>\n\t<li>SAP BW4HANA \u2013 versions 100, 200<\/li>\n\t<li>SAP AS ABAP (DMIS) \u2013 versions 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020<\/li>\n\t<li>SAP S4 HANA (DMIS) \u2013 versions 101, 102, 103, 104, 105<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 December 2020<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=564757079\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=564757079<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-december-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-460","subject":null,"moderation_state":"published","external_url":null},{"nid":2202,"title":"[Control systems] Schneider Electric security advisory","uuid":"5929c740-b408-4b24-a0af-d5f1b65aff06","banner":null,"lang":"en","date_modified":"2020-12-08","date_modified_ts":"2020-12-08T18:10:13Z","date_created":"2020-12-08T18:10:13Z","summary":null,"body":["<article data-history-node-id=\"2202\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-461<br \/>\nDate: 8 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 Schneider Electric published Security Notifications to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Control Expert \u2013 multiple versions and platforms<\/li>\n\t<li>EcoStruxure Geo SCADA Expert \u2013 multiple versions and platforms<\/li>\n\t<li>EcoStruxure Machine Expert \u2013 multiple versions and platforms<\/li>\n\t<li>Modicon Controllers \u2013 multiple versions and platforms<\/li>\n\t<li>Modicon SNMP Service \u2013 multiple versions and platforms<\/li>\n\t<li>Modicon Web Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/wo\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/wo\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-12","alert_type":398,"serial_number":"AV20-461","subject":null,"moderation_state":"published","external_url":null},{"nid":2203,"title":"Apache security advisory","uuid":"644c176c-ac4a-4f50-9f58-654931b6e69b","banner":null,"lang":"en","date_modified":"2020-12-08","date_modified_ts":"2020-12-08T18:15:54Z","date_created":"2020-12-08T18:15:54Z","summary":null,"body":["<article data-history-node-id=\"2203\" about=\"\/en\/alerts-advisories\/apache-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-462<br \/>\nDate: 8 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 Apache published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Apache Struts 2 - versions 2.0.0 to 2.5.25<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution on the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Apache Security Bulletin<br \/><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-061\">https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-061<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-2","alert_type":396,"serial_number":"AV20-462","subject":null,"moderation_state":"published","external_url":null},{"nid":2204,"title":"[Control systems] GE Healthcare security advisory","uuid":"509438cf-9fca-412c-be34-f0b6f93d2166","banner":null,"lang":"en","date_modified":"2020-12-08","date_modified_ts":"2020-12-08T19:32:25Z","date_created":"2020-12-08T19:32:25Z","summary":null,"body":["<article data-history-node-id=\"2204\" about=\"\/en\/alerts-advisories\/control-systems-ge-healthcare-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-463<br \/>\nDate: 8 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 ICS-CERT published an ICS Medical Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>GE Imaging and Ultrasound Products \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to run arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Medical Advisory (ICSMA-20-343-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-343-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-343-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-healthcare-security-advisory","alert_type":398,"serial_number":"AV20-463","subject":null,"moderation_state":"published","external_url":null},{"nid":2205,"title":"Microsoft security advisory \u2013 December 2020 monthly rollup","uuid":"51dd796d-0263-449f-8c16-baf5a7aa46a7","banner":null,"lang":"en","date_modified":"2020-12-08","date_modified_ts":"2020-12-08T19:37:39Z","date_created":"2020-12-08T19:37:39Z","summary":null,"body":["<article data-history-node-id=\"2205\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-december-2020-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-464<br \/>\nDate: 8 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>ChakraCore<\/li>\n\t<li>Dynamics 365 for Finance and Operations<\/li>\n\t<li>Microsoft Exchange<\/li>\n\t<li>Microsoft SharePoint<\/li>\n\t<li>Microsoft Windows<\/li>\n\t<li>Microsoft Windows Server<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>December 2020 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2020-Dec\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2020-Dec<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-december-2020-monthly-rollup","alert_type":396,"serial_number":"AV20-464","subject":null,"moderation_state":"published","external_url":null},{"nid":2206,"title":"[Control systems] ABB security advisory","uuid":"b831800a-3491-41ef-991e-09b9c0272422","banner":null,"lang":"en","date_modified":"2020-12-09","date_modified_ts":"2020-12-09T15:54:17Z","date_created":"2020-12-09T15:54:17Z","summary":null,"body":["<article data-history-node-id=\"2206\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-465<br \/>\nDate: 9 December 2020<\/strong><\/p>\n\n<p>On 2 December 2020 ABB published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ABB Arctic Wireless Gateway ARG600\/ARC600\/ARP600\/ARR600 \u2013 versions 3.4.9 and prior<\/li>\n\t<li>ABB REC\/RER 601\/603 \u2013 all versions<\/li>\n\t<li>Viola Systems Arctic Wireless Gateways \u2013 all versions<\/li>\n\t<li>Viola Systems 3G gateway 2620 \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>ABB Cyber Security Advisory<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA000784&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA000784&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-10","alert_type":398,"serial_number":"AV20-465","subject":null,"moderation_state":"published","external_url":null},{"nid":2207,"title":"Adobe security advisory","uuid":"6a3fd282-e6ee-4289-8f1f-dff337aa6f6e","banner":null,"lang":"en","date_modified":"2020-12-09","date_modified_ts":"2020-12-09T16:01:11Z","date_created":"2020-12-09T16:01:11Z","summary":null,"body":["<article data-history-node-id=\"2207\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-466<br \/>\nDate: 9 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 Adobe published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Prelude \u2013 versions 9.0.1 and prior<\/li>\n\t<li>Adobe Experience Manager \u2013 multiple versions and platforms<\/li>\n\t<li>Adobe Lightroom Classic \u2013 versions 10.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Prelude<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/prelude\/apsb20-70.html\">https:\/\/helpx.adobe.com\/security\/products\/prelude\/apsb20-70.html<\/a><\/p>\n\n<p>Adobe Experience Manager<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb20-72.html\">https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb20-72.html<\/a><\/p>\n\n<p>Adobe Lightroom Classic<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/lightroom\/apsb20-74.html\">https:\/\/helpx.adobe.com\/security\/products\/lightroom\/apsb20-74.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-32","alert_type":396,"serial_number":"AV20-466","subject":null,"moderation_state":"published","external_url":null},{"nid":2208,"title":"FireEye Security Incident","uuid":"eb8e3ddf-a7d5-4a78-a0d3-809680f374ba","banner":null,"lang":"en","date_modified":"2020-12-09","date_modified_ts":"2020-12-09T20:55:50Z","date_created":"2020-12-09T20:55:50Z","summary":null,"body":["<article data-history-node-id=\"2208\" about=\"\/en\/alerts-advisories\/fireeye-security-incident\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-028\n  <br \/>\n  Date: 9 December 2020<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>OVERVIEW\n<\/h3>\n<p>On 8 December 2020 FireEye disclosed that it was recently the victim of a targeted security breach by a highly sophisticated threat actor. [<a href=\"https:\/\/www.fireeye.com\/blog\/products-and-services\/2020\/12\/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html\">1<\/a>]\n<\/p>\n<h3>DETAILS\n<\/h3>\n<p>In a blog post published 8 December 2020, FireEye reported an infiltration of its internal network, carried out by a \u201chighly sophisticated threat actor.\u201d FireEye reported that an investigation was ongoing and that, to date, it had not discovered any exfiltration of customer data. However, red team security assessment tools were stolen. While FireEye has stated it cannot confidently say whether these tools will be used or publicly disclosed by the threat actor, the company released methods of detecting the use of these tools in the event that they are leveraged. [<a href=\"https:\/\/github.com\/fireeye\/red_team_tool_countermeasures\">2<\/a>]\n<\/p>\n<h3>SUGGESTED ACTION\n<\/h3>\n<p>The Cyber Centre recommends that organizations and individuals:\n<\/p>\n<ul><li>Review the CSE Top 10 Security Actions\n    <br \/>\n    (<a href=\"https:\/\/cyber.gc.ca\/en\/top-10-it-security-actions\">https:\/\/cyber.gc.ca\/en\/top-10-it-security-actions<\/a>)<\/li>\n  <li>Review the signatures shared by FireEye and consider them for inclusion within security appliances. [<a href=\"https:\/\/github.com\/fireeye\/red_team_tool_countermeasures\">2<\/a>] Organizations are encouraged to contact vendors if tailored signatures are required for specific products.<\/li>\n  <li>Consider measures to limit the amount of sensitive information that malicious actors can collect about their networks by performing security assessments on network systems for un-necessary or inadequately secured or patched services;<\/li>\n  <li>Assess networks for the presence of vulnerable software, particularly where it is installed on devices exposed to the internet, and update as soon as possible to the latest version.<\/li>\n  <li>Implement two-factor authentication (2FA) on all internet-facing remote access services, starting with perimeter security devices such as firewalls and remote access gateways for teleworkers and administrators.<\/li>\n<\/ul><p>\n  <br \/>\n  Should organizations identify activity similar to that described in this Alert, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>[1] FireEye Shares Details of Recent Cyber Attack, Actions to Protect Community:\n  <br \/><a href=\"https:\/\/www.fireeye.com\/blog\/products-and-services\/2020\/12\/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html\">https:\/\/www.fireeye.com\/blog\/products-and-services\/2020\/12\/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html<\/a>\n<\/p>\n<p>[2] FireEye Red Team Tool Countermeasures:\n  <br \/><a href=\"https:\/\/github.com\/fireeye\/red_team_tool_countermeasures\">https:\/\/github.com\/fireeye\/red_team_tool_countermeasures<\/a>\n<\/p>\n<p>\n  <br \/><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fireeye-security-incident","alert_type":397,"serial_number":"AL20-028","subject":null,"moderation_state":"published","external_url":null},{"nid":2209,"title":"[Control systems] Multiple Embedded TCP\/IP Stacks security advisory","uuid":"cd8f18e8-9d27-48af-86c1-d037cdb55d2f","banner":null,"lang":"en","date_modified":"2020-12-10","date_modified_ts":"2020-12-10T16:01:13Z","date_created":"2020-12-10T15:51:05Z","summary":null,"body":["<article data-history-node-id=\"2209\" about=\"\/en\/alerts-advisories\/control-systems-multiple-embedded-tcpip-stacks-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-467<br \/>\nDate: 10 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 ICS-CERT published an advisory to highlight multiple vulnerabilities in the following embedded TCP\/IP stack products:<\/p>\n\n<ul><li>uIP-Contiki-OS (end-of-life [EOL]) - version 3.0 and prior<\/li>\n\t<li>uIP-Contiki-NG - version 4.5 and prior<\/li>\n\t<li>uIP (EOL) - version 1.0 and prior<\/li>\n\t<li>open-iscsi - version 2.1.12 and prior<\/li>\n\t<li>picoTCP-NG - version 1.7.0 and prior<\/li>\n\t<li>picoTCP (EOL) - version 1.7.0 and prior<\/li>\n\t<li>FNET - version 4.6.3<\/li>\n\t<li>Nut\/Net - version 5.1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a remote actor to corrupt memory, execute arbitrary code, put devices into infinite loops, access unauthorized data, and\/or poison DNS cache.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, follow the recommended mitigations where appropriate and apply the necessary updates when available.<\/p>\n\n<p>ICS-CERT Advisory (ICSA-20-343-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-343-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-343-01<\/a><\/p>\n\n<p>Carnegie Mellon University Vulnerability Note VU#815128<br \/><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/815128\">https:\/\/www.kb.cert.org\/vuls\/id\/815128<\/a><\/p>\n\n<p>Forescout Research Labs AMNESIA:33 Report<br \/><a href=\"https:\/\/www.forescout.com\/research-labs\/amnesia33\/\">https:\/\/www.forescout.com\/research-labs\/amnesia33\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-multiple-embedded-tcpip-stacks-security-advisory","alert_type":398,"serial_number":"AV20-467","subject":null,"moderation_state":"published","external_url":null},{"nid":2210,"title":"Cisco security advisory","uuid":"eed6f1a3-32dc-4d55-bbfd-7df7c8cdca3b","banner":null,"lang":"en","date_modified":"2020-12-10","date_modified_ts":"2020-12-10T19:36:01Z","date_created":"2020-12-10T19:36:01Z","summary":null,"body":["<article data-history-node-id=\"2210\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-71\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-468<br \/>\nDate: 10 December 2020<\/strong><\/p>\n\n<p>On 10 December 2020 Cisco published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Cisco Jabber Desktop and Mobile Client \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation could allow an actor to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Jabber Desktop and Mobile Client<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-jabber-ZktzjpgO\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-jabber-ZktzjpgO<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-71","alert_type":396,"serial_number":"AV20-468","subject":null,"moderation_state":"published","external_url":null},{"nid":2211,"title":"[Control systems] Host Engineering security advisory","uuid":"d6176d4b-49d5-40dd-894d-b3ecb8c4bd1c","banner":null,"lang":"en","date_modified":"2020-12-10","date_modified_ts":"2020-12-10T19:42:13Z","date_created":"2020-12-10T19:42:13Z","summary":null,"body":["<article data-history-node-id=\"2211\" about=\"\/en\/alerts-advisories\/control-systems-host-engineering-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-469<br \/>\nDate: 10 December 2020<\/strong><\/p>\n\n<p>On 10 December 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Host Engineering ECOM100 Module \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-20-345-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-345-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-345-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-host-engineering-security-advisory","alert_type":398,"serial_number":"AV20-469","subject":null,"moderation_state":"published","external_url":null},{"nid":2212,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"eb658b0d-9197-458b-9c37-0fbb18682b55","banner":null,"lang":"en","date_modified":"2020-12-10","date_modified_ts":"2020-12-10T19:48:41Z","date_created":"2020-12-10T19:48:41Z","summary":null,"body":["<article data-history-node-id=\"2212\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-470<br \/>\nDate: 10 December 2020<\/strong><\/p>\n\n<p>On 10 December 2020 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU modules \u2013 versions 1.060 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Medical Advisory (ICSA-20-345-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-345-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-345-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-13","alert_type":398,"serial_number":"AV20-470","subject":null,"moderation_state":"published","external_url":null},{"nid":2213,"title":"[Control systems] Medtronic security advisory","uuid":"9637079a-a0e2-438a-83fb-76ed2d36b7e4","banner":null,"lang":"en","date_modified":"2020-12-11","date_modified_ts":"2020-12-11T13:47:43Z","date_created":"2020-12-11T13:47:43Z","summary":null,"body":["<article data-history-node-id=\"2213\" about=\"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-471<br \/>\nDate: 11 December 2020<\/strong><\/p>\n\n<p>On 10 December 2020 ICS-CERT published an ICS Medical Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Medtronic MyCareLink (MCL) Smart Model 25000 Patient Reader \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to run arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Medical Advisory (ICSMA-20-345-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-345-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-20-345-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory-0","alert_type":398,"serial_number":"AV20-471","subject":null,"moderation_state":"published","external_url":null},{"nid":2214,"title":"Adobe security advisory","uuid":"a567dec9-0907-4744-b566-4d27c337792e","banner":null,"lang":"en","date_modified":"2020-12-11","date_modified_ts":"2020-12-11T13:51:15Z","date_created":"2020-12-11T13:51:15Z","summary":null,"body":["<article data-history-node-id=\"2214\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-472<br \/>\nDate: 11 December 2020<\/strong><\/p>\n\n<p>On 9 December 2020 Adobe published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Adobe Acrobat and Reader\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Acrobat and Reader<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb20-75.html\">https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb20-75.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-33","alert_type":396,"serial_number":"AV20-472","subject":null,"moderation_state":"published","external_url":null},{"nid":2225,"title":"SolarWinds Security Incident","uuid":"bb4347b3-f394-40e1-a559-8d002db5a303","banner":null,"lang":"en","date_modified":"2020-12-17","date_modified_ts":"2020-12-17T22:39:30Z","date_created":"2020-12-14T16:17:23Z","summary":null,"body":["<article data-history-node-id=\"2225\" about=\"\/en\/alerts-advisories\/solarwinds-security-incident\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-029<br \/>\nDate: 14 December 2020<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>On 13 December 2020 SolarWinds disclosed a security advisory outlining recent malicious activity impacting SolarWinds Orion Platform resulting from a supply chain compromise [<a href=\"https:\/\/www.solarwinds.com\/securityadvisory\">1<\/a>]. FireEye has published a report detailing the widespread campaign by a \u201chighly evasive\u201d actor gaining access to numerous public and private organizations around the world. [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\">2<\/a>]<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>FireEye reports they have discovered a global intrusion campaign resulting from a supply chain compromise. Through trojanizing SolarWinds Orion Platform software updates, actors were successfully able to distribute malware.\u00a0This campaign may have begun as early as Spring 2020 and FireEye reports it is currently ongoing. Post compromise activity leverages multiple techniques to evade detection and obscure their activity, which includes lateral movement and data theft. FireEye has provided a detailed analysis as well as opportunities for detection. [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\">2<\/a>][<a href=\"https:\/\/github.com\/fireeye\/sunburst_countermeasures\">3<\/a>]<\/p>\n\n<h2>MITIGATION<\/h2>\n\n<p>SolarWinds has provided guidance on how to identify the version of Orion Platform organizations are using, [<a href=\"https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/Determine-which-version-of-a-SolarWinds-Orion-product-I-have-installed?language=en_US\">4<\/a>] and to check which hotfixes organizations have applied. [<a href=\"https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/Verify-hotfixes-that-have-been-installed?language=en_US\">5<\/a>] If an organization cannot upgrade immediately, please follow the guidelines securing an Orion Platform instance. [<a href=\"https:\/\/www.solarwinds.com\/-\/media\/solarwinds\/swdcv2\/landing-pages\/trust-center\/resources\/secure-configuration-in-the-orion-platform.ashx?rev=32603e0c87d84085b081f99a33fe5f4d&amp;hash=62A998B9753957D82BC0F07005D38368\">6<\/a>]<\/p>\n\n<p>An additional hotfix release, 2020.2.1 HF 2 is anticipated to be made available Tuesday, December 15, 2020. SolarWinds recommends that all customers update to release 2020.2.1 HF 2 once it is available, as the 2020.2.1 HF 2 release both replaces the compromised component and provides several additional security enhancements.<\/p>\n\n<p>The following recommendations provided by FireEye are mitigation techniques that could be deployed as first steps to address the risk of trojanized SolarWinds software in an environment. The Cyber Centre encourages organizations review the below recommendations and action those based on an organizations own risk-based assessment.<\/p>\n\n<ul><li>Ensure that SolarWinds servers are isolated \/ contained until a further review and investigation is conducted. This should include blocking all Internet egress from SolarWinds servers.<\/li>\n\t<li>If SolarWinds infrastructure is not isolated, consider taking the following steps:\n\t<ul><li>Restrict scope of connectivity to endpoints from SolarWinds servers, especially those that would be considered Tier 0 \/ crown jewel assets<\/li>\n\t\t<li>Restrict the scope of accounts that have local administrator privileged on SolarWinds servers.<\/li>\n\t\t<li>Block Internet egress from servers or other endpoints with SolarWinds software.<\/li>\n\t<\/ul><\/li>\n\t<li>Consider (at a minimum) changing passwords for accounts that have access to SolarWinds servers \/ infrastructure. Based upon further review \/ investigation, additional remediation measures may be required.<\/li>\n\t<li>If SolarWinds is used to managed networking infrastructure, consider conducting a review of network device configurations for unexpected \/ unauthorized modifications. Note, this is a proactive measure due to the scope of SolarWinds functionality, not based on investigative findings.<\/li>\n<\/ul><p>FireEye has further provided indicators to assist network defenders in the detection of malicious activity. [<a href=\"https:\/\/github.com\/fireeye\/sunburst_countermeasures\">3<\/a>]<\/p>\n\n<p>If malicious activity is discovered in an environment, FireEye recommends conducting a comprehensive investigation and designing and executing a remediation strategy driven by the investigative findings and details of the impacted environment.<\/p>\n\n<p>Should organizations identify activity similar to that described in this Alert, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] SolarWinds Security Advisory<br \/><a href=\"https:\/\/www.solarwinds.com\/securityadvisory\">https:\/\/www.solarwinds.com\/securityadvisory<\/a><\/p>\n\n<p>[2] Highly Evasive Attacker Leverages SolarWinds Supply Chain<br \/><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html<\/a><\/p>\n\n<p>[3] sunburst_countermeasures<br \/><a href=\"https:\/\/github.com\/fireeye\/sunburst_countermeasures\">https:\/\/github.com\/fireeye\/sunburst_countermeasures<\/a><\/p>\n\n<p>[4] Determine which version of a SolarWinds Orion product I have installed<br \/><a href=\"https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/Determine-which-version-of-a-SolarWinds-Orion-product-I-have-installed?language=en_US\">https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/Determine-which-version-of-a-SolarWinds-Orion-product-I-have-installed?language=en_US<\/a><\/p>\n\n<p>[5] Verify hotfixes that have been installed<br \/><a href=\"https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/Verify-hotfixes-that-have-been-installed?language=en_US\">https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/Verify-hotfixes-that-have-been-installed?language=en_US<\/a><\/p>\n\n<p>[6] Secure Configuration for the Orion Platform<br \/><a href=\"https:\/\/www.solarwinds.com\/-\/media\/solarwinds\/swdcv2\/landing-pages\/trust-center\/resources\/secure-configuration-in-the-orion-platform.ashx?rev=32603e0c87d84085b081f99a33fe5f4d&amp;hash=62A998B9753957D82BC0F07005D38368\">https:\/\/www.solarwinds.com\/-\/media\/solarwinds\/swdcv2\/landing-pages\/trust-center\/resources\/secure-configuration-in-the-orion-platform.ashx?rev=32603e0c87d84085b081f99a33fe5f4d&amp;hash=62A998B9753957D82BC0F07005D38368<\/a><\/p>\n\n<p>[7] Customer Guidance on Recent Nation-State Cyber Attacks<br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2020\/12\/13\/customer-guidance-on-recent-nation-state-cyber-attacks\/\">https:\/\/msrc-blog.microsoft.com\/2020\/12\/13\/customer-guidance-on-recent-nation-state-cyber-attacks\/<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-incident","alert_type":397,"serial_number":"AL20-029","subject":null,"moderation_state":"published","external_url":null},{"nid":2215,"title":"IBM security advisory","uuid":"8cc25afb-b858-47cf-af90-6aeac9d225ec","banner":null,"lang":"en","date_modified":"2020-12-15","date_modified_ts":"2020-12-15T13:39:03Z","date_created":"2020-12-15T13:39:03Z","summary":null,"body":["<article data-history-node-id=\"2215\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-473<br \/>\nDate: 15 December 2020<\/strong><\/p>\n\n<p>Between 7 and 13 December 2020 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0IBM App Connect Enterprise Certified Container \u2013 versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4 and 1.0.5 with Operator<\/li>\n\t<li>\u00a0IBM Aspera High-Speed Transfer Server\/Endpoint\u2013 versions 3.9.6.2 and prior<\/li>\n\t<li>\u00a0IBM WA for ICP Node.js \u2013 versions 1.4.0, 1.4.1 and 1.4.2<\/li>\n\t<li>\u00a0IBM AIX\/VIOS Perl \u2013 multiple versions and filesets<\/li>\n\t<li>\u00a0IBM Watson Discovery for Cloud Pak for Data affected by vulnerability in FasterXML jackson-databind \u2013 versions 2.0.0 to 2.1.4<\/li>\n\t<li>\u00a0FasterXML jackson-databind \u2013 versions 1.4.0, 1.4.1 and 1.4.2<\/li>\n\t<li>\u00a0IBM Watson Discovery for Cloud Pak for Data affected by vulnerability in TensorFlow \u2013 versions 2.0.0 to 2.1.4<\/li>\n\t<li>\u00a0IBM Netezza for Cloud Pak for Data \u2013 Concerto installer \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-29","alert_type":396,"serial_number":"AV20-473","subject":null,"moderation_state":"published","external_url":null},{"nid":2216,"title":"[Control systems] Siemens security advisory","uuid":"58849030-7511-403d-934f-ddf8136bf557","banner":null,"lang":"en","date_modified":"2020-12-15","date_modified_ts":"2020-12-15T19:32:57Z","date_created":"2020-12-15T19:32:57Z","summary":null,"body":["<article data-history-node-id=\"2216\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-474<br \/>\nDate: 15 December 2020<\/strong><\/p>\n\n<p>On 8 December 2020 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SICAM A8000 CP-8000, CP-8021 and CP-8022 \u2013 versions prior to V16<\/li>\n\t<li>TightVNC within SIMATIC \u2013 multiple products and versions<\/li>\n\t<li>LOGO! 8 BM (including SIPLUS variants) and LOGO! Soft Comfort \u2013 versions prior to V8.3<\/li>\n\t<li>Embedded TCP\/IP Stack Vulnerabilities (AMNESIA:33) in:\n\t<ul><li>SIRIUS 3RW5 Modbus TCP \u2013 all versions<\/li>\n\t\t<li>SENTRON PAC3200 \u2013 versions prior to V2.4.5<\/li>\n\t\t<li>SENTRON PAC4200 \u2013 versions prior to V2.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>SIMATIC ET 200SP Open Controller and S7-1500 Software Controller \u2013 versions prior to V21.8<\/li>\n\t<li>XHQ Operations Intelligence \u2013 versions prior to V6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-16","alert_type":398,"serial_number":"AV20-474","subject":null,"moderation_state":"published","external_url":null},{"nid":2217,"title":"Palo Alto Networks security advisory","uuid":"2741b8ab-029a-410d-af03-a33288337a08","banner":null,"lang":"en","date_modified":"2020-12-15","date_modified_ts":"2020-12-15T19:41:18Z","date_created":"2020-12-15T19:37:33Z","summary":null,"body":["<article data-history-node-id=\"2217\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-475<br \/>\nDate: 15 December 2020<\/strong><\/p>\n\n<p>On 9 December 2020 Palo Alto published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cortex XDR Agent \u2013 versions 7.1.* and 7.2.* for Windows without content update 150<\/li>\n<\/ul><p>Exploitation of this vulnerability by an authorized local user may allow them to execute programs with SYSTEM privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cortex XDR Agent:<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2020-2049\">https:\/\/security.paloaltonetworks.com\/CVE-2020-2049<\/a><\/p>\n\n<p>Palo Alto Networks Security Advisories<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-5","alert_type":396,"serial_number":"AV20-475","subject":null,"moderation_state":"published","external_url":null},{"nid":2218,"title":"Apple security advisory","uuid":"ef341b23-2ec4-4280-9833-b8695c5f1127","banner":null,"lang":"en","date_modified":"2020-12-16","date_modified_ts":"2020-12-16T14:15:24Z","date_created":"2020-12-16T14:15:24Z","summary":null,"body":["<article data-history-node-id=\"2218\" about=\"\/en\/alerts-advisories\/apple-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-476<br \/>\nDate: 16 December 2020<\/strong><\/p>\n\n<p>On 14 December 2020 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0iOS and iPadOS for iPhone and iPad - versions prior to 14.3<\/li>\n\t<li>\u00a0macOS Big Sur \u2013 versions prior to 11.1<\/li>\n\t<li>\u00a0macOS Catalina \u2013 versions prior to Security Update 2020-001<\/li>\n\t<li>\u00a0macOS Mojave \u2013 versions prior to Security Update 2020-007<\/li>\n\t<li>\u00a0macOS Big Sur Server \u2013 versions prior to 5.11<\/li>\n\t<li>\u00a0tvOS for Apple TV \u2013 versions prior to 14.3<\/li>\n\t<li>\u00a0watchOS for Apple Watch Series 3 and later \u2013 versions prior to 7.2<\/li>\n\t<li>\u00a0Safari for macOS Catalina and macOS Mojave \u2013 versions prior to 14.0.2<\/li>\n\t<li>\u00a0iOS for iPhone and iPad \u2013 versions prior to 12.5<\/li>\n\t<li>\u00a0watchOS for Apple Watch Series 1 and 2 \u2013 versions prior to 6.3<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution with kernel privileges, privilege escalation, sandbox escape, cross site scripting, privacy bypass, arbitrary file read, unexpected application termination, denial of service, memory disclosure, data corruption, or heap corruption.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-22","alert_type":396,"serial_number":"AV20-476","subject":null,"moderation_state":"published","external_url":null},{"nid":2219,"title":"Mozilla security advisory","uuid":"7e7b42d9-973b-4ba8-a6c1-b35c055dd3f7","banner":null,"lang":"en","date_modified":"2020-12-16","date_modified_ts":"2020-12-16T14:24:15Z","date_created":"2020-12-16T14:24:15Z","summary":null,"body":["<article data-history-node-id=\"2219\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-477<br \/>\nDate: 16 December 2020<\/strong><\/p>\n\n<p>On 15 December 2020 Mozilla published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Thunderbird \u2013 versions prior to 78.6<\/li>\n\t<li>\u00a0Firefox ESR \u2013 versions prior to 78.6<\/li>\n\t<li>\u00a0Firefox \u2013 versions prior to 84<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Thunderbird (MFSA 2020-56)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-56\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-56\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2020-55)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-55\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-55\/<\/a><\/p>\n\n<p>Firefox (MFSA 2020-54)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-54\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2020-54\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-27","alert_type":396,"serial_number":"AV20-477","subject":null,"moderation_state":"published","external_url":null},{"nid":2220,"title":"[Control systems] ABB security advisory","uuid":"0e880945-8dde-4d41-8eb9-3302862cace2","banner":null,"lang":"en","date_modified":"2020-12-16","date_modified_ts":"2020-12-16T18:08:53Z","date_created":"2020-12-16T18:08:53Z","summary":null,"body":["<article data-history-node-id=\"2220\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-478<br \/>\nDate: 16 December 2020<\/strong><\/p>\n\n<p>On 15 December 2020 ABB published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Central Licensing System (CLS) as used in:\n\t<ul><li>ABB Ability Symphony Plus Operations \u2013 versions 3.0 to 3.3<\/li>\n\t\t<li>ABB Ability Symphony Plus Engineering \u2013 versions 1.0 to 2.3<\/li>\n\t\t<li>Composer Harmony \u2013 versions 5.1, 6.0 and 6.1<\/li>\n\t\t<li>Composer Melody \u2013 versions 5.3 and 6.1<\/li>\n\t\t<li>Harmony OPC Server \u2013 versions 6.0, 6.1 and 7.0<\/li>\n\t<\/ul><\/li>\n\t<li>ABB Ability Symphony Plus Historian \u2013 versions 3.0 and 3.1<\/li>\n\t<li>ABB Ability Symphony Plus Operations \u2013 multiple versions and service packs<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>ABB Central Licensing System<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA123981&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA123981&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>ABB Ability Symphony Plus Historian<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA123982&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA123982&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>ABB Ability Symphony Plus Operations<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA123980&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA123980&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-11","alert_type":398,"serial_number":"AV20-478","subject":null,"moderation_state":"published","external_url":null},{"nid":2221,"title":"HPE security advisory","uuid":"94d4625b-80d0-41ea-84dc-92b134415aea","banner":null,"lang":"en","date_modified":"2020-12-17","date_modified_ts":"2020-12-17T14:25:57Z","date_created":"2020-12-17T14:25:57Z","summary":null,"body":["<article data-history-node-id=\"2221\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-479<br \/>\nDate: 17 December 2020<\/strong><\/p>\n\n<p>On 15 December 2020 HPE published a Security Bulletin to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>HPE Systems Insight Manager (SIM) - version 7.6.x<\/li>\n<\/ul><p>Exploitation may lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigation and apply the necessary updates when available.<\/p>\n\n<p>HPE Systems Insight Manager (SIM)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04068en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04068en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-4","alert_type":396,"serial_number":"AV20-479","subject":null,"moderation_state":"published","external_url":null},{"nid":2222,"title":"Red Hat security advisory","uuid":"21f30887-8d88-4953-ae23-b8a80b11ea8f","banner":null,"lang":"en","date_modified":"2020-12-17","date_modified_ts":"2020-12-17T15:50:47Z","date_created":"2020-12-17T15:50:47Z","summary":null,"body":["<article data-history-node-id=\"2222\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-480<br \/>\nDate: 17 December 2020<\/strong><\/p>\n\n<p>On 14 December 2020 Red Hat published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Red Hat Advanced Cluster Management for Kubernetes 2 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability by an unauthenticated, remote actor may allow them to bypass authentication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Red Hat Advanced Cluster Management for Kubernetes 2:<br \/><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2020-27847\">https:\/\/access.redhat.com\/security\/cve\/cve-2020-27847<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-3","alert_type":396,"serial_number":"AV20-480","subject":null,"moderation_state":"published","external_url":null},{"nid":2223,"title":"Citrix security advisory","uuid":"58353d7d-7439-45f0-8660-bd5a93fa7f7f","banner":null,"lang":"en","date_modified":"2020-12-17","date_modified_ts":"2020-12-17T18:40:16Z","date_created":"2020-12-17T18:39:55Z","summary":null,"body":["<article data-history-node-id=\"2223\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-481<br \/>\nDate:\u00a017 December 2020<\/strong><\/p>\n\n<p>On 15 December 2020 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Hypervisor \u2013 versions 8.1 and 8.2 LTSR<\/li>\n\t<li>Citrix XenServer \u2013 versions 7.0 and 7.1 LTSR Cumulative Update 2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX286756)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX286756\">https:\/\/support.citrix.com\/article\/CTX286756<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-13","alert_type":396,"serial_number":"AV20-481","subject":null,"moderation_state":"published","external_url":null},{"nid":2224,"title":"Advanced Persistent Threat Compromises (CISA)","uuid":"e1c484f4-6fe5-4a1b-b9b2-7c2cead9f566","banner":null,"lang":"en","date_modified":"2020-12-17","date_modified_ts":"2020-12-17T21:57:47Z","date_created":"2020-12-17T21:57:47Z","summary":null,"body":["<article data-history-node-id=\"2224\" about=\"\/en\/alerts-advisories\/advanced-persistent-threat-compromises-cisa\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-030\n  <br \/>\n  Date: 17 December 2020<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>OVERVIEW\n<\/h3>\n<p>CISA has issued an Alert containing new information with regard to the SolarWinds supply chain compromise.\n<\/p>\n<h3>DETAILS\n<\/h3>\n<p>On 17 December 2020 the Cybersecurity and Infrastructure Security Agency (CISA), the United States\u2019 agency responsible for protecting its critical infrastructure from physical and cyber threats, produced an in-depth report on recent activity impacting US government agencies, critical infrastructure and private sector organizations. [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\">1<\/a>] This activity is a result of the recently-disclosed SolarWinds supply chain compromise, for which the Cyber Centre issued Alert AL20-029 on 14 December 2020. [<a href=\"https:\/\/www.solarwinds.com\/securityadvisory\">2<\/a>][<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/solarwinds-security-incident\">3<\/a>] The CISA report is a summary of the incidents including information regarding affected Orion products, mitigation advice, and indicators of compromise to aid in detection. CISA has provided the following key takeaways:\n<\/p>\n<ul><li>This is a patient, well-resourced, and focused adversary that has sustained long duration activity on victim networks.<\/li>\n  <li>The SolarWinds Orion supply chain compromise is not the only initial infection vector the actor leveraged.<\/li>\n  <li>Not all organizations that have the backdoor delivered through SolarWinds Orion have been targeted by the adversary with follow-on actions.<\/li>\n  <li>Organizations with suspected compromises need to be highly conscious of operational security, including when engaging in incident response activities and planning and implementing remediation plans.<\/li>\n<\/ul><p>The CISA Alert (AA20-352A) can be found at:\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\"><font color=\"#0066cc\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a<\/font><\/a>\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\"><font color=\"#0066cc\">contact@cyber.gc.ca<\/font><\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>[1] CISA Alert AA20-352A\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\"><font color=\"#0066cc\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a<\/font><\/a>\n<\/p>\n<p>[2] SolarWinds Security Advisory\n  <br \/><a href=\"https:\/\/www.solarwinds.com\/securityadvisory\"><font color=\"#0066cc\">https:\/\/www.solarwinds.com\/securityadvisory<\/font><\/a>\n<\/p>\n<p>[3] Cyber Centre Alert AL20-029:\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/solarwinds-security-incident\"><font color=\"#0066cc\">https:\/\/cyber.gc.ca\/en\/alerts\/solarwinds-security-incident<\/font><\/a>\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/advanced-persistent-threat-compromises-cisa","alert_type":397,"serial_number":"AL20-030","subject":null,"moderation_state":"published","external_url":null},{"nid":2226,"title":"[Control systems] PTC security advisory","uuid":"9dd59e46-4e23-470a-a5f6-e2b960b40c53","banner":null,"lang":"en","date_modified":"2020-12-21","date_modified_ts":"2020-12-21T13:25:48Z","date_created":"2020-12-21T13:25:48Z","summary":null,"body":["<article data-history-node-id=\"2226\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-482<br \/>\nDate: 21 December 2020<\/strong><\/p>\n\n<p>On 17 December 2020 ICS-CERT published Security Advisories to highlight vulnerabilities affecting the following products:<\/p>\n\n<ul><li>PTC Kepware LinkMaster - version 3.0.94.0 and prior<\/li>\n\t<li>PTC Kepware KEPServerEX\n\t<ul><li>Kepware KEPServerEX \u2013 versions 6.0 to 6.9<\/li>\n\t\t<li>ThingWorx Kepware Server \u2013 versions 6.8 and 6.9<\/li>\n\t\t<li>ThingWorx Industrial Connectivity - all versions<\/li>\n\t\t<li>OPC-Aggregator - all versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The following products may have a vulnerable component:<\/p>\n\n<ul><li>Rockwell Automation KEPServer Enterprise<\/li>\n\t<li>GE Digital Industrial Gateway Server - versions v7.68.804 to v7.66<\/li>\n\t<li>Software Toolbox TOP Server \u2013 all 6.x versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to crash a server, cause a denial-of-service condition, leak data, remotely execute code or globally overwrite the service configuration to execute arbitrary code with NT SYSTEM privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>PTC Kepware LinkMaster (ICSA-20-352-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-352-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-352-03<\/a><\/p>\n\n<p>PTC Kepware KEPServerEX (ICSA-20-352-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-352-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-352-02<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory","alert_type":398,"serial_number":"AV20-482","subject":null,"moderation_state":"published","external_url":null},{"nid":2227,"title":"[Control systems] Emerson security advisory","uuid":"bce6c444-f2ae-4253-b93a-0d9374d26349","banner":null,"lang":"en","date_modified":"2020-12-21","date_modified_ts":"2020-12-21T13:29:00Z","date_created":"2020-12-21T13:29:00Z","summary":null,"body":["<article data-history-node-id=\"2227\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-483<br \/>\nDate: 21 December 2020<\/strong><\/p>\n\n<p>On 17 December 2020 Emerson published a Cyber Security Notification to address a vulnerability in the following products:<\/p>\n\n<ul><li>Rosemount X-STREAM enhanced XEGP \u2013 all versions<\/li>\n\t<li>Rosemount X-STREAM enhanced XEGK \u2013 all versions<\/li>\n\t<li>Rosemount X-STREAM enhanced XEFD \u2013 all versions<\/li>\n\t<li>Rosemount X-STREAM enhanced XEXF \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to download files and obtain sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>Emerson Cyber Security Notification (EMR.RMT20003-2)<br \/><a href=\"https:\/\/www.emerson.com\/documents\/automation\/xstream-notification-researcher-response-r1-en-7238504.pdf\">https:\/\/www.emerson.com\/documents\/automation\/xstream-notification-researcher-response-r1-en-7238504.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-3","alert_type":398,"serial_number":"AV20-483","subject":null,"moderation_state":"published","external_url":null},{"nid":2228,"title":"[Control systems] Treck security advisory","uuid":"7a65a9a1-6cf0-47b1-872a-6053716026ef","banner":null,"lang":"en","date_modified":"2020-12-21","date_modified_ts":"2020-12-21T19:59:01Z","date_created":"2020-12-21T19:59:01Z","summary":null,"body":["<article data-history-node-id=\"2228\" about=\"\/en\/alerts-advisories\/control-systems-treck-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-484<br \/>\nDate: 21 December 2020<\/strong><\/p>\n\n<p>On 18 December 2020 ICS-CERT published Security Advisories to highlight vulnerabilities affecting the following product:<\/p>\n\n<ul><li>Treck TCP\/IP stack - version 6.0.1.67 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an unauthenticated actor to cause a denial-of-service, remotely execute code or obtain sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>Treck TCP\/IP Stack (ICSA-20-353-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-353-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-353-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-treck-security-advisory-0","alert_type":398,"serial_number":"AV20-484","subject":null,"moderation_state":"published","external_url":null},{"nid":2229,"title":"IBM security advisory","uuid":"59b7af15-3fb1-4681-b417-04a59576b70d","banner":null,"lang":"en","date_modified":"2020-12-21","date_modified_ts":"2020-12-21T20:22:30Z","date_created":"2020-12-21T20:22:30Z","summary":null,"body":["<article data-history-node-id=\"2229\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-485<br \/>\nDate: 21 December 2020<\/strong><\/p>\n\n<p>Between 14 and 20 December 2020 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Netezza for Cloud Pak for Data - all versions<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Infrastructure Management - versions 2.0 and 2.1<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management - version 2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Netezza for Cloud Pak for Data\u00a0<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-open-source-security-issues-for-nps-console\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-open-source-security-issues-for-nps-console\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-oss-scan-fixes-for-content-pos\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-oss-scan-fixes-for-content-pos\/<\/a><\/p>\n\n<p>IBM Cloud Pak for Multicloud Management Infrastructure Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-node-forge-module-affects-ibm-cloud-pak-for-multicloud-management-managed-service\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-node-forge-module-affects-ibm-cloud-pak-for-multicloud-management-managed-service\/<\/a><\/p>\n\n<p>IBM Cloud Pak for Multicloud Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-serialize-javascript-affects-ibm-cloud-pak-for-multicloud-management-managed-service-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-serialize-javascript-affects-ibm-cloud-pak-for-multicloud-management-managed-service-2\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-jison-affects-ibm-cloud-pak-for-multicloud-management-managed-service-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-in-node-js-jison-affects-ibm-cloud-pak-for-multicloud-management-managed-service-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-30","alert_type":396,"serial_number":"AV20-485","subject":null,"moderation_state":"published","external_url":null},{"nid":2230,"title":"[Control systems] Schneider Electric security advisory","uuid":"808b6a53-7a50-408e-ab31-20d14a6ddd3a","banner":null,"lang":"en","date_modified":"2020-12-22","date_modified_ts":"2020-12-22T14:02:54Z","date_created":"2020-12-22T14:02:54Z","summary":null,"body":["<article data-history-node-id=\"2230\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV20-486<br \/>\nDate: 22 December 2020<\/strong><\/p>\n\n<p>On 18 December 2020 Schneider Electric published Security Notifications to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acti9 \u2013 multiple versions and platforms<\/li>\n\t<li>APC Network Management Card 2 (NMC2)<\/li>\n\t<li>APC Network Management Card 3 (NMC3)<\/li>\n\t<li>ATV340E Altivar Machine Drives<\/li>\n\t<li>ATV Altivar Process Drives \u2013 multiple versions and platforms<\/li>\n\t<li>EGX150\/Link150 Ethernet Gateway<\/li>\n\t<li>eIFE \u2013 multiple versions and platforms<\/li>\n\t<li>IFE \u2013 multiple versions and platforms<\/li>\n\t<li>TM3 Bus Coupler \u2013 multiple versions and platforms<\/li>\n\t<li>VW3A3720, VW3A3721 Altivar Process Communication Modules<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-13","alert_type":398,"serial_number":"AV20-486","subject":null,"moderation_state":"published","external_url":null},{"nid":2231,"title":"Recommendations for SolarWinds Supply-Chain Compromise - update 1","uuid":"6e97333b-e858-4fa1-bc1b-7b9d82056788","banner":null,"lang":"en","date_modified":"2020-12-30","date_modified_ts":"2020-12-30T13:52:31Z","date_created":"2020-12-24T14:57:54Z","summary":null,"body":["<article data-history-node-id=\"2231\" about=\"\/en\/alerts-advisories\/recommendations-solarwinds-supply-chain-compromise\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL20-031<\/strong>\u00a0<strong>UPDATE 1\n  <br \/>\n  Date:\u00a030 December 2020<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>OVERVIEW\n<\/h3>\n<p>On 13 December 2020 SolarWinds disclosed recent malicious activity impacting the SolarWinds Orion Platform [<a href=\"https:\/\/www.solarwinds.com\/securityadvisory\">1<\/a>] and affecting high-profile clients including FireEye and the U.S. Government. This activity was enabled by a supply chain compromise of the product carried out by a highly sophisticated threat actor. It is believed that government agencies and a variety of organizations in Canada and abroad may be affected.\n<\/p>\n<h3 align=\"JUSTIFY\" dir=\"LTR\">UPDATE\n<\/h3>\n<p align=\"JUSTIFY\" dir=\"LTR\"><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">On 26 December 2020 the Computer Emergency Response Team Coordination Center (CERT\/CC) issued an advisory describing a vulnerability in the SolarWinds Orion application programming interface (API). In addition, the Cyber Centre would like to highlight SolarWinds\u2019 list of Orion versions affected by SUNBURST and SUPERNOVA. Please refer to the SUPERNOVA Backdoor section of this Alert for details.<\/span>\n<\/p>\n<h3>DETAILS\n<\/h3>\n<p>On 13 December 2020 SolarWinds disclosed a vulnerability in its SolarWinds Orion software that had been linked to detected malicious activity. [<a href=\"https:\/\/www.solarwinds.com\/securityadvisory\">1<\/a>] On the same day, open-source reporting indicated that the U.S. Treasury Department and possible other U.S. Government Departments had been compromised. Cyber security research firm FireEye also reported that it had been compromised. [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\">2<\/a>]\n<\/p>\n<p>FireEye reported it had discovered a global intrusion campaign resulting from a supply chain compromise. Through trojanizing SolarWinds Orion Platform software updates, actors were able to distribute malware. This campaign may have begun as early as Spring 2020 and FireEye reports it is currently ongoing. Post-compromise activity leverages multiple techniques to evade detection and obscure malicious actions, including lateral movement and data theft.\n<\/p>\n<p>As the cyber security community continues to analyze the activity, additional information has been emerging relevant to detection and remediation. The Cyber Centre is publishing this Alert to provide guidance based on our analysis, engagement and further discussions with the Canadian government, industry, and our international partners. Through those engagements the Cyber Center has received reports that Domain Generation Algorithm (DGA) subdomains associated with this activity are unique to each compromise. The Cyber Centre has been working within the community to identify affected systems and notified Canadian system owners where possible. The impact on these compromised systems remains unidentified, but analysis is ongoing.\n<\/p>\n<h3>RECOMMENDATIONS\n<\/h3>\n<p>The SolarWinds Orion vulnerability and associated compromises are far reaching, and it is important that organizations perform thorough analysis of their networks to ensure the malicious actors have been removed from both the initial point of compromise and any systems potentially impacted. The Cyber Centre recommends users of SolarWinds Orion software to follow the Detection and Mitigation steps as provided below to determine potential impact to their networks. The Cyber Centre strongly encourages organizations to follow their own risk-based assessments on remediation and recovery.\n<\/p>\n<h3>DETECTION\n<\/h3>\n<p>Organizations should first identify any systems with compromised SolarWinds Orion software and isolate them from the Internet immediately. SolarWinds has identified the below versions as compromised:\n<\/p>\n<ul><li>Platform 2019.4 HF5, version 2019.4.5200.9083;<\/li>\n  <li>Platform 2020.2 RC1, version 2020.2.100.12219;<\/li>\n  <li>Platform 2020.2 RC2, version 2020.2.5200.12394;<\/li>\n  <li>Platform 2020.2, 2020.2 HF1, version 2020.2.5300.12432<\/li>\n<\/ul><p>In addition, systems which have, at any time, run one of the compromised SolarWinds versions listed above should also be isolated from the Internet immediately and investigated for signs of compromise.\n<\/p>\n<p>It is recommended that organizations continue monitoring SolarWinds Orion system(s) or systems to which they had access, for anomalous activity. Examples of anomalous activity include, but are not limited to, the below MITRE ATT&amp;CK\u00ae framework techniques that the threat actor has engaged in as reported by CISA Alert (AA20-352A).[<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\">3<\/a>]\n<\/p>\n<ul><li>Query Registry [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1012\/\">T1012<\/a>]<\/li>\n  <li>Obfuscated Files or Information [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1027\/\">T1027<\/a>]<\/li>\n  <li>Obfuscated Files or Information: Steganography [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1027\/003\">T1027.003<\/a>]<\/li>\n  <li>Process Discovery [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1057\/\">T1057<\/a>]<\/li>\n  <li>Indicator Removal on Host: File Deletion [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1070\/004\">T1070.004<\/a>]<\/li>\n  <li>Application Layer Protocol: Web Protocols [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1071\/001\">T1071.001<\/a>]<\/li>\n  <li>Application Layer Protocol: DNS [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1071\/004\">T1071.004<\/a>]<\/li>\n  <li>File and Directory Discovery [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1083\/\">T1083<\/a>]<\/li>\n  <li>Ingress Tool Transfer [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1105\/\">T1105<\/a>]<\/li>\n  <li>Data Encoding: Standard Encoding [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1132\/001\">T1132.001<\/a>]<\/li>\n  <li>Supply Chain Compromise: Compromise Software Dependencies and Development Tools [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1195\/001\">T1195.001<\/a>]<\/li>\n  <li>Supply Chain Compromise: Compromise Software Supply Chain [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1195\/002\">T1195.002<\/a>]<\/li>\n  <li>Software Discovery [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1518\/\">T1518<\/a>]<\/li>\n  <li>Software Discovery: Security Software [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1518\/001\">T1518.001<\/a>]<\/li>\n  <li>Create or Modify System Process: Windows Service [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1543\/003\">T1543.003<\/a>]<\/li>\n  <li>Subvert Trust Controls: Code Signing [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1553\/002\">T1553.002<\/a>]<\/li>\n  <li>Dynamic Resolution: Domain Generation Algorithms [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1568\/002\">T1568.002<\/a>]<\/li>\n  <li>System Services: Service Execution [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1569\/002\">T1569.002<\/a>]<\/li>\n  <li>Compromise Infrastructure [<a href=\"https:\/\/attack.mitre.org\/versions\/v8\/techniques\/T1584\/\">T1584<\/a>]<\/li>\n<\/ul><p>In addition, Microsoft has reported attempts by actors to gain long-term persistence using compromised accounts, or by forging Security Assertion Markup Language (SAML) tokens. Microsoft has reported four main takeaways of which these three outline post-compromise activities resulting from SAML abuse. [<a href=\"https:\/\/msrc-blog.microsoft.com\/2020\/12\/13\/customer-guidance-on-recent-nation-state-cyber-attacks\/\">4<\/a>]\n<\/p>\n<ul><li>Once in the network, the intruder then uses the administrative permissions acquired through the on-premises compromise to gain access to the organization\u2019s global administrator account and\/or trusted SAML token signing certificate. This enables the actor to forge SAML tokens that impersonate any of the organization\u2019s existing users and accounts, including highly privileged accounts.<\/li>\n  <li>Anomalous logins using the SAML tokens created by the compromised token signing certificate can then be made against any on-premises resources (regardless of identity system or vendor) as well as to any cloud environment (regardless of vendor) because they have been configured to trust the certificate. Because the SAML tokens are signed with their own trusted certificate, the anomalies might be missed by the organization.<\/li>\n  <li>Using the global administrator account and\/or the trusted certificate to impersonate highly privileged accounts, the actor may add their own credentials to existing applications or service principals, enabling them to call APIs with the permission assigned to that application.<\/li>\n<\/ul><h3>MITIGATION\n<\/h3>\n<p>The Cyber Centre recommends the following graduated compromise scenarios for operators to determine potential response options. The mitigation responses are divided into four scenarios based the determination of impact:\n<\/p>\n<ul><li>Verify if the identified compromised SolarWinds Orion system has the following:\n    <ul><li>A malicious variant of the file: \u201csolarwinds.orion.core.businesslayer.dll\u201d (hash values available from <a href=\"https:\/\/github.com\/fireeye\/sunburst_countermeasures\/blob\/main\/indicator_release\/Indicator_Release_Hashes.csv\">https:\/\/github.com\/fireeye\/sunburst_countermeasures\/blob\/main\/indicator_release\/Indicator_Release_Hashes.csv<\/a>), otherwise known as the SUNBURST backdoor is present; and<\/li>\n      <li>the capability to resolve Internet reachable addresses from the host is possible.<\/li>\n    <\/ul><\/li>\n<\/ul><p>Based on the presence of this file, one the following four mitigation solutions are recommended:\n<\/p>\n<p>Scenario 1 - If the system did not have the affected version which contained the SUNBURST backdoor, perform the following mitigations:\n<\/p>\n<ul><li>Patch to the latest recommended version by vendor<\/li>\n  <li>Follow recommended industry best practices for hardening of enterprise systems<\/li>\n  <li>Re-introduce system to enterprise environment after performing a thorough risk evaluation<\/li>\n<\/ul><p>Scenario 2 - If the system has the SUNBURST backdoor but did not have the ability to connect to the Internet, then malicious SUNBURST code was unable to reach malicious hosts, perform the following mitigations:\n<\/p>\n<ul><li>Continue isolation of system and rebuild SolarWinds Orion using the latest recommended versions by vendor<\/li>\n  <li>Follow recommended industry best practices for hardening of enterprise systems<\/li>\n  <li>Re-introduce system to enterprise environment after performing a thorough risk evaluation<\/li>\n<\/ul><p>Scenario 3 - If the SUNBURST backdoor is found and\/or following review of network activity, the system is found to have resolved a subdomain of avsvmcloud[.]com, perform the following mitigations:\n<\/p>\n<ul><li>Begin incident response procedures for system compromise;<\/li>\n  <li>Follow detailed remediation support guidance in references below [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\"><font color=\"#0066cc\">2<\/font><\/a>] [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\"><font color=\"#0066cc\">3<\/font><\/a>] [<a href=\"https:\/\/msrc-blog.microsoft.com\/2020\/12\/21\/december-21st-2020-solorigate-resource-center\/\">5<\/a>]<\/li>\n<\/ul><p>Scenario 4 - If the SUNBURST backdoor is found and following a review of network activity, the system is found to have resolved a subdomain of avsvmcloud[.]com as well as additional hosts and IP addresses associated with SUNBURST indicators of compromise provided below, perform the following mitigations:\n<\/p>\n<ul><li>Assume any systems and credentials associated with the Orion platform as potentially compromised;<\/li>\n  <li>Implement incident response options within the affected network(s) using the MITRE ATT&amp;CK\u00ae framework above to identify anomalous activity;<\/li>\n  <li>Follow detailed remediation support guidance in references below [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\"><font color=\"#0066cc\">2<\/font><\/a>] [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\"><font color=\"#0066cc\">3<\/font><\/a>] [<a href=\"https:\/\/msrc-blog.microsoft.com\/2020\/12\/21\/december-21st-2020-solorigate-resource-center\/\"><font color=\"#0066cc\">5<\/font><\/a>]<\/li>\n<\/ul><h3>INDICATORS OF COMPROMISE\n<\/h3>\n<p>Several partners and industry leaders for this incident are providing repositories for information related to this activity. The Cyber Centre recommends that organizations continue to review these sources for updates and recommendations to best defend their networks, host-based systems, and potential response options to compromise.\n<\/p>\n<p>FireEye SUNBURST\n  <br \/><a href=\"https:\/\/github.com\/fireeye\/sunburst_countermeasures\">https:\/\/github.com\/fireeye\/sunburst_countermeasures<\/a>\n<\/p>\n<p>Solorigate Resource Center\n  <br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2020\/12\/21\/december-21st-2020-solorigate-resource-center\/\">https:\/\/msrc-blog.microsoft.com\/2020\/12\/21\/december-21st-2020-solorigate-resource-center\/<\/a>\n<\/p>\n<p>Dark Halo Leverages SolarWinds Compromise to Breach Organizations\n  <br \/><a href=\"https:\/\/www.volexity.com\/blog\/2020\/12\/14\/dark-halo-leverages-solarwinds-compromise-to-breach-organizations\/\">https:\/\/www.volexity.com\/blog\/2020\/12\/14\/dark-halo-leverages-solarwinds-compromise-to-breach-organizations\/<\/a>\n<\/p>\n<h3>SUPPLEMENTAL ANALYSIS\n<\/h3>\n<h4>Additional precautions\n<\/h4>\n<p>Whether or not an active compromise is detected, the Cyber Centre recommends that administrators reset the credentials of any system which are presently used to authenticate with a SolarWinds Orion server. If the adversary has compromised administrative-level credentials, it may not be sufficient to simply mitigate individual issues, systems, servers, or specific user accounts to remove the malicious actor from the network. In such cases, based on the sophistication of the threat actor involved, organizations should consider the entire identity trust-store to be compromised. A full rebuild of the identity trust-store and environment is the safest action [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\"><font color=\"#0066cc\">3<\/font><\/a>].\n<\/p>\n<p>As technical analysis is performed and indicators of compromise are discovered, new exploit mechanisms may emerge. The Cyber Center encourages organizations to review the references enclosed with this Alert, which will most often include these important updates.\n<\/p>\n<h4><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\"><\/span>\n<\/h4>\n<h4 align=\"LEFT\" dir=\"LTR\"><strong><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">SUPERNOVA Backdoor<\/span><\/strong>\n<\/h4>\n<p>On 17 December Palo Alto Networks Unit 42 published a report which outlined a new method of exploitation involving a backdoor named SUPERNOVA located within a DLL file named App_Web_logoimagehandler.ashx.b6031896.dll. Both Unit 42 and Microsoft have concluded that this webshell could not be verified as being leveraged by the same sophisticated actors as SUNBURST but may have resulted from a separate malicious actor. [<a href=\"https:\/\/unit42.paloaltonetworks.com\/solarstorm-supernova\/\">6<\/a>] [<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/12\/18\/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect\/\">7<\/a>]\n<\/p>\n<p>While the Cyber Centre has not observed this activity, Microsoft indicates that the malicious code \u201cprovides an attacker the ability to send and execute any arbitrary C# program on the victim\u2019s device\u201d. Methods of detection are limited due the vulnerability being an in-memory webshell, compiled on the fly and executed dynamically. Unit 42 has published a detailed analysis of the malicious code as well as potential methods of detection. [<a href=\"https:\/\/unit42.paloaltonetworks.com\/solarstorm-supernova\/\">6<\/a>]\n<\/p>\n<p><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\"><\/span>\n<\/p>\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">On 26 December 2020 CERT\/CC issued an advisory highlighting a vulnerability in SolarWinds Orion which allows an unauthenticated remote actor to execute application programming interface (API) commands. Tracked as CVE-2020-10148, this vulnerability is rectified by updates addressing the SUPERNOVA malware. [<a href=\"https:\/\/kb.cert.org\/vuls\/id\/843464\">8<\/a>] <\/span>[<a href=\"https:\/\/www.solarwinds.com\/securityadvisory\"><font color=\"#0066cc\">1<\/font><\/a>]\n<\/p>\n<p><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\"> <\/span>\n<\/p>\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">The Cyber Centre would also like to highlight that numerous SolarWinds Orion platform versions, while not affected by SUNBURST, are affected by SUPERNOVA. SolarWinds has compiled a list of Orion versions affected by SUNBURST and SUPERNOVA in its advisory.<\/span>\u00a0[<a href=\"https:\/\/www.solarwinds.com\/securityadvisory\"><font color=\"#0066cc\">1<\/font><\/a>]\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>[1] SolarWinds Security Advisory\n  <br \/><a href=\"https:\/\/www.solarwinds.com\/securityadvisory\">https:\/\/www.solarwinds.com\/securityadvisory<\/a>\n<\/p>\n<p>[2] Highly Evasive Attacker Leverages SolarWinds Supply Chain\n  <br \/><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/12\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html<\/a>\n<\/p>\n<p>[3] CISA Alert (AA20-352A)\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a<\/a>\n<\/p>\n<p>[4] Customer Guidance on Recent Nation-State Cyber Attacks\n  <br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2020\/12\/13\/customer-guidance-on-recent-nation-state-cyber-attacks\/\">https:\/\/msrc-blog.microsoft.com\/2020\/12\/13\/customer-guidance-on-recent-nation-state-cyber-attacks\/<\/a>\n<\/p>\n<p>[5] Solorigate Resource Center\n  <br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2020\/12\/21\/december-21st-2020-solorigate-resource-center\/\">https:\/\/msrc-blog.microsoft.com\/2020\/12\/21\/december-21st-2020-solorigate-resource-center\/<\/a>\n<\/p>\n<p>[6] SUPERNOVA: A Novel .NET Webshell\n  <br \/><a href=\"https:\/\/unit42.paloaltonetworks.com\/solarstorm-supernova\/\">https:\/\/unit42.paloaltonetworks.com\/solarstorm-supernova\/<\/a>\n<\/p>\n<p>[7] Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers\n  <br \/><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/12\/18\/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect\/\">https:\/\/www.microsoft.com\/security\/blog\/2020\/12\/18\/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect\/<\/a>\n<\/p>\n<p>[8] CERT\/CC Vulnerability Note VU#843464\n  <br \/><a href=\"https:\/\/kb.cert.org\/vuls\/id\/843464\">https:\/\/kb.cert.org\/vuls\/id\/843464<\/a>\n<\/p>\n<p>Should organizations identify activity like that described in this Alert, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<p>\n  <br \/><strong>NOTE TO READERS<\/strong>\n  <br \/><br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses, and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/recommendations-solarwinds-supply-chain-compromise","alert_type":397,"serial_number":"AL20-031","subject":null,"moderation_state":"published","external_url":null},{"nid":2232,"title":"IBM security advisory","uuid":"f80f60c9-0fdb-47c5-a6fc-7a94a1ba9dc3","banner":null,"lang":"en","date_modified":"2020-12-30","date_modified_ts":"2020-12-30T14:33:31Z","date_created":"2020-12-30T14:25:53Z","summary":null,"body":["<article data-history-node-id=\"2232\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p dir=\"LTR\"><strong>Number: AV20-487<br \/>\nDate:\u00a030 December 2020<\/strong><\/p>\n\n<p dir=\"LTR\">Between 21 and 27 December 2020 IBM published a Security Bulletin to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>IBM MQ \u2013 versions 9.2 CD and 9.2 LDS<\/li>\n<\/ul><p dir=\"LTR\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p dir=\"LTR\">IBM MQ<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-mq-is-affected-by-a-vulnerability-in-eclipse-jetty-cve-2019-17638\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-mq-is-affected-by-a-vulnerability-in-eclipse-jetty-cve-2019-17638\/<\/a><\/p>\n\n<p dir=\"LTR\">IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p dir=\"LTR\"><strong>Note to Readers<\/strong><\/p>\n\n<p dir=\"LTR\">The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-31","alert_type":396,"serial_number":"AV20-487","subject":null,"moderation_state":"published","external_url":null},{"nid":2233,"title":"Android security advisory \u2013 January 2021 monthly rollup","uuid":"06379555-950e-4010-b2cd-d697e10cb8a2","banner":null,"lang":"en","date_modified":"2021-01-04","date_modified_ts":"2021-01-04T20:45:10Z","date_created":"2021-01-04T20:45:10Z","summary":null,"body":["<article data-history-node-id=\"2233\" about=\"\/en\/alerts-advisories\/android-security-advisory-january-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-001<br \/>\nDate: 4 January 2021<\/strong><\/p>\n\n<p>On 4 January 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-01-01\">https:\/\/source.android.com\/security\/bulletin\/2021-01-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-january-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-001","subject":null,"moderation_state":"published","external_url":null},{"nid":2234,"title":"[Control systems] Panasonic security advisory","uuid":"2eb0f3b0-ec3c-4dd0-8074-d76982aea6af","banner":null,"lang":"en","date_modified":"2021-01-06","date_modified_ts":"2021-01-06T14:55:57Z","date_created":"2021-01-06T14:52:26Z","summary":null,"body":["<article data-history-node-id=\"2234\" about=\"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-002<br \/>\nDate:\u00a06 January 2021<\/strong><\/p>\n\n<p>On 5 January 2021 ICS-CERT published an advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Panasonic FPWIN Pro - version 7.5.0.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-005-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory","alert_type":398,"serial_number":"AV21-002","subject":null,"moderation_state":"published","external_url":null},{"nid":2235,"title":"[Control systems] Red Lion security advisory","uuid":"2490c16b-46bd-4447-bb7e-051a4d706580","banner":null,"lang":"en","date_modified":"2021-01-06","date_modified_ts":"2021-01-06T14:58:23Z","date_created":"2021-01-06T14:58:23Z","summary":null,"body":["<article data-history-node-id=\"2235\" about=\"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-003<br \/>\nDate:\u00a06 January 2021<\/strong><\/p>\n\n<p>On 5 January 2021 ICS-CERT published an advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Crimson 3.1 - build versions prior to 3119.001<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to create a denial-of-service condition, read and modify the database, and leak memory data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-005-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory-0","alert_type":398,"serial_number":"AV21-003","subject":null,"moderation_state":"published","external_url":null},{"nid":2236,"title":"[Control systems] Delta Electronics security advisory","uuid":"9d87b1f3-866c-48f5-9233-eccb631a96cc","banner":null,"lang":"en","date_modified":"2021-01-06","date_modified_ts":"2021-01-06T15:08:46Z","date_created":"2021-01-06T15:08:46Z","summary":null,"body":["<article data-history-node-id=\"2236\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-004<br \/>\nDate: 6 January 2021<\/strong><\/p>\n\n<p>On 5 January 2021 ICS-CERT published advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>DOPSoft - version 4.0.8.21 and prior<\/li>\n\t<li>CNCSoft ScreenEditor - versions 1.01.26 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-005-05)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-05<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-005-06)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-06\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-06<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-2","alert_type":398,"serial_number":"AV21-004","subject":null,"moderation_state":"published","external_url":null},{"nid":2237,"title":"[Control systems] GE security advisory","uuid":"89d026d1-a4b4-4271-a89f-54af1d08ae2d","banner":null,"lang":"en","date_modified":"2021-01-06","date_modified_ts":"2021-01-06T15:19:25Z","date_created":"2021-01-06T15:19:25Z","summary":null,"body":["<article data-history-node-id=\"2237\" about=\"\/en\/alerts-advisories\/control-systems-ge-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-005<br \/>\nDate: 6 January 2021<\/strong><\/p>\n\n<p>On 5 January 2021 ICS-CERT published an advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Reason RT430, RT431 and RT434 Clocks - firmware versions prior to version 08A06<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an authenticated remote actor to execute arbitrary code on the system or intercept and decrypt encrypted traffic.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-005-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-005-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-security-advisory-1","alert_type":398,"serial_number":"AV21-005","subject":null,"moderation_state":"published","external_url":null},{"nid":2238,"title":"Fortinet security advisory","uuid":"b99cf57e-7c2d-4e43-bc7c-91db8733c98b","banner":null,"lang":"en","date_modified":"2021-01-06","date_modified_ts":"2021-01-06T18:57:41Z","date_created":"2021-01-06T18:57:41Z","summary":null,"body":["<article data-history-node-id=\"2238\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-006<br \/>\nDate: 6 January 2021<\/strong><\/p>\n\n<p>On 4 January 2021 Fortinet published multiple advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FortiGate - multiple versions<\/li>\n\t<li>FortiWeb - multiple versions<\/li>\n\t<li>FortiDeceptor - multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Fortinet PSIRT Advisories<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-6","alert_type":396,"serial_number":"AV21-006","subject":null,"moderation_state":"published","external_url":null},{"nid":2239,"title":"Mozilla security advisory","uuid":"35ae0795-5c9c-49e2-a2fd-04807377c754","banner":null,"lang":"en","date_modified":"2021-01-07","date_modified_ts":"2021-01-07T15:07:41Z","date_created":"2021-01-07T14:55:42Z","summary":null,"body":["<article data-history-node-id=\"2239\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-007<br \/>\nDate:\u00a07 January 2021<\/strong><\/p>\n\n<p>On 6 January 2021 Mozilla published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 84.0.2<\/li>\n\t<li>Firefox for Android \u2013 versions prior to 84.1.3<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\nMozilla Security Advisory (MFSA 2021-01)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-01\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-01\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-28","alert_type":396,"serial_number":"AV21-007","subject":null,"moderation_state":"published","external_url":null},{"nid":2240,"title":"Google Chrome security advisory","uuid":"8873cf19-7321-444b-8fb4-e67fb05c8ec5","banner":null,"lang":"en","date_modified":"2021-01-07","date_modified_ts":"2021-01-07T17:07:57Z","date_created":"2021-01-07T17:07:57Z","summary":null,"body":["<article data-history-node-id=\"2240\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-42\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-008<br \/>\nDate: 7 January 2021<\/strong><\/p>\n\n<p>On 6 January 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 87.0.4280.141<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/01\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/01\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-42","alert_type":396,"serial_number":"AV21-008","subject":null,"moderation_state":"published","external_url":null},{"nid":2241,"title":"[Control systems] Delta Electronics security advisory","uuid":"ca6ebc0b-708e-4f3f-a037-b10ebfdf8b91","banner":null,"lang":"en","date_modified":"2021-01-07","date_modified_ts":"2021-01-07T20:03:01Z","date_created":"2021-01-07T20:03:01Z","summary":null,"body":["<article data-history-node-id=\"2241\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-009<br \/>\nDate: 7 January 2021<\/strong><\/p>\n\n<p>On 7 January 2021 ICS-CERT published an advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>CNCSoft-B - versions 1.0.0.2 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-007-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-007-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-007-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-3","alert_type":398,"serial_number":"AV21-009","subject":null,"moderation_state":"published","external_url":null},{"nid":2242,"title":"[Control systems] Eaton security advisory","uuid":"2c4d9eec-ca83-4165-8619-fbc2289a09d9","banner":null,"lang":"en","date_modified":"2021-01-08","date_modified_ts":"2021-01-08T14:56:32Z","date_created":"2021-01-08T14:56:32Z","summary":null,"body":["<article data-history-node-id=\"2242\" about=\"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-010<br \/>\nDate:\u00a08 January 2021<\/strong><\/p>\n\n<p>On 7 January 2021 ICS-CERT published an advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>EASYsoft - versions 7.20 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a local actor to modify or crash the program.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-007-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-007-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-007-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-1","alert_type":398,"serial_number":"AV21-010","subject":null,"moderation_state":"published","external_url":null},{"nid":2243,"title":"[Control systems] Omron security advisory","uuid":"29b5d37a-a345-4e85-809f-bfc2993ca909","banner":null,"lang":"en","date_modified":"2021-01-08","date_modified_ts":"2021-01-08T15:03:59Z","date_created":"2021-01-08T15:03:59Z","summary":null,"body":["<article data-history-node-id=\"2243\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-011<br \/>\nDate: 8 January 2021<\/strong><\/p>\n\n<p>On 7 January 2021 ICS-CERT published an advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>CX-One - versions 4.60 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial-of-service condition or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-007-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-007-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-007-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-2","alert_type":398,"serial_number":"AV21-011","subject":null,"moderation_state":"published","external_url":null},{"nid":2244,"title":"[Control systems] Innokas Yhtym\u00e4 Oy security advisory","uuid":"7c5d31b9-d988-4108-8be2-c65381ff7c06","banner":null,"lang":"en","date_modified":"2021-01-08","date_modified_ts":"2021-01-08T15:10:53Z","date_created":"2021-01-08T15:10:53Z","summary":null,"body":["<article data-history-node-id=\"2244\" about=\"\/en\/alerts-advisories\/control-systems-innokas-yhtyma-oy-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-012<br \/>\nDate: 8 January 2021<\/strong><\/p>\n\n<p>On 7 January 2021 ICS-CERT published an advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Vital Signs Monitor VC150 - versions prior to 1.7.15<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to modify communications between downstream devices or cause some features of the affected devices to become disabled.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-007-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-007-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-007-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-innokas-yhtyma-oy-security-advisory","alert_type":398,"serial_number":"AV21-012","subject":null,"moderation_state":"published","external_url":null},{"nid":2245,"title":"IBM security advisory","uuid":"5a644b5d-0983-4116-8e76-a5b1a10a206d","banner":null,"lang":"en","date_modified":"2021-01-11","date_modified_ts":"2021-01-11T17:14:37Z","date_created":"2021-01-11T17:14:37Z","summary":null,"body":["<article data-history-node-id=\"2245\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-013<br \/>\nDate: 11 January 2021<\/strong><\/p>\n\n<p>Between 4 and 10 January 2021 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Cloud Event Management on IBM Cloud Private \u2013 all versions<\/li>\n\t<li>Spectrum Discover \u2013 versions prior to 2.0.3<\/li>\n\t<li>IBM Event Streams \u2013 multiple versions<\/li>\n\t<li>IBM Blockchain Platform \u2013 all versions<\/li>\n\t<li>IBM Aspera High-Speed Transfer Server\/Endpoint - versions 3.9.6.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Cloud Event Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-version-6-4-6-of-node-js-module-nodemailer-included-in-ibm-netcool-operations-insight-1-6-2-x-has-a-security-vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-version-6-4-6-of-node-js-module-nodemailer-included-in-ibm-netcool-operations-insight-1-6-2-x-has-a-security-vulnerability\/<\/a><\/p>\n\n<p>Spectrum Discover<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-spectrum-discover-has-addressed-multiple-security-vulnerabilities-cve-2020-13401-cve-2019-20372\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-spectrum-discover-has-addressed-multiple-security-vulnerabilities-cve-2020-13401-cve-2019-20372\/<\/a><\/p>\n\n<p>IBM Event Streams<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-event-streams-is-affected-by-multiple-go-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-event-streams-is-affected-by-multiple-go-vulnerabilities\/<\/a><\/p>\n\n<p>IBM Blockchain<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-upgrade-to-ibp-v2-5-1-to-address-recent-concerns-issues-with-golang-versions-other-than-1-14-12\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-upgrade-to-ibp-v2-5-1-to-address-recent-concerns-issues-with-golang-versions-other-than-1-14-12\/<\/a><\/p>\n\n<p>IBM Aspera<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-jackson-databind-vulnerability-cve-2020-35728-impacts-ibm-aspera-high-speed-transfer-server-and-aspera-high-speed-transfer-endpoint-versions-prior-to-v4-0\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-jackson-databind-vulnerability-cve-2020-35728-impacts-ibm-aspera-high-speed-transfer-server-and-aspera-high-speed-transfer-endpoint-versions-prior-to-v4-0\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-32","alert_type":396,"serial_number":"AV21-013","subject":null,"moderation_state":"published","external_url":null},{"nid":2246,"title":"Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments (CISA)","uuid":"f78bc253-7d5f-47ab-964a-e1cd2db797e6","banner":null,"lang":"en","date_modified":"2021-01-11","date_modified_ts":"2021-01-11T18:42:15Z","date_created":"2021-01-11T18:42:15Z","summary":null,"body":["<article data-history-node-id=\"2246\" about=\"\/en\/alerts-advisories\/detecting-post-compromise-threat-activity-microsoft-cloud-environments-cisa\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-001<br \/>\nDate: 11 January 2021<\/strong><\/p>\n\n<h3>AUDIENCE<\/h3>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h3>PURPOSE<\/h3>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h3>OVERVIEW<\/h3>\n\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Alert [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-008a\">1<\/a>] containing additional information about recent APT activity targeting organizations\u2019 cloud environments.<\/p>\n\n<h3>DETAILS<\/h3>\n\n<p>On 8 January 2021 CISA, the United States\u2019 agency responsible for protecting its critical infrastructure from physical and cyber threats, published Alert AA21-008A [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-008a\">1<\/a>] containing additional information about recent APT activity targeting organizations\u2019 cloud environments. It is a companion product to the previously issued Alert AA20-352A [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\">2<\/a>], which focused on SolarWinds Orion software as the vector.<\/p>\n\n<p>AA21-008A describes additional methods of compromise, including techniques for lateral movement, being leveraged by a sophisticated threat actor. It provides tools and guidance on detecting this activity in organizations\u2019 cloud environments and remediation of post-compromise activities.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n\n<h3>REFERENCES<\/h3>\n\n<p>[1] CISA Alert AA21-008A<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-008a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-008a<\/a><\/p>\n\n<p>[2] CISA Alert AA20-352A<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/detecting-post-compromise-threat-activity-microsoft-cloud-environments-cisa","alert_type":397,"serial_number":"AL21-001","subject":null,"moderation_state":"published","external_url":null},{"nid":2247,"title":"PHP security advisory","uuid":"deb5f62e-a906-4001-8eb6-1abc0b96efcf","banner":null,"lang":"en","date_modified":"2021-01-11","date_modified_ts":"2021-01-11T19:45:32Z","date_created":"2021-01-11T19:30:13Z","summary":null,"body":["<article data-history-node-id=\"2247\" about=\"\/en\/alerts-advisories\/php-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-014<br \/>\nDate: 11 January 2021<\/strong><\/p>\n\n<p>On 8 January 2021 PHP published ChangeLogs to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0PHP 7.3 \u2013 versions 7.3.25 and prior<\/li>\n\t<li>\u00a0PHP 7.4 \u2013 versions 7.4.13 and prior<\/li>\n\t<li>\u00a0PHP 8.0 \u2013 versions 8.0.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>PHP ChangeLog 7<br \/><a href=\"https:\/\/www.php.net\/ChangeLog-7.php#PHP_7_3\">https:\/\/www.php.net\/ChangeLog-7.php#PHP_7_3<\/a><br \/><a href=\"https:\/\/www.php.net\/ChangeLog-7.php#PHP_7_4\">https:\/\/www.php.net\/ChangeLog-7.php#PHP_7_4<\/a><\/p>\n\n<p>PHP ChangeLog 8<br \/><a href=\"https:\/\/www.php.net\/ChangeLog-8.php#PHP_8_0\">https:\/\/www.php.net\/ChangeLog-8.php#PHP_8_0<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-security-advisory-1","alert_type":396,"serial_number":"AV21-014","subject":null,"moderation_state":"published","external_url":null},{"nid":2248,"title":"Mozilla security advisory","uuid":"bfc0d968-75dd-465f-87d7-eef101054f8a","banner":null,"lang":"en","date_modified":"2021-01-11","date_modified_ts":"2021-01-11T19:48:37Z","date_created":"2021-01-11T19:48:37Z","summary":null,"body":["<article data-history-node-id=\"2248\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-015<br \/>\nDate: 11 January 2021<\/strong><\/p>\n\n<p>On 11 January 2021 Mozilla published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>\u00a0Thunderbird \u2013 versions prior to 78.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Mozilla Security Advisory (MFSA 2021-02)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-02\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-02\/<\/a><\/p>\n\n<p>Mozilla Security Advisories<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-29","alert_type":396,"serial_number":"AV21-015","subject":null,"moderation_state":"published","external_url":null},{"nid":2249,"title":"[Control systems] Siemens security advisory","uuid":"36be4dfd-04c1-49d8-8033-bdd417081966","banner":null,"lang":"en","date_modified":"2021-01-12","date_modified_ts":"2021-01-12T19:47:31Z","date_created":"2021-01-12T19:47:31Z","summary":null,"body":["<article data-history-node-id=\"2249\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-016<br \/>\nDate: 12 January 2021<\/strong><\/p>\n\n<p>On 12 January 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SCALANCE X-200 switch family \u2013 all versions<\/li>\n\t<li>SCALANCE X-200IRT switch family \u2013 all versions<\/li>\n\t<li>SCALANCE X-300 switch family \u2013 versions prior to v4.1.0<\/li>\n\t<li>JT2Go \u2013 version 13.1.0 and prior<\/li>\n\t<li>Teamcenter Visualization \u2013 version 13.1.0 and prior<\/li>\n\t<li>Solid Edge \u2013 versions prior to SE2021MP2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>SCALANCE X<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-139628.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-139628.pdf<\/a><br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-274900.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-274900.pdf<\/a><\/p>\n\n<p>Team Center Visualization and JT2Go<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-622830.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-622830.pdf<\/a><\/p>\n\n<p>Solid Edge<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-979834.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-979834.pdf<\/a><\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-17","alert_type":398,"serial_number":"AV21-016","subject":null,"moderation_state":"published","external_url":null},{"nid":2250,"title":"[Control systems] Schneider Electric security advisory","uuid":"95858d82-4c92-4048-9e6c-7b4e20c04e10","banner":null,"lang":"en","date_modified":"2021-01-12","date_modified_ts":"2021-01-12T20:04:45Z","date_created":"2021-01-12T20:04:45Z","summary":null,"body":["<article data-history-node-id=\"2250\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-017<br \/>\nDate: 12 January 2020<\/strong><\/p>\n\n<p>On 12 January 2021 Schneider Electric published Security Notifications to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure\u2122 Operator Terminal Expert \u2013 version 3.1 Service Pack 1A and prior running on Harmony HMIs:\n\t<ul><li>HMIST6 Series<\/li>\n\t\t<li>HMIG3U in HMIGTU Series<\/li>\n\t\t<li>HMISTO Series<\/li>\n\t<\/ul><\/li>\n\t<li>Pro-face BLUE \u2013 version 3.1 Service Pack 1A and prior running on Pro-face HMIs:\n\t<ul><li>ST6000 Series<\/li>\n\t\t<li>SP-5B41 in SP5000 Series<\/li>\n\t\t<li>GP4100 Series<\/li>\n\t<\/ul><\/li>\n\t<li>EcoStruxure Power Build Rapsody software \u2013 version v2.1.13 and prior<\/li>\n\t<li>ACE850 Sepam communication interface \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>EcoStruxure Operator Terminal Expert and Pro-face BLUE<br \/><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-012-01\">https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-012-01<\/a><\/p>\n\n<p>EcoStruxure Power Build Rapsody software<br \/><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-012-02\">https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-012-02<\/a><\/p>\n\n<p>ACE850 Sepam communication interface<br \/><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-012-03\">https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-012-03<\/a><\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-14","alert_type":398,"serial_number":"AV21-017","subject":null,"moderation_state":"published","external_url":null},{"nid":2251,"title":"Adobe security advisory","uuid":"3b48d3a2-b204-4d01-b086-3399505242ac","banner":null,"lang":"en","date_modified":"2021-01-12","date_modified_ts":"2021-01-12T20:16:45Z","date_created":"2021-01-12T20:16:45Z","summary":null,"body":["<article data-history-node-id=\"2251\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-018<br \/>\nDate: 12 January 2021<\/strong><\/p>\n\n<p>On 12 January 2021 Adobe published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Bridge \u2013 versions 11.0 and prior<\/li>\n\t<li>Adobe Captivate \u2013 versions 11.5.1.499 and prior<\/li>\n\t<li>Adobe InCopy \u2013 versions 15.1.3 and prior<\/li>\n\t<li>Adobe Campaign Classic \u2013 multiple versions<\/li>\n\t<li>Adobe Animate \u2013 versions 21.0 and prior<\/li>\n\t<li>Adobe Illustrator 2020 \u2013 versions 25.0 and prior<\/li>\n\t<li>Adobe Photoshop 2021 \u2013 versions 22.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-34","alert_type":396,"serial_number":"AV21-018","subject":null,"moderation_state":"published","external_url":null},{"nid":2252,"title":"SAP security advisory \u2013 January 2021 monthly rollup","uuid":"f29de929-7d1d-4146-b345-636de94c56ea","banner":null,"lang":"en","date_modified":"2021-01-13","date_modified_ts":"2021-01-13T14:13:43Z","date_created":"2021-01-13T14:13:43Z","summary":null,"body":["<article data-history-node-id=\"2252\" about=\"\/en\/alerts-advisories\/sap-security-advisory-january-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-019<br \/>\nDate: 13 January 2021<\/strong><\/p>\n\n<p>On 12 January 2021 SAP published Security Advisories to highlight vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>SAP Business Warehouse \u2013 versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 782<\/li>\n\t<li>SAP BW4HANA \u2013 versions 100, 200<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 January 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=564760476\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=564760476<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-january-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-019","subject":null,"moderation_state":"published","external_url":null},{"nid":2253,"title":"[Control systems] SOOIL security advisory","uuid":"34b041a8-9bd6-4f84-bf28-5b1252fc7bb3","banner":null,"lang":"en","date_modified":"2021-01-13","date_modified_ts":"2021-01-13T14:15:50Z","date_created":"2021-01-13T14:15:50Z","summary":null,"body":["<article data-history-node-id=\"2253\" about=\"\/en\/alerts-advisories\/control-systems-sooil-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-020<br \/>\nDate: 13 January 2021<\/strong><\/p>\n\n<p>On 12 January 2021 ICS-CERT published an advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Dana Diabecare RS \u2013 versions prior to 3.0<\/li>\n\t<li>AnyDana-I \u2013 versions prior to 3.0<\/li>\n\t<li>AnyDana-A \u2013 versions prior to 3.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to access sensitive information, modify therapy settings, bypass authentication, or crash the device being accessed.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-012-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-012-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-012-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sooil-security-advisory","alert_type":398,"serial_number":"AV21-020","subject":null,"moderation_state":"published","external_url":null},{"nid":2254,"title":"Microsoft security advisory \u2013 January 2021 monthly rollup","uuid":"013b3327-108e-434f-acd0-15e147470a19","banner":null,"lang":"en","date_modified":"2021-01-13","date_modified_ts":"2021-01-13T14:18:05Z","date_created":"2021-01-13T14:18:05Z","summary":null,"body":["<article data-history-node-id=\"2254\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-021<br \/>\nDate: 13 January 2021<\/strong><\/p>\n\n<p>On 12 January 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were patches, which Microsoft rated with critical severity, for the following:<\/p>\n\n<ul><li>Microsoft Windows<\/li>\n\t<li>Microsoft Windows Server<\/li>\n\t<li>Microsoft Windows RT<\/li>\n\t<li>Microsoft Windows Defender<\/li>\n\t<li>Microsoft System Center<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>HEVC Video Extensions<\/li>\n\t<li>Microsoft Security Essentials<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p>January 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Jan\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Jan<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-january-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-021","subject":null,"moderation_state":"published","external_url":null},{"nid":2255,"title":"Cisco security advisory","uuid":"86d5e125-f6dd-4fff-80c1-d7c16642cb05","banner":null,"lang":"en","date_modified":"2021-01-13","date_modified_ts":"2021-01-13T20:07:39Z","date_created":"2021-01-13T20:07:39Z","summary":null,"body":["<article data-history-node-id=\"2255\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-72\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-022<br \/>\nDate: 13 January 2021<\/strong><\/p>\n\n<p>On 13 January 2021 Cisco published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-72","alert_type":396,"serial_number":"AV21-022","subject":null,"moderation_state":"published","external_url":null},{"nid":2256,"title":"Juniper Networks security advisory","uuid":"1a6416dd-3eb0-46ca-8058-c2ee68754a25","banner":null,"lang":"en","date_modified":"2021-01-14","date_modified_ts":"2021-01-14T17:19:04Z","date_created":"2021-01-14T17:19:04Z","summary":null,"body":["<article data-history-node-id=\"2256\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-023<br \/>\nDate: 14 January 2021<\/strong><\/p>\n\n<p>On 13 January 2021 Juniper Networks published Security Bulletins to address vulnerabilities in multiple products. Included was a critical severity update for the following:<\/p>\n\n<ul><li>SRC Series \u2013 versions prior to 4.12.0R6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>SRC Series<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA11104&amp;cat=SIRT_1&amp;actp=LIST\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA11104&amp;cat=SIRT_1&amp;actp=LIST<\/a><\/p>\n\n<p>Juniper Networks Security Advisories<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-6","alert_type":396,"serial_number":"AV21-023","subject":null,"moderation_state":"published","external_url":null},{"nid":2257,"title":"HPE security advisory","uuid":"65a00819-2e03-4d7a-bc2c-9f53f266a93a","banner":null,"lang":"en","date_modified":"2021-01-14","date_modified_ts":"2021-01-14T18:34:44Z","date_created":"2021-01-14T18:24:28Z","summary":null,"body":["<article data-history-node-id=\"2257\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-024<br \/>\nDate: 14 January 2021<\/strong><\/p>\n\n<p>On 13 January 2021 HPE published a Security Bulletin to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE UPS Network Module \u2013 versions prior to 1.12.002<\/li>\n<\/ul><p>Exploitation may lead to remote code execution, denial of service, and the exposure of sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE UPS Network Module<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04074en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04074en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-5","alert_type":396,"serial_number":"AV21-024","subject":null,"moderation_state":"published","external_url":null},{"nid":2258,"title":"Cisco security advisory","uuid":"6e22c886-dade-489e-80c0-d6d922c0f097","banner":null,"lang":"en","date_modified":"2021-01-14","date_modified_ts":"2021-01-14T19:58:58Z","date_created":"2021-01-14T19:58:58Z","summary":null,"body":["<article data-history-node-id=\"2258\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-73\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-025<br \/>\nDate: 14 January 2021<\/strong><\/p>\n\n<p>On 13 January 2021 Cisco published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cisco AnyConnect Secure Mobility Client for Windows \u2013 versions prior to 4.9.04043<\/li>\n<\/ul><p>Exploitation could allow an actor to execute arbitrary code on the affected machine with SYSTEM privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco AnyConnect<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-anyconnect-dll-injec-pQnryXLf\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-anyconnect-dll-injec-pQnryXLf<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-73","alert_type":396,"serial_number":"AV21-025","subject":null,"moderation_state":"published","external_url":null},{"nid":2259,"title":"HPE security advisory","uuid":"fa7f70a6-c5c5-4bc2-8c6a-439a9624501a","banner":null,"lang":"en","date_modified":"2021-01-15","date_modified_ts":"2021-01-15T16:18:04Z","date_created":"2021-01-15T16:18:04Z","summary":null,"body":["<article data-history-node-id=\"2259\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-026<br \/>\nDate: 15 January 2021<\/strong><br \/><br \/>\nOn 14 January 2021 HPE published a Security Bulletin to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>AirWave Glass \u2013 version 1.3.2 and prior<\/li>\n<\/ul><p>Exploitation may lead to remote authentication bypass, escalation of privilege, execution of arbitrary commands, unauthenticated arbitrary code execution, unauthorized access and server-side request forgery (SSRF).<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>AirWave Glass Security Bulletin<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04078en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04078en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-6","alert_type":396,"serial_number":"AV21-026","subject":null,"moderation_state":"published","external_url":null},{"nid":2260,"title":"Ubuntu security advisory","uuid":"3d25540c-a65c-4943-8617-bd194b3f3c4a","banner":null,"lang":"en","date_modified":"2021-01-15","date_modified_ts":"2021-01-15T16:20:50Z","date_created":"2021-01-15T16:20:50Z","summary":null,"body":["<article data-history-node-id=\"2260\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-027<br \/>\nDate: 15 January 2021<\/strong><\/p>\n\n<p>On 14 January 2021 Ubuntu released a Security Notice to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to expose sensitive information or modify data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4694-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4694-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-3","alert_type":396,"serial_number":"AV21-027","subject":null,"moderation_state":"published","external_url":null},{"nid":2261,"title":"IBM security advisory","uuid":"4a602d00-5db1-4a15-8cad-fac888909931","banner":null,"lang":"en","date_modified":"2021-01-19","date_modified_ts":"2021-01-19T14:17:13Z","date_created":"2021-01-19T14:08:07Z","summary":null,"body":["<article data-history-node-id=\"2261\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-028<br \/><strong>Date: 19 January 2021<\/strong><\/strong><\/p>\n\n<p>Between 11 and 17 January 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>\u00a0IBM Integration Bus - versions 10.0.0 to 10.0.0.22<\/li>\n\t<li>\u00a0IBM App Connect Enterprise V11 - versions 11.0.0.0 to 11.0.0.10<\/li>\n\t<li>\u00a0IBM Guardium Data Encryption (GDE) - version 3.0.0.2<\/li>\n\t<li>\u00a0IBM MaaS360 Cloud Extender \u2013 version 2.102.x and prior<\/li>\n\t<li>\u00a0IBM Security Privileged Identity Manager - version 2.1.1<\/li>\n\t<li>\u00a0Watson Knowledge Catalog for IBM Cloud Pak for Data \u2013 versions 2.5 and 3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-33","alert_type":396,"serial_number":"AV21-028","subject":null,"moderation_state":"published","external_url":null},{"nid":2262,"title":"[Control systems] Siemens security advisory","uuid":"e610e45d-8b1d-49a2-b49f-fddc74a2db21","banner":null,"lang":"en","date_modified":"2021-01-19","date_modified_ts":"2021-01-19T20:23:47Z","date_created":"2021-01-19T20:23:47Z","summary":null,"body":["<article data-history-node-id=\"2262\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-029<br \/>\nDate: 19 January 2021<\/strong><\/p>\n\n<p>On 19 January 2021 Siemens published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0RUGGEDCOM RM1224 \u2013 all versions<\/li>\n\t<li>\u00a0SCALANCE M-800 \u2013 all versions<\/li>\n\t<li>\u00a0SCALANCE S615 \u2013 all versions<\/li>\n\t<li>\u00a0SCALANCE SC-600 \u2013 all versions<\/li>\n\t<li>\u00a0SCALANCE W1750D - all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>Siemens Security Advisory (SSA-646763)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-646763.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-646763.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-18","alert_type":398,"serial_number":"AV21-029","subject":null,"moderation_state":"published","external_url":null},{"nid":2263,"title":"[Control systems] ABB security advisory","uuid":"f25f47be-96da-4527-bd70-c89986caedfb","banner":null,"lang":"en","date_modified":"2021-01-20","date_modified_ts":"2021-01-20T20:12:54Z","date_created":"2021-01-20T20:12:54Z","summary":null,"body":["<article data-history-node-id=\"2263\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-030<br \/>\nDate: 20 January 2021<\/strong><\/p>\n\n<p>On 19 January 2021 ABB published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>AC500 V2 with onboard ethernet \u2013 versions prior to 2.8.5<\/li>\n<\/ul><p>Exploitation would allow an actor to stop the Programmable Logic Controller (PLC) by sending an unauthenticated, crafted packet over the network.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update when available.<br \/>\nAC500 V2<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010667&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010667&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-12","alert_type":398,"serial_number":"AV21-030","subject":null,"moderation_state":"published","external_url":null},{"nid":2264,"title":"Oracle security advisory \u2013 January 2021 Quarterly Rollup","uuid":"0c9c4a53-c8f6-456e-814e-0f011151ec57","banner":null,"lang":"en","date_modified":"2021-01-20","date_modified_ts":"2021-01-20T20:23:07Z","date_created":"2021-01-20T20:23:07Z","summary":null,"body":["<article data-history-node-id=\"2264\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-january-2021-quarterly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-031<br \/>\nDate: 20 January 2021<\/strong><\/p>\n\n<p>On 19 January 2021 Oracle published a Critical Patch Update Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Enterprise Manager Base Platform \u2013 multiple versions<\/li>\n\t<li>Enterprise Manager Ops Center - version 12.4.0.0<\/li>\n\t<li>Hyperion Infrastructure Technology - version 11.1.2.4<\/li>\n\t<li>Oracle Application Testing Suite - version 13.3.0.1<\/li>\n\t<li>Oracle BAM (Business Activity Monitoring) - versions 11.1.1.9.0 and 12.2.1.3.0<\/li>\n\t<li>Oracle Banking Corporate Lending Process Management - multiple versions<\/li>\n\t<li>Oracle Banking Credit Facilities Process Management - multiple versions<\/li>\n\t<li>Oracle Banking Extensibility Workbench 14.3.0 and 14.4.0<\/li>\n\t<li>Oracle Banking Liquidity Management - versions 14.0.0 to 14.4.0<\/li>\n\t<li>Oracle Banking Payments - version 14.4.0<\/li>\n\t<li>Oracle Banking Supply Chain Finance - versions 14.2.0 to 14.4.0<\/li>\n\t<li>Oracle Banking Trade Finance Process Management - multiple versions<\/li>\n\t<li>Oracle Banking Virtual Account Management - multiple versions<\/li>\n\t<li>Oracle Business Process Management Suite - versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle Coherence - multiple versions<\/li>\n\t<li>Oracle Communications Operations Monitor - versions 4.2 and 4.3<\/li>\n\t<li>Oracle Data Integrator - versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle Enterprise Data Quality - versions 11.1.1.9.0 and 12.2.1.3.0<\/li>\n\t<li>Oracle Enterprise Repository - version 11.1.1.7.0<\/li>\n\t<li>Oracle Financial Services Analytical Applications Infrastructure - versions 8.0.6 to 8.1.0<\/li>\n\t<li>Oracle Financial Services Data Integration Hub - versions 8.0.3 and 8.0.6<\/li>\n\t<li>Oracle Financial Services Market Risk Measurement and Management - version 8.0.6<\/li>\n\t<li>Oracle Health Sciences Information Manager - version 3.0.1<\/li>\n\t<li>Oracle Hospitality Simphony - versions 18.2.7.2 and 19.1.3<\/li>\n\t<li>Oracle Real-Time Decision Server - version 3.2.1.0<\/li>\n\t<li>Oracle Retail Customer Management and Segmentation Foundation - multiple versions<\/li>\n\t<li>Oracle Retail Extract Transform and Load - versions 13.2.5 and 13.2.8<\/li>\n\t<li>Oracle Retail Merchandising System - version 15.0<\/li>\n\t<li>Oracle Retail Sales Audit - version 14.1<\/li>\n\t<li>Oracle Utilities Framework - multiple versions<\/li>\n\t<li>Oracle WebCenter Portal - versions 11.1.1.9.0<\/li>\n\t<li>Oracle WebLogic Server - multiple versions<\/li>\n\t<li>Oracle ZFS Storage Appliance Kit - version 8.8<\/li>\n\t<li>Primavera Unifier - multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\nOracle Critical Patch Update Advisory - January 2021<br \/><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2021.html\">https:\/\/www.oracle.com\/security-alerts\/cpujan2021.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-january-2021-quarterly-rollup","alert_type":396,"serial_number":"AV21-031","subject":null,"moderation_state":"published","external_url":null},{"nid":2265,"title":"[Control systems] Reolink security advisory","uuid":"8d321197-d546-4779-a9d1-fa3ac61a18a3","banner":null,"lang":"en","date_modified":"2021-01-21","date_modified_ts":"2021-01-21T15:55:19Z","date_created":"2021-01-21T15:55:19Z","summary":null,"body":["<article data-history-node-id=\"2265\" about=\"\/en\/alerts-advisories\/control-systems-reolink-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-032<br \/>\nDate: 21 January 2021<\/strong><\/p>\n\n<p>On 19 January 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0\u00a0\u00a0\u00a0 RLC-4XX series<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RLC-5XX series<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 RLN-X10 series<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could allow unauthorized access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-019-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-019-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-019-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-reolink-security-advisory","alert_type":398,"serial_number":"AV21-032","subject":null,"moderation_state":"published","external_url":null},{"nid":2266,"title":"Cisco security advisory","uuid":"c3e13327-0094-4fb2-8756-304549bd960a","banner":null,"lang":"en","date_modified":"2021-01-21","date_modified_ts":"2021-01-21T16:12:08Z","date_created":"2021-01-21T16:12:08Z","summary":null,"body":["<article data-history-node-id=\"2266\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-74\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-033<br \/>\nDate: 21 January 2021<\/strong><br \/>\n\u00a0<br \/>\nBetween 19 and 20 January 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>\u00a0Cisco SD-WAN products \u2013 multiple versions<\/li>\n\t<li>\u00a0Cisco DNA Center \u2013 versions prior to 1.3.1.0<\/li>\n\t<li>\u00a0Cisco Smart Software Manager Satellite - version 5.1.0 and prior<\/li>\n\t<li>\u00a0Cisco Small Business routers - multiple models<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow command injection or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco SD-WAN<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-cmdinjm-9QMSmgcn\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-cmdinjm-9QMSmgcn<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-bufovulns-B5NrSHbj\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-bufovulns-B5NrSHbj<\/a><\/p>\n\n<p>Cisco DNA Center<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-dnac-cmdinj-erumsWh9\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-dnac-cmdinj-erumsWh9<\/a><\/p>\n\n<p>Cisco Smart Software Manager Satellite<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cssm-multici-pgG5WM5A\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cssm-multici-pgG5WM5A<\/a><\/p>\n\n<p>Cisco Small Business routers<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-rv-overflow-WUnUgv4U\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-rv-overflow-WUnUgv4U<\/a><br \/>\n\u00a0<br \/>\nCisco Security Advisories<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-74","alert_type":396,"serial_number":"AV21-033","subject":null,"moderation_state":"published","external_url":null},{"nid":2267,"title":"Google Chrome security advisory","uuid":"4a5c5199-faed-472a-8f4a-b2b68b1f5c90","banner":null,"lang":"en","date_modified":"2021-01-21","date_modified_ts":"2021-01-21T18:03:34Z","date_created":"2021-01-21T18:03:34Z","summary":null,"body":["<article data-history-node-id=\"2267\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-43\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-034<br \/>\nDate: 21 January 2021<\/strong><\/p>\n\n<p>On 19 January 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Chrome for Desktop \u2013 versions prior to 88.0.4324.96<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/01\/stable-channel-update-for-desktop_19.html\">https:\/\/chromereleases.googleblog.com\/2021\/01\/stable-channel-update-for-desktop_19.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-43","alert_type":396,"serial_number":"AV21-034","subject":null,"moderation_state":"published","external_url":null},{"nid":2268,"title":"[Control systems] Dnsmasq security advisory","uuid":"79ef538e-add8-4832-9f6c-3aa394de31ed","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T13:38:19Z","date_created":"2021-01-22T13:38:19Z","summary":null,"body":["<article data-history-node-id=\"2268\" about=\"\/en\/alerts-advisories\/control-systems-dnsmasq-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-035<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 19 January 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Dnsmasq - versions prior to 2.83<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in cache poisoning, remote code execution, and a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-019-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-019-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-019-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-dnsmasq-security-advisory","alert_type":398,"serial_number":"AV21-035","subject":null,"moderation_state":"published","external_url":null},{"nid":2269,"title":"[Control systems] Delta Electronics security advisory","uuid":"f4a56636-18ce-4094-b8fb-38f3deed0f6f","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T13:49:15Z","date_created":"2021-01-22T13:49:15Z","summary":null,"body":["<article data-history-node-id=\"2269\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-036<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 21 January 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ISPSoft \u2013 version 3.12 and prior<\/li>\n\t<li>TPEditor - version 1.98 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to execute code under the privileges of the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-021-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-01<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-021-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-4","alert_type":398,"serial_number":"AV21-036","subject":null,"moderation_state":"published","external_url":null},{"nid":2270,"title":"Ubuntu security advisory","uuid":"58fae5d7-fc7b-4aeb-b38b-5ed098bbae4f","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T13:56:16Z","date_created":"2021-01-22T13:56:16Z","summary":null,"body":["<article data-history-node-id=\"2270\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-037<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 21 January 2021 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow denial-of-service, privilege escalation or access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4689-4)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4689-4\">https:\/\/ubuntu.com\/security\/notices\/USN-4689-4<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-4","alert_type":396,"serial_number":"AV21-037","subject":null,"moderation_state":"published","external_url":null},{"nid":2271,"title":"Drupal security advisory","uuid":"e421616a-1c33-4b98-a0f8-6ac71cefde57","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T14:31:25Z","date_created":"2021-01-22T14:28:34Z","summary":null,"body":["<article data-history-node-id=\"2271\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-038<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 20 January 2021 Drupal published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Drupal 9.1 - versions prior to 9.1.3<\/li>\n\t<li>Drupal 9.0 - versions prior to 9.0.11<\/li>\n\t<li>Drupal 8.9 - versions prior to 8.9.13<\/li>\n\t<li>Drupal 7 - versions prior to 7.78<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<\/p>\n\n<p>Drupal core (SA-CORE-2021-001)<br \/><a href=\"https:\/\/www.drupal.org\/sa-core-2021-001\">https:\/\/www.drupal.org\/sa-core-2021-001<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-12","alert_type":396,"serial_number":"AV21-038","subject":null,"moderation_state":"published","external_url":null},{"nid":2272,"title":"[Control systems] WAGO security advisory","uuid":"6fddc3f8-8616-4f19-9924-77167fa26680","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T14:42:21Z","date_created":"2021-01-22T14:36:08Z","summary":null,"body":["<article data-history-node-id=\"2272\" about=\"\/en\/alerts-advisories\/control-systems-wago-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-039<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 21 January 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>fdtCONTAINER component \u2013 multiple versions<\/li>\n\t<li>fdtCONTAINER application \u2013 multiple versions<\/li>\n\t<li>dtmINSPECTOR - version 3<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to perform code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-021-05)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-05<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wago-security-advisory-1","alert_type":398,"serial_number":"AV21-039","subject":null,"moderation_state":"published","external_url":null},{"nid":2273,"title":"[Control systems] Honeywell security advisory","uuid":"cb7030e5-a46c-4798-9c0e-c644c42f095a","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T17:37:07Z","date_created":"2021-01-22T17:37:07Z","summary":null,"body":["<article data-history-node-id=\"2273\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-040<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 21 January 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0\u00a0\u00a0\u00a0 Matrikon OPC UA Tunneller - versions prior to 6.3.0.8233<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could allow an actor to disclose sensitive information, remotely execute arbitrary code, or crash the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-021-03)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-021-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-4","alert_type":398,"serial_number":"AV21-040","subject":null,"moderation_state":"published","external_url":null},{"nid":2274,"title":"HPE security advisory","uuid":"32f735ca-07ab-4fff-8d98-080ace77cfd1","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T19:29:42Z","date_created":"2021-01-22T19:29:42Z","summary":null,"body":["<article data-history-node-id=\"2274\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-041<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 21 January 2021 HPE published a Security Bulletin to address vulnerabilities in the baseboard management controller (BMC) of the following products:<\/p>\n\n<ul><li>CL3100 Gen10 (CLX) - version 1.08.0.0<\/li>\n\t<li>CL4100 Gen10 (CLX) - version 1.08.0.0<\/li>\n\t<li>CL5800 Gen10 (CLX) - version 1.08.0.0<\/li>\n\t<li>CL3100 Gen10 - version 1.10.0.0<\/li>\n\t<li>CL4100 Gen10 - version 1.10.0.0<\/li>\n\t<li>CL5200 Gen9 - version 1.07.0.0<\/li>\n\t<li>CL5800 Gen9 - version 1.09.0.0<\/li>\n<\/ul><p>Exploitation locally could allow denial-of-service, buffer overflow and path traversal.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04073en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04073en_us<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-7","alert_type":396,"serial_number":"AV21-041","subject":null,"moderation_state":"published","external_url":null},{"nid":2275,"title":"[Control systems] Philips security advisory","uuid":"b9735581-478b-4f67-bc87-b63ccf6ff463","banner":null,"lang":"en","date_modified":"2021-01-22","date_modified_ts":"2021-01-22T20:27:58Z","date_created":"2021-01-22T20:24:59Z","summary":null,"body":["<article data-history-node-id=\"2275\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-042<br \/>\nDate: 22 January 2021<\/strong><\/p>\n\n<p>On 19 January 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>\u00a0Certain Haswell workstations labeled with 12NC identification numbers (4598 009 39471, 4598 009 39481, 4598 009 70861, 4598 009 98531) when running:\n\t<ul><li>\u00a0Interventional Workspot \u2013 multiple versions\u00a0<\/li>\n\t\t<li>\u00a0Coronary Tools\/Dynamic Coronary Roadmap\/Stentboost Live \u2013 version 1.0<\/li>\n\t\t<li>\u00a0ViewForum - version 6.3V1L10<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation could allow an actor within the network to remotely shut down or restart the workstation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Medical Advisory (ICSMA-21-019-01)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-019-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-019-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-8","alert_type":398,"serial_number":"AV21-042","subject":null,"moderation_state":"published","external_url":null},{"nid":2276,"title":"IBM security advisory","uuid":"a4ba17d1-211c-4846-9f34-d53593e6e131","banner":null,"lang":"en","date_modified":"2021-01-25","date_modified_ts":"2021-01-25T20:02:33Z","date_created":"2021-01-25T20:02:33Z","summary":null,"body":["<article data-history-node-id=\"2276\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-043<br \/>\nDate: 25 January 2021<\/strong><\/p>\n\n<p>Between 18 and 24 January 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>\u00a0IBM Integration Bus \u2013 versions 9.0.0.0 to 9.0.0.11 and 10.0.0 to 10.0.0.22<\/li>\n\t<li>\u00a0IBM App Connect Enterprise \u2013 versions 11.0.0.0 to 11.0.0.10<\/li>\n\t<li>\u00a0IBM Cloud Pak for Integration \u2013 versions 2020.2 and 2020.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM App Connect Enterprise and IBM Integration Bus<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-app-connect-enterprise-ibm-integration-bus-are-affected-by-vulnerabilities-in-apache-xerces-c-3-0-0-to-3-2-2-xml-parser-cve-2018-1311\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-app-connect-enterprise-ibm-integration-bus-are-affected-by-vulnerabilities-in-apache-xerces-c-3-0-0-to-3-2-2-xml-parser-cve-2018-1311\/<\/a><\/p>\n\n<p>IBM Cloud Pak for Integration<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-integration-is-affected-by-multiple-go-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-integration-is-affected-by-multiple-go-vulnerabilities\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-34","alert_type":396,"serial_number":"AV21-043","subject":null,"moderation_state":"published","external_url":null},{"nid":2277,"title":"[Control systems] Fuji Electric security advisory","uuid":"01fc0732-d4ac-4803-8b1c-c59931df0e8d","banner":null,"lang":"en","date_modified":"2021-01-26","date_modified_ts":"2021-01-26T20:00:09Z","date_created":"2021-01-26T20:00:09Z","summary":null,"body":["<article data-history-node-id=\"2277\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-044<br \/>\nDate: 26 January 2021<\/strong><\/p>\n\n<p>On 26 January 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Tellus Lite V-Simulator - versions prior to v4.0.10.0<\/li>\n\t<li>V-Server Lite - versions prior to v4.0.10.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to perform code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-026-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-026-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-026-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-3","alert_type":398,"serial_number":"AV21-044","subject":null,"moderation_state":"published","external_url":null},{"nid":2278,"title":"Mozilla security advisory","uuid":"6e2619eb-c8a3-4eda-8394-490f4558ed28","banner":null,"lang":"en","date_modified":"2021-01-26","date_modified_ts":"2021-01-26T20:48:10Z","date_created":"2021-01-26T20:48:10Z","summary":null,"body":["<article data-history-node-id=\"2278\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-045<br \/>\nDate: 26 January 2021<\/strong><\/p>\n\n<p>On 26 January 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR \u2013 versions prior to 78.7<\/li>\n\t<li>Firefox \u2013 versions prior to 85<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox ESR (MFSA 2021-04)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-04\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-04\/<\/a><\/p>\n\n<p>Firefox (MFSA 2021-03)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-03\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-03\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-30","alert_type":396,"serial_number":"AV21-045","subject":null,"moderation_state":"published","external_url":null},{"nid":2279,"title":"Apple security advisory","uuid":"0578730d-9e14-45df-b428-1f8137cfead1","banner":null,"lang":"en","date_modified":"2021-01-27","date_modified_ts":"2021-01-27T15:10:55Z","date_created":"2021-01-27T15:10:55Z","summary":null,"body":["<article data-history-node-id=\"2279\" about=\"\/en\/alerts-advisories\/apple-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-046<br \/>\nDate: 27 January 2021<\/strong><\/p>\n\n<p>On 26 January 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 14.4<\/li>\n\t<li>iPadOS \u2013 versions prior to 14.4<\/li>\n\t<li>tvOS \u2013 versions prior to 14.4<\/li>\n\t<li>watchOS \u2013 versions prior to 7.3<\/li>\n\t<li>Xcode\u00a0 \u2013 versions prior to 12.4<\/li>\n\t<li>iCloud \u2013 versions prior to 12.0<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution, privilege escalation, arbitrary file read, or heap corruption. Apple has received reports that some of these vulnerabilities may have been actively exploited online.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-23","alert_type":396,"serial_number":"AV21-046","subject":null,"moderation_state":"published","external_url":null},{"nid":2280,"title":"Mozilla security advisory","uuid":"71375463-b4ce-4284-89f3-38f0fa38bd8b","banner":null,"lang":"en","date_modified":"2021-01-27","date_modified_ts":"2021-01-27T16:35:15Z","date_created":"2021-01-27T16:35:15Z","summary":null,"body":["<article data-history-node-id=\"2280\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-047<br \/>\nDate: 27 January 2021<\/strong><\/p>\n\n<p>On 26 January 2021 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Thunderbird \u2013 versions prior to 78.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Thunderbird (MFSA 2021-05)<br \/><a href=\"https:\/\/www.mozilla.org\/en-\/security\/advisories\/mfsa2021-05\/\">https:\/\/www.mozilla.org\/en-\/security\/advisories\/mfsa2021-05\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-31","alert_type":396,"serial_number":"AV21-047","subject":null,"moderation_state":"published","external_url":null},{"nid":2281,"title":"Ubuntu security advisory","uuid":"5d01400a-76ba-4d0d-97f8-2e11cf77a80e","banner":null,"lang":"en","date_modified":"2021-01-28","date_modified_ts":"2021-01-28T19:06:52Z","date_created":"2021-01-28T19:06:52Z","summary":null,"body":["<article data-history-node-id=\"2281\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-048<br \/>\nDate: 28 January 2021<\/strong><\/p>\n\n<p>On 28 January 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial-of-service, privilege escalation, data modification, kernel memory modification, access to sensitive information or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4708-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4708-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4708-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4709-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4709-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4709-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4710-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4710-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4710-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4711-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4711-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4711-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4713-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4713-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4713-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-5","alert_type":396,"serial_number":"AV21-048","subject":null,"moderation_state":"published","external_url":null},{"nid":2282,"title":"[Control systems] Siemens security advisory","uuid":"97a4350a-b1bd-4a16-a95d-78719304c201","banner":null,"lang":"en","date_modified":"2021-01-29","date_modified_ts":"2021-01-29T14:04:13Z","date_created":"2021-01-29T14:04:13Z","summary":null,"body":["<article data-history-node-id=\"2282\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-049<br \/>\nDate: 29 January 2021<\/strong><\/p>\n\n<p>On 28 January 2021 Siemens published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SIMATIC HMI Comfort Panels (Including SIPLUS variants) \u2013 versions prior to V16 Update 3a<\/li>\n\t<li>SIMATIC HMI KTP Mobile Panels \u2013 versions prior to V16 Update 3a<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>Siemens Security Advisory (SSA-520004)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-520004.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-520004.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-19","alert_type":398,"serial_number":"AV21-049","subject":null,"moderation_state":"published","external_url":null},{"nid":2283,"title":"[Control systems] Rockwell Automation security advisory","uuid":"8fba492d-18b8-4155-bd6b-341561a2d511","banner":null,"lang":"en","date_modified":"2021-01-29","date_modified_ts":"2021-01-29T14:08:31Z","date_created":"2021-01-29T14:08:31Z","summary":null,"body":["<article data-history-node-id=\"2283\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-050<br \/>\nDate: 29 January 2021<\/strong><\/p>\n\n<p>On 28 January 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>FactoryTalk Linx software - version 6.20 and prior<\/li>\n\t<li>FactoryTalkServices Platform - version 6.20 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-028-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-028-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-028-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-9","alert_type":398,"serial_number":"AV21-050","subject":null,"moderation_state":"published","external_url":null},{"nid":2284,"title":"Android security advisory \u2013 February 2021 monthly rollup","uuid":"09efb147-4f94-428f-b54a-1664b137081c","banner":null,"lang":"en","date_modified":"2021-02-02","date_modified_ts":"2021-02-02T15:34:15Z","date_created":"2021-02-02T15:24:11Z","summary":null,"body":["<article data-history-node-id=\"2284\" about=\"\/en\/alerts-advisories\/android-security-advisory-february-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-051<br \/>\nDate:\u00a02 February 2021<\/strong><\/p>\n\n<p>On 1 February 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-02-01\">https:\/\/source.android.com\/security\/bulletin\/2021-02-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-february-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-051","subject":null,"moderation_state":"published","external_url":null},{"nid":2285,"title":"Apple security advisory","uuid":"15dfb34d-fdb5-4faa-9935-9703aa02e4b1","banner":null,"lang":"en","date_modified":"2021-02-02","date_modified_ts":"2021-02-02T16:33:55Z","date_created":"2021-02-02T16:33:55Z","summary":null,"body":["<article data-history-node-id=\"2285\" about=\"\/en\/alerts-advisories\/apple-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-052<br \/>\nDate:\u00a02 February 2021<\/strong><\/p>\n\n<p>On 1 February 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0macOS Big Sur \u2013 versions 11.0.1 and prior<\/li>\n\t<li>\u00a0macOS Catalina \u2013 versions 10.15.7 and prior<\/li>\n\t<li>\u00a0macOS Mojave \u2013 versions 10.14.6 and prior<\/li>\n\t<li>\u00a0Safari \u2013 versions prior to 14.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates (macOS)<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212147\">https:\/\/support.apple.com\/en-ca\/HT212147<\/a><\/p>\n\n<p>Apple Security Updates (Safari)<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT212152\">https:\/\/support.apple.com\/kb\/HT212152<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-24","alert_type":396,"serial_number":"AV21-052","subject":null,"moderation_state":"published","external_url":null},{"nid":2286,"title":"[Control systems] ABB security advisory","uuid":"f8be977a-1f0b-433b-8ec7-2fd8e9ced0c5","banner":null,"lang":"en","date_modified":"2021-02-02","date_modified_ts":"2021-02-02T20:19:38Z","date_created":"2021-02-02T20:19:38Z","summary":null,"body":["<article data-history-node-id=\"2286\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-053<br \/>\nDate: 2 February 2021<\/strong><\/p>\n\n<p>On 2 February 2021 ABB published a Cyber Security Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>\u00a0AC500 V2 PM554<\/li>\n\t<li>\u00a0AC500 V2 PM556<\/li>\n\t<li>\u00a0AC500 V2 PM564<\/li>\n\t<li>\u00a0AC500 V2 PM566<\/li>\n\t<li>\u00a0AC500 V2 PM572<\/li>\n\t<li>\u00a0AC500 V2 PM573<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>Cyber Security Advisory (ABBVU-ABBVREP0019-3ADR010645)<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010645&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010645&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-13","alert_type":398,"serial_number":"AV21-053","subject":null,"moderation_state":"published","external_url":null},{"nid":2287,"title":"Ubuntu security advisory","uuid":"7170413e-0648-40ef-9f41-fa142639d748","banner":null,"lang":"en","date_modified":"2021-02-02","date_modified_ts":"2021-02-02T20:23:31Z","date_created":"2021-02-02T20:23:31Z","summary":null,"body":["<article data-history-node-id=\"2287\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-054<br \/>\nDate: 2 February 2021<\/strong><\/p>\n\n<p>On 2 February 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>\u00a0Ubuntu 20.10<\/li>\n\t<li>\u00a0Ubuntu 20.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 18.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 16.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, data modification, access to sensitive information or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4709-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4709-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4709-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4711-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4711-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4711-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4713-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4713-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4713-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-6","alert_type":396,"serial_number":"AV21-054","subject":null,"moderation_state":"published","external_url":null},{"nid":2288,"title":"Google Chrome security advisory","uuid":"d4a7e129-5118-4fc6-b16b-00a1d7f3b514","banner":null,"lang":"en","date_modified":"2021-02-03","date_modified_ts":"2021-02-03T13:15:24Z","date_created":"2021-02-03T13:15:24Z","summary":null,"body":["<article data-history-node-id=\"2288\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-44\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-055<br \/>\nDate:\u00a03 February 2021<\/strong><\/p>\n\n<p>On 2 February 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Chrome for Desktop \u2013 versions prior to 88.0.4324.146<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/02\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/02\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-44","alert_type":396,"serial_number":"AV21-055","subject":null,"moderation_state":"published","external_url":null},{"nid":2289,"title":"SonicWall security advisory","uuid":"32ffa797-e447-434b-b148-d1e5bf12e055","banner":null,"lang":"en","date_modified":"2021-02-03","date_modified_ts":"2021-02-03T17:05:40Z","date_created":"2021-02-03T17:05:40Z","summary":null,"body":["<article data-history-node-id=\"2289\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-056<br \/>\nDate: 3 February 2021<\/strong><\/p>\n\n<p>On 1 February 2021 SonicWall published an Alert to address a vulnerability in the following product:<\/p>\n\n<ul><li>\u00a0Secure Mobile Access (SMA) 100 series \u2013 version 10.x<\/li>\n<\/ul><p>SonicWall has reported that they have observed exploitation of this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>SonicWall Alert<br \/><a href=\"https:\/\/www.sonicwall.com\/support\/product-notification\/urgent-security-notice-sonicwall-confirms-sma-100-series-10-x-zero-day-vulnerability-feb-3-6-a-m-cst\/210122173415410\/\">https:\/\/www.sonicwall.com\/support\/product-notification\/urgent-security-notice-sonicwall-confirms-sma-100-series-10-x-zero-day-vulnerability-feb-3-6-a-m-cst\/210122173415410\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p><font face=\"Calibri\" size=\"3\"><font face=\"Calibri\" size=\"3\"><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">\u00a0<\/span><\/font><\/font><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-0","alert_type":396,"serial_number":"AV21-056","subject":null,"moderation_state":"published","external_url":null},{"nid":2290,"title":"Cisco security advisory","uuid":"03eaf032-f704-45f3-bfd1-6a93c1bd4665","banner":null,"lang":"en","date_modified":"2021-02-04","date_modified_ts":"2021-02-04T15:04:56Z","date_created":"2021-02-04T15:04:56Z","summary":null,"body":["<article data-history-node-id=\"2290\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-75\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-057<br \/>\nDate:\u00a04 February 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 3 February 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>\u00a0Cisco Small Business routers - RV160, RV160W, RV260, RV260P and RV260W<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Small Business routers<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-rv160-260-rce-XZeFkNHf\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-rv160-260-rce-XZeFkNHf<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-75","alert_type":396,"serial_number":"AV21-057","subject":null,"moderation_state":"published","external_url":null},{"nid":2291,"title":"Google Chrome security advisory","uuid":"d729f96e-f7c1-4785-900b-64cb9e11b601","banner":null,"lang":"en","date_modified":"2021-02-04","date_modified_ts":"2021-02-04T20:57:44Z","date_created":"2021-02-04T20:57:44Z","summary":null,"body":["<article data-history-node-id=\"2291\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-45\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-058<br \/>\nDate: 4 February 2021<\/strong><\/p>\n\n<p>On 4 February 2021 Google published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 88.0.4324.150<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/02\/stable-channel-update-for-desktop_4.html\">https:\/\/chromereleases.googleblog.com\/2021\/02\/stable-channel-update-for-desktop_4.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-45","alert_type":396,"serial_number":"AV21-058","subject":null,"moderation_state":"published","external_url":null},{"nid":2292,"title":"HPE security advisory","uuid":"ba6f3200-8a50-4ddd-8fee-5d5e39d50495","banner":null,"lang":"en","date_modified":"2021-02-05","date_modified_ts":"2021-02-05T15:12:43Z","date_created":"2021-02-05T15:12:43Z","summary":null,"body":["<article data-history-node-id=\"2292\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-059<br \/>\nDate: 5 February 2021<\/strong><\/p>\n\n<p>Between 2 and 3 February 2021 HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Moonshot Provisioning Manager \u2013 version 1.20<\/li>\n\t<li>HPE and Aruba L2\/L3 switches \u2013 multiple models<\/li>\n\t<li>Apollo 70 System BMC Firmware \u2013 versions prior to 3.0.14.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (HPE and Aruba L2\/L3 switches)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04083en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04083en_us<\/a><\/p>\n\n<p>HPE Security Bulletin (Moonshot Provisioning Manager)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04085en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04085en_us<\/a><br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04084en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04084en_us<\/a><\/p>\n\n<p>HPE Security Bulletin (Apollo 70 System BMC Firmware)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04080en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04080en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-8","alert_type":396,"serial_number":"AV21-059","subject":null,"moderation_state":"published","external_url":null},{"nid":2293,"title":"Sudo security advisory","uuid":"aeaa18b6-36f3-4d93-b4e8-989f38b2e14e","banner":null,"lang":"en","date_modified":"2021-02-05","date_modified_ts":"2021-02-05T15:17:28Z","date_created":"2021-02-05T15:15:40Z","summary":null,"body":["<article data-history-node-id=\"2293\" about=\"\/en\/alerts-advisories\/sudo-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-060<br \/>\nDate: 5 February 2021<\/strong><\/p>\n\n<p>On 26 January 2021 Sudo released an Alert to address a vulnerability in the following:<\/p>\n\n<ul><li>Sudo \u2013 versions 1.8.2 through 1.8.31p2 and 1.9.0 through 1.9.5p1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to elevate privileges on an affected system.<\/p>\n\n<p>It has recently been reported that Linux, macOS, AIX, and Solaris may also be vulnerable. The Cyber Centre encourages users and administrators to review the following web link and apply the necessary update.<\/p>\n\n<p>Sudo Alert<br \/><a href=\"https:\/\/www.sudo.ws\/alerts\/unescape_overflow.html\">https:\/\/www.sudo.ws\/alerts\/unescape_overflow.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sudo-security-advisory","alert_type":396,"serial_number":"AV21-060","subject":null,"moderation_state":"published","external_url":null},{"nid":2294,"title":"[Control systems] Luxion security advisory","uuid":"fa3b41ba-8f0a-4d37-b1cf-4d90d8997088","banner":null,"lang":"en","date_modified":"2021-02-05","date_modified_ts":"2021-02-05T15:18:37Z","date_created":"2021-02-05T15:18:37Z","summary":null,"body":["<article data-history-node-id=\"2294\" about=\"\/en\/alerts-advisories\/control-systems-luxion-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-061<br \/>\nDate: 5 February 2021<\/strong><\/p>\n\n<p>On 4 February 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>KeyShot - versions prior to 10.1<\/li>\n\t<li>KeyShot Viewer - versions prior to 10.1<\/li>\n\t<li>KeyShot Network Rendering - versions prior to 10.1<\/li>\n\t<li>KeyVR - versions prior to 10.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-035-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-035-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-035-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-luxion-security-advisory","alert_type":398,"serial_number":"AV21-061","subject":null,"moderation_state":"published","external_url":null},{"nid":2295,"title":"[Control systems] Horner Automation security advisory","uuid":"10ab7320-53e5-4d93-b57c-432d7dc175ea","banner":null,"lang":"en","date_modified":"2021-02-05","date_modified_ts":"2021-02-05T15:21:14Z","date_created":"2021-02-05T15:21:14Z","summary":null,"body":["<article data-history-node-id=\"2295\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-062<br \/>\nDate: 5 February 2021<\/strong><\/p>\n\n<p>On 4 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Cscape - versions prior to 9.90 SP3.5<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-035-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-035-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-035-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-0","alert_type":398,"serial_number":"AV21-062","subject":null,"moderation_state":"published","external_url":null},{"nid":2296,"title":"SolarWinds security advisory","uuid":"4d97f87e-c93b-402e-bff4-5348557cfaa6","banner":null,"lang":"en","date_modified":"2021-02-05","date_modified_ts":"2021-02-05T19:36:37Z","date_created":"2021-02-05T19:36:37Z","summary":null,"body":["<article data-history-node-id=\"2296\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-063<br \/>\nDate: 5 February 2021<\/strong><\/p>\n\n<p>On 3 February Trustwave published security advisories on vulnerabilities affecting the following products:<\/p>\n\n<ul><li>\u00a0SolarWinds Orion Platform \u2013 versions prior to 2020.2.4<\/li>\n\t<li>\u00a0SolarWinds Serv-U FTP \u2013 versions prior to 15.2.2 Hotfix 1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow code execution and privilege escalation on an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Multiple Vulnerabilities in SolarWinds Orion<br \/><a href=\"https:\/\/www.trustwave.com\/en-us\/resources\/security-resources\/security-advisories\/?fid=28389\">https:\/\/www.trustwave.com\/en-us\/resources\/security-resources\/security-advisories\/?fid=28389<\/a><br \/><a href=\"https:\/\/documentation.solarwinds.com\/en\/Success_Center\/orionplatform\/content\/release_notes\/orion_platform_2020-2-4_release_notes.htm\">https:\/\/documentation.solarwinds.com\/en\/Success_Center\/orionplatform\/content\/release_notes\/orion_platform_2020-2-4_release_notes.htm<\/a><\/p>\n\n<p>Weak ACLs Vulnerability in SolarWinds Serv-U FTP Server 15.2.1 on Windows<br \/><a href=\"https:\/\/www.trustwave.com\/en-us\/resources\/security-resources\/security-advisories\/?fid=28396\">https:\/\/www.trustwave.com\/en-us\/resources\/security-resources\/security-advisories\/?fid=28396<\/a><\/p>\n\n<p><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory","alert_type":396,"serial_number":"AV21-063","subject":null,"moderation_state":"published","external_url":null},{"nid":2297,"title":"Mozilla security advisory","uuid":"2831d58a-f1aa-4467-835b-d9d67f4f4a54","banner":null,"lang":"en","date_modified":"2021-02-05","date_modified_ts":"2021-02-05T19:41:26Z","date_created":"2021-02-05T19:41:26Z","summary":null,"body":["<article data-history-node-id=\"2297\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-064<br \/>\nDate: 5 February 2021<\/strong><\/p>\n\n<p>On 5 February 2021 Mozilla published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>\u00a0Firefox ESR \u2013 versions prior to 78.7.1<\/li>\n\t<li>\u00a0Firefox \u2013 versions prior to 85.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Firefox (MFSA 2021-06)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-06\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-06\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-32","alert_type":396,"serial_number":"AV21-064","subject":null,"moderation_state":"published","external_url":null},{"nid":2298,"title":"Ubuntu security advisory","uuid":"a0fdcaf5-27ed-4eb1-996d-fb118d555bf0","banner":null,"lang":"en","date_modified":"2021-02-08","date_modified_ts":"2021-02-08T13:22:05Z","date_created":"2021-02-08T13:22:05Z","summary":null,"body":["<article data-history-node-id=\"2298\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-065<br \/>\nDate:\u00a08 February 2021<\/strong><\/p>\n\n<p>On 5 February 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, data modification or access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4711-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4711-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4711-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-7","alert_type":396,"serial_number":"AV21-065","subject":null,"moderation_state":"published","external_url":null},{"nid":2299,"title":"IBM security advisory","uuid":"a3ac6031-f56a-4e1c-a586-bec98af158c3","banner":null,"lang":"en","date_modified":"2021-02-08","date_modified_ts":"2021-02-08T19:21:37Z","date_created":"2021-02-08T16:38:06Z","summary":null,"body":["<article data-history-node-id=\"2299\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-066<br \/>\nDate: 8 February 2021<\/strong><\/p>\n\n<p>Between 1 and 7 February 2021 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Aspera High-Speed Transfer Server - versions 3.9.6.2 and prior<\/li>\n\t<li>IBM Aspera High-Speed Transfer Endpoint - versions 3.9.6.2 and prior<\/li>\n\t<li>IBM API Connect - versions 5.0.0.0 to 5.0.8.10, 10.0.1.0 and 2018.4.1.0 to 2018.4.1.13<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - versions 8.1.0.0 to 8.1.10.0 and 7.1.0.0 to 7.1.8.9<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - versions 8.1.0.0 to 8.1.10.0<\/li>\n\t<li>IBM Spectrum Protect Snapshot for VMware - versions 4.1.0.0 to 4.1.6.10<\/li>\n\t<li>IBM MQ certified container software - versions 1.0.x, 1.1.x, 1.2.x and 1.3.x (EUS)<\/li>\n\t<li>IBM Cognos Business Intelligence \u2013 version 10.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-35","alert_type":396,"serial_number":"AV21-066","subject":null,"moderation_state":"published","external_url":null},{"nid":2300,"title":"[Control systems] Schneider Electric security advisory","uuid":"228f14d3-8036-4f2f-85ae-b60832551faf","banner":null,"lang":"en","date_modified":"2021-02-09","date_modified_ts":"2021-02-09T18:36:08Z","date_created":"2021-02-09T18:25:15Z","summary":null,"body":["<article data-history-node-id=\"2300\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-067<br \/>\nDate: 9 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 Schneider Electric published Security Notifications to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PowerLogic\n\t<ul><li>ION7400 - versions prior to 3.0.0<\/li>\n\t\t<li>ION7650 - all versions<\/li>\n\t\t<li>ION7700\/73xx - all versions<\/li>\n\t\t<li>ION83xx\/84xx\/85xx\/8600 - all versions<\/li>\n\t\t<li>ION8650 - versions prior to 4.31.2<\/li>\n\t\t<li>ION8800 - all versions<\/li>\n\t\t<li>ION9000 - versions prior to 3.0.0<\/li>\n\t\t<li>PM8000 - versions prior to 3.0.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>PowerLogic<br \/><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-040-01\">https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-040-01<\/a><\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-15","alert_type":398,"serial_number":"AV21-067","subject":null,"moderation_state":"published","external_url":null},{"nid":2301,"title":"SAP security advisory \u2013 February 2021 monthly rollup","uuid":"e5dcb05a-37d3-4a2f-9a6e-6baa8358cbd8","banner":null,"lang":"en","date_modified":"2021-02-09","date_modified_ts":"2021-02-09T18:37:52Z","date_created":"2021-02-09T18:28:50Z","summary":null,"body":["<article data-history-node-id=\"2301\" about=\"\/en\/alerts-advisories\/sap-security-advisory-february-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-068<br \/>\nDate: 9 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>SAP Business Client - version 6.5<\/li>\n\t<li>SAP Commerce - multiple versions<\/li>\n\t<li>SAP Business Warehouse - multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 February 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=568460543\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=568460543<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-february-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-068","subject":null,"moderation_state":"published","external_url":null},{"nid":2302,"title":"Intel security advisory","uuid":"fa75959f-c10d-4c0e-92be-1d082e7a4f8f","banner":null,"lang":"en","date_modified":"2021-02-09","date_modified_ts":"2021-02-09T20:09:24Z","date_created":"2021-02-09T20:09:24Z","summary":null,"body":["<article data-history-node-id=\"2302\" about=\"\/en\/alerts-advisories\/intel-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-069<br \/>\nDate: 9 February 2021<\/strong><\/p>\n\n<p>On 9 February 2020 Intel published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Intel Server Boards, Server Systems and Compute Modules - multiple versions and platforms<\/li>\n\t<li>Intel Graphics Drivers - multiple versions and platforms<\/li>\n\t<li>Intel XMM 7360 Cell Modem \u2013 UDE versions prior to 9.4.370<\/li>\n\t<li>Intel SSD Toolbox \u2013 all versions.\n\t<ul><li>Intel recommends replacing Intel SSD Toolbox with Intel Memory and Storage Tool.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Intel Product Security Center Advisories<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-16","alert_type":396,"serial_number":"AV21-069","subject":null,"moderation_state":"published","external_url":null},{"nid":2303,"title":"[Control systems] Siemens security advisory","uuid":"291d265b-1c7c-459a-8142-3d97ed3412f8","banner":null,"lang":"en","date_modified":"2021-02-09","date_modified_ts":"2021-02-09T20:14:06Z","date_created":"2021-02-09T20:14:06Z","summary":null,"body":["<article data-history-node-id=\"2303\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-070<br \/>\nDate: 9 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>DIGSI 4 - versions prior to 4.94 SP1 HF 1<\/li>\n\t<li>JT2Go - versions prior to 13.1.0.1<\/li>\n\t<li>Nucleus NET - versions prior to 5.2<\/li>\n\t<li>Nucleus ReadyStart for ARM, MIPS, and PPC - versions prior to 2012.12<\/li>\n\t<li>PCS neo (Administration Console) - version 3.0<\/li>\n\t<li>RUGGEDCOM ROX - versions prior to 2.14.0<\/li>\n\t<li>SCALANCE W780 and W740 (IEEE 802.11n) family - versions prior to 6.3<\/li>\n\t<li>SIMARIS configuration - all versions<\/li>\n\t<li>SIMATIC PCS 7 - all versions<\/li>\n\t<li>SIMATIC WinCC - versions prior to 7.5 SP2<\/li>\n\t<li>SINEC NMS - versions prior to 1.0 SP1 Update 1<\/li>\n\t<li>SINEMA Server - versions prior to 14.0 SP2 Update 2<\/li>\n\t<li>Teamcenter Visualization - versions prior to 13.1.0.1<\/li>\n\t<li>TIA Portal - versions 15, 15.1 and 16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-20","alert_type":398,"serial_number":"AV21-070","subject":null,"moderation_state":"published","external_url":null},{"nid":2304,"title":"Apple security advisory","uuid":"5bd4188d-921c-46e4-8779-fd10ea9ed630","banner":null,"lang":"en","date_modified":"2021-02-10","date_modified_ts":"2021-02-10T12:55:54Z","date_created":"2021-02-10T12:55:54Z","summary":null,"body":["<article data-history-node-id=\"2304\" about=\"\/en\/alerts-advisories\/apple-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-071<br \/>\nDate:\u00a010 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 Apple published a Security Update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Big Sur \u2013 versions prior to 11.2.1<\/li>\n\t<li>macOS Catalina \u2013 versions prior to 10.15.7 (build number 19H524)<\/li>\n\t<li>macOS Mojave \u2013 versions prior to 10.14.6 Security Update 2021-002<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates (macOS)<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212177\">https:\/\/support.apple.com\/en-ca\/HT212177<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-25","alert_type":396,"serial_number":"AV21-071","subject":null,"moderation_state":"published","external_url":null},{"nid":2305,"title":"Adobe security advisory","uuid":"d0d01531-e3b7-4f17-89f8-da72c235fa81","banner":null,"lang":"en","date_modified":"2021-02-10","date_modified_ts":"2021-02-10T13:00:42Z","date_created":"2021-02-10T13:00:42Z","summary":null,"body":["<article data-history-node-id=\"2305\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-072<br \/>\nDate:\u00a010 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 Adobe published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Acrobat \u2013 versions prior to 2020.013.20074, 2020.001.30018 and 2017.011.30188<\/li>\n\t<li>Adobe Animate \u2013 versions 21.0.2 and prior<\/li>\n\t<li>Adobe Dreamweaver \u2013 versions 20.2, 21.0 and prior<\/li>\n\t<li>Adobe Illustrator \u2013 versions 25.2 and prior<\/li>\n\t<li>Magento \u2013 versions prior to 2.4.1, 2.4.0-p1 and 2.3.6<\/li>\n\t<li>Adobe Photoshop \u2013 versions prior to 21.2.4 and 22.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-35","alert_type":396,"serial_number":"AV21-072","subject":null,"moderation_state":"published","external_url":null},{"nid":2306,"title":"Microsoft security advisory \u2013 February 2021 monthly rollup","uuid":"c4b9b8ba-e88f-432c-b096-711f090010ce","banner":null,"lang":"en","date_modified":"2021-02-10","date_modified_ts":"2021-02-10T15:23:48Z","date_created":"2021-02-10T15:23:48Z","summary":null,"body":["<article data-history-node-id=\"2306\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-february-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-073<br \/>\nDate: 10 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>.NET (Core\/Framework)<\/li>\n\t<li>Windows 10, 8.1 and 7<\/li>\n\t<li>Windows RT<\/li>\n\t<li>Windows Server<\/li>\n<\/ul><p>Included in this update is the default enablement of Domain Controller enforcement mode, which blocks insecure NRPC connections from non-compliant devices.\u00a0 This update also addresses a vulnerability in Windows Win32k which may result in an escalation of privilege resulting in full system compromise. Microsoft has confirmed this vulnerability has been detected in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<br \/>\nFebruary 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Feb\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Feb<\/a><\/p>\n\n<p>Netlogon Domain Controller Enforcement Mode - related to CVE-2020-1472<br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/01\/14\/netlogon-domain-controller-enforcement-mode-is-enabled-by-default-beginning-with-the-february-9-2021-security-update-related-to-cve-2020-1472\/\">https:\/\/msrc-blog.microsoft.com\/2021\/01\/14\/netlogon-domain-controller-enforcement-mode-is-enabled-by-default-beginning-with-the-february-9-2021-security-update-related-to-cve-2020-1472\/<\/a><\/p>\n\n<p>Windows Win32k Elevation of Privilege Vulnerability<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-1732\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-1732<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-february-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-073","subject":null,"moderation_state":"published","external_url":null},{"nid":2307,"title":"[Control systems] GE Digital security advisory","uuid":"9e9ff26f-315b-4ed1-ab3d-53c58a1a5e5b","banner":null,"lang":"en","date_modified":"2021-02-10","date_modified_ts":"2021-02-10T15:29:52Z","date_created":"2021-02-10T15:29:52Z","summary":null,"body":["<article data-history-node-id=\"2307\" about=\"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-074<br \/>\nDate: 10 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>HMI\/SCADA iFIX \u2013 versions 6.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an attacker to escalate their privileges.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<br \/>\nICS Advisory (ICSA-21-04-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-040-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-040-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-0","alert_type":398,"serial_number":"AV21-074","subject":null,"moderation_state":"published","external_url":null},{"nid":2308,"title":"[Control systems] Advantech security advisory","uuid":"3b0dc6d9-f02e-4c64-8658-6f3b099f6181","banner":null,"lang":"en","date_modified":"2021-02-10","date_modified_ts":"2021-02-10T15:33:43Z","date_created":"2021-02-10T15:33:43Z","summary":null,"body":["<article data-history-node-id=\"2308\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-075<br \/>\nDate: 10 February 2021<\/strong><\/p>\n\n<p>On 9 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Advantech iView \u2013 versions prior to v5.7.03.6112<\/li>\n<\/ul><p>Exploitation of this vulnerability may allow disclosure of information, an escalation of privileges to the administrator, perform an arbitrary file read, and remotely execute commands.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<br \/>\nICS Advisory (ICSA-21-040-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-040-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-040-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-11","alert_type":398,"serial_number":"AV21-075","subject":null,"moderation_state":"published","external_url":null},{"nid":2309,"title":"Palo Alto Networks security advisory","uuid":"e8cb58f4-93fd-439d-a758-617c060a5e28","banner":null,"lang":"en","date_modified":"2021-02-11","date_modified_ts":"2021-02-11T15:11:02Z","date_created":"2021-02-11T15:11:02Z","summary":null,"body":["<article data-history-node-id=\"2309\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-076<br \/>\nDate: 11 February 2021<\/strong><\/p>\n\n<p>On 10 February 2021 Palo Alto Networks published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Prisma Cloud Compute \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a malicious actor to bypass signature validation during SAML authentication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p>CVE-2021-3033 Prisma Cloud Compute: SAML Authentication Bypass Vulnerability in Console<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3033\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3033<\/a><\/p>\n\n<p>Palo Alto Networks Security Advisories<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-6","alert_type":396,"serial_number":"AV21-076","subject":null,"moderation_state":"published","external_url":null},{"nid":2310,"title":"[Control systems] Multiple Embedded TCP\/IP Stacks security advisory","uuid":"69ec78fa-8276-40a5-8b81-d6af245b7b3f","banner":null,"lang":"en","date_modified":"2021-02-12","date_modified_ts":"2021-02-12T13:21:23Z","date_created":"2021-02-12T13:21:23Z","summary":null,"body":["<article data-history-node-id=\"2310\" about=\"\/en\/alerts-advisories\/control-systems-multiple-embedded-tcpip-stacks-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-078<br \/>\nDate: 12 February 2021<\/strong><\/p>\n\n<p>On 11 February 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Nut\/Net - versions 5.1 and prior<\/li>\n\t<li>\u00a0CycloneTCP - versions 1.9.6 and prior<\/li>\n\t<li>\u00a0NDKTCPIP - versions 2.25 and prior<\/li>\n\t<li>\u00a0FNET - version 4.6.3<\/li>\n\t<li>\u00a0uIP-Contiki-OS - versions 3.0 and prior<\/li>\n\t<li>\u00a0uC\/TCP-IP - versions 3.6.0 and prior<\/li>\n\t<li>\u00a0uIP-Contiki-NG - versions 4.5 and prior<\/li>\n\t<li>\u00a0uIP - versions 1.0 and prior<\/li>\n\t<li>\u00a0picoTCP-NG - versions 1.7.0 and prior<\/li>\n\t<li>\u00a0picoTCP - versions 1.7.0 and prior<\/li>\n\t<li>\u00a0MPLAB Net - versions 3.6.1 and prior<\/li>\n\t<li>\u00a0Nucleus NET \u2013 versions prior to 5.2<\/li>\n\t<li>\u00a0Nucleus ReadyStart for ARM, MIPS, and PPC \u2013 versions prior to 2012.12<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could enable a malicious actor to hijack or spoof TCP connections, cause a denial-of-service, inject of malicious code or bypass authentication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-042-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-042-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-042-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-multiple-embedded-tcpip-stacks-security-advisory-0","alert_type":398,"serial_number":"AV21-078","subject":null,"moderation_state":"published","external_url":null},{"nid":2311,"title":"[Control systems] Rockwell Automation security advisory","uuid":"3a81b662-edaa-47cf-bb2e-3663a091356f","banner":null,"lang":"en","date_modified":"2021-02-12","date_modified_ts":"2021-02-12T13:30:53Z","date_created":"2021-02-12T13:30:53Z","summary":null,"body":["<article data-history-node-id=\"2311\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-077<br \/>\nDate: 12 February 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 11 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>\u00a0DriveTools SP \u2013 versions 5.13 and prior<\/li>\n\t<li>\u00a0DriveExecutive \u2013 versions 5.13 and prior<\/li>\n\t<li>\u00a0Drives AOP \u2013 versions 4.12 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability by a local malicious actor with limited privileges could result in privilege escalation or complete loss of control of the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-042-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-042-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-042-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-10","alert_type":398,"serial_number":"AV21-077","subject":null,"moderation_state":"published","external_url":null},{"nid":2312,"title":"IBM security advisory","uuid":"6ddbe2cd-697b-4d71-8efc-e36366764672","banner":null,"lang":"en","date_modified":"2021-02-15","date_modified_ts":"2021-02-15T16:34:27Z","date_created":"2021-02-15T16:34:27Z","summary":null,"body":["<article data-history-node-id=\"2312\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-079<br \/>\nDate: 15 February 2021<\/strong><\/p>\n\n<p>Between 8 and 14 February 2021 IBM published a Security Bulletin to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>IBM SDK, Java Technology Edition \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM SDK, Java Technology Edition<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-may-affect-ibm-sdk-java-technology-edition-7\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-may-affect-ibm-sdk-java-technology-edition-7\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-36","alert_type":396,"serial_number":"AV21-079","subject":null,"moderation_state":"published","external_url":null},{"nid":2313,"title":"APT-associated intrusion campaign targeting Centreon software (CERT-FR)","uuid":"71c5d340-b6f8-4ae4-a7fb-0e8a68bbbdc5","banner":null,"lang":"en","date_modified":"2021-02-15","date_modified_ts":"2021-02-15T20:12:16Z","date_created":"2021-02-15T20:03:47Z","summary":null,"body":["<article data-history-node-id=\"2313\" about=\"\/en\/alerts-advisories\/apt-associated-intrusion-campaign-targeting-centreon-software-cert-fr\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-002\n  <br \/>\n  Date: 15 February 2021<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\u00a0\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>ASSESSMENT\n<\/h3>\n<p>On 15 February 2021 CERT-FR published an Agence nationale de la s\u00e9curit\u00e9 des syst\u00e8mes d'information (ANSSI) report describing an assessed Advanced Persistent Threat (APT)-associated intrusion set found on the compromised servers of multiple French entities running Centreon, an IT monitoring product produced by a French company of the same name.\n<\/p>\n<p>The report details several components of the intrusion set including malware and C2 infrastructure. Detection and mitigation advice are proposed and Indicators of Compromise (IOCs) supplied.\n<\/p>\n<p>The Cyber Centre would like to highlight the report, as it provides important prevention, detection and mitigation advice to system owners and operators responsible for defending their systems and networks from cyber threats.\n<\/p>\n<p>Should organizations identify similar activity to that described in the referenced report, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>Report \u2013 ANSSI\n  <br \/><a href=\"https:\/\/www.cert.ssi.gouv.fr\/cti\/CERTFR-2021-CTI-005\/\">https:\/\/www.cert.ssi.gouv.fr\/cti\/CERTFR-2021-CTI-005\/<\/a>\u00a0\n<\/p>\n<p>\n  <br \/><strong>Note to Readers<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apt-associated-intrusion-campaign-targeting-centreon-software-cert-fr","alert_type":397,"serial_number":"AL21-002","subject":null,"moderation_state":"published","external_url":null},{"nid":2314,"title":"IBM security advisory","uuid":"abf90404-a3ab-4d46-ad05-5095a66961ce","banner":null,"lang":"en","date_modified":"2021-02-22","date_modified_ts":"2021-02-22T18:27:31Z","date_created":"2021-02-22T18:25:48Z","summary":null,"body":["<article data-history-node-id=\"2314\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-087<br \/><strong>Date: 22 February 2021<\/strong><\/strong><\/p>\n\n<p>Between 15 and 21 February 2021 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Spectrum Conductor - version 2.5.0<\/li>\n\t<li>IBM Spectrum Symphony - version 7.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Spectrum Conductor<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerability-issues-affect-ibm-spectrum-conductor-2-5-0\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerability-issues-affect-ibm-spectrum-conductor-2-5-0\/<\/a><\/p>\n\n<p>IBM Spectrum Symphony<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerability-issues-affect-ibm-spectrum-symphony-7-3-1\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerability-issues-affect-ibm-spectrum-symphony-7-3-1\/<\/a>\u00a0<\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-37","alert_type":396,"serial_number":"AV21-087","subject":null,"moderation_state":"published","external_url":null},{"nid":2315,"title":"HPE security advisory","uuid":"727db4ad-6057-4d10-9bb3-f66e765e345e","banner":null,"lang":"en","date_modified":"2021-02-22","date_modified_ts":"2021-02-22T18:48:31Z","date_created":"2021-02-22T18:43:36Z","summary":null,"body":["<article data-history-node-id=\"2315\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-086<br \/>\nDate: 22 February 2021<\/strong><\/p>\n\n<p>On 19 February 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ClearPass 6.9.x \u2013 versions prior to 6.9.5<\/li>\n\t<li>ClearPass 6.8.x \u2013 versions prior to 6.8.8-HF1<\/li>\n\t<li>ClearPass 6.7.x \u2013 versions prior to 6.7.14-HF1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in authentication bypass, privilege escalation, execution of arbitrary commands, unauthenticated code execution, unauthorized access and server-side request forgery (SSRF).<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (Aruba ClearPass Policy Manager)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04089en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04089en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-9","alert_type":396,"serial_number":"AV21-086","subject":null,"moderation_state":"published","external_url":null},{"nid":2316,"title":"Python security advisory","uuid":"d6846dab-3353-4afe-8a26-8affadb32031","banner":null,"lang":"en","date_modified":"2021-02-23","date_modified_ts":"2021-02-23T17:41:42Z","date_created":"2021-02-23T17:30:02Z","summary":null,"body":["<article data-history-node-id=\"2316\" about=\"\/en\/alerts-advisories\/python-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-088<br \/>\nDate: 23 February 2021<\/strong><\/p>\n\n<p>Between 15 February and 19 February 2021, the Python Software Foundation updated Python to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Python 3.6 \u2013 versions prior to 3.6.13<\/li>\n\t<li>Python 3.7 \u2013 versions prior to 3.7.10<\/li>\n\t<li>Python 3.8 \u2013 versions prior to 3.8.8<\/li>\n\t<li>Python 3.9 \u2013 versions prior to 3.9.2<\/li>\n<\/ul><p>These updates resolve a buffer overflow vulnerability which if exploited could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Buffer overflow in PyCArg_rep<br \/><a href=\"https:\/\/python-security.readthedocs.io\/vuln\/ctypes-buffer-overflow-pycarg_repr.html\">https:\/\/python-security.readthedocs.io\/vuln\/ctypes-buffer-overflow-pycarg_repr.html<\/a><\/p>\n\n<p>Python 3.6<br \/><a href=\"https:\/\/www.python.org\/downloads\/release\/python-3613\/\">https:\/\/www.python.org\/downloads\/release\/python-3613\/<\/a><\/p>\n\n<p>Python 3.7<br \/><a href=\"https:\/\/www.python.org\/downloads\/release\/python-3710\/\">https:\/\/www.python.org\/downloads\/release\/python-3710\/<\/a><\/p>\n\n<p>Python 3.8<br \/><a href=\"https:\/\/www.python.org\/downloads\/release\/python-388\/\">https:\/\/www.python.org\/downloads\/release\/python-388\/<\/a><\/p>\n\n<p>Python 3.9<br \/><a href=\"https:\/\/www.python.org\/downloads\/release\/python-392\/\">https:\/\/www.python.org\/downloads\/release\/python-392\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/python-security-advisory","alert_type":396,"serial_number":"AV21-088","subject":null,"moderation_state":"published","external_url":null},{"nid":2317,"title":"Mozilla security advisory","uuid":"1f79a28a-0952-48b1-8c96-db4c1dec7611","banner":null,"lang":"en","date_modified":"2021-02-23","date_modified_ts":"2021-02-23T18:02:08Z","date_created":"2021-02-23T18:01:35Z","summary":null,"body":["<article data-history-node-id=\"2317\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-089<br \/>\nDate: 23 February 2021<\/strong><\/p>\n\n<p>On 23 February 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Firefox \u2013 versions prior to 86<\/li>\n\t<li>\u00a0Firefox ESR \u2013 versions prior to 78.8<\/li>\n\t<li>\u00a0Thunderbird \u2013 versions prior to 78.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-07)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-07\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-07\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-08)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-08\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-08\/<\/a><\/p>\n\n<p>Thunderbird (MFSA 2021-09)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-09\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-09\/<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-33","alert_type":396,"serial_number":"AV21-089","subject":null,"moderation_state":"published","external_url":null},{"nid":2318,"title":"Google Chrome security advisory","uuid":"d413cd72-d395-4af1-b1a9-218ea437277e","banner":null,"lang":"en","date_modified":"2021-02-23","date_modified_ts":"2021-02-23T19:16:59Z","date_created":"2021-02-23T19:16:59Z","summary":null,"body":["<article data-history-node-id=\"2318\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-46\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-090<br \/>\nDate: 23 February 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 22 February 2021 Google published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Chrome for Desktop (Windows) \u2013 versions prior to 88.0.4324.190<\/li>\n\t<li>\u00a0Chrome for Desktop (macOS) - versions prior to 88.0.4324.192<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/02\/stable-channel-update-for-desktop_22.html\">https:\/\/chromereleases.googleblog.com\/2021\/02\/stable-channel-update-for-desktop_22.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-46","alert_type":396,"serial_number":"AV21-090","subject":null,"moderation_state":"published","external_url":null},{"nid":2319,"title":"[Control systems] Advantech security advisory","uuid":"6efe0398-71a0-4b82-9a6c-cbff535c70c3","banner":null,"lang":"en","date_modified":"2021-02-24","date_modified_ts":"2021-02-24T16:59:20Z","date_created":"2021-02-24T16:53:28Z","summary":null,"body":["<article data-history-node-id=\"2319\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-091<br \/>\nDate: 24 February 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 23 February 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Advantech BB-ESWGP506-2SFP-T industrial ethernet switches - version 1.01.09 and prior<\/li>\n\t<li>Advantech Spectre RT ERT351 - version 5.1.3 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow credential theft, unauthorized access, arbitrary code execution, information disclosure, file deletion or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-054-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-054-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-12","alert_type":398,"serial_number":"AV21-091","subject":null,"moderation_state":"published","external_url":null},{"nid":2320,"title":"[Control systems] Rockwell Automation security advisory","uuid":"5313d03a-6c8f-4090-bc8d-6aaf0d1ae473","banner":null,"lang":"en","date_modified":"2021-02-24","date_modified_ts":"2021-02-24T19:10:03Z","date_created":"2021-02-24T19:10:03Z","summary":null,"body":["<article data-history-node-id=\"2320\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-092<br \/>\nDate: 24 February 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 23 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>FactoryTalk Services Platform \u2013 versions 6.10.00 and 6.11.00<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to create new user accounts and modify or delete configuration and application data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-054-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-11","alert_type":398,"serial_number":"AV21-092","subject":null,"moderation_state":"published","external_url":null},{"nid":2321,"title":"VMware security advisory","uuid":"39b0f201-4f88-40f8-80e0-2bd9f27ed063","banner":null,"lang":"en","date_modified":"2021-02-24","date_modified_ts":"2021-02-24T19:15:00Z","date_created":"2021-02-24T19:15:00Z","summary":null,"body":["<article data-history-node-id=\"2321\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-093<br \/>\nDate: 24 February 2021<\/strong><\/p>\n\n<p>On 23 February 2021 VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware ESXi - versions 6.5, 6.7 and 7.0<\/li>\n\t<li>VMware vCenter Server (vCenter Server) - versions 6.5, 6.7 and 7.0<\/li>\n\t<li>VMware Cloud Foundation (Cloud Foundation) - versions 3.x and 4.x<\/li>\n<\/ul><p>Of note is a critical vulnerability which, if exploited, could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0002)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0002.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0002.html<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-35","alert_type":396,"serial_number":"AV21-093","subject":null,"moderation_state":"published","external_url":null},{"nid":2322,"title":"Cisco security advisory","uuid":"f1a6ff8a-be47-463e-a464-103c2406348d","banner":null,"lang":"en","date_modified":"2021-02-25","date_modified_ts":"2021-02-25T16:35:31Z","date_created":"2021-02-25T16:35:31Z","summary":null,"body":["<article data-history-node-id=\"2322\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-76\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-094<br \/>\nDate: 25 February 2021<\/strong><\/p>\n\n<p>On 24 February 2020 Cisco published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Nexus 3000 Series Switches with NX-OS Software \u2013 versions 9.3(5) and 9.3(6)<\/li>\n\t<li>Nexus 9000 Series Switches in standalone NX-OS mode - versions 9.3(5) and 9.3(6)<\/li>\n\t<li>Cisco Application Services Engine - version 1.1(3d) and prior<\/li>\n\t<li>Cisco ACI Multi-Site Orchestrator (MSO) running a 3.0 release software when deployed on a Cisco Application Services Engine<\/li>\n<\/ul><p>Exploitation could allow an unauthenticated remote actor to bypass authentication, gain privileged access or create, delete, or overwrite arbitrary files with root privileges on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Nexus 3000 Series Switches and Nexus 9000 Series Switches in standalone NX-OS mode<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-3000-9000-fileaction-QtLzDRy2\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-3000-9000-fileaction-QtLzDRy2<\/a><\/p>\n\n<p>Cisco Application Services Engine<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-case-mvuln-dYrDPC6w\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-case-mvuln-dYrDPC6w<\/a><\/p>\n\n<p>Cisco ACI Multi-Site Orchestrator (MSO)<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-mso-authbyp-bb5GmBQv\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-mso-authbyp-bb5GmBQv<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-76","alert_type":396,"serial_number":"AV21-094","subject":null,"moderation_state":"published","external_url":null},{"nid":2323,"title":"[Control systems] Rockwell Automation security advisory","uuid":"43e4bafa-fae2-41a6-9bfd-d9737a5bfd5a","banner":null,"lang":"en","date_modified":"2021-02-26","date_modified_ts":"2021-02-26T14:41:24Z","date_created":"2021-02-26T14:40:44Z","summary":null,"body":["<article data-history-node-id=\"2323\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-095<br \/>\nDate: 26 February 2021<\/strong><\/p>\n\n<p>On 26 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>\u00a0\u00a0\u00a0\u00a0 RSLogix 5000 - versions 16 to 20<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 Studio 5000 Logix Designer - version 21 and later<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 CompactLogix 1768<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 CompactLogix 1769<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 CompactLogix 5370<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 CompactLogix 5380<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 CompactLogix 5480<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 ControlLogix 5550<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 ControlLogix 5560<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 ControlLogix 5570<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 ControlLogix 5580<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 DriveLogix 5560<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 DriveLogix 5730<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 DriveLogix 1794-L34<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 Compact GuardLogix 5370<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 Compact GuardLogix 5380<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 GuardLogix 5570<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 GuardLogix 5580<\/li>\n\t<li>\u00a0\u00a0\u00a0\u00a0 SoftLogix 5800<\/li>\n<\/ul><p>Exploitation could allow a remote unauthenticated actor to connect Logix controllers, or enable an unauthorized third-party tool to alter the controller\u2019s configuration and\/or application code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-056-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-12","alert_type":398,"serial_number":"AV21-095","subject":null,"moderation_state":"published","external_url":null},{"nid":2324,"title":"Ubuntu security advisory","uuid":"fe0c8715-02d9-4e04-a33e-7b52c78f58c8","banner":null,"lang":"en","date_modified":"2021-02-26","date_modified_ts":"2021-02-26T14:45:31Z","date_created":"2021-02-26T14:45:31Z","summary":null,"body":["<article data-history-node-id=\"2324\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-096<br \/>\nDate: 26 February 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 25 February 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>\u00a0Ubuntu 20.10<\/li>\n\t<li>\u00a0Ubuntu 20.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 18.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 16.04 LTS<\/li>\n\t<li>\u00a0Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, data modification, access to sensitive information, writing to read-only portions of memory or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-8","alert_type":396,"serial_number":"AV21-096","subject":null,"moderation_state":"published","external_url":null},{"nid":2325,"title":"[Control systems] PerFact security advisory","uuid":"96c9cc04-d126-46c5-9a39-4ff395f41437","banner":null,"lang":"en","date_modified":"2021-02-26","date_modified_ts":"2021-02-26T14:49:03Z","date_created":"2021-02-26T14:49:03Z","summary":null,"body":["<article data-history-node-id=\"2325\" about=\"\/en\/alerts-advisories\/control-systems-perfact-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-097<br \/>\nDate: 26 February 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 25 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>\u00a0OpenVPN-Client \u2013 versions 1.4.1.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow for local privilege escalation or remote code execution through a malicious webpage.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-056-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-perfact-security-advisory","alert_type":398,"serial_number":"AV21-097","subject":null,"moderation_state":"published","external_url":null},{"nid":2326,"title":"[Control systems] ProSoft Technology security advisory","uuid":"168695bf-9674-40bd-b981-31eb17c3a31a","banner":null,"lang":"en","date_modified":"2021-02-26","date_modified_ts":"2021-02-26T14:52:27Z","date_created":"2021-02-26T14:52:27Z","summary":null,"body":["<article data-history-node-id=\"2326\" about=\"\/en\/alerts-advisories\/control-systems-prosoft-technology-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-098<br \/>\nDate: 26 February 2021<\/strong><\/p>\n\n<p>On 25 February 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>\u00a0ICX35-HWC-A - version 1.9.62 and prior\u00a0<\/li>\n\t<li>\u00a0ICX35-HWC-E - version 1.9.62 and prior<\/li>\n<\/ul><p>Exploitation could allow and actor to change the current user\u2019s password and alter device configurations.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-056-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-prosoft-technology-security-advisory","alert_type":398,"serial_number":"AV21-098","subject":null,"moderation_state":"published","external_url":null},{"nid":2327,"title":"[Control systems] Fatek security advisory","uuid":"247cdc0b-e5af-4c4f-a9fb-98ef286d44bd","banner":null,"lang":"en","date_modified":"2021-02-26","date_modified_ts":"2021-02-26T19:22:02Z","date_created":"2021-02-26T19:22:02Z","summary":null,"body":["<article data-history-node-id=\"2327\" about=\"\/en\/alerts-advisories\/control-systems-fatek-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-099<br \/>\nDate: 26 February 2021<\/strong><\/p>\n\n<p>On 25 February 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>FvDesigner - version 1.5.76 and prior<\/li>\n<\/ul><p>Exploitation may allow an actor to read\/modify information, cause a denial-of-service or execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-056-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-056-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-security-advisory","alert_type":398,"serial_number":"AV21-099","subject":null,"moderation_state":"published","external_url":null},{"nid":2328,"title":"IBM security advisory","uuid":"b278f3cd-7605-4991-ba92-208cff62dcc6","banner":null,"lang":"en","date_modified":"2021-03-01","date_modified_ts":"2021-03-01T16:48:56Z","date_created":"2021-03-01T16:48:56Z","summary":null,"body":["<article data-history-node-id=\"2328\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-100<br \/>\nDate: 1 March 2021<\/strong><\/p>\n\n<p>Between 22 and 28 February 2021 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Cloud Private - versions 3.2.1 CD and 3.2.2 CD<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Security Services - versions 2.0, 2.1 and 2.2<\/li>\n\t<li>IBM WIoTP MessageGateway - version 5.0.0.1<\/li>\n\t<li>IBM IoT MessageSight - versions 2.0.0.2 and 5.0.0.0<\/li>\n\t<li>IBM Cloud Automation Manager - version 4.2.0.1<\/li>\n\t<li>Integration Designer - versions 8.5.7, 19.0.0.2, 20.0.0.1 and 20.0.0.2<\/li>\n\t<li>Cloud Pak for Security (CP4S) - versions 1.4.0.0 and 1.5.0.0<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Infrastructure Management \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-38","alert_type":396,"serial_number":"AV21-100","subject":null,"moderation_state":"published","external_url":null},{"nid":2329,"title":"Android security advisory \u2013 March 2021 monthly rollup","uuid":"757f39d2-a16c-4303-b006-2b375b0bb77e","banner":null,"lang":"en","date_modified":"2021-03-01","date_modified_ts":"2021-03-01T19:58:20Z","date_created":"2021-03-01T19:58:20Z","summary":null,"body":["<article data-history-node-id=\"2329\" about=\"\/en\/alerts-advisories\/android-security-advisory-march-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-101<br \/>\nDate: 1 March 2021<\/strong><\/p>\n\n<p>On 1 March 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-03-01\">https:\/\/source.android.com\/security\/bulletin\/2021-03-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-march-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-101","subject":null,"moderation_state":"published","external_url":null},{"nid":2330,"title":"HPE security advisory","uuid":"159b108d-5038-4478-b61a-de60b44cd2a5","banner":null,"lang":"en","date_modified":"2021-03-02","date_modified_ts":"2021-03-02T15:15:50Z","date_created":"2021-03-02T15:15:50Z","summary":null,"body":["<article data-history-node-id=\"2330\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-102<br \/>\nDate: 2 March 2021<\/strong><\/p>\n\n<p>On 1 March 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Internet Express System Software \u2013 versions A.20.00 to A.23.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (Internet Express System Software)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04095en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04095en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-10","alert_type":396,"serial_number":"AV21-102","subject":null,"moderation_state":"published","external_url":null},{"nid":2406,"title":"Active Exploitation of Microsoft Exchange Vulnerabilities - update 4","uuid":"35f9986f-c7d7-45aa-9b57-8fea632f96cb","banner":null,"lang":"en","date_modified":"2021-04-20","date_modified_ts":"2021-04-20T20:50:26Z","date_created":"2021-03-03T03:56:48Z","summary":null,"body":["<article data-history-node-id=\"2406\" about=\"\/en\/alerts-advisories\/active-exploitation-microsoft-exchange-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-003 UPDATE 4\n  <br \/>\n  Date: 2 March 2021\n  <br \/>\n  Updated: 14 April 2021<\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>OVERVIEW\n<\/h2>\n<p>On 2 March 2021, Microsoft published several security updates for Microsoft Exchange Server to address vulnerabilities that have reportedly been used in limited targeted compromises. Security researcher Volexity has reported that the activity appears to have started as early as January 6, 2021.\n<\/p>\n<h2>UPDATE 4\n<\/h2>\n<p>The Cyber Centre is providing additional information within the DETAILS section of this report on new vulnerabilities affecting Microsoft Exchange Server. On releasing updates Microsoft noted that no exploitation of the new vulnerabilities had been detected. However, there is now a renewed risk of similar exploitation to that observed earlier in March 2021, for any systems that have not received the April 2021 updates.\n<\/p>\n<h2>UPDATE 3\n<\/h2>\n<p>On 11 March 2021, Microsoft Security Intelligence issued a Tweet stating that a new family of ransomware, known as DearCry, is being leveraged by actors exploiting the recently disclosed Exchange vulnerabilities. In addition to DearCry, multiple proofs of concepts leveraging the Exchange vulnerabilities resulting in remote code execution have been made publicly available. These vulnerabilities are being leveraged to gain a foothold within an organization\u2019s network for malicious activity which includes but is not limited to ransomware and the exfiltration of data.\n<\/p>\n<p>The Cyber Centre has received reporting that continue to show unpatched systems internationally, including within Canada. Some of these systems within Canada have been further compromised with malware. All organizations are encouraged to refer to the updated Indicators of Compromise and Mitigation sections of this Alert for additional detection, mitigation and post-compromise guidance.\n<\/p>\n<h2>UPDATE 2\n<\/h2>\n<p>On 5 March 2021, the Microsoft Security Response Center published an update to their blog, which outlines alternative mitigation techniques to help organizations that require additional time to complete patching. [<a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/\">6<\/a>] Within the blog Microsoft has reinforced that these mitigation techniques are only a temporary solution and not a replacement to patching. The Cyber Centre continues to strongly encourage organizations follow the original guidance to block access to these services until completely patched with the required updates.\n<\/p>\n<p>Microsoft has stated that the interim mitigations, if patching Exchange Server 2013, 2016, and 2019 are not immediately possible, is to implement an IIS re-write rule and disable Unified Messaging (UM), Exchange Control Panel (ECP) VDir, and Offline Address Book (OAB) VDir services. Microsoft cautions these mitigations have some known impact to functionality and would be effective against the malicious activity Microsoft has observed, but they do not guarantee complete mitigation for all possible methods of exploitation.\n<\/p>\n<p>The Cyber Centre cautions that neither interim nor recommended patching solutions fully protect systems, which have been previously compromised. As this activity was originally reported prior to official patches being available, organizations are encouraged to conduct a thorough analysis of any systems that may be affected by these vulnerabilities using resources provided by Microsoft. [<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/\"><font color=\"#0066cc\">3<\/font><\/a>]\n<\/p>\n<h2>UPDATE\n<\/h2>\n<p>The Cyber Centre has learned that malicious actors are actively scanning using automated tools to identify unpatched servers. [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/03\/04\/update-alert-mitigating-microsoft-exchange-server-vulnerabilities\">5<\/a>] The Cyber Centre strongly recommends organizations with unpatched external facing servers perform the following:\n<\/p>\n<ul><li>\u00a0Immediately disconnect the server from external interfaces<\/li>\n  <li>\u00a0Follow Microsoft guidance to determine compromise [<a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/02\/multiple-security-updates-released-for-exchange-server\/\">4<\/a>]<\/li>\n  <li>If no compromise has been identified follow the below patching recommendations<\/li>\n<\/ul><p>Microsoft has stated the following versions and cumulative updates (CU) to Exchange must be installed prior to the security update.\n<\/p>\n<ul><li>\u00a0Exchange Server 2010 (update requires SP 3 or any SP 3 RU \u2013 this is a Defense in Depth update)<\/li>\n  <li>\u00a0Exchange Server 2013 (update requires CU 23)<\/li>\n  <li>\u00a0Exchange Server 2016 (update requires CU 19 or CU 18)<\/li>\n  <li>\u00a0Exchange Server 2019 (update requires CU 8 or CU 7)<\/li>\n<\/ul><p>Note: All updates (CU and the security update) must be run as administrator and Microsoft has noted that multiple reboots may be required. Additional information on patching is available through Microsoft's tech community blog. [<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-march-2021-exchange-server-security-updates\/ba-p\/2175901\">1<\/a>]\n<\/p>\n<p>Organizations are encouraged to confirm that no signs of malicious activity have been detected and that both the CU and security update are successful prior to returning the server to service.\n<\/p>\n<h2>DETAILS\n<\/h2>\n<p>Microsoft has published out-of-band Security Updates to address critical vulnerabilities in multiple Exchange products [<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-march-2021-exchange-server-security-updates\/ba-p\/2175901\">1<\/a>]:\n<\/p>\n<ul><li>\u00a0Microsoft Exchange Server 2013\u00a0<\/li>\n  <li>\u00a0Microsoft Exchange Server 2016\u00a0<\/li>\n  <li>\u00a0Microsoft Exchange Server 2019<\/li>\n<\/ul><p>Volexity has also published a blog detailing observed activity of actors remotely exploiting a zero-day server-side request forgery (SSRF) vulnerability in Microsoft Exchange (CVE-2021-26855) [<a href=\"https:\/\/www.volexity.com\/blog\/2021\/03\/02\/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities\/\">2<\/a>]. This method of exploitation does not require authentication and can be accomplished through remote access to a vulnerable external facing Exchange server over HTTPS.\n<\/p>\n<p>Microsoft has reported the following vulnerabilities were used by actors to gain access to victim systems [<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/\">3<\/a>]:\n<\/p>\n<ul><li>CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Exchange which allowed the actor to send arbitrary HTTP requests and authenticate as the Exchange server.<\/li>\n  <li>CVE-2021-26857 is an insecure deserialization vulnerability in the Unified Messaging service. Insecure deserialization is where untrusted user-controllable data is deserialized by a program. Exploiting this vulnerability gave actors the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.<\/li>\n  <li>CVE-2021-26858 is a post-authentication arbitrary file write vulnerability in Exchange. If actors could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin\u2019s credentials.<\/li>\n  <li>CVE-2021-27065 is a post-authentication arbitrary file write vulnerability in Exchange. If an actor could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin\u2019s credentials.<\/li>\n<\/ul><p>After exploiting these vulnerabilities to gain initial access, malicious actors deployed web shells on the compromised server. Web shells potentially allow actors to steal data and perform additional malicious actions that lead to further compromise.\n<\/p>\n<p>(Updated 14 April) On 13 April 2021, Microsoft published Security Updates to address vulnerabilities in multiple products. [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-april-2021-monthly-rollup\">10<\/a>] Included were patches for critical vulnerabilities impacting Microsoft Exchange Server. Microsoft has indicated that the vulnerabilities addressed in the April 2021 security updates affecting Microsoft Exchange products are:\n<\/p>\n<ul><li>\u00a0Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-28480)<\/li>\n<\/ul><p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28480\">https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28480<\/a>\n<\/p>\n<ul><li>\u00a0Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-28481)<\/li>\n<\/ul><p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28481\">https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28481<\/a>\n<\/p>\n<ul><li>\u00a0Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-28482)<\/li>\n<\/ul><p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28482\">https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28482<\/a>\n<\/p>\n<ul><li>\u00a0Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-28483)<\/li>\n<\/ul><p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28483\">https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-28483<\/a>\n<\/p>\n<p>The above vulnerabilities are different from those disclosed in March 2021. Organizations that have recently patched in response to the earlier activity need to do so again with the April 2021 security updates. While Microsoft has reported that active exploitation of these vulnerabilities has not been observed, the Cyber Centre recommends organizations patch as soon as possible. Malicious actors will frequently devise methods of exploitation for recently disclosed vulnerabilities such as these, and it is important that systems be at the most recent versions to prevent future compromise.\n<\/p>\n<h2>INDICATORS OF COMPROMISE\n<\/h2>\n<p>Both Microsoft and Volexity have provided a technical analysis of the activity as well as indicators of compromise for defenders to determine impact.\n<\/p>\n<p>Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities\n  <br \/><a href=\"https:\/\/www.volexity.com\/blog\/2021\/03\/02\/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities\/\">https:\/\/www.volexity.com\/blog\/2021\/03\/02\/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities\/<\/a>\n<\/p>\n<p>HAFNIUM targeting Exchange Servers with 0-day exploits\n  <br \/><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/\">https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/<\/a>\n<\/p>\n<p>(Updated 15 March) On 8 March 2021, Microsoft released a feed of observed indicators of compromise, namely, malware hashes and known malicious file paths observed in campaigns leveraging these vulnerabilities. [<a href=\"https:\/\/raw.githubusercontent.com\/Azure\/Azure-Sentinel\/master\/Sample%20Data\/Feeds\/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv\">8<\/a>]\n<\/p>\n<p>(Updated 15 March) The Cybersecurity and Infrastructure Security (CISA) has recently updated their Alert (AA21-062A) on guidance for the Microsoft Exchange Server vulnerabilities. Furthermore, they have provided malware analysis reports and additional information into the tactics, techniques and procedures of malicious actors. [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-062a\">9<\/a>]\n<\/p>\n<p>The Cyber Centre recommends that organizations continue to review these organizations for updates and recommendations to best defend their networks, host-based systems, and potential response options to compromise.\n<\/p>\n<h2>MITIGATION\n<\/h2>\n<p>The Cyber Centre recommends that organizations prioritize external facing Exchange servers and immediately apply necessary updates. All affected external servers should have remote access temporarily disabled until patches can be applied. All additional affected Exchange servers should be patched following the completion of higher priority external servers.\n<\/p>\n<p>To limit an initial compromise from occurring future hardening of systems can be accomplished through the restriction of untrusted connections by isolating Exchange servers from external facing connections or using a Virtual Private Network (VPN). Microsoft reports that using these mitigations will only protect against the initial portion of the compromise; other portions of the chain can be triggered if an actor already has access or can convince an administrator to run a malicious file.\n<\/p>\n<p>(Updated 15 March) Microsoft has released multiple scripts to aid in the efforts of determining system compromise: [<a href=\"https:\/\/github.com\/microsoft\/CSS-Exchange\/tree\/main\/Security\">7<\/a>]\n<\/p>\n<ul><li>Test-ProxyLogon.ps1: checks Exchange log files for IOCs associated with the leveraging the 4 vulnerabilities.<\/li>\n  <li>Exchange On-premises Mitigation Tool (EOMT): Microsoft has reported this is the most effective way to help quickly protect and mitigate organizations\u2019 Exchange servers prior to patching.<\/li>\n  <li>http-vuln-cve2021-26855.nse: NMAP script used to determine if the specified URL is vulnerable to CVE-2021-26855.<\/li>\n<\/ul><p>(Updated 15 March) While Microsoft has stated that there has been no observed impact to Exchange server functionality using these, administrators are encouraged to review all advice and guidance prior to running any of the referenced tools.\n<\/p>\n<p>(Updated 15 March) The Cyber Centre recommends organizations review the joint advisory of collaborative research effort by the cybersecurity authorities of five nations: Australia, Canada, New Zealand, the United Kingdom, and the United States. It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.\n<\/p>\n<p>(Updated 15 March) <a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/joint-cybersecurity-advisory\">https:\/\/cyber.gc.ca\/en\/guidance\/joint-cybersecurity-advisory<\/a>\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>[1] Released: March 2021 Exchange Server Security Updates\n  <br \/><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-march-2021-exchange-server-security-updates\/ba-p\/2175901\">https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-march-2021-exchange-server-security-updates\/ba-p\/2175901<\/a>\n<\/p>\n<p>[2] Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities\n  <br \/><a href=\"https:\/\/www.volexity.com\/blog\/2021\/03\/02\/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities\/\">https:\/\/www.volexity.com\/blog\/2021\/03\/02\/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities\/<\/a>\n<\/p>\n<p>[3] HAFNIUM targeting Exchange Servers with 0-day exploits\n  <br \/><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/\">https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/<\/a>\n<\/p>\n<p>[4] Multiple Security Updates Released for Exchange Server\n  <br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/02\/multiple-security-updates-released-for-exchange-server\/\">https:\/\/msrc-blog.microsoft.com\/2021\/03\/02\/multiple-security-updates-released-for-exchange-server\/<\/a>\n<\/p>\n<p>[5] Update to Alert on Mitigating Microsoft Exchange Server Vulnerabilities\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/03\/04\/update-alert-mitigating-microsoft-exchange-server-vulnerabilities\">https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/03\/04\/update-alert-mitigating-microsoft-exchange-server-vulnerabilities<\/a>\n<\/p>\n<p>[6] Microsoft Exchange Server Vulnerabilities Mitigations \u2013 March 2021\n  <br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/\">https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/<\/a>\n<\/p>\n<p>[7] Microsoft CSS-Exchange Security Github\n  <br \/><a href=\"https:\/\/github.com\/microsoft\/CSS-Exchange\/tree\/main\/Security\">https:\/\/github.com\/microsoft\/CSS-Exchange\/tree\/main\/Security<\/a>\n<\/p>\n<p>[8] Microsoft Indicators of Compromise Feed\n  <br \/><a href=\"https:\/\/raw.githubusercontent.com\/Azure\/Azure-Sentinel\/master\/Sample%20Data\/Feeds\/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv\">https:\/\/raw.githubusercontent.com\/Azure\/Azure-Sentinel\/master\/Sample%20Data\/Feeds\/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv<\/a> (CSV)\n  <br \/><a href=\"https:\/\/raw.githubusercontent.com\/Azure\/Azure-Sentinel\/master\/Sample%20Data\/Feeds\/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.json\">https:\/\/raw.githubusercontent.com\/Azure\/Azure-Sentinel\/master\/Sample%20Data\/Feeds\/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.json<\/a> (JSON)\n<\/p>\n<p>[9] Alert (AA21-062A) Mitigate Microsoft Exchange Server Vulnerabilities\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-062a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-062a<\/a>\n<\/p>\n<p>[10] Microsoft Security Advisory \u2013 April 2021 Monthly Rollup\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-april-2021-monthly-rollup\">https:\/\/cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-april-2021-monthly-rollup<\/a>\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-microsoft-exchange-vulnerabilities","alert_type":397,"serial_number":"AL21-003","subject":null,"moderation_state":"published","external_url":null},{"nid":2331,"title":"[Control systems] MB connect line security advisory","uuid":"142fcda6-403f-4da3-8494-3e66ae76952e","banner":null,"lang":"en","date_modified":"2021-03-03","date_modified_ts":"2021-03-03T14:56:39Z","date_created":"2021-03-03T14:56:39Z","summary":null,"body":["<article data-history-node-id=\"2331\" about=\"\/en\/alerts-advisories\/control-systems-mb-connect-line-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-103<br \/>\nDate: 3 March 2021<\/strong><\/p>\n\n<p>On 2 March 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0mymbCONNECT24 \u2013 version 2.6.1 and prior<\/li>\n\t<li>\u00a0mbCONNECT24 - version 2.6.1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow information disclosure or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-061-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-061-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-061-03<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mb-connect-line-security-advisory-0","alert_type":398,"serial_number":"AV21-103","subject":null,"moderation_state":"published","external_url":null},{"nid":2332,"title":"[Control systems] Rockwell Automation security advisory","uuid":"777a48cb-1312-4836-aad3-443a87d769b2","banner":null,"lang":"en","date_modified":"2021-03-03","date_modified_ts":"2021-03-03T15:01:47Z","date_created":"2021-03-03T15:01:47Z","summary":null,"body":["<article data-history-node-id=\"2332\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-104<br \/>\nDate: 3 March 2021<\/strong><\/p>\n\n<p>On 2 March 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>\u00a0Armor Compact GuardLogix 5370 controllers - version 33 and prior<\/li>\n\t<li>\u00a0Armor GuardLogix, Safety Controllers - version 33 and prior<\/li>\n\t<li>\u00a0CompactLogix 5370 L1 controllers - version 33 and prior<\/li>\n\t<li>\u00a0CompactLogix 5370 L2 controllers - version 33 and prior<\/li>\n\t<li>\u00a0CompactLogix 5370 L3 controllers - version 33 and prior<\/li>\n\t<li>\u00a0Compact GuardLogix 5370 controllers - version 33 and prior<\/li>\n\t<li>\u00a0ControlLogix 5570 controllers - version 33 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-061-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-061-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-061-02<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-13","alert_type":398,"serial_number":"AV21-104","subject":null,"moderation_state":"published","external_url":null},{"nid":2333,"title":"Google Chrome security advisory","uuid":"fb2d0dc4-271f-43cf-95d6-aecf2fb92452","banner":null,"lang":"en","date_modified":"2021-03-03","date_modified_ts":"2021-03-03T16:41:41Z","date_created":"2021-03-03T16:41:41Z","summary":null,"body":["<article data-history-node-id=\"2333\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-47\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-105<br \/>\nDate: 3 March 2021<\/strong><\/p>\n\n<p>On 2 March 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Chrome for Desktop \u2013 versions prior to 89.0.4389.72<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-47","alert_type":396,"serial_number":"AV21-105","subject":null,"moderation_state":"published","external_url":null},{"nid":2334,"title":"[Control systems] Hitachi ABB Power Grids security advisory","uuid":"4b716460-fc7a-4d1e-be3d-21cbb53e2287","banner":null,"lang":"en","date_modified":"2021-03-03","date_modified_ts":"2021-03-03T18:10:46Z","date_created":"2021-03-03T18:10:46Z","summary":null,"body":["<article data-history-node-id=\"2334\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-106<br \/>\nDate: 3 March 2021<\/strong><\/p>\n\n<p>On 2 March 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Ellipse EAM - version 9.0.25 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow sensitive information disclosure, session hijacking or the compromise of authentication credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-061-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-061-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-061-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-0","alert_type":398,"serial_number":"AV21-106","subject":null,"moderation_state":"published","external_url":null},{"nid":2335,"title":"SaltStack security advisory","uuid":"c6d38748-af36-49b5-b908-98ae86e76044","banner":null,"lang":"en","date_modified":"2021-03-04","date_modified_ts":"2021-03-04T14:28:24Z","date_created":"2021-03-04T14:24:21Z","summary":null,"body":["<article data-history-node-id=\"2335\" about=\"\/en\/alerts-advisories\/saltstack-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-107<br \/>\nDate:\u00a04 March 2021<\/strong><\/p>\n\n<p>On 25 February 2021 the Salt Project published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Salt \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to security bypass, information disclosure, directory traversal, privilege execution, man-in-the-middle and code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Active SaltStack CVE Release 2021-FEB-25<br \/><a href=\"https:\/\/saltproject.io\/security_announcements\/active-saltstack-cve-release-2021-feb-25\/\">https:\/\/saltproject.io\/security_announcements\/active-saltstack-cve-release-2021-feb-25\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/saltstack-security-advisory-0","alert_type":396,"serial_number":"AV21-107","subject":null,"moderation_state":"published","external_url":null},{"nid":2337,"title":"VMware security advisory","uuid":"870930d8-7d5e-4fa3-a177-720560ea3852","banner":null,"lang":"en","date_modified":"2021-03-04","date_modified_ts":"2021-03-04T20:26:55Z","date_created":"2021-03-04T20:26:55Z","summary":null,"body":["<article data-history-node-id=\"2337\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-108<br \/>\nDate: 4 March 2021<\/strong><\/p>\n\n<p>On 2 March 2021 VMware published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>\u00a0VMware View Planner \u2013 version 4.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0003)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0003.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0003.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-36","alert_type":396,"serial_number":"AV21-108","subject":null,"moderation_state":"published","external_url":null},{"nid":2338,"title":"[Control systems] Schneider Electric security advisory","uuid":"aeea8294-69d6-4e86-9097-a124e0a6a2df","banner":null,"lang":"en","date_modified":"2021-03-05","date_modified_ts":"2021-03-05T15:47:48Z","date_created":"2021-03-05T15:47:48Z","summary":null,"body":["<article data-history-node-id=\"2338\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-109<br \/>\nDate: 5 March 2021<\/strong><\/p>\n\n<p>On 4 March 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0WebReports \u2013 versions 1.9 to 3.1<\/li>\n\t<li>\u00a0WebStation \u2013 versions 2.0 to 3.1\u00a0<\/li>\n\t<li>\u00a0Enterprise Server installer \u2013 versions 1.9 to 3.1\u00a0<\/li>\n\t<li>\u00a0Enterprise Central installer \u2013 versions 2.0 to 3.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow unauthorized file uploads and command execution by a remote user, which could result in loss of availability, confidentiality and integrity of the workstation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-063-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-063-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-063-02<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-16","alert_type":398,"serial_number":"AV21-109","subject":null,"moderation_state":"published","external_url":null},{"nid":2339,"title":"[Control systems] Rockwell Automation security advisory","uuid":"a147decc-8607-43d8-9197-862338c91f48","banner":null,"lang":"en","date_modified":"2021-03-05","date_modified_ts":"2021-03-05T19:49:23Z","date_created":"2021-03-05T19:49:23Z","summary":null,"body":["<article data-history-node-id=\"2339\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-110<br \/>\nDate: 5 March 2021<\/strong><\/p>\n\n<p>On 4 March 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>1734-AENTR Series B - versions 4.001 to 4.005 and 5.011 to 5.017<\/li>\n\t<li>1734-AENTR Series C - versions 6.011 and 6.012<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to unauthorized data modification.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<br \/>\nICS Advisory (ICSA-21-063-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-063-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-063-01<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-14","alert_type":398,"serial_number":"AV21-110","subject":null,"moderation_state":"published","external_url":null},{"nid":2340,"title":"Google Chrome security advisory","uuid":"a6d9ff6d-c2e9-4aef-b8ef-ccc7ce16e1d6","banner":null,"lang":"en","date_modified":"2021-03-08","date_modified_ts":"2021-03-08T19:44:37Z","date_created":"2021-03-08T19:44:37Z","summary":null,"body":["<article data-history-node-id=\"2340\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-48\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-111<br \/>\nDate: 8 March 2021<\/strong><\/p>\n\n<p>On 5 March 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Chrome for Desktop \u2013 versions prior to 89.0.4389.82<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop_5.html\">https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop_5.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-48","alert_type":396,"serial_number":"AV21-111","subject":null,"moderation_state":"published","external_url":null},{"nid":2341,"title":"IBM security advisory","uuid":"38c89db9-5ad9-4d4d-883e-bfe197883d95","banner":null,"lang":"en","date_modified":"2021-03-08","date_modified_ts":"2021-03-08T19:51:37Z","date_created":"2021-03-08T19:51:37Z","summary":null,"body":["<article data-history-node-id=\"2341\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-39\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-112<br \/>\nDate: 8 March 2021<\/strong><\/p>\n\n<p>Between 1 and 7 March 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>\u00a0IBM Android Mobile Developer SDK - version 1405<\/li>\n\t<li>\u00a0IBM TPF Toolkit - versions 4.2 and 4.6<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow an actor to obtain access to sensitive information, crash a system or execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Mobile Developer SDK<br \/><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6410462\">https:\/\/www.ibm.com\/support\/pages\/node\/6410462<\/a><\/p>\n\n<p>TPF Toolkit<br \/><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6425015\">https:\/\/www.ibm.com\/support\/pages\/node\/6425015<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-39","alert_type":396,"serial_number":"AV21-112","subject":null,"moderation_state":"published","external_url":null},{"nid":2342,"title":"SonicWall security advisory","uuid":"acdfd800-a3a6-43cd-a96e-ec5effedab61","banner":null,"lang":"en","date_modified":"2021-03-09","date_modified_ts":"2021-03-09T16:46:44Z","date_created":"2021-03-09T16:46:44Z","summary":null,"body":["<article data-history-node-id=\"2342\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-113<br \/>\nDate: 9 March 2021<\/strong><\/p>\n\n<p>On 4 March 2021 SonicWall published an Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>\u00a0SonicWall Directory Services Connector \u2013 versions 4.1.17 and prior<\/li>\n<\/ul><p>\u00a0The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>SonicWall Alert (SNWLID-2021-0003)<br \/><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2021-0003\">https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2021-0003<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-1","alert_type":396,"serial_number":"AV21-113","subject":null,"moderation_state":"published","external_url":null},{"nid":2343,"title":"Apple security advisory","uuid":"f67b8405-777e-4e53-8964-ef4c1c58d668","banner":null,"lang":"en","date_modified":"2021-03-09","date_modified_ts":"2021-03-09T19:10:27Z","date_created":"2021-03-09T19:10:27Z","summary":null,"body":["<article data-history-node-id=\"2343\" about=\"\/en\/alerts-advisories\/apple-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-114<br \/>\nDate: 9 March 2021<\/strong><\/p>\n\n<p>On 8 March 2021 Apple published a Security Update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0macOS Big Sur \u2013 versions prior to 11.2.3<\/li>\n\t<li>\u00a0Safari 14.0.3 \u2013 versions 14610.4.3.1.7 and 15610.4.3.1.7<\/li>\n\t<li>\u00a0watchOS \u2013 versions prior to 7.3.2<\/li>\n\t<li>\u00a0iOS and iPadOS \u2013 versions prior to 14.4.1<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>macOS Big Sur<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT212220\">https:\/\/support.apple.com\/kb\/HT212220<\/a><\/p>\n\n<p>Safari<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT212223\">https:\/\/support.apple.com\/kb\/HT212223<\/a><\/p>\n\n<p>watchOS<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT212222\">https:\/\/support.apple.com\/kb\/HT212222<\/a><\/p>\n\n<p>iOS and iPadOS<br \/><a href=\"https:\/\/support.apple.com\/kb\/HT212221\">https:\/\/support.apple.com\/kb\/HT212221<\/a><\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-26","alert_type":396,"serial_number":"AV21-114","subject":null,"moderation_state":"published","external_url":null},{"nid":2344,"title":"SAP security advisory \u2013 March 2021 monthly rollup","uuid":"4cf707d8-581a-45a5-8943-709e502c9531","banner":null,"lang":"en","date_modified":"2021-03-10","date_modified_ts":"2021-03-10T16:21:34Z","date_created":"2021-03-10T16:21:34Z","summary":null,"body":["<article data-history-node-id=\"2344\" about=\"\/en\/alerts-advisories\/sap-security-advisory-march-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-115<br \/>\nDate: 10 March 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 9 March 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical severity updates for the following:<\/p>\n\n<ul><li>\u00a0SAP Manufacturing Integration and Intelligence - versions 15.1, 15.2, 15.3 and 15.4<\/li>\n\t<li>\u00a0SAP NetWeaver AS JAVA (MigrationService) - versions 7.10, 7.11, 7.30, 7.31, 7.40 and 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 March 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=571343107\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=571343107<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-march-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-115","subject":null,"moderation_state":"published","external_url":null},{"nid":2345,"title":"Adobe security advisory","uuid":"252fc515-3218-40df-bd60-006764cc13d7","banner":null,"lang":"en","date_modified":"2021-03-10","date_modified_ts":"2021-03-10T16:25:54Z","date_created":"2021-03-10T16:25:54Z","summary":null,"body":["<article data-history-node-id=\"2345\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-116<br \/>\nDate: 10 March 2021<br \/>\n\u00a0<\/strong><br \/>\nOn 9 March 2021 Adobe published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Adobe Connect \u2013 versions 11.0.5 and prior<\/li>\n\t<li>\u00a0Adobe Creative Cloud Desktop Application \u2013 versions 5.3 and prior<\/li>\n\t<li>\u00a0Adobe Framemaker \u2013 versions 2019.0.8 and prior<\/li>\n<\/ul><p>Exploitation in some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Connect<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb21-19.html\">https:\/\/helpx.adobe.com\/security\/products\/connect\/apsb21-19.html<\/a><\/p>\n\n<p>Adobe Creative Cloud<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb21-18.html\">https:\/\/helpx.adobe.com\/security\/products\/creative-cloud\/apsb21-18.html<\/a><\/p>\n\n<p>Adobe Framemaker<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb21-14.html\">https:\/\/helpx.adobe.com\/security\/products\/framemaker\/apsb21-14.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-36","alert_type":396,"serial_number":"AV21-116","subject":null,"moderation_state":"published","external_url":null},{"nid":2346,"title":"Microsoft security advisory \u2013 March 2021 monthly rollup","uuid":"be8d2150-22c3-47a4-9302-0c1771cbb59b","banner":null,"lang":"en","date_modified":"2021-03-10","date_modified_ts":"2021-03-10T16:42:09Z","date_created":"2021-03-10T16:30:56Z","summary":null,"body":["<article data-history-node-id=\"2346\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-march-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-117<br \/>\nDate: 10 March 2021<\/strong><\/p>\n\n<p>On 9 March 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>\u00a0Windows 10, 8.1 and 7<\/li>\n\t<li>\u00a0Windows Server and Server Core<\/li>\n\t<li>\u00a0Visual Studio<\/li>\n\t<li>\u00a0Azure Sphere<\/li>\n\t<li>\u00a0Internet Explorer 9 and 11<\/li>\n<\/ul><p>Within the March release notes was mention of security updates for the following versions of Microsoft Exchange:<\/p>\n\n<ul><li>\u00a0Exchange 2010<\/li>\n\t<li>\u00a0Exchange 2013<\/li>\n\t<li>\u00a0Exchange 2016<\/li>\n\t<li>\u00a0Exchange 2019<\/li>\n<\/ul><p>As previously reported the Cyber Centre has learned that these vulnerabilities are being actively exploited. The Cyber Centre strongly recommends organizations follow the advice and guidance provided by AL20-003 UPDATE 2 - Active Exploitation of Microsoft Exchange Vulnerabilities.<\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/active-exploitation-microsoft-exchange-vulnerabilities\">https:\/\/www.cyber.gc.ca\/en\/alerts\/active-exploitation-microsoft-exchange-vulnerabilities<\/a><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>March 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Mar\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Mar<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-march-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-117","subject":null,"moderation_state":"published","external_url":null},{"nid":2347,"title":"[Control systems] Schneider Electric security advisory","uuid":"c16bdae1-7e6e-4c16-97ac-a1455eec5a0b","banner":null,"lang":"en","date_modified":"2021-03-10","date_modified_ts":"2021-03-10T18:16:14Z","date_created":"2021-03-10T18:16:14Z","summary":null,"body":["<article data-history-node-id=\"2347\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-118<br \/>\nDate: 10 March 2021<\/strong><\/p>\n\n<p>On 9 March 2021 Schneider Electric published a Security Notification to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Interactive Graphical SCADA System \u2013 versions prior to 15.0.0.21041<\/li>\n\t<li>PowerLogic Power Meters \u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Interactive Graphical SCADA System<br \/><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-068-01\">https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-068-01<\/a><\/p>\n\n<p>PowerLogic Power Meters<br \/><a href=\"http:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-068-02\">http:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-068-02<\/a><br \/><a href=\"http:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-068-03\">http:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-068-03<\/a><\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-17","alert_type":398,"serial_number":"AV21-118","subject":null,"moderation_state":"published","external_url":null},{"nid":2378,"title":"Vulnerabilities impacting F5 BIG-IP and BIG-IQ - update 1","uuid":"3bf48066-7e43-4dc5-9b7b-cd64d80c90c7","banner":null,"lang":"en","date_modified":"2021-04-01","date_modified_ts":"2021-04-01T18:20:28Z","date_created":"2021-03-10T23:09:55Z","summary":null,"body":["<article data-history-node-id=\"2378\" about=\"\/en\/alerts-advisories\/vulnerabilities-impacting-f5-big-ip-and-big-iq\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\"><\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><strong><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">Number: AL21-004 UPDATE 1<br \/><strong><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">Date: 19 March 2021<\/span><\/strong><\/span><\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\"><\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN\" xml:lang=\"EN\" xml:lang=\"EN\">This Alert is intended for IT professionals and managers of notified organizations. <\/span><\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p align=\"LEFT\" dir=\"LTR\">On 10 March 2021, F5 publicly disclosed details of critical vulnerabilities affecting BIG-IP, BIG-IP Advanced WAF\/ASM, and BIG-IQ products. Neither F5 nor the Cyber Centre are aware of active exploitation of these vulnerabilities; however, due to their criticality it is advised to apply the necessary patches or mitigations immediately.<\/p>\n\n<p dir=\"LTR\"><strong>UPDATE: <\/strong>As of 19 March 2021, the Cyber Centre has become aware of scanning and exploitation attempts against the iControl REST interface of F5 BIG-IP products within Canada. Successful exploitation could result in information disclosure or remote code execution which could lead to a full system compromise.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">On 10 March 2021, F5 published Security Advisory K02566623, which disclosed several vulnerabilities in BIG-IP (all modules), BIG-IP Advanced WAF\/ASM, and BIG-IQ.\u00a0[<a href=\"https:\/\/support.f5.com\/csp\/article\/K02566623\"><font color=\"#0066cc\">1<\/font><\/a>] Four of the disclosed vulnerabilities are of critical severity. Of note are CVE-2021-22986 and CVE-2021-22987 (CVSS 9.8 and CVSS 9.9, respectively) which are vulnerabilities in the control plane for both the iControl REST interface and Traffic Management User Interface (TMUI). <\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">CVE-2021-22986 allows unauthenticated actors with network access to the iControl REST interface to execute arbitrary system commands, create or delete files, and disable services. The BIG-IP system in appliance mode is also vulnerable. <\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">When running in appliance mode, CVE-2021-22987 allows authenticated users with network access to the Traffic Management User Interface (TMUI)\/Configuration utility to execute arbitrary system commands, create or delete files, or disable services. Exploitation can lead to breakout of Appliance mode. <\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">Both vulnerabilities can only be exploited through the control plane, and exploitation of these vulnerabilities could lead to complete system compromise. <\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">The two remaining critical vulnerabilities, CVE-2021-22991 and CVE-2021-22992, disclosed by F5 are buffer overflows affecting BIG-IP and BIG-IP (Advanced WAF and ASM). These vulnerabilities can only be exploited through the data plane. Exploitation of these vulnerabilities could lead to denial of service or, in theory, remote code execution. <\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">F5 recommends patching all systems running versions identified as vulnerable, including those deployed in virtual environments.<span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/span><\/p>\n\n<h2>SUGGESTED ACTIONS<\/h2>\n\n<p>The Cyber Centre recommends organizations review all impacted F5 appliances and virtual deployments and patch to one of the below recommended versions. [<a href=\"https:\/\/support.f5.com\/csp\/article\/K02566623\"><font color=\"#0066cc\">1<\/font><\/a>]<\/p>\n\n<p>BIG-IP:<\/p>\n\n<ul><li>Versions 16.0.0 to 16.0.1 should be upgraded to 16.0.1.1<\/li>\n\t<li>Versions 15.1.0 to 15.1.2 should be upgraded to 15.1.2.1<\/li>\n\t<li>Versions 14.1.0 to 14.1.3.1 should be upgraded to 14.1.4<\/li>\n\t<li>Versions 13.1.0 to 13.1.3.5 should be upgraded to 13.1.3.6<\/li>\n\t<li>Versions 12.1.0 to 12.1.5.2 should be upgraded to 12.1.5.3<\/li>\n\t<li>Versions 11.6.1 to 11.6.5.2 should be upgraded to 11.6.5.3<\/li>\n<\/ul><p>BIG-IQ:<\/p>\n\n<ul><li>Version 8.0.0 is unaffected<\/li>\n\t<li>Versions 7.1.0 to 7.1.0.2 should be upgraded to 8.0.0<\/li>\n\t<li>Versions 7.0.0 to 7.0.0.1 should be upgraded to 7.1.0.3<\/li>\n\t<li>Versions 6.0.0 to 6.1.0 should be upgraded to 7.0.0.2<\/li>\n<\/ul><p>F5 indicates that if a fixed version has not been identified for a branch used by an organization then no update is available. F5 recommends that organizations upgrade to a version with an available patch. Organizations may use the F5 platform matrix to determine compatible software versions for their F5 platform. [<a href=\"https:\/\/support.f5.com\/csp\/article\/K02566623\"><font color=\"#0066cc\">1<\/font><\/a>]<\/p>\n\n<p>While the Cyber Centre strongly encourages patching as soon as possible, administrators should consider applying the mitigations described in the F5 KB articles if patching is not immediately possible. See the [<a href=\"https:\/\/support.f5.com\/csp\/article\/K13123\">4<\/a>] and [<a href=\"https:\/\/support.f5.com\/csp\/article\/K15106\">5<\/a>] for more details. In summary:<\/p>\n\n<ul><li>Block iControl REST access through the self IP address.<\/li>\n\t<li>Block iControl REST access through the management interface.<\/li>\n\t<li>Block Configuration utility access through self IP addresses.<\/li>\n\t<li>Block Configuration utility access through the management interface.<\/li>\n<\/ul><p>Patching as described in this section also fixes the buffer overflow vulnerabilities described in the previous section. There are no mitigations against CVE-2021-22991 other than patching, while for CVE-2021-22992 F5 has provided an iRule mitigation. [<a href=\"https:\/\/support.f5.com\/csp\/article\/K52510511\">9<\/a>] In all cases, the Cyber Centre and F5 recommend patching as the primary mitigation.<\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/p>\n\n<h2 align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">INDICATORS OF COMPROMISE<\/span><\/h2>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><strong>UPDATE: <\/strong>On 18 March security researchers, NCCGroup, released a report [<a href=\"https:\/\/research.nccgroup.com\/2021\/03\/18\/rift-detection-capabilities-for-recent-f5-big-ip-big-iq-icontrol-rest-api-vulnerabilities-cve-2021-22986\/\">10<\/a>] which identified network activity associated with attempted exploitation of CVE-2021-22986. NCCGroup has further published indicators of compromise to aid in the detection of related malicious activity. <span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><strong>UPDATE: <\/strong>Where recommended patches have not been applied, the Cyber Center recommends reviewing relevant iControl REST logs for activity that may be suspicious. The Cyber Center is aware of open-source signatures [<a href=\"https:\/\/github.com\/nccgroup\/Cyber-Defence\/blob\/master\/Signatures\/suricata\/2021_03_cve_2021_22986.txt\">11<\/a>][<a href=\"https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules\">12<\/a>] that administrators may find useful in detecting malicious network activity related to CVE-2021-22986. <span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><\/span><\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\">Note: The Cyber Center is providing reference to these signatures for situational awareness only and makes no claims regarding their effectiveness. As these communication channels may be encrypted the Cyber Centre encourages a thorough analysis of filesystem, logs and network traffic for any potentially vulnerable systems.<\/span><\/p>\n\n<p><span lang=\"EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"> <\/span><\/p>\n\n<p align=\"LEFT\" dir=\"LTR\">Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] K02566623: Overview of F5 critical vulnerabilities (March 2021)<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K02566623\">https:\/\/support.f5.com\/csp\/article\/K02566623<\/a><\/p>\n\n<p>[2] K9502: BIG-IP hotfix and point release matrix<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K9502\">https:\/\/support.f5.com\/csp\/article\/K9502<\/a><\/p>\n\n<p>[3] K15113: BIG-IQ hotfix and point release matrix<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K15113\">https:\/\/support.f5.com\/csp\/article\/K15113<\/a><\/p>\n\n<p>[4] K13123: Managing BIG-IP product hotfixes (11.x - 16.x)<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K13123\">https:\/\/support.f5.com\/csp\/article\/K13123<\/a><\/p>\n\n<p>[5] K15106: Managing BIG-IQ product hotfixes<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K15106\">https:\/\/support.f5.com\/csp\/article\/K15106<\/a><\/p>\n\n<p>[6] K18132488: Appliance mode TMUI authenticated remote command execution vulnerability CVE-2021-22987<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K18132488\">https:\/\/support.f5.com\/csp\/article\/K18132488<\/a><\/p>\n\n<p>[7] K03009991: iControl REST unauthenticated remote command execution vulnerability CVE-2021-22986<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K03009991\">https:\/\/support.f5.com\/csp\/article\/K03009991<\/a><\/p>\n\n<p>[8] K56715231: TMM buffer-overflow vulnerability CVE-2021-22991<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K56715231\">https:\/\/support.f5.com\/csp\/article\/K56715231<\/a><\/p>\n\n<p>[9] K52510511: Advanced WAF\/ASM buffer-overflow vulnerability CVE-2021-22992<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K52510511[10\">https:\/\/support.f5.com\/csp\/article\/K52510511<\/a><\/p>\n\n<p>[10] NCC Group RIFT detection capabilities for CVE-2021-22986<br \/><a href=\"https:\/\/research.nccgroup.com\/2021\/03\/18\/rift-detection-capabilities-for-recent-f5-big-ip-big-iq-icontrol-rest-api-vulnerabilities-cve-2021-22986\/\">https:\/\/research.nccgroup.com\/2021\/03\/18\/rift-detection-capabilities-for-recent-f5-big-ip-big-iq-icontrol-rest-api-vulnerabilities-cve-2021-22986\/<\/a><\/p>\n\n<p>[11] NCC Group CVE-2021-22896 Suricata signatures<br \/><a href=\"https:\/\/github.com\/nccgroup\/Cyber-Defence\/blob\/master\/Signatures\/suricata\/2021_03_cve_2021_22986.txt\">https:\/\/github.com\/nccgroup\/Cyber-Defence\/blob\/master\/Signatures\/suricata\/2021_03_cve_2021_22986.txt<\/a><\/p>\n\n<p>[12] Proofpoint Emerging Threats Suricata rules<br \/><a href=\"https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules\">https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules<\/a><br \/><br \/><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-impacting-f5-big-ip-and-big-iq","alert_type":397,"serial_number":"AL21-004","subject":null,"moderation_state":"published","external_url":null},{"nid":2348,"title":"Adobe security advisory","uuid":"6906ec80-804b-4fd4-8fc4-dbed6c19a101","banner":null,"lang":"en","date_modified":"2021-03-11","date_modified_ts":"2021-03-11T13:34:14Z","date_created":"2021-03-11T13:34:14Z","summary":null,"body":["<article data-history-node-id=\"2348\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-120<br \/>\nDate: 11 March 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 9 March 2021 Adobe published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0Adobe Animate \u2013 versions 21.0.3 and prior<\/li>\n\t<li>\u00a0Adobe Photoshop\n\t<ul><li>\u00a0Photoshop 2020 \u2013 versions 21.2.5 and prior<\/li>\n\t\t<li>\u00a0Photoshop 2021 \u2013 versions 22.2 and prior<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Animate<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/animate\/apsb21-21.html\">https:\/\/helpx.adobe.com\/security\/products\/animate\/apsb21-21.html<\/a><\/p>\n\n<p>Adobe Photoshop<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb21-17.html\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb21-17.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-37","alert_type":396,"serial_number":"AV21-120","subject":null,"moderation_state":"published","external_url":null},{"nid":2349,"title":"[Control systems] Siemens security advisory","uuid":"5720e175-ff2b-442e-b000-cfa08f922d1c","banner":null,"lang":"en","date_modified":"2021-03-11","date_modified_ts":"2021-03-11T13:45:04Z","date_created":"2021-03-11T13:42:29Z","summary":null,"body":["<article data-history-node-id=\"2349\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-119<br \/>\nDate: 11 March 2021<\/strong><br \/><br \/>\nOn 9 March 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Solid Edge SE2020 and SE2021 \u2013 all versions of bundled Luxion Keyshot program<\/li>\n\t<li>Solid Edge SE2020 and SE2021 \u2013 versions prior to SE2020MP13 and SE2021MP3<\/li>\n\t<li>SIMATIC S7 PLCSIM \u2013 version 5.4<\/li>\n\t<li>RUGGEDCOM RM1224 \u2013 version 6.3<\/li>\n\t<li>SCALANCE SC-600 - versions from 2.1 to prior to 2.1.3<\/li>\n\t<li>SCALANCE S615 and M-800 \u2013 version 6.3<\/li>\n\t<li>PLUSCONTROL 1st Generation - all versions<\/li>\n\t<li>SENTRON PAC \/ 3VA Devices \u2013 multiple models and versions<\/li>\n\t<li>SIMATIC MV400 family \u2013 versions prior to 7.0.6<\/li>\n\t<li>SINEMA Remote Connect Server \u2013 versions prior to 3.0<\/li>\n\t<li>LOGO! 8 BM (Incl. SIPLUS variants) \u2013 all versions<\/li>\n\t<li>Mendix Forgot Password Appstore module \u2013 versions prior to 3.2.1<\/li>\n\t<li>Third-Party Component libcurl \u2013 multiple versions<\/li>\n\t<li>Stack Overflow in SCALANCE and RUGGEDCOM Devices \u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-21","alert_type":398,"serial_number":"AV21-119","subject":null,"moderation_state":"published","external_url":null},{"nid":2350,"title":"Google Chrome security advisory","uuid":"6709e7b9-cb8b-47a9-82d8-8107ce1c3f1b","banner":null,"lang":"en","date_modified":"2021-03-15","date_modified_ts":"2021-03-15T16:53:51Z","date_created":"2021-03-15T16:53:51Z","summary":null,"body":["<article data-history-node-id=\"2350\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-49\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-121<br \/>\nDate: 15 March 2021<\/strong><\/p>\n\n<p>On 12 March 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Chrome for Desktop \u2013 versions prior to 89.0.4389.90<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution. Google has received reports that some of these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop_12.html\">https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop_12.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-49","alert_type":396,"serial_number":"AV21-121","subject":null,"moderation_state":"published","external_url":null},{"nid":2351,"title":"IBM security advisory","uuid":"a1fa37b1-f352-4cf8-a7bd-d17875f62b8f","banner":null,"lang":"en","date_modified":"2021-03-15","date_modified_ts":"2021-03-15T16:56:54Z","date_created":"2021-03-15T16:56:54Z","summary":null,"body":["<article data-history-node-id=\"2351\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-40\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-122<br \/>\nDate: 15 March 2021<\/strong><br \/>\n\u00a0<br \/>\nBetween 8 and 14 March 2021 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP Hana - versions 8.1.0.0 to 8.1.11.0 and 7.1.3.0 to 7.1.3.2<\/li>\n\t<li>\u00a0IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Db2 - versions 8.1.0.0 to 8.1.11.0 and 7.1.3.0 to 7.1.3.4<\/li>\n\t<li>\u00a0IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Oracle - versions 8.1.0.0 to 8.1.11.0 and 7.1.3.0 to 7.1.3.4<\/li>\n\t<li>\u00a0IBM Tivoli System Automation for Multiplatforms - version 4.1<\/li>\n\t<li>\u00a0IBM Tivoli System Automation Application Manager - version 4.1<\/li>\n\t<li>\u00a0IBM DB2 - multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-40","alert_type":396,"serial_number":"AV21-122","subject":null,"moderation_state":"published","external_url":null},{"nid":2352,"title":"Microsoft security advisory","uuid":"ed5c0c09-8f09-431f-84a3-1b7ff35a5c17","banner":null,"lang":"en","date_modified":"2021-03-16","date_modified_ts":"2021-03-16T14:59:13Z","date_created":"2021-03-16T14:59:13Z","summary":null,"body":["<article data-history-node-id=\"2352\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-123<br \/>\nDate: 16 March 2021<\/strong><\/p>\n\n<p>On 15 March 2021 Microsoft published an out-of-band Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 89.0.774.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p>Microsoft Edge<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21191\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21191<\/a><\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21192\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21192<\/a><\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21193\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-21193<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-9","alert_type":396,"serial_number":"AV21-123","subject":null,"moderation_state":"published","external_url":null},{"nid":2353,"title":"[Control systems] Advantech security advisory","uuid":"a577964a-93d8-4229-ad9d-eb92a8076909","banner":null,"lang":"en","date_modified":"2021-03-17","date_modified_ts":"2021-03-17T18:40:53Z","date_created":"2021-03-17T18:40:53Z","summary":null,"body":["<article data-history-node-id=\"2353\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-124<br \/>\nDate: 17 March 2021<\/strong><\/p>\n\n<p>On 16 March 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Advantech WebAccess\/SCADA - versions 9.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to session hijacking or redirection to a malicious webpage.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigation and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-075-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-075-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-075-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-13","alert_type":398,"serial_number":"AV21-124","subject":null,"moderation_state":"published","external_url":null},{"nid":2354,"title":"[Control systems] GE security advisory","uuid":"47e3a505-d614-41f5-bbea-a379ae9723bf","banner":null,"lang":"en","date_modified":"2021-03-17","date_modified_ts":"2021-03-17T18:41:26Z","date_created":"2021-03-17T18:41:26Z","summary":null,"body":["<article data-history-node-id=\"2354\" about=\"\/en\/alerts-advisories\/control-systems-ge-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-125<br \/>\nDate: 17 March 2021<\/strong><\/p>\n\n<p>On 16 March 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>GE UR family of advanced protection and control relays \u2013 multiple devices and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to information disclosure, the ability to reboot the device, privileged access and denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-075-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-075-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-075-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-security-advisory-2","alert_type":398,"serial_number":"AV21-125","subject":null,"moderation_state":"published","external_url":null},{"nid":2355,"title":"[Control systems] Hitachi ABB security advisory","uuid":"4a41d4ab-314f-4db3-a75a-ab9ecc63a5ad","banner":null,"lang":"en","date_modified":"2021-03-18","date_modified_ts":"2021-03-18T12:14:30Z","date_created":"2021-03-18T12:14:30Z","summary":null,"body":["<article data-history-node-id=\"2355\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-126<br \/>\nDate: 18 March 2021<\/strong><\/p>\n\n<p>On 16 March 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>AFS660\/AFS665 - version 7.0.07\n\t<ul><li>Including AFS660-SR and AFS665-SR<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigation and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-075-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-075-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-075-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-security-advisory","alert_type":398,"serial_number":"AV21-126","subject":null,"moderation_state":"published","external_url":null},{"nid":2356,"title":"[Control systems] BD security advisory","uuid":"312e3ad7-135a-4378-be1f-32077a341195","banner":null,"lang":"en","date_modified":"2021-03-18","date_modified_ts":"2021-03-18T15:50:48Z","date_created":"2021-03-18T15:50:48Z","summary":null,"body":["<article data-history-node-id=\"2356\" about=\"\/en\/alerts-advisories\/control-systems-bd-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-127<br \/>\nDate: 18 March 2021<\/strong><\/p>\n\n<p>On 16 March 2021 ICS-CERT published an ICS Medical Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Alaris 8015 PC Unit \u2013 versions 9.33 and prior, 9.5 and prior, and 9.7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor with physical access to the device to obtain network authentication credentials and other sensitive data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<br \/>\n\u00a0<br \/>\nICS Medical Advisory (ICSMA-17-017-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-17-017-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-17-017-02<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bd-security-advisory-0","alert_type":398,"serial_number":"AV21-127","subject":null,"moderation_state":"published","external_url":null},{"nid":2357,"title":"[Control systems] Hitachi ABB Power Grids security advisory","uuid":"1b3cba51-88ff-4bf5-a561-ad5d29a7083d","banner":null,"lang":"en","date_modified":"2021-03-19","date_modified_ts":"2021-03-19T13:50:42Z","date_created":"2021-03-19T13:50:42Z","summary":null,"body":["<article data-history-node-id=\"2357\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-128<br \/>\nDate: 19 March 2021<\/strong><\/p>\n\n<p>On 18 March 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>eSOMS - multiple versions<\/li>\n\t<li>eSOMS with Telerik - versions prior to 6.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to upload\/download arbitrary files, execute arbitrary code, or access sensitive data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-077-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-077-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-077-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-077-03) - eSOMS with Telerik<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-077-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-077-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-1","alert_type":398,"serial_number":"AV21-128","subject":null,"moderation_state":"published","external_url":null},{"nid":2358,"title":"[Control systems] Johnson Controls security advisory","uuid":"52c3db7f-d268-4952-9419-411b32377c09","banner":null,"lang":"en","date_modified":"2021-03-19","date_modified_ts":"2021-03-19T13:53:57Z","date_created":"2021-03-19T13:53:57Z","summary":null,"body":["<article data-history-node-id=\"2358\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-129<br \/>\nDate: 19 March 2021<\/strong><\/p>\n\n<p>On 18 March 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>exacqVision Web Service \u2013 versions 20.12.02.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthenticated actor to access sensitive data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-077-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-077-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-077-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-4","alert_type":398,"serial_number":"AV21-129","subject":null,"moderation_state":"published","external_url":null},{"nid":2360,"title":"Adobe security advisory","uuid":"cab7be9b-ccaa-4d39-b6fc-46efc826954e","banner":null,"lang":"en","date_modified":"2021-03-22","date_modified_ts":"2021-03-22T19:05:33Z","date_created":"2021-03-22T18:40:18Z","summary":null,"body":["<article data-history-node-id=\"2360\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-130<br \/>\nDate: 22 March 2021<\/strong><\/p>\n\n<p>On 22 March 2021 Adobe published Security Bulletins to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Adobe Cold Fusion 2016 \u2013 version update 16 and prior<\/li>\n\t<li>Adobe Cold Fusion 2018 \u2013 version update 10 and prior<\/li>\n\t<li>Adobe Cold Fusion 2021 \u2013 version 2021.0.0.323925<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<br \/>\nAdobe ColdFusion<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb21-16.html\">https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb21-16.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-38","alert_type":396,"serial_number":"AV21-130","subject":null,"moderation_state":"published","external_url":null},{"nid":2359,"title":"IBM security advisory","uuid":"1140bf3a-2312-4154-a375-98e35d31b942","banner":null,"lang":"en","date_modified":"2021-03-22","date_modified_ts":"2021-03-22T18:53:52Z","date_created":"2021-03-22T18:53:52Z","summary":null,"body":["<article data-history-node-id=\"2359\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-41\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-131<br \/>\nDate: 22 March 2021<\/strong><\/p>\n\n<p>Between 15 and 21 March 2021 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Security Privileged Identity Manager \u2013 versions 2.1.0, 2.0.2, and 2.1.1<\/li>\n\t<li>IBM Decision Optimization Center (DOC) \u2013 versions 3.9.1, 3.9.0.2, 3.9, 3.8.0.2, 3.8.0.1, and 3.8<\/li>\n\t<li>IBM Decision Optimization Center (ODME) \u2013 versions 3.9.0.1, 3.7.0.2, 3.7.0.1, and 3.7<\/li>\n\t<li>IBM ILOG CPLEX Optimization Studio (COS) \u2013 versions 20.1, 12.10, 12.9, 12.8, 12.7.1, 12.7<\/li>\n\t<li>IBM MaaS360 Cloud Extender \u2013 versions 2.102.x and prior<\/li>\n\t<li>IBM Content Collector for SAP Applications \u2013 version 4.0<\/li>\n\t<li>Rational Application Developer \u2013 versions 9.6 and 9.7<\/li>\n\t<li>IBM Network Performance Insight \u2013 version 1.3.1<\/li>\n\t<li>IBM Spectrum Scale \u2013 versions 5.0.0 to 5.0.5.5 and 5.1.0 to 5.1.0.2<\/li>\n\t<li>IBM CICS Transaction Gateway \u2013 versions 9.2.0.0 to 9.2.0.2, 9.1.0.0 to 9.1.0.3, 9.0.0.0 to 9.0.0.5, 8.1.0.0 to 8.1.0.5, and 8.0.0.0 to 8.0.0.6<\/li>\n\t<li>Cloud Pak for Security \u2013 versions 1.5.0.0, 1.4.0.0, 1.6.0.0, and 1.5.01<\/li>\n\t<li>IBM Spectrum Protect for Enterprise Resource Planning: Data protection for SAP HANA \u2013 versions 8.1.0.0 to 8.1.11.0 and 7.1.3.0 to 7.1.3.2<\/li>\n\t<li>IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Db2 \u2013 versions 8.1.0.0 to 8.1.11.0 and 7.1.3.0 to 7.1.3.4<\/li>\n\t<li>IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Oracle \u2013 versions 8.1.0.0 to 8.1.11.0 and 7.1.3.0 to 7.1.3.4<\/li>\n\t<li>IBM WebSphere Cast Iron Solution \u2013 versions 7.5.0.0, 7.5.0.1, and 7.5.1.0<\/li>\n\t<li>App Connect Professional \u2013 versions 7.5.2.0, 7.5.3.0, and 7.5.4.0<\/li>\n\t<li>IBM Elastic Storage System \u2013 version 6.0.0 to 6.0.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<br \/>\nIBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-41","alert_type":396,"serial_number":"AV21-131","subject":null,"moderation_state":"published","external_url":null},{"nid":2361,"title":"HPE security advisory","uuid":"943e2c33-e1d9-44f0-a339-6bd6b77b497b","banner":null,"lang":"en","date_modified":"2021-03-23","date_modified_ts":"2021-03-23T14:29:55Z","date_created":"2021-03-23T14:29:55Z","summary":null,"body":["<article data-history-node-id=\"2361\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-132<br \/>\nDate: 23 March 2021<\/strong><\/p>\n\n<p>On 22 March 2021 HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE SANnav Management Software - versions prior to 2.1.0a<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (SANnav Management Software)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04098en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04098en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-11","alert_type":396,"serial_number":"AV21-132","subject":null,"moderation_state":"published","external_url":null},{"nid":2362,"title":"Mozilla security advisory","uuid":"aee6e000-9789-4f7d-b25e-be8b13ca73a1","banner":null,"lang":"en","date_modified":"2021-03-23","date_modified_ts":"2021-03-23T18:13:01Z","date_created":"2021-03-23T18:13:01Z","summary":null,"body":["<article data-history-node-id=\"2362\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-133<br \/>\nDate: 23 March 2021<\/strong><\/p>\n\n<p>On 23 March 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 87<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.9<\/li>\n\t<li>Thunderbird \u2013 versions prior to 78.9<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in information disclosure or a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-10)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-10\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-10\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-11)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-11\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-11\/<\/a><\/p>\n\n<p>Thunderbird (MFSA 2021-12)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-12\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-12\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-34","alert_type":396,"serial_number":"AV21-133","subject":null,"moderation_state":"published","external_url":null},{"nid":2363,"title":"[Control systems] Weintek security advisory","uuid":"df4f4121-cc10-4492-9749-72a819f7bed1","banner":null,"lang":"en","date_modified":"2021-03-24","date_modified_ts":"2021-03-24T11:38:27Z","date_created":"2021-03-24T11:38:27Z","summary":null,"body":["<article data-history-node-id=\"2363\" about=\"\/en\/alerts-advisories\/control-systems-weintek-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-134<br \/>\nDate: 24 March 2021<\/strong><\/p>\n\n<p>On 23 March 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>cMT-SVR-1xx\/2xx - versions prior to 20210305<\/li>\n\t<li>cMT-G01\/G02 - versions prior to 20210209<\/li>\n\t<li>cMT-G03\/G04 - versions prior to 20210222<\/li>\n\t<li>cMT3071\/cMT3072\/cMT3090\/cMT3103\/cMT3151 - versions prior to 20210218<\/li>\n\t<li>cMT-HDM - versions prior to 20210204<\/li>\n\t<li>cMT-FHD - versions prior to 20210208<\/li>\n\t<li>cMT-CTRL01 - versions prior to 20210302<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in access to sensitive information or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-082-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-082-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-082-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-weintek-security-advisory","alert_type":398,"serial_number":"AV21-134","subject":null,"moderation_state":"published","external_url":null},{"nid":2364,"title":"[Control systems] GE security advisory","uuid":"0735e813-5122-4a2f-9fc3-f4f2782f94c8","banner":null,"lang":"en","date_modified":"2021-03-24","date_modified_ts":"2021-03-24T12:16:39Z","date_created":"2021-03-24T12:16:39Z","summary":null,"body":["<article data-history-node-id=\"2364\" about=\"\/en\/alerts-advisories\/control-systems-ge-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-135<br \/>\nDate: 24 March 2021<\/strong><\/p>\n\n<p>On 23 March 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MU320E \u2013 versions prior to v04A00.1<\/li>\n\t<li>Reason DR60 \u2013 versions prior to 02A04.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to escalate privileges, use hard-coded credentials to take control of the device or remotely execute code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-082-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-082-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-082-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-082-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-082-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-082-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-security-advisory-3","alert_type":398,"serial_number":"AV21-135","subject":null,"moderation_state":"published","external_url":null},{"nid":2365,"title":"[Control systems] Ovarro security advisory","uuid":"63880177-b46f-4909-b6d0-737d59be068f","banner":null,"lang":"en","date_modified":"2021-03-24","date_modified_ts":"2021-03-24T13:37:45Z","date_created":"2021-03-24T13:29:17Z","summary":null,"body":["<article data-history-node-id=\"2365\" about=\"\/en\/alerts-advisories\/control-systems-ovarro-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-136<br \/>\nDate: 24 March 2021<\/strong><\/p>\n\n<p>On 23 March 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>TBoxLT2 (all models)<\/li>\n\t<li>TBox MS-CPU32<\/li>\n\t<li>TBox MS-CPU32-S2<\/li>\n\t<li>TBox RM2 (all models)<\/li>\n\t<li>TBox TG2 (all models)<\/li>\n\t<li>All versions prior to TWinSoft 12.4 and Firmware 1.46<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, which may cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-054-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-054-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ovarro-security-advisory","alert_type":398,"serial_number":"AV21-136","subject":null,"moderation_state":"published","external_url":null},{"nid":2366,"title":"Ubuntu security advisory","uuid":"7dbc3ce7-6eb9-45c8-8bba-7c28fe6c4d84","banner":null,"lang":"en","date_modified":"2021-03-24","date_modified_ts":"2021-03-24T14:58:43Z","date_created":"2021-03-24T14:58:43Z","summary":null,"body":["<article data-history-node-id=\"2366\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-137<br \/>\nDate: 24 March 2021<\/strong><\/p>\n\n<p>On 23 March 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, access to sensitive information, or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4887-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4887-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4887-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-9","alert_type":396,"serial_number":"AV21-137","subject":null,"moderation_state":"published","external_url":null},{"nid":2367,"title":"Cisco security advisory","uuid":"3cec8160-7a35-413a-a863-8382033daa48","banner":null,"lang":"en","date_modified":"2021-03-25","date_modified_ts":"2021-03-25T12:07:36Z","date_created":"2021-03-25T12:07:36Z","summary":null,"body":["<article data-history-node-id=\"2367\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-77\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-138<br \/>\nDate: 25 March 2021<\/strong><\/p>\n\n<p>On 24 March 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco Jabber \u2013 multiple platforms and versions<\/li>\n<\/ul><p>Exploitation could allow an actor to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Jabber<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cisco-jabber-PWrTATTC\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cisco-jabber-PWrTATTC<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-77","alert_type":396,"serial_number":"AV21-138","subject":null,"moderation_state":"published","external_url":null},{"nid":2368,"title":"HPE security advisory","uuid":"a8f663bc-9a41-4b62-b428-9057fe31122a","banner":null,"lang":"en","date_modified":"2021-03-25","date_modified_ts":"2021-03-25T19:08:27Z","date_created":"2021-03-25T19:08:27Z","summary":null,"body":["<article data-history-node-id=\"2368\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-139<br \/>\nDate: 25 March 2021<\/strong><\/p>\n\n<p>On 24 March 2021 HPE published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers \u2013 versions prior to 2.18<\/li>\n\t<li>HPE Integrated Lights-Out 4 (iLO 4) - versions prior to 2.75<\/li>\n\t<li>HPE Synergy 660 Gen10 Compute Module \u2013 versions prior to HPE Synergy Custom SPP 2020.05.02<\/li>\n\t<li>HPE Synergy 480 Gen10 Compute Module \u2013 versions prior to HPE Synergy Custom SPP 2020.05.02<\/li>\n\t<li>HPE Synergy 480 Gen9 Compute Module \u2013 versions prior HPE Synergy Custom SPP 2020.05.02<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow an actor to remotely execute code, cause denial of service, and expose sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (HPE Synergy Compute Modules with iLO 5 or iLO 4)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04103en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04103en_us<\/a><\/p>\n\n<p>HPE Security Bulletin Library<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library\">https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-12","alert_type":396,"serial_number":"AV21-139","subject":null,"moderation_state":"published","external_url":null},{"nid":2369,"title":"[Control systems] Philips security advisory","uuid":"12e82156-8277-49e4-901b-98a70ed9342e","banner":null,"lang":"en","date_modified":"2021-03-25","date_modified_ts":"2021-03-25T19:13:45Z","date_created":"2021-03-25T19:13:45Z","summary":null,"body":["<article data-history-node-id=\"2369\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-140<br \/>\nDate: 25 March 2021<\/strong><\/p>\n\n<p>On 25 March 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>882300 Gemini 16 Slice<\/li>\n\t<li>882160 Gemini Dual<\/li>\n\t<li>882400 Gemini GXL 10 Slice<\/li>\n\t<li>882390 Gemini GXL 6 Slice<\/li>\n\t<li>882410 Gemini GXL 16 Slice<\/li>\n\t<li>882412 GEMINI LXL<\/li>\n\t<li>882473 Gemini TF Ready<\/li>\n\t<li>882470 Gemini TF 16 w\/ TOF Performance<\/li>\n\t<li>882471 Gemini TF 64 w\/ TOF Performance<\/li>\n\t<li>882476 Gemini TF Big Bore<\/li>\n\t<li>882438 TruFlight Select PET\/CT<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-084-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-084-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-084-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-9","alert_type":398,"serial_number":"AV21-140","subject":null,"moderation_state":"published","external_url":null},{"nid":2370,"title":"Samba security advisory","uuid":"3ada59de-cd08-4fa2-b451-115b646f2e37","banner":null,"lang":"en","date_modified":"2021-03-26","date_modified_ts":"2021-03-26T15:22:56Z","date_created":"2021-03-26T15:22:56Z","summary":null,"body":["<article data-history-node-id=\"2370\" about=\"\/en\/alerts-advisories\/samba-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-141<br \/>\nDate: 26 March 2021<\/strong><\/p>\n\n<p>On 24 March 2021 Samba issued a Security Release highlighting vulnerabilities affecting several versions of its software.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Samba Security Releases<br \/><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">https:\/\/www.samba.org\/samba\/history\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-advisory-4","alert_type":396,"serial_number":"AV21-141","subject":null,"moderation_state":"published","external_url":null},{"nid":2371,"title":"SolarWinds security advisory","uuid":"2cda94ab-9c09-46d0-ac69-c1027a351c23","banner":null,"lang":"en","date_modified":"2021-03-26","date_modified_ts":"2021-03-26T17:55:34Z","date_created":"2021-03-26T17:55:34Z","summary":null,"body":["<article data-history-node-id=\"2371\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-142<br \/>\nDate: 26 March 2021<\/strong><\/p>\n\n<p>On 25 March 2021 SolarWinds published Release Notes which addressed vulnerabilities in the following product:<\/p>\n\n<ul><li>Orion Platform \u2013 versions prior to 2020.0.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an authenticated user to remotely execute code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>SolarWinds Orion Platform<br \/><a href=\"https:\/\/documentation.solarwinds.com\/en\/Success_Center\/orionplatform\/content\/release_notes\/orion_platform_2020-2-5_release_notes.htm\">https:\/\/documentation.solarwinds.com\/en\/Success_Center\/orionplatform\/content\/release_notes\/orion_platform_2020-2-5_release_notes.htm<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-0","alert_type":396,"serial_number":"AV21-142","subject":null,"moderation_state":"published","external_url":null},{"nid":2372,"title":"Apple security advisory","uuid":"b3ecbeae-de5d-442c-9dd5-cdb0ad4bb668","banner":null,"lang":"en","date_modified":"2021-03-29","date_modified_ts":"2021-03-29T13:55:51Z","date_created":"2021-03-29T13:55:51Z","summary":null,"body":["<article data-history-node-id=\"2372\" about=\"\/en\/alerts-advisories\/apple-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-143<br \/>\nDate: 29 March 2021<\/strong><\/p>\n\n<p>On 26 March 2021 Apple published Security Updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 12.5.2<\/li>\n\t<li>iOS \u2013 versions prior to 14.4.2<\/li>\n\t<li>iPadOS \u2013 versions prior to 14.4.2<\/li>\n\t<li>watchOS \u2013 versions prior to 7.3.3<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in universal cross-site scripting. Apple is aware of a report that this vulnerability may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>iOS and iPadOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212256\">https:\/\/support.apple.com\/en-ca\/HT212256<\/a><br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212257\">https:\/\/support.apple.com\/en-ca\/HT212257<\/a><\/p>\n\n<p>WatchOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212258\">https:\/\/support.apple.com\/en-ca\/HT212258<\/a><\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-27","alert_type":396,"serial_number":"AV21-143","subject":null,"moderation_state":"published","external_url":null},{"nid":2373,"title":"IBM security advisory","uuid":"9e702834-11db-4f08-af88-4baa4e1e0829","banner":null,"lang":"en","date_modified":"2021-03-29","date_modified_ts":"2021-03-29T14:19:41Z","date_created":"2021-03-29T14:19:41Z","summary":null,"body":["<article data-history-node-id=\"2373\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-42\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-144<br \/>\nDate: 29 March 2021<\/strong><br \/>\n\u00a0<br \/>\nBetween 22 and 28 March 2021 IBM published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM License Metric Tool - all versions<\/li>\n\t<li>Operations Dashboard - versions 2020.2.1, 2020.3.1 and 2020.4.1-0-eus<\/li>\n\t<li>IBM Operational Decision Manager - versions 8.8.x, 8.9.x and 8.10.x<\/li>\n\t<li>App Connect for Manufacturing - version 2.0.0.5<\/li>\n\t<li>IBM Cloud Pak for Integration (CP4I) Operator - versions 2020.2.1, 2020.3.1 and 2020.4.1-0-eus<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (CP4I) - versions 2020.2.1, 2020.3.1 and 2020.4.1-0-eusAsset Repository in IBM Cloud Pak for Integration (CP4I) - versions 2020.2.1, 2020.3.1 and 2020.4.1-0-eus<\/li>\n\t<li>IBM Tivoli Netcool Impact - versions 7.1.0.0 to 7.1.0.20<\/li>\n\t<li>IBM Elastic Storage Server - versions 5.3.0 to 5.3.6.2<\/li>\n\t<li>IBM Connect: Direct for UNIX - versions 6.1.0 and 6.0.0<\/li>\n\t<li>IBM Sterling Connect: Direct for UNIX - versions 4.3.0 and 4.2.0<\/li>\n\t<li>IBM Lift - all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\n\u00a0<br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-42","alert_type":396,"serial_number":"AV21-144","subject":null,"moderation_state":"published","external_url":null},{"nid":2374,"title":"Ubuntu security advisory","uuid":"b6870aa9-6ea6-40e1-a0cc-bd3fa84cd60f","banner":null,"lang":"en","date_modified":"2021-03-30","date_modified_ts":"2021-03-30T13:36:24Z","date_created":"2021-03-30T13:36:24Z","summary":null,"body":["<article data-history-node-id=\"2374\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-145<br \/>\nDate: 30 March 2021<\/strong><\/p>\n\n<p>On 29 March 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, access to sensitive information, or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4883-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4883-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4883-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4890-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4890-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4890-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-10","alert_type":396,"serial_number":"AV21-145","subject":null,"moderation_state":"published","external_url":null},{"nid":2375,"title":"VMware security advisory","uuid":"f7b9ee47-feca-44c7-b358-36c3dd57bf0b","banner":null,"lang":"en","date_modified":"2021-03-31","date_modified_ts":"2021-03-31T11:32:30Z","date_created":"2021-03-31T11:32:30Z","summary":null,"body":["<article data-history-node-id=\"2375\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-146<br \/>\nDate: 31 March 2021<\/strong><\/p>\n\n<p>On 30 March 2021 VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware vRealize Operations \u2013 multiple versions and platforms<\/li>\n\t<li>VMware Cloud Foundation \u2013 versions 3.x and 4.x<\/li>\n\t<li>vRealize Suite Lifecycle Manager \u2013 version 8.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0004)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0004.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0004.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-37","alert_type":396,"serial_number":"AV21-146","subject":null,"moderation_state":"published","external_url":null},{"nid":2376,"title":"Google Chrome security advisory","uuid":"25f350bb-2cb4-4b81-b0ea-b19b49940f61","banner":null,"lang":"en","date_modified":"2021-03-31","date_modified_ts":"2021-03-31T14:06:09Z","date_created":"2021-03-31T14:06:09Z","summary":null,"body":["<article data-history-node-id=\"2376\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-50\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-147<br \/>\nDate: 31 March 2021<\/strong><\/p>\n\n<p>On 30 March 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 89.0.4389.114<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop_30.html\">https:\/\/chromereleases.googleblog.com\/2021\/03\/stable-channel-update-for-desktop_30.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-50","alert_type":396,"serial_number":"AV21-147","subject":null,"moderation_state":"published","external_url":null},{"nid":2377,"title":"HPE security advisory","uuid":"9486d13c-961f-43a2-a284-d52bb9943aeb","banner":null,"lang":"en","date_modified":"2021-04-01","date_modified_ts":"2021-04-01T13:53:19Z","date_created":"2021-04-01T13:53:19Z","summary":null,"body":["<article data-history-node-id=\"2377\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-148<br \/>\nDate: 1 April 2021<\/strong><\/p>\n\n<p>On 31 March 2021 HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Tomcat-based Servlet v.7.x Engine \u2013 version D.7.0.104.01 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow an actor to remotely execute code, cause denial of service, and expose sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (HP-UX Tomcat-based Servlet v.7.x Engine)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04114en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04114en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-13","alert_type":396,"serial_number":"AV21-148","subject":null,"moderation_state":"published","external_url":null},{"nid":2379,"title":"[Control systems] Rockwell Automation security advisory","uuid":"0cea882c-8a4e-4970-915b-23e4a2b1480e","banner":null,"lang":"en","date_modified":"2021-04-06","date_modified_ts":"2021-04-06T13:51:02Z","date_created":"2021-04-06T13:51:02Z","summary":null,"body":["<article data-history-node-id=\"2379\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-149<br \/>\nDate: 6 April 2021<\/strong><\/p>\n\n<p>On 1 April 2021, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>FactoryTalk AssetCentre - version 10.00 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a remote actor to execute arbitrary commands, execute arbitrary code and perform SQL injection.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-091-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-091-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-091-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-15","alert_type":398,"serial_number":"AV21-149","subject":null,"moderation_state":"published","external_url":null},{"nid":2483,"title":"Exploitation of Fortinet FortiOS vulnerabilities (CISA, FBI) - update 1","uuid":"35098da4-1a61-45f6-a84d-28e2241d8d43","banner":null,"lang":"en","date_modified":"2021-05-28","date_modified_ts":"2021-05-28T16:36:23Z","date_created":"2021-04-06T17:46:11Z","summary":null,"body":["<article data-history-node-id=\"2483\" about=\"\/en\/alerts-advisories\/exploitation-fortinet-fortios-vulnerabilities-cisa-fbi\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-005 UPDATE 1\n  <br \/>\n  Date: 6 April 2021\n  <br \/>\n  Updated: 28 May 2021<\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>PURPOSE\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>ASSESSMENT\n<\/h2>\n<p>On 2 April 2021, the Cybersecurity and Infrastructure Security Agency (CISA), the United States\u2019 agency responsible for protecting its critical infrastructure from physical and cyber threats, and the Federal Bureau of Investigation (FBI) issued a Joint Cybersecurity Advisory [<a href=\"https:\/\/www.ic3.gov\/Media\/News\/2021\/210402.pdf\">1<\/a>], drawing attention to recent scanning and exploitation of vulnerabilities within unpatched Fortinet devices.\n<\/p>\n<p>The advisory states that sophisticated actors have been observed scanning for and are believed to be exploiting three specific vulnerabilities in FortiOS:\n<\/p>\n<ul><li>CVE-2018-13379: A path traversal vulnerability in FortiOS<\/li>\n  <li>CVE-2020-12812: An improper authentication vulnerability in FortiOS SSL VPN<\/li>\n  <li>CVE-2019-5591: A default configuration vulnerability in FortiOS<\/li>\n<\/ul><p>Fortinet has previously published updates to address all the above vulnerabilities and the Cyber Centre reported on CVE-2018-13379 in August 2019. [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-vpn-vulnerabilities\">2<\/a>]\n<\/p>\n<p>The advisory claims that the actors may be using these CVEs alone or in combination to gain access to networks across multiple sectors, including government, commercial and technical services, to pre-position for eventual data exfiltration or data encryption activity.\n<\/p>\n<p>The Cyber Centre would like to highlight this advisory, as it provides important information to system owners and operators responsible for defending their systems and networks from cyber threats.\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<p><strong>UPDATE 1<\/strong>\n<\/p>\n<p>On 27 May 2021, in coordination with CISA, the FBI published an FBI FLASH with an updated warning of continued exploitation of vulnerabilities in FortiOS (CVE-2018-13379, CVE-2020-12812, and CVE-2019-5591) by sophisticated actors. The FBI FLASH states that sophisticated actors exploited vulnerabilities in a Fortigate appliance to access a webserver hosting the domain for a U.S. municipal government. Refer to the FBI FLASH for further details and recommended mitigations.\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>[1] APT Actors Exploit Vulnerabilities to Gain Initial Access for Future Attacks (CISA, FBI)\n  <br \/><a href=\"https:\/\/www.ic3.gov\/Media\/News\/2021\/210402.pdf\">https:\/\/www.ic3.gov\/Media\/News\/2021\/210402.pdf<\/a>\n<\/p>\n<p>[2] Cyber Centre Alert on Active Exploitation of VPN Vulnerabilities (AL19-016):\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-vpn-vulnerabilities\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-vpn-vulnerabilities<\/a>\n<\/p>\n<p>[3] APT Actors Exploiting Fortinet Vulnerabilities to Gain Access for Malicious Activity (CISA, FBI)\n  <br \/><a href=\"https:\/\/www.ic3.gov\/Media\/News\/2021\/210527.pdf\">https:\/\/www.ic3.gov\/Media\/News\/2021\/210527.pdf<\/a>\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exploitation-fortinet-fortios-vulnerabilities-cisa-fbi","alert_type":397,"serial_number":"AL21-005","subject":null,"moderation_state":"published","external_url":null},{"nid":2380,"title":"VMware security advisory","uuid":"d3993f13-1939-4966-90fe-59f2fb11e901","banner":null,"lang":"en","date_modified":"2021-04-06","date_modified_ts":"2021-04-06T18:02:36Z","date_created":"2021-04-06T18:02:36Z","summary":null,"body":["<article data-history-node-id=\"2380\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-150<br \/>\nDate: 6 April 2021<\/strong><br \/><br \/>\nOn 1 April 2021 VMware published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Carbon Black Cloud Workload appliance \u2013 version 1.0.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor with network access to view and alter administrative configuration settings.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0005)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0005.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0005.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-38","alert_type":396,"serial_number":"AV21-150","subject":null,"moderation_state":"published","external_url":null},{"nid":2381,"title":"[Control systems] Hitachi ABB security advisory","uuid":"03184b14-e2c2-44b4-bcf1-bfdbac158bab","banner":null,"lang":"en","date_modified":"2021-04-07","date_modified_ts":"2021-04-07T13:59:37Z","date_created":"2021-04-07T13:57:53Z","summary":null,"body":["<article data-history-node-id=\"2381\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-151<br \/>\nDate: 7 April 2021<\/strong><\/p>\n\n<p>On 6 April 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Relion 670\/650\/SAM600-IO series \u2013 multiple versions\u00a0<\/li>\n\t<li>RTU500 CMU - firmware release 7.x, 8.x, 9.x, 10.x, 11.x, 12.x\u00a0<\/li>\n\t<li>REB500 \u2013 version 7.3, 7.4, 7.5, 7.6<\/li>\n\t<li>REB500 \u2013 version 8.2 and 8.3<\/li>\n\t<li>TEGO1 service unit of FOX615 with ESW - version R1D02 and prior\u00a0<\/li>\n\t<li>MSM - versions prior to 2.1.0<\/li>\n\t<li>GMS600 - version 1.3.0 and prior\u00a0<\/li>\n\t<li>PWC600 - version 1.0 and 1.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigation and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-096-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-096-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-096-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-security-advisory-0","alert_type":398,"serial_number":"AV21-151","subject":null,"moderation_state":"published","external_url":null},{"nid":2382,"title":"Android security advisory \u2013 April 2021 monthly rollup","uuid":"92fd952d-4864-49e8-b64e-c658ef78d4fe","banner":null,"lang":"en","date_modified":"2021-04-07","date_modified_ts":"2021-04-07T14:04:01Z","date_created":"2021-04-07T14:04:01Z","summary":null,"body":["<article data-history-node-id=\"2382\" about=\"\/en\/alerts-advisories\/android-security-advisory-april-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-152<br \/>\nDate: 7 April 2021<\/strong><\/p>\n\n<p>On 5 April 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-04-01\">https:\/\/source.android.com\/security\/bulletin\/2021-04-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-april-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-152","subject":null,"moderation_state":"published","external_url":null},{"nid":2383,"title":"Malicious actors targeting SAP Applications","uuid":"04ef11c3-b1e8-4792-bc28-c847133ebabf","banner":null,"lang":"en","date_modified":"2021-04-08","date_modified_ts":"2021-04-08T13:01:29Z","date_created":"2021-04-08T12:34:56Z","summary":null,"body":["<article data-history-node-id=\"2383\" about=\"\/en\/alerts-advisories\/malicious-actors-targeting-sap-applications\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-006\n  <br \/>\n  Date: 8 April 2021<\/strong>\n<\/p>\n<h3>AUDIENCE\n<\/h3>\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.\n<\/p>\n<h3>PURPOSE\n<\/h3>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h3>OVERVIEW\n<\/h3>\n<p>Onapsis, in partnership with SAP, a supplier of widely used business software, released a threat intelligence report detailing ongoing and extensive targeting of vulnerabilities within SAP applications by Advanced Persistent Threat (APT) actors.\n<\/p>\n<h3>DETAILS\n<\/h3>\n<p>On 6 April 2021, Onapsis and SAP released a threat intelligence report to highlight an APT scanning and exploitation campaign targeting unpatched vulnerable SAP applications. SAP had published patches and mitigation recommendations for the targeted vulnerabilities shortly after discovery. Onapsis and SAP report that they continue to observe organizations failing to patch or apply relevant mitigation recommendations, and that this leaves servers vulnerable to compromise.\n<\/p>\n<p>The report further outlines how actors are both scanning for vulnerable systems to position for future compromise and developing means to exploit the vulnerabilities within a short period of time. If left unpatched these vulnerabilities could lead to full control of SAP applications which may result in the theft of sensitive information, financial fraud or the disruption of mission-critical business by deploying ransomware.\n<\/p>\n<h3>SUGGESTED ACTION\n<\/h3>\n<p>The Cyber Centre encourages those organizations operating SAP environments to:\n<\/p>\n<ul><li>refer to the Onapsis report [<a href=\"https:\/\/onapsis.com\/active-cyberattacks-mission-critical-sap-applications\">1<\/a>] for detection techniques and to determine impact,<\/li>\n  <li>patch all affected applications starting with Internet accessible systems.<\/li>\n<\/ul><p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h3>REFERENCES\n<\/h3>\n<p>[1] Onapsis Threat Intelligence Report Active Cyberattacks on Mission Critical SAP Applications:\n  <br \/><a href=\"https:\/\/onapsis.com\/active-cyberattacks-mission-critical-sap-applications\">https:\/\/onapsis.com\/active-cyberattacks-mission-critical-sap-applications<\/a>\n<\/p>\n<p>[2] Cyber Centre Alert on SAP NetWeaver Java Vulnerability:\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/sap-netweaver-java-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/sap-netweaver-java-vulnerability<\/a>\n<\/p>\n<p>\u00a0\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/malicious-actors-targeting-sap-applications","alert_type":397,"serial_number":"AL21-006","subject":null,"moderation_state":"published","external_url":null},{"nid":2384,"title":"Cisco security advisory","uuid":"9916d494-3d48-40b8-8d00-e729aa10aa5e","banner":null,"lang":"en","date_modified":"2021-04-08","date_modified_ts":"2021-04-08T14:44:21Z","date_created":"2021-04-08T14:44:21Z","summary":null,"body":["<article data-history-node-id=\"2384\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-78\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-153<br \/>\nDate: 8 April 2021<\/strong><\/p>\n\n<p>On 7 April 2020 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco SD-WAN vManage Software \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation could allow an unauthenticated remote actor to execute arbitrary code or gain privileged access on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco SD-WAN vManage Software<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-vmanage-YuTVWqy\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-vmanage-YuTVWqy<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-78","alert_type":396,"serial_number":"AV21-153","subject":null,"moderation_state":"published","external_url":null},{"nid":2385,"title":"[Control systems] FATEK security advisory","uuid":"c903a78a-82cb-4191-9926-cd42f446ea93","banner":null,"lang":"en","date_modified":"2021-04-09","date_modified_ts":"2021-04-09T12:47:24Z","date_created":"2021-04-09T12:47:24Z","summary":null,"body":["<article data-history-node-id=\"2385\" about=\"\/en\/alerts-advisories\/control-systems-fatek-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-154<br \/>\nDate: 9 April 2021<\/strong><\/p>\n\n<p>On 8 April 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>WinProladder - version 3.30 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to execution of arbitrary code.<br \/>\n\u00a0<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigation and apply the necessary update when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-098-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-098-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-098-01<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-security-advisory-0","alert_type":398,"serial_number":"AV21-154","subject":null,"moderation_state":"published","external_url":null},{"nid":2386,"title":"SAP security advisory \u2013 April 2021 monthly rollup","uuid":"088a4d6c-5268-481e-9b0f-5cdeb9b83d66","banner":null,"lang":"en","date_modified":"2021-04-13","date_modified_ts":"2021-04-13T19:30:46Z","date_created":"2021-04-13T19:21:33Z","summary":null,"body":["<article data-history-node-id=\"2386\" about=\"\/en\/alerts-advisories\/sap-security-advisory-april-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-155<br \/>\nDate: 13 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical severity updates for the following:<\/p>\n\n<ul><li>SAP Business Client - version 6.5<\/li>\n\t<li>SAP Commerce - versions 1808, 1811, 1905, 2005 and 2011<\/li>\n\t<li>SAP NetWeaver AS JAVA (MigrationService) - versions 7.10, 7.11, 7.30, 7.31, 7.40 and 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<br \/><br \/>\nSAP Security Patch Day \u2013 April 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=573801649\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=573801649<\/a><br \/><br \/><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-april-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-155","subject":null,"moderation_state":"published","external_url":null},{"nid":2387,"title":"Adobe security advisory","uuid":"58feedf0-060b-40a9-bb8a-06ed8bac8b4f","banner":null,"lang":"en","date_modified":"2021-04-13","date_modified_ts":"2021-04-13T20:01:12Z","date_created":"2021-04-13T20:01:12Z","summary":null,"body":["<article data-history-node-id=\"2387\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-39\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-156<br \/>\nDate: 13 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021 Adobe published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Photoshop 2020 \u2013 version 21.2.6 and prior<\/li>\n\t<li>Adobe Photoshop 2021 \u2013 version 22.3 and prior<\/li>\n\t<li>Adobe Digital Editions \u2013 version 4.5.11.187245 and prior<\/li>\n\t<li>Adobe Bridge \u2013 versions 10.1.1, 11.0.1 and prior<\/li>\n\t<li>Adobe RoboHelp \u2013 versions RH2020.0.3 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Photoshop<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb21-28.html\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb21-28.html<\/a><\/p>\n\n<p>Adobe Digital Editions<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb21-26.html\">https:\/\/helpx.adobe.com\/security\/products\/Digital-Editions\/apsb21-26.html<\/a><\/p>\n\n<p>Adobe Bridge<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb21-23.html\">https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb21-23.html<\/a><\/p>\n\n<p>Adobe RoboHelp<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/robohelp\/apsb21-20.html\">https:\/\/helpx.adobe.com\/security\/products\/robohelp\/apsb21-20.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-39","alert_type":396,"serial_number":"AV21-156","subject":null,"moderation_state":"published","external_url":null},{"nid":2388,"title":"Microsoft security advisory \u2013 April 2021 monthly rollup","uuid":"76f6fbac-eaa2-4c3f-85b8-69e08f497466","banner":null,"lang":"en","date_modified":"2021-04-13","date_modified_ts":"2021-04-13T21:09:18Z","date_created":"2021-04-13T21:09:18Z","summary":null,"body":["<article data-history-node-id=\"2388\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-157<br \/>\nDate: 13 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 10, 8.1, RT 8.1 and 7<\/li>\n\t<li>Windows Server and Server Core<\/li>\n\t<li>Microsoft Azure-related software<\/li>\n\t<li>Microsoft Exchange<\/li>\n<\/ul><p>Microsoft has indicated that the vulnerabilities fixed in the April 2021 security updates affecting Microsoft Exchange products are different from those previously patched in March 2021. Therefore, running March 2021 security tools and scripts will not mitigate these newly identified vulnerabilities. Microsoft reports that these vulnerabilities, reported by a security partner, have not yet been exploited.<\/p>\n\n<p>Microsoft recommends that organizations update on-prem servers as soon as possible as Microsoft Exchange Online customers are already protected by the April 2021 security updates.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>April 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Apr\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Apr<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-april-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-157","subject":null,"moderation_state":"published","external_url":null},{"nid":2389,"title":"[Control systems] Advantech security advisory","uuid":"495a1e1d-5b41-43b3-ad2e-589bd4f303b7","banner":null,"lang":"en","date_modified":"2021-04-14","date_modified_ts":"2021-04-14T12:55:19Z","date_created":"2021-04-14T12:55:19Z","summary":null,"body":["<article data-history-node-id=\"2389\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-158<br \/>\nDate: 14 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>WebAccess\/SCADA - version 9.0.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to login as an \u2018admin\u2019 to fully control the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-103-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-103-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-103-02<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-14","alert_type":398,"serial_number":"AV21-158","subject":null,"moderation_state":"published","external_url":null},{"nid":2390,"title":"[Control systems] JTEKT security advisory","uuid":"7d7bc060-803b-463e-8f1c-a62af00713b0","banner":null,"lang":"en","date_modified":"2021-04-14","date_modified_ts":"2021-04-14T12:58:43Z","date_created":"2021-04-14T12:58:43Z","summary":null,"body":["<article data-history-node-id=\"2390\" about=\"\/en\/alerts-advisories\/control-systems-jtekt-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-159<br \/>\nDate: 14 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>TOYOPUC-PC10 Series:\n\t<ul><li>PC10G-CPU TCC-6353 - all versions<\/li>\n\t\t<li>PC10GE TCC-6464 - all versions<\/li>\n\t\t<li>PC10P TCC-6372 - all versions<\/li>\n\t\t<li>PC10P-DP TCC-6726 - all versions<\/li>\n\t\t<li>PC10P-DP-IO TCC-6752 - all versions<\/li>\n\t\t<li>PC10B-P TCC-6373 - all versions<\/li>\n\t\t<li>PC10B TCC-1021 - all versions<\/li>\n\t\t<li>PC10B-E\/C TCU-6521 - all versions<\/li>\n\t\t<li>PC10E TCC-4737 - all versions<\/li>\n\t<\/ul><\/li>\n\t<li>TOYOPUC-Plus Series:\n\t<ul><li>Plus CPU TCC-6740 - all versions<\/li>\n\t\t<li>Plus EX TCU-6741 - all versions<\/li>\n\t\t<li>Plus EX2 TCU-6858 - all versions<\/li>\n\t\t<li>Plus EFR TCU-6743 - all versions<\/li>\n\t\t<li>Plus EFR2 TCU-6859 - all versions<\/li>\n\t\t<li>Plus 2P-EFR TCU-6929 - all versions<\/li>\n\t\t<li>Plus BUS-EX TCU-6900 - all versions<\/li>\n\t<\/ul><\/li>\n\t<li>TOYOPUC-PC3J\/PC2J Series:\n\t<ul><li>FL\/ET-T-V2H THU-6289 - all versions<\/li>\n\t\t<li>2PORT-EFR THU-6404 - all versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthorized actor to stop Ethernet communications between devices from being established.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-103-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-103-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-103-03<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-jtekt-security-advisory","alert_type":398,"serial_number":"AV21-159","subject":null,"moderation_state":"published","external_url":null},{"nid":2391,"title":"[Control systems] Schneider Electric security advisory","uuid":"8d1f1f60-36b5-454d-9626-f99a65c0572d","banner":null,"lang":"en","date_modified":"2021-04-14","date_modified_ts":"2021-04-14T13:13:50Z","date_created":"2021-04-14T13:13:50Z","summary":null,"body":["<article data-history-node-id=\"2391\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-160<br \/>\nDate: 14 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>SoMachine Basic \u2013 versions prior to v1.6 SP1<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in disclosure and retrieval of arbitrary data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-103-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-103-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-103-01<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-18","alert_type":398,"serial_number":"AV21-160","subject":null,"moderation_state":"published","external_url":null},{"nid":2392,"title":"[Control systems] Siemens security advisory","uuid":"bb6da0b5-3062-47ee-8b56-444cfdd75a16","banner":null,"lang":"en","date_modified":"2021-04-14","date_modified_ts":"2021-04-14T13:21:16Z","date_created":"2021-04-14T13:21:16Z","summary":null,"body":["<article data-history-node-id=\"2392\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-161<br \/>\nDate: 14 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Tecnomatix RobotExpert \u2013 all versions prior to V16.1<\/li>\n\t<li>Nucleus Products \u2013 multiple models and versions<\/li>\n\t<li>SCALANCE X-200 \u2013 multiple models and versions<\/li>\n\t<li>SINEMA Remote Connect Server \u2013 all versions prior to V3.0<\/li>\n\t<li>TIM 4R-IE (Inc. SIPLUS NET variants) - all versions<\/li>\n\t<li>TIM 4R-IE DNP3 (Inc. SIPLUS NET variants) - all versions<\/li>\n\t<li>Solid Edge SE2020 \u2013 all versions prior to SE2020MP13<\/li>\n\t<li>Solid Edge SE2021 \u2013 all versions prior to SE2021MP4<\/li>\n\t<li>SIMOTICS CONNECT 400 \u2013 all versions prior to V0.5.0.0<\/li>\n\t<li>Control Center Server \u2013 all versions prior to V1.5.0<\/li>\n\t<li>Opcenter Quality \u2013 all versions prior to V12.2<\/li>\n\t<li>QMS Automotive \u2013 all versions prior to V12.30<\/li>\n\t<li>Siveillance Video Open Network Bridge \u2013 versions 2018-R2, 2018-R3, 2019-R1 to R3, 2020-R1 to R3<\/li>\n\t<li>LOGO! Soft Comfort \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-22","alert_type":398,"serial_number":"AV21-161","subject":null,"moderation_state":"published","external_url":null},{"nid":2393,"title":"IBM security advisory","uuid":"c1414991-d9d4-4281-bc41-3f6188d6a0d0","banner":null,"lang":"en","date_modified":"2021-04-14","date_modified_ts":"2021-04-14T13:24:48Z","date_created":"2021-04-14T13:24:48Z","summary":null,"body":["<article data-history-node-id=\"2393\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-43\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-162<br \/>\nDate: 14 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Rational Business Developer \u2013 versions 9.5 and 9.6<\/li>\n\t<li>IBM Network Performance Insight \u2013 version 1.3.1<\/li>\n\t<li>IBM Cloud Transformation Advisor \u2013 versions 2.4.0 and 2.4.1<\/li>\n\t<li>IBM Tivoli Composite Application Manager for Transactions - Robotic Response Time \u2013 version 7.4.0.x<\/li>\n\t<li>IBM Sterling Connect Direct File Agent \u2013 versions 1.4.0.0 to 1.4.0.1_iFix005 (AIX and Linux only)<\/li>\n\t<li>IBM Sterling Connect:Direct FTP+ - version 1.3 (AIX and Linux only)<\/li>\n\t<li>IBM Java SDK and IBM Java Runtime for IBM i\u00a0 - versions 7.1, 7.2, 7.3 and 7.4<\/li>\n\t<li>Content Collector (multiple modules) - version 4.0.1.x<\/li>\n\t<li>IBM Watson Machine Learning on CP4D \u2013 versions 2.5 and 3.0<\/li>\n\t<li>IBM Watson Explorer Content Analytics Studio - multiple modules and versions<\/li>\n\t<li>WebSphere Extreme Scale \u2013 versions 8.6.0 and 8.6.1<\/li>\n\t<li>DataQuant for z\/OS - version 2.1<\/li>\n\t<li>IBM Continuous Engineering products based on IBM Jazz Technology - multiple products and versions<\/li>\n\t<li>SPSS Collaboration and Deployment Services \u2013 versions 7.0.0.1, 8.0, 8.1, 8.1.1, 8.2, 8.2.1 and 8.2.2<\/li>\n\t<li>DB2 Query Management Facility - multiple platforms, editions and versions<\/li>\n\t<li>Rational Function Tester \u2013 versions 9.1, 9.2 and 9.5<\/li>\n\t<li>IBM TXSeries for Multiplatforms \u2013 versions 8.2.0.0 to 8.2.0.2 and 9.1.0.0 to 9.1.0.1<\/li>\n\t<li>Capilano (Installation Manager) - version 1.9.x<\/li>\n\t<li>IBM Watson OpenScale (on Cloud Pak for Data) - version 3.5.0<\/li>\n\t<li>Power Hardware Management Console (HMC) - versions 9.1.910.0 and later and 9.2.950.0 and later<\/li>\n\t<li>IBM CICS TX on Cloud - version 10.1.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-43","alert_type":396,"serial_number":"AV21-162","subject":null,"moderation_state":"published","external_url":null},{"nid":2394,"title":"Google Chrome security advisory","uuid":"6b02643b-ac67-44ec-8ae1-475bab99967a","banner":null,"lang":"en","date_modified":"2021-04-14","date_modified_ts":"2021-04-14T15:37:58Z","date_created":"2021-04-14T15:37:58Z","summary":null,"body":["<article data-history-node-id=\"2394\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-51\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-163<br \/>\nDate: 14 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 89.0.4389.128<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution. Google has received reports that these vulnerabilities have available exploits.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-51","alert_type":396,"serial_number":"AV21-163","subject":null,"moderation_state":"published","external_url":null},{"nid":2395,"title":"[Control systems] Siemens security advisory","uuid":"a25c5e10-b34b-4365-86bd-eb3e9c6647e9","banner":null,"lang":"en","date_modified":"2021-04-15","date_modified_ts":"2021-04-15T12:51:09Z","date_created":"2021-04-15T12:51:09Z","summary":null,"body":["<article data-history-node-id=\"2395\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-164<br \/>\nDate: 15 April 2021<\/strong><\/p>\n\n<p>On 14 April 2021 Siemens published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Mendix applications using:\n\t<ul><li>Mendix 7 \u2013 versions prior to V7.23.19<\/li>\n\t\t<li>Mendix 8 - versions prior to V8.17.0<\/li>\n\t\t<li>Mendix 8 (v8.12) - versions prior to V8.12.5<\/li>\n\t\t<li>Mendix 8 (v8.6) - versions prior to V8.6.9<\/li>\n\t\t<li>Mendix 9 \u2013 versions prior to V9.0.5<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisory (SSA-875726)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-875726.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-875726.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-23","alert_type":398,"serial_number":"AV21-164","subject":null,"moderation_state":"published","external_url":null},{"nid":2396,"title":"Ubuntu security advisory","uuid":"4d772474-43b6-43a8-a0dd-8a144a254612","banner":null,"lang":"en","date_modified":"2021-04-15","date_modified_ts":"2021-04-15T14:42:38Z","date_created":"2021-04-15T14:42:38Z","summary":null,"body":["<article data-history-node-id=\"2396\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-165<br \/>\nDate: 15 April 2021<\/strong><\/p>\n\n<p>On 13 April 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, access to sensitive information, or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-11","alert_type":396,"serial_number":"AV21-165","subject":null,"moderation_state":"published","external_url":null},{"nid":2397,"title":"Juniper Networks security advisory","uuid":"b2649b2a-2aa9-4f7a-9857-6c7490ef8182","banner":null,"lang":"en","date_modified":"2021-04-15","date_modified_ts":"2021-04-15T14:48:01Z","date_created":"2021-04-15T14:48:01Z","summary":null,"body":["<article data-history-node-id=\"2397\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-166<br \/>\nDate: 15 April 2021<\/strong><\/p>\n\n<p>On 14 April 2021 Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Junos OS on NFX Series \u2013 versions prior to 19.1R1<\/li>\n\t<li>Junos OS overlayd service \u2013 multiple versions on multiple platforms<\/li>\n\t<li>Juniper Networks AppFormix 3 \u2013 versions prior to 3.1.22, 3.2.14 and 3.3.0<\/li>\n\t<li>SRC Series \u2013 versions prior to 4.13.0-R5<\/li>\n\t<li>Junos Space Security Director \u2013 versions prior to 21.1R1<\/li>\n\t<li>Junos Space \u2013 versions prior to 21.1R1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution, use of hard-coded credentials for system takeover, denial of service condition and execute commands as root.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Juniper Networks Security Bulletins<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-8","alert_type":396,"serial_number":"AV21-166","subject":null,"moderation_state":"published","external_url":null},{"nid":2398,"title":"Google Chrome security advisory","uuid":"714aa1e9-1e61-4d1f-b2af-486e120bf519","banner":null,"lang":"en","date_modified":"2021-04-15","date_modified_ts":"2021-04-15T17:35:47Z","date_created":"2021-04-15T17:35:47Z","summary":null,"body":["<article data-history-node-id=\"2398\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-52\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-167<br \/>\nDate: 15 April 2021<\/strong><\/p>\n\n<p>On 14 April 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 90.0.4430.72<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available:<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop_14.html\">https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop_14.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-52","alert_type":396,"serial_number":"AV21-167","subject":null,"moderation_state":"published","external_url":null},{"nid":2446,"title":"APT Actors Target U.S. and Allied Networks - update 1","uuid":"3a2898e3-cb95-4125-8e57-54e530a4ce62","banner":null,"lang":"en","date_modified":"2021-05-07","date_modified_ts":"2021-05-07T18:54:34Z","date_created":"2021-04-15T19:20:55Z","summary":null,"body":["<article data-history-node-id=\"2446\" about=\"\/en\/alerts-advisories\/apt-actors-target-us-and-allied-networks-nsacisafbi\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-007 UPDATE 1\n  <br \/>\n  Date: 15 April 2021\n  <br \/>\n  Updated: 7 May 2021<\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>PURPOSE\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>OVERVIEW\n<\/h2>\n<p>The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) issued a Joint Cybersecurity Advisory [<a href=\"https:\/\/media.defense.gov\/2021\/Apr\/15\/2002621240\/-1\/-1\/0\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF\">1<\/a>] detailing targeting and exploitation of several vulnerabilities by advanced persistent threat (APT) actors.\n<\/p>\n<p><strong>UPDATE 1<\/strong>\n<\/p>\n<p>On 7 May 2021 the United Kingdom's National Cyber Security Centre (NCSC-UK) published an advisory which outlines additional information associated with APT actors which includes exploited vulnerabilities and post exploitation techniques. [<a href=\"https:\/\/www.ncsc.gov.uk\/news\/joint-advisory-further-ttps-associated-with-svr-cyber-actors\">6<\/a>]\n<\/p>\n<h2>ASSESSMENT\n<\/h2>\n<p>On 15 April 2021, the NSA, CISA, and FBI issued a Joint Cybersecurity Advisory [<a href=\"https:\/\/media.defense.gov\/2021\/Apr\/15\/2002621240\/-1\/-1\/0\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF\">1<\/a>], drawing attention to widespread scanning and exploitation of several vulnerabilities by APT actors. The advisory states that the APT actors are targeting vulnerable systems to obtain authentication credentials and enable further access within networks, including national security and government systems.\n<\/p>\n<p>Examples of recent activity include compromising SolarWinds Orion updates, targeting COVID-19 research facilities, and leveraging a VMWare vulnerability for authentication abuse.\n<\/p>\n<p>The Cybersecurity Advisory highlights the following vulnerabilities being exploited:\n<\/p>\n<ul><li>CVE-2018-13379 Fortinet [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/exploitation-fortinet-fortios-vulnerabilities-cisa-fbi\">2<\/a>], [<a href=\"https:\/\/media.defense.gov\/2020\/Jul\/16\/2002457639\/-1\/-1\/0\/NCSC_APT29_ADVISORY-QUAD-OFFICIAL-20200709-1810.PDF\">3<\/a>]<\/li>\n  <li>CVE-2019-9670 Zimbra [<a href=\"https:\/\/media.defense.gov\/2020\/Jul\/16\/2002457639\/-1\/-1\/0\/NCSC_APT29_ADVISORY-QUAD-OFFICIAL-20200709-1810.PDF\"><font color=\"#0066cc\">3<\/font><\/a>]<\/li>\n  <li>CVE-2019-11510 Pulse Secure [<a href=\"https:\/\/media.defense.gov\/2020\/Jul\/16\/2002457639\/-1\/-1\/0\/NCSC_APT29_ADVISORY-QUAD-OFFICIAL-20200709-1810.PDF\"><font color=\"#0066cc\">3<\/font><\/a>], [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/continued-threat-actor-exploitation-post-pulse-secure-vpn-patching-cisa\">4<\/a>]<\/li>\n  <li>CVE-2019-19781 Citrix [<a href=\"https:\/\/media.defense.gov\/2020\/Jul\/16\/2002457639\/-1\/-1\/0\/NCSC_APT29_ADVISORY-QUAD-OFFICIAL-20200709-1810.PDF\"><font color=\"#0066cc\">3<\/font><\/a>]<\/li>\n  <li>CVE-2020-4006 VMware [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-vmware-vulnerability\">5<\/a>]<\/li>\n<\/ul><p><strong>UPDATE 1<\/strong> [<a href=\"https:\/\/www.ncsc.gov.uk\/news\/joint-advisory-further-ttps-associated-with-svr-cyber-actors\">6<\/a>]\n<\/p>\n<ul><li>CVE-2020-5902 F5 Big-IP<\/li>\n  <li>CVE-2020-14882 Oracle WebLogic<\/li>\n  <li>CVE-2021-21972 VMWare vSphere<\/li>\n  <li>CVE-2019-1653 Cisco router<\/li>\n  <li>CVE-2019-2725 Oracle WebLogic Server<\/li>\n  <li>CVE-2019-7609 Kibana<\/li>\n  <li>CVE-2021-26857 Exchange (SOAP payload)<\/li>\n  <li>CVE-2021-26858 Exchange (Arbitrary files)<\/li>\n  <li>CVE-2021-27065 Exchange (Arbitrary files)<\/li>\n<\/ul><p>The Cyber Centre is highlighting this advisory, as it provides important information to system owners and operators responsible for defending their systems and networks from cyber threats.\n<\/p>\n<p>There are software updates and mitigations for these vulnerabilities. See past reporting by the Cyber Center and partners for more details.\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>[1] APT Actors Exploit Vulnerabilities to Gain Initial Access for Future Attacks (NSA, CISA, FBI)\n  <br \/><a href=\"https:\/\/media.defense.gov\/2021\/Apr\/15\/2002621240\/-1\/-1\/0\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF\">https:\/\/media.defense.gov\/2021\/Apr\/15\/2002621240\/-1\/-1\/0\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF\/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF<\/a>\n<\/p>\n<p>[2] Cyber Centre Alert on Exploitation of Fortinet FortiOS vulnerabilities (CISA, FBI) (AL21-005)\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/exploitation-fortinet-fortios-vulnerabilities-cisa-fbi\">https:\/\/cyber.gc.ca\/en\/alerts\/exploitation-fortinet-fortios-vulnerabilities-cisa-fbi<\/a>\n<\/p>\n<p>[3] Joint Advisory: APT29 targets COVID-19 vaccine development\n  <br \/><a href=\"https:\/\/media.defense.gov\/2020\/Jul\/16\/2002457639\/-1\/-1\/0\/NCSC_APT29_ADVISORY-QUAD-OFFICIAL-20200709-1810.PDF\">https:\/\/media.defense.gov\/2020\/Jul\/16\/2002457639\/-1\/-1\/0\/NCSC_APT29_ADVISORY-QUAD-OFFICIAL-20200709-1810.PDF<\/a>\n<\/p>\n<p>[4] Continued threat actor exploitation post Pulse Secure VPN patching (CISA) (AL20-012)\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/continued-threat-actor-exploitation-post-pulse-secure-vpn-patching-cisa\">https:\/\/cyber.gc.ca\/en\/alerts\/continued-threat-actor-exploitation-post-pulse-secure-vpn-patching-cisa<\/a>\n<\/p>\n<p>[5] Active exploitation of VMware vulnerability (AL20-027)\n  <br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-vmware-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-vmware-vulnerability<\/a>\n<\/p>\n<p>[6] Joint advisory: Further TTPs associated with APT cyber actors\n  <br \/><a href=\"https:\/\/www.ncsc.gov.uk\/news\/joint-advisory-further-ttps-associated-with-svr-cyber-actors\">https:\/\/www.ncsc.gov.uk\/news\/joint-advisory-further-ttps-associated-with-svr-cyber-actors<\/a>\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apt-actors-target-us-and-allied-networks-nsacisafbi","alert_type":397,"serial_number":"AL21-007","subject":null,"moderation_state":"published","external_url":null},{"nid":2399,"title":"[Control systems] EIPStackGroup security advisory","uuid":"20dacdfb-e71c-4791-a2f7-5511cbdfa429","banner":null,"lang":"en","date_modified":"2021-04-16","date_modified_ts":"2021-04-16T13:46:53Z","date_created":"2021-04-16T13:46:53Z","summary":null,"body":["<article data-history-node-id=\"2399\" about=\"\/en\/alerts-advisories\/control-systems-eipstackgroup-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-168<br \/>\nDate: 16 April 2021<\/strong><\/p>\n\n<p>On 15 April 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>OpENer EtherNet\/IP \u2013 commits and versions prior to 10 February 2021<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in information disclosure and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-105-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-105-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-105-02<\/a>\u00a0\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-eipstackgroup-security-advisory","alert_type":398,"serial_number":"AV21-168","subject":null,"moderation_state":"published","external_url":null},{"nid":2400,"title":"[Control systems] Schneider Electric security advisory","uuid":"50c7e399-e1a1-43d0-989e-6fd14d7010d9","banner":null,"lang":"en","date_modified":"2021-04-16","date_modified_ts":"2021-04-16T13:51:20Z","date_created":"2021-04-16T13:51:20Z","summary":null,"body":["<article data-history-node-id=\"2400\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-169<br \/>\nDate: 16 April 2021<\/strong><\/p>\n\n<p>On 15 April 2021, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>C-Bus Toolkit \u2013 version v1.15.7 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-105-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-105-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-105-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-19","alert_type":398,"serial_number":"AV21-169","subject":null,"moderation_state":"published","external_url":null},{"nid":2401,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"57752851-debd-4c59-b672-533393c13f24","banner":null,"lang":"en","date_modified":"2021-04-19","date_modified_ts":"2021-04-19T13:15:27Z","date_created":"2021-04-19T13:15:27Z","summary":null,"body":["<article data-history-node-id=\"2401\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-170<br \/>\nDate: 19 April 2021<\/strong><\/p>\n\n<p>On 15 April 2021 Microsoft published Security Updates to address multiple vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 90.0.818.39<\/li>\n<\/ul><p>Included with the current update are patches for multiple vulnerabilities which may result in code execution and have been recently reported as being actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/deployedge\/microsoft-edge-relnote-stable-channel#version-90081839-april-15\">https:\/\/docs.microsoft.com\/en-us\/deployedge\/microsoft-edge-relnote-stable-channel#version-90081839-april-15<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\">https:\/\/msrc.microsoft.com\/update-guide\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory","alert_type":396,"serial_number":"AV21-170","subject":null,"moderation_state":"published","external_url":null},{"nid":2402,"title":"IBM security advisory","uuid":"a6998599-4fb3-4956-919d-955c94330230","banner":null,"lang":"en","date_modified":"2021-04-19","date_modified_ts":"2021-04-19T15:13:38Z","date_created":"2021-04-19T15:13:38Z","summary":null,"body":["<article data-history-node-id=\"2402\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-44\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-171<br \/>\nDate: 19 April 2021<\/strong><\/p>\n\n<p>Between 14 and 18 April 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Rational Service Tester \u2013 versions 9.1, 9.2 and 9.5<\/li>\n\t<li>Rational Performance Tester - versions 9.1, 9.2 and 9.5<\/li>\n\t<li>IBM Transformation Extender \u2013 versions 9.0 and 10.0<\/li>\n\t<li>WebSphere Transformation Extender \u2013 version 8.4.1<\/li>\n\t<li>IBM Operations Analytics - Log Analysis - versions 1.3.1 to 1.3.6<\/li>\n\t<li>Watson OpenScale (on Cloud Pak for Data) \u2013 version 3.5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-44","alert_type":396,"serial_number":"AV21-171","subject":null,"moderation_state":"published","external_url":null},{"nid":2403,"title":"VMware security advisory","uuid":"305dedbe-e169-4bec-ac4c-7dc78a7416a9","banner":null,"lang":"en","date_modified":"2021-04-19","date_modified_ts":"2021-04-19T15:18:32Z","date_created":"2021-04-19T15:18:32Z","summary":null,"body":["<article data-history-node-id=\"2403\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-39\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-172<br \/>\nDate: 19 April 2021<\/strong><\/p>\n\n<p>On 19 April 2021 VMware published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware NSX-T \u2013 version 3.1.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0006)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0006.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0006.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-39","alert_type":396,"serial_number":"AV21-172","subject":null,"moderation_state":"published","external_url":null},{"nid":2404,"title":"Mozilla security advisory","uuid":"2ec697fe-8a67-4246-bf1a-e07a9b2c38d6","banner":null,"lang":"en","date_modified":"2021-04-20","date_modified_ts":"2021-04-20T11:28:30Z","date_created":"2021-04-20T11:28:30Z","summary":null,"body":["<article data-history-node-id=\"2404\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-173<br \/>\nDate: 20 April 2021<\/strong><\/p>\n\n<p>On 19 April 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 88<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.10<\/li>\n\t<li>Thunderbird \u2013 versions prior to 78.10<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-16)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-16\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-16\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-15)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-15\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-15\/<\/a><\/p>\n\n<p>Thunderbird (MFSA 2021-14)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-14\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-14\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-35","alert_type":396,"serial_number":"AV21-173","subject":null,"moderation_state":"published","external_url":null},{"nid":2405,"title":"HPE security advisory","uuid":"86771c65-7139-4965-8762-f6b65128067f","banner":null,"lang":"en","date_modified":"2021-04-20","date_modified_ts":"2021-04-20T20:35:26Z","date_created":"2021-04-20T19:02:00Z","summary":null,"body":["<article data-history-node-id=\"2405\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-174<br \/>\nDate: 20 April 2021<\/strong><\/p>\n\n<p>On 19 April 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Service Pack for ProLiant \u2013 versions prior to 2021.04.0<\/li>\n\t<li>Intelligent Provisioning \u2013 versions prior to 3.62<\/li>\n\t<li>HPE ProLiant BL460c Gen10 Server Blade \u2013 versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant DL series Gen10 Server \u2013 multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant DL series Gen10 Plus Server \u2013 multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant DX series Gen10 server - multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant DX series Gen10 Plus server - multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant MicroServer Gen10 - multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant ML series Gen10 Server \u2013 multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant XL series Gen10 Server \u2013 multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n\t<li>HPE ProLiant XL series Gen10 Plus Server \u2013 multiple products, and versions prior to SPP version 2021.04.0 and IP version 3.62<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in local execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (HPE Gen10 and Gen10 Plus Servers)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04116en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04116en_us<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-14","alert_type":396,"serial_number":"AV21-174","subject":null,"moderation_state":"published","external_url":null},{"nid":2435,"title":"Active Exploitation of Pulse Connect Secure Vulnerabilities - update 1","uuid":"e41a8a46-a260-49e1-9629-74540e359125","banner":null,"lang":"en","date_modified":"2021-05-03","date_modified_ts":"2021-05-03T21:27:27Z","date_created":"2021-04-21T13:46:02Z","summary":null,"body":["<article data-history-node-id=\"2435\" about=\"\/en\/alerts-advisories\/active-exploitation-pulse-connect-secure-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-008 UPDATE 1\n  <br \/>\n  Date: 21 April 2021\n  <br \/><strong>Updated: 3 May 2021<\/strong><\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.\n<\/p>\n<h2>PURPOSE\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>OVERVIEW\n<\/h2>\n<p>On 20 April 2021, Pulse Secure released a Security Advisory highlighting a critical remote code execution vulnerability in its Pulse Connect Secure product. Open-source reporting has indicated that active exploitation of this vulnerability as well as prior Pulse Secure vulnerabilities have been observed.\n<\/p>\n<h2>DETAILS\n<\/h2>\n<p>On 20 April 2021, Pulse Secure released a Security Advisory highlighting a critical remote code execution vulnerability in its Pulse Connect Secure (PCS) VPN appliance, affecting versions 9.0R3 and above. The vulnerability allows a remote unauthenticated actor to execute arbitrary code on an affected device. According to analysis conducted by Pulse Secure, this vulnerability, tracked as CVE-2021-22893, is actively being leveraged to gain a foothold within private networks. Currently, only a workaround is available to mitigate the impact of CVE-2021-22893. [<a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44784\/?kA23Z000000boUWSAY\">1<\/a>] A final patch to address this vulnerability is expected to be released in early May. In addition to the workaround, Pulse Secure recently released a \u201cPulse Connect Secure Integrity Tool\u201d that verifies the integrity of the PCS filesystem in order to detect additional and\/or modified files. [<a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Secure_Article\/KB44755\">2<\/a>]\n<\/p>\n<p>UPDATE: On 3 May 2021, Pulse Secure released a patch to address CVE-2021-22893 [<a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44784\/?kA23Z000000boUWSAY\">1<\/a>]. Furthermore, the Security Advisory was updated to highlight additional vulnerabilities found in PCS devices, namely, CVE-2021-22894, CVE-2021-22899 and CVE-2021-22900, the first two being critical vulnerabilities. These vulnerabilities are also addressed by the patch.\n<\/p>\n<p>Pulse Secure has been working closely with Mandiant to address recent breaches involving Pulse Secure VPN devices. Details regarding these breaches can be found in Mandiant\u2019s blog. [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/04\/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html\">3<\/a>] The blog highlights that, in addition to CVE-2021-22893, actors have been leveraging other vulnerabilities from 2019 and 2020 to exploit unpatched PCS devices. Mandiant has provided a technical analysis as well as indicators of compromise to aid in the detection of tools leveraged by these actors. [<a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/04\/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html\">3<\/a>][<a href=\"https:\/\/github.com\/fireeye\/pulsesecure_exploitation_countermeasures\">4<\/a>]\n<\/p>\n<h2>SUGGESTED ACTION\n<\/h2>\n<p>The Cyber Centre encourages those organizations leveraging PCS devices to:\n<\/p>\n<ul><li>UPDATE: Apply necessary patches,<\/li>\n  <li>Review the indicators of compromise, published by Mandiant to identify signs of compromise, [<a href=\"https:\/\/github.com\/fireeye\/pulsesecure_exploitation_countermeasures\">4<\/a>]<\/li>\n  <li>Check the integrity of your PCS file system with the PCS Integrity Tool.<\/li>\n<\/ul><p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>[1] SA44784 - 2021-04: Out-of-Cycle Advisory: Pulse Connect Secure RCE Vulnerability (CVE-2021-22893):\n  <br \/><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44784\/?kA23Z000000boUWSAY\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44784\/?kA23Z000000boUWSAY<\/a>\n<\/p>\n<p>[2] KB44755 - Pulse Connect Secure (PCS) Integrity Assurance:\n  <br \/><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Secure_Article\/KB44755\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Secure_Article\/KB44755<\/a>\n<\/p>\n<p>[3] Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day:\n  <br \/><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/04\/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2021\/04\/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html<\/a>\n<\/p>\n<p>[4] Github Pulse Secure Exploitation Countermeasures:\n  <br \/><a href=\"https:\/\/github.com\/fireeye\/pulsesecure_exploitation_countermeasures\">https:\/\/github.com\/fireeye\/pulsesecure_exploitation_countermeasures<\/a>\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n  <br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-pulse-connect-secure-vulnerabilities","alert_type":397,"serial_number":"AL21-008","subject":null,"moderation_state":"published","external_url":null},{"nid":2407,"title":"[Control systems] Delta Electronics security advisory","uuid":"7694de8d-b3bf-40d3-84d4-a3fe92e70335","banner":null,"lang":"en","date_modified":"2021-04-21","date_modified_ts":"2021-04-21T16:59:26Z","date_created":"2021-04-21T16:59:26Z","summary":null,"body":["<article data-history-node-id=\"2407\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-175<br \/>\nDate: 21 April 2021<\/strong><\/p>\n\n<p>On 20 April 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics CNCSoft-B - version 1.0.0.3 and prior<\/li>\n\t<li>Delta Electronics CNCSoft - version 1.01.28 (with ScreenEditor version 1.01.2) and prior<\/li>\n\t<li>Delta Industrial Automation COMMGR - version 1.12 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, arbitrary code execution or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-110-05)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-05<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-110-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-04<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-110-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-03<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-5","alert_type":398,"serial_number":"AV21-175","subject":null,"moderation_state":"published","external_url":null},{"nid":2408,"title":"[Control systems] Eaton security advisory","uuid":"c1b185f1-8f35-42a7-a07b-f584e1e3d802","banner":null,"lang":"en","date_modified":"2021-04-21","date_modified_ts":"2021-04-21T17:04:30Z","date_created":"2021-04-21T17:04:30Z","summary":null,"body":["<article data-history-node-id=\"2408\" about=\"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-176<br \/>\nDate: 21 April 2021<\/strong><\/p>\n\n<p>On 12 April 2021 Eaton published a Vulnerability Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Eaton Intelligent Power Manager (IPM) \u2013 versions prior to 1.69<\/li>\n\t<li>Eaton Intelligent Power Manager Virtual Appliance (IPM VA) \u2013 versions prior to 1.69<\/li>\n\t<li>Eaton Intelligent Power Protector (IPP) \u2013 versions prior to 1.68<\/li>\n<\/ul><p>Exploitation could allow an actor to change settings, upload code, delete files or execute commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Eaton Vulnerability Advisory (ETN-VA-2021-1000)<br \/><a href=\"https:\/\/www.eaton.com\/content\/dam\/eaton\/company\/news-insights\/cybersecurity\/security-bulletins\/eaton-intelligent-power-manager-ipm-vulnerability-advisory.pdf\">https:\/\/www.eaton.com\/content\/dam\/eaton\/company\/news-insights\/cybersecurity\/security-bulletins\/eaton-intelligent-power-manager-ipm-vulnerability-advisory.pdf<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-2","alert_type":398,"serial_number":"AV21-176","subject":null,"moderation_state":"published","external_url":null},{"nid":2409,"title":"[Control systems] Rockwell Automation security advisory","uuid":"81e1e2d1-28c2-49a7-aeca-1b8aee1bc529","banner":null,"lang":"en","date_modified":"2021-04-21","date_modified_ts":"2021-04-21T17:09:48Z","date_created":"2021-04-21T17:09:48Z","summary":null,"body":["<article data-history-node-id=\"2409\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-177<br \/>\nDate: 21 April 2021<\/strong><\/p>\n\n<p>On 20 April 2021, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Stratix 5800 - version 16.12.01 and prior\u00a0<\/li>\n\t<li>Stratix 8000 - version 15.2(7)E3 and prior<\/li>\n\t<li>Stratix 5700 - version 15.2(7)E3 and prior\u00a0<\/li>\n\t<li>Stratix 5410 - version 15.2(7)E3 and prior\u00a0<\/li>\n\t<li>Stratix 5400 - version 15.2(7)E3 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, privilege escalation, web socket hijacking, relative path traversal or command injection.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-110-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-110-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-16","alert_type":398,"serial_number":"AV21-177","subject":null,"moderation_state":"published","external_url":null},{"nid":2410,"title":"Google Chrome security advisory","uuid":"64b37f72-b1c4-43d9-8203-c1632ef7a2fc","banner":null,"lang":"en","date_modified":"2021-04-21","date_modified_ts":"2021-04-21T17:13:03Z","date_created":"2021-04-21T17:13:03Z","summary":null,"body":["<article data-history-node-id=\"2410\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-53\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-178<br \/>\nDate: 21 April 2021<\/strong><\/p>\n\n<p>On 20 April 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 90.0.4430.85<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution. Google has received reports that these vulnerabilities have available exploits.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop_20.html\">https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop_20.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-53","alert_type":396,"serial_number":"AV21-178","subject":null,"moderation_state":"published","external_url":null},{"nid":2411,"title":"[Control systems] Hitachi ABB Power Grids security advisory","uuid":"748d4080-41d1-470e-a94a-4a8cb7e397f5","banner":null,"lang":"en","date_modified":"2021-04-21","date_modified_ts":"2021-04-21T18:39:17Z","date_created":"2021-04-21T18:39:17Z","summary":null,"body":["<article data-history-node-id=\"2411\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-179<br \/>\nDate: 21 April 2021<\/strong><\/p>\n\n<p>On 18 March 2021 Hitachi ABB Power Grids published an advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Ellipse APM - version 5.3.0.1 and prior<\/li>\n\t<li>Ellipse APM \u2013 version 5.2.0.3 and prior<\/li>\n\t<li>Ellipse APM \u2013 version 5.1.0.6 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated actor or integrated application to inject malicious data into the application that could then be executed in a user\u2019s browser.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Hitachi ABB Power Grids advisory (CVE-2021-27887)<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107991A9700&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107991A9700&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-2","alert_type":398,"serial_number":"AV21-179","subject":null,"moderation_state":"published","external_url":null},{"nid":2412,"title":"Oracle security advisory \u2013 April 2021 Quarterly Rollup","uuid":"e3f91dfc-1ccf-4287-97a3-ca13d8aec0d5","banner":null,"lang":"en","date_modified":"2021-04-21","date_modified_ts":"2021-04-21T18:43:59Z","date_created":"2021-04-21T18:43:59Z","summary":null,"body":["<article data-history-node-id=\"2412\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-april-2021-quarterly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-180<br \/>\nDate: 21 April 2021<\/strong><\/p>\n\n<p>On 20 April 2021 Oracle published a Critical Patch Update Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Communications Design Studio: Inventory Services (Netty) - version 7.4.2<\/li>\n\t<li>Oracle Communications Messaging Server: Message Store (Apache PDFBox) - version 8.1.0<\/li>\n\t<li>Oracle Communications Messaging Server: Message Store (Netty) - version 8.1.0<\/li>\n\t<li>Oracle Communications Messaging Server: Message Store (Bouncy Castle Java Library) - version 8.0.2<\/li>\n\t<li>Oracle Communications Application Session Controller: Security (Bouncy Castle Java Library) - version 3.9m0p3<\/li>\n\t<li>Instantis EnterpriseTrack: Browser (Apache Cordova InAppBrowser) - versions 17.1, 17.2 and 17.3<\/li>\n\t<li>Oracle Applications Framework: Home page - version 12.2.10<\/li>\n\t<li>Oracle Marketing: Marketing Administration - versions 12.2.7 to 12.2.10<\/li>\n\t<li>Enterprise Manager Base Platform: Enterprise Manager Install (Nimbus JOSE+JWT) - version 13.4.0.0<\/li>\n\t<li>Oracle FLEXCUBE Private Banking: Financial Planning (Apache ActiveMQ) - versions 12.0.0 and 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Private Banking: Order Management (Spring Integration) - versions 12.0.0 and 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Private Banking: Order Management (Spring Web Services) - versions 12.0.0 and 12.1.0<\/li>\n\t<li>Oracle FLEXCUBE Private Banking: Demographics (Eclipse Jetty) - versions 12.0.0 and 12.1.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition: Analytics Server (Apache Spark) - version 5.5.0.0.0<\/li>\n\t<li>Oracle Fusion Middleware: Centralized Thirdparty Jars (dom4j) - versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle Platform Security for Java: OPSS - versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle WebCenter Portal: Security Framework (Netty) - versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle WebLogic Server: Core - versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n\t<li>Oracle WebLogic Server: Coherence Container - versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n\t<li>FMW Platform: Common Components (Eclipse Jetty) - versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle Health Sciences Information Manager: Health Record Locator (Apache Ant) - versions 3.0.0 to 3.0.2<\/li>\n\t<li>Oracle Hospitality OPERA 5: Logging (Apache log4net) - versions 5.5 and 5.6<\/li>\n\t<li>Oracle Hospitality OPERA 5: Login (Apache Struts) - version 5.6<\/li>\n\t<li>Hyperion Analytic Provider Services: JAPI - versions 11.1.2.4 and 12.2.1.4<\/li>\n\t<li>JD Edwards EnterpriseOne Tools: E1 Dev Platform Tech - Cloud (Bouncy Castle Java Library) - versions prior to 9.2.5.3<\/li>\n\t<li>MySQL Enterprise Monitor: Monitoring: General (Apache Struts) - version 8.0.23 and prior<\/li>\n\t<li>Oracle Retail Xstore Point of Service: Xenvironment (dom4j) - versions 15.0.4, 16.0.6, 17.0.4 and 18.0.3<\/li>\n\t<li>Oracle Retail Xstore Point of Service: Xstore Office (Apache PDFbox) - versions 16.0.6 and 18.0.3<\/li>\n\t<li>Oracle Cloud Infrastructure Storage Gateway: Management Console - versions prior to 1.4<\/li>\n\t<li>Oracle Storage Cloud Software Appliance: Management Console - versions prior to 16.3.1.4.2<\/li>\n\t<li>Oracle Cloud Infrastructure Storage Gateway: Management Console - versions prior to 1.4<\/li>\n\t<li>Oracle Rapid Planning: User interface (Application Development Framework) - version 12.1.3<\/li>\n\t<li>Oracle Advanced Supply Chain Planning: Core - versions 12.1 and 12.2<\/li>\n\t<li>Oracle ZFS Storage Appliance Kit: Operating System Image - version 8.8<\/li>\n\t<li>Oracle Utilities Framework: General (Swagger UI) - versions 4.3.0.6.0, 4.4.0.0.0 and 4.4.0.2.0<\/li>\n\t<li>Oracle Utilities Framework: Securty (Bouncy Castle Java Library) - versions 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0 and 4.4.0.3.0<\/li>\n\t<li>Oracle Secure Global Desktop: Gateway - version 5.6<\/li>\n\t<li>Oracle Secure Global Desktop: Server - version 5.6<\/li>\n\t<li>Oracle Secure Global Desktop: Client - version 5.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Oracle Critical Patch Update Advisory - April 2021<br \/><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2021.html\">https:\/\/www.oracle.com\/security-alerts\/cpuapr2021.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-april-2021-quarterly-rollup","alert_type":396,"serial_number":"AV21-180","subject":null,"moderation_state":"published","external_url":null},{"nid":2413,"title":"SonicWall security advisory","uuid":"4da41a5c-26d2-4193-a0eb-a2754519a168","banner":null,"lang":"en","date_modified":"2021-04-21","date_modified_ts":"2021-04-21T18:50:34Z","date_created":"2021-04-21T18:50:34Z","summary":null,"body":["<article data-history-node-id=\"2413\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-181<br \/>\nDate: 21 April 2021<\/strong><\/p>\n\n<p>On 20 April 2021 SonicWall published a Security Notice to address zero-day vulnerabilities in the following products:<\/p>\n\n<ul><li>Email Security (ES) Windows \u2013 versions 10.01., 10.0.2, 10.0.3 and 10.04-Present<\/li>\n\t<li>Email Security (ES) Hardware &amp; ESXi Virtual Appliance \u2013 versions 10.01., 10.0.2, 10.0.3 and 10.04-Present<\/li>\n\t<li>Hosted Email Security (HES) \u2013 versions 10.01., 10.0.2, 10.0.3 and 10.04-Present<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow an actor to read a random file, write a random file and create an administrative account on affected products.<\/p>\n\n<p>Open Source reporting has indicated that these vulnerabilities have been observed being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Security Notice: SonicWall Email Security Zero-Day Vulnerabilities<br \/><a href=\"https:\/\/www.sonicwall.com\/support\/product-notification\/security-notice-sonicwall-email-security-zero-day-vulnerabilities\/210416112932360\/\">https:\/\/www.sonicwall.com\/support\/product-notification\/security-notice-sonicwall-email-security-zero-day-vulnerabilities\/210416112932360\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-2","alert_type":396,"serial_number":"AV21-181","subject":null,"moderation_state":"published","external_url":null},{"nid":2414,"title":"[Control systems] Siemens and PKE security advisory","uuid":"450992c5-6ca9-4c2b-a2a5-b3241c1856f3","banner":null,"lang":"en","date_modified":"2021-04-22","date_modified_ts":"2021-04-22T13:21:49Z","date_created":"2021-04-22T13:21:49Z","summary":null,"body":["<article data-history-node-id=\"2414\" about=\"\/en\/alerts-advisories\/control-systems-siemens-and-pke-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-182<br \/>\nDate: 22 April 2021<\/strong><\/p>\n\n<p>On 20 April 2021 ICS-CERT published an updated Security Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>SiNVR\/SiVMS Video Server<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access to server data and to possible denial-of-service conditions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-20-070-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-070-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-070-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-and-pke-security-advisory","alert_type":398,"serial_number":"AV21-182","subject":null,"moderation_state":"published","external_url":null},{"nid":2415,"title":"Drupal security advisory","uuid":"a9881765-a362-445e-a423-7106b002181f","banner":null,"lang":"en","date_modified":"2021-04-22","date_modified_ts":"2021-04-22T16:58:18Z","date_created":"2021-04-22T16:58:18Z","summary":null,"body":["<article data-history-node-id=\"2415\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-183<br \/>\nDate: 22 April 2021<\/strong><\/p>\n\n<p>On 21 April 2021 Drupal published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Drupal 9.1 - versions prior to Drupal 9.1.7<\/li>\n\t<li>Drupal 9.0- versions prior to Drupal 9.0.12<\/li>\n\t<li>Drupal 8.9 - versions prior to Drupal 8.9.14<\/li>\n\t<li>Drupal 7 - versions prior to Drupal 7.80<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in cross-site scripting.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<\/p>\n\n<p>Drupal core (SA-CORE-2021-002)<br \/><a href=\"https:\/\/www.drupal.org\/sa-core-2021-002\">https:\/\/www.drupal.org\/sa-core-2021-002<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-13","alert_type":396,"serial_number":"AV21-183","subject":null,"moderation_state":"published","external_url":null},{"nid":2416,"title":"NVIDIA security advisory","uuid":"08d25d4a-8b13-4869-80b7-cd5d2ec2e801","banner":null,"lang":"en","date_modified":"2021-04-23","date_modified_ts":"2021-04-23T11:32:11Z","date_created":"2021-04-23T11:21:47Z","summary":null,"body":["<article data-history-node-id=\"2416\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-184<br \/>\nDate: 23 April 2021<\/strong><\/p>\n\n<p>On 19 April 2021 NVIDIA published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>NVIDIA GPU Display Driver (Windows and Linux) - multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to code execution, denial-of-service, privilege escalation and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>NVIDIA Security Bulletin (NVIDIA GPU Display Driver - April 2021)<br \/><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5172\">https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5172<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-11","alert_type":396,"serial_number":"AV21-184","subject":null,"moderation_state":"published","external_url":null},{"nid":2417,"title":"[Control systems] Horner Automation security advisory","uuid":"8edba484-87d8-4f21-9f6e-5d30cff88981","banner":null,"lang":"en","date_modified":"2021-04-23","date_modified_ts":"2021-04-23T15:50:54Z","date_created":"2021-04-23T15:50:54Z","summary":null,"body":["<article data-history-node-id=\"2417\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-185<br \/>\nDate: 23 April 2021<\/strong><\/p>\n\n<p>On 22 April 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Cscape - versions prior to 9.90 SP4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow code execution in the context of the current process or local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-112-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-112-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-112-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-1","alert_type":398,"serial_number":"AV21-185","subject":null,"moderation_state":"published","external_url":null},{"nid":2418,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"b0bf9ea2-5cf4-4063-a3f7-fba85a99f42e","banner":null,"lang":"en","date_modified":"2021-04-23","date_modified_ts":"2021-04-23T15:53:28Z","date_created":"2021-04-23T15:53:28Z","summary":null,"body":["<article data-history-node-id=\"2418\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-186<br \/>\nDate: 23 April 2021<\/strong><\/p>\n\n<p>On 22 April 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>GOT2000 series \u2013 multiple models, all versions<\/li>\n\t<li>GOT SIMPLE series - GS21 model, all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-112-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-112-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-112-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-14","alert_type":398,"serial_number":"AV21-186","subject":null,"moderation_state":"published","external_url":null},{"nid":2419,"title":"IBM security advisory","uuid":"19733df2-e2b0-47d3-a434-4148cc25b001","banner":null,"lang":"en","date_modified":"2021-04-26","date_modified_ts":"2021-04-26T17:47:13Z","date_created":"2021-04-26T17:47:13Z","summary":null,"body":["<article data-history-node-id=\"2419\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-45\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-187<br \/>\nDate: 26 April 2021<\/strong><\/p>\n\n<p>Between 19 and 25 April 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>InfoSphere Streams \u2013 versions 4.1.1.x, 4.2.1.x and 4.3.1.x<\/li>\n\t<li>IBM Cloud Application Business Insights \u2013 versions 1.1.5 and 1.1.6<\/li>\n\t<li>Log Analysis \u2013 versions 1.3.1 to 1.3.6<\/li>\n\t<li>IBM Watson Machine Learning Server on-prem \u2013 version 2.0.0<\/li>\n\t<li>DB2 \u2013 multiple versions<\/li>\n\t<li>IBM Spectrum Protect Plus Container backup and restore for Kubernetes \u2013 versions 10.1.5 to 10.1.7<\/li>\n\t<li>IBM Spectrum Protect Plus Container backup and restore for OpenShift \u2013 version 10.1.7<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for VMware \u2013 versions 8.1.0.0 to 8.1.11.0<\/li>\n\t<li>SPSS Statistics \u2013 multiple versions<\/li>\n\t<li>DB2 Recovery Expert for LUW \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-45","alert_type":396,"serial_number":"AV21-187","subject":null,"moderation_state":"published","external_url":null},{"nid":2420,"title":"HPE security advisory","uuid":"908050e7-cd94-45ce-94e5-e793d332ca7a","banner":null,"lang":"en","date_modified":"2021-04-26","date_modified_ts":"2021-04-26T19:36:37Z","date_created":"2021-04-26T19:36:37Z","summary":null,"body":["<article data-history-node-id=\"2420\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-188<br \/>\nDate: 26 April 2021<\/strong><\/p>\n\n<p>On 26 April 2021 HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Aruba ClearPass Policy Manager 6.9.x - multiple versions<\/li>\n\t<li>Aruba ClearPass Policy Manager 6.8.x - multiple versions<\/li>\n\t<li>Aruba ClearPass Policy Manager 6.7.x - multiple versions<\/li>\n\t<li>Aruba AirWave Management Platform \u2013 versions prior to 8.2.12.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPESBNW04127 rev.1 - Aruba ClearPass Policy Manager, Multiple Vulnerabilities<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04127en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04127en_us<\/a><\/p>\n\n<p>HPESBNW04126 rev.1 - Aruba AirWave Management Platform, Multiple Vulnerabilities<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04126en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04126en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-15","alert_type":396,"serial_number":"AV21-188","subject":null,"moderation_state":"published","external_url":null},{"nid":2421,"title":"Google Chrome security advisory","uuid":"c12b78b7-bb43-488d-a21c-a3bf79b2b19a","banner":null,"lang":"en","date_modified":"2021-04-27","date_modified_ts":"2021-04-27T13:45:46Z","date_created":"2021-04-27T13:45:46Z","summary":null,"body":["<article data-history-node-id=\"2421\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-54\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-189<br \/>\nDate: 27 April 2021<\/strong><\/p>\n\n<p>On 26 April 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 90.0.4430.93<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop_26.html\">https:\/\/chromereleases.googleblog.com\/2021\/04\/stable-channel-update-for-desktop_26.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-54","alert_type":396,"serial_number":"AV21-189","subject":null,"moderation_state":"published","external_url":null},{"nid":2422,"title":"Apple security advisory","uuid":"480dca9f-116a-4e1a-ae88-d6050c5c2b10","banner":null,"lang":"en","date_modified":"2021-04-27","date_modified_ts":"2021-04-27T15:47:39Z","date_created":"2021-04-27T15:47:39Z","summary":null,"body":["<article data-history-node-id=\"2422\" about=\"\/en\/alerts-advisories\/apple-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-190<br \/>\nDate: 27 April 2021<\/strong><br \/><br \/>\nOn 26 April 2021 Apple published a Security Update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iCloud for Windows \u2013 versions prior to 12.3<\/li>\n\t<li>Xcode \u2013 versions prior to 12.5<\/li>\n\t<li>Safari \u2013 versions prior to 14.1<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.3<\/li>\n\t<li>macOS Catalina \u2013 versions prior to Security Update 2021-002<\/li>\n\t<li>macOS Mojave \u2013 versions prior to Security Update 2021-003<\/li>\n\t<li>iOS \u2013 versions prior to 14.5<\/li>\n\t<li>iPadOS \u2013 versions prior to 14.5<\/li>\n\t<li>watchOS \u2013 versions prior to 7.4<\/li>\n\t<li>tvOS \u2013 versions prior to 14.5<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution.\u00a0 Apple has received reports that some of these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-28","alert_type":396,"serial_number":"AV21-190","subject":null,"moderation_state":"published","external_url":null},{"nid":2423,"title":"Fortinet security advisory","uuid":"968f1c59-9f38-47f3-a48e-ddd745aeefaa","banner":null,"lang":"en","date_modified":"2021-04-28","date_modified_ts":"2021-04-28T12:22:45Z","date_created":"2021-04-28T12:22:45Z","summary":null,"body":["<article data-history-node-id=\"2423\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-191<br \/>\nDate: 28 April 2021<\/strong><\/p>\n\n<p>On 27 April 2021 Fortinet published a Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>FortiWAN \u2013 version 4.5.7 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability may lead to unauthorized data modification which could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>PSIRT Advisory (FG-IR-21-048)<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-048\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-048<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-7","alert_type":396,"serial_number":"AV21-191","subject":null,"moderation_state":"published","external_url":null},{"nid":2424,"title":"Cisco security advisory","uuid":"6faa5786-2618-45ed-8cb9-e339b38a62e7","banner":null,"lang":"en","date_modified":"2021-04-29","date_modified_ts":"2021-04-29T12:45:45Z","date_created":"2021-04-29T12:45:45Z","summary":null,"body":["<article data-history-node-id=\"2424\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-79\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-192<br \/>\nDate: 29 April 2021<\/strong><\/p>\n\n<p>On 28 April 2021 Cisco published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<ul><li>Cisco ASA Software \u2013 versions prior to 9.8<\/li>\n\t<li>Cisco FTD Software \u2013 versions prior to 6.2.2<\/li>\n<\/ul><p>Exploitation could allow an unauthenticated remote actor to execute arbitrary code or gain privileged access on an affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-79","alert_type":396,"serial_number":"AV21-192","subject":null,"moderation_state":"published","external_url":null},{"nid":2425,"title":"ISC BIND security advisory","uuid":"17dfb6cc-b5c3-4c32-ae81-85d07f08653d","banner":null,"lang":"en","date_modified":"2021-04-29","date_modified_ts":"2021-04-29T18:35:12Z","date_created":"2021-04-29T18:35:12Z","summary":null,"body":["<article data-history-node-id=\"2425\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-193<br \/>\nDate: 29 April 2021<\/strong><\/p>\n\n<p>On 28 April 2021 ISC published Security Advisories to address multiple vulnerabilities in the following product.<\/p>\n\n<ul><li>ISC BIND 9 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation could allow an unauthenticated remote actor to trigger an error which could result in a denial of service and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>CVE-2021-25215<br \/><a href=\"https:\/\/kb.isc.org\/docs\/cve-2021-25215\">https:\/\/kb.isc.org\/docs\/cve-2021-25215<\/a><\/p>\n\n<p>CVE-2021-25216<br \/><a href=\"https:\/\/kb.isc.org\/docs\/cve-2021-25216\">https:\/\/kb.isc.org\/docs\/cve-2021-25216<\/a><\/p>\n\n<p>BIND 9 Security Vulnerability Matrix<br \/><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">https:\/\/kb.isc.org\/docs\/aa-00913<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory","alert_type":396,"serial_number":"AV21-193","subject":null,"moderation_state":"published","external_url":null},{"nid":2426,"title":"F5 security advisory","uuid":"5fc309d1-c50f-41ba-88f3-ac120c0ef0f6","banner":null,"lang":"en","date_modified":"2021-04-30","date_modified_ts":"2021-04-30T13:10:38Z","date_created":"2021-04-30T13:10:38Z","summary":null,"body":["<article data-history-node-id=\"2426\" about=\"\/en\/alerts-advisories\/f5-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-194<br \/>\nDate: 30 April 2021<\/strong><\/p>\n\n<p>On 28 April 2021 F5 published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>BIG-IP Branch 13 \u2013 versions 13.1.0.8 to 13.1.3<\/li>\n\t<li>BIG-IP Branch 14 \u2013 versions 14.1.0 to 14.1.4<\/li>\n\t<li>BIG-IP Branch 15 \u2013 versions 15.1.0 to 15.1.2<\/li>\n\t<li>BIG-IP Branch 16 \u2013 versions 16.0.0 to 16.0.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access and remote command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Appliance Mode authenticated iControl REST vulnerability CVE-2021-23015 (K74151369)<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K74151369\">https:\/\/support.f5.com\/csp\/article\/K74151369<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-0","alert_type":396,"serial_number":"AV21-194","subject":null,"moderation_state":"published","external_url":null},{"nid":2427,"title":"HPE security advisory","uuid":"b8d9cc05-734f-4651-b546-e897eaf8d451","banner":null,"lang":"en","date_modified":"2021-04-30","date_modified_ts":"2021-04-30T13:15:21Z","date_created":"2021-04-30T13:13:55Z","summary":null,"body":["<article data-history-node-id=\"2427\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-195<br \/>\nDate: 30 April 2021<\/strong><\/p>\n\n<p>On 29 April 2021 HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX BIND 9.11.1 \u2013 versions prior to C.9.11.1.5.0<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in unauthorized access, denial of service and buffer overflow.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HP-UX BIND, Multiple Vulnerabilities (HPESBUX04128 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04128en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04128en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-16","alert_type":396,"serial_number":"AV21-195","subject":null,"moderation_state":"published","external_url":null},{"nid":2428,"title":"[Control systems] Cassia Networks security advisory","uuid":"0b792eaa-2c33-4e9e-9585-2fa7104b5ddc","banner":null,"lang":"en","date_modified":"2021-04-30","date_modified_ts":"2021-04-30T13:17:05Z","date_created":"2021-04-30T13:17:05Z","summary":null,"body":["<article data-history-node-id=\"2428\" about=\"\/en\/alerts-advisories\/control-systems-cassia-networks-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-196<br \/>\nDate: 30 April 2021<\/strong><\/p>\n\n<p>On 29 April 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Access Controller - versions prior to 2.0.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow any file from the Access Controller server to be read.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-119-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cassia-networks-security-advisory","alert_type":398,"serial_number":"AV21-196","subject":null,"moderation_state":"published","external_url":null},{"nid":2429,"title":"[Control systems] Exacq Technologies security advisory","uuid":"d63e422a-06ad-4efb-a79e-4cea41fc7598","banner":null,"lang":"en","date_modified":"2021-04-30","date_modified_ts":"2021-04-30T13:21:28Z","date_created":"2021-04-30T13:21:28Z","summary":null,"body":["<article data-history-node-id=\"2429\" about=\"\/en\/alerts-advisories\/control-systems-exacq-technologies-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-197<br \/>\nDate: 30 April 2021<\/strong><\/p>\n\n<p>On 29 April 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products running on unpatched versions of the Ubuntu operating system:<\/p>\n\n<ul><li>Linux based Z-Series and A-Series<\/li>\n\t<li>Q-Series<\/li>\n\t<li>G-Series<\/li>\n\t<li>Legacy LC-Series<\/li>\n\t<li>Legacy ELP-Series<\/li>\n\t<li>exacqVision Network Video Recorders (NVR)<\/li>\n\t<li>Linux based C-Series Workstations<\/li>\n\t<li>S-Series Storage Servers<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a local actor to obtain privileged access to the underlying Ubuntu Linux operating system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-119-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-exacq-technologies-security-advisory","alert_type":398,"serial_number":"AV21-197","subject":null,"moderation_state":"published","external_url":null},{"nid":2642,"title":"[Control systems] Multiple RTOS Security Vulnerabilities \u2013 update 1","uuid":"d3b5ebc0-487a-43b7-823e-3cb2e1c8be2e","banner":null,"lang":"en","date_modified":"2021-08-17","date_modified_ts":"2021-08-17T18:29:18Z","date_created":"2021-04-30T13:27:01Z","summary":null,"body":["<article data-history-node-id=\"2642\" about=\"\/en\/alerts-advisories\/control-systems-multiple-rtos-security-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-198 \u2013 Update 1<br \/>\nDate: 30 April 2021<br \/>\nUpdated: 17 August 2021<\/strong><\/p>\n\n<p>On 29 April 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following RTOS (real-time operation system) products:<\/p>\n\n<ul><li>Amazon FreeRTOS - version 10.4.1<\/li>\n\t<li>Apache Nuttx OS - version 9.1.0\u00a0<\/li>\n\t<li>ARM CMSIS-RTOS2 - versions prior to 2.1.3<\/li>\n\t<li>ARM Mbed OS - version 6.3.0<\/li>\n\t<li>ARM mbed-uallaoc - version 1.3.0<\/li>\n\t<li>Cesanta Software Mongoose OS \u2013 version 2.17.0<\/li>\n\t<li>eCosCentric eCosPro RTOS - versions 2.0.1 through 4.5.3<\/li>\n\t<li>Google Cloud IoT Device SDK - version 1.0.2<\/li>\n\t<li>Linux Zephyr RTOS - versions prior to 2.4.0<\/li>\n\t<li>Media Tek LinkIt SDK - versions prior to 4.6.1<\/li>\n\t<li>Micrium OS - versions 5.10.1 and prior<\/li>\n\t<li>NXP MCUXpresso SDK - versions prior to 2.8.2<\/li>\n\t<li>NXP MQX - versions 5.1 and prior<\/li>\n\t<li>Redhat newlib - versions prior to 4.0.0<\/li>\n\t<li>RIOT OS - version 2020.01.1\u00a0<\/li>\n\t<li>Samsung Tizen RT RTOS - versions prior 3.0.GBB<\/li>\n\t<li>TencentOS-tiny - version 3.1.0<\/li>\n\t<li>Texas Instruments CC32XX - versions prior to 4.40.00.07<\/li>\n\t<li>Texas Instruments SimpleLink MSP432E4XX<\/li>\n\t<li>Texas Instruments SimpleLink-CC13XX - versions prior to 4.40.00<\/li>\n\t<li>Texas Instruments SimpleLink-CC26XX - versions prior to 4.40.00<\/li>\n\t<li>Texas Instruments SimpleLink-CC32XX - versions prior to 4.10.03<\/li>\n\t<li>Uclibc-NG - versions prior to 1.0.36\u00a0<\/li>\n\t<li>Windriver VxWorks \u2013 prior to 7.0<\/li>\n<\/ul><p>UPDATE 1<\/p>\n\n<p>As of 17 August 2021, ICS-CERT has updated ICS Advisory ICSA-21-119-04 to include the following affected RTOS (real-time operation system) products:<\/p>\n\n<ul><li>Micrium uC\/OS: uC\/LIB \u2013 versions 1.38.xx and 1.39.00<\/li>\n\t<li>BlackBerry QNX Software Development Platform \u2013 version 6.5.0SP1 and prior<\/li>\n\t<li>BlackBerry QNX OS for Medical \u2013 version 1.1 and prior<\/li>\n\t<li>BlackBerry QNX OS for Safety \u2013 version 1.0.1 and prior<\/li>\n<\/ul><p>END OF UPDATE 1<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-119-04)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-04<\/a><\/p>\n\n<p>UPDATE 1<\/p>\n\n<p>CCCS - [Control Systems] BlackBerry QNX Security Advisory (AV21-401)<\/p>\n\n<p><a href=\"https:\/\/can01.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fcyber.gc.ca%2Fen%2Falerts%2Fcontrol-systems-blackberry-qnx-security-advisory&amp;data=04%7C01%7CJesse.Wood%40cyber.gc.ca%7Cf68f95a495b74a16786508d9618e3852%7Cda9cbe40ec1e4997afb317d87574571a%7C0%7C0%7C637648085722175411%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=FqGuJFvJcK5IilwBJH2gLD%2Be0jQ%2FXGdEe%2BfxXrq2esY%3D&amp;reserved=0\">https:\/\/cyber.gc.ca\/en\/alerts\/control-systems-blackberry-qnx-security-advisory<\/a><\/p>\n\n<p>END OF UPDATE 1<br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-multiple-rtos-security-vulnerabilities","alert_type":398,"serial_number":"AV21-198","subject":null,"moderation_state":"published","external_url":null},{"nid":2430,"title":"[Control systems] Texas Instruments security advisory","uuid":"e9bc7f57-c37e-4f5b-85d2-3d6b30599257","banner":null,"lang":"en","date_modified":"2021-04-30","date_modified_ts":"2021-04-30T13:31:49Z","date_created":"2021-04-30T13:31:49Z","summary":null,"body":["<article data-history-node-id=\"2430\" about=\"\/en\/alerts-advisories\/control-systems-texas-instruments-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-199<br \/>\nDate: 30 April 2021<\/strong><\/p>\n\n<p>On 29 April 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>SimpleLink MSP432E4 SDK \u2013 version 4.20.00.12 and prior<\/li>\n\t<li>SimpleLink CC32XX SDK \u2013 version 4.30.00.06 and prior<\/li>\n\t<li>SimpleLink CC13X0 SDK - versions prior to 4.10.03<\/li>\n\t<li>SimpleLink CC13X2 SDK - versions prior to 4.40.00<\/li>\n\t<li>SimpleLink CC26XX SDK - versions prior to 4.40.00<\/li>\n\t<li>CC3200 SDK \u2013 version 1.5.0 and prior<\/li>\n\t<li>CC3100 SDK - version v1.3.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in memory corruption, allowing remote code execution and causing a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-119-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-119-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-texas-instruments-security-advisory","alert_type":398,"serial_number":"AV21-199","subject":null,"moderation_state":"published","external_url":null},{"nid":2431,"title":"HPE security advisory","uuid":"75f0bf40-468b-44e5-a808-187aa25361de","banner":null,"lang":"en","date_modified":"2021-04-30","date_modified_ts":"2021-04-30T19:33:53Z","date_created":"2021-04-30T19:33:53Z","summary":null,"body":["<article data-history-node-id=\"2431\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-200<br \/>\nDate: 30 April 2021<\/strong><\/p>\n\n<p>On 29 April 2021 HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Edgeline Infrastructure Management Software \u2013 versions prior to 1.22<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in an authentication bypass leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Edgeline Infrastructure Manager, Remote Authentication Bypass (HPESBGN04124 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04124en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04124en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-17","alert_type":396,"serial_number":"AV21-200","subject":null,"moderation_state":"published","external_url":null},{"nid":2432,"title":"[Control systems] B&R security advisory","uuid":"b98a3f41-780d-4d4c-b82f-307962d92222","banner":null,"lang":"en","date_modified":"2021-04-30","date_modified_ts":"2021-04-30T19:42:14Z","date_created":"2021-04-30T19:42:14Z","summary":null,"body":["<article data-history-node-id=\"2432\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-201<br \/>\nDate: 30 April 2021<\/strong><\/p>\n\n<p>On 30 April 2021 B&amp;R published a Cyber Security Advisory to address a vulnerability in the following versions of its:<\/p>\n\n<ul><li>B&amp;R HMI products :\n\t<ul><li>4B1400.00-K30 \u2013 version E0 and prior<\/li>\n\t\t<li>4B1400.00-K32 \u2013 version E0 and prior<\/li>\n\t\t<li>4B1400.00-K59 \u2013 version D0 and prior<\/li>\n\t\t<li>4B1400.00-K60 \u2013 version D0 and prior<\/li>\n\t\t<li>4B1400.00-K63 \u2013 version C0 and prior<\/li>\n\t\t<li>4B1400.00-K64 \u2013 version E0 and prior<\/li>\n\t\t<li>4B1400.00-K65 \u2013 version D0 and prior<\/li>\n\t\t<li>4B1400.00-K68 \u2013 version E0 and prior<\/li>\n\t\t<li>4B1400.00-K69 \u2013 version D0 and prior<\/li>\n\t\t<li>4B1400.00-K70 \u2013 version E0 and prior<\/li>\n\t\t<li>4B1400.00-K73 \u2013 version D0 and prior<\/li>\n\t\t<li>5AP933.156B-K12 \u2013 version A0 and prior<\/li>\n\t\t<li>5AP93D.156C-K01 \u2013 version G0 and prior<\/li>\n\t\t<li>5PC725.1505-K15 \u2013 version H0 and prior<\/li>\n\t\t<li>5PC725.1505-K16 \u2013 version D0 and prior<\/li>\n\t\t<li>5PC725.1505-K17 \u2013 version C0 and prior<\/li>\n\t\t<li>5PC725.1505-K25 \u2013 version G0 and prior<\/li>\n\t\t<li>5PC725.1505-K26 \u2013 version E0 and prior<\/li>\n\t\t<li>5PC725.1505-K27 \u2013 version C0 and prior<\/li>\n\t\t<li>5PC725.1505-K14 \u2013 version I0 and prior<\/li>\n\t\t<li>5PC725.1505-K24 \u2013 version I0 and prior<\/li>\n\t<\/ul><\/li>\n\t<li>B&amp;R I\/O system products:\n\t<ul><li>X20BC00E3 \u2013 version D9 and prior<\/li>\n\t\t<li>X20cBC00E3 \u2013 version D9 and prior<\/li>\n\t\t<li>X67BCE321.L12 \u2013 version C9 and prior<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability by an unauthenticated actor with network access may trigger a Denial-of-Service (DoS) on the affected B&amp;R products, thus compromising the availability of the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>Cyber Security Advisory #02\/2021<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1619200175188-en-original-1.1.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1619200175188-en-original-1.1.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-0","alert_type":398,"serial_number":"AV21-201","subject":null,"moderation_state":"published","external_url":null},{"nid":2433,"title":"IBM security advisory","uuid":"138fdf01-355a-499e-98ff-cbfb9e90a9b3","banner":null,"lang":"en","date_modified":"2021-05-03","date_modified_ts":"2021-05-03T18:46:23Z","date_created":"2021-05-03T18:46:23Z","summary":null,"body":["<article data-history-node-id=\"2433\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-46\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-202<br \/>\nDate: 3 May 2021<\/strong><\/p>\n\n<p>Between 26 April and 2 May 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>IBM Spectrum Protect Snapshot \u2013 multiple platforms, versions 8.1.0.0 to 8.1.11.0<\/li>\n\t<li>IBM Transformation Extender \u2013 versions 9.0, 10.0 and 10.1<\/li>\n\t<li>WebSphere Transformation Extender \u2013 version 8.4.1<\/li>\n\t<li>RDS \u2013 versions 5.2.1 iFix 13 and prior<\/li>\n\t<li>RDA \u2013 multiple versions<\/li>\n\t<li>Cloud Orchestrator \u2013 version 2.5.0.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Spectrum Protect Snapshot on AIX and Linux<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-ibm-java-runtime-affects-ibm-spectrum-protect-snapshot-on-aix-and-linux-cve-2020-27221\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-ibm-java-runtime-affects-ibm-spectrum-protect-snapshot-on-aix-and-linux-cve-2020-27221\/<\/a><\/p>\n\n<p>IBM Transformation Extender<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-buffer-overflow-vulnerability-in-ibm-sdk-affects-ibm-transformation-extender-3\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-buffer-overflow-vulnerability-in-ibm-sdk-affects-ibm-transformation-extender-3\/<\/a><\/p>\n\n<p>Rational Directory Server (Tivoli) &amp; Rational Directory Administrator<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-rational-directory-server-tivoli-rational-directory-administrator-7\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-rational-directory-server-tivoli-rational-directory-administrator-7\/<\/a><\/p>\n\n<p>Cloud Orchestrator<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-sdk-java-technology-edition-may-affect-ibm-cloud-orchestrator-and-ibm-cloud-orchestrator-enterprise-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-sdk-java-technology-edition-may-affect-ibm-cloud-orchestrator-and-ibm-cloud-orchestrator-enterprise-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-46","alert_type":396,"serial_number":"AV21-202","subject":null,"moderation_state":"published","external_url":null},{"nid":2434,"title":"Android security advisory \u2013 May 2021 monthly rollup","uuid":"8abec48c-bf77-4745-8c83-897c05503236","banner":null,"lang":"en","date_modified":"2021-05-03","date_modified_ts":"2021-05-03T19:15:23Z","date_created":"2021-05-03T19:15:23Z","summary":null,"body":["<article data-history-node-id=\"2434\" about=\"\/en\/alerts-advisories\/android-security-advisory-may-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-203<br \/>\nDate: 3 May 2021<\/strong><\/p>\n\n<p>On 3 May 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-05-01\">https:\/\/source.android.com\/security\/bulletin\/2021-05-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-may-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-203","subject":null,"moderation_state":"published","external_url":null},{"nid":2436,"title":"Apple security advisory","uuid":"5d30e49e-da8c-42fc-b586-d0c849ffbc1c","banner":null,"lang":"en","date_modified":"2021-05-04","date_modified_ts":"2021-05-04T12:04:54Z","date_created":"2021-05-04T11:54:54Z","summary":null,"body":["<article data-history-node-id=\"2436\" about=\"\/en\/alerts-advisories\/apple-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-204<br \/>\nDate:\u00a04 May 2021<\/strong><br \/><br \/>\nOn 3 May 2021 Apple published a Security Update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>watchOS \u2013 versions prior to 7.4.1<\/li>\n\t<li>iOS 12 \u2013 versions prior to 12.5.3<\/li>\n\t<li>iOS 14 \u2013 versions prior to 14.5.1<\/li>\n\t<li>iPadOS \u2013 versions prior to 14.5.1<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.3.1<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution.\u00a0 Apple has received reports that some of these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>watchOS<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT212339\">https:\/\/support.apple.com\/en-us\/HT212339<\/a><\/p>\n\n<p>iOS 12<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT212341\">https:\/\/support.apple.com\/en-us\/HT212341<\/a><\/p>\n\n<p>iOS and iPadOS 14<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT212336\">https:\/\/support.apple.com\/en-us\/HT212336<\/a><\/p>\n\n<p>macOS Big Sur<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT212335\">https:\/\/support.apple.com\/en-us\/HT212335<\/a><\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-29","alert_type":396,"serial_number":"AV21-204","subject":null,"moderation_state":"published","external_url":null},{"nid":2437,"title":"Codecov Releases Indicators for Supply Chain Compromise","uuid":"4ed67eb7-bffe-4db0-8ba2-5e11c43d5067","banner":null,"lang":"en","date_modified":"2021-05-04","date_modified_ts":"2021-05-04T19:14:41Z","date_created":"2021-05-04T19:14:41Z","summary":null,"body":["<article data-history-node-id=\"2437\" about=\"\/en\/alerts-advisories\/codecov-releases-indicators-supply-chain-compromise\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-009<br \/>\nDate: 4 May 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>On 15 April 2021, Codecov notified customers of a compromise to their Bash Uploader script that could have resulted in exfiltration of environment variables from a client\u2019s continuous integration (CI) environment. Subsequently, on 29 April 2021, Codecov updated the notification with Indicators of Compromise (IoC) to assist organizations in determining if they have been affected by the compromise.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>On 15 April 2021, Codecov notified [<a href=\"https:\/\/about.codecov.io\/security-update\/\">1<\/a>] its customers of a supply-chain compromise in which a malicious actor made unauthorized changes to its Bash Uploader script. These changes allowed the actor to potentially exfiltrate environment variables stored in the client's CI environment. Environment variables often contain sensitive information such as tokens, API keys and credentials. On 29 April 2021, Codecov updated the notification to include IoC discovered during its analysis that could be used to assist in determining if an organization has been affected by the compromise. The Cyber Centre recommends that organizations review the referenced IoCs to determine if they have been affected by this activity.<\/p>\n\n<p>The Cyber Centre is highlighting this Security Update as it provides important information to system owners, and operators responsible for defending their systems and networks from cyber threats.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] Codecov Bash Uploader Security Update<br \/><a href=\"https:\/\/about.codecov.io\/security-update\/\">https:\/\/about.codecov.io\/security-update\/<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/codecov-releases-indicators-supply-chain-compromise","alert_type":397,"serial_number":"AL21-009","subject":null,"moderation_state":"published","external_url":null},{"nid":2438,"title":"Dell security advisory","uuid":"6b080a6f-8020-4b09-821a-8a1a54c9adc3","banner":null,"lang":"en","date_modified":"2021-05-05","date_modified_ts":"2021-05-05T11:49:41Z","date_created":"2021-05-05T11:49:41Z","summary":null,"body":["<article data-history-node-id=\"2438\" about=\"\/en\/alerts-advisories\/dell-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-205<br \/>\nDate: 5 May 2021<\/strong><\/p>\n\n<p>On 4 May 2021 Dell published a Knowledge Base Article to address a vulnerability in the following product:<\/p>\n\n<ul><li>Client Firmware Update Utility Packages and Tools \u2013 multiple platforms and versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated local actor to escalate privileges, perform a denial of service, or disclose of information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Dell Client Platform Firmware Update Utility Packages and Tools (DSA-2021-088)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000186019\/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000186019\/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-3","alert_type":396,"serial_number":"AV21-205","subject":null,"moderation_state":"published","external_url":null},{"nid":2440,"title":"[Control systems] Delta Electronics security advisory","uuid":"e07a2512-917f-41e5-bee9-476e0a310dfa","banner":null,"lang":"en","date_modified":"2021-05-05","date_modified_ts":"2021-05-05T11:55:52Z","date_created":"2021-05-05T11:54:57Z","summary":null,"body":["<article data-history-node-id=\"2440\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-206<br \/>\nDate: 5 May 2021<\/strong><\/p>\n\n<p>On 4 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CNCSoft ScreenEditor \u2013 versions prior to v1.01.28<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in data corruption, denial-of-service, or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-124-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-124-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-124-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-6","alert_type":398,"serial_number":"AV21-206","subject":null,"moderation_state":"published","external_url":null},{"nid":2439,"title":"[Control systems] Advantech security advisory","uuid":"a8ff8953-48f8-47ae-8e18-379a33ebbf20","banner":null,"lang":"en","date_modified":"2021-05-05","date_modified_ts":"2021-05-05T11:59:59Z","date_created":"2021-05-05T11:59:59Z","summary":null,"body":["<article data-history-node-id=\"2439\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-207<br \/>\nDate: 5 May 2021<\/strong><\/p>\n\n<p>On 4 May 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>WISE-PaaS\/RMM \u2013 versions prior to 9.0.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthenticated actor to query Grafana APIs as administrator.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-124-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-124-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-124-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-15","alert_type":398,"serial_number":"AV21-207","subject":null,"moderation_state":"published","external_url":null},{"nid":2441,"title":"Apple security advisory","uuid":"6d409dc5-ce7c-4457-baf3-4cf5ab1a7b2c","banner":null,"lang":"en","date_modified":"2021-05-05","date_modified_ts":"2021-05-05T12:51:00Z","date_created":"2021-05-05T12:51:00Z","summary":null,"body":["<article data-history-node-id=\"2441\" about=\"\/en\/alerts-advisories\/apple-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-208<br \/>\nDate: 5 May 2021<\/strong><\/p>\n\n<p>On 4 May 2021 Apple published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari \u2013 versions prior to 14.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Safari<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT212340\">https:\/\/support.apple.com\/en-us\/HT212340<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-30","alert_type":396,"serial_number":"AV21-208","subject":null,"moderation_state":"published","external_url":null},{"nid":2442,"title":"Mozilla security advisory","uuid":"f1e09b16-c60d-489f-9ef5-b52732df6350","banner":null,"lang":"en","date_modified":"2021-05-05","date_modified_ts":"2021-05-05T14:37:39Z","date_created":"2021-05-05T14:37:39Z","summary":null,"body":["<article data-history-node-id=\"2442\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-209<br \/>\nDate: 5 May 2021<\/strong><\/p>\n\n<p>On 5 May 2021 Mozilla published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 88.0.1<\/li>\n\t<li>Firefox for Android \u2013 versions prior to 88.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Firefox and Firefox for Android (MFSA 2021-20)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-20\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-20\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-36","alert_type":396,"serial_number":"AV21-209","subject":null,"moderation_state":"published","external_url":null},{"nid":2443,"title":"Cisco security advisory","uuid":"deae63e1-1dab-48b1-9434-16e0c17311ac","banner":null,"lang":"en","date_modified":"2021-05-06","date_modified_ts":"2021-05-06T14:55:25Z","date_created":"2021-05-06T14:55:25Z","summary":null,"body":["<article data-history-node-id=\"2443\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-80\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-210<br \/>\nDate: 6 May 2021<\/strong><br \/><br \/>\nOn 5 May 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco SD-WAN vManage Software \u2013 multiple versions<\/li>\n\t<li>Cisco HyperFlex HX \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation could allow an unauthenticated remote actor to perform command injection, execute arbitrary code, or gain access to sensitive information. Alternatively, exploitation could allow an authenticated local actor to escalate privileges or gain unauthorized access to the application.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco SD-WAN vManage Software<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sd-wan-vmanage-4TbynnhZ\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sd-wan-vmanage-4TbynnhZ<\/a><\/p>\n\n<p>Cisco Hyperflex HX<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hyperflex-rce-TjjNrkpR\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hyperflex-rce-TjjNrkpR<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-80","alert_type":396,"serial_number":"AV21-210","subject":null,"moderation_state":"published","external_url":null},{"nid":2444,"title":"VMware security advisory","uuid":"a29fd262-c084-4918-a177-9d1dfde196b8","banner":null,"lang":"en","date_modified":"2021-05-06","date_modified_ts":"2021-05-06T19:44:08Z","date_created":"2021-05-06T19:44:08Z","summary":null,"body":["<article data-history-node-id=\"2444\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-40\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-211<br \/>\nDate: 6 May 2021<\/strong><\/p>\n\n<p>On 5 May 2021 VMware published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>VMware vRealize Business for Cloud - versions prior to 7.6<\/li>\n<\/ul><p>Exploitation could allow an actor with network access to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0007)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0007.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0007.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-40","alert_type":396,"serial_number":"AV21-211","subject":null,"moderation_state":"published","external_url":null},{"nid":2445,"title":"[Control systems] Open Design Alliance security advisory","uuid":"eabf5f35-8484-45b1-9cd1-e5d963421f2d","banner":null,"lang":"en","date_modified":"2021-05-06","date_modified_ts":"2021-05-06T19:50:45Z","date_created":"2021-05-06T19:47:25Z","summary":null,"body":["<article data-history-node-id=\"2445\" about=\"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-212<br \/>\nDate: 6 May 2021<\/strong><\/p>\n\n<p>On 6 May 2021, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Drawings SDK - versions prior to 2021.12<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to execute code in the context of the current process or cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-047-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-047-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-047-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory","alert_type":398,"serial_number":"AV21-212","subject":null,"moderation_state":"published","external_url":null},{"nid":2447,"title":"[Control systems] ABB security advisory","uuid":"170476ea-a1ff-43fc-89f7-e2a706afa2f1","banner":null,"lang":"en","date_modified":"2021-05-07","date_modified_ts":"2021-05-07T19:03:16Z","date_created":"2021-05-07T19:03:16Z","summary":null,"body":["<article data-history-node-id=\"2447\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-213<br \/>\nDate: 7 May 2021<\/strong><\/p>\n\n<p>On 6 May 2021 ABB published Cyber Security Advisories to address vulnerabilities in multiple products. Included were recommended mitigation actions for a critical vulnerability in the following:<\/p>\n\n<ul><li>AC 800PEC controller \u2013 3rd generation<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution or a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided webs link and perform the suggested mitigations.<\/p>\n\n<p>AC 800PEC platform NAME:WRECK vulnerability (ABBVU-ABBVREP0045-3BHS893949)<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107992A1892&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107992A1892&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a><\/p>\n\n<p>ABB Cyber Security Alerts and Notifications<br \/><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-14","alert_type":398,"serial_number":"AV21-213","subject":null,"moderation_state":"published","external_url":null},{"nid":2448,"title":"Exim security advisory","uuid":"2768abfa-5853-4f07-b481-4dab3d20e850","banner":null,"lang":"en","date_modified":"2021-05-10","date_modified_ts":"2021-05-10T11:52:35Z","date_created":"2021-05-10T11:52:35Z","summary":null,"body":["<article data-history-node-id=\"2448\" about=\"\/en\/alerts-advisories\/exim-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-214<br \/>\nDate:\u00a010 May 2021<\/strong><\/p>\n\n<p>On 4 May 2021, Exim published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Exim mail server \u2013 versions prior to 4.94.2<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could allow a remote unauthenticated actor to execute arbitrary code and gain root privilege.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Qualys Security Advisory<br \/><a href=\"https:\/\/www.exim.org\/static\/doc\/security\/CVE-2020-qualys\/21nails.txt\">https:\/\/www.exim.org\/static\/doc\/security\/CVE-2020-qualys\/21nails.txt<\/a><\/p>\n\n<p>Exim<br \/><a href=\"https:\/\/www.exim.org\/\">https:\/\/www.exim.org\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-3","alert_type":396,"serial_number":"AV21-214","subject":null,"moderation_state":"published","external_url":null},{"nid":2449,"title":"IBM security advisory","uuid":"d57a01c8-91c5-4265-b165-7367b4d38809","banner":null,"lang":"en","date_modified":"2021-05-10","date_modified_ts":"2021-05-10T14:22:15Z","date_created":"2021-05-10T14:22:15Z","summary":null,"body":["<article data-history-node-id=\"2449\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-47\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-215<br \/>\nDate: 10 May 2021<\/strong><\/p>\n\n<p>Between 3 and 9 May 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Watson OpenScale - version 3.0.1<\/li>\n\t<li>Rational Asset Analyzer (RAA) - versions 6.1.0.0 to 6.0.0.23<\/li>\n\t<li>Cloud Orchestrator - version 2.5.0.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Watson OpenScale<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-openscale-on-cloud-pak-for-data-is-impacted-by-cve-2021-3177\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-openscale-on-cloud-pak-for-data-is-impacted-by-cve-2021-3177\/<\/a><\/p>\n\n<p>Rational Asset Analyzer (RAA)<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-affecting-ibm-rational-asset-analyzer-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-affecting-ibm-rational-asset-analyzer-2\/<\/a><\/p>\n\n<p>Cloud Orchestrator<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-sdk-java-technology-edition-may-affect-ibm-cloud-orchestrator-and-ibm-cloud-orchestrator-enterprise-3\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-sdk-java-technology-edition-may-affect-ibm-cloud-orchestrator-and-ibm-cloud-orchestrator-enterprise-3\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-47","alert_type":396,"serial_number":"AV21-215","subject":null,"moderation_state":"published","external_url":null},{"nid":2450,"title":"Google Chrome security advisory","uuid":"4d136e71-84a9-469f-95d1-63a423a07094","banner":null,"lang":"en","date_modified":"2021-05-11","date_modified_ts":"2021-05-11T11:27:45Z","date_created":"2021-05-11T11:27:45Z","summary":null,"body":["<article data-history-node-id=\"2450\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-55\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-216<br \/>\nDate: 11 May 2021<\/strong><\/p>\n\n<p>On 10 May 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 90.0.4430.212<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/05\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/05\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-55","alert_type":396,"serial_number":"AV21-216","subject":null,"moderation_state":"published","external_url":null},{"nid":2451,"title":"[Control systems] Siemens security advisory","uuid":"6e09d02b-7de4-4635-b89b-0dc21dd0b01c","banner":null,"lang":"en","date_modified":"2021-05-11","date_modified_ts":"2021-05-11T17:39:13Z","date_created":"2021-05-11T17:39:13Z","summary":null,"body":["<article data-history-node-id=\"2451\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-217<br \/>\nDate: 11 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SINAMICS \u2013 multiple models and versions<\/li>\n\t<li>SIMATIC HMI Comfort Outdoor Panels (including SIPLUS variants) \u2013 all versions prior to V16 Update 4<\/li>\n\t<li>SIMATIC HMI Comfort Panels (including SIPLUS variants) \u2013 all versions prior to V16 Update 4<\/li>\n\t<li>SIMATIC HMI KTP Mobile Panels \u2013 multiple models and versions<\/li>\n\t<li>SIMATIC WinCC Runtime Advanced \u2013 all versions prior to V16 Update 4<\/li>\n\t<li>SCALANCE W1750D \u2013 version 8.7.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-24","alert_type":398,"serial_number":"AV21-217","subject":null,"moderation_state":"published","external_url":null},{"nid":2452,"title":"SAP security advisory \u2013 May 2021 monthly rollup","uuid":"6c293068-1989-4b77-af77-a8994dee8dbf","banner":null,"lang":"en","date_modified":"2021-05-11","date_modified_ts":"2021-05-11T17:43:48Z","date_created":"2021-05-11T17:43:48Z","summary":null,"body":["<article data-history-node-id=\"2452\" about=\"\/en\/alerts-advisories\/sap-security-advisory-may-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-218<br \/>\nDate: 11 May 2021<\/strong><br \/>\n\u00a0<br \/>\nOn 11 May 2021 SAP published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 May 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=576094655\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=576094655<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-may-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-218","subject":null,"moderation_state":"published","external_url":null},{"nid":2453,"title":"Microsoft security advisory \u2013 May 2021 monthly rollup","uuid":"44ba620b-fd82-4717-a43e-485c23041abc","banner":null,"lang":"en","date_modified":"2021-05-11","date_modified_ts":"2021-05-11T19:30:46Z","date_created":"2021-05-11T19:30:46Z","summary":null,"body":["<article data-history-node-id=\"2453\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-219<br \/>\nDate: 11 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 10, 8.1, RT 8.1 and 7<\/li>\n\t<li>Windows Server and Server Core<\/li>\n\t<li>Internet Explorer<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>May 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-May\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-May<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-may-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-219","subject":null,"moderation_state":"published","external_url":null},{"nid":2454,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"fc59c08f-c568-4908-b5eb-54618e4dc3f1","banner":null,"lang":"en","date_modified":"2021-05-12","date_modified_ts":"2021-05-12T13:43:11Z","date_created":"2021-05-12T13:43:11Z","summary":null,"body":["<article data-history-node-id=\"2454\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-220<br \/>\nDate: 12 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>GOT2000 series:\n\t<ul><li>GT27 model - versions 01.19.000 to 01.38.000\u00a0<\/li>\n\t\t<li>GT25 model - versions 01.19.000 to 01.38.000\u00a0\u00a0<\/li>\n\t\t<li>GT23 model - versions 01.19.000 to 01.38.000\u00a0\u00a0<\/li>\n\t\t<li>GT21 model - versions 01.21.000 to 01.39.000<\/li>\n\t<\/ul><\/li>\n\t<li>GOT SIMPLE series:\n\t<ul><li>GS21 model - versions 01.21.000 to 01.39.000<\/li>\n\t<\/ul><\/li>\n\t<li>GT SoftGOT2000 - versions 1.170C to 1.250L<\/li>\n\t<li>LE7-40GU-L: Screen package data for MODBUS\/TCP v1.00<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-131-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-131-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-131-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-15","alert_type":398,"serial_number":"AV21-220","subject":null,"moderation_state":"published","external_url":null},{"nid":2455,"title":"[Control systems] Omron security advisory","uuid":"c27221fe-68a6-41a7-b240-ee916fdad115","banner":null,"lang":"en","date_modified":"2021-05-12","date_modified_ts":"2021-05-12T13:46:36Z","date_created":"2021-05-12T13:46:36Z","summary":null,"body":["<article data-history-node-id=\"2455\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-221<br \/>\nDate: 12 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>CX-One - version 4.60 and prior, including the following applications:\n\t<ul><li>CX-Server - version 5.0.29.0 and prior<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability may allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-131-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-131-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-131-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-3","alert_type":398,"serial_number":"AV21-221","subject":null,"moderation_state":"published","external_url":null},{"nid":2456,"title":"Adobe security advisory","uuid":"c85cf2f2-ca3b-4c0d-95fd-03e19de3d907","banner":null,"lang":"en","date_modified":"2021-05-12","date_modified_ts":"2021-05-12T13:51:44Z","date_created":"2021-05-12T13:51:44Z","summary":null,"body":["<article data-history-node-id=\"2456\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-40\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-222<br \/>\nDate: 12 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Experience Manager \u2013 multiple versions<\/li>\n\t<li>InDesign \u2013 version 16.0 and prior<\/li>\n\t<li>Illustrator 2021 \u2013 version 25.2 and prior<\/li>\n\t<li>InCopy \u2013 version 16.0 and prior<\/li>\n\t<li>Acrobat Reader DC \u2013 multiple versions<\/li>\n\t<li>Acrobat DC \u2013 multiple versions<\/li>\n\t<li>Acrobat Reader 2020 \u2013 version 2020.001.30020 and prior<\/li>\n\t<li>Acrobat 2020 \u2013 version 2020.001.30020 and prior<\/li>\n\t<li>Acrobat Reader 2017 - version 2017.011.30194 and prior<\/li>\n\t<li>Acrobat 2017 - version 2017.011.30194 and prior<\/li>\n\t<li>Creative Cloud Desktop Application \u2013 version 5.3 and prior<\/li>\n\t<li>After Effects \u2013 version 18.1 and prior<\/li>\n\t<li>Medium \u2013 version 2.4.5.331 and prior<\/li>\n\t<li>Animate \u2013 version 21.0.5 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>Adobe has received a report that CVE-2021-28550, which affects Adobe Reader users on Windows, has been exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-40","alert_type":396,"serial_number":"AV21-222","subject":null,"moderation_state":"published","external_url":null},{"nid":2457,"title":"Pulse Secure security advisory","uuid":"6aeed5ab-ddfd-4abc-b99e-10d4040441ca","banner":null,"lang":"en","date_modified":"2021-05-12","date_modified_ts":"2021-05-12T18:25:44Z","date_created":"2021-05-12T18:25:44Z","summary":null,"body":["<article data-history-node-id=\"2457\" about=\"\/en\/alerts-advisories\/pulse-secure-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-223<br \/>\nDate: 12 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 Pulse Secure published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Virtual Traffic Manager:\n\t<ul><li>versions prior to 21.1<\/li>\n\t\t<li>versions prior to 20.3R1<\/li>\n\t\t<li>versions prior to 20.2R1<\/li>\n\t\t<li>versions prior to 20.1R2<\/li>\n\t\t<li>versions prior to 19.2R4<\/li>\n\t\t<li>versions prior to 18.2R3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to perform unauthorized HTTP requests.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Pulse Secure Security Advisory<br \/><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44790\/?kA23Z000000boUbSAI\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44790\/?kA23Z000000boUbSAI<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/pulse-secure-security-advisory-0","alert_type":396,"serial_number":"AV21-223","subject":null,"moderation_state":"published","external_url":null},{"nid":2458,"title":"Ubuntu security advisory","uuid":"07a256b2-4418-4186-8813-ec642b96f13c","banner":null,"lang":"en","date_modified":"2021-05-12","date_modified_ts":"2021-05-12T18:31:37Z","date_created":"2021-05-12T18:31:37Z","summary":null,"body":["<article data-history-node-id=\"2458\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-224<br \/>\nDate: 12 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, access to sensitive information, privilege escalation or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-12","alert_type":396,"serial_number":"AV21-224","subject":null,"moderation_state":"published","external_url":null},{"nid":2459,"title":"[Control systems] Schneider Electric security advisory","uuid":"60b9c68d-ae25-48de-90f8-45b10e0b1523","banner":null,"lang":"en","date_modified":"2021-05-12","date_modified_ts":"2021-05-12T18:36:19Z","date_created":"2021-05-12T18:36:19Z","summary":null,"body":["<article data-history-node-id=\"2459\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-225<br \/>\nDate: 12 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 Schneider Electric published Security Notifications to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Modicon Managed Switch:\n\t<ul><li>MCSESM* - version 8.21 and prior<\/li>\n\t\t<li>MCSESP* - version 8.21 and prior<\/li>\n\t<\/ul><\/li>\n\t<li>EcoStruxure Machine Expert - versions prior to 2.0<\/li>\n\t<li>Modicon:\n\t<ul><li>M218 - versions prior to 5.1.0.6<\/li>\n\t\t<li>M241 - versions prior to 5.1.9.14<\/li>\n\t\t<li>M251 - versions prior to 5.1.9.14<\/li>\n\t\t<li>M262 - versions prior to 5.1.5.30<\/li>\n\t<\/ul><\/li>\n\t<li>LMC PacDrive Eco\/Pro\/Pro2 - versions prior to 1.64.18.26<\/li>\n\t<li>Vijeo Designer and HMISCU - versions prior to 6.2 SP11<\/li>\n\t<li>ATV IMC \u2013 all versions<\/li>\n\t<li>SoMachine\/SoMachine Motion \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-20","alert_type":398,"serial_number":"AV21-225","subject":null,"moderation_state":"published","external_url":null},{"nid":2460,"title":"[Control systems] Rockwell Automation security advisory","uuid":"c1ae4518-f4d9-44a2-a779-2e0b696ee76c","banner":null,"lang":"en","date_modified":"2021-05-13","date_modified_ts":"2021-05-13T19:46:34Z","date_created":"2021-05-13T19:46:34Z","summary":null,"body":["<article data-history-node-id=\"2460\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-226<br \/>\nDate:\u00a0 13 May 2021<\/strong><\/p>\n\n<p>On 13 May 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Connected Components Workbench \u2013 version 12.00.00 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, authentication bypass and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-133-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-17","alert_type":398,"serial_number":"AV21-226","subject":null,"moderation_state":"published","external_url":null},{"nid":2461,"title":"Citrix security advisory","uuid":"f291b15d-f2b6-4af3-9bee-879922082d38","banner":null,"lang":"en","date_modified":"2021-05-13","date_modified_ts":"2021-05-13T19:58:52Z","date_created":"2021-05-13T19:58:52Z","summary":null,"body":["<article data-history-node-id=\"2461\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-227<br \/>\nDate:\u00a0 13 May 2021<\/strong><\/p>\n\n<p>On 11 May 2021 Citrix published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Citrix Workspace App for Windows - versions prior to 2105 and 1912 LTSR CU4<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX307794)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX307794\">https:\/\/support.citrix.com\/article\/CTX307794<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-14","alert_type":396,"serial_number":"AV21-227","subject":null,"moderation_state":"published","external_url":null},{"nid":2462,"title":"[Control systems] OPC Foundation security advisory","uuid":"5c48159d-bbb8-45d1-8805-88a6ec9a1d4a","banner":null,"lang":"en","date_modified":"2021-05-14","date_modified_ts":"2021-05-14T14:53:17Z","date_created":"2021-05-14T14:53:17Z","summary":null,"body":["<article data-history-node-id=\"2462\" about=\"\/en\/alerts-advisories\/control-systems-opc-foundation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-228<br \/>\nDate:\u00a0 14 May 2021<\/strong><\/p>\n\n<p>On 13 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>OPC UA .NET Standard - versions prior to 1.4.365.48<\/li>\n\t<li>OPC UA .NET Legacy<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a stack overflow.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-133-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-opc-foundation-security-advisory","alert_type":398,"serial_number":"AV21-228","subject":null,"moderation_state":"published","external_url":null},{"nid":2463,"title":"[Control systems] Johnson Controls security advisory","uuid":"9f0ccb0b-8728-4d8b-a19f-22381d369484","banner":null,"lang":"en","date_modified":"2021-05-14","date_modified_ts":"2021-05-14T14:56:17Z","date_created":"2021-05-14T14:56:17Z","summary":null,"body":["<article data-history-node-id=\"2463\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-229<br \/>\nDate:\u00a0 14 May 2021<\/strong><\/p>\n\n<p>On 13 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Tyco AI \u2013 version 1.2 and prior<\/li>\n<\/ul><p>A local actor could exploit this vulnerability to obtain super-user access to the underlying operating system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-133-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-5","alert_type":398,"serial_number":"AV21-229","subject":null,"moderation_state":"published","external_url":null},{"nid":2464,"title":"[Control systems] Unified Automation GmbH security advisory","uuid":"85c99529-9fd2-473b-9c08-61d41b152de6","banner":null,"lang":"en","date_modified":"2021-05-14","date_modified_ts":"2021-05-14T15:01:57Z","date_created":"2021-05-14T15:01:57Z","summary":null,"body":["<article data-history-node-id=\"2464\" about=\"\/en\/alerts-advisories\/control-systems-unified-automation-gmbh-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-230<br \/>\nDate:\u00a0 14 May 2021<\/strong><\/p>\n\n<p>On 13 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Unified Automation .NET based OPC UA Client\/Server SDK Bundle - versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only)<\/li>\n<\/ul><p>Successful exploitation of this vulnerability could allow an unauthenticated actor to read arbitrary files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-133-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-133-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-unified-automation-gmbh-security-advisory","alert_type":398,"serial_number":"AV21-230","subject":null,"moderation_state":"published","external_url":null},{"nid":2465,"title":"IBM security advisory","uuid":"9955624d-2cd6-424d-a717-6a3af0252165","banner":null,"lang":"en","date_modified":"2021-05-17","date_modified_ts":"2021-05-17T18:53:25Z","date_created":"2021-05-17T18:53:25Z","summary":null,"body":["<article data-history-node-id=\"2465\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-48\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-231<br \/>\nDate: 17 May 2021<\/strong><\/p>\n\n<p>Between 10 and 16 May 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Netcool Operations Insight \u2013 version 1.6<\/li>\n\t<li>IBM Netcool Agile Service Manager \u2013 version 1.1<\/li>\n\t<li>IBM InfoSphere Information Server \u2013 version 11.7<\/li>\n\t<li>APM on-premise \u2013 version 8.1.4<\/li>\n\t<li>CP4MCM DataCollectors \u2013 version 2.2<\/li>\n\t<li>Cloud Pak for Security (CP4S) \u2013 version 1.6.0.1 and prior<\/li>\n\t<li>Spectrum Discover \u2013 version 2.0.3<\/li>\n\t<li>IBM Watson Discovery for IBM Cloud Pak for Data \u2013 versions 2.0.0 to 2.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-48","alert_type":396,"serial_number":"AV21-231","subject":null,"moderation_state":"published","external_url":null},{"nid":2466,"title":"[Control systems] Siemens security advisory","uuid":"6dbe735b-f836-446a-9512-2843919fc542","banner":null,"lang":"en","date_modified":"2021-05-17","date_modified_ts":"2021-05-17T18:55:27Z","date_created":"2021-05-17T18:55:27Z","summary":null,"body":["<article data-history-node-id=\"2466\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-232<br \/>\nDate: 17 May 2021<\/strong><\/p>\n\n<p>On 17 May 2021 Siemens published a Security Advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>JT2Go \u2013 versions prior to V13.1.0.2<\/li>\n\t<li>Teamcenter Visualization \u2013 versions prior to V13.1.0.2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities may lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisory (SSA-695540)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-695540.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-695540.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-25","alert_type":398,"serial_number":"AV21-232","subject":null,"moderation_state":"published","external_url":null},{"nid":2467,"title":"[Control systems] Emerson security advisory","uuid":"0cbbc2b3-ad97-412f-b841-cc08204cac72","banner":null,"lang":"en","date_modified":"2021-05-18","date_modified_ts":"2021-05-18T19:41:18Z","date_created":"2021-05-18T19:41:18Z","summary":null,"body":["<article data-history-node-id=\"2467\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-233<br \/>\nDate:\u00a0 18 May 2021<\/strong><\/p>\n\n<p>On 18 May 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Rosemount X-STREAM enhanced XEGP \u2013 all versions<\/li>\n\t<li>Rosemount X-STREAM enhanced XEGK \u2013 all versions<\/li>\n\t<li>Rosemount X-STREAM enhanced XEFD \u2013 all versions<\/li>\n\t<li>Rosemount X-STREAM enhanced XEXF \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to obtain sensitive information, modify configuration, or affect the availability of the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-138-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-138-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-138-01<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-4","alert_type":398,"serial_number":"AV21-233","subject":null,"moderation_state":"published","external_url":null},{"nid":2468,"title":"HPE security advisory","uuid":"afce67b5-9ea0-4ba8-992f-4d1a132e6ef7","banner":null,"lang":"en","date_modified":"2021-05-19","date_modified_ts":"2021-05-19T17:08:46Z","date_created":"2021-05-19T17:08:46Z","summary":null,"body":["<article data-history-node-id=\"2468\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-234<br \/>\nDate: 19 May 2021<\/strong><\/p>\n\n<p>On 18 May 2021 HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Integrated Lights-Out 5 for HPE Gen 10 Servers \u2013 versions prior to 2.44<\/li>\n\t<li>HPE Integrated Lights-Out-4 \u2013 versions prior to 2.78<\/li>\n\t<li>HPE 3PAR \u2013 multiple platforms and versions<\/li>\n\t<li>HPE Apollo \u2013 multiple platforms, versions prior to 2.44<\/li>\n\t<li>HPE ProLiant \u2013 multiple platforms and versions<\/li>\n\t<li>HPE Storage File Controller \u2013 versions prior to 2.44<\/li>\n\t<li>HPE StoreEasy \u2013 multiple platforms and versions<\/li>\n\t<li>HPE Synergy \u2013 multiple platforms, versions prior to HPE Synergy Service Pack 2021.05.01<\/li>\n\t<li>HPE SimpliVity \u2013 multiple platforms and versions<\/li>\n\t<li>Intelligent provisioning \u2013 multiple versions<\/li>\n\t<li>Scripting Toolkit for Linux \u2013 versions prior to 11.51<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in code execution as a privileged user or allow an actor to bypass secure boot on systems where it is enabled.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin (HPESBHF04133 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04133en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04133en_us<\/a><\/p>\n\n<p>HPE Security Bulletin (HPESBHF04121 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04121en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04121en_us<\/a><\/p>\n\n<p>HPE Security Bulletin (HPESBHF04130 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04130en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04130en_us<\/a><\/p>\n\n<p>HPE Security Bulletin (HPESBHF04134 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04134en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04134en_us<\/a><\/p>\n\n<p>HPE Security Bulletin (HPESBHF04147 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04147en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04147en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-18","alert_type":396,"serial_number":"AV21-234","subject":null,"moderation_state":"published","external_url":null},{"nid":2469,"title":"Cisco security advisory","uuid":"a85acdee-03ac-4da9-a961-53cfdf9610fc","banner":null,"lang":"en","date_modified":"2021-05-20","date_modified_ts":"2021-05-20T14:12:02Z","date_created":"2021-05-20T14:12:02Z","summary":null,"body":["<article data-history-node-id=\"2469\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-81\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-235<br \/>\nDate: 20 May 2021<\/strong><\/p>\n\n<p>On 19 May 2021 Cisco published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>Exploitation of these vulnerabilities could result in a denial-of-service, execution of arbitrary commands, arbitrary code execution, privilege escalation, and the ability to write arbitrary files to the file system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-81","alert_type":396,"serial_number":"AV21-235","subject":null,"moderation_state":"published","external_url":null},{"nid":2470,"title":"IBM security advisory","uuid":"ee6fbf68-5014-4dfa-b22e-25c7000ff532","banner":null,"lang":"en","date_modified":"2021-05-25","date_modified_ts":"2021-05-25T19:33:26Z","date_created":"2021-05-25T19:33:26Z","summary":null,"body":["<article data-history-node-id=\"2470\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-49\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-236<br \/>\nDate: 25 May 2021<\/strong><\/p>\n\n<p>Between 17 and 24 May 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM MQ Appliance \u2013 versions 9.1 CD, 9.1 LTS, 9.2 CD and 9.2 LTS<\/li>\n\t<li>IBM Security Guardium \u2013 version 11.2<\/li>\n\t<li>IBM Spectrum Control \u2013 versions 5.3.0.1 to 5.4.2<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Infrastructure Management \u2013 all versions<\/li>\n\t<li>IBM Cloud Automation Manager \u2013 version 4.2.0.1<\/li>\n\t<li>IBM Sterling B2B Integrator \u2013 versions 5.2.0.0 to 5.2.6.5_3, 6.0.0.0 to 6.0.3.3, and 6.1.0.0 to 6.1.0.1<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Monitoring \u2013 versions prior to 2.3<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Security Services \u2013 versions 2.0, 2.1 and 2.2<\/li>\n\t<li>IBM Resilient OnPrem \u2013 IBM Security SOAR<\/li>\n\t<li>IBM Netezza Analytics for NPS \u2013 versions 11.2.1.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-49","alert_type":396,"serial_number":"AV21-236","subject":null,"moderation_state":"published","external_url":null},{"nid":2471,"title":"Apple security advisory","uuid":"c40eea61-dd46-42f8-9d6b-9f8e348a0ab0","banner":null,"lang":"en","date_modified":"2021-05-25","date_modified_ts":"2021-05-25T19:42:48Z","date_created":"2021-05-25T19:42:48Z","summary":null,"body":["<article data-history-node-id=\"2471\" about=\"\/en\/alerts-advisories\/apple-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-237<br \/>\nDate: 25 May 2021<\/strong><\/p>\n\n<p>On 24 May 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Safari \u2013 versions prior to 14.1.1<\/li>\n\t<li>macOS Catalina - versions prior to Security Update 2021-003<\/li>\n\t<li>macOS Mojave - versions prior to Security Update 2021-004<\/li>\n\t<li>macOS Big Sur - versions prior to 11.4<\/li>\n\t<li>iOS - versions prior to 14.6<\/li>\n\t<li>iPadOS - versions prior to 14.6<\/li>\n\t<li>tvOS - versions prior to 14.6<\/li>\n\t<li>watchOS - versions prior to 7.5<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution, denial of-service (DoS), universal cross-site scripting, disclosure of user information or memory contents and the ability to gain root privileges. Apple is aware of a report that some of these issues may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-31","alert_type":396,"serial_number":"AV21-237","subject":null,"moderation_state":"published","external_url":null},{"nid":2472,"title":"VMware security advisory","uuid":"efb8b337-065c-411b-acee-323423e2b16a","banner":null,"lang":"en","date_modified":"2021-05-26","date_modified_ts":"2021-05-26T13:27:03Z","date_created":"2021-05-26T13:27:03Z","summary":null,"body":["<article data-history-node-id=\"2472\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-41\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-238<br \/>\nDate: 26 May 2021<\/strong><\/p>\n\n<p>On 25 May 2021 VMware published a Security Advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware vCenter Server 6.5 - versions prior to 6.5 U3p<\/li>\n\t<li>VMware vCenter Server 6.7 - versions prior to 6.7 U3n<\/li>\n\t<li>VMware vCenter Server 7.0 - versions prior to 7.0 U2b<\/li>\n\t<li>VMware Cloud Foundation 3.X \u2013 versions prior to 3.10.2.1<\/li>\n\t<li>VMware Cloud Foundation 4.X \u2013 versions prior to 4.2.1<\/li>\n<\/ul><p>Exploitation could allow an actor with network access to execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0010)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0010.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0010.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-41","alert_type":396,"serial_number":"AV21-238","subject":null,"moderation_state":"published","external_url":null},{"nid":2473,"title":"[Control systems] Siemens security advisory","uuid":"92fc0d7c-9909-4119-8cf8-325798274069","banner":null,"lang":"en","date_modified":"2021-05-26","date_modified_ts":"2021-05-26T13:30:21Z","date_created":"2021-05-26T13:30:21Z","summary":null,"body":["<article data-history-node-id=\"2473\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-239<br \/>\nDate: 26 May 2021<\/strong><\/p>\n\n<p>On 25 May 2021 Siemens published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Luxion KeyShot (Bundled with Solid Edge SE2020 and SE2021) \u2013 versions prior to 10.2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities may lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisory (SSA-119468)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-119468.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-119468.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-26","alert_type":398,"serial_number":"AV21-239","subject":null,"moderation_state":"published","external_url":null},{"nid":2474,"title":"Google Chrome security advisory","uuid":"64d076e7-8510-418b-97f3-5be947edc157","banner":null,"lang":"en","date_modified":"2021-05-26","date_modified_ts":"2021-05-26T14:02:38Z","date_created":"2021-05-26T14:02:38Z","summary":null,"body":["<article data-history-node-id=\"2474\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-56\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-240<br \/>\nDate: 26 May 2021<\/strong><\/p>\n\n<p>On 25 May 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 91.0.4472.77<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/05\/stable-channel-update-for-desktop_25.html\">https:\/\/chromereleases.googleblog.com\/2021\/05\/stable-channel-update-for-desktop_25.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-56","alert_type":396,"serial_number":"AV21-240","subject":null,"moderation_state":"published","external_url":null},{"nid":2475,"title":"[Control systems] Rockwell Automation security advisory","uuid":"36c4165c-253f-47d0-b95a-dc48e27a42da","banner":null,"lang":"en","date_modified":"2021-05-26","date_modified_ts":"2021-05-26T17:43:07Z","date_created":"2021-05-26T17:43:07Z","summary":null,"body":["<article data-history-node-id=\"2475\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-241<br \/>\nDate:\u00a0 26 May 2021<\/strong><\/p>\n\n<p>On 25 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Micro800 \u2013 all versions<\/li>\n\t<li>MicroLogix 1400 \u2013 version 21 and later when Enhanced Password Security enabled<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in a denial-of-service condition, requiring a firmware flash to recover.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-145-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-145-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-145-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-18","alert_type":398,"serial_number":"AV21-241","subject":null,"moderation_state":"published","external_url":null},{"nid":2476,"title":"F5 security advisory","uuid":"deb2a0db-2c23-4eb0-9bae-ba5b30e4205c","banner":null,"lang":"en","date_modified":"2021-05-27","date_modified_ts":"2021-05-27T13:23:32Z","date_created":"2021-05-27T13:21:53Z","summary":null,"body":["<article data-history-node-id=\"2476\" about=\"\/en\/alerts-advisories\/f5-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-242<br \/>\nDate: 27 May 2021<\/strong><\/p>\n\n<p>On 25 May 2021 F5 published Security Advisories to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>NGINX Controller 3.X \u2013 versions prior to 3.4.0<\/li>\n\t<li>NGINX Controller 2.X \u2013 versions 2.0.0 to 2.9.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in cleartext data interception and exposure of the NGINX Controller Administrator password.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>Overview of NGINX vulnerabilities (K52559937)<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K52559937\">https:\/\/support.f5.com\/csp\/article\/K52559937<\/a><\/p>\n\n<p>F5 Knowledge Center<br \/><a href=\"https:\/\/support.f5.com\/csp\/new-updated-articles\">https:\/\/support.f5.com\/csp\/new-updated-articles<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-1","alert_type":396,"serial_number":"AV21-242","subject":null,"moderation_state":"published","external_url":null},{"nid":2477,"title":"HPE security advisory","uuid":"c30d2139-f928-42fc-8db4-51a3b29f6964","banner":null,"lang":"en","date_modified":"2021-05-27","date_modified_ts":"2021-05-27T16:03:12Z","date_created":"2021-05-27T16:03:12Z","summary":null,"body":["<article data-history-node-id=\"2477\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-243<br \/>\nDate: 27 May 2021<\/strong><\/p>\n\n<p>On 27 May 2021 HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Systems Insight Manager (SIM) \u2013 version 7.6.x<\/li>\n<\/ul><p>Exploitation of this vulnerability may allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Hewlett Packard Enterprise Systems Insight Manager (HPESBGN04068 rev.3)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04068en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04068en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-19","alert_type":396,"serial_number":"AV21-243","subject":null,"moderation_state":"published","external_url":null},{"nid":2478,"title":"Red Hat security advisory","uuid":"88278811-80f0-4825-b3c9-cab25ddba942","banner":null,"lang":"en","date_modified":"2021-05-27","date_modified_ts":"2021-05-27T18:13:31Z","date_created":"2021-05-27T18:13:31Z","summary":null,"body":["<article data-history-node-id=\"2478\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-244<br \/>\nDate: 27 May 2021<\/strong><\/p>\n\n<p>On 25 May 2021 Red Hat published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Red Hat Data Grid 8 \u2013 versions prior to 8.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability by an unauthenticated, remote actor may allow them to bypass authentication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Red Hat Data Grid 8:<br \/><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2021-31917\">https:\/\/access.redhat.com\/security\/cve\/cve-2021-31917<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-4","alert_type":396,"serial_number":"AV21-244","subject":null,"moderation_state":"published","external_url":null},{"nid":2479,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"e972e386-ba28-4c4a-96fd-7c413b3754b9","banner":null,"lang":"en","date_modified":"2021-05-27","date_modified_ts":"2021-05-27T19:47:14Z","date_created":"2021-05-27T19:29:32Z","summary":null,"body":["<article data-history-node-id=\"2479\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-245<br \/>\nDate: 27 May 2021<\/strong><\/p>\n\n<p>On 27 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC iQ-R series:\n\t<ul><li>R00\/01\/02CPU - all versions<\/li>\n\t\t<li>R04\/08\/16\/32\/120(EN)CPU - all versions<\/li>\n\t\t<li>R08\/16\/32\/120SFCPU - all versions<\/li>\n\t\t<li>R08\/16\/32\/120PCPU - all versions<\/li>\n\t\t<li>R08\/16\/32\/120PSFCPU - all versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-147-05)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-05<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-16","alert_type":398,"serial_number":"AV21-245","subject":null,"moderation_state":"published","external_url":null},{"nid":2480,"title":"[Control systems] Mesa Labs security advisory","uuid":"2406d5b6-2681-4707-afba-947e3c4b278b","banner":null,"lang":"en","date_modified":"2021-05-28","date_modified_ts":"2021-05-28T11:39:20Z","date_created":"2021-05-28T11:39:20Z","summary":null,"body":["<article data-history-node-id=\"2480\" about=\"\/en\/alerts-advisories\/control-systems-mesa-labs-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-246<br \/>\nDate:\u00a0 28 May 2021<\/strong><\/p>\n\n<p>On 27 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>AmigaView \u2013 version 3.0 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow remote code execution or authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-147-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mesa-labs-security-advisory","alert_type":398,"serial_number":"AV21-246","subject":null,"moderation_state":"published","external_url":null},{"nid":2481,"title":"[Control systems] Johnson Controls security advisory","uuid":"47b33916-ef92-4825-a034-f9d925d4efdc","banner":null,"lang":"en","date_modified":"2021-05-28","date_modified_ts":"2021-05-28T11:45:36Z","date_created":"2021-05-28T11:45:36Z","summary":null,"body":["<article data-history-node-id=\"2481\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-247<br \/>\nDate:\u00a028 May 2021<\/strong><\/p>\n\n<p>On 27 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>VideoEdge \u2013 versions prior to 5.7.0<\/li>\n<\/ul><p>Exploitation of this vulnerability may allow local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-147-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-6","alert_type":398,"serial_number":"AV21-247","subject":null,"moderation_state":"published","external_url":null},{"nid":2482,"title":"[Control systems] GENIVI Alliance security advisory","uuid":"e8238a56-8e7e-4fe7-bb6a-894dd8d9f413","banner":null,"lang":"en","date_modified":"2021-05-28","date_modified_ts":"2021-05-28T14:45:44Z","date_created":"2021-05-28T14:45:44Z","summary":null,"body":["<article data-history-node-id=\"2482\" about=\"\/en\/alerts-advisories\/control-systems-genivi-alliance-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-248<br \/>\nDate: 28 May 2021<\/strong><\/p>\n\n<p>On 27 May 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Diagnostic Log and Trace (DLT) Daemon \u2013 versions prior to 2.18.6<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-147-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-147-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-genivi-alliance-security-advisory","alert_type":398,"serial_number":"AV21-248","subject":null,"moderation_state":"published","external_url":null},{"nid":2484,"title":"[Control systems] Siemens security advisory","uuid":"380b7d3e-b5e4-4b72-a47f-a303cf03faca","banner":null,"lang":"en","date_modified":"2021-05-28","date_modified_ts":"2021-05-28T18:42:13Z","date_created":"2021-05-28T18:01:14Z","summary":null,"body":["<article data-history-node-id=\"2484\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-249<br \/>\nDate: 28 May 2021<\/strong><br \/><br \/>\nOn 28 May 2021 Siemens published a Security Advisory to address a vulnerability in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SIMATIC Drive Controller family \u2013 versions prior to V2.9.2<\/li>\n\t<li>SIMATIC ET 200SP Open Controller CPU 1515SP PC &amp; PC2 (incl. SIPLUS variants) \u2013 all versions<\/li>\n\t<li>SIMATIC S7-1200 CPU family (incl. SIPLUS variants) \u2013 versions prior to V4.5.0<\/li>\n\t<li>SIMATIC S7-1500 CPU family (incl. related ET200 &amp; SIPLUS variants) \u2013 versions prior to V2.9.2<\/li>\n\t<li>SIMATIC S7-1500 Software Controller \u2013 all versions<\/li>\n\t<li>SIMATIC S7-PLCSIM Advanced \u2013 versions prior to V4.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote, unauthenticated actor to read and write sensitive data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisory (SSA-434534)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-434534.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-434534.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-27","alert_type":398,"serial_number":"AV21-249","subject":null,"moderation_state":"published","external_url":null},{"nid":2485,"title":"IBM security advisory","uuid":"859c2695-1d6c-442c-8a54-02f28481cc0f","banner":null,"lang":"en","date_modified":"2021-05-31","date_modified_ts":"2021-05-31T16:09:00Z","date_created":"2021-05-31T16:09:00Z","summary":null,"body":["<article data-history-node-id=\"2485\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-50\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-250<br \/>\nDate: 31 May 2021<\/strong><\/p>\n\n<p>Between 25 and 30 May 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Spectrum Protect Snapshot for Db2 on AIX and Linux \u2013 versions 8.1.0.0 to 8.1.11.0 and 4.1.0.0 to 4.1.6.4<\/li>\n\t<li>IBM Spectrum Protect Snapshot for Custom Applications on AIX and Linux \u2013 versions 8.1.0.0 to 8.1.11.0 and 4.1.0.0 to 4.1.6.4<\/li>\n\t<li>IBM Spectrum Protect Snapshot for Oracle on AIX and Linux \u2013 versions 8.1.0.0 to 8.1.11.0 and 4.1.0.0 to 4.1.6.4<\/li>\n\t<li>IBM Spectrum Protect Snapshot for Oracle with SAP on AIX and Linux \u2013 versions 8.1.0.0 to 8.1.11.0 and 4.1.0.0 to 4.1.6.4<\/li>\n\t<li>IBM Spectrum Protect Snapshot Prerequisite Checker \u2013 versions 8.1.0.0 to 8.1.11.0 and 4.1.0.0 to 4.1.6.4<\/li>\n\t<li>IBM MQ \u2013 versions 9.1 LTS, 9.0 LTS, 8.0, 9.2 CD, 9.1 CD and 9.2 LTS<\/li>\n\t<li>IBM Watson Knowledge Catalog for IBM Cloud Pak for Data (on-prem) \u2013 versions 2.5, 3.0, 3.5.1, 3.5.2 and 3.5.3<\/li>\n\t<li>IBM WebSphere eXtreme Scale Liberty Deployment (XSLD) - versions 8.6.1.0 to 8.6.1.4<\/li>\n\t<li>IBM Application Gateway \u2013 version 1.0<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.0 and 11.1\u00a0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-50","alert_type":396,"serial_number":"AV21-250","subject":null,"moderation_state":"published","external_url":null},{"nid":2486,"title":"Mozilla security advisory","uuid":"b8fdf489-ddc7-4283-8773-92d2ba36e3b9","banner":null,"lang":"en","date_modified":"2021-06-01","date_modified_ts":"2021-06-01T16:19:04Z","date_created":"2021-06-01T16:19:04Z","summary":null,"body":["<article data-history-node-id=\"2486\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-251<br \/>\nDate: 1 June 2021<\/strong><\/p>\n\n<p>On 1 June 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 89<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.11<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-23)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-23\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-23\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-24)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-24\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-24\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-37","alert_type":396,"serial_number":"AV21-251","subject":null,"moderation_state":"published","external_url":null},{"nid":2487,"title":"Cisco security advisory","uuid":"023ebe47-7a12-4cfa-b33f-ccceb19ddb57","banner":null,"lang":"en","date_modified":"2021-06-01","date_modified_ts":"2021-06-01T18:56:53Z","date_created":"2021-06-01T18:56:53Z","summary":null,"body":["<article data-history-node-id=\"2487\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-82\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-252<br \/>\nDate: 1 June 2021<\/strong><\/p>\n\n<p>On 1 June 2021 Cisco published a Security Advisory to address a vulnerability in multiple products:<\/p>\n\n<ul><li>Cisco Adaptive Security Appliance (ASA) Software \u2013 versions prior to 9.8.4.38, 9.12.4.24, 9.14.3, 9.15.1.15 and 9.16.1.3<\/li>\n\t<li>Cisco Content Security Management Appliance (SMA) - versions prior to 13.8.1 and 14.1.0<\/li>\n\t<li>Cisco Email Security Appliance (ESA) - versions prior to 14.0.0-692 GD<\/li>\n\t<li>Cisco FXOS Software - versions prior to 2.2.2.149, 2.3.1.216, 2.6.1.230, 2.7.1.143, 2.8.1.152 and 2.9.1.143<\/li>\n\t<li>Cisco Web Security Appliance (WSA) - versions prior to 14.0.1<\/li>\n\t<li>Cisco Firepower Threat Defense (FTD) Software \u2013 versions prior to 6.4.0.12, 6.6.5, 6.7.0.2 and 7.0.0<\/li>\n\t<li>Cisco Prime Collaboration Assurance \u2013 versions prior to 12.1 SP4 ES<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated actor to impersonate another authorized user when interacting with an application.<\/p>\n\n<p>Cisco has indicated that it is aware of proof-of-concept exploit code available for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Cisco Security Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-lasso-saml-jun2021-DOXNRLkD\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-lasso-saml-jun2021-DOXNRLkD<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-82","alert_type":396,"serial_number":"AV21-252","subject":null,"moderation_state":"published","external_url":null},{"nid":2488,"title":"[Control systems] Hillrom security advisory","uuid":"8f0961b8-64fb-4100-8d8a-175d37db88b8","banner":null,"lang":"en","date_modified":"2021-06-02","date_modified_ts":"2021-06-02T16:05:53Z","date_created":"2021-06-02T16:05:53Z","summary":null,"body":["<article data-history-node-id=\"2488\" about=\"\/en\/alerts-advisories\/control-systems-hillrom-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-253<br \/>\nDate: 2 June 2021<\/strong><\/p>\n\n<p>On 1 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Welch Allyn Service Tool - versions prior to v1.10<\/li>\n\t<li>Welch Allyn Connex Device Integration Suite \u2013 Network Connectivity Engine (NCE) - versions prior to v5.3<\/li>\n\t<li>Welch Allyn Software Development Kit (SDK) - versions prior to v3.2<\/li>\n\t<li>Welch Allyn Connex Central Station (CS) - versions prior to v1.8.6<\/li>\n\t<li>Welch Allyn Service Monitor - versions prior to v1.7.0.0<\/li>\n\t<li>Welch Allyn Connex Vital Signs Monitor (CVSM) - versions prior to v2.43.02<\/li>\n\t<li>Welch Allyn Connex Integrated Wall System (CIWS) - versions prior to v2.43.02<\/li>\n\t<li>Welch Allyn Connex Spot Monitor (CSM) - versions prior to v1.52<\/li>\n\t<li>Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) \/ Welch Allyn Spot 4400 Vital Signs Extended Care Device - versions prior to v1.11.00<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could allow an actor to cause memory corruption and remotely execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSMA-21-152-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-152-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-152-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hillrom-security-advisory","alert_type":398,"serial_number":"AV21-253","subject":null,"moderation_state":"published","external_url":null},{"nid":2489,"title":"HPE security advisory","uuid":"cb27cfca-10fd-4d9e-b91f-2681d31a94e2","banner":null,"lang":"en","date_modified":"2021-06-02","date_modified_ts":"2021-06-02T17:45:38Z","date_created":"2021-06-02T17:45:38Z","summary":null,"body":["<article data-history-node-id=\"2489\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-254<br \/>\nDate: 2 June 2021<\/strong><\/p>\n\n<p>On 1 June 2021 HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HP-UX System Management Software \u2013 version A.3.2.21.03 and prior<\/li>\n\t<li>HPE System Management Homepage - version A.3.2.21.03 and prior<\/li>\n\t<li>HPE ProLiant m510 Server Cartridge for Moonshot\/Edgeline - versions prior to 2.64<\/li>\n\t<li>HPE ProLiant m710x Server Blade for Moonshot\/Edgeline - versions prior to 2.64<\/li>\n\t<li>HPE ProLiant m710x-L Server Blade for Moonshot\/Edgeline - versions prior to 2.64<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in authentication bypass, remote arbitrary code execution, buffer overflow, cross-site scripting or carriage return line feed (CRLF) injection.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>HPE HP-UX System Management Homepage (HPESBUX04166 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04166en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04166en_us<\/a><\/p>\n\n<p>HPE Integrated Lights-Out 4 (iLO 4) for Moonshot and Edgeline Cartridges and Blades (HPESBHF04143 rev.1)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04143en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04143en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-20","alert_type":396,"serial_number":"AV21-254","subject":null,"moderation_state":"published","external_url":null},{"nid":2490,"title":"Fortinet security advisory","uuid":"6cc3df9a-54de-4137-91ee-f52fd9bde5d8","banner":null,"lang":"en","date_modified":"2021-06-02","date_modified_ts":"2021-06-02T19:24:05Z","date_created":"2021-06-02T19:24:05Z","summary":null,"body":["<article data-history-node-id=\"2490\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-255<br \/>\nDate: 2 June 2021<\/strong><\/p>\n\n<p>On 1 June 2021 Fortinet published multiple PSIRT Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiProxy - versions 2.0.0, 1.2.8 and prior, 1.1.6 and prior and 1.0.7 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to privilege escalation or improper access control.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>PSIRT Advisory (FG-IR-20-231)<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-20-231\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-20-231<\/a><\/p>\n\n<p>PSIRT Advisory (FG-IR-20-233)<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-20-233\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-20-233<\/a><\/p>\n\n<p>Fortinet PSIRT Advisories<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-8","alert_type":396,"serial_number":"AV21-255","subject":null,"moderation_state":"published","external_url":null},{"nid":2491,"title":"Cisco security advisory","uuid":"9b32e775-4f28-4f04-9380-c96a68200b74","banner":null,"lang":"en","date_modified":"2021-06-03","date_modified_ts":"2021-06-03T19:40:54Z","date_created":"2021-06-03T19:40:54Z","summary":null,"body":["<article data-history-node-id=\"2491\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-83\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-256<br \/>\nDate: 3 June 2021<\/strong><\/p>\n\n<p>On 2 June 2021 Cisco published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ASR 5000 Series Aggregation Services Routers running Cisco StarOS \u2013 multiple versions<\/li>\n\t<li>Virtualized Packet Core \u2013 Distributed Instance (VPC-DI) running Cisco StarOS - multiple versions<\/li>\n\t<li>Virtualized Packet Core \u2013 Single Instance (VPC-SI) running Cisco StarOS \u2013 multiple versions<\/li>\n\t<li>SD-WAN vBond Orchestrator Software \u2013 versions 20.4 and 20.5<\/li>\n\t<li>SD-WAN vEdge Cloud Routers \u2013 versions 20.4 and 20.5<\/li>\n\t<li>SD-WAN vEdge Routers \u2013 versions 20.4 and 20.5<\/li>\n\t<li>SD-WAN vManage Software \u2013 versions 20.4 and 20.5<\/li>\n\t<li>SD-WAN vSmart Controller Software \u2013 versions 20.4 and 20.5<\/li>\n\t<li>Cisco Webex Network Recording Player for Windows and MacOS - versions prior to 41.4<\/li>\n\t<li>Cisco Webex Player for Windows and MacOS \u2013 versions prior to 41.4<\/li>\n<\/ul><p>Exploitation could allow an authenticated remote actor to bypass authorization and execute a subset of CLI commands on an affected device, allow an authenticated local actor to gain elevated privileges on an affected system or allow the execution of arbitrary code on an affected system.\u00a0<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-83","alert_type":396,"serial_number":"AV21-256","subject":null,"moderation_state":"published","external_url":null},{"nid":2492,"title":"Mozilla security advisory","uuid":"d0f0eaa0-0a89-4e41-8890-cd8d6b437325","banner":null,"lang":"en","date_modified":"2021-06-03","date_modified_ts":"2021-06-03T19:44:40Z","date_created":"2021-06-03T19:44:40Z","summary":null,"body":["<article data-history-node-id=\"2492\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-257<br \/>\nDate: 3 June 2021<\/strong><\/p>\n\n<p>On 3 June 2021 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 78.11<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Thunderbird (MFSA 2021-26)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-26\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-26\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-38","alert_type":396,"serial_number":"AV21-257","subject":null,"moderation_state":"published","external_url":null},{"nid":2493,"title":"Ubuntu security advisory","uuid":"88c67e35-42cb-4c0b-91a7-f16d58402ec0","banner":null,"lang":"en","date_modified":"2021-06-04","date_modified_ts":"2021-06-04T13:43:12Z","date_created":"2021-06-04T13:43:12Z","summary":null,"body":["<article data-history-node-id=\"2493\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-258<br \/>\nDate: 4 June 2021<\/strong><\/p>\n\n<p>On 3 June 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, access to sensitive information, privilege escalation or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4977-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4977-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4977-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4979-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4979-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4979-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4982-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4982-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4982-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-4983-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4983-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4983-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-13","alert_type":396,"serial_number":"AV21-258","subject":null,"moderation_state":"published","external_url":null},{"nid":2494,"title":"[Control systems] Advantech security advisory","uuid":"8d0ea257-c76e-4c74-96ce-a67c48f8c0eb","banner":null,"lang":"en","date_modified":"2021-06-04","date_modified_ts":"2021-06-04T14:57:08Z","date_created":"2021-06-04T14:57:08Z","summary":null,"body":["<article data-history-node-id=\"2494\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-259<br \/>\nDate: 4 June 2021<\/strong><\/p>\n\n<p>On 3 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>iView - versions prior to v5.7.03.6182<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.\u00a0<\/p>\n\n<p>ICS Advisory (ICSA-21-154-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-154-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-154-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-16","alert_type":398,"serial_number":"AV21-259","subject":null,"moderation_state":"published","external_url":null},{"nid":2495,"title":"Android security advisory \u2013 June 2021 monthly rollup","uuid":"d779437c-0087-4087-8b0e-8ecdac3a0f78","banner":null,"lang":"en","date_modified":"2021-06-07","date_modified_ts":"2021-06-07T18:37:57Z","date_created":"2021-06-07T18:36:11Z","summary":null,"body":["<article data-history-node-id=\"2495\" about=\"\/en\/alerts-advisories\/android-security-advisory-june-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-263<br \/>\nDate: 7 June 2021<\/strong><\/p>\n\n<p>On 7 June 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-06-01\">https:\/\/source.android.com\/security\/bulletin\/2021-06-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-june-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-263","subject":null,"moderation_state":"published","external_url":null},{"nid":2496,"title":"IBM security advisory","uuid":"d6230a6b-8d75-4074-9565-996b4a073278","banner":null,"lang":"en","date_modified":"2021-06-08","date_modified_ts":"2021-06-08T11:18:38Z","date_created":"2021-06-08T11:18:38Z","summary":null,"body":["<article data-history-node-id=\"2496\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-51\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-260<br \/>\nDate: 8 June 2021<\/strong><\/p>\n\n<p>Between 31 May and 6 June 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>InfoSphere Master Data Management \u2013 version 11.6<\/li>\n\t<li>UrbanCode Velocity (UCV) \u2013 all versions<\/li>\n\t<li>IBM Security Guardium \u2013 versions 11.2 and 11.3<\/li>\n\t<li>IBM DataPower Gateway \u2013 versions 10.0.0 and 2018.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>InfoSphere Master Data Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-security-vulnerabilities-have-been-identified-in-ibm-websphere-application-server-used-by-ibm-infosphere-master-data-management-server-11-6\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-security-vulnerabilities-have-been-identified-in-ibm-websphere-application-server-used-by-ibm-infosphere-master-data-management-server-11-6\/<\/a><br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-security-vulnerabilities-have-been-identified-in-ibm-websphere-application-server-used-by-infosphere-master-data-management-11-6\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-security-vulnerabilities-have-been-identified-in-ibm-websphere-application-server-used-by-infosphere-master-data-management-11-6\/<\/a><\/p>\n\n<p>UrbanCode Velocity (UCV)<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cve-2020-15366-an-issue-was-discovered-in-ajv-validate-in-ajv-aka-another-json-schema-validator-6-12-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cve-2020-15366-an-issue-was-discovered-in-ajv-validate-in-ajv-aka-another-json-schema-validator-6-12-2\/<\/a><\/p>\n\n<p>IBM Security Guardium<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-5\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-5\/<\/a><\/p>\n\n<p>IBM DataPower Gateway<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-may-affect-jre-in-ibm-datapower-gateway\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-may-affect-jre-in-ibm-datapower-gateway\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-51","alert_type":396,"serial_number":"AV21-260","subject":null,"moderation_state":"published","external_url":null},{"nid":2497,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"40c1d212-f661-40ad-a65e-923f35c13b16","banner":null,"lang":"en","date_modified":"2021-06-08","date_modified_ts":"2021-06-08T11:32:37Z","date_created":"2021-06-08T11:32:37Z","summary":null,"body":["<article data-history-node-id=\"2497\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-261<br \/>\nDate:\u00a08 June 2021<\/strong><\/p>\n\n<p>On 27 May 2021 B&amp;R Industrial Automation published Cyber Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>B&amp;R Ethernet-based Bus Controllers and related products \u2013 multiple products and versions<\/li>\n\t<li>B&amp;R Ethernet-based Customized HMI devices (e.g. keyboards) - multiple products and versions<\/li>\n\t<li>B&amp;R Motion Control products - multiple products and versions<\/li>\n\t<li>B&amp;R Track Technology products - multiple products and versions<\/li>\n\t<li>Automation Runtime (AR) - version 4.8 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, the writing of arbitrary files and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates where and when available.<\/p>\n\n<p>Cyber Security Advisory (#04\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1621259206587-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1621259206587-en-original-1.0.pdf<\/a><\/p>\n\n<p>Cyber Security Advisory (#05\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1621259206592-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1621259206592-en-original-1.0.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-2","alert_type":398,"serial_number":"AV21-261","subject":null,"moderation_state":"published","external_url":null},{"nid":2498,"title":"Ubuntu security advisory","uuid":"08c686ff-9e47-4166-aa78-f5f0763dcab4","banner":null,"lang":"en","date_modified":"2021-06-08","date_modified_ts":"2021-06-08T11:36:47Z","date_created":"2021-06-08T11:36:47Z","summary":null,"body":["<article data-history-node-id=\"2498\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-262<br \/>\nDate:\u00a08 June 2021<\/strong><\/p>\n\n<p>On 4 June 2021 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, access to sensitive information, privilege escalation or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-4984-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-4984-1\">https:\/\/ubuntu.com\/security\/notices\/USN-4984-1<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-14","alert_type":396,"serial_number":"AV21-262","subject":null,"moderation_state":"published","external_url":null},{"nid":2499,"title":"[Control systems] Schneider Electric security advisory","uuid":"2dfb8054-88f9-4307-b46b-76cbb5e5a612","banner":null,"lang":"en","date_modified":"2021-06-08","date_modified_ts":"2021-06-08T14:39:15Z","date_created":"2021-06-08T14:39:15Z","summary":null,"body":["<article data-history-node-id=\"2499\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-264<br \/>\nDate: 08 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 Schneider Electric published Security Notifications to address vulnerabilities in multiple products. Included were patches for the following:<\/p>\n\n<ul><li>IGSS \u2013 version V15.0.0.21140 and prior<\/li>\n\t<li>PowerLogic PM55xx and PowerLogic PM8ECC:\n\t<ul><li>PM5560 \u2013 versions prior to V2.7.8<\/li>\n\t\t<li>PM5561 \u2013 versions prior to V10.7.3<\/li>\n\t\t<li>PM5562 \u2013 version V2.5.4 and prior<\/li>\n\t\t<li>PM5563 \u2013 versions prior to 2.7.8<\/li>\n\t\t<li>PM8ECC \u2013 all versions<\/li>\n\t<\/ul><\/li>\n\t<li>PowerLogic EGX100 and PowerLogic EGX300:\n\t<ul><li>EGX100 \u2013 all versions<\/li>\n\t\t<li>EGX300 \u2013 all versions<\/li>\n\t<\/ul><\/li>\n\t<li>ISaGRAF:\n\t<ul><li>Easergy T300<\/li>\n\t\t<li>Easergy C5<\/li>\n\t\t<li>MiCOM C264<\/li>\n\t\t<li>PACiS GTW<\/li>\n\t\t<li>EPAS GTW<\/li>\n\t\t<li>SCADAPack 300E RTU<\/li>\n\t\t<li>SCADAPack 53xE RTU<\/li>\n\t\t<li>SCADAPack Workbench<\/li>\n\t\t<li>SCD2200 Firmware for CP-3\/MC-31<\/li>\n\t\t<li>SAGE RTU (C3414 CPU, C3413 CPU, C3412 CPU)<\/li>\n\t<\/ul><\/li>\n\t<li>Modicon X80 BMXNOR0200H RTU \u2013 version SV1.70 IR22 and prior<\/li>\n\t<li>Enerlin\u2019X Com\u2019X \u2013 versions prior to V6.8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-21","alert_type":398,"serial_number":"AV21-264","subject":null,"moderation_state":"published","external_url":null},{"nid":2500,"title":"SAP security advisory \u2013 June 2021 monthly rollup","uuid":"8c847d0c-1524-487c-8e1a-9dc1236fecf2","banner":null,"lang":"en","date_modified":"2021-06-08","date_modified_ts":"2021-06-08T14:45:17Z","date_created":"2021-06-08T14:45:17Z","summary":null,"body":["<article data-history-node-id=\"2500\" about=\"\/en\/alerts-advisories\/sap-security-advisory-june-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-265<br \/>\nDate: 08 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical severity patches for the following:<\/p>\n\n<ul><li>SAP Commerce \u2013 versions 1808, 1811, 1905, 2005 and 2011<\/li>\n\t<li>SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755 and 804\u00a0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 June 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=578125999\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=578125999<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-june-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-265","subject":null,"moderation_state":"published","external_url":null},{"nid":2501,"title":"[Control systems] Siemens security advisory","uuid":"a49623bd-2b86-44b0-abcd-a8d734a12d5c","banner":null,"lang":"en","date_modified":"2021-06-08","date_modified_ts":"2021-06-08T14:49:09Z","date_created":"2021-06-08T14:49:09Z","summary":null,"body":["<article data-history-node-id=\"2501\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-266<br \/>\nDate: 08 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SIMATIC RF \u2013 multiple platforms and versions<\/li>\n\t<li>JT2Go \u2013 versions prior to V13.1.0.3<\/li>\n\t<li>Teamcenter Visualization \u2013 versions prior to V13.1.0.3<\/li>\n\t<li>Mendix SAML Module \u2013 versions prior to V2.1.2<\/li>\n\t<li>TIM 1531 IRC (incl. SIPLUS NET variants) \u2013 versions prior to V2.2<\/li>\n\t<li>SIMATIC NET CP 443-1 OPC UA \u2013 all versions<\/li>\n\t<li>Solid Edge SE2020 \u2013 versions prior to 2020MP14<\/li>\n\t<li>Solid Edge SE2021 \u2013 versions prior to SE2021MP5<\/li>\n\t<li>Simcenter Femap 2020.2 \u2013 versions prior to V2020.2.MP3<\/li>\n\t<li>Simcenter Femap 2021.1 \u2013 versions prior to V2021.1.MP3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to crash services, execute code, extract data, escalate privileges, or cause denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-28","alert_type":398,"serial_number":"AV21-266","subject":null,"moderation_state":"published","external_url":null},{"nid":2502,"title":"[Control systems] Open Design Alliance security advisory","uuid":"155734c4-e8b7-4d45-bae8-014da3aeed8e","banner":null,"lang":"en","date_modified":"2021-06-08","date_modified_ts":"2021-06-08T19:55:01Z","date_created":"2021-06-08T19:55:01Z","summary":null,"body":["<article data-history-node-id=\"2502\" about=\"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-267<br \/>\nDate: 8 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Drawings SDK \u2013 versions 2022.4 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow code execution or cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-159-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory-0","alert_type":398,"serial_number":"AV21-267","subject":null,"moderation_state":"published","external_url":null},{"nid":2503,"title":"Adobe security advisory","uuid":"bc3d6ac9-2af3-4683-8ffb-80337bd9d7f1","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T15:16:21Z","date_created":"2021-06-09T15:16:21Z","summary":null,"body":["<article data-history-node-id=\"2503\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-41\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-268<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Adobe Animate \u2013 version 21.0.6 and prior<\/li>\n\t<li>Adobe After Effects \u2013 version 18.2 and prior<\/li>\n\t<li>RoboHelp Server \u2013 version 2019.0.9 and prior<\/li>\n\t<li>Creative Cloud Desktop Application (Installer) \u2013 version 2.4 and prior<\/li>\n\t<li>Photoshop 2020 \u2013 version 21.2.8 and prior<\/li>\n\t<li>Photoshop 2021 \u2013 version 22.4.1 and prior<\/li>\n\t<li>Acrobat DC and Reader DC \u2013 version 2021.001.20155 and prior<\/li>\n\t<li>Acrobat 2020 and Acrobat Reader 2020 \u2013 version 2020.001.30025 and prior<\/li>\n\t<li>Acrobat 2017 and Acrobat Reader 2017 \u2013 version 2017.011.30196 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-41","alert_type":396,"serial_number":"AV21-268","subject":null,"moderation_state":"published","external_url":null},{"nid":2504,"title":"[Control systems] AVEVA Software, LLC security advisory","uuid":"f62618b1-71f1-4907-90ee-a8cc22a86085","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T15:21:42Z","date_created":"2021-06-09T15:21:42Z","summary":null,"body":["<article data-history-node-id=\"2504\" about=\"\/en\/alerts-advisories\/control-systems-aveva-software-llc-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-269<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>InTouch 2020 \u2013 version R2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could expose plaintext credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-159-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-software-llc-security-advisory","alert_type":398,"serial_number":"AV21-269","subject":null,"moderation_state":"published","external_url":null},{"nid":2505,"title":"Intel security advisory","uuid":"ead80034-c0e4-4aae-bc5e-0550063ccac2","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T15:27:20Z","date_created":"2021-06-09T15:27:20Z","summary":null,"body":["<article data-history-node-id=\"2505\" about=\"\/en\/alerts-advisories\/intel-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-270<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 Intel published Security Advisories to address vulnerabilities in multiple products. Of note is a vulnerability in multiple Intel Processors which could allow an actor to escalate privileges via local access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Intel Product Security Center Advisories<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-17","alert_type":396,"serial_number":"AV21-270","subject":null,"moderation_state":"published","external_url":null},{"nid":2506,"title":"[Control systems] Johnson Controls security advisory","uuid":"cb2108c0-290c-4bd3-952a-30493299fb8e","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T15:34:46Z","date_created":"2021-06-09T15:34:46Z","summary":null,"body":["<article data-history-node-id=\"2506\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-271<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Metasys \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated Metasys user to access or modify system files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-159-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-7","alert_type":398,"serial_number":"AV21-271","subject":null,"moderation_state":"published","external_url":null},{"nid":2507,"title":"[Control systems] Thales security advisory","uuid":"9e8fc7d9-cd6b-44bc-bab3-1e469c0e7df2","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T15:39:32Z","date_created":"2021-06-09T15:39:32Z","summary":null,"body":["<article data-history-node-id=\"2507\" about=\"\/en\/alerts-advisories\/control-systems-thales-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-272<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Sentinel LDK Run-Time Environment \u2013 version 7.6 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to connect on an open port.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-159-06)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-06\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-159-06<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-thales-security-advisory","alert_type":398,"serial_number":"AV21-272","subject":null,"moderation_state":"published","external_url":null},{"nid":2508,"title":"Microsoft security advisory \u2013 June 2021 monthly rollup","uuid":"fd4baf4f-4cbd-4ba5-87a0-9a435d20504b","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T18:02:23Z","date_created":"2021-06-09T18:02:23Z","summary":null,"body":["<article data-history-node-id=\"2508\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-june-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-273<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 7, 8.1, RT 8.1 and 10<\/li>\n\t<li>Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016 and 2019<\/li>\n\t<li>Windows MSHTML<\/li>\n\t<li>SharePoint Server<\/li>\n\t<li>VP9 Video Extensions<\/li>\n\t<li>Defender Malware Protection Engine<\/li>\n\t<li>SharePoint Server<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely or corrupt memory.<\/p>\n\n<p>Of note, Microsoft has stated that the following vulnerabilities are being actively exploited: CVE-2021-31955, CVE-2021-31956, CVE-2021-33739, CVE-2021-33742, CVE-2021-31199, CVE-2021-31201. These vulnerabilities could be used to disclose information or escalate privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>June 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Jun\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Jun<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-june-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-273","subject":null,"moderation_state":"published","external_url":null},{"nid":2509,"title":"HPE security advisory","uuid":"4bd151b2-c162-4c02-9ef4-7b3b26c6024e","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T18:07:13Z","date_created":"2021-06-09T18:07:13Z","summary":null,"body":["<article data-history-node-id=\"2509\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-274<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant \u2013 multiple platforms and versions<\/li>\n\t<li>HPE Apollo 4200 Gen9 Server - versions prior to 2.90<\/li>\n\t<li>HPE Synergy \u2013 multiple platforms, versions prior to 2.90<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in disclosure of information, escalation of privilege or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Security Bulletin Library<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library\">https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-21","alert_type":396,"serial_number":"AV21-274","subject":null,"moderation_state":"published","external_url":null},{"nid":2510,"title":"[Control systems] Rockwell Automation security advisory","uuid":"fd04baab-d94c-4f2b-998e-d189fa7043d7","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T18:11:00Z","date_created":"2021-06-09T18:11:00Z","summary":null,"body":["<article data-history-node-id=\"2510\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-275<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>AADvance Controller \u2013 version 1.4 and prior<\/li>\n\t<li>ISaGRAF Free Runtime in ISaGRAF6 Workbench \u2013 version 6.6.8 and prior<\/li>\n\t<li>Micro800 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities may result in code execution, information disclosure, or a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-280-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-280-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-20-280-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-19","alert_type":398,"serial_number":"AV21-275","subject":null,"moderation_state":"published","external_url":null},{"nid":2511,"title":"Palo Alto Networks security advisory","uuid":"72a6c0d6-23bb-4ddd-8ded-3ce21c562497","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T19:33:56Z","date_created":"2021-06-09T19:33:56Z","summary":null,"body":["<article data-history-node-id=\"2511\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-276<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 9 June 2021 Palo Alto Networks published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Cortex XDR Agent 7.2 \u2013 version 7.2.3 and prior, or without content update 171 or later<\/li>\n\t<li>Cortex XDR Agent 6.1 \u2013 version 6.1.8 and prior<\/li>\n\t<li>Cortex XDR Agent 5.0 \u2013 version 5.0.11 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated local Windows user to execute programs with SYSTEM privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>CVE-2021-3041 Cortex XDR Agent<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3041\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3041<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-7","alert_type":396,"serial_number":"AV21-276","subject":null,"moderation_state":"published","external_url":null},{"nid":2512,"title":"Google Chrome security advisory","uuid":"63d7b560-7684-43b3-b050-abe9fce2766a","banner":null,"lang":"en","date_modified":"2021-06-09","date_modified_ts":"2021-06-09T19:36:42Z","date_created":"2021-06-09T19:36:42Z","summary":null,"body":["<article data-history-node-id=\"2512\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-57\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-277<br \/>\nDate: 9 June 2021<\/strong><\/p>\n\n<p>On 9 June 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 91.0.4472.101<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-57","alert_type":396,"serial_number":"AV21-277","subject":null,"moderation_state":"published","external_url":null},{"nid":2513,"title":"HPE security advisory","uuid":"714adb6f-0ffc-4119-9f52-f5c9e7b26f50","banner":null,"lang":"en","date_modified":"2021-06-10","date_modified_ts":"2021-06-10T17:50:39Z","date_created":"2021-06-10T17:50:39Z","summary":null,"body":["<article data-history-node-id=\"2513\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-278<br \/>\nDate: 10 June 2021<\/strong><\/p>\n\n<p>On 9 June 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE StoreEasy \u2013 multiple platforms, versions prior to 2.90<\/li>\n\t<li>HPE 3PAR \u2013 multiple platforms, versions prior to 2.90<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in disclosure of information, escalation of privilege or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE StoreEasy Gen9 Systems (HPESBST04168)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04168en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04168en_us<\/a>\u00a0<br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-22","alert_type":396,"serial_number":"AV21-278","subject":null,"moderation_state":"published","external_url":null},{"nid":2516,"title":"Citrix security advisory","uuid":"bcea6326-f2de-4f05-90d9-a9cc73d553e1","banner":null,"lang":"en","date_modified":"2021-06-11","date_modified_ts":"2021-06-11T19:04:31Z","date_created":"2021-06-11T18:45:18Z","summary":null,"body":["<article data-history-node-id=\"2516\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-281<br \/>\nDate:\u00a0 11 June 2021<\/strong><\/p>\n\n<p>On 8 June 2021 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix ADC and Citrix Gateway 13.0 \u2013 versions prior to 13.0-82.41<\/li>\n\t<li>Citrix ADC and Citrix Gateway 12.1 \u2013 versions prior to 12.1-62.23<\/li>\n\t<li>Citrix ADC and NetScaler Gateway 11.1 \u2013 versions prior to 65.20<\/li>\n\t<li>Citrix ADC 12.1-FIPS \u2013 versions prior to 12.1-55.238<\/li>\n\t<li>Citrix SD-WAN WANOP 11.4 \u2013 versions prior to 11.4.0<\/li>\n\t<li>Citrix SD-WAN WANOP 11.3 \u2013 versions prior to 11.3.2<\/li>\n\t<li>Citrix SD-WAN WANOP 11.3 \u2013 versions prior to 11.3.1a<\/li>\n\t<li>Citrix SD-WAN WANOP 11.2 \u2013 versions prior to 11.2.3a<\/li>\n\t<li>Citrix SD-WAN WANOP 11.1 \u2013 versions prior to 11.1.2c<\/li>\n\t<li>Citrix SD-WAN WANOP 10.2 \u2013 versions prior to 10.2.9a<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to cause a denial-of-service or be used to steal a valid user session.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX297155)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX297155\">https:\/\/support.citrix.com\/article\/CTX297155<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-15","alert_type":396,"serial_number":"AV21-281","subject":null,"moderation_state":"published","external_url":null},{"nid":2514,"title":"[Control systems] AGG Software security advisory","uuid":"f6a23379-fb5b-4480-815b-1640b4133df3","banner":null,"lang":"en","date_modified":"2021-06-11","date_modified_ts":"2021-06-11T18:51:22Z","date_created":"2021-06-11T18:51:22Z","summary":null,"body":["<article data-history-node-id=\"2514\" about=\"\/en\/alerts-advisories\/control-systems-agg-software-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-279<br \/>\nDate: 11 June 2021<\/strong><\/p>\n\n<p>On 10 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Web Server bundled with Data Logger\u2013 version v.4.0.40.1014 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities may result in remote code execution or exposure of system files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-161-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-161-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-161-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-agg-software-security-advisory","alert_type":398,"serial_number":"AV21-279","subject":null,"moderation_state":"published","external_url":null},{"nid":2515,"title":"[Control systems] ZOLL security advisory","uuid":"7de12d29-fc72-486e-a87e-6730e31ecbec","banner":null,"lang":"en","date_modified":"2021-06-11","date_modified_ts":"2021-06-11T18:56:42Z","date_created":"2021-06-11T18:56:42Z","summary":null,"body":["<article data-history-node-id=\"2515\" about=\"\/en\/alerts-advisories\/control-systems-zoll-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-280<br \/>\nDate: 11 June 2021<\/strong><\/p>\n\n<p>On 10 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Defibrillator Dashboard \u2013 versions prior to 2.2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow remote code execution, allow an actor to access credentials, or impact confidentiality, integrity and availability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-161-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-161-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-161-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-zoll-security-advisory","alert_type":398,"serial_number":"AV21-280","subject":null,"moderation_state":"published","external_url":null},{"nid":2517,"title":"IBM security advisory","uuid":"01baf2b4-7516-452b-b36b-1c6318ebfbba","banner":null,"lang":"en","date_modified":"2021-06-14","date_modified_ts":"2021-06-14T15:57:53Z","date_created":"2021-06-14T15:57:53Z","summary":null,"body":["<article data-history-node-id=\"2517\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-52\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-282<br \/>\nDate: 14 June 2021<\/strong><\/p>\n\n<p>Between 7 and 13 June 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Security Guardium \u2013 versions 11.1 and 11.3<\/li>\n\t<li>IBM Cloud Pak for Applications \u2013 version 4.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Security Guardium<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-jackson-databind-vulnerability-7\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-jackson-databind-vulnerability-7\/<\/a><\/p>\n\n<p>IBM Cloud Pak for Applications<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-applications-4-3-nodejs-and-nodejs-express-appsody-stacks-is-vulnerable-to-information-disclosure-buffer-overflow-and-prototype-pollution-exposures\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-applications-4-3-nodejs-and-nodejs-express-appsody-stacks-is-vulnerable-to-information-disclosure-buffer-overflow-and-prototype-pollution-exposures\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u2003<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-52","alert_type":396,"serial_number":"AV21-282","subject":null,"moderation_state":"published","external_url":null},{"nid":2518,"title":"Apple security advisory","uuid":"c89f9505-3ec0-43e9-a715-ff04d2918955","banner":null,"lang":"en","date_modified":"2021-06-14","date_modified_ts":"2021-06-14T20:03:54Z","date_created":"2021-06-14T20:03:54Z","summary":null,"body":["<article data-history-node-id=\"2518\" about=\"\/en\/alerts-advisories\/apple-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-283<br \/>\nDate: 14 June 2021<\/strong><\/p>\n\n<p>On 14 June 2021 Apple published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>iOS - versions prior to 12.5.4<\/li>\n<\/ul><p>Exploitation of some these vulnerabilities could result in arbitrary code execution. Apple is aware of a report that some of these issues may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>iOS 12<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT212548\">https:\/\/support.apple.com\/en-us\/HT212548<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-32","alert_type":396,"serial_number":"AV21-283","subject":null,"moderation_state":"published","external_url":null},{"nid":2519,"title":"Google Chrome security advisory","uuid":"94909f33-512d-471c-a1c3-0b4a1bacd031","banner":null,"lang":"en","date_modified":"2021-06-15","date_modified_ts":"2021-06-15T19:48:19Z","date_created":"2021-06-15T18:36:52Z","summary":null,"body":["<article data-history-node-id=\"2519\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-58\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-284<br \/>\nDate: 15 June 2021<\/strong><\/p>\n\n<p>On 14 June 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 91.0.4472.106<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop_14.html\">https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop_14.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-58","alert_type":396,"serial_number":"AV21-284","subject":null,"moderation_state":"published","external_url":null},{"nid":2523,"title":"Increase in DDoS Extortion Activity","uuid":"dec5c114-f450-4a69-8847-a9cec7d2e295","banner":null,"lang":"en","date_modified":"2021-06-17","date_modified_ts":"2021-06-17T16:20:06Z","date_created":"2021-06-16T13:45:42Z","summary":null,"body":["<article data-history-node-id=\"2523\" about=\"\/en\/alerts-advisories\/increase-ddos-extortion-activity\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-010<br \/>\nDate: 16 June 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>The Cyber Centre is aware of a recent increase in Distributed Denial of Service (DDoS) activity which is being carried out by malicious actors to extort victims for payment. The Cyber Centre has received reports from trusted partners of Canadian organizations being targeted by this activity.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>The Cyber Centre is aware of open-source reporting describing a recent increase in DDoS extortion activity. The Cyber Centre has also received reports from trusted partners indicating an increase in activity targeting Canadian organizations in multiple sectors.<\/p>\n\n<p>Although reports vary on the techniques used to carry out the DDoS, the activity consists of contact from the threat actor, a demonstration of the DDoS capability, and demands of payment in Bitcoin as ransom to cease the DDoS activity [<a href=\"https:\/\/blogs.akamai.com\/2021\/06\/the-rapid-resurgence-of-ddos-extortion-that-didnt-take-long.html\">1<\/a>],[<a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ransom-ddos-extortion-actor-fancy-lazarus-returns\">2<\/a>].<\/p>\n\n<p>In cases of DDoS extortion, see the Cyber Centre\u2019s guidance for Preventing and Recovering from extortion for guidance on dealing with demands of payment [<a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099\">3<\/a>]. Refer also to the Cyber Centre\u2019s guidance for Protecting Your Organization Against Denial-of-Service Attacks [<a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\">4<\/a>] for more information.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] The Rapid Resurgence of DDoS Extortion<br \/><a href=\"https:\/\/blogs.akamai.com\/2021\/06\/the-rapid-resurgence-of-ddos-extortion-that-didnt-take-long.html\">https:\/\/blogs.akamai.com\/2021\/06\/the-rapid-resurgence-of-ddos-extortion-that-didnt-take-long.html<\/a><\/p>\n\n<p>[2] Ransom DDoS Extortion Actor \u201cFancy Lazarus\u201d Returns<br \/><a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ransom-ddos-extortion-actor-fancy-lazarus-returns\">https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ransom-ddos-extortion-actor-fancy-lazarus-returns<\/a><\/p>\n\n<p>[3] How to Prevent and Recover<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099\">https:\/\/cyber.gc.ca\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099<\/a><\/p>\n\n<p>[4] Protecting Your Organization Against Denial-of-Service Attacks<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\">https:\/\/cyber.gc.ca\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the<br \/>\nCyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information<br \/>\nsharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/increase-ddos-extortion-activity","alert_type":397,"serial_number":"AL21-010","subject":null,"moderation_state":"published","external_url":null},{"nid":2520,"title":"[Control systems] Rockwell Automation security advisory","uuid":"1d97f9c9-6706-4b1c-95e5-fa72ac39690a","banner":null,"lang":"en","date_modified":"2021-06-16","date_modified_ts":"2021-06-16T17:43:55Z","date_created":"2021-06-16T17:43:37Z","summary":null,"body":["<article data-history-node-id=\"2520\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-285<br \/>\nDate: 16 June 2021<\/strong><\/p>\n\n<p>On 10 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>FactoryTalk Services Platform \u2013 version 6.11 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow security policy bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-161-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-161-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-161-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-20","alert_type":398,"serial_number":"AV21-285","subject":null,"moderation_state":"published","external_url":null},{"nid":2521,"title":"[Control systems] Automation Direct security advisory","uuid":"e366c327-ccde-4517-8440-e930316249e0","banner":null,"lang":"en","date_modified":"2021-06-16","date_modified_ts":"2021-06-16T17:45:42Z","date_created":"2021-06-16T17:45:42Z","summary":null,"body":["<article data-history-node-id=\"2521\" about=\"\/en\/alerts-advisories\/control-systems-automation-direct-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-286<br \/>\nDate: 16 June 2021<\/strong><\/p>\n\n<p>On 15 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>CLICK PLC CPU Modules - C0-1x CPUs with firmware versions prior to v3.00<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to log in as a currently or previously authenticated user or discover passwords for valid users.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-166-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-166-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-166-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-automation-direct-security-advisory","alert_type":398,"serial_number":"AV21-286","subject":null,"moderation_state":"published","external_url":null},{"nid":2522,"title":"[Control systems] ThroughTek security advisory","uuid":"ba8119ce-bbb7-495a-a1a9-a720205814e2","banner":null,"lang":"en","date_modified":"2021-06-16","date_modified_ts":"2021-06-16T17:47:55Z","date_created":"2021-06-16T17:47:55Z","summary":null,"body":["<article data-history-node-id=\"2522\" about=\"\/en\/alerts-advisories\/control-systems-throughtek-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-287<br \/>\nDate: 16 June 2021<\/strong><\/p>\n\n<p>On 15 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>P2P SDK\n\t<ul><li>version 3.1.5 and prior<\/li>\n\t\t<li>SDK versions with nossl tag<\/li>\n\t\t<li>device firmware that does not use AuthKey for IOTC connection<\/li>\n\t\t<li>device firmware using the AVAPI module without enabling DTLS mechanism<\/li>\n\t\t<li>device firmware using P2PTunnel or RDT module<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could permit unauthorized access to sensitive information, such as camera audio\/video feeds.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-166-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-166-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-166-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-throughtek-security-advisory","alert_type":398,"serial_number":"AV21-287","subject":null,"moderation_state":"published","external_url":null},{"nid":2525,"title":"[Control systems] Softing security advisory","uuid":"1f4a650a-9142-4456-ace2-76a7f7d889a9","banner":null,"lang":"en","date_modified":"2021-06-17","date_modified_ts":"2021-06-17T19:40:25Z","date_created":"2021-06-17T18:06:50Z","summary":null,"body":["<article data-history-node-id=\"2525\" about=\"\/en\/alerts-advisories\/control-systems-softing-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-288<br \/>\nDate: 17 June 2021<\/strong><\/p>\n\n<p>On 17 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>OPC UA C++ SDK - versions 5.59 to 5.64<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-168-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-168-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-168-02<\/a>\u00a0<br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-softing-security-advisory","alert_type":398,"serial_number":"AV21-288","subject":null,"moderation_state":"published","external_url":null},{"nid":2524,"title":"[Control systems] Advantech security advisory","uuid":"a7203c91-3343-4a4d-af89-f6d753f78687","banner":null,"lang":"en","date_modified":"2021-06-17","date_modified_ts":"2021-06-17T19:38:25Z","date_created":"2021-06-17T19:38:25Z","summary":null,"body":["<article data-history-node-id=\"2524\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-289<br \/>\nDate: 17 June 2021<\/strong><\/p>\n\n<p>On 17 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>WebAccess\/SCADA \u2013 version 9.0.1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to read files outside the intended directory or redirect a user to a malicious webpage.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-168-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-168-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-168-03<\/a>\u00a0<br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-17","alert_type":398,"serial_number":"AV21-289","subject":null,"moderation_state":"published","external_url":null},{"nid":2526,"title":"Google Chrome security advisory","uuid":"bc2a973b-2374-42b2-8f79-6c86ed207ca9","banner":null,"lang":"en","date_modified":"2021-06-18","date_modified_ts":"2021-06-18T20:05:38Z","date_created":"2021-06-18T20:05:38Z","summary":null,"body":["<article data-history-node-id=\"2526\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-59\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-290<br \/>\nDate: 18 June 2021<\/strong><\/p>\n\n<p>On 17 June 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 91.0.4472.114<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2021-30554 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop_17.html\">https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop_17.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-59","alert_type":396,"serial_number":"AV21-290","subject":null,"moderation_state":"published","external_url":null},{"nid":2527,"title":"IBM security advisory","uuid":"80694985-4688-452a-b280-3502b74acf2c","banner":null,"lang":"en","date_modified":"2021-06-21","date_modified_ts":"2021-06-21T14:39:01Z","date_created":"2021-06-21T14:39:01Z","summary":null,"body":["<article data-history-node-id=\"2527\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-53\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-291<br \/>\nDate: 21 June 2021<\/strong><\/p>\n\n<p>Between 14 and 20 June 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Control Center - version 6.2.0.0<\/li>\n\t<li>IBM Spectrum Protect Snapshot for VMware - versions 4.1.0.0 to 4.1.6.11<\/li>\n\t<li>IBM Spectrum Protect Backup-Archive Client - multiple versions<\/li>\n\t<li>IBM Spectrum Protect for Space Management - versions 8.1.7.0 to 8.1.11.0 (Linux) and 8.1.9.0 to 8.1.11.0 (AIX)<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - versions 8.1.0.0 to 8.1.11.0 (Linux and Windows) and 7.1.0.0 to 7.1.8.10 (Linux and Windows)<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - versions 8.1.0.0 to 8.1.11.0 (Windows) and 7.1.0.0 to 7.1.8.x (Windows)<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - versions 8.1.0.0 to 8.1.11.0 and 7.1.0.0 to 7.1.8.10<\/li>\n\t<li>IBM Spectrum Protect Client - versions 7.1.0.0 to 7.1.8.10<\/li>\n\t<li>IBM Security Identity Governance and Intelligence - versions 5.2.5 and 5.2.4<\/li>\n\t<li>IBM QRadar SIEM - multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-53","alert_type":396,"serial_number":"AV21-291","subject":null,"moderation_state":"published","external_url":null},{"nid":2528,"title":"[Control systems] ABB security advisory","uuid":"44b35d5e-f0fc-4ead-8f00-6e3f311cd6d0","banner":null,"lang":"en","date_modified":"2021-06-21","date_modified_ts":"2021-06-21T18:46:26Z","date_created":"2021-06-21T18:46:26Z","summary":null,"body":["<article data-history-node-id=\"2528\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-292<br \/>\nDate: 21 June 2021<\/strong><\/p>\n\n<p>On 21 June 2021 ABB published a Cyber Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automation Builder (AB) - version 2.4.1.1062 and prior<\/li>\n\t<li>Drive Application Builder (DAB) - version 1.1.1.631 and prior<\/li>\n\t<li>Virtual Drive - version 1.0.2.105 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to cause a denial-of-service condition or read data from heap memory.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ABB Cyber Security Advisory (3ADR010770)<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010770&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010770&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-15","alert_type":398,"serial_number":"AV21-292","subject":null,"moderation_state":"published","external_url":null},{"nid":2529,"title":"VMware security advisory","uuid":"01ff5f08-f34d-46f1-8126-5c2bbc5a4140","banner":null,"lang":"en","date_modified":"2021-06-22","date_modified_ts":"2021-06-22T16:19:20Z","date_created":"2021-06-22T16:19:20Z","summary":null,"body":["<article data-history-node-id=\"2529\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-42\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-293<br \/>\nDate: 22 June 2021<\/strong><\/p>\n\n<p>On 22 June 2021 VMware published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>VMware Carbon Black App Control \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation could allow an actor to gain administrative access to the product without having to authenticate.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0012)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0012.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0012.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-42","alert_type":396,"serial_number":"AV21-293","subject":null,"moderation_state":"published","external_url":null},{"nid":2530,"title":"VMware security advisory","uuid":"1cdcc1e2-133d-4772-8a29-805c0b3e01a9","banner":null,"lang":"en","date_modified":"2021-06-22","date_modified_ts":"2021-06-22T20:00:43Z","date_created":"2021-06-22T20:00:43Z","summary":null,"body":["<article data-history-node-id=\"2530\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-43\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-294<br \/>\nDate: 22 June 2021<\/strong><\/p>\n\n<p>On 22 June 2021 VMware published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>VMware Tools for Windows \u2013 version 11.x.y and prior<\/li>\n\t<li>VMRC for Windows \u2013 version 12.x<\/li>\n\t<li>VMware App Volumes \u2013 versions 2.x and 4<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow for local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0013)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0013.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0013.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-43","alert_type":396,"serial_number":"AV21-294","subject":null,"moderation_state":"published","external_url":null},{"nid":2532,"title":"[Control systems] Advantech security advisory","uuid":"d2acd6d9-c9c2-4522-8b24-f13b3f6c9870","banner":null,"lang":"en","date_modified":"2021-06-24","date_modified_ts":"2021-06-24T15:35:25Z","date_created":"2021-06-24T15:25:56Z","summary":null,"body":["<article data-history-node-id=\"2532\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-295<br \/>\nDate: 24 June 2021<\/strong><\/p>\n\n<p>On 22 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>WebAccess HMI Designer - version 2.1.9.95 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in memory corruption and code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-173-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-18","alert_type":398,"serial_number":"AV21-295","subject":null,"moderation_state":"published","external_url":null},{"nid":2531,"title":"Palo Alto Networks security advisory","uuid":"fe1cda72-c7d2-46a6-ac39-1fe68e4b1731","banner":null,"lang":"en","date_modified":"2021-06-24","date_modified_ts":"2021-06-24T15:31:07Z","date_created":"2021-06-24T15:29:12Z","summary":null,"body":["<article data-history-node-id=\"2531\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-296<br \/>\nDate: 24 June 2021<\/strong><\/p>\n\n<p>On 22 June 2021 Palo Alto Networks published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cortex XSOAR \u2013 multiple versions and builds<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote unauthenticated actor with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Palo Alto Networks Security Advisory<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3044\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3044<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-8","alert_type":396,"serial_number":"AV21-296","subject":null,"moderation_state":"published","external_url":null},{"nid":2533,"title":"[Control systems] CODESYS security advisory","uuid":"4d404803-5322-4154-96f9-0c45be0dc7b0","banner":null,"lang":"en","date_modified":"2021-06-24","date_modified_ts":"2021-06-24T15:38:35Z","date_created":"2021-06-24T15:38:35Z","summary":null,"body":["<article data-history-node-id=\"2533\" about=\"\/en\/alerts-advisories\/control-systems-codesys-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-297<br \/>\nDate: 24 June 2021<\/strong><\/p>\n\n<p>On 22 June 2021 ICS-CERT published multiple ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>CODESYS V2 web servers \u2013 versions prior to 1.1.9.20<\/li>\n\t<li>CODESYS Runtime Toolkit 32-bit full \u2013 versions prior to v2.4.7.55<\/li>\n\t<li>CODESYS PLCWinNT \u2013 versions prior to v2.4.7.55<\/li>\n\t<li>CODESYS V2 Runtime Toolkit \u2013 versions prior to 2.4.7.55 (Linux only)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-173-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-173-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-03<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-173-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-173-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-codesys-security-advisory","alert_type":398,"serial_number":"AV21-297","subject":null,"moderation_state":"published","external_url":null},{"nid":2534,"title":"Ubuntu security advisory","uuid":"18bc9de7-8fc4-4904-b3ac-a5007841789f","banner":null,"lang":"en","date_modified":"2021-06-24","date_modified_ts":"2021-06-24T15:41:53Z","date_created":"2021-06-24T15:41:53Z","summary":null,"body":["<article data-history-node-id=\"2534\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-298<br \/>\nDate: 24 June 2021<\/strong><\/p>\n\n<p>On 23 June 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service, access to sensitive information or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p>Note to Readers<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-15","alert_type":396,"serial_number":"AV21-298","subject":null,"moderation_state":"published","external_url":null},{"nid":2535,"title":"[Control systems] Philips security advisory","uuid":"4b1311c8-d907-4786-a189-62d1084a3ce0","banner":null,"lang":"en","date_modified":"2021-06-24","date_modified_ts":"2021-06-24T18:39:34Z","date_created":"2021-06-24T18:39:34Z","summary":null,"body":["<article data-history-node-id=\"2535\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-299<br \/>\nDate: 24 June 2021<\/strong><\/p>\n\n<p>On 24 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Interoperability Solution XDS - versions 2.5 to 3.11 and 2018-1 to 2021-1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-175-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-175-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-175-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-10","alert_type":398,"serial_number":"AV21-299","subject":null,"moderation_state":"published","external_url":null},{"nid":2536,"title":"[Control systems] FATEK Automation security advisory","uuid":"592196af-0fcd-4b88-b0b6-1eb5bf893b15","banner":null,"lang":"en","date_modified":"2021-06-24","date_modified_ts":"2021-06-24T18:42:24Z","date_created":"2021-06-24T18:42:24Z","summary":null,"body":["<article data-history-node-id=\"2536\" about=\"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-300<br \/>\nDate: 24 June 2021<\/strong><\/p>\n\n<p>On 24 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>WinProladder - version 3.30 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-175-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-175-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-175-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-0","alert_type":398,"serial_number":"AV21-300","subject":null,"moderation_state":"published","external_url":null},{"nid":2537,"title":"Google Chrome security advisory","uuid":"2370d78a-4500-4719-89ba-96200cf2bb29","banner":null,"lang":"en","date_modified":"2021-06-24","date_modified_ts":"2021-06-24T20:00:00Z","date_created":"2021-06-24T20:00:00Z","summary":null,"body":["<article data-history-node-id=\"2537\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-60\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-301<br \/>\nDate: 24 June 2021<\/strong><\/p>\n\n<p>On 24 June 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 91.0.4472.123\/.124<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop_24.html\">https:\/\/chromereleases.googleblog.com\/2021\/06\/stable-channel-update-for-desktop_24.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-60","alert_type":396,"serial_number":"AV21-301","subject":null,"moderation_state":"published","external_url":null},{"nid":2538,"title":"Dell security advisory","uuid":"086dad8b-6455-46df-87cc-fb554923e68c","banner":null,"lang":"en","date_modified":"2021-06-28","date_modified_ts":"2021-06-28T18:56:40Z","date_created":"2021-06-28T18:42:22Z","summary":null,"body":["<article data-history-node-id=\"2538\" about=\"\/en\/alerts-advisories\/dell-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-302<br \/>\nDate: 28 June 2021<\/strong><\/p>\n\n<p>On 24 June 2021 Dell published a Knowledge Base Article to address vulnerabilities affecting the following product:<\/p>\n\n<ul><li>Dell Client Platform \u2013 multiple versions and models\n\t<ul><li>BIOSConnect feature<\/li>\n\t\t<li>HTTPS Boot feature<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to cause a denial-of-service, tamper with HTTPS payloads, execute arbitrary code and bypass UEFI restrictions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\nDell Knowledge Base Article (000188682)<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000188682\/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000188682\/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-4","alert_type":396,"serial_number":"AV21-302","subject":null,"moderation_state":"published","external_url":null},{"nid":2539,"title":"IBM security advisory","uuid":"a126650c-0c33-4b20-8e58-0ed30051d2c3","banner":null,"lang":"en","date_modified":"2021-06-28","date_modified_ts":"2021-06-28T19:10:37Z","date_created":"2021-06-28T19:10:37Z","summary":null,"body":["<article data-history-node-id=\"2539\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-54\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-303<br \/>\nDate: 28 June 2021<\/strong><\/p>\n\n<p>Between 21 and 27 June 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Automation - versions 20.0.3-IF002 and 21.0.1<\/li>\n\t<li>IBM Spectrum Protect Backup-Archive Client \u2013 versions:\n\t<ul><li>8.1.0.0 to 8.1.11.0 (Macintosh and Windows)<\/li>\n\t\t<li>8.1.7.0 to 8.1.11.0 (Linux - web user interface only)<\/li>\n\t\t<li>8.1.9.0 to 8.1.11.0 (AIX - web user interface only)<\/li>\n\t\t<li>7.1.0.0 to 7.1.8.10 (Macintosh and Windows)<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Spectrum Protect for Space Management - versions 8.1.7.0 to 8.1.11.0 (Linux) and 8.1.9.0 to 8.1.11.0 (AIX)<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for VMware - versions 8.1.0.0 to 8.1.11.0 (Linux and Windows) and 7.1.0.0 to 7.1.8.10 (Linux and Windows)<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - versions 8.1.0.0 to 8.1.11.0 (Windows) and 7.1.0.0 to 7.1.8.x (Windows)<\/li>\n\t<li>IBM Enterprise Records \u2013 version 5.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-54","alert_type":396,"serial_number":"AV21-303","subject":null,"moderation_state":"published","external_url":null},{"nid":2540,"title":"Cisco security advisory","uuid":"da317bb7-81a5-47cb-9da1-95d3ead41b29","banner":null,"lang":"en","date_modified":"2021-06-29","date_modified_ts":"2021-06-29T14:58:12Z","date_created":"2021-06-29T14:58:12Z","summary":null,"body":["<article data-history-node-id=\"2540\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-84\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-304<br \/>\nDate: 29 June 2021<\/strong><\/p>\n\n<p>On 28 June 2021 Cisco updated a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Adaptive Security Appliance (ASA) Software \u2013 multiple versions<\/li>\n\t<li>Cisco Firepower Threat Defense (FTD) - multiple versions<\/li>\n<\/ul><p>Exploitation could allow the attacker to execute arbitrary script code in the context of the interface or allow the actor to access sensitive, browser-based information.<\/p>\n\n<p>Cisco has indicated it is aware that public exploit code exists for one of the vulnerabilities, and that the vulnerability is being actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-xss-multiple-FCB3vPZe#vp\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-xss-multiple-FCB3vPZe#vp<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-84","alert_type":396,"serial_number":"AV21-304","subject":null,"moderation_state":"published","external_url":null},{"nid":2541,"title":"[Control systems] Panasonic security advisory","uuid":"a3c0d369-39bb-422e-b01c-b447f984c620","banner":null,"lang":"en","date_modified":"2021-06-29","date_modified_ts":"2021-06-29T19:01:06Z","date_created":"2021-06-29T18:55:31Z","summary":null,"body":["<article data-history-node-id=\"2541\" about=\"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-305<br \/>\nDate: 29 June 2021<\/strong><\/p>\n\n<p>On 29 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>FPWIN Pro - version 7.5.1.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-180-03)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory-0","alert_type":398,"serial_number":"AV21-305","subject":null,"moderation_state":"published","external_url":null},{"nid":2542,"title":"[Control systems] Exacq Technologies security advisory","uuid":"d3737c32-a0fb-48a8-a9cc-7db185b807ce","banner":null,"lang":"en","date_modified":"2021-06-29","date_modified_ts":"2021-06-29T19:06:23Z","date_created":"2021-06-29T19:06:23Z","summary":null,"body":["<article data-history-node-id=\"2542\" about=\"\/en\/alerts-advisories\/control-systems-exacq-technologies-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-306<br \/>\nDate: 29 June 2021<\/strong><\/p>\n\n<p>On 29 June 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0exacqVision Web Service - version 21.03 and prior<\/li>\n\t<li>\u00a0exacqVision Enterprise Manager - version 20.12 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to send malicious requests on behalf of the victim.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-180-01)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-01<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-180-02)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-exacq-technologies-security-advisory-0","alert_type":398,"serial_number":"AV21-306","subject":null,"moderation_state":"published","external_url":null},{"nid":2543,"title":"[Control systems] AVEVA Software security advisory","uuid":"0f5bc798-83dd-44ac-a972-181041a1444a","banner":null,"lang":"en","date_modified":"2021-06-30","date_modified_ts":"2021-06-30T15:01:39Z","date_created":"2021-06-30T15:01:39Z","summary":null,"body":["<article data-history-node-id=\"2543\" about=\"\/en\/alerts-advisories\/control-systems-aveva-software-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-308<br \/>\nDate: 30 June 2021<\/strong><\/p>\n\n<p>On 29 June 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>\u00a0AVEVA System Platform - versions 2017 to 2020 R2 P01<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution with system privileges or cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-180-05)<\/p>\n\n<p><a href=\" https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-05\">\u00a0https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-05<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-software-security-advisory","alert_type":398,"serial_number":"AV21-308","subject":null,"moderation_state":"published","external_url":null},{"nid":2545,"title":"[Control systems] JTEKT security advisory","uuid":"690d6f0f-d558-4577-bd1b-e9458a201590","banner":null,"lang":"en","date_modified":"2021-06-30","date_modified_ts":"2021-06-30T15:30:15Z","date_created":"2021-06-30T15:07:38Z","summary":null,"body":["<article data-history-node-id=\"2545\" about=\"\/en\/alerts-advisories\/control-systems-jtekt-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-307<br \/>\nDate: 30 June 2021<\/strong><\/p>\n\n<p>On 29 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<p>Exploitation of this vulnerability could result in denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-180-06)<\/p>\n\n<ul><li>TOYOPUC PLC modules:\n\t<ul><li>PC10G-CPU - versions prior to 3.91<\/li>\n\t\t<li>2PORT-EFR - versions prior to 1.50<\/li>\n\t\t<li>PC10P-DP - versions prior to 1.50<\/li>\n\t\t<li>PC10P-DP-IO - versions prior to 1.50<\/li>\n\t\t<li>Nano 10GX - versions prior to 3.00<\/li>\n\t\t<li>Nano 2ET - versions prior to 2.40<\/li>\n\t\t<li>PC10PE - versions prior to 1.02<\/li>\n\t\t<li>PC10PE-16\/16P - versions prior to 1.02<\/li>\n\t\t<li>PC10E - versions prior to 1.12<\/li>\n\t\t<li>FL\/ET-T-V2H - versions prior to F2.8 E1.5<\/li>\n\t\t<li>PC10B - versions prior to 1.11<\/li>\n\t\t<li>PC10B-P - versions prior to 1.11<\/li>\n\t\t<li>Nano CPU - versions prior to 2.08<\/li>\n\t\t<li>PC10P - versions prior to 1.05<\/li>\n\t\t<li>PC10GE - versions prior to 1.04<\/li>\n\t\t<li>Plus CPU - versions prior to 3.11\u00a0\u00a0 \u00a0<\/li>\n\t\t<li>Plus EX - versions prior to 3.11<\/li>\n\t\t<li>Plus EX2 - versions prior to 3.11<\/li>\n\t\t<li>Plus EFR - versions prior to 3.11<\/li>\n\t\t<li>Plus EFR2 - versions prior to 3.11<\/li>\n\t\t<li>Plus 2P-EFR - versions prior to 3.11<\/li>\n\t\t<li>Plus BUS-EX - versions prior to 2.13<\/li>\n\t<\/ul><\/li>\n<\/ul><p>ICS Advisory (ICSA-21-180-04)<\/p>\n\n<p><a href=\" https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-04\">\u00a0https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-jtekt-security-advisory-0","alert_type":398,"serial_number":"AV21-307","subject":null,"moderation_state":"published","external_url":null},{"nid":2544,"title":"[Control systems] Claroty security advisory","uuid":"0c22cc13-411e-4639-8d9b-33e4065fd377","banner":null,"lang":"en","date_modified":"2021-06-30","date_modified_ts":"2021-06-30T15:21:35Z","date_created":"2021-06-30T15:15:53Z","summary":null,"body":["<article data-history-node-id=\"2544\" about=\"\/en\/alerts-advisories\/control-systems-claroty-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-309<br \/>\nDate: 30 June 2021<\/strong><\/p>\n\n<p>On 29 June 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Secure Remote Access (SRA) Site - versions 3.0 to 3.2<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a\u00a0\u00a0 local user to bypass the application\u2019s access controls.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-180-06)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-06\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-180-06<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-claroty-security-advisory","alert_type":398,"serial_number":"AV21-309","subject":null,"moderation_state":"published","external_url":null},{"nid":2555,"title":"Windows Print Spooler Vulnerability Remains Unpatched \u2013 update 3","uuid":"dfc7403e-ae83-44d2-8c7d-295c606e0656","banner":null,"lang":"en","date_modified":"2021-07-08","date_modified_ts":"2021-07-08T13:58:37Z","date_created":"2021-07-01T01:13:44Z","summary":null,"body":["<article data-history-node-id=\"2555\" about=\"\/en\/alerts-advisories\/windows-print-spooler-vulnerability-remains-unpatched\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-011 UPDATE 3<br \/>\nDate: 30 June 2021<br \/>\nUpdated: 07 July 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.\u00a0 The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>On 29 June 2021, a proof-of-concept (POC) was released for an unpatched vulnerability in the Windows Print Spooler, colloquially named PrintNightmare.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>On 29 June 2021, a proof-of-concept (POC) was released for an unpatched vulnerability in the Windows Print Spooler, colloquially named PrintNightmare. Several more POCs have been released since. They have demonstrated that exploiting this vulnerability can be done remotely by an actor with valid credentials and allows them to run code with SYSTEM-level privileges [<a href=\" https:\/\/www.rapid7.com\/blog\/post\/2021\/06\/30\/cve-2021-1675-printnightmare-patch-does-not-remediate-vulnerability\/\">1<\/a>].<\/p>\n\n<p>A comprehensive list of affected products is not yet available. However, as this vulnerability is within the same function as CVE-2021-1675 [<a href=\" https:\/\/www.rapid7.com\/blog\/post\/2021\/06\/30\/cve-2021-1675-printnightmare-patch-does-not-remediate-vulnerability\/\">1<\/a>] [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-1675\">2<\/a>], Cyber Centre assesses that it may impact the same products, namely:<\/p>\n\n<ul><li>Windows Server 2019, 2016, 2012, 2008, 2004 (Server Core installation), 20H2 (Server Core installation)<\/li>\n\t<li>Windows 10, 8.1, RT 8.1, 7<\/li>\n<\/ul><h2>MITIGATION<\/h2>\n\n<p>Currently the only known mitigation is to disable the Print Spooler service, which will impede the ability to print. Refer to Microsoft\u2019s security guidelines when disabling print spoolers on domain controllers and Active Directory systems [<a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/security\/windows-services\/security-guidelines-for-disabling-system-services-in-windows-server#print-spooler\">3<\/a>] [<a href=\"https:\/\/docs.microsoft.com\/en-us\/defender-for-identity\/cas-isp-print-spooler\">4<\/a>].<\/p>\n\n<p><strong>UPDATE 1<\/strong><br \/>\nOn 1 July 2021, Microsoft assigned CVE-2021-34527 [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34527\">5<\/a>] to the PrintNightmare vulnerability, and updated its guidance to provide another workaround, which is to disable inbound remote printing through Group Policy. Microsoft has indicated that the page will continue to be updated as more details are discovered.<\/p>\n\n<p><strong>UPDATE 2<\/strong><br \/>\nOn 6 July 2021, Microsoft released an out-of-band security update for several versions of Windows to address CVE-2021-34527 <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34527\">[5]<\/a>. Please note that updates for Windows 10 version 1607, Windows Server 2016, or Windows Server 2012 have not yet been released <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34527\">[5]<\/a>.<\/p>\n\n<p><strong>UPDATE 3<\/strong><br \/>\nOn 7 July 2021, Microsoft released an out-of-band security update for Windows 10 version 1607, Windows Server 2016, and Windows Server 2012. All previously noted impacted versions of Windows now have a security update available to address CVE-2021-34527. The Cyber Centre encourages users and administrators to apply the necessary updates and follow hardening guidance related to installation of new print drivers [<a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5005010-restricting-installation-of-new-printer-drivers-after-applying-the-july-6-2021-updates-31b91c02-05bc-4ada-a7ea-183b129578a7\">6<\/a>] and Point and Print [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34527\">5<\/a>].<\/p>\n\n<p>\u00a0<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] Rapid7 (PrintNightmare) Patch Does Not Remediate Vulnerability<br \/><a href=\"https:\/\/www.rapid7.com\/blog\/post\/2021\/06\/30\/cve-2021-1675-printnightmare-patch-does-not-remediate-vulnerability\/\">https:\/\/www.rapid7.com\/blog\/post\/2021\/06\/30\/cve-2021-1675-printnightmare-patch-does-not-remediate-vulnerability\/<\/a><\/p>\n\n<p>[2] Windows Print Spooler Remote Code Execution Vulnerability (CVE-2021-1675)<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-1675\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-1675<\/a><\/p>\n\n<p>[3] Microsoft Security Guidelines for Disabling System Services in Windows Server<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/security\/windows-services\/security-guidelines-for-disabling-system-services-in-windows-server#print-spooler\">https:\/\/docs.microsoft.com\/en-us\/windows-server\/security\/windows-services\/security-guidelines-for-disabling-system-services-in-windows-server#print-spooler<\/a><\/p>\n\n<p>[4] Security assessment: Domain controllers with Print spooler service available<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/defender-for-identity\/cas-isp-print-spooler\">https:\/\/docs.microsoft.com\/en-us\/defender-for-identity\/cas-isp-print-spooler<\/a><\/p>\n\n<p>[5] Windows Print Spooler Remote Code Execution Vulnerability (CVE-2021-34527)<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34527\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34527<\/a><\/p>\n\n<p>[6] KB5005010: Restricting installation of new printer drivers after applying the July 6, 2021 updates<br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5005010-restricting-installation-of-new-printer-drivers-after-applying-the-july-6-2021-updates-31b91c02-05bc-4ada-a7ea-183b129578a7\">https:\/\/support.microsoft.com\/en-us\/topic\/kb5005010-restricting-installation-of-new-printer-drivers-after-applying-the-july-6-2021-updates-31b91c02-05bc-4ada-a7ea-183b129578a7<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><br \/>\nThe Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/windows-print-spooler-vulnerability-remains-unpatched","alert_type":397,"serial_number":"AL21-011","subject":null,"moderation_state":"published","external_url":null},{"nid":2546,"title":"APT Actor Brute Force Campaign (International Partners)","uuid":"7d21e194-4795-4d2f-9dc0-a58107543484","banner":null,"lang":"en","date_modified":"2021-07-02","date_modified_ts":"2021-07-02T18:29:57Z","date_created":"2021-07-02T18:19:06Z","summary":null,"body":["<article data-history-node-id=\"2546\" about=\"\/en\/alerts-advisories\/apt-actor-brute-force-campaign-international-partners\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-012\n  <br \/>\n  Date: 02 July 2021<\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>PURPOSE\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>OVERVIEW\n<\/h2>\n<p>The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), the UK\u2019s National Cyber Security Centre (NCSC), and Federal Bureau of Investigation (FBI) issued a Joint Cybersecurity Advisory [<a href=\"https:\/\/media.defense.gov\/2021\/Jul\/01\/2002753896\/-1\/-1\/1\/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF\">1<\/a>] detailing a global brute force campaign to compromise enterprise and cloud environments by advanced persistent threat (APT) actors.\n<\/p>\n<h2>ASSESSMENT\n<\/h2>\n<p>On 01 July 2021, the NSA, CISA, NCSC, and FBI issued a Joint Cybersecurity Advisory [<a href=\"https:\/\/media.defense.gov\/2021\/Jul\/01\/2002753896\/-1\/-1\/1\/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF\">1<\/a>], drawing attention to an active campaign being carried out to gain access to enterprise and cloud environments of government and private sector targets.\n<\/p>\n<p>The campaign leverages brute force techniques for access attempts against targeted organizations. Upon obtaining credentials, the APT exploits various other known vulnerabilities to gain further access and move laterally through the target network [<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/07\/01\/nsa-cisa-ncsc-fbi-joint-cybersecurity-advisory-russian-gru-brute\">2<\/a>]. The Joint Advisory states that the credentials are used for various malicious purposes.\n<\/p>\n<p>The Cybersecurity Advisory highlights the following vulnerabilities being exploited once credentials had been obtained, however other publicly known vulnerabilities or techniques may be in use:\n<\/p>\n<ul><li>CVE 2020-0688 Microsoft Exchange [<a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-exchange-validation-key-remote-code-execution-vulnerability\">3<\/a>]<\/li>\n  <li>CVE 2020-17144 Microsoft Exchange [<a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-december-2020-monthly-rollup\">4<\/a>]<\/li>\n<\/ul><p>The Cyber Centre is highlighting this Advisory, as it provides important information to system owners and operators responsible for defending their systems and networks from cyber threats.\n<\/p>\n<p>There are software updates and mitigations for the vulnerabilities described above. See past reporting by the Cyber Centre and partners for more details.\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the My Cyber Portal (<a href=\"https:\/\/cyber.gc.ca\/en\/incident-management\">https:\/\/cyber.gc.ca\/en\/incident-management<\/a>), contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>[1] APT Actors Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments (NSA\/CISA\/NCSC\/FBI)\n  <br \/><a href=\"https:\/\/media.defense.gov\/2021\/Jul\/01\/2002753896\/-1\/-1\/1\/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF\">https:\/\/media.defense.gov\/2021\/Jul\/01\/2002753896\/-1\/-1\/1\/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF<\/a>\n<\/p>\n<p>[2] NSA-CISA-NCSC-FBI Joint Cybersecurity Advisory on APT Brute Force Campaign\n  <br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/07\/01\/nsa-cisa-ncsc-fbi-joint-cybersecurity-advisory-russian-gru-brute\">https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/07\/01\/nsa-cisa-ncsc-fbi-joint-cybersecurity-advisory-russian-gru-brute<\/a>\n<\/p>\n<p>[3] Microsoft Exchange Validation Key Remote Code Execution Vulnerability\n  <br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-exchange-validation-key-remote-code-execution-vulnerability\">https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-exchange-validation-key-remote-code-execution-vulnerability<\/a>\n<\/p>\n<p>[4] Microsoft Security Advisory \u2013 December 2020 Monthly Rollup\n  <br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-december-2020-monthly-rollup\">https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-december-2020-monthly-rollup<\/a>\n  <br \/><br \/><strong>NOTE TO READERS<\/strong>\n<\/p>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apt-actor-brute-force-campaign-international-partners","alert_type":397,"serial_number":"AL21-012","subject":null,"moderation_state":"published","external_url":null},{"nid":2547,"title":"[Control systems] Bachmann Electronic security advisory","uuid":"409fdd0a-dac4-405f-b9d2-c499c0307a9d","banner":null,"lang":"en","date_modified":"2021-07-02","date_modified_ts":"2021-07-02T19:55:50Z","date_created":"2021-07-02T19:55:50Z","summary":null,"body":["<article data-history-node-id=\"2547\" about=\"\/en\/alerts-advisories\/control-systems-bachmann-electronic-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-310<br \/>\nDate: 2 July 2021<\/strong><\/p>\n\n<p>On 1 July 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>M-Base Operating Systems and Middleware \u2013 version MSYS v1.06.14 and later<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in the disclosure of credential information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update if available.<\/p>\n\n<p>ICS Advisory (ICSA-21-026-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-026-01-0\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-026-01-0<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bachmann-electronic-security-advisory","alert_type":398,"serial_number":"AV21-310","subject":null,"moderation_state":"published","external_url":null},{"nid":2548,"title":"[Control systems] Delta Electronics security advisory","uuid":"d24c2d78-dac2-407f-bde3-e500cf4b59ce","banner":null,"lang":"en","date_modified":"2021-07-02","date_modified_ts":"2021-07-02T20:00:59Z","date_created":"2021-07-02T20:00:59Z","summary":null,"body":["<article data-history-node-id=\"2548\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-311<br \/>\nDate: 02 July 2021<\/strong><\/p>\n\n<p>On 1 July 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DOPSoft \u2013 version 4.0.10.17 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-182-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-03<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-7","alert_type":398,"serial_number":"AV21-311","subject":null,"moderation_state":"published","external_url":null},{"nid":2549,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"088049a5-b2e2-4482-815f-90ff0f7f4fa5","banner":null,"lang":"en","date_modified":"2021-07-05","date_modified_ts":"2021-07-05T19:11:16Z","date_created":"2021-07-05T19:11:16Z","summary":null,"body":["<article data-history-node-id=\"2549\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-312<br \/>\nDate: 5 July 2021<\/strong><\/p>\n\n<p>On 1 July 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>\n\t<p>Air Conditioning System\/Centralized Controllers: \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/p>\n\n\t<ul><li>\n\t\t<p>G-50A - versions 2.50 to 3.35<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>GB-50A - versions 2.50 to 3.35<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>AG-150A-A - version 3.20 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>AG-150A-J \u2013 version 3.20 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>GB-50ADA-A - version 3.20 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>GB-50ADA-J - version 3.20 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>EB-50GU-A - version 7.09 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>EB-50GU-J - version 7.09 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>AE-200A - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>AE-200E - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>AE-50A - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>AE-50E - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>EW-50A - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>EW-50E - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>TE-200A - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>TE-50A - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>TW-50A - version 7.93 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>CMS-RMD-J - version 1.30 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>G-50A - version 3.35 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>GB-50A - version 3.35 and prior<\/p>\n\t\t<\/li>\n\t\t<li>\n\t\t<p>GB-24A - version 9.11 and prior<\/p>\n\t\t<\/li>\n\t<\/ul><\/li>\n\t<li>\n\t<p>Air Conditioning System\/Expansion Controller: \u00a0<\/p>\n\n\t<ul><li>\n\t\t<p>PAC-YG50ECA - version 2.20 and prior<\/p>\n\t\t<\/li>\n\t<\/ul><\/li>\n\t<li>\n\t<p>Air Conditioning System\/BM adapter: \u00a0\u00a0\u00a0<\/p>\n\n\t<ul><li>\n\t\t<p>BAC-HD150 - version 2.21 and prior<\/p>\n\t\t<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to denial-of-service or information disclosure for the purpose of system tampering.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<p>ICS Advisory (ICSA-21-182-04)<br \/>\n\u00a0<a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-04<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-182-05)<br \/>\n\u00a0<a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-05<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-17","alert_type":398,"serial_number":"AV21-312","subject":null,"moderation_state":"published","external_url":null},{"nid":2573,"title":"[Control systems] Johnson Controls security advisory","uuid":"fc189f77-62a4-4009-ae67-834deebe0d01","banner":null,"lang":"en","date_modified":"2021-07-05","date_modified_ts":"2021-07-05T19:14:41Z","date_created":"2021-07-05T19:14:20Z","summary":null,"body":["<article data-history-node-id=\"2573\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-313<\/strong><br \/><strong>Date: 5 July 2021<\/strong><\/p>\n\n<p>On 1 July 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>C-CURE 9000 \u2013 versions prior to 2.8<\/li>\n\t<li>Facility Explorer SNC Series Supervisory Controller - version 11<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow the remote execution of lower privileged programs, or the unintended modification of system files by an authenticated user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-182-02)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-02<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-182-01)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-182-01<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-8","alert_type":398,"serial_number":"AV21-313","subject":null,"moderation_state":"published","external_url":null},{"nid":2565,"title":"Supply chain enabled ransomware activity affecting multiple managed service providers \u2013 update 1","uuid":"91627745-dda1-4574-a1ca-229191b384f1","banner":null,"lang":"en","date_modified":"2021-07-13","date_modified_ts":"2021-07-13T12:54:41Z","date_created":"2021-07-05T20:15:00Z","summary":null,"body":["<article data-history-node-id=\"2565\" about=\"\/en\/alerts-advisories\/supply-chain-enabled-ransomware-activity-affecting-multiple-managed-service-providers\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-013 UPDATE 1<br \/>\nDate: 5 July 2021<br \/>\nUpdated: 12 July 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") seeks information to assess the impact in Canada, and to help Canadian organizations respond to this malicious activity. Should activity matching the content of this Alert be discovered, recipients are encouraged to report this to the Cyber Centre via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>, or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>). The Cyber Centre also strongly recommends that organizations report malicious activity related to this alert to their local police of jurisdiction.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>The Cyber Centre is aware of open-source reporting [<a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/advisories\/kaseya-management-software-being-used-to-deploy-ransomware\/\">1<\/a>][<a href=\" https:\/\/www.reddit.com\/r\/msp\/comments\/ocggbv\/crticial_ransomware_incident_in_progress\/\">2<\/a>] of large scale REvil (also known as Sodinokibi) ransomware activity affecting multiple managed service providers (MSPs) that use Kaseya VSA, a remote monitoring and management platform [<a href=\"https:\/\/www.kaseya.com\/potential-attack-on-kaseya-vsa\">3<\/a>].<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>On 2 July 2021 researchers reported ransomware dropped to a working directory of multiple on-premises servers running Kaseya VSA, a remote monitoring and management platform commonly used by MSPs. By injecting malicious code into the products and then leveraging its native functions, actors have been able to deploy ransomware at scale across MSPs to their hosted organizations.<\/p>\n\n<p>VSA is available in both an on-premises and a software-as-a-service (SaaS) model. The vendor has disabled the SaaS and will reenable it pending remediation. The company has indicated that the release of patches for on-premises VSA servers will follow restoral of the SaaS offering.<\/p>\n\n<p>The activity has affected approximately 30 MSPs [<a href=\" https:\/\/www.reddit.com\/r\/msp\/comments\/ocggbv\/crticial_ransomware_incident_in_progress\/\">2<\/a>], encrypting files of more than one-thousand businesses. Impact has been reported in multiple countries including Canada.<\/p>\n\n<h2>MITIGATION<\/h2>\n\n<p>For Managed Service PROVIDERS:<\/p>\n\n<ul><li>All On-Premises VSA Servers should continue to remain offline [<a href=\":\/\/www.kaseya.com\/potential-attack-on-kaseya-vsa\">3<\/a>] until further instructions are provided by Kaseya about when it is safe to restore operations.<\/li>\n\t<li>The Cyber Centre recommends that MSPs download the Kaseya VSA Detection Tool. [<a href=\"https:\/\/kaseya.app.box.com\/s\/0ysvgss7w48nxh8k1xt7fqhbcjxhas40\">4<\/a>] The tool analyzes a system (either VSA server or managed endpoint) and determines whether any indicators of compromise (IoC) are present.<\/li>\n\t<li>Require multi-factor authentication (MFA) on all accounts controlled by the organization, and where possible, for customer-facing services.<\/li>\n\t<li>Implement allow-listing to limit communication with remote monitoring and management (RMM) capabilities to known IP address pairs; and\/or<\/li>\n\t<li>Place administrative interfaces of RMM behind a virtual private network (VPN) or a firewall on a dedicated administrative network.<\/li>\n\t<li>Monitor Kaseya\u2019s dedicated web page for the timing of patches addressing the compromise for on-premises customers. [<a href=\"https:\/\/www.kaseya.com\/potential-attack-on-kaseya-vsa\">3<\/a>]<\/li>\n<\/ul><p>For Managed Service CUSTOMERS:<\/p>\n\n<p>If affected by this activity, take immediate action to implement the following cybersecurity best practices. Note: these actions are especially important for MSP customers who do not currently have their RMM service running due to the Kaseya incident:<\/p>\n\n<ul><li>Ensure backups are current and stored in an easily retrievable location that is air-gapped from the organizational network.<\/li>\n\t<li>Where possible, revert to a manual patch management process that follows vendor remediation guidance, including the installation of new patches as soon as they become available.<\/li>\n\t<li>Require multi-factor authentication.<\/li>\n\t<li>Follow the principle of least privilege on key network resources admin accounts.<\/li>\n<\/ul><p>For advice and guidance on recovering from a ransomware incident please refer to the Cyber Centre\u2019s publication <a href=\"\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099\">Ransomware: How to Prevent and Recover (ITSAP.00.099)<\/a>.[5]<\/p>\n\n<h2>INDICATORS<\/h2>\n\n<p>The Cyber Centre is aware of open-source indicators for this ongoing incident and is providing them as-is for awareness [<a href=\"https:\/\/community.sophos.com\/b\/security-blog\/posts\/active-ransomware-attack-on-kaseya-customers\">6<\/a>][<a href=\"https:\/\/github.com\/pgl\/kaseya-revil-cnc-domains\/blob\/main\/revil-kaseya-cnc-domains.txt\">7<\/a>]. The Cyber Centre has not verified the technical details described in this disclosure. It is recommended to verify business services requirements before implementing.<\/p>\n\n<p><strong>UPDATE 1<\/strong><\/p>\n\n<p>On 11 July 2021, Kaseya updated its website [<a href=\"https:\/\/www.kaseya.com\/potential-attack-on-kaseya-vsa\">3<\/a>] to indicate that it had released a patch [<a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403785889041\">8<\/a>] to VSA on-premises customers and had begun to deploy the patch [<a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403785889041\">8<\/a>] to VSA SaaS Infrastructure prior to its stated target of 1600 EDT on 11 July 2021. On 12 July 2021, the company stated that all SaaS customers' service had been restored, and that customers with on-premises deployments were in the process of applying the patch.<\/p>\n\n<p>The Cyber Centre is also aware of spam e-mails containing attachments and links to malware in the guise of \u2018patches\u2019 for Kaseya VSA. The malware reportedly [<a href=\"https:\/\/twitter.com\/MBThreatIntel\/status\/1412518446013812737\">9<\/a>] includes components of Cobalt Strike, a legitimate post-compromise toolkit for penetration testing that is often employed by malicious actors and enables a \u2018back door\u2019 functionality on an affected host. Kaseya has stated [<a href=\"https:\/\/www.kaseya.com\/potential-attack-on-kaseya-vsa\">3<\/a>] that it is not having its partners contact customers, that any contact from apparent partners is likely fraudulent, and that e-mails from Kaseya itself would not contain attachments or links.<\/p>\n\n<p>Kaseya has provided a hardening guide and start up runbook for the SaaS [<a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403709476369\">10<\/a>][<a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403622421009-VSA-SaaS-Best-Practices\">11<\/a>] and on-premises [<a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403709150993incident-response\">12<\/a>][<a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403760102417\">13<\/a>] offerings.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] <a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/advisories\/kaseya-management-software-being-used-to-deploy-ransomware\/\">Kaseya management software being used to deploy ransomware<\/a><\/p>\n\n<p>[2] <a href=\"https:\/\/www.reddit.com\/r\/msp\/comments\/ocggbv\/crticial_ransomware_incident_in_progress\/\">Reddit post from Huntress Labs<\/a><\/p>\n\n<p>[3] <a href=\"https:\/\/www.kaseya.com\/potential-attack-on-kaseya-vsa\">Kaseya\u2019s updates related to the incident<\/a><\/p>\n\n<p>[4] <a href=\"https:\/\/kaseya.app.box.com\/s\/0ysvgss7w48nxh8k1xt7fqhbcjxhas40\">Kaseya\u2019s detections tool<\/a><\/p>\n\n<p>[5] <a href=\"\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099\">Ransomware: How to Prevent and Recover (ITSAP.00.099)<\/a><\/p>\n\n<p>[6] <a href=\"https:\/\/community.sophos.com\/b\/security-blog\/posts\/active-ransomware-attack-on-kaseya-customers\">Sophos Kaseya VSA Supply-Chain Ransomware Attack<\/a><\/p>\n\n<p>[7] <a href=\"https:\/\/github.com\/pgl\/kaseya-revil-cnc-domains\/blob\/main\/revil-kaseya-cnc-domains.txt\">REvil Kaseya Attack CNCs<\/a><\/p>\n\n<p>[8] <a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403785889041\">VSA SaaS and On-Premise Release Notes<\/a><\/p>\n\n<p>[9] <a href=\"https:\/\/twitter.com\/MBThreatIntel\/status\/1412518446013812737\">Malwarebytes Threat Intelligence<\/a><\/p>\n\n<p>[10] <a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403709476369\">VSA SaaS Startup Runbook<\/a><\/p>\n\n<p>[11] <a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403622421009-VSA-SaaS-Best-Practices\">VSA SaaS Hardening and Best Practice Guide <\/a><\/p>\n\n<p>[12] <a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403760102417\">On Premises Startup Runbook<\/a><\/p>\n\n<p>[13] <a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403760102417\">VSA On-Premise Hardening and Practice Guide<\/a><\/p>\n\n<p><a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403760102417\">https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403760102417<\/a><\/p>\n\n<p><br \/><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security, and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/supply-chain-enabled-ransomware-activity-affecting-multiple-managed-service-providers","alert_type":397,"serial_number":"AL21-013","subject":null,"moderation_state":"published","external_url":null},{"nid":2550,"title":"IBM security advisory","uuid":"8f2096ac-6737-4b14-9969-d4a9d43446bf","banner":null,"lang":"en","date_modified":"2021-07-06","date_modified_ts":"2021-07-06T13:36:00Z","date_created":"2021-07-06T13:35:19Z","summary":null,"body":["<article data-history-node-id=\"2550\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-55\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-314<br \/>\nDate: 6 July 2021<\/strong><\/p>\n\n<p>Between 28 June and 4 July 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Watson Discovery for Cloud Pak for Data \u2013 versions 2.0.0 to 2.2.1<\/li>\n\t<li>IBM Cognos Analytics - versions 11.0 and 11.1<\/li>\n\t<li>IBM Spectrum Protect Plus \u2013 versions 10.1.0 to 10.1.8<\/li>\n\t<li>IBM Spectrum Protect Plus Microsoft File Systems backup and restore - versions 10.1.6 to 10.1.8<\/li>\n\t<li>IBM Rational ClearQuest \u2013 versions 9.0, 9.0.1, 9.0.2 and 9.1<\/li>\n\t<li>IBM Rational ClearCase \u2013 versions 8.0.0, 8.0.1, 9.0, 9.0.1, 9.0.2 and 9.1<\/li>\n\t<li>IBM SDK Java Technology Edition in Jazz Team Server \u2013 multiple server based applications and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-55","alert_type":396,"serial_number":"AV21-314","subject":null,"moderation_state":"published","external_url":null},{"nid":2895,"title":"[Control systems] Moxa security advisory","uuid":"4ebb2a17-8822-4324-8602-275d96c9c5ad","banner":null,"lang":"en","date_modified":"2021-12-24","date_modified_ts":"2021-12-24T13:46:13Z","date_created":"2021-07-06T19:37:56Z","summary":null,"body":["<article data-history-node-id=\"2895\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"MsoNormal\" style=\"line-height:115%\"><b><span style=\"mso-ascii-font-family:&#10;Calibri;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;&#10;mso-bidi-font-family:Calibri\">Number: AV21-315<\/span><\/b><br \/><b><span style=\"mso-ascii-font-family:Calibri;mso-fareast-font-family:Calibri;&#10;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri\">Date: 6 July 2021<\/span><\/b><o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\" style=\"line-height:115%\"><b><span style=\"font-size:14.0pt;&#10;line-height:115%;mso-ascii-font-family:Calibri;mso-fareast-font-family:Calibri;&#10;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri\"><o:p><\/o:p><\/span><\/b><span style=\"mso-ascii-font-family:&#10;Calibri;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;&#10;mso-bidi-font-family:Calibri\">On 6 July 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<o:p><\/o:p><\/span><\/p>\n\n<ul><li class=\"MsoListParagraph\" style=\"text-indent: -0.25in; line-height: 115%;\"><!--[if !supportLists]--><span style=\"font-family:Symbol;&#10;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol\"><span style=\"mso-list:Ignore\"><span style=\"font:7.0pt &quot;Times New Roman&quot;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><\/span><\/span><!--[endif]--><span style=\"mso-fareast-font-family:&quot;MS Mincho&quot;;&#10;mso-fareast-theme-font:minor-fareast\">\u00a0 NPort IAW5000A-I\/O Series - version 2.2 and prior<\/span><span style=\"font-family:&quot;MS Mincho&quot;;mso-ascii-theme-font:minor-fareast;&#10;mso-fareast-theme-font:minor-fareast;mso-hansi-theme-font:minor-fareast;&#10;mso-bidi-font-family:&quot;MS Mincho&quot;;mso-bidi-theme-font:minor-fareast\"><o:p><\/o:p><\/span><\/li>\n<\/ul><p class=\"MsoNormal\" style=\"line-height:115%\"><span style=\"mso-ascii-font-family:&#10;Calibri;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;&#10;mso-bidi-font-family:Calibri\">Exploitation of these vulnerabilities could lead to denial-of-service or remote code execution.<\/span><o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\" style=\"line-height:115%\"><span style=\"mso-ascii-font-family:&#10;Calibri;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;&#10;mso-bidi-font-family:Calibri\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/span><o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\" style=\"line-height:115%\"><span style=\"mso-ascii-font-family:&#10;Calibri;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;&#10;mso-bidi-font-family:Calibri\">ICS Advisory (ICSA-21-187-01)<\/span><br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-187-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-187-01<\/a> <o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\" style=\"line-height:115%\"><b><span style=\"font-size:14.0pt;&#10;line-height:115%;mso-ascii-font-family:Calibri;mso-fareast-font-family:Calibri;&#10;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri\">Note to Readers<\/span><\/b><o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\" style=\"line-height:115%\"><span style=\"mso-ascii-font-family:&#10;Calibri;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;&#10;mso-bidi-font-family:Calibri\">The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.<span style=\"mso-spacerun:yes\">\u00a0 <\/span>We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/span><o:p><\/o:p><\/p>\n\n<p><span lang=\"FR-CA\" style=\"mso-ascii-font-family:&#10;Calibri;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;&#10;mso-bidi-font-family:Calibri;mso-ansi-language:FR-CA\" xml:lang=\"FR-CA\" xml:lang=\"FR-CA\"><\/span><span lang=\"FR-CA\" style=\"mso-ansi-language:&#10;FR-CA\" xml:lang=\"FR-CA\" xml:lang=\"FR-CA\"><o:p><\/o:p><\/span><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-3","alert_type":398,"serial_number":"AV21-315","subject":null,"moderation_state":"published","external_url":null},{"nid":2552,"title":"[Control systems] Philips security advisory","uuid":"b0c2cbeb-6472-49e0-9f7d-2645f6ad0b43","banner":null,"lang":"en","date_modified":"2021-07-07","date_modified_ts":"2021-07-07T12:04:14Z","date_created":"2021-07-07T12:03:50Z","summary":null,"body":["<article data-history-node-id=\"2552\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-316<br \/>\nDate: 7 July 2021<\/strong><\/p>\n\n<p>On 6 July 2021 ICS-CERT published an ICSMA Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Vue PACS - version 12.2.x.x and prior<\/li>\n\t<li>Vue MyVue - version 12.2.x.x and prior<\/li>\n\t<li>Vue Speech - version 12.2.x.x and prior<\/li>\n\t<li>Vue Motion - version 12.2.1.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICSMA Advisory (ICSMA-21-187-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-187-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-187-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-11","alert_type":398,"serial_number":"AV21-316","subject":null,"moderation_state":"published","external_url":null},{"nid":2551,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"400e71f8-5bc8-426a-aa36-b6944193dce3","banner":null,"lang":"en","date_modified":"2021-07-07","date_modified_ts":"2021-07-07T12:08:54Z","date_created":"2021-07-07T12:08:54Z","summary":null,"body":["<article data-history-node-id=\"2551\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-317<br \/>\nDate: 7 July 2021<\/strong><\/p>\n\n<p>On 5 July 2021 B&amp;R Industrial Automation published a Cyber Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>X20IF10E3-1 - versions prior to 1.8<\/li>\n\t<li>X20cIF10E3-1 - versions prior to 1.8<\/li>\n\t<li>5ACPCI.XPNS-00 - versions 1.5.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to cause a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>B&amp;R Industrial Automation Cyber Security Advisory (#07\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1622986485635-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1622986485635-en-original-1.0.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-3","alert_type":398,"serial_number":"AV21-317","subject":null,"moderation_state":"published","external_url":null},{"nid":2553,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"fc2c3f4b-931c-4c51-afea-bf7d9870b87c","banner":null,"lang":"en","date_modified":"2021-07-07","date_modified_ts":"2021-07-07T18:57:39Z","date_created":"2021-07-07T17:55:32Z","summary":null,"body":["<article data-history-node-id=\"2553\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-318<br \/>\nDate: 7 July 2021<\/strong><\/p>\n\n<p>On 5 July 2021 B&amp;R Industrial Automation published a Cyber Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>X20 EthernetIP Adapters:\n\t<ul><li>X20IF10D3-1 - versions prior to 1.5.0.0<\/li>\n\t\t<li>X20cIF10D3-1 - versions prior to 1.5.0.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to cause a denial-of-service condition or execute remote code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>B&amp;R Industrial Automation Cyber Security Advisory (#06\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1622986485562-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1622986485562-en-original-1.0.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-4","alert_type":398,"serial_number":"AV21-318","subject":null,"moderation_state":"published","external_url":null},{"nid":2554,"title":"Cisco security advisory","uuid":"bc001d7b-6f46-4a0a-b1f9-cb7c36024d14","banner":null,"lang":"en","date_modified":"2021-07-08","date_modified_ts":"2021-07-08T13:31:13Z","date_created":"2021-07-08T13:31:13Z","summary":null,"body":["<article data-history-node-id=\"2554\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-85\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-319<br \/>\nDate: 8 July 2021<\/strong><\/p>\n\n<p>On 7 July 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Of note are updates for the following:<\/p>\n\n<ul><li>Cisco AsyncOS for Web Security Appliance (WSA) \u2013 multiple versions<\/li>\n\t<li>Cisco Business Process Automation (BPA) \u2013 versions prior to 3.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a remote actor to perform command injection and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco AsyncOS for Web Security Appliance (WSA)<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-scr-web-priv-esc-k3HCGJZ\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-scr-web-priv-esc-k3HCGJZ<\/a><\/p>\n\n<p>Cisco Business Process Automation (BPA)<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-bpa-priv-esc-dgubwbH4\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-bpa-priv-esc-dgubwbH4<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-85","alert_type":396,"serial_number":"AV21-319","subject":null,"moderation_state":"published","external_url":null},{"nid":2556,"title":" Fortinet security advisory","uuid":"7586d1b6-691e-4a2c-afe2-88a336241eb5","banner":null,"lang":"en","date_modified":"2021-07-08","date_modified_ts":"2021-07-08T16:44:20Z","date_created":"2021-07-08T16:42:20Z","summary":null,"body":["<article data-history-node-id=\"2556\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-320<br \/>\nDate: 8 July 2021<\/strong><\/p>\n\n<p>On 7 July 2021 Fortinet published multiple PSIRT Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiMail - versions 6.4.3 and prior, 6.2.6 and prior, 6.0.10 and prior and 5.4.12 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to unauthenticated code execution and execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>PSIRT Advisory (FG-IR-21-012)<\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-012\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-012<\/a><\/p>\n\n<p>Fortinet PSIRT Advisories<\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-9","alert_type":396,"serial_number":"AV21-320","subject":null,"moderation_state":"published","external_url":null},{"nid":2557,"title":"HPE security advisory","uuid":"05bcb9a6-5cb2-43cc-a014-abcca34f86a7","banner":null,"lang":"en","date_modified":"2021-07-08","date_modified_ts":"2021-07-08T19:28:58Z","date_created":"2021-07-08T19:28:58Z","summary":null,"body":["<article data-history-node-id=\"2557\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-321<br \/>\nDate: 8 July 2021<\/strong><\/p>\n\n<p>On 5 July 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ClearPass 6.9.x \u2013 versions prior to 6.9.6<\/li>\n\t<li>ClearPass 6.8.x \u2013 versions prior to 6.8.9<\/li>\n\t<li>ClearPass 6.7.x \u2013 all versions<\/li>\n\t<li>ClearPass 6.6.x \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in arbitrary command execution, authentication bypass, escalation of privilege, SQL injection, insecure deserialization or denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>HPE Aruba ClearPass Policy Manager (HPESBNW04181)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04181en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04181en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-23","alert_type":396,"serial_number":"AV21-321","subject":null,"moderation_state":"published","external_url":null},{"nid":2558,"title":"Android security advisory \u2013 July 2021 monthly rollup","uuid":"209be7d3-7e70-4c29-be08-d9e969be62f5","banner":null,"lang":"en","date_modified":"2021-07-08","date_modified_ts":"2021-07-08T19:44:43Z","date_created":"2021-07-08T19:44:43Z","summary":null,"body":["<article data-history-node-id=\"2558\" about=\"\/en\/alerts-advisories\/android-security-advisory-july-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-322<br \/>\nDate: 8 July 2021<\/strong><\/p>\n\n<p>On 7 July 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-07-01\">https:\/\/source.android.com\/security\/bulletin\/2021-07-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-july-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-322","subject":null,"moderation_state":"published","external_url":null},{"nid":2559,"title":"[Control systems] MTD Software security advisory","uuid":"b44221b5-7b46-4595-8757-15cbe88b3478","banner":null,"lang":"en","date_modified":"2021-07-09","date_modified_ts":"2021-07-09T14:22:07Z","date_created":"2021-07-09T14:16:37Z","summary":null,"body":["<article data-history-node-id=\"2559\" about=\"\/en\/alerts-advisories\/control-systems-mtd-software-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-323<br \/>\nDate: 9 July 2021<\/strong><\/p>\n\n<p>On 8 July 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MTD AutoSave \u2013 versions prior to 6.02.06<\/li>\n\t<li>MTD AutoSave \u2013 versions 7.00 to 7.04<\/li>\n\t<li>AutoSave for System Platform (A4SP) \u2013 versions prior to 4.01<\/li>\n\t<li>A4SP \u2013 version 5.00<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-189-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-189-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-189-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mtd-software-security-advisory","alert_type":398,"serial_number":"AV21-323","subject":null,"moderation_state":"published","external_url":null},{"nid":2560,"title":"Dell security advisory","uuid":"ec242580-2734-411f-883c-ecf3d4b7963f","banner":null,"lang":"en","date_modified":"2021-07-09","date_modified_ts":"2021-07-09T14:33:22Z","date_created":"2021-07-09T14:33:22Z","summary":null,"body":["<article data-history-node-id=\"2560\" about=\"\/en\/alerts-advisories\/dell-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-324<br \/>\nDate: 9 July 2021<\/strong><\/p>\n\n<p>On 7 July 2021 Dell published Knowledge Base Articles to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Avamar \u2013 multiple versions on multiple platforms<\/li>\n\t<li>Dell Networker Virtual Edition (NVE) \u2013 version 19.4 on SUSE Linux Enterprise 12 SP5<\/li>\n\t<li>Dell PowerProtect \u2013 DP Series<\/li>\n\t<li>Dell Integrated Data Protection Appliance (IDPA) \u2013 versions 2.6 or 2.61<\/li>\n\t<li>Dell PowerFlex Appliance \u2013 versions prior to Intelligent_Catalog_37_355_00_r16.zip and Intelligent_Catalog_37_361_00_r14.zip<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Dell Avamar, Networker, PowerProtect and Integrated Data Protection Appliance<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000189404\/dsa-2021-141-dell-emc-avamar-and-networker-security-update-for-multiple-components\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000189404\/dsa-2021-141-dell-emc-avamar-and-networker-security-update-for-multiple-components<\/a><\/p>\n\n<p>Dell PowerFlex Appliance<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000189435\/dsa-2021-128-dell-emc-powerflex-appliance-security-update-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000189435\/dsa-2021-128-dell-emc-powerflex-appliance-security-update-for-multiple-third-party-component-vulnerabilities<\/a><\/p>\n\n<p>Dell Security Advisories<br \/><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">https:\/\/www.dell.com\/support\/security\/en-ca<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-5","alert_type":396,"serial_number":"AV21-324","subject":null,"moderation_state":"published","external_url":null},{"nid":2561,"title":"[Control systems] Rockwell Automation security advisory","uuid":"a69d7869-6752-46ca-a936-e40dadb4044b","banner":null,"lang":"en","date_modified":"2021-07-09","date_modified_ts":"2021-07-09T15:04:03Z","date_created":"2021-07-09T15:04:03Z","summary":null,"body":["<article data-history-node-id=\"2561\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-325<br \/>\nDate: 9 July 2021<\/strong><\/p>\n\n<p>On 8 July 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>MicroLogix 1100 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-189-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-189-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-189-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-21","alert_type":398,"serial_number":"AV21-325","subject":null,"moderation_state":"published","external_url":null},{"nid":2562,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"10644903-7d73-465e-a61c-866ed451d532","banner":null,"lang":"en","date_modified":"2021-07-09","date_modified_ts":"2021-07-09T17:54:19Z","date_created":"2021-07-09T17:54:19Z","summary":null,"body":["<article data-history-node-id=\"2562\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-326<br \/>\nDate: 9 July 2021<\/strong><\/p>\n\n<p>On 9 July 2021 B&amp;R Industrial Automation published a Cyber Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Automation Runtime webserver - versions prior to 4.91<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthenticated actor to cause a remote denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>B&amp;R Industrial Automation Cyber Security Advisory (#08\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1625405588264-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1625405588264-en-original-1.0.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-5","alert_type":398,"serial_number":"AV21-326","subject":null,"moderation_state":"published","external_url":null},{"nid":2563,"title":"IBM security advisory","uuid":"7d2da339-b44d-4cba-83d7-d08399de7699","banner":null,"lang":"en","date_modified":"2021-07-12","date_modified_ts":"2021-07-12T15:00:41Z","date_created":"2021-07-12T15:00:41Z","summary":null,"body":["<article data-history-node-id=\"2563\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-56\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-327<br \/>\nDate: 12 July 2021<\/strong><\/p>\n\n<p>Between 5 and 11 July 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Security Guardium Insights \u2013 version 2.5<\/li>\n\t<li>IBM Cloud Pak for Integration \u2013 versions 2020.4.1-0-eus, 2020.4.1-1-eus and 2021.1.1-0<\/li>\n\t<li>IBM Spectrum Discover \u2013 multiple versions<\/li>\n\t<li>IBM Spectrum Symphony \u2013 versions 7.2.1, 7.3 and 7.3.1<\/li>\n\t<li>IBM UrbanCode Deploy \u2013 multiple versions<\/li>\n\t<li>IBM InfoSphere Information Server \u2013 version 11.7<\/li>\n\t<li>IBM Security Identity Governance and Intelligence \u2013 versions 5.2.4 to 5.2.6<\/li>\n\t<li>IBM License Metric Tool \u2013 all versions<\/li>\n\t<li>IBM App connect Enterprise v11 \u2013 versions V11.0.0.0 to V11.0.0.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-56","alert_type":396,"serial_number":"AV21-327","subject":null,"moderation_state":"published","external_url":null},{"nid":2564,"title":"SolarWinds security advisory","uuid":"0ecd1e03-aacb-4159-8d62-cf87fd549138","banner":null,"lang":"en","date_modified":"2021-07-12","date_modified_ts":"2021-07-12T18:49:56Z","date_created":"2021-07-12T18:49:27Z","summary":null,"body":["<article data-history-node-id=\"2564\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-328<br \/>\nDate: 12 July 2021<\/strong><\/p>\n\n<p>On 9 July 2021 SolarWinds published a Security Advisory to address a vulnerability in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Serv-U \u2013 all versions prior to 15.2.3 HF2<\/li>\n<\/ul><p>Exploitation of this vulnerability may lead to execution of arbitrary code with privileges.<br \/>\nSolarWinds indicates this vulnerability only affects Serv-U Managed File Transfer and Serv-U Secure FTP. SolarWinds has been notified by Microsoft of limited, targeted exploitation of this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\nSolarWinds Security Advisory (CVE-2021-35211)<\/p>\n\n<p><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2021-35211\">https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2021-35211<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-1","alert_type":396,"serial_number":"AV21-328","subject":null,"moderation_state":"published","external_url":null},{"nid":2566,"title":"ForgeRock security advisory","uuid":"39949cbc-287f-4512-a5f3-242212d47322","banner":null,"lang":"en","date_modified":"2021-07-13","date_modified_ts":"2021-07-13T13:45:26Z","date_created":"2021-07-13T13:45:26Z","summary":null,"body":["<article data-history-node-id=\"2566\" about=\"\/en\/alerts-advisories\/forgerock-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-329<br \/>\nDate: 13 July 2021<\/strong><\/p>\n\n<p>On 29 June 2021 ForgeRock published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Access Management \u2013 version 6.5.3 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability may lead to unauthenticated remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>ForgeRock Security Advisory<br \/><a href=\"https:\/\/backstage.forgerock.com\/knowledge\/kb\/article\/a47894244\">https:\/\/backstage.forgerock.com\/knowledge\/kb\/article\/a47894244<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/forgerock-security-advisory","alert_type":396,"serial_number":"AV21-329","subject":null,"moderation_state":"published","external_url":null},{"nid":2567,"title":"[Control systems] Siemens security advisory","uuid":"d9fc8ed1-73dc-4fed-bdfc-f0be398b0312","banner":null,"lang":"en","date_modified":"2021-07-13","date_modified_ts":"2021-07-13T20:20:39Z","date_created":"2021-07-13T20:11:17Z","summary":null,"body":["<article data-history-node-id=\"2567\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-331<br \/>\nDate: 13 July 2021<\/strong><\/p>\n\n<p>On 13 July 2021 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Solid Edge SE2021 \u2013 versions prior to SE2021MP5<\/li>\n\t<li>JT Utilities \u2013 versions prior to V13.0.2.0<\/li>\n\t<li>Mendix - multiple platforms and versions<\/li>\n\t<li>RUGGEDCOM ROS - multiple platforms and versions<\/li>\n\t<li>SINAMICS PERFECT HARMONY GH180 Drives \u2013 all versions<\/li>\n\t<li>SINUMERIK \u2013 multiple platforms and versions<\/li>\n\t<li>RWG Universal Controller \u2013 multiple platforms and versions<\/li>\n\t<li>JT2Go \u2013 versions prior to V13.2<\/li>\n\t<li>Teamcenter Visualization \u2013 versions prior to V13.2<\/li>\n\t<li>RUGGEDCOM WIN \u2013 all versions<\/li>\n\t<li>SCALANCE \u2013 multiple platforms and versions<\/li>\n\t<li>Teamcenter Active Workspace \u2013 multiple platforms and versions<\/li>\n\t<li>SIMATIC \u2013 multiple platforms and versions<\/li>\n\t<li>SIPROTEC \u2013 multiple platforms and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to crash services, execute code, extract data, escalate privileges, or cause denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-29","alert_type":398,"serial_number":"AV21-331","subject":null,"moderation_state":"published","external_url":null},{"nid":2571,"title":"Mozilla security advisory","uuid":"ef6d650a-54a5-40d8-b37e-460595058b29","banner":null,"lang":"en","date_modified":"2021-07-13","date_modified_ts":"2021-07-13T20:31:14Z","date_created":"2021-07-13T20:15:23Z","summary":null,"body":["<article data-history-node-id=\"2571\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-39\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-330<br \/>\nDate: 13 July 2021<\/strong><\/p>\n\n<p>On 13 July 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 90<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.12<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-28)<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-28\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-28\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-29)<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-29\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-29\/<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-39","alert_type":396,"serial_number":"AV21-330","subject":null,"moderation_state":"published","external_url":null},{"nid":2568,"title":"[Control systems] Schneider Electric security advisory","uuid":"2a4f84d9-105c-4149-adbf-cce0204e189b","banner":null,"lang":"en","date_modified":"2021-07-13","date_modified_ts":"2021-07-13T20:22:15Z","date_created":"2021-07-13T20:22:15Z","summary":null,"body":["<article data-history-node-id=\"2568\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-332<br \/>\nDate: 13 July 2021<\/strong><\/p>\n\n<p>On 13 July 2021 Schneider Electric published Security Notifications to address vulnerabilities in multiple products. Included were patches for the following:<\/p>\n\n<ul><li>EVlink \u2013 multiple platforms and versions<\/li>\n\t<li>Easergy T200 RTU \u2013 multiple platforms and versions<\/li>\n\t<li>Easergy T300 RTU \u2013 version V2.7.1 and prior<\/li>\n\t<li>C-Bus Toolkit \u2013 version V1.15.8 and prior<\/li>\n\t<li>SoSafe Configurable \u2013 versions prior to V1.8.1<\/li>\n\t<li>EcoStruxure Control Expert \u2013 versions prior to V15.0 SP1<\/li>\n\t<li>EcoStruxure Process Expert \u2013 all versions<\/li>\n\t<li>SCADAPack RemoteConnect x70 \u2013 all versions<\/li>\n\t<li>Modicon M580 \u2013 all versions<\/li>\n\t<li>Modicon M340 \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-22","alert_type":398,"serial_number":"AV21-332","subject":null,"moderation_state":"published","external_url":null},{"nid":2569,"title":"SAP security advisory \u2013 July 2021 monthly rollup","uuid":"63309c36-adcb-49fd-9c1e-1045dd9f7847","banner":null,"lang":"en","date_modified":"2021-07-13","date_modified_ts":"2021-07-13T20:25:08Z","date_created":"2021-07-13T20:25:08Z","summary":null,"body":["<article data-history-node-id=\"2569\" about=\"\/en\/alerts-advisories\/sap-security-advisory-july-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-333<br \/>\nDate: 13 July 2021<\/strong><\/p>\n\n<p>On 13 July 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were high severity patches for the following:<\/p>\n\n<ul><li>SAP NetWeaver Guided Procedures - versions 7.10, 7.20, 7.30, 7.31, 7.40 and 7.50<\/li>\n\t<li>SAP NetWeaver AS for Java - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 July 2021<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=580617506\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=580617506<\/a><br \/><br \/><strong>Note to Readers \u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-july-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-333","subject":null,"moderation_state":"published","external_url":null},{"nid":2570,"title":"Adobe security advisory","uuid":"342be0a0-7e76-4ec9-96da-3507cf6a3413","banner":null,"lang":"en","date_modified":"2021-07-13","date_modified_ts":"2021-07-13T20:28:11Z","date_created":"2021-07-13T20:28:11Z","summary":null,"body":["<article data-history-node-id=\"2570\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-42\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-334<br \/>\nDate: 13 July 2021<\/strong><\/p>\n\n<p>On 13 July 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Adobe Dimension \u2013 version 3.4 and prior<\/li>\n\t<li>Illustrator 2021 \u2013 version 25.2.3 and prior<\/li>\n\t<li>Adobe Framemaker 2019 \u2013 Update 8 and prior<\/li>\n\t<li>Adobe Framemaker 2020 \u2013 Update 1 and prior<\/li>\n\t<li>Acrobat DC and Reader DC \u2013 version 2021.005.20054 and prior<\/li>\n\t<li>Acrobat 2020 and Acrobat Reader 2020 \u2013 version 2020.004.30005 and prior<\/li>\n\t<li>Acrobat 2017 and Acrobat Reader 2017 \u2013 version 2017.011.30197 and prior<\/li>\n\t<li>Adobe Bridge\u00a0- version 11.0.2 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p><span style=\"font-size:11.0pt\"><span style=\"line-height:107%\"><span style=\"font-family:&quot;Calibri&quot;,sans-serif\"><\/span><\/span><\/span><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-42","alert_type":396,"serial_number":"AV21-334","subject":null,"moderation_state":"published","external_url":null},{"nid":2572,"title":"Microsoft security advisory \u2013 July 2021 monthly rollup","uuid":"d7f37be7-880a-449b-a148-fccb013f3891","banner":null,"lang":"en","date_modified":"2021-07-14","date_modified_ts":"2021-07-14T15:23:52Z","date_created":"2021-07-14T15:23:52Z","summary":null,"body":["<article data-history-node-id=\"2572\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-335<br \/>\nDate: 14 July 2021<\/strong><\/p>\n\n<p>On 13 July 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 7, 8.1, RT 8.1 and 10<\/li>\n\t<li>Windows Server version 20H2 and version 2004<\/li>\n\t<li>Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016 and 2019<\/li>\n\t<li>Microsoft Dynamics 365 Business Central<\/li>\n\t<li>Microsoft Exchange Server 2013, 2016 and 2019<\/li>\n\t<li>Microsoft Malware Protection Engine<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.<\/p>\n\n<p>Of note, Microsoft has indicated that exploitation has been detected for the following vulnerabilities: CVE-2021-31979, CVE-2021-34448 and CVE-2021-33771. These vulnerabilities could be used to escalate privileges or corrupt memory.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>July 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Jul\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Jul<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong> \u00a0<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-335","subject":null,"moderation_state":"published","external_url":null},{"nid":2574,"title":"Juniper Networks security advisory","uuid":"3243f8dd-9b3f-4967-8243-268f289c118c","banner":null,"lang":"en","date_modified":"2021-07-14","date_modified_ts":"2021-07-14T19:41:16Z","date_created":"2021-07-14T19:22:37Z","summary":null,"body":["<article data-history-node-id=\"2574\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-336<br \/>\nDate: 14 July 2021<\/strong><\/p>\n\n<p>On 14 July 2021 Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Juniper Networks Steel-Belted Radius Carrier Edition \u2013 versions 8.4.1, 8.5.0 and 8.6.0<\/li>\n\t<li>Juniper Networks Contrail Networking and Contrail Networking 3.2 \u2013 versions prior to 2011 and 3.2.18<\/li>\n\t<li>Juniper Networks CTPView \u2013 versions prior to 9.1R2<\/li>\n\t<li>Juniper Contrail Insights \u2013 versions prior to 3.2.12a1<\/li>\n\t<li>Junos Space \u2013 versions prior to 21.2R1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution, denial of service and the ability to execute commands as root.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Juniper Networks Security Bulletins<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-9","alert_type":396,"serial_number":"AV21-336","subject":null,"moderation_state":"published","external_url":null},{"nid":2575,"title":"Palo Alto Networks security advisory","uuid":"dec00cc2-e9ac-4593-b122-9c18c199ba0c","banner":null,"lang":"en","date_modified":"2021-07-15","date_modified_ts":"2021-07-15T13:09:02Z","date_created":"2021-07-15T13:09:02Z","summary":null,"body":["<article data-history-node-id=\"2575\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-337<br \/>\nDate: 15 July 2021<\/strong><\/p>\n\n<p>On 14 July 2021 Palo Alto Networks published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Prisma Cloud Compute 21.04 \u2013 versions prior to 21.04.439<\/li>\n\t<li>Prisma Cloud Compute 20.12 \u2013 versions prior to 20.12.552<\/li>\n\t<li>Cortex XDR Agent \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Palo Alto Networks Security Advisory (CVE-2021-3043)<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3043\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3043<\/a><\/p>\n\n<p>Palo Alto Networks Security Advisory (CVE-2021-3042)<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3042\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3042<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-9","alert_type":396,"serial_number":"AV21-337","subject":null,"moderation_state":"published","external_url":null},{"nid":2576,"title":"Cisco security advisory","uuid":"42f0945c-a51a-4563-90b3-6272206cdc48","banner":null,"lang":"en","date_modified":"2021-07-16","date_modified_ts":"2021-07-16T12:52:04Z","date_created":"2021-07-16T12:52:04Z","summary":null,"body":["<article data-history-node-id=\"2576\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-86\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-338<br \/>\nDate: 16 July 2021<\/strong><\/p>\n\n<p>On 15 July 2021 Cisco published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Cisco Adaptive Security Appliance (ASA) Software \u2013 version 9.16.1<\/li>\n\t<li>Cisco Firepower Threat Defense (FTD) \u2013 version 7.0.0<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asa-ftd-ipsec-dos-TFKQbgWC  \">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asa-ftd-ipsec-dos-TFKQbgWC \u00a0<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-86","alert_type":396,"serial_number":"AV21-338","subject":null,"moderation_state":"published","external_url":null},{"nid":2577,"title":"Google Chrome security advisory","uuid":"c14d43ee-cb50-435c-b756-b47b04529680","banner":null,"lang":"en","date_modified":"2021-07-16","date_modified_ts":"2021-07-16T14:49:08Z","date_created":"2021-07-16T14:49:08Z","summary":null,"body":["<article data-history-node-id=\"2577\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-61\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-339<br \/>\nDate: 16 July 2021<\/strong><\/p>\n\n<p>On 15 July 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 91.0.4472.164<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/07\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/07\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-61","alert_type":396,"serial_number":"AV21-339","subject":null,"moderation_state":"published","external_url":null},{"nid":2578,"title":"SonicWall releases Urgent Security Notice for EOL SRA and SMA 8.x devices at risk of Ransomware","uuid":"a52dc8f3-2a30-44be-b62d-0459f35b55f5","banner":null,"lang":"en","date_modified":"2021-07-16","date_modified_ts":"2021-07-16T18:38:59Z","date_created":"2021-07-16T18:38:21Z","summary":null,"body":["<article data-history-node-id=\"2578\" about=\"\/en\/alerts-advisories\/sonicwall-releases-urgent-security-notice-eol-sra-and-sma-8x-devices-risk-ransomware\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-014<br \/>\nDate: 16 July 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") seeks information to assess the impact in Canada, and to help Canadian organizations respond to this malicious activity.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>On 14 July 2021 SonicWall published an Urgent Security Notice [1] to address a vulnerability in its end-of-life Secure Remote Access (SRA) and Secure Mobile Access (SMA) 100 series products running 8.x firmware.<\/p>\n\n<p>SonicWall is aware of an imminent ransomware campaign that uses stolen credentials and leverages a known vulnerability in these products. This vulnerability has been patched in newer versions of firmware.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report this to the Cyber Centre via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>, or by telephone (1-833-CYBER-88 or 1-833-292-3788). The Cyber Centre also strongly recommends that organizations report malicious activity related to this alert to their police of jurisdiction.<\/p>\n\n<h2>MITIGATION<\/h2>\n\n<p>Organizations using the following end-of-life SMA and\/or SRA devices running firmware 8.x should either update their firmware or disconnect their appliances following guidance provided by SonicWall [<a href=\"https:\/\/www.sonicwall.com\/support\/product-notification\/urgent-security-notice-critical-risk-to-unpatched-end-of-life-sra-sma-8-x-remote-access-devices\/210713105333210\/\">1<\/a>].<\/p>\n\n<ul><li>SRA 4600\/1600 (EOL 2019)\n\t<ul><li>Disconnect immediately<\/li>\n\t\t<li>Reset passwords<\/li>\n\t<\/ul><\/li>\n\t<li>\u00a0SRA 4200\/1200 (EOL 2016)\n\t<ul><li>Disconnect immediately<\/li>\n\t\t<li>Reset passwords<\/li>\n\t<\/ul><\/li>\n\t<li>SSL-VPN 200\/2000\/400 (EOL 2013\/2014)\n\t<ul><li>Disconnect immediately<\/li>\n\t\t<li>Reset passwords<\/li>\n\t<\/ul><\/li>\n\t<li>SMA 400\/200 (Still Supported, in Limited Retirement Mode)\n\t<ul><li>Update to 10.2.0.7-34 or 9.0.0.10 immediately<\/li>\n\t\t<li>Reset passwords<\/li>\n\t\t<li>Enable MFA<\/li>\n\t<\/ul><\/li>\n<\/ul><h2>REFERENCES<\/h2>\n\n<p>[1] SonicWall Urgent Security Notice<br \/><a href=\"https:\/\/www.sonicwall.com\/support\/product-notification\/urgent-security-notice-critical-risk-to-unpatched-end-of-life-sra-sma-8-x-remote-access-devices\/210713105333210\/\">https:\/\/www.sonicwall.com\/support\/product-notification\/urgent-security-notice-critical-risk-to-unpatched-end-of-life-sra-sma-8-x-remote-access-devices\/210713105333210\/<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security, and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-releases-urgent-security-notice-eol-sra-and-sma-8x-devices-risk-ransomware","alert_type":397,"serial_number":"AL21-014","subject":null,"moderation_state":"published","external_url":null},{"nid":2625,"title":"Vulnerability in the Windows Print Spooler Service \u2013 UPDATE 1","uuid":"24064da1-8c17-4016-a29b-c9b1d906c840","banner":null,"lang":"en","date_modified":"2021-08-10","date_modified_ts":"2021-08-10T22:10:28Z","date_created":"2021-07-16T21:26:03Z","summary":null,"body":["<article data-history-node-id=\"2625\" about=\"\/en\/alerts-advisories\/vulnerability-windows-print-spooler-service\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-015 UPDATE 1<br \/>\nDate: 16 July 2021<br \/>\nUpdated: 10 August 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>Microsoft has published a knowledge base article describing CVE-2021-34481, a new privilege elevation vulnerability in the Windows Print Spooler service [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34481\">1<\/a>]. It is unrelated to the previously released PrintNightmare vulnerability described in the Cyber Centre Alert AL21-011 [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/windows-print-spooler-vulnerability-remains-unpatched\">2<\/a>].<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>On 15 July 2021 Microsoft published a knowledge base article [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34481\">1<\/a>] describing CVE-2021-34481, a local privilege elevation vulnerability in which the Windows Print Spooler service improperly performs privileged file operations. An actor exploiting this vulnerability could run arbitrary code with SYSTEM privileges. The actor could then install programs; view, change, or delete data; or create new accounts with full user rights.<\/p>\n\n<p>To exploit the vulnerability, an actor must have the ability to execute code on the affected system.<\/p>\n\n<p>As reported in the Cyber Centre Alert AL21-011 [<a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/windows-print-spooler-vulnerability-remains-unpatched\">2<\/a>], the Windows Print Spooler has been the source of several recent vulnerabilities. Although the present vulnerability is associated with the same service, it is otherwise unrelated, and would need to be addressed by a separate update.<\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>UPDATE 1<\/strong><\/p>\n\n<p>On 10 August 2021, Microsoft revised the impact of this vulnerability from local privilege escalation to remote code execution. This change occurred after Microsoft completed their investigation of the vulnerability [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34481\">1<\/a>].<\/p>\n\n<h2>MITIGATION<\/h2>\n\n<p>Currently the only known mitigation for CVE-2021-34481 is to disable the Print Spooler service, as described in the knowledge base article [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34481\">1<\/a>]. This will impede the ability to print.<\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>UPDATE 1<\/strong><\/p>\n\n<p>On 10 August 2021, mitigation for CVE-2021-34481 was released as part of the August 2021 Security Updates [<a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-august-2021-monthly-rollup\">3<\/a>]. The provided update changes the default behaviour of Point and Print to now require administrative privileges when adding or updating print drivers [<a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/08\/10\/point-and-print-default-behavior-change\/\">4<\/a>]. Microsoft has released guidance for organizations that still require non-administrative users to install or update print drivers [<a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5005652-manage-new-point-and-print-default-driver-installation-behavior-cve-2021-34481-873642bf-2634-49c5-a23b-6d8e9a302872\">5<\/a>]. Note that following this guidance will return the system to a vulnerable state.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] Windows Print Spooler Elevation of Privilege Vulnerability<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34481\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34481<\/a><\/p>\n\n<p>[2] AL21-011 Windows Print Spooler Vulnerability Remains Unpatched<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/windows-print-spooler-vulnerability-remains-unpatched\">https:\/\/cyber.gc.ca\/en\/alerts\/windows-print-spooler-vulnerability-remains-unpatched<\/a><\/p>\n\n<p>[3] AV21-385 Microsoft Security Advisory \u2013 August 2021 Monthly Rollup<br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-august-2021-monthly-rollup\">https:\/\/www.cyber.gc.ca\/en\/alerts\/microsoft-security-advisory-august-2021-monthly-rollup<\/a><\/p>\n\n<p>[4] Point and Print Default Behavior Change<br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/08\/10\/point-and-print-default-behavior-change\/\">https:\/\/msrc-blog.microsoft.com\/2021\/08\/10\/point-and-print-default-behavior-change\/<\/a><\/p>\n\n<p>[5] KB5005652\u2014Manage new Point and Print default driver installation behavior (CVE-2021-34481)<br \/><a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5005652-manage-new-point-and-print-default-driver-installation-behavior-cve-2021-34481-873642bf-2634-49c5-a23b-6d8e9a302872\">https:\/\/support.microsoft.com\/en-us\/topic\/kb5005652-manage-new-point-and-print-default-driver-installation-behavior-cve-2021-34481-873642bf-2634-49c5-a23b-6d8e9a302872<\/a><\/p>\n\n<p><br \/><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-windows-print-spooler-service","alert_type":397,"serial_number":"AL21-015","subject":null,"moderation_state":"published","external_url":null},{"nid":2579,"title":"Ubuntu security advisory","uuid":"16d4a344-d471-4b10-a554-2691953ff955","banner":null,"lang":"en","date_modified":"2021-07-19","date_modified_ts":"2021-07-19T13:42:15Z","date_created":"2021-07-19T13:42:15Z","summary":null,"body":["<article data-history-node-id=\"2579\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-342<br \/>\nDate: 19 July 2021<\/strong><\/p>\n\n<p>On 19 July 2021 Ubuntu released a Security Notice to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (LSN-0078-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0078-1\">https:\/\/ubuntu.com\/security\/notices\/LSN-0078-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-16","alert_type":396,"serial_number":"AV21-342","subject":null,"moderation_state":"published","external_url":null},{"nid":2580,"title":"IBM security advisory","uuid":"6ff17e85-73e5-4a62-bbe1-785776c78df5","banner":null,"lang":"en","date_modified":"2021-07-19","date_modified_ts":"2021-07-19T13:45:31Z","date_created":"2021-07-19T13:45:31Z","summary":null,"body":["<article data-history-node-id=\"2580\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-57\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-341<br \/>\nDate: 19 July 2021<\/strong><\/p>\n\n<p>Between 12 and 18 July 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Resilient OnPrem \u2013 IBM Security SOAR<\/li>\n\t<li>IBM InfoSphere Data Replication \u2013 versions 11.4.0, 11.4, and 11.3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-57","alert_type":396,"serial_number":"AV21-341","subject":null,"moderation_state":"published","external_url":null},{"nid":2581,"title":"[Control systems] Ypsomed security advisory","uuid":"3e0e755f-9c4b-4e91-b158-d2cf07c704f6","banner":null,"lang":"en","date_modified":"2021-07-19","date_modified_ts":"2021-07-19T13:51:21Z","date_created":"2021-07-19T13:49:37Z","summary":null,"body":["<article data-history-node-id=\"2581\" about=\"\/en\/alerts-advisories\/control-systems-ypsomed-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-340<br \/>\nDate: 19 July 2021<\/strong><\/p>\n\n<p>On 15 July 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Ypsomed mylife Cloud - versions prior to 1.7.2<\/li>\n\t<li>Ypsomed mylife App - versions prior to 1.7.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to obtain sensitive application information or modify the integrity of data being transmitted.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-196-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-196-01 \">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-196-01 <\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ypsomed-security-advisory","alert_type":398,"serial_number":"AV21-340","subject":null,"moderation_state":"published","external_url":null},{"nid":2582,"title":"Fortinet security advisory","uuid":"acd97550-e419-4fa8-9c25-9d87a2f25914","banner":null,"lang":"en","date_modified":"2021-07-20","date_modified_ts":"2021-07-20T13:42:43Z","date_created":"2021-07-20T13:28:17Z","summary":null,"body":["<article data-history-node-id=\"2582\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-343<br \/>\nDate: 20 July 2021<\/strong><\/p>\n\n<p>On 19 July 2021 Fortinet published a PSIRT Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>FortiManager \u2013 multiple versions<\/li>\n\t<li>FortiAnalyzer \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution as root.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>PSIRT Advisory (FG-IR-21-067)<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-067\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-067<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-10","alert_type":396,"serial_number":"AV21-343","subject":null,"moderation_state":"published","external_url":null},{"nid":2583,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"7488229f-775f-4eeb-82e3-0846e3d2fddd","banner":null,"lang":"en","date_modified":"2021-07-20","date_modified_ts":"2021-07-20T19:22:46Z","date_created":"2021-07-20T19:22:46Z","summary":null,"body":["<article data-history-node-id=\"2583\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-344<br \/>\nDate: 20 July 2021<\/strong><\/p>\n\n<p>On 19 July 2021 Microsoft published Security Updates to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 91.0.864.71<\/li>\n<\/ul><p>Included with the current update is a patch for a vulnerability which has been recently reported as being exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-19-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-19-2021<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\">https:\/\/msrc.microsoft.com\/update-guide\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-0","alert_type":396,"serial_number":"AV21-344","subject":null,"moderation_state":"published","external_url":null},{"nid":2584,"title":"HPE security advisory","uuid":"70b9ddfd-d72d-466e-9b9f-e03234bb9c6e","banner":null,"lang":"en","date_modified":"2021-07-20","date_modified_ts":"2021-07-20T19:27:30Z","date_created":"2021-07-20T19:27:30Z","summary":null,"body":["<article data-history-node-id=\"2584\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-345<br \/>\nDate: 20 July 2021<\/strong><\/p>\n\n<p>On 19 July 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Aruba 8400\/8360\/8325 and 6400\/6300\/6200F switch series running the following versions of AOS-CX firmware:\n\t<ul><li>10.04.xxxx - versions prior to 10.04.3070<\/li>\n\t\t<li>10.05.xxxx - versions prior to 10.05.0070<\/li>\n\t\t<li>10.06.xxxx - versions prior to 10.06.0110<\/li>\n\t\t<li>10.07.xxxx - versions prior to 10.07.0001<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in bypassing source port UDP randomization, remote code execution, or overwriting of firmware and CSS paths.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE Aruba AOS-CX Switch Series (HPESBNW04185)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04185en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04185en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-24","alert_type":396,"serial_number":"AV21-345","subject":null,"moderation_state":"published","external_url":null},{"nid":2585,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"ae5a4680-91ab-4979-b595-57ce994759f4","banner":null,"lang":"en","date_modified":"2021-07-21","date_modified_ts":"2021-07-21T15:36:41Z","date_created":"2021-07-21T15:36:41Z","summary":null,"body":["<article data-history-node-id=\"2585\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-346<br \/>\nDate: 21 July 2021<\/strong><\/p>\n\n<p>On 20 July 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>FX3U-ENET - firmware version 1.14 and prior<\/li>\n\t<li>FX3U-ENET-L - firmware version 1.14 and prior<\/li>\n\t<li>FX3U-ENET-P502 - firmware version 1.14 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability may lead to denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-201-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-201-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-201-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-18","alert_type":398,"serial_number":"AV21-346","subject":null,"moderation_state":"published","external_url":null},{"nid":2586,"title":"Adobe security advisory","uuid":"e45ed349-28fa-4d95-97a4-071c70206a81","banner":null,"lang":"en","date_modified":"2021-07-21","date_modified_ts":"2021-07-21T15:42:37Z","date_created":"2021-07-21T15:42:37Z","summary":null,"body":["<article data-history-node-id=\"2586\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-43\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-347<br \/>\nDate: 21 July 2021<\/strong><\/p>\n\n<p>On 20 July 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Adobe Media Encoder \u2013 version 15.2 and prior<\/li>\n\t<li>Adobe After Effects \u2013 version 18.2.1 and prior<\/li>\n\t<li>Adobe Premiere Pro \u2013 version 15.2 and prior<\/li>\n\t<li>Adobe Prelude \u2013 version 10.0 and prior<\/li>\n\t<li>Character Animator 2020 \u2013 version 4.2 and prior<\/li>\n\t<li>Photoshop 2020 \u2013 version 21.2.9 and prior<\/li>\n\t<li>Photoshop 2021 \u2013 version 22.4.2 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution, arbitrary file system read and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-43","alert_type":396,"serial_number":"AV21-347","subject":null,"moderation_state":"published","external_url":null},{"nid":2587,"title":"Google Chrome security advisory","uuid":"d8634734-4191-4a8f-93d0-168139a7f1e4","banner":null,"lang":"en","date_modified":"2021-07-21","date_modified_ts":"2021-07-21T16:29:16Z","date_created":"2021-07-21T16:29:16Z","summary":null,"body":["<article data-history-node-id=\"2587\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-62\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-348<br \/>\nDate: 21 July 2021<\/strong><\/p>\n\n<p>On 20 July 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 92.0.4515.107<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/07\/stable-channel-update-for-desktop_20.html\">https:\/\/chromereleases.googleblog.com\/2021\/07\/stable-channel-update-for-desktop_20.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-62","alert_type":396,"serial_number":"AV21-348","subject":null,"moderation_state":"published","external_url":null},{"nid":2588,"title":"Drupal security advisory","uuid":"0e10873f-d693-4e21-9075-d325235be072","banner":null,"lang":"en","date_modified":"2021-07-21","date_modified_ts":"2021-07-21T17:57:24Z","date_created":"2021-07-21T17:57:24Z","summary":null,"body":["<article data-history-node-id=\"2588\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-349<br \/>\nDate: 21 July 2021<\/strong><\/p>\n\n<p>On 21 July 2021 Drupal published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Drupal 9.2 - versions prior to Drupal 9.2.2<\/li>\n\t<li>Drupal 9.1- versions prior to Drupal 9.1.11<\/li>\n\t<li>Drupal 8.9 - versions prior to Drupal 8.9.17<\/li>\n\t<li>Drupal 7 - versions prior to Drupal 7.82<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates:<\/p>\n\n<p>Drupal core (SA-CORE-2021-004)<br \/><a href=\"https:\/\/www.drupal.org\/sa-core-2021-004\">https:\/\/www.drupal.org\/sa-core-2021-004\u00a0 <\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-14","alert_type":396,"serial_number":"AV21-349","subject":null,"moderation_state":"published","external_url":null},{"nid":2589,"title":"Oracle security advisory","uuid":"be381631-bffc-4bb8-a662-2cabd9ba1aae","banner":null,"lang":"en","date_modified":"2021-07-22","date_modified_ts":"2021-07-22T14:56:13Z","date_created":"2021-07-22T14:56:13Z","summary":null,"body":["<article data-history-node-id=\"2589\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-350<br \/>\nDate: 22 July 2021<\/strong><\/p>\n\n<p>On 20 July 2021 Oracle published a Critical Patch Update Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Essbase Analytic Provider Services \u2013 version 21.2<\/li>\n\t<li>Oracle Commerce Platform \u2013 versions 11.0.0, 11.1.0, 11.2.0, and versions 11.3.0 to 11.3.2<\/li>\n\t<li>Oracle Communications BRM \u2013 Elastic Charging Engine \u2013 version 12.0.0.3.0<\/li>\n\t<li>Oracle Communications Unified Inventory Management \u2013 versions 7.3.2, 7.3.4, 7.3.5, 7.4.0, and 7.4.1<\/li>\n\t<li>Oracle Communications Offline Mediation Controller \u2013 version 12.0.0.3.0<\/li>\n\t<li>Oracle Communications Pricing Design Center \u2013 version 12.0.0.3.0<\/li>\n\t<li>Oracle Communications Cloud Native Core Security Edge Protection Proxy \u2013 versions 1.7.0 and 1.5.2<\/li>\n\t<li>Oracle Communications Diameter Signaling Router (DSR) \u2013 versions 8.0.0 to 8.5.0<\/li>\n\t<li>Oracle Communications EAGLE Software \u2013 versions 46.6.0 to 46.8.2<\/li>\n\t<li>Oracle Primavera Gateway \u2013 versions 18.8.0 to 18.8.11<\/li>\n\t<li>Oracle Marketing \u2013 versions 12.1.1 to 12.1.3 and 12.2.3 to 12.2.10<\/li>\n\t<li>Oracle Enterprise Manager Base Platform \u2013 version 13.4.0.0<\/li>\n\t<li>Oracle Banking Enterprise Default Management \u2013 versions 2.10.0 and 2.12.0<\/li>\n\t<li>Oracle Banking Platform \u2013 versions 2.4.0, 2.7.1, 2.9.0 and 2.12.0<\/li>\n\t<li>Oracle Banking Liquidity Management \u2013 versions 14.2, 14.3, and 14.5<\/li>\n\t<li>Oracle FLEXCUBE Private Banking \u2013 versions 12.0.0 and 12.1.0<\/li>\n\t<li>Oracle BAM (Business Activity Monitoring) - versions 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0<\/li>\n\t<li>Oracle WebCenter Portal - versions 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition \u2013 version 12.2.1.4.0<\/li>\n\t<li>Oracle Data Integrator \u2013 version 12.2.1.4.0<\/li>\n\t<li>Oracle JDeveloper - versions 12.2.1.3.0, and 12.2.1.4.0<\/li>\n\t<li>Oracle WebCenter Portal - versions 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0<\/li>\n\t<li>Oracle WebLogic Server - versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0<\/li>\n\t<li>Hyperion Infrastructure Technology \u2013 versions 11.1.2.4 and 11.2.5.0<\/li>\n\t<li>Oracle GraalVM Enterprise Edition - versions 20.3.2 and 21.1.0<\/li>\n\t<li>JD Edwards EnterpriseOne Tools \u2013 versions 9.2.5.3 and prior<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools \u2013 versions 8.58 and 8.59<\/li>\n\t<li>Oracle Policy Automation \u2013 versions 12.2.0 to 12.2.22<\/li>\n\t<li>Oracle Retail Xstore Point of Service \u2013 versions 16.0.6, 17.0.4, 18.0.3 and 19.0.2<\/li>\n\t<li>Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers \u2013 versions prior to XCP2400 and versions prior to XPC3100<\/li>\n\t<li>Oracle Secure Global Desktop \u2013 version 5.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Oracle Critical Patch Update Advisory - July 2021<br \/><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2021.html\">https:\/\/www.oracle.com\/security-alerts\/cpujul2021.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-3","alert_type":396,"serial_number":"AV21-350","subject":null,"moderation_state":"published","external_url":null},{"nid":2590,"title":"Ubuntu security advisory","uuid":"33deaedd-e088-4873-b69a-a67857bd8f51","banner":null,"lang":"en","date_modified":"2021-07-22","date_modified_ts":"2021-07-22T15:03:30Z","date_created":"2021-07-22T15:03:30Z","summary":null,"body":["<article data-history-node-id=\"2590\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-351<br \/>\nDate: 22 July 2021<\/strong><\/p>\n\n<p>On 20 July 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in execution of arbitrary code, denial of service, injection of packets, exposing of information, or decryption of fragments.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5018-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5018-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5018-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5017-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5017-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5017-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5016-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5016-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5016-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5015-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5015-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5015-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5014-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5014-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5014-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-17","alert_type":396,"serial_number":"AV21-351","subject":null,"moderation_state":"published","external_url":null},{"nid":2592,"title":"Microsoft security advisory","uuid":"a19897e9-d01d-4a12-bedc-0082cf1e8604","banner":null,"lang":"en","date_modified":"2021-07-22","date_modified_ts":"2021-07-22T16:46:19Z","date_created":"2021-07-22T15:53:43Z","summary":null,"body":["<article data-history-node-id=\"2592\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-352<br \/>\nDate: 22 July 2021<\/strong><\/p>\n\n<p>On 20 July 2021 Microsoft published an out-of-band Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Windows 10 \u2013 versions 1809 and later<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor with the ability to execute code on a victim system to obtain sensitive system information and elevate privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigation after verifying potential business impacts and apply the necessary updates when available.<\/p>\n\n<p>Windows Elevation of Privilege Vulnerability (CVE-2021-36934)<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36934\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36934<\/a><\/p>\n\n<p>Microsoft Windows 10 gives unprivileged user access to SAM, SYSTEM, and SECURITY files<br \/><a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/506989\">https:\/\/www.kb.cert.org\/vuls\/id\/506989<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-10","alert_type":396,"serial_number":"AV21-352","subject":null,"moderation_state":"published","external_url":null},{"nid":2591,"title":"Apple security advisory","uuid":"3d758875-6ea4-4563-b259-dc498ba0c31f","banner":null,"lang":"en","date_modified":"2021-07-22","date_modified_ts":"2021-07-22T16:40:11Z","date_created":"2021-07-22T16:40:11Z","summary":null,"body":["<article data-history-node-id=\"2591\" about=\"\/en\/alerts-advisories\/apple-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-353<br \/>\nDate: 22 July 2021<\/strong><\/p>\n\n<p>On 19 and 21 July 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>tvOS - versions prior to 14.7<\/li>\n\t<li>watchOS \u2013 versions prior to 7.6<\/li>\n\t<li>iOS \u2013 versions prior to 14.7<\/li>\n\t<li>iPadOS \u2013 versions prior to 14.7<\/li>\n\t<li>Safari \u2013 versions prior to 14.1.2<\/li>\n\t<li>macOS Catalina \u2013 versions prior to Security Update 2021-004<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.5<\/li>\n\t<li>MacOS Mojave \u2013 versions prior to Security Update 2021-005<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution, unexpected application termination, elevation of privileges, circumvention of sandbox restrictions, denial of service, disclosure of information and bypass of signing checks or permissions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-33","alert_type":396,"serial_number":"AV21-353","subject":null,"moderation_state":"published","external_url":null},{"nid":2593,"title":"Cisco security advisory","uuid":"252dbc8a-54c8-4d4b-a5b1-341997e34269","banner":null,"lang":"en","date_modified":"2021-07-22","date_modified_ts":"2021-07-22T16:53:56Z","date_created":"2021-07-22T16:52:06Z","summary":null,"body":["<article data-history-node-id=\"2593\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-87\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-354<br \/>\nDate: 22 July 2021<\/strong><\/p>\n\n<p>On 21 July 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Of note are updates for the following:<\/p>\n\n<ul><li>Cisco Intersight Virtual Appliance \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to access sensitive internal services and make configuration changes on the affected device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Intersight Virtual Appliance<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ucsi2-iptaclbp-L8Dzs8m8\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ucsi2-iptaclbp-L8Dzs8m8<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-87","alert_type":396,"serial_number":"AV21-354","subject":null,"moderation_state":"published","external_url":null},{"nid":2594,"title":"Multiple Printer Drivers security advisory","uuid":"7a8a03e5-1a84-4973-9bb5-94ede32f4fe4","banner":null,"lang":"en","date_modified":"2021-07-22","date_modified_ts":"2021-07-22T17:23:29Z","date_created":"2021-07-22T17:23:29Z","summary":null,"body":["<article data-history-node-id=\"2594\" about=\"\/en\/alerts-advisories\/multiple-printer-drivers-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-355<br \/>\nDate: 22 July 2021<\/strong><\/p>\n\n<p>On 20 July 2021 security researchers published information detailing a high severity vulnerability affecting the print drivers for several hundred printer models from the following manufacturers:<\/p>\n\n<ul><li>Hewlett Packard \u2013 multiple models<\/li>\n\t<li>Samsung \u2013 multiple models<\/li>\n\t<li>Xerox:\n\t<ul><li>B205\/B210\/B215<\/li>\n\t\t<li>Phaser 3020\/3052\/3260\/3320<\/li>\n\t\t<li>WorkCentre 3025\/3215\/3225\/3315\/3325<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unprivileged user to gain SYSTEM privileges and run code in kernel mode.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>HP and Samsung Knowledge Base<br \/><a href=\"https:\/\/support.hp.com\/us-en\/document\/ish_3900395-3833905-16\">https:\/\/support.hp.com\/us-en\/document\/ish_3900395-3833905-16<\/a><\/p>\n\n<p>Xerox Bulletin<br \/><a href=\"https:\/\/securitydocs.business.xerox.com\/wp-content\/uploads\/2021\/05\/cert_Security_Mini_Bulletin_XRX21K_for_B2XX_PH30xx_3260_3320_WC3025_32xx_33xx.pdf\">https:\/\/securitydocs.business.xerox.com\/wp-content\/uploads\/2021\/05\/cert_Security_Mini_Bulletin_XRX21K_for_B2XX_PH30xx_3260_3320_WC3025_32xx_33xx.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/multiple-printer-drivers-security-advisory","alert_type":396,"serial_number":"AV21-355","subject":null,"moderation_state":"published","external_url":null},{"nid":2595,"title":"HPE security advisory","uuid":"f9646987-42b6-4165-8009-f818607e5d15","banner":null,"lang":"en","date_modified":"2021-07-23","date_modified_ts":"2021-07-23T18:00:55Z","date_created":"2021-07-23T18:00:55Z","summary":null,"body":["<article data-history-node-id=\"2595\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-356<br \/>\nDate: 23 July 2021<\/strong><\/p>\n\n<p>On 22 July 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Brocade 8Gb SAN Switch for HPE BladeSystem c-Class \u2013 versions prior to 7.4.2h<\/li>\n\t<li>HPE 1606 Extension SAN Switch \u2013 versions prior to 7.4.2h<\/li>\n\t<li>HPE 8\/24 SAN Switch \u2013 versions prior to 7.4.2h<\/li>\n\t<li>HPE 8\/8 SAN Switch \u2013 versions prior to 7.4.2h<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in local code execution or writing arbitrary content to files, or remote denial of service or injection of arbitrary HTTP headers.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE SAN Switches with Brocade Fabric OS (FOS) (HPESBNW04142)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04142en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04142en_us<\/a><\/p>\n\n<p>HPE Security Bulletin Library<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library\">https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-25","alert_type":396,"serial_number":"AV21-356","subject":null,"moderation_state":"published","external_url":null},{"nid":2596,"title":"Ubuntu security advisory","uuid":"cd2c84f8-d035-4561-a13f-899424f89da5","banner":null,"lang":"en","date_modified":"2021-07-26","date_modified_ts":"2021-07-26T18:23:27Z","date_created":"2021-07-26T17:30:11Z","summary":null,"body":["<article data-history-node-id=\"2596\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-357<br \/>\nDate: 26 July 2021<\/strong><\/p>\n\n<p>On 26 July 2021 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in execution of arbitrary code or denial of service.<br \/>\nThe Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (LSN-0079-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0079-1\">https:\/\/ubuntu.com\/security\/notices\/LSN-0079-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-18","alert_type":396,"serial_number":"AV21-357","subject":null,"moderation_state":"published","external_url":null},{"nid":2597,"title":"IBM security advisory","uuid":"828b9a5a-704c-4fa4-81c8-da5266290011","banner":null,"lang":"en","date_modified":"2021-07-26","date_modified_ts":"2021-07-26T19:42:34Z","date_created":"2021-07-26T19:22:51Z","summary":null,"body":["<article data-history-node-id=\"2597\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-58\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-358<br \/>\nDate: 26 July 2021<\/strong><\/p>\n\n<p>Between 19 and 25 July 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise \u2013 versions 11.0.0.0 - 11.0.0.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-58","alert_type":396,"serial_number":"AV21-358","subject":null,"moderation_state":"published","external_url":null},{"nid":2598,"title":"Apple security advisory","uuid":"48e12f3a-d056-4c66-b685-2063af2d67c8","banner":null,"lang":"en","date_modified":"2021-07-26","date_modified_ts":"2021-07-26T19:58:19Z","date_created":"2021-07-26T19:52:44Z","summary":null,"body":["<article data-history-node-id=\"2598\" about=\"\/en\/alerts-advisories\/apple-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-359<br \/>\nDate: 26 July 2021<\/strong><\/p>\n\n<p>On 26 July 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 14.7.1<\/li>\n\t<li>iPadOS \u2013 versions prior to 14.7.1<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.5.1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution. Apple is aware of a report that some of these vulnerabilities may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-34","alert_type":396,"serial_number":"AV21-359","subject":null,"moderation_state":"published","external_url":null},{"nid":2599,"title":"[Control systems] KUKA security advisory","uuid":"f724499e-5540-4a2d-a9dc-0c93ae454e16","banner":null,"lang":"en","date_modified":"2021-07-27","date_modified_ts":"2021-07-27T19:57:53Z","date_created":"2021-07-27T19:55:41Z","summary":null,"body":["<article data-history-node-id=\"2599\" about=\"\/en\/alerts-advisories\/control-systems-kuka-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-360<br \/>\nDate: 27 July 2021<\/strong><\/p>\n\n<p>On 27 July 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>KR C4 - versions prior to 8.7<\/li>\n\t<li>KSS - all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-208-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-kuka-security-advisory","alert_type":398,"serial_number":"AV21-360","subject":null,"moderation_state":"published","external_url":null},{"nid":2600,"title":"[Control systems] Geutebr\u00fcck security advisory","uuid":"8079e2bc-9230-48b8-95dd-6068852ffc98","banner":null,"lang":"en","date_modified":"2021-07-28","date_modified_ts":"2021-07-28T13:09:55Z","date_created":"2021-07-28T13:00:28Z","summary":null,"body":["<article data-history-node-id=\"2600\" about=\"\/en\/alerts-advisories\/control-systems-geutebruck-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-361<br \/>\nDate: 28 July 2021<\/strong><\/p>\n\n<p>On 27 July 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>E2 Series cameras \u2013 G-CAM - versions 1.12.0.27 and prior, 1.12.13.2 and 1.12.14.5\n\t<ul><li>EBC-21xx<\/li>\n\t\t<li>EFD-22xx<\/li>\n\t\t<li>ETHC-22xx<\/li>\n\t\t<li>EWPC-22xx<\/li>\n\t<\/ul><\/li>\n\t<li>Encoder G-Code - versions 1.12.0.27 and prior, 1.12.13.2 and 1.12.14.5\n\t<ul><li>EEC-2xx<\/li>\n\t\t<li>EEN-20xx<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-208-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-geutebruck-security-advisory-0","alert_type":398,"serial_number":"AV21-361","subject":null,"moderation_state":"published","external_url":null},{"nid":2603,"title":"[Control systems] Delta Electronics security advisory","uuid":"df191b21-1cc4-48a3-bb72-521d96d96ea6","banner":null,"lang":"en","date_modified":"2021-07-28","date_modified_ts":"2021-07-28T16:07:24Z","date_created":"2021-07-28T14:01:58Z","summary":null,"body":["<article data-history-node-id=\"2603\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-362<br \/>\nDate: 28 July 2021<\/strong><\/p>\n\n<p>On 27 July 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DIAScreen - versions prior to 1.1.0 \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-208-05)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-05<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-8","alert_type":398,"serial_number":"AV21-362","subject":null,"moderation_state":"published","external_url":null},{"nid":2601,"title":"[Control systems] LCDS\u2014Le\u00e3o Consultoria e Desenvolvimento de Sistemas Ltda ME security advisory","uuid":"fe3487be-36fd-4d8d-8995-9ae2ef52dece","banner":null,"lang":"en","date_modified":"2021-07-28","date_modified_ts":"2021-07-28T14:31:07Z","date_created":"2021-07-28T14:31:07Z","summary":null,"body":["<article data-history-node-id=\"2601\" about=\"\/en\/alerts-advisories\/control-systems-lcds-leao-consultoria-e-desenvolvimento-de-sistemas-ltda-me-security\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-363<br \/>\nDate: 28 July 2021<\/strong><\/p>\n\n<p>On 27 July 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>LAquis SCADA - versions 4.3.1.1011 and prior \u00a0<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-208-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-lcds-leao-consultoria-e-desenvolvimento-de-sistemas-ltda-me-security","alert_type":398,"serial_number":"AV21-363","subject":null,"moderation_state":"published","external_url":null},{"nid":2602,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"91e6d16b-f9da-4bf3-b007-35d16063fb40","banner":null,"lang":"en","date_modified":"2021-07-28","date_modified_ts":"2021-07-28T14:57:36Z","date_created":"2021-07-28T14:54:23Z","summary":null,"body":["<article data-history-node-id=\"2602\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-364<br \/>\nDate: 28 July 2021<\/strong><\/p>\n\n<p>On 27 July 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>GOT2000 models GT27, GT25 and GT23 using the MODBUS\/TCP Slave, Gateway communication driver - versions 01.19.000 to 01.39.010<\/li>\n\t<li>GT SoftGOT2000 using MODBUS\/TCP Slave communication - versions 1.170C to 1.256S<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-208-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-208-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-19","alert_type":398,"serial_number":"AV21-364","subject":null,"moderation_state":"published","external_url":null},{"nid":2604,"title":"[Control systems] CODESYS security advisory","uuid":"85fec0d6-ccc3-4491-b535-c0d747cf5163","banner":null,"lang":"en","date_modified":"2021-07-28","date_modified_ts":"2021-07-28T19:58:45Z","date_created":"2021-07-28T19:54:25Z","summary":null,"body":["<article data-history-node-id=\"2604\" about=\"\/en\/alerts-advisories\/control-systems-codesys-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-365<br \/>\nDate: 28 July 2021<\/strong><\/p>\n\n<p>On 22 July 2021 CODESYS published multiple Security Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>CODESYS V3 web server \u2013 versions prior to 3.5.17.10<\/li>\n\t<li>CODESYS Control V3 Runtime System Toolkit \u2013 multiple platforms and versions prior to 4.2.0.0<\/li>\n\t<li>CODESYS Control V3 Runtime System Toolkit for VxWorks \u2013 version 3.5.8.0 to versions prior to 3.5.17.10<\/li>\n\t<li>CODESYS Gateway V3 \u2013 multiple platforms and versions<\/li>\n\t<li>CODESYS Development System V3 32 and 64 bit\u2013 versions prior to 3.5.17.10<\/li>\n\t<li>CODESYS EtherNetIP \u2013 version 3.5.16.0 to versions prior to 4.1.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>CODESYS Security Advisories<br \/><a href=\"https:\/\/www.codesys.com\/security\/security-reports.html\">https:\/\/www.codesys.com\/security\/security-reports.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-codesys-security-advisory-0","alert_type":398,"serial_number":"AV21-365","subject":null,"moderation_state":"published","external_url":null},{"nid":2605,"title":"Foxit security advisory","uuid":"2b7faf09-83b4-43ce-83d0-8765d98a62ab","banner":null,"lang":"en","date_modified":"2021-07-29","date_modified_ts":"2021-07-29T14:04:20Z","date_created":"2021-07-29T14:04:20Z","summary":null,"body":["<article data-history-node-id=\"2605\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-366<br \/>\nDate: 29 July 2021<\/strong><\/p>\n\n<p>On 27 July 2021 Foxit published a Security Bulletin to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Reader for Windows \u2013 version 11.0.0.49893 and prior<\/li>\n\t<li>Foxit PDF Editor for Windows \u2013 version 11.0.0.49893 and versions prior to 10.1.4.37651<\/li>\n\t<li>Foxit PDF Reader for MAC \u2013 version 11.0.0.0510 and prior<\/li>\n\t<li>Foxit PDF Editor for MAC \u2013 version 11.0.0.0510 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure, arbitrary file creation, remote code execution, or cause a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Foxit Security Bulletins<br \/><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">https:\/\/www.foxit.com\/support\/security-bulletins.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-3","alert_type":396,"serial_number":"AV21-366","subject":null,"moderation_state":"published","external_url":null},{"nid":2607,"title":"[Control systems] Wibu-Systems AG security advisory","uuid":"6c00bf19-6bd1-438b-9fcd-a352cd0e2fd1","banner":null,"lang":"en","date_modified":"2021-07-30","date_modified_ts":"2021-07-30T14:58:02Z","date_created":"2021-07-30T11:59:41Z","summary":null,"body":["<article data-history-node-id=\"2607\" about=\"\/en\/alerts-advisories\/control-systems-wibu-systems-ag-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-367<br \/>\nDate: 30 July 2021<\/strong><\/p>\n\n<p>On 29 July 2021, ICS-CERT published an Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Wibu-Systems AG CodeMeter Runtime \u2013 versions prior to 7.21a<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a malicious actor to cause a denial-of-service or expose sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary manufacturer update.<\/p>\n\n<p>ICS Advisory (ICSA-21-210-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-210-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-210-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wibu-systems-ag-security-advisory-0","alert_type":398,"serial_number":"AV21-367","subject":null,"moderation_state":"published","external_url":null},{"nid":2606,"title":"[Control systems] Hitachi ABB Power Grids security advisory","uuid":"4497e05e-2157-46ae-b0bf-36c8f511abf2","banner":null,"lang":"en","date_modified":"2021-07-30","date_modified_ts":"2021-07-30T12:05:32Z","date_created":"2021-07-30T12:05:32Z","summary":null,"body":["<article data-history-node-id=\"2606\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-368<br \/>\nDate: 30 July 2021<\/strong><\/p>\n\n<p>On 29 July 2021, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>eSOMS - version 6.3 and prior\u00a0\u00a0 \u00a0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to credential theft.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigation and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-210-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-210-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-210-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-3","alert_type":398,"serial_number":"AV21-368","subject":null,"moderation_state":"published","external_url":null},{"nid":2608,"title":"Apple security advisory","uuid":"86c32589-15ab-4162-940c-6c79e090711c","banner":null,"lang":"en","date_modified":"2021-07-30","date_modified_ts":"2021-07-30T16:11:14Z","date_created":"2021-07-30T16:07:46Z","summary":null,"body":["<article data-history-node-id=\"2608\" about=\"\/en\/alerts-advisories\/apple-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-369<br \/>\nDate: 30 July 2021<\/strong><\/p>\n\n<p>On 29 July 2021 Apple published a Security Update to address a vulnerability in the following product:<\/p>\n\n<ul><li>watchOS \u2013 versions prior to 7.6.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary update.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-35","alert_type":396,"serial_number":"AV21-369","subject":null,"moderation_state":"published","external_url":null},{"nid":2609,"title":"Android security advisory \u2013 August 2021 monthly rollup","uuid":"46eafa07-9604-4006-bc9b-d29b91b21ed9","banner":null,"lang":"en","date_modified":"2021-08-03","date_modified_ts":"2021-08-03T15:24:56Z","date_created":"2021-08-03T15:00:32Z","summary":null,"body":["<article data-history-node-id=\"2609\" about=\"\/en\/alerts-advisories\/android-security-advisory-august-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-370<br \/>\nDate: 3 August 2021<\/strong><\/p>\n\n<p>On 2 August 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-08-01\">https:\/\/source.android.com\/security\/bulletin\/2021-08-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-august-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-370","subject":null,"moderation_state":"published","external_url":null},{"nid":2610,"title":"IBM security advisory","uuid":"ff44320f-8694-4698-b852-609434abca39","banner":null,"lang":"en","date_modified":"2021-08-03","date_modified_ts":"2021-08-03T16:08:41Z","date_created":"2021-08-03T16:08:41Z","summary":null,"body":["<article data-history-node-id=\"2610\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-59\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-371<br \/>\nDate: 3 August 2021<\/strong><\/p>\n\n<p>Between 26 July and 2 August 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>WA for CP4D - versions 1.4.2 and 1.5.0<\/li>\n\t<li>WA for ICP - versions 1.4.2 and 1.5.0<\/li>\n\t<li>Cloud Pak for Security (CP4S) \u2013 multiple versions<\/li>\n\t<li>Partner Engagement Manager - version 2.0<\/li>\n\t<li>IBM i2 Analyst's Notebook Premium - version IBM i2 Analyze 4.3.2<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Infrastructure Management \u2013 all versions<\/li>\n\t<li>IBM QRadar SIEM \u2013 versions with PROTOCOL-RabbitMQ version 7.3 or 7.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-59","alert_type":396,"serial_number":"AV21-371","subject":null,"moderation_state":"published","external_url":null},{"nid":2611,"title":"[Control systems] NicheStack TCP\/IP Stack security advisory","uuid":"00bf03b7-2d6a-4de8-94eb-f231f6505e5b","banner":null,"lang":"en","date_modified":"2021-08-04","date_modified_ts":"2021-08-04T19:36:08Z","date_created":"2021-08-04T19:36:08Z","summary":null,"body":["<article data-history-node-id=\"2611\" about=\"\/en\/alerts-advisories\/control-systems-nichestack-tcpip-stack-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-372<br \/>\nDate: 04 August 2021<\/strong><\/p>\n\n<p>On 4 August 2021 two security research labs published a report publicly disclosing a set of vulnerabilities known collectively as \u201cINFRA:HALT\u201d in the NicheStack TCP\/IP stack implementation. Among the 14 zero-day vulnerabilities are two, CVE-2020-25928 and CVE-2021-31226, which are rated as critical. The following products are affected:<\/p>\n\n<ul><li>InterNiche \u2013 multiple packages and versions<\/li>\n\t<li>NicheLite \u2013 multiple packages and versions<\/li>\n<\/ul><p>NicheStack TCP\/IP stack is a low-level technology embedded in numerous devices utilized in operational technology and critical infrastructure, with a high concentration in manufacturing.<\/p>\n\n<p>Exploitation of these critical vulnerabilities could result in remote code execution. Exploitation of the other disclosed vulnerabilities could result in denial of service, information leaks, TCP spoofing, or DNS cache poisoning.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Additional vendors affected by the reported vulnerabilities may also release security advisories related to their impacted products.<\/p>\n\n<p>HCC Embedded Security Advisories (NicheStack)<br \/><a href=\"https:\/\/www.hcc-embedded.com\/support\/security-advisories\">https:\/\/www.hcc-embedded.com\/support\/security-advisories<\/a><\/p>\n\n<p>Forescout INFRA:HALT<br \/><a href=\"https:\/\/www.forescout.com\/research-labs\/infra-halt\/\">https:\/\/www.forescout.com\/research-labs\/infra-halt\/<\/a><\/p>\n\n<p>JFRrog INFRA:HALT 14 New Security Vulnerabilities Found in NicheStack<br \/><a href=\"https:\/\/jfrog.com\/blog\/infrahalt-14-new-security-vulnerabilities-found-in-nichestack\/\">https:\/\/jfrog.com\/blog\/infrahalt-14-new-security-vulnerabilities-found-in-nichestack\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-nichestack-tcpip-stack-security-advisory","alert_type":398,"serial_number":"AV21-372","subject":null,"moderation_state":"published","external_url":null},{"nid":2612,"title":"Cisco security advisory","uuid":"ad070d60-a325-4f77-9acd-229927631f27","banner":null,"lang":"en","date_modified":"2021-08-05","date_modified_ts":"2021-08-05T14:43:43Z","date_created":"2021-08-05T14:43:43Z","summary":null,"body":["<article data-history-node-id=\"2612\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-88\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-373<br \/>\nDate: 5 August 2021<\/strong><\/p>\n\n<p>On 4 August 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>RV340 Dual WAN Gigabit VPN Router \u2013 firmware versions prior to Release 1.0.03.22<\/li>\n\t<li>RV340W Dual WAN Gigabit Wireless-AC VPN Router \u2013 firmware versions prior to Release 1.0.03.22<\/li>\n\t<li>RV345 Dual WAN Gigabit VPN Router \u2013 firmware versions prior to Release 1.0.03.22<\/li>\n\t<li>RV345P Dual WAN Gigabit POE VPN Router \u2013 firmware versions prior to Release 1.0.03.22<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, denial-of-service and arbitrary command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-88","alert_type":396,"serial_number":"AV21-373","subject":null,"moderation_state":"published","external_url":null},{"nid":2613,"title":"[Control systems] Siemens security advisory","uuid":"af6ec100-3d9a-4e7c-8d03-ee23a8941584","banner":null,"lang":"en","date_modified":"2021-08-05","date_modified_ts":"2021-08-05T18:55:38Z","date_created":"2021-08-05T18:47:21Z","summary":null,"body":["<article data-history-node-id=\"2613\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-374<br \/>\nDate: 5 August 2021<\/strong><\/p>\n\n<p>On 4 August 2021 Siemens published a Security Advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SENTRON 3WA COM190 \u2013 versions prior to 2.0.0<\/li>\n\t<li>SENTRON 3WL COM35 \u2013 versions prior to 1.2.0<\/li>\n\t<li>SENTRON 7KM PAC Switched Ethernet PROFINET Expansion Module \u2013 versions prior to 3.0.4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-30","alert_type":398,"serial_number":"AV21-374","subject":null,"moderation_state":"published","external_url":null},{"nid":2614,"title":"[Control systems] Schneider Electric security advisory","uuid":"3645258b-378f-4dd5-9f96-4e46d2515168","banner":null,"lang":"en","date_modified":"2021-08-05","date_modified_ts":"2021-08-05T19:06:12Z","date_created":"2021-08-05T19:06:12Z","summary":null,"body":["<article data-history-node-id=\"2614\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-375<br \/>\nDate: 5 August 2021<\/strong><\/p>\n\n<p>On 5 August 2021 Schneider Electric published a Security Notification to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Lexium ILE, ILA, ILS \u2013 firmware version V01.103 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Security Notification (SEVD-2021-217-01)<br \/><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-217-01\">https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2021-217-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-23","alert_type":398,"serial_number":"AV21-375","subject":null,"moderation_state":"published","external_url":null},{"nid":2615,"title":"Pulse Secure security advisory","uuid":"b058cee8-1389-46b6-8041-25b2ba635021","banner":null,"lang":"en","date_modified":"2021-08-06","date_modified_ts":"2021-08-06T13:50:09Z","date_created":"2021-08-06T13:50:09Z","summary":null,"body":["<article data-history-node-id=\"2615\" about=\"\/en\/alerts-advisories\/pulse-secure-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-376<br \/>\nDate: 6 August 2021<\/strong><\/p>\n\n<p>On 5 August 2021 Pulse Secure published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Pulse Connect Secure - versions prior to 9.1R12<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to perform a file write, delete arbitrary files, run arbitrary commands and perform cross-site scripting.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Pulse Secure Security Advisory<br \/><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44858\/?kA23Z000000L6oySAC\">https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA44858\/?kA23Z000000L6oySAC<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/pulse-secure-security-advisory-1","alert_type":396,"serial_number":"AV21-376","subject":null,"moderation_state":"published","external_url":null},{"nid":2616,"title":"[Control systems] FATEK Automation security advisory","uuid":"05b9831e-9404-40bb-adc7-2f914f3ab08b","banner":null,"lang":"en","date_modified":"2021-08-06","date_modified_ts":"2021-08-06T13:54:20Z","date_created":"2021-08-06T13:54:20Z","summary":null,"body":["<article data-history-node-id=\"2616\" about=\"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-377<br \/>\nDate: 6 August 2021<\/strong><\/p>\n\n<p>On 5 August 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>FvDesigner - version 1.5.88 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-217-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-217-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-217-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-1","alert_type":398,"serial_number":"AV21-377","subject":null,"moderation_state":"published","external_url":null},{"nid":2617,"title":"[Control systems] Advantech security advisory","uuid":"7dfa7408-1ed5-438b-9ab6-e05dd2ec7a39","banner":null,"lang":"en","date_modified":"2021-08-06","date_modified_ts":"2021-08-06T15:09:08Z","date_created":"2021-08-06T15:09:08Z","summary":null,"body":["<article data-history-node-id=\"2617\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-378<br \/>\nDate: 6 August 2021<\/strong><\/p>\n\n<p>On 5 August 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>WebAccess\/SCADA - versions prior to 8.4.5 and versions prior to 9.0.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to hijack a user\u2019s session, gain unauthorized access to files and directories, and execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-217-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-217-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-217-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-19","alert_type":398,"serial_number":"AV21-378","subject":null,"moderation_state":"published","external_url":null},{"nid":2618,"title":"[Control systems] mySCADA security advisory","uuid":"d64b2823-05ea-4970-84a4-81dfdbe5c0ac","banner":null,"lang":"en","date_modified":"2021-08-06","date_modified_ts":"2021-08-06T15:12:16Z","date_created":"2021-08-06T15:12:16Z","summary":null,"body":["<article data-history-node-id=\"2618\" about=\"\/en\/alerts-advisories\/control-systems-myscada-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-379<br \/>\nDate: 6 August 2021<\/strong><\/p>\n\n<p>On 5 August 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>myPRO - versions prior to 8.20.0 \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and arbitrary file upload.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-217-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-217-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-217-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-myscada-security-advisory","alert_type":398,"serial_number":"AV21-379","subject":null,"moderation_state":"published","external_url":null},{"nid":2619,"title":"VMware security advisory","uuid":"3702893d-2a11-419c-8ab6-0c5fd1968429","banner":null,"lang":"en","date_modified":"2021-08-06","date_modified_ts":"2021-08-06T15:38:54Z","date_created":"2021-08-06T15:38:54Z","summary":null,"body":["<article data-history-node-id=\"2619\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-44\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-380<br \/>\nDate: 6 August 2021<\/strong><\/p>\n\n<p>On 5 August 2021 VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Workspace One Access (Access) \u2013 version 20.10 and 20.10.01<\/li>\n\t<li>VMware Identity Manager (vIDM) \u2013 versions 3.3.2 to 3.3.5<\/li>\n\t<li>VMware vRealize Automation (vRA) \u2013 versions 7.6 and 8.x<\/li>\n\t<li>VMware Cloud Foundation \u2013 versions 4.x<\/li>\n\t<li>vRealize Suite Lifecycle Manager \u2013 versions 8.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to unauthorized access and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0016)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0016.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0016.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-44","alert_type":396,"serial_number":"AV21-380","subject":null,"moderation_state":"published","external_url":null},{"nid":2620,"title":"[Control systems] Swisslog Healthcare security advisory","uuid":"2048f84f-7244-48fb-80f1-adb2af0ea8fd","banner":null,"lang":"en","date_modified":"2021-08-06","date_modified_ts":"2021-08-06T17:12:29Z","date_created":"2021-08-06T17:12:29Z","summary":null,"body":["<article data-history-node-id=\"2620\" about=\"\/en\/alerts-advisories\/control-systems-swisslog-healthcare-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-381<br \/>\nDate: 6 August 2021<\/strong><\/p>\n\n<p>On 3 August 2021 ICS-CERT published an ICS Medical Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Nexus Control Panel - versions prior to 7.2.5.7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to gain control of the device, escalate privileges, or execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-215-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-215-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-215-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-swisslog-healthcare-security-advisory","alert_type":398,"serial_number":"AV21-381","subject":null,"moderation_state":"published","external_url":null},{"nid":2621,"title":"SAP security advisory \u2013 August 2021 monthly rollup","uuid":"784b402c-a7fb-410a-afec-6261f6db3967","banner":null,"lang":"en","date_modified":"2021-08-10","date_modified_ts":"2021-08-10T13:39:53Z","date_created":"2021-08-10T13:30:07Z","summary":null,"body":["<article data-history-node-id=\"2621\" about=\"\/en\/alerts-advisories\/sap-security-advisory-august-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-382<br \/>\nDate: 10 August 2021<\/strong><\/p>\n\n<p>On 10 August 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Business One - version 10.0<\/li>\n\t<li>SAP NetWeaver Development Infrastructure (Component Build Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50<\/li>\n\t<li>DMIS Mobile Plug-In - versions DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710 and 2011_1_752, 2020<\/li>\n\t<li>SAP S\/4HANA - versions SAPSCORE 125, S4CORE 102, 102, 103, 104 and 105<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 August 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=582222806\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=582222806<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-august-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-382","subject":null,"moderation_state":"published","external_url":null},{"nid":2622,"title":"Mozilla security advisory","uuid":"503561d5-49b8-4cae-a30d-66590bf8ec9a","banner":null,"lang":"en","date_modified":"2021-08-10","date_modified_ts":"2021-08-10T15:02:02Z","date_created":"2021-08-10T15:02:02Z","summary":null,"body":["<article data-history-node-id=\"2622\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-40\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-383<br \/>\nDate: 10 August 2021<\/strong><\/p>\n\n<p>On 10 August 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 91<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.13<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in a denial-of-service or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-33)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-33\/  \">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-33\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-34)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-34\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-34\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-40","alert_type":396,"serial_number":"AV21-383","subject":null,"moderation_state":"published","external_url":null},{"nid":2623,"title":"[Control systems] Siemens security advisory","uuid":"3b9a9e9e-2b7a-4dd7-85b9-7d52107a6e5c","banner":null,"lang":"en","date_modified":"2021-08-10","date_modified_ts":"2021-08-10T15:06:18Z","date_created":"2021-08-10T15:06:18Z","summary":null,"body":["<article data-history-node-id=\"2623\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-384<br \/>\nDate: 10 August 2021<\/strong><\/p>\n\n<p>On 10 August 2021 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SIMATIC products \u2013 multiple products and versions<\/li>\n\t<li>SINUMERIC products \u2013 multiple products and versions<\/li>\n\t<li>JT2Go - versions prior to V13.2.0.2<\/li>\n\t<li>Teamcenter Visualization - versions prior to V13.2.0.2<\/li>\n\t<li>Industrial Gas Turbines \u2013 multiple products and versions<\/li>\n\t<li>Aeroderivative Gas Turbines \u2013 multiple products and versions<\/li>\n\t<li>Solid Edge SE2021 \u2013 versions prior to SE2021MP7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service, arbitrary code execution, data extraction, authentication bypass or the downloading of arbitrary code to a PLC.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Advisories<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-31","alert_type":398,"serial_number":"AV21-384","subject":null,"moderation_state":"published","external_url":null},{"nid":2624,"title":"Microsoft security advisory \u2013 August 2021 monthly rollup","uuid":"7fe3f9d1-e66a-4a13-a2c6-bd3a164ad446","banner":null,"lang":"en","date_modified":"2021-08-10","date_modified_ts":"2021-08-10T19:12:00Z","date_created":"2021-08-10T19:12:00Z","summary":null,"body":["<article data-history-node-id=\"2624\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-385<br \/>\nDate: 10 August 2021<\/strong><\/p>\n\n<p>On 10 August 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 7, 8.1, RT 8.1 and 10<\/li>\n\t<li>Windows Server version 20H2 and version 2004<\/li>\n\t<li>Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016 and 2019<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.<\/p>\n\n<p>Of note, Microsoft has indicated that exploitation has been detected for the following vulnerability:<\/p>\n\n<ul><li>CVE-2021-36948<\/li>\n<\/ul><p>This vulnerability could be used to escalate privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>August 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Aug\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Aug<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0 <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-385","subject":null,"moderation_state":"published","external_url":null},{"nid":2626,"title":"Adobe security advisory","uuid":"22c1b1dd-4173-4eee-b077-ad3c3b603ca0","banner":null,"lang":"en","date_modified":"2021-08-11","date_modified_ts":"2021-08-11T13:45:30Z","date_created":"2021-08-11T13:35:00Z","summary":null,"body":["<article data-history-node-id=\"2626\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-44\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-386<br \/>\nDate: 11 August 2021<\/strong><\/p>\n\n<p>On 10 August 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0Magento Commerce \u2013 versions 2.4.2 and prior<br \/>\n\u2022\u00a0\u00a0 \u00a0Magento Commerce \u2013 versions 2.4.2-p1 and prior<br \/>\n\u2022\u00a0\u00a0 \u00a0Magento Commerce \u2013 versions 2.3.7 and prior<br \/>\n\u2022\u00a0\u00a0 \u00a0Magento Open Source \u2013 versions 2.4.2-p1 and prior<br \/>\n\u2022\u00a0\u00a0 \u00a0Magento Open Source \u2013 versions 2.3.7 and prior<\/p>\n\n<p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Magento Commerce and Magento Open Source (ASPB21-64)<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb21-64.html\">https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb21-64.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-44","alert_type":396,"serial_number":"AV21-386","subject":null,"moderation_state":"published","external_url":null},{"nid":2628,"title":"Intel security advisory","uuid":"2247e533-0f8f-4e94-9bd2-92ac0076a01e","banner":null,"lang":"en","date_modified":"2021-08-11","date_modified_ts":"2021-08-11T13:45:53Z","date_created":"2021-08-11T13:40:46Z","summary":null,"body":["<article data-history-node-id=\"2628\" about=\"\/en\/alerts-advisories\/intel-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-387<br \/>\nDate: 11 August 2021<\/strong><\/p>\n\n<p>On 10 August 2021 Intel published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0Intel NUC 9 Extreme Laptop Kit LAPQC71A \u2013 versions prior to 2.2.0.20<br \/>\n\u2022\u00a0\u00a0 \u00a0Intel NUC 9 Extreme Laptop Kit LAPQC71B - versions prior to 2.2.0.20<br \/>\n\u2022\u00a0\u00a0 \u00a0Intel NUC 9 Extreme Laptop Kit LAPQC71C - versions prior to 2.2.0.20<br \/>\n\u2022\u00a0\u00a0 \u00a0Intel NUC 9 Extreme Laptop Kit LAPQC71D - versions prior to 2.2.0.20<br \/>\n\u2022\u00a0\u00a0 \u00a0Intel Ethernet Controllers X722 and 800 series Linux RMDA driver - versions prior to 1.3.19<br \/>\n\u2022\u00a0\u00a0 \u00a0Intel Ethernet Controllers 800 series Linux driver - versions prior to 1.4.11<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to privilege escalation, denial-of-service and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Intel NUC 9 Extreme Laptop Kit (INTEL-SA-00553)<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00553.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00553.html<\/a><\/p>\n\n<p>Intel Ethernet Controllers (INTEL-SA-00515)<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00515.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00515.html<\/a><\/p>\n\n<p>Intel Product Security Center Advisories<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-18","alert_type":396,"serial_number":"AV21-387","subject":null,"moderation_state":"published","external_url":null},{"nid":2627,"title":"Apple security advisory","uuid":"31907035-c145-46f8-a04b-3dc41eb50965","banner":null,"lang":"en","date_modified":"2021-08-11","date_modified_ts":"2021-08-11T14:55:53Z","date_created":"2021-08-11T14:18:07Z","summary":null,"body":["<article data-history-node-id=\"2627\" about=\"\/en\/alerts-advisories\/apple-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-388<br \/>\nDate: 11 August 2021<\/strong><\/p>\n\n<p>On 9 August 2021 Apple published a Security Update to address vulnerabilities in the following product:\u00a0\u00a0 iTunes for Windows \u2013 versions prior to 12.11.4<\/p>\n\n<p>Exploitation of these vulnerabilities could allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary update.<\/p>\n\n<ul><li>iTunes for Windows<\/li>\n<\/ul><p><a href=\"https:\/\/support.apple.com\/en-ca\/HT212609\">https:\/\/support.apple.com\/en-ca\/HT212609<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-36","alert_type":396,"serial_number":"AV21-388","subject":null,"moderation_state":"published","external_url":null},{"nid":2629,"title":"Mozilla security advisory","uuid":"59f62252-f2e1-4730-99c9-b6ef544099e5","banner":null,"lang":"en","date_modified":"2021-08-11","date_modified_ts":"2021-08-11T15:58:48Z","date_created":"2021-08-11T15:43:42Z","summary":null,"body":["<article data-history-node-id=\"2629\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-41\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-389<br \/>\nDate: 11 August 2021<\/strong><\/p>\n\n<p>On 10 August 2021 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 78.13<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in a denial-of-service or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Thunderbird (MFSA 2021-35)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-35\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-35\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-41","alert_type":396,"serial_number":"AV21-389","subject":null,"moderation_state":"published","external_url":null},{"nid":2630,"title":"Dell security advisory","uuid":"925c67ca-bc3a-4f02-8c29-cb402ccd07e0","banner":null,"lang":"en","date_modified":"2021-08-11","date_modified_ts":"2021-08-11T20:05:50Z","date_created":"2021-08-11T19:45:14Z","summary":null,"body":["<article data-history-node-id=\"2630\" about=\"\/en\/alerts-advisories\/dell-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-390<br \/>\nDate: 11 August 2021<\/strong><\/p>\n\n<p>On 9 August 2021 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell PowerScale OneFS \u2013 versions 8.2.x to 9.2.x.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Dell PowerScale OneFS (DSA-2021-142)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000190408\/dsa-2021-142-dell-powerscale-onefs-security-update-for-multiple-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000190408\/dsa-2021-142-dell-powerscale-onefs-security-update-for-multiple-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-6","alert_type":396,"serial_number":"AV21-390","subject":null,"moderation_state":"published","external_url":null},{"nid":2631,"title":"Palo Alto Networks security advisory","uuid":"2856a0d9-c5b8-4abe-a2e2-5d5ed5dae35e","banner":null,"lang":"en","date_modified":"2021-08-12","date_modified_ts":"2021-08-12T15:07:01Z","date_created":"2021-08-12T15:07:01Z","summary":null,"body":["<article data-history-node-id=\"2631\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-391<br \/>\nDate: 12 August 2021<\/strong><\/p>\n\n<p>On 11 August 2021 Palo Alto Networks published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>PAN-OS 9.0 - versions 9.0.10 to 9.0.14<\/li>\n\t<li>PAN-OS 9.1 - versions 9.1.4 to 9.1.10<\/li>\n\t<li>PAN-OS 10.0 - version 10.0.7 and prior<\/li>\n\t<li>PAN-OS 10.1 - versions 10.1.0 to 10.1.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary command execution. Palo Alto Networks has indicated it is aware that public exploit code exists for this vulnerability, but that it is not aware of any active exploitation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, implement the recommended mitigations and apply the necessary updates when available.<\/p>\n\n<p>Palo Alto Networks Security Advisory (CVE-2021-3050)<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3050\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3050<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-10","alert_type":396,"serial_number":"AV21-391","subject":null,"moderation_state":"published","external_url":null},{"nid":2632,"title":"Mozilla security advisory","uuid":"dd7055de-051a-4990-b609-9d905ab91d0c","banner":null,"lang":"en","date_modified":"2021-08-12","date_modified_ts":"2021-08-12T18:08:47Z","date_created":"2021-08-12T18:04:49Z","summary":null,"body":["<article data-history-node-id=\"2632\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-42\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-392<br \/>\nDate: 12 August 2021<\/strong><\/p>\n\n<p>On 11 August 2021 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 91<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in a denial-of-service or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Thunderbird (MFSA 2021-36)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-36\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-36\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-42","alert_type":396,"serial_number":"AV21-392","subject":null,"moderation_state":"published","external_url":null},{"nid":2706,"title":"Ongoing Vulnerabilities Involving Windows Print Spooler - UPDATE 1","uuid":"a33b4c06-9d57-44fc-a0bd-d090c97ea463","banner":null,"lang":"en","date_modified":"2021-09-15","date_modified_ts":"2021-09-15T18:56:10Z","date_created":"2021-08-12T19:46:32Z","summary":null,"body":["<article data-history-node-id=\"2706\" about=\"\/en\/alerts-advisories\/ongoing-vulnerabilities-involving-windows-print-spooler\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-016 UPDATE 1\n  <br \/>\n  Date: 12 August 2021\n  <br \/>\n  Updated: 15 September 2021<\/strong><strong> <\/strong>\n<\/p>\n<h2>AUDIENCE\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>PURPOSE\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>OVERVIEW\n<\/h2>\n<p>Microsoft has published a knowledge base article describing CVE-2021-36958 [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36958\">1<\/a>], a new local privilege escalation vulnerability involving the Windows Print Spooler service. There is no patch available for this vulnerability at the time of this publication. Workarounds have been provided by Microsoft.\n<\/p>\n<h2>DETAILS\n<\/h2>\n<p>On 11 August 2021 Microsoft published a knowledge base article [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36958\">1<\/a>] describing CVE-2021-36958, a local privilege escalation vulnerability in which the Windows Print Spooler service improperly performs privileged file operations. An actor exploiting this vulnerability could run arbitrary code with SYSTEM privileges. The actor could then install programs; view, change, or delete data; or create new accounts with full user rights.\n<\/p>\n<p>As reported in the Cyber Centre Alert AL21-011 [<a href=\"\/en\/alerts-advisories\/windows-print-spooler-vulnerability-remains-unpatched\">2<\/a>] and the Cyber Centre Alert AL21-015 [<a href=\"\/en\/alerts-advisories\/alerts\/vulnerability-windows-print-spooler-service\">3<\/a>], the Windows Print Spooler has been the source of several recent vulnerabilities. CVE-2021-36958 is the latest addition to the PrintNightmare group of vulnerabilities.\n<\/p>\n<p>There have been multiple names used in open-source channels to describe this current vulnerability before CVE-2021-36958 was provided, including \u201cPrintNightmare v4\u201d and \u201cSystemNightmare\u201d. Additionally, CERT\/CC has published Vulnerability Note VU#131152 [<a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/131152\">4<\/a>] to detail information about this vulnerability.\n<\/p>\n<p>The Cyber Centre is aware that a proof of concept exists.\n<\/p>\n<h2>MITIGATION\n<\/h2>\n<p>\n  <br \/><strong>UPDATE 1<\/strong>\n<\/p>\n<p>On 14 September 2021, a patch for CVE-2021-36958 was released as part of the September 2021 Security Updates [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36958\">1<\/a>].\n<\/p>\n<p><s>There is currently no patch available for CVE-2021-36958. The workaround provided by Microsoft is to stop and disable the Print Spooler service [1]. This will impede the ability to print.<\/s>\n  <br \/>\n  \u00a0\n  <br \/>\n  Windows updates have been published for the other vulnerabilities related to the Windows Print Spooler. Refer to the previously released Cyber Centre Alerts [<a href=\"\/en\/alerts-advisories\/en\/alerts\/windows-print-spooler-vulnerability-remains-unpatched\">2<\/a>][<a href=\"\/en\/alerts-advisories\/en\/alerts\/vulnerability-windows-print-spooler-service\">3<\/a>] for more information.\n<\/p>\n<h2>REFERENCES\n<\/h2>\n<p>[1] <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36958\">Windows KB Article \u2013 CVE-2021-36958<\/a>\n<\/p>\n<p>[2] <a href=\"\/en\/alerts-advisories\/en\/alerts\/windows-print-spooler-vulnerability-remains-unpatched\">Cyber Centre Alert AL21-011<\/a>\n<\/p>\n<p>[3] <a href=\"\/en\/alerts-advisories\/en\/alerts\/vulnerability-windows-print-spooler-service\">Cyber Centre Alert AL21-015<\/a>\n<\/p>\n<p>[4] <a href=\"https:\/\/www.kb.cert.org\/vuls\/id\/131152\">CERT\/CC VU#131152<\/a>\n<\/p>\n<p>\u00a0\n<\/p>\n<p><strong>NOTE TO READERS<\/strong>\n  <br \/><br \/>\n  The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\n<\/p>\n<p>\u00a0\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ongoing-vulnerabilities-involving-windows-print-spooler","alert_type":397,"serial_number":"AL21-016","subject":null,"moderation_state":"published","external_url":null},{"nid":2634,"title":"[Control systems] Cognex security advisory","uuid":"2f8e4d01-2cb2-4444-86ba-ac1f6938f04d","banner":null,"lang":"en","date_modified":"2021-08-13","date_modified_ts":"2021-08-13T14:28:10Z","date_created":"2021-08-13T13:52:32Z","summary":null,"body":["<article data-history-node-id=\"2634\" about=\"\/en\/alerts-advisories\/control-systems-cognex-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-393<br \/>\nDate: 13 August 2021<\/strong><\/p>\n\n<p>On 12 August 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>In-Sight OPC Server - version 5.7.4 (96) and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor access to system level permissions and local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-224-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-224-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-224-01<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cognex-security-advisory","alert_type":398,"serial_number":"AV21-393","subject":null,"moderation_state":"published","external_url":null},{"nid":2633,"title":"[Control systems] Horner Automation security advisory","uuid":"635a6db3-5916-4f6a-a2ed-c7a4aebf4941","banner":null,"lang":"en","date_modified":"2021-08-13","date_modified_ts":"2021-08-13T14:26:54Z","date_created":"2021-08-13T13:54:54Z","summary":null,"body":["<article data-history-node-id=\"2633\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-394<br \/>\nDate: 13 August 2021<\/strong><\/p>\n\n<p>On 12 August 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Cscape - versions prior to 9.90 SP5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow code execution in the context of the current process.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-224-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-224-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-224-02<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-2","alert_type":398,"serial_number":"AV21-394","subject":null,"moderation_state":"published","external_url":null},{"nid":2635,"title":"[Control systems] Schneider Electric security advisory ","uuid":"ff1fa75d-0ccd-4c07-86d5-15ada29e949d","banner":null,"lang":"en","date_modified":"2021-08-13","date_modified_ts":"2021-08-13T17:31:59Z","date_created":"2021-08-13T13:58:02Z","summary":null,"body":["<article data-history-node-id=\"2635\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-395<br \/>\nDate: 13\u00a0August\u00a02021<\/strong><\/p>\n\n<p>On 10\u00a0August\u00a02021\u00a0Schneider Electric\u00a0published\u00a0Security Notifications\u00a0to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Harmony\/Magelis\u00a0HMI Products configured by\u00a0Vijeo\u00a0Designer,\u00a0Vijeo\u00a0Designer Basic and\u00a0EcoStruxure\u00a0Machine Expert \u2013 multiple products and versions\u00a0<\/li>\n\t<li>EcoStruxure\u00a0Control Expert\u00a0-\u00a0all versions (including former Unity Pro)\u00a0\u00a0<\/li>\n\t<li>EcoStruxure\u00a0Process Expert\u00a0-\u00a0all versions (including former HDCS)\u00a0<\/li>\n\t<li>SCADAPack\u00a0RemoteConnect\u00a0for x70\u00a0<\/li>\n\t<li>GP-Pro EX \u2013 version\u00a0V4.09.250 and prior\u00a0<\/li>\n\t<li>Modicon PAC Controllers and PLC Simulator for\u00a0EcoStruxure\u00a0Control Expert and\u00a0EcoStruxure\u00a0Process Expert \u2013 multiple products and versions\u00a0<\/li>\n\t<li>AccuSine\u00a0PCS+ \/ PFV+ - versions prior to V1.6.7\u00a0\u00a0<\/li>\n\t<li>AccuSine\u00a0PCSn\u00a0- versions prior to V2.2.4\u00a0<\/li>\n\t<li>Programmable Automation Controller (PacDrive) M - all versions\u00a0<\/li>\n\t<li>NTZ\u00a0Mekhanotronika\u00a0Rus. LLC SHAIIS-MT-111, SHASU-MT-107 and SHFK-MT, and SHFK-MT-104 Control Panels \u2013 multiple products and versions\u00a0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\u00a0<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal <a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\" target=\"_blank\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><br \/><br \/><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber\u00a0security\u00a0and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and\u00a0support, and\u00a0coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-25","alert_type":398,"serial_number":"AV21-395","subject":null,"moderation_state":"published","external_url":null},{"nid":2636,"title":"IBM security advisory","uuid":"d5b851eb-fee1-4f8d-ae0a-9236c1b82e94","banner":null,"lang":"en","date_modified":"2021-08-16","date_modified_ts":"2021-08-16T13:49:47Z","date_created":"2021-08-16T13:49:47Z","summary":null,"body":["<article data-history-node-id=\"2636\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-60\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-396<br \/>\nDate: 16 August 2021<\/strong><\/p>\n\n<p>Between 2 and 15 August 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Security Guardium \u2013 versions 11.1, 11.2 and 11.3<\/li>\n\t<li>Partner Engagement Manager \u2013 version 2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Security Guardium<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-6\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-6\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-jackson-databind-vulnerability-8\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-jackson-databind-vulnerability-8\/<\/a><\/p>\n\n<p>IBM Partner Engagement Manager<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-de-serialization-vulnerability-affects-ibm-partner-engagement-manager-cve-2021-29781-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-de-serialization-vulnerability-affects-ibm-partner-engagement-manager-cve-2021-29781-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-60","alert_type":396,"serial_number":"AV21-396","subject":null,"moderation_state":"published","external_url":null},{"nid":2637,"title":"Apple security advisory","uuid":"9f9322f3-1e0e-49c8-89b6-8ae9ccffb09d","banner":null,"lang":"en","date_modified":"2021-08-16","date_modified_ts":"2021-08-16T19:25:36Z","date_created":"2021-08-16T19:25:36Z","summary":null,"body":["<article data-history-node-id=\"2637\" about=\"\/en\/alerts-advisories\/apple-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-397<br \/>\nDate: 16 August 2021<\/strong><\/p>\n\n<p>On 16 August 2021 Apple published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>iCloud for Windows \u2013 versions prior to 12.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary update.<\/p>\n\n<p>iCloud for Windows<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212607\">https:\/\/support.apple.com\/en-ca\/HT212607<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-37","alert_type":396,"serial_number":"AV21-397","subject":null,"moderation_state":"published","external_url":null},{"nid":2638,"title":"HPE security advisory","uuid":"865437db-1524-4229-8fc6-fb294ca236bc","banner":null,"lang":"en","date_modified":"2021-08-17","date_modified_ts":"2021-08-17T13:24:57Z","date_created":"2021-08-17T13:24:57Z","summary":null,"body":["<article data-history-node-id=\"2638\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-398<br \/>\nDate: 17 August 2021<\/strong><\/p>\n\n<p>On 16 August 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Integrity MC990 X Server - versions prior to firmware bundle 2021.07<\/li>\n\t<li>SGI UV 300, 300H, 300RL, 30EX \u2013 versions prior to firmware and diagnostic software 2021.07<\/li>\n\t<li>SGI UV 3000 \u2013 versions prior to firmware and diagnostic software 2021.06<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>HPE SGI UV 300\/3000 and Integrity MC990 X (HPESBHF04187)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04187en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04187en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-26","alert_type":396,"serial_number":"AV21-398","subject":null,"moderation_state":"published","external_url":null},{"nid":2639,"title":"Google Chrome security advisory","uuid":"3ff7f7e4-ca27-4bb2-a8f1-55e21efc14df","banner":null,"lang":"en","date_modified":"2021-08-17","date_modified_ts":"2021-08-17T14:54:22Z","date_created":"2021-08-17T14:54:22Z","summary":null,"body":["<article data-history-node-id=\"2639\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-63\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-399<br \/>\nDate: 17 August 2021<\/strong><\/p>\n\n<p>On 16 August 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 92.0.4515.159<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/08\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/08\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-63","alert_type":396,"serial_number":"AV21-399","subject":null,"moderation_state":"published","external_url":null},{"nid":2640,"title":"Ubuntu security advisory","uuid":"bcf95bdf-27e1-4c6a-9023-34e25debfff9","banner":null,"lang":"en","date_modified":"2021-08-17","date_modified_ts":"2021-08-17T14:58:08Z","date_created":"2021-08-17T14:58:08Z","summary":null,"body":["<article data-history-node-id=\"2640\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-400<br \/>\nDate: 17 August 2021<\/strong><\/p>\n\n<p>On 16 August 2021 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in execution of arbitrary code or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (LSN-0080-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0080-1\">https:\/\/ubuntu.com\/security\/notices\/LSN-0080-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-19","alert_type":396,"serial_number":"AV21-400","subject":null,"moderation_state":"published","external_url":null},{"nid":2641,"title":"[Control systems] BlackBerry QNX security advisory","uuid":"47f6afe5-f13c-4b46-a7da-dbdfbc8d0c17","banner":null,"lang":"en","date_modified":"2021-08-17","date_modified_ts":"2021-08-17T17:37:17Z","date_created":"2021-08-17T17:32:50Z","summary":null,"body":["<article data-history-node-id=\"2641\" about=\"\/en\/alerts-advisories\/control-systems-blackberry-qnx-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-401<br \/>\nDate: 17 August 2021<\/strong><\/p>\n\n<p>On 17 August, BlackBerry published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BlackBerry QNX Software Development Platform \u2013 version 6.5.0SP1 and prior<\/li>\n\t<li>QNX OS for Medical \u2013 version 1.1 and prior<\/li>\n\t<li>QNX OS for Safety \u2013 version 1.0.1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary memory allocation, resulting in unexpected behavior such as a denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>BlackBerry QNX Advisory (KB 82334)<\/p>\n\n<p><a href=\"https:\/\/support.blackberry.com\/kb\/articleDetail?articleNumber=000082334\">https:\/\/support.blackberry.com\/kb\/articleDetail?articleNumber=000082334<\/a><\/p>\n\n<p>ICS Advisory (ICSA-AA21-229A)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-229a\">https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-229a<\/a><\/p>\n\n<p>CCCS \u2013 Multiple RTOS Security Vulnerabilities (AV21-198)<\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/control-systems-multiple-rtos-security-vulnerabilities\">https:\/\/cyber.gc.ca\/en\/alerts\/control-systems-multiple-rtos-security-vulnerabilities<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-blackberry-qnx-security-advisory","alert_type":398,"serial_number":"AV21-401","subject":null,"moderation_state":"published","external_url":null},{"nid":2643,"title":"[Control systems] xArrow security advisory","uuid":"37b279a0-1ebc-41fb-a3d1-d603dcce179b","banner":null,"lang":"en","date_modified":"2021-08-18","date_modified_ts":"2021-08-18T13:25:21Z","date_created":"2021-08-18T13:25:21Z","summary":null,"body":["<article data-history-node-id=\"2643\" about=\"\/en\/alerts-advisories\/control-systems-xarrow-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-402<br \/>\nDate: 18 August 2021<\/strong><\/p>\n\n<p>On 17 August 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>xArrow (SCADA\/HMI) - version 7.2 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-229-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-229-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-229-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-xarrow-security-advisory","alert_type":398,"serial_number":"AV21-402","subject":null,"moderation_state":"published","external_url":null},{"nid":2644,"title":"Mozilla security advisory","uuid":"2b8075a3-0c4a-419d-95e3-6bb8c893c92b","banner":null,"lang":"en","date_modified":"2021-08-18","date_modified_ts":"2021-08-18T13:29:46Z","date_created":"2021-08-18T13:29:46Z","summary":null,"body":["<article data-history-node-id=\"2644\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-43\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-403<br \/>\nDate: 18 August 2021<\/strong><\/p>\n\n<p>On 16 August 2021 Mozilla published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 91.0.1<\/li>\n\t<li>Thunderbird \u2013 versions prior to 91.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Firefox, Thunderbird (MFSA 2021-37)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-37\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-37\/<\/a><\/p>\n\n<p><strong>Note to Reader<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-43","alert_type":396,"serial_number":"AV21-403","subject":null,"moderation_state":"published","external_url":null},{"nid":2646,"title":"[Control systems] Advantech security advisory","uuid":"a3a4ecba-0a60-495d-b900-12a18bfacafd","banner":null,"lang":"en","date_modified":"2021-08-18","date_modified_ts":"2021-08-18T14:00:50Z","date_created":"2021-08-18T13:51:50Z","summary":null,"body":["<article data-history-node-id=\"2646\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-404<br \/>\nDate: 18 August 2021<\/strong><o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\">On 17 August 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<o:p><\/o:p><\/p>\n\n<p class=\"MsoListParagraph\" style=\"text-indent: -0.25in;\"><!--[if !supportLists]--><span style=\"font-family:&quot;Cambria&quot;,serif;mso-ascii-theme-font:minor-latin;mso-hansi-theme-font:&#10;minor-latin\"><o:p><\/o:p><\/span><\/p>\n\n<ul><li>WebAccess\/NMS - versions prior to v3.0.3_Build6299<\/li>\n<\/ul><p class=\"MsoNormal\">Exploitation of this vulnerability could result in information disclosure.<span style=\"mso-fareast-font-family:&quot;MS Mincho&quot;\"><o:p><\/o:p><\/span><\/p>\n\n<p class=\"MsoNormal\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\">ICS Advisory (ICSA-21-229-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-229-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-229-02<\/a><br \/><br \/><strong>Note to Readers<\/strong><o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\">The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<o:p><\/o:p><\/p>\n\n<p class=\"MsoNormal\"><o:p>\u00a0<\/o:p><\/p>\n\n<p class=\"MsoNormal\"><o:p>\u00a0<\/o:p><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-20","alert_type":398,"serial_number":"AV21-404","subject":null,"moderation_state":"published","external_url":null},{"nid":2645,"title":"[Control systems] ThroughTek security advisory","uuid":"67730ba6-ff82-4805-b1db-71a5bd334818","banner":null,"lang":"en","date_modified":"2021-08-18","date_modified_ts":"2021-08-18T13:56:15Z","date_created":"2021-08-18T13:56:15Z","summary":null,"body":["<article data-history-node-id=\"2645\" about=\"\/en\/alerts-advisories\/control-systems-throughtek-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-405<br \/>\nDate: 18 August 2021<\/strong><\/p>\n\n<p>On 17 August 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Kalay P2P Software Development Kit (SDK) \u2013 versions:\n\t<ul><li>3.1.5 and prior<\/li>\n\t\t<li>SDK versions with the nossl tag<\/li>\n\t\t<li>device firmware that does not use AuthKey for IOTC connection<\/li>\n\t\t<li>device firmware using the AVAPI module without enabling DTLS mechanism<\/li>\n\t\t<li>device firmware using P2PTunnel or RDT module<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution or unauthorized access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-229-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-229-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-229-01<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-throughtek-security-advisory-0","alert_type":398,"serial_number":"AV21-405","subject":null,"moderation_state":"published","external_url":null},{"nid":2647,"title":"Adobe security advisory","uuid":"17bfbd5a-1466-437b-b120-a5ce982bc3d1","banner":null,"lang":"en","date_modified":"2021-08-18","date_modified_ts":"2021-08-18T14:07:36Z","date_created":"2021-08-18T14:04:21Z","summary":null,"body":["<article data-history-node-id=\"2647\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-45\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-406<br \/>\nDate: 18 August 2021<\/strong><\/p>\n\n<p>On 17 August 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe Media Encoder \u2013 versions 15.4 and prior<\/li>\n\t<li>Adobe Bridge \u2013 versions 11.1 and prior<\/li>\n\t<li>Adobe Photoshop 2020 \u2013 versions 21.2.10 and prior<\/li>\n\t<li>Adobe Photoshop 2021 \u2013 versions 22.4.3 and prior<\/li>\n\t<li>Adobe XMP-Toolkit-SDK \u2013 versions 2020.1 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution, memory leak, denial-of-service or arbitrary file system read.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Adobe Media Encoder (APSB21-70)<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb21-70.html\">https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb21-70.html<\/a><\/p>\n\n<p>Adobe Bridge (APSB21-69)<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb21-69.html\">https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb21-69.html<\/a><\/p>\n\n<p>Adobe Photoshop (APSB21-68)<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb21-68.html\">https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb21-68.html<\/a><\/p>\n\n<p>Adobe\u00a0XMP Toolkit SDK (APSB21-65)<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/xmpcore\/apsb21-65.html\">https:\/\/helpx.adobe.com\/security\/products\/xmpcore\/apsb21-65.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-45","alert_type":396,"serial_number":"AV21-406","subject":null,"moderation_state":"published","external_url":null},{"nid":2648,"title":"Dell security advisory","uuid":"c95fb92d-49f9-40e6-85de-60c46bbd5ed3","banner":null,"lang":"en","date_modified":"2021-08-18","date_modified_ts":"2021-08-18T16:05:31Z","date_created":"2021-08-18T15:10:56Z","summary":null,"body":["<article data-history-node-id=\"2648\" about=\"\/en\/alerts-advisories\/dell-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-407<br \/>\nDate: 18 August 2021<\/strong><\/p>\n\n<p>On 17 August 2021 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0\u00a0Dell EMC Unisphere Central \u2013 versions prior to 4.0.9.1402238<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to compromise of the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Dell EMC Unisphere Central (DSA-2021-171)<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000190602\/dsa-2021-171-dell-emc-unisphere-central-security-update-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000190602\/dsa-2021-171-dell-emc-unisphere-central-security-update-for-multiple-third-party-component-vulnerabilities<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-7","alert_type":396,"serial_number":"AV21-407","subject":null,"moderation_state":"published","external_url":null},{"nid":2649,"title":"Ubuntu security advisory","uuid":"934d9b65-e145-4193-8fc3-b2a153e81e2c","banner":null,"lang":"en","date_modified":"2021-08-18","date_modified_ts":"2021-08-18T18:01:34Z","date_created":"2021-08-18T18:01:34Z","summary":null,"body":["<article data-history-node-id=\"2649\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-408<br \/>\nDate: 18 August 2021<\/strong><\/p>\n\n<p>On 18 August 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in exposure of sensitive information, denial of service or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5044-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5044-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5044-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5045-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5045-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5045-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5046-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5046-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5046-1<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-20","alert_type":396,"serial_number":"AV21-408","subject":null,"moderation_state":"published","external_url":null},{"nid":2651,"title":"[Control systems] Siemens security advisory","uuid":"da8e2427-6071-4dc6-95a6-c2c1ec26d551","banner":null,"lang":"en","date_modified":"2021-08-19","date_modified_ts":"2021-08-19T15:47:13Z","date_created":"2021-08-19T15:02:53Z","summary":null,"body":["<article data-history-node-id=\"2651\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-409<br \/>\nDate: 19 August 2021<\/strong><\/p>\n\n<p>On 19 August 2021 Siemens published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SINEMA Remote Connect Client \u2013 versions prior to V3.0 SP1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow privilege escalation or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>SINEMA Remote Connect Client<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-816035.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-816035.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-32","alert_type":398,"serial_number":"AV21-409","subject":null,"moderation_state":"published","external_url":null},{"nid":2650,"title":"Fortinet security advisory","uuid":"47c0a20f-ea03-4d20-8e54-a7286112d644","banner":null,"lang":"en","date_modified":"2021-08-19","date_modified_ts":"2021-08-19T15:05:53Z","date_created":"2021-08-19T15:05:53Z","summary":null,"body":["<article data-history-node-id=\"2650\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-410<br \/>\nDate: 19 August 2021<\/strong><\/p>\n\n<p>On 18 August 2021 Fortinet published a PSIRT Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>FortiWeb \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may allow arbitrary commands to be executed.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>PSIRT Advisory (FG-IR-21-116)<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-116\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-116<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-11","alert_type":396,"serial_number":"AV21-410","subject":null,"moderation_state":"published","external_url":null},{"nid":2652,"title":"ISC BIND security advisory","uuid":"f6a6b1e9-6561-4de9-b08b-d79154566952","banner":null,"lang":"en","date_modified":"2021-08-19","date_modified_ts":"2021-08-19T18:12:28Z","date_created":"2021-08-19T18:04:43Z","summary":null,"body":["<article data-history-node-id=\"2652\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-411<br \/>\nDate: 19 August 2021<\/strong><\/p>\n\n<p>On 18 August 2021 ISC published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ISC BIND 9 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>CVE-2021-25218<\/p>\n\n<p><a href=\"https:\/\/kb.isc.org\/v1\/docs\/cve-2021-25218\">https:\/\/kb.isc.org\/v1\/docs\/cve-2021-25218<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-0","alert_type":396,"serial_number":"AV21-411","subject":null,"moderation_state":"published","external_url":null},{"nid":2653,"title":"[Control systems] AVEVA Software security advisory","uuid":"9fa6c529-89d7-42fa-9801-7691e05dde6b","banner":null,"lang":"en","date_modified":"2021-08-19","date_modified_ts":"2021-08-19T18:21:17Z","date_created":"2021-08-19T18:21:17Z","summary":null,"body":["<article data-history-node-id=\"2653\" about=\"\/en\/alerts-advisories\/control-systems-aveva-software-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-412<br \/>\nDate: 19 August 2021<\/strong><\/p>\n\n<p>On 19 August 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA System Platform \u2013 version 2020 R2 P01 and prior<\/li>\n\t<li>AVEVA InTouch \u2013 version 2020 R2 P01 and prior<\/li>\n\t<li>AVEVA Historian \u2013 version 2020 R2 P01 and prior<\/li>\n\t<li>AVEVA Communication Drivers Pack \u2013 version 2020 R2 and prior<\/li>\n\t<li>AVEVA Operations Integration Core \u2013 version 3.0 and prior<\/li>\n\t<li>AVEVA Data Acquisition Servers - all versions<\/li>\n\t<li>AVEVA Batch Management \u2013 version 2020 and prior<\/li>\n\t<li>AVEVA MES \u2013 version 2014 R2 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could cause denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-231-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-231-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-231-01<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-software-security-advisory-0","alert_type":398,"serial_number":"AV21-412","subject":null,"moderation_state":"published","external_url":null},{"nid":2654,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"5a027cc3-8444-4d9c-98f1-eacb77a68402","banner":null,"lang":"en","date_modified":"2021-08-19","date_modified_ts":"2021-08-19T19:47:32Z","date_created":"2021-08-19T19:47:32Z","summary":null,"body":["<article data-history-node-id=\"2654\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-413<br \/>\nDate: 19 August 2021<\/strong><\/p>\n\n<p>On 19 August 2021 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 92.0.902.78<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-19-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-19-2021<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\">https:\/\/msrc.microsoft.com\/update-guide\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-1","alert_type":396,"serial_number":"AV21-413","subject":null,"moderation_state":"published","external_url":null},{"nid":2655,"title":"IBM security advisory","uuid":"322604ba-13e4-4ea2-922f-95a037c3ce14","banner":null,"lang":"en","date_modified":"2021-08-23","date_modified_ts":"2021-08-23T15:56:08Z","date_created":"2021-08-23T15:56:08Z","summary":null,"body":["<article data-history-node-id=\"2655\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-61\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-414<br \/>\nDate: 23 August 2021<\/strong><\/p>\n\n<p>Between 16 and 22 August 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Integration Bus \u2013 versions V10.0.0.0 to V10.0.0.23<\/li>\n\t<li>IBM App Connect Enterprise \u2013 versions V11.0.0.0 to V11.0.0.13 and 12.0.1.0<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management \u2013 versions 2.2 and 2.3<\/li>\n\t<li>IBM Security Directory Server \u2013 version 6.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Integration Bus &amp; IBM App Connect Enterprise<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-4\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-4\/<\/a><\/p>\n\n<p>IBM Cloud Pak for Multicloud Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-multicloud-management-monitoring-has-applied-security-fixes-for-its-use-of-golang-go\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cloud-pak-for-multicloud-management-monitoring-has-applied-security-fixes-for-its-use-of-golang-go\/<\/a><\/p>\n\n<p>IBM Security Directory Server<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-security-directory-server-4\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-security-directory-server-4\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-61","alert_type":396,"serial_number":"AV21-414","subject":null,"moderation_state":"published","external_url":null},{"nid":2656,"title":"Ongoing Exploitation of ProxyShell Exploit Chain ","uuid":"8e711831-feab-4299-bb33-9f1a18d759a3","banner":null,"lang":"en","date_modified":"2021-08-24","date_modified_ts":"2021-08-24T16:50:38Z","date_created":"2021-08-24T16:50:03Z","summary":null,"body":["<article data-history-node-id=\"2656\" about=\"\/en\/alerts-advisories\/ongoing-exploitation-proxyshell-exploit-chain\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-017<br \/>\nDate: 24 August 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>The Cyber Centre is aware of ongoing scanning and exploitation of the ProxyShell exploit chain affecting unpatched Microsoft Exchange Servers. Microsoft has previously released updates to remediate these vulnerabilities in April and May of 2021.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>The Cyber Centre is aware of ongoing scanning and exploitation of the ProxyShell exploit chain affecting unpatched Microsoft Exchange Servers. There are three vulnerabilities involved in the ProxyShell exploit chain:<\/p>\n\n<ul><li>CVE-2021-34473 [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34473\">1<\/a>]<\/li>\n\t<li>CVE-2021-34523 [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34523  \">2<\/a>]<\/li>\n\t<li>CVE-2021-31207 [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-31207  \">3<\/a>]<\/li>\n<\/ul><p>Microsoft released updates for these vulnerabilities as part of their April 2021 and May 2021 monthly security updates [<a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2021-monthly-rollup\">4<\/a>][<a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2021-monthly-rollup\">5<\/a>][<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-may-2021-exchange-server-security-updates\/ba-p\/2335209  \">6<\/a>].<\/p>\n\n<p>ProxyShell exploits a vulnerability in the Microsoft Exchange Autodiscover service to access an arbitrary backend URL leading to access as a privileged user on the system. A malicious actor can leverage ProxyShell to gain full control of the affected system.<\/p>\n\n<p>The Cyber Centre is aware of publicly available exploit code.<\/p>\n\n<h2>MITIGATION<\/h2>\n\n<p>Microsoft released updates for these vulnerabilities as part of their April 2021 and May 2021 monthly security updates [<a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2021-monthly-rollup\">4<\/a>][<a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2021-monthly-rollup\">5<\/a>][<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-may-2021-exchange-server-security-updates\/ba-p\/2335209  \">6<\/a>].<\/p>\n\n<p>The Cyber Centre strongly encourages organizations to immediately apply the outstanding updates for these vulnerabilities and check for signs of anomalous activity.<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34473\">Windows KB Article \u2013 CVE-2021-34473<\/a><\/p>\n\n<p>[2] <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34523\">Windows KB Article \u2013 CVE-2021-34523\u00a0<\/a><\/p>\n\n<p>[3] <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-31207\">Windows KB Article \u2013 CVE-2021-31207<\/a><\/p>\n\n<p>[4] <a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2021-monthly-rollup\">Microsoft Security Advisory \u2013 April 2021 Monthly Rollup (Cyber Centre Advisory AV21-157)<\/a><\/p>\n\n<p>[5] <a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2021-monthly-rollup\">Microsoft Security Advisory \u2013 May 2021 Monthly Rollup (Cyber Centre Advisory AV21-219)<\/a><\/p>\n\n<p>[6] <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-may-2021-exchange-server-security-updates\/ba-p\/2335209\">Microsoft Exchange Team Blog - May 2021 Exchange Server Security Updates<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n(The English version precedes)<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ongoing-exploitation-proxyshell-exploit-chain","alert_type":397,"serial_number":"AL21-017","subject":null,"moderation_state":"published","external_url":null},{"nid":2657,"title":"[Control systems] Delta Electronics security advisory","uuid":"c10c82c0-3d09-4d86-b5bc-041ab394ce5f","banner":null,"lang":"en","date_modified":"2021-08-25","date_modified_ts":"2021-08-25T12:35:32Z","date_created":"2021-08-25T12:11:08Z","summary":null,"body":["<article data-history-node-id=\"2657\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-415<br \/>\nDate: 25 August 2021<\/strong><\/p>\n\n<p>On 24 August 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>TPEditor - version v1.98.06 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-236-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-236-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-236-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-9","alert_type":398,"serial_number":"AV21-415","subject":null,"moderation_state":"published","external_url":null},{"nid":2658,"title":"Ubuntu security advisory","uuid":"c0a67602-efcb-4533-8976-bc80bad62e9c","banner":null,"lang":"en","date_modified":"2021-08-25","date_modified_ts":"2021-08-25T12:37:30Z","date_created":"2021-08-25T12:15:34Z","summary":null,"body":["<article data-history-node-id=\"2658\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-416<br \/>\nDate: 25 August 2021<\/strong><\/p>\n\n<p>On 24 August 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.04<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in exposure of sensitive information, denial of service or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5051-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5051-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5051-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-21","alert_type":396,"serial_number":"AV21-416","subject":null,"moderation_state":"published","external_url":null},{"nid":2659,"title":"[Control systems] Hitachi ABB Power Grids security advisory","uuid":"934dfb99-70ed-4fa1-8461-964f3db8c3b7","banner":null,"lang":"en","date_modified":"2021-08-25","date_modified_ts":"2021-08-25T12:59:29Z","date_created":"2021-08-25T12:59:29Z","summary":null,"body":["<article data-history-node-id=\"2659\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-417<br \/>\nDate: 25 August 2021<\/strong><\/p>\n\n<p>On 24 August 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Retail Operations - version 5.7.2 and prior<\/li>\n\t<li>Counterparty Settlement and Billing (CSB) \u2013 version 5.7.2 and prior<\/li>\n\t<li>TropOS - version 8.9.4.8 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to access database credentials, shut down the product, and access or alter system data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-236-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-236-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-236-01<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-236-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-236-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-236-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-4","alert_type":398,"serial_number":"AV21-417","subject":null,"moderation_state":"published","external_url":null},{"nid":2660,"title":"VMware security advisory","uuid":"d36c7cfc-e0f6-4970-a143-4a4e536d0ed8","banner":null,"lang":"en","date_modified":"2021-08-25","date_modified_ts":"2021-08-25T15:11:19Z","date_created":"2021-08-25T15:11:19Z","summary":null,"body":["<article data-history-node-id=\"2660\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-45\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-418<br \/>\nDate: 25 August 2021<\/strong><\/p>\n\n<p>On 24 August 2021 VMware published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware vRealize Operations Manager \u2013 multiple versions<\/li>\n\t<li>VMware Cloud Foundation - versions 3.x and 4.x<\/li>\n\t<li>vRealize Suite Lifecycle Manager \u2013 version 8.x<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to unauthenticated API access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0018)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0018.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0018.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-45","alert_type":396,"serial_number":"AV21-418","subject":null,"moderation_state":"published","external_url":null},{"nid":2661,"title":"F5 security advisory","uuid":"7bce9ae0-d9c0-416c-b883-f93195590d47","banner":null,"lang":"en","date_modified":"2021-08-26","date_modified_ts":"2021-08-26T13:29:33Z","date_created":"2021-08-26T13:29:33Z","summary":null,"body":["<article data-history-node-id=\"2661\" about=\"\/en\/alerts-advisories\/f5-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-419<br \/>\nDate: 26 August 2021<\/strong><\/p>\n\n<p>On 24 August 2021, F5 published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG IP \u2013 multiple versions<\/li>\n\t<li>BIG IQ \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Overview of F5 Vulnerabilities (August 2021)<br \/><a href=\"https:\/\/support.f5.com\/csp\/article\/K50974556\">https:\/\/support.f5.com\/csp\/article\/K50974556<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0 <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-2","alert_type":396,"serial_number":"AV21-419","subject":null,"moderation_state":"published","external_url":null},{"nid":2662,"title":"Atlassian security advisory","uuid":"eb26cae8-3cc5-40a6-93cf-cbdff8d30d0d","banner":null,"lang":"en","date_modified":"2021-08-26","date_modified_ts":"2021-08-26T17:47:18Z","date_created":"2021-08-26T17:47:18Z","summary":null,"body":["<article data-history-node-id=\"2662\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-420<br \/>\nDate: 26 August 2021<\/strong><\/p>\n\n<p>On 25 August 2021 Atlassian published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Confluence Server \u2013 multiple versions<\/li>\n\t<li>Confluence Data Server \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may allow execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Atlassian Confluence Security Advisory<br \/><a href=\"https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2021-08-25-1077906215.html \">https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2021-08-25-1077906215.html\u00a0<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory","alert_type":396,"serial_number":"AV21-420","subject":null,"moderation_state":"published","external_url":null},{"nid":2663,"title":"Cisco security advisory","uuid":"d14e1389-0caa-4a61-8bd3-05108ba27481","banner":null,"lang":"en","date_modified":"2021-08-26","date_modified_ts":"2021-08-26T17:51:09Z","date_created":"2021-08-26T17:51:09Z","summary":null,"body":["<article data-history-node-id=\"2663\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-89\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-421<br \/>\nDate: 26 August 2021<\/strong><\/p>\n\n<p>On 25 August 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Application Policy Infrastructure Controller \u2013 multiple versions<\/li>\n\t<li>Cisco Cloud Application Policy Infrastructure Controller \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an unauthenticated, remote actor to read or write arbitrary files on an affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco Application Policy Infrastructure Controller (APIC) Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-capic-frw-Nt3RYxR2\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-capic-frw-Nt3RYxR2<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-89","alert_type":396,"serial_number":"AV21-421","subject":null,"moderation_state":"published","external_url":null},{"nid":2664,"title":"[Control systems] Annke security advisory","uuid":"9a6eb66f-0a3e-4fbf-87ea-56dd55eec4a0","banner":null,"lang":"en","date_modified":"2021-08-27","date_modified_ts":"2021-08-27T15:36:21Z","date_created":"2021-08-27T15:36:21Z","summary":null,"body":["<article data-history-node-id=\"2664\" about=\"\/en\/alerts-advisories\/control-systems-annke-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-422<br \/>\nDate: 27 August 2021<\/strong><\/p>\n\n<p>On 26 August 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>N48PBB (NVR) - version V3.4.106 build 200422 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-238-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-annke-security-advisory","alert_type":398,"serial_number":"AV21-422","subject":null,"moderation_state":"published","external_url":null},{"nid":2665,"title":"[Control systems] Delta Electronics security advisory","uuid":"b737d9aa-f40b-48c0-9fc1-68884746a233","banner":null,"lang":"en","date_modified":"2021-08-27","date_modified_ts":"2021-08-27T15:39:16Z","date_created":"2021-08-27T15:39:16Z","summary":null,"body":["<article data-history-node-id=\"2665\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-423<br \/>\nDate: 27 August 2021<\/strong><\/p>\n\n<p>On 26 August 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>DIAEnergie - version 1.7.5 and prior<\/li>\n\t<li>DOPSoft - version 4.00.11 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-238-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-03<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-238-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-10","alert_type":398,"serial_number":"AV21-423","subject":null,"moderation_state":"published","external_url":null},{"nid":2666,"title":"Microsoft Azure security advisory","uuid":"4c02c27f-97c7-4e4a-b56d-1e9e0bac596e","banner":null,"lang":"en","date_modified":"2021-08-27","date_modified_ts":"2021-08-27T17:41:20Z","date_created":"2021-08-27T17:41:20Z","summary":null,"body":["<article data-history-node-id=\"2666\" about=\"\/en\/alerts-advisories\/microsoft-azure-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-424<br \/>\nDate: 27 August 2021<\/strong><\/p>\n\n<p>On 26 August 2021 security researchers disclosed a vulnerability in Microsoft\u2019s Azure cloud platform. The following Azure component is affected:<\/p>\n\n<ul><li>Cosmos DB<\/li>\n<\/ul><p>Exploitation of this vulnerability would have exposed credentials that could have allowed an unauthorized actor to view, modify or delete data in Cosmos DB databases.<\/p>\n\n<p>Microsoft has indicated in open-source reporting that it remediated the vulnerability on 14 August 2021. However, the researchers suggest that Azure Cosmos DB keys may have been exposed prior to this.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, assess the risk of potential exposure and consider regenerating the Cosmos DB primary key.<\/p>\n\n<p>ChaosDB - Critical Vulnerability in Microsoft Azure Cosmos DB<br \/><a href=\"https:\/\/chaosdb.wiz.io\/\">https:\/\/chaosdb.wiz.io\/<\/a><\/p>\n\n<p>Secure access to data in Azure Cosmos DB<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/cosmos-db\/secure-access-to-data?tabs=using-primary-key#primary-keys\">https:\/\/docs.microsoft.com\/en-us\/azure\/cosmos-db\/secure-access-to-data?tabs=using-primary-key#primary-keys<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0 <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-azure-security-advisory","alert_type":396,"serial_number":"AV21-424","subject":null,"moderation_state":"published","external_url":null},{"nid":2667,"title":"[Control systems] Johnson Controls security advisory","uuid":"665f6b8d-3331-40bf-98ae-3abd5fbde2f3","banner":null,"lang":"en","date_modified":"2021-08-27","date_modified_ts":"2021-08-27T17:44:37Z","date_created":"2021-08-27T17:44:37Z","summary":null,"body":["<article data-history-node-id=\"2667\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-425<br \/>\nDate: 27 August 2021<\/strong><\/p>\n\n<p>On 26 August 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CEM Systems AC2000 \u2013 versions 10.1 to 10.5<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to unauthorized access to the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-238-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-238-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-9","alert_type":398,"serial_number":"AV21-425","subject":null,"moderation_state":"published","external_url":null},{"nid":2668,"title":"IBM security advisory","uuid":"110d6b97-861a-4eff-bb3b-36bd9e279f50","banner":null,"lang":"en","date_modified":"2021-08-30","date_modified_ts":"2021-08-30T17:38:57Z","date_created":"2021-08-30T17:38:57Z","summary":null,"body":["<article data-history-node-id=\"2668\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-62\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-426<br \/>\nDate: 30 August 2021<\/strong><\/p>\n\n<p>Between 23 and 29 August 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SDS VA - version 8.0.1<\/li>\n\t<li>ITNCM - version 6.4.2<\/li>\n\t<li>IBM App Connect Enterprise \u2013 versions V11.0.0.0 to V11.0.0.13 and V12.0.1.0<\/li>\n\t<li>IBM Integration Bus V10.0.0.0 \u2013 version V10.0.0.23<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>SDS VA<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-have-been-identified-in-ibm-java-sdk-that-affect-ibm-security-directory-suite-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-have-been-identified-in-ibm-java-sdk-that-affect-ibm-security-directory-suite-2\/<\/a><\/p>\n\n<p>ITNCM<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-xstream-publicly-disclosed-vulnerability-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-xstream-publicly-disclosed-vulnerability-2\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-xstream-publicly-disclosed-vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-xstream-publicly-disclosed-vulnerability\/<\/a><\/p>\n\n<p>IBM Integration Bus &amp; IBM App Connect Enterprise<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-6\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-6\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-5\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-5\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-62","alert_type":396,"serial_number":"AV21-426","subject":null,"moderation_state":"published","external_url":null},{"nid":2669,"title":"[Control systems] Sensormatic Electronics security advisory","uuid":"e7238ef6-3c7a-49d6-90a0-2d2002c922ba","banner":null,"lang":"en","date_modified":"2021-08-31","date_modified_ts":"2021-08-31T18:59:33Z","date_created":"2021-08-31T18:59:33Z","summary":null,"body":["<article data-history-node-id=\"2669\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-427<br \/>\nDate: 31 August 2021<\/strong><\/p>\n\n<p>On 31 August 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>KT-1 - version 2.09.02 and prior<\/li>\n<\/ul><p>The affected product may not receive support and updates for potential vulnerabilities as it uses an unsupported version of Microsoft Windows CE.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-243-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-243-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-243-01<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory","alert_type":398,"serial_number":"AV21-427","subject":null,"moderation_state":"published","external_url":null},{"nid":2670,"title":"Google Chrome security advisory","uuid":"f4407890-ca77-4cad-81e9-bc4f29b32263","banner":null,"lang":"en","date_modified":"2021-09-01","date_modified_ts":"2021-09-01T14:08:02Z","date_created":"2021-09-01T14:08:02Z","summary":null,"body":["<article data-history-node-id=\"2670\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-64\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-428<br \/>\nDate: 1 September 2021<\/strong><\/p>\n\n<p>On 31 August 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 93.0.4577.63<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/08\/stable-channel-update-for-desktop_31.html\">https:\/\/chromereleases.googleblog.com\/2021\/08\/stable-channel-update-for-desktop_31.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-64","alert_type":396,"serial_number":"AV21-428","subject":null,"moderation_state":"published","external_url":null},{"nid":2671,"title":"Cisco security advisory","uuid":"5849823c-bf55-451c-951e-0824a9deeb6f","banner":null,"lang":"en","date_modified":"2021-09-01","date_modified_ts":"2021-09-01T18:35:28Z","date_created":"2021-09-01T18:35:28Z","summary":null,"body":["<article data-history-node-id=\"2671\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-90\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-429<br \/>\nDate: 1 September 2021<\/strong><\/p>\n\n<p>On 1 September 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco Enterprise NFV Infrastructure Software (NFVIS) \u2013 release 4.5.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco NFVIS Security Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nfvis-g2DMVVh\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nfvis-g2DMVVh<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-90","alert_type":396,"serial_number":"AV21-429","subject":null,"moderation_state":"published","external_url":null},{"nid":2672,"title":"HPE security advisory","uuid":"d7522c2a-1f70-487b-b8b4-004d98d8f3a1","banner":null,"lang":"en","date_modified":"2021-09-02","date_modified_ts":"2021-09-02T15:13:40Z","date_created":"2021-09-02T15:13:40Z","summary":null,"body":["<article data-history-node-id=\"2672\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-430<br \/>\nDate: 2 September 2021<\/strong><\/p>\n\n<p>On 31 August 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ArubaOS \u2013 multiple versions<\/li>\n\t<li>Aruba SD-WAN Software and Gateways \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in remote code execution, arbitrary command execution, the deletion of arbitrary files, denial of service, and the disclosure or modification of sensitive data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE ArubaOS and SD-WAN (HPESBNW04190)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04190en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04190en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-27","alert_type":396,"serial_number":"AV21-430","subject":null,"moderation_state":"published","external_url":null},{"nid":2673,"title":"[Control systems] Advantech security advisory","uuid":"cbe52de4-58ae-430b-89a1-1002f1638a83","banner":null,"lang":"en","date_modified":"2021-09-02","date_modified_ts":"2021-09-02T17:43:21Z","date_created":"2021-09-02T17:43:21Z","summary":null,"body":["<article data-history-node-id=\"2673\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-431<br \/>\nDate: 2 September 2021<\/strong><\/p>\n\n<p>On 2 September 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>WebAccess - version 9.02 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-245-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-245-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-245-03<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-21","alert_type":398,"serial_number":"AV21-431","subject":null,"moderation_state":"published","external_url":null},{"nid":2674,"title":"[Control systems] Sensormatic Electronics security advisory","uuid":"b637c084-62cd-4e1c-bfb1-360be8fee0d2","banner":null,"lang":"en","date_modified":"2021-09-02","date_modified_ts":"2021-09-02T17:47:01Z","date_created":"2021-09-02T17:47:01Z","summary":null,"body":["<article data-history-node-id=\"2674\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-432<br \/>\nDate: 2 September 2021<\/strong><\/p>\n\n<p>On 2 September 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Pro Gen 3 - versions prior to 2.8.0<\/li>\n\t<li>Flex Gen 2 - versions prior to 1.9.4<\/li>\n\t<li>Pro 2 - all versions<\/li>\n\t<li>Insight - versions prior to 1.4.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-245-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-245-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-245-01<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-0","alert_type":398,"serial_number":"AV21-432","subject":null,"moderation_state":"published","external_url":null},{"nid":2675,"title":"[Control systems] JTEKT Corporation security advisory","uuid":"1b9a526d-ef56-4c20-b437-32950d3cdf10","banner":null,"lang":"en","date_modified":"2021-09-03","date_modified_ts":"2021-09-03T13:52:25Z","date_created":"2021-09-03T13:48:30Z","summary":null,"body":["<article data-history-node-id=\"2675\" about=\"\/en\/alerts-advisories\/control-systems-jtekt-corporation-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-433<br \/>\nDate: 3 September 2021<\/strong><\/p>\n\n<p>On 2 September 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>TOYOPUC-PC10 Series \u2013 multiple models and versions<\/li>\n\t<li>TOYOPUC-Plus Series \u2013 multiple models and versions<\/li>\n\t<li>TOYOPUC-PC3J\/PC2J Series \u2013 multiple models and versions<\/li>\n\t<li>TOYOPUC-Nano Series \u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow a remote actor to deny Ethernet communications between affected devices without authorization.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-245-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-245-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-245-02<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-jtekt-corporation-security-advisory","alert_type":398,"serial_number":"AV21-433","subject":null,"moderation_state":"published","external_url":null},{"nid":2676,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"c279dff3-61fd-4fcf-96e2-14031c8301d8","banner":null,"lang":"en","date_modified":"2021-09-03","date_modified_ts":"2021-09-03T15:17:54Z","date_created":"2021-09-03T15:16:50Z","summary":null,"body":["<article data-history-node-id=\"2676\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-434<br \/>\nDate: 3 September 2021<\/strong><\/p>\n\n<p>On 2 September 2021 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 93.0.961.38<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-2-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-2-2021<\/a><\/p>\n\n<p>Security Update Guide<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\">https:\/\/msrc.microsoft.com\/update-guide\/<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-2","alert_type":396,"serial_number":"AV21-434","subject":null,"moderation_state":"published","external_url":null},{"nid":2677,"title":"[Control systems] ABB security advisory","uuid":"92bbf53d-a651-4911-ab38-909e8f4568da","banner":null,"lang":"en","date_modified":"2021-09-03","date_modified_ts":"2021-09-03T18:42:27Z","date_created":"2021-09-03T18:41:57Z","summary":null,"body":["<article data-history-node-id=\"2677\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-435<br \/>\nDate: 3 September 2021<\/strong><\/p>\n\n<p>On 3 September 2021 ABB published a Cyber Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB Base Software for SoftControl \u2013 version 6.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ABB Cyber Security Advisory (2PAA122974)<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA122974&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2PAA122974&amp;Action=Launch<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-16","alert_type":398,"serial_number":"AV21-435","subject":null,"moderation_state":"published","external_url":null},{"nid":2678,"title":"IBM security advisory","uuid":"11a9301b-29cf-4b53-bcaa-8f5b119b5fad","banner":null,"lang":"en","date_modified":"2021-09-07","date_modified_ts":"2021-09-07T17:27:26Z","date_created":"2021-09-07T17:27:26Z","summary":null,"body":["<article data-history-node-id=\"2678\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-63\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-436<br \/>\nDate: 7 September 2021<\/strong><\/p>\n\n<p>Between 30 August and 6 September 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak System \u2013 version 2.3.x.x<\/li>\n\t<li>IBM UrbanCode Deploy \u2013 multiple versions<\/li>\n\t<li>ISIM VA \u2013 versions 7.0.1 and 7.0.2<\/li>\n\t<li>SDS VA \u2013 version 8.0.1<\/li>\n\t<li>IBM Sterling External Authentication Server \u2013 version 2.4.3.2<\/li>\n\t<li>IBM Secure External Authentication Server \u2013 versions 6.0.1 and 6.0.2<\/li>\n\t<li>IBM Security Guardium \u2013 versions 11.2 and 11.3<\/li>\n\t<li>ITNCM - version 6.4.2<\/li>\n\t<li>IBM Integration Bus \u2013 versions V10.0.0.0 to V10.0.0.23<\/li>\n\t<li>IBM App Connect Enterprise \u2013 versions V11.0.0.0 to V11.0.0.13 and V12.0.1.0<\/li>\n\t<li>IBM Sterling Secure Proxy \u2013 version 3.4.3.2<\/li>\n\t<li>IBM Secure Proxy \u2013 versions 6.0.1 and 6.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-63","alert_type":396,"serial_number":"AV21-436","subject":null,"moderation_state":"published","external_url":null},{"nid":2679,"title":"Mozilla security advisory","uuid":"51474ed5-76f4-4f9f-ab53-3208c6a28535","banner":null,"lang":"en","date_modified":"2021-09-07","date_modified_ts":"2021-09-07T19:53:47Z","date_created":"2021-09-07T19:53:47Z","summary":null,"body":["<article data-history-node-id=\"2679\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-44\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-437<br \/>\nDate: 7 September 2021<\/strong><\/p>\n\n<p>On 7 September 2021 Mozilla published Security Advisories to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 92<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.14 and 91.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-38)<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-38\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-38\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-39 and MFSA 2021-40)<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-39\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-39\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-40\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-40\/<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-44","alert_type":396,"serial_number":"AV21-437","subject":null,"moderation_state":"published","external_url":null},{"nid":2680,"title":"Cisco security advisory","uuid":"97f906ae-7377-462f-a757-4c2efaac4600","banner":null,"lang":"en","date_modified":"2021-09-08","date_modified_ts":"2021-09-08T19:02:55Z","date_created":"2021-09-08T19:02:55Z","summary":null,"body":["<article data-history-node-id=\"2680\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-91\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-438<br \/>\nDate: 8 September 2021<\/strong><\/p>\n\n<p>On 8 September 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco IOS XR Software \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-91","alert_type":396,"serial_number":"AV21-438","subject":null,"moderation_state":"published","external_url":null},{"nid":2681,"title":"Android security advisory \u2013 September 2021 monthly rollup","uuid":"69f0dbcf-4299-4b09-8291-9db3322fcff2","banner":null,"lang":"en","date_modified":"2021-09-08","date_modified_ts":"2021-09-08T19:05:35Z","date_created":"2021-09-08T19:05:35Z","summary":null,"body":["<article data-history-node-id=\"2681\" about=\"\/en\/alerts-advisories\/android-security-advisory-september-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-439<br \/>\nDate: 8 September 2021<\/strong><\/p>\n\n<p>On 7 September 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-09-01\">https:\/\/source.android.com\/security\/bulletin\/2021-09-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-september-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-439","subject":null,"moderation_state":"published","external_url":null},{"nid":2682,"title":"[Control systems] Hitachi ABB Power Grids security advisory","uuid":"0591b2a1-fdc9-46ab-8cb7-722913160946","banner":null,"lang":"en","date_modified":"2021-09-08","date_modified_ts":"2021-09-08T19:11:28Z","date_created":"2021-09-08T19:08:06Z","summary":null,"body":["<article data-history-node-id=\"2682\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-440<br \/>\nDate: 8 September 2021<\/strong><\/p>\n\n<p>On 7 September 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>SDM600 - versions prior to 1.2 FP2 HF6 (Build Nr. 1.2.14002.257)<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-250-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-250-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-250-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-abb-power-grids-security-advisory-5","alert_type":398,"serial_number":"AV21-440","subject":null,"moderation_state":"published","external_url":null},{"nid":2683,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"137a1b79-311b-4f5f-9fed-761e1d03b209","banner":null,"lang":"en","date_modified":"2021-09-08","date_modified_ts":"2021-09-08T19:30:43Z","date_created":"2021-09-08T19:30:24Z","summary":null,"body":["<article data-history-node-id=\"2683\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-441<br \/>\nDate: 8 September 2021<\/strong><\/p>\n\n<p>On 7 September 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MELSEC iQ-R Series CPU Modules:\n\t<ul><li>R08\/16\/32\/120SFCPU: All versions<\/li>\n\t\t<li>R08\/16\/32\/120PSFCPU: All versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-250-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-250-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-250-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-20","alert_type":398,"serial_number":"AV21-441","subject":null,"moderation_state":"published","external_url":null},{"nid":2702,"title":"Active Exploitation of Microsoft MSHTML Remote Code Execution Vulnerability - update 1","uuid":"b4006ce8-1d4f-4169-92dc-95827ee866ca","banner":null,"lang":"en","date_modified":"2021-09-14","date_modified_ts":"2021-09-14T19:13:04Z","date_created":"2021-09-08T21:28:48Z","summary":null,"body":["<article data-history-node-id=\"2702\" about=\"\/en\/alerts-advisories\/active-exploitation-microsoft-mshtml-remote-code-execution-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-018 UPDATE 1<br \/>\nDate: 8 September 2021<br \/>\nUpdated: 14 September 2021<\/strong><\/p>\n\n<h2>AUDIENCE<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>PURPOSE<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>OVERVIEW<\/h2>\n\n<p>The Cyber Centre is aware of reported ongoing scanning and exploitation of an unpatched remote code execution vulnerability in MSHTML affecting Microsoft Windows [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\">1<\/a>]. Microsoft has released guidance to mitigate this vulnerability.<\/p>\n\n<h2>DETAILS<\/h2>\n\n<p>On 7 September 2021 Microsoft released a KB article [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\">1<\/a>] detailing an unpatched remote code execution vulnerability, tracked as CVE-2021-40444, in MSHTML affecting multiple versions of Microsoft Windows. Exploitation of this vulnerability could involve the creation of a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine.<\/p>\n\n<p>Successful exploitation requires user interaction to open a malicious document and then enable editing. By default, Microsoft Office prevents exploitation of this vulnerability by opening documents from the Internet in Protected View or Application Guard for Office.<\/p>\n\n<p>Microsoft reports that this vulnerability has been publicly disclosed and that it is aware of targeted attempts at exploitation using specially crafted Microsoft Office documents [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\">1<\/a>][<a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/09\/07\/microsoft-releases-mitigations-and-workarounds-cve-2021-40444\">2<\/a>].<\/p>\n\n<h2>MITIGATION<\/h2>\n\n<p><strong>UPDATE 1<\/strong><br \/>\nOn 14 September 2021, a patch for CVE-2021-40444 was released as part of the September 2021 Security Updates [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\">1<\/a>].<\/p>\n\n<p>Microsoft outlines a workaround to mitigate this vulnerability as part of the KB article released on 7 September 2021.<\/p>\n\n<p>The Cyber Centre encourages organizations to review the Microsoft KB article [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\">1<\/a>] for detailed information.<\/p>\n\n<h2>DETECTION<\/h2>\n\n<p>Microsoft indicates that both Microsoft Defender Antivirus and Microsoft Defender for Endpoint can detect and protect against CVE-2021-40444 [<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\">1<\/a>].<\/p>\n\n<p>The Cyber Centre encourages organizations to ensure their anti-virus software is up to date [<a href=\"\/en\/guidance\/protect-your-organization-malware-itsap00057\">3<\/a>].<\/p>\n\n<h2>REFERENCES<\/h2>\n\n<p>[1] <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\">Windows KB Article \u2013 CVE-2021-40444<\/a><\/p>\n\n<p>[2] <a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/09\/07\/microsoft-releases-mitigations-and-workarounds-cve-2021-40444\">CISA - Microsoft Releases Mitigations and Workarounds for CVE-2021-40444<\/a><\/p>\n\n<p>[3] <a href=\"\/en\/guidance\/protect-your-organization-malware-itsap00057\">Protect Your Organization From Malware (ITSAP.00.057)<\/a><\/p>\n\n<p><strong>NOTE TO READERS<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-microsoft-mshtml-remote-code-execution-vulnerability","alert_type":397,"serial_number":"AL21-018","subject":null,"moderation_state":"published","external_url":null},{"nid":2684,"title":"Fortinet security advisory","uuid":"2475b94c-ea0f-4cb8-a8a1-c427de688bca","banner":null,"lang":"en","date_modified":"2021-09-09","date_modified_ts":"2021-09-09T12:04:25Z","date_created":"2021-09-09T12:04:25Z","summary":null,"body":["<article data-history-node-id=\"2684\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-442<br \/>\nDate: 9 September 2021<\/strong><\/p>\n\n<p>On 7 September 2021 Fortinet published PSIRT Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiWeb \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Fortinet PSIRT Advisories<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-12","alert_type":396,"serial_number":"AV21-442","subject":null,"moderation_state":"published","external_url":null},{"nid":2685,"title":"Netgear security advisory","uuid":"932a3dff-f7c2-487b-9977-f61e9480d5b7","banner":null,"lang":"en","date_modified":"2021-09-09","date_modified_ts":"2021-09-09T13:41:19Z","date_created":"2021-09-09T13:41:19Z","summary":null,"body":["<article data-history-node-id=\"2685\" about=\"\/en\/alerts-advisories\/netgear-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-444<br \/>\nDate: 9 September 2021<\/strong><\/p>\n\n<p>On 3 September 2021 Netgear published a Security Advisory to address vulnerabilities in the following network switching products:<\/p>\n\n<ul><li>GC108P - firmware version prior to 1.0.8.2<\/li>\n\t<li>GC108PP - firmware version prior to 1.0.8.2<\/li>\n\t<li>GS108Tv3 - firmware version prior to 7.0.7.2<\/li>\n\t<li>GS110TPP - firmware version prior to 7.0.7.2<\/li>\n\t<li>GS110TPv3 - firmware version prior to 7.0.7.2<\/li>\n\t<li>GS110TUP - firmware version prior to 1.0.5.3<\/li>\n\t<li>GS308T - firmware version prior to 1.0.3.2<\/li>\n\t<li>GS310TP - firmware version prior to 1.0.3.2<\/li>\n\t<li>GS710TUP - firmware version prior to 1.0.5.3<\/li>\n\t<li>GS716TP - firmware version prior to 1.0.4.2<\/li>\n\t<li>GS716TPP - firmware version prior to 1.0.4.2<\/li>\n\t<li>GS724TPP - firmware version prior to 2.0.6.3<\/li>\n\t<li>GS724TPv2 - firmware version prior to 2.0.6.3<\/li>\n\t<li>GS728TPPv2 - firmware version prior to 6.0.8.2<\/li>\n\t<li>GS728TPv2 - firmware version prior to 6.0.8.2<\/li>\n\t<li>GS750E - firmware version prior to 1.0.1.10<\/li>\n\t<li>GS752TPP - firmware version prior to 6.0.8.2<\/li>\n\t<li>GS752TPv2 - firmware version prior to 6.0.8.2<\/li>\n\t<li>MS510TXM - firmware version prior to 1.0.4.2<\/li>\n\t<li>MS510TXUP - firmware version prior to 1.0.4.2<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to take full control of affected devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Netgear Security Advisory<br \/><a href=\"https:\/\/kb.netgear.com\/000063978\/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Smart-Switches-PSV-2021-0140-PSV-2021-0144-PSV-2021-0145\">https:\/\/kb.netgear.com\/000063978\/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Smart-Switches-PSV-2021-0140-PSV-2021-0144-PSV-2021-0145<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/netgear-security-advisory-1","alert_type":396,"serial_number":"AV21-444","subject":null,"moderation_state":"published","external_url":null},{"nid":2686,"title":"Ubuntu security advisory","uuid":"70aae02f-15c0-4818-86a7-cfdadda462e6","banner":null,"lang":"en","date_modified":"2021-09-09","date_modified_ts":"2021-09-09T13:51:11Z","date_created":"2021-09-09T13:51:11Z","summary":null,"body":["<article data-history-node-id=\"2686\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-443<br \/>\nDate: 9 September 2021<\/strong><\/p>\n\n<p>On 8 September 2021 Ubuntu released a Security Notice to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to cause a denial of service or run programs as an administrator.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5062-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5062-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5062-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices\u00a0 <\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-22","alert_type":396,"serial_number":"AV21-443","subject":null,"moderation_state":"published","external_url":null},{"nid":2687,"title":"Zoho security advisory","uuid":"7f736255-e700-40ea-9d34-33736cd7513f","banner":null,"lang":"en","date_modified":"2021-09-09","date_modified_ts":"2021-09-09T19:32:22Z","date_created":"2021-09-09T19:26:37Z","summary":null,"body":["<article data-history-node-id=\"2687\" about=\"\/en\/alerts-advisories\/zoho-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-445<br \/>\nDate: 9 September 2021<\/strong><\/p>\n\n<p>On 7 September 2021 Zoho published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ManageEngine ADSelfService Plus - build 6113 and prior<\/li>\n<\/ul><p>Zoho is aware that an exploit exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Zoho Security Advisory<br \/><a href=\"https:\/\/www.manageengine.com\/products\/self-service-password\/kb\/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html\">https:\/\/www.manageengine.com\/products\/self-service-password\/kb\/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zoho-security-advisory","alert_type":396,"serial_number":"AV21-445","subject":null,"moderation_state":"published","external_url":null},{"nid":2688,"title":"Palo Alto Networks security advisory","uuid":"07199dc6-f9a2-4239-8930-b4d9ee1b937a","banner":null,"lang":"en","date_modified":"2021-09-10","date_modified_ts":"2021-09-10T13:58:29Z","date_created":"2021-09-10T13:58:29Z","summary":null,"body":["<article data-history-node-id=\"2688\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-446<br \/>\nDate: 10 September 2021<\/strong><\/p>\n\n<p>On 8 September 2021 Palo Alto Networks published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>PAN-OS 8.1 - versions prior to 8.1.20<\/li>\n\t<li>PAN-OS 9.0 - versions prior to 9.0.14<\/li>\n\t<li>PAN-OS 9.1 - versions prior to 9.1.11<\/li>\n\t<li>PAN-OS 10.0 - versions prior to 10.0.7<\/li>\n\t<li>PAN-OS 10.1 - versions prior to 10.1.2<\/li>\n\t<li>Cortex XSOAR \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, cross site scripting, authentication bypass or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, implement the recommended mitigations and apply the necessary updates.<\/p>\n\n<p>Palo Alto Networks Security Advisories<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-11","alert_type":396,"serial_number":"AV21-446","subject":null,"moderation_state":"published","external_url":null},{"nid":2689,"title":"[Control systems] ABB security advisory","uuid":"d8bd77b2-03f3-431a-a0b7-9b923c18b38d","banner":null,"lang":"en","date_modified":"2021-09-10","date_modified_ts":"2021-09-10T15:18:07Z","date_created":"2021-09-10T15:18:07Z","summary":null,"body":["<article data-history-node-id=\"2689\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-447<br \/>\nDate: 10 September 2021<\/strong><\/p>\n\n<p>On 7 September 2021 ABB published a Cyber Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>EIBPORT \u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an unauthenticated actor to gain access to sensitive data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ABB Cyber Security Advisory (9AKK107992A7304)<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107992A7304&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK107992A7304&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-17","alert_type":398,"serial_number":"AV21-447","subject":null,"moderation_state":"published","external_url":null},{"nid":2690,"title":"Ubuntu security advisory","uuid":"4b64cea5-74f2-4f30-8d9d-5c6b88f9a761","banner":null,"lang":"en","date_modified":"2021-09-10","date_modified_ts":"2021-09-10T16:18:07Z","date_created":"2021-09-10T16:18:07Z","summary":null,"body":["<article data-history-node-id=\"2690\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-448<br \/>\nDate: 10 September 2021<\/strong><\/p>\n\n<p>On 8 - 9 September 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service, data modification, access to sensitive information, bypass of security restrictions or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5070-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5070-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5070-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5071-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5071-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5071-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5072-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5072-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5072-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5073-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5073-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5073-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices \">https:\/\/ubuntu.com\/security\/notices\u00a0<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-23","alert_type":396,"serial_number":"AV21-448","subject":null,"moderation_state":"published","external_url":null},{"nid":2691,"title":"Citrix security advisory","uuid":"1abb4d59-db0e-4c33-859b-4d4abc1ec072","banner":null,"lang":"en","date_modified":"2021-09-10","date_modified_ts":"2021-09-10T16:23:34Z","date_created":"2021-09-10T16:23:34Z","summary":null,"body":["<article data-history-node-id=\"2691\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-449<br \/>\nDate:\u00a0 10 September 2021<\/strong><\/p>\n\n<p>On 8 September 2021 Citrix published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Citrix Hypervisor \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to cause a host denial-of-service or host compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX325319)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX325319\">https:\/\/support.citrix.com\/article\/CTX325319<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-16","alert_type":396,"serial_number":"AV21-449","subject":null,"moderation_state":"published","external_url":null},{"nid":2692,"title":"[Control systems] AVEVA security advisory","uuid":"1e62b3fe-6d4a-46b4-a6ba-761a1e8ccd29","banner":null,"lang":"en","date_modified":"2021-09-10","date_modified_ts":"2021-09-10T19:30:34Z","date_created":"2021-09-10T19:30:34Z","summary":null,"body":["<article data-history-node-id=\"2692\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-451<br \/>\nDate: 10 September 2021<\/strong><\/p>\n\n<p>On 9 September 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>PCS Portal - versions 4.5.2, 4.5.1, 4.5.0 and 4.4.6<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-252-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-252-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-252-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-1","alert_type":398,"serial_number":"AV21-451","subject":null,"moderation_state":"published","external_url":null},{"nid":2693,"title":"[Control systems] Delta Electronics security advisory","uuid":"87617d83-7f36-4e92-a2d7-76ec8072ecbc","banner":null,"lang":"en","date_modified":"2021-09-10","date_modified_ts":"2021-09-10T19:33:33Z","date_created":"2021-09-10T19:33:33Z","summary":null,"body":["<article data-history-node-id=\"2693\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-450<br \/>\nDate: 10 September 2021<\/strong><\/p>\n\n<p>On 9 September 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DOPSoft 2 - version 2.00.07 and prior\u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-252-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-252-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-252-02<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-11","alert_type":398,"serial_number":"AV21-450","subject":null,"moderation_state":"published","external_url":null},{"nid":2694,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"21767df4-c6bb-4748-abbc-bea44a7aa219","banner":null,"lang":"en","date_modified":"2021-09-13","date_modified_ts":"2021-09-13T10:51:52Z","date_created":"2021-09-13T10:51:52Z","summary":null,"body":["<article data-history-node-id=\"2694\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-452<br \/>\nDate: 13 September 2021<\/strong><\/p>\n\n<p>On 9 September 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>smartRTU - firmware versions prior to 3.3<\/li>\n\t<li>INEA ME-RTU - firmware versions prior to 3.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to obtain credentials and execute arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-252-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-252-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-252-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-21","alert_type":398,"serial_number":"AV21-452","subject":null,"moderation_state":"published","external_url":null},{"nid":2695,"title":"IBM security advisory","uuid":"a2bd7e73-1c03-49a0-a172-688281c415a1","banner":null,"lang":"en","date_modified":"2021-09-13","date_modified_ts":"2021-09-13T16:36:57Z","date_created":"2021-09-13T16:36:57Z","summary":null,"body":["<article data-history-node-id=\"2695\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-64\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-453<br \/>\nDate: 13 September 2021<\/strong><\/p>\n\n<p>Between 7 and 12 September 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Intelligent Operations Center \u2013 versions 5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6, 5.2 and 5.2.1<\/li>\n\t<li>IBM Secure Proxy \u2013 versions 6.0.1 and 6.0.2<\/li>\n\t<li>Sterling Connect:Express for UNIX \u2013 version 1.5.x<\/li>\n\t<li>IBM DataPower Gateway V10 CD \u2013 version 10.0.2.0<\/li>\n\t<li>IBM DataPower Gateway 10.0.1 \u2013 versions 10.0.0.0 to 10.0.1.3<\/li>\n\t<li>IBM DataPower Gateway 2018.4.1 \u2013 versions 2018.4.1.0 to 2018.4.1.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-64","alert_type":396,"serial_number":"AV21-453","subject":null,"moderation_state":"published","external_url":null},{"nid":2696,"title":"WordPress security advisory","uuid":"9fabb801-1dc9-42e3-b7a1-6845eed21136","banner":null,"lang":"en","date_modified":"2021-09-13","date_modified_ts":"2021-09-13T17:27:22Z","date_created":"2021-09-13T17:27:22Z","summary":null,"body":["<article data-history-node-id=\"2696\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-454<br \/>\nDate: 13 September 2021<\/strong><\/p>\n\n<p>On 9 September 2021 WordPress published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>WordPress \u2013 versions 5.4 to 5.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>WordPress Security and Maintenance Release<br \/><a href=\"https:\/\/wordpress.org\/news\/2021\/09\/wordpress-5-8-1-security-and-maintenance-release\/\">https:\/\/wordpress.org\/news\/2021\/09\/wordpress-5-8-1-security-and-maintenance-release\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-4","alert_type":396,"serial_number":"AV21-454","subject":null,"moderation_state":"published","external_url":null},{"nid":2697,"title":"Apple security advisory","uuid":"582c17de-106d-4cd5-a383-0b2b88e0c823","banner":null,"lang":"en","date_modified":"2021-09-14","date_modified_ts":"2021-09-14T14:17:52Z","date_created":"2021-09-13T18:35:18Z","summary":null,"body":["<article data-history-node-id=\"2697\" about=\"\/en\/alerts-advisories\/apple-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-455<br \/>\nDate: 13 September 2021<\/strong><\/p>\n\n<p>On 13 September 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 14.8<\/li>\n\t<li>iPadOS \u2013 versions prior to 14.8<\/li>\n\t<li>watchOS \u2013 versions prior to 7.6.2<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.6<\/li>\n\t<li>MacOS Catalina \u2013 versions prior to 2021-005<\/li>\n\t<li>Safari \u2013 versions prior to 14.1.2<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary update.<\/p>\n\n<p>iOS and iPadOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212807\">https:\/\/support.apple.com\/en-ca\/HT212807<\/a><\/p>\n\n<p>watchOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212806\">https:\/\/support.apple.com\/en-ca\/HT212806<\/a><\/p>\n\n<p>MacOS Big Sur<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212804\">https:\/\/support.apple.com\/en-ca\/HT212804<\/a><\/p>\n\n<p>MacOS Catalina<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212805\">https:\/\/support.apple.com\/en-ca\/HT212805<\/a><\/p>\n\n<p>Safari<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212808\">https:\/\/support.apple.com\/en-ca\/HT212808<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-38","alert_type":396,"serial_number":"AV21-455","subject":null,"moderation_state":"published","external_url":null},{"nid":2698,"title":"SAP security advisory \u2013 September 2021 monthly rollup","uuid":"654f6268-fcfe-42f1-9c07-61251d119298","banner":null,"lang":"en","date_modified":"2021-09-14","date_modified_ts":"2021-09-14T15:57:39Z","date_created":"2021-09-14T15:57:39Z","summary":null,"body":["<article data-history-node-id=\"2698\" about=\"\/en\/alerts-advisories\/sap-security-advisory-september-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-456<br \/>\nDate: 14 September 2021<\/strong><\/p>\n\n<p>On 14 September 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Business Client \u2013 version 6.5<\/li>\n\t<li>SAP NetWeaver Application Server \u2013 versions 7.11, 7.200, 7.30, 7.31, 7.40 and 7.50<\/li>\n\t<li>SAP Business One - version 10.0<\/li>\n\t<li>SAP S\/4HANA - versions 1511, 1610, 1709, 1809, 1909, 2020 and 2021<\/li>\n\t<li>SAP LT Replication Server - versions 2.0 and 3.0<\/li>\n\t<li>SAP LTRS for S\/4HANA - version 1.0<\/li>\n\t<li>SAP Test Data Migration Server - version 4.0<\/li>\n\t<li>SAP Landscape Transformation - version 2.0<\/li>\n\t<li>SAP NetWeaver (Visual Composer 7.0 RT) - versions 7.30, 7.31, 7.40 and 7.50<\/li>\n\t<li>SAP NetWeaver Knowledge Management XML Forms - versions 7.10, 7.11, 7.30, 7.31, 7.40 and 7.50<\/li>\n\t<li>SAP Contact Center - version 700<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 September 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=585106405\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=585106405<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0 <\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-september-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-456","subject":null,"moderation_state":"published","external_url":null},{"nid":2700,"title":"Google Chrome security advisory","uuid":"9f42474d-68ee-4d6f-aab2-49859d11e86c","banner":null,"lang":"en","date_modified":"2021-09-14","date_modified_ts":"2021-09-14T17:31:31Z","date_created":"2021-09-14T17:31:31Z","summary":null,"body":["<article data-history-node-id=\"2700\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-65\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-457<br \/>\nDate: 14 September 2021<\/strong><\/p>\n\n<p>On 13 September 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0Chrome for Desktop \u2013 versions prior to 93.0.4577.82<\/p>\n\n<p>Google is aware that exploits for CVE-2021-30632 and CVE-2021-30633 exist in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-65","alert_type":396,"serial_number":"AV21-457","subject":null,"moderation_state":"published","external_url":null},{"nid":2699,"title":"[Control systems] Siemens security advisory","uuid":"c6748893-65e5-48d0-881b-f641d067b9c8","banner":null,"lang":"en","date_modified":"2021-09-14","date_modified_ts":"2021-09-14T17:37:42Z","date_created":"2021-09-14T17:37:42Z","summary":null,"body":["<article data-history-node-id=\"2699\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-458<br \/>\nDate: 14 September 2021<\/strong><\/p>\n\n<p>On 14 September 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Simcenter STAR-CCM+ Viewer \u2013 versions prior to V2021.2.1<\/li>\n\t<li>RUGGEDCOM ROX \u2013 multiple platforms, versions prior to V2.14.1<\/li>\n\t<li>NX 1980 Series \u2013 versions prior to V1984<\/li>\n\t<li>SINEC NMS \u2013 versions prior to V1.0 SP1<\/li>\n\t<li>Cerberus DMS \u2013 multiple platforms and versions<\/li>\n\t<li>Desigo CC \u2013 multiple platforms and versions<\/li>\n\t<li>SIPROTEC 5 relays \u2013 multiple platforms and versions<\/li>\n\t<li>GMA-Manager \u2013 all versions with OIS running Debian 9 or prior<\/li>\n\t<li>Operation Scheduler \u2013 all versions with OIS running Debian 9 or prior<\/li>\n\t<li>Siveillance Control \u2013 all versions with OIS running Debian 9 or prior<\/li>\n\t<li>Siveillance Control Pro \u2013 all versions<\/li>\n\t<li>SIMATIC \u2013 multiple platforms, all versions<\/li>\n\t<li>SCALANCE \u2013 multiple platforms and versions<\/li>\n\t<li>Industrial Edge Management \u2013 versions prior to V1.3<\/li>\n\t<li>LOGO! CMR2020\/2040 \u2013 versions prior to V2.2<\/li>\n\t<li>APOGEE \u2013 multiple platforms and versions<\/li>\n\t<li>TALON TC Compact\/Modular \u2013 versions prior to V3.5.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, remote code execution, data extraction, privilege escalation, unauthorized access, configuration manipulation, or user impersonation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Publications<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-33","alert_type":398,"serial_number":"AV21-458","subject":null,"moderation_state":"published","external_url":null},{"nid":2701,"title":"[Control systems] Schneider Electric security advisory","uuid":"f4f1902c-f1c4-4a43-9051-260bed8e9e97","banner":null,"lang":"en","date_modified":"2021-09-14","date_modified_ts":"2021-09-14T18:56:59Z","date_created":"2021-09-14T18:56:59Z","summary":null,"body":["<article data-history-node-id=\"2701\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-459<br \/>\nDate: 14 September 2021<\/strong><\/p>\n\n<p>On 14 September 2021 Schneider Electric published Security Notifications to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>\u00a0EcoStruxure Control Expert - all versions (including former Unity Pro)<\/li>\n\t<li>EcoStruxure Process Expert - all versions (including former HDCS)<\/li>\n\t<li>SCADAPack RemoteConnect for x70 - all versions<\/li>\n\t<li>Modicon \u2013 multiple models and versions<\/li>\n\t<li>StruxureWare Data Center Expert - version 7.8.1 and prior<\/li>\n\t<li>Conext ComBox \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, denial of service and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-24","alert_type":398,"serial_number":"AV21-459","subject":null,"moderation_state":"published","external_url":null},{"nid":2703,"title":"Adobe security advisory","uuid":"ff0d988d-63a4-4d1b-8883-77b2af76d413","banner":null,"lang":"en","date_modified":"2021-09-15","date_modified_ts":"2021-09-15T12:48:24Z","date_created":"2021-09-15T12:43:27Z","summary":null,"body":["<article data-history-node-id=\"2703\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-46\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-460<br \/>\nDate: 15 September 2021<\/strong><\/p>\n\n<p>On 14 September 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Acrobat Reader and Reader DC for Windows \u2013 version 2021.005.20060 and prior<\/li>\n\t<li>Acrobat Reader and Reader DC for macOS \u2013 version 2021.005.20058 and prior<\/li>\n\t<li>Acrobat 2020 and Reader 2020 \u2013 version 2020.004.30006 and prior<\/li>\n\t<li>Acrobat 2017 and Reader 2017 \u2013 version 2017.011.30199 and prior<\/li>\n\t<li>Adobe InCopy for Windows \u2013 version 16.3 and prior<\/li>\n\t<li>Adobe InCopy for macOS \u2013 version 16.3.1 and prior<\/li>\n\t<li>Adobe inDesign for Windows \u2013 version 16.3 and prior<\/li>\n\t<li>Adobe inDesign for macOS \u2013 version 16.3.2 and prior<\/li>\n\t<li>Adobe Framemaker \u2013 version 2019 Update 8 and prior and version 2020 release update 2 and prior<\/li>\n\t<li>Photoshop Elements \u2013 version 2021 build 19.0 (20210304.m.15367) and prior<\/li>\n\t<li>Adobe Premiere Elements \u2013 version 2021 build 19.0 (20210127.daily.2235820) and prior<\/li>\n\t<li>Adobe Digital Editions \u2013 version 4.5.11.187646<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution and arbitrary file system write.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-46","alert_type":396,"serial_number":"AV21-460","subject":null,"moderation_state":"published","external_url":null},{"nid":2709,"title":"Microsoft security advisory \u2013 September 2021 monthly rollup - UPDATE 1","uuid":"efe1973a-7184-4713-bd69-b24c6fe6b050","banner":null,"lang":"en","date_modified":"2021-09-17","date_modified_ts":"2021-09-17T21:07:22Z","date_created":"2021-09-15T12:51:27Z","summary":null,"body":["<article data-history-node-id=\"2709\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-461<br \/>\nDate: 14 September 2021<br \/>\nUpdate: 17 September 202<\/strong>1<\/p>\n\n<p>\u00a0<\/p>\n\n<p>On 14 September 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Azure Open Management Infrastructure<\/li>\n\t<li>Windows 7, 8.1, RT 8.1 and 10<\/li>\n\t<li>Windows Server version 20H2 and version 2004<\/li>\n\t<li>Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019 and 2022<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.<\/p>\n\n<p><strong>UPDATE 1<\/strong><\/p>\n\n<p>On 16 September 2021 the Microsoft Security Response Center published a blog post to provide additional guidance related to the Open Management Infrastructure (OMI) vulnerabilities within Azure VM Management Extensions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>September 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Sep\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Sep<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>UPDATE 1 <\/strong>\u2013 MSRC - Additional Guidance Regarding OMI Vulnerabilities within Azure VM Management Extensions<br \/><a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/09\/16\/additional-guidance-regarding-omi-vulnerabilities-within-azure-vm-management-extensions\/\">https:\/\/msrc-blog.microsoft.com\/2021\/09\/16\/additional-guidance-regarding-omi-vulnerabilities-within-azure-vm-management-extensions\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong>\u00a0<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-461","subject":null,"moderation_state":"published","external_url":null},{"nid":2704,"title":"[Control systems] Johnson Controls security advisory","uuid":"8fe05d2f-5732-4ac5-bee8-86968498f663","banner":null,"lang":"en","date_modified":"2021-09-15","date_modified_ts":"2021-09-15T15:43:26Z","date_created":"2021-09-15T15:43:26Z","summary":null,"body":["<article data-history-node-id=\"2704\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-462<br \/>\nDate: 15 September 2021<\/strong><\/p>\n\n<p>On 14 September 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>KT-1 Door Controllers \u2013 versions 3.01 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to authentication bypass by capture-replay.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-257-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-257-02-0\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-257-02-0<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-10","alert_type":398,"serial_number":"AV21-462","subject":null,"moderation_state":"published","external_url":null},{"nid":2705,"title":"[Control systems] Digi International security advisory","uuid":"986986bd-02bf-42a1-b1ae-15c513d1c01a","banner":null,"lang":"en","date_modified":"2021-09-15","date_modified_ts":"2021-09-15T15:46:04Z","date_created":"2021-09-15T15:46:04Z","summary":null,"body":["<article data-history-node-id=\"2705\" about=\"\/en\/alerts-advisories\/control-systems-digi-international-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-463<br \/>\nDate: 15 September 2021<\/strong><\/p>\n\n<p>On 14 September 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Digi PortServer TS 16 \u2013 Firmware versions 82000684 and 82000685<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to command execution or setting modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-257-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-257-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-257-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-digi-international-security-advisory","alert_type":398,"serial_number":"AV21-463","subject":null,"moderation_state":"published","external_url":null},{"nid":2707,"title":"Apple security advisory","uuid":"ad0d5e3d-4689-4c09-bae7-508bdbbdfca6","banner":null,"lang":"en","date_modified":"2021-09-16","date_modified_ts":"2021-09-16T11:09:51Z","date_created":"2021-09-16T11:09:51Z","summary":null,"body":["<article data-history-node-id=\"2707\" about=\"\/en\/alerts-advisories\/apple-security-advisory-39\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-464<br \/>\nDate: 16 September 2021<\/strong><\/p>\n\n<p>On 15 September 2021 Apple published a Security Update to address a vulnerability in the following product:<\/p>\n\n<ul><li>iTunes U \u2013 versions prior to 3.8.3<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary update.<\/p>\n\n<p>iTunes U<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212809\">https:\/\/support.apple.com\/en-ca\/HT212809<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-39","alert_type":396,"serial_number":"AV21-464","subject":null,"moderation_state":"published","external_url":null},{"nid":2708,"title":"Dell security advisory","uuid":"f8ff8935-43b6-4882-9ad7-537dc5826c00","banner":null,"lang":"en","date_modified":"2021-09-17","date_modified_ts":"2021-09-17T12:29:47Z","date_created":"2021-09-17T12:29:47Z","summary":null,"body":["<article data-history-node-id=\"2708\" about=\"\/en\/alerts-advisories\/dell-security-advisory-8\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-465<br \/>\nDate: 17 September 2021<\/strong><\/p>\n\n<p>On 16 September 2021 Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerPath Windows \u2013 versions prior to OpenSSL Configuration Utility 2.0<\/li>\n\t<li>Dell BIOS \u2013 multiple products and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to system compromise, unauthorized access to sensitive information or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Dell PowerPath Windows (DSA-2021-186)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191543\/dsa-2021-186\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191543\/dsa-2021-186<\/a><\/p>\n\n<p>Dell Client Security Update (DSA-2021-156)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191495\/dsa-2021-156\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191495\/dsa-2021-156<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-8","alert_type":396,"serial_number":"AV21-465","subject":null,"moderation_state":"published","external_url":null},{"nid":2710,"title":"IBM security advisory","uuid":"5d12a8c8-8ee7-4550-8fea-dd4a4ab5a223","banner":null,"lang":"en","date_modified":"2021-09-20","date_modified_ts":"2021-09-20T15:37:50Z","date_created":"2021-09-20T15:37:50Z","summary":null,"body":["<article data-history-node-id=\"2710\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-65\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-466<br \/>\nDate: 20 September 2021<\/strong><\/p>\n\n<p>Between 13 and 19 September 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Security Guardium \u2013 versions 11.2 and 11.3<\/li>\n\t<li>API Connect \u2013 versions V5.0.0.0 to V5.0.8.11<\/li>\n\t<li>IBM Data Replication \u2013 versions 11.3.3, 11.4 and 11.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-65","alert_type":396,"serial_number":"AV21-466","subject":null,"moderation_state":"published","external_url":null},{"nid":2711,"title":"Apple security advisory","uuid":"b9385f1a-66a8-4a27-9bf2-7483696e808d","banner":null,"lang":"en","date_modified":"2021-09-20","date_modified_ts":"2021-09-20T18:51:43Z","date_created":"2021-09-20T18:51:43Z","summary":null,"body":["<article data-history-node-id=\"2711\" about=\"\/en\/alerts-advisories\/apple-security-advisory-40\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-467<br \/>\nDate: 20 September 2021<\/strong><\/p>\n\n<p>On 20 September 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15<\/li>\n\t<li>iPadOS \u2013 versions prior to 15<\/li>\n\t<li>watchOS \u2013 versions prior to 8<\/li>\n\t<li>tvOS \u2013 versions prior to 15<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution, denial-of-service or unauthorised access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>iOS and iPadOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212814\">https:\/\/support.apple.com\/en-ca\/HT212814<\/a><\/p>\n\n<p>watchOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212819\">https:\/\/support.apple.com\/en-ca\/HT212819<\/a><\/p>\n\n<p>tvOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212815\">https:\/\/support.apple.com\/en-ca\/HT212815<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-40","alert_type":396,"serial_number":"AV21-467","subject":null,"moderation_state":"published","external_url":null},{"nid":2712,"title":"Apple security advisory","uuid":"c0da6a0d-598a-4a21-b2e1-0a07c30f32d4","banner":null,"lang":"en","date_modified":"2021-09-21","date_modified_ts":"2021-09-21T16:17:28Z","date_created":"2021-09-21T16:17:28Z","summary":null,"body":["<article data-history-node-id=\"2712\" about=\"\/en\/alerts-advisories\/apple-security-advisory-41\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-468<br \/>\nDate: 21 September 2021<\/strong><\/p>\n\n<p>On 20 September 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ITunes for Windows \u2013 versions prior to 12.12<\/li>\n\t<li>Safari \u2013 versions prior to 15<\/li>\n\t<li>Xcode \u2013 versions prior to 13<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>ITunes for Windows<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212817\">https:\/\/support.apple.com\/en-ca\/HT212817<\/a><br \/>\n\u00a0<br \/>\nSafari<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212816\">https:\/\/support.apple.com\/en-ca\/HT212816<\/a><br \/>\n\u00a0<br \/>\nXcode<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212818\">https:\/\/support.apple.com\/en-ca\/HT212818<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-41","alert_type":396,"serial_number":"AV21-468","subject":null,"moderation_state":"published","external_url":null},{"nid":2713,"title":"VMware security advisory","uuid":"46130611-7d0e-43b7-8757-bb6bfe68370c","banner":null,"lang":"en","date_modified":"2021-09-22","date_modified_ts":"2021-09-22T10:34:49Z","date_created":"2021-09-22T10:34:49Z","summary":null,"body":["<article data-history-node-id=\"2713\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-46\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-469<br \/>\nDate: 22 September 2021<\/strong><\/p>\n\n<p>On 21 September 2021 VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware vCenter Server - versions 6.5, 6.7 and 7.0<\/li>\n\t<li>VMware Cloud Foundation (vCenter Server) - versions 3.x and 4.x<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to privilege escalation, remote code execution, access to restricted endpoints or to the manipulation of VM network settings.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0020)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0020.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0020.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-46","alert_type":396,"serial_number":"AV21-469","subject":null,"moderation_state":"published","external_url":null},{"nid":2714,"title":"Google Chrome security advisory","uuid":"c5002ca2-9040-429b-8388-4d981c04dc57","banner":null,"lang":"en","date_modified":"2021-09-22","date_modified_ts":"2021-09-22T19:54:02Z","date_created":"2021-09-22T19:54:02Z","summary":null,"body":["<article data-history-node-id=\"2714\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-66\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-470<br \/>\nDate: 22 September 2021<\/strong><\/p>\n\n<p>On 21 September 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 94.0.4606.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop_21.html\">https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop_21.html<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-66","alert_type":396,"serial_number":"AV21-470","subject":null,"moderation_state":"published","external_url":null},{"nid":2715,"title":"Cisco security advisory","uuid":"1db6ac00-e845-4010-934b-e8dac80ab219","banner":null,"lang":"en","date_modified":"2021-09-23","date_modified_ts":"2021-09-23T15:12:15Z","date_created":"2021-09-23T15:12:15Z","summary":null,"body":["<article data-history-node-id=\"2715\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-92\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-471<br \/>\nDate: 23 September 2021<\/strong><\/p>\n\n<p>On 22 September 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco IOS XE SD-WAN Software on:\n\t<ul><li>1000 Series Integrated Services Routers (ISRs)<\/li>\n\t\t<li>4000 Series ISRs<\/li>\n\t\t<li>ASR 1000 Series Aggregation Services Routers<\/li>\n\t\t<li>Cloud Services Router 1000V Series<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco IOS XE Software for Catalyst 9000 Family Wireless Controllers on:\n\t<ul><li>Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches<\/li>\n\t\t<li>Catalyst 9800 Series Wireless Controllers<\/li>\n\t\t<li>Catalyst 9800-CL Wireless Controllers for Cloud<\/li>\n\t\t<li>Embedded Wireless Controller on Catalyst Access Points<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco IOS XE Software \u2013 certain configurations<\/li>\n\t<li>Cisco IOS XE SD-WAN Software \u2013 certain configurations<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, authentication bypass or denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-92","alert_type":396,"serial_number":"AV21-471","subject":null,"moderation_state":"published","external_url":null},{"nid":2716,"title":"Dell security advisory","uuid":"f0049bb3-6393-4754-808f-8d75aa79c8bb","banner":null,"lang":"en","date_modified":"2021-09-23","date_modified_ts":"2021-09-23T18:41:20Z","date_created":"2021-09-23T18:39:42Z","summary":null,"body":["<article data-history-node-id=\"2716\" about=\"\/en\/alerts-advisories\/dell-security-advisory-9\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-472<br \/>\nDate: 23 September 2021<\/strong><\/p>\n\n<p>On 21 September 2021 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Data Protection Central - versions 18.1, 18.2, 19.1, 19.2, 19.3, 19.4 and 19.5 \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to compromise of the affected system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Dell Knowledge Base Article (DSA-2021-195)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191727\/dsa-2021-195-dell-emc-data-protection-central-security-update-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191727\/dsa-2021-195-dell-emc-data-protection-central-security-update-for-multiple-third-party-component-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-9","alert_type":396,"serial_number":"AV21-472","subject":null,"moderation_state":"published","external_url":null},{"nid":2717,"title":"[Control systems] Trane security advisory","uuid":"63f998c6-f461-4fcc-a4b8-90a9889e1398","banner":null,"lang":"en","date_modified":"2021-09-24","date_modified_ts":"2021-09-24T13:27:19Z","date_created":"2021-09-24T13:27:19Z","summary":null,"body":["<article data-history-node-id=\"2717\" about=\"\/en\/alerts-advisories\/control-systems-trane-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-473<br \/>\nDate: 24 September 2021<\/strong><\/p>\n\n<p>On 23 September 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Symbio 700 (including Odyssey Split Systems) - versions prior to 1.00.0023<\/li>\n\t<li>Symbio 800 (including IntelliPak Rooftop Air Conditioner, Chiller Models: CenTraVac Simplex, CentraVac Duplex, ACR, RTAF, CMAF, HDWA.RTWF, CGWF, CXWF, CCUF and GVAF) - versions prior to 1.00.0007<\/li>\n\t<li>Tracer SC - versions prior to 4.4 SP7\u00a0\u00a0 \u00a0<\/li>\n\t<li>Tracer SC+ - versions prior to 5.3 SP3<\/li>\n\t<li>Tracer Concierge - versions prior to 5.3 SP3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-266-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-266-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-266-01<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-266-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-266-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-266-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-trane-security-advisory","alert_type":398,"serial_number":"AV21-473","subject":null,"moderation_state":"published","external_url":null},{"nid":2718,"title":"SonicWall security advisory","uuid":"cd5835d3-4c71-42e0-982c-ee6c1e3c356a","banner":null,"lang":"en","date_modified":"2021-09-24","date_modified_ts":"2021-09-24T18:06:45Z","date_created":"2021-09-24T18:06:45Z","summary":null,"body":["<article data-history-node-id=\"2718\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-474<br \/>\nDate: 24 September 2021<\/strong><\/p>\n\n<p>On 23 September 2021 SonicWall published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SMA 200 \u2013 multiple versions<\/li>\n\t<li>SMA 210 - multiple versions<\/li>\n\t<li>SMA 400 - multiple versions<\/li>\n\t<li>SMA 410 - multiple versions<\/li>\n\t<li>SMA 500v (ESX, KVM, AWS, Azure) - multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may allow an unauthenticated actor to delete an arbitrary file, potentially resulting in a reboot to factory default settings.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Security Advisory (SNWLID-2021-0021)<br \/><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2021-0021\">https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2021-0021<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-3","alert_type":396,"serial_number":"AV21-474","subject":null,"moderation_state":"published","external_url":null},{"nid":2719,"title":"Apple security advisory","uuid":"6fac31a2-68db-451b-ab71-fc9337037782","banner":null,"lang":"en","date_modified":"2021-09-24","date_modified_ts":"2021-09-24T18:11:22Z","date_created":"2021-09-24T18:11:22Z","summary":null,"body":["<article data-history-node-id=\"2719\" about=\"\/en\/alerts-advisories\/apple-security-advisory-42\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-475<br \/>\nDate: 24 September 2021<\/strong><\/p>\n\n<p>On 23 September 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Catalina \u2013 versions prior to Security Update 2021-006<\/li>\n\t<li>iOS \u2013 versions prior to 12.5.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution.<\/p>\n\n<p>Apple is aware of reports that exploits for both vulnerabilities exist in the wild, and of reports that the iOS vulnerabilities may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>macOS Catalina<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212825\">https:\/\/support.apple.com\/en-ca\/HT212825<\/a><\/p>\n\n<p>iOS<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212824\">https:\/\/support.apple.com\/en-ca\/HT212824<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-42","alert_type":396,"serial_number":"AV21-475","subject":null,"moderation_state":"published","external_url":null},{"nid":2720,"title":"Google Chrome security advisory","uuid":"1eaca4d1-1ee0-4748-815b-9f70a6a6210d","banner":null,"lang":"en","date_modified":"2021-09-24","date_modified_ts":"2021-09-24T19:09:04Z","date_created":"2021-09-24T19:09:04Z","summary":null,"body":["<article data-history-node-id=\"2720\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-67\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-476<br \/>\nDate: 24 September 2021<\/strong><\/p>\n\n<p>On 24 September 2021 Google published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 94.0.4606.61<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2021-37973 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop_24.html\">https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop_24.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-67","alert_type":396,"serial_number":"AV21-476","subject":null,"moderation_state":"published","external_url":null},{"nid":2721,"title":"IBM security advisory","uuid":"686c90df-9532-4ff5-b710-edf5cae6f6be","banner":null,"lang":"en","date_modified":"2021-09-27","date_modified_ts":"2021-09-27T15:25:42Z","date_created":"2021-09-27T15:25:26Z","summary":null,"body":["<article data-history-node-id=\"2721\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-66\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-477<br \/>\nDate: 27 September 2021<\/strong><\/p>\n\n<p>Between 20 and 26 September 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise \u2013 V11.0.0.0 to V11.0.0.13 and V12.0.1.0<\/li>\n\t<li>IBM QRadar \u2013 7.3.0 to 7.3.3 Patch 9 and 7.4.0 to 7.4.3 Patch 2<\/li>\n\t<li>IBM Cloud Pak System \u2013 version 2.3.x.x<\/li>\n\t<li>ClevOS (IBM Cloud Object Storage Systems) \u2013 multiple releases<\/li>\n\t<li>IBM i \u2013 versions 7.1, 7.2, 7.3 and 7.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-66","alert_type":396,"serial_number":"AV21-477","subject":null,"moderation_state":"published","external_url":null},{"nid":2722,"title":"Dell security advisory","uuid":"1fb899cd-aa7a-4f60-9a7c-a8448274d018","banner":null,"lang":"en","date_modified":"2021-09-28","date_modified_ts":"2021-09-28T15:22:02Z","date_created":"2021-09-28T15:22:02Z","summary":null,"body":["<article data-history-node-id=\"2722\" about=\"\/en\/alerts-advisories\/dell-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-478<br \/>\nDate: 28 September 2021<\/strong><\/p>\n\n<p>On 27 September 2021 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC PowerProtect Data Manager \u2013 versions 19.8 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Dell PowerProtect (DSA-2021-181)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191930\/dsa-2021-181-dell-emc-power-protect-data-manager-update-for-multiple-security-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191930\/dsa-2021-181-dell-emc-power-protect-data-manager-update-for-multiple-security-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-10","alert_type":396,"serial_number":"AV21-478","subject":null,"moderation_state":"published","external_url":null},{"nid":2723,"title":"Ubuntu security advisory","uuid":"e35af599-123c-411c-a8e2-8bebf904281b","banner":null,"lang":"en","date_modified":"2021-09-29","date_modified_ts":"2021-09-29T12:39:14Z","date_created":"2021-09-29T12:39:14Z","summary":null,"body":["<article data-history-node-id=\"2723\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-479<br \/>\nDate: 29 September 2021<\/strong><\/p>\n\n<p>On 28 September 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or allow execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5091-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5091-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5091-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5092-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5092-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5092-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices \">https:\/\/ubuntu.com\/security\/notices\u00a0<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-24","alert_type":396,"serial_number":"AV21-479","subject":null,"moderation_state":"published","external_url":null},{"nid":2724,"title":"[Control systems] Siemens security advisory","uuid":"1c785d5a-e21e-4821-bfe4-ecf906087fee","banner":null,"lang":"en","date_modified":"2021-09-29","date_modified_ts":"2021-09-29T12:46:51Z","date_created":"2021-09-29T12:46:51Z","summary":null,"body":["<article data-history-node-id=\"2724\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-480<br \/>\nDate: 29 September 2021<\/strong><\/p>\n\n<p>On 28 September 2021 Siemens published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Solid Edge SE2021 \u2013 versions prior to SE2021MP8<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, code execution or information exposure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Solid Edge SE2021 (SSA-728618)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-728618.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-728618.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-34","alert_type":398,"serial_number":"AV21-480","subject":null,"moderation_state":"published","external_url":null},{"nid":2725,"title":"Red Hat security advisory","uuid":"62df4282-6ee2-429a-88bd-3f70a2a1a35a","banner":null,"lang":"en","date_modified":"2021-09-29","date_modified_ts":"2021-09-29T12:52:08Z","date_created":"2021-09-29T12:52:08Z","summary":null,"body":["<article data-history-node-id=\"2725\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-481<br \/>\nDate: 29 September 2021<\/strong><\/p>\n\n<p>On 28 September 2021 Red Hat published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Red Hat Quay 3 \u2013 version 3.5.6<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Red Hat Quay 3:<br \/><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2021-3762\">https:\/\/access.redhat.com\/security\/cve\/cve-2021-3762<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-5","alert_type":396,"serial_number":"AV21-481","subject":null,"moderation_state":"published","external_url":null},{"nid":2726,"title":"Dell security advisory","uuid":"64bf3645-e686-42ac-834e-d1ff0e1a99a5","banner":null,"lang":"en","date_modified":"2021-09-29","date_modified_ts":"2021-09-29T15:21:40Z","date_created":"2021-09-29T15:21:40Z","summary":null,"body":["<article data-history-node-id=\"2726\" about=\"\/en\/alerts-advisories\/dell-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-482<br \/>\nDate: 29 September 2021<\/strong><\/p>\n\n<p>On 28 September 2021 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Dell EMC VxRail Appliance (DSA-2021-196)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191991\/dsa-2021-196-dell-emc-vxrail-appliance-security-update-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000191991\/dsa-2021-196-dell-emc-vxrail-appliance-security-update-for-multiple-third-party-component-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-11","alert_type":396,"serial_number":"AV21-482","subject":null,"moderation_state":"published","external_url":null},{"nid":2727,"title":"Ubuntu security advisory","uuid":"9689a191-2392-4e2c-b128-09c10f34e201","banner":null,"lang":"en","date_modified":"2021-09-29","date_modified_ts":"2021-09-29T15:35:59Z","date_created":"2021-09-29T15:35:59Z","summary":null,"body":["<article data-history-node-id=\"2727\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-483<br \/>\nDate: 29 September 2021<\/strong><\/p>\n\n<p>On 29 September 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or allow execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5092-2)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5092-2\">https:\/\/ubuntu.com\/security\/notices\/USN-5092-2<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5094-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5094-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5094-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a> \u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-25","alert_type":396,"serial_number":"AV21-483","subject":null,"moderation_state":"published","external_url":null},{"nid":2728,"title":"Google Chrome security advisory","uuid":"ec960940-6381-4bbd-88db-606d6674e451","banner":null,"lang":"en","date_modified":"2021-10-01","date_modified_ts":"2021-10-01T14:02:41Z","date_created":"2021-10-01T14:02:41Z","summary":null,"body":["<article data-history-node-id=\"2728\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-68\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-484<br \/>\nDate: 1 October 2021<\/strong><\/p>\n\n<p>On 30 September 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 94.0.4606.71<\/li>\n<\/ul><p>Google is aware that exploits for CVE-2021-37975 and CVE-2021-37976 exist in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop_30.html\">https:\/\/chromereleases.googleblog.com\/2021\/09\/stable-channel-update-for-desktop_30.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-68","alert_type":396,"serial_number":"AV21-484","subject":null,"moderation_state":"published","external_url":null},{"nid":2729,"title":" [Control systems] Boston Scientific security advisory","uuid":"48dbbb59-7780-4ce2-880f-c972fdd601b5","banner":null,"lang":"en","date_modified":"2021-10-01","date_modified_ts":"2021-10-01T17:39:27Z","date_created":"2021-10-01T17:39:27Z","summary":null,"body":["<article data-history-node-id=\"2729\" about=\"\/en\/alerts-advisories\/control-systems-boston-scientific-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-485<br \/>\nDate: 1 October 2021<\/strong><\/p>\n\n<p>On 30 September 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ZOOM LATITUDE Programmer\/Recorder\/Monitor \u2013 Model 3120<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to access patient protected health information (PHI) or compromise the integrity of the device.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSMA-21-273-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-273-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-273-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-boston-scientific-security-advisory","alert_type":398,"serial_number":"AV21-485","subject":null,"moderation_state":"published","external_url":null},{"nid":2730,"title":"IBM security advisory","uuid":"3a227292-3edb-4cca-b8e1-ed5c509cabf3","banner":null,"lang":"en","date_modified":"2021-10-04","date_modified_ts":"2021-10-04T18:35:22Z","date_created":"2021-10-04T18:35:22Z","summary":null,"body":["<article data-history-node-id=\"2730\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-67\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-486<br \/>\nDate: 4 October 2021<\/strong><\/p>\n\n<p>Between 27 September and 3 October 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Watson Discovery for IBM Cloud Pak for Data \u2013 versions 2.0.0 to 2.2.1 and 4.0.0<\/li>\n\t<li>IBM QRadar Azure marketplace images - versions 7.3.0 to 7.3.3 Patch 9 and 7.4.0 to 7.4.3 Patch 2<\/li>\n\t<li>Cloud Pak for Security (CP4S) - versions 1.7.0.0, 1.7.1.0 and 1.7.2.0<\/li>\n\t<li>IBM Business Automation Workflow - versions V21.0, V20.0, V19.0 and V18.0<\/li>\n\t<li>IBM Business Process Manager - version V8.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Watson Discovery for IBM Cloud Pak for Data<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-python-cryptography\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-python-cryptography\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-ratpack-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-watson-discovery-for-ibm-cloud-pak-for-data-affected-by-vulnerability-in-ratpack-2\/<\/a><\/p>\n\n<p>IBM QRadar Azure marketplace images<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-qradar-azure-marketplace-images-include-open-management-infrastructure-rpm-which-is-vulnerable-to-remote-code-execution-cve-2021-38647-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-qradar-azure-marketplace-images-include-open-management-infrastructure-rpm-which-is-vulnerable-to-remote-code-execution-cve-2021-38647-2\/<\/a><\/p>\n\n<p>Cloud Pak for Security (CP4S)<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cloud-pak-for-security-is-vulnerable-to-several-cves\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cloud-pak-for-security-is-vulnerable-to-several-cves\/<\/a><\/p>\n\n<p>IBM Business Automation Workflow and IBM Business Process Manager<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-may-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-offline-documentation\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-may-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-offline-documentation\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-67","alert_type":396,"serial_number":"AV21-486","subject":null,"moderation_state":"published","external_url":null},{"nid":2731,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"7a16fd72-bfa1-4987-a1ad-b640362735b3","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T11:42:46Z","date_created":"2021-10-05T11:42:46Z","summary":null,"body":["<article data-history-node-id=\"2731\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-487<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 1 October 2021 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 94.0.992.38<\/li>\n<\/ul><p>Microsoft is aware of reporting that CVE-2021-37975 and CVE-2021-37976 have an exploit in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-1-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-1-2021<\/a><br \/>\n\u00a0<br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-3","alert_type":396,"serial_number":"AV21-487","subject":null,"moderation_state":"published","external_url":null},{"nid":2732,"title":"Android security advisory \u2013 October 2021 monthly rollup","uuid":"9933b107-c521-4b7b-b8ec-dc1a68c6a6b6","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T11:46:25Z","date_created":"2021-10-05T11:46:25Z","summary":null,"body":["<article data-history-node-id=\"2732\" about=\"\/en\/alerts-advisories\/android-security-advisory-october-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-488<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 4 October 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-10-01\">https:\/\/source.android.com\/security\/bulletin\/2021-10-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-october-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-488","subject":null,"moderation_state":"published","external_url":null},{"nid":2733,"title":"Mozilla security advisory","uuid":"25edc528-2e08-41ee-911c-1db2dd0902a7","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T14:48:55Z","date_created":"2021-10-05T14:48:55Z","summary":null,"body":["<article data-history-node-id=\"2733\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-45\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-489<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 Mozilla published Security Advisories to address multiple vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 93<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 78.15 and 91.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-43)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-43\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-43\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-44 and MFSA 2021-45)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-44\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-44\/<\/a><br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-45\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-45\/<\/a><\/p>\n\n<p><strong>Note to Reader<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-45","alert_type":396,"serial_number":"AV21-489","subject":null,"moderation_state":"published","external_url":null},{"nid":2734,"title":"Dell security advisory","uuid":"b3569f88-138f-4817-8a6f-3ee73fedd504","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T16:47:42Z","date_created":"2021-10-05T16:47:42Z","summary":null,"body":["<article data-history-node-id=\"2734\" about=\"\/en\/alerts-advisories\/dell-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-490<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Integrated Data Protection Appliance \u2013 versions prior to 2.7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Dell EMC Integrated Data Protection Appliance (DSA-2021-203)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000192191\/dsa-2021-203-dell-emc-integrated-data-protection-appliance-security-update-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000192191\/dsa-2021-203-dell-emc-integrated-data-protection-appliance-security-update-for-multiple-third-party-component-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-12","alert_type":396,"serial_number":"AV21-490","subject":null,"moderation_state":"published","external_url":null},{"nid":2735,"title":"Fortinet security advisory","uuid":"b12e9206-a4bb-4de4-aa93-ed2bf848eaba","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T17:26:08Z","date_created":"2021-10-05T17:26:08Z","summary":null,"body":["<article data-history-node-id=\"2735\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-491<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 Fortinet published PSIRT Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiClientEMS \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Fortinet PSIRT Advisories<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-13","alert_type":396,"serial_number":"AV21-491","subject":null,"moderation_state":"published","external_url":null},{"nid":2736,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"8095ae67-2776-4131-80f2-ec6827e1c164","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T18:38:42Z","date_created":"2021-10-05T18:38:42Z","summary":null,"body":["<article data-history-node-id=\"2736\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-493<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>GOT2000 Series GT21 Model \u2013 multiple models and versions<\/li>\n\t<li>GOT SIMPLE Series GS21 Model \u2013 multiple models and versions<\/li>\n\t<li>Tension Controller LE7-40GU-L \u2013 all versions<\/li>\n<\/ul><p>\u00a0Exploitation of these vulnerabilities could result in denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-278-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-22","alert_type":398,"serial_number":"AV21-493","subject":null,"moderation_state":"published","external_url":null},{"nid":2737,"title":"[Control systems] Honeywell security advisory","uuid":"86a74f75-b6af-471b-9dee-0526e4f7db74","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T18:42:45Z","date_created":"2021-10-05T18:42:45Z","summary":null,"body":["<article data-history-node-id=\"2737\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-492<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>C200 - all versions<\/li>\n\t<li>C200E - all versions<\/li>\n\t<li>C300 and ACE controllers - all versions<\/li>\n<\/ul><p>\u00a0Exploitation of these vulnerabilities could result in remote code execution and denial-of-service.<br \/>\n\u00a0<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>ICS Advisory (ICSA-21-278-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-5","alert_type":398,"serial_number":"AV21-492","subject":null,"moderation_state":"published","external_url":null},{"nid":2738,"title":"[Control systems] Emerson security advisory","uuid":"a04980eb-0ca8-425c-ba4a-6be1e8b01119","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T18:49:36Z","date_created":"2021-10-05T18:49:36Z","summary":null,"body":["<article data-history-node-id=\"2738\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-494<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>WirelessHART 1410 Gateway - versions prior to v4.7.94<\/li>\n\t<li>WirelessHART 1410D Gateway - versions prior to v4.7.94<\/li>\n\t<li>WirelessHART 1420 Gateway - versions prior to v4.7.94<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-278-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-5","alert_type":398,"serial_number":"AV21-494","subject":null,"moderation_state":"published","external_url":null},{"nid":2747,"title":"Apache security advisory \u2013 update 1","uuid":"b46c6698-0e97-471c-a0d5-7a4a262815c0","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T15:11:53Z","date_created":"2021-10-05T18:50:24Z","summary":null,"body":["<article data-history-node-id=\"2747\" about=\"\/en\/alerts-advisories\/apache-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-495<br \/>\nDate: 5 October 2021<br \/>\nUpdated: 8 October 2021<\/strong><\/p>\n\n<p>On 4 October 2021 Apache published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Apache HTTP Server - version 2.4.49<\/li>\n<\/ul><p><strong>UPDATE 1<\/strong><\/p>\n\n<p>On 7 October 2021 Apache released HTTP Server version 2.4.51 to address deficient remediation of CVE-2021-41773 in the following product:<\/p>\n\n<ul><li>Apache HTTP Server \u2013 version 2.4.50<\/li>\n<\/ul><p><strong>END OF UPDATE 1<\/strong><\/p>\n\n<p>Exploitation of some of these vulnerabilities may result in information disclosure.<\/p>\n\n<p>Apache has stated that CVE-2021-41773 is known to be exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Apache Security Bulletin<\/p>\n\n<p><a href=\"https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html\">https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html<\/a> \u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-3","alert_type":396,"serial_number":"AV21-495","subject":null,"moderation_state":"published","external_url":null},{"nid":2739,"title":"HPE security advisory","uuid":"e43da88d-8446-43c2-9c29-3da561909ced","banner":null,"lang":"en","date_modified":"2021-10-05","date_modified_ts":"2021-10-05T19:34:47Z","date_created":"2021-10-05T19:34:47Z","summary":null,"body":["<article data-history-node-id=\"2739\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-496<br \/>\nDate: 5 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 HPE published a Security Bulletin to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>HP\/HPE 3PAR StoreServ \u2013 multiple platforms and versions<\/li>\n\t<li>HPE Primera 600 Storage \u2013 multiple versions<\/li>\n\t<li>HPE Alletra 9000 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HPE 3PAR StoreServe, HPE Primera Storage and HPE Alletra 9000 Storage Arrays (HPESBST04191)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04191en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04191en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-28","alert_type":396,"serial_number":"AV21-496","subject":null,"moderation_state":"published","external_url":null},{"nid":2896,"title":"[Control systems] Moxa security advisory","uuid":"5e9e3e9b-a479-4dfa-9f70-996f98f9a413","banner":null,"lang":"en","date_modified":"2021-12-24","date_modified_ts":"2021-12-24T13:46:19Z","date_created":"2021-10-06T13:29:15Z","summary":null,"body":["<article data-history-node-id=\"2896\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-497<br \/>\nDate: 6 October 2021<\/strong><\/p>\n\n<p>On 5 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>MXview Network Management Software - versions 3.x to 3.2.2<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities may allow an actor to create or overwrite critical files to execute code, gain access to the program, obtain credentials, disable the software, read and modify otherwise inaccessible data, create remote connections to internal communication channels, or interact with and use MQTT remotely.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-278-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-278-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-4","alert_type":398,"serial_number":"AV21-497","subject":null,"moderation_state":"published","external_url":null},{"nid":2740,"title":"Cisco security advisory","uuid":"75a18516-e151-4d68-bc55-e6d423219f68","banner":null,"lang":"en","date_modified":"2021-10-06","date_modified_ts":"2021-10-06T18:41:25Z","date_created":"2021-10-06T18:41:25Z","summary":null,"body":["<article data-history-node-id=\"2740\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-93\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-498<br \/>\nDate: 6 October 2021<\/strong><\/p>\n\n<p>On 6 October 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were high severity updates for the following:<\/p>\n\n<ul><li>Cisco AnyConnect Secure Mobility Client for Linux and Mac OS Release \u2013 versions prior to 4.10.03104<\/li>\n\t<li>Cisco ATA 190 Series Analog Telephone Adapter \u2013 multiple versions<\/li>\n\t<li>Cisco Identity Services Engine \u2013 multiple versions<\/li>\n\t<li>Cisco Small Business 220 Series Smart Switches \u2013 versions 1.2.0.6 and prior<\/li>\n\t<li>Cisco Intersight Virtual Appliance \u2013 versions 1.0.9-150 to 1.0.9-292<\/li>\n\t<li>Cisco AsyncOS for Cisco Web Security Appliance \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary remote code execution, denial-of-service and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-93","alert_type":396,"serial_number":"AV21-498","subject":null,"moderation_state":"published","external_url":null},{"nid":2741,"title":"[Control systems] Exacq Technologies security advisory","uuid":"3b05a798-3a04-4aed-8780-b87b6672cabc","banner":null,"lang":"en","date_modified":"2021-10-08","date_modified_ts":"2021-10-08T15:38:48Z","date_created":"2021-10-08T15:38:48Z","summary":null,"body":["<article data-history-node-id=\"2741\" about=\"\/en\/alerts-advisories\/control-systems-exacq-technologies-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-499<br \/>\nDate: 8 October 2021<\/strong><\/p>\n\n<p>On 7 October 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>exacqVision Web Service - versions 21.06.11.0 and prior<\/li>\n\t<li>exacqVision Server 32-bit - versions 21.06.11.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-280-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-01<\/a> \u00a0\u00a0<\/p>\n\n<p>ICS Advisory (ICSA-21-280-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-exacq-technologies-security-advisory-1","alert_type":398,"serial_number":"AV21-499","subject":null,"moderation_state":"published","external_url":null},{"nid":2742,"title":"[Control systems] FATEK Automation security advisory","uuid":"800b6f60-f809-4bed-9c70-3b5826a3d104","banner":null,"lang":"en","date_modified":"2021-10-08","date_modified_ts":"2021-10-08T15:56:19Z","date_created":"2021-10-08T15:55:53Z","summary":null,"body":["<article data-history-node-id=\"2742\" about=\"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-500<br \/>\nDate: 8 October 2021<\/strong><\/p>\n\n<p>On 7 October 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>WinProladder \u2013 versions 3.30 and prior<\/li>\n\t<li>Communication Server \u2013 versions 1.13 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, remote code execution, and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-280-06)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-06\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-06<\/a> \u00a0<\/p>\n\n<p>ICS Advisory (ICSA-21-280-07)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-07\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-07<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-2","alert_type":398,"serial_number":"AV21-500","subject":null,"moderation_state":"published","external_url":null},{"nid":2743,"title":"[Control systems] InHand Networks security advisory","uuid":"e43a754d-cde0-414d-9b19-21896176f0f1","banner":null,"lang":"en","date_modified":"2021-10-08","date_modified_ts":"2021-10-08T17:44:49Z","date_created":"2021-10-08T17:44:49Z","summary":null,"body":["<article data-history-node-id=\"2743\" about=\"\/en\/alerts-advisories\/control-systems-inhand-networks-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-501<br \/>\nDate: 8 October 2021<\/strong><\/p>\n\n<p>On 7 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>IR615 Router \u2013 versions 2.3.0.r4724 and 2.3.0.r4870<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and execution of remote code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-280-05)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-05<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inhand-networks-security-advisory","alert_type":398,"serial_number":"AV21-501","subject":null,"moderation_state":"published","external_url":null},{"nid":2744,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"6c160d6e-41c7-4ab8-889b-d60fa85165e6","banner":null,"lang":"en","date_modified":"2021-10-08","date_modified_ts":"2021-10-08T17:46:51Z","date_created":"2021-10-08T17:46:51Z","summary":null,"body":["<article data-history-node-id=\"2744\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-502<br \/>\nDate: 8 October 2021<\/strong><\/p>\n\n<p>On 7 October 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>R12CCPU-V \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-280-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-04<\/a> \u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-23","alert_type":398,"serial_number":"AV21-502","subject":null,"moderation_state":"published","external_url":null},{"nid":2746,"title":"[Control systems] Mobile Industrial Robots security advisory","uuid":"3895baec-3c3e-4aa1-a903-4260e180d759","banner":null,"lang":"en","date_modified":"2021-10-08","date_modified_ts":"2021-10-08T18:11:19Z","date_created":"2021-10-08T17:48:37Z","summary":null,"body":["<article data-history-node-id=\"2746\" about=\"\/en\/alerts-advisories\/control-systems-mobile-industrial-robots-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-503<br \/>\nDate: 8 October 2021<\/strong><\/p>\n\n<p>On 7 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MiR100, MiR200, MiR250, MiR500, MiR1000 - versions prior to 2.10.2.1<\/li>\n\t<li>MiR Fleet - versions prior to 2.10.2.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in privilege escalation, data exfiltration, control of the robot, and a denial-of-service condition.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-280-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-280-02<\/a> \u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mobile-industrial-robots-security-advisory","alert_type":398,"serial_number":"AV21-503","subject":null,"moderation_state":"published","external_url":null},{"nid":2745,"title":"Google Chrome security advisory","uuid":"ba18963b-2609-46f8-ac97-9ce7611fe3e9","banner":null,"lang":"en","date_modified":"2021-10-08","date_modified_ts":"2021-10-08T17:55:30Z","date_created":"2021-10-08T17:55:30Z","summary":null,"body":["<article data-history-node-id=\"2745\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-69\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-504<br \/>\nDate: 8 October 2021<\/strong><\/p>\n\n<p>On 7 October 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 94.0.4606.81<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/10\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/10\/stable-channel-update-for-desktop.html<\/a> \u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-69","alert_type":396,"serial_number":"AV21-504","subject":null,"moderation_state":"published","external_url":null},{"nid":2748,"title":"SAP security advisory \u2013 October 2021 monthly rollup","uuid":"fd936883-75ff-4b4f-a99c-924f00ae7451","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T17:16:49Z","date_created":"2021-10-12T17:16:49Z","summary":null,"body":["<article data-history-node-id=\"2748\" about=\"\/en\/alerts-advisories\/sap-security-advisory-october-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-505<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 12 October 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Environmental Compliance - version 3.0<\/li>\n\t<li>SAP NetWeaver AS ABAP and ABAP Platform - versions 700, 701, 702, 710, 730, 731, 740, 750, 751, 752, 753, 754, 755 and 756<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. \u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 October 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=587169983\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=587169983<\/a><\/p>\n\n<p><strong>Note to Readers <\/strong>\u00a0<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-october-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-505","subject":null,"moderation_state":"published","external_url":null},{"nid":2749,"title":"[Control systems] Advantech security advisory","uuid":"ce3314ad-a8d3-49a7-b8f3-f9c1a9c4b534","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T17:20:56Z","date_created":"2021-10-12T17:20:56Z","summary":null,"body":["<article data-history-node-id=\"2749\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-22\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-506<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 12 October 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>WebAccess - version 9.02 and prior<\/li>\n\t<li>WebAccess\/SCADA - version 9.0.3 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-285-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-285-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-285-01<\/a>\u00a0 \u00a0<\/p>\n\n<p>ICS Advisory (ICSA-21-285-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-285-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-285-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-22","alert_type":398,"serial_number":"AV21-506","subject":null,"moderation_state":"published","external_url":null},{"nid":2750,"title":"Mozilla security advisory","uuid":"3dcc73f7-4d93-4b28-bf4a-611f3d94ca80","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T19:03:51Z","date_created":"2021-10-12T19:03:51Z","summary":null,"body":["<article data-history-node-id=\"2750\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-46\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-510<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 6 October 2021 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 91.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Thunderbird (MFSA 2021-47)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-47\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-47\/<\/a><\/p>\n\n<p><strong>Note to Reader<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-46","alert_type":396,"serial_number":"AV21-510","subject":null,"moderation_state":"published","external_url":null},{"nid":2754,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"854a7e78-3301-48e7-87df-f474a970c48f","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T19:06:38Z","date_created":"2021-10-12T19:06:23Z","summary":null,"body":["<article data-history-node-id=\"2754\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-507<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 11 October 2021 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 94.0.992.47<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-11-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-11-2021<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-4","alert_type":396,"serial_number":"AV21-507","subject":null,"moderation_state":"published","external_url":null},{"nid":2751,"title":"[Control systems] Schneider Electric security advisory","uuid":"55a12533-17ce-4bfb-9b12-ebe9a8e037e6","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T19:07:13Z","date_created":"2021-10-12T19:07:13Z","summary":null,"body":["<article data-history-node-id=\"2751\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-511<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 12 October 2021 Schneider Electric published Security Notifications to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Modicon TM5 \u2013 multiple models and versions<\/li>\n\t<li>Modicon M218 Logic Controller \u2013 version v5.1.0.6 and prior<\/li>\n\t<li>Schneider Conext Advisor 2 Cloud \u2013 version 2.02 and prior<\/li>\n\t<li>Schneider Conext Advisor 2 Gateway \u2013 version 1.28.45 and prior<\/li>\n\t<li>Schneider Conext Control V2 Gateway \u2013 version 2.6 and prior<\/li>\n\t<li>IGSS Data Collector \u2013 version V15.0.0.21243 and prior<\/li>\n\t<li>ConneXium Network \u2013 all versions<\/li>\n\t<li>spaceLYnk \u2013 version V2.6.1 and prior<\/li>\n\t<li>Wiser for KNX \u2013 version V2.6.1 and prior<\/li>\n\t<li>fellerLYnk \u2013 version V2.6.1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, denial of service and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-26","alert_type":398,"serial_number":"AV21-511","subject":null,"moderation_state":"published","external_url":null},{"nid":2756,"title":"Apple security advisory","uuid":"4a032800-a44a-4e92-89a7-2c4b3cb4df7d","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T19:15:53Z","date_created":"2021-10-12T19:08:08Z","summary":null,"body":["<article data-history-node-id=\"2756\" about=\"\/en\/alerts-advisories\/apple-security-advisory-43\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-508<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 11 October 2021 Apple published a Security Update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15.0.2<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.0.2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow arbitrary code execution.<\/p>\n\n<p>Apple is aware of a report that this issue may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>iOS and iPadOS<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-ca\/HT212846\">https:\/\/support.apple.com\/en-ca\/HT212846<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-43","alert_type":396,"serial_number":"AV21-508","subject":null,"moderation_state":"published","external_url":null},{"nid":2752,"title":"[Control systems] Siemens security advisory","uuid":"d7bfb7d7-775f-4f9a-b32a-6af98920bd81","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T19:11:09Z","date_created":"2021-10-12T19:11:09Z","summary":null,"body":["<article data-history-node-id=\"2752\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-35\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-512<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 12 October 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SCALANCE W1750D \u2013 multiple versions<\/li>\n\t<li>SINUMERIK 808D \u2013 all versions<\/li>\n\t<li>SINUMERIK 828D \u2013 versions prior to V4.95<\/li>\n\t<li>RUGGEDCOM ROX \u2013 multiple platforms, versions prior to V2.14.1<\/li>\n\t<li>SINEC NMS \u2013 versions prior to V1.0 SP2 Update 1<\/li>\n\t<li>SIMATIC Process Historian \u2013 multiple platforms, all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial of service, remote code execution, privilege escalation and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Publications<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-35","alert_type":398,"serial_number":"AV21-512","subject":null,"moderation_state":"published","external_url":null},{"nid":2753,"title":"IBM security advisory","uuid":"2536878a-92d9-4442-8d9a-7cbb8c042583","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T19:12:57Z","date_created":"2021-10-12T19:12:41Z","summary":null,"body":["<article data-history-node-id=\"2753\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-68\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-509<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>Between 4 and 11 October 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Virtualization Engine TS7700 (3957-VEC and 3957-VED) \u2013 versions 8.51.0.63, 8.51.1.26 and 8.52.100.32<\/li>\n\t<li>IBM POWER9 \u2013 multiple products and versions<\/li>\n\t<li>IBM Cloud Pak System \u2013 versions 2.3.x.x<\/li>\n\t<li>IBM Sterling B2B Integrator (IT37913) \u2013 versions 6.0.1.0 to 6.0.3.4 and 6.1.0.0 to 6.1.0.2<\/li>\n\t<li>IBM Sterling B2B Integrator (IT37848) \u2013 versions 5.2.0.0 to 6.0.3.4 and 6.1.0.0 to 6.1.0.3<\/li>\n\t<li>IBM Sterling B2B Integrator (IT38512) \u2013 versions 5.2.0.0 to 5.2.6.5_4, 6.0.0.0 to 6.0.0.6, 6.0.1.0 to 6.0.3.4 and 6.1.0.0 to 6.1.0.2<\/li>\n\t<li>IBM Sterling B2B Integrator (IT36552) \u2013 versions 5.2.0.0 to 5.2.6.5_3, 6.0.0.0 to 6.0.0.6, 6.0.1.0 to 6.0.3.4 and 6.1.0.0 to 6.1.0.2<\/li>\n\t<li>IBM App Connect Enterprise Certified Container \u2013 versions 1.0 to 1.5 with Operator<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-68","alert_type":396,"serial_number":"AV21-509","subject":null,"moderation_state":"published","external_url":null},{"nid":2755,"title":"Microsoft security advisory \u2013 October 2021 monthly rollup","uuid":"12741c23-cb23-4f54-86cd-baaab0b5acf6","banner":null,"lang":"en","date_modified":"2021-10-12","date_modified_ts":"2021-10-12T19:16:02Z","date_created":"2021-10-12T19:16:02Z","summary":null,"body":["<article data-history-node-id=\"2755\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-513<br \/>\nDate: 12 October 2021<\/strong><\/p>\n\n<p>On 12 October 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 10 and 11<\/li>\n\t<li>Windows Server Core version 20H2, version 2004, 2019 and 2022<\/li>\n\t<li>Windows Server 2019 and 2022<\/li>\n\t<li>Microsoft Word 2013 RT SP1, 2013 SP1 and 2016<\/li>\n\t<li>Microsoft Office 2019, Online Server, and Web Apps Server 2013 SP1<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2013 SP1 and 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.<\/p>\n\n<p>Of note, Microsoft has indicated that exploitation has been detected for the following vulnerability: CVE-2021-40449.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>October 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Oct\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Oct<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers\u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-october-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-513","subject":null,"moderation_state":"published","external_url":null},{"nid":2757,"title":"Ubuntu security advisory","uuid":"45c362ef-a11a-4ab1-8c77-adad6d1fcf8b","banner":null,"lang":"en","date_modified":"2021-10-13","date_modified_ts":"2021-10-13T16:18:56Z","date_created":"2021-10-13T16:16:55Z","summary":null,"body":["<article data-history-node-id=\"2757\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-514<br \/>\nDate: 13 October 2021<\/strong><\/p>\n\n<p>On 6 October 2021 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or allow execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5106-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5106-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5106-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices  \">https:\/\/ubuntu.com\/security\/notices\u00a0 <\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-26","alert_type":396,"serial_number":"AV21-514","subject":null,"moderation_state":"published","external_url":null},{"nid":2758,"title":"Adobe security advisory","uuid":"8a4775e7-b4cb-4ee6-b717-1fe83a86a2ec","banner":null,"lang":"en","date_modified":"2021-10-13","date_modified_ts":"2021-10-13T16:21:22Z","date_created":"2021-10-13T16:21:22Z","summary":null,"body":["<article data-history-node-id=\"2758\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-47\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-515<br \/>\nDate: 13 October 2021<\/strong><\/p>\n\n<p>On 12 October 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Acrobat DC and Reader DC for Windows \u2013 version 21.007.20095 and prior<\/li>\n\t<li>Acrobat DC and Reader DC for macOS \u2013 version 21.007.20096 and prior<\/li>\n\t<li>Acrobat 2020 and Reader 2020 \u2013 version 20.004.30015 and prior<\/li>\n\t<li>Acrobat 2017 and Reader 2017 \u2013 version 17.011.30202 and prior<\/li>\n\t<li>Adobe Acrobat Reader for Android \u2013 version 21.8.0 and prior<\/li>\n\t<li>Adobe Connect \u2013 version 11.2.2 and prior<\/li>\n\t<li>Adobe ops-cli \u2013 version 2.0.4 and prior<\/li>\n\t<li>Adobe Commerce \u2013 multiple versions<\/li>\n\t<li>Magento Open Source \u2013 multiple versions<\/li>\n\t<li>Adobe Campaign Standard \u2013 version 21.2.1 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\/security\/security-bulletin.ug.html\">https:\/\/helpx.adobe.com\/security.html\/security\/security-bulletin.ug.html<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-47","alert_type":396,"serial_number":"AV21-515","subject":null,"moderation_state":"published","external_url":null},{"nid":2759,"title":"Intel security advisory","uuid":"5aebe705-2179-439e-806f-594caabe64ea","banner":null,"lang":"en","date_modified":"2021-10-14","date_modified_ts":"2021-10-14T18:01:35Z","date_created":"2021-10-14T18:01:35Z","summary":null,"body":["<article data-history-node-id=\"2759\" about=\"\/en\/alerts-advisories\/intel-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-516<br \/>\nDate: 14 October 2021<\/strong><\/p>\n\n<p>On 12 October 2021 Intel published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Intel SGX SDK for Windows \u2013 version v2.12 and prior<\/li>\n\t<li>Intel SGX SDK for Linux \u2013 version v2.13 and prior<\/li>\n\t<li>Intel Processors supporting SGX2 \u2013 multiple platforms and versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Intel SGX SDK Advisory (INTEL-SA-00548)<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00548.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00548.html<\/a><\/p>\n\n<p>Intel Product Security Center Advisories<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-19","alert_type":396,"serial_number":"AV21-516","subject":null,"moderation_state":"published","external_url":null},{"nid":2760,"title":"Palo Alto Networks security advisory","uuid":"0f86f5d2-4d70-446c-bfec-fb976dba4d6d","banner":null,"lang":"en","date_modified":"2021-10-14","date_modified_ts":"2021-10-14T18:04:39Z","date_created":"2021-10-14T18:04:39Z","summary":null,"body":["<article data-history-node-id=\"2760\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-517<br \/>\nDate: 14 October 2021<\/strong><\/p>\n\n<p>On 13 October 2021 Palo Alto Networks published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li><a name=\"_Hlk82090969\" id=\"_Hlk82090969\">GlobalProtect App \u2013 multiple platforms and versions<\/a><\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution with SYSTEM privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>GlobalProtect App (GPC-13039)<\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3057\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3057<\/a><\/p>\n\n<p>Palo Alto Networks Security Advisories<\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-12","alert_type":396,"serial_number":"AV21-517","subject":null,"moderation_state":"published","external_url":null},{"nid":2761,"title":"Juniper Networks security advisory","uuid":"b9ace316-15aa-48e5-b3f2-5eceae8df3c5","banner":null,"lang":"en","date_modified":"2021-10-14","date_modified_ts":"2021-10-14T18:07:01Z","date_created":"2021-10-14T18:07:01Z","summary":null,"body":["<article data-history-node-id=\"2761\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-10\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-518<br \/>\nDate: 14 October 2021<\/strong><\/p>\n\n<p>On 13 October 2021 Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Juno OS \u2013 multiple platforms and versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Juniper Networks Security Advisories<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-10","alert_type":396,"serial_number":"AV21-518","subject":null,"moderation_state":"published","external_url":null},{"nid":2762,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"2c9d3687-f70c-412d-8cc5-557da7b143be","banner":null,"lang":"en","date_modified":"2021-10-15","date_modified_ts":"2021-10-15T15:47:44Z","date_created":"2021-10-15T15:47:44Z","summary":null,"body":["<article data-history-node-id=\"2762\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-24\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-519<br \/>\nDate: 15 October 2021<\/strong><\/p>\n\n<p>On 14 October 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC iQ-R Series CPU Module:\n\t<ul><li>R08\/16\/32\/120SFCPU - all versions<\/li>\n\t\t<li>R08\/16\/32\/120PSFCPU - all versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to obtain credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-287-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-287-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-287-03<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-24","alert_type":398,"serial_number":"AV21-519","subject":null,"moderation_state":"published","external_url":null},{"nid":2763,"title":"[Control systems] Uffizio security advisory","uuid":"bb67a19d-11c7-42c1-b48c-b67fe90c08b1","banner":null,"lang":"en","date_modified":"2021-10-15","date_modified_ts":"2021-10-15T18:21:44Z","date_created":"2021-10-15T18:21:44Z","summary":null,"body":["<article data-history-node-id=\"2763\" about=\"\/en\/alerts-advisories\/control-systems-uffizio-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-520<br \/>\nDate: 15 October 2021<\/strong><\/p>\n\n<p>On 14 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>GPS Tracker \u2013 all versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-287-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-287-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-287-02<\/a>\u00a0\u00a0\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-uffizio-security-advisory","alert_type":398,"serial_number":"AV21-520","subject":null,"moderation_state":"published","external_url":null},{"nid":2764,"title":"IBM security advisory","uuid":"08b0b6cf-e499-4ef9-9120-fef5785755ed","banner":null,"lang":"en","date_modified":"2021-10-18","date_modified_ts":"2021-10-18T15:50:23Z","date_created":"2021-10-18T15:50:23Z","summary":null,"body":["<article data-history-node-id=\"2764\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-69\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-521<br \/>\nDate: 18 October 2021<\/strong><\/p>\n\n<p>Between 12 and 17 October 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Foundry Migration Runtime \u2013 version 4.1.1<\/li>\n\t<li>IBM Cognos Analytics with Watson \u2013 versions 11.2.0 and 11.1.7<\/li>\n\t<li>IBM Cloud Pak for Security \u2013 versions 1.7.2.0, 1.7.1.0 and 1.7.0.0<\/li>\n\t<li>IBM Security Access Manager \u2013 version 9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Cloud Foundry Migration Runtime<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-affect-ibm-cloud-foundry-migration-runtime\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-affect-ibm-cloud-foundry-migration-runtime\/<\/a><\/p>\n\n<p>IBM Cognos Analytics with Watson<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cognos-analytics-with-watson-11-2-1-has-addressed-multiple-vulnerabilities\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-cognos-analytics-with-watson-11-2-1-has-addressed-multiple-vulnerabilities\/<\/a><\/p>\n\n<p>IBM Cloud Pak for Security<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cloud-pak-for-security-is-vulnerable-to-several-cves-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cloud-pak-for-security-is-vulnerable-to-several-cves-2\/<\/a><\/p>\n\n<p>IBM Security Access Manager<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-have-been-addressed-in-ibm-security-access-manager\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-security-vulnerabilities-have-been-addressed-in-ibm-security-access-manager\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-69","alert_type":396,"serial_number":"AV21-521","subject":null,"moderation_state":"published","external_url":null},{"nid":2765,"title":"[Control systems] AUVESY security advisory","uuid":"98111323-fde5-48a3-857d-245613d1eef5","banner":null,"lang":"en","date_modified":"2021-10-19","date_modified_ts":"2021-10-19T19:33:35Z","date_created":"2021-10-19T19:33:35Z","summary":null,"body":["<article data-history-node-id=\"2765\" about=\"\/en\/alerts-advisories\/control-systems-auvesy-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-522<br \/>\nDate: 19 October 2021<\/strong><\/p>\n\n<p>On 19 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Versiondog - versions prior to v8.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-292-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-292-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-292-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-auvesy-security-advisory","alert_type":398,"serial_number":"AV21-522","subject":null,"moderation_state":"published","external_url":null},{"nid":2766,"title":"Google Chrome security advisory","uuid":"72acad2d-b0f3-425b-a36d-231336a6cb58","banner":null,"lang":"en","date_modified":"2021-10-20","date_modified_ts":"2021-10-20T12:18:29Z","date_created":"2021-10-20T12:18:29Z","summary":null,"body":["<article data-history-node-id=\"2766\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-70\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-523<br \/>\nDate: 20 October 2021<\/strong><\/p>\n\n<p>On 19 October 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 95.0.4638.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/10\/stable-channel-update-for-desktop_19.html\">https:\/\/chromereleases.googleblog.com\/2021\/10\/stable-channel-update-for-desktop_19.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-70","alert_type":396,"serial_number":"AV21-523","subject":null,"moderation_state":"published","external_url":null},{"nid":2767,"title":"[Control systems] Trane security advisory","uuid":"95da9cf0-99be-4322-a65a-bcd7e7a5cc0d","banner":null,"lang":"en","date_modified":"2021-10-20","date_modified_ts":"2021-10-20T14:54:13Z","date_created":"2021-10-20T13:22:29Z","summary":null,"body":["<article data-history-node-id=\"2767\" about=\"\/en\/alerts-advisories\/control-systems-trane-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-524<br \/>\nDate: 20 October 2021<\/strong><\/p>\n\n<p>On 19 October 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Tracer SC - firmware v3.8 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow for redirection to a malicious webpage and theft of the user\u2019s cookie.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-292-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-292-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-292-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-trane-security-advisory-0","alert_type":398,"serial_number":"AV21-524","subject":null,"moderation_state":"published","external_url":null},{"nid":2768,"title":"Ubuntu security advisory","uuid":"ef263efa-d61d-49f3-b5a2-e7b87a905b15","banner":null,"lang":"en","date_modified":"2021-10-20","date_modified_ts":"2021-10-20T17:36:29Z","date_created":"2021-10-20T17:36:29Z","summary":null,"body":["<article data-history-node-id=\"2768\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-525<br \/>\nDate: 20 October 2021<\/strong><\/p>\n\n<p>On 19 October 2021 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or allow execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5113-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5113-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5113-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices  \">https:\/\/ubuntu.com\/security\/notices \u00a0<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-27","alert_type":396,"serial_number":"AV21-525","subject":null,"moderation_state":"published","external_url":null},{"nid":2769,"title":"Cisco security advisory","uuid":"3f2944e1-1d7d-457f-8651-4ca3e6147ae4","banner":null,"lang":"en","date_modified":"2021-10-20","date_modified_ts":"2021-10-20T19:40:35Z","date_created":"2021-10-20T19:40:35Z","summary":null,"body":["<article data-history-node-id=\"2769\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-94\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-526<br \/>\nDate: 20 October 2021<\/strong><\/p>\n\n<p>On 20 October 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Universal IOS XE SD-WAN Software \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability\u00a0could allow an actor to execute arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Cisco IOS Security Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sd-wan-rhpbE34A\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sd-wan-rhpbE34A<\/a><\/p>\n\n<p>Cisco Security Advisories<br \/>\n\u00a0<a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-94","alert_type":396,"serial_number":"AV21-526","subject":null,"moderation_state":"published","external_url":null},{"nid":2770,"title":"Oracle security advisory \u2013 October 2021 Quarterly Rollup","uuid":"1713be19-3dcc-4a3f-a746-5df77a41eded","banner":null,"lang":"en","date_modified":"2021-10-21","date_modified_ts":"2021-10-21T12:46:20Z","date_created":"2021-10-21T12:46:20Z","summary":null,"body":["<article data-history-node-id=\"2770\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-october-2021-quarterly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-527<br \/>\nDate: 21 October 2021<\/strong><\/p>\n\n<p>On 19 October 2021 Oracle published a Critical Patch Update Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Essbase Administration Services - version 11.1.2.4.046 and prior<\/li>\n\t<li>Oracle Communications Pricing Design Center - version 12.0.0.3.0<\/li>\n\t<li>Oracle Communications Policy Management - version 12.5.0<\/li>\n\t<li>Oracle Communications Diameter Signaling Router - versions 8.0.0.0 to 8.5.0.0<\/li>\n\t<li>Oracle Communications EAGLE LNP Application Processor - versions 46.7, 46.8 and 46.9<\/li>\n\t<li>Oracle Communications Element Manager - versions 8.2.0.0 to 8.2.4.0<\/li>\n\t<li>Oracle Communications LSMS - versions 13.1, 13.2, 13.3 and 13.4<\/li>\n\t<li>Oracle Communications Session Report Manager - versions 8.0.0.0 to 8.2.2.0<\/li>\n\t<li>Oracle Communications Session Route Manager - versions 8.0.0.0 to 8.2.2.0<\/li>\n\t<li>Tekelec Virtual Operating Environment - versions 3.4.0 to 3.7.1<\/li>\n\t<li>Oracle Communications Control Plane Monitor - versions 3.4, 4.2, 4.3 and 4.4<\/li>\n\t<li>Oracle Communications Fraud Monitor - versions 3.4 to 4.4<\/li>\n\t<li>Oracle Communications Operations Monitor - versions 3.4, 4.2, 4.3 and 4.4<\/li>\n\t<li>Oracle Enterprise Telephony Fraud Monitor - versions 3.4, 4.2, 4.3 and 4.4<\/li>\n\t<li>Instantis EnterpriseTrack - versions 17.1, 17.2 and 17.3<\/li>\n\t<li>Enterprise Manager Ops Center - version 12.4.0.0<\/li>\n\t<li>Oracle Banking Virtual Account Management - versions 14.2, 14.3 and 14.5<\/li>\n\t<li>Oracle Banking Corporate Lending Process Management - versions 14.2, 14.3 and 14.5<\/li>\n\t<li>Oracle Banking Credit Facilities Process Management - versions 14.2, 14.3 and 14.5<\/li>\n\t<li>Oracle Banking Supply Chain Finance - versions 14.2, 14.3 and 14.5<\/li>\n\t<li>Oracle FLEXCUBE Core Banking - versions 11.7, 11.8, 11.9 and 11.10<\/li>\n\t<li>Oracle WebCenter Sites - versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle WebLogic Server - versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n\t<li>Oracle Healthcare Data Repository - version 8.1.0<\/li>\n\t<li>Oracle Documaker - versions 12.6.0 to 12.6.4<\/li>\n\t<li>Oracle Insurance Policy Administration - versions 11.0.0 to 11.3.1<\/li>\n\t<li>MySQL Cluster - version 8.0.26 and prior<\/li>\n\t<li>MySQL Server - versions 5.7.35 and prior, 8.0.26 and prior<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools - versions 8.57, 8.58 and 8.59<\/li>\n\t<li>Oracle ZFS Storage Appliance Kit - version 8.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Oracle Critical Patch Update Advisory - October 2021<br \/><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuoct2021.html\">https:\/\/www.oracle.com\/security-alerts\/cpuoct2021.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-october-2021-quarterly-rollup","alert_type":396,"serial_number":"AV21-527","subject":null,"moderation_state":"published","external_url":null},{"nid":2771,"title":"Ubuntu security advisory","uuid":"99afbf36-76e7-4317-8a10-abca3e34834b","banner":null,"lang":"en","date_modified":"2021-10-21","date_modified_ts":"2021-10-21T19:49:33Z","date_created":"2021-10-21T19:48:51Z","summary":null,"body":["<article data-history-node-id=\"2771\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-528<br \/>\nDate: 21 October 2021<\/strong><\/p>\n\n<p>On 20 October 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li><a name=\"_Hlk85711223\" id=\"_Hlk85711223\">Ubuntu 14.04 ESM <\/a><\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service, allow privilege escalation or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a name=\"_Hlk85711510\" id=\"_Hlk85711510\">Ubuntu Security Notice (USN-5117-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5117-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5117-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5116-1)<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5116-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5116-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5115-1)<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5115-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5115-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5114-1)<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5114-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5114-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a>\u00a0<br \/><br \/><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-28","alert_type":396,"serial_number":"AV21-528","subject":null,"moderation_state":"published","external_url":null},{"nid":2772,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"5eff6cc0-fcb4-497d-afd7-8870afd3dfb0","banner":null,"lang":"en","date_modified":"2021-10-21","date_modified_ts":"2021-10-21T21:58:00Z","date_created":"2021-10-21T21:57:47Z","summary":null,"body":["<article data-history-node-id=\"2772\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-25\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-529<br \/>\nDate: 21 October 2021<\/strong><\/p>\n\n<p>On 21 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ICONICS GENESIS64 - version 10.97 and prior<\/li>\n\t<li>Mitsubishi Electric MC Works64 - version 4.04E and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-294-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-294-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-294-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-25","alert_type":398,"serial_number":"AV21-529","subject":null,"moderation_state":"published","external_url":null},{"nid":2773,"title":"[Control systems] B. Braun Melsungen AG security advisory","uuid":"7aedc7e0-9558-4b1b-8e9f-a904c892df4b","banner":null,"lang":"en","date_modified":"2021-10-22","date_modified_ts":"2021-10-22T13:59:41Z","date_created":"2021-10-22T13:59:41Z","summary":null,"body":["<article data-history-node-id=\"2773\" about=\"\/en\/alerts-advisories\/control-systems-b-braun-melsungen-ag-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-530<br \/>\nDate: 22 October 2021<\/strong><\/p>\n\n<p>On 21 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Battery pack SP with WiFi - versions 028U000061 and prior<\/li>\n\t<li>SpaceStation with SpaceCom 2 - versions 012U000061 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure, privilege escalation, upload of arbitrary files and execution of arbitrary commands .<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-294-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-294-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-294-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-b-braun-melsungen-ag-security-advisory","alert_type":398,"serial_number":"AV21-530","subject":null,"moderation_state":"published","external_url":null},{"nid":2774,"title":"[Control systems] Delta Electronics security advisory","uuid":"be27a418-7e42-4d11-b8f2-ce229a5141ef","banner":null,"lang":"en","date_modified":"2021-10-22","date_modified_ts":"2021-10-22T15:09:16Z","date_created":"2021-10-22T15:09:16Z","summary":null,"body":["<article data-history-node-id=\"2774\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-531<br \/>\nDate: 22 October 2021<\/strong><\/p>\n\n<p>On 21 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DIALink - version 1.2.4.0 and prior \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure, directory traversal, privilege elevation, upload of arbitrary files and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSA-21-294-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-294-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-294-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-12","alert_type":398,"serial_number":"AV21-531","subject":null,"moderation_state":"published","external_url":null},{"nid":2775,"title":"GPS Daemon security advisory","uuid":"a7608364-267b-4c6d-a8d1-c619fb4b2603","banner":null,"lang":"en","date_modified":"2021-10-22","date_modified_ts":"2021-10-22T16:16:45Z","date_created":"2021-10-22T16:16:45Z","summary":null,"body":["<article data-history-node-id=\"2775\" about=\"\/en\/alerts-advisories\/gps-daemon-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-532<br \/>\nDate: 22 October 2021<\/strong><\/p>\n\n<p>On 21 October 2021 US-CERT published an Advisory to highlight a bug in the following product:<\/p>\n\n<ul><li>GPS Daemon (GPSD) \u2013 versions 3.20 to 3.22<\/li>\n<\/ul><p>On 24 October 2021, Network Time Protocol (NTP) servers using the affected versions of this product may reset to March 2002, potentially affecting the availability of systems and services that rely on NTP.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>GPS Daemon<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/10\/21\/gps-daemon-gpsd-rollover-bug\">https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/10\/21\/gps-daemon-gpsd-rollover-bug<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gps-daemon-security-advisory","alert_type":396,"serial_number":"AV21-532","subject":null,"moderation_state":"published","external_url":null},{"nid":2776,"title":" Ubuntu security advisory","uuid":"8097c6dc-9874-448e-9a99-00d0bdb2a025","banner":null,"lang":"en","date_modified":"2021-10-22","date_modified_ts":"2021-10-22T17:46:14Z","date_created":"2021-10-22T17:46:14Z","summary":null,"body":["<article data-history-node-id=\"2776\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-533<br \/>\nDate: 22 October 2021<\/strong><\/p>\n\n<p>On 21 and 22 October 2021 Ubuntu released Security Notices to address vulnerabilities in multiple products. Included were Linux kernel updates to the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service, allow privilege escalation or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5116-2)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5116-2\">https:\/\/ubuntu.com\/security\/notices\/USN-5116-2<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5120-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5120-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5120-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a> \u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-29","alert_type":396,"serial_number":"AV21-533","subject":null,"moderation_state":"published","external_url":null},{"nid":2777,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"53cd191d-ff30-4e5d-9568-d710e5685f05","banner":null,"lang":"en","date_modified":"2021-10-25","date_modified_ts":"2021-10-25T15:08:18Z","date_created":"2021-10-25T15:08:18Z","summary":null,"body":["<article data-history-node-id=\"2777\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-534<br \/>\nDate: 25 October 2021<\/strong><\/p>\n\n<p>On 21 October 2021 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 95.0.1020.30<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-21-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-21-2021<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-5","alert_type":396,"serial_number":"AV21-534","subject":null,"moderation_state":"published","external_url":null},{"nid":2778,"title":"IBM security advisory","uuid":"9048162e-6fbd-4ae0-abcb-a4ca77d2754f","banner":null,"lang":"en","date_modified":"2021-10-25","date_modified_ts":"2021-10-25T15:12:15Z","date_created":"2021-10-25T15:12:15Z","summary":null,"body":["<article data-history-node-id=\"2778\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-70\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-535<br \/>\nDate: 25 October 2021<\/strong><\/p>\n\n<p>Between 18 and 24 October 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Watson Explorer Deep Analytics Edition Foundational Components \u2013 multiple versions<\/li>\n\t<li>Watson Explorer Foundational Components \u2013 multiple versions<\/li>\n\t<li>QRadar Advisor - versions 2.5 to 2.6.1<\/li>\n\t<li>IBM Cloud Pak System - multiple versions<\/li>\n\t<li>Cloud Pak for Security (CP4S) - versions 1.7.0.0, 1.7.1.0 and 1.7.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Watson Explorer Deep Analytics Edition Foundational Components<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-affect-watson-explorer-foundational-components-cve-2021-3712-cve-2021-3711\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-affect-watson-explorer-foundational-components-cve-2021-3712-cve-2021-3711\/<\/a><\/p>\n\n<p>Watson Explorer Foundational Components<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-affect-watson-explorer-foundational-components-cve-2021-3712-cve-2021-3711\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-affect-watson-explorer-foundational-components-cve-2021-3712-cve-2021-3711\/<\/a><\/p>\n\n<p>QRadar Advisor<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-qradar-advisor-with-watson-uses-components-with-known-vulnerabilities-cve-2020-36242-cve-2021-33503-cve-2020-28493\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-qradar-advisor-with-watson-uses-components-with-known-vulnerabilities-cve-2020-36242-cve-2021-33503-cve-2020-28493\/<\/a><\/p>\n\n<p>IBM Cloud Pak System<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-vmware-vcenter-affect-ibm-cloud-pak-system\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-vmware-vcenter-affect-ibm-cloud-pak-system\/<\/a><\/p>\n\n<p>Cloud Pak for Security (CP4S)<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cloud-pak-for-security-uses-packages-that-are-vulnerable-to-several-cves\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-cloud-pak-for-security-uses-packages-that-are-vulnerable-to-several-cves\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-70","alert_type":396,"serial_number":"AV21-535","subject":null,"moderation_state":"published","external_url":null},{"nid":2779,"title":"Apple security advisory","uuid":"ca7a067b-f962-4143-855e-5139ae82f6bf","banner":null,"lang":"en","date_modified":"2021-10-26","date_modified_ts":"2021-10-26T18:07:54Z","date_created":"2021-10-26T18:07:54Z","summary":null,"body":["<article data-history-node-id=\"2779\" about=\"\/en\/alerts-advisories\/apple-security-advisory-44\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-536<br \/>\nDate: 26 October 2021<\/strong><\/p>\n\n<p>On 25 October 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Monterey \u2013 versions prior to 12.0.1<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.6.1<\/li>\n\t<li>macOS Catalina \u2013 versions prior to Security Update 2021-007<\/li>\n\t<li>watchOS \u2013 versions prior to 8.1<\/li>\n\t<li>iOS \u2013 versions prior to 15.1<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.1<\/li>\n\t<li>tvOS \u2013 versions prior to 15.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-44","alert_type":396,"serial_number":"AV21-536","subject":null,"moderation_state":"published","external_url":null},{"nid":2780,"title":"[Control systems] ABB security advisory","uuid":"de158781-5a00-4fc3-a3a3-526c9c8ba54a","banner":null,"lang":"en","date_modified":"2021-10-26","date_modified_ts":"2021-10-26T18:17:50Z","date_created":"2021-10-26T18:17:50Z","summary":null,"body":["<article data-history-node-id=\"2780\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-537<br \/>\nDate: 26 October 2021<\/strong><\/p>\n\n<p>On 19 October 2021 ABB published a Cyber Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>PCM600 Update Manager \u2013 versions prior to 2.4.21218.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ABB Cyber Security Advisory (2NGA001142)<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001142&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001142&amp;Action=Launch<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-18","alert_type":398,"serial_number":"AV21-537","subject":null,"moderation_state":"published","external_url":null},{"nid":2781,"title":"[Control systems] Fuji Electric security advisory","uuid":"4f993993-ce08-4155-b677-633f5919f8d0","banner":null,"lang":"en","date_modified":"2021-10-26","date_modified_ts":"2021-10-26T19:19:09Z","date_created":"2021-10-26T19:19:09Z","summary":null,"body":["<article data-history-node-id=\"2781\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-538<br \/>\nDate: 26 October 2021<\/strong><\/p>\n\n<p>On 26 October 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>V-Server Lite - versions prior to v4.0.12.0<\/li>\n\t<li>Tellus Lite V-Simulator - versions prior to v4.0.12.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure, denial-of-service and code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-299-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-299-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-299-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-4","alert_type":398,"serial_number":"AV21-538","subject":null,"moderation_state":"published","external_url":null},{"nid":2782,"title":"Adobe security advisory","uuid":"3c0094d1-7de7-4760-ab8b-17bfceb90ac7","banner":null,"lang":"en","date_modified":"2021-10-26","date_modified_ts":"2021-10-26T19:53:30Z","date_created":"2021-10-26T19:53:30Z","summary":null,"body":["<article data-history-node-id=\"2782\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-48\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-539<br \/>\nDate: 26 October 2021<\/strong><\/p>\n\n<p>On 26 October 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe Bridge \u2013 version 11.1.1 and prior<\/li>\n\t<li>Adobe Audition \u2013 version 14.4 and prior<\/li>\n\t<li>Adobe After Effects \u2013 version 18.4.1 and prior<\/li>\n\t<li>Adobe Lightroom Classic \u2013 version 10.3 and prior<\/li>\n\t<li>Adobe Prelude \u2013 version 10.1 and prior<\/li>\n\t<li>Adobe Character Animator \u2013 version 4.4 and prior<\/li>\n\t<li>Adobe Premiere Pro \u2013 version 15.4.1 and prior<\/li>\n\t<li>Adobe Media Encoder \u2013 version 15.4.1 and prior<\/li>\n\t<li>Adobe Illustrator \u2013 version 25.4.1 and prior<\/li>\n\t<li>Adobe InDesign \u2013 version 16.4 and prior<\/li>\n\t<li>Adobe Premiere Elements \u2013 version 2021 [build 19.0 (20210809.daily.2242976) and earlier] and prior<\/li>\n\t<li>Adobe Animate \u2013 version 21.0.9 and prior<\/li>\n\t<li>Adobe Photoshop 2021 \u2013 version 22.5.1 and prior<\/li>\n\t<li>Adobe XMP-Toolkit-SDK \u2013 version 2021.07 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-48","alert_type":396,"serial_number":"AV21-539","subject":null,"moderation_state":"published","external_url":null},{"nid":2783,"title":"Cisco security advisory","uuid":"4eaa8a37-3bfb-44e9-8dfe-e72deacd382b","banner":null,"lang":"en","date_modified":"2021-10-27","date_modified_ts":"2021-10-27T19:24:49Z","date_created":"2021-10-27T19:20:17Z","summary":null,"body":["<article data-history-node-id=\"2783\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-95\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-540<br \/>\nDate: 27 October 2021<\/strong><\/p>\n\n<p>On 27 October 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco FTD Software \u2013 multiple versions<\/li>\n\t<li>Open Source Snort \u2013 versions prior to 3.1.0.100<\/li>\n\t<li>Cisco ASA Software \u2013 multiple versions<\/li>\n\t<li>Cisco FMC Software \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in denial-of-service and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<\/p>\n\n<p><a href=\" https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">\u00a0https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-95","alert_type":396,"serial_number":"AV21-540","subject":null,"moderation_state":"published","external_url":null},{"nid":2784,"title":"Apple security advisory","uuid":"b0988c49-4317-41df-95a4-7dc240d99a06","banner":null,"lang":"en","date_modified":"2021-10-28","date_modified_ts":"2021-10-28T17:55:43Z","date_created":"2021-10-28T17:55:43Z","summary":null,"body":["<article data-history-node-id=\"2784\" about=\"\/en\/alerts-advisories\/apple-security-advisory-45\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-541<br \/>\nDate: 28 October 2021<\/strong><\/p>\n\n<p>On 27 October 2021 Apple published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari \u2013 versions prior to 15.1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in information disclosure and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Apple Security Update (Safari)<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212875\">https:\/\/support.apple.com\/en-ca\/HT212875<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-45","alert_type":396,"serial_number":"AV21-541","subject":null,"moderation_state":"published","external_url":null},{"nid":2785,"title":"[Control systems] Sensormatic Electronics security advisory","uuid":"58bf2890-27f5-4ca0-a5c5-f1aaa2e452e8","banner":null,"lang":"en","date_modified":"2021-10-29","date_modified_ts":"2021-10-29T12:12:16Z","date_created":"2021-10-29T12:00:25Z","summary":null,"body":["<article data-history-node-id=\"2785\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-542<br \/>\nDate: 29 October 2021<\/strong><\/p>\n\n<p>On 28 October 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0victor - version 5.7 and prior<br \/>\n\u00a0<br \/>\nExploitation of this vulnerability could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-301-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-301-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-301-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-1","alert_type":398,"serial_number":"AV21-542","subject":null,"moderation_state":"published","external_url":null},{"nid":2786,"title":"Google Chrome security advisory","uuid":"8c36d47b-acf7-42b0-813a-09e7cf6e7008","banner":null,"lang":"en","date_modified":"2021-10-29","date_modified_ts":"2021-10-29T17:41:31Z","date_created":"2021-10-29T17:41:31Z","summary":null,"body":["<article data-history-node-id=\"2786\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-71\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-543<br \/>\nDate: 29 October 2021<\/strong><\/p>\n\n<p>On 28 October 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 95.0.4638.69<\/li>\n<\/ul><p>Google is aware that exploits for CVE-2021-38000 and CVE-2021-38003 exist in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/10\/stable-channel-update-for-desktop_28.html\">https:\/\/chromereleases.googleblog.com\/2021\/10\/stable-channel-update-for-desktop_28.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-71","alert_type":396,"serial_number":"AV21-543","subject":null,"moderation_state":"published","external_url":null},{"nid":2787,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"fbbc7a96-e4e8-4465-96d1-f45283497af9","banner":null,"lang":"en","date_modified":"2021-10-29","date_modified_ts":"2021-10-29T17:44:22Z","date_created":"2021-10-29T17:44:22Z","summary":null,"body":["<article data-history-node-id=\"2787\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-544<br \/>\nDate: 29 October 2021<\/strong><\/p>\n\n<p>On 29 October 2021 B&amp;R Industrial Automation published a Cyber Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Automation Studio 4 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>B&amp;R Industrial Automation Cyber Security Advisory (#12\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1634138454867-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1634138454867-en-original-1.0.pdf<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-6","alert_type":398,"serial_number":"AV21-544","subject":null,"moderation_state":"published","external_url":null},{"nid":2788,"title":"HPE security advisory","uuid":"879697ee-c5f2-47e0-b503-f5ffa413b23d","banner":null,"lang":"en","date_modified":"2021-10-29","date_modified_ts":"2021-10-29T17:46:55Z","date_created":"2021-10-29T17:46:55Z","summary":null,"body":["<article data-history-node-id=\"2788\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-545<br \/>\nDate: 29 October 2021<\/strong><\/p>\n\n<p>On 29 October 2021 HPE published a Security Bulletin to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>iLO Amplifier Pack - versions 1.80, 1.81, 1.90 and 1.95<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>HP Security Bulletin (HPESBGN04189)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04189en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04189en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-29","alert_type":396,"serial_number":"AV21-545","subject":null,"moderation_state":"published","external_url":null},{"nid":2789,"title":"IBM security advisory","uuid":"242105ec-6d73-4b86-899f-6161dcc691f5","banner":null,"lang":"en","date_modified":"2021-11-01","date_modified_ts":"2021-11-01T14:05:38Z","date_created":"2021-11-01T14:05:38Z","summary":null,"body":["<article data-history-node-id=\"2789\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-71\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-546<br \/>\nDate: 1 November 2021<\/strong><\/p>\n\n<p>Between 25 and 31 October 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Rational Application Developer for WebSphere Software \u2013 versions 9.6 and 9.7<\/li>\n\t<li>Spectrum Discover \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Rational Application Developer for WebSphere Software<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affect-ibm-rational-application-developer-for-websphere-software-september-2021-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affect-ibm-rational-application-developer-for-websphere-software-september-2021-2\/<\/a><\/p>\n\n<p>IBM Spectrum Discover<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-the-python-python-cryptography-and-urllib3-affect-ibm-spectrum-discover-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-the-python-python-cryptography-and-urllib3-affect-ibm-spectrum-discover-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-71","alert_type":396,"serial_number":"AV21-546","subject":null,"moderation_state":"published","external_url":null},{"nid":2790,"title":"Microsoft Edge (Chromium-based) security advisory","uuid":"3db278d0-af89-41f9-a4b3-c95108868ca6","banner":null,"lang":"en","date_modified":"2021-11-01","date_modified_ts":"2021-11-01T18:48:17Z","date_created":"2021-11-01T18:39:03Z","summary":null,"body":["<article data-history-node-id=\"2790\" about=\"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-547<br \/>\nDate: 1 November 2021<\/strong><\/p>\n\n<p>On 29 October 2021 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based) \u2013 versions prior to 95.0.1020.40<\/li>\n<\/ul><p>Microsoft is aware that exploits for CVE-2021-38000 and CVE-2021-38003 exist in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-29-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-29-2021<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-chromium-based-security-advisory-6","alert_type":396,"serial_number":"AV21-547","subject":null,"moderation_state":"published","external_url":null},{"nid":2791,"title":"Dell security advisory","uuid":"dacd28db-fabf-44f4-ab1a-a62bc9932a5d","banner":null,"lang":"en","date_modified":"2021-11-01","date_modified_ts":"2021-11-01T19:59:14Z","date_created":"2021-11-01T19:59:14Z","summary":null,"body":["<article data-history-node-id=\"2791\" about=\"\/en\/alerts-advisories\/dell-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-548<br \/>\nDate: 1 November 2021<\/strong><\/p>\n\n<p>\u00a0<\/p>\n\n<p>On 1 November 2021 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SmartFabric OS10 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>\u00a0<\/p>\n\n<p>Dell EMC SmartFabric (DSA-2021-189)<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193076\/dsa-2021-189-dell-emc-smartfabric-os10-security-update-for-a-multiple-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193076\/dsa-2021-189-dell-emc-smartfabric-os10-security-update-for-a-multiple-component-vulnerabilities<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-13","alert_type":396,"serial_number":"AV21-548","subject":null,"moderation_state":"published","external_url":null},{"nid":2792,"title":"Android security advisory \u2013 November 2021 monthly rollup","uuid":"2a2f2df4-354b-482f-9f1b-3f36dd7735ea","banner":null,"lang":"en","date_modified":"2021-11-02","date_modified_ts":"2021-11-02T12:26:17Z","date_created":"2021-11-02T12:26:17Z","summary":null,"body":["<article data-history-node-id=\"2792\" about=\"\/en\/alerts-advisories\/android-security-advisory-november-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-549<br \/>\nDate: 2 November <a name=\"_Hlk60663528\" id=\"_Hlk60663528\">2021<\/a><\/strong><\/p>\n\n<p>On 1 November 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>Android is aware of indications that CVE-2021-1048 may be under limited, targeted exploitation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-11-01\">https:\/\/source.android.com\/security\/bulletin\/2021-11-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-november-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-549","subject":null,"moderation_state":"published","external_url":null},{"nid":2793,"title":"Mozilla security advisory","uuid":"64ec7133-a20d-462b-9f71-2ba6f5468734","banner":null,"lang":"en","date_modified":"2021-11-02","date_modified_ts":"2021-11-02T14:28:36Z","date_created":"2021-11-02T14:28:36Z","summary":null,"body":["<article data-history-node-id=\"2793\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-47\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-560<br \/>\nDate: 2 November 2021<\/strong><\/p>\n\n<p>On 2 November 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 94<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-48)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-48\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-48\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-49)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-49\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-49\/<\/a><\/p>\n\n<p><strong>Note to Reader<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-47","alert_type":396,"serial_number":"AV21-560","subject":null,"moderation_state":"published","external_url":null},{"nid":2794,"title":"[Control systems] Sensormatic Electronics security advisory","uuid":"9aa8c594-85e3-4031-8c9e-cdee37c06a03","banner":null,"lang":"en","date_modified":"2021-11-02","date_modified_ts":"2021-11-02T18:06:18Z","date_created":"2021-11-02T18:06:18Z","summary":null,"body":["<article data-history-node-id=\"2794\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-561<br \/>\nDate: 2 November 2021<\/strong><\/p>\n\n<p>On 2 November 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>VideoEdge \u2013 versions prior to v5.7.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-306-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-306-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-306-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-2","alert_type":398,"serial_number":"AV21-561","subject":null,"moderation_state":"published","external_url":null},{"nid":2795,"title":"Fortinet security advisory","uuid":"87fbbe9f-6572-4079-b7e0-dc4367b5e919","banner":null,"lang":"en","date_modified":"2021-11-03","date_modified_ts":"2021-11-03T16:22:58Z","date_created":"2021-11-03T16:22:58Z","summary":null,"body":["<article data-history-node-id=\"2795\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-562<br \/>\nDate: 3 November 2021<\/strong><\/p>\n\n<p>On 2 November 2021 Fortinet published PSIRT Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Fortinet PSIRT Advisories<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-15","alert_type":396,"serial_number":"AV21-562","subject":null,"moderation_state":"published","external_url":null},{"nid":2796,"title":"Mozilla security advisory","uuid":"972af908-391e-42dc-a5ed-3f4786d47b26","banner":null,"lang":"en","date_modified":"2021-11-03","date_modified_ts":"2021-11-03T16:27:28Z","date_created":"2021-11-03T16:27:28Z","summary":null,"body":["<article data-history-node-id=\"2796\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-48\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-563<br \/>\nDate: 3 November 2021<\/strong><\/p>\n\n<p>On 3 November 2021 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 91.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Thunderbird (MFSA 2021-50)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-50\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-50\/<\/a><\/p>\n\n<p><strong>Note to Reader<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-48","alert_type":396,"serial_number":"AV21-563","subject":null,"moderation_state":"published","external_url":null},{"nid":2797,"title":"Cisco security advisory","uuid":"728d396a-52a1-422d-a1e5-02773d1295b9","banner":null,"lang":"en","date_modified":"2021-11-04","date_modified_ts":"2021-11-04T16:13:38Z","date_created":"2021-11-04T16:13:38Z","summary":null,"body":["<article data-history-node-id=\"2797\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-96\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-564<br \/>\nDate: 4 November 2021<\/strong><\/p>\n\n<p>On 3 November 2021 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco PON Switch \u2013 multiple versions<\/li>\n\t<li>Cisco Policy Suite \u2013 versions 21.1.0, 20.2.0, and versions prior to 20.2.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an unauthenticated remote actor to log in with default credentials or as the root user, perform command injection, or modify configurations.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Cisco Security Advisories<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">https:\/\/tools.cisco.com\/security\/center\/publicationListing.x<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-96","alert_type":396,"serial_number":"AV21-564","subject":null,"moderation_state":"published","external_url":null},{"nid":2798,"title":"[Control systems] Philips security advisory","uuid":"76d9ead6-1aab-4af1-af83-bda8a9024262","banner":null,"lang":"en","date_modified":"2021-11-04","date_modified_ts":"2021-11-04T19:11:55Z","date_created":"2021-11-04T18:41:42Z","summary":null,"body":["<article data-history-node-id=\"2798\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-565<br \/>\nDate: 4 November 2021<\/strong><\/p>\n\n<p>On 4 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Tasy EMR HTML5 \u2013 version 3.06.1803 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service and unauthorized access.<\/p>\n\n<p>CISA is aware that exploits for these vulnerabilities exist in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-308-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-308-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-308-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-12","alert_type":398,"serial_number":"AV21-565","subject":null,"moderation_state":"published","external_url":null},{"nid":2799,"title":"[Control systems] AzeoTech security advisory","uuid":"bc82db7d-0b01-451d-9b99-1c6b59290d5a","banner":null,"lang":"en","date_modified":"2021-11-05","date_modified_ts":"2021-11-05T15:09:41Z","date_created":"2021-11-05T15:09:41Z","summary":null,"body":["<article data-history-node-id=\"2799\" about=\"\/en\/alerts-advisories\/control-systems-azeotech-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-566<br \/>\nDate: 5 November 2021<\/strong><\/p>\n\n<p>On 4 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DAQFactory \u2013 version 18.1 Build 2347 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in code execution, memory corruption or unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-308-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-308-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-308-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-azeotech-security-advisory","alert_type":398,"serial_number":"AV21-566","subject":null,"moderation_state":"published","external_url":null},{"nid":2800,"title":"[Control systems] VISAM security advisory","uuid":"49d23676-f6df-47cf-a561-dcf677457c90","banner":null,"lang":"en","date_modified":"2021-11-05","date_modified_ts":"2021-11-05T15:12:43Z","date_created":"2021-11-05T15:12:43Z","summary":null,"body":["<article data-history-node-id=\"2800\" about=\"\/en\/alerts-advisories\/control-systems-visam-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-567<br \/>\nDate: 5 November 2021<\/strong><\/p>\n\n<p>On 4 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>VBASE Pro-RT\/Server-RT (Web Remote) \u2013 version 11.6.0.6<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in malicious input, disclosure of local files, access to NTLM hashes, or access to sensitive files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-308-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-308-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-308-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-visam-security-advisory-0","alert_type":398,"serial_number":"AV21-567","subject":null,"moderation_state":"published","external_url":null},{"nid":2801,"title":"Dell security advisory","uuid":"a50cdabf-ad75-4988-ae80-d993eafc407a","banner":null,"lang":"en","date_modified":"2021-11-05","date_modified_ts":"2021-11-05T18:47:26Z","date_created":"2021-11-05T18:11:58Z","summary":null,"body":["<article data-history-node-id=\"2801\" about=\"\/en\/alerts-advisories\/dell-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-568<br \/>\nDate: 5 November 2021<\/strong><\/p>\n\n<p>On 4 November 2021 Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>DLm8500 and DLm2500 \u2013 DLm Release 5.4.0.0 or prior with DLm Security 5.4.0.0 or prior<\/li>\n\t<li>Dell EMC VxRail Appliance - versions 7.0.x\u00a0 prior to 7.0.300<\/li>\n\t<li>PowerFlex Appliance \u2013 versions prior to Intelligent_Catalog_38_356_00_r10 and versions prior to Intelligent_Catalog_38_362_00_r7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Dell EMC Disk Library (DSA-2021-225)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193245\/dsa-2021-225-dell-emc-disk-library-for-mainframe-security-update-for-2021-1-intel-platform-update-ipu-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193245\/dsa-2021-225-dell-emc-disk-library-for-mainframe-security-update-for-2021-1-intel-platform-update-ipu-vulnerabilities<\/a><\/p>\n\n<p>Dell EMC VxRail (DSA-2021-231)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193205\/dsa-2021-231-dell-emc-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193205\/dsa-2021-231-dell-emc-vxrail-security-update-for-multiple-third-party-component-vulnerabilities<\/a><\/p>\n\n<p>Dell EMC PowerFlex (DSA-2021-241)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193276\/dsa-2021-241-dell-emc-powerflex-appliance-security-update-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193276\/dsa-2021-241-dell-emc-powerflex-appliance-security-update-for-multiple-third-party-component-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-14","alert_type":396,"serial_number":"AV21-568","subject":null,"moderation_state":"published","external_url":null},{"nid":2802,"title":"IBM security advisory","uuid":"e04ccbb7-1c74-4e57-b651-c9c468b2d848","banner":null,"lang":"en","date_modified":"2021-11-08","date_modified_ts":"2021-11-08T18:07:23Z","date_created":"2021-11-08T18:07:23Z","summary":null,"body":["<article data-history-node-id=\"2802\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-72\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-569<br \/>\nDate: 8 November 2021<\/strong><\/p>\n\n<p>Between 1 and 7 November 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM WIoTP MessageGateway\u00a0 \u2013 version 5.0.0.1<\/li>\n\t<li>IBM Security Guardium - versions 10.5, 10.6, 11.0, 11.1, 11.2 and 11.3<\/li>\n\t<li>IBM Security Verify Gateway for RADIUS \u2013 version 1.x<\/li>\n\t<li>IBM Security Verify Gateway for Windows Login \u2013 version 1.x<\/li>\n\t<li>IBM Security Verify Bridge for Directory Sync \u2013 version 1.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM WIoTP MessageGateway<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openssl-publicly-disclosed-vulnerability-affects-messagegateway-cve-2021-3711\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-openssl-publicly-disclosed-vulnerability-affects-messagegateway-cve-2021-3711\/<\/a><\/p>\n\n<p>IBM Security Guardium<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-jackson-databind-vulnerability-9\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-a-jackson-databind-vulnerability-9\/<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-9\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-9\/<\/a><\/p>\n\n<p>IBM Security Verify products<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletinmultiple-security-vulnerabilities-fixed-in-openssl-as-shipped-with-ibm-security-verify-products-cve-2021-3711-cve-2021-3712\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletinmultiple-security-vulnerabilities-fixed-in-openssl-as-shipped-with-ibm-security-verify-products-cve-2021-3711-cve-2021-3712\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-72","alert_type":396,"serial_number":"AV21-569","subject":null,"moderation_state":"published","external_url":null},{"nid":2803,"title":"Ubuntu security advisory","uuid":"1a750340-c9f3-43db-8c75-0a5776565fcb","banner":null,"lang":"en","date_modified":"2021-11-09","date_modified_ts":"2021-11-09T16:00:15Z","date_created":"2021-11-09T16:00:15Z","summary":null,"body":["<article data-history-node-id=\"2803\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-570<br \/>\nDate: 9 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5135-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5135-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5135-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5130-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5130-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5130-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5136-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5136-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5136-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5137-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5137-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5137-1<\/a><\/p>\n\n<p><a href=\"Ubuntu Security Notices https:\/\/ubuntu.com\/security\/notices  \">Ubuntu Security Notices<br \/>\nhttps:\/\/ubuntu.com\/security\/notices\u00a0 <\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-30","alert_type":396,"serial_number":"AV21-570","subject":null,"moderation_state":"published","external_url":null},{"nid":2804,"title":"Citrix security advisory","uuid":"986b68a7-a3d4-4b2a-ab24-1a20c9441ede","banner":null,"lang":"en","date_modified":"2021-11-09","date_modified_ts":"2021-11-09T17:25:22Z","date_created":"2021-11-09T17:25:22Z","summary":null,"body":["<article data-history-node-id=\"2804\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-571<br \/>\nDate: 9 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix ADC and Citrix Gateway 13.0 \u2013 versions prior to 13.0-83.27<\/li>\n\t<li>Citrix ADC and Citrix Gateway 12.1 \u2013 versions prior to 12.1-63.22<\/li>\n\t<li>Citrix ADC and NetScaler Gateway 11.1 \u2013 versions prior to 11.1-65.23<\/li>\n\t<li>Citrix ADC 12.1-FIPS \u2013 versions prior to 12.1-55.257<\/li>\n\t<li>Citrix SD-WAN WANOP Edition 11.4 \u2013 versions prior to 11.4.2<\/li>\n\t<li>Citrix SD-WAN WANOP Edition 10.2 \u2013 versions prior to 10.2.9c<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Citrix Security Bulletin (CTX330728)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX330728\">https:\/\/support.citrix.com\/article\/CTX330728<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-17","alert_type":396,"serial_number":"AV21-571","subject":null,"moderation_state":"published","external_url":null},{"nid":2873,"title":"SAP security advisory \u2013 November 2021 monthly rollup","uuid":"64c90263-b4d9-4362-93ef-f653177a4f2c","banner":null,"lang":"en","date_modified":"2021-12-16","date_modified_ts":"2021-12-16T21:31:14Z","date_created":"2021-11-09T19:45:06Z","summary":null,"body":["<article data-history-node-id=\"2873\" about=\"\/en\/alerts-advisories\/sap-security-advisory-november-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-572<br \/>\nDate: 9 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85 and 7.86<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<br \/>\n\u00a0<br \/>\nSAP Security Patch Day \u2013 November 2021<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=589496864\">https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=589496864<\/a><\/p>\n\n<p><strong>Note to Readers \u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-november-2021-monthly-rollup","alert_type":396,"serial_number":"AV1-572","subject":null,"moderation_state":"published","external_url":null},{"nid":2805,"title":"[Control systems] Siemens security advisory","uuid":"e9141e55-7c69-4890-9d6d-87a89b0fa58b","banner":null,"lang":"en","date_modified":"2021-11-09","date_modified_ts":"2021-11-09T20:24:17Z","date_created":"2021-11-09T20:24:17Z","summary":null,"body":["<article data-history-node-id=\"2805\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-36\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-573<br \/>\nDate: 9 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>APOGEE \u2013 multiple products, all versions<\/li>\n\t<li>Capital VSTAR \u2013 multiple versions<\/li>\n\t<li>Climatix POL909 (AWM module) \u2013 versions prior to V11.34<\/li>\n\t<li>Mendix Applications \u2013 multiple products and versions<\/li>\n\t<li>NucleusRTOS \u2013 multiple products and versions<\/li>\n\t<li>NX \u2013 multiple series and versions<\/li>\n\t<li>PSS(R) \u2013 multiple products and versions<\/li>\n\t<li>SCALANCE W1750D \u2013 version V8.7.1.3 and prior<\/li>\n\t<li>SENTRON powermanager V3 \u2013 all versions<\/li>\n\t<li>SICAM 230 \u2013 all versions<\/li>\n\t<li>SIMATIC \u2013 multiple products and versions<\/li>\n\t<li>SIMIT Simulation Platform \u2013 versions prior to V10.0<\/li>\n\t<li>Siveillance Video DLNA Server \u2013 version 2019 R1<\/li>\n\t<li>TALON \u2013 multiple products, all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, disclosure of sensitive information, remote code execution, modification of data in transit, privilege escalation and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Siemens Security Publications<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-36","alert_type":398,"serial_number":"AV21-573","subject":null,"moderation_state":"published","external_url":null},{"nid":2806,"title":"[Control systems] Schneider Electric security advisory","uuid":"36bff0e6-5359-44b6-9e95-acdf7bf3b2f6","banner":null,"lang":"en","date_modified":"2021-11-09","date_modified_ts":"2021-11-09T20:28:49Z","date_created":"2021-11-09T20:28:49Z","summary":null,"body":["<article data-history-node-id=\"2806\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-574<br \/>\nDate: 9 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 Schneider Electric published Security Notifications to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APC Power Distribution products \u2013 multiple products and versions<\/li>\n\t<li>Battery Management products \u2013 multiple products and versions<\/li>\n\t<li>Cooling products \u2013 multiple products and versions<\/li>\n\t<li>EcoStruxure Process Expert \u2013 versions prior to V2021<\/li>\n\t<li>Environmental Monitoring \u2013 multiple products and versions<\/li>\n\t<li>Eurotherm by Schneider Electric GUIcon \u2013 version 2.0 (Build 683.003) and prior<\/li>\n\t<li>Multiple products affected by memory allocation vulnerabilities commonly referred to as \u2018BadAlloc\u2019<\/li>\n\t<li>Network Management Card 2 (NMC2)<\/li>\n\t<li>Network Management Card 3 (NMC3)<\/li>\n\t<li>SCADAPack 312E, 313E, 314E, 330E, 333E, 334E, 337E, 350E and 357E RTUs \u2013 firmware versions V8.18.1 and prior<\/li>\n\t<li>Schneider Electric Software Update \u2013 versions V2.3.0 to V2.5.1<\/li>\n\t<li>TelevisAir V3.0 Dongle BTLE \u2013 part number ADBT42* and prior<\/li>\n\t<li>Uninterruptible Power Supply (UPS) products \u2013 multiple products and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unintended network access, execution of malicious web code, remote code execution, denial of service and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-27","alert_type":398,"serial_number":"AV21-574","subject":null,"moderation_state":"published","external_url":null},{"nid":2807,"title":"Intel security advisory","uuid":"cc51d8d4-aff7-4a53-842f-410af6e610d0","banner":null,"lang":"en","date_modified":"2021-11-09","date_modified_ts":"2021-11-09T20:59:09Z","date_created":"2021-11-09T20:59:09Z","summary":null,"body":["<article data-history-node-id=\"2807\" about=\"\/en\/alerts-advisories\/intel-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-575<br \/>\nDate: 9 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 Intel published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIOS Reference Code \u2013 multiple products<\/li>\n\t<li>Intel Core Processors with Radeon RX Vega M GL Graphics \u2013 versions prior to 21.10<\/li>\n\t<li>Intel Killer WiFi Software \u2013 multiple products, versions prior to v2.4.1541<\/li>\n\t<li>Intel PROSet\/Wireless WiFi \u2013 multiple products, versions prior to 22.40<\/li>\n\t<li>Intel SSD DC Firmware \u2013 multiple products and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>BIOS Reference Code (INTEL-SA-00562)<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00562.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00562.html<\/a><\/p>\n\n<p>Intel Core Processors with Radeon RX Vega M GL Graphics (INTEL-SA-00481)<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00481.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00481.html<\/a><\/p>\n\n<p>Intel PROSet\/Wireless WiFi and Killer WiFi Software (INTEL-SA-00509)<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00509.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00509.html<\/a><\/p>\n\n<p>Intel SSD DC Firmware (INTEL-SA-00535)<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00535.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00535.html<\/a><\/p>\n\n<p>Intel Product Security Center Advisories<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-20","alert_type":396,"serial_number":"AV21-575","subject":null,"moderation_state":"published","external_url":null},{"nid":2808,"title":"Microsoft security advisory \u2013 November 2021 monthly rollup","uuid":"a1111a45-8f7c-4fb3-92f8-8be58c084ea2","banner":null,"lang":"en","date_modified":"2021-11-10","date_modified_ts":"2021-11-10T12:44:40Z","date_created":"2021-11-10T12:44:40Z","summary":null,"body":["<article data-history-node-id=\"2808\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-november-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-576<br \/>\nDate: 10 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft Dynamics 365<\/li>\n\t<li>Microsoft Malware Protection Engine<\/li>\n\t<li>Microsoft Visual Studio 2017 and 2019<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 7, 8.1, RT 8.1, 10 and 11<\/li>\n\t<li>Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019 and 2022 \u00a0<\/li>\n\t<li>Windows Server Core 2012, 2012 R2, 2016, 2019, 2022, 20H2 and 2004<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.<\/p>\n\n<p>Of note, Microsoft has indicated that exploitation has been detected for the following vulnerabilities: CVE-2021-42321 and CVE-2021-42292.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>November 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Nov\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Nov<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n\n<p><strong>Note to Readers \u00a0<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-november-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-576","subject":null,"moderation_state":"published","external_url":null},{"nid":2809,"title":"[Control systems] mySCADA security advisory","uuid":"584479c1-b96a-4653-951b-861e3ef30bcf","banner":null,"lang":"en","date_modified":"2021-11-10","date_modified_ts":"2021-11-10T14:53:21Z","date_created":"2021-11-10T14:53:21Z","summary":null,"body":["<article data-history-node-id=\"2809\" about=\"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-577<br \/>\nDate: 10 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>myDESIGNER \u2013 version 8.20.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ICS Advisory (ICSA-21-313-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-313-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-313-04<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-0","alert_type":398,"serial_number":"AV21-577","subject":null,"moderation_state":"published","external_url":null},{"nid":2810,"title":"Adobe security advisory","uuid":"a6918dde-aee0-46a9-9f4e-e81389be9331","banner":null,"lang":"en","date_modified":"2021-11-10","date_modified_ts":"2021-11-10T15:02:16Z","date_created":"2021-11-10T14:59:15Z","summary":null,"body":["<article data-history-node-id=\"2810\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-49\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-578<br \/>\nDate: 10 November 2021<\/strong><\/p>\n\n<p>On 10 November 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe InCopy \u2013 version 16.4 and prior \u00a0<\/li>\n\t<li>RoboHelp Server \u2013 version RHS2020.0.1 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in denial of service or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Security Update Available for Adobe InCopy (APSB21-110)<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/incopy\/apsb21-110.html\">https:\/\/helpx.adobe.com\/security\/products\/incopy\/apsb21-110.html<\/a><\/p>\n\n<p>Security hotfix available for RoboHelp Server (APSB21-87)<br \/><a href=\"https:\/\/helpx.adobe.com\/security\/products\/robohelp-server\/apsb21-87.html\">https:\/\/helpx.adobe.com\/security\/products\/robohelp-server\/apsb21-87.html<\/a><\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-49","alert_type":396,"serial_number":"AV21-578","subject":null,"moderation_state":"published","external_url":null},{"nid":2811,"title":"[Control systems] Philips security advisory","uuid":"38be37ee-8c40-4197-a309-d623d89a4bb1","banner":null,"lang":"en","date_modified":"2021-11-10","date_modified_ts":"2021-11-10T19:19:39Z","date_created":"2021-11-10T19:19:39Z","summary":null,"body":["<article data-history-node-id=\"2811\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-579<br \/>\nDate: 10 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MRI 1.5T \u2013 version 5.x.x<\/li>\n\t<li>MRI 3T \u2013 version 5.x.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an unauthorized actor to execute software, modify system configuration, view\/update files, and export data (including patient data) to an untrusted environment.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p>ICS Advisory (ICSMA-21-313-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-313-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-313-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-13","alert_type":398,"serial_number":"AV21-579","subject":null,"moderation_state":"published","external_url":null},{"nid":2812,"title":"[Control systems] OSIsoft security advisory","uuid":"69e775ee-0394-4b96-972c-68ce55786b00","banner":null,"lang":"en","date_modified":"2021-11-10","date_modified_ts":"2021-11-10T19:23:19Z","date_created":"2021-11-10T19:23:19Z","summary":null,"body":["<article data-history-node-id=\"2812\" about=\"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-580<br \/>\nDate: 10 November 2021<\/strong><\/p>\n\n<p>On 9 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>PI Vision \u2013 versions prior to 2021<\/li>\n\t<li>PI Web API \u2013 version 2019 SPI and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote authenticated access to sensitive information, the delivery of false information, or to the disclosure, modification or deletion of information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-313-05)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-313-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-313-05<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-313-06)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-313-06\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-313-06<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-osisoft-security-advisory-2","alert_type":398,"serial_number":"AV21-580","subject":null,"moderation_state":"published","external_url":null},{"nid":2813,"title":"Palo Alto Networks security advisory","uuid":"9e7f9322-54df-4404-b71d-b38dbbc98571","banner":null,"lang":"en","date_modified":"2021-11-10","date_modified_ts":"2021-11-10T19:27:21Z","date_created":"2021-11-10T19:27:21Z","summary":null,"body":["<article data-history-node-id=\"2813\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-581<br \/>\nDate: 10 November 2021<\/strong><\/p>\n\n<p>On 10 November 2021 Palo Alto Networks published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>PAN-OS 8.1 \u2013 versions prior to 8.1.17<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthenticated network-based actor to disrupt system processes and potentially execute arbitrary code with root privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>PAN-OS (PAN-96528)<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-3064\">https:\/\/security.paloaltonetworks.com\/CVE-2021-3064<\/a><\/p>\n\n<p>Palo Alto Networks Security Advisories<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/\">https:\/\/security.paloaltonetworks.com\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-13","alert_type":396,"serial_number":"AV21-581","subject":null,"moderation_state":"published","external_url":null},{"nid":2814,"title":"Apple security advisory","uuid":"79b21eca-f1c5-4279-a11f-863ce29b1956","banner":null,"lang":"en","date_modified":"2021-11-12","date_modified_ts":"2021-11-12T14:43:11Z","date_created":"2021-11-12T14:43:11Z","summary":null,"body":["<article data-history-node-id=\"2814\" about=\"\/en\/alerts-advisories\/apple-security-advisory-46\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-582<br \/>\nDate: 12 November 2021<\/strong><\/p>\n\n<p>On 10 November 2021 Apple published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>iCloud for Windows \u2013 versions prior to 13<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary update.<\/p>\n\n<p>Apple Security Update (HT212953)<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212953\">https:\/\/support.apple.com\/en-ca\/HT212953<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-46","alert_type":396,"serial_number":"AV21-582","subject":null,"moderation_state":"published","external_url":null},{"nid":2815,"title":"Ubuntu security advisory","uuid":"92732818-e42d-4544-9c5d-b520abdeb628","banner":null,"lang":"en","date_modified":"2021-11-12","date_modified_ts":"2021-11-12T15:50:56Z","date_created":"2021-11-12T15:46:02Z","summary":null,"body":["<article data-history-node-id=\"2815\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-583<br \/>\nDate: 12 November 2021<\/strong><\/p>\n\n<p>On 11 November 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5137-2)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5137-2\">https:\/\/ubuntu.com\/security\/notices\/USN-5137-2<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5139-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5139-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5139-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5140-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5140-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5140-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (LSN-0082-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0082-1\">https:\/\/ubuntu.com\/security\/notices\/LSN-0082-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-31","alert_type":396,"serial_number":"AV21-583","subject":null,"moderation_state":"published","external_url":null},{"nid":2816,"title":"[Control systems] WECON security advisory","uuid":"3a4a58e7-40ac-4085-81c5-4c642c9e6b6d","banner":null,"lang":"en","date_modified":"2021-11-12","date_modified_ts":"2021-11-12T20:48:43Z","date_created":"2021-11-12T20:48:43Z","summary":null,"body":["<article data-history-node-id=\"2816\" about=\"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-584<br \/>\nDate: 12 November 2021<\/strong><\/p>\n\n<p>On 11 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>PLC Editor - version 1.3.8 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-315-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-315-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-315-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-2","alert_type":398,"serial_number":"AV21-584","subject":null,"moderation_state":"published","external_url":null},{"nid":2817,"title":"IBM security advisory","uuid":"a3ecfbb4-cc60-4a5f-a299-8bdb3585dc66","banner":null,"lang":"en","date_modified":"2021-11-15","date_modified_ts":"2021-11-15T16:07:10Z","date_created":"2021-11-15T16:07:10Z","summary":null,"body":["<article data-history-node-id=\"2817\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-73\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-585<br \/>\nDate: 15 November 2021<\/strong><\/p>\n\n<p>Between 8 and 14 November 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Object Storage Systems \u2013 versions 3.16.1.24 and prior<\/li>\n\t<li>IBM Safer Payments \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Cloud Object Storage Systems<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-object-storage-systems-nov-2021-v1\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-object-storage-systems-nov-2021-v1\/<\/a><\/p>\n\n<p>IBM Safer Payments<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-safer-payments-v5-7-to-v6-3-releases-are-affected-by-an-openssl-security-advisory-cve-2021-3711\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-safer-payments-v5-7-to-v6-3-releases-are-affected-by-an-openssl-security-advisory-cve-2021-3711\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-73","alert_type":396,"serial_number":"AV21-585","subject":null,"moderation_state":"published","external_url":null},{"nid":2818,"title":" [Control systems] Multiple Data Distribution Service Implementations security advisory","uuid":"8bdc75a5-cd3c-44ee-b0bb-8da453ee2080","banner":null,"lang":"en","date_modified":"2021-11-15","date_modified_ts":"2021-11-15T17:00:01Z","date_created":"2021-11-15T17:00:01Z","summary":null,"body":["<article data-history-node-id=\"2818\" about=\"\/en\/alerts-advisories\/control-systems-multiple-data-distribution-service-implementations-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-586<br \/>\nDate: 15 November 2021<\/strong><\/p>\n\n<p>On 11 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Eclipse CycloneDDS - versions prior to 0.8.0<\/li>\n\t<li>eProsima Fast DDS - versions prior to 2.4.0 (#2269)<\/li>\n\t<li>GurumNetworks GurumDDS - all versions<\/li>\n\t<li>Object Computing, Inc. (OCI) OpenDDS - versions prior to 3.18.1<\/li>\n\t<li>Real-Time Innovations (RTI) Connext DDS Professional and Connext DDS Secure - versions 4.2x to 6.1.0<\/li>\n\t<li>RTI Connext DDS Micro - version 3.0.0 and later<\/li>\n\t<li>TwinOaks Computing CoreDX DDS - versions prior to 5.9.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, denial-of-service or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates where available.<\/p>\n\n<p>ICS Advisory (ICSA-21-315-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-315-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-315-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-multiple-data-distribution-service-implementations-security-advisory","alert_type":398,"serial_number":"AV21-586","subject":null,"moderation_state":"published","external_url":null},{"nid":2819,"title":"Google Chrome security advisory","uuid":"baafbea0-801a-4586-9333-1829676918af","banner":null,"lang":"en","date_modified":"2021-11-15","date_modified_ts":"2021-11-15T19:44:47Z","date_created":"2021-11-15T19:44:47Z","summary":null,"body":["<article data-history-node-id=\"2819\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-72\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-587<br \/>\nDate: 15 November 2021<\/strong><\/p>\n\n<p>On 15 November 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 96.0.4664.45<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/11\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2021\/11\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-72","alert_type":396,"serial_number":"AV21-587","subject":null,"moderation_state":"published","external_url":null},{"nid":2820,"title":"[Control systems] FATEK Automation security advisory","uuid":"9bb3693c-3094-437f-a808-2a79527cf201","banner":null,"lang":"en","date_modified":"2021-11-16","date_modified_ts":"2021-11-16T20:33:28Z","date_created":"2021-11-16T20:33:28Z","summary":null,"body":["<article data-history-node-id=\"2820\" about=\"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-588<br \/>\nDate: 16 November 2021<\/strong><\/p>\n\n<p>On 16 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>WinProladder \u2013 version 3.30_24518 and prior \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-320-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-320-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-320-01<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-3","alert_type":398,"serial_number":"AV21-588","subject":null,"moderation_state":"published","external_url":null},{"nid":2821,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"1c14c5de-4f19-485c-bf78-9ad58306efe2","banner":null,"lang":"en","date_modified":"2021-11-17","date_modified_ts":"2021-11-17T17:35:07Z","date_created":"2021-11-17T17:35:07Z","summary":null,"body":["<article data-history-node-id=\"2821\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-26\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-589<br \/>\nDate: 17 November 2021<\/strong><\/p>\n\n<p>On 16 November 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>GOT2000 series \u2013 multiple models, all versions<\/li>\n\t<li>GOT SIMPLE series \u2013 GS21 model, all versions<\/li>\n\t<li>GT SoftGOT2000 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in system misconfiguration and the loss of information integrity.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-320-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-320-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-320-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-26","alert_type":398,"serial_number":"AV21-589","subject":null,"moderation_state":"published","external_url":null},{"nid":2822,"title":"Trend Micro security advisory","uuid":"dae87f3d-ccd3-4e52-a149-0aebb6ce3f15","banner":null,"lang":"en","date_modified":"2021-11-17","date_modified_ts":"2021-11-17T18:59:59Z","date_created":"2021-11-17T18:59:59Z","summary":null,"body":["<article data-history-node-id=\"2822\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-590<br \/>\nDate: 17 November 2021<\/strong><\/p>\n\n<p>On 16 November 2021 Trend Micro released a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Trend Micro Antivirus for MAC \u2013 version 2021 (v11)<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>Trend Micro Security Bulletin<br \/><a href=\"https:\/\/helpcenter.trendmicro.com\/en-us\/article\/tmka-10832\">https:\/\/helpcenter.trendmicro.com\/en-us\/article\/tmka-10832<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory","alert_type":396,"serial_number":"AV21-590","subject":null,"moderation_state":"published","external_url":null},{"nid":2823,"title":"[Control systems] Philips security advisory","uuid":"9aa23cc6-2ace-417a-8dee-1a8e6d2c23d6","banner":null,"lang":"en","date_modified":"2021-11-18","date_modified_ts":"2021-11-18T20:30:50Z","date_created":"2021-11-18T20:30:50Z","summary":null,"body":["<article data-history-node-id=\"2823\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-591<br \/>\nDate: 18 November 2021<\/strong><\/p>\n\n<p>On 18 November 2021 ICS-CERT published ICS Medical Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Efficia CM Series \u2013 revisions A.01 to C.0x and 4.0<\/li>\n\t<li>IntelliBridge EC 40 Hub \u2013 version C.00.04 and prior<\/li>\n\t<li>IntelliBridge EC 80 Hub \u2013 version C.00.04 and prior<\/li>\n\t<li>Patient Information Center iX (PIC iX) \u2013 versions B.02, C.02 and C.03<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access to data (including patient data), denial of service, or modifications to system configuration.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Medical Advisory (ICSMA-21-322-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-322-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-322-01<\/a><\/p>\n\n<p>ICS Medical Advisory (ICSMA-21-322-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-322-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-322-02<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-14","alert_type":398,"serial_number":"AV21-591","subject":null,"moderation_state":"published","external_url":null},{"nid":2824,"title":"Microsoft Azure security advisory","uuid":"56367015-c375-48d3-a5a9-206a7b738285","banner":null,"lang":"en","date_modified":"2021-11-19","date_modified_ts":"2021-11-19T20:58:39Z","date_created":"2021-11-19T20:57:27Z","summary":null,"body":["<article data-history-node-id=\"2824\" about=\"\/en\/alerts-advisories\/microsoft-azure-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-593<br \/>\nDate: 19 November 2021<\/strong><\/p>\n\n<p>On 17 November 2021 Microsoft published a Security Update to address a vulnerability in the following products:<\/p>\n\n<ul><li>Azure Automation<\/li>\n\t<li>Azure Migrate Appliances<\/li>\n\t<li>Azure Site Recovery<\/li>\n\t<li>Azure AD applications and Service Principals<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>Azure Active Directory Information Disclosure Vulnerability<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42306\">https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42306<\/a>\u00a0<\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-azure-security-advisory-0","alert_type":396,"serial_number":"AV21-593","subject":null,"moderation_state":"published","external_url":null},{"nid":2825,"title":"HPE security advisory","uuid":"66e48a7d-b59f-464b-83b1-657ac0d97343","banner":null,"lang":"en","date_modified":"2021-11-19","date_modified_ts":"2021-11-19T21:02:13Z","date_created":"2021-11-19T21:02:13Z","summary":null,"body":["<article data-history-node-id=\"2825\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-30\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-592<br \/>\nDate: 19 November 2021<\/strong><\/p>\n\n<p>On 17 November 2021 HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Emulex HBA Manager \u2013 versions prior to 12.8.542.26, in the following models:\n\t<ul><li>HPE 8Gb PCIe Host Bus Adapters \u2013 multiple models<\/li>\n\t\t<li>HPE SN1100E 16Gb Host Bus Adapter \u2013 multiple models<\/li>\n\t\t<li>HPE SN1200E 16Gb Fibre Channel Host Bus Adapter \u2013 multiple models<\/li>\n\t\t<li>HPE SN1600E 32Gb Fibre Channel Host Bus Adapter \u2013 multiple models<\/li>\n\t\t<li>HPE SN1610E 32Gb Fibre Channel Host Bus Adapter \u2013 multiple models<\/li>\n\t\t<li>HPE SN1700E 64Gb Fibre Channel Host Bus Adapter \u2013 multiple models<\/li>\n\t\t<li>HPE LPe1205A 8Gb Fibre Channel Host Bus Adapter for BladeSystem c-Class<\/li>\n\t\t<li>HPE LPe1605 16Gb Fibre Channel Host Bus Adapter for BladeSystem c-Class<\/li>\n\t\t<li>HPE Synergy 3530C 16Gb Fibre Channel Host Bus Adapter<\/li>\n\t\t<li>HPE Synergy 5330C 32Gb Fibre Channel Host Bus Adapter<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in remote file download, data modification, or buffer overflow.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>HP Security Bulletin (hpesbst04210en_us)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04210en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04210en_us<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-30","alert_type":396,"serial_number":"AV21-592","subject":null,"moderation_state":"published","external_url":null},{"nid":2826,"title":"IBM security advisory","uuid":"84489d46-8982-467a-9adc-bce1c82a4cc3","banner":null,"lang":"en","date_modified":"2021-11-22","date_modified_ts":"2021-11-22T17:08:47Z","date_created":"2021-11-22T17:08:47Z","summary":null,"body":["<article data-history-node-id=\"2826\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-74\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-594<br \/>\nDate: 22 November 2021<\/strong><\/p>\n\n<p>Between 15 and 21 November 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak System \u2013 version 2.3<\/li>\n\t<li>IBM InfoSphere Information Server \u2013 version 11.7<\/li>\n\t<li>IBM MQ for HPE NonStop \u2013 version 8.1.0<\/li>\n\t<li>WebSphere MQ V5.3 for HP NonStop Server (MIPS and Itanium) \u2013 version 5.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Cloud Pak System<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-ibm-sdk-java-affects-ibm-cloud-pak-system-cve-2020-27221\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-ibm-sdk-java-affects-ibm-cloud-pak-system-cve-2020-27221\/<\/a><\/p>\n\n<p>IBM InfoSphere Information Server<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-openssl-affects-ibm-infosphere-information-server-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-multiple-vulnerabilities-in-openssl-affects-ibm-infosphere-information-server-2\/<\/a><\/p>\n\n<p>IBM MQ for HPE NonStop<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-mq-for-hp-nonstop-server-is-affected-by-openssl-vulnerability-cve-2021-3711\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-mq-for-hp-nonstop-server-is-affected-by-openssl-vulnerability-cve-2021-3711\/<\/a><\/p>\n\n<p>WebSphere MQ V5.3 for HP NonStop Server (MIPS and Itanium)<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-websphere-mq-for-hp-nonstop-server-is-affected-by-openssl-vulnerability-cve-2021-3711\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-websphere-mq-for-hp-nonstop-server-is-affected-by-openssl-vulnerability-cve-2021-3711\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-74","alert_type":396,"serial_number":"AV21-594","subject":null,"moderation_state":"published","external_url":null},{"nid":2827,"title":"Dell security advisory","uuid":"ac1369b2-d525-4c01-a650-1a941465a2d8","banner":null,"lang":"en","date_modified":"2021-11-22","date_modified_ts":"2021-11-22T19:52:35Z","date_created":"2021-11-22T19:52:35Z","summary":null,"body":["<article data-history-node-id=\"2827\" about=\"\/en\/alerts-advisories\/dell-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-595<br \/>\nDate: 22 November 2021<\/strong><\/p>\n\n<p>On 19 and 22 November 2021 Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC Streaming Data Platform \u2013 versions prior to 1.3<\/li>\n\t<li>Dell EMC VNXe1600 \u2013 versions prior to 3.1.16.10.220572<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities may result in information disclosure, unauthorized data modification and impersonation of legitimate users.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Dell EMC Streaming Data Platform (DSA-2021-205)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193697\/dsa-2021-205-dell-emc-streaming-data-platform-security-update-for-third-party-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193697\/dsa-2021-205-dell-emc-streaming-data-platform-security-update-for-third-party-vulnerabilities<\/a><\/p>\n\n<p>Dell EMC VNXe1600 (DSA-2021-214)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193742\/dsa-2021-214-dell-emc-vnxe1600-for-multiple-third-party-component-vulnerabilities\">https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000193742\/dsa-2021-214-dell-emc-vnxe1600-for-multiple-third-party-component-vulnerabilities<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-15","alert_type":396,"serial_number":"AV21-595","subject":null,"moderation_state":"published","external_url":null},{"nid":2828,"title":"Microsoft Edge security advisory","uuid":"b7215a60-5f45-464e-8a89-ae45d71cb510","banner":null,"lang":"en","date_modified":"2021-11-22","date_modified_ts":"2021-11-22T19:57:57Z","date_created":"2021-11-22T19:57:57Z","summary":null,"body":["<article data-history-node-id=\"2828\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-596<br \/>\nDate: 22 November 2021<\/strong><\/p>\n\n<p>On 19 November 2021 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 96.0.1054.29<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-19-2021\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-19-2021<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory","alert_type":396,"serial_number":"AV21-596","subject":null,"moderation_state":"published","external_url":null},{"nid":2829,"title":"VMware security advisory","uuid":"518e1298-11ef-4fb2-b068-2a57c5312f7b","banner":null,"lang":"en","date_modified":"2021-11-24","date_modified_ts":"2021-11-24T12:13:38Z","date_created":"2021-11-24T12:13:38Z","summary":null,"body":["<article data-history-node-id=\"2829\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-47\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-597<br \/>\nDate: 24 November 2021<\/strong><\/p>\n\n<p>On 23 November 2021 VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware vCenter Server \u2013 versions 6.5 and 6.7<\/li>\n\t<li>VMware Cloud Foundation \u2013 version 3.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0027)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0027.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0027.html<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-47","alert_type":396,"serial_number":"AV21-597","subject":null,"moderation_state":"published","external_url":null},{"nid":2830,"title":"Cisco security advisory","uuid":"0fa7abc7-6c34-43f2-aaf6-16d8b0b2a96e","banner":null,"lang":"en","date_modified":"2021-11-25","date_modified_ts":"2021-11-25T16:20:11Z","date_created":"2021-11-25T16:12:50Z","summary":null,"body":["<article data-history-node-id=\"2830\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-97\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-598<br \/>\nDate: 25 November 2021<\/strong><\/p>\n\n<p>On 24 November 2021 Cisco published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Cisco Expressway Series \u2013 versions prior to X14.0.4 and X14.1<\/li>\n<\/ul><p>Cisco is aware that an exploit for CVE-2021-40438 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p>Cisco Expressway Series<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-apache-httpd-2.4.49-VWL69sWQ\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-apache-httpd-2.4.49-VWL69sWQ<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-97","alert_type":396,"serial_number":"AV21-598","subject":null,"moderation_state":"published","external_url":null},{"nid":2831,"title":"IBM security advisory","uuid":"ca1e1f1a-6928-4e34-9d0c-c4948ea1e2f9","banner":null,"lang":"en","date_modified":"2021-11-29","date_modified_ts":"2021-11-29T18:34:15Z","date_created":"2021-11-29T18:32:42Z","summary":null,"body":["<article data-history-node-id=\"2831\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-75\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-599<br \/>\nDate: 29 November 2021<\/strong><\/p>\n\n<p>Between 22 and 28 November 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>IBM Cloud Pak System \u2013 version 2.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>IBM Cloud Pak System<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-ibm-sdk-java-affects-ibm-cloud-pak-system-cve-2020-27221-2\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-ibm-sdk-java-affects-ibm-cloud-pak-system-cve-2020-27221-2\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-75","alert_type":396,"serial_number":"AV21-599","subject":null,"moderation_state":"published","external_url":null},{"nid":2832,"title":"Fortinet security advisory","uuid":"29ef1abf-87cb-4332-91ba-bbcbfd4a6606","banner":null,"lang":"en","date_modified":"2021-11-29","date_modified_ts":"2021-11-29T21:02:23Z","date_created":"2021-11-29T21:02:12Z","summary":null,"body":["<article data-history-node-id=\"2832\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-600<br \/>\nDate: 29 November 2021<\/strong><\/p>\n\n<p>\u00a0On 29 November 2021 Fortinet published a PSIRT Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>FortiClient EMS \u2013 multiple versions<\/li>\n\t<li>FortiClient Windows \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in code or command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Fortinet PSIRT Advisory (FG-IR-21-088)<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-088\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-088<\/a><\/p>\n\n<p><strong>Note to Readers<\/strong><\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment.\u00a0 We are Canada\u2019s national authority on cyber security and we lead the government\u2019s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-16","alert_type":396,"serial_number":"AV21-600","subject":null,"moderation_state":"published","external_url":null},{"nid":2838,"title":"[Control systems] B&R Industrial Automation security advisory","uuid":"43d42adf-96f5-450f-90f7-f387fffda067","banner":null,"lang":"en","date_modified":"2021-12-01","date_modified_ts":"2021-12-01T15:05:29Z","date_created":"2021-11-30T20:24:03Z","summary":null,"body":["<article data-history-node-id=\"2838\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-7\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-601<br \/>\nDate: 30 November 2021<\/strong><\/p>\n\n<p>On 30 November 2021 B&amp;R Industrial Automation published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>TCP\/IP stack in:\n\t<ul><li>Vision cameras \u2013 multiple models and versions<\/li>\n\t\t<li>Safe Logic \u2013 multiple models and versions<\/li>\n\t\t<li>Bus Controllers \u2013 multiple models and versions<\/li>\n\t\t<li>Motion components \u2013 multiple models and versions<\/li>\n\t<\/ul><\/li>\n\t<li>B&amp;R Automation Studio \u2013 versions 4.6.x and prior, 4.7.6 and prior, 4.8.5 and prior and 4.9.3 and prior.<\/li>\n\t<li>B&amp;R Automation NET\/PVI - versions 4.6.x and prior, 4.7.6 and prior, 4.8.5 and prior and 4.9.3 and prior.<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to session hijacking or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, once available.<\/p>\n\n<p>Number:Jack Cyber Security Advisory (#13\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1636745459972-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1636745459972-en-original-1.0.pdf<\/a><\/p>\n\n<p>B&amp;R Automation Studio\/NET\/PVI Cyber Security Advisory (#14\/2021)<br \/><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1636745459964-en-original-1.0.pdf\">https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1636745459964-en-original-1.0.pdf<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-7","alert_type":398,"serial_number":"AV21-601","subject":null,"moderation_state":"published","external_url":null},{"nid":2835,"title":"[Control systems] Xylem security advisory","uuid":"d1f02834-91f3-4c96-bb1e-59bb44d89e13","banner":null,"lang":"en","date_modified":"2021-12-01","date_modified_ts":"2021-12-01T14:00:00Z","date_created":"2021-12-01T14:00:00Z","summary":null,"body":["<article data-history-node-id=\"2835\" about=\"\/en\/alerts-advisories\/control-systems-xylem-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-602<br \/>\nDate: 1 December 2021<\/strong><\/p>\n\n<p>On 30 November 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0AADI GeoView Webservice - versions prior to v2.1.3<\/p>\n\n<p>Exploitation of this vulnerability could lead to unauthorized data modification.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-334-01)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-01<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-xylem-security-advisory","alert_type":398,"serial_number":"AV21-602","subject":null,"moderation_state":"published","external_url":null},{"nid":2833,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"46701274-764e-44e9-9a9a-c49cae843a97","banner":null,"lang":"en","date_modified":"2021-12-01","date_modified_ts":"2021-12-01T14:02:21Z","date_created":"2021-12-01T14:02:21Z","summary":null,"body":["<article data-history-node-id=\"2833\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-27\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-603<br \/>\nDate: 1 December 2021<\/strong><\/p>\n\n<p>On 30 November 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0MELSEC iQ-R Series \u2013 multiple models and firmware versions<br \/>\n\u2022\u00a0\u00a0 \u00a0MELSEC Q Series \u2013 multiple models and firmware versions<br \/>\n\u2022\u00a0\u00a0 \u00a0MELSEC L Series L02\/06\/26CPU(-P), L26CPU-(P)BT \u2013 all versions<br \/>\n\u2022\u00a0\u00a0 \u00a0MELIPC Series MI5122-VW \u2013 all versions<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-334-02)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-02<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-27","alert_type":398,"serial_number":"AV21-603","subject":null,"moderation_state":"published","external_url":null},{"nid":2834,"title":" [Control systems] Hitachi Energy security advisory","uuid":"e93fd011-1e06-48a6-bd01-7f67f57908fb","banner":null,"lang":"en","date_modified":"2021-12-01","date_modified_ts":"2021-12-01T14:04:52Z","date_created":"2021-12-01T14:04:52Z","summary":null,"body":["<article data-history-node-id=\"2834\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-604<br \/>\nDate: 1 December 2021<\/strong><\/p>\n\n<p>On 30 November 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0Counterparty Settlement and Billing (CSB) \u2013 version 5.7.3 and prior \u00a0<br \/>\n\u2022\u00a0\u00a0 \u00a0Retail Operations \u2013 version 5.7.3 and prior<\/p>\n\n<p>Exploitation of this vulnerability could result in unauthorized access and modification of data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-334-05)<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-05<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory","alert_type":398,"serial_number":"AV21-604","subject":null,"moderation_state":"published","external_url":null},{"nid":2836,"title":"[Control systems] Delta Electronics security advisory","uuid":"f4c4febe-f9fa-414d-a158-a7743392f51d","banner":null,"lang":"en","date_modified":"2021-12-01","date_modified_ts":"2021-12-01T14:41:15Z","date_created":"2021-12-01T14:41:15Z","summary":null,"body":["<article data-history-node-id=\"2836\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-13\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-605<br \/>\nDate: 1 December 2021<\/strong><\/p>\n\n<p>On 30 November 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CNCSoft - version 1.01.30 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-334-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-03<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-13","alert_type":398,"serial_number":"AV21-605","subject":null,"moderation_state":"published","external_url":null},{"nid":2837,"title":"[Control systems] Johnson Controls security advisory","uuid":"d9471ac6-bb5d-49ca-bd5b-76168e672817","banner":null,"lang":"en","date_modified":"2021-12-01","date_modified_ts":"2021-12-01T14:45:19Z","date_created":"2021-12-01T14:45:19Z","summary":null,"body":["<article data-history-node-id=\"2837\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-606<br \/>\nDate: 1 December 2021<\/strong><\/p>\n\n<p>On 30 November 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CEM Systems AC2000 - versions prior to 10.6<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-334-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-04 \">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-334-04 <\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-11","alert_type":398,"serial_number":"AV21-606","subject":null,"moderation_state":"published","external_url":null},{"nid":2839,"title":"Ubuntu security advisory","uuid":"8db2fb53-a3cf-4dc7-99f8-ad46a69956a7","banner":null,"lang":"en","date_modified":"2021-12-01","date_modified_ts":"2021-12-01T19:45:49Z","date_created":"2021-12-01T19:45:49Z","summary":null,"body":["<article data-history-node-id=\"2839\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-607<br \/>\nDate: 1 December 2021<\/strong><\/p>\n\n<p>On 1 December 2021 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or lead to the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notice (USN-5161-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5161-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5161-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5162-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5162-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5162-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5163-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5163-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5163-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5164-1)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5164-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5164-1<\/a><\/p>\n\n<p>Ubuntu Security Notice (USN-5165)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5165-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5165-1<\/a><\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices  \">https:\/\/ubuntu.com\/security\/notices\u00a0 <\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-32","alert_type":396,"serial_number":"AV21-607","subject":null,"moderation_state":"published","external_url":null},{"nid":2840,"title":"[Control systems] Distributed Data Systems security advisory","uuid":"a236ef3a-b6ee-47ea-859a-4e38fe0cb827","banner":null,"lang":"en","date_modified":"2021-12-03","date_modified_ts":"2021-12-03T12:35:18Z","date_created":"2021-12-03T12:35:18Z","summary":null,"body":["<article data-history-node-id=\"2840\" about=\"\/en\/alerts-advisories\/control-systems-distributed-data-systems-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-608<br \/>\nDate: 3 December 2021<\/strong><\/p>\n\n<p>On 3 December 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0WebHMI - versions prior to 4.1 \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution or authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-336-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-03<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-distributed-data-systems-security-advisory","alert_type":398,"serial_number":"AV21-608","subject":null,"moderation_state":"published","external_url":null},{"nid":2841,"title":"Mozilla security advisory","uuid":"ab86607f-8502-4a84-b8b1-e7bbdbab32b5","banner":null,"lang":"en","date_modified":"2021-12-03","date_modified_ts":"2021-12-03T14:23:30Z","date_created":"2021-12-03T14:23:30Z","summary":null,"body":["<article data-history-node-id=\"2841\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-49\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-609<br \/>\nDate: 3 December 2021<\/strong><\/p>\n\n<p>On 1 December 2021 Mozilla published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Network Security Services \u2013 versions prior to 3.73 and 3.68.1 ESR<\/li>\n<\/ul><p>Network Security Services (NSS) are a set of widely used cross-platform cryptography libraries designed to support various algorithms and protocols within security-enabled client\/server applications. These libraries are incorporated into many mainstream products as well as multiple open-source applications.<\/p>\n\n<p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Additional vendors affected by the reported vulnerabilities may also release security advisories related to their impacted products.<\/p>\n\n<p>Mozilla Foundation Security Advisory (MFSA2021-51)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-51\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-51\/<\/a><\/p>\n\n<p>Red Hat Security Bulletin (RHSB-2021-008)<br \/><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/RHSB-2021-008\">https:\/\/access.redhat.com\/security\/vulnerabilities\/RHSB-2021-008<\/a><\/p>\n\n<p>Ubuntu Security Notices (USN-5168-1 and USN-5168-3)<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5168-1\">https:\/\/ubuntu.com\/security\/notices\/USN-5168-1<\/a><br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5168-3\">https:\/\/ubuntu.com\/security\/notices\/USN-5168-3<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-49","alert_type":396,"serial_number":"AV21-609","subject":null,"moderation_state":"published","external_url":null},{"nid":2842,"title":"[Control systems] Hitachi Energy security advisory","uuid":"4d8e95b6-c350-4807-b445-6ed603e59de1","banner":null,"lang":"en","date_modified":"2021-12-03","date_modified_ts":"2021-12-03T17:05:01Z","date_created":"2021-12-03T17:05:01Z","summary":null,"body":["<article data-history-node-id=\"2842\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-610<br \/>\nDate: 3 December 2021<\/strong><\/p>\n\n<p>On 2 December 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>APM Edge \u2013 versions 1.0, 2.0 and 3.0<\/li>\n\t<li>RTU500 series CMU \u2013 multiple firmware versions<\/li>\n\t<li>PCM600 Update Manager \u2013 multiple versions<\/li>\n\t<li>Relion 670\/650\/SAM600-IO \u2013 multiple versions, all revisions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow for TCP connection hijacking, security bypass, information disclosure, system reboot or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<p>ICS Advisory (ICSA-21-336-04)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-04<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-336-05)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-05\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-05<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-336-06)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-06\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-06<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-336-07)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-07\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-07<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-336-08)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-08\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-08<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-0","alert_type":398,"serial_number":"AV21-610","subject":null,"moderation_state":"published","external_url":null},{"nid":2843,"title":"[Control systems] Johnson Controls security advisory","uuid":"82f109b1-fd6d-4e4f-8647-ca9ff6eb6312","banner":null,"lang":"en","date_modified":"2021-12-03","date_modified_ts":"2021-12-03T17:47:13Z","date_created":"2021-12-03T17:47:13Z","summary":null,"body":["<article data-history-node-id=\"2843\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-12\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-611<br \/>\nDate: 3 December 2021<\/strong><\/p>\n\n<p>On 2 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Sensormatic Entrapass \u2013 versions prior to 8.40<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-336-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-02<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-12","alert_type":398,"serial_number":"AV21-611","subject":null,"moderation_state":"published","external_url":null},{"nid":2844,"title":"[Control systems] Schneider Electric security advisory","uuid":"f39113e2-512d-4382-852a-96e8541de6c7","banner":null,"lang":"en","date_modified":"2021-12-06","date_modified_ts":"2021-12-06T13:09:37Z","date_created":"2021-12-06T13:09:37Z","summary":null,"body":["<article data-history-node-id=\"2844\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-612<br \/>\nDate: 6 December 2021<\/strong><\/p>\n\n<p>On 2 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Schneider Electric Software Update (SESU) \u2013 versions 2.3.0 to 2.5.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to obtain credentials and bypass authentication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-336-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-336-01<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-28","alert_type":398,"serial_number":"AV21-612","subject":null,"moderation_state":"published","external_url":null},{"nid":2845,"title":"IBM security advisory","uuid":"c31e33ca-8a5d-45a9-8b8e-2b0b2e680f79","banner":null,"lang":"en","date_modified":"2021-12-06","date_modified_ts":"2021-12-06T16:25:20Z","date_created":"2021-12-06T16:25:20Z","summary":null,"body":["<article data-history-node-id=\"2845\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-76\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-613<br \/>\nDate: 6 December 2021<\/strong><\/p>\n\n<p>Between 29 November and 5 December 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Automation Manager \u2013 version 4.2.0.1<\/li>\n\t<li>IBM Event Streams in IBM Cloud Pak for Integration \u2013 multiple versions<\/li>\n\t<li>8335-GTC \u2013 version OP910<\/li>\n\t<li>8335-GTG \u2013 version OP910<\/li>\n\t<li>8335-GTH \u2013 versions OP920, OP930 and OP940<\/li>\n\t<li>8335-GTW \u2013 version OP910<\/li>\n\t<li>8335-GTX \u2013 version OP940<\/li>\n\t<li>9183-22X \u2013 version OP940<\/li>\n\t<li>7063-CR2 \u2013 version OP940<\/li>\n\t<li>IBM Cloud Pak System \u2013 multiple versions<\/li>\n\t<li>Curam SPM \u2013 versions 8.0.0 and 7.0.11<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.1.x and 11.2.0<\/li>\n\t<li>IBM QRadar SIEM \u2013 multiple versions<\/li>\n\t<li>IBM Integration Bus \u2013 versions V10.0.0 to V10.0.0.24<\/li>\n\t<li>IBM App connect Enterprise \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-76","alert_type":396,"serial_number":"AV21-613","subject":null,"moderation_state":"published","external_url":null},{"nid":2846,"title":"[Control systems] ABB security advisory","uuid":"69e492bd-5d42-4b89-976e-ca738301f658","banner":null,"lang":"en","date_modified":"2021-12-06","date_modified_ts":"2021-12-06T19:27:48Z","date_created":"2021-12-06T19:27:48Z","summary":null,"body":["<article data-history-node-id=\"2846\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-19\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-614<br \/>\nDate: 6 December 2021<\/strong><\/p>\n\n<p>On 6 December 2021 ABB published a Cyber Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>RobotWare \u2013 versions prior to 7.3.2<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in information disclosure and unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p>ABB Cyber Security Advisory (SI20265)<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=SI20265&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=SI20265&amp;Action=Launch<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-19","alert_type":398,"serial_number":"AV21-614","subject":null,"moderation_state":"published","external_url":null},{"nid":2847,"title":"Android security advisory \u2013 December 2021 monthly rollup","uuid":"edfd53a2-5b43-466c-b485-65ac7ebc6378","banner":null,"lang":"en","date_modified":"2021-12-06","date_modified_ts":"2021-12-06T20:47:11Z","date_created":"2021-12-06T20:47:11Z","summary":null,"body":["<article data-history-node-id=\"2847\" about=\"\/en\/alerts-advisories\/android-security-advisory-december-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-615<br \/>\nDate: 6 December 2021<\/strong><\/p>\n\n<p>On 6 December 2021 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2021-12-01\">https:\/\/source.android.com\/security\/bulletin\/2021-12-01<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-december-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-615","subject":null,"moderation_state":"published","external_url":null},{"nid":2848,"title":"Google Chrome security advisory","uuid":"1041ea5d-2f44-4215-ab48-e91c288eef9b","banner":null,"lang":"en","date_modified":"2021-12-07","date_modified_ts":"2021-12-07T16:12:00Z","date_created":"2021-12-07T16:12:00Z","summary":null,"body":["<article data-history-node-id=\"2848\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-73\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-616<br \/>\nDate: 7 December 2021<\/strong><\/p>\n\n<p>On 6 December 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 96.0.4664.93<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/12\/stable-channel-update-for-desktop.html \">https:\/\/chromereleases.googleblog.com\/2021\/12\/stable-channel-update-for-desktop.html <\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-73","alert_type":396,"serial_number":"AV21-616","subject":null,"moderation_state":"published","external_url":null},{"nid":2849,"title":"Mozilla security advisory","uuid":"80204ab7-b1b8-4138-9aab-3d83c1e8ae45","banner":null,"lang":"en","date_modified":"2021-12-07","date_modified_ts":"2021-12-07T17:24:41Z","date_created":"2021-12-07T17:24:41Z","summary":null,"body":["<article data-history-node-id=\"2849\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-50\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-617<br \/>\nDate: 7 December 2021<\/strong><\/p>\n\n<p>On 7 December 2021 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 95<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.4.0<\/li>\n\t<li>Thunderbird \u2013 versions prior to 91.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Firefox (MFSA 2021-52)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-52\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-52\/<\/a><\/p>\n\n<p>Firefox ESR (MFSA 2021-53)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-53\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-53\/<\/a><\/p>\n\n<p>Thunderbird (MFSA 2021-54)<br \/><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-54\/\">https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2021-54\/<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-50","alert_type":396,"serial_number":"AV21-617","subject":null,"moderation_state":"published","external_url":null},{"nid":2850,"title":"[Control systems] Hitachi Energy security advisory","uuid":"49d54ba5-7c90-4390-9b5a-dbaefd86d530","banner":null,"lang":"en","date_modified":"2021-12-08","date_modified_ts":"2021-12-08T11:54:27Z","date_created":"2021-12-08T11:54:27Z","summary":null,"body":["<article data-history-node-id=\"2850\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-618<br \/>\nDate: 8 December 2021<\/strong><\/p>\n\n<p>On 7 December 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>FOX61x \u2013 versions prior to R15A<\/li>\n\t<li>RTU500 Series CMU Firmware \u2013 multiple versions<\/li>\n\t<li>XMC20 \u2013 versions prior to R15A \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service and unauthorized access. \u00a0<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-341-01)<br \/><a href=\" https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-341-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-341-01<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-341-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-341-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-341-02<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-1","alert_type":398,"serial_number":"AV21-618","subject":null,"moderation_state":"published","external_url":null},{"nid":2851,"title":"[Control systems] FANUC security advisory","uuid":"47f0c589-db9d-48e6-b0a6-60af67d4f1bd","banner":null,"lang":"en","date_modified":"2021-12-08","date_modified_ts":"2021-12-08T12:00:12Z","date_created":"2021-12-08T12:00:12Z","summary":null,"body":["<article data-history-node-id=\"2851\" about=\"\/en\/alerts-advisories\/control-systems-fanuc-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-619<br \/>\nDate: 8 December 2021<\/strong><\/p>\n\n<p>On 7 December 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>R-30iA \u2013 multiple versions<\/li>\n\t<li>R-30iB \u2013 multiple versions<\/li>\n\t<li>R-30iB Mate \u2013 multiple versions<\/li>\n\t<li>R-30iB Compact \u2013 multiple versions<\/li>\n\t<li>R-30iB Plus \u2013 multiple versions<\/li>\n\t<li>R-30iB Mate Plus \u2013 multiple versions<\/li>\n\t<li>R-30iB Compact Plus \u2013 multiple versions<\/li>\n\t<li>R-30iB Mini Plus \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial-of-service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-243-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-243-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-243-02<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fanuc-security-advisory","alert_type":398,"serial_number":"AV21-619","subject":null,"moderation_state":"published","external_url":null},{"nid":2852,"title":"Fortinet security advisory","uuid":"ff7a44c3-ef63-4ab6-aef7-d54be4b874dc","banner":null,"lang":"en","date_modified":"2021-12-08","date_modified_ts":"2021-12-08T12:04:09Z","date_created":"2021-12-08T12:04:09Z","summary":null,"body":["<article data-history-node-id=\"2852\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-17\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-620<br \/>\nDate: 8 December 2021<\/strong><\/p>\n\n<p>On 7 December 2021 Fortinet published PSIRT Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiWeb \u2013 multiple versions<\/li>\n\t<li>FortlWLM \u2013 version 8.6.1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, arbitrary command execution or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Fortinet PSIRT Advisories<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\">https:\/\/www.fortiguard.com\/psirt<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-17","alert_type":396,"serial_number":"AV21-620","subject":null,"moderation_state":"published","external_url":null},{"nid":2853,"title":"Zoho security advisory","uuid":"98d1d206-fe23-4019-bfeb-29b4f6fc5181","banner":null,"lang":"en","date_modified":"2021-12-08","date_modified_ts":"2021-12-08T16:50:11Z","date_created":"2021-12-08T16:50:11Z","summary":null,"body":["<article data-history-node-id=\"2853\" about=\"\/en\/alerts-advisories\/zoho-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-621<br \/>\nDate: 8 December 2021<\/strong><\/p>\n\n<p>On 3 December 2021 Zoho published a Vulnerability Notification to address a vulnerability in the following products:<\/p>\n\n<ul><li>ManageEngine Desktop Central \u2013 builds 10.1.2127.17 and prior, 10.1.2128.0 to 10.1.2137.2<\/li>\n\t<li>ManageEngine Desktop Central MSP \u2013 builds 10.1.2127.17 and prior, 10.1.2128.0 to 10.1.2137.2<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow for remote code execution.<\/p>\n\n<p>Zoho has noted it is aware of exploitation of this vulnerability in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Zoho Vulnerability Notification<br \/><a href=\"https:\/\/pitstop.manageengine.com\/portal\/en\/community\/topic\/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp\">https:\/\/pitstop.manageengine.com\/portal\/en\/community\/topic\/an-authentication-bypass-vulnerability-identified-and-fixed-in-desktop-central-and-desktop-central-msp<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zoho-security-advisory-0","alert_type":396,"serial_number":"AV21-621","subject":null,"moderation_state":"published","external_url":null},{"nid":2854,"title":"SonicWall security advisory","uuid":"cc44a974-8566-483c-a2fe-a09c92d2c0c7","banner":null,"lang":"en","date_modified":"2021-12-08","date_modified_ts":"2021-12-08T19:18:58Z","date_created":"2021-12-08T19:18:58Z","summary":null,"body":["<article data-history-node-id=\"2854\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-622<br \/>\nDate: 8 December 2021<\/strong><\/p>\n\n<p>On 1 December 2021 SonicWall published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SMA 100 series \u2013 multiple firmware versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Security Advisory (SNWLID-2021-0026)<br \/><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2021-0026\">https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2021-0026<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-4","alert_type":396,"serial_number":"AV21-622","subject":null,"moderation_state":"published","external_url":null},{"nid":2855,"title":"[Control systems] Hitachi Energy security advisory","uuid":"6614ceae-23a6-4f77-9797-e2c94693bee0","banner":null,"lang":"en","date_modified":"2021-12-09","date_modified_ts":"2021-12-09T19:02:29Z","date_created":"2021-12-09T19:02:29Z","summary":null,"body":["<article data-history-node-id=\"2855\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-623<br \/>\nDate: 9 December 2021<\/strong><\/p>\n\n<p>On 9 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>GMS600 \u2013 multiple versions<\/li>\n\t<li>PWC600 \u2013 multiple versions<\/li>\n\t<li>Relion 670\/650\/SAM600-IO series \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access and denial -of- service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-343-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-343-01 \">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-343-01 <\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-2","alert_type":398,"serial_number":"AV21-623","subject":null,"moderation_state":"published","external_url":null},{"nid":2856,"title":"[Control systems] Hillrom security advisory","uuid":"816f3163-7a47-4eab-ac42-b7f17c744d1d","banner":null,"lang":"en","date_modified":"2021-12-09","date_modified_ts":"2021-12-09T19:04:51Z","date_created":"2021-12-09T19:04:51Z","summary":null,"body":["<article data-history-node-id=\"2856\" about=\"\/en\/alerts-advisories\/control-systems-hillrom-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-624<br \/>\nDate: 9 December 2021<\/strong><\/p>\n\n<p>On 9 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Welch Allyn Q-Stress Cardiac Stress Testing System - version 6.0.0 to 6.3.1<\/li>\n\t<li>Welch Allyn X-Scribe Cardiac Stress Testing System - version 5.01 to 6.3.1<\/li>\n\t<li>Welch Allyn Diagnostic Cardiology Suite - version 2.1.0<\/li>\n\t<li>Welch Allyn Vision Express - version 6.1.0 to 6.4.0<\/li>\n\t<li>Welch Allyn H-Scribe Holter Analysis System - version 5.01 to 6.4.0<\/li>\n\t<li>Welch Allyn R-Scribe Resting ECG System - version 5.01 to 7.0.0<\/li>\n\t<li>Welch Allyn Connex Cardio - version 1.0.0 to 1.1.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSMA-21-343-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-343-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-21-343-01<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hillrom-security-advisory-0","alert_type":398,"serial_number":"AV21-624","subject":null,"moderation_state":"published","external_url":null},{"nid":2857,"title":"[Control systems] WECON security advisory","uuid":"edbc88bf-228c-4eb4-94af-8a5a54facc55","banner":null,"lang":"en","date_modified":"2021-12-09","date_modified_ts":"2021-12-09T19:07:08Z","date_created":"2021-12-09T19:07:08Z","summary":null,"body":["<article data-history-node-id=\"2857\" about=\"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-625<br \/>\nDate: 9 December 2021<\/strong><\/p>\n\n<p>On 9 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>LeviStudioU \u2013 version 2019-09-21 and prior \u00a0<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-343-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-343-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-343-02<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-3","alert_type":398,"serial_number":"AV21-625","subject":null,"moderation_state":"published","external_url":null},{"nid":2858,"title":"Apache security advisory","uuid":"1798e224-084f-42ab-919c-49a0855dd758","banner":null,"lang":"en","date_modified":"2021-12-10","date_modified_ts":"2021-12-10T17:17:54Z","date_created":"2021-12-10T16:45:14Z","summary":null,"body":["<article data-history-node-id=\"2858\" about=\"\/en\/alerts-advisories\/apache-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-626<br \/>\nDate: 10 December 2021<\/strong><\/p>\n\n<p>On 10 December 2021 Apache published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Apache Log4j \u2013 version 2.0-beta9 to 2.14.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>Open-source reporting indicates that this vulnerability is being exploited in the wild and that proofs of concept are being shared online.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Apache Log4j:<br \/><a href=\"https:\/\/logging.apache.org\/log4j\/2.x\/security.html\">https:\/\/logging.apache.org\/log4j\/2.x\/security.html<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-4","alert_type":396,"serial_number":"AV21-626","subject":null,"moderation_state":"published","external_url":null},{"nid":2859,"title":"IBM security advisory","uuid":"11afe8de-a574-4c9f-905a-273866bba54e","banner":null,"lang":"en","date_modified":"2021-12-13","date_modified_ts":"2021-12-13T19:26:41Z","date_created":"2021-12-13T19:26:41Z","summary":null,"body":["<article data-history-node-id=\"2859\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-77\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-627<br \/>\nDate: 13 December 2021<\/strong><\/p>\n\n<p>Between 6 and 12 December 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise \u2013 versions V11, V11.0.0.0 to V11.0.0.12<\/li>\n\t<li>IBM Spectrum Copy Data Management \u2013 versions 2.2.13 and prior<\/li>\n\t<li>IBM Spectrum Protect Backup-Archive Client \u2013 multiple versions<\/li>\n\t<li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p>IBM App Connect Enterprise<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-app-connect-enterprise-v11-is-affected-by-vulnerabilities-in-node-js-cve-2021-23358-3\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-app-connect-enterprise-v11-is-affected-by-vulnerabilities-in-node-js-cve-2021-23358-3\/<\/a><\/p>\n\n<p>IBM Spectrum Copy Data Management<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-jackson-jquery-and-dom4j-affect-ibm-spectrum-copy-data-management\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-jackson-jquery-and-dom4j-affect-ibm-spectrum-copy-data-management\/<\/a> \u00a0<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-xstream-affect-ibm-spectrum-copy-data-management\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-xstream-affect-ibm-spectrum-copy-data-management\/<\/a><\/p>\n\n<p>IBM Spectrum Protect Backup-Archive Client<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-openssl-affect-ibm-spectrum-protect-backup-archive-client-netapp-services-cve-2021-3712-cve-2021-3711\/\">https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerabilities-in-openssl-affect-ibm-spectrum-protect-backup-archive-client-netapp-services-cve-2021-3712-cve-2021-3711\/<\/a><\/p>\n\n<p>IBM \u2013 Apache Log4j Vulnerability<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-77","alert_type":396,"serial_number":"AV21-627","subject":null,"moderation_state":"published","external_url":null},{"nid":2860,"title":"Google Chrome security advisory","uuid":"634c9631-9b42-4af0-b55a-3c5170a5c2f1","banner":null,"lang":"en","date_modified":"2021-12-14","date_modified_ts":"2021-12-14T17:42:15Z","date_created":"2021-12-14T17:42:15Z","summary":null,"body":["<article data-history-node-id=\"2860\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-74\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-628<br \/>\nDate: 14 December 2021<\/strong><\/p>\n\n<p>On 13 December 2021 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 96.0.4664.110<\/li>\n<\/ul><p>Google is aware of reports that an exploit for CVE-2021-4102 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2021\/12\/stable-channel-update-for-desktop_13.html\">https:\/\/chromereleases.googleblog.com\/2021\/12\/stable-channel-update-for-desktop_13.html<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-74","alert_type":396,"serial_number":"AV21-628","subject":null,"moderation_state":"published","external_url":null},{"nid":2861,"title":"Apple security advisory","uuid":"1573f772-174e-4a0a-8d95-d1c392467ace","banner":null,"lang":"en","date_modified":"2021-12-14","date_modified_ts":"2021-12-14T17:46:55Z","date_created":"2021-12-14T17:46:55Z","summary":null,"body":["<article data-history-node-id=\"2861\" about=\"\/en\/alerts-advisories\/apple-security-advisory-47\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-629<br \/>\nDate: 14 December 2021<\/strong><\/p>\n\n<p>On 13 December 2021 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Monterey \u2013 versions prior to 12.1<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.6.2<\/li>\n\t<li>macOS Catalina \u2013 versions prior to Security Update 2021-008<\/li>\n\t<li>watchOS \u2013 versions prior to 8.3<\/li>\n\t<li>iOS \u2013 versions prior to 15.2<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.2<\/li>\n\t<li>tvOS \u2013 versions prior to 15.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">https:\/\/support.apple.com\/en-us\/HT201222<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-47","alert_type":396,"serial_number":"AV21-629","subject":null,"moderation_state":"published","external_url":null},{"nid":2862,"title":"[Control systems] Advantech security advisory","uuid":"48e21d8b-e0af-433e-8aa6-1da0da59eeb0","banner":null,"lang":"en","date_modified":"2021-12-14","date_modified_ts":"2021-12-14T17:53:33Z","date_created":"2021-12-14T17:53:33Z","summary":null,"body":["<article data-history-node-id=\"2862\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-23\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-630<br \/>\nDate: 14 December 2021<\/strong><\/p>\n\n<p>On 14 December 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>R-SeeNet \u2013 version 2.4.16 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow for local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-348-01)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-348-01\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-348-01<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-23","alert_type":398,"serial_number":"AV21-630","subject":null,"moderation_state":"published","external_url":null},{"nid":2863,"title":"Microsoft security advisory \u2013 December 2021 monthly rollup","uuid":"9a23b85e-6fad-47b2-af5d-76473292fb62","banner":null,"lang":"en","date_modified":"2021-12-14","date_modified_ts":"2021-12-14T19:52:58Z","date_created":"2021-12-14T19:52:58Z","summary":null,"body":["<article data-history-node-id=\"2863\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-december-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-631<br \/>\nDate: 14 December 2021<\/strong><\/p>\n\n<p>On 14 December 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft 4K Wireless Display Adapter<\/li>\n\t<li>Microsoft Defender for IoT<\/li>\n\t<li>Office app<\/li>\n\t<li>Visual Studio Code WSL Extension<\/li>\n\t<li>Windows 7, 8.1, RT 8.1, 10 and 11<\/li>\n\t<li>Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019 and 2022 \u00a0<\/li>\n\t<li>Windows Server Core 2012, 2012 R2, 2016, 2019, 2022, 20H2 and 2004<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.<\/p>\n\n<p>Of note, Microsoft has indicated that exploitation has been detected for the following vulnerability: CVE-2021-43890.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>December 2021 Release Notes<br \/><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Dec\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2021-Dec<\/a><\/p>\n\n<p>Security Update Guide<br \/><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-december-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-631","subject":null,"moderation_state":"published","external_url":null},{"nid":2864,"title":"[Control systems] Schneider Electric security advisory","uuid":"f14ee275-dc7b-4817-9490-c72fb0ba85e6","banner":null,"lang":"en","date_modified":"2021-12-14","date_modified_ts":"2021-12-14T19:57:22Z","date_created":"2021-12-14T19:57:22Z","summary":null,"body":["<article data-history-node-id=\"2864\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-29\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-632<br \/>\nDate: 14 December 2021<\/strong><\/p>\n\n<p>On 14 December 2021 Schneider Electric published Security Notifications to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APC Rack PDU products \u2013 multiple products and versions<\/li>\n\t<li>EcoStruxure Power Monitoring Expert \u2013 version 9.0 and prior<\/li>\n\t<li>EVlink \u2013 multiple products and versions<\/li>\n\t<li>IGSS Data Collector \u2013 version V15.0.0.21320 and prior<\/li>\n\t<li>Apache Log4j Vulnerability<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access, execution of malicious web code, remote code execution, denial of service and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Apache Log4j Vulnerability<br \/><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SESB-2021-347-01\">https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SESB-2021-347-01<\/a><\/p>\n\n<p>Schneider Electric Cybersecurity Support Portal<br \/><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-29","alert_type":398,"serial_number":"AV21-632","subject":null,"moderation_state":"published","external_url":null},{"nid":2865,"title":"[Control systems] Siemens security advisory","uuid":"b9bf8ab9-c601-4c87-aeaf-d216d583d86a","banner":null,"lang":"en","date_modified":"2021-12-14","date_modified_ts":"2021-12-14T20:01:05Z","date_created":"2021-12-14T20:01:05Z","summary":null,"body":["<article data-history-node-id=\"2865\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-37\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-633<br \/>\nDate: 14 December 2021<\/strong><\/p>\n\n<p>On 13 and 14 December 2021 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apache Log4j Vulnerability<\/li>\n\t<li>Capital VSTAR \u2013 all versions<\/li>\n\t<li>JT2G0 \u2013 versions prior to V13.2.0.5<\/li>\n\t<li>JT Utilities \u2013 versions prior to V13.1.1.0<\/li>\n\t<li>JTTK \u2013 versions prior to V11.1.1.0<\/li>\n\t<li>ModelSim Simulation \u2013 all versions<\/li>\n\t<li>POWER METER SICAM Q100 \u2013 multiple products and versions<\/li>\n\t<li>Questa Simulation \u2013 all versions<\/li>\n\t<li>SiPass integrated \u2013 multiple products and versions<\/li>\n\t<li>Simcenter STAR-CCM+ Viewer \u2013 versions prior to 2021.3.1<\/li>\n\t<li>SIMATIC \u2013 multiple products and versions<\/li>\n\t<li>SINUMERIK Edge \u2013 versions prior to V3.2<\/li>\n\t<li>Siveillance Identity \u2013 multiple products and versions<\/li>\n\t<li>Teamcenter Active Workspace \u2013 multiple products and versions<\/li>\n\t<li>Teamcenter Visualization \u2013 versions prior to V13.2.0.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, disclosure of sensitive information, remote code execution, modification of data in transit, privilege escalation and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>Apache Log4j Vulnerability<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-661247.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-661247.pdf<\/a><\/p>\n\n<p>Siemens Security Publications<br \/><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-37","alert_type":398,"serial_number":"AV21-633","subject":null,"moderation_state":"published","external_url":null},{"nid":2866,"title":"SAP security advisory \u2013 December 2021 monthly rollup","uuid":"e74c9e1e-b293-4164-b074-c561062c4d09","banner":null,"lang":"en","date_modified":"2021-12-14","date_modified_ts":"2021-12-14T20:44:03Z","date_created":"2021-12-14T20:44:03Z","summary":null,"body":["<article data-history-node-id=\"2866\" about=\"\/en\/alerts-advisories\/sap-security-advisory-december-2021-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-634<br \/>\nDate: 14 December 2021<\/strong><\/p>\n\n<p>On 14 December 2021 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Commerce \u2013 version 2001<\/li>\n\t<li>SAP ABAP Server &amp; ABAP Platform \u2013 versions 701, 740, 750, 751, 752, 753, 754, 755, 756 and 804<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. \u00a0<\/p>\n\n<p>SAP Security Patch Day \u2013 December 2021<br \/><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/display\/PSR\/SAP+Security+Patch+Day+-+December+2021 \">https:\/\/wiki.scn.sap.com\/wiki\/display\/PSR\/SAP+Security+Patch+Day+-+December+2021 <\/a><span lang=\"FR-CA\" style=\"mso-ascii-font-family:Calibri;mso-fareast-font-family:Calibri;&#10;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;mso-ansi-language:&#10;FR-CA\" xml:lang=\"FR-CA\" xml:lang=\"FR-CA\"><\/span><span lang=\"FR-CA\" style=\"mso-ansi-language:&#10;FR-CA\" xml:lang=\"FR-CA\" xml:lang=\"FR-CA\"><o:p><\/o:p><\/span><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-december-2021-monthly-rollup","alert_type":396,"serial_number":"AV21-634","subject":null,"moderation_state":"published","external_url":null},{"nid":2900,"title":"Active exploitation of Apache Log4j vulnerability - update 7","uuid":"f9a8fad7-f452-4f39-869c-f6c0de156880","banner":null,"lang":"en","date_modified":"2021-12-29","date_modified_ts":"2021-12-29T18:26:53Z","date_created":"2021-12-14T21:59:32Z","summary":null,"body":["<article data-history-node-id=\"2900\" about=\"\/en\/alerts-advisories\/active-exploitation-apache-log4j-vulnerability\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AL21-019 - Update 7<br \/>\nDate: December 10, 2021<br \/>\nUpdated: December 29, 2021<\/strong><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations. Recipients of this information may redistribute it within their respective organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>On 10 December 2021, Apache released a Security Advisory <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> highlighting a critical remote code execution vulnerability in Log4j, a widely deployed Java-based logging utility. Open-source reporting indicates that active scanning and exploitation of this vulnerability have been observed.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 10 December 2021, Apache released a Security Advisory <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> highlighting a critical remote code execution vulnerability in Log4j, affecting versions between 2.0-beta9 to 2.14.1. The vulnerability allows a remote unauthenticated actor to execute arbitrary code on an affected device.<\/p>\n\n<p>Open-source reporting indicates that the critical vulnerability, tracked as CVE-2021-44228 <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, is actively being scanned for and exploited. Due to the Log4j library\u2019s widespread use in popular frameworks, many third-party apps may also be vulnerable to exploitation. In addition, Log4j is often used in enterprise Java software and is also included in several Apache frameworks including but not limited to: Apache Struts2, Apache Solr, Apache Druid, Apache Flink and Apache Swift. Other Java frameworks also include it in their libraries, including but not limited to: Netty, MyBatis and the Spring Framework. <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<h2>Update 1<\/h2>\n\n<p>The Apache Log4j library allows for developers to log output from various data sources within their applications. In certain circumstances, the data being logged originates from user input. Notably, it supports Java Naming and Directory Interface (JNDI) features, which it leverages in configuration, logging messages and parameters. In vulnerable versions of Log4j, logged user data containing JNDI lookups to actor-controlled endpoints could be performed, which would result in the server loading and executing arbitrary code from the endpoint.<\/p>\n\n<p>The Cyber Centre strongly encourages organizations internally review potentially impacted applications. While non-exhaustive, community sources are assisting in these efforts with the identification of impacted products. <sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><\/p>\n\n<p>Apache has released Log4j version 2.15, which addresses this vulnerability. In addition, Apache has provided workarounds for previous releases when upgrading is not possible.<\/p>\n\n<h2>Update 2<\/h2>\n\n<p>It has been determined that Log4j 2.15.0 may still be vulnerable under certain non-default configurations. Apache has released Log4j version 2.16.0 to address this latest vulnerability, which is tracked as CVE-2021-45046. <sup id=\"fn8-2-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<h2>Update 3<\/h2>\n\n<p><strike>The Cyber Centre assesses that organizations who have already patched to 2.15.0 and use a standard configuration can follow standard patching processes for updating to 2.16.0. Organizations who have not updated yet should update to 2.16.0 or apply the suggested mitigation if updating is not immediately possible.<\/strike><\/p>\n\n<p>NCSC-NL, with the help of the security community, has compiled a robust source of information regarding the Log4j vulnerability including but not limited to indicators of compromise, mitigation advice and affected software.<sup id=\"fn1-1-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>\u00a0 Additionally, CISA\u2019s guidance is a valuable source of information.<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup><\/p>\n\n<h2>Update 4<\/h2>\n\n<p>On 17 December 2021 Apache updated its assessment of the severity and impact of CVE-2021-45046 to critical, remote code execution. <sup id=\"fn1-2-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<h2>Update 5<\/h2>\n\n<p>On 17 December 2021 Apache released Log4j 2.17 to address a denial of service (DOS) vulnerability in versions 2.0-alpha1 through 2.16.0 (Java 8). This vulnerability has been assigned CVE-2021-45105 and has been rated CVSS 7.5. <sup id=\"fn1e-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<h2>Update 6<\/h2>\n\n<p>On 22 December 2021 Apache released Log4j 2.12.3 for Java 7 users and 2.3.1 for Java 6 users to address currently known vulnerabilities and harden JNDI functionality. <sup id=\"fn1-3-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> The Cyber Centre encourages users of Java 6 and 7 to upgrade to a later version of Java as public support for these versions has ended.<\/p>\n\n<p>In addition, the Cyber Centre has collaborated with its international counterparts to release \u201cJoint cybersecurity advisory on mitigating Log4Shell and other Log4j-related vulnerabilities.\u201d <sup id=\"fn12e-rf\"><a class=\"fn-lnk\" href=\"#fn12\"><span class=\"wb-inv\">Footnote <\/span>12<\/a><\/sup><\/p>\n\n<h2>Update 7<\/h2>\n\n<p>On 28 December 2021 Apache released Log4j version 2.17.1 (Java 8), 2.12.4 (Java 7) and 2.3.2 (Java 6) to address a vulnerability in versions prior to 2.17.1 (Java 8), 2.1.4 (Java 7) and 2.1.3 (Java 6). This vulnerability has been assigned CVE-2021-44832 and a CVSS 6.6. Exploitation of this vulnerability would require that an actor have permission to modify a specific configuration file on an affected system in order to achieve remote code execution. <sup id=\"fn1e-2-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>The Cyber Centre encourages those organizations with applications leveraging Apache Log4j to:<\/p>\n\n<ul><li><strong>Update 7 (Java 8): <\/strong>Cyber Centre recommends upgrading to Log4j version 2.16 or later as soon as possible.<\/li>\n\t<li><strong>Update 7 (Java 7):<\/strong> Cyber Centre recommends that Java 7 users refer to Apache for specific actions and consider upgrading to a later version of Java. <sup id=\"fn1e-3-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> Log4j version 2.1.4 has been released.<\/li>\n\t<li><strong>Update 7 (Java 6):<\/strong> Cyber Centre recommends that Java 6 users refer to Apache for specific actions and consider upgrading to a later version of Java. <sup id=\"fn1e-4-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> Log4j version 2.3.2 has been released.<\/li>\n\t<li>\n\t<p><strong>Update 6:<\/strong> If upgrading is not immediately possible, consider applying the suggested mitigation from Apache. <sup id=\"fn1e-5-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\t<\/li>\n\t<li>Check logs for signs of compromise.<\/li>\n<\/ul><p>Additional vendors affected by the reported vulnerabilities may also release security advisories related to their impacted products.<\/p>\n\n<h2>Detection<\/h2>\n\n<p>Identify Java Naming and Directory Interface (JNDI) lookups in upstream logs to verify for potential impact or exploit attempts. <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/p>\n\n<p>Verify traffic from known scanning IP addresses <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> by checking firewall logs.<\/p>\n\n<h2>Update 1<span class=\"wb-inv\">.1<\/span><\/h2>\n\n<h3>Mitigation<\/h3>\n\n<p>Apache recommends the following mitigations if patching cannot be immediately performed: <sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<ul><li><strike>In Log4j versions &gt;= 2.10, the vulnerable behavior can be mitigated by setting the system property \u201clog4j2.formatMsgNoLookups\u201d to \u201ctrue\u201d. Alternatively, the environment variable \u201cLOG4J_FORMAT_MSG_NO_LOOKUPS\u201d can be set to \u201ctrue\u201d in order to mitigate this behavior.<\/strike>\n\n\t<ul><li><strong>Update 2:<\/strong> This mitigation measure has been discredited according to Apache. <sup id=\"fn1c-2-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t<\/ul><\/li>\n\t<li>For Log4j versions &lt; 2.16.0, the mitigation is to remove the JndiLookup class from the classpath by running the following command.\n\t<ul><li>\u201czip -q -d log4j-core-*.jar org\/apache\/logging\/log4j\/core\/lookup\/JndiLookup.class\u201d<\/li>\n\t\t<li><strong>Update 2:\u00a0<\/strong>\u00a0This mitigation measure has been expanded to include all versions of Log4j &lt; 2.16.0. <sup id=\"fn8-3-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t<\/ul><\/li>\n\t<li><strong>Update 5:<\/strong> For Log4j versions &lt; 2.17.0, the mitigation for CVE-2021-45105 is to remove or replace references to Context Lookups in the configuration.\n\t<ul><li>In PatternLayout in the logging configuration, replace Context Lookups like ${ctx:loginId} or $${ctx:loginId} with Thread Context Map patterns (%X, %mdc, or %MDC). <sup id=\"fn1k-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t\t<li>Otherwise, in the configuration, remove references to Context Lookups like ${ctx:loginId} or $${ctx:loginId} where they originate from sources external to the application such as HTTP headers or user input. <sup id=\"fn1l-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t<\/ul><\/li>\n<\/ul><p>Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre through <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/logging.apache.org\/log4j\/2.x\/security.html\">Apache Log4j Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts\/apache-security-advisory-4\">CCCS AV21-626 Apache Security Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-44228\">CVE-2021-44228<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.ncsc.gov.uk\/news\/apache-log4j-vulnerability\">CERT United Kingdom - Alert: Active scanning for Apache Log4j 2 vulnerability (CVE-2021-44228)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/advisories\/log4j-rce-0-day-actively-exploited\/\">CERT New Zealand - Log4j RCE 0-day actively exploited<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/gist.github.com\/Neo23x0\/e4c8b03ff8cdf1fa63b7d15db6e3860b\">Florian Roth - log4j RCE Exploitation Detection (Grep and YARA)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/gist.github.com\/gnremy\/c546c7911d5f876f263309d7161a7217\">Greynoise IP List - CVE-2021-44228 Apache Log4j RCE Attempts<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/github.com\/YfryTchsGD\/Log4jAttackSurface\">GitHub community resource identifying vulnerable applications<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/github.com\/NCSC-NL\/log4shell\">NCSC-NL : Resource GitHub<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote <\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/uscert\/apache-log4j-vulnerability-guidance\">CISA Apache Log4j Vulnerability Guidance<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote <\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-45105\">CVE-2021-45105<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote <\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 12<\/dt>\n\t<dd id=\"fn12\">\n\t<p><a href=\"\/en\/guidance\/joint-cybersecurity-advisory-mitigating-log4shell-and-other-log4j-related-vulnerabilities\">Joint cybersecurity advisory on mitigating Log4Shell and other Log4j-related vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn12-rf\"><span class=\"wb-inv\">Return to footnote <\/span>12<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-apache-log4j-vulnerability","alert_type":397,"serial_number":"AL21-019","subject":null,"moderation_state":"published","external_url":null},{"nid":2867,"title":"Cisco security advisory","uuid":"7c0d93c4-e08c-4b67-861d-e1bf4b593adf","banner":null,"lang":"en","date_modified":"2021-12-15","date_modified_ts":"2021-12-15T16:50:26Z","date_created":"2021-12-15T16:50:26Z","summary":null,"body":["<article data-history-node-id=\"2867\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-98\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-635<br \/>\nDate: 15 December 2021<\/strong><\/p>\n\n<p>On 10 December 2021 Cisco published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Cisco Security Advisory<br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-apache-log4j-qRuKNEbd\">https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-apache-log4j-qRuKNEbd<\/a><\/p>\n\n<p>Apache Security Advisory (AV21-626)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4\">https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability \">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability <\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-98","alert_type":396,"serial_number":"AV21-635","subject":null,"moderation_state":"published","external_url":null},{"nid":2868,"title":" VMware security advisory","uuid":"4359b1be-475e-4886-b2f4-b8fc49c7c5ce","banner":null,"lang":"en","date_modified":"2021-12-15","date_modified_ts":"2021-12-15T16:52:34Z","date_created":"2021-12-15T16:52:34Z","summary":null,"body":["<article data-history-node-id=\"2868\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-48\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-637<br \/>\nDate: 15 December 2021<\/strong><\/p>\n\n<p>On 10 December 2021 VMware published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>VMware Security Advisory<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0028.html  \">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0028.html \u00a0<\/a><\/p>\n\n<p>Apache Security Advisory (AV21-626)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4\">https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability \">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability <\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-48","alert_type":396,"serial_number":"AV21-637","subject":null,"moderation_state":"published","external_url":null},{"nid":2869,"title":"Adobe security advisory","uuid":"151293c7-a208-45de-adce-5ed16df0f759","banner":null,"lang":"en","date_modified":"2021-12-15","date_modified_ts":"2021-12-15T16:53:22Z","date_created":"2021-12-15T16:53:22Z","summary":null,"body":["<article data-history-node-id=\"2869\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-50\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-636<br \/>\nDate: 15 December 2021<\/strong><\/p>\n\n<p>On 14 December 2021 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe After Effects \u2013 multiple versions<\/li>\n\t<li>Adobe Audition \u2013 multiple versions<\/li>\n\t<li>Adobe Connect \u2013 version 11.3 and prior<\/li>\n\t<li>Adobe Dimension \u2013 version 3.4.3 and prior<\/li>\n\t<li>Adobe Experience Manager \u2013 version 6.5.10.0 and prior<\/li>\n\t<li>Adobe Media Encoder \u2013 multiple versions<\/li>\n\t<li>Adobe Prelude \u2013 version 22.0 and prior<\/li>\n\t<li>Adobe Premiere Pro \u2013 multiple versions<\/li>\n\t<li>Adobe Premiere Rush \u2013 version 1.5.16 and prior<\/li>\n\t<li>Lightroom \u2013 version 4.4 and prior<\/li>\n\t<li>Photoshop 2021 \u2013 version 22.5.3 and prior<\/li>\n\t<li>Photoshop 2022 \u2013 version 23.0.2 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Adobe Security Bulletins and Advisories<br \/><a href=\"https:\/\/helpx.adobe.com\/security.html\">https:\/\/helpx.adobe.com\/security.html<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-50","alert_type":396,"serial_number":"AV21-636","subject":null,"moderation_state":"published","external_url":null},{"nid":2870,"title":"Intel security advisory","uuid":"4e55d444-1f5a-4bc9-8e8c-ef283e5d111a","banner":null,"lang":"en","date_modified":"2021-12-15","date_modified_ts":"2021-12-15T16:56:14Z","date_created":"2021-12-15T16:56:14Z","summary":null,"body":["<article data-history-node-id=\"2870\" about=\"\/en\/alerts-advisories\/intel-security-advisory-21\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-639<br \/>\nDate: 15 December 2021<\/strong><\/p>\n\n<p>On 14 December 2021 Intel published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Intel Security Advisory (INTEL-SA-00646)<br \/><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00646.html\">https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00646.html<\/a>\u00a0<\/p>\n\n<p>Apache Security Advisory (AV21-626)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4\">https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-21","alert_type":396,"serial_number":"AV21-639","subject":null,"moderation_state":"published","external_url":null},{"nid":2871,"title":"Apple security advisory","uuid":"3bdbf935-b2bc-4842-a3e5-3bd1c1ff0200","banner":null,"lang":"en","date_modified":"2021-12-15","date_modified_ts":"2021-12-15T16:56:36Z","date_created":"2021-12-15T16:56:36Z","summary":null,"body":["<article data-history-node-id=\"2871\" about=\"\/en\/alerts-advisories\/apple-security-advisory-48\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-638<br \/>\nDate: 15 December 2021<\/strong><\/p>\n\n<p>On 14 December 2021 Apple published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari \u2013 versions prior to 15.2<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Apple Security Updates<br \/><a href=\"https:\/\/support.apple.com\/en-ca\/HT212982\">https:\/\/support.apple.com\/en-ca\/HT212982<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-48","alert_type":396,"serial_number":"AV21-638","subject":null,"moderation_state":"published","external_url":null},{"nid":2872,"title":"[Control systems] ABB security advisory","uuid":"994f9576-49bb-46e4-bcb8-173cf9bbddd9","banner":null,"lang":"en","date_modified":"2021-12-15","date_modified_ts":"2021-12-15T20:33:03Z","date_created":"2021-12-15T20:33:03Z","summary":null,"body":["<article data-history-node-id=\"2872\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-20\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-640<br \/>\nDate: 15 December 2021<\/strong><\/p>\n\n<p>On 15 December 2021 ABB published a Security Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>ABB Security Advisory<br \/><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9ADB012621&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9ADB012621&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch<\/a>\u00a0 \u00a0<\/p>\n\n<p>Apache Security Advisory (AV21-626)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4\">https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-20","alert_type":398,"serial_number":"AV21-640","subject":null,"moderation_state":"published","external_url":null},{"nid":2874,"title":"VMware security advisory","uuid":"8b8bc0c3-0475-471e-aec9-7c7497140731","banner":null,"lang":"en","date_modified":"2021-12-17","date_modified_ts":"2021-12-17T18:05:41Z","date_created":"2021-12-17T18:05:41Z","summary":null,"body":["<article data-history-node-id=\"2874\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-49\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-641<br \/>\nDate: 17 December 2021<\/strong><\/p>\n\n<p>On 16 December 2021 VMware published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Workspace ONE UEM console \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthenticated actor to access sensitive data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>VMware Security Advisory (VMSA-2021-0029)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0029.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0029.html<\/a>\u00a0<\/p>\n\n<p>CRSVC-25521 - Workspace ONE UEM - Guidance for addressing CVE-2021-22054<br \/><a href=\"https:\/\/kb.vmware.com\/s\/article\/87167\">https:\/\/kb.vmware.com\/s\/article\/87167<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-49","alert_type":396,"serial_number":"AV21-641","subject":null,"moderation_state":"published","external_url":null},{"nid":2875,"title":"[Control systems] Delta Electronics security advisory","uuid":"9a3feab6-129b-4915-927f-3eeec38b9914","banner":null,"lang":"en","date_modified":"2021-12-17","date_modified_ts":"2021-12-17T18:08:43Z","date_created":"2021-12-17T18:08:43Z","summary":null,"body":["<article data-history-node-id=\"2875\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-642<br \/>\nDate: 17 December 2021<\/strong><\/p>\n\n<p>On 16 December 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>CNCSoft \u2013 version 1.01.30 and prior<\/li>\n\t<li>DIAEnergie \u2013 version 1.7.5 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service, information disclosure and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-238-03)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-238-03\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-238-03<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-350-02)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-02\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-02<\/a>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-14","alert_type":398,"serial_number":"AV21-642","subject":null,"moderation_state":"published","external_url":null},{"nid":2876,"title":"[Control systems] Mitsubishi Electric security advisory","uuid":"4f222420-6188-430e-a3e0-65257b375684","banner":null,"lang":"en","date_modified":"2021-12-17","date_modified_ts":"2021-12-17T18:11:19Z","date_created":"2021-12-17T18:11:19Z","summary":null,"body":["<article data-history-node-id=\"2876\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-28\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-643<br \/>\nDate: 17 December 2021<\/strong><\/p>\n\n<p>On 16 December 2021 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>EZSockdet \u2013 all versions<\/li>\n\t<li>GX Works2 \u2013 versions 1.606G and prior<\/li>\n\t<li>MELSOFT Navigator \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-350-04)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-04\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-04<\/a><\/p>\n\n<p>ICS Advisory (ICSA-21-350-05)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-05\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-05<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-28","alert_type":398,"serial_number":"AV21-643","subject":null,"moderation_state":"published","external_url":null},{"nid":2877,"title":"[Control systems] Wibu-Systems AG security advisory","uuid":"d902c261-da0d-475d-8be0-0f9c2f03070c","banner":null,"lang":"en","date_modified":"2021-12-17","date_modified_ts":"2021-12-17T18:18:09Z","date_created":"2021-12-17T18:18:09Z","summary":null,"body":["<article data-history-node-id=\"2877\" about=\"\/en\/alerts-advisories\/control-systems-wibu-systems-ag-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-644<br \/>\nDate: 17 December 2021<\/strong><\/p>\n\n<p>On 16 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CodeMeter Runtime \u2013 all versions prior to 7.30a<\/li>\n<\/ul><p>Exploitation of this vulnerability may lead to a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-350-03)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-03\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-03<\/a>\u00a0\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wibu-systems-ag-security-advisory-1","alert_type":398,"serial_number":"AV21-644","subject":null,"moderation_state":"published","external_url":null},{"nid":2878,"title":"[Control systems] Xylem security advisory","uuid":"2c0134c3-688e-4678-a3b5-f3f5d1e198c7","banner":null,"lang":"en","date_modified":"2021-12-17","date_modified_ts":"2021-12-17T18:19:55Z","date_created":"2021-12-17T18:19:55Z","summary":null,"body":["<article data-history-node-id=\"2878\" about=\"\/en\/alerts-advisories\/control-systems-xylem-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-645<br \/>\nDate: 17 December 2021<\/strong><\/p>\n\n<p>On 16 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>AquaView - versions 1.60, 7.x and 8.x<\/li>\n<\/ul><p>Exploitation of this vulnerability may lead to unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-350-01)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-01\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-01<\/a>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-xylem-security-advisory-0","alert_type":398,"serial_number":"AV21-645","subject":null,"moderation_state":"published","external_url":null},{"nid":2879,"title":"IBM security advisory","uuid":"034b00df-4e36-4891-90a7-57e3a52d0b7e","banner":null,"lang":"en","date_modified":"2021-12-21","date_modified_ts":"2021-12-21T14:00:44Z","date_created":"2021-12-21T13:50:48Z","summary":null,"body":["<article data-history-node-id=\"2879\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-78\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-646<br \/>\nDate: 21 December 2021<\/strong><\/p>\n\n<p>Between 13 and 19 December 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0IBM Cloud Pak for Multicloud Management Monitoring \u2013 versions prior to 2.3 Fix Pack 2<br \/>\n\u2022\u00a0\u00a0 \u00a0IBM QRadar SIEM \u2013 versions 7.3.0 to 7.3.3 FP 10 and 7.4.0 to 7.4.3 FP 4 \u00a0<br \/>\n\u2022\u00a0\u00a0 \u00a0IBM Resilient \u2013 version IBM Security SOAR<br \/>\n\u2022\u00a0\u00a0 \u00a0IBM Tivoli Netcool System Service Monitors\/Application Service Monitors \u2013 version 4.0.1 \u00a0<br \/>\n\u2022\u00a0\u00a0 \u00a0Watson Discovery versions 4.0.0 to 4.0.3 and 2.0.0 to 2.2.1<br \/>\n\u2022\u00a0\u00a0 \u00a0IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p>IBM \u2013 Apache Log4j Vulnerability<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-78","alert_type":396,"serial_number":"AV21-646","subject":null,"moderation_state":"published","external_url":null},{"nid":2880,"title":"Dell security advisory","uuid":"93115810-ebbf-4d6b-b3f2-b7e0ae2ce15a","banner":null,"lang":"en","date_modified":"2021-12-21","date_modified_ts":"2021-12-21T19:48:15Z","date_created":"2021-12-21T19:48:15Z","summary":null,"body":["<article data-history-node-id=\"2880\" about=\"\/en\/alerts-advisories\/dell-security-advisory-16\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-647<br \/>\nDate: 21 December 2021<\/strong><\/p>\n\n<p>Between 14 and 20 December 2021 Dell published Security Advisories to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Dell Response to Apache Log4j Remote Code Execution Vulnerability (DSN\u20132021\u2013007)<br \/><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en\u2013ca\/000194372\/dsn\u20132021\u2013007\u2013dell\u2013response\u2013to\u2013apache\u2013log4j\u2013remote\u2013code\u2013execution\u2013vulnerability\">https:\/\/www.dell.com\/support\/kbdoc\/en\u2013ca\/000194372\/dsn\u20132021\u2013007\u2013dell\u2013response\u2013to\u2013apache\u2013log4j\u2013remote\u2013code\u2013execution\u2013vulnerability<\/a><\/p>\n\n<p>Security Advisories and Notices<br \/><a href=\"https:\/\/www.dell.com\/support\/security\/en\u2013ca\">https:\/\/www.dell.com\/support\/security\/en\u2013ca<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-16","alert_type":396,"serial_number":"AV21-647","subject":null,"moderation_state":"published","external_url":null},{"nid":2881,"title":"HPE security advisory","uuid":"ab72e06f-2c5e-497b-a18e-9f2d5d60dab5","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T12:32:25Z","date_created":"2021-12-22T12:32:25Z","summary":null,"body":["<article data-history-node-id=\"2881\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-31\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-648<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>Between 15 and 20 December 2021 HPE published Security Bulletins to address critical vulnerabilities, which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>HPE Security Bulletin Library<br \/><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary\">https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-31","alert_type":396,"serial_number":"AV21-648","subject":null,"moderation_state":"published","external_url":null},{"nid":2884,"title":"Juniper Networks security advisory","uuid":"c8860c70-4326-43ba-9b58-fc5ecd6e9e41","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T12:36:23Z","date_created":"2021-12-22T12:36:23Z","summary":null,"body":["<article data-history-node-id=\"2884\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-11\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-649<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 13 December 2021 Juniper published an Out of Cycle Security Advisory to address critical vulnerabilities, which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to remote code execution.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Out of Cycle Security Advisory (JSA11259)<br \/><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA11259&amp;cat=SIRT_1&amp;actp=LIST\">https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;id=JSA11259&amp;cat=SIRT_1&amp;actp=LIST<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-11","alert_type":396,"serial_number":"AV21-649","subject":null,"moderation_state":"published","external_url":null},{"nid":2882,"title":"Oracle security advisory","uuid":"c09cb48b-881b-4b9f-8b9b-871d8d093e9c","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T12:40:16Z","date_created":"2021-12-22T12:40:16Z","summary":null,"body":["<article data-history-node-id=\"2882\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-650<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 10 December 2021 Oracle published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Oracle Security Alert Advisory (CVE-2021-44228)<br \/><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2021-44228.html\">https:\/\/www.oracle.com\/security-alerts\/alert-cve-2021-44228.html<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-4","alert_type":396,"serial_number":"AV21-650","subject":null,"moderation_state":"published","external_url":null},{"nid":2885,"title":"Ubuntu security advisory","uuid":"4b9d71a7-1ab4-4fa7-ae9c-4109cdfdb79d","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T12:52:17Z","date_created":"2021-12-22T12:52:17Z","summary":null,"body":["<article data-history-node-id=\"2885\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-33\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-651<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>Between 14 and 19 December 2021 Ubuntu published Security Notices to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a><\/p>\n\n<p>Ubuntu Log4Shell<br \/><a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/KnowledgeBase\/Log4Shell\">https:\/\/wiki.ubuntu.com\/SecurityTeam\/KnowledgeBase\/Log4Shell<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-33","alert_type":396,"serial_number":"AV21-651","subject":null,"moderation_state":"published","external_url":null},{"nid":2883,"title":"Palo Alto Networks security advisory","uuid":"5cc1c230-8729-4231-9782-a214525b857f","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T12:55:57Z","date_created":"2021-12-22T12:55:31Z","summary":null,"body":["<article data-history-node-id=\"2883\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-14\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-652<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 10 December 2021 Palo Alto Networks published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Palo Alto Networks Security Advisory (Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105)<br \/><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2021-44228\">https:\/\/security.paloaltonetworks.com\/CVE-2021-44228<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-14","alert_type":396,"serial_number":"AV21-652","subject":null,"moderation_state":"published","external_url":null},{"nid":2888,"title":"[Control systems] WECON security advisory ","uuid":"fbd1892f-8444-4a91-b7f9-4d0f28b7fa62","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T18:29:29Z","date_created":"2021-12-22T18:15:55Z","summary":null,"body":["<article data-history-node-id=\"2888\" about=\"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-653<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 21 December 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>LeviStudioU \u2013 version 2019-09-21 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-355-03)<\/p>\n\n<p><a href=\" https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-03<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wecon-security-advisory-4","alert_type":398,"serial_number":"AV21-653","subject":null,"moderation_state":"published","external_url":null},{"nid":2886,"title":" [Control systems] Emerson security advisory ","uuid":"52772b51-2ab4-4abd-8b11-8b0274e7fe9c","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T18:19:03Z","date_created":"2021-12-22T18:19:03Z","summary":null,"body":["<article data-history-node-id=\"2886\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-6\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-654<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 21 December 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DeltaV Distributed Control System Controllers and Workstations \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial-of-service and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-355-04)<\/p>\n\n<p><a href=\" https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-04\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-04<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-6","alert_type":398,"serial_number":"AV21-654","subject":null,"moderation_state":"published","external_url":null},{"nid":2887,"title":"[Control systems] Horner Automation security advisory","uuid":"efc21909-cf61-4a96-b7c6-bc71b089b93d","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T18:29:13Z","date_created":"2021-12-22T18:21:27Z","summary":null,"body":["<article data-history-node-id=\"2887\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-3\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-655<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 21 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Cscape EnvisionRV \u2013 version v4.50.3.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-355-02)<\/p>\n\n<p><a href=\" https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-02<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-3","alert_type":398,"serial_number":"AV21-655","subject":null,"moderation_state":"published","external_url":null},{"nid":2889,"title":"[Control systems] Siemens security advisory","uuid":"4b3622b6-6d41-4d4e-a916-93b68559ea21","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T20:28:10Z","date_created":"2021-12-22T20:28:10Z","summary":null,"body":["<article data-history-node-id=\"2889\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-38\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-656<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 20 December 2021 Siemens published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<ul><li>TraceAlertServerPLUS - all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations.<\/p>\n\n<p>Siemens Security Advisory (SSA-397453)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-397453.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-397453.pdf<\/a><\/p>\n\n<p>Siemens Apache Log4j Advisory (SSA-661247)<br \/><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-661247.pdf\">https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-661247.pdf<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-38","alert_type":398,"serial_number":"AV21-656","subject":null,"moderation_state":"published","external_url":null},{"nid":2890,"title":"Citrix security advisory","uuid":"6a8c16d1-2464-4852-8901-0f7aad65f9db","banner":null,"lang":"en","date_modified":"2021-12-22","date_modified_ts":"2021-12-22T20:31:01Z","date_created":"2021-12-22T20:31:01Z","summary":null,"body":["<article data-history-node-id=\"2890\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-657<br \/>\nDate: 22 December 2021<\/strong><\/p>\n\n<p>On 11 December 2021 Citrix published a Security Advisory to address critical vulnerabilities which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Citrix Security Advisory for CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105 (CTX335705)<br \/><a href=\"https:\/\/support.citrix.com\/article\/CTX335705\">https:\/\/support.citrix.com\/article\/CTX335705<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-18","alert_type":396,"serial_number":"AV21-657","subject":null,"moderation_state":"published","external_url":null},{"nid":2891,"title":"Apache security advisory","uuid":"8cd80720-fb8d-429d-bfc8-b5811fa9499f","banner":null,"lang":"en","date_modified":"2021-12-23","date_modified_ts":"2021-12-23T19:51:03Z","date_created":"2021-12-23T19:51:03Z","summary":null,"body":["<article data-history-node-id=\"2891\" about=\"\/en\/alerts-advisories\/apache-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-658<br \/>\nDate: 23 December 2021<\/strong><\/p>\n\n<p>On 20 December 2021 Apache published an update to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Apache HTTP Server - version 2.4.51 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Apache HTTP Server 2.4 vulnerabilities<br \/><a href=\"https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html \">https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html\u00a0<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-5","alert_type":396,"serial_number":"AV21-658","subject":null,"moderation_state":"published","external_url":null},{"nid":2892,"title":"[Control systems] Fresenius Kabi security advisory","uuid":"dc2819fb-65e8-46a4-b075-5430a71dde12","banner":null,"lang":"en","date_modified":"2021-12-23","date_modified_ts":"2021-12-23T19:54:27Z","date_created":"2021-12-23T19:54:27Z","summary":null,"body":["<article data-history-node-id=\"2892\" about=\"\/en\/alerts-advisories\/control-systems-fresenius-kabi-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-659<br \/>\nDate: 23 December 2021<\/strong><\/p>\n\n<p>On 21 December 2021 ICS\u2013CERT published an ICS Medical Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Agilia Connect WiFi module of pumps \u2013 pump versions vD25 and prior\u00a0\u00a0 \u00a0<\/li>\n\t<li>Agilia Link+ \u2013 version v3.0 D15 and prior<\/li>\n\t<li>Vigilant Software Suite (Vigilant Centerium, Vigilant MasterMed and Vigilant Insight) \u2013 version v1.0<\/li>\n\t<li>Agilia Partner maintenance software \u2013 version v3.3.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to gain access to sensitive information, modify settings or parameters, or perform arbitrary actions as an authenticated user.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Medical Advisory (ICSMA\u201321\u2013355\u201301)<br \/><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsma-21-355-01\">https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsma-21-355-01<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fresenius-kabi-security-advisory","alert_type":398,"serial_number":"AV21-659","subject":null,"moderation_state":"published","external_url":null},{"nid":2893,"title":"[Control systems] mySCADA security advisory","uuid":"b0506f55-f186-4e95-ad01-a98bf5e616d8","banner":null,"lang":"en","date_modified":"2021-12-23","date_modified_ts":"2021-12-23T20:21:12Z","date_created":"2021-12-23T19:58:38Z","summary":null,"body":["<article data-history-node-id=\"2893\" about=\"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-660<br \/>\nDate: 23 December 2021<\/strong><\/p>\n\n<p>On 21 December 2021 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>myPRO - versions 8.20.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in complete compromise of the product.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-355-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-355-01<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-1","alert_type":398,"serial_number":"AV21-660","subject":null,"moderation_state":"published","external_url":null},{"nid":2897,"title":"[Control systems] Moxa security advisory","uuid":"0d6ebfb3-61e3-42d5-be13-f3386fc191fe","banner":null,"lang":"en","date_modified":"2021-12-24","date_modified_ts":"2021-12-24T13:46:25Z","date_created":"2021-12-23T20:25:30Z","summary":null,"body":["<article data-history-node-id=\"2897\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-661<br \/>\nDate: 23 December 2021<\/strong><\/p>\n\n<p>On 23 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>MGate MB3180 Series - firmware version 2.2 and prior<\/li>\n\t<li>MGate MB3280 Series - firmware version 4.1 and prior<\/li>\n\t<li>MGate MB3480 Series - firmware version 3.2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSA-21-357-01)<br \/><a href=\" https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-357-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-357-01<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-5","alert_type":398,"serial_number":"AV21-661","subject":null,"moderation_state":"published","external_url":null},{"nid":2894,"title":"[Control systems] Exacq Technologies","uuid":"00d2a9d2-f234-4360-a945-e53651d7f671","banner":null,"lang":"en","date_modified":"2021-12-23","date_modified_ts":"2021-12-23T20:30:00Z","date_created":"2021-12-23T20:28:25Z","summary":null,"body":["<article data-history-node-id=\"2894\" about=\"\/en\/alerts-advisories\/control-systems-exacq-technologies\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-662<br \/>\nDate: 23 December 2021<\/strong><\/p>\n\n<p>On 23 December 2021 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Exacq Enterprise Manager - version 21.12 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-21-357-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-357-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-357-02<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-exacq-technologies","alert_type":398,"serial_number":"AV21-662","subject":null,"moderation_state":"published","external_url":null},{"nid":2898,"title":"IBM security advisory","uuid":"23038920-b483-44af-a663-c99296586c62","banner":null,"lang":"en","date_modified":"2021-12-29","date_modified_ts":"2021-12-29T15:32:11Z","date_created":"2021-12-29T15:32:11Z","summary":null,"body":["<article data-history-node-id=\"2898\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-79\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-663<br \/>\nDate: 29 December 2021<\/strong><\/p>\n\n<p>Between 20 and 28 December 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container \u2013 version 1.1-eus with Operator<\/li>\n\t<li>IBM Business Automation Workflow \u2013 versions 18.0, 19.0, 20.0 and 21.0<\/li>\n\t<li>IBM Business Monitor \u2013 versions 8.5.5, 8.5.6 and 8.5.7<\/li>\n\t<li>IBM Business Process Manager \u2013 versions 8.5 and 8.6<\/li>\n\t<li>IBM Event Streams \u2013 multiple versions<\/li>\n\t<li>IBM Rational ClearCase \u2013 multiple versions<\/li>\n\t<li>IBM Rational ClearQuest \u2013 versions 9.0, 9.0.1, 9.0.2 and 9.1<\/li>\n\t<li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p>IBM \u2013 Apache Log4j Vulnerability<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-79","alert_type":396,"serial_number":"AV21-663","subject":null,"moderation_state":"published","external_url":null},{"nid":2899,"title":"Fortinet security advisory","uuid":"585204db-7832-4cf4-a59c-2c11838eba62","banner":null,"lang":"en","date_modified":"2021-12-29","date_modified_ts":"2021-12-29T15:36:15Z","date_created":"2021-12-29T15:36:15Z","summary":null,"body":["<article data-history-node-id=\"2899\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-18\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV21-664<br \/>\nDate: 29 December 2021<\/strong><\/p>\n\n<p>On 12 December 2021 Fortinet published a PSIRT Advisory to investigate and address a critical vulnerability, tracked as CVE-2021-44228, which may affect multiple products using the Apache Log4j logging utility.<\/p>\n\n<p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p>Fortinet PSIRT Advisories<br \/><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-245\">https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-245<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-18","alert_type":396,"serial_number":"AV21-664","subject":null,"moderation_state":"published","external_url":null},{"nid":2901,"title":"IBM security advisory","uuid":"827c3a70-1784-4791-906d-cd0fd099c182","banner":null,"lang":"en","date_modified":"2022-01-04","date_modified_ts":"2022-01-04T16:13:33Z","date_created":"2022-01-04T16:13:33Z","summary":null,"body":["<article data-history-node-id=\"2901\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-80\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-001<br \/>\nDate: 4 January 2022<\/strong><\/p>\n\n<p>Between 29 December 2021 and 3 January 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p>IBM \u2013 Apache Log4j Vulnerability<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-80","alert_type":396,"serial_number":"AV22-001","subject":null,"moderation_state":"published","external_url":null},{"nid":2902,"title":" VMware security advisory","uuid":"e7be3c3b-509b-4aa4-99e7-aadc9ad672c2","banner":null,"lang":"en","date_modified":"2022-01-04","date_modified_ts":"2022-01-04T19:13:34Z","date_created":"2022-01-04T18:29:13Z","summary":null,"body":["<article data-history-node-id=\"2902\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-50\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-002<br \/>\nDate: 4 January 2022<\/strong><\/p>\n\n<p>On 4 January 2022 VMware published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>VMware ESXi \u2013 version 6.5, 6.7 and 7.0<\/li>\n\t<li>VMware Workstation \u2013 version 16.x<\/li>\n\t<li>VMware Fusion \u2013 version 12.x<\/li>\n\t<li>VMware Cloud Foundation \u2013 version 3.x and 4.x<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p>VMware Security Advisory (VMSA-2022-0001)<br \/><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0001.html\">https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0001.html<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-50","alert_type":396,"serial_number":"AV22-002","subject":null,"moderation_state":"published","external_url":null},{"nid":2903,"title":"Android security advisory \u2013 January 2022 monthly rollup","uuid":"db12b608-1590-49ab-b2c3-35c3c93bf702","banner":null,"lang":"en","date_modified":"2022-01-05","date_modified_ts":"2022-01-05T12:14:34Z","date_created":"2022-01-05T12:09:05Z","summary":null,"body":["<article data-history-node-id=\"2903\" about=\"\/en\/alerts-advisories\/android-security-advisory-january-2022-monthly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-003<br \/>\nDate: 5 January 2022<\/strong><\/p>\n\n<p>On 4 January 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Android Security Bulletin<br \/><a href=\"https:\/\/source.android.com\/security\/bulletin\/2022-01-01\">https:\/\/source.android.com\/security\/bulletin\/2022-01-01<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-january-2022-monthly-rollup","alert_type":396,"serial_number":"AV22-003","subject":null,"moderation_state":"published","external_url":null},{"nid":2904,"title":"Google Chrome security advisory","uuid":"d2b83462-0d46-41d1-98d2-2d326b55f64b","banner":null,"lang":"en","date_modified":"2022-01-05","date_modified_ts":"2022-01-05T14:41:21Z","date_created":"2022-01-05T14:41:21Z","summary":null,"body":["<article data-history-node-id=\"2904\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-75\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-004<br \/>\nDate: 5 January 2022<\/strong><\/p>\n\n<p>On 4 January 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 97.0.4692.71<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p>Google Chrome Security Advisory<br \/><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/01\/stable-channel-update-for-desktop.html\">https:\/\/chromereleases.googleblog.com\/2022\/01\/stable-channel-update-for-desktop.html<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-75","alert_type":396,"serial_number":"AV22-004","subject":null,"moderation_state":"published","external_url":null},{"nid":2905,"title":"Ubuntu security advisory","uuid":"f6a55b41-ad7f-4f59-9bf6-c2d54eff4914","banner":null,"lang":"en","date_modified":"2022-01-06","date_modified_ts":"2022-01-06T18:34:55Z","date_created":"2022-01-06T18:34:55Z","summary":null,"body":["<article data-history-node-id=\"2905\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-34\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-005<br \/>\nDate: 6 January 2022<\/strong><\/p>\n\n<p>On 6 January 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service or lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p>Ubuntu Security Notices<br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\">https:\/\/ubuntu.com\/security\/notices<\/a> \u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-34","alert_type":396,"serial_number":"AV22-005","subject":null,"moderation_state":"published","external_url":null},{"nid":2906,"title":"[Control systems] Philips security advisory","uuid":"fd8e83d5-54f8-46a6-a70b-f8302c8106b2","banner":null,"lang":"en","date_modified":"2022-01-06","date_modified_ts":"2022-01-06T18:52:10Z","date_created":"2022-01-06T18:52:10Z","summary":null,"body":["<article data-history-node-id=\"2906\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-15\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-006<br \/>\nDate: 6 January 2022<\/strong><\/p>\n\n<p>On 6 January 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Engage Software - version 6.2.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p>ICS Advisory (ICSMA-22-006-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-006-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-006-01<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-15","alert_type":398,"serial_number":"AV22-006","subject":null,"moderation_state":"published","external_url":null},{"nid":2907,"title":"[Control systems] Omron security advisory","uuid":"3fd8fefb-e6eb-4135-9019-e100b2240afc","banner":null,"lang":"en","date_modified":"2022-01-06","date_modified_ts":"2022-01-06T18:54:26Z","date_created":"2022-01-06T18:54:26Z","summary":null,"body":["<article data-history-node-id=\"2907\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-4\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-007<br \/>\nDate: 6 January 2022<\/strong><\/p>\n\n<p>On 6 January 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CX-One - version 4.60 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-22-006-01)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-006-01\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-006-01<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-4","alert_type":398,"serial_number":"AV22-007","subject":null,"moderation_state":"published","external_url":null},{"nid":2908,"title":"[Control systems] Fernhill Software, Ltd. security advisory","uuid":"5b63ba7e-521d-418c-ab22-be29b72e5bea","banner":null,"lang":"en","date_modified":"2022-01-06","date_modified_ts":"2022-01-06T18:57:12Z","date_created":"2022-01-06T18:57:12Z","summary":null,"body":["<article data-history-node-id=\"2908\" about=\"\/en\/alerts-advisories\/control-systems-fernhill-software-ltd-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-008<br \/>\nDate: 6 January 2022<\/strong><\/p>\n\n<p>On 6 January 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Fernhill SCADA Server - version 3.77 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-22-006-02)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-006-02\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-006-02<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fernhill-software-ltd-security-advisory","alert_type":398,"serial_number":"AV22-008","subject":null,"moderation_state":"published","external_url":null},{"nid":2909,"title":"[Control systems] IDEC security advisory","uuid":"d164f995-5e4e-4b29-9640-5be7c8a8ae04","banner":null,"lang":"en","date_modified":"2022-01-06","date_modified_ts":"2022-01-06T20:15:23Z","date_created":"2022-01-06T20:15:23Z","summary":null,"body":["<article data-history-node-id=\"2909\" about=\"\/en\/alerts-advisories\/control-systems-idec-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-009<br \/>\nDate: 6 January 2022<\/strong><\/p>\n\n<p>On 6 January 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>FC6A MICROSmart All-in-One CPU Module \u2013 version 2.32 and prior<\/li>\n\t<li>FC6B MICROSmart All-in-One CPU Module \u2013 version 2.31 and prior<\/li>\n\t<li>FC6A MICROSmart Plus CPU Module \u2013 version 1.91 and prior<\/li>\n\t<li>FC6B MICROSmart Plus CPU Module \u2013 version 2.31 and prior<\/li>\n\t<li>FT1A Controller SmartAXIS Pro\/Lite \u2013 version 2.31 and prior<\/li>\n\t<li>WindLDR \u2013 version 8.19.1 and prior<\/li>\n\t<li>WindEDIT Lite \u2013 version 1.3.1 and prior<\/li>\n\t<li>Data File Manager \u2013 version 2.12.1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to obtain credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p>ICS Advisory (ICSA-22-006-03)<br \/><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-006-03\">https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-006-03<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-idec-security-advisory","alert_type":398,"serial_number":"AV22-009","subject":null,"moderation_state":"published","external_url":null},{"nid":2910,"title":"Microsoft Edge security advisory","uuid":"7088d622-0be3-43aa-a0bc-3e0476beaa7b","banner":null,"lang":"en","date_modified":"2022-01-07","date_modified_ts":"2022-01-07T18:38:34Z","date_created":"2022-01-07T18:38:34Z","summary":null,"body":["<article data-history-node-id=\"2910\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-010<br \/>\nDate: 7 January 2022<\/strong><\/p>\n\n<p>On 6 January 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 97.0.1072.55<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft Edge Stable Channel Release Notes<br \/><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-6-2022\">https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-6-2022<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-0","alert_type":396,"serial_number":"AV22-010","subject":null,"moderation_state":"published","external_url":null},{"nid":2911,"title":"HPE security advisory","uuid":"814e20df-cb73-4a04-81cc-0b795ed32405","banner":null,"lang":"en","date_modified":"2022-01-07","date_modified_ts":"2022-01-07T20:14:41Z","date_created":"2022-01-07T20:14:41Z","summary":null,"body":["<article data-history-node-id=\"2911\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-32\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-011<br \/>\nDate: 7 January 2022<\/strong><\/p>\n\n<p>On 7 January 2022 HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Edgeline EL300 Converged Edge System \u2013 versions prior to v1.50<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in arbitrary code execution, unauthorized data access and memory corruption.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>HP Security Bulletin (HPESBGN04214EN_US)<br \/><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04214en_us\">https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04214en_us<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-32","alert_type":396,"serial_number":"AV22-011","subject":null,"moderation_state":"published","external_url":null},{"nid":2912,"title":"IBM security advisory","uuid":"5efd5665-3f44-4d32-804d-2f66b323fcfc","banner":null,"lang":"en","date_modified":"2022-01-10","date_modified_ts":"2022-01-10T15:39:09Z","date_created":"2022-01-10T15:39:09Z","summary":null,"body":["<article data-history-node-id=\"2912\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-81\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-012<br \/>\nDate: 10 January 2022<\/strong><\/p>\n\n<p>Between 4 and 9 January 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p>IBM \u2013 Apache Log4j Vulnerability<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/<\/a><\/p>\n\n<p>IBM Product Security Incident Response<br \/><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">https:\/\/www.ibm.com\/blogs\/psirt\/<\/a><\/p>\n\n<p>Active Exploitation of Apache Log4j Vulnerability (AL21-019)<br \/><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-81","alert_type":396,"serial_number":"AV22-012","subject":null,"moderation_state":"published","external_url":null},{"nid":2913,"title":"HPE security advisory (AV22-013)","uuid":"09d49aab-7d7d-4bf6-8bc5-6e9674458061","banner":null,"lang":"en","date_modified":"2022-01-11","date_modified_ts":"2022-01-11T19:22:04Z","date_created":"2022-01-11T16:16:34Z","summary":null,"body":["<article data-history-node-id=\"2913\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-013\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-013<br \/>\nDate: 11 January 2022<\/strong><\/p>\n\n<p>On 10 January 2022 HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HP-UX 11.31 PHNE_42509 \u2013 telnetd Patch 11.31<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04206en_us\">HP Security Bulletin (HPESBUX04206EN_US)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-013","alert_type":396,"serial_number":"AV22-013","subject":null,"moderation_state":"published","external_url":null},{"nid":2914,"title":"SAP security advisory \u2013 January 2022 monthly rollup (AV22-014)","uuid":"5c9150d2-039d-4062-b6c6-17f721899a99","banner":null,"lang":"en","date_modified":"2022-01-11","date_modified_ts":"2022-01-11T20:04:06Z","date_created":"2022-01-11T20:04:06Z","summary":null,"body":["<article data-history-node-id=\"2914\" about=\"\/en\/alerts-advisories\/sap-security-advisory-january-2022-monthly-rollup-av22-014\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-014<br \/>\nDate: 11 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Customer Checkout<\/li>\n\t<li>SAP BTP Cloud Foundry<\/li>\n\t<li>SAP Landscape Management<\/li>\n\t<li>SAP Connected Health Platform 2.0 - Fhirserver<\/li>\n\t<li>SAP HANA XS Advanced Cockpit<\/li>\n\t<li>SAP NetWeaver Process Integration (Java Web Service Adapter)<\/li>\n\t<li>SAP HANA XS Advanced<\/li>\n\t<li>Internet of Things Edge Platform<\/li>\n\t<li>SAP BTP Kyma<\/li>\n\t<li>SAP Enable Now Manager<\/li>\n\t<li>SAP Cloud for Customer (add-in for Lotus notes client)<\/li>\n\t<li>SAP Localization Hub, digital compliance service for India<\/li>\n\t<li>SAP Edge Services On Premise Edition<\/li>\n\t<li>SAP Edge Services Cloud Edition<\/li>\n\t<li>SAP BTP API Management (Tenant Cloning Tool)<\/li>\n\t<li>SAP NetWeaver ABAP Server and ABAP Platform (Adobe LiveCycle Designer 11.0)<\/li>\n\t<li>SAP Digital Manufacturing Cloud for Edge Computing<\/li>\n\t<li>SAP Enterprise Continuous Testing by Tricentis<\/li>\n\t<li>SAP Cloud-to-Cloud Interoperability<\/li>\n\t<li>Reference Template for enabling ingestion and persistence of time series data in Azure<\/li>\n\t<li>SAP Business One<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\u00a0<\/p>\n\n<p><a href=\"https:\/\/wiki.scn.sap.com\/wiki\/pages\/viewpage.action?pageId=596902035\">SAP Security Patch Day \u2013 January 2022<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-january-2022-monthly-rollup-av22-014","alert_type":396,"serial_number":"AV22-014","subject":null,"moderation_state":"published","external_url":null},{"nid":2915,"title":"Microsoft security advisory \u2013 January 2022 monthly rollup (AV22-015)","uuid":"d6079509-d40c-41ac-a370-d842b4acdbcb","banner":null,"lang":"en","date_modified":"2022-01-12","date_modified_ts":"2022-01-12T14:11:36Z","date_created":"2022-01-12T14:11:36Z","summary":null,"body":["<article data-history-node-id=\"2915\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2022-monthly-rollup-av22-015\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-015<br \/>\nDate: 12 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>HEVC Video Extensions<\/li>\n\t<li>Microsoft Exchange Server 2013 CU23, 2016 CU21 and CU22, 2019 CU10 and CU11<\/li>\n\t<li>Microsoft Office \u2013 multiple applications and versions<\/li>\n\t<li>Microsoft SharePoint<\/li>\n\t<li>Windows 7, 8.1, RT 8.1, 10 and 11<\/li>\n\t<li>Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019 and 2022 \u00a0<\/li>\n\t<li>Windows Server Core 2008, 2012, 2012 R2, 2016, 2019, 2022 and 20H2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Jan\">January 2022 Release Notes<\/a><\/p>\n\n<p><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\">Security Update Guide<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-january-2022-monthly-rollup-av22-015","alert_type":396,"serial_number":"AV22-015","subject":null,"moderation_state":"published","external_url":null},{"nid":2916,"title":"[Control systems] Sensormatic Electronics security advisory (AV22-016)","uuid":"c731deff-46d2-48a0-a197-b186a879ab5b","banner":null,"lang":"en","date_modified":"2022-01-12","date_modified_ts":"2022-01-12T17:45:39Z","date_created":"2022-01-12T17:45:39Z","summary":null,"body":["<article data-history-node-id=\"2916\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av22-016\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-016<br \/>\nDate: 12 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>VideoEdge \u2013 versions 5.4.1 to 5.7.1 \u00a0<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-011-01\">ICS Advisory (ICSA-22-011-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av22-016","alert_type":398,"serial_number":"AV22-016","subject":null,"moderation_state":"published","external_url":null},{"nid":2917,"title":"Adobe security advisory (AV22-017)","uuid":"9c620ec8-99e9-4833-8636-f0b5ab1874f1","banner":null,"lang":"en","date_modified":"2022-01-12","date_modified_ts":"2022-01-12T19:38:37Z","date_created":"2022-01-12T19:30:46Z","summary":null,"body":["<article data-history-node-id=\"2917\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-017\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-017<br \/>\nDate: 12 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 Adobe published Security Bulletins to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Adobe Acrobat and Reader \u2013 multiple versions and platforms<\/li>\n\t<li>Adobe Bridge \u2013 multiple versions and platforms<\/li>\n\t<li>Adobe Illustrator \u2013 multiple versions and platforms<\/li>\n\t<li>Adobe InCopy \u2013 version 16.4 and prior for Windows and macOS<\/li>\n\t<li>Adobe InDesign \u2013 version 16.4 and prior for Windows and macOS<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution, privilege escalation, denial of service and security feature bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb22-01.html\">Adobe Acrobat and Reader<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb22-03.html\">Adobe Bridge<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/illustrator\/apsb22-02.html\">Adobe Illustrator<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/incopy\/apsb22-04.html\">Adobe InCopy<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb22-05.html \">Adobe InDesign<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-017","alert_type":396,"serial_number":"AV22-017","subject":null,"moderation_state":"published","external_url":null},{"nid":2918,"title":"Mozilla security advisory (AV22-018)","uuid":"2813a2b7-a083-4ddf-bed2-fc9b3eb40836","banner":null,"lang":"en","date_modified":"2022-01-12","date_modified_ts":"2022-01-12T20:48:49Z","date_created":"2022-01-12T20:40:35Z","summary":null,"body":["<article data-history-node-id=\"2918\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-018\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-018<br \/>\nDate: 12 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 96<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.5<\/li>\n\t<li>Thunderbird \u2013 versions prior to 91.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-01\/\">Firefox (MFSA 2022-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-02\/\">Firefox ESR (MFSA 2022-02)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-03\/\">Thunderbird (MFSA 2022-03)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-018","alert_type":396,"serial_number":"AV22-018","subject":null,"moderation_state":"published","external_url":null},{"nid":2919,"title":"Cisco security advisory (AV22-019)","uuid":"bf528b6e-3ad8-4f4c-a8a4-4567f009e4a7","banner":null,"lang":"en","date_modified":"2022-01-13","date_modified_ts":"2022-01-13T13:19:04Z","date_created":"2022-01-13T13:17:08Z","summary":null,"body":["<article data-history-node-id=\"2919\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-019\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-019<br \/>\nDate: 13 January 2022<\/strong><\/p>\n\n<p>On 12 January 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco Unified Contact Center Domain Manager \u2013 multiple versions<\/li>\n\t<li>Cisco Unified Contact Center Management Portal \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation could allow for privilege elevation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ccmp-priv-esc-JzhTFLm4\">Cisco Unified CCDM\/CCMP Advisory<\/a><\/p>\n\n<p><a href=\" https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-019","alert_type":396,"serial_number":"AV22-019","subject":null,"moderation_state":"published","external_url":null},{"nid":2920,"title":"Apple security advisory (AV22-020)","uuid":"db584390-1d3d-440a-88ea-ac7f5ded113a","banner":null,"lang":"en","date_modified":"2022-01-13","date_modified_ts":"2022-01-13T13:24:52Z","date_created":"2022-01-13T13:22:11Z","summary":null,"body":["<article data-history-node-id=\"2920\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-020\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p>Number: AV22-020<br \/>\nDate: 13 January 2022<\/p>\n\n<p>On 12 January 2022 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15.2.1<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.2.1<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-020","alert_type":396,"serial_number":"AV22-020","subject":null,"moderation_state":"published","external_url":null},{"nid":2921,"title":"Palo Alto Networks security advisory (AV22-021)","uuid":"b66de6dc-214e-4614-9c76-282d825e4924","banner":null,"lang":"en","date_modified":"2022-01-13","date_modified_ts":"2022-01-13T14:38:11Z","date_created":"2022-01-13T14:35:59Z","summary":null,"body":["<article data-history-node-id=\"2921\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-021\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-021<br \/>\nDate: 13 January 2022<\/strong><\/p>\n\n<p>On 12 January 2022 Palo Alto Networks published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cortex XDR Agent \u2013 versions prior to 5.0.12 and 6.1.9<\/li>\n<\/ul><p>Exploitation could allow for privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2022-0015\">Cortex XDR Agent Advisory<\/a><\/p>\n\n<p><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Networks Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-021","alert_type":396,"serial_number":"AV22-021","subject":null,"moderation_state":"published","external_url":null},{"nid":2922,"title":"[Control systems] Siemens security advisory (AV22-022)","uuid":"163996fb-724a-4a97-a0c2-1aef5cca0248","banner":null,"lang":"en","date_modified":"2022-01-13","date_modified_ts":"2022-01-13T16:12:13Z","date_created":"2022-01-13T16:12:13Z","summary":null,"body":["<article data-history-node-id=\"2922\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-022\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-022<br \/>\nDate: 13 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>COMOS \u2013 versions prior to 10.4.1<\/li>\n\t<li>PLUSCONTROL 1st Generation \u2013 all versions<\/li>\n\t<li>SICAM A8000 \u2013 multiple models, versions prior to 16.20<\/li>\n\t<li>SICAM PQ Analyzer \u2013 versions prior to 3.18<\/li>\n\t<li>SIPROTEC 5 \u2013 multiple models, versions prior to 8.83<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial-of-service, disclosure of sensitive information, privilege escalation and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Publications<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-022","alert_type":398,"serial_number":"AV22-022","subject":null,"moderation_state":"published","external_url":null},{"nid":2923,"title":"Citrix security advisory (AV22-023)","uuid":"1beb69d0-f2e2-425b-91f8-187edad19dff","banner":null,"lang":"en","date_modified":"2022-01-13","date_modified_ts":"2022-01-13T19:11:27Z","date_created":"2022-01-13T19:10:11Z","summary":null,"body":["<article data-history-node-id=\"2923\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-023\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-023<br \/>\nDate: 13 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 Citrix published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Citrix Workspace App for Linux \u2013 versions 2012 to 2111 (with App Protection installed)<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX338435\">Citrix Workspace App for Linux Security Bulletin<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-023","alert_type":396,"serial_number":"AV22-023","subject":null,"moderation_state":"published","external_url":null},{"nid":2924,"title":"Ubuntu security advisory (AV22-024)","uuid":"3ec07dcc-57cb-4e21-96ed-bd37e5aacb5e","banner":null,"lang":"en","date_modified":"2022-01-13","date_modified_ts":"2022-01-13T20:37:16Z","date_created":"2022-01-13T20:37:16Z","summary":null,"body":["<article data-history-node-id=\"2924\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-024\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-024<br \/>\nDate: 13 January 2022<\/strong><\/p>\n\n<p>On 11 and 12 January 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could expose sensitive information, cause a denial of service, lead to arbitrary code execution or could lead to unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-024","alert_type":396,"serial_number":"AV22-024","subject":null,"moderation_state":"published","external_url":null},{"nid":2925,"title":"[Control systems] Schneider Electric security advisory (AV22-025)","uuid":"009044f5-be3e-4ed3-bf42-e3952cd57e7e","banner":null,"lang":"en","date_modified":"2022-01-14","date_modified_ts":"2022-01-14T14:17:04Z","date_created":"2022-01-14T14:11:22Z","summary":null,"body":["<article data-history-node-id=\"2925\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-025\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-025<br \/>\nDate: 14 January 2022<\/strong><\/p>\n\n<p>On 11 January 2022 Schneider Electric published Security Notifications to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Modicon M340 \u2013 multiple models and versions<\/li>\n\t<li>Easergy products \u2013 multiple models and firmware versions<\/li>\n\t<li>ConneXium Tofino Firewall - multiple models and versions<\/li>\n\t<li>CODESYS V3 Runtime, Development System and Gateway \u2013 multiple products and versions<\/li>\n\t<li>EcoStruxure Power Monitoring Expert \u2013 version 2020 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access, arbitrary code execution, denial of service, information disclosure, data modification and credential disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Cybersecurity Support Portal<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-025","alert_type":398,"serial_number":"AV22-025","subject":null,"moderation_state":"published","external_url":null},{"nid":2926,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-026)","uuid":"1d9233e4-74ca-4610-a466-e11d8cec59d6","banner":null,"lang":"en","date_modified":"2022-01-14","date_modified_ts":"2022-01-14T18:46:01Z","date_created":"2022-01-14T18:46:01Z","summary":null,"body":["<article data-history-node-id=\"2926\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-026\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-026<br \/>\nDate: 14 January 2022<\/strong><\/p>\n\n<p>On 13 January 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>FX3U-ENET \u2013 firmware version 1.16 and prior<\/li>\n\t<li>FX3U-ENET-L \u2013 firmware version 1.16 and prior<\/li>\n\t<li>FX3U-ENET-P502 \u2013 firmware version 1.16 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-013-01\">ICS Advisory (ICSA-22-013-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-013-07 \">ICS Advisory (ICSA-22-013-07)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-026","alert_type":398,"serial_number":"AV22-026","subject":null,"moderation_state":"published","external_url":null},{"nid":2927,"title":"Juniper Networks security advisory (AV22-027)","uuid":"e4bc26af-050a-4058-a2b5-a699db33392c","banner":null,"lang":"en","date_modified":"2022-01-14","date_modified_ts":"2022-01-14T20:22:47Z","date_created":"2022-01-14T20:22:47Z","summary":null,"body":["<article data-history-node-id=\"2927\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-027\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-027<br \/>\nDate: 14 January 2022<\/strong><\/p>\n\n<p>On 12 January 2022 Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Contrail Cloud \u2013 versions prior to 13.6.0<\/li>\n\t<li>Contrail Networking \u2013 versions prior to 2011<\/li>\n\t<li>Junos OS \u2013 versions prior to 21.3R2<\/li>\n\t<li>Junos Space \u2013 versions prior to 21.3R1<\/li>\n\t<li>Steel Belted Radius Carrier Edition \u2013 versions prior to 8.6.0R15 for 64-bit Solaris<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">Juniper Networks Security Advisories<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-027","alert_type":396,"serial_number":"AV22-027","subject":null,"moderation_state":"published","external_url":null},{"nid":2929,"title":"Wiper malware targeting Ukrainian organizations","uuid":"91e2e7bc-54ac-4509-a94c-2f6b2702ff5d","banner":null,"lang":"en","date_modified":"2022-01-17","date_modified_ts":"2022-01-17T21:22:25Z","date_created":"2022-01-17T19:21:51Z","summary":null,"body":["<article data-history-node-id=\"2929\" about=\"\/en\/alerts-advisories\/wiper-malware-targeting-ukrainian-organizations\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL22-001<br \/><strong>Date: <\/strong>January 17, 2022\u00a0 \u00a0<br \/><!--<strong>Updated:&nbsp;<\/strong>December 17, 2022--><\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>Microsoft Threat Intelligence Center (MSTIC) published a blog post detailing a malware campaign targeting multiple Ukrainian organisations <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 15 January 2022, MSTIC published a blog post highlighting a malware campaign targeting Ukrainian organisations in various sectors. The United States Cybersecurity &amp; Infrastructure Security Agency (CISA) amplified this publication on 16 January 2022<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">\u00a0 <\/span>2<\/a><\/sup> .<\/p>\n\n<p>MSTIC indicates that initial evidence of this campaign surfaced on victim systems in Ukraine on January 13, 2022. Affected sectors currently include government, non-profit, and information technology, with the possibility of more organisations and sectors being affected as the situation evolves. Microsoft states, \u201cMSTIC is not able to assess intent of the identified destructive actions but does believe these actions represent an elevated risk to any government agency, non-profit or enterprise located or with systems in Ukraine.\u201d <sup id=\"fn1-rf-2\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">ootnote <\/span>1<\/a><\/sup><\/p>\n\n<p>The malware being delivered purports to be ransomware, as a ransom note is provided, but there is no mechanism for recovery and targeted devices are inoperable after infection. The malware overwrites the contents of the master boot record (MBR), a small portion of the hard drive that tells the computer how to load its operating system when the computer is powered on. In addition, second-stage malware downloads and executes malicious code designed to overwrite files containing specific file extensions (see MSTICs blog<sup id=\"fn1-rf-3\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> for a list of 189 file extensions so far).<\/p>\n\n<p>The MSTIC blog post also provides indicators of compromise and other recommended actions for system owners and operators responsible for defending their systems and networks from cyber threats. Microsoft advises monitoring their blog post as it will be updated if the situation evolves.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/01\/15\/destructive-malware-targeting-ukrainian-organizations\/\">Destructive malware targeting Ukrainian organizations<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/01\/16\/microsoft-warns-destructive-malware-targeting-ukrainian\">Microsoft Warns of Destructive Malware Targeting Ukrainian Organizations<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wiper-malware-targeting-ukrainian-organizations","alert_type":397,"serial_number":"AL22-001","subject":null,"moderation_state":"published","external_url":null},{"nid":2928,"title":"IBM security advisory (AV22-028)","uuid":"9628466f-663f-4fc7-a2b9-9e02a8665ebf","banner":null,"lang":"en","date_modified":"2022-01-17","date_modified_ts":"2022-01-17T19:33:17Z","date_created":"2022-01-17T19:33:17Z","summary":null,"body":["<article data-history-node-id=\"2928\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-028\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-028<br \/>\nDate: 17 January 2022<\/strong><\/p>\n\n<p>Between 10 and 16 January 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Data Risk Manager \u2013 version 2.0.6<\/li>\n\t<li>IBM HTTP Server \u2013 version 9.0<\/li>\n\t<li>IBM Planning Analytics \u2013 version 2.0<\/li>\n\t<li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n\t<li>IBM Cloud Transformation Advisor \u2013 version 2.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-028","alert_type":396,"serial_number":"AV22-028","subject":null,"moderation_state":"published","external_url":null},{"nid":2930,"title":"F5 security advisory (AV22-029)","uuid":"0e6db91e-9d81-4a0d-b265-406ed95c9f1d","banner":null,"lang":"en","date_modified":"2022-01-19","date_modified_ts":"2022-01-19T15:56:24Z","date_created":"2022-01-19T15:52:40Z","summary":null,"body":["<article data-history-node-id=\"2930\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-029\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-029<br \/>\nDate: 19 January 2022<\/strong><\/p>\n\n<p>On 19 January 2022, F5 published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG IP \u2013 multiple versions and platforms<\/li>\n\t<li>BIG IQ \u2013 multiple versions and platforms<\/li>\n\t<li>NGINX Controller API Management \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities may cause a denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K40084114\">Overview of F5 vulnerabilities (January 2022)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-029","alert_type":396,"serial_number":"AV22-029","subject":null,"moderation_state":"published","external_url":null},{"nid":2931,"title":"Oracle security advisory \u2013 January 2022 quarterly rollup (AV22-030)","uuid":"96a77c27-21e9-4b7f-9994-d4f1ceb8d191","banner":null,"lang":"en","date_modified":"2022-01-19","date_modified_ts":"2022-01-19T19:31:58Z","date_created":"2022-01-19T19:31:58Z","summary":null,"body":["<article data-history-node-id=\"2931\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-january-2022-quarterly-rollup-av22-030\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-030<br \/>\nDate: 19 January 2022<\/strong><\/p>\n\n<p>On 18 January 2022 Oracle published a Critical Patch Update Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Enterprise Manager Ops Center \u2013 version 12.4.0.0<\/li>\n\t<li>Instantis EnterpriseTrack \u2013 versions 17.1, 17.2 and 17.3<\/li>\n\t<li>Oracle Access Manager \u2013 versions 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle Banking APIs \u2013 versions 18.1 to 18.3, 19.1, 19.2, 20.1 and 21.1<\/li>\n\t<li>Oracle Banking Digital Experience \u2013 versions 18.1 to 18.3, 19.1, 19.2, 20.1 and 21.1<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition \u2013 versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle Communications Billing and Revenue Management \u2013 versions 12.0.0.3 and 12.0.0.4<\/li>\n\t<li>Oracle Communications Cloud Native Core Policy \u2013 version 1.14.0<\/li>\n\t<li>Oracle Communications EAGLE Application Processor \u2013 versions 16.1 to 16.4<\/li>\n\t<li>Oracle Essbase \u2013 versions prior to 11.1.2.4.047 and 21.3<\/li>\n\t<li>Oracle Essbase Administration Services \u2013 versions prior to 11.1.2.4.047<\/li>\n\t<li>Oracle GoldenGate \u2013 versions prior to 21.4.0.0.0<\/li>\n\t<li>Oracle HTTP Server \u2013 versions 12.2.1.3.0, 12.2.1.4.0 and 12.2.1.5.0<\/li>\n\t<li>Oracle Insurance Policy Administration J2EE \u2013 versions 10.2.0, 10.2.4, 11.0.2 and 11.1.0 to 11.3.0<\/li>\n\t<li>Oracle Insurance Rules Palette \u2013 versions 10.2.0, 10.2.4, 11.0.2 and 11.1.0 to 11.3.0<\/li>\n\t<li>Oracle Secure Backup \u2013 versions prior to 18.1.0.1.0<\/li>\n\t<li>Oracle Utilities Framework \u2013 versions 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 to 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0 and 4.4.0.3.0<\/li>\n\t<li>Oracle WebLogic Server \u2013 versions 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n\t<li>OSS Support Tools \u2013 versions prior to 2.12.42<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools \u2013 versions 8.57, 8.58 and 8.59<\/li>\n\t<li>Primavera Unifier \u2013 versions 17.7 to 17.12, 18.8, 19.12, 20.12 and 21.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2022.html\">Oracle Critical Patch Update Advisory \u2013 January 2022<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-january-2022-quarterly-rollup-av22-030","alert_type":396,"serial_number":"AV22-030","subject":null,"moderation_state":"published","external_url":null},{"nid":2932,"title":"Dell security advisory (AV22-031)","uuid":"1cee6f36-43aa-47d2-9f53-4eb3e208549c","banner":null,"lang":"en","date_modified":"2022-01-19","date_modified_ts":"2022-01-19T19:39:47Z","date_created":"2022-01-19T19:39:47Z","summary":null,"body":["<article data-history-node-id=\"2932\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-031\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-031<br \/>\nDate: 19 January 2022<\/strong><\/p>\n\n<p>On 19 January 2022 Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC AppSync \u2013 versions prior to 4.4.0.0<\/li>\n\t<li>Dell EMC NetWorker \u2013 versions 19.1.x, 19.2.x, 19.3.x, 19.4.x and 19.5.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-031","alert_type":396,"serial_number":"AV22-031","subject":null,"moderation_state":"published","external_url":null},{"nid":2933,"title":"Cisco security advisory (AV22-032)","uuid":"e57f50e5-1425-4e3e-8130-79e421c6d28e","banner":null,"lang":"en","date_modified":"2022-01-19","date_modified_ts":"2022-01-19T20:52:06Z","date_created":"2022-01-19T20:52:06Z","summary":null,"body":["<article data-history-node-id=\"2933\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-032\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-032<br \/>\nDate: 19 January 2022<\/strong><\/p>\n\n<p>On 19 January 2022 Cisco published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Carrier Packet Transport \u2013 all versions<\/li>\n\t<li>Cisco RCM for Cisco StarOS \u2013 versions prior to 21.25.4<\/li>\n\t<li>Cisco Snort \u2013 versions prior to 2.9.18 and 3.1.0.100<\/li>\n\t<li>ConfD \u2013 multiple versions<\/li>\n\t<li>Cybervision \u2013 versions prior to 4.0.2<\/li>\n\t<li>Enterprise NFV Infrastructure Software \u2013 versions prior to 3.12.1<\/li>\n\t<li>Firepower Threat Defense \u2013 multiple versions<\/li>\n\t<li>IOS XE SD-WAN \u2013 multiple versions<\/li>\n\t<li>IOS XR Software \u2013 multiple versions<\/li>\n\t<li>Meraki MX \u2013 multiple versions<\/li>\n\t<li>Network Convergence System \u2013 multiple versions and platforms<\/li>\n\t<li>Network Service Orchestrator \u2013 multiple versions<\/li>\n\t<li>SD-WAN \u2013 multiple versions and platforms<\/li>\n\t<li>Ultra Gateway Platform \u2013 versions prior to 6.15.0<\/li>\n\t<li>Unified Threat Defense \u2013 multiple versions<\/li>\n\t<li>Virtual Topology System \u2013 versions prior to 2.6.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-032","alert_type":396,"serial_number":"AV22-032","subject":null,"moderation_state":"published","external_url":null},{"nid":2936,"title":"Ubuntu security advisory (AV22-033)","uuid":"2e8d00ef-7788-4155-90d6-ed90f39a4ece","banner":null,"lang":"en","date_modified":"2022-01-20","date_modified_ts":"2022-01-20T16:25:56Z","date_created":"2022-01-20T15:55:16Z","summary":null,"body":["<article data-history-node-id=\"2936\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-033\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-033<br \/>\nDate: 20 January 2022<\/strong><\/p>\n\n<p>On 19 January 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 21.04<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could cause a denial of service or lead to the execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5240-1\">Ubuntu Security Notice (USN-5240-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-033","alert_type":396,"serial_number":"AV22-033","subject":null,"moderation_state":"published","external_url":null},{"nid":2935,"title":"Google Chrome security advisory (AV22-034)","uuid":"458fec96-d5b3-436f-b359-b50a30dc2712","banner":null,"lang":"en","date_modified":"2022-01-20","date_modified_ts":"2022-01-20T16:25:37Z","date_created":"2022-01-20T15:59:20Z","summary":null,"body":["<article data-history-node-id=\"2935\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-034\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-034<br \/>\nDate: 20 January 2022<\/strong><\/p>\n\n<p>On 19 January 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 97.0.4692.99 and 96.0.4664.110<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/01\/stable-channel-update-for-desktop_19.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-034","alert_type":396,"serial_number":"AV22-034","subject":null,"moderation_state":"published","external_url":null},{"nid":2934,"title":"Red Hat security advisory (AV22-035)","uuid":"d606fc91-184d-4437-b3b3-2192b59dbf7e","banner":null,"lang":"en","date_modified":"2022-01-20","date_modified_ts":"2022-01-20T16:25:06Z","date_created":"2022-01-20T16:21:23Z","summary":null,"body":["<article data-history-node-id=\"2934\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-035\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-035<br \/>\nDate: 20 January 2022<\/strong><\/p>\n\n<p>Between 17 and 18 January 2022 Red Hat published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Red Hat CodeReady<\/li>\n\t<li>Red Hat Enterprise \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat JBoss \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat OpenShift Container Platform 4<\/li>\n\t<li>Red Hat Single Sign-On<\/li>\n\t<li>Red Hat Virtualization 4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2022-0185\">CVE-2022-0185<\/a><\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2022-23307\">CVE-2022-23307<\/a><\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2022-23305\">CVE-2022-23305<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-035","alert_type":396,"serial_number":"AV22-035","subject":null,"moderation_state":"published","external_url":null},{"nid":2937,"title":"[Control systems] B&R Industrial Automation security advisory (AV22-036)","uuid":"aa9b35b5-382f-4f81-ba06-12bddbc9bfcd","banner":null,"lang":"en","date_modified":"2022-01-20","date_modified_ts":"2022-01-20T16:50:00Z","date_created":"2022-01-20T16:50:00Z","summary":null,"body":["<article data-history-node-id=\"2937\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-av22-036\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-036<br \/>\nDate: 20 January 2022<\/strong><\/p>\n\n<p>On 20 January 2022 B&amp;R Industrial Automation published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Automation Studio 4 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1640529306294-en-original-1.0.pdf\">Cyber Security Advisory (#01\/2022)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-av22-036","alert_type":398,"serial_number":"AV22-036","subject":null,"moderation_state":"published","external_url":null},{"nid":2938,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-037)","uuid":"b86b2916-c079-4c5f-ba90-5456ce33846f","banner":null,"lang":"en","date_modified":"2022-01-21","date_modified_ts":"2022-01-21T13:23:08Z","date_created":"2022-01-21T13:23:08Z","summary":null,"body":["<article data-history-node-id=\"2938\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-037\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-037<br \/>\nDate: 21 January 2022<\/strong><\/p>\n\n<p>On 20 January 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ICONICS Suite \u2013 multiple versions<\/li>\n\t<li>Mitsubishi Electric MC Works64 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to security bypass, information disclosure or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-020-01\">ICS Advisory (ICSA-22-020-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-037","alert_type":398,"serial_number":"AV22-037","subject":null,"moderation_state":"published","external_url":null},{"nid":2939,"title":"IBM security advisory (AV22-038)","uuid":"5e76219e-08f7-4ddd-9175-9f150bbf953e","banner":null,"lang":"en","date_modified":"2022-01-24","date_modified_ts":"2022-01-24T15:50:25Z","date_created":"2022-01-24T15:50:25Z","summary":null,"body":["<article data-history-node-id=\"2939\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-038\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-038<br \/>\nDate: 24 January 2022<\/strong><\/p>\n\n<p>Between 17 and 23 January 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\u00a0\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-038","alert_type":396,"serial_number":"AV22-038","subject":null,"moderation_state":"published","external_url":null},{"nid":2940,"title":"McAfee security advisory (AV22-039)","uuid":"31da9421-39aa-44e1-9e69-7b5b8e53b579","banner":null,"lang":"en","date_modified":"2022-01-24","date_modified_ts":"2022-01-24T19:31:12Z","date_created":"2022-01-24T19:31:12Z","summary":null,"body":["<article data-history-node-id=\"2940\" about=\"\/en\/alerts-advisories\/mcafee-security-advisory-av22-039\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-039<br \/>\nDate: 24 January 2022<\/strong><\/p>\n\n<p>On 18 January 2022 McAfee released a security update to address multiple vulnerabilities in the following product:<\/p>\n\n<ul><li>McAfee Agent \u2013 versions prior to 5.7.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10378\">McAfee security bulletin<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mcafee-security-advisory-av22-039","alert_type":396,"serial_number":"AV22-039","subject":null,"moderation_state":"published","external_url":null},{"nid":2941,"title":"[Control systems] GE Gas Power security advisory (AV22-040)","uuid":"30fe3bdb-1b71-45fa-9500-c85cff47aaa6","banner":null,"lang":"en","date_modified":"2022-01-25","date_modified_ts":"2022-01-25T18:48:00Z","date_created":"2022-01-25T18:48:00Z","summary":null,"body":["<article data-history-node-id=\"2941\" about=\"\/en\/alerts-advisories\/control-systems-ge-gas-power-security-advisory-av22-040\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-040<br \/>\nDate: 25 January 2022<\/strong><\/p>\n\n<p>On 25 January 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ToolBoxST OS \u2013 versions prior to 07.09.07C \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may lead to unauthorized data modification and execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-025-01\">ICS Advisory (ICSA-22-025-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-gas-power-security-advisory-av22-040","alert_type":398,"serial_number":"AV22-040","subject":null,"moderation_state":"published","external_url":null},{"nid":2943,"title":"Apple security advisory (AV22-041)","uuid":"0bc94013-5d30-4820-a9bc-bce1a2290626","banner":null,"lang":"en","date_modified":"2022-01-27","date_modified_ts":"2022-01-27T16:14:22Z","date_created":"2022-01-26T20:18:10Z","summary":null,"body":["<article data-history-node-id=\"2943\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-041\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-041<br \/>\nDate: 26 January 2022<\/strong><\/p>\n\n<p>On 26 January 2022 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15.3<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.3<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.6.3<\/li>\n\t<li>macOS Catalina \u2013 versions prior to Security Update 2022-001<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.2<\/li>\n\t<li>Safari \u2013 versions prior to 15.3<\/li>\n\t<li>tvOS \u2013 versions prior to 15.3<\/li>\n\t<li>watchOS \u2013 versions prior to 8.4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to code execution, privilege escalation and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-041","alert_type":396,"serial_number":"AV22-041","subject":null,"moderation_state":"published","external_url":null},{"nid":2942,"title":"Linux security advisory (AV22-042)","uuid":"ff6d5005-72c8-480b-8739-6c33e77fa871","banner":null,"lang":"en","date_modified":"2022-01-27","date_modified_ts":"2022-01-27T14:48:22Z","date_created":"2022-01-27T14:48:22Z","summary":null,"body":["<article data-history-node-id=\"2942\" about=\"\/en\/alerts-advisories\/linux-security-advisory-av22-042\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-042<br \/>\nDate: 27 January 2022<\/strong><\/p>\n\n<p>On 25 January 2022 several Linux distributions released security updates to address a vulnerability in the following product:<\/p>\n\n<ul><li>PolKit \u2013 all versions<\/li>\n<\/ul><p>PolKit is a component for controlling system-wide privileges and is present in the default configuration of all major Linux distributions.<\/p>\n\n<p>Exploitation of this vulnerability may lead to local privilege escalation to root.<\/p>\n\n<p>Proof-of-concept exploit code has been released publicly.<\/p>\n\n<p>Please note that the list below is not exhaustive and that other versions of Linux may also be affected.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.debian.org\/security\/2022\/dsa-5059\">Debian<\/a><br \/><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories?q=polkit&amp;p=1&amp;sort=portal_publication_date%20desc&amp;rows=10&amp;portal_advisory_type=Security%20Advisory&amp;documentKind=Errata\">Red Hat<\/a><br \/><a href=\"https:\/\/www.suse.com\/support\/update\/\">SUSE<\/a><br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5252-1\">Ubuntu<\/a><br \/><a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2022\/01\/25\/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034\">Qualys\u2019 Disclosure<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-security-advisory-av22-042","alert_type":396,"serial_number":"AV22-042","subject":null,"moderation_state":"published","external_url":null},{"nid":2944,"title":"HPE security advisory (AV22-043)","uuid":"345a6003-5e12-4068-95fb-9fd127add3cd","banner":null,"lang":"en","date_modified":"2022-01-28","date_modified_ts":"2022-01-28T12:59:25Z","date_created":"2022-01-28T12:59:25Z","summary":null,"body":["<article data-history-node-id=\"2944\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-043\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-043<br \/>\nDate: 28 January 2022<\/strong><\/p>\n\n<p>On 27 January 2022, HPE published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Agentless Management Service for Windows x64 \u2013 versions prior to 1.44.0.0<\/li>\n\t<li>HPE ProLiant Agentless Management Service for HPE Apollo, ProLiant and Synergy Gen9 servers \u2013 versions prior to 10.96.0.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to local code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04233en_us\">HPE Security Bulletin (hpesbgn04233en_us)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-043","alert_type":396,"serial_number":"AV22-043","subject":null,"moderation_state":"published","external_url":null},{"nid":2945,"title":"IBM security advisory (AV22-044)","uuid":"d4300963-fe4f-4e5f-bd4c-5cb768421312","banner":null,"lang":"en","date_modified":"2022-01-31","date_modified_ts":"2022-01-31T16:04:56Z","date_created":"2022-01-31T16:04:56Z","summary":null,"body":["<article data-history-node-id=\"2945\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-044\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-044<br \/>\nDate: 31 January 2022<\/strong><\/p>\n\n<p>Between 24 and 30 January 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n\t<li>Cloud Pak for Security (CP4S) \u2013 versions 1.7.2.0, 1.8.0.0 and 1.8.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-044","alert_type":396,"serial_number":"AV22-044","subject":null,"moderation_state":"published","external_url":null},{"nid":2946,"title":"[Control systems] ABB security advisory (AV22-045)","uuid":"d9f58419-2515-4eb3-862a-321512f576ed","banner":null,"lang":"en","date_modified":"2022-01-31","date_modified_ts":"2022-01-31T19:10:49Z","date_created":"2022-01-31T19:10:49Z","summary":null,"body":["<article data-history-node-id=\"2946\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-045\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-045<br \/>\nDate: 31 January 2022<\/strong><\/p>\n\n<p>On 24 January 2022 ABB published a Cyber Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>800xA, Control Software for AC 800M \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA000908&amp;Action=Launch\">ABB Cyber Security Advisory (7PAA000908)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-045","alert_type":398,"serial_number":"AV22-045","subject":null,"moderation_state":"published","external_url":null},{"nid":2947,"title":"F5 security advisory (AV22-046)","uuid":"3a96e6d4-bd72-4e0c-a343-2b36e56a81ef","banner":null,"lang":"en","date_modified":"2022-01-31","date_modified_ts":"2022-01-31T19:13:22Z","date_created":"2022-01-31T19:13:22Z","summary":null,"body":["<article data-history-node-id=\"2947\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-046\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-046<br \/>\nDate: 31 January 2022<\/strong><\/p>\n\n<p>On 28 January 2022, F5 published a Security Advisory to address a vulnerability in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>F5OS-A \u2013 version 1.0.0<\/li>\n\t<li>F5OS-C \u2013 multiple versions<\/li>\n\t<li>Traffix SDC \u2013 versions 5.1.0 and 5.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K54450124 \">F5 Security Advisory (K54450124)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-046","alert_type":396,"serial_number":"AV22-046","subject":null,"moderation_state":"published","external_url":null},{"nid":2948,"title":"Samba security advisory (AV22-047)","uuid":"586eb51b-5b16-43fa-82d2-d2ef8052f0dd","banner":null,"lang":"en","date_modified":"2022-02-01","date_modified_ts":"2022-02-01T15:39:43Z","date_created":"2022-02-01T15:38:10Z","summary":null,"body":["<article data-history-node-id=\"2948\" about=\"\/en\/alerts-advisories\/samba-security-advisory-av22-047\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-047<br \/>\nDate: 1 February 2022<\/strong><\/p>\n\n<p>On 31 January 2022, Samba published Security Advisories to address vulnerabilities. Included was a critical update for the following:<\/p>\n\n<ul><li>Samba \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2021-44142.html\">Samba Security Advisory (CVE-2022-44142)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.samba.org\/samba\/history\/security.html\">Samba Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samba-security-advisory-av22-047","alert_type":396,"serial_number":"AV22-047","subject":null,"moderation_state":"published","external_url":null},{"nid":2949,"title":"[Control systems] Ricon Mobile security advisory (AV22-048)","uuid":"db96570b-f6e5-45df-95ec-51ff8effa29b","banner":null,"lang":"en","date_modified":"2022-02-01","date_modified_ts":"2022-02-01T20:11:28Z","date_created":"2022-02-01T20:11:28Z","summary":null,"body":["<article data-history-node-id=\"2949\" about=\"\/en\/alerts-advisories\/control-systems-ricon-mobile-security-advisory-av22-048\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-048<br \/>\nDate: 1 February 2022<\/strong><\/p>\n\n<p>On 1 February 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>S9922XL \u2013 version 16.10.3<\/li>\n\t<li>S9922L \u2013 version 16.10.3<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote arbitrary command execution.<\/p>\n\n<p>Proof-of-concept exploit code has been released publicly.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-032-01\">ICS Advisory (ICSA-22-032-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ricon-mobile-security-advisory-av22-048","alert_type":398,"serial_number":"AV22-048","subject":null,"moderation_state":"published","external_url":null},{"nid":2950,"title":"[Control systems] Advantech security advisory (AV22-049)","uuid":"c9324a29-0098-4a14-8f0e-13a4baf4c97e","banner":null,"lang":"en","date_modified":"2022-02-01","date_modified_ts":"2022-02-01T20:14:18Z","date_created":"2022-02-01T20:14:18Z","summary":null,"body":["<article data-history-node-id=\"2950\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-049\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-049<br \/>\nDate: 1 February 2022<\/strong><\/p>\n\n<p>On 1 February 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>ADAM-3600 \u2013 version 2.6.2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-032-02\">ICS Advisory (ICSA-21-032-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-049","alert_type":398,"serial_number":"AV22-049","subject":null,"moderation_state":"published","external_url":null},{"nid":2951,"title":"Fortinet security advisory (AV22-050)","uuid":"c7370aa8-eaa9-4047-913c-35bfc8aadff1","banner":null,"lang":"en","date_modified":"2022-02-02","date_modified_ts":"2022-02-02T15:40:43Z","date_created":"2022-02-02T15:40:43Z","summary":null,"body":["<article data-history-node-id=\"2951\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-050\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-050<br \/>\nDate: 2 February 2022<\/strong><\/p>\n\n<p>On 1 February 2022 Fortinet published PSIRT Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiWeb \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution or arbitrary command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-050","alert_type":396,"serial_number":"AV22-050","subject":null,"moderation_state":"published","external_url":null},{"nid":2952,"title":"Google Chrome security advisory (AV22-051)","uuid":"072e38e0-afc1-4486-8b89-d9296092a7c5","banner":null,"lang":"en","date_modified":"2022-02-02","date_modified_ts":"2022-02-02T15:43:56Z","date_created":"2022-02-02T15:43:56Z","summary":null,"body":["<article data-history-node-id=\"2952\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-051\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-051<br \/>\nDate: 2 February 2022<\/strong><\/p>\n\n<p>On 1 February 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 98.0.4758.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/02\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-051","alert_type":396,"serial_number":"AV22-051","subject":null,"moderation_state":"published","external_url":null},{"nid":2953,"title":"Dell security advisory (AV22-052)","uuid":"3e140684-bde8-4133-adb8-0b398ff00c7f","banner":null,"lang":"en","date_modified":"2022-02-02","date_modified_ts":"2022-02-02T17:40:54Z","date_created":"2022-02-02T17:40:54Z","summary":null,"body":["<article data-history-node-id=\"2953\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-052\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong><a name=\"_Int_PUv0j9H6\" id=\"_Int_PUv0j9H6\">Number: AV22-052<br \/>\nDate: 2 February 2022<\/a><\/strong><\/p>\n\n<p>On 1 February 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Cyber Recovery \u2013 versions prior to 19.9.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000195873\/dsa-2022-020-dell-emc-cyber-recovery-security-update-for-multiple-third-party-components-vulnerabilities\">Dell Security Advisory (000195873)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-052","alert_type":396,"serial_number":"AV22-052","subject":null,"moderation_state":"published","external_url":null},{"nid":2954,"title":"HPE security advisory (AV22-053)","uuid":"227fedb2-9904-41ae-b6f3-1cce350432c2","banner":null,"lang":"en","date_modified":"2022-02-03","date_modified_ts":"2022-02-03T12:52:35Z","date_created":"2022-02-02T21:00:23Z","summary":null,"body":["<article data-history-node-id=\"2954\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-053\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-053<br \/>\nDate: 2 February 2022<\/strong><\/p>\n\n<p class=\"MsoNormal\"><span style=\"mso-ascii-font-family:Calibri;mso-fareast-font-family:&#10;Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri\"><\/span><\/p>\n\n<p>On 1 February 2022, HPE published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Aruba Analytics and Location Engine \u2013 version 2.2.0.1 and prior<\/li>\n\t<li>Aruba ClearPass Policy Manager \u2013 version 6.10.3 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>\u00a0<\/p>\n\n<p class=\"MsoNormal\"><span lang=\"EN-CA\" style=\"mso-ascii-font-family:Calibri;&#10;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#10;Calibri;color:black;mso-themecolor:text1;mso-ansi-language:EN-CA\" xml:lang=\"EN-CA\" xml:lang=\"EN-CA\"><\/span><span style=\"mso-ascii-font-family:Calibri;&#10;mso-fareast-font-family:Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:&#10;Calibri;color:black;mso-themecolor:text1\"><o:p><\/o:p><\/span><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04237en_us\">HPE Security Bulletin (hpesbnw04237en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/linux-security-advisory-av22-042\">Linux security advisory (AV22-042)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-053","alert_type":396,"serial_number":"AV22-053","subject":null,"moderation_state":"published","external_url":null},{"nid":2955,"title":"Ubuntu security advisory (AV22-054)","uuid":"aa5b970f-a7a7-4721-8f64-716c1784bf90","banner":null,"lang":"en","date_modified":"2022-02-03","date_modified_ts":"2022-02-03T17:48:15Z","date_created":"2022-02-03T17:48:15Z","summary":null,"body":["<article data-history-node-id=\"2955\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-054\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-054<br \/>\nDate: 3 February 2022<\/strong><\/p>\n\n<p>On 3 February 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could cause a denial of service or lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-054","alert_type":396,"serial_number":"AV22-054","subject":null,"moderation_state":"published","external_url":null},{"nid":2956,"title":"Cisco security advisory (AV22-055)","uuid":"219ffb90-bcd2-4e3b-97d9-f700fbb94c52","banner":null,"lang":"en","date_modified":"2022-02-03","date_modified_ts":"2022-02-03T19:03:32Z","date_created":"2022-02-03T19:03:32Z","summary":null,"body":["<article data-history-node-id=\"2956\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-055\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-055<br \/>\nDate: 3 February 2022<\/strong><\/p>\n\n<p>On 2 February 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical patches for the following:<\/p>\n\n<ul><li>Cisco Small Business RV series routers \u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, privilege escalation, arbitrary command execution, authentication bypass, denial of service and the ability to fetch and run unsigned software.<\/p>\n\n<p>Cisco PSIRT has stated that proof-of-concept exploit code is available for several of these vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-smb-mult-vuln-KA9PK6D\">Cisco Small Business RV Series Routers Advisory<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-055","alert_type":396,"serial_number":"AV22-055","subject":null,"moderation_state":"published","external_url":null},{"nid":2957,"title":"[Control systems] Sensormatic Electronics security advisory (AV22-056)","uuid":"141c31fe-5707-4f57-94b9-5dfa6810ded2","banner":null,"lang":"en","date_modified":"2022-02-03","date_modified_ts":"2022-02-03T20:12:34Z","date_created":"2022-02-03T20:12:34Z","summary":null,"body":["<article data-history-node-id=\"2957\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av22-056\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-056<br \/>\nDate: 3 February 2022<\/strong><\/p>\n\n<p>On 3 February 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>PowerManage \u2013 versions 4.0 to 4.8<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-034-01\">ICS Advisory (ICSA-22-034-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/apache-security-advisory-4\">Apache Security Advisory (AV21-626)<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av22-056","alert_type":398,"serial_number":"AV22-056","subject":null,"moderation_state":"published","external_url":null},{"nid":2958,"title":"[Control systems] Airspan Networks security advisory (AV22-057)","uuid":"6150d60a-2cb8-4a74-8c57-899649dfe361","banner":null,"lang":"en","date_modified":"2022-02-03","date_modified_ts":"2022-02-03T20:16:35Z","date_created":"2022-02-03T20:16:35Z","summary":null,"body":["<article data-history-node-id=\"2958\" about=\"\/en\/alerts-advisories\/control-systems-airspan-networks-security-advisory-av22-057\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-057<br \/>\nDate: 3 February 2022<\/strong><\/p>\n\n<p>On 3 February 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MMP \u2013 versions prior to 1.0.3<\/li>\n\t<li>PTP C-series - versions prior to 2.8.6.1<\/li>\n\t<li>PTMP C-series and A5x - versions prior to 2.5.4.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, denial of service, information disclosure and execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-034-02\">ICS Advisory (ICSA-22-034-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-airspan-networks-security-advisory-av22-057","alert_type":398,"serial_number":"AV22-057","subject":null,"moderation_state":"published","external_url":null},{"nid":2959,"title":"F5 security advisory (AV22-058)","uuid":"a8281da5-1ce5-4201-a76b-2e103d295d97","banner":null,"lang":"en","date_modified":"2022-02-07","date_modified_ts":"2022-02-07T13:32:59Z","date_created":"2022-02-07T13:32:59Z","summary":null,"body":["<article data-history-node-id=\"2959\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-058\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-058<br \/>\nDate: 7 February 2022<\/strong><\/p>\n\n<p>On 3 February 2022, F5 published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 multiple versions<\/li>\n\t<li>F5OS-A \u2013 version 1.0.0<\/li>\n\t<li>F5OS-C \u2013 multiple versions<\/li>\n\t<li>Traffix SDC \u2013 versions 5.1.0 and 5.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K05295469\">F5 Security Advisory (K05295469)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K40508224\">F5 Security Advisory (K40508224)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-058","alert_type":396,"serial_number":"AV22-058","subject":null,"moderation_state":"published","external_url":null},{"nid":2960,"title":"IBM security advisory (AV22-059)","uuid":"41d9df41-ab8b-4139-a61e-0b930019d1d7","banner":null,"lang":"en","date_modified":"2022-02-07","date_modified_ts":"2022-02-07T16:21:08Z","date_created":"2022-02-07T16:21:08Z","summary":null,"body":["<article data-history-node-id=\"2960\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-059\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-059<br \/>\nDate: 7 February 2022<\/strong><\/p>\n\n<p>Between 31 January and 6 February 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Planning Analytics \u2013 version 2.0<\/li>\n\t<li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n\t<li>IBM Security Verify Access Appliance \u2013 versions 10.0.0, 10.0.1 and 10.0.2<\/li>\n\t<li>IBM Security Verify Access Docker \u2013 versions 10.0.0, 10.0.1 and 10.0.2<\/li>\n\t<li>IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes \u2013 versions 10.1.5 to 10.1.9.2<\/li>\n\t<li>IBM Spectrum Protect Plus Container Backup and Restore for OpenShift \u2013 versions 10.1.7 to 10.1.9.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-059","alert_type":396,"serial_number":"AV22-059","subject":null,"moderation_state":"published","external_url":null},{"nid":2961,"title":"Android security advisory \u2013 February 2022 monthly rollup (AV22-060)","uuid":"1ac4b228-06a3-4048-8071-b963325656f4","banner":null,"lang":"en","date_modified":"2022-02-07","date_modified_ts":"2022-02-07T19:28:34Z","date_created":"2022-02-07T19:23:40Z","summary":null,"body":["<article data-history-node-id=\"2961\" about=\"\/en\/alerts-advisories\/android-security-advisory-february-2022-monthly-rollup-av22-060\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-060<br \/>\nDate: 7 February 2022<\/strong><\/p>\n\n<p>On 7 February 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2022-02-01\">Android Security Bulletin<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-february-2022-monthly-rollup-av22-060","alert_type":396,"serial_number":"AV22-060","subject":null,"moderation_state":"published","external_url":null},{"nid":2962,"title":"[Control systems] Siemens security advisory (AV22-061)","uuid":"85ec9e8c-fb46-4505-81c8-077f55de1d05","banner":null,"lang":"en","date_modified":"2022-02-08","date_modified_ts":"2022-02-08T18:23:57Z","date_created":"2022-02-08T18:23:57Z","summary":null,"body":["<article data-history-node-id=\"2962\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-061\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-061<br \/>\nDate: 8 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>JT2Go \u2013 all versions<\/li>\n\t<li>RUGGEDCOM \u2013 multiple products and versions<\/li>\n\t<li>SCALANCE \u2013 multiple products and versions<\/li>\n\t<li>SICAM TOOLBOX II \u2013 all versions<\/li>\n\t<li>SINEMA Remote Connect Server \u2013 versions prior to v2.0<\/li>\n\t<li>SINEMA Server V14 \u2013 all versions<\/li>\n\t<li>SIMATIC \u2013 multiple products and versions<\/li>\n\t<li>Simcenter Femap v2020.2 and v2021.1 - all versions<\/li>\n\t<li>SINEC NMS \u2013 all versions<\/li>\n\t<li>SINUMERIK Operate \u2013 all versions<\/li>\n\t<li>SIPLUS \u2013 multiple products and versions<\/li>\n\t<li>Solid Edge SE2021 \u2013 versions prior to SE2021MP9<\/li>\n\t<li>Solid Edge SE2022 \u2013 versions prior to SE2022MP1<\/li>\n\t<li>Spectrum Power 4 \u2013 versions prior to v4.70 SP9 Security Patch 1<\/li>\n\t<li>Teamcenter Visualization \u2013 multiple versions<\/li>\n\t<li>TIA Administrator \u2013 all versions<\/li>\n\t<li>TIM 1531 IRC (including SIPLUS NET variants) \u2013 versions prior to v2.2<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial of service, arbitrary code execution, disclosure of sensitive information or authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Publications<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-061","alert_type":398,"serial_number":"AV22-061","subject":null,"moderation_state":"published","external_url":null},{"nid":2963,"title":"Mozilla security advisory (AV22-062)","uuid":"469f38d6-4c60-4453-a936-b24fc49b68cc","banner":null,"lang":"en","date_modified":"2022-02-08","date_modified_ts":"2022-02-08T18:28:36Z","date_created":"2022-02-08T18:28:36Z","summary":null,"body":["<article data-history-node-id=\"2963\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-062\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-062<br \/>\nDate: 8 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 97<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-04\/\">Firefox (MFSA 2022-04)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-05\/\">Firefox ESR (MFSA 2022-05)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-062","alert_type":396,"serial_number":"AV22-062","subject":null,"moderation_state":"published","external_url":null},{"nid":2964,"title":"SAP security advisory \u2013 February 2022 monthly rollup (AV22-063)","uuid":"c951a9cb-76a0-480f-8039-dc1819c2afb5","banner":null,"lang":"en","date_modified":"2022-02-08","date_modified_ts":"2022-02-08T18:32:22Z","date_created":"2022-02-08T18:32:22Z","summary":null,"body":["<article data-history-node-id=\"2964\" about=\"\/en\/alerts-advisories\/sap-security-advisory-february-2022-monthly-rollup-av22-063\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-063<br \/>\nDate: 8 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Web Dispatcher \u2013 versions 7.49, 7.53, 7.77, 7.81, 7.85, 7.22EXT, 7.86 and 7.87<\/li>\n\t<li>SAP Content Server \u2013 version 7.53<\/li>\n\t<li>SAP NetWeaver and ABAP Platform \u2013 multiple versions<\/li>\n\t<li>SAP Commerce \u2013 versions 1905, 2005, 2105 and 2011<\/li>\n\t<li>SAP Data Intelligence (on-premise) \u2013 version 3<\/li>\n\t<li>Internet of Things Edge Platform \u2013 version 4.0<\/li>\n\t<li>SAP Customer Checkout \u2013 version 2<\/li>\n\t<li>SAP Business Client \u2013 version 6.5<\/li>\n\t<li>SAP Solution Manager (Diagnostics Root Cause Analysis Tools) \u2013 version 720<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. \u00a0<\/p>\n\n<p><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day \u2013 February 2022<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-february-2022-monthly-rollup-av22-063","alert_type":396,"serial_number":"AV22-063","subject":null,"moderation_state":"published","external_url":null},{"nid":2965,"title":"Microsoft security advisory \u2013 February 2022 monthly rollup (AV22-064)","uuid":"69d8069d-8a57-4b60-ad98-520c4ac50f06","banner":null,"lang":"en","date_modified":"2022-02-08","date_modified_ts":"2022-02-08T20:55:48Z","date_created":"2022-02-08T20:55:48Z","summary":null,"body":["<article data-history-node-id=\"2965\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-february-2022-monthly-rollup-av22-064\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-064<br \/>\nDate: 8 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were important updates for the following:<\/p>\n\n<ul><li>.NET 5.0<\/li>\n\t<li>.NET 6.0<\/li>\n\t<li>Azure Data Explorer<\/li>\n\t<li>HEVC\/VP9 Video Extensions<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Dynamics GP<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Microsoft Outlook<\/li>\n\t<li>Microsoft SharePoint Server and Enterprise Server<\/li>\n\t<li>Microsoft Teams Admin Center<\/li>\n\t<li>Microsoft Teams for Android<\/li>\n\t<li>OneDrive for Android<\/li>\n\t<li>PowerBI-client JS SDK<\/li>\n\t<li>SQL Server 2019 for Linux Containers<\/li>\n\t<li>Visual Studio<\/li>\n\t<li>Windows 8, 10, 11, RT<\/li>\n\t<li>Windows Server 2008, 2012, 2016, 2019, 2022<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Feb\">February 2022 Release Notes<\/a><\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-february-2022-monthly-rollup-av22-064","alert_type":396,"serial_number":"AV22-064","subject":null,"moderation_state":"published","external_url":null},{"nid":2966,"title":"Intel security advisory (AV22-065)","uuid":"6e0d6f6b-5588-4091-8518-60ee51bc06ec","banner":null,"lang":"en","date_modified":"2022-02-09","date_modified_ts":"2022-02-09T15:49:29Z","date_created":"2022-02-09T15:49:29Z","summary":null,"body":["<article data-history-node-id=\"2966\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av22-065\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-065<br \/>\nDate: 9 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022 Intel published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>2nd Generation Intel Xeon Scalable Processor Family<\/li>\n\t<li>6th Generation Intel Core Processor Family<\/li>\n\t<li>7th Generation Intel Core Processor Family<\/li>\n\t<li>8th Generation Intel Core Processor Family<\/li>\n\t<li>9th Generation Intel Core Processor Family<\/li>\n\t<li>10th Generation Intel Core Processor Family<\/li>\n\t<li>11th Generation Intel Core Processor Family<\/li>\n\t<li>Intel AMT SDK \u2013 versions prior to 16.0.3<\/li>\n\t<li>Intel Atom Processor C3XXX Family<\/li>\n\t<li>Intel Core X-series Processor Family<\/li>\n\t<li>Intel MEBx \u2013 versions prior to 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004<\/li>\n\t<li>Intel Quartus Prime Pro Edition \u2013 versions prior to 21.3<\/li>\n\t<li>Intel Quartus Prime Standard Edition \u2013 versions prior to 21.1<\/li>\n\t<li>Intel SCS \u2013 versions prior to 12.2<\/li>\n\t<li>Intel Xeon Scalable Processor Family<\/li>\n\t<li>Intel Xeon Processor W Family<\/li>\n\t<li>Intel Xeon Processor E Family<\/li>\n\t<li>Intel Xeon Processor D Family<\/li>\n\t<li>Kernelflinger project \u2013 commits prior to 5081b436def045e3fad5debe0a7ffcf8456b1579<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00527.html\">Intel Security Advisory (INTEL-SA-00527)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00575.html\">Intel Security Advisory (INTEL-SA-00575)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00591.html\">Intel Security Advisory (INTEL-SA-00591)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00632.html\">Intel Security Advisory (INTEL-SA-00632)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av22-065","alert_type":396,"serial_number":"AV22-065","subject":null,"moderation_state":"published","external_url":null},{"nid":2967,"title":"Adobe security advisory (AV22-066)","uuid":"bf015228-b6fa-4da2-8455-41e0ba953142","banner":null,"lang":"en","date_modified":"2022-02-09","date_modified_ts":"2022-02-09T15:58:40Z","date_created":"2022-02-09T15:58:40Z","summary":null,"body":["<article data-history-node-id=\"2967\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-066\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-066<br \/>\nDate: 9 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022 Adobe published Security Bulletins to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Adobe After Effects \u2013 versions prior to 22.2 and 18.4.4<\/li>\n\t<li>Adobe Photoshop 2021 \u2013 versions prior to 22.5.5<\/li>\n\t<li>Adobe Photoshop 2022 \u2013 versions prior to 23.1.1<\/li>\n\t<li>Adobe Illustrator 2021 \u2013 versions prior to 25.4.4<\/li>\n\t<li>Adobe Illustrator 2022 \u2013 versions prior to 26.0.3<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution, privilege escalation, denial of service and memory leak.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/after_effects\/apsb22-09.html\">Adobe After Effects<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/illustrator\/apsb22-07.html\">Adobe Illustrator<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb22-08.html\">Adobe Photoshop<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-066","alert_type":396,"serial_number":"AV22-066","subject":null,"moderation_state":"published","external_url":null},{"nid":2968,"title":"[Control systems] Schneider Electric security advisory (AV22-067)","uuid":"50bf286b-ff4c-4ffe-808b-874551a3945a","banner":null,"lang":"en","date_modified":"2022-02-09","date_modified_ts":"2022-02-09T16:05:12Z","date_created":"2022-02-09T16:05:12Z","summary":null,"body":["<article data-history-node-id=\"2968\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-067\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-067<br \/>\nDate: 9 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022 Schneider Electric published Security Notifications to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ClearSCADA \u2013 all versions<\/li>\n\t<li>Easergy P40 series \u2013 multiple products, all PX4X firmware versions<\/li>\n\t<li>EcoStruxure EV Charging Expert \u2013 versions prior to SP8 (Version 01) v4.0.0.13<\/li>\n\t<li>EcoStruxure Geo SCADA Expert 2019 and 2020 \u2013 all versions<\/li>\n\t<li>fellerLYnk \u2013 version v2.6.2 and prior<\/li>\n\t<li>Harmony\/Magelis IPC Series \u2013 all versions<\/li>\n\t<li>IGSS Data Server \u2013 version V15.0.0.22020 and prior<\/li>\n\t<li>spaceLYnk \u2013 version v2.6.2 and prior<\/li>\n\t<li>Vijeo Designer \u2013 versions prior to v6.2 SP11 Multiple Hotfix 4<\/li>\n\t<li>Vijeo Designer Basic \u2013 versions prior to v1.2.1<\/li>\n\t<li>Wiser for KNX \u2013 version v2.6.2 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access, remote code execution, denial of service, information disclosure, data modification and credential disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Cybersecurity Support Portal<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-067","alert_type":398,"serial_number":"AV22-067","subject":null,"moderation_state":"published","external_url":null},{"nid":2969,"title":"Ubuntu security advisory (AV22-068)","uuid":"ba3df0f6-4b13-4f76-97c6-2395435fe64c","banner":null,"lang":"en","date_modified":"2022-02-09","date_modified_ts":"2022-02-09T16:09:39Z","date_created":"2022-02-09T16:09:39Z","summary":null,"body":["<article data-history-node-id=\"2969\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-068\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-068<br \/>\nDate: 9 February 2022<\/strong><\/p>\n\n<p>On 8 and 9 February 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could cause a denial of service, privilege escalation and information disclosure or lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5267-2\">Ubuntu Security Notice (USN-5267-2)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5278-1\">Ubuntu Security Notice (USN-5278-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-068","alert_type":396,"serial_number":"AV22-068","subject":null,"moderation_state":"published","external_url":null},{"nid":2970,"title":"HPE security advisory (AV22-069)","uuid":"203fcfea-fd0e-484d-9f26-2d254ced8617","banner":null,"lang":"en","date_modified":"2022-02-09","date_modified_ts":"2022-02-09T16:14:01Z","date_created":"2022-02-09T16:14:01Z","summary":null,"body":["<article data-history-node-id=\"2970\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-069\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-069<br \/>\nDate: 9 February 2022<\/strong><\/p>\n\n<p>On 8 February 2022, HPE published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Apollo \u2013 multiple versions and platforms<\/li>\n\t<li>HPE ProLiant \u2013 multiple versions and platforms<\/li>\n\t<li>HPE Synergy \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation, denial of service, or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04243en_us\">HPE Security Bulletin (hpesbhf04243en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-069","alert_type":396,"serial_number":"AV22-069","subject":null,"moderation_state":"published","external_url":null},{"nid":2971,"title":"Dell security advisory (AV22-070)","uuid":"86e70af8-26f7-44f5-91e1-e0bac4f0b08a","banner":null,"lang":"en","date_modified":"2022-02-10","date_modified_ts":"2022-02-10T18:31:22Z","date_created":"2022-02-10T18:31:22Z","summary":null,"body":["<article data-history-node-id=\"2971\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-070\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-070<br \/>\nDate: 10 February 2022<\/strong><\/p>\n\n<p>On 10 February 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Elastic Cloud Storage \u2013 versions prior to ECS 3.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000196201\/dsa-2022-025-dell-emc-elastic-cloud-storage-security-update-for-third-party-vulnerabilities\">Dell Security Advisory (000196201)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-070","alert_type":396,"serial_number":"AV22-070","subject":null,"moderation_state":"published","external_url":null},{"nid":2972,"title":"Apple security advisory (AV22-071)","uuid":"dcd73554-36b5-4693-b534-f360bd264b62","banner":null,"lang":"en","date_modified":"2022-02-10","date_modified_ts":"2022-02-10T20:41:34Z","date_created":"2022-02-10T20:41:34Z","summary":null,"body":["<article data-history-node-id=\"2972\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-071\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-071<br \/>\nDate: 10 February 2022<\/strong><\/p>\n\n<p>On 10 February 2022 Apple published Security Updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15.3.1<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.3.1<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.2.1<\/li>\n\t<li>Safari \u2013 versions prior to 15.3<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>Apple is aware of a report that some of this issue may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-071","alert_type":396,"serial_number":"AV22-071","subject":null,"moderation_state":"published","external_url":null},{"nid":2974,"title":"Dell security advisory (AV22-072)","uuid":"2616c984-0fed-41e1-b1b7-aa0fe2b0bc0b","banner":null,"lang":"en","date_modified":"2022-02-11","date_modified_ts":"2022-02-11T20:46:19Z","date_created":"2022-02-11T16:15:19Z","summary":null,"body":["<article data-history-node-id=\"2974\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-072\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-072<br \/>\nDate: 11 February 2022<\/strong><\/p>\n\n<p>On 11 February 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC VxRail \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000196209\/dsa-2022-044-dell-emc-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000196209)<\/a><\/p>\n\n<p>\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-072","alert_type":396,"serial_number":"AV22-072","subject":null,"moderation_state":"published","external_url":null},{"nid":2973,"title":"HPE security advisory (AV22-073)","uuid":"7bdd31ee-37de-4a97-b052-f05c886f8ce9","banner":null,"lang":"en","date_modified":"2022-02-11","date_modified_ts":"2022-02-11T20:39:37Z","date_created":"2022-02-11T20:38:52Z","summary":null,"body":["<article data-history-node-id=\"2973\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-073\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-073<br \/>\nDate: 11 February 2022<\/strong><\/p>\n\n<p>On 11 February 2022, HPE published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Samba on NonStop \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to security bypass, elevation of privilege or code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbns04250en_us\">HPE Security Bulletin (hpesbns04250en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/samba-security-advisory-av22-047\">Samba Security Advisory (AV22-047)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-073","alert_type":396,"serial_number":"AV22-073","subject":null,"moderation_state":"published","external_url":null},{"nid":2975,"title":"IBM security advisory (AV22-074)","uuid":"42de08d1-5bd3-485f-9671-eabfc39852bd","banner":null,"lang":"en","date_modified":"2022-02-14","date_modified_ts":"2022-02-14T17:13:24Z","date_created":"2022-02-14T17:13:24Z","summary":null,"body":["<article data-history-node-id=\"2975\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-074\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-074<br \/>\nDate: 14 February 2022<\/strong><\/p>\n\n<p>Between 7 and 13 February 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Cloud Object Storage Systems \u2013 version 3.16.3.36 and prior<\/li>\n\t<li>IBM Cloud Private \u2013 multiple versions<\/li>\n\t<li>IBM Rational Build Forge \u2013 versions 8.0 to 8.0.0.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an\u2013update\u2013on\u2013the\u2013apache\u2013log4j\u2013cve\u20132021\u201344228\u2013vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-074","alert_type":396,"serial_number":"AV22-074","subject":null,"moderation_state":"published","external_url":null},{"nid":2976,"title":"Adobe security advisory (AV22-075)","uuid":"32f7b0bc-eda5-461c-9580-57e94260f942","banner":null,"lang":"en","date_modified":"2022-02-14","date_modified_ts":"2022-02-14T17:18:59Z","date_created":"2022-02-14T17:18:59Z","summary":null,"body":["<article data-history-node-id=\"2976\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-075\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-075<br \/>\nDate: 14 February 2022<\/strong><\/p>\n\n<p>On 13 February 2022 Adobe published a Security Bulletin to address a vulnerability in multiple products:<\/p>\n\n<ul><li>Adobe Commerce \u2013 versions 2.4.3-p1 and 2.3.7-p2 and prior<\/li>\n\t<li>Magento Open Source \u2013 versions 2.4.3-p1 and 2.3.7-p2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb22-12.html\">Adobe Commerce<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-075","alert_type":396,"serial_number":"AV22-075","subject":null,"moderation_state":"published","external_url":null},{"nid":2977,"title":"Google Chrome security advisory (AV22-076)","uuid":"4e6b9128-016d-46ea-ae6b-b1d5136b42fb","banner":null,"lang":"en","date_modified":"2022-02-15","date_modified_ts":"2022-02-15T13:59:33Z","date_created":"2022-02-15T13:59:33Z","summary":null,"body":["<article data-history-node-id=\"2977\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-076\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-076<br \/>\nDate: 15 February 2022<\/strong><\/p>\n\n<p>On 14 February 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 98.0.4758.102<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2022-0609 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/02\/stable-channel-update-for-desktop_14.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-076","alert_type":396,"serial_number":"AV22-076","subject":null,"moderation_state":"published","external_url":null},{"nid":2978,"title":"VMware security advisory (AV22-077)","uuid":"2ae571ef-ff66-42fc-91d3-3fdc9bbdc6d4","banner":null,"lang":"en","date_modified":"2022-02-15","date_modified_ts":"2022-02-15T15:39:44Z","date_created":"2022-02-15T15:29:45Z","summary":null,"body":["<article data-history-node-id=\"2978\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-077\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-077<br \/>\nDate: 15 February 2022<\/strong><\/p>\n\n<p>On 15 February 2022 VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation \u2013 version 3.x and 4.x<\/li>\n\t<li>VMware ESXi \u2013 version 6.5, 6.7, 7.0 U1, 7.0 U2 and 7.0 U3<\/li>\n\t<li>VMware Fusion \u2013 version 12.x<\/li>\n\t<li>VMware Workstation \u2013 version 16.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, access of services or escalation of privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0004.html\">VMware Security Advisory (VMSA-2022-0004)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-077","alert_type":396,"serial_number":"AV22-077","subject":null,"moderation_state":"published","external_url":null},{"nid":2979,"title":"VMware security advisory (AV22-078)","uuid":"27b1bfea-53d9-491e-9dc4-8effec2b5197","banner":null,"lang":"en","date_modified":"2022-02-15","date_modified_ts":"2022-02-15T19:14:46Z","date_created":"2022-02-15T19:14:46Z","summary":null,"body":["<article data-history-node-id=\"2979\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-078\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-078<br \/>\nDate: 15 February 2022<\/strong><\/p>\n\n<p>On 15 February 2022 VMware published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware NSX Data Center for vSphere \u2013 versions prior to 6.4.13<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0005.html\">VMware Security Advisory (VMSA-2022-0005)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-078","alert_type":396,"serial_number":"AV22-078","subject":null,"moderation_state":"published","external_url":null},{"nid":2980,"title":"Mozilla security advisory (AV22-079)","uuid":"006baba1-27b2-4327-bf75-8459fee100dc","banner":null,"lang":"en","date_modified":"2022-02-16","date_modified_ts":"2022-02-16T14:18:56Z","date_created":"2022-02-16T14:18:56Z","summary":null,"body":["<article data-history-node-id=\"2980\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-079\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-079<br \/>\nDate: 16 February 2022<\/strong><\/p>\n\n<p>On 15 February 2022 Mozilla published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 91.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-07\/\">Thunderbird (MFSA 2022-07)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-079","alert_type":396,"serial_number":"AV22-079","subject":null,"moderation_state":"published","external_url":null},{"nid":2981,"title":"Cisco security advisory (AV22-080)","uuid":"9f64f0ca-814a-45cf-aa68-bea3d3003fa9","banner":null,"lang":"en","date_modified":"2022-02-16","date_modified_ts":"2022-02-16T18:52:06Z","date_created":"2022-02-16T18:52:06Z","summary":null,"body":["<article data-history-node-id=\"2981\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-080\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-080<br \/>\nDate: 16 February 2022<\/strong><\/p>\n\n<p>On 16 February 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>Cisco AsyncOS \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-esa-dos-MxZvGtgU\">Cisco ESA Security Advisory<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-080","alert_type":396,"serial_number":"AV22-080","subject":null,"moderation_state":"published","external_url":null},{"nid":2982,"title":"Microsoft Edge security advisory (AV22-081)","uuid":"626a0931-5a08-4bec-9f7d-255120fec0e9","banner":null,"lang":"en","date_modified":"2022-02-16","date_modified_ts":"2022-02-16T20:25:39Z","date_created":"2022-02-16T20:25:39Z","summary":null,"body":["<article data-history-node-id=\"2982\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-081\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-081<br \/>\nDate: 16 February 2022<\/strong><\/p>\n\n<p>On 16 February 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 98.0.1108.55<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2022-0609 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-16-2022\">Microsoft Edge Stable Channel Release Notes<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-081","alert_type":396,"serial_number":"AV22-081","subject":null,"moderation_state":"published","external_url":null},{"nid":2983,"title":"[Control systems] Siemens security advisory (AV22-082)","uuid":"147de010-a0be-48fd-8997-3aeb3c04b81f","banner":null,"lang":"en","date_modified":"2022-02-17","date_modified_ts":"2022-02-17T13:50:20Z","date_created":"2022-02-17T13:50:20Z","summary":null,"body":["<article data-history-node-id=\"2983\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-082\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-082<br \/>\nDate: 17 February 2022<\/strong><\/p>\n\n<p>On 17 February 2022 Siemens published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Simcenter Femap \u2013 versions prior to V2022.1.1<\/li>\n\t<li>SPPA-S2000 \u2013 versions V3.04 and V3.06<\/li>\n\t<li>SPPA-S3000 \u2013 versions V3.04 and V3.05<\/li>\n\t<li>SPPA-T3000 \u2013 version R8.2 SP2<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to denial of service, remote code execution or disclosure of sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications \">Siemens Security Publications<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-082","alert_type":398,"serial_number":"AV22-082","subject":null,"moderation_state":"published","external_url":null},{"nid":2984,"title":"Dell security advisory (AV22-083)","uuid":"9a0cb793-419a-411b-acad-5754c0c27523","banner":null,"lang":"en","date_modified":"2022-02-17","date_modified_ts":"2022-02-17T15:23:11Z","date_created":"2022-02-17T13:53:09Z","summary":null,"body":["<article data-history-node-id=\"2984\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-083\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-083<br \/>\nDate: 17 February 2022<\/strong><\/p>\n\n<p>On 16 February 2022 Dell published a Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC PowerStore X Operating System \u2013 versions prior to ESXi 6.7 P06<\/li>\n\t<li>Dell EMC PowerStore T Operating System \u2013 versions prior to 2.1.0.0-1553419<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196419\/dsa-2022-047-dell-emc-powerstore-family-security-update-for-vmware-vulnerabilities\">Dell Security Advisory (000196419)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196367\/dsa-2022-014-dell-emc-powerstore-family-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (000196367)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-083","alert_type":396,"serial_number":"AV22-083","subject":null,"moderation_state":"published","external_url":null},{"nid":2985,"title":"Google Chrome security advisory (AV22-084)","uuid":"4fa14d58-35ae-4342-9148-1d87f4fa45c7","banner":null,"lang":"en","date_modified":"2022-02-17","date_modified_ts":"2022-02-17T16:37:19Z","date_created":"2022-02-17T16:37:19Z","summary":null,"body":["<article data-history-node-id=\"2985\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-084\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-084<br \/>\nDate: 17 February 2022<\/strong><\/p>\n\n<p>On 16 February 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome LTS Candidate LTC-96 \u2013 versions prior to 96.0.4664.194<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/02\/long-term-support-channel-update_16.html \">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-084","alert_type":396,"serial_number":"AV22-084","subject":null,"moderation_state":"published","external_url":null},{"nid":2986,"title":"Dell security advisory (AV22-085)","uuid":"04141d81-34b2-4e1a-95a5-9448cb830bc2","banner":null,"lang":"en","date_modified":"2022-02-17","date_modified_ts":"2022-02-17T20:04:27Z","date_created":"2022-02-17T20:04:27Z","summary":null,"body":["<article data-history-node-id=\"2986\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-085\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-085<br \/>\nDate: 17 February 2022<\/strong><\/p>\n\n<p>On 17 February 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Cloud Disaster Recovery \u2013 version 19.9.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196449\/dsa-2022-048-dell-emc-cloud-disaster-recovery-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000196449)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-085","alert_type":396,"serial_number":"AV22-085","subject":null,"moderation_state":"published","external_url":null},{"nid":2987,"title":"Ubuntu security advisory (AV22-086)","uuid":"cdb4d059-742c-42b1-b428-0fc5d320fe53","banner":null,"lang":"en","date_modified":"2022-02-18","date_modified_ts":"2022-02-18T16:08:18Z","date_created":"2022-02-18T16:08:18Z","summary":null,"body":["<article data-history-node-id=\"2987\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-086\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-086<br \/>\nDate: 18 February 2022<\/strong><\/p>\n\n<p>On 18 February 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service, privilege escalation, information disclosure or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5294-1\">Ubuntu Security Notice (USN-5294-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5295-1\">Ubuntu Security Notice (USN-5295-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-086","alert_type":396,"serial_number":"AV22-086","subject":null,"moderation_state":"published","external_url":null},{"nid":2988,"title":"HPE security advisory (AV22-087)","uuid":"1012aeab-42fa-4fec-9799-6adcdd58ffba","banner":null,"lang":"en","date_modified":"2022-02-18","date_modified_ts":"2022-02-18T16:13:43Z","date_created":"2022-02-18T16:13:43Z","summary":null,"body":["<article data-history-node-id=\"2988\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-087\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-087<br \/>\nDate: 18 February 2022<\/strong><\/p>\n\n<p>On 17 February 2022, HPE published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Brocade Fibre Channel SAN Switch \u2013 multiple versions and platforms<\/li>\n\t<li>HPE B-Series Switch \u2013 multiple versions and platforms<\/li>\n\t<li>HPE SAN Director Switch \u2013 multiple versions and platforms<\/li>\n\t<li>HPE Universal IoT Platform \u2013 version 1.8.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution, authentication bypass, denial of service or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04241en_us\">HPE Security Bulletin (hpesbnw04241en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04254en_us\">HPE Security Bulletin (hpesbst04254en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04255en_us\">HPE Security Bulletin (hpesbst04255en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary\">HPE Security Bulletins<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-087","alert_type":396,"serial_number":"AV22-087","subject":null,"moderation_state":"published","external_url":null},{"nid":2989,"title":"IBM security advisory (AV22-088)","uuid":"d0f34c72-820d-4634-91e7-891560d4c042","banner":null,"lang":"en","date_modified":"2022-02-21","date_modified_ts":"2022-02-21T18:32:10Z","date_created":"2022-02-21T18:26:37Z","summary":null,"body":["<article data-history-node-id=\"2989\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-088\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-088<br \/>\nDate: 21 February 2022<\/strong><\/p>\n\n<p>Between 14 and 20 February 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Cloud Pak for Data Systems \u2013 versions 1.0 to 1.0.7.7<\/li>\n\t<li>IBM Integrated Analytics System \u2013 versions 1.0.0 to 1.0.27.0<\/li>\n\t<li>IBM Planning Analytics \u2013 versions prior to 2.0.9.11<\/li>\n\t<li>IBM Planning Analytics Workspace \u2013 versions prior to 2.0.72<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-088","alert_type":396,"serial_number":"AV22-088","subject":null,"moderation_state":"published","external_url":null},{"nid":2990,"title":"Ubuntu security advisory (AV22-089)","uuid":"00362c8f-0649-4956-b005-1e9fbb5cb72a","banner":null,"lang":"en","date_modified":"2022-02-22","date_modified_ts":"2022-02-22T20:10:36Z","date_created":"2022-02-22T20:10:36Z","summary":null,"body":["<article data-history-node-id=\"2990\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-089\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-089<br \/>\nDate: 22 February 2022<\/strong><\/p>\n\n<p>On 22 February 2022 Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could cause a denial of service, privilege escalation and information disclosure or lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5295-2\">Ubuntu Security Notice (USN-5295-2)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5297-1\">Ubuntu Security Notice (USN-5297-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5294-2\">Ubuntu Security Notice (USN-5294-2)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5298-1\">Ubuntu Security Notice (USN-5298-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5299-1\">Ubuntu Security Notice (USN-5299-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices  \">Ubuntu Security Notices<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-089","alert_type":396,"serial_number":"AV22-089","subject":null,"moderation_state":"published","external_url":null},{"nid":2991,"title":"Red Hat security advisory (AV22-090)","uuid":"526bba7d-5839-4873-b841-68bd68570207","banner":null,"lang":"en","date_modified":"2022-02-22","date_modified_ts":"2022-02-22T20:15:15Z","date_created":"2022-02-22T20:15:15Z","summary":null,"body":["<article data-history-node-id=\"2991\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-090\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-090<br \/>\nDate: 22 February 2022<\/strong><\/p>\n\n<p>On 22 February 2022 Red Hat published Security Advisories to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories\">Red Hat Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-090","alert_type":396,"serial_number":"AV22-090","subject":null,"moderation_state":"published","external_url":null},{"nid":2992,"title":"Dell security advisory (AV22-091)","uuid":"346d9da8-39b1-4922-9800-6484161fc351","banner":null,"lang":"en","date_modified":"2022-02-22","date_modified_ts":"2022-02-22T20:17:53Z","date_created":"2022-02-22T20:17:53Z","summary":null,"body":["<article data-history-node-id=\"2992\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-091\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-091<br \/>\nDate: 22 February 2022<\/strong><\/p>\n\n<p>On 22 February 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Integrated Data Protection Appliance \u2013 versions prior to 2.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196568\/dsa-2022-052-dell-emc-integrated-data-protection-appliance-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000196568)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-091","alert_type":396,"serial_number":"AV22-091","subject":null,"moderation_state":"published","external_url":null},{"nid":2993,"title":"[Control systems] Siemens security advisory (AV22-092)","uuid":"5525f045-bb9a-4c4d-917e-0067af99046d","banner":null,"lang":"en","date_modified":"2022-02-23","date_modified_ts":"2022-02-23T12:52:17Z","date_created":"2022-02-23T12:52:17Z","summary":null,"body":["<article data-history-node-id=\"2993\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-092\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-092<br \/>\nDate: 23 February 2022<\/strong><\/p>\n\n<p>On 22 February 2022 Siemens published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SIMATIC Field PG M5 \u2013 all versions<\/li>\n\t<li>SIMATIC Field PG M6 \u2013 all versions<\/li>\n\t<li>SIMATIC Industrial PC \u2013 multiple versions and platforms<\/li>\n\t<li>SIMATIC ITP1000 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-306654.pdf\">Siemens Security Publications (SSA-306654)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-092","alert_type":398,"serial_number":"AV22-092","subject":null,"moderation_state":"published","external_url":null},{"nid":2994,"title":"Google Chrome security advisory (AV22-093)","uuid":"6b91cc7c-51b3-4987-ab1e-2b3fe9905291","banner":null,"lang":"en","date_modified":"2022-02-23","date_modified_ts":"2022-02-23T19:16:41Z","date_created":"2022-02-23T19:16:41Z","summary":null,"body":["<article data-history-node-id=\"2994\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-093\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-093<br \/>\nDate: 23 February 2022<\/strong><\/p>\n\n<p>On 22 February 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 98.0.4758.109<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/02\/stable-channel-update-for-desktop_22.html\">Google Chrome Security Advisory<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-093","alert_type":396,"serial_number":"AV22-093","subject":null,"moderation_state":"published","external_url":null},{"nid":2995,"title":"[Control systems] GE security advisory (AV22-094)","uuid":"280b69d5-f2dd-4b52-bacb-0ff185b6438b","banner":null,"lang":"en","date_modified":"2022-02-23","date_modified_ts":"2022-02-23T20:42:06Z","date_created":"2022-02-23T20:42:06Z","summary":null,"body":["<article data-history-node-id=\"2995\" about=\"\/en\/alerts-advisories\/control-systems-ge-security-advisory-av22-094\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-094<br \/>\nDate: 23 February 2022<\/strong><\/p>\n\n<p>On 22 February 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Proficy CIMPLICITY \u2013 all version<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure, privilege escalation and code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-053-01\">ICS Advisory (ICSA-22-053-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-053-02\">ICS Advisory (ICSA-22-053-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-security-advisory-av22-094","alert_type":398,"serial_number":"AV22-094","subject":null,"moderation_state":"published","external_url":null},{"nid":2996,"title":"[Control systems] WIN-911 security advisory (AV22-095)","uuid":"c3ad939e-85b1-4b7b-98ce-f81fe824296a","banner":null,"lang":"en","date_modified":"2022-02-24","date_modified_ts":"2022-02-24T13:05:16Z","date_created":"2022-02-24T13:05:16Z","summary":null,"body":["<article data-history-node-id=\"2996\" about=\"\/en\/alerts-advisories\/control-systems-win-911-security-advisory-av22-095\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-095<br \/>\nDate: 24 February 2022<\/strong><\/p>\n\n<p>On 22 February 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>WIN-911 2021 R1 \u2013 version 5.21.10<\/li>\n\t<li>WIN-911 2021 R2 \u2013 version 5.21.17<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-053-03\">ICS Advisory (ICSA-22-053-03)<\/a><\/p>\n\n<p><a href=\"https:\/\/supportdesk.win911.com\/support\/solutions\/articles\/24000074683-win-911-2021-r1-r2-file-permission-vulnerability\">WIN-911<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-win-911-security-advisory-av22-095","alert_type":398,"serial_number":"AV22-095","subject":null,"moderation_state":"published","external_url":null},{"nid":3006,"title":"Disruptive activity against Ukrainian organizations - update 1","uuid":"30218cec-9a21-49cd-965b-d506297d18fd","banner":null,"lang":"en","date_modified":"2022-02-25","date_modified_ts":"2022-02-25T18:47:07Z","date_created":"2022-02-24T18:59:35Z","summary":null,"body":["<article data-history-node-id=\"3006\" about=\"\/en\/alerts-advisories\/disruptive-activity-against-ukrainian-organizations\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL22-002\n  <br \/><strong>Date:<\/strong> 24 February 2022\n  <br \/><strong>Updated:<\/strong> 25 February 2022\n<\/p>\n<h2>Audience\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>Purpose\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>Overview\n<\/h2>\n<p>On 23 February 2022 the Canadian Centre for Cyber Security (Cyber Centre) became aware of a new disruptive malware, named HermeticWiper, targeting Ukrainian organizations <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.\n<\/p>\n<p>This Alert is being released to raise awareness and share open-source indicators associated with this activity.\n<\/p>\n<h2>Details\n<\/h2>\n<p>On 23 February 2022 the Canadian Centre for Cyber Security (Cyber Centre) became aware of a new disruptive malware, named HermeticWiper, targeting Ukrainian organizations <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.\n<\/p>\n<p>HermeticWiper abuses a benign driver to corrupt the Master Boot Record (MBR) of every physical drive and each drive partition to make the victim system inoperable after machine shutdown. HermeticWiper also modifies several registry keys to disable system crash dumps.\n<\/p>\n<p>The malware has additional functionalities that are being investigated.\n<\/p>\n<p>The referenced SentinelLabs blog post <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> provides indicators of compromise for system owners and operators responsible for defending their systems and networks from cyber threats. The Cyber Centre has not verified the technical details described in this disclosure and is providing this information as is for situational awareness and potential action. <strong>It is important to verify business services and network environments before implementing any blocks based on these indicators.<\/strong> The Cyber Centre does not accept liability for negative consequences resulting from the use of the information provided herein.\n<\/p>\n<p>The Cyber Centre has currently received no indication of activity in Canada but is amplifying this information out of an abundance of caution. If the Cyber Centre acquires any additional information on this topic, it will be provided through an update or additional publication.\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<h2>Update 1\n<\/h2>\n<p>In addition to SentinelLabs <sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, several security vendors have published articles detailing the HermeticWiper malware, named according to the digital certificate, and its associated indicators of compromise.\n<\/p>\n<p>ESET published a summary of the activity surrounding the disruption and provided hashes for both Symantec and SentinelLabs reports <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.\n<\/p>\n<p>Zscalar published an in-depth article that provides a technical analysis of actor infrastructure, HermeticWiper, and other related malware <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. Zscalar also provides details, including indicators of compromise, regarding targeted campaigns against commercial and public entities in Ukraine.\n<\/p>\n<p>Symantec published an article that provides several additional indicators of compromise and economic sectors targeted by the malware <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. Symantec has identified evidence of related malicious activity beginning as early as November 2021. Ransomware may also have been deployed against victims at the same time as HermeticWiper.\n<\/p>\n<!-- ENDNOTES SECTION -->\n<section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References\n    <\/h2>\n    <dl><dt>1\n      <\/dt>\n      <dd id=\"fn1\">\n        <p>HermeticWiper\u00a0| <a href=\"https:\/\/www.sentinelone.com\/labs\/hermetic-wiper-ukraine-under-attack\/\">New Destructive Malware Used In Cyber Attacks on Ukraine<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>2\n      <\/dt>\n      <dd id=\"fn2\">\n        <p>HermeticWiper\u00a0| <a href=\"https:\/\/www.welivesecurity.com\/2022\/02\/24\/hermeticwiper-new-data-wiping-malware-hits-ukraine\/\">New data\u2011wiping malware hits Ukraine<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>3\n      <\/dt>\n      <dd id=\"fn3\">\n        <p><a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/hermetic-wiper-resurgence-targeted-attacks-ukraine\">Hermetic Wiper &amp; resurgence of targeted attacks on Ukraine<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>4\n      <\/dt>\n      <dd id=\"fn4\">\n        <p><a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/ukraine-wiper-malware-russia\">Ukraine: Disk-wiping Attacks Precede Russian Invasion<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n    <\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/disruptive-activity-against-ukrainian-organizations","alert_type":397,"serial_number":"AL22-002","subject":null,"moderation_state":"published","external_url":null},{"nid":2997,"title":"Cisco security advisory (AV22-096)","uuid":"c50120ec-7ed3-45ab-9fdf-67002d5e94cf","banner":null,"lang":"en","date_modified":"2022-02-24","date_modified_ts":"2022-02-24T19:28:04Z","date_created":"2022-02-24T19:28:04Z","summary":null,"body":["<article data-history-node-id=\"2997\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-096\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-096<br \/>\nDate: 24 February 2022<\/strong><\/p>\n\n<p>On 23 February 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Nexus 3000, 6000, 9000 and 9500 series switches \u2013 multiple models and versions<\/li>\n\t<li>Nexus 5500, 5600, 9200 and 9300 platform switches \u2013 multiple models and versions<\/li>\n\t<li>NX-OS software \u2013 multiple platforms<\/li>\n\t<li>UCS 6400 series fabric interconnects<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow for arbitrary code execution or cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-bfd-dos-wGQXrzxn\">Cisco Nexus Security Advisory<\/a><br \/><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-nxapi-cmdinject-ULukNMZ2#fs\">Cisco NX-OS Security Advisory<\/a><br \/><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cfsoip-dos-tpykyDr\">Cisco NX-OS Fabric Security advisory<\/a><br \/><br \/><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-096","alert_type":396,"serial_number":"AV22-096","subject":null,"moderation_state":"published","external_url":null},{"nid":2999,"title":"Red Hat security advisory (AV22-097)","uuid":"29d9fdee-7f00-4f95-b054-104f57dd4df5","banner":null,"lang":"en","date_modified":"2022-02-25","date_modified_ts":"2022-02-25T13:59:50Z","date_created":"2022-02-25T13:59:50Z","summary":null,"body":["<article data-history-node-id=\"2999\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-097\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-097<br \/>\nDate: 24 February 2022<\/strong><\/p>\n\n<p>On 23 February 2022 Red Hat published Security Advisories to address Samba vulnerabilities in the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><br \/><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:0663\">Red Hat Security Advisory (RHSA-2022:0663)<\/a><br \/><br \/><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:0664\">Red Hat Security Advisory (RHSA-2022:0664)<\/a><br \/><br \/><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/samba-security-advisory-av22-047\">Samba security advisory (AV22-047)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-097","alert_type":396,"serial_number":"AV22-097","subject":null,"moderation_state":"published","external_url":null},{"nid":2998,"title":" [Control systems] Schneider Electric security advisory (AV22-098) ","uuid":"313516bb-6cec-4a8d-a8bb-515a2227f634","banner":null,"lang":"en","date_modified":"2022-02-25","date_modified_ts":"2022-02-25T14:04:19Z","date_created":"2022-02-25T14:04:19Z","summary":null,"body":["<article data-history-node-id=\"2998\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-098\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-098<br \/>\nDate: 24 February 2022<\/strong><\/p>\n\n<p>On 24 February 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Easergy P3 \u2013 firmware versions prior to v30.205<\/li>\n\t<li>Easergy P5 \u2013 firmware versions prior to v01.401.101<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, information disclosure or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-055-03\">ICS Advisory (ICSA-22-055-03)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-098","alert_type":398,"serial_number":"AV22-098","subject":null,"moderation_state":"published","external_url":null},{"nid":3000,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-099)","uuid":"7a21c180-22d9-4ff3-8b98-71bb7a715e51","banner":null,"lang":"en","date_modified":"2022-02-25","date_modified_ts":"2022-02-25T17:05:10Z","date_created":"2022-02-25T17:05:10Z","summary":null,"body":["<article data-history-node-id=\"3000\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-099\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-099<br \/>\nDate: 25 February 2022<\/strong><\/p>\n\n<p>On 24 February 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoWebServerIII\n\t<ul><li>MES3-255C-EN \u2013 versions 3.0.0 to 3.3.0<\/li>\n\t\t<li>MES3-255C-DM-EN \u2013 versions 3.0.0 to 3.3.0<\/li>\n\t\t<li>MES3-255C-CN \u2013 versions 3.0.0 to 3.3.0<\/li>\n\t\t<li>MES3-255C-DM-CN \u2013 versions 3.0.0 to 3.3.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure, unauthorized data modification or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-055-02\">ICS Advisory (ICSA-22-055-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-099","alert_type":398,"serial_number":"AV22-099","subject":null,"moderation_state":"published","external_url":null},{"nid":3001,"title":"[Control systems] FATEK Automation security advisory (AV22-100)","uuid":"2c9c16da-f6e3-49c0-bfd4-6d6ee3c10176","banner":null,"lang":"en","date_modified":"2022-02-25","date_modified_ts":"2022-02-25T19:45:26Z","date_created":"2022-02-25T19:45:26Z","summary":null,"body":["<article data-history-node-id=\"3001\" about=\"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-av22-100\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-100<br \/>\nDate: 25 February 2022<\/strong><\/p>\n\n<p>On 24 February 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>FvDesigner \u2013 versions 1.5.100 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-055-01 \">ICS Advisory (ICSA-22-055-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-av22-100","alert_type":398,"serial_number":"AV22-100","subject":null,"moderation_state":"published","external_url":null},{"nid":3002,"title":"[Control systems] Bently Nevada security advisory (AV22-101)","uuid":"a1951ac3-a676-402f-99c2-1e08b7557137","banner":null,"lang":"en","date_modified":"2022-02-25","date_modified_ts":"2022-02-25T19:48:25Z","date_created":"2022-02-25T19:48:25Z","summary":null,"body":["<article data-history-node-id=\"3002\" about=\"\/en\/alerts-advisories\/control-systems-bently-nevada-security-advisory-av22-101\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-101<br \/>\nDate: 25 February 2022<\/strong><\/p>\n\n<p>On 24 February 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>3500 software \u2013 multiple models and versions<\/li>\n\t<li>System 1 software \u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to obtain credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-21-231-02 \">ICS Advisory (ICSA-21-231-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bently-nevada-security-advisory-av22-101","alert_type":398,"serial_number":"AV22-101","subject":null,"moderation_state":"published","external_url":null},{"nid":3003,"title":"Mozilla security advisory (AV22-102)","uuid":"3699a41f-ee3a-425b-abb5-70891cd46742","banner":null,"lang":"en","date_modified":"2022-02-25","date_modified_ts":"2022-02-25T20:39:15Z","date_created":"2022-02-25T20:39:15Z","summary":null,"body":["<article data-history-node-id=\"3003\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-102\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-102<br \/>\nDate: 25 February 2022<\/strong><\/p>\n\n<p>On 23 February 2022 Mozilla published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Mozilla VPN \u2013 versions prior to 2.7.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-08\/\">Mozilla VPN (MFSA 2022-08)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-102","alert_type":396,"serial_number":"AV22-102","subject":null,"moderation_state":"published","external_url":null},{"nid":3004,"title":"Dell security advisory (AV22-103)","uuid":"aa989417-e4e5-4c0f-91eb-deeb5776d01f","banner":null,"lang":"en","date_modified":"2022-02-28","date_modified_ts":"2022-02-28T15:43:28Z","date_created":"2022-02-28T15:43:28Z","summary":null,"body":["<article data-history-node-id=\"3004\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-103\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-103<br \/>\nDate: 28 February 2022<\/strong><\/p>\n\n<p>On 23 February 2022 Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC VPLEX \u2013 versions prior to BIOS 2.5.1, iDRAC 4.40.40.00 and NIC 21.80.9<\/li>\n\t<li>Dell EMC VxRail Appliance \u2013 versions 7.0.x prior to 7.0.350<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196668\/dsa-2022-060-dell-emc-vs2-server-pe-security-update-for-multiple-security-vulnerabilities\">Dell Security Advisory (000196668)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196707\/dsa-2022-056-dell-emc-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000196707)<\/a><br \/><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-103","alert_type":396,"serial_number":"AV22-103","subject":null,"moderation_state":"published","external_url":null},{"nid":3005,"title":"HPE security advisory (AV22-104)","uuid":"c0660b28-6671-49ff-9527-d9f7ea5c33e4","banner":null,"lang":"en","date_modified":"2022-02-28","date_modified_ts":"2022-02-28T15:49:51Z","date_created":"2022-02-28T15:49:51Z","summary":null,"body":["<article data-history-node-id=\"3005\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-104\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-104<br \/>\nDate: 28 February 2022<\/strong><\/p>\n\n<p>On 24 February 2022, HPE published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Series Switches with AOS-CX firmware \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution, remote execution of arbitrary commands, denial of service or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04259en_us\">HPE Security Bulletin (hpesbnw04259en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-104","alert_type":396,"serial_number":"AV22-104","subject":null,"moderation_state":"published","external_url":null},{"nid":3007,"title":"IBM security advisory (AV22-105)","uuid":"e5d7c0fe-6e15-49f8-bb60-e46ac1cbe6af","banner":null,"lang":"en","date_modified":"2022-02-28","date_modified_ts":"2022-02-28T17:21:06Z","date_created":"2022-02-28T17:21:06Z","summary":null,"body":["<article data-history-node-id=\"3007\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-105\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-105<br \/>\nDate: 28 February 2022<\/strong><\/p>\n\n<p>Between 21 and 27 February 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Cloud Pak for Data System \u2013 versions 2.0.0.0 to 2.0.1.1<\/li>\n\t<li>IBM HTTP Server \u2013 multiple versions<\/li>\n\t<li>IBM Netezza for Cloud Pak for Data \u2013 versions 11.1.0.0 to 11.2.1.3<\/li>\n\t<li>IBM Planning Analytics \u2013 version 2.0<\/li>\n\t<li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n\t<li>IBM WebSphere Application Server Liberty \u2013 versions 17.0.0.3 to 22.0.0.2<\/li>\n\t<li>IBM WebSphere Application Server \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-105","alert_type":396,"serial_number":"AV22-105","subject":null,"moderation_state":"published","external_url":null},{"nid":3008,"title":"[Control systems] ABB security advisory (AV22-106)","uuid":"a4d0864c-5bb3-4f03-9500-125211e7cae7","banner":null,"lang":"en","date_modified":"2022-02-28","date_modified_ts":"2022-02-28T20:15:28Z","date_created":"2022-02-28T20:15:28Z","summary":null,"body":["<article data-history-node-id=\"3008\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-106\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-106<br \/>\nDate: 28 February 2022<\/strong><\/p>\n\n<p>On 17 February 2022 ABB published a Cyber Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>800xA, Control Software for AC 800M \u2013 multiple versions<\/li>\n\t<li>Control Builder Safe \u2013 multiple versions<\/li>\n\t<li>Compact Product Suite Control and I\/O \u2013 multiple versions<\/li>\n\t<li>ABB Base Software for SoftControl \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA001499&amp;Action=Launch\">ABB Cyber Security Advisory (7PAA001499)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-106","alert_type":398,"serial_number":"AV22-106","subject":null,"moderation_state":"published","external_url":null},{"nid":3009,"title":"Fortinet security advisory (AV22-107)","uuid":"f21731e3-dff7-4d07-b2a3-a38e24d39efa","banner":null,"lang":"en","date_modified":"2022-03-02","date_modified_ts":"2022-03-02T13:36:35Z","date_created":"2022-03-02T13:36:35Z","summary":null,"body":["<article data-history-node-id=\"3009\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-107\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-107<br \/>\nDate: 2 March 2022<\/strong><\/p>\n\n<p>On 1 March 2022 Fortinet published PSIRT Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>FortiMail \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-107","alert_type":396,"serial_number":"AV22-107","subject":null,"moderation_state":"published","external_url":null},{"nid":3010,"title":"Google Chrome security advisory (AV22-108)","uuid":"f0223e97-0719-429c-bfaa-caa1e05df524","banner":null,"lang":"en","date_modified":"2022-03-02","date_modified_ts":"2022-03-02T13:39:32Z","date_created":"2022-03-02T13:39:32Z","summary":null,"body":["<article data-history-node-id=\"3010\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-108\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-108<br \/>\nDate: 2 March 2022<\/strong><\/p>\n\n<p>On 1 March 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 99.0.4844.51<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/03\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-108","alert_type":396,"serial_number":"AV22-108","subject":null,"moderation_state":"published","external_url":null},{"nid":3011,"title":"Cisco security advisory (AV22-109)","uuid":"12191a0f-03ed-495a-9b81-cdc006b465eb","banner":null,"lang":"en","date_modified":"2022-03-02","date_modified_ts":"2022-03-02T19:05:19Z","date_created":"2022-03-02T19:05:19Z","summary":null,"body":["<article data-history-node-id=\"3011\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-109\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-109<br \/>\nDate: 2 March 2022<\/strong><\/p>\n\n<p>On 2 March 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Expressway Series \u2013 version 14.0 and prior<\/li>\n\t<li>Cisco TelePresence VCS \u2013 version 14.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an actor to execute arbitrary code or overwrite critical files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-expressway-filewrite-87Q5YRk\">Cisco Security Bulletin<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-109","alert_type":396,"serial_number":"AV22-109","subject":null,"moderation_state":"published","external_url":null},{"nid":3012,"title":"Dell security advisory (AV22-110)","uuid":"d13d8392-105f-4ab8-a625-0796332861fa","banner":null,"lang":"en","date_modified":"2022-03-03","date_modified_ts":"2022-03-03T16:19:00Z","date_created":"2022-03-03T16:19:00Z","summary":null,"body":["<article data-history-node-id=\"3012\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-110\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-110<br \/>\nDate: 3 March 2022<\/strong><\/p>\n\n<p>Between 28 February and 2 March 2022 Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC Data Protection Advisor (DPA) \u2013 multiple versions<\/li>\n\t<li>Dell EMC Enterprise Hybrid Cloud \u2013 versions prior to 4.1.2<\/li>\n\t<li>Dell EMC NetWorker vProxy \u2013 version 4.3.0-15 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196859\/dsa-2022-058-dell-emc-enterprise-hybrid-cloud-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000196859)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196827\/dsa-2022-061-dell-emc-data-protection-advisor-dpa-security-update-for-third-party-vulnerabilities\">Dell Security Advisory (000196827)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000196911\/dsa-2022-055-dell-emc-networker-vproxy-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Advisory (000196911)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-110","alert_type":396,"serial_number":"AV22-110","subject":null,"moderation_state":"published","external_url":null},{"nid":3013,"title":"[Control systems] BD security advisory (AV22-111)","uuid":"59730ae3-017b-4468-85ea-e40bcc2595b4","banner":null,"lang":"en","date_modified":"2022-03-04","date_modified_ts":"2022-03-04T12:26:20Z","date_created":"2022-03-04T12:26:20Z","summary":null,"body":["<article data-history-node-id=\"3013\" about=\"\/en\/alerts-advisories\/control-systems-bd-security-advisory-av22-111\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-111<br \/>\nDate: 4 March 2022<\/strong><\/p>\n\n<p>On 3 March 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>BD Pyxis Anesthesia Station ES \u2013 all versions<\/li>\n\t<li>BD Pyxis Anesthesia Station 4000 \u2013 all versions<\/li>\n\t<li>BD Pyxis CATO \u2013 all versions<\/li>\n\t<li>BD Pyxis CIISafe \u2013 all versions<\/li>\n\t<li>BD Pyxis Inventory Connect \u2013 all versions<\/li>\n\t<li>BD Pyxis IV Prep \u2013 all versions<\/li>\n\t<li>BD Pyxis JITrBUD \u2013 all versions<\/li>\n\t<li>BD Pyxis KanBan RF \u2013 all versions<\/li>\n\t<li>BD Pyxis Logistics \u2013 all versions<\/li>\n\t<li>BD Pyxis Med Link Family \u2013 all versions<\/li>\n\t<li>BD Pyxis MedBank \u2013 all versions<\/li>\n\t<li>BD Pyxis MedStation 4000 \u2013 all versions<\/li>\n\t<li>BD Pyxis MedStation ES \u2013 all versions<\/li>\n\t<li>BD Pyxis MedStation ES Server \u2013 all versions<\/li>\n\t<li>BD Pyxis ParAssist \u2013 all versions<\/li>\n\t<li>BD Pyxis PharmoPack \u2013 all versions<\/li>\n\t<li>BD Pyxis ProcedureStation (including EC) \u2013 all versions<\/li>\n\t<li>BD Pyxis Rapid Rx \u2013 all versions<\/li>\n\t<li>BD Pyxis StockStation \u2013 all versions<\/li>\n\t<li>BD Pyxis SupplyCenter \u2013 all versions<\/li>\n\t<li>BD Pyxis SupplyRoller \u2013 all versions<\/li>\n\t<li>BD Pyxis SupplyStation (including RF, EC, CP) \u2013 all versions<\/li>\n\t<li>BD Pyxis Track and Deliver \u2013 all versions<\/li>\n\t<li>BD Rowa Pouch Packaging Systems \u2013 all versions<\/li>\n\t<li>BD Viper LT system \u2013 version 2.0 and later<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-062-01\">ICS Advisory (ICSMA-22-062-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-062-02\">ICS Advisory (ICSMA-22-062-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bd-security-advisory-av22-111","alert_type":398,"serial_number":"AV22-111","subject":null,"moderation_state":"published","external_url":null},{"nid":3014,"title":"[Control systems] IPCOMM security advisory (AV22-112)","uuid":"68339ecf-e47b-4e59-a68f-dac87244e69b","banner":null,"lang":"en","date_modified":"2022-03-04","date_modified_ts":"2022-03-04T12:31:55Z","date_created":"2022-03-04T12:31:55Z","summary":null,"body":["<article data-history-node-id=\"3014\" about=\"\/en\/alerts-advisories\/control-systems-ipcomm-security-advisory-av22-112\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-112<br \/>\nDate: 4 March 2022<\/strong><\/p>\n\n<p>On 3 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ipDIO \u2013 firmware version 3.9 2016\/04\/18 \/ IPDIO SW 3.9<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-062-01\">ICS Advisory (ICSA-22-062-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ipcomm-security-advisory-av22-112","alert_type":398,"serial_number":"AV22-112","subject":null,"moderation_state":"published","external_url":null},{"nid":3015,"title":"[Control systems] B&R Industrial Automation security advisory (AV22-113)","uuid":"4308a9da-2e32-4077-a652-ebdf5442bc02","banner":null,"lang":"en","date_modified":"2022-03-04","date_modified_ts":"2022-03-04T15:01:57Z","date_created":"2022-03-04T15:01:57Z","summary":null,"body":["<article data-history-node-id=\"3015\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-av22-113\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-113<br \/>\nDate: 4 March 2022<\/strong><\/p>\n\n<p>On 3 March 2022 B&amp;R Industrial Automation published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>B&amp;R APROL AutoYaST \u2013 version V4.2-064.0.211004 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1644947115875-en-original-1.0.pdf\">Cyber Security Advisory (#02\/2022)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-av22-113","alert_type":398,"serial_number":"AV22-113","subject":null,"moderation_state":"published","external_url":null},{"nid":3016,"title":"Microsoft Edge security advisory (AV22-114)","uuid":"9487c9a9-e45f-4c48-9057-8149e7af514c","banner":null,"lang":"en","date_modified":"2022-03-04","date_modified_ts":"2022-03-04T15:04:28Z","date_created":"2022-03-04T15:04:28Z","summary":null,"body":["<article data-history-node-id=\"3016\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-114\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-114<br \/>\nDate: 4 March 2022<\/strong><\/p>\n\n<p>On 3 March 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 99.0.1150.30<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-3-2022\">Microsoft Edge Stable Channel Release Notes<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-114","alert_type":396,"serial_number":"AV22-114","subject":null,"moderation_state":"published","external_url":null},{"nid":3017,"title":"Dell security advisory (AV22-115)","uuid":"ba2a6173-ee08-4ffc-bed8-cbe0228c9a5e","banner":null,"lang":"en","date_modified":"2022-03-07","date_modified_ts":"2022-03-07T14:54:50Z","date_created":"2022-03-07T14:54:50Z","summary":null,"body":["<article data-history-node-id=\"3017\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-115\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-115<br \/>\nDate: 7 March 2022<\/strong><\/p>\n\n<p>On 3 March 2022 Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC SRM \u2013 versions prior to 4.7.0.1<\/li>\n\t<li>Dell EMC SRM Vapp \u2013 versions prior to 4.7.0.1<\/li>\n\t<li>Dell EMC SMR \u2013 versions prior to 4.7.0.1<\/li>\n\t<li>Dell EMC SMR Vapp \u2013 versions prior to 4.7.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000196956\/dsa-2022-049-dell-emc-srm-and-dell-emc-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000196956)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Dell Security Advisories<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-115","alert_type":396,"serial_number":"AV22-115","subject":null,"moderation_state":"published","external_url":null},{"nid":3018,"title":"[Control systems] Trailer Power Line Communications security advisory (AV22-116)","uuid":"f06dad63-7068-497f-9db0-f6b7beab8b00","banner":null,"lang":"en","date_modified":"2022-03-07","date_modified_ts":"2022-03-07T14:58:00Z","date_created":"2022-03-07T14:58:00Z","summary":null,"body":["<article data-history-node-id=\"3018\" about=\"\/en\/alerts-advisories\/control-systems-trailer-power-line-communications-security-advisory-av22-116\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-116<br \/>\nDate: 7 March 2022<\/strong><\/p>\n\n<p>On 4 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Power Line Communications (PLC): J2497 (PLC4TRUCKS) \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in the execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-063-01\">ICS Advisory (ICSA-22-063-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-trailer-power-line-communications-security-advisory-av22-116","alert_type":398,"serial_number":"AV22-116","subject":null,"moderation_state":"published","external_url":null},{"nid":3020,"title":"IBM security advisory (AV22-118)","uuid":"a0266b3e-6713-43e7-bbfc-794f8634aca1","banner":null,"lang":"en","date_modified":"2022-03-07","date_modified_ts":"2022-03-07T16:23:12Z","date_created":"2022-03-07T16:23:12Z","summary":null,"body":["<article data-history-node-id=\"3020\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-118\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-118<br \/>\nDate: 07 March 2022<\/strong><\/p>\n\n<p>Between 28 February and 6 March 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Build Forge \u2013 versions 8.0 to 8.0.0.20<\/li>\n\t<li>IBM Cloud Object Storage Systems \u2013 versions 3.16.3.47 and prior<\/li>\n\t<li>IBM HTTP Server \u2013 versions 7.0, 8.0, 8.5 and 9.0<\/li>\n\t<li>IBM QRadar SIEM \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Spectrum Control \u2013 versions 5.4.0 to 5.4.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-118","alert_type":396,"serial_number":"AV22-118","subject":null,"moderation_state":"published","external_url":null},{"nid":3019,"title":"Mozilla security advisory (AV22-117)","uuid":"5fe29f04-4240-493b-9a10-b179b48ae32d","banner":null,"lang":"en","date_modified":"2022-03-07","date_modified_ts":"2022-03-07T16:27:57Z","date_created":"2022-03-07T16:27:57Z","summary":null,"body":["<article data-history-node-id=\"3019\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-117\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-117<br \/>\nDate: 7 March 2022<\/strong><\/p>\n\n<p>On 5 March 2022 Mozilla published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 97.0.2<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.6.1<\/li>\n\t<li>Firefox for Android \u2013 versions prior to 97.3<\/li>\n\t<li>Focus \u2013 versions prior to 97.3<\/li>\n\t<li>Thunderbird \u2013 versions prior to 91.6.2<\/li>\n<\/ul><p>Mozilla has received reports that these vulnerabilities have been actively exploited.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-09\">Mozilla Security Advisory (MFSA 2022-09)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-117","alert_type":396,"serial_number":"AV22-117","subject":null,"moderation_state":"published","external_url":null},{"nid":3021,"title":"Android security advisory \u2013 March 2022 monthly rollup (AV22-119)","uuid":"9bdc8b51-a7ba-4e85-a9cb-879247a13e87","banner":null,"lang":"en","date_modified":"2022-03-07","date_modified_ts":"2022-03-07T19:38:36Z","date_created":"2022-03-07T19:38:36Z","summary":null,"body":["<article data-history-node-id=\"3021\" about=\"\/en\/alerts-advisories\/android-security-advisory-march-2022-monthly-rollup-av22-119\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-119<br \/>\nDate: 7 March 2022<\/strong><\/p>\n\n<p>On 7 March 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\" https:\/\/source.android.com\/security\/bulletin\/2022-03-01\">Android Security Bulletin<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-march-2022-monthly-rollup-av22-119","alert_type":396,"serial_number":"AV22-119","subject":null,"moderation_state":"published","external_url":null},{"nid":3022,"title":"[Control systems] Siemens security advisory (AV22-120)","uuid":"4cccda47-3c36-4731-8956-d57300f4d65f","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T15:44:57Z","date_created":"2022-03-08T15:44:57Z","summary":null,"body":["<article data-history-node-id=\"3022\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-120\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-120<br \/>\nDate: 8 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Mendix Forgot Password Appstore module \u2013 multiple versions<\/li>\n\t<li>RUGGEDCOM ROX RX \u2013 versions prior to V2.15.0<\/li>\n\t<li>SINEC INS \u2013 versions prior to V1.0.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-134279.pdf\">Siemens Security Advisory (SSA-134279)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-594438.pdf\">Siemens Security Advisory (SSA-594438)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/pdf\/ssa-389290.pdf\">Siemens Security Advisory (SSA-389290)<\/a><\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-120","alert_type":398,"serial_number":"AV22-120","subject":null,"moderation_state":"published","external_url":null},{"nid":3023,"title":"[Control systems] Schneider Electric security advisory (AV22-121)","uuid":"ade86cb0-1796-42b0-949b-a12f44d78c3f","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T15:50:39Z","date_created":"2022-03-08T15:50:39Z","summary":null,"body":["<article data-history-node-id=\"3023\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-121\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-121<br \/>\nDate: 8 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Schneider Electric published Security Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Control Expert \u2013 version V15.0 SP1 and prior<\/li>\n\t<li>EcoStruxure Process Expert \u2013 version V2021 and prior<\/li>\n\t<li>Ritto Wiser Door \u2013 all versions<\/li>\n\t<li>SmartConnect Family \u2013 multiple versions and platforms<\/li>\n\t<li>Smart-UPS Family \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-067-01\">Schneider Security Advisory (SEVD-2022-067-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-067-02\">Schneider Security Advisory (SEVD-2022-067-02)<\/a><\/p>\n\n<p><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-067-03\">Schneider Security Advisory (SEVD-2022-067-03)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-121","alert_type":398,"serial_number":"AV22-121","subject":null,"moderation_state":"published","external_url":null},{"nid":3024,"title":"Mozilla security advisory (AV22-122)","uuid":"31cd9777-4af5-4899-9658-c6f44430d9df","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T16:04:44Z","date_created":"2022-03-08T16:04:44Z","summary":null,"body":["<article data-history-node-id=\"3024\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-122\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-122<br \/>\nDate: 8 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 98<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-10 \">Mozilla Security Advisory (MFSA 2022-10)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-11\/\">Mozilla Security Advisory (MFSA 2022-11)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-122","alert_type":396,"serial_number":"AV22-122","subject":null,"moderation_state":"published","external_url":null},{"nid":3025,"title":"Mitel security advisory (AV22-123)","uuid":"f9c7bef4-5844-460f-8ae3-4b38d9edcad1","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T17:17:58Z","date_created":"2022-03-08T17:17:58Z","summary":null,"body":["<article data-history-node-id=\"3025\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av22-123\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-123<br \/>\nDate: 8 March 2022<\/strong><\/p>\n\n<p>On 22 February 2022 Mitel published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Mitel MiCollab \u2013 version R9.4SP1 and prior<\/li>\n\t<li>MiVoice Business Express \u2013 version R8.1 and prior<\/li>\n<\/ul><p>The Cyber Centre is aware of reports that this vulnerability may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-22-0001\">Mitel Product Security Advisory (22-0001)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av22-123","alert_type":396,"serial_number":"AV22-123","subject":null,"moderation_state":"published","external_url":null},{"nid":3026,"title":"[Control systems] PTC security advisory (AV22-124)","uuid":"459fff20-9c02-4076-a4da-74746734c779","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T19:53:20Z","date_created":"2022-03-08T19:53:20Z","summary":null,"body":["<article data-history-node-id=\"3026\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av22-124\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-124<br \/>\nDate: 8 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Axeda agent \u2013 all versions<\/li>\n\t<li>Axeda Desktop Server for Windows \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, unauthorized access and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-067-01\">ICS Advisory (ICSA-22-067-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.forescout.com\/blog\/access-7-vulnerabilities-impact-supply-chain-component-in-medical-and-iot-device-models\/\">Forescout Research Labs ACCESS:7 Report<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av22-124","alert_type":398,"serial_number":"AV22-124","subject":null,"moderation_state":"published","external_url":null},{"nid":3027,"title":"[Control systems] AVEVA security advisory (AV22-125)","uuid":"1d08f16e-6ed2-46d5-b05a-cbbaf93067d9","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T19:56:42Z","date_created":"2022-03-08T19:56:42Z","summary":null,"body":["<article data-history-node-id=\"3027\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-125\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-125<br \/>\nDate: 8 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>AVEVA System Platform 2020 R2 P01<\/li>\n\t<li>AVEVA System Platform 2020 R2S<\/li>\n\t<li>AVEVA System Platform 2020<\/li>\n<\/ul><p>Successful exploitation of this vulnerability may allow an actor to obtain credentials.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-067-02\">ICS Advisory (ICSA-22-067-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-125","alert_type":398,"serial_number":"AV22-125","subject":null,"moderation_state":"published","external_url":null},{"nid":3028,"title":"Microsoft security advisory \u2013 March 2022 monthly rollup (AV22-126)","uuid":"8a4c7969-b962-49ff-abfd-2d7cd1ea9ba5","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T20:28:05Z","date_created":"2022-03-08T20:28:05Z","summary":null,"body":["<article data-history-node-id=\"3028\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-march-2022-monthly-rollup-av22-126\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-126<br \/>\nDate: 8 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>.NET \u2013 multiple versions<\/li>\n\t<li>Azure Site Recovery \u2013 multiple versions<\/li>\n\t<li>Defender \u2013 multiple versions<\/li>\n\t<li>Exchange Server \u2013 multiple versions<\/li>\n\t<li>Intune Company Portal for iOS<\/li>\n\t<li>Microsoft 365 Apps for Enterprise \u2013 multiple platforms<\/li>\n\t<li>Microsoft Office \u2013 multiple versions and platforms<\/li>\n\t<li>Paint 3D<\/li>\n\t<li>Remote Desktop client for Desktop \u2013 multiple versions<\/li>\n\t<li>Skype Extension for Chrome<\/li>\n\t<li>Windows 11 \u2013 all versions<\/li>\n\t<li>Windows 10 \u2013 multiple versions<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions<\/li>\n\t<li>Windows 7 \u2013 multiple versions<\/li>\n\t<li>Windows Server \u2013 multiple versions<\/li>\n\t<li>Visual Studio \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Mar\">March 2022 Release Notes<\/a><\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-march-2022-monthly-rollup-av22-126","alert_type":396,"serial_number":"AV22-126","subject":null,"moderation_state":"published","external_url":null},{"nid":3029,"title":"Vulnerability in Mitel MiCollab and MiVoice Business Express","uuid":"74110f31-34b3-4462-bd4f-de30a529d1a3","banner":null,"lang":"en","date_modified":"2022-03-08","date_modified_ts":"2022-03-08T23:21:29Z","date_created":"2022-03-08T23:18:43Z","summary":null,"body":["<article data-history-node-id=\"3029\" about=\"\/en\/alerts-advisories\/vulnerability-mitel-micollab-and-mivoice-business-express\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL22-003\n  <br \/><strong>Date:<\/strong> 8 March 2022\n<\/p>\n<h2>Audience\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>Purpose\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>Overview\n<\/h2>\n<p>On 22 February 2022, Mitel published a security advisory addressing a security access vulnerability in their MiCollab and MiVoice Business Express products that may allow a remote unauthenticated actor to gain unauthorized access, potentially execute code or cause these systems to generate a denial of service (DoS) attack.\n<\/p>\n<h2>Details\n<\/h2>\n<p>On 22 February 2022 Mitel published a security advisory <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> addressing vulnerabilities in their MiCollab and MiVoice Business Express products. Exploitation of these vulnerabilities may result in unauthorized access to sensitive information and services or arbitrary code execution. By submitting specially-crafted messages, a remote actor can also abuse these systems to generate large volumes of network traffic that can be used in a denial of service (DoS) attack.\n<\/p>\n<p>On March 8, the Cyber Centre released a security advisory covering these Mitel products, and multiple sources published articles with details regarding this vulnerability and associated observed exploitation activity <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.\n<\/p>\n<p>Multiple sources <sup id=\"fn4b-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5b-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6b-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> have reported that this vulnerability has been exploited to achieve significant reflection\/amplification of traffic that has been abused to launch impactful DDoS activity. Reports indicate that exploitation of this vulnerability has resulted in amplification of 53 million packets per second, and that this activity can be sustained over several hours.\n<\/p>\n<h2>Mitigation\n<\/h2>\n<p>For organizations who have deployed these products, Mitel has recommended the following mitigations to protect these systems from external abuse:\n<\/p>\n<ul><li>Configure the systems behind a firewall or border gateway device to ensure MiCollab\/MiVoice are not exposed directly to the internet<\/li>\n  <li>Apply appropriate firewall rules to block external access to specific ports (UDP 10074)<\/li>\n  <li>Mitel has made a script available <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> to provide mitigation for this vulnerability<\/li>\n<\/ul><p>For defenders of network perimeters, it is recommended to use a layered approach to security by implementing multiple controls and techniques and to ensure that a plan is in place to mitigate and respond to DDoS attacks.\n<\/p>\n<ul><li>Review and implement guidance from the Cyber Centre publication <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> on protecting your organization against denial of service attacks<\/li>\n  <li>Monitor UDP ports for traffic incoming from UDP port 10074 and consider applying mitigations such as firewall rules if activity described in this Alert is observed<\/li>\n<\/ul><!-- ENDNOTES SECTION --><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References\n    <\/h2>\n    <dl><dt>1\n      <\/dt>\n      <dd id=\"fn1\">\n        <p><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-22-0001\" rel=\"external\">Mitel MiCollab and MiVoice Security Bulletin (ID: 22-0001)<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>2\n      <\/dt>\n      <dd id=\"fn2\">\n        <p><a href=\"https:\/\/mitel.custhelp.com\/app\/answers\/answer_view\/a_id\/1017561\" rel=\"external\">Security Access Control Remediation for MiCollab and MiVoice Business Express Servers (SO6795)<\/a> (Requires client account)\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>3\n      <\/dt>\n      <dd id=\"fn3\">\n        <p><a href=\"\/en\/alerts-advisories\/mitel-security-advisory-av22-123\">Canadian Centre for Cyber Security Mitel Security Advisory<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>4\n      <\/dt>\n      <dd id=\"fn4\">\n        <p><a href=\"https:\/\/www.akamai.com\/blog\/security\/phone-home-ddos-attack-vector\" rel=\"external\">CVE-2022-26143: TP240PhoneHome Reflection\/Amplification DDoS Attack Vector <\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>5\n      <\/dt>\n      <dd id=\"fn5\">\n        <p><a href=\"https:\/\/blog.cloudflare.com\/cve-2022-26143\/\" rel=\"external\">CVE-2022-26143: TP240PhoneHome Reflection\/Amplification DDoS Attack Vector<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>6\n      <\/dt>\n      <dd id=\"fn6\">\n        <p><a href=\"https:\/\/www.shadowserver.org\/news\/cve-2022-26143-tp240phonehome-reflection-amplification-ddos-attack-vector\/\" rel=\"external\">CVE-2022-26143: TP240PhoneHome Reflection\/Amplification DDoS Attack Vector<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n      <dt>7\n      <\/dt>\n      <dd id=\"fn7\">\n        <p><a href=\"\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\" rel=\"external\">Protecting Your Organization Against Denial of Service Attacks<\/a>\n        <\/p>\n        <p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a>\n        <\/p>\n      <\/dd>\n    <\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-mitel-micollab-and-mivoice-business-express","alert_type":397,"serial_number":"AL22-003","subject":null,"moderation_state":"published","external_url":null},{"nid":3030,"title":"SAP security advisory \u2013 March 2022 monthly rollup (AV22-127)","uuid":"b6fc5f30-394e-4d72-a164-5095dabe18a9","banner":null,"lang":"en","date_modified":"2022-03-09","date_modified_ts":"2022-03-09T17:29:04Z","date_created":"2022-03-09T17:29:04Z","summary":null,"body":["<article data-history-node-id=\"3030\" about=\"\/en\/alerts-advisories\/sap-security-advisory-march-2022-monthly-rollup-av22-127\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-127<br \/>\nDate: 9 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Work Manager \u2013 versions 6.4, 6.5 and 6.6<\/li>\n\t<li>SAP Inventory Manager \u2013 versions 4.3 and 4.4<\/li>\n\t<li>Simple Diagnostics Agent<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. \u00a0<\/p>\n\n<p><a href=\" https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10 \">SAP Security Patch Day \u2013 March 2022<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability  \">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-march-2022-monthly-rollup-av22-127","alert_type":396,"serial_number":"AV22-127","subject":null,"moderation_state":"published","external_url":null},{"nid":3031,"title":"Adobe security advisory (AV22-128)","uuid":"e897c056-613d-4182-909e-b71eb6cde5e1","banner":null,"lang":"en","date_modified":"2022-03-09","date_modified_ts":"2022-03-09T17:34:47Z","date_created":"2022-03-09T17:34:47Z","summary":null,"body":["<article data-history-node-id=\"3031\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-128\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-128<br \/>\nDate: 9 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Adobe published a Security Bulletin to address a vulnerability in multiple products:<\/p>\n\n<ul><li>After Effects \u2013 versions 18.4.4 and prior; versions 22.2 and prior<\/li>\n\t<li>Illustrator 2022 \u2013 version 26.0.3 and prior<\/li>\n\t<li>Photoshop 2021 \u2013 version 22.5.5 and prior<\/li>\n\t<li>Photoshop 2022 \u2013 version 23.1.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/after_effects\/apsb22-17.html \">Adobe After Effects<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/illustrator\/apsb22-15.html \">Adobe Illustrator<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb22-14.html \">Adobe Photoshop<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-128","alert_type":396,"serial_number":"AV22-128","subject":null,"moderation_state":"published","external_url":null},{"nid":3032,"title":" Dell security advisory (AV22-129)","uuid":"b4afa83c-4430-4318-8c5b-e8dd51d8a555","banner":null,"lang":"en","date_modified":"2022-03-09","date_modified_ts":"2022-03-09T17:38:28Z","date_created":"2022-03-09T17:38:28Z","summary":null,"body":["<article data-history-node-id=\"3032\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-129\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-129<br \/>\nDate: 9 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Dell published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC Avamar \u2013 multiple versions and platforms<\/li>\n\t<li>Dell EMC NetWorker Virtual Edition \u2013 multiple versions and platforms<\/li>\n\t<li>Dell EMC PowerProtect \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000197069\/dsa-2022-05-dell-emc-avamar-dell-emc-networker-virtual-edition-nve-and-dell-emc-powerprotect-dp-series-appliance-dell-emc-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (000197069)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-129","alert_type":396,"serial_number":"AV22-129","subject":null,"moderation_state":"published","external_url":null},{"nid":3033,"title":"Ubuntu security advisory (AV22-130)","uuid":"a3aad9bd-1e19-45cc-a083-6065a917e3fd","banner":null,"lang":"en","date_modified":"2022-03-09","date_modified_ts":"2022-03-09T17:42:33Z","date_created":"2022-03-09T17:42:33Z","summary":null,"body":["<article data-history-node-id=\"3033\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-130\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-130<br \/>\nDate: 9 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5317-1 \">Ubuntu Security Notice (USN-5317-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5318-1\">Ubuntu Security Notice (USN-5318-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5319-1 \">Ubuntu Security Notice (USN-5319-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices  \">Ubuntu Security Notices<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-130","alert_type":396,"serial_number":"AV22-130","subject":null,"moderation_state":"published","external_url":null},{"nid":3034,"title":"HPE security advisory (AV22-131)","uuid":"f4684de2-5fc8-4158-9722-fd8154cdbd5d","banner":null,"lang":"en","date_modified":"2022-03-09","date_modified_ts":"2022-03-09T17:47:07Z","date_created":"2022-03-09T17:47:07Z","summary":null,"body":["<article data-history-node-id=\"3034\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-131\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-131<br \/>\nDate: 9 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022, HPE published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Alletra 6000 Witness OVA \u2013 versions 6.0.0.0, 5.3.x and 5.2.1.0<\/li>\n\t<li>HPE Nimble Storage \u2013 versions 6.0.0.0, 5.3.x and 5.2.1.0<\/li>\n\t<li>HPE B-Series SANnav \u2013 2.2.0, 2.1.1, 2.1.0 and 2.0.0<\/li>\n\t<li>HPE Virtualized Converged NonStop \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to elevation of privilege or code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04258en_us \">HPE Security Bulletin (hpesbst04258en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04261en_us \">HPE Security Bulletin (hpesbst04261en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbns04260en_us \">HPE Security Bulletin (hpesbns04260en_us)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-131","alert_type":396,"serial_number":"AV22-131","subject":null,"moderation_state":"published","external_url":null},{"nid":3035,"title":"Red Hat security advisory (AV22-132)","uuid":"3c27bf1d-9503-4627-92bc-6039fbec95a8","banner":null,"lang":"en","date_modified":"2022-03-14","date_modified_ts":"2022-03-14T13:12:06Z","date_created":"2022-03-14T13:12:06Z","summary":null,"body":["<article data-history-node-id=\"3035\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-132\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-132<br \/>\nDate: 14 March 2022<\/strong><\/p>\n\n<p>On 8 March 2022 Red Hat published a Security Advisory to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux 8 \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat OpenShift Container Platform 4<\/li>\n\t<li>Red Hat Virtualization 4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/RHSB-2022-002\">Red Hat Security Advisory (RHSB-2022-002)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-132","alert_type":396,"serial_number":"AV22-132","subject":null,"moderation_state":"published","external_url":null},{"nid":3036,"title":"IBM security advisory (AV22-133)","uuid":"3c6d5f01-0002-4b4a-98ea-b373a956d075","banner":null,"lang":"en","date_modified":"2022-03-14","date_modified_ts":"2022-03-14T15:18:04Z","date_created":"2022-03-14T15:18:04Z","summary":null,"body":["<article data-history-node-id=\"3036\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-133\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-133<br \/>\nDate: 14 March 2022<\/strong><\/p>\n\n<p>Between 7 and 13 March 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Application Business Insights \u2013 versions 1.1.5 to 1.1.7<\/li>\n\t<li>IBM Cloud Pak System \u2013 version 2.3<\/li>\n\t<li>IBM Cloud Pak System Software Suite \u2013 version 2.3.3.0<\/li>\n\t<li>IBM Spectrum Control \u2013 versions 5.4.0 to 5.4.5.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-133","alert_type":396,"serial_number":"AV22-133","subject":null,"moderation_state":"published","external_url":null},{"nid":3037,"title":"Apple security advisory (AV22-134)","uuid":"9eb6ef12-478e-43ca-b503-4c8f9d7edf03","banner":null,"lang":"en","date_modified":"2022-03-14","date_modified_ts":"2022-03-14T18:51:41Z","date_created":"2022-03-14T18:51:41Z","summary":null,"body":["<article data-history-node-id=\"3037\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-134\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-134<br \/>\nDate: 14 March 2022<\/strong><\/p>\n\n<p>On 14 March 2022 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15.4<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.4<\/li>\n\t<li>iTunes \u2013 versions prior to 12.12.3<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.6.5<\/li>\n\t<li>macOS Catalina \u2013 versions prior to Security Update 2022-003<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.3<\/li>\n\t<li>tvOS \u2013 versions prior to 15.4<\/li>\n\t<li>watchOS \u2013 versions prior to 8.5<\/li>\n\t<li>Xcode \u2013 version prior to 13.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-134","alert_type":396,"serial_number":"AV22-134","subject":null,"moderation_state":"published","external_url":null},{"nid":3038,"title":"Google Chrome security advisory (AV22-135)","uuid":"e461ad55-c223-4eda-bec1-5fef86ca5309","banner":null,"lang":"en","date_modified":"2022-03-16","date_modified_ts":"2022-03-16T13:52:42Z","date_created":"2022-03-16T13:52:42Z","summary":null,"body":["<article data-history-node-id=\"3038\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-135\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-135<br \/>\nDate: 16 March 2022<\/strong><\/p>\n\n<p>On 15 March 2022 Google published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Chrome for Desktop Stable \u2013 versions prior to 99.0.4844.74<\/li>\n\t<li>Chrome for Desktop Long Term Support \u2013 versions prior to 96.0.4664.202<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/03\/stable-channel-update-for-desktop_15.html\">Google Chrome Security Advisory (Stable channel)<\/a><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/03\/long-term-support-channel-update.html\">Google Chrome Security Advisory (Long Term Support channel)<\/a><\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-135","alert_type":396,"serial_number":"AV22-135","subject":null,"moderation_state":"published","external_url":null},{"nid":3039,"title":"Apple security advisory (AV22-136)","uuid":"2c82bd40-741d-406e-9792-68993dee445f","banner":null,"lang":"en","date_modified":"2022-03-16","date_modified_ts":"2022-03-16T19:14:05Z","date_created":"2022-03-16T19:14:05Z","summary":null,"body":["<article data-history-node-id=\"3039\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-136\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-136<br \/>\nDate: 16 March 2022<\/strong><\/p>\n\n<p>On 15 March 2022 Apple published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari \u2013 versions prior to 15.4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-136","alert_type":396,"serial_number":"AV22-136","subject":null,"moderation_state":"published","external_url":null},{"nid":3040,"title":"OpenSSL security advisory (AV22-137)","uuid":"89a6cad1-c0c1-42c3-b51a-19ddabc89c23","banner":null,"lang":"en","date_modified":"2022-03-17","date_modified_ts":"2022-03-17T13:40:53Z","date_created":"2022-03-17T13:40:53Z","summary":null,"body":["<article data-history-node-id=\"3040\" about=\"\/en\/alerts-advisories\/openssl-security-advisory-av22-137\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-137<br \/>\nDate: 17 March 2022<\/strong><\/p>\n\n<p>On 15 March 2022 OpenSSL published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>OpenSSL \u2013 versions 1.0.2, 1.1.1 and 3.0<\/li>\n<\/ul><p>OpenSSL is a software library for applications that secures communications over computer networks. It is widely used by websites and is present in many programs and operating systems.<\/p>\n\n<p>Exploitation of this vulnerability may lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Please note that the list is not exhaustive.<\/p>\n\n<p><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20220315.txt\">OpenSSL Security Advisory<\/a><\/p>\n\n<p><a href=\"https:\/\/www.debian.org\/security\/2022\/dsa-5103\">Debian (DSA-5103-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-22:03.openssl.asc\">FreeBSD (SA-22:03)<\/a><\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2022-0778\">Red Hat<\/a><\/p>\n\n<p><a href=\"https:\/\/www.suse.com\/support\/update\">SUSE Advisories<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5328-2\">Ubuntu (USN-5328-2)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory-av22-137","alert_type":396,"serial_number":"AV22-137","subject":null,"moderation_state":"published","external_url":null},{"nid":3041,"title":"Dell security advisory (AV22-138)","uuid":"959f6efa-ff25-4366-868f-8ae3f78346a2","banner":null,"lang":"en","date_modified":"2022-03-18","date_modified_ts":"2022-03-18T19:31:38Z","date_created":"2022-03-18T19:31:38Z","summary":null,"body":["<article data-history-node-id=\"3041\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-138\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-138<br \/>\nDate: 18 March 2022<\/strong><\/p>\n\n<p>On 16 March 2022 Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC AppSync \u2013 versions 3.9.0.0 to 4.3.0.0<\/li>\n\t<li>Dell EMC CloudLink \u2013 versions prior to 7.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000197433\/dsa-2022-070-dell-emc-appsync-security-update-for-a-path-traversal-vulnerability\">Dell Security Advisory (DSA-2022-070)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000197425\/dsa-2022-064-dell-emc-cloudlink-security-update-for-security-vulnerabilities\">Dell Security Advisory (DSA-2022-064)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-138","alert_type":396,"serial_number":"AV22-138","subject":null,"moderation_state":"published","external_url":null},{"nid":3042,"title":"IBM security advisory (AV22-139)","uuid":"fad50eea-610d-4e76-bdae-dccd8ea14335","banner":null,"lang":"en","date_modified":"2022-03-21","date_modified_ts":"2022-03-21T16:12:24Z","date_created":"2022-03-21T16:12:24Z","summary":null,"body":["<article data-history-node-id=\"3042\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-139\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-139<br \/>\nDate: 21 March 2022<\/strong><\/p>\n\n<p>Between 14 and 20 March 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability - multiple versions and platforms<\/li>\n\t<li>IBM Cloud Automation Manager \u2013 version 4.2.0.1<\/li>\n\t<li>IBM Control Center \u2013 version 6.1.3 and 6.2.0.0<\/li>\n\t<li>IBM Netezza Performance Portal \u2013 versions prior to 2.1.1.12<\/li>\n\t<li>IBM Spectrum Protect Operations Center \u2013 version 8.1.0.000 to 8.1.13.300<\/li>\n\t<li>IBM Spectrum Protect for Virtual Environments \u2013 multiple platforms, version 8.1.0.0 to 8.1.13.3<\/li>\n\t<li>IBM Spectrum Protect for Workstations Central Administration Console \u2013 version 8.1.0.0 to 8.1.2.3<\/li>\n\t<li>IBM Tivoli Netcool\/OMNIbus Integrations \u2013 Probe DSL Factory Framework<\/li>\n\t<li>Tivoli Composite Application Manager for Application Diagnostics \u2013 version 7.1.0<\/li>\n\t<li>IBM TRIRIGA \u2013 version 4.0<\/li>\n\t<li>IBM TRIRIGA Application Platform \u2013 version 3.8<\/li>\n\t<li>Websphere Application Server \u2013 v8.5 and v9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/  \">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-139","alert_type":396,"serial_number":"AV22-139","subject":null,"moderation_state":"published","external_url":null},{"nid":3043,"title":"Ubuntu security advisory (AV22-140)","uuid":"52288bca-c341-406a-a8c8-8cba0fc2ac4f","banner":null,"lang":"en","date_modified":"2022-03-22","date_modified_ts":"2022-03-22T13:57:02Z","date_created":"2022-03-22T13:57:02Z","summary":null,"body":["<article data-history-node-id=\"3043\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-140\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-140<br \/>\nDate: 22 March 2022<\/strong><\/p>\n\n<p>On 22 March 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5337-1\">Ubuntu Security Notice (USN-5337-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5338-1\">Ubuntu Security Notice (USN-5338-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5339-1\">Ubuntu Security Notice (USN-5339-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-140","alert_type":396,"serial_number":"AV22-140","subject":null,"moderation_state":"published","external_url":null},{"nid":3044,"title":"[Control systems] Delta Electronics security advisory (AV22-141)","uuid":"a3e617e9-e3d1-42df-ae47-9fe854420db5","banner":null,"lang":"en","date_modified":"2022-03-22","date_modified_ts":"2022-03-22T18:47:53Z","date_created":"2022-03-22T18:47:53Z","summary":null,"body":["<article data-history-node-id=\"3044\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-141\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-141<br \/>\nDate: 22 March 2022<\/strong><\/p>\n\n<p>On 22 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DIAEnergie \u2013 versions prior to 1.8.02.004<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-081-01\">ICS Advisory (ICSA-22-081-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-141","alert_type":398,"serial_number":"AV22-141","subject":null,"moderation_state":"published","external_url":null},{"nid":3045,"title":"F5 security advisory (AV22-142)","uuid":"e0a8c971-2d2c-4e0e-b4b1-e43211e9d45e","banner":null,"lang":"en","date_modified":"2022-03-22","date_modified_ts":"2022-03-22T18:53:20Z","date_created":"2022-03-22T18:53:20Z","summary":null,"body":["<article data-history-node-id=\"3045\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-142\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-142<br \/>\nDate: 22 March 2022<\/strong><br \/><br \/>\nOn 22 March 2022, F5 published Security Advisories to address a vulnerability in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions<\/li>\n\t<li>Traffix SDC \u2013 versions 5.1.0 and 5.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K31323265\">F5 Security Advisory (K31323265)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-142","alert_type":396,"serial_number":"AV22-142","subject":null,"moderation_state":"published","external_url":null},{"nid":3046,"title":"Ubuntu security advisory (AV22-144)","uuid":"76b4effd-99a5-4b29-9af4-d8b6ebf2b7be","banner":null,"lang":"en","date_modified":"2022-03-23","date_modified_ts":"2022-03-23T13:25:47Z","date_created":"2022-03-23T13:25:47Z","summary":null,"body":["<article data-history-node-id=\"3046\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-144\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-144<br \/>\nDate: 23 March 2022<\/strong><\/p>\n\n<p>On 22 March 2022 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5343-1\">Ubuntu Security Notice (USN-5343-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-144","alert_type":396,"serial_number":"AV22-144","subject":null,"moderation_state":"published","external_url":null},{"nid":3047,"title":"VMware security advisory (AV22-145)","uuid":"f9fcec5e-ed6e-42c8-89ac-5bc4a48aa6bc","banner":null,"lang":"en","date_modified":"2022-03-23","date_modified_ts":"2022-03-23T15:54:59Z","date_created":"2022-03-23T15:54:59Z","summary":null,"body":["<article data-history-node-id=\"3047\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-145\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-145<br \/>\nDate: 23 March 2022<\/strong><\/p>\n\n<p>On 23 March 2022 VMware published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Carbon Black App Control (AppC) \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0008.html\">VMware Security Advisory (VMSA-2022-0008)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-145","alert_type":396,"serial_number":"AV22-145","subject":null,"moderation_state":"published","external_url":null},{"nid":3048,"title":"Dell security advisory (AV22-143)","uuid":"073c8f52-6960-45a7-88c4-ebe4afdda3a0","banner":null,"lang":"en","date_modified":"2022-03-23","date_modified_ts":"2022-03-23T16:09:28Z","date_created":"2022-03-23T16:09:28Z","summary":null,"body":["<article data-history-node-id=\"3048\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-143\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-143<br \/>\nDate: 23 March 2022<\/strong><\/p>\n\n<p>On 22 March 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell Cyber Recovery \u2013 versions prior to 19.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000197612\/dsa-2022-067-dell-emc-cyber-recovery-security-update-for-multiple-third-party-components-vulnerabilities\">Dell Security Advisory (000197612)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-143","alert_type":396,"serial_number":"AV22-143","subject":null,"moderation_state":"published","external_url":null},{"nid":3049,"title":"Dell security advisory (AV22-146)","uuid":"dc933e10-ffd6-4a79-8cea-9ae6f1899b65","banner":null,"lang":"en","date_modified":"2022-03-23","date_modified_ts":"2022-03-23T16:51:14Z","date_created":"2022-03-23T16:51:14Z","summary":null,"body":["<article data-history-node-id=\"3049\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-146\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-146<br \/>\nDate: 23 March 2022<\/strong><\/p>\n\n<p>On 10 March 2022 Dell published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Alienware \u2013 multiple versions and platforms<\/li>\n\t<li>Dell Edge Gateway 3000 Series \u2013 versions prior to 1.7.0<\/li>\n\t<li>Dell Edge Gateway 5000\/5100 \u2013 versions prior to 1.17.0<\/li>\n\t<li>Dell Embedded Box PC 3000 \u2013 versions prior to 1.13.0<\/li>\n\t<li>Dell Embedded Box PC 5000 \u2013 versions prior to 1.14.0<\/li>\n\t<li>Inspiron \u2013 multiple versions and platforms<\/li>\n\t<li>Latitude 3379 \u2013 versions prior to 1.0.34<\/li>\n\t<li>Vostro \u2013 multiple versions and platforms<\/li>\n\t<li>Wyse 7040 Thin Client \u2013 versions prior to 1.15.0<\/li>\n\t<li>XPS 8930 \u2013 versions prior to 1.1.21<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000197057\/dsa-2022-053\">Dell Security Advisory (000197057)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-146","alert_type":396,"serial_number":"AV22-146","subject":null,"moderation_state":"published","external_url":null},{"nid":3050,"title":"Ubuntu security advisory (AV22-147)","uuid":"3f50bca3-0180-4a78-9e74-1e55f4431dd9","banner":null,"lang":"en","date_modified":"2022-03-24","date_modified_ts":"2022-03-24T13:02:46Z","date_created":"2022-03-24T13:02:46Z","summary":null,"body":["<article data-history-node-id=\"3050\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-147\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-147<br \/>\nDate: 24 March 2022<\/strong><\/p>\n\n<p>On 23 March 2022 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0085-1\">Ubuntu Security Notice (LSN-0085-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-147","alert_type":396,"serial_number":"AV22-147","subject":null,"moderation_state":"published","external_url":null},{"nid":3051,"title":"[Control systems] Yokogawa security advisory (AV22-148)","uuid":"63e4cbcc-86fd-4851-8c58-9d53d8ee3279","banner":null,"lang":"en","date_modified":"2022-03-24","date_modified_ts":"2022-03-24T18:53:57Z","date_created":"2022-03-24T18:53:57Z","summary":null,"body":["<article data-history-node-id=\"3051\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-148\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-148<br \/>\nDate: 24 March 2022<\/strong><\/p>\n\n<p>On 24 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class) \u2013 versions R3.08.10 to R3.09.00<\/li>\n\t<li>CENTUM VP (Including CENTUM VP Entry Class) \u2013 multiple versions<\/li>\n\t<li>Exaopc \u2013 versions R3.72.00 to R3.79.00<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in the suppression of alarms, reading or writing of files, denial of service, or arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-083-01 \">ICS Advisory (ICSA-22-083-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-148","alert_type":398,"serial_number":"AV22-148","subject":null,"moderation_state":"published","external_url":null},{"nid":3052,"title":"[Control systems] mySCADA security advisory (AV22-149)","uuid":"25ebb4ce-5b48-4652-bede-9d429281a73a","banner":null,"lang":"en","date_modified":"2022-03-24","date_modified_ts":"2022-03-24T18:58:01Z","date_created":"2022-03-24T18:58:01Z","summary":null,"body":["<article data-history-node-id=\"3052\" about=\"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-av22-149\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-149<br \/>\nDate: 24 March 2022<\/strong><\/p>\n\n<p>On 24 March 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>myPRO - versions 8.25.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in injection of arbitrary operating system commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-083-02 \">ICS Advisory (ICSA-22-083-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-av22-149","alert_type":398,"serial_number":"AV22-149","subject":null,"moderation_state":"published","external_url":null},{"nid":3053,"title":"Google Chrome security advisory (AV22-150)","uuid":"58eadfb2-0d7c-4bc4-a393-5521505dcd12","banner":null,"lang":"en","date_modified":"2022-03-25","date_modified_ts":"2022-03-25T19:13:50Z","date_created":"2022-03-25T19:13:50Z","summary":null,"body":["<article data-history-node-id=\"3053\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-150\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-150<br \/>\nDate: 25 March 2022<\/strong><\/p>\n\n<p>On 25 March 2022 Google published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 99.0.4844.84<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2022-1096 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/03\/stable-channel-update-for-desktop_25.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-150","alert_type":396,"serial_number":"AV22-150","subject":null,"moderation_state":"published","external_url":null},{"nid":3054,"title":"IBM security advisory (AV22-151)","uuid":"5c591c4e-f43e-4e15-bc7f-2f32b8b35cc4","banner":null,"lang":"en","date_modified":"2022-03-28","date_modified_ts":"2022-03-28T18:11:38Z","date_created":"2022-03-28T18:11:38Z","summary":null,"body":["<article data-history-node-id=\"3054\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-151\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-151<br \/>\nDate: 28 March 2022<\/strong><\/p>\n\n<p>Between 21 and 27 March 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability - multiple versions and platforms<\/li>\n\t<li>IBM Watson Knowledge Catalog in Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM WebSphere Extreme Scale \u2013 versions 8.6.1.0 to 8.6.1.5<\/li>\n\t<li>Cloudera Data Platform Private Cloud Base for IBM \u2013 versions 7.1.6 and 7.1.7<\/li>\n\t<li>Db2 Big SQL \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/  \">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-151","alert_type":396,"serial_number":"AV22-151","subject":null,"moderation_state":"published","external_url":null},{"nid":3055,"title":"[Control systems] Schneider Electric security advisory (AV22-152)","uuid":"9cc43453-5993-400c-a82e-1e94d6c52cfb","banner":null,"lang":"en","date_modified":"2022-03-28","date_modified_ts":"2022-03-28T18:15:55Z","date_created":"2022-03-28T18:15:55Z","summary":null,"body":["<article data-history-node-id=\"3055\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-152\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-152<br \/>\nDate: 28 March 2022<\/strong><\/p>\n\n<p>On 28 March 2022 Schneider Electric published a Security Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>SCADAPack Workbench \u2013 version 6.6.8a and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-087-01\">Schneider Security Advisory (SEVD-2022-087-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-152","alert_type":398,"serial_number":"AV22-152","subject":null,"moderation_state":"published","external_url":null},{"nid":3056,"title":"[Control systems] Philips security advisory (AV22-153)","uuid":"8410fe92-80b0-4e21-a93a-14b0c2ab4e21","banner":null,"lang":"en","date_modified":"2022-03-29","date_modified_ts":"2022-03-29T17:45:11Z","date_created":"2022-03-29T17:45:11Z","summary":null,"body":["<article data-history-node-id=\"3056\" about=\"\/en\/alerts-advisories\/control-systems-philips-security-advisory-av22-153\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-153<br \/>\nDate: 29 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Philips e-Alert \u2013 version 2.7 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-088-01 \">ICS Advisory (ICSMA-22-088-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-philips-security-advisory-av22-153","alert_type":398,"serial_number":"AV22-153","subject":null,"moderation_state":"published","external_url":null},{"nid":3057,"title":"F5 security advisory (AV22-154)","uuid":"fa9f3e2d-f911-46c7-8449-f84e27247035","banner":null,"lang":"en","date_modified":"2022-03-29","date_modified_ts":"2022-03-29T17:48:18Z","date_created":"2022-03-29T17:48:18Z","summary":null,"body":["<article data-history-node-id=\"3057\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-154\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-154<br \/>\nDate: 29 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022, F5 published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Traffix SDC \u2013 version 5.1.0<\/li>\n<\/ul><p>Exploitation of this vulnerability may result in an escalation of privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K03674368\">F5 Security Advisory (K03674368)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-154","alert_type":396,"serial_number":"AV22-154","subject":null,"moderation_state":"published","external_url":null},{"nid":3058,"title":"Microsoft Edge security advisory (AV22-155)","uuid":"80001113-5174-4cd4-a6f4-4aa320e6fc5a","banner":null,"lang":"en","date_modified":"2022-03-29","date_modified_ts":"2022-03-29T19:08:49Z","date_created":"2022-03-29T19:08:49Z","summary":null,"body":["<article data-history-node-id=\"3058\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-155\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-155<br \/>\nDate: 29 March 2022<\/strong><\/p>\n\n<p>On 26 March 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 99.0.1150.55<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2022-1096 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-26-2022\">Microsoft Edge Stable Channel Release Notes<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-155","alert_type":396,"serial_number":"AV22-155","subject":null,"moderation_state":"published","external_url":null},{"nid":3059,"title":"[Control systems] Rockwell Automation security advisory (AV22-156)","uuid":"52856944-e215-4a2b-ac8c-d9e2b92dfad1","banner":null,"lang":"en","date_modified":"2022-03-29","date_modified_ts":"2022-03-29T19:12:57Z","date_created":"2022-03-29T19:12:57Z","summary":null,"body":["<article data-history-node-id=\"3059\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-156\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-156<br \/>\nDate: 29 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Connected Component Workbench \u2013 version v12.00 and prior<\/li>\n\t<li>ISaGRAF Workbench \u2013 version v6.6.9 and prior<\/li>\n\t<li>Safety Instrumented Systems Workstation \u2013 version v1.1 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-088-01 \">ICS Advisory (ICSA-22-088-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-156","alert_type":398,"serial_number":"AV22-156","subject":null,"moderation_state":"published","external_url":null},{"nid":3060,"title":"[Control systems] Hitachi Energy security advisory (AV22-157)","uuid":"4a110b58-9198-460a-bec1-0ee818a9b8bc","banner":null,"lang":"en","date_modified":"2022-03-29","date_modified_ts":"2022-03-29T19:31:13Z","date_created":"2022-03-29T19:31:13Z","summary":null,"body":["<article data-history-node-id=\"3060\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-157\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-157<br \/>\nDate: 29 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>LinkOne WebView \u2013 versions v3.20, v3.22, v3.23, v3.24, v3.25, and v3.26<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-088-03 \">ICS Advisory (ICSA-22-088-03)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-157","alert_type":398,"serial_number":"AV22-157","subject":null,"moderation_state":"published","external_url":null},{"nid":3061,"title":"[Control systems] Modbus Tools security advisory (AV22-158)","uuid":"9194c802-55e5-4132-b6bc-e32372a352f0","banner":null,"lang":"en","date_modified":"2022-03-29","date_modified_ts":"2022-03-29T19:37:41Z","date_created":"2022-03-29T19:37:41Z","summary":null,"body":["<article data-history-node-id=\"3061\" about=\"\/en\/alerts-advisories\/control-systems-modbus-tools-security-advisory-av22-158\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-158<br \/>\nDate: 29 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Modbus Slave \u2013 version 7.4.2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-088-04 \">ICS Advisory (ICSA-22-088-04)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-modbus-tools-security-advisory-av22-158","alert_type":398,"serial_number":"AV22-158","subject":null,"moderation_state":"published","external_url":null},{"nid":3062,"title":"[Control systems] Omron security advisory (AV22-159)","uuid":"dd6d9109-4636-4f66-9127-30648c4c90c7","banner":null,"lang":"en","date_modified":"2022-03-29","date_modified_ts":"2022-03-29T19:41:11Z","date_created":"2022-03-29T19:41:11Z","summary":null,"body":["<article data-history-node-id=\"3062\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-159\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-159<br \/>\nDate: 29 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Omron CX-Position \u2013 version 2.5.3 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-088-02 \">ICS Advisory (ICSA-22-088-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-159","alert_type":398,"serial_number":"AV22-159","subject":null,"moderation_state":"published","external_url":null},{"nid":3063,"title":" Ubuntu security advisory (AV22-160)","uuid":"073f0358-ba9c-4d7c-8467-0b9669acdb91","banner":null,"lang":"en","date_modified":"2022-03-30","date_modified_ts":"2022-03-30T13:27:14Z","date_created":"2022-03-30T13:27:14Z","summary":null,"body":["<article data-history-node-id=\"3063\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-160\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-160<br \/>\nDate: 30 March 2022<\/strong><\/p>\n\n<p>On 28 March 2022 Ubuntu released a Security Notice to address a vulnerability in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5353-1\">Ubuntu Security Notice (USN-5353-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-160","alert_type":396,"serial_number":"AV22-160","subject":null,"moderation_state":"published","external_url":null},{"nid":3064,"title":"SonicWall security advisory (AV22-161)","uuid":"a2e49241-458b-4918-93ab-b2b7b75787cd","banner":null,"lang":"en","date_modified":"2022-03-30","date_modified_ts":"2022-03-30T13:35:01Z","date_created":"2022-03-30T13:35:01Z","summary":null,"body":["<article data-history-node-id=\"3064\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av22-161\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-161<br \/>\nDate: 30 March 2022<\/strong><\/p>\n\n<p>On 24 March 2022 SonicWall published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SonicWall Firewall Appliances \u2013 multiple platforms and firmware versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2022-0003\">Security Advisory (SNWLID-2022-0003)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av22-161","alert_type":396,"serial_number":"AV22-161","subject":null,"moderation_state":"published","external_url":null},{"nid":3065,"title":"Dell security advisory (AV22-162)","uuid":"36367742-31b7-487a-a00f-d8609bcc370b","banner":null,"lang":"en","date_modified":"2022-03-30","date_modified_ts":"2022-03-30T18:55:04Z","date_created":"2022-03-30T18:55:04Z","summary":null,"body":["<article data-history-node-id=\"3065\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-162\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-162<br \/>\nDate: 30 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC PowerProtect Data Manager \u2013 version 19.9 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000197865\/dsa-2022-080-dell-emc-power-protect-data-manager-update-for-multiple-security-vulnerabilities \">Dell security advisory (000197865)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-162","alert_type":396,"serial_number":"AV22-162","subject":null,"moderation_state":"published","external_url":null},{"nid":3066,"title":"Google Chrome security advisory (AV22-163)","uuid":"ac8b3924-bd4f-4bf8-8fd5-ace69142aaca","banner":null,"lang":"en","date_modified":"2022-03-30","date_modified_ts":"2022-03-30T18:57:59Z","date_created":"2022-03-30T18:57:59Z","summary":null,"body":["<article data-history-node-id=\"3066\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-163\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-163<br \/>\nDate: 30 March 2022<\/strong><\/p>\n\n<p>On 29 March 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 100.0.4896.60<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/03\/stable-channel-update-for-desktop_29.html \">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-163","alert_type":396,"serial_number":"AV22-163","subject":null,"moderation_state":"published","external_url":null},{"nid":3067,"title":"[Control systems] Fuji Electric security advisory (AV22-164)","uuid":"e99109d3-50e2-4b5c-874f-4e8c4d0b845e","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T17:47:19Z","date_created":"2022-03-31T17:47:19Z","summary":null,"body":["<article data-history-node-id=\"3067\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-164\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-164<br \/>\nDate: 31 March 2022<\/strong><\/p>\n\n<p>On 31 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Alpha5 \u2013 versions prior to 4.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and arbitrary code execution.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-090-03\">ICS Advisory (ICSA-22-090-03)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-164","alert_type":398,"serial_number":"AV22-164","subject":null,"moderation_state":"published","external_url":null},{"nid":3068,"title":"[Control systems] Hitachi Energy security advisory (AV22-165)","uuid":"d32a8244-adcd-4de4-a708-9cdccbdbc261","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T17:50:13Z","date_created":"2022-03-31T17:50:13Z","summary":null,"body":["<article data-history-node-id=\"3068\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-165\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-165<br \/>\nDate: 31 March 2022<\/strong><\/p>\n\n<p>On 31 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>e-mesh EMS \u2013 version 1.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-090-02\">ICS Advisory (ICSA-22-090-02)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-165","alert_type":398,"serial_number":"AV22-165","subject":null,"moderation_state":"published","external_url":null},{"nid":3071,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-166)","uuid":"c6c7e349-1f43-4490-a6c7-2d780d03e962","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T18:47:50Z","date_created":"2022-03-31T18:47:50Z","summary":null,"body":["<article data-history-node-id=\"3071\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-166\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><span lang=\"FR-CA\" style=\"mso-ansi-language:FR-CA\" xml:lang=\"FR-CA\" xml:lang=\"FR-CA\"><o:p><\/o:p><\/span><\/p>\n\n<p><strong>Number: AV22-166<br \/>\nDate: 31 March 2022<\/strong><\/p>\n\n<p>On 31 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MELSEC iQ-F Series FX5U(C) CPU modules \u2013 all models, all versions<\/li>\n\t<li>MELSEC iQ-F Series FX5UJ CPU modules \u2013 all models, all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to authentication bypass and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-090-04 \">ICS Advisory (ICSA-22-090-04)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-166","alert_type":398,"serial_number":"AV22-166","subject":null,"moderation_state":"published","external_url":null},{"nid":3073,"title":"Spring remote code execution vulnerabilities ","uuid":"37e252c2-2845-4845-9f10-5d2d74feba2d","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T18:56:39Z","date_created":"2022-03-31T18:53:25Z","summary":null,"body":["<article data-history-node-id=\"3073\" about=\"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL22-004<br \/><strong>Date: <\/strong>31 March 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>On 30 March 2022, security researchers disclosed proof-of-concept exploitation code online for a vulnerability in the Java Spring Framework on Java Development Kit (JDK) versions 9 and up. The existence of the vulnerability and potential for exploitation has since been independently <span class=\"nowrap\">confirmed <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"> <span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"> <span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/span><\/p>\n\n<p>Spring subsequently published a blog article to address the vulnerability, and has released patches, workarounds and methods to identify the vulnerability <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>Spring published updates <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> to address vulnerabilities in Spring Cloud Function on 29 March, but it should be noted that these vulnerabilities are distinct from those in the Spring Core Framework.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 31 March 2022, developers of the Spring Core framework reported a critical remote code execution (RCE) vulnerability that \u201cimpacts Spring MVC and Spring WebFlux applications running on the Java Development Kit (JDK) 9+\u201d <sup id=\"fn4a-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. This vulnerability is known in the open-source security community as Spring4Shell or SpringShell. Spring states that \u201cthe specific exploit requires the application to be packaged as a Web application ARchive (WAR) and deployed to Apache Tomcat\u201d <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. However, as it is possible that new methods for exploiting this vulnerability will emerge, patching affected applications is highly recommended.<\/p>\n\n<p>At the time of reporting, applications are only vulnerable under certain conditions, and not all deployments will be affected by this vulnerability <sup id=\"fn4b-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>Security researchers state that in order to be vulnerable, a Spring application must \u201cmake use of Spring Beans, use Spring Parameter Binding, and a Spring Parameter Binding must be configured to use a non-basic parameter type, such as POJOs (Plain Old Java Objects)\u201d <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. It is strongly recommended to continue to monitor the Spring blog on this topic for updates as the situation is evolving <sup id=\"fn4c-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>In open-source discourse on this topic, the vulnerability described in this Alert was often confused with a recently patched vulnerability in Spring Cloud (CVE-2022-22963) <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>. It should be noted that these two vulnerabilities are not related, but both should be patched or mitigated in a timely manner.<\/p>\n\n<p>Proof-of-concept code for CVE-2022-22963 and SpringShell exists publicly, and sources have reported successful exploitation under certain circumstances <sup id=\"fn1d-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2d-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3d-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<h2>Suggested action<\/h2>\n\n<p>For organizations who have deployed these products, the Cyber Centre recommends the following mitigations to protect applications and systems affected by these vulnerabilities:<\/p>\n\n<ul><li>Continue to monitor the Spring blog posts on this issue, as the situation is still developing <sup id=\"fn4f-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5d-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n\t<li>Patch affected applications with Spring Framework 5.3.18 or 5.2.20 and Spring Cloud 3.17, 3.2.3, which address SpringShell and CVE-2022-22963, respectively<\/li>\n\t<li>If patching is not immediately possible, follow all suggested vendor workarounds <sup id=\"fn4g-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5f-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n\t<li>Use a Web Application Firewall (WAF) wherever possible<\/li>\n\t<li>Consider implementing workarounds and YARA rules shared by security researchers <sup id=\"fn1g-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2n-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3m-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn6h-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> if patching is not possible<\/li>\n<\/ul><!-- ENDNOTES SECTION --><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-spring-java-framework-zero-day-allows-remote-code-execution\/\">New Spring Java framework zero-day allows remote code execution<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.praetorian.com\/blog\/spring-core-jdk9-rce\/\">Spring Core on JDK9+ is vulnerable to remote code execution<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to <span>first<\/span> footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/03\/30\/spring4shell-zero-day-vulnerability-in-spring-framework\/\">Spring4Shell: Zero-Day Vulnerability in Spring Framework<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/spring.io\/blog\/2022\/03\/31\/spring-framework-rce-early-announcement\">Spring Framework RCE, Early Announcement<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/spring.io\/blog\/2022\/03\/29\/cve-report-published-for-spring-cloud-function\">CVE report published for Spring Cloud Function<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/github.com\/Neo23x0\/signature-base\/blob\/master\/yara\/expl_spring4shell.yar\">YARA rule for PoC Activity Detection (Florian Roth)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities","alert_type":397,"serial_number":"AL22-004","subject":null,"moderation_state":"published","external_url":null},{"nid":3069,"title":"[Control systems] Rockwell Automation security advisory (AV22-167)","uuid":"6b0891e5-6e5e-4c1f-954c-0af546e8a8b0","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T18:55:37Z","date_created":"2022-03-31T18:55:37Z","summary":null,"body":["<article data-history-node-id=\"3069\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-167\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-167<br \/>\nDate: 31 March 2022<\/strong><\/p>\n\n<p>On 31 March 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>CompactLogix \u2013 multiple platforms<\/li>\n\t<li>Compact GuardLogix \u2013 multiple platforms<\/li>\n\t<li>ControlLogix \u2013 multiple platforms<\/li>\n\t<li>GuardLogix \u2013 multiple platforms<\/li>\n\t<li>FlexLogix 1794-L34 controllers<\/li>\n\t<li>DriveLogix 5730 controllers<\/li>\n\t<li>SoftLogix 5800 controllers<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-090-05\">ICS Advisory (ICSA-22-090-05)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-090-07\">ICS Advisory (ICSA-22-090-07)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-167","alert_type":398,"serial_number":"AV22-167","subject":null,"moderation_state":"published","external_url":null},{"nid":3070,"title":"[Control systems] General Electric Renewable Energy security advisory (AV22-168)","uuid":"1890063f-9eaa-44d8-b094-72265f716a41","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T18:59:40Z","date_created":"2022-03-31T18:59:40Z","summary":null,"body":["<article data-history-node-id=\"3070\" about=\"\/en\/alerts-advisories\/control-systems-general-electric-renewable-energy-security-advisory-av22-168\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-168<br \/>\nDate: 31 March 2022<\/strong><\/p>\n\n<p>On 31 March 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>iNET\/iNET II series radio firmware \u2013 versions prior to rev. 8.3.0<\/li>\n\t<li>SD series radio firmware \u2013 versions prior to rev. 6.4.7<\/li>\n\t<li>TD220X series radio firmware \u2013 versions prior to rev. 2.0.16<\/li>\n\t<li>TD220MAX series radio firmware \u2013 versions prior to rev. 1.2.6<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could result in remote code execution, unauthorized access, and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-090-06\">ICS Advisory (ICSA-22-090-06)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-general-electric-renewable-energy-security-advisory-av22-168","alert_type":398,"serial_number":"AV22-168","subject":null,"moderation_state":"published","external_url":null},{"nid":3072,"title":"Ubuntu security advisory (AV22-169)","uuid":"5d891dd1-f124-48a1-b0d3-f79d6bfac490","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T19:23:24Z","date_created":"2022-03-31T19:23:24Z","summary":null,"body":["<article data-history-node-id=\"3072\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-169\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-169<br \/>\nDate: 31 March 2022<\/strong><\/p>\n\n<p>On 31 March 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5358-1\">Ubuntu Security Notice (USN-5358-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5357-1\">Ubuntu Security Notice (USN-5357-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-169","alert_type":396,"serial_number":"AV22-169","subject":null,"moderation_state":"published","external_url":null},{"nid":3074,"title":"Apple security advisory (AV22-170)","uuid":"323e8181-3291-4935-a2d9-186a7e413f15","banner":null,"lang":"en","date_modified":"2022-03-31","date_modified_ts":"2022-03-31T19:38:24Z","date_created":"2022-03-31T19:38:24Z","summary":null,"body":["<article data-history-node-id=\"3074\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-170\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-170<br \/>\nDate: 31 March 2022<\/strong><\/p>\n\n<p>On 31 March 2022 Apple published a Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPad - versions prior to 15.4.1<\/li>\n\t<li>macOS Monterey \u2013 versions prior 12.3.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution or information disclosure.<\/p>\n\n<p>Apple has received reports that some of these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-170","alert_type":396,"serial_number":"AV22-170","subject":null,"moderation_state":"published","external_url":null},{"nid":3077,"title":" Ubuntu security advisory (AV22-171)","uuid":"59e9f5fc-01f6-43dc-9887-61a37704a7a7","banner":null,"lang":"en","date_modified":"2022-04-01","date_modified_ts":"2022-04-01T13:24:39Z","date_created":"2022-04-01T13:24:39Z","summary":null,"body":["<article data-history-node-id=\"3077\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-171\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-171<br \/>\nDate: 1 April 2022<\/strong><\/p>\n\n<p>On 31 March and 1 April 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5357-2\">Ubuntu Security Notice (USN-5357-2)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5358-2\">Ubuntu Security Notice (USN-5358-2)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5361-1\">Ubuntu Security Notice (USN-5361-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5362-1\">Ubuntu Security Notice (USN-5362-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-171","alert_type":396,"serial_number":"AV22-171","subject":null,"moderation_state":"published","external_url":null},{"nid":3078,"title":"Pulse Secure security advisory (AV22-172)","uuid":"873db7b5-4de9-49fc-a228-9315bb2a1d3b","banner":null,"lang":"en","date_modified":"2022-04-01","date_modified_ts":"2022-04-01T13:50:23Z","date_created":"2022-04-01T13:50:23Z","summary":null,"body":["<article data-history-node-id=\"3078\" about=\"\/en\/alerts-advisories\/pulse-secure-security-advisory-av22-172\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-172<br \/>\nDate: 1 April 2022<\/strong><\/p>\n\n<p>On 31 March 2022 Pulse Secure published a Security Advisory. Included were updates for the following:<\/p>\n\n<ul><li>Pulse Connect Secure \u2013 version 9.1R14 and prior<\/li>\n\t<li>Pulse One \u2013 version 2.0.2104 and prior<\/li>\n\t<li>Pulse Policy Secure \u2013 version 9.1R14 and prior<\/li>\n\t<li>Pulse Secure Services Director \u2013 version 21.1R1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/CVE-2022-0778-OpenSSL-Vulnerability-may-lead-to-DoS-attack\/?kA23Z000000L6pDSAS\">Pulse Secure Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/pulse-secure-security-advisory-av22-172","alert_type":396,"serial_number":"AV22-172","subject":null,"moderation_state":"published","external_url":null},{"nid":3075,"title":"IBM security advisory (AV22-173)","uuid":"1b3a0eae-af95-4212-b81d-a94658eddeba","banner":null,"lang":"en","date_modified":"2022-04-04","date_modified_ts":"2022-04-04T18:13:56Z","date_created":"2022-04-04T18:13:56Z","summary":null,"body":["<article data-history-node-id=\"3075\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-173\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-173<br \/>\nDate: 4 April 2022<\/strong><\/p>\n\n<p>Between 28 March to 3 April 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM \u2013 Apache Log4j Vulnerability \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Cloud Pak for Security \u2013 versions 1.8.0.0, 1.8.1.0 and 1.9.1.0<\/li>\n\t<li>IBM Partner Engagement Manager \u2013 version 2.0<\/li>\n\t<li>IBM QRadar Network Security \u2013 versions 5.4.0 and 5.5.0<\/li>\n\t<li>IBM QRadar Network Packet Capture \u2013 multiple versions<\/li>\n\t<li>IBM Spectrum Discover \u2013 versions 2.0.4 and 2.0.4.1 to 2.0.4.4<\/li>\n\t<li>IBM WebSphere Application Server Liberty for IBM i \u2013 versions 7.2, 7.3 and 7.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/  \">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-173","alert_type":396,"serial_number":"AV22-173","subject":null,"moderation_state":"published","external_url":null},{"nid":3079,"title":"Android security advisory \u2013 April 2022 monthly rollup (AV22-174)","uuid":"0b727bf2-fa48-4a38-b77b-a3fd9ffa34f5","banner":null,"lang":"en","date_modified":"2022-04-05","date_modified_ts":"2022-04-05T11:39:09Z","date_created":"2022-04-05T11:39:09Z","summary":null,"body":["<article data-history-node-id=\"3079\" about=\"\/en\/alerts-advisories\/android-security-advisory-april-2022-monthly-rollup-av22-174\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-174<br \/>\nDate: 5 April 2022<\/strong><\/p>\n\n<p>On 1 April 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2022-04-01\">Android Security Bulletin<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-april-2022-monthly-rollup-av22-174","alert_type":396,"serial_number":"AV22-174","subject":null,"moderation_state":"published","external_url":null},{"nid":3080,"title":"Fortinet security advisory (AV22-175)","uuid":"1b3d2704-5362-42df-bb17-6a0353ecf01e","banner":null,"lang":"en","date_modified":"2022-04-05","date_modified_ts":"2022-04-05T11:42:18Z","date_created":"2022-04-05T11:42:18Z","summary":null,"body":["<article data-history-node-id=\"3080\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-175\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-175<br \/>\nDate: 4 April 2022<\/strong><\/p>\n\n<p>On 1 April 2022 Fortinet published PSIRT Advisories to address vulnerabilities affecting multiple products:<\/p>\n\n<ul><li>Spring4Shell and CVE-2022-22963 \u2013 multiple products and versions<\/li>\n\t<li>CVE-2022-0778 (OpenSSL) \u2013 multiple products and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-072\">Spring4Shell and CVE-2022-22963 vulnerabilities<\/a><\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-059\">OpenSSL library vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities\">CCCS Alert Spring remote code execution vulnerabilities<\/a><\/p>\n\n<p><a href=\" https:\/\/www.cyber.gc.ca\/en\/alerts\/openssl-security-advisory-av22-137\">CCCS OpenSSL security advisory (AV22-137)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-175","alert_type":396,"serial_number":"AV22-175","subject":null,"moderation_state":"published","external_url":null},{"nid":3081,"title":"Google Chrome security advisory (AV22-176)","uuid":"da4525bc-dcd6-4c40-a780-662dd5f8f8f1","banner":null,"lang":"en","date_modified":"2022-04-05","date_modified_ts":"2022-04-05T14:02:57Z","date_created":"2022-04-05T14:02:57Z","summary":null,"body":["<article data-history-node-id=\"3081\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-176\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-176<br \/>\nDate: 5 April 2022<\/strong><\/p>\n\n<p>On 1 April 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 100.0.4896.75<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/04\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-176","alert_type":396,"serial_number":"AV22-176","subject":null,"moderation_state":"published","external_url":null},{"nid":3076,"title":"Cisco security advisory (AV22-177)","uuid":"043824d2-1d74-417d-82e2-8745dc037861","banner":null,"lang":"en","date_modified":"2022-04-05","date_modified_ts":"2022-04-05T16:58:07Z","date_created":"2022-04-05T16:58:07Z","summary":null,"body":["<article data-history-node-id=\"3076\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-177\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-177<br \/>\nDate: 5 April 2022<\/strong><\/p>\n\n<p>On 1 April 2022 Cisco published Security Advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Vulnerability in Spring Framework Affecting Cisco Products<\/li>\n\t<li>Vulnerability in Spring Cloud Function Framework Affecting Cisco Products<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-java-spring-rce-Zx9GUc67\">Vulnerability in Spring Framework Affecting Cisco Products<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-java-spring-scf-rce-DQrHhJxH\">Vulnerability in Spring Cloud Function Framework Affecting Cisco Products<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities\">CCCS Alert Spring remote code execution vulnerabilities<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-177","alert_type":396,"serial_number":"AV22-177","subject":null,"moderation_state":"published","external_url":null},{"nid":3082,"title":"VMware security advisory (AV22-178)","uuid":"38107341-5006-44f3-8216-885f740f3e28","banner":null,"lang":"en","date_modified":"2022-04-05","date_modified_ts":"2022-04-05T19:26:17Z","date_created":"2022-04-05T19:26:17Z","summary":null,"body":["<article data-history-node-id=\"3082\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-178\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-178<br \/>\nDate: 5 April 2022<\/strong><\/p>\n\n<p>On 2 April 2022 VMware published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Tanzu Application Service for VMs \u2013 version 2.13, 2.12 and 2.11<\/li>\n\t<li>Tanzu Application Service \u2013 version 2.10<\/li>\n\t<li>Tanzu Operations Manager \u2013 version 2.10, 2.9 and 2.8<\/li>\n\t<li>TKGI \u2013 version 1.13, 1.12 and 1.11<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0010.html\">VMware Security Advisory (VMSA-2022-0010)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities\">CCCS Alert Spring remote code execution vulnerabilities<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-178","alert_type":396,"serial_number":"AV22-178","subject":null,"moderation_state":"published","external_url":null},{"nid":3083,"title":"Mozilla security advisory (AV22-179)","uuid":"ce7f9110-a2da-41dd-b140-c179816cd7b2","banner":null,"lang":"en","date_modified":"2022-04-05","date_modified_ts":"2022-04-05T19:51:49Z","date_created":"2022-04-05T19:51:49Z","summary":null,"body":["<article data-history-node-id=\"3083\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-179\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-179<br \/>\nDate: 5 April 2022<\/strong><\/p>\n\n<p>On 5 April 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 99<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-14\/\">Mozilla Security Advisory (MFSA 2022-14)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-13\/\">Mozilla Security Advisory (MFSA 2022-13)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-179","alert_type":396,"serial_number":"AV22-179","subject":null,"moderation_state":"published","external_url":null},{"nid":3084,"title":"F5 security advisory (AV22-180)","uuid":"0ba771ef-66ea-4a7c-9f9c-a307b1d8ac13","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T13:55:22Z","date_created":"2022-04-06T13:55:22Z","summary":null,"body":["<article data-history-node-id=\"3084\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-180\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-180<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>Between 4 and 5 April 2022, F5 published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 multiple versions<\/li>\n\t<li>F5OS-A \u2013 version 1.0.0 to 1.0.1<\/li>\n\t<li>F5OS-C \u2013 multiple versions<\/li>\n\t<li>Traffix SDC \u2013 versions 5.1.0 and 5.2.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in a denial of service and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, apply the recommended mitigations and apply the necessary updates once available.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K29855410\">F5 Security Advisory (K29855410)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K40508224\">F5 Security Advisory (K40508224)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K49419538\">F5 Security Bulletin (K49419538)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K10002140\">F5 Security Bulletin (K10002140)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-180","alert_type":396,"serial_number":"AV22-180","subject":null,"moderation_state":"published","external_url":null},{"nid":3085,"title":"Red Hat security advisory (AV22-181)","uuid":"c83cd56c-be17-4fa9-9975-06d3f0424b58","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T15:45:33Z","date_created":"2022-04-06T15:45:33Z","summary":null,"body":["<article data-history-node-id=\"3085\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-181\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-181<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>Between 5 and 6 April 2022 Red Hat published Security Advisories to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat OpenStack \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host 4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation and information disclosure.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories\">Red Hat Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-181","alert_type":396,"serial_number":"AV22-181","subject":null,"moderation_state":"published","external_url":null},{"nid":3088,"title":"[Control systems] Rockwell Automation security advisory (AV22-182)","uuid":"b75c4eb6-bb74-436e-8059-b4c6c09498b2","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T15:48:54Z","date_created":"2022-04-06T15:48:54Z","summary":null,"body":["<article data-history-node-id=\"3088\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-182\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-182<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>On 5 April 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Connected Component Workbench \u2013 version 13.00.00 and prior<\/li>\n\t<li>ISaGRAF Workbench \u2013 versions 6.0 to 6.6.9<\/li>\n\t<li>Safety Instrumented Systems Workstation \u2013 version 1.2 and prior (for Trusted Controllers)<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-095-01 \">ICS Advisory (ICSA-22-095-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-182","alert_type":398,"serial_number":"AV22-182","subject":null,"moderation_state":"published","external_url":null},{"nid":3086,"title":"[Control systems] LifePoint Informatics security advisory (AV22-183)","uuid":"25c97c0c-0232-4bd2-88cc-a10e60dc1d4b","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T16:03:36Z","date_created":"2022-04-06T16:03:36Z","summary":null,"body":["<article data-history-node-id=\"3086\" about=\"\/en\/alerts-advisories\/control-systems-lifepoint-informatics-security-advisory-av22-183\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-183<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>On 5 April 2022 ICS-CERT published an ICS Medical Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Patient Portal \u2013 version LPI 3.5.12.P30<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-095-01 \">ICS Advisory (ICSMA-22-095-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-lifepoint-informatics-security-advisory-av22-183","alert_type":398,"serial_number":"AV22-183","subject":null,"moderation_state":"published","external_url":null},{"nid":3087,"title":"Fortinet security advisory (AV22-184)","uuid":"88f2bbc6-e2c3-408f-99fe-5739c9632499","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T16:08:17Z","date_created":"2022-04-06T16:08:17Z","summary":null,"body":["<article data-history-node-id=\"3087\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-184\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-184<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>On 5 April 2022 Fortinet published PSIRT Advisories to address vulnerabilities affecting multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>FortiWAN \u2013 version 4.5.8 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-062\">FortiWAN \u2013 Pervasive SQL injection (FG-IR-21-062)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt-monthly-advisory\/april-2022-vulnerability-advisories\">Fortinet PSIRT Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-184","alert_type":396,"serial_number":"AV22-184","subject":null,"moderation_state":"published","external_url":null},{"nid":3089,"title":"[Control systems] Johnson Controls security advisory (AV22-185)","uuid":"1d8783bf-3356-4b9f-bab6-9772a4d5fa67","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T16:18:34Z","date_created":"2022-04-06T16:18:34Z","summary":null,"body":["<article data-history-node-id=\"3089\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-185\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-185<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>On 5 April 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Metasys ADS\/ADX\/OAS \u2013 versions 10 and 11<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in server-side request forgery (SSRF).<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-095-02 \">ICS Advisory (ICSA-22-095-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-185","alert_type":398,"serial_number":"AV22-185","subject":null,"moderation_state":"published","external_url":null},{"nid":3090,"title":"Dell security advisory (AV22-186)","uuid":"4e64d989-83ce-4498-9f5a-289022e64150","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T17:13:50Z","date_created":"2022-04-06T17:13:50Z","summary":null,"body":["<article data-history-node-id=\"3090\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-186\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-186<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>On 6 April 2022 Dell published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>R640, R740, R840 custom node \u2013 iDRAC versions prior to 5.10.10.00<\/li>\n\t<li>R640, R740, R840 custom node \u2013 BIOS versions prior to 2.13.3<\/li>\n\t<li>R650, R750 custom node \u2013 iDRAC versions prior to 5.10.10.00<\/li>\n\t<li>R650, R750, R6525 custom node \u2013 BIOS versions prior to 2.13.3<\/li>\n\t<li>R630\\R730xd \u2013 BIOS versions prior to 2.14.0<\/li>\n\t<li>ESXi 7.0 \u2013 versions prior to 7.0U3c<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000198136\/dsa-2022-087-dell-emc-powerflex-15g-based-custom-node-14g-based-vxflex-ready-node-and-13g-based-scaleio-ready-node-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (000198136)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-186","alert_type":396,"serial_number":"AV22-186","subject":null,"moderation_state":"published","external_url":null},{"nid":3091,"title":"VMware security advisory (AV22-187)","uuid":"9b8c9aa8-aca0-405b-af1d-8d5ea7f4b8e8","banner":null,"lang":"en","date_modified":"2022-04-06","date_modified_ts":"2022-04-06T19:12:09Z","date_created":"2022-04-06T19:12:09Z","summary":null,"body":["<article data-history-node-id=\"3091\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-187\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-187<br \/>\nDate: 6 April 2022<\/strong><\/p>\n\n<p>On 6 April 2022 VMware published a Security Advisory to address critical vulnerabilities in multiple products:<\/p>\n\n<ul><li>VMware Cloud Foundation \u2013 multiple versions<\/li>\n\t<li>VMware vIDM \u2013 multiple versions<\/li>\n\t<li>VMware vRealize Automation \u2013 versions 7.6 and 8.x<\/li>\n\t<li>VMware vRealize Suite Lifecycle Manager (vIDM) - versions 8.x<\/li>\n\t<li>VMware Workspace ONE Access \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution and authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0011.html \">VMSA-2022-0011<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-187","alert_type":396,"serial_number":"AV22-187","subject":null,"moderation_state":"published","external_url":null},{"nid":3092,"title":"Mozilla security advisory (AV22-188)","uuid":"b8a1c8ce-770a-401e-8566-f952b3c7c2b6","banner":null,"lang":"en","date_modified":"2022-04-07","date_modified_ts":"2022-04-07T13:11:27Z","date_created":"2022-04-07T13:11:27Z","summary":null,"body":["<article data-history-node-id=\"3092\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-188\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-188<br \/>\nDate: 7 April 2022<\/strong><\/p>\n\n<p>On 5 April 2022 Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 91.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-15\/\">Mozilla Security Advisory (MFSA 2022-15)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-188","alert_type":396,"serial_number":"AV22-188","subject":null,"moderation_state":"published","external_url":null},{"nid":3093,"title":"Ubuntu security advisory (AV22-189)","uuid":"571c918f-f9bd-494e-866f-1a0d766c3daa","banner":null,"lang":"en","date_modified":"2022-04-07","date_modified_ts":"2022-04-07T15:45:51Z","date_created":"2022-04-07T15:45:51Z","summary":null,"body":["<article data-history-node-id=\"3093\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-189\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-189<br \/>\nDate: 7 April 2022<\/strong><\/p>\n\n<p>On 6 April 2022 Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5368-1\">Ubuntu Security Notice (USN-5368-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-189","alert_type":396,"serial_number":"AV22-189","subject":null,"moderation_state":"published","external_url":null},{"nid":3094,"title":"HPE security advisory (AV22-190)","uuid":"d59ab3c8-6ee0-498b-920d-7b7b1db166cf","banner":null,"lang":"en","date_modified":"2022-04-07","date_modified_ts":"2022-04-07T19:34:21Z","date_created":"2022-04-07T19:34:21Z","summary":null,"body":["<article data-history-node-id=\"3094\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-190\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-190<br \/>\nDate: 7 April 2022<\/strong><\/p>\n\n<p>On 6 April 2022, HPE published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>Included were updates for the following:<\/p>\n\n<ul><li>HPE Aruba Instant On 1930 Switches \u2013 firmware versions prior to v1.0.7.0 (Local web interface only)<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04270en_us\">HPE Security Bulletin (hpesbnw04270en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-190","alert_type":396,"serial_number":"AV22-190","subject":null,"moderation_state":"published","external_url":null},{"nid":3095,"title":"[Control systems] ABB security advisory (AV22-191)","uuid":"5764a25e-4eb4-43e7-97c5-8ffb14f07f68","banner":null,"lang":"en","date_modified":"2022-04-08","date_modified_ts":"2022-04-08T11:42:29Z","date_created":"2022-04-08T11:42:29Z","summary":null,"body":["<article data-history-node-id=\"3095\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-191\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-191<br \/>\nDate: 8 April 2022<\/strong><\/p>\n\n<p>On 7 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Symphony Plus SPIET800 \u2013 firmware version A_B and prior<\/li>\n\t<li>Symphony Plus PNI800 \u2013 firmware version A_B and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-097-02\">ISC Advisory (ICSA-22-097-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-191","alert_type":398,"serial_number":"AV22-191","subject":null,"moderation_state":"published","external_url":null},{"nid":3096,"title":"[Control systems] Pepperl+Fuchs security advisory (AV22-192)","uuid":"1f352cdd-a7ee-4f55-86da-c85ac5f68840","banner":null,"lang":"en","date_modified":"2022-04-08","date_modified_ts":"2022-04-08T13:07:13Z","date_created":"2022-04-08T13:07:13Z","summary":null,"body":["<article data-history-node-id=\"3096\" about=\"\/en\/alerts-advisories\/control-systems-pepperlfuchs-security-advisory-av22-192\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-192<br \/>\nDate: 8 April 2022<\/strong><\/p>\n\n<p>On 7 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>WirelessHART-Gateway WHA-GW-F2D2-0-AS- Z2-ETH \u2013 versions 3.0.7, 3.0.8 and 3.0.9<\/li>\n\t<li>WirelessHART-Gateway WHA-GW-F2D2-0-AS- Z2-ETH.EIP \u2013 versions 3.0.7, 3.0.8 and 3.0.9<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may result in denial of service, remote code execution and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-097-01\">ISC Advisory (ICSA-22-097-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-pepperlfuchs-security-advisory-av22-192","alert_type":398,"serial_number":"AV22-192","subject":null,"moderation_state":"published","external_url":null},{"nid":3097,"title":"IBM security advisory (AV22-193)","uuid":"7f7e598a-07a7-4ac6-960c-807255564e32","banner":null,"lang":"en","date_modified":"2022-04-11","date_modified_ts":"2022-04-11T15:46:39Z","date_created":"2022-04-11T15:46:39Z","summary":null,"body":["<article data-history-node-id=\"3097\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-193\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-193<br \/>\nDate: 11 April 2022<\/strong><\/p>\n\n<p>Between 4 and 10 April 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Watson Machine Learning Accelerator \u2013 multiple versions<\/li>\n\t<li>IBM Tivoli Netcool Impact \u2013 version 7.1.0<\/li>\n\t<li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-ibm-planning-analytics-workspace-is-affected-by-security-vulnerabilities-16\/\">IBM Security Bulletin<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-a-security-vulnerability-has-been-identified-in-dojo-toolkil-shipped-with-ibm-tivoli-netcool-impact-cve-2021-23450\/\">IBM Security Bulletin<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/security-bulletin-vulnerability-in-json4j-cve-2021-3918-publicly-disclosed-vulnerability-impacts-ibm-watson-machine-learning-accelerator\/\">IBM Security Bulletin<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-193","alert_type":396,"serial_number":"AV22-193","subject":null,"moderation_state":"published","external_url":null},{"nid":3098,"title":"[Control systems] ABB security advisory (AV22-194)","uuid":"8ffb1d88-1212-4c9b-bd1c-2747ce75474c","banner":null,"lang":"en","date_modified":"2022-04-11","date_modified_ts":"2022-04-11T15:50:55Z","date_created":"2022-04-11T15:50:55Z","summary":null,"body":["<article data-history-node-id=\"3098\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-194\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-194<br \/>\nDate: 11 April 2022<\/strong><\/p>\n\n<p>On 11 April 2022 ABB published Cyber Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ARM600 \u2013 multiple versions and platforms<\/li>\n\t<li>Viola Systems M2M Gateway \u2013 firmware version 3.x.x<\/li>\n\t<li>ABB Arctic wireless gateways \u2013 multiple versions and platforms<\/li>\n\t<li>Viola Systems Arctic wireless gateways \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, privilege escalation and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001254&amp;Action=Launch\">ABB Cyber Security Advisory (2NGA001254)<\/a><\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001253&amp;Action=Launch\">ABB Cyber Security Advisory (2NGA001253)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-194","alert_type":398,"serial_number":"AV22-194","subject":null,"moderation_state":"published","external_url":null},{"nid":3099,"title":"Google Chrome security advisory (AV22-195)","uuid":"1c52b1b6-9f7e-4561-8bb4-36994d5a98c6","banner":null,"lang":"en","date_modified":"2022-04-11","date_modified_ts":"2022-04-11T19:56:45Z","date_created":"2022-04-11T19:56:45Z","summary":null,"body":["<article data-history-node-id=\"3099\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-195\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-195<br \/>\nDate: 11 April 2022<\/strong><\/p>\n\n<p>On 11 April 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 100.0.4896.88<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/04\/stable-channel-update-for-desktop_11.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-195","alert_type":396,"serial_number":"AV22-195","subject":null,"moderation_state":"published","external_url":null},{"nid":3100,"title":"[Control systems] Siemens security advisory (AV22-196)","uuid":"dcd9d955-cbb2-4d19-a9f4-5b02b03174df","banner":null,"lang":"en","date_modified":"2022-04-12","date_modified_ts":"2022-04-12T14:59:05Z","date_created":"2022-04-12T14:59:05Z","summary":null,"body":["<article data-history-node-id=\"3100\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-196\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-196<br \/>\nDate: 12 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SIMATIC Energy Manager Basic \u2013 versions prior to V7.3 Update 1<\/li>\n\t<li>SIMATIC Energy Manager PRO \u2013 versions prior to V7.3 Update 1<\/li>\n\t<li>SCALANCE X-300 Switch \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-655554.html\">Siemens Security Advisory (SSA-655554)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-836527.html\">Siemens Security Advisory (SSA-836527)<\/a><\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-196","alert_type":398,"serial_number":"AV22-196","subject":null,"moderation_state":"published","external_url":null},{"nid":3101,"title":"[Control systems] Schneider Electric security advisory (AV22-197)","uuid":"86481510-f1ad-44e1-83da-1837d127abb1","banner":null,"lang":"en","date_modified":"2022-04-12","date_modified_ts":"2022-04-12T15:05:05Z","date_created":"2022-04-12T15:05:05Z","summary":null,"body":["<article data-history-node-id=\"3101\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-197\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-197<br \/>\nDate: 12 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>IGSS Data Server \u2013 version V15.0.0.22073 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-102-01\">Schneider Security Advisory (SEVD-2022-102-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-197","alert_type":398,"serial_number":"AV22-197","subject":null,"moderation_state":"published","external_url":null},{"nid":3102,"title":"Citrix security advisory (AV22-198)","uuid":"4fd302e7-afc9-415a-815e-622ba6e082b9","banner":null,"lang":"en","date_modified":"2022-04-12","date_modified_ts":"2022-04-12T18:28:32Z","date_created":"2022-04-12T18:28:32Z","summary":null,"body":["<article data-history-node-id=\"3102\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-198\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-198<br \/>\nDate: 12 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 Citrix published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Citrix SD-WAN Center Management Console \u2013 versions prior to 11.4.3<\/li>\n\t<li>Citrix SD-WAN Standard\/Premium Edition Appliance \u2013 versions prior to 11.4.1<\/li>\n\t<li>Citrix SD-WAN Orchestrator for On-Premises \u2013 versions prior to 13.2.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow cross-site scripting and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX370550\">Citrix SD-WAN Security Bulletin for CVE-2022-27505 and CVE-2022-27506 <\/a><\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/search\/#\/All%20Products?ct=Security%20Bulletins\">Citrix Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-198","alert_type":396,"serial_number":"AV22-198","subject":null,"moderation_state":"published","external_url":null},{"nid":3103,"title":"[Control systems] Aethon security advisory (AV22-199)","uuid":"ed81c164-cb94-42e4-8a97-ddb8d9548df9","banner":null,"lang":"en","date_modified":"2022-04-12","date_modified_ts":"2022-04-12T18:45:57Z","date_created":"2022-04-12T18:45:57Z","summary":null,"body":["<article data-history-node-id=\"3103\" about=\"\/en\/alerts-advisories\/control-systems-aethon-security-advisory-av22-199\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-199<br \/>\nDate: 12 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>TUG Home Base Server \u2013 versions prior to 24<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure, execution of arbitrary commands and denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-102-05 \">ICS Advisory (ICSA-22-102-05)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aethon-security-advisory-av22-199","alert_type":398,"serial_number":"AV22-199","subject":null,"moderation_state":"published","external_url":null},{"nid":3104,"title":"Microsoft security advisory \u2013 April 2022 monthly rollup (AV22-200)","uuid":"6f6e586a-620a-4b42-8e7f-e78a900c2cff","banner":null,"lang":"en","date_modified":"2022-04-12","date_modified_ts":"2022-04-12T18:48:30Z","date_created":"2022-04-12T18:48:30Z","summary":null,"body":["<article data-history-node-id=\"3104\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2022-monthly-rollup-av22-200\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-200<br \/>\nDate: 12 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dynamics 365 \u2013 versions 9.0 and 9.1<\/li>\n\t<li>Windows 11 \u2013 multiple versions<\/li>\n\t<li>Windows 10 \u2013 multiple versions<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions<\/li>\n\t<li>Windows 7 \u2013 multiple versions<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Apr\">April 2022 Release Notes<\/a><\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-april-2022-monthly-rollup-av22-200","alert_type":396,"serial_number":"AV22-200","subject":null,"moderation_state":"published","external_url":null},{"nid":3105,"title":"Adobe security advisory (AV22-201)","uuid":"94780ba1-1cb3-45bf-a0d0-241827823641","banner":null,"lang":"en","date_modified":"2022-04-12","date_modified_ts":"2022-04-12T18:51:09Z","date_created":"2022-04-12T18:51:09Z","summary":null,"body":["<article data-history-node-id=\"3105\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-201\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-201<br \/>\nDate: 12 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 Adobe published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Adobe Commerce \u2013 multiple versions<\/li>\n\t<li>Magento Open Source \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb22-13.html\">Adobe Commerce and Magento Open Source<\/a><\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-201","alert_type":396,"serial_number":"AV22-201","subject":null,"moderation_state":"published","external_url":null},{"nid":3106,"title":"SAP security advisory \u2013 April 2022 monthly rollup (AV22-202)","uuid":"e6ddeeee-5117-4b50-a533-f933fe01eae3","banner":null,"lang":"en","date_modified":"2022-04-12","date_modified_ts":"2022-04-12T19:22:10Z","date_created":"2022-04-12T19:22:10Z","summary":null,"body":["<article data-history-node-id=\"3106\" about=\"\/en\/alerts-advisories\/sap-security-advisory-april-2022-monthly-rollup-av22-202\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-202<br \/>\nDate: 12 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 SAP published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>SAP HANA Extended Application Service \u2013 version 1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. \u00a0<\/p>\n\n<p><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day \u2013 April 2022<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities\">CCCS Alert Spring remote code execution vulnerabilities<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-april-2022-monthly-rollup-av22-202","alert_type":396,"serial_number":"AV22-202","subject":null,"moderation_state":"published","external_url":null},{"nid":3107,"title":"Dell security advisory (AV22-203)","uuid":"c6766195-4334-4a4a-ac69-eb8e109b061f","banner":null,"lang":"en","date_modified":"2022-04-13","date_modified_ts":"2022-04-13T14:05:02Z","date_created":"2022-04-13T14:05:02Z","summary":null,"body":["<article data-history-node-id=\"3107\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-203\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-203<br \/>\nDate: 13 April 2022<\/strong><\/p>\n\n<p>On 11 April 2022 Dell published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC Data Protection Search \u2013 version 19.5 and prior<\/li>\n\t<li>Dell EMC Integrated Data Protection Appliance \u2013 version 2.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000198300\/dsa-2022-075-dell-emc-data-protection-search-and-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (000198300)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-203","alert_type":396,"serial_number":"AV22-203","subject":null,"moderation_state":"published","external_url":null},{"nid":3108,"title":"Cisco security advisory (AV22-205)","uuid":"c77fe401-7b6b-4419-8334-71fe9505399b","banner":null,"lang":"en","date_modified":"2022-04-13","date_modified_ts":"2022-04-13T17:30:17Z","date_created":"2022-04-13T17:30:17Z","summary":null,"body":["<article data-history-node-id=\"3108\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-205\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-205<br \/>\nDate: 13 April 2022<\/strong><br \/><br \/>\nOn 13 April 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>3504 Wireless Controller - Release 8.10.151.0 or Release 8.10.162.0<\/li>\n\t<li>5520 Wireless Controller - Release 8.10.151.0 or Release 8.10.162.0<\/li>\n\t<li>8540 Wireless Controller - Release 8.10.151.0 or Release 8.10.162.0<\/li>\n\t<li>Mobility Express - Release 8.10.151.0 or Release 8.10.162.0<\/li>\n\t<li>Virtual Wireless Controller (vWLC) - Release 8.10.151.0 or Release 8.10.162.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-wlc-auth-bypass-JRNhV4fF\">Cisco Security Advisory (cisco-sa-wlc-auth-bypass-JRNhV4fF)<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-205","alert_type":396,"serial_number":"AV22-205","subject":null,"moderation_state":"published","external_url":null},{"nid":3109,"title":"Juniper Networks security advisory (AV22-206)","uuid":"742a69b0-c466-46fb-9351-ebafb26a9ac8","banner":null,"lang":"en","date_modified":"2022-04-13","date_modified_ts":"2022-04-13T19:49:30Z","date_created":"2022-04-13T19:49:30Z","summary":null,"body":["<article data-history-node-id=\"3109\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-206\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-206<br \/>\nDate: 13 April 2022<\/strong><\/p>\n\n<p>On 13 April 2022 Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Contrail Networking \u2013 versions prior to 2011.L4<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2022-04-Security-Bulletin-Contrail-Networking-Multiple-Vulnerabilities-have-been-resolved-in-Contrail-Networking-release-2011-L4\">Juniper Networks Security Bulletin (JSA69510)<\/a><\/p>\n\n<p><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=date descending&amp;f:ctype=[Security Advisories]\">Juniper Networks Security Bulletins<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-206","alert_type":396,"serial_number":"AV22-206","subject":null,"moderation_state":"published","external_url":null},{"nid":3110,"title":"VMware security advisory (AV22-207)","uuid":"287a5044-4636-47a8-acac-4376f4c6e3c9","banner":null,"lang":"en","date_modified":"2022-04-14","date_modified_ts":"2022-04-14T18:05:21Z","date_created":"2022-04-14T18:05:21Z","summary":null,"body":["<article data-history-node-id=\"3110\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-207\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-207<br \/>\nDate: 14 April 2022<\/strong><\/p>\n\n<p>On 14 April 2022 VMware published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>VMware Cloud Director \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0013.html \">VMSA-2022-0013<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-207","alert_type":396,"serial_number":"AV22-207","subject":null,"moderation_state":"published","external_url":null},{"nid":3111,"title":"[Control systems] Delta Electronics security advisory (AV22-208)","uuid":"ec18c057-7465-4843-96f8-eddd2b4af58e","banner":null,"lang":"en","date_modified":"2022-04-14","date_modified_ts":"2022-04-14T19:09:53Z","date_created":"2022-04-14T19:09:53Z","summary":null,"body":["<article data-history-node-id=\"3111\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-208\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-208<br \/>\nDate: 14 April 2022<\/strong><\/p>\n\n<p>On 14 April 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>DMARS \u2013 versions prior to v2.1.10.24<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-104-01\">ICS Advisory (ICSA-22-104-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-208","alert_type":398,"serial_number":"AV22-208","subject":null,"moderation_state":"published","external_url":null},{"nid":3112,"title":"[Control systems] Johnson Controls Inc. security advisory (AV22-209)","uuid":"190d68eb-7a04-4838-a0e6-88b4e7760a30","banner":null,"lang":"en","date_modified":"2022-04-14","date_modified_ts":"2022-04-14T19:13:33Z","date_created":"2022-04-14T19:13:33Z","summary":null,"body":["<article data-history-node-id=\"3112\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-inc-security-advisory-av22-209\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-209<br \/>\nDate: 14 April 2022<\/strong><\/p>\n\n<p>On 14 April 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Metasys ADS\/ADX\/OAS Servers \u2013 versions 10 and 11<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-104-02\">ICS Advisory (ICSA-22-104-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-inc-security-advisory-av22-209","alert_type":398,"serial_number":"AV22-209","subject":null,"moderation_state":"published","external_url":null},{"nid":3113,"title":"[Control systems] Red Lion security advisory (AV22-210)","uuid":"412599a2-e192-455d-aae1-a9b07acc05de","banner":null,"lang":"en","date_modified":"2022-04-14","date_modified_ts":"2022-04-14T19:17:20Z","date_created":"2022-04-14T19:17:20Z","summary":null,"body":["<article data-history-node-id=\"3113\" about=\"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory-av22-210\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-210<br \/>\nDate: 14 April 2022<\/strong><\/p>\n\n<p>On 14 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DA50N - all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-104-03\">ICS Advisory (ICSA-22-104-03)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory-av22-210","alert_type":398,"serial_number":"AV22-210","subject":null,"moderation_state":"published","external_url":null},{"nid":3114,"title":"Google Chrome security advisory (AV22-211)","uuid":"c43bdab9-ee95-4a63-afe0-a0e6e1317968","banner":null,"lang":"en","date_modified":"2022-04-19","date_modified_ts":"2022-04-19T14:11:02Z","date_created":"2022-04-19T14:11:02Z","summary":null,"body":["<article data-history-node-id=\"3114\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-211\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-211<br \/>\nDate: 19 April 2022<\/strong><\/p>\n\n<p>On 14 April 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 100.0.4896.127<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2022-1364 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/04\/stable-channel-update-for-desktop_14.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-211","alert_type":396,"serial_number":"AV22-211","subject":null,"moderation_state":"published","external_url":null},{"nid":3115,"title":"IBM security advisory (AV22-212)","uuid":"7bc53abf-0fe0-4825-921d-0ae72188cc73","banner":null,"lang":"en","date_modified":"2022-04-19","date_modified_ts":"2022-04-19T17:46:38Z","date_created":"2022-04-19T17:46:38Z","summary":null,"body":["<article data-history-node-id=\"3115\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-212\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-212<br \/>\nDate: 19 April 2022<\/strong><\/p>\n\n<p>Between 11 and 17 April 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>App Connect Enterprise Certified Container \u2013 multiple versions<\/li>\n\t<li>Cloud APM \u2013 version 8.1.4<\/li>\n\t<li>Data Risk Manager \u2013 2.0.6.12<\/li>\n\t<li>Db2 On Openshift \u2013 multiple versions<\/li>\n\t<li>Db2 and Db2 Warehouse on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>Informix Dynamic Server \u2013 versions 12.10 and 14.10<\/li>\n\t<li>Maximo for Civil Infrastructure \u2013 versions 7.6.2.1, 7.6.3 and 7.6.3.1<\/li>\n\t<li>Netezza Analytics \u2013 multiple versions and platforms<\/li>\n\t<li>Process Mining \u2013 1.12.0.3<\/li>\n\t<li>Security Guardium \u2013 multiple versions<\/li>\n\t<li>Security SOAR \u2013 versions 26 to 44.1<\/li>\n\t<li>Sterling B2B Integrator \u2013 multiple versions<\/li>\n\t<li>Tivoli Netcool Impact \u2013 multiple versions<\/li>\n\t<li>Tivoli Network Manager \u2013 versions 4.2 to 4.2.0.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/ \">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-212","alert_type":396,"serial_number":"AV22-212","subject":null,"moderation_state":"published","external_url":null},{"nid":3116,"title":"Microsoft Edge security advisory (AV22-213)","uuid":"362a3415-5640-4596-84c2-363070fbd55d","banner":null,"lang":"en","date_modified":"2022-04-19","date_modified_ts":"2022-04-19T17:51:40Z","date_created":"2022-04-19T17:51:40Z","summary":null,"body":["<article data-history-node-id=\"3116\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-213\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-213<br \/>\nDate: 19 April 2022<\/strong><\/p>\n\n<p>On 15 April 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 100.0.1185.44<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2022-1364 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-15-2022  \">Microsoft Edge Stable Channel Release Notes<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-213","alert_type":396,"serial_number":"AV22-213","subject":null,"moderation_state":"published","external_url":null},{"nid":3117,"title":"[Control systems] FANUC security advisory (AV22-214)","uuid":"3a4357cc-bc5c-4cc9-aa79-57b566c7c6fc","banner":null,"lang":"en","date_modified":"2022-04-19","date_modified_ts":"2022-04-19T19:36:27Z","date_created":"2022-04-19T19:36:27Z","summary":null,"body":["<article data-history-node-id=\"3117\" about=\"\/en\/alerts-advisories\/control-systems-fanuc-security-advisory-av22-214\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-214<br \/>\nDate: 19 April 2022<\/strong><\/p>\n\n<p>On 19 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ROBOGUIDE \u2013 v9.40083.00.05 (Rev T) and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, denial of service, and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-109-03\">ICS Advisory (ICSA-22-109-03)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fanuc-security-advisory-av22-214","alert_type":398,"serial_number":"AV22-214","subject":null,"moderation_state":"published","external_url":null},{"nid":3118,"title":"[Control systems] Automated Logic security advisory (AV22-215)","uuid":"adf38e96-556b-41bd-804b-c4d0cc70e54d","banner":null,"lang":"en","date_modified":"2022-04-19","date_modified_ts":"2022-04-19T19:39:15Z","date_created":"2022-04-19T19:39:15Z","summary":null,"body":["<article data-history-node-id=\"3118\" about=\"\/en\/alerts-advisories\/control-systems-automated-logic-security-advisory-av22-215\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-215<br \/>\nDate: 19 April 2022<\/strong><\/p>\n\n<p>On 19 April 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>WebCtrl Server \u2013 version 7.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-109-02\">ICS Advisory (ICSA-22-109-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-automated-logic-security-advisory-av22-215","alert_type":398,"serial_number":"AV22-215","subject":null,"moderation_state":"published","external_url":null},{"nid":3119,"title":"[Control systems] Interlogix security advisory (AV22-216)","uuid":"6b6df7e5-a0bb-4c30-8b2a-d2726bd338e0","banner":null,"lang":"en","date_modified":"2022-04-19","date_modified_ts":"2022-04-19T19:42:01Z","date_created":"2022-04-19T19:42:01Z","summary":null,"body":["<article data-history-node-id=\"3119\" about=\"\/en\/alerts-advisories\/control-systems-interlogix-security-advisory-av22-216\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-216<br \/>\nDate: 19 April 2022<\/strong><\/p>\n\n<p>On 19 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Hills ComNav \u2013 versions prior to 3002-19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-109-01\">ICS Advisory (ICSA-22-109-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-interlogix-security-advisory-av22-216","alert_type":398,"serial_number":"AV22-216","subject":null,"moderation_state":"published","external_url":null},{"nid":3120,"title":"[Control systems] Elcomplus security advisory (AV22-217)","uuid":"9983b14a-665c-4735-a817-ddb2e6faba4a","banner":null,"lang":"en","date_modified":"2022-04-19","date_modified_ts":"2022-04-19T19:45:11Z","date_created":"2022-04-19T19:45:11Z","summary":null,"body":["<article data-history-node-id=\"3120\" about=\"\/en\/alerts-advisories\/control-systems-elcomplus-security-advisory-av22-217\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-217<br \/>\nDate: 19 April 2022<\/strong><\/p>\n\n<p>On 19 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>SmartPPT SCADA \u2013 version v1.1<\/li>\n\t<li>SmartPPT SCADA Server \u2013 version v1.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-109-04\">ICS Advisory (ICSA-22-109-04)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-109-05\">ICS Advisory (ICSA-22-109-05)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-elcomplus-security-advisory-av22-217","alert_type":398,"serial_number":"AV22-217","subject":null,"moderation_state":"published","external_url":null},{"nid":3121,"title":"[Control systems] Siemens security advisory (AV22-218)","uuid":"5ebf6ba3-b3a4-49f6-9602-42c239142a6a","banner":null,"lang":"en","date_modified":"2022-04-20","date_modified_ts":"2022-04-20T12:27:05Z","date_created":"2022-04-20T12:27:05Z","summary":null,"body":["<article data-history-node-id=\"3121\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-218\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-218<br \/>\nDate: 20 April 2022<\/strong><\/p>\n\n<p>On 19 April 2022 Siemens published Security Advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>Operation Scheduler \u2013 versions prior to V2.0.4<\/li>\n\t<li>SiPass integrated \u2013 multiple versions and platforms<\/li>\n\t<li>Siveillance Identity \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-254054.html\">Siemens Security Advisory (SSA-254054)<\/a><\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-218","alert_type":398,"serial_number":"AV22-218","subject":null,"moderation_state":"published","external_url":null},{"nid":3122,"title":"Cisco security advisory (AV22-219)","uuid":"b6bcc928-02a4-4678-8b99-433c3a3c7b23","banner":null,"lang":"en","date_modified":"2022-04-20","date_modified_ts":"2022-04-20T17:59:27Z","date_created":"2022-04-20T17:59:27Z","summary":null,"body":["<article data-history-node-id=\"3122\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-219\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-219<br \/>\nDate: 20 April 2022<\/strong><\/p>\n\n<p>On 20 April 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>RoomOS \u2013 versions prior to January 2022<\/li>\n\t<li>TelePresence CE \u2013 multiple versions<\/li>\n\t<li>Umbrella Virtual Appliance \u2013 versions prior to 3.3.2<\/li>\n\t<li>Virtualized Infrastructure Manager \u2013 versions prior to 4.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ce-roomos-dos-c65x2Qf2\">Cisco Security Advisory (cisco-sa-ce-roomos-dos-c65x2Qf2)<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-uva-static-key-6RQTRs4c\">Cisco Security Advisory (cisco-sa-uva-static-key-6RQTRs4c)<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-vim-privesc-T2tsFUf\">Cisco Security Advisory (cisco-sa-vim-privesc-T2tsFUf)<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-219","alert_type":396,"serial_number":"AV22-219","subject":null,"moderation_state":"published","external_url":null},{"nid":3123,"title":"Oracle security advisory \u2013 April 2022 Quarterly Rollup (AV22-220)","uuid":"34b5d85b-756a-4c5d-b18b-2e071f6b2a52","banner":null,"lang":"en","date_modified":"2022-04-20","date_modified_ts":"2022-04-20T18:03:35Z","date_created":"2022-04-20T18:03:35Z","summary":null,"body":["<article data-history-node-id=\"3123\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-april-2022-quarterly-rollup-av22-220\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-220<br \/>\nDate: 20 April 2022<\/strong><\/p>\n\n<p>On 19 April 2022 Oracle published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Blockchain Platform \u2013 versions prior to 21.1.2<\/li>\n\t<li>Communications Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Communications \u2013 multiple versions and platforms<\/li>\n\t<li>E-Business Suite \u2013 multiple versions<\/li>\n\t<li>Enterprise Manager \u2013 multiple versions and platforms<\/li>\n\t<li>Financial Services Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Fusion Middleware \u2013 multiple versions and platforms<\/li>\n\t<li>GoldenGate \u2013 multiple versions and platforms<\/li>\n\t<li>HealthCare Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Health Sciences Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Hyperion \u2013 multiple versions and platforms<\/li>\n\t<li>JD Edwards \u2013 multiple versions and platforms<\/li>\n\t<li>MySQL \u2013 multiple versions and platforms<\/li>\n\t<li>Oracle Systems \u2013 multiple versions and platforms<\/li>\n\t<li>Retail Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Supply Chain \u2013 multiple versions and platforms<\/li>\n\t<li>Virtualization \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2022.html\">Oracle Critical Patch Update Advisory \u2013 April 2022<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-april-2022-quarterly-rollup-av22-220","alert_type":396,"serial_number":"AV22-220","subject":null,"moderation_state":"published","external_url":null},{"nid":3124,"title":"HPE security advisory (AV22-221)","uuid":"1506855f-659d-408f-b805-92a0f13494e3","banner":null,"lang":"en","date_modified":"2022-04-21","date_modified_ts":"2022-04-21T16:38:08Z","date_created":"2022-04-21T16:38:08Z","summary":null,"body":["<article data-history-node-id=\"3124\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-221\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-221<br \/>\nDate: 21 April 2022<\/strong><\/p>\n\n<p>On 20 April 2022, HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>IceWall Gen 11 certd module \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of this vulnerability could cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbmu04275en_us\">HPE Security Bulletin (hpesbnw04275en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-221","alert_type":396,"serial_number":"AV22-221","subject":null,"moderation_state":"published","external_url":null},{"nid":3125,"title":"Ubuntu security advisory (AV22-222)","uuid":"849a5c0b-787f-476f-a5d8-13e0103d2df1","banner":null,"lang":"en","date_modified":"2022-04-21","date_modified_ts":"2022-04-21T16:43:15Z","date_created":"2022-04-21T16:43:15Z","summary":null,"body":["<article data-history-node-id=\"3125\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-222\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-222<br \/>\nDate: 21 April 2022<\/strong><\/p>\n\n<p>Between 20 and 21 April 2022, Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5381-1  \">Ubuntu Security Notice (USN-5381-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5383-1\">Ubuntu Security Notice (USN-5383-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5384-1\">Ubuntu Security Notice (USN-5384-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5385-1\">Ubuntu Security Notice (USN-5385-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-222","alert_type":396,"serial_number":"AV22-222","subject":null,"moderation_state":"published","external_url":null},{"nid":3126,"title":"[Control systems] Johnson Controls security advisory (AV22-223)","uuid":"3cdce541-0059-4daf-b0c7-8863092c76d7","banner":null,"lang":"en","date_modified":"2022-04-21","date_modified_ts":"2022-04-21T19:39:52Z","date_created":"2022-04-21T19:39:52Z","summary":null,"body":["<article data-history-node-id=\"3126\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-223\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-223<br \/>\nDate: 21 April 2022<\/strong><\/p>\n\n<p>On 21 April 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Metasys System Configuration Tool (SCT) \u2013 versions prior to 14.2.2<\/li>\n\t<li>Metasys System Configuration Tool Pro (SCT Pro) \u2013 versions prior to 14.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-111-02 \">ICS Advisory (ICSA-22-111-02)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-223","alert_type":398,"serial_number":"AV22-223","subject":null,"moderation_state":"published","external_url":null},{"nid":3127,"title":"[Control systems] Hitachi Energy security advisory (AV22-224)","uuid":"3b8e6f0c-0649-415f-8294-77c1cb33e693","banner":null,"lang":"en","date_modified":"2022-04-21","date_modified_ts":"2022-04-21T19:42:18Z","date_created":"2022-04-21T19:42:18Z","summary":null,"body":["<article data-history-node-id=\"3127\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-224\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-224<br \/>\nDate: 21 April 2022<\/strong><\/p>\n\n<p>On 21 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>MicroSCADA Pro\/X SYS600 \u2013 versions prior to 10.3 \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-111-03 \">ICS Advisory (ICSA-22-111-03)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-224","alert_type":398,"serial_number":"AV22-224","subject":null,"moderation_state":"published","external_url":null},{"nid":3128,"title":"[Control systems] Delta Electronics security advisory (AV22-225)","uuid":"f79a4886-805e-475e-afb3-6a186f7dfeae","banner":null,"lang":"en","date_modified":"2022-04-21","date_modified_ts":"2022-04-21T19:44:43Z","date_created":"2022-04-21T19:44:43Z","summary":null,"body":["<article data-history-node-id=\"3128\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-225\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-225<br \/>\nDate: 21 April 2022<\/strong><\/p>\n\n<p>On 21 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ASDA-Soft \u2013 version 5.4.1.0 and prior \u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-111-01 \">ICS Advisory (ICSA-22-111-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-225","alert_type":398,"serial_number":"AV22-225","subject":null,"moderation_state":"published","external_url":null},{"nid":3133,"title":"Apache security advisory (AV22-204) - update 1","uuid":"c1a60ccb-f6bd-40b4-a2ff-5331df2ecba9","banner":null,"lang":"en","date_modified":"2022-04-22","date_modified_ts":"2022-04-22T20:04:16Z","date_created":"2022-04-22T17:02:52Z","summary":null,"body":["<article data-history-node-id=\"3133\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av22-204\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-204<br \/>\nDate: 13 April 2022<br \/>\nUpdated: 22 April 2022<\/strong><\/p>\n\n<p>On 12 April 2022 Apache published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Apache Struts \u2013 versions 2.0.0 to 2.5.29<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On 20 April 2022, this vulnerability was re-evaluated to a CVSS 9.8 in NIST NVD (National Institute of Standards and Technology National Vulnerability Database). In addition, an alleged proof of concept is available. The Cyber Centre would like to highlight that exposure to this vulnerability requires implementations of forced OGNL (Object Graph Navigation Language) evaluation in the tag's attributes based on untrusted\/unvalidated user input, which is not recommended by Apache.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<h2 class=\"h3\">References<\/h2>\n\n<p><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-062\">Apache Struts Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/struts.apache.org\/security\/#do-not-use-incoming-untrusted-user-input-in-forced-expression-evaluation\">Apache Struts\u00a0| Security Guide\u00a0| Do not use incoming, untrusted user input in forced expression evaluation<\/a><\/p>\n\n<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-31805\">NVD NIST CVE-2021-31805<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av22-204","alert_type":396,"serial_number":"AV22-204","subject":null,"moderation_state":"published","external_url":null},{"nid":3129,"title":"Dell security advisory (AV22-226)","uuid":"d56d5582-e1d2-46a7-a8b4-6cc231eb1f82","banner":null,"lang":"en","date_modified":"2022-04-22","date_modified_ts":"2022-04-22T18:23:18Z","date_created":"2022-04-22T18:23:18Z","summary":null,"body":["<article data-history-node-id=\"3129\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-226\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-226<br \/>\nDate: 22 April 2022<\/strong><\/p>\n\n<p>On 21 April 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC VxRail \u2013 4.7.x versions prior to 4.7.542<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000198739\/dsa-2022-101-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000198739)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities  \">Spring remote code execution vulnerabilities (AL22-004)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-226","alert_type":396,"serial_number":"AV22-226","subject":null,"moderation_state":"published","external_url":null},{"nid":3130,"title":"IBM security advisory (AV22-227)","uuid":"95effed4-658e-48c3-89e8-52db62967b9b","banner":null,"lang":"en","date_modified":"2022-04-25","date_modified_ts":"2022-04-25T17:54:15Z","date_created":"2022-04-25T17:54:15Z","summary":null,"body":["<article data-history-node-id=\"3130\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-227\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-227<br \/>\nDate: 25 April 2022<\/strong><\/p>\n\n<p>Between 18 and 24 April 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM DB2 \u2013 multiple versions<\/li>\n\t<li>IBM Cognos Analytics \u2013 multiple versions<\/li>\n\t<li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n\t<li>IBM QRadar Use Case Manager \u2013 versions 1.0 to 3.4.0<\/li>\n\t<li>IBM Robotic Process Automation \u2013 multiple versions<\/li>\n\t<li>IBM Sterling File Gateway \u2013 multiple versions<\/li>\n\t<li>IBM Watson Explorer \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities \">Spring remote code execution vulnerabilities (AL22-004)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-227","alert_type":396,"serial_number":"AV22-227","subject":null,"moderation_state":"published","external_url":null},{"nid":3131,"title":"Dell security advisory (AV22-228)","uuid":"b565211a-3b1b-495e-8293-a2bfdff969c4","banner":null,"lang":"en","date_modified":"2022-04-25","date_modified_ts":"2022-04-25T19:40:04Z","date_created":"2022-04-25T19:40:04Z","summary":null,"body":["<article data-history-node-id=\"3131\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-228\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-228<br \/>\nDate: 25 April 2022<\/strong><\/p>\n\n<p>Dell Security Advisory (AV22-228)<br \/>\nOn 25 April 2022 Dell published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>PowerPath Management Appliance \u2013 multiple versions<\/li>\n\t<li>PowerPath Linux \u2013 version 7.4<\/li>\n\t<li>PowerPath Windows \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000198826\/dsa-2022-108-powerpath-and-powerpath-management-appliance-security-update-for-openssl-vulnerability\">Dell Security Advisory (000198826)<\/a><br \/><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-228","alert_type":396,"serial_number":"AV22-228","subject":null,"moderation_state":"published","external_url":null},{"nid":3132,"title":"Dell security advisory (AV22-229)","uuid":"2cdf4b74-1050-4399-9928-9b987c22564d","banner":null,"lang":"en","date_modified":"2022-04-26","date_modified_ts":"2022-04-26T12:16:38Z","date_created":"2022-04-26T12:16:38Z","summary":null,"body":["<article data-history-node-id=\"3132\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-229\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-229<br \/>\nDate: 26 April 2022<\/strong><\/p>\n\n<p>On 25 April 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC NetWorker vProxy \u2013 version 4.3.0-17 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000198849\/dsa-2022-109-dell-emc-networker-vproxy-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Advisory (000198849)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-229","alert_type":396,"serial_number":"AV22-229","subject":null,"moderation_state":"published","external_url":null},{"nid":3134,"title":"HPE security advisory (AV22-230)","uuid":"f6484102-bfe0-4079-b6f7-e8447fc0191c","banner":null,"lang":"en","date_modified":"2022-04-26","date_modified_ts":"2022-04-26T14:48:14Z","date_created":"2022-04-26T14:48:14Z","summary":null,"body":["<article data-history-node-id=\"3134\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-230\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-230<br \/>\nDate: 26 April 2022<\/strong><\/p>\n\n<p>On 25 April 2022, HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SimpliVity Omnistack for HPE \u2013 versions prior to 4.1.0U1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow remote code execution and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04272en_us\">HPE Security Bulletin (hpesbst04272en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-230","alert_type":396,"serial_number":"AV22-230","subject":null,"moderation_state":"published","external_url":null},{"nid":3135,"title":"F5 security advisory (AV22-231)","uuid":"b5e501e6-2276-4d3c-9141-b82716d28412","banner":null,"lang":"en","date_modified":"2022-04-26","date_modified_ts":"2022-04-26T14:54:16Z","date_created":"2022-04-26T14:54:16Z","summary":null,"body":["<article data-history-node-id=\"3135\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-231\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-231<br \/>\nDate: 26 April 2022<\/strong><\/p>\n\n<p>On 25 April 2022, F5 published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Traffix SDC \u2013 version 5.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability may allow local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the suggested mitigation.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K53648360 \">F5 Security Advisory (K53648360)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-231","alert_type":396,"serial_number":"AV22-231","subject":null,"moderation_state":"published","external_url":null},{"nid":3136,"title":"[Control systems] Hitachi Energy security advisory (AV22-232)","uuid":"648b7fba-b61c-46e9-aa91-ec8880e670ff","banner":null,"lang":"en","date_modified":"2022-04-26","date_modified_ts":"2022-04-26T18:20:26Z","date_created":"2022-04-26T18:20:26Z","summary":null,"body":["<article data-history-node-id=\"3136\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-232\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-232<br \/>\nDate: 26 April 2022<\/strong><\/p>\n\n<p>On 26 April 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>System Data Manager \u2013 SDM600 versions prior to 1.2 FP2 HF10<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a denial of service or information disclosure. \u00a0<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-116-01\">ICS Advisory (ICSA-22-116-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-232","alert_type":398,"serial_number":"AV22-232","subject":null,"moderation_state":"published","external_url":null},{"nid":3137,"title":"Ubuntu security advisory (AV22-233)","uuid":"a7d3ba15-c2d1-4cf8-b8b1-405ba8795cd0","banner":null,"lang":"en","date_modified":"2022-04-26","date_modified_ts":"2022-04-26T19:39:38Z","date_created":"2022-04-26T19:39:38Z","summary":null,"body":["<article data-history-node-id=\"3137\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-233\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-233<br \/>\nDate: 26 April 2022<\/strong><\/p>\n\n<p>On 26 April 2022, Ubuntu released a Security Notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5390-1\">Ubuntu Security Notice (USN-5390-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-233","alert_type":396,"serial_number":"AV22-233","subject":null,"moderation_state":"published","external_url":null},{"nid":3138,"title":"Google Chrome security advisory (AV22-234)","uuid":"0a88bf3b-0600-47bd-945a-cc8ff1d21a44","banner":null,"lang":"en","date_modified":"2022-04-27","date_modified_ts":"2022-04-27T15:35:51Z","date_created":"2022-04-27T15:35:51Z","summary":null,"body":["<article data-history-node-id=\"3138\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-234\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-234<br \/>\nDate: 27 April 2022<\/strong><\/p>\n\n<p>On 26 April 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 101.0.4951.41<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/04\/stable-channel-update-for-desktop_26.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-234","alert_type":396,"serial_number":"AV22-234","subject":null,"moderation_state":"published","external_url":null},{"nid":3139,"title":"Cisco security advisory (AV22-235)","uuid":"43793b51-3f8a-41c5-9a35-e8b78c74e7ba","banner":null,"lang":"en","date_modified":"2022-04-27","date_modified_ts":"2022-04-27T18:08:28Z","date_created":"2022-04-27T18:08:28Z","summary":null,"body":["<article data-history-node-id=\"3139\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-235\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-235<br \/>\nDate: 27 April 2022<\/strong><\/p>\n\n<p>On 27 April 2022 Cisco published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Adaptive Security Appliance \u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Firepower Threat Defense \u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Firepower Management Center \u2013 multiple versions<\/li>\n\t<li>Cisco IOS XE Software \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-235","alert_type":396,"serial_number":"AV22-235","subject":null,"moderation_state":"published","external_url":null},{"nid":3159,"title":"WSO2 Remote code execution vulnerabilities","uuid":"71d68edd-acd0-4f27-8d20-83a3d0333987","banner":null,"lang":"en","date_modified":"2022-04-27","date_modified_ts":"2022-04-27T20:01:56Z","date_created":"2022-04-27T19:53:03Z","summary":null,"body":["<article data-history-node-id=\"3159\" about=\"\/en\/alerts-advisories\/wso2-remote-code-execution-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL22-005<br \/><strong>Date: <\/strong>27 April 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>On 1 April 2022, WSO2 disclosed a vulnerability <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"> <span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, tracked as CVE-2022-29464 <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"> <span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>, that impacts a line of products which when exploited would allow remote code execution due to improper validation of user input.<\/p>\n\n<p>On 25 April 2022, CISA disclosed that the vulnerability was being actively exploited <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. The Cyber Centre is also aware that active exploitation has been reported within Canada.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 1 April 2022, WSO2 disclosed vulnerability CVE-2022-29464 <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"> <span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"> <span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> that allows remote code execution on multiple products. Rated as a CVSS 9.8, the vulnerability is due to an improper validation of user inputs. Exploitation results in the successful upload of an arbitrary file to the affected system which can then be remotely executed by an unauthenticated user for further exploitation.<\/p>\n\n<p>The vulnerability has been identified as affecting the following products:<\/p>\n\n<ul><li>WSO2 API Manager 2.2.0 and above<\/li>\n\t<li>WSO2 Identity Server 5.2.0 and above<\/li>\n\t<li>WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, 5.6.0<\/li>\n\t<li>WSO2 Identity Server as Key Manager 5.3.0 and above<\/li>\n\t<li>WSO2 Enterprise Integrator 6.2.0 and above<\/li>\n\t<li>WSO2 Open Banking AM 1.4.0 and above<\/li>\n\t<li>WSO2 Open Banking KM 1.4.0 and above<\/li>\n<\/ul><h2>Suggested action<\/h2>\n\n<p>WSO2 has provided temporary mitigations and delivered the fixes for all the supported product versions. All customers with a support subscription should review the WSO2 Updates and apply the recommended fixes <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>For organizations who are using open-source versions, end-of-license versions or who are not able to install the fixes, WSO2 recommends mitigations to protect applications and systems affected by these vulnerabilities. A summary of these mitigations from the WSO2 security advisory <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> are:<\/p>\n\n<ul><li>For API Manager, Identity Server, Identity Server as Key Manager, IS Analytics\n\t<ul><li>Remove all the mappings defined inside the FileUploadConfig tag in &lt;product_home&gt;\/repository\/conf\/carbon.xml<\/li>\n\t<\/ul><\/li>\n\t<li>For API Manager\n\t<ul><li>Add the referenced configuration to &lt;product_home&gt;\/repository\/conf\/deployment.toml<\/li>\n\t<\/ul><\/li>\n\t<li>For Identity Server, Identity Server as Key Manager\n\t<ul><li>Add the referenced configuration to &lt;product_home&gt;\/repository\/conf\/deployment.toml<\/li>\n\t<\/ul><\/li>\n\t<li>For Enterprise Integrator\n\t<ul><li>For EI profile remove the following mappings in the &lt;product_home&gt;\/conf\/carbon.xml file from the &lt;FileUploadConfig&gt; section.<\/li>\n\t\t<li>For Business process \/ Broker and Analytics profiles apply the same change for carbon.xml file at the following locations respectively.<\/li>\n\t<\/ul><\/li>\n\t<li>For other unsupported products\/versions based on WSO2 Carbon Kernel 4 versions\n\t<ul><li>Remove all the mappings defined inside the FileUploadConfig tag in &lt;product_home&gt;\/repository\/conf\/carbon.xml<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Proofpoint has released a Suricata Intrusion Detection System (IDS) signature to assist in the identification of exploitation attempts <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/docs.wso2.com\/display\/Security\/Security+Advisory+WSO2-2021-1738\">WSO2 Security Advisory WSO2-2021-1738 <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-29464\">NIST National Vulnerability Database (CVE-2022-29464)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to <span>first<\/span> footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities Catalog, CISA<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/wso2.com\/updates\/\">WSO2 Product Update Portal<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/rules.emergingthreats.net\/open\/suricata-5.0\/emerging-all.rules\">2036378 - ET EXPLOIT WSO2 Server RCE (CVE-2022-29464)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wso2-remote-code-execution-vulnerabilities","alert_type":397,"serial_number":"AL22-005","subject":null,"moderation_state":"published","external_url":null},{"nid":3140,"title":"Dell security advisory (AV22-236)","uuid":"dce2c3a9-6fd6-444d-8ceb-9795847b4cb4","banner":null,"lang":"en","date_modified":"2022-04-29","date_modified_ts":"2022-04-29T18:12:14Z","date_created":"2022-04-29T18:12:14Z","summary":null,"body":["<article data-history-node-id=\"3140\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-236\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-236<br \/>\nDate: 29 April 2022<\/strong><\/p>\n\n<p>On 28 April 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Enterprise Hybrid Cloud \u2013 versions prior to 4.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199001\/dsa-2022-114-dell-emc-enterprise-hybrid-cloud-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (000199001)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-236","alert_type":396,"serial_number":"AV22-236","subject":null,"moderation_state":"published","external_url":null},{"nid":3141,"title":"[Control systems] ABB security advisory (AV22-237)","uuid":"44be5809-1e60-426d-9fe0-8c32b9006e0a","banner":null,"lang":"en","date_modified":"2022-04-29","date_modified_ts":"2022-04-29T18:15:19Z","date_created":"2022-04-29T18:15:19Z","summary":null,"body":["<article data-history-node-id=\"3141\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-237\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-237<br \/>\nDate: 29 April 2022<\/strong><\/p>\n\n<p>On 28 April 2022 ABB published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>AC500 V3 \u2013 versions prior to 3.6.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR010997&amp;Action=Launch\">ABB Cyber Security Advisory (3ADR010997)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-237","alert_type":398,"serial_number":"AV22-237","subject":null,"moderation_state":"published","external_url":null},{"nid":3142,"title":"Microsoft Edge security advisory (AV22-238)","uuid":"f7c6fd66-68ef-4424-9043-2bde0912097b","banner":null,"lang":"en","date_modified":"2022-04-29","date_modified_ts":"2022-04-29T18:19:23Z","date_created":"2022-04-29T18:19:23Z","summary":null,"body":["<article data-history-node-id=\"3142\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-238\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-238<br \/>\nDate: 29 April 2022<\/strong><\/p>\n\n<p>On 28 April 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 101.0.1210.32<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-28-2022\">Microsoft Edge Stable Channel Release Notes<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-238","alert_type":396,"serial_number":"AV22-238","subject":null,"moderation_state":"published","external_url":null},{"nid":3143,"title":"Dell security advisory (AV22-239)","uuid":"769590e8-7e90-4ccd-b578-feaa8290ed7b","banner":null,"lang":"en","date_modified":"2022-05-02","date_modified_ts":"2022-05-02T14:49:39Z","date_created":"2022-05-02T14:49:39Z","summary":null,"body":["<article data-history-node-id=\"3143\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-239\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-239<br \/>\nDate: 2 May 2022<\/strong><\/p>\n\n<p>On 29 April 2022 Dell published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Unity Operating Environment \u2013 versions prior to 5.2.0.0.5.173<\/li>\n\t<li>Dell UnityVSA Operating Environment \u2013 versions prior to 5.2.0.0.5.173<\/li>\n\t<li>Dell Unity XT Operating Environment \u2013 versions prior to 5.2.0.0.5.173<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199050\/dsa-2022-021-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (000199050)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-239","alert_type":396,"serial_number":"AV22-239","subject":null,"moderation_state":"published","external_url":null},{"nid":3144,"title":"IBM security advisory (AV22-240)","uuid":"c359c085-c8c2-4623-a8b7-19dd1b481247","banner":null,"lang":"en","date_modified":"2022-05-02","date_modified_ts":"2022-05-02T17:00:31Z","date_created":"2022-05-02T17:00:31Z","summary":null,"body":["<article data-history-node-id=\"3144\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-240\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-240<br \/>\nDate: 2 May 2022<\/strong><\/p>\n\n<p>Between 25 April and 1 May 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Content Collector for Email \u2013 version 4.0.x<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.1.x and 11.2.x<\/li>\n\t<li>InfoSphere Information Server, Server on Cloud \u2013 version 11.7<\/li>\n\t<li>Operations Dashboard \u2013 versions 2020.4.1, 2021.1.1, 2021.2.1, 2021.3.1 and 2021.4.1<\/li>\n\t<li>PowerVM Novalink \u2013 versions 1.0.0.16, 2.0, 2.0.1, 2.0.2 and 2.0.2.1<\/li>\n\t<li>SPSS Collaboration and Deployment Services \u2013 versions 8.2, 8.2.1 and 8.2.2<\/li>\n\t<li>Watson Discovery for IBM Cloud Pak for Data \u2013 versions 2.0.0 to 2.2.1 and 4.0.0 to 4.0.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities \">Spring remote code execution vulnerabilities<\/a> (AL22-004)<br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-240","alert_type":396,"serial_number":"AV22-240","subject":null,"moderation_state":"published","external_url":null},{"nid":3145,"title":"F5 security advisory (AV22-241)","uuid":"8db193ac-e7bd-43c9-b7b6-abf411feaa82","banner":null,"lang":"en","date_modified":"2022-05-02","date_modified_ts":"2022-05-02T19:05:05Z","date_created":"2022-05-02T19:05:05Z","summary":null,"body":["<article data-history-node-id=\"3145\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-241\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-241<br \/>\nDate: 2 May 2022<\/strong><\/p>\n\n<p>Between 29 April 2022 and 1 May 2022, F5 published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple modules and versions<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 multiple versions<\/li>\n\t<li>F5OS \u2013 multiple versions<\/li>\n\t<li>Traffix SDC \u2013 version 5.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/new-updated-articles\">F5 Security Advisories<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-241","alert_type":396,"serial_number":"AV22-241","subject":null,"moderation_state":"published","external_url":null},{"nid":3146,"title":"Android security advisory (AV22-242)","uuid":"8037f7da-8849-421a-a0a0-c6f17e5c0e91","banner":null,"lang":"en","date_modified":"2022-05-02","date_modified_ts":"2022-05-02T19:07:40Z","date_created":"2022-05-02T19:07:40Z","summary":null,"body":["<article data-history-node-id=\"3146\" about=\"\/en\/alerts-advisories\/android-security-advisory-av22-242\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-242<br \/>\nDate: 2 May 2022<\/strong><\/p>\n\n<p>On 2 May 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2022-05-01\">Android Security Bulletin<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-av22-242","alert_type":396,"serial_number":"AV22-242","subject":null,"moderation_state":"published","external_url":null},{"nid":3147,"title":"Dell security advisory (AV22-243)","uuid":"d3430b56-407f-4de2-a4e9-dbe548e89109","banner":null,"lang":"en","date_modified":"2022-05-03","date_modified_ts":"2022-05-03T14:25:11Z","date_created":"2022-05-03T14:25:11Z","summary":null,"body":["<article data-history-node-id=\"3147\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-243\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-243\n  <br \/>\n  Date: 3 May 2022<\/strong>\n<\/p>\n<p>On 2 May 2022 Dell published Security Advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Cloud Tiering Appliance \u2013 versions 13.0 and 13.1<\/li>\n  <li>Dell EMC AppSync \u2013 versions 4.2.0.0 and 4.3.0.0<\/li>\n  <li>vRO Plug-in \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199084\/dsa-2022-111-dell-emc-cloud-tiering-appliance-security-update-for-third-party-component-vulnerabilities\">Dell Security Advisory (DSA-2022-111)<\/a>\n<\/p>\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199089\/dsa-2022-104-dell-emc-appsync-security-update-for-a-spring-spring4shell-or-springshell-vulnerability\">Dell Security Advisory (DSA-2022-104)<\/a>\n<\/p>\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199086\/dsa-2022-113-vrealize-orchestrator-vro-plug-ins-for-dell-emc-storage-security-update-for-spring-rce-vulnerabilities\">Dell Security Advisory (DSA-2022-113)<\/a>\n<\/p>\n<p><a href=\"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a>\n  <br \/>\n  \u00a0\n<\/p>\n<p>\u00a0\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-243","alert_type":396,"serial_number":"AV22-243","subject":null,"moderation_state":"published","external_url":null},{"nid":3148,"title":"Mozilla security advisory (AV22-244)","uuid":"b5772c74-7aa9-4858-9e9f-d7a7dcd0b321","banner":null,"lang":"en","date_modified":"2022-05-03","date_modified_ts":"2022-05-03T14:28:52Z","date_created":"2022-05-03T14:28:52Z","summary":null,"body":["<article data-history-node-id=\"3148\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-244\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-244<br \/>\nDate: 3 May 2022<\/strong><\/p>\n\n<p>On 3 May 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 100<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-16\/\">Mozilla Security Advisory (MFSA 2022-16)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-17\/\">Mozilla Security Advisory (MFSA 2022-17)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-244","alert_type":396,"serial_number":"AV22-244","subject":null,"moderation_state":"published","external_url":null},{"nid":3149,"title":"HPE security advisory (AV22-245)","uuid":"738ed181-d011-4c58-a82c-186150c34035","banner":null,"lang":"en","date_modified":"2022-05-03","date_modified_ts":"2022-05-03T15:18:50Z","date_created":"2022-05-03T15:18:50Z","summary":null,"body":["<article data-history-node-id=\"3149\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-245\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-245<br \/>\nDate: 3 May 2022<\/strong><\/p>\n\n<p>On 2 May 2022, HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HP-UX 11i v3 ONC and NFS Software \u2013 versions prior to B.11.31.23<\/li>\n<\/ul><p>Exploitation of this vulnerability could cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04274en_us\">HPE Security Bulletin (hpesbux04274en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-245","alert_type":396,"serial_number":"AV22-245","subject":null,"moderation_state":"published","external_url":null},{"nid":3151,"title":"Fortinet security advisory (AV22-246)","uuid":"12802c22-1cf6-40dd-a547-26feda94e6dd","banner":null,"lang":"en","date_modified":"2022-05-03","date_modified_ts":"2022-05-03T17:48:05Z","date_created":"2022-05-03T17:48:05Z","summary":null,"body":["<article data-history-node-id=\"3151\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-246\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-246<br \/>\nDate: 3 May 2022<\/strong><\/p>\n\n<p>On 3 May 2022 Fortinet published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FortiFone \u2013 version 3.0.11 and prior<\/li>\n\t<li>FortiIsolator \u2013 version 2.3.2 and prior<\/li>\n\t<li>FortiClientWindows \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to unauthorized access, remote code execution or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-22-007\">FortiFone \u2013 Multiple vulnerabilities in PJSIP library (FG-IR-22-007)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-040\">FortiIsolator \u2013 Unauthorized user able to regenerate CA certificate (FG-IR-21-040)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-154\">FortiFone \u2013 Privilege escalation in FortiClient installer (FG-IR-21-154)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-246","alert_type":396,"serial_number":"AV22-246","subject":null,"moderation_state":"published","external_url":null},{"nid":3150,"title":"[Control systems] Yokogawa security advisory (AV22-247)","uuid":"ded1a2bc-8c13-4f40-98c4-2e4e2292b993","banner":null,"lang":"en","date_modified":"2022-05-03","date_modified_ts":"2022-05-03T17:54:29Z","date_created":"2022-05-03T17:54:29Z","summary":null,"body":["<article data-history-node-id=\"3150\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-247\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-247<br \/>\nDate: 3 May 2022<\/strong><\/p>\n\n<p>On 3 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>CENTUM VP \u2013 multiple versions<\/li>\n\t<li>B\/M9000 VP \u2013 multiple versions<\/li>\n\t<li>Prosafe-RS \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-123-01 \">ICS Advisory (ICSA-22-123-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-247","alert_type":398,"serial_number":"AV22-247","subject":null,"moderation_state":"published","external_url":null},{"nid":3152,"title":"F5 security advisory (AV22-248)","uuid":"5e3dc32e-011b-4934-9f00-70878abf7dc1","banner":null,"lang":"en","date_modified":"2022-05-04","date_modified_ts":"2022-05-04T15:25:08Z","date_created":"2022-05-04T15:25:08Z","summary":null,"body":["<article data-history-node-id=\"3152\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-248\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-248<br \/>\nDate: 4 May 2022<\/strong><\/p>\n\n<p>On 4 May 2022, F5 published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple modules and versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to remote code execution, denial of service or unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K55879220\">F5 Security Advisory (K55879220) \u2013 Overview of F5 vulnerabilities<\/a><\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/new-updated-articles\">F5 Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-248","alert_type":396,"serial_number":"AV22-248","subject":null,"moderation_state":"published","external_url":null},{"nid":3153,"title":"HPE security advisory (AV22-249)","uuid":"759cdaa5-5e76-4176-8ffb-ab6acb5ce560","banner":null,"lang":"en","date_modified":"2022-05-04","date_modified_ts":"2022-05-04T15:49:41Z","date_created":"2022-05-04T15:49:41Z","summary":null,"body":["<article data-history-node-id=\"3153\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-249\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-249<br \/>\nDate: 4 May 2022<\/strong><\/p>\n\n<p>On 3 May 2022, HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Aruba Switch \u2013 multiple models<\/li>\n\t<li>ArubaOS-Switch \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04291en_us\">HPE Security Bulletin (hpesbnw04291en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-249","alert_type":396,"serial_number":"AV22-249","subject":null,"moderation_state":"published","external_url":null},{"nid":3154,"title":"Cisco security advisory (AV22-250)","uuid":"b5cf73d2-d670-4096-8fd0-17407b21d2cd","banner":null,"lang":"en","date_modified":"2022-05-04","date_modified_ts":"2022-05-04T19:00:26Z","date_created":"2022-05-04T19:00:26Z","summary":null,"body":["<article data-history-node-id=\"3154\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-250\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-250<br \/>\nDate: 4 May 2022<\/strong><\/p>\n\n<p>On 4 May 2022 Cisco published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Cisco Enterprise NFVIS \u2013 versions prior to 4.7.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to virtual machine escape, execution of arbitrary commands or unauthorized access to data.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-NFVIS-MUL-7DySRX9\">Cisco Security Advisory (cisco-sa-NFVIS-MUL-7DySRX9)<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-250","alert_type":396,"serial_number":"AV22-250","subject":null,"moderation_state":"published","external_url":null},{"nid":3155,"title":"Dell security advisory (AV22-251)","uuid":"f1692af7-edc9-42ea-bda5-2d9caf529175","banner":null,"lang":"en","date_modified":"2022-05-05","date_modified_ts":"2022-05-05T13:55:40Z","date_created":"2022-05-05T13:55:40Z","summary":null,"body":["<article data-history-node-id=\"3155\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-251\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-251<br \/>\nDate: 5 May 2022<\/strong><\/p>\n\n<p>On 4 May 2022 Dell published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC NetWorker vProxy \u2013 version 4.3.0-17 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199156\/dsa-2022-121-dell-emc-networker-vproxy-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Advisory (DSA-2022-121)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-251","alert_type":396,"serial_number":"AV22-251","subject":null,"moderation_state":"published","external_url":null},{"nid":3156,"title":"HPE security advisory (AV22-252)","uuid":"c3500564-4639-4201-8756-1b5b3470c0e7","banner":null,"lang":"en","date_modified":"2022-05-05","date_modified_ts":"2022-05-05T16:30:31Z","date_created":"2022-05-05T16:30:31Z","summary":null,"body":["<article data-history-node-id=\"3156\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-252\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-252<br \/>\nDate: 5 May 2022<\/strong><\/p>\n\n<p>Between 4 and 5 May 2022, HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AirWave Management Platform \u2013 version 8.2.14.0 and prior<\/li>\n\t<li>Aruba Fabric Composer and Plexxi Composable Fabric Manager \u2013 version 6.2.0 and prior<\/li>\n\t<li>ClearPass Policy Manager \u2013 multiple versions<\/li>\n\t<li>HPE SANnav Management Software \u2013 versions 2.0.0, 2.1.0x and 2.1.1x<\/li>\n\t<li>Silver Peak Orchestrator \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service, arbitrary code execution and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04282en_us\">HPE Security Bulletin (hpesbst04282en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04285en_us\">HPE Security Bulletin (hpesbnw04285en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04279en_us\">HPE Security Bulletin (hpesbnw04279en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-252","alert_type":396,"serial_number":"AV22-252","subject":null,"moderation_state":"published","external_url":null},{"nid":3157,"title":"[Control systems] Johnson Controls security advisory (AV22-253)","uuid":"b28f6a55-22ea-4cde-95de-1cb4f807e661","banner":null,"lang":"en","date_modified":"2022-05-05","date_modified_ts":"2022-05-05T18:45:20Z","date_created":"2022-05-05T18:45:20Z","summary":null,"body":["<article data-history-node-id=\"3157\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-253\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-253<br \/>\nDate: 5 May 2022<\/strong><\/p>\n\n<p>On 5 May 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Metasys ADS\/ADX\/OAS Servers \u2013 versions 10 and 11<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated user to obtain or change the credentials of other users.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-125-01\">ICS Advisory (ICSA-22-125-01)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-253","alert_type":398,"serial_number":"AV22-253","subject":null,"moderation_state":"published","external_url":null},{"nid":3161,"title":"F5 security advisory (AV22-254)","uuid":"c74dd93e-df7e-4ce9-8c92-4948947e8fd0","banner":null,"lang":"en","date_modified":"2022-05-09","date_modified_ts":"2022-05-09T15:09:58Z","date_created":"2022-05-09T15:09:58Z","summary":null,"body":["<article data-history-node-id=\"3161\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-254\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-254<br \/>\nDate: 9 May 2022<\/strong><\/p>\n\n<p>On 6 May 2022, F5 published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>BIG-IP \u2013 versions prior to 17.0.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to the execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K12492858\">F5 Security Advisory (K12492858)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-254","alert_type":396,"serial_number":"AV22-254","subject":null,"moderation_state":"published","external_url":null},{"nid":3162,"title":"IBM security advisory (AV22-255)","uuid":"acefea10-17e1-43ec-8677-8173c63cba8f","banner":null,"lang":"en","date_modified":"2022-05-09","date_modified_ts":"2022-05-09T15:13:20Z","date_created":"2022-05-09T15:13:20Z","summary":null,"body":["<article data-history-node-id=\"3162\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-255\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-255\n  <br \/>\n  Date: 9 May 2022<\/strong>\n<\/p>\n<p>Between 2 and 8 May 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>IBM API Connect \u2013 versions V10.0.0.0 to V10.0.1.1<\/li>\n  <li>IBM Cloud Pak System \u2013 multiple versions<\/li>\n  <li>IBM Cloud Transformation Advisor \u2013 versions 2.0.1 to 3.0.0<\/li>\n  <li>IBM Watson Assistant for IBM Cloud Pack for Data \u2013 multiple versions<\/li>\n  <li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data \u2013 versions 4.0.0 to 4.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a>\n<\/p>\n<p><a href=\"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a>\n  <br \/>\n  \u00a0\n<\/p>\n<p>\u00a0\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-255","alert_type":396,"serial_number":"AV22-255","subject":null,"moderation_state":"published","external_url":null},{"nid":3163,"title":"[Control systems] Adminer security advisory (AV22-256)","uuid":"e39b4455-0814-4df3-bc09-9805c5d7ae98","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T16:39:44Z","date_created":"2022-05-10T16:39:44Z","summary":null,"body":["<article data-history-node-id=\"3163\" about=\"\/en\/alerts-advisories\/control-systems-adminer-security-advisory-av22-256\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-256<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Adminer \u2013 versions 1.112.0 to 4.6.2<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-130-01\">ICS Advisory (ICSA-22-130-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-adminer-security-advisory-av22-256","alert_type":398,"serial_number":"AV22-256","subject":null,"moderation_state":"published","external_url":null},{"nid":3164,"title":"[Control systems] Eaton security advisory (AV22-257)","uuid":"6d513ba4-a21b-42b4-8972-e1ec880582ba","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T16:44:16Z","date_created":"2022-05-10T16:44:16Z","summary":null,"body":["<article data-history-node-id=\"3164\" about=\"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-av22-257\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-257<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Eaton Intelligent Power Protector (IPP) \u2013 versions prior to v1.69 release 166<\/li>\n\t<li>Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) \u2013 version v1.5.0 plus205 and prior<\/li>\n\t<li>Eaton Intelligent Power Manager (IPM) v1 \u2013 versions prior to v1.70<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-130-02\">ICS Advisory (ICSA-22-130-02)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-130-03\">ICS Advisory (ICSA-22-130-03)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-130-04\">ICS Advisory (ICSA-22-130-04)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-eaton-security-advisory-av22-257","alert_type":398,"serial_number":"AV22-257","subject":null,"moderation_state":"published","external_url":null},{"nid":3165,"title":"Microsoft security advisory \u2013 May 2022 monthly rollup (AV22-258)","uuid":"96f9832f-4ecf-42b8-8ce7-e04b1e92917b","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T18:52:09Z","date_created":"2022-05-10T18:52:09Z","summary":null,"body":["<article data-history-node-id=\"3165\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2022-monthly-rollup-av22-258\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-258<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 11 \u2013 multiple versions<\/li>\n\t<li>Windows 10 \u2013 multiple versions<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions<\/li>\n\t<li>Windows 7 \u2013 multiple versions<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-May\">May 2022 Release Notes<\/a><\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-may-2022-monthly-rollup-av22-258","alert_type":396,"serial_number":"AV22-258","subject":null,"moderation_state":"published","external_url":null},{"nid":3166,"title":"[Control systems] Schneider Electric security advisory (AV22-259)","uuid":"b78b4f8a-7736-4d0c-977b-cd5129ffadae","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T19:39:38Z","date_created":"2022-05-10T19:39:38Z","summary":null,"body":["<article data-history-node-id=\"3166\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-259\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-259<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Wiser Smart, EER21000 \u2013 version V4.5 and prior<\/li>\n\t<li>Wiser Smart, EER21001 \u2013 version V4.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/download\/document\/SEVD-2022-130-03\">Schneider Security Advisory (SEVD-2022-130-03)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-259","alert_type":398,"serial_number":"AV22-259","subject":null,"moderation_state":"published","external_url":null},{"nid":3167,"title":"[Control systems] Siemens security advisory (AV22-260)","uuid":"59ec3f32-c121-4313-b47d-2cb1c4cf28b2","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T19:42:58Z","date_created":"2022-05-10T19:42:58Z","summary":null,"body":["<article data-history-node-id=\"3167\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-260\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-260<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Desigo DXR2 \u2013 versions prior to V01.21.142.5-22<\/li>\n\t<li>Desigo PXC3 \u2013 versions prior to V01.21.142.4-18<\/li>\n\t<li>Desigo PXC4 \u2013 versions prior to V02.20.142.10-10884<\/li>\n\t<li>Desigo PXC5 \u2013 versions prior to V02.20.142.10-10884<\/li>\n\t<li>SICAM P850 \u2013 multiple versions and platforms<\/li>\n\t<li>SICAM P855 \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-626968.html\">Siemens Security Advisory (SSA-626968)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-165073.html\">Siemens Security Advisory (SSA-165073)<\/a><\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-260","alert_type":398,"serial_number":"AV22-260","subject":null,"moderation_state":"published","external_url":null},{"nid":3168,"title":"[Control systems] AVEVA security advisory (AV22-261)","uuid":"a19273f9-f2ca-4e68-97bb-2ab623a88edb","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T19:46:08Z","date_created":"2022-05-10T19:46:08Z","summary":null,"body":["<article data-history-node-id=\"3168\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-261\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-261<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>AVEVA InTouch Access Anywhere \u2013 all versions<\/li>\n\t<li>AVEVA Plant SCADA Access Anywhere \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-130-05\">ICS Advisory (ICSA-22-130-05)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-261","alert_type":398,"serial_number":"AV22-261","subject":null,"moderation_state":"published","external_url":null},{"nid":3169,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-262)","uuid":"ea71b83c-03d6-4ef8-9741-a1805ebc92ba","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T19:51:36Z","date_created":"2022-05-10T19:51:36Z","summary":null,"body":["<article data-history-node-id=\"3169\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-262\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-262<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MELSOFT GT OPC UA Client \u2013 versions 1.00A to 1.02C<\/li>\n\t<li>GT SoftGOT2000 \u2013 versions 1.215Z to 1.270G<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-130-06\">ICS Advisory (ICSA-22-130-06)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-262","alert_type":398,"serial_number":"AV22-262","subject":null,"moderation_state":"published","external_url":null},{"nid":3170,"title":"Google Chrome security advisory (AV22-263)","uuid":"d83b9818-180f-4f5c-8b90-b0567283d29b","banner":null,"lang":"en","date_modified":"2022-05-10","date_modified_ts":"2022-05-10T19:54:09Z","date_created":"2022-05-10T19:54:09Z","summary":null,"body":["<article data-history-node-id=\"3170\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-263\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-263<br \/>\nDate: 10 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 101.0.4951.64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/05\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-263","alert_type":396,"serial_number":"AV22-263","subject":null,"moderation_state":"published","external_url":null},{"nid":3171,"title":"Adobe security advisory (AV22-264)","uuid":"3b726d41-f24c-498f-9d71-1a3098fafea9","banner":null,"lang":"en","date_modified":"2022-05-11","date_modified_ts":"2022-05-11T14:40:59Z","date_created":"2022-05-11T14:40:59Z","summary":null,"body":["<article data-history-node-id=\"3171\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-264\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-264<br \/>\nDate: 11 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 Adobe published Security Bulletins to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Character Animator 2021 \u2013 version 4.4.2 and prior<\/li>\n\t<li>Character Animator 2022 \u2013 version 22.3 and prior<\/li>\n\t<li>ColdFusion 2018 \u2013 Update 13 and prior<\/li>\n\t<li>ColdFusion 2021 \u2013 version 3 and prior<\/li>\n\t<li>Framemaker \u2013 multiple versions<\/li>\n\t<li>InCopy \u2013 multiple versions<\/li>\n\t<li>InDesign \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-264","alert_type":396,"serial_number":"AV22-264","subject":null,"moderation_state":"published","external_url":null},{"nid":3172,"title":"Dell security advisory (AV22-265)","uuid":"65527914-ce2a-4d6b-83ef-17fea6818724","banner":null,"lang":"en","date_modified":"2022-05-11","date_modified_ts":"2022-05-11T14:45:37Z","date_created":"2022-05-11T14:45:37Z","summary":null,"body":["<article data-history-node-id=\"3172\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-265\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-265<br \/>\nDate: 11 May 2022<\/strong><\/p>\n\n<p>On 9 May 2022 Dell published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Latitude 5495 \u2013 BIOS versions prior to 1.6.0<\/li>\n\t<li>OptiPlex 5055 A-Series \u2013 BIOS versions prior to 1.5.0<\/li>\n\t<li>OptiPlex 5055 Ryzen APU \u2013 BIOS versions prior to 1.5.0<\/li>\n\t<li>OptiPlex 5055 Ryzen CPU \u2013 BIOS versions prior to 1.5.0<\/li>\n\t<li>PowerEdge Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199269\/dsa-2022-126\">Dell Security Advisory (DSA-2022-126)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199283\/dsa-2022-093\">Dell Security Advisory (DSA-2022-093)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-265","alert_type":396,"serial_number":"AV22-265","subject":null,"moderation_state":"published","external_url":null},{"nid":3173,"title":"HPE security advisory (AV22-266)","uuid":"068aec30-9b0c-4d0d-846e-c725d33c54f0","banner":null,"lang":"en","date_modified":"2022-05-11","date_modified_ts":"2022-05-11T16:19:25Z","date_created":"2022-05-11T16:19:25Z","summary":null,"body":["<article data-history-node-id=\"3173\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-266\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-266<br \/>\nDate: 11 May 2022<\/strong><\/p>\n\n<p>Between 9 and 10 May 2022, HPE published Security Bulletins to address vulnerabilities multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Apollo 4200 Gen10 Server \u2013 versions prior to 2.64_04_21_2022<\/li>\n\t<li>HPE 3PAR StoreServ \u2013 versions prior to 2.94_04_14_2022<\/li>\n\t<li>HPE Storage \u2013 multiple versions and platforms<\/li>\n\t<li>ProLiant \u2013 multiple versions and platforms<\/li>\n\t<li>StoreEasy \u2013 multiple versions and platforms<\/li>\n\t<li>StoreVirtual \u2013 versions prior to 2.94_04_14_2022<\/li>\n\t<li>Synergy \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04286en_us\">HPE Security Bulletin (hpesbhf04286en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04292en_us\">HPE Security Bulletin (hpesbhf04292en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04296en_us\">HPE Security Bulletin (hpesbhf04296en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04294en_us\">HPE Security Bulletin (hpesbst04294en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-266","alert_type":396,"serial_number":"AV22-266","subject":null,"moderation_state":"published","external_url":null},{"nid":3174,"title":" SAP security advisory \u2013 May 2022 monthly rollup (AV22-267)","uuid":"9170b5e6-a8f5-49b3-aece-bdb805cc119b","banner":null,"lang":"en","date_modified":"2022-05-11","date_modified_ts":"2022-05-11T16:25:04Z","date_created":"2022-05-11T16:25:04Z","summary":null,"body":["<article data-history-node-id=\"3174\" about=\"\/en\/alerts-advisories\/sap-security-advisory-may-2022-monthly-rollup-av22-267\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-267<br \/>\nDate: 11 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Business One Cloud \u2013 version 1.1<\/li>\n\t<li>SAP Commerce \u2013 versions 1905, 2005, 2105 and 2011<\/li>\n\t<li>SAP Customer Profitability Analytics \u2013 version 2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. \u00a0<\/p>\n\n<p><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day<\/a><\/p>\n\n<p><a href=\"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities\">CCCS Alert Spring remote code execution vulnerabilities<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-may-2022-monthly-rollup-av22-267","alert_type":396,"serial_number":"AV22-267","subject":null,"moderation_state":"published","external_url":null},{"nid":3175,"title":"Red Hat security advisory (AV22-268)","uuid":"757957b7-9457-4422-b1e2-58f63c19381b","banner":null,"lang":"en","date_modified":"2022-05-11","date_modified_ts":"2022-05-11T19:16:31Z","date_created":"2022-05-11T19:16:31Z","summary":null,"body":["<article data-history-node-id=\"3175\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-268\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-268<br \/>\nDate: 11 May 2022<\/strong><\/p>\n\n<p>On 11 May 2022 Red Hat published Security Advisories to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server \u2013 AUS 7.3 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 AUS 7.4 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 AUS 7.6 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 TUS 7.6 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE \u2013 Update Services for SAP Solutions 7.6 ppc64le<\/li>\n\t<li>Red Hat Enterprise Linux Server for x86_64 \u2013 Update Services for SAP Solutions 7.6 x86_64<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:2186\">Red Hat Security Advisory (RHSA-2022:2186)<\/a><\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:2188\">Red Hat Security Advisory (RHSA-2022:2188)<\/a><\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:2189\">Red Hat Security Advisory (RHSA-2022:2189)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-268","alert_type":396,"serial_number":"AV22-268","subject":null,"moderation_state":"published","external_url":null},{"nid":3176,"title":"Intel security advisory (AV22-269)","uuid":"665165d1-973f-4727-92c3-371d3def6a12","banner":null,"lang":"en","date_modified":"2022-05-11","date_modified_ts":"2022-05-11T19:28:28Z","date_created":"2022-05-11T19:28:28Z","summary":null,"body":["<article data-history-node-id=\"3176\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av22-269\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-269<br \/>\nDate: 11 May 2022<\/strong><\/p>\n\n<p>On 10 May 2022 Intel published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>10th Generation Intel Core Processor Family<\/li>\n\t<li>2nd Generation Intel Xeon Scalable Processors<\/li>\n\t<li>3rd Generation Intel Xeon Scalable Processor Family<\/li>\n\t<li>Intel Celeron N4000 and N5000 Processor Families<\/li>\n\t<li>Intel Core Processors \u2013 multiple generations and platforms<\/li>\n\t<li>Intel Core Processors with Intel Hybrid Technology<\/li>\n\t<li>Intel Core X-series Processors<\/li>\n\t<li>Intel Pentium Silver N6000 Processor Family<\/li>\n\t<li>Intel Xeon Processor \u2013 multiple families and platforms<\/li>\n\t<li>Rocket Lake Xeon<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00601.html\">Intel Security Advisory (INTEL-SA-00601)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av22-269","alert_type":396,"serial_number":"AV22-269","subject":null,"moderation_state":"published","external_url":null},{"nid":3217,"title":"Ubuntu security advisory (AV22-270)","uuid":"987fa1d7-b333-4462-85b0-e7c2460416e7","banner":null,"lang":"en","date_modified":"2022-05-12","date_modified_ts":"2022-05-12T18:17:52Z","date_created":"2022-05-12T18:17:52Z","summary":null,"body":["<article data-history-node-id=\"3217\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-270\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-270<br \/>\nDate: 12 May 2022<\/strong><\/p>\n\n<p>On 12 May 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-270","alert_type":396,"serial_number":"AV22-270","subject":null,"moderation_state":"published","external_url":null},{"nid":3218,"title":"[Control systems] Delta Electronics security advisory (AV22-271)","uuid":"61851dca-045f-44d2-8719-3be0bb455165","banner":null,"lang":"en","date_modified":"2022-05-13","date_modified_ts":"2022-05-13T12:22:22Z","date_created":"2022-05-13T12:22:22Z","summary":null,"body":["<article data-history-node-id=\"3218\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-271\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-271<br \/>\nDate: 13 May 2022<\/strong><\/p>\n\n<p>On 12 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>CNCSoft \u2013 versions prior to 1.01.32<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-132-01\">ICS Advisory (ICSA-22-132-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-271","alert_type":398,"serial_number":"AV22-271","subject":null,"moderation_state":"published","external_url":null},{"nid":3219,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-272)","uuid":"3e1bb7e8-119e-4b0e-8ba0-aba08a43e0ee","banner":null,"lang":"en","date_modified":"2022-05-13","date_modified_ts":"2022-05-13T12:25:12Z","date_created":"2022-05-13T12:25:12Z","summary":null,"body":["<article data-history-node-id=\"3219\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-272\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-272<br \/>\nDate: 13 May 2022<\/strong><\/p>\n\n<p>On 12 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>MELSOFT iQ AppPortal (SW1DND-IQAPL-M) \u2013 versions 1.00A to 1.26C<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, denial of service, information disclosure and authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-132-02\">ICS Advisory (ICSA-22-132-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-272","alert_type":398,"serial_number":"AV22-272","subject":null,"moderation_state":"published","external_url":null},{"nid":3220,"title":"[Control systems] Cambium Networks security advisory (AV22-273)","uuid":"f7c725b3-471b-40cb-8ecb-5f71cca4a342","banner":null,"lang":"en","date_modified":"2022-05-13","date_modified_ts":"2022-05-13T14:30:20Z","date_created":"2022-05-13T14:30:20Z","summary":null,"body":["<article data-history-node-id=\"3220\" about=\"\/en\/alerts-advisories\/control-systems-cambium-networks-security-advisory-av22-273\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-273<br \/>\nDate: 13 May 2022<\/strong><\/p>\n\n<p>On 12 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>cnMaestro On-Premises \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-132-04\">ICS Advisory (ICSA-22-132-04)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cambium-networks-security-advisory-av22-273","alert_type":398,"serial_number":"AV22-273","subject":null,"moderation_state":"published","external_url":null},{"nid":3221,"title":"[Control systems] Inkscape security advisory (AV22-274)","uuid":"9c83b152-a9a0-4648-ae1f-1d854c6432c9","banner":null,"lang":"en","date_modified":"2022-05-13","date_modified_ts":"2022-05-13T14:34:53Z","date_created":"2022-05-13T14:34:53Z","summary":null,"body":["<article data-history-node-id=\"3221\" about=\"\/en\/alerts-advisories\/control-systems-inkscape-security-advisory-av22-274\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-274<br \/>\nDate: 13 May 2022<\/strong><\/p>\n\n<p>On 12 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Inkscape - version 0.91<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-132-03\">ICS Advisory (ICSA-22-132-03)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inkscape-security-advisory-av22-274","alert_type":398,"serial_number":"AV22-274","subject":null,"moderation_state":"published","external_url":null},{"nid":3222,"title":"Dell security advisory (AV22-275)","uuid":"a3322e38-66c5-4c7f-88ac-e26490295825","banner":null,"lang":"en","date_modified":"2022-05-13","date_modified_ts":"2022-05-13T18:24:50Z","date_created":"2022-05-13T18:24:50Z","summary":null,"body":["<article data-history-node-id=\"3222\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-275\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-275<br \/>\nDate: 13 May 2022<\/strong><\/p>\n\n<p>On 11 May 2022 Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC AppSync \u2013 version 4.4.0.0<\/li>\n\t<li>Dell Unity Operating Environment (OE) \u2013 versions prior to 5.2.0.0.5.173<\/li>\n\t<li>Dell UnityVSA Operating Environment (OE) \u2013 versions prior to 5.2.0.0.5.173<\/li>\n\t<li>Dell Unity XT Operating Environment (OE) \u2013 versions prior to 5.2.0.0.5.173<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199446\/dsa-2022-138-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-cross-site-scripting-vulnerability\">Dell Security Advisory (DSA-2022-138)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199436\/dsa-2022-131-dell-emc-appsync-security-update-for-multiple-vulnerabilities-in-embedded-service-enabler-ese-component-of-appsync\">Dell Security Advisory (DSA-2022-131)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-275","alert_type":396,"serial_number":"AV22-275","subject":null,"moderation_state":"published","external_url":null},{"nid":3223,"title":"IBM security advisory (AV22-276)","uuid":"65285dab-55cb-4da4-88e2-d375cf5fe48b","banner":null,"lang":"en","date_modified":"2022-05-16","date_modified_ts":"2022-05-16T18:45:29Z","date_created":"2022-05-16T18:45:29Z","summary":null,"body":["<article data-history-node-id=\"3223\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-276\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-276<br \/>\nDate: 16 May 2022<\/strong><\/p>\n\n<p>Between 9 and 15 May 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Common Cryptographic Architecture \u2013 versions 5.0 to 5.7.11<\/li>\n\t<li>IBM C\u00faram SPM \u2013 version 7.0.11<\/li>\n\t<li>IBM Cloud Pak System \u2013 version 2.3<\/li>\n\t<li>IBM Security Guardium \u2013 versions 10.0; 10.5; 11.1; 11.2; 11.3<\/li>\n\t<li>IBM Spectrum Scale \u2013 versions 5.0.0 to 5.0.5.13 and 5.1.0 to 5.1.3<\/li>\n\t<li>IBM Sterling Connect:Direct \u2013 versions 6.2.0.0 to 6.2.0.3_iFix012<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a><\/p>\n\n<p><a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"f9a8fad7-f452-4f39-869c-f6c0de156880\" href=\"\/en\/alerts-advisories\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-276","alert_type":396,"serial_number":"AV22-276","subject":null,"moderation_state":"published","external_url":null},{"nid":3224,"title":"Apple security advisory (AV22-277)","uuid":"0e4dd191-d9e4-417f-b6ce-3b492ec362cb","banner":null,"lang":"en","date_modified":"2022-05-17","date_modified_ts":"2022-05-17T17:57:29Z","date_created":"2022-05-17T17:57:29Z","summary":null,"body":["<article data-history-node-id=\"3224\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-277\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-277<br \/>\nDate: 17 May 2022<\/strong><\/p>\n\n<p>On 16 May 2022 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 15.5<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.6.6<\/li>\n\t<li>macOS Catalina \u2013 versions prior to 2022-004<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.4<\/li>\n\t<li>Safari \u2013 versions prior to 15.5<\/li>\n\t<li>tvOS \u2013 versions prior to 15.5<\/li>\n\t<li>watchOS \u2013 versions prior to 8.6<\/li>\n\t<li>Xcode \u2013 versions prior to 13.4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>Apple has received reports that some of these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-277","alert_type":396,"serial_number":"AV22-277","subject":null,"moderation_state":"published","external_url":null},{"nid":3225,"title":"[Control systems] Circutor security advisory (AV22-278)","uuid":"1df6f693-558f-44b3-b367-3b8bfda745cc","banner":null,"lang":"en","date_modified":"2022-05-17","date_modified_ts":"2022-05-17T18:08:56Z","date_created":"2022-05-17T18:08:56Z","summary":null,"body":["<article data-history-node-id=\"3225\" about=\"\/en\/alerts-advisories\/control-systems-circutor-security-advisory-av22-278\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-278<br \/>\nDate: 17 May 2022<\/strong><\/p>\n\n<p>On 17 May 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Circutor COMPACT DC-S BASIC \u2013 version CIR_CDC_v1.2.17<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-137-01 \">ICS Advisory (ICSA-22-137-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-circutor-security-advisory-av22-278","alert_type":398,"serial_number":"AV22-278","subject":null,"moderation_state":"published","external_url":null},{"nid":3226,"title":"NVIDIA security advisory (AV22-279)","uuid":"69adda55-21a6-4d12-8a35-2e600989a52e","banner":null,"lang":"en","date_modified":"2022-05-18","date_modified_ts":"2022-05-18T17:57:12Z","date_created":"2022-05-18T17:57:12Z","summary":null,"body":["<article data-history-node-id=\"3226\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-av22-279\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-279<br \/>\nDate: 18 May 2022<\/strong><\/p>\n\n<p>On 16 May 2022 NVIDIA published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NVIDIA GPU Display Driver \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to information disclosure, data modification or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5353\">Security Bulletin: NVIDIA GPU Display Driver - May 2022<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-av22-279","alert_type":396,"serial_number":"AV22-279","subject":null,"moderation_state":"published","external_url":null},{"nid":3227,"title":"VMware security advisory (AV22-280)","uuid":"35f4874d-b443-4821-85e6-347247439685","banner":null,"lang":"en","date_modified":"2022-05-18","date_modified_ts":"2022-05-18T18:15:16Z","date_created":"2022-05-18T18:15:16Z","summary":null,"body":["<article data-history-node-id=\"3227\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-280\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-280<br \/>\nDate: 18 May 2022<\/strong><\/p>\n\n<p>On 18 May 2022 VMware published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware Cloud Foundation \u2013 multiple versions<\/li>\n\t<li>VMware Identity Manager \u2013 multiple versions<\/li>\n\t<li>VMware vRealize Automation \u2013 versions 7.6 and 8.x<\/li>\n\t<li>VMware vRealize Suite Lifecycle Manager \u2013 versions 8.x<\/li>\n\t<li>VMware Workspace ONE Access \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to authentication bypass and local privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0014.html\">VMSA-2022-0014<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-280","alert_type":396,"serial_number":"AV22-280","subject":null,"moderation_state":"published","external_url":null},{"nid":3228,"title":"Critical vulnerability impacting VMware applications","uuid":"90764da4-9025-4276-9ab3-1d763519fab4","banner":null,"lang":"en","date_modified":"2022-05-19","date_modified_ts":"2022-05-19T22:37:01Z","date_created":"2022-05-19T22:21:51Z","summary":null,"body":["<article data-history-node-id=\"3228\" about=\"\/en\/alerts-advisories\/critical-vulnerability-impacting-vmware-applications\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL22-006<br \/><strong>Date: <\/strong>19 May 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>On 18 May 2022 VMware published a Security Advisory to address vulnerabilities in multiple products <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"> <span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. Of these vulnerabilities, CVE-2022-22972 has been rated as critical with a maximum CVSSv3 base score of 9.8. Open-source analysis indicates that systems within Canada may be vulnerable to exploitation by this and related vulnerabilities.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 18 May 2022 VMware published a Security Advisory to address two vulnerabilities, CVE-2022-22972 and CVE-2022-22973, in multiple products <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"> <span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. One of these vulnerabilities, CVE-2022-22972, has a CVSSv3 score of 9.8 and could result in administrative access via authentication bypass. On the same day, the Cybersecurity and Infrastructure Security Agency (CISA) published an Emergency Directive to raise awareness of previous VMware vulnerabilities that are actively being exploited (CVE 2022-22954 and CVE 2022-22960) and instructs federal organisations to patch all four of these vulnerabilities as soon as possible <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"> <span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>The following products are affected:<\/p>\n\n<ul><li>VMware Cloud Foundation \u2013 multiple versions<\/li>\n\t<li>VMware Identity Manager \u2013 multiple versions<\/li>\n\t<li>VMware vRealize Automation \u2013 versions 7.6 and 8.x<\/li>\n\t<li>VMware vRealize Suite Lifecycle Manager \u2013 versions 8.x<\/li>\n\t<li>VMware Workspace ONE Access \u2013 multiple versions<\/li>\n<\/ul><p>CISA indicates that after observing the short amount of time required to reverse engineer and begin exploiting CVE 2022-22954 and CVE 2022-22960, advanced persistent threat (APT) actors are highly likely to exploit CVE-2022-22972 and CVE-2022-22973 within a short timeframe. CISA states that exploitation of these vulnerabilities may permit malicious actors to trigger a server-side template injection that may result in remote code execution (CVE-2022-22954), elevation of privileges to 'root' (CVE-2022-22960 and CVE-2022-22973) and the ability to obtain administrative access without the need to authenticate (CVE-2022-22972).<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>The Cyber Centre recommends organizations follow the instructions provided by VMware <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"> <span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, which include:<\/p>\n\n<ul><li>Upgrade instances of unsupported versions to a newer, supported version before applying the patch. This patch will not work on unsupported versions.<\/li>\n\t<li>Take a snapshot or backup of the appliance(s) and the database server before applying the procedure.<\/li>\n\t<li>Download and install the patches provided by VMware.<\/li>\n\t<li>If patches cannot be immediately applied, VMware has provided a workaround as a temporary solution. It should be noted that applying the workaround will result in the loss of certain functionality.<\/li>\n<\/ul><p>In addition, the Cyber Center recommends that any Internet-accessible systems using affected products that have not been patched in response to VMware security advisories VMSA-2022-0011.1 <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"> <span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> and VMSA-2022-0014 <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"> <span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> should be disconnected until patching and an assessment that no exploitation has occurred are complete.<\/p>\n\n<p>On 18 May 2022, CISA released Alert AA22-138B which outlines threat activity targeting unpatched VMware vulnerabilities that could result in full system control <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"> <span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>. The Alert contains various methods to detect malicious activity as well as incident response recommendations.<\/p>\n\n<p>Should organizations identify associated activity to that described in this Alert, recipients are encouraged to contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0014.html\" rel=\"external\">VMware Advisory VMSA-2022-0014<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/emergency-directive-22-03\" rel=\"external\">CISA Emergency Directive 22-03 Mitigate VMware Vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to <span>first<\/span> footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/kb.vmware.com\/s\/article\/88433\" rel=\"external\">VMware HW-156875 - Workaround instructions to address CVE-2022-22972<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0011.html\" rel=\"external\">VMware Advisory VMSA-2022-0011.1<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-138b\" rel=\"external\">CISA Alert (AA22-138B) Threat Actors Chaining Unpatched VMware Vulnerabilities for Full System Control<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/critical-vulnerability-impacting-vmware-applications","alert_type":397,"serial_number":"AL22-006","subject":null,"moderation_state":"published","external_url":null},{"nid":3229,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-281)","uuid":"2e1785c0-b85d-4117-b347-a898795eb15c","banner":null,"lang":"en","date_modified":"2022-05-20","date_modified_ts":"2022-05-20T13:19:58Z","date_created":"2022-05-20T13:19:58Z","summary":null,"body":["<article data-history-node-id=\"3229\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-281\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-281<br \/>\nDate: 20 May 2022<\/strong><\/p>\n\n<p>On 19 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MELSEC iQ-F FX5U-xMy\/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS \u2013 versions prior to 1.270<\/li>\n\t<li>MELSEC iQ-F FX5UC-xMy\/z x=32,64,96, y=T,R, z=D,DSS \u2013 versions prior to 1.270<\/li>\n\t<li>MELSEC iQ-F FX5UC-32MT\/DS-TS, FX5UC-32MT\/DSS-TS, FX5UC-32MR\/DS \u2013 versions prior to 1.270<\/li>\n\t<li>MELSEC iQ-F FX5UJ-xMy\/z x=24,40,60, y=T,R, z=ES,ESS \u2013 versions prior to 1.030<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-139-01 \">ICS Advisory (ICSA-22-139-01)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-281","alert_type":398,"serial_number":"AV22-281","subject":null,"moderation_state":"published","external_url":null},{"nid":3230,"title":"Mozilla security advisory (AV22-282)","uuid":"572a331d-0c58-4d66-8e55-ed40f387d5e5","banner":null,"lang":"en","date_modified":"2022-05-20","date_modified_ts":"2022-05-20T17:43:53Z","date_created":"2022-05-20T17:43:53Z","summary":null,"body":["<article data-history-node-id=\"3230\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-282\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-282<br \/>\nDate: 20 May 2022<\/strong><\/p>\n\n<p>On 20 May 2022 Mozilla published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 100.0.2<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.9.1<\/li>\n\t<li>Firefox for Android \u2013 versions prior to 100.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-19\/\">Mozilla Security Advisory (MFSA 2022-19)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-282","alert_type":396,"serial_number":"AV22-282","subject":null,"moderation_state":"published","external_url":null},{"nid":3231,"title":"IBM security advisory (AV22-283)","uuid":"05daa57c-3ca2-4c7c-9395-59ab57c801c3","banner":null,"lang":"en","date_modified":"2022-05-24","date_modified_ts":"2022-05-24T17:42:57Z","date_created":"2022-05-24T17:42:57Z","summary":null,"body":["<article data-history-node-id=\"3231\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-283\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-283\n  <br \/>\n  Date: 24 May 2022<\/strong>\n<\/p>\n<p>Between 16 and 23 May 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>IBM Cloud Private \u2013 versions 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.2.1 CD and 3.2.2 CD<\/li>\n  <li>IBM MQ Operator CD release \u2013 version 1.8.0<\/li>\n  <li>IBM MQ Operator EUS release \u2013 version 1.3.2<\/li>\n  <li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n  <li>IBM Robotic Process Automation with Automation Anywhere \u2013 version 19.0<\/li>\n  <li>IBM Spectrum Protect Plus \u2013 version 10.1.0.0 to 10.1.9.3<\/li>\n  <li>IBM Supplied MQ Advanced Queue Manager Container images \u2013 versions 9.2.5.0 to r1 and 9.2.0.4 to r1<\/li>\n  <li>IBM TXSeries for Multiplatforms \u2013 versions 8.2 and 9.1<\/li>\n  <li>IBM Tivoli Monitoring \u2013 version 6.3.0 to 6.3.0.7 (up to 6.3.0.7 Service pack 10)<\/li>\n  <li>PowerVC \u2013 versions 2.0.2 and 2.0.2.1<\/li>\n  <li>Rational Asset Analyzer (RAA) \u2013 version 6.1.0.0 to 6.1.0.23<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a>\n<\/p>\n<p><a href=\"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a>\n<\/p>\n<p><a href=\"\/en\/alerts-advisories\/active-exploitation-apache-log4j-vulnerability \">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a>\n<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-283","alert_type":396,"serial_number":"AV22-283","subject":null,"moderation_state":"published","external_url":null},{"nid":3232,"title":"[Control systems] Matrikon security advisory (AV22-284)","uuid":"34f7e293-7bd1-4b22-bdc5-6dd7019979dd","banner":null,"lang":"en","date_modified":"2022-05-24","date_modified_ts":"2022-05-24T19:25:32Z","date_created":"2022-05-24T19:25:32Z","summary":null,"body":["<article data-history-node-id=\"3232\" about=\"\/en\/alerts-advisories\/control-systems-matrikon-security-advisory-av22-284\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-284<br \/>\nDate: 24 May 2022<\/strong><\/p>\n\n<p>On 24 May 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Matrikon OPC Server - all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-144-02\">ICS Advisory (ICSA-22-144-02)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-matrikon-security-advisory-av22-284","alert_type":398,"serial_number":"AV22-284","subject":null,"moderation_state":"published","external_url":null},{"nid":3233,"title":"Google Chrome security advisory (AV22-285)","uuid":"a14944d5-f61a-45f0-befc-5348a42ff236","banner":null,"lang":"en","date_modified":"2022-05-25","date_modified_ts":"2022-05-25T13:46:23Z","date_created":"2022-05-25T13:46:23Z","summary":null,"body":["<article data-history-node-id=\"3233\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-285\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-285<br \/>\nDate: 25 May 2022<\/strong><\/p>\n\n<p>On 24 May 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 102.0.5005.61<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/05\/stable-channel-update-for-desktop_24.html \">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-285","alert_type":396,"serial_number":"AV22-285","subject":null,"moderation_state":"published","external_url":null},{"nid":3234,"title":"Dell security advisory (AV22-286)","uuid":"e80aa3ef-5ad5-4df2-a357-b02d9d43f7c2","banner":null,"lang":"en","date_modified":"2022-05-25","date_modified_ts":"2022-05-25T13:49:50Z","date_created":"2022-05-25T13:49:50Z","summary":null,"body":["<article data-history-node-id=\"3234\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-286\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-286<br \/>\nDate: 25 May 2022<\/strong><\/p>\n\n<p>On 24 May 2022 Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC Integrated Data Protection Appliance \u2013 versions 2.7.2, 2.7.1, 2.7.0, 2.6.x, 2.5, 2.4.x, 2.3.x, and 2.2<\/li>\n\t<li>PowerProtect DD Appliances model: DD6400 \u2013 versions 7.0 to 7.7 and version 7.8<\/li>\n\t<li>PowerProtect DD Appliances model: DD6900, DD9400, DD9900, and DD3300 \u2013 versions 7.0 to 7.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, once available.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000200050\/dsa-2022-146-dell-emc-integrated-data-protection-appliance-security-update-for-idrac-component-vulnerability\">Dell Security Advisory (DSA-2022-146)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000199904\/dsa-2022-140-dell-technologies-powerprotect-data-domain-security-update-for-idrac9-vnc-console-authentication-vulnerability\">Dell Security Advisory (DSA-2022-140)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-286","alert_type":396,"serial_number":"AV22-286","subject":null,"moderation_state":"published","external_url":null},{"nid":3235,"title":"[Control systems] Rockwell Automation security advisory (AV22-287)","uuid":"924ac960-0814-484a-a92a-5b5561782527","banner":null,"lang":"en","date_modified":"2022-05-25","date_modified_ts":"2022-05-25T13:53:48Z","date_created":"2022-05-25T13:53:48Z","summary":null,"body":["<article data-history-node-id=\"3235\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-287\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-287<br \/>\nDate: 25 May 2022<\/strong><\/p>\n\n<p>On 24 May 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>CompactLogix 5380 controllers \u2013 versions 32.013 and prior<\/li>\n\t<li>Compact GuardLogix 5380 controllers \u2013 versions 32.013 and prior<\/li>\n\t<li>CompactLogix 5480 controllers \u2013 versions 32.013 and prior<\/li>\n\t<li>ControlLogix 5580 controllers \u2013 versions 32.013 and prior<\/li>\n\t<li>GuardLogix 5580 controllers \u2013 versions 32.013 and prior<\/li>\n\t<li>CompactLogix 5370 controllers \u2013 versions 33.013 and prior<\/li>\n\t<li>Compact GuardLogix 5370 controllers \u2013 versions 33.013 and prior<\/li>\n\t<li>ControlLogix 5570 controllers \u2013 versions 33.013 and prior<\/li>\n\t<li>GuardLogix 5570 controllers \u2013 versions 33.013 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-144-01 \">ICS Advisory (ICSA-22-144-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-287","alert_type":398,"serial_number":"AV22-287","subject":null,"moderation_state":"published","external_url":null},{"nid":3236,"title":"Ubuntu security advisory (AV22-288)","uuid":"8510b5f5-f521-4f84-8037-f1eac4f3821a","banner":null,"lang":"en","date_modified":"2022-05-25","date_modified_ts":"2022-05-25T18:16:12Z","date_created":"2022-05-25T18:16:12Z","summary":null,"body":["<article data-history-node-id=\"3236\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-288\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-288<br \/>\nDate: 25 May 2022<\/strong><\/p>\n\n<p>On 24 May 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-288","alert_type":396,"serial_number":"AV22-288","subject":null,"moderation_state":"published","external_url":null},{"nid":3237,"title":"Citrix security advisory (AV22-289)","uuid":"4106124d-8d47-49b6-b2d8-561e43644345","banner":null,"lang":"en","date_modified":"2022-05-26","date_modified_ts":"2022-05-26T12:34:54Z","date_created":"2022-05-26T12:34:54Z","summary":null,"body":["<article data-history-node-id=\"3237\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-289\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-289<br \/>\nDate: 26 May 2022<\/strong><\/p>\n\n<p>On 25 May 2022 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix ADC \u2013 multiple versions<\/li>\n\t<li>Citrix Gateway \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX457048\">Citrix Security Bulletin (CTX457048)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-289","alert_type":396,"serial_number":"AV22-289","subject":null,"moderation_state":"published","external_url":null},{"nid":3238,"title":"[Control systems] Horner Automation security advisory (AV22-290)","uuid":"c896395e-d656-4502-b5c6-b3d06d637c8b","banner":null,"lang":"en","date_modified":"2022-05-26","date_modified_ts":"2022-05-26T19:32:54Z","date_created":"2022-05-26T19:32:54Z","summary":null,"body":["<article data-history-node-id=\"3238\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av22-290\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-290<br \/>\nDate: 26 May 2022<\/strong><\/p>\n\n<p>On 26 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Horner Automation Cscape Csfont \u2013 version 9.90 SP5 (v9.90.196) and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-146-02 \">ICS Advisory (ICSA-22-146-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av22-290","alert_type":398,"serial_number":"AV22-290","subject":null,"moderation_state":"published","external_url":null},{"nid":3239,"title":"[Control systems] Keysight Technologies security advisory (AV22-291)","uuid":"e4e36aad-ba0b-469d-b935-443d7ed3a7ee","banner":null,"lang":"en","date_modified":"2022-05-26","date_modified_ts":"2022-05-26T19:36:07Z","date_created":"2022-05-26T19:36:07Z","summary":null,"body":["<article data-history-node-id=\"3239\" about=\"\/en\/alerts-advisories\/control-systems-keysight-technologies-security-advisory-av22-291\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-291<br \/>\nDate: 26 May 2022<\/strong><\/p>\n\n<p>On 26 May 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Keysight N6854A Geolocation Server \u2013 versions prior to 2.4.0<\/li>\n\t<li>Keysight N6841A RF Sensor \u2013 versions prior to 2.4.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow for arbitrary code execution and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-146-01\">ICS Advisory (ICSA-22-146-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-keysight-technologies-security-advisory-av22-291","alert_type":398,"serial_number":"AV22-291","subject":null,"moderation_state":"published","external_url":null},{"nid":3240,"title":"[Control systems] ABB security advisory (AV22-292)","uuid":"fccdbd1b-92a4-4e72-a3b5-86a418fdb096","banner":null,"lang":"en","date_modified":"2022-05-27","date_modified_ts":"2022-05-27T13:00:34Z","date_created":"2022-05-27T13:00:34Z","summary":null,"body":["<article data-history-node-id=\"3240\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-292\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-292<br \/>\nDate: 27 May 2022<\/strong><\/p>\n\n<p>On 26 May 2022 ABB published a Cyber Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<p>\u2022\u00a0\u00a0 \u00a0E-Design \u2013 version 1.12.2.0004 and prior<\/p>\n\n<p>Exploitation of these vulnerabilities could result in a denial of service and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2%20CMT%200%200%206%200%208%206&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Cyber Security Advisory (2 CMT 006 086)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-292","alert_type":398,"serial_number":"AV22-292","subject":null,"moderation_state":"published","external_url":null},{"nid":3242,"title":"HPE security advisory (AV22-293)","uuid":"eecb91ac-10b7-475d-a791-973e18c4345d","banner":null,"lang":"en","date_modified":"2022-05-27","date_modified_ts":"2022-05-27T13:51:09Z","date_created":"2022-05-27T13:50:48Z","summary":null,"body":["<article data-history-node-id=\"3242\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-293\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-293<br \/>\nDate: 27 May 2022<\/strong><\/p>\n\n<p>On 24 May 2022, HPE published a Security Bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE IceWall Identity Manager \u2013 version 6.0 (Windows\/Oracle JDK 17.0.2)<\/li>\n\t<li>HPE IceWall Gen11 Password Reset Option \u2013 Windows\/Oracle JDK 17.0.2<\/li>\n\t<li>HPE IceWall MFA \u2013 multiple products (Windows\/Oracle JDK 17.0.2)<\/li>\n\t<li>HPE IceWall Federation OIDC \u2013 multiple versions (Windows\/Oracle JDK 17.0.2)<\/li>\n<\/ul><p>Exploitation of these vulnerability could allow for unauthorized data read\/modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbmu04316en_us\">HPE Security Bulletin (hpesbmu04316en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-293","alert_type":396,"serial_number":"AV22-293","subject":null,"moderation_state":"published","external_url":null},{"nid":3241,"title":"Dell security advisory (AV22-294)","uuid":"302931ac-1cca-4acb-afd1-599c53de98c1","banner":null,"lang":"en","date_modified":"2022-05-27","date_modified_ts":"2022-05-27T13:56:45Z","date_created":"2022-05-27T13:56:30Z","summary":null,"body":["<article data-history-node-id=\"3241\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-294\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-294<br \/>\nDate: 27 May 2022<\/strong><\/p>\n\n<p>On 26 May 2022 Dell published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell VxRail \u2013 4.5.x versions prior to 4.5.480<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000200100\/dsa-2022-137-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (DSA-2022-137)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-294","alert_type":396,"serial_number":"AV22-294","subject":null,"moderation_state":"published","external_url":null},{"nid":3243,"title":"IBM security advisory (AV22-295)","uuid":"b2d7146b-d444-404b-800a-dde1aa9e8bb5","banner":null,"lang":"en","date_modified":"2022-05-30","date_modified_ts":"2022-05-30T16:13:46Z","date_created":"2022-05-30T16:13:46Z","summary":null,"body":["<article data-history-node-id=\"3243\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-295\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-295<br \/>\nDate: 30 May 2022<\/strong><\/p>\n\n<p>Between 24 and 29 May 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Security Guardium \u2013 versions 10.5, 10.6, 11.0, 11.1, 11.2 and 11.3<\/li>\n\t<li>IBM Spectrum Control \u2013 versions 5.4.0 to 5.4.6<\/li>\n\t<li>IBM Sterling Connect:Direct for UNIX \u2013 version 6.2.0.0 to 6.2.0.3.iFix010<\/li>\n\t<li>IBM Sterling Control Center \u2013 versions 6.2.0.0 and 6.2.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"\/en\/alerts-advisories\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-295","alert_type":396,"serial_number":"AV22-295","subject":null,"moderation_state":"published","external_url":null},{"nid":3244,"title":"Mozilla security advisory (AV22-296)","uuid":"64c09369-ac2b-459e-a8fe-5287849baf3b","banner":null,"lang":"en","date_modified":"2022-05-31","date_modified_ts":"2022-05-31T15:08:09Z","date_created":"2022-05-31T15:08:09Z","summary":null,"body":["<article data-history-node-id=\"3244\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-296\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-296<br \/>\nDate: 31 May 2022<\/strong><\/p>\n\n<p>On 31 May 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 101<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-20\/\">Mozilla Security Advisory (MFSA 2022-20)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-21\/\">Mozilla Security Advisory (MFSA 2022-21)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-296","alert_type":396,"serial_number":"AV22-296","subject":null,"moderation_state":"published","external_url":null},{"nid":3259,"title":"[Control systems] Fuji Electric security advisory (AV22-297)","uuid":"84519a65-fbd7-4cfd-9837-f4805e2b1108","banner":null,"lang":"en","date_modified":"2022-05-31","date_modified_ts":"2022-05-31T16:58:30Z","date_created":"2022-05-31T16:58:30Z","summary":null,"body":["<article data-history-node-id=\"3259\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-297\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-297<br \/>\nDate: 31 May 2022<\/strong><\/p>\n\n<p>On 31 May 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Alpha7 PC Loader \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-151-01\">ICS Advisory (ICSA-22-151-01)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-297","alert_type":398,"serial_number":"AV22-297","subject":null,"moderation_state":"published","external_url":null},{"nid":3260,"title":"[Control systems] BD security advisory (AV22-298)","uuid":"9dd27abd-9d9c-4f33-920a-94bf74c27db8","banner":null,"lang":"en","date_modified":"2022-05-31","date_modified_ts":"2022-05-31T19:14:35Z","date_created":"2022-05-31T19:14:35Z","summary":null,"body":["<article data-history-node-id=\"3260\" about=\"\/en\/alerts-advisories\/control-systems-bd-security-advisory-av22-298\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-298<br \/>\nDate: 31 May 2022<\/strong><\/p>\n\n<p>On 31 May 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>BD Pyxis \u2013 multiple platforms<\/li>\n\t<li>BD Synapsys - versions 4.20, 4.20 SR1 and 4.30<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow a threat actor to read or modify sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-151-01\">ICSMA Advisory (ICSMA-22-151-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-151-02\">ICSMA Advisory (ICSMA-22-151-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bd-security-advisory-av22-298","alert_type":398,"serial_number":"AV22-298","subject":null,"moderation_state":"published","external_url":null},{"nid":3262,"title":"Ubuntu security advisory (AV22-299)","uuid":"23ce2c17-7c99-4250-a811-dd8f857ce9bb","banner":null,"lang":"en","date_modified":"2022-06-01","date_modified_ts":"2022-06-01T18:16:01Z","date_created":"2022-06-01T18:16:01Z","summary":null,"body":["<article data-history-node-id=\"3262\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-299\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-299<br \/>\nDate: 1 June 2022<\/strong><\/p>\n\n<p>On 1 June 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5442-2\">Ubuntu Security Notice (USN-5442-2)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5443-2\">Ubuntu Security Notice (USN-5443-2)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-299","alert_type":396,"serial_number":"AV22-299","subject":null,"moderation_state":"published","external_url":null},{"nid":3263,"title":"[Control systems] Illumina security advisory (AV22-300)","uuid":"bda1cba6-3fd5-4426-a265-93e9e5c2d19d","banner":null,"lang":"en","date_modified":"2022-06-02","date_modified_ts":"2022-06-02T18:11:51Z","date_created":"2022-06-02T18:11:51Z","summary":null,"body":["<article data-history-node-id=\"3263\" about=\"\/en\/alerts-advisories\/control-systems-illumina-security-advisory-av22-300\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-300<br \/>\nDate: 2 June 2022<\/strong><\/p>\n\n<p>On 2 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>MiSeq Dx IVD \u2013 LRM versions 1.3 to 3.1<\/li>\n\t<li>NextSeq 550Dx IVD \u2013 LRM versions 1.3 to 3.1<\/li>\n\t<li>iSeq 100 Instrument ROU \u2013 LRM versions 1.3 to 3.1<\/li>\n\t<li>MiSeq Instrument ROU \u2013 LRM versions 1.3 to 3.1<\/li>\n\t<li>MiniSeq Instrument ROU \u2013 LRM versions 1.3 to 3.1<\/li>\n\t<li>NextSeq 500 Instrument ROU \u2013 LRM versions 1.3 to 3.1<\/li>\n\t<li>NextSeq 550 Instrument ROU \u2013 LRM versions 1.3 to 3.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-153-02\">ICS Advisory (ICSA-22-153-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-illumina-security-advisory-av22-300","alert_type":398,"serial_number":"AV22-300","subject":null,"moderation_state":"published","external_url":null},{"nid":3264,"title":"[Control systems] Carrier LenelS2 security advisory (AV22-301)","uuid":"a7b9d2b4-36d0-47b0-ad58-7d737043ba4b","banner":null,"lang":"en","date_modified":"2022-06-02","date_modified_ts":"2022-06-02T18:14:46Z","date_created":"2022-06-02T18:14:46Z","summary":null,"body":["<article data-history-node-id=\"3264\" about=\"\/en\/alerts-advisories\/control-systems-carrier-lenels2-security-advisory-av22-301\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-301<br \/>\nDate: 2 June 2022<\/strong><\/p>\n\n<p>On 2 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>LNL-X2210<\/li>\n\t<li>LNL-X2220<\/li>\n\t<li>LNL-X3300<\/li>\n\t<li>LNL-X4420<\/li>\n\t<li>LNL-4420<\/li>\n\t<li>S2-LP-1501<\/li>\n\t<li>S2-LP-4502<\/li>\n\t<li>S2-LP-2500<\/li>\n\t<li>S2-LP-1502<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-153-01\">ICS Advisory (ICSA-22-153-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-carrier-lenels2-security-advisory-av22-301","alert_type":398,"serial_number":"AV22-301","subject":null,"moderation_state":"published","external_url":null},{"nid":3265,"title":"Active exploitation of Atlassian Confluence - update 1","uuid":"8e664892-3551-495f-a051-b23e749bcebb","banner":null,"lang":"en","date_modified":"2022-06-03","date_modified_ts":"2022-06-03T15:04:59Z","date_created":"2022-06-03T14:58:50Z","summary":null,"body":["<article data-history-node-id=\"3265\" about=\"\/en\/alerts-advisories\/active-exploitation-atlassian-confluence\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL22-008<br \/><strong>Date: <\/strong>3 June 2022<br \/><strong>Updated: <\/strong>3 June 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>The Cyber Centre is aware of reported exploitation of a remote code execution vulnerability (CVE-2022-26134) in Confluence Server and Confluence Data Center products <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. <s>Patches or mitigation recommendations for the vulnerability have not yet been released.<\/s> Atlassian has reported that Atlassian Cloud instances are unaffected.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 02 June 2022 Atlassian released Security Advisory 2022-06-02 which outlines a recently discovered vulnerability impacting Confluence Server and Data products <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. CVE-2022-26134 is a critical vulnerability which may result in unauthenticated remote code execution. Atlassian has indicated that all supported versions are affected. The earliest version has yet to be confirmed, but it is likely that all versions are impacted.<\/p>\n\n<p>While there has been no indication of a proof of concept, cyber security firm Veloxity, who originally reported the malicious activity, has observed malicious actors actively exploiting Confluence instances resulting in the deployment of webshells, reconnaissance and data exfiltration <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>Atlassian has updated affected versions to include all versions after 1.3.0. In addition, fixed versions have been released by Atlassian.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>The Cyber Centre encourages organizations with impacted Confluence Server and Confluence Data Center products to:<\/p>\n\n<ul><li>Update 1: Upgrade to the fixed versions indicated by Atlassian as soon as possible <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t<li>If upgrading cannot be immediately performed,\n\t<ul><li>Restrict Confluence Server and Data Center instances from the internet, or<\/li>\n\t\t<li>Disable Confluence Server and Data Center instances.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Volexity has released indicators of compromise (IOCs) for network defenders to review for signs of exploitation. If a system has been identified as affected, it is strongly recommended that it be disconnected from any networks and to start a thorough review of associated network systems for compromise. The Cyber Center also recommends impacted organizations follow the mitigation strategies outlined in AR20-245A, a joint cybersecurity advisory which outlines Technical Approaches to Uncovering and Remediating Malicious Activity <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre has not verified the technical details described in this disclosure and is providing this information as is for situational awareness and potential action. <strong>It is important that organizations verify the potential impact on business services and network environments before implementing any of the above recommended actions<\/strong>.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a> or <a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/confluence.atlassian.com\/doc\/confluence-security-advisory-2022-06-02-1130377146.html\" rel=\"external\">Confluence Security Advisory 2022-06-02<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.volexity.com\/blog\/2022\/06\/02\/zero-day-exploitation-of-atlassian-confluence\/\" rel=\"external\">Zero-Day Exploitation of Atlassian Confluence<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to <span>first<\/span> footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/guidance\/joint-cybersecurity-advisory\" rel=\"external\">Technical Approaches to Uncovering and Remediating Malicious Activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/active-exploitation-atlassian-confluence","alert_type":397,"serial_number":"AL22-008","subject":null,"moderation_state":"published","external_url":null},{"nid":3266,"title":"IBM security advisory (AV22-302)","uuid":"bb48fb1a-bd55-4826-adf0-5eda32010e43","banner":null,"lang":"en","date_modified":"2022-06-06","date_modified_ts":"2022-06-06T16:46:56Z","date_created":"2022-06-06T16:46:56Z","summary":null,"body":["<article data-history-node-id=\"3266\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-302\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-302<br \/>\nDate: 6 June 2022<\/strong><\/p>\n\n<p>Between 30 May 2022 and 5 June 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>App Connect Enterprise Certified Container with Operator \u2013 version(s) 1.1 to eus, 2.1, 3.0, 3.1, 4.0 and 4.1<\/li>\n\t<li>HMC \u2013 version V10.1.1010.0 and later and V9.2.950.0 and later<\/li>\n\t<li>IBM CICS TX Advanced \u2013 versions 10.1 and 11.1<\/li>\n\t<li>IBM CICS TX Standard \u2013 version 11.1<\/li>\n\t<li>IBM Cloud Private \u2013 versions 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.2.1 CD and 3.2.2 CD<\/li>\n\t<li>IBM Cloud Pak System \u2013 multiple versions<\/li>\n\t<li>IBM Common Licensing \u2013 versions ART 8.1.6, ART 9.0 and Agent 9.0<\/li>\n\t<li>IBM DataPower Gateway \u2013 version 2018.4.1.0 to 2018.4.1.17<\/li>\n\t<li>IBM DataPower Gateway 10.0.1 \u2013 versions 10.0.1.0 to 10.0.1.6<\/li>\n\t<li>IBM DataPower Gateway 2018.4.1 \u2013 versions 2018.4.1.0 to 2018.4.1.19<\/li>\n\t<li>IBM DataPower Gateway V10CD \u2013 versions 10.0.2.0 to 10.0.4.0<\/li>\n\t<li>IBM Edge Application Manger \u2013 version 4.3<\/li>\n\t<li>IBM PureData System for Operational Analytics \u2013 version 1.1<\/li>\n\t<li>IBM QRadar Data Synchronization App \u2013 version 1.0 to 3.0.0<\/li>\n\t<li>IBM Tivoli Monitoring \u2013 version 6.3.0 Fix Pack 7 Service Pack 5 and later<\/li>\n\t<li>IBM Watson Machine Learning Accelerator \u2013 multiple versions<\/li>\n\t<li>SPSS Collaboration and Deployment Services \u2013 versions 8.0, 8.1, 8.1.1, 8.2, 8.2.1, 8.2.2 and 8.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities \">Spring remote code execution vulnerabilities (AL22-004)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-302","alert_type":396,"serial_number":"AV22-302","subject":null,"moderation_state":"published","external_url":null},{"nid":3267,"title":"Microsoft Edge security advisory (AV22-303)","uuid":"09f8dc73-e3f0-471f-9aab-e4d3ce3b1c02","banner":null,"lang":"en","date_modified":"2022-06-06","date_modified_ts":"2022-06-06T16:51:08Z","date_created":"2022-06-06T16:51:08Z","summary":null,"body":["<article data-history-node-id=\"3267\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-303\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-303<br \/>\nDate: 6 June 2022<\/strong><\/p>\n\n<p>On 31 May 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 102.0.1245.30<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-31-2022\">Microsoft Edge Stable Channel Release Notes<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-303","alert_type":396,"serial_number":"AV22-303","subject":null,"moderation_state":"published","external_url":null},{"nid":3268,"title":"Dell security advisory (AV22-304)","uuid":"f3b9057e-e291-4904-b1c2-907917a3b4bc","banner":null,"lang":"en","date_modified":"2022-06-06","date_modified_ts":"2022-06-06T16:53:57Z","date_created":"2022-06-06T16:53:57Z","summary":null,"body":["<article data-history-node-id=\"3268\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-304\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-304<br \/>\nDate: 6 June 2022<\/strong><\/p>\n\n<p>Between 31 May 2022 and 3 June 2022 Dell published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC Elastic Cloud Storage \u2013 versions prior to ECS 3.7.0.2<\/li>\n\t<li>Dell EMC Unisphere Central \u2013 versions prior to 4.0.10.1673904<\/li>\n\t<li>Dell PowerFlex \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active exploitation of Apache Log4j vulnerability<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-304","alert_type":396,"serial_number":"AV22-304","subject":null,"moderation_state":"published","external_url":null},{"nid":3269,"title":"Android security advisory \u2013 June 2022 monthly rollup (AV22-305)","uuid":"700fa083-2b0d-4e45-959b-2753cb10f86d","banner":null,"lang":"en","date_modified":"2022-06-06","date_modified_ts":"2022-06-06T19:33:42Z","date_created":"2022-06-06T19:33:42Z","summary":null,"body":["<article data-history-node-id=\"3269\" about=\"\/en\/alerts-advisories\/android-security-advisory-june-2022-monthly-rollup-av22-305\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-305<br \/>\nDate: 6 June 2022<\/strong><\/p>\n\n<p>On 6 June 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/source.android.com\/security\/bulletin\/2022-06-01 \">Android Security Bulletin<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-june-2022-monthly-rollup-av22-305","alert_type":396,"serial_number":"AV22-305","subject":null,"moderation_state":"published","external_url":null},{"nid":3270,"title":"Fortinet security advisory (AV22-306)","uuid":"ab50117e-bcb3-43b2-86fc-70ce2b5c5831","banner":null,"lang":"en","date_modified":"2022-06-07","date_modified_ts":"2022-06-07T17:38:48Z","date_created":"2022-06-07T17:38:48Z","summary":null,"body":["<article data-history-node-id=\"3270\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-306\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-306<br \/>\nDate: 7 June 2022<\/strong><\/p>\n\n<p>On 7 June 2022 Fortinet published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>FortiAnalyzer \u2013 version 7.02 and prior, version 6.4.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. \u00a0<\/p>\n\n<p><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-22-008\">Fortinet PSIRT Advisory (FG-IR-22-008)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-306","alert_type":396,"serial_number":"AV22-306","subject":null,"moderation_state":"published","external_url":null},{"nid":3271,"title":"Red Hat security advisory (AV22-307)","uuid":"6cf243e2-03d1-406a-bc8f-5ce581d963e9","banner":null,"lang":"en","date_modified":"2022-06-07","date_modified_ts":"2022-06-07T17:42:07Z","date_created":"2022-06-07T17:42:07Z","summary":null,"body":["<article data-history-node-id=\"3271\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-307\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-307<br \/>\nDate: 7 June 2022<\/strong><\/p>\n\n<p>Between 31 May and 7 June 2022 Red Hat published Security Advisories to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux 9<\/li>\n\t<li>Red Hat Enterprise Linux 8.4 Extended Update Support<\/li>\n\t<li>Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions<\/li>\n\t<li>Red Hat Enterprise Linux 8<\/li>\n\t<li>Red Hat Virtualization 4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, once available.<\/p>\n\n<p><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2022-27666\">Red Hat Security Advisory (CVE-2022-27666)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-307","alert_type":396,"serial_number":"AV22-307","subject":null,"moderation_state":"published","external_url":null},{"nid":3272,"title":"HPE security advisory (AV22-308)","uuid":"1a88781d-8e12-4b3a-a1f6-4345b8399d19","banner":null,"lang":"en","date_modified":"2022-06-07","date_modified_ts":"2022-06-07T19:15:55Z","date_created":"2022-06-07T19:15:55Z","summary":null,"body":["<article data-history-node-id=\"3272\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-308\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-308<br \/>\nDate: 7 June 2022<\/strong><\/p>\n\n<p>On 7 June 2022, HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Superdome Flex Server \u2013 firmware versions prior to 3.55.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04314en_us\">HPE Security Bulletin (hpesbhf04314en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-308","alert_type":396,"serial_number":"AV22-308","subject":null,"moderation_state":"published","external_url":null},{"nid":3273,"title":"Dell security advisory (AV22-309)","uuid":"8ea9ecdc-535f-4881-8dff-97ce85429b4c","banner":null,"lang":"en","date_modified":"2022-06-07","date_modified_ts":"2022-06-07T19:19:11Z","date_created":"2022-06-07T19:19:11Z","summary":null,"body":["<article data-history-node-id=\"3273\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-309\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-309<br \/>\nDate: 7 June 2022<\/strong><\/p>\n\n<p>On 6 June 2022 Dell published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Precision 7920 Rack \u2013 versions 5.00.00.00 to versions prior to 5.10.10.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000199284\/dsa-2022-094\">Dell Security Advisory (000199284)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-309","alert_type":396,"serial_number":"AV22-309","subject":null,"moderation_state":"published","external_url":null},{"nid":3282,"title":"Ubuntu security advisory (AV22-310)","uuid":"1e40d2e6-5469-45d6-81ff-20ef577396d8","banner":null,"lang":"en","date_modified":"2022-06-09","date_modified_ts":"2022-06-09T13:46:40Z","date_created":"2022-06-09T13:46:40Z","summary":null,"body":["<article data-history-node-id=\"3282\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-310\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-310<br \/>\nDate: 9 June 2022<\/strong><\/p>\n\n<p>On 8 June 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-310","alert_type":396,"serial_number":"AV22-310","subject":null,"moderation_state":"published","external_url":null},{"nid":3283,"title":"HPE security advisory (AV22-311)","uuid":"845e54b1-7e7c-4bcf-a4be-caeca2ecaa10","banner":null,"lang":"en","date_modified":"2022-06-09","date_modified_ts":"2022-06-09T13:50:10Z","date_created":"2022-06-09T13:50:10Z","summary":null,"body":["<article data-history-node-id=\"3283\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-311\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-311<br \/>\nDate: 9 June 2022<\/strong><\/p>\n\n<p>On 7 June 2022, HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Common Internet File System Client\/Server \u2013 versions prior to B.04.15.00.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04323en_us\">HPE Security Bulletin (hpesbux04323en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-311","alert_type":396,"serial_number":"AV22-311","subject":null,"moderation_state":"published","external_url":null},{"nid":3284,"title":"F5 security advisory (AV22-312)","uuid":"904d4f59-8ad4-4712-96b3-703722adf732","banner":null,"lang":"en","date_modified":"2022-06-09","date_modified_ts":"2022-06-09T17:30:11Z","date_created":"2022-06-09T17:30:11Z","summary":null,"body":["<article data-history-node-id=\"3284\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-312\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-312<br \/>\nDate: 9 June 2022<\/strong><\/p>\n\n<p>On 8 June 2022, F5 published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Traffix SDC \u2013 version 5.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K13559191 \">F5 Security Advisory (K13559191)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-312","alert_type":396,"serial_number":"AV22-312","subject":null,"moderation_state":"published","external_url":null},{"nid":3285,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-313)","uuid":"0574c90e-f380-477d-a5f1-3508dc742f1e","banner":null,"lang":"en","date_modified":"2022-06-09","date_modified_ts":"2022-06-09T17:34:50Z","date_created":"2022-06-09T17:34:50Z","summary":null,"body":["<article data-history-node-id=\"3285\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-313\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-313<br \/>\nDate: 9 June 2022<\/strong><\/p>\n\n<p>On 9 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>AE-200J \u2013 version 7.97 and prior<\/li>\n\t<li>AE-200A \u2013 version 7.97 and prior<\/li>\n\t<li>AE-200E \u2013 version 7.97 and prior<\/li>\n\t<li>AE-50J \u2013 version 7.97 and prior<\/li>\n\t<li>AE-50A \u2013 version 7.97 and prior<\/li>\n\t<li>AE-50E \u2013 version 7.97 and prior<\/li>\n\t<li>AG-150A-A \u2013 version 3.21 and prior<\/li>\n\t<li>AG-150A-J \u2013 version 3.21 and prior<\/li>\n\t<li>G-150AD \u2013 version 3.21 and prior<\/li>\n\t<li>GB-50AD \u2013 version 3.21 and prior<\/li>\n\t<li>GB-50ADA-A \u2013 version 3.21 and prior<\/li>\n\t<li>GB-50ADA-J \u2013 version 3.21 and prior<\/li>\n\t<li>EB-50GU-A \u2013 version 7.10 and prior<\/li>\n\t<li>EB-50GU-J \u2013 version 7.10 and prior<\/li>\n\t<li>EW-50J \u2013 version 7.97 and prior<\/li>\n\t<li>EW-50A \u2013 version 7.97 and prior<\/li>\n\t<li>EW-50E \u2013 version 7.97 and prior<\/li>\n\t<li>TE-200A \u2013 version 7.97 and prior<\/li>\n\t<li>TE-50A \u2013 version 7.97 and prior<\/li>\n\t<li>TW-50A \u2013 version 7.97 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-160-01\">ICS Advisory (ICSA-22-160-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-313","alert_type":398,"serial_number":"AV22-313","subject":null,"moderation_state":"published","external_url":null},{"nid":3286,"title":"Google Chrome security advisory (AV22-314)","uuid":"4f2e085a-2e26-4bb8-80e0-986058b77eba","banner":null,"lang":"en","date_modified":"2022-06-09","date_modified_ts":"2022-06-09T19:41:26Z","date_created":"2022-06-09T19:41:26Z","summary":null,"body":["<article data-history-node-id=\"3286\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-314\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-314<br \/>\nDate: 9 June 2022<\/strong><\/p>\n\n<p>On 9 June 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 102.0.5005.115<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/06\/stable-channel-update-for-desktop.html \">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-314","alert_type":396,"serial_number":"AV22-314","subject":null,"moderation_state":"published","external_url":null},{"nid":3287,"title":"Microsoft Edge security advisory (AV22-315)","uuid":"a6f8f0de-f573-42f7-a6ba-68442729d24b","banner":null,"lang":"en","date_modified":"2022-06-09","date_modified_ts":"2022-06-09T19:43:35Z","date_created":"2022-06-09T19:43:35Z","summary":null,"body":["<article data-history-node-id=\"3287\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-315\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-315<br \/>\nDate: 9 June 2022<\/strong><\/p>\n\n<p>On 9 June 2022 Microsoft published a Security Update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 102.0.1245.39<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-9-2022\">Microsoft Edge Stable Channel Release Notes<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-315","alert_type":396,"serial_number":"AV22-315","subject":null,"moderation_state":"published","external_url":null},{"nid":3288,"title":"Dell security advisory (AV22-316)","uuid":"b7196863-eb90-4787-b129-21b1a08eb235","banner":null,"lang":"en","date_modified":"2022-06-10","date_modified_ts":"2022-06-10T20:03:52Z","date_created":"2022-06-10T20:03:52Z","summary":null,"body":["<article data-history-node-id=\"3288\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-316\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-316<br \/>\nDate: 10 June 2022<\/strong><\/p>\n\n<p>On 9 June 2022 Dell published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell SupportAssist \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000200456\/dsa-2022-139-dell-supportassist-for-home-pcs-and-business-pcs-security-update-for-multiple-security-vulnerabilities\">Dell Security Advisory (000200456)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-316","alert_type":396,"serial_number":"AV22-316","subject":null,"moderation_state":"published","external_url":null},{"nid":3289,"title":"IBM security advisory (AV22-317)","uuid":"69a423e4-98f2-457a-a521-fca8b2d51e8d","banner":null,"lang":"en","date_modified":"2022-06-13","date_modified_ts":"2022-06-13T14:59:46Z","date_created":"2022-06-13T14:59:46Z","summary":null,"body":["<article data-history-node-id=\"3289\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-317\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-317<br \/>\nDate: 13 June 2022<\/strong><\/p>\n\n<p>Between 6 and 12 June 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cognos Command Center \u2013 version 10.2.4.1<\/li>\n\t<li>IBM Db2 \u2013 version v11.5<\/li>\n\t<li>IBM Db2 Web Query for i \u2013 versions 2.3.0 and 2.2.1<\/li>\n\t<li>IBM Hardware Management Console (HMC) \u2013 versions 89.0x.xx.xx, 89.1x.xx.xx and 89.2x.xx.xx<\/li>\n\t<li>IBM IoT MessageSight \u2013 version 5.0.0.0<\/li>\n\t<li>IBM MaaS360 Cloud Extender Agent \u2013 version 2.106.100.008 and prior<\/li>\n\t<li>IBM MaaS360 Mobile Enterprise Gateway \u2013 version 2.106.200 and prior<\/li>\n\t<li>IBM MaaS360 VPN Module \u2013 version 2.106.100 and prior<\/li>\n\t<li>IBM Process Mining \u2013 version 1.12.0.3<\/li>\n\t<li>IBM Security SiteProtector System \u2013 version 3.1.1<\/li>\n\t<li>IBM Spectrum Copy Data Management \u2013 versions 2.2.0.0 to 2.2.15.0<\/li>\n\t<li>IBM Sterling Connect Direct Web Services \u2013 versions 1.0, 6.1.0, 6.2.0 and 6.0<\/li>\n\t<li>IBM WIoTP MessageGateway \u2013 version 5.0.0.1<\/li>\n\t<li>ICP \u2013 IBM Match 360 \u2013 version 4.0.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities\">Spring remote code execution vulnerabilities (AL22-004)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-317","alert_type":396,"serial_number":"AV22-317","subject":null,"moderation_state":"published","external_url":null},{"nid":3290,"title":"PingPull APT remote access tool","uuid":"7d0abf37-cb26-4992-9fd8-b920c352a448","banner":null,"lang":"en","date_modified":"2022-06-13","date_modified_ts":"2022-06-13T19:29:53Z","date_created":"2022-06-13T19:07:04Z","summary":null,"body":["<article data-history-node-id=\"3290\" about=\"\/en\/alerts-advisories\/pingpull-apt-remote-access-tool\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL22-009\n  <br \/><strong>Date: <\/strong>13 June 2022\n<\/p>\n<h2>Audience\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>Purpose\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>Overview\n<\/h2>\n<p>On 13 June 2022, Palo Alto\u2019s Unit 42 released a report on PingPull, a backdoor malware operated by a sophisticated actor.\n<\/p>\n<h2>Details\n<\/h2>\n<p>On 13 June 2022, Palo Alto Networks\u2019 Unit 42 released a report <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> detailing a new remote access tool (RAT), named PingPull, in use by an advanced persistent threat (APT) actor. This actor has been active since at least 2012, targeting telecommunications providers, financial institutions and government entities.\n<\/p>\n<p>PINGPULL is a lightweight Internet Control Message Protocol (ICMP), Hypertext Transfer Protocol (HTTP) and Transmission Control Protocol (TCP) enabled backdoor that provides the threat actor with the ability to run commands and access a reverse shell on a compromised host.\n<\/p>\n<p>Broadly, the implant possesses the following capabilities:\n<\/p>\n<ul><li>List system drives and directories<\/li>\n  <li>Copy, move, read, write, modify and delete files and directories<\/li>\n  <li>Launch processes<\/li>\n  <li>Encrypt communications<\/li>\n<\/ul><p>PingPull masquerades as the legitimate \u201ciphlpsvc\u201d service and connects to infrastructure using oddly configured certificates. <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n<p>The Cyber Centre has received reports of this malware impacting organizations within Canada.\n<\/p>\n<h2>Recommended actions\n<\/h2>\n<p>To increase the defensive posture of critical networks and reduce the risk of infection, the Cyber Centre recommends organizations review and action the indicators of compromise included in the Palo Alto Networks\u2019 Unit 42 report. <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n<p>The Cyber Centre has not verified the technical details described in this disclosure and is providing this information as is for situational awareness and potential action. It is important that organizations verify the potential impact on business services and network environments before implementing any of the above recommended actions.\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+1-833-292-3788\">1-833-CYBER-88<\/a>) or (<a href=\"tel:+1-833-292-3788\">1-833-292-3788<\/a>).\n<\/p>\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References\n  <\/h2>\n  <dl><dt>Footnote 1\n    <\/dt>\n    <dd id=\"fn1\">\n      <p><a href=\"https:\/\/unit42.paloaltonetworks.com\/pingpull-gallium\/\" rel=\"external\">GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n  <\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/pingpull-apt-remote-access-tool","alert_type":397,"serial_number":"AL22-009","subject":null,"moderation_state":"published","external_url":null},{"nid":3291,"title":"SAP security advisory \u2013 June 2022 monthly rollup (AV22-318)","uuid":"5810f98c-cba9-444a-a062-19e66b40e9bf","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T13:35:38Z","date_created":"2022-06-14T13:35:38Z","summary":null,"body":["<article data-history-node-id=\"3291\" about=\"\/en\/alerts-advisories\/sap-security-advisory-june-2022-monthly-rollup-av22-318\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-318<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 SAP published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>SAP Business Client \u2013 version 6.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<p><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-june-2022-monthly-rollup-av22-318","alert_type":396,"serial_number":"AV22-318","subject":null,"moderation_state":"published","external_url":null},{"nid":3292,"title":"[Control systems] Schneider Electric security advisory (AV22-319)","uuid":"42ad81af-cd8c-4ea7-a9ed-3d6a751a2748","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T13:47:29Z","date_created":"2022-06-14T13:47:29Z","summary":null,"body":["<article data-history-node-id=\"3292\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-319\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-319<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Clipsal C-Bus Network Automation Controller, 5500NAC \u2013 version V1.10.0 and prior<\/li>\n\t<li>Clipsal Wiser for C-Bus Automation Controller, 5500SHAC \u2013 version V1.10.0 and prior<\/li>\n\t<li>IGSS Data Server \u2013\u00a0 versions prior to 15.0.0.22139<\/li>\n\t<li>Schneider Electric C-Bus Network Automation Controller, LSS5500NAC \u2013 version V1.10.0 and prior<\/li>\n\t<li>Schneider Electric Wiser for C-Bus Automation Controller, LSS5500SHAC \u2013 version V1.10.0 and prior<\/li>\n\t<li>SpaceLogic C-Bus Network Automation Controller, 5500NAC2 \u2013 version V1.10.0 and prior<\/li>\n\t<li>SpaceLogic C-Bus Application Controller, 5500AC2 \u2013 version V1.10.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/download.schneider-electric.com\/files?p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification.pdf\">Schneider Security Advisory (SEVD-2022-165-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/download.schneider-electric.com\/files?p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-165-06_C-Bus_Home_Automation_Products_Security_Notification.pdf\">Schneider Security Advisory (SEVD-2022-165-06)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-319","alert_type":398,"serial_number":"AV22-319","subject":null,"moderation_state":"published","external_url":null},{"nid":3293,"title":" [Control systems] Siemens security advisory (AV22-320)","uuid":"c93f1530-bfbe-43f7-b5fa-02e5a303980f","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T14:06:30Z","date_created":"2022-06-14T14:06:30Z","summary":null,"body":["<article data-history-node-id=\"3293\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-320\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-320<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>RUGGEDCOM NMS \u2013 all versions<\/li>\n\t<li>SCALANCE LPE9403 (6GK5998-3GS00-2AC2) \u2013 versions prior to V2.0<\/li>\n\t<li>SICAM GridEdge \u2013 multiple platforms, versions prior to V2.6.6<\/li>\n\t<li>SINEC NMS \u2013 all versions<\/li>\n\t<li>SINEMA Remote Connect Server \u2013 versions prior to V3.1<\/li>\n\t<li>SINEMA Server V14 \u2013 all versions<\/li>\n\t<li>Teamcenter \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-685781.html\">Siemens Security Advisory (SSA-685781)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-631336.html\">Siemens Security Advisory (SSA-631336)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-484086.html\">Siemens Security Advisory (SSA-484068)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-222547.html\">Siemens Security Advisory (SSA-222547)<\/a><\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-220589.html\">Siemens Security Advisory (SSA-220589)<\/a><\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-320","alert_type":398,"serial_number":"AV22-320","subject":null,"moderation_state":"published","external_url":null},{"nid":3294,"title":"Dell security advisory (AV22-321)","uuid":"6e61b3d3-5277-4785-8c2d-99f9bd7c0554","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T15:41:25Z","date_created":"2022-06-14T15:41:25Z","summary":null,"body":["<article data-history-node-id=\"3294\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-321\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-321<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 Dell published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Dell VNXe3200 \u2013 version 3.1.17.10223906 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000200585\/dsa-2022-141-dell-emc-vnxe3200-security-update-for-windows-ntlm-elevation-of-privilege-vulnerability\">Dell Security Advisory (000200585)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-321","alert_type":396,"serial_number":"AV22-321","subject":null,"moderation_state":"published","external_url":null},{"nid":3295,"title":"[Control systems] ABB security advisory (AV22-322)","uuid":"ec8e46cf-212e-4448-897f-b43585d47977","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T16:21:35Z","date_created":"2022-06-14T16:21:35Z","summary":null,"body":["<article data-history-node-id=\"3295\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-322\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-322<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 ABB published a Cyber Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Automation Builder \u2013 version 1.1.0 to 2.5.0<\/li>\n\t<li>Drive Compose entry \u2013 version 2.0 to 2.7<\/li>\n\t<li>Drive Composer pro \u2013 version 2.0 to 2.7<\/li>\n\t<li>Mint WorkBench \u2013 version 5866 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\" https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108467A0305 \">ABB Cyber Security Advisory (9AKK108467A0305)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-322","alert_type":398,"serial_number":"AV22-322","subject":null,"moderation_state":"published","external_url":null},{"nid":3296,"title":"[Control systems] Meridian Cooperative security advisory (AV22-323)","uuid":"b90f8064-e7b7-46eb-a191-960165be7f62","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T16:39:33Z","date_created":"2022-06-14T16:39:33Z","summary":null,"body":["<article data-history-node-id=\"3296\" about=\"\/en\/alerts-advisories\/control-systems-meridian-cooperative-security-advisory-av22-323\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-323<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Meridian utility software \u2013 versions 22.02 and 22.03<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-165-02 \">ICS Advisory (ICSA-22-165-02)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-meridian-cooperative-security-advisory-av22-323","alert_type":398,"serial_number":"AV22-323","subject":null,"moderation_state":"published","external_url":null},{"nid":3261,"title":"Follina vulnerability impacting Microsoft products - Update 1","uuid":"2b57f017-6973-45ca-af1b-7b4e8baf17a4","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T13:38:28Z","date_created":"2022-06-14T17:35:22Z","summary":null,"body":["<article data-history-node-id=\"3261\" about=\"\/en\/alerts-advisories\/follina-vulnerability-impacting-microsoft-products\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL22-007<br \/><strong>Date:\u00a0<\/strong>31 May 2022<br \/><strong>Updated:\u00a0<\/strong>14 June\u00a0 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Overview<\/h2>\n\n<p>On 30 May 2022 Microsoft published guidance for a vulnerability, dubbed \u201cFollina\u201d, impacting the Microsoft Support Diagnostic Tool (MSDT) with active exploitation recently reported due to the release of proofs of concept.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 30 May 2022 Microsoft published guidance for a vulnerability impacting the Microsoft Support Diagnostic Tool (MSDT). <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> This vulnerability is also known as \u201cFollina\u201d and has been designated CVE-2022-30190.<\/p>\n\n<p>Exploitation of CVE-2022-30190, with a Common Vulnerability Scoring System (CVSS) score of 7.8, may result in the execution of arbitrary code. Several technical reviews of this vulnerability have been published in open source <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, along with several proofs of concept.<\/p>\n\n<p>Open-source reporting has indicated that active exploitation of this vulnerability has been observed in the wild. <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On 14 June 2022, a patch for CVE-2022-30190 was released as part of the June 2022 Security Updates.<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> Organizations are encouraged to update affected products according to Microsoft\u2019s recommendations.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p><strong>Update 1<\/strong> - If patching is not possible, <s>Although a patch for this vulnerability is not yet provided,<\/s> the Cyber Centre recommends organizations follow the mitigations provided by Microsoft and open source where possible, which include:<\/p>\n\n<ul><li>Disabling the MSDT URL Protocol, which inhibits the ability for MSDT to launch. <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t<li>If using Microsoft Defender for Endpoint, block Office applications from creating child processes. <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n\t<li>Disabling Troubleshooting Wizards via the EnableDiagnostics registry value until a patch is available. <sup id=\"fn5a-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n<\/ul><p>In addition, the Cyber Centre recommends organizations review the Cyber Centre\u2019s advice on recognizing phishing techniques and educate users on the dangers of phishing. <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> Users should never open any emails from unexpected contacts or with unexpected content.<\/p>\n\n<p>The Cyber Centre has not verified all the technical recommendations described in this disclosure and is providing this information as is for awareness. Before applying any of the above recommended actions it is important that organizations check with vendors, application developers and systems administrators to ensure business services and network environments continuity are assured prior to implementing any enterprise level changes.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+18332923788\">1-833-CYBER-88<\/a> or <a href=\"tel:+18332923788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc-blog.microsoft.com\/2022\/05\/30\/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability\/\" rel=\"external\">Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.scythe.io\/library\/breaking-follina-msdt-vulnerability\" rel=\"external\">Breaking: Follina (MSDT) Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to <span>first<\/span> footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.huntress.com\/blog\/microsoft-office-remote-code-execution-follina-msdt-bug\" rel=\"external\">Rapid Response: Microsoft Office RCE \u2013 \u201cFollina\u201d MSDT Attack<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/isc.sans.edu\/diary\/28698\" rel=\"external\">First Exploitation of Follina Seen in the Wild<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cyber.gov.au\/acsc\/view-all-content\/alerts\/exploitation-microsoft-office-vulnerability-follina\" rel=\"external\">Exploitation of Microsoft Office vulnerability: Follina<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/dont-take-bait-recognize-and-avoid-phishing-attacks\">Don\u2019t take the bait: Recognize and avoid phishing attacks<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-30190\" rel=\"external\">Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/follina-vulnerability-impacting-microsoft-products","alert_type":397,"serial_number":"AL22-007","subject":null,"moderation_state":"published","external_url":null},{"nid":3297,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-324)","uuid":"4af12e53-554f-4d14-8e2d-996230e18407","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T18:25:55Z","date_created":"2022-06-14T18:25:55Z","summary":null,"body":["<article data-history-node-id=\"3297\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-324\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-324<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC-Q Series QJ71E71-100 \u2013 first five digits of serial number 24061 and prior<\/li>\n\t<li>MELSEC-L Series LJ71E71-100 \u2013 first five digits of serial number 24061 and prior<\/li>\n\t<li>MELSEC iQ-R Series RD81MES96N \u2013 firmware version 08 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-165-03\">ICS Advisory (ICSA-22-165-03)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-324","alert_type":398,"serial_number":"AV22-324","subject":null,"moderation_state":"published","external_url":null},{"nid":3301,"title":"Microsoft security advisory \u2013 June 2022 monthly rollup (AV22-325)","uuid":"74dd603a-586b-4a93-b36a-410a988e1c7a","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T18:49:21Z","date_created":"2022-06-14T18:49:21Z","summary":null,"body":["<article data-history-node-id=\"3301\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-june-2022-monthly-rollup-av22-325\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-325<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 11 \u2013 multiple versions<\/li>\n\t<li>Windows 10 \u2013 multiple versions<\/li>\n\t<li>Windows 8.1<\/li>\n\t<li>Windows 7 \u2013 multiple versions<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2022-30190 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Jun\">June 2022 Release Notes<\/a><\/p>\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-june-2022-monthly-rollup-av22-325","alert_type":396,"serial_number":"AV22-325","subject":null,"moderation_state":"published","external_url":null},{"nid":3298,"title":"[Control systems] Johnson Controls security advisory (AV22-326)","uuid":"7e18bc0a-8083-4e56-abb4-b22ee0c63a36","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T18:52:59Z","date_created":"2022-06-14T18:52:59Z","summary":null,"body":["<article data-history-node-id=\"3298\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-326\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-326<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Metasys ADS\/ADX\/OAS Servers \u2013 versions 10 and 11<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an authenticated user to obtain or change the credentials of other users or inject code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<p><a href=\" https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-165-01 \">ICS Advisory (ICSA-22-165-01)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-326","alert_type":398,"serial_number":"AV22-326","subject":null,"moderation_state":"published","external_url":null},{"nid":3299,"title":"Adobe security advisory (AV22-327)","uuid":"97b4d80d-7ace-4cb6-aed7-62901989061e","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T18:55:08Z","date_created":"2022-06-14T18:55:08Z","summary":null,"body":["<article data-history-node-id=\"3299\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-327\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-327<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 Adobe published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Animate \u2013 version 22.0.5 and prior\u00a0\u00a0\u00a0 \u00a0<\/li>\n\t<li>Adobe Bridge \u2013 version 12.0.1 and prior<\/li>\n\t<li>Adobe InCopy \u2013 multiple versions<\/li>\n\t<li>Adobe InDesign \u2013 multiple versions<\/li>\n\t<li>Illustrator 2022 \u2013 version 26.0.2 and prior<\/li>\n\t<li>Illustrator 2021 \u2013 version 25.4.5 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, data modification, memory leaks, and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link(s) and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/helpx.adobe.com\/security.html \">Adobe Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-327","alert_type":396,"serial_number":"AV22-327","subject":null,"moderation_state":"published","external_url":null},{"nid":3300,"title":"Dell security advisory (AV22-328)","uuid":"9f231a18-4776-4b99-ab3d-bfae56d4758e","banner":null,"lang":"en","date_modified":"2022-06-14","date_modified_ts":"2022-06-14T18:57:27Z","date_created":"2022-06-14T18:57:27Z","summary":null,"body":["<article data-history-node-id=\"3300\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-328\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-328<br \/>\nDate: 14 June 2022<\/strong><\/p>\n\n<p>On 14 June 2022 Dell published a Security Bulletin to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell EMC Elastic Cloud Storage \u2013 versions prior to 3.6.2.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000199950\/dsa-2022-130-dell-emc-elastic-cloud-storage-security-update-for-third-party-vulnerabilities\">Dell Security Advisory (000199950)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-328","alert_type":396,"serial_number":"AV22-328","subject":null,"moderation_state":"published","external_url":null},{"nid":3303,"title":"Cisco security advisory (AV22-329)","uuid":"747cdaba-a1b1-4626-9e34-864e5d6dbaa6","banner":null,"lang":"en","date_modified":"2022-06-15","date_modified_ts":"2022-06-15T18:39:26Z","date_created":"2022-06-15T18:39:26Z","summary":null,"body":["<article data-history-node-id=\"3303\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-329\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-329<br \/>\nDate: 15 June 2022<\/strong><\/p>\n\n<p>On 15 June 2022 Cisco published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Secure Email and Web Manager \u2013 multiple versions<\/li>\n\t<li>Email Security Appliance \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sma-esa-auth-bypass-66kEcxQD\">Cisco Security Advisory (cisco-sa-sma-esa-auth-bypass-66kEcxQD)<\/a><\/p>\n\n<p><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-329","alert_type":396,"serial_number":"AV22-329","subject":null,"moderation_state":"published","external_url":null},{"nid":3305,"title":"[Control Systems] AutomationDirect security advisory (AV22-330)","uuid":"2977d181-55ab-41fb-8a52-09c99575d285","banner":null,"lang":"en","date_modified":"2022-06-16","date_modified_ts":"2022-06-16T19:04:58Z","date_created":"2022-06-16T19:04:58Z","summary":null,"body":["<article data-history-node-id=\"3305\" about=\"\/en\/alerts-advisories\/control-systems-automationdirect-security-advisory-av22-330\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-330<br \/>\nDate: 16 June 2022<\/strong><\/p>\n\n<p>On 16 June 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>DirectLOGIC \u2013 multiple platforms and versions<\/li>\n\t<li>C-more EA9 \u2013 multiple platforms, versions prior to 6.73<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-167-01\">ICS Advisory (ICSA-22-167-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-167-02\">ICS Advisory (ICSA-22-167-02)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-167-03\">ICS Advisory (ICSA-22-167-03)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-automationdirect-security-advisory-av22-330","alert_type":398,"serial_number":"AV22-330","subject":null,"moderation_state":"published","external_url":null},{"nid":3306,"title":"[Control Systems] Hillrom Medical Device Management security advisory (AV22-331)","uuid":"8aa7169f-112a-44ca-8cdf-e5212b1ea70f","banner":null,"lang":"en","date_modified":"2022-06-16","date_modified_ts":"2022-06-16T19:09:31Z","date_created":"2022-06-16T19:09:31Z","summary":null,"body":["<article data-history-node-id=\"3306\" about=\"\/en\/alerts-advisories\/control-systems-hillrom-medical-device-management-security-advisory-av22-331\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-331<br \/>\nDate: 16 June 2022<\/strong><\/p>\n\n<p>On 16 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Welch Allyn ELI 380 Resting Electrocardiograph \u2013 version 2.6.0 and prior<\/li>\n\t<li>Welch Allyn ELI 280\/BUR280\/MLBUR 280 Resting Electrocardiograph \u2013 version 2.3.1 and prior<\/li>\n\t<li>Welch Allyn ELI 250c\/BUR 250c Resting Electrocardiograph \u2013 version 2.1.2 and prior<\/li>\n\t<li>Welch Allyn ELI 150c\/BUR 150c\/MLBUR 150c Resting Electrocardiograph \u2013 version 2.2.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in command execution, privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-167-01 \">ICS Advisory (ICSMA-22-167-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hillrom-medical-device-management-security-advisory-av22-331","alert_type":398,"serial_number":"AV22-331","subject":null,"moderation_state":"published","external_url":null},{"nid":3307,"title":"Citrix security advisory (AV22-332)","uuid":"fd60fbad-a925-4fcd-afc9-4775d5c437f8","banner":null,"lang":"en","date_modified":"2022-06-17","date_modified_ts":"2022-06-17T12:08:02Z","date_created":"2022-06-17T12:08:02Z","summary":null,"body":["<article data-history-node-id=\"3307\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-332\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-332<br \/>\nDate: 17 June May 2022<\/strong><\/p>\n\n<p>On 16 June 2022 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix ADM 13.1 \u2013 versions prior to 13.1-21.53<\/li>\n\t<li>Citrix ADM 13.0 \u2013 versions prior to 13.0-85.19<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service or the modification of the administrator password.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/support.citrix.com\/article\/CTX460016\/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512\">Citrix Security Bulletin (CTX460016)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-332","alert_type":396,"serial_number":"AV22-332","subject":null,"moderation_state":"published","external_url":null},{"nid":3308,"title":"Ubuntu security advisory (AV22-333)","uuid":"db104211-042b-4a31-9f57-9efdab6bc7e1","banner":null,"lang":"en","date_modified":"2022-06-17","date_modified_ts":"2022-06-17T13:11:41Z","date_created":"2022-06-17T13:11:25Z","summary":null,"body":["<article data-history-node-id=\"3308\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-333\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-333<br \/>\nDate: 17 June 2022<\/strong><\/p>\n\n<p><br \/>\nOn 17 June 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5484-1\">Ubuntu Security Notice (USN-5484-1)<\/a><br \/><br \/><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5485-1\">Ubuntu Security Notice (USN-5485-1)<\/a><br \/><br \/><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-333","alert_type":396,"serial_number":"AV22-333","subject":null,"moderation_state":"published","external_url":null},{"nid":3309,"title":"Dell security advisory (AV22-334)","uuid":"df370979-a662-4d44-ab07-7004e15a56ab","banner":null,"lang":"en","date_modified":"2022-06-17","date_modified_ts":"2022-06-17T13:19:04Z","date_created":"2022-06-17T13:19:04Z","summary":null,"body":["<article data-history-node-id=\"3309\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-334\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-334<br \/>\nDate: 17 June 2022<\/strong><\/p>\n\n<p>On 17 June 2022 Dell published a Security Bulletin to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell PowerScale OneFS \u2013 versions 8.2.x to 9.3.0.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000200681\/dsa-2022-118-dell-emc-powerscale-onefs-security-update\">Dell Security Advisory (000200681) <\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-334","alert_type":396,"serial_number":"AV22-334","subject":null,"moderation_state":"published","external_url":null},{"nid":3310,"title":"HPE security advisory (AV22-335)","uuid":"d8a0baca-1b22-41ef-8f0c-e65cda15bfd8","banner":null,"lang":"en","date_modified":"2022-06-17","date_modified_ts":"2022-06-17T13:23:31Z","date_created":"2022-06-17T13:23:31Z","summary":null,"body":["<article data-history-node-id=\"3310\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-335\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-335<br \/>\nDate: 17 June 2022<\/strong><\/p>\n\n<p>On 17 June 2022, HPE published a Security Bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>Cray Legacy Shasta System Solutions \u2013 multiple platforms and versions<\/li>\n\t<li>HPE Cray EX Supercomputers \u2013 multiple platforms and versions<\/li>\n\t<li>HPE Slingshot \u2013 all Slingshot switch controllers, versions prior to 1.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbcr04284en_us\">HPE Security Bulletin (hpesbcr04284en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-335","alert_type":396,"serial_number":"AV22-335","subject":null,"moderation_state":"published","external_url":null},{"nid":3311,"title":"IBM security advisory (AV22-336)","uuid":"38bc5f62-c620-4509-8324-849f6f629c45","banner":null,"lang":"en","date_modified":"2022-06-20","date_modified_ts":"2022-06-20T15:48:19Z","date_created":"2022-06-20T15:48:19Z","summary":null,"body":["<article data-history-node-id=\"3311\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-336\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-336<br \/>\nDate: 20 June 2022<\/strong><\/p>\n\n<p>Between 13 and 19 June 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Disconnected Log Collector \u2013 versions 1.0 to 1.7.2<\/li>\n\t<li>IBM Analytic Accelerator Framework for Communication Service Providers (AAF) \u2013 version 4.0.0.0.0<\/li>\n\t<li>IBM Cloud Object Storage Systems \u2013 multiple versions<\/li>\n\t<li>IBM Customer and Network Analytics for Communications Service Providers and Datasets (CNA) \u2013 version 10.0.0.0.0<\/li>\n\t<li>IBM Integration Bus \u2013 versions 10.0.0.0 to 10.0.0.25<\/li>\n\t<li>IBM Security Guardium \u2013 versions 10.5, 10.6, 11.0, 11.1, 11.2, 11.3 and 11.4<\/li>\n\t<li>IBM Spectrum Copy Data Management \u2013 versions 2.2.0.0 to 2.2.15.0<\/li>\n\t<li>IBM Tivoli Netcool\/OMNIbus Integration \u2013 multiple versions<\/li>\n\t<li>Netcool Operations Insight \u2013 versions 1.4.x, 1.5.x and 1.6.x<\/li>\n\t<li>Rational Test Control Panel component in Rational Test Virtualization Server and Workbench \u2013 versions 9.2.1.1, 9.5, 10.0.2.1, 10.1.3 and 10.2.2<\/li>\n\t<li>StoredIQ \u2013 versions 7.6.0.0 to 7.6.0.22<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities  \">Spring remote code execution vulnerabilities (AL22-004)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability\/\">IBM \u2013 Apache Log4j Vulnerability<\/a><\/p>\n\n<p><a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/active-exploitation-apache-log4j-vulnerability\">Active Exploitation of Apache Log4j Vulnerability (AL21-019)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-336","alert_type":396,"serial_number":"AV22-336","subject":null,"moderation_state":"published","external_url":null},{"nid":3314,"title":"[Control Systems] ABB security advisory (AV22-337)","uuid":"a01a6ed3-57ae-47a7-850e-4a5181f268a5","banner":null,"lang":"en","date_modified":"2022-06-21","date_modified_ts":"2022-06-21T15:51:09Z","date_created":"2022-06-21T15:51:09Z","summary":null,"body":["<article data-history-node-id=\"3314\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-337\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-337<br \/>\nDate: 21 June 2022<\/strong><\/p>\n\n<p>On 21 June 2022 ABB published a Cyber Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>REX640 PCL1 Firmware \u2013 version 1.0.7 and prior<\/li>\n\t<li>REX640 PCL2 Firmware \u2013 versions prior to 1.1.4<\/li>\n\t<li>REX640 PCL3 Firmware \u2013 versions prior to 1.2.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001421\">ABB Cyber Security Advisory (2 NGA 001 42 1)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-337","alert_type":398,"serial_number":"AV22-337","subject":null,"moderation_state":"published","external_url":null},{"nid":3315,"title":"[Control Systems] Siemens security advisory (AV22-338)","uuid":"0633e19c-2c52-4e96-a96f-37d6336a1cbd","banner":null,"lang":"en","date_modified":"2022-06-21","date_modified_ts":"2022-06-21T15:55:17Z","date_created":"2022-06-21T15:55:17Z","summary":null,"body":["<article data-history-node-id=\"3315\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-338\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-338<br \/>\nDate: 21 June 2022<\/strong><\/p>\n\n<p>On 21 June 2022 Siemens published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SIMATIC WinCC OA \u2013 versions 3.16, 3.17 and 3.18<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow authentication bypass and impersonation of legitimate users.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-111512.html\">Siemens Security Advisory (SSA-111512)<\/a><\/p>\n\n<p><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-338","alert_type":398,"serial_number":"AV22-338","subject":null,"moderation_state":"published","external_url":null},{"nid":3316,"title":"[Control Systems] JTEKT security advisory (AV22-339)","uuid":"a8c55ebc-e98d-4cb3-a47f-229dde74eea1","banner":null,"lang":"en","date_modified":"2022-06-22","date_modified_ts":"2022-06-22T11:56:49Z","date_created":"2022-06-22T11:56:49Z","summary":null,"body":["<article data-history-node-id=\"3316\" about=\"\/en\/alerts-advisories\/control-systems-jtekt-security-advisory-av22-339\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-339<br \/>\nDate: 21 June 2022<\/strong><\/p>\n\n<p>On 21 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>TOYOPUC Programmable Logic Controllers \u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-172-02\">ICS Advisory (ICSA-22-172-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-jtekt-security-advisory-av22-339","alert_type":398,"serial_number":"AV22-339","subject":null,"moderation_state":"published","external_url":null},{"nid":3317,"title":"[Control Systems] Mitsubishi Electric security advisory (AV22-340)","uuid":"49f0dbd5-8ef6-42c4-8832-739323ce3bae","banner":null,"lang":"en","date_modified":"2022-06-22","date_modified_ts":"2022-06-22T12:02:23Z","date_created":"2022-06-22T12:02:23Z","summary":null,"body":["<article data-history-node-id=\"3317\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-340\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-340<br \/>\nDate: 21 June 2022<\/strong><\/p>\n\n<p>On 21 June 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC-Q Series Q03UDECPU, Q04\/06\/10\/13\/20\/26\/50\/100UDEHCPU \u2013 all versions<\/li>\n\t<li>MELSEC-Q Series Q03\/04\/06\/13\/26UDVCPU \u2013 first five digits of serial number 24051 and prior<\/li>\n\t<li>MELSEC-Q Series Q04\/06\/13\/26UDPVCPU \u2013 first five digits of serial number 24051 and prior<\/li>\n\t<li>MELSEC-L Series L02\/06\/26CPU(-P), L26CPU-(P)BT \u2013 first five digits of serial number 24051 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-172-01\">ICS Advisory (ICSA-22-172-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-340","alert_type":398,"serial_number":"AV22-340","subject":null,"moderation_state":"published","external_url":null},{"nid":3318,"title":"[Control Systems] Phoenix Contact security advisory (AV22-341)","uuid":"eb109628-0fea-4225-b1c6-c1c5db18bb5b","banner":null,"lang":"en","date_modified":"2022-06-22","date_modified_ts":"2022-06-22T12:09:56Z","date_created":"2022-06-22T12:09:56Z","summary":null,"body":["<article data-history-node-id=\"3318\" about=\"\/en\/alerts-advisories\/systemes-de-controle-bulletin-de-securite-phoenix-contact-av22-341\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-341<br \/>\nDate: 21 June 2022<\/strong><\/p>\n\n<p>On 21 June 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Classic Line Industrial Controllers \u2013 multiple models and versions<\/li>\n\t<li>MULTIPROG \u2013 all versions<\/li>\n\t<li>ProConOS \u2013 all versions<\/li>\n\t<li>ProConOS eCLR \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service, arbitrary code execution or unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-172-03\">ICS Advisory (ICSA-22-172-03)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-172-04\">ICS Advisory (ICSA-22-172-04)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-172-05\">ICS Advisory (ICSA-22-172-05)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/systemes-de-controle-bulletin-de-securite-phoenix-contact-av22-341","alert_type":398,"serial_number":"AV22-341","subject":null,"moderation_state":"published","external_url":null},{"nid":3319,"title":"Google Chrome security advisory (AV22-342)","uuid":"1f57503c-343a-4233-9826-d7b00169bf0f","banner":null,"lang":"en","date_modified":"2022-06-22","date_modified_ts":"2022-06-22T13:27:16Z","date_created":"2022-06-22T13:27:16Z","summary":null,"body":["<article data-history-node-id=\"3319\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-342\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-342<br \/>\nDate: 22 June 2022<\/strong><\/p>\n\n<p>On 21 June 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 103.0.5060.53<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/06\/stable-channel-update-for-desktop_21.html\">Google Chrome Security Advisory<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-342","alert_type":396,"serial_number":"AV22-342","subject":null,"moderation_state":"published","external_url":null},{"nid":3320,"title":"HPE security advisory (AV22-343)","uuid":"450e7364-54f6-43f4-b7f2-7d85adb2886e","banner":null,"lang":"en","date_modified":"2022-06-22","date_modified_ts":"2022-06-22T18:01:46Z","date_created":"2022-06-22T18:01:46Z","summary":null,"body":["<article data-history-node-id=\"3320\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-343\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-343<br \/>\nDate: 22 June 2022<\/strong><\/p>\n\n<p>On 21 June 2022, HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Distributed Systems Management\/Software Configuration Manager \u2013 version T6031H03^ADP<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbns04328en_us\">HPE Security Bulletin (hpesbns04328en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-343","alert_type":396,"serial_number":"AV22-343","subject":null,"moderation_state":"published","external_url":null},{"nid":3323,"title":"Dell security advisory (AV22-344)","uuid":"75358e77-6613-402a-86ae-1ea27e858520","banner":null,"lang":"en","date_modified":"2022-06-22","date_modified_ts":"2022-06-22T19:56:12Z","date_created":"2022-06-22T19:56:12Z","summary":null,"body":["<article data-history-node-id=\"3323\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-344\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-344<br \/>\nDate: 22 June 2022<\/strong><\/p>\n\n<p>On 22 June 2022, Dell published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>OS9 \u2013 versions prior to 9.14.1.12<\/li>\n\t<li>OS9 \u2013 versions prior to 9.14.2.14<\/li>\n\t<li>R650 and R750 Custom Node iDRAC \u2013 versions prior to 5.10.30.00<\/li>\n\t<li>R640, R740 and R840 VxFlex Ready Node iDRAC \u2013 versions prior to 5.10.30.00<\/li>\n\t<li>R630 and R730xd ScaleIO Ready Node iDRAC \u2013 versions prior to 2.83.83.83<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000200859\/dsa-2022-170-dell-emc-os9-security-update-for-an-openssl-vulnerability\">Dell Security Bulletin (000200859)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000200861\/dsa-2022-147-dell-emc-powerflex-15g-based-custom-node-14g-based-vxflex-ready-node-and-13g-based-scaleio-ready-node-security-update-for-idrac-based-vulnerabilities\">Dell Security Bulletin (000200861)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-344","alert_type":396,"serial_number":"AV22-344","subject":null,"moderation_state":"published","external_url":null},{"nid":3324,"title":"Microsoft Edge security advisory (AV22-345)","uuid":"a2d8f464-0e63-4212-9ecc-64f7bcbfa874","banner":null,"lang":"en","date_modified":"2022-06-23","date_modified_ts":"2022-06-23T19:29:47Z","date_created":"2022-06-23T19:29:47Z","summary":null,"body":["<article data-history-node-id=\"3324\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-345\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-345<br \/>\nDate: 23 June 2022<\/strong><\/p>\n\n<p>On 23 June 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 103.0.1264.37<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-23-2022\">Microsoft Edge Stable Channel Release Notes<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-345","alert_type":396,"serial_number":"AV22-345","subject":null,"moderation_state":"published","external_url":null},{"nid":3325,"title":"[Control Systems] Yokogawa security advisory (AV22-346)","uuid":"1cad5e48-9ee3-4ecf-8d3a-a575dbb1b72b","banner":null,"lang":"en","date_modified":"2022-06-23","date_modified_ts":"2022-06-23T19:32:47Z","date_created":"2022-06-23T19:32:47Z","summary":null,"body":["<article data-history-node-id=\"3325\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-346\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-346<br \/>\nDate: 23 June 2022<\/strong><\/p>\n\n<p>On 23 June 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>CENTUM CS 3000 (including CENTUM CS 3000 Entry Class) \u2013 multiple versions<\/li>\n\t<li>CENTUM VP (including CENTUM VP Entry Class) \u2013 multiple versions<\/li>\n\t<li>Exaopc \u2013 multiple versions<\/li>\n\t<li>B\/M9000CS \u2013 versions R5.04.01 to R5.05.01<\/li>\n\t<li>B\/M9000 VP \u2013 versions R6.01.01 to R8.03.01<\/li>\n\t<li>STARDOM FCN\/FCJ \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-174-01\">ICS Advisory (ICSA-22-174-01)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-174-02\">ICS Advisory (ICSA-22-174-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-346","alert_type":398,"serial_number":"AV22-346","subject":null,"moderation_state":"published","external_url":null},{"nid":3326,"title":"[Control Systems] Elcomplus LLC security advisory (AV22-347)","uuid":"c8ff8902-ee71-47b4-bb0a-2a60b6061dcf","banner":null,"lang":"en","date_modified":"2022-06-23","date_modified_ts":"2022-06-23T19:36:04Z","date_created":"2022-06-23T19:36:04Z","summary":null,"body":["<article data-history-node-id=\"3326\" about=\"\/en\/alerts-advisories\/control-systems-elcomplus-llc-security-advisory-av22-347\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-347<br \/>\nDate: 23 June 2022<\/strong><\/p>\n\n<p>On 23 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>SmartICS \u2013 version 2.3.4.0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow for data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-174-05\">ICS Advisory (ICSA-22-174-05)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-elcomplus-llc-security-advisory-av22-347","alert_type":398,"serial_number":"AV22-347","subject":null,"moderation_state":"published","external_url":null},{"nid":3327,"title":"[Control Systems] OFFIS security advisory (AV22-348)","uuid":"7f914651-56a0-4ecd-8f47-048429c03f8d","banner":null,"lang":"en","date_modified":"2022-06-23","date_modified_ts":"2022-06-23T19:38:47Z","date_created":"2022-06-23T19:38:47Z","summary":null,"body":["<article data-history-node-id=\"3327\" about=\"\/en\/alerts-advisories\/control-systems-offis-security-advisory-av22-348\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-348<br \/>\nDate: 23 June 2022<\/strong><\/p>\n\n<p>On 23 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>DCMTK \u2013 versions prior to 3.6.7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-174-01\">ICS Advisory (ICSMA-22-174-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-offis-security-advisory-av22-348","alert_type":398,"serial_number":"AV22-348","subject":null,"moderation_state":"published","external_url":null},{"nid":3328,"title":"[Control Systems] Pyramid Solutions, Inc. security advisory (AV22-349)","uuid":"92cc530c-bd5c-47db-a1b8-7698a8a08024","banner":null,"lang":"en","date_modified":"2022-06-23","date_modified_ts":"2022-06-23T19:41:07Z","date_created":"2022-06-23T19:41:07Z","summary":null,"body":["<article data-history-node-id=\"3328\" about=\"\/en\/alerts-advisories\/control-systems-pyramid-solutions-inc-security-advisory-av22-349\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-349<br \/>\nDate: 23 June 2022<\/strong><\/p>\n\n<p>On 23 June 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>EtherNet\/IP Adapter Development Kit (EADK) \u2013 version 4.4.0 and prior<\/li>\n\t<li>EtherNet\/IP Adapter DLL Kit (EIPA) \u2013 version 4.4.0 and prior<\/li>\n\t<li>EtherNet\/IP Scanner Development Kit (EDKS) \u2013 version 4.4.0 and prior<\/li>\n\t<li>EtherNet\/IP Scanner DLL Kit (EIPS) \u2013 version 4.4.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-174-04\">ICS Advisory (ICSA-22-174-04)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-pyramid-solutions-inc-security-advisory-av22-349","alert_type":398,"serial_number":"AV22-349","subject":null,"moderation_state":"published","external_url":null},{"nid":3329,"title":"[Control Systems] Secheron security advisory (AV22-350)","uuid":"48e00453-0ad2-45d9-8a1e-20feb348a449","banner":null,"lang":"en","date_modified":"2022-06-23","date_modified_ts":"2022-06-23T19:43:32Z","date_created":"2022-06-23T19:43:32Z","summary":null,"body":["<article data-history-node-id=\"3329\" about=\"\/en\/alerts-advisories\/control-systems-secheron-security-advisory-av22-350\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-350<br \/>\nDate: 23 June 2022<\/strong><\/p>\n\n<p>On 23 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>SEPCOS Single Package firmware \u2013 versions prior to 1.23.21<\/li>\n\t<li>SEPCOS Single Package firmware \u2013 versions prior to 1.24.8<\/li>\n\t<li>SEPCOS Single Package firmware \u2013 versions prior to 1.25.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-174-03\">ICS Advisory (ICSA-22-174-03)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-secheron-security-advisory-av22-350","alert_type":398,"serial_number":"AV22-350","subject":null,"moderation_state":"published","external_url":null},{"nid":3330,"title":"APT actors continue exploitation of Log4Shell in VMware products","uuid":"56d52dea-fbc3-4b60-a70c-31fe50ab93d8","banner":null,"lang":"en","date_modified":"2022-06-24","date_modified_ts":"2022-06-24T19:24:45Z","date_created":"2022-06-24T18:33:51Z","summary":null,"body":["<article data-history-node-id=\"3330\" about=\"\/en\/alerts-advisories\/apt-actors-continue-exploitation-log4shell-vmware-products\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL22-010<br \/><strong>Date:\u00a0<\/strong>24 June 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 23 June 2022 the Cybersecurity and Infrastructure Security Agency (CISA) and the United States Coast Guard Cyber Command (CGCYBER) released a joint Cybersecurity Advisory (CSA) <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. This was released to warn network defenders of continued exploitation of CVE-2021-44228 (Log4Shell) by Advanced Persistent Threat (APT) actors within unpatched VMware Horizon and Unified Access Gateway (UAG) servers.<\/p>\n\n<p>This CSA contains tactics, techniques and procedures (TTPs) and indicators of compromise (IOCs) of the suspected APT activity. These resources can be leveraged by network defenders to determine if malicious activity has occurred and provide recommendations for incident response.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>The Cyber Centre encourages organizations with vulnerable VMware Horizon and UAG systems to:<\/p>\n\n<ul><li>Review the Joint Advisory on mitigating Log4Shell originally released December 2021 and follow the included advice and guidance <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/li>\n\t<li>Review the recent CISA and CGCYBER Alert for additional information <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t<li>Update all affected systems to the latest version<\/li>\n\t<li>Utilize TTPs and IOCs to examine\/remediate affected and associated systems<\/li>\n<\/ul><p>The Cyber Centre has not verified the technical details described in this disclosure and is providing this information as is for situational awareness and potential action. <strong>It is important that organizations verify the potential impact on business services and network environments before implementing any of the above or referenced recommended actions.<\/strong><\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+18332923788\">1-833-CYBER-88<\/a> or <a href=\"tel:+18332923788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-174a\">CISA and CGCYBER Alert (AA22-174A)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa21-356a\">Joint Advisory Mitigating Log4Shell and Other Log4j-Related Vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apt-actors-continue-exploitation-log4shell-vmware-products","alert_type":397,"serial_number":"AL22-010","subject":null,"moderation_state":"published","external_url":null},{"nid":3335,"title":"IBM security advisory (AV22-351)","uuid":"119fe451-07a4-47b4-a712-4dfd649374a5","banner":null,"lang":"en","date_modified":"2022-06-27","date_modified_ts":"2022-06-27T15:13:22Z","date_created":"2022-06-27T15:13:22Z","summary":null,"body":["<article data-history-node-id=\"3335\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-351\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-351<br \/>\nDate: 27 June 2022<\/strong><\/p>\n\n<p>Between 20 and 26 June 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM CICS TX Advanced \u2013 version 11.1<\/li>\n\t<li>IBM CICS TX Standard \u2013 all versions<\/li>\n\t<li>IBM Cloud Pak for Business Automation \u2013 multiple versions<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.1.x and 11.2.x<\/li>\n\t<li>IBM DataPower Gateway \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Security Guardium \u2013 versions 10.5, 10.6, 11.0, 11.1, 11.2, 11.3 and 11.4<\/li>\n\t<li>IBM Spectrum Conductor \u2013 versions 2.4.1, 2.5.0 and 2.5.1<\/li>\n\t<li>IBM Spectrum Symphony \u2013 versions 7.3, 7.3.1 and 7.3.2<\/li>\n\t<li>QRadar SIEM \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts\/spring-remote-code-execution-vulnerabilities \">Spring remote code execution vulnerabilities (AL22-004)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-351","alert_type":396,"serial_number":"AV22-351","subject":null,"moderation_state":"published","external_url":null},{"nid":3336,"title":"Ubuntu security advisory (AV22-352)","uuid":"7dab89a6-5904-4623-a743-21a669bec68b","banner":null,"lang":"en","date_modified":"2022-06-27","date_modified_ts":"2022-06-27T17:02:37Z","date_created":"2022-06-27T17:02:37Z","summary":null,"body":["<article data-history-node-id=\"3336\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-352\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-352<br \/>\nDate: 27 June 2022<\/strong><\/p>\n\n<p>On 27 June 2022 Ubuntu released a Security Notice to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 21.10<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5493-1\">Ubuntu Security Notice (USN-5493-1)<\/a><\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-352","alert_type":396,"serial_number":"AV22-352","subject":null,"moderation_state":"published","external_url":null},{"nid":3337,"title":"Dell security advisory (AV22-353)","uuid":"6766849c-c14c-472f-901a-a9727f2e8434","banner":null,"lang":"en","date_modified":"2022-06-27","date_modified_ts":"2022-06-27T19:20:46Z","date_created":"2022-06-27T19:20:26Z","summary":null,"body":["<article data-history-node-id=\"3337\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-353\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-353<br \/>\nDate: 27 June 2022<\/strong><\/p>\n\n<p>On 27 June 2022, Dell published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell SupportAssist for Home PCs \u2013 versions prior to 3.11.4<\/li>\n\t<li>Dell SupportAssist for Business PCs \u2013 versions prior to 3.2.0<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to privilege escalation, arbitrary code execution or data modification.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000200456\/dsa-2022-139-dell-supportassist-for-home-pcs-and-business-pcs-security-update-for-multiple-security-vulnerabilities\">Dell Security Bulletin (DSA-2022-139)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-353","alert_type":396,"serial_number":"AV22-353","subject":null,"moderation_state":"published","external_url":null},{"nid":3338,"title":"Mozilla security advisory (AV22-354)","uuid":"ff485218-fc79-446a-b295-1fa2f1ba3e69","banner":null,"lang":"en","date_modified":"2022-06-28","date_modified_ts":"2022-06-28T14:34:12Z","date_created":"2022-06-28T14:34:12Z","summary":null,"body":["<article data-history-node-id=\"3338\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-354\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-354<br \/>\nDate: 28 June 2022<\/strong><\/p>\n\n<p>On 28 June 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 102<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-24\">Mozilla Security Advisory (MFSA 2022-24)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-25\">Mozilla Security Advisory (MFSA 2022-25)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-354","alert_type":396,"serial_number":"AV22-354","subject":null,"moderation_state":"published","external_url":null},{"nid":3339,"title":"HPE security advisory (AV22-355)","uuid":"d205c144-dc86-4688-ae30-ce92a6f079c5","banner":null,"lang":"en","date_modified":"2022-06-28","date_modified_ts":"2022-06-28T16:26:04Z","date_created":"2022-06-28T16:26:04Z","summary":null,"body":["<article data-history-node-id=\"3339\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-355\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-355<br \/>\nDate: 28 June 2022<\/strong><\/p>\n\n<p>On 27 June 2022, HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE B-Series SANnav Management Portal \u2013 multiple versions and platforms<\/li>\n\t<li>HPE ProLiant \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to privilege escalation, information disclosure or a denial of service.<br \/>\nThe Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04329en_us\">HPE Security Bulletin (hpesbst04329en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04303en_us\">HPE Security Bulletin (hpesbhf04303en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-355","alert_type":396,"serial_number":"AV22-355","subject":null,"moderation_state":"published","external_url":null},{"nid":3340,"title":"[Control Systems] Motorola Solutions security advisory (AV22-356)","uuid":"fb3ed49a-24ee-40a4-97f7-cce1e9c9a6f1","banner":null,"lang":"en","date_modified":"2022-06-28","date_modified_ts":"2022-06-28T18:36:30Z","date_created":"2022-06-28T18:36:30Z","summary":null,"body":["<article data-history-node-id=\"3340\" about=\"\/en\/alerts-advisories\/control-systems-motorola-solutions-security-advisory-av22-356\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-356<br \/>\nDate: 28 June 2022<\/strong><\/p>\n\n<p>On 28 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ACE IP gateway (CPU 4600) \u2013 all versions<\/li>\n\t<li>MDLC \u2013 versions 4.80.0024, 4.82.004 and 4.83.001 \u00a0<\/li>\n\t<li>MOSCAD IP gateway (IPGW) \u2013 all versions<\/li>\n\t<li>Motorola Solutions ACE1000 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to privilege escalation, information disclosure, a denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-179-04\">ICS Advisory (ICSA-22-179-04)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-179-05\">ICS Advisory (ICSA-22-179-05)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-179-06 \">ICS Advisory (ICSA-22-179-06)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-motorola-solutions-security-advisory-av22-356","alert_type":398,"serial_number":"AV22-356","subject":null,"moderation_state":"published","external_url":null},{"nid":3341,"title":"[Control Systems] Advantech security advisory (AV22-357)","uuid":"316ffaf4-9f57-457f-a930-701a781b2881","banner":null,"lang":"en","date_modified":"2022-06-28","date_modified_ts":"2022-06-28T18:55:26Z","date_created":"2022-06-28T18:55:26Z","summary":null,"body":["<article data-history-node-id=\"3341\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-357\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-357<br \/>\nDate: 28 June 2022<\/strong><\/p>\n\n<p>On 28 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Advantech iView \u2013 versions prior to 5_7_04_6469<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution or allow an actor to read and modify information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-179-03\">ICS Advisory (ICSA-22-179-03)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-357","alert_type":398,"serial_number":"AV22-357","subject":null,"moderation_state":"published","external_url":null},{"nid":3342,"title":"[Control Systems] Omron security advisory (AV22-358)","uuid":"70807298-4dc7-4e0d-bf15-253e40321173","banner":null,"lang":"en","date_modified":"2022-06-28","date_modified_ts":"2022-06-28T19:00:43Z","date_created":"2022-06-28T19:00:43Z","summary":null,"body":["<article data-history-node-id=\"3342\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-358\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-358<br \/>\nDate: 28 June 2022<\/strong><\/p>\n\n<p>On 28 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Omron SYSMAC CS\/CJ\/CP Series and NJ\/NX Series \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to a denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-179-02 \">ICS Advisory (ICSA-22-179-02)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-358","alert_type":398,"serial_number":"AV22-358","subject":null,"moderation_state":"published","external_url":null},{"nid":3343,"title":"[Control Systems] ABB security advisory (AV22-359)","uuid":"f0d83bec-597c-4a90-a616-3add3c01e90b","banner":null,"lang":"en","date_modified":"2022-06-28","date_modified_ts":"2022-06-28T19:13:54Z","date_created":"2022-06-28T19:13:54Z","summary":null,"body":["<article data-history-node-id=\"3343\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-359\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-359<br \/>\nDate: 28 June 2022<\/strong><\/p>\n\n<p>On 28 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>e-Design \u2013 versions prior to 1.12.2.0006<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to a denial of service or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-179-01\">ICS Advisory (ICSA-22-179-01)<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-359","alert_type":398,"serial_number":"AV22-359","subject":null,"moderation_state":"published","external_url":null},{"nid":3344,"title":"Mozilla security advisory (AV22-360)","uuid":"682c9943-70b1-4d77-ab4d-3e2d207d65f8","banner":null,"lang":"en","date_modified":"2022-06-29","date_modified_ts":"2022-06-29T14:00:56Z","date_created":"2022-06-29T14:00:56Z","summary":null,"body":["<article data-history-node-id=\"3344\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-360\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-360<br \/>\nDate: 29 June 2022<\/strong><\/p>\n\n<p>On 28 June 2022 Mozilla published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 102<\/li>\n\t<li>Thunderbird ESR \u2013 versions prior to 91.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-26\/\">Mozilla Security Advisory (MFSA 2022-26)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-360","alert_type":396,"serial_number":"AV22-360","subject":null,"moderation_state":"published","external_url":null},{"nid":3346,"title":"Dell security advisory (AV22-361)","uuid":"32e7441e-e79d-4bf4-babf-84602442915b","banner":null,"lang":"en","date_modified":"2022-06-29","date_modified_ts":"2022-06-29T19:08:32Z","date_created":"2022-06-29T19:08:32Z","summary":null,"body":["<article data-history-node-id=\"3346\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-361\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-361<br \/>\nDate: 29 June 2022<\/strong><\/p>\n\n<p>On 29 June 2022, Dell published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell SRM \u2013 versions prior to 4.7.1.0<\/li>\n\t<li>Dell SMR \u2013 versions prior to 4.7.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000200893\/dsa-2022-155-dell-emc-srm-and-dell-emc-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Bulletin (DSA-2022-155)<\/a><\/p>\n\n<p><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-361","alert_type":396,"serial_number":"AV22-361","subject":null,"moderation_state":"published","external_url":null},{"nid":3347,"title":"HPE security advisory (AV22-362)","uuid":"4d7dbf96-0df8-413d-859d-80569d6649ac","banner":null,"lang":"en","date_modified":"2022-06-30","date_modified_ts":"2022-06-30T13:48:47Z","date_created":"2022-06-30T13:48:47Z","summary":null,"body":["<article data-history-node-id=\"3347\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-362\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-362<br \/>\nDate: 30 June 2022<\/strong><\/p>\n\n<p>On 29 June 2022, HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE SimpliVity \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04298en_us\">HPE Security Bulletin (hpesbst04298en_us)<\/a><\/p>\n\n<p><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletins<\/a><br \/>\n\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-362","alert_type":396,"serial_number":"AV22-362","subject":null,"moderation_state":"published","external_url":null},{"nid":3348,"title":"[Control Systems] Exemys security advisory (AV22-363)","uuid":"bc03f930-3864-4200-9b5f-a2236ed0ee82","banner":null,"lang":"en","date_modified":"2022-06-30","date_modified_ts":"2022-06-30T19:34:15Z","date_created":"2022-06-30T19:34:15Z","summary":null,"body":["<article data-history-node-id=\"3348\" about=\"\/en\/alerts-advisories\/control-systems-exemys-security-advisory-av22-363\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-363<br \/>\nDate: 30 June 2022<\/strong><\/p>\n\n<p>On 30 June 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Exemys RME1-AI \u2013 firmware version 2.1.6 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor to bypass authentication.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-181-01\">ICS Advisory (ICSA-22-181-01)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-exemys-security-advisory-av22-363","alert_type":398,"serial_number":"AV22-363","subject":null,"moderation_state":"published","external_url":null},{"nid":3349,"title":"[Control Systems] Yokogawa security advisory (AV22-364)","uuid":"c75acec4-9de0-454b-90fb-737b4126713e","banner":null,"lang":"en","date_modified":"2022-06-30","date_modified_ts":"2022-06-30T19:39:53Z","date_created":"2022-06-30T19:39:53Z","summary":null,"body":["<article data-history-node-id=\"3349\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-364\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-364<br \/>\nDate: 30 June 2022<\/strong><\/p>\n\n<p>On 30 June 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Wide Area Communication Router (for AW810D) VI461 \u2013 Vnet\/IP firmware (F) R12 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-181-02\">ICS Advisory (ICSA-22-181-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-364","alert_type":398,"serial_number":"AV22-364","subject":null,"moderation_state":"published","external_url":null},{"nid":3350,"title":"[Control Systems] Emerson security advisory (AV22-365)","uuid":"d498ca60-ee6e-4610-9145-6c164c098499","banner":null,"lang":"en","date_modified":"2022-06-30","date_modified_ts":"2022-06-30T19:44:28Z","date_created":"2022-06-30T19:44:28Z","summary":null,"body":["<article data-history-node-id=\"3350\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-365\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-365<br \/>\nDate: 30 June 2022<\/strong><\/p>\n\n<p>On 30 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>DeltaV M-series \u2013 all versions<\/li>\n\t<li>DeltaV S-series \u2013 all versions<\/li>\n\t<li>DeltaV P-series \u2013 all versions<\/li>\n\t<li>DeltaV SIS \u2013 all versions<\/li>\n\t<li>DeltaV CIOC\/EIOC\/WIOC IO cards \u2013 all versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to a denial of service and system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-181-03\">ICS Advisory (ICSA-22-181-03)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-365","alert_type":398,"serial_number":"AV22-365","subject":null,"moderation_state":"published","external_url":null},{"nid":3351,"title":"[Control Systems] Distributed Data Systems security advisory (AV22-366)","uuid":"b7c99c47-5a27-49d3-abd7-46191d2205c5","banner":null,"lang":"en","date_modified":"2022-06-30","date_modified_ts":"2022-06-30T19:48:23Z","date_created":"2022-06-30T19:48:23Z","summary":null,"body":["<article data-history-node-id=\"3351\" about=\"\/en\/alerts-advisories\/control-systems-distributed-data-systems-security-advisory-av22-366\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-366<br \/>\nDate: 30 June 2022<\/strong><\/p>\n\n<p>On 30 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>WebHMI \u2013 version 4.1.1.7662 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-181-04\">ICS Advisory (ICSA-22-181-04)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-distributed-data-systems-security-advisory-av22-366","alert_type":398,"serial_number":"AV22-366","subject":null,"moderation_state":"published","external_url":null},{"nid":3352,"title":"[Control Systems] Mitsubishi security advisory (AV22-367)","uuid":"46743c73-6bd0-4aad-b617-b03ee7d2e12a","banner":null,"lang":"en","date_modified":"2022-06-30","date_modified_ts":"2022-06-30T19:57:45Z","date_created":"2022-06-30T19:57:45Z","summary":null,"body":["<article data-history-node-id=\"3352\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-security-advisory-av22-367\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-367<br \/>\nDate: 30 June 2022<\/strong><\/p>\n\n<p>On 30 June 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>EZSocket \u2013 all versions<\/li>\n\t<li>GX Works2 \u2013 version 1.606G and prior<\/li>\n\t<li>MELSOFT Navigator \u2013 version 2.84N and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-21-350-05\">ICS Advisory (ICSA-21-350-05)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-security-advisory-av22-367","alert_type":398,"serial_number":"AV22-367","subject":null,"moderation_state":"published","external_url":null},{"nid":3353,"title":"[Control Systems] CODESYS security advisory (AV22-368)","uuid":"63eecbf6-5465-42b4-a39f-a9929504b691","banner":null,"lang":"en","date_modified":"2022-06-30","date_modified_ts":"2022-06-30T20:02:41Z","date_created":"2022-06-30T20:02:41Z","summary":null,"body":["<article data-history-node-id=\"3353\" about=\"\/en\/alerts-advisories\/control-systems-codesys-security-advisory-av22-368\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-368<br \/>\nDate: 30 June 2022<\/strong><\/p>\n\n<p>On 30 June 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CODESYS Gateway Server \u2013 version 2.3.9.33 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/ICSA-15-258-02\">ICS Advisory (ICSA-15-258-02)<\/a><br \/>\n\u00a0<\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-codesys-security-advisory-av22-368","alert_type":398,"serial_number":"AV22-368","subject":null,"moderation_state":"published","external_url":null},{"nid":3354,"title":"Dell security advisory (AV22-369)","uuid":"4ebb4614-8be7-4c3f-ac83-1581faaa82b0","banner":null,"lang":"en","date_modified":"2022-07-04","date_modified_ts":"2022-07-04T16:56:07Z","date_created":"2022-07-04T16:56:07Z","summary":null,"body":["<article data-history-node-id=\"3354\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-369\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-369<\/strong><br \/><strong>Date: 4 July 2022<\/strong><\/p>\n\n<p>On 30 June 2022, Dell published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC Data Protection Central \u2013 versions 19.1 to 19.6<\/li>\n\t<li>PowerProtect DP Series Appliance \u2013 versions 2.5, 2.6\/2.61, 2.7\/2.7.1\/2.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201096\/dsa-2022-164-dell-emc-data-protection-central-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Bulletin (DSA-2022-164)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-369","alert_type":396,"serial_number":"AV22-369","subject":null,"moderation_state":"published","external_url":null},{"nid":3356,"title":"IBM security advisory (AV22-370)","uuid":"85f19022-5bb5-4c7d-bc5f-bdd17ff99e9d","banner":null,"lang":"en","date_modified":"2022-07-04","date_modified_ts":"2022-07-04T19:00:18Z","date_created":"2022-07-04T19:00:18Z","summary":null,"body":["<article data-history-node-id=\"3356\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-370\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-370 <\/strong><br \/><strong>Date: 4 July 2022 <\/strong><\/p>\n\n<p>Between 27 June and 3 July 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Db2 and Db2 Warehouse\u00ae on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM Db2 On Openshift \u2013 multiple versions<\/li>\n\t<li>IBM i \u2013 versions 7.2, 7.3, 7.4 and 7.5<\/li>\n\t<li>IBM Robotic Process Automation 21.0.1 \u2013 versions prior to 21.0.1.5<\/li>\n\t<li>IBM Spectrum Protect Plus \u2013 versions 10.1.0.0 to 10.1.10.2<\/li>\n\t<li>Watson Discovery \u2013 versions 4.0.0 to 4.0.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-370","alert_type":396,"serial_number":"AV22-370","subject":null,"moderation_state":"published","external_url":null},{"nid":3357,"title":"Google Chrome security advisory (AV22-371)","uuid":"f30ad018-2463-45da-a0b7-8b1961b892a4","banner":null,"lang":"en","date_modified":"2022-07-05","date_modified_ts":"2022-07-05T14:30:12Z","date_created":"2022-07-05T14:30:12Z","summary":null,"body":["<article data-history-node-id=\"3357\" about=\"\/en\/alerts-advisories\/google-chrome-scurity-advisory-av22-371\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-371<\/strong><br \/><strong>Date: 5 July 2022 <\/strong><\/p>\n\n<p>On 4 July 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 103.0.5060.114<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2022-2294 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/07\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-scurity-advisory-av22-371","alert_type":396,"serial_number":"AV22-371","subject":null,"moderation_state":"published","external_url":null},{"nid":3358,"title":"Ubuntu security advisory (AV22-372)","uuid":"26ccd598-574f-41ae-906f-86e7b16fd593","banner":null,"lang":"en","date_modified":"2022-07-05","date_modified_ts":"2022-07-05T18:58:20Z","date_created":"2022-07-05T18:58:20Z","summary":null,"body":["<article data-history-node-id=\"3358\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-372\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-372<\/strong><br \/><strong>Date: 5 July 2022<\/strong><\/p>\n\n<p>On 1 July 2022 Ubuntu released Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-372","alert_type":396,"serial_number":"AV22-372","subject":null,"moderation_state":"published","external_url":null},{"nid":3361,"title":"Fortinet security advisory (AV22-373)","uuid":"972ab379-7ea5-48ca-bc7f-b46497625ffe","banner":null,"lang":"en","date_modified":"2022-07-06","date_modified_ts":"2022-07-06T15:30:00Z","date_created":"2022-07-06T15:30:00Z","summary":null,"body":["<article data-history-node-id=\"3361\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-373\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-373<\/strong><br \/><strong>Date: 5 July 2022<\/strong><\/p>\n\n<p>On 5 July 2022 Fortinet published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiClient \u2013 multiple versions<\/li>\n\t<li>FortiDeceptor \u2013 multiple versions<\/li>\n\t<li>FortiNAC \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-190\">Fortinet PSIRT Advisory (FG-IR-21-190)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-213\">Fortinet PSIRT Advisory (FG-IR-21-213)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-058\">Fortinet PSIRT Advisory (FG-IR-22-058)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-373","alert_type":396,"serial_number":"AV22-373","subject":null,"moderation_state":"published","external_url":null},{"nid":3362,"title":"HPE security advisory (AV22-374)","uuid":"b0ccd2ce-adf3-42e6-9098-b34983681ea1","banner":null,"lang":"en","date_modified":"2022-07-06","date_modified_ts":"2022-07-06T15:41:59Z","date_created":"2022-07-06T15:41:59Z","summary":null,"body":["<article data-history-node-id=\"3362\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-374\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-374<\/strong><br \/><strong>Date: 6 July 2022<\/strong><\/p>\n\n<p>On 6 July 2022, HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Apache-based Web Server \u2013 versions prior to 2.4.53.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04335en_us\">HPE Security Bulletin (hpesbux04335en_us)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-374","alert_type":396,"serial_number":"AV22-374","subject":null,"moderation_state":"published","external_url":null},{"nid":3363,"title":"OpenSSL security advisory (AV22-375)","uuid":"39d314ea-efbe-4a96-a437-b45ec56d6df7","banner":null,"lang":"en","date_modified":"2022-07-06","date_modified_ts":"2022-07-06T17:07:21Z","date_created":"2022-07-06T17:07:21Z","summary":null,"body":["<article data-history-node-id=\"3363\" about=\"\/en\/alerts-advisories\/openssl-security-advisory-av22-375\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-375<\/strong><br \/><strong>Date: 6 July 2022<\/strong><\/p>\n\n<p>On 5 July 2022 OpenSSL published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSL - versions prior to 1.1.1q<\/li>\n\t<li>OpenSSL - versions prior to 3.0.5<\/li>\n<\/ul><p>OpenSSL is a software library for applications that secures communications over computer networks. It is widely used by websites and is present in many programs and operating systems.<\/p>\n\n<p>Exploitation of some of these vulnerabilities may lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20220705.txt\">OpenSSL Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory-av22-375","alert_type":396,"serial_number":"AV22-375","subject":null,"moderation_state":"published","external_url":null},{"nid":3364,"title":"Cisco security advisory (AV22-376)","uuid":"0f0e572e-85e4-48cf-a609-ac57735f0bfb","banner":null,"lang":"en","date_modified":"2022-07-06","date_modified_ts":"2022-07-06T20:15:23Z","date_created":"2022-07-06T20:15:23Z","summary":null,"body":["<article data-history-node-id=\"3364\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-376\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-376<\/strong><br \/><strong>Date: 6 July 2022<\/strong><\/p>\n\n<p>On 6 July 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Cisco Expressway Series \u2013 versions prior to 14.0.7<\/li>\n\t<li>Cisco TelePresence VCS Release \u2013 versions prior to 14.0.7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities may allow an actor to overwrite arbitrary files or gain access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-expressway-overwrite-3buqW8LH\">Cisco Security Advisory (cisco-sa-expressway-overwrite-3buqW8LH)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-376","alert_type":396,"serial_number":"AV22-376","subject":null,"moderation_state":"published","external_url":null},{"nid":3365,"title":"Android security advisory \u2013 July 2022 monthly rollup (AV22-377)","uuid":"1bd7a5a5-3089-45f6-a3e3-547b1bb76752","banner":null,"lang":"en","date_modified":"2022-07-06","date_modified_ts":"2022-07-06T20:30:02Z","date_created":"2022-07-06T20:30:02Z","summary":null,"body":["<article data-history-node-id=\"3365\" about=\"\/en\/alerts-advisories\/android-security-advisory-july-2022-monthly-rollup-av22-377\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-377<\/strong><br \/><strong>Date: 6 July 2022<\/strong><\/p>\n\n<p>On 6 July 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/security\/bulletin\/2022-07-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-july-2022-monthly-rollup-av22-377","alert_type":396,"serial_number":"AV22-377","subject":null,"moderation_state":"published","external_url":null},{"nid":3366,"title":"[Control systems] Rockwell Automation security advisory (AV22-378)","uuid":"fc8f313c-d6cb-4dcb-b5f4-62958df35a73","banner":null,"lang":"en","date_modified":"2022-07-07","date_modified_ts":"2022-07-07T18:11:50Z","date_created":"2022-07-07T18:11:50Z","summary":null,"body":["<article data-history-node-id=\"3366\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-378\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-378<\/strong><br \/><strong>Date: 7 July 2022<\/strong><\/p>\n\n<p>On 7 July 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>MicroLogix 1400 \u2013 version 21.007 and prior<\/li>\n\t<li>MicroLogix 1100 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-188-01\">ICS Advisory (ICSA-22-188-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-378","alert_type":398,"serial_number":"AV22-378","subject":null,"moderation_state":"published","external_url":null},{"nid":3367,"title":"[Control Systems] Bently Nevada security advisory (AV22-379)","uuid":"11a9a405-8f5f-4070-ab3e-59593b0c3d94","banner":null,"lang":"en","date_modified":"2022-07-07","date_modified_ts":"2022-07-07T18:19:51Z","date_created":"2022-07-07T18:19:51Z","summary":null,"body":["<article data-history-node-id=\"3367\" about=\"\/en\/alerts-advisories\/control-systems-bently-nevada-security-advisory-av22-379\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-379<\/strong><br \/>\n<strong>Date: 7 July 2022<\/strong><\/p>\n\n<p>On 7 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul>\n\t<li>Bently Nevada 3701\/40 \u2013 versions prior to 4.1<\/li>\n\t<li>Bently Nevada 3701\/44 \u2013 versions prior to 4.1<\/li>\n\t<li>Bently Nevada 3701\/46 \u2013 versions prior to 4.1<\/li>\n\t<li>Bently Nevada 60M100 (3701\/60) \u2013 all versions<\/li>\n<\/ul>\n\n<p>Exploitation of these vulnerabilities could result in remote code execution, file manipulation or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\">\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-188-02\">ICS Advisory (ICSA-22-188-02)<\/a><\/li>\n<\/ul>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bently-nevada-security-advisory-av22-379","alert_type":398,"serial_number":"AV22-379","subject":null,"moderation_state":"published","external_url":null},{"nid":3369,"title":"Microsoft Edge security advisory (AV22-380)","uuid":"acb779d0-a3dc-4731-8b47-7ec8bf83da8a","banner":null,"lang":"en","date_modified":"2022-07-08","date_modified_ts":"2022-07-08T20:44:33Z","date_created":"2022-07-08T20:44:33Z","summary":null,"body":["<article data-history-node-id=\"3369\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-380\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-380<\/strong><br \/><strong>Date: 8 July 2022<\/strong><\/p>\n\n<p>On 6 July 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 103.0.1264.49<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2022-2294 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-6-2022\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-380","alert_type":396,"serial_number":"AV22-380","subject":null,"moderation_state":"published","external_url":null},{"nid":3370,"title":"Dell security advisory (AV22-381)","uuid":"0b19a813-efde-4b05-ac6f-eb9fd779ea61","banner":null,"lang":"en","date_modified":"2022-07-08","date_modified_ts":"2022-07-08T20:51:14Z","date_created":"2022-07-08T20:51:14Z","summary":null,"body":["<article data-history-node-id=\"3370\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-381\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-381<\/strong><br \/><strong>Date: 8 July 2022<\/strong><\/p>\n\n<p>Between 7 and 8 July 2022, Dell published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell VxRail Appliance \u2013 versions 7.0.x prior to 7.0.372<\/li>\n\t<li>PowerProtect DD Appliance \u2013 multiple models and versions<\/li>\n\t<li>PowerProtect DD DDOS and DDMC \u2013 multiple versions<\/li>\n\t<li>PowerStore T OS \u2013 versions prior to 3.0.0.0-1732745<\/li>\n\t<li>PowerStore Command Line Interface (CLI) tool for Linux x86\/x64 \u2013 versions prior to 3.0.0.0-1732745<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201322\/dsa-2022-175-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Bulletin (DSA-2022-175)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201296\/dsa-2022-187-dell-technologies-powerprotect-data-domain-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Bulletin (DSA-2022-187)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201283\/dsa-2022-159-dell-powerstore-family-security-update-for-multiple-vulnerabilities\">Dell Security Bulletin (DSA-2022-159)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-381","alert_type":396,"serial_number":"AV22-381","subject":null,"moderation_state":"published","external_url":null},{"nid":3371,"title":"IBM security advisory (AV22-382)","uuid":"37a89b0c-8b44-4e22-87f6-4f0d20721820","banner":null,"lang":"en","date_modified":"2022-07-11","date_modified_ts":"2022-07-11T19:21:32Z","date_created":"2022-07-11T19:21:32Z","summary":null,"body":["<article data-history-node-id=\"3371\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-382\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-382<\/strong><br \/><strong>Date: 11 July 2022<\/strong><\/p>\n\n<p>Between 4 and 10 July 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM MQ Operator CD \u2013 version 1.8.2<\/li>\n\t<li>IBM QRadar Network Packet Capture \u2013 multiple versions<\/li>\n\t<li>IBM Tivoli Netcool Impact \u2013 version 7.1.0<\/li>\n\t<li>IBM Tivoli Netcool System Service Monitors\/Application Service Monitors \u2013 version 4.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-382","alert_type":396,"serial_number":"AV22-382","subject":null,"moderation_state":"published","external_url":null},{"nid":3376,"title":"SAP security advisory \u2013 July 2022 monthly rollup (AV22-383)","uuid":"0f3bc260-0383-4051-aa14-e2946ae8e53e","banner":null,"lang":"en","date_modified":"2022-07-12","date_modified_ts":"2022-07-12T18:03:59Z","date_created":"2022-07-12T16:05:18Z","summary":null,"body":["<article data-history-node-id=\"3376\" about=\"\/en\/alerts-advisories\/sap-security-advisory-july-2022-monthly-rollup-av22-383\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-383<\/strong><br \/><strong>Date: 12 July 2022<\/strong><\/p>\n\n<p>On 12 July 2022 SAP published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Business One \u2013 version 10<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform \u2013 versions 420 and 430<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-july-2022-monthly-rollup-av22-383","alert_type":396,"serial_number":"AV22-383","subject":null,"moderation_state":"published","external_url":null},{"nid":3377,"title":"[Control systems] Schneider Electric security advisory (AV22-384) ","uuid":"afa9ec28-fcd8-4028-9872-8f8cf0864c3e","banner":null,"lang":"en","date_modified":"2022-07-12","date_modified_ts":"2022-07-12T18:13:28Z","date_created":"2022-07-12T16:22:53Z","summary":null,"body":["<article data-history-node-id=\"3377\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-384\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-384<\/strong><br \/><strong>Date: 12 July 2022<\/strong><\/p>\n\n<p>On 12 July 2022 Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Acti9 PowerTag Link C (A9XELC10-A) \u2013 version 1.7.5 and prior<\/li>\n\t<li>Acti9 PowerTag Link C (A9XELC10-B) \u2013 version 2.12.0 and prior<\/li>\n\t<li>Easergy P5 \u2013 firmware version 01.401.102 and prior<\/li>\n\t<li>OPC UA Modicon Communication Module (BMENUA0100) \u2013 version 1.10 and prior<\/li>\n\t<li>SpaceLogic C-Bus Home Controller \u2013 versions 1.31.460 and prior<\/li>\n\t<li>X80 advanced RTU Communication Module (BMENOR2200H) \u2013 versions 1.0<\/li>\n\t<li>X80 advanced RTU Communication Module (BMENOR2200H) \u2013 version 2.01 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-193-01_OPC_UA_X80_Advanced_RTU_Modicon_Communication_Modules+_Security_Notification.pdf&amp;p_Doc_Ref=SEVD-2022-193-01&amp;_ga=2.169455780.463961950.1657515209-2030058615.1657267224\">Schneider Security Advisory (SEVD-2022-193-01) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-193-02_SpaceLogic-C-Bus-Home-Controller-Wiser_MK2_Security_Notification.pdf\">Schneider Security Advisory (SEVD-2022-193-02) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-193-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-193-03_Acti9_PowerTag_Link_C_Security_Notification.pdf\">Schneider Security Advisory (SEVD-2022-193-03) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-193-04&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-193-04_Easergy_P5_Security_Notification.pdf\">Schneider Security Advisory (SEVD-2022-193-04) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-384","alert_type":398,"serial_number":"AV22-384","subject":null,"moderation_state":"published","external_url":null},{"nid":3378,"title":"[Control systems] Siemens security advisory (AV22-385)","uuid":"0f6d23ef-5a07-454b-82b7-f1c0d795da77","banner":null,"lang":"en","date_modified":"2022-07-12","date_modified_ts":"2022-07-12T18:14:13Z","date_created":"2022-07-12T16:38:27Z","summary":null,"body":["<article data-history-node-id=\"3378\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-385\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-385<\/strong><br \/><strong>Date: 12 July 2022<\/strong><\/p>\n\n<p>On 12 July 2022 Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Opcenter Quality \u2013 multiple versions<\/li>\n\t<li>SCALANCE X Switch Devices \u2013 multiple versions and platforms<\/li>\n\t<li>SIMATIC CP Devices \u2013 multiple versions and platforms<\/li>\n\t<li>SIMATIC eaSie Core Package (6DL5424-0AX00-0AV8) \u2013 versions prior to V22.00<\/li>\n\t<li>SINAMICS PERFECT HARMONY GH180 Drives \u2013 drives manufactured since 2015 and prior to 2022<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-385","alert_type":398,"serial_number":"AV22-385","subject":null,"moderation_state":"published","external_url":null},{"nid":3380,"title":"Adobe security advisory (AV22-386)","uuid":"5c4f9c0d-967a-45d2-a24d-50db37cca58d","banner":null,"lang":"en","date_modified":"2022-07-12","date_modified_ts":"2022-07-12T19:05:47Z","date_created":"2022-07-12T19:05:47Z","summary":null,"body":["<article data-history-node-id=\"3380\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-386\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-386<\/strong><br \/><strong>Date: 12 July 2022<\/strong><\/p>\n\n<p>On 12 July 2022 Adobe published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat \u2013 multiple versions<\/li>\n\t<li>Character Animator2021 - version 4.4.7 and prior<\/li>\n\t<li>Character Animator 2022 - version 22.4 and prior<\/li>\n\t<li>Photoshop 2021 - version 22.5.7 and prior<\/li>\n\t<li>Photoshop 2022 - version 23.3.2 and prior<\/li>\n\t<li>RoboHelp - version RH2020.0.7 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution or memory leaks.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-386","alert_type":396,"serial_number":"AV22-386","subject":null,"moderation_state":"published","external_url":null},{"nid":3381,"title":"Microsoft security advisory \u2013 July 2022 monthly rollup (AV22-387)","uuid":"e7dcd07f-80ed-486f-a913-d0aa835c96e6","banner":null,"lang":"en","date_modified":"2022-07-12","date_modified_ts":"2022-07-12T19:14:59Z","date_created":"2022-07-12T19:14:59Z","summary":null,"body":["<article data-history-node-id=\"3381\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2022-monthly-rollup-av22-387\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-387<\/strong><br \/>\n<strong>Date: 12 July 2022<\/strong><\/p>\n\n<p>On 12 July 2022 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 11 \u2013 multiple versions<\/li>\n\t<li>Windows 10 \u2013 multiple versions<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions<\/li>\n\t<li>Windows 7 \u2013 multiple versions<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul>\n\n<p>Microsoft has indicated that CVE-2022-22047 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\">\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Jul\">July 2022 release notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2022-monthly-rollup-av22-387","alert_type":396,"serial_number":"AV22-387","subject":null,"moderation_state":"published","external_url":null},{"nid":3382,"title":"[Control systems] Dahua security advisory (AV22-388)","uuid":"8d79dc75-44b7-425f-bab3-62ff69dd7ba9","banner":null,"lang":"en","date_modified":"2022-07-12","date_modified_ts":"2022-07-12T21:00:38Z","date_created":"2022-07-12T21:00:38Z","summary":null,"body":["<article data-history-node-id=\"3382\" about=\"\/en\/alerts-advisories\/control-systems-dahua-security-advisory-av22-388\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-388<\/strong><br \/><strong>Date: 12 July 2022<\/strong><\/p>\n\n<p>On 12 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Dahua ASI7213X-T1 \u2013 firmware version 1.000.10Be006.0.R.201213<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access, upload of arbitrary files, information disclosure or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-193-01\">ICS Advisory (ICSA-22-193-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-dahua-security-advisory-av22-388","alert_type":398,"serial_number":"AV22-388","subject":null,"moderation_state":"published","external_url":null},{"nid":3383,"title":"Citrix security advisory (AV22-389)","uuid":"887b1173-321d-4796-b2b6-3e9e2bd50fbb","banner":null,"lang":"en","date_modified":"2022-07-12","date_modified_ts":"2022-07-12T21:07:50Z","date_created":"2022-07-12T21:07:50Z","summary":null,"body":["<article data-history-node-id=\"3383\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-389\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-389<\/strong><br \/>\n<strong>Date: 12 July 2022<\/strong><\/p>\n\n<p>On 12 July 2022 Citrix published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul>\n\t<li>Citrix Hypervisor AMD Zen 1 and AMD Zen 2 \u2013 versions prior to 8.2 Cumulative Update 1<\/li>\n\t<li>Citrix XenServer AMD Zen 1 and AMD Zen 2 \u2013 versions prior to 7.1 Cumulative Update 2<\/li>\n<\/ul>\n\n<p>Exploitation of these vulnerabilities could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\">\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX461397\/citrix-hypervisor-security-bulletin-for-cve202223816-and-cve202223825\">Citrix Security Bulletin (CTX461397)<\/a><\/li>\n<\/ul>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-389","alert_type":396,"serial_number":"AV22-389","subject":null,"moderation_state":"published","external_url":null},{"nid":3384,"title":"Dell security advisory (AV22-390)","uuid":"37c2a65a-d635-44da-9866-8cc7330bfa18","banner":null,"lang":"en","date_modified":"2022-07-13","date_modified_ts":"2022-07-13T19:30:54Z","date_created":"2022-07-13T19:30:54Z","summary":null,"body":["<article data-history-node-id=\"3384\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-390\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-390<\/strong><br \/><strong>Date: 13 July 2022<\/strong><\/p>\n\n<p>On 13 July 2022 Dell published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell NetWorker Runtime Environment (NRE) \u2014 version 8.0.12 and prior<\/li>\n\t<li>Dell xDoctor4ECS \u2014 version 4.8-80.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201429\/dsa-2022-185-dell-emc-xdoctor4ecs-security-update-for-multiple-third-party-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-185)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201463\/dsa-2022-189-dell-emc-networker-runtime-environment-nre-security-update-for-java-se-embedded-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-189)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-390","alert_type":396,"serial_number":"AV22-390","subject":null,"moderation_state":"published","external_url":null},{"nid":3385,"title":"Juniper Networks security advisory (AV22-391)","uuid":"bc5e80c7-caca-4569-9b6f-ea330e45d0b0","banner":null,"lang":"en","date_modified":"2022-07-13","date_modified_ts":"2022-07-13T19:40:19Z","date_created":"2022-07-13T19:40:19Z","summary":null,"body":["<article data-history-node-id=\"3385\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-391\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-391<\/strong><br \/>\n<strong>Date: 13 July 2022<\/strong><\/p>\n\n<p>On 13 July 2022 Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul>\n\t<li>Juniper Networks Contrail Networking \u2013 versions prior to 21.4.0<\/li>\n\t<li>Juniper Networks Junos Space \u2013 versions prior to 22.1R1<\/li>\n\t<li>Juniper Networks Junos Space Policy Enforcer \u2013 versions prior to 22.1R1<\/li>\n\t<li>Juniper Networks NorthStar Controller \u2013 multiple versions<\/li>\n<\/ul>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\">\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2022-07-Security-Bulletin-Northstar-Controller-nginx-component-allows-remote-attacker-to-cause-worker-process-crash-or-potentially-arbitrary-code-execution-CVE-2021-23017-2?language=en_US\" rel=\"external\">Juniper Networks Security Advisory (JSA69703)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2022-07-Security-Bulletin-Junos-Space-Multiple-vulnerabilities-resolved-in-22-2R1-release-CVE-2022-22218?language=en_US\" rel=\"external\">Juniper Networks Security Advisory (JSA69722)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2022-07-Security-Bulletin-Junos-Space-Security-Director-Policy-Enforcer-upgraded-to-CentOS-7-9?language=en_US\" rel=\"external\">Juniper Networks Security Advisory (JSA69723)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2022-07-Security-Bulletin-Contrail-Networking-Multiple-vulnerabilities-resolved-in-Contrail-Networking-21-4?language=en_US\" rel=\"external\">Juniper Networks Security Advisory (JSA69726)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=date%20descending&amp;f:ctype=[Security%20Advisories]\" rel=\"external\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-391","alert_type":396,"serial_number":"AV22-391","subject":null,"moderation_state":"published","external_url":null},{"nid":3386,"title":"Ubuntu security advisory (AV22-392)","uuid":"a76f3915-0995-4448-a88a-10a619ed1351","banner":null,"lang":"en","date_modified":"2022-07-14","date_modified_ts":"2022-07-14T18:58:38Z","date_created":"2022-07-14T18:58:38Z","summary":null,"body":["<article data-history-node-id=\"3386\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-392\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-392<\/strong><br \/><strong>Date: 14 July 2022<\/strong><\/p>\n\n<p>Between 13 and 14 July 2022 Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-392","alert_type":396,"serial_number":"AV22-392","subject":null,"moderation_state":"published","external_url":null},{"nid":3387,"title":"[Control systems] Open Design Alliance security advisory (AV22-393)","uuid":"0d368bca-31f4-4c5f-b123-bd66b2f9a62a","banner":null,"lang":"en","date_modified":"2022-07-14","date_modified_ts":"2022-07-14T19:11:33Z","date_created":"2022-07-14T19:11:33Z","summary":null,"body":["<article data-history-node-id=\"3387\" about=\"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory-av22-393\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-393<\/strong><br \/><strong>Date: 14 July 2022<\/strong><\/p>\n\n<p>On 14 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Drawing SDK \u2013 versions prior to 2023.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-195-11\" rel=\"external\">ICS Advisory (ICSA-22-195-11)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory-av22-393","alert_type":398,"serial_number":"AV22-393","subject":null,"moderation_state":"published","external_url":null},{"nid":3388,"title":"[Control systems] ABB security advisory (AV22-394)","uuid":"81191500-0034-4a27-b036-894de45ae910","banner":null,"lang":"en","date_modified":"2022-07-15","date_modified_ts":"2022-07-15T16:38:09Z","date_created":"2022-07-15T16:38:09Z","summary":null,"body":["<article data-history-node-id=\"3388\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-394\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-394<\/strong><br \/>\n<strong>Date: 15 July 2022<\/strong><\/p>\n\n<p>On 14 July 2022 ABB published a Cyber Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul>\n\t<li>RMC-100 (Standard) - versions prior to 2105457-037<\/li>\n\t<li>RMC-100-LITE - versions prior to 2106229-011<\/li>\n\t<li>XIO - versions prior to 2106198-008<\/li>\n\t<li>XFC - versions prior to 2105805-016<\/li>\n\t<li>XRC - versions prior to 2105864-016<\/li>\n\t<li>uFLO - versions prior to 2105298-024<\/li>\n\t<li>UDC - versions prior to 2106177-007<\/li>\n<\/ul>\n\n<p>Exploitation of this vulnerability could lead to unauthorized access and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\">\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108467A0927\" rel=\"external\">ABB Cyber Security Advisory (9AKK108467A0927) (PDF)<\/a><\/li>\n<\/ul>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-394","alert_type":398,"serial_number":"AV22-394","subject":null,"moderation_state":"published","external_url":null},{"nid":3392,"title":"IBM security advisory (AV22-395)","uuid":"846f7d4b-19f7-4c2d-887a-e140a90dfcc6","banner":null,"lang":"en","date_modified":"2022-07-18","date_modified_ts":"2022-07-18T18:02:33Z","date_created":"2022-07-18T18:02:33Z","summary":null,"body":["<article data-history-node-id=\"3392\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-395\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-395<\/strong><br \/><strong>Date: 18 July 2022<\/strong><\/p>\n\n<p>Between 11 and 17 July 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container \u2013 multiple versions<\/li>\n\t<li>IBM Content Manager OnDemand for Multiplatforms \u2013 versions 10.1.x and 10.5.x<\/li>\n\t<li>IBM Enterprise Content Management System Monitor \u2013 version 5.5<\/li>\n\t<li>IBM i Modernization Engine for Lifecycle Integration \u2013 version 1.0<\/li>\n\t<li>IBM Integration Bus \u2013 versions 10.0.0.0 to 10.0.0.26<\/li>\n\t<li>IBM Tivoli Netcool Impact \u2013 version 7.1.0<\/li>\n\t<li>IBM Tivoli Netcool\/OMNIbus_GUI \u2013 versions 8.1.0 FP26 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-395","alert_type":396,"serial_number":"AV22-395","subject":null,"moderation_state":"published","external_url":null},{"nid":3393,"title":"Dell security advisory (AV22-396)","uuid":"193b6aa9-8182-41a0-8730-4dcec789ee90","banner":null,"lang":"en","date_modified":"2022-07-18","date_modified_ts":"2022-07-18T19:57:30Z","date_created":"2022-07-18T19:57:30Z","summary":null,"body":["<article data-history-node-id=\"3393\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-396\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-396<\/strong><br \/><strong>Date: 18 July 2022<\/strong><\/p>\n\n<p>On 18 July 2022 Dell published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Avamar \u2014 multiple versions and platforms<\/li>\n\t<li>Dell Networker Virtual Edition (NVE) \u2014 multiple versions and platforms<\/li>\n\t<li>Dell PowerProtect DP Series Appliance and Integrated Data Protection Appliance \u2014 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201576\/dsa-2022-191-dell-emc-avamar-dell-emc-networker-virtual-edition-nve-and-dell-emc-powerprotect-dp-series-appliance-dell-emc-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-191)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-396","alert_type":396,"serial_number":"AV22-396","subject":null,"moderation_state":"published","external_url":null},{"nid":3397,"title":"Red Hat security advisory (AV22-398)","uuid":"6edd3953-2e3c-4950-b98f-a764c0fefa0a","banner":null,"lang":"en","date_modified":"2022-07-19","date_modified_ts":"2022-07-19T20:28:54Z","date_created":"2022-07-19T20:10:01Z","summary":null,"body":["<article data-history-node-id=\"3397\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-398\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-398<\/strong><br \/><strong>Date: 19 July 2022<\/strong><\/p>\n\n<p>On 19 July 2022 Red Hat published a Security Advisory to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server \u2013 Extended Life Cycle Support 6 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 Extended Life Cycle Support 6 i386<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 Extended Life Cycle Support (for IBM z Systems) 6 s390x<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:5640\" rel=\"external\">Red Hat Security Advisory (RHSA-2022-5640)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-398","alert_type":396,"serial_number":"AV22-398","subject":null,"moderation_state":"published","external_url":null},{"nid":3398,"title":"[Control systems] MiCODUS security advisory (AV22-397)","uuid":"c8163266-35b3-4949-9919-3425c0332fac","banner":null,"lang":"en","date_modified":"2022-07-19","date_modified_ts":"2022-07-19T20:24:37Z","date_created":"2022-07-19T20:24:37Z","summary":null,"body":["<article data-history-node-id=\"3398\" about=\"\/en\/alerts-advisories\/control-systems-micodus-security-advisory-av22-397\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-397<\/strong><br \/><strong>Date: 19 July 2022<\/strong><\/p>\n\n<p>On 19 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>MV720 GPS tracker<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-200-01\" rel=\"external\">ICS Advisory (ICSA-22-200-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-micodus-security-advisory-av22-397","alert_type":398,"serial_number":"AV22-397","subject":null,"moderation_state":"published","external_url":null},{"nid":3400,"title":"Oracle security advisory \u2013 July 2022 quarterly rollup (AV22-399)","uuid":"b211102a-e0f2-4e43-a20f-a3f4c36b4f39","banner":null,"lang":"en","date_modified":"2022-07-20","date_modified_ts":"2022-07-20T19:08:55Z","date_created":"2022-07-20T19:08:55Z","summary":null,"body":["<article data-history-node-id=\"3400\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-july-2022-quarterly-rollup\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-399<\/strong><br \/>\n<strong>Date: 20 July 2022<\/strong><\/p>\n\n<p>On 19 July 2022 Oracle published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul>\n\t<li>Agile Engineering Data Management \u2013 version 6.2.1.0<\/li>\n\t<li>Commerce Guided Search \u2013 version 11.3.2<\/li>\n\t<li>Commerce Platform \u2013 version 11.3.2<\/li>\n\t<li>Communications Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Database - Enterprise Edition \u2013 versions 12.1.0.2, 19c and 21c<\/li>\n\t<li>E-Business Suite Information Discovery \u2013 version 12.2.3 to 12.2.11<\/li>\n\t<li>Enterprise Manager Ops Center \u2013 version 12.4.0.0<\/li>\n\t<li>Enterprise Operations Monitor \u2013 versions 4.3, 4.4 and 5.0<\/li>\n\t<li>Financial Services Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Hospitality OPERA 5 \u2013 version 5.6<\/li>\n\t<li>HTTP Server \u2013 versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>JD Edwards EnterpriseOne Tools \u2013 version 9.2.6.1 and prior<\/li>\n\t<li>Middleware Common Libraries and Tools \u2013 versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>MySQL \u2013 multiple versions and platform<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools \u2013 versions 8.58 and 8.59<\/li>\n\t<li>Retail Applications \u2013 multiple versions and platforms<\/li>\n\t<li>Security Service \u2013 versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Transportation Management \u2013 version 1.4.4<\/li>\n\t<li>WebLogic Server \u2013 versions 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n\t<li>Weblogic Server Proxy Plug-in \u2013 versions 12.2.1.3.0 and 12.2.1.4.0<\/li>\n<\/ul>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\">\n\t<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2022.html\" rel=\"external\">Oracle Critical Patch Update Advisory \u2013 July 2022<\/a><\/li>\n<\/ul>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-july-2022-quarterly-rollup","alert_type":396,"serial_number":"AV22-399","subject":null,"moderation_state":"published","external_url":null},{"nid":3401,"title":"Google Chrome security advisory (AV22-400)","uuid":"1b0d2d81-a2ab-4c26-bbf4-0f0cf8dcafaf","banner":null,"lang":"en","date_modified":"2022-07-20","date_modified_ts":"2022-07-20T19:20:26Z","date_created":"2022-07-20T19:20:26Z","summary":null,"body":["<article data-history-node-id=\"3401\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-400\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-400<\/strong><br \/><strong>Date: 20 July 2022<\/strong><\/p>\n\n<p>On 19 July 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 103.0.5060.134<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/07\/stable-channel-update-for-desktop_19.html\" rel=\"external\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-400","alert_type":396,"serial_number":"AV22-400","subject":null,"moderation_state":"published","external_url":null},{"nid":3402,"title":"Cisco security advisory (AV22-401)","uuid":"a4c11c6c-3990-4ac7-9429-ed60b33086b4","banner":null,"lang":"en","date_modified":"2022-07-20","date_modified_ts":"2022-07-20T19:38:53Z","date_created":"2022-07-20T19:38:53Z","summary":null,"body":["<article data-history-node-id=\"3402\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-401\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-401<\/strong><br \/><strong>Date: 20 July 2022<\/strong><\/p>\n\n<p>On 20 July 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Cisco Nexus Dashboard \u2013 versions 1.1, 2.0, 2.1 and 2.2<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ndb-mhcvuln-vpsBPJ9y\" rel=\"external\">Cisco Security Advisory (cisco-sa-ndb-mhcvuln-vpsBPJ9y)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\" rel=\"external\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-401","alert_type":396,"serial_number":"AV22-401","subject":null,"moderation_state":"published","external_url":null},{"nid":3403,"title":"Apple security advisory (AV22-402)","uuid":"ceb2f4fc-13e1-4bdb-8cd6-79a079f0533b","banner":null,"lang":"en","date_modified":"2022-07-20","date_modified_ts":"2022-07-20T21:11:38Z","date_created":"2022-07-20T21:11:38Z","summary":null,"body":["<article data-history-node-id=\"3403\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-402\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-402<\/strong><br \/><strong>Date: 20 July 2022<\/strong><\/p>\n\n<p>On 20 July 2022 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 15.6<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.6.8<\/li>\n\t<li>macOS Catalina \u2013 versions prior to 2022-005<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.5<\/li>\n\t<li>Safari \u2013 versions prior to 15.6<\/li>\n\t<li>tvOS \u2013 versions prior to 15.6<\/li>\n\t<li>watchOS \u2013 versions prior to 8.7<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" rel=\"external\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-402","alert_type":396,"serial_number":"AV22-402","subject":null,"moderation_state":"published","external_url":null},{"nid":3404,"title":"Drupal security advisory (AV22-403)","uuid":"a9c18672-f421-4094-a109-bd3e7fe621ad","banner":null,"lang":"en","date_modified":"2022-07-20","date_modified_ts":"2022-07-20T21:19:24Z","date_created":"2022-07-20T21:19:24Z","summary":null,"body":["<article data-history-node-id=\"3404\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av22-403\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-403<\/strong><br \/><strong>Date: 20 July 2022<\/strong><\/p>\n\n<p>On 20 July 2022 Drupal published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Drupal core \u2013 versions 9.3 and 9.4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-core-2022-014\" rel=\"external\">Drupal Security Advisory (SA-CORE-2022-014)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\" rel=\"external\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av22-403","alert_type":396,"serial_number":"AV22-403","subject":null,"moderation_state":"published","external_url":null},{"nid":3406,"title":"Atlassian security advisory (AV22-404)","uuid":"4147defb-ee14-44fa-987e-e174ce372d1d","banner":null,"lang":"en","date_modified":"2022-07-21","date_modified_ts":"2022-07-21T17:42:24Z","date_created":"2022-07-21T17:42:24Z","summary":null,"body":["<article data-history-node-id=\"3406\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av22-404\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-404<\/strong><br \/><strong>Date: 21 July 2022<\/strong><\/p>\n\n<p>On 20 July 2022 Atlassian published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Server and Data Center \u2013 multiple versions<\/li>\n\t<li>Bitbucket Server and Data Center \u2013 multiple versions<\/li>\n\t<li>Confluence Server and Data Center \u2013 multiple versions<\/li>\n\t<li>Crowd Server and Data Center \u2013 multiple versions<\/li>\n\t<li>Fisheye and Crucible \u2013 versions prior to 4.8.10<\/li>\n\t<li>Jira Server and Data Center \u2013 multiple versions<\/li>\n\t<li>Jira Service Management Server and Data Center \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to security bypass and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/multiple-products-security-advisory-cve-2022-26136-cve-2022-26137-1141493031.html\" rel=\"external\">Atlassian Security Advisory (Multiple-Products-Advisory)<\/a><\/li>\n\t<li><a href=\"https:\/\/confluence.atlassian.com\/doc\/questions-for-confluence-security-advisory-2022-07-20-1142446709.html\" rel=\"external\">Atlassian Security Advisory (Questions-for-Confluence)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av22-404","alert_type":396,"serial_number":"AV22-404","subject":null,"moderation_state":"published","external_url":null},{"nid":3407,"title":"Ubuntu security advisory (AV22-405)","uuid":"6b4b02c9-f07a-4d87-8a6b-e91a7a115bae","banner":null,"lang":"en","date_modified":"2022-07-21","date_modified_ts":"2022-07-21T19:08:10Z","date_created":"2022-07-21T19:08:10Z","summary":null,"body":["<article data-history-node-id=\"3407\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-405\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-405<\/strong><br \/><strong>Date: 21 July 2022<\/strong><\/p>\n\n<p>On 21 July 2022 Ubuntu published a Security Notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5529-1\" rel=\"external\">Ubuntu Security Notice (USN-5529-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-405","alert_type":396,"serial_number":"AV22-405","subject":null,"moderation_state":"published","external_url":null},{"nid":3408,"title":"Dell security advisory (AV22-406)","uuid":"e37d6c5f-03dd-4f1f-8458-dbc06ea8e55d","banner":null,"lang":"en","date_modified":"2022-07-22","date_modified_ts":"2022-07-22T15:36:29Z","date_created":"2022-07-22T15:36:29Z","summary":null,"body":["<article data-history-node-id=\"3408\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-406\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-406<\/strong><br \/><strong>Date: 22 July 2022<\/strong><\/p>\n\n<p>On 19 July 2022, Dell published a Security Bulletin to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Connectrix (Cisco) DCNM \u2013 versions prior to 11.5(4)<\/li>\n\t<li>Connectrix (Cisco) NDFC \u2013 versions prior to 12.0(2f)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201622\/dsa-2022-167-dell-connectrix-cisco-security-update-for-multiple-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-167)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-406","alert_type":396,"serial_number":"AV22-406","subject":null,"moderation_state":"published","external_url":null},{"nid":3409,"title":"[Control systems] AutomationDirect security advisory (AV22-407)","uuid":"2d68ae4d-a519-450a-b8f4-7de2c2ed36e0","banner":null,"lang":"en","date_modified":"2022-07-22","date_modified_ts":"2022-07-22T15:43:52Z","date_created":"2022-07-22T15:43:52Z","summary":null,"body":["<article data-history-node-id=\"3409\" about=\"\/en\/alerts-advisories\/control-systems-automationdirect-security-advisory-av22-407\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-407<\/strong><br \/><strong>Date: 22 July 2022<\/strong><\/p>\n\n<p>On 21 July 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Stride Field I\/O \u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in credential disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-202-05\" rel=\"external\">ICS Advisory (ICSA-22-202-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-automationdirect-security-advisory-av22-407","alert_type":398,"serial_number":"AV22-407","subject":null,"moderation_state":"published","external_url":null},{"nid":3410,"title":"[Control systems] ABB security advisory (AV22-408)","uuid":"8c846960-bfdb-4c13-a5f1-865227fbf032","banner":null,"lang":"en","date_modified":"2022-07-22","date_modified_ts":"2022-07-22T16:16:14Z","date_created":"2022-07-22T16:16:14Z","summary":null,"body":["<article data-history-node-id=\"3410\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-408\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-408<\/strong><br \/><strong>Date: 22 July 2022<\/strong><\/p>\n\n<p>On 21 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Automation Builder \u2013 versions 1.1.0 to 2.5.0<\/li>\n\t<li>ABB Drive Composer Entry \u2013 versions 2.0 to 2.7<\/li>\n\t<li>ABB Drive Composer Pro \u2013 versions 2.0 to 2.7<\/li>\n\t<li>Mint Workbench \u2013 version 5866 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-202-01\" rel=\"external\">ICS Advisory (ICSA-22-202-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-408","alert_type":398,"serial_number":"AV22-408","subject":null,"moderation_state":"published","external_url":null},{"nid":3413,"title":"[Control systems] Johnson Controls security advisory (AV22-410)","uuid":"9e29c780-7a4e-450a-916e-47e59f992960","banner":null,"lang":"en","date_modified":"2022-07-22","date_modified_ts":"2022-07-22T21:06:22Z","date_created":"2022-07-22T19:17:51Z","summary":null,"body":["<article data-history-node-id=\"3413\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-410\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-410<\/strong><br \/><strong>Date: 22 July 2022<\/strong><\/p>\n\n<p>On 21 July 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Johnson Controls Metasys ADS, ADX, OAS with MUI \u2013 versions 10 and 11<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-202-02\" rel=\"external\">ICS Advisory (ICSA-22-202-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-410","alert_type":398,"serial_number":"AV22-410","subject":null,"moderation_state":"published","external_url":null},{"nid":3414,"title":"[Control systems] ICONICS and Mitsubishi Electric security advisory (AV22-409)","uuid":"1ad0f542-e2f0-4f08-ac9d-c3bff5184bc8","banner":null,"lang":"en","date_modified":"2022-07-22","date_modified_ts":"2022-07-22T20:52:36Z","date_created":"2022-07-22T20:52:36Z","summary":null,"body":["<article data-history-node-id=\"3414\" about=\"\/en\/alerts-advisories\/control-systems-iconics-and-mitsubishi-electric-security-advisory-av22-409\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-409<\/strong><br \/><strong>Date: 22 July 2022<\/strong><\/p>\n\n<p>On 21 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ICONICS AnalytiX \u2013 version 10.97.1 and prior<\/li>\n\t<li>ICONICS GENESIS64 \u2013 version 10.97.1 and prior<\/li>\n\t<li>ICONICS GenBrokerX64 \u2013 version 10.97.1 and prior<\/li>\n\t<li>ICONICS GraphWorX64 \u2013 version 10.97.1 and prior<\/li>\n\t<li>ICONICS Hyper Historian \u2013 version 10.97.1 and prior<\/li>\n\t<li>ICONICS IoTWorX \u2013 versions 10.97 and 10.97.1<\/li>\n\t<li>ICONICS MobileHMI \u2013 versions 10.97 and 10.97.1<\/li>\n\t<li>Mitsubishi Electric MC Works64 \u2013 version 4.04E and prior (v10.95.210.01)<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution, information disclosure or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-202-04\" rel=\"external\">ICS Advisory (ICSA-22-202-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-iconics-and-mitsubishi-electric-security-advisory-av22-409","alert_type":398,"serial_number":"AV22-409","subject":null,"moderation_state":"published","external_url":null},{"nid":3415,"title":"[Control systems] Rockwell Automation security advisory (AV22-411)","uuid":"01250864-d5a0-47c1-85bd-9b4920407f67","banner":null,"lang":"en","date_modified":"2022-07-22","date_modified_ts":"2022-07-22T21:11:20Z","date_created":"2022-07-22T21:11:20Z","summary":null,"body":["<article data-history-node-id=\"3415\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-411\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-411<\/strong><br \/><strong>Date: 22 July 2022<\/strong><\/p>\n\n<p>On 21 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ISaGRAF Workbench \u2013 versions 6.0 to 6.6.9<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-202-03\" rel=\"external\">ICS Advisory (ICSA-22-202-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-411","alert_type":398,"serial_number":"AV22-411","subject":null,"moderation_state":"published","external_url":null},{"nid":3416,"title":"IBM security advisory (AV22-412)","uuid":"e6431bdd-d6de-4561-a66f-968d4420af5e","banner":null,"lang":"en","date_modified":"2022-07-25","date_modified_ts":"2022-07-25T16:57:50Z","date_created":"2022-07-25T16:57:50Z","summary":null,"body":["<article data-history-node-id=\"3416\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-412\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-412<\/strong><br \/><strong>Date: 25 July 2022<\/strong><\/p>\n\n<p>Between 18 and 24 July 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Maximo Scheduler Optimization \u2013 version 8.0.0<\/li>\n\t<li>IBM OpenPages with Watson \u2013 versions 8.1 to 8.2.0.4.2<\/li>\n\t<li>IBM PureData System for Operational Analytics \u2013 version 1.1 (A1801)<\/li>\n\t<li>IBM QRadar Network Security \u2013 versions 5.40 and 5.5.0<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager virtual appliance component \u2013 version 10.0<\/li>\n\t<li>IBM Security Verify Information Queue \u2013 version 10.0.2<\/li>\n\t<li>ITNM \u2013 version 4.2.0.x<\/li>\n\t<li>Log Analysis \u2013 version 1.3.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-412","alert_type":396,"serial_number":"AV22-412","subject":null,"moderation_state":"published","external_url":null},{"nid":3417,"title":"SonicWall security advisory (AV22-413)","uuid":"57cda197-1d01-4cb0-b86b-a0ed9f0812d2","banner":null,"lang":"en","date_modified":"2022-07-25","date_modified_ts":"2022-07-25T18:59:37Z","date_created":"2022-07-25T18:59:37Z","summary":null,"body":["<article data-history-node-id=\"3417\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av22-413\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-413<\/strong><br \/><strong>Date: 25 July 2022<\/strong><\/p>\n\n<p>On 21 July 2022, SonicWall published Security Bulletins to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>SonicWall Analytics On-Prem \u2013 version 2.5.0.3-2520 and prior<\/li>\n\t<li>SonicWall Global Management System (GMS) \u2013 version 9.3.1-SP2-Hotfix-1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sonicwall.com\/support\/knowledge-base\/security-notice-sonicwall-analytics-on-prem-sql-injection-vulnerability\/220613083254037\/\" rel=\"external\">Security Notice: SonicWall Analytics On-Prem SQL Injection Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.sonicwall.com\/support\/knowledge-base\/security-notice-sonicwall-gms-sql-injection-vulnerability\/220613083124303\/\" rel=\"external\">Security Notice: SonicWall GMS SQL Injection Vulnerability<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av22-413","alert_type":396,"serial_number":"AV22-413","subject":null,"moderation_state":"published","external_url":null},{"nid":3419,"title":" Dell security advisory (AV22-414)","uuid":"3c72fc7f-76c9-4c11-aa51-ae9e3fb78a89","banner":null,"lang":"en","date_modified":"2022-07-25","date_modified_ts":"2022-07-25T19:13:48Z","date_created":"2022-07-25T19:13:48Z","summary":null,"body":["<article data-history-node-id=\"3419\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-414\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-414<\/strong><br \/><strong>Date: 25 July 2022<\/strong><\/p>\n\n<p>On 25 July 2022, Dell published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cloud Tiering Appliance \u2013 versions 13.0.x and 13.1.x<\/li>\n\t<li>Dell Container Storage Modules \u2013 versions prior to 1.3<\/li>\n\t<li>Dell NetWorker vProxy \u2013 version 4.3.0-22 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201834\/dsa-2022-200-dell-emc-cloud-tiering-appliance-security-update-for-multiple\" rel=\"external\">Dell Security Bulletin (DSA-2022-200)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201835\/dsa-2022-202-dell-container-storage-modules-security-update-for-multiple-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-202)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201810\/dsa-2022-197-dell-emc-networker-vproxy-security-update-for-multiple-third-party-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-197)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-414","alert_type":396,"serial_number":"AV22-414","subject":null,"moderation_state":"published","external_url":null},{"nid":3421,"title":"Dell security advisory (AV22-415)","uuid":"56796279-3856-40e3-bf84-5d3f2b606b0e","banner":null,"lang":"en","date_modified":"2022-07-26","date_modified_ts":"2022-07-26T18:09:47Z","date_created":"2022-07-26T18:09:47Z","summary":null,"body":["<article data-history-node-id=\"3421\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-415\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-415<\/strong><br \/><strong>Date: 26 July 2022<\/strong><\/p>\n\n<p>On 26 July 2022, Dell published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Policy Manager for Secure Connect Gateway \u2013 version 5.10.00.00<\/li>\n\t<li>Dell Secure Connect Gateway \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201859\/dsa-2022-198-dell-emc-policy-manager-for-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-198)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201854\/dsa-2022-173-dell-emc-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-173)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-415","alert_type":396,"serial_number":"AV22-415","subject":null,"moderation_state":"published","external_url":null},{"nid":3422,"title":"[Control systems] Inductive Automation security advisory (AV22-416) ","uuid":"6bcd30c9-fe8c-4d53-85a1-99283c49b337","banner":null,"lang":"en","date_modified":"2022-07-26","date_modified_ts":"2022-07-26T18:17:19Z","date_created":"2022-07-26T18:17:19Z","summary":null,"body":["<article data-history-node-id=\"3422\" about=\"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-av22-416\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-416<\/strong><br \/><strong>Date: 26 July 2022<\/strong><\/p>\n\n<p>On 26 July 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Inductive Automation Ignition \u2013 versions prior to 8.1.9 and 7.9.21<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-207-01\" rel=\"external\">ICS Advisory (ICSA-22-207-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-av22-416","alert_type":398,"serial_number":"AV22-416","subject":null,"moderation_state":"published","external_url":null},{"nid":3423,"title":"[Control systems] MOXA security advisory (AV22-417)","uuid":"fcba026b-5fc8-47dc-976e-6ad7b35c26dc","banner":null,"lang":"en","date_modified":"2022-07-26","date_modified_ts":"2022-07-26T18:53:21Z","date_created":"2022-07-26T18:53:21Z","summary":null,"body":["<article data-history-node-id=\"3423\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av22-417\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-417<\/strong><br \/><strong>Date: 26 July 2022<\/strong><\/p>\n\n<p>On 26 July 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>NPort 5110 - firmware version 2.10<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-207-04\" rel=\"external\">ICS Advisory (ICSA-22-207-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av22-417","alert_type":398,"serial_number":"AV22-417","subject":null,"moderation_state":"published","external_url":null},{"nid":3424,"title":"[Control systems] Honeywell security advisory (AV22-418)","uuid":"5bf2d9d8-f128-44e4-a90e-0cd5f954277e","banner":null,"lang":"en","date_modified":"2022-07-26","date_modified_ts":"2022-07-26T19:00:07Z","date_created":"2022-07-26T19:00:07Z","summary":null,"body":["<article data-history-node-id=\"3424\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av22-418\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-418<\/strong><br \/><strong>Date: 26 July 2022<\/strong><\/p>\n\n<p>On 26 July 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Safety Manager \u2013 multiple versions<\/li>\n\t<li>Saia Burgess PG5 PCD \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow data modification or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-207-02\" rel=\"external\">ICS Advisory (ICSA-22-207-02)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-207-03\" rel=\"external\">ICS Advisory (ICSA-22-207-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av22-418","alert_type":398,"serial_number":"AV22-418","subject":null,"moderation_state":"published","external_url":null},{"nid":3425,"title":"Dell security advisory (AV22-419)","uuid":"2e25ab0b-3a7f-489e-bd74-9f50a5b3acb4","banner":null,"lang":"en","date_modified":"2022-07-27","date_modified_ts":"2022-07-27T18:08:11Z","date_created":"2022-07-27T18:08:11Z","summary":null,"body":["<article data-history-node-id=\"3425\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-419\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-419<\/strong><br \/><strong>Date: 27 July 2022<\/strong><\/p>\n\n<p>On 27 July 2022 Dell published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell AppSync \u2013 versions 4.4.0.0 and 4.4.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201907\/dsa-2022-195-dell-appsync-security-update-for-multiple-vulnerabilities-in-embedded-service-enabler-ese-component-of-appsync\" rel=\"external\">Dell Security Bulletin (DSA-2022-195)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-419","alert_type":396,"serial_number":"AV22-419","subject":null,"moderation_state":"published","external_url":null},{"nid":3426,"title":"Trellix security advisory (AV22-420)","uuid":"c1a144c9-a119-4c9f-a530-8056741b02e5","banner":null,"lang":"en","date_modified":"2022-07-27","date_modified_ts":"2022-07-27T18:16:36Z","date_created":"2022-07-27T18:16:36Z","summary":null,"body":["<article data-history-node-id=\"3426\" about=\"\/en\/alerts-advisories\/trellix-security-advisory-av22-420\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-420<\/strong><br \/><strong>Date: 27 July 2022<\/strong><\/p>\n\n<p>On 26 July 2022 Trellix published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>McAfee Agent \u2013 versions prior to 5.7.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kcm.trellix.com\/corporate\/index?page=content&amp;id=SB10385\" rel=\"external\">Trellix Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trellix-security-advisory-av22-420","alert_type":396,"serial_number":"AV22-420","subject":null,"moderation_state":"published","external_url":null},{"nid":3427,"title":"Dell security advisory (AV22-421)","uuid":"6cf8ad3e-44ca-4148-8328-6084088a90ac","banner":null,"lang":"en","date_modified":"2022-07-27","date_modified_ts":"2022-07-27T18:47:52Z","date_created":"2022-07-27T18:47:52Z","summary":null,"body":["<article data-history-node-id=\"3427\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-421\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-421<\/strong><br \/><strong>Date: 27 July 2022<\/strong><\/p>\n\n<p>On 27 July 2022 Dell published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell PowerMax Embedded NAS \u2013 versions prior to 8.1.15.401<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201919\/dsa-2022-165-dell-emc-powermax-embedded-nas-security-update-for-multiple-security-vulnerabilities\" rel=\"external\">Dell Security Bulletin (DSA-2022-165)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-421","alert_type":396,"serial_number":"AV22-421","subject":null,"moderation_state":"published","external_url":null},{"nid":3429,"title":"[Control systems] Rockwell Automation security advisory (AV22-422)","uuid":"8cd479b2-d945-4456-8e93-73a956d79d7f","banner":null,"lang":"en","date_modified":"2022-07-28","date_modified_ts":"2022-07-28T20:31:45Z","date_created":"2022-07-28T20:31:45Z","summary":null,"body":["<article data-history-node-id=\"3429\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-422\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-422<\/strong><br \/><strong>Date: 28 July 2022<\/strong><\/p>\n\n<p>On 28 July 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>FactoryTalk Linx Enterprise software - versions 6.20, 6.21, and 6.30<\/li>\n\t<li>Enhanced HIM (eHIM) for PowerFlex 6000T - version 1.001<\/li>\n\t<li>Connected Components Workbench software - versions 11, 12, 13, and 20<\/li>\n\t<li>FactoryTalk View Site Edition - version 13<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-209-01\" rel=\"external\">ICS Advisory (ICSA-22-209-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-422","alert_type":398,"serial_number":"AV22-422","subject":null,"moderation_state":"published","external_url":null},{"nid":3430,"title":"Mitel security advisory (AV22-423)","uuid":"c422cbf7-d291-41ed-be01-3f27f6f8dda4","banner":null,"lang":"en","date_modified":"2022-07-28","date_modified_ts":"2022-07-28T20:39:31Z","date_created":"2022-07-28T20:39:31Z","summary":null,"body":["<article data-history-node-id=\"3430\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av22-423\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-423<\/strong><br \/><strong>Date: 28 July 2022<\/strong><\/p>\n\n<p>On 27 July 2022 Mitel published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Mitel MiCollab \u2013 version 9.5.0.101 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-22-0006\" rel=\"external\">Mitel Product Security Advisory (22-0006)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av22-423","alert_type":396,"serial_number":"AV22-423","subject":null,"moderation_state":"published","external_url":null},{"nid":3431,"title":"HPE security advisory (AV22-424)","uuid":"284dd3e8-343d-4f19-87e4-f0e1cdc31f56","banner":null,"lang":"en","date_modified":"2022-07-29","date_modified_ts":"2022-07-29T14:29:04Z","date_created":"2022-07-29T14:24:48Z","summary":null,"body":["<article data-history-node-id=\"3431\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-424\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-424<\/strong><br \/><strong>Date: 29 July 2022<\/strong><\/p>\n\n<p>On 28 July 2022, HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Apollo \u2013 multiple platforms, versions prior to 2.71<\/li>\n\t<li>HPE Edgeline \u2013 multiple platforms, versions prior to 2.71<\/li>\n\t<li>HPE Integrated Lights-Out 5 for HPE Gen10 Servers \u2013 versions prior to 2.71<\/li>\n\t<li>HPE ProLiant \u2013 multiple platforms, versions prior to 2.71<\/li>\n\t<li>HPE Storage \u2013 multiple platforms, versions prior to 2.71<\/li>\n\t<li>HPE StoreEasy \u2013 multiple platforms, versions prior to 2.71<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04333en_us\">HPE Security Bulletin (hpesbhf04333en_us)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-424","alert_type":396,"serial_number":"AV22-424","subject":null,"moderation_state":"published","external_url":null},{"nid":3432,"title":"Ubuntu Security Advisory (AV22-425)","uuid":"9ab177a0-b17c-4385-80c4-3d9eaa0f5d0a","banner":null,"lang":"en","date_modified":"2022-07-29","date_modified_ts":"2022-07-29T15:23:09Z","date_created":"2022-07-29T15:21:08Z","summary":null,"body":["<article data-history-node-id=\"3432\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-425\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-425<\/strong><br \/><strong>Date: 29 July 2022<\/strong><\/p>\n\n<p>Between 28 and 29 July 2022 Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-425","alert_type":396,"serial_number":"AV22-425","subject":null,"moderation_state":"published","external_url":null},{"nid":3433,"title":"Dell security advisory (AV22-427)","uuid":"ad7d718c-b201-4552-b3d9-36cf8f44d2df","banner":null,"lang":"en","date_modified":"2022-07-29","date_modified_ts":"2022-07-29T19:21:01Z","date_created":"2022-07-29T19:14:07Z","summary":null,"body":["<article data-history-node-id=\"3433\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-427\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-427<\/strong><br \/><strong>Date: 29 July 2022<\/strong><\/p>\n\n<p>On 28 July 2022 Dell published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Data Protection Central\u00a0\u2013 multiple versions<\/li>\n\t<li>PowerProtect DP Series Appliance\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Data Protection Search\u00a0\u2013 version 19.6.0 and prior<\/li>\n\t<li>Dell Integrated Data Protection Appliance\u00a0\u2013 version 2.7.2 and prior<\/li>\n\t<li>Dell Unity\/VSA\/XT Operating Environment\u00a0\u2013 versions prior to 5.2.0.5.013<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000201967\/dsa-2022-206-dell-emc-data-protection-central-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Bulletin (DSA-2022-206)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000201991\/dsa-2022-209-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities\">Dell Security Bulletin (DSA-2022-209)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000201968\/dsa-2022-212-dell-emc-data-protection-central-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Bulletin (DSA-2022-212)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000201964\/dsa-2022-213-dell-emc-search-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Bulletin (DSA-2022-213)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-427","alert_type":396,"serial_number":"AV22-427","subject":null,"moderation_state":"published","external_url":null},{"nid":3434,"title":"[Control systems] ABB security advisory (AV22-426)","uuid":"0a81fe34-6e90-4adf-8162-11c35a5f0a57","banner":null,"lang":"en","date_modified":"2022-07-29","date_modified_ts":"2022-07-29T19:24:05Z","date_created":"2022-07-29T19:22:04Z","summary":null,"body":["<article data-history-node-id=\"3434\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-426\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-426<\/strong><br \/><strong>Date: 29 July 2022<\/strong><\/p>\n\n<p>On 26 July 2022 ABB published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Zenon\u00a0\u2013 versions prior to 8.20<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to unauthorized access or data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001479\">Cyber Security Advisory (2NGA001479) (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-426","alert_type":398,"serial_number":"AV22-426","subject":null,"moderation_state":"published","external_url":null},{"nid":3436,"title":"VMware security advisory (AV22-428)","uuid":"b76582a3-c7a6-4651-986c-944daf49e304","banner":null,"lang":"en","date_modified":"2022-08-02","date_modified_ts":"2022-08-02T17:29:11Z","date_created":"2022-08-02T17:29:11Z","summary":null,"body":["<article data-history-node-id=\"3436\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-428\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-428<\/strong><br \/><strong>Date: 2 August 2022<\/strong><\/p>\n\n<p>On 2 August 2022 VMware published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Access - versions 21.08.0.0 and 21.08.0.1<\/li>\n\t<li>vIDM - versions 3.3.4, 3.3.5 and 3.3.6<\/li>\n\t<li>vRealize Automation (vIDM) - version 7.6<\/li>\n\t<li>VMware Cloud Foundation (vIDM) - versions 4.3.x, 4.2.x and 4.4.x<\/li>\n\t<li>vRealize Suite Lifecycle Manager (vIDM) - version 8.x<\/li>\n\t<li>VMware Cloud Foundation (vRA) - version 3.x<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0021.html\" rel=\"external\">VMSA-2022-0021<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-428","alert_type":396,"serial_number":"AV22-428","subject":null,"moderation_state":"published","external_url":null},{"nid":3437,"title":"IBM security advisory (AV22-429)","uuid":"998b6b8c-1aa0-46ab-aded-c31e691f9616","banner":null,"lang":"en","date_modified":"2022-08-02","date_modified_ts":"2022-08-02T18:50:40Z","date_created":"2022-08-02T18:50:40Z","summary":null,"body":["<article data-history-node-id=\"3437\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-429\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-429<\/strong><br \/><strong>Date: 2 August 2022<\/strong><\/p>\n\n<p>Between 25 July and 1 August 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM AIX \u2013 version 7.3<\/li>\n\t<li>IBM Common Licensing \u2013 version 9.0<\/li>\n\t<li>IBM Engineering Lifecycle Optimization \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Engineering Systems Design Rhapsody \u2013 versions 8.4, 9.0 and 9.0.1<\/li>\n\t<li>IBM Engineering Test Management \u2013 multiple versions<\/li>\n\t<li>IBM PowerVM VIOS \u2013 version 3.1<\/li>\n\t<li>IBM Process Mining \u2013 version 1.12.0.4<\/li>\n\t<li>IBM Rational ClearCase \u2013 multiple versions<\/li>\n\t<li>IBM Rational Quality Manager \u2013 versions 6.0.6 and 6.0.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-429","alert_type":396,"serial_number":"AV22-429","subject":null,"moderation_state":"published","external_url":null},{"nid":3438,"title":"Android security advisory \u2013 August 2022 monthly rollup (AV22-430)","uuid":"e95c28a8-802d-4903-b44c-05d4e099f5ff","banner":null,"lang":"en","date_modified":"2022-08-02","date_modified_ts":"2022-08-02T19:01:05Z","date_created":"2022-08-02T19:01:05Z","summary":null,"body":["<article data-history-node-id=\"3438\" about=\"\/en\/alerts-advisories\/android-security-advisory-august-2022-monthly-rollup-av22-430\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-430<\/strong><br \/><strong>Date: 2 August 2022<\/strong><\/p>\n\n<p>On 2 August 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/security\/bulletin\/2022-08-01\" ref=\"external\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-august-2022-monthly-rollup-av22-430","alert_type":396,"serial_number":"AV22-430","subject":null,"moderation_state":"published","external_url":null},{"nid":3440,"title":"Google Chrome security advisory (AV22-431)","uuid":"2b818c38-a544-4b11-aa7c-898bfec25ce2","banner":null,"lang":"en","date_modified":"2022-08-03","date_modified_ts":"2022-08-03T18:35:03Z","date_created":"2022-08-03T18:35:03Z","summary":null,"body":["<article data-history-node-id=\"3440\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-431\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-431<\/strong><br \/><strong>Date: 3 August 2022<\/strong><\/p>\n\n<p>On 2 August 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 104.0.5112.79\/80\/81<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/08\/stable-channel-update-for-desktop.html\" rel=\"external\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-431","alert_type":396,"serial_number":"AV22-431","subject":null,"moderation_state":"published","external_url":null},{"nid":3441,"title":"Ubuntu security advisory (AV22-432)","uuid":"a512944e-2c10-46ca-99f1-e2acc2bd2d82","banner":null,"lang":"en","date_modified":"2022-08-03","date_modified_ts":"2022-08-03T18:42:23Z","date_created":"2022-08-03T18:42:23Z","summary":null,"body":["<article data-history-node-id=\"3441\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-432\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-432<\/strong><br \/><strong>Date: 3 August 2022<\/strong><\/p>\n\n<p>On 2 August 2022 Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the following web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5544-1\" rel=\"external\">Ubuntu Security Notice (USN-5544-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5545-1\" rel=\"external\">Ubuntu Security Notice (USN-5545-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices \" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-432","alert_type":396,"serial_number":"AV22-432","subject":null,"moderation_state":"published","external_url":null},{"nid":3442,"title":"F5 security advisory (AV22-433)","uuid":"273c9ab5-c6a0-4f2b-bb3a-f2fca7097827","banner":null,"lang":"en","date_modified":"2022-08-03","date_modified_ts":"2022-08-03T20:01:17Z","date_created":"2022-08-03T20:01:17Z","summary":null,"body":["<article data-history-node-id=\"3442\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-433\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-433<\/strong><br \/><strong>Date: 3 August 2022<\/strong><\/p>\n\n<p>On 3 August 2022 F5 published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K14649763\" rel=\"external\">F5 Security Advisory (K14649763)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-433","alert_type":396,"serial_number":"AV22-433","subject":null,"moderation_state":"published","external_url":null},{"nid":3443,"title":"Cisco security advisory (AV22-434)","uuid":"a31db952-b87a-4eb3-ab67-ce62cadf7fc1","banner":null,"lang":"en","date_modified":"2022-08-03","date_modified_ts":"2022-08-03T20:10:12Z","date_created":"2022-08-03T20:10:12Z","summary":null,"body":["<article data-history-node-id=\"3443\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-434\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-434<\/strong><br \/><strong>Date: 3 August 2022<\/strong><\/p>\n\n<p>On 3 August 2022 Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Small Business RV Series Routers \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution or cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sb-mult-vuln-CbVp4SUR\" rel=\"external\">Cisco Security Advisory (cisco-sa-sb-mult-vuln-CbVp4SUR)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\" rel=\"external\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-434","alert_type":396,"serial_number":"AV22-434","subject":null,"moderation_state":"published","external_url":null},{"nid":3445,"title":"[Control systems] Digi International security advisory (AV22-435)","uuid":"8a7ff4e2-e826-46ea-8779-44666cd73eef","banner":null,"lang":"en","date_modified":"2022-08-04","date_modified_ts":"2022-08-04T21:11:34Z","date_created":"2022-08-04T21:11:34Z","summary":null,"body":["<article data-history-node-id=\"3445\" about=\"\/en\/alerts-advisories\/control-systems-digi-international-security-advisory-av22-435\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-435<\/strong><br \/><strong>Date: 4 August 2022<\/strong><\/p>\n\n<p>On 4 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Digi ConnectPort X2D Gateway \u2013 all firmware versions manufactured prior to January 2020<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-216-01\" rel=\"external\">ICS Advisory (ICSA-22-216-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-digi-international-security-advisory-av22-435","alert_type":398,"serial_number":"AV22-435","subject":null,"moderation_state":"published","external_url":null},{"nid":3447,"title":"IBM security advisory (AV22-438)","uuid":"6abc86fd-c256-49a6-9c78-75fc10260f8a","banner":null,"lang":"en","date_modified":"2022-08-08","date_modified_ts":"2022-08-08T19:06:39Z","date_created":"2022-08-08T18:26:53Z","summary":null,"body":["<article data-history-node-id=\"3447\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-438\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-438<\/strong><br \/><strong>Date: 8 August 2022<\/strong><\/p>\n\n<p>Between 1 and 7 August 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM DRM \u2013 version 2.0.6.13<\/li>\n\t<li>IBM Sterling B2B Integrator \u2013 version 6.0.0.0 to 6.0.3.6, 6.1.0.0 to 6.1.0.5 and 6.1.1.1<\/li>\n\t<li>IBM Sterling File Gateway \u2013 version 6.0.0.0 to 6.0.3.6, 6.1.0.0 to 6.1.0.5 and 6.1.1.1<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data \u2013 version 4.0.0 to 4.5.0<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data \u2013 version v4.5<\/li>\n\t<li>IBM Db2 On Openshift \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-438","alert_type":396,"serial_number":"AV22-438","subject":null,"moderation_state":"published","external_url":null},{"nid":3446,"title":"Dell security advisory (AV22-436)","uuid":"73d24574-aaeb-4beb-90ce-1c7ef2559e73","banner":null,"lang":"en","date_modified":"2022-08-08","date_modified_ts":"2022-08-08T18:31:39Z","date_created":"2022-08-08T18:31:39Z","summary":null,"body":["<article data-history-node-id=\"3446\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-436\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-436<\/strong><br \/><strong>Date: 8 August 2022<\/strong><\/p>\n\n<p>Between 1 and 7 August 2022, Dell published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cyber Recovery \u2013 versions prior to 19.11.0.2<\/li>\n\t<li>Data Computing Appliance (DCA) \u2013 versions prior to 4.3.1.0 and Firmware tool 3I00<\/li>\n\t<li>Dell CloudLink \u2013 versions prior to 7.1.4<\/li>\n\t<li>Dell VPLEX \u2013 versions prior to BIOS 2.8.3, iDRAC9 5.10.10.00 and NIC 22.00.6<\/li>\n\t<li>Dell VPLEX VS2 and VS6 \u2013 versions prior to 6.2.0.07<\/li>\n\t<li>RecoverPoint Classic \u2013 versions 5.1.0, 5.1 SP4, 5.1 SP4 P1 and 5.1 SP4 P2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-us\" rel=\"external\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-436","alert_type":396,"serial_number":"AV22-436","subject":null,"moderation_state":"published","external_url":null},{"nid":3448,"title":"Microsoft Edge security advisory (AV22-437)","uuid":"3994d926-5a96-480a-a0bb-8ce71ce4cd23","banner":null,"lang":"en","date_modified":"2022-08-08","date_modified_ts":"2022-08-08T19:01:47Z","date_created":"2022-08-08T19:01:47Z","summary":null,"body":["<article data-history-node-id=\"3448\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-437\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-437<\/strong><br \/><strong>Date: 8 August 2022<\/strong><\/p>\n\n<p>On 5 August 2022 Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 104.0.1293.47<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-5-2022\" rel=\"external\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-437","alert_type":396,"serial_number":"AV22-437","subject":null,"moderation_state":"published","external_url":null},{"nid":3449,"title":"SAP security advisory \u2013 August 2022 monthly rollup (AV22-439)","uuid":"2b53d3c2-a701-4183-a914-1801519ae50f","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T18:31:07Z","date_created":"2022-08-09T18:31:07Z","summary":null,"body":["<article data-history-node-id=\"3449\" about=\"\/en\/alerts-advisories\/sap-security-advisory-august-2022-monthly-rollup-av22-439\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-439<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, SAP published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>SAP Business Client \u2013 versions 6.5, 7.0 and 7.70<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\" rel=\"external\">SAP Security Patch Day \u2013 August 2022 (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-august-2022-monthly-rollup-av22-439","alert_type":396,"serial_number":"AV22-439","subject":null,"moderation_state":"published","external_url":null},{"nid":3450,"title":"[Control systems] Emerson security advisory (AV22-442)","uuid":"663f3f1d-cd1a-41e2-becc-51bf7af5ae8d","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T18:47:35Z","date_created":"2022-08-09T18:47:35Z","summary":null,"body":["<article data-history-node-id=\"3450\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-442\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-442<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ControlWave \u2013 all versions<\/li>\n\t<li>OpenBSI \u2013 version 5.9 SP3 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-221-02\" rel=\"external\">ICS Advisory (ICSA-22-221-02)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-221-03\" rel=\"external\">ICS Advisory (ICSA-22-221-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-442","alert_type":398,"serial_number":"AV22-442","subject":null,"moderation_state":"published","external_url":null},{"nid":3451,"title":"Intel security advisory (AV22-443)","uuid":"72d635ca-e5fc-4a1f-97c4-02f92f4c3fbe","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T18:56:59Z","date_created":"2022-08-09T18:56:59Z","summary":null,"body":["<article data-history-node-id=\"3451\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av22-443\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-443<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, Intel published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Intel Data Center Manager \u2013 versions prior to 4.1<\/li>\n\t<li>Open AMT Cloud Toolkit \u2013 versions prior to 2.0.2 and 2.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\" rel=\"external\">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av22-443","alert_type":396,"serial_number":"AV22-443","subject":null,"moderation_state":"published","external_url":null},{"nid":3453,"title":"Red Hat security advisory (AV22-440)","uuid":"1626d93c-045c-456c-8a18-3a2ce28904f3","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T18:35:32Z","date_created":"2022-08-09T19:05:24Z","summary":null,"body":["<article data-history-node-id=\"3453\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-440\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-440<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022 Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Workstation 7 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories\" rel=\"external\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-440","alert_type":396,"serial_number":"AV22-440","subject":null,"moderation_state":"published","external_url":null},{"nid":3452,"title":"[Control systems] Schneider Electric security advisory (AV22-444) ","uuid":"a52be2cb-7a71-4be6-976f-10a27ff4a4fa","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T19:07:43Z","date_created":"2022-08-09T19:07:43Z","summary":null,"body":["<article data-history-node-id=\"3452\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-444\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-444<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>EcoStruxure Control Expert \u2013 multiple versions and platforms<\/li>\n\t<li>EcoStruxure Process Expert \u2013 multiple versions and platforms<\/li>\n\t<li>Legacy Modicon Quantum\/Premium \u2013 all versions<\/li>\n\t<li>Modicon M340 CPU \u2013 version V3.40 and prior<\/li>\n\t<li>Modicon M580 CPU \u2013 version V3.22 and prior<\/li>\n\t<li>Modicon MC80 (BMKC80) \u2013 all versions<\/li>\n\t<li>Modicon Momentum MDI (171CBU) \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\" rel=\"external\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-444","alert_type":398,"serial_number":"AV22-444","subject":null,"moderation_state":"published","external_url":null},{"nid":3454,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-441)","uuid":"0398afe7-23c6-43f4-8b85-42e8e71391d4","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T18:37:53Z","date_created":"2022-08-09T19:13:32Z","summary":null,"body":["<article data-history-node-id=\"3454\" about=\"\/en\/alerts-advisories\/mitsubishi-electric-security-advisory-av22-441\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-441 <\/strong><br \/><strong>Date: 9 August 2022 <\/strong><\/p>\n\n<p>On 9 August 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>GT SoftGOT2000 \u2013 version 1.275M<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-221-01\" rel=\"external\">ICS Advisory (ICSA-22-221-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitsubishi-electric-security-advisory-av22-441","alert_type":398,"serial_number":"AV22-441","subject":null,"moderation_state":"published","external_url":null},{"nid":3455,"title":"Adobe security advisory (AV22-446)","uuid":"70c6617d-ca78-4888-a285-972f52bf6361","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T19:29:04Z","date_created":"2022-08-09T19:24:55Z","summary":null,"body":["<article data-history-node-id=\"3455\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-446\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-446<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022 Adobe published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat and Acrobat Reader \u2013 multiple versions and platforms<\/li>\n\t<li>Adobe Commerce \u2013 multiple versions<\/li>\n\t<li>Adobe Framemaker \u2013 2019 Release Update 8 and prior<\/li>\n\t<li>Adobe Framemaker \u2013 2020 Release Update 4 and prior<\/li>\n\t<li>Adobe Premiere Elements \u2013 2022 (version 20.0)<\/li>\n\t<li>Illustrator 2022 \u2013 version 26.3.1 and prior<\/li>\n\t<li>Illustrator 2021 \u2013 version 25.4.6 and prior<\/li>\n\t<li>Magneto Open Source \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\" rel=\"external\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-446","alert_type":396,"serial_number":"AV22-446","subject":null,"moderation_state":"published","external_url":null},{"nid":3457,"title":"Citrix security advisory (AV22-447)","uuid":"0a82daa8-973b-4d49-9ef4-35931bf06da4","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T19:36:26Z","date_created":"2022-08-09T19:34:08Z","summary":null,"body":["<article data-history-node-id=\"3457\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-447\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-447<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, Citrix published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Citrix Hypervisor 7.1 LTSR CU2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX463455\" rel=\"external\">Citrix Security Bulletin (CTX463455)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-447","alert_type":396,"serial_number":"AV22-447","subject":null,"moderation_state":"published","external_url":null},{"nid":3456,"title":"[Control systems] Siemens security advisory (AV22-445) ","uuid":"b2c4a400-4bd3-41da-89c4-566f536d8b9f","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T19:15:10Z","date_created":"2022-08-09T19:35:21Z","summary":null,"body":["<article data-history-node-id=\"3456\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-445\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-445<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SCALANCE M-800 \/ S615 \u2013 all versions<\/li>\n\t<li>SCALANCE SC-600 family \u2013 versions prior to V2.3.1<\/li>\n\t<li>SCALANCE W-700 IEEE 802.11ax family \u2013 all versions<\/li>\n\t<li>SCALANCE W-700 IEEE 802.11n family \u2013 all versions<\/li>\n\t<li>SCALANCE W-1700 IEEE 802.11ac family \u2013 all versions<\/li>\n\t<li>SCALANCE XB-200 switch family \u2013 all versions<\/li>\n\t<li>SCALANCE XC-200 switch family \u2013 all versions<\/li>\n\t<li>SCALANCE XF-200BA switch family \u2013 all versions<\/li>\n\t<li>SCALANCE XM-400 family \u2013 all versions<\/li>\n\t<li>SCALANCE XP-200 switch family \u2013 all versions<\/li>\n\t<li>SCALANCE XR-300WG switch family \u2013 all versions<\/li>\n\t<li>SCALANCE XR-500 family \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\" rel=\"external\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-445","alert_type":398,"serial_number":"AV22-445","subject":null,"moderation_state":"published","external_url":null},{"nid":3458,"title":"Microsoft security advisory \u2013 August 2022 monthly rollup (AV22-448)","uuid":"a788d024-57d1-4073-899a-5c6b07c4d31f","banner":null,"lang":"en","date_modified":"2022-08-09","date_modified_ts":"2022-08-09T19:43:01Z","date_created":"2022-08-09T19:39:11Z","summary":null,"body":["<article data-history-node-id=\"3458\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2022-monthly-rollup-av22-448\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-448<\/strong><br \/><strong>Date: 9 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Azure Batch \u2013 versions prior to 1.9.27<\/li>\n\t<li>Microsoft Exchange Server \u2013 multiple versions<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows 10 \u2013 multiple versions<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions<\/li>\n\t<li>Windows 7<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2022-34713 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Aug\" rel=\"external\">August 2022 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\" rel=\"external\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2022-monthly-rollup-av22-448","alert_type":396,"serial_number":"AV22-448","subject":null,"moderation_state":"published","external_url":null},{"nid":3459,"title":"HPE security advisory (AV22-449)","uuid":"bdf22847-285d-4843-ba7b-03d34e89d3e3","banner":null,"lang":"en","date_modified":"2022-08-10","date_modified_ts":"2022-08-10T20:39:56Z","date_created":"2022-08-10T20:39:56Z","summary":null,"body":["<article data-history-node-id=\"3459\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-449\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-449<\/strong><br \/><strong>Date: 10 August 2022<\/strong><\/p>\n\n<p>On 9 August 2022, HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant \u2013 multiple versions and platforms<\/li>\n\t<li>HPE Synergy 480 Gen10 Plus Compute Module \u2013 versions prior to 1.62_07-14-2022<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary\" rel=\"external\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-449","alert_type":396,"serial_number":"AV22-449","subject":null,"moderation_state":"published","external_url":null},{"nid":3461,"title":"Ubuntu security advisory (AV22-450)","uuid":"91d6c949-4e23-490e-ae4d-6f5ae0d2ee56","banner":null,"lang":"en","date_modified":"2022-08-11","date_modified_ts":"2022-08-11T17:28:00Z","date_created":"2022-08-11T17:22:58Z","summary":null,"body":["<article data-history-node-id=\"3461\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-450\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-450<\/strong><br \/><strong>Date: 10 August 2022<\/strong><\/p>\n\n<p>On 10 August 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-450","alert_type":396,"serial_number":"AV22-450","subject":null,"moderation_state":"published","external_url":null},{"nid":3462,"title":"[Control systems] Emerson security advisory (AV22-451)","uuid":"f02271d5-869a-49e9-9085-e9d4506b1d74","banner":null,"lang":"en","date_modified":"2022-08-11","date_modified_ts":"2022-08-11T17:50:02Z","date_created":"2022-08-11T17:47:44Z","summary":null,"body":["<article data-history-node-id=\"3462\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-451\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-451<\/strong><br \/><strong>Date: 11 August 2022<\/strong><\/p>\n\n<p>On 11 August 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>ROC800 \u2013 all versions<\/li>\n\t<li>ROC800L \u2013 all versions<\/li>\n\t<li>DL8000 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-223-04\" rel=\"external\">ICS Advisory (ICSA-22-223-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-451","alert_type":398,"serial_number":"AV22-451","subject":null,"moderation_state":"published","external_url":null},{"nid":3463,"title":"Palo Alto Networks security advisory (AV22-452)","uuid":"a8fa92e4-ac78-4946-973c-4bfd75fa3c3f","banner":null,"lang":"en","date_modified":"2022-08-11","date_modified_ts":"2022-08-11T18:03:21Z","date_created":"2022-08-11T17:59:27Z","summary":null,"body":["<article data-history-node-id=\"3463\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-452\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-452<\/strong><br \/><strong>Date: 11 August 2022<\/strong><\/p>\n\n<p>On 10 August 2022, Palo Alto Networks published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>PAN-OS 10.2 - versions prior to 10.2.2-h2<\/li>\n\t<li>PAN-OS 10.1 - versions prior to 10.1.6-h6<\/li>\n\t<li>PAN-OS 10.0 - versions prior to 10.0.11-h1<\/li>\n\t<li>PAN-OS 9.1 - versions prior to 9.1.14-h4<\/li>\n\t<li>PAN-OS 9.0 - versions prior to 9.0.16-h3<\/li>\n\t<li>PAN-OS 8.1 - versions prior to 8.1.23-h1<\/li>\n<\/ul><p>Exploitation of this vulnerability could cause a reflected denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2022-0028\" rel=\"external\">Palo Alto Networks Security Advisory (CVE-2022-0028)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-452","alert_type":396,"serial_number":"AV22-452","subject":null,"moderation_state":"published","external_url":null},{"nid":3466,"title":"IBM security advisory (AV22-453)","uuid":"fd737dbe-20b8-4289-94ee-1508c2748a23","banner":null,"lang":"en","date_modified":"2022-08-15","date_modified_ts":"2022-08-15T15:41:47Z","date_created":"2022-08-15T15:27:34Z","summary":null,"body":["<article data-history-node-id=\"3466\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-453\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-453<\/strong><br \/><strong>Date: 15 August 2022<\/strong><\/p>\n\n<p>Between 8 and 14 August 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Automation Assets in IBM Cloud Pak for Integration (CP4I) \u2013 versions 2020.4.1, 2021.1.1, 2021.2.1 and 2021.4.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak System \u2013 multiple versions<\/li>\n\t<li>IBM MQ Operator \u2013 EUS release 1.3.5 and LTS Release 2.0.0<\/li>\n\t<li>IBM Sterling Connect:Direct File Agent \u2013 version 1.4.0.0 to 1.4.0.2_iFix026<\/li>\n\t<li>IBM supplied MQ Advanced container images \u2013 version v9.2.0.5-r3 and v9.3.0.0-r1<\/li>\n\t<li>InfoSphere Master Data Management \u2013 version 11.6 and 12.0<\/li>\n\t<li>ISIM VA \u2013 version 7.0.1 and 7.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-453","alert_type":396,"serial_number":"AV22-453","subject":null,"moderation_state":"published","external_url":null},{"nid":3467,"title":"Dell security advisory (AV22-454)","uuid":"e7de983c-fc4c-48cb-bd7a-a4fe29136b6f","banner":null,"lang":"en","date_modified":"2022-08-15","date_modified_ts":"2022-08-15T15:53:55Z","date_created":"2022-08-15T15:53:55Z","summary":null,"body":["<article data-history-node-id=\"3467\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-454\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-454<\/strong><br \/><strong>Date: 15 August 2022<\/strong><\/p>\n\n<p>Between 8 and 14 August 2022, Dell published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Enterprise Hybrid Cloud \u2013 versions prior to 4.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-us\" rel=\"external\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-454","alert_type":396,"serial_number":"AV22-454","subject":null,"moderation_state":"published","external_url":null},{"nid":3468,"title":"[Control systems] B&R Industrial Automation security advisory (AV22-455)","uuid":"dff8b79f-319d-4e9e-a327-92e36bfcba36","banner":null,"lang":"en","date_modified":"2022-08-16","date_modified_ts":"2022-08-16T18:02:27Z","date_created":"2022-08-16T17:57:40Z","summary":null,"body":["<article data-history-node-id=\"3468\" about=\"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-av22-455\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-455<\/strong><br \/><strong>Date: 16 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Automation Studio 4 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-228-05 \" rel=\"external\">ICS Advisory (ICSA-22-228-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-industrial-automation-security-advisory-av22-455","alert_type":398,"serial_number":"AV22-455","subject":null,"moderation_state":"published","external_url":null},{"nid":3469,"title":"[Control systems] Delta Electronics security advisory (AV22-456) ","uuid":"ab53f1e8-4f94-4630-9e18-2d5c70bc84bc","banner":null,"lang":"en","date_modified":"2022-08-16","date_modified_ts":"2022-08-16T18:09:50Z","date_created":"2022-08-16T18:04:37Z","summary":null,"body":["<article data-history-node-id=\"3469\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-456\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-456<\/strong><br \/><strong>Date: 16 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Delta Robot Automation Studio (DRAS) \u2013 versions prior to 1.13.20<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-228-03\" rel=\"external\">ICS Advisory (ICSA-22-228-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-456","alert_type":398,"serial_number":"AV22-456","subject":null,"moderation_state":"published","external_url":null},{"nid":3470,"title":"[Control systems] Emerson security advisory (AV22-457)","uuid":"19ccda22-8da6-4c77-8a43-04e374829593","banner":null,"lang":"en","date_modified":"2022-08-16","date_modified_ts":"2022-08-16T18:17:39Z","date_created":"2022-08-16T18:13:09Z","summary":null,"body":["<article data-history-node-id=\"3470\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-457\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-457<\/strong><br \/><strong>Date: 16 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Proficy Machine Edition \u2013 version 9.80 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution or the upload of arbitrary files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-228-06\" rel=\"external\">ICS Advisory (ICSA-22-228-06)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av22-457","alert_type":398,"serial_number":"AV22-457","subject":null,"moderation_state":"published","external_url":null},{"nid":3471,"title":"[Control systems] LS Electric, LS Industrial Systems security advisory (AV22-458)","uuid":"4553f1a4-6fb5-45ab-89c0-d855d01cd740","banner":null,"lang":"en","date_modified":"2022-08-16","date_modified_ts":"2022-08-16T18:23:34Z","date_created":"2022-08-16T18:20:00Z","summary":null,"body":["<article data-history-node-id=\"3471\" about=\"\/en\/alerts-advisories\/control-systems-ls-electric-ls-industrial-systems-security-advisory-av22-458\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-458<\/strong><br \/><strong>Date: 16 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>LS Electric PLC \u2013 all versions<\/li>\n\t<li>XG5000 \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in credential exposure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-228-02\" rel=\"external\">ICS Advisory (ICSA-22-228-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ls-electric-ls-industrial-systems-security-advisory-av22-458","alert_type":398,"serial_number":"AV22-458","subject":null,"moderation_state":"published","external_url":null},{"nid":3472,"title":"[Control systems] Sequi security advisory (AV22-459)","uuid":"d5ddef28-0920-4741-9265-f7f17529d177","banner":null,"lang":"en","date_modified":"2022-08-16","date_modified_ts":"2022-08-16T18:31:01Z","date_created":"2022-08-16T18:26:25Z","summary":null,"body":["<article data-history-node-id=\"3472\" about=\"\/en\/alerts-advisories\/control-systems-sequi-security-advisory-av22-459\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-459<\/strong><br \/><strong>Date: 16 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Sequi PortBloque S \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in the modification of the device configuration.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-228-07\" rel=\"external\">ICS Advisory (ICSA-22-228-07)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sequi-security-advisory-av22-459","alert_type":398,"serial_number":"AV22-459","subject":null,"moderation_state":"published","external_url":null},{"nid":3473,"title":"[Control systems] Yokogawa security advisory (AV22-460)","uuid":"92b3fac0-2647-4909-a845-5b748d46ef93","banner":null,"lang":"en","date_modified":"2022-08-16","date_modified_ts":"2022-08-16T18:39:18Z","date_created":"2022-08-16T18:36:23Z","summary":null,"body":["<article data-history-node-id=\"3473\" about=\"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-460\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-460<\/strong><br \/><strong>Date: 16 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CENTUM VP\/CS 3000 Controller FCS \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-228-01\" rel=\"external\">ICS Advisory (ICSA-22-228-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-yokogawa-security-advisory-av22-460","alert_type":398,"serial_number":"AV22-460","subject":null,"moderation_state":"published","external_url":null},{"nid":3474,"title":"[Control systems] Softing security advisory (AV22-461)","uuid":"3f2adc6d-0c8c-4cc7-902d-774dc78d6253","banner":null,"lang":"en","date_modified":"2022-08-16","date_modified_ts":"2022-08-16T18:48:12Z","date_created":"2022-08-16T18:42:03Z","summary":null,"body":["<article data-history-node-id=\"3474\" about=\"\/en\/alerts-advisories\/control-systems-softing-security-advisory-av22-461\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-461<\/strong><br \/><strong>Date: 16 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Secure Integration Server \u2013 version 1.22<\/li>\n\t<li>edgeConnector \u2013 version 3.1<\/li>\n\t<li>edgeAggregator \u2013 version 3.1<\/li>\n\t<li>OPC UA C++ Server SDK \u2013 version 6<\/li>\n\t<li>OPC Suite \u2013 version 5.2<\/li>\n\t<li>uaGate \u2013 version 1.74<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-228-04\" rel=\"external\">ICS Advisory (ICSA-22-228-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-softing-security-advisory-av22-461","alert_type":398,"serial_number":"AV22-461","subject":null,"moderation_state":"published","external_url":null},{"nid":3476,"title":"Google Chrome security advisory (AV22-462)","uuid":"45eb8049-af6a-44ce-ad3e-3e76e04bcc83","banner":null,"lang":"en","date_modified":"2022-08-17","date_modified_ts":"2022-08-17T15:53:44Z","date_created":"2022-08-17T15:50:00Z","summary":null,"body":["<article data-history-node-id=\"3476\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-462\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-462<\/strong><br \/><strong>Date: 17 August 2022<\/strong><\/p>\n\n<p>On 16 August 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 104.0.5112.102\/101<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/08\/stable-channel-update-for-desktop.html\" rel=\"external\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-462","alert_type":396,"serial_number":"AV22-462","subject":null,"moderation_state":"published","external_url":null},{"nid":3478,"title":"Apple security advisory (AV22-463)","uuid":"98672c14-b6dd-4143-9f5b-ebbf1926c46e","banner":null,"lang":"en","date_modified":"2022-08-17","date_modified_ts":"2022-08-17T19:01:33Z","date_created":"2022-08-17T18:53:17Z","summary":null,"body":["<article data-history-node-id=\"3478\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-463\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-463<\/strong>\n  <br \/><strong>Date: 18 August 2022<\/strong>\n<\/p>\n<p>On 17 and 18 August 2022 Apple published Security Updates to address vulnerabilities in the following products:\n<\/p>\n<ul><li>iOS and iPadOS \u2013 versions prior to 15.6.1<\/li>\n  <li>macOS Monterey \u2013 versions prior to 12.5.1<\/li>\n  <li>Safari \u2013 versions prior to 15.6.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.\n<\/p>\n<p>Apple has received reports that some of these vulnerabilities have been actively exploited.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" rel=\"external\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-463","alert_type":396,"serial_number":"AV22-463","subject":null,"moderation_state":"published","external_url":null},{"nid":3481,"title":"IBM security advisory (AV22-464)","uuid":"0f5f5295-098a-4ddd-82d7-e6c092fbb130","banner":null,"lang":"en","date_modified":"2022-08-22","date_modified_ts":"2022-08-22T18:33:06Z","date_created":"2022-08-22T18:27:20Z","summary":null,"body":["<article data-history-node-id=\"3481\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-464\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-464<\/strong><br \/><strong>Date: 22 August 2022<\/strong><\/p>\n\n<p>Between 15 and 21 August 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Spectrum Discover \u2013 multiple versions<\/li>\n\t<li>IBM DataPower Gateway \u2013 multiple versions<\/li>\n\t<li>IBM Sterling Connect:Direct for Microsoft Windows \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak System \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak System Software Suite \u2013 version 2.3.3.0<\/li>\n\t<li>IBM SPSS Modeler \u2013 version 18.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-464","alert_type":396,"serial_number":"AV22-464","subject":null,"moderation_state":"published","external_url":null},{"nid":3482,"title":"Dell security advisory (AV22-465)","uuid":"a6feb17b-816e-41dd-82e6-c22830c369e5","banner":null,"lang":"en","date_modified":"2022-08-22","date_modified_ts":"2022-08-22T18:40:55Z","date_created":"2022-08-22T18:38:01Z","summary":null,"body":["<article data-history-node-id=\"3482\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-465\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-465<\/strong><br \/><strong>Date: 22 August 2022<\/strong><\/p>\n\n<p>Between 15 and 21 August 2022, Dell published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell PowerFlex Rack \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-us \">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-465","alert_type":396,"serial_number":"AV22-465","subject":null,"moderation_state":"published","external_url":null},{"nid":3483,"title":"Mozilla security advisory (AV22-466)","uuid":"a3077a1a-6753-4745-a23b-507513a9c5b1","banner":null,"lang":"en","date_modified":"2022-08-23","date_modified_ts":"2022-08-23T16:05:00Z","date_created":"2022-08-23T15:48:49Z","summary":null,"body":["<article data-history-node-id=\"3483\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-466\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-466<\/strong><br \/><strong>Date: 23 August 2022<\/strong><\/p>\n\n<p>On 23 August 2022 Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 104<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 91.13<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 102.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-33\/\">Mozilla Security Advisory (MFSA 2022-33)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-34\/\">Mozilla Security Advisory (MFSA 2022-34)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-35\/\">Mozilla Security Advisory (MFSA 2022-35)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-466","alert_type":396,"serial_number":"AV22-466","subject":null,"moderation_state":"published","external_url":null},{"nid":3484,"title":"[Control Systems] Delta Electronics security advisory (AV22-467)","uuid":"30f4ebb2-a147-4441-9732-61fe8115b96a","banner":null,"lang":"en","date_modified":"2022-08-23","date_modified_ts":"2022-08-23T19:52:40Z","date_created":"2022-08-23T19:48:03Z","summary":null,"body":["<article data-history-node-id=\"3484\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-467\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-467<\/strong><br \/><strong>Date: 23 August 2022<\/strong><\/p>\n\n<p>On 23 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Delta Industrial Automation DIALink \u2013 version 1.4.0.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-235-02\">ICS Advisory (ICSA-22-235-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-467","alert_type":398,"serial_number":"AV22-467","subject":null,"moderation_state":"published","external_url":null},{"nid":3485,"title":"[Control Systems] ARC Informatique security advisory (AV22-468)","uuid":"a646fc07-2ba9-45b7-8f59-ad326b3d3ad2","banner":null,"lang":"en","date_modified":"2022-08-23","date_modified_ts":"2022-08-23T20:00:50Z","date_created":"2022-08-23T19:57:05Z","summary":null,"body":["<article data-history-node-id=\"3485\" about=\"\/en\/alerts-advisories\/control-systems-arc-informatique-security-advisory-av22-468\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-468<\/strong><br \/><strong>Date: 23 August 2022<\/strong><\/p>\n\n<p>On 23 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>PcVue 12 OAuth web service configuration<\/li>\n\t<li>PcVue 15 OAuth web service configuration<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-235-01-0\">ICS Advisory (ICSA-22-235-01-0)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-arc-informatique-security-advisory-av22-468","alert_type":398,"serial_number":"AV22-468","subject":null,"moderation_state":"published","external_url":null},{"nid":3486,"title":"[Control Systems] mySCADA security advisory (AV22-469)","uuid":"f5b0947e-d488-4633-99d0-6ac5d5b97049","banner":null,"lang":"en","date_modified":"2022-08-23","date_modified_ts":"2022-08-23T20:15:13Z","date_created":"2022-08-23T20:11:12Z","summary":null,"body":["<article data-history-node-id=\"3486\" about=\"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-av22-469\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-469<\/strong><br \/><strong>Date: 23 August 2022<\/strong><\/p>\n\n<p>On 23 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>myPRO \u2013 versions 8.26.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-235-03\">ICS Advisory (ICSA-22-235-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-av22-469","alert_type":398,"serial_number":"AV22-469","subject":null,"moderation_state":"published","external_url":null},{"nid":3487,"title":"[Control systems] Hitachi Energy security advisory (AV22-470)","uuid":"a63b8a72-6caf-47c2-b843-f1199a7635df","banner":null,"lang":"en","date_modified":"2022-08-23","date_modified_ts":"2022-08-23T20:22:08Z","date_created":"2022-08-23T20:17:14Z","summary":null,"body":["<article data-history-node-id=\"3487\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-470\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-470<\/strong><br \/><strong>Date: 23 August 2022<\/strong><\/p>\n\n<p>On 23 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>RTU500 series CMU Firmware \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-235-07\">ICS Advisory (ICSA-22-235-07)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-470","alert_type":398,"serial_number":"AV22-470","subject":null,"moderation_state":"published","external_url":null},{"nid":3488,"title":"[Control systems] Measuresoft security advisory (AV22-471)","uuid":"6f9bd18e-2315-46f8-b05b-681ca9dd5afb","banner":null,"lang":"en","date_modified":"2022-08-23","date_modified_ts":"2022-08-23T20:29:29Z","date_created":"2022-08-23T20:24:14Z","summary":null,"body":["<article data-history-node-id=\"3488\" about=\"\/en\/alerts-advisories\/control-systems-measuresoft-security-advisory-av22-471\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-471<\/strong><br \/><strong>Date: 23 August 2022<\/strong><\/p>\n\n<p>On 23 August 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ScadaPro Server Client \u2013 all versions<\/li>\n\t<li>ScadaPro Server \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution, privilege escalation or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-235-05\">ICS Advisory (ICSA-22-235-05)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-235-06\">ICS Advisory (ICSA-22-235-06)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-measuresoft-security-advisory-av22-471","alert_type":398,"serial_number":"AV22-471","subject":null,"moderation_state":"published","external_url":null},{"nid":3489,"title":"Ubuntu security advisory (AV22-472)","uuid":"8af079ed-c51b-4a06-9210-161f73497563","banner":null,"lang":"en","date_modified":"2022-08-24","date_modified_ts":"2022-08-24T19:29:15Z","date_created":"2022-08-24T19:23:49Z","summary":null,"body":["<article data-history-node-id=\"3489\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-472\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-472<\/strong><br \/><strong>Date: 24 August 2022<\/strong><\/p>\n\n<p>On 24 August 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5577-1\">Ubuntu Security Notice (USN-5577-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5579-1\">Ubuntu Security Notice (USN-5579-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5580-1\">Ubuntu Security Notice (USN-5580-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-472","alert_type":396,"serial_number":"AV22-472","subject":null,"moderation_state":"published","external_url":null},{"nid":3490,"title":"Cisco security advisory (AV22-473)","uuid":"0cb5db3e-6d92-4a89-a1a8-41833844516d","banner":null,"lang":"en","date_modified":"2022-08-24","date_modified_ts":"2022-08-24T19:39:33Z","date_created":"2022-08-24T19:33:48Z","summary":null,"body":["<article data-history-node-id=\"3490\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-473\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-473<\/strong><br \/><strong>Date: 24 August 2022<\/strong><\/p>\n\n<p>On 24 August 2022, Cisco published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco ACI MSO \u2013 versions 3.1 and prior<\/li>\n\t<li>Cisco FXOS Software \u2013 multiple versions and platforms<\/li>\n\t<li>Cisco NXOS Software \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-473","alert_type":396,"serial_number":"AV22-473","subject":null,"moderation_state":"published","external_url":null},{"nid":3491,"title":"GitLab security advisory (AV22-474)","uuid":"bf1b12d5-6197-4974-8d0a-cd07eb13e183","banner":null,"lang":"en","date_modified":"2022-08-25","date_modified_ts":"2022-08-25T11:43:44Z","date_created":"2022-08-25T11:38:47Z","summary":null,"body":["<article data-history-node-id=\"3491\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av22-474\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-474<\/strong><br \/><strong>Date: 24 August 2022<\/strong><\/p>\n\n<p>On 22 August 2022, GitLab published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition \u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2022\/08\/22\/critical-security-release-gitlab-15-3-1-released\/\">GitLab Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av22-474","alert_type":396,"serial_number":"AV22-474","subject":null,"moderation_state":"published","external_url":null},{"nid":3492,"title":"[Control systems] FATEK Automation security advisory (AV22-475)","uuid":"da212959-88ad-4c87-8929-355c774636ae","banner":null,"lang":"en","date_modified":"2022-08-25","date_modified_ts":"2022-08-25T19:01:04Z","date_created":"2022-08-25T18:58:10Z","summary":null,"body":["<article data-history-node-id=\"3492\" about=\"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-av22-475\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-475<\/strong><br \/><strong>Date: 25 August 2022<\/strong><\/p>\n\n<p>On 25 August 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>FvDesigner - version 1.5.103 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-237-01 \">ICS Advisory (ICSA-22-237-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fatek-automation-security-advisory-av22-475","alert_type":398,"serial_number":"AV22-475","subject":null,"moderation_state":"published","external_url":null},{"nid":3493,"title":"Ubuntu security advisory (AV22-476)","uuid":"ed98697b-dc75-4d05-9459-1a62e04a42be","banner":null,"lang":"en","date_modified":"2022-08-25","date_modified_ts":"2022-08-25T19:41:44Z","date_created":"2022-08-25T19:37:10Z","summary":null,"body":["<article data-history-node-id=\"3493\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-476\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-476<\/strong><br \/><strong>Date: 25 August 2022<\/strong><\/p>\n\n<p>On 25 August 2022, Ubuntu published a Security Notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5582-1\" rel=\"external\">Ubuntu Security Notice (USN-5582-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-476","alert_type":396,"serial_number":"AV22-476","subject":null,"moderation_state":"published","external_url":null},{"nid":3494,"title":"[Control systems] ABB Security advisory (AV22-477)","uuid":"03276164-5d4c-442d-8d1a-a106e5a27d35","banner":null,"lang":"en","date_modified":"2022-08-26","date_modified_ts":"2022-08-26T18:19:41Z","date_created":"2022-08-26T18:16:33Z","summary":null,"body":["<article data-history-node-id=\"3494\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-477\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-477<\/strong><br \/><strong>Date: <\/strong><strong>26 August 2022<\/strong><\/p>\n\n<p>On 25 August 2022, ABB published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ARM600 M2M Gateway ARM600C2500NA \u2013 UEFI version prior to 2.5.1<\/li>\n\t<li>ARM600 M2M Gateway ARM600C2505NA \u2013 UEFI version prior to 2.5.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001477\">ABB Security Advisory (2NGA001477) (PDF)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-477","alert_type":398,"serial_number":"AV22-477","subject":null,"moderation_state":"published","external_url":null},{"nid":3495,"title":"F5 security advisory (AV22-478)","uuid":"ccf29fbb-a4e7-40b4-8519-43be79a61d38","banner":null,"lang":"en","date_modified":"2022-08-26","date_modified_ts":"2022-08-26T18:28:01Z","date_created":"2022-08-26T18:26:52Z","summary":null,"body":["<article data-history-node-id=\"3495\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-478\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-478<\/strong><br \/><strong>Date: <\/strong><strong>26 August 2022<\/strong><\/p>\n\n<p>On 25 August 2022, F5 published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Traffix SDC \u2013 version 5.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link.<\/p>\n\n<p><a href=\"https:\/\/support.f5.com\/csp\/article\/K42795243\">F5 Security Advisory (K42795243)<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-478","alert_type":396,"serial_number":"AV22-478","subject":null,"moderation_state":"published","external_url":null},{"nid":3496,"title":"Atlassian security advisory (AV22-479)","uuid":"31f64b0d-f094-4733-9fe3-2beec1931c35","banner":null,"lang":"en","date_modified":"2022-08-26","date_modified_ts":"2022-08-26T18:38:30Z","date_created":"2022-08-26T18:35:23Z","summary":null,"body":["<article data-history-node-id=\"3496\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av22-479\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-479<\/strong><br \/><strong>Date: <\/strong><strong>26 August 2022<\/strong><\/p>\n\n<p>On 24 August 2022, Atlassian published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Bitbucket Server \u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow arbitrary code execution.<\/p>\n\n<p>\u00a0The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-server-and-data-center-advisory-2022-08-24-1155489835.html\">Atlassian Security Advisory (BSERV-13438)<\/a><\/p>\n\n<p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av22-479","alert_type":396,"serial_number":"AV22-479","subject":null,"moderation_state":"published","external_url":null},{"nid":3497,"title":"IBM security advisory (AV22-480)","uuid":"e9e6f52d-fb4f-4db0-a2cf-287c3fff2046","banner":null,"lang":"en","date_modified":"2022-08-29","date_modified_ts":"2022-08-29T15:55:29Z","date_created":"2022-08-29T15:54:52Z","summary":null,"body":["<article data-history-node-id=\"3497\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-480\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-480<\/strong><br \/><strong>Date: 29 August 2022<\/strong><\/p>\n\n<p>Between 22 and 28 August 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Security Guardium Key Lifecycle Manager \u2013 version 4.1.1<\/li>\n\t<li>IBM QRadar SIEM \u2013 multiple versions<\/li>\n\t<li>IBM Spectrum Discover \u2013 versions 2.0.4.0 to 2.0.4.6<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak \u2013 versions 21.0.1, 21.0.2 and 21.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-480","alert_type":396,"serial_number":"AV22-480","subject":null,"moderation_state":"published","external_url":null},{"nid":3498,"title":"Dell security advisory (AV22-481)","uuid":"9a64d398-d586-4ac9-a833-a936e58de439","banner":null,"lang":"en","date_modified":"2022-08-29","date_modified_ts":"2022-08-29T16:02:22Z","date_created":"2022-08-29T15:58:44Z","summary":null,"body":["<article data-history-node-id=\"3498\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-481\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-481<\/strong><br \/><strong>Date: 29 August 2022<\/strong><\/p>\n\n<p>Between 22 and 28 August 2022, Dell published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell NetWorker vProxy \u2013 version 4.3.0-29 and prior<\/li>\n\t<li>Dell Avamar Server \u2013 versions 19.2 to 19.7<\/li>\n\t<li>Dell Avamar Virtual Edition \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-us \" rel=\"external\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-481","alert_type":396,"serial_number":"AV22-481","subject":null,"moderation_state":"published","external_url":null},{"nid":3500,"title":"[Control systems] Hitachi Energy security advisory (AV22-482)","uuid":"43efd0be-0dce-49fd-a50e-84e7062a1c1b","banner":null,"lang":"en","date_modified":"2022-08-30","date_modified_ts":"2022-08-30T19:39:10Z","date_created":"2022-08-30T19:38:28Z","summary":null,"body":["<article data-history-node-id=\"3500\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-482\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-482<\/strong><br \/><strong>Date: 30 August 2022<\/strong><\/p>\n\n<p>On 30 August 2022, ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>FACTS Control Platform (FCP) \u2013 multiple versions<\/li>\n\t<li>Modular Switchgear Monitoring (MSM) \u2013 version 2.2 and earlier<\/li>\n\t<li>Gateway Station (GWS) \u2013 multiple versions<\/li>\n\t<li>RTU500 series CMU Firmware \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access, information disclosure and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-01\" rel=\"external\">ICS Advisory (ICSA-22-242-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-02\" rel=\"external\">ICS Advisory (ICSA-22-242-02)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-03\" rel=\"external\">ICS Advisory (ICSA-22-242-03)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-04\" rel=\"external\">ICS Advisory (ICSA-22-242-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-482","alert_type":398,"serial_number":"AV22-482","subject":null,"moderation_state":"published","external_url":null},{"nid":3501,"title":"[Control systems] Fuji Electric security advisory (AV22-483)","uuid":"166a4630-3f44-4437-8b7b-6ee9ed075264","banner":null,"lang":"en","date_modified":"2022-08-30","date_modified_ts":"2022-08-30T19:44:52Z","date_created":"2022-08-30T19:44:18Z","summary":null,"body":["<article data-history-node-id=\"3501\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-483\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-483<\/strong><br \/><strong>Date: 30 August 2022<\/strong><\/p>\n\n<p>On 30 August 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>D300win \u2013 versions prior to 3.7.1.17<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could lead to information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-05\" rel=\"external\">ICS Advisory (ICSA-22-242-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-483","alert_type":398,"serial_number":"AV22-483","subject":null,"moderation_state":"published","external_url":null},{"nid":3502,"title":"[Control systems] Honeywell security advisory (AV22-484)","uuid":"bf76ad95-deae-4f2a-b6a3-40bbfc596a4f","banner":null,"lang":"en","date_modified":"2022-08-31","date_modified_ts":"2022-08-31T11:56:35Z","date_created":"2022-08-31T11:56:00Z","summary":null,"body":["<article data-history-node-id=\"3502\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av22-484\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-484<\/strong><br \/><strong>Date: 30 August 2022<\/strong><\/p>\n\n<p>On 30 August 2022 ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>ControlEdge \u2013 versions prior to 151.2<\/li>\n\t<li>IQ Series Controllers \u2013 all versions<\/li>\n\t<li>Experion LX \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution, information disclosure and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-06\" rel=\"external\">ICS Advisory (ICSA-22-242-06)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-07\" rel=\"external\">ICS Advisory (ICSA-22-242-07)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-08\" rel=\"external\">ICS Advisory (ICSA-22-242-08)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av22-484","alert_type":398,"serial_number":"AV22-484","subject":null,"moderation_state":"published","external_url":null},{"nid":3503,"title":"[Control systems] Omron security advisory (AV22-485)","uuid":"7fa27245-6757-4c64-afb5-eca4e9897e26","banner":null,"lang":"en","date_modified":"2022-08-31","date_modified_ts":"2022-08-31T12:02:32Z","date_created":"2022-08-31T11:59:24Z","summary":null,"body":["<article data-history-node-id=\"3503\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-485\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-485<\/strong><br \/><strong>Date: 30 August 2022<\/strong><\/p>\n\n<p>On 30 August 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Omron CX-Programmer \u2013 versions prior to v9.78<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-09\" rel=\"external\">ICS Advisory (ICSA-22-242-09)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-485","alert_type":398,"serial_number":"AV22-485","subject":null,"moderation_state":"published","external_url":null},{"nid":3504,"title":"[Control systems] PTC security advisory (AV22-486)","uuid":"3a65388f-bf8b-450c-8397-abf8de5870e1","banner":null,"lang":"en","date_modified":"2022-08-31","date_modified_ts":"2022-08-31T12:10:54Z","date_created":"2022-08-31T12:04:59Z","summary":null,"body":["<article data-history-node-id=\"3504\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av22-486\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-486<\/strong><br \/><strong>Date: 30 August 2022<\/strong><\/p>\n\n<p>On 30 August 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products<\/p>\n\n<ul><li>Kepware KEPServerEX \u2013 versions prior to 6.12<\/li>\n\t<li>ThingWorkx Kepware Server \u2013 versions prior to 6.12<\/li>\n\t<li>ThingWorkx Industrial Connectivity \u2013 all versions<\/li>\n\t<li>OPC-Aggregator \u2013 versions prior to 6.12<\/li>\n\t<li>ThingWorkx Kepware Edge \u2013 version 1.4 and prior<\/li>\n\t<li>Rockwell Automation KEPServer Enterprise \u2013 versions prior to v6.12<\/li>\n\t<li>GE Digital Industrial Gateway Server \u2013 versions prior to v7.612<\/li>\n\t<li>Software Toolbox TOP Server \u2013 versions prior to v6.12<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-242-10\" rel=\"external\">ICS Advisory (ICSA-22-242-10)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av22-486","alert_type":398,"serial_number":"AV22-486","subject":null,"moderation_state":"published","external_url":null},{"nid":3506,"title":"Ubuntu security advisory (AV22-487)","uuid":"e1bd081e-9b82-4ae0-a3c1-2cb1979015db","banner":null,"lang":"en","date_modified":"2022-08-31","date_modified_ts":"2022-08-31T19:11:28Z","date_created":"2022-08-31T19:08:03Z","summary":null,"body":["<article data-history-node-id=\"3506\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-487\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-487<\/strong><br \/><strong>Date: 31 August 2022<\/strong><\/p>\n\n<p>On 30 August 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-487","alert_type":396,"serial_number":"AV22-487","subject":null,"moderation_state":"published","external_url":null},{"nid":3507,"title":"Google Chrome security advisory (AV22-488)","uuid":"edcd3a39-0a86-415b-8a3c-61b8c7456b9c","banner":null,"lang":"en","date_modified":"2022-08-31","date_modified_ts":"2022-08-31T19:15:56Z","date_created":"2022-08-31T19:15:32Z","summary":null,"body":["<article data-history-node-id=\"3507\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-488\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-488<\/strong><br \/><strong>Date: 31 August 2022<\/strong><\/p>\n\n<p>On 30 August 2022 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 105.0.5195.52\/53\/54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/08\/stable-channel-update-for-desktop_30.html\" rel=\"external\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-488","alert_type":396,"serial_number":"AV22-488","subject":null,"moderation_state":"published","external_url":null},{"nid":3510,"title":"[Control systems] Delta Electronics security advisory (AV22-489)","uuid":"706f653e-b976-405b-b879-859175ab7083","banner":null,"lang":"en","date_modified":"2022-09-01","date_modified_ts":"2022-09-01T17:27:08Z","date_created":"2022-09-01T17:23:56Z","summary":null,"body":["<article data-history-node-id=\"3510\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-489\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-489<\/strong><br \/><strong>Date: 1 September 2022<\/strong><\/p>\n\n<p>On 1 September 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>DOPSoft \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-244-01\" rel=\"external\">ICS Advisory (ICSA-22-244-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-489","alert_type":398,"serial_number":"AV22-489","subject":null,"moderation_state":"published","external_url":null},{"nid":3513,"title":"Microsoft Edge security advisory (AV22-490)","uuid":"03ab148e-8714-4d48-bb77-b3a0156be276","banner":null,"lang":"en","date_modified":"2022-09-02","date_modified_ts":"2022-09-02T19:13:21Z","date_created":"2022-09-02T19:10:23Z","summary":null,"body":["<article data-history-node-id=\"3513\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-490\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-490<\/strong><br \/><strong>Date: 2 September 2022<\/strong><\/p>\n\n<p>On 1 September 2022, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 105.0.1343.25<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-1-2022\" rel=\"external\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-490","alert_type":396,"serial_number":"AV22-490","subject":null,"moderation_state":"published","external_url":null},{"nid":3515,"title":"[Control systems] Contec Health security advisory (AV22-491)","uuid":"67da9b93-fcef-4944-a14a-656fc8a438f2","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T19:33:56Z","date_created":"2022-09-06T19:17:29Z","summary":null,"body":["<article data-history-node-id=\"3515\" about=\"\/en\/alerts-advisories\/control-systems-contec-health-security-advisory-av22-491\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-491<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 1 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Contec Health CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsma-22-244-01\" rel=\"external\">ICS Advisory (ICSMA-22-244-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-contec-health-security-advisory-av22-491","alert_type":398,"serial_number":"AV22-491","subject":null,"moderation_state":"published","external_url":null},{"nid":3516,"title":"[Control systems] Hitachi Energy security advisory (AV22-492) ","uuid":"2bdf3805-2596-4263-8c52-042385ab8d3f","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T19:43:34Z","date_created":"2022-09-06T19:41:00Z","summary":null,"body":["<article data-history-node-id=\"3516\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-492\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-492<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 6 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>TXpert Hub CoreTec 4 \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-249-04 \" rel=\"external\">ICS Advisory (ICSA-22-249-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-492","alert_type":398,"serial_number":"AV22-492","subject":null,"moderation_state":"published","external_url":null},{"nid":3517,"title":"[Control systems] Cognex security advisory (AV22-493) ","uuid":"69fd2e37-6ced-4c83-9f6c-98608afcda0b","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T19:57:04Z","date_created":"2022-09-06T19:53:22Z","summary":null,"body":["<article data-history-node-id=\"3517\" about=\"\/en\/alerts-advisories\/control-systems-cognex-security-advisory-av22-493\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-493<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 6 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Cognex 3D-A1000 Dimensioning System \u2013 firmware version 1.0.3 (3354) and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in data modification and privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-249-03  \" rel=\"external\">ICS Advisory (ICSA-22-249-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cognex-security-advisory-av22-493","alert_type":398,"serial_number":"AV22-493","subject":null,"moderation_state":"published","external_url":null},{"nid":3518,"title":"[Control systems] AVEVA security advisory (AV22-494)","uuid":"4ecc51b7-e54f-4778-877b-25966bb9c742","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T20:06:51Z","date_created":"2022-09-06T20:05:24Z","summary":null,"body":["<article data-history-node-id=\"3518\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-494\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-494<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 6 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>AVEVA Edge \u2013 2020 R2 SP1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, denial of service, and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-249-02 \" rel=\"external\">ICS Advisory (ICSA-22-249-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-494","alert_type":398,"serial_number":"AV22-494","subject":null,"moderation_state":"published","external_url":null},{"nid":3519,"title":"[Control systems] Triangle Microworks security advisory (AV22-495) ","uuid":"0367352e-14e9-44a4-90e2-76a17b1e775b","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T20:16:46Z","date_created":"2022-09-06T20:15:54Z","summary":null,"body":["<article data-history-node-id=\"3519\" about=\"\/en\/alerts-advisories\/control-systems-triangle-microworks-security-advisory-av22-495\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-495<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 6 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>TMW Library: IEC 61850 \u2013 multiple versions<\/li>\n\t<li>TMW Library: IEC 60870-6 (ICCP\/Tase.2) \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-249-01\" rel=\"external\">ICS Advisory (ICSA-22-249-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-triangle-microworks-security-advisory-av22-495","alert_type":398,"serial_number":"AV22-495","subject":null,"moderation_state":"published","external_url":null},{"nid":3520,"title":"IBM security advisory (AV22-496)","uuid":"e44ca705-816e-4856-858e-727b9da67490","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T20:26:00Z","date_created":"2022-09-06T20:20:40Z","summary":null,"body":["<article data-history-node-id=\"3520\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-496\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-496<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>Between 29 August and 5 September 2022, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Business Automation Workflow containers \u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Workflow traditional \u2013 multiple versions<\/li>\n\t<li>IBM Business Process Manager \u2013 multiple versions<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.1.x and 11.2.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-496","alert_type":396,"serial_number":"AV22-496","subject":null,"moderation_state":"published","external_url":null},{"nid":3521,"title":"Dell security advisory (AV22-497)","uuid":"2ed942e8-5da6-46a7-b5c0-72ade27f50f7","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T20:33:07Z","date_created":"2022-09-06T20:29:45Z","summary":null,"body":["<article data-history-node-id=\"3521\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-497\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-497<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>Between 29 August and 5 September 2022, Dell published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell NetWorker \u2013 versions 19.2.1.x, 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0<\/li>\n\t<li>SmartFabric OS10 \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-497","alert_type":396,"serial_number":"AV22-497","subject":null,"moderation_state":"published","external_url":null},{"nid":3522,"title":"Fortinet security advisory (AV22-498)","uuid":"7352e58b-7b57-423e-b53b-d59e92a054d0","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T20:39:16Z","date_created":"2022-09-06T20:34:56Z","summary":null,"body":["<article data-history-node-id=\"3522\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-498\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-498<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 6 September 2022, Fortinet published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiAP \u2013 multiple versions<\/li>\n\t<li>FortiAP-S \u2013 multiple versions<\/li>\n\t<li>FortiAP-U \u2013 multiple versions<\/li>\n\t<li>FortiAP-W2 \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\" rel=\"external\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-498","alert_type":396,"serial_number":"AV22-498","subject":null,"moderation_state":"published","external_url":null},{"nid":3523,"title":"Android security advisory \u2013 September 2022 monthly rollup (AV22-499)","uuid":"bfd03b6e-4979-4af7-b2b4-a594b24e8035","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T20:45:24Z","date_created":"2022-09-06T20:43:33Z","summary":null,"body":["<article data-history-node-id=\"3523\" about=\"\/en\/alerts-advisories\/android-security-advisory-september-2022-monthly-rollup-av22-499\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-499<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 6 September 2022 Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2022-09-01\" rel=\"external\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-september-2022-monthly-rollup-av22-499","alert_type":396,"serial_number":"AV22-499","subject":null,"moderation_state":"published","external_url":null},{"nid":3524,"title":"F5 security advisory (AV22-500)","uuid":"192c161e-01ee-4427-ad39-07f89fb4c063","banner":null,"lang":"en","date_modified":"2022-09-06","date_modified_ts":"2022-09-06T20:51:41Z","date_created":"2022-09-06T20:51:17Z","summary":null,"body":["<article data-history-node-id=\"3524\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-500\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-500<\/strong><br \/><strong>Date: 6 September 2022<\/strong><\/p>\n\n<p>On 6 September 2022, F5 published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>F5OS-A \u2013 versions 1.1.1 to 1.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K12055286\" rel=\"external\">F5 Security Advisory (K12055286)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-500","alert_type":396,"serial_number":"AV22-500","subject":null,"moderation_state":"published","external_url":null},{"nid":3525,"title":"Cisco security advisory (AV22-501)","uuid":"f826d4c1-54b8-47ad-a9fe-4f48a05cbd8a","banner":null,"lang":"en","date_modified":"2022-09-07","date_modified_ts":"2022-09-07T18:51:22Z","date_created":"2022-09-07T18:50:47Z","summary":null,"body":["<article data-history-node-id=\"3525\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-501\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-501<\/strong><br \/><strong>Date: 7 September 2022<\/strong><\/p>\n\n<p>On 7 September 2022, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adaptive Security Virtual Appliance (ASAv) \u2013 multiple versions<\/li>\n\t<li>Cisco Catalyst 8000V Edge Software \u2013 multiple versions<\/li>\n\t<li>Cisco SD-WAN vManage Software \u2013 multiple versions<\/li>\n\t<li>Secure Firewall Threat Defense Virtual \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\" rel=\"external\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-501","alert_type":396,"serial_number":"AV22-501","subject":null,"moderation_state":"published","external_url":null},{"nid":3528,"title":"[Control systems] MZ Automation security advisory (AV22-502) ","uuid":"4dcebc88-2838-4476-b2d0-0988870ae8f2","banner":null,"lang":"en","date_modified":"2022-09-08","date_modified_ts":"2022-09-08T18:51:23Z","date_created":"2022-09-08T18:50:42Z","summary":null,"body":["<article data-history-node-id=\"3528\" about=\"\/en\/alerts-advisories\/control-systems-mz-automation-security-advisory-av22-502\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-502<\/strong><br \/><strong>Date: 8 September 2022<\/strong><\/p>\n\n<p>On 8 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>libIEC61850 \u2013 version 1.5 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow remote code execution or cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-251-01\" rel=\"external\">ICS Advisory (ICSA-22-251-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mz-automation-security-advisory-av22-502","alert_type":398,"serial_number":"AV22-502","subject":null,"moderation_state":"published","external_url":null},{"nid":3529,"title":"[Control systems] Baxter security advisory (AV22-503) ","uuid":"8bcbeb0a-eaf5-44ac-b244-aa37142958ad","banner":null,"lang":"en","date_modified":"2022-09-08","date_modified_ts":"2022-09-08T18:59:57Z","date_created":"2022-09-08T18:57:35Z","summary":null,"body":["<article data-history-node-id=\"3529\" about=\"\/en\/alerts-advisories\/control-systems-baxter-security-advisory-av22-503\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-503<\/strong><br \/><strong>Date: 8 September 2022<\/strong><\/p>\n\n<p>On 8 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Baxter Spectrum IQ \u2013 multiple models and versions<\/li>\n\t<li>Sigma Spectrum \u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure and changes to device configuration.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-251-01\" rel=\"external\">ICS Advisory (ICSMA-22-251-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-baxter-security-advisory-av22-503","alert_type":398,"serial_number":"AV22-503","subject":null,"moderation_state":"published","external_url":null},{"nid":3531,"title":"IBM security advisory (AV22-504)","uuid":"11836272-c1dc-4e38-9962-5289af3dcc21","banner":null,"lang":"en","date_modified":"2022-09-12","date_modified_ts":"2022-09-12T15:55:09Z","date_created":"2022-09-12T15:53:38Z","summary":null,"body":["<article data-history-node-id=\"3531\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-504\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-504<\/strong><br \/><strong>Date: 12 September 2022<\/strong><\/p>\n\n<p>Between 6 and 11 September 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n\t<li>IBM SPSS Analytic Server \u2013 version 3.4<\/li>\n\t<li>IBM Sterling Connect:Direct for UNIX \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-504","alert_type":396,"serial_number":"AV22-504","subject":null,"moderation_state":"published","external_url":null},{"nid":3532,"title":"Ubuntu security advisory (AV22-505)","uuid":"e7a32be7-61ec-449d-bfe3-fc650efad9c3","banner":null,"lang":"en","date_modified":"2022-09-12","date_modified_ts":"2022-09-12T16:02:40Z","date_created":"2022-09-12T16:02:10Z","summary":null,"body":["<article data-history-node-id=\"3532\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-505\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-505<\/strong><br \/><strong>Date: 12 September 2022<\/strong><\/p>\n\n<p>Between 5 and 11 September 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-505","alert_type":396,"serial_number":"AV22-505","subject":null,"moderation_state":"published","external_url":null},{"nid":3533,"title":"Dell security advisory (AV22-506)","uuid":"6b580c96-251d-43bd-b56d-37bab8970ed2","banner":null,"lang":"en","date_modified":"2022-09-12","date_modified_ts":"2022-09-12T17:54:09Z","date_created":"2022-09-12T17:34:31Z","summary":null,"body":["<article data-history-node-id=\"3533\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-506\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-506<\/strong><br \/><strong>Date: 12 September 2022<\/strong><\/p>\n\n<p>Between 6 and 11 September 2022, Dell published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell PowerScale OneFS \u2013 multiple versions<\/li>\n\t<li>eVASA Provider Virtual Appliance \u2013 versions prior to 9.2.3.7<\/li>\n\t<li>PowerMaxOS \u2013 version 5978.711.711<\/li>\n\t<li>Solutions Enabler Virtual Appliance \u2013 versions prior to 9.2.3.4<\/li>\n\t<li>Unisphere for PowerMax \u2013 versions prior to 9.2.3.15<\/li>\n\t<li>Unisphere for PowerMax Virtual Appliance \u2013 versions prior to 9.2.3.15<\/li>\n\t<li>VASA Provider Standalone \u2013 versions prior to 9.2.3.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-506","alert_type":396,"serial_number":"AV22-506","subject":null,"moderation_state":"published","external_url":null},{"nid":3534,"title":"Apple security advisory (AV22-507)","uuid":"10ee3dc7-45d4-4f36-b5f8-7be0cc7eb195","banner":null,"lang":"en","date_modified":"2022-09-12","date_modified_ts":"2022-09-12T19:52:21Z","date_created":"2022-09-12T19:51:45Z","summary":null,"body":["<article data-history-node-id=\"3534\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-507\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-507<\/strong><br \/><strong>Date: 12 September 2022<\/strong><\/p>\n\n<p>On 12 September 2022 Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15.7 and versions prior to 16<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.7<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.7<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.6<\/li>\n\t<li>Safari \u2013 versions prior to 16<\/li>\n\t<li>tvOS \u2013 versions prior to 16<\/li>\n\t<li>watchOS \u2013 versions prior to 9<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, privilege escalation and security bypass.<\/p>\n\n<p>Apple has received reports that some of these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" rel=\"external\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-507","alert_type":396,"serial_number":"AV22-507","subject":null,"moderation_state":"published","external_url":null},{"nid":3535,"title":"[Control Systems] Siemens security advisory (AV22-508) ","uuid":"0556ee32-9bd9-49c7-bc7c-0599689381f3","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T15:17:26Z","date_created":"2022-09-13T15:16:54Z","summary":null,"body":["<article data-history-node-id=\"3535\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-508\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-508<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>CoreShield One-Way Gateway (OWG) Software \u2013 versions prior to V2.2<\/li>\n\t<li>Mendix SAML Module \u2013 multiple versions and platforms<\/li>\n\t<li>Parasolid \u2013 multiple versions<\/li>\n\t<li>RUGGEDCOM \u2013 versions prior to V5.6.0<\/li>\n\t<li>SINEC INS \u2013 versions prior to V1.0 SP2<\/li>\n\t<li>Simcenter Femap \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\" rel=\"external\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-508","alert_type":398,"serial_number":"AV22-508","subject":null,"moderation_state":"published","external_url":null},{"nid":3536,"title":"[Control Systems] Schneider Electric Security Advisory (AV22-509)","uuid":"1aaa7c58-9230-4995-9ed2-f1ba9c922e49","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T15:29:14Z","date_created":"2022-09-13T15:26:28Z","summary":null,"body":["<article data-history-node-id=\"3536\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-509\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-509<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BLUE Open Studio 2020 Service Pack 2 \u2013 version V20.0.2 and prior<\/li>\n\t<li>EcoStruxure Machine SCADA Expert 2020 Service Pack 2 \u2013 version V20.0.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-509","alert_type":398,"serial_number":"AV22-509","subject":null,"moderation_state":"published","external_url":null},{"nid":3537,"title":"Citrix security advisory (AV22-510)","uuid":"a54afffa-1cec-470c-bd0e-876e01ed8477","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T16:06:08Z","date_created":"2022-09-13T16:05:33Z","summary":null,"body":["<article data-history-node-id=\"3537\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-510\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-510<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, Citrix published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Citrix Hypervisor 8.2 LTSR CU1 Hotfix XS82ECU1008<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX463901 \" rel=\"external\">Citrix Security Bulletin (CTX463901)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-510","alert_type":396,"serial_number":"AV22-510","subject":null,"moderation_state":"published","external_url":null},{"nid":3538,"title":"SAP security advisory \u2013 September 2022 monthly rollup (AV22-511)","uuid":"fe8d1fa3-14d3-4964-bf6e-2ba4a6376948","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T16:12:55Z","date_created":"2022-09-13T16:12:16Z","summary":null,"body":["<article data-history-node-id=\"3538\" about=\"\/en\/alerts-advisories\/sap-security-advisory-september-2022-monthly-rollup-av22-511\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-511<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, SAP published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Business One \u2013 version 10.0<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform (CMC) \u2013 version 430<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\" rel=\"external\">SAP Security Patch Day \u2013 September 2022<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-september-2022-monthly-rollup-av22-511","alert_type":396,"serial_number":"AV22-511","subject":null,"moderation_state":"published","external_url":null},{"nid":3539,"title":"Adobe Security Advisory (AV22-512)","uuid":"1b57e718-d0bf-4850-a73b-1fe4c120fd86","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T18:16:05Z","date_created":"2022-09-13T18:14:10Z","summary":null,"body":["<article data-history-node-id=\"3539\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-512\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-512<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, Adobe published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Animate 2021 \u2013 version 21.0.11 and prior<\/li>\n\t<li>Adobe Animate 2022 \u2013 version 22.0.7 and prior<\/li>\n\t<li>Adobe Bridge \u2013 multiple versions<\/li>\n\t<li>Adobe InCopy \u2013 multiple versions<\/li>\n\t<li>Adobe InDesign \u2013 multiple versions<\/li>\n\t<li>Illustrator 2021 \u2013 version 25.4.7 and prior<\/li>\n\t<li>Illustrator 2022 \u2013 version 26.4 and prior<\/li>\n\t<li>Photoshop 2021 \u2013 version 22.5.8 and prior<\/li>\n\t<li>Photoshop 2022 \u2013 version 23.4.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-512","alert_type":396,"serial_number":"AV22-512","subject":null,"moderation_state":"published","external_url":null},{"nid":3540,"title":"Microsoft Security Advisory \u2013 September 2022 Monthly Rollup (AV22-513)","uuid":"abd8a73d-a7a2-44ea-a779-1e90762015a8","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T19:06:16Z","date_created":"2022-09-13T19:04:10Z","summary":null,"body":["<article data-history-node-id=\"3540\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2022-monthly-rollup-av22-513\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-513<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft Dynamics CRM (on-premises) \u2013 multiple versions<\/li>\n\t<li>Windows 7 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows RT 8.1<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2022-37969 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Sep\">September 2022 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2022-monthly-rollup-av22-513","alert_type":396,"serial_number":"AV22-513","subject":null,"moderation_state":"published","external_url":null},{"nid":3541,"title":"[Control Systems] Delta Industrial Automation Security Advisory (AV22-514) ","uuid":"9d61e24a-9828-441f-be9f-5841efd8a164","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T19:18:08Z","date_created":"2022-09-13T19:16:44Z","summary":null,"body":["<article data-history-node-id=\"3541\" about=\"\/en\/alerts-advisories\/control-systems-delta-industrial-automation-security-advisory-av22-514\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-514<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>DIAEnergie \u2013 version 1.8.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-256-03\">ICS Advisory (ICSA-22-256-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-industrial-automation-security-advisory-av22-514","alert_type":398,"serial_number":"AV22-514","subject":null,"moderation_state":"published","external_url":null},{"nid":3542,"title":"[Control Systems] Kingspan Security Advisory (AV22-515)","uuid":"fb6cf1f6-1260-4ef6-bf4b-c03d2daf3101","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T19:22:55Z","date_created":"2022-09-13T19:21:38Z","summary":null,"body":["<article data-history-node-id=\"3542\" about=\"\/en\/alerts-advisories\/control-systems-kingspan-security-advisory-av22-515\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-515<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Kingspan TMS300 CS \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthenticated actor to alter device configuration.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-256-04\">ICS Advisory (ICSA-22-256-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-kingspan-security-advisory-av22-515","alert_type":398,"serial_number":"AV22-515","subject":null,"moderation_state":"published","external_url":null},{"nid":3543,"title":"[Control systems] Hitachi Energy security advisory (AV22-516) ","uuid":"b35dd206-9c66-44fc-9424-58fa39222078","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T19:37:59Z","date_created":"2022-09-13T19:34:32Z","summary":null,"body":["<article data-history-node-id=\"3543\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-516\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-516<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>TXpert Hub CoreTec 4\u00a0\u2013 multiples versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-256-01\">ICS Advisory (ICSA-22-256-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-516","alert_type":398,"serial_number":"AV22-516","subject":null,"moderation_state":"published","external_url":null},{"nid":3544,"title":"[Control systems] Honeywell security advisory (AV22-517)","uuid":"a65c761e-fb54-47b9-95be-cfd838daaedb","banner":null,"lang":"en","date_modified":"2022-09-13","date_modified_ts":"2022-09-13T19:44:40Z","date_created":"2022-09-13T19:42:23Z","summary":null,"body":["<article data-history-node-id=\"3544\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av22-517\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-517<\/strong><br \/><strong>Date: 13 September 2022<\/strong><\/p>\n\n<p>On 13 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>SoftMaster\u00a0\u2013 version 4.51<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in code execution or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-256-02\">ICS Advisory (ICSA-22-256-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av22-517","alert_type":398,"serial_number":"AV22-517","subject":null,"moderation_state":"published","external_url":null},{"nid":3545,"title":"Google Chrome Security Advisory (AV22-518)","uuid":"38c404b6-cc86-493e-bbac-e4aa683d0fe4","banner":null,"lang":"en","date_modified":"2022-09-14","date_modified_ts":"2022-09-14T18:23:13Z","date_created":"2022-09-14T18:21:25Z","summary":null,"body":["<article data-history-node-id=\"3545\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-518\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-518<\/strong><br \/><strong>Date: 14 September 2022<\/strong><\/p>\n\n<p>On 14 September 2022, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 105.0.5195.125<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/09\/stable-channel-update-for-desktop_14.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-518","alert_type":396,"serial_number":"AV22-518","subject":null,"moderation_state":"published","external_url":null},{"nid":3550,"title":"HPE security advisory (AV22-519)","uuid":"8b63079c-11c7-4281-9c25-45059efaa12f","banner":null,"lang":"en","date_modified":"2022-09-15","date_modified_ts":"2022-09-15T19:35:33Z","date_created":"2022-09-15T19:31:46Z","summary":null,"body":["<article data-history-node-id=\"3550\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-519\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-519<\/strong><br \/><strong>Date: 15 September 2022<\/strong><\/p>\n\n<p>On 14 September 2022, HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Integrated Lights-Out 5 (iLO 5) \u2013 multiple platforms, software versions prior to 2.72<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution, information disclosure or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04365en_us\" rel=\"external\">HPE Security Bulletin (HPESBHF04365)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-519","alert_type":396,"serial_number":"AV22-519","subject":null,"moderation_state":"published","external_url":null},{"nid":3551,"title":"Microsoft Edge security advisory (AV22-520)","uuid":"c56b065f-2270-4df6-a47a-c736d4a1a433","banner":null,"lang":"en","date_modified":"2022-09-16","date_modified_ts":"2022-09-16T16:19:44Z","date_created":"2022-09-16T16:19:09Z","summary":null,"body":["<article data-history-node-id=\"3551\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-520\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-520<\/strong><br \/><strong>Date: 16 September 2022<\/strong><\/p>\n\n<p>On 15 September 2022, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 105.0.1343.42<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security\" rel=\"external\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-520","alert_type":396,"serial_number":"AV22-520","subject":null,"moderation_state":"published","external_url":null},{"nid":3552,"title":"HPE security advisory (AV22-521)","uuid":"71756cca-25ca-4247-97e1-feec5d81c9df","banner":null,"lang":"en","date_modified":"2022-09-16","date_modified_ts":"2022-09-16T19:18:19Z","date_created":"2022-09-16T19:14:38Z","summary":null,"body":["<article data-history-node-id=\"3552\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-521\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-521<\/strong><br \/><strong>Date: 16 September 2022<\/strong><\/p>\n\n<p>On 15 September 2022, HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ClearPass Policy Manager \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution, local privilege escalation or a denial of service<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04362en_us\">HPE Security Bulletin (HPESBNW04362)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-521","alert_type":396,"serial_number":"AV22-521","subject":null,"moderation_state":"published","external_url":null},{"nid":3553,"title":"IBM security advisory (AV22-522)","uuid":"4e71496f-6528-40f4-aa27-f4497e6f7b06","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T14:31:16Z","date_created":"2022-09-20T14:25:25Z","summary":null,"body":["<article data-history-node-id=\"3553\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-522\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-522<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>Between 12 and 19 September 2022 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Call Center for Commerce \u2013 versions 9.5.0 and 10.0<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps \u2013 version 3.x<\/li>\n\t<li>IBM Spectrum Copy Data Management \u2013 version 2.2.0.0 to 2.2.16.0<\/li>\n\t<li>IBM Spectrum Protect Plus \u2013 version 10.1.0 to 10.1.11<\/li>\n\t<li>IBM Sterling Control Center \u2013 version 6.2.1.0 GA to iFix07<\/li>\n\t<li>IBM Sterling Order Management \u2013 versions 9.5.x and 10.0<\/li>\n\t<li>Intelligent Operations Center (IOC) \u2013 versions 5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6, 5.2, 5.2.1 and 5.2.2<\/li>\n\t<li>Log Analysis \u2013 version 1.3.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-522","alert_type":396,"serial_number":"AV22-522","subject":null,"moderation_state":"published","external_url":null},{"nid":3554,"title":"Ubuntu security advisory (AV22-523)","uuid":"4516b342-60dc-40c9-8113-4df3ca50947e","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T14:36:27Z","date_created":"2022-09-20T14:35:18Z","summary":null,"body":["<article data-history-node-id=\"3554\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-523\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-523<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>Between 12 and 19 September 2022, Ubuntu published a Security Notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-523","alert_type":396,"serial_number":"AV22-523","subject":null,"moderation_state":"published","external_url":null},{"nid":3555,"title":"Dell security advisory (AV22-524)","uuid":"847de93b-3a6b-4614-b13e-00314c0eb296","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T14:42:05Z","date_created":"2022-09-20T14:39:27Z","summary":null,"body":["<article data-history-node-id=\"3555\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-524\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-524<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>Between 12 and 19 September 2022, Dell published Security Bulletins to address critical vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell BSAFE SSL-J \u2013 multiple versions<\/li>\n\t<li>Dell BSAFE Crypto-J \u2013 versions prior to 6.2.6.1<\/li>\n\t<li>Dell NetWorker vProxy \u2013 version 4.3.0-22 and prior<\/li>\n\t<li>Connectrix (Brocade) FOS \u2013 multiple versions<\/li>\n\t<li>Dell ECS \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-524","alert_type":396,"serial_number":"AV22-524","subject":null,"moderation_state":"published","external_url":null},{"nid":3556,"title":"HPE security advisory (AV22-525)","uuid":"62c5ec19-7d43-4bfa-89cb-6f30b3816ca6","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T15:43:19Z","date_created":"2022-09-20T15:38:57Z","summary":null,"body":["<article data-history-node-id=\"3556\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-525\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-525<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>On 19 September 2022, HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Brocade 8Gb, 16Gb and 32Gb \u2013 multiple platforms and versions<\/li>\n\t<li>Brocade 8\/12c and 8\/24c \u2013 multiple platforms and versions<\/li>\n\t<li>HPE 8\/8 and 8\/24 SAN Switch \u2013 multiple versions<\/li>\n\t<li>HPE 1606 Extension SAN Switch \u2013 multiple versions<\/li>\n\t<li>HPE B-Series \u2013 multiple platforms and versions<\/li>\n\t<li>HPE SN3000B, SN8000B, SN8600B and SN87000B \u2013 multiple platforms and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution, privilege escalation, information disclosure or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04367en_us\" rel=\"external\">HPE Security Bulletin (HPESBNW04367)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-525","alert_type":396,"serial_number":"AV22-525","subject":null,"moderation_state":"published","external_url":null},{"nid":3557,"title":"Mozilla security advisory (AV22-526)","uuid":"6b5d637f-c252-4d22-94d8-1cc188ccfbfc","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T17:20:18Z","date_created":"2022-09-20T17:14:17Z","summary":null,"body":["<article data-history-node-id=\"3557\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-526\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-526<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>Between 19 and 20 September 2022, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 91.13.1<\/li>\n\t<li>Firefox \u2013 versions prior to 105<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 102.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-39\/\" rel=\"external\">Mozilla Security Advisory (MFSA 2022-39)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-40\/\" rel=\"external\">Mozilla Security Advisory (MFSA 2022-40)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-41\/\" rel=\"external\">Mozilla Security Advisory (MFSA 2022-41)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\" rel=\"external\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-526","alert_type":396,"serial_number":"AV22-526","subject":null,"moderation_state":"published","external_url":null},{"nid":3558,"title":"[Control systems] Medtronic security advisory (AV22-527)","uuid":"2b2f548a-07af-4b8d-859a-43a7be3662ff","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T17:40:23Z","date_created":"2022-09-20T17:36:34Z","summary":null,"body":["<article data-history-node-id=\"3558\" about=\"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory-av22-527\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-527<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>On 20 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>MiniMed 620G \u2013 version MMT-1710<\/li>\n\t<li>MiniMed 630G \u2013 versions MMT-1715, MMT-1754 and MMT-1755<\/li>\n\t<li>MiniMed 640G \u2013 versions MMT-1711, MMT-1712, MMT-1751 and MMT-1752<\/li>\n\t<li>MiniMed 670G \u2013 versions MMT-1740, MMT-1741, MMT-1742, MMT-1760, MMT-1762, MMT-1762, MMT-1780, MMT-1781 and MMT-1782<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-263-01 \" rel=\"external\">ICS Advisory (ICSMA-22-263-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory-av22-527","alert_type":398,"serial_number":"AV22-527","subject":null,"moderation_state":"published","external_url":null},{"nid":3559,"title":"[Control systems] Dataprobe security advisory (AV22-528)","uuid":"528ac284-ea1e-4cba-839b-a8713f984481","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T17:45:56Z","date_created":"2022-09-20T17:42:48Z","summary":null,"body":["<article data-history-node-id=\"3559\" about=\"\/en\/alerts-advisories\/control-systems-dataprobe-security-advisory-av22-528\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-528<\/strong>\n  <br \/><strong>Date: 20 September 2022<\/strong>\n<\/p>\n<p>On 20 September 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:\n<\/p>\n<ul><li>Dataprobe iBoot-PDU FW \u2013 versions prior to 1.42.06162022<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-263-03 \" rel=\"external\">ICS Advisory (ICSA-22-263-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-dataprobe-security-advisory-av22-528","alert_type":398,"serial_number":"AV22-528","subject":null,"moderation_state":"published","external_url":null},{"nid":3560,"title":"[Control systems] Host Engineering security advisory (AV22-529)","uuid":"6ba93771-3c2f-4659-bf65-97180fb2ba8a","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T17:50:51Z","date_created":"2022-09-20T17:48:05Z","summary":null,"body":["<article data-history-node-id=\"3560\" about=\"\/en\/alerts-advisories\/control-systems-host-engineering-security-advisory-av22-529\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-529<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>On 20 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>H0-ECOM100 Communications Module \u2013 firmware version v5.0.155 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-263-04 \" rel=\"external\">ICS Advisory (ICSA-22-263-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-host-engineering-security-advisory-av22-529","alert_type":398,"serial_number":"AV22-529","subject":null,"moderation_state":"published","external_url":null},{"nid":3561,"title":"[Control systems] Hitachi Energy security advisory (AV22-530)","uuid":"b1b810b3-eb70-46cc-9ffc-bc56e447320e","banner":null,"lang":"en","date_modified":"2022-09-20","date_modified_ts":"2022-09-20T17:59:14Z","date_created":"2022-09-20T17:54:50Z","summary":null,"body":["<article data-history-node-id=\"3561\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-530\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-530<\/strong><br \/><strong>Date: 20 September 2022<\/strong><\/p>\n\n<p>On 20 September 2022, ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Energy AFF660 FW \u2013 version 03.0.02 and prior<\/li>\n\t<li>Hitachi Energy AFF665 FW \u2013 version 03.0.02 and prior<\/li>\n\t<li>Hitachi Energy PROMOD IV \u2013 versions 11.2, 11.3 and 11.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-263-01\" rel=\"external\">ICS Advisory (ICSA-22-263-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-263-02\" rel=\"external\">ICS Advisory (ICSA-22-263-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-530","alert_type":398,"serial_number":"AV22-530","subject":null,"moderation_state":"published","external_url":null},{"nid":3562,"title":"HPE security advisory (AV22-531)","uuid":"4080e3ef-ff79-4537-b178-15b0b64173a8","banner":null,"lang":"en","date_modified":"2022-09-21","date_modified_ts":"2022-09-21T20:07:26Z","date_created":"2022-09-21T20:00:54Z","summary":null,"body":["<article data-history-node-id=\"3562\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-531\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-531<\/strong><br \/><strong>Date: 21 September 2022<\/strong><\/p>\n\n<p>On 20 September 2022, HPE published a Security Bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE Edgeline e920, e920d and e920t Server Blades \u2013 firmware versions prior to 1.62_08-16-2022<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04355en_us\" rel=\"external\">HPE Security Bulletin (HPESBHF04355)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-531","alert_type":396,"serial_number":"AV22-531","subject":null,"moderation_state":"published","external_url":null},{"nid":3563,"title":"Red Hat Security Advisory (AV22-532)","uuid":"0bdf8107-fe42-43ee-a21a-dbbc63043309","banner":null,"lang":"en","date_modified":"2022-09-22","date_modified_ts":"2022-09-22T14:59:02Z","date_created":"2022-09-22T14:55:21Z","summary":null,"body":["<article data-history-node-id=\"3563\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-532\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-532<\/strong><br \/><strong>Date: 22 September 2022<\/strong><\/p>\n\n<p>On 20 September 2022, Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:6610\">Red Hat Security Advisory (RHSA-2022:6610)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:6592\">Red Hat Security Advisory (RHSA-2022:6592)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:6582\">Red Hat Security Advisory (RHSA-2022:6582)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-532","alert_type":396,"serial_number":"AV22-532","subject":null,"moderation_state":"published","external_url":null},{"nid":3564,"title":"Microsoft security advisory (AV22-533)","uuid":"98a8eea2-69ea-400c-8443-063bc6739163","banner":null,"lang":"en","date_modified":"2022-09-22","date_modified_ts":"2022-09-22T19:16:16Z","date_created":"2022-09-22T19:15:43Z","summary":null,"body":["<article data-history-node-id=\"3564\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-av22-533\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-533<\/strong><br \/><strong>Date: 22 September 2022<\/strong><\/p>\n\n<p>On 20 September 2022, Microsoft published a Security Update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Endpoint Configuration Manager \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37972\" rel=\"external\">Microsoft Endpoint Configuration Manager Spoofing Vulnerability (CVE-2022-37972)<\/a><\/li>\n\t<li><a href=\"https:\/\/learn.microsoft.com\/en-ca\/mem\/configmgr\/hotfix\/2207\/15498768\" rel=\"external\">Endpoint Configuration Manager Update (KB15498768)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-av22-533","alert_type":396,"serial_number":"AV22-533","subject":null,"moderation_state":"published","external_url":null},{"nid":3565,"title":"[Control Systems] Measuresoft Security Advisory (AV22-534)","uuid":"5c81b81e-080d-4d4a-a8be-a75e3d204f40","banner":null,"lang":"en","date_modified":"2022-09-23","date_modified_ts":"2022-09-23T11:29:35Z","date_created":"2022-09-23T11:27:45Z","summary":null,"body":["<article data-history-node-id=\"3565\" about=\"\/en\/alerts-advisories\/control-systems-measuresoft-security-advisory-av22-534\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-534<\/strong><br \/><strong>Date: 23 September 2022<\/strong><\/p>\n\n<p>On 22 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>ScadaPro Server \u2013 version 6.7<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated actor to execute arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-265-01\">ICS Advisory (ICSA-22-265-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-measuresoft-security-advisory-av22-534","alert_type":398,"serial_number":"AV22-534","subject":null,"moderation_state":"published","external_url":null},{"nid":3566,"title":"IBM Security Advisory (AV22-535)","uuid":"f2eca01e-bc20-4636-8313-c5316286f7d7","banner":null,"lang":"en","date_modified":"2022-09-26","date_modified_ts":"2022-09-26T17:23:50Z","date_created":"2022-09-26T17:21:58Z","summary":null,"body":["<article data-history-node-id=\"3566\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-535\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-535<\/strong><br \/><strong>Date: 26 September 2022<\/strong><\/p>\n\n<p>Between 20 and 25 September 2022, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>curl-7.83.1-1.aix7.1.ppc.rpm \u2013 versions 7.19.4 to 7.83.0<\/li>\n\t<li>IBM Tivoli Netcool Impact \u2013 version 7.1.0<\/li>\n\t<li>PowerSC \u2013 versions 1.3, 2.0 and 2.1<\/li>\n\t<li>powerscStd.tnc_pm \u2013 versions 1.3.0.4 to 2.1.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-535","alert_type":396,"serial_number":"AV22-535","subject":null,"moderation_state":"published","external_url":null},{"nid":3567,"title":"Ubuntu Security Advisory (AV22-536)","uuid":"1b0248f1-aa6f-43bc-8118-f3faf1c2f6b6","banner":null,"lang":"en","date_modified":"2022-09-26","date_modified_ts":"2022-09-26T17:29:17Z","date_created":"2022-09-26T17:27:13Z","summary":null,"body":["<article data-history-node-id=\"3567\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-536\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-536<\/strong><br \/><strong>Date: 26 September 2022<\/strong><\/p>\n\n<p>Between 20 and 25 September 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-536","alert_type":396,"serial_number":"AV22-536","subject":null,"moderation_state":"published","external_url":null},{"nid":3568,"title":"Dell Security Advisory (AV22-537)","uuid":"62408594-08bd-42dd-9920-d0877da8da29","banner":null,"lang":"en","date_modified":"2022-09-26","date_modified_ts":"2022-09-26T17:34:04Z","date_created":"2022-09-26T17:32:32Z","summary":null,"body":["<article data-history-node-id=\"3568\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-537\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-537<\/strong><br \/><strong>Date: 26 September 2022<\/strong><\/p>\n\n<p>Between 20 and 25 September 2022, Dell published Security Bulletins to address critical vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell NetWorker vProxy \u2013 versions 4.3.0-31 and prior<\/li>\n\t<li>Dell VxRail Appliance 7.0.x \u2013 versions prior to 7.0.400<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-537","alert_type":396,"serial_number":"AV22-537","subject":null,"moderation_state":"published","external_url":null},{"nid":3569,"title":"HPE security advisory (AV22-538)","uuid":"a8259660-226d-4a6f-994c-8dea443b984a","banner":null,"lang":"en","date_modified":"2022-09-26","date_modified_ts":"2022-09-26T18:31:28Z","date_created":"2022-09-26T18:29:35Z","summary":null,"body":["<article data-history-node-id=\"3569\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-538\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-538<\/strong><br \/><strong>Date: 26 September 2022<\/strong><\/p>\n\n<p>On 26 September 2022, HPE published a Security Bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE Nimble Storage Hybrid Flash Arrays \u2013 versions prior to 5.2.1.900 (LTSR), 5.3.0.0 (GA)<\/li>\n\t<li>Nimble Storage Secondary Flash Arrays \u2013 versions prior to 5.2.1.900 (LTSR), 5.3.0.0 (GA)<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04359en_us\">HPE Security Bulletin (HPESBST04359)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-538","alert_type":396,"serial_number":"AV22-538","subject":null,"moderation_state":"published","external_url":null},{"nid":3570,"title":"[Control systems] ABB security advisory (AV22-539)","uuid":"3de0c6c5-18fc-48ea-a384-84175f9c7d16","banner":null,"lang":"en","date_modified":"2022-09-27","date_modified_ts":"2022-09-27T15:48:59Z","date_created":"2022-09-27T15:48:11Z","summary":null,"body":["<article data-history-node-id=\"3570\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-539\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-539<\/strong><br \/><strong>Date: 27 September 2022<\/strong><\/p>\n\n<p>On 19 September 2022, ABB published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB Central Licensing System (CLS), Ability SCADAvantage \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service, privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108467A3198\" rel=\"external\">ABB Security Advisory (3CCA020 - 003309)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-539","alert_type":398,"serial_number":"AV22-539","subject":null,"moderation_state":"published","external_url":null},{"nid":3571,"title":"[Control Systems] Rockwell Automation Security Advisory (AV22-540)","uuid":"fefa8ad9-f9d4-4c27-b243-b52aef259492","banner":null,"lang":"en","date_modified":"2022-09-27","date_modified_ts":"2022-09-27T17:44:52Z","date_created":"2022-09-27T17:43:27Z","summary":null,"body":["<article data-history-node-id=\"3571\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-540\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-540<\/strong><br \/><strong>Date: 27 September 2022<\/strong><\/p>\n\n<p>On 27 September 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>ThinManager ThinServer \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-270-03\">ICS Advisory (ICSA-22-270-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-540","alert_type":398,"serial_number":"AV22-540","subject":null,"moderation_state":"published","external_url":null},{"nid":3572,"title":"[Control Systems] Hitachi Energy Security Advisory (AV22-541)","uuid":"3ec7fc6c-9ada-4e7f-bb0b-f196936f1e03","banner":null,"lang":"en","date_modified":"2022-09-27","date_modified_ts":"2022-09-27T17:50:01Z","date_created":"2022-09-27T17:47:49Z","summary":null,"body":["<article data-history-node-id=\"3572\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-541\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-541<\/strong><br \/><strong>Date: 27 September 2022<\/strong><\/p>\n\n<p>On 27 September 2022, ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>AFS660\/AFS665 Industrial Switches \u2013 version 7.0.02 and prior<\/li>\n\t<li>Lumada APM Edge \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to system compromise or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-270-01\">ICS Advisory (ICSA-22-270-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-270-02\">ICS Advisory (ICSA-22-270-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-541","alert_type":398,"serial_number":"AV22-541","subject":null,"moderation_state":"published","external_url":null},{"nid":3574,"title":"Google Chrome security advisory (AV22-542)","uuid":"cb21e80b-7fe7-4977-bb26-04a03f7e6e17","banner":null,"lang":"en","date_modified":"2022-09-27","date_modified_ts":"2022-09-27T19:41:07Z","date_created":"2022-09-27T19:40:37Z","summary":null,"body":["<article data-history-node-id=\"3574\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-542\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-542<\/strong><br \/><strong>Date: 27 September 2022<\/strong><\/p>\n\n<p>On 27 September 2022, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 106.0.5249.61<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/09\/stable-channel-update-for-desktop_27.html\" rel=\"external\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-542","alert_type":396,"serial_number":"AV22-542","subject":null,"moderation_state":"published","external_url":null},{"nid":3577,"title":"Cisco security advisory (AV22-543)","uuid":"72dfa728-a5dc-4e7f-ae45-f3be1e90ea73","banner":null,"lang":"en","date_modified":"2022-09-29","date_modified_ts":"2022-09-29T12:01:16Z","date_created":"2022-09-29T12:00:34Z","summary":null,"body":["<article data-history-node-id=\"3577\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-543\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-543<\/strong><br \/><strong>Date: 28 September 2022<\/strong><\/p>\n\n<p>On 28 September 2022, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco IOS Software \u2013 multiple versions and platforms<\/li>\n\t<li>Cisco IOS XE Software \u2013 multiple versions and platforms<\/li>\n\t<li>Cisco SD-WAN Software \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\" rel=\"external\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-543","alert_type":396,"serial_number":"AV22-543","subject":null,"moderation_state":"published","external_url":null},{"nid":3578,"title":"Drupal security advisory (AV22-544)","uuid":"15699246-c48c-4e2c-b245-0b9d337c0d2b","banner":null,"lang":"en","date_modified":"2022-09-29","date_modified_ts":"2022-09-29T12:07:18Z","date_created":"2022-09-29T12:04:49Z","summary":null,"body":["<article data-history-node-id=\"3578\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av22-544\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-544<\/strong><br \/><strong>Date: 28 September 2022<\/strong><\/p>\n\n<p>On 28 September 2022, Drupal published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Drupal 9.3 \u2013 versions prior to 9.3.22<\/li>\n\t<li>Drupal 9.4 \u2013 versions prior to 9.4.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-core-2022-016\" rel=\"external\">Drupal Security Advisory (SA-CORE-2022-016)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av22-544","alert_type":396,"serial_number":"AV22-544","subject":null,"moderation_state":"published","external_url":null},{"nid":3584,"title":"Mozilla security advisory (AV22-545)","uuid":"f60dbf29-7885-4d17-af90-64819974d04f","banner":null,"lang":"en","date_modified":"2022-09-29","date_modified_ts":"2022-09-29T19:09:42Z","date_created":"2022-09-29T19:04:01Z","summary":null,"body":["<article data-history-node-id=\"3584\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-545\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-545<\/strong><br \/><strong>Date: 29 September 2022<\/strong><\/p>\n\n<p>On 28 September 2022, Mozilla published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 102.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-43\/ \" rel=\"external\">Mozilla Security Advisory (MFSA 2022-43)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-545","alert_type":396,"serial_number":"AV22-545","subject":null,"moderation_state":"published","external_url":null},{"nid":3585,"title":"[Control systems] Hitachi Energy security advisory (AV22-546) ","uuid":"132a338d-49a6-4a67-8eee-a3d6d1869940","banner":null,"lang":"en","date_modified":"2022-09-29","date_modified_ts":"2022-09-29T19:19:42Z","date_created":"2022-09-29T19:13:35Z","summary":null,"body":["<article data-history-node-id=\"3585\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-546\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-546<\/strong><br \/><strong>Date: 29 September 2022<\/strong><\/p>\n\n<p>On 29 September 2022, ICS-CERT published ICS Advisories to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>SYS600 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow arbitrary code execution, authentication bypass and a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-272-01\" rel=\"external\">ICS Advisory (ICSA-22-272-01) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-272-02\" rel=\"external\">ICS Advisory (ICSA-22-272-02) <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-546","alert_type":398,"serial_number":"AV22-546","subject":null,"moderation_state":"published","external_url":null},{"nid":3586,"title":"HPE security advisory (AV22-547)","uuid":"70a08fa5-5fe9-483d-acd8-219835cb52ca","banner":null,"lang":"en","date_modified":"2022-09-29","date_modified_ts":"2022-09-29T19:29:40Z","date_created":"2022-09-29T19:22:31Z","summary":null,"body":["<article data-history-node-id=\"3586\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-547\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-547<\/strong><br \/><strong>Date: 29 September 2022<\/strong><\/p>\n\n<p>Between 27 and 28 2022, HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Aruba InstantOS - multiple versions<\/li>\n\t<li>ArubaOS 10.3.x - versions 10.3.1.0 and prior<\/li>\n\t<li>HP-UX OpenSSL \u2013 versions prior to A.01.01.01p.001<\/li>\n\t<li>HPE NonStop \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04368en_us\" rel=\"external\">HPE Security Bulletin (HPESBUX04368)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04371en_us\" rel=\"external\">HPE Security Bulletin (HPESBNW04371)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbns04337en_us\" rel=\"external\">HPE Security Bulletin (HPESBNS04337)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1 \" rel=\"external\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-547","alert_type":396,"serial_number":"AV22-547","subject":null,"moderation_state":"published","external_url":null},{"nid":3587,"title":"Microsoft Exchange zero-day vulnerabilities - Update 1","uuid":"aead28da-63ef-41dc-9f82-8ba9b4b36d21","banner":null,"lang":"en","date_modified":"2022-11-09","date_modified_ts":"2022-11-09T18:06:47Z","date_created":"2022-09-30T17:34:36Z","summary":null,"body":["<article data-history-node-id=\"3587\" about=\"\/en\/alerts-advisories\/microsoft-exchange-zero-day-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL22-011<br \/><strong>Date:\u00a0<\/strong>30 September 2022<br \/><strong>Updated:\u00a0<\/strong>9 November 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 29 September 2022, Microsoft published an advisory confirming the existence of vulnerabilities impacting Microsoft Exchange<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. First reported by GTSC Vietnam Technology Services<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>, the vulnerabilities can only be exploited by an authenticated user. Microsoft reports that the first vulnerability identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, while the second, identified as CVE-2022-41082, allows remote code execution (RCE) when PowerShell is accessible to the malicious actor.<\/p>\n\n<p>GTSC has reported that these vulnerabilities have been exploited by malicious actors and has resulted in the deployment of webshells as well as information disclosure, command execution and lateral activity.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On 8 November 2022, patches for CVE-2022-41040 <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> and CVE-2022-41082 <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> were released as part of the November 2022 Security Updates <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>Microsoft has reported that patches are in development but have confirmed that mitigation recommendations, such as those provided by GTSC, are successful in blocking the activity. Those recommendations are available within both the Microsoft and GTSC advisories <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn4a-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>As a result of incident response GTSC compiled several Indicators of Compromise (IOCs) to aid network defenders in the detection of malicious activity. The Cyber Centre recommends affected customers review the Cyber Centre joint cybersecurity advisory on technical approaches to uncovering and remediating malicious activity <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre recommends Exchange customers continue to monitor Microsoft advisory spaces and update systems when a patch is made available.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+18332923788\">1-833-CYBER-88<\/a> or <a href=\"tel:+18332923788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc-blog.microsoft.com\/2022\/09\/29\/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server\/\">Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/gteltsc.vn\/blog\/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html\">New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/news-events\/joint-cybersecurity-advisory\">Technical Approaches to Uncovering and Remediating Malicious Activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/09\/30\/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082\/\" rel=\"external\">Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-41040\" rel=\"external\">CVE-2022-41040<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-41082\" rel=\"external\">CVE-2022-41082<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\" rel=\"external\">Security Update Guide<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-exchange-zero-day-vulnerabilities","alert_type":397,"serial_number":"AL22-011","subject":null,"moderation_state":"published","external_url":null},{"nid":3588,"title":"Supply chain compromise impacting Comm100 Live Chat software - Update 1","uuid":"88108b81-2c5c-4bae-a92a-c49aeb4cba83","banner":null,"lang":"en","date_modified":"2022-10-02","date_modified_ts":"2022-10-02T16:12:40Z","date_created":"2022-10-02T16:11:47Z","summary":null,"body":["<article data-history-node-id=\"3588\" about=\"\/en\/alerts-advisories\/supply-chain-compromise-impacting-comm100-live-chat-software\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL22-012<br \/><strong>Date:\u00a0<\/strong>2 October 2022<br \/><strong>Updated:\u00a0<\/strong>13 October 2022<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On 30 September 2022 CrowdStrike published a blog detailing a new supply chain compromise impacting the Comm100 Network Corporation <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. The report describes that a highly competent threat actor conducted a supply chain compromise which resulted in a trojanized installer of the Comm100 Live Chat application being used to distribute malware. The installer was signed on 26 September 2022 using a valid Comm100 Network Corporation certificate.<\/p>\n\n<p>The installer was last reported as being infected and accessible for download on 29 September 2022. Comm100 has recently published a clean installer (10.0.9).<\/p>\n\n<p>The Cyber Centre has received reports of active compromise where the trojanized application has been found to be installed and in use.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On 6 October 2022, Comm100 issued a press release <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> detailing the security incident affecting their Agent Console Windows Desktop App. Included was specific guidance <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> for removing the trojan from the Comm100 Agent Console Windows Desktop App version 10.0.8.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review these vendor pages and to apply the provided remediations in addition to following the guidance in the <strong>recommended actions<\/strong> below.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>At this time, only two versions have been reported as containing the malicious payload:<\/p>\n\n<ul><li><strong>10.0.72 with SHA256 Hash 6f0fae95f5637710d1464b42ba49f9533443181262f78805d3ff13bea3b8fd45<\/strong>\n\n\t<ul><li>Crowdstrike reports that they are aware that this file contains the same backdoor however they have not observed it in the wild.<\/li>\n\t<\/ul><\/li>\n\t<li><strong>10.0.8 with SHA256 Hash ac5c0823d623a7999f0db345611084e0a494770c3d6dd5feeba4199deee82b86<\/strong>\n\t<ul><li>Crowdstrike reports this file is an Electron application that contains a JavaScript (JS) backdoor within the file main.js of the embedded Asar archive.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Organizations are encouraged to identify and isolate any systems having deployed either of these versions. Crowdstrike has also published several Indicators of Compromise (IOCs) to aid network defenders in the detection of malicious activity. <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<p>The Cyber Centre wishes to highlight that mitigation efforts resulting from the compromise of systems by competent threat actors may require more than simply mitigating individual issues, systems, servers. In cases such as these, based on the perceived sophistication of the threat actor involved, organizations should consider additional mitigative efforts besides simply the removal or updating of the product. The Cyber Centre recommends affected customers review the Cyber Centre joint cybersecurity advisory on technical approaches to uncovering and remediating malicious activity <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+18332923788\">1-833-CYBER-88<\/a> or <a href=\"tel:+18332923788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.crowdstrike.com\/blog\/new-supply-chain-attack-leverages-comm100-chat-installer\/\">CrowdStrike Falcon Platform Identifies Supply Chain Attack via a Trojanized Comm100 Chat Installer<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/news-events\/joint-cybersecurity-advisory\">Technical Approaches to Uncovering and Remediating Malicious Activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.comm100.com\/newsroom\/press\/security-incident-on-september-29-2022\/\" rel=\"external\">Comm100 Press Release<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/dash11.comm100.io\/kb\/100\/f9627b0c-6ff8-45c5-bdf5-b627f234d9bf\/a\/43c9deb2-b878-400a-93ea-ae73c516d95e\/how-to-remove-trojan-from-the-agent-console-windows-desktop-app-v10-0-8\" rel=\"external\">Comm100 Remediation Guidance<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/supply-chain-compromise-impacting-comm100-live-chat-software","alert_type":397,"serial_number":"AL22-012","subject":null,"moderation_state":"published","external_url":null},{"nid":3591,"title":"Ubuntu security advisory (AV22-548)","uuid":"0bc1ccc1-f2f5-4559-9cdd-175223b486bb","banner":null,"lang":"en","date_modified":"2022-10-03","date_modified_ts":"2022-10-03T16:51:10Z","date_created":"2022-10-03T16:38:08Z","summary":null,"body":["<article data-history-node-id=\"3591\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-548\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-548<\/strong><br \/><strong>Date: 3 October 2022<\/strong><\/p>\n\n<p>Between 26 September and 2 October 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu security notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-548","alert_type":396,"serial_number":"AV22-548","subject":null,"moderation_state":"published","external_url":null},{"nid":3592,"title":"IBM security advisory (AV22-549)","uuid":"ba0ad95f-ae7b-4e50-a96e-f0e875c8d37c","banner":null,"lang":"en","date_modified":"2022-10-03","date_modified_ts":"2022-10-03T17:04:08Z","date_created":"2022-10-03T17:03:24Z","summary":null,"body":["<article data-history-node-id=\"3592\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-549\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-549<\/strong><br \/><strong>Date: 3 October 2022<\/strong><\/p>\n\n<p>Between 26 September and 2 October 2022, IBM published Security Bulletins to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-549","alert_type":396,"serial_number":"AV22-549","subject":null,"moderation_state":"published","external_url":null},{"nid":3593,"title":"Dell security advisory (AV22-550)","uuid":"06acaaf5-1288-4db1-9843-aa772c45f25a","banner":null,"lang":"en","date_modified":"2022-10-03","date_modified_ts":"2022-10-03T17:45:07Z","date_created":"2022-10-03T17:16:05Z","summary":null,"body":["<article data-history-node-id=\"3593\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-550\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-550<\/strong><br \/><strong>Date: 3 October 2022<\/strong><\/p>\n\n<p>Between 26 September and 2 October 2022, Dell published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell EMC VPLEX VS2-Server-PE\u00a0\u2013 versions prior to BIOS 2.9.1 and versions prior to iDRAC 5.10.30.00<\/li>\n\t<li>PowerMax OS\u00a0\u2013 version 5978<\/li>\n\t<li>Solutions Enabler\u00a0\u2013 versions prior to 9.2.3.5<\/li>\n\t<li>Unisphere 360\u00a0\u2013 versions prior to 9.2.3.8<\/li>\n\t<li>Unisphere for PowerMax\u00a0\u2013 versions prior to 9.2.3.20<\/li>\n\t<li>eVASA Provider Virtual Appliance\u00a0\u2013 versions prior to 9.2.4.11<\/li>\n\t<li>VASA Provider Standalone\u00a0\u2013 versions prior to 9.2.4.21<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-550","alert_type":396,"serial_number":"AV22-550","subject":null,"moderation_state":"published","external_url":null},{"nid":3594,"title":"Google Chrome Security Advisory (AV22-551)","uuid":"02183d64-7e13-4f5b-b668-8db63d4bcb0d","banner":null,"lang":"en","date_modified":"2022-10-03","date_modified_ts":"2022-10-03T18:33:10Z","date_created":"2022-10-03T18:31:36Z","summary":null,"body":["<article data-history-node-id=\"3594\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-551\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-551<\/strong><br \/><strong>Date: 3 October 2022<\/strong><\/p>\n\n<p>On 30 September 2022, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 106.0.5249.91<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/09\/stable-channel-update-for-desktop_30.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-551","alert_type":396,"serial_number":"AV22-551","subject":null,"moderation_state":"published","external_url":null},{"nid":3595,"title":"Android Security Advisory \u2013 October 2022 Monthly Rollup (AV22-552)","uuid":"ec7a8017-57c2-4c39-9835-b9195357786e","banner":null,"lang":"en","date_modified":"2022-10-03","date_modified_ts":"2022-10-03T18:37:32Z","date_created":"2022-10-03T18:36:24Z","summary":null,"body":["<article data-history-node-id=\"3595\" about=\"\/en\/alerts-advisories\/android-security-advisory-october-2022-monthly-rollup-av22-552\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-552<\/strong><br \/><strong>Date: 3 October 2022<\/strong><\/p>\n\n<p>On 3 October 2022, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2022-10-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-october-2022-monthly-rollup-av22-552","alert_type":396,"serial_number":"AV22-552","subject":null,"moderation_state":"published","external_url":null},{"nid":3596,"title":"Microsoft Edge security advisory (AV22-553)","uuid":"721b3721-3103-4891-bfe0-8015eaa8e18f","banner":null,"lang":"en","date_modified":"2022-10-04","date_modified_ts":"2022-10-04T14:48:52Z","date_created":"2022-10-04T14:45:29Z","summary":null,"body":["<article data-history-node-id=\"3596\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-553\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-553<\/strong><br \/><strong>Date: 4 October 2022<\/strong><\/p>\n\n<p>On 3 October 2022, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 106.0.1370.34<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-3-2022\" rel=\"external\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-553","alert_type":396,"serial_number":"AV22-553","subject":null,"moderation_state":"published","external_url":null},{"nid":3601,"title":"[Control systems] Omron security advisory (AV22-554)","uuid":"4575933b-4cf7-4f8b-addc-c47fab972074","banner":null,"lang":"en","date_modified":"2022-10-05","date_modified_ts":"2022-10-05T15:09:39Z","date_created":"2022-10-05T14:57:40Z","summary":null,"body":["<article data-history-node-id=\"3601\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-554\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-554<\/strong><br \/><strong>Date: 5 October 2022<\/strong><\/p>\n\n<p>On 4 October 2022 ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>CX-Programmer: Version 9.78 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-277-04\" rel=\"external\">ICS Advisory (ICSA-22-277-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-554","alert_type":398,"serial_number":"AV22-554","subject":null,"moderation_state":"published","external_url":null},{"nid":3602,"title":"[Control systems] Becton, Dickinson and Company (BD) security advisory (AV22-555)","uuid":"d9b4de67-6648-4b32-80b8-21297c9ac841","banner":null,"lang":"en","date_modified":"2022-10-05","date_modified_ts":"2022-10-05T15:20:39Z","date_created":"2022-10-05T15:15:28Z","summary":null,"body":["<article data-history-node-id=\"3602\" about=\"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-bd-security-advisory-av22-555\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-555<\/strong><br \/><strong>Date: 5 October 2022<\/strong><\/p>\n\n<p>On 4 October 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>BD Totalys MultiProcessor \u2013 version 1.70 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-277-01\" rel=\"external\">ICS Advisory (ICSMA-22-277-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-bd-security-advisory-av22-555","alert_type":398,"serial_number":"AV22-555","subject":null,"moderation_state":"published","external_url":null},{"nid":3603,"title":"[Control systems] Johnson Controls Inc. security advisory (AV22-556) ","uuid":"fa7c7530-bb15-4d42-8c75-56ac9f298530","banner":null,"lang":"en","date_modified":"2022-10-05","date_modified_ts":"2022-10-05T15:27:41Z","date_created":"2022-10-05T15:24:54Z","summary":null,"body":["<article data-history-node-id=\"3603\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-inc-security-advisory-av22-556\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-556<\/strong><br \/><strong>Date: 5 October 2022<\/strong><\/p>\n\n<p>On 4 October 2022 ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Metasys ADX Server \u2013 version 12.0 running MVE<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-277-01\" rel=\"external\">ICS Advisory (ICSA-22-277-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-inc-security-advisory-av22-556","alert_type":398,"serial_number":"AV22-556","subject":null,"moderation_state":"published","external_url":null},{"nid":3604,"title":"[Control systems] Hitachi Energy security advisory (AV22-557)","uuid":"a9bfe597-e828-44cc-aeff-23edabe727e4","banner":null,"lang":"en","date_modified":"2022-10-05","date_modified_ts":"2022-10-05T15:39:29Z","date_created":"2022-10-05T15:36:19Z","summary":null,"body":["<article data-history-node-id=\"3604\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-557\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-557<\/strong><br \/><strong>Date: 5 October 2022<\/strong><\/p>\n\n<p>On 4 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Modular Switchgear Monitoring (MSM) \u2013 version 2.2 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in execution of arbitrary commands and impersonation of legitimate users.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-277-02\" rel=\"external\">ICS Advisory (ICSA-22-277-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-557","alert_type":398,"serial_number":"AV22-557","subject":null,"moderation_state":"published","external_url":null},{"nid":3605,"title":"[Control systems] Horner Automation security advisory (AV22-558)","uuid":"2d362c17-0f61-45fa-8c26-bd9575594528","banner":null,"lang":"en","date_modified":"2022-10-05","date_modified_ts":"2022-10-05T15:44:25Z","date_created":"2022-10-05T15:41:16Z","summary":null,"body":["<article data-history-node-id=\"3605\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av22-558\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-558<\/strong><br \/><strong>Date: 5 October 2022<\/strong><\/p>\n\n<p>On 4 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Cscape \u2013 version 9.90 SP 6 and prior<\/li>\n\t<li>Cscape \u2013 version 9.90 SP 7 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-277-03\" rel=\"external\">ICS Advisory (ICSA-22-277-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av22-558","alert_type":398,"serial_number":"AV22-558","subject":null,"moderation_state":"published","external_url":null},{"nid":3607,"title":"Cisco security advisory (AV22-559)","uuid":"a4feb85f-d857-495a-8eb1-1a62e8ecbfba","banner":null,"lang":"en","date_modified":"2022-10-05","date_modified_ts":"2022-10-05T18:07:30Z","date_created":"2022-10-05T18:06:46Z","summary":null,"body":["<article data-history-node-id=\"3607\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-559\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-559<\/strong><br \/><strong>Date: 5 October 2022<\/strong><\/p>\n\n<p>On 5 October 2022, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Enterprise NFV Infrastructure Software\u00a0\u2013 versions prior to 4.9.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-559","alert_type":396,"serial_number":"AV22-559","subject":null,"moderation_state":"published","external_url":null},{"nid":3608,"title":"[Control systems] Rockwell automation security advisory (AV22-560)","uuid":"051e5889-023d-4bb5-b080-2b65ed00a6b0","banner":null,"lang":"en","date_modified":"2022-10-06","date_modified_ts":"2022-10-06T18:48:36Z","date_created":"2022-10-06T18:46:16Z","summary":null,"body":["<article data-history-node-id=\"3608\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-560\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-560<\/strong><br \/><strong>Date: 6 October 2022<\/strong><\/p>\n\n<p>On 6 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>FactoryTalk VantagePoint\u00a0\u2013 firmware versions prior to 8.0<\/li>\n\t<li>FactoryTalk VantagePoint\u00a0\u2013 firmware versions between 8.0 and 8.10<\/li>\n\t<li>FactoryTalk VantagePoint\u00a0\u2013 firmware versions between 8.10 and 8.20<\/li>\n\t<li>FactoryTalk VantagePoint\u00a0\u2013 firmware versions between 8.20 and 8.30<\/li>\n\t<li>FactoryTalk VantagePoint\u00a0\u2013 firmware versions between 8.30 and 8.31<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-279-01\">ICS Advisory (ICSA-22-279-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-560","alert_type":398,"serial_number":"AV22-560","subject":null,"moderation_state":"published","external_url":null},{"nid":3609,"title":"[Control systems] HIWIN security advisory (AV22-561)","uuid":"01d61ae2-82e3-4d1a-926f-3bbe1487fa96","banner":null,"lang":"en","date_modified":"2022-10-06","date_modified_ts":"2022-10-06T18:53:54Z","date_created":"2022-10-06T18:52:37Z","summary":null,"body":["<article data-history-node-id=\"3609\" about=\"\/en\/alerts-advisories\/control-systems-hiwin-security-advisory-av22-561\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-561<\/strong>\n  <br \/><strong>Date: 6 October 2022<\/strong>\n<\/p>\n<p>On 6 October 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:\n<\/p>\n<ul><li>HIWIN Robot System Software (HRSS)\u00a0\u2013 version 3.3.21.9869<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-279-02\">ICS Advisory (ICSA-22-279-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hiwin-security-advisory-av22-561","alert_type":398,"serial_number":"AV22-561","subject":null,"moderation_state":"published","external_url":null},{"nid":3610,"title":"F5 security advisory (AV22-562)","uuid":"3adb1de7-3663-401f-b090-f7fab3d28e1e","banner":null,"lang":"en","date_modified":"2022-10-06","date_modified_ts":"2022-10-06T18:59:07Z","date_created":"2022-10-06T18:56:47Z","summary":null,"body":["<article data-history-node-id=\"3610\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-562\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-562<\/strong><br \/><strong>Date: 6 October 2022<\/strong><\/p>\n\n<p>On 6 October 2022, F5 published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>BIG-IP\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IQ Centralized Management\u00a0\u2013 version 7.1.0 and version 8.0.0 to 8.2.0<\/li>\n\t<li>Traffic SDC\u00a0\u2013 version 5.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K10812540\">F5 Security Advisory (K10812540)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-562","alert_type":396,"serial_number":"AV22-562","subject":null,"moderation_state":"published","external_url":null},{"nid":3611,"title":"Fortinet Security Advisory (AV22-563)","uuid":"e99c3f09-ba56-44d5-b880-b274f380ec4d","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T13:18:12Z","date_created":"2022-10-11T13:15:55Z","summary":null,"body":["<article data-history-node-id=\"3611\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-563\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-563<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 10 October 2022, Fortinet published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>FortiOS\u00a0\u2013 versions 7.0.0 to 7.0.6 and versions 7.2.0 to 7.2.1<\/li>\n\t<li>FortiProxy\u00a0\u2013 versions 7.0.0 to 7.0.6 and version 7.2.0<\/li>\n\t<li>FortiSwitchManager\u00a0\u2013 versions 7.0.0 and 7.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>Fortinet has received reports that this vulnerability has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-377\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-563","alert_type":396,"serial_number":"AV22-563","subject":null,"moderation_state":"published","external_url":null},{"nid":3614,"title":"IBM security advisory (AV22-564)","uuid":"9789651c-56e0-45ab-8f29-50774da49db6","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T17:57:20Z","date_created":"2022-10-11T17:55:11Z","summary":null,"body":["<article data-history-node-id=\"3614\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-564\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-564<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>Between 3 and 10 October 2022, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Content Manager OnDemand for z\/OS \u2013 versions 10.1.x and 10.5.x<\/li>\n\t<li>IBM HTTP Server \u2013 multiple versions<\/li>\n\t<li>IBM MaaS360 Cloud Extender Agent \u2013 version 2.106.500.011 and prior<\/li>\n\t<li>IBM MaaS360 Cloud Extender Base \u2013 version 2.106.500 and prior<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak \u2013 version 21.0.2<\/li>\n\t<li>IBM Tivoli Monitoring \u2013 version 6.3.0.7 Service Pack 12<\/li>\n\t<li>IBM Tivoli Netcool\/OMNIbus_GUI \u2013 version 8.1.0 FP27 and prior<\/li>\n\t<li>IBM z\/Transaction Processing Facility \u2013 version 1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-564","alert_type":396,"serial_number":"AV22-564","subject":null,"moderation_state":"published","external_url":null},{"nid":3615,"title":"Dell security advisory (AV22-565)","uuid":"070b3360-e267-4408-a7a4-e369a1f1764c","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T18:23:33Z","date_created":"2022-10-11T18:03:01Z","summary":null,"body":["<article data-history-node-id=\"3615\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-565\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-565<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>Between 3 and 10 October 2022, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC Avamar \u2013 multiple versions<\/li>\n\t<li>Dell EMC NetWorker Virtual Edition \u2013 multiple versions<\/li>\n\t<li>Dell EMC PowerProtect DP Series Appliance \/ Dell EMC Integrated Data Protection Appliance \u2013 multiple versions<\/li>\n\t<li>Dell EMC RecoverPoint for Virtual machines \u2013 multiple versions<\/li>\n\t<li>Dell EMC SRM \u2013 versions prior to 4.8.0.0<\/li>\n\t<li>Dell EMC Storage Monitoring and Reporting \u2013 versions prior to 4.8.0.0<\/li>\n\t<li>Dell Metronode VS5 \u2013 versions prior to 7.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca \" rel=\"external\">Dell Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-565","alert_type":396,"serial_number":"AV22-565","subject":null,"moderation_state":"published","external_url":null},{"nid":3616,"title":"Ubuntu security advisory (AV22-566)","uuid":"6e871a9c-e420-47cc-a287-8e761a0f821d","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T18:32:30Z","date_created":"2022-10-11T18:28:31Z","summary":null,"body":["<article data-history-node-id=\"3616\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-566\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-566<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>Between 3 and 10 October 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-566","alert_type":396,"serial_number":"AV22-566","subject":null,"moderation_state":"published","external_url":null},{"nid":3617,"title":"Apple security advisory (AV22-567)","uuid":"9d766232-dfaf-413e-bc7c-a81e72f24598","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T18:37:25Z","date_created":"2022-10-11T18:34:50Z","summary":null,"body":["<article data-history-node-id=\"3617\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-567\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-567<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 10 October 2022, Apple published a Security Update to address a vulnerability in the following product:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 16.0.3<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213480 \" rel=\"external\">Apple Security Update (HT213480)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-567","alert_type":396,"serial_number":"AV22-567","subject":null,"moderation_state":"published","external_url":null},{"nid":3618,"title":"Fortinet security advisory (AV22-568)","uuid":"566d8d20-005f-4cdc-8433-83b6ebb3748e","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T18:49:40Z","date_created":"2022-10-11T18:42:34Z","summary":null,"body":["<article data-history-node-id=\"3618\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-568\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-568<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 10 October 2022, Fortinet published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiTester \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-22-237\" rel=\"external\">Fortinet PSIRT Advisory (FG-IR-22-237)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\" rel=\"external\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-568","alert_type":396,"serial_number":"AV22-568","subject":null,"moderation_state":"published","external_url":null},{"nid":3619,"title":"[Control systems] Schneider Electric security advisory (AV22-569) ","uuid":"ea7d7e2f-d417-43ed-bfd9-6cf0c45bf484","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T19:02:04Z","date_created":"2022-10-11T18:51:21Z","summary":null,"body":["<article data-history-node-id=\"3619\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-569\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-569<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>EcoStruxure Power SCADA Operation \u2013 multiple versions<\/li>\n\t<li>SAGE RTU \u2013 multiple versions<\/li>\n\t<li>EcoStruxure Panel Server Box (PAS900) \u2013 version V3.1.16 and prior<\/li>\n\t<li>EcoStruxure Operator Terminal Expert \u2013 version V3.3 Hotfix 1 and prior<\/li>\n\t<li>Pro-face BLUE \u2013 version V3.3 Hotfix 1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp \" rel=\"external\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-569","alert_type":398,"serial_number":"AV22-569","subject":null,"moderation_state":"published","external_url":null},{"nid":3620,"title":"Microsoft security advisory \u2013 October 2022 monthly rollup (AV22-570)","uuid":"9a0c5683-0d44-4ce3-b706-bf9ceef32c07","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T19:10:27Z","date_created":"2022-10-11T19:03:54Z","summary":null,"body":["<article data-history-node-id=\"3620\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2022-monthly-rollup-av22-570\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-570<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Azure Arc-enabled Kubernetes cluster \u2013 multiple versions<\/li>\n\t<li>Azure Stack Edge<\/li>\n\t<li>Microsoft 365 Apps<\/li>\n\t<li>Microsoft Office \u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint \u2013 multiple versions<\/li>\n\t<li>Windows 7 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows RT 8.1<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2022-41033 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Oct\" rel=\"external\">October 2022 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\" rel=\"external\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-october-2022-monthly-rollup-av22-570","alert_type":396,"serial_number":"AV22-570","subject":null,"moderation_state":"published","external_url":null},{"nid":3621,"title":"[Control systems] Siemens security advisory (AV22-571) ","uuid":"c3272e25-e6c8-4f89-ae6e-533a2704f8fd","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T19:18:15Z","date_created":"2022-10-11T19:17:12Z","summary":null,"body":["<article data-history-node-id=\"3621\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-571\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-571<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cerberus DMS \u2013 all versions<\/li>\n\t<li>Desigo CC \u2013 all versions<\/li>\n\t<li>Desigo CC Compact \u2013 all versions<\/li>\n\t<li>LOGO! 8 BM \u2013 all versions<\/li>\n\t<li>SICAM P850 \u2013 multiple versions and platforms<\/li>\n\t<li>SICAM P855 \u2013 multiple versions and platforms<\/li>\n\t<li>SIMATIC Drive Controller family \u2013 versions prior to V2.9.2<\/li>\n\t<li>SIMATIC ET 200SP Open Controller CPU 1515SP PC2 \u2013 versions prior to V21.9<\/li>\n\t<li>SIMATIC ET 200SP Open Controller CPU 1515SP PC \u2013 all versions<\/li>\n\t<li>SIMATIC S7-1200 CPU family \u2013 versions prior to V4.5.0<\/li>\n\t<li>SIMATIC S7-1500 CPU family \u2013 versions prior to V2.9.2<\/li>\n\t<li>SIMATIC S7-1500 Software Controller \u2013 versions prior to V21.9<\/li>\n\t<li>SIMATIC S7-PLCSIM Advanced \u2013 versions prior to V4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications \" rel=\"external\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-571","alert_type":398,"serial_number":"AV22-571","subject":null,"moderation_state":"published","external_url":null},{"nid":3622,"title":"SAP security advisory \u2013 October 2022 monthly rollup (AV22-572)","uuid":"9c1000ff-7e06-446c-a212-0af2479257b3","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T19:23:25Z","date_created":"2022-10-11T19:20:09Z","summary":null,"body":["<article data-history-node-id=\"3622\" about=\"\/en\/alerts-advisories\/sap-security-advisory-october-2022-monthly-rollup-av22-572\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-572<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Commerce \u2013 versions 1905, 2005, 2105, 2011 and 2205<\/li>\n\t<li>SAP Manufacturing Execution \u2013 versions 15.1, 15.2 and 15.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\" rel=\"external\">SAP Security Patch Day \u2013 October 2022<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-october-2022-monthly-rollup-av22-572","alert_type":396,"serial_number":"AV22-572","subject":null,"moderation_state":"published","external_url":null},{"nid":3623,"title":"[Control systems] Sensormatic Electronics security advisory (AV22-573)","uuid":"30542816-ecfe-4a6d-939e-9c28cc41e093","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T19:57:58Z","date_created":"2022-10-11T19:55:10Z","summary":null,"body":["<article data-history-node-id=\"3623\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av22-573\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-573<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>C-CURE 9000 \u2013 version 2.90 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-284-03 \" rel=\"external\">ICS Advisory (ICSA-22-284-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av22-573","alert_type":398,"serial_number":"AV22-573","subject":null,"moderation_state":"published","external_url":null},{"nid":3624,"title":"[Control systems] Altair security advisory (AV22-574)","uuid":"db2ced74-a085-4275-9fee-6993fae7b58c","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T20:02:56Z","date_created":"2022-10-11T20:00:21Z","summary":null,"body":["<article data-history-node-id=\"3624\" about=\"\/en\/alerts-advisories\/control-systems-altair-security-advisory-av22-574\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-574<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>HyperView Player \u2013 versions 2021.1.0.27 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-284-01\" rel=\"external\">ICS Advisory (ICSA-22-284-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-altair-security-advisory-av22-574","alert_type":398,"serial_number":"AV22-574","subject":null,"moderation_state":"published","external_url":null},{"nid":3625,"title":"[Control systems] Daikin security advisory (AV22-575)","uuid":"bdb03156-d509-45f4-b5fa-1b42372e93bf","banner":null,"lang":"en","date_modified":"2022-10-11","date_modified_ts":"2022-10-11T20:07:50Z","date_created":"2022-10-11T20:05:47Z","summary":null,"body":["<article data-history-node-id=\"3625\" about=\"\/en\/alerts-advisories\/control-systems-daikin-security-advisory-av22-575\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-575<\/strong><br \/><strong>Date: 11 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>SVMPC1 \u2013 version 2.1.22 and prior<\/li>\n\t<li>SVMPC2 \u2013 version 1.2.3 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-284-02\" rel=\"external\">ICS Advisory (ICSA-22-284-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-daikin-security-advisory-av22-575","alert_type":398,"serial_number":"AV22-575","subject":null,"moderation_state":"published","external_url":null},{"nid":3627,"title":"Adobe security advisory (AV22-576)","uuid":"02b6cf1d-7102-44ce-b468-02e1ea32e85e","banner":null,"lang":"en","date_modified":"2022-10-12","date_modified_ts":"2022-10-12T20:31:39Z","date_created":"2022-10-12T19:54:10Z","summary":null,"body":["<article data-history-node-id=\"3627\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-576\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-576<\/strong>\n  <br \/><strong>Date: 12 October 2022<\/strong>\n<\/p>\n<p>On 11 October 2022, Adobe published Security Advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Acrobat 2020 \u2013 version 20.005.30381 and prior<\/li>\n  <li>Acrobat DC \u2013 version 22.002.20212 and prior<\/li>\n  <li>Acrobat Reader 2020 \u2013 version 20.005.30381 and prior<\/li>\n  <li>Acrobat Reader DC \u2013 version 22.002.20212 and prior<\/li>\n  <li>Adobe Commerce \u2013 multiple versions<\/li>\n  <li>Adobe Dimension \u2013 version 3.4.5 and prior<\/li>\n  <li>ColdFusion 2018 \u2013 version 14 and prior<\/li>\n  <li>ColdFusion 2021 \u2013 version 4 and prior<\/li>\n  <li>Magento Open Source \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/security-bulletin.html\" rel=\"external\">Adobe Security Advisories<\/a><\/li>\n\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-576","alert_type":396,"serial_number":"AV22-576","subject":null,"moderation_state":"published","external_url":null},{"nid":3628,"title":"HPE security advisory (AV22-577)","uuid":"c2f8f409-4054-48d8-8c59-f87bd061042b","banner":null,"lang":"en","date_modified":"2022-10-12","date_modified_ts":"2022-10-12T20:39:23Z","date_created":"2022-10-12T20:38:39Z","summary":null,"body":["<article data-history-node-id=\"3628\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-577\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-577<\/strong><br \/><strong>Date: 12 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, HPE published a Security Bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Aruba EdgeConnect Enterprise Orchestrator \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04373en_us\" rel=\"external\">HPE Security Bulletin (HPESBNW04373)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-577","alert_type":396,"serial_number":"AV22-577","subject":null,"moderation_state":"published","external_url":null},{"nid":3630,"title":"Palo Alto Networks security advisory (AV22-578)","uuid":"a4375451-e5c5-4ac4-98c9-67972615e344","banner":null,"lang":"en","date_modified":"2022-10-13","date_modified_ts":"2022-10-13T19:00:30Z","date_created":"2022-10-13T19:00:01Z","summary":null,"body":["<article data-history-node-id=\"3630\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-578\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-578<\/strong><br \/><strong>Date: 13 October 2022<\/strong><\/p>\n\n<p>On 12 October 2022, Palo Alto Networks published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>PAN-OS 8.1 - versions prior to 8.1.24<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2022-0030 \" rel=\"external\">Palo Alto Networks Security Advisory (CVE-2022-0030)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-578","alert_type":396,"serial_number":"AV22-578","subject":null,"moderation_state":"published","external_url":null},{"nid":3631,"title":"Pulse Secure security advisory (AV22-579)","uuid":"b15ff467-1759-489f-b9da-190613c08f3a","banner":null,"lang":"en","date_modified":"2022-10-14","date_modified_ts":"2022-10-14T18:00:11Z","date_created":"2022-10-14T17:57:56Z","summary":null,"body":["<article data-history-node-id=\"3631\" about=\"\/en\/alerts-advisories\/pulse-secure-security-advisory-av22-579\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-579<\/strong><br \/><strong>Date: 14 October 2022<\/strong><\/p>\n\n<p>On 13 October 2022, Pulse Secure published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Connect Secure\u00a0\u2013 multiple versions<\/li>\n\t<li>Ivanti Neurons for Zero-Trust Gateway\u00a0\u2013 versions prior to 22.3R1<\/li>\n\t<li>Ivanti Policy Secure\u00a0\u2013 versions prior to 9.1R17 and 22.3R1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.pulsesecure.net\/articles\/Pulse_Security_Advisories\/SA45520\/?kA23Z000000GH5OSAW\">Pulse Secure Security Advisory (SA45520)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/pulse-secure-security-advisory-av22-579","alert_type":396,"serial_number":"AV22-579","subject":null,"moderation_state":"published","external_url":null},{"nid":3632,"title":"Google Chrome Security Advisory (AV22-580)","uuid":"95c7b0cc-e804-458f-9b89-14c407f6dfcf","banner":null,"lang":"en","date_modified":"2022-10-14","date_modified_ts":"2022-10-14T18:04:57Z","date_created":"2022-10-14T18:03:35Z","summary":null,"body":["<article data-history-node-id=\"3632\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-580\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-580<\/strong><br \/><strong>Date: 14 October 2022<\/strong><\/p>\n\n<p>On 11 October 2022, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 106.0.5249.119<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/10\/stable-channel-update-for-desktop_11.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-580","alert_type":396,"serial_number":"AV22-580","subject":null,"moderation_state":"published","external_url":null},{"nid":3633,"title":"[Control systems] Hitachi Energy Security Advisory (AV22-581)","uuid":"fe87db06-bf41-4669-a433-96cd6fcfd7d7","banner":null,"lang":"en","date_modified":"2022-10-14","date_modified_ts":"2022-10-14T18:09:45Z","date_created":"2022-10-14T18:08:09Z","summary":null,"body":["<article data-history-node-id=\"3633\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-581\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-581<\/strong><br \/><strong>Date: 14 October 2022<\/strong><\/p>\n\n<p>On 13 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Lumada Asset Performance Manager\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-286-05\">ICS Advisory (ICSA-22-286-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-581","alert_type":398,"serial_number":"AV22-581","subject":null,"moderation_state":"published","external_url":null},{"nid":3634,"title":"Juniper Networks Security Advisory (AV22-582)","uuid":"f1049379-c4c7-4eb9-87be-205840dde702","banner":null,"lang":"en","date_modified":"2022-10-14","date_modified_ts":"2022-10-14T18:14:13Z","date_created":"2022-10-14T18:12:19Z","summary":null,"body":["<article data-history-node-id=\"3634\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-582\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-582<\/strong><br \/><strong>Date: 14 October 2022<\/strong><\/p>\n\n<p>On 12 October 2022, Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Contrail Networking\u00a0\u2013 versions prior to 2011.L5<\/li>\n\t<li>Junos Space\u00a0\u2013 versions prior to 22.2R1<\/li>\n\t<li>Session Smart Router\u00a0\u2013 versions prior to 5.4.7 and 5.5<\/li>\n\t<li>Steel Belted Radius Carrier Edition (64-bit Solaris and Linux)\u00a0\u2013 versions prior to 8.6.0R16<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=date%20descending&amp;f:ctype=[Security%20Advisories]\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-582","alert_type":396,"serial_number":"AV22-582","subject":null,"moderation_state":"published","external_url":null},{"nid":3636,"title":"Ubuntu security advisory (AV22-583)","uuid":"79af591a-09c2-4367-ba67-3598bcdac5a9","banner":null,"lang":"en","date_modified":"2022-10-17","date_modified_ts":"2022-10-17T20:02:47Z","date_created":"2022-10-17T20:01:44Z","summary":null,"body":["<article data-history-node-id=\"3636\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-583\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-583<\/strong><br \/><strong>Date: 17 October 2022<\/strong><\/p>\n\n<p>Between 11 and 16 October 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-583","alert_type":396,"serial_number":"AV22-583","subject":null,"moderation_state":"published","external_url":null},{"nid":3637,"title":"IBM security advisory (AV22-584)","uuid":"244e057c-2585-467b-9fab-19129c7098ae","banner":null,"lang":"en","date_modified":"2022-10-17","date_modified_ts":"2022-10-17T20:21:52Z","date_created":"2022-10-17T20:18:57Z","summary":null,"body":["<article data-history-node-id=\"3637\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-584\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-584<\/strong><br \/><strong>Date: 17 October 2022<\/strong><\/p>\n\n<p>Between 11 and 16 October 2022, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak System \u2013 multiple versions and platforms<\/li>\n\t<li>IBM Hortonworks DataFlow \u2013 version 3.5<\/li>\n\t<li>IBM InfoSphere Information Server \u2013 version 11.7<\/li>\n\t<li>IBM Watson Discovery \u2013 versions 4.0.0 to 4.5.1<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data \u2013 versions 4.0.0 to 4.5.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-584","alert_type":396,"serial_number":"AV22-584","subject":null,"moderation_state":"published","external_url":null},{"nid":3638,"title":"Dell security advisory (AV22-585)","uuid":"10a031c4-31f6-46a9-b7db-9a6ecec524b0","banner":null,"lang":"en","date_modified":"2022-10-17","date_modified_ts":"2022-10-17T20:36:23Z","date_created":"2022-10-17T20:27:48Z","summary":null,"body":["<article data-history-node-id=\"3638\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-585\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-585<\/strong><br \/><strong>Date: 17 October 2022<\/strong><\/p>\n\n<p>Between 10 and 16 October 2022, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Dell EMC PowerScale OneFS \u2013 multiple versions and platforms<\/li>\n\t<li>Dell Streaming Data Platform \u2013 versions 1.1.x, 1.2.x and 1.3.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-585","alert_type":396,"serial_number":"AV22-585","subject":null,"moderation_state":"published","external_url":null},{"nid":3639,"title":"[Control systems] Advantech security advisory (AV22-586)","uuid":"8eba8da1-27a2-4a65-abfe-8d23dcac7bff","banner":null,"lang":"en","date_modified":"2022-10-18","date_modified_ts":"2022-10-18T19:50:32Z","date_created":"2022-10-18T19:49:29Z","summary":null,"body":["<article data-history-node-id=\"3639\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-586\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-586<\/strong><br \/><strong>Date: 18 October 2022<\/strong><\/p>\n\n<p>On 18 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Advantech R-SeeNet \u2013 versions prior to 2.4.19<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote data modification or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-291-01\" rel=\"external\">ICS Advisory (ICSA-22-291-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-586","alert_type":398,"serial_number":"AV22-586","subject":null,"moderation_state":"published","external_url":null},{"nid":3640,"title":"Mozilla security advisory (AV22-587)","uuid":"4cdfa50f-e999-475a-9d58-48a82f605ed9","banner":null,"lang":"en","date_modified":"2022-10-18","date_modified_ts":"2022-10-18T19:57:09Z","date_created":"2022-10-18T19:53:06Z","summary":null,"body":["<article data-history-node-id=\"3640\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-587\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-587<\/strong><br \/><strong>Date: 18 October 2022<\/strong><\/p>\n\n<p>On 18 October 2022, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 106<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 102.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-44\/\" rel=\"external\">Mozilla Security Advisory (MFSA 2022-44)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-45\/\" rel=\"external\">Mozilla Security Advisory (MFSA 2022-45)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\" rel=\"external\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-587","alert_type":396,"serial_number":"AV22-587","subject":null,"moderation_state":"published","external_url":null},{"nid":3642,"title":"Oracle security advisory \u2013 October 2022 quarterly rollup (AV22-588)","uuid":"441c3131-6b5a-4236-a8c1-70ca7b79c9db","banner":null,"lang":"en","date_modified":"2022-10-19","date_modified_ts":"2022-10-19T20:19:54Z","date_created":"2022-10-19T20:19:02Z","summary":null,"body":["<article data-history-node-id=\"3642\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-october-2022-quarterly-rollup-av22-588\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-588<\/strong><br \/><strong>Date: 19 October 2022<\/strong><\/p>\n\n<p>On 18 October 2022, Oracle published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Application Management Pack for Oracle E-Business Suite \u2013 version 13.4.1.0.0<\/li>\n\t<li>Enterprise Manager Base Platform \u2013 version 13.4.0.0<\/li>\n\t<li>Enterprise Manager Ops Center \u2013 version 12.4.0.0<\/li>\n\t<li>JD Edwards EnterpriseOne Tools \u2013 version 9.2.6.3 and prior<\/li>\n\t<li>MySQL Enterprise Backup \u2013 version 4.1.4 and prior<\/li>\n\t<li>Oracle Agile Engineering Data Management \u2013 version 6.2.1.0<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition \u2013 version 5.9.0.0 and 6.4.0.0<\/li>\n\t<li>Oracle Commerce Platform \u2013 versions 11.3.0 to 11.3.2<\/li>\n\t<li>Oracle Communications \u2013 multiple versions and platforms<\/li>\n\t<li>Oracle Data Integrator \u2013 version 12.2.1.4.0<\/li>\n\t<li>Oracle Enterprise Operations Monitor \u2013 versions 4.4 and 5.0<\/li>\n\t<li>Oracle Financial Services Analytical Applications Infrastructure \u2013 multiple versions<\/li>\n\t<li>Oracle GoldenGate \u2013 version 19c<\/li>\n\t<li>Oracle GraalVM Enterprise Edition \u2013 multiple versions<\/li>\n\t<li>Oracle Healthcare Foundation \u2013 version 8.1 and 8.2<\/li>\n\t<li>Oracle HTTP Server \u2013 version 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle Hyperion Infrastructure Technology \u2013 version 11.2.9<\/li>\n\t<li>Oracle Middleware Common Libraries and Tools \u2013 version 12.2.1.3.0<\/li>\n\t<li>Oracle Outside In Technology \u2013 version 8.5.6<\/li>\n\t<li>Oracle Retail Fiscal Management \u2013 version 14.2<\/li>\n\t<li>Oracle SD-WAN Edge \u2013 version 7.0.7 and 9.1.1.2.0<\/li>\n\t<li>Oracle Secure Backup \u2013 versions prior to 18.1.0.2.0<\/li>\n\t<li>Oracle Utilities Testing Accelerator \u2013 multiple versions<\/li>\n\t<li>Oracle Web Applications Desktop Integrator \u2013 version 12.2.3 to 12.2.11<\/li>\n\t<li>Oracle WebCenter Content \u2013 version 12.2.1.3.0<\/li>\n\t<li>Oracle WebCenter Portal \u2013 version 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Oracle WebCenter Sites \u2013 version 12.2.1.3.0 and 12.2.1.4.0<\/li>\n\t<li>Siebel Apps (Marketing) \u2013 version 22.8 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuoct2022.html  \" rel=\"external\">Oracle Critical Patch Update Advisory \u2013 October 2022<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-october-2022-quarterly-rollup-av22-588","alert_type":396,"serial_number":"AV22-588","subject":null,"moderation_state":"published","external_url":null},{"nid":3643,"title":"F5 security advisory (AV22-589)","uuid":"baee6b9b-177c-4137-ab62-ce5db154065f","banner":null,"lang":"en","date_modified":"2022-10-19","date_modified_ts":"2022-10-19T20:27:59Z","date_created":"2022-10-19T20:22:22Z","summary":null,"body":["<article data-history-node-id=\"3643\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-589\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-589<\/strong><br \/><strong>Date: 19 October 2022<\/strong><\/p>\n\n<p>On 19 October 2022, F5 published Security Advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, apply the recommended mitigations and apply the necessary updates once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K30425568\" rel=\"external\">F5 Security Advisory (K30425568) \u2013 Overview of F5 vulnerabilities (October 2022)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.f5.com\/csp\/new-updated-articles\" rel=\"external\">F5 Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-589","alert_type":396,"serial_number":"AV22-589","subject":null,"moderation_state":"published","external_url":null},{"nid":3644,"title":"Adobe security advisory (AV22-590)","uuid":"5dcf0406-073c-4eaa-a82a-11e1e42856be","banner":null,"lang":"en","date_modified":"2022-10-19","date_modified_ts":"2022-10-19T20:35:35Z","date_created":"2022-10-19T20:31:32Z","summary":null,"body":["<article data-history-node-id=\"3644\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av22-590\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-590<\/strong><br \/><strong>Date: 19 October 2022<\/strong><\/p>\n\n<p>On 18 October 2022, Adobe published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Illustrator 2022 - version 26.4\u202fand\u202fprior\u202f<\/li>\n\t<li>Illustrator 2021 - version 25.4.7\u202fand\u202fprior\u202f<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/illustrator\/apsb22-56.html\" rel=\"external\">Adobe Security Advisory (APSB22-56)<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\" rel=\"external\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av22-590","alert_type":396,"serial_number":"AV22-590","subject":null,"moderation_state":"published","external_url":null},{"nid":3645,"title":"Cisco security advisory (AV22-591)","uuid":"897c6d3b-f2ab-4d7c-a858-46b936852cca","banner":null,"lang":"en","date_modified":"2022-10-19","date_modified_ts":"2022-10-19T20:41:44Z","date_created":"2022-10-19T20:40:39Z","summary":null,"body":["<article data-history-node-id=\"3645\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-591\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-591<\/strong><br \/><strong>Date: 19 October 2022<\/strong><\/p>\n\n<p>On 19 October 2022, Cisco published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Cisco Meraki MX Series - multiple versions and platforms<\/li>\n\t<li>Cisco Meraki Z3 Teleworker Gateway - multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\" rel=\"external\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-591","alert_type":396,"serial_number":"AV22-591","subject":null,"moderation_state":"published","external_url":null},{"nid":3648,"title":"[Control systems] Bentley Systems security advisory (AV22-592)","uuid":"c8eb61b1-5241-4b29-bf43-e2094c3ac225","banner":null,"lang":"en","date_modified":"2022-10-20","date_modified_ts":"2022-10-20T19:16:03Z","date_created":"2022-10-20T19:15:37Z","summary":null,"body":["<article data-history-node-id=\"3648\" about=\"\/en\/alerts-advisories\/control-systems-bentley-systems-security-advisory-av22-592\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-592<\/strong><br \/><strong>Date: 20 October 2022<\/strong><\/p>\n\n<p>On 20 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Bentley Systems MicroStation Connect - version 10.17.0.209 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-293-01\" rel=\"external\">ICS Advisory (ICSA-22-293-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bentley-systems-security-advisory-av22-592","alert_type":398,"serial_number":"AV22-592","subject":null,"moderation_state":"published","external_url":null},{"nid":3650,"title":"[Control Systems] Siemens security advisory (AV22-593) ","uuid":"1594c487-dfba-44ad-aaed-0b3e1b9bf2c8","banner":null,"lang":"en","date_modified":"2022-10-21","date_modified_ts":"2022-10-21T19:17:10Z","date_created":"2022-10-21T19:16:41Z","summary":null,"body":["<article data-history-node-id=\"3650\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-593\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-593<\/strong><br \/><strong>Date: 21 October 2022<\/strong><\/p>\n\n<p>On 21 October 2022, Siemens published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Siveillance Video Mobile Server V2022 R2 \u2013 versions prior to V22.2a<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-640732.html\" rel=\"external\">Siemens Security Advisory (SSA-640732)<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications \" rel=\"external\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-593","alert_type":398,"serial_number":"AV22-593","subject":null,"moderation_state":"published","external_url":null},{"nid":3651,"title":"IBM security advisory (AV22-594)","uuid":"47f47253-a037-4613-9304-38cb5d94a750","banner":null,"lang":"en","date_modified":"2022-10-24","date_modified_ts":"2022-10-24T17:12:17Z","date_created":"2022-10-24T17:06:24Z","summary":null,"body":["<article data-history-node-id=\"3651\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-594\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-594<\/strong><br \/><strong>Date: 24 October 2022<\/strong><\/p>\n\n<p>Between 17 and 23 October 2022, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>CP4BA \u2013 versions 21.0.3 and 22.0.1<\/li>\n\t<li>Enterprise Content Management System Monitor \u2013 version 5.5<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Infrastructure Management \u2013 all versions<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.1.x and 11.2.x<\/li>\n\t<li>IBM ECM CMIS and FileNet Collaboration Services \u2013 version 3.0.6<\/li>\n\t<li>IBM Maximo Scheduler Optimization \u2013 all versions<\/li>\n\t<li>IBM QRadar Pulse App \u2013 version 1.0.0 to 2.2.8<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak \u2013 versions prior to 21.0.5<\/li>\n\t<li>IBM Sterling Order Management \u2013 versions 9.5.x and 10.0<\/li>\n\t<li>QRadar User Behavior Analytics \u2013 version 4.1.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-594","alert_type":396,"serial_number":"AV22-594","subject":null,"moderation_state":"published","external_url":null},{"nid":3652,"title":"Ubuntu security advisory (AV22-595)","uuid":"68777aa9-b030-479e-8381-800fba897fd4","banner":null,"lang":"en","date_modified":"2022-10-24","date_modified_ts":"2022-10-24T17:17:42Z","date_created":"2022-10-24T17:14:25Z","summary":null,"body":["<article data-history-node-id=\"3652\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-595\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-595<\/strong><br \/><strong>Date: 24 October 2022<\/strong><\/p>\n\n<p>Between 17 and 23 October 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-595","alert_type":396,"serial_number":"AV22-595","subject":null,"moderation_state":"published","external_url":null},{"nid":3653,"title":"Apple security advisory (AV22-596)","uuid":"f08755e9-d932-45b8-bc01-d0acff76c1e4","banner":null,"lang":"en","date_modified":"2022-10-25","date_modified_ts":"2022-10-25T14:21:42Z","date_created":"2022-10-25T14:21:09Z","summary":null,"body":["<article data-history-node-id=\"3653\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-596\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-596<\/strong><br \/><strong>Date: 25 October 2022<\/strong><\/p>\n\n<p>On 24 October 2022, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 16.1<\/li>\n\t<li>iPadOS \u2013 versions prior to 16<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.7.1<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.6.1<\/li>\n\t<li>macOS Ventura \u2013 versions prior to 13<\/li>\n\t<li>Safari \u2013 versions prior to 16.1<\/li>\n\t<li>tvOS \u2013 versions prior to 16.1<\/li>\n\t<li>watchOS \u2013 versions prior to 9.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" rel=\"external\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-596","alert_type":396,"serial_number":"AV22-596","subject":null,"moderation_state":"published","external_url":null},{"nid":3656,"title":"[Control systems] Delta Electronics security advisory (AV22-597)","uuid":"3a57d9b1-f322-4dea-9fea-00db7f14d7bb","banner":null,"lang":"en","date_modified":"2022-10-25","date_modified_ts":"2022-10-25T19:16:13Z","date_created":"2022-10-25T19:15:43Z","summary":null,"body":["<article data-history-node-id=\"3656\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-597\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-597<\/strong><br \/><strong>Date: 25 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, ICS-CERT published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>DIAEnergie \u2013 versions prior to v1.9.01.002<\/li>\n\t<li>InfraSuite Device Master \u2013 version 00.00.01a and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, denial of service or data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-298-06 \" rel=\"external\">ICS Advisory (ICSA-22-298-06)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-298-07 \" rel=\"external\">ICS Advisory (ICSA-22-298-07)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-597","alert_type":396,"serial_number":"AV22-597","subject":null,"moderation_state":"published","external_url":null},{"nid":3657,"title":"VMware security advisory (AV22-598)","uuid":"0cbc9592-266f-407e-b7dd-0b48dc347775","banner":null,"lang":"en","date_modified":"2022-10-25","date_modified_ts":"2022-10-25T19:21:33Z","date_created":"2022-10-25T19:18:56Z","summary":null,"body":["<article data-history-node-id=\"3657\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-598\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-598<\/strong><br \/><strong>Date: 25 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, VMware published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>VMware Cloud Foundation (NSX-V) \u2013 versions prior to 3.11.0.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-00031.html\" rel=\"external\">VMSA-2022-00031<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-598","alert_type":396,"serial_number":"AV22-598","subject":null,"moderation_state":"published","external_url":null},{"nid":3658,"title":"[Control systems] Hitachi Energy security advisory (AV22-599)","uuid":"869196f7-6246-46c0-8702-b5c6b07c36b4","banner":null,"lang":"en","date_modified":"2022-10-25","date_modified_ts":"2022-10-25T19:43:57Z","date_created":"2022-10-25T19:42:43Z","summary":null,"body":["<article data-history-node-id=\"3658\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-599\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-599<\/strong><br \/><strong>Date: 25 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>On 25 October 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-298-04\" rel=\"external\">ICS Advisory (ICSA-22-298-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-599","alert_type":398,"serial_number":"AV22-599","subject":null,"moderation_state":"published","external_url":null},{"nid":3659,"title":"[Control systems] Haas automation security advisory (AV22-600)","uuid":"ef555d3e-f8aa-4c80-8c55-92942ee8914e","banner":null,"lang":"en","date_modified":"2022-10-26","date_modified_ts":"2022-10-26T11:29:07Z","date_created":"2022-10-26T11:25:46Z","summary":null,"body":["<article data-history-node-id=\"3659\" about=\"\/en\/alerts-advisories\/control-systems-haas-automation-security-advisory-av22-600\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-600<\/strong><br \/><strong>Date: 26 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Haas Controller\u00a0\u2013 version 100.20.000.1110<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-298-01\">ICS Advisory (ICSA-22-298-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-haas-automation-security-advisory-av22-600","alert_type":398,"serial_number":"AV22-600","subject":null,"moderation_state":"published","external_url":null},{"nid":3660,"title":"Google Chrome security advisory (AV22-601)","uuid":"d4a22080-8f61-4c33-8c08-d62f5a3243b5","banner":null,"lang":"en","date_modified":"2022-10-26","date_modified_ts":"2022-10-26T14:32:08Z","date_created":"2022-10-26T14:31:30Z","summary":null,"body":["<article data-history-node-id=\"3660\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-601\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-601<\/strong><br \/><strong>Date: 26 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/10\/stable-channel-update-for-desktop_25.html \" rel=\"external\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-601","alert_type":396,"serial_number":"AV22-601","subject":null,"moderation_state":"published","external_url":null},{"nid":3661,"title":"[Control systems] Johnson Controls security advisory (AV22-602)","uuid":"0f959871-c284-44b9-b5ea-665810c90de6","banner":null,"lang":"en","date_modified":"2022-10-26","date_modified_ts":"2022-10-26T15:28:33Z","date_created":"2022-10-26T15:28:01Z","summary":null,"body":["<article data-history-node-id=\"3661\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-602\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-602<\/strong><br \/><strong>Date: 26 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CEVAS \u2013 versions prior to 1.01.46<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-298-05\" rel=\"external\">ICS Advisory (ICSA-22-298-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av22-602","alert_type":398,"serial_number":"AV22-602","subject":null,"moderation_state":"published","external_url":null},{"nid":3662,"title":"[Control systems] HEIDENHAIN security advisory (AV22-603)","uuid":"1672aa6f-5376-47ab-9026-20fe0e039774","banner":null,"lang":"en","date_modified":"2022-10-26","date_modified_ts":"2022-10-26T15:35:34Z","date_created":"2022-10-26T15:32:10Z","summary":null,"body":["<article data-history-node-id=\"3662\" about=\"\/en\/alerts-advisories\/control-systems-heidenhain-security-advisory-av22-603\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-603<\/strong><br \/><strong>Date: 26 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HEIDENHAIN Controller TNC 640 \u2013 version 340590 07 SP5 running HEROS 5.08.3 controlling HARTFORD 5A-65E CNC machine<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure, data modification or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-298-02\" rel=\"external\">ICS Advisory (ICSA-22-298-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-heidenhain-security-advisory-av22-603","alert_type":398,"serial_number":"AV22-603","subject":null,"moderation_state":"published","external_url":null},{"nid":3663,"title":"[Control systems] AliveCor security advisory (AV22-604)","uuid":"0a6b19c8-50c9-4879-b9a5-8b29bb6018fd","banner":null,"lang":"en","date_modified":"2022-10-26","date_modified_ts":"2022-10-26T17:16:22Z","date_created":"2022-10-26T17:13:30Z","summary":null,"body":["<article data-history-node-id=\"3663\" about=\"\/en\/alerts-advisories\/control-systems-alivecor-security-advisory-av22-604\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-604<\/strong><br \/><strong>Date: 26 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Kardia Android application \u2013 version 5.17.1-754993421 and prior<\/li>\n\t<li>KardiaMobile IoT device \u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure, data modification or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-298-01\" rel=\"external\">ICS Advisory (ICSMA-22-298-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-alivecor-security-advisory-av22-604","alert_type":398,"serial_number":"AV22-604","subject":null,"moderation_state":"published","external_url":null},{"nid":3664,"title":"HPE security advisory (AV22-605)","uuid":"963c3127-7331-48d5-9965-6325595bec46","banner":null,"lang":"en","date_modified":"2022-10-26","date_modified_ts":"2022-10-26T20:02:40Z","date_created":"2022-10-26T20:01:53Z","summary":null,"body":["<article data-history-node-id=\"3664\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-605\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-605<\/strong><br \/><strong>Date: 26 October 2022<\/strong><\/p>\n\n<p>On 25 October 2022, HPE published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Aruba SD-WAN Software and Gateways\u00a0\u2013 version 8.7.0.0-2.3.0.6 and prior<\/li>\n\t<li>ArubaOS SD-WAN Gateways\u00a0\u2013 version 8.7.0.0-2.3.0.6 and prior<\/li>\n\t<li>ArubaOS Wi-Fi Controllers and Gateways\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04381en_us\" rel=\"external\">HPE Security Bulletin (HPESBNW04381<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-605","alert_type":396,"serial_number":"AV22-605","subject":null,"moderation_state":"published","external_url":null},{"nid":3666,"title":"[Control systems] SAUTER Controls security advisory (AV22-606)","uuid":"96fa13a6-e767-475c-9418-3cc1e39463b5","banner":null,"lang":"en","date_modified":"2022-10-27","date_modified_ts":"2022-10-27T17:12:31Z","date_created":"2022-10-27T17:12:03Z","summary":null,"body":["<article data-history-node-id=\"3666\" about=\"\/en\/alerts-advisories\/control-systems-sauter-controls-security-advisory-av22-606\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-606<\/strong><br \/><strong>Date: 27 October 2022<\/strong><\/p>\n\n<p>On 27 October 2022 ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SAUTER moduWeb \u2013 firmware version 2.7.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-300-02\" rel=\"external\">ICS Advisory (ICSA-22-300-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sauter-controls-security-advisory-av22-606","alert_type":398,"serial_number":"AV22-606","subject":null,"moderation_state":"published","external_url":null},{"nid":3668,"title":"[Control systems] Rockwell Automation security advisory (AV22-607)","uuid":"3ce4b074-b982-46fa-9791-c5d3561671df","banner":null,"lang":"en","date_modified":"2022-10-27","date_modified_ts":"2022-10-27T18:07:45Z","date_created":"2022-10-27T18:07:11Z","summary":null,"body":["<article data-history-node-id=\"3668\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-607\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-607<\/strong><br \/><strong>Date: 27 October 2022<\/strong><\/p>\n\n<p>On 27 October 2022, ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Stratix 5800 switches \u2013 versions prior to v16.12.01<\/li>\n\t<li>Stratix 5400\/5410 switches \u2013 versions prior to v15.2(7)E2<\/li>\n\t<li>FactoryTalk Alarm and Events Server \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-300-03\" rel=\"external\">ICS Advisory (ICSA-22-300-03)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-300-01\" rel=\"external\">ICS Advisory (ICSA-22-300-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-607","alert_type":398,"serial_number":"AV22-607","subject":null,"moderation_state":"published","external_url":null},{"nid":3670,"title":"Apple security advisory (AV22-608)","uuid":"9d836d16-efd2-49bd-9a4c-65a23314cc3d","banner":null,"lang":"en","date_modified":"2022-10-27","date_modified_ts":"2022-10-27T20:14:38Z","date_created":"2022-10-27T20:13:57Z","summary":null,"body":["<article data-history-node-id=\"3670\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-608\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-608<\/strong><br \/><strong>Date: 27 October 2022<\/strong><\/p>\n\n<p>On 27 October 2022, Apple published a Security Update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 15.7.1<\/li>\n\t<li>iPadOS \u2013 versions prior to 15.7.1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213490\" rel=\"external\">Apple Security Update (HT213490)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-608","alert_type":396,"serial_number":"AV22-608","subject":null,"moderation_state":"published","external_url":null},{"nid":3671,"title":"[Control systems] Trihedral security advisory (AV22-609)","uuid":"ba66afe0-c33f-4b11-a337-ccf5cae1f358","banner":null,"lang":"en","date_modified":"2022-10-28","date_modified_ts":"2022-10-28T14:33:00Z","date_created":"2022-10-28T14:30:25Z","summary":null,"body":["<article data-history-node-id=\"3671\" about=\"\/en\/alerts-advisories\/control-systems-trihedral-security-advisory-av22-609\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-609<\/strong><br \/><strong>Date: 27 October 2022<\/strong><\/p>\n\n<p>On 27 October 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>VTScada\u00a0\u2013 version 12.0.38 and prior configured to accept incoming HTTP(S) connections<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-300-04\" rel=\"external\">ICS Advisory (ICSA-22-300-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-trihedral-security-advisory-av22-609","alert_type":398,"serial_number":"AV22-609","subject":null,"moderation_state":"published","external_url":null},{"nid":3672,"title":"Microsoft Edge security advisory (AV22-610)","uuid":"2f100178-baf8-4a83-a015-f895ae18ecb3","banner":null,"lang":"en","date_modified":"2022-10-28","date_modified_ts":"2022-10-28T19:07:10Z","date_created":"2022-10-28T19:06:43Z","summary":null,"body":["<article data-history-node-id=\"3672\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-610\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-610<\/strong><br \/><strong>Date: 28 October 2022<\/strong><\/p>\n\n<p>On 27 October 2022, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 107.0.1418.24<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-27-2022\" rel=\"external\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-610","alert_type":396,"serial_number":"AV22-610","subject":null,"moderation_state":"published","external_url":null},{"nid":3673,"title":"Fortinet security advisory (AV22-611)","uuid":"65919b3e-1bc1-4245-ac72-5ed0ccc243d9","banner":null,"lang":"en","date_modified":"2022-10-28","date_modified_ts":"2022-10-28T19:21:34Z","date_created":"2022-10-28T19:20:06Z","summary":null,"body":["<article data-history-node-id=\"3673\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-611\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-611<\/strong><br \/><strong>Date: 28 October 2022<\/strong><\/p>\n\n<p>On 28 October 2022, Fortinet published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>FortiOS \u2013 multiple versions<\/li>\n\t<li>FortiManager \u2013 multiple versions<\/li>\n\t<li>FortiAnalyzer \u2013 multiple versions<\/li>\n\t<li>FortiDeceptor \u2013 multiple versions<\/li>\n\t<li>FortiDDoS \u2013 multiple versions<\/li>\n\t<li>FortiAuthenticator \u2013 multiple versions<\/li>\n\t<li>FortiMail \u2013 multiple versions<\/li>\n\t<li>FortiRecorder \u2013 multiple versions<\/li>\n\t<li>FortiProxy \u2013 version 7.0.0 to 7.0.3<\/li>\n\t<li>FortiSwitch \u2013 multiple versions<\/li>\n\t<li>FortiWeb \u2013 multiple versions<\/li>\n\t<li>FortiADCManager \u2013 multiple versions<\/li>\n\t<li>FortiSIEM \u2013 multiple versions<\/li>\n\t<li>FortiVoiceEnterprise \u2013 multiple versions<\/li>\n\t<li>FortiNDR \u2013 multiple versions<\/li>\n\t<li>FortiClientWindows \u2013 multiple versions<\/li>\n\t<li>FortiClientEMS \u2013 multiple versions<\/li>\n\t<li>FortiADC \u2013 multiple versions<\/li>\n\t<li>FortiTester \u2013 version 7.1.0 and prior<\/li>\n\t<li>FortiAIOps \u2013 version 1.0.x<\/li>\n\t<li>FortiAP \u2013 multiple versions<\/li>\n\t<li>FortiAP-W2 \u2013 multiple versions<\/li>\n\t<li>FortiClientMac \u2013 multiple versions<\/li>\n\t<li>FortiClientLinux \u2013 multiple versions<\/li>\n\t<li>FortiClientiOS \u2013 multiple versions<\/li>\n\t<li>FortiClientAndroid \u2013 multiple versions<\/li>\n\t<li>FortiIsolator \u2013 multiple versions<\/li>\n\t<li>FortiWAN \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-059\" rel=\"external\">Fortinet PSIRT Advisory (FG-IR-22-059)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\" rel=\"external\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-611","alert_type":396,"serial_number":"AV22-611","subject":null,"moderation_state":"published","external_url":null},{"nid":3674,"title":"Google Chrome security advisory (AV22-612)","uuid":"2e385166-4d8e-4a37-a147-8e7a5618097e","banner":null,"lang":"en","date_modified":"2022-10-28","date_modified_ts":"2022-10-28T19:26:38Z","date_created":"2022-10-28T19:23:26Z","summary":null,"body":["<article data-history-node-id=\"3674\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-612\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-612<\/strong><br \/><strong>Date: 28 October 2022<\/strong><\/p>\n\n<p>On 27 October 2022, Google published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2022-3723 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/10\/stable-channel-update-for-desktop_27.html\" rel=\"external\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-612","alert_type":396,"serial_number":"AV22-612","subject":null,"moderation_state":"published","external_url":null},{"nid":3676,"title":"IBM security advisory (AV22-613)","uuid":"6b56ad17-294a-414a-9a2c-60249458a7a3","banner":null,"lang":"en","date_modified":"2022-10-31","date_modified_ts":"2022-10-31T17:05:17Z","date_created":"2022-10-31T17:04:37Z","summary":null,"body":["<article data-history-node-id=\"3676\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-613\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-613<\/strong><br \/><strong>Date: 31 October 2022<\/strong><\/p>\n\n<p>Between 24 and 30 October 2022, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Business Automation Manager Open Editions \u2013 version 8.0.0<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps \u2013 versions 3.1, 3.2, 3.3 and 3.4<\/li>\n\t<li>IBM Cloud Pak System \u2013 version 2.3<\/li>\n\t<li>IBM Cloud Pak System Software Suite \u2013 version 2.3.3.0<\/li>\n\t<li>IBM Cloud Transformation Advisor \u2013 versions 2.0.1 to 3.3.0<\/li>\n\t<li>IBM QRadar SIEM \u2013 multiple versions<\/li>\n\t<li>IBM Security Guardium \u2013 versions 10.5, 10.6, 11.0, 11.1, 11.2, 11.3 and 11.4<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM\u00ae Db2\u00ae On Openshift \u2013 versions v11.5.x<\/li>\n\t<li>ICP \u2013 IBM Answer Retrieval for Watson Discovery \u2013 all versions<\/li>\n\t<li>Netcool Operations Insight \u2013 versions 1.4.x, 1.5.x and 1.6.x<\/li>\n\t<li>Voice Gateway \u2013 versions 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.7.1 and 1.0.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-613","alert_type":396,"serial_number":"AV22-613","subject":null,"moderation_state":"published","external_url":null},{"nid":3677,"title":"Ubuntu security advisory (AV22-614)","uuid":"a25f8c60-9483-41db-9ed1-21fc095e38a5","banner":null,"lang":"en","date_modified":"2022-10-31","date_modified_ts":"2022-10-31T17:28:32Z","date_created":"2022-10-31T17:28:03Z","summary":null,"body":["<article data-history-node-id=\"3677\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-614\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-614<\/strong><br \/><strong>Date: 31 October 2022<\/strong><\/p>\n\n<p>Between 24 and 30 October 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\" rel=\"external\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-614","alert_type":396,"serial_number":"AV22-614","subject":null,"moderation_state":"published","external_url":null},{"nid":3678,"title":"Dell security advisory (AV22-615)","uuid":"57d746b1-a760-4a41-8745-320d41d19bd6","banner":null,"lang":"en","date_modified":"2022-10-31","date_modified_ts":"2022-10-31T17:38:10Z","date_created":"2022-10-31T17:37:43Z","summary":null,"body":["<article data-history-node-id=\"3678\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-615\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-615<\/strong><br \/><strong>Date: 31 October 2022<\/strong><\/p>\n\n<p>Between 24 and 30 October 2022, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Dell EMC Data Protection Central \u2013 versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, and 19.7<\/li>\n\t<li>PowerProtect DP Series Appliance \u2013 version 2.5<\/li>\n\t<li>Dell VxRail Appliance \u2013 version 7.0.x prior to 7.0.401<\/li>\n\t<li>PowerStore T OS \u2013 versions prior to 3.2.0.0-1828615<\/li>\n\t<li>PowerStore X OS \u2013 versions prior to 3.2.0.0-1828615<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca \" rel=\"external\">Dell Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-615","alert_type":396,"serial_number":"AV22-615","subject":null,"moderation_state":"published","external_url":null},{"nid":3679,"title":"Microsoft Edge security advisory (AV22-616)","uuid":"7be6d622-6ea0-472a-ab35-404425218ea5","banner":null,"lang":"en","date_modified":"2022-11-01","date_modified_ts":"2022-11-01T15:17:59Z","date_created":"2022-11-01T15:17:28Z","summary":null,"body":["<article data-history-node-id=\"3679\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-616\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-616<\/strong><br \/><strong>Date: 1 November 2022<\/strong><\/p>\n\n<p>On 31 October 2022, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 107.0.1418.26<\/li>\n\t<li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 106.0.1370.61<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2022-3723 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-31-2022\" rel=\"external\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-616","alert_type":396,"serial_number":"AV22-616","subject":null,"moderation_state":"published","external_url":null},{"nid":3680,"title":"OpenSSL security advisory (AV22-617)","uuid":"e9126dd9-e41f-4964-8026-e395fe08a0c5","banner":null,"lang":"en","date_modified":"2022-11-01","date_modified_ts":"2022-11-01T18:49:19Z","date_created":"2022-11-01T18:48:50Z","summary":null,"body":["<article data-history-node-id=\"3680\" about=\"\/en\/alerts-advisories\/openssl-security-advisory-av22-617\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-617<\/strong><br \/><strong>Date: 1 November 2022<\/strong><\/p>\n\n<p>On 1 November 2022, OpenSSL published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSL - versions 3.0.0 to 3.0.6<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities may lead to remote code execution or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.openssl.org\/news\/secadv\/20221101.txt\" rel=\"external\">OpenSSL Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory-av22-617","alert_type":396,"serial_number":"AV22-617","subject":null,"moderation_state":"published","external_url":null},{"nid":3681,"title":"F5 security advisory (AV22-618)","uuid":"b13d41c6-eeb1-4e90-a20e-d444d7bbc157","banner":null,"lang":"en","date_modified":"2022-11-01","date_modified_ts":"2022-11-01T19:42:30Z","date_created":"2022-11-01T19:40:08Z","summary":null,"body":["<article data-history-node-id=\"3681\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-618\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-618<\/strong><br \/><strong>Date: 1 November 2022<\/strong><\/p>\n\n<p>On 31 October 2022, F5 published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions and platforms<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 versions 7.1.0 and 8.0.0 to 8.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, apply the recommended mitigations and apply the necessary updates once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K44454157 \" rel=\"external\">F5 Security Advisory (K44454157) <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-618","alert_type":396,"serial_number":"AV22-618","subject":null,"moderation_state":"published","external_url":null},{"nid":3682,"title":"Fortinet security advisory (AV22-619)","uuid":"16ae3778-facf-4b62-9275-9ec67c91daad","banner":null,"lang":"en","date_modified":"2022-11-01","date_modified_ts":"2022-11-01T20:02:03Z","date_created":"2022-11-01T20:01:25Z","summary":null,"body":["<article data-history-node-id=\"3682\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-619\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-619<\/strong><br \/><strong>Date: 1 November 2022<\/strong><\/p>\n\n<p>On 1 November 2022, Fortinet published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FortiADC \u2013 versions 6.2.0 to 6.2.4, 7.0.0 to 7.0.2, and 7.1<\/li>\n\t<li>FortiAnalyzer \u2013 versions 6.2, 6.4.0 to 6.4.8, and 7.0.0 through 7.0.4<\/li>\n\t<li>FortiManager \u2013 versions 6.2 and 6.4.0 to 6.4.8<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to cross-site scripting.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-232\" rel=\"external\">Fortinet PSIRT Advisory (FG-IR-22-059)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-314\" rel=\"external\">Fortinet PSIRT Advisory (FG-IR-22-314)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-228\" rel=\"external\">Fortinet PSIRT Advisory (FG-IR-21-228)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\" rel=\"external\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-619","alert_type":396,"serial_number":"AV22-619","subject":null,"moderation_state":"published","external_url":null},{"nid":3683,"title":"Cisco security advisory (AV22-620)","uuid":"2451c887-1b82-461d-bfb8-3f30b09b7ea3","banner":null,"lang":"en","date_modified":"2022-11-02","date_modified_ts":"2022-11-02T19:32:40Z","date_created":"2022-11-02T19:31:35Z","summary":null,"body":["<article data-history-node-id=\"3683\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-620\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-620<\/strong><br \/><strong>Date: 2 November 2022<\/strong><\/p>\n\n<p>On 2 November 2022, Cisco published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Identity Services Engine (ISE) Software \u2013 multiple versions<\/li>\n\t<li>Cisco BroadWorks CommPilot Application Software \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-csrf-vgNtTpAs\" rel=\"external\">Cisco Security Advisory (cisco-sa-ise-csrf-vgNtTpAs)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-broadworks-ssrf-BJeQfpp\" rel=\"external\">Cisco Security Advisory (cisco-sa-broadworks-ssrf-BJeQfpp)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\" rel=\"external\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-620","alert_type":396,"serial_number":"AV22-620","subject":null,"moderation_state":"published","external_url":null},{"nid":3684,"title":"[Control systems] ETIC Telecom security advisory (AV22-621)","uuid":"94eb4f33-5eb7-48a8-8885-ffda9bf74dd0","banner":null,"lang":"en","date_modified":"2022-11-03","date_modified_ts":"2022-11-03T17:48:31Z","date_created":"2022-11-03T17:44:50Z","summary":null,"body":["<article data-history-node-id=\"3684\" about=\"\/en\/alerts-advisories\/control-systems-etic-telecom-security-advisory-av22-621\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-621<\/strong><br \/><strong>Date: 3 November 2022<\/strong><\/p>\n\n<p>On 3 November 2022, ICS-CERT published an ICS Advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ETIC Telecom Remote Access Server (RAS) \u2013 version 4.5.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in access to sensitive information or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-307-01\" rel=\"external\">ICS Advisory (ICSA-22-307-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-etic-telecom-security-advisory-av22-621","alert_type":398,"serial_number":"AV22-621","subject":null,"moderation_state":"published","external_url":null},{"nid":3685,"title":"IBM security advisory (AV22-622)","uuid":"96f11c7d-e24f-4c26-9221-cea9b58d8e66","banner":null,"lang":"en","date_modified":"2022-11-07","date_modified_ts":"2022-11-07T19:33:46Z","date_created":"2022-11-07T19:25:05Z","summary":null,"body":["<article data-history-node-id=\"3685\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-622\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-622<\/strong><br \/><strong>Date: 7 November 2022<\/strong><\/p>\n\n<p>Between 31 October and 6 November 2022, IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>AIX \u2013 version 7.3<\/li>\n\t<li>App Connect Enterprise Certified Container \u2013 versions 4.1, 4.2, 5.0, 5.0-lts, 5.1, 5.2 and 6.0<\/li>\n\t<li>IBM Cloud Object System \u2013 version 3.16.8.49 and prior<\/li>\n\t<li>IBM Cloud Pak for Security \u2013 versions 1.8.0.0, 1.8.1.0, 1.9.0.0 and 1.9.1.0<\/li>\n\t<li>IBM Cloud Transformation Advisor \u2013 versions 2.0.1 to 3.3.0<\/li>\n\t<li>IBM InfoSphere Information Server \u2013 version 11.7<\/li>\n\t<li>IBM PureData System for Operational Analytics \u2013 version 1.1<\/li>\n\t<li>IBM QRadar SIEM \u2013 multiple versions<\/li>\n\t<li>IBM Security Verify Access and Access Docker \u2013 version 10.0.0<\/li>\n\t<li>IBM SPSS Modeler Client, Server and Solution Publisher \u2013 versions 18.3 and 18.4<\/li>\n\t<li>IBM SPSS Modeler Collaboration and Deployment Services Adapter \u2013 versions 18.3 and 18.4<\/li>\n\t<li>Voice Gateway \u2013 versions 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.7.1 and 1.0.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-622","alert_type":396,"serial_number":"AV22-622","subject":null,"moderation_state":"published","external_url":null},{"nid":3686,"title":"Dell security advisory (AV22-623)","uuid":"b00261ee-f145-4082-af17-5ed415f1185b","banner":null,"lang":"en","date_modified":"2022-11-07","date_modified_ts":"2022-11-07T21:32:20Z","date_created":"2022-11-07T21:28:27Z","summary":null,"body":["<article data-history-node-id=\"3686\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-623\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-623<\/strong><br \/><strong>Date: 7 November 2022<\/strong><\/p>\n\n<p>Between 31 October and 6 November 2022, Dell published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell EMC Cyber Recovery\u00a0\u2013 versions prior to 19.12<\/li>\n\t<li>Dell ESXi\u00a0\u2013 versions prior to 6.7 P07<\/li>\n\t<li>Dell PowerProtect Data Manager\u00a0\u2013 version 19.11 and prior<\/li>\n\t<li>R630 and R730xd Ready node\u00a0\u2013 PowerEdge bios 13g versions prior to 2.15.0<\/li>\n\t<li>Dell XC\u00a0\u2013 versions prior to RIM-2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-623","alert_type":396,"serial_number":"AV22-623","subject":null,"moderation_state":"published","external_url":null},{"nid":3687,"title":"Android security advisory \u2013 November 2022 monthly rollup (AV22-624)","uuid":"b9ecf572-cf57-4271-af60-7488eebea9ae","banner":null,"lang":"en","date_modified":"2022-11-08","date_modified_ts":"2022-11-08T15:25:46Z","date_created":"2022-11-08T15:07:50Z","summary":null,"body":["<article data-history-node-id=\"3687\" about=\"\/en\/alerts-advisories\/android-security-advisory-november-2022-monthly-rollup-av22-624\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-624<\/strong><br \/><strong>Date: 8 November 2022<\/strong><\/p>\n\n<p>On 7 November 2022, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2022-11-01\" rel=\"external\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-november-2022-monthly-rollup-av22-624","alert_type":396,"serial_number":"AV22-624","subject":null,"moderation_state":"published","external_url":null},{"nid":3688,"title":"Red Hat security advisory (AV22-625)","uuid":"1eb8e327-80a7-4bd9-ad52-0230bb6c52ca","banner":null,"lang":"en","date_modified":"2022-11-08","date_modified_ts":"2022-11-08T18:21:32Z","date_created":"2022-11-08T18:18:58Z","summary":null,"body":["<article data-history-node-id=\"3688\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-625\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-625<\/strong><br \/><strong>Date: 8 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates to address Linux kernel vulnerabilities in the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux 8\u00a0\u2013 multiple platforms<\/li>\n\t<li>Red Hat Enterprise Linux 8 Real Time\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:7683\">Red Hat security advisory (RHSA-2022:7683)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:7444\">Red Hat security advisory (RHSA-2022:7444)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/\">Red Hat security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-625","alert_type":396,"serial_number":"AV22-625","subject":null,"moderation_state":"published","external_url":null},{"nid":3689,"title":"SAP security advisory \u2013 November 2022 monthly rollup (AV22-626)","uuid":"f9ef2a3e-3f83-4f12-a63b-995a0b7c41a8","banner":null,"lang":"en","date_modified":"2022-11-08","date_modified_ts":"2022-11-08T18:27:27Z","date_created":"2022-11-08T18:24:49Z","summary":null,"body":["<article data-history-node-id=\"3689\" about=\"\/en\/alerts-advisories\/sap-security-advisory-november-2022-monthly-rollup-av22-626\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-626<\/strong><br \/><strong>Date: 8 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Commerce\u00a0\u2013 versions 1905, 2005, 2105, 2011 and 2205<\/li>\n\t<li>SAP Business Objects Business Intelligence Platform\u00a0\u2013 versions 4.2 and 4.3<\/li>\n\t<li>SAPUI5\u00a0\u2013 versions 600, 700, 800, 900 and 1000<\/li>\n\t<li>SAPUI5 Client Runtime \u2013 versions 754, 755, 756 and 757<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day\u00a0\u2013 November 2022 (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-november-2022-monthly-rollup-av22-626","alert_type":396,"serial_number":"AV22-626","subject":null,"moderation_state":"published","external_url":null},{"nid":3690,"title":"Microsoft security advisory \u2013 November 2022 monthly rollup (AV22-627)","uuid":"32c58162-921b-4ac7-985e-99d491cf497c","banner":null,"lang":"en","date_modified":"2022-11-08","date_modified_ts":"2022-11-08T20:03:21Z","date_created":"2022-11-08T20:01:03Z","summary":null,"body":["<article data-history-node-id=\"3690\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-november-2022-monthly-rollup-av22-627\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-627<\/strong><br \/><strong>Date: 8 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Azure CLI<\/li>\n\t<li>Microsoft Exchange Server \u2013 multiple versions<\/li>\n\t<li>Windows 7 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows RT 8.1<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2022-41091, CVE-2022-41128, CVE-2022-41073 and CVE-2022-41125 have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Nov\">November 2022 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-november-2022-monthly-rollup-av22-627","alert_type":396,"serial_number":"AV22-627","subject":null,"moderation_state":"published","external_url":null},{"nid":3692,"title":"VMware security advisory (AV22-628)","uuid":"8e30b42c-dceb-461f-98cb-b064cb965b91","banner":null,"lang":"en","date_modified":"2022-11-09","date_modified_ts":"2022-11-09T18:14:36Z","date_created":"2022-11-09T18:13:09Z","summary":null,"body":["<article data-history-node-id=\"3692\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-628\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-628<\/strong><br \/><strong>Date: 9 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, VMware published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Workspace ONE Assist \u2013 versions 21.x and 22.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow an unauthenticated actor to obtain administrative access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0028.html\">VMSA-2022-0028<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-628","alert_type":396,"serial_number":"AV22-628","subject":null,"moderation_state":"published","external_url":null},{"nid":3693,"title":"Citrix security advisory (AV22-629)","uuid":"159ecc56-0788-49cd-a624-3fe51aac5f09","banner":null,"lang":"en","date_modified":"2022-11-09","date_modified_ts":"2022-11-09T20:00:09Z","date_created":"2022-11-09T19:58:30Z","summary":null,"body":["<article data-history-node-id=\"3693\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-629\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-629<\/strong><br \/><strong>Date: 9 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, Citrix published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Citrix ADC \u2013 multiple versions<\/li>\n\t<li>Citrix Gateway \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX463706\/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516\">CTX463706<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-629","alert_type":396,"serial_number":"AV22-629","subject":null,"moderation_state":"published","external_url":null},{"nid":3694,"title":"Cisco security advisory (AV22-630)","uuid":"b8449691-b106-45b1-a864-431633129bc6","banner":null,"lang":"en","date_modified":"2022-11-09","date_modified_ts":"2022-11-09T20:13:34Z","date_created":"2022-11-09T20:11:51Z","summary":null,"body":["<article data-history-node-id=\"3694\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-630\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-630<\/strong><br \/><strong>Date: 9 November 2022<\/strong><\/p>\n\n<p>On 9 November 2022, Cisco published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ASA 5500-X Series<\/li>\n\t<li>Firepower 4100 Series<\/li>\n\t<li>Firepower 9300 Series<\/li>\n\t<li>Cisco ASA Software \u2013 multiple versions<\/li>\n\t<li>Cisco FMC Software \u2013 multiple versions<\/li>\n\t<li>Cisco FTD Software \u2013 multiple versions<\/li>\n\t<li>Cisco NGIPS Software \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure or cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-630","alert_type":396,"serial_number":"AV22-630","subject":null,"moderation_state":"published","external_url":null},{"nid":3695,"title":"Google Chrome security advisory (AV22-631)","uuid":"f23d7ad2-26b2-48dd-8fa9-4c889d9ee9de","banner":null,"lang":"en","date_modified":"2022-11-09","date_modified_ts":"2022-11-09T21:22:34Z","date_created":"2022-11-09T21:09:59Z","summary":null,"body":["<article data-history-node-id=\"3695\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-631\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-631<\/strong><br \/><strong>Date: 9 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for desktop\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/11\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-631","alert_type":396,"serial_number":"AV22-631","subject":null,"moderation_state":"published","external_url":null},{"nid":3696,"title":"Intel security advisory (AV22-632)","uuid":"16aaaac5-f4ea-403a-abb0-20ba1c00c791","banner":null,"lang":"en","date_modified":"2022-11-10","date_modified_ts":"2022-11-10T15:45:02Z","date_created":"2022-11-10T15:42:16Z","summary":null,"body":["<article data-history-node-id=\"3696\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av22-632\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-632<\/strong><br \/><strong>Date: 10 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, Intel published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Active Management Technology (AMT)\u00a0\u2013 multiple versions<\/li>\n\t<li>Active Management Technology SDK\u00a0\u2013 versions prior to 16.0.4.1<\/li>\n\t<li>Converged Security and Manageability Engine (CSME)\u00a0\u2013 multiple versions<\/li>\n\t<li>Data Center Manager (DCM)\u00a0\u2013 versions prior to 5.0<\/li>\n\t<li>Endpoint Management Assistant (EMA)\u00a0\u2013 versions prior to 1.7.1<\/li>\n\t<li>Intel XMM 7560 Modem M.2 software\u00a0\u2013 versions prior to M2_7560_R_01.2146.00<\/li>\n\t<li>Manageability Commander (MC)\u00a0\u2013 versions prior to 2.3.2<\/li>\n\t<li>NUC BIOS firmware\u00a0\u2013 multiple platforms and versions<\/li>\n\t<li>Processors\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Server Boards and Systems\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Server Platform Services (SPS)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av22-632","alert_type":396,"serial_number":"AV22-632","subject":null,"moderation_state":"published","external_url":null},{"nid":3697,"title":"[Control systems] Schneider electric security advisory (AV22-633) ","uuid":"c8652e4b-7f0f-47e6-b230-7f733e29c2c9","banner":null,"lang":"en","date_modified":"2022-11-10","date_modified_ts":"2022-11-10T15:52:57Z","date_created":"2022-11-10T15:49:09Z","summary":null,"body":["<article data-history-node-id=\"3697\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-633\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-633<\/strong><br \/><strong>Date: 10 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>NetBotz 4 355\/450\/455\/550\/570\u00a0\u2013 version V4.7.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-312-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-312-01-NetBotz_4_Security_Notification.pdf\">Schneider Electric Security Notification (SEVD-2022-312-01) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av22-633","alert_type":398,"serial_number":"AV22-633","subject":null,"moderation_state":"published","external_url":null},{"nid":3698,"title":"[Control systems] Siemens security advisory (AV22-634)","uuid":"29ab3538-5780-4e25-9557-5a13ec12888a","banner":null,"lang":"en","date_modified":"2022-11-10","date_modified_ts":"2022-11-10T16:02:37Z","date_created":"2022-11-10T15:57:41Z","summary":null,"body":["<article data-history-node-id=\"3698\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-634\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-634<\/strong><br \/><strong>Date: 10 November 2022<\/strong><\/p>\n\n<p>On 8 November 2022, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>ModelSim Simulation\u00a0\u2013 all versions<\/li>\n\t<li>POWER METER SICAM Q100\u00a0\u2013 versions prior to V2.50<\/li>\n\t<li>Questa Simulation\u00a0\u2013 all versions<\/li>\n\t<li>SCALANCE W1750D\u00a0\u2013 all versions<\/li>\n\t<li>SCALANCE X-200 and X200IRT\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SINUMERIK ONE\u00a0\u2013 all versions<\/li>\n\t<li>SINUMERIK MC\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-634","alert_type":398,"serial_number":"AV22-634","subject":null,"moderation_state":"published","external_url":null},{"nid":3699,"title":"Ongoing reports of Qakbot malware incidents \u2013 Update 2","uuid":"c4a7c87b-4aed-43e9-9a69-c8c12456d3cf","banner":null,"lang":"en","date_modified":"2023-02-08","date_modified_ts":"2023-02-08T16:21:20Z","date_created":"2022-11-10T16:24:09Z","summary":null,"body":["<article data-history-node-id=\"3699\" about=\"\/en\/alerts-advisories\/ongoing-reports-qakbot-malware-incidents\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:&nbsp;<\/strong>AL22-013\n  <br>\n  <strong>Date:&nbsp;<\/strong>10 November 2022\n  <br>\n  <strong>Updated: <\/strong>16 February 2023\n<\/p>\n<h2>Audience\n<\/h2>\n<p>This Alert is intended for IT professionals and managers of notified organizations.\n<\/p>\n<h2>Purpose\n<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n<\/p>\n<h2>Details\n<\/h2>\n<p>Throughout 2022, the Cyber Centre has observed several waves of reporting from Canadian organizations related to Qakbot compromises. Similar activity has been reported in numerous countries. The compromises do not seem to be targeted to a specific sector or geographical location.\n<\/p>\n<p>Qakbot, also known as Qbot or Pinkslipbot, began as information-stealing malware targeting financial institutions but has since evolved in both its functionality and the industries it targets. The malware is modular in nature and offers a variety of capabilities, including the ability to steal sensitive data and to propagate inside a network. These added capabilities can be downloaded by the malware post-compromise. In recent years, Qakbot has been observed acting as a \u201cstage one\u201d malware responsible for downloading other malicious payloads such as ransomware or Cobalt Strike.\n<\/p>\n<p>Qakbot is commonly delivered using many phishing methods including via malicious emails, which come from previously unseen email addresses or as replies to existing email conversations&nbsp;<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>&nbsp;<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. The reuse of existing email conversations has been particularly effective as the emails appear to come from a trusted source, often from someone with whom the email recipient has recently been in communication. This technique results in a convincing message that an unsuspecting recipient may believe to be legitimate and feels safe to click a link which downloads a malicious ZIP file or to open an attached HTML file with the malicious ZIP file embedded.\n<\/p>\n<p>Good deception tactics by the threat actor may lead the user to open the ZIP file (often password protected) and then open a series of embedded files leading to the malware itself. In recent months, one of the embedded files has been an ISO file, which is opened as a folder in Windows. This is one method that threat actors use in an attempt to bypass Mark of the Web protections&nbsp;<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.\n<\/p>\n<p>Users should be wary of attachments that require special instructions to open, navigation of multiple folder layers or any unpackaging actions required to access the intended document. In these situations, users should consider a follow up verification of the email by contacting the original sender by phone or by creating a new email conversation using the email address from another source (not as a reply to the suspicious email).\n<\/p>\n<p>Malicious actors will continue to alter their initial methods of infection and as such system administrators are encouraged to implement as many mitigation measures as possible to prevent phishing in general&nbsp;<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>&nbsp;<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>&nbsp;<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.\n<\/p>\n<p>Following the initial compromise, the Cyber Centre has observed and received reports of deployment of post compromise tools such as Cobalt Strike and Brute Ratel which were used to further compromise affected networks.\n<\/p>\n<p>Further compromised networks could be leveraged for additional malicious activity, including ransomware.\n<\/p>\n<h2>Tactics, Techniques, and Procedures (TTP)\n<\/h2>\n<p>Commonly observed methods of exploitation are being identified below along with reference to the MITRE ATT&amp;CK framework to provide additional context and mitigation advice&nbsp;<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>:\n<\/p>\n<h3>Resource Development (Mitre T1586.002)\n<\/h3>\n<p>Hijacking existing email threads increases the chances of additional successful compromises.\n<\/p>\n<h3>Initial Access (Mitre T1566.001, T1566.002)\n<\/h3>\n<p>Qakbot is primarily delivered via malicious emails as a zipped attachment, link, or embedded image.\n<\/p>\n<h3>Execution (Mitre T1204.001, T1204.002, T1218.010, T1218.011)\n<\/h3>\n<p>Following a victim opening the LNK file, the Qakbot DLL is executed.\n<\/p>\n<h3>Command and Control (Mitre T1071.001, T1132.001)\n<\/h3>\n<p>Upon installation, Qakbot will beacon to its C2 infrastructure with encoded messages sent via HTTPS GET and POST requests. The IP addresses of the C2 infrastructure are updated in Qakbot as malicious infrastructure is identified and acted upon.\n<\/p>\n<h3>Persistence (Mitre T1547.001, T1053.005)\n<\/h3>\n<p>Qakbot commonly achieves persistence through scheduled tasks and registry run keys.\n<\/p>\n<h3>Defense Evasion (Mitre T1140, T1553.005)\n<\/h3>\n<p>Use of password-protected zipped files and ISO files to avoid detection.\n<\/p>\n<h3>Discovery (Mitre T1016)\n<\/h3>\n<p>One of the Qakbot modules provides several tools for scanning the internal network. For example, Qakbot has been observed performing an ARP scan in order to discover other endpoints on the network.&nbsp;<sup id=\"fn1s-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>\n<\/p>\n<p>Similar activity was also described in SANS\u2019 Incident Handler\u2019s Diary Blog titled \u201cTA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt)\u201d.&nbsp;<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>\n<\/p>\n<h2>Update 1\n<\/h2>\n<p>In early February 2023, the Cyber Centre was made aware of an increase in phishing emails containing malicious OneNote attachments (.one) being used to deliver Qakbot and other malware.\n<\/p>\n<p>The malicious OneNote attachments contain embedded files and may include an image that appears to be a clickable button. Opening the attachment may lead to a security warning prompt displayed to the user. If the user bypasses the warning and opens the embedded file, the file executes its payload which may be a shortcut (LNK) file, an HTML application (HTA), or a Windows Script File (WSF) <sup id=\"fn17-rf\"><a class=\"fn-lnk\" href=\"#fn17\"><span class=\"wb-inv\">Footnote <\/span>17<\/a><\/sup><sup id=\"fn18-rf\"><a class=\"fn-lnk\" href=\"#fn18\"><span class=\"wb-inv\">Footnote <\/span>18<\/a><\/sup> which subsequently leads to the delivery of Qakbot malware.\n<\/p>\n<p>Threat actors leverage the inherent trust in platforms, like Microsoft OneNote, to bypass some protections by email anti-spam filters and online enterprise gateways.\n<\/p>\n<p>If your organization does not use Microsoft OneNote, consider filtering incoming attachments with the OneNote file extension to prevent end users from opening any malicious OneNote documents.\n<\/p>\n<h2>Update 2\n<\/h2>\n<p>On February 16, 2023, the Cyber Centre released an update of the YARA rule below to widen detection capabilities.\n<\/p>\n<h2>Mitigation\n<\/h2>\n<h3>Yara:\n<\/h3>\n<p>The following YARA rule is not intended to be used on production systems or to inform blocking rules without first being validated through an organization's own internal testing processes to ensure appropriate performance and limit the risk of false positives. These rules are intended to serve as a starting point for hunting efforts to identify activity; however, they may need adjustment overtime if the malware family changes.\n<\/p>\n<p><span class=\"wb-inv\">Yara code begins<\/span>\n<\/p>\n<pre>\n<code>rule onenote_downloader {\n\n    meta:\n        id = \"5agXf6mY0R9rvwzpeYjzns\"\n        fingerprint = \"17dd9c81bd00db3907a8d444f2f6dddb0cae0b2ba15ec68a3d721ac0cf1ea022\"\n        version = \"6.0\"\n        first_imported = \"2023-02-06\"\n        last_modified = \"2023-02-15\"\n        status = \"RELEASED\"\n        sharing = \"TLP:WHITE\"\n        source = \"CCCS\"\n        author = \"reveng@CCCS\"\n        description = \"Malicious one note file that is being used to download and\/or execute payload.\"\n        category = \"MALWARE\"\n        malware_type = \"DOWNLOADER\"\n        mitre_att = \"TA0002\"\n        actor_type = \"CRIMEWARE\"\n        reference = \"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/onenote-documents-increasingly-used-to-deliver-malware\"\n        reference = \"https:\/\/blog.didierstevens.com\/2023\/01\/22\/analyzing-malicious-onenote-documents\/\"\n        hash = \"636f8f5fa6d17d092007a750a38cbe4d171e608eab5b8264dbfa35209529cb9a\"\n        hash = \"f674b1c858ea26730ab113c83a87f71a38cb367e8ef20223f5a1f668b29b7938\"\n\n    strings:\n        $onenote_guid = { e4 52 5c 7b 8c d8 a7 4d ae b1 53 78 d0 29 96 d3 }\n        $fo = {e716e3bd65261145a4c48d4d0b7a9eac}\n        $str0 = \"powershell\" ascii\n        $str2 = \"FromBase64String\" ascii\n        $str3 = \"WScript.Shell\" ascii\n        $str4 = \"WshShell\" ascii\n        $str6 = \"%70%6F%77%65%72%73%68%65%6C%6C\"\n\n        $fname0 = \".hta\" wide\n        $fname1 = \".cmd\" wide\n        $fname2 = \"Z:\\\\build\\\\one\" wide\n        $fname3 = \".hta\" wide\n        $fname4 = \".bat\" wide\n        $fname5 = \".vbs\" wide\n        $fname6 = \".scr\" wide\n        $fname7 = \".iso\" wide\n        $fname8 = \".img\" wide\n        $fname9 = \".exe\" wide\n        $fname10 = \".ps1\" wide\n        $fname11 = \".wsf\" wide\n        $fname12 = \".jse\" wide\n        $fname13 = \"Z:\\\\builder\\\\\" wide\n\n    condition:\n        $onenote_guid and (\n            \/* check if we have the strings within a single file block *\/\n            for any i in (1..#fo):(\n                for 1 of ($str*):(\n                    $ in (@fo[i] + 0x24 ..  \n                          @fo[i] + 0x24 + uint16(@fo[i] + 16)\n                         )\n                )\n            )\n            or\n            \/* or the file names referenced twice *\/\n            for any of ($fname*):(\n                #>=2\n            )\n        ) \n}\n\n<\/code>\n<\/pre>\n<p><span class=\"wb-inv\">Yara code ends<\/span>\n<\/p>\n<h2>Recommended actions\n<\/h2>\n<p>The Cyber Centre recommends that organizations:\n<\/p>\n<ul>\n  <li>Expand employee awareness and training opportunities for phishing and spam, including the ability to recognize malicious emails and procedures on what to do if one is received.&nbsp;<sup id=\"fn4s-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>&nbsp;<sup id=\"fn5s-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>&nbsp;<sup id=\"fn6s-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/li>\n  <li>Employees should consider additional verification when a received email seems unusual or has extra layers of actions. Verification should not be a reply to the suspicious email received.<\/li>\n  <li>Ensure systems are regularly patched and that antivirus software is always up to date.<\/li>\n  <li>Employ the principle of least privilege for user accounts. This can limit the impact of malware in the event that it is inadvertently executed on a machine.<\/li>\n  <li>Ensure that macros are disabled by default for untrusted documents.<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup><\/li>\n  <li>Review the complete list of MITRE ATT&amp;CK techniques employed by malicious actors leveraging Qakbot and the associated mitigations to assist in reducing the threat surface.&nbsp;<sup id=\"fn7d-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><\/li>\n  <li>The Cyber Centre has several publications on security best practices to protect your organization. These include the Cyber Centre\u2019s \u201cTop 10 IT Security Actions\u201d, \u201cRansomware Guidance\u201d and \u201cProtect Your Organization from Malware\u201d.&nbsp;<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>&nbsp;<sup id=\"fn4d-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>&nbsp;<sup id=\"fn5d-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>&nbsp;<sup id=\"fn6d-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>&nbsp;<sup id=\"fn10d-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>&nbsp;<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup><\/li>\n  <li>Ensure that proactive measures have been taken to plan and prepare for ransomware.&nbsp;<sup id=\"fn12-rf\"><a class=\"fn-lnk\" href=\"#fn12\"><span class=\"wb-inv\">Footnote <\/span>12<\/a><\/sup>&nbsp;<sup id=\"fn13-rf\"><a class=\"fn-lnk\" href=\"#fn13\"><span class=\"wb-inv\">Footnote <\/span>13<\/a><\/sup><\/li>\n  <li>CISA has several publications of interest related to Qakbot&nbsp;<sup id=\"fn14-rf\"><a class=\"fn-lnk\" href=\"#fn14\"><span class=\"wb-inv\">Footnote <\/span>14<\/a><\/sup>&nbsp;<sup id=\"fn15a-rf\"><a class=\"fn-lnk\" href=\"#fn15\"><span class=\"wb-inv\">Footnote <\/span>15<\/a><\/sup><\/li>\n<\/ul>\n<p>In addition, organizations may also consider disabling auto-mounting of disk image files, such as ISO files, to prevent use of detection bypass techniques. This could be achieved through modification of Registry values, which would require serious consideration of possible issues to standard operating procedure if disk image files are regularly used.\n<\/p>\n<p>The Cyber Centre wishes to highlight that mitigation efforts resulting from the compromise of systems by competent threat actors may require more than simply mitigating individual issues, systems and servers. In cases such as these, based on the perceived sophistication of the threat actor involved, organizations should consider additional mitigative efforts besides simply the removal or updating of the product. The Cyber Centre recommends affected customers review the Cyber Centre joint cybersecurity advisory on technical approaches to uncovering and remediating malicious activity&nbsp;<sup id=\"fn16-rf\"><a class=\"fn-lnk\" href=\"#fn16\"><span class=\"wb-inv\">Footnote <\/span>16<\/a><\/sup>.\n<\/p>\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, contact the Cyber Centre by email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>), or by telephone (<a href=\"tel:+18332923788\">1-833-CYBER-88<\/a> or <a href=\"tel:+18332923788\">1-833-292-3788<\/a>).\n<\/p>\n<!-- ENDNOTES SECTION -->\n<aside class=\"wb-fnote\" role=\"note\">\n  <h2 id=\"fn\">References\n  <\/h2>\n  <dl>\n    <dt>Footnote 1\n    <\/dt>\n    <dd id=\"fn1\">\n      <p><a href=\"https:\/\/news.sophos.com\/en-us\/2022\/03\/10\/qakbot-injects-itself-into-the-middle-of-your-conversations\/\">Qakbot injects itself into the middle of your conversations<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 2\n    <\/dt>\n    <dd id=\"fn2\">\n      <p><a href=\"https:\/\/blog.talosintelligence.com\/what-talos-incident-response-learned\/\">What Talos Incident Response learned from a recent Qakbot attack hijacking old email threads<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 3\n    <\/dt>\n    <dd id=\"fn3\">\n      <p><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/j\/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html\">Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 4\n    <\/dt>\n    <dd id=\"fn4\">\n      <p><a href=\"\/en\/guidance\/dont-take-bait-recognize-and-avoid-phishing-attacks\" rel=\"external\">Don't take the bait: Recognize and avoid phishing attacks<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 5\n    <\/dt>\n    <dd id=\"fn5\">\n      <p><a href=\"\/en\/guidance\/spotting-malicious-email-messages-itsap00100\" rel=\"external\">Spotting malicious email messages <\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 6\n    <\/dt>\n    <dd id=\"fn6\">\n      <p><a href=\"https:\/\/www.getcybersafe.gc.ca\/en\/blogs\/spear-phishing-what-it-and-how-you-can-protect-yourself\" rel=\"external\">Spear phishing: What it is and how you can protect yourself<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 7\n    <\/dt>\n    <dd id=\"fn7\">\n      <p><a href=\"https:\/\/attack.mitre.org\/software\/S0650\/\" rel=\"external\">MITRE ATT&amp;K&nbsp;- Qakbot<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 8\n    <\/dt>\n    <dd id=\"fn8\">\n      <p><a href=\"https:\/\/isc.sans.edu\/forums\/diary\/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt\/28728\/\" rel=\"external\">TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt)<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 9\n    <\/dt>\n    <dd id=\"fn9\">\n      <p><a href=\"\/en\/top-10-it-security-actions\" rel=\"external\">Top 10 IT security actions<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote <\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 10\n    <\/dt>\n    <dd id=\"fn10\">\n      <p><a href=\"\/en\/guidance\/how-protect-your-organization-malicious-macros-itsap00200\" rel=\"external\">How to protect your organization from malicious macros (ITSAP.00.200) <\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote <\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 11\n    <\/dt>\n    <dd id=\"fn11\">\n      <p><a href=\"\/en\/guidance\/protect-your-organization-malware-itsap00057\" rel=\"external\">Protect your organization from malware (ITSAP.00.057)<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote <\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 12\n    <\/dt>\n    <dd id=\"fn12\">\n      <p><a href=\"\/en\/guidance\/ransomware\" rel=\"external\">Ransomware guidance<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn12-rf\"><span class=\"wb-inv\">Return to footnote <\/span>12<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 13\n    <\/dt>\n    <dd id=\"fn13\">\n      <p><a href=\"\/en\/guidance\/ransomware-how-prevent-and-recover-itsap00099\" rel=\"external\">Ransomware: How to prevent and recover<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn13-rf\"><span class=\"wb-inv\">Return to footnote <\/span>13<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 14\n    <\/dt>\n    <dd id=\"fn14\">\n      <p><a href=\"https:\/\/www.cisa.gov\/stopransomware\/qbotqakbot-malware-report\" rel=\"external\">CISA&nbsp;- Qbot\/Qakbot Malware Report<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn14-rf\"><span class=\"wb-inv\">Return to footnote <\/span>14<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 15\n    <\/dt>\n    <dd id=\"fn15\">\n      <p><a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-216a\" rel=\"external\">CISA&nbsp;- 2021 Top Malware Strains<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn15-rf\"><span class=\"wb-inv\">Return to footnote <\/span>15<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 16\n    <\/dt>\n    <dd id=\"fn16\">\n      <p><a href=\"\/en\/news-events\/joint-cybersecurity-advisory \" rel=\"external\">Technical Approaches to Uncovering and Remediating Malicious Activity<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn16-rf\"><span class=\"wb-inv\">Return to footnote <\/span>16<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 17\n    <\/dt>\n    <dd id=\"fn17\">\n      <p><a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/onenote-documents-increasingly-used-to-deliver-malware\" rel=\"external\">OneNote Documents Increasingly Used to Deliver Malware<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn17-rf\"><span class=\"wb-inv\">Return to footnote <\/span>17<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 18\n    <\/dt>\n    <dd id=\"fn18\">\n      <p><a href=\"https:\/\/news.sophos.com\/en-us\/2023\/02\/06\/qakbot-onenote-attacks\/\" rel=\"external\">QakBot OneNote Attacks<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn18-rf\"><span class=\"wb-inv\">Return to footnote <\/span>18<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n  <\/dl>\n<\/aside>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ongoing-reports-qakbot-malware-incidents","alert_type":397,"serial_number":"AL22-013","subject":null,"moderation_state":"published","external_url":null},{"nid":3700,"title":"Apple security advisory (AV22-635)","uuid":"fe202cc8-4b7f-448c-82d2-ee21ce11ca24","banner":null,"lang":"en","date_modified":"2022-11-10","date_modified_ts":"2022-11-10T18:17:50Z","date_created":"2022-11-10T18:15:12Z","summary":null,"body":["<article data-history-node-id=\"3700\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-635\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-635<\/strong><br \/><strong>Date: 10 November 2022<\/strong><\/p>\n\n<p>On 9 November 2022, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 16.1.1<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 16.1.1<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.0.1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution or cause a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213504\">Apple Security Update (HT213504)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213505\">Apple Security Update (HT213505)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-635","alert_type":396,"serial_number":"AV22-635","subject":null,"moderation_state":"published","external_url":null},{"nid":3701,"title":"HPE security advisory (AV22-636)","uuid":"34ec19ae-3eff-4290-9f4f-22733d868684","banner":null,"lang":"en","date_modified":"2022-11-10","date_modified_ts":"2022-11-10T21:15:12Z","date_created":"2022-11-10T21:14:40Z","summary":null,"body":["<article data-history-node-id=\"3701\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-636\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-636<\/strong><br \/><strong>Date: 10 November 2022<\/strong><\/p>\n\n<p>Between 7 and 9 November 2022, HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Proliant Servers \u2013 multiple versions and platforms<\/li>\n\t<li>HPE ProLiant m510 Server Cartridge \u2013 versions prior to 1.96_10-13-2022<\/li>\n\t<li>HPE SAN Switches with Brocade Fabric OS (FOS) \u2013 multiple versions<\/li>\n\t<li>HPE Synergy 480 and 660 Gen9 Compute Modules \u2013 firmware versions prior to v3.04_08-04-2022<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary\" rel=\"external\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-636","alert_type":396,"serial_number":"AV22-636","subject":null,"moderation_state":"published","external_url":null},{"nid":3703,"title":"Microsoft Edge security advisory (AV22-637)","uuid":"3d2213cb-340a-4022-abae-d0f6a0d84ccb","banner":null,"lang":"en","date_modified":"2022-11-14","date_modified_ts":"2022-11-14T19:25:49Z","date_created":"2022-11-14T19:25:16Z","summary":null,"body":["<article data-history-node-id=\"3703\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-637\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-637<\/strong><br \/><strong>Date: 14 November 2022<\/strong><\/p>\n\n<p>On 10 November 2022, Microsoft published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge \u2013 versions prior to 107.0.1418.42<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-10-2022\" rel=\"external\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-637","alert_type":396,"serial_number":"AV22-637","subject":null,"moderation_state":"published","external_url":null},{"nid":3704,"title":"[Control Systems] Omron security advisory (AV22-638)","uuid":"7bf2bf4f-0a8b-4c89-af95-e5639a5f82fb","banner":null,"lang":"en","date_modified":"2022-11-14","date_modified_ts":"2022-11-14T19:32:37Z","date_created":"2022-11-14T19:28:41Z","summary":null,"body":["<article data-history-node-id=\"3704\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-638\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-638<\/strong><br \/><strong>Date: 14 November 2022<\/strong><\/p>\n\n<p>On 10 November 2022, ICS-CERT published ICS Advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Automation Software Sysmac Studio \u2013 versions 49 and prior<\/li>\n\t<li>NA-series Programmable Terminal (NA5-15W, NA5-12W, NA5-9W, NA5-7W) \u2013 versions 1.15 and prior<\/li>\n\t<li>NJ-series Machine Automation Controller \u2013 versions 48 and prior<\/li>\n\t<li>NX1-series Machine Automation Controller \u2013 versions 1.48 and prior<\/li>\n\t<li>NX7-series Machine Automation Controller \u2013 versions 1.28 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-314-07\" rel=\"external\">ICS Advisory (ICSA-22-314-07) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-314-08\" rel=\"external\">ICS Advisory (ICSA-22-314-08) <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-638","alert_type":398,"serial_number":"AV22-638","subject":null,"moderation_state":"published","external_url":null},{"nid":3705,"title":"Mitel security advisory (AV22-639)","uuid":"88d22ef2-32d8-4165-9e15-a20acc83b229","banner":null,"lang":"en","date_modified":"2022-11-14","date_modified_ts":"2022-11-14T19:40:20Z","date_created":"2022-11-14T19:35:22Z","summary":null,"body":["<article data-history-node-id=\"3705\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av22-639\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-639<\/strong><br \/><strong>Date: 14 November 2022<\/strong><\/p>\n\n<p>On 12 November 2022, Mitel published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>MiCollab \u2013 version 9.6.0.105 and prior<\/li>\n\t<li>MiVoice Connect \u2013 version 19.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-22-0007\" rel=\"external\">Mitel Security Advisory (22-0007-001)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-22-0008\" rel=\"external\">Mitel Security Advisory (22-0008-001)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\" rel=\"external\">Mitel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av22-639","alert_type":396,"serial_number":"AV22-639","subject":null,"moderation_state":"published","external_url":null},{"nid":3706,"title":"IBM security advisory (AV22-640)","uuid":"9b723e5e-f0a3-48cf-b1d5-7372eabf905c","banner":null,"lang":"en","date_modified":"2022-11-14","date_modified_ts":"2022-11-14T19:50:02Z","date_created":"2022-11-14T19:46:04Z","summary":null,"body":["<article data-history-node-id=\"3706\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-640\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-640<\/strong><br \/><strong>Date: 14 November 2022<\/strong><\/p>\n\n<p>Between 7 and 13 November 2022, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Security (CP4S) \u2013 version 1.10.0.0 to 1.10.1.0<\/li>\n\t<li>IBM Db2 \u2013 version 11.5<\/li>\n\t<li>IBM QRadar Assistant \u2013 version 1.0.0 to 3.5.2<\/li>\n\t<li>IBM QRadar Network Packet Capture \u2013 multiple versions<\/li>\n\t<li>IBM Security Guardium \u2013 versions 10.5, 10.6, 11.0, 11.1, 11.2, 11.3 and 11.4<\/li>\n\t<li>IBM Security Verify Access \u2013 version 10.0.X<\/li>\n\t<li>IBM Security Verify Access Docker \u2013 version 10.0.X<\/li>\n\t<li>IBM Tivoli Monitoring \u2013 multiple versions<\/li>\n\t<li>InfoSphere Information Server \u2013 version 11.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\" rel=\"external\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-640","alert_type":396,"serial_number":"AV22-640","subject":null,"moderation_state":"published","external_url":null},{"nid":3707,"title":"Dell security advisory (AV22-641)","uuid":"4ad2a3df-c202-4398-a763-5a33eac68942","banner":null,"lang":"en","date_modified":"2022-11-14","date_modified_ts":"2022-11-14T20:00:49Z","date_created":"2022-11-14T19:54:49Z","summary":null,"body":["<article data-history-node-id=\"3707\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-641\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-641<\/strong><br \/><strong>Date: 14 November 2022<\/strong><\/p>\n\n<p>Between 7 and 13 November 2022, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Connectrix (Brocade) FOS \u2013 multiple versions<\/li>\n\t<li>Dell SCG Policy Manager \u2013 version 5.12.00.00<\/li>\n\t<li>Dell Secure Connect Gateway \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000204996\/dsa-2022-272-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities\" rel=\"external\">Dell Security Advisory (DSA-2022-272)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000204995\/dsa-2022-273-dell-secure-connect-gateway-policy-manager-security-update-for-multiple-proprietary-code-vulnerabilities\" rel=\"external\">Dell Security Advisory (DSA-2022-273)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000205092\/dsa-2022-304-dell-connectrix-brocade-security-update-for-ezswitch-vulnerability\" rel=\"external\">Dell Security Advisory (DSA-2022-304)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\" rel=\"external\">Dell Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-641","alert_type":396,"serial_number":"AV22-641","subject":null,"moderation_state":"published","external_url":null},{"nid":3708,"title":"[Control Systems] ABB security advisory (AV22-642)","uuid":"f9072c9e-50a4-4455-8c70-b2bdef95ea14","banner":null,"lang":"en","date_modified":"2022-11-15","date_modified_ts":"2022-11-15T15:34:48Z","date_created":"2022-11-15T15:34:21Z","summary":null,"body":["<article data-history-node-id=\"3708\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-642\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-642<\/strong><br \/><strong>Date: 15 November 2022<\/strong><\/p>\n\n<p>On 15 November 2022, ABB published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>PCM600 \u2013 version 2.11 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001518&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch \" rel=\"external\">ABB Security Advisory (2NGA001518)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-642","alert_type":398,"serial_number":"AV22-642","subject":null,"moderation_state":"published","external_url":null},{"nid":3709,"title":"Mozilla security advisory (AV22-643)","uuid":"e9e5f89b-2797-4316-9179-f9fd3b851803","banner":null,"lang":"en","date_modified":"2022-11-15","date_modified_ts":"2022-11-15T15:44:54Z","date_created":"2022-11-15T15:37:18Z","summary":null,"body":["<article data-history-node-id=\"3709\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-643\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-643<\/strong><br \/><strong>Date: 15 November 2022<\/strong><\/p>\n\n<p>On 15 November 2022, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 107<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 102.5<\/li>\n\t<li>Thunderbird \u2013 versions prior to 102.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-47\/\" rel=\"external\">Mozilla Security Advisory (MFSA2022-47)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-48\/\" rel=\"external\">Mozilla Security Advisory (MFSA2022-48)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-49\/\" rel=\"external\">Mozilla Security Advisory (MFSA2022-49)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\" rel=\"external\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-643","alert_type":396,"serial_number":"AV22-643","subject":null,"moderation_state":"published","external_url":null},{"nid":3710,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-644)","uuid":"7f730da4-9f2d-41ab-89cd-41e1ef0ffea8","banner":null,"lang":"en","date_modified":"2022-11-15","date_modified_ts":"2022-11-15T21:18:43Z","date_created":"2022-11-15T21:18:00Z","summary":null,"body":["<article data-history-node-id=\"3710\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-644\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-644<\/strong><br \/><strong>Date: 15 November 2022<\/strong><\/p>\n\n<p>On 15 November 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>GT SoftGOT2000\u00a0\u2013 versions 1.275M to 1.280S<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-319-01\" rel=\"external\">ICS Advisory (ICSA-22-319-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-644","alert_type":398,"serial_number":"AV22-644","subject":null,"moderation_state":"published","external_url":null},{"nid":3713,"title":"F5 security advisory (AV22-645)","uuid":"4acfa583-c74d-4023-b3e5-b6d0bce977d4","banner":null,"lang":"en","date_modified":"2022-11-16","date_modified_ts":"2022-11-16T19:52:51Z","date_created":"2022-11-16T19:44:21Z","summary":null,"body":["<article data-history-node-id=\"3713\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av22-645\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-645<\/strong><br \/><strong>Date: 16 November 2022<\/strong><\/p>\n\n<p>On 16 November 2022, F5 published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions and platforms<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 versions 7.1.0 and 8.0.0 to 8.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.f5.com\/csp\/article\/K94221585\" rel=\"external\">F5 Security Advisory (K94221585)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.f5.com\/csp\/article\/K13325942\" rel=\"external\">F5 Security Advisory (K13325942)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av22-645","alert_type":396,"serial_number":"AV22-645","subject":null,"moderation_state":"published","external_url":null},{"nid":3716,"title":"[Control systems] Red Lion Controls security advisory (AV22-646)","uuid":"a734bc16-e0ee-4f23-83f8-5733793d60a6","banner":null,"lang":"en","date_modified":"2022-11-17","date_modified_ts":"2022-11-17T19:55:40Z","date_created":"2022-11-17T19:55:04Z","summary":null,"body":["<article data-history-node-id=\"3716\" about=\"\/en\/alerts-advisories\/control-systems-red-lion-controls-security-advisory-av22-646\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-646<\/strong><br \/><strong>Date: 17 November 2022<\/strong><\/p>\n\n<p>On 17 November 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Crimson 3.0 \u2013 version 707.000 and prior<\/li>\n\t<li>Crimson 3.1 \u2013 version 001 and prior<\/li>\n\t<li>Crimson 3.2 \u2013 version2.0044.0 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to credential disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-321-01\" rel=\"external\">ICS Advisory (ICSA-22-321-01) <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-red-lion-controls-security-advisory-av22-646","alert_type":398,"serial_number":"AV22-646","subject":null,"moderation_state":"published","external_url":null},{"nid":3717,"title":"[Control systems] Cradlepoint security advisory (AV22-647)","uuid":"dd3cae68-1c6c-4ca9-b94c-6a8cbbaefbb5","banner":null,"lang":"en","date_modified":"2022-11-17","date_modified_ts":"2022-11-17T20:01:33Z","date_created":"2022-11-17T19:59:06Z","summary":null,"body":["<article data-history-node-id=\"3717\" about=\"\/en\/alerts-advisories\/control-systems-cradlepoint-security-advisory-av22-647\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-647<\/strong><br \/><strong>Date: 17 November 2022<\/strong><\/p>\n\n<p>On 17 November 2022, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Cradlepoint IBR600 NetCloud OS (NCOS) \u2013 version 6.5.0.160bc2e and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow arbitrary code execution or execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-321-02\" rel=\"external\">ICS Advisory (ICSA-22-321-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cradlepoint-security-advisory-av22-647","alert_type":398,"serial_number":"AV22-647","subject":null,"moderation_state":"published","external_url":null},{"nid":3718,"title":"Atlassian security advisory (AV22-648)","uuid":"80aa5a7d-9c7d-40f2-a97d-4f515adb4b68","banner":null,"lang":"en","date_modified":"2022-11-18","date_modified_ts":"2022-11-18T20:02:32Z","date_created":"2022-11-18T20:00:57Z","summary":null,"body":["<article data-history-node-id=\"3718\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av22-648\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><b>Number: AV22-648<\/b><\/p>\n\n<p><b>Date: 17<\/b><b> November 2022<\/b><\/p>\n\n<p>On 16 November 2022, Atlassian published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bitbucket Server and Data Center \u2013 versions 7.0 to 7.21 and versions 8.0 to 8.4<\/li>\n\t<li>Crowd 3.0.0 \u2013 versions 3.0.0 to 3.7.2<\/li>\n\t<li>Crowd 4.0.0 \u2013 versions 4.0.0 to 4.3<\/li>\n\t<li>Crowd 5.0.0 \u2013 versions 5.0.0 to0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/bitbucketserver\/bitbucket-server-and-data-center-security-advisory-2022-11-16-1180141667.html\">Atlassian Security Advisory (BSERV-13522)<\/a><\/li>\n\t<li><a href=\"https:\/\/confluence.atlassian.com\/crowd\/crowd-security-advisory-november-2022-1168866129.html\">Atlassian Security Advisory (CWD-5888)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av22-648","alert_type":396,"serial_number":"AV22-648","subject":null,"moderation_state":"published","external_url":null},{"nid":3720,"title":"HPE security advisory (AV22-649)","uuid":"ae6784be-71bc-4ea5-aad6-3188db0a2587","banner":null,"lang":"en","date_modified":"2022-11-18","date_modified_ts":"2022-11-18T20:56:11Z","date_created":"2022-11-18T20:55:39Z","summary":null,"body":["<article data-history-node-id=\"3720\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-649\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-649<\/strong><br \/><strong>Date: 18 November 2022<\/strong><\/p>\n\n<p>On 16 November 2022, HPE published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>OfficeConnect 1820 Network switches \u2013 multiple versions and models<\/li>\n\t<li>OfficeConnect 1850 Network switches \u2013 multiple versions and models<\/li>\n\t<li>OfficeConnect 1920S Network switches \u2013 multiple versions and models<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04383en_us\" rel=\"external\">HPE Security Bulletin (HPESBNW04383)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-649","alert_type":396,"serial_number":"AV22-649","subject":null,"moderation_state":"published","external_url":null},{"nid":3721,"title":"IBM security advisory (AV22-650)","uuid":"5b051bf7-5139-4d01-b4fb-c10be32b35ef","banner":null,"lang":"en","date_modified":"2022-11-21","date_modified_ts":"2022-11-21T20:27:33Z","date_created":"2022-11-21T20:26:59Z","summary":null,"body":["<article data-history-node-id=\"3721\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-650\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-650<\/strong><br \/><strong>Date: 21 November 2022<\/strong><\/p>\n\n<p>Between 14 and 20 November 2022, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>InfoSphere Information Server \u2013 version 11.7<\/li>\n\t<li>Log Analysis \u2013 versions 1.3.x<\/li>\n\t<li>Log Analysis \u2013 versions 1.3.7.0, 1.3.7.1 and 1.3.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-650","alert_type":396,"serial_number":"AV22-650","subject":null,"moderation_state":"published","external_url":null},{"nid":3722,"title":"Ubuntu security advisory (AV22-651)","uuid":"550cd7bf-32b5-4608-b910-720fcc57ca8f","banner":null,"lang":"en","date_modified":"2022-11-21","date_modified_ts":"2022-11-21T20:32:33Z","date_created":"2022-11-21T20:29:46Z","summary":null,"body":["<article data-history-node-id=\"3722\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-651\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-651<\/strong><br \/><strong>Date: 21 November 2022<\/strong><\/p>\n\n<p>Between 14 and 20 November 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-651","alert_type":396,"serial_number":"AV22-651","subject":null,"moderation_state":"published","external_url":null},{"nid":3724,"title":"[Control systems] AVEVA\u00a0security advisory (AV22-652)","uuid":"35385ccb-18c1-4356-a597-6aa868eb1c68","banner":null,"lang":"en","date_modified":"2022-11-23","date_modified_ts":"2022-11-23T13:57:50Z","date_created":"2022-11-23T13:55:41Z","summary":null,"body":["<article data-history-node-id=\"3724\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-652\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-652<\/strong><br \/><strong>Date: 22 November 2022<\/strong><\/p>\n\n<p>On 22 November 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA Edge \u2013 version 2020 R2 SP1<\/li>\n\t<li>AVEVA Edge \u2013 version 2020 R2 SP1 with HF 2020.2.00.40<\/li>\n\t<li>AVEVA Edge \u2013 2020 R2 and all prior versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-326-01\">ICS Advisory (ICSA-22-326-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-652","alert_type":398,"serial_number":"AV22-652","subject":null,"moderation_state":"published","external_url":null},{"nid":3725,"title":"[Control systems] Digital Alert Systems security advisory (AV22-653)","uuid":"77a6f56b-14a0-4139-aa4e-f9e3525507c0","banner":null,"lang":"en","date_modified":"2022-11-23","date_modified_ts":"2022-11-23T14:04:16Z","date_created":"2022-11-23T14:01:17Z","summary":null,"body":["<article data-history-node-id=\"3725\" about=\"\/en\/alerts-advisories\/control-systems-digital-alert-systems-security-advisory-av22-653\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-653<\/strong><br \/><strong>Date: 22 November 2022<\/strong><\/p>\n\n<p>On 22 November 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Digital Alert Systems DASDEC software \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in the injection of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-326-02\">ICS Advisory (ICSA-22-326-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-digital-alert-systems-security-advisory-av22-653","alert_type":398,"serial_number":"AV22-653","subject":null,"moderation_state":"published","external_url":null},{"nid":3726,"title":"[Control systems] Phoenix Contact security advisory (AV22-654)","uuid":"944c9391-60aa-4189-8099-edf2964ce04f","banner":null,"lang":"en","date_modified":"2022-11-23","date_modified_ts":"2022-11-23T14:20:05Z","date_created":"2022-11-23T14:16:44Z","summary":null,"body":["<article data-history-node-id=\"3726\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av22-654\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-654<\/strong><br \/><strong>Date: 22 November 2022<\/strong><\/p>\n\n<p>On 22 November 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AUTOMATIONWORX Software Suite Config+ \u2013 version 1.89 and prior<\/li>\n\t<li>AUTOMATIONWORX Software Suite PC Worx \u2013 version 1.89 and prior<\/li>\n\t<li>AUTOMATIONWORX Software Suite PC Worx Express \u2013 version 1.89 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-326-03\">ICS Advisory (ICSA-22-326-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av22-654","alert_type":398,"serial_number":"AV22-654","subject":null,"moderation_state":"published","external_url":null},{"nid":3729,"title":"[Control systems] General Electric security advisory (AV22-655)","uuid":"57c9b741-f869-4e28-a023-6219be8a4452","banner":null,"lang":"en","date_modified":"2022-11-23","date_modified_ts":"2022-11-23T20:59:56Z","date_created":"2022-11-23T20:57:36Z","summary":null,"body":["<article data-history-node-id=\"3729\" about=\"\/en\/alerts-advisories\/control-systems-general-electric-security-advisory-av22-655\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-655<\/strong><br \/><strong>Date: 23 November 2022<\/strong><\/p>\n\n<p>On 22 November 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>CIMPLICITY \u2013 versions 2022 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-326-04\">ICS Advisory (ICSA-22-326-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-general-electric-security-advisory-av22-655","alert_type":398,"serial_number":"AV22-655","subject":null,"moderation_state":"published","external_url":null},{"nid":3730,"title":"[Control systems] Moxa security advisory (AV22-656)","uuid":"414affa3-d8f9-4043-b766-51744ee29069","banner":null,"lang":"en","date_modified":"2022-11-23","date_modified_ts":"2022-11-23T21:07:38Z","date_created":"2022-11-23T21:02:39Z","summary":null,"body":["<article data-history-node-id=\"3730\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av22-656\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-656<\/strong><br \/><strong>Date: 23 November 2022<\/strong><\/p>\n\n<p>On 22 November 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>UC-8100A-ME-T System Image \u2013 versions v1.0 to v1.6<\/li>\n\t<li>UC-2100 System Image \u2013 versions v1.0 to v1.12<\/li>\n\t<li>UC-2100-W System Image \u2013 versions v1.0 to v 1.12<\/li>\n\t<li>UC-3100 System Image \u2013 versions v1.0 to v1.6<\/li>\n\t<li>UC-5100 System Image \u2013 versions v1.0 to v1.4<\/li>\n\t<li>UC-8100 System Image \u2013 versions v3.0 to v3.5<\/li>\n\t<li>UC-8100-ME-T System Image \u2013 versions v3.0 and v3.1<\/li>\n\t<li>UC-8100A-ME-T System Image \u2013 versions v1.0 to v1.6<\/li>\n\t<li>UC-8200 System Image \u2013 version v1.0 to version v1.5<\/li>\n\t<li>AIG-300 System Image \u2013 version v1.0 to version v1.4<\/li>\n\t<li>UC-8410A with Debian 9 System Image \u2013 versions v4.0.2 and v4.1.2<\/li>\n\t<li>UC-8580 with Debian 9 System Image \u2013 versions v2.0 and v2.1<\/li>\n\t<li>UC-8540 with Debian 9 System Image \u2013 versions v2.0 and v2.1<\/li>\n\t<li>DA-662C-16-LX (GLB) System Image \u2013 versions v1.0.2 to v1.1.2<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-326-05\">ICS Advisory (ICSA-22-326-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av22-656","alert_type":398,"serial_number":"AV22-656","subject":null,"moderation_state":"published","external_url":null},{"nid":3731,"title":"HPE security advisory (AV22-657)","uuid":"0a7415bb-07ba-4413-b077-3705f1a240c6","banner":null,"lang":"en","date_modified":"2022-11-23","date_modified_ts":"2022-11-23T21:13:03Z","date_created":"2022-11-23T21:10:10Z","summary":null,"body":["<article data-history-node-id=\"3731\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-657\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-657<\/strong><br \/><strong>Date: 23 November 2022<\/strong><\/p>\n\n<p>On 22 November 2022, HPE published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Cloudline CL2200 Gen10 Server \u2013 versions prior to BMC 12.77.04<\/li>\n\t<li>HPE Cloudline CL2100 Gen10 Server \u2013 versions prior to BMC 12.77.04<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution or privilege elevation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04385en_us\">HPE Security Bulletin (HPESBHF04385)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-657","alert_type":396,"serial_number":"AV22-657","subject":null,"moderation_state":"published","external_url":null},{"nid":3733,"title":"[Control systems] ABB security advisory (AV22-658)","uuid":"5e67ce33-673b-4acb-965f-6baf2ca2bcd4","banner":null,"lang":"en","date_modified":"2022-11-24","date_modified_ts":"2022-11-24T20:33:05Z","date_created":"2022-11-24T20:32:30Z","summary":null,"body":["<article data-history-node-id=\"3733\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-658\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-658<\/strong><br \/><strong>Date: 24 November 2022<\/strong><\/p>\n\n<p>On 21 November 2022, ABB published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>APROL \u2013 version R4.0 and later<\/li>\n\t<li>ARM600 M2M Gateway series \u2013 multiple models with firmware version 5.0.2 and prior<\/li>\n\t<li>ARM600 M2M Gateway Enterprise Edition series \u2013 multiple models with firmware version 5.0.2 and prior<\/li>\n\t<li>ARM600SW M2M Gateway \u2013 multiple models with firmware version 5.0.2 and prior<\/li>\n\t<li>AS Target for Simulink \u2013 version 6.2 and later<\/li>\n\t<li>B&amp;R Automation Studio (AS) \u2013 version 4.0 and later<\/li>\n\t<li>B&amp;R Technology Guarding (TG) \u2013 version 1.3 and prior<\/li>\n\t<li>Process Visualization Interface (PVI) \u2013 version 4.0 and later<\/li>\n\t<li>Viola Systems M2M Gateway Enterprise Edition series \u2013 firmware versions 3.x.x<\/li>\n\t<li>Viola Systems M2M Gateway series \u2013 firmware versions 3.x.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001478\">ABB Security Advisory (2NGA001478)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1667745192537-en-original-1.0.pdf\">ABB Security Advisory (1667745192537)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-658","alert_type":398,"serial_number":"AV22-658","subject":null,"moderation_state":"published","external_url":null},{"nid":3734,"title":"Google Chrome security advisory (AV22-659)","uuid":"fd897c64-e906-4524-adec-f6f04b2b8a7c","banner":null,"lang":"en","date_modified":"2022-11-24","date_modified_ts":"2022-11-24T20:38:53Z","date_created":"2022-11-24T20:35:49Z","summary":null,"body":["<article data-history-node-id=\"3734\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-659\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-659<\/strong><br \/><strong>Date: 24 November 2022<\/strong><\/p>\n\n<p>On 24 November 2022, Google published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 107.0.5304.121<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2022-4135 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/11\/stable-channel-update-for-desktop_24.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-659","alert_type":396,"serial_number":"AV22-659","subject":null,"moderation_state":"published","external_url":null},{"nid":3737,"title":"Dell security advisory (AV22-660)","uuid":"f02bc29d-819a-4842-a977-8ac209949b9d","banner":null,"lang":"en","date_modified":"2022-11-28","date_modified_ts":"2022-11-28T16:27:19Z","date_created":"2022-11-28T16:26:34Z","summary":null,"body":["<article data-history-node-id=\"3737\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-660\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-660<\/strong><br \/><strong>Date: 28 November 2022<\/strong><\/p>\n\n<p>Between 21 November and 27 November 2022, Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Command | Configure \u2013 versions prior to 4.9.0<\/li>\n\t<li>Dell Enterprise Hybrid Cloud \u2013 versions prior to 4.1.2<\/li>\n\t<li>Dell Virtual Storage Integrator for VMWare vSphere Client \u2013 versions 9.1.1 and 10.0<\/li>\n\t<li>Cloud Tiering Appliance \u2013 multiple versions<\/li>\n\t<li>PowerScale OneFS \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-660","alert_type":396,"serial_number":"AV22-660","subject":null,"moderation_state":"published","external_url":null},{"nid":3738,"title":"IBM security advisory (AV22-661)","uuid":"6eb6190e-8704-492e-88f8-053e77ba804f","banner":null,"lang":"en","date_modified":"2022-11-28","date_modified_ts":"2022-11-28T16:52:46Z","date_created":"2022-11-28T16:42:52Z","summary":null,"body":["<article data-history-node-id=\"3738\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-661\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-661<\/strong><br \/><strong>Date: 28 November 2022<\/strong><\/p>\n\n<p>Between 21 November and 27 November 2022, IBM published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cloud Pak for Security (CP4S) \u2013 versions 1.10.0.0 to 1.10.4.0<\/li>\n\t<li>IBM QRadar Network Security \u2013 versions 5.4.0 and 5.5.0<\/li>\n\t<li>IBM QRadar SIEM \u2013 versions 7.4.0 to 7.4.3 Fix Pack 7 and 7.5.0 to 7.5.0 Update Pack 3 Interim Fix 2<\/li>\n\t<li>IBM Security Verify Governance \u2013 version 10.0<\/li>\n\t<li>IBM Sterling Connect:Direct File Agent \u2013 versions 1.4.0.0 to 1.4.0.2_iFix028<\/li>\n\t<li>IBM Sterling Connect:Direct for Microsoft Windows \u2013 multiple versions<\/li>\n\t<li>InfoSphere Information Server, InfoSphere Information Server on Cloud \u2013 version 11.7<\/li>\n\t<li>Log Analysis \u2013 versions 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1 and 1.3.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/blogs\/psirt\">IBM Product Security Incident Response <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-661","alert_type":396,"serial_number":"AV22-661","subject":null,"moderation_state":"published","external_url":null},{"nid":3739,"title":"[Control systems] Hitachi Energy security advisory (AV22-662)","uuid":"ff3b59b2-3c67-49b7-b55d-0bd9655fb57c","banner":null,"lang":"en","date_modified":"2022-11-29","date_modified_ts":"2022-11-29T21:14:12Z","date_created":"2022-11-29T21:09:43Z","summary":null,"body":["<article data-history-node-id=\"3739\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-662\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-662<\/strong><br \/><strong>Date: 29 November 2022<\/strong><\/p>\n\n<p>On 29 November 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SYS600 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an authenticated actor to escalate privileges.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-333-03\">ICS Advisory (ICSA-22-333-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av22-662","alert_type":398,"serial_number":"AV22-662","subject":null,"moderation_state":"published","external_url":null},{"nid":3740,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-663)","uuid":"1b694889-a8ea-4a13-998a-5d6b36f1aede","banner":null,"lang":"en","date_modified":"2022-11-29","date_modified_ts":"2022-11-29T21:34:39Z","date_created":"2022-11-29T21:29:37Z","summary":null,"body":["<article data-history-node-id=\"3740\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-663\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-663<\/strong><br \/><strong>Date: 29 November 2022<\/strong><\/p>\n\n<p>On 29 November 2022, ICS-CERT published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GOT2000 Series \u2013 multiple versions and models<\/li>\n\t<li>GX Works3 \u2013 multiple versions<\/li>\n\t<li>MX OPC UA Module Configurator-R \u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service or a full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-333-01\">ICS Advisory (ICSA-22-333-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-333-05\">ICS Advisory (ICSA-22-333-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-663","alert_type":398,"serial_number":"AV22-663","subject":null,"moderation_state":"published","external_url":null},{"nid":3741,"title":"[Control systems] Moxa security advisory (AV22-664)","uuid":"8c67943b-a723-42f5-a04c-777101bb34c4","banner":null,"lang":"en","date_modified":"2022-11-29","date_modified_ts":"2022-11-29T21:40:55Z","date_created":"2022-11-29T21:36:51Z","summary":null,"body":["<article data-history-node-id=\"3741\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av22-664\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-664<\/strong><br \/><strong>Date: 29 November 2022<\/strong><\/p>\n\n<p>On 29 November 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Moxa UC Series \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an actor with physical access to take full control of the system.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-333-04\">ICS Advisory (ICSA-22-333-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av22-664","alert_type":398,"serial_number":"AV22-664","subject":null,"moderation_state":"published","external_url":null},{"nid":3744,"title":"Google Chrome security advisory (AV22-665)","uuid":"b66af7b7-ca79-436a-9da1-3e6debd87873","banner":null,"lang":"en","date_modified":"2022-11-30","date_modified_ts":"2022-11-30T18:15:33Z","date_created":"2022-11-30T18:14:09Z","summary":null,"body":["<article data-history-node-id=\"3744\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-665\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-665<\/strong><br \/><strong>Date: 30 November 2022<\/strong><\/p>\n\n<p>On 29 November 2022, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 108.0.5359.71\/72<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/11\/stable-channel-update-for-desktop_29.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-665","alert_type":396,"serial_number":"AV22-665","subject":null,"moderation_state":"published","external_url":null},{"nid":3745,"title":"NVIDIA security advisory (AV22-666)","uuid":"02137ed5-6e57-4d87-a6f8-645bb16f70c0","banner":null,"lang":"en","date_modified":"2022-11-30","date_modified_ts":"2022-11-30T21:12:10Z","date_created":"2022-11-30T21:11:37Z","summary":null,"body":["<article data-history-node-id=\"3745\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-av22-666\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-666<\/strong><br \/><strong>Date: 30 November 2022<\/strong><\/p>\n\n<p>On 28 November 2022, NVIDIA published a Security Bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NVIDIA GPU Display Driver \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution, denial of service, escalation of privileges, information disclosure or data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5415\">NVIDIA Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-av22-666","alert_type":396,"serial_number":"AV22-666","subject":null,"moderation_state":"published","external_url":null},{"nid":3751,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-667)","uuid":"78b8f07a-2b72-48fb-acdd-285ad3924266","banner":null,"lang":"en","date_modified":"2022-12-02","date_modified_ts":"2022-12-02T18:59:13Z","date_created":"2022-12-02T18:49:51Z","summary":null,"body":["<article data-history-node-id=\"3751\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-667\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-667<\/strong><br \/><strong>Date: 2 December 2022<\/strong><\/p>\n\n<p>On 1 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>RJ71EN71 \u2013 firmware version 65 and prior<\/li>\n\t<li>R04\/08\/16\/32\/120ENCPU \u2013 firmware version 65 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-335-01\">ICS Advisory (ICSA-22-335-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-667","alert_type":398,"serial_number":"AV22-667","subject":null,"moderation_state":"published","external_url":null},{"nid":3752,"title":"[Control systems] BD security advisory (AV22-668)","uuid":"2739b9c4-a334-4012-9688-219c69a3723e","banner":null,"lang":"en","date_modified":"2022-12-02","date_modified_ts":"2022-12-02T19:16:23Z","date_created":"2022-12-02T19:08:13Z","summary":null,"body":["<article data-history-node-id=\"3752\" about=\"\/en\/alerts-advisories\/control-systems-bd-security-advisory-av22-668\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-668<\/strong><br \/><strong>Date: 2 December 2022<\/strong><\/p>\n\n<p>On 1 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>BD BodyGuard<\/li>\n\t<li>CME BodyGuard 323 (2nd Edition)<\/li>\n\t<li>CME BodyGuard 323 Color Vision (2nd Edition)<\/li>\n\t<li>CME BodyGuard 323 Color Vision (3rd Edition)<\/li>\n\t<li>CME BodyGuard Twins (2nd Edition)<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service or an alteration of device configurations.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsma-22-335-01\">ICS Advisory (ICSMA-22-335-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bd-security-advisory-av22-668","alert_type":398,"serial_number":"AV22-668","subject":null,"moderation_state":"published","external_url":null},{"nid":3753,"title":"[Control systems] Horner Automation security advisory (AV22-669)","uuid":"cef41208-4c74-4ed8-b2a9-4c4e7ed49137","banner":null,"lang":"en","date_modified":"2022-12-02","date_modified_ts":"2022-12-02T19:22:37Z","date_created":"2022-12-02T19:20:15Z","summary":null,"body":["<article data-history-node-id=\"3753\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av22-669\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-669<\/strong><br \/><strong>Date: 2 December 2022<\/strong><\/p>\n\n<p>On 1 December 2022, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>RCC 972 \u2013 firmware version 15.40<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-335-02\">ICS Advisory (ICSA-22-335-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av22-669","alert_type":398,"serial_number":"AV22-669","subject":null,"moderation_state":"published","external_url":null},{"nid":3762,"title":"[Control Systems] ABB security advisory (AV22-670)","uuid":"6935959e-c9fd-41c3-ae36-9b1d7a807089","banner":null,"lang":"en","date_modified":"2022-12-02","date_modified_ts":"2022-12-02T20:34:37Z","date_created":"2022-12-02T20:34:03Z","summary":null,"body":["<article data-history-node-id=\"3762\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-670\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-670<\/strong><br \/><strong>Date: 2 December 2022<\/strong><\/p>\n\n<p>On 29 November 2022, ABB published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB zenon \u2013 versions prior to 8.20 (104000)<\/li>\n\t<li>ZEE600 \u2013 version 2.0.1 and prior<\/li>\n\t<li>ZEE600C \u2013 version 2.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001479\">ABB Security Advisory (2NGA001479)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-670","alert_type":398,"serial_number":"AV22-670","subject":null,"moderation_state":"published","external_url":null},{"nid":3805,"title":"Ubuntu security advisory (AV22-671)","uuid":"5934f72f-5cf1-4bd1-ae1e-d0f6598f7e1f","banner":null,"lang":"en","date_modified":"2022-12-05","date_modified_ts":"2022-12-05T19:24:09Z","date_created":"2022-12-05T19:19:53Z","summary":null,"body":["<article data-history-node-id=\"3805\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-671\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-671<\/strong><br \/><strong>Date: 5 December 2022<\/strong><\/p>\n\n<p>Between 28 November and 4 December 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-671","alert_type":396,"serial_number":"AV22-671","subject":null,"moderation_state":"published","external_url":null},{"nid":3806,"title":"IBM security advisory (AV22-672)","uuid":"1ff8e5c7-0dc0-4ce4-b5eb-c90152d539ac","banner":null,"lang":"en","date_modified":"2022-12-05","date_modified_ts":"2022-12-05T19:31:59Z","date_created":"2022-12-05T19:31:32Z","summary":null,"body":["<article data-history-node-id=\"3806\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-672\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-672<\/strong><br \/><strong>Date: 5 December 2022<\/strong><\/p>\n\n<p>Between 28 November and 4 December 2022, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>App Connect Enterprise Certified Container \u2013 versions 4.1, 4.2, 5.0-lts, 5.1, 5.2, 6.0 and 6.1<\/li>\n\t<li>IBM MQ Operator \u2013 version LTS release 2.0.4 and CD release 2.1<\/li>\n\t<li>IBM Operations Analytics Predictive Insights \u2013 versions 1.3.3, 1.3.5 and 1.3.6<\/li>\n\t<li>IBM Planning Analytics Workspace \u2013 version 2.0<\/li>\n\t<li>IBM Sterling Connect:Direct for UNIX \u2013 multiple versions<\/li>\n\t<li>IBM Sterling Control Center \u2013 version 6.2.1.0 GA to iFix08<\/li>\n\t<li>IBM supplied MQ Advanced container images \u2013 version 9.3.0.1-r2, 9.3.1.0-r1 and prior<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data \u2013 version 4.0.0 to 4.5.4<\/li>\n\t<li>UCD \u2013 IBM UrbanCode Deploy \u2013 versions 7.1.0.0 to 7.1.2.8 and 7.2.0.0 to 7.2.3.1<\/li>\n\t<li>Watson Discovery \u2013 version 4.0.0 to 4.5.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-672","alert_type":396,"serial_number":"AV22-672","subject":null,"moderation_state":"published","external_url":null},{"nid":3807,"title":"Dell security advisory (AV22-673)","uuid":"b9545eb4-03fc-4a8c-a09e-5fd20bf053e2","banner":null,"lang":"en","date_modified":"2022-12-05","date_modified_ts":"2022-12-05T19:39:59Z","date_created":"2022-12-05T19:35:43Z","summary":null,"body":["<article data-history-node-id=\"3807\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-673\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-673<\/strong><br \/><strong>Date: 5 December 2022<\/strong><\/p>\n\n<p>Between 28 November and 4 December 2022, Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Command | Configure \u2013 versions 4.6, 4.7 and 4.8<\/li>\n\t<li>Dell Command | Integration Suite for System Center \u2013 versions 6.2 and 6.3<\/li>\n\t<li>Dell Command | Intel vPro Out of Band \u2013 versions 4.2 and 4.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/000205888\/dsa-2022-333-dell-command-configure-for-linux-os-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Advisory (DSA-2022-333)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/000205885\/dsa-2022-331-dell-command-integration-suite-security-update-for\">Dell Security Advisory (DSA-2022-331)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/000205886\/title-dsa-2022-332-dell-command-integration-suite-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Advisory (DSA-2022-332)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-673","alert_type":396,"serial_number":"AV22-673","subject":null,"moderation_state":"published","external_url":null},{"nid":3808,"title":"Red Hat security advisory (AV22-674)","uuid":"5310f545-5c28-40fe-91b8-7117de77666e","banner":null,"lang":"en","date_modified":"2022-12-05","date_modified_ts":"2022-12-05T20:10:00Z","date_created":"2022-12-05T19:41:54Z","summary":null,"body":["<article data-history-node-id=\"3808\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-674\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-674<\/strong><br \/><strong>Date: 5 December 2022<\/strong><\/p>\n\n<p>On 2 December 2022, Red Hat published Security Advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:8768\">Red Hat Security Advisory (RHSA-2022:8768)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:8767\">Red Hat Security Advisory (RHSA-2022:8767)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:8765\">Red Hat Security Advisory (RHSA-2022:8765)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories  \">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-674","alert_type":396,"serial_number":"AV22-674","subject":null,"moderation_state":"published","external_url":null},{"nid":3809,"title":"HPE security advisory (AV22-675)","uuid":"9fc157d1-62ba-4743-abd7-7373edb7c60a","banner":null,"lang":"en","date_modified":"2022-12-05","date_modified_ts":"2022-12-05T20:19:38Z","date_created":"2022-12-05T20:15:01Z","summary":null,"body":["<article data-history-node-id=\"3809\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-675\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-675<\/strong><br \/><strong>Date: 5 December 2022<\/strong><\/p>\n\n<p>On 29 and 30 November 2022, HPE published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AirWave Management Platform \u2013 version 8.2.15.0 and prior<\/li>\n\t<li>HP-UX Apache-based Web Server \u2013 versions prior to B.2.4.54.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04391en_us\">HPE Security Bulletin (HPESBNW04391)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04397en_us\">Red Hat Security Advisory (RHSA-2022:8767)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-675","alert_type":396,"serial_number":"AV22-675","subject":null,"moderation_state":"published","external_url":null},{"nid":3810,"title":"GitLab security advisory (AV22-676)","uuid":"b676dda0-e9bb-4732-a1eb-f4e61bd0d9f9","banner":null,"lang":"en","date_modified":"2022-12-05","date_modified_ts":"2022-12-05T20:25:54Z","date_created":"2022-12-05T20:22:11Z","summary":null,"body":["<article data-history-node-id=\"3810\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av22-676\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-676<\/strong><br \/><strong>Date: 5 December 2022<\/strong><\/p>\n\n<p>On 30 November 2022, GitLab published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) - versions prior to 15.6.1, 15.5.5 and 15.4.6<\/li>\n\t<li>GitLab Enterprise Edition (EE) - versions prior to 15.6.1, 15.5.5 and 15.4.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2022\/11\/30\/security-release-gitlab-15-6-1-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av22-676","alert_type":396,"serial_number":"AV22-676","subject":null,"moderation_state":"published","external_url":null},{"nid":3811,"title":"Sophos security advisory (AV22-677)","uuid":"44ac915f-4c33-4265-b2d3-ca4851c69143","banner":null,"lang":"en","date_modified":"2022-12-05","date_modified_ts":"2022-12-05T20:31:28Z","date_created":"2022-12-05T20:28:55Z","summary":null,"body":["<article data-history-node-id=\"3811\" about=\"\/en\/alerts-advisories\/sophos-security-advisory-av22-677\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-677<\/strong><br \/><strong>Date: 5 December 2022<\/strong><\/p>\n\n<p>On 1 December 2022, Sophos published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Sophos Firewall \u2013 versions prior to v19.5 GA<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sophos.com\/en-us\/security-advisories\/sophos-sa-20221201-sfos-19-5-0\">Sophos Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sophos-security-advisory-av22-677","alert_type":396,"serial_number":"AV22-677","subject":null,"moderation_state":"published","external_url":null},{"nid":3812,"title":"Trend Micro security advisory (AV22-678)","uuid":"dc1d875b-3d27-43c7-8b21-3c2d92ed7ca1","banner":null,"lang":"en","date_modified":"2022-12-06","date_modified_ts":"2022-12-06T14:58:19Z","date_created":"2022-12-06T14:54:14Z","summary":null,"body":["<article data-history-node-id=\"3812\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory-av22-678\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-678<\/strong><br \/><strong>Date: 6 December 2022<\/strong><\/p>\n\n<p>On 1 December 2022, Trend Micro published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apex One<\/li>\n\t<li>Apex One as a Service<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/success.trendmicro.com\/dcx\/s\/solution\/000291830?language=en_US\">Trend Micro Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory-av22-678","alert_type":396,"serial_number":"AV22-678","subject":null,"moderation_state":"published","external_url":null},{"nid":3813,"title":"Android security advisory \u2013 December 2022 monthly rollup (AV22-679)","uuid":"0666f26f-a6e2-4ef4-9e51-6881871811e7","banner":null,"lang":"en","date_modified":"2022-12-06","date_modified_ts":"2022-12-06T15:06:15Z","date_created":"2022-12-06T15:01:57Z","summary":null,"body":["<article data-history-node-id=\"3813\" about=\"\/en\/alerts-advisories\/android-security-advisory-december-2022-monthly-rollup-av22-679\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-679<\/strong><br \/><strong>Date: 6 December 2022<\/strong><\/p>\n\n<p>On 5 December 2022, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2022-12-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-december-2022-monthly-rollup-av22-679","alert_type":396,"serial_number":"AV22-679","subject":null,"moderation_state":"published","external_url":null},{"nid":3814,"title":"Microsoft Edge security advisory (AV22-680)","uuid":"bd85aef9-9bce-40fd-b421-6a1ba9e90b66","banner":null,"lang":"en","date_modified":"2022-12-06","date_modified_ts":"2022-12-06T15:09:22Z","date_created":"2022-12-06T15:08:29Z","summary":null,"body":["<article data-history-node-id=\"3814\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-680\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-680<\/strong><br \/><strong>Date: 6 December 2022<\/strong><\/p>\n\n<p>On 5 December 2022, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 108.0.1462.42<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2022-4262 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-5-2022\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-680","alert_type":396,"serial_number":"AV22-680","subject":null,"moderation_state":"published","external_url":null},{"nid":3815,"title":"Intel security advisory (AV22-681)","uuid":"55beb6e4-5213-4aa8-ba02-7cab46aceb38","banner":null,"lang":"en","date_modified":"2022-12-06","date_modified_ts":"2022-12-06T20:46:41Z","date_created":"2022-12-06T20:43:40Z","summary":null,"body":["<article data-history-node-id=\"3815\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av22-681\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-681<\/strong><br \/><strong>Date: 6 December 2022<\/strong><\/p>\n\n<p>On 5 December 2022, Intel published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Intel Server Board M10JNP2SB Family \u2013 BMC Firmware versions prior to 1.11<\/li>\n\t<li>Intel Server Board M20NTP Family \u2013 BMC Firmware versions prior to v0027<\/li>\n\t<li>Intel Server Board M70KLP2SB Family \u2013 BMC Firmware versions prior to 4.15<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00801.html\">Intel Security Advisory (INTEL-SA-00801)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av22-681","alert_type":396,"serial_number":"AV22-681","subject":null,"moderation_state":"published","external_url":null},{"nid":3816,"title":"Fortinet Security Advisory (AV22-682)","uuid":"e8612e14-b694-49c3-8920-dcccfcc5a054","banner":null,"lang":"en","date_modified":"2022-12-06","date_modified_ts":"2022-12-06T20:53:32Z","date_created":"2022-12-06T20:50:10Z","summary":null,"body":["<article data-history-node-id=\"3816\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-682\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-682<\/strong><br \/><strong>Date: 6 December 2022<\/strong><\/p>\n\n<p>On 6 December 2022, Fortinet published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiOS \u2013 multiple versions<\/li>\n\t<li>FortiProxy \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-255\">Fortinet PSIRT Advisory (FG-IR-22-255)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-682","alert_type":396,"serial_number":"AV22-682","subject":null,"moderation_state":"published","external_url":null},{"nid":3817,"title":"HPE security advisory (AV22-683)","uuid":"8acd1e21-e565-4c27-a8e1-f007de69cd3b","banner":null,"lang":"en","date_modified":"2022-12-07","date_modified_ts":"2022-12-07T21:39:45Z","date_created":"2022-12-07T21:36:48Z","summary":null,"body":["<article data-history-node-id=\"3817\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-683\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-683<\/strong><br \/><strong>Date: 7 December 2022<\/strong><\/p>\n\n<p>On 6 December 2022, HPE published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Aruba ClearPass Policy Manager 6.10.x \u2013 version 6.10.7 and prior<\/li>\n\t<li>Aruba ClearPass Policy Manager 6.9.x \u2013 version 6.9.12 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04394en_us\">HPE Security Advisory (hpesbnw04394)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-683","alert_type":396,"serial_number":"AV22-683","subject":null,"moderation_state":"published","external_url":null},{"nid":3818,"title":"Proofpoint security advisory (AV22-684)","uuid":"bdf73388-ba65-4ef2-b244-80a055c12ef1","banner":null,"lang":"en","date_modified":"2022-12-07","date_modified_ts":"2022-12-07T21:46:42Z","date_created":"2022-12-07T21:42:00Z","summary":null,"body":["<article data-history-node-id=\"3818\" about=\"\/en\/alerts-advisories\/proofpoint-security-advisory-av22-684\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-684<\/strong><br \/><strong>Date: 7 December 2022<\/strong><\/p>\n\n<p>On 6 December 2022, Proofpoint published Security Advisories to address vulnerabilities in the following produc:<\/p>\n\n<ul><li>Proofpoint Enterprise Protection \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.proofpoint.com\/us\/security\/security-advisories\/pfpt-sa-2022-0002\">Proofpoint Security Advisory (PFPT-SA-2022-0002)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.proofpoint.com\/us\/security\/security-advisories\/pfpt-sa-2022-0003\">Proofpoint Security Advisory (PFPT-SA-0003)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.proofpoint.com\/us\/security\/security-advisories\">Proofpoint Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/proofpoint-security-advisory-av22-684","alert_type":396,"serial_number":"AV22-684","subject":null,"moderation_state":"published","external_url":null},{"nid":3820,"title":"[Control systems] Advantech\u00a0security advisory (AV22-685)","uuid":"110e10f4-c703-4d7c-9c27-e122860cb8d7","banner":null,"lang":"en","date_modified":"2022-12-08","date_modified_ts":"2022-12-08T20:18:32Z","date_created":"2022-12-08T20:17:47Z","summary":null,"body":["<article data-history-node-id=\"3820\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-685\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-685<\/strong><br \/><strong>Date: 8 December 2022<\/strong><\/p>\n\n<p>On 8 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Advantech iView \u2013 version 5.7.04.6469 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-342-01\">ICS Advisory (ICSA-22-342-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av22-685","alert_type":398,"serial_number":"AV22-685","subject":null,"moderation_state":"published","external_url":null},{"nid":3821,"title":"[Control systems] AVEVA security advisory (AV22-686)","uuid":"c563e82e-1b17-48e0-8a75-4ff3bb54b922","banner":null,"lang":"en","date_modified":"2022-12-08","date_modified_ts":"2022-12-08T20:38:37Z","date_created":"2022-12-08T20:22:13Z","summary":null,"body":["<article data-history-node-id=\"3821\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-686\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-686<\/strong><br \/><strong>Date: 8 December 2022<\/strong><\/p>\n\n<p>On 8 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>AVEVA InTouch Access Anywhere \u2013 version 2020 R2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-342-02\">ICS Advisory (ICSA-22-342-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av22-686","alert_type":398,"serial_number":"AV22-686","subject":null,"moderation_state":"published","external_url":null},{"nid":3822,"title":"[Control systems] Rockwell Automation security advisory (AV22-687)","uuid":"30cba34f-ff8a-46dd-b6cf-04c144cacbd6","banner":null,"lang":"en","date_modified":"2022-12-08","date_modified_ts":"2022-12-08T21:08:25Z","date_created":"2022-12-08T21:03:25Z","summary":null,"body":["<article data-history-node-id=\"3822\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-687\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-687<\/strong><br \/><strong>Date: 8 December 2022<\/strong><\/p>\n\n<p>On 8 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>CompactLogix 5380 controllers \u2013 firmware version 31.011 and prior<\/li>\n\t<li>Compact GuardLogix 5380 controllers \u2013 firmware version 31.011 and prior<\/li>\n\t<li>CompactLogix 5480 controllers \u2013 firmware version 32.011 and prior<\/li>\n\t<li>ControlLogix 5580 controllers \u2013 firmware version 31.011 and prior<\/li>\n\t<li>GuardLogix 5580 controllers \u2013 firmware version 31.011 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"&#10;https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-342-03\">ICS Advisory (ICSA-22-342-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-687","alert_type":398,"serial_number":"AV22-687","subject":null,"moderation_state":"published","external_url":null},{"nid":3823,"title":"Cisco security advisory (AV22-688)","uuid":"e3a1ffcb-43a3-49d5-a4ba-a1a0d3686b38","banner":null,"lang":"en","date_modified":"2022-12-08","date_modified_ts":"2022-12-08T21:12:28Z","date_created":"2022-12-08T21:11:51Z","summary":null,"body":["<article data-history-node-id=\"3823\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av22-688\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-688<\/strong><br \/><strong>Date: 8 December 2022<\/strong><\/p>\n\n<p>On 8 December 2022, Cisco published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>IP Phone 7800 Series \u2013 version 14.2 and prior<\/li>\n\t<li>IP Phone 8800 Series \u2013 version 14.2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service or remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ipp-oobwrite-8cMF5r7U\">Cisco Security Advisory (cisco-sa-ipp-oobwrite-8cMF5r7U)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av22-688","alert_type":396,"serial_number":"AV22-688","subject":null,"moderation_state":"published","external_url":null},{"nid":3824,"title":"VMware security advisory (AV22-689)","uuid":"8d3614db-46b4-494e-9c7e-f6f2adfd2dba","banner":null,"lang":"en","date_modified":"2022-12-09","date_modified_ts":"2022-12-09T18:30:48Z","date_created":"2022-12-09T18:27:18Z","summary":null,"body":["<article data-history-node-id=\"3824\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-689\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-689<\/strong><br \/><strong>Date: 9 December 2022<\/strong><\/p>\n\n<p>On 8 December 2022, VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cloud Foundation \u2013 versions 3.x and 4.x<\/li>\n\t<li>ESXi \u2013 versions 6.5, 6.7 and 7.0<\/li>\n\t<li>vCenter Server \u2013 versions 6.5, 6.7 and 7.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates..<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0030.html\">VMSA-2022-0030<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-689","alert_type":396,"serial_number":"AV22-689","subject":null,"moderation_state":"published","external_url":null},{"nid":3826,"title":"Dell security advisory (AV22-690)","uuid":"fbce6b08-25ce-45a4-9a92-f02b0714980a","banner":null,"lang":"en","date_modified":"2022-12-12","date_modified_ts":"2022-12-12T20:11:49Z","date_created":"2022-12-12T20:11:13Z","summary":null,"body":["<article data-history-node-id=\"3826\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-690\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-690<\/strong><br \/><strong>Date: 12 December 2022<\/strong><\/p>\n\n<p>Between 5 and 11 December 2022, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen5A \u2013 version 19.4 and later<\/li>\n\t<li>Dell ECS \u2013 versions prior to 3.6.x, 3.7, 3.7.0.1, 3.7.0.2, 3.7.0.3 and 3.7.0.4<\/li>\n\t<li>NetWorker vProxy \u2013 version 4.3.0-34 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206085\/dsa-2022-344-dell-emc-avamar-ads-gen5a-march-2022-block-release-security-update\">Dell Security Update (Dell Avamar Data Store Gen5A)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206201\/dsa-2022-294-dell-ecs-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update (Dell ECS)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206067\/dsa-2022-342-dell-networker-vproxy-security-update-for-multiple-vulnerabilities\">Dell Security Update (NetWorker vProxy)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-690","alert_type":396,"serial_number":"AV22-690","subject":null,"moderation_state":"published","external_url":null},{"nid":3827,"title":"IBM security advisory (AV22-691)","uuid":"e8d4973b-ee1e-4f72-878d-01b349d4e507","banner":null,"lang":"en","date_modified":"2022-12-12","date_modified_ts":"2022-12-12T20:34:31Z","date_created":"2022-12-12T20:33:57Z","summary":null,"body":["<article data-history-node-id=\"3827\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-691\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-691<\/strong><br \/><strong>Date: 12 December 2022<\/strong><\/p>\n\n<p>Between 5 and 11 December 2022, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Data Risk Manager (DRM) \u2013 version 2.0.6.14<\/li>\n\t<li>InfoSphere Information Server and InfoSphere Information Server on Cloud \u2013 version 11.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6846157\">IBM Security Bulletin (IBM DRM) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6841279\">IBM Security Bulletin (InfoSphere Information Server, InfoSphere Information Server on Cloud) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-691","alert_type":396,"serial_number":"AV22-691","subject":null,"moderation_state":"published","external_url":null},{"nid":3829,"title":"Intel security advisory (AV22-692)","uuid":"01601d71-ad92-468e-ad81-b675fddc4d7a","banner":null,"lang":"en","date_modified":"2022-12-12","date_modified_ts":"2022-12-12T20:48:24Z","date_created":"2022-12-12T20:40:44Z","summary":null,"body":["<article data-history-node-id=\"3829\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av22-692\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-692<\/strong><br \/><strong>Date: 12 December 2022<\/strong><\/p>\n\n<p>On 9 December 2022, Intel published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Intel OpenIPC binaries for At-Scale Debug (ASD)<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00789.html\">Intel Security Advisory (INTEL-SA-00789)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av22-692","alert_type":396,"serial_number":"AV22-692","subject":null,"moderation_state":"published","external_url":null},{"nid":3830,"title":"Fortinet security advisory (AV22-693)","uuid":"d13435e6-22f6-4833-8b99-ff6a50386dcd","banner":null,"lang":"en","date_modified":"2022-12-12","date_modified_ts":"2022-12-12T20:55:13Z","date_created":"2022-12-12T20:51:20Z","summary":null,"body":["<article data-history-node-id=\"3830\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av22-693\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-693<\/strong><br \/><strong>Date: 12 December 2022<\/strong><\/p>\n\n<p>On 12 December 2022, Fortinet published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>FortiOS \u2013 multiple versions<\/li>\n\t<li>FortiOS-6K7K \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code or command execution.<\/p>\n\n<p>Fortinet has reported that vulnerability CVE-2022-42475 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-398\">Fortiguard PSIRT Advisory (FG-IR-22-398)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av22-693","alert_type":396,"serial_number":"AV22-693","subject":null,"moderation_state":"published","external_url":null},{"nid":3831,"title":"Lenovo security advisory (AV22-694)","uuid":"1d2d057c-e663-4553-8b62-282d9c35f905","banner":null,"lang":"en","date_modified":"2022-12-12","date_modified_ts":"2022-12-12T21:02:35Z","date_created":"2022-12-12T20:59:42Z","summary":null,"body":["<article data-history-node-id=\"3831\" about=\"\/en\/alerts-advisories\/lenovo-security-advisory-av22-694\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-693<\/strong><br \/><strong>Date: 12 December 2022<\/strong><\/p>\n\n<p>On 7 December 2022, Lenovo published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Converged HX \u2013 multiple platforms<\/li>\n\t<li>Hyperscale \u2013 multiple platforms<\/li>\n\t<li>Storage \u2013 multiple platforms<\/li>\n\t<li>ThinkServer \u2013 multiple platforms<\/li>\n\t<li>ThinkSystem \u2013 multiple platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution, privilege elevation or credential disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.lenovo.com\/us\/en\/product_security\/LEN-98711\">Lenovo Security Advisory (LEN-98711)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/lenovo-security-advisory-av22-694","alert_type":396,"serial_number":"AV22-694","subject":null,"moderation_state":"published","external_url":null},{"nid":3832,"title":"Schneider Electric (AV22-695)","uuid":"0b573ce5-9dfb-437d-9b3f-caa2c2036579","banner":null,"lang":"en","date_modified":"2022-12-13","date_modified_ts":"2022-12-13T15:19:45Z","date_created":"2022-12-13T15:00:36Z","summary":null,"body":["<article data-history-node-id=\"3832\" about=\"\/en\/alerts-advisories\/schneider-electric-av22-695\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-695<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APC Easy UPS Online Monitoring Software\u00a0\u2013 versions V2.5-GA, V2.5-GA-01-22261 and prior<\/li>\n\t<li>EcoStruxture Power Commission\u00a0\u2013 version V2.25 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-347-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-347-01-APC_Easy_UPS_Online_Monitoring_Software_Security_Notification.pdf\">Schneider Electric Security Notification (SEVD-2022-347-01) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2022-347-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2022-347-03_EcoStruxure_Power_Commission_Security_Notification.pdf\">Schneider Electric Security Notification (SEVD-2022-347-03) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/schneider-electric-av22-695","alert_type":396,"serial_number":"AV22-695","subject":null,"moderation_state":"published","external_url":null},{"nid":3833,"title":"SAP security advisory \u2013 December 2022 monthly rollup (AV22-696)","uuid":"af6f0ada-ea64-4e0b-b97c-33818bdc2ca3","banner":null,"lang":"en","date_modified":"2022-12-13","date_modified_ts":"2022-12-13T17:43:31Z","date_created":"2022-12-13T17:38:48Z","summary":null,"body":["<article data-history-node-id=\"3833\" about=\"\/en\/alerts-advisories\/sap-security-advisory-december-2022-monthly-rollup-av22-696\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-696<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Business Client \u2013 versions 6.5, 7.0 and 7.70<\/li>\n\t<li>SAP Commerce \u2013 versions 1905, 2005, 2105, 2011 and 2205<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform \u2013 versions 420 and 430<\/li>\n\t<li>SAP NetWeaver Process Integration \u2013 version 7.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day\u00a0- December 2022<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-december-2022-monthly-rollup-av22-696","alert_type":396,"serial_number":"AV22-696","subject":null,"moderation_state":"published","external_url":null},{"nid":3834,"title":"Citrix security advisory (AV22-697)","uuid":"15c5d0d7-1b25-4d1d-addb-2b60386f0bcf","banner":null,"lang":"en","date_modified":"2022-12-13","date_modified_ts":"2022-12-13T17:53:17Z","date_created":"2022-12-13T17:48:01Z","summary":null,"body":["<article data-history-node-id=\"3834\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av22-697\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-697<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Citrix published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Citrix ADC \u2013 multiple versions<\/li>\n\t<li>Citrix Gateway \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX474995\/citrix-adc-and-citrix-gateway-security-bulletin-for-cve202227518\">CTX474995<\/a><\/li>\n\t<li><a href=\"https:\/\/www.citrix.com\/blogs\/2022\/12\/13\/critical-security-update-now-available-for-citrix-adc-citrix-gateway\/  \">Citrix CVE-2022-27518 Blog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av22-697","alert_type":396,"serial_number":"AV22-697","subject":null,"moderation_state":"published","external_url":null},{"nid":3835,"title":"[Control systems] Siemens security advisory (AV22-698)","uuid":"557624da-2b2e-488b-aa9c-6a49b93b606f","banner":null,"lang":"en","date_modified":"2022-12-13","date_modified_ts":"2022-12-13T17:58:14Z","date_created":"2022-12-13T17:55:25Z","summary":null,"body":["<article data-history-node-id=\"3835\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-698\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-698<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APOGEE PXC Series (BACnet) \u2013 versions prior to V3.5.5<\/li>\n\t<li>APOGEE PXC Series (P2 Ethernet) \u2013 versions prior to V2.8.20<\/li>\n\t<li>TALON TC Series (BACnet) \u2013 versions prior to V3.5.5<\/li>\n\t<li>SCALANCE X204RNA \u2013 multiple platforms, versions prior to V3.2.7<\/li>\n\t<li>SICAM PAS\/PQS \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-698","alert_type":398,"serial_number":"AV22-698","subject":null,"moderation_state":"published","external_url":null},{"nid":3836,"title":"Mozilla security advisory (AV22-699)","uuid":"8e5d06f1-0f59-4dee-9984-544d58d8a3af","banner":null,"lang":"en","date_modified":"2022-12-13","date_modified_ts":"2022-12-13T19:40:41Z","date_created":"2022-12-13T19:37:18Z","summary":null,"body":["<article data-history-node-id=\"3836\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-699\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-699<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 108<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 102.6<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 102.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-51\/\">Mozilla security advisory (Firefox)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-52\/\">Mozilla security advisory (Firefox ESR)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-53\/\">Mozilla security advisory (Thunderbird)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-699","alert_type":396,"serial_number":"AV22-699","subject":null,"moderation_state":"published","external_url":null},{"nid":3837,"title":"[Control systems] ICONICS and Mitsubishi electric security advisory (AV22-700)","uuid":"d9d83c22-2048-4dfd-a315-8ae8477734f8","banner":null,"lang":"en","date_modified":"2022-12-13","date_modified_ts":"2022-12-13T19:48:21Z","date_created":"2022-12-13T19:46:10Z","summary":null,"body":["<article data-history-node-id=\"3837\" about=\"\/en\/alerts-advisories\/control-systems-iconics-and-mitsubishi-electric-security-advisory-av22-700\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-700<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ICONICS Suite\u00a0\u2013 versions v10.96 to v10.97.2<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-347-01\">ICS Advisory (ICSA-22-347-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-iconics-and-mitsubishi-electric-security-advisory-av22-700","alert_type":398,"serial_number":"AV22-700","subject":null,"moderation_state":"published","external_url":null},{"nid":3838,"title":"[Control systems] Contec security advisory (AV22-701)","uuid":"07a6c94e-3ec2-464c-b575-0a38f7f491f6","banner":null,"lang":"en","date_modified":"2022-12-13","date_modified_ts":"2022-12-13T19:56:09Z","date_created":"2022-12-13T19:53:25Z","summary":null,"body":["<article data-history-node-id=\"3838\" about=\"\/en\/alerts-advisories\/control-systems-contec-security-advisory-av22-701\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-701<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>CONPROSYS HMI System (CHS)\u00a0\u2013 version 3.4.4 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to the execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-347-03\">ICS Advisory (ICSA-22-347-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-contec-security-advisory-av22-701","alert_type":398,"serial_number":"AV22-701","subject":null,"moderation_state":"published","external_url":null},{"nid":3839,"title":"Microsoft security advisory \u2013 December 2022 monthly rollup \u2013 Update 1 (AV22-702)","uuid":"bdfc5285-cd4e-4089-8b92-263c0aa1e87c","banner":null,"lang":"en","date_modified":"2022-12-14","date_modified_ts":"2022-12-14T13:34:50Z","date_created":"2022-12-14T13:27:55Z","summary":null,"body":["<article data-history-node-id=\"3839\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-december-2022-monthly-rollup-av22-702\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-702<\/strong>\n  <br \/><strong>Date: 13 December 2022<\/strong>\n<\/p>\n<p>On 13 December 2022, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>Microsoft Dynamics \u2013 multiple versions<\/li>\n  <li>Microsoft SharePoint \u2013 multiple versions<\/li>\n  <li>Microsoft .NET Framework \u2013 versions 3.5 and 4.8.1<\/li>\n  <li>PowerShell \u2013 versions 7.2 and 7.3<\/li>\n  <li>Windows 7 \u2013 multiple versions and platforms<\/li>\n  <li>Windows 8.1 \u2013 multiple versions and platforms<\/li>\n  <li>Windows 10 \u2013 multiple versions and platforms<\/li>\n  <li>Windows 11 \u2013 multiple versions and platforms<\/li>\n  <li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2022-44698 has been actively exploited.\n<\/p>\n<h2 class=\"h3\">Update 1\n<\/h2>\n<p>On 13 December 2022, Microsoft upgraded <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37958\">CVE-2022-37958<\/a> (13 September 2022) affecting the SPNEGO Extended Negotiation (NEGOEX) Security Mechanism from <strong>Important Information Disclosure<\/strong> to <strong>Critical Remote Code Execution<\/strong>. While there have been no reports of public exploitation, the Cyber Centre recommends clients consider applying the appropriate patches to protect their networks.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Dec\">December 2022 Release Notes<\/a><\/li>\n  <li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-december-2022-monthly-rollup-av22-702","alert_type":396,"serial_number":"AV22-702","subject":null,"moderation_state":"published","external_url":null},{"nid":3840,"title":"Red Hat security advisory (AV22-703)","uuid":"d6a036a4-29a3-4732-bf78-03e6aff8fc5b","banner":null,"lang":"en","date_modified":"2022-12-14","date_modified_ts":"2022-12-14T13:49:23Z","date_created":"2022-12-14T13:48:29Z","summary":null,"body":["<article data-history-node-id=\"3840\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av22-703\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-703<\/strong><br \/><strong>Date: 13 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates to address Linux kernel vulnerabilities in the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:8941\">Red Hat Security Advisory (RHSA-2022:8941)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:8973\">Red Hat Security Advisory (RHSA-2022:8973)<\/a><\/li>\n\t<li><a href=\"Red Hat Security Advisory (RHSA-2022:8974)\">Red Hat Security Advisory (RHSA-2022:8974)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2022:8989\">Red Hat Security Advisory (RHSA-2022:8989)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories \">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av22-703","alert_type":396,"serial_number":"AV22-703","subject":null,"moderation_state":"published","external_url":null},{"nid":3842,"title":"Apple security advisory (AV22-704)","uuid":"14ca4629-b17c-45b2-86c4-6b89d1c813e1","banner":null,"lang":"en","date_modified":"2022-12-14","date_modified_ts":"2022-12-14T16:02:58Z","date_created":"2022-12-14T16:01:55Z","summary":null,"body":["<article data-history-node-id=\"3842\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av22-704\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-704<\/strong><br \/><strong>Date: 14 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iCloud for Windows \u2013 versions prior to 14.1<\/li>\n\t<li>iOS\/iPadOS 15 \u2013 versions prior to 15.7.2<\/li>\n\t<li>iOS\/ iPadOS 16 \u2013 versions prior to 16.2<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.7.2<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.6.2<\/li>\n\t<li>macOS Ventura \u2013 versions prior to 13.1<\/li>\n\t<li>Safari \u2013 versions prior to 16.2<\/li>\n\t<li>tvOS \u2013 versions prior to 16.2<\/li>\n\t<li>watchOS \u2013 versions prior to 9.2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution, privilege escalation or access to sensitive information.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av22-704","alert_type":396,"serial_number":"AV22-704","subject":null,"moderation_state":"published","external_url":null},{"nid":3843,"title":"Google Chrome security advisory (AV22-705)","uuid":"04f494e5-7bcb-4b86-8de9-c40d5030c7f9","banner":null,"lang":"en","date_modified":"2022-12-14","date_modified_ts":"2022-12-14T16:13:34Z","date_created":"2022-12-14T16:07:31Z","summary":null,"body":["<article data-history-node-id=\"3843\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-705\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-705<\/strong><br \/><strong>Date: 14 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Google published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Chrome for Android \u2013 versions prior to 108.0.5359.128<\/li>\n\t<li>Chrome for Desktop \u2013 versions prior to 108.0.5359.124 (Mac and Linux) and 108.0.5359.125 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/12\/chrome-for-android-update_13.html\">Google Chrome Security Advisory (Android)<\/a><\/li>\n\t<li><a href=\"https:\/\/chromereleases.googleblog.com\/2022\/12\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory (Desktop)<\/a><\/li>\n\t<li><a href=\"https:\/\/chromereleases.googleblog.com\">Google Chrome Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av22-705","alert_type":396,"serial_number":"AV22-705","subject":null,"moderation_state":"published","external_url":null},{"nid":3844,"title":"HPE security advisory (AV22-706)","uuid":"7663a79d-ad86-498b-bf1e-47c157e9fcbd","banner":null,"lang":"en","date_modified":"2022-12-14","date_modified_ts":"2022-12-14T17:49:05Z","date_created":"2022-12-14T17:47:32Z","summary":null,"body":["<article data-history-node-id=\"3844\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av22-706\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-706<\/strong><br \/><strong>Date: 14 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, HPE published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Aruba EdgeConnect Enterprise Orchestrator\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04396en_us\">HPE Security Advisory (Aruba EdgeConnect)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/km\/Security-Bulletin-Library\">HPE Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av22-706","alert_type":396,"serial_number":"AV22-706","subject":null,"moderation_state":"published","external_url":null},{"nid":3847,"title":"VMware security advisory (AV22-707)","uuid":"1eabea2c-8c55-4775-af6e-df054e44094c","banner":null,"lang":"en","date_modified":"2022-12-15","date_modified_ts":"2022-12-15T20:57:00Z","date_created":"2022-12-15T20:56:20Z","summary":null,"body":["<article data-history-node-id=\"3847\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av22-707\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-707<\/strong><br \/><strong>Date: 15 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, VMware published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware Fusion \u2013 versions prior to 12.2.5<\/li>\n\t<li>VMware Workstation \u2013 versions prior to 16.2.5<\/li>\n\t<li>VMware vRealize Network Insight (vRNI) \u2013 versions 6.2, 6.3, 6.4 6.5.x, 6.6 and 6.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0031.html\">VMware Security Advisory (VMSA-2022-0031)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2022-0033.html\">VMware Security Advisory (VMSA-2022-0033)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av22-707","alert_type":396,"serial_number":"AV22-707","subject":null,"moderation_state":"published","external_url":null},{"nid":3849,"title":"[Control systems] Prosys OPC security advisory (AV22-708)","uuid":"3579496b-cbbf-4c5b-bfd8-6db8df46dac4","banner":null,"lang":"en","date_modified":"2022-12-15","date_modified_ts":"2022-12-15T21:07:48Z","date_created":"2022-12-15T21:01:26Z","summary":null,"body":["<article data-history-node-id=\"3849\" about=\"\/en\/alerts-advisories\/control-systems-prosys-opc-security-advisory-av22-708\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-707<\/strong><br \/><strong>Date: 15 December 2022<\/strong><\/p>\n\n<p>On 15 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Prosys OPC UA Simulation Server \u2013 versions prior to 5.4.0<\/li>\n\t<li>Prosys OPC UA Modbus Server \u2013 version 1.4.18-5 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-349-01\">ICS Advisory (ICSA-22-349-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-prosys-opc-security-advisory-av22-708","alert_type":398,"serial_number":"AV22-708","subject":null,"moderation_state":"published","external_url":null},{"nid":3853,"title":"Dell security advisory (AV22-709)","uuid":"1c5689d3-eb63-4c12-a7a9-9c40f0b48071","banner":null,"lang":"en","date_modified":"2022-12-19","date_modified_ts":"2022-12-19T18:22:51Z","date_created":"2022-12-19T18:17:43Z","summary":null,"body":["<article data-history-node-id=\"3853\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-709\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-709<\/strong><br \/><strong>Date: 19 December 2022<\/strong><\/p>\n\n<p>Between 12 and 18 December 2022, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Network Management Console \u2013 versions 19.4.x, 19.5.x and 19.6.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206423\/dsa-2022-357-dell-networker-management-console-security-update-for-apache-vulnerability-in-port-9090\">Dell Security Update (NetWorker Management Console)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-709","alert_type":396,"serial_number":"AV22-709","subject":null,"moderation_state":"published","external_url":null},{"nid":3854,"title":"Ubuntu security advisory (AV22-710)","uuid":"d0428c7a-66e9-446d-ad08-731dae02e016","banner":null,"lang":"en","date_modified":"2022-12-19","date_modified_ts":"2022-12-19T18:29:19Z","date_created":"2022-12-19T18:26:41Z","summary":null,"body":["<article data-history-node-id=\"3854\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-710\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-710<\/strong><br \/><strong>Date: 19 December 2022<\/strong><\/p>\n\n<p>Between 12 and 18 December 2022, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av22-710","alert_type":396,"serial_number":"AV22-710","subject":null,"moderation_state":"published","external_url":null},{"nid":3855,"title":"IBM security advisory (AV22-711)","uuid":"97ab10cb-5d4c-4c01-b6bf-07d8892cf3aa","banner":null,"lang":"en","date_modified":"2022-12-19","date_modified_ts":"2022-12-19T19:36:26Z","date_created":"2022-12-19T19:36:04Z","summary":null,"body":["<article data-history-node-id=\"3855\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-711\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-711<\/strong><br \/><strong>Date: 19 December 2022<\/strong><\/p>\n\n<p>Between 12 and 18 December 2022, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation \u2013 multiple versions<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.1.x and 11.2.x<\/li>\n\t<li>IBM Db2 Net Search Extender \u2013 versions V9.7, V10.1, V10.5 and V11.1<\/li>\n\t<li>IBM Spectrum Control \u2013 version 5.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6848295\">IBM Security Bulletin (IBM Cloud Pak for Business Automation) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6841801\">IBM Security Bulletin (IBM Cognos Analytics) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6847293\">IBM Security Bulletin (IBM Db2 Net Search Extender) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6848213\">IBM Security Bulletin (IBM Spectrum Control) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-711","alert_type":396,"serial_number":"AV22-711","subject":null,"moderation_state":"published","external_url":null},{"nid":3856,"title":"Microsoft Edge security advisory (AV22-712)","uuid":"321fd104-2dc4-4e66-b135-4c69dc277b4d","banner":null,"lang":"en","date_modified":"2022-12-20","date_modified_ts":"2022-12-20T14:19:05Z","date_created":"2022-12-20T14:18:35Z","summary":null,"body":["<article data-history-node-id=\"3856\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-712\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-712<\/strong><br \/><strong>Date: 20 December 2022<\/strong><\/p>\n\n<p>On 16 December 2022, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 108.0.1462.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-16-2022\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av22-712","alert_type":396,"serial_number":"AV22-712","subject":null,"moderation_state":"published","external_url":null},{"nid":3859,"title":"[Control systems] ARC informatique security advisory (AV22-713)","uuid":"f5173be0-a0bc-441c-b24c-2326effb7c50","banner":null,"lang":"en","date_modified":"2022-12-20","date_modified_ts":"2022-12-20T19:48:01Z","date_created":"2022-12-20T19:46:13Z","summary":null,"body":["<article data-history-node-id=\"3859\" about=\"\/en\/alerts-advisories\/control-systems-arc-informatique-security-advisory-av22-713\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-713<\/strong><br \/><strong>Date: 20 December 2022<\/strong><\/p>\n\n<p>On 20 December 2022 ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PcVue\u00a0\u2013 versions 8.10 to 15.2.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-354-03\">ICS Advisory (ICSA-22-354-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-arc-informatique-security-advisory-av22-713","alert_type":398,"serial_number":"AV22-713","subject":null,"moderation_state":"published","external_url":null},{"nid":3860,"title":"[Control systems] Fuji electric security advisory (AV22-714)","uuid":"a57a9043-ebe9-4007-a572-be5a678b26fb","banner":null,"lang":"en","date_modified":"2022-12-20","date_modified_ts":"2022-12-20T19:53:04Z","date_created":"2022-12-20T19:50:53Z","summary":null,"body":["<article data-history-node-id=\"3860\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-714\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-714<\/strong><br \/><strong>Date: 20 December 2022<\/strong><\/p>\n\n<p>On 20 December 2022 ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Tellus Lite V-Simulator\u00a0\u2013 version 4.0.12.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-354-01\">ICS Advisory (ICSA-22-354-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av22-714","alert_type":398,"serial_number":"AV22-714","subject":null,"moderation_state":"published","external_url":null},{"nid":3861,"title":"[Control systems] Rockwell automation security advisory (AV22-715)","uuid":"fa1ed6c2-2979-42e1-8e99-d140f7727a9b","banner":null,"lang":"en","date_modified":"2022-12-20","date_modified_ts":"2022-12-20T21:26:03Z","date_created":"2022-12-20T21:22:29Z","summary":null,"body":["<article data-history-node-id=\"3861\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-715\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-715<\/strong><br \/><strong>Date: 20 December 2022<\/strong><\/p>\n\n<p>On 20 December 2022, ICS-CERT published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CompactLogix 5370\u00a0\u2013 versions 20 to 33<\/li>\n\t<li>Compact GuardLogix 5370\u00a0\u2013 versions 28 to 33<\/li>\n\t<li>ControlLogix 5570\u00a0\u2013 versions 20 to 33<\/li>\n\t<li>ControlLogix 5570 redundancy\u00a0\u2013 versions 20 to 33<\/li>\n\t<li>GuardLogix 5570\u00a0\u2013 versions 20 to 33<\/li>\n\t<li>MicroLogix 1100\u00a0\u2013 all versions<\/li>\n\t<li>MicroLogix 1400 A\u00a0\u2013 versions 7.000 and prior<\/li>\n\t<li>MicroLogix 1400 B\/C\u00a0\u2013 versions 21.007 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution or denial-of-service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-354-02\">ICS Advisory (ICSA-22-354-02)<\/a><\/li>\n\t<li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-354-04\">ICS Advisory (ICSA-22-354-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-715","alert_type":398,"serial_number":"AV22-715","subject":null,"moderation_state":"published","external_url":null},{"nid":3863,"title":"Mozilla security advisory (AV22-716)","uuid":"9ee41871-13ae-4778-9d1f-de25c99a8dd8","banner":null,"lang":"en","date_modified":"2022-12-21","date_modified_ts":"2022-12-21T19:37:13Z","date_created":"2022-12-21T19:18:57Z","summary":null,"body":["<article data-history-node-id=\"3863\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av22-716\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-716<\/strong><br \/><strong>Date: 21 December 2022<\/strong><\/p>\n\n<p>On 20 December 2022, Mozilla published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Thunderbird \u2013 versions prior to 102.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2022-54\/\">Mozilla Security Advisory (MFSA 2022-54)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av22-716","alert_type":396,"serial_number":"AV22-716","subject":null,"moderation_state":"published","external_url":null},{"nid":3864,"title":"[Control systems] Omron security advisory (AV22-717)","uuid":"cdb197c8-2f20-4a38-94dc-ad5b7b206f60","banner":null,"lang":"en","date_modified":"2022-12-22","date_modified_ts":"2022-12-22T19:00:40Z","date_created":"2022-12-22T19:00:12Z","summary":null,"body":["<article data-history-node-id=\"3864\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-717\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-717<\/strong><br \/><strong>Date: 22 December 2022<\/strong><\/p>\n\n<p>On 22 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>CX-Programmer \u2013 version 9.78 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-356-04\">ICS Advisory (ICSA-22-356-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av22-717","alert_type":398,"serial_number":"AV22-717","subject":null,"moderation_state":"published","external_url":null},{"nid":3865,"title":"[Control systems] Mitsubishi Electric security advisory (AV22-718)","uuid":"a609c60b-63f8-4007-b6a8-d9a7959f9424","banner":null,"lang":"en","date_modified":"2022-12-22","date_modified_ts":"2022-12-22T19:06:00Z","date_created":"2022-12-22T19:02:47Z","summary":null,"body":["<article data-history-node-id=\"3865\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-718\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-718<\/strong><br \/><strong>Date: 22 December 2022<\/strong><\/p>\n\n<p>On 22 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC iQ-R Series R00\/01\/02CPU - firmware versions 32 and prior<\/li>\n\t<li>MELSEC iQ-R Series R04\/08\/16\/32\/120(EN)CPU - firmware versions 65 and prior<\/li>\n\t<li>MELSEC iQ-R Series R08\/16\/32\/120SFCPU - all versions<\/li>\n\t<li>MELSEC iQ-R Series R12CCPU-V - all versions<\/li>\n\t<li>MELSEC iQ-L Series L04\/08\/16\/32HCPU - all versions<\/li>\n\t<li>MELIPC Series MI5122-VW - all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-356-03\">ICS Advisory (ICSA-22-356-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av22-718","alert_type":398,"serial_number":"AV22-718","subject":null,"moderation_state":"published","external_url":null},{"nid":3866,"title":"[Control systems] Rockwell Automation security advisory (AV22-719)","uuid":"d3075395-9e40-4ee1-b1d4-c6be2febc8f8","banner":null,"lang":"en","date_modified":"2022-12-22","date_modified_ts":"2022-12-22T19:10:39Z","date_created":"2022-12-22T19:07:57Z","summary":null,"body":["<article data-history-node-id=\"3866\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-719\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-719<\/strong><br \/><strong>Date: 22 December 2022<\/strong><\/p>\n\n<p>On 22 December 2022 ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MStudio 5000 Logix Emulate - version .20-33<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-356-02\">ICS Advisory (ICSA-22-356-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av22-719","alert_type":398,"serial_number":"AV22-719","subject":null,"moderation_state":"published","external_url":null},{"nid":3867,"title":"[Control systems] Priva security advisory (AV22-720)","uuid":"ea01de03-8dd6-43a1-9e1a-bdb76602e275","banner":null,"lang":"en","date_modified":"2022-12-22","date_modified_ts":"2022-12-22T19:17:05Z","date_created":"2022-12-22T19:16:15Z","summary":null,"body":["<article data-history-node-id=\"3867\" about=\"\/en\/alerts-advisories\/control-systems-priva-security-advisory-av22-720\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-720<\/strong><br \/><strong>Date: 22 December 2022<\/strong><\/p>\n\n<p>On 22 December 2022, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Bacnet - all versions prior to 8.7.8.0<\/li>\n\t<li>Blue ID - all versions prior to 8.7.8.0<\/li>\n\t<li>Compass - all versions prior to 8.7.8.0<\/li>\n\t<li>Connect - all versions prior to 8.7.8.0<\/li>\n\t<li>TPC - all versions prior to 8.7.8.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to information disclosure and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-22-356-01\">ICS Advisory (ICSA-22-356-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-priva-security-advisory-av22-720","alert_type":398,"serial_number":"AV22-720","subject":null,"moderation_state":"published","external_url":null},{"nid":3868,"title":"[Control systems] Siemens security advisory (AV22-721)","uuid":"fdc6b025-b030-4aac-b7c2-ddb7a76deb39","banner":null,"lang":"en","date_modified":"2022-12-22","date_modified_ts":"2022-12-22T21:04:06Z","date_created":"2022-12-22T21:01:37Z","summary":null,"body":["<article data-history-node-id=\"3868\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-721\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-721<\/strong><br \/><strong>Date: 22 December 2022<\/strong><\/p>\n\n<p>On 13 December 2022, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following product:<\/p>\n\n<ul><li>SIPROTEC 5 \u2013 multiple models, versions prior to V7.58<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-223771.html\">Siemens Security Advisory (SSA-223771)<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av22-721","alert_type":398,"serial_number":"AV22-721","subject":null,"moderation_state":"published","external_url":null},{"nid":3870,"title":"Juniper Networks security advisory (AV22-722)","uuid":"9e862df4-51eb-4010-aab9-a2c949cf30ae","banner":null,"lang":"en","date_modified":"2022-12-23","date_modified_ts":"2022-12-23T18:25:15Z","date_created":"2022-12-23T18:21:55Z","summary":null,"body":["<article data-history-node-id=\"3870\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-722\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-722<\/strong><br \/><strong>Date: 23 December 2022<\/strong><\/p>\n\n<p>On 22 December 2022, Juniper Networks published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Junos OS \u2013 version 22.3R1<\/li>\n\t<li>Junos OS \u2013 version 22.3R1-EVO<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2022-12-Out-of-Cycle-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-A-BGP-session-will-flap-upon-receipt-of-a-specific-optional-transitive-attribute-in-version-22-3R1-CVE-2022-22184?language=en_US\">Juniper Networks Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av22-722","alert_type":396,"serial_number":"AV22-722","subject":null,"moderation_state":"published","external_url":null},{"nid":3871,"title":"Dell security advisory (AV22-723)","uuid":"3229f7fb-dc3e-4b49-b479-85cb44016d61","banner":null,"lang":"en","date_modified":"2022-12-28","date_modified_ts":"2022-12-28T15:15:18Z","date_created":"2022-12-28T15:10:55Z","summary":null,"body":["<article data-history-node-id=\"3871\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av22-723\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-723<\/strong>\n  <br \/><strong>Date: 28 December 2022<\/strong>\n<\/p>\n<p>Between 19 and 27 December 2022, Dell published Security Advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Dell PowerScale OneFS\u00a0\u2013 multiple versions<\/li>\n  <li>Dell SMR and SMR vApp\u00a0\u2013 versions prior to 4.8.0.1<\/li>\n  <li>Dell SRM and SRM vApp\u00a0\u2013 versions prior to 4.8.0.1<\/li>\n  <li>Dell Streaming Data Platform\u00a0\u2013 versions 1.1.x, 1.2.x, 1.3.x and 1.4.x<\/li>\n  <li>Dell VxRail Appliance\u00a0\u2013 versions 7.0.x prior to 7.0.410<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206943\/dsa-2022-335-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (DSA-2022-335)<\/a><\/li>\n  <li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206927\/dsa-2022-323-dell-emc-powerscale-onefs-security-updates-for-multiple-security-vulnerabilities\">Dell Security Advisory (DSA-2022-323)<\/a><\/li>\n  <li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206739\/dsa-2022-352-dell-emc-srm-and-dell-emc-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (DSA-2022-352)<\/a><\/li>\n  <li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000206671\/dsa-2022-349-dell-streaming-data-platform-security-update\">Dell Security Advisory (DSA-2022-349)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av22-723","alert_type":396,"serial_number":"AV22-723","subject":null,"moderation_state":"published","external_url":null},{"nid":3872,"title":"IBM security advisory (AV22-724)","uuid":"a22b6e7d-b4b2-4330-839b-2a750cdeb5e8","banner":null,"lang":"en","date_modified":"2022-12-28","date_modified_ts":"2022-12-28T15:21:03Z","date_created":"2022-12-28T15:19:16Z","summary":null,"body":["<article data-history-node-id=\"3872\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av22-724\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-724<\/strong><br \/><strong>Date: 28 December 2022<\/strong><\/p>\n\n<p>Between 19 and 27 December 2022, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Infrastructure Management\u00a0\u2013 all versions<\/li>\n\t<li>IBM Tivoli Netcool Impact\u00a0\u2013 version 7.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av22-724","alert_type":396,"serial_number":"AV22-724","subject":null,"moderation_state":"published","external_url":null},{"nid":3873,"title":"[Control systems] ABB security advisory (AV22-725)","uuid":"dc7890de-907f-434d-bbc2-3aea1b935e9d","banner":null,"lang":"en","date_modified":"2022-12-28","date_modified_ts":"2022-12-28T15:25:55Z","date_created":"2022-12-28T15:23:49Z","summary":null,"body":["<article data-history-node-id=\"3873\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-725\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV22-725<\/strong><br \/><strong>Date: 28 December 2022<\/strong><\/p>\n\n<p>On 27 December 2022, ABB published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Infinity DC Power Plant\u00a0\u2013 versions H5692448, G104, G842, G224L, G630-4, G451C(2) and G461(2)\u00a0\u2013 comcode 150047415<\/li>\n\t<li>Pulsar Plus System Controller\u00a0\u2013 version NE843_S\u00a0\u2013 comcode 150042936<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108467A6732\">ABB Security Advisory (9AKK108467A6732)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av22-725","alert_type":398,"serial_number":"AV22-725","subject":null,"moderation_state":"published","external_url":null},{"nid":3874,"title":"IBM security advisory (AV23-001)","uuid":"8177d9ab-fac9-44a4-bbf5-996d416e3e64","banner":null,"lang":"en","date_modified":"2023-01-03","date_modified_ts":"2023-01-03T21:04:15Z","date_created":"2023-01-03T21:03:47Z","summary":null,"body":["<article data-history-node-id=\"3874\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-001\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-001<\/strong><br \/><strong>Date: 3 January 2023<\/strong><\/p>\n\n<p>Between 28 December 2022 and 2 January 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-001","alert_type":396,"serial_number":"AV23-001","subject":null,"moderation_state":"published","external_url":null},{"nid":3875,"title":"Fortinet security advisory (AV23-002)","uuid":"5cbc5ee3-aca1-4567-9a00-8eac5239952f","banner":null,"lang":"en","date_modified":"2023-01-03","date_modified_ts":"2023-01-03T21:10:39Z","date_created":"2023-01-03T21:06:00Z","summary":null,"body":["<article data-history-node-id=\"3875\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-002\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-002<\/strong><br \/><strong>Date: 3 January 2023<\/strong><\/p>\n\n<p>On 3 January 2023, Fortinet published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FortiADC - multiple versions<\/li>\n\t<li>FortiTester - multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code or command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-22-061\">Fortinet PSIRT Advisory (FG-IR-22-061)<\/a><\/li>\n\t<li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-22-274\">Fortinet PSIRT Advisory (FG-IR-22-274)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-002","alert_type":396,"serial_number":"AV23-002","subject":null,"moderation_state":"published","external_url":null},{"nid":3876,"title":"Dell security advisory (AV23-003)","uuid":"49976256-a108-4a6f-901b-e0f858e570cd","banner":null,"lang":"en","date_modified":"2023-01-04","date_modified_ts":"2023-01-04T20:52:46Z","date_created":"2023-01-04T20:45:48Z","summary":null,"body":["<article data-history-node-id=\"3876\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-003\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-003<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 4, 2023<\/p>\n\n<p>Between December 28, 2022 and January 3, 2023, Dell published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerStore T operating system - versions prior to 2.1.1.2-1885194<\/li>\n\t<li>Dell PowerStore X operating system - versions prior to 2.1.1.2-1885194<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000206395\/dsa-2022-356-dell-powerstore-family-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (DSA-2022-356)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-003","alert_type":396,"serial_number":"AV23-003","subject":null,"moderation_state":"published","external_url":null},{"nid":3877,"title":"[Control systems] Hitachi Energy security advisory (AV23-004)","uuid":"8d0c06f6-df81-4df3-9d83-1da2f8ecdb31","banner":null,"lang":"en","date_modified":"2023-01-05","date_modified_ts":"2023-01-05T20:46:56Z","date_created":"2023-01-05T20:46:31Z","summary":null,"body":["<article data-history-node-id=\"3877\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-004\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-004<\/strong><br \/><strong>Date: January 5, 2023<\/strong><\/p>\n\n<p>On 05 January 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>UNEM \u2013 multiple versions\u00a0\u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-005-01\">ICS Advisory (ICSA-23-005-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-004","alert_type":398,"serial_number":"AV23-004","subject":null,"moderation_state":"published","external_url":null},{"nid":3878,"title":"Android security advisory \u2013 January 2023 monthly rollup (AV23-005)","uuid":"1b530361-2c25-4d39-add3-03012a1925d3","banner":null,"lang":"en","date_modified":"2023-01-06","date_modified_ts":"2023-01-06T18:58:19Z","date_created":"2023-01-06T18:57:48Z","summary":null,"body":["<article data-history-node-id=\"3878\" about=\"\/en\/alerts-advisories\/android-security-advisory-january-2023-monthly-rollup-av23-005\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-005<\/strong><br \/><strong>Date: January 6, 2023<\/strong><\/p>\n\n<p>On 3 January 2023, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-01-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-january-2023-monthly-rollup-av23-005","alert_type":396,"serial_number":"AV23-005","subject":null,"moderation_state":"published","external_url":null},{"nid":3879,"title":"Ubuntu security advisory (AV23-006)","uuid":"bfe87d40-d922-44e6-8cb9-3e445ac7d1c8","banner":null,"lang":"en","date_modified":"2023-01-09","date_modified_ts":"2023-01-09T18:05:45Z","date_created":"2023-01-09T17:56:33Z","summary":null,"body":["<article data-history-node-id=\"3879\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-006\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-006<br \/><strong>Date: <\/strong>January 09, 2023<\/p>\n\n<p>Between January 2nd and 8th 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-006","alert_type":396,"serial_number":"AV23-006","subject":null,"moderation_state":"published","external_url":null},{"nid":3880,"title":"Dell security advisory (AV23-007)","uuid":"66a86a24-d9c9-45fd-9c49-d29f9e3bcc14","banner":null,"lang":"en","date_modified":"2023-01-09","date_modified_ts":"2023-01-09T19:00:28Z","date_created":"2023-01-09T18:55:47Z","summary":null,"body":["<article data-history-node-id=\"3880\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-007\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-007<\/p>\n\n<p><strong>Date: <\/strong>January 9, 2023<\/p>\n\n<p>Between January 4 to 8th, 2023, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Integrated DataProtect Appliance model - versions 2.7.2 and 2.7.3<\/li>\n\t<li>PowerProtect DD - multiple versions and platforms<\/li>\n\t<li>Dell VxRail Appliance - 8.0.x versions prior to 8.0.000<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000207274\/dsa-2022-336-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (DSA-2022-336)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000207174\/dsa-2022-302-dell-technologies-powerprotect-dd-security-update-for-multiple-third-party-security-vulnerabilities\">Dell Security Advisory (DSA-2022-302)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-007","alert_type":396,"serial_number":"AV23-007","subject":null,"moderation_state":"published","external_url":null},{"nid":3881,"title":"[Control systems] Hitachi Energy security advisory (AV23-008)","uuid":"71fc2437-a314-4ad4-9f1e-72855309e9b9","banner":null,"lang":"en","date_modified":"2023-01-09","date_modified_ts":"2023-01-09T19:45:40Z","date_created":"2023-01-09T19:39:30Z","summary":null,"body":["<article data-history-node-id=\"3881\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-008\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-008<br \/><strong>Date: <\/strong>January 09, 2023<\/p>\n\n<p>On January 5th, 2023, ICS-CERT published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FOXMAN-UN \u2013 multiple versions<\/li>\n\t<li>Lumada APM \u2013 version 6.5.0.0 and versions 6.1.0.0 to 6.4.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-005-03\">ICS Advisory (ICSA-23-005-03)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-005-02\">ICS Advisory (ICSA-23-005-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-008","alert_type":398,"serial_number":"AV23-008","subject":null,"moderation_state":"published","external_url":null},{"nid":3882,"title":"SAP security advisory \u2013 January 2023 monthly rollup (AV23-009)","uuid":"b40ed3d6-3f06-4c04-b626-d3163d94ffb8","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T18:49:23Z","date_created":"2023-01-10T18:47:26Z","summary":null,"body":["<article data-history-node-id=\"3882\" about=\"\/en\/alerts-advisories\/sap-security-advisory-january-2023-monthly-rollup-av23-009\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-009<br \/><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP BusinessObjects Business Intelligence Platform \u2013 multiple versions and platforms<\/li>\n\t<li>SAP Business Planning and Consolidation MS \u2013 versions 800 and 810<\/li>\n\t<li>SAP NetWeaver ABAP Server and ABAP Platform \u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver AS for Java \u2013 version 7.50<\/li>\n\t<li>SAP NetWeaver Process Integration \u2013 version 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day \u2013 January 2023 (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-january-2023-monthly-rollup-av23-009","alert_type":396,"serial_number":"AV23-009","subject":null,"moderation_state":"published","external_url":null},{"nid":3883,"title":"[Control systems] Schneider Electric security advisory (AV23-010) ","uuid":"a039bf05-2973-4e6f-bff0-5304edcc08c7","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T19:02:06Z","date_created":"2023-01-10T19:01:19Z","summary":null,"body":["<article data-history-node-id=\"3883\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-010\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-010<br \/><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, Schneider Electric published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>EcoStruxure Control Expert \u2013 all versions<\/li>\n\t<li>EcoStruxure Geo SCADA Expert 2019, 2020 and 2021 \u2013 versions prior to October 2022<\/li>\n\t<li>EcoStruxure Power SCADA Anywhere \u2013 versions 2022, 2021, 2020 R2, 2020, 9.0 and 8.x<\/li>\n\t<li>EcoStruxure Power SCADA Operation 2020 \u2013 multiple versions<\/li>\n\t<li>Ecostruxure Power Operation 2021 \u2013 versions 2021, 2021 CU1, 2021 CU2 and 2021 CU3<\/li>\n\t<li>EcoStruxure Process Expert \u2013 version V2020 and prior<\/li>\n\t<li>Modicon PLC and PAC \u2013 multiple versions and platforms<\/li>\n\t<li>PowerSCADA Expert \u2013 version 8.x<\/li>\n\t<li>Power SCADA Operation \u2013 version 9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-010","alert_type":398,"serial_number":"AV23-010","subject":null,"moderation_state":"published","external_url":null},{"nid":3884,"title":"[Control systems] Black Box security advisory (AV23-011)","uuid":"b1ab0f18-82dd-47fe-a22a-63eb1914aa8e","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T19:14:31Z","date_created":"2023-01-10T19:13:27Z","summary":null,"body":["<article data-history-node-id=\"3884\" about=\"\/en\/alerts-advisories\/control-systems-black-box-security-advisory-av23-011\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-011<br \/><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Black Box KVM ACR1000A-R-R2 \u2013 Firmware version v3.4.31307<\/li>\n\t<li>Black Box KVM ACR1000A-T-R2 \u2013 Firmware version v3.4.31307<\/li>\n\t<li>Black Box KVM ACR1002A-T \u2013 Firmware version v3.4.31307<\/li>\n\t<li>Black Box KVM ACR1002A-R \u2013 Firmware version v3.4.31307<\/li>\n\t<li>Black Box KVM ACR1020A-T \u2013 Firmware version v3.4.31307<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-010-01\">ICS Advisory (ICSA-23-010-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-black-box-security-advisory-av23-011","alert_type":398,"serial_number":"AV23-011","subject":null,"moderation_state":"published","external_url":null},{"nid":3885,"title":"[Control systems] Siemens security advisory (AV23-012) ","uuid":"21bb35da-fd4b-41c3-9a40-8abfdc0a33f4","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T19:24:10Z","date_created":"2023-01-10T19:23:01Z","summary":null,"body":["<article data-history-node-id=\"3885\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-012\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-012<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Automation License Manager \u2013 multiple versions<\/li>\n\t<li>Mendix SAML \u2013 multiple versions<\/li>\n\t<li>JT Open \u2013 versions prior to V11.1.1.0<\/li>\n\t<li>JT Utilities \u2013 versions prior to V13.1.1.0<\/li>\n\t<li>SINEC INS \u2013 versions prior to V1.0 SP2 Update 1<\/li>\n\t<li>Solid Edge \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-012","alert_type":398,"serial_number":"AV23-012","subject":null,"moderation_state":"published","external_url":null},{"nid":3886,"title":"HPE security advisory (AV23-013)","uuid":"f9ddef6b-1447-47d5-8b66-06ad2f3bfc26","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T20:12:49Z","date_created":"2023-01-10T20:11:58Z","summary":null,"body":["<article data-history-node-id=\"3886\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-013\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-013<br \/><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, HPE published a security bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE SimpliVity 380 Gen9 \u2013 versions prior to OmniStack Firmware version 2023_0110<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04403en_us\">HPE security bulletin (HPESBHF04403)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-013","alert_type":396,"serial_number":"AV23-013","subject":null,"moderation_state":"published","external_url":null},{"nid":3887,"title":"Adobe security advisory (AV23-014)","uuid":"56a73cc9-e855-4d1f-90c5-6d2c1fed3e6e","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T20:22:45Z","date_created":"2023-01-10T20:21:26Z","summary":null,"body":["<article data-history-node-id=\"3887\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-014\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-014<br \/><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat 2020 \u2013 version 20.005.30418 and prior<\/li>\n\t<li>Acrobat DC \u2013 multiple versions<\/li>\n\t<li>Acrobat Reader 2020 \u2013 version 20.005.30418 and prior<\/li>\n\t<li>Acrobat Reader DC \u2013 multiple versions<\/li>\n\t<li>Adobe Dimension \u2013 version 3.4.6 and prior<\/li>\n\t<li>Adobe InCopy \u2013 version ID18.0 and prior and ID17.4 and prior<\/li>\n\t<li>Adobe InDesign \u2013 version ID18.0 and prior and ID17.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/security-bulletin.html\">Adobe security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-014","alert_type":396,"serial_number":"AV23-014","subject":null,"moderation_state":"published","external_url":null},{"nid":3888,"title":"Intel security advisory (AV23-015)","uuid":"ea2c509d-9961-4bf5-a28d-5bc076d88bc3","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T20:32:42Z","date_created":"2023-01-10T20:26:00Z","summary":null,"body":["<article data-history-node-id=\"3888\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av23-015\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-015<br \/><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, Intel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Intel C++ Compiler Classic \u2013 versions prior to 2021.8<\/li>\n\t<li>Intel oneAPI DPC++\/C++ Compiler \u2013 versions prior to 2022.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00773.html\">Intel security advisory (INTEL-SA-00773)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av23-015","alert_type":396,"serial_number":"AV23-015","subject":null,"moderation_state":"published","external_url":null},{"nid":3889,"title":"Microsoft security advisory \u2013 January 2023 monthly rollup (AV23-016)","uuid":"b2154f6e-bef2-4ffb-9e3e-706172f36afe","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T20:55:19Z","date_created":"2023-01-10T20:47:15Z","summary":null,"body":["<article data-history-node-id=\"3889\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2023-monthly-rollup-av23-016\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-016<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft SharePoint \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 7 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 8.1 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><ul><\/ul><p>Microsoft has indicated that CVE-2023-21674 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Jan\">January 2023 release notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security update guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-january-2023-monthly-rollup-av23-016","alert_type":396,"serial_number":"AV23-016","subject":null,"moderation_state":"published","external_url":null},{"nid":3890,"title":"Google Chrome security advisory (AV23-017)","uuid":"8321a943-c921-4592-8d7c-aaf941c01cb1","banner":null,"lang":"en","date_modified":"2023-01-10","date_modified_ts":"2023-01-10T21:08:03Z","date_created":"2023-01-10T21:02:02Z","summary":null,"body":["<article data-history-node-id=\"3890\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-017\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-017<br \/><strong>Date: <\/strong>January 10, 2023<\/p>\n\n<p>On January 10, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 109.0.5414.74, 109.0.5414.74\/.75 and 109.0.5414.87<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/01\/stable-channel-update-for-desktop.html\">Google Chrome security advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-017","alert_type":396,"serial_number":"AV23-017","subject":null,"moderation_state":"published","external_url":null},{"nid":3891,"title":"Cisco security advisory (AV23-018)","uuid":"3204c104-76b1-4d15-b24d-fbbce5c3b72f","banner":null,"lang":"en","date_modified":"2023-01-11","date_modified_ts":"2023-01-11T20:22:03Z","date_created":"2023-01-11T20:04:11Z","summary":null,"body":["<article data-history-node-id=\"3891\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-018\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-018<br \/><strong>Date: <\/strong>January 11, 2023<\/p>\n\n<p>On January 11, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco BroadWorks Application Delivery Platform Device Management \u2013 version 22.0<\/li>\n\t<li>Cisco BroadWorks Xtended Services Platform \u2013 versions 22.0 and 23.0<\/li>\n\t<li>Cisco Industrial Network Director \u2013 version 1<\/li>\n\t<li>IP Phone 7800 and 8800 Series \u2013 versions prior to 14.1(1)SR2<\/li>\n\t<li>Wireless IP Phone 8821 \u2013 versions prior to 11.0(6)SR4<\/li>\n\t<li>RV016 Multi-WAN VPN Routers<\/li>\n\t<li>RV042 Dual WAN VPN Routers<\/li>\n\t<li>RV042G Dual Gigabit WAN VPN Routers<\/li>\n\t<li>RV082 Dual WAN VPN Routers<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-018","alert_type":396,"serial_number":"AV23-018","subject":null,"moderation_state":"published","external_url":null},{"nid":3892,"title":"Juniper Networks security advisory (AV23-019)","uuid":"a78a0e4b-b617-40cc-8bf6-f99d58e043b5","banner":null,"lang":"en","date_modified":"2023-01-11","date_modified_ts":"2023-01-11T20:30:54Z","date_created":"2023-01-11T20:25:12Z","summary":null,"body":["<article data-history-node-id=\"3892\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-019\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-019<br \/><strong>Date: <\/strong>January 11, 2023<\/p>\n\n<p>On January 11, 2023, Juniper Networks published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Contrail Cloud \u2013 versions prior to 13.7.0<\/li>\n\t<li>Contrail Service Orchestration \u2013 versions prior to 6.3.0<\/li>\n\t<li>Junos Space \u2013 versions prior to 22.3R1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy&amp;f:ctype=[Security%20Advisories\">Juniper networks security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-019","alert_type":396,"serial_number":"AV23-019","subject":null,"moderation_state":"published","external_url":null},{"nid":3893,"title":"F5 security advisory (AV23-020)","uuid":"602ff0f8-6a6a-460b-a190-9f25ca3f743f","banner":null,"lang":"en","date_modified":"2023-01-12","date_modified_ts":"2023-01-12T18:38:29Z","date_created":"2023-01-12T18:27:36Z","summary":null,"body":["<article data-history-node-id=\"3893\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av23-020\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-20<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 12, 2023<\/p>\n\n<p>Between January 10 and 11, 2023, F5 published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions and platforms<\/li>\n\t<li>BIG-IP Guided Configuration (GC) \u2013 versions 8.0, 7.0, 6.0, 5.0, 4.1 and 3.0<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 versions 7.1.0 and 8.0.0 to 8.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=security&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending&amp;f:@f5_document_type=[Security%20Advisory\">F5 Security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av23-020","alert_type":396,"serial_number":"AV23-020","subject":null,"moderation_state":"published","external_url":null},{"nid":3894,"title":"[Control systems] InHand Networks security advisory (AV23-021)","uuid":"0f1917f6-2e5b-4eb9-9bf7-9989e579b31f","banner":null,"lang":"en","date_modified":"2023-01-12","date_modified_ts":"2023-01-12T20:50:31Z","date_created":"2023-01-12T20:46:33Z","summary":null,"body":["<article data-history-node-id=\"3894\" about=\"\/en\/alerts-advisories\/control-systems-inhand-networks-security-advisory-av23-021\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-021<\/strong><br \/><strong>Date: January 12, 2023<\/strong><\/p>\n\n<p>On 12 January 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>InRouter 302 \u2013 versions prior to IR302 V3.5.56<\/li>\n\t<li>InRouter 615 \u2013 versions prior to InRouter6XX-S-V2.3.0.r5542<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-012-03\">ICS Advisory (ICSA-23-012-03)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inhand-networks-security-advisory-av23-021","alert_type":398,"serial_number":"AV23-021","subject":null,"moderation_state":"published","external_url":null},{"nid":3895,"title":"[Control systems] Johnson Controls security advisory (AV23-022)","uuid":"5f5acbb9-b0fa-42f0-b6f2-b702df70c6b9","banner":null,"lang":"en","date_modified":"2023-01-12","date_modified_ts":"2023-01-12T20:55:41Z","date_created":"2023-01-12T20:52:59Z","summary":null,"body":["<article data-history-node-id=\"3895\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-022\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-022<\/strong><br \/><strong>Date: January 12, 2023<\/strong><\/p>\n\n<p>On 12 January 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Metasys ADS\/ADX\/OAS Version 10.X \u2013 versions prior to 10.1.6<\/li>\n\t<li>Metasys ADS\/ADX\/OAS Version 11.X \u2013 versions prior to 11.0.3<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-012-06\">ICS Advisory (ICSA-23-012-06)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-022","alert_type":398,"serial_number":"AV23-022","subject":null,"moderation_state":"published","external_url":null},{"nid":3896,"title":"[Control systems] Panasonic security advisory (AV23-023)","uuid":"088ea20d-3ca2-4271-9da1-c5c61271eea1","banner":null,"lang":"en","date_modified":"2023-01-12","date_modified_ts":"2023-01-12T21:01:21Z","date_created":"2023-01-12T20:57:38Z","summary":null,"body":["<article data-history-node-id=\"3896\" about=\"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory-av23-023\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-023<\/strong><br \/><strong>Date: January 12, 2023<\/strong><\/p>\n\n<p>On 12 January 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>VCC-HD5600P \u2013 version 2.03-06<\/li>\n\t<li>VDC-HD3300P \u2013 version 2.03-08<\/li>\n\t<li>VDC-HD3300P \u2013 version 1.02-05<\/li>\n\t<li>VCC-HD3300 \u2013 version 2.03-02<\/li>\n\t<li>VDC-HD3100P \u2013 version 2.03-00<\/li>\n\t<li>VCC-HD2100P \u2013 version 2.03-02<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-012-04\">ICS Advisory (ICSA-23-012-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory-av23-023","alert_type":398,"serial_number":"AV23-023","subject":null,"moderation_state":"published","external_url":null},{"nid":3897,"title":"[Control systems] Sewio security advisory (AV23-024)","uuid":"e2efa3dc-0c68-4837-8824-79fac2bb83ad","banner":null,"lang":"en","date_modified":"2023-01-12","date_modified_ts":"2023-01-12T21:06:53Z","date_created":"2023-01-12T21:05:00Z","summary":null,"body":["<article data-history-node-id=\"3897\" about=\"\/en\/alerts-advisories\/control-systems-sewio-security-advisory-av23-024\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-024<\/strong><br \/><strong>Date: January 12, 2023<\/strong><\/p>\n\n<p>On 12 January 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>RTLS Studio \u2013 version 2.0.0 to 2.6.2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-012-01\">ICS Advisory (ICSA-23-012-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sewio-security-advisory-av23-024","alert_type":398,"serial_number":"AV23-024","subject":null,"moderation_state":"published","external_url":null},{"nid":3898,"title":"[Control systems] SAUTER Controls security advisory (AV23-025)","uuid":"01356157-4f0b-4513-b0a4-12f4b3daf833","banner":null,"lang":"en","date_modified":"2023-01-12","date_modified_ts":"2023-01-12T21:10:52Z","date_created":"2023-01-12T21:08:39Z","summary":null,"body":["<article data-history-node-id=\"3898\" about=\"\/en\/alerts-advisories\/control-systems-sauter-controls-security-advisory-av23-025\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-025<\/strong><br \/><strong>Date: January 12, 2023<\/strong><\/p>\n\n<p>On 12 January 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Nova \u2013 multiple versions and platforms<\/li>\n\t<li>moduNet300 \u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-012-05\">ICS Advisory (ICSA-22-012-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sauter-controls-security-advisory-av23-025","alert_type":398,"serial_number":"AV23-025","subject":null,"moderation_state":"published","external_url":null},{"nid":3899,"title":"[Control systems] RONDS security advisory (AV23-026)","uuid":"201f4f2a-ed65-468b-a7f2-42172a1405f9","banner":null,"lang":"en","date_modified":"2023-01-12","date_modified_ts":"2023-01-12T21:14:39Z","date_created":"2023-01-12T21:12:36Z","summary":null,"body":["<article data-history-node-id=\"3899\" about=\"\/en\/alerts-advisories\/control-systems-ronds-security-advisory-av23-026\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: AV23-026<\/strong><br \/><strong>Date: January 12, 2023<\/strong><\/p>\n\n<p>On 12 January 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>RONDS EPM \u2013 version v1.19.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-012-02\">ICS Advisory (ICSA-23-012-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ronds-security-advisory-av23-026","alert_type":398,"serial_number":"AV23-026","subject":null,"moderation_state":"published","external_url":null},{"nid":3900,"title":"Microsoft Edge security advisory (AV23-027)","uuid":"068d3e40-5cf8-4367-ad78-d6edc4ef52a6","banner":null,"lang":"en","date_modified":"2023-01-13","date_modified_ts":"2023-01-13T20:42:46Z","date_created":"2023-01-13T20:34:18Z","summary":null,"body":["<article data-history-node-id=\"3900\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-027\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-027<br \/><strong>Date: <\/strong>January 13, 2023<\/p>\n\n<p>On January 12, 2023, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 109.0.1518.49<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-12-2023\">Microsoft Edge stable channel release notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-027","alert_type":396,"serial_number":"AV23-027","subject":null,"moderation_state":"published","external_url":null},{"nid":3901,"title":"Red Hat security advisory (AV23-028)","uuid":"012b60f9-a400-496a-b1a6-c15d07d588c8","banner":null,"lang":"en","date_modified":"2023-01-13","date_modified_ts":"2023-01-13T20:56:12Z","date_created":"2023-01-13T20:55:08Z","summary":null,"body":["<article data-history-node-id=\"3901\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-028\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-028<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 13, 2023<\/p>\n\n<p>On January 12, 2023, Red Hat published security advisories to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories?q=&amp;p=2&amp;sort=portal_publication_date%20desc&amp;rows=10&amp;portal_advisory_type=Security%20Advisory&amp;documentKind=PortalProduct\">Red Hat security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-028","alert_type":396,"serial_number":"AV23-028","subject":null,"moderation_state":"published","external_url":null},{"nid":3902,"title":"[Control systems] Hitachi Energy security advisory (AV23-029)","uuid":"1d4bd7cb-6ceb-4428-8d53-677919ac3202","banner":null,"lang":"en","date_modified":"2023-01-16","date_modified_ts":"2023-01-16T19:55:28Z","date_created":"2023-01-16T19:50:30Z","summary":null,"body":["<article data-history-node-id=\"3902\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-029\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-029<br \/><strong>Date: <\/strong>January 16, 2023<\/p>\n\n<p>On January 12, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Lumada APM \u2013 SaaS \u2013 versions 6.0.0.0 to 6.4.220601.0<\/li>\n\t<li>Lumada APM \u2013 On Premises \u2013 versions 6.0.0.0.0 to 6.4.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-012-07\">ICS advisory (ICSA-23-012-07)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-029","alert_type":398,"serial_number":"AV23-029","subject":null,"moderation_state":"published","external_url":null},{"nid":3903,"title":"Dell security advisory (AV23-030)","uuid":"209a2882-1ce6-4a62-9972-81f5a095e204","banner":null,"lang":"en","date_modified":"2023-01-16","date_modified_ts":"2023-01-16T20:50:24Z","date_created":"2023-01-16T20:46:38Z","summary":null,"body":["<article data-history-node-id=\"3903\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-030\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-030<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 16, 2023<\/p>\n\n<p>Between January 9 and 15, 2023, Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Container Storage Modules \u2013 versions 1.4 and prior<\/li>\n\t<li>Dell PowerEdge Servers \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000207371\/dsa-2023-002-dell-poweredge-server-security-update-for-amd-server-vulnerabilities\">Dell security advisory (DSA-2023-002)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000207373\/dsa-2023-006-dell-container-storage-modules-security-update-for-a-multipath-tools-vulnerability\">Dell security advisory (DSA-2023-006)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-030","alert_type":396,"serial_number":"AV23-030","subject":null,"moderation_state":"published","external_url":null},{"nid":3904,"title":"IBM security advisory (AV23-031)","uuid":"57284e4a-5bf9-454f-9b84-9d1d81cf8b60","banner":null,"lang":"en","date_modified":"2023-01-16","date_modified_ts":"2023-01-16T21:06:31Z","date_created":"2023-01-16T21:01:17Z","summary":null,"body":["<article data-history-node-id=\"3904\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-031\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-031<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 16, 2023<\/p>\n\n<p>Between January 9 and 15, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Decision Optimization for Cloud Pak for Data \u2013 all versions<\/li>\n\t<li>IBM Business Automation Workflow \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6854317\">IBM security bulletin (Decision optimization for cloud pak for data) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6853681\">IBM security bulletin (IBM business automation workflow) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM product security incident response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-031","alert_type":396,"serial_number":"AV23-031","subject":null,"moderation_state":"published","external_url":null},{"nid":3906,"title":"Ubuntu security advisory (AV23-032)","uuid":"d9369fdf-df97-424e-ad15-71750fc29a4e","banner":null,"lang":"en","date_modified":"2023-01-16","date_modified_ts":"2023-01-16T21:26:28Z","date_created":"2023-01-16T21:26:03Z","summary":null,"body":["<article data-history-node-id=\"3906\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-032\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-032<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 16, 2023<\/p>\n\n<p>Between January 9 and 15, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu security notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-032","alert_type":396,"serial_number":"AV23-032","subject":null,"moderation_state":"published","external_url":null},{"nid":3907,"title":"Mozilla security advisory (AV23-033)","uuid":"049ff9cc-710d-495f-b02b-4179c47c3e79","banner":null,"lang":"en","date_modified":"2023-01-18","date_modified_ts":"2023-01-18T14:54:20Z","date_created":"2023-01-18T14:42:39Z","summary":null,"body":["<article data-history-node-id=\"3907\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-033\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-033<br \/><strong>Date: <\/strong>January 17, 2023<strong> <\/strong><\/p>\n\n<p>On January 17, 2023, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0- versions prior to 109<\/li>\n\t<li>Firefox ESR\u00a0- versions prior to 102.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-01\/\">Mozilla Security Advisory (MFSA 2023-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-02\/\">Mozilla Security Advisory (MFSA 2023-02)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-033","alert_type":396,"serial_number":"AV23-033","subject":null,"moderation_state":"published","external_url":null},{"nid":3908,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-034)","uuid":"375c4294-0248-4a10-b782-0b4f67815678","banner":null,"lang":"en","date_modified":"2023-01-18","date_modified_ts":"2023-01-18T19:30:32Z","date_created":"2023-01-18T19:30:32Z","summary":null,"body":["<article data-history-node-id=\"3908\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-034\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-034<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 18, 2023<\/p>\n\n<p>On January 17, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC iQ-F Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>MELSEC iQ-R Series\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-017-02\">ICS Advisory (ICSA-23-017-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-034","alert_type":398,"serial_number":"AV23-034","subject":null,"moderation_state":"published","external_url":null},{"nid":3909,"title":"[Control systems] GE Digital security advisory (AV23-035)","uuid":"4ef169fa-7ef3-4281-bf2c-b7fd30799e63","banner":null,"lang":"en","date_modified":"2023-01-18","date_modified_ts":"2023-01-18T19:44:00Z","date_created":"2023-01-18T19:44:00Z","summary":null,"body":["<article data-history-node-id=\"3909\" about=\"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-035\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-035<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 18, 2023<\/p>\n\n<p>On January 17, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Proficy Historian\u00a0\u2013 version v7.0 and later<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-017-01\">ICS Advisory (ICSA-23-017-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-035","alert_type":398,"serial_number":"AV23-035","subject":null,"moderation_state":"published","external_url":null},{"nid":3910,"title":"Oracle security advisory \u2013 January 2023 quarterly rollup (AV23-036)","uuid":"606b2c4f-4a56-487d-b103-a62ff07f7b7c","banner":null,"lang":"en","date_modified":"2023-01-18","date_modified_ts":"2023-01-18T19:54:32Z","date_created":"2023-01-18T19:54:32Z","summary":null,"body":["<article data-history-node-id=\"3910\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-january-2023-quarterly-rollup-av23-036\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-036\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 18, 2023\n<\/p>\n<p>On January 17, 2023, Oracle published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>Enterprise Manager Base Platform\u00a0\u2013 versions 13.4.0.0 and 13.5.0.0<\/li>\n  <li>Fujitsu Servers\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>JD Edwards EnterpriseOne Orchestrator\u00a0\u2013 versions prior to 9.2.7.2<\/li>\n  <li>Management Cloud Engine \u2013 version 22.1.0.0.0<\/li>\n  <li>Middleware Common Libraries and Tools \u2013 versions 12.2.1.4.0 and 14.1.1.0.0<\/li>\n  <li>MySQL Enterprise Monitor\u00a0\u2013 version 8.0.32 and prior<\/li>\n  <li>MySQL Server\u00a0\u2013 multiple versions<\/li>\n  <li>MySQL Shell\u00a0\u2013 version 8.0.31 and prior<\/li>\n  <li>MySQL Workbench\u00a0\u2013 version 8.0.31 and prior<\/li>\n  <li>Oracle Banking Enterprise Default Management\u00a0\u2013 version 2.7.0<\/li>\n  <li>Oracle Banking Party Management\u00a0\u2013 version 2.7.0<\/li>\n  <li>Oracle Business Intelligence Enterprise Edition\u00a0\u2013 versions 5.9.0.0.0 and 6.4.0.0.0<\/li>\n  <li>Oracle Coherence\u00a0\u2013 versions 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n  <li>Oracle Commerce Guided Search\u00a0\u2013 version 11.3.2<\/li>\n  <li>Oracle Communications\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Oracle Essbase\u00a0\u2013 version 21.4<\/li>\n  <li>Oracle Financial Services Crime and Compliance Management Studio\u00a0\u2013 version 8.0.8.3.1<\/li>\n  <li>Oracle Global Lifecycle Management NextGen OUI Framework\u00a0\u2013 version prior to 13.9.4.2.11<\/li>\n  <li>Oracle Health Sciences Empirica Signal\u00a0\u2013 versions 9.1.0.52 and 9.2.0.52<\/li>\n  <li>Oracle Healthcare Data Repository\u00a0\u2013 version 8.1.0.0 to 8.1.3.1<\/li>\n  <li>Oracle Healthcare Translational Research\u00a0\u2013 version 4.1.0.0 to 4.1.1.1<\/li>\n  <li>Oracle HTTP Server\u00a0\u2013 version 12.2.1.4.0<\/li>\n  <li>Oracle Hyperion Infrastructure Technology\u00a0\u2013 version 11.2.10<\/li>\n  <li>Oracle Middleware Common Libraries and Tools\u00a0\u2013 version 12.2.1.4.0<\/li>\n  <li>Oracle Outside In Technology\u00a0\u2013 version 8.5.6<\/li>\n  <li>Oracle Utilities Framework\u00a0\u2013 versions 4.4.0.3.0 and 4.5.0.0.0<\/li>\n  <li>Oracle Utilities Network Management System\u00a0\u2013 multiple versions<\/li>\n  <li>Oracle WebCenter Content\u00a0\u2013 version 12.2.1.4.0<\/li>\n  <li>Oracle WebCenter Sites\u00a0\u2013 version 12.2.1.4.0<\/li>\n  <li>Oracle WebLogic Server\u00a0\u2013 versions 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0<\/li>\n  <li>OSS Support Tools\u00a0\u2013 versions 2.12.43, 22.4.22.10.18 and 22.2.22.4.5<\/li>\n  <li>PeopleSoft Enterprise CC Common Application Objects\u00a0\u2013 version 9.2<\/li>\n  <li>PeopleSoft Enterprise PeopleTools\u00a0\u2013 versions 8.58, 8.59 and 8.60<\/li>\n  <li>Primavera Gateway\u00a0\u2013 multiple versions<\/li>\n  <li>Siebel CRM\u00a0\u2013 version 22.10 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2023.html\">Oracle Critical Patch Update Advisory \u2013 January 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-january-2023-quarterly-rollup-av23-036","alert_type":396,"serial_number":"AV23-036","subject":null,"moderation_state":"published","external_url":null},{"nid":3911,"title":"GitLab security advisory (AV23-037)","uuid":"df6ecd32-4c40-40c8-9fde-010dac8d621a","banner":null,"lang":"en","date_modified":"2023-01-18","date_modified_ts":"2023-01-18T21:32:02Z","date_created":"2023-01-18T21:32:02Z","summary":null,"body":["<article data-history-node-id=\"3911\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-037\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-037<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 18, 2023<\/p>\n\n<p>On January 17, 2023, GitLab published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0- versions prior to 15.7.5, 15.6.6 and 15.5.9<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0- versions prior to 15.7.5, 15.6.6 and 15.5.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/01\/17\/critical-security-release-gitlab-15-7-5-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-037","alert_type":396,"serial_number":"AV23-037","subject":null,"moderation_state":"published","external_url":null},{"nid":3912,"title":"Sudo security advisory (AV23-038)","uuid":"cf827352-b2b4-411d-a650-bd0121ed887d","banner":null,"lang":"en","date_modified":"2023-01-18","date_modified_ts":"2023-01-18T21:45:59Z","date_created":"2023-01-18T21:32:45Z","summary":null,"body":["<article data-history-node-id=\"3912\" about=\"\/en\/alerts-advisories\/sudo-security-advisory-av23-038\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-038<br \/><strong>Date: <\/strong>January 18, 2023<\/p>\n\n<p>On January 18, 2023, Sudo published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Sudo\u00a0\u2013 versions 1.8.0 to 1.9.12p1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sudo.ws\/security\/advisories\/sudoedit_any\/\">Sudo Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sudo-security-advisory-av23-038","alert_type":396,"serial_number":"AV23-038","subject":null,"moderation_state":"published","external_url":null},{"nid":3913,"title":"[Control systems] Hitachi Energy security advisory (AV23-039) ","uuid":"0023c1d5-6276-4d41-bb20-784c6a866963","banner":null,"lang":"en","date_modified":"2023-01-19","date_modified_ts":"2023-01-19T20:47:01Z","date_created":"2023-01-19T20:40:49Z","summary":null,"body":["<article data-history-node-id=\"3913\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-039\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-039<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 19, 2023<\/p>\n\n<p>On January 19, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PCU400 \u2013 versions 9.3.x prior to 9.3.8<\/li>\n\t<li>PCULogger tool \u2013 version 1.0.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-019-01\">ICS Advisory (ICSA-23-019-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-039","alert_type":398,"serial_number":"AV23-039","subject":null,"moderation_state":"published","external_url":null},{"nid":3914,"title":"Cisco security advisory (AV23-040)","uuid":"de218ae8-63c0-49a8-834a-9ec0eb9543d4","banner":null,"lang":"en","date_modified":"2023-01-19","date_modified_ts":"2023-01-19T20:55:48Z","date_created":"2023-01-19T20:51:41Z","summary":null,"body":["<article data-history-node-id=\"3914\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-040\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-040<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 19, 2023<\/p>\n\n<p>On January 18, 2023, Cisco published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Cisco Unified CM \u2013 multiple versions<\/li>\n\t<li>Cisco Unified CM SME \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cucm-sql-rpPczR8n\">Cisco security advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-040","alert_type":396,"serial_number":"AV23-040","subject":null,"moderation_state":"published","external_url":null},{"nid":3916,"title":"Dell security advisory (AV23-043)","uuid":"5b006da5-9a08-4d23-bb78-26bfc3e7d53f","banner":null,"lang":"en","date_modified":"2023-01-24","date_modified_ts":"2023-01-24T14:15:48Z","date_created":"2023-01-23T18:14:51Z","summary":null,"body":["<article data-history-node-id=\"3916\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-043\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-043<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 23, 2023<\/p>\n\n<p>Between January 16 and 22, 2023, Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cloud Mobility for Dell Storag\u00a0\u2013 versions 1.3.3.X and prior<\/li>\n\t<li>Dell Repository Manager (DRM\u00a0\u2013 version 3.4.2 and prior<\/li>\n\t<li>ME5012, ME5024 and ME508\u00a0\u2013 versions prior to ME5.1.1.0.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000207521\/dsa-2023-019-dell-emc-cloud-mobility-security-update-for-certificate-revocation-vulnerability \">Dell Security Advisory (DSA-2023-019)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000207513\/dsa-2023-017-dell-emc-repository-manager-drm-security-update-foranimproper-privilege-managementvulnerability\">Dell Security Advisory (DSA-2023-017)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000207533\/dsa-2023-018-dell-emc-powervault-me5-security-update-for-a-client-desync-attack-vulnerability \">Dell Security Advisory (DSA-2023-018)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-043","alert_type":396,"serial_number":"AV23-043","subject":null,"moderation_state":"published","external_url":null},{"nid":3917,"title":"IBM security advisory (AV23-041)","uuid":"02ac2431-2424-468c-92c2-2b437a1819ff","banner":null,"lang":"en","date_modified":"2023-01-23","date_modified_ts":"2023-01-23T18:15:23Z","date_created":"2023-01-23T18:15:23Z","summary":null,"body":["<article data-history-node-id=\"3917\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-041\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-041<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 23, 2023<\/p>\n\n<p>Between January 16 and 22, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cloud Pak for Security (CP4S)\u00a0\u2013 version 1.10.0.0 to 1.10.7.0<\/li>\n\t<li>IBM Spectrum Conductor\u00a0\u2013 versions 2.4.1, 2.5.0 and 2.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6856401\">IBM Security Bulletin (Cloud Pak for Security)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6856391\">IBM Security Bulletin (IBM Spectrum Conductor)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-041","alert_type":396,"serial_number":"AV23-041","subject":null,"moderation_state":"published","external_url":null},{"nid":3918,"title":"Ubuntu security advisory (AV23-042)","uuid":"e401d95f-7b9b-42a9-b3c8-39e8bac6a555","banner":null,"lang":"en","date_modified":"2023-01-23","date_modified_ts":"2023-01-23T18:52:50Z","date_created":"2023-01-23T18:52:50Z","summary":null,"body":["<article data-history-node-id=\"3918\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-042\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-042<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 23, 2023<\/p>\n\n<p>Between January 16 and 22, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-042","alert_type":396,"serial_number":"AV23-042","subject":null,"moderation_state":"published","external_url":null},{"nid":3919,"title":"[Control systems] XINJE security advisory (AV23-044)","uuid":"7ef4725b-656b-4feb-80b0-f34c9117e0c0","banner":null,"lang":"en","date_modified":"2023-01-24","date_modified_ts":"2023-01-24T18:17:13Z","date_created":"2023-01-24T18:17:13Z","summary":null,"body":["<article data-history-node-id=\"3919\" about=\"\/en\/alerts-advisories\/control-systems-xinje-security-advisory-av23-044\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-044<br \/><strong>Date: <\/strong>January 24, 2023<\/p>\n\n<p>On January 24, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>XINJE XD\u00a0\u2013 version 3.5.1 and prior<\/li>\n<\/ul><p>Successful exploitation of these vulnerabilities could lead to data modification and arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-22-024-01\">ICS Advisory (ICSA-22-024-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-xinje-security-advisory-av23-044","alert_type":398,"serial_number":"AV23-044","subject":null,"moderation_state":"published","external_url":null},{"nid":3920,"title":"VMware security advisory (AV23-046)","uuid":"7738971b-3f1b-402f-8adb-b55a457b89b1","banner":null,"lang":"en","date_modified":"2023-01-25","date_modified_ts":"2023-01-25T13:25:11Z","date_created":"2023-01-24T20:01:04Z","summary":null,"body":["<article data-history-node-id=\"3920\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-046\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-046<br \/><strong>Date: <\/strong>January 24, 2023<\/p>\n\n<p>On January 24, 2023, VMware published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware vRealize Log Insight\u00a0\u2013 versions 8.x prior to 8.10.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0001.html\">VMware Security Advisory (VMSA-2023-0001)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-046","alert_type":396,"serial_number":"AV23-046","subject":null,"moderation_state":"published","external_url":null},{"nid":3921,"title":"[Control systems] SOCOMEC security advisory (AV23-045)","uuid":"3d22312e-b359-42be-965b-fe7aad45a1b6","banner":null,"lang":"en","date_modified":"2023-01-24","date_modified_ts":"2023-01-24T21:49:11Z","date_created":"2023-01-24T21:49:11Z","summary":null,"body":["<article data-history-node-id=\"3921\" about=\"\/en\/alerts-advisories\/control-systems-socomec-security-advisory-av23-045\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-045<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 24, 2023<\/p>\n\n<p>On January 24, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SOCOMEC MODULYS GP\u00a0\u2013 Netvision v7.20 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-024-02\">ICS Advisory (ICSA-23-024-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-socomec-security-advisory-av23-045","alert_type":398,"serial_number":"AV23-045","subject":null,"moderation_state":"published","external_url":null},{"nid":3922,"title":"Apple security advisory (AV23-047)","uuid":"4fb58890-c7a6-4035-a8df-261059992004","banner":null,"lang":"en","date_modified":"2023-01-25","date_modified_ts":"2023-01-25T13:37:17Z","date_created":"2023-01-25T13:37:17Z","summary":null,"body":["<article data-history-node-id=\"3922\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-047\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-047<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 24, 2023<\/p>\n\n<p>Between January 23 and 24, 2023, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS 12\u00a0- versions prior to 12.5.7<\/li>\n\t<li>iOS\/iPadOS 15\u00a0- versions prior to 15.7.3<\/li>\n\t<li>iOS\/iPadOS 16\u00a0- versions prior to 16.3<\/li>\n\t<li>macOS Big Sur\u00a0- versions prior to 11.7.3<\/li>\n\t<li>macOS Monterey\u00a0- versions prior to 12.6.3<\/li>\n\t<li>macOS Ventura\u00a0- versions prior to 13.2<\/li>\n\t<li>Safari\u00a0- versions prior to 16.3<\/li>\n\t<li>tvOS\u00a0- versions prior to 16.3<\/li>\n\t<li>watchOS\u00a0- versions prior to 9.3<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution, privilege escalation or access to sensitive information.<\/p>\n\n<p>Apple has received reports that CVE-2022-42856 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-047","alert_type":396,"serial_number":"AV23-047","subject":null,"moderation_state":"published","external_url":null},{"nid":3923,"title":"Google Chrome security advisory (AV23-048)","uuid":"748ac39d-13ce-48f7-8862-213716a7624f","banner":null,"lang":"en","date_modified":"2023-01-25","date_modified_ts":"2023-01-25T13:58:12Z","date_created":"2023-01-25T13:58:12Z","summary":null,"body":["<article data-history-node-id=\"3923\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-048\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-048<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 24, 2023<\/p>\n\n<p>On January 24, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 109.0.5414.119\/.120<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/01\/stable-channel-update-for-desktop_24.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-048","alert_type":396,"serial_number":"AV23-048","subject":null,"moderation_state":"published","external_url":null},{"nid":3924,"title":"ISC BIND security advisory (AV23-049)","uuid":"58807c8f-737f-4061-9e62-ecb341085f17","banner":null,"lang":"en","date_modified":"2023-01-26","date_modified_ts":"2023-01-26T15:02:15Z","date_created":"2023-01-26T15:02:15Z","summary":null,"body":["<article data-history-node-id=\"3924\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av23-049\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-049<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 26, 2023<\/p>\n\n<p>On January 25, 2023, ISC published Security Advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ISC BIND 9\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2022-3094\">ISC BIND security advisory (CVE-2022-3094)<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2022-3736\">ISC BIND security advisory (CVE-2022-3736)<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2022-3924\">ISC BIND security advisory (CVE-2022-3924)<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av23-049","alert_type":396,"serial_number":"AV23-049","subject":null,"moderation_state":"published","external_url":null},{"nid":3925,"title":"[Control systems] Snap One security advisory (AV23-050)","uuid":"148b8dd6-b761-442c-9b77-6359c33947a4","banner":null,"lang":"en","date_modified":"2023-01-26","date_modified_ts":"2023-01-26T21:07:41Z","date_created":"2023-01-26T21:07:41Z","summary":null,"body":["<article data-history-node-id=\"3925\" about=\"\/en\/alerts-advisories\/control-systems-snap-one-security-advisory-av23-050\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-050<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 26, 2023<\/p>\n\n<p>On January 26, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Wattbox WB-300-IP-3\u00a0\u2013 versions WB10.9a17 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-026-03\">ICS Advisory (ICSA-23-026-03)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-snap-one-security-advisory-av23-050","alert_type":398,"serial_number":"AV23-050","subject":null,"moderation_state":"published","external_url":null},{"nid":3926,"title":"[Control systems] Sierra Wireless security advisory (AV23-051)","uuid":"e7f4c940-bd94-433c-8c3e-f571f12834be","banner":null,"lang":"en","date_modified":"2023-01-26","date_modified_ts":"2023-01-26T22:01:05Z","date_created":"2023-01-26T22:01:05Z","summary":null,"body":["<article data-history-node-id=\"3926\" about=\"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory-av23-051\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-051<br \/><strong>Date: <\/strong>January 26, 2023<\/p>\n\n<p>On January 26, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Airlink Router\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in information disclosure and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-026-04\">ICS Advisory (ICSA-23-026-04)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory-av23-051","alert_type":398,"serial_number":"AV23-051","subject":null,"moderation_state":"published","external_url":null},{"nid":3927,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-052)","uuid":"8da916fa-69af-4dfb-9942-79458c31a030","banner":null,"lang":"en","date_modified":"2023-01-27","date_modified_ts":"2023-01-27T13:34:37Z","date_created":"2023-01-27T13:34:37Z","summary":null,"body":["<article data-history-node-id=\"3927\" about=\"\/en\/alerts-advisories\/systemes-controle-bulletin-securite-mitsubishi-electric-av23-052\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-052<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 26, 2023<\/p>\n\n<p>On January 26, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MELFA SD\/SQ Series\u00a0- firmware version S7x and prior<\/li>\n\t<li>MELFA SD\/SQ Series\u00a0- firmware version R7x and prior<\/li>\n\t<li>MELFA F-Series\u00a0- firmware version S7x and prior<\/li>\n\t<li>MELFA F-Series\u00a0\u2013 firmware version R7x and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-026-05 \">ICS Advisory (ICSA-23-026-05)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/systemes-controle-bulletin-securite-mitsubishi-electric-av23-052","alert_type":398,"serial_number":"AV23-052","subject":null,"moderation_state":"published","external_url":null},{"nid":3928,"title":"[Control systems] Delta Electronics security advisory (AV23-055)","uuid":"e09545eb-bbb1-4047-a68a-7c5767e6f08c","banner":null,"lang":"en","date_modified":"2023-01-30","date_modified_ts":"2023-01-30T13:33:32Z","date_created":"2023-01-27T13:54:54Z","summary":null,"body":["<article data-history-node-id=\"3928\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-055\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-055\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 30, 2023\n<\/p>\n<p>On January 26, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following products:\n<\/p>\n<ul><li>CNCSoft\u00a0- versions prior to v1.01.34<\/li>\n  <li>Running ScreenEditor\u00a0- version 1.01.5 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in remote code execution.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-026-01\">ICS Advisory (ICSA-23-026-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-055","alert_type":398,"serial_number":"AV23-055","subject":null,"moderation_state":"published","external_url":null},{"nid":3929,"title":"[Control systems] Landis+Gyr security advisory (AV23-053)","uuid":"50c138d8-19bb-410e-91f5-f7cc54a238e6","banner":null,"lang":"en","date_modified":"2023-01-27","date_modified_ts":"2023-01-27T14:45:53Z","date_created":"2023-01-27T14:45:53Z","summary":null,"body":["<article data-history-node-id=\"3929\" about=\"\/en\/alerts-advisories\/control-systems-landisgyr-security-advisory-av23-053\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-053\n  <br \/><strong>Date: <\/strong>January 27, 2023\n<\/p>\n<p>On January 26, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>E850 (ZMQ200)\u00a0\u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-026-07\">ICS Advisory (ICSA-23-026-07)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-landisgyr-security-advisory-av23-053","alert_type":398,"serial_number":"AV23-053","subject":null,"moderation_state":"published","external_url":null},{"nid":3930,"title":"[Control systems] Econolite security advisory (AV23-054)","uuid":"6a52c2fc-9376-4e14-8aaf-1ea52fc04889","banner":null,"lang":"en","date_modified":"2023-01-27","date_modified_ts":"2023-01-27T15:28:54Z","date_created":"2023-01-27T15:28:54Z","summary":null,"body":["<article data-history-node-id=\"3930\" about=\"\/en\/alerts-advisories\/control-systems-econolite-security-advisory-av23-054\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-054\n  <br \/><strong>Date: <\/strong>January 27, 2023\n<\/p>\n<p>On January 26, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:\n<\/p>\n<ul><li>EOS\u00a0\u2013 all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a full system compromise.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-026-02\">ICS Advisory (ICSA-23-026-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-econolite-security-advisory-av23-054","alert_type":398,"serial_number":"AV23-054","subject":null,"moderation_state":"published","external_url":null},{"nid":3931,"title":"[Control systems] Rockwell Automation security advisory (AV23-056)","uuid":"8d975d48-b1ce-4dfd-9382-814be389fa00","banner":null,"lang":"en","date_modified":"2023-01-30","date_modified_ts":"2023-01-30T13:45:39Z","date_created":"2023-01-27T20:39:30Z","summary":null,"body":["<article data-history-node-id=\"3931\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-056\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-056<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 30, 2023<\/p>\n\n<p>On January 26, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following:<\/p>\n\n<ul><li>Rockwell Automation products using GoAhead web server<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-026-06\">ICS Advisory (ICSA-23-026-06)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-056","alert_type":398,"serial_number":"AV23-056","subject":null,"moderation_state":"published","external_url":null},{"nid":3932,"title":"IBM security advisory (AV23-057)","uuid":"078d5223-ab22-4de4-a8bb-ae341a1604c0","banner":null,"lang":"en","date_modified":"2023-01-31","date_modified_ts":"2023-01-31T14:57:00Z","date_created":"2023-01-30T16:43:15Z","summary":null,"body":["<article data-history-node-id=\"3932\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-057\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-057<br \/><strong>Date: <\/strong>January 31, 2023<\/p>\n\n<p>Between January 23 and 29, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM MQ Operator CD\u00a0\u2013 version 2.2.1 and prior<\/li>\n\t<li>IBM MQ Operator LTS\u00a0\u2013 version 2.0.6 and prior<\/li>\n\t<li>IBM supplied MQ Advanced container images\u00a0\u2013 versions 9.3.0.1-r4, 9.3.1.0-r3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6857613\">IBM Security Bulletin (IBM MQ)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-057","alert_type":396,"serial_number":"AV23-057","subject":null,"moderation_state":"published","external_url":null},{"nid":3933,"title":"Ubuntu security advisory (AV23-058)","uuid":"2f006f29-efb6-4ed9-9a49-bf1be8176980","banner":null,"lang":"en","date_modified":"2023-01-31","date_modified_ts":"2023-01-31T14:58:10Z","date_created":"2023-01-30T16:53:48Z","summary":null,"body":["<article data-history-node-id=\"3933\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-058\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-058<br \/><strong>Date: <\/strong>January 31, 2023<\/p>\n\n<p>Between January 23 and 29, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-058","alert_type":396,"serial_number":"AV23-058","subject":null,"moderation_state":"published","external_url":null},{"nid":3934,"title":"[Control systems] Delta Electronics security advisory (AV23-059)","uuid":"fda0b22d-424e-4364-b212-c2d694cd403c","banner":null,"lang":"en","date_modified":"2023-01-31","date_modified_ts":"2023-01-31T20:47:18Z","date_created":"2023-01-31T20:47:18Z","summary":null,"body":["<article data-history-node-id=\"3934\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-059\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-059<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 31, 2023<\/p>\n\n<p>On January 31, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>DOPSoft\u00a0\u2013 version 4.00.16.22 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-031-01\">ICS Advisory (ICSA-23-031-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-059","alert_type":398,"serial_number":"AV23-059","subject":null,"moderation_state":"published","external_url":null},{"nid":3935,"title":"HPE security advisory (AV23-060)","uuid":"fe40162a-58a8-438e-8faa-e44c1db4d065","banner":null,"lang":"en","date_modified":"2023-02-02","date_modified_ts":"2023-02-02T14:22:52Z","date_created":"2023-02-01T21:15:58Z","summary":null,"body":["<article data-history-node-id=\"3935\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-060\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-060<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 2, 2023<\/p>\n\n<p>On February 1, 2023, HPE published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE OneView\u00a0\u2013 versions prior to 8.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04402en_us\">HPE Security Bulletin (HPESBGN04402EN_US)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-060","alert_type":396,"serial_number":"AV23-060","subject":null,"moderation_state":"published","external_url":null},{"nid":3936,"title":"F5 security advisory (AV23-061)","uuid":"0504fe90-a196-416e-9c93-45d16a24bbdc","banner":null,"lang":"en","date_modified":"2023-02-02","date_modified_ts":"2023-02-02T14:31:45Z","date_created":"2023-02-01T21:48:12Z","summary":null,"body":["<article data-history-node-id=\"3936\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av23-061\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-061<br \/><strong>Date: <\/strong>February 2, 2023<\/p>\n\n<p>On February 1, 2023, F5 published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>BIG-IP\u00a0- multiple versions and platforms<\/li>\n\t<li>F5OS\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000130496\">F5 Security Advisory (K000130496) \u2013 Overview of F5 vulnerabilities (February 2023)<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=cve&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending\">F5 Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av23-061","alert_type":396,"serial_number":"AV23-061","subject":null,"moderation_state":"published","external_url":null},{"nid":3938,"title":"Atlassian security advisory (AV23-062)","uuid":"8d977a46-68dd-45d4-bb91-3b94644811b7","banner":null,"lang":"en","date_modified":"2023-02-02","date_modified_ts":"2023-02-02T16:42:24Z","date_created":"2023-02-02T16:42:24Z","summary":null,"body":["<article data-history-node-id=\"3938\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-062\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-062<br \/><strong>Date: <\/strong>February 2, 2023<\/p>\n\n<p>On February 1, 2023, Atlassian published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Jira Service Management Server and Data Center\u00a0\u2013 versions 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1 and 5.5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/jira\/jira-service-management-server-and-data-center-advisory-cve-2023-22501-1188786458.html\">Atlassian Security Advisory (CVE-2023-22501)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-062","alert_type":396,"serial_number":"AV23-062","subject":null,"moderation_state":"published","external_url":null},{"nid":3940,"title":"[Control systems] Baicells security advisory (AV23-065)","uuid":"63bb5ee6-f044-4d9f-a890-3409a3aee954","banner":null,"lang":"en","date_modified":"2023-02-03","date_modified_ts":"2023-02-03T16:52:11Z","date_created":"2023-02-02T22:10:47Z","summary":null,"body":["<article data-history-node-id=\"3940\" about=\"\/en\/alerts-advisories\/control-systems-baicells-security-advisory-av23-065\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-065<br \/><strong>Date: <\/strong>February 3, 2023<\/p>\n\n<p>On February 2, 2023, ICS\u2011CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Nova 227, 233, 243 and 246\u00a0\u2013 firmware version RTS\/RTD 3.6.6 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-033-03\">ICS Advisory (ICSA\u201123\u2011033\u201103)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-baicells-security-advisory-av23-065","alert_type":398,"serial_number":"AV23-065","subject":null,"moderation_state":"published","external_url":null},{"nid":3941,"title":"[Control systems] Delta Electronics security advisory (AV22-063)","uuid":"e6c812ef-d28b-43d9-bd65-4ffe701a5f00","banner":null,"lang":"en","date_modified":"2023-02-03","date_modified_ts":"2023-02-03T13:41:15Z","date_created":"2023-02-03T13:41:15Z","summary":null,"body":["<article data-history-node-id=\"3941\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-063\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-063<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 03, 2023<\/p>\n\n<p>On February 2, 2023, ICS-CERT published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>DIAScreen\u00a0- versions 1.2.1.23 and prior<\/li>\n\t<li>DVW-W02W2-E2\u00a0- version 2.42<\/li>\n\t<li>DX-2100-L1-CN\u00a0- version 1.5.0.10<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution and unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-033-01\">ICS Advisory (ICSA-23-033-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-033-04\">ICS Advisory (ICSA-23-033-04)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-033-05\">ICS Advisory (ICSA-23-033-05)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av22-063","alert_type":398,"serial_number":"AV23-063","subject":null,"moderation_state":"published","external_url":null},{"nid":3942,"title":"VMware security advisory (AV23-066)","uuid":"fb5e965e-c0fa-4de6-ad77-6da67616a6a5","banner":null,"lang":"en","date_modified":"2023-02-03","date_modified_ts":"2023-02-03T18:09:54Z","date_created":"2023-02-03T14:41:01Z","summary":null,"body":["<article data-history-node-id=\"3942\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-066\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-066<br \/><strong>Date: <\/strong>February 3, 2023<\/p>\n\n<p>On February 3, 2023, VMware published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>VMware Workstation\u00a0\u2013 versions prior to 17.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0003.html\">VMware Security Advisory (VMSA-2023-0003)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-066","alert_type":396,"serial_number":"AV23-066","subject":null,"moderation_state":"published","external_url":null},{"nid":3943,"title":"[Control systems] Mitsubishi security advisory (AV23-064)","uuid":"fa333211-55fc-476c-bc75-551ee7713882","banner":null,"lang":"en","date_modified":"2023-02-03","date_modified_ts":"2023-02-03T16:01:38Z","date_created":"2023-02-03T16:01:38Z","summary":null,"body":["<article data-history-node-id=\"3943\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-security-advisory-av23-064\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-064<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 03, 2023<\/p>\n\n<p>On February 2, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GOT2000 Series, GT25 and GT27 models\u00a0- versions 01.14.000 to 01.47.000<\/li>\n\t<li>GT SoftGOT2000\u00a0- versions 1.265B to 1.285X<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution, user impersonation and information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-033-02\">ICS Advisory (ICSA-23-033-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-security-advisory-av23-064","alert_type":398,"serial_number":"AV23-064","subject":null,"moderation_state":"published","external_url":null},{"nid":3944,"title":"Microsoft Edge security advisory (AV23-067)","uuid":"d89c4f13-dd03-4f6b-a48f-7a116ffa9e4d","banner":null,"lang":"en","date_modified":"2023-02-03","date_modified_ts":"2023-02-03T18:41:59Z","date_created":"2023-02-03T18:28:26Z","summary":null,"body":["<article data-history-node-id=\"3944\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-067\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-067<br \/><strong>Date: <\/strong>February 3, 2023<\/p>\n\n<p>On February 2, 2023, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 109.0.1518.78<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-2-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-067","alert_type":396,"serial_number":"AV23-067","subject":null,"moderation_state":"published","external_url":null},{"nid":3945,"title":"ABB security advisory (AV23-068)","uuid":"d9bd1746-768c-4c44-b150-155461ba74fc","banner":null,"lang":"en","date_modified":"2023-02-06","date_modified_ts":"2023-02-06T14:59:19Z","date_created":"2023-02-03T21:15:48Z","summary":null,"body":["<article data-history-node-id=\"3945\" about=\"\/en\/alerts-advisories\/abb-security-advisory-av23-068\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-068<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 6, 2023<\/p>\n\n<p>On January 30, 2023, ABB published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>B&amp;R APROL\u00a0\u2013 versions prior to R 4.2-07<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service, access to sensitive information or data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1674823095245-en-original-1.0.pdf\">ABB Security Advisory (B&amp;R APROL)(PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/abb-security-advisory-av23-068","alert_type":396,"serial_number":"AV23-068","subject":null,"moderation_state":"published","external_url":null},{"nid":3946,"title":"IBM security advisory (AV23-069)","uuid":"603fdd3f-509a-4bad-b511-2d7d4159bc20","banner":null,"lang":"en","date_modified":"2023-02-06","date_modified_ts":"2023-02-06T18:25:49Z","date_created":"2023-02-06T16:50:23Z","summary":null,"body":["<article data-history-node-id=\"3946\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-069\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-069<br \/><strong>Date: <\/strong>February 6, 2023<\/p>\n\n<p>Between January 30 and February 5, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Db2 and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6890703\">IBM Security Bulletin (IBM Db2)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-069","alert_type":396,"serial_number":"AV23-069","subject":null,"moderation_state":"published","external_url":null},{"nid":3948,"title":"Ubuntu security advisory (AV23-070)","uuid":"ab99beda-9206-4745-a526-b0790819cae5","banner":null,"lang":"en","date_modified":"2023-02-06","date_modified_ts":"2023-02-06T18:33:49Z","date_created":"2023-02-06T18:29:07Z","summary":null,"body":["<article data-history-node-id=\"3948\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-070\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-070<br \/><strong>Date: <\/strong>February 6, 2023<\/p>\n\n<p>Between January 30 and February 5, 2023, Ubuntu published a Security Notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5832-1\">Ubuntu Security Notice (USN-5832-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-070","alert_type":396,"serial_number":"AV23-070","subject":null,"moderation_state":"published","external_url":null},{"nid":3947,"title":"Dell security advisory (AV23-071)","uuid":"44fead59-96b9-4934-aa6a-04b827f5c240","banner":null,"lang":"en","date_modified":"2023-02-06","date_modified_ts":"2023-02-06T20:06:37Z","date_created":"2023-02-06T19:56:58Z","summary":null,"body":["<article data-history-node-id=\"3947\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-071\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-071<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 6, 2023<\/p>\n\n<p>Between January 30 and February 5, 2023, Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>PowerFlex Appliance\u00a0- multiple versions<\/li>\n\t<li>PowerFlex Rack\u00a0- multiple versions<\/li>\n\t<li>Dell Avamar\u00a0- multiple platforms and versions<\/li>\n\t<li>Dell NetWorker Virtual edition\u00a0- multiple versions<\/li>\n\t<li>Dell PowerProtect\u00a0- multiple platforms and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000208055\/dsa-2023-026-dell-emc-powerflex-appliance-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (DSA-2023-026)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000208056\/dsa-2022-025-dell-emc-powerflex-rack-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory (DSA-2023-025)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000208261\/dsa-2022-359-dell-emc-avamar-dell-emc-networker-virtual-edition-nve-and-dell-emc-powerprotect-dp-series-appliance-dell-emc-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (DSA-2023-359)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000208263\/dsa-2023-036-dell-emc-avamar-server-avamar-virtual-edition-security-update-for-apache-struts-vulnerability\">Dell Security Advisory (DSA-036)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-071","alert_type":396,"serial_number":"AV23-071","subject":null,"moderation_state":"published","external_url":null},{"nid":3951,"title":"Android security advisory \u2013 February 2023 monthly rollup (AV23-072)","uuid":"61104358-cd23-4559-b86b-91098f81c58f","banner":null,"lang":"en","date_modified":"2023-02-07","date_modified_ts":"2023-02-07T17:13:02Z","date_created":"2023-02-07T17:06:32Z","summary":null,"body":["<article data-history-node-id=\"3951\" about=\"\/en\/alerts-advisories\/android-security-advisory-february-2023-monthly-rollup-av23-072\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-072<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 7, 2023<\/p>\n\n<p>On February 6, 2023, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-02-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-february-2023-monthly-rollup-av23-072","alert_type":396,"serial_number":"AV23-072","subject":null,"moderation_state":"published","external_url":null},{"nid":3952,"title":"Google Chrome security advisory (AV23-073)","uuid":"aceebf8e-fe0a-4d84-8e70-bb0ef7db81fc","banner":null,"lang":"en","date_modified":"2023-02-08","date_modified_ts":"2023-02-08T16:42:52Z","date_created":"2023-02-08T16:34:08Z","summary":null,"body":["<article data-history-node-id=\"3952\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-073\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-073<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 8, 2023<\/p>\n\n<p>On February 7, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 0.5481.77 (Mac and Linux) and 110.0.5481.77\/.78 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/02\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-073","alert_type":396,"serial_number":"AV23-073","subject":null,"moderation_state":"published","external_url":null},{"nid":3953,"title":"[Control systems] EnOcean Edge security advisory (AV23-074)","uuid":"9579b0bc-71e6-47d9-8edd-ea1809048abb","banner":null,"lang":"en","date_modified":"2023-02-08","date_modified_ts":"2023-02-08T16:49:13Z","date_created":"2023-02-08T16:44:53Z","summary":null,"body":["<article data-history-node-id=\"3953\" about=\"\/en\/alerts-advisories\/control-systems-enocean-edge-security-advisory-av23-074\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-074<br \/><strong>Date: <\/strong>February 8, 2023<\/p>\n\n<p>On February 7, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>EnOcean SmartServer\u00a0\u2013 version 2.2 SR8\/SP8 (4.12.006) with i.LON Vision v2.2 SR8\/SP8 (4.12.006)<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-037-01\">ICS Advisory (ICSA-23-037-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-enocean-edge-security-advisory-av23-074","alert_type":398,"serial_number":"AV23-074","subject":null,"moderation_state":"published","external_url":null},{"nid":3955,"title":"[Control systems] Horner security advisory (AV23-075)","uuid":"54b8807e-9f08-4fe7-b540-7e157bdae9ce","banner":null,"lang":"en","date_modified":"2023-02-10","date_modified_ts":"2023-02-10T16:19:28Z","date_created":"2023-02-10T16:11:26Z","summary":null,"body":["<article data-history-node-id=\"3955\" about=\"\/en\/alerts-advisories\/control-systems-horner-security-advisory-av23-075\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-075<br \/><!-- DATES Pick one update the day xx, delete the rest --><\/p>\n\n<p><strong>Date: <\/strong>February 10, 2023<\/p>\n\n<p>On February 9, 2023, ICS-CERT published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Cscape Envision RV\u00a0\u2013 version 4.60<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-040-04\">ICS Advisory (ICSA-23-040-04)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-security-advisory-av23-075","alert_type":398,"serial_number":"AV23-075","subject":null,"moderation_state":"published","external_url":null},{"nid":3956,"title":"[Control systems] LS ELECTRIC security advisory (AV23-076)","uuid":"8b2325dd-6a13-4e0a-ab46-f82fae59bf96","banner":null,"lang":"en","date_modified":"2023-02-10","date_modified_ts":"2023-02-10T16:54:04Z","date_created":"2023-02-10T16:45:22Z","summary":null,"body":["<article data-history-node-id=\"3956\" about=\"\/en\/alerts-advisories\/control-systems-ls-electric-security-advisory-av23-076\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-076<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 10, 2023<\/p>\n\n<p>On February 9, 2023, ICS-CERT published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>XBC-DN32U: Operating System\u00a0\u2013 version 01.80<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in the impersonation of legitimate users or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-040-02\">ICS Advisory (ICSA-23-040-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ls-electric-security-advisory-av23-076","alert_type":398,"serial_number":"AV23-076","subject":null,"moderation_state":"published","external_url":null},{"nid":3957,"title":"[Control systems] Control By Web security advisory (AV23-077)","uuid":"52ce6666-2790-4760-aa39-8d0396b65b97","banner":null,"lang":"en","date_modified":"2023-02-10","date_modified_ts":"2023-02-10T17:16:09Z","date_created":"2023-02-10T17:08:12Z","summary":null,"body":["<article data-history-node-id=\"3957\" about=\"\/en\/alerts-advisories\/control-systems-control-web-security-advisory-av23-077\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-077<br \/><strong>Date: <\/strong>February 10, 2023<\/p>\n\n<p>On February 9, 2023, ICS-CERT published a Security Advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>X-400\u00a0- firmware versions prior to 2.8\u00a0<\/li>\n\t<li>X-600M\u00a0- firmware versions prior to 1.16.00\u00a0<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-040-01\">ICS Advisory (ICSA-23-040-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-control-web-security-advisory-av23-077","alert_type":398,"serial_number":"AV23-077","subject":null,"moderation_state":"published","external_url":null},{"nid":3958,"title":"[Control systems] Johnson Controls security advisory (AV23-078)","uuid":"7e48320a-9acf-4c46-988e-6b63a85b2637","banner":null,"lang":"en","date_modified":"2023-02-10","date_modified_ts":"2023-02-10T17:26:06Z","date_created":"2023-02-10T17:20:41Z","summary":null,"body":["<article data-history-node-id=\"3958\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-078\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-078<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 10, 2023<\/p>\n\n<p>On February 9, 2023, ICS-CERT published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>System Configuration Tool (SCT) version 14\u00a0\u2013 versions prior to 14.2.3<\/li>\n\t<li>System Configuration Tool (SCT) version 15\u00a0\u2013 versions prior to 15.0.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in the impersonation of legitimate users.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-040-03\">ICS Advisory (ICSA-23-040-03)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-078","alert_type":398,"serial_number":"AV23-078","subject":null,"moderation_state":"published","external_url":null},{"nid":3959,"title":"Microsoft Edge security advisory (AV23-079)","uuid":"438c390a-9052-4364-b797-1f1b57a02284","banner":null,"lang":"en","date_modified":"2023-02-13","date_modified_ts":"2023-02-13T15:46:17Z","date_created":"2023-02-10T20:57:50Z","summary":null,"body":["<article data-history-node-id=\"3959\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-079\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-079<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong> February 13, 2023<\/p>\n\n<p>On February 9, 2023, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 110.0.1587.41<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-9-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-079","alert_type":396,"serial_number":"AV23-079","subject":null,"moderation_state":"published","external_url":null},{"nid":3960,"title":"ABB security advisory (AV23-080)","uuid":"9d8a82e3-06e6-4a01-9ea0-3c67cd65124e","banner":null,"lang":"en","date_modified":"2023-02-13","date_modified_ts":"2023-02-13T15:49:22Z","date_created":"2023-02-10T21:34:37Z","summary":null,"body":["<article data-history-node-id=\"3960\" about=\"\/en\/alerts-advisories\/abb-security-advisory-av23-080\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-080<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 13, 2023<\/p>\n\n<p>On February 10, 2023, ABB published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Drive Composer\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108467A7957&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Security Advisory (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/abb-security-advisory-av23-080","alert_type":396,"serial_number":"AV23-080","subject":null,"moderation_state":"published","external_url":null},{"nid":3962,"title":"Dell security advisory (AV23-081)","uuid":"e4759dfb-bc5e-45dd-ad8e-13b965d11a4c","banner":null,"lang":"en","date_modified":"2023-02-13","date_modified_ts":"2023-02-13T18:44:45Z","date_created":"2023-02-13T18:31:03Z","summary":null,"body":["<article data-history-node-id=\"3962\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-081\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-081<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 13, 2023<\/p>\n\n<p>Between February 6 and February 12, 2023, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Data Protection Search\u00a0- multiple versions<\/li>\n\t<li>Dell Integrated Data Protection Appliance\u00a0- multiple platforms and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000208448\/dsa-2023-063-dell-emc-data-protection-search-security-update-for-multiple-vulnerabilities\">Dell Security Advisory (DSA-2023-063)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-081","alert_type":396,"serial_number":"AV23-081","subject":null,"moderation_state":"published","external_url":null},{"nid":3963,"title":"Ubuntu security advisory (AV23-082)","uuid":"d42ee156-afc6-411f-8277-75818c22131b","banner":null,"lang":"en","date_modified":"2023-02-13","date_modified_ts":"2023-02-13T19:06:50Z","date_created":"2023-02-13T18:58:30Z","summary":null,"body":["<article data-history-node-id=\"3963\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-082\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-082<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 13, 2023<\/p>\n\n<p>Between February 6 and February 12, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04<\/li>\n\t<li>Ubuntu 18.04<\/li>\n\t<li>Ubuntu 20.04<\/li>\n\t<li>Ubuntu 22.04<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-082","alert_type":396,"serial_number":"AV23-082","subject":null,"moderation_state":"published","external_url":null},{"nid":3964,"title":"IBM security advisory (AV23-083)","uuid":"6b0147c1-d3c4-4145-bdfc-f3ae21241686","banner":null,"lang":"en","date_modified":"2023-02-13","date_modified_ts":"2023-02-13T21:28:20Z","date_created":"2023-02-13T21:07:49Z","summary":null,"body":["<article data-history-node-id=\"3964\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-083\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-083<br \/><strong>Date: <\/strong>February\u00a013, 2023<\/p>\n\n<p>Between February 6 and February 12, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Business Automation Manager Open Editions\u00a0\u2013 version 8.0.1<\/li>\n\t<li>IBM Security Directory Integrator\u00a0\u2013 version 7.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6953705\">IBM Security Bulletin (IBM Business Automation Manager Open Editions)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6955033\">IBM Security Bulletin (IBM Security Directory Integrator)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-083","alert_type":396,"serial_number":"AV23-083","subject":null,"moderation_state":"published","external_url":null},{"nid":3966,"title":"SAP security advisory \u2013 February 2023 monthly rollup (AV23-084)","uuid":"3c3ecf94-8b40-497b-ab0b-56008451dd9a","banner":null,"lang":"en","date_modified":"2023-02-14","date_modified_ts":"2023-02-14T17:01:19Z","date_created":"2023-02-14T16:46:54Z","summary":null,"body":["<article data-history-node-id=\"3966\" about=\"\/en\/alerts-advisories\/sap-security-advisory-february-2023-monthly-rollup-av23-084\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-084<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 14, 2023<\/p>\n\n<p>On February 14, 2023, SAP published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP BusinessObjects Business Intelligence\u00a0- multiple versions and platforms<\/li>\n\t<li>SAP Host Agent Service\u00a0- versions 7.21 and 7.22<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day\u00a0\u2013 February 2023 (PDF)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-february-2023-monthly-rollup-av23-084","alert_type":396,"serial_number":"AV23-084","subject":null,"moderation_state":"published","external_url":null},{"nid":3965,"title":"[Control systems] Siemens security advisory (AV23-085)","uuid":"eeaa6860-704a-40eb-8165-95fe670145ca","banner":null,"lang":"en","date_modified":"2023-02-14","date_modified_ts":"2023-02-14T17:05:14Z","date_created":"2023-02-14T16:51:01Z","summary":null,"body":["<article data-history-node-id=\"3965\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-085\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-085<br \/><strong>Date: <\/strong>February\u00a014, 2023<\/p>\n\n<p>On February 14, 2023, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>COMOS\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Brownfield Connectivity Client\u00a0\u2013 versions prior to 2.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-085","alert_type":398,"serial_number":"AV23-085","subject":null,"moderation_state":"published","external_url":null},{"nid":3967,"title":"Apple security advisory (AV23-086)","uuid":"ddb48fe0-060a-4815-9cf0-b1ed4a8b8302","banner":null,"lang":"en","date_modified":"2023-02-14","date_modified_ts":"2023-02-14T18:40:24Z","date_created":"2023-02-14T18:28:16Z","summary":null,"body":["<article data-history-node-id=\"3967\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-086\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-086<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 14, 2023<\/p>\n\n<p>On February 13, 2023, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\/iPadOS 16\u00a0- versions prior to 16.3.1<\/li>\n\t<li>macOS Ventura\u00a0- versions prior to 13.2.1<\/li>\n\t<li>Safari\u00a0- versions prior to 16.3.1<\/li>\n\t<li>tvOS\u00a0- versions prior to 16.3.2<\/li>\n\t<li>watchOS\u00a0- versions prior to 9.3.1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution, privilege escalation or access to sensitive information.<\/p>\n\n<p>Apple has reported that CVE-2023-23529 may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-086","alert_type":396,"serial_number":"AV23-086","subject":null,"moderation_state":"published","external_url":null},{"nid":3968,"title":"[Control systems] Weintek security advisory (AV23-087)","uuid":"9861e76e-07c9-41fd-97e7-a8a171822ceb","banner":null,"lang":"en","date_modified":"2023-02-14","date_modified_ts":"2023-02-14T21:11:12Z","date_created":"2023-02-14T21:01:14Z","summary":null,"body":["<article data-history-node-id=\"3968\" about=\"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-087\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-087<br \/><strong>Date: <\/strong>February 14, 2023<\/p>\n\n<p>On February 14, 2023, ICS-CERT published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Weintek EasyBuilder Pro\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in information disclosure and system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-045-01\">ICS Advisory (ICSA-23-045-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-087","alert_type":398,"serial_number":"AV23-087","subject":null,"moderation_state":"published","external_url":null},{"nid":3969,"title":"Microsoft security advisory \u2013 February 2023 monthly rollup (AV23-088)","uuid":"1d0f06ea-a0a3-409b-884e-ce362fa6170f","banner":null,"lang":"en","date_modified":"2023-02-14","date_modified_ts":"2023-02-14T21:23:04Z","date_created":"2023-02-14T21:05:50Z","summary":null,"body":["<article data-history-node-id=\"3969\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-february-2023-monthly-rollup-av23-088\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-088<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 14, 2023<\/p>\n\n<p>On February 14, 2023, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft 365 Apps\u00a0- multiples versions and platforms<\/li>\n\t<li>Microsoft Office\u00a0- multiple versions and platforms<\/li>\n\t<li>Microsoft .NET\u00a0- multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint\u00a0- multiple versions and platforms<\/li>\n\t<li>Microsoft SQL Server\u00a0- multiple versions and platforms<\/li>\n\t<li>Microsoft Visual Studio\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 10\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-21823, CVE-2023-21715 and CVE-2023-23376 have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Feb\">February 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-february-2023-monthly-rollup-av23-088","alert_type":396,"serial_number":"AV23-088","subject":null,"moderation_state":"published","external_url":null},{"nid":3971,"title":"Citrix security advisory (AV23-091)","uuid":"55b46657-0750-460b-a5c8-95c6ea784bac","banner":null,"lang":"en","date_modified":"2023-02-15","date_modified_ts":"2023-02-15T20:07:33Z","date_created":"2023-02-15T16:55:30Z","summary":null,"body":["<article data-history-node-id=\"3971\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av23-091\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-091<br \/><strong>Date: <\/strong>February 15, 2023<\/p>\n\n<p>On February 14, 2023, Citrix published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Virtual Apps and Desktops\u00a0\u2013 multiple versions<\/li>\n\t<li>Citrix Workspace App for Windows\u00a0\u2013 multiple versions<\/li>\n\t<li>Citrix Workspace App for Linux\u00a0\u2013 versions prior to 2302<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX477616\/citrix-virtual-apps-and-desktops-security-bulletin-for-cve202324483\">Citrix Security Advisory CTX477616<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX477617\/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485\">Citrix Security Advisory CTX477617<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX477618\/citrix-workspace-app-for-linux-security-bulletin-for-cve202324486\">Citrix Security Advisory CTX477618<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center\/search#\/All%20Products?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av23-091","alert_type":396,"serial_number":"AV23-091","subject":null,"moderation_state":"published","external_url":null},{"nid":3972,"title":"Mozilla security advisory (AV23-089)","uuid":"13b18228-3705-4d67-97fd-5109b4f4cf9e","banner":null,"lang":"en","date_modified":"2023-02-15","date_modified_ts":"2023-02-15T18:36:18Z","date_created":"2023-02-15T18:22:28Z","summary":null,"body":["<article data-history-node-id=\"3972\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-089\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-089<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 15, 2023<\/p>\n\n<p>On February 14, 2023, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0- versions prior to 102.8<\/li>\n\t<li>Firefox\u00a0- versions prior to 110<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-06\/\">Mozilla Security Advisory (MFSA 2023-06)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-05\/\">Mozilla Security Advisory (MFSA 2023-05)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-089","alert_type":396,"serial_number":"AV23-089","subject":null,"moderation_state":"published","external_url":null},{"nid":3973,"title":"Adobe security advisory (AV23-090)","uuid":"4adc1fb9-65cd-4b0a-923b-b8d49739c08e","banner":null,"lang":"en","date_modified":"2023-02-15","date_modified_ts":"2023-02-15T19:33:10Z","date_created":"2023-02-15T18:42:00Z","summary":null,"body":["<article data-history-node-id=\"3973\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-090\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-090<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 15, 2023<\/p>\n\n<p>On February 14, 2023, Adobe published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe After Effects\u00a0- multiple versions<\/li>\n\t<li>Adobe Animate 2022\u00a0- version 22.0.8 and prior<\/li>\n\t<li>Adobe Animate 2023\u00a0- version 23.0.0 and prior<\/li>\n\t<li>Adobe Bridge\u00a0- multiple versions<\/li>\n\t<li>Adobe Connect\u00a0- multiple versions<\/li>\n\t<li>Adobe FrameMaker\u00a0- 2020 Release Update 4 and prior<\/li>\n\t<li>Adobe FrameMaker\u00a0- 2022 Release and prior<\/li>\n\t<li>Adobe InDesign\u00a0- multiple versions<\/li>\n\t<li>Adobe Photoshop 2022\u00a0- version 23.5.3 and prior<\/li>\n\t<li>Adobe Photoshop 2023\u00a0- version 24.1 and prior<\/li>\n\t<li>Adobe Premiere Rush\u00a0- version 2.6 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0- version 1.3.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/security-bulletin.html\">Adobe Security Advisories <\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-090","alert_type":396,"serial_number":"AV23-090","subject":null,"moderation_state":"published","external_url":null},{"nid":3975,"title":"Cisco security advisory (AV23-093)","uuid":"7d8ebbc1-8489-42f2-a5cc-799a1a0a7be2","banner":null,"lang":"en","date_modified":"2023-02-15","date_modified_ts":"2023-02-15T21:19:41Z","date_created":"2023-02-15T21:04:24Z","summary":null,"body":["<article data-history-node-id=\"3975\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-093\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-093<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 15, 2023<\/p>\n\n<p>On February 15, 2023, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Secure Endpoint\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Secure Endpoint Private Cloud\u00a0\u2013 versions prior to 3.6.0<\/li>\n\t<li>Cisco Secure Web Appliance\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-clamav-q8DThCy\">Cisco Security Advisory (cisco-sa-clamav-q8DThCy)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-093","alert_type":396,"serial_number":"AV23-093","subject":null,"moderation_state":"published","external_url":null},{"nid":3974,"title":"Intel security advisory (AV23-092)\u00ad\u00ad\u00ad\u00ad\u00ad\u00ad","uuid":"1a3e104a-93c0-4043-a83c-db7cb1cb568f","banner":null,"lang":"en","date_modified":"2023-02-15","date_modified_ts":"2023-02-15T21:15:59Z","date_created":"2023-02-15T21:08:53Z","summary":null,"body":["<article data-history-node-id=\"3974\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av23-092\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-092<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 15, 2023<\/p>\n\n<p>On February 14, 2023, Intel published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Intel Integrated BMC firmware\u00a0\u2013 multiple versions<\/li>\n\t<li>Intel OpenBMC firmware\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00737.html\">Intel Security Advisory (INTEL-SA-737)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av23-092","alert_type":396,"serial_number":"AV23-092","subject":null,"moderation_state":"published","external_url":null},{"nid":3976,"title":"Apache security advisory (AV23-094)","uuid":"00ff2674-4e92-4a47-8fe1-e8daef9fe57a","banner":null,"lang":"en","date_modified":"2023-02-16","date_modified_ts":"2023-02-16T19:25:45Z","date_created":"2023-02-16T19:08:02Z","summary":null,"body":["<article data-history-node-id=\"3976\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av23-094\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-094<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 16, 2023<\/p>\n\n<p>On February 8, 2023, Apache published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Apache Kafka\u00a0- versions prior to 3.4.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kafka.apache.org\/cve-list\">Apache Kafka Vulnerabilities<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av23-094","alert_type":396,"serial_number":"AV23-094","subject":null,"moderation_state":"published","external_url":null},{"nid":3977,"title":"HPE security advisory (AV23-095)","uuid":"3897182a-77c8-46d7-99e5-eafc70ce094f","banner":null,"lang":"en","date_modified":"2023-02-16","date_modified_ts":"2023-02-16T20:32:33Z","date_created":"2023-02-16T20:22:22Z","summary":null,"body":["<article data-history-node-id=\"3977\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-095\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-095<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 16, 2023<\/p>\n\n<p>On February 14 and 15, 2023, HPE published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HPE ProLiant DX560 Gen10 server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant DX360 Gen10 Plus server - multiple versions<\/li>\n\t<li>HPE ProLiant DX380 Gen10 Plus server - multiple versions<\/li>\n\t<li>HPE ProLiant BL460c Gen10 Server Blade - multiple versions<\/li>\n\t<li>HPE ProLiant DL20 Gen10 Server - versions prior to 2.68_01-12-2023<\/li>\n\t<li>HPE ProLiant DL160 Gen10 Server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant DL180 Gen10 Server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant DL360 Gen10 Server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant DL380 Gen10 Server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant DL560 Gen10 Server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant ML110 Gen10 Server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant ML30 Gen10 Server - versions prior to 2.68_01-12-2023<\/li>\n\t<li>HPE ProLiant ML350 Gen10 Server - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE ProLiant DL360 Gen10 Plus server - multiple versions<\/li>\n\t<li>HPE ProLiant DL380 Gen10 Plus server - multiple versions<\/li>\n\t<li>HPE ProLiant DL110 Gen10 Plus Telco server - multiple versions<\/li>\n\t<li>HPE ProLiant ML30 Gen10 Plus server - versions prior to SPS_E3_06.00.03.300.0 - CVE-2022-36794<\/li>\n\t<li>HPE ProLiant DL20 Gen10 Plus server - multiple versions<\/li>\n\t<li>HPE ProLiant MicroServer Gen10 Plus v2 - multiple versions<\/li>\n\t<li>HPE StoreEasy 1660 Storage - multiple versions<\/li>\n\t<li>HPE StoreEasy 1860 Storage - multiple versions<\/li>\n\t<li>HPE StoreEasy 1460 Storage - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE StoreEasy 1560 Storage - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE StoreEasy 1660 Expanded Storage - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE StoreEasy 1660 Performance Storage - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE StoreEasy 1860 Performance Storage - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE Storage File Controller - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE Storage Performance File Controller - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE Superdome Flex 280 Server -Prior to 1.40.60<\/li>\n\t<li>HPE Synergy 480 Gen10 Compute Module - versions prior to 2.76_02-09-2023<\/li>\n\t<li>HPE Synergy 480 Gen10 Plus Compute Module - multiple versions<\/li>\n\t<li>HPE Synergy 660 Gen10 Compute Module - versions prior to 2.76_02-09-2023<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-095","alert_type":396,"serial_number":"AV23-095","subject":null,"moderation_state":"published","external_url":null},{"nid":3978,"title":"[Control systems] Schneider Electric security advisory (AV23-096) ","uuid":"c3d5317e-b003-4b76-8dbb-72483bd75d2d","banner":null,"lang":"en","date_modified":"2023-02-16","date_modified_ts":"2023-02-16T20:51:18Z","date_created":"2023-02-16T20:45:53Z","summary":null,"body":["<article data-history-node-id=\"3978\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-096\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-096<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 16, 2023<\/p>\n\n<p>On February 14, 2023, Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>ClearSCADA\u00a0\u2013 all versions<\/li>\n\t<li>EcoStruxure Geo SCADA Expert 2019, 2020 and 2021\u00a0\u2013 versions prior to October 2022<\/li>\n\t<li>Merten KNX Devices\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>StruxureWare Data Center Expert\u00a0\u2013 versions 7.9.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp \">Schneider Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-096","alert_type":398,"serial_number":"AV23-096","subject":null,"moderation_state":"published","external_url":null},{"nid":3979,"title":"Atlassian security advisory (AV23-099)","uuid":"16d70bbd-dfe1-4c5d-829e-9aa896c48709","banner":null,"lang":"en","date_modified":"2023-02-17","date_modified_ts":"2023-02-17T18:52:02Z","date_created":"2023-02-17T15:50:14Z","summary":null,"body":["<article data-history-node-id=\"3979\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-099\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-099<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 17, 2023<\/p>\n\n<p>On February 15, 2023, Atlassian published a Security Advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Server and Data Center\u00a0- multiple versions<\/li>\n\t<li>Bitbucket Server and Data Center\u00a0- multiple versions<\/li>\n\t<li>Crucible\u00a0- multiple versions<\/li>\n\t<li>Fisheye\u00a0- multiple versions<\/li>\n\t<li>Sourcetree\u00a0-multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/multiple-products-security-advisory-git-buffer-overflow-cve-2022-41903-cve-2022-23521-1189805967.html  \">Atlassian Security Advisory (Multiple-Products-Advisory)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-099","alert_type":396,"serial_number":"AV23-099","subject":null,"moderation_state":"published","external_url":null},{"nid":3980,"title":"SolarWinds security advisory (AV23-097)","uuid":"7701210f-15e4-4195-bf59-691e17c966a1","banner":null,"lang":"en","date_modified":"2023-02-17","date_modified_ts":"2023-02-17T16:52:28Z","date_created":"2023-02-17T16:43:30Z","summary":null,"body":["<article data-history-node-id=\"3980\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av23-097\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-097<br \/><strong>Date: <\/strong>February 17, 2023<\/p>\n\n<p>On February 15, 2023, SolarWinds published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SolarWinds Platform\u00a0\u2013 versions prior to 2023.1<\/li>\n\t<li>Server &amp; Application Monitor\u00a0\u2013 version 2022.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av23-097","alert_type":396,"serial_number":"AV23-097","subject":null,"moderation_state":"published","external_url":null},{"nid":3981,"title":"Fortinet security advisory (AV23-098)","uuid":"14b131e7-1192-4dd8-9a6f-6d936aa1ffda","banner":null,"lang":"en","date_modified":"2023-02-17","date_modified_ts":"2023-02-17T17:02:52Z","date_created":"2023-02-17T16:54:11Z","summary":null,"body":["<article data-history-node-id=\"3981\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-098\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-098<br \/><strong>Date: <\/strong>February 17, 2023<\/p>\n\n<p>On February 16, 2023, Fortinet published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiNAC\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiWeb\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-300\">Fortinet PSIRT Advisory (FG-IR-22-300)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-21-186\">Fortinet PSIRT Advisory (FG-IR-21-186)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-098","alert_type":396,"serial_number":"AV23-098","subject":null,"moderation_state":"published","external_url":null},{"nid":3984,"title":"B&R security advisory (AV23-100)","uuid":"b98fb211-c549-409b-aa46-230817d88b3e","banner":null,"lang":"en","date_modified":"2023-02-20","date_modified_ts":"2023-02-20T16:19:05Z","date_created":"2023-02-20T15:37:38Z","summary":null,"body":["<article data-history-node-id=\"3984\" about=\"\/en\/alerts-advisories\/br-security-advisory-av23-100\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-100\n  <br \/><strong>Date: <\/strong>February\u00a020, 2023\n<\/p>\n<p>Between February\u00a014 and February\u00a015, 2023, B&amp;R published Security Advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>B&amp;R Automation Runtime (AR)\u00a0- multiple versions<\/li>\n  <li>APC 3100 and 220\u00a0- multiple versions<\/li>\n  <li>PPC 3100, 2200, 1200 and 80\u00a0- multiple versions<\/li>\n  <li>MPC 3100\u00a0- versions prior to 1.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1675607299099-en-original-1.0.pdf\">B&amp;R Security Advisory (Automation Runtime)<\/a> (PDF)<\/li>\n  <li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1675931547567-en-original-1.0.pdf\">B&amp;R Security Advisory (Insyde UEFI Boot Issues)<\/a> (PDF)<\/li>\n  <li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/ \">B&amp;R Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/br-security-advisory-av23-100","alert_type":396,"serial_number":"AV23-100","subject":null,"moderation_state":"published","external_url":null},{"nid":3985,"title":"Ubuntu security advisory (AV23-101)","uuid":"a2341c6d-94b2-49c6-95d6-ca0c91f6952a","banner":null,"lang":"en","date_modified":"2023-02-20","date_modified_ts":"2023-02-20T17:00:13Z","date_created":"2023-02-20T15:37:40Z","summary":null,"body":["<article data-history-node-id=\"3985\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-101\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-101<br \/><strong>Date: <\/strong>February\u00a020, 2023<\/p>\n\n<p>Between February\u00a013 and February\u00a019, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-101","alert_type":396,"serial_number":"AV23-101","subject":null,"moderation_state":"published","external_url":null},{"nid":3983,"title":"Dell security advisory (AV23-102)","uuid":"81a4449b-3a9f-49a5-8552-6b2bd5ce0105","banner":null,"lang":"en","date_modified":"2023-02-20","date_modified_ts":"2023-02-20T18:34:39Z","date_created":"2023-02-20T15:54:01Z","summary":null,"body":["<article data-history-node-id=\"3983\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-102\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-102<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 20, 2023<\/p>\n\n<p>Between February 13 and February 19, 2023, Dell published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cloud Tiering Appliance\u00a0- multiple versions and platforms<\/li>\n\t<li>Dell Data Protection Central\u00a0- multiple versions<\/li>\n\t<li>Dell Edge Gateway 5200\u00a0- BIOS versions prior to 1.06.10<\/li>\n\t<li>Dell Secure Connect Gateway\u00a0- versions 5.12.00.10 and 5.14.0.12<\/li>\n\t<li>Dell Secure Connect Gateway Policy Manager\u00a0- version 5.14.00.00<\/li>\n\t<li>PowerEdge\u00a0- multiple versions and platforms<\/li>\n\t<li>PowerProtect DP Series Appliance\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-102","alert_type":396,"serial_number":"AV23-102","subject":null,"moderation_state":"published","external_url":null},{"nid":3986,"title":"IBM security advisory (AV23-103)","uuid":"802343cc-8ec0-483c-8eea-5a7066e5cca7","banner":null,"lang":"en","date_modified":"2023-02-20","date_modified_ts":"2023-02-20T18:36:56Z","date_created":"2023-02-20T18:17:09Z","summary":null,"body":["<article data-history-node-id=\"3986\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-103\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-103<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 20, 2023<\/p>\n\n<p>Between February 13 and February 19, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Aspera Faspex\u00a0- version 4.4.2 PL2<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Security Services\u00a0- versions 2.2 and 2.3<\/li>\n<\/ul><p>The Cyber Centre is aware of reports that CVE-2022-47986 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6952319\">IBM Security Bulletin (Aspera Faspex)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6956311\">IBM Security Bulletin (Cloud Pak)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-103","alert_type":396,"serial_number":"AV23-103","subject":null,"moderation_state":"published","external_url":null},{"nid":3988,"title":"HPE security advisory (AV23-104)","uuid":"7579776c-434b-4453-af55-556f64d1520c","banner":null,"lang":"en","date_modified":"2023-02-21","date_modified_ts":"2023-02-21T19:00:27Z","date_created":"2023-02-21T18:54:39Z","summary":null,"body":["<article data-history-node-id=\"3988\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-104\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-104<br \/><strong>Date: <\/strong>February\u00a021, 2023<\/p>\n\n<p>On February\u00a017, 2023, HPE published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE OneView for VMware vCenter\u00a0\u2013 versions 9.6, 10.0, 10.1, 10.2, 10.3, 10.4, 11.0, 11.1 and 11.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04449en_us\">HPE Security Bulletin (HPE OneView)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-104","alert_type":396,"serial_number":"AV23-104","subject":null,"moderation_state":"published","external_url":null},{"nid":3989,"title":"VMware security advisory (AV23-105)","uuid":"8a86a524-cd03-4302-b512-dc2c187bd113","banner":null,"lang":"en","date_modified":"2023-02-21","date_modified_ts":"2023-02-21T19:19:40Z","date_created":"2023-02-21T18:55:18Z","summary":null,"body":["<article data-history-node-id=\"3989\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-105\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-105<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 21, 2023<\/p>\n\n<p>On February 21, 2023, VMware published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Carbon Black App Control\u00a0\u2013 versions 8.7.x, 8.8.x et 8.9.x.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0004.html\">VMware Security Advisory (VMSA-2023-0004) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-105","alert_type":396,"serial_number":"AV23-105","subject":null,"moderation_state":"published","external_url":null},{"nid":3990,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-106)","uuid":"074ff133-2a8a-4cb9-98fd-c1f1bfab1507","banner":null,"lang":"en","date_modified":"2023-02-21","date_modified_ts":"2023-02-21T20:57:34Z","date_created":"2023-02-21T20:49:04Z","summary":null,"body":["<article data-history-node-id=\"3990\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-106\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-106<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a021, 2023<\/p>\n\n<p>On February\u00a021, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MELSOFT iQ AppPortal (SW1DND-IQAPL-M)\u00a0\u2013 versions v1.00A to 1.29F<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/uscert\/ics\/advisories\/icsa-23-052-01\">ICS Advisory (ICSA-23-052-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-106","alert_type":398,"serial_number":"AV23-106","subject":null,"moderation_state":"published","external_url":null},{"nid":3991,"title":"Red Hat security advisory (AV23-107)","uuid":"87f0adf2-8b3a-4740-930c-ae6a243a98f3","banner":null,"lang":"en","date_modified":"2023-02-22","date_modified_ts":"2023-02-22T16:09:18Z","date_created":"2023-02-22T15:55:00Z","summary":null,"body":["<article data-history-node-id=\"3991\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-107\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-107<br \/><strong>Date: <\/strong>February\u00a022, 2023<\/p>\n\n<p>On February\u00a021, 2023, Red Hat published Security Advisories to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories?q=&amp;p=2&amp;sort=portal_publication_date%20desc&amp;rows=10&amp;portal_advisory_type=Security%20Advisory&amp;documentKind=PortalProduct\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-107","alert_type":396,"serial_number":"AV23-107","subject":null,"moderation_state":"published","external_url":null},{"nid":3992,"title":"HPE security advisory (AV23-108)","uuid":"204d7ccb-5414-4840-9346-1d838bef7dbb","banner":null,"lang":"en","date_modified":"2023-02-22","date_modified_ts":"2023-02-22T19:05:50Z","date_created":"2023-02-22T18:56:01Z","summary":null,"body":["<article data-history-node-id=\"3992\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-108\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-108<br \/><strong>Date: <\/strong>February\u00a022, 2023<\/p>\n\n<p>On February\u00a021, 2023, HPE published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Serviceguard for Linux\u00a0\u2013 versions prior to A.12.80.05 and A.15.00.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbmu04452en_us\">HPE Security Bulletin (HPE Serviceguard)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-108","alert_type":396,"serial_number":"AV23-108","subject":null,"moderation_state":"published","external_url":null},{"nid":3993,"title":"Cisco security advisory (AV23-109)","uuid":"30fa1caf-9c30-4f97-90c2-a74e4533fad6","banner":null,"lang":"en","date_modified":"2023-02-22","date_modified_ts":"2023-02-22T19:24:45Z","date_created":"2023-02-22T19:16:34Z","summary":null,"body":["<article data-history-node-id=\"3993\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-109\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-109<br \/><strong>Date: <\/strong>February\u00a022, 2023<\/p>\n\n<p>On February\u00a022, 2023, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco APIC\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Cloud Network Controller\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Nexus 9000 Series Fabric Switches\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-capic-csrfv-DMx6KSwV\">Cisco Security Advisory (cisco-sa-capic-csrfv-DMx6KSwV)<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-aci-lldp-dos-ySCNZOpX\">Cisco Security Advisory (cisco-sa-aci-lldp-dos-ySCNZOpX)<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-109","alert_type":396,"serial_number":"AV23-109","subject":null,"moderation_state":"published","external_url":null},{"nid":3994,"title":"Trellix security advisory (AV23-110)","uuid":"38493041-64fa-4c1e-946f-b7979b0dbe08","banner":null,"lang":"en","date_modified":"2023-02-22","date_modified_ts":"2023-02-22T20:57:08Z","date_created":"2023-02-22T20:49:45Z","summary":null,"body":["<article data-history-node-id=\"3994\" about=\"\/en\/alerts-advisories\/trellix-security-advisory-av23-110\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-110<br \/><strong>Date: <\/strong>February\u00a022, 2023<\/p>\n\n<p>On February\u00a022, 2023, Trellix published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Trellix Agent\u00a0\u2013 all versions<\/li>\n\t<li>Trellix Intelligent Sandbox\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kcm.trellix.com\/corporate\/index?page=content&amp;id=SB10395&amp;actp=null&amp;viewlocale=en_US&amp;showDraft=false&amp;platinum_status=false&amp;locale=en_US\">Trellix Security Advisory (OpenSSL)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportm.trellix.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter\">Trellix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trellix-security-advisory-av23-110","alert_type":396,"serial_number":"AV23-110","subject":null,"moderation_state":"published","external_url":null},{"nid":3995,"title":"Google Chrome security advisory (AV23-111)","uuid":"505baab5-d00e-43b5-9eed-fe21a6fe2a2a","banner":null,"lang":"en","date_modified":"2023-02-23","date_modified_ts":"2023-02-23T14:36:31Z","date_created":"2023-02-23T14:31:59Z","summary":null,"body":["<article data-history-node-id=\"3995\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-111\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-111<br \/><strong>Date: <\/strong>February\u00a023, 2023<\/p>\n\n<p>On February\u00a022, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 110.0.5481.177 (Mac and Linux) and 110.0.5481.177\/.178 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/02\/stable-channel-desktop-update_22.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-111","alert_type":396,"serial_number":"AV23-111","subject":null,"moderation_state":"published","external_url":null},{"nid":3996,"title":"[Control systems] PTC Security Advisory (AV23-112)","uuid":"2397c6cc-1f12-4129-807a-17d435b266fa","banner":null,"lang":"en","date_modified":"2023-02-23","date_modified_ts":"2023-02-23T19:39:30Z","date_created":"2023-02-23T19:04:17Z","summary":null,"body":["<article data-history-node-id=\"3996\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-112\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-112<br \/><strong>Date: <\/strong>February\u00a023, 2023<\/p>\n\n<p>On February\u00a023, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ThingWorx Edge C-SDK\u00a0\u2013 version 2.2.12.1052 and prior<\/li>\n\t<li>.NET-SDK\u00a0\u2013 version 5.8.4.971 and prior<\/li>\n\t<li>ThingWorx Edge MicroServer (EMS)\u00a0\u2013 version 5.4.10.0 and prior<\/li>\n\t<li>Kepware KEPServerEX\u00a0\u2013 version 6.12 and prior<\/li>\n\t<li>ThingWorx Kepware Server\u00a0\u2013 version 6.12 and prior<\/li>\n\t<li>ThingWorx Industrial Connectivity\u00a0\u2013 all versions<\/li>\n\t<li>ThingWorx Kepware Edge\u00a0\u2013 version 1.5 and prior<\/li>\n\t<li>Rockwell Automation KEPServer Enterprise\u00a0\u2013 version 6.12 and prior<\/li>\n\t<li>GE Digital Industrial Gateway Server\u00a0\u2013 version 7.612 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in denial of service and remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/us-cert.cisa.gov\/ics\/advisories\/icsa-23-054-01\">ICS Advisory (ICSA-23-054-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-112","alert_type":398,"serial_number":"AV23-112","subject":null,"moderation_state":"published","external_url":null},{"nid":3998,"title":"Risk of malicious cyber activity against Ukraine-aligned nations","uuid":"b87a4cfc-4266-462e-932d-44b5eb14a2bd","banner":null,"lang":"en","date_modified":"2023-02-24","date_modified_ts":"2023-02-24T19:17:22Z","date_created":"2023-02-24T19:16:05Z","summary":null,"body":["<article data-history-node-id=\"3998\" about=\"\/en\/alerts-advisories\/risk-malicious-cyber-activity-against-ukraine-aligned-nations\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-001<br \/><strong>Date:\u00a0<\/strong>February 24, 2023<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is urging Canadian organizations to be vigilant and prepared for potential malicious cyber activity following the one-year mark of Russia\u2019s war on Ukraine. The Cyber Centre would like to specifically warn Canadian organizations and critical infrastructure operators to be prepared for the possible disruption, defacement, and attempted exploitation of Canadian network assets by cyber threat actors aligned with Russian interests.<\/p>\n\n<p>On February 23, 2023, CISA published an Alert<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> urging organizations and individuals to increase their cyber vigilance and have provided their assessment that Ukraine-aligned countries may experience disruptive and defacement attacks against websites on February 24, 2023, the anniversary of the Russian invasion of Ukraine. CISA has provided several recommendations for their constituents of which the Cyber Centre also recommends the following:<\/p>\n\n<ul><li>Increasing organizational vigilance<\/li>\n\t<li>Implementing cybersecurity best practices<\/li>\n\t<li>Increasing resilience and preparing for rapid response<\/li>\n\t<li>Lowering the threshold for threat and information sharing<\/li>\n<\/ul><p>The Cyber Centre is aware that Russia-aligned actors have conducted Distributed Denial of Service (DDoS) campaigns towards Ukraine-aligned nations and recommends the following guidance to better protect Canadian organizations.<\/p>\n\n<p><a href=\"\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\">Protecting your organization against denial of service attacks - ITSAP.80.100<\/a><\/p>\n\n<p>The Cyber Centre encourages Canadian organizations to review their security posture and to ensure security controls are effective and in place. See recommended actions for further guidance.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Review the following joint publications which may help organizations detect and mitigate threats outlined in this report. <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/li>\n\t<li>Review perimeter systems to determine if related activity has occurred or how to better prepare for potential malicious activity.<\/li>\n\t<li>Report any cyber incidents to the Cyber Centre which may be associated with threats outlined in this report.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><!-- ENDNOTES SECTION --><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/02\/23\/cisa-urges-increased-vigilance-one-year-after-russias-invasion-ukraine\">CISA Urges Increased Vigilance One Year After Russia\u2019s Invasion of Ukraine<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/news-events\/joint-cyber-security-advisory-russian-state-sponsored-and-criminal-cyber-threats-critical\">Joint cyber security advisory on Russian state-sponsored and criminal cyber threats to critical infrastructure<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/news-events\/joint-cybersecurity-advisory\">(AR20-245A) Technical Approaches to Uncovering and Remediating Malicious Activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">CCCS Top 10 IT security actions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/cyber-security-guidance-heightened-threat-levels-itsap10101\">Cyber security guidance for heightened threat levels - ITSAP.10.101<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/cyber-security-precautions-russian-invasion-ukraine\">Cyber security precautions \u2013 Russian invasion of Ukraine<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/cyber-threat-bulletin-cyber-threat-activity-related-russian-invasion-ukraine \">Cyber threat bulletin: Cyber Centre reminds Canadian critical infrastructure operators<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/risk-malicious-cyber-activity-against-ukraine-aligned-nations","alert_type":397,"serial_number":"AL23-001","subject":null,"moderation_state":"published","external_url":null},{"nid":4001,"title":"Ubuntu security advisory (AV23-113)","uuid":"c78f75c1-eff6-486a-9217-108e682d34df","banner":null,"lang":"en","date_modified":"2023-02-27","date_modified_ts":"2023-02-27T18:27:45Z","date_created":"2023-02-27T18:22:59Z","summary":null,"body":["<article data-history-node-id=\"4001\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-113\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-113<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 27, 2023<\/p>\n\n<p>Between February 20 and 26, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-113","alert_type":396,"serial_number":"AV23-113","subject":null,"moderation_state":"published","external_url":null},{"nid":4003,"title":"[Control systems] B&R security advisory (AV23-114)","uuid":"24ba81d1-c109-4177-b584-673775697fa4","banner":null,"lang":"en","date_modified":"2023-02-28","date_modified_ts":"2023-02-28T15:28:58Z","date_created":"2023-02-28T15:09:52Z","summary":null,"body":["<article data-history-node-id=\"4003\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av23-114\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-114<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 28, 2023<\/p>\n\n<p>On February 27, 2023, B&amp;R published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mobile Panel 7100\u00a0- multiple versions and models<\/li>\n\t<li>Power Panel\u00a0- multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1676909111782-en-original-1.0.pdf\">B&amp;R Security Advisory (S A22P 011)(PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av23-114","alert_type":398,"serial_number":"AV23-114","subject":null,"moderation_state":"published","external_url":null},{"nid":4004,"title":"[Control systems] ABB security advisory (AV23-115)","uuid":"996521ef-d69b-49c5-8863-2b6fbdfe1d96","banner":null,"lang":"en","date_modified":"2023-02-28","date_modified_ts":"2023-02-28T16:51:04Z","date_created":"2023-02-28T15:38:10Z","summary":null,"body":["<article data-history-node-id=\"4004\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-115\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-115<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 28, 2023<\/p>\n\n<p>On February 27, 2023, ABB published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>AC 800PEC\u00a0\u2013 multiple versions and models<\/li>\n\t<li>DT2S\u00a0\u2013 version 1.0.0.2 and prior<\/li>\n\t<li>SYNCHROTACT\u00a0\u2013 multiple versions and models<\/li>\n\t<li>UNIREC for Marines\u00a0\u2013 version 5.0.08 and prior<\/li>\n\t<li>UNITROL 6000\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3BHS910120&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Security Advisory (3BH S9101 20) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-115","alert_type":398,"serial_number":"AV23-115","subject":null,"moderation_state":"published","external_url":null},{"nid":4005,"title":"Microsoft Edge security advisory (AV23-116)","uuid":"92132202-bea3-4215-97e9-d9874482417a","banner":null,"lang":"en","date_modified":"2023-02-28","date_modified_ts":"2023-02-28T18:50:23Z","date_created":"2023-02-28T18:43:36Z","summary":null,"body":["<article data-history-node-id=\"4005\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-116\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-116<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 28, 2023<\/p>\n\n<p>On February 25, 2023, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 110.0.1587.56<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-25-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-116","alert_type":396,"serial_number":"AV23-116","subject":null,"moderation_state":"published","external_url":null},{"nid":4009,"title":"[Control systems] Hitachi Energy security advisory (AV23-117)","uuid":"b951e379-28e7-4836-bc38-eba98def13e0","banner":null,"lang":"en","date_modified":"2023-02-28","date_modified_ts":"2023-02-28T21:48:17Z","date_created":"2023-02-28T21:44:20Z","summary":null,"body":["<article data-history-node-id=\"4009\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-117\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-117<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 28, 2023<\/p>\n\n<p>On February 28, 2023, CISA published ICS Advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Gateway Station\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-059-01\">ICS Advisory (ICSA-23-059-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-059-02\">ICS Advisory (ICSA-23-059-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-117","alert_type":398,"serial_number":"AV23-117","subject":null,"moderation_state":"published","external_url":null},{"nid":4010,"title":"IBM security advisory (AV23-118)","uuid":"5a9b470e-e759-4427-adfc-9799e2b579cf","banner":null,"lang":"en","date_modified":"2023-03-02","date_modified_ts":"2023-03-02T16:08:37Z","date_created":"2023-03-01T16:17:55Z","summary":null,"body":["<article data-history-node-id=\"4010\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-118\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-118<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 2, 2023<\/p>\n\n<p>Between February 20 and February 26, 2023, IBM published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-118","alert_type":396,"serial_number":"AV23-118","subject":null,"moderation_state":"published","external_url":null},{"nid":4012,"title":"HPE security advisory (AV23-119)","uuid":"d481cda0-d686-4b58-86d3-a79b453720c8","banner":null,"lang":"en","date_modified":"2023-03-02","date_modified_ts":"2023-03-02T16:11:24Z","date_created":"2023-03-01T18:55:56Z","summary":null,"body":["<article data-history-node-id=\"4012\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-119\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-119<br \/><strong>Date: <\/strong>March\u00a02, 2023<\/p>\n\n<p>Between February\u00a027 and 28, 2023, HPE published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ArubaOS\u00a0\u2013 multiple versions<\/li>\n\t<li>ArubaOS SD-WAN\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Edgeline e920, e920d and e920t Server Blade\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04454en_us\">HPE Security Bulletin (ArubaOS hpesbhf04410)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04410en_us\">HPE Security Bulletin (HPE Edgeline hpesbhf04410)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04412en_us\">HPE Security Bulletin (HPE Edgeline hpesbhf04412)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-119","alert_type":396,"serial_number":"AV23-119","subject":null,"moderation_state":"published","external_url":null},{"nid":4013,"title":"Cisco Security Advisory (AV23-120)","uuid":"d7b8e0ea-44f1-4f44-9636-aa7b5ec3efe5","banner":null,"lang":"en","date_modified":"2023-03-02","date_modified_ts":"2023-03-02T16:12:52Z","date_created":"2023-03-01T19:40:02Z","summary":null,"body":["<article data-history-node-id=\"4013\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-120\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-120<br \/><strong>Date: <\/strong>March\u00a02, 2023<\/p>\n\n<p>On March\u00a01, 2023, Cisco published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>IP Phone 6800 Series with Multiplatform Firmware\u00a0- multiple versions<\/li>\n\t<li>IP Phone 7800 Series with Multiplatform Firmware\u00a0- multiple versions<\/li>\n\t<li>IP Phone 8800 Series with Multiplatform Firmware\u00a0- multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to injection of arbitrary operating system commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ip-phone-cmd-inj-KMFynVcP\">Cisco IP Phone 6800, 7800, 7900, and 8800 Series Web UI Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-120","alert_type":396,"serial_number":"AV23-120","subject":null,"moderation_state":"published","external_url":null},{"nid":4014,"title":"[Control systems] ABB security advisory (AV23-121)","uuid":"3c7e684c-0c51-4c58-a5e7-3b8094a9c919","banner":null,"lang":"en","date_modified":"2023-03-02","date_modified_ts":"2023-03-02T18:18:26Z","date_created":"2023-03-02T18:11:54Z","summary":null,"body":["<article data-history-node-id=\"4014\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-121\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-121<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 2, 2023<\/p>\n\n<p>On March 1, 2023, ABB published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB Ability Symphony Plus S+ Operations\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA006722&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Security Advisory (7PAA006722) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-121","alert_type":398,"serial_number":"AV23-121","subject":null,"moderation_state":"published","external_url":null},{"nid":4015,"title":"[Control systems] Rittal security advisory (AV23-124)","uuid":"20298044-83f8-446b-b131-781dc1280755","banner":null,"lang":"en","date_modified":"2023-03-02","date_modified_ts":"2023-03-02T21:04:11Z","date_created":"2023-03-02T20:09:58Z","summary":null,"body":["<article data-history-node-id=\"4015\" about=\"\/en\/alerts-advisories\/control-systems-rittal-security-advisory-av23-124\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-124<br \/><strong>Date: <\/strong>March\u00a02, 2023<\/p>\n\n<p>On March\u00a02, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>CMC III<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-061-03\">ICS Advisory (ICSA-23-061-03)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rittal-security-advisory-av23-124","alert_type":398,"serial_number":"AV23-124","subject":null,"moderation_state":"published","external_url":null},{"nid":4016,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-122)","uuid":"8e75accc-21de-41de-8b4b-7e2544f22c8e","banner":null,"lang":"en","date_modified":"2023-03-02","date_modified_ts":"2023-03-02T20:30:29Z","date_created":"2023-03-02T20:13:36Z","summary":null,"body":["<article data-history-node-id=\"4016\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-122\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-122<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 2, 2023<\/p>\n\n<p>On March 2, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC iQ-F FX5U(C) CPU modules\u00a0- all models and all versions<\/li>\n\t<li>MELSEC iQ-F FX5UJ CPU modules\u00a0- all models and all versions<\/li>\n\t<li>MELSEC iQ-F FX5S CPU modules\u00a0- all models and all versions<\/li>\n\t<li>MELSEC iQ-F FX5-ENET\u00a0- all versions<\/li>\n\t<li>MELSEC iQ-F FX5-ENET\/IP\u00a0- all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-061-01\">ICS Advisory (ICSA-23-061-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-122","alert_type":398,"serial_number":"AV23-122","subject":null,"moderation_state":"published","external_url":null},{"nid":4017,"title":"[Control systems] Baicells security advisory (AV23-123)","uuid":"58d41f0b-ebb1-4de9-9c64-ffacdbcb8b9c","banner":null,"lang":"en","date_modified":"2023-03-02","date_modified_ts":"2023-03-02T20:59:08Z","date_created":"2023-03-02T20:41:41Z","summary":null,"body":["<article data-history-node-id=\"4017\" about=\"\/en\/alerts-advisories\/control-systems-baicells-security-advisory-av23-123\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-123<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 2, 2023<\/p>\n\n<p>On March 2, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Nova 436Q<\/li>\n\t<li>Nova 430E<\/li>\n\t<li>Nova 430I<\/li>\n\t<li>Neutrino 430<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-061-02\">ICS Advisory (ICSA-23-061-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-baicells-security-advisory-av23-123","alert_type":398,"serial_number":"AV23-123","subject":null,"moderation_state":"published","external_url":null},{"nid":4020,"title":"GitLab security advisory (AV23-125)","uuid":"9cdec0d1-71ca-474f-ae43-b4fd3d1e98d2","banner":null,"lang":"en","date_modified":"2023-03-03","date_modified_ts":"2023-03-03T20:56:48Z","date_created":"2023-03-03T20:50:06Z","summary":null,"body":["<article data-history-node-id=\"4020\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-125\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-125<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 3, 2023<\/p>\n\n<p>On March\u00a02,\u00a02023, GitLab published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 15.9.2, 15.8.4 and 15.7.8<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 15.9.2, 15.8.4 and 15.7.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/03\/02\/security-release-gitlab-15-9-2-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-125","alert_type":396,"serial_number":"AV23-125","subject":null,"moderation_state":"published","external_url":null},{"nid":4021,"title":"HPE security advisory (AV23-126)","uuid":"f65babb9-d7f8-4681-bd40-c9db4c7fdab3","banner":null,"lang":"en","date_modified":"2023-03-03","date_modified_ts":"2023-03-03T21:50:56Z","date_created":"2023-03-03T21:24:23Z","summary":null,"body":["<article data-history-node-id=\"4021\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-126\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-126<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 6, 2023<\/p>\n\n<p>Between March 1 and 2, 2023, HPE published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HPE Apollo 2000 and 4200 Gen10 Plus System\u00a0- versions prior to SPS 04.04.04.300<\/li>\n\t<li>HPE ProLiant\u00a0- multiple versions and models<\/li>\n\t<li>HPE Edgeline e920, e920d and e920t Server Blade\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04441en_us\">HPE Security Bulletin (hpesbhf04441)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04409en_us\">HPE Security Bulletin (hpesbhf04409)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-126","alert_type":396,"serial_number":"AV23-126","subject":null,"moderation_state":"published","external_url":null},{"nid":4022,"title":"IBM security advisory (AV23-127)","uuid":"e27f4f0f-cd0b-4f51-b281-98119e4ca729","banner":null,"lang":"en","date_modified":"2023-03-06","date_modified_ts":"2023-03-06T16:47:23Z","date_created":"2023-03-06T16:26:22Z","summary":null,"body":["<article data-history-node-id=\"4022\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-127\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-127<br \/><strong>Date: <\/strong>March\u00a06, 2023<\/p>\n\n<p>Between February\u00a027 and March\u00a05, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Network Automation\u00a0\u2013 versions 2.x prior to 2.4.4<\/li>\n\t<li>IBM Observability with Instana\u00a0\u2013 versions 239-0 to 239-2, 241-0 to 241-2 and 243-0<\/li>\n\t<li>IBM Rational ClearCase\u00a0\u2013 versions 9.0.2, 9.1 and 10.0.0<\/li>\n\t<li>IBM WebSphere Remote Server\u00a0\u2013 versions 8.5 and 9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6959583\">IBM Security Bulletin (IBM Cloud Pak for Network Automation)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6959969\">IBM Security Bulletin (IBM Observability with Instana)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6959883\">IBM Security Bulletin (IBM Rational ClearCase)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6959691\">IBM Security Bulletin (IBM WebSphere Remote Server)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-127","alert_type":396,"serial_number":"AV23-127","subject":null,"moderation_state":"published","external_url":null},{"nid":4023,"title":"Dell security advisory (AV23-128)","uuid":"b656c6bd-f11b-40e9-aa64-f4892f7c636d","banner":null,"lang":"en","date_modified":"2023-03-06","date_modified_ts":"2023-03-06T16:57:56Z","date_created":"2023-03-06T16:53:55Z","summary":null,"body":["<article data-history-node-id=\"4023\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-128\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-128<br \/><strong>Date: <\/strong>March\u00a06, 2023<\/p>\n\n<p>Between February\u00a027 and March\u00a05, 2023, Dell published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell NetWorker, NVE\u00a0\u2013 version 19.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-128","alert_type":396,"serial_number":"AV23-128","subject":null,"moderation_state":"published","external_url":null},{"nid":4028,"title":"Ubuntu security advisory (AV23-129)","uuid":"06cf767b-7905-4474-919b-4a737b791c9f","banner":null,"lang":"en","date_modified":"2023-03-06","date_modified_ts":"2023-03-06T19:21:39Z","date_created":"2023-03-06T19:15:44Z","summary":null,"body":["<article data-history-node-id=\"4028\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-129\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-129<br \/><strong>Date: <\/strong>March\u00a06, 2023<\/p>\n\n<p>Between February\u00a027 and March\u00a05, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-129","alert_type":396,"serial_number":"AV23-129","subject":null,"moderation_state":"published","external_url":null},{"nid":4029,"title":"Android security advisory \u2013 March 2023 monthly rollup (AV23-130)","uuid":"1483ce6f-2a7f-452e-85a9-9e8f5df69368","banner":null,"lang":"en","date_modified":"2023-03-06","date_modified_ts":"2023-03-06T20:25:40Z","date_created":"2023-03-06T20:20:19Z","summary":null,"body":["<article data-history-node-id=\"4029\" about=\"\/en\/alerts-advisories\/android-security-advisory-march-2023-monthly-rollup-av23-130\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-130<br \/><strong>Date: <\/strong>March 7, 2023<\/p>\n\n<p>On March\u00a06,\u00a02023, Android published a security bulletin to address vulnerabilities in Android devices. The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-03-01\">Android security bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-march-2023-monthly-rollup-av23-130","alert_type":396,"serial_number":"AV23-130","subject":null,"moderation_state":"published","external_url":null},{"nid":4030,"title":"[Control systems] ABB security advisory (AV23-131)","uuid":"bd6921cb-d09b-49c0-9a1a-661846b26854","banner":null,"lang":"en","date_modified":"2023-03-07","date_modified_ts":"2023-03-07T20:08:28Z","date_created":"2023-03-07T20:01:09Z","summary":null,"body":["<article data-history-node-id=\"4030\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-131\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-131<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a07,\u00a02023<\/p>\n\n<p>On March\u00a07,\u00a02023, ABB published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>COM600\u00a0\u2013\u00a0firmware versions 2.x, 3.x, 4.x and 5.x<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001574&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Security Advisory 2NGA001574 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-131","alert_type":398,"serial_number":"AV23-131","subject":null,"moderation_state":"published","external_url":null},{"nid":4031,"title":"Fortinet security advisory (AV23-132)","uuid":"e96d4d80-5185-4be6-b7ea-d619a9e0535b","banner":null,"lang":"en","date_modified":"2023-03-08","date_modified_ts":"2023-03-08T13:42:13Z","date_created":"2023-03-08T13:36:58Z","summary":null,"body":["<article data-history-node-id=\"4031\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-132\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-132<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 8, 2023<\/p>\n\n<p>On March\u00a07,\u00a02023, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiGate\u00a0\u2013 multiple platforms<\/li>\n\t<li>FortiOS\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiProxy\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiWifi\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-001\">Fortinet PSIRT Advisory (FG-IR-23-001)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-132","alert_type":396,"serial_number":"AV23-132","subject":null,"moderation_state":"published","external_url":null},{"nid":4032,"title":"Google Chrome security advisory (AV23-133)","uuid":"dc1a47ce-4d81-47bb-a1e9-a7e8cbf6d886","banner":null,"lang":"en","date_modified":"2023-03-08","date_modified_ts":"2023-03-08T14:20:48Z","date_created":"2023-03-08T14:15:46Z","summary":null,"body":["<article data-history-node-id=\"4032\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-133\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-133<br \/><strong>Date: <\/strong>March\u00a08,\u00a02023<\/p>\n\n<p>On March\u00a07,\u00a02023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 0.5563.64 (Mac and Linux) and 111.0.5563.64\/.65 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/03\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-133","alert_type":396,"serial_number":"AV23-133","subject":null,"moderation_state":"published","external_url":null},{"nid":4033,"title":"Cisco Security Advisory (AV23-134)","uuid":"d3def2d1-f655-4f16-afb8-f84fb00b028f","banner":null,"lang":"en","date_modified":"2023-03-08","date_modified_ts":"2023-03-08T19:40:56Z","date_created":"2023-03-08T19:32:40Z","summary":null,"body":["<article data-history-node-id=\"4033\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-134\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-134<br \/><strong>Date: <\/strong>March\u00a08, 2023<\/p>\n\n<p>On March\u00a08, 2023, Cisco published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cisco IOS XR 64-bit\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-bfd-XmRescbT\">Cisco Security Advisory (cisco-sa-bfd-XmRescbT)<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-134","alert_type":396,"serial_number":"AV23-134","subject":null,"moderation_state":"published","external_url":null},{"nid":4034,"title":"[Control systems] Akuvox security advisory (AV23-135)","uuid":"03895e74-880f-4c82-bb8d-30abf9e18834","banner":null,"lang":"en","date_modified":"2023-03-09","date_modified_ts":"2023-03-09T20:25:59Z","date_created":"2023-03-09T20:10:00Z","summary":null,"body":["<article data-history-node-id=\"4034\" about=\"\/en\/alerts-advisories\/control-systems-akuvox-security-advisory-av23-135\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-135<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 9, 2023<\/p>\n\n<p>On March 9, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>E11\u00a0\u2013 all versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-068-01\">ICS Advisory (ICSA-23-068-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95 \">ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-akuvox-security-advisory-av23-135","alert_type":398,"serial_number":"AV23-135","subject":null,"moderation_state":"published","external_url":null},{"nid":4035,"title":"[Control systems] B&R security advisory (AV23-136)","uuid":"38f05d8a-ecd2-4c2a-b250-a9e67b21fd60","banner":null,"lang":"en","date_modified":"2023-03-09","date_modified_ts":"2023-03-09T20:49:54Z","date_created":"2023-03-09T20:40:37Z","summary":null,"body":["<article data-history-node-id=\"4035\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av23-136\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-136<br \/><strong>Date: <\/strong>March\u00a09, 2023<\/p>\n\n<p>On Marchh\u00a09, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>System Diagnostics Manager\u00a0\u2013 version 3.00 and later, version C4.93 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-068-02\">ICS Advisory (ICSA-23-068-02)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av23-136","alert_type":398,"serial_number":"AV23-136","subject":null,"moderation_state":"published","external_url":null},{"nid":4036,"title":"[Control systems] STEP Tools security advisory (AV23-137)","uuid":"e8984252-04b6-4ed5-9555-bb0523bd6c33","banner":null,"lang":"en","date_modified":"2023-03-09","date_modified_ts":"2023-03-09T21:06:19Z","date_created":"2023-03-09T20:59:58Z","summary":null,"body":["<article data-history-node-id=\"4036\" about=\"\/en\/alerts-advisories\/control-systems-step-tools-security-advisory-av23-137\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-137<br \/><strong>Date: <\/strong>March\u00a09, 2023<\/p>\n\n<p>On March\u00a09, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>STEPTools (ifcmesh library)\u00a0\u2013 version 18.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-068-04\">ICS Advisory (ICSA-23-068-04)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-step-tools-security-advisory-av23-137","alert_type":398,"serial_number":"AV23-137","subject":null,"moderation_state":"published","external_url":null},{"nid":4037,"title":"[Control systems] Hitachi security advisory (AV23-138)","uuid":"d6527436-8795-4bb9-a06b-df9f1a91f876","banner":null,"lang":"en","date_modified":"2023-03-10","date_modified_ts":"2023-03-10T13:02:47Z","date_created":"2023-03-10T12:53:32Z","summary":null,"body":["<article data-history-node-id=\"4037\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-security-advisory-av23-138\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-138<br \/><strong>Date: <\/strong>March\u00a010,\u00a02023<\/p>\n\n<p>On March\u00a09,\u00a02023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Relion 650 \u2013 versions 2.2.0, 2.2.1, 2.2.4 and 2.2.5<\/li>\n\t<li>Relion 670 \u2013 versions 2.2.0 to 2.2.5<\/li>\n\t<li>SAM600-IO \u2013 version 2.2.1<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-068-05\">ICS Advisory (ICSA-23-068-05)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-security-advisory-av23-138","alert_type":398,"serial_number":"AV23-138","subject":null,"moderation_state":"published","external_url":null},{"nid":4039,"title":"IBM security advisory (AV23-139)","uuid":"6b781654-ae28-4fc3-9473-f25b3c2d737a","banner":null,"lang":"en","date_modified":"2023-03-13","date_modified_ts":"2023-03-13T14:21:52Z","date_created":"2023-03-13T14:15:01Z","summary":null,"body":["<article data-history-node-id=\"4039\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-139\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-139<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 13,\u00a02023<\/p>\n\n<p>Between March\u00a06\u00a0and\u00a012,\u00a02023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Robotic Process Automation for Cloud Pak\u00a0\u2013 version\u00a021.0.1\u00a0to\u00a021.0.7.1\u00a0and\u00a023.0.0\u00a0to\u00a023.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6962201\">IBM Security Bulletin (IBM Robotic Process Automation for Cloud Pak)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-139","alert_type":396,"serial_number":"AV23-139","subject":null,"moderation_state":"published","external_url":null},{"nid":4040,"title":"Dell security advisory (AV23-140)","uuid":"2a54e03d-73f1-4c44-ba0a-6609beb2de6e","banner":null,"lang":"en","date_modified":"2023-03-13","date_modified_ts":"2023-03-13T14:49:33Z","date_created":"2023-03-13T14:30:11Z","summary":null,"body":["<article data-history-node-id=\"4040\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-140\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV23-140<br \/><strong>Date:<\/strong> March 13,\u00a02023<\/p>\n\n<p>Between March 6\u00a0and\u00a012,\u00a02023, Dell published security sdvisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance \u2013 8.0.x versions prior to version 8.0.020<\/li>\n\t<li>Dell GeoDrive for Windows \u2013 version 2.2-P3<\/li>\n\t<li>Dell Hybrid Client (Ubuntu 20.04 and Ubuntu 22.04) \u2013 versions 1.8 and 2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000210980\/dsa-2023-065-dell-vxrail-8-x-security-update-for-multiple-third-party-component-vulnerabilities \">DSA-2023-065 (Dell VxRail 8.x)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000210935\/dsa-2023-005-dell-emc-geodrive-for-windows-security-update-for-openssl-vulnerability\">DSA-2023-005 (Dell GeoDrive)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000210895\/dsa-2023-087-dell-hybrid-client-security-update-for-a-sudo-vulnerability\">DSA-2023-087 (Dell Hybrid)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-140","alert_type":396,"serial_number":"AV23-140","subject":null,"moderation_state":"published","external_url":null},{"nid":4041,"title":"Ubuntu security advisory (AV23-141)","uuid":"aeac3299-d704-4faa-aa00-4ff7f1f2ec03","banner":null,"lang":"en","date_modified":"2023-03-13","date_modified_ts":"2023-03-13T15:41:55Z","date_created":"2023-03-13T15:18:50Z","summary":null,"body":["<article data-history-node-id=\"4041\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-141\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-141<br \/><strong>Date: <\/strong>March\u00a013, 2023<\/p>\n\n<p>Between March\u00a06 and March\u00a012, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-141","alert_type":396,"serial_number":"AV23-141","subject":null,"moderation_state":"published","external_url":null},{"nid":4042,"title":"Microsoft Edge security advisory (AV23-142)","uuid":"035a0ea1-2212-4243-b35a-c94180c5faad","banner":null,"lang":"en","date_modified":"2023-03-14","date_modified_ts":"2023-03-14T17:13:38Z","date_created":"2023-03-14T17:05:53Z","summary":null,"body":["<article data-history-node-id=\"4042\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-142\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-142<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 14, 202<\/p>\n\n<p>On March 13, 2023, Microsoft published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 110.0.1587.69<\/li>\n\t<li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 111.0.1661.41<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-13-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-142","alert_type":396,"serial_number":"AV23-142","subject":null,"moderation_state":"published","external_url":null},{"nid":4044,"title":"SAP security advisory \u2013 March 2023 monthly rollup (AV23-143)","uuid":"c371ebda-41c4-4700-96a7-1f7afa6fca72","banner":null,"lang":"en","date_modified":"2023-03-14","date_modified_ts":"2023-03-14T17:35:32Z","date_created":"2023-03-14T17:18:55Z","summary":null,"body":["<article data-history-node-id=\"4044\" about=\"\/en\/alerts-advisories\/sap-security-advisory-march-2023-monthly-rollup-av23-143\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-143<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 14, 2023<\/p>\n\n<p>On March 14, 2023, SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Business Objects Business Intelligence Platform\u00a0\u2013 version 420 and 430<\/li>\n\t<li>SAP NetWeaver Application Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day\u00a0\u2013 March 2023 (PDF)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-march-2023-monthly-rollup-av23-143","alert_type":396,"serial_number":"AV23-143","subject":null,"moderation_state":"published","external_url":null},{"nid":4043,"title":"[Control systems] Schneider Electric security advisory (AV23-144)","uuid":"fa220b58-7d18-4116-8827-90f2e7bde80f","banner":null,"lang":"en","date_modified":"2023-03-14","date_modified_ts":"2023-03-14T18:03:09Z","date_created":"2023-03-14T17:22:25Z","summary":null,"body":["<article data-history-node-id=\"4043\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-144\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-144<br \/><strong>Date: <\/strong>March\u00a014, 2023<\/p>\n\n<p>On March\u00a014, 2023, Schneider Electric published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Interative Graphical SCADA System (IGSS)\u00a0\u2013 version 16.0.0.23040 and prior<\/li>\n\t<li>PowerLogic HDPM6000\u00a0\u2013 version 0.58.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-144","alert_type":398,"serial_number":"AV23-144","subject":null,"moderation_state":"published","external_url":null},{"nid":4045,"title":"[Control systems] Siemens security advisory (AV23-145)","uuid":"27211442-fdf4-43f4-be54-53609cb69af7","banner":null,"lang":"en","date_modified":"2023-03-14","date_modified_ts":"2023-03-14T18:06:45Z","date_created":"2023-03-14T17:22:26Z","summary":null,"body":["<article data-history-node-id=\"4045\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-145\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-145<br \/><strong>Date: <\/strong>March\u00a014, 2023<\/p>\n\n<p>On March\u00a014, 2023, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Mendix SAML\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>RUGGEDCOM\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-145","alert_type":398,"serial_number":"AV23-145","subject":null,"moderation_state":"published","external_url":null},{"nid":4046,"title":"Mozilla security advisory (AV23-147)","uuid":"c5261386-71fc-45be-a7cd-11e0ade418e1","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T13:14:10Z","date_created":"2023-03-14T20:20:44Z","summary":null,"body":["<article data-history-node-id=\"4046\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-147\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-147<br \/><strong>Date: <\/strong>March\u00a015, 2023<\/p>\n\n<p>On March\u00a014, 2023, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 102.9<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 111<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-10\/\">Mozilla Security Advisory (MFSA 2023-10)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-09\/\">Mozilla Security Advisory (MFSA 2023-09)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-147","alert_type":396,"serial_number":"AV23-147","subject":null,"moderation_state":"published","external_url":null},{"nid":4048,"title":"[Control systems] Omron security advisory (AV23-148)","uuid":"39658c97-9964-44fd-8746-7d365dfb4592","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T13:33:44Z","date_created":"2023-03-14T20:20:48Z","summary":null,"body":["<article data-history-node-id=\"4048\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av23-148\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-148<br \/><strong>Date: <\/strong>March\u00a015, 2023<\/p>\n\n<p>On March\u00a014, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SYSMAC CJ-series\u00a0\u2013 multiple versions<\/li>\n\t<li>SYSMAC CS-series\u00a0\u2013 multiple versions<\/li>\n\t<li>SYSMAC CP-series\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-073-01\">ICS Advisory (ICSA-23-073-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av23-148","alert_type":398,"serial_number":"AV23-148","subject":null,"moderation_state":"published","external_url":null},{"nid":4047,"title":"Microsoft security advisory \u2013 March 2023 monthly rollup (AV23-146)","uuid":"487d1b87-1ec4-4fad-861c-93a64c45d443","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T13:13:00Z","date_created":"2023-03-14T20:37:43Z","summary":null,"body":["<article data-history-node-id=\"4047\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-march-2023-monthly-rollup-av23-146\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-146<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 15, 2023<\/p>\n\n<p>On March 14, 2023, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft 365 Apps\u00a0- multiples versions and platforms<\/li>\n\t<li>Microsoft Office\u00a0- multiple versions and platforms<\/li>\n\t<li>Microsoft Outlook\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 10\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-23397 and CVE-2023-24880 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Mar\">March 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-march-2023-monthly-rollup-av23-146","alert_type":396,"serial_number":"AV23-146","subject":null,"moderation_state":"published","external_url":null},{"nid":4049,"title":"[Control systems] GE Digital security advisory (AV23-150)","uuid":"8582ef99-118b-495f-b474-35203220a2cb","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T14:08:00Z","date_created":"2023-03-15T13:17:06Z","summary":null,"body":["<article data-history-node-id=\"4049\" about=\"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-150\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-150<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 15, 2023<\/p>\n\n<p>On March 14, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>GE Digital Proficy iFIX\u00a0\u2013 versions 2022, 6.1 and 6.5<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a full system compromise.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-073-03\">ICS Advisory (ICSA-23-073-03)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-150","alert_type":398,"serial_number":"AV23-150","subject":null,"moderation_state":"published","external_url":null},{"nid":4051,"title":"[Control systems] AVEVA security advisory (AV23-151)","uuid":"146f3750-d042-4476-85fd-661997815ca0","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T14:14:21Z","date_created":"2023-03-15T13:36:19Z","summary":null,"body":["<article data-history-node-id=\"4051\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av23-151\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-151<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 15, 2023<\/p>\n\n<p>On March 14, 2023, CISA published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>AVEVA Plant SCADA\u00a0\u2013 multiple versions<\/li>\n\t<li>AVEVA Telemetry Server\u00a0\u2013 version 2020 R2 SP1 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to a denial of service or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-073-04\">ICS Advisory (ICSA-23-073-04)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av23-151","alert_type":398,"serial_number":"AV23-151","subject":null,"moderation_state":"published","external_url":null},{"nid":4050,"title":"[Control systems] Autodesk security advisory (AV23-149)","uuid":"0c5d8702-c806-431d-b020-ec2e08011397","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T13:41:52Z","date_created":"2023-03-15T13:37:57Z","summary":null,"body":["<article data-history-node-id=\"4050\" about=\"\/en\/alerts-advisories\/control-systems-autodesk-security-advisory-av23-149\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-149<br \/><strong>Date: <\/strong>March\u00a015, 2023<\/p>\n\n<p>On March\u00a014, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Autodesk FBX SDK\u00a0\u2013 version 2020 and prior<\/li>\n\t<li>Luxion KeyShot\u00a0\u2013 version 11.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-073-02\">ICS Advisory (ICSA-23-073-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-autodesk-security-advisory-av23-149","alert_type":398,"serial_number":"AV23-149","subject":null,"moderation_state":"published","external_url":null},{"nid":4052,"title":"Adobe security advisory (AV23-152)","uuid":"3ad785af-7f10-43e4-a584-987270521abc","banner":null,"lang":"en","date_modified":"2023-03-17","date_modified_ts":"2023-03-17T12:55:45Z","date_created":"2023-03-15T15:40:10Z","summary":null,"body":["<article data-history-node-id=\"4052\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-152\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-152<br \/><strong>Date: <\/strong>March\u00a015, 2023<\/p>\n\n<p>On March\u00a014, 2023, Adobe published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Commerce\u00a0\u2013 versions 2.4.4-p2 and 2.4.5-p1 and prior<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 3.4.7 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 AEM Cloud Service and version 6.5.15.0 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 2.0.0 and prior<\/li>\n\t<li>ColdFusion 2018\u00a0\u2013 version update 15 and prior<\/li>\n\t<li>ColdFusion 2021\u00a0\u2013 version update 5 and prior<\/li>\n\t<li>Creative Cloud Desktop Application\u00a0\u2013 version 5.9.1 and prior<\/li>\n\t<li>Illustrator 2023\u00a0\u2013 version 27.2.0 and prior<\/li>\n\t<li>Magento Open Source\u00a0\u2013 versions 2.4.4-p2 and 2.4.5-p1 and prior<\/li>\n\t<li>Photoshop 2022\u00a0\u2013 version 23.5.3 and prior<\/li>\n\t<li>Photoshop 2023\u00a0\u2013 version 24.1.1 and prior<\/li>\n<\/ul><p>Adobe has indicated that CVE-2023-26360 has been exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/security-bulletin.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-152","alert_type":396,"serial_number":"AV23-152","subject":null,"moderation_state":"published","external_url":null},{"nid":4053,"title":"HPE security advisory (AV23-153)","uuid":"4f812a05-6b28-4d84-9606-daf84d05f2d1","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T17:27:09Z","date_created":"2023-03-15T17:17:52Z","summary":null,"body":["<article data-history-node-id=\"4053\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-153\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-153<br \/><strong>Date: <\/strong>March\u00a015, 2023<\/p>\n\n<p>Between March\u00a012 and 14, 2023, HPE published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>ClearPass Policy Manager 6.11.x, 6.10.x and 6.9.x\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Integrated Lights-Out 4 (iLO 4)\u00a0\u2013 versions prior to 2.82<\/li>\n\t<li>HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers\u00a0\u2013 versions prior to 2.78<\/li>\n\t<li>HPE Integrated Lights-Out 6 (iLO 6)\u00a0\u2013 versions prior to 1.20<\/li>\n\t<li>HPE NonStop Platform\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-153","alert_type":396,"serial_number":"AV23-153","subject":null,"moderation_state":"published","external_url":null},{"nid":4054,"title":"Microsoft Outlook zero-day vulnerability allowing NTLM credential theft - CVE-2023-23397","uuid":"db360d9b-f239-41ce-b3d8-04cf17672a60","banner":null,"lang":"en","date_modified":"2023-03-15","date_modified_ts":"2023-03-15T19:05:11Z","date_created":"2023-03-15T19:01:30Z","summary":null,"body":["<article data-history-node-id=\"4054\" about=\"\/en\/alerts-advisories\/microsoft-outlook-zero-day-vulnerability-allowing-ntlm-credential-theft\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-002<br \/><strong>Date:\u00a0<\/strong>March 15, 2023<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On March 14, 2023, Microsoft published advisories highlighting several critical vulnerabilities<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. One of those advisories, CVE-2023-23397, disclosed a vulnerability impacting Microsoft Outlook and highlighted it has been exploited in the wild<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. Open source has further reported that this zero-day vulnerability was exploited by sophisticated actors<span class=\"nowrap\"><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/span>.<\/p>\n\n<p>CVE-2023-23397 allows a threat actor to send a specially crafted email with a malicious payload that will cause the victim\u2019s Outlook client to automatically connect to a Universal Naming Convention (UNC) location under the actor\u2019s control to receive the Net-NTLMv2 user\u2019s password hash<sup id=\"fn2b-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. This disclosure of credentials would permit further methods of exploitation<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<p>Exploitation can occur prior to the email being opened or previewed by the user. The Cyber Center can confirm successful reproduction of a payload invoking the exploit.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>The Cyber Centre recommends patching immediately<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>. If that is not possible, some or all of the following mitigations and actions should be performed as quickly as possible:<\/p>\n\n<ul><li>Block TCP 445\/SMB outbound from your networks to prevent inadvertent communications to the threat actor resulting from this exploit.<\/li>\n\t<li>Add users to the Protected Users Security Group, which prevents the use of NTLM as an authentication mechanism<span class=\"nowrap\"><sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><\/span>.<\/li>\n\t<li>Restrict the use of NTLM<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>.<\/li>\n\t<li>Periodically run a script provided by Microsoft to detect potentially malicious messaging items (mail, calendar and tasks)<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/li>\n<\/ul><p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the My Cyber Portal, email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or telephone (1-833-CYBER-88 or <a href=\"tel:1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2023-23397\">Microsoft Outlook Elevation of Privilege Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-march-2023-patch-tuesday-fixes-2-zero-days-83-flaws\/\">Microsoft March 2023 Patch Tuesday fixes 2 zero-days, 83 flaws<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/blog\/2023\/03\/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability\/\">Microsoft Mitigates Outlook Elevation of Privilege Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-march-2023-exchange-server-security-updates\/ba-p\/3764224\">March 2023 Exchange Server Security Updates<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/confirmation.aspx?id=36036\">Mitigating Pass-the-Hash (PtH) Attacks and Other Credential Theft Techniques<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/microsoft-security-advisory-march-2023-monthly-rollup-av23-146\">Microsoft security advisory\u00a0\u2013 March 2023 monthly rollup (AV23-146)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/security\/credentials-protection-and-management\/protected-users-security-group\">Protected Users Security Group<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/threat-protection\/security-policy-settings\/network-security-restrict-ntlm-ntlm-authentication-in-this-domain\">Network security: Restrict NTLM: NTLM authentication in this domain<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/microsoft.github.io\/CSS-Exchange\/Security\/CVE-2023-23397\/\">Microsoft CVE-2023-23397 script<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote <\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-outlook-zero-day-vulnerability-allowing-ntlm-credential-theft","alert_type":397,"serial_number":"AL23-002","subject":null,"moderation_state":"published","external_url":null},{"nid":4056,"title":"Red Hat security advisory (AV23-154)","uuid":"f4405e1b-5cb4-4162-9e26-f21cd2951d0a","banner":null,"lang":"en","date_modified":"2023-03-16","date_modified_ts":"2023-03-16T17:10:26Z","date_created":"2023-03-16T17:09:02Z","summary":null,"body":["<article data-history-node-id=\"4056\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-154\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-154<br \/><strong>Date: <\/strong>March\u00a016,\u00a02023<\/p>\n\n<p>Between March\u00a014\u00a0and\u00a015,\u00a02023, Red Hat published security advisories to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories?q=&amp;p=2&amp;sort=portal_publication_date%20desc&amp;rows=10&amp;portal_advisory_type=Security%20Advisory&amp;documentKind=PortalProduct\">Red Hat security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-154","alert_type":396,"serial_number":"AV23-154","subject":null,"moderation_state":"published","external_url":null},{"nid":4057,"title":"[Control systems] Rockwell Automation security advisory (AV23-155)","uuid":"c6e21f7a-d791-4788-b896-dded520e18c2","banner":null,"lang":"en","date_modified":"2023-03-17","date_modified_ts":"2023-03-17T14:16:53Z","date_created":"2023-03-17T14:10:01Z","summary":null,"body":["<article data-history-node-id=\"4057\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-155\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-155<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 17, 2023<\/p>\n\n<p>On March 16, 2023, CISA published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Modbus TCP Server AOI\u00a0\u2013 versions 2.00 and 2.03<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-075-07\">ICS Advisory (ICSA-23-075-07)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-155","alert_type":398,"serial_number":"AV23-155","subject":null,"moderation_state":"published","external_url":null},{"nid":4058,"title":"[Control systems] Honeywell security advisory (AV23-156)","uuid":"cec75903-f4c9-40ce-9ba3-abe1300fb150","banner":null,"lang":"en","date_modified":"2023-03-17","date_modified_ts":"2023-03-17T15:44:52Z","date_created":"2023-03-17T15:40:40Z","summary":null,"body":["<article data-history-node-id=\"4058\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av23-156\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-156<br \/><strong>Date: <\/strong>March\u00a017, 2023<\/p>\n\n<p>On March\u00a016, 2023, CISA published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Honeywell OneWireless WDM\u00a0\u2013 versions prior to R322.1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to the execution of arbitrary commands.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-075-06\">ICS Advisory (ICSA-23-075-06)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av23-156","alert_type":398,"serial_number":"AV23-156","subject":null,"moderation_state":"published","external_url":null},{"nid":4059,"title":"Ubuntu security advisory (AV23-157)","uuid":"0d8a7c18-35bd-4d91-89ef-753ddb4325d1","banner":null,"lang":"en","date_modified":"2023-03-20","date_modified_ts":"2023-03-20T17:24:25Z","date_created":"2023-03-20T17:15:13Z","summary":null,"body":["<article data-history-node-id=\"4059\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-157\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-157<br \/><strong>Date: <\/strong>March\u00a020, 2023<\/p>\n\n<p>Between March\u00a013 and March\u00a019, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-157","alert_type":396,"serial_number":"AV23-157","subject":null,"moderation_state":"published","external_url":null},{"nid":4061,"title":"IBM security advisory (AV23-158)","uuid":"f81dd046-2231-4148-a151-0d7e0585c656","banner":null,"lang":"en","date_modified":"2023-03-20","date_modified_ts":"2023-03-20T20:00:09Z","date_created":"2023-03-20T19:38:37Z","summary":null,"body":["<article data-history-node-id=\"4061\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-158\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-158<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 20, 2023<\/p>\n\n<p>Between March 13 and 19, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>IBM Spectrum Protect Client\u00a0\u2013 version 8.1.7.0 to 8.1.17.1<\/li>\n\t<li>IBM Spectrum Protect for Space Management\u00a0\u2013 version 8.1.7.0 to 8.1.17.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6956237\">IBM Security Bulletin (IBM Spectrum Protect)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-158","alert_type":396,"serial_number":"AV23-158","subject":null,"moderation_state":"published","external_url":null},{"nid":4062,"title":"[Control systems] VISAM security advisory (AV23-159)","uuid":"769e1fde-44fb-4851-961b-403413e26561","banner":null,"lang":"en","date_modified":"2023-03-22","date_modified_ts":"2023-03-22T14:04:46Z","date_created":"2023-03-22T13:57:01Z","summary":null,"body":["<article data-history-node-id=\"4062\" about=\"\/en\/alerts-advisories\/control-systems-visam-security-advisory-av23-159\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-159<br \/><strong>Date: <\/strong>March\u00a022, 2023<\/p>\n\n<p>On March\u00a021, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VBASE Automation Base\u00a0- versions prior to 11.7.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-080-05\">ICS Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-visam-security-advisory-av23-159","alert_type":398,"serial_number":"AV23-159","subject":null,"moderation_state":"published","external_url":null},{"nid":4064,"title":"[Control systems] Rockwell Automation security advisory (AV23-161) ","uuid":"4a4b837f-ceab-4703-9ecc-340b5bc672e1","banner":null,"lang":"en","date_modified":"2023-03-22","date_modified_ts":"2023-03-22T14:39:05Z","date_created":"2023-03-22T14:02:20Z","summary":null,"body":["<article data-history-node-id=\"4064\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-161\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-161<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 22 2023<\/p>\n\n<p>On March 21, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ThinManager ThinServer\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-080-06\">ICS Advisory (ICSA-23-080-06)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-161","alert_type":398,"serial_number":"AV23-161","subject":null,"moderation_state":"published","external_url":null},{"nid":4063,"title":"[Control systems] Keysight Technologies security advisory (AV23-160)","uuid":"744323a4-e63b-4338-b6b4-edb18e918df4","banner":null,"lang":"en","date_modified":"2023-03-22","date_modified_ts":"2023-03-22T14:22:08Z","date_created":"2023-03-22T14:10:27Z","summary":null,"body":["<article data-history-node-id=\"4063\" about=\"\/en\/alerts-advisories\/control-systems-keysight-technologies-security-advisory-av23-160\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-160<br \/><strong>Date:\u00a0<\/strong>March\u00a022, 2023<\/p>\n\n<p>On March\u00a021, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>N6854A Geolocation Server\u00a0- version 2.4.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-080-01\">ICS Advisory (ICSA-23-080-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-keysight-technologies-security-advisory-av23-160","alert_type":398,"serial_number":"AV23-160","subject":null,"moderation_state":"published","external_url":null},{"nid":4065,"title":"Google Chrome security advisory (AV23-162)","uuid":"0eb0b9ff-57c0-4ccd-944b-cad0f1d8680a","banner":null,"lang":"en","date_modified":"2023-03-22","date_modified_ts":"2023-03-22T14:56:17Z","date_created":"2023-03-22T14:48:27Z","summary":null,"body":["<article data-history-node-id=\"4065\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-162\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-162<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 22, 2023<\/p>\n\n<p>On March 21, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 111.0.5563.110 (Mac and Linux) and 111.0.5563.110\/.111 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/03\/stable-channel-update-for-desktop_21.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-162","alert_type":396,"serial_number":"AV23-162","subject":null,"moderation_state":"published","external_url":null},{"nid":4066,"title":"[Control systems] Delta Electronics security advisory (AV23-163) ","uuid":"405a87fa-91c0-4cd0-872b-f1cea6be75c2","banner":null,"lang":"en","date_modified":"2023-03-22","date_modified_ts":"2023-03-22T15:28:47Z","date_created":"2023-03-22T15:22:52Z","summary":null,"body":["<article data-history-node-id=\"4066\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-163\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-163<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 22, 2023<\/p>\n\n<p>On March 21, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>InfraSuite Device Master\u00a0- versions prior to 1.0.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-080-02\">ICS Advisory (ICSA-23-080-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-163","alert_type":398,"serial_number":"AV23-163","subject":null,"moderation_state":"published","external_url":null},{"nid":4067,"title":"Cisco Security Advisory (AV23-164)","uuid":"f04fa578-a73c-42a0-be92-18ecb1f0ade8","banner":null,"lang":"en","date_modified":"2023-03-22","date_modified_ts":"2023-03-22T20:02:29Z","date_created":"2023-03-22T19:41:32Z","summary":null,"body":["<article data-history-node-id=\"4067\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-164\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-164<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 22, 2023<\/p>\n\n<p>On March 22, 2023, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco DNA Center\u00a0\u2013 versions prior to 2.3.3.6<\/li>\n\t<li>Cisco IOS\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-164","alert_type":396,"serial_number":"AV23-164","subject":null,"moderation_state":"published","external_url":null},{"nid":4068,"title":"Red Hat security advisory (AV23-165)","uuid":"9b4050e2-bc74-4b49-a921-894d1b042b3c","banner":null,"lang":"en","date_modified":"2023-03-22","date_modified_ts":"2023-03-22T20:51:12Z","date_created":"2023-03-22T20:40:45Z","summary":null,"body":["<article data-history-node-id=\"4068\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-165\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-165<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 22, 2023<\/p>\n\n<p>On March 20, 2023, Red Hat published Security Advisories to address a vulnerability in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux 9<\/li>\n\t<li>Red Hat Virtualization 4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2022-4744\">Red Hat Security Advisory (CVE-2022-4744)<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories?q=&amp;p=2&amp;sort=portal_publication_date%20desc&amp;rows=10&amp;portal_advisory_type=Security%20Advisory&amp;documentKind=PortalProduct\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-165","alert_type":396,"serial_number":"AV23-165","subject":null,"moderation_state":"published","external_url":null},{"nid":4069,"title":"[Control systems] CP Plus security advisory (AV23-166) ","uuid":"891620e3-a01a-464e-8dbe-dea9614aafd7","banner":null,"lang":"en","date_modified":"2023-03-23","date_modified_ts":"2023-03-23T18:51:56Z","date_created":"2023-03-23T18:29:24Z","summary":null,"body":["<article data-history-node-id=\"4069\" about=\"\/en\/alerts-advisories\/control-systems-cp-plus-security-advisory-av23-166\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-166<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 23, 2023<\/p>\n\n<p>On March 23, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>KVMS Pro \u2013 version V2.01.0.T.190521 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-082-02\">ICS Advisory (ICSA-23-082-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cp-plus-security-advisory-av23-166","alert_type":398,"serial_number":"AV23-166","subject":null,"moderation_state":"published","external_url":null},{"nid":4071,"title":"[Control systems] RoboDK security advisory (AV23-168)","uuid":"28e3fe80-ab05-4cc9-ab15-512c522738b5","banner":null,"lang":"en","date_modified":"2023-03-23","date_modified_ts":"2023-03-23T20:07:10Z","date_created":"2023-03-23T18:41:38Z","summary":null,"body":["<article data-history-node-id=\"4071\" about=\"\/en\/alerts-advisories\/control-systems-robodk-security-advisory-av23-168\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-168<br \/><strong>Date: <\/strong>March\u00a023, 2023<\/p>\n\n<p>On March\u00a023, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>RoboDK\u00a0- version v5.5.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-082-01\">ICS Advisory (ICSA-23-082-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English- ******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-robodk-security-advisory-av23-168","alert_type":398,"serial_number":"AV23-168","subject":null,"moderation_state":"published","external_url":null},{"nid":4072,"title":"[Control systems] SAUTER security advisory (AV23-169)","uuid":"aed18bb8-2652-4c5b-9a95-3809321698ad","banner":null,"lang":"en","date_modified":"2023-03-23","date_modified_ts":"2023-03-23T20:08:24Z","date_created":"2023-03-23T18:41:39Z","summary":null,"body":["<article data-history-node-id=\"4072\" about=\"\/en\/alerts-advisories\/control-systems-sauter-security-advisory-av23-169\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-169<br \/><strong>Date: <\/strong>March\u00a023, 2023<\/p>\n\n<p>On March\u00a023, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>EY-AS525F001 with moduWeb<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-082-03\">ICS Advisory (ICSA-23-082-03)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sauter-security-advisory-av23-169","alert_type":398,"serial_number":"AV23-169","subject":null,"moderation_state":"published","external_url":null},{"nid":4073,"title":"[Control systems] Schneider Electric security advisory (AV23-170)","uuid":"778e3d03-d4d3-4ebb-9d7a-61f0e2eeeb46","banner":null,"lang":"en","date_modified":"2023-03-23","date_modified_ts":"2023-03-23T20:09:14Z","date_created":"2023-03-23T18:41:39Z","summary":null,"body":["<article data-history-node-id=\"4073\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-170\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-170<br \/><strong>Date: <\/strong>March\u00a023, 2023<\/p>\n\n<p>On March\u00a023, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>IGSS Data Server (IGSSdataServer.exe)\u00a0\u2013 version V16.0.0.23040 and prior<\/li>\n\t<li>IGSS Dashboard (DashBoard.exe)\u00a0- version V16.0.0.23040 and prior<\/li>\n\t<li>Custom Reports (RMS16.dll)\u00a0- version V16.0.0.23040 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-082-04\">ICS Advisory (ICSA-23-082-04)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-170","alert_type":398,"serial_number":"AV23-170","subject":null,"moderation_state":"published","external_url":null},{"nid":4070,"title":"[Control systems] ABB security advisory (AV23-167)","uuid":"a1fe915a-b5ef-4fae-9a45-dc97cef045b7","banner":null,"lang":"en","date_modified":"2023-03-23","date_modified_ts":"2023-03-23T19:00:56Z","date_created":"2023-03-23T18:57:51Z","summary":null,"body":["<article data-history-node-id=\"4070\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-167\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-167<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 23, 2023<\/p>\n\n<p>On March 23, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Infinity DC Power Plant \u2013 version H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) \u2013 comcode 150047415<\/li>\n\t<li>ABB Pulsar Plus System Controller \u2013 version NE843_S \u2013 comcode 150042936<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-082-05\">ICS Advisory (ICSA-23-082-05)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-167","alert_type":398,"serial_number":"AV23-167","subject":null,"moderation_state":"published","external_url":null},{"nid":4074,"title":"[Control systems] ProPump and Controls security advisory (AV23-171)","uuid":"ac58ad87-ea64-4127-bdca-241eeb0ec0ee","banner":null,"lang":"en","date_modified":"2023-03-24","date_modified_ts":"2023-03-24T18:08:14Z","date_created":"2023-03-24T18:03:24Z","summary":null,"body":["<article data-history-node-id=\"4074\" about=\"\/en\/alerts-advisories\/control-systems-propump-and-controls-security-advisory-av23-171\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-171<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 24, 2023<\/p>\n\n<p>On March 23, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Osprey Pump Controll\u00a0\u2013 version 1.01<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to unauthorized access or a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-082-06\">ICS Advisory (ICSA-23-080-06)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-propump-and-controls-security-advisory-av23-171","alert_type":398,"serial_number":"AV23-171","subject":null,"moderation_state":"published","external_url":null},{"nid":4081,"title":"Ubuntu security advisory (AV23-172)","uuid":"eb27f908-9b82-440f-ac05-e7b7f9b127df","banner":null,"lang":"en","date_modified":"2023-03-27","date_modified_ts":"2023-03-27T18:59:12Z","date_created":"2023-03-27T18:53:38Z","summary":null,"body":["<article data-history-node-id=\"4081\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-172\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-172<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 27, 2023<\/p>\n\n<p>Between March 20 and March 26, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5970-1\">Ubuntu Security Notice (USN-5970-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-172","alert_type":396,"serial_number":"AV23-172","subject":null,"moderation_state":"published","external_url":null},{"nid":4082,"title":"Dell security advisory (AV23-173)","uuid":"d55717e6-2986-4d7c-aa98-3f9cb9a05872","banner":null,"lang":"en","date_modified":"2023-03-28","date_modified_ts":"2023-03-28T15:04:01Z","date_created":"2023-03-27T19:38:07Z","summary":null,"body":["<article data-history-node-id=\"4082\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-173\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-173<br \/><strong>Date: <\/strong>March\u00a028, 2023<\/p>\n\n<p>Between March\u00a020 and 26, 2023, Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PowerProtect DD DDOS and DDMC\u00a0\u2013 versions prior to 6.2.1.90 and version 7.0 to 7.10<\/li>\n\t<li>PowerProtect DD SmartScale\u00a0\u2013 version 7.8 to 7.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000211365\/dsa-2023-110-dell-technologies-powerprotect-dd-security-update-for-multiple-security-vulnerabilities\">Dell Security Advisory (DSA-2023-110)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-173","alert_type":396,"serial_number":"AV23-173","subject":null,"moderation_state":"published","external_url":null},{"nid":4083,"title":"IBM security advisory (AV23-174)","uuid":"027f2d9f-125f-4f2f-aae9-ae460193b7d3","banner":null,"lang":"en","date_modified":"2023-03-28","date_modified_ts":"2023-03-28T15:36:27Z","date_created":"2023-03-27T20:37:21Z","summary":null,"body":["<article data-history-node-id=\"4083\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-174\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-174<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 28, 2023<\/p>\n\n<p>Between March 20 and 26, 2023, IBM published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-174","alert_type":396,"serial_number":"AV23-174","subject":null,"moderation_state":"published","external_url":null},{"nid":4084,"title":"[Control systems] ABB security advisory (AV23-175)","uuid":"ccdfbc08-a6ed-4fe6-aebf-cc744075a5c2","banner":null,"lang":"en","date_modified":"2023-03-28","date_modified_ts":"2023-03-28T15:37:00Z","date_created":"2023-03-28T14:58:33Z","summary":null,"body":["<article data-history-node-id=\"4084\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-175\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-175<br \/><strong>Date: <\/strong>March\u00a028, 2023<\/p>\n\n<p>On March\u00a027, 2023, ABB published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>RCCMD\u00a0\u2013 versions prior to 4.40 230207<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2CMT006099_EN&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Security Advisory (2CMT006099)<\/a> (PDF)<\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-175","alert_type":398,"serial_number":"AV23-175","subject":null,"moderation_state":"published","external_url":null},{"nid":4085,"title":"Apple security advisory (AV23-176)","uuid":"b1fda94b-9a9f-4f24-a21d-167ef3fd01af","banner":null,"lang":"en","date_modified":"2023-03-28","date_modified_ts":"2023-03-28T17:53:27Z","date_created":"2023-03-28T17:15:56Z","summary":null,"body":["<article data-history-node-id=\"4085\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-176\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-176<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 28, 2023<\/p>\n\n<p>On March 27, 2023, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0- versions prior to 15.7.4<\/li>\n\t<li>iOS and iPadOS\u00a0- versions prior to 16.4<\/li>\n\t<li>macOS Big Sur\u00a0- versions prior to 11.7.5<\/li>\n\t<li>macOS Monterey\u00a0- versions prior to 12.6.4<\/li>\n\t<li>macOS Ventura\u00a0- versions prior to 13.3<\/li>\n\t<li>Safari\u00a0- versions prior to 16.4<\/li>\n\t<li>Studio Display Firmware Update\u00a0- versions prior to macOS Ventura 13.3<\/li>\n\t<li>tvOS\u00a0- versions prior to 16.4<\/li>\n\t<li>watchOS\u00a0- versions prior to 9.4<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution, privilege escalation or access to sensitive information.<\/p>\n\n<p>Apple has reported that CVE-2023-23529 may have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-176","alert_type":396,"serial_number":"AV23-176","subject":null,"moderation_state":"published","external_url":null},{"nid":4086,"title":"Mozilla security advisory (AV23-177)","uuid":"967af1c4-e0d5-423c-b8bf-44735f9e7fa7","banner":null,"lang":"en","date_modified":"2023-03-29","date_modified_ts":"2023-03-29T14:22:23Z","date_created":"2023-03-29T14:10:40Z","summary":null,"body":["<article data-history-node-id=\"4086\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-177\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-177<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 29, 2023<\/p>\n\n<p>On March 28, 2023, Mozilla published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Thunderbird\u00a0- versions prior to 102.9.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-12\/\">Mozilla Security Advisory (MFSA 2023-12)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-177","alert_type":396,"serial_number":"AV23-177","subject":null,"moderation_state":"published","external_url":null},{"nid":4090,"title":"Supply chain compromise impacting 3CXDesktopApp","uuid":"f0cbd569-47a1-48c4-a03b-041649b89f4f","banner":null,"lang":"en","date_modified":"2023-03-30","date_modified_ts":"2023-03-30T20:31:11Z","date_created":"2023-03-30T15:38:09Z","summary":null,"body":["<article data-history-node-id=\"4090\" about=\"\/en\/alerts-advisories\/supply-chain-compromise-impacting-3cxdesktopapp\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-003<br \/><strong>Date:\u00a0<\/strong>March 30, 2023<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On March 29, 2023, security researchers published reports detailing a new supply chain compromise affecting the 3CXDesktopApp <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. The reports describe the researchers\u2019 observations of malicious activity originating from legitimately signed 3CXDesktopApp binaries.<\/p>\n\n<p>Reported malicious behaviours include beaconing to malicious infrastructure, deployment of second-stage payloads and hands-on-keyboard activity by the threat actors <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>3CXDesktopApp is available on multiple platforms, and reports currently indicate that both Windows and MacOS versions are affected <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. In particular, 3CX has identified the following versions as being affected <sup id=\"fn4a-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>:<\/p>\n\n<ul><li>3CXDesktopApp for Windows\u00a0\u2013 versions 18.12.407 and 18.12.416<\/li>\n\t<li>3CXDesktopApp for Mac\u00a0\u2013 versions 18.11.1213, 18.12.402 and 18.12.416<\/li>\n<\/ul><p>At the time of this report, the primary impact reported due to this compromise is the theft of system and browser information, including browsing history <sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. The Cyber Centre is aware of reports that credentials stored in the browser may have also been stolen <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<h2>Recommended actions<\/h2>\n\n<p>Organizations are encouraged to identify and isolate any systems having deployed the 3CXDesktopApp. Security researchers have published several indicators of compromise (IOCs) to aid network defenders in the detection of malicious activity <sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2b-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>3CX recommends that the client-based electron app is uninstalled from systems and that customers instead use the priority web application (PWA), a web-based client, to ensure that the latest updates are installed <sup id=\"fn4b-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre wishes to highlight that mitigation efforts resulting from the compromise of systems by competent threat actors may require more than simply mitigating individual issues, systems and servers. In cases such as these, based on the perceived sophistication of the threat actor involved, organizations should consider additional mitigative efforts besides simply the removal or updating of the product. The Cyber Centre recommends affected customers review the Cyber Centre joint cybersecurity advisory on technical approaches to uncovering and remediating malicious activity <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>Should activity matching the content of this Alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, email (<a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>) or telephone (1-833-CYBER-88 or <a href=\"tel:1-833-292-3788\">1-833-292-3788<\/a>).<\/p>\n<!-- ENDNOTES SECTION -->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.crowdstrike.com\/blog\/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers\/\">CrowdStrike Falcon Platform Detects and Prevents Active Intrusion Campaign Targeting 3CXDesktopApp Customers<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.sentinelone.com\/blog\/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack\/\">Ongoing Campaign Trojanizes 3CXDesktopApp in Supply Chain Attack<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/news-events\/joint-cybersecurity-advisory\">Joint Cyber Security Advisory \u2013 Technical Approaches to Uncovering and Remediating Malicious Activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.3cx.com\/blog\/news\/desktopapp-security-alert-updates\/\">3CX DesktopApp Security Alert<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack\/\">Hackers compromise 3CX desktop app in a supply chain attack<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/news.sophos.com\/en-us\/2023\/03\/29\/3cx-dll-sideloading-attack\/\">3CX DLL Sideloading Attack<\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/supply-chain-compromise-impacting-3cxdesktopapp","alert_type":397,"serial_number":"AL23-003","subject":null,"moderation_state":"published","external_url":null},{"nid":4089,"title":"[Control systems] Hitachi Energy security advisory (AV23-178)","uuid":"0d3b9422-ae66-41bd-85fa-2140bc9c865d","banner":null,"lang":"en","date_modified":"2023-03-30","date_modified_ts":"2023-03-30T19:24:02Z","date_created":"2023-03-30T19:17:57Z","summary":null,"body":["<article data-history-node-id=\"4089\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-178\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-178<br \/><strong>Date: <\/strong>March\u00a030, 2023<\/p>\n\n<p>On March\u00a030, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Hitachi Energy IEC 61850 MMS-Server<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-089-01 \">ICS Advisory (ICSA-23-089-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-178","alert_type":398,"serial_number":"AV23-178","subject":null,"moderation_state":"published","external_url":null},{"nid":4091,"title":"Apple security advisory (AV23-179)","uuid":"3e93d487-74b5-4d8e-b31d-2d6617bf6db9","banner":null,"lang":"en","date_modified":"2023-03-31","date_modified_ts":"2023-03-31T17:31:18Z","date_created":"2023-03-31T17:10:55Z","summary":null,"body":["<article data-history-node-id=\"4091\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-179\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-179\n  <br \/><strong>Date: <\/strong>March\u00a031, 2023\n<\/p>\n<p>On March\u00a030, 2023, Apple published a Security Update to address vulnerabilities in the following product:\n<\/p>\n<ul><li>Xcode\u00a0\u2013 versions prior to 14.3<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution or access to sensitive information.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-179","alert_type":396,"serial_number":"AV23-179","subject":null,"moderation_state":"published","external_url":null},{"nid":4092,"title":"[Control systems] ABB security advisory (AV23-180)","uuid":"88513ae8-42e1-4b3e-aeed-aa78fd15738a","banner":null,"lang":"en","date_modified":"2023-03-31","date_modified_ts":"2023-03-31T18:32:14Z","date_created":"2023-03-31T18:25:55Z","summary":null,"body":["<article data-history-node-id=\"4092\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-180\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-180<br \/><strong>Date: <\/strong>March\u00a031, 2023<\/p>\n\n<p>On March\u00a031, 2023, ABB published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AC500 V2\u00a0\u2013 firmware versions prior to 2.8.6<\/li>\n\t<li>Flow-X\u00a0\u2013 firmware versions 3.2.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108467A9754\">ABB Advisory (9AKK108467A9754)<\/a> (PDF)<\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011162\">ABB Advisory (3ADR011162)<\/a> (PDF)<\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-180","alert_type":398,"serial_number":"AV23-180","subject":null,"moderation_state":"published","external_url":null},{"nid":4093,"title":"Dell security advisory (AV23-181)","uuid":"41394447-0c3a-48db-9fbd-44859faffbea","banner":null,"lang":"en","date_modified":"2023-04-03","date_modified_ts":"2023-04-03T17:35:51Z","date_created":"2023-04-03T17:29:55Z","summary":null,"body":["<article data-history-node-id=\"4093\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-181\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-181<br \/><strong>Date: <\/strong>April\u00a03, 2023<\/p>\n\n<p>Between March\u00a027 and April\u00a02, 2023, Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Streaming Data Platform\u00a0\u2013 versions 1.1.x, 1.2.x, 1.3.x, 1.4.x and 1.5.x<\/li>\n\t<li>PowerScale OneFS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000211636\/dsa-2023-086-dell-streaming-data-platform-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update (DSA-2023-086)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000211539\/dell-emc-powerscale-onefs-security\">Dell Security Update (DSA-2023-102)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-181","alert_type":396,"serial_number":"AV23-181","subject":null,"moderation_state":"published","external_url":null},{"nid":4094,"title":"Ubuntu security advisory (AV23-182)","uuid":"f2555298-b52e-4b36-bc43-006f1cbf4c9d","banner":null,"lang":"en","date_modified":"2023-04-03","date_modified_ts":"2023-04-03T17:47:34Z","date_created":"2023-04-03T17:29:55Z","summary":null,"body":["<article data-history-node-id=\"4094\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-182\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-182<br \/><strong>Date: <\/strong>April\u00a03, 2023<\/p>\n\n<p>Between March\u00a027 and April\u00a02, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-182","alert_type":396,"serial_number":"AV23-182","subject":null,"moderation_state":"published","external_url":null},{"nid":4096,"title":"Android security advisory \u2013 April 2023 monthly rollup (AV23-185)","uuid":"16dae94e-709d-4c03-ab9d-0752ac41361b","banner":null,"lang":"en","date_modified":"2023-04-04","date_modified_ts":"2023-04-04T14:14:07Z","date_created":"2023-04-03T20:22:01Z","summary":null,"body":["<article data-history-node-id=\"4096\" about=\"\/en\/alerts-advisories\/android-security-advisory-april-2023-monthly-rollup-av23-185\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-185<br \/><strong>Date: <\/strong>April\u00a04, 2023<\/p>\n\n<p>On April\u00a03, 2023, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-04-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-april-2023-monthly-rollup-av23-185","alert_type":396,"serial_number":"AV23-185","subject":null,"moderation_state":"published","external_url":null},{"nid":4095,"title":"Trellix security advisory (AV23-184)","uuid":"21736e12-685d-421e-9a68-fa04b0b0734d","banner":null,"lang":"en","date_modified":"2023-04-04","date_modified_ts":"2023-04-04T14:13:27Z","date_created":"2023-04-03T20:22:47Z","summary":null,"body":["<article data-history-node-id=\"4095\" about=\"\/en\/alerts-advisories\/trellix-security-advisory-av23-184\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-184<br \/><strong>Date: <\/strong>April\u00a04, 2023<\/p>\n\n<p>On March\u00a030, 2023, Trellix published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Trellix Agent (Windows and Linux)\u00a0\u2013 version 5.7.8 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kcm.trellix.com\/corporate\/index?page=content&amp;id=SB10396\">Trellix Security Advisory (SB10396)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportm.trellix.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter\">Trellix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trellix-security-advisory-av23-184","alert_type":396,"serial_number":"AV23-184","subject":null,"moderation_state":"published","external_url":null},{"nid":4097,"title":"IBM security advisory (AV23-183)","uuid":"93f37a07-64d3-4523-8ba3-0390466a636a","banner":null,"lang":"en","date_modified":"2023-04-03","date_modified_ts":"2023-04-03T20:55:46Z","date_created":"2023-04-03T20:24:14Z","summary":null,"body":["<article data-history-node-id=\"4097\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-183\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-183<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 4, 2023<\/p>\n\n<p>Between March 27 and April 2, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 versions 2.3.0.1, 2.3.1.0 (Intel), 2.3 and 2.3.3.0 to 2.3.3.5 (Intel)<\/li>\n\t<li>IBM Cloud Pak System Software Suite\u00a0\u2013 version 2.3.3.0 to 2.3.3.5<\/li>\n\t<li>IBM Tivoli Monitoring\u00a0\u2013 version 6.3.0 Fix Pack 7 Service Pack 5 (or later Service Pack)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6967877\">IBM Security Bulletin\u00a0- 6967877<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6967193\">IBM Security Bulletin\u00a0- 6967193<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6967183\">IBM Security Bulletin\u00a0- 6967183<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6967187\">IBM Security Bulletin\u00a0- 6967187<\/a><\/li>\n\t<!-- awaiting three links-->\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6967237\">IBM Security Bulletin\u00a0- 6967237<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-183","alert_type":396,"serial_number":"AV23-183","subject":null,"moderation_state":"published","external_url":null},{"nid":4099,"title":"Google Chrome security advisory (AV23-187)","uuid":"336d5659-1056-4c1e-9f73-6c1b7879129d","banner":null,"lang":"en","date_modified":"2023-04-05","date_modified_ts":"2023-04-05T18:41:33Z","date_created":"2023-04-05T17:34:24Z","summary":null,"body":["<article data-history-node-id=\"4099\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-187\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-187<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 5, 2023<\/p>\n\n<p>On April 4, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 112.0.5615.49 (Linux and Mac) and 112.0.5615.49\/50 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/04\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-187","alert_type":396,"serial_number":"AV23-187","subject":null,"moderation_state":"published","external_url":null},{"nid":4098,"title":"[Control systems] Nexx Smart Home security advisory (AV23-186)","uuid":"b69ffae3-efd6-48af-a711-83b781eafa02","banner":null,"lang":"en","date_modified":"2023-04-05","date_modified_ts":"2023-04-05T17:47:42Z","date_created":"2023-04-05T17:37:35Z","summary":null,"body":["<article data-history-node-id=\"4098\" about=\"\/en\/alerts-advisories\/control-systems-nexx-smart-home-security-advisory-av23-186\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-186<br \/><strong>Date: <\/strong>April\u00a05, 2023<\/p>\n\n<p>On April\u00a04, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Nexx Garage Door Controller (NXG-100B, NXG-200)\u00a0\u2013 version nxg200v-p3-4-1 and prior<\/li>\n\t<li>Nexx Smart Plug (NXPG-100W)\u00a0\u2013 version nxpg100cv4-0-0 and prior<\/li>\n\t<li>Nexx Smart Alarm (NXAL-100)\u00a0\u2013 version nxal100v-p1-9-1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to information disclosure, code execution or device hijacking.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-094-01\">ICS Advisory\u00a0- ICSA-23-094-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-nexx-smart-home-security-advisory-av23-186","alert_type":398,"serial_number":"AV23-186","subject":null,"moderation_state":"published","external_url":null},{"nid":4100,"title":"Red Hat security advisory (AV23-188)","uuid":"779bd749-755f-4041-ab86-b18310671c2f","banner":null,"lang":"en","date_modified":"2023-04-05","date_modified_ts":"2023-04-05T20:33:57Z","date_created":"2023-04-05T20:28:04Z","summary":null,"body":["<article data-history-node-id=\"4100\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-188\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-188<br \/><strong>Date: <\/strong>April\u00a05, 2023<\/p>\n\n<p>Between March\u00a021 and April\u00a05, 2023, Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories?q=&amp;p=2&amp;sort=portal_publication_date%20desc&amp;rows=10&amp;portal_advisory_type=Security%20Advisory&amp;documentKind=PortalProduct\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-188","alert_type":396,"serial_number":"AV23-188","subject":null,"moderation_state":"published","external_url":null},{"nid":4101,"title":"Cisco security advisory (AV23-189)","uuid":"10e8af62-10d3-4489-ab41-70a775dc1c3d","banner":null,"lang":"en","date_modified":"2023-04-06","date_modified_ts":"2023-04-06T18:34:02Z","date_created":"2023-04-06T18:08:28Z","summary":null,"body":["<article data-history-node-id=\"4101\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-189\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-189<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 6, 2023<\/p>\n\n<p>On April 5, 2023, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Evolved Programmable Network Manager\u00a0\u2013 version 7.0.0 and prior<\/li>\n\t<li>Cisco Identity Services Engine\u00a0\u2013 version 3.2<\/li>\n\t<li>Cisco Secure Network Analytics\u00a0\u2013 version 7.4.1 and prior<\/li>\n\t<li>Cisco Prime Infrastructure\u00a0\u2013 versions prior to 3.10.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-stealthsmc-rce-sfNBPjcS\">Cisco Security Advisory\u00a0- cisco-sa-stealthsmc-rce-sfNBPjcS<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-adeos-MLAyEcvk\">Cisco Security Advisory\u00a0- cisco-sa-adeos-MLAyEcvk<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-189","alert_type":396,"serial_number":"AV23-189","subject":null,"moderation_state":"published","external_url":null},{"nid":4102,"title":"Sophos security advisory (AV23-190)","uuid":"5e265c32-bc6a-4bd1-a37c-063edb53aec7","banner":null,"lang":"en","date_modified":"2023-04-06","date_modified_ts":"2023-04-06T19:06:33Z","date_created":"2023-04-06T18:50:16Z","summary":null,"body":["<article data-history-node-id=\"4102\" about=\"\/en\/alerts-advisories\/sophos-security-advisory-av23-190\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-190<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 6, 2023<\/p>\n\n<p>On April 4, 2023, Sophos published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Sophos Web Appliance\u00a0\u2013 versions prior to 4.3.10.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sophos.com\/en-us\/security-advisories\/sophos-sa-20230404-swa-rce\">Sophos Security Advisory\u00a0- sophos-sa-20230404-swa-rce<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sophos-security-advisory-av23-190","alert_type":396,"serial_number":"AV23-190","subject":null,"moderation_state":"published","external_url":null},{"nid":4103,"title":"[Control systems] ABB security advisory (AV23-191)","uuid":"09c51d3b-49c2-47d4-a869-4d05fe8fd59a","banner":null,"lang":"en","date_modified":"2023-04-06","date_modified_ts":"2023-04-06T20:10:24Z","date_created":"2023-04-06T19:45:56Z","summary":null,"body":["<article data-history-node-id=\"4103\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-191\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-191<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 6, 2023<\/p>\n\n<p>On April 6, 2023, ABB published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>My Control System (on-premise)\u00a0\u2013 versions 5.0 to 5.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA007893\">ABB Advisory\u00a0- 7PAA007893 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-191","alert_type":398,"serial_number":"AV23-191","subject":null,"moderation_state":"published","external_url":null},{"nid":4104,"title":"[Control systems] mySCADA security advisory (AV23-192)","uuid":"bc8a1dd4-73e7-4519-98f4-6e8c70bbff8c","banner":null,"lang":"en","date_modified":"2023-04-06","date_modified_ts":"2023-04-06T20:27:05Z","date_created":"2023-04-06T20:18:16Z","summary":null,"body":["<article data-history-node-id=\"4104\" about=\"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-av23-192\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-192<br \/><strong>Date: <\/strong>April\u00a06, 2023<\/p>\n\n<p>On April\u00a06, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>mySCADA myPRO\u00a0\u2013 version 8.26.0 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary command execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-096-06\">ICS Advisory\u00a0- ICSA-23-096-06<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-myscada-security-advisory-av23-192","alert_type":398,"serial_number":"AV23-192","subject":null,"moderation_state":"published","external_url":null},{"nid":4105,"title":"[Control systems] Korenix security advisory (AV23-193) ","uuid":"7892e48f-3246-4d63-9aa4-55df479d6d93","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T12:10:58Z","date_created":"2023-04-11T12:05:52Z","summary":null,"body":["<article data-history-node-id=\"4105\" about=\"\/en\/alerts-advisories\/control-systems-korenix-security-advisory-av23-193\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-193<br \/><strong>Date: <\/strong>April\u00a011,\u00a02023<\/p>\n\n<p>On April\u00a06,\u00a02023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Korenix Jetwave \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary command execution or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-096-04\">ICS Advisory - ICSA-23-096-04<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-korenix-security-advisory-av23-193","alert_type":398,"serial_number":"AV23-193","subject":null,"moderation_state":"published","external_url":null},{"nid":4107,"title":"[Control systems] Industrial Control Links security advisory (AV23-194)","uuid":"f0a8a73b-1c19-4fbc-b566-8f6d7a03738f","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T13:34:44Z","date_created":"2023-04-11T13:21:28Z","summary":null,"body":["<article data-history-node-id=\"4107\" about=\"\/en\/alerts-advisories\/control-systems-industrial-control-links-security-advisory-av23-194\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-194<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 11, 2023<\/p>\n\n<p>On April 6, 2023, CISA published an ICS Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ScadaFlex II SCADA Controllers\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-096-01\">ICS Advisory\u00a0- ICSA-23-096-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-industrial-control-links-security-advisory-av23-194","alert_type":398,"serial_number":"AV23-194","subject":null,"moderation_state":"published","external_url":null},{"nid":4108,"title":"[Control systems] Hitachi Energy security advisory (AV23-195) ","uuid":"a2133690-3a43-409c-abc5-99ad75f734f6","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T13:38:49Z","date_created":"2023-04-11T13:28:46Z","summary":null,"body":["<article data-history-node-id=\"4108\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-195\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-195<br \/><strong>Date: <\/strong>April\u00a011, 2023<\/p>\n\n<p>On April\u00a06, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MicroSCADA System Data Manager SDM600\u00a0\u2013 versions prior to v1.2 FP3 HF4 (Build Nr.\u00a01.2.23000.291) and prior to v1.3.0 (Build Nr.\u00a01.3.0.1339)<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution, information disclosure, privilege escalation or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-096-05\">ICS Advisory\u00a0- ICSA-23-096-05<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-195","alert_type":398,"serial_number":"AV23-195","subject":null,"moderation_state":"published","external_url":null},{"nid":4109,"title":"[Control systems] JTEKT Electronics security advisory (AV23-196)","uuid":"67773694-42b2-4b13-8b30-178ef83025ad","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T13:48:32Z","date_created":"2023-04-11T13:28:53Z","summary":null,"body":["<article data-history-node-id=\"4109\" about=\"\/en\/alerts-advisories\/control-systems-jtekt-electronics-security-advisory-av23-196\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-196<br \/><strong>Date: <\/strong>April\u00a011, 2023<\/p>\n\n<p>On April\u00a06, 2023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Kostac PLC Programming Software\u00a0\u2013 version 1.6.9.0 and prior<\/li>\n\t<li>Screen Creator Advance 2\u00a0\u2013 version 0.1.1.4 Build01<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-096-02\">ICS Advisory\u00a0- ICSA-23-096-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-096-03\">ICS Advisory\u00a0- ICSA-23-096-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-jtekt-electronics-security-advisory-av23-196","alert_type":398,"serial_number":"AV23-196","subject":null,"moderation_state":"published","external_url":null},{"nid":4110,"title":"Apple security advisory (AV23-197)","uuid":"fe519150-36e1-436f-b40e-45c51dd49a50","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T14:12:26Z","date_created":"2023-04-11T13:58:35Z","summary":null,"body":["<article data-history-node-id=\"4110\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-197\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-197<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 11, 2023<\/p>\n\n<p>On April 7 and 10, 2023, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0- versions prior to 15.7.5 and 16.4.1<\/li>\n\t<li>macOS Big Sur\u00a0- versions prior to 11.7.6<\/li>\n\t<li>macOS Monterey\u00a0- versions prior to 12.6.5<\/li>\n\t<li>macOs Ventura\u00a0- versions prior to 13.3.1<\/li>\n\t<li>Safari\u00a0- versions prior to 16.4.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>Apple has received reports that these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-197","alert_type":396,"serial_number":"AV23-197","subject":null,"moderation_state":"published","external_url":null},{"nid":4111,"title":"IBM security advisory (AV23-199)","uuid":"fb950cc3-93a0-4a2f-b5a8-f53ed1ab1592","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T15:19:03Z","date_created":"2023-04-11T14:01:27Z","summary":null,"body":["<article data-history-node-id=\"4111\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-199\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-199<br \/><strong>Date: <\/strong>April\u00a011, 2023<\/p>\n\n<p>Between April\u00a03 and 10, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Automation Assets in IBM Cloud Pak for Integration (CP4I)\u00a0\u2013 multiple versions<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (CP4I)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6982851\">IBM Security Bulletin\u00a0\u2013 6982851<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-199","alert_type":396,"serial_number":"AV23-199","subject":null,"moderation_state":"published","external_url":null},{"nid":4112,"title":"Dell security advisory (AV23-200)","uuid":"ad7216ad-0cd6-46b6-a903-cd59732c933e","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T15:20:37Z","date_created":"2023-04-11T14:01:28Z","summary":null,"body":["<article data-history-node-id=\"4112\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-200\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-200<br \/><strong>Date: <\/strong>April\u00a011, 2023<\/p>\n\n<p>Between April\u00a03 and 10, 2023, Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerProtect Data Manager\u00a0\u2013 version 19.12 and prior<\/li>\n\t<li>PowerStore T OS\u00a0\u2013 versions prior to 3.2.1.0-1989710<\/li>\n\t<li>PowerStore X OS\u00a0\u2013 versions prior to 3.2.1.0-1989710<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000211965\/dsa-2023-127-dell-powerprotect-data-manager-security-update-for-multiple-security-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-127<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000212002\/dsa-2023-129-dell-powerstore-family-security-update-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-129<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-200","alert_type":396,"serial_number":"AV23-200","subject":null,"moderation_state":"published","external_url":null},{"nid":4113,"title":"Ubuntu security advisory (AV23-198)","uuid":"53c2c515-fe67-4df0-9b83-c81742f62fa0","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T14:50:29Z","date_created":"2023-04-11T14:35:01Z","summary":null,"body":["<article data-history-node-id=\"4113\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-198\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-198<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 11, 2023<\/p>\n\n<p>Between April 3 and 10, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6000-1\">Ubuntu Security Notice\u00a0- USN-6000-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6001-1\">Ubuntu Security Notice\u00a0- USN-6001-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-198","alert_type":396,"serial_number":"AV23-198","subject":null,"moderation_state":"published","external_url":null},{"nid":4114,"title":"[Control systems] Siemens security advisory (AV23-201) ","uuid":"fb7871a1-95eb-4720-8d3e-9991eb31b89c","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T15:45:23Z","date_created":"2023-04-11T15:36:39Z","summary":null,"body":["<article data-history-node-id=\"4114\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-201\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-201<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 11, 2023<\/p>\n\n<p>On April 11, 2023, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>CP-8031 MASTER MODULE (6MF2803-1AA00)\u00a0\u2013 versions prior to CPCI85 V05<\/li>\n\t<li>CP-8050 MASTER MODULE (6MF2805-0AA00)\u00a0\u2013 versions prior to CPCI85 V05<\/li>\n\t<li>SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SIPLUS NET SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-201","alert_type":398,"serial_number":"AV23-201","subject":null,"moderation_state":"published","external_url":null},{"nid":4115,"title":"[Control systems] Schneider Electric security advisory (AV23-202)","uuid":"34e4caae-b2f6-4b72-9e79-2e908a12c259","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T16:03:12Z","date_created":"2023-04-11T15:40:33Z","summary":null,"body":["<article data-history-node-id=\"4115\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-202\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-202<br \/><strong>Date: <\/strong>April\u00a011, 2023<\/p>\n\n<p>On April\u00a011, 2023, Schneider Electric published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>APC Easy UPS Online Monitoring Software\u00a0\u2013 version 2.5-GA-01-22320 and prior<\/li>\n\t<li>Easergy Builder installer\u00a0\u2013 version 1.7.23 and prior<\/li>\n\t<li>EcoStruxure Control Expert\u00a0\u2013 versions 15.1 and later<\/li>\n\t<li>HMISCU Controller\u00a0\u2013 all versions<\/li>\n\t<li>InsightHome\/InsightFacility\/Context Gateway\u00a0\u2013 version 1.16 build 004 and prior<\/li>\n\t<li>Modicon PLCs\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>PacDrive\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Schneider Electric Easy UPS Online Monitoring Software\u00a0\u2013 version 2.5-GA-01-22320 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-202","alert_type":398,"serial_number":"AV23-202","subject":null,"moderation_state":"published","external_url":null},{"nid":4117,"title":"Mozilla Security Advisory (AV23-203)","uuid":"36c01ccf-78cf-4afa-ac58-4d2ab86bc250","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T17:31:54Z","date_created":"2023-04-11T15:40:33Z","summary":null,"body":["<article data-history-node-id=\"4117\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-203\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-203<br \/><strong>Date: <\/strong>April\u00a011, 2023<\/p>\n\n<p>On April\u00a011, 2023, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0- versions prior to 112<\/li>\n\t<li>Firefox for Android\u00a0- versions prior to 112<\/li>\n\t<li>Firefox ESR\u00a0- versions prior to 102.10<\/li>\n\t<li>Focus for Android\u00a0- versions prior to 112<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-13\/\">Mozilla Security Advisory (MFSA 2023-13)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-14\/\">Mozilla Security Advisory (MFSA 2023-14)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-203","alert_type":396,"serial_number":"AV23-203","subject":null,"moderation_state":"published","external_url":null},{"nid":4116,"title":"SAP security advisory \u2013 April 2023 monthly rollup (AV23-204)","uuid":"b5c43513-1c2e-4e66-8e65-294699fcc3ee","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T17:54:49Z","date_created":"2023-04-11T15:53:53Z","summary":null,"body":["<article data-history-node-id=\"4116\" about=\"\/en\/alerts-advisories\/sap-security-advisory-april-2023-monthly-rollup-av23-204\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-204<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 11, 2023<\/p>\n\n<p>On April 11, 2023, SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Diagnostics Agent\u00a0\u2013 version 720<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform\u00a0\u2013 versions 420 and 430<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day\u00a0\u2013 April 2023 (PDF)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-april-2023-monthly-rollup-av23-204","alert_type":396,"serial_number":"AV23-204","subject":null,"moderation_state":"published","external_url":null},{"nid":4118,"title":"Fortinet security advisory (AV23-205)","uuid":"2d83dee1-beeb-493b-8448-f040ee4e56f6","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T18:14:47Z","date_created":"2023-04-11T18:00:17Z","summary":null,"body":["<article data-history-node-id=\"4118\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-205\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-205<br \/><strong>Date: <\/strong>April\u00a011, 2023<\/p>\n\n<p>On April\u00a011, 2023, Fortinet published Security Advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>FortiPresence\u00a0\u2013 versions 1.0, 1.1 and 1.2<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-22-355\">Fortinet PSIRT Advisory\u00a0- FG-IR-22-355<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-205","alert_type":396,"serial_number":"AV23-205","subject":null,"moderation_state":"published","external_url":null},{"nid":4119,"title":"Microsoft security advisory \u2013 April 2023 monthly rollup (AV23-206)","uuid":"83c35bac-6bc6-43b6-a271-5e9c03c8b864","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T19:59:09Z","date_created":"2023-04-11T18:44:36Z","summary":null,"body":["<article data-history-node-id=\"4119\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2023-monthly-rollup-av23-206\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-206<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 11, 2023<\/p>\n\n<p>On April 11, 2023, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Raw Image Extension\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 10\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-28252 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Apr\">April 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-april-2023-monthly-rollup-av23-206","alert_type":396,"serial_number":"AV23-206","subject":null,"moderation_state":"published","external_url":null},{"nid":4120,"title":"Novi Survey security advisory (AV23-207)","uuid":"7dad91c2-587a-4009-98fb-f93229cd2475","banner":null,"lang":"en","date_modified":"2023-04-11","date_modified_ts":"2023-04-11T20:22:34Z","date_created":"2023-04-11T20:15:55Z","summary":null,"body":["<article data-history-node-id=\"4120\" about=\"\/en\/alerts-advisories\/novi-survey-security-advisory-av23-207\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-207<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 11, 2023<\/p>\n\n<p>On April 10, 2023, Novi Survey published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Novi Survey\u00a0- versions prior to 8.9.43676<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/novisurvey.net\/blog\/novi-survey-security-advisory-apr-2023.aspx\">Novi Survey Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/novi-survey-security-advisory-av23-207","alert_type":396,"serial_number":"AV23-207","subject":null,"moderation_state":"published","external_url":null},{"nid":4122,"title":"Adobe security advisory (AV23-208)","uuid":"87e6da2d-89a3-48c4-ad07-3e962c4b88f6","banner":null,"lang":"en","date_modified":"2023-04-12","date_modified_ts":"2023-04-12T14:24:21Z","date_created":"2023-04-12T14:13:47Z","summary":null,"body":["<article data-history-node-id=\"4122\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-208\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-208<br \/><strong>Date: <\/strong>April\u00a012, 2023<\/p>\n\n<p>On April\u00a011, 2023, Adobe published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat 2020\u00a0\u2013 version 20.005.30441 and prior<\/li>\n\t<li>Acrobat DC\u00a0\u2013 version 23.001.20093 and prior<\/li>\n\t<li>Adobe Digital Editions\u00a0\u2013 version 4.5.11.187303 and prior<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 3.4.8 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 17.4 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 18.1 and prior<\/li>\n\t<li>Acrobat Reader 2020\u00a0\u2013 version 20.005.30441 and prior<\/li>\n\t<li>Acrobat Reader DC\u00a0\u2013 version 23.001.20093 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version 12.4.0 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 2.0.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/security-bulletin.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-208","alert_type":396,"serial_number":"AV23-208","subject":null,"moderation_state":"published","external_url":null},{"nid":4123,"title":"Drupal security advisory (AV23-209)","uuid":"ae1588cd-f238-4026-9206-4a689995cde5","banner":null,"lang":"en","date_modified":"2023-04-12","date_modified_ts":"2023-04-12T18:58:41Z","date_created":"2023-04-12T18:54:13Z","summary":null,"body":["<article data-history-node-id=\"4123\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av23-209\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-209<br \/><strong>Date:<\/strong> April 12, 2023<\/p>\n\n<p>On April 12, 2023, Drupal published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Protected Pages module for Drupal 8\/9\/10\u00a0\u2013 versions prior to Protected Pages 8.x-1.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2023-013\">Drupal security advisory\u00a0- SA-CONTRIB-2023-013<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av23-209","alert_type":396,"serial_number":"AV23-209","subject":null,"moderation_state":"published","external_url":null},{"nid":4125,"title":"[Control Systems] FANUC security advisory (AV23-210)","uuid":"a3ba9809-fe57-40d9-a6b5-0b667fffc7f1","banner":null,"lang":"en","date_modified":"2023-04-13","date_modified_ts":"2023-04-13T15:17:24Z","date_created":"2023-04-13T15:11:04Z","summary":null,"body":["<article data-history-node-id=\"4125\" about=\"\/en\/alerts-advisories\/control-systems-fanuc-security-advisory-av23-210\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-210<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 13, 2023<\/p>\n\n<p>On April 11, 2023, CISA published an ICS Security Advisory to address a vulnerability in the following product\u00a0:<\/p>\n\n<ul><li>ROBOGUIDE-HandlingPRO\u00a0- version 9 Rev.ZD and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-101-01\">ICS Advisory\u00a0- ICSA-23-101-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fanuc-security-advisory-av23-210","alert_type":398,"serial_number":"AV23-210","subject":null,"moderation_state":"published","external_url":null},{"nid":4129,"title":"[Control systems] Datakit security advisory (AV23-212)","uuid":"efa4a51f-45c0-4a9d-853e-6289dae3f4a9","banner":null,"lang":"en","date_modified":"2023-04-14","date_modified_ts":"2023-04-14T13:19:00Z","date_created":"2023-04-14T13:13:49Z","summary":null,"body":["<article data-history-node-id=\"4129\" about=\"\/en\/alerts-advisories\/control-systems-datakit-security-advisory-av23-212\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-212<br \/><strong>Date: <\/strong>April\u00a014, 2023<\/p>\n\n<p>On April\u00a013, 2023, CISA published ICS Advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>CrossCAD\/Ware_x64 library\u00a0\u2013 versions prior to 2023.1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution or information disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-103-14\">ICS Advisory\u00a0- ICSA-23-103-14<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-datakit-security-advisory-av23-212","alert_type":398,"serial_number":"AV23-212","subject":null,"moderation_state":"published","external_url":null},{"nid":4130,"title":"[Control systems] B. Braun security advisory (AV23-213)","uuid":"7353605a-d511-4d40-8ae0-52e7f03db0d4","banner":null,"lang":"en","date_modified":"2023-04-14","date_modified_ts":"2023-04-14T13:30:30Z","date_created":"2023-04-14T13:26:37Z","summary":null,"body":["<article data-history-node-id=\"4130\" about=\"\/en\/alerts-advisories\/control-systems-b-braun-security-advisory-av23-213\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-213\n  <br \/><strong>Date: <\/strong>April\u00a014,\u00a02023\n<\/p>\n<p>On April\u00a013,\u00a02023, CISA published ICS Advisories to address a vulnerability in the following product:\n<\/p>\n<ul><li>Battery pack SP with Wi-Fi (SN 138853 and higher) \u2013 software versions 053L000091 (global), 054U000091 (U.S.), 053L000092 (global) and 054U000092 (U.S.)<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to unauthorized access.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-103-01\">ICS Advisory \u2013 ICSMA-23-103-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-b-braun-security-advisory-av23-213","alert_type":398,"serial_number":"AV23-213","subject":null,"moderation_state":"published","external_url":null},{"nid":4131,"title":"[Control systems] ABB security advisory (AV23-214)","uuid":"1ac047a0-9d8f-499d-b0ea-abbfb8d116e4","banner":null,"lang":"en","date_modified":"2023-04-14","date_modified_ts":"2023-04-14T13:33:50Z","date_created":"2023-04-14T13:28:05Z","summary":null,"body":["<article data-history-node-id=\"4131\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-214\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-214<br \/><strong>Date: <\/strong>April\u00a014, 2023<\/p>\n\n<p>On April\u00a014, 2023, ABB published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>B&amp;R VC4 visualization\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1681046878970-en-original-1.0.pdf\">ABB Advisory\u00a0- SA23P002 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-214","alert_type":398,"serial_number":"AV23-214","subject":null,"moderation_state":"published","external_url":null},{"nid":4133,"title":"[Control systems] Mitsubishi Electric India security advisory (AV23-211)","uuid":"6678ea85-54fb-41b6-ae6a-e3983b04cea0","banner":null,"lang":"en","date_modified":"2023-04-14","date_modified_ts":"2023-04-14T13:10:35Z","date_created":"2023-04-14T13:49:48Z","summary":null,"body":["<article data-history-node-id=\"4133\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-india-security-advisory-av23-211\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-211<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 14, 2023<\/p>\n\n<p>On April 13, 2023, CISA published ICS Advisories to address a vulnerability in the following product:<\/p>\n\n<ul><li>Mitsubishi Electric India GC-ENET-COM\u00a0\u2013 models with beginning serial number 16XXXXXXXXX<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-103-15\">ICS Advisory\u00a0- ICSA-23-103-15<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-india-security-advisory-av23-211","alert_type":398,"serial_number":"AV23-211","subject":null,"moderation_state":"published","external_url":null},{"nid":4134,"title":"Google Chrome Security Advisory (AV23-215)","uuid":"2a3858b4-c57e-4f8e-9161-5f91a5ae2458","banner":null,"lang":"en","date_modified":"2023-04-14","date_modified_ts":"2023-04-14T18:12:37Z","date_created":"2023-04-14T18:02:32Z","summary":null,"body":["<article data-history-node-id=\"4134\" about=\"\/en\/alerts-advisories\/av23-215-google-chrome-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-215<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 14, 2023<\/p>\n\n<p>On 14 April 2023 Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 112.0.5615.121<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2023-2033 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/04\/stable-channel-update-for-desktop_14.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/av23-215-google-chrome-security-advisory","alert_type":396,"serial_number":"AV23-215","subject":null,"moderation_state":"published","external_url":null},{"nid":4135,"title":"HPE security advisory (AV23-216)","uuid":"940c1f60-15a8-4787-b055-18cd011b43c8","banner":null,"lang":"en","date_modified":"2023-04-14","date_modified_ts":"2023-04-14T18:58:57Z","date_created":"2023-04-14T18:48:55Z","summary":null,"body":["<article data-history-node-id=\"4135\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-216\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-216<br \/><strong>Date: <\/strong>April\u00a014, 2023<\/p>\n\n<p>On April\u00a012, 2023, HPE published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HPE OneView\u00a0- version prior to 8.2 and 6.60.04 LTS<\/li>\n\t<li>HPE OneView Global Dashboard\u00a0- version prior to 2.72<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-216","alert_type":396,"serial_number":"AV23-216","subject":null,"moderation_state":"published","external_url":null},{"nid":4136,"title":"Juniper Networks security advisory (AV23-217)","uuid":"8aed674f-076f-452b-998d-c51eed4b6119","banner":null,"lang":"en","date_modified":"2023-04-14","date_modified_ts":"2023-04-14T19:06:03Z","date_created":"2023-04-14T18:58:31Z","summary":null,"body":["<article data-history-node-id=\"4136\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-217\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-217<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 14, 2023<\/p>\n\n<p>On April 12, 2023, Juniper Networks published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Juniper Networks Junos OS\u00a0- all versions<\/li>\n\t<li>Juniper Secure Analytics JSA Series\u00a0- versions prior to STRM 7.5.0UP4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy&amp;numberOfResults=100&amp;f:ctype=[Security%20Advisories\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-217","alert_type":396,"serial_number":"AV23-217","subject":null,"moderation_state":"published","external_url":null},{"nid":4137,"title":"Ubuntu security advisory (AV23-218)","uuid":"809d2c78-a237-40e3-a6b5-3512e6f27fbc","banner":null,"lang":"en","date_modified":"2023-04-17","date_modified_ts":"2023-04-17T14:48:52Z","date_created":"2023-04-17T14:32:27Z","summary":null,"body":["<article data-history-node-id=\"4137\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-218\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-218<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 17, 2023<\/p>\n\n<p>Between April 10 and 16, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-218","alert_type":396,"serial_number":"AV23-218","subject":null,"moderation_state":"published","external_url":null},{"nid":4138,"title":"Dell security advisory (AV23-219)","uuid":"d40f066d-59bc-410b-ab47-9c0154752f45","banner":null,"lang":"en","date_modified":"2023-04-17","date_modified_ts":"2023-04-17T15:21:27Z","date_created":"2023-04-17T14:55:20Z","summary":null,"body":["<article data-history-node-id=\"4138\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-219\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-219<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 17, 2023<\/p>\n\n<p>Between April 10 and 16, 2023, Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC SRM, EMC SRM Vapp, EMC SMR and EMC SMR Vapp\u00a0\u2013 versions prior to 4.9.0.0<\/li>\n\t<li>Dell Client BIOS\u00a0\u2013 multiple versions<\/li>\n\t<li>PowerProtect Cyber Recovery\u00a0\u2013 versions prior to 19.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000212409\/dsa-2023-140-dell-emc-cyber-recovery-security-update-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-140<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000212332\/dsa-2023-122-dell-emc-srm-and-dell-emc-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-122<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000212223\/dsa-2023-095\">Dell Security Update\u00a0- DSA-2023-095<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-219","alert_type":396,"serial_number":"AV23-219","subject":null,"moderation_state":"published","external_url":null},{"nid":4139,"title":"IBM security advisory (AV23-220)","uuid":"e9dcc373-21b2-40dd-96b7-e4028e488845","banner":null,"lang":"en","date_modified":"2023-04-17","date_modified_ts":"2023-04-17T15:40:24Z","date_created":"2023-04-17T15:29:34Z","summary":null,"body":["<article data-history-node-id=\"4139\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-220\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-220<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 17, 2023<\/p>\n\n<p>Between April 10 and 16, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>IBM Workload Scheduler\u00a0\u2013 versions 9.5 and 10.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6984157\">IBM Security Bulletin\u00a0- 6984157<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-220","alert_type":396,"serial_number":"AV23-220","subject":null,"moderation_state":"published","external_url":null},{"nid":4141,"title":"PaperCut security advisory (AV23-221)","uuid":"7aea523f-7031-49b2-adde-7d935dda5587","banner":null,"lang":"en","date_modified":"2023-04-18","date_modified_ts":"2023-04-18T18:10:31Z","date_created":"2023-04-18T18:03:49Z","summary":null,"body":["<article data-history-node-id=\"4141\" about=\"\/en\/alerts-advisories\/papercut-security-advisory-av23-221\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-221<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 18,\u00a02023<\/p>\n\n<p>In March 2023, PaperCut published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PaperCut MF\/NG\u00a0\u2013 version 8.0 and later, version 15.0 and later<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to remote code execution or information disclosure.<\/p>\n\n<p>PaperCut has indicated that these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.papercut.com\/kb\/Main\/PO-1216-and-PO-1219#zdi-can-19226-po-1219\">PaperCut Security Advisory\u00a0- March 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/papercut-security-advisory-av23-221","alert_type":396,"serial_number":"AV23-221","subject":null,"moderation_state":"published","external_url":null},{"nid":4143,"title":"Red Hat security advisory (AV23-222)","uuid":"5d148c94-6b5f-40ba-8dc6-3d4eb8c9f81f","banner":null,"lang":"en","date_modified":"2023-04-19","date_modified_ts":"2023-04-19T14:40:17Z","date_created":"2023-04-19T14:23:40Z","summary":null,"body":["<article data-history-node-id=\"4143\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-222\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-222\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 19, 2023\n<\/p>\n<p>On April 18, 2023, Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:\n<\/p>\n<ul><li>Red Hat CodeReady Linux Builder\u00a0- multiple versions and platforms<\/li>\n  <li>Red Hat Enterprise Linux\u00a0- multiple versions and platforms<\/li>\n  <li>Red Hat Enterprise Linux Server\u00a0- multiple versions and platforms<\/li>\n  <li>Red Hat Virtualization Host 4 for RHEL 8 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/#\/security-advisories?q=&amp;p=2&amp;sort=portal_publication_date%20desc&amp;rows=10&amp;portal_advisory_type=Security%20Advisory&amp;documentKind=PortalProduct\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-222","alert_type":396,"serial_number":"AV23-222","subject":null,"moderation_state":"published","external_url":null},{"nid":4144,"title":"Google Chrome security advisory (AV23-223)","uuid":"b9e3249e-807a-4834-b7da-443750816f7e","banner":null,"lang":"en","date_modified":"2023-04-19","date_modified_ts":"2023-04-19T15:30:14Z","date_created":"2023-04-19T14:47:52Z","summary":null,"body":["<article data-history-node-id=\"4144\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-223\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-223<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 19, 2023<\/p>\n\n<p>On April 18, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 112.0.5615.137\/138 (Windows) and 112.0.5615.137 (Mac)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2023-2136 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/04\/stable-channel-update-for-desktop_18.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-223","alert_type":396,"serial_number":"AV23-223","subject":null,"moderation_state":"published","external_url":null},{"nid":4145,"title":"[Control systems] Omron security advisory (AV23-224)","uuid":"b90d656e-a694-409d-926f-355da75eb394","banner":null,"lang":"en","date_modified":"2023-04-19","date_modified_ts":"2023-04-19T17:51:31Z","date_created":"2023-04-19T17:44:46Z","summary":null,"body":["<article data-history-node-id=\"4145\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av23-224\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-224<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 18, 2023<\/p>\n\n<p>On April 18, 2023, CISA published an ICS Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SYSMAC CJ2H-CPU6[]\u00a0-EIP\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CJ2H-CPU6[]\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CJ2M-CPU[][]\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CJ1G-CPU[][]P\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CS1H-CPU[][]H\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CS1G-CPU[][]H\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CS1D-CPU[][]HA\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CS1D-CPU[][]H\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CS1D-CPU[][]SA\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CS1D-CPU[][]S\u00a0\u2013 all versions<\/li>\n\t<li>SYSMAC CS1D-CPU[][]P\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-108-01\">ICS Advisory\u00a0- ICSA-23-108-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av23-224","alert_type":398,"serial_number":"AV23-224","subject":null,"moderation_state":"published","external_url":null},{"nid":4146,"title":"Oracle security advisory \u2013 April 2023 quarterly rollup (AV23-225)","uuid":"cc50d4e3-a3c4-4808-977a-f543a86410fa","banner":null,"lang":"en","date_modified":"2023-04-19","date_modified_ts":"2023-04-19T17:59:00Z","date_created":"2023-04-19T17:53:20Z","summary":null,"body":["<article data-history-node-id=\"4146\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-april-2023-quarterly-rollup-av23-225\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-225<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 18, 2023<\/p>\n\n<p>On April 18, 2023, Oracle published a Security Advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Construction and Engineering<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle GoldenGate<\/li>\n\t<li>Oracle Healthcare Applications<\/li>\n\t<li>Oracle Hyperion<\/li>\n\t<li>Oracle Insurance Applications<\/li>\n\t<li>Oracle JD Edwards<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle PeopleSoft<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Utilities Applications<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2023.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 April 2023<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-april-2023-quarterly-rollup-av23-225","alert_type":396,"serial_number":"AV23-225","subject":null,"moderation_state":"published","external_url":null},{"nid":4147,"title":"Cisco security advisory (AV23-226)","uuid":"7dd0bb07-9dac-49a8-a67a-aed3828982fe","banner":null,"lang":"en","date_modified":"2023-04-19","date_modified_ts":"2023-04-19T18:39:40Z","date_created":"2023-04-19T18:33:45Z","summary":null,"body":["<article data-history-node-id=\"4147\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-226\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-226<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 19, 2023<\/p>\n\n<p>On April 19, 2023, Cisco published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Industrial Network Director (IND)\u00a0\u2013 versions prior to 1.11.3<\/li>\n\t<li>Cisco Modeling Labs\u00a0\u2013 versions 2.3, 2.4 and 2.5<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to the execution of arbitrary commands, information disclosure or authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ind-CAeLFk6V\">Cisco Security Advisory\u00a0- cisco-sa-ind-CAeLFk6V<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cml-auth-bypass-4fUCCeG5\">Cisco Security Advisory\u00a0- cisco-sa-cml-auth-bypass-4fUCCeG5<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-226","alert_type":396,"serial_number":"AV23-226","subject":null,"moderation_state":"published","external_url":null},{"nid":4148,"title":"NVIDIA security advisory (AV23-227)","uuid":"f94d30a4-fdb6-4cd6-adfe-1423c87c082d","banner":null,"lang":"en","date_modified":"2023-04-19","date_modified_ts":"2023-04-19T18:45:39Z","date_created":"2023-04-19T18:41:48Z","summary":null,"body":["<article data-history-node-id=\"4148\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-av23-227\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-227<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 19, 2023<\/p>\n\n<p>Between April 18 and 19, 2023, NVIDIA published Security Bulletins to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>NVIDIA DGX-1 Servers \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution, denial of service, escalation of privileges, information disclosure or data modification.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5458\">NVIDIA Security Bulletin\u00a0- NVIDIA DGX-1\u00a0- April 2023<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-av23-227","alert_type":396,"serial_number":"AV23-227","subject":null,"moderation_state":"published","external_url":null},{"nid":4150,"title":"Microsoft Edge security advisory (AV23-228)","uuid":"58d4cbd3-f21f-4fe1-bb23-7fe2a3aacb60","banner":null,"lang":"en","date_modified":"2023-04-20","date_modified_ts":"2023-04-20T17:24:49Z","date_created":"2023-04-20T17:21:38Z","summary":null,"body":["<article data-history-node-id=\"4150\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-228\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-228<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 19, 2023<\/p>\n\n<p>On April 19, 2023, Microsoft published a Security Update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 112.0.1722.54<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2023-2136 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-19-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-228","alert_type":396,"serial_number":"AV23-228","subject":null,"moderation_state":"published","external_url":null},{"nid":4151,"title":"[Control systems] INEA security advisory (AV23-229)","uuid":"9a86ed45-319a-4a2d-ae4f-d4a89b9accb7","banner":null,"lang":"en","date_modified":"2023-04-20","date_modified_ts":"2023-04-20T18:19:51Z","date_created":"2023-04-20T18:16:18Z","summary":null,"body":["<article data-history-node-id=\"4151\" about=\"\/en\/alerts-advisories\/control-systems-inea-security-advisory-av23-229\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-229<br \/><strong>Date: <\/strong>April 20, 2023<\/p>\n\n<p>On April 20, 2023, CISA published an ICS Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ME RTU\u00a0\u2013 versions prior to 3.36<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-110-01\">ICS Advisory\u00a0- ICSA-23-110-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inea-security-advisory-av23-229","alert_type":398,"serial_number":"AV23-229","subject":null,"moderation_state":"published","external_url":null},{"nid":4152,"title":"VMware security advisory (AV23-230)","uuid":"ca273443-2051-4508-afe9-50591c73d40d","banner":null,"lang":"en","date_modified":"2023-04-20","date_modified_ts":"2023-04-20T18:25:09Z","date_created":"2023-04-20T18:21:08Z","summary":null,"body":["<article data-history-node-id=\"4152\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-230\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-230<br \/><strong>Date: <\/strong>April 20, 2023<\/p>\n\n<p>On April 20, 2023, VMware published a Security Advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>VMware Aria Operations for Logs (Operations for Logs)\u00a0\u2013 versions prior to 8.12<\/li>\n\t<li>VMware Cloud Foundation (VMware Aria Operations for Logs)\u00a0\u2013 version 4.x<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0007.html\">VMware Security Advisory\u00a0- VMSA-2023-0007<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-230","alert_type":396,"serial_number":"AV23-230","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4156,"title":"Microsoft Edge security advisory (AV23-231)","uuid":"cfd6d9e9-dbb1-47ac-a4f1-af3f2720ac94","banner":null,"lang":"en","date_modified":"2023-04-21","date_modified_ts":"2023-04-21T19:29:56Z","date_created":"2023-04-21T19:26:09Z","summary":null,"body":["<article data-history-node-id=\"4156\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-231\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-231<br \/><strong>Date: <\/strong>April 21, 2023<\/p>\n\n<p>On April 21, 2023, Microsoft published Security Updates to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 112.0.1722.58<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-21-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-231","alert_type":396,"serial_number":"AV23-231","subject":null,"moderation_state":"published","external_url":null},{"nid":4158,"title":"IBM security advisory (AV23-232)","uuid":"168da185-844f-4943-89e6-2ec2a262fc9d","banner":null,"lang":"en","date_modified":"2023-04-24","date_modified_ts":"2023-04-24T17:53:28Z","date_created":"2023-04-24T17:49:29Z","summary":null,"body":["<article data-history-node-id=\"4158\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-232\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-232<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 24, 2023<\/p>\n\n<p>Between April 17 and 23, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Network Automation\u00a0\u2013 versions 2.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6984171\">IBM Security Bulletin\u00a0\u2013 6984171<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-232","alert_type":396,"serial_number":"AV23-232","subject":null,"moderation_state":"published","external_url":null},{"nid":4159,"title":"Dell security advisory (AV23-233)","uuid":"f05cfb0c-29b7-4d89-ac0d-708154b4b4cb","banner":null,"lang":"en","date_modified":"2023-04-24","date_modified_ts":"2023-04-24T17:58:54Z","date_created":"2023-04-24T17:55:04Z","summary":null,"body":["<article data-history-node-id=\"4159\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-233\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-233<br \/><strong>Date: <\/strong>April 24, 2023<\/p>\n\n<p>Between April 17 and 23, 2023, Dell published a Security Advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell EMC Data Protection Central\u00a0\u2013 multiple versions<\/li>\n\t<li>PowerProtect DP Series Appliance\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000212544\/dsa-2023-143-dell-emc-data-protection-central-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update - DSA-2023-143<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-233","alert_type":396,"serial_number":"AV23-233","subject":null,"moderation_state":"published","external_url":null},{"nid":4160,"title":"Ubuntu security advisory (AV23-234)","uuid":"45a1e6e0-f067-4d07-8abe-6c768f6ed305","banner":null,"lang":"en","date_modified":"2023-04-24","date_modified_ts":"2023-04-24T18:03:16Z","date_created":"2023-04-24T17:59:29Z","summary":null,"body":["<article data-history-node-id=\"4160\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-234\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-234<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 24, 2023<\/p>\n\n<p>Between April 17 and 23, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-234","alert_type":396,"serial_number":"AV23-234","subject":null,"moderation_state":"published","external_url":null},{"nid":4161,"title":"[Control systems] Keysight security advisory (AV23-235)","uuid":"e4d56f29-bae6-44c0-adc4-720a75fbe173","banner":null,"lang":"en","date_modified":"2023-04-25","date_modified_ts":"2023-04-25T18:41:37Z","date_created":"2023-04-25T18:38:27Z","summary":null,"body":["<article data-history-node-id=\"4161\" about=\"\/en\/alerts-advisories\/control-systems-keysight-security-advisory-av23-235\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-235<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 25, 2023<\/p>\n\n<p>On April 25, 2023, CISA published an ICS Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>N8844A Data Analytics Web Service\u00a0\u2013 version 2.1.7351 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-115-01\">ICS Advisory\u00a0- ICSA-23-115-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-keysight-security-advisory-av23-235","alert_type":398,"serial_number":"AV23-235","subject":null,"moderation_state":"published","external_url":null},{"nid":4162,"title":"[Control systems] Scada-LTS security advisory (AV23-236)","uuid":"1272c9f5-75da-4467-940e-0d8e2a0e43fd","banner":null,"lang":"en","date_modified":"2023-04-25","date_modified_ts":"2023-04-25T18:49:48Z","date_created":"2023-04-25T18:46:42Z","summary":null,"body":["<article data-history-node-id=\"4162\" about=\"\/en\/alerts-advisories\/control-systems-scada-lts-security-advisory-av23-236\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-236<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong> April 25, 2023<\/p>\n\n<p>On April 25, 2023, CISA published an ICS Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Scada-LTS\u00a0\u2013 version 2.7.4 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution. CISA has indicated it is aware that public exploit code exists for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-115-02\">ICS Advisory\u00a0- ICSA-23-115-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-scada-lts-security-advisory-av23-236","alert_type":398,"serial_number":"AV23-236","subject":null,"moderation_state":"published","external_url":null},{"nid":4163,"title":"VMware security advisory (AV23-237)","uuid":"ef5c6f26-8bb2-4798-873e-78ed90043247","banner":null,"lang":"en","date_modified":"2023-04-25","date_modified_ts":"2023-04-25T18:56:33Z","date_created":"2023-04-25T18:53:30Z","summary":null,"body":["<article data-history-node-id=\"4163\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-237\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-237<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 25, 2023<\/p>\n\n<p>On April 25, 2023, VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Workstation Pro\u00a0\/\u00a0Player (Workstation) 17.x\u00a0\u2013 versions prior to 17.0.2<\/li>\n\t<li>VMware Fusion 13.x\u00a0\u2013 versions prior to 13.0.2<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0008.html\">VMware Security Advisory\u00a0- VMSA-2023-0008<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-237","alert_type":396,"serial_number":"AV23-237","subject":null,"moderation_state":"published","external_url":null},{"nid":4164,"title":"Red Hat security advisory (AV23-238)","uuid":"61a08a3b-a45d-4878-b91b-c0ac22bce910","banner":null,"lang":"en","date_modified":"2023-04-25","date_modified_ts":"2023-04-25T20:11:31Z","date_created":"2023-04-25T20:08:34Z","summary":null,"body":["<article data-history-node-id=\"4164\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-238\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-238<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>April 25, 2023<\/p>\n\n<p>Between April 21 and 25, 2023, Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories?q=&amp;p=1&amp;sort=portal_publication_date+desc&amp;rows=10&amp;portal_advisory_type=Security+Advisory&amp;documentKind=PortalProduct\">Red Hat Security <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-238","alert_type":396,"serial_number":"AV23-238","subject":null,"moderation_state":"published","external_url":null},{"nid":4166,"title":"[Control systems] Illumina security advisory (AV23-239)","uuid":"9e3d18da-0614-44c5-b79c-bb5eecf79b95","banner":null,"lang":"en","date_modified":"2023-04-27","date_modified_ts":"2023-04-27T18:50:18Z","date_created":"2023-04-27T18:44:03Z","summary":null,"body":["<article data-history-node-id=\"4166\" about=\"\/en\/alerts-advisories\/control-systems-illumina-security-advisory-av23-239\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-239<br \/><strong>Date: <\/strong>April 27, 2023<\/p>\n\n<p>On April 27, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iScan Control Software\u00a0\u2013 versions 4.0.0 and 4.0.5<\/li>\n\t<li>iSeq 100\u00a0\u2013 all versions<\/li>\n\t<li>MiniSeq Control Software\u00a0\u2013 version 2.0 and later<\/li>\n\t<li>MiSeq Control Software\u00a0\u2013 version 4.0 (RUO Mode)<\/li>\n\t<li>MiSeqDx Operating Software\u00a0\u2013 version 4.0.1 and later<\/li>\n\t<li>NextSeq\u00a0\u2013 multiple versions and models<\/li>\n\t<li>NovaSeq\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-117-01\">ICS Medical Advisory\u00a0- ICSMA-23-117-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-illumina-security-advisory-av23-239","alert_type":398,"serial_number":"AV23-239","subject":null,"moderation_state":"published","external_url":null},{"nid":4167,"title":"IBM security advisory (AV23-240)","uuid":"e4ea73cd-6803-4584-94c2-3344f670a13d","banner":null,"lang":"en","date_modified":"2023-05-01","date_modified_ts":"2023-05-01T17:51:54Z","date_created":"2023-05-01T17:44:11Z","summary":null,"body":["<article data-history-node-id=\"4167\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-240\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-240<br \/><strong>Date: <\/strong>April 24, 2023<\/p>\n\n<p>Between April 24 and 30, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Db2 Graph\u00a0\u2013 version 1.0.0.592 to 1.0.0.1514<\/li>\n\t<li>IBM MQ\u00a0\u2013 versions 9.0 LTS, 9.2 CD, 9.2 LTS, 9.3 CD and 9.3 LTS<\/li>\n\t<li>IBM MQ Appliance\u00a0\u2013 versions 9.3 CD and 9.3 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6985689\">IBM Security Bulletin\u00a0- 6985689<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6986579\">IBM Security Bulletin\u00a0- 6986579<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6986569\">IBM Security Bulletin\u00a0- 6986569<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-240","alert_type":396,"serial_number":"AV23-240","subject":null,"moderation_state":"published","external_url":null},{"nid":4168,"title":"Ubuntu security advisory (AV23-241)","uuid":"523928b7-8fe5-462d-8147-f14012874e4c","banner":null,"lang":"en","date_modified":"2023-05-01","date_modified_ts":"2023-05-01T17:58:48Z","date_created":"2023-05-01T17:52:42Z","summary":null,"body":["<article data-history-node-id=\"4168\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-241\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-241<br \/><strong>Date: <\/strong>May 1, 2023<\/p>\n\n<p>Between April 24 and 30, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-241","alert_type":396,"serial_number":"AV23-241","subject":null,"moderation_state":"published","external_url":null},{"nid":4169,"title":"Dell security advisory (AV23-242)","uuid":"ef47c179-96ba-4514-b9dd-6f2e65bc57f7","banner":null,"lang":"en","date_modified":"2023-05-01","date_modified_ts":"2023-05-01T18:03:25Z","date_created":"2023-05-01T17:59:45Z","summary":null,"body":["<article data-history-node-id=\"4169\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-242\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-242<br \/><strong>Date: <\/strong>May 1, 2023<\/p>\n\n<p>Between April 24 and 30, 2023, Dell published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell CloudLink\u00a0\u2013 version prior to 8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000212820\/dsa-2023-150-dell-cloudlink-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-150<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-242","alert_type":396,"serial_number":"AV23-242","subject":null,"moderation_state":"published","external_url":null},{"nid":4170,"title":"F5 security advisory (AV23-243)","uuid":"f2726d2b-7600-4939-b8c7-81ef9daf4e1c","banner":null,"lang":"en","date_modified":"2023-05-02","date_modified_ts":"2023-05-02T18:45:47Z","date_created":"2023-05-02T18:29:22Z","summary":null,"body":["<article data-history-node-id=\"4170\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av23-243\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-243<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 2, 2023<\/p>\n\n<p>Between April 28 and May 1, 2023, F5 published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP Next CNF\u00a0\u2013 version 1.1.0<\/li>\n\t<li>BIG-IP Next SPK\u00a0\u2013 versions 1.5.0 to 1.7.1<\/li>\n\t<li>F5OS-A\u00a0\u2013 version 1.3.0 to 1.3.1<\/li>\n\t<li>F5OS-C\u00a0\u2013 versions 1.5.0 and version 1.3.0 to 1.3.2<\/li>\n\t<li>Traffix SDC\u00a0\u2013 version 5.2.0<\/li>\n\t<li>NGINX API Connectivity Manager\u00a0- version 1.0.0 to 1.4.1<\/li>\n\t<li>NGINX Instance Manager\u00a0- versions 2.0.0 to 2.8.0<\/li>\n\t<li>NGINX Security Monitoring\u00a0- versions 1.0.0 to 1.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000133615\">F5 Security Advisory\u00a0- K000133615 <\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000133706\">F5 Security Advisory\u00a0- K000133706<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000133233\">F5 Security Advisory\u00a0- K000133233<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000133417\">F5 Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av23-243","alert_type":396,"serial_number":"AV23-243","subject":null,"moderation_state":"published","external_url":null},{"nid":4171,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-244) ","uuid":"40dbf9c5-4c1d-4310-9f01-2902a443fc6f","banner":null,"lang":"en","date_modified":"2023-05-02","date_modified_ts":"2023-05-02T18:59:14Z","date_created":"2023-05-02T18:56:11Z","summary":null,"body":["<article data-history-node-id=\"4171\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-244\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-244<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 2, 2023<\/p>\n\n<p>On May 2, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>MI5122-VM (MELIPC Series)\u00a0- all versions<\/li>\n\t<li>MI1002-W (MELIPC Series)\u00a0- all versions<\/li>\n\t<li>MI2012-W (MELIPC Series)\u00a0- all versions<\/li>\n\t<li>MI3321G-W (MELIPC Series)\u00a0- all versions<\/li>\n\t<li>MI3315G-W (MELIPC Series)\u00a0- all versions<\/li>\n\t<li>Q24DHCCPU-LS (MELSEC Q Series)\u00a0- all versions<\/li>\n\t<li>Q24DHCCPU-V (MELSEC Q Series)\u00a0- all versions<\/li>\n\t<li>Q24DHCCPU-VG (MELSEC Q Series)\u00a0- all versions<\/li>\n\t<li>Q26DHCCPU-LS (MELSEC Q Series)\u00a0- all versions<\/li>\n\t<li>R102WCPU-W (MELSEC iQ-R Series)\u00a0- all versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in privilege escalation and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-122-01\">ICS Advisory\u00a0- ICSA-23-122-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-244","alert_type":398,"serial_number":"AV23-244","subject":null,"moderation_state":"published","external_url":null},{"nid":4177,"title":"Google Chrome security advisory (AV23-245)","uuid":"4656c5a4-56c8-47d9-801a-9657621746c1","banner":null,"lang":"en","date_modified":"2023-05-03","date_modified_ts":"2023-05-03T18:00:34Z","date_created":"2023-05-03T17:56:19Z","summary":null,"body":["<article data-history-node-id=\"4177\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-245\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-245<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 3, 2023<\/p>\n\n<p>On May 2, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 113.0.5672.63\/.64 (Windows) and 113.0.5672.63 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/05\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-245","alert_type":396,"serial_number":"AV23-245","subject":null,"moderation_state":"published","external_url":null},{"nid":4178,"title":"Cisco security advisory (AV23-246)","uuid":"b30096a2-7ece-45eb-851c-8d58d5efbbef","banner":null,"lang":"en","date_modified":"2023-05-04","date_modified_ts":"2023-05-04T19:11:24Z","date_created":"2023-05-04T18:58:16Z","summary":null,"body":["<article data-history-node-id=\"4178\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-246\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-246<br \/><strong>Date: <\/strong>May 4, 2023\u00a0<\/p>\n\n<p>On May 3, 2023, Cisco published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Cisco SPA112 2-Port phone adapters<\/li>\n<\/ul><p>Cisco has identified end-of-life for the Cisco SPA112 2-Port Phone Adapter and is not releasing firmware updates to address the vulnerability described in the advisory. The Cyber Centre encourages users and administrators to review the vendor advisory for guidance.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-spa-unauth-upgrade-UqhyTWW\">Cisco security advisory - cisco-sa-spa-unauth-upgrade-UqhyTWW<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/unified-communications\/small-business-voice-gateways-ata\/eos-eol-notice-c51-743206.html\">Cisco End-of-Sale and End-of-Life announcement for Cisco SPA112 2-Port phone adapter<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/unified-communications\/small-business-voice-gateways-ata\/eos-eol-notice-c51-743206.html\">Cisco security advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-246","alert_type":396,"serial_number":"AV23-246","subject":null,"moderation_state":"published","external_url":null},{"nid":4179,"title":"Fortinet security advisory (AV23-247)","uuid":"5bad6951-8042-49fb-9c19-6472e611af23","banner":null,"lang":"en","date_modified":"2023-05-04","date_modified_ts":"2023-05-04T19:21:50Z","date_created":"2023-05-04T19:16:47Z","summary":null,"body":["<article data-history-node-id=\"4179\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-247\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-247<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May\u00a04, 2023<\/p>\n\n<p>On May\u00a03, 2023, Fortinet published Security Advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>FortiADC \u2013 versions 7.1.0\u00a0to 7.1.1 and version 7.2.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to unauthorized access. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-22-297\">Fortinet PSIRT Advisory - FG-IR-22-297<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-247","alert_type":396,"serial_number":"AV23-247","subject":null,"moderation_state":"published","external_url":null},{"nid":4182,"title":"Ubuntu security advisory (AV23-248)","uuid":"80d9b881-44e9-4b55-9709-763ffd1024ae","banner":null,"lang":"en","date_modified":"2023-05-08","date_modified_ts":"2023-05-08T20:30:11Z","date_created":"2023-05-08T20:24:37Z","summary":null,"body":["<article data-history-node-id=\"4182\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-248\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-248<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 8, 2023<\/p>\n\n<p>Between May 1 and 7, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 L<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-248","alert_type":396,"serial_number":"AV23-248","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4183,"title":"Dell security advisory (AV23-249)","uuid":"eea90617-1032-471c-932e-aad11512f56b","banner":null,"lang":"en","date_modified":"2023-05-08","date_modified_ts":"2023-05-08T20:39:14Z","date_created":"2023-05-08T20:34:46Z","summary":null,"body":["<article data-history-node-id=\"4183\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-249\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-249<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 8, 2023<\/p>\n\n<p>Between May 1 and 7, 2023, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance \u2013 7.0.x versions prior to 7.0.450<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000213011\/dsa-2023-071-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities-7-0-450\">Dell Security Update - DSA-2023-071<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-249","alert_type":396,"serial_number":"AV23-249","subject":"dell","moderation_state":"published","external_url":null},{"nid":4184,"title":"IBM security advisory (AV23-250)","uuid":"cd493f3a-01f9-4feb-8799-6b7cde99f4d1","banner":null,"lang":"en","date_modified":"2023-05-08","date_modified_ts":"2023-05-08T20:46:08Z","date_created":"2023-05-08T20:40:44Z","summary":null,"body":["<article data-history-node-id=\"4184\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-250\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-250<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 8, 2023<\/p>\n\n<p>Between May 1 and 7, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cognos Command Center \u2013 version 10.2.4.1<\/li>\n\t<li>Watson Discovery \u2013 version 4.0.0 to 4.6.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6988263\">IBM Security Bulletin \u2013 6988263<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6985063\">IBM Security Bulletin \u2013 6985063<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6983240\">IBM Security Bulletin \u2013 6983240<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-250","alert_type":396,"serial_number":"AV23-250","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4185,"title":"Hunting Russian intelligence \u201cSnake\u201d malware - Joint cybersecurity advisory ","uuid":"3f5a4e11-9ded-45e8-9c8e-076343f1289f","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T12:56:24Z","date_created":"2023-05-09T12:15:27Z","summary":null,"body":["<article data-history-node-id=\"4185\" about=\"\/en\/alerts-advisories\/hunting-russian-intelligence-snake-malware-joint-cybersecurity-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-004<br \/><strong>Date:\u00a0<\/strong>May 9, 2023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On May\u00a09,\u00a02023, the Canadian Centre for Cyber Security joined cyber security partners from US agencies, the Australian Cyber Security Centre (ACSC), New Zealand\u2019s National Cyber Security Centre (NCSC-NZ) and the United Kingdom\u2019s National Cyber Security Centre (NCSC-UK) to publish a joint Cybersecurity advisory (CSA) on a cyber espionage tool named Snake. The advisory was published to raise awareness that Snake has been used globally by a malicious cyber actor with infrastructure being identified in over 50 countries across North America, South America, Europe, Africa, Asia and Australia. The purpose of Snake was to collect sensitive intelligence from high-priority targets such as government networks, research facilities and journalists.<\/p>\n\n<p>The Cyber Centre is highlighting the advisory, as it provides important prevention, detection and mitigation advice to system owners and operators responsible for defending their systems and networks from cyber threats.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><h2>References<\/h2>\n\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-129a\">Hunting Russian Intelligence \u201cSnake\u201d Malware<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hunting-russian-intelligence-snake-malware-joint-cybersecurity-advisory","alert_type":397,"serial_number":"AL23-004","subject":null,"moderation_state":"published","external_url":null},{"nid":4186,"title":"Microsoft Edge security advisory (AV23-251)","uuid":"fc9ca3e1-5c45-4b3b-8e16-81621b92d8db","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T13:56:26Z","date_created":"2023-05-09T13:54:24Z","summary":null,"body":["<article data-history-node-id=\"4186\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-251\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-251<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 9, 2023<\/p>\n\n<p>On May 5, 2023, Microsoft published Security Updates to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 113.0.1774.35<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-5-2023 \">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-251","alert_type":396,"serial_number":"AV23-251","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4187,"title":"SAP security advisory \u2013 May 2023 monthly rollup (AV23-252)","uuid":"adf83cf5-6a9b-4b24-bbe7-f9ef4b70cee2","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T17:54:37Z","date_created":"2023-05-09T17:50:10Z","summary":null,"body":["<article data-history-node-id=\"4187\" about=\"\/en\/alerts-advisories\/sap-security-advisory-may-2023-monthly-rollup-av23-252\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-252<br \/><strong>Date: <\/strong>May 9, 2023<\/p>\n\n<p>On May 9, 2023, SAP published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP 3D Visual Enterprise License Manager\u00a0\u2013 version 15<\/li>\n\t<li>SAP BusinessObjects Intelligence Platform\u00a0\u2013 versions 420 and 430<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day\u00a0\u2013 May 2023<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-may-2023-monthly-rollup-av23-252","alert_type":396,"serial_number":"AV23-252","subject":"sap","moderation_state":"published","external_url":null},{"nid":4188,"title":"Mozilla security advisory (AV23-253)","uuid":"3cef3c9a-8d9c-4132-81ee-4a6e0c7ad287","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T18:01:22Z","date_created":"2023-05-09T17:56:11Z","summary":null,"body":["<article data-history-node-id=\"4188\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-253\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-253<br \/><strong>Date: <\/strong>May 9, 2023<\/p>\n\n<p>On May 9, 2023, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 102.11<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 113<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-17\/\">Mozilla Security Advisory - MFSA 2023-17<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-16\/\">Mozilla Security Advisory - MFSA 2023-16<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-253","alert_type":396,"serial_number":"AV23-253","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4189,"title":"[Control systems] Schneider Electric security advisory (AV23-254)","uuid":"f8251d6c-1e34-4f14-9d56-2a64b0b1a111","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T18:10:33Z","date_created":"2023-05-09T18:06:30Z","summary":null,"body":["<article data-history-node-id=\"4189\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-254\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-254 <strong>Date: <\/strong>May 9, 2023<\/p>\n\n<p>On May 9, 2023, Schneider Electric published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Power Operation\u00a0\u2013 versions 2022, 2021 CU3 and prior<\/li>\n\t<li>EcoStruxure Power SCADA Operation\u00a0\u2013 version 2020 and prior<\/li>\n\t<li>OPC Factory Server\u00a0\u2013 versions prior to V3.63SP2<\/li>\n\t<li>PowerLogic ION7400 \/ PM8000 \/ ION9000\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Power SCADA Anywhere\u00a0\u2013 versions 1.1 and 1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-254","alert_type":398,"serial_number":"AV23-254","subject":"other","moderation_state":"published","external_url":null},{"nid":4190,"title":"Microsoft security advisory \u2013 May 2023 monthly rollup - Update 1 (AV23-255)","uuid":"8b75e82a-2809-428a-8594-08ab15afe059","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T12:46:45Z","date_created":"2023-05-09T18:57:46Z","summary":null,"body":["<article data-history-node-id=\"4190\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2023-monthly-rollup-av23-255\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-255<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 11, 2023<\/p>\n\n<p>On May 9, 2023, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft Sharepoint Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-24932 and CVE-2023-29336 have been exploited.<\/p>\n\n<p>In addition to critical updates, Microsoft has also released CVE-2023-29324 as an update to a previously patched Outlook Elevation of Privilege Vulnerability CVE-2023-23397 and is recommending that customers apply both updates to remain fully protected.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-29324\">Windows MSHTML platform security feature bypass vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/blog\/2023\/03\/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability\/\">Microsoft mitigates Outlook elevation of privilege vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-May\">May 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-may-2023-monthly-rollup-av23-255","alert_type":396,"serial_number":"AV23-255","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4191,"title":"[Control systems] Siemens security advisory (AV23-256) ","uuid":"7ab5cb41-d81e-4442-8a4f-36e68b6e4119","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T19:07:51Z","date_created":"2023-05-09T19:06:02Z","summary":null,"body":["<article data-history-node-id=\"4191\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-256\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-256<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 9, 2023<\/p>\n\n<p>On May 9, 2023, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SCALANCE LPE9403\u00a0\u2013 versions prior to V2.1<\/li>\n\t<li>SINEC NMS\u00a0\u2013 versions prior to V1.0.3.1<\/li>\n\t<li>Siveillance Video Event and Management Servers\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\u2003\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-256","alert_type":398,"serial_number":"AV23-256","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4192,"title":"Adobe security advisory (AV23-257)","uuid":"72c08c48-cca6-469f-b4df-b5db0ebbaee7","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T20:20:14Z","date_created":"2023-05-09T20:18:19Z","summary":null,"body":["<article data-history-node-id=\"4192\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-257\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-257<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 9, 2023<\/p>\n\n<p>On May 9, 2023, Adobe published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Adobe Substance 3D Painter\u00a0- version 8.3.0\u202fand\u202fprior\u202f<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/substance3d_painter\/apsb23-29.html\">Adobe Security Advisory\u00a0- APSB23-29<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-257","alert_type":396,"serial_number":"AV23-257","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4193,"title":"Red Hat security advisory (AV23-258)","uuid":"3d35de62-5ead-4cf7-a2dd-db4e28afd3c8","banner":null,"lang":"en","date_modified":"2023-05-09","date_modified_ts":"2023-05-09T20:26:30Z","date_created":"2023-05-09T20:23:55Z","summary":null,"body":["<article data-history-node-id=\"4193\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-258\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-258<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 9, 2023<\/p>\n\n<p>On May 9, 2023, Red Hat published Security Advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories?q=&amp;p=1&amp;sort=portal_publication_date+desc&amp;rows=10&amp;portal_advisory_type=Security+Advisory&amp;documentKind=PortalProduct\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-258","alert_type":396,"serial_number":"AV23-258","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4195,"title":"[Control systems] Hitachi Energy security advisory (AV23-259) ","uuid":"4b896d60-27b6-4623-b9fd-8407606c348f","banner":null,"lang":"en","date_modified":"2023-05-10","date_modified_ts":"2023-05-10T15:40:16Z","date_created":"2023-05-10T15:30:47Z","summary":null,"body":["<article data-history-node-id=\"4195\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-259\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-259<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May\u00a010,\u00a02023<\/p>\n\n<p>On May\u00a09,\u00a02023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Modular Switchgear Monitoring (MSM) \u2013 version 2.2.5 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to credential disclosure or denial of service. The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-129-02\">ICS Advisory - ICSA-23-129-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-259","alert_type":398,"serial_number":"AV23-259","subject":"other","moderation_state":"published","external_url":null},{"nid":4196,"title":"Intel security advisory (AV23-260) ","uuid":"91b88e40-2713-4f16-9f4f-9cf2e0547b19","banner":null,"lang":"en","date_modified":"2023-05-10","date_modified_ts":"2023-05-10T15:52:55Z","date_created":"2023-05-10T15:42:55Z","summary":null,"body":["<article data-history-node-id=\"4196\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av23-260\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-260<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 10, 2023<\/p>\n\n<p>On May 9, 2023, Intel published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Data Center Manager (DCM) software \u2013 versions prior to 5.1<\/li>\n\t<li>i915 Graphics for Linux \u2013 kernel versions prior to V1.0.3.1<\/li>\n\t<li>Intel Processors \u2013 multiple versions<\/li>\n\t<li>NUC firmware \u2013 multiple versions and platforms<\/li>\n\t<li>oneAPI HPC Toolkit \u2013 versions prior to 2023.0.0<\/li>\n\t<li>One Boot Flash Update (OFU) software \u2013 versions prior to 14.1.30<\/li>\n\t<li>QuickAssist Technology (QAT) Engine for OpenSSL \u2013 versions prior to 0.6.16<\/li>\n\t<li>QuickAssist Technology (QAT) driver for Windows \u2013 versions prior to 1.9.0<\/li>\n\t<li>Retail Edge Mobile application \u2013 multiple versions and platforms<\/li>\n\t<li>Server Board M50CYP\/ D50TNP Family \u2013 BMC firmware prior to version 2.90<\/li>\n\t<li>System Usage Report (SUR) software \u2013 versions prior to 2.4.8989<\/li>\n\t<li>Trace Analyzer and Collector software \u2013 versions prior to 2021.8.0 Dec 2022<\/li>\n\t<li>Virtual RAID on CPU (VROC) software \u2013 versions prior to 7.7.6.1003<\/li>\n\t<li>WULT software maintained by Intel \u2013 versions prior to 1.0.0 (commit id 592300b)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel security advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av23-260","alert_type":396,"serial_number":"AV23-260","subject":"intel","moderation_state":"published","external_url":null},{"nid":4197,"title":"HPE security advisory (AV23-261)","uuid":"59d657cc-1c26-4332-a436-c834804691e5","banner":null,"lang":"en","date_modified":"2023-05-10","date_modified_ts":"2023-05-10T17:30:19Z","date_created":"2023-05-10T17:27:03Z","summary":null,"body":["<article data-history-node-id=\"4197\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-261\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-261<br \/><strong>Date: <\/strong>May 10, 2023<\/p>\n\n<p>On May 10, 2023, HPE published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Aruba Access Points running InstantOS and ArubaOS 10\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-261","alert_type":396,"serial_number":"AV23-261","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4199,"title":"[Control systems] Rockwell Automation security advisory (AV23-262) ","uuid":"0c877edd-f7d3-4f99-945a-6f7a8bc9dca8","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T12:42:12Z","date_created":"2023-05-12T12:38:04Z","summary":null,"body":["<article data-history-node-id=\"4199\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-262\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-262<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 12, 2023<\/p>\n\n<p>On May 11, 2023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Arena Simulation Software\u00a0\u2013 version 16.20.01<\/li>\n\t<li>Kinetix 5500 EtherNet\/IP Servo Drive\u00a0\u2013 version 7.13<\/li>\n\t<li>PanelView 800\u00a0\u2013 multiple versions<\/li>\n\t<li>ThinManager\u00a0\u2013 versions 13.0 to 13.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-14\">ICS Advisory\u00a0- ICSA-23-131-14<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-15\">ICS Advisory\u00a0- ICSA-23-131-15<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-10\">ICS Advisory\u00a0- ICSA-23-131-10<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-09\">ICS Advisory\u00a0- ICSA-23-131-09<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-262","alert_type":398,"serial_number":"AV23-262","subject":"other","moderation_state":"published","external_url":null},{"nid":4200,"title":"[Control systems] BirdDog security advisory (AV23-263) ","uuid":"b8910cb9-ccaa-40e6-b13a-455b9613b94e","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T12:51:48Z","date_created":"2023-05-12T12:47:13Z","summary":null,"body":["<article data-history-node-id=\"4200\" about=\"\/en\/alerts-advisories\/control-systems-birddog-security-advisory-av23-263\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-263<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 12, 2023<\/p>\n\n<p>On May 11, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>4K QUAD\u00a0\u2013 versions 4.5.181 and 4.5.196<\/li>\n\t<li>A300 EYES\u00a0\u2013 version 3.4<\/li>\n\t<li>MINI\u00a0\u2013 version 2.62<\/li>\n\t<li>STUDIO R3\u00a0\u2013 version 3.6.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-11\">ICS Advisory\u00a0- ICSA-23-131-11<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-birddog-security-advisory-av23-263","alert_type":398,"serial_number":"AV23-263","subject":"other","moderation_state":"published","external_url":null},{"nid":4201,"title":"[Control systems] Teltonika security advisory (AV23-264) ","uuid":"5693000a-b100-4edc-b46d-2478d339110f","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T13:02:12Z","date_created":"2023-05-12T12:59:14Z","summary":null,"body":["<article data-history-node-id=\"4201\" about=\"\/en\/alerts-advisories\/control-systems-teltonika-security-advisory-av23-264\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-264<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 12, 2023<\/p>\n\n<p>On May 11, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Remote Management System (RMS) \u2013 versions prior to 4.14.0<\/li>\n\t<li>RUT model routers \u2013 versions 00.07.00 to 00.07.03.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-08 \">ICS Advisory - ICSA-23-131-08<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-teltonika-security-advisory-av23-264","alert_type":398,"serial_number":"AV23-264","subject":"other","moderation_state":"published","external_url":null},{"nid":4202,"title":"[Control systems] SDG Technologies security advisory (AV23-265) ","uuid":"2ce4ee6e-4430-4180-8124-6a57ff8794fe","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T14:07:25Z","date_created":"2023-05-12T13:57:13Z","summary":null,"body":["<article data-history-node-id=\"4202\" about=\"\/en\/alerts-advisories\/control-systems-sdg-technologies-security-advisory-av23-265\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-265<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 12, 2023\u00a0<\/p>\n\n<p>On May 11, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>PnPSCADA (cross platforms) \u2013 versions 2.*<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-12\">ICS advisory - ICSA-23-131-12<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sdg-technologies-security-advisory-av23-265","alert_type":398,"serial_number":"AV23-265","subject":"other","moderation_state":"published","external_url":null},{"nid":4203,"title":"[Control systems] Sierra Wireless security advisory (AV23-266) ","uuid":"e7e8ce6c-9621-4405-9551-cfa5dbe875a2","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T14:16:45Z","date_created":"2023-05-12T14:10:48Z","summary":null,"body":["<article data-history-node-id=\"4203\" about=\"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory-av23-266\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-266\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 12, 2023\n<\/p>\n<p>On May 11, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:\n<\/p>\n\n<ul><li>AirVantage Platform<\/li>\n\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-07\">ICS Advisory - ICSA-23-131-07<\/a><\/li>\n\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory-av23-266","alert_type":398,"serial_number":"AV23-266","subject":"other","moderation_state":"published","external_url":null},{"nid":4204,"title":"[Control systems] PTC security advisory (AV23-267) ","uuid":"df82afb1-74cd-4bdf-943c-6b4d6cdcd40b","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T15:09:08Z","date_created":"2023-05-12T14:22:30Z","summary":null,"body":["<article data-history-node-id=\"4204\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-267\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-267<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 12, 2023<\/p>\n\n<p>On May 11, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Vuforia Studio \u2013 versions prior to 9.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-131-13\">ICS Advisory - ICSA-23-131-13<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-267","alert_type":398,"serial_number":"AV23-267","subject":"other","moderation_state":"published","external_url":null},{"nid":4205,"title":"VMware security advisory (AV23-268)","uuid":"3a87aa0d-5ee4-4794-a01c-7dcdd04eb970","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T17:13:33Z","date_created":"2023-05-12T15:19:21Z","summary":null,"body":["<article data-history-node-id=\"4205\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-268\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-268<br \/><strong>Date: <\/strong>May\u00a012, 2023<\/p>\n\n<p>On May\u00a011, 2023, VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Aria Operations\u00a0\u2013 multiple versions<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 version 4.x<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary command execution or privilege escalation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0009.html\">VMware Security Advisory\u00a0- VMSA-2023-0009<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-268","alert_type":396,"serial_number":"AV23-268","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4206,"title":"Foxit security advisory (AV23-269)","uuid":"1b2b8662-0b14-41aa-b359-0584757cb016","banner":null,"lang":"en","date_modified":"2023-05-12","date_modified_ts":"2023-05-12T17:44:19Z","date_created":"2023-05-12T15:47:14Z","summary":null,"body":["<article data-history-node-id=\"4206\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av23-269\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-269<br \/><strong>Date: <\/strong>May\u00a012, 2023<\/p>\n\n<p>On April\u00a019, 2023, Foxit published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader\u00a0\u2013 version 12.1.1.15289 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to remote code execution or privilege escalation.<\/p>\n\n<p>The Cyber Centre has received reports that a public exploit exists for CVE\u20112023\u201127363.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av23-269","alert_type":396,"serial_number":"AV23-269","subject":"other","moderation_state":"published","external_url":null},{"nid":4208,"title":"IBM security advisory (AV23-270)","uuid":"328213fe-051d-4084-b409-f181898f6d6d","banner":null,"lang":"en","date_modified":"2023-05-15","date_modified_ts":"2023-05-15T13:51:42Z","date_created":"2023-05-15T13:45:52Z","summary":null,"body":["<article data-history-node-id=\"4208\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-270\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-270<br \/><strong>Date: <\/strong>May\u00a015, 2023<\/p>\n\n<p>Between May\u00a08 and 14, 2023, IBM published Security Advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-270","alert_type":396,"serial_number":"AV23-270","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4209,"title":"Ubuntu security advisory (AV23-271)","uuid":"1ed25539-2b3a-436d-b35a-46bba4208fdc","banner":null,"lang":"en","date_modified":"2023-05-15","date_modified_ts":"2023-05-15T14:06:11Z","date_created":"2023-05-15T13:45:52Z","summary":null,"body":["<article data-history-node-id=\"4209\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-271\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-271\n  <br \/><strong>Date: <\/strong>May\u00a015, 2023\n<\/p>\n<p>Between May\u00a08 and 14, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:\n<\/p>\n<ul><li>Ubuntu 18.04 ESM<\/li>\n  <li>Ubuntu 20.04 LTS<\/li>\n  <li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-271","alert_type":396,"serial_number":"AV23-271","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4210,"title":"Dell security advisory (AV23-272)","uuid":"9ede031f-b754-47a5-a88f-b7c475e76493","banner":null,"lang":"en","date_modified":"2023-05-15","date_modified_ts":"2023-05-15T15:33:13Z","date_created":"2023-05-15T13:45:52Z","summary":null,"body":["<article data-history-node-id=\"4210\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-272\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-272<br \/><strong>Date: <\/strong>May\u00a015, 2023<\/p>\n\n<p>Between May\u00a08 and 14, 2023, Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell NetWorker Management Console (NMC)\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Unity Operating Environment (OE)\u00a0\u2013 versions prior to 5.3.0.0.5.120<\/li>\n\t<li>Dell UnityVSA Operating Environment (OE)\u00a0\u2013 versions prior to 5.3.0.0.5.120<\/li>\n\t<li>Dell Unity XT Operating Environment (OE)\u00a0\u2013 versions prior to 5.3.0.0.5.120<\/li>\n\t<li>RecoverPoint Classic\u00a0\u2013 versions 5.1 SP4, 5.1 SP4 P1, 5.1 SP4 P2 and 5.1 SP4 P3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000213385\/dsa-2023-054-dell-networker-management-console-nmc-security-update-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-054<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000213152\/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-141<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000213384\/dsa-2023-169-dell-recoverpoint-classic-security-update-for-multiple-component-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-169<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-272","alert_type":396,"serial_number":"AV23-272","subject":"dell","moderation_state":"published","external_url":null},{"nid":4211,"title":"[Control systems] Rockwell Automation security advisory (AV23-273)","uuid":"7594058c-6860-49ad-89a2-7e4cc8383207","banner":null,"lang":"en","date_modified":"2023-05-16","date_modified_ts":"2023-05-16T17:29:25Z","date_created":"2023-05-16T17:27:13Z","summary":null,"body":["<article data-history-node-id=\"4211\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-273\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-273<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 16, 2023<\/p>\n\n<p>On May 16, 2023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ArmorStart ST281E\u00a0\u2013 versions 2.004.06 and later<\/li>\n\t<li>ArmorStart ST284E\u00a0\u2013 all versions<\/li>\n\t<li>ArmorStart ST280E\u00a0\u2013 all versions<\/li>\n\t<li>FactoryTalk Vantagepoint\u00a0\u2013 versions prior 8.40<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-136-03\">ICS Advisory\u00a0- ICSA-23-136-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-136-02 \">ICS Advisory\u00a0- ICSA-23-136-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-273","alert_type":398,"serial_number":"AV23-273","subject":"other","moderation_state":"published","external_url":null},{"nid":4212,"title":"[Control systems] Snap One security advisory (AV23-274)","uuid":"cef6b650-779c-47e2-8aa3-007580bdf683","banner":null,"lang":"en","date_modified":"2023-05-16","date_modified_ts":"2023-05-16T17:36:25Z","date_created":"2023-05-16T17:34:15Z","summary":null,"body":["<article data-history-node-id=\"4212\" about=\"\/en\/alerts-advisories\/control-systems-snap-one-security-advisory-av23-274\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-274<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 16, 2023<\/p>\n\n<p>On May 16, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OvrC Pro\u00a0\u2013 version 7.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-136-01 \">ICS Advisory\u00a0- ICSA-23-136-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-snap-one-security-advisory-av23-274","alert_type":398,"serial_number":"AV23-274","subject":"other","moderation_state":"published","external_url":null},{"nid":4213,"title":"Google Chrome security advisory (AV23-275)","uuid":"4738eaba-2f0b-4dbd-8b64-b06aa3351e7a","banner":null,"lang":"en","date_modified":"2023-05-16","date_modified_ts":"2023-05-16T20:07:13Z","date_created":"2023-05-16T20:03:45Z","summary":null,"body":["<article data-history-node-id=\"4213\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-275\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-275<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 16, 2023<\/p>\n\n<p>On May 16, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 113.0.5672.126\/.127 (Windows) and 113.0.5672.126 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/05\/stable-channel-update-for-desktop_16.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-275","alert_type":396,"serial_number":"AV23-275","subject":"other","moderation_state":"published","external_url":null},{"nid":4215,"title":"[Control systems] ABB security advisory (AV23-276)","uuid":"df2addf9-ea58-4bed-bb1d-4d15f36be56a","banner":null,"lang":"en","date_modified":"2023-05-17","date_modified_ts":"2023-05-17T13:23:07Z","date_created":"2023-05-17T13:15:45Z","summary":null,"body":["<article data-history-node-id=\"4215\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-276\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-276<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 17, 2023<\/p>\n\n<p>On May 17, 2023, ABB published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Terra AC wallbox \u2013 multiple platforms and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108468A1415&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB advisory \u2013 9AKK108468A1415<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB security advisories <\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-276","alert_type":398,"serial_number":"AV23-276","subject":"abb","moderation_state":"published","external_url":null},{"nid":4217,"title":"HPE security advisory (AV23-277)","uuid":"203187d3-b305-4876-bd2d-696196edb651","banner":null,"lang":"en","date_modified":"2023-05-17","date_modified_ts":"2023-05-17T17:49:59Z","date_created":"2023-05-17T17:42:08Z","summary":null,"body":["<article data-history-node-id=\"4217\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-277\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-x277<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 17, 2023<\/p>\n\n<p>Between May 16 and 17, 2023, HPE published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HPE Cray EX235a Accelerator Blade \u2013 versions prior to 1.6.2<\/li>\n\t<li>HPE ProLiant e910 Server Blade \u2013 versions prior to v2.06_04-20-2023<\/li>\n\t<li>HPE ProLiant m750 Server Blade \u2013 versions prior to v1.58_04-20-2023<\/li>\n\t<li>HPE ProLiant e910t Server Blade \u2013 versions to v2.06_04-20-2023<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440\">HPE security bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-277","alert_type":396,"serial_number":"AV23-277","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4218,"title":"Cisco security advisory (AV23-278)","uuid":"104e266d-8aae-4573-92ba-ab5225dfc924","banner":null,"lang":"en","date_modified":"2023-05-17","date_modified_ts":"2023-05-17T18:47:29Z","date_created":"2023-05-17T18:42:36Z","summary":null,"body":["<article data-history-node-id=\"4218\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-278\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-278\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 17, 2023\n<\/p>\n<p>On May 17, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>250 Smart series, 350 Managed series, 350X Stackable Managed series, and 550X Stackable Managed series Switches \u2013 versions prior to 2.5.9.16<\/li>\n  <li>Business 250 Smart series and Business 350 Managed series Switches \u2013 versions prior to 3.3.0.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sg-web-multi-S9g4Nkgv\">Cisco security advisory - cisco-sa-sg-web-multi-S9g4Nkgv<\/a><\/li>\n  <li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco security advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-278","alert_type":396,"serial_number":"AV23-278","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4219,"title":"AV23-279 Mitel security advisory ","uuid":"216b8ece-f016-480f-9489-6cb7da1272bb","banner":null,"lang":"en","date_modified":"2023-05-18","date_modified_ts":"2023-05-18T14:08:08Z","date_created":"2023-05-18T14:01:46Z","summary":null,"body":["<article data-history-node-id=\"4219\" about=\"\/en\/alerts-advisories\/av23-279-mitel-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-279<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 18,\u00a02023<\/p>\n\n<p>On 17 May 2023, Mitel published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>MiVoice Connect \u2013 version 19.3 SP2 (22.24.1500.0) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-23-0004\">Mitel security advisory - 23-0004<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel security advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/av23-279-mitel-security-advisory","alert_type":396,"serial_number":"AV23-279","subject":"mitel","moderation_state":"published","external_url":null},{"nid":4221,"title":"People's Republic of China state-sponsored cyber actor living off the land to evade detection - Joint cybersecurity advisory ","uuid":"e3bcde99-daf3-497b-8f9e-b2eb16cc167a","banner":null,"lang":"en","date_modified":"2023-05-24","date_modified_ts":"2023-05-24T19:58:23Z","date_created":"2023-05-19T14:19:36Z","summary":null,"body":["<article data-history-node-id=\"4221\" about=\"\/en\/alerts-advisories\/peoples-republic-china-state-sponsored-cyber-actor-living-land-evade-detection-joint-cybersecurity-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-005<br \/><strong>Date:\u00a0<\/strong>May 24,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On May 24,\u00a02023, the Canadian Centre for Cyber Security joined cyber security partners from US agencies, the Australian Cyber Security Centre\u00a0(ACSC), New Zealand\u2019s National Cyber Security Centre\u00a0(NCSC-NZ) and the United Kingdom\u2019s National Cyber Security Centre\u00a0(NCSC-UK) to publish a joint Cybersecurity Advisory (CSA) providing an overview of activity by a People\u2019s Republic of China state-sponsored cyber actor.\u00a0<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<p>The Cyber Centre is highlighting the advisory as it provides detection and mitigation recommendations for system owners and operators to better protect themselves from this cyber actor.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My\u00a0Cyber\u00a0Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p>People's Republic of China state-sponsored cyber actor living off the land to evade detection - <a href=\"https:\/\/media.defense.gov\/2023\/May\/24\/2003229517\/-1\/-1\/0\/CSA_Living_off_the_Land.PDF\">Joint cybersecurity advisory (PDF)<\/a>\u00a0<\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/peoples-republic-china-state-sponsored-cyber-actor-living-land-evade-detection-joint-cybersecurity-advisory","alert_type":397,"serial_number":"AL23-005","subject":"other","moderation_state":"published","external_url":null},{"nid":4223,"title":"[Control systems] Carlo Gavazzi security advisory (AV23-280)","uuid":"cdfdb0ab-625f-46f7-af80-6f9e80f1470e","banner":null,"lang":"en","date_modified":"2023-05-19","date_modified_ts":"2023-05-19T16:00:40Z","date_created":"2023-05-19T15:24:36Z","summary":null,"body":["<article data-history-node-id=\"4223\" about=\"\/en\/alerts-advisories\/control-systems-carlo-gavazzi-security-advisory-av23-280\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-280<br \/><strong>Date: <\/strong>May\u00a019, 2023<\/p>\n\n<p>On May\u00a018, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Powersoft\u00a0\u2013 versions 2.1.1.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-138-01\">ICS Advisory\u00a0- ICSA-23-138-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-carlo-gavazzi-security-advisory-av23-280","alert_type":398,"serial_number":"AV23-280","subject":"ics","moderation_state":"published","external_url":null},{"nid":4228,"title":"[Control systems] Hitachi Energy security advisory (AV23-283)","uuid":"442578fa-fbb4-4fca-bdcf-6b9f2239f4fb","banner":null,"lang":"en","date_modified":"2023-05-19","date_modified_ts":"2023-05-19T21:05:40Z","date_created":"2023-05-19T15:24:37Z","summary":null,"body":["<article data-history-node-id=\"4228\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-283\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-283<br \/><strong>Date: <\/strong>May\u00a019, 2023<\/p>\n\n<p>On May\u00a018, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SYS600\u00a0\u2013 version 9.4 FP2 Hotfix 5 and prior<\/li>\n\t<li>SYS600\u00a0\u2013 version 10.1.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-138-03\">ICS Advisory\u00a0- ICSA-23-138-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-283","alert_type":398,"serial_number":"AV23-283","subject":"ics","moderation_state":"published","external_url":null},{"nid":4229,"title":"Apple security advisory (AV23-284)","uuid":"4dfb8ebf-38e2-4ff7-9b05-4da5e16b1061","banner":null,"lang":"en","date_modified":"2023-05-19","date_modified_ts":"2023-05-19T21:06:52Z","date_created":"2023-05-19T15:24:37Z","summary":null,"body":["<article data-history-node-id=\"4229\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-284\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-284<br \/><strong>Date: <\/strong>May\u00a019, 2023<\/p>\n\n<p>On May\u00a018, 2023, Apple published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 15.7.6 and 16.5<\/li>\n\t<li>macOS Big Sur\u00a0\u2013 versions prior to 11.7.7<\/li>\n\t<li>macOS Monterey\u00a0\u2013 versions prior to 12.6.6<\/li>\n\t<li>macOs Ventura\u00a0\u2013 versions prior to 13.4<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 16.5<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 16.5<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 9.5<\/li>\n<\/ul><p>Apple has received reports that some of these vulnerabilities have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-284","alert_type":396,"serial_number":"AV23-284","subject":"apple","moderation_state":"published","external_url":null},{"nid":4225,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-281)","uuid":"db2b8aca-aae5-4a3d-97de-6a5415af2fa2","banner":null,"lang":"en","date_modified":"2023-05-19","date_modified_ts":"2023-05-19T17:44:44Z","date_created":"2023-05-19T15:24:37Z","summary":null,"body":["<article data-history-node-id=\"4225\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-281\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-281<br \/><strong>Date: <\/strong>May\u00a019, 2023<\/p>\n\n<p>On May\u00a018, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>WS0-GETH00200\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-138-02\">ICS Advisory\u00a0- ICSA-23-138-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-281","alert_type":398,"serial_number":"AV23-281","subject":"ics","moderation_state":"published","external_url":null},{"nid":4230,"title":"Microsoft Edge security advisory (AV23-285)","uuid":"99065017-ebd6-487f-a85b-62be9ae92881","banner":null,"lang":"en","date_modified":"2023-05-19","date_modified_ts":"2023-05-19T21:08:23Z","date_created":"2023-05-19T15:24:40Z","summary":null,"body":["<article data-history-node-id=\"4230\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-285\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-285<br \/><strong>Date: <\/strong>May\u00a019, 2023<\/p>\n\n<p>On May\u00a018, 2023, Microsoft published Security Updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 113.0.1774.50<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 112.0.1722.84<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-18-2023\">Microsoft Edge Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-285","alert_type":396,"serial_number":"AV23-285","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4227,"title":"[Control systems] Johnson Controls security advisory (AV23-282)","uuid":"0f76eff0-822f-4d81-9651-5b0a1f794561","banner":null,"lang":"en","date_modified":"2023-05-19","date_modified_ts":"2023-05-19T21:03:42Z","date_created":"2023-05-19T20:56:46Z","summary":null,"body":["<article data-history-node-id=\"4227\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-282\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-282<br \/><strong>Date: <\/strong>May\u00a019, 2023<\/p>\n\n<p>On May\u00a018, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenBlue Enterprise Manager Data Collector\u00a0- firmware versions prior to 3.2.5.75<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-138-04\">ICS Advisory\u00a0- ICSA-23-138-04<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-282","alert_type":398,"serial_number":"AV23-282","subject":"ics","moderation_state":"published","external_url":null},{"nid":4231,"title":"IBM security advisory (AV23-286)","uuid":"2d5b8580-79af-4782-889b-a464303b9f8b","banner":null,"lang":"en","date_modified":"2023-05-23","date_modified_ts":"2023-05-23T17:18:57Z","date_created":"2023-05-23T17:14:31Z","summary":null,"body":["<article data-history-node-id=\"4231\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-286\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-286<br \/><strong>Date: <\/strong>May 23, 2023<\/p>\n\n<p>Between May 15 and 21, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Engineering Requirements Quality Assistant On-Premises\u00a0\u2013 all versions<\/li>\n\t<li>IBM Maximo Asset Management\u00a0\u2013 versions 7.6.1.2 and 7.6.1.3<\/li>\n\t<li>InfoSphere Information Server\u00a0\u2013 version 11.7<\/li>\n\t<li>PowerVM Hypervisor\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM product security incident response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-286","alert_type":396,"serial_number":"AV23-286","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4232,"title":"Ubuntu security advisory (AV23-287)","uuid":"6cd90bca-985c-44dc-9436-27cf39a1724d","banner":null,"lang":"en","date_modified":"2023-05-23","date_modified_ts":"2023-05-23T17:23:45Z","date_created":"2023-05-23T17:19:52Z","summary":null,"body":["<article data-history-node-id=\"4232\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-287\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-287<br \/><strong>Date: <\/strong>May 23, 2023<\/p>\n\n<p>Between May 15 and 21, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-287","alert_type":396,"serial_number":"AV23-287","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4233,"title":"Dell security advisory (AV23-288)","uuid":"2606b13a-f05f-4f05-96cf-1507e59715fb","banner":null,"lang":"en","date_modified":"2023-05-23","date_modified_ts":"2023-05-23T17:28:15Z","date_created":"2023-05-23T17:24:16Z","summary":null,"body":["<article data-history-node-id=\"4233\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-288\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-288<br \/><strong>Date: <\/strong>May 23, 2023<\/p>\n\n<p>Between May 15 and 21, 2023, Dell published Security Advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Avamar\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Dell Integrated Data Protection Appliance (IDPA)\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell NetWorker Virtual Edition (NVE)\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerProtect DP Series Appliance\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000213738\/dsa-2023-187-dell-avamar-dell-networker-virtual-edition-nve-and-dell-powerprotect-dp-series-appliance-dell-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities-os-security-rollup-2023r1\">Dell Security Update - DSA-2023-187<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-288","alert_type":396,"serial_number":"AV23-288","subject":"dell","moderation_state":"published","external_url":null},{"nid":4235,"title":"[Control systems] Horner Automation security advisory (AV23-289) ","uuid":"bcf80607-b1b8-49eb-b591-37aa3fd9d895","banner":null,"lang":"en","date_modified":"2023-05-23","date_modified_ts":"2023-05-23T19:34:50Z","date_created":"2023-05-23T19:31:14Z","summary":null,"body":["<article data-history-node-id=\"4235\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av23-289\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-289<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 23, 2023<\/p>\n\n<p>On May 23, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cscape\u00a0\u2013 version v9.90 SP8<\/li>\n\t<li>Cscape EnvisionRV\u00a0\u2013 version v4.70<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-143-04\">ICS Advisory\u00a0- ICSA-23-143-04<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av23-289","alert_type":398,"serial_number":"AV23-289","subject":"other","moderation_state":"published","external_url":null},{"nid":4237,"title":"[Control systems] Hitachi Energy security advisory (AV23-291) ","uuid":"1afb2556-b437-4250-9fd1-f996f5ce4245","banner":null,"lang":"en","date_modified":"2023-05-23","date_modified_ts":"2023-05-23T19:39:00Z","date_created":"2023-05-23T19:33:40Z","summary":null,"body":["<article data-history-node-id=\"4237\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-291\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-291<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 23, 2023<\/p>\n\n<p>On May 23, 2023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AFS660\/665S, AFS660\/665C, AFS670v2 \u2013 firmware version 7.1.05 and prior<\/li>\n\t<li>AFS670\/675, AFR67x \u2013 firmware version 9.1.07 and prior<\/li>\n\t<li>AFF660\/665 \u2013 firmware version 03.0.02 and prior<\/li>\n\t<li>AFS65x \u2013 all versions<\/li>\n\t<li>RTU500 \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-143-01\">ICS Advisory - ICSA-23-143-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-143-02\">ICS Advisory - ICSA-23-143-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-291","alert_type":398,"serial_number":"AV23-291","subject":"other","moderation_state":"published","external_url":null},{"nid":4236,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-290) ","uuid":"31c59deb-e457-4621-9695-d7e1ff39d432","banner":null,"lang":"en","date_modified":"2023-05-23","date_modified_ts":"2023-05-23T19:38:39Z","date_created":"2023-05-23T19:35:33Z","summary":null,"body":["<article data-history-node-id=\"4236\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-290\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-290<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 23, 2023<\/p>\n\n<p>On May 23, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>MELSEC Series CPU module\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-143-03\">ICS Advisory\u00a0- ICSA-23-143-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-290","alert_type":396,"serial_number":"AV23-290","subject":"other","moderation_state":"published","external_url":null},{"nid":4238,"title":"Apple security advisory (AV23-292)","uuid":"027070bc-80bb-40af-a589-14677126a557","banner":null,"lang":"en","date_modified":"2023-05-23","date_modified_ts":"2023-05-23T19:46:23Z","date_created":"2023-05-23T19:41:14Z","summary":null,"body":["<article data-history-node-id=\"4238\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-292\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-292<br \/><strong>Date:<\/strong> May\u00a023,\u00a02023<\/p>\n\n<p>On May\u00a023,\u00a02023, Apple published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>iTunes for Windows \u2013 versions prior to 12.12.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213763\">Apple security update \u2013 HT213763<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-292","alert_type":396,"serial_number":"AV23-292","subject":"apple","moderation_state":"published","external_url":null},{"nid":4244,"title":"GitLab security advisory (AV23-293)","uuid":"0c626ac9-2a7e-469a-b704-0506ac662ac8","banner":null,"lang":"en","date_modified":"2023-05-24","date_modified_ts":"2023-05-24T18:56:31Z","date_created":"2023-05-24T18:52:51Z","summary":null,"body":["<article data-history-node-id=\"4244\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-293\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-293<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 24, 2023<\/p>\n\n<p>On May 23, 2023, GitLab published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 version 16.0.0<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 version 16.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/05\/23\/critical-security-release-gitlab-16-0-1-released\/\">GitLab security advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-293","alert_type":396,"serial_number":"AV23-293","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4245,"title":"[Control systems] Moxa security advisory (AV23-294)","uuid":"09aaf66e-b866-4060-b0f2-8e691bd34f80","banner":null,"lang":"en","date_modified":"2023-05-25","date_modified_ts":"2023-05-25T19:06:45Z","date_created":"2023-05-25T18:37:58Z","summary":null,"body":["<article data-history-node-id=\"4245\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av23-294\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-294<br \/><strong>Date: <\/strong>May\u00a025, 2023<\/p>\n\n<p>On May\u00a025, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MXsecurity Series\u00a0\u2013 version v1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-145-01\">ICS Advisory\u00a0- ICSA-23-145-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av23-294","alert_type":398,"serial_number":"AV23-294","subject":"ics","moderation_state":"published","external_url":null},{"nid":4247,"title":"Dell security advisory (AV23-295)","uuid":"74d1b2f9-44ca-4b0f-ae3d-1ea42f3f9d74","banner":null,"lang":"en","date_modified":"2023-05-29","date_modified_ts":"2023-05-29T18:27:27Z","date_created":"2023-05-29T18:10:32Z","summary":null,"body":["<article data-history-node-id=\"4247\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-295\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-295<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 29, 2023<\/p>\n\n<p>Between May 22 and 28, 2023, Dell published Security Advisories to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>PowerEdge T30\u00a0\u2013 versions prior to 1.11.0<\/li>\n\t<li>PowerEdge T40\u00a0\u2013 versions prior to 1.11.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000214120\/dsa-2023-183-dell-poweredge-t30-and-t40-mini-tower-security-update-for-an-tianocore-edk2-vulnerability\">Dell Security Update\u00a0- DSA-2023-183<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-295","alert_type":396,"serial_number":"AV23-295","subject":"dell","moderation_state":"published","external_url":null},{"nid":4248,"title":"IBM security advisory (AV23-296)","uuid":"d3bbb32e-d1f3-4ae6-9be6-58ea8c8fe0d1","banner":null,"lang":"en","date_modified":"2023-05-29","date_modified_ts":"2023-05-29T18:56:45Z","date_created":"2023-05-29T18:42:45Z","summary":null,"body":["<article data-history-node-id=\"4248\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-296\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-296<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 29, 2023<\/p>\n\n<p>Between May 22 and 28, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM CICS TX Advanced\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6998367\">IBM Security Bulletin\u00a0- 6998767<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6998361\">IBM Security Bulletin\u00a0- 6998361<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-296","alert_type":396,"serial_number":"AV23-296","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4249,"title":"HPE security advisory (AV23-298)","uuid":"9082657b-bd51-46a4-a008-d08d2b5795f4","banner":null,"lang":"en","date_modified":"2023-05-29","date_modified_ts":"2023-05-29T19:43:59Z","date_created":"2023-05-30T11:59:41Z","summary":null,"body":["<article data-history-node-id=\"4249\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-298\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-298<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May\u00a030, 2023<\/p>\n\n<p>On May 25,\u00a02023, HPE published security bulletins to address vulnerabilities in multiple products.<\/p>\n\n<p>Included were updates for the following:<\/p>\n\n<ul><li>HPE IceWall \u2013 multiple versions and platforms<\/li>\n\t<li>HPE ProLiant XL170r Gen10 Server \u2013 firmware versions prior to 2023_0502<\/li>\n\t<li>HPE SimpliVity \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440\">HPE security bulletins<\/a><\/li>\n\t<li>\u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-298","alert_type":396,"serial_number":"AV23-298","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4251,"title":"Ubuntu security advisory (AV23-297)","uuid":"00ecea51-6660-4f1b-a52f-4abf32254997","banner":null,"lang":"en","date_modified":"2023-05-29","date_modified_ts":"2023-05-29T19:33:52Z","date_created":"2023-05-30T17:15:49Z","summary":null,"body":["<article data-history-node-id=\"4251\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-297\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-297<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 29,\u00a02023<\/p>\n\n<p>Between May 22\u00a0and 28,\u00a02023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu security notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-297","alert_type":396,"serial_number":"AV23-297","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4252,"title":"[Control systems] Advantech security advisory (AV23-299)","uuid":"2a850c87-25d2-4aaf-ac25-c053cb3a26bd","banner":null,"lang":"en","date_modified":"2023-05-30","date_modified_ts":"2023-05-30T17:36:20Z","date_created":"2023-05-30T17:29:18Z","summary":null,"body":["<article data-history-node-id=\"4252\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-299\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-299<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May\u00a030,\u00a02023<\/p>\n\n<p>On May 30,\u00a02023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>WebAccess\/SCADA - version 8.4.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-150-01\">ICS advisory - ICSA-23-150-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-299","alert_type":398,"serial_number":"AV23-299","subject":"other","moderation_state":"published","external_url":null},{"nid":4253,"title":"Barracuda security advisory (AV23-300) - Update 1","uuid":"9c630487-8169-4324-ac50-67d3858f4a8d","banner":null,"lang":"en","date_modified":"2023-06-15","date_modified_ts":"2023-06-15T20:14:56Z","date_created":"2023-05-31T17:34:40Z","summary":null,"body":["<article data-history-node-id=\"4253\" about=\"\/en\/alerts-advisories\/barracuda-security-advisory-av23-300\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-300<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 31, 2023<br \/><strong>Updated: <\/strong>June 15, 2023<\/p>\n\n<p>Between May 23\u00a0and\u00a030, 2023, Barracuda published security advisories to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Barracuda Email Security Gateway Appliance \u2013 versions 5.1.3.001 to 9.2.0.006<\/li>\n<\/ul><p>Barracuda has indicated that CVE-2023-2868 has been actively exploited.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On June 15, 2023, Barracuda updated their advisory related to vulnerability CVE-2023-2868. Included within the advisory were references to a security blog published by Mandiant that provided a detailed analysis of the reported activity, indicators of compromise (IOCs) and network and file-based signatures that organizations can leverage for their network defences.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mandiant.com\/resources\/blog\/barracuda-esg-exploited-globally\">Mandiant Barracuda ESG exploited globally<\/a><\/li>\n\t<li><a href=\"https:\/\/www.barracuda.com\/company\/legal\/esg-vulnerability\">Barracuda security notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/barracuda-security-advisory-av23-300","alert_type":396,"serial_number":"AV23-300","subject":"other","moderation_state":"published","external_url":null},{"nid":4254,"title":"Google Chrome security advisory (AV23-301)","uuid":"eb89ece4-20a5-4170-b039-f83e69b72b5a","banner":null,"lang":"en","date_modified":"2023-05-31","date_modified_ts":"2023-05-31T17:47:07Z","date_created":"2023-05-31T17:43:29Z","summary":null,"body":["<article data-history-node-id=\"4254\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-301\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-301<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>May 31, 2023<\/p>\n\n<p>On May 30,\u00a02023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 114.0.5735.90\/91 (Windows) and 114.0.5735.90 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/05\/stable-channel-update-for-desktop_30.html\">Google chrome security advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-301","alert_type":396,"serial_number":"AV23-301","subject":"other","moderation_state":"published","external_url":null},{"nid":4255,"title":"[Control systems] ABB security advisory (AV23-302)","uuid":"73f7731e-7fb7-4b28-bf42-ffbe4e2ae337","banner":null,"lang":"en","date_modified":"2023-06-01","date_modified_ts":"2023-06-01T13:38:59Z","date_created":"2023-06-01T13:33:22Z","summary":null,"body":["<article data-history-node-id=\"4255\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-302\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-302<br \/><strong>Date: <\/strong>June\u00a01, 2023<\/p>\n\n<p>On May\u00a031, 2023, ABB published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>B&amp;R APROL\u00a0- version 4.2-07 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1683466151350-en-original-1.0.pdf\">ABB Advisory\u00a0\u2013 SA23P011 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-302","alert_type":398,"serial_number":"AV23-302","subject":"abb","moderation_state":"published","external_url":null},{"nid":4256,"title":"MOVEit Transfer security advisory (AV23-303)","uuid":"4d414df7-4336-42f7-a944-627384bca49a","banner":null,"lang":"en","date_modified":"2023-06-01","date_modified_ts":"2023-06-01T18:54:33Z","date_created":"2023-06-01T18:47:57Z","summary":null,"body":["<article data-history-node-id=\"4256\" about=\"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-303\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-303<br \/><strong>Date: <\/strong>June\u00a01, 2023<\/p>\n\n<p>On May\u00a031, 2023, Progress published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>MOVEit Transfer\u00a0\u2013 versions 2023.0.0, 2022.1.x, 2022.0.x, 2021.1.x and 2021.0.x<\/li>\n<\/ul><p>The Cyber Centre has received reports that this vulnerability may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Vulnerability-31May2023\">MOVEit Transfer Critical Vulnerability<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-303","alert_type":396,"serial_number":"AV23-303","subject":"other","moderation_state":"published","external_url":null},{"nid":4258,"title":"[Control systems] HID Global security advisory (AV23-304)","uuid":"e745f6b5-134b-414b-b23c-f6dc6b98000d","banner":null,"lang":"en","date_modified":"2023-06-01","date_modified_ts":"2023-06-01T20:12:33Z","date_created":"2023-06-01T19:49:50Z","summary":null,"body":["<article data-history-node-id=\"4258\" about=\"\/en\/alerts-advisories\/control-systems-hid-global-security-advisory-av23-304\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-304<br \/><strong>Date: <\/strong>June\u00a01, 2023<\/p>\n\n<p>On June\u00a01, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HID SAFE\u00a0- versions 5.8.0 through 5.11.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-152-02\">ICS Advisory\u00a0- ICSA-23-152-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hid-global-security-advisory-av23-304","alert_type":398,"serial_number":"AV23-304","subject":"ics","moderation_state":"published","external_url":null},{"nid":4261,"title":"Dell security advisory (AV23-305)","uuid":"e28907c0-f499-444e-9db9-1b2db4da9cca","banner":null,"lang":"en","date_modified":"2023-06-05","date_modified_ts":"2023-06-05T18:08:53Z","date_created":"2023-06-05T18:00:55Z","summary":null,"body":["<article data-history-node-id=\"4261\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-305\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-305<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date:<\/strong> June 5, 2023<\/p>\n\n<p>Between May 29 and June 4, 2023, Dell published Security Advisories to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Dell Secure Connect Gateway\u00a0\u2013 version 5.14.00.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000214205\/dsa-2023-164-dell-secure-connect-gateway-security-update-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-164<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-305","alert_type":396,"serial_number":"AV23-305","subject":"dell","moderation_state":"published","external_url":null},{"nid":4262,"title":"IBM security advisory (AV23-306)","uuid":"18bb33ca-bfc1-47e5-9c32-0be84e8813a0","banner":null,"lang":"en","date_modified":"2023-06-05","date_modified_ts":"2023-06-05T18:35:23Z","date_created":"2023-06-05T18:18:16Z","summary":null,"body":["<article data-history-node-id=\"4262\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-306\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-306<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 5, 2023<\/p>\n\n<p>Between May 29 and June 4, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Business Automation Manager Open Editions\u00a0\u2013 versions 8.0.0, 8.0.1 and 8.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6999633\">IBM Security Bulletin\u00a0- 6999633<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-306","alert_type":396,"serial_number":"AV23-306","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4263,"title":"Ubuntu security advisory (AV23-307)","uuid":"eaaca018-1663-495c-8ebc-82f97d7111f4","banner":null,"lang":"en","date_modified":"2023-06-05","date_modified_ts":"2023-06-05T18:52:16Z","date_created":"2023-06-05T18:38:45Z","summary":null,"body":["<article data-history-node-id=\"4263\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-307\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-307<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 5, 2023<\/p>\n\n<p>Between May 29 and June 4, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-307","alert_type":396,"serial_number":"AV23-307","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4264,"title":"Microsoft Edge security advisory (AV23-308)","uuid":"c1c72d6b-bcf8-49c5-b0c8-771b231b8367","banner":null,"lang":"en","date_modified":"2023-06-05","date_modified_ts":"2023-06-05T19:43:24Z","date_created":"2023-06-05T19:40:24Z","summary":null,"body":["<article data-history-node-id=\"4264\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-308\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-308<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 05, 2023<\/p>\n\n<p>On June 2, 2023, Microsoft published Security Updates to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 114.0.1823.37<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/deployedge\/microsoft-edge-relnotes-security#june-2-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-308","alert_type":396,"serial_number":"AV23-308","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4265,"title":"Foxit security advisory (AV23-309)","uuid":"6a582688-76a8-4d25-b1a6-935fa7c139b1","banner":null,"lang":"en","date_modified":"2023-06-05","date_modified_ts":"2023-06-05T19:55:21Z","date_created":"2023-06-05T19:50:50Z","summary":null,"body":["<article data-history-node-id=\"4265\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av23-309\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-309<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 5, 2023<\/p>\n\n<p>On May 31, 2023, Foxit published a Security Advisory to address vulnerabilities in the following product :<\/p>\n\n<ul><li><span>Foxit PDF Editor \u2013 version 11.2.5.53785 and prior and version 10.1.11.37866 and prior<\/span><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\"><span>Foxit Security Bulletins<\/span><\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av23-309","alert_type":396,"serial_number":"AV23-309","subject":"other","moderation_state":"published","external_url":null},{"nid":4266,"title":"Google Chrome security advisory (AV23-310)","uuid":"e943974a-1f32-453f-b5ce-026d118ed739","banner":null,"lang":"en","date_modified":"2023-06-06","date_modified_ts":"2023-06-06T15:36:07Z","date_created":"2023-06-06T15:32:06Z","summary":null,"body":["<article data-history-node-id=\"4266\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-310\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-310<br \/><strong>Date: <\/strong>June 6, 2023<\/p>\n\n<p>On June 5, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 114.0.5735.110 (Windows) and 114.0.5735.106 (Linux and Mac)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2023-3079 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/06\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-310","alert_type":396,"serial_number":"AV23-310","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4267,"title":"HPE security advisory (AV23-311)","uuid":"5e8bf70f-978c-46a8-91a9-d62d43f1a4da","banner":null,"lang":"en","date_modified":"2023-06-06","date_modified_ts":"2023-06-06T15:42:01Z","date_created":"2023-06-06T15:38:31Z","summary":null,"body":["<article data-history-node-id=\"4267\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-311\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-311<br \/><strong>Date: <\/strong>June 6, 2023<\/p>\n\n<p>Between May 30 and June 4, 2023, HPE published Security Bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HP-UX BIND\u00a0\u2013 versions 9.11.1 prior to C.9.11.1.6.0<\/li>\n\t<li>HP-UX IPv6 Stack\u00a0\u2013 version 11.31 cumulative ARPA Transport patch PHNE_44861 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-311","alert_type":396,"serial_number":"AV23-311","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4268,"title":"[Control systems] ABB security advisory (AV23-312)","uuid":"92250ce7-7cbc-4cf7-94b5-75ca09ae8af8","banner":null,"lang":"en","date_modified":"2023-06-06","date_modified_ts":"2023-06-06T15:47:31Z","date_created":"2023-06-06T15:43:27Z","summary":null,"body":["<article data-history-node-id=\"4268\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-312\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-312<br \/><strong>Date: <\/strong>June 6, 2023<\/p>\n\n<p>On June 1, 2023, ABB published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ASPECT-Enterprise\u00a0\u2013 multiple models and firmware versions prior to 3.07.01<\/li>\n\t<li>MATRIX Series\u00a0\u2013 multiple models and firmware versions prior to 3.07.01<\/li>\n\t<li>NEXUS Series\u00a0\u2013 multiple models and firmware versions prior to 3.07.01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2CKA000073B5403&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Advisory\u00a0\u2013 2CKA000073B5403<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-312","alert_type":398,"serial_number":"AV23-312","subject":"abb","moderation_state":"published","external_url":null},{"nid":4269,"title":"Mozilla security advisory (AV23-313)","uuid":"14823bd8-81f2-4043-8023-5def526ec291","banner":null,"lang":"en","date_modified":"2023-06-06","date_modified_ts":"2023-06-06T19:34:34Z","date_created":"2023-06-06T19:27:58Z","summary":null,"body":["<article data-history-node-id=\"4269\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-313\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-313<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 6, 2023<\/p>\n\n<p>On June 6, 2023, Mozilla published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR \u2013 versions prior to 102.12<\/li>\n\t<li>Firefox \u2013 versions prior to 114<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-19\/\">Mozilla Security Advisory - MFSA 2023-19<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-20\/\">Mozilla Security Advisory - MFSA 2023-20<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-313","alert_type":396,"serial_number":"AV23-313","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4270,"title":"Android security advisory \u2013 June 2023 Monthly Rollup (AV23-314)","uuid":"007e6403-2054-4a6a-a755-49db9c960ef1","banner":null,"lang":"en","date_modified":"2023-06-06","date_modified_ts":"2023-06-06T19:43:04Z","date_created":"2023-06-06T19:39:31Z","summary":null,"body":["<article data-history-node-id=\"4270\" about=\"\/en\/alerts-advisories\/android-security-advisory-june-2023-monthly-rollup-av23-314\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-314<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 6, 2023<\/p>\n\n<p>On June 5, 2023, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-06-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -French-******************************************************--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-june-2023-monthly-rollup-av23-314","alert_type":396,"serial_number":"AV23-314","subject":"android","moderation_state":"published","external_url":null},{"nid":4271,"title":"[Control systems] Delta Electronics security advisory (AV23-315) ","uuid":"9d0d58b5-1ed3-4124-9659-ea2cd6e26c69","banner":null,"lang":"en","date_modified":"2023-06-07","date_modified_ts":"2023-06-07T14:05:08Z","date_created":"2023-06-07T14:01:46Z","summary":null,"body":["<article data-history-node-id=\"4271\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-315\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-315<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 7, 2023<\/p>\n\n<p>On June 6, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>CNCSoft-B DOPSoft \u2013 version 1.0.0.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-157-01\">ICS Advisory (ICSA-23-157-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-315","alert_type":398,"serial_number":"AV23-315","subject":"other","moderation_state":"published","external_url":null},{"nid":4272,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-316) ","uuid":"768e0093-711d-4369-882e-5f68e09cb455","banner":null,"lang":"en","date_modified":"2023-06-07","date_modified_ts":"2023-06-07T14:14:36Z","date_created":"2023-06-07T14:07:32Z","summary":null,"body":["<article data-history-node-id=\"4272\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-316\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-316<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 7, 2023<\/p>\n\n<p>On June 6, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>MELSEC iQ-R\/iQ-F Series EtherNet\/IP Modules and EtherNet\/IP Configuration tools:\n\t<ul><li>RJ71EIP91 \u2013 all versions<\/li>\n\t\t<li>SW1DNN-EIPCT-BD \u2013 all versions<\/li>\n\t\t<li>FX5-ENET\/IP \u2013 all versions<\/li>\n\t\t<li>SW1DNN-EIPCTFX5-BD \u2013 all versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-157-02\">ICS Advisory - ICSA-23-157-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-316","alert_type":398,"serial_number":"AV23-316","subject":"other","moderation_state":"published","external_url":null},{"nid":4273,"title":"VMware security advisory (AV23-317)","uuid":"04844584-6610-4979-8f1c-3264e1f2f9fb","banner":null,"lang":"en","date_modified":"2023-06-07","date_modified_ts":"2023-06-07T16:50:38Z","date_created":"2023-06-07T16:46:48Z","summary":null,"body":["<article data-history-node-id=\"4273\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-317\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-317<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 7, 2023<\/p>\n\n<p>On June 7, 2023, VMware published a Security Advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Aria Operations Networks \u2013 versions 6.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0012.html\">VMware security advisory - VMSA-2023-0012<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware security advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-317","alert_type":396,"serial_number":"AV23-317","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4274,"title":"Microsoft Edge security advisory (AV23-318)","uuid":"a438eb57-a527-404c-a304-74303d6c34ab","banner":null,"lang":"en","date_modified":"2023-06-07","date_modified_ts":"2023-06-07T16:57:28Z","date_created":"2023-06-07T16:54:10Z","summary":null,"body":["<article data-history-node-id=\"4274\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-318\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-318\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 7, 2023\n<\/p>\n\n<p>On June 6, 2023, Microsoft published a security update to address a vulnerability in the following product:\n<\/p>\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 114.0.1823.41<\/li>\n\n<\/ul><p>\n  Microsoft is aware that an exploit for CVE-2023-3079 exists in the wild.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-6-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-318","alert_type":396,"serial_number":"AV23-318","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4276,"title":"Cisco security advisory (AV23-319)","uuid":"30b42a8f-335d-45c8-8de9-310e1a353225","banner":null,"lang":"en","date_modified":"2023-06-07","date_modified_ts":"2023-06-07T19:00:49Z","date_created":"2023-06-07T18:50:46Z","summary":null,"body":["<article data-history-node-id=\"4276\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-319\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-319<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 7, 2023<\/p>\n\n<p>On June 7, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) \u2013 versions prior to 14.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-expressway-priv-esc-Ls2B9t7b\">Cisco security advisory - cisco-sa-expressway-priv-esc-ls2b9t7b<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco security advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-319","alert_type":396,"serial_number":"AV23-319","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4277,"title":"[Control systems] Sensormatic Electronics security advisory (AV23-320)","uuid":"82ed7c89-d2f4-4a32-a932-9eb8f5a6cf3e","banner":null,"lang":"en","date_modified":"2023-06-08","date_modified_ts":"2023-06-08T19:10:41Z","date_created":"2023-06-08T18:26:57Z","summary":null,"body":["<article data-history-node-id=\"4277\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av23-320\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-320<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 8, 2023<\/p>\n\n<p>On June 8, 2023, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Illustra Pro Gen 4 Dome\u00a0\u2013 version Illustra.SS016.05.09.04.0006 and prior<\/li>\n\t<li>Illustra Pro Gen 4 PTZ\u00a0\u2013 version Illustra. SS010.05.09.04.0022 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in credential disclosure.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-159-02\">ICS Advisory (ICSA-23-159-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av23-320","alert_type":398,"serial_number":"AV23-320","subject":"ics","moderation_state":"published","external_url":null},{"nid":4278,"title":"[Control systems] Atlas Copco security advisory (AV23-321)","uuid":"116f4dd1-26ee-4422-ba0d-89a4b20d1ed7","banner":null,"lang":"en","date_modified":"2023-06-08","date_modified_ts":"2023-06-08T19:33:21Z","date_created":"2023-06-08T19:23:32Z","summary":null,"body":["<article data-history-node-id=\"4278\" about=\"\/en\/alerts-advisories\/control-systems-atlas-copco-security-advisory-av23-321\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-321<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 8, 2023<\/p>\n\n<p>On June 8, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Power Focus 6000\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-159-01\">ICS Advisory (ICSA-23-159-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-atlas-copco-security-advisory-av23-321","alert_type":398,"serial_number":"AV23-321","subject":"ics","moderation_state":"published","external_url":null},{"nid":4280,"title":"MOVEit Transfer security advisory (AV23-322)","uuid":"6e50263a-c27e-459e-b0c3-93562b6368a4","banner":null,"lang":"en","date_modified":"2023-06-09","date_modified_ts":"2023-06-09T19:23:14Z","date_created":"2023-06-09T19:17:45Z","summary":null,"body":["<article data-history-node-id=\"4280\" about=\"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-322-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-322<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 9, 2023<\/p>\n\n<p>On June\u00a09,\u00a02023, Progress published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>MOVEit Transfer \u2013 versions prior to 2023.0.2, 2022.1.6, 2022.0.5, 2021.1.5 and 2021.0.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Vulnerability-CVE-Pending-Reserve-Status-June-9-2023\">MOVEit Transfer Critical Vulnerability<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-322-0","alert_type":396,"serial_number":"AV23-322","subject":"other","moderation_state":"published","external_url":null},{"nid":4281,"title":"Vulnerability impacting FortiGate\/FortiOS (CVE-2023-27997) \u2013 Update 2","uuid":"82e5aab9-4e3e-474d-82a3-e63943afcadf","banner":null,"lang":"en","date_modified":"2023-07-06","date_modified_ts":"2023-07-06T15:26:31Z","date_created":"2023-06-12T15:14:05Z","summary":null,"body":["<article data-history-node-id=\"4281\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-fortigatefortios-cve-2023-27997\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-006<br \/><strong>Date:\u00a0<\/strong>July 6,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On June\u00a010,\u00a02023, the Cyber Centre became aware of open-source reporting which indicated there was a pending vulnerability disclosure expected for June 13, 2023, affecting the SSL-VPN component on FortiGate appliances <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. On June\u00a011, additional open-source reporting reinforced these claims with confirmation by the threat researcher and the organization the researcher represents. <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/p>\n\n<p>On June\u00a011,\u00a02023, BleepingComputer published an article containing citations from the researcher that identifies the vulnerability impacts the SSL-VPN components of FortiGATE\/FortiOS which could result in remote code execution. The researcher claims the vulnerability can be exploited without authentication and the capability to bypass multi-factor authentication reportedly exists.<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<p>Open-source indicates that the CVE assigned to this vulnerability is CVE-2023-27997.<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/p>\n<\/section><section><h2>Update 1<\/h2>\n\n<p>On June 12, 2023, Fortinet published security advisory FG-IR-23-097 describing CVE-2023-27997, which was originally disclosed in open-source<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>. Fortinet reports that a heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiProxy SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests. Fortinet also reports that the vulnerability may have been exploited in a limited number of cases<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>. On 13 June the Cybersecurity and Infrastructure Security Agency (CISA) updated the Known Exploited Vulnerabilities catalog to reflect known exploitation of this vulnerability.<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup><\/p>\n\n<p>The affected products list has been updated below to reflect Fortinet's recommended patch levels.<\/p>\n<\/section><section><h2>Update 2<\/h2>\n\n<p>On June 30, 2023, researchers at Bishop Fox reported that there continues to be a significant number of vulnerable Fortinet devices accessible via the Internet and demonstrated a proof of concept of the vulnerability\u00a0<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>. On July 5, 2023, the Canadian Centre for Cyber Security (Cyber Centre) conducted an assessment and has identified that a number of organizations within Canada continue to use Fortinet appliances that are vulnerable to CVE-2023-27997. Canadian organizations are strongly encouraged to review all Fortinet devices that use SSL-VPN to confirm that all unpatched devices are isolated and patched.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>This vulnerability can be exploited if unpatched Fortinet devices permit external connectivity to the SSL-VPN service. The Cyber Centre recommends as a temporary workaround that that the SSL-VPN service be disabled until patching can be completed.<\/p>\n\n<p>The Cyber Centre strongly recommends that organizations patch any vulnerable Fortinet devices. On June 12, 2023, Fortinet published FG-IR-23-097<sup id=\"fn7a-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> which identifies the following affected products and recommended patch levels:<\/p>\n\n<ul><li>FortiOS-6K7K version 7.0.12 or above<\/li>\n\t<li>FortiOS-6K7K version 6.4.13 or above<\/li>\n\t<li>FortiOS-6K7K version 6.2.15 or above<\/li>\n\t<li>FortiOS-6K7K version 6.0.17 or above<\/li>\n\t<li>FortiProxy version 7.2.4 or above<\/li>\n\t<li>FortiProxy version 7.0.10 or above<\/li>\n\t<li>FortiOS version 7.4.0 or above<\/li>\n\t<li>FortiOS version 7.2.5 or above<\/li>\n\t<li>FortiOS version 7.0.12 or above<\/li>\n\t<li>FortiOS version 6.4.13 or above<\/li>\n\t<li>FortiOS version 6.2.14 or above<\/li>\n\t<li>FortiOS version 6.0.17 or above<\/li>\n<\/ul><p>Organizations should review and implement the Cyber Centre\u2019s Top 10 IT Security Actions <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t<li>Patching operating systems and applications.<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the Official Languages Act is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/olympecyberdefense.fr\/1193-2\/\">Alerte Fortinet FortiGate VPN SSL (French only)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/twitter.com\/cfreal_\/status\/1667852157536616451\">Twitter (Charles Fol - @cfreal_)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/twitter.com\/LexfoSecurite\/status\/1667898590713266177\">Twitter (Lexfo - @LexfoSecurite)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fortinet-fixes-critical-rce-flaw-in-fortigate-ssl-vpn-devices-patch-now\/\">Fortinet fixes critical RCE flaw in Fortigate SSL-VPN devices, patch now<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-27997\">CVE-2023-27997<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-097\">FortiOS &amp; FortiProxy\u00a0- Heap buffer overflow in sslvpn pre-authentication<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/www.fortinet.com\/blog\/psirt-blogs\/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign\">Analysis of CVE-2023-27997 and Clarifications on Volt Typhoon Campaign<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities Catalog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote <\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">CVE-2023-27997 Is Exploitable, and 69% of FortiGate Firewalls Are Vulnerable<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote <\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-fortigatefortios-cve-2023-27997","alert_type":397,"serial_number":"AL23-006","subject":"other","moderation_state":"published","external_url":null},{"nid":4282,"title":"Ubuntu security advisory (AV23-323)","uuid":"068ddc84-4718-4af5-ba04-57e0fe56ed0a","banner":null,"lang":"en","date_modified":"2023-06-12","date_modified_ts":"2023-06-12T16:09:14Z","date_created":"2023-06-12T15:59:27Z","summary":null,"body":["<article data-history-node-id=\"4282\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-323\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-323<br \/><strong>Date: <\/strong>June\u00a012, 2023<\/p>\n\n<p>Between June\u00a05 and 11, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-323","alert_type":396,"serial_number":"AV23-323","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4283,"title":"IBM security advisory (AV23-324)","uuid":"519a0f25-0875-4c9b-861e-f66644240e9a","banner":null,"lang":"en","date_modified":"2023-06-12","date_modified_ts":"2023-06-12T16:18:43Z","date_created":"2023-06-12T16:13:44Z","summary":null,"body":["<article data-history-node-id=\"4283\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-324\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-324<br \/><strong>Date: <\/strong>June\u00a012, 2023<\/p>\n\n<p>Between June\u00a05 and 11, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Financial Transaction Manager for Corporate Payment Services for Multi-Platform\u00a0\u2013 version 3.2.10<\/li>\n\t<li>Financial Transaction Manager for Digital Payments for Multi-Platform\u00a0\u2013 version 3.2.10<\/li>\n\t<li>Financial Transaction Manager for High Value Payments for Multi-Platform\u00a0\u2013 version 3.2.10<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM i Modernization Engine for Lifecycle Integration\u00a0\u2013 version 1.0 to 1.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7002671\">IBM Security Bulletin\u00a0- 7002671<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6998727\">IBM Security Bulletin\u00a0- 6998727<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7001851\">IBM Security Bulletin\u00a0- 7001851<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-324","alert_type":396,"serial_number":"AV23-324","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4284,"title":"Dell security advisory (AV23-325)","uuid":"b794dc78-08ec-4bc0-b66c-80cec6af4102","banner":null,"lang":"en","date_modified":"2023-06-12","date_modified_ts":"2023-06-12T16:31:49Z","date_created":"2023-06-12T16:13:44Z","summary":null,"body":["<article data-history-node-id=\"4284\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-325\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-325<br \/><strong>Date: <\/strong>June\u00a012, 2023<\/p>\n\n<p>Between June\u00a05 and 11, 2023, Dell published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CyberSense\u00a0\u2013 versions prior to 8.2<\/li>\n\t<li>Dell Streaming Data Platform\u00a0\u2013 version 1.1.x to 1.6.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/fr-ca\/000214647\/dsa-2023-202-security-update-for-dell-index-engines-cybersense\">Dell Security Update\u00a0- DSA-2023-202<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000214599\/dsa-2023-195-dell-streaming-data-platform-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-195<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-325","alert_type":396,"serial_number":"AV23-325","subject":"dell","moderation_state":"published","external_url":null},{"nid":4285,"title":"SAP security advisory \u2013 June 2023 monthly rollup (AV23-326)","uuid":"cdfd906e-1ef5-4d3d-a737-e1f41d80c96c","banner":null,"lang":"en","date_modified":"2023-06-13","date_modified_ts":"2023-06-13T15:50:09Z","date_created":"2023-06-13T15:45:54Z","summary":null,"body":["<article data-history-node-id=\"4285\" about=\"\/en\/alerts-advisories\/sap-security-advisory-june-2023-monthly-rollup-av23-326\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-326<br \/><strong>Date: <\/strong>June 13, 2023<\/p>\n\n<p>On June 13, 2023, SAP published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Plant Connectivity\u00a0\u2013 version 15.5<\/li>\n\t<li>SAP UI5 Variant Management\u00a0\u2013 versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757 and UI_700 200<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day\u00a0\u2013 June 2023<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-june-2023-monthly-rollup-av23-326","alert_type":396,"serial_number":"AV23-326","subject":"sap","moderation_state":"published","external_url":null},{"nid":4286,"title":"[Control systems] ABB security advisory (AV23-327)","uuid":"7669fb43-96d0-4558-a605-4c79e99102a2","banner":null,"lang":"en","date_modified":"2023-06-13","date_modified_ts":"2023-06-13T15:55:51Z","date_created":"2023-06-13T15:51:09Z","summary":null,"body":["<article data-history-node-id=\"4286\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-327\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-327<br \/><strong>Date: <\/strong>June 13, 2023<\/p>\n\n<p>On June 12, 2023, ABB published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>REX640 PCL1\u00a0\u2013 versions prior to 1.0.8<\/li>\n\t<li>REX640 PCL2\u00a0\u2013 versions prior to 1.1.4<\/li>\n\t<li>REX640 PCL3\u00a0\u2013 versions prior to 1.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001423&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Advisory\u00a0- 2NGA001423<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-327","alert_type":398,"serial_number":"AV23-327","subject":"abb","moderation_state":"published","external_url":null},{"nid":4287,"title":"[Control systems] Schneider Electric security advisory (AV23-328) ","uuid":"c9807670-2542-4a92-aa18-e07378aa6dcf","banner":null,"lang":"en","date_modified":"2023-06-13","date_modified_ts":"2023-06-13T16:01:30Z","date_created":"2023-06-13T15:56:34Z","summary":null,"body":["<article data-history-node-id=\"4287\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-328\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-328<br \/><strong>Date: <\/strong>June 13, 2023<\/p>\n\n<p>On June 13, 2023, Schneider Electric published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Foxboro DCS Control Core Services\u00a0\u2013 versions prior to update HF9857795<\/li>\n\t<li>EcoStruxure Operator Terminal Expert\u00a0\u2013 version 3.3 SP1 and prior<\/li>\n\t<li>Foxboro SCADA\u00a0\u2013 all versions<\/li>\n\t<li>IGSS Dashboard\u00a0\u2013 version v16.0.0.23130 and prior<\/li>\n\t<li>Pro-face BLUE\u00a0\u2013 version 3.3 SP1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-328","alert_type":396,"serial_number":"AV23-328","subject":"other","moderation_state":"published","external_url":null},{"nid":4288,"title":"Citrix security advisory (AV23-329)","uuid":"a0f10ca8-daca-4b97-b45a-121214043be7","banner":null,"lang":"en","date_modified":"2023-06-13","date_modified_ts":"2023-06-13T16:06:42Z","date_created":"2023-06-13T16:02:49Z","summary":null,"body":["<article data-history-node-id=\"4288\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av23-329\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-329<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 13, 2023<\/p>\n\n<p>On June 13, 2023, Citrix published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ShareFile storage zones controller\u00a0\u2013 versions prior to 5.11.24<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX559517\/sharefile-storagezones-controller-security-update-for-cve202324489\">Citrix Security Advisory\u00a0- CTX559517<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center\/search#\/All%20Products?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av23-329","alert_type":396,"serial_number":"AV23-329","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4289,"title":"Fortinet security advisory (AV23-330)","uuid":"8a906367-9a9e-4c32-ada1-5fe0e0a8b399","banner":null,"lang":"en","date_modified":"2023-06-13","date_modified_ts":"2023-06-13T18:37:35Z","date_created":"2023-06-13T18:31:27Z","summary":null,"body":["<article data-history-node-id=\"4289\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-330\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-330<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 13, 2023<\/p>\n\n<p>On June 12, 2023, Fortinet published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following::<\/p>\n\n<ul><li>FortiADC and FortiADCManager\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiOS\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>FortiProxy\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiSIEM\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>Fortinet has indicated that CVE-2023-27997 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"\/en\/alerts-advisories\/vulnerability-impacting-fortigatefortios-cve-2023-27997\">Alert\u00a0\u2013 Vulnerability impacting FortiGate\/FortiOS (CVE-2023-27997)<\/a><\/li>\n\t<li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-23-097\">Fortinet PSIRT Advisory (FG-IR-23-097)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-330","alert_type":396,"serial_number":"AV23-330","subject":"other","moderation_state":"published","external_url":null},{"nid":4290,"title":"[Control systems] Siemens security advisory (AV23-331) ","uuid":"93f98532-408e-473c-8504-9faa4e019103","banner":null,"lang":"en","date_modified":"2023-06-13","date_modified_ts":"2023-06-13T18:42:52Z","date_created":"2023-06-13T18:38:15Z","summary":null,"body":["<article data-history-node-id=\"4290\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-331\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-331<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 13, 2023<\/p>\n\n<p>On June 13, 2023, Siemens published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>POWER METER SICAM Q200 family\u00a0\u2013 versions prior to V2.70<\/li>\n\t<li>SIMATIC PCS 7\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-1500 TM MFP\u00a0- BIOS\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-1500 TM MFP\u00a0- Linux\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-PM\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC STEP 7 V5\u00a0\u2013 versions prior to V5.7<\/li>\n\t<li>SINAMICS GL 150\u00a0\u2013 multiple versions<\/li>\n\t<li>SINAMICS PERFECT HARMONY GH180 6SR5\u00a0\u2013 multiple versions<\/li>\n\t<li>SINAMICS SL150\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-331","alert_type":398,"serial_number":"AV23-331","subject":"other","moderation_state":"published","external_url":null},{"nid":4291,"title":"Google Chrome security advisory (AV23-332)","uuid":"17d8fdfe-458f-4b4b-a1b1-419a3471ceda","banner":null,"lang":"en","date_modified":"2023-06-14","date_modified_ts":"2023-06-14T11:52:37Z","date_created":"2023-06-14T11:49:18Z","summary":null,"body":["<article data-history-node-id=\"4291\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-332\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-332<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 14, 2023<\/p>\n\n<p>On June 13, 2023, Google published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 114.0.5735.133\/134 (Windows) and 114.0.5735.133 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/06\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-332","alert_type":396,"serial_number":"AV23-332","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4294,"title":"Adobe security advisory (AV23-334)","uuid":"90c826d2-cdd7-4bfd-8fa9-fe0afcb419d7","banner":null,"lang":"en","date_modified":"2023-06-14","date_modified_ts":"2023-06-14T12:07:30Z","date_created":"2023-06-14T11:56:35Z","summary":null,"body":["<article data-history-node-id=\"4294\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-334\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-334<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 14, 2023<\/p>\n\n<p>On June 13, 2023, Adobe published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Animate 2022 - version 22.0.9\u00a0and prior<\/li>\n\t<li>Adobe Animate 2023 - version 23.0.1\u00a0and prior<\/li>\n\t<li>Adobe Commerce \u2013 multiple versions<\/li>\n\t<li>Adobe Experience Manager (AEM) \u2013 version 6.5.16.0 and prior<\/li>\n\t<li>Adobe Substance 3D Designer - version 12.4.1 and prior<\/li>\n\t<li>Magento Open Source \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/experience-manager\/apsb23-31.html\">Adobe Security Advisory - APSB23-31<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb23-35.html\">Adobe security advisory - APSB23-35<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/animate\/apsb23-36.html\">Adobe security advisory - APSB23-36<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/substance3d_designer\/apsb23-39.html\">Adobe security advisory - APSB23-39<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe security advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-334","alert_type":396,"serial_number":"AV23-334","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4292,"title":"Microsoft security advisory \u2013 June 2023 monthly rollup (AV23-333)","uuid":"3f796c27-d94e-44da-a0c0-afc00908d8be","banner":null,"lang":"en","date_modified":"2023-06-14","date_modified_ts":"2023-06-14T12:04:44Z","date_created":"2023-06-14T12:01:38Z","summary":null,"body":["<article data-history-node-id=\"4292\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-june-2023-monthly-rollup-av23-333\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-333<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 14, 2023<\/p>\n\n<p>On June 13, 2023, Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft .NET \u2013 multiple versions<\/li>\n\t<li>Microsoft Office \u2013 multiple versions<\/li>\n\t<li>Microsoft Sharepoint Server 2019<\/li>\n\t<li>Microsoft Visual Studio \u2013 multiple versions<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Jun\">June 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-june-2023-monthly-rollup-av23-333","alert_type":396,"serial_number":"AV23-333","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4295,"title":"[Control systems] Datalogics security advisory (AV23-335) ","uuid":"e70d7c11-b44f-46c0-b748-504916e35355","banner":null,"lang":"en","date_modified":"2023-06-14","date_modified_ts":"2023-06-14T12:15:21Z","date_created":"2023-06-14T12:09:48Z","summary":null,"body":["<article data-history-node-id=\"4295\" about=\"\/en\/alerts-advisories\/control-systems-datalogics-security-advisory-av23-335\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-335<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a014,\u00a02023<\/p>\n\n<p>On June 13, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Library APFDFL \u2013 version\u00a0v18.0.4PlusP1e and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-164-01\">ICS Advisory (ICSA-23-164-01)<\/a> <!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-datalogics-security-advisory-av23-335","alert_type":398,"serial_number":"AV23-335","subject":"other","moderation_state":"published","external_url":null},{"nid":4296,"title":"[Control systems] Rockwell Automation security advisory (AV23-336) ","uuid":"8e129a31-ef84-4e65-8ead-d9bf083ef276","banner":null,"lang":"en","date_modified":"2023-06-14","date_modified_ts":"2023-06-14T12:22:12Z","date_created":"2023-06-14T12:16:56Z","summary":null,"body":["<article data-history-node-id=\"4296\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-336\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-336<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 14, 2023<\/p>\n\n<p>On June 13,\u00a02023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FactoryTalk Edge Gateway \u2013 version v1.3<\/li>\n\t<li>FactoryTalk Policy Manager \u2013 version v6.11.0<\/li>\n\t<li>FactoryTalk System Services \u2013 version v6.11.0<\/li>\n\t<li>FactoryTalk Transaction Manager \u2013 version 13.10 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-164-02\">ICS Advisory (ICSA-23-164-02)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-164-03\">ICS Advisory (ICSA-23-164-03)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-164-04\">ICS Advisory (ICSA-23-164-04)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-336","alert_type":398,"serial_number":"AV23-336","subject":"other","moderation_state":"published","external_url":null},{"nid":4299,"title":"Understanding ransomware threat actors: LockBit - joint cybersecurity advisory","uuid":"27f40394-63c9-4060-9636-cbc09a5d86ee","banner":null,"lang":"en","date_modified":"2023-06-14","date_modified_ts":"2023-06-14T16:24:48Z","date_created":"2023-06-14T16:17:19Z","summary":null,"body":["<article data-history-node-id=\"4299\" about=\"\/en\/alerts-advisories\/understanding-ransomware-threat-actors-lockbit-joint-cybersecurity-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-007\n  <br \/><strong>Date:\u00a0<\/strong>June\u00a014\u00a02023\n<\/p>\n<section><h2>Audience\n  <\/h2>\n  <p>This Alert is intended for IT professionals and managers of notified organizations.\n  <\/p>\n<\/section><section><h2>Purpose\n  <\/h2>\n  <p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n  <\/p>\n<\/section><section><h2>Details\n  <\/h2>\n  <p>On June\u00a014,\u00a02023, the Canadian Centre for Cyber Security joined cyber security partners from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), the Multi-State Information Sharing and Analysis Center (MS-ISAC),the Australian Cyber Security Centre (ACSC), New Zealand\u2019s Computer Emergency Response Team (CERT-NZ) and National Cyber Security Centre (NCSC-NZ), the National Cyber Security Agency of France (ANSSI), Germany\u2019s Federal Office for Information Security (BSI) and the United Kingdom\u2019s National Cyber Security Centre (NCSC-UK) to publish a joint Cybersecurity Advisory (CSA) detailing LockBit, the world\u2019s most deployed Ransomware-as-a-Service (RaaS) variant.<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n  <p>The first noted infection of Lockbit within Canada was recorded in March\u00a02020, and by\u00a02022, Lockbit was responsible for 22% of all attributed ransomware incidents. The LockBit data leak site lists themselves as the most active global ransomware group and RaaS provider in terms of the number of victims. LockBit affiliates have targeted a broad range of critical infrastructure sectors worldwide including financial services, food and agriculture, education, energy, government and emergency services, healthcare, manufacturing and transportation.\n  <\/p>\n  <p>This joint advisory is being published to provide awareness on observed activity from LockBit ransomware incidents and to provide recommended mitigations to proactively improve an organization\u2019s defenses against this ransomware operation. It contains technical descriptions of the ransomware, indicators of compromise (IoCs), commonly exploited CVEs, as well as tactics, techniques, and procedures (TTPs) used by the threat actors. Additional guidance is also available in the Cyber Centre\u2019s Ransomware playbook (ITSM.00.099) <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> and in the Cyber Centre\u2019s Top 10 IT security actions based on analysis of cyber threat trends to help minimize intrusions or the impacts of a successful cyber intrusion. <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/p>\n  <p>The authoring organizations encourage the implementation of the recommendations found in the referenced CSA to reduce the likelihood and impact of future ransomware incidents.\n  <\/p>\n  <p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.\n  <\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References\n  <\/h2>\n  <dl><dt>Footnote 1\n    <\/dt>\n    <dd id=\"fn1\">\n      <p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/06\/14\/cisa-and-partners-release-joint-advisory-understanding-ransomware-threat-actors-lockbit\">Understanding Ransomware Threat Actors: LockBit - Joint Cybersecurity Advisory<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 2\n    <\/dt>\n    <dd id=\"fn2\">\n      <p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/ransomware-playbook-itsm00099\">The Cyber Centre Ransomware playbook (ITSM.00.099)<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 3\n    <\/dt>\n    <dd id=\"fn3\">\n      <p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions\">Top 10 IT security actions<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n  <\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/understanding-ransomware-threat-actors-lockbit-joint-cybersecurity-advisory","alert_type":397,"serial_number":"AL23-007","subject":"other","moderation_state":"published","external_url":null},{"nid":4300,"title":"Microsoft Edge security advisory (AV23-337)","uuid":"27e090f6-40a4-431a-9684-981f8ae279ab","banner":null,"lang":"en","date_modified":"2023-06-14","date_modified_ts":"2023-06-14T18:36:33Z","date_created":"2023-06-14T18:34:33Z","summary":null,"body":["<article data-history-node-id=\"4300\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-337\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-337<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 14, 2023<\/p>\n\n<p>On June 13, 2023, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 109.0.1518.115<\/li>\n<\/ul><p>Microsoft is aware that an exploit for CVE-2023-3079 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-13-2023 \u2003\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-337","alert_type":396,"serial_number":"AV23-337","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4301,"title":"[Control systems] SUBNET Solutions security advisory (AV23-338)","uuid":"bb7ec160-2d8d-46ca-b893-be7aef7eb99a","banner":null,"lang":"en","date_modified":"2023-06-15","date_modified_ts":"2023-06-15T17:46:47Z","date_created":"2023-06-15T17:38:10Z","summary":null,"body":["<article data-history-node-id=\"4301\" about=\"\/en\/alerts-advisories\/control-systems-subnet-solutions-security-advisory-av23-338\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-338<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a015, 2023<\/p>\n\n<p>On June\u00a015, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>PowerSYSTEM Center\u00a0\u2013 version 2020 U10 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-166-01\">ICS Advisory (ICSA-23-166-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-subnet-solutions-security-advisory-av23-338","alert_type":398,"serial_number":"AV23-338","subject":"ics","moderation_state":"published","external_url":null},{"nid":4302,"title":"[Control systems] Advantech security advisory (AV23-339)","uuid":"4f77b817-265d-41c9-945e-78c43f270978","banner":null,"lang":"en","date_modified":"2023-06-15","date_modified_ts":"2023-06-15T19:40:30Z","date_created":"2023-06-15T17:38:10Z","summary":null,"body":["<article data-history-node-id=\"4302\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-339\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-339<br \/><strong>Date: <\/strong>June\u00a015, 2023<\/p>\n\n<p>On June\u00a015, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>WebAccess\/SCADA\u00a0\u2013 versions prior to 9.1.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-166-02\">ICS Advisory (ICSA-23-166-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-339","alert_type":398,"serial_number":"AV23-339","subject":"ics","moderation_state":"published","external_url":null},{"nid":4303,"title":"MOVEit Transfer security advisory (AV23-340)","uuid":"1a14aad9-b54e-4bae-ad8f-a4ba8d3c65cf","banner":null,"lang":"en","date_modified":"2023-06-15","date_modified_ts":"2023-06-15T20:06:12Z","date_created":"2023-06-15T19:43:18Z","summary":null,"body":["<article data-history-node-id=\"4303\" about=\"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-340\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-340<br \/><strong>Date: <\/strong>June\u00a015, 2023<\/p>\n\n<p>On June\u00a015, 2023, Progress published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>MOVEit Transfer\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Vulnerability-15June2023\">MOVEit Transfer Critical Vulnerability\u00a0- 15\u00a0June 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-340","alert_type":396,"serial_number":"AV23-340","subject":"other","moderation_state":"published","external_url":null},{"nid":4305,"title":"Foxit security advisory (AV23-341)","uuid":"a409ea63-6296-4fd4-b3c8-b8ac428a9168","banner":null,"lang":"en","date_modified":"2023-06-16","date_modified_ts":"2023-06-16T15:32:46Z","date_created":"2023-06-16T15:03:52Z","summary":null,"body":["<article data-history-node-id=\"4305\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av23-341\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-341<br \/><strong>Date: <\/strong>June\u00a016, 2023<\/p>\n\n<p>On June\u00a016, 2023, Foxit published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Foxit PhantomPDF\u00a0\u2013 version 10.1.11.37866 and prior<\/li>\n<\/ul><p>The Cyber Centre has received reports that some of these vulnerabilities have available exploits.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av23-341","alert_type":396,"serial_number":"AV23-341","subject":"other","moderation_state":"published","external_url":null},{"nid":4307,"title":"Microsoft Edge security advisory (AV23-342)","uuid":"1de9206d-a2cc-41e7-a0cd-e9c629572f9d","banner":null,"lang":"en","date_modified":"2023-06-16","date_modified_ts":"2023-06-16T19:27:32Z","date_created":"2023-06-16T19:12:20Z","summary":null,"body":["<article data-history-node-id=\"4307\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-342\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-342<br \/><strong>Date: <\/strong>June\u00a016, 2023<\/p>\n\n<p>On June\u00a015, 2023, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 114.0.1823.51<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-15-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-342","alert_type":396,"serial_number":"AV23-342","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4308,"title":"HPE security advisory (AV23-343)","uuid":"e98d51c7-35d1-4a03-b8e3-a49042caeb8c","banner":null,"lang":"en","date_modified":"2023-06-16","date_modified_ts":"2023-06-16T19:50:45Z","date_created":"2023-06-16T19:12:20Z","summary":null,"body":["<article data-history-node-id=\"4308\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-343\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-343<br \/><strong>Date: <\/strong>June\u00a016, 2023<\/p>\n\n<p>On June\u00a016, 2023, HPE published Security Bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Insight Remote Support\u00a0\u2013 version 7.12<\/li>\n\t<li>HPE Integrity MC990 X Server RMC\u00a0\u2013 firmware version 1.2.7 and prior<\/li>\n\t<li>SGI UV 300 RMC\u00a0\u2013 firmware version 1.2.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04487en_us\">HPE Security Bulletin\u00a0- hpesbgn04487en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04473en_us\">HPE Security Bulletin\u00a0- hpesbhf04473en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-343","alert_type":396,"serial_number":"AV23-343","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4310,"title":"Ubuntu security advisory (AV23-345)","uuid":"0ed78051-1ffc-4d7d-a4f4-a9054834b1fc","banner":null,"lang":"en","date_modified":"2023-06-19","date_modified_ts":"2023-06-19T16:50:12Z","date_created":"2023-06-19T16:44:02Z","summary":null,"body":["<article data-history-node-id=\"4310\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-345\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-345<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 19, 2023<\/p>\n\n<p>Between June\u00a012 and 18, 2023, Ubuntu published security sotices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu\u00a020.04 LTS<\/li>\n\t<li>Ubuntu\u00a022.04 LTS<\/li>\n\t<li>Ubuntu\u00a022.10<\/li>\n\t<li>Ubuntu\u00a023.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu security notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-345","alert_type":396,"serial_number":"AV23-345","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4311,"title":"IBM security advisory (AV23-346)","uuid":"6335a64d-8f2d-4369-b0e6-28dd553c9f96","banner":null,"lang":"en","date_modified":"2023-06-19","date_modified_ts":"2023-06-19T16:59:04Z","date_created":"2023-06-19T16:52:29Z","summary":null,"body":["<article data-history-node-id=\"4311\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-346\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-346<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a019, 2023<\/p>\n\n<p>Between June\u00a012 and\u00a018, 2023, IBM published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cloud Pak for Security (CP4S) \u2013 version 1.10.0.0 to\u00a01.10.10.0<\/li>\n\t<li>IBM Spectrum Copy Data Management \u2013 version 2.2.0.0 to\u00a02.2.19.0<\/li>\n\t<li>PowerSC \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7004653\">IBM security bulletin - 7004653<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/6998399\">IBM security bulletin - 6998399<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7004263\">IBM security bulletin - 7004263<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM product security incident response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-346","alert_type":396,"serial_number":"AV23-346","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4312,"title":"Dell security advisory (AV23-344)","uuid":"88246467-ba82-44a6-9ac1-9ad748dfb71c","banner":null,"lang":"en","date_modified":"2023-06-19","date_modified_ts":"2023-06-19T16:48:48Z","date_created":"2023-06-19T17:08:41Z","summary":null,"body":["<article data-history-node-id=\"4312\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-344\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-344<br \/><strong>Date: <\/strong>June\u00a019, 2023<\/p>\n\n<p>Between June\u00a012 and 18, 2023, Dell published Security Advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell PowerProtect Cyber Recovery\u00a0\u2013 version 19.4 to 19.13.0.2<\/li>\n\t<li>PowerEdge T30\u00a0\u2013 versions prior to 1.11.0<\/li>\n\t<li>PowerEdge T40\u00a0\u2013 versions prior to 1.11.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000214943\/dsa-2023-201-security-update-for-dell-powerprotect-cyber-recovery\">Dell Security Update\u00a0- DSA-2023-201<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000214910\/dsa-2023-204-security-update-for-dell-poweredge-t30-t40-mini-tower-server-for-multiple-memory-leak-vulnerability\">Dell Security Update\u00a0- DSA-2023-204<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-344","alert_type":396,"serial_number":"AV23-344","subject":"dell","moderation_state":"published","external_url":null},{"nid":4313,"title":"HPE security advisory (AV23-347)","uuid":"230ec414-c518-46ce-bdde-5a009c398459","banner":null,"lang":"en","date_modified":"2023-06-20","date_modified_ts":"2023-06-20T17:29:45Z","date_created":"2023-06-20T17:26:32Z","summary":null,"body":["<article data-history-node-id=\"4313\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-347\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-347<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 20, 2023<\/p>\n\n<p>On June\u00a018,\u00a02023, HPE published Security Bulletins to address a vulnerability in the following product:<\/p>\n\n<ul><li>IceWall Gen11 certd module (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbmu04488en_us\">HPE security bulletin - hpesbgn04488en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440\">HPE security bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-347","alert_type":396,"serial_number":"AV23-347","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4314,"title":"[Control systems] Enphase security advisory (AV23-348) ","uuid":"12feccbf-3019-4185-881e-6f1b5dac8371","banner":null,"lang":"en","date_modified":"2023-06-20","date_modified_ts":"2023-06-20T17:34:41Z","date_created":"2023-06-20T17:32:00Z","summary":null,"body":["<article data-history-node-id=\"4314\" about=\"\/en\/alerts-advisories\/control-systems-enphase-security-advisory-av23-348\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-348<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 20, 2023<\/p>\n\n<p>On June\u00a020,\u00a02023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Envoy \u2013 version D7.0.88 and prior<\/li>\n\t<li>Installer Toolkit \u2013 version 3.27.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-171-01\">ICS Advisory (ICSA-23-171-01)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-171-02\">ICS Advisory (ICSA-23-171-02)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-enphase-security-advisory-av23-348","alert_type":398,"serial_number":"AV23-348","subject":"other","moderation_state":"published","external_url":null},{"nid":4316,"title":"Ivanti security advisory (AV23-349)","uuid":"d9f0713c-7f6a-4210-bfca-01fb1f9fb4d1","banner":null,"lang":"en","date_modified":"2023-06-21","date_modified_ts":"2023-06-21T15:41:26Z","date_created":"2023-06-21T15:39:15Z","summary":null,"body":["<article data-history-node-id=\"4316\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-349\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-349<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 21, 2023<\/p>\n\n<p>On June 19, 2023, Ivanti (Pulse Secure) published a Security Bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Ivanti (Pulse Secure) Endpoint Manager\u00a0\u2013 EPM version 2022 SU3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/SA-2023-06-20-CVE-2023-28323?language=en_US\">Ivanti Security Bulletin - SA-2023-06-20<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Pulse Secure Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-349","alert_type":396,"serial_number":"AV23-349","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4317,"title":"Juniper Networks security advisory (AV23-350)","uuid":"b623ec55-daaa-41c4-805e-0defbed8412d","banner":null,"lang":"en","date_modified":"2023-06-21","date_modified_ts":"2023-06-21T19:51:52Z","date_created":"2023-06-21T19:48:42Z","summary":null,"body":["<article data-history-node-id=\"4317\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-350\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-350<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 21, 2023<\/p>\n\n<p>On June 21, 2023, Juniper Networks published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Juniper Networks Junos OS \u2013 multiple versions<\/li>\n\t<li>Juniper Networks Junos OS Evolved \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2023-06-Out-of-Cycle-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-A-BGP-session-will-flap-upon-receipt-of-a-specific-optional-transitive-attribute-CVE-2023-0026?language=en_US\">Juniper Networks Security Advisory - JSA71542<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2023-06-Out-of-Cycle-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-A-BGP-session-will-flap-upon-receipt-of-a-specific-optional-transitive-attribute-CVE-2023-0026?language=en_US\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-350","alert_type":396,"serial_number":"AV23-350","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4318,"title":"Apple security advisory (AV23-351)","uuid":"d158120d-6ac7-4416-bd5a-060ef041be42","banner":null,"lang":"en","date_modified":"2023-06-22","date_modified_ts":"2023-06-22T15:31:15Z","date_created":"2023-06-21T20:04:04Z","summary":null,"body":["<article data-history-node-id=\"4318\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-351\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-351\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 21, 2023\n<\/p>\n<p>On June 21, 2023, Apple published Security Updates to address vulnerabilities in the following products:\n<\/p>\n<ul><li>iOS and iPadOS\u00a0\u2013 multiple versions<\/li>\n  <li>macOS Big Sur\u00a0\u2013 versions prior to 11.7.8<\/li>\n  <li>macOS Monterey\u00a0\u2013 versions prior to 12.6.7<\/li>\n  <li>macOs Ventura\u00a0\u2013 versions prior to 13.4.1<\/li>\n  <li>Safari\u00a0\u2013 versions prior to 16.5.1<\/li>\n  <li>watchOS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>\n  Apple has received reports that some of these vulnerabilities have been actively exploited.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple security updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-351","alert_type":396,"serial_number":"AV23-351","subject":"apple","moderation_state":"published","external_url":null},{"nid":4319,"title":"VMware security advisory (AV23-352)","uuid":"da20729d-45d2-43e8-abd8-a9d6c66b19c9","banner":null,"lang":"en","date_modified":"2023-06-22","date_modified_ts":"2023-06-22T16:22:56Z","date_created":"2023-06-22T16:15:01Z","summary":null,"body":["<article data-history-node-id=\"4319\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-352\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-352<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 22, 2023<\/p>\n\n<p>On June 22, 2023, VMware published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation\u00a0\u2013 multiple versions<\/li>\n\t<li>VMware vCenter Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0014.html\">VMware Security Advisory\u00a0- VMSA-2023-0014<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-352","alert_type":396,"serial_number":"AV23-352","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4320,"title":"[Control systems] Advantech security advisory (AV23-353)","uuid":"0b616365-df05-40a5-b482-eb57cfbcd517","banner":null,"lang":"en","date_modified":"2023-06-22","date_modified_ts":"2023-06-22T16:39:30Z","date_created":"2023-06-22T16:30:28Z","summary":null,"body":["<article data-history-node-id=\"4320\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-353\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-353<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 22, 2023<\/p>\n\n<p>On June 22, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>R-SeeNet\u00a0\u2013 version 2.4.22 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-173-02\">ICS Advisory (ICSA-23-173-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-353","alert_type":398,"serial_number":"AV23-353","subject":"ics","moderation_state":"published","external_url":null},{"nid":4321,"title":"[Control systems] SpiderControl security advisory (AV23-354)","uuid":"96b5a6b9-bf17-46b0-99e5-cb514e7f004d","banner":null,"lang":"en","date_modified":"2023-06-22","date_modified_ts":"2023-06-22T17:11:51Z","date_created":"2023-06-22T16:30:28Z","summary":null,"body":["<article data-history-node-id=\"4321\" about=\"\/en\/alerts-advisories\/control-systems-spidercontrol-security-advisory-av23-354\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-354<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 22, 2023<\/p>\n\n<p>On June 22, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SCADAWebServer\u00a0\u2013 version 2.08 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-173-03\">ICS Advisory (ICSA-23-173-03)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-spidercontrol-security-advisory-av23-354","alert_type":398,"serial_number":"AV23-354","subject":"ics","moderation_state":"published","external_url":null},{"nid":4322,"title":"Drupal security advisory (AV23-355)","uuid":"8caf6158-ac7a-4b0b-aab3-f0044548f080","banner":null,"lang":"en","date_modified":"2023-06-23","date_modified_ts":"2023-06-23T15:52:34Z","date_created":"2023-06-23T15:32:02Z","summary":null,"body":["<article data-history-node-id=\"4322\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av23-355\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-355<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a023, 2023<\/p>\n\n<p>On June\u00a021, 2023, Drupal published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Photos module 6.0.x for Drupal 9 or 10\u00a0\u2013 versions prior to 6.0.4<\/li>\n\t<li>Photos module 8.x for Drupal 9\u00a0\u2013 versions prior to 8.x-4.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2023-022\">Drupal Security Advisory\u00a0- SA-CONTRIB-2023-022<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av23-355","alert_type":396,"serial_number":"AV23-355","subject":"drupal","moderation_state":"published","external_url":null},{"nid":4323,"title":"ISC BIND security advisory (AV23-356)","uuid":"7bff3d0b-1577-4529-bfa0-01d335b10957","banner":null,"lang":"en","date_modified":"2023-06-23","date_modified_ts":"2023-06-23T17:54:28Z","date_created":"2023-06-23T15:32:03Z","summary":null,"body":["<article data-history-node-id=\"4323\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av23-356\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-356<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a023, 2023<\/p>\n\n<p>On June\u00a021, 2023, ISC published Security Advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ISC BIND 9\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2023-2911\">ISC BIND security advisory (CVE-2023-2911)<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2023-2829\">ISC BIND security advisory (CVE-2023-2829)<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2023-2828\">ISC BIND security advisory (CVE-2023-2828)<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av23-356","alert_type":396,"serial_number":"AV23-356","subject":"other","moderation_state":"published","external_url":null},{"nid":4324,"title":"Fortinet security advisory (AV23-357)","uuid":"7aade608-fbc8-45df-aee5-336a29191bf8","banner":null,"lang":"en","date_modified":"2023-06-23","date_modified_ts":"2023-06-23T18:10:00Z","date_created":"2023-06-23T15:32:03Z","summary":null,"body":["<article data-history-node-id=\"4324\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-357\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-357<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a023, 2023<\/p>\n\n<p>On June\u00a023, 2023, Fortinet published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>FortiNAC\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-074\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-074<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-357","alert_type":396,"serial_number":"AV23-357","subject":"other","moderation_state":"published","external_url":null},{"nid":4325,"title":"Grafana security advisory (AV23-358)","uuid":"364706a1-d9ed-4d9b-97b7-680edb0cd858","banner":null,"lang":"en","date_modified":"2023-06-23","date_modified_ts":"2023-06-23T18:33:53Z","date_created":"2023-06-23T18:26:07Z","summary":null,"body":["<article data-history-node-id=\"4325\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av23-358\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-358<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a023, 2023<\/p>\n\n<p>On June\u00a022, 2023, Grafana published a Security Advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Grafana\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/blog\/2023\/06\/22\/grafana-security-release-for-cve-2023-3128\/\">Grafana Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/blog\/2023\/06\/potential-risk-of-privilege-escalation-in-azure-ad-applications\/\">Potential risk of privilege escalation in Azure AD applications<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av23-358","alert_type":396,"serial_number":"AV23-358","subject":"other","moderation_state":"published","external_url":null},{"nid":4326,"title":"Ivanti security  advisory (AV23-359)","uuid":"d31bb749-a5d5-4de3-a38b-5d6fdf282377","banner":null,"lang":"en","date_modified":"2023-06-23","date_modified_ts":"2023-06-23T19:51:22Z","date_created":"2023-06-23T19:41:20Z","summary":null,"body":["<article data-history-node-id=\"4326\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-359\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-359<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 23,\u00a02023<\/p>\n\n<p>On June 22,\u00a02023, Ivanti published a Security Bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>Ivanti Secure Access Client \u2013 versions prior to 22.3R3<\/li>\n\t<li>Pulse Secure Installer Service \u2013 versions prior to 9.1R18.23795<\/li>\n\t<li>Pulse Secure Desktop Client \u2013 version 9.1R15 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-34298-Ivanti-Secure-Access-Client-local-privilege-escalation?language=en_US\">Ivanti security bulletin - CVE-2023-34298<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory\">Ivanti pulse secure security bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-359","alert_type":396,"serial_number":"AV23-359","subject":"other","moderation_state":"published","external_url":null},{"nid":4327,"title":"Dell security advisory (AV23-360)","uuid":"009c2869-7370-4d5e-a7e2-44a9ed7ead7e","banner":null,"lang":"en","date_modified":"2023-06-26","date_modified_ts":"2023-06-26T17:16:40Z","date_created":"2023-06-26T17:12:19Z","summary":null,"body":["<article data-history-node-id=\"4327\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-360\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-360<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 26, 2023<\/p>\n\n<p>Between June\u00a019 and 25, 2023, Dell published Security Advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell PowerStore\u00a0\u2013 multiple models and versions prior to 3.5.0.0-2050321<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000215171\/dsa-2023-173-dell-powerstore-family-security-update-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-173<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-360","alert_type":396,"serial_number":"AV23-360","subject":"dell","moderation_state":"published","external_url":null},{"nid":4328,"title":"Ubuntu security advisory (AV23-361)","uuid":"6762222f-ccc4-435f-8247-de8481c0117e","banner":null,"lang":"en","date_modified":"2023-06-26","date_modified_ts":"2023-06-26T18:04:18Z","date_created":"2023-06-26T17:24:44Z","summary":null,"body":["<article data-history-node-id=\"4328\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-361\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-361<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 26, 2023<\/p>\n\n<p>Between June 19 and 25, 2023, Ubuntu published Security Notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0095-1\">Ubuntu Security Notice\u00a0- LSN-0095-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6185-1\">Ubuntu Security Notice\u00a0- USN-6185-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6186-1\">Ubuntu Security Notice\u00a0- USN-6186-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6187-1\">Ubuntu Security Notice\u00a0- USN-6187-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-361","alert_type":396,"serial_number":"AV23-361","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4329,"title":"IBM security advisory (AV23-362)","uuid":"4d2f9696-59e8-4b69-afab-88f0c98a3659","banner":null,"lang":"en","date_modified":"2023-06-26","date_modified_ts":"2023-06-26T18:28:51Z","date_created":"2023-06-26T18:24:04Z","summary":null,"body":["<article data-history-node-id=\"4329\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-362\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-362<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 26, 2023<\/p>\n\n<p>Between June\u00a019 and\u00a025, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cloud Pak for Network Automation (CP4NA) \u2013 version 2.x<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager virtual appliance component \u2013 all versions<\/li>\n\t<li>IBM Spectrum Control \u2013 version 5.4<\/li>\n\t<li>IBM Spectrum Discover \u2013 multiple versions<\/li>\n\t<li>IBM Spectrum Protect Plus \u2013 versions 10.1.0 to 10.1.14<\/li>\n\t<li>Operations Dashboard \u2013 versions 2021.1.1, 2021.2.1, 2021.3.1, 2021.4.1 and 2022.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product security incident response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-362","alert_type":396,"serial_number":"AV23-362","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4332,"title":"[Control systems] Hitachi Energy security advisory (AV23-364)","uuid":"e5e6386e-45e6-462b-9905-ec457c06561b","banner":null,"lang":"en","date_modified":"2023-06-27","date_modified_ts":"2023-06-27T18:04:42Z","date_created":"2023-06-27T18:01:05Z","summary":null,"body":["<article data-history-node-id=\"4332\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-364\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-364<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 27, 2023<\/p>\n\n<p>On June\u00a027,\u00a02023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>FOXMAN-UN \u2013 multiple versions<\/li>\n\t<li>UNEM \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-178-01\">ICS Advisory - ICSA-23-178-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-364","alert_type":398,"serial_number":"AV23-364","subject":"other","moderation_state":"published","external_url":null},{"nid":4333,"title":"Google Chrome security advisory (AV23-363)","uuid":"20a91eb4-bd09-443f-ae4f-8587fb245dbe","banner":null,"lang":"en","date_modified":"2023-06-27","date_modified_ts":"2023-06-27T18:18:29Z","date_created":"2023-06-27T18:14:11Z","summary":null,"body":["<article data-history-node-id=\"4333\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-363\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-363<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 27, 2023<\/p>\n\n<p>On June 26, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 114.0.5735.198\/199 (Windows) and 114.0.5735.198 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/06\/stable-channel-update-for-desktop_26.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-363","alert_type":396,"serial_number":"AV23-363","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4334,"title":"Red Hat security advisory (AV23-365)","uuid":"9c052eee-d156-420f-b6a3-1b534cfd2a9d","banner":null,"lang":"en","date_modified":"2023-06-28","date_modified_ts":"2023-06-28T12:16:08Z","date_created":"2023-06-28T12:12:35Z","summary":null,"body":["<article data-history-node-id=\"4334\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-365\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-365<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June 28, 2023<\/p>\n\n<p>On June\u00a027,\u00a02023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server for Power LE \u2013 update services for SAP solutions 8.1 ppc64le<\/li>\n\t<li>Red Hat Enterprise Linux for x86_64 \u2013 update services for SAP solutions 8.1 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-365","alert_type":396,"serial_number":"AV23-365","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4336,"title":"[Control systems] Delta Electronics security advisory (AV23-366)","uuid":"b78efa8b-3a66-4568-b27b-8b46082938f5","banner":null,"lang":"en","date_modified":"2023-06-29","date_modified_ts":"2023-06-29T18:41:37Z","date_created":"2023-06-29T17:56:23Z","summary":null,"body":["<article data-history-node-id=\"4336\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-366\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-366<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a029, 2023<\/p>\n\n<p>On June\u00a029, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>InfraSuite Device Master\u00a0\u2013 versions prior to 1.0.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-180-01\">ICS Advisory (ICSA-23-180-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-366","alert_type":398,"serial_number":"AV23-366","subject":"ics","moderation_state":"published","external_url":null},{"nid":4337,"title":"GitLab security advisory (AV23-367)","uuid":"d6003804-1c9f-424e-9a70-fe6e389964c8","banner":null,"lang":"en","date_modified":"2023-06-29","date_modified_ts":"2023-06-29T19:07:24Z","date_created":"2023-06-29T17:56:23Z","summary":null,"body":["<article data-history-node-id=\"4337\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-367\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-367<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a029, 2023<\/p>\n\n<p>On June\u00a029, 2023, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 16.1.1, 16.0.6 and 15.11.10<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 16.1.1, 16.0.6 and 15.11.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/06\/29\/security-release-gitlab-16-1-1-released\/\">GitLab Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-367","alert_type":396,"serial_number":"AV23-367","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4338,"title":"Trellix security advisory (AV23-368)","uuid":"f5d6f350-6557-4cd0-9401-726be9734024","banner":null,"lang":"en","date_modified":"2023-06-29","date_modified_ts":"2023-06-29T20:07:30Z","date_created":"2023-06-29T20:03:18Z","summary":null,"body":["<article data-history-node-id=\"4338\" about=\"\/en\/alerts-advisories\/trellix-security-advisory-av23-368\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-368<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a029, 2023<\/p>\n\n<p>On June\u00a028, 2023, Trellix published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Trellix Enterprise Security Manager\u00a0\u2013 version 11.6.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kcm.trellix.com\/corporate\/index?page=content&amp;id=SB10403\">Trellix Security Advisory (SB10403)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportm.trellix.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter\">Trellix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trellix-security-advisory-av23-368","alert_type":396,"serial_number":"AV23-368","subject":"trellix","moderation_state":"published","external_url":null},{"nid":4339,"title":"[Control systems] Ovarro security advisory (AV23-369)","uuid":"2e197464-95e9-43b7-b673-1ac306be74eb","banner":null,"lang":"en","date_modified":"2023-06-30","date_modified_ts":"2023-06-30T17:49:18Z","date_created":"2023-06-30T17:35:45Z","summary":null,"body":["<article data-history-node-id=\"4339\" about=\"\/en\/alerts-advisories\/control-systems-ovarro-security-advisory-av23-369\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-369<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a030, 2023<\/p>\n\n<p>On June\u00a029, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>TBox RTU\u00a0\u2013 multiple firmware versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-180-03\">ICS Advisory\u00a0- ICSA-23-180-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ovarro-security-advisory-av23-369","alert_type":398,"serial_number":"AV23-369","subject":"ics","moderation_state":"published","external_url":null},{"nid":4340,"title":"[Control systems] Schneider Electric security advisory (AV23-370)","uuid":"8e01e63d-5a32-4b49-8aa8-05363f765e61","banner":null,"lang":"en","date_modified":"2023-06-30","date_modified_ts":"2023-06-30T18:05:26Z","date_created":"2023-06-30T17:35:46Z","summary":null,"body":["<article data-history-node-id=\"4340\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-370\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-370<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a030, 2023<\/p>\n\n<p>On June\u00a029, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>EcoStruxure Operator Terminal Expert VXDZ\u00a0\u2013 version 3.3 SP1 and prior<\/li>\n<\/ul><p>CISA has indicated it is aware that public exploit code exists for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-180-02\">ICS Advisory\u00a0- ICSA-23-180-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-370","alert_type":398,"serial_number":"AV23-370","subject":"ics","moderation_state":"published","external_url":null},{"nid":4341,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-371)","uuid":"228fba35-624a-4c28-9127-59d69ec7f573","banner":null,"lang":"en","date_modified":"2023-06-30","date_modified_ts":"2023-06-30T18:12:28Z","date_created":"2023-06-30T17:35:46Z","summary":null,"body":["<article data-history-node-id=\"4341\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-371\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-371<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a030, 2023<\/p>\n\n<p>On June\u00a029, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MELSEC-F Series\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-180-04\">ICS Advisory\u00a0- ICSA-23-180-04<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-371","alert_type":398,"serial_number":"AV23-371","subject":"ics","moderation_state":"published","external_url":null},{"nid":4342,"title":"[Control systems] Medtronic security advisory (AV23-372)","uuid":"44a3dda2-5006-4d94-82d9-682f37e62936","banner":null,"lang":"en","date_modified":"2023-06-30","date_modified_ts":"2023-06-30T18:20:10Z","date_created":"2023-06-30T17:35:46Z","summary":null,"body":["<article data-history-node-id=\"4342\" about=\"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory-av23-372\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-372<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a030, 2023<\/p>\n\n<p>On June\u00a029, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Paceart Optima System\u00a0\u2013 version 1.11 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-180-01\">ICS Advisory\u00a0- ICSMA-23-180-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-medtronic-security-advisory-av23-372","alert_type":398,"serial_number":"AV23-372","subject":"ics","moderation_state":"published","external_url":null},{"nid":4343,"title":"Microsoft Edge security advisory (AV23-373)","uuid":"90e8e182-05dd-45dd-91c8-b913f5074c6b","banner":null,"lang":"en","date_modified":"2023-06-30","date_modified_ts":"2023-06-30T20:48:07Z","date_created":"2023-06-30T20:40:59Z","summary":null,"body":["<article data-history-node-id=\"4343\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-373\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-373<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>June\u00a030, 2023<\/p>\n\n<p>On June\u00a029, 2023, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 114.0.1823.67<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-29-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-373","alert_type":396,"serial_number":"AV23-373","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4344,"title":"Dell security advisory (AV23-374)","uuid":"78d266b3-baa3-487c-aea4-88e390428f96","banner":null,"lang":"en","date_modified":"2023-07-04","date_modified_ts":"2023-07-04T15:42:27Z","date_created":"2023-07-04T15:32:20Z","summary":null,"body":["<article data-history-node-id=\"4344\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-374\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-374<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 4, 2023<\/p>\n\n<p>Between June\u00a026 and July\u00a02, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Networker \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000215283\/dsa-2023-155-security-update-for-dell-networker-spring-security-vulnerabilities\">Dell Security Update - DSA-2023-155<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-374","alert_type":396,"serial_number":"AV23-374","subject":"dell","moderation_state":"published","external_url":null},{"nid":4345,"title":"IBM security advisory (AV23-375)","uuid":"fd786c7d-075e-4c52-a4f4-3a60657e28ca","banner":null,"lang":"en","date_modified":"2023-07-04","date_modified_ts":"2023-07-04T15:52:30Z","date_created":"2023-07-04T15:47:32Z","summary":null,"body":["<article data-history-node-id=\"4345\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-375\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-375<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a04, 2023<\/p>\n\n<p>Between June 26\u00a0and July\u00a02, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>AIX \u2013 version 7.3.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation \u2013 multiple versions<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM Db2 Warehouse on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM OpenPages for Cloud Pak for Data \u2013 version 4.5.x and 4.6.x<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak \u2013 multiple versions<\/li>\n\t<li>IBM Security Guardium \u2013 version 11.3<\/li>\n\t<li>IBM Security Verify Governance \u2013 all versions<\/li>\n\t<li>IBM Tivoli Netcool Impact \u2013 version 7.1.0<\/li>\n\t<li>Watson AI Gateway for CP4D \u2013 version Gateway Operator 1.0.16<\/li>\n\t<li>Watson Discovery \u2013 version 4.0.0 to 4.6.5<\/li>\n\t<li>Watson Speech Services Cartridge for IBM Cloud Pak for Data \u2013 version 4.0.0 to 4.6.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-375","alert_type":396,"serial_number":"AV23-375","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4346,"title":"Ubuntu security advisory (AV23-376)","uuid":"2238a739-dbd8-4a50-a03c-8b2d2395d298","banner":null,"lang":"en","date_modified":"2023-07-04","date_modified_ts":"2023-07-04T18:31:45Z","date_created":"2023-07-04T18:26:00Z","summary":null,"body":["<article data-history-node-id=\"4346\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-376\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-376<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 4, 2023<\/p>\n\n<p>Between June 26 and July 2, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 22.10<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-376","alert_type":396,"serial_number":"AV23-376","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4347,"title":"Mozilla security advisory (AV23-377)","uuid":"5219090b-b816-4fdc-8cc2-6b812a408557","banner":null,"lang":"en","date_modified":"2023-07-04","date_modified_ts":"2023-07-04T18:44:16Z","date_created":"2023-07-04T18:35:44Z","summary":null,"body":["<article data-history-node-id=\"4347\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-377\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-377<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a04, 2023<\/p>\n\n<p>On July\u00a04, 2023, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 115<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 102.13<\/li>\n\t<li>Thunderbird \u2013 versions prior to 102.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-22\/\">Mozilla Security Advisory - MFSA 2023-22<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-23\/\">Mozilla Security Advisory - MFSA 2023-23<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-24\/\">Mozilla Security Advisory - MFSA 2023-24<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-377","alert_type":396,"serial_number":"AV23-377","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4349,"title":"GitLab security advisory (AV23-378)","uuid":"32e26b6b-b002-490c-9c6e-3d563fb215b5","banner":null,"lang":"en","date_modified":"2023-07-06","date_modified_ts":"2023-07-06T14:32:06Z","date_created":"2023-07-06T14:23:21Z","summary":null,"body":["<article data-history-node-id=\"4349\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-378\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-387<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 6, 2023<\/p>\n\n<p>On July 5, 2023, GitLab published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 16.1.2, 16.0.7 and 15.11.11<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 16.1.2, 16.0.7 and 15.11.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/07\/05\/security-release-gitlab-16-1-2-released\/\">GitLab Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-378","alert_type":396,"serial_number":"AV23-378","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4350,"title":"Increased Truebot activity infects U.S. and Canada based networks - Joint Cybersecurity Advisory ","uuid":"d4281a03-d2ad-4960-8218-4467905e43d1","banner":null,"lang":"en","date_modified":"2023-07-06","date_modified_ts":"2023-07-06T14:45:21Z","date_created":"2023-07-06T14:26:49Z","summary":null,"body":["<article data-history-node-id=\"4350\" about=\"\/en\/alerts-advisories\/increased-truebot-activity-infects-us-and-canada-based-networks-scale-joint-cybersecurity-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-008<br \/><strong>Date:\u00a0<\/strong>July 6,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On July\u00a06,\u00a02023, the Canadian Centre for Cyber Security (CCCS) joined cyber security partners from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI) and the Multi-State Information Sharing and Analysis Center (MS-ISAC) to publish a joint Cybersecurity Advisory (CSA) in response to cyber threat actors leveraging newly identified Truebot malware variants against organizations in Canada and the United States.<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<p>Truebot is a botnet used by malicious cyber groups to collect and exfiltrate sensitive data from its target victims for financial gain. Previously used phishing campaigns have been successful but as recent as May 31, 2023, CVE-2022-31199 has been exploited for initial access; CVE-2022-31199 is a remote code execution vulnerability in the Netwrix Auditor application that can be used to deliver malware at scale within the compromised network. Open-source reporting and analytical findings show that cyber threat actors are using both phishing campaigns with malicious redirect hyperlinks and CVE-2022-31199 exploitation to deliver new Truebot malware variants.<\/p>\n\n<p>This joint advisory is being published to provide awareness on the Truebot malware variants. The Cybersecurity Advisory (CSA) contains technical details of the malware, indicators of compromise (IoCs), tactics, techniques, and procedures (TTPs) used by the threat actors, detection methods and mitigations. Additional guidance is available in the Cyber Centre\u2019s Ransomware playbook (ITSM.00.099) <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> and in the Cyber Centre\u2019s Top 10 IT security actions to protect Internet connected networks and information (ITSM.00.089) <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. These publications are based on analysis of cyber threat trends to help minimize intrusions or the impacts of a successful cyber intrusion.<\/p>\n\n<p>The authoring organizations encourage hunting for malicious activity using guidance found in the referenced CSA to reduce the likelihood and impact of future incidents.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/cisa.gov\/news-events\/cybersecurity-advisories\/aa23-187a\">Increased Truebot Activity Infects U.S. and Canada Based Networks - Joint Cybersecurity Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/ransomware-playbook-itsm00099\">Cyber Centre\u2019s Ransomware playbook (ITSM.00.099)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.00.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/increased-truebot-activity-infects-us-and-canada-based-networks-scale-joint-cybersecurity-advisory","alert_type":397,"serial_number":"AL23-008","subject":"other","moderation_state":"published","external_url":null},{"nid":4351,"title":"Android security advisory \u2013 July 2023 Monthly Rollup (AV23-379)","uuid":"cb62e567-6da8-4e16-892a-70a1aa1e0d09","banner":null,"lang":"en","date_modified":"2023-07-06","date_modified_ts":"2023-07-06T14:51:57Z","date_created":"2023-07-06T14:46:14Z","summary":null,"body":["<article data-history-node-id=\"4351\" about=\"\/en\/alerts-advisories\/android-security-advisory-july-2023-monthly-rollup-av23-379\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-379<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 07, 2023<\/p>\n\n<p>On July 5, 2023, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-07-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-july-2023-monthly-rollup-av23-379","alert_type":396,"serial_number":"AV23-379","subject":"android","moderation_state":"published","external_url":null},{"nid":4353,"title":"[Control systems] ABUS security advisory (AV23-381)","uuid":"ea85c75d-9c2a-49d8-bd9d-a10bbeef0bee","banner":null,"lang":"en","date_modified":"2023-07-06","date_modified_ts":"2023-07-06T20:33:23Z","date_created":"2023-07-06T19:49:00Z","summary":null,"body":["<article data-history-node-id=\"4353\" about=\"\/en\/alerts-advisories\/control-systems-abus-security-advisory-av23-381\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-381<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a06, 2023<\/p>\n\n<p>On July\u00a06, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABUS TVIP\u00a0\u2013 versions 20000 to 21150<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-187-02\">ICS Advisory (ICSA-23-187-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abus-security-advisory-av23-381","alert_type":398,"serial_number":"AV23-381","subject":"ics","moderation_state":"published","external_url":null},{"nid":4352,"title":"[Control systems] PiiGAB security advisory (AV23-380)","uuid":"9c3a72ff-5c28-4d3b-8188-ae971103cfde","banner":null,"lang":"en","date_modified":"2023-07-06","date_modified_ts":"2023-07-06T20:20:03Z","date_created":"2023-07-06T20:09:32Z","summary":null,"body":["<article data-history-node-id=\"4352\" about=\"\/en\/alerts-advisories\/control-systems-piigab-security-advisory-av23-380\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-380<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 6, 2023<\/p>\n\n<p>On July 6, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>M-Bus SoftwarePack 900S<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-187-01\">ICS Advisory (ICSA-23-187-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-piigab-security-advisory-av23-380","alert_type":398,"serial_number":"AV23-380","subject":"other","moderation_state":"published","external_url":null},{"nid":4354,"title":"MOVEit Transfer security advisory (AV23-382)","uuid":"d9954b92-746a-4760-afe3-4886ff0d9afe","banner":null,"lang":"en","date_modified":"2023-07-07","date_modified_ts":"2023-07-07T15:23:08Z","date_created":"2023-07-07T15:17:39Z","summary":null,"body":["<article data-history-node-id=\"4354\" about=\"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-382\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-382<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a07, 2023<\/p>\n\n<p>On July\u00a06, 2023, Progress published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MOVEit Transfer 2023.0.x (15.0.x)<\/li>\n\t<li>MOVEit Transfer 2022.1.x (14.1.x)<\/li>\n\t<li>MOVEit Transfer 2022.0.x (14.0.x)<\/li>\n\t<li>MOVEit Transfer 2021.1.x (13.1.x)<\/li>\n\t<li>MOVEit Transfer 2021.0.x (13.0.x)<\/li>\n\t<li>MOVEit Transfer 2020.1.6\u00a0\u2013 version 12.1.6 and later<\/li>\n\t<li>MOVEit Transfer 2020.0.x\u00a0\u2013 version 12.0.x and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Service-Pack-July-2023\">MOVEit Transfer Service Pack (July 2023)<\/a><\/li>\n\t<li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-2020-1-Service-Pack-July-2023\">MOVEit Transfer 2020.1 (12.1) Service Pack (July 2023)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/moveit-transfer-security-advisory-av23-382","alert_type":396,"serial_number":"AV23-382","subject":"other","moderation_state":"published","external_url":null},{"nid":4356,"title":"Dell security advisory (AV23-383)","uuid":"843a451d-2941-43aa-87be-2c9d2b6cd4fa","banner":null,"lang":"en","date_modified":"2023-07-10","date_modified_ts":"2023-07-10T16:01:32Z","date_created":"2023-07-10T15:58:41Z","summary":null,"body":["<article data-history-node-id=\"4356\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-383\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-383<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 10, 2023<\/p>\n\n<p>Between July 3 and 9, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Container Storage Modules\u00a0\u2013 versions prior to 1.7<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 versions 19.7 and 19.8<\/li>\n\t<li>Dell iDRAC9\u00a0\u2013 versions prior to 6.10.30.20<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell NetWorker Management Console (NMC)\u00a0\u2013 multiple versions<\/li>\n\t<li>Integrated Data Protection Appliance (PowerProtect DP Series)\u00a0\u2013 version 2.7.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-383","alert_type":396,"serial_number":"AV23-383","subject":"dell","moderation_state":"published","external_url":null},{"nid":4357,"title":"IBM security advisory (AV23-384)","uuid":"4fca0a43-5351-4a2a-a08e-f123e93582a8","banner":null,"lang":"en","date_modified":"2023-07-10","date_modified_ts":"2023-07-10T16:08:07Z","date_created":"2023-07-10T16:05:51Z","summary":null,"body":["<article data-history-node-id=\"4357\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-384\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-384<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 10, 2023<\/p>\n\n<p>Between July 3 and 9, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>APM Agents for Monitoring \u2013 all versions<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps \u2013 versions 3.x<\/li>\n\t<li>IBM Cloud Pak System \u2013 version 2.3.2.0, 2.3.1.1 and 2.3.3.0<\/li>\n\t<li>IBM Cloud Pak System Software Suite \u2013 version 2.3.3.0<\/li>\n\t<li>IBM DS8900 Management Console - multiple versions<\/li>\n\t<li>IBM Match 360 \u2013 all versions<\/li>\n\t<li>IBM Process Mining \u2013 version 1.12.0.4, 1.12.0.5, 1.13.0, 1.13.1, 1.13.2 and 1.14.0<\/li>\n\t<li>IBM QRadar SIEM \u2013 version 7.5.0 to 7.5.0 UP5<\/li>\n\t<li>IBM Watson Assistant for Cloud pak for Data \u2013 version 4.0.6, 4.0.7, 4.0.8, 4.5.1, 4.5.3, 4.6, 4.6.3, 4.6.2 and 4.0.5<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data \u2013 version 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8, 4.5.1, 4.5.3, 4.6.2, 4.6.3 and 4.0.2<\/li>\n\t<li>IBM Watson Knowledge Catalog on-prem \u2013 version 4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-384","alert_type":396,"serial_number":"AV23-384","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4358,"title":"Ubuntu security advisory (AV23-385)","uuid":"6b2facb1-5474-42f3-afd4-2535d77fd722","banner":null,"lang":"en","date_modified":"2023-07-10","date_modified_ts":"2023-07-10T16:15:22Z","date_created":"2023-07-10T16:14:05Z","summary":null,"body":["<article data-history-node-id=\"4358\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-385\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-385<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 10, 2023<\/p>\n\n<p>Between July 3 and 9, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-385","alert_type":396,"serial_number":"AV23-385","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4360,"title":"Apple security advisory (AV23-386)","uuid":"51ff593a-c727-4da3-ada9-41c075f0d6fc","banner":null,"lang":"en","date_modified":"2023-07-10","date_modified_ts":"2023-07-10T19:33:22Z","date_created":"2023-07-10T19:30:42Z","summary":null,"body":["<article data-history-node-id=\"4360\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-386\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-386<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 10, 2023<\/p>\n\n<p>On July 10, 2023, Apple published rapid security responses to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 16.5.1 (a)<\/li>\n\t<li>macOs Ventura \u2013 versions prior to 13.4.1 (a)<\/li>\n<\/ul><p>Apple has received reports that CVE-2023-37450 has been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213823\">Apple Rapid Security Responses \u2013 HT213823<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213825\">Apple Rapid Security Responses \u2013 HT213825<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-386","alert_type":396,"serial_number":"AV23-386","subject":"apple","moderation_state":"published","external_url":null},{"nid":4361,"title":"[Control systems] Siemens security advisory (AV23-387)","uuid":"4b492d80-9147-44c2-9dc6-fb9a57e89781","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T15:43:53Z","date_created":"2023-07-11T15:36:10Z","summary":null,"body":["<article data-history-node-id=\"4361\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-387\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-387\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023\n<\/p>\n<p>On July 11, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>Ruggedcom Rox\u00a0\u2013 versions prior to V2.16.0<\/li>\n  <li>Simatic CN 4100\u00a0\u2013 versions prior to V2.5<\/li>\n  <li>Simatic MV500 Devices\u00a0\u2013 version prior to V3.3.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-146325.html\">Siemens Security Advisories\u00a0\u2013 SSA-146325<\/a><\/li>\n  <li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-313488.html\">Siemens Security Advisories\u00a0\u2013 SSA-313488<\/a><\/li>\n  <li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-561322.html\">Siemens Security Advisories\u00a0\u2013 SSA-561322<\/a><\/li>\n  <li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-387","alert_type":398,"serial_number":"AV23-387","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4362,"title":"[Control systems] Schneider Electric security advisory (AV23-388)","uuid":"8a8b081b-5bb7-4ef7-ac46-9dae5ef49b28","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T15:51:38Z","date_created":"2023-07-11T15:46:41Z","summary":null,"body":["<article data-history-node-id=\"4362\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-388\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-388<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, Schneider Electric published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Accutech Manager Version\u00a0- version 2.7 and prior<\/li>\n\t<li>EcoStruxure OPC UA Server Expert\u00a0- versions prior to SV2.01 SP2<\/li>\n\t<li>HMISCU Controller\u00a0- all versions<\/li>\n\t<li>Modicon Controller\u00a0- all versions<\/li>\n\t<li>Modicon Controller LMC058\u00a0- all versions<\/li>\n\t<li>Modicon Controller M218\u00a0- all versions<\/li>\n\t<li>Modicon Controller M241\u00a0- all versions<\/li>\n\t<li>Modicon Controller M251\u00a0- all versions<\/li>\n\t<li>Modicon Controller M258\u00a0- all versions<\/li>\n\t<li>Modicon Controller M262\u00a0- all versions<\/li>\n\t<li>PacDrive 3 Controllers: LMC Eco\/Pro\/Pro2\u00a0- all versions<\/li>\n\t<li>SoftSPS embedded in EcoStruxure Machine Expert\u00a0- all versions<\/li>\n\t<li>StruxureWare Data Center Expert\u00a0- version 7.9.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-388","alert_type":398,"serial_number":"AV23-388","subject":"other","moderation_state":"published","external_url":null},{"nid":4363,"title":"Mozilla security advisory (AV23-389)","uuid":"e8baa96d-58be-4b1d-920c-ea4be25eeb36","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T15:57:49Z","date_created":"2023-07-11T15:53:17Z","summary":null,"body":["<article data-history-node-id=\"4363\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-389\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-389<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, Mozilla published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 115.0.2<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-26\/\">Mozilla Security Advisory\u00a0- MFSA 2023-26<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-389","alert_type":396,"serial_number":"AV23-389","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4364,"title":"SAP security advisory \u2013 July 2023 monthly rollup (AV23-390)","uuid":"8929f893-3976-467d-a164-274e4b4b2317","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T17:45:04Z","date_created":"2023-07-11T17:29:12Z","summary":null,"body":["<article data-history-node-id=\"4364\" about=\"\/en\/alerts-advisories\/sap-security-advisory-july-2023-monthly-rollup-av23-390\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-390<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP ECC and SAP S\/4HANA\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP SQL Anywhere\u00a0\u2013 version 17.0<\/li>\n\t<li>SAP Web Dispatcher\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day **\u00a0\u2013 July 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-july-2023-monthly-rollup-av23-390","alert_type":396,"serial_number":"AV23-390","subject":"other","moderation_state":"published","external_url":null},{"nid":4365,"title":"[Control systems] Sensormatic Electronics security advisory (AV23-392)","uuid":"e0142de5-5f39-4860-b20c-1b7013dbaa31","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T18:43:30Z","date_created":"2023-07-11T18:29:46Z","summary":null,"body":["<article data-history-node-id=\"4365\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av23-392\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-392<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, CISA published an ICS advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Sensormatic Electronics iSTAR Ultra and iSTAR Ultra LT\u00a0\u2013 firmware after version 6.8.6 and prior to 6.9.2 CU01<\/li>\n\t<li>Sensormatic Electronics iSTAR Ultra G2 and iSTAR Edge G2\u00a0\u2013 firmware versions prior to 6.9.2 CU01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-192-02\">ICS Advisory\u00a0- ICSA-23-192-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av23-392","alert_type":398,"serial_number":"AV23-392","subject":"other","moderation_state":"published","external_url":null},{"nid":4366,"title":"[Control systems] Rockwell Automation security advisory (AV23-391)","uuid":"e3ec6b29-1aa9-4684-b6b4-af40a48429de","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T18:38:30Z","date_created":"2023-07-11T18:35:51Z","summary":null,"body":["<article data-history-node-id=\"4366\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-391\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-391<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Rockwell Automation Enhanced HIM\u00a0\u2013 version 1.001<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-192-01\">ICS Advisory - ICSA-23-192-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-391","alert_type":398,"serial_number":"AV23-391","subject":"other","moderation_state":"published","external_url":null},{"nid":4367,"title":"[Control systems] Panasonic security advisory (AV23-393)","uuid":"cd598b82-1e77-481f-9150-5427cbbce848","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T18:46:11Z","date_created":"2023-07-11T18:39:27Z","summary":null,"body":["<article data-history-node-id=\"4367\" about=\"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory-av23-393\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-393<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, CISA published an ICS advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>Panasonic Control FPWIN \u2013 version 7.6.0.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-192-03\">ICS Advisory - ICSA-23-192-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-panasonic-security-advisory-av23-393","alert_type":398,"serial_number":"AV23-393","subject":"other","moderation_state":"published","external_url":null},{"nid":4368,"title":"Microsoft security advisory \u2013 July 2023 monthly rollup (AV23-394)","uuid":"15de5491-1016-4af3-9b6c-922fb583ab3c","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T19:35:42Z","date_created":"2023-07-11T19:33:02Z","summary":null,"body":["<article data-history-node-id=\"4368\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2023-monthly-rollup-av23-394\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-394<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Windows 10\u00a0\u2014 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2014 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2014 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint Server\u00a0\u2014 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-24932, CVE-2023-32046, CVE-2023-32049, CVE-2023-35311, CVE-2023-36874 and CVE-2023-36884 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Jul\">July 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2023-monthly-rollup-av23-394","alert_type":396,"serial_number":"AV23-394","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4369,"title":"Adobe security advisory (AV23-395)","uuid":"00ce623a-2f0e-416e-9158-7248db9c351f","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T19:43:46Z","date_created":"2023-07-11T19:40:59Z","summary":null,"body":["<article data-history-node-id=\"4369\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-395\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-395<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe InDesign\u00a0\u2013 multiple versions<\/li>\n\t<li>ColdFusion 2018\u00a0\u2013 version Update 16 and prior<\/li>\n\t<li>ColdFusion 2021\u00a0\u2013 version Update 6 and prior<\/li>\n\t<li>ColdFusion 2023\u00a0\u2013 version GA Release (2023.0.0.330468) \u202f<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb23-38.html\">Adobe Security Advisory - APSB23-38<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb23-40.html\">Adobe Security Advisory - APSB23-40<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-395","alert_type":396,"serial_number":"AV23-395","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4370,"title":"Citrix security advisory (AV23-396)","uuid":"1f7a8d04-ca9f-40ee-9b91-147b91ef97fd","banner":null,"lang":"en","date_modified":"2023-07-11","date_modified_ts":"2023-07-11T19:52:30Z","date_created":"2023-07-11T19:49:16Z","summary":null,"body":["<article data-history-node-id=\"4370\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av23-396\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-396<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 11, 2023<\/p>\n\n<p>On July 11, 2023, Citrix published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Secure Access client for Windows\u00a0\u2013 versions prior to 23.5.1.3<\/li>\n\t<li>Citrix Secure Access client for Ubuntu\u00a0\u2013 versions prior to 23.5.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX561480\/citrix-secure-access-client-for-windows-security-bulletin-for-cve202324491\">Citrix Security Advisory \u2013 CTX561480<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX564169\/citrix-secure-access-client-for-ubuntu-security-bulletin-for-cve202324492\">Citrix Security Advisory \u2013 CTX564169 <\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center\/search#\/All%20Products?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av23-396","alert_type":396,"serial_number":"AV23-396","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4371,"title":"Fortinet security advisory (AV23-397)","uuid":"ebdd594b-4714-4047-970f-8ced91cc5ad5","banner":null,"lang":"en","date_modified":"2023-07-12","date_modified_ts":"2023-07-12T15:47:36Z","date_created":"2023-07-12T15:29:06Z","summary":null,"body":["<article data-history-node-id=\"4371\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-397\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-397<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 12, 2023<\/p>\n\n<p>On July 11, 2023, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiOS\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiProxy\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-183\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-183<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-397","alert_type":396,"serial_number":"AV23-397","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":4372,"title":"Apple security advisory (AV23-398)","uuid":"c80cd7b5-1f28-4cf9-b01f-6f0aba1b6e44","banner":null,"lang":"en","date_modified":"2023-07-12","date_modified_ts":"2023-07-12T15:56:29Z","date_created":"2023-07-12T15:50:12Z","summary":null,"body":["<article data-history-node-id=\"4372\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-398\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-398<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 12, 2023<\/p>\n\n<p>On July 10, 2023, Apple published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Safari\u00a0\u2013 versions prior to 16.5.2.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213826\">Apple Security Update\u00a0\u2013 HT213826<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-398","alert_type":396,"serial_number":"AV23-398","subject":"apple","moderation_state":"published","external_url":null},{"nid":4373,"title":"[Control systems] Rockwell Automation security advisory (AV23-399) ","uuid":"d82a80b9-2305-43b5-8f45-5f48856878e7","banner":null,"lang":"en","date_modified":"2023-07-12","date_modified_ts":"2023-07-12T17:11:33Z","date_created":"2023-07-12T17:10:02Z","summary":null,"body":["<article data-history-node-id=\"4373\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-399\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-399<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 12, 2023<\/p>\n\n<p>On July 12, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Rockwell Automation Communication Modules 1756 EN2x, 1756 EN3x and 1756-EN4x \u2013 multiple firmware versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-193-01\">ICS Advisory - ICSA-23-193-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-399","alert_type":398,"serial_number":"AV23-399","subject":"other","moderation_state":"published","external_url":null},{"nid":4374,"title":"Cisco security advisory (AV23-400)","uuid":"57888413-b0e2-4f69-9884-547b6eaba0ce","banner":null,"lang":"en","date_modified":"2023-07-12","date_modified_ts":"2023-07-12T17:17:08Z","date_created":"2023-07-12T17:15:32Z","summary":null,"body":["<article data-history-node-id=\"4374\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-400\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-400<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 12, 2023<\/p>\n\n<p>On July 12, 2023, Cisco published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cisco SD-WAN vManage software\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-vmanage-unauthapi-sphCLYPA\">Cisco Security Advisory - cisco-sa-vmanage-unauthapi-sphCLYPA<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x \">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-400","alert_type":396,"serial_number":"AV23-400","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4375,"title":"Juniper Networks security advisory (AV23-401)","uuid":"2611dfea-1fb0-474d-ace0-3e063ef9310a","banner":null,"lang":"en","date_modified":"2023-07-12","date_modified_ts":"2023-07-12T19:46:12Z","date_created":"2023-07-12T19:41:40Z","summary":null,"body":["<article data-history-node-id=\"4375\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-401\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-401<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 12, 2023<\/p>\n\n<p>On July 12, 2023, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Juniper Networks Contrail Cloud\u00a0\u2013 versions prior to 16.3.0<\/li>\n\t<li>Juniper Networks Junos OS\u00a0\u2013 versions prior to 23.2R1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2023-07-Security-Bulletin-Contrail-Cloud-Multiple-Vulnerabilities-have-been-resolved-in-Contrail-Cloud-release-16-3-0?language=en_US\">Juniper Networks Security Advisories\u00a0\u2013 JSA71650<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2023-07-Security-Bulletin-Junos-OS-J-Web-Multiple-Vulnerabilities-in-PHP-software?language=en_US\">Juniper Networks Security Advisories\u00a0\u2013 JSA71653<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy&amp;numberOfResults=100&amp;f:ctype=[Security%20Advisories]\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-401","alert_type":396,"serial_number":"AV23-401","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4376,"title":"SonicWall security advisory (AV23-402)","uuid":"a98922e8-301a-41e9-b2cb-7fceb2dc1814","banner":null,"lang":"en","date_modified":"2023-07-12","date_modified_ts":"2023-07-12T19:51:38Z","date_created":"2023-07-12T19:47:43Z","summary":null,"body":["<article data-history-node-id=\"4376\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-402\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-402<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 12, 2023<\/p>\n\n<p>On July 12, 2023, SonicWall published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SonicWall GMS\u00a0\u2013 version 9.3.9320 and prior<\/li>\n\t<li>SonicWall Analytics\u00a0\u2013 version 2.5.0.4-R7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2023-0010\">SonicWall Security Advisory\u00a0- SNWLID-2023-0010<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-402","alert_type":396,"serial_number":"AV23-402","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":4377,"title":"HPE security advisory (AV23-403)","uuid":"ee20d3aa-7ce2-4188-8d67-f691e13d1999","banner":null,"lang":"en","date_modified":"2023-07-12","date_modified_ts":"2023-07-12T19:56:42Z","date_created":"2023-07-12T19:53:03Z","summary":null,"body":["<article data-history-node-id=\"4377\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-403\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-403<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 12, 2023<\/p>\n\n<p>On July 11, 2023, HPE published a security bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ArubaOS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04490en_us\">HPE Security Bulletin\u00a0- hpesbgn04490en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-403","alert_type":396,"serial_number":"AV23-403","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4379,"title":"Apple security advisory (AV23-404)","uuid":"311931d0-32fa-4eff-94da-6bfa866294e8","banner":null,"lang":"en","date_modified":"2023-07-13","date_modified_ts":"2023-07-13T18:00:02Z","date_created":"2023-07-13T17:54:10Z","summary":null,"body":["<article data-history-node-id=\"4379\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-404\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-404<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a013, 2023<\/p>\n\n<p>On July\u00a012, 2023, Apple published rapid security responses to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 16.5.1 (c)<\/li>\n\t<li>macOs Ventura\u00a0\u2013 versions prior to 13.4.1 (c)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213823\">Apple Rapid Security Responses\u00a0\u2013 HT213823<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213825\">Apple Rapid Security Responses\u00a0\u2013 HT213825<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-404","alert_type":396,"serial_number":"AV23-404","subject":"apple","moderation_state":"published","external_url":null},{"nid":4380,"title":"Drupal security advisory (AV23-405)","uuid":"5aa037a8-c839-4c0d-877f-448877b03ae9","banner":null,"lang":"en","date_modified":"2023-07-13","date_modified_ts":"2023-07-13T18:27:51Z","date_created":"2023-07-13T18:09:38Z","summary":null,"body":["<article data-history-node-id=\"4380\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av23-405\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-405<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a013, 2023<\/p>\n\n<p>On July\u00a012, 2023, Drupal published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Two-factor Authentication (TFA) module for Drupal 8\/9\u00a0- version prior to 8.x-1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2023-030\">Drupal Security Advisory\u00a0- SA-CONTRIB-2023-030<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av23-405","alert_type":396,"serial_number":"AV23-405","subject":"drupal","moderation_state":"published","external_url":null},{"nid":4381,"title":"[Control systems] Honeywell security advisory (AV23-406)","uuid":"b7b84f86-bfcc-43f3-b04a-9b843bf885be","banner":null,"lang":"en","date_modified":"2023-07-13","date_modified_ts":"2023-07-13T20:08:51Z","date_created":"2023-07-13T20:03:46Z","summary":null,"body":["<article data-history-node-id=\"4381\" about=\"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av23-406\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-406<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 13, 2023<\/p>\n\n<p>On July 13, 2023, CISA published an ICS advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Honeywell Experion PKS\u00a0\u2013 versions prior to R520.2<\/li>\n\t<li>Honeywell Experion LX\u00a0\u2013 versions prior to R520.2<\/li>\n\t<li>Honeywell Experion PlantCruise\u00a0\u2013 versions prior to R520.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-194-06\">ICS Advisory - ICSA-23-194-06<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-honeywell-security-advisory-av23-406","alert_type":398,"serial_number":"AV23-406","subject":"other","moderation_state":"published","external_url":null},{"nid":4382,"title":"[Control systems] Rockwell Automation security advisory (AV23-407)","uuid":"497a5702-7220-4261-93c9-4867928d5469","banner":null,"lang":"en","date_modified":"2023-07-13","date_modified_ts":"2023-07-13T20:17:00Z","date_created":"2023-07-13T20:15:10Z","summary":null,"body":["<article data-history-node-id=\"4382\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-407\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-407<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 13, 2023<\/p>\n\n<p>On July 13, 2023, CISA published an ICS advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>PowerMonitor 1000 \u2013 version V4.011<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-194-05\">ICS Advisory - ICSA-23-194-05<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-407","alert_type":398,"serial_number":"AV23-407","subject":"other","moderation_state":"published","external_url":null},{"nid":4383,"title":"[Control systems] BD Alaris security advisory (AV23-408)","uuid":"7389c36e-e27d-4096-a015-5e5ca354b907","banner":null,"lang":"en","date_modified":"2023-07-13","date_modified_ts":"2023-07-13T20:24:36Z","date_created":"2023-07-13T20:22:22Z","summary":null,"body":["<article data-history-node-id=\"4383\" about=\"\/en\/alerts-advisories\/control-systems-bd-alaris-security-advisory-av23-408\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-408<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 13, 2023<\/p>\n\n<p>On July 13, 2023, CISA published an ICS advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>BD Alaris Point-of-Care Unit (PCU) Model 8015\u00a0\u2013 version 12.1.3 and prior<\/li>\n\t<li>BD Alaris Guardrails Editor\u00a0\u2013 version 12.1.2 and prior<\/li>\n\t<li>BD Alaris Systems Manager\u00a0\u2013 version 12.3 and prior<\/li>\n\t<li>CQI Reporter\u00a0\u2013 version v10.17 and prior<\/li>\n\t<li>Calculation Services\u00a0\u2013 version 1.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-194-01\">ICS Advisory - ICSMA-23-194-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bd-alaris-security-advisory-av23-408","alert_type":398,"serial_number":"AV23-408","subject":"other","moderation_state":"published","external_url":null},{"nid":4386,"title":"HPE security advisory (AV23-409)","uuid":"54ad6a72-e8af-4c18-baea-6cc48042769e","banner":null,"lang":"en","date_modified":"2023-07-14","date_modified_ts":"2023-07-14T15:31:42Z","date_created":"2023-07-14T15:30:02Z","summary":null,"body":["<article data-history-node-id=\"4386\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-409\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-409<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 14, 2023<\/p>\n\n<p>On July 13, 2023, HPE published a security bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Intelligent Provisioning for Gen9 platform \u2013 versions prior to 2.87<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04486en_us\">HPE Security Bulletin - hpesbgn04486en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-409","alert_type":396,"serial_number":"AV23-409","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4387,"title":"Microsoft Edge security advisory (AV23-410)","uuid":"6073d5c8-b311-4982-a9e1-810636d9a139","banner":null,"lang":"en","date_modified":"2023-07-14","date_modified_ts":"2023-07-14T15:37:08Z","date_created":"2023-07-14T15:35:28Z","summary":null,"body":["<article data-history-node-id=\"4387\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-410\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-410<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 14, 2023<\/p>\n\n<p>On July 13, 2023, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 114.0.1823.82<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-13-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-410","alert_type":396,"serial_number":"AV23-410","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4390,"title":"Dell security advisory (AV23-413)","uuid":"973f5f7f-a455-474e-a0d2-696413274937","banner":null,"lang":"en","date_modified":"2023-07-17","date_modified_ts":"2023-07-17T15:53:40Z","date_created":"2023-07-17T15:11:20Z","summary":null,"body":["<article data-history-node-id=\"4390\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-413\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-413<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 17, 2023<\/p>\n\n<p>Between July 10 and 16, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Data Protection Central\u00a0\u2013 versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, 19.7 and 19.8<\/li>\n\t<li>PowerProtect Cyber Recovery\u00a0\u2013 version 19.13 and prior<\/li>\n\t<li>PowerProtect Data Protection Appliance\u00a0\u2013 versions 2.6.x and 2.7.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000215713\/dsa-2023-237-security-update-for-dell-data-protection-central-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-237<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000215782\/dsa-2023-253-security-update-for-dell-powerprotect-cyber-recovery-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-253<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-413","alert_type":396,"serial_number":"AV23-413","subject":"dell","moderation_state":"published","external_url":null},{"nid":4391,"title":"IBM security advisory (AV23-412)","uuid":"2df40e75-d10b-4b4c-b2fd-7098c963060b","banner":null,"lang":"en","date_modified":"2023-07-17","date_modified_ts":"2023-07-17T15:49:41Z","date_created":"2023-07-17T15:12:04Z","summary":null,"body":["<article data-history-node-id=\"4391\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-412\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-412<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a017, 2023<\/p>\n\n<p>Between July\u00a010 and 16, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Maximo Application Suite\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.2, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8, 4.5.1, 4.5.3, 4.6.2 and 4.6.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-412","alert_type":396,"serial_number":"AV23-412","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4389,"title":"Ubuntu security advisory (AV23-411)","uuid":"179b444f-6392-43ba-a508-38c51c3f6cc4","banner":null,"lang":"en","date_modified":"2023-07-17","date_modified_ts":"2023-07-17T15:32:32Z","date_created":"2023-07-17T15:12:05Z","summary":null,"body":["<article data-history-node-id=\"4389\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-411\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-411<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a017, 2023<\/p>\n\n<p>Between July\u00a010 and 16, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-411","alert_type":396,"serial_number":"AV23-411","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4392,"title":"Adobe security advisory (AV23-414)","uuid":"63fbb9ca-1087-4033-8ef2-ef03064d26b1","banner":null,"lang":"en","date_modified":"2023-07-17","date_modified_ts":"2023-07-17T16:01:55Z","date_created":"2023-07-17T15:43:40Z","summary":null,"body":["<article data-history-node-id=\"4392\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-414\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-414\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 17, 2023\n<\/p>\n<p>On July 14, 2023, Adobe published a security advisory to address a critical vulnerability in the following products:\n<\/p>\n<ul><li>ColdFusion 2018\u00a0\u2013 version Update 17 and prior<\/li>\n  <li>ColdFusion 2021\u00a0\u2013 version Update 7 and prior<\/li>\n  <li>ColdFusion 2023\u00a0\u2013 version Update 1 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in arbitrary code execution.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb23-41.html\">Adobe Security Advisory\u00a0- APSB23-41<\/a><\/li>\n  <li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-414","alert_type":396,"serial_number":"AV23-414","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4393,"title":"SonicWall security advisory (AV23-415)","uuid":"9f6401fd-e835-4466-a5b1-141b34f6ae16","banner":null,"lang":"en","date_modified":"2023-07-17","date_modified_ts":"2023-07-17T16:30:23Z","date_created":"2023-07-17T16:11:58Z","summary":null,"body":["<article data-history-node-id=\"4393\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-415\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-415<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 17, 2023<\/p>\n\n<p>On July 12, 2023, SonicWall published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Analytics\u00a0- version 2.5.0.4-R7 and prior<\/li>\n\t<li>GMS\u00a0- Virtual Appliance\u00a0- version 9.3.2-SP1 and prior<\/li>\n\t<li>GMS\u00a0- Windows\u00a0- version 9.3.2-SP1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2023-0010\">SonicWall Security Advisory\u00a0- SNWLID-2023-0010<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-415","alert_type":396,"serial_number":"AV23-415","subject":"other","moderation_state":"published","external_url":null},{"nid":4394,"title":"Citrix security advisory (AV23-416)","uuid":"fe56b6ae-1c85-4e5c-bdfa-7a1fad3d8d06","banner":null,"lang":"en","date_modified":"2023-07-18","date_modified_ts":"2023-07-18T15:49:37Z","date_created":"2023-07-18T15:27:57Z","summary":null,"body":["<article data-history-node-id=\"4394\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av23-416\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-416<br \/><strong>Date:<\/strong> July 18, 2023<\/p>\n\n<p>On July 18, 2023, Citrix published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway 13.1\u00a0\u2013 versions prior to 13.1-49.13<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.0\u00a0\u2013 versions prior to 13.0-91.13<\/li>\n\t<li>NetScaler ADC 13.1-FIPS\u00a0\u2013 versions prior to 13.1-37.159<\/li>\n\t<li>NetScaler ADC 12.1-FIPS\u00a0\u2013 versions prior to 12.1-65.36<\/li>\n\t<li>NetScaler ADC 12.1-NDcPP\u00a0\u2013 versions prior to 12.65.36<\/li>\n<\/ul><p>Citrix has reported that vulnerability CVE-2023-3519 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX561482\/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467\">Citrix Security Advisory\u00a0- CTX561482<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center\/search#\/All%20Products?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av23-416","alert_type":396,"serial_number":"AV23-416","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4398,"title":"[Control systems] WellinTech security advisory (AV23-420)","uuid":"416b2993-7a54-4237-93d4-a541afeceeec","banner":null,"lang":"en","date_modified":"2023-07-18","date_modified_ts":"2023-07-18T19:37:57Z","date_created":"2023-07-18T19:23:35Z","summary":null,"body":["<article data-history-node-id=\"4398\" about=\"\/en\/alerts-advisories\/control-systems-wellintech-security-advisory-av23-420\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-420<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, CISA published an ICS advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>KingHistorian\u00a0\u2013 version 35.01.00.05<\/li>\n<\/ul><p>CISA has indicated it is aware that public exploit code exists for these vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-199-07 \">ICS Advisory - ICSA-23-199-07<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wellintech-security-advisory-av23-420","alert_type":398,"serial_number":"AV23-420","subject":"other","moderation_state":"published","external_url":null},{"nid":4395,"title":"[Control systems] GE Digital security advisory (AV23-417)","uuid":"e144b64c-639f-429c-9cef-25070300ff95","banner":null,"lang":"en","date_modified":"2023-07-18","date_modified_ts":"2023-07-18T19:29:41Z","date_created":"2023-07-18T19:25:41Z","summary":null,"body":["<article data-history-node-id=\"4395\" about=\"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-417\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-417<br \/><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, CISA published an ICS advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>CIMPLICITY\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-199-06\">ICS Advisory - ICSA-23-199-06<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-417","alert_type":398,"serial_number":"AV23-417","subject":"other","moderation_state":"published","external_url":null},{"nid":4396,"title":"[Control systems] Iagona security advisory (AV23-418)","uuid":"744e34f9-d054-4ffd-bf6d-52d1cb39f969","banner":null,"lang":"en","date_modified":"2023-07-18","date_modified_ts":"2023-07-18T19:33:49Z","date_created":"2023-07-18T19:30:31Z","summary":null,"body":["<article data-history-node-id=\"4396\" about=\"\/en\/alerts-advisories\/control-systems-iagona-security-advisory-av23-418\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-418<br \/><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, CISA published an ICS advisory to highlight vulnerabilities in the following product:<\/p>\n\n<ul><li>ScrutisWeb\u00a0\u2013 version 2.1.37 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-199-03\">ICS Advisory\u00a0- ICSA-23-199-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-iagona-security-advisory-av23-418","alert_type":398,"serial_number":"AV23-418","subject":"other","moderation_state":"published","external_url":null},{"nid":4397,"title":"[Control systems] Rockwell Automation security advisory (AV23-419)","uuid":"576207db-7043-46b9-83b9-7d5187f145de","banner":null,"lang":"en","date_modified":"2023-07-18","date_modified_ts":"2023-07-18T19:37:20Z","date_created":"2023-07-18T19:34:30Z","summary":null,"body":["<article data-history-node-id=\"4397\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-419\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-419<br \/><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, CISA published an ICS advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Kinetix 5700\u00a0\u2013 version V13.001<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-199-01\">ICS Advisory\u00a0- ICSA-23-199-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-419","alert_type":398,"serial_number":"AV23-419","subject":"other","moderation_state":"published","external_url":null},{"nid":4399,"title":"[Control systems] GeoVision security advisory (AV23-421)","uuid":"4406e303-4560-4c36-bbd1-97d3a13dd0e5","banner":null,"lang":"en","date_modified":"2023-07-18","date_modified_ts":"2023-07-18T19:43:02Z","date_created":"2023-07-18T19:41:33Z","summary":null,"body":["<article data-history-node-id=\"4399\" about=\"\/en\/alerts-advisories\/control-systems-geovision-security-advisory-av23-421\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-421<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, CISA published an ICS security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>GV-ADR2701\u00a0\u2013 version V1.00_2017_12_15<\/li>\n<\/ul><p>CISA has indicated it is aware that public exploit code exists for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-199-05  \">ICS Advisory\u00a0- ICSA-23-199-05<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-geovision-security-advisory-av23-421","alert_type":398,"serial_number":"AV23-421","subject":"other","moderation_state":"published","external_url":null},{"nid":4400,"title":"[Control systems] Keysight security advisory (AV23-422)","uuid":"62e22313-c08b-4c0c-896a-867f0ebc7340","banner":null,"lang":"en","date_modified":"2023-07-18","date_modified_ts":"2023-07-18T19:47:24Z","date_created":"2023-07-18T19:45:53Z","summary":null,"body":["<article data-history-node-id=\"4400\" about=\"\/en\/alerts-advisories\/control-systems-keysight-security-advisory-av23-422\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-422<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, CISA published an ICS security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>N6854A Geolocation Server\u00a0\u2013 version 2.4.2 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-199-02 \">ICS Advisory - ICSA-23-199-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-keysight-security-advisory-av23-422","alert_type":398,"serial_number":"AV23-422","subject":"other","moderation_state":"published","external_url":null},{"nid":4401,"title":"[Control systems] Weintek security advisory (AV23-423)","uuid":"565d27ff-fb80-434e-bca6-a62f96c9818c","banner":null,"lang":"en","date_modified":"2023-07-19","date_modified_ts":"2023-07-19T12:31:41Z","date_created":"2023-07-19T12:26:32Z","summary":null,"body":["<article data-history-node-id=\"4401\" about=\"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-423\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-423<br \/><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Weincloud Account API\u00a0\u2013 version 0.13.6 and prior<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-199-04 \">ICS Advisory\u00a0- ICSA-23-199-04<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-423","alert_type":398,"serial_number":"AV23-423","subject":"other","moderation_state":"published","external_url":null},{"nid":4402,"title":"Red Hat security advisory (AV23-424)","uuid":"21a2ebe8-0339-4cfa-8a54-e0da28d0dfeb","banner":null,"lang":"en","date_modified":"2023-07-19","date_modified_ts":"2023-07-19T12:40:00Z","date_created":"2023-07-19T12:34:46Z","summary":null,"body":["<article data-history-node-id=\"4402\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-424\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-424<br \/><strong>Date: <\/strong>July 18, 2023<\/p>\n\n<p>On July 18, 2023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host 4 for RHEL 8 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-424","alert_type":396,"serial_number":"AV23-424","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4403,"title":"Google Chrome security advisory (AV23-425)","uuid":"4a12491b-8068-4ef7-880d-86b8bc922a68","banner":null,"lang":"en","date_modified":"2023-07-19","date_modified_ts":"2023-07-19T14:36:25Z","date_created":"2023-07-19T14:31:18Z","summary":null,"body":["<article data-history-node-id=\"4403\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-425\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-425<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 19, 2023<\/p>\n\n<p>On July 18, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 115.0.5790.98\/99 (Windows) and 115.0.5790.98 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/07\/stable-channel-update-for-desktop.html \">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-425","alert_type":396,"serial_number":"AV23-425","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4404,"title":"Oracle security advisory \u2013 July 2023 quarterly rollup (AV23-426)","uuid":"2323cf28-a2a9-48c4-bde8-6ce0a384da1e","banner":null,"lang":"en","date_modified":"2023-07-19","date_modified_ts":"2023-07-19T14:41:33Z","date_created":"2023-07-19T14:39:46Z","summary":null,"body":["<article data-history-node-id=\"4404\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-july-2023-quarterly-rollup-av23-426\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-426<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 19, 2023<\/p>\n\n<p>On July 18, 2023, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Application Express<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Food and Beverage Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle Hospitality Applications<\/li>\n\t<li>Oracle Hyperion<\/li>\n\t<li>Oracle JD Edwards<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle PeopleSoft<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Siebel CRM<\/li>\n\t<li>Oracle Supply Chain<\/li>\n\t<li>Oracle Utilities Applications<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2023.html \u2003\">Oracle Critical Patch Update Advisory \u2013 July 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-july-2023-quarterly-rollup-av23-426","alert_type":396,"serial_number":"AV23-426","subject":"other","moderation_state":"published","external_url":null},{"nid":4405,"title":"Foxit security advisory (AV23-427)","uuid":"c74b728f-e1e5-45bd-beef-0b66555f2709","banner":null,"lang":"en","date_modified":"2023-07-19","date_modified_ts":"2023-07-19T15:21:37Z","date_created":"2023-07-19T15:17:51Z","summary":null,"body":["<article data-history-node-id=\"4405\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av23-427\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-427<br \/><strong>Date: <\/strong>July 19, 2023<\/p>\n\n<p>On July 19, 2023, Foxit published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader\u00a0\u2013 version 12.1.2.15332 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av23-427","alert_type":396,"serial_number":"AV23-427","subject":"other","moderation_state":"published","external_url":null},{"nid":4406,"title":"Adobe security advisory (AV23-428)","uuid":"fb624bba-f2a6-4de9-9c91-c97d9cc1ffb3","banner":null,"lang":"en","date_modified":"2023-07-19","date_modified_ts":"2023-07-19T19:55:09Z","date_created":"2023-07-19T19:52:47Z","summary":null,"body":["<article data-history-node-id=\"4406\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-428\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-428<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 19, 2023<\/p>\n\n<p>On July 19, 2023, Adobe published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ColdFusion 2018\u00a0\u2013 version Update 18 and prior<\/li>\n\t<li>ColdFusion 2021\u00a0\u2013 version Update 8 and prior<\/li>\n\t<li>ColdFusion 2023\u00a0\u2013 version Update 2 and prior<\/li>\n<\/ul><p>Adobe has received reports that CVE-2023-38205 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb23-47.html \">Adobe Security Advisory - APSB23-47<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-428","alert_type":396,"serial_number":"AV23-428","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4407,"title":"Atlassian security advisory (AV23-429)","uuid":"ea8131b1-29ee-47f0-b980-a43ef03b6a1b","banner":null,"lang":"en","date_modified":"2023-07-19","date_modified_ts":"2023-07-19T20:00:50Z","date_created":"2023-07-19T19:59:29Z","summary":null,"body":["<article data-history-node-id=\"4407\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-429\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-429<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 19, 2023<\/p>\n\n<p>On July 18, 2023, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Server and Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server and Data Center\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-july-18-2023-1251417643.html \">Atlassian Security Advisory \u2013 July 18 2023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-429","alert_type":396,"serial_number":"AV23-429","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4408,"title":"Threat Actors exploiting Citrix CVE-2023-3519 to implant Webshells - CISA cybersecurity advisory ","uuid":"b4536235-10ec-4b24-8bf9-f3facaf18dba","banner":null,"lang":"en","date_modified":"2023-07-21","date_modified_ts":"2023-07-21T13:52:06Z","date_created":"2023-07-21T17:41:34Z","summary":null,"body":["<article data-history-node-id=\"4408\" about=\"\/en\/alerts-advisories\/threat-actors-exploiting-citrix-cve-2023-3519-implant-webshells-cisa-cybersecurity-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-009<br \/><strong>Date:\u00a0<\/strong>July 21,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On July 18, 2023, the Cyber Centre published AV23-416<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> highlighting multiple vulnerabilities in NetScaler (formally Citrix) Application Delivery Controller (ADC) and NetScaler Gateway appliances. The advisory raised awareness that vulnerabilities existed and that one had been exploited.<\/p>\n\n<p>On July 20, 2023, the Cybersecurity and Infrastructure Security Agency (CISA) published a Cybersecurity Advisory (CSA)<span class=\"nowrap\"><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/span> in response to cyber threat actors exploiting CVE-2023-3519, an unauthenticated remote code execution vulnerability affecting NetScaler Application Delivery Controllers (ADC) and NetScaler Gateways.<\/p>\n\n<p>The Cybersecurity Advisory (CSA) provides awareness of exploitation, technical details of the exploit activity, tactics, techniques, and procedures (TTPs) used by threat actors, detection methods and mitigations. Additional guidance is available in the Cyber Centre\u2019s Top 10 IT security actions to protect Internet connected networks and information (ITSM.00.089)<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. These publications are based on analysis of cyber threat trends to help minimize intrusions or the impacts of a successful cyber intrusion.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/citrix-security-advisory-av23-416\">AV23-416 Citrix security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-201a\">Threat Actors Exploiting Citrix CVE-2023-3519 to Implant Webshells\u00a0- CISA Cybersecurity Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information\u00a0-ITSM.00.089<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/threat-actors-exploiting-citrix-cve-2023-3519-implant-webshells-cisa-cybersecurity-advisory","alert_type":397,"serial_number":"AL23-009","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4409,"title":"Dell security advisory (AV23-430)","uuid":"e1062483-c45d-4b43-b9d3-10aff937c897","banner":null,"lang":"en","date_modified":"2023-07-24","date_modified_ts":"2023-07-24T16:25:12Z","date_created":"2023-07-24T16:08:24Z","summary":null,"body":["<article data-history-node-id=\"4409\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-430\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-430<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 24, 2023<\/p>\n\n<p>Between July 17 and 23, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell PowerProtect Data Manager\u00a0\u2013 version 19.13 and prior<\/li>\n\t<li>XtremIO X2\u00a0\u2013 versions prior to 6.4.1-11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000215920\/dsa-2023-244-security-update-for-dell-powerprotect-data-manager\">Dell Security Update\u00a0- DSA-2023-244<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000215898\/dsa-2023-242-security-update-for-dell-xtremio-x2\">Dell Security Update\u00a0- DSA-2023-242<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-430","alert_type":396,"serial_number":"AV23-430","subject":"dell","moderation_state":"published","external_url":null},{"nid":4410,"title":"IBM security advisory (AV23-431)","uuid":"6eb7103d-c430-4f85-9536-178f99392e28","banner":null,"lang":"en","date_modified":"2023-07-24","date_modified_ts":"2023-07-24T16:43:50Z","date_created":"2023-07-24T16:32:37Z","summary":null,"body":["<article data-history-node-id=\"4410\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-431\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-431<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 24, 2023<\/p>\n\n<p>Between July 17 and 23, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>APM Agents for Monitoring\u00a0\u2013 all versions<\/li>\n\t<li>\u00a0IBM Security Verify Governance, Identity Manager virtual appliance component\u00a0\u2013 all versions prior to 10.0.1 Fixpack 5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7012397\">IBM Security Bulletin\u00a0- 7012397<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7012649\">IBM Security Bulletin\u00a0- 7012649<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-431","alert_type":396,"serial_number":"AV23-431","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4420,"title":"Ubuntu security advisory (AV23-432)","uuid":"61e9a3bb-b815-479a-8a72-4f8168c7108b","banner":null,"lang":"en","date_modified":"2023-07-24","date_modified_ts":"2023-07-24T18:04:27Z","date_created":"2023-07-24T17:53:18Z","summary":null,"body":["<article data-history-node-id=\"4420\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-432\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-432<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 24, 2023<\/p>\n\n<p>Between July 17 and 23, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6234-1\">Ubuntu Security Notice\u00a0\u2013 USN-6234-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6235-1\">Ubuntu Security Notice\u00a0\u2013 USN-6235-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-432","alert_type":396,"serial_number":"AV23-432","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4421,"title":"Apple security advisory (AV23-433)","uuid":"25ce940f-0c4c-4aca-b942-cb348863069e","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T12:00:27Z","date_created":"2023-07-25T11:55:23Z","summary":null,"body":["<article data-history-node-id=\"4421\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-433\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-433\n  <br \/><strong>Date: <\/strong>July 25, 2023\n<\/p>\n<p>On July 24, 2023, Apple published security updates to address vulnerabilities in the following products:\n<\/p>\n<ul><li>iOS and iPadOS\u00a0\u2013 multiple versions<\/li>\n  <li>macOS Big Sur\u00a0\u2013 versions prior to 11.7.9<\/li>\n  <li>macOS Monterey\u00a0\u2013 versions prior to 12.6.8<\/li>\n  <li>macOS Ventura\u00a0\u2013 versions prior to 13.5<\/li>\n  <li>Safari\u00a0\u2013 versions prior to 16.6<\/li>\n  <li>tvOS\u00a0\u2013 versions prior to 16.6<\/li>\n  <li>watchOS\u00a0\u2013 versions prior to 9.6<\/li>\n<\/ul><p>Apple has received reports that CVE-2023-37450 and CVE-2023-38606 may have been actively exploited.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-433","alert_type":396,"serial_number":"AV23-433","subject":"apple","moderation_state":"published","external_url":null},{"nid":4422,"title":"Ivanti security advisory (AV23-434)","uuid":"9ae7d62d-0ed4-4a39-ae9e-f2cfaf6fdaab","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T13:50:53Z","date_created":"2023-07-25T13:45:37Z","summary":null,"body":["<article data-history-node-id=\"4422\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-434\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-434\n  <br \/><strong>Date: <\/strong>July 25, 2023\n<\/p>\n<p>On July 24, 2023, Ivanti published a security bulletin to address a critical vulnerability in the following product:\n<\/p>\n<ul><li>Ivanti Endpoint Manager Mobile\u00a0\u2013 all versions<\/li>\n<\/ul><p>Ivanti has indicated that CVE-2023-35078 has been exploited.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US \">Ivanti Security Bulletin\u00a0- CVE-2023-35078<\/a><\/li>\n  <li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-434","alert_type":396,"serial_number":"AV23-434","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4423,"title":"Threat Actors Exploiting Ivanti Endpoint Manager Mobile CVE-2023-35078 - Update 1","uuid":"d35103d5-c97b-424a-94bf-7386f223d197","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T17:53:11Z","date_created":"2023-07-25T15:38:09Z","summary":null,"body":["<article data-history-node-id=\"4423\" about=\"\/en\/alerts-advisories\/threat-actors-exploiting-ivanti-cve-2023-35078\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-011<br \/><strong>Date:\u00a0<\/strong>July 25,\u00a02023<br \/><strong>Updated:\u00a0<\/strong>July 28,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On July 24, 2023, Ivanti published an article<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> highlighting a remotely exploitable vulnerability (CVE-2023-35078) in Ivanti Endpoint Manager Mobile (EPMM) (formerly MobileIron Core). Ivanti has stated that exploitation of this vulnerability enables an unauthorized, remote (internet-facing) actor to potentially access users\u2019 personally identifiable information and make limited changes to the server. CISA has since published an Alert which further states that this vulnerability may also result in other configuration changes, including the creation of an EPMM administrative account that can make further changes to a vulnerable system.<span class=\"nowrap\"><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/span> Ivanti additionally reported that this vulnerability has been exploited, and Norway\u2019s National Security Authority and Departments\u2019 Security and Service Organization have stated publicly<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> they have been affected by this zero-day vulnerability.<\/p>\n\n<p>On July 25, 2023, the Cyber Centre published AV23-434<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> highlighting the vulnerability in Ivanti Endpoint Manager Mobile (EPMM). The advisory raised awareness that a vulnerability exists and that it had been exploited. The Cyber Centre has assessed that there are a number of potentially affected devices within Canada.<\/p>\n<\/section><section><h2>Update 1<\/h2>\n\n<p>On July 28, 2023, Ivanti published an article<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> highlighting an additional vulnerability recently exploited by malicious actors. Ivanti states that CVE-2023-35081 enables an authenticated administrator to perform arbitrary file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass administrator authentication and ACLs restrictions (if applicable). Ivanti has further reported that patches are now available for CVE-2023-35081. Organizations are encouraged to review the article and install the recommended updates.<\/p>\n<\/section><section><h2>Recommendations<\/h2>\n\n<p>The Cyber Centre recommends that any organizations who use these devices, to ensure that they are patched as soon as possible.<\/p>\n\n<p>Additional guidance is available in the Cyber Centre\u2019s Top 10 IT security actions to protect Internet connected networks and information (ITSM.00.089)<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>. These publications are based on analysis of cyber threat trends to help minimize intrusions or the impacts of a successful cyber intrusion.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US\">Ivanti security article<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/07\/24\/ivanti-releases-security-updates-endpoint-manager-mobile-epmm-cve-2023-35078\">CISA\u00a0- Ivanti Releases Security Updates for Endpoint Manager Mobile (EPMM) CVE-2023-35078<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nsm.no\/aktuelt\/nulldagssarbarhet-i-ivanti-endpoint-manager-mobileiron-core\">Norwegian Statement (In Norwegian only)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-434\">CCCS AV23-434 Ivanti security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.00.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-35081-Arbitrary-File-Write?language=en_US \">CVE-2023-35081\u00a0- Remote Arbitrary File Write<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/threat-actors-exploiting-ivanti-cve-2023-35078","alert_type":397,"serial_number":"AL23-011","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4424,"title":"ALPHV\/BlackCat Ransomware Targeting of Canadian Industries","uuid":"a1f2be9d-656f-47ff-b62e-956bd5e7c46e","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T16:00:45Z","date_created":"2023-07-25T15:54:17Z","summary":null,"body":["<article data-history-node-id=\"4424\" about=\"\/en\/alerts-advisories\/alphvblackcat-ransomware-targeting-canadian-industries\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-010<br \/><strong>Date:\u00a0<\/strong>July 25,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>The Communications Security Establishment (CSE) and its Canadian Centre for Cyber Security (Cyber Centre) are aware of incidents where victims were infected with ALPHV\/BlackCat ransomware. As of July 24, 2023, incidents involving ALPHV\/BlackCat have impacted multiple sectors within Canada and globally.<\/p>\n\n<p>The Cyber Centre assesses that ALPHV\/BlackCat are almost certainly financially motivated and have shown no pattern to victimization that suggests deliberate targeting. The Cyber Centre assesses that ALPHV\/BlackCat and its affiliates very likely select their victims based on opportunity. ALPHV\/BlackCat is responsible for a significant share of attributed Canadian ransomware incidents that the Cyber Centre is aware of between January 2022 and June 2023. ALPHV\/BlackCat has presented a threat to Canadian organizations since at least January 2022 and will very likely continue to threaten Canadian and international organizations into the latter half of 2023.<\/p>\n\n<p>In 2023, BlackBerry published an article which details the BlackCat malware <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. In the report they state \u201cBlackCat has most often targeted companies in the financial, manufacturing, legal, and professional services industries \u2014 but BlackCat\u2019s exploits span all industries.\u201d With a campaign that \u201coften employ a triple-extortion tactic: making individual ransom demands for the decryption of infected files; for not publishing stolen data; and for not launching denial of service (DoS) attacks.\"<\/p>\n\n<p>The Cyber Centre continues to monitor activities impacting Canadian Ransomware victims and will provide further technical indicators along with advice and guidance as they are made available. The Cyber Centre is providing the following TTPs and attached IOCs related to activity recently reported to the Cyber Centre to provide network defenders techniques to better protect themselves. All government and non-government partners are also encouraged to use cyber security best practices to protect their environments.<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/p>\n<\/section><section><h2>Tactics, techniques, and procedures (TTP)<\/h2>\n\n<p>The following MITRE ATT&amp;CK techniques leveraged by the actors<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> were reported to the Cyber Centre or referenced through open-source. They are being provided to outline the reported activity. MITRE provides detection and mitigation strategies for system operators to better protect their network systems. These resources are available in the references section of this Alert.<\/p>\n\n<h3>Initial access<\/h3>\n\n<p>Threat actors have been reportedly using multiple forms of social engineering to gain access to user credentials. This has included phishing email and SMS messages with links to target-themed credential phishing, as well as phone calls to the users to harvest their credentials.<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<ul><li>T1586\u00a0\u2013 Compromise Accounts<\/li>\n\t<li>T1566\u00a0\u2013 Phishing<\/li>\n<\/ul><p>Threat actors have also been reportedly bypassing MFA by various means, including MFA fatigue and social engineering. <sup id=\"fn4a-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<ul><li>T1111\u00a0- Multi-Factor Authentication Interception<\/li>\n<\/ul><h3>Privilege escalation<\/h3>\n\n<p>Threat actors have been reportedly leveraging compromised credentials to conduct additional credential theft to escalate privileges.<sup id=\"fn4b-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> Threat actors have also been reportedly compromising privileged accounts as part of the initial access.<\/p>\n\n<ul><li>TA0004\u00a0\u2013 Privilege Escalation<\/li>\n<\/ul><h3>Command and control (C2)<\/h3>\n\n<p>Following initial compromise, threat actors have also been reportedly using various remote monitoring and management tools to maintain persistence, many of which are commercial products to avoid detection.<sup id=\"fn4c-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<ul><li>T1219\u00a0\u2013 Remote Access Software<\/li>\n<\/ul><h3>Scanning<\/h3>\n\n<p>Following initial compromise, threat actors have been reportedly leveraging various tools to scan for RDP and SMB enabled devices on the network.<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/p>\n\n<ul><li>T1135\u00a0\u2013 Network Share Discovery<\/li>\n\t<li>T1046\u00a0\u2013 Network Service Discovery<\/li>\n<\/ul><h3>Persistence<\/h3>\n\n<p>Threat actors have been reportedly adding their own MFA tokens to existing user accounts. This allows the threat actor to maintain persistence while avoiding detection.<sup id=\"fn4d-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<ul><li>T1098.005\u00a0- Account Manipulation: Device Registration<\/li>\n<\/ul><p>Threat actors have also been reportedly adding federated domains to Azure AD to maintain persistence.<\/p>\n\n<ul><li>T1484.002\u00a0\u2013 Domain Policy Modification: Domain Trust Modification<\/li>\n<\/ul><p>Threat actors have also been reportedly using scheduled tasks to maintain persistence<sup id=\"fn5a-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/p>\n\n<ul><li>T1053.005\u00a0\u2013 Scheduled Task\/Job: Scheduled Task<\/li>\n<\/ul><p>Threat actors have also been reportedly using various remote monitoring and management tools to maintain persistence, many of which are commercial products to avoid detection.<sup id=\"fn4e-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/p>\n\n<ul><li>T1219\u00a0\u2013 Remote Access Software<\/li>\n<\/ul><p>Threat actors have also been reportedly abusing continuous configuration management software such as Ansible to maintain persistence. These tools are abused to automatically re-infect new systems.<\/p>\n\n<ul><li>T1525\u00a0- Implant Internal Image<\/li>\n<\/ul><h3>Movement within network<\/h3>\n\n<p>To move laterally within the network, threat actors have been reportedly leveraging management tools such as Microsoft InTune and WSUS to spread within the network.<\/p>\n\n<ul><li>T1072\u00a0- Software Deployment Tools<\/li>\n<\/ul><p>Threat actors have also been reportedly using RDP connections to perform further credential theft via LSASS dumping.<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/p>\n\n<ul><li>T1021.001 - Remote Services: Remote Desktop Protocol<\/li>\n<\/ul><h3>Recovery prevention and obstruction<\/h3>\n\n<p>To prevent and obstruct recovery efforts, threat actors have been reportedly deleting virtual machine backups and snapshots. Threat actors have also been reportedly deleting Windows shadow copy backups during the encryption process.<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<ul><li>T1490 \u2013 Inhibit System Recovery<\/li>\n<\/ul><\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Review the attached indicators of compromise and above TTPs to determine if related activity has occurred. If activity has been detected and a compromise has occurred:\n\t<ul><li>Reimage compromised systems.<\/li>\n\t\t<li>Reset all potentially compromised credentials.<\/li>\n\t<\/ul><\/li>\n\t<li>Review the MITRE ATT&amp;CK techniques and mitigations<sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> to assist in reducing potential threat surfaces.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> with an emphasis on the following topics.<\/p>\n\n<ul><li>Phishing Awareness. This includes both identification of phishing but also procedures on what to do if a phishing email is received.\n\t<ul><li>The Cyber Centre has several publications available on Phishing Awareness<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/li>\n\t<\/ul><\/li>\n\t<li>Phishing Technical Controls.<\/li>\n\t<li>Multi-factor Authentication.\n\t<ul><li>Favouring hard tokens for sensitive or critical systems or accounts.<\/li>\n\t<\/ul><\/li>\n\t<li>Enforcing the Management of Administrative Privileges.\n\t<ul><li>Minimize number of administrators and privileged roles.<\/li>\n\t\t<li>Conduct administrative activities on managed, hardened, and dedicated devices with restricted access to email, web browsing and outside connectivity.<\/li>\n\t\t<li>Enable two-person integrity when resetting administrative accounts to minimize successful social engineering activities.<\/li>\n\t<\/ul><\/li>\n\t<li>Remote Access Management and Controls.<\/li>\n\t<li>Network segmentation and demilitarized zones (DMZs).\n\t<ul><li>Configure firewalls to selectively control and monitor traffic passed between zones.<\/li>\n\t<\/ul><\/li>\n\t<li>Software Management and Deployment Controls.<\/li>\n\t<li>Business continuity planning, which is tested and validated.<\/li>\n\t<li>Review the Cyber Centres Playbook on Ransomware (ITSM.00.099) and apply recommended security controls.<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup><\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><h2>Indicators of compromise<\/h2>\n\n<p>The Cyber Centre is releasing the following indicators of compromise (IoCs) associated with ALPHV\/BlackCat activity. The Cyber Centre wishes to highlight that some of the provided network indicators may be used for legitimate purposes. The presence of connections to these network indicators does not necessarily imply that a system has been compromised, but it does merit further investigation to verify the systems integrity.<\/p>\n\n<p>Additionally, as these indicators may contain legitimate infrastructure or software, it is important to verify business services and network environments before implementing any blocks based on these indicators.<\/p>\n\n<table class=\"table table-bordered\"><thead><tr><th class=\"active col-md-5\" id=\"tbl1_1\">Indicator<\/th>\n\t\t\t<th class=\"active col-md-3\" id=\"tbl1_2\">Type<\/th>\n\t\t\t<th class=\"active col-md-3\" id=\"tbl1_3\">Notes<\/th>\n\t\t<\/tr><\/thead><tbody><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_4\">fleetdeck_agent_svc.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_4\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_4\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_5\">njmatio0.fdx.cmd<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_5\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_5\">TA Scripts (njmatio0)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_6\">privacy.sexy<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_6\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_6\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_7\">run-{B9184FF9-B695-4605-B649-BF3A488E9BF5}-v3854.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_7\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_7\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_8\">run-{B9184FF9-B695-4605-B649-BF3A488E9BF5}-v3857.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_8\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_8\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_9\">[REDACTED]_non_employee_pcs__onprem__azure__aws__mk2_locker_windows32 (1).zip<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_9\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_9\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_10\">[REDACTED]_non_employee_pcs__onprem__azure__aws__mk2_locker_windows32(1).zip<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_10\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_10\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_11\">[REDACTED]_non_employee_pcs__onprem__azure__aws__mk2_locker_windows32.zip<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_11\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_11\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_12\">WhenTheyCry0.ps1<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_12\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_12\">TA Scripts (WhenTheyCry0.ps1)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_13\">Win\u00a0- [REDACTED]\u00a0- Dynamically Set Time Zone<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_13\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_13\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_14\">Win10\u00a0-\u00a0CloudPC\u00a0-\u00a0Teams WebRTC Plugin<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_14\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_14\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_15\">Win\u00a0- [REDACTED]\u00a0- Zscaler Remediation v4<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_15\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_15\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_16\">Win10\u00a0-\u00a0WKSConfig\u00a0-\u00a0Add [REDACTED]Admin10<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_16\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_16\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_17\">WindowsDefenderATPOffboardingScript_valid_until_2023-07-23.cmd<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_17\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_17\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_18\">WindowsDefenderATPOffboardingScript_valid_until_2023-07-24.cmd<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_18\">filename<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_18\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_19\">C:\\ATP.cmd<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_19\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_19\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_20\">C:\\forti.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_20\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_20\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_21\">C:\\fortis.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_21\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_21\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_22\">C:\\fortiss.bat<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_22\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_22\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_24\">C:\\Program Files (x86)\\FleetDeck Agent\\fleetdeck_agent_svc.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_24\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_24\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_25\">C:\\Users\\Arssvc\\downloads\\24hours.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_25\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_25\">TA Executables (24hours.exe)\u00a0|\u00a0TA created user ARSSCV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_26\">C:\\Users\\[REDACTED]\\AppData\\Local\\VirtualStore\\Program Files (x86)\\FleetDeck Agent\\credentials.json<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_26\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_26\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_27\">C:\\Users\\[REDACTED]\\AppData\\Local\\VirtualStore\\Program Files (x86)\\FleetDeck Agent\\deployment.json<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_27\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_27\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_28\">C:\\Users\\[REDACTED]\\AppData\\Local\\VirtualStore\\Program Files (x86)\\FleetDeck Agent\\latest.json<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_28\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_28\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_29\">C:\\Users\\[REDACTED]\\AppData\\Local\\VirtualStore\\Program Files (x86)\\FleetDeck Agent\\z7RvqxPCGUS2jCWMFVomadRMQD6C.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_29\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_29\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_30\">C:\\Users\\[REDACTED]\\Downloads\\FFjEqOaD6jGqN9upnK00kAbxWNH2FFXYuW.exe<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_30\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_30\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_31\">C:\\Windows\\System32\\Tasks\\privacy.sexy<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_31\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_31\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_32\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\Downloads\\script0.ps1<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_32\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_32\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_33\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\Downloads\\ygkmZF5i4UtMWqDE6V3J.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_33\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_33\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_34\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\JN3x4VqhB81TOXBUl0JRfERIWjoCs.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_34\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_34\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_35\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\bin\\g2dF1nbbDK3vpS9A4AxMNvIzQeqZx.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_35\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_35\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_36\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\RuntimeSettings\\sCgJDQc9XLmMC0TYUnemYl.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_36\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_36\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_37\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\Downloads\\UyRsql4uhjaYT5Lm2wM.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_37\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_37\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_38\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\Status\\3XjHpEDkYDxh7GzUuVhwN7k6xCjKCU.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_38\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_38\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_39\">C:\\Packages\\Plugins\\Microsoft.CPlat.Core.RunCommandWindows\\1.1.15\\Status\\aatftpKN1N46jZeJTPV.txt<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_39\">filepath<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_39\">[nil]<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_40\">2uee6idu7qoaqdata000.blob.core.windows[.]net<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_40\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_40\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_41\">fleetdeck[.]io<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_41\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_41\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_42\">gofile[.]io<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_42\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_42\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_43\">level[.]io<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_43\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_43\">LEVEL.IO<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_44\">pinyin-[REDACTED].s3.us-west-2.amazonaws[.]com<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_44\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_44\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_45\">privacy[.]sexy<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_45\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_45\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_46\">storjshare[.]io<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_46\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_46\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_47\">[REDACTED]-sso[.]com<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_47\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_47\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_48\">temp[.]sh<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_48\">FQDN<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_48\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_49\">162.33.179[.]114<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_49\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_49\">UPDATE.EXE<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_50\">193.149.187[.]213<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_50\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_50\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_51\">4.157.42[.]62<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_51\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_51\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_52\">40.88.54[.]192<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_52\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_52\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_53\">52.188.53[.]135<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_53\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_53\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_54\">206.188.196[.]78<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_54\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_54\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_55\">193.149.187[.]213<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_55\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_55\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_56\">45.154.138[.]39<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_56\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_56\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_57\">47.154.86[.]24<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_57\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_57\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_58\">67.216.143[.]42<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_58\">IPv4<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_58\">TA Infrastructure<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_59\">29efd64dd3c7fe1e2b022b7ad73a1ba5<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_59\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_59\">MIMIKATZ<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_60\">3c5a420aed54867a0fd0d373637595d2<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_60\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_60\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_61\">44eee3d7f6d60f3390c68ad3f1cb1b77<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_61\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_61\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_62\">4b940893856bbde6c7c587d7e10ec4d1<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_62\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_62\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_63\">4bfe8fafe03fe781f75c375bdade54f7<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_63\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_63\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_64\">60cf9dfc495e4bd99e31b2b6079f654e<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_64\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_64\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_65\">61b13d54c8dda98b7aa13e75abfdbd12<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_65\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_65\">UPDATE.EXE<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_66\">7f4c0d171e104eea3c48e03ade1ec68a<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_66\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_66\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_67\">825e125eb34abb8197178ed10d5452d5<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_67\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_67\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_68\">adc52a4c68173dce2733dbfe45c5ebe9<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_68\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_68\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_69\">bbeb9589a0f406d0d4921df68641ccf1<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_69\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_69\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_70\">cc51281a38bdc87a7ad0e4b612181ced<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_70\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_70\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_71\">d2848456bc6fc3bdccf6998befeced4b<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_71\">MD5<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_71\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_72\">1c939f39a93aa425f857f76a8072ef0e43153ed0<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_72\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_72\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_73\">48579f02785e022db5d31c229be8b9a098134d95<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_73\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_73\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_74\">6f464abe5f9591b3786f21ef911fc6cd1f717131<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_74\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_74\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_75\">9d966e90c1c6bc7100e9b089fe6c8ce52a6b379c<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_75\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_75\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_76\">a9ed0ca8e08cf1e7569fcda769351850c748d681<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_76\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_76\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_77\">b2cfe7344875528ce6bf64719c7eadadffb3e567<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_77\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_77\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_78\">b6da15fb313b3c7d66923f6144bac69aa19e74d1<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_78\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_78\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_79\">bd53bd285071966d8799e5d9ceaa84a0b058a4fb<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_79\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_79\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_80\">c219e7bee1cb92e2026a81ac333cd6f439a077b2<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_80\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_80\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_81\">d278d06db4e1b8a6379308a797c0304676a30e10<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_81\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_81\">UPDATE.EXE<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_82\">d34043b44a7405e1359ef5f4dbebd09f324d9645<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_82\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_82\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_83\">e3b6ea8c46fa831cec6f235a5cf48b38a4ae8d69<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_83\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_83\">MIMIKATZ<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_84\">eb410e312adadda3a3d13c608b8bb5ef7ecb812c<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_84\">SHA1<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_84\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_85\">140bcad5397858a7fa35a79dba4cd83decd4ae2927a22983218b3a0efebd8b9e<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_85\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_85\">TA Scripts (njmatio0)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_86\">1c2fbab9c849db1e8d8f26d217a7434aad3cab45b6f3c6c2de81b548220779fd<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_86\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_86\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_87\">20529bcdc538cc28303300bab95b9daeb07264cf7ccdef837f87e26ea2a4f23f<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_87\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_87\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_88\">234f8d70d92dde7d8f5edee2d3b3152214ef0b86c8e7c30274371fa9880243e6<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_88\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_88\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_89\">243e1d202848ae99d8ee7a13f08316a8f0d37db93379df2fcbae7ff82754d89e<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_89\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_89\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_90\">25e6fef0dce4e0f6260442b164ce7305561223429771b96f7448db8f337955cb<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_90\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_90\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_91\">61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_91\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_91\">MIMIKATZ<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_92\">84d33d77ea225839f0f2e473e20108e77f8a3e2a125eac844dc85116ef9792f5<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_92\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_92\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_93\">85ba48604d680d2786f485d70a6892dcf059c646e28b0a9befe530f9e3e459a5<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_93\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_93\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_94\">b6bb576e3dd58f09218cf455d94e4db253af5f244f70f88abd78af0dc29c1246<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_94\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_94\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_95\">bfa3cf521eefaaecc5d54028b3c12ea571033d4fe98e94d0031912b55071357b<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_95\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_95\">ALPHV<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_96\">c97641412ba384933dae4d4de377bc57bd0c9cd6d17b52a9a38c7c9a6eadd64c<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_96\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_96\">TA Scripts (Disable MDE)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_97\">da8c1976b9756cfb9afdcb4eaca193f411f96cee65835a87b3efb3423b33810b<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_97\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_97\">TA Scripts (WhenTheyCry0.ps1)<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_98\">df1f54952d918b1ddabf543ac50c2dafbca7aad2e5681824c0d1a44416da9c1d<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_98\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_98\">Malicious Intune Scripts<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_99\">e616846973de11765207dddbdf7712a74b2d804a08b65badb47f9ef09a640d4f<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_99\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_99\">FLEETDECK<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_100\">e7e8a15588225ae93f2ebc91769352de0d48bfdcfcb93718e66119eb23dee976<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_100\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_100\">UPDATE.EXE<\/td>\n\t\t<\/tr><tr><th class=\"active col-md-5 small\" headers=\"tbl1_1\" id=\"tbl1_101\">f51166cf076d96c47b5c2ba22e65903b21e4d6735e585e1c51f796108a0a54f9<\/th>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_2 tbl1_101\">SHA256<\/td>\n\t\t\t<td class=\"col-md-3\" headers=\"tbl1_3 tbl1_101\">ALPHV<\/td>\n\t\t<\/tr><\/tbody><\/table><\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the Official Languages Act is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.blackberry.com\/us\/en\/solutions\/endpoint-security\/ransomware-protection\/blackcat\">BlackCat Malware (AKA ALPHV)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/top-10-it-security-actions\">Top 10 IT Security Actions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/attack.mitre.org\/\">MITRE ATT&amp;K <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.crowdstrike.com\/blog\/analysis-of-intrusion-campaign-targeting-telecom-and-bpo-companies\/\">Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.group-ib.com\/blog\/blackcat\/ \">Fat Cats: An analysis of the BlackCat ransomware affiliate program<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/06\/13\/the-many-lives-of-blackcat-ransomware\/\">The many lives of BlackCat ransomware<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/dont-take-bait-recognize-and-avoid-phishing-attacks \">Don't Take the Bait: Recognize and Avoid Phishing Attacks<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/spotting-malicious-email-messages-itsap00100 \">Spotting Malicious Email Messages<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.getcybersafe.gc.ca\/en\/blogs\/spear-phishing-what-it-and-how-you-can-protect-yourself \">Spear phishing: What it is and how you can protect yourself<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/ransomware-playbook-itsm00099 \">The Cyber Centre Ransomware playbook (ITSM.00.099)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><section><h2>MITRE ATT&amp;CK techniques<\/h2>\n\n<ul class=\"list-unstyled lst-spcd\"><li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1586\/002\/\">ID: T1586.002\u00a0\u2013 Compromise Accounts: Email Accounts<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1586\/\">ID: T1586\u00a0\u2013 Compromise Accounts<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1566\/\">ID: T1566\u00a0\u2013 Phishing<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1111\/\">ID: T1111\u00a0- Multi-Factor Authentication Interception<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/tactics\/TA0004\/\">ID: TA0004\u00a0\u2013 Privilege Escalation<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1219\/\">ID: T1219\u00a0\u2013 Remote Access Software<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1135\/ \">ID: T1135\u00a0\u2013 Network Share Discovery<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1046\/\">ID: T1046\u00a0\u2013 Network Service Discovery<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1098\/005\/\">ID: T1098.005\u00a0- Account Manipulation: Device Registration<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1484\/002\/\">ID: T1484.002\u00a0\u2013 Domain Policy Modification: Domain Trust Modification<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1053\/005\/\">ID: T1053.005\u00a0\u2013 Scheduled Task\/Job: Scheduled Task<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1219\/\">ID: T1219\u00a0\u2013 Remote Access Software<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1525\/\">ID: T1525\u00a0- Implant Internal Image<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1072\/\">ID: T1072\u00a0- Software Deployment Tools<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1021\/001\/\">ID: T1021.001\u00a0- Remote Services: Remote Desktop Protocol<\/a><\/li>\n\t<li><a href=\"https:\/\/attack.mitre.org\/techniques\/T1490\/\">ID: T1490\u00a0\u2013 Inhibit System Recovery<\/a><\/li>\n<\/ul><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/alphvblackcat-ransomware-targeting-canadian-industries","alert_type":397,"serial_number":"AL23-010","subject":"other","moderation_state":"published","external_url":null},{"nid":4428,"title":"[Control systems] Rockwell Automation security advisory (AV23-438)","uuid":"f423bdbd-a061-4c6e-b2f6-590a9851ee46","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T18:51:47Z","date_created":"2023-07-25T18:17:52Z","summary":null,"body":["<article data-history-node-id=\"4428\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-438\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-438<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 25, 2023<\/p>\n\n<p>On July 25, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ThinManager ThinServer\u00a0\u2013 versions 13.0.0 to 13.0.2 and 13.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-206-02\">ICS Advisory - ICSA-23-206-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-438","alert_type":398,"serial_number":"AV23-438","subject":"other","moderation_state":"published","external_url":null},{"nid":4425,"title":"Citrix security advisory (AV23-435)","uuid":"57ee35cc-8958-42bb-95ba-e5f9829502be","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T18:22:25Z","date_created":"2023-07-25T18:18:28Z","summary":null,"body":["<article data-history-node-id=\"4425\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av23-435\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-435\n  <br \/><strong>Date: <\/strong>July 25, 2023\n<\/p>\n<p>On July 24, 2023, Citrix published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>Citrix Hypervisor\u00a0- version 8.2 Cumulative Update 1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX566835\/citrix-hypervisor-security-update-for-cve202320593\">Citrix Security Advisory\u00a0\u2013 CTX566835<\/a><\/li>\n  <li><a href=\"https:\/\/support.citrix.com\/knowledge-center\/search#\/All%20Products?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av23-435","alert_type":396,"serial_number":"AV23-435","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4426,"title":"[Control systems] Johnson Controls security advisory (AV23-436)","uuid":"0037245d-ee42-4271-a166-66fa5717bb62","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T18:25:02Z","date_created":"2023-07-25T18:23:24Z","summary":null,"body":["<article data-history-node-id=\"4426\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-436\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-436<br \/><strong>Date: <\/strong>July 25, 2023<\/p>\n\n<p>On July 25, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>IQ Wifi 6\u00a0\u2013 firmware versions prior to 2.0.2<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-206-04\">ICS Advisory\u00a0- ICSA-23-206-04<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-436","alert_type":398,"serial_number":"AV23-436","subject":"other","moderation_state":"published","external_url":null},{"nid":4427,"title":"[Control systems] Emerson security advisory (AV23-437)","uuid":"1fb8babc-8052-4cca-89df-ebb1bb61344f","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T18:29:58Z","date_created":"2023-07-25T18:27:55Z","summary":null,"body":["<article data-history-node-id=\"4427\" about=\"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av23-437\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-437<br \/><strong>Date: <\/strong>July 25, 2023<\/p>\n\n<p>On July 25, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>DL8000\u00a0\u2013 all firmware versions and platforms<\/li>\n\t<li>ROC809 and ROC827\u00a0\u2013 all firmware versions and platforms<\/li>\n\t<li>ROC809L and ROC827L\u00a0\u2013 all firmware versions<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in unauthorized access.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-206-03\">ICS Advisory\u00a0- ICSA-23-206-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-emerson-security-advisory-av23-437","alert_type":398,"serial_number":"AV23-437","subject":"other","moderation_state":"published","external_url":null},{"nid":4429,"title":"[Control systems] Axis Communications security advisory (AV23-439)","uuid":"d75ea681-f250-4360-bdf8-d5e61d3e20fb","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T18:55:07Z","date_created":"2023-07-25T18:54:13Z","summary":null,"body":["<article data-history-node-id=\"4429\" about=\"\/en\/alerts-advisories\/control-systems-axis-communications-security-advisory-av23-439\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-439<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 25, 2023<\/p>\n\n<p>On July 25, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>AXIS A1001\u00a0\u2013 version 1.65.4 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in arbitrary code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-206-01\">ICS Advisory - ICSA-23-206-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-axis-communications-security-advisory-av23-439","alert_type":398,"serial_number":"AV23-439","subject":"other","moderation_state":"published","external_url":null},{"nid":4430,"title":"HPE security advisory (AV23-440)","uuid":"d0ef715d-f9b5-47b1-9720-09b785afe3a6","banner":null,"lang":"en","date_modified":"2023-07-25","date_modified_ts":"2023-07-25T19:32:34Z","date_created":"2023-07-25T19:29:53Z","summary":null,"body":["<article data-history-node-id=\"4430\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-440\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-440<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 25, 2023<\/p>\n\n<p>On July 24, 2023, HPE published a security bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>IceWall Identity Manager\u00a0- versions prior to 5.0 Patch 6 (RHEL and HP-UX) and versions prior to 6.0 Patch 3 (RHEL and Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbmu04496en_us\">HPE Security Bulletin - hpesbmu04496en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-440","alert_type":396,"serial_number":"AV23-440","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4432,"title":"PaperCut security advisory (AV23-441)","uuid":"11375a0c-f7d2-4969-80ad-5df826e15f79","banner":null,"lang":"en","date_modified":"2023-07-26","date_modified_ts":"2023-07-26T18:27:28Z","date_created":"2023-07-26T18:23:51Z","summary":null,"body":["<article data-history-node-id=\"4432\" about=\"\/en\/alerts-advisories\/papercut-security-advisory-av23-441\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-441<br \/><strong>Date: <\/strong>July 26, 2023<\/p>\n\n<p>On July 25, 2023, PaperCut published a security bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>PaperCut NG\/MF Application Server\u00a0\u2013 versions prior to 22.1.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to upload\/download of arbitrary files.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.papercut.com\/kb\/Main\/SecurityBulletinJuly2023\/\">PaperCut Security Bulletin \u2013 July 2023<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/papercut-security-advisory-av23-441","alert_type":396,"serial_number":"AV23-441","subject":"other","moderation_state":"published","external_url":null},{"nid":4433,"title":"[Control systems] ABB security advisory (AV23-442)","uuid":"e919ae15-2c66-474a-af64-215ea7eb3e67","banner":null,"lang":"en","date_modified":"2023-07-26","date_modified_ts":"2023-07-26T19:42:44Z","date_created":"2023-07-26T19:39:08Z","summary":null,"body":["<article data-history-node-id=\"4433\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-442\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-442<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 26, 2023<\/p>\n\n<p>Between July 24 and 26, 2023, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Ability Zenon\u00a0\u2013 version 11 build 106404 and prior<\/li>\n\t<li>B&amp;R Automation Runtime\u00a0\u2013 versions prior to G4.93<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001801&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Advisory \u2013 2NGA001801<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/downloads_br_productcatalogue\/assets\/1689787619746-en-original-1.0.pdf\">ABB Advisory \u2013 SA23P013<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-442","alert_type":398,"serial_number":"AV23-442","subject":"abb","moderation_state":"published","external_url":null},{"nid":4434,"title":"HPE security advisory (AV23-443)","uuid":"1fe87e1f-5b5a-4437-8b9e-77ec22f508ac","banner":null,"lang":"en","date_modified":"2023-07-27","date_modified_ts":"2023-07-27T15:10:55Z","date_created":"2023-07-27T15:06:28Z","summary":null,"body":["<article data-history-node-id=\"4434\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-443\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-443<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a027, 2023<\/p>\n\n<p>On July\u00a025, 2023, HPE published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ArubaOS\u00a0\u2013 version 10.4.0.1 and prior<\/li>\n\t<li>InstantOS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04492en_us\">HPE Security Bulletin\u00a0- hpesbmu04492en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-443","alert_type":396,"serial_number":"AV23-443","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4435,"title":"Drupal security advisory (AV23-444)","uuid":"27719f2c-9754-4501-9a3a-7ae649556567","banner":null,"lang":"en","date_modified":"2023-07-27","date_modified_ts":"2023-07-27T15:25:00Z","date_created":"2023-07-27T15:06:29Z","summary":null,"body":["<article data-history-node-id=\"4435\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av23-444\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-444<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a027, 2023<\/p>\n\n<p>On July\u00a026, 2023, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Drupal Symfony Mailer module\u00a0\u2013 versions prior to v1.2.2<\/li>\n\t<li>Drupal Symfony Mailer module\u00a0\u2013 versions prior to v1.3.0-rc3<\/li>\n\t<li>Minify Source HTML module for Drupal\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2023-031\">Drupal Security Advisory\u00a0- SA-CONTRIB-2023-031<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2023-032\">Drupal Security Advisory\u00a0- SA-CONTRIB-2023-032<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av23-444","alert_type":396,"serial_number":"AV23-444","subject":"drupal","moderation_state":"published","external_url":null},{"nid":4438,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-446)","uuid":"e9218599-83d3-4c04-94b1-89cbcc7d6599","banner":null,"lang":"en","date_modified":"2023-07-27","date_modified_ts":"2023-07-27T18:54:54Z","date_created":"2023-07-27T18:40:16Z","summary":null,"body":["<article data-history-node-id=\"4438\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-446\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-446<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a027, 2023<\/p>\n\n<p>On July\u00a027, 2023, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitsubishi Electric CNC C80 Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Mitsubishi Electric CNC IoT Unit Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Mitsubishi Electric CNC M8 Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Mitsubishi Electric CNC M8V Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Mitsubishi Electric MELIPC Series\u00a0\u2013 firmware version 05 and prior<\/li>\n\t<li>Mitsubishi Electric MELSEC CPU Models\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-22-172-01\">ICS Advisory\u00a0- ICSA-22-172-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-208-03\">ICS Advisory\u00a0- ICSA-23-208-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-446","alert_type":398,"serial_number":"AV23-446","subject":"ics","moderation_state":"published","external_url":null},{"nid":4437,"title":"[Control systems] ETIC Telecom security advisory (AV23-445)","uuid":"1d64688d-76a9-4540-83e6-882cae500490","banner":null,"lang":"en","date_modified":"2023-07-27","date_modified_ts":"2023-07-27T18:53:33Z","date_created":"2023-07-27T18:48:26Z","summary":null,"body":["<article data-history-node-id=\"4437\" about=\"\/en\/alerts-advisories\/control-systems-etic-telecom-security-advisory-av23-445\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-445<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 27, 2023<\/p>\n\n<p>On July 27, 2023, CISA published ICS advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ETIC Telecom Remote Access Server (RAS)\u00a0\u2013 version 4.5.0 and prior<\/li>\n\t<li>ETIC Telecom Remote Access Server (RAS)\u00a0\u2013 version 4.7.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-22-307-01\">ICS Advisory\u00a0- ICSA-22-307-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-208-01\">ICS Advisory\u00a0- ICSA-23-208-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-etic-telecom-security-advisory-av23-445","alert_type":398,"serial_number":"AV23-445","subject":"other","moderation_state":"published","external_url":null},{"nid":4439,"title":"[Control systems] PTC security advisory (AV23-447) ","uuid":"c1242a65-5006-4a5e-81b6-d136b711ecff","banner":null,"lang":"en","date_modified":"2023-07-27","date_modified_ts":"2023-07-27T19:00:49Z","date_created":"2023-07-27T18:52:55Z","summary":null,"body":["<article data-history-node-id=\"4439\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-447\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-447<br \/><strong>Date: <\/strong>July 27, 2023<\/p>\n\n<p>On July 27, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>PTC KEPServerEX\u00a0\u2013 versions 6.0 to 6.14.263<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-208-0\">ICS Advisory\u00a0- ICSA-23-208-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-447","alert_type":398,"serial_number":"AV23-447","subject":"other","moderation_state":"published","external_url":null},{"nid":4440,"title":"Ivanti security advisory (AV23-448)","uuid":"b13e46ba-e004-4cd6-9d79-bfdf2fe69b78","banner":null,"lang":"en","date_modified":"2023-07-28","date_modified_ts":"2023-07-28T18:04:47Z","date_created":"2023-07-28T17:33:49Z","summary":null,"body":["<article data-history-node-id=\"4440\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-448\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-448<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a028, 2023<\/p>\n\n<p>On July\u00a027, 2023, Ivanti published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Ivanti Desktop and Server Management (DSM)\u00a0\u2013 version 2022.2 SU2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/SA-2023-07-26-CVE-2023-28129?language=en_US\">Ivanti Security Advisory\u00a0- SA-2023-07-26<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-448","alert_type":396,"serial_number":"AV23-448","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4442,"title":"IBM security advisory (AV23-449)","uuid":"c38a90e5-f81a-40df-8aa6-5df5ed80b6a8","banner":null,"lang":"en","date_modified":"2023-07-31","date_modified_ts":"2023-07-31T15:55:28Z","date_created":"2023-07-31T15:27:49Z","summary":null,"body":["<article data-history-node-id=\"4442\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-449\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-449<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 31, 2023<\/p>\n\n<p>Between July 24 and 30, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>App Connect Enterprise Certified Container\u00a0- version 6.2<\/li>\n\t<li>IBM Business Automation Manager Open Editions\u00a0- versions 8.0.0, 8.0.1 and 8.0.2<\/li>\n\t<li>IBM Cloud Transformation Advisor\u00a0- version 2.0.1 to 3.6.0<\/li>\n\t<li>IBM Cognos Analytics\u00a0- versions 11.1, 11.1.x, 11.2.0 and 11.2.x<\/li>\n\t<li>IBM Data Virtualization(DV) on Cloud Pak for Data(CPD)\u00a0- multiple versions<\/li>\n\t<li>IBM Event Streams\u00a0- version 10.0.0 to 11.1.6<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\u00a0- versions 8.9 and 8.10<\/li>\n\t<li>IBM Security Access Manager for Enterprise Single-Sign On\u00a0- version 8.2.2<\/li>\n\t<li>IBM Storage Protect Plus Container Agent\u00a0- version 10.1.5 to 10.1.12.5<\/li>\n\t<li>IBM TRIRIGA\u00a0- all versions<\/li>\n\t<li>IBM TRIRIGA Application Platform\u00a0- version 4.0<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0- versions 4.0.0 to 4.7.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-449","alert_type":396,"serial_number":"AV23-449","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4443,"title":"[Control systems] ABB security advisory (AV23-451)","uuid":"c2d7f29f-893e-4c8e-b280-1b8e4b29758c","banner":null,"lang":"en","date_modified":"2023-07-31","date_modified_ts":"2023-07-31T16:15:16Z","date_created":"2023-07-31T15:42:02Z","summary":null,"body":["<article data-history-node-id=\"4443\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-451\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-451<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July\u00a031, 2023<\/p>\n\n<p>On July\u00a028, 2023, ABB published security advisories to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB AO-OPC\u00a0\u2013 version 3.2.1.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108468A4093&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Advisory\u00a0\u2013 9AKK108468A4093 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-451","alert_type":398,"serial_number":"AV23-451","subject":"abb","moderation_state":"published","external_url":null},{"nid":4444,"title":"Ubuntu security advisory (AV23-450)","uuid":"b16d376b-8c4d-47ea-b823-005efaa26e56","banner":null,"lang":"en","date_modified":"2023-07-31","date_modified_ts":"2023-07-31T16:08:25Z","date_created":"2023-07-31T16:03:00Z","summary":null,"body":["<article data-history-node-id=\"4444\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-450\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-450<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>July 31, 2023<\/p>\n\n<p>Between July 24 and 30, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-450","alert_type":396,"serial_number":"AV23-450","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4446,"title":"Mozilla security advisory (AV23-452)","uuid":"819e5074-adbf-4e77-b39c-b93ef65acef6","banner":null,"lang":"en","date_modified":"2023-08-01","date_modified_ts":"2023-08-01T13:54:41Z","date_created":"2023-08-01T13:31:49Z","summary":null,"body":["<article data-history-node-id=\"4446\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-452\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-452<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August\u00a01, 2023<\/p>\n\n<p>On August\u00a01, 2023, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 116<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 102.14<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-29\/\">Mozilla Security Advisory\u00a0- MFSA 2023-29<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-30\/\">Mozilla Security Advisory\u00a0- MFSA 2023-30<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-31\/\">Mozilla Security Advisory\u00a0- MFSA 2023-31<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-452","alert_type":396,"serial_number":"AV23-452","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4449,"title":"[Control systems] APSystems security advisory (AV23-453)","uuid":"61d6d196-70e2-4e36-be79-dbb7a5aa719e","banner":null,"lang":"en","date_modified":"2023-08-01","date_modified_ts":"2023-08-01T15:50:54Z","date_created":"2023-08-01T15:47:45Z","summary":null,"body":["<article data-history-node-id=\"4449\" about=\"\/en\/alerts-advisories\/control-systems-apsystems-security-advisory-av23-453\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-453<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August\u00a01, 2023<\/p>\n\n<p>On August\u00a01, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>APSystems Altenergy Power Control Software\u00a0\u2013 version C1.2.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-213-01\">ICS Advisory\u00a0- ICSA-23-213-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-apsystems-security-advisory-av23-453","alert_type":398,"serial_number":"AV23-453","subject":"ics","moderation_state":"published","external_url":null},{"nid":4450,"title":"GitLab security advisory (AV23-454)","uuid":"732a6349-857c-45ae-a768-48f84f2e1c52","banner":null,"lang":"en","date_modified":"2023-08-01","date_modified_ts":"2023-08-01T19:13:53Z","date_created":"2023-08-01T19:07:59Z","summary":null,"body":["<article data-history-node-id=\"4450\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-454\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-454<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August\u00a01, 2023<\/p>\n\n<p>On August\u00a01, 2023, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/08\/01\/security-release-gitlab-16-2-2-released\/\">GitLab Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-454","alert_type":396,"serial_number":"AV23-454","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4451,"title":"HPE security advisory (AV23-455)","uuid":"4a1b78b8-5ab1-4a9e-924b-556cf99dc4d9","banner":null,"lang":"en","date_modified":"2023-08-02","date_modified_ts":"2023-08-02T13:00:48Z","date_created":"2023-08-02T12:55:30Z","summary":null,"body":["<article data-history-node-id=\"4451\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-455\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-xx<br \/><strong>Date: <\/strong>August 02, 2023<\/p>\n\n<p>On August 1, 2023, HPE published security bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Aruba CX Switches\u00a0\u2013 multiple versions and models<\/li>\n\t<li>HPE Fibre Channel and SAN Switches with Brocade Fabric OS\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04498en_us\">HPE Security Bulletin - hpesbnw04498en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04494en_us\">HPE Security Bulletin - hpesbst04494en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-455","alert_type":396,"serial_number":"AV23-455","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4453,"title":"Mitel security advisory (AV23-456)","uuid":"f162e724-8d96-4487-a075-10290dc4016b","banner":null,"lang":"en","date_modified":"2023-08-02","date_modified_ts":"2023-08-02T14:41:46Z","date_created":"2023-08-02T14:32:38Z","summary":null,"body":["<article data-history-node-id=\"4453\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av23-456\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-456<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 2, 2023<\/p>\n\n<p>On August\u00a02,\u00a02023, Mitel published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Mitel MiVoice Office 400 SMB Controller \u2013 version\u00a01.2.5.23 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-23-0008\">Mitel security advisory \u2013 23-0008<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-23-0009\">Mitel security advisory \u2013 23-0009<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av23-456","alert_type":396,"serial_number":"AV23-456","subject":"mitel","moderation_state":"published","external_url":null},{"nid":4454,"title":"F5 security advisory (AV23-457)","uuid":"3699ecf6-295b-4c66-9ebb-f2731c61af43","banner":null,"lang":"en","date_modified":"2023-08-02","date_modified_ts":"2023-08-02T17:20:16Z","date_created":"2023-08-02T17:18:48Z","summary":null,"body":["<article data-history-node-id=\"4454\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av23-457\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV23-457<\/p>\n\n<p><strong>Date:<\/strong> August 2, 2023<\/p>\n\n<p>On August 2, 2023, F5 published security bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions<\/li>\n\t<li>BIG-IP APM \u2013 multiple versions<\/li>\n\t<li>BIG-IP APM Clients \u2013 versions 7.2.3 to 7.2.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000135479\">F5 Security advisory - K000135479<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=cve&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending\">F5 Security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av23-457","alert_type":396,"serial_number":"AV23-457","subject":"other","moderation_state":"published","external_url":null},{"nid":4455,"title":"2022 Top routinely exploited vulnerabilities ","uuid":"d6cfab31-5fff-4804-ba6a-f0fde7140c21","banner":null,"lang":"en","date_modified":"2023-08-03","date_modified_ts":"2023-08-03T14:01:40Z","date_created":"2023-08-02T18:39:37Z","summary":null,"body":["<article data-history-node-id=\"4455\" about=\"\/en\/alerts-advisories\/2022-top-routinely-exploited-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-012<br \/><strong>Date:\u00a0<\/strong>August 3,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On August 3, 2023, the Canadian Centre for Cyber Security (CCCS) joined cyber security partners from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), Australian Cyber Security Centre (ACSC), New Zealand Computer Emergency Response Team (CERT-NZ) and National Cyber Security Centre (NCSC-NZ) and the United Kingdom\u2019s National Cyber Security Centre (NCSC-UK) to publish a joint Cybersecurity Advisory (CSA) detailing the Common Vulnerabilities and Exposures (CVEs) routinely and frequently exploited by malicious cyber actors in 2022 and the associated Common Weakness Enumerations (CWEs)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>This joint advisory is being published to provide awareness on the CVEs routinely and frequently exploited by malicious cyber actors and the mitigations organizations can take to protect themselves. The Joint Cybersecurity Advisory highlights that in 2022, malicious cyber actors exploited more older software vulnerabilities than recently disclosed vulnerabilities to target unpatched, internet-facing systems. Malicious cyber actors generally have the most success exploiting these known, older, and globally prevalent vulnerabilities and will prioritize the development of exploits or use publicly available Proof of concept (PoC) code.<\/p>\n\n<p>The Cybersecurity Advisory (CSA) contains a list of the most routinely exploited vulnerabilities, steps for vendors and developers to ensure their products are secure-by-design and default, and mitigations for end-user organizations to improve their cyber security posture. Additional guidance is available in the Cyber Centre\u2019s Top 10 IT security actions to protect Internet connected networks and information\u00a0- ITSM.00.089<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. These publications are based on analysis of cyber threat trends to help minimize intrusions or the impacts of a successful cyber intrusion.<\/p>\n\n<p>The authoring organizations encourage timely patching to reduce the effectiveness of known exploits as well as hunting for malicious activity using guidance found in the referenced CSA to reduce the likelihood and impact of future incidents.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-215a\">2022 Top Routinely Exploited Vulnerabilities\u00a0- Joint Cybersecurity Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information\u00a0-ITSM.00.089<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/2022-top-routinely-exploited-vulnerabilities","alert_type":397,"serial_number":"AL23-012","subject":"other","moderation_state":"published","external_url":null},{"nid":4456,"title":"Google Chrome security advisory (AV23-458)","uuid":"429c86fe-c511-41b2-9afc-2f5210aae5d0","banner":null,"lang":"en","date_modified":"2023-08-03","date_modified_ts":"2023-08-03T13:12:39Z","date_created":"2023-08-03T13:06:14Z","summary":null,"body":["<article data-history-node-id=\"4456\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-458\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-458<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August\u00a03, 2023<\/p>\n\n<p>On August\u00a02, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 115.0.5790.170\/.171 (Windows) and 115.0.5790.170 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/08\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-458","alert_type":396,"serial_number":"AV23-458","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4458,"title":"[Control systems] TEL-STER security advisory (AV23-459)","uuid":"3481cfac-d68c-4c7a-843a-c9a0850e4950","banner":null,"lang":"en","date_modified":"2023-08-03","date_modified_ts":"2023-08-03T18:00:23Z","date_created":"2023-08-03T17:49:49Z","summary":null,"body":["<article data-history-node-id=\"4458\" about=\"\/en\/alerts-advisories\/control-systems-tel-ster-security-advisory-av23-459\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-459<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 3, 203<\/p>\n\n<p>On August 3, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>TEL-STER TelWin SCADA WebInterface\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-215-03\">ICS Advisory\u00a0- ICSA-23-215-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-tel-ster-security-advisory-av23-459","alert_type":398,"serial_number":"AV23-459","subject":"ics","moderation_state":"published","external_url":null},{"nid":4460,"title":"[Control systems] Sensormatic Electronics security advisory (AV23-460)","uuid":"95ae0468-ab74-4e08-be6a-1920b7bd4b64","banner":null,"lang":"en","date_modified":"2023-08-03","date_modified_ts":"2023-08-03T18:20:39Z","date_created":"2023-08-03T18:10:08Z","summary":null,"body":["<article data-history-node-id=\"4460\" about=\"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av23-460\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-460<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 3, 2023<\/p>\n\n<p>On August 3, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Sensormatic Electronics VideoEdge\u00a0\u2013 versions prior to 6.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-215-04\">ICS Advisory\u00a0- ICSA-23-215-04<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sensormatic-electronics-security-advisory-av23-460","alert_type":398,"serial_number":"AV23-460","subject":"ics","moderation_state":"published","external_url":null},{"nid":4459,"title":"Midnight Blizzard conducts targeted social engineering over Microsoft Teams","uuid":"03417605-e22f-46ea-9340-b0db9c5133eb","banner":null,"lang":"en","date_modified":"2023-08-03","date_modified_ts":"2023-08-03T18:28:30Z","date_created":"2023-08-03T18:14:31Z","summary":null,"body":["<article data-history-node-id=\"4459\" about=\"\/en\/alerts-advisories\/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-013<br \/><strong>Date:\u00a0<\/strong>August 3,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On August 2, 2023, Microsoft Threat Intelligence published an advisory<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> highlighting details of targeted social engineering activity by threat actor Midnight Blizzard (previously tracked by Microsoft as NOBELIUM) taking place over Microsoft Teams. Using previously compromised Microsoft 365 tenants renamed to appear as technical support entities, Midnight Blizzard steals credentials by sending messages over Teams to engage with users and bypass multifactor authentication (MFA) prompts.<\/p>\n\n<p>While this campaign has affected fewer than 40 organizations globally, the Cyber Centre has received reports of attempts within Canada.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Review the Microsoft advisory and look for indicators of compromise to determine if related activity has occurred. If activity has been detected and a compromise has occurred:\n\t<ul><li>Reimage compromised systems.<\/li>\n\t\t<li>Reset all potentially compromised credentials.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> with an emphasis on the following topics.<\/p>\n\n<ul><li>Phishing Awareness. This includes both identification of phishing but also procedures on what to do if a phishing email is received.\n\t<ul><li>The Cyber Centre has several publications available on Phishing Awareness<span class=\"nowrap\"><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/span>.<\/li>\n\t\t<li>Phishing Technical Controls.<\/li>\n\t<\/ul><\/li>\n\t<li>Multi-factor Authentication.\n\t<ul><li>Where feasible, implement phishing-resistant MFA like FIDO2 security keys, Windows Hello, and Certificate Based Auth.<\/li>\n\t<\/ul><\/li>\n\t<li>Enforcing the Management of Administrative Privileges.\n\t<ul><li>Minimize the number of administrators and privileged roles.<\/li>\n\t\t<li>Conduct administrative activities on managed, hardened, and dedicated devices with restricted access to email, web browsing and outside connectivity.<\/li>\n\t\t<li>Enable two-person integrity when resetting administrative accounts to minimize successful social engineering activities.<\/li>\n\t<\/ul><\/li>\n\t<li>Remote Access Management and Controls.\n\t<ul><li>Network segmentation and demilitarized zones (DMZs).\n\t\t<ul><li>Configure firewalls to selectively control and monitor traffic passed between zones.<\/li>\n\t\t<\/ul><\/li>\n\t<\/ul><\/li>\n\t<li>Implementing location and device based conditional access policies.<\/li>\n\t<li>Software Management and Deployment Controls.<\/li>\n\t<li>Business continuity planning, which is tested and validated.<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <em>Official Languages Act<\/em> is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/08\/02\/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams\/\">Midnight Blizzard conducts targeted social engineering over Microsoft Teams<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/top-10-it-security-actions\">Top 10 IT security actions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/guidance\/dont-take-bait-recognize-and-avoid-phishing-attacks\">Don't Take the Bait: Recognize and avoid phishing attacks <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/spotting-malicious-email-messages-itsap00100 \">Spotting malicious email messages<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.getcybersafe.gc.ca\/en\/blogs\/spear-phishing-what-it-and-how-you-can-protect-yourself\">Spear phishing: What it is and how you can protect yourself<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams","alert_type":397,"serial_number":"AL23-013","subject":"other","moderation_state":"published","external_url":null},{"nid":4461,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-461)","uuid":"44450c3b-ca0c-4d33-96c0-e8f5125e3ba7","banner":null,"lang":"en","date_modified":"2023-08-03","date_modified_ts":"2023-08-03T18:44:45Z","date_created":"2023-08-03T18:24:44Z","summary":null,"body":["<article data-history-node-id=\"4461\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-461\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-461<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August w, 2023<\/p>\n\n<p>On August 3, 2023, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitsubishi Electric GOT2000 (models GT21, GT23, GT25, GT27\u00a0\u2013 versions prior to v01.50.000<\/li>\n\t<li>Mitsubishi Electric GOT Simple (models GS25, GS21\u00a0\u2013 versions prior to v01.50.000<\/li>\n\t<li>Mitsubishi Electric GT Designer3 Version1 (GOT2000\u00a0\u2013 versions prior to v1.300N<\/li>\n\t<li>Mitsubishi Electric GT SoftGOT2000\u00a0\u2013 versions prior to v1.300N<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-215-01\">ICS Advisory\u00a0- ICSA-23-215-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-215-02\">ICS Advisory\u00a0- ICSA-23-215-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-461","alert_type":398,"serial_number":"AV23-461","subject":"other","moderation_state":"published","external_url":null},{"nid":4463,"title":"Ivanti security advisory (AV23-462)","uuid":"c1a938d1-8caa-4f57-882c-29d5388c52d5","banner":null,"lang":"en","date_modified":"2023-08-04","date_modified_ts":"2023-08-04T17:19:10Z","date_created":"2023-08-04T17:13:55Z","summary":null,"body":["<article data-history-node-id=\"4463\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-462\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-462<br \/><strong>Date: <\/strong>August 4, 2023<\/p>\n\n<p>On August 3, 2023, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Avalanche\u00a0\u2013 version 6.4.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Avalanche-Vulnerabilities-Addressed-in-6-4-1?language=en_US\">Ivanti Security Advisory\u00a0- 000087219<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-462","alert_type":396,"serial_number":"AV23-462","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4464,"title":"Dell security advisory (AV23-463)","uuid":"c6827922-a0c4-4822-b07c-87ba716467f8","banner":null,"lang":"en","date_modified":"2023-08-08","date_modified_ts":"2023-08-08T17:44:28Z","date_created":"2023-08-08T17:39:46Z","summary":null,"body":["<article data-history-node-id=\"4464\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-463\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-463<br \/><strong>Date: <\/strong>August 8, 2023<\/p>\n\n<p>Between July 31 and August 6, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Avamar NDMP Accelerator\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar Server Hardware Appliance Gen4S\/ Gen4T\/ Gen5A\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar Virtual Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar VMware Image Proxy\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Container Storage Modules\u00a0\u2013 versions prior to 1.7.1<\/li>\n\t<li>Dell NetWorker Virtual Edition (NVE)\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerProtect DP Series Appliance \/ Dell Integrated Data Protection Appliance (IDPA)\u00a0\u2013 multiple versions<\/li>\n\t<li>PowerProtect Cyber Recovery\u00a0\u2013 version 19.14.0.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-463","alert_type":396,"serial_number":"AV23-463","subject":"dell","moderation_state":"published","external_url":null},{"nid":4465,"title":"Android security advisory \u2013 August 2023 Monthly Rollup (AV23-464)","uuid":"34d0939b-db77-47c4-9d7c-bbc2eb47d7ca","banner":null,"lang":"en","date_modified":"2023-08-08","date_modified_ts":"2023-08-08T17:48:20Z","date_created":"2023-08-08T17:45:18Z","summary":null,"body":["<article data-history-node-id=\"4465\" about=\"\/en\/alerts-advisories\/android-security-advisory-august-2023-monthly-rollup-av23-464\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-464<br \/><strong>Date: <\/strong>August 8, 2023<\/p>\n\n<p>On August 7, 2023, Android published a security bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-08-01 \">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-august-2023-monthly-rollup-av23-464","alert_type":396,"serial_number":"AV23-464","subject":"android","moderation_state":"published","external_url":null},{"nid":4466,"title":"IBM security advisory (AV23-465)","uuid":"b67b294e-f4cc-4adb-a215-c7bdd7af10af","banner":null,"lang":"en","date_modified":"2023-08-08","date_modified_ts":"2023-08-08T17:53:24Z","date_created":"2023-08-08T17:49:25Z","summary":null,"body":["<article data-history-node-id=\"4466\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-465\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-465<br \/><strong>Date: <\/strong>August 8, 2023<\/p>\n\n<p>Between July 31 and August 6, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 versions 1.10.0.0 to 1.10.12.0<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps\u00a0\u2013 version 4.x<\/li>\n\t<li>IBM MQ Operator\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM supplied MQ Advanced container images\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-465","alert_type":396,"serial_number":"AV23-465","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4467,"title":"Adobe security advisory (AV23-466)","uuid":"b87e4da7-63ec-4352-bd4f-60e6ca9507f4","banner":null,"lang":"en","date_modified":"2023-08-08","date_modified_ts":"2023-08-08T19:25:53Z","date_created":"2023-08-08T19:19:47Z","summary":null,"body":["<article data-history-node-id=\"4467\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-466\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-466<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 8, 2023<\/p>\n\n<p>On August 8, 2023, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat DC and Reader\u00a0\u2013 version 23.003.20244 and prior<\/li>\n\t<li>Acrobat 2020 and Reader\u00a0\u2013 version 20.005.30467 and prior<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 3.4.9 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb23-30.html\">Adobe Security Advisory - APSB23-30<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb23-42.html\">Adobe Security Advisory - APSB23-42<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/dimension\/apsb23-44.html\">Adobe Security Advisory - APSB23-44<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-466","alert_type":396,"serial_number":"AV23-466","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4468,"title":"[Control systems] Hitachi Energy security advisory (AV23-467) ","uuid":"27ff5677-0d0c-4307-b40b-ac3c8a05b846","banner":null,"lang":"en","date_modified":"2023-08-08","date_modified_ts":"2023-08-08T19:31:07Z","date_created":"2023-08-08T19:27:34Z","summary":null,"body":["<article data-history-node-id=\"4468\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-467\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-467<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 8, 2023<\/p>\n\n<p>On August 8, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Hitachi Energy RTU500 series \u2013 version 13.3.1 and 13.3.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-220-02\">ICS Advisory - ICSA-23-220-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-467","alert_type":398,"serial_number":"AV23-467","subject":"other","moderation_state":"published","external_url":null},{"nid":4469,"title":"[Control systems] Schneider Electric security advisory (AV23-468) ","uuid":"f06781f2-8074-4d7f-8397-98a940faa293","banner":null,"lang":"en","date_modified":"2023-08-08","date_modified_ts":"2023-08-08T19:35:34Z","date_created":"2023-08-08T19:32:59Z","summary":null,"body":["<article data-history-node-id=\"4469\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-468\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-468<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 8, 2023<\/p>\n\n<p>On August 8, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>IGSS Dashboard (DashBoard.exe) - version 16.0.0.23130 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-220-01\">ICS Advisory - ICSA-23-220-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-468","alert_type":398,"serial_number":"AV23-468","subject":"other","moderation_state":"published","external_url":null},{"nid":4470,"title":"SAP security advisory \u2013 August 2023 monthly rollup (AV23-469)","uuid":"4e8a3310-e08f-401e-b4d6-7ee2ddbf4ae2","banner":null,"lang":"en","date_modified":"2023-08-09","date_modified_ts":"2023-08-09T11:31:37Z","date_created":"2023-08-09T11:25:33Z","summary":null,"body":["<article data-history-node-id=\"4470\" about=\"\/en\/alerts-advisories\/sap-security-advisory-august-2023-monthly-rollup-av23-469\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-469<br \/><strong>Date: <\/strong>August 9, 2023<\/p>\n\n<p>On August 8, 2023, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP PowerDesigner\u00a0- version 16.7<\/li>\n\t<li>SAP ECC and SAP S\/4HANA (IS-OIL)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day \u2013 August 2023<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-august-2023-monthly-rollup-av23-469","alert_type":396,"serial_number":"AV23-469","subject":"sap","moderation_state":"published","external_url":null},{"nid":4471,"title":"Microsoft security advisory \u2013 August 2023 monthly rollup (AV23-470)","uuid":"f4ca5b16-1a8c-4944-b51f-2a1ae1745b69","banner":null,"lang":"en","date_modified":"2023-08-09","date_modified_ts":"2023-08-09T11:38:30Z","date_created":"2023-08-09T11:33:31Z","summary":null,"body":["<article data-history-node-id=\"4471\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2023-monthly-rollup-av23-470\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-470<br \/><strong>Date: <\/strong>August 9, 2023<\/p>\n\n<p>On August 8, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Microsoft Exchange Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Microsoft Office \u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Teams \u2013 multiple platforms<\/li>\n\t<li>.NET and Visual Studio \u2013 multiple versions<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-36884 and CVE-2023-38180 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Aug\">August 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2023-monthly-rollup-av23-470","alert_type":396,"serial_number":"AV23-470","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4475,"title":"Intel security advisory (AV23-471) ","uuid":"5e23f1ba-cda0-40e8-8af8-ef28b57cd003","banner":null,"lang":"en","date_modified":"2023-08-09","date_modified_ts":"2023-08-09T17:22:55Z","date_created":"2023-08-09T17:14:07Z","summary":null,"body":["<article data-history-node-id=\"4475\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av23-471\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV23-471<br \/><strong>Date:<\/strong> August 9, 2023<\/p>\n\n<p>On August 8,\u00a02023, Intel published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>Included were updates for the following:<\/p>\n\n<ul><li>Intel PROSet\/Wireless WiFi \u2013 versions prior to 22.220 HF<\/li>\n\t<li>Killer WiFi \u2013 versions prior to 3.2.20.23023<\/li>\n\t<li>Intel(R) AMT and Intel(R) Standard Manageability \u2013 multiple versions<\/li>\n\t<li>Intel Xeon Processors with Intel Software Guard Extensions (SGX) \u2013 multiple platforms<\/li>\n\t<li>Intel Virtual RAID on CPU (VROC) \u2013 versions prior to 8.0.0.4035<\/li>\n\t<li>Intel Easy Streaming Wizard software \u2013 all versions<\/li>\n\t<li>Intel NUC Pro Software Suite for Windows \u2013 versions prior to 2.0.0.9<\/li>\n\t<li>Intel Unite Software \u2013 versions prior to 4.2.11 for Mac and 4.2.34962 for Windows<\/li>\n\t<li>Intel AI Hackathon \u2013 versions prior to 2.0.0<\/li>\n\t<li>Intel DSA software \u2013 versions prior to 23.1.9<\/li>\n\t<li>Intel NUC Kit and Mini PC BIOS firmware \u2013 multiple versions and platforms<\/li>\n\t<li>Intel Manageability Commander \u2013 versions prior to 2.3<\/li>\n\t<li>Intel Unison \u2013 versions prior to 10.12<\/li>\n\t<li>Intel NUC BIOS \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av23-471","alert_type":396,"serial_number":"AV23-471","subject":"intel","moderation_state":"published","external_url":null},{"nid":4476,"title":"[Control systems]\u00a0Siemens security advisory (AV23-472)","uuid":"525b6639-f43d-4302-af78-70d49976af58","banner":null,"lang":"en","date_modified":"2023-08-09","date_modified_ts":"2023-08-09T17:47:00Z","date_created":"2023-08-09T17:35:13Z","summary":null,"body":["<article data-history-node-id=\"4476\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-472\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong>\u00a0AV23-472<br \/><strong>Date:<\/strong>\u00a0August 9, 2023<\/p>\n\n<p>On August 8, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>RUGGEDCOM CROSSBOW \u2013 versions prior to V5.4<\/li>\n\t<li>RUGGEDCOM ROS \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-472630.html\">Siemens Security Advisories \u2013 SSA-472630<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-908185.html\">Siemens Security Advisories \u2013 SSA-908185<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-472","alert_type":398,"serial_number":"AV23-472","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4477,"title":"Microsoft Edge security advisory (AV23-473)","uuid":"ad8bf08a-a2cc-4a92-8459-4212bb171ece","banner":null,"lang":"en","date_modified":"2023-08-09","date_modified_ts":"2023-08-09T18:07:25Z","date_created":"2023-08-09T18:03:46Z","summary":null,"body":["<article data-history-node-id=\"4477\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-473\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-473<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 9, 2023<\/p>\n\n<p>On August 7, 2023, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 115.0.1901.200<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 114.0.1823.106<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-7-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-473","alert_type":396,"serial_number":"AV23-473","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4478,"title":"Red Hat security advisory (AV23-474)","uuid":"1dcdf8fc-4433-4952-8889-faa4923da1bc","banner":null,"lang":"en","date_modified":"2023-08-09","date_modified_ts":"2023-08-09T18:12:51Z","date_created":"2023-08-09T18:09:25Z","summary":null,"body":["<article data-history-node-id=\"4478\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-474\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-474<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 9, 2023<\/p>\n\n<p>On August 8, 2023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux for x86_64\u00a0\u2013 Update Services for SAP Solutions 8.1 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 Update Services for SAP Solutions 8.1 ppc64le<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:4515\">Red Hat Security Advisory \u2013 RHSA-2023:4515<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-474","alert_type":396,"serial_number":"AV23-474","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4479,"title":"HPE security advisory (AV23-475)","uuid":"9d1e9e6f-6d6c-4875-b299-d43ad7575db1","banner":null,"lang":"en","date_modified":"2023-08-09","date_modified_ts":"2023-08-09T18:47:02Z","date_created":"2023-08-09T18:43:36Z","summary":null,"body":["<article data-history-node-id=\"4479\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-475\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-475<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 9, 2023<\/p>\n\n<p>On August 8, 2023, HPE published security bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>HPE Unified Correlation Analyzer \u2013 versions 4.3.x prior to 4.3.27<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04499en_us\">HPE Security Bulletin - hpesbgn04499en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-475","alert_type":396,"serial_number":"AV23-475","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4480,"title":"[Control systems] ABB security advisory (AV23-476)","uuid":"af749a62-2243-4248-92a2-c6356a3182e4","banner":null,"lang":"en","date_modified":"2023-08-10","date_modified_ts":"2023-08-10T18:40:54Z","date_created":"2023-08-10T18:28:25Z","summary":null,"body":["<article data-history-node-id=\"4480\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-476\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-476<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August\u00a010, 2023<\/p>\n\n<p>On August\u00a04, 2023, ABB published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Freelance AC 700F and AC 900F\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA007517&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Advisory\u00a0\u2013 7PAA007517 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-476","alert_type":398,"serial_number":"AV23-476","subject":"abb","moderation_state":"published","external_url":null},{"nid":4481,"title":"Ubuntu security advisory (AV23-477)","uuid":"a322e4d2-5e18-4479-b2ae-833ee697a494","banner":null,"lang":"en","date_modified":"2023-08-14","date_modified_ts":"2023-08-14T14:58:19Z","date_created":"2023-08-14T14:53:23Z","summary":null,"body":["<article data-history-node-id=\"4481\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-477\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-477<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August\u00a014, 2023<\/p>\n\n<p>Between August\u00a07 and 13, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6283-1\">Ubuntu Security Notice (USN-6283-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6284-1\">Ubuntu Security Notice (USN-6284-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6285-1\">Ubuntu Security Notice (USN-6285-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-477","alert_type":396,"serial_number":"AV23-477","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4482,"title":"IBM security advisory (AV23-478)","uuid":"88f4da9f-bb7c-4917-ad61-f6fc8ec2aa1f","banner":null,"lang":"en","date_modified":"2023-08-14","date_modified_ts":"2023-08-14T15:31:33Z","date_created":"2023-08-14T14:53:24Z","summary":null,"body":["<article data-history-node-id=\"4482\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-478\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-478<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August\u00a014, 2023<\/p>\n\n<p>Between August\u00a07 and 13, 2023, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-478","alert_type":396,"serial_number":"AV23-478","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4483,"title":"Dell security advisory (AV23-479)","uuid":"f4ee4ecd-a9f3-4666-9fc5-a8ff918b0af9","banner":null,"lang":"en","date_modified":"2023-08-14","date_modified_ts":"2023-08-14T16:07:58Z","date_created":"2023-08-14T15:52:17Z","summary":null,"body":["<article data-history-node-id=\"4483\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-479\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-479<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 14, 2023<\/p>\n\n<p>Between August 7 and 13, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Connectrix\u00a0- multiple versions and models<\/li>\n\t<li>Dell EMC Networking MX5108n\u00a0- multiple versions<\/li>\n\t<li>Dell EMC Networking MX9116n\u00a0- multiple versions<\/li>\n\t<li>Dell SmartFabric OS10\u00a0- 10.5.5.2 (mx), 10.5.5.3, 10.5.2.x, 10.5.3.x, 10.5.4.6 (mx), 10.5.4.x, 10.5.5.0 and 10.5.5.1 (mx)<\/li>\n\t<li>Dell SmartFabric Storage Software\u00a0- versions prior to 1.4.0<\/li>\n\t<li>Enterprise SONiC Distribution\u00a0- versions 3.5.x, 4.0.x and 4.1.0<\/li>\n\t<li>ESI (Enterprise Storage Integrator) for SAP LAMA\u00a0- versions prior to v10.0.0.0<\/li>\n\t<li>SANnav Connectrix\u00a0- multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-479","alert_type":396,"serial_number":"AV23-479","subject":"dell","moderation_state":"published","external_url":null},{"nid":4484,"title":"Google Chrome security advisory (AV23-482)","uuid":"3496b2bd-d1cb-42b8-b161-cf5de00f0c3b","banner":null,"lang":"en","date_modified":"2023-08-15","date_modified_ts":"2023-08-15T18:19:05Z","date_created":"2023-08-15T18:16:06Z","summary":null,"body":["<article data-history-node-id=\"4484\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-482\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-482<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 15, 2023<\/p>\n\n<p>On August 15, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 116.0.5845.96\/.97 (Windows) and 116.0.5845.96 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/08\/stable-channel-update-for-desktop_15.html \">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-482","alert_type":396,"serial_number":"AV23-482","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4485,"title":"[Control systems] Schneider Electric security advisory (AV23-480) ","uuid":"5e6c6338-8258-41bd-8462-bb52b81e6b0e","banner":null,"lang":"en","date_modified":"2023-08-15","date_modified_ts":"2023-08-15T18:27:11Z","date_created":"2023-08-15T18:20:24Z","summary":null,"body":["<article data-history-node-id=\"4485\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-480\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-480<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 15, 2023<\/p>\n\n<p>On August 15, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>EcoStruxure Control Expert\u00a0- all versions<\/li>\n\t<li>EcoStruxure Process Expert\u00a0- version V2020 and prior<\/li>\n\t<li>Modicon M340 CPU (part numbers BMXP34*)\u00a0- all versions<\/li>\n\t<li>Modicon M580 CPU (part numbers BMEP* and BMEH*)\u00a0- all versions<\/li>\n\t<li>Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)\u00a0- all versions<\/li>\n\t<li>Modicon Momentum Unity M1E Processor (171CBU*)\u00a0- all versions<\/li>\n\t<li>Modicon MC80 (BMKC80)\u00a0- all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-227-01\">ICS Advisory - ICSA-23-227-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-480","alert_type":398,"serial_number":"AV23-480","subject":"other","moderation_state":"published","external_url":null},{"nid":4486,"title":"[Control systems] Rockwell Automation security advisory (AV23-481)","uuid":"55370c70-d99c-463e-982e-d801bdad6912","banner":null,"lang":"en","date_modified":"2023-08-15","date_modified_ts":"2023-08-15T18:32:36Z","date_created":"2023-08-15T18:29:17Z","summary":null,"body":["<article data-history-node-id=\"4486\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-481\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-481<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 15, 2023<\/p>\n\n<p>On August 15, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Armor PowerFlex\u00a0\u2013 version v1.003<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-227-02  \">ICS Advisory - ICSA-23-227-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-481","alert_type":398,"serial_number":"AV23-481","subject":"other","moderation_state":"published","external_url":null},{"nid":4488,"title":"Atlassian security advisory (AV23-483)","uuid":"3b7342fd-bd7e-433c-af03-1a0eeee8515f","banner":null,"lang":"en","date_modified":"2023-08-16","date_modified_ts":"2023-08-16T12:17:04Z","date_created":"2023-08-16T12:15:23Z","summary":null,"body":["<article data-history-node-id=\"4488\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-483\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-483<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 15, 2023<\/p>\n\n<p>On August 15, 2023, Atlassian published a security bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>Confluence Server and Data Center\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-august-15-2023-1276870882.html \">Atlassian Security Advisory - August 15 2023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-483","alert_type":396,"serial_number":"AV23-483","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4489,"title":"HPE security advisory (AV23-484)","uuid":"a2ba80ac-98d4-4c4b-bd7a-8845685207ee","banner":null,"lang":"en","date_modified":"2023-08-16","date_modified_ts":"2023-08-16T12:27:38Z","date_created":"2023-08-16T12:22:50Z","summary":null,"body":["<article data-history-node-id=\"4489\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-484\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-484<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 15, 2023<\/p>\n\n<p>Between August 14 and 15, 2023, HPE published security bulletins to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE SimpliVity 380 Gen10\u00a0\u2013 versions prior to OmniStack Firmware version 2023_0803<\/li>\n\t<li>HPE SimpliVity 380 Gen10 G\u00a0\u2013 versions prior to OmniStack Firmware version 2023_0803<\/li>\n\t<li>HPE SimpliVity 380 Gen10 H\u00a0\u2013 versions prior to OmniStack Firmware version 2023_0803<\/li>\n\t<li>HPE SimpliVity 190r Gen10 Server\u00a0\u2013 versions prior to OmniStack Firmware version 2023_0803<\/li>\n\t<li>HPE SimpliVity 170r Gen10 Server\u00a0\u2013 versions prior to OmniStack Firmware version 2023_0803<\/li>\n\t<li>Aruba Virtual Intranet Access (VIA) Windows Client Only\u00a0\u2013 version 4.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04527en_us \">HPE Security Bulletin \u2013 hpesbnw04527en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04463en_us \">HPE Security Bulletin \u2013 hpesbhf04463en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-484","alert_type":396,"serial_number":"AV23-484","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4490,"title":"Cisco security advisory (AV23-485)","uuid":"0c387ff0-a299-47b1-bf54-d7e805d394e5","banner":null,"lang":"en","date_modified":"2023-08-16","date_modified_ts":"2023-08-16T17:37:50Z","date_created":"2023-08-16T17:34:44Z","summary":null,"body":["<article data-history-node-id=\"4490\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-485\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-485<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 16, 2023<\/p>\n\n<p>On August 16, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco ThousandEyes Enterprise Agent\u00a0\u2013 versions prior to 0.218<\/li>\n\t<li>Cisco Unified Communications Manager (CM)\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Communications Manager Session Management Edition (CM SME)\u00a0\u2013 multiple versions<\/li>\n\t<li>Secure Endpoint Connector for Windows\u00a0\u2013 multiple versions<\/li>\n\t<li>Secure Endpoint Private Cloud\u00a0\u2013 versions prior to 3.8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x \">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-485","alert_type":396,"serial_number":"AV23-485","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4491,"title":"[Control systems] ICONICS security advisory (AV23-486) ","uuid":"17fb5546-e6b4-4895-be7e-e1c5ea983a24","banner":null,"lang":"en","date_modified":"2023-08-17","date_modified_ts":"2023-08-17T17:20:56Z","date_created":"2023-08-17T17:18:12Z","summary":null,"body":["<article data-history-node-id=\"4491\" about=\"\/en\/alerts-advisories\/control-systems-iconics-security-advisory-av23-486\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-486<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 17, 2023<\/p>\n\n<p>On August 17, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ICONICS Suite\u00a0\u2013 version 10.97.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-229-01 \">ICS Advisory - ICSA-23-229-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-iconics-security-advisory-av23-486","alert_type":398,"serial_number":"AV23-486","subject":"other","moderation_state":"published","external_url":null},{"nid":4492,"title":"[Control systems] Walchem security advisory (AV23-487)","uuid":"41455e2a-e695-4907-8d9c-78aa0c4b380a","banner":null,"lang":"en","date_modified":"2023-08-17","date_modified_ts":"2023-08-17T18:44:49Z","date_created":"2023-08-17T18:37:43Z","summary":null,"body":["<article data-history-node-id=\"4492\" about=\"\/en\/alerts-advisories\/control-systems-walchem-security-advisory-av23-487\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-487<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 17, 2023<\/p>\n\n<p>On August 17, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Intuition 9\u00a0\u2013 versions prior to v4.21<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-229-04\">ICS Advisory\u00a0- ICSA-23-229-04<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-walchem-security-advisory-av23-487","alert_type":398,"serial_number":"AV23-487","subject":"other","moderation_state":"published","external_url":null},{"nid":4493,"title":"HPE security advisory (AV23-488)","uuid":"56e3b20d-c4bb-4b37-85c4-6e18906cb8a7","banner":null,"lang":"en","date_modified":"2023-08-18","date_modified_ts":"2023-08-18T20:07:17Z","date_created":"2023-08-18T20:04:42Z","summary":null,"body":["<article data-history-node-id=\"4493\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-488\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-488<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 18, 2023<\/p>\n\n<p>On August 17, 2023, HPE published a security bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Web Server Suite Software PHP\u00a0\u2013 version 7.4.7.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04528en_us\">HPE Security Bulletin \u2013 hpesbux04528en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-488","alert_type":396,"serial_number":"AV23-488","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4494,"title":"Juniper Networks security advisory - Update 1 (AV23-489)","uuid":"303dce93-0627-4cd6-8477-5384b888ffdf","banner":null,"lang":"en","date_modified":"2023-08-30","date_modified_ts":"2023-08-30T18:44:46Z","date_created":"2023-08-18T20:08:44Z","summary":null,"body":["<article data-history-node-id=\"4494\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-489\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-489<br \/><strong>Date: <\/strong>August 18, 2023<br \/><strong>Updated: <\/strong>August 30, 2023<\/p>\n\n<p>On August 17, 2023, Juniper Networks published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Juniper Networks Junos OS (SRX and EX Series) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre has received reports CVE-2023-36844, CVE-2023-36845, CVE-2023-36846 and CVE-2023-36847 have available exploits.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US\">Juniper Networks Security Advisories \u2013 JSA72300<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy&amp;numberOfResults=100&amp;f:ctype=[Security%20Advisories]\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-489","alert_type":396,"serial_number":"AV23-489","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4496,"title":"Dell security advisory (AV23-490)","uuid":"ab018162-7f1a-44b8-a24d-cd0f9f30699f","banner":null,"lang":"en","date_modified":"2023-08-21","date_modified_ts":"2023-08-21T17:31:20Z","date_created":"2023-08-21T17:23:43Z","summary":null,"body":["<article data-history-node-id=\"4496\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-490\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-490<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 21, 2023<\/p>\n\n<p>Between August 14 and 20, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell Edge Gateway 5200\u00a0- versions prior to 1.04.10<\/li>\n\t<li>Dell Networking Virtual Edge Platform (VEP) 4600\u00a0- versions prior to UFW 3.5<\/li>\n\t<li>Dell PowerSwitch\u00a0- multiple versions and models<\/li>\n\t<li>Dell SD-WAN Edge 600\u00a0- versions 3.50.0.9 to 13<\/li>\n\t<li>PowerScale OneFS\u00a0- multiple versions<\/li>\n\t<li>Virtual Edge Platform 1405 (VEP 1425, VEP 1445, VEP1485)\u00a0- versions prior to UFW 2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-490","alert_type":396,"serial_number":"AV23-490","subject":"dell","moderation_state":"published","external_url":null},{"nid":4497,"title":"IBM security advisory (AV23-491)","uuid":"0d435d68-b4b8-466f-adf4-8a08e897e792","banner":null,"lang":"en","date_modified":"2023-08-21","date_modified_ts":"2023-08-21T17:42:59Z","date_created":"2023-08-21T17:35:59Z","summary":null,"body":["<article data-history-node-id=\"4497\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-491\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-491<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 21, 2023<\/p>\n\n<p>Between August 14 and August 20, 2023, IBM published security bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Security Guardium\u00a0- versions 10.6, 11.3, 11.4 and 11.5<\/li>\n\t<li>IBM Voice Gateway\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7027853\">IBM Security Bulletin\u00a0\u2013 7027853<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7027854\">IBM Security Bulletin\u00a0\u2013 7027854<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7026694\">IBM Security Bulletin\u00a0\u2013 7026694<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-491","alert_type":396,"serial_number":"AV23-491","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4498,"title":"Ubuntu security advisory (AV23-492)","uuid":"6258f198-be9f-4a44-be3c-7f65c0d07bfc","banner":null,"lang":"en","date_modified":"2023-08-21","date_modified_ts":"2023-08-21T18:04:36Z","date_created":"2023-08-21T17:53:08Z","summary":null,"body":["<article data-history-node-id=\"4498\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-492\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-492<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 21, 2023<\/p>\n\n<p>Between August 14 and 20, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6300-1\">Ubuntu Security Notice (USN-6300-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6301-1\">Ubuntu Security Notice (USN-6301-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-492","alert_type":396,"serial_number":"AV23-492","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4499,"title":"Ivanti security advisory (AV23-493)","uuid":"bec90c19-3414-4d09-869d-6bf9587ff8a2","banner":null,"lang":"en","date_modified":"2023-08-21","date_modified_ts":"2023-08-21T18:57:27Z","date_created":"2023-08-21T18:28:34Z","summary":null,"body":["<article data-history-node-id=\"4499\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-493\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-493<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 21, 2023<\/p>\n\n<p>On August 21, 2023, Ivanti published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Ivanti Sentry (formerly MobileIron Sentry)\u00a0\u2013 versions 9.18.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US\">Ivanti Security Advisories\u00a0- CVE-2023-38035<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-493","alert_type":396,"serial_number":"AV23-493","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4500,"title":"Microsoft Edge security advisory (AV23-494)","uuid":"2d629d34-fe4e-4ef0-b842-07bf179f95a3","banner":null,"lang":"en","date_modified":"2023-08-22","date_modified_ts":"2023-08-22T16:32:23Z","date_created":"2023-08-22T16:27:27Z","summary":null,"body":["<article data-history-node-id=\"4500\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-494\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-494<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 22, 2023<\/p>\n\n<p>On August 21, 2023, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 116.0.1938.54<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 116.0.1938.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-21-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-494","alert_type":396,"serial_number":"AV23-494","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4501,"title":"[Control systems] Trane Technologies security advisory (AV23-496)","uuid":"5ddeb01d-4f1d-40d4-8837-80fc35927fcc","banner":null,"lang":"en","date_modified":"2023-08-22","date_modified_ts":"2023-08-22T18:44:51Z","date_created":"2023-08-22T18:08:56Z","summary":null,"body":["<article data-history-node-id=\"4501\" about=\"\/en\/alerts-advisories\/control-systems-trane-technologies-security-advisory-av23-496\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-496<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 22, 2023<\/p>\n\n<p>On August 22, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Trane Technologies Thermostats\u00a0\u2013 multiple models and firmware versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-234-02\">ICS Advisory\u00a0- ICSA-23-234-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-trane-technologies-security-advisory-av23-496","alert_type":398,"serial_number":"AV23-496","subject":"other","moderation_state":"published","external_url":null},{"nid":4502,"title":"[Control systems] Hitachi Energy security advisory (AV23-495)","uuid":"d5f37859-2a39-4271-ac4f-55a5bd8f14e7","banner":null,"lang":"en","date_modified":"2023-08-22","date_modified_ts":"2023-08-22T18:38:08Z","date_created":"2023-08-22T18:33:47Z","summary":null,"body":["<article data-history-node-id=\"4502\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-495\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-495<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 22, 2023<\/p>\n\n<p>On August 22, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Energy AFF660\/665\u00a0\u2013 firmware version 03.0.02 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-234-01\">ICS Advisory\u00a0- ICSA-23-234-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-495","alert_type":398,"serial_number":"AV23-495","subject":"other","moderation_state":"published","external_url":null},{"nid":4504,"title":"[Control systems] Rockwell Automation security advisory (AV23-497) ","uuid":"7e7911c1-f0ff-44ed-a208-c39baf19cb7e","banner":null,"lang":"en","date_modified":"2023-08-22","date_modified_ts":"2023-08-22T19:00:59Z","date_created":"2023-08-22T18:45:39Z","summary":null,"body":["<article data-history-node-id=\"4504\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-497\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-497<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 22, 2023<\/p>\n\n<p>On August 22, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-234-03\">ICS Advisory\u00a0- ICSA-23-234-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-497","alert_type":398,"serial_number":"AV23-497","subject":"other","moderation_state":"published","external_url":null},{"nid":4505,"title":"Google Chrome security advisory (AV23-498)","uuid":"102870a2-1db3-4787-a4c0-81ace271647e","banner":null,"lang":"en","date_modified":"2023-08-23","date_modified_ts":"2023-08-23T14:24:29Z","date_created":"2023-08-23T14:18:07Z","summary":null,"body":["<article data-history-node-id=\"4505\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-498\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-498<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 23, 2023<\/p>\n\n<p>On August 22, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 116.0.5845.110\/.111 (Windows) and 116.0.5845.110 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/08\/chrome-desktop-stable-update.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-498","alert_type":396,"serial_number":"AV23-498","subject":"other","moderation_state":"published","external_url":null},{"nid":4506,"title":"HPE security advisory (AV23-499)","uuid":"14530aeb-fad2-4d00-a6bd-0ff80842a099","banner":null,"lang":"en","date_modified":"2023-08-23","date_modified_ts":"2023-08-23T14:32:31Z","date_created":"2023-08-23T14:29:38Z","summary":null,"body":["<article data-history-node-id=\"4506\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-499\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-499<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 23, 2023<\/p>\n\n<p>On August 22, 2023, HPE published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE EdgeConnect SD-WAN Orchestrator \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04531en_us\">HPE Security Bulletin \u2013 hpesbux04531en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-499","alert_type":396,"serial_number":"AV23-499","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4507,"title":"Cisco security advisory (AV23-500)","uuid":"0f6fae99-4cbf-4ee7-88a7-b59a1476c38f","banner":null,"lang":"en","date_modified":"2023-08-24","date_modified_ts":"2023-08-24T12:24:31Z","date_created":"2023-08-24T12:18:40Z","summary":null,"body":["<article data-history-node-id=\"4507\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-500\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-500<br \/><strong>Date: <\/strong>August 24, 2023<\/p>\n\n<p>On August 23, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Firepower 4100 Series<\/li>\n\t<li>Firepower 9300 Security Appliances<\/li>\n\t<li>UCS 6300 Series Fabric Interconnects<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-fp-ucsfi-snmp-dos-qtv69NAO\">Cisco Security Advisory - cisco-sa-fp-ucsfi-snmp-dos-qtv69NAO<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-500","alert_type":396,"serial_number":"AV23-500","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4508,"title":"[Control systems] KNX Association security advisory (AV23-501)","uuid":"406a986d-da98-4c74-8554-04fe6db57220","banner":null,"lang":"en","date_modified":"2023-08-24","date_modified_ts":"2023-08-24T18:33:40Z","date_created":"2023-08-24T18:16:52Z","summary":null,"body":["<article data-history-node-id=\"4508\" about=\"\/en\/alerts-advisories\/control-systems-knx-association-security-advisory-av23-501\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-501<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 24, 2023<\/p>\n\n<p>On August 24, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>KNX devices using Connection Authorization Option 1 Style in which no BCU Key is currently set\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-236-01\">ICS Advisory - ICSA-23-236-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-knx-association-security-advisory-av23-501","alert_type":398,"serial_number":"AV23-501","subject":"other","moderation_state":"published","external_url":null},{"nid":4509,"title":"[Control systems] Opto 22 security advisory (AV23-502) ","uuid":"166638b6-4a6a-4a17-8775-a04d8e79e325","banner":null,"lang":"en","date_modified":"2023-08-24","date_modified_ts":"2023-08-24T18:38:55Z","date_created":"2023-08-24T18:21:48Z","summary":null,"body":["<article data-history-node-id=\"4509\" about=\"\/en\/alerts-advisories\/control-systems-opto-22-security-advisory-av23-502\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-502<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 24, 2023<\/p>\n\n<p>On August 24, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Opto 22 NAP PAC S1 \u2013 version R10.3b<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-236-02\">ICS Advisory - ICSA-23-236-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-opto-22-security-advisory-av23-502","alert_type":398,"serial_number":"AV23-502","subject":"other","moderation_state":"published","external_url":null},{"nid":4510,"title":"[Control systems] CODESYS security advisory (AV23-503) ","uuid":"1ea5115f-78f5-495e-b82d-f4c99757d6c2","banner":null,"lang":"en","date_modified":"2023-08-24","date_modified_ts":"2023-08-24T18:42:55Z","date_created":"2023-08-24T18:26:28Z","summary":null,"body":["<article data-history-node-id=\"4510\" about=\"\/en\/alerts-advisories\/control-systems-codesys-security-advisory-av23-503\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-503<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 24, 2023<\/p>\n\n<p>On August 24, 2023, CISA published ICS advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>CODESYS Development System\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-236-03\">ICS Advisory - ICSA-23-236-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-236-04\">ICS Advisory - ICSA-23-236-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-236-05\">ICS Advisory - ICSA-23-236-05<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-codesys-security-advisory-av23-503","alert_type":398,"serial_number":"AV23-503","subject":"other","moderation_state":"published","external_url":null},{"nid":4511,"title":"[Control systems] Rockwell Automation security advisory (AV23-504)","uuid":"0f921323-4d41-4bf5-bc3c-1d1ae0a9ca6e","banner":null,"lang":"en","date_modified":"2023-08-24","date_modified_ts":"2023-08-24T18:51:33Z","date_created":"2023-08-24T18:44:38Z","summary":null,"body":["<article data-history-node-id=\"4511\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-504\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-504<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 24, 2023<\/p>\n\n<p>On August 24, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>1734-AENT\/1734-AENTR Series C\u00a0\u2013 versions 7.011 and prior<\/li>\n\t<li>1734-AENT\/1734-AENTR Series B\u00a0\u2013 versions 5.019 and prior<\/li>\n\t<li>1738-AENT\/ 1738-AENTR Series B\u00a0\u2013 versions 6.011 and prior<\/li>\n\t<li>1794-AENTR Series A\u00a0\u2013 versions 2.011 and prior<\/li>\n\t<li>1732E-16CFGM12QCWR Series A\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-12X4M12QCDR Series A\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-16CFGM12QCR Series A\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-16CFGM12P5QCR Series A\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-12X4M12P5QCDR Series A\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-16CFGM12P5QCWR Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-IB16M12R Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-OB16M12R Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-16CFGM12R Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-IB16M12DR Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-OB16M12DR Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1732E-8X8M12DR Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n\t<li>1799ER-IQ10XOQ10 Series B\u00a0\u2013 versions 3.011 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-236-06\">ICS Advisory - ICSA-23-236-06<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-504","alert_type":398,"serial_number":"AV23-504","subject":"other","moderation_state":"published","external_url":null},{"nid":4513,"title":"Dell security advisory (AV23-505)","uuid":"467b8850-c85e-4913-b8d0-db1c719ca7a2","banner":null,"lang":"en","date_modified":"2023-08-28","date_modified_ts":"2023-08-28T14:47:42Z","date_created":"2023-08-28T14:41:18Z","summary":null,"body":["<article data-history-node-id=\"4513\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-505\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-505<br \/><strong>Date: <\/strong>August 28, 2023<strong> <\/strong><\/p>\n\n<p>Between August 21 and 27, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell Cloud Tiering Appliance\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerEdge T40 BIOS\u00a0\u2013 versions prior to 1.12.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000216897\/dsa-2023-207-security-update-for-dell-poweredge-t40-mini-tower-server-openssl-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-207<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000216918\/dsa-2023-308-security-update-for-dell-cloud-tiering-appliance\">Dell Security Update\u00a0- DSA-2023-308<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000216919\/dsa-2023-309-security-update-for-dell-cloud-tiering-appliance\">Dell Security Update\u00a0- DSA-2023-309<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-505","alert_type":396,"serial_number":"AV23-505","subject":"dell","moderation_state":"published","external_url":null},{"nid":4514,"title":"IBM security advisory (AV23-506)","uuid":"be60b299-d03f-4d03-b042-22151b9b6e5c","banner":null,"lang":"en","date_modified":"2023-08-28","date_modified_ts":"2023-08-28T14:52:27Z","date_created":"2023-08-28T14:48:49Z","summary":null,"body":["<article data-history-node-id=\"4514\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-506\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-506<br \/><strong>Date: <\/strong>August 28, 2023<\/p>\n\n<p>Between August 21 and August 27, 2023, IBM published security bulletins to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7028727\">IBM Security Bulletin\u00a0\u2013 7028727<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-506","alert_type":396,"serial_number":"AV23-506","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4515,"title":"Microsoft Edge security advisory (AV23-507)","uuid":"e77fec88-710f-4155-b70f-2c1f09ac3275","banner":null,"lang":"en","date_modified":"2023-08-28","date_modified_ts":"2023-08-28T15:10:22Z","date_created":"2023-08-28T15:06:37Z","summary":null,"body":["<article data-history-node-id=\"4515\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-507\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-507<br \/><strong>Date: <\/strong>August 28, 2023<\/p>\n\n<p>On August 25, 2023, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 116.0.1938.62<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-25-2023 \">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-507","alert_type":396,"serial_number":"AV23-507","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4516,"title":"Mozilla security advisory (AV23-508)","uuid":"0c308fde-f005-4784-a189-c59246bf56b9","banner":null,"lang":"en","date_modified":"2023-08-29","date_modified_ts":"2023-08-29T14:00:10Z","date_created":"2023-08-29T13:54:35Z","summary":null,"body":["<article data-history-node-id=\"4516\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-508\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-508<br \/><strong>Date: <\/strong>August 29, 2023<\/p>\n\n<p>On August 29, 2023, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 117<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 102.15<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-34\/\">Mozilla Security Advisory\u00a0- MFSA 2023-34<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-35\/\">Mozilla Security Advisory\u00a0- MFSA 2023-35<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-36\/\">Mozilla Security Advisory\u00a0- MFSA 2023-36<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-508","alert_type":396,"serial_number":"AV23-508","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4517,"title":"[Control systems] PTC security advisory (AV23-509) ","uuid":"2cffbcdb-bc71-4153-9bea-a0cd531a6113","banner":null,"lang":"en","date_modified":"2023-08-29","date_modified_ts":"2023-08-29T14:52:18Z","date_created":"2023-08-29T14:49:10Z","summary":null,"body":["<article data-history-node-id=\"4517\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-509\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-509<br \/><strong>Date: <\/strong>August 29, 2023<\/p>\n\n<p>On August 29, 2023, CISA published an ICS advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>PTC Codebeamer\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-241-01\">ICS Advisory\u00a0- ICSA-23-241-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-509","alert_type":398,"serial_number":"AV23-509","subject":"other","moderation_state":"published","external_url":null},{"nid":4518,"title":"VMware security advisory (AV23-510)","uuid":"ebe5bd83-f95d-4abd-90e2-35c251f05ea3","banner":null,"lang":"en","date_modified":"2023-08-29","date_modified_ts":"2023-08-29T17:36:24Z","date_created":"2023-08-29T17:33:07Z","summary":null,"body":["<article data-history-node-id=\"4518\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-510\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-510<br \/><strong>Date: <\/strong>August 29, 2023<\/p>\n\n<p>On August 29, 2023, VMware published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Aria Operations for Networks\u00a0\u2013 versions prior to 6.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0018.html\">VMware Security Advisory - VMSA-2023-0018<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html \">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-510","alert_type":396,"serial_number":"AV23-510","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4519,"title":"Google Chrome security advisory (AV23-511)","uuid":"75a77884-d5a0-4ff2-85de-9a91df590cc8","banner":null,"lang":"en","date_modified":"2023-08-29","date_modified_ts":"2023-08-29T18:19:21Z","date_created":"2023-08-29T18:15:46Z","summary":null,"body":["<article data-history-node-id=\"4519\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-511\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-511\n  <br \/><strong>Date: <\/strong>August 29, 2023\n<\/p>\n<p>On August 29, 2023, Google published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 116.0.5845.140\/.141 (Windows) and 116.0.5845.140 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/08\/stable-channel-update-for-desktop_29.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-511","alert_type":396,"serial_number":"AV23-511","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4521,"title":"HPE security advisory (AV23-512)","uuid":"2af8b8c4-a345-428d-ae02-d3f0f5db1af5","banner":null,"lang":"en","date_modified":"2023-08-30","date_modified_ts":"2023-08-30T12:49:31Z","date_created":"2023-08-30T12:25:26Z","summary":null,"body":["<article data-history-node-id=\"4521\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-512\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-512<br \/><strong>Date: <\/strong>August 30, 2023<\/p>\n\n<p>On August 29, 2023, HPE published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking Switch \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04533en_us\">HPE Security Bulletin \u2013 hpesbnw04533en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-512","alert_type":396,"serial_number":"AV23-512","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4524,"title":"VMware security advisory (AV23-513)","uuid":"d3f3d4e2-9306-40eb-9723-40fd0475c489","banner":null,"lang":"en","date_modified":"2023-08-31","date_modified_ts":"2023-08-31T13:00:46Z","date_created":"2023-08-31T12:58:03Z","summary":null,"body":["<article data-history-node-id=\"4524\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-513\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-513<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 31, 2023<\/p>\n\n<p>On August 31, 2023, VMware published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Tools \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0019.html\">VMware Security Advisory - VMSA-2023-0019<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-513","alert_type":396,"serial_number":"AV23-513","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4525,"title":"HPE security advisory (AV23-514)","uuid":"61f74f52-6ec4-429b-9141-09ace85b0ff8","banner":null,"lang":"en","date_modified":"2023-08-31","date_modified_ts":"2023-08-31T13:08:00Z","date_created":"2023-08-31T13:04:06Z","summary":null,"body":["<article data-history-node-id=\"4525\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-514\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-514<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 31, 2023<\/p>\n\n<p>On August 31, 2023, HPE published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE SANnav Global View \u2013 versions prior to 2.2.2a<\/li>\n\t<li>HPE SANnav Global View \u2013 versions prior to 2.3.0<\/li>\n\t<li>HPE SANnav Management Portal \u2013 versions prior to 2.2.2a<\/li>\n\t<li>HPE SANnav Management Portal \u2013 versions prior to 2.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04532en_us\">HPE Security Bulletin \u2013 hpesbst04532en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-514","alert_type":396,"serial_number":"AV23-514","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4526,"title":"[Control systems] PTC security advisory (AV23-515)","uuid":"405671d1-6dd5-4869-8195-fd9c4754ee40","banner":null,"lang":"en","date_modified":"2023-08-31","date_modified_ts":"2023-08-31T15:41:14Z","date_created":"2023-08-31T15:37:57Z","summary":null,"body":["<article data-history-node-id=\"4526\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-515\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-515<br \/><strong>Date: <\/strong>August 31, 2023<\/p>\n\n<p>On August 31, 2023, CISA published an ICS advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>PTC Kepware KepServerEX\u00a0\u2013 version 6.14.263.0 and prior<\/li>\n\t<li>PTC ThingWorx Kepware Server\u00a0\u2013 version 6.14.263.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-243-03\">ICS Advisory\u00a0- ICSA-23-243-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-515","alert_type":398,"serial_number":"AV23-515","subject":"other","moderation_state":"published","external_url":null},{"nid":4527,"title":"[Control systems] Digi security advisory (AV23-516)","uuid":"9c5974af-5e22-4ed7-956a-d5ca0a8434e5","banner":null,"lang":"en","date_modified":"2023-08-31","date_modified_ts":"2023-08-31T15:46:56Z","date_created":"2023-08-31T15:42:06Z","summary":null,"body":["<article data-history-node-id=\"4527\" about=\"\/en\/alerts-advisories\/control-systems-digi-security-advisory-av23-516\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-516<br \/><strong>Date: <\/strong>August 31, 2023<\/p>\n\n<p>On August 31, 2023, CISA published an ICS advisory to highlight a vulnerability in the following products:<\/p>\n\n<ul><li>Digi RealPort\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Digi ConnectPort\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Digi Passport Console Server\u00a0\u2013 all versions<\/li>\n\t<li>Digi CM Console Server\u00a0\u2013 all versions<\/li>\n\t<li>Digi PortServer TS\u00a0\u2013 all versions and multiple platforms<\/li>\n\t<li>Digi One\u00a0\u2013 all versions and multiple platforms<\/li>\n\t<li>Digi WR31\u00a0\u2013 all versions<\/li>\n\t<li>Digi WR11 XT\u00a0\u2013 all versions<\/li>\n\t<li>Digi WR44 R\u00a0\u2013 all versions<\/li>\n\t<li>Digi WR21\u00a0\u2013 all versions<\/li>\n\t<li>Digi Connect\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-243-04\">ICS Advisory\u00a0- ICSA-23-243-04<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-digi-security-advisory-av23-516","alert_type":398,"serial_number":"AV23-516","subject":"other","moderation_state":"published","external_url":null},{"nid":4528,"title":"[Control systems] ARDEREG security advisory (AV23-517)","uuid":"c5eed4db-246f-4b64-a98d-a9306bcf3916","banner":null,"lang":"en","date_modified":"2023-08-31","date_modified_ts":"2023-08-31T16:06:11Z","date_created":"2023-08-31T16:03:51Z","summary":null,"body":["<article data-history-node-id=\"4528\" about=\"\/en\/alerts-advisories\/control-systems-ardereg-security-advisory-av23-517\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-517<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 31, 2023<\/p>\n\n<p>On August 31, 2023, CISA published an ICS advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>ARDEREG Sistemas SCADA \u2013 version 2.203 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-243-01\">ICS Advisory - ICSA-23-243-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ardereg-security-advisory-av23-517","alert_type":398,"serial_number":"AV23-517","subject":"other","moderation_state":"published","external_url":null},{"nid":4529,"title":"[Control systems] GE Digital security advisory (AV23-518)","uuid":"423e8991-0619-406e-a367-e0e85163afb4","banner":null,"lang":"en","date_modified":"2023-08-31","date_modified_ts":"2023-08-31T16:10:54Z","date_created":"2023-08-31T16:07:50Z","summary":null,"body":["<article data-history-node-id=\"4529\" about=\"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-518\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-518<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>August 31, 2023<\/p>\n\n<p>On August 31, 2023, CISA published an ICS advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>GE Digital CIMPLICITY \u2013 version v2023<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-243-02\">ICS Advisory - ICSA-23-243-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ge-digital-security-advisory-av23-518","alert_type":398,"serial_number":"AV23-518","subject":"other","moderation_state":"published","external_url":null},{"nid":4530,"title":"Ivanti security advisory (AV23-519)","uuid":"944cce0a-8f39-4e15-b493-4863339b5052","banner":null,"lang":"en","date_modified":"2023-08-31","date_modified_ts":"2023-08-31T19:00:01Z","date_created":"2023-08-31T18:56:13Z","summary":null,"body":["<article data-history-node-id=\"4530\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-519\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-519<br \/><strong>Date: <\/strong>August 31, 2023<\/p>\n\n<p>On August 31, 2023, Ivanti published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Ivanti Avalanche\u00a0\u2013 version 6.4.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Avalanche-CVE-2023-38036?language=en_US\">Ivanti Security Advisory - Avalanche CVE-2023-38036<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-519","alert_type":396,"serial_number":"AV23-519","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4531,"title":"Microsoft Edge security advisory (AV23-520)","uuid":"62ed7d4e-1ce8-42f7-b1a5-16dc9c364319","banner":null,"lang":"en","date_modified":"2023-09-01","date_modified_ts":"2023-09-01T13:44:14Z","date_created":"2023-09-01T13:36:01Z","summary":null,"body":["<article data-history-node-id=\"4531\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-520\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-520<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 1, 2023<\/p>\n\n<p>On August\u00a031,\u00a02023, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 116.0.1938.69<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-31-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-520","alert_type":396,"serial_number":"AV23-520","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4532,"title":"Dell security advisory (AV23-521)","uuid":"2538a581-b32d-45bb-ae92-34e17a0d80cb","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T13:58:08Z","date_created":"2023-09-05T13:53:27Z","summary":null,"body":["<article data-history-node-id=\"4532\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-521\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-521<br \/><strong>Date: <\/strong>September 5, 2023<\/p>\n\n<p>Between August 28 and September 3, 2023, Dell published security advisories to address vulnerabilities in a product. Included were updates for the following:<\/p>\n\n<ul><li>Dell ECS\u00a0\u2013 versions prior to 3.8.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000217202\/dsa-2023-298-security-update-for-dell-ecs-3-8-0-3-multiple-vulnerabilities\">Dell Security Update (Dell ECS)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-521","alert_type":396,"serial_number":"AV23-521","subject":"dell","moderation_state":"published","external_url":null},{"nid":4533,"title":"IBM security advisory (AV23-522)","uuid":"c0b28550-ed36-4b78-b55d-af9b9e006185","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T14:07:09Z","date_created":"2023-09-05T14:00:45Z","summary":null,"body":["<article data-history-node-id=\"4533\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-522\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-522<br \/><strong>Date: <\/strong>September 5, 2023<\/p>\n\n<p>Between August 28 and September 3, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Automation Assets in IBM Cloud Pak for Integration (CP4I)\u00a0\u2013 multiples versions;<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiples versions;<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps\u00a0\u2013 version 4.x;<\/li>\n\t<li>IBM i Modernization Engine for Lifecycle Integration\u00a0\u2013 version 1.0 to 1.4.3;<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 versions 8.1 and 8.9;<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- IoT Component\u00a0\u2013 multiples versions;<\/li>\n\t<li>IBM MQ Operator\u00a0\u2013 multiples versions;<\/li>\n\t<li>IBM Sterling External Authentication Server\u00a0\u2013 versions 6.0.3 and 6.1.0;<\/li>\n\t<li>IBM Storage Defender\u00a0- Data Protect\u00a0\u2013 version 1.0.0 to 1.2.0;<\/li>\n\t<li>IBM Storage Fusion IBM Storage Fusion HCI\u00a0\u2013 version 2.1.0 to 2.4.0;<\/li>\n\t<li>IBM supplied MQ Advanced container images\u00a0\u2013 multiples versions;<\/li>\n\t<li>ICP\u00a0- IBM Match 360\u00a0\u2013 version 4.7.0;<\/li>\n\t<li>Operations Dashboard\u00a0\u2013 multiples versions;<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (CP4I)\u00a0\u2013 multiples versions;<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-522","alert_type":396,"serial_number":"AV23-522","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4534,"title":"Ubuntu security advisory (AV23-523)","uuid":"ada2df57-c947-4a44-9125-c625f9f30669","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T14:11:35Z","date_created":"2023-09-05T14:08:38Z","summary":null,"body":["<article data-history-node-id=\"4534\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-523\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-523<\/p>\n\n<p><strong>Date: <\/strong>September 5, 2023<\/p>\n\n<p>Between August 28 and September 3, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-523","alert_type":396,"serial_number":"AV23-523","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4535,"title":"[Control systems] Fujitsu security advisory (AV23-524) ","uuid":"59c9bbe0-7302-4797-8633-233c896cf1f4","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T18:37:51Z","date_created":"2023-09-05T18:34:47Z","summary":null,"body":["<article data-history-node-id=\"4535\" about=\"\/en\/alerts-advisories\/control-systems-fujitsu-security-advisory-av23-524\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-524<br \/><strong>Date: <\/strong>September 5, 2023<\/p>\n\n<p>On September 5, 2023, ICS-CERT published a security advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Fujitsu Real-time Video Transmission Gear \u201cIP series\u201d \u2013 multiple products and multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-248-01\">ICS Advisory (ICSA-23-248-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fujitsu-security-advisory-av23-524","alert_type":398,"serial_number":"AV23-524","subject":null,"moderation_state":"published","external_url":null},{"nid":4536,"title":"[Control systems] Softneta security advisory (AV23-525) ","uuid":"ec6cb116-c12e-4469-8f23-a3df69feb8f6","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T18:41:04Z","date_created":"2023-09-05T18:38:30Z","summary":null,"body":["<article data-history-node-id=\"4536\" about=\"\/en\/alerts-advisories\/control-systems-softneta-security-advisory-av23-525\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-525<br \/><strong>Date: <\/strong>September 5, 2023<\/p>\n\n<p>On September 5, 2023, ICS-CERT published a security advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Softneta MedDream PACS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-248-01\">ICSMA Advisory (ICSMA-23-248-01)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-softneta-security-advisory-av23-525","alert_type":398,"serial_number":"AV23-525","subject":"other","moderation_state":"published","external_url":null},{"nid":4537,"title":"[Control systems] ABB security advisory (AV23-526)","uuid":"acaad3c2-d2a9-4d4d-b590-51db7e2a5acc","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T18:44:15Z","date_created":"2023-09-05T18:41:46Z","summary":null,"body":["<article data-history-node-id=\"4537\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-526\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-526<br \/><strong>Date: <\/strong>September 5, 2023<\/p>\n\n<p>On September 5, 2023, ICS-CERT published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB AC500 v3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011211&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Advisory (3ADR011211)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-526","alert_type":396,"serial_number":"AV23-526","subject":"other","moderation_state":"published","external_url":null},{"nid":4538,"title":"Google Chrome security advisory (AV23-527)","uuid":"6723941e-7d42-4d8d-9899-3c96391b6f28","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T18:58:25Z","date_created":"2023-09-05T18:53:11Z","summary":null,"body":["<article data-history-node-id=\"4538\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-527\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Date: <\/strong>September\u00a05, 2023<br \/><strong>Number: <\/strong>AV23-527<\/p>\n\n<p>On September\u00a05, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 116.0.5845.179\/.180 (Windows) and 116.0.5845.179 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"&#10;    https:\/\/chromereleases.googleblog.com\/2023\/09\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-527","alert_type":396,"serial_number":"AV23-527","subject":"other","moderation_state":"published","external_url":null},{"nid":4539,"title":"Android security advisory \u2013 August 2023 Monthly Rollup (AV23-528)","uuid":"254cd797-78c3-44fa-b4c9-ad6b6cc51229","banner":null,"lang":"en","date_modified":"2023-09-05","date_modified_ts":"2023-09-05T19:05:23Z","date_created":"2023-09-05T19:02:39Z","summary":null,"body":["<article data-history-node-id=\"4539\" about=\"\/en\/alerts-advisories\/android-security-advisory-august-2023-monthly-rollup-av23-528\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV23-528<br \/><strong>Date: <\/strong>September\u00a05, 2023<\/p>\n\n<p>On September\u00a05, 2023, Android published a Security Bulletin to address vulnerabilities in Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"&#10;    https:\/\/source.android.com\/docs\/security\/bulletin\/2023-09-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-august-2023-monthly-rollup-av23-528","alert_type":396,"serial_number":"AV23-528","subject":"android","moderation_state":"published","external_url":null},{"nid":4540,"title":"Cisco security advisory (AV23-529)","uuid":"2f0bc2c1-983b-4b74-9e0f-bc290de690d6","banner":null,"lang":"en","date_modified":"2023-09-06","date_modified_ts":"2023-09-06T17:51:04Z","date_created":"2023-09-06T17:46:21Z","summary":null,"body":["<article data-history-node-id=\"4540\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-529\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-529<br \/><strong>Date: <\/strong>September 6, 2023<\/p>\n\n<p>On September 6, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Cisco BroadWorks Application Delivery Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco BroadWorks Xtended Services Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco ISE PSNs\u00a0- versions 3.1 and 3.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-bw-auth-bypass-kCggMWhX\">Cisco Security Advisory\u00a0- cisco-sa-bw-auth-bypass-kCggMWhX<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-radius-dos-W7cNn7gt\">Cisco Security Advisory\u00a0- cisco-sa-ise-radius-dos-W7cNn7gt<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x \">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-529","alert_type":396,"serial_number":"AV23-529","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4541,"title":"HPE security advisory (AV23-530)","uuid":"7942180f-462d-4f11-80df-589f12ac440f","banner":null,"lang":"en","date_modified":"2023-09-07","date_modified_ts":"2023-09-07T14:21:22Z","date_created":"2023-09-07T14:17:20Z","summary":null,"body":["<article data-history-node-id=\"4541\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-530\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-530<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 7, 2023<\/p>\n\n<p>On September 7, 2023, HPE published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba 9200 and 9000 Series Controllers and Gateways \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04535en_us\">HPE Security Bulletin \u2013 hpesbnw04535en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-530","alert_type":396,"serial_number":"AV23-530","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4542,"title":"[Control systems] SOCOMEC security advisory (AV23-531)","uuid":"170b0448-a564-4c46-be4d-22398c09377a","banner":null,"lang":"en","date_modified":"2023-09-07","date_modified_ts":"2023-09-07T17:42:43Z","date_created":"2023-09-07T17:32:24Z","summary":null,"body":["<article data-history-node-id=\"4542\" about=\"\/en\/alerts-advisories\/control-systems-socomec-security-advisory-av23-531\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-531<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 7, 2023<\/p>\n\n<p>On September 7, 2023, ICS-CERT published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MOD3GP-SY-120K \u2013 Web firmware v01.12.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-250-03\">ICS Advisory (ICSA-23-250-03)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-socomec-security-advisory-av23-531","alert_type":396,"serial_number":"AV23-531","subject":"other","moderation_state":"published","external_url":null},{"nid":4543,"title":"[Control systems] Phoenix Contact security advisory (AV23-532)","uuid":"e127050c-bfe4-4698-afeb-41045f3357be","banner":null,"lang":"en","date_modified":"2023-09-07","date_modified_ts":"2023-09-07T17:50:55Z","date_created":"2023-09-07T17:46:49Z","summary":null,"body":["<article data-history-node-id=\"4543\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av23-532\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-532<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 7, 2023<\/p>\n\n<p>On September 7, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>TC ROUTER 3002T-4G \u2013 versions prior to 2.07.2<\/li>\n\t<li>TC ROUTER 3002T-4G ATT \u2013 versions prior to 2.07.2<\/li>\n\t<li>TC ROUTER 3002T-4G VZW \u2013 versions prior to 2.07.2<\/li>\n\t<li>TC CLOUD CLIENT 1002-4G \u2013 versions prior to 2.07.2<\/li>\n\t<li>TC CLOUD CLIENT 1002-4G ATT \u2013 versions prior to 2.07.2<\/li>\n\t<li>TC CLOUD CLIENT 1002-4G VZW \u2013 versions prior to 2.07.2<\/li>\n\t<li>CLOUD CLIENT 1101T-TX\/TX \u2013 versions prior to 2.06.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-250-02\">ICS Advisory (ICSA-23-250-02)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av23-532","alert_type":398,"serial_number":"AV23-532","subject":"other","moderation_state":"published","external_url":null},{"nid":4544,"title":"[Control systems] Dover Fueling Solutions security advisory (AV23-533)","uuid":"6bf980e7-f685-4f17-9c83-b82940558d70","banner":null,"lang":"en","date_modified":"2023-09-07","date_modified_ts":"2023-09-07T17:55:51Z","date_created":"2023-09-07T17:53:29Z","summary":null,"body":["<article data-history-node-id=\"4544\" about=\"\/en\/alerts-advisories\/control-systems-dover-fueling-solutions-security-advisory-av23-533\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-533<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 7, 2023<\/p>\n\n<p>On September 7, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MAGLINK LX Web Console Configuration \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\" https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-250-01\">ICS Advisory (ICSA-23-250-01)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-dover-fueling-solutions-security-advisory-av23-533","alert_type":398,"serial_number":"AV23-533","subject":"other","moderation_state":"published","external_url":null},{"nid":4545,"title":"Apple security advisory (AV23-534)","uuid":"8f44bb24-a7d6-4adb-884e-707dab8ec949","banner":null,"lang":"en","date_modified":"2023-09-07","date_modified_ts":"2023-09-07T19:19:11Z","date_created":"2023-09-07T19:14:52Z","summary":null,"body":["<article data-history-node-id=\"4545\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-534\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-534<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 7, 2023<\/p>\n\n<p>On September 7, 2023, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 16.6.1<\/li>\n\t<li>macOS Ventura \u2013 versions prior to 13.5.2<\/li>\n\t<li>watchOS \u2013 versions prior to 9.6.2<\/li>\n<\/ul><p>Apple has received reports that CVE-2023-41064 and CVE-2023-41061 have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-534","alert_type":396,"serial_number":"AV23-534","subject":"apple","moderation_state":"published","external_url":null},{"nid":4547,"title":"Ubuntu security advisory (AV23-535)","uuid":"b303a0d4-4e06-4438-873f-abc2d83d72b7","banner":null,"lang":"en","date_modified":"2023-09-11","date_modified_ts":"2023-09-11T15:24:58Z","date_created":"2023-09-11T15:14:56Z","summary":null,"body":["<article data-history-node-id=\"4547\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-535\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-535<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 11, 2023<\/p>\n\n<p>Between September\u00a04 and 10, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-535","alert_type":396,"serial_number":"AV23-535","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4548,"title":"Dell security advisory (AV23-536)","uuid":"5917b586-c879-4847-aa20-1b96823f72ec","banner":null,"lang":"en","date_modified":"2023-09-11","date_modified_ts":"2023-09-11T15:28:04Z","date_created":"2023-09-11T15:26:42Z","summary":null,"body":["<article data-history-node-id=\"4548\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-536\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-536<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 11, 2023<\/p>\n\n<p>Between September 4 and 10, 2023, Dell published security advisories to address vulnerabilities in a product. Included was an update for the following:<\/p>\n\n<ul><li>Dell NetWorker vProxy \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000217446\/dsa-2023-267-security-update-for-dell-networker-vproxy-gsoap-vulnerabilities\">Dell Security Update (dsa-2023-267)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-536","alert_type":396,"serial_number":"AV23-536","subject":"dell","moderation_state":"published","external_url":null},{"nid":4549,"title":"IBM security advisory (AV23-537)","uuid":"7bbe1604-cd76-4600-8370-6fb456f5ac1a","banner":null,"lang":"en","date_modified":"2023-09-11","date_modified_ts":"2023-09-11T15:32:43Z","date_created":"2023-09-11T15:29:37Z","summary":null,"body":["<article data-history-node-id=\"4549\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-537\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-537<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 11, 2023<\/p>\n\n<p>Between September 4 and 10, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Multicloud Management Monitoring\u00a0\u2013 versions 2.0 to 2.3 fix pack 6<\/li>\n\t<li>IBM Cloud Pak for Network Automation\u00a0\u2013 version 2.5<\/li>\n\t<li>Intelligent Operations Center (IOC)\u00a0\u2013 versions 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6, 5.2, 5.2.1, 5.2.2, 5.2.3 and 5.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-537","alert_type":396,"serial_number":"AV23-537","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4551,"title":"Apple security advisory (AV23-538)","uuid":"565c8d3f-e3f9-48b9-9b57-3dfd50b48c7d","banner":null,"lang":"en","date_modified":"2023-09-11","date_modified_ts":"2023-09-11T19:14:59Z","date_created":"2023-09-11T19:09:24Z","summary":null,"body":["<article data-history-node-id=\"4551\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-538\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-538<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 11, 2023<\/p>\n\n<p>On September 11, 2023, Apple published security updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 15.7.9<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.6.9<\/li>\n\t<li>macOS Big Sur \u2013 versions prior to 11.7.10<\/li>\n<\/ul><p>Apple has received reports that CVE-2023-41064 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-538","alert_type":396,"serial_number":"AV23-538","subject":"apple","moderation_state":"published","external_url":null},{"nid":4552,"title":"Foxit security advisory (AV23-539)","uuid":"cb9a6bc2-62a2-4497-b8da-3e3d63010f0b","banner":null,"lang":"en","date_modified":"2023-09-11","date_modified_ts":"2023-09-11T19:20:54Z","date_created":"2023-09-11T19:19:10Z","summary":null,"body":["<article data-history-node-id=\"4552\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av23-539\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-539<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 11, 2023<\/p>\n\n<p>On September 11, 2023, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor \u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader \u2013 version 12.1.3.15356 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av23-539","alert_type":396,"serial_number":"AV23-539","subject":"other","moderation_state":"published","external_url":null},{"nid":4553,"title":"Google Chrome security advisory (AV23-540)","uuid":"f23008fa-d652-4b7b-914d-1f8b76484e96","banner":null,"lang":"en","date_modified":"2023-09-11","date_modified_ts":"2023-09-11T19:36:47Z","date_created":"2023-09-11T19:33:10Z","summary":null,"body":["<article data-history-node-id=\"4553\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-540\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-540<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 11, 2023<\/p>\n\n<p>On September 11, 2023, Google published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 116.0.5845.187\/.188 (Windows) and 116.0.5845.187 (Linux and Mac)<\/li>\n<\/ul><p>Google has indicated that this vulnerability has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/09\/stable-channel-update-for-desktop_11.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-540","alert_type":396,"serial_number":"AV23-540","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4554,"title":"SAP security advisory \u2013 September 2023 monthly rollup (AV23-541)","uuid":"dbdea66b-bf27-4604-a65c-fe5146f7bc88","banner":null,"lang":"en","date_modified":"2023-09-12","date_modified_ts":"2023-09-12T13:41:42Z","date_created":"2023-09-12T13:30:49Z","summary":null,"body":["<article data-history-node-id=\"4554\" about=\"\/en\/alerts-advisories\/sap-security-advisory-september-2023-monthly-rollup-av23-541\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-541<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 12, 2023<\/p>\n\n<p>On September 12, 2023, SAP published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Business Intelligence Platform \u2013 versions 420 and 430<\/li>\n\t<li>SAP CommonCryptoLib \u2013 multiple products and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day \u2013 September 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-september-2023-monthly-rollup-av23-541","alert_type":396,"serial_number":"AV23-541","subject":"sap","moderation_state":"published","external_url":null},{"nid":4555,"title":"[Control systems] Siemens security advisory (AV23-542) ","uuid":"c9cb10db-9eb8-44a4-9314-2a2ed43a4c45","banner":null,"lang":"en","date_modified":"2023-09-12","date_modified_ts":"2023-09-12T13:49:01Z","date_created":"2023-09-12T13:44:27Z","summary":null,"body":["<article data-history-node-id=\"4555\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-542\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-542<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 12, 2023<\/p>\n\n<p>On September 12, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>PSSCAPE V14 \u2013 versions prior to V14.2023-08-23<\/li>\n\t<li>PSSCAPE V15 \u2013 versions prior to V15.0.22<\/li>\n\t<li>PSSE V34 \u2013 versions prior to V34.9.6<\/li>\n\t<li>PSSE V35 \u2013 all versions<\/li>\n\t<li>PSSODMS V13.0 \u2013 all versions<\/li>\n\t<li>PSSODMS V13.1 \u2013 versions prior to V13.1.12.1<\/li>\n\t<li>SIMATIC PCS neo V3 \u2013 all versions<\/li>\n\t<li>SIMATIC PCS neo V4 \u2013 all versions<\/li>\n\t<li>SIMATIC WinCC OA V3.17 \u2013 all versions<\/li>\n\t<li>SIMATIC WinCC OA V3.19 \u2013 versions prior to V3.19 P006<\/li>\n\t<li>SIMIT Simulation Platform \u2013 all versions<\/li>\n\t<li>SINEC INS \u2013 all versions<\/li>\n\t<li>SINEMA Remote Connect \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-240541.html\">Siemens Security Advisories - SSA-240541<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-542","alert_type":398,"serial_number":"AV23-542","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4556,"title":"[Control systems] Schneider Electric security advisory (AV23-543)","uuid":"1b0cd3d0-1673-4928-8741-7a179e57f964","banner":null,"lang":"en","date_modified":"2023-09-12","date_modified_ts":"2023-09-12T15:59:09Z","date_created":"2023-09-12T15:54:05Z","summary":null,"body":["<article data-history-node-id=\"4556\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-543\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-543<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 12, 2023<\/p>\n\n<p>On September 12, 2023, Schneider Electric published an advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>IGSS Dashboard Update Service (IGSSupdateservice.exe) \u2013 version v16.0.0.23211 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-255-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-255-01.pdf\">Schneider Electric Security Notification - SEVD-2023-255-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-543","alert_type":398,"serial_number":"AV23-543","subject":"other","moderation_state":"published","external_url":null},{"nid":4557,"title":"[Control systems] Hitachi Energy security advisory (AV23-544) ","uuid":"1ac71d55-9ebc-4d2f-a51d-e2daadc583ea","banner":null,"lang":"en","date_modified":"2023-09-12","date_modified_ts":"2023-09-12T18:01:02Z","date_created":"2023-09-12T17:55:32Z","summary":null,"body":["<article data-history-node-id=\"4557\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-544\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-544<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 12, 2023<\/p>\n\n<p>On September 12, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Lumada APM Edge \u2013 version 4.0 and prior<\/li>\n\t<li>Lumada APM Edge \u2013 version 6.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-255-01 \">ICS Advisory - ICSA-23-255-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-544","alert_type":398,"serial_number":"AV23-544","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4558,"title":"Fujitsu security advisory (AV23-545)","uuid":"dc4281af-571d-46bb-b11c-f028b43461d4","banner":null,"lang":"en","date_modified":"2023-09-12","date_modified_ts":"2023-09-12T18:04:13Z","date_created":"2023-09-12T18:02:27Z","summary":null,"body":["<article data-history-node-id=\"4558\" about=\"\/en\/alerts-advisories\/fujitsu-security-advisory-av23-545\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-545<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 12, 2023<\/p>\n\n<p>On September 12, 2023, CISA published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Infrastructure Manager \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-255-02\">ICS Advisory - ICSA-23-255-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fujitsu-security-advisory-av23-545","alert_type":398,"serial_number":"AV23-545","subject":"other","moderation_state":"published","external_url":null},{"nid":4559,"title":"Adobe security advisory (AV23-546)","uuid":"c5a60ddf-e7d9-4fb7-987d-6d348f62a81e","banner":null,"lang":"en","date_modified":"2023-09-12","date_modified_ts":"2023-09-12T18:42:58Z","date_created":"2023-09-12T18:34:13Z","summary":null,"body":["<article data-history-node-id=\"4559\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-546\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-546<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 12, 2023<\/p>\n\n<p>On September 12, 2023, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><\/ul><ul><li>Acrobat DC\u00a0and Reader DC \u2013 version 23.003.20284 and prior<\/li>\n\t<li>Acrobat 2020 and Reader 2020 \u2013 version 20.005.30516 (Mac) and 20.005.30514 (Windows) and prior<\/li>\n<\/ul><p>Adobe has indicated that CVE-2023-26369 has been actively exploited.\u00a0<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb23-34.html\">Adobe Security Advisory - APSB23-34<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-546","alert_type":396,"serial_number":"AV23-546","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4560,"title":"Microsoft security advisory \u2013 September 2023 monthly rollup (AV23-547)","uuid":"62b2d895-bec5-40f0-ab75-7e8872f30714","banner":null,"lang":"en","date_modified":"2023-09-12","date_modified_ts":"2023-09-12T18:49:18Z","date_created":"2023-09-12T18:44:02Z","summary":null,"body":["<article data-history-node-id=\"4560\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2023-monthly-rollup-av23-547\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-547<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 12, 2023<\/p>\n\n<p>On September 12, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Azure Kubernetes Service<\/li>\n\t<li>Microsoft Visual Studio \u2013 multiple versions and platforms<\/li>\n\t<li>.NET 7.0 and 6.0<\/li>\n\t<li>Windows 10 \u2013 multiple platforms<\/li>\n\t<li>Windows 11 \u2013 multiple platforms<\/li>\n<\/ul><p>Windows Server 2022 Microsoft has indicated that CVE-2023-36802 and CVE-2023-36761 have been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Sep\">September 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2023-monthly-rollup-av23-547","alert_type":396,"serial_number":"AV23-546","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4562,"title":"Microsoft Edge security advisory (AV23-548)","uuid":"e837b25f-0129-438d-9805-99d62e6aebd0","banner":null,"lang":"en","date_modified":"2023-09-13","date_modified_ts":"2023-09-13T15:53:33Z","date_created":"2023-09-13T15:50:24Z","summary":null,"body":["<article data-history-node-id=\"4562\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-548\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-548<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 13, 2023<\/p>\n\n<p>On September 12, 2023, Microsoft published a security update to address a vulnerability in the following products:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 116.0.1938.81<\/li>\n\t<li>Microsoft Edge Stable Channel \u2013 versions prior to 116.0.1938.81<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2023-4863 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-12-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-548","alert_type":396,"serial_number":"AV23-548","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4563,"title":"Google Chrome security advisory (AV23-549)","uuid":"56d3b776-56ad-449a-ac01-a46f6e89a8dc","banner":null,"lang":"en","date_modified":"2023-09-13","date_modified_ts":"2023-09-13T15:58:17Z","date_created":"2023-09-13T15:55:07Z","summary":null,"body":["<article data-history-node-id=\"4563\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-549\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-549<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 13, 2023<\/p>\n\n<p>On September 12, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 117.0.5938.62\/.63 (Windows) and 117.0.5938.62 (Linux and Mac)<\/li>\n<\/ul><p>Google has indicated that CVE-2023-4863 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/09\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-549","alert_type":396,"serial_number":"AV23-549","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4564,"title":"Mozilla security advisory (AV23-550)","uuid":"89ed3cbb-8fd1-4779-9148-8d6fefa4e4fc","banner":null,"lang":"en","date_modified":"2023-09-13","date_modified_ts":"2023-09-13T16:19:00Z","date_created":"2023-09-13T16:08:34Z","summary":null,"body":["<article data-history-node-id=\"4564\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-550\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-550<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September\u00a013, 2023<\/p>\n\n<p>On September\u00a012, 2023, Mozilla published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 117.0.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.2.1 and 102.15.1<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 115.2.2 and 102.15.1<\/li>\n<\/ul><p>Mozilla has indicated that CVE-2023-4863 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-40\/\">Mozilla Security Advisory\u00a0- MFSA 2023-40<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-550","alert_type":396,"serial_number":"AV23-550","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4565,"title":"Fortinet security advisory (AV23-551)","uuid":"6d358cc6-b58f-415c-9433-208461725e7c","banner":null,"lang":"en","date_modified":"2023-09-13","date_modified_ts":"2023-09-13T16:25:28Z","date_created":"2023-09-13T16:08:34Z","summary":null,"body":["<article data-history-node-id=\"4565\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-551\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-551<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September\u00a013, 2023<\/p>\n\n<p>On September\u00a013, 2023, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiADC\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiOS\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiProxy\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiWeb\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-551","alert_type":396,"serial_number":"AV23-551","subject":"other","moderation_state":"published","external_url":null},{"nid":4566,"title":"Red Hat security advisory (AV23-552)","uuid":"c82ff4aa-65db-4394-9f78-b4fa59f56566","banner":null,"lang":"en","date_modified":"2023-09-13","date_modified_ts":"2023-09-13T16:37:51Z","date_created":"2023-09-13T16:08:35Z","summary":null,"body":["<article data-history-node-id=\"4566\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-552\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-552<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September\u00a013, 2023<\/p>\n\n<p>On September\u00a012, 2023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux for Real Time 9 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time for NFV 9 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:5091\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:5091<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-552","alert_type":396,"serial_number":"AV23-552","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4575,"title":"Palo Alto Networks security advisory (AV22-553)","uuid":"030651b7-7105-4163-bdb3-eb06071d70ad","banner":null,"lang":"en","date_modified":"2023-09-14","date_modified_ts":"2023-09-14T13:50:47Z","date_created":"2023-09-14T13:43:47Z","summary":null,"body":["<article data-history-node-id=\"4575\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-553\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-553\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 14, 2023\n<\/p>\n<p>On September 13, 2023, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:\n<\/p>\n<ul><li>PAN-OS 0\u00a0\u2013 versions prior to 11.0.3<\/li>\n  <li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.6<\/li>\n  <li>PAN-OS 10.1\u00a0\u2013 versions prior to 10.1.11<\/li>\n  <li>PAN-OS 9.1\u00a0\u2013 version 9.1.16 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2023-38802\">Palo Alto Networks Security Advisory\u00a0- CVE-2023-38802<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av22-553","alert_type":396,"serial_number":"AV23-553","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":4577,"title":"[Control systems] Siemens security advisory (AV23-554)","uuid":"0baa3fb4-83d5-491a-a6a4-36ee50fddf2c","banner":null,"lang":"en","date_modified":"2023-09-14","date_modified_ts":"2023-09-14T15:18:46Z","date_created":"2023-09-14T15:15:57Z","summary":null,"body":["<article data-history-node-id=\"4577\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-554\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-554<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 14, 2023<\/p>\n\n<p>On September 14, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>Spectrum Power 7\u00a0\u2013 versions prior to V23Q3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-357182.html\">Siemens Security Advisories - SSA-357182<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SiemensSecurityAdvisories\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-554","alert_type":398,"serial_number":"AV23-554","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4578,"title":"[Control systems] Rockwell Automation security advisory (AV23-555) ","uuid":"5c2c5e1b-160f-4c7d-96f2-f19a799967ae","banner":null,"lang":"en","date_modified":"2023-09-14","date_modified_ts":"2023-09-14T17:42:12Z","date_created":"2023-09-14T17:39:00Z","summary":null,"body":["<article data-history-node-id=\"4578\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-555\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-555<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 14, 2023<\/p>\n\n<p>On September 14, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Pavilion8 \u2013 versions v5.17.00 and v5.17.01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-257-07\">ICS Advisory - ICSA-23-257-07<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-555","alert_type":398,"serial_number":"AV23-555","subject":"other","moderation_state":"published","external_url":null},{"nid":4579,"title":"HPE security advisory (AV23-556)","uuid":"1fd591f7-4fd1-4cbb-b688-2bff410ffa3d","banner":null,"lang":"en","date_modified":"2023-09-14","date_modified_ts":"2023-09-14T17:45:49Z","date_created":"2023-09-14T17:43:52Z","summary":null,"body":["<article data-history-node-id=\"4579\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-556\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-556<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 14, 2023<\/p>\n\n<p>On September 14, 2023, HPE published a security bulletin to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE OneView \u2013 versions prior to v8.30.01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-257-07\">HPE Security Bulletin \u2013 hpesbgn04538en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-556","alert_type":396,"serial_number":"AV23-556","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4580,"title":"Drupal security advisory (AV23-557)","uuid":"687de1cb-01e4-4589-9f10-cf78d25614c0","banner":null,"lang":"en","date_modified":"2023-09-14","date_modified_ts":"2023-09-14T18:16:20Z","date_created":"2023-09-14T18:13:51Z","summary":null,"body":["<article data-history-node-id=\"4580\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av23-557\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-557<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 14, 2023<\/p>\n\n<p>On September 13, 2023, Drupal published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Mail Login\u00a0\u2013 versions prior to 8.x-2.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2023-045\">Drupal Security Advisory - SA-CONTRIB-2023-045<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av23-557","alert_type":396,"serial_number":"AV23-557","subject":"drupal","moderation_state":"published","external_url":null},{"nid":4582,"title":"Distributed Denial of Service campaign targeting multiple Canadian sectors","uuid":"dcab58b4-37c0-4de0-b52c-5405d0120232","banner":null,"lang":"en","date_modified":"2023-09-15","date_modified_ts":"2023-09-15T14:41:02Z","date_created":"2023-09-15T14:39:21Z","summary":null,"body":["<article data-history-node-id=\"4582\" about=\"\/en\/alerts-advisories\/distributed-denial-service-campaign-targeting-multiple-canadian-sectors\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-014<br \/><strong>Date:\u00a0<\/strong>September 15,\u00a02023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>Since 13 September 2023, the Cyber Centre has been aware and responding to reports of several distributed denial of service (DDoS) campaigns targeting multiple levels within the Government of Canada, as well as the financial and transportation sectors.<\/p>\n\n<p>This Alert is being published to raise awareness of these campaigns, to highlight the potential impact to government services and to provide guidance for organizations who may be targeted by malicious activity. \u00a0Open-source reporting links some of this activity to Russian state-sponsored cyber threat actors whose tactics, techniques and procedures have been extensively documented <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. In July 2022, the Cyber Centre assessed that Russian state-sponsored cyber threat actors would almost certainly continue to perform actions in support of the Russian military's strategic and tactical objectives in Ukraine <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. On February 24, 2023, the Cyber Centre reported on similar activity involving DDoS campaigns towards Ukraine-aligned nations <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>Open-source reporting indicates that the actors leverage denial of service tools to harass organizations <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>. This is accomplished through a collection of systems operating as a botnet that degrades a targeted web server's ability to provide services. This degradation is then publicized by the actors. In most cases, this nuisance activity can be managed by on-premises solutions; however, assistance from third party DDoS solutions should be considered to prevent significant and focused malicious activity. Websites will commonly return to a normal state of operation once the actors have stopped the malicious activity.<\/p>\n<\/section><section><h2>Suggested action<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Review perimeter systems to determine if related activity has occurred.<\/li>\n\t<li>Review and implement preventative actions outlined within the Cyber Centre's guidance on protecting your organization against denial-of-service attacks <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/li>\n\t<li>Review the Cybersecurity and Infrastructure Security Agency (CISA) published guidance for US agencies to aid in DDoS considerations including technical mitigation recommendations in responding to DDOS activity<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.team-cymru.com\/post\/a-blog-with-noname\/\">A Blog with NoName<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/falconfeeds.io\/blog\/post\/inside-the-world-of-noname05716-unmasking-the-notorious-ddos-hackers-607894 \">Unmasking the Notorious DDoS Hackers<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/cyber-threat-bulletin-cyber-threat-activity-related-russian-invasion-ukraine\">Cyber threat bulletin: Cyber threat activity related to the Russian invasion of Ukraine<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/risk-malicious-cyber-activity-against-ukraine-aligned-nations\">Risk of malicious cyber activity against Ukraine-aligned nations<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/decoded.avast.io\/martinchlumecky\/ddosia-project\/\">DDosia Project<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\">Protecting your organization against denial-of-service attacks - ITSAP.80.100<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-09\/TLP%20CLEAR%20-DDOS%20Mitigations%20Guidance_508c.pdf\">Capacity Enhancement Guide: Volumetric Ddos Technical Guidance For Fceb Agencies (PDF)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">CCCS Top 10 IT security actions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/distributed-denial-service-campaign-targeting-multiple-canadian-sectors","alert_type":397,"serial_number":"AL23-014","subject":"other","moderation_state":"published","external_url":null},{"nid":4584,"title":"Ubuntu security advisory (AV23-558)","uuid":"67b078e8-7638-4b6b-98d3-69e02a136dca","banner":null,"lang":"en","date_modified":"2023-09-18","date_modified_ts":"2023-09-18T17:17:46Z","date_created":"2023-09-18T17:14:46Z","summary":null,"body":["<article data-history-node-id=\"4584\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-558\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-558<br \/><strong>Date: <\/strong>September 18, 2023<\/p>\n\n<p>Between September 11 and 17, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-558","alert_type":396,"serial_number":"AV23-558","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4585,"title":"Dell security advisory (AV23-559)","uuid":"7592c767-1341-42a0-b46d-2569416b32b8","banner":null,"lang":"en","date_modified":"2023-09-18","date_modified_ts":"2023-09-18T17:23:16Z","date_created":"2023-09-18T17:20:02Z","summary":null,"body":["<article data-history-node-id=\"4585\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-559\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-559<br \/><strong>Date: <\/strong>September 18, 2023<\/p>\n\n<p>Between September 11 and 17, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Dell Streaming Data Platform\u00a0\u2013 versions 1.1.x to 1.7.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000217490\/dsa-2023-303-security-update-for-dell-streaming-data-platform\">Dell Security Update (dsa-2023-303)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-559","alert_type":396,"serial_number":"AV23-559","subject":"dell","moderation_state":"published","external_url":null},{"nid":4586,"title":"IBM security advisory (AV23-560)","uuid":"6516630a-abb1-4067-8d59-e7f2e2d454c7","banner":null,"lang":"en","date_modified":"2023-09-18","date_modified_ts":"2023-09-18T17:28:20Z","date_created":"2023-09-18T17:24:52Z","summary":null,"body":["<article data-history-node-id=\"4586\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-560\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-560<br \/><strong>Date: <\/strong>September 18, 2023<\/p>\n\n<p>Between September 11 and 17, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cloud Pak for Security (CP4S)\u00a0\u2013 version 1.10.0.0 to 1.10.14.0<\/li>\n\t<li>IBM App Connect Enterprise\u00a0\u2013 version 12.0.1.0 to 12.0.9.0<\/li>\n\t<li>IBM CICS TX Advanced\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM Cloud APM, Advanced Private\u00a0\u2013 version 8.1.4<\/li>\n\t<li>IBM Cloud APM, Base Private\u00a0\u2013 version 8.1.4<\/li>\n\t<li>IBM Cloud Pak for Multicloud Management Monitoring\u00a0\u2013 version 2.0 to 2.3 FP6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-560","alert_type":396,"serial_number":"AV23-560","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4587,"title":"Microsoft Edge security advisory (AV23-561)","uuid":"f20483bb-abb3-431c-94c2-aa4a6fba0dce","banner":null,"lang":"en","date_modified":"2023-09-18","date_modified_ts":"2023-09-18T19:27:21Z","date_created":"2023-09-18T19:26:02Z","summary":null,"body":["<article data-history-node-id=\"4587\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-561\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-561<br \/><strong>Date: <\/strong>September 18, 2023<\/p>\n\n<p>On September 15, 2023, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 109.0.1518.140<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2023-4863 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-15-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-561","alert_type":396,"serial_number":"AV23-561","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4588,"title":"GitLab security advisory (AV23-562)","uuid":"03f90104-c9da-4cd2-91a3-49f3ad250043","banner":null,"lang":"en","date_modified":"2023-09-19","date_modified_ts":"2023-09-19T17:24:47Z","date_created":"2023-09-19T17:22:20Z","summary":null,"body":["<article data-history-node-id=\"4588\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-562\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-562<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 19, 2023<\/p>\n\n<p>On September 18, 2023, GitLab published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/09\/18\/security-release-gitlab-16-3-4-released\/\">GitLab Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-562","alert_type":396,"serial_number":"AV23-562","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4589,"title":"Foxit security advisory (AV23-563)","uuid":"7927b4ac-4520-4ecf-96fd-bae37d1d0638","banner":null,"lang":"en","date_modified":"2023-09-19","date_modified_ts":"2023-09-19T18:29:15Z","date_created":"2023-09-19T18:26:06Z","summary":null,"body":["<article data-history-node-id=\"4589\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av23-563\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-563<br \/><strong>Date: <\/strong>September 19, 2023<\/p>\n\n<p>On September 19, 2023, Foxit published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Foxit PDF Editor for Mac\u00a0\u2013 version 11.1.4.1121 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletinsx<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av23-563","alert_type":396,"serial_number":"AV23-563","subject":null,"moderation_state":"published","external_url":null},{"nid":4590,"title":"[Control systems] Omron security advisory (AV23-564)","uuid":"9bec72e8-e687-431f-98ff-04ff8b5ca2bd","banner":null,"lang":"en","date_modified":"2023-09-19","date_modified_ts":"2023-09-19T18:34:46Z","date_created":"2023-09-19T18:30:29Z","summary":null,"body":["<article data-history-node-id=\"4590\" about=\"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av23-564\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-564<br \/><strong>Date: <\/strong>September 19, 2023<\/p>\n\n<p>On September 19, 2023, CISA published ICS security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Sysmac CJ\/CS\/CP Series PLC\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Sysmac Studio\u00a0\u2013 version 1.54 and prior<\/li>\n\t<li>NX-IO Configurator\u00a0\u2013 version 1.22 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-262-03\">ICS Advisory\u00a0- ICSA-23-262-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-262-04\">ICS Advisory\u00a0- ICSA-23-262-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-262-05\">ICS Advisory\u00a0- ICSA-23-262-05<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-omron-security-advisory-av23-564","alert_type":398,"serial_number":"AV23-564","subject":"other","moderation_state":"published","external_url":null},{"nid":4591,"title":"[Control systems] Siemens security advisory (AV23-565) ","uuid":"f408a69e-1de3-40a8-ae53-f1445636808f","banner":null,"lang":"en","date_modified":"2023-09-20","date_modified_ts":"2023-09-20T11:37:30Z","date_created":"2023-09-20T11:33:54Z","summary":null,"body":["<article data-history-node-id=\"4591\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-565\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-565<br \/><strong>Date: <\/strong>September 20, 2023<\/p>\n\n<p>On September 19, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SIMATIC PCS neo Administration Console\u00a0\u2013 versions 4.0 and 4.0 Update 1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-262-01\">ICS Advisory\u00a0- ICSA-23-262-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-565","alert_type":398,"serial_number":"AV23-565","subject":"other","moderation_state":"published","external_url":null},{"nid":4592,"title":"Atlassian security advisory (AV23-566)","uuid":"732fb393-96ee-43c9-9dbc-5a3a62f2ae2a","banner":null,"lang":"en","date_modified":"2023-09-20","date_modified_ts":"2023-09-20T17:20:48Z","date_created":"2023-09-20T17:16:18Z","summary":null,"body":["<article data-history-node-id=\"4592\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-566\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-566<br \/><strong>Date: <\/strong>September 20, 2023<\/p>\n\n<p>On September 19, 2023, Atlassian published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Server and Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Server and Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server and Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Server and Data Center\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-september-19-2023-1283691616.html\">Atlassian Security Bulletin\u00a0- September 19 2023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-566","alert_type":396,"serial_number":"AV23-566","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4593,"title":"Apple security advisory (AV23-567)","uuid":"29003484-f8d1-47ea-bc96-b69182aa7ce4","banner":null,"lang":"en","date_modified":"2023-09-20","date_modified_ts":"2023-09-20T17:25:39Z","date_created":"2023-09-20T17:22:14Z","summary":null,"body":["<article data-history-node-id=\"4593\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-567\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-567<br \/><strong>Date: <\/strong>September 20, 2023<\/p>\n\n<p>On September 18, 2023, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 17<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 17<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-567","alert_type":396,"serial_number":"AV23-567","subject":"apple","moderation_state":"published","external_url":null},{"nid":4594,"title":"Red Hat security advisory (AV23-568)","uuid":"aeba5d4c-6b7e-45b1-a5ec-bb9c7b5b6e07","banner":null,"lang":"en","date_modified":"2023-09-20","date_modified_ts":"2023-09-20T17:30:32Z","date_created":"2023-09-20T17:26:52Z","summary":null,"body":["<article data-history-node-id=\"4594\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-568\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-568<br \/><strong>Date: <\/strong>September 20, 2023<\/p>\n\n<p>On September 19, 2023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:5244\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:5244<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-568","alert_type":396,"serial_number":"AV23-568","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4595,"title":"Drupal security advisory (AV23-569)","uuid":"7b5701b1-fb8b-41c2-9106-d4b0a4907f75","banner":null,"lang":"en","date_modified":"2023-09-20","date_modified_ts":"2023-09-20T18:37:26Z","date_created":"2023-09-20T18:32:37Z","summary":null,"body":["<article data-history-node-id=\"4595\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av23-569\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-569<br \/><strong>Date: <\/strong>September 20, 2023<\/p>\n\n<p>On September 20, 2023, Drupal published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Drupal core\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-core-2023-006\">Drupal Security Advisory\u00a0- SA-CORE-2023-006<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av23-569","alert_type":396,"serial_number":"AV23-569","subject":"drupal","moderation_state":"published","external_url":null},{"nid":4597,"title":"[Control systems] Rockwell Automation security advisory (AV23-570) ","uuid":"48495ae4-5d6b-4430-b9a7-9bdd4f3fe7c6","banner":null,"lang":"en","date_modified":"2023-09-21","date_modified_ts":"2023-09-21T19:13:49Z","date_created":"2023-09-21T19:08:46Z","summary":null,"body":["<article data-history-node-id=\"4597\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-570\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-570<br \/><strong>Date: <\/strong>September 21, 2023<\/p>\n\n<p>On September 21, 2023, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Connected Components Workbench\u00a0\u2013 versions prior to R21<\/li>\n\t<li>FactoryTalk View Machine Edition\u00a0\u2013 versions 13.0 and 12.0 and prior<\/li>\n\t<li>Logix Communication Modules\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-264-04\">ICS Advisory\u00a0- ICSA-23-264-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-264-05\">ICS Advisory\u00a0- ICSA-23-264-05<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-264-06\">ICS Advisory\u00a0- ICSA-23-264-06<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-570","alert_type":398,"serial_number":"AV23-570","subject":"other","moderation_state":"published","external_url":null},{"nid":4598,"title":"[Control systems] Siemens security advisory (AV23-571) ","uuid":"34786668-b45a-4436-b225-a8ff33e07137","banner":null,"lang":"en","date_modified":"2023-09-21","date_modified_ts":"2023-09-21T19:18:02Z","date_created":"2023-09-21T19:15:14Z","summary":null,"body":["<article data-history-node-id=\"4598\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-571\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-571<br \/><strong>Date: <\/strong>September 21, 2023<\/p>\n\n<p>On September 21, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Spectrum Power 7\u00a0\u2013 versions prior to V23Q3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-264-02\">ICS Advisory\u00a0- ICSA-23-264-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-571","alert_type":398,"serial_number":"AV23-571","subject":"other","moderation_state":"published","external_url":null},{"nid":4599,"title":"[Control systems] Siemens security advisory (AV23-572)","uuid":"13e30fd2-105d-43a2-98cb-c9a5e4982c47","banner":null,"lang":"en","date_modified":"2023-09-21","date_modified_ts":"2023-09-21T19:24:10Z","date_created":"2023-09-21T19:20:17Z","summary":null,"body":["<article data-history-node-id=\"4599\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-572\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-572<br \/><strong>Date: <\/strong>September 21, 2023<\/p>\n\n<p>On September 21, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>460 Series\u00a0\u2013 versions prior to v8.9.8<\/li>\n<\/ul><p>CISA has indicated it is aware that public exploit code exists for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-264-01\">ICS Advisory\u00a0- ICSA-23-264-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-572","alert_type":398,"serial_number":"AV23-572","subject":"other","moderation_state":"published","external_url":null},{"nid":4600,"title":"[Control systems] Delta Electronics security advisory (AV23-573)","uuid":"996892d7-d725-4ef3-b0f5-4851d81b51a7","banner":null,"lang":"en","date_modified":"2023-09-21","date_modified_ts":"2023-09-21T19:28:28Z","date_created":"2023-09-21T19:25:30Z","summary":null,"body":["<article data-history-node-id=\"4600\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-573\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-573<br \/><strong>Date: <\/strong>September 21, 2023<\/p>\n\n<p>On September 21, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>DIAScreen\u00a0\u2013 versions prior to v1.3.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-264-03\">ICS Advisory\u00a0- ICSA-23-264-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-573","alert_type":398,"serial_number":"AV23-573","subject":"other","moderation_state":"published","external_url":null},{"nid":4601,"title":"Apple security advisory (AV23-574)","uuid":"4a604c8b-eb51-4c18-9e9d-30559ec44f1d","banner":null,"lang":"en","date_modified":"2023-09-22","date_modified_ts":"2023-09-22T11:32:12Z","date_created":"2023-09-22T11:27:17Z","summary":null,"body":["<article data-history-node-id=\"4601\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-574\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-574<br \/><strong>Date: <\/strong>September 22, 2023<\/p>\n\n<p>On September 21, 2023, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 17.0.1<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 16.7<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 16.6.1<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.6<\/li>\n\t<li>macOS Monterey\u00a0\u2013 versions prior to 12.7<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 10.0.1<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 9.6.3<\/li>\n<\/ul><p>Apple has received reports that CVE-2023-41991, CVE-2023-41992 and CVE-2023-41993 have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222 \">Apple security updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-574","alert_type":396,"serial_number":"AV23-574","subject":"apple","moderation_state":"published","external_url":null},{"nid":4602,"title":"Dell security advisory (AV23-575)","uuid":"de969167-242f-4443-9466-921af5008bc2","banner":null,"lang":"en","date_modified":"2023-09-25","date_modified_ts":"2023-09-25T15:51:34Z","date_created":"2023-09-25T15:47:18Z","summary":null,"body":["<article data-history-node-id=\"4602\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-575\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-575<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 25, 2023<\/p>\n\n<p>Between September\u00a018\u00a0and\u00a024, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Dell Secure Connect Gateway \u2013 versions 5.12.00.10, 5.14.00.16 and 5.16.00.14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000217814\/dsa-2023-305-security-update-for-dell-secure-connect-gateway-multiple-third-party-component-vulnerabilities\">Dell Security Update - dsa-2023-305<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-575","alert_type":396,"serial_number":"AV23-575","subject":"dell","moderation_state":"published","external_url":null},{"nid":4603,"title":"Ubuntu security advisory (AV23-576)","uuid":"98ee67fa-dedf-4a6b-9ae1-18e0a7504acd","banner":null,"lang":"en","date_modified":"2023-09-25","date_modified_ts":"2023-09-25T15:55:08Z","date_created":"2023-09-25T15:52:46Z","summary":null,"body":["<article data-history-node-id=\"4603\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-576\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-576<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 25, 2023<\/p>\n\n<p>Between September\u00a018\u00a0and\u00a024, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04\u00a0ESM<\/li>\n\t<li>Ubuntu 20.04\u00a0LTS<\/li>\n\t<li>Ubuntu 22.04\u00a0LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-576","alert_type":396,"serial_number":"AV23-576","subject":"dell","moderation_state":"published","external_url":null},{"nid":4604,"title":"Mozilla security advisory (AV23-577)","uuid":"c2574131-0da9-4e42-8ef7-031692fe70be","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T14:16:12Z","date_created":"2023-09-26T14:11:52Z","summary":null,"body":["<article data-history-node-id=\"4604\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-577\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-577<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 26, 2023, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 118<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-41\/ \">Mozilla Security Advisory\u00a0- MFSA 2023-41<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-42\/ \">Mozilla Security Advisory\u00a0- MFSA 2023-42<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/ \">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-577","alert_type":396,"serial_number":"AV23-577","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4605,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-578)","uuid":"c2b86c80-35c4-4353-ad44-9c8439868147","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T18:00:23Z","date_created":"2023-09-26T17:56:15Z","summary":null,"body":["<article data-history-node-id=\"4605\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-578\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-578<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 26, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>GX Works3\u00a0- all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-269-03\">ICS Advisory\u00a0- ICSA-23-269-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-578","alert_type":398,"serial_number":"AV23-578","subject":"other","moderation_state":"published","external_url":null},{"nid":4606,"title":"[Control systems] Hitachi Energy security advisory (AV23-579) ","uuid":"6d5cbdbb-4310-4fa7-ab68-90f5669487c9","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T18:07:12Z","date_created":"2023-09-26T18:02:28Z","summary":null,"body":["<article data-history-node-id=\"4606\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-579\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-579<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 26, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Asset Suite\u00a0- versions 9.6.3.11.1 and prior<\/li>\n\t<li>Asset Suite\u00a0- version 9.6.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-269-02\">ICS Advisory\u00a0- ICSA-23-269-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-579","alert_type":398,"serial_number":"AV23-579","subject":"other","moderation_state":"published","external_url":null},{"nid":4607,"title":"[Control systems] Advantech security advisory (AV23-580) ","uuid":"5b5e2e86-ecff-4884-9128-35bf6aeea5d8","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T18:12:00Z","date_created":"2023-09-26T18:08:37Z","summary":null,"body":["<article data-history-node-id=\"4607\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-580\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-580<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 26, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EKI-1521-CE series\u00a0- versions 1.24 and prior<\/li>\n\t<li>EKI-1522-CE series\u00a0- versions 1.24 and prior<\/li>\n\t<li>EKI-1524-CE series\u00a0- versions 1.24 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-269-04\">ICS Advisory (ICSA-23-269-04)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-580","alert_type":398,"serial_number":"AV23-580","subject":"other","moderation_state":"published","external_url":null},{"nid":4608,"title":"[Control systems] Suprema Inc. security advisory (AV23-581) ","uuid":"39a57958-df01-4d6f-bcc1-bad3fe8f8620","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T18:15:50Z","date_created":"2023-09-26T18:13:18Z","summary":null,"body":["<article data-history-node-id=\"4608\" about=\"\/en\/alerts-advisories\/control-systems-suprema-inc-security-advisory-av23-581\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-581<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 26, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>BioStar 2\u00a0- version 2.8.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-269-01\">ICS Advisory - ICSA-23-269-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-suprema-inc-security-advisory-av23-581","alert_type":398,"serial_number":"AV23-581","subject":"other","moderation_state":"published","external_url":null},{"nid":4609,"title":"[Control systems] Bently Nevada security advisory (AV23-582)","uuid":"bf287f91-d79c-4605-a394-1e4d077d97e0","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T18:20:02Z","date_created":"2023-09-26T18:17:24Z","summary":null,"body":["<article data-history-node-id=\"4609\" about=\"\/en\/alerts-advisories\/control-systems-bently-nevada-security-advisory-av23-582\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-582<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 26, 2023, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Bently Nevada 3500 Rack (TDI Firmware)\u00a0- version 5.05<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-269-05\">ICS Advisory\u00a0- ICSA-23-269-05<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-bently-nevada-security-advisory-av23-582","alert_type":398,"serial_number":"AV23-582","subject":"other","moderation_state":"published","external_url":null},{"nid":4610,"title":"Apple security advisory (AV23-583)","uuid":"7eb129d9-bae5-4d12-86a2-0f99fdea34e7","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T19:20:50Z","date_created":"2023-09-26T19:17:08Z","summary":null,"body":["<article data-history-node-id=\"4610\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-583\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-583<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 26, 2023, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Sonoma\u00a0\u2013 versions prior to 14 (Sonoma)<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 17<\/li>\n\t<li>iOS\u00a0\u2013 versions prior to 17.0.2<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 17.0.2<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 10.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Apple has received reports that CVE-2023-41993 has been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT213940\">Apple Security Update- HT213940<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-583","alert_type":396,"serial_number":"AV23-583","subject":"apple","moderation_state":"published","external_url":null},{"nid":4611,"title":"Google security advisory (AV23-584)","uuid":"f812dc30-a463-4975-a79a-b0a080ea1f79","banner":null,"lang":"en","date_modified":"2023-09-26","date_modified_ts":"2023-09-26T19:29:15Z","date_created":"2023-09-26T19:24:38Z","summary":null,"body":["<article data-history-node-id=\"4611\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-584\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-584<br \/><strong>Date: <\/strong>September 26, 2023<\/p>\n\n<p>On September 25, 2023, Google published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>libwebp\u00a0\u2013 version 0.5.0 to versions prior to 1.3.2<\/li>\n<\/ul><p>Google has indicated that CVE-2023-5129 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-5129\">CVE\u00a0- CVE-2023-5129<\/a><\/li>\n\t<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/google-assigns-new-maximum-rated-cve-to-libwebp-bug-exploited-in-attacks\/ \">BleepingComputer\u00a0- Google assigns new maximum rated CVE to libwebp bug exploited in attacks<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-584","alert_type":396,"serial_number":"AV23-584","subject":"other","moderation_state":"published","external_url":null},{"nid":4612,"title":"Cisco security advisory (AV23-586)","uuid":"312d92cb-be29-43ed-87a9-6b6b79a92083","banner":null,"lang":"en","date_modified":"2023-09-27","date_modified_ts":"2023-09-27T17:31:17Z","date_created":"2023-09-27T17:28:03Z","summary":null,"body":["<article data-history-node-id=\"4612\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-586\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-586<br \/><strong>Date: <\/strong>September 27, 2023<\/p>\n\n<p>On September 27, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following product:<\/p>\n\n<ul><li>Cisco Catalyst SD-WAN Manager\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-vman-sc-LRLfu2z\">Cisco Security Advisory\u00a0- Cisco Catalyst SD-WAN Manager Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x \">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-586","alert_type":396,"serial_number":"AV23-586","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4614,"title":"Mozilla security advisory (AV23-587)","uuid":"89f14cec-ee79-4efd-a7a8-29d6ffa72a52","banner":null,"lang":"en","date_modified":"2023-09-28","date_modified_ts":"2023-09-28T14:01:11Z","date_created":"2023-09-28T13:57:51Z","summary":null,"body":["<article data-history-node-id=\"4614\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-587\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-587<br \/><strong>Date: <\/strong>September 28, 2023<\/p>\n\n<p>On September 28, 2023, Mozilla published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox 118.0.1<\/li>\n\t<li>Firefox ESR 115.3.1<\/li>\n\t<li>Firefox Focus for Android 118.1<\/li>\n\t<li>Firefox for Android 118.1<\/li>\n<\/ul><p>Mozilla is aware that CVE-2023-5217 has been exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-44\/ \">Mozilla Security Advisory\u00a0- MFSA 2023-44<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/ \">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-587","alert_type":396,"serial_number":"AV23-587","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4615,"title":"Google Chrome security advisory (AV23-588)","uuid":"97e3fead-0636-4edf-aecd-3eddc708de5f","banner":null,"lang":"en","date_modified":"2023-09-28","date_modified_ts":"2023-09-28T14:06:46Z","date_created":"2023-09-28T14:03:04Z","summary":null,"body":["<article data-history-node-id=\"4615\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-588\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-588<br \/><strong>Date: <\/strong>September 28, 2023<\/p>\n\n<p>On September 28, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 117.0.5938.132 (Windows, Linux and Mac)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2023-5217 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/09\/stable-channel-update-for-desktop_27.html \">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-588","alert_type":396,"serial_number":"AV23-588","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4616,"title":"[Control systems] Rockwell automation security advisory (AV23-590)","uuid":"aeaa6a96-c8d2-447a-a6c4-729223a198c6","banner":null,"lang":"en","date_modified":"2023-09-28","date_modified_ts":"2023-09-28T18:14:12Z","date_created":"2023-09-28T18:10:22Z","summary":null,"body":["<article data-history-node-id=\"4616\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-590\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-590<br \/><strong>Date: <\/strong>September 28, 2023<\/p>\n\n<p>On September 28, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>PanelView 800 2711R-T10T\u00a0\u2013 version 3.011 to versions prior to 6.011<\/li>\n\t<li>PanelView 800 2711R-T7T\u00a0\u2013 version 3.011 to versions prior to 6.011<\/li>\n\t<li>PanelView 800 2711R-T4T\u00a0\u2013 version 3.011 to versions prior to 6.011<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-271-01\">ICS Advisory\u00a0- ICSA-23-271-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-590","alert_type":398,"serial_number":"AV23-590","subject":"other","moderation_state":"published","external_url":null},{"nid":4618,"title":"GitLab security advisory (AV23-591)","uuid":"7c5341eb-9278-4e24-ada9-14674bd88a00","banner":null,"lang":"en","date_modified":"2023-09-29","date_modified_ts":"2023-09-29T12:05:22Z","date_created":"2023-09-29T12:02:46Z","summary":null,"body":["<article data-history-node-id=\"4618\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-591\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-591<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 28, 2023<\/p>\n\n<p>On September 28, 2023, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/09\/28\/security-release-gitlab-16-4-1-released\/\">GitLab Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-591","alert_type":396,"serial_number":"AV23-591","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4623,"title":"Progress security advisory (AV23-592)","uuid":"59385e5b-afd3-4e74-874f-009d60386cf8","banner":null,"lang":"en","date_modified":"2023-09-29","date_modified_ts":"2023-09-29T15:57:07Z","date_created":"2023-09-29T15:46:45Z","summary":null,"body":["<article data-history-node-id=\"4623\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av23-592\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-592<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 29, 2023<\/p>\n\n<p>On September\u00a027,\u00a02023, Progress published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>WS_FTP Server 2020 \u2013 versions prior to 8.7.4<\/li>\n\t<li>WS_FTP Server 2022 \u2013 versions prior to 8.8.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/WS-FTP-Server-Critical-Vulnerability-September-2023\">WS_FTP Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av23-592","alert_type":396,"serial_number":"AV23-592","subject":"other","moderation_state":"published","external_url":null},{"nid":4625,"title":"Android security advisory \u2013 October 2023 monthly rollup (AV23-593)","uuid":"f7997283-0f74-4e99-be79-0049e83adc7e","banner":null,"lang":"en","date_modified":"2023-10-03","date_modified_ts":"2023-10-03T17:47:49Z","date_created":"2023-10-03T17:44:44Z","summary":null,"body":["<article data-history-node-id=\"4625\" about=\"\/en\/alerts-advisories\/android-security-advisory-october-2023-monthly-rollup-av23-593\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-593<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>September 3, 2023<\/p>\n\n<p>On October\u00a02, 2023, Android published a security bulletin to address vulnerabilities affecting Android devices.:<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-10-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-october-2023-monthly-rollup-av23-593","alert_type":396,"serial_number":"AV23-593","subject":"android","moderation_state":"published","external_url":null},{"nid":4626,"title":"Dell security advisory (AV23-594)","uuid":"25dacdda-f189-4ce5-ba07-f4a8c4b3bd88","banner":null,"lang":"en","date_modified":"2023-10-03","date_modified_ts":"2023-10-03T17:52:21Z","date_created":"2023-10-03T17:49:15Z","summary":null,"body":["<article data-history-node-id=\"4626\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-594\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-594<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 3, 2023<\/p>\n\n<p>Between September 25 and October 1, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen5a \u2013 firmware versions prior to 2.18.1<\/li>\n\t<li>Dell Container Storage Modules \u2013 versions prior to 1.8<\/li>\n\t<li>Dell Metro Node VS5 \u2013 versions prior to 8.0.0, BIOS versions prior to 2.17.1, iDRAC versions prior to 6.10.30.20 and NIC versions prior to 21.5.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218008\/dsa-2023-114-security-update-for-dell-avamar-data-store-gen5a-vulnerabilities\">Dell Security Update - dsa-2023-114<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218111\/dsa-2023-372-dell-container-storage-modules-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Update - dsa-2023-372<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000217979\/dsa-2023-281-security-update-for-dell-emc-vplex-metro-node-multiple-third-party-component-vulnerabilities\">Dell Security Update - dsa-2023-281<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-594","alert_type":396,"serial_number":"AV23-594","subject":"android","moderation_state":"published","external_url":null},{"nid":4627,"title":"Ubuntu security advisory (AV23-595)","uuid":"fb77cd0f-39a1-4609-b2c8-7a650ee2f9a7","banner":null,"lang":"en","date_modified":"2023-10-03","date_modified_ts":"2023-10-03T18:04:55Z","date_created":"2023-10-03T18:01:44Z","summary":null,"body":["<article data-history-node-id=\"4627\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-595\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-595<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 3, 2023<\/p>\n\n<p>Between September 25 and October 1, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-595","alert_type":396,"serial_number":"AV23-595","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4628,"title":"Exim security advisory (AV23-596)","uuid":"e92183a9-667b-4f87-8999-6f4680bb4a6a","banner":null,"lang":"en","date_modified":"2023-10-03","date_modified_ts":"2023-10-03T19:44:25Z","date_created":"2023-10-03T19:42:40Z","summary":null,"body":["<article data-history-node-id=\"4628\" about=\"\/en\/alerts-advisories\/exim-security-advisory-av23-596\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-596<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 3, 2023<\/p>\n\n<p>On October\u00a03, 2023, Exim published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Exim Internet Mailer \u2013 versions prior to 4.96.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.exim.org\/static\/doc\/security\/CVE-2023-zdi.txt\">Exim Security Update - CVE-2023-zdi<\/a><\/li>\n\t<li><a href=\"https:\/\/www.exim.org\/\">Exim Internet Mailer<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-av23-596","alert_type":396,"serial_number":"AV23-596","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4629,"title":"IBM security advisory (AV23-597)","uuid":"b2218826-6688-4522-afd3-d318842efb4d","banner":null,"lang":"en","date_modified":"2023-10-04","date_modified_ts":"2023-10-04T15:09:37Z","date_created":"2023-10-04T14:57:26Z","summary":null,"body":["<article data-history-node-id=\"4629\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-597\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-597<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a04, 2023<\/p>\n\n<p>Between September\u00a025 and October\u00a01, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud APM, Advanced Private\u00a0\u2013 version 8.1.4<\/li>\n\t<li>IBM Cloud APM, Base Private\u00a0\u2013 version 8.1.4<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps\u00a0\u2013 version 4.0.0 to 4.1.2<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 versions 2.3.1.0, 2.3.2.0 (Intel), 2.3.0.1 and 2.3.3.0 to 2.3.3.6 (Intel)<\/li>\n\t<li>IBM Cloud Pak System Software Suite\u00a0\u2013 version 2.3.3.0 to 2.3.3.6 (Intel)<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 versions 11.1.x, 11.2.x and 12.0<\/li>\n\t<li>IBM Disconnected Log Collector\u00a0\u2013 version v1.0 to v1.8.2<\/li>\n\t<li>IBM Storage Protect Server\u00a0\u2013 version 8.1<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 4.7.2<\/li>\n\t<li>Transport Module Common Integration Library\u00a0\u2013 versions common-transportmodule-29_0 to common-transportmodule-37_0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-597","alert_type":396,"serial_number":"AV23-597","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4630,"title":"Google Chrome security advisory (AV23-598)","uuid":"ceb9c326-872f-42a4-bc53-3ff020872d89","banner":null,"lang":"en","date_modified":"2023-10-04","date_modified_ts":"2023-10-04T15:42:39Z","date_created":"2023-10-04T14:57:27Z","summary":null,"body":["<article data-history-node-id=\"4630\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-598\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-598<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a04, 2023<\/p>\n\n<p>On October\u00a03, 2023, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 117.0.5938.149 (Linux and Mac) and 117.0.5938.149\/.150 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/10\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-598","alert_type":396,"serial_number":"AV23-598","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4631,"title":"Cisco security advisory (AV23-599)","uuid":"54df46a8-766f-4d19-b085-0e4ef1bacc52","banner":null,"lang":"en","date_modified":"2023-10-04","date_modified_ts":"2023-10-04T19:50:52Z","date_created":"2023-10-04T19:44:44Z","summary":null,"body":["<article data-history-node-id=\"4631\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-599\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-599<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 4, 2023<\/p>\n\n<p>On October 4, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following product:<\/p>\n\n<ul><li>Cisco Emergency Responder\u00a0\u2013 version 12.5(1)SU4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cer-priv-esc-B9t3hqk9\">Cisco Security Advisory - cisco-sa-cer-priv-esc-B9t3hqk9<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-599","alert_type":396,"serial_number":"AV23-599","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4633,"title":"Red Hat security advisory (AV23-600)","uuid":"57f770f2-fd4f-4878-8034-033beb70bc9c","banner":null,"lang":"en","date_modified":"2023-10-04","date_modified_ts":"2023-10-04T20:17:05Z","date_created":"2023-10-04T20:13:54Z","summary":null,"body":["<article data-history-node-id=\"4633\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-600\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-600<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 4, 2023<\/p>\n\n<p>On October 3, 2023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server \u2013 versions AUS 7.6 x86_64 and AUS 7.7 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:5414\">Red Hat Security Advisory \u2013 RHSA-2023:5414<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:5419\">Red Hat Security Advisory \u2013 RHSA-2023:5419<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-600","alert_type":396,"serial_number":"AV23-600","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4634,"title":"Apple security advisory (AV23-601)","uuid":"403cf663-ebb3-40a2-a704-4aa2df6c81d9","banner":null,"lang":"en","date_modified":"2023-10-04","date_modified_ts":"2023-10-04T20:36:47Z","date_created":"2023-10-04T20:32:12Z","summary":null,"body":["<article data-history-node-id=\"4634\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-601\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-601<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 4, 2023<\/p>\n\n<p>On October 4, 2023, Apple published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 versions prior to 17.0.3<\/li>\n\t<li>iPadOS \u2013 versions prior to 17.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Apple has received reports that CVE-2023- 42824 has been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213961\">Apple Security Update - HT213961<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-601","alert_type":396,"serial_number":"AV23-601","subject":"apple","moderation_state":"published","external_url":null},{"nid":4635,"title":"Atlassian security advisory (AV23-602)","uuid":"add1b6b5-784a-4fa1-b35b-39c17d34ecaf","banner":null,"lang":"en","date_modified":"2023-10-05","date_modified_ts":"2023-10-05T13:46:00Z","date_created":"2023-10-05T13:30:30Z","summary":null,"body":["<article data-history-node-id=\"4635\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-602\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-602<br \/><strong>Date: <\/strong>October 5, 2023<\/p>\n\n<p>On October 4, 2023, Atlassian published a security bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>Confluence Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Atlassian has received reports that CVE-2023- 22515 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html\">Atlassian Security Bulletin - CVE-2023-22515<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-602","alert_type":396,"serial_number":"AV23-602","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4636,"title":"Microsoft Edge security advisory (AV23-603)","uuid":"c23e640b-5717-4a6f-bece-fac41a6f4bc1","banner":null,"lang":"en","date_modified":"2023-10-05","date_modified_ts":"2023-10-05T20:13:19Z","date_created":"2023-10-05T20:10:43Z","summary":null,"body":["<article data-history-node-id=\"4636\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-603\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-603<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 5, 2023<\/p>\n\n<p>On October 4, 2023, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 117.0.2045.55<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-4-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-603","alert_type":396,"serial_number":"AV23-603","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4637,"title":"SonicWall security advisory (AV23-604)","uuid":"0f7ea2a5-6370-4327-af93-2fb2dc960800","banner":null,"lang":"en","date_modified":"2023-10-05","date_modified_ts":"2023-10-05T20:18:41Z","date_created":"2023-10-05T20:15:19Z","summary":null,"body":["<article data-history-node-id=\"4637\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-604\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-604<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 5, 2023<\/p>\n\n<p>On September 29, 2023, SonicWall published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>NetExtender Windows (32 and 64 bit)\u00a0\u2013 versions 10.2.336 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2023-0013\">SonicWall Security Advisory \u2013 SNWLID-2023-0013<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2023-0014\">SonicWall Security Advisory \u2013 SNWLID-2023-0014<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-604","alert_type":396,"serial_number":"AV23-604","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":4638,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-605)","uuid":"7a99d837-38a7-41a5-92eb-be12f7a69548","banner":null,"lang":"en","date_modified":"2023-10-05","date_modified_ts":"2023-10-05T20:23:32Z","date_created":"2023-10-05T20:20:41Z","summary":null,"body":["<article data-history-node-id=\"4638\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-605\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-605<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 5, 2023<\/p>\n\n<p>On October 5, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CC-Link IE TSN Industrial Managed Switch model NZ2MHG-TSNT8F2\u00a0\u2013 all versions<\/li>\n\t<li>CC-Link IE TSN Industrial Managed Switch model NZ2MHG-TSNT4\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-278-03 \">ICS Advisory - ICSA-23-278-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-605","alert_type":398,"serial_number":"AV23-605","subject":"other","moderation_state":"published","external_url":null},{"nid":4639,"title":"[Control systems] Hitachi security advisory (AV23-606)","uuid":"aedf0e3e-9509-4b91-8943-8926ac9b334a","banner":null,"lang":"en","date_modified":"2023-10-05","date_modified_ts":"2023-10-05T20:28:33Z","date_created":"2023-10-05T20:25:35Z","summary":null,"body":["<article data-history-node-id=\"4639\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-security-advisory-av23-606\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-606<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 5, 2023<\/p>\n\n<p>On October 5, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AFF66X FW\u00a0\u2013 version 03.0.02 and prior<\/li>\n\t<li>AFS66X-S\u00a0\u2013 all versions<\/li>\n\t<li>AFS660-C\u00a0\u2013 all versions<\/li>\n\t<li>AFS66X-B\u00a0\u2013 all versions<\/li>\n\t<li>AFS670-V20\u00a0\u2013 all versions<\/li>\n\t<li>AFS65X\u00a0\u2013 all versions<\/li>\n\t<li>AFS67X\u00a0\u2013 all versions<\/li>\n\t<li>AFR677\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-278-01\">ICS Advisory - ICSA-23-278-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-security-advisory-av23-606","alert_type":398,"serial_number":"AV23-606","subject":"other","moderation_state":"published","external_url":null},{"nid":4640,"title":"[Control systems] Qognify security advisory (AV23-607)","uuid":"c05f885d-ec5d-46af-b7d7-56e08d0dd410","banner":null,"lang":"en","date_modified":"2023-10-05","date_modified_ts":"2023-10-05T20:33:44Z","date_created":"2023-10-05T20:31:48Z","summary":null,"body":["<article data-history-node-id=\"4640\" about=\"\/en\/alerts-advisories\/control-systems-qognify-security-advisory-av23-607\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-607<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 5, 2023<\/p>\n\n<p>On October 5, 2023, CISA published an ICS advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>NiceVision \u2013 version 3.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-278-02\">ICS Advisory - ICSA-23-278-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-qognify-security-advisory-av23-607","alert_type":398,"serial_number":"AV23-607","subject":"other","moderation_state":"published","external_url":null},{"nid":4641,"title":"Drupal security advisory (AV23-608)","uuid":"be752241-f7a0-48c7-b8f6-f745b52c7fae","banner":null,"lang":"en","date_modified":"2023-10-06","date_modified_ts":"2023-10-06T18:54:45Z","date_created":"2023-10-06T18:52:35Z","summary":null,"body":["<article data-history-node-id=\"4641\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av23-608\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong> AV23-608<br \/><strong>Date: <\/strong>October 6, 2023<\/p>\n\n<p>On October 4, 2023, Drupal published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Mail Login\u00a0\u2013 versions prior to 8.x-2.9<\/span><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2023-048\">Drupal Security Advisory\u00a0- SA-CONTRIB-2023-048<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av23-608","alert_type":396,"serial_number":"AV23-608","subject":"drupal","moderation_state":"published","external_url":null},{"nid":4643,"title":"Dell security advisory (AV23-609)","uuid":"d6f7d2d2-7f80-4fb9-b82e-064332b8b97c","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T17:48:55Z","date_created":"2023-10-10T17:45:42Z","summary":null,"body":["<article data-history-node-id=\"4643\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-609\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-609<br \/><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>Between October 2 and 8, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell PowerStore\u00a0\u2013 multiple versions and models.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218046\/dsa-2023-366-dell-powerstore-family-security-update-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-366<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-609","alert_type":396,"serial_number":"AV23-609","subject":"dell","moderation_state":"published","external_url":null},{"nid":4644,"title":"IBM security advisory (AV23-610)","uuid":"98665713-71f5-4a38-b4d7-cd572b535166","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T17:54:12Z","date_created":"2023-10-10T17:50:08Z","summary":null,"body":["<article data-history-node-id=\"4644\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-610\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-610<br \/><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>Between October 2 and October 8, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Network Automation\u00a0\u2013 version 2.x<\/li>\n\t<li>IBM Cloud Transformation Advisor\u00a0\u2013 version 2.0.1 to 3.6.2<\/li>\n\t<li>IBM Db2\u00a0\u2013 version 11.5.x<\/li>\n\t<li>IBM Security Verify Governance\u00a0\u2013 versions 10.0 and 10.0.2<\/li>\n\t<li>IBM Sterling Order Management\u00a0\u2013 version 10.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-610","alert_type":396,"serial_number":"AV23-610","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4645,"title":"Ubuntu security advisory (AV23-611)","uuid":"025338af-d247-449f-b46c-12838e90d166","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T17:58:40Z","date_created":"2023-10-10T17:55:42Z","summary":null,"body":["<article data-history-node-id=\"4645\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-611\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-611<br \/><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>Between October 2 and October 8, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-611","alert_type":396,"serial_number":"AV23-611","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4646,"title":"[Control systems] Schneider Electric security advisory (AV23-612)","uuid":"82ac1215-1773-4b1d-b0f4-ac6ab927e2bc","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T20:01:12Z","date_created":"2023-10-10T19:54:40Z","summary":null,"body":["<article data-history-node-id=\"4646\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-612\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-612<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>On October 10, 2023, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Power Monitoring Expert (PME)\u00a0- versions prior to Hotfix-145271<\/li>\n\t<li>EcoStruxure Power Operation (EPO) with Advanced Reports\u00a0- versions prior to Hotfix-145271<\/li>\n\t<li>EcoStruxure Power SCADA\u00a0- versions prior to Hotfix-145271<\/li>\n\t<li>SpaceLogic C-Bus Toolkit\u00a0- version 1.16.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-283-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-283-01.pdf\">Schneider Electric Security Notification - SEVD-2023-283-01 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-283-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-283-02.pdf\">Schneider Electric Security Notification - SEVD-2023-283-02 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-612","alert_type":398,"serial_number":"AV23-612","subject":"other","moderation_state":"published","external_url":null},{"nid":4647,"title":"SAP security advisory \u2013 October 2023 monthly rollup (AV23-613)","uuid":"757a9c04-e406-4a24-9ad5-340d732d6b8c","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T20:06:59Z","date_created":"2023-10-10T20:02:17Z","summary":null,"body":["<article data-history-node-id=\"4647\" about=\"\/en\/alerts-advisories\/sap-security-advisory-october-2023-monthly-rollup-av23-613\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-613<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>On October 10, 2023, SAP published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>SAP Business Client\u00a0\u2013 versions 6.5, 7.0 and 7.70<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day \u2013 October 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-october-2023-monthly-rollup-av23-613","alert_type":396,"serial_number":"AV23-613","subject":"sap","moderation_state":"published","external_url":null},{"nid":4648,"title":"Citrix security advisory (AV23-614)","uuid":"cc3e42a0-22f1-4b80-9d44-f026a724257c","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T20:13:24Z","date_created":"2023-10-10T20:08:58Z","summary":null,"body":["<article data-history-node-id=\"4648\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av23-614\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-614<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>On October 10, 2023, Citrix published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway\u202f14.1\u00a0\u2013 versions prior to 14.1-8.50<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.1\u00a0\u2013 versions prior to 13.1-49.15<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.0\u00a0\u2013 versions prior to 13.0-92.19<\/li>\n\t<li>NetScaler ADC 13.1-FIPS\u00a0\u2013 versions prior to 13.1-37.164<\/li>\n\t<li>NetScaler ADC 12.1-FIPS\u00a0\u2013 versions prior to 12.1-55.300<\/li>\n\t<li>NetScaler ADC 12.1-NDcPP\u00a0\u2013 versions prior to 12.1-55.300<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX579459\/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967\">Citrix Security Advisory - CTX579459<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center\/search#\/All%20Products?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av23-614","alert_type":396,"serial_number":"AV23-614","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4649,"title":"Microsoft security advisory \u2013 October 2023 monthly rollup (AV23-615)","uuid":"75165cee-361a-41e0-9afd-41baddd8baaf","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T20:19:23Z","date_created":"2023-10-10T20:15:41Z","summary":null,"body":["<article data-history-node-id=\"4649\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2023-monthly-rollup-av23-615\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-615<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>On October 10, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Windows 10 \u2013 multiple platforms<\/li>\n\t<li>Windows 11 \u2013 multiple platforms<\/li>\n\t<li>Windows Server \u2013 multiple platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-44487, CVE-2023-36563 and CVE-2023-41763 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Oct\">October 2023 release notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security update guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-october-2023-monthly-rollup-av23-615","alert_type":396,"serial_number":"AV23-615","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4650,"title":"Fortinet security advisory (AV23-616)","uuid":"23f22204-069c-4823-8d45-63a7842b05ad","banner":null,"lang":"en","date_modified":"2023-10-10","date_modified_ts":"2023-10-10T20:29:20Z","date_created":"2023-10-10T20:25:01Z","summary":null,"body":["<article data-history-node-id=\"4650\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-616\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-616<br \/><strong>Date: <\/strong>October 10, 2023<\/p>\n\n<p>On October 10, 2023, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiSIEM\u00a0\u2013 multiples versions<\/li>\n\t<li>FortiWLM 8.6\u00a0\u2013 version 8.6.0 to 8.6.5<\/li>\n\t<li>FortiWLM 8.5\u00a0\u2013 version 8.5.0 to 8.5.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-130\">Fortinet PSIRT Advisory FG-IR-23-130<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-140\">Fortinet PSIRT Advisory FG-IR-23-140<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-085\">Fortinet PSIRT Advisory FG-IR-23-085<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-616","alert_type":396,"serial_number":"AV23-616","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":4651,"title":"Vulnerability impacting HTTP\/2 - Rapid Reset","uuid":"7309d676-23f8-4e8c-87be-5775b631a0af","banner":null,"lang":"en","date_modified":"2023-10-11","date_modified_ts":"2023-10-11T14:44:26Z","date_created":"2023-10-11T14:29:20Z","summary":null,"body":["<article data-history-node-id=\"4651\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-http2-rapid-reset\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-015\n  <br \/><strong>Date:\u00a0<\/strong>October 11, 2023\n<\/p>\n<section><h2>Audience\n  <\/h2>\n  <p>This Alert is intended for IT professionals and managers.\n  <\/p>\n<\/section><section><h2>Purpose\n  <\/h2>\n  <p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.\n  <\/p>\n<\/section><section><h2>Details\n  <\/h2>\n  <p>The Cyber Centre is aware of industry research<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> regarding a recent vulnerability<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> impacting HTTP\/2, a version of the HTTP protocol most commonly used for webservers. Vulnerability CVE-2023-44487 leverages a flaw in HTTP\/2 which results in an overload of a targeted web server with malformed requests, leading to a denial of service. Open source has reported that this vulnerability has been exploited in the wild.<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n  <p>On October 10, 2023, Microsoft published an article on the activity and has published patches for impacted systems.<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/p>\n  <p>This Alert is being published to raise awareness of CVE-2023-44487, to highlight the potential impact to organizations and to provide guidance for organizations who may be targeted by related malicious activity.\n  <\/p>\n<\/section><section><h2>Suggested action\n  <\/h2>\n  <p>The Cyber Centre recommends organizations:\n  <\/p>\n  <ul><li>Immediately patch affected systems when updates addressing this vulnerability become available.<\/li>\n    <li>Enable web application firewall (WAF) rate limiting rules.<sup id=\"fn5a-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n    <li>Restrict internet access to your web applications based upon known malicious IP addresses or geographic location, where possible.<sup id=\"fn5b-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n    <li>Review and implement preventative actions outlined within the Cyber Centre\u2019s guidance on protecting your organization against denial-of-service attacks.<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/li>\n    <li>Review the Cybersecurity and Infrastructure Security Agency (CISA) published guidance for US agencies to aid in DDoS considerations including technical mitigation recommendations in responding to DDoS activity.<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><\/li>\n    <li>Review industry research for additional recommendations.<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/li>\n  <\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> with an emphasis on the following topics:\n  <\/p>\n  <ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n    <li>Isolate web-facing applications<\/li>\n  <\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.\n  <\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References\n  <\/h2>\n  <dl><dt>Footnote 1\n    <\/dt>\n    <dd id=\"fn1\">\n      <p><a href=\"https:\/\/blog.cloudflare.com\/technical-breakdown-http2-rapid-reset-ddos-attack\/\">HTTP\/2 Rapid Reset: deconstructing the record-breaking attack<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 2\n    <\/dt>\n    <dd id=\"fn2\">\n      <p><a href=\"https:\/\/cloud.google.com\/blog\/products\/identity-security\/how-it-works-the-novel-http2-rapid-reset-ddos-attack?hl=en\">How it works: The novel HTTP\/2 \u2018Rapid Reset\u2019 DDoS attack<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 3\n    <\/dt>\n    <dd id=\"fn3\">\n      <p><a href=\"https:\/\/aws.amazon.com\/fr\/blogs\/security\/how-aws-protects-customers-from-ddos-events\/\">How AWS protects customers from DDoS events<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 4\n    <\/dt>\n    <dd id=\"fn4\">\n      <p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-44487\">CVE-2023-44487<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 5\n    <\/dt>\n    <dd id=\"fn5\">\n      <p><a href=\"https:\/\/msrc.microsoft.com\/blog\/2023\/10\/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http\/2\/ \">Microsoft Response to Distributed Denial of Service (DDoS) Attacks against HTTP\/2<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 6\n    <\/dt>\n    <dd id=\"fn6\">\n      <p><a href=\"\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\">Protecting your organization against denial-of-service attacks\u00a0- ITSAP.80.100<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 7\n    <\/dt>\n    <dd id=\"fn7\">\n      <p><a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-09\/TLP%20CLEAR%20-DDOS%20Mitigations%20Guidance_508c.pdf\">Capacity Enhancement Guide: Volumetric Ddos Technical Guidance For Fceb Agencies (PDF)<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n    <dt>Footnote 8\n    <\/dt>\n    <dd id=\"fn8\">\n      <p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">CCCS Top 10 IT security actions<\/a>\n      <\/p>\n      <p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a>\n      <\/p>\n    <\/dd>\n  <\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-http2-rapid-reset","alert_type":397,"serial_number":"AL23-015","subject":"other","moderation_state":"published","external_url":null},{"nid":4652,"title":"Apple security advisory (AV23-617)","uuid":"4f75cdcc-280c-4087-9df9-e8a7959945b7","banner":null,"lang":"en","date_modified":"2023-10-11","date_modified_ts":"2023-10-11T17:30:18Z","date_created":"2023-10-11T17:03:43Z","summary":null,"body":["<article data-history-node-id=\"4652\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-617\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-617<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a011, 2023<\/p>\n\n<p>On October\u00a010, 2023, Apple published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 16.7.1<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 16.7.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Apple has received reports that CVE-2023-42824 has been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT213972\">Apple Security Update\u00a0- HT213972<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-617","alert_type":396,"serial_number":"AV23-617","subject":"apple","moderation_state":"published","external_url":null},{"nid":4653,"title":"Adobe security advisory (AV23-618)","uuid":"2a71a780-1c61-4a63-8091-073e823813a3","banner":null,"lang":"en","date_modified":"2023-10-11","date_modified_ts":"2023-10-11T17:41:50Z","date_created":"2023-10-11T17:03:44Z","summary":null,"body":["<article data-history-node-id=\"4653\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-618\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-618<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a011, 2023<\/p>\n\n<p>On October\u00a010, 2023, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Bridge\u00a0\u2013 version 12.0.4 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 13.0.3 and prior<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n\t<li>Photoshop 2022\u00a0\u2013 version 23.5.5 and prior<\/li>\n\t<li>Photoshop 2023\u00a0\u2013 version 24.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb23-49.html\">Adobe Security Advisory\u00a0- APSB23-49<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb23-50.html\">Adobe Security Advisory\u00a0\u2013 APSB23-50<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/photoshop\/apsb23-51.html\">Adobe Security Advisory\u00a0\u2013 APSB23-51<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-618","alert_type":396,"serial_number":"AV23-618","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4654,"title":"Google Chrome security advisory (AV23-619)","uuid":"6c703495-6119-458d-9de3-dcba5a33bc69","banner":null,"lang":"en","date_modified":"2023-10-11","date_modified_ts":"2023-10-11T17:47:48Z","date_created":"2023-10-11T17:03:44Z","summary":null,"body":["<article data-history-node-id=\"4654\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-619\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-619<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a011, 2023<\/p>\n\n<p>On October\u00a010, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 118.0.5993.70 (Linux and Mac) and 118.0.5993.70\/.71 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/10\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-619","alert_type":396,"serial_number":"AV23-619","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4655,"title":"[Control systems] Siemens security advisory (AV23-620)","uuid":"c5861d2f-a7b7-4925-81d0-69ab2b1b2ebe","banner":null,"lang":"en","date_modified":"2023-10-11","date_modified_ts":"2023-10-11T20:15:49Z","date_created":"2023-10-11T20:07:09Z","summary":null,"body":["<article data-history-node-id=\"4655\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-620\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-620<br \/><strong>Date: <\/strong>October\u00a011, 2023<\/p>\n\n<p>On October\u00a010, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0) \u2013 versions prior to V8.10.0.6<\/li>\n\t<li>SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0) \u2013 versions prior to V8.10.0.6<\/li>\n\t<li>SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0) \u2013 versions prior to V8.10.0.6<\/li>\n\t<li>Simcenter Amesim \u2013 versions prior to V2021.1<\/li>\n\t<li>SINEC NMS \u2013 versions prior to v2.0<\/li>\n\t<li>SICAM PAS\/PQS \u2013 version v8.00 to v8.22<\/li>\n\t<li>CP-8031 MASTER MODULE (6MF2803-1AA00) \u2013 versions prior to CPCI85 V05.11<\/li>\n\t<li>CP-8050 MASTER MODULE (6MF2805-0AA00) \u2013 versions prior to CPCI85 V05.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-620","alert_type":398,"serial_number":"AV23-620","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4656,"title":"Curl security advisory (AV23-621)","uuid":"50c7ddcb-ec99-4350-9541-12fef75b6cc7","banner":null,"lang":"en","date_modified":"2023-10-11","date_modified_ts":"2023-10-11T20:24:33Z","date_created":"2023-10-11T20:19:36Z","summary":null,"body":["<article data-history-node-id=\"4656\" about=\"\/en\/alerts-advisories\/curl-security-advisory-av23-621\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-621<br \/><strong>Date: <\/strong>October\u00a011, 2023<\/p>\n\n<p>On October\u00a011, 2023, Curl published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>libcurl \u2013 version 7.69.0 to 8.3.0<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to a heap-based buffer overflow.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/curl.se\/docs\/CVE-2023-38545.html\">Curl Advisory CVE-2023-38545<\/a><\/li>\n\t<li><a href=\"https:\/\/curl.se\/docs\/security.html\">Curl Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/curl-security-advisory-av23-621","alert_type":398,"serial_number":"AV23-621","subject":"other","moderation_state":"published","external_url":null},{"nid":4657,"title":"Juniper Networks security advisory (AV23-622)","uuid":"472bd77f-0fc9-45b9-b6b9-32aa78f7c204","banner":null,"lang":"en","date_modified":"2023-10-12","date_modified_ts":"2023-10-12T17:10:57Z","date_created":"2023-10-12T17:07:06Z","summary":null,"body":["<article data-history-node-id=\"4657\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-622\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-622<br \/><strong>Date: <\/strong>October\u00a012, 2023<\/p>\n\n<p>On October\u00a011, 2023, Juniper published a security advisory to address a vulnerability in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-622","alert_type":396,"serial_number":"AV23-622","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4658,"title":"[Control systems] Weintek security advisory (AV23-623)","uuid":"8767b3f4-b9bb-4b09-82e2-ba201718ba3d","banner":null,"lang":"en","date_modified":"2023-10-12","date_modified_ts":"2023-10-12T17:21:31Z","date_created":"2023-10-12T17:18:22Z","summary":null,"body":["<article data-history-node-id=\"4658\" about=\"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-623\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-623<br \/><strong>Date: <\/strong>October\u00a012, 2023<\/p>\n\n<p>On October\u00a012, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>cMT-FHD \u2013 version 20210210 and prior<\/li>\n\t<li>cMT-HDM \u2013 version 20210204 and prior<\/li>\n\t<li>cMT3071 \u2013 version 20210218 and prior<\/li>\n\t<li>cMT3072 \u2013 version 20210218 and prior<\/li>\n\t<li>cMT3103 \u2013 version 20210218 and prior<\/li>\n\t<li>cMT3090 \u2013 version 20210218 and prior<\/li>\n\t<li>cMT3151 \u2013 version 20210218 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-285-12\">ICS Advisory \u2013 ICSA-23-285-12<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-623","alert_type":398,"serial_number":"AV23-623","subject":"other","moderation_state":"published","external_url":null},{"nid":4659,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-624)","uuid":"9aaa20a4-2bfc-4809-82ab-101e29263ce5","banner":null,"lang":"en","date_modified":"2023-10-12","date_modified_ts":"2023-10-12T17:26:05Z","date_created":"2023-10-12T17:24:29Z","summary":null,"body":["<article data-history-node-id=\"4659\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-624\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-624<br \/><strong>Date: <\/strong>October\u00a012, 2023<\/p>\n\n<p>On October\u00a012, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>MELSEC-F series \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-285-13\">ICS Advisory \u2013 ICSA-23-285-13<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-624","alert_type":398,"serial_number":"AV23-624","subject":"other","moderation_state":"published","external_url":null},{"nid":4660,"title":"[Control systems] Advantech security advisory (AV23-626)","uuid":"824795a5-6d4d-4285-b6e0-c4d56cda0ca2","banner":null,"lang":"en","date_modified":"2023-10-12","date_modified_ts":"2023-10-12T17:42:53Z","date_created":"2023-10-12T17:40:21Z","summary":null,"body":["<article data-history-node-id=\"4660\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-626\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-626<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 12, 2023<\/p>\n\n<p>On October 12, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Advantech WebAccess\u00a0\u2013 version 9.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-285-15\">ICS Advisory \u2013 ICSA-23-285-15<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av23-626","alert_type":398,"serial_number":"AV23-626","subject":"other","moderation_state":"published","external_url":null},{"nid":4661,"title":"[Control systems] Hikvision security advisory (AV23-625)","uuid":"3567e05e-7d0a-4961-9ffe-b4acf0271615","banner":null,"lang":"en","date_modified":"2023-10-12","date_modified_ts":"2023-10-12T17:47:14Z","date_created":"2023-10-12T17:43:46Z","summary":null,"body":["<article data-history-node-id=\"4661\" about=\"\/en\/alerts-advisories\/control-systems-hikvision-security-advisory-av23-625\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-625<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 12, 2023<\/p>\n\n<p>On October 12, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>DS-K1T804AXX\u00a0\u2013 version V1.4.0_build221212 and prior<\/li>\n\t<li>DS-K1T341AXX\u00a0\u2013 version V3.2.30_build221223 and prior<\/li>\n\t<li>DS-K1T671XXX\u00a0\u2013 version V3.2.30_build221223 and prior<\/li>\n\t<li>DS-K1T343XXX\u00a0\u2013 version V3.14.0_build230117 and prior<\/li>\n\t<li>DS-K1T341C\u00a0\u2013 version V3.3.8_build230112 and prior<\/li>\n\t<li>DS-K1T320XXX\u00a0\u2013 version V3.5.0_build220706 and prior<\/li>\n\t<li>DS-KH63 Series\u00a0\u2013 version V2.2.8_build230219 and prior<\/li>\n\t<li>DS-KH85 Series\u00a0\u2013 version V2.2.8_build230219 and prior<\/li>\n\t<li>DS-KH62 Series\u00a0\u2013 version V1.4.62_build220414 and prior<\/li>\n\t<li>DS-KH9310-WTE1(B)\u00a0\u2013 version V2.1.76_build230204 and prior<\/li>\n\t<li>DS-KH9510-WTE1(B)\u00a0\u2013 version V2.1.76_build230204 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-285-14\">ICS Advisory - ICSA-23-285-14<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hikvision-security-advisory-av23-625","alert_type":398,"serial_number":"AV23-625","subject":"other","moderation_state":"published","external_url":null},{"nid":4662,"title":"[Control systems] Santesoft Electric security advisory (AV23-627)","uuid":"93fb1093-14f0-486a-bef7-f5123d0ea423","banner":null,"lang":"en","date_modified":"2023-10-12","date_modified_ts":"2023-10-12T17:52:15Z","date_created":"2023-10-12T17:49:25Z","summary":null,"body":["<article data-history-node-id=\"4662\" about=\"\/en\/alerts-advisories\/control-systems-santesoft-electric-security-advisory-av23-627\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-627<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 12, 2023<\/p>\n\n<p>On October 12, 2023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Sante DICOM Viewer Pro \u2013 version v12.2.4 and prior<\/li>\n\t<li>Sante FFT Imaging \u2013 versions v1.4.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-285-01\">ICS Advisory - ICSMA-23-285-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-285-02\">ICS Advisory - ICSMA-23-285-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-santesoft-electric-security-advisory-av23-627","alert_type":398,"serial_number":"AV23-627","subject":"other","moderation_state":"published","external_url":null},{"nid":4663,"title":"HPE security advisory (AV23-628)","uuid":"19e9828b-c7db-43c0-bcfc-85d812a6c34f","banner":null,"lang":"en","date_modified":"2023-10-12","date_modified_ts":"2023-10-12T19:11:34Z","date_created":"2023-10-12T19:05:55Z","summary":null,"body":["<article data-history-node-id=\"4663\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-628\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-628<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 12, 2023<\/p>\n\n<p>On October 12, 2023, HPE published a security bulletin to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Smart Array P824i-p Controller \u2013 versions prior to v8.2.19<\/li>\n\t<li>HPE MR216i-a Gen10 Plus x16 Lanes without Cache NVMe\/SAS 12G Controller \u2013 versions prior to v8.2.19<\/li>\n\t<li>HPE MR216i-p Gen10 Plus x16 Lanes without Cache NVMe\/SAS 12G Controller \u2013 versions prior to v8.2.19<\/li>\n\t<li>HPE MR416i-a Gen10 Plus x16 Lanes 4GB Cache NVMe\/SAS 12G Controller \u2013 versions prior to v8.2.19<\/li>\n\t<li>HPE MR416i-p Gen10 Plus x16 Lanes 4GB Cache NVMe\/SAS 12G Controller \u2013 versions prior to v8.2.19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04536en_us\">HPE Security Bulletin \u2013 hpesbgn04536en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-628","alert_type":396,"serial_number":"AV23-628","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4664,"title":"Fortinet security advisory (AV23-629)","uuid":"67a6d8a6-b7be-4faf-8042-dc2e0f5c76ab","banner":null,"lang":"en","date_modified":"2023-10-13","date_modified_ts":"2023-10-13T19:50:25Z","date_created":"2023-10-13T19:46:16Z","summary":null,"body":["<article data-history-node-id=\"4664\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-629\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-629<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 13, 2023<\/p>\n\n<p>On October 13, 2023, Fortinet published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>FortiSandbox \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-280\">Fortinet PSIRT Advisory \u2013 FG-IR-23-280<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-273\">Fortinet PSIRT Advisory \u2013 FG-IR-23-273<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-215\">Fortinet PSIRT Advisory \u2013 FG-IR-23-215<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-311\">Fortinet PSIRT Advisory \u2013 FG-IR-23-311<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-629","alert_type":396,"serial_number":"AV23-629","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":4665,"title":"Ubuntu security advisory (AV23-630)","uuid":"95688556-aa54-4fac-b73e-43701a355510","banner":null,"lang":"en","date_modified":"2023-10-16","date_modified_ts":"2023-10-16T14:16:03Z","date_created":"2023-10-16T13:53:19Z","summary":null,"body":["<article data-history-node-id=\"4665\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-630\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-630<br \/><strong>Date: <\/strong>October 16, 2023<\/p>\n\n<p>Between October 9 and October 15, 2023, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0098-1\">Ubuntu Security Notice\u00a0\u2013 LSN-0098-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-630","alert_type":396,"serial_number":"AV23-630","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4666,"title":"Dell security advisory (AV23-631)","uuid":"7afcdeac-9185-4a5e-9a64-ea71f437d35c","banner":null,"lang":"en","date_modified":"2023-10-16","date_modified_ts":"2023-10-16T15:03:31Z","date_created":"2023-10-16T14:27:39Z","summary":null,"body":["<article data-history-node-id=\"4666\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-631\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-631<br \/><strong>Date: <\/strong>October 16, 2023<\/p>\n\n<p>Between October 9 and 15, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC SMR \u2013 versions prior to 4.10.0.0<\/li>\n\t<li>Dell EMC SMR Vapp \u2013 versions prior to 4.10.0.0<\/li>\n\t<li>Dell EMC SRM \u2013 versions prior to 4.10.1.0<\/li>\n\t<li>Dell EMC SRM Vapp \u2013 versions prior to 4.10.0.0<\/li>\n\t<li>Dell EMC VxRail Appliance \u2013 7.0.x versions prior to 7.0.480<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218468\/security-update-for-dell-emc-srm-and-dell-emc-storage-monitoring-and-reporting-smr-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- Security Update for Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR) for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218139\/dsa-2023-320-security-update-for-dell-vxrail-multiple-vulnerabilities-7-0-480\">Dell Security Update - DSA-2023-320<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-631","alert_type":396,"serial_number":"AV23-631","subject":"dell","moderation_state":"published","external_url":null},{"nid":4667,"title":"IBM security advisory (AV23-632)","uuid":"270918e5-71c4-41d9-b262-98af8f74a4ad","banner":null,"lang":"en","date_modified":"2023-10-16","date_modified_ts":"2023-10-16T15:36:38Z","date_created":"2023-10-16T15:10:07Z","summary":null,"body":["<article data-history-node-id=\"4667\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-632\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-632<br \/><strong>Date: <\/strong>October 23, 2023<\/p>\n\n<p>Between October 9 and October 15, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Business Automation Manager Open Editions \u2013 versions 8.0.0 to 8.0.3<\/li>\n\t<li>IBM Db2 REST\u00a0\u2013 versions 1.0.0.121-amd64 to 1.0.0.276-amd64<\/li>\n\t<li>IBM Engineering Lifecycle Optimization\u00a0- Publishing\u00a0\u2013 versions 7.0.1 and 7.0.2<\/li>\n\t<li>IBM Jazz Reporting Service \u2013 versions 7.0.1 and 7.0.2<\/li>\n\t<li>IBM Operations Analytics Predictive Insights\u00a0\u2013 version 1.3.6<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 versions 1.14.0 and 1.14.1<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5.0 to 7.5.0 UP6<\/li>\n\t<li>IBM QRadar User Case Manager App\u00a0\u2013 versions 1.0 to 3.7.0<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak\u00a0\u2013 versions 21.0.0 to 21.0.7.8 and versions 23.0.0 to 23.0.9<\/li>\n\t<li>IBM Storage Protect for Virtual Environments: Data Protection for VMware\u00a0\u2013 versions 8.1.0.0 to 8.1.14.0<\/li>\n\t<li>Red Hat Certified Ansible Collection for IBM Storage Virtualize\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-632","alert_type":396,"serial_number":"AV23-632","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4668,"title":"Cisco security advisory (AV23-633)","uuid":"92c058f4-e8dc-4302-86dd-69fa317b0735","banner":null,"lang":"en","date_modified":"2023-10-16","date_modified_ts":"2023-10-16T17:09:14Z","date_created":"2023-10-16T16:55:20Z","summary":null,"body":["<article data-history-node-id=\"4668\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-633\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-633\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a016, 2023\n<\/p>\n<p>On October\u00a016, 2023, Cisco published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>Cisco IOS XE\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<p>Cisco reports that CVE-2023-20198 is being exploited.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxe-webui-privesc-j22SaA4z\">Cisco Security Advisory - cisco-sa-iosxe-webui-privesc-j22SaA4z<\/a><\/li>\n  <li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-633","alert_type":396,"serial_number":"AV23-633","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4670,"title":"SonicWall security advisory (AV23-634)","uuid":"fa99dbba-89f0-41a7-9179-869ff5284fd0","banner":null,"lang":"en","date_modified":"2023-10-16","date_modified_ts":"2023-10-16T18:26:26Z","date_created":"2023-10-16T18:23:22Z","summary":null,"body":["<article data-history-node-id=\"4670\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-634\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-634<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 16, 2023<\/p>\n\n<p>On October 16, 2023, SonicWall published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SonicWall SonicOS\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2023-0012\">SonicWall Security Advisory \u2013 SNWLID-2023-0012<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av23-634","alert_type":396,"serial_number":"AV23-634","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":4672,"title":"[Control systems] Rockwell automation security advisory (AV23-635) ","uuid":"a9b318e6-214e-4961-b90c-adec87ff5161","banner":null,"lang":"en","date_modified":"2023-10-17","date_modified_ts":"2023-10-17T18:59:57Z","date_created":"2023-10-17T18:48:05Z","summary":null,"body":["<article data-history-node-id=\"4672\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-635\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-635<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 17, 2023<\/p>\n\n<p>On October 17, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Rockwell Automation FactoryTalk Linx \u2013 version 6.20 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-290-02\">ICS Advisory - ICSA-23-290-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-635","alert_type":398,"serial_number":"AV23-635","subject":"other","moderation_state":"published","external_url":null},{"nid":4673,"title":"Google Chrome security advisory (AV23-636)","uuid":"d63dd107-d8b0-4f50-8456-cc829027bdc3","banner":null,"lang":"en","date_modified":"2023-10-18","date_modified_ts":"2023-10-18T15:39:15Z","date_created":"2023-10-18T15:35:08Z","summary":null,"body":["<article data-history-node-id=\"4673\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-636\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-636<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 18, 2023<\/p>\n\n<p>On October 17, 2023, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 118.0.5993.88 (Linux and Mac) and 118.0.5993.88\/.89 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/10\/stable-channel-update-for-desktop_17.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-636","alert_type":396,"serial_number":"AV23-636","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4674,"title":"Oracle security advisory \u2013 October 2023 quarterly rollup (AV23-637)","uuid":"8cd4eff8-c8c6-4db9-9fcf-c1f35887f370","banner":null,"lang":"en","date_modified":"2023-10-18","date_modified_ts":"2023-10-18T15:46:49Z","date_created":"2023-10-18T15:41:42Z","summary":null,"body":["<article data-history-node-id=\"4674\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-october-2023-quarterly-rollup-av23-637\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-637<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 18, 2023<\/p>\n\n<p>On October 17, 2023, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle Hospitality Applications<\/li>\n\t<li>Oracle Hyperion<\/li>\n\t<li>Oracle Insurance Applications<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle PeopleSoft<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Utilities Applications<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuoct2023.html\">Oracle Critical Patch Update Advisory \u2013 October 2023<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-october-2023-quarterly-rollup-av23-637","alert_type":396,"serial_number":"AV23-637","subject":"oracle","moderation_state":"published","external_url":null},{"nid":4675,"title":"Vulnerability impacting Cisco devices (CVE-2023-20198) - Update 3","uuid":"6658fc1a-bd4d-4bc6-8989-35f8e093cd8a","banner":null,"lang":"en","date_modified":"2023-11-01","date_modified_ts":"2023-11-01T13:42:20Z","date_created":"2023-10-18T19:56:03Z","summary":null,"body":["<article data-history-node-id=\"4675\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-cisco-devices-cve-2023-20198\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-016<br \/><strong>Date:\u00a0<\/strong>October 18, 2023<br \/><strong>Updated: <\/strong>November 1, 2023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On October 16, 2023, Cisco reported<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> that a critical, 0-day privilege escalation vulnerability in the web UI interface of routers, switches and wireless controllers running IOS XE are being remotely exploited to gain privileged access.<\/p>\n\n<p>This vulnerability is tracked under CVE-2023-20198 and has the maximum security CVSS rating of 10.0.<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/p>\n\n<p>Open source is reporting that thousands of online, vulnerable devices have been compromised.<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/p>\n\n<p>This Alert is being published to raise awareness of this activity, highlight the potential impact to organizations and to provide guidance for organizations who may be impacted by this malicious activity.<\/p>\n<\/section><section><h2>Update 1<\/h2>\n\n<p>On October 22, 2023 Cisco updated their advisory<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> to indicate that the first updates are now available for some versions of IOS XE software. Cisco has also published a Software Fix Availability document to aid in the identification of affected products and the date when the images will be available for download.<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup><\/p>\n\n<p>On October 20, 2023 Cisco also updated their advisory<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> highlighting an additional vulnerability that was exploited by malicious actors. After successfully exploiting CVE-2023-20198 to gain initial access on vulnerable devices, threat actors were observed exploiting CVE-2023-20273 to elevate their privileges in order to write a backdoor to the device.<\/p>\n\n<p>The Cyber Centre recommends organizations continue to monitor the Cisco advisory and blog<sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2b-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> as well as the Software Fix Availability document<sup id=\"fn9a-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup> for additional updates to aid in the remediation of these vulnerabilities.<\/p>\n<\/section><section><h2>Update 2<\/h2>\n\n<p>On October 23, Cisco Talos updated their blog post<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> to advise that an updated version of the backdoor, which now includes a preliminary check of the HTTP Authorization header, has been observed. Talos speculates that this header check functionality has likely been added as a reactive measure to hinder the ability to identify affected devices.<\/p>\n\n<p>This updated backdoor shares most of its core functionality with the original backdoor and Talos believes it has been in use since October 20. To assist in the detection of the new backdoor, Talos has updated their blog with additional guidance to help detect the presence of either variants.<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/p>\n\n<p>The successful exploitation of this vulnerability allows a malicious actor to gain \"level 15\" (administrative) access to the device. With this access, the malicious actor can then collect configuration information, create additional administrative accounts, and leverage another vulnerability (CVE-2023-20273) to run arbitrary code on the device with elevated privileges.<\/p>\n\n<p>The Cyber Centre is aware that Canadian organizations have been impacted by both the original and updated backdoor. The Cyber Centre strongly encourages all organizations to review their network environments, identify potentially impacted devices and follow the below suggested actions.<\/p>\n<\/section><section><h2>Update 3<\/h2>\n\n<p>Between October 27 and October 31, 2023, Cisco has updated their advisory <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> to highlight additional patches being made available for devices vulnerable to CVE-2023-20198 and CVE-2023-20273.<\/p>\n\n<p>On October 28, 2023, proof of concept code was published on open source along with reports of additional activity targeting the vulnerabilities. Any organizations with continued external facing access to the vulnerable services should assume full device compromise. Malicious activity impacting these devices may result in internal network access and organizations are encouraged to begin cyber incident response activities. <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Follow Cisco Talos\u2019 guidance and mitigation from their Threat Advisory Blog<sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/li>\n\t<li>Prioritize reviewing devices that are exposed to the internet and are critical to your organization.<\/li>\n\t<li>Leverage available centralized logging tools to review account creation activity.<\/li>\n\t<li>Immediately patch affected systems when updates addressing this vulnerability become available.<\/li>\n<\/ul><p>The Cyber Centre wishes to highlight that mitigation efforts resulting from the compromise of systems by competent threat actors may require more than simply mitigating individual issues, systems and servers. The Cyber Centre recommends affected customers review the Cyber Centre joint cybersecurity advisory on technical approaches to uncovering and remediating malicious activity<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidate, monitor, and defend internet gateways<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxe-webui-privesc-j22SaA4z\">Cisco IOS XE Software Web UI Privilege Escalation Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/blog.talosintelligence.com\/active-exploitation-of-cisco-ios-xe-software\/\">Cisco Talos Blog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-20198\">NIST\u00a0\u2013 National Vulnerability Database CVE-2023-20198<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/vulncheck.com\/blog\/cisco-implants\">VulnCheck\u00a0\u2013 Widespread Cisco IOS XE implants in the wild<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/arstechnica.com\/security\/2023\/10\/actively-exploited-cisco-0-day-with-maximum-10-severity-gives-full-network-control\/\">Ars Technica\u00a0\u2013 Actively exploited cisco 0 day with maximum 10 severity gives full network access<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/twitter.com\/Shadowserver\/status\/1714483336876355873\">Shadowserver IOS XE post<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/news-events\/joint-cybersecurity-advisory\">Joint cybersecurity advisory\u00a0- Technical approaches to uncovering and remediating malicious activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">CCCS Top 10 IT security actions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/ios-nx-os-software\/ios-xe-dublin-17121\/221128-software-fix-availability-for-cisco-ios.html \">Software Fix Availability for Cisco IOS XE Software Web UI Privilege Escalation Vulnerability\u00a0- CVE-2023-20198<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote <\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-cisco-devices-cve-2023-20198","alert_type":397,"serial_number":"AL23-016","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4676,"title":"F5 security advisory (AV23-638)","uuid":"95102826-d80d-44df-8646-0dd80360e2de","banner":null,"lang":"en","date_modified":"2023-10-19","date_modified_ts":"2023-10-19T13:09:05Z","date_created":"2023-10-19T13:04:52Z","summary":null,"body":["<article data-history-node-id=\"4676\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av23-638\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-638\n  <br \/><strong>Date: <\/strong>October 19, 2023\n<\/p>\n<p>On October 10, 2023, F5 published security advisories to address vulnerabilities in multiple products. Included were updates for the following:\n<\/p>\n<ul><li>BIG-IP\u00a0\u2013 multiple versions<\/li>\n  <li>BIG-IP APM\u00a0\u2013 multiple versions<\/li>\n  <li>BIG-IP APM Clients\u00a0\u2013 versions 7.2.3 to 7.2.4<\/li>\n  <li>BIG-IP Next SPK\u00a0\u2013 versions 1.6.0 to 1.8.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000137053\">F5 Security Advisory\u00a0- K000137053<\/a><\/li>\n  <li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=cve&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending\">F5 Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av23-638","alert_type":396,"serial_number":"AV23-638","subject":"f5","moderation_state":"published","external_url":null},{"nid":4677,"title":"Atlassian security advisory (AV23-639)","uuid":"7d39dcb4-15d2-4bc6-82c0-1e7d818b189f","banner":null,"lang":"en","date_modified":"2023-10-19","date_modified_ts":"2023-10-19T13:53:38Z","date_created":"2023-10-19T13:49:29Z","summary":null,"body":["<article data-history-node-id=\"4677\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-639\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-639<br \/><strong>Date: <\/strong>October 19, 2023<\/p>\n\n<p>On October 17, 2023, Atlassian published security bulletins to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Sourcetree for Mac\u00a0\u2013 multiple versions<\/li>\n\t<li>Sourcetree for Windows\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-october-17-2023-1299929380.html\">Atlassian Security Bulletin\u00a0\u2013 October 17 2023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-639","alert_type":396,"serial_number":"AV23-639","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4678,"title":"VMware security advisory (AV23-640)","uuid":"0b09ac2b-4346-475b-9bcd-c58e0bec5b32","banner":null,"lang":"en","date_modified":"2023-10-24","date_modified_ts":"2023-10-24T17:58:47Z","date_created":"2023-10-20T19:19:02Z","summary":null,"body":["<article data-history-node-id=\"4678\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-640\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-640<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a020, 2023<\/p>\n\n<p>On October\u00a019, 2023, VMware published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>VMware Aria Operations for Logs\u00a0\u2013 version 8.x<\/li>\n\t<li>VMware Cloud Foundation (VMware Aria Operations for Logs)\u00a0\u2013 version 5.x and 4.x<\/li>\n<\/ul><p>VMware has indicated that CVE-2023-34051 has an available exploit. Exploitation of some of these vulnerabilities could lead to remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0021.html\">VMSA-2023-0021<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-640","alert_type":396,"serial_number":"AV23-640","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4679,"title":"Ivanti security advisory (AV23-641)","uuid":"880160a2-2f03-4768-91c7-09e720677899","banner":null,"lang":"en","date_modified":"2023-10-20","date_modified_ts":"2023-10-20T20:08:52Z","date_created":"2023-10-20T20:04:42Z","summary":null,"body":["<article data-history-node-id=\"4679\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-641\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-641<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a020, 2023<\/p>\n\n<p>On October\u00a019, 2023, Ivanti published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Ivanti Secure Access Client\u00a0\u2013 versions prior to 22.6R1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-38041-New-client-side-release-to-address-a-privilege-escalation-on-Windows-user-machines?language=en_US\">Ivanti Security Advisory\u00a0- CVE-2023-38041<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-641","alert_type":396,"serial_number":"AV23-641","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4681,"title":"Ubuntu security advisory (AV23-642)","uuid":"30192c8c-33b5-42d3-88f9-c2122d535295","banner":null,"lang":"en","date_modified":"2023-10-23","date_modified_ts":"2023-10-23T17:24:29Z","date_created":"2023-10-23T17:21:26Z","summary":null,"body":["<article data-history-node-id=\"4681\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-642\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-642<br \/><strong>Date: <\/strong>October 23, 2023<\/p>\n\n<p>Between October 16 and 22, 2023, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-642","alert_type":396,"serial_number":"AV23-642","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4682,"title":"Dell security advisory (AV23-643)","uuid":"030c8811-fe55-416e-9ec6-a32d321bb1a3","banner":null,"lang":"en","date_modified":"2023-10-23","date_modified_ts":"2023-10-23T17:33:10Z","date_created":"2023-10-23T17:26:12Z","summary":null,"body":["<article data-history-node-id=\"4682\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-643\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-643<br \/><strong>Date: <\/strong>October 23, 2023<\/p>\n\n<p>Between October 16 and 22, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Data Protection Central\u00a0\u2013 version 19.4 to 19.9.0-12<\/li>\n\t<li>Dell Object Scale\u00a0\u2013 versions 1.0.0, 1.0.1, 1.0.2 and 1.2.0<\/li>\n\t<li>Dell PowerProtect DataDomain\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerProtect Data Protection Series Appliance\u00a0\u2013 version 2.6.1 to 2.7.4<\/li>\n\t<li>Dell Unity Operating Environment (OE)\u00a0\u2013 versions prior to 5.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218736\/dsa-2023-379-security-update-for-dell-data-protection-central\">Dell Security Update\u00a0- DSA-2023-379<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218660\/dsa-2023-381-security-update-for-dell-objectscale-1-3-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-381<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218619\/dsa-2023-389-security-update-for-dell-technologies-powerprotect-datadomain-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-389<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000218604\/dsa-2023-349-security-update-for-dell-unity-family-dell-emc-unity-all-flash-for-multiple-component-vulnerabilities\">Dell Security Update - DSA-2023-349<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-643","alert_type":396,"serial_number":"AV23-643","subject":"dell","moderation_state":"published","external_url":null},{"nid":4683,"title":"IBM security advisory (AV23-644)","uuid":"c6005c69-05f5-4456-817a-1e006879c325","banner":null,"lang":"en","date_modified":"2023-10-23","date_modified_ts":"2023-10-23T17:37:44Z","date_created":"2023-10-23T17:33:52Z","summary":null,"body":["<article data-history-node-id=\"4683\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-644\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-644<br \/><strong>Date: <\/strong>October 23, 2023<\/p>\n\n<p>Between October 16 and 22, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Integrated Analytics System\u00a0\u2013 versions 1.0.0 to 1.0.28.0<\/li>\n\t<li>IBM Security Verify Governance\u00a0\u2013 version 1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7053417\">IBM Security Bulletin\u00a0- 7053417<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7057377\">IBM Security Bulletin\u00a0- 7057377<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-644","alert_type":396,"serial_number":"AV23-644","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4684,"title":"Mozilla security advisory (AV23-645)","uuid":"076dff29-f9a0-4304-ba61-95075b19bdba","banner":null,"lang":"en","date_modified":"2023-10-24","date_modified_ts":"2023-10-24T17:51:48Z","date_created":"2023-10-24T17:46:55Z","summary":null,"body":["<article data-history-node-id=\"4684\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-645\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-645<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 24, 2023<\/p>\n\n<p>On October 24, 2023, Mozilla published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 119<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-45\/\">Mozilla Security Advisory - MFSA 2023-45<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-46\/\">Mozilla Security Advisory - MFSA 2023-46<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-645","alert_type":396,"serial_number":"AV23-645","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4685,"title":"[Control systems] Rockwell Automation security advisory (AV23-646)","uuid":"251598cd-30ac-4c90-b7c3-9375cb92b17a","banner":null,"lang":"en","date_modified":"2023-10-24","date_modified_ts":"2023-10-24T18:07:27Z","date_created":"2023-10-24T18:02:48Z","summary":null,"body":["<article data-history-node-id=\"4685\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-646\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-646<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 24, 2023<\/p>\n\n<p>On October 24, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Stratix 5800\u00a0\u2013 all versions<\/li>\n\t<li>Stratix 5200\u00a0\u2013 all versions<\/li>\n<\/ul><p>Cisco reported that this vulnerability in the web UI interface of routers, switches and wireless controllers running IOS XE is being exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-297-01\">ICS Advisory\u00a0- ICSA-23-297-01<\/a><\/li>\n\t<li><a href=\"\/en\/alerts-advisories\/vulnerability-impacting-cisco-devices-cve-2023-20198\">Vulnerability impacting Cisco devices CVE-2023-20198<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-646","alert_type":398,"serial_number":"AV23-646","subject":"other","moderation_state":"published","external_url":null},{"nid":4686,"title":"Google Chrome security advisory (AV23-647)","uuid":"1ffdb131-dd33-4195-8e60-90a72f96e58e","banner":null,"lang":"en","date_modified":"2023-10-25","date_modified_ts":"2023-10-25T15:42:16Z","date_created":"2023-10-25T14:43:51Z","summary":null,"body":["<article data-history-node-id=\"4686\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-647\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-647<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a025, 2023<\/p>\n\n<p>On October\u00a024, 2023, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Chrome for Desktop Stable Channel\u00a0\u2013 versions prior to 118.0.5993.117 (Mac and Linux) and 118.0.5993.117\/.118 (Windows)<\/li>\n\t<li>Chrome for Desktop Extended Stable Channel\u00a0\u2013 versions prior to 118.0.5993.117 (Mac and Linux) and 118.0.5993.118 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/10\/stable-channel-update-for-desktop_24.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-647","alert_type":396,"serial_number":"AV23-647","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4687,"title":"VMware security advisory (AV23-648)","uuid":"1ae094a9-638a-4730-8606-97ce3afe37c6","banner":null,"lang":"en","date_modified":"2023-10-25","date_modified_ts":"2023-10-25T15:50:46Z","date_created":"2023-10-25T14:43:51Z","summary":null,"body":["<article data-history-node-id=\"4687\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-648\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-648<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October\u00a025, 2023<\/p>\n\n<p>On October\u00a025, 2023, VMware published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware vCenter Server\u00a0\u2013 multiple versions<\/li>\n\t<li>VMware Cloud Foundation (VMware vCenter Server)\u00a0\u2013 versions 5.x and 4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0023.html\">VMSA-2023-0023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-648","alert_type":396,"serial_number":"AV23-648","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4688,"title":"Apple security advisory (AV23-649)","uuid":"adbb6f75-7efe-4b01-af59-8c5d79d0158b","banner":null,"lang":"en","date_modified":"2023-10-25","date_modified_ts":"2023-10-25T19:16:32Z","date_created":"2023-10-25T19:13:10Z","summary":null,"body":["<article data-history-node-id=\"4688\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-649\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-649<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 25, 2023<\/p>\n\n<p>On October 25, 2023, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS \u2013 multiple versions<\/li>\n\t<li>iPadOS \u2013 multiple versions<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.7.1<\/li>\n\t<li>macOS Sonoma \u2013 versions prior to 14.1<\/li>\n\t<li>macOS Ventura \u2013 versions prior to 13.6.1<\/li>\n\t<li>Safari \u2013 versions prior to 17.1<\/li>\n\t<li>tvOS \u2013 versions prior to 17.1<\/li>\n\t<li>watchOS \u2013 versions prior to 10.1<\/li>\n<\/ul><p>Apple has received reports that CVE-2023-32434 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-649","alert_type":396,"serial_number":"AV23-649","subject":"apple","moderation_state":"published","external_url":null},{"nid":4689,"title":"F5 security advisory (AV23-650)","uuid":"aca66bfa-998c-424a-b3b7-14e36d2bf6db","banner":null,"lang":"en","date_modified":"2023-10-25","date_modified_ts":"2023-10-25T19:21:58Z","date_created":"2023-10-25T19:19:26Z","summary":null,"body":["<article data-history-node-id=\"4689\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av23-650\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-650\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 25, 2023\n<\/p>\n<p>On October 24, 2023, F5 published a security advisory to address a vulnerability in the following products:\n<\/p>\n<ul><li>BIG-IP \u2013 multiple versions and modules<\/li>\n  <li>BIG-IP Next \u2013 version 20.0.1<\/li>\n  <li>BIG-IP Next SPK \u2013 version 1.5.0 to 1.8.2<\/li>\n  <li>BIG-IP Next CNF \u2013 version 1.1.0 to 1.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000137315\">F5 Security Advisory - K000137315<\/a><\/li>\n  <li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=cve&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending\">F5 Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av23-650","alert_type":396,"serial_number":"AV23-650","subject":"f5","moderation_state":"published","external_url":null},{"nid":4690,"title":"[Control systems] Rockwell Automation security advisory (AV23-654)","uuid":"9d663428-e7cb-4f6e-806e-e573e99bfcdf","banner":null,"lang":"en","date_modified":"2023-10-26","date_modified_ts":"2023-10-26T17:15:41Z","date_created":"2023-10-26T17:11:04Z","summary":null,"body":["<article data-history-node-id=\"4690\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-654\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-654<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 26, 2023<\/p>\n\n<p>On October 26, 2023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Arena \u2013 version 16.20.00001<\/li>\n\t<li>FactoryTalk Services Platform \u2013 version 2.74<\/li>\n\t<li>FactoryTalk View Site Edition \u2013 version 11.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-04\">ICS Advisory - ICSA-23-299-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-05\">ICS Advisory - ICSA-23-299-05<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-06\">ICS Advisory - ICSA-23-299-06<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-654","alert_type":398,"serial_number":"AV23-654","subject":"other","moderation_state":"published","external_url":null},{"nid":4691,"title":"[Control systems] Sielco security advisory (AV23-655)","uuid":"44c7c904-bccb-44c4-802c-882cfdb1e4ba","banner":null,"lang":"en","date_modified":"2023-10-26","date_modified_ts":"2023-10-26T17:21:45Z","date_created":"2023-10-26T17:18:40Z","summary":null,"body":["<article data-history-node-id=\"4691\" about=\"\/en\/alerts-advisories\/control-systems-sielco-security-advisory-av23-655\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-655<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 26, 2023<\/p>\n\n<p>On October 26, 2023, CISA published ICS Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Analog FM transmitter \u2013 multiple versions and models<\/li>\n\t<li>PolyEco1000 \u2013 multiple versions and models<\/li>\n\t<li>Radio Link \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-07\">ICS Advisory - ICSA-23-299-07<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-08\">ICS Advisory - ICSA-23-299-08<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sielco-security-advisory-av23-655","alert_type":398,"serial_number":"AV23-655","subject":"other","moderation_state":"published","external_url":null},{"nid":4692,"title":"[Control systems] Dingtian security advisory (AV23-651)","uuid":"d62c482d-2dc7-41a7-ad7c-0f4da1d81079","banner":null,"lang":"en","date_modified":"2023-10-26","date_modified_ts":"2023-10-26T17:24:55Z","date_created":"2023-10-26T17:19:09Z","summary":null,"body":["<article data-history-node-id=\"4692\" about=\"\/en\/alerts-advisories\/dingtian-security-advisory-av23-651\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-651<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 26, 2023<\/p>\n\n<p>On October 26, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>DT-R002 \u2013 version 3.1.276A<\/li>\n<\/ul><p>CISA has indicated that this vulnerability has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-01\">ICS Advisory - ICSA -23-299-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dingtian-security-advisory-av23-651","alert_type":398,"serial_number":"AV23-651","subject":"other","moderation_state":"published","external_url":null},{"nid":4693,"title":"[Control systems] Centralite security advisory (AV23-652)","uuid":"1502e4ed-c6b8-4eef-acad-fb39c1f4264e","banner":null,"lang":"en","date_modified":"2023-10-26","date_modified_ts":"2023-10-26T17:44:39Z","date_created":"2023-10-26T17:41:34Z","summary":null,"body":["<article data-history-node-id=\"4693\" about=\"\/en\/alerts-advisories\/control-systems-centralite-security-advisory-av23-652\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-652<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 26, 2023<\/p>\n\n<p>On October 26, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Pearl Thermostat \u2013 version 0x04075010<\/li>\n<\/ul><p>CISA has indicated that this vulnerability has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-02\">ICS Advisory - ICSA-23-299-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-centralite-security-advisory-av23-652","alert_type":398,"serial_number":"AV23-652","subject":"other","moderation_state":"published","external_url":null},{"nid":4694,"title":"[Control systems] Ashlar-Vellum security advisory (AV23-653)","uuid":"faaa14cb-4181-49ff-83a2-c3a50d59ce61","banner":null,"lang":"en","date_modified":"2023-10-26","date_modified_ts":"2023-10-26T18:47:36Z","date_created":"2023-10-26T18:25:38Z","summary":null,"body":["<article data-history-node-id=\"4694\" about=\"\/en\/alerts-advisories\/control-systems-ashlar-vellum-security-advisory-av23-653\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-653\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 26, 2023\n<\/p>\n<p>On October 26, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Cobalt \u2013 version v12 SP0 Build (1204.77) and prior<\/li>\n  <li>Cobalt Share \u2013 version v12 SP0 Build (1204.77) and prior<\/li>\n  <li>Graphite \u2013 version v13.0.48 and prior<\/li>\n  <li>Xenon \u2013 version v12 SP0 Build (1204.77) and prior<\/li>\n  <li>Argon \u2013 version v12 SP0 Build (1204.77) and prior<\/li>\n  <li>Lithium \u2013 version v12 SP0 Build (1204.77) and prior<\/li>\n\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-299-03\">ICS Advisory - ICSA-23-299-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ashlar-vellum-security-advisory-av23-653","alert_type":398,"serial_number":"AV23-653","subject":"other","moderation_state":"published","external_url":null},{"nid":4695,"title":"F5 security advisory (AV23-656)","uuid":"9560271e-92d7-4c71-941e-8087a4a736a5","banner":null,"lang":"en","date_modified":"2023-10-27","date_modified_ts":"2023-10-27T15:17:02Z","date_created":"2023-10-26T19:05:08Z","summary":null,"body":["<article data-history-node-id=\"4695\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av23-656\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-656<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 26, 2023<\/p>\n\n<p>On October 26, 2023, F5 published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>BIG-IP \u2013 multiple versions and modules<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000137353\">F5 Security Advisory - K000137353<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000137365\">F5 Security Advisory - K000137365<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=cve&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending\">F5 Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av23-656","alert_type":396,"serial_number":"AV23-656","subject":"f5","moderation_state":"published","external_url":null},{"nid":4698,"title":"VMware security advisory (AV23-657)","uuid":"4b05e6c8-8e6c-4ba5-9208-9d235606efa7","banner":null,"lang":"en","date_modified":"2023-10-27","date_modified_ts":"2023-10-27T16:09:28Z","date_created":"2023-10-27T16:00:44Z","summary":null,"body":["<article data-history-node-id=\"4698\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-657\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-657<br \/><strong>Date: <\/strong>October 27, 2023<\/p>\n\n<p>On October 26, 2023, VMware published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Tools\u00a0\u2013 versions 12.x.x, 11.x.x and 10.3.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0024.html\">VMSA-2023-0024<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-657","alert_type":396,"serial_number":"AV23-657","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4699,"title":"Mozilla security advisory (AV23-658)","uuid":"c30ed574-86c9-4deb-b964-ccf29b86e9a5","banner":null,"lang":"en","date_modified":"2023-10-27","date_modified_ts":"2023-10-27T19:45:18Z","date_created":"2023-10-27T19:39:45Z","summary":null,"body":["<article data-history-node-id=\"4699\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-658\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-658<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 27, 2023<\/p>\n\n<p>On October 24, 2023, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox for iOS\u00a0\u2013 versions prior to 119<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 115.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-48\/\">Mozilla Security Advisory - MFSA 2023-48<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-47\/\">Mozilla Security Advisory - MFSA 2023-47<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-658","alert_type":396,"serial_number":"AV23-658","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4700,"title":"[Control systems] NextGen HealthCare security advisory (AV23-659)","uuid":"f6766579-6607-4744-b571-779922136534","banner":null,"lang":"en","date_modified":"2023-10-27","date_modified_ts":"2023-10-27T19:53:53Z","date_created":"2023-10-27T19:49:57Z","summary":null,"body":["<article data-history-node-id=\"4700\" about=\"\/en\/alerts-advisories\/control-systems-nextgen-healthcare-security-advisory-av23-659\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-659<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>October 27, 2023<\/p>\n\n<p>On October 17, 2023, NextGen HealthCare published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Mirth Connect\u00a0\u2013 versions prior to 4.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/nextgenhealthcare\/connect\/releases\/tag\/4.4.1\">NextGen HealthCare Mirth Connect - 4.41 What\u2019s New<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-nextgen-healthcare-security-advisory-av23-659","alert_type":398,"serial_number":"AV23-659","subject":"other","moderation_state":"published","external_url":null},{"nid":4701,"title":"IBM security advisory (AV23-660)","uuid":"2cbb1693-9996-4c81-b004-ebcc56eeb444","banner":null,"lang":"en","date_modified":"2023-10-30","date_modified_ts":"2023-10-30T13:28:36Z","date_created":"2023-10-30T13:08:47Z","summary":null,"body":["<article data-history-node-id=\"4701\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-660\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-660<br \/><strong>Date: <\/strong>October\u00a030, 2023<\/p>\n\n<p>Between October 23\u00a0and\u00a029, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps\u00a0\u2013 version 4.2.0<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 version 7.5 to 7.5.0 UP7<\/li>\n\t<li>UCB\u00a0- IBM UrbanCode Build\u00a0\u2013 version 6.1.7 to 6.1.7.9<\/li>\n\t<li>UCR \u00a0- IBM UrbanCode Release\u00a0\u2013 version 6.2.x to 6.2.5.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-660","alert_type":396,"serial_number":"AV23-660","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4703,"title":"Ubuntu security advisory (AV23-661)","uuid":"de2adce2-0497-4f73-961d-cc7d3ec5969f","banner":null,"lang":"en","date_modified":"2023-10-30","date_modified_ts":"2023-10-30T14:36:25Z","date_created":"2023-10-30T14:25:33Z","summary":null,"body":["<article data-history-node-id=\"4703\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-661\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-661<br \/><strong>Date: <\/strong>October 30, 2023<\/p>\n\n<p>Between October 23 and 29, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6440-3\">Ubuntu Security Notice (USN-6440-3)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6441-2\">Ubuntu Security Notice (USN-6441-2)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6444-2\">Ubuntu Security Notice (USN-6444-2)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6445-2\">Ubuntu Security Notice (USN-6445-2)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6446-2\">Ubuntu Security Notice (USN-6446-2)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6446-3\">Ubuntu Security Notice (USN-6446-3)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6454-1\">Ubuntu Security Notice (USN-6454-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-661","alert_type":396,"serial_number":"AV23-661","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4704,"title":"[Control systems] ABB security advisory (AV23-662) ","uuid":"64f4a427-b7c7-4e5e-b642-295aff2bd196","banner":null,"lang":"en","date_modified":"2023-10-30","date_modified_ts":"2023-10-30T16:15:06Z","date_created":"2023-10-30T15:43:23Z","summary":null,"body":["<article data-history-node-id=\"4704\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-662\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-662<br \/><strong>Date: <\/strong>October 30, 2023<\/p>\n\n<p>On October 30, 2023, ABB published at ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB COM600\u00a0\u2013 versions 4.x and 5.<\/li>\n<\/ul><p>The exploitation of this vulnerability can lead to arbitrary code execution or devices becoming inaccessible.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001822&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB COM600 CODESYS Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av23-662","alert_type":398,"serial_number":"AV23-662","subject":"abb","moderation_state":"published","external_url":null},{"nid":4706,"title":"[Control systems] INEA security advisory (AV23-663)","uuid":"b701508f-d73f-4097-b6a2-824025074ed1","banner":null,"lang":"en","date_modified":"2023-10-31","date_modified_ts":"2023-10-31T17:17:36Z","date_created":"2023-10-31T17:14:25Z","summary":null,"body":["<article data-history-node-id=\"4706\" about=\"\/en\/alerts-advisories\/control-systems-inea-security-advisory-av23-663\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-663<br \/><strong>Date: <\/strong>October 31, 2023<\/p>\n\n<p>On October 31, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ME RTU\u00a0\u2013 versions 3.36b and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-304-02\">ICS Advisory\u00a0\u2013 ICSA-23-304-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inea-security-advisory-av23-663","alert_type":398,"serial_number":"AV23-663","subject":"other","moderation_state":"published","external_url":null},{"nid":4707,"title":"[Control systems] Zavio security advisory (AV23-664)","uuid":"7a9907d4-1d8d-479d-bc16-b02200e89fce","banner":null,"lang":"en","date_modified":"2023-10-31","date_modified_ts":"2023-10-31T18:10:15Z","date_created":"2023-10-31T18:06:56Z","summary":null,"body":["<article data-history-node-id=\"4707\" about=\"\/en\/alerts-advisories\/control-systems-zavio-security-advisory-av23-664\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-664<br \/><strong>Date: <\/strong>October 31, 2023<\/p>\n\n<p>On October 31, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>IP Camera CF7500\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CF7300\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CF7201\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CF7501\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CB3211\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CB3212\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CB5220\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CB6231\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera B8520\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera B8220\u00a0\u2013 version M2.1.6.05<\/li>\n\t<li>IP Camera CD321\u00a0\u2013 version M2.1.6.05<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-304-03\">ICS Advisory\u00a0\u2013 ICSA-23-304-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-zavio-security-advisory-av23-664","alert_type":398,"serial_number":"AV23-664","subject":"other","moderation_state":"published","external_url":null},{"nid":4708,"title":"Atlassian security advisory (AV23-665)","uuid":"6cce8e7b-f2f2-423c-831f-a38d21671100","banner":null,"lang":"en","date_modified":"2023-10-31","date_modified_ts":"2023-10-31T19:14:31Z","date_created":"2023-10-31T19:03:33Z","summary":null,"body":["<article data-history-node-id=\"4708\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-665\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-665<br \/><strong>Date: <\/strong>October 31, 2023<\/p>\n\n<p>On October 30, 2023, Atlassian published a security bulletin to address a vulnerability in the following product:<\/p>\n\n<ul><li>Confluence data center and server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html\">Atlassian Security Bulletin\u00a0\u2013 October 30 2023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-665","alert_type":396,"serial_number":"AV23-665","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4710,"title":"Cisco security advisory (AV23-666)","uuid":"45f92a89-61df-4530-8fcb-4f69697dcb0b","banner":null,"lang":"en","date_modified":"2023-11-01","date_modified_ts":"2023-11-01T18:40:01Z","date_created":"2023-11-01T18:37:04Z","summary":null,"body":["<article data-history-node-id=\"4710\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-666\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-666<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 1, 2023<\/p>\n\n<p>On November 1, 2023, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Cisco Identity Services Engine\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Firepower Threat Defense\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Firepower Management Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Adaptive Security Appliance\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Identity Services Engine\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-666","alert_type":396,"serial_number":"AV23-666","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4711,"title":"Google Chrome security advisory (AV23-667)","uuid":"f146260a-e37a-416f-a618-c33962000d7c","banner":null,"lang":"en","date_modified":"2023-11-01","date_modified_ts":"2023-11-01T18:47:14Z","date_created":"2023-11-01T18:42:09Z","summary":null,"body":["<article data-history-node-id=\"4711\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-667-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-667<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 1, 2023<\/p>\n\n<p>On October 31, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 119.0.6045.105\/.106 (Windows) and 119.0.6045.105 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/10\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-667-0","alert_type":396,"serial_number":"AV23-667","subject":"other","moderation_state":"published","external_url":null},{"nid":4712,"title":"VMware security advisory (AV23-668)","uuid":"2b13a12f-4c9a-4438-8139-a61ad8e0f50c","banner":null,"lang":"en","date_modified":"2023-11-01","date_modified_ts":"2023-11-01T20:24:33Z","date_created":"2023-11-01T20:20:08Z","summary":null,"body":["<article data-history-node-id=\"4712\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-668\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-668\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 1, 2023\n<\/p>\n<p>On October 31, 2023, VMware published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>VMware Workspace ONE UEM 2302\u00a0\u2013 versions prior to 23.2.0.10<\/li>\n  <li>VMware Workspace ONE UEM 2212\u00a0\u2013 versions prior to 22.12.0.20<\/li>\n  <li>VMware Workspace ONE UEM 2209\u00a0\u2013 versions prior to 22.9.0.29<\/li>\n  <li>VMware Workspace ONE UEM 2206\u00a0\u2013 versions prior to 22.6.0.36<\/li>\n  <li>VMware Workspace ONE UEM 2203\u00a0\u2013 versions prior to 22.3.0.48<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0025.html\">VMSA-2023-0025<\/a><\/li>\n  <li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-668","alert_type":396,"serial_number":"AV23-668","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4713,"title":"Apache security advisory (AV23-669)","uuid":"861b62ab-d4d8-424e-a388-dab9fe347808","banner":null,"lang":"en","date_modified":"2023-11-02","date_modified_ts":"2023-11-02T14:28:51Z","date_created":"2023-11-02T14:19:58Z","summary":null,"body":["<article data-history-node-id=\"4713\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av23-669\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-669<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date:\u00a0 <\/strong>November 2, 2023<\/p>\n\n<p>On October 27, 2023, Apache published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ActiveMQ 5.18 \u2013 versions prior to 5.18.3<\/li>\n\t<li>ActiveMQ 5.17 \u2013 versions prior to 5.17.6<\/li>\n\t<li>ActiveMQ 5.16 \u2013 versions prior to 5.16.7<\/li>\n\t<li>ActiveMQ \u2013 versions prior to 5.15.16<\/li>\n\t<li>ActiveMQ Legacy OpenWire Module 5.18 \u2013 versions prior to 5.18.3<\/li>\n\t<li>ActiveMQ Legacy OpenWire Module 5.17 \u2013 versions prior to 5.17.6<\/li>\n\t<li>ActiveMQ Legacy OpenWire Module 5.16 \u2013 versions prior to 5.16.7<\/li>\n\t<li>ActiveMQ Legacy OpenWire Module 5.8 \u2013 versions prior to 5.15.16<\/li>\n<\/ul><p>Open source has reported that CVE-2023-46604 has been exploited. Successful exploitation of this vulnerability can permit remote code execution to a threat actor.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/activemq.apache.org\/security-advisories.data\/CVE-2023-46604\">Apache security advisory \u2013 AMQ-9370<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-46604\">CVE-2023-46604<\/a><\/li>\n\t<li><a href=\"https:\/\/activemq.apache.org\/security-advisories.data\/\">Apache Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av23-669","alert_type":396,"serial_number":"AV23-669","subject":"other","moderation_state":"published","external_url":null},{"nid":4714,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-670) ","uuid":"57982de4-0044-482b-8b70-24cc96a6fda9","banner":null,"lang":"en","date_modified":"2023-11-02","date_modified_ts":"2023-11-02T16:00:39Z","date_created":"2023-11-02T15:56:15Z","summary":null,"body":["<article data-history-node-id=\"4714\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-670\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-670<br \/><strong>Date: <\/strong>November 2, 2023<\/p>\n\n<p>On November 2, 2023, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitsubishi Electric MELSEC Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F Series CPU module\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-306-02\">ICS Advisory\u00a0- ICSA-23-306-02 (iQ-F CPU Module)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-306-03\">ICS Advisory\u00a0- ICSA-23-306-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-670","alert_type":398,"serial_number":"AV23-670","subject":"other","moderation_state":"published","external_url":null},{"nid":4715,"title":"[Control Systems] Red Lion Controls security advisory (AV23-671)","uuid":"2f8da2a6-71eb-4758-9a2f-240c626d5c37","banner":null,"lang":"en","date_modified":"2023-11-02","date_modified_ts":"2023-11-02T17:14:15Z","date_created":"2023-11-02T17:09:26Z","summary":null,"body":["<article data-history-node-id=\"4715\" about=\"\/en\/alerts-advisories\/control-systems-red-lion-controls-security-advisory-av23-671\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-671<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 2, 2023<\/p>\n\n<p>On 2\u00a0November\u00a02023, ICS-CERT published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Crimson 3.2 \u2013 version 2.0053.18 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"ICS Advisory (ICSA-23-306-01) \">ICS Advisory (ICSA-23-306-01) <\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-red-lion-controls-security-advisory-av23-671","alert_type":398,"serial_number":"AV23-671","subject":"other","moderation_state":"published","external_url":null},{"nid":4716,"title":"[Control Systems] Franklin Fueling System security advisory (AV23-672)","uuid":"c45a21c1-2abb-426d-b00d-0f580bae547b","banner":null,"lang":"en","date_modified":"2023-11-02","date_modified_ts":"2023-11-02T17:45:20Z","date_created":"2023-11-02T17:41:18Z","summary":null,"body":["<article data-history-node-id=\"4716\" about=\"\/en\/alerts-advisories\/control-systems-franklin-fueling-system-security-advisory-av23-672\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-672<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November\u00a02, 2023<\/p>\n\n<p>On November\u00a02, 2023, CISA published an ICS Advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Franklin Fueling System TS-550 \u2013 versions prior to 1.9.23.8960<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"ICS Advisory (ICSA-23-306-04) \">ICS Advisory (ICSA-23-306-04) <\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-franklin-fueling-system-security-advisory-av23-672","alert_type":396,"serial_number":"AV23-672","subject":"other","moderation_state":"published","external_url":null},{"nid":4717,"title":"[Control systems] Weintek security advisory (AV23-673) ","uuid":"3471eefb-c3e9-4dbf-b692-f503f541383f","banner":null,"lang":"en","date_modified":"2023-11-02","date_modified_ts":"2023-11-02T19:23:51Z","date_created":"2023-11-02T19:16:42Z","summary":null,"body":["<article data-history-node-id=\"4717\" about=\"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-673\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-673<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 2, 2023<\/p>\n\n<p>On November 2, 2023, CISA published an ICS Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>EasyBuilder Pro \u2013 versions prior to v6.07.02<\/li>\n\t<li>EasyBuilder Pro \u2013 versions 6.08.01.592 and prior<\/li>\n\t<li>EasyBuilder Pro \u2013 versions 6.08.02.470 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-306-05\">ICS Advisory \u2013 ICSA-23-306-05<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-weintek-security-advisory-av23-673","alert_type":398,"serial_number":"AV23-673","subject":"other","moderation_state":"published","external_url":null},{"nid":4719,"title":"Microsoft Edge security advisory (AV23-674)","uuid":"d0dbff8b-16ad-4bdc-b8bb-dd99fb6de975","banner":null,"lang":"en","date_modified":"2023-11-03","date_modified_ts":"2023-11-03T19:36:44Z","date_created":"2023-11-03T19:33:13Z","summary":null,"body":["<article data-history-node-id=\"4719\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-674\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-674<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 3, 2023<\/p>\n\n<p>On November 2, 2023, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 119.0.2151.44<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-2-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-674","alert_type":396,"serial_number":"AV23-674","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4721,"title":"IBM security advisory (AV23-675)","uuid":"8f42dd3b-6ef6-4c1e-a069-9851eee8d9f1","banner":null,"lang":"en","date_modified":"2023-11-06","date_modified_ts":"2023-11-06T18:25:53Z","date_created":"2023-11-06T18:24:33Z","summary":null,"body":["<article data-history-node-id=\"4721\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-675\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-675<br \/><strong>Date: <\/strong>November\u00a06, 2023<\/p>\n\n<p>Between October\u00a030 and November\u00a05, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Platform Navigator in IBM Cloud Pak for Integration (CP4I) \u2013 multiple versions<\/li>\n\t<li>Automation Assets in IBM Cloud Pak for Integration (CP4I) \u2013 multiple versions<\/li>\n\t<li>IBM Storage Ceph \u2013 version 5.3z1-z4 and versions prior to 6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7062415\">IBM Security Bulletin - 7062415<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7061954\">IBM Security Bulletin - 7061954<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-675","alert_type":396,"serial_number":"AV23-675","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4724,"title":"Dell security advisory (AV23-676)","uuid":"062c811d-fee6-46c2-a73d-1f4874bcc31c","banner":null,"lang":"en","date_modified":"2023-11-06","date_modified_ts":"2023-11-06T18:56:51Z","date_created":"2023-11-06T18:49:17Z","summary":null,"body":["<article data-history-node-id=\"4724\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-676\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-676<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 6, 2023<\/p>\n\n<p>Between October 30 and November 5, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Avamar NDMP Accelerator \u2013 multiple versions<\/li>\n\t<li>Dell Avamar Server Hardware Appliance Gen4T, Gen5A \u2013 multiple versions<\/li>\n\t<li>Dell Avamar Virtual Edition \u2013 multiple versions<\/li>\n\t<li>Dell Avamar VMware Image Proxy \u2013 multiple versions<\/li>\n\t<li>Dell NetWorker Virtual Edition (NVE) \u2013 multiple versions<\/li>\n\t<li>Dell PowerProtect DP Series Appliance \/ Dell Integrated Data Protection Appliance (IDPA) \u2013 version 2.7.x and version 2.6.x<\/li>\n\t<li>Dell PowerScale OneFS \u2013 version 9.5.0.0 to 9.5.0.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219029\/dsa-2023-410-security-update-for-dell-avamar-dell-networker-virtual-edition-nve-and-dell-powerprotect-dp-series-appliance-dell-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities\">Dell Security Update - DSA-2023-410<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219104\/dell-powerscale-onefs-security-updates\">Dell Security Update - DSA-2023-411<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-676","alert_type":396,"serial_number":"AV23-676","subject":"dell","moderation_state":"published","external_url":null},{"nid":4725,"title":"Ubuntu security advisory (AV23-677)","uuid":"e440ab95-28c4-4f01-ad21-e6641fb232c1","banner":null,"lang":"en","date_modified":"2023-11-06","date_modified_ts":"2023-11-06T19:05:56Z","date_created":"2023-11-06T19:02:04Z","summary":null,"body":["<article data-history-node-id=\"4725\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-677-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-677<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 6, 2023<\/p>\n\n<p>Between October 30 and November 5, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-677-0","alert_type":396,"serial_number":"AV23-677","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4726,"title":"SolarWinds security advisory (AV23-678)","uuid":"40c7334a-e82c-40e1-8a93-6c3b3b5380b7","banner":null,"lang":"en","date_modified":"2023-11-06","date_modified_ts":"2023-11-06T20:48:33Z","date_created":"2023-11-06T20:47:42Z","summary":null,"body":["<article data-history-node-id=\"4726\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av23-678\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-678<br \/><strong>Date: <\/strong>November\u00a06, 2023<\/p>\n\n<p>On November\u00a01, 2023, SolarWinds published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Network Configuration Manager \u2013 version 2023.3.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2023-33227\">SolarWinds Security Advisory \u2013 CVE-2023-33227<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av23-678","alert_type":396,"serial_number":"AV23-678","subject":"other","moderation_state":"published","external_url":null},{"nid":4727,"title":"Red Hat security advisory (AV23-679)","uuid":"79a1b9ad-752f-4edb-a1f3-e267f1eb6d97","banner":null,"lang":"en","date_modified":"2023-11-07","date_modified_ts":"2023-11-07T16:47:08Z","date_created":"2023-11-07T16:43:32Z","summary":null,"body":["<article data-history-node-id=\"4727\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-679\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-679<br \/><strong>Date: <\/strong>November 7, 2023<\/p>\n\n<p>On November 6, 2023, Red Hat published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Redis RedisGraph\u00a0\u2013 version v.2.x to v.2.12.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2023-47004\">Red Hat Security Advisory\u00a0\u2013 CVE-2023-47004<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-679","alert_type":396,"serial_number":"AV23-679","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4728,"title":"[Control systems] General Electric security advisory (AV23-680) ","uuid":"f3f2f31f-dcb5-4602-b21d-f5f87509ddd9","banner":null,"lang":"en","date_modified":"2023-11-07","date_modified_ts":"2023-11-07T20:04:13Z","date_created":"2023-11-07T20:01:31Z","summary":null,"body":["<article data-history-node-id=\"4728\" about=\"\/en\/alerts-advisories\/control-systems-general-electric-security-advisory-av23-680\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-680<br \/><strong>Date: <\/strong>November 7, 2023<\/p>\n\n<p>On November 7, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>General Electric MiCOM S1 Agile\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-311-23\">ICS Advisory\u00a0\u2013 ICSA-23-311-23<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-general-electric-security-advisory-av23-680","alert_type":398,"serial_number":"AV23-680","subject":"other","moderation_state":"published","external_url":null},{"nid":4729,"title":"Google Chrome security advisory (AV23-681)","uuid":"65d7c98c-ba85-4c17-acee-2443f090800f","banner":null,"lang":"en","date_modified":"2023-11-08","date_modified_ts":"2023-11-08T16:13:37Z","date_created":"2023-11-08T15:47:29Z","summary":null,"body":["<article data-history-node-id=\"4729\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-681\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-681<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November\u00a08, 2023<\/p>\n\n<p>On November\u00a07, 2023, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 119.0.6045.123 (Mac and Linux) and 119.0.6045.123\/.124 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/11\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-681","alert_type":396,"serial_number":"AV23-681","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4730,"title":"SysAid security advisory (AV23-682)","uuid":"1ac20a40-6498-446f-9281-ba33f86d0c20","banner":null,"lang":"en","date_modified":"2023-11-09","date_modified_ts":"2023-11-09T18:22:48Z","date_created":"2023-11-09T18:16:06Z","summary":null,"body":["<article data-history-node-id=\"4730\" about=\"\/en\/alerts-advisories\/sysaid-security-advisory-av23-682\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-682<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date:<\/strong>November 9, 2023<\/p>\n\n<p>On November 8, 2023, SysAid published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SysAid IT Support Software\u00a0\u2013 versions prior to 23.3.36<\/li>\n<\/ul><p>SysAid has received reports that CVE-2023-47246 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sysaid.com\/blog\/service-desk\/on-premise-software-security-vulnerability-notification\">SysAid Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sysaid-security-advisory-av23-682","alert_type":396,"serial_number":"AV23-682","subject":"other","moderation_state":"published","external_url":null},{"nid":4731,"title":"[Control systems] Johnson Controls security advisory (AV23-683)","uuid":"bbd0ea27-4322-4af2-be75-491f704933ea","banner":null,"lang":"en","date_modified":"2023-11-09","date_modified_ts":"2023-11-09T19:19:51Z","date_created":"2023-11-09T18:32:12Z","summary":null,"body":["<article data-history-node-id=\"4731\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-683\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-683<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 9, 2023<\/p>\n\n<p>On November 9, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Quantum HD Unity Compressor control panels (Q5)\u00a0\u2013 versions prior to v11.22<\/li>\n\t<li>Quantum HD Unity Compressor control panels (Q6)\u00a0\u2013 versions prior to v12.22<\/li>\n\t<li>Quantum HD Unity AcuAir control panels (Q5)\u00a0\u2013 versions prior to v11.12<\/li>\n\t<li>Quantum HD Unity AcuAir control panels (Q6)\u00a0\u2013 versions prior to v12.12<\/li>\n\t<li>Quantum HD Unity Condenser\/Vessel control panels (Q5)\u00a0\u2013 versions prior to v11.11<\/li>\n\t<li>Quantum HD Unity Condenser\/Vessel control panels (Q6)\u00a0\u2013 versions prior to v12.11<\/li>\n\t<li>Quantum HD Unity Evaporator control panels (Q5)\u00a0\u2013 versions prior to v11.11<\/li>\n\t<li>Quantum HD Unity Evaporator control panels (Q6)\u00a0\u2013 versions prior to v12.11<\/li>\n\t<li>Quantum HD Unity Engine Room control panels (Q5)\u00a0\u2013 versions prior to v11.11<\/li>\n\t<li>Quantum HD Unity Engine Room control panels (Q6)\u00a0\u2013 versions prior to v12.11<\/li>\n\t<li>Quantum HD Unity Interface control panels (Q5)\u00a0\u2013 versions prior to v11.11<\/li>\n\t<li>Quantum HD Unity Interface control panels (Q6)\u00a0\u2013 versions prior to v12.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-313-01\">ICS Advisory\u00a0\u2013 ICSA-23-313-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-683","alert_type":398,"serial_number":"AV23-683","subject":"other","moderation_state":"published","external_url":null},{"nid":4732,"title":"[Control systems] Hitachi Energy security advisory (AV23-684) ","uuid":"0eb6dd5f-409a-41c8-966d-682453c87bf1","banner":null,"lang":"en","date_modified":"2023-11-09","date_modified_ts":"2023-11-09T19:42:52Z","date_created":"2023-11-09T19:25:57Z","summary":null,"body":["<article data-history-node-id=\"4732\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-684\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-684<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 9, 2023<\/p>\n\n<p>On November 9, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>eSOMS\u00a0\u2013 version v6.3.13 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-313-02\">ICS Advisory\u00a0\u2013 ICSA-23-313-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-684","alert_type":396,"serial_number":"AV23-684","subject":"other","moderation_state":"published","external_url":null},{"nid":4733,"title":"Microsoft Edge security advisory (AV23-685)","uuid":"1ff67951-dd95-438f-8966-e7cf9fde4148","banner":null,"lang":"en","date_modified":"2023-11-10","date_modified_ts":"2023-11-10T15:44:19Z","date_created":"2023-11-10T15:27:55Z","summary":null,"body":["<article data-history-node-id=\"4733\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-685\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-685<br \/><strong>Date: <\/strong>November 10, 2023<\/p>\n\n<p>On November 9, 2023, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 118.0.2088.102<\/li>\n\t<li>Microsoft Edge Stable Channel \u2013 versions prior to 119.0.2151.58<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-9-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-685","alert_type":396,"serial_number":"AV23-685","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4734,"title":"Dell security advisory (AV23-687)","uuid":"a30a9fe7-05a9-4148-a8d9-940b4c336cb0","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T15:15:31Z","date_created":"2023-11-14T14:49:53Z","summary":null,"body":["<article data-history-node-id=\"4734\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-687\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-687<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>Between November 6 and November 12, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell NetWorker Virtual Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Secure Connect Gateway\u00a0\u2013 version 5.18.00.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219309\/dsa-2023-413-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-413<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219248\/dsa-2023-056-security-update-for-dell-networker-virtual-edition-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-056<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-687","alert_type":396,"serial_number":"AV23-687","subject":"dell","moderation_state":"published","external_url":null},{"nid":4735,"title":"Ubuntu security advisory (AV23-686)","uuid":"40cbcc87-ca0f-4141-ba00-1affaeabcfd3","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T16:00:08Z","date_created":"2023-11-14T15:17:17Z","summary":null,"body":["<article data-history-node-id=\"4735\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-686\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-686<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>Between November 6 and November 12, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6465-3\">Ubuntu Security Notice (USN-6465-3)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6462-2\">Ubuntu Security Notice (USN-6462-2)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-686","alert_type":396,"serial_number":"AV23-686","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4736,"title":"IBM security advisory (AV23-688)","uuid":"56a62b5f-fae3-4f53-991a-525e6082d37f","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T16:22:33Z","date_created":"2023-11-14T16:17:20Z","summary":null,"body":["<article data-history-node-id=\"4736\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-688\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-688<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>Between November 6 and November 12, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>IBM Event Streams\u00a0\u2013 version 10.0.0 to 11.2.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7067435\">IBM Security Bulletin\u00a0- 7067435<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-688","alert_type":396,"serial_number":"AV23-688","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4737,"title":"Android security advisory \u2013 November 2023 Monthly Rollup (AV23-689)","uuid":"31b0cada-1f92-4093-be71-6a1fa4b90454","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T16:33:35Z","date_created":"2023-11-14T16:29:25Z","summary":null,"body":["<article data-history-node-id=\"4737\" about=\"\/en\/alerts-advisories\/android-security-advisory-november-2023-monthly-rollup-av23-689\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-689<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 6, 2023, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-11-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-november-2023-monthly-rollup-av23-689","alert_type":396,"serial_number":"AV23-689","subject":"android","moderation_state":"published","external_url":null},{"nid":4738,"title":"Ivanti security advisory (AV23-690)","uuid":"e67797ab-05c0-4b9e-8ef9-dd14757bbea2","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T16:49:54Z","date_created":"2023-11-14T16:45:05Z","summary":null,"body":["<article data-history-node-id=\"4738\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-690\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-690<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 9, 2023, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Endpoint Manager Mobile \u2013 multiple versions<\/li>\n\t<li>Ivanti Secure Access Client \u2013 versions prior to 22.6R1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-39335?language=en_US\">Ivanti Security Advisory - CVE-2023-39335<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-fixes-included-in-the-latest-Ivanti-Secure-Access-Client-Release?language=en_US \">Ivanti - Security fixes included in the latest Ivanti Secure Access Client Release<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-690","alert_type":396,"serial_number":"AV23-690","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4740,"title":"[Control systems] Siemens security advisory (AV23-692)","uuid":"1b9a9645-b845-4c23-a0fd-274ae563cc7e","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T20:01:25Z","date_created":"2023-11-14T19:11:44Z","summary":null,"body":["<article data-history-node-id=\"4740\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-692\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-692<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>COMOS\u00a0\u2013 multiple versions<\/li>\n\t<li>Desigo CC family\u00a0\u2013 multiple versions<\/li>\n\t<li>SCALANCE XB-200\/XC-200\/XP-200\/XF-200BA\/XR-300WG Family\u00a0\u2013 versions prior to 4.5<\/li>\n\t<li>SIMATIC MV500\u00a0\u2013 versions prior to 3.3.5<\/li>\n\t<li>SINEC PNI\u00a0\u2013 versions prior to 2.0<\/li>\n\t<li>SIPROTEC 4 7SJ66\u00a0\u2013 versions prior to 4.41<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-692","alert_type":398,"serial_number":"AV23-692","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4742,"title":"[Control systems] Schneider Electric security advisory (AV23-693)","uuid":"c7490638-665c-41d9-816e-e59e34f8e261","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T20:03:34Z","date_created":"2023-11-14T19:26:36Z","summary":null,"body":["<article data-history-node-id=\"4742\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-693\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-693<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14, 2023, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ExoStructure Power Monitoring Expert 2020\u00a0\u2013 versions prior to CU3<\/li>\n\t<li>ExoStructure Power Monitoring Expert 2021\u00a0\u2013 versions prior to CU2<\/li>\n\t<li>ExoStructure Power Operation Advanced Reporting and Dashboards Module 2021\u00a0\u2013 versions prior to CU2<\/li>\n\t<li>ExoStructure Power SCADA Operation Advanced Reporting and Dashboards Module 2020\u00a0\u2013 versions prior to CU3<\/li>\n\t<li>ION8650\u00a0\u2013 all versions<\/li>\n\t<li>ION8800\u00a0\u2013 all versions<\/li>\n\t<li>Galaxy VL\u00a0\u2013 version 12.21<\/li>\n\t<li>Galaxy VS\u00a0\u2013 version 6.82<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-318-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-318-01.pdf\">Schneider Electric Security Notification - SEVD-2023-318-01 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-318-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-318-02.pdf\">Schneider Electric Security Notification - SEVD-2023-318-02 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-318-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-318-03.pdf\">Schneider Electric Security Notification - SEVD-2023-318-03 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-693","alert_type":398,"serial_number":"AV23-693","subject":"other","moderation_state":"published","external_url":null},{"nid":4741,"title":"SAP security advisory \u2013 November 2023 monthly rollup (AV23-691)","uuid":"3f547807-3154-48b7-b579-235bd0be8a99","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T19:46:03Z","date_created":"2023-11-14T19:41:36Z","summary":null,"body":["<article data-history-node-id=\"4741\" about=\"\/en\/alerts-advisories\/sap-security-advisory-november-2023-monthly-rollup-av23-691\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-691<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November\u00a014,\u00a02023, SAP published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>SAP Business One \u2013 version 10.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day \u2013 November 2023<\/a><\/li>\n\t<li>\u00a0<\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-november-2023-monthly-rollup-av23-691","alert_type":396,"serial_number":"AV23-691","subject":"sap","moderation_state":"published","external_url":null},{"nid":4743,"title":"Adobe security advisory (AV23-694)","uuid":"4e5d6c26-68ae-4607-ab72-219cba4a3fb7","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T20:15:25Z","date_created":"2023-11-14T20:03:56Z","summary":null,"body":["<article data-history-node-id=\"4743\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-694\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-694<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14, 2023, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe ColdFusion\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe RoboHelp Server\u00a0\u2013 version RHS 11.4 and prior<\/li>\n\t<li>Adobe Acrobat DC and Acrobat Reader DC\u00a0\u2013 version 23.006.20360 and prior<\/li>\n\t<li>Adobe Acrobat 2020 and Acrobat Reader 2020\u00a0\u2013 version 20.005.30524 and prior<\/li>\n\t<li>Adobe FrameMaker Publishing Server\u00a0\u2013 version 2022 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Audition\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Premiere Pro\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe After Effects\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-694","alert_type":396,"serial_number":"AV23-694","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4744,"title":"[Control systems] Rockwell Automation security advisory (AV23-695) ","uuid":"702dbaa3-27d1-4f98-b07a-f4648331b2f9","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T20:32:02Z","date_created":"2023-11-14T20:24:49Z","summary":null,"body":["<article data-history-node-id=\"4744\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-695\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-695<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14, 2023, CISA published ICS advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>SIS Workstation\u00a0\u2013 version 1.2 up to but not including 2.00<\/li>\n\t<li>ISaGRAF Workbench\u00a0\u2013 version 6.6.9 up to but not including 6.06.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-318-02\">ICS Advisory\u00a0- ICSA-23-318-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av23-695","alert_type":398,"serial_number":"AV23-695","subject":"other","moderation_state":"published","external_url":null},{"nid":4746,"title":"[Control systems] AVEVA security advisory (AV23-697) ","uuid":"a82af00d-ba14-48c6-b957-1f6163a97789","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T20:33:38Z","date_created":"2023-11-14T20:26:52Z","summary":null,"body":["<article data-history-node-id=\"4746\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av23-697\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-697<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA SystemPlatform\u00a0- version 2020 R2 SP1 P01 and prior<\/li>\n\t<li>AVEVA Historian\u00a0- version 2020 R2 SP1 P01 and prior<\/li>\n\t<li>AVEVA Application Server\u00a0- version 2020 R2 SP1 P01 and prior<\/li>\n\t<li>AVEVA InTouch\u00a0- version 2020 R2 SP1 P01 and prior<\/li>\n\t<li>AVEVA Enterprise Licensing\u00a0- version 3.7.002 and prior<\/li>\n\t<li>AVEVA Manufacturing Execution System\u00a0- version 2020 P01 and prior<\/li>\n\t<li>AVEVA Recipe Management\u00a0- version 2020 R2 Update 1 Patch 2 and prior<\/li>\n\t<li>AVEVA Batch Management\u00a0- version 2020 SP1 and prior<\/li>\n\t<li>AVEVA Edge\u00a0- version 2020 R2 SP1 P01 and prior<\/li>\n\t<li>AVEVA Worktasks \u00a0- version 2020 U2 and prior<\/li>\n\t<li>AVEVA Plant SCADA\u00a0- version 2020 R2 Update 15 and prior<\/li>\n\t<li>AVEVA Mobile Operator\u00a0- version 2020 R1 and prior<\/li>\n\t<li>AVEVA Communication Drivers Pack\u00a0- version 2020 R2 SP1 and prior<\/li>\n\t<li>AVEVA Telemetry Server\u00a0- version 2020 R2 SP1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-318-01 \">ICS Advisory \u2013 ICSA-23-318-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av23-697","alert_type":398,"serial_number":"AV23-697","subject":"other","moderation_state":"published","external_url":null},{"nid":4745,"title":"Fortinet security advisory (AV23-696)","uuid":"68416dd7-1464-477a-98b7-0565d92bcd04","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T20:35:39Z","date_created":"2023-11-14T20:28:30Z","summary":null,"body":["<article data-history-node-id=\"4745\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-696\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-696<br \/><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14, 2023, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiADC\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiGate FGT_VM64_KVM\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiSIEM\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiWAN\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiWLM\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-696","alert_type":396,"serial_number":"AV23-696","subject":"other","moderation_state":"published","external_url":null},{"nid":4747,"title":"Intel security advisory (AV23-698)","uuid":"6d4036dc-be68-4d17-8e16-797930172065","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T20:34:25Z","date_created":"2023-11-14T20:29:30Z","summary":null,"body":["<article data-history-node-id=\"4747\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av23-698\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-698<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14,\u00a02023, Intel published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Intel Server Board BIOS \u2013 multiple versions and platforms<\/li>\n\t<li>Intel QAT Library \u2013 versions prior to 22.07.1<\/li>\n\t<li>Intel QAT driver for Windows \u2013 multiple versions and platforms<\/li>\n\t<li>Intel OFU software \u2013 versions prior to 14.1.31<\/li>\n\t<li>Intel Data Center Manager software \u2013 versions prior to 5.2<\/li>\n\t<li>Intel NUC \u2013 multiple versions and platforms<\/li>\n\t<li>Intel Connectivity Performance Suite software \u2013 versions prior to 2.1123.214.2<\/li>\n\t<li>Intel Core Processors \u2013 multiple platforms<\/li>\n\t<li>Intel Xeon Processors \u2013 multiple platforms<\/li>\n\t<li>Intel Unison software \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av23-698","alert_type":396,"serial_number":"AV23-698","subject":"intel","moderation_state":"published","external_url":null},{"nid":4748,"title":"Google Chrome security advisory (AV23-699)","uuid":"a71abf91-5bbe-40c3-93cf-689cebf2b649","banner":null,"lang":"en","date_modified":"2023-11-14","date_modified_ts":"2023-11-14T22:04:18Z","date_created":"2023-11-14T22:00:32Z","summary":null,"body":["<article data-history-node-id=\"4748\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-699\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-699<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 14, 2023<\/p>\n\n<p>On November 14, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 119.0.6045.159 (Mac and Linux) and 119.0.6045.159\/.160 (Windows)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/11\/stable-channel-update-for-desktop_14.html \">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-699","alert_type":396,"serial_number":"AV23-699","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4749,"title":"Microsoft security advisory \u2013 November 2023 monthly rollup (AV23-700)","uuid":"a232f14e-c37a-4243-b37a-dba4220c0f89","banner":null,"lang":"en","date_modified":"2023-11-15","date_modified_ts":"2023-11-15T15:03:19Z","date_created":"2023-11-15T14:40:33Z","summary":null,"body":["<article data-history-node-id=\"4749\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-november-2023-monthly-rollup-av23-700\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-700<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November\u00a015, 2023<\/p>\n\n<p>On November\u00a014, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Windows 10\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple platforms<\/li>\n\t<li>Azure CLI\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2023-36025 and CVE-2023-36036 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Nov\">November 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-november-2023-monthly-rollup-av23-700","alert_type":396,"serial_number":"AV23-700","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4750,"title":"HPE security advisory (AV23-701)","uuid":"2bead9fb-f26d-470a-9526-d2ccf77b7acb","banner":null,"lang":"en","date_modified":"2023-11-15","date_modified_ts":"2023-11-15T15:17:55Z","date_created":"2023-11-15T15:07:05Z","summary":null,"body":["<article data-history-node-id=\"4750\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-701\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-701<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November\u00a015, 2023<\/p>\n\n<p>On November\u00a015, 2023, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>ArubaOS\u00a0\u2013 multiple versions<\/li>\n\t<li>InstantOS\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Synergy 480 Gen10 Plus Compute Module\u00a0\u2013 versions prior to 1.90_10-19-2023<\/li>\n\t<li>HPE SimpliVity 380 Gen10 Plus\u00a0\u2013 versions prior to OmniStack Firmware 2023_0913<\/li>\n\t<li>HPE ProLiant Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Cray EX235n Server\u00a0\u2013 versions prior to 1.3.1 (HFP 23.9)<\/li>\n\t<li>HPE Cray Compute Blade\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE StoreEasy Storage\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-701","alert_type":396,"serial_number":"AV23-701","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4751,"title":"VMware security advisory (AV23-702)","uuid":"493cf0b8-1092-4b2e-a4ea-f9e632fca3fe","banner":null,"lang":"en","date_modified":"2023-11-15","date_modified_ts":"2023-11-15T18:13:23Z","date_created":"2023-11-15T18:07:22Z","summary":null,"body":["<article data-history-node-id=\"4751\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av23-702\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-702<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 15, 2023<\/p>\n\n<p>On November 14, 2023, VMware published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Cloud Director Appliance\u00a0\u2013 version 10.5 if upgraded from 10.4.x or below<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0026.html\">VMware Security Advisory\u00a0- VMSA-2023-0026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av23-702","alert_type":396,"serial_number":"AV23-702","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4752,"title":"Citrix security advisory (AV23-703)","uuid":"cf1a8c99-c902-473b-ac8c-7a320790225f","banner":null,"lang":"en","date_modified":"2023-11-15","date_modified_ts":"2023-11-15T20:18:24Z","date_created":"2023-11-15T20:10:33Z","summary":null,"body":["<article data-history-node-id=\"4752\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av23-703\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-703<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 15, 2023<\/p>\n\n<p>On November 15, 2023, Citrix published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Citrix Hypervisor\u00a0\u2013 version 2 CU1 LTSR<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX583037\/citrix-hypervisor-security-bulletin-for-cve202323583-and-cve202346835\">Citrix Security Advisory\u00a0- CTX583037<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center\/search#\/All%20Products?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av23-703","alert_type":396,"serial_number":"AV23-703","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4753,"title":"Juniper Networks security advisory (AV23-704)","uuid":"cf5320f2-3206-4427-b7f1-d62c4e237830","banner":null,"lang":"en","date_modified":"2023-11-16","date_modified_ts":"2023-11-16T14:49:29Z","date_created":"2023-11-16T14:32:19Z","summary":null,"body":["<article data-history-node-id=\"4753\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-704\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-704<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 16, 2023<\/p>\n\n<p>On November 16, 2023, Juniper Networks published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Juniper Secure Analytics\u00a0\u2013 versions prior to 7.5.0 UP7 IF02<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2023-11-Security-Bulletin-JSA-Series-Multiple-vulnerabilities-resolved?language=en_US\">Juniper Networks Security Advisories\u00a0- JSA74298<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-704","alert_type":396,"serial_number":"AV23-704","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4754,"title":"[Control systems] Hitachi Energy security advisory (AV23-705) ","uuid":"8114b27a-8b3b-4e2c-9696-6e5d8709bdfe","banner":null,"lang":"en","date_modified":"2023-11-16","date_modified_ts":"2023-11-16T18:28:28Z","date_created":"2023-11-16T18:24:32Z","summary":null,"body":["<article data-history-node-id=\"4754\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-705\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-705\n  <br \/><strong>Date: <\/strong>November 16, 2023\n<\/p>\n<p>On November 16, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:\n<\/p>\n<ul><li>Hitachi MACH SSW\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-320-02\">ICS Advisory\u00a0\u2013 ICSA-23-320-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-energy-security-advisory-av23-705","alert_type":398,"serial_number":"AV23-705","subject":"other","moderation_state":"published","external_url":null},{"nid":4755,"title":"[Control systems] Red Lion security advisory (AV23-706) ","uuid":"51b728ae-fcc0-4902-be9c-a5ba4e61f28b","banner":null,"lang":"en","date_modified":"2023-11-16","date_modified_ts":"2023-11-16T18:34:38Z","date_created":"2023-11-16T18:30:40Z","summary":null,"body":["<article data-history-node-id=\"4755\" about=\"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory-av23-706\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-706<br \/><strong>Date: <\/strong>November 16, 2023<\/p>\n\n<p>On November 16, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ST-IPm-8460\u00a0\u2013 firmware version 6.0.202 and later<\/li>\n\t<li>ST-IPm-6350\u00a0\u2013 firmware version 4.9.114 and later<\/li>\n\t<li>VT-mIPm-135-D\u00a0\u2013 firmware version 4.9.114 and later<\/li>\n\t<li>VT-mIPm-245-D\u00a0\u2013 firmware version 4.9.114 and later<\/li>\n\t<li>VT-IPm2m-213-D\u00a0\u2013 firmware version 4.9.114 and later<\/li>\n\t<li>VT-IPm2m-113-D\u00a0\u2013 firmware version 4.9.114 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-320-01\">ICS Advisory \u2013 ICSA-23-320-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-red-lion-security-advisory-av23-706","alert_type":398,"serial_number":"AV23-706","subject":"other","moderation_state":"published","external_url":null},{"nid":4756,"title":"Microsoft Edge security advisory (AV23-707)","uuid":"dbc17f06-5ce5-4c1e-9ac7-ccb1f23c3ac0","banner":null,"lang":"en","date_modified":"2023-11-17","date_modified_ts":"2023-11-17T14:58:13Z","date_created":"2023-11-17T14:51:39Z","summary":null,"body":["<article data-history-node-id=\"4756\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-707\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-707<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 17, 2023<\/p>\n\n<p>On November 16, 2023, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 118.0.2088.109<\/li>\n\t<li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 119.0.2151.72<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-16-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-707","alert_type":396,"serial_number":"AV23-707","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4757,"title":"Trellix security advisory (AV23-708)","uuid":"69681f2f-390a-41ca-b838-d52115f456a5","banner":null,"lang":"en","date_modified":"2023-11-17","date_modified_ts":"2023-11-17T15:26:06Z","date_created":"2023-11-17T15:20:15Z","summary":null,"body":["<article data-history-node-id=\"4757\" about=\"\/en\/alerts-advisories\/trellix-security-advisory-av23-708\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-708<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 17, 2023<\/p>\n\n<p>On November 16, 2023, Trellix published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ePolicy Orchestrator \u201cOn-Premises\u201d\u00a0\u2013 versions prior to 5.10.0 SP1 UP2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kcm.trellix.com\/corporate\/index?page=content&amp;id=SB10410\">Trellix Security Advisory (SB10410)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportm.trellix.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter\">Trellix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trellix-security-advisory-av23-708","alert_type":396,"serial_number":"AV23-708","subject":"trellix","moderation_state":"published","external_url":null},{"nid":4762,"title":"Ubuntu security advisory (AV23-709)","uuid":"d4b8aae7-78b2-4443-992b-cc909f404d97","banner":null,"lang":"en","date_modified":"2023-11-20","date_modified_ts":"2023-11-20T19:40:03Z","date_created":"2023-11-20T19:31:59Z","summary":null,"body":["<article data-history-node-id=\"4762\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-709\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-709<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 20, 2023<\/p>\n\n<p>Between November 13 and November 19, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6479-1\">Ubuntu Security Notice\u00a0- USN-6479-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-709","alert_type":396,"serial_number":"AV23-709","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4763,"title":"IBM security advisory (AV23-710)","uuid":"24d41328-8ffb-437c-a09c-39ea73b65f11","banner":null,"lang":"en","date_modified":"2023-11-20","date_modified_ts":"2023-11-20T19:58:50Z","date_created":"2023-11-20T19:43:46Z","summary":null,"body":["<article data-history-node-id=\"4763\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-710\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-710<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 20, 2023<\/p>\n\n<p>Between November 13 and November 19, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Planning Analytics Workspace\u00a0\u2013 version 2.0<\/li>\n\t<li>IBM Storage Protect for Virtual Environments for Hyper-V\u00a0\u2013 version 8.1.0.0 to 8.1.19.0<\/li>\n\t<li>IBM Storage Protect for Virtual Environments for VMware\u00a0\u2013 version 8.1.0.0 to 8.1.19.0<\/li>\n\t<li>Operations Dashboard\u00a0\u2013 versions 2021.1.1, 2021.2.1, 2021.3.1, 2021.4.1 and 2022.2.1<\/li>\n\t<li>Watson Machine Learning Accelerator on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7079947\">IBM Security Bulletin\u00a0- 7079947<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7078751\">IBM Security Bulletin\u00a0\u2013 7078751<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7076970\">IBM Security Bulletin\u00a0\u2013 7076970<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7076269\">IBM Security Bulletin\u00a0- 7076269<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-710","alert_type":396,"serial_number":"AV23-710","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4765,"title":"Dell security advisory (AV23-711)","uuid":"248b98ca-7140-4ad8-a1c1-879823391dd4","banner":null,"lang":"en","date_modified":"2023-11-20","date_modified_ts":"2023-11-20T20:16:00Z","date_created":"2023-11-20T20:04:54Z","summary":null,"body":["<article data-history-node-id=\"4765\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-711\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-711<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 20, 2023<\/p>\n\n<p>Between November 13 and November 19, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance\u00a0\u2013 8.0.x versions prior to 8.0.200<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219486\/dsa-2023-408-security-update-for-dell-vxrail-multiple-third-party-component-vulnerabilities-8-0-200\">Dell Security Update\u00a0- DSA-2023-408<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-711","alert_type":396,"serial_number":"AV23-711","subject":"dell","moderation_state":"published","external_url":null},{"nid":4768,"title":"Red Hat security advisory (AV23-712)","uuid":"95481103-11da-4ab0-ab5f-e112336f68f0","banner":null,"lang":"en","date_modified":"2023-11-21","date_modified_ts":"2023-11-21T18:15:33Z","date_created":"2023-11-21T18:03:37Z","summary":null,"body":["<article data-history-node-id=\"4768\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-712\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-712<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 21, 2023<\/p>\n\n<p>On November 21, 2023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Desktop\u00a0\u2013 version 7 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Workstation\u00a0\u2013 version 7 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7382\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:7382<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7423\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:7423<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7434\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:7434<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-712","alert_type":396,"serial_number":"AV23-712","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4769,"title":"Mozilla security advisory (AV23-713)","uuid":"e71b05d7-abbb-48a9-b409-2842cb58d5e1","banner":null,"lang":"en","date_modified":"2023-11-21","date_modified_ts":"2023-11-21T18:29:39Z","date_created":"2023-11-21T18:20:42Z","summary":null,"body":["<article data-history-node-id=\"4769\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-713\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-713<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 21, 2023<\/p>\n\n<p>On November 21, 2023, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 120<\/li>\n\t<li>Firefox for iOS\u00a0\u2013 versions prior to 120<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.5<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-49\/\">Mozilla Security Advisory\u00a0- MFSA 2023-49<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-51\/\">Mozilla Security Advisory\u00a0- MFSA 2023-51<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-50\/\">Mozilla Security Advisory\u00a0- MFSA 2023-50<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-52\/\">Mozilla Security Advisory\u00a0- MFSA 2023-52<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-713","alert_type":396,"serial_number":"AV23-713","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4770,"title":"[Control systems] WAGO security advisory (AV23-715)","uuid":"df7cff99-ffbb-4c6b-9adf-280ac2029730","banner":null,"lang":"en","date_modified":"2023-11-21","date_modified_ts":"2023-11-21T20:24:26Z","date_created":"2023-11-21T19:58:19Z","summary":null,"body":["<article data-history-node-id=\"4770\" about=\"\/en\/alerts-advisories\/control-systems-wago-security-advisory-av23-715\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-715<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 21, 2023<\/p>\n\n<p>On November 21, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Compact Controller CC100\u00a0\u2013 multiple firmware versions<\/li>\n\t<li>Edge Controller\u00a0\u2013 multiple firmware versions<\/li>\n\t<li>PFC100\u00a0\u2013 multiple firmware versions<\/li>\n\t<li>PFC200\u00a0\u2013 multiple firmware versions<\/li>\n\t<li>Touch Panel 600 Series\u00a0\u2013 multiple firmware versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-325-01\">ICS Advisory\u00a0\u2013 ICSA-23-325-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-wago-security-advisory-av23-715","alert_type":398,"serial_number":"AV23-715","subject":"other","moderation_state":"published","external_url":null},{"nid":4771,"title":"[Control systems] Fuji Electric security advisory (AV23-714)","uuid":"c001d61f-311e-4cd4-9388-34e4433c518b","banner":null,"lang":"en","date_modified":"2023-11-21","date_modified_ts":"2023-11-21T20:18:44Z","date_created":"2023-11-21T20:13:15Z","summary":null,"body":["<article data-history-node-id=\"4771\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av23-714\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-714<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 21, 2023<\/p>\n\n<p>On November 21, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Tellus Lite V-Simulator\u00a0\u2013 versions prior to V4.0.19.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-325-02\">ICS Advisory\u00a0\u2013 ICSA-23-325-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av23-714","alert_type":398,"serial_number":"AV23-714","subject":"other","moderation_state":"published","external_url":null},{"nid":4772,"title":"HPE security advisory (AV23-716)","uuid":"43aa4bf3-50b8-4420-be93-7a35438b614c","banner":null,"lang":"en","date_modified":"2023-11-22","date_modified_ts":"2023-11-22T16:45:30Z","date_created":"2023-11-22T16:38:12Z","summary":null,"body":["<article data-history-node-id=\"4772\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-716\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-716<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 22, 2023<\/p>\n\n<p>On November 20, 2023, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HPE Edgeline e920, e920d and e920t Server Blades\u00a0\u2013 firmware versions prior to 1.78_10-31-2023<\/li>\n\t<li>HP-UX OpenSSL Software\u00a0\u2013 versions prior to A.01.01.01w.001<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04554en_us\">HPE Security Bulletin\u00a0- hpesbhf04554en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04564en_us\">HPE Security Bulletin\u00a0- hpesbux04564en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-716","alert_type":396,"serial_number":"AV23-716","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4773,"title":"Atlassian security advisory (AV23-717)","uuid":"fd9e5c52-3441-46b0-b704-41cf3258760f","banner":null,"lang":"en","date_modified":"2023-11-22","date_modified_ts":"2023-11-22T18:48:42Z","date_created":"2023-11-22T18:41:03Z","summary":null,"body":["<article data-history-node-id=\"4773\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-717\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-717<br \/><strong>Date: <\/strong>November 22, 2023<\/p>\n\n<p>On November 21, 2023, Atlassian published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo data center and server\u00a0\u2013 version 8.1.0 and later<\/li>\n\t<li>Bitbucket data center and server\u00a0\u2013 version 7.21.0 and later<\/li>\n\t<li>Confluence data center and server\u00a0\u2013 version 6.13.0 and later<\/li>\n\t<li>Crowd data center and server\u00a0\u2013 version 3.4.6 and later<\/li>\n\t<li>Jira software data center and server\u00a0\u2013 version 8.20.0 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-november-21-2023-1318881573.html\">Atlassian Security Bulletin\u00a0\u2013 November 21 2023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-717","alert_type":396,"serial_number":"AV23-717","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4774,"title":"Foxit security advisory (AV23-718)","uuid":"0e1ffd07-9832-4b38-bbe1-123d427bbaa1","banner":null,"lang":"en","date_modified":"2023-11-23","date_modified_ts":"2023-11-23T14:57:13Z","date_created":"2023-11-23T14:52:34Z","summary":null,"body":["<article data-history-node-id=\"4774\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av23-718\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-718<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 23, 2023<\/p>\n\n<p>On November 22, 2023, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor for Windows\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader for Windows\u00a0\u2013 version 2023.2.0.21408 and prior<\/li>\n\t<li>Foxit PDF Editor for Mac\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader for Mac\u00a0\u2013 version 2023.2.0.61611 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av23-718","alert_type":396,"serial_number":"AV23-718","subject":"other","moderation_state":"published","external_url":null},{"nid":4778,"title":"Dell security advisory (AV23-719)","uuid":"36baa061-303f-4129-bb8c-93eb4eab0e8c","banner":null,"lang":"en","date_modified":"2023-11-27","date_modified_ts":"2023-11-27T16:48:23Z","date_created":"2023-11-27T16:38:31Z","summary":null,"body":["<article data-history-node-id=\"4778\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-719\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-719<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 27, 2023<\/p>\n\n<p>Between November 20 and November 26, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Data Protection Advisor Agent\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerProtect Data Manager\u00a0\u2013 versions prior to 19.15<\/li>\n\t<li>PowerProtect Cyber Recovery\u00a0\u2013 19.14.0.2 and prior<\/li>\n\t<li>PowerStore 1000X\u00a0\u2013 versions prior to 7.0u3o<\/li>\n\t<li>PowerStore 3000X\u00a0\u2013 versions prior to 3.6.0.0-2145637<\/li>\n\t<li>PowerStore 5000X\u00a0\u2013 versions prior to 7.0u3o<\/li>\n\t<li>PowerStore 7000X\u00a0\u2013 versions prior to 7.0u3o<\/li>\n\t<li>PowerStore 9000X\u00a0\u2013 versions prior to 7.0u3o<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-719","alert_type":396,"serial_number":"AV23-719","subject":"dell","moderation_state":"published","external_url":null},{"nid":4779,"title":"Ubuntu security advisory (AV23-720)","uuid":"76927c47-f436-47b7-a452-eadc5baf87f0","banner":null,"lang":"en","date_modified":"2023-11-27","date_modified_ts":"2023-11-27T16:59:24Z","date_created":"2023-11-27T16:52:09Z","summary":null,"body":["<article data-history-node-id=\"4779\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-720\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-720<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 27, 2023<\/p>\n\n<p>Between November 20 and November 26, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 16.04 ESM<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 18.04 ESM<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 20.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 22.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 23.04<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-720","alert_type":396,"serial_number":"AV23-720","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4780,"title":"ownCloud security advisory (AV23-721)","uuid":"8515863e-9eb0-49c3-81a0-119bfc90d2d8","banner":null,"lang":"en","date_modified":"2023-11-28","date_modified_ts":"2023-11-28T18:23:20Z","date_created":"2023-11-27T19:32:43Z","summary":null,"body":["<article data-history-node-id=\"4780\" about=\"\/en\/alerts-advisories\/owncloud-security-advisory-av23-721\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-721<br \/><strong>Date: <\/strong>November 28, 2023<\/p>\n\n<p>On November 21, 2023, ownCloud published security advisories to address critical vulnerabilities in the following products::<\/p>\n\n<ul><li>ownCloud graphapi\u00a0\u2013 version 0.20 to 0.30<\/li>\n\t<li>ownCloud oauth2\u00a0\u2013 prior to version 0.6.1<\/li>\n\t<li>ownCloud core\u00a0\u2013 version 10.6.0 to 10.13.0<\/li>\n<\/ul><p>The Cyber Centre has received reports that CVE-2023-49103 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ownCloud.com\/security-advisories\/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments\/\">ownCloud Security Advisory\u00a0\u2013 graphapi<\/a><\/li>\n\t<li><a href=\"https:\/\/ownCloud.com\/security-advisories\/subdomain-validation-bypass\/\">ownCloud Security Advisory\u00a0\u2013 oauth2<\/a><\/li>\n\t<li><a href=\"https:\/\/ownCloud.com\/security-advisories\/webdav-api-authentication-bypass-using-pre-signed-urls\/\">ownCloud Security Advisory\u00a0\u2013 core<\/a><\/li>\n\t<li><a href=\"https:\/\/ownCloud.com\/security\">ownCloud Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/owncloud-security-advisory-av23-721","alert_type":396,"serial_number":"AV23-721","subject":"other","moderation_state":"published","external_url":null},{"nid":4782,"title":"Vulnerability CVE-2023-49103 impacting ownCloud file sharing application","uuid":"704b695f-10c1-4342-a15c-1caafea85f83","banner":null,"lang":"en","date_modified":"2023-11-28","date_modified_ts":"2023-11-28T21:14:37Z","date_created":"2023-11-28T20:24:36Z","summary":null,"body":["<article data-history-node-id=\"4782\" about=\"\/en\/alerts-advisories\/vulnerability-cve-2023-49103-impacting-owncloud-file-sharing-application\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-017<br \/><strong>Date: <\/strong>November 28, 2023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of three recent critical vulnerabilities <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> impacting ownCloud, an open-source file sync and sharing solution used to manage and share files hosted on-site. One of these vulnerabilities, CVE-2023-49103<span class=\"nowrap\"> <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/span>, leverages a flaw to obtain administrative passwords, mail server credentials and configuration information in containerized deployments. The Cyber Centre has received reports that this vulnerability has been exploited in the wild. <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/p>\n\n<p>This Alert is being published to raise awareness of CVE-2023-49103, to highlight the potential impact to organizations and to provide guidance for organizations who may be targeted by related malicious activity.<\/p>\n<\/section><section><h2>Suggested action<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Perform mitigations suggested by the vendor.<\/li>\n\t<li>Immediately patch affected systems when updates addressing this vulnerability become available.<\/li>\n\t<li>Permit internet access to your web applications based upon known good IP addresses or geographic location, where possible.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidate, monitor, and defend internet gateways<\/li>\n\t<li>Segment and separate information<\/li>\n\t<li>Isolate internet-facing applications<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/owncloud.com\/security-advisories\/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments\/\">ownCloud security advisory - Disclosure of sensitive credentials and configuration in containerized deployments<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/owncloud.com\/security-advisories\/subdomain-validation-bypass\/\">ownCloud security advisory - Subdomain Validation Bypass<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/owncloud.com\/security-advisories\/webdav-api-authentication-bypass-using-pre-signed-urls\/\">WebDAV Api Authentication Bypass using Pre-Signed URLs<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-49103\">CVE-2023-49103<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/owncloud-security-advisory-av23-721\">ownCloud security advisory AV23-721<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-start-exploiting-critical-owncloud-flaw-patch-now\/\">Hackers start exploiting critical ownCloud flaw, patch now<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">CCCS Top 10 IT security actions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-cve-2023-49103-impacting-owncloud-file-sharing-application","alert_type":397,"serial_number":"AL23-017","subject":"other","moderation_state":"published","external_url":null},{"nid":4783,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-722)","uuid":"d279d16d-ded6-403a-bb65-26d462798185","banner":null,"lang":"en","date_modified":"2023-11-29","date_modified_ts":"2023-11-29T13:59:47Z","date_created":"2023-11-29T13:51:17Z","summary":null,"body":["<article data-history-node-id=\"4783\" about=\"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av23-722\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-722<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 29, 2023<\/p>\n\n<p>On November 28, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>GX Works2\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-331-03\">ICS Advisory\u00a0\u2013 ICSA-23-331-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fuji-electric-security-advisory-av23-722","alert_type":398,"serial_number":"AV23-722","subject":"other","moderation_state":"published","external_url":null},{"nid":4784,"title":"[Control systems] Delta Electronics security advisory (AV23-723)","uuid":"a2bc6bf3-2541-4c25-9802-7accbd83600e","banner":null,"lang":"en","date_modified":"2023-11-29","date_modified_ts":"2023-11-29T14:07:14Z","date_created":"2023-11-29T14:00:09Z","summary":null,"body":["<article data-history-node-id=\"4784\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-723\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-723<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 29, 2023<\/p>\n\n<p>On November 28, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>InfraSuite Device Master\u00a0\u2013 version 1.0.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-331-01\">ICS Advisory\u00a0\u2013 ICSA-23-331-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-723","alert_type":398,"serial_number":"AV23-723","subject":"other","moderation_state":"published","external_url":null},{"nid":4785,"title":"[Control systems] Franklin Electric Fueling Systems security advisory (AV23-724)","uuid":"e560245e-4c65-42ba-95b3-45307836b918","banner":null,"lang":"en","date_modified":"2023-11-29","date_modified_ts":"2023-11-29T14:19:20Z","date_created":"2023-11-29T14:11:06Z","summary":null,"body":["<article data-history-node-id=\"4785\" about=\"\/en\/alerts-advisories\/control-systems-franklin-electric-fueling-systems-security-advisory-av23-724\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-724\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 29, 2023\n<\/p>\n<p>On November 28, 2023, CISA published an ICS advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>FFS Colibri\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-331-02\">ICS Advisory\u00a0\u2013 ICSA-23-331-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-franklin-electric-fueling-systems-security-advisory-av23-724","alert_type":398,"serial_number":"AV23-724","subject":"other","moderation_state":"published","external_url":null},{"nid":4787,"title":"[Control systems] Becton, Dickinson and Company security advisory (AV23-725)","uuid":"1816c3af-8aa1-4a6e-b6b5-0a0c3733820f","banner":null,"lang":"en","date_modified":"2023-11-29","date_modified_ts":"2023-11-29T14:46:26Z","date_created":"2023-11-29T14:30:15Z","summary":null,"body":["<article data-history-node-id=\"4787\" about=\"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-security-advisory-av23-725\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-725<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 29, 2023<\/p>\n\n<p>On November 28, 2023, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BD FACSChorus\u00a0\u2013 versions 5.0 and 5.1<\/li>\n\t<li>BD FACSChorus\u00a0\u2013 versions 3.0 and 3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-23-331-01\">ICS Advisory\u00a0\u2013 ICSMA-23-331-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-becton-dickinson-and-company-security-advisory-av23-725","alert_type":398,"serial_number":"AV23-725","subject":"other","moderation_state":"published","external_url":null},{"nid":4790,"title":"Google Chrome security advisory (AV23-726)","uuid":"df2e4e28-e958-4c90-8f8f-7b8afd11bfc4","banner":null,"lang":"en","date_modified":"2023-11-29","date_modified_ts":"2023-11-29T18:27:10Z","date_created":"2023-11-29T18:12:58Z","summary":null,"body":["<article data-history-node-id=\"4790\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-726\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-726<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 29, 2023<\/p>\n\n<p>On November 28, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 119.0.6045.199 (Mac and Linux) and 119.0.6045.199\/.200 (Windows)<\/li>\n<\/ul><p>Google has indicated that CVE-2023-6345 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/11\/stable-channel-update-for-desktop_28.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-726","alert_type":396,"serial_number":"AV23-726","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4791,"title":"Trellix security advisory (AV23-727)","uuid":"a1aeaba2-7876-4f39-a0d8-f8a6d6044687","banner":null,"lang":"en","date_modified":"2023-11-29","date_modified_ts":"2023-11-29T18:45:52Z","date_created":"2023-11-29T18:31:37Z","summary":null,"body":["<article data-history-node-id=\"4791\" about=\"\/en\/alerts-advisories\/trellix-security-advisory-av23-727\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-727<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 29, 2023<\/p>\n\n<p>On November 27 and 29, 2023, Trellix published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Trellix Application and Change Control (TACC)\u00a0\u2013 versions prior to 8.4.0<\/li>\n\t<li>Trellix Enterprise Security Manager (ESM)\u00a0\u2013 versions prior to 11.6.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kcm.trellix.com\/corporate\/index?page=content&amp;id=SB10411\">Trellix Security Advisory (SB10411)<\/a><\/li>\n\t<li><a href=\"https:\/\/kcm.trellix.com\/corporate\/index?page=content&amp;id=SB10413\">Trellix Security Advisory (SB10413)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportm.trellix.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter\">Trellix Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trellix-security-advisory-av23-727","alert_type":396,"serial_number":"AV23-727","subject":"trellix","moderation_state":"published","external_url":null},{"nid":4792,"title":"Red Hat security advisory (AV23-728)","uuid":"010b70b6-4aba-4673-9075-6c39e2091b74","banner":null,"lang":"en","date_modified":"2023-11-29","date_modified_ts":"2023-11-29T20:08:02Z","date_created":"2023-11-29T19:58:36Z","summary":null,"body":["<article data-history-node-id=\"4792\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-728\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-728<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 29, 2023<\/p>\n\n<p>On November 28 and 29, 2023, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7539\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:7539<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7549\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:7549<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7557\">Red Hat Security Advisory\u00a0\u2013 RHSA-2023:7557<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-728","alert_type":396,"serial_number":"AV23-728","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4793,"title":"Microsoft Edge security advisory (AV23-729)","uuid":"bc495c06-39ac-4083-b86f-4e4cf5511342","banner":null,"lang":"en","date_modified":"2023-11-30","date_modified_ts":"2023-11-30T19:19:53Z","date_created":"2023-11-30T19:16:15Z","summary":null,"body":["<article data-history-node-id=\"4793\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-729\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-729<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 30, 2023<\/p>\n\n<p>On November 29, 2023, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 118.0.2088.122<\/li>\n\t<li>Microsoft Edge Stable Channel \u2013 versions prior to 119.0.2151.97<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-29-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-729","alert_type":396,"serial_number":"AV23-729","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4794,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-730)","uuid":"c691469b-3267-4f42-a7eb-11f239210652","banner":null,"lang":"en","date_modified":"2023-11-30","date_modified_ts":"2023-11-30T19:27:35Z","date_created":"2023-11-30T19:16:57Z","summary":null,"body":["<article data-history-node-id=\"4794\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-730\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-730<br \/><strong>Date: <\/strong>November 30, 2023<\/p>\n\n<p>On November 30, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Mitsubishi GX Works3\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi MELSOFT iQ AppPortal\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi MELSOFT Navigator\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Motion Control Setting\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-334-04\">ICS Advisory\u00a0- ICSA-23-334-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-730","alert_type":398,"serial_number":"AV23-730","subject":"other","moderation_state":"published","external_url":null},{"nid":4795,"title":"[Control systems] Delta Electronics security advisory (AV23-731)","uuid":"9edc492b-e202-43ff-8663-fd4bf4da0de7","banner":null,"lang":"en","date_modified":"2023-11-30","date_modified_ts":"2023-11-30T19:27:45Z","date_created":"2023-11-30T19:22:59Z","summary":null,"body":["<article data-history-node-id=\"4795\" about=\"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-731\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-731<br \/><strong>Date: <\/strong>November 30, 2023<\/p>\n\n<p>On November 30, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>DOPSoft\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-334-01\">ICS Advisory\u00a0\u2013 ICSA-23-334-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-delta-electronics-security-advisory-av23-731","alert_type":398,"serial_number":"AV23-731","subject":"other","moderation_state":"published","external_url":null},{"nid":4796,"title":"[Control systems] PTC security advisory (AV23-732)","uuid":"d948d90f-5953-4932-a384-137e05da43f6","banner":null,"lang":"en","date_modified":"2023-11-30","date_modified_ts":"2023-11-30T19:26:58Z","date_created":"2023-11-30T19:23:39Z","summary":null,"body":["<article data-history-node-id=\"4796\" about=\"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-732\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-732<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 30, 2023<\/p>\n\n<p>On November 30, 2023, CISA published an ICS advisory to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>KEPServerEX \u2013 v6.14.263.0 and prior<\/li>\n\t<li>ThingWorx Kepware Server \u2013 v6.14.263.0 and prior<\/li>\n\t<li>ThingWorx Industrial Connectivity \u2013 all versions<\/li>\n\t<li>OPC-Aggregator \u2013 v6.14 and prior<\/li>\n\t<li>ThingWorx Kepware Edge \u2013 v1.7 and prior<\/li>\n\t<li>Rockwell Automation KEPServer Enterprise \u2013 v6.14.263.0 and prior<\/li>\n\t<li>GE Digital Industrial Gateway Server \u2013 v7.614 and prior<\/li>\n\t<li>Software Toolbox TOP Server \u2013 v6.14.263.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-334-03\">ICS Advisory - ICSA-23-334-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ptc-security-advisory-av23-732","alert_type":398,"serial_number":"AV23-732","subject":"other","moderation_state":"published","external_url":null},{"nid":4797,"title":"Apple security advisory (AV23-733)","uuid":"2de7d8c2-986c-47e7-9ad5-3cef9c24c73d","banner":null,"lang":"en","date_modified":"2023-11-30","date_modified_ts":"2023-11-30T21:15:13Z","date_created":"2023-11-30T21:07:01Z","summary":null,"body":["<article data-history-node-id=\"4797\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-733\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-733<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 30, 2023<\/p>\n\n<p>On November 30, 2023, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 17.1.2<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 17.1.2<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.1.2<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 17.1.2<\/li>\n<\/ul><p>Apple has received reports that CVE-2023-42916 and CVE-2023-42917 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT214031\">Apple Security Update\u00a0- HT214031<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT214032\">Apple Security Update\u00a0- HT214032<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT214033\">Apple Security Update\u00a0- HT214033<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-733","alert_type":396,"serial_number":"AV23-733","subject":"apple","moderation_state":"published","external_url":null},{"nid":4798,"title":"GitLab security advisory (AV23-734)","uuid":"5e75d4fe-9bb8-4c16-a87d-d6e32bdacdba","banner":null,"lang":"en","date_modified":"2023-11-30","date_modified_ts":"2023-11-30T21:21:58Z","date_created":"2023-11-30T21:16:57Z","summary":null,"body":["<article data-history-node-id=\"4798\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-734\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-734<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>November 30, 2023<\/p>\n\n<p>On November 30, 2023, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/11\/30\/security-release-gitlab-16-6-1-released\/ \">GitLab Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-734","alert_type":396,"serial_number":"AV23-734","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4799,"title":"Exploitation of Unitronics programmable logic controllers ","uuid":"89e2f349-f088-4704-883e-5ab8efd3f485","banner":null,"lang":"en","date_modified":"2023-12-01","date_modified_ts":"2023-12-01T19:29:10Z","date_created":"2023-12-01T18:30:30Z","summary":null,"body":["<article data-history-node-id=\"4799\" about=\"\/en\/alerts-advisories\/exploitation-unitronics-programmable-logic-controllers\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-018<br \/><strong>Date:\u00a0<\/strong>December 1, 2023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of reported exploitation of Unitronics programmable logic controllers (PLCs) used in the water and wastewater systems sector. The Cyber Centre recommends organizations review the guidance published by the Cybersecurity and Infrastructure Security Agency (CISA) about this activity and follow the recommended mitigations<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">ootnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>The risk to industrial control systems accessible from the Internet is not limited to Unitronics devices or the water and wastewater systems sector. The Cyber Centre recommends that organizations using industrial control systems review and implement the security guidance in the Cyber Centre's \"Security considerations for industrial control systems\"<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">otnote <\/span>2<\/a><\/sup>.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Review and implement the guidance published by CISA on the activity targeting Unitronics programmable logic controllers<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/li>\n\t<li>Review and implement the security mitigations in the Cyber Centre's \"Security considerations for industrial control systems\" guidance<sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/11\/28\/exploitation-unitronics-plcs-used-water-and-wastewater-systems\">Exploitation of Unitronics PLCs used in Water and Wastewater Systems<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/security-considerations-industrial-control-systems-itsap00050\">Security considerations for industrial control systems (ITSAP.00.050)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exploitation-unitronics-programmable-logic-controllers","alert_type":397,"serial_number":"AL23-018","subject":"other","moderation_state":"published","external_url":null},{"nid":4800,"title":"Dell security advisory (AV23-735)","uuid":"697706ea-1875-4619-a1c7-fd5a23c01310","banner":null,"lang":"en","date_modified":"2023-12-04","date_modified_ts":"2023-12-04T18:12:55Z","date_created":"2023-12-04T17:51:07Z","summary":null,"body":["<article data-history-node-id=\"4800\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-735\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-735<br \/><strong>Date: <\/strong>December 4, 2023<\/p>\n\n<p>Between November 27 and December 3, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cloud Tiering Appliance\u00a0\u2013 versions prior to 13.1.0.2.35<\/li>\n\t<li>Cloud Tiering Appliance\u00a0\u2013 versions prior to 13.2.0.2.26<\/li>\n\t<li>Disk Library for mainframe DLm2500\u00a0\u2013 versions prior to 5.5.0.4<\/li>\n\t<li>Disk Library for mainframe DLm8500\u00a0\u2013 versions prior to 5.5.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219978\/dsa-2023-453-security-update-for-dell-cloud-tiering-appliance-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- Cloud Tiering Appliance v13.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219980\/dsa-2023-454-security-update-for-dell-cloud-tiering-appliance-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- Cloud Tiering Appliance v13.2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219990\/dsa-2023-418-security-update-for-dell-emc-dlm-vulnerabilities\">Dell Security Update\u00a0- Disk Library for mainframe DLm2500<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000219990\/dsa-2023-418-security-update-for-dell-emc-dlm-vulnerabilities\">Dell Security Update\u00a0- Disk Library for mainframe DLm8500<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-735","alert_type":396,"serial_number":"AV23-735","subject":"dell","moderation_state":"published","external_url":null},{"nid":4801,"title":"IBM security advisory (AV23-736)","uuid":"18e6b540-f50c-4ab2-8c5f-b62c6f7f174c","banner":null,"lang":"en","date_modified":"2023-12-04","date_modified_ts":"2023-12-04T18:18:48Z","date_created":"2023-12-04T18:18:15Z","summary":null,"body":["<article data-history-node-id=\"4801\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-736\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-736<br \/><strong>Date: <\/strong>December 04, 2023<\/p>\n\n<p>Between November 27 and December 3, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>IBM Maximo Application Suite\u00a0\u2013 Monitor Component\u00a0\u2013 versions 8.10 and 8.11<\/li>\n\t<li>IBM Sterling B2B Integrator\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 4.7.4<\/li>\n\t<li>InfoSphere Information Server\u00a0\u2013 version 11.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7084134\">IBM Security Bulletin\u00a0- IBM Maximo Application Suite\u00a0- Monitor Component<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7084080\">IBM Security Bulletin\u00a0- IBM Sterling B2B Integrator<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7086116\">IBM Security Bulletin\u00a0- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7070765\">IBM Security Bulletin\u00a0- InfoSphere Information Server<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-736","alert_type":396,"serial_number":"AV23-736","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4802,"title":"Ubuntu security advisory (AV23-737)","uuid":"9b896236-dd04-4e7b-90b4-0b2b48858b97","banner":null,"lang":"en","date_modified":"2023-12-04","date_modified_ts":"2023-12-04T19:10:12Z","date_created":"2023-12-04T19:02:07Z","summary":null,"body":["<article data-history-node-id=\"4802\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-737\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-737<br \/><strong>Date: <\/strong>December 04, 2023<\/p>\n\n<p>Between November 27 and December 3, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6494-2\">Ubuntu Security Notice\u00a0\u2013 USN-6494-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6495-2\">Ubuntu Security Notice\u00a0\u2013 USN-6495-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6496-2\">Ubuntu Security Notice\u00a0\u2013 USN-6496-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6502-4\">Ubuntu Security Notice \u00a0\u2013 USN-6502-4<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-737","alert_type":396,"serial_number":"AV23-737","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4803,"title":"Android security advisory \u2013 December 2023 Monthly Rollup (AV23-738)","uuid":"5749d7cd-a048-450f-8e88-8735014e951e","banner":null,"lang":"en","date_modified":"2023-12-04","date_modified_ts":"2023-12-04T20:19:00Z","date_created":"2023-12-04T20:10:45Z","summary":null,"body":["<article data-history-node-id=\"4803\" about=\"\/en\/alerts-advisories\/android-security-advisory-december-2023-monthly-rollup-av23-738\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-738<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 4, 2023<\/p>\n\n<p>On December 4, 2023, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2023-12-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-december-2023-monthly-rollup-av23-738","alert_type":396,"serial_number":"AV23-738","subject":"android","moderation_state":"published","external_url":null},{"nid":4804,"title":"[Control systems] Zebra security advisory (AV23-739) ","uuid":"54dc376b-e000-4dec-a075-c5e597e85510","banner":null,"lang":"en","date_modified":"2023-12-05","date_modified_ts":"2023-12-05T16:54:47Z","date_created":"2023-12-05T16:48:30Z","summary":null,"body":["<article data-history-node-id=\"4804\" about=\"\/en\/alerts-advisories\/control-systems-zebra-security-advisory-av23-739\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-739<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 5, 2023<\/p>\n\n<p>On December 5, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ZTC Industrial ZT410\u00a0\u2013 All versions<\/li>\n\t<li>ZTC Desktop GK420d\u00a0\u2013 All versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-339-01\">ICS Advisory\u00a0\u2013 ICSA-23-339-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-zebra-security-advisory-av23-739","alert_type":398,"serial_number":"AV23-739","subject":"other","moderation_state":"published","external_url":null},{"nid":4805,"title":"Qualcomm security advisory (AV23-740)","uuid":"22a20b40-ee2c-4c1d-bcb7-dcd87c418c07","banner":null,"lang":"en","date_modified":"2023-12-06","date_modified_ts":"2023-12-06T14:18:49Z","date_created":"2023-12-05T21:32:00Z","summary":null,"body":["<article data-history-node-id=\"4805\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-av23-740\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-740<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 5, 2023<\/p>\n\n<p>On December 5, 2023, Qualcomm published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Qualcomm\u00a0\u2013 multiple chipsets<\/li>\n<\/ul><p>CISA has indicated that CVE-2022-22071, CVE-2023-33063, CVE-2023-33106 and CVE-2023-33107 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/december-2023-bulletin.html\">Qualcomm\u00a0\u2013 December 2023 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">CISA\u00a0\u2013 Known Exploited Vulnerabilities Catalog<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-av23-740","alert_type":396,"serial_number":"AV23-740","subject":"other","moderation_state":"published","external_url":null},{"nid":4807,"title":"Google Chrome security advisory (AV23-741)","uuid":"971f9bb6-3ad6-4196-a334-c099c5d9b89f","banner":null,"lang":"en","date_modified":"2023-12-06","date_modified_ts":"2023-12-06T14:59:26Z","date_created":"2023-12-06T14:48:37Z","summary":null,"body":["<article data-history-node-id=\"4807\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-741\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-741<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 6, 2023<\/p>\n\n<p>On December 5, 2023, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 120.0.6099.62\/.63 (Windows) and versions prior to 120.0.6099.62 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/12\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-741","alert_type":396,"serial_number":"AV23-741","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4808,"title":"Atlassian security advisory (AV23-742)","uuid":"cb9745c3-0da0-4252-ac6e-df74f6ba7758","banner":null,"lang":"en","date_modified":"2023-12-06","date_modified_ts":"2023-12-06T16:14:15Z","date_created":"2023-12-06T15:39:27Z","summary":null,"body":["<article data-history-node-id=\"4808\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-742\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-742<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 6, 2023<\/p>\n\n<p>On December 5, 2023, Atlassian published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Atlassian Companion App for MacOS\u00a0\u2013 versions prior to 2.0.0<\/li>\n\t<li>Assets Discovery\u00a0\u2013 multiple versions<\/li>\n\t<li>SnakeYAML library\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html\">SnakeYAML library RCE Vulnerability In Multiple Products<\/a><\/li>\n\t<li><a href=\"https:\/\/confluence.atlassian.com\/security\/cve-2023-22522-rce-vulnerability-in-confluence-data-center-and-confluence-server-1319570362.html\">RCE Vulnerability In Confluence Data Center and Confluence Server<\/a><\/li>\n\t<li><a href=\"https:\/\/confluence.atlassian.com\/security\/cve-2023-22524-rce-vulnerability-in-atlassian-companion-app-for-macos-1319249492.html\">RCE Vulnerability in Atlassian Companion App for MacOS<\/a><\/li>\n\t<li><a href=\"https:\/\/confluence.atlassian.com\/security\/cve-2023-22523-rce-vulnerability-in-assets-discovery-1319248914.html\">RCE Vulnerability in Assets Discovery<\/a><\/li>\n\t<li><a href=\"https:\/\/confluence.atlassian.com\/security\/december-2023-security-advisories-overview-1318892103.html\">Atlassian December 2023 Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-742","alert_type":396,"serial_number":"AV23-742","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4814,"title":"[Control systems] ControlbyWeb security advisory (AV23-743)","uuid":"ef2cfe5c-5b54-4146-9003-f852668e8787","banner":null,"lang":"en","date_modified":"2023-12-07","date_modified_ts":"2023-12-07T20:34:26Z","date_created":"2023-12-07T20:29:03Z","summary":null,"body":["<article data-history-node-id=\"4814\" about=\"\/en\/alerts-advisories\/control-systems-controlbyweb-security-advisory-av23-743\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-743<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 7, 2023<\/p>\n\n<p>On December 7, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Relay X-332-24I\u00a0\u2013 firmware version 1.06<\/li>\n\t<li>Relay X-301-I\u00a0\u2013 firmware version 1.15<\/li>\n\t<li>Relay X-301-24I\u00a0\u2013 firmware version 1.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-341-05\">ICS Advisory\u00a0\u2013 ICSA-23-341-05<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-controlbyweb-security-advisory-av23-743","alert_type":398,"serial_number":"AV23-743","subject":"other","moderation_state":"published","external_url":null},{"nid":4815,"title":"[Control systems] Johnson Controls security advisory (AV23-744)","uuid":"ede1d49c-0831-4893-9e6f-1a9924e5e87e","banner":null,"lang":"en","date_modified":"2023-12-07","date_modified_ts":"2023-12-07T20:44:41Z","date_created":"2023-12-07T20:38:02Z","summary":null,"body":["<article data-history-node-id=\"4815\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-744\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-744<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 7, 2023<\/p>\n\n<p>On December 7, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Facility Explorer F4-SNC\u00a0\u2013 versions prior to 11.0.6<\/li>\n\t<li>Facility Explorer F4-SNC\u00a0\u2013 versions prior to 12.0.4<\/li>\n\t<li>Metasys NAE55 engines\u00a0\u2013 versions prior to 12.0.4<\/li>\n\t<li>Metasys SNC engines\u00a0\u2013 versions prior to 12.0.4<\/li>\n\t<li>Metasys SNE engines\u00a0\u2013 versions prior to 12.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-341-03\">ICS Advisory\u00a0\u2013 ICSA-23-341-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-744","alert_type":398,"serial_number":"AV23-744","subject":"other","moderation_state":"published","external_url":null},{"nid":4816,"title":"[Control systems] Mitsubishi Electric security advisory (AV23-745)","uuid":"0c8cbf11-e902-4741-a5b8-f490a13dd687","banner":null,"lang":"en","date_modified":"2023-12-07","date_modified_ts":"2023-12-07T20:55:06Z","date_created":"2023-12-07T20:48:14Z","summary":null,"body":["<article data-history-node-id=\"4816\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-745\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-745\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 7, 2023\n<\/p>\n<p>On December 7, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:\n<\/p>\n<ul><li>MELIPC MI5122-VW\u00a0\u2013 all versions<\/li>\n  <li>MELIPC MI2012-W\u00a0\u2013 all Versions<\/li>\n  <li>MELIPC MI1002-W\u00a0\u2013 all versions<\/li>\n  <li>MELIPC MI3321G-W\u00a0\u2013 all versions<\/li>\n  <li>MELIPC MI3315G-W\u00a0\u2013 all versions<\/li>\n  <li>MELSEC iQ-R R102WCPU-W\u00a0\u2013 all versions<\/li>\n  <li>MELSEC Q Q24DHCCPU-V\u00a0\u2013 all versions<\/li>\n  <li>MELSEC Q Q24DHCCPU-VG\u00a0\u2013 all versions<\/li>\n  <li>MELSEC Q Q24DHCCPU-LS\u00a0\u2013 all versions<\/li>\n  <li>MELSEC Q Q26DHCCPU-LS\u00a0\u2013 all versions<\/li>\n\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-341-01\">ICS Advisory\u00a0- ICSA-23-341-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av23-745","alert_type":398,"serial_number":"AV23-745","subject":"other","moderation_state":"published","external_url":null},{"nid":4817,"title":"[Control systems] Schweitzer Engineering Laboratories security advisory (AV23-746)","uuid":"2752c92f-da96-4aac-8364-2e5cae458488","banner":null,"lang":"en","date_modified":"2023-12-08","date_modified_ts":"2023-12-08T13:49:58Z","date_created":"2023-12-08T13:41:57Z","summary":null,"body":["<article data-history-node-id=\"4817\" about=\"\/en\/alerts-advisories\/control-systems-schweitzer-engineering-laboratories-security-advisory-av23-746\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-746<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 8, 2023<\/p>\n\n<p>On December 7, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SEL-411L\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-341-02\">ICS Advisory\u00a0\u2013 ICSA-23-341-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schweitzer-engineering-laboratories-security-advisory-av23-746","alert_type":398,"serial_number":"AV23-746","subject":"other","moderation_state":"published","external_url":null},{"nid":4818,"title":"[Control systems] Sierra Wireless security advisory (AV23-747) ","uuid":"307283a5-8f40-43ba-983e-f99441f6671f","banner":null,"lang":"en","date_modified":"2023-12-08","date_modified_ts":"2023-12-08T14:05:43Z","date_created":"2023-12-08T13:54:35Z","summary":null,"body":["<article data-history-node-id=\"4818\" about=\"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory-av23-747\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-747<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 8, 2023<\/p>\n\n<p>On December 7, 2023, CISA published an ICS Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AirLink router\u00a0\u2013 ALEOS firmware versions prior to 4.9.9<\/li>\n\t<li>AirLink router\u00a0\u2013 ALEOS firmware versions prior to 4.17.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-341-06\">ICS Advisory\u00a0- ICSA-23-341-06<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sierra-wireless-security-advisory-av23-747","alert_type":398,"serial_number":"AV23-747","subject":"ics","moderation_state":"published","external_url":null},{"nid":4819,"title":"Apache security advisory (AV23-748)","uuid":"169aa4f9-5a38-4039-90e6-4be0ca4846f2","banner":null,"lang":"en","date_modified":"2023-12-08","date_modified_ts":"2023-12-08T14:32:08Z","date_created":"2023-12-08T14:10:03Z","summary":null,"body":["<article data-history-node-id=\"4819\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av23-748\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-748<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 8, 2023<\/p>\n\n<p>On December 4, 2023, Apache published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Apache Struts\u00a0\u2013 versions 2.0.0 to 2.3.37 (EOL)<\/li>\n\t<li>Apache Struts\u00a0\u2013 versions 2.5.0 to 2.5.32<\/li>\n\t<li>Apache Struts\u00a0\u2013 versions 6.0.0 to 6.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/s2-066\">Apache Security Bulletin\u00a0\u2013 S2-066<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av23-748","alert_type":396,"serial_number":"AV23-748","subject":"other","moderation_state":"published","external_url":null},{"nid":4820,"title":"Microsoft Edge security advisory (AV23-749)","uuid":"6cd2ebc1-8716-4ca5-961c-276f619a1ab3","banner":null,"lang":"en","date_modified":"2023-12-08","date_modified_ts":"2023-12-08T19:09:24Z","date_created":"2023-12-08T19:06:13Z","summary":null,"body":["<article data-history-node-id=\"4820\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-749\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-749<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 8, 2023<\/p>\n\n<p>On December 7, 2023, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 120.0.2210.61<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-7-2023\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-749","alert_type":396,"serial_number":"AV23-749","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4823,"title":"Ubuntu security advisory (AV23-750)","uuid":"109a1df6-8af0-499c-affe-4009d97f27a2","banner":null,"lang":"en","date_modified":"2023-12-11","date_modified_ts":"2023-12-11T20:00:00Z","date_created":"2023-12-11T20:04:50Z","summary":null,"body":["<article data-history-node-id=\"4823\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-750\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-750<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 11, 2023<\/p>\n\n<p>Between December 4 and December 10, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6532-1\">Ubuntu Security Notice - USN-6532-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6533-1\">Ubuntu Security Notice - USN-6533-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6534-1\">Ubuntu Security Notice - USN-6534-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6536-1\">Ubuntu Security Notice - USN-6536-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6537-1\">Ubuntu Security Notice - USN-6537-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-750","alert_type":396,"serial_number":"AV23-750","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4821,"title":"Dell security advisory (AV23-752)","uuid":"6ebc7a9c-f260-4866-acdd-a4b400297ff5","banner":null,"lang":"en","date_modified":"2023-12-11","date_modified_ts":"2023-12-11T20:10:00Z","date_created":"2023-12-11T20:05:10Z","summary":null,"body":["<article data-history-node-id=\"4821\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-752\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-752<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 11, 2023<\/p>\n\n<p>Between December\u00a04 and December\u00a010,\u00a02023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell PowerProtect Data Manager DM5500 Appliance \u2013 version dm5500 5.14 and prior<\/li>\n\t<li>PowerFlex appliance \u2013 versions prior to 38.365.00<\/li>\n\t<li>PowerFlex rack \u2013 versions prior to 3.6.5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220107\/dsa-2023-425-security-update-for-dell-powerprotect-data-manager-dm5500-appliance-for-multiple-vulnerabilities\">Dell Security Update - Dell PowerProtect Data Manager DM5500 Appliance<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220225\/dsa-2023-458-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities\">Dell Security Update - PowerFlex appliance<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220223\/dsa-2023-457-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities\">Dell Security Update - PowerFlex rack<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices <\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-752","alert_type":396,"serial_number":"AV23-752","subject":"dell","moderation_state":"published","external_url":null},{"nid":4822,"title":"Apple security advisory (AV23-753)","uuid":"999f39c6-5c08-4a0a-99ba-9ff083f65226","banner":null,"lang":"en","date_modified":"2023-12-11","date_modified_ts":"2023-12-11T20:15:00Z","date_created":"2023-12-11T20:11:30Z","summary":null,"body":["<article data-history-node-id=\"4822\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-753\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-753<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 11, 2023<\/p>\n\n<p>On December 11, 2023, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 17.2<\/li>\n\t<li>iOS and iPadOS \u2013 versions prior to 16.7.3<\/li>\n\t<li>macOS Sonoma \u2013 versions prior to 14.2<\/li>\n\t<li>macOS Ventura \u2013 versions prior to 13.6.3<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.7.2<\/li>\n\t<li>Safari \u2013 versions prior to 17.2<\/li>\n\t<li>tvOS \u2013 versions prior to 17.2<\/li>\n\t<li>watchOS \u2013 versions prior to 10.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-753","alert_type":396,"serial_number":"AV23-753","subject":"apple","moderation_state":"published","external_url":null},{"nid":4824,"title":"IBM security advisory (AV23-751)","uuid":"ba003506-a561-48d6-8fb0-359136b73f55","banner":null,"lang":"en","date_modified":"2023-12-11","date_modified_ts":"2023-12-11T20:05:00Z","date_created":"2023-12-11T20:20:10Z","summary":null,"body":["<article data-history-node-id=\"4824\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-751\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-751<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 11, 2023<\/p>\n\n<p>Between December 4 and December 10, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Watson Studio on Cloud Pak for Data \u2013 versions 4.6.x and 4.7.x<\/li>\n\t<li>IBM Cloud Pak for Watson AIOps \u2013 versions prior to 4.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7090404\">IBM Security Bulletin \u2013 Watson Studio in Cloud Pak for Data<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7091317\">IBM Security Bulletin - CloudPak for Watson AIOPs<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-751","alert_type":396,"serial_number":"AV23-751","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4828,"title":"[Control systems] Schneider Electric security advisory (AV23-754)","uuid":"a4564b8d-44ea-40f4-b844-f66bd5527242","banner":null,"lang":"en","date_modified":"2023-12-12","date_modified_ts":"2023-12-12T13:00:00Z","date_created":"2023-12-12T13:00:00Z","summary":null,"body":["<article data-history-node-id=\"4828\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-754\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-754<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 12, 2023<\/p>\n\n<p>On December 12, 2023, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Easy UPS Online Monitoring Software\u00a0\u2013 version 2.6-GA-01-23116 and prior<\/li>\n\t<li>Trio Q-Series Ethernet Data Radio\u00a0\u2013 all versions<\/li>\n\t<li>Trio E-Series Ethernet Data Radio\u00a0\u2013 all versions<\/li>\n\t<li>Trio J-Series Ethernet Data Radio\u00a0\u2013 all versions<\/li>\n\t<li>Plant iT\/Brewmaxx\u00a0\u2013 version v9.60 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-346-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-346-03.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2023-346-03 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-346-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-346-01.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2023-346-01 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2023-346-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2023-346-02.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2023-346-02 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av23-754","alert_type":398,"serial_number":"AV23-754","subject":"other","moderation_state":"published","external_url":null},{"nid":4825,"title":"HPE security advisory (AV23-755)","uuid":"5ff88fb7-118c-4dd6-a82c-b7155c318589","banner":null,"lang":"en","date_modified":"2023-12-12","date_modified_ts":"2023-12-12T18:57:00Z","date_created":"2023-12-12T18:58:57Z","summary":null,"body":["<article data-history-node-id=\"4825\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-755\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-755<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 12, 2023<\/p>\n\n<p>On December 12, 2023, HPE published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telecommunication Management Information Platform\u00a0\u2013 versions 8.3.x and 8.4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04558en_us\">HPE Security Bulletin\u00a0- hpesbnw04558<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-755","alert_type":396,"serial_number":"AV23-755","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4826,"title":"SAP security advisory \u2013 December 2023 monthly rollup (AV23-756)","uuid":"bdfc606f-42e0-4dbe-88ea-c68ea63ac879","banner":null,"lang":"en","date_modified":"2023-12-12","date_modified_ts":"2023-12-12T19:37:41Z","date_created":"2023-12-12T19:26:45Z","summary":null,"body":["<article data-history-node-id=\"4826\" about=\"\/en\/alerts-advisories\/sap-security-advisory-december-2023-monthly-rollup-av23-756\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-756<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 12, 2023<\/p>\n\n<p>On December 12, 2023, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Business Technology Platform (BTP) Security Services Integration Libraries\u00a0\u2013 multiple products and versions<\/li>\n\t<li>SAP ECC and SAP S\/4HANA (IS-OIL)\u00a0\u2013 versions 600, 602, 603, 604, 605, 606, 617, 618, 800, 802, 803, 804, 805, 806 and 807<\/li>\n\t<li>SAP Commerce Cloud\u00a0\u2013 version 8.1<\/li>\n\t<li>Business Objects BI Platform\u00a0\u2013 versions 420 and 430<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day **\u00a0\u2013 December 2023 (PDF)<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-december-2023-monthly-rollup-av23-756","alert_type":396,"serial_number":"AV23-756","subject":"sap","moderation_state":"published","external_url":null},{"nid":4827,"title":"Fortinet security advisory (AV23-757)","uuid":"7eec140e-bc84-4096-92a9-b959befe21a0","banner":null,"lang":"en","date_modified":"2023-12-12","date_modified_ts":"2023-12-12T20:36:01Z","date_created":"2023-12-12T19:42:42Z","summary":null,"body":["<article data-history-node-id=\"4827\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av23-757\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-757<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 12, 2023<\/p>\n\n<p>On December 12, 2023, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiMail\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiNDR\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiOS\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiPAM\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiProxy\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiPortal\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiRecorder\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiSwitch\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiVoice\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiWLM\u00a0\u2013 versions 8.6.0 to 8.6.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av23-757","alert_type":396,"serial_number":"AV23-757","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":4829,"title":"Microsoft security advisory \u2013 December 2023 monthly rollup (AV23-758)","uuid":"b3484f77-5516-46bd-a7a6-62eea3156b7d","banner":null,"lang":"en","date_modified":"2023-12-12","date_modified_ts":"2023-12-12T21:28:53Z","date_created":"2023-12-12T21:21:08Z","summary":null,"body":["<article data-history-node-id=\"4829\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-december-2023-monthly-rollup-av23-758\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-758<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 12, 2023<\/p>\n\n<p>On December 12, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Windows 10\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Azure\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Dynamics\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Dec\">December 2023 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-december-2023-monthly-rollup-av23-758","alert_type":396,"serial_number":"AV23-758","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4830,"title":"Adobe security advisory (AV23-759)","uuid":"b5265c79-f2c3-4a12-86e7-35b643460c92","banner":null,"lang":"en","date_modified":"2023-12-12","date_modified_ts":"2023-12-12T21:47:56Z","date_created":"2023-12-12T21:40:30Z","summary":null,"body":["<article data-history-node-id=\"4830\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-759\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-759<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 12, 2023<\/p>\n\n<p>On December 12, 2023, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe Prelude\u00a0\u2013 version 22.6 and prior<\/li>\n\t<li>Illustrator 2024\u00a0\u2013 version 28.0 and prior<\/li>\n\t<li>Illustrator 2023\u00a0\u2013 version 27.9 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 versions ID19.0, ID17.4.2 and prior<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 3.4.10 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 AEM Cloud Service and version 6.5.18.0 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 2.1.1 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler\u00a0\u2013 version 4.2.1 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version 13.0.0 and prior<\/li>\n\t<li>Adobe After Effects\u00a0\u2013 versions 24.0.3, 23.6.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-759","alert_type":396,"serial_number":"AV23-759","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4831,"title":"[Control systems] Siemens security advisory (AV23-760)","uuid":"3e681b91-30f3-4eab-b0fb-05665e84c423","banner":null,"lang":"en","date_modified":"2023-12-12","date_modified_ts":"2023-12-12T21:54:02Z","date_created":"2023-12-12T21:50:12Z","summary":null,"body":["<article data-history-node-id=\"4831\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-760\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-760<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 12, 2023<\/p>\n\n<p>On December 12, 2023, Siemens published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>RUGGEDCOM RM1224\u00a0\u2013 multiple versions<\/li>\n\t<li>SCALANCE\u00a0\u2013 multiple platforms and multiple versions<\/li>\n\t<li>SIMATIC S7-1500 CPU\u00a0\u2013 version 3.1 and later<\/li>\n\t<li>SIPLUS S7-1500\u00a0\u2013 version 3.1 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av23-760","alert_type":398,"serial_number":"AV23-760","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4832,"title":"Ivanti security advisory (AV23-761)","uuid":"2e7e6ef3-405c-4e4d-bf11-449a54c14ccb","banner":null,"lang":"en","date_modified":"2023-12-13","date_modified_ts":"2023-12-13T13:55:26Z","date_created":"2023-12-13T13:49:45Z","summary":null,"body":["<article data-history-node-id=\"4832\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-761\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-761<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 13, 2023<\/p>\n\n<p>On December 4, 2023, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Connect Secure\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-patch-release-Ivanti-Connect-Secure-22-6R2-and-22-6R2-1?language=en_US\">Ivanti\u00a0- Security patch release\u00a0- Ivanti Connect Secure 22.6R2 and 22.6R2.1 <\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-761","alert_type":396,"serial_number":"AV23-761","subject":"other","moderation_state":"published","external_url":null},{"nid":4833,"title":"Atlassian security advisory (AV23-762)","uuid":"db89676c-203f-4b2d-a9ad-999b0f271848","banner":null,"lang":"en","date_modified":"2023-12-13","date_modified_ts":"2023-12-13T20:09:48Z","date_created":"2023-12-13T20:04:53Z","summary":null,"body":["<article data-history-node-id=\"4833\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av23-762\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-762<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 13, 2023<\/p>\n\n<p>On December 12, 2023, Atlassian published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Bamboo Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Bamboo Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.atlassian.com\/trust\/data-protection\/vulnerabilities\">Atlassian Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av23-762","alert_type":396,"serial_number":"AV23-762","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4834,"title":"GitLab security advisory (AV23-763)","uuid":"f07f06df-544a-42fe-b9b9-f243b99dddd2","banner":null,"lang":"en","date_modified":"2023-12-13","date_modified_ts":"2023-12-13T20:18:15Z","date_created":"2023-12-13T20:14:08Z","summary":null,"body":["<article data-history-node-id=\"4834\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av23-763\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-763<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 13, 2023<\/p>\n\n<p>On December 13, 2023, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2023\/12\/13\/security-release-gitlab-16-6-2-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av23-763","alert_type":396,"serial_number":"AV23-763","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4835,"title":"Palo Alto Networks security advisory (AV23-764)","uuid":"e6ab5994-084b-478a-966f-604e146430ac","banner":null,"lang":"en","date_modified":"2023-12-14","date_modified_ts":"2023-12-14T14:59:56Z","date_created":"2023-12-14T14:49:53Z","summary":null,"body":["<article data-history-node-id=\"4835\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av23-764\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-764<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 14, 2023<\/p>\n\n<p>On December 13, 2023, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>PAN-OS 11.0\u00a0\u2013 versions prior to 11.0.1<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 2.4<\/li>\n\t<li>PAN-OS 10.1\u00a0\u2013 versions prior to 10.1.9<\/li>\n\t<li>PAN-OS 10.0\u00a0\u2013 versions prior to 10.0.12<\/li>\n\t<li>PAN-OS 9.1\u00a0\u2013 versions prior to 9.1.16<\/li>\n\t<li>PAN-OS 9.0\u00a0\u2013 versions prior to 9.0.17<\/li>\n\t<li>PAN-OS 8.1\u00a0\u2013 versions prior to 8.1.25<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2023-6790\">Palo Alto Networks Security Advisory\u00a0- CVE-2023-6790<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av23-764","alert_type":396,"serial_number":"AV23-764","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":4836,"title":"HPE security advisory (AV23-765)","uuid":"13c63bf7-ae6e-4302-8a80-72d38c538d5a","banner":null,"lang":"en","date_modified":"2023-12-14","date_modified_ts":"2023-12-14T15:15:15Z","date_created":"2023-12-14T15:08:20Z","summary":null,"body":["<article data-history-node-id=\"4836\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-765\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-765<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 14, 2023<\/p>\n\n<p>On December 13, 2023, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Intelligent Management Center (iMC)\u00a0\u2013 versions prior to 7.3 E0710H02<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbnw04574en_us\">HPE Security Bulletin\u00a0- hpesbnw04574en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-765","alert_type":396,"serial_number":"AV23-765","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4837,"title":"[Control systems] Cambium security advisory (AV23-766)","uuid":"db24ef03-e63d-4eb7-9c2a-c28570ffaa6a","banner":null,"lang":"en","date_modified":"2023-12-14","date_modified_ts":"2023-12-14T17:56:09Z","date_created":"2023-12-14T17:46:29Z","summary":null,"body":["<article data-history-node-id=\"4837\" about=\"\/en\/alerts-advisories\/control-systems-cambium-security-advisory-av23-766\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-766<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December\u00a014, 2023<\/p>\n\n<p>On December\u00a014, 2023, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cambium ePMP Force 300-25\u00a0\u2013 version 4.7.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-348-01\">ICS Advisory\u00a0- ICSA-23-348-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cambium-security-advisory-av23-766","alert_type":398,"serial_number":"AV23-766","subject":"ics","moderation_state":"published","external_url":null},{"nid":4838,"title":"[Control systems] Johnson Controls security advisory (AV23-767)","uuid":"27f71fae-4762-4828-9265-d7c43afcf712","banner":null,"lang":"en","date_modified":"2023-12-14","date_modified_ts":"2023-12-14T18:19:14Z","date_created":"2023-12-14T18:09:18Z","summary":null,"body":["<article data-history-node-id=\"4838\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-767\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-767<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 14, 2023<\/p>\n\n<p>On December 14, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Kantech Gen1 ioSmart card reader\u00a0\u2013 firmware versions prior to 1.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-348-02\">ICS Advisory\u00a0\u2013 ICSA-23-348-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av23-767","alert_type":398,"serial_number":"AV23-767","subject":"other","moderation_state":"published","external_url":null},{"nid":4839,"title":"[Control systems] Unitronics security advisory (AV23-768) ","uuid":"240df2b3-ffed-4983-ab01-74d4fedd8dc2","banner":null,"lang":"en","date_modified":"2023-12-15","date_modified_ts":"2023-12-15T13:57:00Z","date_created":"2023-12-15T13:49:17Z","summary":null,"body":["<article data-history-node-id=\"4839\" about=\"\/en\/alerts-advisories\/control-systems-unitronics-security-advisory-av23-768\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-768<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 15, 2023<\/p>\n\n<p>On December 14, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Vision Logic\u00a0\u2013 versions prior to 9.9.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-348-15\">ICS Advisory\u00a0\u2013 ICSA-23-348-15<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/exploitation-unitronics-programmable-logic-controllers\">Alert\u00a0\u2013 Exploitation of Unitronics programmable logic controllers<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-unitronics-security-advisory-av23-768","alert_type":398,"serial_number":"AV23-768","subject":"other","moderation_state":"published","external_url":null},{"nid":4840,"title":"Vulnerability impacting Apache Struts 2 (CVE-2023-50164)","uuid":"f57e4830-1833-49df-8e4e-5483613e038f","banner":null,"lang":"en","date_modified":"2023-12-15","date_modified_ts":"2023-12-15T19:18:54Z","date_created":"2023-12-15T19:15:10Z","summary":null,"body":["<article data-history-node-id=\"4840\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-apache-struts-2-cve-2023-50164\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL23-019<br \/><strong>Date:\u00a0<\/strong>December 15, 2023<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On December 4, 2023, Apache released a security bulletin to address a critical vulnerability (CVE-2023-50164) affecting Apache Struts 2 versions 2.0.0 to 2.3.37, 2.5.0 to 2.5.32 and 6.0.0 to 6.3.0<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. The vulnerability is rated as a 9.8 on the Common Vulnerability Scoring System (CVSS3) and can allow a malicious actor to upload malicious files and perform remote code execution<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) and our cyber security partners have published alerts and advisories encouraging all organizations to apply patches to the affected products<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<p>Historically, vulnerabilities impacting Struts 2 have been significant due to the broad adoption of the Apache Struts 2 framework within the industry.<\/p>\n\n<p>The Cyber Centre has verified publicly available proof of concepts (POCs) and is aware of malicious activity within Canada.<\/p>\n\n<p>The Cyber Centre strongly recommends that organizations patch the affected Apache Struts 2 systems to versions 2.5.33 and 6.3.0.2 or greater at their earliest opportunity.\u00a0 Apache Struts versions 2.0.0 to 2.3.37 are vulnerable but are no longer supported. Impacted organizations are encouraged to update any unsupported products to a supported version.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<p>Verify the existence of Apache Struts on their hosts, monitor for signs of exploitation and patch software using Struts 2 as soon as possible.<\/p>\n\n<p>For Linux systems, the lsof command may be used to identify commonly named struts files loaded within applications with the following command:<\/p>\n\n<ul><li>sudo lsof -w | grep -i \"struts2.*\\.jar\"<\/li>\n<\/ul><p>For Windows systems, it may be possible to determine the location of commonly named Apache Struts archives by using the following Powershell command replacing &lt;DRIVEPATH&gt; for each mounted drive.<\/p>\n\n<ul><li>Get-ChildItem -Path &lt;DRIVEPATH&gt; -Recurse -ErrorAction SilentlyContinue\u00a0-Filter '*struts*.jar'<\/li>\n<\/ul><p>This technique of detection is not a definitive method in the identification of all impacted systems and products. The Cyber Centre strongly recommends that organizations monitor vendor advisory spaces to receive notifications of impact along with mitigation recommendations and patches.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">otnote <\/span>7<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><h2>Partner Reporting<\/h2>\n\n<p><a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/critical-vulnerability-in-popular-java-framework-apache-struts2\">ACSC - Critical Vulnerability in popular Java framework Apache Struts2 \u2013 Alert<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/12\/12\/apache-software-foundation-updates-struts-2\">CISA - The Apache Software Foundation Updates Struts 2 \u2013 Alert<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ncsc.govt.nz\/news\/cve-struts2\/\">NCSC-NZ - Cyber Security Alert: CVE affecting Apache Struts 2 \u2013 Advisory<\/a><\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/s2-066\">Apache Struts 2 Security Bulletin - S2-066 <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-50164\">CVE-2023-50164 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/apache-security-advisory-av23-748\">CCCS AV23-748 \u2013 Apache security advisory <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/12\/12\/apache-software-foundation-updates-struts-2\">The Apache Software Foundation Updates Struts 2<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/critical-vulnerability-in-popular-java-framework-apache-struts2\">Critical vulnerability in popular Java framework Apache Struts2<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.ncsc.govt.nz\/news\/cve-struts2\/\">Cyber Security Alert: CVE affecting Apache Struts 2<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-apache-struts-2-cve-2023-50164","alert_type":397,"serial_number":"AL23-019","subject":"other","moderation_state":"published","external_url":null},{"nid":4841,"title":"Adobe security advisory (AV23-769)","uuid":"3934b72d-e74a-4d85-a8f2-5c79e7377150","banner":null,"lang":"en","date_modified":"2023-12-18","date_modified_ts":"2023-12-18T14:15:15Z","date_created":"2023-12-18T14:09:19Z","summary":null,"body":["<article data-history-node-id=\"4841\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av23-769\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-769\n  <br \/><strong>Date: <\/strong>December 18, 2023\n<\/p>\n<p>On December 15, 2023, Adobe published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>Adobe Experience Manager (AEM) Forms on JEE\u00a0\u2013 version 6.5.19.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/vulnerability-impacting-apache-struts-2-cve-2023-50164\">The Canadian Centre for Cyber Security Alert\u00a0\u2013 AL23-019<\/a><\/li>\n  <li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/aem-forms\/apsb23-77.html\">Adobe Security Advisory\u00a0- APSB23-77<\/a><\/li>\n  <li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av23-769","alert_type":396,"serial_number":"AV23-769","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4842,"title":"Ubuntu security advisory (AV23-770)","uuid":"a7dc1321-780f-4779-ac84-be76387b50e4","banner":null,"lang":"en","date_modified":"2023-12-18","date_modified_ts":"2023-12-18T15:58:32Z","date_created":"2023-12-18T15:45:10Z","summary":null,"body":["<article data-history-node-id=\"4842\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-770\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-770<br \/><strong>Date: <\/strong>December 18, 2023<\/p>\n\n<p>Between December 11 and December 17, 2023, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av23-770","alert_type":396,"serial_number":"AV23-770","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4843,"title":"Dell security advisory (AV23-771)","uuid":"5ae4a0ff-4686-4e4f-befe-99233ad6ea84","banner":null,"lang":"en","date_modified":"2023-12-18","date_modified_ts":"2023-12-18T16:42:59Z","date_created":"2023-12-18T16:39:31Z","summary":null,"body":["<article data-history-node-id=\"4843\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-771\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-771<br \/><strong>Date: <\/strong>December 18, 2023<\/p>\n\n<p>Between December 11 and December 17, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell EMC SMR\u00a0\u2013 versions prior to 4.10.0.1<\/li>\n\t<li>Dell EMC SMR Vapp\u00a0\u2013 versions prior to 4.10.0.1<\/li>\n\t<li>Dell EMC SRM\u00a0\u2013 versions prior to 4.10.0.1<\/li>\n\t<li>Dell EMC SRM Vapp\u00a0\u2013 versions prior to 4.10.0.1<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 7.0.x versions prior to 7.0.482<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ai?lwp=rt\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-771","alert_type":396,"serial_number":"AV23-771","subject":"dell","moderation_state":"published","external_url":null},{"nid":4844,"title":"IBM security advisory (AV23-772)","uuid":"f1b07039-fc36-4225-8dfc-c96df5c47916","banner":null,"lang":"en","date_modified":"2023-12-18","date_modified_ts":"2023-12-18T17:28:33Z","date_created":"2023-12-18T17:23:44Z","summary":null,"body":["<article data-history-node-id=\"4844\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-772\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-772<br \/><strong>Date: <\/strong>December 18, 2023<\/p>\n\n<p>Between December 11 and December 17, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Automation Decision Services\u00a0\u2013 version 23.0.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- multiple versions and platforms<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 versions 1.14.2, 1.14.2 IF001 and 1.14.1<\/li>\n\t<li>IBM Security Guardium\u00a0\u2013 version 11.5<\/li>\n\t<li>IBM Spectrum Control\u00a0\u2013 version 5.4<\/li>\n\t<li>IBM Tivoli Netcool Impact\u00a0\u2013 version 7.1.0<\/li>\n\t<li>IBM Watson Machine Learning Accelerator on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-772","alert_type":396,"serial_number":"AV23-772","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4846,"title":"Red Hat security advisory (AV23-773)","uuid":"97adf2bc-1051-4ed2-b2c2-725499d78d61","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T14:22:55Z","date_created":"2023-12-19T14:09:53Z","summary":null,"body":["<article data-history-node-id=\"4846\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av23-773\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-773<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>Between December 11 and December 17, 2023, Red Hat published security advisories to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux for x86_64 9 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux for IBM z Systems 9 s390x<\/li>\n\t<li>Red Hat Enterprise Linux for Power, little endian 9 ppc64le<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time 9 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time for NFV 9 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux for ARM 64 9 aarch64<\/li>\n\t<li>Red Hat CodeReady Linux Builder for x86_64 9 x86_64<\/li>\n\t<li>Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le<\/li>\n\t<li>Red Hat CodeReady Linux Builder for ARM 64 9 aarch64<\/li>\n\t<li>Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7734\">Red Hat Security Advisories \u2013 RHSA-2023:7734<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2023:7749\">Red Hat Security Advisories \u2013 RHSA-2023:7749<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av23-773","alert_type":396,"serial_number":"AV23-773","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4847,"title":"Cisco security advisory (AV23-774)","uuid":"fe79e3bf-afe5-43a2-ae24-864d7ebe3595","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T14:35:06Z","date_created":"2023-12-19T14:32:48Z","summary":null,"body":["<article data-history-node-id=\"4847\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av23-774\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-774<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>On December 12, 2023, Cisco published a security advisory to address an Apache Struts vulnerability in the following products:<\/p>\n\n<ul><li>Cisco Identity Services Engine (ISE) \u2013 versions prior to 3.1<\/li>\n\t<li>Cisco Unified SIP Proxy Software \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Please monitor the Cisco Advisory for additional product updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/vulnerability-impacting-apache-struts-2-cve-2023-50164\">The Canadian Centre for Cyber Security Alert \u2013 AL23-019<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-struts-C2kCMkmT \">Apache Struts Vulnerability Affecting Cisco Products: December 2023 \u2013 cisco-sa-struts-C2kCMkmT<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av23-774","alert_type":396,"serial_number":"AV23-774","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4848,"title":"Mozilla security advisory (AV23-776)","uuid":"c42f0926-1816-4ae0-aa7e-e14fdff66eb6","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T18:41:33Z","date_created":"2023-12-19T18:33:33Z","summary":null,"body":["<article data-history-node-id=\"4848\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av23-776\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-776<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>On December 19, 2023, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 121<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.6<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 115.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-54\/\">Mozilla Security Advisory\u00a0- MFSA 2023-54<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-55\/\">Mozilla Security Advisory\u00a0- MFSA 2023-55<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2023-56\/\">Mozilla Security Advisory\u00a0- MFSA 2023-56<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av23-776","alert_type":396,"serial_number":"AV23-776","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4849,"title":"Microsoft Edge security advisory (AV23-775)","uuid":"cc5b1b52-82be-4587-88a2-72c57da16bc6","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T18:10:53Z","date_created":"2023-12-19T18:45:11Z","summary":null,"body":["<article data-history-node-id=\"4849\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-775\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   -->\n<p><strong>Serial number: <\/strong>AV23-775\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023\n<\/p>\n<p>On December 14, 2023, Microsoft published a security update to address a vulnerability in the following product:\n<\/p>\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 120.0.2210.77<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-14-2023\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-775","alert_type":396,"serial_number":"AV23-775","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4850,"title":"HPE security advisory (AV23-777)","uuid":"d85c1c0d-90c0-4d9d-b3f1-55503154f5b6","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T19:16:20Z","date_created":"2023-12-19T18:54:37Z","summary":null,"body":["<article data-history-node-id=\"4850\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-777\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-777<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>On December 19, 2023, HPE published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers\u00a0\u2013 firmware version 2.63 to versions prior to 3.0<\/li>\n\t<li>HPE Integrated Lights-Out 6 (iLO 6)\u00a0\u2013 firmware version 1.05 to versions prior to 1.55<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04584en_us\">HPE Security Bulletin\u00a0- hpesbnw04584en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-777","alert_type":396,"serial_number":"AV23-777","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4851,"title":"[Control systems] Subnet Solutions security advisory (AV23-778)","uuid":"c467bab5-bbd2-43d4-891a-3f32f52ec0d0","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T19:44:21Z","date_created":"2023-12-19T19:39:54Z","summary":null,"body":["<article data-history-node-id=\"4851\" about=\"\/en\/alerts-advisories\/control-systems-subnet-solutions-security-advisory-av23-778\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-778<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>On December 19, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>PowerSYSTEM Center \u2013 version 2020 5.0.x to 5.16.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-353-01\">ICS Advisory \u2013 ICSA-23-353-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-subnet-solutions-security-advisory-av23-778","alert_type":398,"serial_number":"AV23-778","subject":"other","moderation_state":"published","external_url":null},{"nid":4853,"title":"[Control systems] Open Design Alliance security advisory (AV23-780) ","uuid":"7a44bacb-7fd7-47a5-8777-3423adaf3c53","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T20:33:22Z","date_created":"2023-12-19T19:45:40Z","summary":null,"body":["<article data-history-node-id=\"4853\" about=\"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory-av23-780\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-780<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>On December 19, 2023, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Drawing SDK\u00a0\u2013 versions prior to 2024.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-353-04\">ICS Advisory\u00a0\u2013 ICSA-23-353-04<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-open-design-alliance-security-advisory-av23-780","alert_type":398,"serial_number":"AV23-780","subject":"ics","moderation_state":"published","external_url":null},{"nid":4852,"title":"[Control systems] EFACEC security advisory (AV23-779) ","uuid":"889f6cf9-43c8-4ce4-a55a-23c9212f6400","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T19:52:12Z","date_created":"2023-12-19T19:48:19Z","summary":null,"body":["<article data-history-node-id=\"4852\" about=\"\/en\/alerts-advisories\/control-systems-efacec-security-advisory-av23-779\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV23-779<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>On December 19, 2023, CISA published ICS advisories to address a vulnerabilities in the following products:<\/p>\n\n<ul><li>BCU 500 \u2013 version 4.07<\/li>\n\t<li>UC 500E \u2013 version 10.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-353-02\">ICS Advisory \u2013 ICSA-23-353-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-353-03\">ICS Advisory \u2013 ICSA-23-353-03<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-efacec-security-advisory-av23-779","alert_type":398,"serial_number":"AV23-779","subject":"other","moderation_state":"published","external_url":null},{"nid":4854,"title":"[Control systems] EuroTel security advisory (AV23-781)","uuid":"ce92a147-75cf-46eb-a4e9-511d9498b410","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T20:49:50Z","date_created":"2023-12-19T20:36:57Z","summary":null,"body":["<article data-history-node-id=\"4854\" about=\"\/en\/alerts-advisories\/control-systems-eurotel-security-advisory-av23-781\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-781\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023\n<\/p>\n<p>On December 19, 2023, CISA published an ICS advisory to address critical vulnerabilities in the following products:\n<\/p>\n<ul><li>ETL3100\u00a0\u2013 version v01c01<\/li>\n  <li>ETL3100\u00a0\u2013 version v01x37<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-353-05\">ICS Advisory\u00a0\u2013 ICSA-23-353-05<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-eurotel-security-advisory-av23-781","alert_type":398,"serial_number":"AV23-781","subject":"ics","moderation_state":"published","external_url":null},{"nid":4855,"title":" Apple security advisory (AV23-782)","uuid":"a6d05673-5c50-4b0a-b610-e137e9d3ec2f","banner":null,"lang":"en","date_modified":"2023-12-19","date_modified_ts":"2023-12-19T21:00:06Z","date_created":"2023-12-19T20:53:52Z","summary":null,"body":["<article data-history-node-id=\"4855\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av23-782\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-782<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 19, 2023<\/p>\n\n<p>On December 19, 2023, Apple published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>macOS Sonoma\u00a0\u2013 versions prior to 14.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT214048\">Apple Security Update\u00a0- HT214048<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av23-782","alert_type":396,"serial_number":"AV23-782","subject":"apple","moderation_state":"published","external_url":null},{"nid":4856,"title":"Ivanti security advisory (AV23-783)","uuid":"b1e339ab-61d2-4362-925d-090d20d4c8fb","banner":null,"lang":"en","date_modified":"2023-12-20","date_modified_ts":"2023-12-20T16:16:42Z","date_created":"2023-12-20T16:11:21Z","summary":null,"body":["<article data-history-node-id=\"4856\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av23-783\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-783<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December\u00a020, 2023<\/p>\n\n<p>On December\u00a018, 2023, Ivanti published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Avalanche\u00a0\u2013 versions prior to 6.4.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Avalanche-6-4-2-Security-Hardening-and-CVEs-addressed?language=en_US\">Ivanti Security Advisory\u00a0- Avalanche 6.4.2<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av23-783","alert_type":396,"serial_number":"AV23-783","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4857,"title":"Google Chrome security advisory (AV23-784)","uuid":"71ef19b5-6856-451c-a2a1-77e04f7889a7","banner":null,"lang":"en","date_modified":"2023-12-20","date_modified_ts":"2023-12-20T20:08:34Z","date_created":"2023-12-20T20:04:51Z","summary":null,"body":["<article data-history-node-id=\"4857\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-784\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-784<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 20, 2023<\/p>\n\n<p>On December 20, 2023, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop \u2013 versions prior to 120.0.6099.129\/130 (Windows) and versions prior to 120.0.6099.129 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google has indicated that CVE-2023-7024 has an available exploit.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2023\/12\/stable-channel-update-for-desktop_20.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av23-784","alert_type":396,"serial_number":"AV23-784","subject":"other","moderation_state":"published","external_url":null},{"nid":4858,"title":"[Control systems] FXC security advisory (AV23-785) ","uuid":"fbc2287b-06a9-497c-ba65-9118da31d8ff","banner":null,"lang":"en","date_modified":"2023-12-21","date_modified_ts":"2023-12-21T18:53:39Z","date_created":"2023-12-21T18:48:51Z","summary":null,"body":["<article data-history-node-id=\"4858\" about=\"\/en\/alerts-advisories\/control-systems-fxc-security-advisory-av23-785\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-785<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 21, 2023<\/p>\n\n<p>On December 21, 2023, CISA published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>AE1021PE firmware \u2013 version 2.0.9 and prior<\/li>\n\t<li>AE1021 firmware \u2013 version 2.0.9 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-355-01\">ICS Advisory \u2013 ICSA-23-355-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-fxc-security-advisory-av23-785","alert_type":396,"serial_number":"AV23-785","subject":"other","moderation_state":"published","external_url":null},{"nid":4859,"title":"[Control systems] QNAP security advisory (AV23-786) ","uuid":"15efef33-c934-4d3c-b9b5-5773794f6667","banner":null,"lang":"en","date_modified":"2023-12-21","date_modified_ts":"2023-12-21T18:57:54Z","date_created":"2023-12-21T18:55:58Z","summary":null,"body":["<article data-history-node-id=\"4859\" about=\"\/en\/alerts-advisories\/control-systems-qnap-security-advisory-av23-786\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-786<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 21, 2023<\/p>\n\n<p>On December 21, 2023, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VioStor NVR QVR firmware \u2013 versions prior to 4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-355-02\">ICS Advisory \u2013 ICSA-23-355-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-qnap-security-advisory-av23-786","alert_type":396,"serial_number":"AV23-786","subject":"other","moderation_state":"published","external_url":null},{"nid":4860,"title":"HPE security advisory (AV23-787)","uuid":"c0ec906e-1ab6-4f37-b547-1a995f643cbe","banner":null,"lang":"en","date_modified":"2023-12-21","date_modified_ts":"2023-12-21T20:08:21Z","date_created":"2023-12-21T20:01:58Z","summary":null,"body":["<article data-history-node-id=\"4860\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av23-787\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-787<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 21, 2023<\/p>\n\n<p>On December 21, 2023, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console (UOC)\u00a0- versions prior to 3.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbmu04573en_us\">HPE Security Bulletin\u00a0- hpesbnw04573en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av23-787","alert_type":396,"serial_number":"AV23-787","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4861,"title":"Microsoft Edge security advisory (AV23-788)","uuid":"68f9ba8d-ce31-46ff-bbcd-14a21681aebf","banner":null,"lang":"en","date_modified":"2023-12-22","date_modified_ts":"2023-12-22T16:37:59Z","date_created":"2023-12-22T16:28:53Z","summary":null,"body":["<article data-history-node-id=\"4861\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-788\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-788<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 22, 2023<\/p>\n\n<p>On December 21, 2023, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 120.0.2210.91<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft has received reports that CVE-2023-7024 has been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-21-2023\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av23-788","alert_type":396,"serial_number":"AV23-788","subject":"other","moderation_state":"published","external_url":null},{"nid":4862,"title":"IBM security advisory (AV23-789)","uuid":"9c23b161-eda1-440d-9433-f720f5fbaeea","banner":null,"lang":"en","date_modified":"2023-12-27","date_modified_ts":"2023-12-27T15:34:24Z","date_created":"2023-12-27T15:20:40Z","summary":null,"body":["<article data-history-node-id=\"4862\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av23-789\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-789<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 27, 2023<\/p>\n\n<p>Between December 18 and 24, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Planning Analytics\u00a0\u2013 version 2.0<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP7<\/li>\n\t<li>IBM Security SOAR\u00a0\u2013 versions 50.2, 50.1, 50.0, 49.2, 49.1, 49.0, 48.2, 48.1 and 48.0<\/li>\n\t<li>IBM Storage Fusion\u00a0\u2013 versions 2.1.0 to 2.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7099335\">IBM Security Bulletin\u00a0- 70799335<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7099297\">IBM Security Bulletin\u00a0- 7099297<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7096528\">IBM Security Bulletin\u00a0- 7096528<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7101348\">IBM Security Bulletin\u00a0- 7101348<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av23-789","alert_type":396,"serial_number":"AV23-789","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4864,"title":"Dell security advisory (AV23-790)","uuid":"85d36732-db15-45f6-b9e0-f86d816bc8ff","banner":null,"lang":"en","date_modified":"2023-12-28","date_modified_ts":"2023-12-28T15:11:15Z","date_created":"2023-12-28T15:01:03Z","summary":null,"body":["<article data-history-node-id=\"4864\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av23-790\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-790<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 28, 2023<\/p>\n\n<p>Between December 18 and 24, 2023, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Networker Monitoring Service\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Networker FLR, VCUI\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Streaming Data Platform\u00a0\u2013 version 1.1.x to 1.8.x<\/li>\n\t<li>Integrated Data Protection Appliance\u00a0\u2013 version 2.7.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220669\/dsa-2023-409-security-update-for-dell-networker-multiple-security-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-409<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220577\/dsa-2023-460-security-update-for-dell-streaming-data-platform-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-460<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220651\/dsa-2023-416-security-update-for-dell-powerprotect-dp-series-appliance-idpa-infrastructure-for-multiple-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-416<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av23-790","alert_type":396,"serial_number":"AV23-790","subject":"dell","moderation_state":"published","external_url":null},{"nid":4866,"title":"Juniper Networks security advisory (AV23-791)","uuid":"a1c3b327-4c51-44ad-a2e4-4bcba0a2f34f","banner":null,"lang":"en","date_modified":"2023-12-28","date_modified_ts":"2023-12-28T19:33:24Z","date_created":"2023-12-28T19:21:43Z","summary":null,"body":["<article data-history-node-id=\"4866\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-791\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-791<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>December 28, 2023<\/p>\n\n<p>On December 28, 2023, Juniper Networks published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Juniper Secure Analytics\u00a0\u2013 versions prior to 7.5.0 UP7 IF03<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2023-12-Security-Bulletin-JSA-Series-Multiple-vulnerabilities-resolved?language=en_US\">Juniper Networks Security Advisories\u00a0- JSA75636<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;numberOfResults=50&amp;f:ctype=[Security%20Advisories]\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av23-791","alert_type":396,"serial_number":"AV23-791","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4867,"title":"IBM security advisory (AV24-001)","uuid":"c4b2a883-9658-458e-a8e8-0487db8181b8","banner":null,"lang":"en","date_modified":"2024-01-02","date_modified_ts":"2024-01-02T14:49:08Z","date_created":"2024-01-02T14:35:53Z","summary":null,"body":["<article data-history-node-id=\"4867\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-001\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-001<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 2, 2024<\/p>\n\n<p>Between December 25 and 31, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Storage Protect Server\u00a0\u2013 version 8.1<\/li>\n\t<li>IBM App Connect Professional\u00a0\u2013 version 7.5.5.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 IOT Component\u00a0\u2013 versions 8.7 and 8.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7103673\">IBM Security Bulletin\u00a0- 7103673<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7103502\">IBM Security Bulletin\u00a0- 7103502<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7101884\">IBM Security Bulletin\u00a0- 7101884<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7101882\">IBM Security Bulletin\u00a0- 7101882<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-001","alert_type":396,"serial_number":"AV24-001","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4870,"title":"Google Chrome security advisory (AV24-003)","uuid":"bf9e6493-d929-40db-838b-dabebd5dbc46","banner":null,"lang":"en","date_modified":"2024-01-03","date_modified_ts":"2024-01-03T20:15:00Z","date_created":"2024-01-03T20:02:21Z","summary":null,"body":["<article data-history-node-id=\"4870\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-003\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-003<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 3, 2024<\/p>\n\n<p>On January 3, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 120.0.6099.199\/200 (Windows) and 120.0.6099.199 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/01\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-003","alert_type":396,"serial_number":"AV24-003","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4871,"title":" Android security advisory \u2013 January 2024 Monthly Rollup (AV24-002)","uuid":"57bb8d8e-3af5-47f8-b7b3-61a0dd6f3f02","banner":null,"lang":"en","date_modified":"2024-01-03","date_modified_ts":"2024-01-03T20:00:12Z","date_created":"2024-01-03T20:27:24Z","summary":null,"body":["<article data-history-node-id=\"4871\" about=\"\/en\/alerts-advisories\/android-security-advisory-january-2024-monthly-rollup-av24-002\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV23-002<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 3, 2024<\/p>\n\n<p>On January 3, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-01-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-january-2024-monthly-rollup-av24-002","alert_type":396,"serial_number":"AV24-002","subject":"android","moderation_state":"published","external_url":null},{"nid":4872,"title":"HPE security advisory (AV24-004)","uuid":"609245c5-5aa3-472f-954d-cf12d25abe0c","banner":null,"lang":"en","date_modified":"2024-01-04","date_modified_ts":"2024-01-04T14:32:42Z","date_created":"2024-01-04T14:28:47Z","summary":null,"body":["<article data-history-node-id=\"4872\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-004\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-004<br \/><strong>Date: <\/strong>January 4, 2024<\/p>\n\n<p>On January 3, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console (UOC)\u00a0- versions prior to 3.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04570en_us\">HPE Security Bulletin\u00a0- hpesbgn04570en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-004","alert_type":396,"serial_number":"AV24-004","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4873,"title":" [Control systems] Rockwell Automation security advisory (AV24-005) ","uuid":"c16aea47-b9eb-4be4-ac71-71a944184735","banner":null,"lang":"en","date_modified":"2024-01-04","date_modified_ts":"2024-01-04T18:06:10Z","date_created":"2024-01-04T18:03:49Z","summary":null,"body":["<article data-history-node-id=\"4873\" about=\"\/en\/alerts-advisories\/rockwell-automation-security-advisory-av24-005\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-005<br \/><strong>Date: <\/strong>January 04, 2024<\/p>\n\n<p>On January 4, 2024, CISA published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Factory Talk\u00a0\u2013 version 4.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-004-01\">ICS Advisory\u00a0- ICSA-24-004-01<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rockwell-automation-security-advisory-av24-005","alert_type":398,"serial_number":"AV24-005","subject":"other","moderation_state":"published","external_url":null},{"nid":4874,"title":" [Control systems] Mitsubishi Electric security advisory (AV24-006) ","uuid":"10538ab4-2e82-4f0e-8cf3-72d159939b8d","banner":null,"lang":"en","date_modified":"2024-01-04","date_modified_ts":"2024-01-04T18:51:17Z","date_created":"2024-01-04T18:39:40Z","summary":null,"body":["<article data-history-node-id=\"4874\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av24-006\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-006<br \/><strong>Date: <\/strong>January 4, 2024<\/p>\n\n<p>On January 4, 2024, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FX5-OPC\u00a0\u2013 version 1.006 and prior<\/li>\n\t<li>GT SoftGOT2000\u00a0\u2013 versions 1.275M to 1.290C<\/li>\n\t<li>MX OPC Server UA\u00a0\u2013 version 3.05F and later<\/li>\n\t<li>OPC UA Data Collector\u00a0\u2013 version 1.04E and prior<\/li>\n\t<li>OPC UA Server Unit\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-004-02\">ICS Advisory\u00a0- ICSA-24-004-02<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av24-006","alert_type":398,"serial_number":"AV24-006","subject":"other","moderation_state":"published","external_url":null},{"nid":4875,"title":"Ivanti security advisory (AV24-007)","uuid":"6980d7a9-5a8a-4f90-859f-fa84268c21dd","banner":null,"lang":"en","date_modified":"2024-01-04","date_modified_ts":"2024-01-04T21:13:24Z","date_created":"2024-01-04T21:00:38Z","summary":null,"body":["<article data-history-node-id=\"4875\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-007\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   -->\n<p><strong>Serial number:<\/strong> AV24-007<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date\u00a0: <\/strong>January 4, 2024<\/p>\n\n<p>On January 4, 2024, Ivanti published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Ivanti EPM 2021\u00a0\u2013 versions prior to SU5<\/li>\n\t<li>Ivanti EPM 2022\u00a0\u2013 versions prior to SU5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/SA-2023-12-19-CVE-2023-39336?language=en_US\">Ivanti Security Advisory\u00a0- SA-2023-12-19-CVE-2023-39336<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -French-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-007","alert_type":396,"serial_number":"AV24-007","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4876,"title":"Ubuntu security advisory (AV24-008)","uuid":"9e571bef-43c4-4f21-a7ac-0241c7a952da","banner":null,"lang":"en","date_modified":"2024-01-08","date_modified_ts":"2024-01-08T16:44:30Z","date_created":"2024-01-08T16:33:36Z","summary":null,"body":["<article data-history-node-id=\"4876\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-008\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-008<br \/><strong>Date: <\/strong>January 8, 2024<\/p>\n\n<p>Between January 1 and 7, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6549-4\">Ubuntu Security Notice\u00a0\u2013 USN-6549-4<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/noticess\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-008","alert_type":396,"serial_number":"AV24-008","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4877,"title":"Dell security advisory (AV24-009)","uuid":"468c6529-54e4-44a5-84f9-d8155149612f","banner":null,"lang":"en","date_modified":"2024-01-08","date_modified_ts":"2024-01-08T16:52:35Z","date_created":"2024-01-08T16:49:42Z","summary":null,"body":["<article data-history-node-id=\"4877\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-009\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-009<br \/><strong>Date: <\/strong>January 8, 2023<\/p>\n\n<p>Between January 1 and 7, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Isilon\u00a0\u2013 multiple models and versions prior to 12.0<\/li>\n\t<li>PowerScale\u00a0\u2013 multiple models and versions prior to 12.0<\/li>\n\t<li>PowerScale Hybrid\u00a0\u2013 multiple models and versions prior to 12.0<\/li>\n\t<li>PowerScale Archive\u00a0\u2013 multiple models and versions prior to 12.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220650\/dsa-2023-459-security-update-for-dell-powerscale-onefs-for-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- DSA-2023-459<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-009","alert_type":396,"serial_number":"AV24-009","subject":"dell","moderation_state":"published","external_url":null},{"nid":4878,"title":"IBM security advisory (AV24-010)","uuid":"23c21934-f193-4671-86be-6ede0699c452","banner":null,"lang":"en","date_modified":"2024-01-08","date_modified_ts":"2024-01-08T20:13:03Z","date_created":"2024-01-08T19:57:44Z","summary":null,"body":["<article data-history-node-id=\"4878\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-010\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-010<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a08, 2024<\/p>\n\n<p>Between January\u00a01 and 7, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Analyst Workflow\u00a0\u2013 version 1.0.0 to 2.31.7<\/li>\n\t<li>IBM Db2 Web Query for i\u00a0\u2013 version 2.4.0<\/li>\n\t<li>IBM Storage Fusion HCI\u00a0\u2013 version 2.5.2 to 2.6.1<\/li>\n\t<li>IBM\u00ae Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>Watson Machine Learning on Cloud Pak for Data\u00a0\u2013 versions 4.6.0 and 4.7.0 and fixpacks<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-010","alert_type":396,"serial_number":"AV24-010","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4879,"title":"Microsoft Edge security advisory (AV24-011)","uuid":"00f077db-b780-4505-a86c-9f1cdf66e23e","banner":null,"lang":"en","date_modified":"2024-01-08","date_modified_ts":"2024-01-08T21:26:24Z","date_created":"2024-01-08T21:22:53Z","summary":null,"body":["<article data-history-node-id=\"4879\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-011\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-011\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a08, 2024\n<\/p>\n<p>On January\u00a05, 2024, Microsoft published a security update to address vulnerabilities in the following product:\n<\/p>\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 120.0.2210.121<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-5-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-011","alert_type":396,"serial_number":"AV24-011","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4882,"title":"[Control systems] Schneider Electric security advisory (AV24-012) ","uuid":"fc03bcf3-c51f-4473-8f99-e03ee4047b8e","banner":null,"lang":"en","date_modified":"2024-01-09","date_modified_ts":"2024-01-09T21:06:06Z","date_created":"2024-01-09T20:59:48Z","summary":null,"body":["<article data-history-node-id=\"4882\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-012\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-012<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 9, 2024<\/p>\n\n<p>On January 9, 2024, Schneider Electric published security advisories to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Easergy Studio\u00a0\u2013 version 9.3.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-009-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-009-02.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-009-02 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-012","alert_type":398,"serial_number":"AV24-012","subject":"other","moderation_state":"published","external_url":null},{"nid":4883,"title":"[Control systems] Siemens security advisory (AV24-013) ","uuid":"8be4c41e-9731-475e-b3e9-1999fb3a80fd","banner":null,"lang":"en","date_modified":"2024-01-09","date_modified_ts":"2024-01-09T21:17:44Z","date_created":"2024-01-09T21:09:32Z","summary":null,"body":["<article data-history-node-id=\"4883\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-013\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-013<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 09, 2024<\/p>\n\n<p>On January 9, 2024, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>CP-8031 MASTER MODULE (6MF2803-1AA00)\u00a0\u2013 firmware versions prior to CPCI85 V05.20<\/li>\n\t<li>CP-8050 MASTER MODULE (6MF2805-0AA00)\u00a0\u2013 firmware versions prior to CPCI85 V05.20<\/li>\n\t<li>JT2Go\u00a0\u2013 versions 14.3.0.6 and prior<\/li>\n\t<li>SIMATIC CN 4100\u00a0\u2013 versions prior to 2.7<\/li>\n\t<li>SIMATIC IPC647E\u00a0\u2013 maxView Storage Manager versions prior to 4.14.00.26068<\/li>\n\t<li>SIMATIC IPC847E\u00a0\u2013 maxView Storage Manager versions prior to 4.14.00.26068<\/li>\n\t<li>SIMATIC IPC1047E\u00a0\u2013 maxView Storage Manager versions prior to 4.14.00.26068<\/li>\n\t<li>Solid Edge SE2023\u00a0\u2013 versions prior to 223.0 Update 10<\/li>\n\t<li>Spectrum Power 7\u00a0\u2013 versions prior to V23Q4<\/li>\n\t<li>Teamcenter Visualization\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-013","alert_type":398,"serial_number":"AV24-013","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4884,"title":"SAP security advisory \u2013 January 2024 monthly rollup (AV24-014)","uuid":"6753c9d5-bd45-4f5d-a5d7-8ef44b404d9b","banner":null,"lang":"en","date_modified":"2024-01-09","date_modified_ts":"2024-01-09T21:25:06Z","date_created":"2024-01-09T21:09:32Z","summary":null,"body":["<article data-history-node-id=\"4884\" about=\"\/en\/alerts-advisories\/sap-security-advisory-january-2024-monthly-rollup-av24-014\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-014\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 09, 2024\n<\/p>\n<p>On January 9, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>SAP BTP Security Services Integration Library @sap\/xssec\u00a0\u2013 versions prior to 3.6.0<\/li>\n  <li>SAP Application Router Library @sap\/approuter\u00a0\u2013 version 14.4.2<\/li>\n  <li>SAP Edge Integration Cell\u00a0\u2013 versions 8.9.13 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dam.sap.com\/mac\/app\/e\/pdf\/preview\/embed\/ucQrx6G?ltr=a&amp;rc=10\">SAP Security Patch Day **\u00a0\u2013 January 2024<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-january-2024-monthly-rollup-av24-014","alert_type":396,"serial_number":"AV24-014","subject":"sap","moderation_state":"published","external_url":null},{"nid":4885,"title":"Google Chrome security advisory (AV24-015)","uuid":"f48cf099-6d97-46da-88f3-d7ff233c28ed","banner":null,"lang":"en","date_modified":"2024-01-09","date_modified_ts":"2024-01-09T21:31:24Z","date_created":"2024-01-09T21:13:35Z","summary":null,"body":["<article data-history-node-id=\"4885\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-015\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-015<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a09, 2024<\/p>\n\n<p>On January\u00a09, 2024, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 120.0.6099.216\/217 (Windows) and 120.0.6099.216 (Linux and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/01\/stable-channel-update-for-desktop_9.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-015","alert_type":396,"serial_number":"AV24-015","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4886,"title":"HPE security advisory (AV24-016)","uuid":"a672c79a-40b3-4398-88f3-8a64f0215b0b","banner":null,"lang":"en","date_modified":"2024-01-09","date_modified_ts":"2024-01-09T21:32:43Z","date_created":"2024-01-09T21:13:35Z","summary":null,"body":["<article data-history-node-id=\"4886\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-016\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-016<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a09, 2024<\/p>\n\n<p>On January\u00a09, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE OneView\u00a0- versions prior to 8.70<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow server-side request forgery (SSRF), local privilege escalation, remote code execution, cause a denial of service or an unauthorized restore.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04586en_us\">HPE Security Bulletin\u00a0- hpesbgn04586en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-016","alert_type":396,"serial_number":"AV24-016","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4887,"title":"Fortinet security advisory (AV24-017)","uuid":"733d0da6-1d4d-4a3b-b20b-88bf54d5abde","banner":null,"lang":"en","date_modified":"2024-01-09","date_modified_ts":"2024-01-09T21:33:30Z","date_created":"2024-01-09T21:13:35Z","summary":null,"body":["<article data-history-node-id=\"4887\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-017\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-017<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a09, 2024<\/p>\n\n<p>On January\u00a09, 2024, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.1<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 version 7.2.5<\/li>\n\t<li>FortiProxy 7.4\u00a0\u2013 versions 7.4.0 to 7.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-017","alert_type":396,"serial_number":"AV24-017","subject":"other","moderation_state":"published","external_url":null},{"nid":4888,"title":"Microsoft security advisory \u2013 January 2024 monthly rollup (AV24-018)","uuid":"624a489c-04a9-4230-8d03-f20674a3d20f","banner":null,"lang":"en","date_modified":"2024-01-09","date_modified_ts":"2024-01-09T21:37:08Z","date_created":"2024-01-09T21:13:36Z","summary":null,"body":["<article data-history-node-id=\"4888\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2024-monthly-rollup-av24-018\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-018<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a09, 2024<\/p>\n\n<p>On January\u00a09, 2024, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Windows 10\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Jan\">January 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-january-2024-monthly-rollup-av24-018","alert_type":396,"serial_number":"AV24-018","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4889,"title":"Intel security advisory (AV24-019)","uuid":"933943cf-ad63-43a5-a6e9-6e906076117f","banner":null,"lang":"en","date_modified":"2024-01-10","date_modified_ts":"2024-01-10T16:13:34Z","date_created":"2024-01-10T16:07:23Z","summary":null,"body":["<article data-history-node-id=\"4889\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av24-019\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-019<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a010, 2024<\/p>\n\n<p>On January\u00a09, 2024, Intel published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Intel NUC\u00a0\u2013 multiple firmware versions and platforms<\/li>\n\t<li>Intel\u00ae NUC Pro Software Suite Configuration Tool\u00a0\u2013 versions prior to 3.0.0.6<\/li>\n\t<li>Intel HotKey Services for Windows 10 for NUC P14E Laptop Element\u00a0\u2013 versions prior to 1.1.45<\/li>\n\t<li>Intel HID Event Filter drivers for Windows 10 for some NUC laptops\u00a0\u2013 versions prior to 2.2.2.1<\/li>\n\t<li>Intel Integrated Sensor Hub (ISH) driver for Windows 10 for NUC P14E Laptop Element\u00a0\u2013 versions prior to 5.4.1.4479<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-01028.html\">Intel Security Advisory\u00a0\u2013 INTEL-SA-01028<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-01009.html\">Intel Security Advisory\u00a0\u2013 INTEL-SA-01009<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-00964.html\">Intel Security Advisory\u00a0\u2013 INTEL-SA-00964<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av24-019","alert_type":396,"serial_number":"AV24-019","subject":"intel","moderation_state":"published","external_url":null},{"nid":4891,"title":"Ivanti security advisory (AV24-020)","uuid":"ea3e586b-6175-4c7f-b916-85e62cca033e","banner":null,"lang":"en","date_modified":"2024-01-10","date_modified_ts":"2024-01-10T20:33:06Z","date_created":"2024-01-10T20:24:30Z","summary":null,"body":["<article data-history-node-id=\"4891\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-020\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-020<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a010, 2024<\/p>\n\n<p>On January\u00a010, 2024, Ivanti published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Connect Secure (ICS) gateway\u00a0\u2013 versions 9.x and 22.x<\/li>\n\t<li>Ivanti Policy Secure (ICS) gateway\u00a0\u2013 versions 9.x and 22.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow for authentication bypass and execution of arbitrary commands.<\/p>\n\n<p>Ivanti has indicated that CVE-2023-46805 and CVE-2024-21887 have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\">Ivanti Security Advisory\u00a0\u2013 CVE-2023-46805-CVE-2024-21887<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-020","alert_type":396,"serial_number":"AV24-020","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4892,"title":"Cisco security advisory (AV24-021)","uuid":"7c6732e3-3f5e-4e84-9771-873e81756d65","banner":null,"lang":"en","date_modified":"2024-01-10","date_modified_ts":"2024-01-10T21:22:03Z","date_created":"2024-01-10T21:13:58Z","summary":null,"body":["<article data-history-node-id=\"4892\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-021\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-021<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 10, 2024<\/p>\n\n<p>On January 10, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Unity Connection (ISE)\u00a0\u2013 versions prior to 12.5.1.19017-4 and 14.0.1.14006-5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cuc-unauth-afu-FROYsCsD\">Cisco Advisory\u00a0\u2013 cisco-sa-cuc-unauth-afu-FROYsCsD<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-021","alert_type":396,"serial_number":"AV24-021","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4894,"title":"Ivanti Connect Secure and Ivanti Policy Secure gateways zero-day vulnerabilities \u2013 Update 2","uuid":"9e3cba5f-1390-46d0-bab8-3c3e12c0e723","banner":null,"lang":"en","date_modified":"2024-01-17","date_modified_ts":"2024-01-17T21:26:00Z","date_created":"2024-01-11T13:37:28Z","summary":null,"body":["<article data-history-node-id=\"4894\" about=\"\/en\/alerts-advisories\/ivanti-connect-secure-and-ivanti-policy-secure-gateways-zero-day-vulnerabilities\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL24-001<br \/><strong>Date:\u00a0<\/strong>January 31, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On January 10, 2024, the Cyber Centre was made aware of an authentication bypass vulnerability (CVE-2023-46805) and a command injection vulnerability (CVE-2024-21887) impacting Ivanti Connect Secure (ICS), formerly known as Pulse Connect Secure, and Ivanti Policy Secure (IPS) gateways. Ivanti published a security advisory to highlight these vulnerabilities<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn-1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. These vulnerabilities impact all supported versions of the software\u00a0\u2013 versions 9.x and 22.x. To highlight the vulnerabilities, the Cyber Centre released an advisory on January 10, 2024<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>As of January 10, Ivanti has stated that patches are still under active development and are not ready for distribution. Ivanti has released mitigation steps to address these vulnerabilities. Ivanti also suggests monitoring their Knowledge Base article for patch availability updates related to support versions of Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS), as they become available<sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn-3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>Ivanti has reported that they are aware of exploitation and have observed evidence of threat actors attempting to manipulate Ivanti\u2019s internal integrity checker tool (ICT) which is used to ensure filesystem integrity.<\/p>\n\n<p>Volexity has published a report with an incident summary and indicators of compromise for activity related to these vulnerabilities<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n<\/section><section><h2>Update 1<\/h2>\n\n<p>On January 15, 2024, Volexity published a report indicating that widespread exploitation has been detected<sup id=\"fn5-rf2\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre is aware of proof-of-concept code available in open source.<\/p>\n\n<p>On January 16, 2024, Ivanti published new guidance related to recovering from exploitation of these vulnerabilities<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<p>Any organizations with continued external facing access to the vulnerable services should assume full device compromise.<\/p>\n<\/section><section><h2>Update 2<\/h2>\n\n<p>On January 31, 2024, Ivanti updated their security advisory to indicate the release of patches for the authentication bypass (CVE-2023-46805) and command injection (CVE-2024-21887) vulnerabilities impacting Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) gateways<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn-1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>Ivanti also disclosed two additional vulnerabilities affecting their Connect Secure, Policy Secure, and Neurons for ZTA products<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>. A privilege escalation (CVE-2024-21888) allows a server-side request forgery (CVE-2024-21893) in the SAML component and allows a threat actor to access certain restricted resources without authentication. Fixes for these new vulnerabilities are also included in the recently published patches along with new mitigation advice for supported versions where a patch has not been provided<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn-3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> The Cyber Centre has released a security advisory to highlight these additional vulnerabilities<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<p>On January 31, 2024, Mandiant published a blog detailing additional tactics, techniques, and procedures (TTPs) detailing post-exploitation activity and have published indicators of compromise and signatures to aid in the <span class=\"nowrap\">detection of compromise<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn-10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>.<\/span><\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that:<\/p>\n\n<ul><li>Any organizations using Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) gateways review the Ivanti KB article for mitigation steps and patching information.<\/li>\n\t<li>Organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> with an emphasis on the following topics:\n\t<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t\t<li>Patching operating systems and applications.<\/li>\n\t\t<li>Segmenting and separating information.<\/li>\n\t\t<li>Protecting information at the enterprise level.<\/li>\n\t<\/ul><\/li>\n\t<li>The ICT is a snapshot of the current state of the appliance and cannot necessarily detect threat actor activity if they have returned the appliance to a clean state. The ICT does not scan for malware or other Indicators of Compromise. Ivanti recommends as a best practice for customers to always run the ICT in conjunction with continuous monitoring. To avoid malicious activity resulting from manipulation of results from the internal ICT Ivanti recommends that all customers instead run the external ICT.<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><h2>Partner Reporting<\/h2>\n\n<p><a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/critical-vulnerabilities-ivanti-connect-secure-ics-and-ivanti-policy-secure-ips\">ACSC\u00a0- Critical vulnerabilities in Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) <\/a><\/p>\n\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2024\/01\/10\/ivanti-releases-security-update-connect-secure-and-policy-secure-gateways\">CISA\u00a0- Ivanti Releases Security Update for Connect Secure and Policy Secure Gateways <\/a><\/p>\n\n<p><a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/advisories\/vulnerabilities-in-ivanti-gateways-actively-exploited\/\">CERTNZ\u00a0- Vulnerabilities in Ivanti Connect gateways actively exploited <\/a><\/p>\n\n<p><a href=\"https:\/\/www.ncsc.govt.nz\/news\/cves-ivanti-connect-secure\/\">NCSC-NZ\u00a0- Cyber Security Alert: CVEs affecting Ivanti Connect Secure <\/a><\/p>\n\n<p><a href=\"https:\/\/www.ncsc.gov.uk\/news\/exploitation-ivanti-vulnerabilities\">NCSC-UK\u00a0- Exploitation of vulnerabilities affecting Ivanti Connect Secure and Ivanti Policy Secure <\/a><\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn-1\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\">CVE-2023-46805 (Authentication Bypass) &amp; CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-020\">CCCS AV24-20\u00a0\u2013 Ivanti security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn-3\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\">KB\u00a0- CVE-2023-46805 (Authentication Bypass) &amp; CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.volexity.com\/blog\/2024\/01\/10\/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn\/\">Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.volexity.com\/blog\/2024\/01\/15\/ivanti-connect-secure-vpn-exploitation-goes-global\/\">Ivanti Connect Secure VPN Exploitation Goes Global<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US\">Recovery Steps Related to CVE-2023-46805 and CVE-2024-21887<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089 \">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US\">CVE-2024-21888 Privilege Escalation for Ivanti Connect Secure and Ivanti Policy Secure<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/ivanti-security-advisory-av24-058\">CCCS AV24-58 \u2013 Ivanti security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote <\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn-10\">\n\t<p><a href=\"https:\/\/www.mandiant.com\/resources\/blog\/investigating-ivanti-zero-day-exploitation\">Mandiant Cutting Edge Blog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote <\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-connect-secure-and-ivanti-policy-secure-gateways-zero-day-vulnerabilities","alert_type":397,"serial_number":"AL24-001","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4895,"title":"Apple security advisory (AV24-022)","uuid":"caf077be-8fc2-4fa7-aa59-71d869ff761c","banner":null,"lang":"en","date_modified":"2024-01-11","date_modified_ts":"2024-01-11T15:28:39Z","date_created":"2024-01-11T15:27:03Z","summary":null,"body":["<article data-history-node-id=\"4895\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-022\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-022<br \/><strong>Date: <\/strong>January 11, 2024<\/p>\n\n<p>On January 9, 2024, Apple published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Magic Keyboard\u00a0\u2013 firmware versions prior to 2.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT214050\">Apple Security Update\u00a0- HT214050<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><p>-<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-022","alert_type":396,"serial_number":"AV24-022","subject":"apple","moderation_state":"published","external_url":null},{"nid":4896,"title":"[Control systems] Horner Automation security advisory (AV24-023) ","uuid":"d92d0fe8-089e-4c6a-82d7-e04917809ba7","banner":null,"lang":"en","date_modified":"2024-01-11","date_modified_ts":"2024-01-11T20:07:05Z","date_created":"2024-01-11T20:00:49Z","summary":null,"body":["<article data-history-node-id=\"4896\" about=\"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av24-023\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-023<br \/><strong>Date: <\/strong>January 11, 2024<\/p>\n\n<p>On January 11, 2024, CISA published an ICS Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cscape\u00a0\u2013 version v9.90 SP10 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-011-04\">ICS Advisory\u00a0- ICSA-24-011-04<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-horner-automation-security-advisory-av24-023","alert_type":398,"serial_number":"AV24-023","subject":"other","moderation_state":"published","external_url":null},{"nid":4897,"title":"[Control systems] Rapid Software security advisory (AV24-024) ","uuid":"d911fde7-1386-4d46-ad69-3bcb80c5d64a","banner":null,"lang":"en","date_modified":"2024-01-11","date_modified_ts":"2024-01-11T20:23:26Z","date_created":"2024-01-11T20:09:28Z","summary":null,"body":["<article data-history-node-id=\"4897\" about=\"\/en\/alerts-advisories\/control-systems-rapid-software-security-advisory-av24-024\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-024<br \/><strong>Date: <\/strong>January 11, 2024<\/p>\n\n<p>On January 11, 2024, CISA published an ICS Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Rapid SCADA\u00a0\u2013 version 5.8.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-011-03\">ICS Advisory\u00a0- ICSA-24-011-03<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rapid-software-security-advisory-av24-024","alert_type":398,"serial_number":"AV24-024","subject":"other","moderation_state":"published","external_url":null},{"nid":4898,"title":"GitLab security advisory (AV24-025)","uuid":"923f2936-168a-4c2d-86c4-ffb4ce5a750f","banner":null,"lang":"en","date_modified":"2024-01-12","date_modified_ts":"2024-01-12T15:17:37Z","date_created":"2024-01-12T15:12:20Z","summary":null,"body":["<article data-history-node-id=\"4898\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-025\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-025<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a012, 2024<\/p>\n\n<p>On January\u00a011, 2024, GitLab published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could allow for the impersonation of legitimate users or full system compromise.<\/p>\n\n<p>Open-source reporting has indicated that proof-of-concept exploit code is available for this vulnerability.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/01\/11\/critical-security-release-gitlab-16-7-2-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-025","alert_type":396,"serial_number":"AV24-025","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4900,"title":"Microsoft Edge security advisory (AV24-026)","uuid":"73e5ff44-12db-4995-ac0e-e0393ab85b55","banner":null,"lang":"en","date_modified":"2024-01-12","date_modified_ts":"2024-01-12T19:08:39Z","date_created":"2024-01-12T19:05:18Z","summary":null,"body":["<article data-history-node-id=\"4900\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-026\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-026<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a012, 2024<\/p>\n\n<p>On January\u00a011, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 120.0.2210.133<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-11-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-026","alert_type":396,"serial_number":"AV24-026","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4902,"title":"Juniper Networks security advisory (AV24-027)","uuid":"c06079a7-36a4-423f-bd03-6b9b02eb8749","banner":null,"lang":"en","date_modified":"2024-01-15","date_modified_ts":"2024-01-15T15:50:35Z","date_created":"2024-01-15T15:44:26Z","summary":null,"body":["<article data-history-node-id=\"4902\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-027\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-027<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 15, 2024<\/p>\n\n<p>On January 10, 2024, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>CTPView\u00a0\u2013 versions prior to 9.1R5<\/li>\n\t<li>Junos OS\u00a0\u2013 multiple versions<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 multiple versions<\/li>\n\t<li>Security Director Insights\u00a0\u2013 versions prior to 23.1R1<\/li>\n\t<li>Session Smart Router\u00a0\u2013 versions prior to SSR-6.2.3-r2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy&amp;numberOfResults=100&amp;f:ctype=[Security%20Advisories]\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-027","alert_type":396,"serial_number":"AV24-027","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4903,"title":"Ubuntu security advisory (AV24-028)","uuid":"d62cabc8-0515-40d0-ab31-118bc784441d","banner":null,"lang":"en","date_modified":"2024-01-15","date_modified_ts":"2024-01-15T16:14:43Z","date_created":"2024-01-15T15:57:33Z","summary":null,"body":["<article data-history-node-id=\"4903\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-028\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-028<br \/><strong>Date: <\/strong>January 15, 2024<\/p>\n\n<p>Between January 8 and 14, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-028","alert_type":396,"serial_number":"AV24-028","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4906,"title":"Vulnerability impacting GitLab (CVE-2023-7028) ","uuid":"d31515ee-2d95-4206-b3d5-f6ade1af9137","banner":null,"lang":"en","date_modified":"2024-01-15","date_modified_ts":"2024-01-15T18:23:11Z","date_created":"2024-01-15T15:59:17Z","summary":null,"body":["<article data-history-node-id=\"4906\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-gitlab-cve-2023-7028\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL24-002<br \/><strong>Date:\u00a0<\/strong>January 15, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On January 11, the Cyber Centre became aware of critical vulnerabilities impacting multiple versions of GitLab Community Edition (CE) and GitLab Enterprise Edition (EE). CVE-2023-7028, a vulnerability which permits account take over via password reset emails was rated the maximum CVSS (Common Vulnerability Scoring System) score of 10<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. On January 12 the Cyber Centre published AV24-025 which highlighted the vulnerabilities and encouraged readers to patch at their earliest opportunity<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. Later that day, the Cyber Centre became aware of multiple proof of concepts which look to exploit CVE-2023-7028. There is an elevated risk that targeted exploitation will soon impact self-managed GitLab services.<\/p>\n\n<p>The following versions of GitLab self-managed instances are impacted:<\/p>\n\n<ul><li>16.1 to 16.1.5<\/li>\n\t<li>16.2 to 16.2.8<\/li>\n\t<li>16.3 to 16.3.6<\/li>\n\t<li>16.4 to 16.4.4<\/li>\n\t<li>16.5 to 16.5.5<\/li>\n\t<li>16.6 to 16.6.3<\/li>\n\t<li>16.7 to 16.7.1<\/li>\n<\/ul><\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that:<\/p>\n\n<ul><li>Any organizations using affected version of GitLab should ensure that the service is inaccessible until patches are installed.\n\t<ul><li>GitLab encourages users to not skip upgrade stops as this could create instability, with 16.3.x being a required upgrade stop.<\/li>\n\t<\/ul><\/li>\n\t<li>While CVE-2023-7028 may still result in a successful password reset, the implementation of two factor authentication (2FA) will deny malicious actors access to compromised accounts. Enforcing <abbr title=\"two factor authentication\">2FA <\/abbr> will help to ensure that malicious actors cannot login with compromised credentials.<\/li>\n\t<li>Organizations should review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> with an emphasis on the following topics:\n\t<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t\t<li>Patching operating systems and applications.<\/li>\n\t\t<li>Segmenting and separating information.<\/li>\n\t\t<li>Protecting information at the enterprise level.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/01\/11\/critical-security-release-gitlab-16-7-2-released\/#account-takeover-via-password-reset-without-user-interactions\">GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6 <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-025\">GitLab security advisory (AV24-025)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089) <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-gitlab-cve-2023-7028","alert_type":397,"serial_number":"AL24-002","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4905,"title":"IBM security advisory (AV24-029)","uuid":"8512e511-7fbf-4190-8fe7-b92bc03a78d6","banner":null,"lang":"en","date_modified":"2024-01-15","date_modified_ts":"2024-01-15T16:41:24Z","date_created":"2024-01-15T16:34:37Z","summary":null,"body":["<article data-history-node-id=\"4905\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-029\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-029<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a015, 2024<\/p>\n\n<p>Between January\u00a08 and 14, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak System\u00a0\u2013 versions 2.3.2.0 (Power), 2.3.1.1, 2.3.3.0 to 2.3.3.6 Interim Fix 1 (Intel) and 2.3.3.7 (Power)<\/li>\n\t<li>IBM Cloud Pak System Software Suite\u00a0\u2013 version 2.3.3.0 to 2.3.3.6 Interim Fix 1 (Intel)<\/li>\n\t<li>IBM Operational Decision Manager\u00a0\u2013 versions 8.10.5.1, 8.11.0.1, 8.11.1 and 8.12.0<\/li>\n\t<li>IBM Security Verify Access 10.0.0.0\u00a0\u2013 version 10.0.0.0<\/li>\n\t<li>IBM Security Verify Access Appliance\u00a0\u2013 version 10.0.0.0 to 10.0.6.1<\/li>\n\t<li>IBM Security Verify Access Docker\u00a0\u2013 version 10.0.0.0 to 10.0.6.1<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager software component\u00a0\u2013 version ISVG 10.0.2<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager virtual appliance component\u00a0\u2013 version ISVG 10.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-029","alert_type":396,"serial_number":"AV24-029","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4909,"title":"Citrix security advisory (AV24-030)","uuid":"e35aeff2-7a5c-43d6-8067-c2b8dd1cb7f6","banner":null,"lang":"en","date_modified":"2024-01-16","date_modified_ts":"2024-01-16T17:10:17Z","date_created":"2024-01-16T17:02:03Z","summary":null,"body":["<article data-history-node-id=\"4909\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av24-030\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-030<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a016,\u00a02024<\/p>\n\n<p>On January 16, 2024, Citrix published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway\u202f14.1\u00a0\u2014 versions prior to 14.1-12.35<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway\u202f13.1\u00a0\u2014 versions prior to 13.1-51.15<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway\u202f13.0\u00a0\u2014 versions prior to 13.0-92.21<\/li>\n\t<li>NetScaler ADC 13.1-FIPS\u00a0\u2014 versions prior to 13.1-37.176<\/li>\n\t<li>NetScaler ADC 12.1-FIPS\u00a0\u2014 versions prior to 12.1-55.302<\/li>\n\t<li>NetScaler ADC 12.1-NDcPP\u00a0\u2014 versions prior to 12.1-55.302<\/li>\n<\/ul><p>Citrix has indicated that CVE-2023-6548 and CVE-2023-6549 have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX584986\/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549\">Citrix Security Advisory\u00a0\u2013 CTX584986<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av24-030","alert_type":396,"serial_number":"AV24-030","subject":"citrix","moderation_state":"published","external_url":null},{"nid":4910,"title":"[Control systems] SEW-EURODRIVE security advisory (AV24-032)","uuid":"a2d19a68-82b6-440f-9245-aeedfaccc20b","banner":null,"lang":"en","date_modified":"2024-01-16","date_modified_ts":"2024-01-16T20:00:21Z","date_created":"2024-01-16T19:08:22Z","summary":null,"body":["<article data-history-node-id=\"4910\" about=\"\/en\/alerts-advisories\/control-systems-sew-eurodrive-security-advisory-av24-032\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-032<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a016, 2024<\/p>\n\n<p>On January\u00a016, 2024, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>MOVITOOLS MotionStudio\u00a0\u2013 version 6.5.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-016-01\">ICS Advisory\u00a0\u2013 CSA-24-016-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-sew-eurodrive-security-advisory-av24-032","alert_type":398,"serial_number":"AV24-032","subject":"ics","moderation_state":"published","external_url":null},{"nid":4911,"title":"[Control systems] Integration Objects security advisory (AV24-033)","uuid":"a5168ad1-419d-43a7-ae28-ffabda04bd1d","banner":null,"lang":"en","date_modified":"2024-01-16","date_modified_ts":"2024-01-16T20:00:59Z","date_created":"2024-01-16T19:20:42Z","summary":null,"body":["<article data-history-node-id=\"4911\" about=\"\/en\/alerts-advisories\/control-systems-integration-objects-security-advisory-av24-033\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-033<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a016, 2024<\/p>\n\n<p>On January\u00a016, 2024, CISA published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>OPC Server Toolkit\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-016-02\">ICS Advisory\u00a0\u2013 ICSA-24-016-02<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-integration-objects-security-advisory-av24-033","alert_type":398,"serial_number":"AV24-033","subject":"ics","moderation_state":"published","external_url":null},{"nid":4912,"title":"VMWare security advisory (AV24-031)","uuid":"6a0195fa-331e-493e-8959-34416a260291","banner":null,"lang":"en","date_modified":"2024-01-16","date_modified_ts":"2024-01-16T19:31:03Z","date_created":"2024-01-16T19:24:15Z","summary":null,"body":["<article data-history-node-id=\"4912\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-031\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-031<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 16, 2023<\/p>\n\n<p>On January 16, 2024, VMWare released a security advisory to address vulnerabilities in the following products::<\/p>\n\n<ul><li>VMware Aria Automation\u00a0\u2013 versions 8.11.x, 8.12.x, 8.13.x and 8.14.x<\/li>\n\t<li>VMWare Cloud Foundation\u00a0\u2013 versions 4.x and 5.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0001.html\">VMWare Security Advisory\u00a0\u2013 VMSA-2024-0001<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMWare Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-031","alert_type":396,"serial_number":"AV24-031","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4913,"title":"Google Chrome security advisory (AV24-034)","uuid":"43ff655c-e6bd-43a0-8d87-fcd5d73c8b72","banner":null,"lang":"en","date_modified":"2024-01-16","date_modified_ts":"2024-01-16T20:05:55Z","date_created":"2024-01-16T20:02:54Z","summary":null,"body":["<article data-history-node-id=\"4913\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-034\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-034<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a016, 2024<\/p>\n\n<p>On January\u00a016, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 120.0.6099.224\/225 (Windows), 120.0.6099.234 (Mac) and 120.0.6099.224 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Google has indicated that CVE-2024-0519 has an available exploit.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/01\/stable-channel-update-for-desktop_16.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-034","alert_type":396,"serial_number":"AV24-034","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4915,"title":"Atlassian security advisory (AV24-035)","uuid":"e6c21980-66b5-4771-9ae0-9247c06409c7","banner":null,"lang":"en","date_modified":"2024-01-16","date_modified_ts":"2024-01-16T21:34:59Z","date_created":"2024-01-16T21:30:02Z","summary":null,"body":["<article data-history-node-id=\"4915\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-035\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-035<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a016, 2024<\/p>\n\n<p>On January\u00a016, 2024, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Confluence Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Successful exploitation of this vulnerability (CVE-2023-22527) can allow an unauthenticated attacker to perform remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html\">Atlassian Security bulletin CVE-2023-22527 \u2013 Remote Code Execution vulnerability in Confluence Data Center and Confluence Server<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-035","alert_type":396,"serial_number":"AV24-035","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":4916,"title":"SonicWall security advisory (AV24-036)","uuid":"019ecd65-03a8-497e-9c55-b8b448eb7fe7","banner":null,"lang":"en","date_modified":"2024-01-17","date_modified_ts":"2024-01-17T19:59:42Z","date_created":"2024-01-17T19:55:37Z","summary":null,"body":["<article data-history-node-id=\"4916\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-036\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-036<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a017, 2024<\/p>\n\n<p>On January\u00a017, 2024, SonicWall published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SonicWall Capture Client\u00a0\u2013 version 3.7.10 and prior<\/li>\n\t<li>NetExtender Windows Client\u00a0\u2013 version 10.2.337 and prior<\/li>\n<\/ul><p>Exploitation of this vulnerability could result in a denial of service or execution of arbitrary code.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2023-6340\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2023-6340<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-036","alert_type":396,"serial_number":"AV24-036","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":4917,"title":"Oracle security advisory \u2013 January 2024 quarterly rollup (AV24-037)","uuid":"047d6ac2-3b66-42e6-9b61-b8ef67283d80","banner":null,"lang":"en","date_modified":"2024-01-18","date_modified_ts":"2024-01-18T13:46:11Z","date_created":"2024-01-18T13:36:20Z","summary":null,"body":["<article data-history-node-id=\"4917\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-january-2024-quarterly-rollup-av24-037\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-037<br \/><strong>Date: <\/strong>January 18, 2024<\/p>\n\n<p>On January\u00a016,\u00a02024, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Essbase<\/li>\n\t<li>Oracle Financial Services<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle Hyperion<\/li>\n\t<li>Oracle JD Edwards<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle REST Data Services<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Secure Backup<\/li>\n\t<li>Oracle SQL Developer<\/li>\n\t<li>Oracle Systems<\/li>\n\t<li>Oracle TimesTen In-Memory Database<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2024.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 January 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-january-2024-quarterly-rollup-av24-037","alert_type":396,"serial_number":"AV24-037","subject":"oracle","moderation_state":"published","external_url":null},{"nid":4920,"title":"HPE security advisory (AV24-038)","uuid":"258d6d85-23e3-4223-bf7a-ddb9536e4bcc","banner":null,"lang":"en","date_modified":"2024-01-19","date_modified_ts":"2024-01-19T15:39:10Z","date_created":"2024-01-19T15:28:38Z","summary":null,"body":["<article data-history-node-id=\"4920\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-038\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-038<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 19, 2024<\/p>\n\n<p>On January 17, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Apache-based Web Server\u00a0\u2013 versions prior to B.2.4.58.00<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote exploitation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbux04589en_us\">HPE Security Bulletin\u00a0- hpesbux04589en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-038","alert_type":396,"serial_number":"AV24-038","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4921,"title":"[Control systems] AVEVA security advisory (AV24-039)","uuid":"a94d0983-24db-4857-89ff-7ecaeededdeb","banner":null,"lang":"en","date_modified":"2024-01-19","date_modified_ts":"2024-01-19T15:56:04Z","date_created":"2024-01-19T15:35:43Z","summary":null,"body":["<article data-history-node-id=\"4921\" about=\"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av24-039\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-039<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a019, 2024<\/p>\n\n<p>On January\u00a018, 2024, CISA published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PI Server 2023\u00a0\u2013 versions prior to Patch 1<\/li>\n\t<li>PI Server 2018\u00a0\u2013 version SP3 Patch 5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-018-01\">ICS Advisory\u00a0\u2013 ICSA-24-018-01<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-aveva-security-advisory-av24-039","alert_type":398,"serial_number":"AV24-039","subject":"ics","moderation_state":"published","external_url":null},{"nid":4923,"title":"Dell security advisory (AV24-040)","uuid":"2240151a-55ce-4f35-8584-122b6206afb2","banner":null,"lang":"en","date_modified":"2024-01-22","date_modified_ts":"2024-01-22T16:05:07Z","date_created":"2024-01-22T14:54:30Z","summary":null,"body":["<article data-history-node-id=\"4923\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-040\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-040<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 22, 2024<\/p>\n\n<p>Between January 15 and 21, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Data Protection Central\u00a0\u2013 version 19.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000221194\/dsa-2024-010-security-update-for-dell-data-protection-central-for-multiple-third-party-vulnerabilities?lwp=rt\">Dell Security Update\u00a0- DSA-2024-010<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-040","alert_type":396,"serial_number":"AV24-040","subject":"dell","moderation_state":"published","external_url":null},{"nid":4924,"title":"IBM security advisory (AV24-041)","uuid":"19bcd916-b360-4a75-b220-087ae0e166c9","banner":null,"lang":"en","date_modified":"2024-01-22","date_modified_ts":"2024-01-22T17:36:59Z","date_created":"2024-01-22T17:31:10Z","summary":null,"body":["<article data-history-node-id=\"4924\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-041\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-041<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 22, 2024<\/p>\n\n<p>Between January 15 and 21, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterpriseh\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Business Automationh\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Integration Bush\u00a0\u2013 versions 10.1 to 10.1.0.2<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pakh\u00a0\u2013 versions 21.0.0 to 21.0.7.12 and 23.0.0 to 23.0.12<\/li>\n\t<li>IBM Security Verify Access\u00a0\u2013 version 10.0.0.0 to 10.0.6.1<\/li>\n\t<li>IBM Security Verify Access Dockerh\u00a0\u2013 version 10.0.0.0 to 10.0.6.1<\/li>\n\t<li>IBM Storage Ceph\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-041","alert_type":396,"serial_number":"AV24-041","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4925,"title":"Red Hat security advisory (AV24-042)","uuid":"e217654e-7b34-4b62-a3d8-e73f137fd66a","banner":null,"lang":"en","date_modified":"2024-01-22","date_modified_ts":"2024-01-22T19:18:43Z","date_created":"2024-01-22T19:06:36Z","summary":null,"body":["<article data-history-node-id=\"4925\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-042\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-042<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a022, 2024<\/p>\n\n<p>Between January\u00a015 and 21, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server\u00a0\u2013 versions AUS 7.6 x86_64 and AUS 7.7 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0261\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0261<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0262\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0262<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-042","alert_type":396,"serial_number":"AV24-042","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4926,"title":"Apple security advisory (AV24-043)","uuid":"928285b3-6df3-4f28-a99c-9dc2b6651815","banner":null,"lang":"en","date_modified":"2024-01-22","date_modified_ts":"2024-01-22T20:50:02Z","date_created":"2024-01-22T20:41:53Z","summary":null,"body":["<article data-history-node-id=\"4926\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-043\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-043<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a022, 2024<\/p>\n\n<p>On January\u00a022, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 17.3<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 16.7.5<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 15.8.1<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.3<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.6.4<\/li>\n\t<li>macOS Monterey\u00a0\u2013 versions prior to 12.7.3<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 10.3<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 17.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-043","alert_type":396,"serial_number":"AV24-043","subject":"apple","moderation_state":"published","external_url":null},{"nid":4927,"title":"Apple security advisory (AV24-044)","uuid":"0f917441-578e-4e61-a224-69459b5c6a4b","banner":null,"lang":"en","date_modified":"2024-01-23","date_modified_ts":"2024-01-23T14:52:11Z","date_created":"2024-01-23T14:46:34Z","summary":null,"body":["<article data-history-node-id=\"4927\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-044\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-044<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 23, 2024<\/p>\n\n<p>On January 22, 2024, Apple published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari\u00a0\u2013 versions prior to 3<\/li>\n<\/ul><p>Apple has received reports that CVE-2024-23222 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT214056\">About the security content of Safari 17.3<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-044","alert_type":396,"serial_number":"AV24-044","subject":"apple","moderation_state":"published","external_url":null},{"nid":4928,"title":"HPE security advisory (AV24-045)","uuid":"2558bff0-f04d-4391-9b26-496d9bf10f35","banner":null,"lang":"en","date_modified":"2024-01-23","date_modified_ts":"2024-01-23T15:01:04Z","date_created":"2024-01-23T14:56:32Z","summary":null,"body":["<article data-history-node-id=\"4928\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-045\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-045<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 23, 2024<\/p>\n\n<p>On January 22 and 23, 2024, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Superdome Flex Server\u00a0\u2013 versions prior to 90.18<\/li>\n\t<li>HPE Superdome Flex 280 Server\u00a0\u2013 versions prior to v1.70.14<\/li>\n\t<li>HPE Compute Scale-up Server 3200\u00a0\u2013 versions prior to v1.10.342<\/li>\n\t<li>HPE Unified Mediation Bus\u00a0\u2013 versions prior to 4.4<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could result in remote exploitation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04576en_us\">HPE Security Bulletin\u00a0- hpesbhf04576en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04569en_us\">HPE Security Bulletin\u00a0\u2013 hpesbgn04569en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-045","alert_type":396,"serial_number":"AV24-045","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4929,"title":"Mozilla security advisory (AV24-046)","uuid":"079f16fd-57ef-4ecb-83a2-8f7981286147","banner":null,"lang":"en","date_modified":"2024-01-23","date_modified_ts":"2024-01-23T16:15:53Z","date_created":"2024-01-23T16:11:44Z","summary":null,"body":["<article data-history-node-id=\"4929\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-046\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-046<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 23, 2023<\/p>\n\n<p>On January 23, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 122<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.7<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-01\/\">Mozilla Security Advisory\u00a0- MFSA 2024-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-02\/\">Mozilla Security Advisory\u00a0- MFSA 2024-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-04\/\">Mozilla Security Advisory\u00a0- MFSA 2024-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><!--*************************************************** START ADVISORY -French-  ******************************************************--><!--  <span lang=\"en\"><\/span>   --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-046","alert_type":396,"serial_number":"AV24-046","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":4931,"title":"Fortra security advisory (AV24-047)","uuid":"bfa5ddd7-f296-45b8-846c-710ffbcde9e1","banner":null,"lang":"en","date_modified":"2024-01-23","date_modified_ts":"2024-01-23T20:43:19Z","date_created":"2024-01-23T20:39:13Z","summary":null,"body":["<article data-history-node-id=\"4931\" about=\"\/en\/alerts-advisories\/fortra-security-advisory-av24-047\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-047<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 23, 2024<\/p>\n\n<p>On January 22, 2024, Fortra published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Fortra GoAnywhere MFT \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortra.com\/security\/advisory\/fi-2024-001\">Fortra Security Advisories - FI-2024-001<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortra.com\/security\">Fortra Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortra-security-advisory-av24-047","alert_type":396,"serial_number":"AV24-047","subject":"other","moderation_state":"published","external_url":null},{"nid":4932,"title":"Google Chrome security advisory (AV24-048)","uuid":"282691df-eabb-4dac-b7a1-e38759dfcb55","banner":null,"lang":"en","date_modified":"2024-01-23","date_modified_ts":"2024-01-23T21:12:54Z","date_created":"2024-01-23T20:58:45Z","summary":null,"body":["<article data-history-node-id=\"4932\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-048\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-048<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a023, 2024<\/p>\n\n<p>On January\u00a023, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 121.0.6167.85\/.86 (Windows) and 121.0.6167.85 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/01\/stable-channel-update-for-desktop_23.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-048","alert_type":396,"serial_number":"AV24-048","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4934,"title":"Cisco security advisory (AV24-049)","uuid":"918dad3c-9ecb-4e71-94fa-e513d788fee8","banner":null,"lang":"en","date_modified":"2024-01-24","date_modified_ts":"2024-01-24T19:28:29Z","date_created":"2024-01-24T19:19:30Z","summary":null,"body":["<article data-history-node-id=\"4934\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-049\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-049<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a024, 2024<\/p>\n\n<p>On January\u00a024, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Packaged Contact Center Enterprise (PCCE)\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Communications Manager (Unified CM)\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P)\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Communications Manager Session Management Edition (Unified CM SME)\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Contact Center Enterprise (UCCE)\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Contact Center Express (UCCX)\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unity Connection\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Virtualized Voice Browser\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cucm-rce-bWNzQcUm#fs\">Cisco Advisory\u00a0\u2013 cisco-sa-cucm-rce-bWNzQcUm<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-049","alert_type":396,"serial_number":"AV24-049","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4940,"title":"GitLab security advisory (AV24-050)","uuid":"e167449b-61e2-49bf-b915-2855ceb4c459","banner":null,"lang":"en","date_modified":"2024-01-25","date_modified_ts":"2024-01-25T18:27:24Z","date_created":"2024-01-25T18:23:25Z","summary":null,"body":["<article data-history-node-id=\"4940\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-050\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-050<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a025, 2024<\/p>\n\n<p>On January\u00a025, 2024, GitLab published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 multiple versions<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/01\/25\/critical-security-release-gitlab-16-8-1-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-050","alert_type":396,"serial_number":"AV24-050","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":4942,"title":"Juniper Networks security advisory (AV24-051)","uuid":"ded789c3-5619-49bd-b52d-84cdba3b4fc0","banner":null,"lang":"en","date_modified":"2024-01-26","date_modified_ts":"2024-01-26T15:17:58Z","date_created":"2024-01-26T15:14:13Z","summary":null,"body":["<article data-history-node-id=\"4942\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-051\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-051<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 26, 2024<\/p>\n\n<p>On January 25, 2024, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Junos OS SRX and EX series \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US \">Juniper Networks Security Advisories \u2013 JSA76390<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-051","alert_type":396,"serial_number":"AV24-051","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4943,"title":"Microsoft Edge security advisory (AV24-052)","uuid":"b4b7a3e4-979e-4d03-9297-f892fe25d282","banner":null,"lang":"en","date_modified":"2024-01-26","date_modified_ts":"2024-01-26T15:40:47Z","date_created":"2024-01-26T15:35:42Z","summary":null,"body":["<article data-history-node-id=\"4943\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-052\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-052<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 26, 2024<\/p>\n\n<p>On January 25, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 121.0.2277.83<\/li>\n\t<li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 120.0.2210.160<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-25-2024   \">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-052","alert_type":396,"serial_number":"AV24-052","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4945,"title":"[Control systems] CISA ICS security advisories (AV24-055) ","uuid":"273a736d-b251-4de4-9420-6dda89cec99b","banner":null,"lang":"en","date_modified":"2024-01-29","date_modified_ts":"2024-01-29T20:27:14Z","date_created":"2024-01-29T18:35:05Z","summary":null,"body":["<article data-history-node-id=\"4945\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-055\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-055<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a029, 2024<\/p>\n\n<p>Between January\u00a022 and\u00a028, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>APSystems Energy Communication Unit Power Control Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Crestron AM-300\u00a0\u2013 version 1.4499.00018<\/li>\n\t<li>Lantronix XPort Device Server Configuration Manager\u00a0\u2013 version 2.0.0.13<\/li>\n\t<li>MachineSense FeverWarn ESP32<\/li>\n\t<li>MachineSense FeverWarn RaspberryPi<\/li>\n\t<li>MachineSense FeverWarn DataHub RaspberryPi<\/li>\n\t<li>Orthanc Osimis WebViewer\u00a0\u2013 version 1.4.2.0-9d9eff4<\/li>\n\t<li>SystemK NVR 504\u00a0\u2013 version 2.3.5SK.30084998<\/li>\n\t<li>SystemK NVR 508\u00a0\u2013 version 2.3.5SK.30084998<\/li>\n\t<li>SystemK NVR 516\u00a0\u2013 version 2.3.5SK.30084998<\/li>\n\t<li>Voltronic Power ViewPower Pro\u00a0\u2013 version 2.0-22165<\/li>\n\t<li>Westermo Lynx\u00a0\u2013 model version L206-F2G1<\/li>\n\t<li>Westermo Lynx\u00a0\u2013 firmware version 4.24<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<p>Beginning January 29, 2024, the Cyber Centre will be publishing a summary of CISA's ICS Advisories from the week before into a single Cyber Centre advisory each week.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-055","alert_type":398,"serial_number":"AV24-055","subject":"ics","moderation_state":"published","external_url":null},{"nid":4946,"title":"Dell security advisory (AV24-053)","uuid":"bd137b1d-af1b-4e61-af49-d7706f1a81ef","banner":null,"lang":"en","date_modified":"2024-01-29","date_modified_ts":"2024-01-29T19:15:57Z","date_created":"2024-01-29T18:50:26Z","summary":null,"body":["<article data-history-node-id=\"4946\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-053\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-053<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 29, 2023<\/p>\n\n<p>Between January 22 and 28, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell NetWorker\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000221474\/dsa-2024-059-security-update-for-dell-networker-multiple-components-vulnerabilities\">Dell Security Update\u00a0- DSA-2024-059<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-053","alert_type":396,"serial_number":"AV24-053","subject":"dell","moderation_state":"published","external_url":null},{"nid":4947,"title":"Ubuntu security advisory (AV24-054)","uuid":"d31ca80a-a927-4a28-8431-6c8076813067","banner":null,"lang":"en","date_modified":"2024-01-29","date_modified_ts":"2024-01-29T19:19:48Z","date_created":"2024-01-29T19:16:24Z","summary":null,"body":["<article data-history-node-id=\"4947\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-054\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-054<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a029, 2024<\/p>\n\n<p>Between January\u00a022 and 28, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-054","alert_type":396,"serial_number":"AV24-054","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4948,"title":"Jenkins security advisory (AV24-056)","uuid":"47b825cc-e3d0-4a43-aa4e-f4fd3d1eec42","banner":null,"lang":"en","date_modified":"2024-01-29","date_modified_ts":"2024-01-29T20:32:03Z","date_created":"2024-01-29T20:27:56Z","summary":null,"body":["<article data-history-node-id=\"4948\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av24-056\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-056<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January\u00a029, 2024<\/p>\n\n<p>On January\u00a024, 2024, Jenkins published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Jenkins (core)\u00a0- multiple versions<\/li>\n<\/ul><p>Open-source reporting has indicated that proof\u2011of\u2011concept exploit code is available for some of these vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2024-01-24\/\">Jenkins Security Advisory 2024-01-24<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av24-056","alert_type":396,"serial_number":"AV24-056","subject":"other","moderation_state":"published","external_url":null},{"nid":4949,"title":"Google Chrome security advisory (AV24-057)","uuid":"8b16ee42-a7c5-46e4-8ee8-b51c96324852","banner":null,"lang":"en","date_modified":"2024-01-30","date_modified_ts":"2024-01-30T20:01:37Z","date_created":"2024-01-30T19:46:02Z","summary":null,"body":["<article data-history-node-id=\"4949\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-057\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-057<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 30, 2024<\/p>\n\n<p>On January 30, 2024, Google published a security advisory to address vulnerabilities in the following product::<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 121.0.6167.139\/140 (Windows) and 121.0.6167.139 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/01\/stable-channel-update-for-desktop_30.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-057","alert_type":396,"serial_number":"AV24-057","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4950,"title":"Ivanti security advisory (AV24-058)","uuid":"4ac274ed-e433-4ef5-942c-a8e0e340e8b1","banner":null,"lang":"en","date_modified":"2024-01-31","date_modified_ts":"2024-01-31T17:02:46Z","date_created":"2024-01-31T16:51:05Z","summary":null,"body":["<article data-history-node-id=\"4950\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-058\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-058<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>January 31, 2024<\/p>\n\n<p>On January 31, 2024, Ivanti published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Connect Secure (ICS) gateway\u00a0\u2013 versions 9.x and 22.x<\/li>\n\t<li>Ivanti Policy Secure (ICS) gateway\u00a0\u2013 versions 9.x and 22.x<\/li>\n\t<li>ZTA\u00a0\u2013 version 22.x<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow for privilege escalation and server-side request forgery (SSRF).<\/p>\n\n<p>Ivanti has indicated that CVE-2024-21893 have been actively exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US\">Ivanti Security Advisory\u00a0\u2013 CVE-2023-21888<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US%23t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=%5bSecurity%20Advisory%5d%20\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-058","alert_type":396,"serial_number":"AV24-058","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4951,"title":"Juniper Networks security advisory (AV24-059)","uuid":"b941f10d-ea6e-4837-9308-bb2398c9c6d6","banner":null,"lang":"en","date_modified":"2024-02-01","date_modified_ts":"2024-02-01T17:14:32Z","date_created":"2024-02-01T16:58:35Z","summary":null,"body":["<article data-history-node-id=\"4951\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-059\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-059<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 1, 2024<\/p>\n\n<p>On February 1, 2024, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Log Collector\u00a0\u2013 versions prior to v1.8.4<\/li>\n\t<li>SOAR Plugin App\u00a0\u2013 versions prior to 5.3.1<\/li>\n\t<li>Deployment Intelligence App\u00a0\u2013 versions prior to 3.0.12<\/li>\n\t<li>User Behavior Analytics Application\u00a0\u2013 versions prior to 4.1.14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2024-01-Security-Bulletin-JSA-Series-Multiple-vulnerabilities-resolved-in-JSA-Applications?language=en_US\">Juniper Networks Security Advisories\u00a0- JSA76718<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-059","alert_type":396,"serial_number":"AV24-059","subject":"juniper","moderation_state":"published","external_url":null},{"nid":4952,"title":"Apple security advisory (AV24-060)","uuid":"6276c9f9-23da-44da-85ff-6d073dbb38f3","banner":null,"lang":"en","date_modified":"2024-02-01","date_modified_ts":"2024-02-01T20:58:38Z","date_created":"2024-02-01T20:18:41Z","summary":null,"body":["<article data-history-node-id=\"4952\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-060\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-060<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a01, 2024<\/p>\n\n<p>On January\u00a031, 2024, Apple published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>visionOS\u00a0\u2013 versions prior to 1.0.2<\/li>\n<\/ul><p>Apple has received reports that CVE-2024-23222 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT214070\">About the security content of visionOS 1.0.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-060","alert_type":396,"serial_number":"AV24-060","subject":"apple","moderation_state":"published","external_url":null},{"nid":4953,"title":"Microsoft Edge security advisory (AV24-061)","uuid":"8f5c44bc-2d4b-4221-a20d-6282243d95cb","banner":null,"lang":"en","date_modified":"2024-02-02","date_modified_ts":"2024-02-02T16:35:04Z","date_created":"2024-02-02T16:27:32Z","summary":null,"body":["<article data-history-node-id=\"4953\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-061\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-061<br \/><!-- DATES Pick one update the day xx, delete the rest --><\/p>\n\n<p><strong>Date: <\/strong>February 2, 2024<\/p>\n\n<p>On February 1, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 121.0.2277.98<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 120.0.2210.167<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-1-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-061","alert_type":396,"serial_number":"AV24-061","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4954,"title":"Ubuntu security advisory (AV24-062)","uuid":"a1ee6e01-5270-4425-9457-6c0af3838ec6","banner":null,"lang":"en","date_modified":"2024-02-05","date_modified_ts":"2024-02-05T16:40:19Z","date_created":"2024-02-05T16:33:23Z","summary":null,"body":["<article data-history-node-id=\"4954\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-062\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-062<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 5, 2024<\/p>\n\n<p>Between January 29 and February 4, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6604-2\">Ubuntu Security Notice\u00a0- USN-6604-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6605-2\">Ubuntu Security Notice\u00a0- USN-6605-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6609-2\">Ubuntu Security Notice\u00a0- USN-6609-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-062","alert_type":396,"serial_number":"AV24-062","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4955,"title":"IBM security advisory (AV24-063)","uuid":"ce806b5a-3dce-4c26-9ed9-f692345747dc","banner":null,"lang":"en","date_modified":"2024-02-05","date_modified_ts":"2024-02-05T16:52:00Z","date_created":"2024-02-05T16:44:39Z","summary":null,"body":["<article data-history-node-id=\"4955\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-063\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-063<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 5, 2024<\/p>\n\n<p>Between January 29 and February 4, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for AIOps\u00a0\u2013 versions 4.1.0 to 4-3.0<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 version 12.0.x, 11.2.x and 11.1.x<\/li>\n\t<li>IBM Data Risk Manager\u00a0\u2013 version 2.0.6.19<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Sterling Control Center\u00a0\u2013 version 6.3.0<\/li>\n\t<li>IBM Sterling Transformation Extender\u00a0\u2013 versions 11.0, 10.1.2, 10.1.1 and 10.1.0<\/li>\n\t<li>IBM Storage Protect Plus\u00a0\u2013 version 10.1<\/li>\n\t<li>QRadar User Behaviour Analytics\u00a0\u2013 version 1.0.0 to 4.1.13<\/li>\n\t<li>Watson Discovery\u00a0\u2013 versions 4.0.0 to 4.8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-063","alert_type":396,"serial_number":"AV24-063","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4956,"title":"Red Hat security advisory (AV24-064)","uuid":"b307dd1b-a355-4ef6-982a-834c29315ae6","banner":null,"lang":"en","date_modified":"2024-02-05","date_modified_ts":"2024-02-05T17:07:34Z","date_created":"2024-02-05T17:00:06Z","summary":null,"body":["<article data-history-node-id=\"4956\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-064\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-064<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 5, 2024<\/p>\n\n<p>Between January 29 and February 4, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 Update Services for SAP Solutions 8.4 ppc64le<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0554\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0554<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0575\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0575<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0593\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0593<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-064","alert_type":396,"serial_number":"AV24-064","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4957,"title":"[Control systems] CISA ICS security advisories (AV24-065) ","uuid":"cf5d7c1b-c905-469a-9d75-702eac812cd5","banner":null,"lang":"en","date_modified":"2024-02-05","date_modified_ts":"2024-02-05T17:23:48Z","date_created":"2024-02-05T17:14:28Z","summary":null,"body":["<article data-history-node-id=\"4957\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-065\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-065<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 5, 2024<\/p>\n\n<p>Between January 29 and February 4, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA Edge\u00a0\u2013 versions 2020 R2 SP2 and prior<\/li>\n\t<li>Emerson Rosemount GC370XA, GC700XA and GC1500XA\u00a0\u2013 version 4.1.5<\/li>\n\t<li>Gessler GmbH WEB-MASTER\u00a0\u2013 version 7.9<\/li>\n\t<li>Hitron Systems DVR HVR-4781, DVR HVR-8781, DVR HVR-16781, DVR LGUVR-4H, DVR LGUVR-8H and DVR LGUVR-16H\u00a0\u2013 versions 1.03 to 4.02<\/li>\n\t<li>Mitsubishi Electric EZSocket\u00a0\u2013 versions 3.0 and later<\/li>\n\t<li>Mitsubishi Electric FR Configurator2\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric GT Designer3 Version1(GOT1000)\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric GT Designer3 Version1(GOT2000)\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric GX Works2\u00a0\u2013 versions 1.11M and later<\/li>\n\t<li>Mitsubishi Electric GX Works3\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric MELSOFT Navigator\u00a0\u2013 versions 1.04E and later<\/li>\n\t<li>Mitsubishi Electric MT Works2\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric MX Component\u00a0\u2013 versions 4.00A and later<\/li>\n\t<li>Mitsubishi Electric MX OPC Server DA\/UA (Software packaged with MC Works64)\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric WS0-GETH00200\u00a0\u2013 all serial numbers<\/li>\n\t<li>Rockwell Automation ControlLogix 5570\u00a0\u2013 firmware version 20.011<\/li>\n\t<li>Rockwell Automation ControlLogix 5570 Redundancy\u00a0\u2013 firmware version 20.054_kit1<\/li>\n\t<li>Rockwell Automation GuardLogix 5570\u00a0\u2013 firmware version 20.011<\/li>\n\t<li>Rockwell Automation FactoryTalk Service Platform\u00a0\u2013 versions prior to v6.4<\/li>\n\t<li>Rockwell Automation LP30, LP40, LP50 and BM40 Operator Panel\u00a0\u2013 versions prior to V3.5.19.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-065","alert_type":398,"serial_number":"AV24-065","subject":"ics","moderation_state":"published","external_url":null},{"nid":4958,"title":"Dell security advisory (AV24-066)","uuid":"9ee2170c-0191-4a34-b366-07e6f0605304","banner":null,"lang":"en","date_modified":"2024-02-05","date_modified_ts":"2024-02-05T19:42:58Z","date_created":"2024-02-05T19:19:15Z","summary":null,"body":["<article data-history-node-id=\"4958\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-066\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-066<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a05, 2024<\/p>\n\n<p>Between January\u00a029 and February\u00a04, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Avamar 19.10 Virtual Edition\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell Avamar Data Store Gen4T, Gen5A\u00a0\u2013 versions 19.4, 19.7, 19.8 and 19.9<\/li>\n\t<li>Dell Data Protection Search\u00a0\u2013 versions 19.2.0, 19.3.0, 19.4.0, 19.5.0, 19.5.1, 19.6.0, 19.6.1, 19.6.2 and 19.6.3<\/li>\n\t<li>DELL EMC VPLEX VS2\/VS6\u00a0\u2013 versions prior to 6.2.1<\/li>\n\t<li>vRealize Data Protection Extension\u00a0\u2013 versions 8.11.1, 8.11.2, 8.12.1, 8.12.2, 8.11.0, 8.12.0, 8.13.0 and 8.13.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-066","alert_type":396,"serial_number":"AV24-066","subject":"dell","moderation_state":"published","external_url":null},{"nid":4959,"title":"[Control systems] B&R security advisory (AV24-067)","uuid":"9c87e01a-4c47-4da1-bdce-d0baad48c5c0","banner":null,"lang":"en","date_modified":"2024-02-05","date_modified_ts":"2024-02-05T19:54:42Z","date_created":"2024-02-05T19:19:16Z","summary":null,"body":["<article data-history-node-id=\"4959\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-067\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-067<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a05, 2024<\/p>\n\n<p>On February\u00a05, 2024, B&amp;R published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>B&amp;R Automation Runtime\u00a0\u2013 versions prior to 14.93<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA23P004_FTP_uses_unsecure_encryption_mechanisms-f57c147c.pdf\">B&amp;R Advisory \u2013 SA23P004 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-067","alert_type":398,"serial_number":"AV24-067","subject":"br-automation","moderation_state":"published","external_url":null},{"nid":4960,"title":"Android security advisory \u2013 February 2024 monthly rollup (AV24-068)","uuid":"338c3daa-593a-44b8-8a77-421f27af667c","banner":null,"lang":"en","date_modified":"2024-02-05","date_modified_ts":"2024-02-05T20:06:02Z","date_created":"2024-02-05T19:19:16Z","summary":null,"body":["<article data-history-node-id=\"4960\" about=\"\/en\/alerts-advisories\/android-security-advisory-february-2024-monthly-rollup-av24-068\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-068<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a05, 2024<\/p>\n\n<p>On February\u00a05, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-02-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-february-2024-monthly-rollup-av24-068","alert_type":396,"serial_number":"AV24-068","subject":"android","moderation_state":"published","external_url":null},{"nid":4961,"title":"HPE security advisory (AV24-069)","uuid":"ff3c36a4-8f43-4451-b734-57329f6a88a3","banner":null,"lang":"en","date_modified":"2024-02-06","date_modified_ts":"2024-02-06T14:39:39Z","date_created":"2024-02-06T14:34:05Z","summary":null,"body":["<article data-history-node-id=\"4961\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-069\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-069<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 6, 2024<\/p>\n\n<p>On February 5, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console (UOC)\u00a0\u2013 versions prior to v3.1.1<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04590en_us\">HPE Security Bulletin\u00a0- hpesbgn04590en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-069","alert_type":396,"serial_number":"AV24-069","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4963,"title":"VMWare security advisory (AV24-070)","uuid":"813cadf2-85b4-487b-a775-7fea98853a31","banner":null,"lang":"en","date_modified":"2024-02-06","date_modified_ts":"2024-02-06T20:10:25Z","date_created":"2024-02-06T20:06:40Z","summary":null,"body":["<article data-history-node-id=\"4963\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-070\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-070<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a06, 2024<\/p>\n\n<p>On February\u00a06, 2024, VMWare released a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Aria Operations for Networks\u00a0\u2013 versions 6.x prior to 6.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0002.html\">VMWare Security Advisory\u00a0- VMSA-2024-0002<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMWare Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-070","alert_type":396,"serial_number":"AV24-070","subject":"vmware","moderation_state":"published","external_url":null},{"nid":4965,"title":"Google Chrome security advisory (AV24-071)","uuid":"7c68eacc-efc0-4706-b3d5-6b8e502893b0","banner":null,"lang":"en","date_modified":"2024-02-07","date_modified_ts":"2024-02-07T17:02:08Z","date_created":"2024-02-07T16:52:49Z","summary":null,"body":["<article data-history-node-id=\"4965\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-071\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-071<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a07, 2024<\/p>\n\n<p>On February\u00a06, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 121.0.6167.160\/161 (Windows) and 121.0.6167.160 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/02\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-071","alert_type":396,"serial_number":"AV24-071","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4966,"title":"Cisco security advisory (AV24-072)","uuid":"7d24a5d2-c762-45ec-9860-8b35023e739b","banner":null,"lang":"en","date_modified":"2024-02-07","date_modified_ts":"2024-02-07T17:08:18Z","date_created":"2024-02-07T16:52:53Z","summary":null,"body":["<article data-history-node-id=\"4966\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-072\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-072<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a07, 2024<\/p>\n\n<p>On February\u00a07, 2024, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Expressway Series\u00a0\u2013 versions prior to 14.3.4<\/li>\n\t<li>Secure Endpoint Connector for Windows\u00a0\u2013 versions prior to 7.5.17 and 8.2.1<\/li>\n\t<li>Secure Endpoint Private Cloud\u00a0\u2013 versions prior to 3.8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-expressway-csrf-KnnZDMj3\">Cisco Advisory\u00a0- cisco-sa-expressway-csrf-KnnZDMj3<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-clamav-hDffu6t\">Cisco Advisory\u00a0- cisco-sa-clamav-hDffu6t<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-072","alert_type":396,"serial_number":"AV24-072","subject":"cisco","moderation_state":"published","external_url":null},{"nid":4968,"title":"SonicWall security advisory (AV24-073)","uuid":"966c2bb7-d41a-4021-99e3-f937c3494152","banner":null,"lang":"en","date_modified":"2024-02-08","date_modified_ts":"2024-02-08T15:26:58Z","date_created":"2024-02-08T14:32:00Z","summary":null,"body":["<article data-history-node-id=\"4968\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-073\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-073<br \/><!-- DATES Pick one update the day xx, delete the rest --><\/p>\n\n<p><strong>Date: <\/strong>February 8,<\/p>\n\n<p>On February 7, 2024, SonicWall published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SonicOS\u00a0\u2013 firmware version 7.1.1-7040<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to authentication bypass.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2024-0003\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2024-0003<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-073","alert_type":396,"serial_number":"AV24-073","subject":"other","moderation_state":"published","external_url":null},{"nid":4971,"title":"Fortinet security advisory (AV24-074)","uuid":"fa17f596-2e4e-4c15-8607-7c43b9042717","banner":null,"lang":"en","date_modified":"2024-02-09","date_modified_ts":"2024-02-09T16:14:06Z","date_created":"2024-02-09T16:06:11Z","summary":null,"body":["<article data-history-node-id=\"4971\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-074\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-074\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><\/p>\n<p><strong>Date: <\/strong>February 09, 2024\n<\/p>\n<p>On February 8, 2024, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:\n<\/p>\n<ul><li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.2<\/li>\n  <li>FortiOS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.6<\/li>\n  <li>FortiOS 7.0\u00a0\u2013 versions 7.0.0 to 7.0.13<\/li>\n  <li>FortiOS 6.4\u00a0\u2013 versions 6.4.0 to 6.4.14<\/li>\n  <li>FortiOS 6.2\u00a0\u2013 versions 6.2.0 to 6.2.15<\/li>\n  <li>FortiOS 6.0\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<p>Fortinet has indicated that CVE-2024-21762 may have been exploited.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-24-015\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-015<\/a><\/li>\n  <li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-029\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-029<\/a><\/li>\n  <li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-074","alert_type":396,"serial_number":"AV24-074","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":4972,"title":"Ivanti security advisory (AV24-075)","uuid":"a66ba119-419d-4ee5-841c-23e7af34373a","banner":null,"lang":"en","date_modified":"2024-02-09","date_modified_ts":"2024-02-09T16:45:59Z","date_created":"2024-02-09T16:31:48Z","summary":null,"body":["<article data-history-node-id=\"4972\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-075\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-075\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a09, 2024\n<\/p>\n<p>On February\u00a08, 2024, Ivanti published a security advisory to address a vulnerability in the following products:\n<\/p>\n<ul><li>Ivanti Connect Secure (ICS) gateway\u00a0\u2013 versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and 22.5R2.2<\/li>\n  <li>Ivanti Policy Secure (ICS) gateway\u00a0\u2013 version 22.5R1.1<\/li>\n  <li>ZTA gateway\u00a0\u2013 versions 22.6R1.3<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow for authentication bypass.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates once available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US\">Ivanti Security Advisory\u00a0- CVE-2024-22024 (XXE) for Ivanti Connect Secure and Ivanti Policy Secure<\/a><\/li>\n  <li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-075","alert_type":396,"serial_number":"AV24-075","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":4974,"title":"Vulnerabilities impacting Fortinet FortiOS \u2013 Update 1","uuid":"9977a228-915a-4b27-8604-e655add7684c","banner":null,"lang":"en","date_modified":"2024-10-11","date_modified_ts":"2024-10-11T19:55:48Z","date_created":"2024-02-09T18:57:44Z","summary":null,"body":["<article data-history-node-id=\"4974\" about=\"\/en\/alerts-advisories\/vulnerabilities-impacting-fortinet-fortios\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL24-003<br \/><strong>Date:\u00a0<\/strong>October\u00a011,\u00a02024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On February 8, 2024, the Cyber Centre became aware of vulnerabilities impacting multiple versions of Fortinet FortiOS. In response to this advisory the Cyber Centre released advisory AV24-074 on February 9, 2024<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>Fortinet reports that CVE-2024-21762 is an out-of-bounds write vulnerability in SSL VPN that may allow a remote unauthenticated threat actor to execute arbitrary code and commands via specially crafted HTTP request<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. Fortinet has indicated that CVE-2024-21762 may have been exploited in the wild.\u00a0<\/p>\n\n<p>A second significant vulnerability (CVE-2024-23113) was reported which is a format string bug within the FortiOS FortiGate to FortiManager (fgfmd) protocol.\u00a0 The vulnerability may allow a remote, unauthenticated threat actor to execute arbitrary code or commands via specially crafted requests<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. Fortinet has not indicated that this vulnerability has been exploited.<\/p>\n\n<p>On February 9, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) updated their Known Exploited Vulnerabilities (KEV) Catalog in response to the Fortinet FortiOS out-of-bound write vulnerability CVE-2024-21762<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n<\/section><section><h2>Update 1<\/h2>\n\n<p>Fortinet updated their advisories<sup id=\"fn2-rf2\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf2\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> to include additional affected products and to advise that both vulnerabilities have been exploited. The Cyber Centre has noted the additional affected products under Suggested Actions below.<\/p>\n\n<p>On October\u00a09, 2024, CISA released a statement<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> indicating that CVE-2024-23113 is being actively exploited in the wild and added it to their Known Exploited Vulnerabilities (KEV) Catalog<sup id=\"fn4-rf2\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>Fortinet recommends as a temporary workaround, to disable the SSL-VPN service until patching can be completed for CVE-2024-21762<sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>In regard to CVE-2024-23113, Fortinet also recommends that organizations consider whether there is a need to expose the fgfm daemon (port 541) to the internet for inbound connections, until patching can be completed<sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre strongly recommends that organizations determine if any Fortinet devices need to be patched to remediate these vulnerabilities.<\/p>\n\n<p><strong>Version:<\/strong><\/p>\n\n<ul class=\"list-unstyled\"><li>FortiOS 7.6\u00a0- <strong>Affected:<\/strong> Not affected\u00a0- <strong>Solution:<\/strong> Not Applicable<\/li>\n\t<li>FortiOS 7.4\u00a0- <strong>Affected:<\/strong> 7.4.0 to 7.4.2\u00a0- <strong>Solution:<\/strong> Upgrade to 7.4.3 or above<\/li>\n\t<li>FortiOS 7.2\u00a0- <strong>Affected:<\/strong> 7.2.0 to 7.2.6\u00a0- <strong>Solution:<\/strong> Upgrade to 7.2.7 or above<\/li>\n\t<li>FortiOS 7.0\u00a0- <strong>Affected:<\/strong> 7.0.0 to 7.0.13\u00a0- <strong>Solution:<\/strong> Upgrade to 7.0.14 or above<\/li>\n\t<li>FortiOS 6.4\u00a0- <strong>Affected:<\/strong> 6.4.0 to 6.4.14\u00a0- <strong>Solution:<\/strong> Upgrade to 6.4.15 or above<\/li>\n\t<li>FortiOS 6.2\u00a0- <strong>Affected:<\/strong> 6.2.0 to 6.2.15\u00a0- <strong>Solution:<\/strong> Upgrade to 6.2.16 or above<\/li>\n\t<li>FortiOS 6.0\u00a0- <strong>Affected:<\/strong> 6.0 all versions\u00a0- <strong>Solution:<\/strong> Migrate to a fixed release<\/li>\n\t<li>FortiPAM 1.3\u00a0- <strong>Affected:<\/strong> Not affected\u00a0- <strong>Solution:<\/strong> Not Applicable<\/li>\n\t<li>FortiPAM 1.2\u00a0- <strong>Affected:<\/strong> 1.2 all versions\u00a0- <strong>Solution:<\/strong> Migrate to a fixed release<\/li>\n\t<li>FortiPAM 1.1\u00a0- <strong>Affected:<\/strong> 1.1 all versions\u00a0- <strong>Solution:<\/strong> Migrate to a fixed release<\/li>\n\t<li>FortiPAM 1.0\u00a0- <strong>Affected:<\/strong> 1.0 all versions\u00a0- <strong>Solution:<\/strong> Migrate to a fixed release<\/li>\n\t<li>FortiProxy 7.4\u00a0- <strong>Affected:<\/strong> 7.4.0 through 7.4.2\u00a0- <strong>Solution:<\/strong> Upgrade to 7.4.3 or above<\/li>\n\t<li>FortiProxy 7.2\u00a0- <strong>Affected:<\/strong> 7.2.0 through 7.2.8\u00a0- <strong>Solution:<\/strong> Upgrade to 7.2.9 or above<\/li>\n\t<li>FortiProxy 7.0\u00a0- <strong>Affected:<\/strong> 7.0.0 through 7.0.15\u00a0- <strong>Solution:<\/strong> Upgrade to 7.0.16 or above<\/li>\n\t<li>FortiProxy 2.0\u00a0- <strong>Affected:<\/strong> 2.0.0 through 2.0.13\u00a0- <strong>Solution:<\/strong> Upgrade to 2.0.14 or above<\/li>\n\t<li>FortiProxy 1.2\u00a0- <strong>Affected:<\/strong> 1.2 all versions\u00a0- <strong>Solution:<\/strong> Migrate to a fixed release<\/li>\n\t<li>FortiProxy 1.1\u00a0- <strong>Affected:<\/strong> 1.1 all versions\u00a0- <strong>Solution:<\/strong> Migrate to a fixed release<\/li>\n\t<li>FortiProxy 1.0\u00a0- <strong>Affected:<\/strong> 1.0 all versions\u00a0- <strong>Solution:<\/strong> Migrate to a fixed release<\/li>\n\t<li>FortiWeb 7.4\u00a0- <strong>Affected:<\/strong> 7.4.0 through 7.4.2\u00a0- <strong>Solution:<\/strong> Upgrade to 7.4.3 or above<\/li>\n<\/ul><\/section><section><p>Organizations should also review and implement the Cyber Centre's Top 10 IT Security Actions <sup id=\"fn5a-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>consolidating, monitoring, and defending Internet gateways<\/li>\n\t<li>patching operating systems and applications<\/li>\n\t<li>isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><h2>Partner Reporting<\/h2>\n\n<p><a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/critical-vulnerability-fortios\">ACSC\u00a0- Critical Vulnerability in FortiOS\u00a0<\/a><\/p>\n\n<p><a href=\"https:\/\/www.ncsc.govt.nz\/news\/cves-fortios-ssl-vpn\/\">NCSC-NZ\u00a0- Cyber Security Alert: CVEs affecting FortiOS SSL VPN<\/a><\/p>\n<\/section><!--************************************************* ENDNOTES SECTION&nbsp;- IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <i>Official Languages Act<\/i> is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-074\">CCCS AV24-074\u00a0\u2013 Fortinet Security Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-24-015\">FortiOS\u00a0- Out-of-bound Write in sslvpnd<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-029\">FortiOS\u00a0- Format String Bug in fgfmd<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities Catalog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2024\/10\/09\/cisa-adds-three-known-exploited-vulnerabilities-catalog\">CISA Adds Three Known Exploited Vulnerabilities to Catalog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-impacting-fortinet-fortios","alert_type":397,"serial_number":"AL24-003","subject":"other","moderation_state":"published","external_url":null},{"nid":4973,"title":"Microsoft Edge security advisory (AV24-076)","uuid":"f43e1872-08f3-4fc4-a91b-d5cc3f64daf6","banner":null,"lang":"en","date_modified":"2024-02-09","date_modified_ts":"2024-02-09T19:32:34Z","date_created":"2024-02-09T19:28:06Z","summary":null,"body":["<article data-history-node-id=\"4973\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-076\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-076<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a09, 2024<\/p>\n\n<p>On February\u00a08, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 121.0.2277.112<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 120.0.2210.175<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-8-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-076","alert_type":396,"serial_number":"AV24-076","subject":"other","moderation_state":"published","external_url":null},{"nid":4976,"title":"Ubuntu security advisory (AV24-077)","uuid":"5b8b7737-acf2-4a6a-bf31-0be4cc5deaa5","banner":null,"lang":"en","date_modified":"2024-02-12","date_modified_ts":"2024-02-12T19:47:57Z","date_created":"2024-02-12T19:37:16Z","summary":null,"body":["<article data-history-node-id=\"4976\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-077\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-077<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a012, 2024<\/p>\n\n<p>Between February\u00a05 and 11, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-077","alert_type":396,"serial_number":"AV24-077","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4977,"title":"Dell security advisory (AV24-078)","uuid":"11cbbff3-c7e6-4475-8be7-954c2bd08d91","banner":null,"lang":"en","date_modified":"2024-02-12","date_modified_ts":"2024-02-12T19:58:58Z","date_created":"2024-02-12T19:37:16Z","summary":null,"body":["<article data-history-node-id=\"4977\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-078\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-078<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a012, 2024<\/p>\n\n<p>Between February\u00a05 and 11, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell PowerProtect DP Series Appliance (IDPA)\u00a0\u2013 versions 2.6.1 to 2.7.6 with Data Protection Central OS Update prior to dpc-osupdate-1.1.16-1<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 versions 19.5 to 10.10.0-4 with Data Protection Central OS Update prior to dpc-osupdate-1.1.16-1<\/li>\n\t<li>Dell SmartFabric Storage Software\u00a0\u2013 versions prior to 1.4.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000221816\/dsa-2024-057-security-update-for-dell-data-protection-central-for-third-party-vulnerabilities\">Dell Security Update\u00a0\u2013 Dell Data Protection Central<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000221816\/dsa-2024-057-security-update-for-dell-data-protection-central-for-third-party-vulnerabilities\">Dell Security Update\u00a0\u2013 PowerProtect DP Series Appliance (IDPA)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000221912\/dsa-20204-047-security-update-for-dell-smartfabric-storage-software-vulnerabilities\">Dell Security Update\u00a0\u2013 SmartFabric Storage Software<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-078","alert_type":396,"serial_number":"AV24-078","subject":"dell","moderation_state":"published","external_url":null},{"nid":4978,"title":"IBM security advisory (AV24-079)","uuid":"a776e4f5-d49c-4312-990f-f1e493e33bec","banner":null,"lang":"en","date_modified":"2024-02-12","date_modified_ts":"2024-02-12T20:23:48Z","date_created":"2024-02-12T19:37:21Z","summary":null,"body":["<article data-history-node-id=\"4978\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-079\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-079<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a012, 2024<\/p>\n\n<p>Between February\u00a05 and 11, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Object System\u00a0\u2013 version 3.18.0.21 and prior<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 versions 2.3.1.1, 2.3.3.7 and 2.3.20 (Power)<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 versions 2.3.3.0 to 2.3.3.6 (Intel)<\/li>\n\t<li>IBM MaaS360 Cloud Extender Agent\u00a0\u2013 version 3.000.250.023 and prior<\/li>\n\t<li>IBM MaaS360 Mobile Enterprise Gateway\u00a0\u2013 version 3.000.300 and prior<\/li>\n\t<li>IBM MaaS360 VPN\u00a0\u2013 version 3.000.200 and prior<\/li>\n\t<li>IBM Sterling Control Center\u00a0\u2013 version 6.3.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7116050\">IBM Security Bulletin\u00a0\u2013 7116050<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7115283\">IBM Security Bulletin\u00a0\u2013 7115283<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7115287\">IBM Security Bulletin\u00a0\u2013 7115287<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7114810\">IBM Security Bulletin\u00a0\u2013 7114810<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-079","alert_type":396,"serial_number":"AV24-079","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4979,"title":"Red Hat security advisory (AV24-080)","uuid":"56c781ad-efbb-4d29-81ec-557451c790f9","banner":null,"lang":"en","date_modified":"2024-02-12","date_modified_ts":"2024-02-12T20:33:49Z","date_created":"2024-02-12T20:27:13Z","summary":null,"body":["<article data-history-node-id=\"4979\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-080\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-080<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a012, 2024<\/p>\n\n<p>Between February\u00a05 and 11, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host\u00a0\u2013 version 4 for RHEL 8 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0725\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0725<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0724\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0724<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-080","alert_type":396,"serial_number":"AV24-080","subject":"redhat","moderation_state":"published","external_url":null},{"nid":4980,"title":"[Control systems] CISA ICS security advisories (AV24-081)","uuid":"59102ff2-708a-4d2a-83c5-7f6b9a84b355","banner":null,"lang":"en","date_modified":"2024-02-12","date_modified_ts":"2024-02-12T20:42:47Z","date_created":"2024-02-12T20:27:14Z","summary":null,"body":["<article data-history-node-id=\"4980\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-081\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-081<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a012, 2024<\/p>\n\n<p>Between February\u00a05 and 11, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Qolsys IQ Panel 4\u00a0\u2013 versions prior to 4.4.2<\/li>\n\t<li>Qolsys IQ4 Hub\u00a0\u2013 versions prior to 4.4.2<\/li>\n\t<li>HID iCLASS SE CP1000 Encoder\u00a0\u2013 all versions<\/li>\n\t<li>HID iCLASS SE Readers\u00a0\u2013 all versions<\/li>\n\t<li>HID iCLASS SE Reader Modules\u00a0\u2013 all versions<\/li>\n\t<li>HID iCLASS SE Reader configuration cards\u00a0\u2013 all versions<\/li>\n\t<li>HID iCLASS SE Processors\u00a0\u2013 all versions<\/li>\n\t<li>HID OMNIKEY Readers\u00a0\u2013 multiple models and versions<\/li>\n\t<li>HID iCLASS SE reader configuration cards\u00a0\u2013 all versions<\/li>\n\t<li>HID OMNIKEY Secure Elements reader configuration cards\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-039-01\">CISA ICS Advisory\u00a0\u2013 icsa-24-039-07<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-037-01\">CISA ICS Advisory\u00a0\u2013 icsa-24-037-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-037-02\">CISA ICS Advisory\u00a0\u2013 icsa-24-037-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-081","alert_type":398,"serial_number":"AV24-081","subject":"ics","moderation_state":"published","external_url":null},{"nid":4981,"title":"HPE security advisory (AV24-082)","uuid":"3ce0298e-d251-4e13-b7b6-a71b93df7e1d","banner":null,"lang":"en","date_modified":"2024-02-13","date_modified_ts":"2024-02-13T15:23:56Z","date_created":"2024-02-13T15:19:04Z","summary":null,"body":["<article data-history-node-id=\"4981\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-082\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-082<br \/><strong>Date: <\/strong>February 13, 2024<\/p>\n\n<p>On February 12, 2024, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE SimpliVity 380 Gen10 Plus\u00a0\u2013 HPE OmniStack firmware versions prior to 2024_0131<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to information disclosure, privilege escalation or denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04566en_us\">HPE Security Bulletin\u00a0- hpesbhf04566en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-082","alert_type":396,"serial_number":"AV24-082","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4983,"title":"[Control systems] Schneider Electric security advisory (AV24-083)","uuid":"aa0666a8-b39f-43a2-a7f0-bb3798a8d691","banner":null,"lang":"en","date_modified":"2024-02-13","date_modified_ts":"2024-02-13T20:26:39Z","date_created":"2024-02-13T20:16:06Z","summary":null,"body":["<article data-history-node-id=\"4983\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-083\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-083<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 13, 2024<\/p>\n\n<p>On February 13, 2024, Schneider Electric published security advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Control Expert\u00a0\u2013 versions prior to v16.0<\/li>\n\t<li>EcoStruxure IT Gateway\u00a0\u2013 versions 1.20.x and prior<\/li>\n\t<li>EcoStruxure Process Expert\u00a0\u2013 versions prior to v2023<\/li>\n\t<li>Modicon M340 CPU\u00a0\u2013 versions prior to sv3.60<\/li>\n\t<li>Modicon M580 CPU\u00a0\u2013 versions prior to sv4.20<\/li>\n\t<li>Modicon M580 CPU Safety\u00a0\u2013 all versions<\/li>\n\t<li>Harmony Control Relay RMNF22TB30\u00a0\u2013 all versions<\/li>\n\t<li>Harmony Timer Relay RENF22R2MMW\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-044-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-044-01.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-044-01 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-044-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-044-02.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-044-02 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-044-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-044-03.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-044-03 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-083","alert_type":398,"serial_number":"AV24-083","subject":"other","moderation_state":"published","external_url":null},{"nid":4984,"title":"Microsoft security advisory \u2013 February 2024 monthly rollup (AV24-084)","uuid":"3c516c96-5062-4395-be81-d244f6e0818b","banner":null,"lang":"en","date_modified":"2024-02-13","date_modified_ts":"2024-02-13T20:34:07Z","date_created":"2024-02-13T20:21:06Z","summary":null,"body":["<article data-history-node-id=\"4984\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-february-2024-monthly-rollup-av24-084\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-084<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a013, 2024<\/p>\n\n<p>On February\u00a013, 2024, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps for Enterprise\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Dynamics 365 Business Central\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Exchange Server 2016 and 2019\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Office 2016, 2019 and LTSC\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-21413, CVE-2024-21412, CVE-2024-21410 and CVE-2024-21351 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Feb\">February 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-21413\">National Vulnerability Database\u00a0\u2013 CVE-2024-21413 Detail<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-february-2024-monthly-rollup-av24-084","alert_type":396,"serial_number":"AV24-084","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":4985,"title":"[Control systems] Siemens security advisory (AV24-085)","uuid":"6e826715-a814-4f23-bdf6-d05ccb4f8eae","banner":null,"lang":"en","date_modified":"2024-02-13","date_modified_ts":"2024-02-13T21:10:26Z","date_created":"2024-02-13T21:03:51Z","summary":null,"body":["<article data-history-node-id=\"4985\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-085\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-085<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a013, 2024<\/p>\n\n<p>On February\u00a013, 2024, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Location Intelligence\u00a0\u2013 versions prior to V4.3<\/li>\n\t<li>Polarion ALM\u00a0\u2013 all versions<\/li>\n\t<li>Parasolid\u00a0\u2013 multiple versions<\/li>\n\t<li>RUGGEDCOM APE1808\u00a0\u2013 all versions with Nozomi Guardian\u00a0\/\u00a0CMC prior to 23.3.0<\/li>\n\t<li>SCALANCE CP343-1 Devices\u00a0\u2013 all versions<\/li>\n\t<li>SCALANCE XCM-\/XRM-300\u00a0\u2013 versions prior to V2.4<\/li>\n\t<li>SCALANCE W1750D\u00a0\u2013 all versions<\/li>\n\t<li>SCALANCE SC-600 Family\u00a0\u2013 versions prior to 3.1<\/li>\n\t<li>SIMATIC WinCC\u00a0\u2013 multiple versions<\/li>\n\t<li>SIMATIC OpenPCS 7\u00a0\u2013 version 9.1<\/li>\n\t<li>SIMATIC BATCH\u00a0\u2013 version 9.1<\/li>\n\t<li>SIMATIC PCS 7\u00a0\u2013 version 9.1<\/li>\n\t<li>SIMATIC Route Control\u00a0\u2013 version 9.1<\/li>\n\t<li>SIMATIC RTLS Gateway\u00a0\u2013 multiple models and versions<\/li>\n\t<li>SINEC NMS\u00a0\u2013 firmware versions prior to V2.0 SP1<\/li>\n\t<li>SIDIS Prime\u00a0\u2013 versions prior to V4.0.400<\/li>\n\t<li>Simatic WinCC Runtime Professional\u00a0\u2013 versions 18 and 19<\/li>\n\t<li>Simcenter Femap\u00a0\u2013 multiple versions<\/li>\n\t<li>Tecnomatix Plant Simulation V2201 and V2302\u00a0\u2013 all versions<\/li>\n\t<li>Unicam FX\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-085","alert_type":398,"serial_number":"AV24-085","subject":"siemens","moderation_state":"published","external_url":null},{"nid":4987,"title":"Adobe security advisory (AV24-086)","uuid":"e5200056-420d-44d6-83aa-9847e4cf8fde","banner":null,"lang":"en","date_modified":"2024-02-14","date_modified_ts":"2024-02-14T13:56:25Z","date_created":"2024-02-14T14:24:36Z","summary":null,"body":["<article data-history-node-id=\"4987\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-086\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-086<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a014, 2024<\/p>\n\n<p>On February\u00a013, 2024, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Acrobat DC\u00a0\u2013 version 23.008.20470 and prior<\/li>\n\t<li>Acrobat Reader DC\u00a0\u2013 version 23.008.20470 and prior<\/li>\n\t<li>Acrobat 2020\u00a0\u2013 version 20.005.30539 and prior<\/li>\n\t<li>Acrobat Reader 2020\u00a0\u2013 version 20.005.30539 and prior<\/li>\n\t<li>Adobe Audition\u00a0\u2013 versions 23.6.2 and prior and 24.0.3 and prior<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe FrameMaker Publishing Server\u00a0\u2013 version 2022 Update 1 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 9.1.1 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version 13.1.0 and prior<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-086","alert_type":396,"serial_number":"AV24-086","subject":"adobe","moderation_state":"published","external_url":null},{"nid":4986,"title":"Google Chrome security advisory (AV24-087)","uuid":"9b0c1cf0-73c5-486d-a905-d1174f5cc455","banner":null,"lang":"en","date_modified":"2024-02-14","date_modified_ts":"2024-02-14T14:45:58Z","date_created":"2024-02-14T14:31:33Z","summary":null,"body":["<article data-history-node-id=\"4986\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-087\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-087\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 14, 2024\n<\/p>\n<p>On February 13, 2024, Google published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 121.0.6167.184\/185 (Windows) and 121.0.6167.184 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/02\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-087","alert_type":396,"serial_number":"AV24-087","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":4988,"title":"[Control systems] B&R security advisory (AV24-088)","uuid":"b307cdff-8b0d-4f87-b464-0f4fc76652fd","banner":null,"lang":"en","date_modified":"2024-02-14","date_modified_ts":"2024-02-14T18:58:54Z","date_created":"2024-02-14T18:50:10Z","summary":null,"body":["<article data-history-node-id=\"4988\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av23-088\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-088<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 14, 2024<\/p>\n\n<p>On February 14, 2024, B&amp;R published a security advisory to address a vulnerability in multiple products:<\/p>\n\n<ul><li>APROL R 4.2 (SLE12)\u00a0\u2013 all versions<\/li>\n\t<li>APROL R 4.4 (SLE15)\u00a0\u2013 versions prior to APROL-AutoYaST-DVD-V4.4-000.0.240108-SLE15-SP4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA24P004_SSH_Service_Vulnerable_To_Terrapin_Attack-275204bc.pdf\">B&amp;R Advisory\u00a0\u2013 SA24P004 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av23-088","alert_type":398,"serial_number":"AV24-088","subject":"other","moderation_state":"published","external_url":null},{"nid":4989,"title":"HPE security advisory (AV24-089)","uuid":"68e49c23-63ac-4463-8ce1-6c2f7e22c506","banner":null,"lang":"en","date_modified":"2024-02-14","date_modified_ts":"2024-02-14T19:38:00Z","date_created":"2024-02-14T19:07:07Z","summary":null,"body":["<article data-history-node-id=\"4989\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-089\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-089<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 14, 2024<\/p>\n\n<p>On February 13, 2024, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant DL, DX and XL servers\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04591en_us\">HPE Security Bulletin\u00a0- hpesbhf04591en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04594en_us\">HPE Security Bulletin\u00a0- hpesbhf04594en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-089","alert_type":396,"serial_number":"AV24-089","subject":"hpe","moderation_state":"published","external_url":null},{"nid":4990,"title":"SAP security advisory \u2013 February 2024 monthly rollup (AV24-090)","uuid":"56188dfe-8d0f-4801-a0a6-5b68f8f81694","banner":null,"lang":"en","date_modified":"2024-02-14","date_modified_ts":"2024-02-14T19:43:09Z","date_created":"2024-02-14T19:37:03Z","summary":null,"body":["<article data-history-node-id=\"4990\" about=\"\/en\/alerts-advisories\/sap-security-advisory-february-2024-monthly-rollup-av24-090\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-090<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a014, 2024<\/p>\n\n<p>On February\u00a013, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Application Basis (ABA)\u00a0\u2013 versions 700, 701, 702, 731, 740, 750, 751, 752, 75C and 75I<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/february-2024.html\">SAP Security Patch Day\u00a0\u2013 February 2024<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-february-2024-monthly-rollup-av24-090","alert_type":396,"serial_number":"AV24-090","subject":"sap","moderation_state":"published","external_url":null},{"nid":4991,"title":"F5 security advisory (AV24-091)","uuid":"8b7e1fad-fa3c-4abb-8c06-98811c1515de","banner":null,"lang":"en","date_modified":"2024-02-14","date_modified_ts":"2024-02-14T20:59:41Z","date_created":"2024-02-14T20:43:39Z","summary":null,"body":["<article data-history-node-id=\"4991\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av24-091\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-091<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 14, 2024<\/p>\n\n<p>On February 14, 2024, F5 published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP\u00a0\u2013 multiple versions and modules<\/li>\n\t<li>NGIX Plus\u00a0\u2013 versions R30 and R31<\/li>\n\t<li>NGIX Open Source\u00a0\u2013 versions 1.25.0 to 1.25.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=cve&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending\">F5 Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av24-091","alert_type":396,"serial_number":"AV24-091","subject":"f5","moderation_state":"published","external_url":null},{"nid":4993,"title":"ISC BIND security advisory (AV24-092)","uuid":"cc0e4d56-1ff3-416d-a034-7a501e848785","banner":null,"lang":"en","date_modified":"2024-02-16","date_modified_ts":"2024-02-16T18:18:35Z","date_created":"2024-02-16T18:08:23Z","summary":null,"body":["<article data-history-node-id=\"4993\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av24-092\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-092<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 16, 2024<\/p>\n\n<p>On February 14, 2024, ISC published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ISC BIND 9\u00a0\u2013 versions prior to 9.16.48, 9.18.24, and 9.19.21<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.isc.org\/blogs\/2024-bind-security-release\/\">ISC BIND\u00a0\u2013 2024 bind security release<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2023-50387\">ISC BIND security advisory\u00a0- CVE-2023-50387<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2023-50868\">ISC BIND security advisory\u00a0- CVE-2023-50868<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av24-092","alert_type":396,"serial_number":"AV24-092","subject":"other","moderation_state":"published","external_url":null},{"nid":4994,"title":"SolarWinds security advisory (AV24-093)","uuid":"c3e0422b-8aa0-414e-bcd5-cefbe71807f9","banner":null,"lang":"en","date_modified":"2024-02-16","date_modified_ts":"2024-02-16T20:07:07Z","date_created":"2024-02-16T20:01:08Z","summary":null,"body":["<article data-history-node-id=\"4994\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-093\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-093<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a016, 2024<\/p>\n\n<p>On February\u00a06, 2024, SolarWinds published Security Advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SolarWinds Access Rights Manager\u00a0\u2013 versions prior to 2023.2.3<\/li>\n\t<li>SolarWinds Platform\u00a0\u2013 versions prior to 2024.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.solarwinds.com\/en\/success_center\/arm\/content\/release_notes\/arm_2023-2-3_release_notes.htm\">SolarWinds Security Advisory\u00a0\u2013 arm_2023-2-3_release_notes<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.solarwinds.com\/en\/success_center\/orionplatform\/content\/release_notes\/solarwinds_platform_2024-1_release_notes.htm\">SolarWinds Security Advisory\u00a0\u2013 solarwinds_platform_2024-1_release_notes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-093","alert_type":396,"serial_number":"AV24-093","subject":"other","moderation_state":"published","external_url":null},{"nid":4995,"title":"IBM security advisory (AV24-094)","uuid":"2b92d0e4-07f1-4086-a1bd-2365a98501f5","banner":null,"lang":"en","date_modified":"2024-02-19","date_modified_ts":"2024-02-19T16:12:26Z","date_created":"2024-02-19T16:06:46Z","summary":null,"body":["<article data-history-node-id=\"4995\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-094\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-094<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 19, 2024<\/p>\n\n<p>Between February 12 and 18, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>DataPower Operations Dashboard\u00a0\u2013 version 1.0.19.0<\/li>\n\t<li>IBM Cloud APM, Advanced Private\u00a0\u2013 version 8.1.4<\/li>\n\t<li>IBM Cloud APM, Base Private\u00a0\u2013 version 8.1.4<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 version 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>QRadar Suite Software\u00a0\u2013 version 1.10.12.0 to 1.10.17.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-094","alert_type":396,"serial_number":"AV24-094","subject":"ibm","moderation_state":"published","external_url":null},{"nid":4996,"title":"Dell security advisory (AV24-095)","uuid":"ae75b1ed-712c-409c-a249-b28a5fd6916d","banner":null,"lang":"en","date_modified":"2024-02-19","date_modified_ts":"2024-02-19T16:26:19Z","date_created":"2024-02-19T16:21:16Z","summary":null,"body":["<article data-history-node-id=\"4996\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-095\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-095<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 19, 2024<\/p>\n\n<p>Between February\u00a012 and February\u00a018,\u00a02024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 version 03.00.00.00<\/li>\n\t<li>Dell Power Protect Data Manager\u00a0\u2013 version 19.15 and prior<\/li>\n\t<li>Dell Unity\u00a0\u2013 versions prior to 5.4<\/li>\n\t<li>RecoverPoint for Virtual Machines\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-095","alert_type":396,"serial_number":"AV24-095","subject":"dell","moderation_state":"published","external_url":null},{"nid":4997,"title":"Ubuntu security advisory (AV24-096)","uuid":"ec9ee1c6-d7d8-42be-b48b-1583d3d613e3","banner":null,"lang":"en","date_modified":"2024-02-19","date_modified_ts":"2024-02-19T16:42:28Z","date_created":"2024-02-19T16:29:29Z","summary":null,"body":["<article data-history-node-id=\"4997\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-096\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-096<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a019, 2024<\/p>\n\n<p>Between February\u00a012 and 18, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-096","alert_type":396,"serial_number":"AV24-096","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":4998,"title":"[Control systems] CISA ICS security advisories (AV24-097)","uuid":"8ced67b5-f040-48a8-9639-f20f1eb4146a","banner":null,"lang":"en","date_modified":"2024-02-19","date_modified_ts":"2024-02-19T16:43:32Z","date_created":"2024-02-19T16:29:29Z","summary":null,"body":["<article data-history-node-id=\"4998\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-097\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-097<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a019, 2024<\/p>\n\n<p>Between February\u00a012 and 18, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitsubishi Electric MELSEC iQ-R Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SCALANCE W1750D\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMATIC CP 343-1 (6GK7343-1EX30-0XE0)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIPLUS NET CP 343-1 (6AG1343-1EX30-7XE0)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIPLUS NET CP 343-1 Lean (6AG1343-1CX10-2XE0)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIDIS Prime\u00a0\u2013 versions prior to V4.0.400<\/li>\n\t<li>Siemens SIMATIC RTLS Gateway\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Rockwell Automation FactoryTalk Service Platform\u00a0\u2013 versions prior to v2.74<\/li>\n\t<li>Siemens Location Intelligence\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens Parasolid\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Polarion ALM\u00a0\u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM APE1808\u00a0\u2013 versions prior to 23.3.0<\/li>\n\t<li>Siemens SCALANCE SC-600 Family\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SCALANCE XCM-\/XRM-300\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens OpenPCS\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC BATCH V9.1\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC PCS 7 V9.1\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC Route Control V9.1\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC WinCC\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens Simcenter Femap\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V2.0 SP1<\/li>\n\t<li>Siemens Tecnomatix Plant Simulation\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens Unicam FX\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-097","alert_type":398,"serial_number":"AV24-097","subject":"ics","moderation_state":"published","external_url":null},{"nid":5000,"title":"Red Hat security advisory (AV24-098)","uuid":"be955817-56d6-471f-916c-0255d0d942fe","banner":null,"lang":"en","date_modified":"2024-02-19","date_modified_ts":"2024-02-19T20:18:38Z","date_created":"2024-02-19T20:08:08Z","summary":null,"body":["<article data-history-node-id=\"5000\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-098\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-098<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a019, 2024<\/p>\n\n<p>Between February\u00a012 and 18, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0851\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0851<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:0850\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:0850<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-098","alert_type":396,"serial_number":"AV24-098","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5001,"title":"Mozilla security advisory (AV24-099)","uuid":"9afd5a07-2c8e-44d0-86ed-44e80460533f","banner":null,"lang":"en","date_modified":"2024-02-20","date_modified_ts":"2024-02-20T14:26:17Z","date_created":"2024-02-20T14:19:47Z","summary":null,"body":["<article data-history-node-id=\"5001\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-099\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-099<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a020, 2024<\/p>\n\n<p>On February\u00a020, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 123<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-05\/\">Mozilla Security Advisory\u00a0- MFSA 2024-05<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-06\/\">Mozilla Security Advisory\u00a0- MFSA 2024-06<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-099","alert_type":396,"serial_number":"AV24-099","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5002,"title":"ConnectWise security advisory (AV24-100) \u2013 Update 1","uuid":"6fa7a060-fe4b-41ca-8391-5a5a13c7355a","banner":null,"lang":"en","date_modified":"2024-02-21","date_modified_ts":"2024-02-21T16:55:23Z","date_created":"2024-02-20T16:12:54Z","summary":null,"body":["<article data-history-node-id=\"5002\" about=\"\/en\/alerts-advisories\/connectwise-security-advisory-av24-100\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-100<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 19, 2024<\/p>\n\n<p><strong>Updated:<\/strong> February\u00a020, 2024<\/p>\n\n<p>On February\u00a019, 2024, ConnectWise published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>ConnectWise ScreenConnect\u00a0\u2013 version 23.9.7 and prior<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On February\u00a020, 2024, ConnectWise updated their advisory to indicate that these vulnerabilities have been exploited.<\/p>\n\n<p>The Cyber Centre recommends organizations review the indicators of compromise to determine if similar activity has been observed.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/connectwise-screenconnect-23.9.8\">ConnectWise Security Bulletin\u00a0- connectwise-screenconnect-23.9.8<\/a><\/li>\n\t<li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\">ConnectWise Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/connectwise-security-advisory-av24-100","alert_type":396,"serial_number":"AV24-100","subject":"other","moderation_state":"published","external_url":null},{"nid":5003,"title":"VMware security advisory (AV24-101)","uuid":"7e8504ad-f0c5-411a-96ce-5a7b2924a43e","banner":null,"lang":"en","date_modified":"2024-02-20","date_modified_ts":"2024-02-20T19:19:12Z","date_created":"2024-02-20T19:03:19Z","summary":null,"body":["<article data-history-node-id=\"5003\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-101\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-101<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a020, 2024<\/p>\n\n<p>On February\u00a020, 2024, VMware released a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Enhanced Authentication Plug-in (EAP)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0003.html\">VMware Security Advisory\u00a0- VMSA-2024-0003<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-101","alert_type":396,"serial_number":"AV24-101","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5004,"title":"Google Chrome security advisory (AV24-102)","uuid":"1d4dc80c-7eaf-4cfc-b082-30f6cfc07c38","banner":null,"lang":"en","date_modified":"2024-02-21","date_modified_ts":"2024-02-21T13:55:24Z","date_created":"2024-02-21T13:48:05Z","summary":null,"body":["<article data-history-node-id=\"5004\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-102\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-102<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 21, 2024<\/p>\n\n<p>On February 20, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 122.0.6261.57\/.58 (Windows) and 122.0.6261.57 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/02\/stable-channel-update-for-desktop_20.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-102","alert_type":396,"serial_number":"AV24-102","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5005,"title":"GitLab security advisory (AV24-103)","uuid":"08d24bf8-5a19-4ff0-b667-6b4eaa9a37b3","banner":null,"lang":"en","date_modified":"2024-02-21","date_modified_ts":"2024-02-21T19:34:04Z","date_created":"2024-02-21T19:28:25Z","summary":null,"body":["<article data-history-node-id=\"5005\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-103\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-103<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a021, 2024<\/p>\n\n<p>On February\u00a021, 2024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 16.9.1, 16.8.3 and 16.7.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 16.9.1, 16.8.3 and 16.7.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/02\/21\/security-release-gitlab-16-9-1-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-103","alert_type":396,"serial_number":"AV24-103","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5006,"title":"Atlassian security advisory (AV24-104)","uuid":"6beda2f6-3ad4-4450-bdae-3940fd498cb6","banner":null,"lang":"en","date_modified":"2024-02-21","date_modified_ts":"2024-02-21T21:07:03Z","date_created":"2024-02-21T20:55:45Z","summary":null,"body":["<article data-history-node-id=\"5006\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-104\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-104<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February\u00a021, 2024<\/p>\n\n<p>On February\u00a020, 2024, Atlassian published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Software Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Assets Discovery\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-february-20-2024-1354501606.html\">Atlassian February 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-104","alert_type":396,"serial_number":"AV24-104","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5007,"title":"[Control systems] B&R security advisory (AV24-105)","uuid":"39d957d6-2319-4c07-9220-3ea4932fce5f","banner":null,"lang":"en","date_modified":"2024-02-22","date_modified_ts":"2024-02-22T15:03:09Z","date_created":"2024-02-22T14:57:11Z","summary":null,"body":["<article data-history-node-id=\"5007\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-105\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-105<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 22, 2024<\/p>\n\n<p>On February\u00a022,\u00a02024, B&amp;R published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>B&amp;R Automation Studio\u00a0\u2013 versions prior to 4.6<\/li>\n\t<li>B&amp;R Technology Guarding\u00a0\u2013 versions prior to 1.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA23P019_Automation_Studio_Upgrade_Service_uses_insufficient_encryption.pdf-1b3b181c.pdf\">B&amp;R Advisory\u00a0\u2013 SA23P019 (PDF) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-105","alert_type":398,"serial_number":"AV24-105","subject":"other","moderation_state":"published","external_url":null},{"nid":5008,"title":"Vulnerabilities impacting ConnectWise ScreenConnect","uuid":"ec88bca4-3c84-4be4-a13f-e2982bb40ef2","banner":null,"lang":"en","date_modified":"2024-02-22","date_modified_ts":"2024-02-22T20:05:14Z","date_created":"2024-02-22T16:49:30Z","summary":null,"body":["<article data-history-node-id=\"5008\" about=\"\/en\/alerts-advisories\/vulnerabilities-impacting-connectwise-screenconnect\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL24-004<br \/><strong>Date:\u00a0<\/strong>February 22,\u00a02024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On February 19, 2024, the Cyber Centre became aware of vulnerabilities impacting all versions of ConnectWise ScreenConnect prior to 23.9.8. In response, the Cyber Centre released advisory AV24-100 along with an update on February 20, 2024, highlighting that the vulnerabilities are being exploited<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>ConnectWise reports that CVE-2024-1709 is an authentication bypass vulnerability and CVE-2024-1708 is a path traversal flaw. These vulnerabilities combined could allow for remote code execution (RCE)<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>While ConnectWise has indicated that CVE-2024-1709 may be exploited in the wild, open-source researchers have reported that exploitation impacting both CVE-2024-1708 and CVE-2024-1709 have been observed and in some cases resulted in the deployment of ransomware.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations patch any ScreenConnect systems immediately. ConnectWise recommends updating impacted products to version 23.9.8<sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. The vendor states cloud partners are remediated against both vulnerabilities reported on February 19.<\/p>\n\n<p>Organizations should also review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t<li>Patching operating systems and applications.<\/li>\n\t<li>Isolate web-facing applications.<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><h2>Partner Reporting<\/h2>\n\n<p><a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/advisories\/unauthenticated-remote-code-execution-in-connectwises-screenconnect\/\">NCSC-NZ\u00a0- Unauthenticated Remote Code Execution in ConnectWise's ScreenConnect<\/a><\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <em>Official Languages Act<\/em> is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"\/en\/alerts-advisories\/connectwise-security-advisory-av24-100\">CCCS AV24-100\u00a0\u2013 ConnectWise Security Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/connectwise-screenconnect-23.9.8\">ConnectWise\u00a0\u2013 ConnectWise ScreenConnect 23.9.8 Security Fix<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-impacting-connectwise-screenconnect","alert_type":397,"serial_number":"AL24-004","subject":"other","moderation_state":"published","external_url":null},{"nid":5012,"title":"[Control systems] CISA ICS security advisories (AV24-106) ","uuid":"8f9406b0-04cb-4f8a-ba99-d47b51c0d82b","banner":null,"lang":"en","date_modified":"2024-02-26","date_modified_ts":"2024-02-26T16:01:11Z","date_created":"2024-02-26T15:54:21Z","summary":null,"body":["<article data-history-node-id=\"5012\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-106\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-106\n  <br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 26, 2024\n<\/p>\n<p>Between February 19 and 25, 2024, CISA published ICS advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Commend WS203VICM\u00a0\u2013 versions 1.7 and prior<\/li>\n  <li>Ethercat Zeek Plugin\u00a0\u2013 versions d78dda6 and prior<\/li>\n  <li>Mitsubishi Electric Wire-cut EDM MV Series\u00a0- all versions<\/li>\n  <li>Mitsubishi Electric Wire-cut EDM MP Series\u00a0- all versions<\/li>\n  <li>Mitsubishi Electric Wire-cut EDM MX Series\u00a0- all versions<\/li>\n  <li>Mitsubishi Electric Sinker EDM SV-P Series\u00a0- all versions<\/li>\n  <li>Mitsubishi Electric Sinker EDM SG Series\u00a0- all versions<\/li>\n  <li>Delta Electronics CNCSoft-B\u00a0\u2013 versions prior to v1.0.0.4<\/li>\n  <li>Delta Electronics DOPSoft\u00a0\u2013 versions prior to v4.0.0.82<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-106","alert_type":398,"serial_number":"AV24-106","subject":"ics","moderation_state":"published","external_url":null},{"nid":5013,"title":"Ubuntu security advisory (AV24-107)","uuid":"6fce5da8-8d74-421f-861b-4bfa41a6cbf7","banner":null,"lang":"en","date_modified":"2024-02-26","date_modified_ts":"2024-02-26T16:10:55Z","date_created":"2024-02-26T16:06:12Z","summary":null,"body":["<article data-history-node-id=\"5013\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-107\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-107<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date:<\/strong> February 26, 2024<\/p>\n\n<p>Between February 19 and 25, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-107","alert_type":396,"serial_number":"AV24-107","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5014,"title":"Dell security advisory (AV24-108)","uuid":"68ca39ad-9d99-4e25-b539-c35fae9fee39","banner":null,"lang":"en","date_modified":"2024-02-26","date_modified_ts":"2024-02-26T16:28:16Z","date_created":"2024-02-26T16:16:08Z","summary":null,"body":["<article data-history-node-id=\"5014\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-108\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-108<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 26, 2024<\/p>\n\n<p>Between February 19 and 25, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Avamar 19.10 Virtual Edition for VMware ESXi and vSphere\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar NDMP Accelerator\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar Server Hardware Appliance Gen4T\/ Gen5A\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar Virtual Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar VMware Image Proxy\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Networker Virtual Edition (NVE)\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Power Protect DP Series Appliance\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Integrated Data Protection Appliance (IDPA\u00a0\u2013 multiple versions<\/li>\n\t<li>Integrated Data Protection Appliance (PowerProtect DP Series)\u00a0\u2013 version 2.7.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-108","alert_type":396,"serial_number":"AV24-108","subject":"dell","moderation_state":"published","external_url":null},{"nid":5015,"title":"IBM security advisory (AV24-109)","uuid":"d12e91a1-0d7b-45ea-ab91-54010b9eda8b","banner":null,"lang":"en","date_modified":"2024-02-26","date_modified_ts":"2024-02-26T16:45:56Z","date_created":"2024-02-26T16:39:37Z","summary":null,"body":["<article data-history-node-id=\"5015\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-109\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-109<br \/><!-- DATES Pick one update the day xx, delete the rest --><\/p>\n\n<p><strong>Date: <\/strong>February 26, 2024<\/p>\n\n<p>Between February 19 and 25, 2023, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>AIX\u00a0\u2013 version 7.3<\/li>\n\t<li>IBM Cloud Pak for Data Scheduling\u00a0\u2013 version 4.6.4 to 4.7.4<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 versions 11.1.7, 11.2.4 and 12.0.0<\/li>\n\t<li>IBM i\u00a0\u2013 versions 7.2, 7.3, 7.4 and 7.5<\/li>\n\t<li>IBM VIOS\u00a0\u2013 Version 4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-109","alert_type":396,"serial_number":"AV24-109","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5016,"title":"Google Chrome security advisory (AV24-110)","uuid":"22e7deaf-d3a9-44b8-b45d-442c2337572e","banner":null,"lang":"en","date_modified":"2024-02-28","date_modified_ts":"2024-02-28T17:33:28Z","date_created":"2024-02-28T17:28:30Z","summary":null,"body":["<article data-history-node-id=\"5016\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-110\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-110<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 28, 2024<\/p>\n\n<p>On February 27, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 122.0.6261.94\/.95 (Windows) and 122.0.6261.94 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/02\/stable-channel-update-for-desktop_27.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-110","alert_type":396,"serial_number":"AV24-110","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5017,"title":"Cisco security advisory (AV24-111)","uuid":"b0e410e0-a856-43cd-8441-fe23f21a38dd","banner":null,"lang":"en","date_modified":"2024-02-28","date_modified_ts":"2024-02-28T18:59:22Z","date_created":"2024-02-28T18:11:11Z","summary":null,"body":["<article data-history-node-id=\"5017\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-111\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-111<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 28, 2024<\/p>\n\n<p>On February 28, 2024, Cisco published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Cisco NX-OS\u00a0- multiple platforms and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-ebgp-dos-L3QCwVJ\">Cisco Advisory\u00a0\u2013 cisco-sa-nxos-ebgp-dos-L3QCwVJ<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ipv6-mpls-dos-R9ycXkwM\">Cisco Advisory\u00a0\u2013 cisco-sa-ipv6-mpls-dos-R9ycXkwM<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-111","alert_type":396,"serial_number":"AV24-111","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5018,"title":"HPE security advisory (AV24-112)","uuid":"34a59973-853c-4d8d-8c50-67680d7d9b01","banner":null,"lang":"en","date_modified":"2024-02-29","date_modified_ts":"2024-02-29T14:28:29Z","date_created":"2024-02-29T14:22:25Z","summary":null,"body":["<article data-history-node-id=\"5018\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-112\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-112<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 29, 2024<\/p>\n\n<p>On February 27,\u00a02024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Aruba ClearPass Policy Manager 6.12.x\u00a0\u2013 version 6.12.0<\/li>\n\t<li>Aruba ClearPass Policy Manager 6.11.x\u00a0\u2013 version 6.11.6 and prior<\/li>\n\t<li>Aruba ClearPass Policy Manager 6.10.x\u00a0\u2013 version 6.10.8 Hotfix Q4 2023 and prior<\/li>\n\t<li>Aruba ClearPass Policy Manager 6.9.x\u00a0\u2013 version 6.9.13 Hotfix Q4 2023 and prior<\/li>\n<\/ul><p>Exploitation of some of these vulnerabilities could result in remote code execution.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.arubanetworks.com\/assets\/alert\/ARUBA-PSA-2024-001.txt\">HPE Aruba Security Bulletin\u00a0- ARUBA-PSA-2024-001<\/a><\/li>\n\t<li><a href=\"https:\/\/www.arubanetworks.com\/support-services\/security-bulletins\/\">HPE Aruba Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-112","alert_type":396,"serial_number":"AV24-112","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5020,"title":"Juniper security advisory (AV24-113)","uuid":"aff58ee8-4d92-4d6e-a741-8c42defaca3d","banner":null,"lang":"en","date_modified":"2024-02-29","date_modified_ts":"2024-02-29T19:28:42Z","date_created":"2024-02-29T19:20:36Z","summary":null,"body":["<article data-history-node-id=\"5020\" about=\"\/en\/alerts-advisories\/juniper-security-advisory-av24-113\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-113<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>February 29, 2024<\/p>\n\n<p>On February\u00a029,\u00a02024, Juniper published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Juniper Secure Analytics\u00a0\u2013 versions prior to 7.5.0 UP7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP7-IF05?language=en_US\">Juniper Security Bulletin\u00a0\u2013 JSA77742<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy&amp;f:ctype=[Security%20Advisories\">Juniper Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-advisory-av24-113","alert_type":396,"serial_number":"AV24-113","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5021,"title":"Mitel security advisory (AV24-114)","uuid":"dd9febd9-dbfd-4276-ba6d-cfe5829f3c7b","banner":null,"lang":"en","date_modified":"2024-03-04","date_modified_ts":"2024-03-04T15:22:52Z","date_created":"2024-03-04T15:02:11Z","summary":null,"body":["<article data-history-node-id=\"5021\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-114\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-114<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a04, 2024<\/p>\n\n<p>On February\u00a029, 2024, Mitel published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Mitel MiContact Center Business\u00a0\u2013 version 10.0.0.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/-\/media\/mitel\/file\/pdf\/support\/security-advisories\/security-bulletin_24-0001-001-v1.pdf\">Mitel Security Bulletin\u00a0- 24-0001-001 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/-\/media\/mitel\/file\/pdf\/support\/security-advisories\/security-bulletin_24-0002-001-v1.pdf\">Mitel Security Bulletin\u00a0- 24-0002-001 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-114","alert_type":396,"serial_number":"AV24-114","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5022,"title":"[Control systems] CISA ICS security advisories (AV24-115)","uuid":"85a2a73a-c469-48ad-89c9-5f7b2d35dcd0","banner":null,"lang":"en","date_modified":"2024-03-04","date_modified_ts":"2024-03-04T15:37:57Z","date_created":"2024-03-04T15:02:11Z","summary":null,"body":["<article data-history-node-id=\"5022\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-115\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-115<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a04, 2024<\/p>\n\n<p>Between February\u00a026 and March\u00a03, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitsubishi Electric MELSEC iQ-F\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Santesoft Sante DICOM Viewer Pro\u00a0\u2013 version 14.0.3 and prior<\/li>\n\t<li>Delta Electronics CNCSoft-B\u00a0\u2013 versions 1.0.0.4 and prior<\/li>\n\t<li>MicroDicom DICOM Viewer\u00a0\u2013 versions 2023.3 (build 9342) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-115","alert_type":398,"serial_number":"AV24-115","subject":"ics","moderation_state":"published","external_url":null},{"nid":5023,"title":"Ubuntu security advisory (AV24-116)","uuid":"6a0e69c5-9217-4a70-8aa1-3f1379b708b9","banner":null,"lang":"en","date_modified":"2024-03-04","date_modified_ts":"2024-03-04T15:43:19Z","date_created":"2024-03-04T15:02:12Z","summary":null,"body":["<article data-history-node-id=\"5023\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-116\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-116<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a04, 2024<\/p>\n\n<p>Between February\u00a026 and March\u00a03, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-116","alert_type":396,"serial_number":"AV24-116","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5024,"title":"Dell security advisory (AV24-117)","uuid":"557c631a-8a2c-47dd-94f5-4eb8d496c239","banner":null,"lang":"en","date_modified":"2024-03-04","date_modified_ts":"2024-03-04T18:59:18Z","date_created":"2024-03-04T18:29:46Z","summary":null,"body":["<article data-history-node-id=\"5024\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-117\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-117<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a04, 2024<\/p>\n\n<p>Between February\u00a026 and March\u00a03, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Protection Advisor\u00a0\u2013 version 19.9<\/li>\n\t<li>Dell Secure Connect Gateway\u00a0\u2013 version 5.20.00.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-117","alert_type":396,"serial_number":"AV24-117","subject":"dell","moderation_state":"published","external_url":null},{"nid":5025,"title":"Red Hat security advisory (AV24-118)","uuid":"d611653d-298a-4e08-8722-08008a51a36d","banner":null,"lang":"en","date_modified":"2024-03-04","date_modified_ts":"2024-03-04T19:19:47Z","date_created":"2024-03-04T18:29:47Z","summary":null,"body":["<article data-history-node-id=\"5025\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-118\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-118<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a04, 2024<\/p>\n\n<p>Between February\u00a026 and March\u00a03, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-118","alert_type":396,"serial_number":"AV24-118","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5026,"title":"Android security advisory \u2013 March 2024 Monthly Rollup (AV24-119)","uuid":"4e10ac46-bb18-4845-a53d-612d2e7e4cb3","banner":null,"lang":"en","date_modified":"2024-03-04","date_modified_ts":"2024-03-04T20:09:44Z","date_created":"2024-03-04T20:07:18Z","summary":null,"body":["<article data-history-node-id=\"5026\" about=\"\/en\/alerts-advisories\/android-security-advisory-march-2024-monthly-rollup-av24-119\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-119<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a04, 2024<\/p>\n\n<p>On March\u00a04, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-03-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-march-2024-monthly-rollup-av24-119","alert_type":396,"serial_number":"AV24-119","subject":"android","moderation_state":"published","external_url":null},{"nid":5027,"title":"SolarWinds security advisory (AV24-120)","uuid":"df848153-4500-47d9-9471-ecd7b87ec261","banner":null,"lang":"en","date_modified":"2024-03-05","date_modified_ts":"2024-03-05T14:14:38Z","date_created":"2024-03-05T14:13:35Z","summary":null,"body":["<article data-history-node-id=\"5027\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-120\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-120<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a05,\u00a02024<\/p>\n\n<p>On March\u00a01,\u00a02024, SolarWinds published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SolarWinds Security Event Manager\u00a0\u2013 versions prior to 2023.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.solarwinds.com\/en\/success_center\/sem\/content\/release_notes\/sem_2023-4-1_release_notes.htm\">SolarWinds Security Advisory\u00a0\u2013 sem_2023-4-1_release_notes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-120","alert_type":396,"serial_number":"AV24-120","subject":"other","moderation_state":"published","external_url":null},{"nid":5028,"title":"JetBrains security advisory (AV24-121)","uuid":"09e9bc16-abd2-448b-8760-52a33a07ec41","banner":null,"lang":"en","date_modified":"2024-03-05","date_modified_ts":"2024-03-05T19:31:48Z","date_created":"2024-03-05T19:26:21Z","summary":null,"body":["<article data-history-node-id=\"5028\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av24-121\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-121<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 5, 2024<\/p>\n\n<p>On March\u00a03,\u00a02024, JetBrains published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>JetBrains TeamCity On-Premises\u00a0\u2013 versions prior to 2023.11.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.jetbrains.com\/teamcity\/2024\/03\/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now\/\">JetBrains Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains Fixed Security Issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av24-121","alert_type":396,"serial_number":"AV24-121","subject":"other","moderation_state":"published","external_url":null},{"nid":5029,"title":"VMware security advisory (AV24-122)","uuid":"5b650335-654c-4182-a0c8-0de215b6e6f7","banner":null,"lang":"en","date_modified":"2024-03-05","date_modified_ts":"2024-03-05T19:47:21Z","date_created":"2024-03-05T19:42:18Z","summary":null,"body":["<article data-history-node-id=\"5029\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-122\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-122<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 5, 2024<\/p>\n\n<p>On March\u00a05,\u00a02024, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation\u00a0\u2013 versions 4.x and 5.x<\/li>\n\t<li>VMware ESXi\u00a0\u2013 versions 7.0 and 8.0<\/li>\n\t<li>VMware Fusion for MacOS\u00a0\u2013 versions 13.x prior to 13.5.1<\/li>\n\t<li>VMware Workstation\u00a0\u2013 versions 17.x prior to 17.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0006.html\">VMware Security Advisory\u00a0- VMSA-2024-0006<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vmware.com\/security\/advisories.html\">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-122","alert_type":396,"serial_number":"AV24-122","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5030,"title":"Google Chrome security advisory (AV24-123)","uuid":"b7a5e67b-fa79-40f6-8e91-ad4d72c6eb89","banner":null,"lang":"en","date_modified":"2024-03-06","date_modified_ts":"2024-03-06T15:03:41Z","date_created":"2024-03-06T14:34:26Z","summary":null,"body":["<article data-history-node-id=\"5030\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-123\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-123<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a06, 2024<\/p>\n\n<p>On March\u00a05, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 122.0.6261.111\/.112 (Windows) and 122.0.6261.111 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/03\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-123","alert_type":396,"serial_number":"AV24-123","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5032,"title":"Cisco security advisory (AV24-124)","uuid":"6c394eb1-25e3-435e-8059-20d33c88fc88","banner":null,"lang":"en","date_modified":"2024-03-06","date_modified_ts":"2024-03-06T19:35:09Z","date_created":"2024-03-06T19:29:07Z","summary":null,"body":["<article data-history-node-id=\"5032\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-124\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-124<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a06, 2024<\/p>\n\n<p>On March\u00a06, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Secure Client\u00a0\u2013 versions 4.10.04065 to versions prior to 4.10.08025<\/li>\n\t<li>Cisco Secure Client\u00a0\u2013 version 5.0<\/li>\n\t<li>Cisco Secure Client\u00a0\u2013 versions 5.1 prior to 5.1.2.42<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-secure-client-crlf-W43V4G7\">Cisco Advisory\u00a0\u2013 cisco-sa-secure-client-crlf-W43V4G7<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-124","alert_type":396,"serial_number":"AV24-124","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5033,"title":"Drupal security advisory (AV24-125)","uuid":"00d32d7a-ede0-4af5-93a6-5854c1e0955a","banner":null,"lang":"en","date_modified":"2024-03-06","date_modified_ts":"2024-03-06T19:39:20Z","date_created":"2024-03-06T19:29:08Z","summary":null,"body":["<article data-history-node-id=\"5033\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-125\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-125<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a06, 2024<\/p>\n\n<p>On March\u00a06, 2024, Drupal published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Registration role module\u00a0\u2013 versions 2.x prior to 2.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-015\">Drupal Security Advisory\u00a0- SA-CONTRIB-2024-015<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-125","alert_type":396,"serial_number":"AV24-125","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5034,"title":"Apple security advisory (AV24-126)","uuid":"9c3b21f9-5a85-48ec-b06f-a0d2005d49b5","banner":null,"lang":"en","date_modified":"2024-03-06","date_modified_ts":"2024-03-06T20:51:06Z","date_created":"2024-03-06T20:45:52Z","summary":null,"body":["<article data-history-node-id=\"5034\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-126\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-126<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a06, 2024<\/p>\n\n<p>On March\u00a05, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 17.4<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 16.7.6<\/li>\n<\/ul><p>Apple has received reports that CVE-2024-23225 and CVE-2024-23296 have been exploited. Exploitation of these vulnerabilities could lead to a bypass of kernel memory protections.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT214081\">About the security content of iOS 17.4 and iPadOS 17.4<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-ca\/HT214082\">About the security content of iOS 16.7.6 and iPadOS 16.7.6<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-126","alert_type":396,"serial_number":"AV24-126","subject":"apple","moderation_state":"published","external_url":null},{"nid":5035,"title":"GitLab security advisory (AV24-127)","uuid":"40c0da90-cd0d-4134-b7f4-2085d8090645","banner":null,"lang":"en","date_modified":"2024-03-06","date_modified_ts":"2024-03-06T20:56:24Z","date_created":"2024-03-06T20:45:53Z","summary":null,"body":["<article data-history-node-id=\"5035\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-127\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-127<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a06, 2024<\/p>\n\n<p>On March\u00a06, 2024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 16.9.2, 16.8.4 and 16.7.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 16.9.2, 16.8.4 and 16.7.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/03\/06\/security-release-gitlab-16-9-2-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-127","alert_type":396,"serial_number":"AV24-127","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5036,"title":"Apple security advisory (AV24-128)","uuid":"56c5c231-c97c-4152-9884-a9fead1496d6","banner":null,"lang":"en","date_modified":"2024-03-07","date_modified_ts":"2024-03-07T20:51:29Z","date_created":"2024-03-07T20:46:40Z","summary":null,"body":["<article data-history-node-id=\"5036\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-128\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-128<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a07, 2024<\/p>\n\n<p>On March\u00a07, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Monterey\u00a0\u2013 versions prior to 12.7.4<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.4<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.6.5<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 17.4<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 17.4<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 1.1<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 10.4<\/li>\n<\/ul><p>Apple has received reports that CVE-2024-23225 and CVE-2024-23296 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-128","alert_type":396,"serial_number":"AV24-128","subject":"apple","moderation_state":"published","external_url":null},{"nid":5037,"title":"Microsoft Edge security advisory (AV24-129)","uuid":"6fb2deda-7be5-4346-a73c-faa893b620ab","banner":null,"lang":"en","date_modified":"2024-03-08","date_modified_ts":"2024-03-08T14:49:02Z","date_created":"2024-03-08T14:46:08Z","summary":null,"body":["<article data-history-node-id=\"5037\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-129\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-129<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a08, 2024<\/p>\n\n<p>On March\u00a07, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 122.0.2365.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-7-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-129","alert_type":396,"serial_number":"AV24-129","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5038,"title":"[Control systems] CISA ICS security advisories (AV24-130) ","uuid":"fbad4fc0-da0c-4323-964a-f6e7b622adb0","banner":null,"lang":"en","date_modified":"2024-03-11","date_modified_ts":"2024-03-11T14:00:03Z","date_created":"2024-03-11T14:03:27Z","summary":null,"body":["<article data-history-node-id=\"5038\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-130\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-130<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2024<\/p>\n\n<p>Between March 4\u00a0and\u00a010, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Chirp Systems Chirp Access\u00a0\u2013 all versions<\/li>\n\t<li>Nice Linear eMerge E3-Series\u00a0\u2013 versions 1.00-06 and prior<\/li>\n\t<li>Santesoft Sante FFT Imaging\u00a0\u2013 versions 1.4.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-130","alert_type":398,"serial_number":"AV24-130","subject":"ics","moderation_state":"published","external_url":null},{"nid":5039,"title":"Dell security advisory (AV24-131)","uuid":"d013e057-7c11-44b4-bb5e-a4c37d0c16ac","banner":null,"lang":"en","date_modified":"2024-03-11","date_modified_ts":"2024-03-11T14:00:05Z","date_created":"2024-03-11T14:15:24Z","summary":null,"body":["<article data-history-node-id=\"5039\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-131\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-131<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2024<\/p>\n\n<p>Between March 4 and 10, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Isilon A200\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>Isilon A2000\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>Isilon F800\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>Isilon H400\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>Isilon H500\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>Isilon H5600\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>Isilon H600\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale Archive A300\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale Archive A3000\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale B100\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale F200\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale F600\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale F900\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale Hybrid H700\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale Hybrid H7000\u00a0\u2013 versions prior to 12.1<\/li>\n\t<li>PowerScale P100\u00a0\u2013 versions prior to 12.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-131","alert_type":396,"serial_number":"AV24-131","subject":"dell","moderation_state":"published","external_url":null},{"nid":5040,"title":"Ubuntu security advisory (AV24-132)","uuid":"ae4982a1-8c52-40a9-b592-d74071e7402e","banner":null,"lang":"en","date_modified":"2024-03-11","date_modified_ts":"2024-03-11T14:10:01Z","date_created":"2024-03-11T14:49:28Z","summary":null,"body":["<article data-history-node-id=\"5040\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-132\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-132<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2024<\/p>\n\n<p>Between March 4 and 10, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-132","alert_type":396,"serial_number":"AV24-132","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5042,"title":"IBM security advisory (AV24-133)","uuid":"764421bb-b25c-40fe-ba95-942f901477e8","banner":null,"lang":"en","date_modified":"2024-03-11","date_modified_ts":"2024-03-11T14:20:00Z","date_created":"2024-03-11T15:12:08Z","summary":null,"body":["<article data-history-node-id=\"5042\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-133-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-133<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2024<\/p>\n\n<p>Between March 4 and 10, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM CP4NA\u00a0\u2013 version 2.6.5<\/li>\n\t<li>IBM DS8900F R9.2\u00a0\u2013 versions 89.21.31.0 and 89.21.19.0<\/li>\n\t<li>IBM DS8900F R9.3\u00a0\u2013 versions 89.30.68.0, 89.32.40.0 and 89.33.48.0<\/li>\n\t<li>IBM Transformation Extender Advanced\u00a0\u2013 versions 9.0 and 10.0<\/li>\n\t<li>IBM WebSphere Service Registry and Repository\u00a0\u2013 version 8.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7129813\">IBM Security Bulletin\u00a0- 7129813<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7130084\">IBM Security Bulletin\u00a0\u2013 7130084<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7129806\">IBM Security Bulletin\u00a0- 7129806<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7129833\">IBM Security Bulletin\u00a0- 7129833<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-133-0","alert_type":396,"serial_number":"AV24-133","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5043,"title":"Red Hat security advisory (AV24-134)","uuid":"04963916-2dff-413e-9c7e-9d2bdb9a5a1a","banner":null,"lang":"en","date_modified":"2024-03-11","date_modified_ts":"2024-03-11T15:32:21Z","date_created":"2024-03-11T15:25:05Z","summary":null,"body":["<article data-history-node-id=\"5043\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-134\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-134<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2024<\/p>\n\n<p>Between March 4 and 10, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host 4 for RHEL 8 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:1112\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:1112<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:1188\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:1188<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-134","alert_type":396,"serial_number":"AV24-134","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5046,"title":"[Control systems] Schneider Electric security advisory (AV24-135)","uuid":"632270db-a4cb-400c-b77e-2eb439d1cb17","banner":null,"lang":"en","date_modified":"2024-03-12","date_modified_ts":"2024-03-12T13:08:23Z","date_created":"2024-03-12T13:01:35Z","summary":null,"body":["<article data-history-node-id=\"5046\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-135\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-135<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 12, 2024<\/p>\n\n<p>On March 12, 2024, Schneider Electric published security advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Easergy T200\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>EcoStruxure Power Design Ecodial\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-072-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-072-01.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-072-01 (PDF) <\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-072-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-072-02.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-072-02 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-135","alert_type":398,"serial_number":"AV24-135","subject":"other","moderation_state":"published","external_url":null},{"nid":5047,"title":"SAP security advisory \u2013 March 2024 monthly rollup (AV24-136)","uuid":"4f4c4144-11a9-42ca-94f2-86f8106bd6ce","banner":null,"lang":"en","date_modified":"2024-03-12","date_modified_ts":"2024-03-12T13:51:09Z","date_created":"2024-03-12T13:45:31Z","summary":null,"body":["<article data-history-node-id=\"5047\" about=\"\/en\/alerts-advisories\/sap-security-advisory-march-2024-monthly-rollup-av24-136\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-136<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 12, 2024<\/p>\n\n<p>On March 12, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Build Apps\u00a0\u2013 versions prior to 4.9.145<\/li>\n\t<li>SAP NetWeaver AS Java (Administrator Log Viewer plug-in)\u00a0\u2013 version 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/march-2024.html\">SAP Security Patch Day\u00a0- March\u00a02024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-march-2024-monthly-rollup-av24-136","alert_type":396,"serial_number":"AV24-136","subject":"sap","moderation_state":"published","external_url":null},{"nid":5048,"title":"[Control systems] Siemens security advisory (AV24-137)","uuid":"2ae7c2e2-d761-4e0e-9d96-9c2b43a4e3c7","banner":null,"lang":"en","date_modified":"2024-03-12","date_modified_ts":"2024-03-12T14:19:09Z","date_created":"2024-03-12T14:11:29Z","summary":null,"body":["<article data-history-node-id=\"5048\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-137\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-137<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 12, 2024<\/p>\n\n<p>On March 12, 2024, Siemens published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cerberus PRO\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>RUGGEDCOM APE1808 with Fortinet NGFW\u00a0\u2013 all versions<\/li>\n\t<li>SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SENTRON 3KC ATC6 Expansion Module Ethernet\u00a0\u2013 all versions<\/li>\n\t<li>SENTRON 7KM PAC3x20\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SIMATIC RF160B\u00a0\u2013 versions prior to 2.2<\/li>\n\t<li>SINEMA Remote Connect Client\u00a0\u2013 versions prior to 3.1 SP1<\/li>\n\t<li>SINEMA Remote Connect Server\u00a0\u2013 versions prior to 3.2<\/li>\n\t<li>SIPROTEC 5\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siveillance Control\u00a0\u2013 versions 2.8 to versions prior to 3.1.1<\/li>\n\t<li>Sinteso\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Solid Edge\u00a0\u2013 versions prior to 223.0.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-137","alert_type":398,"serial_number":"AV24-137","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5049,"title":"Fortinet security advisory (AV24-138)","uuid":"9b9b5af0-8a38-4939-9453-c69de6e9dafe","banner":null,"lang":"en","date_modified":"2024-03-12","date_modified_ts":"2024-03-12T19:14:52Z","date_created":"2024-03-12T18:30:28Z","summary":null,"body":["<article data-history-node-id=\"5049\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-138\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-138<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a012, 2024<\/p>\n\n<p>On March\u00a012, 2024, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>FortiClientEMS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.2<\/li>\n\t<li>FortiClientEMS 7.0\u00a0\u2013 versions 7.0.1 to 7.0.10<\/li>\n\t<li>FortiClientEMS 6.4\u00a0\u2013 all versions<\/li>\n\t<li>FortiClientEMS 6.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiClientEMS 6.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiManager\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.1<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.5<\/li>\n\t<li>FortiOS 7.0\u00a0\u2013 versions 7.0.0 to 7.0.12<\/li>\n\t<li>FortiOS 6.4\u00a0\u2013 versions 6.4.0 to 6.4.14<\/li>\n\t<li>FortiOS 6.2\u00a0\u2013 versions 6.2.0 to 6.2.15<\/li>\n\t<li>FortiPAM 1.1\u00a0\u2013 all versions<\/li>\n\t<li>FortiPAM 1.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiProxy 7.4\u00a0\u2013 version 7.4.0<\/li>\n\t<li>FortiProxy 7.2\u00a0\u2013 versions 7.2.0 to 7.2.6<\/li>\n\t<li>FortiProxy 7.0\u00a0\u2013 versions 7.0.0 to 7.0.12<\/li>\n\t<li>FortiProxy 2.0\u00a0\u2013 versions 2.0.0 to 2.0.13<\/li>\n\t<li>FortiSwitchManager 7.2\u00a0\u2013 versions 7.2.0 to 7.2.2<\/li>\n\t<li>FortiSwitchManager 7.0\u00a0\u2013 versions 7.0.0 to 7.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-390\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-390<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-007\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-007<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-328\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-328<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-103\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-103<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-138","alert_type":396,"serial_number":"AV24-138","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":5050,"title":"Adobe security advisory (AV24-139)","uuid":"32b742c2-9cb0-4f02-806b-01da4810c1fb","banner":null,"lang":"en","date_modified":"2024-03-12","date_modified_ts":"2024-03-12T19:25:00Z","date_created":"2024-03-12T19:05:24Z","summary":null,"body":["<article data-history-node-id=\"5050\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-139\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-139<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a012, 2024<\/p>\n\n<p>On March\u00a012, 2024, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe Animate 2023\u00a0\u2013 version 23.0.3 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0\u2013 version 24.0 and prior<\/li>\n\t<li>Adobe Bridge 13.0\u00a0\u2013 version 13.0.5 and prior<\/li>\n\t<li>Adobe Bridge 14.0\u00a0\u2013 version 14.0.1 and prior<\/li>\n\t<li>Adobe ColdFusion 2021\u00a0\u2013 version Update 12 and prior<\/li>\n\t<li>Adobe ColdFusion 2023\u00a0\u2013 version Update 6 and prior<\/li>\n\t<li>Adobe Lightroom for MacOS\u00a0\u2013 version 7.1.2 and prior<\/li>\n\t<li>Adobe Premiere Pro 23\u00a0\u2013 version 23.6.2 and prior<\/li>\n\t<li>Adobe Premiere Pro 24\u00a0\u2013 version 24.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-139","alert_type":396,"serial_number":"AV24-139","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5051,"title":"Microsoft security advisory \u2013 March 2024 monthly rollup (AV24-140)","uuid":"4c4e628d-345e-4784-96dd-bd603c3ad6a3","banner":null,"lang":"en","date_modified":"2024-03-12","date_modified_ts":"2024-03-12T20:02:51Z","date_created":"2024-03-12T19:56:50Z","summary":null,"body":["<article data-history-node-id=\"5051\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-march-2024-monthly-rollup-av24-140\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-140<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a012, 2024<\/p>\n\n<p>On March\u00a012, 2024, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Azure Kubernetes Service Confidential Containers\u00a0\u2013 versions prior to 0.3.3<\/li>\n\t<li>Microsoft Exchange Server 2016 CU 23\u00a0\u2013 versions prior to SU12<\/li>\n\t<li>Microsoft Exchange Server 2019 CU 13\u00a0\u2013 versions prior to SU5<\/li>\n\t<li>Microsoft Exchange Server 2019 CU 14\u00a0\u2013 versions prior to SU1<\/li>\n\t<li>Microsoft SQL Server backend for Django\u00a0\u2013 versions prior to 1.4.1<\/li>\n\t<li>Microsoft System Center Operations Manager (SCOM) 2019\u00a0\u2013 versions prior to 10.19.1253.0<\/li>\n\t<li>Microsoft System Center Operations Manager (SCOM) 2022\u00a0\u2013 versions prior to 10.22.1070.0<\/li>\n\t<li>Open Management Infrastructure\u00a0\u2013 versions prior to 1.8.1-0<\/li>\n\t<li>Skype for Consumer\u00a0\u2013 versions prior to 8.113<\/li>\n\t<li>Visual Studio Code\u00a0\u2013 versions prior to 1.87.2<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Mar\">March 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-march-2024-monthly-rollup-av24-140","alert_type":396,"serial_number":"AV24-140","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5052,"title":"Google Chrome security advisory (AV24-141)","uuid":"91b7cde9-acae-4b33-a516-8957f71b06a4","banner":null,"lang":"en","date_modified":"2024-03-13","date_modified_ts":"2024-03-13T14:21:42Z","date_created":"2024-03-13T13:58:04Z","summary":null,"body":["<article data-history-node-id=\"5052\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-141\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-141<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a013, 2024<\/p>\n\n<p>On March\u00a012, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 122.0.6261.128\/.129 (Windows and Mac) and 122.0.6261.128 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/03\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-141","alert_type":396,"serial_number":"AV24-141","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5053,"title":"Mitel security advisory (AV24-142)","uuid":"f57f9979-d1b2-418c-a13e-c2804c7cec3b","banner":null,"lang":"en","date_modified":"2024-03-13","date_modified_ts":"2024-03-13T15:16:31Z","date_created":"2024-03-13T15:04:20Z","summary":null,"body":["<article data-history-node-id=\"5053\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-142\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-142<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a013, 2024<\/p>\n\n<p>On March\u00a013, 2024, Mitel published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Mitel InAttend\u00a0\u2013 versions 2.6 SP4 to 2.7<\/li>\n\t<li>Mitel CMG\u00a0\u2013 versions 8.5 SP4 to 8.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0003\">Mitel Security Advisory\u00a0- 24-0003<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-142","alert_type":396,"serial_number":"AV24-142","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5055,"title":"Cisco security advisory (AV24-143)","uuid":"798b7ad3-52c7-4fa9-86ed-3a6fed297824","banner":null,"lang":"en","date_modified":"2024-03-13","date_modified_ts":"2024-03-13T19:57:26Z","date_created":"2024-03-13T19:56:22Z","summary":null,"body":["<article data-history-node-id=\"5055\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-143\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-143<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a013, 2024<\/p>\n\n<p>On March\u00a013, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco IOS XR\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxr-ssh-privesc-eWDMKew3\">Cisco Advisory\u00a0\u2013 cisco-sa-iosxr-ssh-privesc-eWDMKew3<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-143","alert_type":396,"serial_number":"AV24-143","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5057,"title":"HPE security advisory (AV24-144)","uuid":"7492acda-ac4b-4de3-8526-4fc95e072241","banner":null,"lang":"en","date_modified":"2024-03-15","date_modified_ts":"2024-03-15T13:44:14Z","date_created":"2024-03-15T13:26:15Z","summary":null,"body":["<article data-history-node-id=\"5057\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-144\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-144<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a015, 2024<\/p>\n\n<p>On March\u00a015, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console (UOC)\u00a0\u2013 versions prior to 3.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04618en_us\">HPE Security Bulletin\u00a0- hpesbgn04618en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-144","alert_type":396,"serial_number":"AV24-144","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5058,"title":"Microsoft Edge security advisory (AV24-145)","uuid":"f50db514-28b2-46d0-ad58-94ca36c94dd3","banner":null,"lang":"en","date_modified":"2024-03-15","date_modified_ts":"2024-03-15T13:54:13Z","date_created":"2024-03-15T13:26:15Z","summary":null,"body":["<article data-history-node-id=\"5058\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-145\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-145<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a015, 2024<\/p>\n\n<p>On March\u00a014, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 122.0.2365.92<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-14-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-145","alert_type":396,"serial_number":"AV24-145","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5060,"title":"Dell security advisory (AV24-146)","uuid":"7b7e5f12-9233-413e-83a5-c51e4d0c71b7","banner":null,"lang":"en","date_modified":"2024-03-18","date_modified_ts":"2024-03-18T15:43:32Z","date_created":"2024-03-18T15:23:22Z","summary":null,"body":["<article data-history-node-id=\"5060\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-146\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-146<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a018, 2024<\/p>\n\n<p>Between March\u00a011 and 17, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance\u00a0\u2013 8.0.x versions prior to 8.0.210<\/li>\n\t<li>NetWorker vProxy\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000223129\/dsa-2024-050-security-update-for-dell-vxrail-multiple-third-party-component-vulnerabilities-8-0-210\">Dell Security Update\u00a0\u2013 Dell EMC VxRail Appliance<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000222965\/dsa-2024-091-security-update-for-dell-networker-vproxy-multiple-component-vulnerabilities\">Dell Security Update\u00a0\u2013 NetWorker vProxy<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-146","alert_type":396,"serial_number":"AV24-146","subject":"dell","moderation_state":"published","external_url":null},{"nid":5061,"title":"Ubuntu security advisory (AV24-147)","uuid":"ba01cff8-594c-48d7-b95b-ea701fdde492","banner":null,"lang":"en","date_modified":"2024-03-18","date_modified_ts":"2024-03-18T15:44:20Z","date_created":"2024-03-18T15:23:22Z","summary":null,"body":["<article data-history-node-id=\"5061\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-147\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-147<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a018, 2024<\/p>\n\n<p>Between March\u00a011 and 17, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-147","alert_type":396,"serial_number":"AV24-147","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5062,"title":"IBM security advisory (AV24-148)","uuid":"d8234107-cc98-4484-85a0-2e1d24004ec6","banner":null,"lang":"en","date_modified":"2024-03-18","date_modified_ts":"2024-03-18T15:45:31Z","date_created":"2024-03-18T15:23:23Z","summary":null,"body":["<article data-history-node-id=\"5062\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-148\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-148<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a018, 2024<\/p>\n\n<p>Between March\u00a011 and 17, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Automation Decision Services\u00a0\u2013 versions 23.0.1 and 23.0.2<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 versions Build 250 to 267<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 version 7.5 to 7.5.0 UP7<\/li>\n\t<li>IBM Sterling Secure Proxy\u00a0\u2013 versions 6.0.3 and 6.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-148","alert_type":396,"serial_number":"AV24-148","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5063,"title":"Red Hat security advisory (AV24-149)","uuid":"30b6119d-721e-4dda-b4a2-b769f0a72805","banner":null,"lang":"en","date_modified":"2024-03-18","date_modified_ts":"2024-03-18T15:47:25Z","date_created":"2024-03-18T15:23:23Z","summary":null,"body":["<article data-history-node-id=\"5063\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-149\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-149<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a018, 2024<\/p>\n\n<p>Between March\u00a011 and 17, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server Extended Life Cycle Support (for IBM z Systems)\u00a0\u2013 version 7 s390x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-149","alert_type":396,"serial_number":"AV24-149","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5064,"title":"[Control systems] CISA ICS security advisories (AV24-150)","uuid":"e20c4862-2056-4033-802a-749355c4d7d7","banner":null,"lang":"en","date_modified":"2024-03-18","date_modified_ts":"2024-03-18T17:22:38Z","date_created":"2024-03-18T17:15:34Z","summary":null,"body":["<article data-history-node-id=\"5064\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-150\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-150<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a018, 2024<\/p>\n\n<p>Between March\u00a011 and 17, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics DIAEnergie\u00a0\u2013 versions prior to 1.10.00.005<\/li>\n\t<li>Mitsubishi Electric MELSEC-L Series\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric MELSEC-Q Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Schneider EcoStruxure Power Design Ecodial\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Cerberus PRO\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens RUGGEDCOM APE1808 with Fortinet NGFW\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SENTRON 3KC ATC6 Expansion Module Ethernet\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SENTRON 7KM PAC3x20\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SIMATIC RF160B\u00a0\u2013 versions prior to 2.2<\/li>\n\t<li>Siemens SINEMA Remote Connect Client\u00a0\u2013 versions prior to 3.1 SP1<\/li>\n\t<li>Siemens SINEMA Remote Connect Server\u00a0\u2013 versions prior to 3.2<\/li>\n\t<li>Siemens Siveillance Control\u00a0\u2013 versions 2.8 to versions prior to 3.1.1<\/li>\n\t<li>Siemens Sinteso\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Solid Edge\u00a0\u2013 versions prior to 223.0.11<\/li>\n\t<li>Softing edgeConnector\u00a0\u2013 version 3.60<\/li>\n\t<li>Softing edgeAggregator\u00a0\u2013 version 3.60<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-150","alert_type":398,"serial_number":"AV24-150","subject":"ics","moderation_state":"published","external_url":null},{"nid":5065,"title":"Mozilla security advisory (AV24-151)","uuid":"8acc6c43-a3f5-4242-9a55-61ff598795e6","banner":null,"lang":"en","date_modified":"2024-03-19","date_modified_ts":"2024-03-19T13:50:57Z","date_created":"2024-03-19T13:45:17Z","summary":null,"body":["<article data-history-node-id=\"5065\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-151\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-151<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a019, 2024<\/p>\n\n<p>On March\u00a019, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 124<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-12\/\">Mozilla Security Advisory\u00a0- MFSA 2024-12<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-13\/\">Mozilla Security Advisory\u00a0- MFSA 2024-13<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-151","alert_type":396,"serial_number":"AV24-151","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5067,"title":"Atlassian security advisory (AV24-152)","uuid":"c24c8ec8-43f2-483d-95d7-c575cb806b25","banner":null,"lang":"en","date_modified":"2024-03-19","date_modified_ts":"2024-03-19T18:38:20Z","date_created":"2024-03-19T18:25:12Z","summary":null,"body":["<article data-history-node-id=\"5067\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-152\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-152<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a019, 2024<\/p>\n\n<p>On March\u00a019, 2024, Atlassian published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Centre\u00a0\u2013 multiple versions<\/li>\n\t<li>Bamboo Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Centre\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Software Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Software Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-march-19-2024-1369444862.html\">Atlassian March 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/data-protection\/vulnerabilities\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-152","alert_type":396,"serial_number":"AV24-152","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5068,"title":"Google Chrome security advisory (AV24-153)","uuid":"172b0bc4-4d33-41f3-8aa6-e4d40614a661","banner":null,"lang":"en","date_modified":"2024-03-20","date_modified_ts":"2024-03-20T14:36:04Z","date_created":"2024-03-20T14:30:49Z","summary":null,"body":["<article data-history-node-id=\"5068\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-153\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-153<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a020, 2024<\/p>\n\n<p>On March\u00a019, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 123.0.6312.58\/.59 (Windows and Mac) and 123.0.6312.58 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/03\/stable-channel-update-for-desktop_19.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-153","alert_type":396,"serial_number":"AV24-153","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5069,"title":"Ivanti security advisory (AV24-154)","uuid":"44a961c3-1cf8-46c7-b179-c5d91335c7bf","banner":null,"lang":"en","date_modified":"2024-03-20","date_modified_ts":"2024-03-20T19:08:03Z","date_created":"2024-03-20T18:59:35Z","summary":null,"body":["<article data-history-node-id=\"5069\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-154\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-154<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 20, 2024<\/p>\n\n<p>On March 20, 2024, Ivanti published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Ivanti Neurons for ITSM (2023.3, 2023.2 and 2023.1)\u00a0\u2013 all versions<\/li>\n\t<li>Ivanti Standalone Sentry \u2013 versions 9.17.0, 9.18.0, 9.19.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/SA-CVE-2023-46808-Authenticated-Remote-File-Write-for-Ivanti-Neurons-for-ITSM?language=en_US\">Ivanti Security Advisory\u00a0- CVE-2023-46808 (Authenticated Remote File Write) for Ivanti Neurons for ITSM<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US\">Ivanti Security Advisory\u00a0- CVE-2023-41724 (Remote Code Execution) for Ivanti Standalone Sentry<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-154","alert_type":396,"serial_number":"AV24-154","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5072,"title":"Mozilla security advisory (AV24-155)","uuid":"a48901b6-8613-4dcb-b49f-afbc82bc0569","banner":null,"lang":"en","date_modified":"2024-03-22","date_modified_ts":"2024-03-22T14:43:00Z","date_created":"2024-03-22T14:03:17Z","summary":null,"body":["<article data-history-node-id=\"5072\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-155\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-155<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March\u00a022, 2024<\/p>\n\n<p>On March\u00a022, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 124.0.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.9.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-15\/\">Mozilla Security Advisory\u00a0- MFSA 2024-15<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-16\/\">Mozilla Security Advisory\u00a0- MFSA 2024-16<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-155","alert_type":396,"serial_number":"AV24-155","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5073,"title":"Ubuntu security advisory (AV24-156)","uuid":"f82b5e2a-8acb-4a9b-a9d5-bbc377c01084","banner":null,"lang":"en","date_modified":"2024-03-25","date_modified_ts":"2024-03-25T17:24:39Z","date_created":"2024-03-25T17:17:53Z","summary":null,"body":["<article data-history-node-id=\"5073\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-156\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-156<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 25, 2024<\/p>\n\n<p>Between March 18 and 24, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-156","alert_type":396,"serial_number":"AV24-156","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5074,"title":"IBM security advisory (AV24-157)","uuid":"547b10d5-fdb2-4afc-bf1c-13b6ab41613c","banner":null,"lang":"en","date_modified":"2024-03-25","date_modified_ts":"2024-03-25T20:40:13Z","date_created":"2024-03-25T20:30:09Z","summary":null,"body":["<article data-history-node-id=\"5074\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-157\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-157<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 25, 2024<\/p>\n\n<p>Between March 18 and 24, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise\u00a0\u2013 versions 11.0.0.1 to 11.0.0.24 and 12.0.1.0 to 12.0.11.1<\/li>\n\t<li>IBM Cloud Pak for Data Scheduling\u00a0\u2013 version 4.6.4 to 4.7.4<\/li>\n\t<li>IBM Security Verify Information Queue\u00a0\u2013 versions 10.0.6 and 10.0.7<\/li>\n\t<li>IBM Spectrum Control\u00a0\u2013 all 5.4 versions<\/li>\n\t<li>IBM Storage Copy Data Management\u00a0\u2013 version 2.2.0.0 to 2.2.22.1<\/li>\n\t<li>IBM Storage Protect Plus Server\u00a0\u2013 version 10.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-157","alert_type":396,"serial_number":"AV24-157","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5075,"title":"Dell security advisory (AV24-158)","uuid":"08d72405-77bb-4060-9db0-15dbafcc10d1","banner":null,"lang":"en","date_modified":"2024-03-25","date_modified_ts":"2024-03-25T20:51:17Z","date_created":"2024-03-25T20:45:17Z","summary":null,"body":["<article data-history-node-id=\"5075\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-158\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-158<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 25, 2024<\/p>\n\n<p>Between March 18 and 24, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 4.13.34<\/li>\n\t<li>APEX Cloud Platform Foundation Software\u00a0\u2013 versions prior to 03.00.03.00<\/li>\n\t<li>DELL Data Lakehouse System Software\u00a0\u2013 version 1.0.0.0<\/li>\n\t<li>Dell EMC VxRail Appliance\u00a0\u2013 versions prior to 7.0.483 and versions prior to 8.0.120<\/li>\n\t<li>Dell PowerProtect DD Management Center\u00a0\u2013 versions 7.0 through 7.12, versions 7.10.1.0 through 7.10.1.15 and versions 7.7.5.0 through 7.7.5.25<\/li>\n\t<li>Dell PowerProtect DD Management Center with SmartScale feature\u00a0\u2013 versions 7.10.1.0 through 7.10.1.15 and versions 7.8 through 7.12<\/li>\n\t<li>Dell Networking S5448-ON\u00a0\u2013 versions prior to v3.52.5.1-10<\/li>\n\t<li>Dell Networking S5448F-ON\u00a0\u2013 versions prior to v3.52.5.1-10<\/li>\n\t<li>Dell Networking Z9432F-ON\u00a0\u2013 versions prior to v3.51.5.1-18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-158","alert_type":396,"serial_number":"AV24-158","subject":"dell","moderation_state":"published","external_url":null},{"nid":5076,"title":"Apple security advisory (AV24-159)","uuid":"c32f3b0b-d3a4-4ae9-bc8c-83ed97f1503a","banner":null,"lang":"en","date_modified":"2024-03-26","date_modified_ts":"2024-03-26T12:52:03Z","date_created":"2024-03-25T20:59:29Z","summary":null,"body":["<article data-history-node-id=\"5076\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-159\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--*************************************************** START ADVISORY -English- ******************************************************-->\n<p><strong>Serial number: <\/strong>AV24-159<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 26, 2024<\/p>\n\n<p>On March 21 and 25, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Sonoma\u00a0\u2013 versions prior to 14.4.1<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.6.6<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 17.4.1<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 16.7.7<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 17.4.1<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 1.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><!--*************************************************** END ADVISORY -English-******************************************************--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-159","alert_type":396,"serial_number":"AV24-159","subject":"apple","moderation_state":"published","external_url":null},{"nid":5078,"title":"[Control systems] CISA ICS security advisories (AV24-160) ","uuid":"c8599b17-f371-4a85-be24-874fabb791b0","banner":null,"lang":"en","date_modified":"2024-03-26","date_modified_ts":"2024-03-26T15:26:25Z","date_created":"2024-03-26T15:01:38Z","summary":null,"body":["<article data-history-node-id=\"5078\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-160\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-160<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 26, 2024<\/p>\n\n<p>Between March 18 and 24, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Advantech WebAccess\/SCADA\u00a0\u2013 version 9.1.5U<\/li>\n\t<li>Franklin Fueling System EVO 55\u00a0 \u2013 versions prior to 2.26.3.8963<\/li>\n\t<li>Franklin Fueling System EVO 500\u00a0 \u2013 versions prior to 2.26.3.8963<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-079-01\">CISA ICS Advisory\u00a0\u2013 ICSA-24-079-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-081-01\">CISA ICS Advisory\u00a0\u2013 ICSA-24-081-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-160","alert_type":398,"serial_number":"AV24-160","subject":"ics","moderation_state":"published","external_url":null},{"nid":5077,"title":"Red Hat security advisory (AV24-161)","uuid":"b55be0f4-5568-4db0-a811-46d12862cc1e","banner":null,"lang":"en","date_modified":"2024-03-26","date_modified_ts":"2024-03-26T15:30:31Z","date_created":"2024-03-26T15:04:05Z","summary":null,"body":["<article data-history-node-id=\"5077\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-161\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-161<br \/><strong>Date: <\/strong>March 26, 2024<\/p>\n\n<p>Between March\u00a018 and 24,\u00a02024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\/for NFV\u00a0\u2013 Telecommunications Update Service 8.4 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-161","alert_type":396,"serial_number":"AV24-161","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5079,"title":"Google Chrome security advisory (AV24-162)","uuid":"571d322d-8997-4af2-ba13-515b85cba3c8","banner":null,"lang":"en","date_modified":"2024-03-26","date_modified_ts":"2024-03-26T19:43:33Z","date_created":"2024-03-26T19:29:14Z","summary":null,"body":["<article data-history-node-id=\"5079\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-162\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-162<br \/><strong>Date: <\/strong>March\u00a026, 2024<\/p>\n\n<p>On March\u00a026, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 123.0.6312.86\/.87 (Windows and Mac) and 123.0.6312.86 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/03\/stable-channel-update-for-desktop_26.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-162","alert_type":396,"serial_number":"AV24-162","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5080,"title":"[Control systems] Siemens security advisory (AV24-163)","uuid":"626fb10e-19e4-43df-b98e-87fd64d4d9ac","banner":null,"lang":"en","date_modified":"2024-03-27","date_modified_ts":"2024-03-27T15:24:20Z","date_created":"2024-03-27T15:19:32Z","summary":null,"body":["<article data-history-node-id=\"5080\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-163\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-163<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 27, 2024<\/p>\n\n<p>On March 26, 2024, Siemens published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Discovery and Basic Configuration Protocol (DCP)\u00a0\u2013 multiple products<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-163","alert_type":398,"serial_number":"AV24-163","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5081,"title":"Microsoft Edge security advisory (AV24-164)","uuid":"4ca16c21-5be9-4e6f-a6ae-4efe3a9e2c47","banner":null,"lang":"en","date_modified":"2024-03-27","date_modified_ts":"2024-03-27T15:45:45Z","date_created":"2024-03-27T15:41:15Z","summary":null,"body":["<article data-history-node-id=\"5081\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-164\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-164<br \/><strong>Date: <\/strong>March\u00a027, 2024<\/p>\n\n<p>On March\u00a022, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 123.0.2420.53<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-22-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-164","alert_type":396,"serial_number":"AV24-164","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5082,"title":"Cisco security advisory (AV24-165)","uuid":"d0276c0a-d47b-42da-8551-49a231595ba6","banner":null,"lang":"en","date_modified":"2024-03-28","date_modified_ts":"2024-03-28T10:37:28Z","date_created":"2024-03-28T10:32:00Z","summary":null,"body":["<article data-history-node-id=\"5082\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-165\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-165<br \/><strong>Date: <\/strong>March 28, 2024<\/p>\n\n<p>On March 27, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco IOS\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco IOS XE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Access Points\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Cisco Switches\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Cisco SD-Access fabric edge node\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-165","alert_type":396,"serial_number":"AV24-165","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5083,"title":"GitLab security advisory (AV24-166)","uuid":"fdded0ee-49b3-465b-9c8e-321d17057dbb","banner":null,"lang":"en","date_modified":"2024-03-28","date_modified_ts":"2024-03-28T10:51:24Z","date_created":"2024-03-28T10:44:45Z","summary":null,"body":["<article data-history-node-id=\"5083\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-166\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-166<br \/><strong>Date: <\/strong>March 28, 2024<\/p>\n\n<p>On March 27,\u00a02024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 16.10.1, 16.9.3 and 16.8.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 16.10.1, 16.9.3 and 16.8.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/03\/27\/security-release-gitlab-16-10-1-released\/\">GitLab Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-166","alert_type":396,"serial_number":"AV24-166","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5084,"title":"JetBrains security advisory (AV24-167)","uuid":"bade8929-3b63-40f1-8a60-5572fa6be9af","banner":null,"lang":"en","date_modified":"2024-03-28","date_modified_ts":"2024-03-28T11:07:43Z","date_created":"2024-03-28T11:02:01Z","summary":null,"body":["<article data-history-node-id=\"5084\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av24-167\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-167<br \/><strong>Date: <\/strong>March 28, 2024<\/p>\n\n<p>On March 27, 2024, JetBrains published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>JetBrains TeamCity On-Premises\u00a0\u2013 versions prior to 2024.03<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/help\/teamcity\/teamcity-2024-03-release-notes.html\">JetBrains Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains Fixed Security Issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av24-167","alert_type":396,"serial_number":"AV24-167","subject":"other","moderation_state":"published","external_url":null},{"nid":5085,"title":"Microsoft Edge security advisory (AV24-168)","uuid":"a5e47a25-774b-4deb-896e-f71dd625a6b2","banner":null,"lang":"en","date_modified":"2024-03-28","date_modified_ts":"2024-03-28T19:47:51Z","date_created":"2024-03-28T19:42:20Z","summary":null,"body":["<article data-history-node-id=\"5085\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-168\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-168<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 28, 2024<\/p>\n\n<p>On March 27, 2024, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 123.0.2420.65<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 122.0.2365.113<\/li>\n<\/ul><p>The Chromium team reports that an exploit for CVE-2024-2883 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-27-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-168","alert_type":396,"serial_number":"AV24-168","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5086,"title":"IBM security advisory (AV24-169)","uuid":"81f0e4a4-de01-4c78-a048-ffff4f15fca1","banner":null,"lang":"en","date_modified":"2024-04-02","date_modified_ts":"2024-04-02T13:56:54Z","date_created":"2024-04-02T13:52:32Z","summary":null,"body":["<article data-history-node-id=\"5086\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-169\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-169<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 2, 2024<\/p>\n\n<p>Between March 25 and 31, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud PAK for AIOps\u00a0\u2013 versions 4.1.0 to 4-4.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Intelligent Operations Centre (IOC)\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM MQ Operator\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Operations Analytics Predictive Insights\u00a0\u2013 versions 1.3.6 to 1.3.6.7 (iFix7)<\/li>\n\t<li>IBM Planning Analytics Workspace\u00a0\u2013 version 2.0<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5.0 to 7.5.0 UP7 IF06<\/li>\n\t<li>IBM supplied MQ Advanced container images\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-169","alert_type":396,"serial_number":"AV24-169","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5087,"title":"Ubuntu security advisory (AV24-170)","uuid":"2af04938-c752-46c8-88a8-b87e3c4416ac","banner":null,"lang":"en","date_modified":"2024-04-02","date_modified_ts":"2024-04-02T14:12:13Z","date_created":"2024-04-02T14:08:37Z","summary":null,"body":["<article data-history-node-id=\"5087\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-170\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-170<br \/><strong>Date: <\/strong>April 2, 2024<\/p>\n\n<p>Between March 25 and 31, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-170","alert_type":396,"serial_number":"AV24-170","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5088,"title":"Red Hat security advisory (AV24-171)","uuid":"69b5b7ab-dbee-4452-bf7a-80307f9dcf54","banner":null,"lang":"en","date_modified":"2024-04-02","date_modified_ts":"2024-04-02T14:36:35Z","date_created":"2024-04-02T14:29:34Z","summary":null,"body":["<article data-history-node-id=\"5088\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-171\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-171<br \/><strong>Date: <\/strong>April 2, 2024<\/p>\n\n<p>Between March 25 and 31, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:1532\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:1532<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-171","alert_type":396,"serial_number":"AV24-171","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5089,"title":"[Control systems] CISA ICS security advisories (AV24-172)","uuid":"8e70083d-e226-49ad-97fb-365fd26150fe","banner":null,"lang":"en","date_modified":"2024-04-02","date_modified_ts":"2024-04-02T16:12:09Z","date_created":"2024-04-02T16:02:18Z","summary":null,"body":["<article data-history-node-id=\"5089\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-172\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-172<br \/><strong>Date: <\/strong>April 2, 2024<\/p>\n\n<p>Between March 25 and 31, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automation-Direct C-MORE EA9 HMI\u00a0\u2013 multiple platforms, version 6.77 and prior<\/li>\n\t<li>Rockwell Automation Arena Simulation\u00a0\u2013 version 16.00<\/li>\n\t<li>Rockwell Automation FactoryTalk View ME\u00a0\u2013 versions<\/li>\n\t<li>prior to v14<\/li>\n\t<li>Rockwell Automation PowerFlex 527\u00a0\u2013 versions v2.001.x and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-086-01\">CISA ICS Advisory\u00a0\u2013 ICSA-24-086-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-086-02\">CISA ICS Advisory\u00a0\u2013 ICSA-24-086-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-086-03\">CISA ICS Advisory\u00a0\u2013 ICSA-24-086-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-086-04\">CISA ICS Advisory\u00a0\u2013 ICSA-24-086-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-172","alert_type":398,"serial_number":"AV24-172","subject":"ics","moderation_state":"published","external_url":null},{"nid":5090,"title":"HPE security advisory (AV24-173)","uuid":"b3f4c169-9bac-4c8e-badf-c68de761d716","banner":null,"lang":"en","date_modified":"2024-04-02","date_modified_ts":"2024-04-02T16:22:05Z","date_created":"2024-04-02T16:18:11Z","summary":null,"body":["<article data-history-node-id=\"5090\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-173\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-173<br \/><strong>Date: <\/strong>April 2, 2024<\/p>\n\n<p>On April 1, 2024, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE NonStop Web ViewPoint Enterprise\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbns04624en_us\">HPE Security Bulletin - hpesbns04624en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-173","alert_type":396,"serial_number":"AV24-173","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5091,"title":"Android security advisory \u2013 April 2024 Monthly Rollup (AV24-174)","uuid":"5b4980bf-0b0a-4d1f-b836-3ac57a1636a7","banner":null,"lang":"en","date_modified":"2024-04-02","date_modified_ts":"2024-04-02T18:57:07Z","date_created":"2024-04-02T18:35:47Z","summary":null,"body":["<article data-history-node-id=\"5091\" about=\"\/en\/alerts-advisories\/android-security-advisory-april-2024-monthly-rollup-av24-174\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-174<br \/><strong>Date: <\/strong>April\u00a02, 2024<\/p>\n\n<p>On April\u00a01, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-04-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-april-2024-monthly-rollup-av24-174","alert_type":396,"serial_number":"AV24-174","subject":"android","moderation_state":"published","external_url":null},{"nid":5092,"title":"HPE security advisory (AV24-175)","uuid":"24e69c22-9dfa-4334-a1af-4236f48616bb","banner":null,"lang":"en","date_modified":"2024-04-02","date_modified_ts":"2024-04-02T19:37:23Z","date_created":"2024-04-02T19:28:23Z","summary":null,"body":["<article data-history-node-id=\"5092\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-175\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-175<br \/><strong>Date: <\/strong>April\u00a02, 2024<\/p>\n\n<p>On April\u00a02, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Alletra\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Apollo\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Edgeline\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Compute Edge Server e930t\u00a0\u2013 versions prior to v2.16_03-01-2024<\/li>\n\t<li>HPE ProLiant\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Synergy\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04593en_us\">HPE Security Bulletin\u00a0- hpesbhf04593en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-175","alert_type":396,"serial_number":"AV24-175","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5093,"title":"Google Chrome security advisory (AV24-176)","uuid":"7c4b48c4-a965-4d5a-a37f-8a5115c714c3","banner":null,"lang":"en","date_modified":"2024-04-03","date_modified_ts":"2024-04-03T13:57:20Z","date_created":"2024-04-03T13:54:04Z","summary":null,"body":["<article data-history-node-id=\"5093\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-176\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-176<br \/><strong>Date: <\/strong>April\u00a03, 2024<\/p>\n\n<p>On April\u00a02, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 123.0.6312.105\/.106\/.107 (Windows and Mac) and 123.0.6312.105 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/04\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-176","alert_type":396,"serial_number":"AV24-176","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5095,"title":"Ivanti security advisory (AV24-177)","uuid":"f0f2b50d-be0b-49e6-a43e-b4c668c031a2","banner":null,"lang":"en","date_modified":"2024-04-03","date_modified_ts":"2024-04-03T18:02:18Z","date_created":"2024-04-03T17:43:20Z","summary":null,"body":["<article data-history-node-id=\"5095\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-177\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-177<br \/><strong>Date: <\/strong>April\u00a03, 2024<\/p>\n\n<p>On April\u00a03, 2024, Ivanti published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Connect Secure (9.x and 22.x)\u00a0\u2013 all versions<\/li>\n\t<li>Ivanti Policy Secure Gateway (9.x and 22.x)\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US\">Ivanti Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-177","alert_type":396,"serial_number":"AV24-177","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5096,"title":"Cisco security advisory (AV24-178)","uuid":"aba22556-1272-4836-867b-f5a428520555","banner":null,"lang":"en","date_modified":"2024-04-03","date_modified_ts":"2024-04-03T18:11:37Z","date_created":"2024-04-03T17:43:20Z","summary":null,"body":["<article data-history-node-id=\"5096\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-178\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-178<br \/><strong>Date: <\/strong>April\u00a03, 2024<\/p>\n\n<p>On April\u00a03, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>Cisco Nexus Dashboard Fabric Controller (NDFC)\u00a0\u2013 version 12.1.3b<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ndfc-dir-trav-SSn3AYDw\">Cisco Security Advisory\u00a0\u2013 cisco-sa-ndfc-dir-trav-SSn3AYDw<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-178","alert_type":396,"serial_number":"AV24-178","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5098,"title":"HPE security advisory (AV24-179)","uuid":"93936baa-938e-4408-abb0-333a817fdab6","banner":null,"lang":"en","date_modified":"2024-04-03","date_modified_ts":"2024-04-03T20:12:45Z","date_created":"2024-04-03T20:08:47Z","summary":null,"body":["<article data-history-node-id=\"5098\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-179\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-179<br \/><strong>Date: <\/strong>April\u00a03, 2024<\/p>\n\n<p>On April\u00a03, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console Assurance Monitoring (UOCAM)\u00a0\u2013 versions prior to 3.1.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04629en_us\">HPE Security Bulletin\u00a0- hpesbgn04629en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-179","alert_type":396,"serial_number":"AV24-179","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5099,"title":"[Control systems] ABB security advisory (AV24-180)","uuid":"ae291bc4-9de5-4425-b0c6-02cfa2eeaa46","banner":null,"lang":"en","date_modified":"2024-04-04","date_modified_ts":"2024-04-04T20:13:54Z","date_created":"2024-04-04T20:03:12Z","summary":null,"body":["<article data-history-node-id=\"5099\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-180\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-180<br \/><strong>Date: <\/strong>April\u00a04, 2024<\/p>\n\n<p>On April\u00a03, 2024, ABB published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ABB S+ Operations\u00a0\u2013 multiple versions<\/li>\n\t<li>ABB S+ Engineering\u00a0\u2013 versions 2.1 to 2.3 RU3<\/li>\n\t<li>ABB S+ Analyst using Fast Data Logger\u00a0\u2013 versions 7.0.0.0 to 7.2.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA002536&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch&amp;_ga=2.232073879.948564512.1712174687-1852414007.1701111067\">ABB Security Advisory (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-180","alert_type":398,"serial_number":"AV24-180","subject":"abb","moderation_state":"published","external_url":null},{"nid":5101,"title":"Microsoft Edge security advisory (AV24-181)","uuid":"721653d0-39ed-45ce-9043-64e5e7ab09a5","banner":null,"lang":"en","date_modified":"2024-04-05","date_modified_ts":"2024-04-05T14:52:24Z","date_created":"2024-04-05T14:44:26Z","summary":null,"body":["<article data-history-node-id=\"5101\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-181\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-181<br \/><strong>Date: <\/strong>April\u00a05, 2024<\/p>\n\n<p>On April\u00a04, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 123.0.2420.81<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-4-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-181","alert_type":396,"serial_number":"AV24-181","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5103,"title":"IBM security advisory (AV24-182)","uuid":"83c7bb7d-2045-435d-a09c-d4101a90f09d","banner":null,"lang":"en","date_modified":"2024-04-08","date_modified_ts":"2024-04-08T17:30:23Z","date_created":"2024-04-08T17:31:23Z","summary":null,"body":["<article data-history-node-id=\"5103\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-182\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-182<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2024<\/p>\n\n<p>Between April 1 and 7, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM CP4NA\u00a0\u2013 version 2.7<\/li>\n\t<li>IBM App Connect Enterprise\u00a0\u2013 version 12.0.1.0 to 12.0.11.2<\/li>\n\t<li>IBM Maximo Application Suite IoT Component\u00a0\u2013 versions 8.7 and 8.8<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 versions 1.14.1, 1.14.2, 1.14.2 IF001, 1.14.3, 1.14.3 IF001 and 1.14.0<\/li>\n\t<li>IBM Tivoli Netcool Impact\u00a0\u2013 version 7.1.0.0 to 7.1.0.32<\/li>\n\t<li>IBM Jazz for Service Management\u00a0\u2013 version 1.1.3.0 to 1.1.3.20<\/li>\n\t<li>IBM Netcool Operations Insight\u00a0\u2013 versions 1.4 to 1.4.1.2, 1.5 to 1.5.0.1 and 1.6 to 1.6.11<\/li>\n\t<li>IBM PCOMM\u00a0\u2013 versions 14.0.6 and 15.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-182","alert_type":396,"serial_number":"AV24-182","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5104,"title":"Ubuntu security advisory (AV24-183)","uuid":"ec3173de-6f1b-449a-8c6d-dca22b6e9b6c","banner":null,"lang":"en","date_modified":"2024-04-08","date_modified_ts":"2024-04-08T18:00:00Z","date_created":"2024-04-08T18:04:03Z","summary":null,"body":["<article data-history-node-id=\"5104\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-183\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-183<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2024<\/p>\n\n<p>Between April 1 and 7, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0102-1\">Ubuntu Security Notice\u00a0\u2013 LSN-0102-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-183","alert_type":396,"serial_number":"AV24-183","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5102,"title":"[Control systems] CISA ICS security advisories (AV24-184)","uuid":"2461cbfb-7012-460b-bed3-8b4d9096fc87","banner":null,"lang":"en","date_modified":"2024-04-08","date_modified_ts":"2024-04-08T18:07:52Z","date_created":"2024-04-08T18:20:54Z","summary":null,"body":["<article data-history-node-id=\"5102\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-184\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-184<br \/><strong>Date: <\/strong>April\u00a08, 2024<\/p>\n\n<p>Between April 1 and 7, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Energy Asset Suite\u00a0\u2013 versions prior to 9.6.3.13 and versions prior to 9.6.4.1<\/li>\n\t<li>IOSiX IO-1020 Micro ELD\u00a0\u2013 versions prior to 360<\/li>\n\t<li>Schweitzer Engineering SEL-700 series relays\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-093-01\">CISA ICS Advisory\u00a0\u2013 ICSA-24-093-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-095-01\">CISA ICS Advisory\u00a0\u2013 ICSA-24-095-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-095-02\">CISA ICS Advisory\u00a0\u2013 ICSA-24-095-02 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-184","alert_type":398,"serial_number":"AV24-184","subject":"ics","moderation_state":"published","external_url":null},{"nid":5105,"title":"Red Hat security advisory (AV24-185)","uuid":"b142ed91-6990-4811-9f79-b45b42f2fd41","banner":null,"lang":"en","date_modified":"2024-04-08","date_modified_ts":"2024-04-08T20:16:39Z","date_created":"2024-04-08T19:54:42Z","summary":null,"body":["<article data-history-node-id=\"5105\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-185\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-185<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2024<\/p>\n\n<p>Between April 1 and 7, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-185","alert_type":396,"serial_number":"AV24-185","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5107,"title":"[Control systems] Schneider Electric security advisory (AV24-186)","uuid":"ee6a2d9e-4cff-41e4-afc6-9e34a112f96a","banner":null,"lang":"en","date_modified":"2024-04-09","date_modified_ts":"2024-04-09T14:04:20Z","date_created":"2024-04-09T13:57:00Z","summary":null,"body":["<article data-history-node-id=\"5107\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-186\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-186<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 9, 2024<\/p>\n\n<p>On April 9, 2024, Schneider Electric published a security advisory to highlight a vulnerability in the following product:<\/p>\n\n<ul><li>Easergy Studio\u00a0\u2013 versions prior to 9.3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-100-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-100-01.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-100-01 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-186","alert_type":398,"serial_number":"AV24-186","subject":"other","moderation_state":"published","external_url":null},{"nid":5106,"title":"[Control systems] Siemens security advisory (AV24-187)","uuid":"4d7c1fa1-f8af-4910-9fc3-d74d0c064922","banner":null,"lang":"en","date_modified":"2024-04-09","date_modified_ts":"2024-04-09T14:11:14Z","date_created":"2024-04-09T14:12:10Z","summary":null,"body":["<article data-history-node-id=\"5106\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-187\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-187<br \/><strong>Date: <\/strong>April 9, 2024<\/p>\n\n<p>On April 9, 2024, Siemens published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Parasolid\u00a0\u2013 multiple versions<\/li>\n\t<li>RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW\u00a0\u2013 all versions<\/li>\n\t<li>SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SIMATIC S7-1500 TM MFP\u00a0\u2013 all versions<\/li>\n\t<li>SINEC NMS\u00a0\u2013 versions prior to 2.0 SP2<\/li>\n\t<li>TeleControl Server Basic V3\u00a0\u2013 versions prior to 3.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-187","alert_type":398,"serial_number":"AV24-187","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5108,"title":"HPE security advisory (AV24-188)","uuid":"05b3d165-0724-4521-96ba-8fdb81f6dc8b","banner":null,"lang":"en","date_modified":"2024-04-09","date_modified_ts":"2024-04-09T17:53:03Z","date_created":"2024-04-09T17:40:04Z","summary":null,"body":["<article data-history-node-id=\"5108\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-188\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-188<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2024<\/p>\n\n<p>On April 9, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified Correlation Analyzer (UCA)\u00a0\u2013 versions prior to 4.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbgn04598en_us\">HPE Security Bulletin\u00a0- hpesbgn04598en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-188","alert_type":396,"serial_number":"AV24-188","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5109,"title":"SAP security advisory \u2013 April 2024 monthly rollup (AV24-189)","uuid":"682030a6-9a27-4916-8293-88abcfaaf969","banner":null,"lang":"en","date_modified":"2024-04-09","date_modified_ts":"2024-04-09T18:19:24Z","date_created":"2024-04-09T17:54:50Z","summary":null,"body":["<article data-history-node-id=\"5109\" about=\"\/en\/alerts-advisories\/sap-security-advisory-april-2024-monthly-rollup-av24-189\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-189<br \/><strong>Date: <\/strong>April\u00a09, 2024<\/p>\n\n<p>On April\u00a09, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP BusinessObjects Web Intelligence\u00a0\u2013 versions prior to 4.2 and 4.3<\/li>\n\t<li>SAP NetWeaver AS Java User Management Engine\u00a0\u2013 version prior to SERVERCORE 7.50, J2EE-APPS 7.50 and UMEADMIN 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/april-2024.html\">SAP Security Patch Day\u00a0- April 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-april-2024-monthly-rollup-av24-189","alert_type":396,"serial_number":"AV24-189","subject":"sap","moderation_state":"published","external_url":null},{"nid":5110,"title":"Fortinet security advisory (AV24-190)","uuid":"dab3030a-c482-4b5e-8549-88708b085398","banner":null,"lang":"en","date_modified":"2024-04-09","date_modified_ts":"2024-04-09T18:48:12Z","date_created":"2024-04-09T17:54:51Z","summary":null,"body":["<article data-history-node-id=\"5110\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-190\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-190<br \/><strong>Date: <\/strong>April\u00a09, 2024<\/p>\n\n<p>On April\u00a09, 2024, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>FortiClientLinux 7.2\u00a0\u2013 version 7.2.0<\/li>\n\t<li>FortiClientLinux 7.0\u00a0\u2013 versions 7.0.6 to 7.0.10<\/li>\n\t<li>FortiClientLinux 7.0\u00a0\u2013 versions 7.0.3 to 7.0.4<\/li>\n\t<li>FortiClientMac 7.2\u00a0\u2013 versions 7.2.0 to 7.2.3<\/li>\n\t<li>FortiClientMac 7.0\u00a0\u2013 versions 7.0.6 to 7.0.10<\/li>\n\t<li>FortiOS\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiProxy\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiSandbox 4.4\u00a0\u2013 versions 4.4.0 to 4.4.3<\/li>\n\t<li>FortiSandbox 4.2\u00a0\u2013 versions 4.2.0 to 4.2.6<\/li>\n\t<li>FortiSandbox 4.0\u00a0\u2013 versions 4.0.0 to 4.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-087\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-087<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-345\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-345<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-454\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-454<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-489\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-489<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-493\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-493<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-190","alert_type":396,"serial_number":"AV24-190","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":5111,"title":"Adobe security advisory (AV24-191)","uuid":"2d8aa0f3-fdf2-45bb-8cf2-09de534c9cfb","banner":null,"lang":"en","date_modified":"2024-04-09","date_modified_ts":"2024-04-09T21:02:17Z","date_created":"2024-04-09T20:56:27Z","summary":null,"body":["<article data-history-node-id=\"5111\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-191\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-191<br \/><strong>Date: <\/strong>April\u00a09, 2024<\/p>\n\n<p>On April\u00a09, 2024, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe Animate 2023\u00a0- version 23.0.4 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0- version 24.0.1 and prior<\/li>\n\t<li>Adobe Commerce\u00a0- multiple versions<\/li>\n\t<li>Adobe Media Encoder\u00a0- version 23.6.4 and prior<\/li>\n\t<li>Adobe Media Encoder\u00a0- version 24.2.1 and prior<\/li>\n\t<li>Magento Open Source\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb24-18.html\">Adobe Security Advisory\u00a0- APSB24-18<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/media-encoder\/apsb24-23.html\">Adobe Security Advisory\u00a0- APSB24-23<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/animate\/apsb24-26.html\">Adobe Security Advisory\u00a0- APSB24-26<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-191","alert_type":396,"serial_number":"AV24-191","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5112,"title":"Microsoft security advisory \u2013 April 2024 monthly rollup (AV24-192)","uuid":"35aa0e40-0000-4efe-91f0-a6b1b9722af2","banner":null,"lang":"en","date_modified":"2024-04-10","date_modified_ts":"2024-04-10T14:35:54Z","date_created":"2024-04-10T14:11:49Z","summary":null,"body":["<article data-history-node-id=\"5112\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2024-monthly-rollup-av24-192\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-192<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 10, 2024<\/p>\n\n<p>On April 9, 2024, Microsoft published security updates to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Microsoft .NET\u00a0\u2013 multiple versions<\/li>\n\t<li>Microsoft .NET Framework\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Azure Kubernetes Service Confidential Containers\u00a0\u2013 multiple versions<\/li>\n\t<li>Microsoft Defender for IoT\u00a0\u2013 versions prior to 24.1.3<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SQL Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Microsoft Visual Studio\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Apr\">April 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-april-2024-monthly-rollup-av24-192","alert_type":396,"serial_number":"AV24-192","subject":"other","moderation_state":"published","external_url":null},{"nid":5113,"title":"Palo Alto Networks security advisory (AV24-193)","uuid":"165aa959-f389-4d4e-b6b1-1af212063064","banner":null,"lang":"en","date_modified":"2024-04-10","date_modified_ts":"2024-04-10T18:36:46Z","date_created":"2024-04-10T18:05:27Z","summary":null,"body":["<article data-history-node-id=\"5113\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-193\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-193<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 10, 2024<\/p>\n\n<p>On April 10, 2024, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.2<\/li>\n\t<li>PAN-OS 11.0\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.1\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.0\u00a0\u2013 versions prior to 10.0.12<\/li>\n\t<li>PAN-OS 9.1\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 9.0\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 8.1\u00a0\u2013 versions prior to 8.1.24<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-3382\">Palo Alto Networks Security Advisory\u00a0- CVE-2024-3382<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-3383\">Palo Alto Networks Security Advisory\u00a0- CVE-2024-3383<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-3384\">Palo Alto Networks Security Advisory\u00a0- CVE-2024-3384<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-3385\">Palo Alto Networks Security Advisory\u00a0- CVE-2024-3385<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-193","alert_type":396,"serial_number":"AV24-193","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5114,"title":"Google Chrome security advisory (AV24-194)","uuid":"1abe93ab-18d1-40f4-a118-f8f2340f9eb0","banner":null,"lang":"en","date_modified":"2024-04-10","date_modified_ts":"2024-04-10T20:18:05Z","date_created":"2024-04-10T20:13:47Z","summary":null,"body":["<article data-history-node-id=\"5114\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-194\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-194<br \/><strong>Date: <\/strong>April\u00a010, 2024<\/p>\n\n<p>On April\u00a010, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome for Desktop\u00a0\u2013 versions prior to 123.0.6312.122\/.123 (Windows), 123.0.6312.122\/.123\/.124 (Mac) and 123.0.6312.122 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/04\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-194","alert_type":396,"serial_number":"AV24-194","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5115,"title":"Citrix security advisory (AV24-195)","uuid":"c591273d-b5e5-4c0b-ac75-f9174daabcb4","banner":null,"lang":"en","date_modified":"2024-04-11","date_modified_ts":"2024-04-11T14:24:01Z","date_created":"2024-04-11T14:03:13Z","summary":null,"body":["<article data-history-node-id=\"5115\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av24-195\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-195<br \/><strong>Date: <\/strong>April\u00a011, 2024<\/p>\n\n<p>On April\u00a011, 2024, Citrix published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>XenServer\u00a0\u2013 version 8<\/li>\n\t<li>Citrix Hypervisor\u00a0\u2013 version 8.2 CU1 LTSR<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could allow information disclosure and denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX633151\/xenserver-and-citrix-hypervisor-security-update-for-cve202346842-cve20242201-and-cve202431142\">Citrix Security Advisory\u00a0\u2013 CTX633151<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av24-195","alert_type":396,"serial_number":"AV24-195","subject":"citrix","moderation_state":"published","external_url":null},{"nid":5116,"title":"Mitel security advisory (AV24-196)","uuid":"cd686282-f939-475e-b1b0-9de1e2735e27","banner":null,"lang":"en","date_modified":"2024-04-11","date_modified_ts":"2024-04-11T17:54:38Z","date_created":"2024-04-11T17:49:46Z","summary":null,"body":["<article data-history-node-id=\"5116\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-196\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-196<br \/><strong>Date: <\/strong>April 11, 2024<\/p>\n\n<p>On April 10, 2024, Mitel published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MiCollab\u00a0\u2013 version 9.7.1.110 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0004\">Mitel Security Advisory - 24-0004<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0005\">Mitel Security Advisory - 24-0005<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-196","alert_type":396,"serial_number":"AV24-196","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5117,"title":"[Control systems] B&R security advisory (AV24-197)","uuid":"f54183fd-114d-47c0-bac9-db03e316b4cf","banner":null,"lang":"en","date_modified":"2024-04-11","date_modified_ts":"2024-04-11T19:07:00Z","date_created":"2024-04-11T18:53:19Z","summary":null,"body":["<article data-history-node-id=\"5117\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-197\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-197<br \/><strong>Date: <\/strong>April\u00a011, 2024<\/p>\n\n<p>On April\u00a010, 2024, B&amp;R published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>B&amp;R APROL R4.2\u00a0\u2013 version R4.2-07 (SLES 12) and prior<\/li>\n\t<li>B&amp;R APROL R4.4\u00a0\u2013 version R4.4-00P2 (SLES 15) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA24P006_Several_vulnerabilities_in_the_Docker_Engine_used_by_BR_APROL-48d3d928.pdf\">B&amp;R Cyber Security Advisory (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-197","alert_type":398,"serial_number":"AV24-197","subject":"ics","moderation_state":"published","external_url":null},{"nid":5118,"title":"Palo Alto Networks security advisory (AV24-198)","uuid":"dc1608a8-c971-4d29-9ec5-f5b7ecb1db6a","banner":null,"lang":"en","date_modified":"2024-04-12","date_modified_ts":"2024-04-12T12:52:04Z","date_created":"2024-04-12T12:51:43Z","summary":null,"body":["<article data-history-node-id=\"5118\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-198\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-198<br \/><strong>Date: <\/strong>April 12, 2024<\/p>\n\n<p>On April 12, 2024, Palo Alto Networks published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.2-h3<\/li>\n\t<li>PAN-OS 11.0\u00a0\u2013 versions prior to 0.4-h1<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.9-h1<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to remote code execution. Palo Alto Networks has indicated that CVE-2024-3400 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-3400\">Palo Alto Networks Security Advisory\u00a0- CVE-2024-3400 <\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-198","alert_type":396,"serial_number":"AV24-198","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5120,"title":"Vulnerability impacting PAN-OS GlobalProtect Gateway - Update 2","uuid":"9af26729-6662-4992-8ddb-93e47753dc83","banner":null,"lang":"en","date_modified":"2024-04-17","date_modified_ts":"2024-04-17T19:23:07Z","date_created":"2024-04-12T15:42:49Z","summary":null,"body":["<article data-history-node-id=\"5120\" about=\"\/en\/alerts-advisories\/al24-005-vulnerability-impacting-pan-os-globalprotect-gateway\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL24-005<br \/><strong>Date: <\/strong>April 17,\u00a02024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On April\u00a012, 2024, Palo Alto Networks published a security advisory about a critical vulnerability (CVE-2024-3400) impacting the GlobalProtect Gateway feature in PAN-OS 11.1, 11.0 and 10.2<span class=\"nowrap\"><sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/span>. In response to this advisory, the Cyber Centre released advisory AV24-198 on April 12<span class=\"nowrap\"><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/span>.<\/p>\n\n<p>Exploitation of CVE-2024-3400 may allow an unauthenticated threat actor to execute arbitrary code with root privileges on the firewall<span class=\"nowrap\"><sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/span>. Palo Alto Networks is aware of limited exploitation of CVE-2024-3400.<\/p>\n\n<p>This vulnerability affects the following PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls with the configurations for both GlobalProtect gateway and device telemetry enabled:<\/p>\n\n<ul><li>PAN-OS 11.1 \u2013 versions prior to 11.1.2-h3<\/li>\n\t<li>PAN-OS 11.0 \u2013 versions prior to 11.0.4-h1<\/li>\n\t<li>PAN-OS 10.2 \u2013 versions prior to 10.2.9-h1<\/li>\n<\/ul><p>Fixes for this vulnerability are in development and are expected to be released by April 14<span class=\"nowrap\"><span class=\"nowrap\"><sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">ootnote <\/span>1<\/a><\/sup><\/span><\/span>.<\/p>\n\n<p>Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On April 14, 2024, Palo Alto Networks released hotfixes for PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, and PAN-OS 11.1.2-h3<span class=\"nowrap\"><span class=\"nowrap\"><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/span><\/span>. Hotfixes for additional versions will be made available in the coming days.<\/p>\n\n<h2>Update 2<\/h2>\n\n<p>On April 17, 2024, Palo Alto Networks updated their security advisory<sup id=\"fn1g-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> to reflect that having device telemetry disabled does NOT protect PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls configured with GlobalProtect gateway and\/or GlobalProtect portal from exploitation.<\/p>\n\n<p>With the GlobalProtect portal product now added as a vulnerable configuration, Palo Alto Networks no longer recommends this as a mitigation and clients with affected versions are advised to apply the hotfixes.<\/p>\n\n<p>Palo Alto Networks has also provided additional Threat Prevention Threat IDs 95189 and 95191 (available in Applications and Threats content version 8836-8695 and later). Customers with a Threat Prevention subscription can leverage the new signatures for detection and prevention.<\/p>\n\n<p>Clients can verify whether they have a GlobalProtect gateway or GlobalProtect portal configured by checking for entries in their firewall web interface (Network &gt; GlobalProtect &gt; Gateways or Network &gt; GlobalProtect &gt; Portals).<\/p>\n\n<p>To reflect the updated guidance from Palo Alto Networks, the Cyber Centre has removed the recommendation to disable telemetry as a mitigation strategy.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p><strong>Update April 17 2024<\/strong><\/p>\n\n<p>Clients can verify whether they have a GlobalProtect gateway or GlobalProtect portal configured by checking for entries in their firewall web interface (Network &gt; GlobalProtect &gt; Gateways or Network &gt; GlobalProtect &gt; Portals).<\/p>\n\n<p>To reflect the updated guidance from Palo Alto Networks, the Cyber Centre has removed the recommendation to disable telemetry as a mitigation strategy.<\/p>\n\n<p><strong>End of update<\/strong><\/p>\n\n<p>The Cyber Centre strongly recommends that organizations patch affected firewalls when fixes are made available.<\/p>\n\n<p>Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 95187 (introduced in Applications and Threats content version 8833-8682).<\/p>\n\n<p>In addition to enabling Threat ID 95187, customers must ensure vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device<span class=\"nowrap\"><sup id=\"fn1d-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/span>.<\/p>\n\n<p>If you are unable to apply the Threat Prevention based mitigation at this time, you can still mitigate the impact of this vulnerability by temporarily disabling device telemetry until the device is upgraded to a fixed PAN-OS version. Once upgraded, device telemetry should be re-enabled on the device<span class=\"nowrap\"><sup id=\"fn1e-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/span>.<\/p>\n\n<p>The Cyber Centre recommends organizations review open source resources for additional information and indicators of compromise<span class=\"nowrap\"><sup id=\"fn3f-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4a-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/span>.<\/p>\n\n<p>Organizations should also review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<span class=\"nowrap\"><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/span> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t<li>Patching operating systems and applications.<\/li>\n\t<li>Isolate web-facing applications.<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>Partner Reporting<\/h2>\n\n<p><a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/os-command-injection-vulnerability-in-globalprotect-gateway\">ACSC - OS Command Injection Vulnerability in GlobalProtect Gateway<\/a><\/p>\n\n<p><a href=\"https:\/\/www.cert.govt.nz\/it-specialists\/advisories\/palo-alto-command-injection-vulnerability-in-pan-os-globalprotect\/\">NCSC-NZ - Palo Alto Command Injection Vulnerability in PAN-OS GlobalProtect<\/a><\/p>\n<\/section><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <i>Official Languages Act<\/i> is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-3400\">CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect Gateway<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1a-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-198\">AV24-198 \u2013 Palo Alto Networks security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/unit42.paloaltonetworks.com\/cve-2024-3400\/\">Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.volexity.com\/blog\/2024\/04\/12\/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400\/\">Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/product-downloads?language=en_US\">Palo Alto Networks product downloads (Login required)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al24-005-vulnerability-impacting-pan-os-globalprotect-gateway","alert_type":397,"serial_number":"AL24-005","subject":"other","moderation_state":"published","external_url":null},{"nid":5122,"title":"IBM security advisory (AV24-199)","uuid":"a76ea02c-384a-497a-be63-ef65257ac48b","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T16:16:18Z","date_created":"2024-04-15T16:10:53Z","summary":null,"body":["<article data-history-node-id=\"5122\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-199\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-199<br \/><strong>Date: <\/strong>April 15, 2024<\/p>\n\n<p>Between April 8 and 14, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Analyst Workflow\u00a0\u2013 versions 1.0.0 to 2.32.0<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 versions 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Disconnected Log Collector\u00a0\u2013 versions 1.0 to 1.8.4<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component \u2013 versions 8.11 and 8.10<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 builds 261 to 268<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP8<\/li>\n\t<li>IBM Sterling B2B Integrator\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Sterling Order Management\u00a0\u2013 version 10.0<\/li>\n\t<li>IBM Tivoli Netcool Impact\u00a0\u2013 versions 7.1.0.1 to 7.1.0.32<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.0 to 4.8.3<\/li>\n\t<li>PCOMM\u00a0\u2013 versions 14.0.6 and 15.0.1<\/li>\n\t<li>QRadar Suite Software\u00a0\u2013 versions 1.10.12.0 to 1.10.19.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-199","alert_type":396,"serial_number":"AV24-199","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5123,"title":"[Control systems] CISA ICS security advisories (AV24-200) ","uuid":"5cf0d6fb-bf28-4fc1-946f-908e6a7faecc","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T16:33:11Z","date_created":"2024-04-15T16:25:58Z","summary":null,"body":["<article data-history-node-id=\"5123\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-200\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-200<br \/><strong>Date: <\/strong>April 15, 2024<\/p>\n\n<p>Between April 8 and 14, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Rockwell Automation 5015-AENFTXT\u00a0\u2013 version 35 and versions prior to 2.12.1<\/li>\n\t<li>Siemens SIMATIC s7-1500 TM MFP (GNU\/Linux subsystem)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC PCS 7 V9.1\u00a0\u2013 versions prior to V9.1 SP2 UC04<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Professional V17\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Professional V18\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Professional V19\u00a0\u2013 versions prior to V19 Update 1<\/li>\n\t<li>Siemens SIMATIC WinCC V7.5\u00a0\u2013 versions prior to V7.5 SP2 Update 16<\/li>\n\t<li>Siemens SIMATIC WinCC V8.0\u00a0\u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM APE1808\u00a0\u2013 versions with Palo Alto Networks Virtual NGFW prior to V11.0.1<\/li>\n\t<li>Siemens RUGGEDCOM APE1808\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens RUGGEDCOM APE1808\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens RUGGEDCOM APE1808\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SCALANCE W1750D (JP) (6GK5750-2HX01-1AD0)\u00a0\u2013 versions prior to V8.10.0.9<\/li>\n\t<li>Siemens SCALANCE W1750D (ROW) (6GK5750-2HX01-1AA0)\u00a0\u2013 versions prior to V8.10.0.9<\/li>\n\t<li>Siemens SCALANCE W1750D (USA) (6GK5750-2HX01-1AB0)\u00a0\u2013 versions prior to V8.10.0.9<\/li>\n\t<li>Siemens Parasolid V35.1\u00a0\u2013 versions prior to V35.1.254<\/li>\n\t<li>Siemens Parasolid V36.0\u00a0\u2013 versions prior to V36.0.207<\/li>\n\t<li>Siemens Parasolid V36.1\u00a0\u2013 versions prior to V36.1.147<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V2.0 SP2<\/li>\n\t<li>Siemens TeleControl Server Basic V3\u00a0\u2013 versions prior to V3.1.2<\/li>\n\t<li>SUBNET Solutions PowerSYSTEM Server\u00a0\u2013 version 4.07.00 and prior<\/li>\n\t<li>SUBNET Solutions Substation Server 2021\u00a0\u2013 version 4.07.00 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-200","alert_type":398,"serial_number":"AV24-200","subject":"ics","moderation_state":"published","external_url":null},{"nid":5124,"title":"Red Hat security advisory (AV24-201)","uuid":"ff9106f8-7582-4d2e-9b90-b0f528eaa428","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T16:53:38Z","date_created":"2024-04-15T16:47:55Z","summary":null,"body":["<article data-history-node-id=\"5124\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-201\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-201<br \/><strong>Date: <\/strong>April 15, 2024<\/p>\n\n<p>Between April 8 and 14, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server\u00a0- AUS 7.6 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0- AUS 7.7 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:1747\">Red Hat Security Advisory\u00a0- RHSA-2024:1747<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:1746\">Red Hat Security Advisory\u00a0- RHSA-2024:1746<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-201","alert_type":396,"serial_number":"AV24-201","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5125,"title":"Ubuntu security advisory (AV24-202)","uuid":"0dc59956-b449-46cf-9ccf-2387cb2a749b","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T17:05:14Z","date_created":"2024-04-15T16:59:40Z","summary":null,"body":["<article data-history-node-id=\"5125\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-202\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-202<br \/><strong>Date: <\/strong>April 15, 2024<\/p>\n\n<p>Between April 8 and 14, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6701-4\">Ubuntu Security Notice\u00a0\u2013 USN-6701-4 <\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6726-1\">Ubuntu Security Notice\u00a0\u2013 USN-6726-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6725-1\">Ubuntu Security Notice\u00a0\u2013 USN-6725-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6724-1\">Ubuntu Security Notice\u00a0\u2013 USN-6724-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-202","alert_type":396,"serial_number":"AV24-202","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5126,"title":"Microsoft Edge security advisory (AV24-203)","uuid":"f31a5f23-4fa0-4a25-86b1-5ec1e92bbd80","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T18:43:12Z","date_created":"2024-04-15T18:22:43Z","summary":null,"body":["<article data-history-node-id=\"5126\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-203\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-203<br \/><strong>Date: <\/strong>April\u00a015, 2024<\/p>\n\n<p>On April\u00a012, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 123.0.2420.97<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-12-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-203","alert_type":396,"serial_number":"AV24-203","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5127,"title":"HPE security advisory (AV24-204)","uuid":"36b1cf59-01fe-4f61-a102-d620ffba5c23","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T18:52:08Z","date_created":"2024-04-15T18:22:44Z","summary":null,"body":["<article data-history-node-id=\"5127\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-204\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-204<br \/><strong>Date: <\/strong>April\u00a015, 2024<\/p>\n\n<p>On April\u00a014, 2024, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>HPE Compute Scale-up Server 3200\u00a0\u2013 versions prior to v1.20.128<\/li>\n\t<li>HPE Superdome Flex 280 Server\u00a0\u2013 versions prior to v1.70.14<\/li>\n\t<li>HPE Superdome Flex Server\u00a0\u2013 versions prior to v3.90.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04632en_us\">HPE Security Bulletin\u00a0- hpesbhf04632en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbhf04633en_us\">HPE Security Bulletin\u00a0- hpesbhf04633en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-204","alert_type":396,"serial_number":"AV24-204","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5128,"title":"Dell security advisory (AV24-205)","uuid":"ed3cd990-7116-4f92-9de4-226ab1ab0c83","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T19:09:41Z","date_created":"2024-04-15T18:54:21Z","summary":null,"body":["<article data-history-node-id=\"5128\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-205\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-205<br \/><strong>Date: <\/strong>April\u00a015, 2024<\/p>\n\n<p>Between April\u00a08 and 14, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell NetWorker\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Storage Resource Manager\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-205","alert_type":396,"serial_number":"AV24-205","subject":"dell","moderation_state":"published","external_url":null},{"nid":5129,"title":"[Control systems] B&R security advisory (AV24-206)","uuid":"0e54f0fd-be90-490d-b8a3-498b3c0d96d4","banner":null,"lang":"en","date_modified":"2024-04-15","date_modified_ts":"2024-04-15T19:49:09Z","date_created":"2024-04-15T19:43:29Z","summary":null,"body":["<article data-history-node-id=\"5129\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-206\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-206<br \/><strong>Date: <\/strong>April\u00a015, 2024<\/p>\n\n<p>On April\u00a011, 2024, B&amp;R published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>APC2200\u00a0\u2013 version 1.33 and prior<\/li>\n\t<li>APC3100\u00a0\u2013 version 1.43 and prior<\/li>\n\t<li>APC4100\u00a0\u2013 versions prior to 1.06<\/li>\n\t<li>APC910\u00a0\u2013 version 1.25 and prior<\/li>\n\t<li>C80\u00a0\u2013 version 1.13 and prior<\/li>\n\t<li>MPC3100\u00a0\u2013 version 1.22 and prior<\/li>\n\t<li>PPC1200\u00a0\u2013 version 1.13 and prior<\/li>\n\t<li>PPC2200\u00a0\u2013 version 1.33 and prior<\/li>\n\t<li>PPC3100\u00a0\u2013 version 1.43 and prior<\/li>\n\t<li>PPC900\u00a0\u2013 version 2.13 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA24P002_xPCs_vulnerable_to_LogoFail-bf1f2ea5.pdf\">B&amp;R Cyber Security Advisory (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-206","alert_type":398,"serial_number":"AV24-206","subject":"br-automation","moderation_state":"published","external_url":null},{"nid":5130,"title":"Juniper security advisory (AV24-207)","uuid":"c02c5d28-1f50-4997-9b24-72644cdd9990","banner":null,"lang":"en","date_modified":"2024-04-16","date_modified_ts":"2024-04-16T17:30:14Z","date_created":"2024-04-16T15:58:12Z","summary":null,"body":["<article data-history-node-id=\"5130\" about=\"\/en\/alerts-advisories\/juniper-security-advisory-av24-207\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-207<br \/><strong>Date: <\/strong>April\u00a016, 2024<\/p>\n\n<p>On April\u00a010, 2024, Juniper published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>cRPD\u00a0\u2013 versions prior to 23.4R1<\/li>\n\t<li>Juniper Cloud Native Router\u00a0\u2013 versions prior to 23.4<\/li>\n\t<li>Junos OS\u00a0\u2013 versions prior to 23.4R1-S1, 23.4R2 and 2R1<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]\">Juniper Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-advisory-av24-207","alert_type":396,"serial_number":"AV24-207","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5131,"title":"PuTTY security advisory (AV24-208)","uuid":"75f5fe53-3e38-402c-958c-de20346bf0f5","banner":null,"lang":"en","date_modified":"2024-04-16","date_modified_ts":"2024-04-16T17:42:04Z","date_created":"2024-04-16T15:58:13Z","summary":null,"body":["<article data-history-node-id=\"5131\" about=\"\/en\/alerts-advisories\/putty-security-advisory-av24-208\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-208<br \/><strong>Date: <\/strong>April\u00a016, 2024<\/p>\n\n<p>On April\u00a015, 2024, PuTTY published an update to address a vulnerability in the following product:<\/p>\n\n<ul><li>PuTTY\u00a0\u2013 version 0.68 to 0.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.chiark.greenend.org.uk\/~sgtatham\/putty\/wishlist\/vuln-p521-bias.html\">PuTTY vulnerability vuln-p521-bias<\/a><\/li>\n\t<li><a href=\"https:\/\/www.chiark.greenend.org.uk\/~sgtatham\/putty\/latest.html\">Download PuTTY: latest release (0.81)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/putty-security-advisory-av24-208","alert_type":396,"serial_number":"AV24-208","subject":"other","moderation_state":"published","external_url":null},{"nid":5132,"title":"Mozilla security advisory (AV24-209)","uuid":"dfc35416-8840-4dee-9c31-210ea95c135a","banner":null,"lang":"en","date_modified":"2024-04-16","date_modified_ts":"2024-04-16T17:49:19Z","date_created":"2024-04-16T17:43:25Z","summary":null,"body":["<article data-history-node-id=\"5132\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-209\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-209<br \/><strong>Date: <\/strong>April\u00a016, 2024<\/p>\n\n<p>On April\u00a016, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 125<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-18\/\">Mozilla Security Advisory\u00a0- MFSA 2024-18<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-19\/\">Mozilla Security Advisory\u00a0- MFSA 2024-19<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-209","alert_type":396,"serial_number":"AV24-209","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5133,"title":"Google Chrome security advisory (AV24-212)","uuid":"a0e7d3d2-cf9a-41b9-ad7d-b82de7c36fba","banner":null,"lang":"en","date_modified":"2024-04-17","date_modified_ts":"2024-04-17T13:54:29Z","date_created":"2024-04-17T13:48:38Z","summary":null,"body":["<article data-history-node-id=\"5133\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-212\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-212<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 17, 2024<\/p>\n\n<p>On April 16, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.60\/.61 (Windows and Mac) and 124.0.6367.60 (Linux)<\/li>\n\t<li>Extended Stable channel Chrome for Desktop\u00a0\u2013 versions prior to 14.0.6367.60\/.61 (Windows and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/04\/stable-channel-update-for-desktop_16.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-212","alert_type":396,"serial_number":"AV24-212","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5134,"title":"Oracle security advisory \u2013 April 2024 quarterly rollup (AV24-210)","uuid":"6513fb50-f1f3-4817-a192-ca2f73889948","banner":null,"lang":"en","date_modified":"2024-04-17","date_modified_ts":"2024-04-17T12:00:00Z","date_created":"2024-04-17T14:28:58Z","summary":null,"body":["<article data-history-node-id=\"5134\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-april-2024-quarterly-rollup-av24-210\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-210<br \/><strong>Date: <\/strong>April\u00a017, 2024<\/p>\n\n<p>On April\u00a016, 2024, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Commerce<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle E-Business Suite<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Food and Beverage<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle HealthCare Applications<\/li>\n\t<li>Oracle Insurance Applications<\/li>\n\t<li>Oracle PeopleSoft<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Systems<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2024.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 April 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-april-2024-quarterly-rollup-av24-210","alert_type":396,"serial_number":"AV24-210","subject":"oracle","moderation_state":"published","external_url":null},{"nid":5135,"title":"Atlassian security advisory (AV24-211)","uuid":"401f405f-c709-4156-928d-011c7528e60d","banner":null,"lang":"en","date_modified":"2024-04-17","date_modified_ts":"2024-04-17T12:10:00Z","date_created":"2024-04-17T14:28:59Z","summary":null,"body":["<article data-history-node-id=\"5135\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-211\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-211<br \/><strong>Date: <\/strong>April\u00a017, 2024<\/p>\n\n<p>On April\u00a016, 2024, Atlassian published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Bamboo Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Software Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Software Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-april-16-2024-1387857429.html\">Atlassian April 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/data-protection\/vulnerabilities\">Security at Atlassian: Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-211","alert_type":396,"serial_number":"AV24-211","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5136,"title":"Cisco security advisory (AV24-213)","uuid":"f4f4120a-36b8-47d5-add6-60df07c32ca8","banner":null,"lang":"en","date_modified":"2024-04-17","date_modified_ts":"2024-04-17T18:10:23Z","date_created":"2024-04-17T17:58:11Z","summary":null,"body":["<article data-history-node-id=\"5136\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-213\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-213<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 17, 2024<\/p>\n\n<p>On April 17, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Integrated Management Controller (IMC)\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cimc-cmd-inj-bLuPcb\">Cisco Security Advisory\u00a0\u2013 cisco-sa-cimc-cmd-inj-bLuPcb<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cimc-cmd-inj-mUx4c5AJ\">Cisco Security Advisory\u00a0\u2013 cisco-sa-cimc-cmd-inj-mUx4c5AJ<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-213","alert_type":396,"serial_number":"AV24-213","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5137,"title":"Microsoft Edge security advisory (AV24-214)","uuid":"43599482-95e9-43fa-8573-3690ce213687","banner":null,"lang":"en","date_modified":"2024-04-19","date_modified_ts":"2024-04-19T15:08:14Z","date_created":"2024-04-19T14:08:48Z","summary":null,"body":["<article data-history-node-id=\"5137\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-214\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-214<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 19, 2024<\/p>\n\n<p>On April 18, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 0.2478.51<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-18-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-214","alert_type":396,"serial_number":"AV24-214","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5138,"title":"Ivanti security advisory (AV24-215)","uuid":"cfafaec9-1f26-4497-9167-949b5c82d8ec","banner":null,"lang":"en","date_modified":"2024-04-19","date_modified_ts":"2024-04-19T15:20:49Z","date_created":"2024-04-19T15:12:44Z","summary":null,"body":["<article data-history-node-id=\"5138\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-215\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-215<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 19, 2024<\/p>\n\n<p>On April 19, 2024, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Avalanche\u00a0\u2013 versions prior to 6.4.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US\">Avalanche 6.4.3 Security Hardening and CVEs addressed<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-215","alert_type":396,"serial_number":"AV24-215","subject":"other","moderation_state":"published","external_url":null},{"nid":5140,"title":"[Control systems] CISA ICS security advisories (AV24-216)","uuid":"228bc1a0-3f4d-4ed7-a100-96665b1bb4b3","banner":null,"lang":"en","date_modified":"2024-04-22","date_modified_ts":"2024-04-22T14:45:34Z","date_created":"2024-04-22T14:09:33Z","summary":null,"body":["<article data-history-node-id=\"5140\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-216\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-216<br \/><strong>Date: <\/strong>April\u00a022, 2024<\/p>\n\n<p>Between April\u00a015 and April\u00a021, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Electrolink FM\/DAB\/TV Transmitter\u00a0\u2013 multiple versions<\/li>\n\t<li>Measuresoft ScadaPro\u00a0\u2013 version 6.9.0.0<\/li>\n\t<li>RoboDK\u00a0\u2013 version v5.5.4 (Windows 64 bit)<\/li>\n\t<li>Rockwell Automation ControlLogix 5580\u00a0\u2013 version V35.011<\/li>\n\t<li>Rockwell Automation GuardLogix 5580\u00a0\u2013 version V35.011<\/li>\n\t<li>Rockwell Automation CompactLogix 5380\u00a0\u2013 version V35.011<\/li>\n\t<li>Rockwell Automation 1756-EN4TR\u00a0\u2013 version V5.001<\/li>\n\t<li>Unitronics Vision series PLCs\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-216","alert_type":398,"serial_number":"AV24-216","subject":"ics","moderation_state":"published","external_url":null},{"nid":5141,"title":"IBM security advisory (AV24-218)","uuid":"b670cdc5-99cf-414d-94be-711b8b19013e","banner":null,"lang":"en","date_modified":"2024-04-22","date_modified_ts":"2024-04-22T19:13:14Z","date_created":"2024-04-22T19:00:47Z","summary":null,"body":["<article data-history-node-id=\"5141\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-218\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-218<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 22, 2024<\/p>\n\n<p>Between April 15 and 21, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Edge Application Manager\u00a0\u2013 versions 4.4 and 4.5<\/li>\n\t<li>IBM Db2 and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 versions prior to v4.8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7148864\">IBM Security Bulletin\u00a0\u2013 7148864<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7148847\">IBM Security Bulletin\u00a0\u2013 7148847<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-218","alert_type":396,"serial_number":"AV24-218","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5142,"title":"Red Hat security advisory (AV24-217)","uuid":"33e91b5b-711c-4936-b1bb-8bab40d06248","banner":null,"lang":"en","date_modified":"2024-04-22","date_modified_ts":"2024-04-22T17:32:34Z","date_created":"2024-04-22T19:26:32Z","summary":null,"body":["<article data-history-node-id=\"5142\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-217\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-217<br \/><strong>Date: <\/strong>April\u00a022, 2024<\/p>\n\n<p>Between April\u00a015 and 21, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host 4 for RHEL 8 x86_64\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-217","alert_type":396,"serial_number":"AV24-217","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5143,"title":"Ubuntu security advisory (AV24-219)","uuid":"8fac9884-9b2c-4d0a-aae6-eb961bdabfbc","banner":null,"lang":"en","date_modified":"2024-04-22","date_modified_ts":"2024-04-22T19:44:19Z","date_created":"2024-04-22T19:37:58Z","summary":null,"body":["<article data-history-node-id=\"5143\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-219\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-219<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 22, 2024<\/p>\n\n<p>Between April 15 and 21, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-219","alert_type":396,"serial_number":"AV24-219","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5145,"title":"Dell security advisory (AV24-220)","uuid":"bc7bb8fb-74de-4bab-acd8-6b09899ab969","banner":null,"lang":"en","date_modified":"2024-04-23","date_modified_ts":"2024-04-23T14:10:24Z","date_created":"2024-04-23T13:19:16Z","summary":null,"body":["<article data-history-node-id=\"5145\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-220\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-220<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 23, 2024<\/p>\n\n<p>Between April 15 and 21, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell custom VMware ESXi\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell EMC VxRail Appliance\u00a0\u2013 8.0.x versions prior to 8.0.211<\/li>\n\t<li>Dell SmartFabric OS10\u00a0\u2013 version 10.5.5.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000224179\/dsa-2024-182-security-update-for-dell-custom-vmware-esxi-vulnerabilities\">Dell Security Update (Dell custom VMware ESXi)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000224302\/dsa-2024-178-security-update-for-dell-vxrail-8-0-211-multiple-third-party-component-vulnerabilities\">Dell Security Update (Dell EMC VxRail Appliance)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000224301\/dsa-2024-185-security-update-for-dell-os10-third-party-vulnerabilities\">Dell Security Update (Dell SmartFabric OS10)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-220","alert_type":396,"serial_number":"AV24-220","subject":"dell","moderation_state":"published","external_url":null},{"nid":5148,"title":"Google Chrome security advisory (AV24-222)","uuid":"c36633fc-13eb-4165-94d2-3f6f75e91972","banner":null,"lang":"en","date_modified":"2024-04-24","date_modified_ts":"2024-04-24T16:29:49Z","date_created":"2024-04-24T16:23:48Z","summary":null,"body":["<article data-history-node-id=\"5148\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-222\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-222<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 24, 2024<\/p>\n\n<p>On April 24, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.78\/.79 (Windows and Mac) and 124.0.6367.78 (Linux)<\/li>\n\t<li>Extended Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.78\/.79 (Windows and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/04\/stable-channel-update-for-desktop_24.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-222","alert_type":396,"serial_number":"AV24-222","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5149,"title":"CrushFTP security advisory (AV24-221)","uuid":"26b7921e-14bd-499d-aab6-624e1cc1d3ad","banner":null,"lang":"en","date_modified":"2024-04-24","date_modified_ts":"2024-04-24T16:19:36Z","date_created":"2024-04-24T17:18:34Z","summary":null,"body":["<article data-history-node-id=\"5149\" about=\"\/en\/alerts-advisories\/crushftp-security-advisory-av24-221\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-221<br \/><strong>Date: <\/strong>April\u00a024, 2024<\/p>\n\n<p>On April\u00a019, 2024, CrushFTP published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>CrushFTP\u00a0\u2013 versions prior to 10.7.1 and 11.x versions prior to 11.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.crushftp.com\/crush11wiki\/Wiki.jsp?page=Update\">CrushFTP Update<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/crushftp-security-advisory-av24-221","alert_type":396,"serial_number":"AV24-221","subject":"other","moderation_state":"published","external_url":null},{"nid":5150,"title":"Cyber activity impacting CISCO ASA devices","uuid":"dfc68aad-90be-4b2f-a02b-b034567ab80f","banner":null,"lang":"en","date_modified":"2024-04-24","date_modified_ts":"2024-04-24T18:13:06Z","date_created":"2024-04-24T18:12:15Z","summary":null,"body":["<article data-history-node-id=\"5150\" about=\"\/en\/alerts-advisories\/cyber-activity-impacting-cisco-asa-devices\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL24-006<br \/><strong>Date: <\/strong>April 24,\u00a02024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On April 24, 2024, the Canadian Centre for Cyber Security (Cyber Centre), Australian Signals Directorate's Australian Cyber Security Centre and The UK's National Cyber Security Centre (NCSC) released a joint Cyber Security Advisory<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> to bring awareness of newly published information by Cisco on the vulnerabilities exploited in recent incidents worldwide.<\/p>\n\n<p>On the same day, Cisco Talos published a blog post<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> containing the latest technical details of these vulnerabilities affecting Cisco ASA devices, as well as information on two additional newly discovered vulnerabilities (CVE-2024-20353<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> and CVE-2024-20359<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>) leveraged during these incidents.<\/p>\n\n<p>Please refer to these documents for additional details and recommendations.<\/p>\n<\/section><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <em>Official Languages Act<\/em> is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/news-events\/cyber-activity-impacting-cisco-asa-vpns\">Cyber Centre\u2019s joint cyber security advisory CSA24-001<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1a-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/blog.talosintelligence.com\/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices\/\">Cisco Talos blog post<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-websrvs-dos-X8gNucD2\">Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability (CVE-2024-20353)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-persist-rce-FLsNXF4h\">Cisco Adaptive Security Appliance and Firepower Threat Defense Software Persistent Local Code Execution Vulnerability (CVE-2024-20359)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cyber-activity-impacting-cisco-asa-devices","alert_type":397,"serial_number":"AL24-006","subject":"other","moderation_state":"published","external_url":null},{"nid":5151,"title":"Cisco security advisory (AV24-223)","uuid":"12221d7c-a429-4fbf-a292-0fe696f3ce80","banner":null,"lang":"en","date_modified":"2024-04-24","date_modified_ts":"2024-04-24T19:05:09Z","date_created":"2024-04-24T18:29:11Z","summary":null,"body":["<article data-history-node-id=\"5151\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-223\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-223<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 24, 2024<\/p>\n\n<p>On April 24, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Adaptive Security (ASA) Software\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Firepower Threat Defense (FTD) Software\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cyber.gc.ca\/en\/news-events\/cyber-activity-impacting-cisco-asa-vpns\">Cyber Activity Impacting CISCO ASA VPNs<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-websrvs-dos-X8gNucD2\">Cisco Security Advisory\u00a0\u2013 cisco-sa-asaftd-websrvs-dos-X8gNucD2 <\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-persist-rce-FLsNXF4h\">Cisco Security Advisory\u00a0\u2013 cisco-sa-asaftd-persist-rce-FLsNXF4h<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-223","alert_type":396,"serial_number":"AV24-233","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5152,"title":"Drupal security advisory (AV24-224)","uuid":"ec0498d7-9546-474d-beb2-c1fc13d1c0d3","banner":null,"lang":"en","date_modified":"2024-04-25","date_modified_ts":"2024-04-25T13:26:19Z","date_created":"2024-04-25T13:16:59Z","summary":null,"body":["<article data-history-node-id=\"5152\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-224\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-224<br \/><strong>Date: <\/strong>April 25, 2024<\/p>\n\n<p>On April 24, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>Advanced Progressive Web Applications (PWA) \u2013 versions prior to 8.x-1.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-017\">Drupal Security Advisory - SA-CONTRIB-2024-017<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-\n--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-224","alert_type":396,"serial_number":"AV24-224","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5154,"title":"Mitel security advisory (AV24-226)","uuid":"d970652b-7768-4e07-9063-827d5b582c47","banner":null,"lang":"en","date_modified":"2024-04-25","date_modified_ts":"2024-04-25T15:17:32Z","date_created":"2024-04-25T14:53:17Z","summary":null,"body":["<article data-history-node-id=\"5154\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-226\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-226<br \/><strong>Date: <\/strong>April\u00a025, 2024<\/p>\n\n<p>On April\u00a024, 2024, Mitel published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MiContact Center Business\u00a0\u2013 version 10.0.0.4 Hotfix KB560110 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-ca\/support\/security-advisories\/mitel-product-security-advisory-24-0011\">Mitel Security Advisory\u00a0- 24-0011<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-ca\/support\/security-advisories\/mitel-product-security-advisory-24-0012\">Mitel Security Advisory\u00a0- 24-0012<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-226","alert_type":396,"serial_number":"AV24-226","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5153,"title":"HPE security advisory (AV24-225)","uuid":"377e8942-d662-4969-a478-3a8b2fed3357","banner":null,"lang":"en","date_modified":"2024-04-25","date_modified_ts":"2024-04-25T15:08:13Z","date_created":"2024-04-25T14:53:18Z","summary":null,"body":["<article data-history-node-id=\"5153\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-225\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-225<br \/><strong>Date: <\/strong>April\u00a025, 2024<\/p>\n\n<p>On April\u00a025, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE SAN Switches with Brocade Fabric OS (FOS)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04635en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbst04635en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-225","alert_type":396,"serial_number":"AV24-225","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5155,"title":"Ubuntu security advisory (AV24-227)","uuid":"fb3e4e58-4c30-4674-920e-42ee2cf5a735","banner":null,"lang":"en","date_modified":"2024-04-29","date_modified_ts":"2024-04-29T17:06:56Z","date_created":"2024-04-29T15:46:07Z","summary":null,"body":["<article data-history-node-id=\"5155\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-227\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-227<br \/><strong>Date: <\/strong>April\u00a029, 2024<\/p>\n\n<p>Between April\u00a022 and 28, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6742-2\">Ubuntu Security Notice\u00a0\u2013 USN-6742-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6743-3\">Ubuntu Security Notice\u00a0\u2013 USN-6743-3<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6743-2\">Ubuntu Security Notice\u00a0\u2013 USN-6743-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-227","alert_type":396,"serial_number":"AV24-227","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5156,"title":"Dell security advisory (AV24-228)","uuid":"11ba991d-a79a-4cb5-9216-0f6995e7e1a8","banner":null,"lang":"en","date_modified":"2024-04-29","date_modified_ts":"2024-04-29T17:14:09Z","date_created":"2024-04-29T15:46:08Z","summary":null,"body":["<article data-history-node-id=\"5156\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-228\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-228<br \/><strong>Date: <\/strong>April\u00a029, 2024<\/p>\n\n<p>Between April\u00a022 and 28, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Dell Object Scale\u00a0\u2013 versions prior to 1.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000224456\/dsa-2024-119-dell-objectscale-1-4-0-security-update-for-multiple-third-party-vulnerabilities\">Dell Security Update\u00a0\u2013 Dell ObjectScale<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-228","alert_type":396,"serial_number":"AV24-228","subject":"dell","moderation_state":"published","external_url":null},{"nid":5157,"title":"IBM security advisory (AV24-229)","uuid":"4ee86443-6fb5-425d-80d0-98b7891d4cbf","banner":null,"lang":"en","date_modified":"2024-04-29","date_modified_ts":"2024-04-29T17:25:43Z","date_created":"2024-04-29T15:46:08Z","summary":null,"body":["<article data-history-node-id=\"5157\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-229\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-229<br \/><strong>Date: <\/strong>April\u00a029, 2024<\/p>\n\n<p>Between April\u00a022 and 28, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Administration Runtime Expert for i\u00a0\u2013 version 7.2, 7.3, 7.4 and 7.5<\/li>\n\t<li>IBM Cloud Pak for Network Automation\u00a0\u2013 version 2.7.1<\/li>\n\t<li>IBM Cloud Pak for AIOps\u00a0\u2013 version 4.1.0 to 4.5.0<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager Container\u00a0\u2013 version 10.0.2<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager software component\u00a0\u2013 version 10.0.2<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager virtual appliance component\u00a0\u2013 version 10.0.2<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 4.8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-229","alert_type":396,"serial_number":"AV24-229","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5158,"title":"[Control systems] CISA ICS security advisories (AV24-230)","uuid":"ea8b69a7-6782-4101-814f-2420b4ab6fbb","banner":null,"lang":"en","date_modified":"2024-04-29","date_modified_ts":"2024-04-29T20:02:58Z","date_created":"2024-04-29T19:28:44Z","summary":null,"body":["<article data-history-node-id=\"5158\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-230\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-230\n  <br \/><strong>Date: <\/strong>April\u00a029, 2024\n<\/p>\n<p>Between April\u00a022 and April\u00a028, 2024, CISA published ICS advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Hitachi Energy RTU500 series CMU Firmware\u00a0\u2013 multiple versions<\/li>\n  <li>Hitachi Energy MACH SCM\u00a0\u2013 multiple versions<\/li>\n  <li>Siemens RUGGEDCOM APE1808\u00a0\u2013 all versions<\/li>\n  <li>Honeywell Experion PKS\u00a0\u2013 multiple versions<\/li>\n  <li>Honeywell Experion LX\u00a0\u2013 multiple versions<\/li>\n  <li>Honeywell PlantCruise by Experion\u00a0\u2013 multiple versions<\/li>\n  <li>Honeywell Safety Manager\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-230","alert_type":398,"serial_number":"AV24-230","subject":"ics","moderation_state":"published","external_url":null},{"nid":5159,"title":"Microsoft Edge security advisory (AV24-231)","uuid":"40150f41-eed4-4e6b-9fa0-83f553f9097f","banner":null,"lang":"en","date_modified":"2024-04-29","date_modified_ts":"2024-04-29T20:18:06Z","date_created":"2024-04-29T19:28:45Z","summary":null,"body":["<article data-history-node-id=\"5159\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-231\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-231<br \/><strong>Date: <\/strong>April\u00a029, 2024<\/p>\n\n<p>On April\u00a026, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 124.0.2478.67<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-26-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-231","alert_type":396,"serial_number":"AV24-231","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5160,"title":"HPE security advisory (AV24-232)","uuid":"b4a7190e-0483-4564-825c-97bafda7697f","banner":null,"lang":"en","date_modified":"2024-04-30","date_modified_ts":"2024-04-30T20:28:23Z","date_created":"2024-04-30T20:24:32Z","summary":null,"body":["<article data-history-node-id=\"5160\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-232\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-232<br \/><strong>Date: <\/strong>April\u00a030, 2024<\/p>\n\n<p>On April\u00a030, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE OneView\u00a0\u2013 versions prior to 8.90<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04639en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbst04639en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-232","alert_type":396,"serial_number":"AV24-232","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5161,"title":"SonicWall security advisory (AV24-233)","uuid":"ec9327d5-600f-4384-ab43-b4cd6c4dd3e3","banner":null,"lang":"en","date_modified":"2024-04-30","date_modified_ts":"2024-04-30T20:34:22Z","date_created":"2024-04-30T20:28:56Z","summary":null,"body":["<article data-history-node-id=\"5161\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-233\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-233<br \/><strong>Date: <\/strong>April\u00a030, 2024<\/p>\n\n<p>On April\u00a030, 2024, SonicWall published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SonicWall GMS (Virtual Appliance, Windows)\u00a0\u2013 version 9.3.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2024-0007\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2024-0007<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-233","alert_type":396,"serial_number":"AV24-233","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":5163,"title":"Google Chrome security advisory (AV24-234)","uuid":"fe179f52-1ee9-44ce-9b7f-91bb921c3b76","banner":null,"lang":"en","date_modified":"2024-05-01","date_modified_ts":"2024-05-01T14:14:49Z","date_created":"2024-05-01T14:10:33Z","summary":null,"body":["<article data-history-node-id=\"5163\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-234\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-234<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 1, 2024<\/p>\n\n<p>On April 30, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.118\/.119 (Windows and Mac) and 124.0.6367.118 (Linux)<\/li>\n\t<li>Extended Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.118 (Windows and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/04\/stable-channel-update-for-desktop_30.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-234","alert_type":396,"serial_number":"AV24-234","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5164,"title":"HPE security advisory (AV24-235)","uuid":"3faf73f5-03bf-41b5-8ac1-02d144ccd0b7","banner":null,"lang":"en","date_modified":"2024-05-01","date_modified_ts":"2024-05-01T14:19:42Z","date_created":"2024-05-01T14:16:26Z","summary":null,"body":["<article data-history-node-id=\"5164\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-235\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-235<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 1, 2024<\/p>\n\n<p>On May 1, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking ArubaOS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04640en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbst04640en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US \">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-235","alert_type":396,"serial_number":"AV24-235","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5166,"title":"Cisco security advisory (AV24-236)","uuid":"9186c7ea-e5f9-4149-9751-890dc8ca88dd","banner":null,"lang":"en","date_modified":"2024-05-01","date_modified_ts":"2024-05-01T17:23:34Z","date_created":"2024-05-01T17:18:28Z","summary":null,"body":["<article data-history-node-id=\"5166\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-236\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-236<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 1, 2024<\/p>\n\n<p>On May 1, 2024, Cisco published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco IP Phone 6800 Series with Multiplatform Firmware\u00a0\u2013 version 12.0.4 and prior<\/li>\n\t<li>Cisco IP Phone 7800 Series with Multiplatform Firmware\u00a0\u2013 version 12.0.4 and prior<\/li>\n\t<li>Cisco IP Phone 8800 Series with Multiplatform Firmware\u00a0\u2013 version 12.0.4 and prior<\/li>\n\t<li>Cisco Video Phone 8875 in Multiplatform Mode\u00a0\u2013 version 2.3.1.001 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ipphone-multi-vulns-cXAhCvS\">Cisco Security Advisory\u00a0\u2013 cisco-sa-ipphone-multi-vulns-cXAhCvS<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x \">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-236","alert_type":396,"serial_number":"AV24-236","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5167,"title":"Microsoft Edge security advisory (AV24-237)","uuid":"a0bdc561-5776-4ef7-9288-82d9e0481c3e","banner":null,"lang":"en","date_modified":"2024-05-03","date_modified_ts":"2024-05-03T14:59:12Z","date_created":"2024-05-03T14:38:57Z","summary":null,"body":["<article data-history-node-id=\"5167\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-237\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-237<br \/><strong>Date: <\/strong>May\u00a03, 2024<\/p>\n\n<p>On May\u00a02, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 124.0.2478.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-2-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-237","alert_type":396,"serial_number":"AV24-237","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5168,"title":"Dell security advisory (AV24-238)","uuid":"3479ba04-f68b-4f84-8cf1-bf094c53b376","banner":null,"lang":"en","date_modified":"2024-05-06","date_modified_ts":"2024-05-06T19:23:53Z","date_created":"2024-05-06T19:01:35Z","summary":null,"body":["<article data-history-node-id=\"5168\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-238\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-238<br \/><strong>Date: <\/strong>May\u00a06, 2024<\/p>\n\n<p>Between April\u00a029 and May\u00a05, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Dell PowerProtect DD2200 appliance\u00a0\u2013 versions prior to 6.2.1.110<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000224649\/dsa-2024-186-dell-technologies-powerprotect-dd-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Update (Dell PowerProtect DD2200 appliance)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-238","alert_type":396,"serial_number":"AV24-238","subject":"dell","moderation_state":"published","external_url":null},{"nid":5169,"title":"IBM security advisory (AV24-239)","uuid":"18aa6e3d-95e5-4d5a-bccc-83dac55067b1","banner":null,"lang":"en","date_modified":"2024-05-06","date_modified_ts":"2024-05-06T19:33:24Z","date_created":"2024-05-06T19:01:35Z","summary":null,"body":["<article data-history-node-id=\"5169\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-239\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-239<br \/><strong>Date: <\/strong>May\u00a06, 2024<\/p>\n\n<p>Between April\u00a029 and May\u00a05, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Business Automation Manager Open Editions\u00a0\u2013 versions 8.0.4 and 8.0.4-IF001<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Controller\u00a0\u2013 versions 10.4.1, 10.4.2 and 11.0.0<\/li>\n\t<li>IBM Planning Analytics\u00a0\u2013 versions 2.0 and 2.1<\/li>\n\t<li>IBM QRadar SIEM (On Azure Marketplace)\u00a0\u2013 version 7.3.3 to 7.5.0<\/li>\n\t<li>IBM Spectrum Discover\u00a0\u2013 versions 2.1.0, 2.1.1, 2.1.2, 2.1.3 and 2.1.4<\/li>\n\t<li>IBM Storage Copy Data Management\u00a0\u2013 version 2.2.0.0 to 2.2.23.0<\/li>\n\t<li>IBM Storage Scale\u00a0\u2013 version 5.1.0.0 to 5.1.9.2<\/li>\n\t<li>IBM Storage Scale System\u00a0\u2013 versions 6.1.0.0 to 6.1.2.8 and 6.1.3.0 to 6.1.9.1<\/li>\n\t<li>Watson Discovery\u00a0\u2013 version 4.0.0 to 4.8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-239","alert_type":396,"serial_number":"AV24-239","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5170,"title":"[Control systems] CISA ICS security advisories (AV24-240)","uuid":"53b0c6a0-23d7-46de-b44b-28292f6af2dc","banner":null,"lang":"en","date_modified":"2024-05-06","date_modified_ts":"2024-05-06T19:38:53Z","date_created":"2024-05-06T19:01:35Z","summary":null,"body":["<article data-history-node-id=\"5170\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-240\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-240<br \/><strong>Date: <\/strong>May\u00a06, 2024<\/p>\n\n<p>Between April\u00a029 and May\u00a05, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CyberPower PowerPanel\u00a0\u2013 version 4.9.0 and prior<\/li>\n\t<li>Delta Electronics CNCSoft-G2\u00a0\u2013 version 2.0.0.5 (with DOPSoft v5.0.0.93) and prior<\/li>\n\t<li>Delta Electronics DIAEnergie\u00a0\u2013 versions v1.10.00.005<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-123-01\">CISA ICS Advisory\u00a0\u2013 ICSA-24-123-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-121-01\">CISA ICS Advisory\u00a0\u2013 ICSA-24-121-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-123-02\">CISA ICS Advisory\u00a0\u2013 ICSA-24-123-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-240","alert_type":398,"serial_number":"AV24-240","subject":"ics","moderation_state":"published","external_url":null},{"nid":5171,"title":"Red Hat security advisory (AV24-241)","uuid":"1d00ad41-bcf1-47dc-a1b4-f05fc18e993a","banner":null,"lang":"en","date_modified":"2024-05-06","date_modified_ts":"2024-05-06T20:03:29Z","date_created":"2024-05-06T19:13:15Z","summary":null,"body":["<article data-history-node-id=\"5171\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-241\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-241<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 6, 2024<\/p>\n\n<p>Between April 29 and May 5, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host 4 for RHEL 8 x86_64\u00a0\u2013 multiple versions<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-241","alert_type":396,"serial_number":"AV24-241","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5172,"title":"Ubuntu security advisory (AV24-242)","uuid":"12c872ca-c841-42a4-8952-0104533698b1","banner":null,"lang":"en","date_modified":"2024-05-06","date_modified_ts":"2024-05-06T20:20:54Z","date_created":"2024-05-06T19:13:15Z","summary":null,"body":["<article data-history-node-id=\"5172\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-242\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-242<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 6, 2024<\/p>\n\n<p>Between April 29 and May 5, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0103-1\">Ubuntu Security Notice\u00a0- LSN-0103-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-242","alert_type":396,"serial_number":"AV24-242","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5173,"title":"Android security advisory \u2013 May 2024 Monthly Rollup (AV24-243)","uuid":"d1f16f99-34aa-4022-aebd-f4d0f35f08b6","banner":null,"lang":"en","date_modified":"2024-05-06","date_modified_ts":"2024-05-06T20:21:46Z","date_created":"2024-05-06T19:13:15Z","summary":null,"body":["<article data-history-node-id=\"5173\" about=\"\/en\/alerts-advisories\/android-security-advisory-may-2024-monthly-rollup-av24-243\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-243<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 6, 2024<\/p>\n\n<p>On May 6, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-05-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-may-2024-monthly-rollup-av24-243","alert_type":396,"serial_number":"AV24-243","subject":"android","moderation_state":"published","external_url":null},{"nid":5174,"title":"Google Chrome security advisory (AV24-244)","uuid":"faf40fd0-929b-4df3-96e2-9668277a1346","banner":null,"lang":"en","date_modified":"2024-05-07","date_modified_ts":"2024-05-07T19:39:30Z","date_created":"2024-05-07T19:26:04Z","summary":null,"body":["<article data-history-node-id=\"5174\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-244\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-244<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 7, 2024<\/p>\n\n<p>On May 7, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.155\/.156 (Windows and Mac) and 124.0.6367.155 (Linux)<\/li>\n\t<li>Extended Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.155 (Windows and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/05\/stable-channel-update-for-desktop_7.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-244","alert_type":396,"serial_number":"AV24-244","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5176,"title":"Tinyproxy security advisory (AV24-245)","uuid":"46fd5adb-5d7c-4512-ac72-048d54cf3589","banner":null,"lang":"en","date_modified":"2024-05-08","date_modified_ts":"2024-05-08T14:31:59Z","date_created":"2024-05-08T14:00:31Z","summary":null,"body":["<article data-history-node-id=\"5176\" about=\"\/en\/alerts-advisories\/tinyproxy-security-advisory-av24-245\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-245<br \/><strong>Date: <\/strong>May\u00a08, 2024<\/p>\n\n<p>On May\u00a01, 2024, Talos published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Tinyproxy\u00a0\u2013 versions 1.11.1 and 1.10.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/talosintelligence.com\/vulnerability_reports\/TALOS-2023-1889\">Talos vulnerability report\u00a0- TALOS-2023-1889<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/tinyproxy\/tinyproxy\/issues\/533\">Some details about CVE-2023-49606 #533<\/a><\/li>\n\t<li><a href=\"https:\/\/tinyproxy.github.io\/\">Tinyproxy<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tinyproxy-security-advisory-av24-245","alert_type":396,"serial_number":"AV24-245","subject":"other","moderation_state":"published","external_url":null},{"nid":5178,"title":"Apple security advisory (AV24-247)","uuid":"21f42a4e-d436-4218-a660-27c2c5f0a2b2","banner":null,"lang":"en","date_modified":"2024-05-08","date_modified_ts":"2024-05-08T20:12:06Z","date_created":"2024-05-08T19:21:17Z","summary":null,"body":["<article data-history-node-id=\"5178\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-247\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-247<br \/><strong>Date: <\/strong>May\u00a08, 2024<\/p>\n\n<p>On May\u00a08, 2024, Apple published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Apple iTunes\u00a0\u2013 version 12.13.2 for Windows 10 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT214099\">Apple Security Update\u00a0- HT214099<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-247","alert_type":396,"serial_number":"AV24-247","subject":"apple","moderation_state":"published","external_url":null},{"nid":5177,"title":"Citrix security advisory (AV24-246)","uuid":"ef703871-c016-49b7-8cfa-f62c82024b71","banner":null,"lang":"en","date_modified":"2024-05-08","date_modified_ts":"2024-05-08T19:37:11Z","date_created":"2024-05-08T19:31:25Z","summary":null,"body":["<article data-history-node-id=\"5177\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av24-246\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-246<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 8, 2024<\/p>\n\n<p>On May 8, 2024, Citrix published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>XenCenter for Citrix Hypervisor\u00a0\u2013 version 8.2 CU1 LTSR<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX633416\/citrix-hypervisor-security-update-for-cve202431497\">Citrix Security Advisory\u00a0\u2013 CTX633416<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av24-246","alert_type":396,"serial_number":"AV24-246","subject":"citrix","moderation_state":"published","external_url":null},{"nid":5179,"title":"F5 security advisory (AV24-248)","uuid":"c0750870-5eba-488c-a8b1-9841e541b424","banner":null,"lang":"en","date_modified":"2024-05-10","date_modified_ts":"2024-05-10T13:09:48Z","date_created":"2024-05-10T12:58:33Z","summary":null,"body":["<article data-history-node-id=\"5179\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av24-248\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-248\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 10, 2024\n<\/p>\n<p>On May 8, 2024, F5 published security updates for multiple products. Included were updates for the following:\n<\/p>\n<ul><li>BIG-IP (all modules)\u00a0\u2013 multiple versions and models<\/li>\n  <li>BIG-IP Next Central Manager\u00a0\u2013 multiple versions and models<\/li>\n  <li>BIG-IP (AFM)\u00a0\u2013 multiple versions and models<\/li>\n  <li>BIG-IP Next CN\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>Open-source reporting has indicated that proof-of-concept exploit code is available for some of these vulnerabilities.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000139404\">F5 Quarterly Security Notification (May 2024)<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av24-248","alert_type":396,"serial_number":"AV24-248","subject":"f5","moderation_state":"published","external_url":null},{"nid":5180,"title":"Google Chrome security advisory (AV24-249)","uuid":"8a07409b-c0d2-4a72-86af-daadc86fd53b","banner":null,"lang":"en","date_modified":"2024-05-10","date_modified_ts":"2024-05-10T13:37:30Z","date_created":"2024-05-10T13:13:46Z","summary":null,"body":["<article data-history-node-id=\"5180\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-249\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-249<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 10, 2024<\/p>\n\n<p>On May 9, 2024, Google published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.201\/.202 (Windows and Mac) and 124.0.6367.201 (Linux)<\/li>\n\t<li>Extended Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.201 (Windows and Mac)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2024-4671 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/05\/stable-channel-update-for-desktop_9.html\">Google Chrome Security Advisory (en anglais seulement)<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-249","alert_type":396,"serial_number":"AV24-249","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5184,"title":"IBM security advisory (AV24-250)","uuid":"ad9825ae-6826-4f8b-b163-39b0ac0defb0","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T15:41:35Z","date_created":"2024-05-13T15:22:51Z","summary":null,"body":["<article data-history-node-id=\"5184\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-250\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-250<br \/><strong>Date: <\/strong>May\u00a013, 2024<\/p>\n\n<p>Between May\u00a06 and 12, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cloudera Data Platform Private Cloud Base with IBM (CDP)\u00a0\u2013 version 7.1.9<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 Monitor Component\u00a0\u2013 versions 8.10 and 8.11<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP8 IF01<\/li>\n\t<li>QRadar User Beahviour Analytics\u00a0\u2013 versions 1.0.0 to 4.1.15<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services\u00a0\u2013 versions 6.0, 6.1.0, 6.2.0 and 6.3.0<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services (Certified Container)\u00a0\u2013 all versions<\/li>\n\t<li>IBM Storage Scale\u00a0\u2013 versions 5.1.0.0 to 5.1.9.2<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.0 to 4.8.4<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.0 to 4.8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-250","alert_type":396,"serial_number":"AV24-250","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5185,"title":"Ubuntu security advisory (AV24-251)","uuid":"db3c8aff-5c46-4af3-b4e3-856d8026b1b1","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T15:52:53Z","date_created":"2024-05-13T15:22:51Z","summary":null,"body":["<article data-history-node-id=\"5185\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-251\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-251<br \/><strong>Date: <\/strong>May\u00a013, 2024<\/p>\n\n<p>Between May\u00a06 and 12, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6765-1\">Ubuntu Security Notice (USN-6765-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6766-1\">Ubuntu Security Notice (USN-6766-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6767-1\">Ubuntu Security Notice (USN-6767-1)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-251","alert_type":396,"serial_number":"AV24-251","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5186,"title":"Dell security advisory (AV24-252)","uuid":"c06d4b0c-0f1d-4f32-8156-01980acf6438","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T15:57:18Z","date_created":"2024-05-13T15:45:20Z","summary":null,"body":["<article data-history-node-id=\"5186\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-252\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-252<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2024<\/p>\n\n<p>Between May 6 and 12, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell Avamar NDMP Accelerator\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10 running SUSE Linux Enterprise 12 SP5<\/li>\n\t<li>Dell Avamar Server Hardware Appliance Gen4T\/ Gen5A\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10 running SUSE Linux Enterprise 12 SP5<\/li>\n\t<li>Dell Avamar Virtual Edition\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10 running SUSE Linux Enterprise 12 SP5<\/li>\n\t<li>Dell Avamar VMware Image Proxy\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10 running SUSE Linux Enterprise 12 SP5<\/li>\n\t<li>Dell Networker Virtual Edition (NVE)\u00a0\u2013 versions 19.4.x, 19.5.x, 19.6.x, 19.7.x, 19.8.x, 19.9.x and 19.10.x running SUSE Linux Enterprise 12 SP5<\/li>\n\t<li>Dell Power Protect DP Series Appliance \/ Dell Integrated Data Protection Appliance (IDPA)\u00a0\u2013 version 2.7.x running SLES12SP5<\/li>\n\t<li>Dell PowerProtect Data Manager DM5500 Appliance\u00a0\u2013 versions 5.15 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-252","alert_type":396,"serial_number":"AV24-252","subject":"dell","moderation_state":"published","external_url":null},{"nid":5187,"title":"[Control systems] CISA ICS security advisories (AV24-253) ","uuid":"275192b9-b56e-4046-b9b7-946b12323f39","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T16:10:33Z","date_created":"2024-05-13T16:03:50Z","summary":null,"body":["<article data-history-node-id=\"5187\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-253\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-253<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2024<\/p>\n\n<p>Between May 6 and 12, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>alpitronic Hypercharger EV charger\u00a0\u2013 all versions<\/li>\n\t<li>Delta Electronics InfraSuite Device Master\u00a0\u2013 version 1.0.10 and prior<\/li>\n\t<li>PTC Codebeamer\u00a0\u2013 multiple versions<\/li>\n\t<li>Rockwell Automation FactoryTalk Historian SE\u00a0\u2013 version v9.0 and prior<\/li>\n\t<li>SUBNET Solutions Substation Server\u00a0\u2013 version 2.23.10 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-253","alert_type":398,"serial_number":"AV24-253","subject":"ics","moderation_state":"published","external_url":null},{"nid":5189,"title":"Microsoft Edge security advisory (AV24-254)","uuid":"86b4deb7-ee46-4f58-9151-5af48a1cba29","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T18:07:57Z","date_created":"2024-05-13T17:48:13Z","summary":null,"body":["<article data-history-node-id=\"5189\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-254\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-254<br \/><strong>Date: <\/strong>May\u00a013, 2024<\/p>\n\n<p>On May\u00a010, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 124.0.2478.97<\/li>\n\t<li>Microsoft Edge Extended Stable channel\u00a0\u2013 versions prior to 124.0.2478.97<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2024-4671 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-10-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-254","alert_type":396,"serial_number":"AV24-254","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5190,"title":"Juniper security advisory (AV24-255)","uuid":"2c486f8c-cb3e-40d2-a4c1-dd2106a40e76","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T18:30:10Z","date_created":"2024-05-13T17:48:14Z","summary":null,"body":["<article data-history-node-id=\"5190\" about=\"\/en\/alerts-advisories\/juniper-security-advisory-av24-255\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-255<br \/><strong>Date: <\/strong>May\u00a013, 2024<\/p>\n\n<p>On May\u00a09, 2024, Juniper published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Junos OS\u00a0\u2013 version 19.4R1 and later<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 version 22.3R1 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US\">2024-05 Reference Advisory: Junos OS and Junos OS Evolved: Multiple CVEs reported in OpenSSH<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]\">Juniper Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-advisory-av24-255","alert_type":396,"serial_number":"AV24-255","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5191,"title":"Red Hat security advisory (AV24-256)","uuid":"d78fa7a0-ad02-472b-9227-6bc5335fe8a6","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T18:36:13Z","date_created":"2024-05-13T17:48:14Z","summary":null,"body":["<article data-history-node-id=\"5191\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-256\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-256<br \/><strong>Date: <\/strong>May\u00a013, 2024<\/p>\n\n<p>Between May\u00a06 and 12, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux for x86_64\u00a0\u2013 version Extended Update Support 8.8 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux for Power, little endian\u00a0\u2013 version Extended Update Support 8.8 ppc64le<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 version TUS 8.8 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 version Update Services for SAP Solutions 8.8 ppc64le<\/li>\n\t<li>Red Hat Enterprise Linux for x86_64\u00a0\u2013 version Update Services for SAP Solutions 8.8 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:2697\">RHSA-2024:2697\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-256","alert_type":396,"serial_number":"AV24-256","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5192,"title":"Apple security advisory (AV24-257)","uuid":"75032a23-d187-4ea8-9b59-c4b5b4a37f03","banner":null,"lang":"en","date_modified":"2024-05-13","date_modified_ts":"2024-05-13T19:41:47Z","date_created":"2024-05-13T19:35:09Z","summary":null,"body":["<article data-history-node-id=\"5192\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-257\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-257<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2024<\/p>\n\n<p>On May 13, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 16.7.8<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 17.5<\/li>\n\t<li>macOS Monterey\u00a0\u2013 versions prior to 12.7.5<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.5<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.6.7<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 17.5<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 10.5<\/li>\n<\/ul><p>Apple is aware that CVE-2024-23296 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-257","alert_type":396,"serial_number":"AV24-257","subject":"apple","moderation_state":"published","external_url":null},{"nid":5193,"title":"Apple security advisory (AV24-258)","uuid":"9456a684-961c-4def-b1f5-c5ac9c5ef9fb","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T15:04:41Z","date_created":"2024-05-14T14:57:13Z","summary":null,"body":["<article data-history-node-id=\"5193\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-258\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-258<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 13, 2024, Apple published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Safari\u00a0\u2013 versions prior to 17.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-ca\/HT214103\">About the security content of Safari 17.5<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-258","alert_type":396,"serial_number":"AV24-258","subject":"apple","moderation_state":"published","external_url":null},{"nid":5194,"title":"Google Chrome security advisory (AV24-259)","uuid":"f0f6dfda-2663-407e-98fe-49ba69f14046","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T15:20:37Z","date_created":"2024-05-14T15:12:40Z","summary":null,"body":["<article data-history-node-id=\"5194\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-259\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-259<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 13, 2024, Google published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.207\/.208 (Windows and Mac) and 124.0.6367.207 (Linux)<\/li>\n\t<li>Extended Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 124.0.6367.207 (Windows and Mac)<\/li>\n<\/ul><p>Google has indicated that CVE-2024-4761 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/05\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-259","alert_type":396,"serial_number":"AV24-259","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5195,"title":"VMware security advisory (AV24-260)","uuid":"62bcf2e6-9986-447b-bcf5-ac1371b6703b","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T15:40:14Z","date_created":"2024-05-14T15:12:40Z","summary":null,"body":["<article data-history-node-id=\"5195\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-260\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-260<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Fusion\u00a0\u2013 versions 13.x prior to 13.5.2<\/li>\n\t<li>VMware Workstation\u00a0\u2013 versions 17.x prior to 17.5.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24280\">VMware Workstation and Fusion updates address multiple security vulnerabilities (CVE-2024-22267, CVE-2024-22268, CVE-2024-22269, CVE-2024-22270)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-260","alert_type":396,"serial_number":"AV24-260","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5196,"title":"[Control systems] B&R security advisory (AV24-261) ","uuid":"e50216de-d5f4-4744-a2ba-45ba686a384c","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T15:51:35Z","date_created":"2024-05-14T15:12:40Z","summary":null,"body":["<article data-history-node-id=\"5196\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-261\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-261<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, B&amp;R published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Automation Runtime Simulation\u00a0\u2013 version 14.93 and prior<\/li>\n\t<li>B&amp;R Hypervisor Installer\u00a0\u2013 version 14.93 and prior<\/li>\n\t<li>mapp Cockpit\u00a0\u2013 versions prior to 5.24.2<\/li>\n\t<li>mapp Safety\u00a0\u2013 versions prior to 5.24.2<\/li>\n\t<li>mapp Vision\u00a0\u2013 versions prior to 5.26.1<\/li>\n\t<li>mapp View\u00a0\u2013 versions prior to 5.24.2<\/li>\n\t<li>Scene Viewer\u00a0\u2013 versions prior to 4.4<\/li>\n\t<li>Visual Components 4\u00a0\u2013 versions prior to 4.73.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA24P005_Insecure_Loading_of_Code-c7d9e49c.pdf\">Insecure Loading of Code in B&amp;R Products (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-261","alert_type":398,"serial_number":"AV24-261","subject":"other","moderation_state":"published","external_url":null},{"nid":5197,"title":"[Control systems] ABB security advisory (AV24-262) ","uuid":"2e8cbdd8-031d-4482-afd3-2bd92e905e02","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T16:01:54Z","date_created":"2024-05-14T15:12:40Z","summary":null,"body":["<article data-history-node-id=\"5197\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-262\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-262<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, ABB published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>IRC5 RobotWare 6\u00a0\u2013 multiple versions<\/li>\n\t<li>OmniCore RobotWare7\u00a0\u2013 versions prior to 7.14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=SI20330&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">IRC5 \/ OmniCore RobotWare\u00a0\u2013 Multiple Vulnerabilities (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-262","alert_type":398,"serial_number":"AV24-262","subject":"abb","moderation_state":"published","external_url":null},{"nid":5198,"title":"[Control systems] Siemens security advisory (AV24-263) ","uuid":"4f6877c1-0796-48c2-86c1-b60d7b16d014","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T16:23:07Z","date_created":"2024-05-14T15:12:40Z","summary":null,"body":["<article data-history-node-id=\"5198\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-263\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-263<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, Siemens published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cerberus PRO UL Compact Panel FC922\/924\u00a0\u2013 versions prior to MP4<\/li>\n\t<li>Cerberus PRO UL Engineering Tool\u00a0\u2013 versions prior to MP4<\/li>\n\t<li>Cerberus PRO UL X300 Cloud Distribution\u00a0\u2013 versions prior to V4.3.0001<\/li>\n\t<li>Desigo Fire Safety UL Compact Panel FC2025\/2050\u00a0\u2013 versions prior to MP4<\/li>\n\t<li>Desigo Fire Safety UL Engineering Tool\u00a0\u2013 versions prior to MP4<\/li>\n\t<li>Desigo Fire Safety UL X300 Cloud Distribution\u00a0\u2013 versions prior to V4.3.0001<\/li>\n\t<li>RUGGEDCOM CROSSBOW\u00a0\u2013 versions prior to V5.5<\/li>\n\t<li>SIMATIC CN 4100\u00a0\u2013 versions prior to V3.0<\/li>\n\t<li>SIMATIC RTLS Locating Manager\u00a0\u2013 multiple platforms, versions prior to V3.0.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-953710.html?ste_sid=15f36f762d23402f29a724772e9bf98c\">SSA-953710: Vulnerabilities in the Network Communication Stack in Desigo Fire Safety UL and Cerberus PRO UL Fire Protection Systems<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-916916.html?ste_sid=15f36f762d23402f29a724772e9bf98c\">SSA-916916: Security Vulnerabilities Fixed in RUGGEDCOM CROSSBOW V5.5<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-273900.html?ste_sid=15f36f762d23402f29a724772e9bf98c\">SSA-273900: Multiple Vulnerabilities in SIMATIC CN 4100 before V3.0<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-093430.html?ste_sid=15f36f762d23402f29a724772e9bf98c\">SSA-093430: Multiple Vulnerabilities in SIMATIC RTLS Locating Manager before V3.0<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-263","alert_type":398,"serial_number":"AV24-263","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5199,"title":"Mozilla security advisory (AV24-264)","uuid":"f21dbe0b-501a-4e0f-b4a1-436bd79de4c7","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T17:26:11Z","date_created":"2024-05-14T17:21:03Z","summary":null,"body":["<article data-history-node-id=\"5199\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-264\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-264<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 126<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-21\/\">Mozilla Security Advisory - MFSA 2024-21<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-22\/\">Mozilla Security Advisory - MFSA 2024-22<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-264","alert_type":396,"serial_number":"AV24-264","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5200,"title":"SAP security advisory \u2013 May 2024 monthly rollup (AV24-265)","uuid":"115f5611-a360-4f4d-b527-3ddf66b34c4e","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T17:31:33Z","date_created":"2024-05-14T17:27:47Z","summary":null,"body":["<article data-history-node-id=\"5200\" about=\"\/en\/alerts-advisories\/sap-security-advisory-may-2024-monthly-rollup-av24-265\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-265<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP CX Commerce\u00a0\u2013 version HY_COM 2205<\/li>\n\t<li>SAP NetWeaver Application Server ABAP and ABAP Platform\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/may-2024.html\">SAP Security Patch Day\u00a0- May 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-may-2024-monthly-rollup-av24-265","alert_type":396,"serial_number":"AV24-265","subject":"sap","moderation_state":"published","external_url":null},{"nid":5202,"title":"Microsoft security advisory \u2013 May 2024 monthly rollup (AV24-266)","uuid":"511518ee-41a6-445e-8eed-67fb95e243ae","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T18:41:39Z","date_created":"2024-05-14T18:34:22Z","summary":null,"body":["<article data-history-node-id=\"5202\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2024-monthly-rollup-av24-266\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-266<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dynamics 365 Customer Insights<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft .NET 7.0 and 8.0<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Visual Studio\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple platforms and versions<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple platforms and versions<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-30040 and CVE-2024-30051 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-May\">May 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-may-2024-monthly-rollup-av24-266","alert_type":396,"serial_number":"AV24-266","subject":"other","moderation_state":"published","external_url":null},{"nid":5204,"title":"Fortinet security advisory (AV24-267)","uuid":"96f29aa5-3403-48ae-9a2c-28fcfaa09c7c","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T18:47:40Z","date_created":"2024-05-14T18:44:01Z","summary":null,"body":["<article data-history-node-id=\"5204\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-267\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-267<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2024<\/p>\n\n<p>On May 14, 2024, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>FortiPortal 7.2 \u2013 versions 7.2.0 to 7.2.1<\/li>\n\t<li>FortiPortal 7.0 \u2013 versions 7.0.0 to 7.0.6<\/li>\n\t<li>FortiSOAR 7.4 \u2013 all versions<\/li>\n\t<li>FortiSOAR 7.3 \u2013 all versions<\/li>\n\t<li>FortiSOAR 7.2 \u2013 all versions<\/li>\n\t<li>FortiSOAR 7.0 \u2013 all versions<\/li>\n\t<li>FortiSOAR 6.4 \u2013 all versions<\/li>\n\t<li>FortiWebManager 7.2 \u2013 version 7.2.0<\/li>\n\t<li>FortiWebManager 7.0 \u2013 versions 7.0.0 to 7.0.4<\/li>\n\t<li>FortiWebManager 6.3 \u2013 version 6.3.0<\/li>\n\t<li>FortiWebManager 6.2 \u2013 versions 6.2.3 to 6.2.4<\/li>\n\t<li>FortiWebManager 6.0 \u2013 version 6.0.2<\/li>\n\t<li>FortiSandbox 4.4 \u2013 versions 4.4.0 to 4.4.4<\/li>\n\t<li>FortiSandbox 4.2 \u2013 versions 4.2.0 to 4.2.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-267","alert_type":396,"serial_number":"AV24-267","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":5206,"title":"Adobe security advisory (AV24-268)","uuid":"d3dbd915-507e-448f-9100-4bb100e8f5d8","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T20:05:24Z","date_created":"2024-05-14T19:59:12Z","summary":null,"body":["<article data-history-node-id=\"5206\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-268\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-268<br \/><strong>Date: <\/strong>May\u00a014, 2024<\/p>\n\n<p>On May\u00a014, 2024, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat DC\u00a0\u2013 version 24.002.20736 and prior<\/li>\n\t<li>Acrobat Reader DC\u00a0\u2013 version 24.002.20736 and prior<\/li>\n\t<li>Acrobat 2020\u00a0\u2013 version 20.005.30574 and prior<\/li>\n\t<li>Acrobat Reader 2020\u00a0\u2013 version 20.005.30574 and prior<\/li>\n\t<li>Adobe Animate 2023\u00a0\u2013 version 23.0.5 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0\u2013 version 24.0.2 and prior<\/li>\n\t<li>Adobe Dreamweaver\u00a0\u2013 version 21.3 and prior<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 versions 2020 Release Update 5 and 2022 Release Update 3 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version 13.1.1 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 9.1.2 and prior<\/li>\n\t<li>Aero\u00a0\u2013 version 0.23.4 and prior<\/li>\n\t<li>Illustrator 2023\u00a0\u2013 version 27.9.3 and prior<\/li>\n\t<li>Illustrator 2024\u00a0\u2013 version 28.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-268","alert_type":396,"serial_number":"AV24-268","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5207,"title":"Intel security advisory (AV24-269)","uuid":"bd19d916-b333-4d45-8603-9a2103b1930c","banner":null,"lang":"en","date_modified":"2024-05-14","date_modified_ts":"2024-05-14T20:32:05Z","date_created":"2024-05-14T19:59:13Z","summary":null,"body":["<article data-history-node-id=\"5207\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av24-269\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-269<br \/><strong>Date: <\/strong>May\u00a014, 2024<\/p>\n\n<p>On May\u00a014, 2024, Intel published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Intel Agilex 7 FPGAs and SoC FPGAs Firmware\u00a0\u2013 versions after 21.4<\/li>\n\t<li>Intel Stratix 10 FPGAs and SoC FPGAs Firmware\u00a0\u2013 versions after 21.2<\/li>\n\t<li>Intel Arc &amp; Iris Xe Graphics software\u00a0\u2013 versions prior to 31.0.101.5081<\/li>\n\t<li>Intel DTT software\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Intel Ethernet Controller I225 Manageability firmware\u00a0\u2013 versions prior to 1.87<\/li>\n\t<li>Intel Ethernet Adapters\u00a0\u2013 versions prior to 29.0.1<\/li>\n\t<li>Intel GPA software\u00a0\u2013 versions prior to 2023.3<\/li>\n\t<li>Intel GPA Framework software\u00a0\u2013 versions prior to 2023.3<\/li>\n\t<li>Intel Neural Compressor software\u00a0\u2013 versions prior to 2.5.0<\/li>\n\t<li>Intel Power Gadget software for macOS X\u00a0\u2013 versions prior to 3.7.0<\/li>\n\t<li>Intel Power Gadget software for Windows\u00a0\u2013 versions prior to 3.6.0<\/li>\n\t<li>Intel PROSet\/Wireless Wi-Fi software\u00a0\u2013 versions prior to 23.20<\/li>\n\t<li>Intel Server D50DNP Family<\/li>\n\t<li>Intel Server M50FCP Family<\/li>\n\t<li>Intel Server Board S2600BP Family<\/li>\n\t<li>Intel TDX module software\u00a0\u2013 versions prior to TDX_1.5.05.46.698<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av24-269","alert_type":396,"serial_number":"AV24-269","subject":"intel","moderation_state":"published","external_url":null},{"nid":5208,"title":"Microsoft Edge security advisory (AV24-270)","uuid":"01dc4398-6ca7-4d93-9b8b-7958c39a30c7","banner":null,"lang":"en","date_modified":"2024-05-15","date_modified_ts":"2024-05-15T15:27:22Z","date_created":"2024-05-15T15:17:11Z","summary":null,"body":["<article data-history-node-id=\"5208\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-270\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-270<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 15, 2024<\/p>\n\n<p>On May 14, 2024, Microsoft published a security update to address a vulnerability in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 0.2478.105<\/li>\n\t<li>Microsoft Edge Extended Stable channel \u2013 versions prior to 124.0.2478.105<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>Microsoft has received reports that CVE-2024-4761 has been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"Release notes for Microsoft Edge Security Updates\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-French-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-270","alert_type":396,"serial_number":"AV24-270","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5209,"title":"HPE security advisory (AV24-271)","uuid":"f1eabcd3-dfa7-4c9c-87cb-ac2a4a52a573","banner":null,"lang":"en","date_modified":"2024-05-15","date_modified_ts":"2024-05-15T15:35:28Z","date_created":"2024-05-15T15:32:53Z","summary":null,"body":["<article data-history-node-id=\"5209\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-271\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-271<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 15, 2024<\/p>\n\n<p>On May 14, 2024, HPE published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>ArubaOS 10.5.x.x \u2013 version 10.5.1.0 and prior<\/li>\n\t<li>ArubaOS 10.4.x.x \u2013 version 10.4.1.0 and prior<\/li>\n\t<li>ArubaOS 10.3.x.x \u2013 all versions<\/li>\n\t<li>InstantOS 8.11.x.x \u2013 version 8.11.2.1 and prior<\/li>\n\t<li>InstantOS 8.10.x.x \u2013 version 8.10.0.10 and prior<\/li>\n\t<li>InstantOS 8.9.x.x \u2013 all versions<\/li>\n\t<li>InstantOS 8.8.x.x \u2013 all versions<\/li>\n\t<li>InstantOS 8.7.x.x \u2013 all versions<\/li>\n\t<li>InstantOS 8.6.x.x \u2013 version 8.6.0.23 and prior<\/li>\n\t<li>InstantOS 8.5.x.x \u2013 all versions<\/li>\n\t<li>InstantOS 8.4.x.x \u2013 all versions<\/li>\n\t<li>InstantOS 6.5.x.x \u2013 all versions<\/li>\n\t<li>InstantOS 6.4.x.x \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04647en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbnw04647<\/a><\/li>\n\t<li><a class=\"external-link\" href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-French-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-271","alert_type":396,"serial_number":"AV24-271","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5210,"title":"F5 security advisory (AV24-272)","uuid":"20a2529f-ef2a-45d2-8053-971f0aed37e8","banner":null,"lang":"en","date_modified":"2024-05-15","date_modified_ts":"2024-05-15T15:48:52Z","date_created":"2024-05-15T15:43:31Z","summary":null,"body":["<article data-history-node-id=\"5210\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av24-272\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-272<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 15, 2024<\/p>\n\n<p>On May 14, 2024, F5 published security updates for multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP \u2013 versions 17.1.0 to 17.1.1, 16.1.0 to 16.1.4 and 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 version 8.1.0 to 8.3.0<\/li>\n\t<li>Traffix SDC \u2013 version 5.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000139594\">F5 Security Advisory - K000139594: libxml2 vulnerability CVE-2022-40304<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=security&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending&amp;f:@f5_document_type=[Security%20Advisory]\">F5 Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av24-272","alert_type":396,"serial_number":"AV24-272","subject":"f5","moderation_state":"published","external_url":null},{"nid":5211,"title":"Cisco security advisory (AV24-273)","uuid":"a2282962-af2f-430b-b62c-d5540080993b","banner":null,"lang":"en","date_modified":"2024-05-15","date_modified_ts":"2024-05-15T19:53:18Z","date_created":"2024-05-15T19:35:23Z","summary":null,"body":["<article data-history-node-id=\"5211\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-273\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-273<br \/><strong>Date: <\/strong>May\u00a015, 2024<\/p>\n\n<p>On May\u00a015, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Crosswork Network Services Orchestrator (NSO) CLI\u00a0\u2013 multiple versions<\/li>\n\t<li>ConfD CLI\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nso-hcc-priv-esc-OWBWCs5D\">Cisco Crosswork Network Services Orchestrator Privilege Escalation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nso-rwpesc-qrQGnh3f\">Cisco Crosswork Network Services Ochestrator Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cnfd-rwpesc-ZAOufyx8\">ConfD CLI Privilege Escalation and Arbitrary File Read and Write Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-273","alert_type":396,"serial_number":"AV24-273","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5212,"title":"Google Chrome security advisory (AV24-274)","uuid":"e10aae07-046b-420f-bbbd-ec2fa5f1be96","banner":null,"lang":"en","date_modified":"2024-05-16","date_modified_ts":"2024-05-16T13:47:38Z","date_created":"2024-05-16T13:35:43Z","summary":null,"body":["<article data-history-node-id=\"5212\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-274\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-274<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 16, 2024<\/p>\n\n<p>On May 15, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 125.0.6422.60\/.61 (Windows and Mac) and 125.0.6422.60 (Linux)<\/li>\n<\/ul><p>Google has indicated that CVE-2024-4947 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/05\/stable-channel-update-for-desktop_15.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-274","alert_type":396,"serial_number":"AV24-274","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5213,"title":"Drupal security advisory (AV24-275)","uuid":"6adcf65c-e07d-4b5b-81a9-739618efb110","banner":null,"lang":"en","date_modified":"2024-05-16","date_modified_ts":"2024-05-16T14:00:21Z","date_created":"2024-05-16T13:52:32Z","summary":null,"body":["<article data-history-node-id=\"5213\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-275\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-275<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 16, 2024<\/p>\n\n<p>On May 15, 2024, Drupal published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>RESTful Web Services\u00a0\u2013 versions prior to 7.x-2.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-019\">RESTful Web Services\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2024-019<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-275","alert_type":396,"serial_number":"AV24-275","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5214,"title":"Microsoft Edge security advisory (AV24-276)","uuid":"d7243c23-b9b3-487a-b3ae-5c02d367764c","banner":null,"lang":"en","date_modified":"2024-05-17","date_modified_ts":"2024-05-17T14:40:22Z","date_created":"2024-05-17T14:24:31Z","summary":null,"body":["<article data-history-node-id=\"5214\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-276\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-276<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 17, 2024<\/p>\n\n<p>On May 16, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 0.2478.109<\/li>\n\t<li>Microsoft Edge Extended Stable channel\u00a0\u2013 versions prior to 124.0.2478.109<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2024-4947 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-16-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-276","alert_type":396,"serial_number":"AV24-276","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5215,"title":"HPE security advisory (AV24-277)","uuid":"f6247c25-ea8c-4776-b614-e77b1b9c32e9","banner":null,"lang":"en","date_modified":"2024-05-17","date_modified_ts":"2024-05-17T16:04:01Z","date_created":"2024-05-17T14:47:48Z","summary":null,"body":["<article data-history-node-id=\"5215\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-277\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-277<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 17, 2024<\/p>\n\n<p>On May 17, 2024, HPE published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE B-series SN2600B SAN Extension Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE B-series SN3600B Fibre Channel Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE B-series SN4700B SAN Extension Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE B-series SN6600B Fibre Channel Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE B-series SN6650B Fibre Channel Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE B-series SN6700B Fibre Channel Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE B-series SN6750B Fibre Channel Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE SN8600B 4-slot SAN Director Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE SN8700B 4-slot SAN Director Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE SN8600B 8-slot SAN Director Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>HPE SN8700B 8-slot SAN Director Switch\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n\t<li>Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy\u00a0\u2013 version 9.x prior to v9.1.1d1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04649en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbst04649<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-277","alert_type":396,"serial_number":"AV24-277","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5216,"title":"F5 security advisory (AV24-278)","uuid":"6ba2ceeb-6c40-427f-bcc0-94aaa8b39867","banner":null,"lang":"en","date_modified":"2024-05-17","date_modified_ts":"2024-05-17T16:16:42Z","date_created":"2024-05-17T16:10:54Z","summary":null,"body":["<article data-history-node-id=\"5216\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av24-278\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-278<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 17, 2024<\/p>\n\n<p>On May 16, 2024, F5 published security updates for multiple products. Included were updates for the following product:<\/p>\n\n<ul><li>F5OS-A\u00a0\u2013 versions 1.7.0 and 1.5.1 to 1.5.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000139652\">F5 Security Advisory\u00a0- K000139652: Intel CPU vulnerability CVE-2023-23583<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/global-search\/%40uri#q=security&amp;sort=%40f5_updated_published_date%20descending%3B%40f5_original_published_date%20descending&amp;f:@f5_document_type=[Security%20Advisory]\">F5 Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av24-278","alert_type":396,"serial_number":"AV24-278","subject":"f5","moderation_state":"published","external_url":null},{"nid":5217,"title":"Ubuntu security advisory (AV24-279)","uuid":"8b0de9eb-a010-47aa-973f-d26b11d2915a","banner":null,"lang":"en","date_modified":"2024-05-21","date_modified_ts":"2024-05-21T15:26:47Z","date_created":"2024-05-21T15:18:56Z","summary":null,"body":["<article data-history-node-id=\"5217\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-279\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-279<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 21, 2024<\/p>\n\n<p>Between May 13 and 19, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-279","alert_type":396,"serial_number":"AV24-279","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5218,"title":"IBM security advisory (AV24-280)","uuid":"87923eef-5a29-429e-8c9c-84a987230eb1","banner":null,"lang":"en","date_modified":"2024-05-21","date_modified_ts":"2024-05-21T16:04:38Z","date_created":"2024-05-21T15:36:35Z","summary":null,"body":["<article data-history-node-id=\"5218\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-280\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-280<br \/><strong>Date: <\/strong>May\u00a021, 2024<\/p>\n\n<p>Between May\u00a013 and 19, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM i Modernization Engine for Lifecycle Integration\u00a0\u2013 version 1.0 to 1.4.6<\/li>\n\t<li>IBM Operational Decision Manager\u00a0\u2013 versions 8.10.4, 8.10.5.2, 8.11.0.1, 8.11.1 and 8.12.0.1<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 version 1.14.4<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 version 7.5 to 7.5.0 UP8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-280","alert_type":396,"serial_number":"AV24-280","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5219,"title":"Dell security advisory (AV24-281)","uuid":"4304175e-c9d0-4d14-81df-9596605ef627","banner":null,"lang":"en","date_modified":"2024-05-21","date_modified_ts":"2024-05-21T16:12:37Z","date_created":"2024-05-21T15:36:35Z","summary":null,"body":["<article data-history-node-id=\"5219\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-281\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-281<br \/><strong>Date: <\/strong>May\u00a021, 2024<\/p>\n\n<p>Between May\u00a013 and 19, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 4.13.39<\/li>\n\t<li>APEX Cloud Platform Foundation Software\u00a0\u2013 03.xx versions prior to 03.00.04.01<\/li>\n\t<li>Dell Apex Cloud Platform for Microsoft Azure\u00a0\u2013 versions prior to 01.01.01.01<\/li>\n\t<li>Dell Protection Advisor\u00a0\u2013 versions 19.5 to 19.9<\/li>\n\t<li>Disk Library for mainframe\u00a0\u2013 versions prior to 5.5.0.5<\/li>\n\t<li>Microsoft Azure Stack HCI\u00a0\u2013 versions prior to 10.2402<\/li>\n\t<li>PowerEdge T30\u00a0\u2013 versions prior to 1.14.0<\/li>\n\t<li>PowerEdge T40\u00a0\u2013 versions prior to 1.15.0<\/li>\n\t<li>PowerProtect DP Series Appliance (IDPA)\u00a0\u2013 version 2.7.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-281","alert_type":396,"serial_number":"AV24-281","subject":"dell","moderation_state":"published","external_url":null},{"nid":5220,"title":"Red Hat security advisory (AV24-282)","uuid":"f6a25c20-301f-462b-9f40-7ccba0c39479","banner":null,"lang":"en","date_modified":"2024-05-21","date_modified_ts":"2024-05-21T19:11:15Z","date_created":"2024-05-21T19:01:30Z","summary":null,"body":["<article data-history-node-id=\"5220\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-282\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-282<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 21, 2024<\/p>\n\n<p>Between May 13 and 19, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:2845\">RHSA-2024:2845\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:2846\">RHSA-2024:2846\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-282","alert_type":396,"serial_number":"AV24-282","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5221,"title":"[Control systems] CISA ICS security advisories (AV24-283)","uuid":"adb80d0e-73a9-4645-81d3-351588999736","banner":null,"lang":"en","date_modified":"2024-05-21","date_modified_ts":"2024-05-21T19:41:00Z","date_created":"2024-05-21T19:23:21Z","summary":null,"body":["<article data-history-node-id=\"5221\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-283\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-283<br \/><strong>Date: <\/strong>May\u00a021, 2024<\/p>\n\n<p>Between May\u00a013 and 19, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Johnson Controls Software House C-CURE 9000\u00a0\u2013 version 3.00.2<\/li>\n\t<li>Mitsubishi Electric Multiple FA Engineering Software Products\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Rockwell Automation FactoryTalk Remote Access\u00a0\u2013 version 13.5.0.174 and prior<\/li>\n\t<li>Rockwell Automation FactoryTalk View SE\u00a0\u2013 versions prior to 14.0<\/li>\n\t<li>Siemens Cerberus PRO UL\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Desigo Fire Safety UL\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens JT2Go\u00a0\u2013 versions prior to 2312.0001<\/li>\n\t<li>Siemens Parasolid\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Polarion ALM\u00a0\u2013 versions prior to 2404.0<\/li>\n\t<li>Siemens PS\/IGES Parasolid Translator Component\u00a0\u2013 versions prior to 27.1.215<\/li>\n\t<li>Siemens RUGGEDCOM APE1808LNX CC (6GK60150AL20-0GH1)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM APE1808LNX (6GK6015-0AL200GH0)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM CROSSBOW\u00a0\u2013 versions prior to 5.5<\/li>\n\t<li>Siemens SICAM\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SIMATIC CN 4100\u00a0\u2013 versions prior to 3.0<\/li>\n\t<li>Siemens SIMATIC RTLS Locating Manager\u00a0\u2013 multiple platforms, versions prior to V3.0.1.1<\/li>\n\t<li>Siemens Simcenter Nastran\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Solid Edge\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Teamcenter Visualization\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SUBNET PowerSYSTEM Center\u00a0\u2013 version 19 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-283","alert_type":398,"serial_number":"AV24-283","subject":"ics","moderation_state":"published","external_url":null},{"nid":5222,"title":"GitHub security advisory (AV24-284)","uuid":"16269a24-7f9a-467c-a521-8c2d741009b3","banner":null,"lang":"en","date_modified":"2024-05-21","date_modified_ts":"2024-05-21T19:51:20Z","date_created":"2024-05-21T19:36:14Z","summary":null,"body":["<article data-history-node-id=\"5222\" about=\"\/en\/alerts-advisories\/github-security-advisory-av24-284\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-284<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 21, 2024<\/p>\n\n<p>On May 20, 2024, GitHub published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.12.x prior to 3.12.4<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.11.x prior to 3.11.10<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.10.x prior to 3.10.12<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.9.x prior to 3.9.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.12\/admin\/release-notes#3.12.4\">GitHub Release Notes #3.12.4<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.11\/admin\/release-notes#3.11.10\">GitHub Release Notes #3.11.10<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.10\/admin\/release-notes#3.10.12\">GitHub Release Notes #3.10.12<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.9\/admin\/release-notes#3.9.15\">GitHub Release Notes #3.9.15<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av24-284","alert_type":396,"serial_number":"AV24-284","subject":"other","moderation_state":"published","external_url":null},{"nid":5224,"title":"Google Chrome security advisory (AV24-285)","uuid":"4969cdae-2cf5-4e8c-99a6-1d987f7ea7b1","banner":null,"lang":"en","date_modified":"2024-05-22","date_modified_ts":"2024-05-22T17:39:35Z","date_created":"2024-05-22T17:30:29Z","summary":null,"body":["<article data-history-node-id=\"5224\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-285\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-285<br \/><strong>Date: <\/strong>May\u00a022, 2024<\/p>\n\n<p>On May\u00a021, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 125.0.6422.76\/.77 (Windows and Mac) and 125.0.6422.76 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/05\/stable-channel-update-for-desktop_21.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-285","alert_type":396,"serial_number":"AV24-285","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5225,"title":"Ivanti security advisory (AV24-286)","uuid":"beb8c7b1-7fa7-461d-af29-c143a30020b9","banner":null,"lang":"en","date_modified":"2024-05-22","date_modified_ts":"2024-05-22T17:49:49Z","date_created":"2024-05-22T17:30:30Z","summary":null,"body":["<article data-history-node-id=\"5225\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-286\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-286<br \/><strong>Date: <\/strong>May\u00a022, 2024<\/p>\n\n<p>On May\u00a021, 2024, Ivanti published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Ivanti Connect Secure (ICS)\u00a0\u2013 versions 9.x and 22.x<\/li>\n\t<li>Ivanti Endpoint Manager (EPM)\u00a0\u2013 version 2022 SU5 and prior<\/li>\n\t<li>Ivanti Neurons for ITSM\/ITAM\u00a0\u2013 versions 2023.4, 2023.3, 2023.2 and 2023.1<\/li>\n\t<li>Ivanti Policy Secure gateways\u00a0\u2013 versions prior to 22.7R1<\/li>\n\t<li>Ivanti Secure Access\u00a0\u2013 versions prior to 22.7R1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-Security-Advisory-Ivanti-Secure-Access-Client-May-2024?language=en_US\">KB Security Advisory Ivanti Secure Access Client May 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-Security-Advisory-EPM-May-2024?language=en_US\">KB Security Advisory EPM May 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-CVE-2024-22059-and-CVE-2024-22060-for-Ivanti-Neurons-for-ITSM?language=en_US\">KB: CVE-2024-22059 and CVE-2024-22060 for Ivanti Neurons for ITSM<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/KB-Security-Advisory-Ivanti-Connect-Secure-Ivanti-Policy-Secure-May-2024?language=en_US\">KB Security Advisory Ivanti Connect Secure &amp; Ivanti Policy Secure May 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-286","alert_type":396,"serial_number":"AV24-286","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5226,"title":"VMware security advisory (AV24-287)","uuid":"44405e6e-805e-4378-8dda-e4cf47a3254d","banner":null,"lang":"en","date_modified":"2024-05-22","date_modified_ts":"2024-05-22T18:11:28Z","date_created":"2024-05-22T17:40:55Z","summary":null,"body":["<article data-history-node-id=\"5226\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-287\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-287<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 22, 2024<\/p>\n\n<p>On May 21, 2024, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation (ESXi)\u00a0\u2013 multiple versions<\/li>\n\t<li>VMware Cloud Foundation (vCenter Server)\u00a0\u2013 multiple versions<\/li>\n\t<li>VMware ESXi\u00a0\u2013 versions 8.0 prior to ESXi80U2sb-23305545 and versions 7.0 prior to ESXi70U3sq-23794019<\/li>\n\t<li>VMware Fusion\u00a0\u2013 versions prior to 13.5.1<\/li>\n\t<li>VMware vCenter Server\u00a0\u2013 versions 8.0 prior to 8.0 U2b and versions 7.0 prior to 7.0 U3q<\/li>\n\t<li>VMware Workstation\u00a0\u2013 versions prior to 17.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24308\">VMSA-2024-0011:VMware ESXi, Workstation, Fusion and vCenter Server updates address multiple security vulnerabilities (CVE-2024-22273, CVE-2024-22274, CVE-2024-22275)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-287","alert_type":396,"serial_number":"AV24-287","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5227,"title":"Cisco security advisory (AV24-288)","uuid":"aee7468e-cfa1-4b79-922f-70bc76930090","banner":null,"lang":"en","date_modified":"2024-05-22","date_modified_ts":"2024-05-22T19:44:41Z","date_created":"2024-05-22T19:12:52Z","summary":null,"body":["<article data-history-node-id=\"5227\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-288\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-288<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 22, 2024<\/p>\n\n<p>On May 22, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Firepower Management Center Software\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-fmc-sqli-WFFDnNOs\">Cisco Firepower Management Center Software SQL Injection Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-288","alert_type":396,"serial_number":"AV24-288","subject":"other","moderation_state":"published","external_url":null},{"nid":5228,"title":"Atlassian security advisory (AV24-289)","uuid":"d45e63cd-4ffc-4601-b583-6b414eedfd48","banner":null,"lang":"en","date_modified":"2024-05-22","date_modified_ts":"2024-05-22T19:46:38Z","date_created":"2024-05-22T19:17:51Z","summary":null,"body":["<article data-history-node-id=\"5228\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-289\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-289<br \/><strong>Date: <\/strong>May\u00a022, 2024<\/p>\n\n<p>On May\u00a021, 2024, Atlassian published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Bamboo Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Software Data Center\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Software Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-may-21-2024-1387867145.html\">Atlassian May 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/data-protection\/vulnerabilities\">Security at Atlassian: Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-289","alert_type":396,"serial_number":"AV24-289","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5230,"title":"HPE security advisory (AV24-290)","uuid":"6102414a-e90b-45cd-8860-3d02bb494d9e","banner":null,"lang":"en","date_modified":"2024-05-23","date_modified_ts":"2024-05-23T14:34:42Z","date_created":"2024-05-23T14:31:48Z","summary":null,"body":["<article data-history-node-id=\"5230\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-290\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-290<br \/><strong>Date: <\/strong>May\u00a023, 2024<\/p>\n\n<p>On May\u00a020, 2024, HPE published security advisories to address vulnerabilities in multiple products. Included was an update for the following product:<\/p>\n\n<ul><li>HPE SANnav Management Software\u00a0\u2013 versions prior to 2.3.0a and 2.3.1a<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04648en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbst04648<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-290","alert_type":396,"serial_number":"AV24-290","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5231,"title":"GitLab security advisory (AV24-292)","uuid":"166a9e6b-490d-4ced-b990-3fa1614de663","banner":null,"lang":"en","date_modified":"2024-05-23","date_modified_ts":"2024-05-23T19:04:09Z","date_created":"2024-05-23T18:50:33Z","summary":null,"body":["<article data-history-node-id=\"5231\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-292\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-292<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 23, 2024<\/p>\n\n<p>On May 22, 2024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 0.1, 16.11.3 and 16.10.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.0.1, 16.11.3 and 16.10.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/05\/22\/patch-release-gitlab-17-0-1-released\/\">GitLab Patch Release: 17.0.1, 16.11.3, 16.10.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-292","alert_type":396,"serial_number":"AV24-292","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5232,"title":"Mitel security advisory (AV24-291)","uuid":"4c466dae-cbfd-4f21-8dda-142feb9d0b31","banner":null,"lang":"en","date_modified":"2024-05-23","date_modified_ts":"2024-05-23T19:00:00Z","date_created":"2024-05-23T19:10:51Z","summary":null,"body":["<article data-history-node-id=\"5232\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-291\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-291<br \/><strong>Date: <\/strong>May\u00a023, 2024<\/p>\n\n<p>On May\u00a023, 2024, Mitel published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitel MiCollab\u00a0\u2013 version 9.7.1.110 and prior, version 9.8.0.33 and prior<\/li>\n\t<li>Mitel MiVoice Business Solution Virtual Instance (MiVB SVI)\u00a0\u2013 version 1.0.0.25<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0013\">Mitel security advisory HPE Security Bulletin\u00a0\u2013 24-0013<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0014\">Mitel security advisory HPE Security Bulletin\u00a0\u2013 24-0014<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0015\">Mitel security advisory HPE Security Bulletin\u00a0\u2013 24-0015<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0016\">Mitel security advisory HPE Security Bulletin\u00a0\u2013 24-0016<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-291","alert_type":396,"serial_number":"AV24-291","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5233,"title":"Google Chrome security advisory (AV24-293)","uuid":"80ef07bd-0604-4e72-9999-aa9fd714541e","banner":null,"lang":"en","date_modified":"2024-05-24","date_modified_ts":"2024-05-24T16:18:28Z","date_created":"2024-05-24T15:18:19Z","summary":null,"body":["<article data-history-node-id=\"5233\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-293\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-293<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 24, 2024<\/p>\n\n<p>On May 23, 2024, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 125.0.6422.112\/.113 (Windows and Mac) and 125.0.6422.112 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/05\/stable-channel-update-for-desktop_23.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-293","alert_type":396,"serial_number":"AV24-293","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5234,"title":"Dell security advisory (AV24-294)","uuid":"cca40388-0074-4462-a0d4-3571e9862cee","banner":null,"lang":"en","date_modified":"2024-05-27","date_modified_ts":"2024-05-27T18:10:34Z","date_created":"2024-05-27T17:33:13Z","summary":null,"body":["<article data-history-node-id=\"5234\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-294\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-294<br \/><strong>Date: <\/strong>May\u00a027, 2024<\/p>\n\n<p>Between May\u00a020 and 26, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell NetWorker Runtime Environment (NRE)\u00a0\u2013 version 8.0.18<\/li>\n\t<li>Live Optics Windows and Live Optics PE Collector\u00a0\u2013 versions 25.1.12.151 and prior<\/li>\n\t<li>Dell EMC VxRail Appliance\u00a0\u2013 7.0.x versions prior to 7.0.484<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000225215\/dsa-2024-224-security-update-for-dell-networker-runtime-environment-nre-vulnerabilities\">Dell Security Update (Dell NetWorker Runtime Environment (NRE))<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000225301\/dsa-2024-205-security-update-for-dell-live-optics-collector-third-party-component-vulnerabilities\">Dell Security Update (Dell Live Optics Collector)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000225327\/dsa-2024-215-security-update-for-dell-vxrail-7-0-484-multiple-third-party-component-vulnerabilities\">Dell Security Update (Dell VxRail)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-294","alert_type":396,"serial_number":"AV24-294","subject":"dell","moderation_state":"published","external_url":null},{"nid":5235,"title":"Ubuntu security advisory (AV24-295)","uuid":"ff6c13f5-8f69-4631-abae-997cc695a091","banner":null,"lang":"en","date_modified":"2024-05-27","date_modified_ts":"2024-05-27T18:17:55Z","date_created":"2024-05-27T17:33:14Z","summary":null,"body":["<article data-history-node-id=\"5235\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-295\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-295<br \/><strong>Date: <\/strong>May\u00a027, 2024<\/p>\n\n<p>Between May\u00a020 and 26, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-295","alert_type":396,"serial_number":"AV24-295","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5236,"title":"IBM security advisory (AV24-296)","uuid":"30d54dd7-fa0e-4d77-8e0c-693e647146c9","banner":null,"lang":"en","date_modified":"2024-05-27","date_modified_ts":"2024-05-27T18:22:47Z","date_created":"2024-05-27T17:33:14Z","summary":null,"body":["<article data-history-node-id=\"5236\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-296\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-296<br \/><strong>Date: <\/strong>May\u00a027, 2024<\/p>\n\n<p>Between May\u00a020 and 26, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>CP4NA\u00a0\u2013 version 2.7.2<\/li>\n\t<li>Db2 Rest\u00a0\u2013 versions 1.0.0.121-amd64 to 1.0.0.301-amd64<\/li>\n\t<li>IBM Security Guardium\u00a0\u2013 versions 11.4, 11.5 and 12.0<\/li>\n\t<li>IBM Storage Fusion\u00a0\u2013 versions 2.3.0 to 2.7.1 and 2.5.0 to 2.7.2<\/li>\n\t<li>IBM Storage Fusion HCI\u00a0\u2013 versions 2.5.2 to 2.7.2<\/li>\n\t<li>IBM Storage Protect Plus Container Agent (Kubernetes)\u00a0\u2013 versions 10.1.5 to 10.1.12<\/li>\n\t<li>IBM Storage Protect Plus Container Agent (Red Hat OpenShift)\u00a0\u2013 versions 10.1.7 to 10.1.12<\/li>\n\t<li>ICP - Discovery\u00a0\u2013 versions 4.0.0 to 4.8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-296","alert_type":396,"serial_number":"AV24-296","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5237,"title":"Red Hat security advisory (AV24-297)","uuid":"f9cabb5d-0eaf-49aa-a4e5-6623eb63971a","banner":null,"lang":"en","date_modified":"2024-05-27","date_modified_ts":"2024-05-27T19:52:13Z","date_created":"2024-05-27T19:04:06Z","summary":null,"body":["<article data-history-node-id=\"5237\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-297\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-297<br \/><strong>Date: <\/strong>May\u00a027, 2024<\/p>\n\n<p>Between May\u00a020 and 26, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-297","alert_type":396,"serial_number":"AV24-297","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5238,"title":"[Control systems] CISA ICS security advisories (AV24-298)","uuid":"e925e690-86cd-4221-86bf-a546ba22b47b","banner":null,"lang":"en","date_modified":"2024-05-27","date_modified_ts":"2024-05-27T19:56:45Z","date_created":"2024-05-27T19:04:07Z","summary":null,"body":["<article data-history-node-id=\"5238\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-298\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-298<br \/><strong>Date: <\/strong>May\u00a027, 2024<\/p>\n\n<p>Between May\u00a020 and 26, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AutomationDirect Productivity PLCs\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>LCDS LAquis SCADA\u00a0\u2013 versions 4.7.1.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-144-01\">AutomationDirect Productivity PLCs<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-142-01\">LCDS LAquis SCADA<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-298","alert_type":398,"serial_number":"AV24-298","subject":"ics","moderation_state":"published","external_url":null},{"nid":5239,"title":"Microsoft Edge security advisory (AV24-299)","uuid":"f4cfc150-c13f-4c78-b387-a8247864d4db","banner":null,"lang":"en","date_modified":"2024-05-28","date_modified_ts":"2024-05-28T12:04:47Z","date_created":"2024-05-28T12:01:06Z","summary":null,"body":["<article data-history-node-id=\"5239\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-299\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-299<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 28, 2024<\/p>\n\n<p>On May 24, 2024, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 0.2535.67<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-5274 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-24-2024 \">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-299","alert_type":396,"serial_number":"AV24-299","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5240,"title":"Foxit security advisory (AV24-300)","uuid":"81320047-076a-44f2-87a8-808906d255fc","banner":null,"lang":"en","date_modified":"2024-05-28","date_modified_ts":"2024-05-28T12:13:03Z","date_created":"2024-05-28T12:06:13Z","summary":null,"body":["<article data-history-node-id=\"5240\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av24-300\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-300<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 28, 2024<\/p>\n\n<p>Between May 24 and May 26, 2024, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor for Windows\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader for Windows\u00a0\u2013 versions prior to 2024.2.1.25153<\/li>\n\t<li>Foxit PDF Editor for Mac\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader for Mac\u00a0\u2013 versions prior to 2024.2.1.64379<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av24-300","alert_type":396,"serial_number":"AV24-300","subject":"other","moderation_state":"published","external_url":null},{"nid":5241,"title":"HPE security advisory (AV24-301)","uuid":"627356e3-d6fd-46b9-ad5e-14c90c4aa13b","banner":null,"lang":"en","date_modified":"2024-05-28","date_modified_ts":"2024-05-28T15:48:41Z","date_created":"2024-05-28T15:37:13Z","summary":null,"body":["<article data-history-node-id=\"5241\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-301\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-301<br \/><strong>Date: <\/strong>May\u00a028, 2024<\/p>\n\n<p>On May\u00a027, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Tomcat-based Servlet v.9.x Engine\u00a0\u2013 version D.9.0.43.01 and prior.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04652en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbux04652<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-301","alert_type":396,"serial_number":"AV24-301","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5242,"title":"Citrix security advisory (AV24-302)","uuid":"01381555-ecde-4e95-8ce8-53a7ff29276b","banner":null,"lang":"en","date_modified":"2024-05-28","date_modified_ts":"2024-05-28T15:53:34Z","date_created":"2024-05-28T15:37:14Z","summary":null,"body":["<article data-history-node-id=\"5242\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av24-302\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-302<br \/><strong>Date: <\/strong>May\u00a028, 2024<\/p>\n\n<p>On May\u00a028, 2024, Citrix published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Citrix Workspace app for Mac\u00a0\u2013 version prior to 2402.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX675851\/citrix-workspace-app-for-mac-security-bulletin-for-cve20245027\">Citrix Security Advisory\u00a0\u2013 CTX675851<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av24-302","alert_type":396,"serial_number":"AV24-302","subject":"citrix","moderation_state":"published","external_url":null},{"nid":5243,"title":"Ivanti security advisory (AV24-303)","uuid":"d111e406-23c4-4143-b2e0-1b807b9f5089","banner":null,"lang":"en","date_modified":"2024-05-29","date_modified_ts":"2024-05-29T15:59:52Z","date_created":"2024-05-29T15:54:05Z","summary":null,"body":["<article data-history-node-id=\"5243\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-303\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-303<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 29, 2024<\/p>\n\n<p>On May 28, 2024, Ivanti published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager (EPM)\u00a0\u2013 unsupported version 2021.1 SU5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/CVE-2024-22058-Privilege-Escalation-for-Ivanti-Endpoint-Manager-EPM?language=en_US\">CVE-2024-22058 Privilege Escalation for Ivanti Endpoint Manager (EPM)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-303","alert_type":396,"serial_number":"AV24-303","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5244,"title":"Mitel security advisory (AV24-304)","uuid":"af11023b-ae04-4482-bb34-6e42143f70ec","banner":null,"lang":"en","date_modified":"2024-05-29","date_modified_ts":"2024-05-29T16:09:53Z","date_created":"2024-05-29T16:04:14Z","summary":null,"body":["<article data-history-node-id=\"5244\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-304\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n<p><strong>Serial number: <\/strong>AV24-304\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 29, 2024\n<\/p>\n<p>On May 29, 2024, Mitel published a Security Advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>MiVoice MX-ONE\u00a0\u2013 version 7.6 SP1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0017\">Mitel Security Advisory\u00a0- 24-0017<\/a><\/li>\n  <li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-304","alert_type":396,"serial_number":"AV24-304","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5245,"title":"Check Point security advisory (AV24-305)","uuid":"151fcf22-a0d6-47f1-8b41-3e297715117c","banner":null,"lang":"en","date_modified":"2024-05-29","date_modified_ts":"2024-05-29T20:15:58Z","date_created":"2024-05-29T19:42:59Z","summary":null,"body":["<article data-history-node-id=\"5245\" about=\"\/en\/alerts-advisories\/check-point-security-advisory-av24-305\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-305<br \/><strong>Date: <\/strong>May\u00a029, 2024<\/p>\n\n<p>On May\u00a027, 2024, Check Point published a security update to address a vulnerability in the following products:<\/p>\n\n<ul><li>CloudGuard Network\u00a0\u2013 multiple versions<\/li>\n\t<li>Quantum Maestro\u00a0\u2013 multiple versions<\/li>\n\t<li>Quantum Scalable Chassis\u00a0\u2013 multiple versions<\/li>\n\t<li>Quantum Security Gateways\u00a0\u2013 multiple versions<\/li>\n\t<li>Quantum Spark Appliances\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre has received reports that CVE-2024-24919 is being exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk182336\">Check Point Security Update\u00a0\u2013 sk182336<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/\">Check Point Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/check-point-security-advisory-av24-305","alert_type":396,"serial_number":"AV24-305","subject":"other","moderation_state":"published","external_url":null},{"nid":5247,"title":"Google Chrome security advisory (AV24-306)","uuid":"55c6c34f-2965-4b56-912a-9ac5ee267d94","banner":null,"lang":"en","date_modified":"2024-05-31","date_modified_ts":"2024-05-31T18:35:37Z","date_created":"2024-05-31T18:21:12Z","summary":null,"body":["<article data-history-node-id=\"5247\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-306\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-306<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 31, 2024<\/p>\n\n<p>On May 30, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 125.0.6422.141\/.142 (Windows and Mac) and 125.0.6422.141 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/05\/stable-channel-update-for-desktop_30.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-306","alert_type":396,"serial_number":"AV24-306","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5248,"title":"Vulnerability impacting Check Point Network Security Gateways (CVE-2024-24919)","uuid":"abd60553-36d0-4a94-9a00-d8f571b03294","banner":null,"lang":"en","date_modified":"2024-05-31","date_modified_ts":"2024-05-31T19:13:19Z","date_created":"2024-05-31T18:53:47Z","summary":null,"body":["<article data-history-node-id=\"5248\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-check-point-network-security-gateways-cve-2024-24919\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL24-007<br \/><strong>Date: <\/strong>May\u00a031, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a critical vulnerability (CVE-2024-24919) impacting Check Point Security Gateways with IPsec VPN blade enabled and in the Remote Access VPN community or with Mobile Access blade enabled<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. An unauthenticated threat actor can exploit this vulnerability to access sensitive information as superuser on the device<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. On May\u00a029, the Cyber Centre published AV24-305 to encourage readers to patch at their earliest opportunity<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre has received reports that this vulnerability is being actively exploited.<\/p>\n\n<p>The following Check Point products and versions are affected by this vulnerability:<\/p>\n\n<ul><li>Products:\n\t<ul><li>CloudGuard Network<\/li>\n\t\t<li>Quantum Maestro<\/li>\n\t\t<li>Quantum Scalable Chassis<\/li>\n\t\t<li>Quantum Security Gateways<\/li>\n\t\t<li>Quantum Spark Appliances<\/li>\n\t<\/ul><\/li>\n\t<li>Versions:\n\t<ul><li>R77.20 (EOL)<\/li>\n\t\t<li>R77.30 (EOL)<\/li>\n\t\t<li>R80.10 (EOL)<\/li>\n\t\t<li>R80.20 (EOL)<\/li>\n\t\t<li>R80.20.x<\/li>\n\t\t<li>R80.20SP (EOL)<\/li>\n\t\t<li>R80.30 (EOL)<\/li>\n\t\t<li>R80.30SP (EOL)<\/li>\n\t\t<li>R80.40 (EOL)<\/li>\n\t\t<li>R81<\/li>\n\t\t<li>R81.10<\/li>\n\t\t<li>R81.10.x<\/li>\n\t\t<li>R81.20<\/li>\n\t<\/ul><\/li>\n<\/ul><\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that:<\/p>\n\n<ul><li>Organizations using an affected device and version should ensure that the system is patched immediately<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/li>\n\t<li>All stored credentials and certificates present on the device should be reset or revoked both on the device and the enterprise environment.<\/li>\n\t<li>Organizations disable unused, local VPN accounts.<\/li>\n\t<li>Organizations should review connection logs to identify authorized connections from unknown sources.<\/li>\n\t<li>Organizations should review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> with an emphasis on the following topics:\n\t<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t\t<li>Patching operating systems and applications.<\/li>\n\t\t<li>Enforce the management of administrative privileges.<\/li>\n\t\t<li>Segmenting and separating information.<\/li>\n\t\t<li>Protecting information at the enterprise level.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <i>Official Languages Act<\/i> is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk182336\">Preventative Hotfix for CVE-2024-24919\u00a0- Quantum Gateway Information Disclosure<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1a-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/blog.checkpoint.com\/security\/enhance-your-vpn-security-posture\/\">Important Security Update\u00a0\u2013 Stay Protected Against VPN Information Disclosure (CVE-2024-24919)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/labs.watchtowr.com\/check-point-wrong-check-point-cve-2024-24919\/\">Check Point\u00a0\u2013 Wrong Check Point (CVE-2024-24919)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/check-point-security-advisory-av24-305\">Check Point security advisory (AV24-305)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-check-point-network-security-gateways-cve-2024-24919","alert_type":397,"serial_number":"AL24-007","subject":"other","moderation_state":"published","external_url":null},{"nid":5249,"title":"IBM security advisory (AV24-309)","uuid":"9d7acf75-3516-4255-ae56-ef4c2f3b8f02","banner":null,"lang":"en","date_modified":"2024-06-03","date_modified_ts":"2024-06-03T16:11:27Z","date_created":"2024-06-03T14:15:57Z","summary":null,"body":["<article data-history-node-id=\"5249\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-309\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-309<br \/><strong>Date: <\/strong>June\u00a03, 2024<\/p>\n\n<p>Between May\u00a027 and June\u00a02, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 versions 3.5 to refresh 10, 4.0 to refresh 9, 4.5 to refresh 3, 4.6 to refresh 6, 4.7 to refresh 4 and 4.7 to refresh 4<\/li>\n\t<li>IBM Planning Analytics Local\u00a0- IBM Planning Analytics Workspace\u00a0\u2013 versions 2.1 and 2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7155078\">IBM Security Bulletin\u00a0- Multiple vulnerabilities affect IBM Db2\u00ae on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7151122\">IBM Security Bulletin\u00a0- IBM Planning Analytics Workspace is affected by vulnerabilities in multiple Open Source Software (OSS) components<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-309","alert_type":396,"serial_number":"AV24-309","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5250,"title":"Dell security advisory (AV24-308)","uuid":"04dbd736-db2f-446d-a48d-ff594d99197b","banner":null,"lang":"en","date_modified":"2024-06-03","date_modified_ts":"2024-06-03T16:08:05Z","date_created":"2024-06-03T15:19:29Z","summary":null,"body":["<article data-history-node-id=\"5250\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-308\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-308<br \/><strong>Date: <\/strong>June\u00a03, 2024<\/p>\n\n<p>Between May\u00a027 and June\u00a02, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Live Optics Linux Collector\u00a0\u2013 versions prior to 25.1.10.29<\/li>\n\t<li>Live Optics Windows Collector and Live Optics PE Collector\u00a0\u2013 versions prior to 25.2.1.153<\/li>\n\t<li>PowerStore 1000T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 1200T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 3000T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 3200T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 5000T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 500T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 5200T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 7000T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 9000T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n\t<li>PowerStore 9200T\u00a0\u2013 versions prior to 4.0.0.0 to 2284811<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-308","alert_type":396,"serial_number":"AV24-308","subject":"dell","moderation_state":"published","external_url":null},{"nid":5251,"title":"[Control systems] CISA ICS security advisories (AV24-307)","uuid":"5757e88e-c191-4965-a8c5-514ad5f35d1c","banner":null,"lang":"en","date_modified":"2024-06-03","date_modified_ts":"2024-06-03T15:56:11Z","date_created":"2024-06-03T15:46:32Z","summary":null,"body":["<article data-history-node-id=\"5251\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-307\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-307<br \/><strong>Date: <\/strong>June\u00a03, 2024<\/p>\n\n<p>Between May\u00a027 and June\u00a02, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Baxter Welch Allyn Connex Spot Monitor (CSM)\u00a0\u2013 version 1.52 and prior<\/li>\n\t<li>Baxter Welch Allyn Product Configuration Tool\u00a0\u2013 version 1.9.4.1 and prior<\/li>\n\t<li>Campbell Scientific CSI Web Server\u00a0\u2013 version 1.6 and prior<\/li>\n\t<li>Campbell Scientific RTMC Pro\u00a0\u2013 version 5.0 and prior<\/li>\n\t<li>Fuji Electric Monitouch V-SFT\u00a0\u2013 versions prior to 6.2.3.0<\/li>\n\t<li>Inosoft VisiWin 7\u00a0\u2013 versions prior to 2024-1<\/li>\n\t<li>LenelS2 NetBox\u00a0\u2013 versions prior to 5.6.2<\/li>\n\t<li>Westermo EDW-100\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-307","alert_type":398,"serial_number":"AV24-307","subject":"ics","moderation_state":"published","external_url":null},{"nid":5252,"title":"Ubuntu security advisory (AV24-310)","uuid":"113a0800-4989-4d24-a89e-4993f5699cc2","banner":null,"lang":"en","date_modified":"2024-06-03","date_modified_ts":"2024-06-03T17:55:14Z","date_created":"2024-06-03T17:17:55Z","summary":null,"body":["<article data-history-node-id=\"5252\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-310\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-310<br \/><strong>Date: <\/strong>June\u00a03, 2024<\/p>\n\n<p>Between May\u00a027 and June\u00a02, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6795-1\">USN-6795-1\u00a0- Linux kernel (Intel IoTG) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-310","alert_type":396,"serial_number":"AV24-310","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5254,"title":"[Control systems] ABB security advisory (AV24-312)","uuid":"d6c92891-aac6-444a-8de7-fc28e1016152","banner":null,"lang":"en","date_modified":"2024-06-03","date_modified_ts":"2024-06-03T18:24:30Z","date_created":"2024-06-03T17:17:56Z","summary":null,"body":["<article data-history-node-id=\"5254\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-312\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-312<br \/><strong>Date: <\/strong>June\u00a03, 2024<\/p>\n\n<p>On June\u00a03, 2024, ABB published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>WebPro SNMP card PowerValue\u00a0\u2013 version 1.1.8.j and prior<\/li>\n\t<li>WebPro SNMP card PowerValue UL\u00a0\u2013 version 1.1.8.j and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2CMT006108&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB WebPro SNMP card PowerValue Cross-Site Scripting (XSS) vulnerability (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-312","alert_type":398,"serial_number":"AV24-312","subject":"abb","moderation_state":"published","external_url":null},{"nid":5253,"title":"Red Hat security advisory (AV24-311)","uuid":"72182bf2-4e8f-42b8-b754-7b5876f925eb","banner":null,"lang":"en","date_modified":"2024-06-03","date_modified_ts":"2024-06-03T18:07:55Z","date_created":"2024-06-03T17:18:00Z","summary":null,"body":["<article data-history-node-id=\"5253\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-311\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-311<br \/><strong>Date: <\/strong>June\u00a03, 2024<\/p>\n\n<p>Between May\u00a027 and June\u00a02, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Virtualization Host 4 for RHEL 8 x86_64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-311","alert_type":396,"serial_number":"AV24-311","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5255,"title":"Android security advisory \u2013 June 2024 Monthly Rollup (AV24-313)","uuid":"194c31cc-9e3b-471d-87ec-f0a24ca48f9e","banner":null,"lang":"en","date_modified":"2024-06-03","date_modified_ts":"2024-06-03T18:31:20Z","date_created":"2024-06-03T18:27:04Z","summary":null,"body":["<article data-history-node-id=\"5255\" about=\"\/en\/alerts-advisories\/android-security-advisory-june-2024-monthly-rollup-av24-313\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-313<br \/><strong>Date: <\/strong>June\u00a03, 2024<\/p>\n\n<p>On June\u00a03, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-06-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-june-2024-monthly-rollup-av24-313","alert_type":396,"serial_number":"AV24-313","subject":"android","moderation_state":"published","external_url":null},{"nid":5256,"title":"Microsoft Edge security advisory (AV24-314)","uuid":"d235fdcb-8ee9-4a60-9102-c42aa7260b19","banner":null,"lang":"en","date_modified":"2024-06-04","date_modified_ts":"2024-06-04T14:29:08Z","date_created":"2024-06-04T14:01:12Z","summary":null,"body":["<article data-history-node-id=\"5256\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-314\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-314<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 4, 2024<\/p>\n\n<p>On June 3, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 125.0.2535.85<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-314","alert_type":396,"serial_number":"AV24-314","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5257,"title":"HPE security advisory (AV24-315)","uuid":"c3743e76-b0d5-4832-a99b-4cf0322e4c0c","banner":null,"lang":"en","date_modified":"2024-06-05","date_modified_ts":"2024-06-05T13:19:31Z","date_created":"2024-06-05T13:11:58Z","summary":null,"body":["<article data-history-node-id=\"5257\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-315\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-315<br \/><strong>Date: <\/strong>June\u00a05, 2024<\/p>\n\n<p>On June\u00a04, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Alletra 4110\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE Alletra 4120\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant DL110 Gen11\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant DL320 Gen11 Server\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant DL360 Gen11 Server\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant DL380 Gen11 Server\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant DL380a Gen11\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant DL560 Gen11\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant ML110 Gen11\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant ML350 Gen11 Server\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE Compute Edge Server e930t\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE Synergy 480 Gen11 Compute Module\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04642en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04642en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-315","alert_type":396,"serial_number":"AV24-315","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5258,"title":"[Control systems] ABB security advisory (AV24-316)","uuid":"ab29ef81-e35e-4fcb-9c86-983099408921","banner":null,"lang":"en","date_modified":"2024-06-06","date_modified_ts":"2024-06-06T13:21:45Z","date_created":"2024-06-06T13:14:46Z","summary":null,"body":["<article data-history-node-id=\"5258\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-316\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-316<br \/><strong>Date: <\/strong>June\u00a05, 2024<\/p>\n\n<p>On June\u00a04, 2024, ABB published an ICS advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>2,4\" Display 55\u00a0\u2013 version 1.00<\/li>\n\t<li>2,4\" Display 63\u00a0\u2013 version 1.00<\/li>\n\t<li>2,4\" Display 70\u00a0\u2013 version 1.00<\/li>\n\t<li>RoomTouch 4\"\u00a0\u2013 version 1.00<\/li>\n\t<li>Bus Coupling Unit KNX\u00a0\u2013 version 1.3.0.33<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108464A0803&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">KNX Secure Devices FDSK Leak and replay attack (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-316","alert_type":398,"serial_number":"AV24-316","subject":"abb","moderation_state":"published","external_url":null},{"nid":5261,"title":"HPE security advisory (AV24-317)","uuid":"0b486811-c4bb-43e7-8801-c2dc787b14c3","banner":null,"lang":"en","date_modified":"2024-06-06","date_modified_ts":"2024-06-06T18:38:41Z","date_created":"2024-06-06T18:33:34Z","summary":null,"body":["<article data-history-node-id=\"5261\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-317\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-317<br \/><strong>Date: <\/strong>June\u00a06, 2024<\/p>\n\n<p>On June\u00a05, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE StoreEasy 1670 Performance Storage\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE StoreEasy 1670 Storage\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE StoreEasy 1870 Performance Storage\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE StoreEasy 1870 Storage\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04651en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04651en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-317","alert_type":396,"serial_number":"AV24-317","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5262,"title":"SolarWinds security advisory (AV24-318)","uuid":"4caa0859-cb00-4f66-ba70-e2d135d6871f","banner":null,"lang":"en","date_modified":"2024-06-06","date_modified_ts":"2024-06-06T18:50:00Z","date_created":"2024-06-06T18:33:34Z","summary":null,"body":["<article data-history-node-id=\"5262\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-318\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-318<br \/><strong>Date: <\/strong>June\u00a06, 2024<\/p>\n\n<p>Between June\u00a04 and 5, 2024, SolarWinds published security advisories to address vulnerabilities multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SolarWinds Platform\u00a0\u2013 version 2024.1 SR 1 and prior<\/li>\n\t<li>SolarWinds Serv-U\u00a0\u2013 version 15.4.2 HF 1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-28996\">SolarWinds Platform SWQL Injection Vulnerability (CVE-2024-28996)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-28995\">SolarWinds Serv-U Directory Transversal Vulnerability (CVE-2024-28995)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-318","alert_type":396,"serial_number":"AV24-318","subject":"other","moderation_state":"published","external_url":null},{"nid":5263,"title":"[Control systems] CISA ICS security advisories (AV24-319)","uuid":"c0a96359-dc44-428b-9329-07b943081027","banner":null,"lang":"en","date_modified":"2024-06-10","date_modified_ts":"2024-06-10T12:58:39Z","date_created":"2024-06-10T12:28:20Z","summary":null,"body":["<article data-history-node-id=\"5263\" about=\"\/en\/alerts-advisories\/cisa-ics-security-advisories-av24-319\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-319<br \/><strong>Date: <\/strong>June 10, 2024<\/p>\n\n<p>Between June 3 and 9, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Emerson PAC Machine Edition\u00a0\u2013 all versions<\/li>\n\t<li>Emerson PACSystem RXi\u00a0\u2013 all versions<\/li>\n\t<li>Emerson PACSystem RX3i\u00a0\u2013 all versions<\/li>\n\t<li>Emerson PACSystem RSTi-EP\u00a0\u2013 all versions<\/li>\n\t<li>Emerson PACSystem VersaMax\u00a0\u2013 all versions<\/li>\n\t<li>Emerson Fanuc VersaMax\u00a0\u2013 all versions<\/li>\n\t<li>Emerson Ovation\u00a0\u2013 version 3.8.0 feature pack 1 and prior<\/li>\n\t<li>Johnson Controls Software House iStar Pro Door Controller\u00a0\u2013 all versions<\/li>\n\t<li>Johnson Controls ICU\u00a0- version 6.9.2.25888 and prior<\/li>\n\t<li>Mitsubishi NZ2MHG-TSNT8F2\u00a0\u2013 versions 05 and prior<\/li>\n\t<li>Mitsubishi NZ2MHG-TSNT4\u00a0\u2013 versions 05 and prior<\/li>\n\t<li>Uniview NVR301-04S2-P4\u00a0\u2013 versions prior to NVR-B3801.20.17.240507<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisa-ics-security-advisories-av24-319","alert_type":398,"serial_number":"AV24-319","subject":"ics","moderation_state":"published","external_url":null},{"nid":5264,"title":"Dell security advisory (AV24-320)","uuid":"c3c04c4c-b8bf-499b-8f5e-2b6941103d7c","banner":null,"lang":"en","date_modified":"2024-06-10","date_modified_ts":"2024-06-10T13:10:24Z","date_created":"2024-06-10T13:01:42Z","summary":null,"body":["<article data-history-node-id=\"5264\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-320\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-320<br \/><strong>Date: <\/strong>June 10, 2024<\/p>\n\n<p>Between June 3 and 9, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance\u00a0- 8.0.x versions prior to 8.0.212<\/li>\n\t<li>Dell PowerScale OneFS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000225667\/dsa-2024-210-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities\">Dell Security Advisory\u00a0- DSA-2024-210<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000225710\/dsa-2024-244-security-update-for-dell-vxrail-8-0-212-multiple-third-party-component-vulnerabilities\">Dell Security Advisory\u00a0- DSA-2024-244<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-320","alert_type":396,"serial_number":"AV24-320","subject":"dell","moderation_state":"published","external_url":null},{"nid":5265,"title":"IBM security advisory (AV24-321)","uuid":"fcefda2c-a0a4-4475-995b-0bf011ec9e56","banner":null,"lang":"en","date_modified":"2024-06-10","date_modified_ts":"2024-06-10T13:31:08Z","date_created":"2024-06-10T13:12:08Z","summary":null,"body":["<article data-history-node-id=\"5265\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-321\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-321<br \/><strong>Date: <\/strong>June 10, 2024<\/p>\n\n<p>Between June 3 and 9, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container\u00a0\u2013 versions 5.0-lts, 10.1, 11.0, 11.1, 11.2 and 11.3<\/li>\n\t<li>IBM ICP - Discovery\u00a0\u2013 version 4.0.0 to 4.8.4<\/li>\n\t<li>IBM Jazz Foundation\u00a0\u2013 version 7.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7156386\">IBM Security Bulletin\u00a0- 7156386<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7156617\">IBM Security Bulletin\u00a0- 7156617<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7156475\">IBM Security Bulletin\u00a0- 7156475<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-321","alert_type":396,"serial_number":"AV24-321","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5266,"title":"Ubuntu security advisory (AV24-322)","uuid":"d8d3d7da-f353-4cc8-86b7-e1456524bf50","banner":null,"lang":"en","date_modified":"2024-06-10","date_modified_ts":"2024-06-10T13:43:40Z","date_created":"2024-06-10T13:37:55Z","summary":null,"body":["<article data-history-node-id=\"5266\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-322\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-322<br \/><strong>Date: <\/strong>June 10, 2024<\/p>\n\n<p>Between June 3 and 9, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6816-1\">USN-6816-1\u00a0- Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-322","alert_type":396,"serial_number":"AV24-322","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5267,"title":"Red Hat security advisory (AV24-323)","uuid":"8f6a1005-c0a9-4db5-aad8-4fa11ae4a20c","banner":null,"lang":"en","date_modified":"2024-06-10","date_modified_ts":"2024-06-10T13:58:42Z","date_created":"2024-06-10T13:47:02Z","summary":null,"body":["<article data-history-node-id=\"5267\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-323\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-323<br \/><strong>Date: <\/strong>June 10, 2024<\/p>\n\n<p>Between June 3 and 9, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:3618\">Red Hat Security Advisory\u00a0- RHSA-2024:3618<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:3619\">Red Hat Security Advisory\u00a0- RHSA-2024:3619<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:3627\">Red Hat Security Advisory\u00a0- RHSA-2024:3627<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-323","alert_type":396,"serial_number":"AV24-323","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5268,"title":"HPE security advisory (AV24-324)","uuid":"db786b24-5320-4089-97b8-2f0b53110896","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T13:33:33Z","date_created":"2024-06-11T13:15:14Z","summary":null,"body":["<article data-history-node-id=\"5268\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-324\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-324<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 11, 2024<\/p>\n\n<p>On June 11, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified Topology Manager (UTM)\u00a0\u2013 versions prior to v4.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04655en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbgn04655en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-324","alert_type":396,"serial_number":"AV24-324","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5269,"title":"SAP security advisory \u2013 June 2024 monthly rollup (AV24-325)","uuid":"291ebaf9-aafb-463b-97e8-118147ad5694","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T14:50:26Z","date_created":"2024-06-11T13:38:10Z","summary":null,"body":["<article data-history-node-id=\"5269\" about=\"\/en\/alerts-advisories\/sap-security-advisory-june-2024-monthly-rollup-av24-325\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-325<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 11, 2024<\/p>\n\n<p>On June 11, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Financial Consolidation\u00a0\u2013 version FINANCE 1010<\/li>\n\t<li>SAP NetWeaver AS Java\u00a0\u2013 version MMR_SERVER 7.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/june-2024.html\">SAP Security Patch Day\u00a0- June 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-june-2024-monthly-rollup-av24-325","alert_type":396,"serial_number":"AV24-325","subject":"sap","moderation_state":"published","external_url":null},{"nid":5270,"title":"Mozilla security advisory (AV24-327)","uuid":"c0bb2357-1b74-46ce-b87a-38334de937e7","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T15:41:09Z","date_created":"2024-06-11T14:54:33Z","summary":null,"body":["<article data-history-node-id=\"5270\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-327\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-327<br \/><strong>Date: <\/strong>June\u00a011, 2024<\/p>\n\n<p>On June\u00a011, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 127<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-25\/\">Mozilla Security Advisory\u00a0- MFSA 2024-25<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-26\/\">Mozilla Security Advisory\u00a0- MFSA 2024-26<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-327","alert_type":396,"serial_number":"AV24-327","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5271,"title":"[Control systems] Schneider Electric security advisory (AV24-326)","uuid":"ae7245b2-ca79-427c-81f7-725e8f644315","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T15:13:05Z","date_created":"2024-06-11T15:07:01Z","summary":null,"body":["<article data-history-node-id=\"5271\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-326\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-326<br \/><strong>Date: <\/strong>June\u00a011, 2024<\/p>\n\n<p>On June\u00a011, 2024, Schneider Electric published security advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>EVlink Home Smart\u00a0\u2013 version v2.0.4.1.2_131 and v2.0.3.8.2_128<\/li>\n\t<li>Modicon M340\u00a0\u2013 all versions<\/li>\n\t<li>Network module, Modicon M340, Modbus\/TCP BMXNOE0100\u00a0\u2013 all versions<\/li>\n\t<li>Network module, Modicon M340, Ethernet TCP\/IP BMXNOE0110\u00a0\u2013 all versions<\/li>\n\t<li>PowerLogic P5\u00a0\u2013 version v01.500.101 and prior<\/li>\n\t<li>Sage 1410\u00a0\u2013 version C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Sage 1430\u00a0\u2013 version C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Sage 1450\u00a0\u2013 version C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Sage 2400\u00a0\u2013 version C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Sage 3030 Magnum\u00a0\u2013 version C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Sage 4400\u00a0\u2013 version C3414-500-S02K5_P8 and prior<\/li>\n\t<li>SpaceLogic AS-P\u00a0\u2013 version v5.0.3 and prior<\/li>\n\t<li>SpaceLogic AS-B\u00a0\u2013 version v5.0.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-326","alert_type":398,"serial_number":"AV24-326","subject":"se","moderation_state":"published","external_url":null},{"nid":5272,"title":"[Control systems] Siemens security advisory (AV24-328) ","uuid":"c656384f-08d0-4cbd-afb5-7f36b9df4314","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T17:26:44Z","date_created":"2024-06-11T16:49:08Z","summary":null,"body":["<article data-history-node-id=\"5272\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-328\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-328<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 11, 2024<\/p>\n\n<p>On June 11, 2024, Siemens published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CPCX26 Central Processing\/Communication\u00a0\u2013 versions prior to V06.02<\/li>\n\t<li>ETA4 Ethernet Interface IEC60870-5-104\u00a0\u2013 versions prior to V10.46<\/li>\n\t<li>ETA5 Ethernet Int. 1x100TX IEC61850 Ed.2\u00a0\u2013 versions prior to V03.27<\/li>\n\t<li>JT2Go\u00a0\u2013 versions prior to V2312.0004<\/li>\n\t<li>Mendix Applications using Mendix 10\u00a0\u2013 versions prior to V10.11.0<\/li>\n\t<li>Mendix Applications using Mendix 10 (V10.6)\u00a0\u2013 versions prior to V10.6.9<\/li>\n\t<li>Mendix Applications using Mendix 9\u00a0\u2013 versions V9.3.0 to versions prior to V9.24.22<\/li>\n\t<li>PCCX26 Ax 1703 PE, Contr, Communication Element\u00a0\u2013 versions prior to V06.05<\/li>\n\t<li>PowerSys\u00a0\u2013 versions prior to V3.11<\/li>\n\t<li>SCALANCE W700 802.11 AX Family\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SCALANCE XM-400\/XR-500\u00a0\u2013 versions prior to V6.6.1 and multiple platforms<\/li>\n\t<li>SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0)\u00a0\u2013 versions prior to V2.3<\/li>\n\t<li>SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0)\u00a0\u2013 versions prior to V2.3<\/li>\n\t<li>SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0)\u00a0\u2013 versions prior to V2.3<\/li>\n\t<li>SIMATIC S7-200 SMART CPU \u2013 multiple versions and platforms<\/li>\n\t<li>SINEC Traffic Analyzer (6GK8822-1BG01-0BA0)\u00a0\u2013 versions prior to V1.2<\/li>\n\t<li>SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0)\u00a0\u2013 versions prior to V2.3<\/li>\n\t<li>SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0)\u00a0\u2013 versions prior to V2.3<\/li>\n\t<li>SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0)\u00a0\u2013 versions prior to V2.3<\/li>\n\t<li>SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)\u00a0\u2013 versions prior to V2.4.8<\/li>\n\t<li>SITOP UPS1600 10 A Ethernet\/ PROFINET (6EP4134-3AB00-2AY0)\u00a0\u2013 versions prior to V2.5.4<\/li>\n\t<li>SITOP UPS1600 20 A Ethernet\/ PROFINET (6EP4136-3AB00-2AY0)\u00a0\u2013 versions prior to V2.5.4<\/li>\n\t<li>SITOP UPS1600 40 A Ethernet\/ PROFINET (6EP4137-3AB00-2AY0)\u00a0\u2013 versions prior to V2.5.4<\/li>\n\t<li>SITOP UPS1600 EX 20 A Ethernet PROFINET (6EP4136-3AC00-2AY0)\u00a0\u2013 versions prior to V2.5.4<\/li>\n\t<li>ST7 ScadaConnect (6NH7997-5DA10-0AA0) \u2013 versions prior to V1.1<\/li>\n\t<li>Teamcenter Visualization V14.2\u00a0\u2013 all versions<\/li>\n\t<li>Teamcenter Visualization V14.3\u00a0\u2013 versions prior to V14.3.0.9<\/li>\n\t<li>Teamcenter Visualization V2312\u00a0\u2013 versions prior to V2312.0004<\/li>\n\t<li>Tecnomatix Plant Simulation V2302\u00a0\u2013 versions prior to V2302.0012<\/li>\n\t<li>Tecnomatix Plant Simulation V2404\u00a0\u2013 versions prior to V2404.0001<\/li>\n\t<li>TIA Administrator\u00a0\u2013 versions prior to V3 SP2<\/li>\n\t<li>TIM 1531 IRC (6GK7543-1MX00-0XE0)\u00a0\u2013 versions prior to V2.4.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-328","alert_type":398,"serial_number":"AV24-328","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5273,"title":"JetBrains security advisory (AV24-329)","uuid":"b55a8514-bae6-469c-8bf0-ce4eb4ad775f","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T17:56:57Z","date_created":"2024-06-11T17:50:50Z","summary":null,"body":["<article data-history-node-id=\"5273\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av24-329\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-329<br \/><strong>Date: <\/strong>June\u00a011, 2024<\/p>\n\n<p>On June\u00a010, 2024, JetBrains published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Aqua\u00a0\u2013 versions prior to 2024.1.2<\/li>\n\t<li>CLion\u00a0\u2013 versions prior to 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3 and 2024.2 EAP2<\/li>\n\t<li>DataGrip\u00a0\u2013 versions prior to 2023.1.3, 2023.2.4, 2023.3.5 and 2024.1.4<\/li>\n\t<li>DataSpell\u00a0\u2013 versions prior to 2023.1.6, 2023.2.7, 2023.3.6 and 2024.1.2 EAP1<\/li>\n\t<li>GoLand\u00a0\u2013 versions prior to 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3 and 2024.2 EAP3<\/li>\n\t<li>IntelliJ IDEA\u00a0\u2013 versions prior to 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3 and 2024.2 EAP3<\/li>\n\t<li>MPS\u00a0\u2013 versions prior to 2023.2.1, 2023.3.1 and 2024.1 EAP2<\/li>\n\t<li>PhpStorm\u00a0\u2013 versions prior to 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3 and 2024.2 EAP3<\/li>\n\t<li>PyCharm\u00a0\u2013 versions prior to 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3 and 2024.2 EAP2<\/li>\n\t<li>Rider\u00a0\u2013 versions prior to 2023.1.7, 2023.2.5, 2023.3.6 and 2024.1.3<\/li>\n\t<li>RubyMine\u00a0\u2013 versions prior to 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3 and 2024.2 EAP4<\/li>\n\t<li>RustRover\u00a0\u2013 versions prior to 2024.1.1<\/li>\n\t<li>WebStorm\u00a0\u2013 versions prior to 2023.1.6, 2023.2.7, 2023.3.7 and 2024.1.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.jetbrains.com\/security\/2024\/06\/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin\/\">JetBrains Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains Fixed Security Issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av24-329","alert_type":396,"serial_number":"AV24-329","subject":"other","moderation_state":"published","external_url":null},{"nid":5274,"title":"Microsoft security advisory \u2013 June 2024 monthly rollup (AV24-330)","uuid":"4c44cd4c-e7d6-43b0-8c27-c1cd9e3381ff","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T19:07:29Z","date_created":"2024-06-11T18:41:18Z","summary":null,"body":["<article data-history-node-id=\"5274\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-june-2024-monthly-rollup-av24-330\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n<p><strong>Serial number: <\/strong>AV24-330\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 11, 2024\n<\/p>\n<p>On June 11, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:\n<\/p>\n<ul><li>Azure Data Science Virtual Machines for Linux<\/li>\n  <li>Azure File Sync<\/li>\n  <li>Azure Identity Library<\/li>\n  <li>Azure Monitor Agent<\/li>\n  <li>Azure Storage Movement Client Library for .NET<\/li>\n  <li>Microsoft 365 Apps for Enterprise\u00a0\u2013 multiple platforms<\/li>\n  <li>Microsoft Authentication Library (MSAL)<\/li>\n  <li>Microsoft Dynamics 365 Business Central 2023 Release Wave 1<\/li>\n  <li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Microsoft Outlook 2016<\/li>\n  <li>Microsoft SharePoint Server\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Microsoft Visual Studio\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Jun\">June 2024 Release Notes<\/a><\/li>\n  <li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-june-2024-monthly-rollup-av24-330","alert_type":396,"serial_number":"AV24-330","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5275,"title":"Adobe security advisory (AV24-331)","uuid":"56a03796-e04e-44c5-a8b6-1cbcf1b4d068","banner":null,"lang":"en","date_modified":"2024-06-11","date_modified_ts":"2024-06-11T19:34:03Z","date_created":"2024-06-11T19:28:45Z","summary":null,"body":["<article data-history-node-id=\"5275\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-331\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-331<br \/><strong>Date: <\/strong>June\u00a011, 2024<\/p>\n\n<p>On June\u00a011, 2024, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Commerce Webhooks Plugin\u00a0\u2013 versions 1.2.0 to 1.4.0<\/li>\n\t<li>Adobe Experience Manager\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe FrameMaker Publishing Server\u00a0\u2013 versions prior to 2022.3<\/li>\n\t<li>Adobe Photoshop 2023\u00a0\u2013 versions prior to 24.7.4<\/li>\n\t<li>Adobe Photoshop 2024\u00a0\u2013 versions prior to 25.9<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 versions prior to 3.0.2<\/li>\n\t<li>ColdFusion 2021\u00a0\u2013 versions prior to Update 14<\/li>\n\t<li>ColdFusion 2023\u00a0\u2013 versions prior to Update 8<\/li>\n\t<li>Magneto Open Source\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-331","alert_type":396,"serial_number":"AV24-331","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5276,"title":"Google Chrome security advisory (AV24-332)","uuid":"6f338257-f3ae-4bf5-8792-f9929ad0e2e2","banner":null,"lang":"en","date_modified":"2024-06-12","date_modified_ts":"2024-06-12T12:37:21Z","date_created":"2024-06-12T12:30:05Z","summary":null,"body":["<article data-history-node-id=\"5276\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-332\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-332<br \/><strong>Date: <\/strong>June 12, 2024<\/p>\n\n<p>On June 11, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 126.0.6478.56\/57 (Windows and Mac) and 126.0.6478.54 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/06\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-332","alert_type":396,"serial_number":"AV24-332","subject":"other","moderation_state":"published","external_url":null},{"nid":5277,"title":"Veeam security advisory (AV24-333)","uuid":"83b45f48-1fbf-420f-841d-b3815677d579","banner":null,"lang":"en","date_modified":"2024-06-12","date_modified_ts":"2024-06-12T14:45:37Z","date_created":"2024-06-12T14:39:29Z","summary":null,"body":["<article data-history-node-id=\"5277\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av24-333\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-333<br \/><strong>Date: <\/strong>June 12, 2024<\/p>\n\n<p>On June 10, 2024, Veeam published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Veeam Recovery Orchestrator\u00a0\u2013 versions prior to 7.1.0.230 and versions prior to 7.0.0.379<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4585\">Veeam Security Advisory\u00a0\u2013 kb4585<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av24-333","alert_type":396,"serial_number":"AV24-333","subject":"other","moderation_state":"published","external_url":null},{"nid":5278,"title":"Unauthorized user access to Snowflake customer accounts","uuid":"4f825c59-9a59-4062-8800-20f3540d7027","banner":null,"lang":"en","date_modified":"2024-06-12","date_modified_ts":"2024-06-12T18:42:09Z","date_created":"2024-06-12T18:40:37Z","summary":null,"body":["<article data-history-node-id=\"5278\" about=\"\/en\/alerts-advisories\/unauthorized-user-access-snowflake-customer-accounts\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL24-008<br \/><strong>Date: <\/strong>June\u00a012, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of incidents impacting Snowflake customer data through unauthorized access resulting from malicious identity-based activity. Snowflake has reported that the activity is not the result of a vulnerability within Snowflake products<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that:<\/p>\n\n<ul><li>Organizations review guidance provided by Snowflake to aid in the detection of suspicious activity and harden user accounts<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. Organizations should also enable Multi-Factor Authentication (MFA)<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/li>\n\t<li>The Cyber Centre has published guidance on defence in depth strategies for cloud-based services<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. Organizations are encouraged to review the published guidance for security considerations.<\/li>\n\t<li>Organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> with an emphasis on the following topics:\n\t<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t\t<li>Enforce the management of administrative privileges.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <i>Official Languages Act<\/i> is in the language(s) provided.<\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/community.snowflake.com\/s\/article\/Communication-ID-0108977-Additional-Information\">Detecting and Preventing Unauthorized User Access: Instructions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1a-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/docs.snowflake.com\/en\/user-guide\/security-mfa\">Multi-factor authentication (MFA)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/guidance\/itsp50104-guidance-defence-depth-cloud-based-services\">ITSP.50.104 Guidance on defence in depth for cloud-based services<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/unauthorized-user-access-snowflake-customer-accounts","alert_type":397,"serial_number":"AL24-008","subject":"other","moderation_state":"published","external_url":null},{"nid":5279,"title":"[Control systems] ABB security advisory (AV24-334) ","uuid":"ca7d5c23-3b9a-49c9-ae50-fa136a64c316","banner":null,"lang":"en","date_modified":"2024-06-12","date_modified_ts":"2024-06-12T18:53:51Z","date_created":"2024-06-12T18:41:07Z","summary":null,"body":["<article data-history-node-id=\"5279\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-334\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-334<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 12, 2024<\/p>\n\n<p>On June 12, 2024, ABB published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB 800xA Base\u00a0\u2013 version 6.1.1-2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA013309&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB 800xA Base 6.0.x, 6.1.x CSLib communication DoS vulnerability (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-334","alert_type":398,"serial_number":"AV24-334","subject":"abb","moderation_state":"published","external_url":null},{"nid":5282,"title":"Google Chrome security advisory (AV24-335)","uuid":"966f04df-7ce2-43fa-97b1-ae4610ee16b2","banner":null,"lang":"en","date_modified":"2024-06-14","date_modified_ts":"2024-06-14T14:43:25Z","date_created":"2024-06-14T14:33:32Z","summary":null,"body":["<article data-history-node-id=\"5282\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-335\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-335<br \/><strong>Date: <\/strong>June 14, 2024<\/p>\n\n<p>On June 13, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 126.0.6478.61\/.62 (Windows and Mac) and 126.0.6478.61 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/06\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-335","alert_type":396,"serial_number":"AV24-335","subject":"other","moderation_state":"published","external_url":null},{"nid":5283,"title":"Microsoft Edge security advisory (AV24-336)","uuid":"a255eca2-96ab-4e5a-a4cd-d9e88d053f78","banner":null,"lang":"en","date_modified":"2024-06-14","date_modified_ts":"2024-06-14T14:52:03Z","date_created":"2024-06-14T14:44:32Z","summary":null,"body":["<article data-history-node-id=\"5283\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-336\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-336<br \/><strong>Date: <\/strong>June 14, 2024<\/p>\n\n<p>On June 13, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 0.2592.56<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-13-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-336","alert_type":396,"serial_number":"AV24-336","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5284,"title":"Mozilla security advisory (AV24-337)","uuid":"813af59b-f718-4658-997d-3bc76f493698","banner":null,"lang":"en","date_modified":"2024-06-14","date_modified_ts":"2024-06-14T15:04:30Z","date_created":"2024-06-14T14:53:44Z","summary":null,"body":["<article data-history-node-id=\"5284\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-337\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-337<br \/><strong>Date: <\/strong>June 14, 2024<\/p>\n\n<p>On June 13, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox for iOS\u00a0\u2013 versions prior to 127<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 115.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-27\/\">Mozilla Security Advisory\u00a0- MFSA 2024-27<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-28\/\">Mozilla Security Advisory\u00a0- MFSA 2024-28<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisory\u00a0<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-337","alert_type":396,"serial_number":"AV24-337","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5285,"title":"Dell security advisory (AV24-338)","uuid":"02d5e448-7eae-4a3e-82d7-1b93165419cd","banner":null,"lang":"en","date_modified":"2024-06-17","date_modified_ts":"2024-06-17T14:09:26Z","date_created":"2024-06-17T13:36:45Z","summary":null,"body":["<article data-history-node-id=\"5285\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-338\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-338<br \/><strong>Date: <\/strong>June 17, 2024<\/p>\n\n<p>Between June 10 and 16, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell Data Protection Central\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Secure Connect Gateway\u00a0\u2013 version 5.22.00.18<\/li>\n\t<li>PowerProtect DP Series (Integrated Data Protection Appliance (IDPA) Appliance)\u00a0\u2013 version 2.7.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000225991\/dsa-2024-253-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory\u00a0\u2013 DSA-2024-253<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000225893\/dsa-2024-266-security-update-for-dell-data-protection-central-for-multiple-security-vulnerabilities\">Dell Security Advisory\u00a0\u2013 DSA-2024-266<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-338","alert_type":396,"serial_number":"AV24-338","subject":"dell","moderation_state":"published","external_url":null},{"nid":5286,"title":"IBM security advisory (AV24-339)","uuid":"1a179d53-0f4a-4ac7-a9e1-2ccbf3c5c562","banner":null,"lang":"en","date_modified":"2024-06-17","date_modified_ts":"2024-06-17T15:15:11Z","date_created":"2024-06-17T15:06:28Z","summary":null,"body":["<article data-history-node-id=\"5286\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-339\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-339<br \/><strong>Date: <\/strong>June 17, 2024<\/p>\n\n<p>Between June 10 and 16, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following product:<\/p>\n\n<ul><li>IBM Storage Copy Data Management\u00a0\u2013 version 2.2.0.0 to 2.2.23.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7154709\">IBM Security Bulletin\u00a0- 7154709<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-339","alert_type":396,"serial_number":"AV24-339","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5287,"title":"[Control systems] CISA ICS security advisories (AV24-340)","uuid":"f02d1e6d-2324-4902-9e11-cddd74a3d7b1","banner":null,"lang":"en","date_modified":"2024-06-17","date_modified_ts":"2024-06-17T20:35:25Z","date_created":"2024-06-17T20:02:53Z","summary":null,"body":["<article data-history-node-id=\"5287\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-340\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-340<br \/><strong>Date: <\/strong>June\u00a017, 2024<\/p>\n\n<p>Between June\u00a010 and June\u00a016, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Siemens Mendix Applications\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SIMATIC S7-200 SMART Devices\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Siemens TIA Administrator\u00a0\u2013 versions prior to V3 SP2<\/li>\n\t<li>Siemens ST7 ScadaConnect\u00a0\u2013 versions prior to 1.1<\/li>\n\t<li>Siemens SITOP UPS1600\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Siemens TIM 1531 IRC\u00a0\u2013 versions prior to 2.4.8<\/li>\n\t<li>Siemens PowerSys\u00a0\u2013 versions prior to 3.11<\/li>\n\t<li>Siemens Teamcenter Visualization\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Siemens SICAM AK3\/BC\/TM\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Siemens SIMATIC and SIPLUS\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Siemens SCALANCE\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Siemens SINEC Traffic Analyzer\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Fuji Electric Tellus Lite V-Simulator\u00a0\u2013 versions prior to 4.0.20.0<\/li>\n\t<li>Rockwell Automation FactoryTalk View SE\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Motorola Solutions Vigilant License Plate Readers\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Mitsubishi Electric\u00a0\u2013 multiple versions and products<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-340","alert_type":398,"serial_number":"AV24-340","subject":"ics","moderation_state":"published","external_url":null},{"nid":5288,"title":"Red Hat security advisory (AV24-341)","uuid":"b7c8103f-b1d3-42c6-a835-7c0cc8c07be9","banner":null,"lang":"en","date_modified":"2024-06-18","date_modified_ts":"2024-06-18T18:06:44Z","date_created":"2024-06-18T17:30:26Z","summary":null,"body":["<article data-history-node-id=\"5288\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-341\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-341<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 18, 2024<\/p>\n\n<p>Between June 10 and 16, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:3859\">Red Hat Security Advisory\u00a0- RHSA-2024:3859<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:3855\">Red Hat Security Advisory\u00a0- RHSA-2024:3855<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:3854\">Red Hat Security Advisory\u00a0- RHSA-2024:3854<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-341","alert_type":396,"serial_number":"AV24-341","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5290,"title":"Google Chrome security advisory (AV24-342)","uuid":"ee501802-dd2d-4ac3-b4f2-133fabcc16ed","banner":null,"lang":"en","date_modified":"2024-06-19","date_modified_ts":"2024-06-19T14:15:09Z","date_created":"2024-06-19T14:07:18Z","summary":null,"body":["<article data-history-node-id=\"5290\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-342\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-342<br \/><strong>Date: <\/strong>June 19, 2024<\/p>\n\n<p>On June 18, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 126.0.6478.114\/115 (Windows and Mac) and 126.0.6478.114 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/06\/stable-channel-update-for-desktop_18.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-342","alert_type":396,"serial_number":"AV24-342","subject":"other","moderation_state":"published","external_url":null},{"nid":5291,"title":"Atlassian security advisory (AV24-343)","uuid":"86df6ddf-fefc-4575-aaf0-9654d3e0828a","banner":null,"lang":"en","date_modified":"2024-06-19","date_modified_ts":"2024-06-19T14:33:37Z","date_created":"2024-06-19T14:26:46Z","summary":null,"body":["<article data-history-node-id=\"5291\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-343\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-343<br \/><strong>Date: <\/strong>June 19, 2024<\/p>\n\n<p>On June 18, 2024, Atlassian published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Fisheye\/Crucible\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-june-18-2024-1409286211.html\">Atlassian February 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-343","alert_type":396,"serial_number":"AV24-343","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5292,"title":"Juniper Networks security advisory (AV24-344)","uuid":"7f0e6422-4093-4c3f-929a-6c51a23dcef4","banner":null,"lang":"en","date_modified":"2024-06-19","date_modified_ts":"2024-06-19T14:43:55Z","date_created":"2024-06-19T14:36:28Z","summary":null,"body":["<article data-history-node-id=\"5292\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-344\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-344<br \/><strong>Date: <\/strong>June 19, 2024<\/p>\n\n<p>On June 19, 2024, Juniper Networks published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Juniper Secure Analytics\u00a0\u2013 versions prior to 7.5.0 UP8 and 7.5.0 UP8 IF02<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US\">Juniper Networks Security Advisories\u00a0\u2013 JSA82681<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-344","alert_type":396,"serial_number":"AV24-344","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5293,"title":"VMware security advisory (AV24-345)","uuid":"08e49950-0f56-4bb6-9117-511a4f237e4e","banner":null,"lang":"en","date_modified":"2024-06-19","date_modified_ts":"2024-06-19T17:50:42Z","date_created":"2024-06-19T17:23:31Z","summary":null,"body":["<article data-history-node-id=\"5293\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-345\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-345<br \/><strong>Date: <\/strong>June\u00a019, 2024<\/p>\n\n<p>On June\u00a018, 2024, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware vCenter Server\u00a0\u2013 versions 8.0 prior to 8.0 U2d, versions 8.0 prior to 8.0 U1e and versions 7.0 prior to 7.0 U3r<\/li>\n\t<li>VMware Cloud Foundation (vCenter Server)\u00a0\u2013 versions 4.x and 5.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24453\">VMSA-2024-0012:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories - VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-345","alert_type":396,"serial_number":"AV24-345","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5295,"title":"Microsoft Edge security advisory (AV24-346)","uuid":"8060c5ef-7f40-49af-97b7-afff42d4cd14","banner":null,"lang":"en","date_modified":"2024-06-21","date_modified_ts":"2024-06-21T17:29:37Z","date_created":"2024-06-21T17:15:43Z","summary":null,"body":["<article data-history-node-id=\"5295\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-346\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-346<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 21, 2024<\/p>\n\n<p>On June 20, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 126.0.2592.68<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-20-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-346","alert_type":396,"serial_number":"AV24-346","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5299,"title":"IBM security advisory (AV24-348)","uuid":"c776ebde-1a4d-4341-bff3-fa47c1aeb025","banner":null,"lang":"en","date_modified":"2024-06-24","date_modified_ts":"2024-06-24T18:08:25Z","date_created":"2024-06-24T17:51:19Z","summary":null,"body":["<article data-history-node-id=\"5299\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-348\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-348<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 24, 2024<\/p>\n\n<p>Between June 17 and 23, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>IBM Business Automation Workflow containers\u00a0\u2013 version 23.0.2 to V23.0.2-IF004<\/li>\n\t<li>IBM Business Automation Workflow traditional\u00a0\u2013 version 23.0.2<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 version 12.0 to 12.0.2 and version 11.2.0 to 11.2.4 FP2<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM i\u00a0\u2013 versions 7.3, 7.4 and 7.5<\/li>\n\t<li>IBM Maximo Application Suite (IoT Component)\u00a0\u2013 version 8.8.x and 8.7.x<\/li>\n\t<li>IBM Security SOAR\u00a0\u2013 version 51.0.2.0 and prior<\/li>\n\t<li>IBM Storage Insights (Data Collector)\u00a0\u2013 version 20240510-0638 and prior<\/li>\n\t<li>IBM Storage Protect for Space Management\u00a0\u2013 version 8.1.0.0 to 8.1.21.0<\/li>\n\t<li>IBM Storage Scale System\u00a0\u2013 version 6.1.0.0 to 6.1.2.9 and version 6.1.3.0 to 6.1.9.2<\/li>\n\t<li>IBM Storage Virtualize\u00a0\u2013 versions 8.4, 8.5 and 8.6<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 4.8.5<\/li>\n\t<li>IBM Watson Explorer Analytical Components\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Watson Explorer DAE Foundational Components \u2013 multiple versions<\/li>\n\t<li>IBM Watson Explorer Foundational Components\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 4.8.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-348","alert_type":396,"serial_number":"AV24-348","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5298,"title":"Dell security advisory (AV24-347)","uuid":"b31e8366-3f91-4f43-a3c7-bf33fe36cac3","banner":null,"lang":"en","date_modified":"2024-06-24","date_modified_ts":"2024-06-24T17:55:07Z","date_created":"2024-06-24T17:52:11Z","summary":null,"body":["<article data-history-node-id=\"5298\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-347\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-347<br \/><strong>Date: <\/strong>June\u00a024, 2024<\/p>\n\n<p>Between June\u00a017 and 23, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance\u00a0\u2013 7.0x versions prior to 7.0.520<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000226270\/dsa-2024-247-security-update-for-dell-vxrail-7-0-520-multiple-third-party-component-vulnerabilities\">Dell Security Advisory\u00a0\u2013 DSA-2024-247<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-347","alert_type":396,"serial_number":"AV24-347","subject":"dell","moderation_state":"published","external_url":null},{"nid":5300,"title":"Ubuntu security advisory (AV24-349)","uuid":"618bdca0-26e1-49dd-8530-dcb5637de039","banner":null,"lang":"en","date_modified":"2024-06-24","date_modified_ts":"2024-06-24T19:08:46Z","date_created":"2024-06-24T18:21:36Z","summary":null,"body":["<article data-history-node-id=\"5300\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-349\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-349<br \/><strong>Date: <\/strong>June\u00a024, 2024<\/p>\n\n<p>Between June\u00a017 and 23, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6818-4\">USN-6818-7\u00a0- Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-349","alert_type":396,"serial_number":"AV24-349","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5301,"title":"[Control systems] CISA ICS security advisories (AV24-350)","uuid":"3b5232e8-e8ec-49c1-b1d6-eb07bae5ad71","banner":null,"lang":"en","date_modified":"2024-06-24","date_modified_ts":"2024-06-24T20:49:54Z","date_created":"2024-06-24T19:49:02Z","summary":null,"body":["<article data-history-node-id=\"5301\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-350\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-350<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 24, 2024<\/p>\n\n<p>Between June 17 and June 23, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CAREL Boss-Mini\u00a0\u2013 version 1.4.0 (Build 6221)<\/li>\n\t<li>RAD Data Communications SecFlow-2\u00a0\u2013 all versions<\/li>\n\t<li>Westermo L210-F2G Lynx\u00a0\u2013 version 4.21.0<\/li>\n\t<li>Yokogawa CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class)\u00a0\u2013 version R3.08.10 to R3.09.50<\/li>\n\t<li>Yokogawa CENTUM VP (Including CENTUM VP Entry Class)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-170-01\">RAD Data Communications SecFlow-2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-172-01\">Yokogawa CENTUM<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-172-02\">CAREL Boss-Mini<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-172-03\">Westermo L210-F2G<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-350","alert_type":398,"serial_number":"AV24-350","subject":"ics","moderation_state":"published","external_url":null},{"nid":5305,"title":"Google Chrome security advisory (AV24-351)","uuid":"99dbf78c-5706-4d55-a1d7-a5f2e9ff2050","banner":null,"lang":"en","date_modified":"2024-06-25","date_modified_ts":"2024-06-25T13:59:47Z","date_created":"2024-06-25T13:51:47Z","summary":null,"body":["<article data-history-node-id=\"5305\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-351\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-351<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 25, 2024<\/p>\n\n<p>On June 24, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 126.0.6478.126\/127 (Windows and Mac) and 126.0.6478.126 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/06\/stable-channel-update-for-desktop_24.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-351","alert_type":396,"serial_number":"AV24-351","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5306,"title":"Citrix security advisory (AV24-352)","uuid":"9a8b8df6-f451-4231-834c-d828fb4a095f","banner":null,"lang":"en","date_modified":"2024-06-25","date_modified_ts":"2024-06-25T14:14:32Z","date_created":"2024-06-25T13:51:47Z","summary":null,"body":["<article data-history-node-id=\"5306\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av24-352\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-352<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 25, 2024<\/p>\n\n<p>On June 24, 2024, Citrix published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Citrix NetScaler Gateway\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX677069\/cloud-software-group-security-advisory-for-cve20243661\">Citrix Security Advisory\u00a0\u2013 CTX677069<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av24-352","alert_type":396,"serial_number":"AV24-352","subject":"citrix","moderation_state":"published","external_url":null},{"nid":5308,"title":"[Control systems] ABB security advisory (AV24-353)","uuid":"be51829b-f3d1-4c1f-b8ec-f97b08188720","banner":null,"lang":"en","date_modified":"2024-06-25","date_modified_ts":"2024-06-25T15:46:10Z","date_created":"2024-06-25T15:42:44Z","summary":null,"body":["<article data-history-node-id=\"5308\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-353\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-353<br \/><strong>Date: <\/strong>June\u00a025, 2024<\/p>\n\n<p>On June\u00a025, 2024, ABB published an ICS advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB PCM600\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA002251&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch&amp;_ga=2.185932074.289672297.1719254637-932887643.1715694277\">ABB PCM600 Installer Vulnerability (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-353","alert_type":398,"serial_number":"AV24-353","subject":"abb","moderation_state":"published","external_url":null},{"nid":5309,"title":"Progress security advisory (AV24-354)","uuid":"dd73b7e2-5ee7-4566-8a23-ffe22015f0a0","banner":null,"lang":"en","date_modified":"2024-06-25","date_modified_ts":"2024-06-25T20:28:07Z","date_created":"2024-06-25T20:19:17Z","summary":null,"body":["<article data-history-node-id=\"5309\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av24-354\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-354<br \/><strong>Date: <\/strong>June\u00a025, 2024<\/p>\n\n<p>On June\u00a025, 2024, Progress published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>MOVEit Gateway\u00a0\u2013 version 2024.0.0<\/li>\n\t<li>MOVEit Transfer\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>Open-source reporting has indicated that CVE-2024-5806 may have been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Gateway-Critical-Security-Alert-Bulletin-June-2024-CVE-2024-5805\">MOVEit Gateway Critical Security Alert Bulletin\u00a0\u2013 June 2024\u00a0\u2013 (CVE-2024-5805)<\/a><\/li>\n\t<li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806\">MOVEit Transfer Critical Security Alert Bulletin\u00a0\u2013 June 2024\u00a0\u2013 (CVE-2024-5806)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av24-354","alert_type":396,"serial_number":"AV24-354","subject":"other","moderation_state":"published","external_url":null},{"nid":5311,"title":"GitLab security advisory (AV24-355)","uuid":"fec7425a-3d6c-46e2-b2a3-f16ce75c2642","banner":null,"lang":"en","date_modified":"2024-06-26","date_modified_ts":"2024-06-26T19:00:10Z","date_created":"2024-06-26T18:36:36Z","summary":null,"body":["<article data-history-node-id=\"5311\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-355\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-355<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 26, 2024<\/p>\n\n<p>On June 26, 2024, GitLab published a security advisory to address critical vulnerabilities in the following products::<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 1.1, 17.0.3 and 16.11.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 1.1, 17.0.3 and 16.11.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/06\/26\/patch-release-gitlab-17-1-1-released\/\">GitLab Critical Patch Release: 17.1.1, 17.0.3, 16.11.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-355","alert_type":396,"serial_number":"AV24-355","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5313,"title":"Fortra security advisory (AV24-356)","uuid":"613d3d84-0282-4e16-80ef-2b4697e0b7ec","banner":null,"lang":"en","date_modified":"2024-06-27","date_modified_ts":"2024-06-27T15:52:15Z","date_created":"2024-06-27T15:48:53Z","summary":null,"body":["<article data-history-node-id=\"5313\" about=\"\/en\/alerts-advisories\/fortra-security-advisory-av24-356\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-356<br \/><strong>Date: <\/strong>June\u00a027, 2024<\/p>\n\n<p>On June\u00a025, 2024, Fortra published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Fortra FileCatalyst Workflow\u00a0\u2013 version 5.1.6 Build 135 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortra.com\/security\/advisory\/fi-2024-008\">Fortra Security Advisories\u00a0- FI-2024-008<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortra.com\/security\">Fortra Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortra-security-advisory-av24-356","alert_type":396,"serial_number":"AV24-356","subject":"other","moderation_state":"published","external_url":null},{"nid":5314,"title":"Microsoft Edge security advisory (AV24-357)","uuid":"2ac6cc54-f950-4b0d-81e3-3015643271f7","banner":null,"lang":"en","date_modified":"2024-06-28","date_modified_ts":"2024-06-28T15:03:46Z","date_created":"2024-06-28T14:42:32Z","summary":null,"body":["<article data-history-node-id=\"5314\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-357\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-357<br \/><strong>Date: <\/strong>June 28, 2024<\/p>\n\n<p>On June 27, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 126.0.2592.81<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-27-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-357","alert_type":396,"serial_number":"AV24-357","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5315,"title":"HPE security advisory (AV24-358)","uuid":"09d7d320-781e-4e71-8d98-d043a35daf61","banner":null,"lang":"en","date_modified":"2024-06-28","date_modified_ts":"2024-06-28T15:17:23Z","date_created":"2024-06-28T15:08:16Z","summary":null,"body":["<article data-history-node-id=\"5315\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-358\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-358<br \/><strong>Date: <\/strong>June 28, 2024<\/p>\n\n<p>On June 28, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant DL325 Gen10 Plus server\u00a0\u2013 versions prior to 2.84 (HFP 23.9)<\/li>\n\t<li>HPE ProLiant DL385 Gen10 Plus server\u00a0\u2013 versions prior to 2.84 (HFP 23.9)<\/li>\n\t<li>HPE ProLiant XL645d Gen10 Plus Server\u00a0\u2013 versions prior to 2.84 (HFP 23.9)<\/li>\n\t<li>HPE ProLiant XL675d Gen10 Plus Server\u00a0\u2013 versions prior to 2.84 (HFP 23.9)<\/li>\n\t<li>HPE Cray EX235a Accelerator Blade\u00a0\u2013 versions prior to 1.8.0 (HFP 24.3.1)<\/li>\n\t<li>HPE Cray EX235n Server\u00a0\u2013 versions prior to 1.3.1 (HFP 23.9)<\/li>\n\t<li>HPE Cray EX425 Compute Blade\u00a0\u2013 versions prior to 1.7.2 (HFP 23.9) Gen 2, and Gen 3 EPYC Processors<\/li>\n\t<li>HPE Cray EX4252 Compute Blade\u00a0\u2013 versions prior to 1.4.0 (HFP 23.8)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04657en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0\u2013 hpesbcr04657en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-358","alert_type":396,"serial_number":"AV24-358","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5316,"title":"Juniper Networks security advisory (AV24-359)","uuid":"cf09c63b-dd4e-4f8f-b192-14e71c1c7363","banner":null,"lang":"en","date_modified":"2024-06-28","date_modified_ts":"2024-06-28T18:31:25Z","date_created":"2024-06-28T18:27:12Z","summary":null,"body":["<article data-history-node-id=\"5316\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-359\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-359<br \/><strong>Date: <\/strong>June\u00a028, 2024<\/p>\n\n<p>On June\u00a027, 2024, Juniper Networks published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Juniper Session Smart Conductor\u00a0\u2013 multiple versions<\/li>\n\t<li>Juniper Session Smart Router\u00a0\u2013 multiple versions<\/li>\n\t<li>Juniper WAN Assurance Router\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2024-06-Out-Of-Cycle-Security-Bulletin-Session-Smart-Router-SSR-On-redundant-router-deployments-API-authentication-can-be-bypassed-CVE-2024-2973?language=en_US\">Juniper Networks Security Advisories\u00a0\u2013 JSA83126<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-359","alert_type":396,"serial_number":"AV24-359","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5318,"title":"[Control systems] CISA ICS security advisories (AV24-363) ","uuid":"d3d74e0f-9c3e-4e21-a9f1-2152485915a5","banner":null,"lang":"en","date_modified":"2024-07-02","date_modified_ts":"2024-07-02T17:10:44Z","date_created":"2024-07-02T14:50:01Z","summary":null,"body":["<article data-history-node-id=\"5318\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-363\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-363<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 2, 2024<\/p>\n\n<p>Between June 24 and 30, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB 800xA Base\u00a0\u2013 versions 6.1.1-2 and prior<\/li>\n\t<li>PTC Creo Elements\/Direct License Server\u00a0\u2013 version 20.7.0.0 and prior<\/li>\n\t<li>SDG Technologies PnPSCADA\u00a0- versions prior to 4<\/li>\n\t<li>Markoni-D (Compact) FM Transmitters\u00a0\u2013 all versions prior to 2.0.1<\/li>\n\t<li>Markoni-DH (Exciter+Amplifiers) FM Transmitters\u00a0\u2013 all versions prior to 2.0<\/li>\n\t<li>Yokogawa FAST\/TOOLS RVSVRN Package\u00a0\u2013 versions R9.01 through R10.04<\/li>\n\t<li>Yokogawa FAST\/TOOLS UNSVRN Package\u00a0\u2013 versions R9.01 through R10.04<\/li>\n\t<li>Yokogawa FAST\/TOOLS HMIWEB Package\u00a0\u2013 versions R9.01 through R10.04<\/li>\n\t<li>Yokogawa FAST\/TOOLS FTEES Package\u00a0\u2013 versions R9.01 through R10.04<\/li>\n\t<li>Yokogawa FAST\/TOOLS HMIMOB Package\u00a0\u2013 versions R9.01 through R10.04<\/li>\n\t<li>Yokogawa CI Server\u00a0\u2013 versions R1.01.00 through R1.03.00<\/li>\n\t<li>Johnson Controls Illustra Essential Gen 4\u00a0\u2013 versions Illustra.Ess4.01.02.10.5982 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-363","alert_type":398,"serial_number":"AV24-363","subject":"other","moderation_state":"published","external_url":null},{"nid":5319,"title":"Dell security advisory (AV24-360)","uuid":"5ee777ac-54d1-4d29-ac89-583d3dce9d0c","banner":null,"lang":"en","date_modified":"2024-07-02","date_modified_ts":"2024-07-02T15:41:09Z","date_created":"2024-07-02T14:54:49Z","summary":null,"body":["<article data-history-node-id=\"5319\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-360\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-360<br \/><strong>Date: <\/strong>July\u00a02, 2024<\/p>\n\n<p>Between June\u00a024 and 30, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Avamar Virtual Edition for Hyper-V 2012\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10<\/li>\n\t<li>Avamar Virtual Edition for Hyper-V 2012R2, Hyper-V 2016, and Hyper-V 2019\u00a0\u2013 versions 19.4, 19.7,19.8,19.9 and 19.10<\/li>\n\t<li>Avamar Virtual Edition for KVM\/Open Stack KVM\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10<\/li>\n\t<li>Avamar Virtual Edition for VMware ESXi and vSphere\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10<\/li>\n\t<li>Avamar Virtual Edition for VMware vSphere only\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10<\/li>\n\t<li>Dell Avamar Data Store Gen4T\u00a0\u2013 version ADS Gen4T<\/li>\n\t<li>Dell Avamar Data Store Gen5A\u00a0\u2013 version ADS Gen5A<\/li>\n\t<li>Dell Avamar Data Store Gen5A, Gen4T\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9 and 19.10<\/li>\n\t<li>Dell Power Protect DP Series (Integrated Data Protection Appliance (IDPA))\u00a0\u2013 version 2.7.6 and prior (only 8x models)<\/li>\n\t<li>Dell PowerProtect DD Management Center with SmartScale feature\u00a0\u2013 versions 7.8 to 7.13<\/li>\n\t<li>Dell PowerProtect DD Management Center\u00a0\u2013 versions 7.0 through 7.13<\/li>\n\t<li>Dell PowerProtect DD Management Center\u00a0\u2013 versions 7.0 through 7.13<\/li>\n\t<li>Dell PowerProtect DD appliance models: DD6300, DD6800, and DD9300\u00a0\u2013 versions 7.0 through 7.13<\/li>\n\t<li>Dell PowerProtect DD series appliances, Dell PowerProtect DD Virtual Edition, Dell APEX Protection Storage\u00a0\u2013 versions 7.0 through 7.13<\/li>\n\t<li>Dell PowerProtect DP Series Appliance - IDPA (Integrated Data Protection Appliance): All Models\u00a0\u2013 versions prior to 2.7.7<\/li>\n\t<li>Dell PowerProtect Data Manager Appliance model: DM5500\u00a0\u2013 versions prior to 5.16.0.0<\/li>\n\t<li>Dell Protection Advisor\u00a0\u2013 versions 19.7, 19.8, 19.9 and 19.10<\/li>\n\t<li>PowerProtect Data Manager Appliance model: DM5500\u00a0\u2013 versions prior to 5.16.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-360","alert_type":396,"serial_number":"AV24-360","subject":"dell","moderation_state":"published","external_url":null},{"nid":5321,"title":"IBM security advisory (AV24-361)","uuid":"6a231838-01d3-4bfe-a7e4-3b0c369302f3","banner":null,"lang":"en","date_modified":"2024-07-02","date_modified_ts":"2024-07-02T16:14:01Z","date_created":"2024-07-02T14:54:49Z","summary":null,"body":["<article data-history-node-id=\"5321\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-361\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-361<br \/><strong>Date: <\/strong>July\u00a02, 2024<\/p>\n\n<p>Between June\u00a024 and 30, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for AIOps\u00a0\u2013 versions 4.1.0 to 4.5.1<\/li>\n\t<li>IBM Cloud Transformation Advisor\u00a0\u2013 versions 2.0.1 to 3.9.0<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 versions 11.2.0 to 11.2.4 FP3, 12.0.0 to 12.0.2 and 12.0.0 to 12.0.3<\/li>\n\t<li>IBM Cognos Dashboards on Cloud Pak for Data\u00a0\u2013 versions 4.7.0 to 5.0<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 version Build 271<\/li>\n\t<li>IBM Jazz Foundation\u00a0\u2013 versions 6.0.6, 6.0.6.1, 7.0, 7.0.1 and 7.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-361","alert_type":396,"serial_number":"AV24-361","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5322,"title":"Ubuntu security advisory (AV24-362)","uuid":"7b681abd-ce2f-4575-9762-e5921cd35074","banner":null,"lang":"en","date_modified":"2024-07-02","date_modified_ts":"2024-07-02T16:20:14Z","date_created":"2024-07-02T14:54:49Z","summary":null,"body":["<article data-history-node-id=\"5322\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-362\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-362<br \/><strong>Date: <\/strong>July\u00a02, 2024<\/p>\n\n<p>Between June\u00a024 and 30, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6819-4\">USN-6819-4\u00a0- Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-362","alert_type":396,"serial_number":"AV24-362","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5320,"title":"Android security advisory \u2013 July 2024 Monthly Rollup (AV24-364)","uuid":"2aa6066b-89b4-4ecd-b20a-571d34634414","banner":null,"lang":"en","date_modified":"2024-07-02","date_modified_ts":"2024-07-02T17:13:55Z","date_created":"2024-07-02T16:07:39Z","summary":null,"body":["<article data-history-node-id=\"5320\" about=\"\/en\/alerts-advisories\/android-security-advisory-july-2024-monthly-rollup-av24-364\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-364<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 2, 2024<\/p>\n\n<p>On July 1, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-07-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-july-2024-monthly-rollup-av24-364","alert_type":396,"serial_number":"AV24-364","subject":"android","moderation_state":"published","external_url":null},{"nid":5323,"title":"[Control systems] ABB security advisory (AV24-365)","uuid":"316295e5-9348-4795-9882-e12ec9e75bf6","banner":null,"lang":"en","date_modified":"2024-07-02","date_modified_ts":"2024-07-02T17:57:19Z","date_created":"2024-07-02T17:38:32Z","summary":null,"body":["<article data-history-node-id=\"5323\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-365\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-365<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 2, 2024<\/p>\n\n<p>On June 26, 2024, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ASPECT Enterprise\u00a0\u2013 versions prior to 3.07.02<\/li>\n\t<li>NEXUS Series\u00a0\u2013 versions prior to 3.07.02<\/li>\n\t<li>MATRIX Series\u00a0\u2013 versions prior to 3.07.02<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108469A6101&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch&amp;_ga=2.9243829.1400312266.1719932384-79362040.1701890613\">ABB PCM600 Installer Vulnerability (PDF) <\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-365","alert_type":398,"serial_number":"AV24-365","subject":"abb","moderation_state":"published","external_url":null},{"nid":5324,"title":"OpenSSH security advisory (AV24-366)","uuid":"6e95abec-3a89-44d1-a817-e0757ddda434","banner":null,"lang":"en","date_modified":"2024-07-02","date_modified_ts":"2024-07-02T19:29:35Z","date_created":"2024-07-02T19:22:59Z","summary":null,"body":["<article data-history-node-id=\"5324\" about=\"\/en\/alerts-advisories\/openssh-security-advisory-av24-366\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-366<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 2, 2024<\/p>\n\n<p>On July 1, 2024, OpenSSH published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>OpenSSH\u00a0\u2013 versions 8.5p1 to 9.7p1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.openssh.com\/txt\/release-9.8\">OpenSSH 9.8\/9.8p1 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.openssh.com\/\">OpenSSH<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssh-security-advisory-av24-366","alert_type":396,"serial_number":"AV24-366","subject":"other","moderation_state":"published","external_url":null},{"nid":5325,"title":"Red Hat security advisory (AV24-367)","uuid":"0b74d596-f8d7-4f60-a664-115f8b5e13e8","banner":null,"lang":"en","date_modified":"2024-07-03","date_modified_ts":"2024-07-03T14:11:16Z","date_created":"2024-07-03T13:46:32Z","summary":null,"body":["<article data-history-node-id=\"5325\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-367\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-367<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 3, 2024<\/p>\n\n<p>Between June 24 and 30, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platform<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platform<\/li>\n\t<li>Red Hat Enterprise Linux for ARM 64\u00a0\u2013 multiple versions and platform<\/li>\n\t<li>Red Hat Enterprise Linux for IBM z Systems\u00a0\u2013 multiple versions and platform<\/li>\n\t<li>Red Hat Enterprise Linux for Power\u00a0\u2013 multiple versions and platform<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platform<\/li>\n\t<li>Red Hat Enterprise Linux for x86_64\u00a0\u2013 multiple versions and platform<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-367","alert_type":396,"serial_number":"AV24-367","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5326,"title":"HPE security advisory (AV24-368)","uuid":"f84185f8-1597-4d7e-af88-2f860bb3808b","banner":null,"lang":"en","date_modified":"2024-07-03","date_modified_ts":"2024-07-03T19:46:40Z","date_created":"2024-07-03T18:30:41Z","summary":null,"body":["<article data-history-node-id=\"5326\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-368\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-368<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 3, 2024<\/p>\n\n<p>On July 3, 2024, HPE published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE Cray EX235a Accelerator Blade\u00a0\u2013 versions prior to BIOS 1.8.0 in HFP 24.3.1<\/li>\n\t<li>HPE Cray EX235n Server\u00a0\u2013 versions prior to BIOS 1.3.1 in HFP 23.9<\/li>\n\t<li>HPE Cray EX425 Compute Blade\u00a0\u2013 versions prior to BIOS 1.7.2 in HFP 23.9<\/li>\n\t<li>HPE Cray EX4252 Compute Blade\u00a0\u2013 version prior to BIOS 1.4.0 in HFP 23.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04666en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04666en_us <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-368","alert_type":396,"serial_number":"AV24-368","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5327,"title":"[Control systems] ABB security advisory (AV24-369) ","uuid":"7304efd3-7741-4b1d-a550-06e0e9be9cf4","banner":null,"lang":"en","date_modified":"2024-07-04","date_modified_ts":"2024-07-04T18:16:14Z","date_created":"2024-07-04T18:10:52Z","summary":null,"body":["<article data-history-node-id=\"5327\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-369\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-369\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 4, 2024\n<\/p>\n<p>On July 4, 2024, ABB published security advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>ASPECT Enterprise\u00a0\u2013 version 3.08.01 and prior<\/li>\n  <li>NEXUS Series\u00a0\u2013 version 3.08.01 and prior<\/li>\n  <li>MATRIX Series\u00a0\u2013 version 3.08.01 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108469A7497&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch&amp;_ga=2.55061291.1400312266.1719932384-79362040.1701890613\">ASPECT system, ASPECT system RCE, unauthorized-Access vulnerabilities (PDF)<\/a><\/li>\n  <li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-369","alert_type":398,"serial_number":"AV24-369","subject":"abb","moderation_state":"published","external_url":null},{"nid":5328,"title":"RADIUS protocol susceptible to forgery attacks - Update 1","uuid":"ebef86a5-cbc1-4f14-b298-52df2bd16b2c","banner":null,"lang":"en","date_modified":"2024-07-05","date_modified_ts":"2024-07-05T20:08:12Z","date_created":"2024-07-05T19:10:56Z","summary":null,"body":["<article data-history-node-id=\"5328\" about=\"\/en\/alerts-advisories\/radius-protocol-susceptible-forgery-attacks\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL24-009<br \/><strong>Date: <\/strong>July\u00a09, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of industry research regarding a recent vulnerability<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> impacting the RADIUS protocol (CVE-2024-3596)\u00a0\u2013 a common authentication, authorization and accounting network protocol used for managing network accesses. The vulnerability could allow a person-in-the-middle threat actor to authenticate themself to a victim\u2019s system or deny authentication to legitimate users.<\/p>\n\n<p>RADIUS is a popular lightweight authentication protocol used for networking devices. It is in wide-spread use to authenticate both users and devices. The protocol is also widely supported by networking devices from basic network switches to more complex VPN solutions. RADIUS has also been adopted in much of the cloud services that provide tiered role-based access-control to resources. As a client-server protocol, RADIUS uses a Request-Response model to verify authentication requests and further provide any role-based access using Groups. It can also be proxied to support multi-tenant roaming access services.<\/p>\n\n<p>This vulnerability is due to the lack of authentication and integrity validation with the RADIUS protocol. An adversary could exploit the weak cryptographic hash MD5 and forge authentication responses from a RADIUS server.<\/p>\n\n<p>As of 9 July 2024, the Cyber Centre is not aware of this vulnerability having been exploited.<\/p>\n\n<p>A malicious actor wanting to exploit this vulnerability would require both view and modify access to RADIUS packets in transit (man-in-the-middle). Any unencrypted RADIUS communication particularly RADIUS over UDP and RADIUS over TCP would be vulnerable.<\/p>\n\n<p>This Alert is being published to raise awareness of this vulnerability, to highlight the potential impact to organizations and to provide guidance for organizations who may be targeted by related malicious activity.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>16 August 2024\u00a0- The Cyber Centre has revised this Alert to better align with industry recommendations.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends:<\/p>\n\n<ul><li>Verify with vendors that patches are available for any implementation of RADIUS used within an environment and ensure that all applicable systems are patched.<\/li>\n\t<li>Configure RADIUS clients and servers to always send and validate Message-Authenticator attributes for all requests and responses, as when using the Extensible Authentication Protocol (EAP)<\/li>\n\t<li>Use RADIUS within an encrypted and authenticated channel.\n\t<ul><li>Use RADIUS\/TLS or RADIUS\/DTLS.<\/li>\n\t\t<li>Consider tunnelling RADIUS traffic through IPsec or MACsec if feasible<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/li>\n\t<\/ul><\/li>\n\t<li>Block all RADIUS\/UDP and RADIUS\/TCP traffic from internet facing interfaces.\n\t<ul><li>Do not send unsecured RADIUS traffic over local or Internet networks.<\/li>\n\t<\/ul><\/li>\n\t<li>Implement firewall rules to deny the unapproved flow of RADIUS packets to unintended network segments.\n\t<ul><li>Block UDP port 1645 or 1812 for authentication and UDP port 1646 or 1813 for accounting at the perimeter firewall.<\/li>\n\t<\/ul><\/li>\n\t<li>Ensure physical security of all network devices by implementing measures to prevent unauthorized physical access to networking devices and cabling infrastructure.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions )<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways.<\/li>\n\t<li>Patch operating systems and applications.<\/li>\n\t<li>Harden operating systems and applications.<\/li>\n\t<li>Segment and separate information<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/li>\n<\/ul><p>The Cyber Centre wishes to highlight that mitigation efforts resulting from the compromise of systems by competent threat actors may require more than simply mitigating individual issues, systems and servers. The Cyber Centre recommends affected customers review the Cyber Centre joint cybersecurity advisory on technical approaches to uncovering and remediating malicious activity <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.blastradius.fail\/\">Blast Radius<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1a-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/kb.cert.org\/vuls\/id\/456537\">CERT CC<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/guidance\/guidance-securely-configuring-network-protocols-itsp40062\">Guidance on securely configuring network protocols (ITSP.40.062)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/news-events\/joint-advisory-modern-approaches-network-access-security\">Joint advisory on modern approaches to network access security<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/news-events\/joint-cybersecurity-advisory\">Technical Approaches to Uncovering and Remediating Malicious Activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/section><section><h2>Additional resources<\/h2>\n\n<ul><li><a href=\"\/en\/guidance\/secure-your-accounts-and-devices-multi-factor-authentication-itsap30030\">Secure your accounts and devices with multi-factor authentication (ITSAP.30.030)<\/a><\/li>\n\t<li><a href=\"\/en\/guidance\/user-authentication-guidance-information-technology-systems-itsp30031-v3\">User authentication guidance for information technology systems (ITSP.30.031 v3)<\/a><\/li>\n\t<li><a href=\"\/en\/guidance\/wi-fi-security-itsp80002\">Wi-Fi Security (ITSP.80.002)<\/a><\/li>\n\t<li><a href=\"\/en\/guidance\/baseline-cyber-security-controls-small-and-medium-organizations\">Baseline cyber security controls for small and medium organizations<\/a><\/li>\n\t<li><a href=\"\/en\/guidance\/cryptographic-algorithms-unclassified-protected-protected-b-information-itsp40111\">Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information\u00a0- ITSP.40.111<\/a><\/li>\n\t<li><a href=\"\/en\/guidance\/obsolete-products-itsap00095\">Obsolete products\u00a0- ITSAP.00.095<\/a><\/li>\n<\/ul><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/radius-protocol-susceptible-forgery-attacks","alert_type":397,"serial_number":"AL24-009","subject":"other","moderation_state":"published","external_url":null},{"nid":5329,"title":"Dell security advisory (AV24-370)","uuid":"d9e86de0-a654-474b-9f6d-589b770f23f5","banner":null,"lang":"en","date_modified":"2024-07-08","date_modified_ts":"2024-07-08T17:56:20Z","date_created":"2024-07-08T17:51:43Z","summary":null,"body":["<article data-history-node-id=\"5329\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-370\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-370<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 8, 2024<\/p>\n\n<p>Between July 1 and 7, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Data Protection Central\u00a0\u2013 version 19.10.0-4 and prior<\/li>\n\t<li>Dell EMC VxRail Appliance\u00a0\u2013 7.0.x versions prior to 7.0.521<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 5.0.1.0<\/li>\n\t<li>Dell Storage Resource Manager\u00a0\u2013 versions prior to 5.0.1.0<\/li>\n\t<li>NetWorker vProxy\u00a0\u2013 versions 19.10 to 19.10.0.3, versions 19.8 to 19.8.0.4, versions 19.9 to 19.9.0.7 and versions prior to 19.8<\/li>\n\t<li>PowerScale\u00a0\u2013 multiple models and versions prior to 12.2<\/li>\n\t<li>PowerStore\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-370","alert_type":396,"serial_number":"AV24-370","subject":"dell","moderation_state":"published","external_url":null},{"nid":5330,"title":"Ubuntu security advisory (AV24-371)","uuid":"f3c13760-c6b0-4e57-bc4a-ece4866f07fe","banner":null,"lang":"en","date_modified":"2024-07-08","date_modified_ts":"2024-07-08T18:03:16Z","date_created":"2024-07-08T17:59:31Z","summary":null,"body":["<article data-history-node-id=\"5330\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-371\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-371<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 8, 2024<\/p>\n\n<p>Between July 1 and 7, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-371","alert_type":396,"serial_number":"AV24-371","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5331,"title":"IBM security advisory (AV24-372)","uuid":"1c31fe16-ab4f-4578-ad4f-848f66fe0f46","banner":null,"lang":"en","date_modified":"2024-07-08","date_modified_ts":"2024-07-08T18:11:05Z","date_created":"2024-07-08T18:05:12Z","summary":null,"body":["<article data-history-node-id=\"5331\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-372\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-372<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 8, 2024<\/p>\n\n<p>Between July 1 and 7, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following product:<\/p>\n\n<ul><li>IBM Observability with Instana (OnPrem)\u00a0\u2013 version Build 273<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7159660\">IBM Security Bulletin (IBM Observability with Instana (OnPrem))<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-372","alert_type":396,"serial_number":"AV24-372","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5332,"title":"GeoServer security advisory (AV24-373)","uuid":"91e4779c-639d-40d7-b98d-c4dae2560a31","banner":null,"lang":"en","date_modified":"2024-07-08","date_modified_ts":"2024-07-08T20:17:04Z","date_created":"2024-07-08T20:06:51Z","summary":null,"body":["<article data-history-node-id=\"5332\" about=\"\/en\/alerts-advisories\/geoserver-security-advisory-av24-373\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-373<br \/><strong>Date: <\/strong>July\u00a08, 2024<\/p>\n\n<p>Between June\u00a013 and 18, 2024, GeoServer published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>GeoServer\u00a0\u2013 2.25.0 versions prior to 2.25.2, 2.24.0 versions prior to 2.24.4 and versions prior to 2.23.6<\/li>\n\t<li>GeoTools\u00a0\u2013 31.0 versions prior to 31.2, 30.0 versions prior to 30.4 and versions prior to 29.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p>NSFOCUS has indicated that these vulnerabilities have available exploits<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/geoserver.org\/announcements\/vulnerability\/2024\/06\/18\/geoserver-2-25-2-released.html\">GeoServer 2.25.2 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/geoserver.org\/announcements\/vulnerability\/2024\/06\/18\/geoserver-2-24-4-released.html\">GeoServer 2.24.4 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/geoserver.org\/announcements\/vulnerability\/2024\/06\/13\/geoserver-2-23-6-released.html\">GeoServer 2.23.6 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/geoserver.org\/\">GeoServer<\/a><\/li>\n<\/ul><!--FOOTNOTE SECTION EN--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/nsfocusglobal.com\/remote-code-execution-vulnerability-between-geoserver-and-geotools-cve-2024-36401-cve-2024-36404-notification\/\">NSFOCUS Blog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/geoserver-security-advisory-av24-373","alert_type":396,"serial_number":"AV24-373","subject":"other","moderation_state":"published","external_url":null},{"nid":5335,"title":"[Control systems] CISA ICS security advisories (AV24-374)","uuid":"e44a6821-04b7-4259-886d-24e36bb8d5db","banner":null,"lang":"en","date_modified":"2024-07-09","date_modified_ts":"2024-07-09T14:29:55Z","date_created":"2024-07-09T14:19:54Z","summary":null,"body":["<article data-history-node-id=\"5335\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-374\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-374<br \/><strong>Date: <\/strong>July\u00a09, 2024<\/p>\n\n<p>Between July\u00a01 and 7, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ICONICS AlarmWorX Multimedia (AlarmWorX64 MMX)\u00a0\u2013 versions prior to 10.97.3<\/li>\n\t<li>ICONICS MobileHMI\u00a0\u2013 versions prior to 10.97.3<\/li>\n\t<li>ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI\u00a0\u2013 versions prior to 10.97.3<\/li>\n\t<li>Kantech KT1 Door Controller, Rev01\u00a0\u2013 versions 2.09.01 and prior<\/li>\n\t<li>Kantech KT2 Door Controller, Rev01\u00a0\u2013 versions 2.09.01 and prior<\/li>\n\t<li>Kantech KT400 Door Controller, Rev01\u00a0\u2013 versions 3.01.16 and prior<\/li>\n\t<li>mySCADA myPRO\u00a0\u2013 versions prior to 8.31.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-184-01\">CISA ICS Advisory\u00a0- ICSA-24-184-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-184-02\">CISA ICS Advisory\u00a0- ICSA-24-184-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-184-03\">CISA ICS Advisory\u00a0- ICSA-24-184-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-374","alert_type":398,"serial_number":"AV24-374","subject":"ics","moderation_state":"published","external_url":null},{"nid":5336,"title":"Citrix security advisory (AV24-375)","uuid":"0415bca2-1c6c-4b47-96b5-1c27deec8690","banner":null,"lang":"en","date_modified":"2024-07-09","date_modified_ts":"2024-07-09T19:51:17Z","date_created":"2024-07-09T19:37:09Z","summary":null,"body":["<article data-history-node-id=\"5336\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av24-375\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-375<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 9, 2024<\/p>\n\n<p>On July 9, 2024, Citrix published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Virtual Apps and Desktops\u00a0\u2013 versions prior to 2402 Long Term Service Release (LTSR)<\/li>\n\t<li>Citrix Virtual Apps and Desktops\u00a0\u2013 version 1912 LTSR prior to CU9<\/li>\n\t<li>Citrix Virtual Apps and Desktops\u00a0\u2013 version 2203 LTSR prior to CU5<\/li>\n\t<li>NetScalar Console\u00a0\u2013 multiple versions<\/li>\n\t<li>NetScalar SVM\u00a0\u2013 multiple versions<\/li>\n\t<li>NetScalar Agent\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/article\/CTX677998\/netscaler-console-agent-and-svm-security-bulletin-for-cve20246235-and-cve20246236\">Citrix Security Advisory\u00a0\u2013 CTX677998<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/article\/CTX678035\/windows-virtual-delivery-agent-for-cvad-and-citrix-daas-security-bulletin-cve20246151\">Citrix Security Advisory\u00a0\u2013 CTX678035<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av24-375","alert_type":396,"serial_number":"AV24-375","subject":"citrix","moderation_state":"published","external_url":null},{"nid":5337,"title":"Microsoft security advisory \u2013 July 2024 monthly rollup (AV24-376)","uuid":"9dee045e-e2bc-4aa9-9a3f-7bcee7e88912","banner":null,"lang":"en","date_modified":"2024-07-09","date_modified_ts":"2024-07-09T20:11:34Z","date_created":"2024-07-09T19:56:09Z","summary":null,"body":["<article data-history-node-id=\"5337\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2024-monthly-rollup-av24-376\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-376<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 9, 2024<\/p>\n\n<p>On July 9, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Azure Network Watcher VM Extension for Windows<\/li>\n\t<li>Azure Kinect SDK<\/li>\n\t<li>Azure CycleCloud\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Azure DevOps Server 2022.1<\/li>\n\t<li>Microsoft 365 Apps for Enterprise\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft .NET Framework\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Defender for IoT<\/li>\n\t<li>Microsoft Dynamics 365 (on-premise)\u00a0\u2013 version 9.1<\/li>\n\t<li>Microsoft OLE DB Driver for SQL Server\u00a0\u2013 versions 18 and 19<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Outlook 2016<\/li>\n\t<li>Microsoft SQL Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Visual Studio\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>.NET\u00a0\u2013 version 8.0<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2024-38112\">CVE-2024-38112<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2024-38080\">CVE-2024-38080<\/a> have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Jul\">July 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2024-monthly-rollup-av24-376","alert_type":396,"serial_number":"AV24-376","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5338,"title":"Fortinet security advisory (AV24-377)","uuid":"76cef441-3809-4f73-8c24-71d2980f544c","banner":null,"lang":"en","date_modified":"2024-07-09","date_modified_ts":"2024-07-09T20:19:12Z","date_created":"2024-07-09T20:10:23Z","summary":null,"body":["<article data-history-node-id=\"5338\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-377\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-377<br \/><strong>Date: <\/strong>July\u00a09, 2024<\/p>\n\n<p>On July\u00a09, 2024, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>FortiADC 7.4\u00a0\u2013 versions prior to 7.4.1<\/li>\n\t<li>FortiADC 7.2\u00a0\u2013 versions prior to 7.2.4<\/li>\n\t<li>FortiADC 7.1\u00a0\u2013 all versions<\/li>\n\t<li>FortiADC 7.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiADC 6.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiADC 6.1\u00a0\u2013 all versions<\/li>\n\t<li>FortiADC 6.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiAIOps 2.0\u00a0\u2013 versions prior to 2.0.1<\/li>\n\t<li>FortiExtender 7.4\u00a0\u2013 versions prior to 7.4.3<\/li>\n\t<li>FortiExtender 7.2\u00a0\u2013 versions prior to 7.2.5<\/li>\n\t<li>FortiExtender 7.0\u00a0\u2013 versions prior to 7.0.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-298\">Fortinet PSIRT Advisory\u00a0- FG-IR-22-298<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-459\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-459<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-069\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-069<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-072\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-072<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-377","alert_type":396,"serial_number":"AV24-377","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":5339,"title":"Mozilla security advisory (AV24-378)","uuid":"a70a2d67-ac26-4e11-9815-0632ebb131b4","banner":null,"lang":"en","date_modified":"2024-07-10","date_modified_ts":"2024-07-10T16:02:25Z","date_created":"2024-07-10T15:48:10Z","summary":null,"body":["<article data-history-node-id=\"5339\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-378\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-378<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 10, 2024<\/p>\n\n<p>On July 9, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 115.13<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 128<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-30\/\">Mozilla Security Advisory\u00a0- MFSA 2024-30<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-29\/\">Mozilla Security Advisory\u00a0- MFSA 2024-29<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-378","alert_type":396,"serial_number":"AV24-378","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5340,"title":"Adobe security advisory (AV24-379)","uuid":"d54db7db-5ccb-4b36-ad29-3be26bd303e7","banner":null,"lang":"en","date_modified":"2024-07-10","date_modified_ts":"2024-07-10T18:10:49Z","date_created":"2024-07-10T17:05:32Z","summary":null,"body":["<article data-history-node-id=\"5340\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-379\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-374<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 10, 2024<\/p>\n\n<p>On July 9, 2024, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Adobe InDesign\u00a0\u2013 versions ID19.3 and prior and ID18.5.2 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 versions 13.0.7 and prior and 14.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb24-48.html\">Adobe Security Advisory\u00a0- APSB24-48<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb24-51.html\">Adobe Security Advisory\u00a0- APSB24-51<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-379","alert_type":396,"serial_number":"AV24-379","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5341,"title":"Red Hat security advisory (AV24-380)","uuid":"365b3020-e4c9-4fae-a583-0794c6fca7c3","banner":null,"lang":"en","date_modified":"2024-07-10","date_modified_ts":"2024-07-10T18:36:02Z","date_created":"2024-07-10T18:20:41Z","summary":null,"body":["<article data-history-node-id=\"5341\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-380\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-380<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 10, 2024<\/p>\n\n<p>Between July 1 and 7, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<p><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\"> Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/span> <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\"> Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/span> <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\"> Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/span> <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\"> Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/span><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4352\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:4352<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4349\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:4349<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4211\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:4211<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-380","alert_type":396,"serial_number":"AV24-380","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5342,"title":"[Control systems] Schneider Electric security advisory (AV24-381) ","uuid":"33f5877f-4673-48ae-8292-2c4d0fb4d05d","banner":null,"lang":"en","date_modified":"2024-07-10","date_modified_ts":"2024-07-10T19:32:01Z","date_created":"2024-07-10T19:22:52Z","summary":null,"body":["<article data-history-node-id=\"5342\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-381\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-381<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 10, 2024<\/p>\n\n<p>On June 9, 2024, Schneider Electric published security advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Foxboro DCS Core Control Services\u00a0\u2013 versions 9.8 and prior<\/li>\n\t<li>EcoStruxure Foxboro SCADA FoxRTU Station\u00a0\u2013 versions prior to v9.3.0<\/li>\n\t<li>Modicon Controllers M241 \/ M251\u00a0\u2013 all versions<\/li>\n\t<li>Modicon Controllers M258 \/ LMC058\u00a0\u2013 all versions<\/li>\n\t<li>Modicon Controllers M262\u00a0\u2013 all versions<\/li>\n\t<li>Wiser Home Controller WHC-5918A\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-381","alert_type":398,"serial_number":"AV24-381","subject":"other","moderation_state":"published","external_url":null},{"nid":5343,"title":"SAP security advisory \u2013 July 2024 monthly rollup (AV24-382)","uuid":"11d63443-a11b-4fd8-93cd-d2582a23ec36","banner":null,"lang":"en","date_modified":"2024-07-10","date_modified_ts":"2024-07-10T19:46:13Z","date_created":"2024-07-10T19:36:22Z","summary":null,"body":["<article data-history-node-id=\"5343\" about=\"\/en\/alerts-advisories\/sap-security-advisory-july-2024-monthly-rollup-av24-382\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-382<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 10, 2024<\/p>\n\n<p>On July 9, 2024, SAP published a security advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP PDCE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/content\/dam\/support\/en_us\/library\/ssp\/my-support\/knowledge-base\/security-notes-news\/2024%2007%20Patch%20Day%20Blog%20V1.pdf\">SAP Security Patch Day\u00a0- July 2024 (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-july-2024-monthly-rollup-av24-382","alert_type":396,"serial_number":"AV24-382","subject":"sap","moderation_state":"published","external_url":null},{"nid":5344,"title":"Palo Alto Networks security advisory (AV24-383)","uuid":"1f83a961-2c38-4ca4-addd-ce3556846323","banner":null,"lang":"en","date_modified":"2024-07-10","date_modified_ts":"2024-07-10T20:54:29Z","date_created":"2024-07-10T20:48:12Z","summary":null,"body":["<article data-history-node-id=\"5344\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-383\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-383<br \/><strong>Date: <\/strong>July\u00a010, 2024<\/p>\n\n<p>On July\u00a010, 2024, Palo Alto Networks published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Palo Alto Networks Expedition\u00a0\u2013 versions prior to 1.2.92<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-5910\">Palo Alto Networks Security Advisory\u00a0- CVE-2024-5910<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-383","alert_type":396,"serial_number":"AV24-383","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5349,"title":"VMware security advisory (AV24-384)","uuid":"a2dce77d-46b9-42b6-8d78-5cbae4a6e404","banner":null,"lang":"en","date_modified":"2024-07-11","date_modified_ts":"2024-07-11T17:24:54Z","date_created":"2024-07-11T17:20:57Z","summary":null,"body":["<article data-history-node-id=\"5349\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-384\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-384<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 11, 2024<\/p>\n\n<p>On July 10, 2024, VMware released a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Aria Automation\u00a0\u2013 versions 8.x<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 versions 5.x and 4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24598 \">VMware VMSA-2024-0017<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-384","alert_type":396,"serial_number":"AV24-384","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5350,"title":"[Control systems] Siemens security advisory (AV24-385) ","uuid":"a0814df7-e24d-4234-b08f-913b9b5f2333","banner":null,"lang":"en","date_modified":"2024-07-11","date_modified_ts":"2024-07-11T17:43:04Z","date_created":"2024-07-11T17:29:40Z","summary":null,"body":["<article data-history-node-id=\"5350\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-385\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-385<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 11, 2024<\/p>\n\n<p>On July 9, 2024, Siemens published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>JT Open \u2013 versions prior to V11.5<\/li>\n\t<li>JT2Go \u2013 versions prior to V14.3.0.8<\/li>\n\t<li>Mendix Encryption \u2013 versions V10.0.0 and V10.0.1<\/li>\n\t<li>JT Open \u2013 versions prior to V11.5<\/li>\n\t<li>PLM XML SDK \u2013 versions prior to V7.1.0.014<\/li>\n\t<li>RUGGEDCOM APE1808 (configured with Palo Alto Networks Virtual NGFW) \u2013 all versions<\/li>\n\t<li>RUGGEDCOM APE1808 (configured with Fortigate NGFW) \u2013 all versions<\/li>\n\t<li>RUGGEDCOM CROSSBOW \u2013 all versions<\/li>\n\t<li>RUGGEDCOM ROS V4.x, V5.x and II Families \u2013 multiple versions<\/li>\n\t<li>SCALANCE Family Devices \u2013 multiple versions and platforms<\/li>\n\t<li>SIMATIC Energy Manager Basic \u2013 versions prior to V7.5<\/li>\n\t<li>SIMATIC Energy Manager PRO \u2013 versions prior to V7.5<\/li>\n\t<li>SIMATIC IPC DiagBase \u2013 all versions<\/li>\n\t<li>SIMATIC IPC DiagMonitor \u2013 all versions<\/li>\n\t<li>SIMATIC WinCC Runtime Professional V19 \u2013 versions prior to V19 Update 1<\/li>\n\t<li>SIMATIC WinCC Runtime Professional V18 \u2013 all versions<\/li>\n\t<li>SIMATIC WinCC V7.4 \u2013 versions prior to V7.4 SP1 Update 23<\/li>\n\t<li>SIMATIC WinCC V7.5 \u2013 versions prior to V7.5 SP2 Update 16<\/li>\n\t<li>SIMATIC WinCC V8.0 \u2013 versions prior to V8.0 Update 5<\/li>\n\t<li>Simcenter Femap \u2013 versions prior to V2406<\/li>\n\t<li>SIMIT V10 \u2013 all versions<\/li>\n\t<li>SIMIT V11 \u2013 all versions<\/li>\n\t<li>SINEC INS (with RADIUS Server feature enabled) \u2013 all versions<\/li>\n\t<li>SINEMA Remote Connect Server \u2013 versions prior to V3.2 SP1<\/li>\n\t<li>SINEMA Remote Connect Client \u2013 versions prior to V3.2 HF1<\/li>\n\t<li>SIPROTEC 5 CPxxx Devices \u2013 multiple versions and platforms<\/li>\n\t<li>SIPROTEC 5 Communication Modules \u2013 multiple versions and platforms<\/li>\n\t<li>Teamcenter Visualization V14.1 \u2013 versions prior to V14.1.0.14<\/li>\n\t<li>Teamcenter Visualization V14.2 \u2013 versions prior to V14.2.0.10<\/li>\n\t<li>Teamcenter Visualization V14.3 \u2013 versions prior to V14.3.0.8<\/li>\n\t<li>Teamcenter Visualization V2312 \u2013 versions prior to V2312.0002<\/li>\n\t<li>Totally Integrated Automation Portal (TIA Portal) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\u2003\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-385","alert_type":398,"serial_number":"AV24-385","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5351,"title":"GitLab security advisory (AV24-386)","uuid":"518adfbe-5922-4b81-a22b-f77da05afd7a","banner":null,"lang":"en","date_modified":"2024-07-11","date_modified_ts":"2024-07-11T17:58:28Z","date_created":"2024-07-11T17:54:51Z","summary":null,"body":["<article data-history-node-id=\"5351\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-386\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-386<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 11, 2024<\/p>\n\n<p>On July 10, 2024, GitLab published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.1.2, 17.0.4 and 16.11.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.1.2, 17.0.4 and 16.11.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/07\/10\/patch-release-gitlab-17-1-2-released\/\">GitLab Critical Patch Release: 17.1.2, 17.0.4, 16.11.6 <\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/ \u2003\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-386","alert_type":396,"serial_number":"AV24-386","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5352,"title":"Mitel security advisory (AV24-387)","uuid":"2e30551e-42fe-4a60-a96f-225956533baa","banner":null,"lang":"en","date_modified":"2024-07-11","date_modified_ts":"2024-07-11T19:59:45Z","date_created":"2024-07-11T19:55:51Z","summary":null,"body":["<article data-history-node-id=\"5352\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-387\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-387<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 11, 2024<\/p>\n\n<p>On July 10, 2024, Mitel published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitel MiContact Center Enterprise \u2013 version 9.7 SP1 and prior<\/li>\n\t<li>Mitel CMG Suite \u2013 version 9.0 and prior<\/li>\n\t<li>Unify OpenScape Voice Trace Manager \u2013 version V8.R0.9.13 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0018\">Mitel security advisory - 24-0018<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/obso-2407-01\">Mitel security advisory - OBSO-2407-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-387","alert_type":396,"serial_number":"AV24-387","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5355,"title":"Dell security advisory (AV24-388)","uuid":"76f9e098-6d98-4b0e-a518-0363a209764e","banner":null,"lang":"en","date_modified":"2024-07-15","date_modified_ts":"2024-07-15T17:11:19Z","date_created":"2024-07-15T17:00:41Z","summary":null,"body":["<article data-history-node-id=\"5355\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-388\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-388<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 15, 2024<\/p>\n\n<p>Between July 8 and 14, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance\u00a0\u2013 8.0.x versions prior to 8.0.213<\/li>\n\t<li>PowerFlex Custom Node\u00a0\u2013 versions prior to 1.13.2, versions prior to 1.7.2, versions prior to 2.1.5 and versions prior to 2.14.1<\/li>\n\t<li>VxFlex Ready Node\u00a0\u2013 versions prior to 2.21.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000226863\/dsa-2024-289-security-update-for-dell-vxrail-8-0-213-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0\u2013 DSA-2024-289<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000226833\/dsa-2024-311-security-update-for-dell-vxflex-ready-node-and-powerflex-custom-node-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0\u2013 DSA-2024-311<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-388","alert_type":396,"serial_number":"AV24-388","subject":"dell","moderation_state":"published","external_url":null},{"nid":5356,"title":"Ubuntu security advisory (AV24-389)","uuid":"7b9ef6a4-6fa7-4868-9cc4-80c018f6a3c3","banner":null,"lang":"en","date_modified":"2024-07-15","date_modified_ts":"2024-07-15T17:36:31Z","date_created":"2024-07-15T17:20:33Z","summary":null,"body":["<article data-history-node-id=\"5356\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-389\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-389<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 15, 2024<\/p>\n\n<p>Between July 8 and 14, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 23.10<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-389","alert_type":396,"serial_number":"AV24-389","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5357,"title":"IBM security advisory (AV24-390)","uuid":"2df414a9-540a-4453-afa9-013e448f60f5","banner":null,"lang":"en","date_modified":"2024-07-15","date_modified_ts":"2024-07-15T17:50:37Z","date_created":"2024-07-15T17:41:40Z","summary":null,"body":["<article data-history-node-id=\"5357\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-390\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-390<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><\/p>\n\n<p><strong>Date: <\/strong>July 15, 2024<\/p>\n\n<p>Between July 8 and 14, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following product:<\/p>\n\n<ul><li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP8 IF03<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7160134\">IBM Security Bulletin (IBM QRadar SIEM)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-390","alert_type":396,"serial_number":"AV24-390","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5363,"title":"[Control systems] CISA ICS security advisories (AV24-391)","uuid":"edbf30ff-1264-4d1a-be6d-b98b92d4f3d9","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T14:25:54Z","date_created":"2024-07-16T14:25:25Z","summary":null,"body":["<article data-history-node-id=\"5363\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-391\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-391<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2024<\/p>\n\n<p>Between July 8 and 14, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics CNCSoft-G2 \u2013 version 2.0.0.5<\/li>\n\t<li>HMS Industrial Networks Anybus-CompactCom 30 \u2013 all versions<\/li>\n\t<li>Johnson Controls Inc. Illustra Pro Gen 4 Camera \u2013 version SS016.05.03.01.0010 and prior<\/li>\n\t<li>Johnson Controls Inc. Software House C-CURE 9000 \u2013 multiple versions and platforms<\/li>\n\t<li>Mitsubishi Electric MELIPC Series MI5122-VW \u2013 firmware versions \u201c05\u201d to \u201c07\u201d<\/li>\n\t<li>Rockwell Automation FactoryTalk Policy Manager \u2013 version 6.40<\/li>\n\t<li>Rockwell Automation FactoryTalk System Services \u2013 version 6.40<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer \u2013 versions 11.1.0, 11.2.0, 12.0.0, 12.1.0, 13.0.0, 13.1.0 and 13.2.0<\/li>\n\t<li>Siemens IPC DiagBase and DiagMonitor \u2013 all versions<\/li>\n\t<li>Siemens JT2Go \u2013 versions prior to V14.3.0.8<\/li>\n\t<li>Siemens JT Open \u2013 all versions<\/li>\n\t<li>Siemens Mendix Encryption \u2013 version V10.0.0 and prior<\/li>\n\t<li>Siemens PLM XML SDK \u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM \u2013 multiple versions and models<\/li>\n\t<li>Siemens SCALANCE \u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMATIC Energy Manager Basic and Pro \u2013 versions prior to V7.5<\/li>\n\t<li>Siemens SIMATIC PCS neo V4.0 \u2013 all versions<\/li>\n\t<li>Siemens SIMATIC PCS 7 V9.1 \u2013 all versions<\/li>\n\t<li>Siemens SIMATIC STEP 7 \u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMATIC WinCC \u2013 multiple versions and models<\/li>\n\t<li>Siemens Simcenter Femap \u2013 versions prior to V2406<\/li>\n\t<li>Siemens SIMIT \u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMOCODE ES \u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMOTION SCOUT \u2013 all versions, multiple models<\/li>\n\t<li>Siemens SINAMICS Startdrive \u2013 all versions, multiple models<\/li>\n\t<li>Siemens SINEC INS \u2013 multiple versions<\/li>\n\t<li>Siemens SINEMA Remote Connect Client \u2013 versions prior to V3.2 HF1<\/li>\n\t<li>Siemens SINEMA Remote Connect Server \u2013 all versions<\/li>\n\t<li>Siemens SIPLUS NET SCALANCE \u2013 multiple versions and models<\/li>\n\t<li>Siemens SIPROTEC 5 \u2013 multiple versions and models<\/li>\n\t<li>Siemens SIRIUS \u2013 multiple versions and models<\/li>\n\t<li>Siemens Soft Starter \u2013 multiple versions and models<\/li>\n\t<li>Siemens Teamcenter Visualization \u2013 multiple versions<\/li>\n\t<li>Siemens TIA Portal \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-391","alert_type":398,"serial_number":"AV24-391","subject":"other","moderation_state":"published","external_url":null},{"nid":5359,"title":"Exim security advisory (AV23-392)","uuid":"e1e0bf80-1998-4a4e-8015-9bd1a9e7be8a","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T14:50:29Z","date_created":"2024-07-16T14:37:10Z","summary":null,"body":["<article data-history-node-id=\"5359\" about=\"\/en\/alerts-advisories\/exim-security-advisory-av23-392\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-392<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2024<\/p>\n\n<p>On July 10, 2024, Exim published an update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Exim Internet Mailer\u00a0\u2013 versions prior to 4.98<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.exim.org\/lurker\/message\/20240710.155945.8823670d.pt.html\">Exim 4.98 released<\/a><\/li>\n\t<li><a href=\"https:\/\/www.exim.org\/\">Exim Internet Mailer<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-av23-392","alert_type":396,"serial_number":"AV24-392","subject":"other","moderation_state":"published","external_url":null},{"nid":5360,"title":"HPE security advisory (AV24-393)","uuid":"880af5ef-f124-4de4-9e25-7a8a888a31c8","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T15:14:44Z","date_created":"2024-07-16T15:00:16Z","summary":null,"body":["<article data-history-node-id=\"5360\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-393\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-393<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2024<\/p>\n\n<p>On July 11, 2024, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking\u00a0\u2013 multiple products and versions<\/li>\n\t<li>HPE CrayXD665\u00a0\u2013 versions prior to BMC 1.14<\/li>\n\t<li>HPE CrayXD670\u00a0\u2013 versions prior to BMC 1.14<\/li>\n\t<li>HPE Moonshot1500 2.0 Chassis Manager Module\u00a0\u2013 versions prior to v4.0-b43<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04662en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0\u2013 HPE Aruba Networking<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04667en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0\u2013 HPE Cray Servers<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04668en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0\u2013 HPE Moonshot 1500 Chassis Manager 2.0<\/a><\/li>\n\t<li><a href=\"\/en\/alerts-advisories\/radius-protocol-susceptible-forgery-attacks\">Alert\u00a0- RADIUS Protocol Susceptible to Forgery Attacks<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-393","alert_type":396,"serial_number":"AV24-393","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5361,"title":"Juniper security advisory (AV24-394)","uuid":"a4c2fe5b-fbab-4162-923c-9abba839b634","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T15:41:02Z","date_created":"2024-07-16T15:35:13Z","summary":null,"body":["<article data-history-node-id=\"5361\" about=\"\/en\/alerts-advisories\/juniper-security-advisory-av24-394\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-394<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2024<\/p>\n\n<p>Between July 10 and 15, 2024, Juniper published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BBE Cloudsetup (BCS)\u00a0\u2013 versions prior to 2.1.0<\/li>\n\t<li>Junos OS\u00a0\u2013 multiple versions<\/li>\n\t<li>Juno OS Evolved\u00a0\u2013 multiple versions<\/li>\n\t<li>Junos Space\u00a0\u2013 versions prior to 24.1R1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&amp;f:ctype=[Security%20Advisories]\">Juniper Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-security-advisory-av24-394","alert_type":396,"serial_number":"AV24-394","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5362,"title":"HPE security advisory (AV24-395)","uuid":"c0935622-144c-4ef0-bbef-23853797a520","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T15:56:13Z","date_created":"2024-07-16T15:43:58Z","summary":null,"body":["<article data-history-node-id=\"5362\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-395\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-395<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16 2024<\/p>\n\n<p>On July 16, 2024, HPE published security advisories to address vulnerabilities in multiple products. Included was an update for the following product:<\/p>\n\n<ul><li>HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Unified Console<\/span>\u00a0versions prior to v3.1.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04665en_us&amp;docLocale=en_US\">HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Security Bulletin<\/span>\u00a0- hpesbgn04665en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-395","alert_type":396,"serial_number":"AV24-395","subject":"other","moderation_state":"published","external_url":null},{"nid":5364,"title":"Red Hat security advisory (AV24-396)","uuid":"1374f1fb-9ac0-4f5a-8ffb-cce8834ba9f3","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T18:40:48Z","date_created":"2024-07-16T18:24:31Z","summary":null,"body":["<article data-history-node-id=\"5364\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-396\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-396<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2024<\/p>\n\n<p>Between July 8 and 14, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4412\">Red Hat security advisory\u00a0\u2013 RHSA-2024:4412<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4415\">Red Hat security advisory\u00a0\u2013 RHSA-2024:4415<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4447\">Red Hat security advisory\u00a0\u2013 RHSA-2024:4447<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-396","alert_type":396,"serial_number":"AV24-396","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5365,"title":"Atlassian security advisory (AV24-397)","uuid":"5e73a473-90e0-47a9-af24-70b6e44e7661","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T18:55:37Z","date_created":"2024-07-16T18:46:03Z","summary":null,"body":["<article data-history-node-id=\"5365\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-397\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-397<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2024<\/p>\n\n<p>On July 16, 2024, Atlassian published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiples versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiples versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiples versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-july-16-2024-1417150917.html\">Atlassian July 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-397","alert_type":396,"serial_number":"AV24-397","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5366,"title":"Ivanti security advisory (AV24-398)","uuid":"f7b046fe-6e75-4929-8ccd-11362ce8a25f","banner":null,"lang":"en","date_modified":"2024-07-16","date_modified_ts":"2024-07-16T19:06:14Z","date_created":"2024-07-16T18:59:59Z","summary":null,"body":["<article data-history-node-id=\"5366\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-398\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-398<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2024<\/p>\n\n<p>On July 16, 2024, Ivanti published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager (EPM) 2024 flat<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-EPM-July-2024-for-EPM-2024?language=en_US\">KB Security Advisory Ivanti Endpoint Manager (EPM) July 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-398","alert_type":396,"serial_number":"AV24-398","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5367,"title":"HPE security advisory (AV24-399)","uuid":"cacd4b84-1f6d-4665-97d7-e445b5c5aa87","banner":null,"lang":"en","date_modified":"2024-07-17","date_modified_ts":"2024-07-17T14:44:01Z","date_created":"2024-07-17T14:39:29Z","summary":null,"body":["<article data-history-node-id=\"5367\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-399\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-399<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 17, 2024<\/p>\n\n<p>On July 16, 2024, HPE published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>HPE 3PAR Service Processor\u00a0\u2013 versions v5.1.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04663en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbst04663<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-399","alert_type":396,"serial_number":"AV24-399","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5368,"title":"Cisco security advisory (AV24-400)","uuid":"dfba77e7-1a22-40ee-9333-dc1e1601c256","banner":null,"lang":"en","date_modified":"2024-07-17","date_modified_ts":"2024-07-17T14:55:50Z","date_created":"2024-07-17T14:50:27Z","summary":null,"body":["<article data-history-node-id=\"5368\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-400\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-400<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 17, 2024<\/p>\n\n<p>In July 2024, Cisco published a security advisory to address a vulnerability in OpenSSH Server which is used in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"\/en\/alerts-advisories\/openssh-security-advisory-av24-366\">OpenSSH security advisory (AV24-366)<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-openssh-rce-2024\">Cisco Security Advisory\u00a0\u2013 cisco-sa-openssh-rce-2024<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-400","alert_type":396,"serial_number":"AV24-400","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5369,"title":"Oracle security advisory \u2013 July 2024 quarterly rollup (AV24-401) - Update 1","uuid":"16cfba36-4f6d-4c2e-9514-c95dfc2af71d","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T17:39:35Z","date_created":"2024-07-17T15:50:26Z","summary":null,"body":["<article data-history-node-id=\"5369\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-july-2024-quarterly-rollup-av24-401\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-401<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 17, 2024<br \/><strong>Updated: <\/strong>June 1, 2026<\/p>\n\n<p>On July 16, 2024, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Financial Services Application<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle Siebel CRM<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On June 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2024.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 July 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21182\">CISA KEV: CVE-2024-21182<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-july-2024-quarterly-rollup-av24-401","alert_type":396,"serial_number":"AV24-401","subject":"other","moderation_state":"published","external_url":null},{"nid":5370,"title":"Google Chrome security advisory (AV24-402)","uuid":"1a82696c-318e-4d58-94a8-fc20f3a7f5c9","banner":null,"lang":"en","date_modified":"2024-07-17","date_modified_ts":"2024-07-17T16:07:25Z","date_created":"2024-07-17T16:03:00Z","summary":null,"body":["<article data-history-node-id=\"5370\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-402\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-402<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 17, 2024<\/p>\n\n<p>On July 16, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 126.0.6478.182\/183 (Windows and Mac) and 126.0.6478.182 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/07\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-402","alert_type":396,"serial_number":"AV24-402","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5371,"title":"Cisco security advisory (AV24-403)","uuid":"cc0ba967-86b2-4f80-b981-25d2f44ab820","banner":null,"lang":"en","date_modified":"2024-07-17","date_modified_ts":"2024-07-17T17:54:45Z","date_created":"2024-07-17T17:28:48Z","summary":null,"body":["<article data-history-node-id=\"5371\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-403\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-403<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 17, 2024<\/p>\n\n<p>In July 2024, Cisco published a security advisory to address a vulnerability in the RADIUS protocol which is used in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-radius-spoofing-july-2024-87cCDwZ3\">Cisco Security Advisory\u00a0- cisco-sa-radius-spoofing-july-2024-87cCDwZ3<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"\/en\/alerts-advisories\/radius-protocol-susceptible-forgery-attacks\">Alert\u00a0- RADIUS Protocol Susceptible to Forgery Attacks<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-403","alert_type":396,"serial_number":"AV24-403","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5373,"title":"Cisco security advisory (AV24-404)","uuid":"5a3b646c-4f8c-4c71-a8a3-6c297c723eea","banner":null,"lang":"en","date_modified":"2024-07-17","date_modified_ts":"2024-07-17T20:27:08Z","date_created":"2024-07-17T20:10:55Z","summary":null,"body":["<article data-history-node-id=\"5373\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-404\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-404<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 17, 2024<\/p>\n\n<p>On July 17, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco AsyncOS for Secure Web Appliance\u00a0\u2013 versions 14.5, 15.0 and 15.1<\/li>\n\t<li>Cisco Secure Email Gateway\u00a0\u2013 Content Scanner Tools versions prior to 23.3.0.4823<\/li>\n\t<li>Cisco Smart Software Manager On-Prem (SSM On-Prem)\u00a0\u2013 version 8-202206 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-swa-priv-esc-7uHpZsCC\">Cisco Security Advisory\u00a0- cisco-sa-swa-priv-esc-7uHpZsCC<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-esa-afw-bGG2UsjH\">Cisco Security Advisory\u00a0- cisco-sa-esa-afw-bGG2UsjH<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cssm-auth-sLw3uhUy\">Cisco Security Advisory\u00a0- cisco-sa-cssm-auth-sLw3uhUy<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-404","alert_type":396,"serial_number":"AV24-404","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5376,"title":"Mitel security advisory (AV24-405)","uuid":"abd1f824-13bc-47de-a9ec-fa34d8619ba5","banner":null,"lang":"en","date_modified":"2024-07-18","date_modified_ts":"2024-07-18T15:08:30Z","date_created":"2024-07-18T14:41:22Z","summary":null,"body":["<article data-history-node-id=\"5376\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-405\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-405<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 18, 2024<\/p>\n\n<p>On July 17, 2024, Mitel published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitel 6800 Series SIP Phones\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n\t<li>Mitel 6900 Series SIP Phones\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n\t<li>Mitel 6900w Series SIP Phones\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n\t<li>Mitel 6970 Conference Unit\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n\t<li>Unify OpenScape 4000\u00a0\u2013 version v11 R0.22 and prior<\/li>\n\t<li>Unify OpenScape 4000 Assistant\u00a0\u2013 version v11 R0.22 and prior<\/li>\n\t<li>Unify OpenScape 4000 Manager\u00a0\u2013 versions v10 R1.34, V10 R1.42 and v11 R0.22 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0019\">Mitel security advisory\u00a0- 24-0019<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0020\">Mitel security advisory\u00a0- 24-0020<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/obso-2407-02\">Mitel security advisory\u00a0- OBSO-2407-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/obso-2407-03\">Mitel security advisory\u00a0- OBSO-2407-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-405","alert_type":396,"serial_number":"AV24-405","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5377,"title":"SolarWinds security advisory (AV24-406)","uuid":"f830d78b-47e8-443b-b07e-402f52ad1df9","banner":null,"lang":"en","date_modified":"2024-07-18","date_modified_ts":"2024-07-18T15:53:43Z","date_created":"2024-07-18T15:14:51Z","summary":null,"body":["<article data-history-node-id=\"5377\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-406\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-406<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 18, 2024<\/p>\n\n<p>On July 17, 2024, SolarWinds published security advisories to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>SolarWinds Access Rights Manager (ARM)\u00a0\u2013 version 2023.2.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-23471\">SolarWinds Access Rights Manager (ARM) CreateFile Directory Traversal Remote Code Execution Vulnerability (CVE-2024-23471)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-23469\">SolarWinds Access Rights Manager Exposed Dangerous Method Remote Code Execution Vulnerability (CVE-2024-23469)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-28074\">SolarWinds Access Rights Manager (ARM) Internal Deserialization Remote Code Execution Vulnerability (CVE-2024-28074)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-23472\">SolarWinds ARM Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability (CVE-2024-23472)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-406","alert_type":396,"serial_number":"AV24-406","subject":"other","moderation_state":"published","external_url":null},{"nid":5378,"title":"ServiceNow security advisory (AV24-407)","uuid":"d4fd925b-4ef5-4bfa-ae98-19192bea2c17","banner":null,"lang":"en","date_modified":"2024-07-18","date_modified_ts":"2024-07-18T18:18:54Z","date_created":"2024-07-18T18:05:23Z","summary":null,"body":["<article data-history-node-id=\"5378\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av24-407\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-407<br \/><strong>Date: <\/strong>July 18, 2024<\/p>\n\n<p>On July 10, 2024, ServiceNow published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>ServiceNow Utah\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Vancouver\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Washington\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1645154\">CVE-2024-4879\u00a0- Jelly Template Injection Vulnerability in ServiceNow UI Macros<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1648313\">CVE-2024-5217\u00a0\u2013 Incomplete Input Validation in GlideExpression Script<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_browse&amp;kb_knowledge_base=7c8751eadbd95d9055b5e14c13961967&amp;category=e6e9d566db1d5d9055b5e14c139619ee\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av24-407","alert_type":396,"serial_number":"AV24-407","subject":"other","moderation_state":"published","external_url":null},{"nid":5379,"title":"Ivanti security advisory (AV24-408)","uuid":"53d543c2-144f-42fa-9549-e5da8003d5a3","banner":null,"lang":"en","date_modified":"2024-07-18","date_modified_ts":"2024-07-18T19:17:14Z","date_created":"2024-07-18T18:54:01Z","summary":null,"body":["<article data-history-node-id=\"5379\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-408\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-408<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 18, 2024<\/p>\n\n<p>On July 17, 2024, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager for Mobile (EPMM)\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024?language=en_US\">Security Advisory Ivanti Endpoint Manager for Mobile (EPMM) July 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-408","alert_type":396,"serial_number":"AV24-408","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5380,"title":"Issue impacting CrowdStrike Falcon EDR","uuid":"e3958687-9700-4de8-856d-b95e86921027","banner":null,"lang":"en","date_modified":"2024-07-19","date_modified_ts":"2024-07-19T16:20:00Z","date_created":"2024-07-19T13:08:54Z","summary":null,"body":["<article data-history-node-id=\"5380\" about=\"\/en\/alerts-advisories\/issue-impacting-crowdstrike-falcon-edr\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL24-010<br \/><strong>Date: <\/strong>July\u00a019, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On July 19, 2024, the Cyber Centre became aware of an issue impacting systems worldwide resulting from a faulty software update within the CrowdStrike Falcon Endpoint Detection and Response tool (EDR). The faulty update referred to as a \u2018channel file\u2019 has resulted in Windows based systems employing this tool to crash and not restore themselves automatically. CrowdStrike has indicated that this error only impacts Windows systems, with Mac and Linux hosts unaffected.<\/p>\n\n<p>Impact of this issue has been observed within Canada and worldwide. Organizations who employ the CrowdStrike Falcon <abbr title=\"Endpoint Detection and Response tool\">EDR <\/abbr> solution are encouraged to review the suggested actions below to restore impacted systems and seek further guidance found on the CrowdStrike support portal for the latest updates. <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/p>\n\n<p>The Cyber Centre has received reports that threat actors are using this incident for the purpose of phishing and other related malicious activity. The Cyber Centre recommends organizations reinforce to employees to only trust recommended sources and to not click links on untrusted or questionable emails.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that affected organizations follow the steps below to remove the affected channel files on any impacted systems that are crashing during boot:<\/p>\n\n<ol><li>Boot Windows into Safe Mode or Windows Recovery Environment (WinRe).<\/li>\n\t<li>Go to C:\\Windows\\System32\\drivers\\CrowdStrike<\/li>\n\t<li>Locate and delete file(s) matching \"C-00000291*.sys\"<\/li>\n\t<li>Boot normally.<br \/><strong>Please note that organizations which use Bitlocker may require a recovery key.<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/strong><\/li>\n<\/ol><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.crowdstrike.com\/blog\/statement-on-windows-sensor-update\/\">CrowdStrike Windows Sensor Update<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1a-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/supportportal.crowdstrike.com\/s\/login\/\">CrowdStrike Customer Center<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/finding-your-bitlocker-recovery-key-in-windows-6b71ad27-0b89-ea08-f143-056f5ab347d6\">Finding your BitLocker recovery key in Windows<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/issue-impacting-crowdstrike-falcon-edr","alert_type":397,"serial_number":"AL24-010","subject":"other","moderation_state":"published","external_url":null},{"nid":5381,"title":"Microsoft Edge security advisory (AV24-409)","uuid":"277f89c5-64f8-48ef-a282-6a35504ad4cb","banner":null,"lang":"en","date_modified":"2024-07-19","date_modified_ts":"2024-07-19T17:22:15Z","date_created":"2024-07-19T17:14:33Z","summary":null,"body":["<article data-history-node-id=\"5381\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-409\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-409<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><\/p>\n\n<p><strong>Date: <\/strong>July 19, 2024<\/p>\n\n<p>On July 18, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 120.2592.113<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-18-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-409","alert_type":396,"serial_number":"AV24-409","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5382,"title":"Ubuntu security advisory (AV24-410)","uuid":"0d72194a-5b6f-4b97-a0fc-4445d0937066","banner":null,"lang":"en","date_modified":"2024-07-22","date_modified_ts":"2024-07-22T14:53:47Z","date_created":"2024-07-22T14:46:01Z","summary":null,"body":["<article data-history-node-id=\"5382\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-410\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-410<br \/><strong>Date: <\/strong>July 22, 2024<\/p>\n\n<p>Between July 15 and 21, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-410","alert_type":396,"serial_number":"AV24-410","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5383,"title":"IBM security advisory (AV24-411)","uuid":"07807701-5c33-4d2c-88cf-a63eeb9f9c7b","banner":null,"lang":"en","date_modified":"2024-07-22","date_modified_ts":"2024-07-22T17:22:33Z","date_created":"2024-07-22T17:01:38Z","summary":null,"body":["<article data-history-node-id=\"5383\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-411\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-411<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 22, 2024<\/p>\n\n<p>Between July 15 and 21, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Engineering Requirements Management DOORS\u00a0\u2013 version 9.7.2.8<\/li>\n\t<li>IBM Engineering Requirements Management DOORS Web Access\u00a0\u2013 version 9.7.2.8<\/li>\n\t<li>IBM Robotic Process Automation\u00a0\u2013 version 21.0.0 to 21.0.7.14 and 23.0.0 to 23.0.14<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak\u00a0\u2013 version 21.0.0 to 21.0.7.14 and 23.0.0 to 23.0.14<\/li>\n\t<li>IBM Security Guardium\u00a0\u2013 version 12.0<\/li>\n\t<li>IBM Storage Ceph\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-411","alert_type":396,"serial_number":"AV24-411","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5384,"title":"Dell security advisory (AV24-412)","uuid":"a4e2556f-bb90-45bb-b616-517c2fc5dfe8","banner":null,"lang":"en","date_modified":"2024-07-22","date_modified_ts":"2024-07-22T17:53:14Z","date_created":"2024-07-22T17:32:41Z","summary":null,"body":["<article data-history-node-id=\"5384\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-412\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-412<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 22, 2024<\/p>\n\n<p>Between July 15 and 21, 2024, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Dell<\/span> published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Data Protection Search\u00a0\u2013 versions 19.4.0, 19.5.0, 19.5.1, 19.6.0, 19.6.1, 19.6.2, 19.6.3, 19.6.4 and 19.3.0<\/li>\n\t<li>Dell ECS\u00a0\u2013 versions prior to 3.8.1.1<\/li>\n\t<li>Integrated Data Protection Appliance (IDPA)\u00a0\u2013 versions prior to 2.7.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000226918\/dsa-2024-031-security-update-for-dell-data-protection-search-for-multiple-third-party-component-vulnerabilities\">Dell Security Update DSA-2024-031<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000227051\/dsa-2024-239-security-update-dell-ecs-3-8-1-1-for-multiple-security-vulnerabilities\">Dell Security Update DSA-2024-239<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000220651\/dsa-2023-416-security-update-for-dell-powerprotect-dp-series-appliance-idpa-infrastructure-for-multiple-vulnerabilities\">Dell Security Update DSA-2024-416<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-412","alert_type":396,"serial_number":"AV24-412","subject":"dell","moderation_state":"published","external_url":null},{"nid":5385,"title":"[Control systems] CISA ICS security advisories (AV24-413) ","uuid":"6d0b7a29-28c1-4928-96d1-91a43a349686","banner":null,"lang":"en","date_modified":"2024-07-22","date_modified_ts":"2024-07-22T18:17:11Z","date_created":"2024-07-22T17:56:46Z","summary":null,"body":["<article data-history-node-id=\"5385\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-413\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-413<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 22, 2024<\/p>\n\n<p>Between July 15 and 21, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Philips Vue PACS\u00a0\u2013 versions prior to 12.2.8.410<\/li>\n\t<li>Subnet Solutions PowerSYSTEM Center 2020\u00a0\u2013 update 20 and prior<\/li>\n\t<li>Mitsubishi Electric MELSOFT MaiLab\u00a0\u2013 versions 1.00A to 1.05F<\/li>\n\t<li>Rockwell Automation Pavilion 8\u00a0\u2013 versions 5.15.00 through 5.20.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-medical-advisories\/icsma-24-200-01\">CISA ICS Advisory\u00a0- ICSMA-24-200-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-200-02\">CISA ICS Advisory\u00a0- ICSA-24-200-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-200-01\">CISA ICS Advisory\u00a0- ICSA-24-200-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-198-01\">CISA ICS Advisory\u00a0- ICSA-24-198-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-413","alert_type":398,"serial_number":"AV24-413","subject":"ics","moderation_state":"published","external_url":null},{"nid":5386,"title":"Sonicwall advisory (AV24-414)","uuid":"ef65f64d-7822-4cd8-9878-42ffadd4885e","banner":null,"lang":"en","date_modified":"2024-07-22","date_modified_ts":"2024-07-22T19:02:05Z","date_created":"2024-07-22T18:42:33Z","summary":null,"body":["<article data-history-node-id=\"5386\" about=\"\/en\/alerts-advisories\/sonicwall-advisory-av24-414\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-414<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 22, 2024<\/p>\n\n<p>On July 17, 2024, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Sonicwall<\/span> published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>SonicOS IPSEC VPN\u00a0\u2013 multiple products and versions<\/li>\n\t<li>SMA100 NetExtender Windows Client\u00a0\u2013 versions 10.2.339 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">Sonicwall security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-advisory-av24-414","alert_type":396,"serial_number":"AV24-414","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":5389,"title":"HPE advisory (AV24-415)","uuid":"b28e4e7b-7cfb-47c9-8c50-049bb1f17b98","banner":null,"lang":"en","date_modified":"2024-07-23","date_modified_ts":"2024-07-23T13:58:45Z","date_created":"2024-07-23T13:53:18Z","summary":null,"body":["<article data-history-node-id=\"5389\" about=\"\/en\/alerts-advisories\/hpe-advisory-av24-415\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-415<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 23, 2024<\/p>\n\n<p>On July 22, 2024, HPE published a security advisory to address vulnerabilities for the following products:<\/p>\n\n<ul><li>HPE Alletra 4110 \u2013 version 2.20_05-27-2024 and prior<\/li>\n\t<li>HPE Alletra 4120 \u2013 version 2.20_05-27-2024 and prior<\/li>\n\t<li>HPE Compute Edge Server e930t \u2013 version 2.20_05-27-2024 and prior<\/li>\n\t<li>HPE ProLiant \u2013 multiple versions and platforms<\/li>\n\t<li>HPE Synergy \u2013 multiple versions and platforms<\/li>\n\t<li>HPE Apollo \u2013 multiple versions and platforms<\/li>\n\t<li>HPE Edgeline \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04671en_us&amp;docLocale=en_US\">HPE security advisory - hpesbhf04671en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE security bulletin library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-advisory-av24-415","alert_type":396,"serial_number":"AV24-415","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5397,"title":"Red Hat security advisory (AV24-416)","uuid":"05c918a1-9e5c-415f-9495-c259fb696fd0","banner":null,"lang":"en","date_modified":"2024-07-23","date_modified_ts":"2024-07-23T20:26:14Z","date_created":"2024-07-23T20:06:34Z","summary":null,"body":["<article data-history-node-id=\"5397\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-416\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-416<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 23, 2024<\/p>\n\n<p>Between July 15 and 21, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4583\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:4583<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:4533\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:4533<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-416","alert_type":396,"serial_number":"AV24-416","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5399,"title":"[Control systems] Siemens security advisory (AV24-417)","uuid":"0a9be7b9-09a5-4b61-9c08-b06da732b977","banner":null,"lang":"en","date_modified":"2024-07-25","date_modified_ts":"2024-07-25T13:06:33Z","date_created":"2024-07-25T12:56:09Z","summary":null,"body":["<article data-history-node-id=\"5399\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-417\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-417<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 25, 2024<\/p>\n\n<p>On July 22, 2024, Siemens published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>SICAM device family\u00a0\u2013 multiples versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-071402.html?ste_sid=6d8b8accb9a1815b5a31e156f3f65246\">Siemens\u00a0\u2013 SSA-071402\u00a0\u2013 SICAM<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-417","alert_type":398,"serial_number":"AV24-417","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5400,"title":"Mitel security advisory (AV24-418)","uuid":"ffe5e539-555f-4ae0-9d52-71c1e480b20e","banner":null,"lang":"en","date_modified":"2024-07-25","date_modified_ts":"2024-07-25T14:12:50Z","date_created":"2024-07-25T13:13:48Z","summary":null,"body":["<article data-history-node-id=\"5400\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-418\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-418<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 25, 2024<\/p>\n\n<p>On July 24, 2024, Mitel published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitel MiCollab\u00a0\u2013 version 9.8 SP1 (9.8.1.5) and prior<\/li>\n\t<li>Mitel MiVB\u00a0\u2013 version 1.0.0.27 and prior<\/li>\n\t<li>Mitel 6800 Series SIP Phones\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n\t<li>Mitel 6900 Series SIP Phones\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n\t<li>Mitel 6900w Series SIP Phone\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n\t<li>Mitel 6970 Conference Unit\u00a0\u2013 version R6.4.0.HF1 (R6.4.0.136) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0022\">Mitel security advisory\u00a0- 24-0022<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0023\">Mitel security advisory\u00a0- 24-0023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-418","alert_type":396,"serial_number":"AV24-418","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5401,"title":"ISC BIND security advisory (AV24-419)","uuid":"5be317bc-97ae-4257-a395-b9344872e5f9","banner":null,"lang":"en","date_modified":"2024-07-25","date_modified_ts":"2024-07-25T14:49:51Z","date_created":"2024-07-25T14:17:01Z","summary":null,"body":["<article data-history-node-id=\"5401\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av24-419\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-419<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 25, 2024<\/p>\n\n<p>On July 23, 2024, ISC published a Security Advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ISC BIND 9\u00a0- versions 9.0.0 to 9.11.37, 9.16.0 to 9.16.50, 9.18.0 to 9.18.27, 9.19.0 to 9.19.24, 9.9.3-S1 to 9.11.37-S1, 9.16.8-S1 to 9.16.49-S1 and 9.18.11-S1 to 9.18.27-S1<\/li>\n<\/ul><p>Exploitation of these vulnerabilities could lead to a denial of service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/v1\/docs\/cve-2024-0760\">ISC BIND <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">security advisory<\/span>\u00a0- CVE-2024-0760<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Security Vulnerability Matrix<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av24-419","alert_type":396,"serial_number":"AV24-419","subject":"ics","moderation_state":"published","external_url":null},{"nid":5402,"title":"Google Chrome security advisory (AV24-420)","uuid":"171c1475-2809-425f-9202-971af924a388","banner":null,"lang":"en","date_modified":"2024-07-25","date_modified_ts":"2024-07-25T15:11:17Z","date_created":"2024-07-25T14:53:05Z","summary":null,"body":["<article data-history-node-id=\"5402\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-420\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-420<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 25, 2024<\/p>\n\n<p>On July 23, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 127.0.6533.72\/73 (Windows and Mac) and 127.0.6533.72 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/07\/stable-channel-update-for-desktop_23.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-420","alert_type":396,"serial_number":"AV24-420","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5403,"title":"HPE security advisory (AV24-421)","uuid":"79adc3c2-d993-470e-86e5-19226a72164f","banner":null,"lang":"en","date_modified":"2024-07-25","date_modified_ts":"2024-07-25T18:36:47Z","date_created":"2024-07-25T18:11:00Z","summary":null,"body":["<article data-history-node-id=\"5403\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-421\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-421<br \/><strong>Date: <\/strong>July\u00a025, 2024<\/p>\n\n<p>On July\u00a022, 2024, HPE published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE Alletra 4110 and 4120\u00a0\u2013 versions prior to 2.20_05-27-2024<\/li>\n\t<li>HPE ProLiant\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Synergy 480 and 660\u00a0\u2013 versions prior to v3.20_05-27-2024<\/li>\n\t<li>HPE Apollo 2000 and 4200\u00a0\u2013 versions prior to v2.10_05-27-2024<\/li>\n\t<li>HPE Edgeline\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Compute Edge Server e930t\u00a0\u2013 versions prior to v2.20_05-27-2024<\/li>\n\t<li>HPE EdgeConnect SD-Wan orchestrator\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Unified OSS Console Assurance Monitoring (UOCAM)\u00a0\u2013 versions prior to 3.1.7<\/li>\n\t<li>HPE Aruba networking EdgeConnect SD-Wan\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04671en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04671en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04672en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04672en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04673en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04673en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-421","alert_type":396,"serial_number":"AV24-421","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5404,"title":"Microsoft Edge security advisory (AV24-422)","uuid":"d13c6f7f-bd7d-49fb-9e68-d099e34f1ad6","banner":null,"lang":"en","date_modified":"2024-07-26","date_modified_ts":"2024-07-26T17:47:27Z","date_created":"2024-07-26T17:15:52Z","summary":null,"body":["<article data-history-node-id=\"5404\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-422\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-422<br \/><strong>Date: <\/strong>July\u00a026, 2024<\/p>\n\n<p>On July\u00a025, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 127.0.2651.74<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/deployedge\/microsoft-edge-relnotes-security#july-25-2024\">Release notes for Microsoft Edge Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-422","alert_type":396,"serial_number":"AV24-422","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5405,"title":"Dell security advisory (AV24-423)","uuid":"ca95ce1d-4e3a-424c-832f-1849701835c0","banner":null,"lang":"en","date_modified":"2024-07-29","date_modified_ts":"2024-07-29T16:01:18Z","date_created":"2024-07-29T15:53:09Z","summary":null,"body":["<article data-history-node-id=\"5405\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-423\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-423<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 29, 2024<\/p>\n\n<p>Between July 22 and 28, 2024, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Dell<\/span> published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>DD3300 Appliance\u00a0\u2013 versions prior to 7.10.1.0, 7.11.0.0 and 7.7.5.1<\/li>\n\t<li>DD6400 Appliance\u00a0\u2013 versions prior to 7.10.1.0, 7.11.0.0 and 7.7.5.1<\/li>\n\t<li>DD6900 Appliance\u00a0\u2013 versions prior to 7.10.1.0 and 7.11.0.0<\/li>\n\t<li>DD9400 Appliance\u00a0\u2013 versions prior to 7.10.1.0, 7.11.0.0 and 7.7.5.1<\/li>\n\t<li>DD9410 Appliance\u00a0\u2013 versions prior to 8.1.0.0 and 8.2.0.0<\/li>\n\t<li>DD9900 Appliance\u00a0\u2013 versions prior to 7.10.1.0, 7.11.0.0 and 7.7.5.1<\/li>\n\t<li>DD9910 Appliance\u00a0\u2013 versions prior to 8.1.0.0 and 8.2.0.0<\/li>\n\t<li>Dell Protection Advisor\u00a0\u2013 versions 19.8, 19.9 and 19.10<\/li>\n\t<li>Dell Power Protect Data Manager\u00a0\u2013 versions prior to 19.17 build 10<\/li>\n\t<li>Dell PowerProtect DDOS\u00a0\u2013 multiple products and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-423","alert_type":396,"serial_number":"AV24-423","subject":"dell","moderation_state":"published","external_url":null},{"nid":5406,"title":"IBM security advisory (AV24-424)","uuid":"a78eeb06-a55f-4b9a-a21f-bb1428ca6662","banner":null,"lang":"en","date_modified":"2024-07-29","date_modified_ts":"2024-07-29T16:13:51Z","date_created":"2024-07-29T15:53:09Z","summary":null,"body":["<article data-history-node-id=\"5406\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-424\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-424<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 29, 2024<\/p>\n\n<p>Between July 22 and 28, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>CICS Transaction Gateway Desktop Edition\u00a0\u2013 versions 9.2 and 9.3<\/li>\n\t<li>HMC V10.2.1030.0\u00a0\u2013 version V10.2.1030.0<\/li>\n\t<li>HMC V10.3.1050.0\u00a0\u2013 version V10.3.1050.0<\/li>\n\t<li>IBM CICS Transaction Gateway for Multiplatforms\u00a0\u2013 versions 9.2 and 9.3<\/li>\n\t<li>IBM WebSphere Remote Server\u00a0\u2013 versions 8.5, 9.0 and 9.1<\/li>\n\t<li>IBM Storage Ceph\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP8 IF03<\/li>\n\t<li>IBM QRadar Network Packet Capture\u00a0\u2013 versions 7.5.0 to 7.5.0 Update Package 7<\/li>\n\t<li>IBM QRadar Data Synchronization App\u00a0\u2013 versions 1.0 to 3.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-424","alert_type":396,"serial_number":"AV24-424","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5408,"title":"Ubuntu security advisory (AV24-425)","uuid":"d300e266-6a67-4af9-9ff9-20686fe827b6","banner":null,"lang":"en","date_modified":"2024-07-29","date_modified_ts":"2024-07-29T17:41:07Z","date_created":"2024-07-29T17:10:56Z","summary":null,"body":["<article data-history-node-id=\"5408\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-425\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-425<br \/><strong>Date: <\/strong>July\u00a029, 2024<\/p>\n\n<p>Between July\u00a022 and 28, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-425","alert_type":396,"serial_number":"AV24-425","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5409,"title":"[Control systems] CISA ICS security advisories (AV24-426)","uuid":"3ba50f52-10c9-40ef-bfbc-319399a2816b","banner":null,"lang":"en","date_modified":"2024-07-29","date_modified_ts":"2024-07-29T18:03:23Z","date_created":"2024-07-29T17:10:57Z","summary":null,"body":["<article data-history-node-id=\"5409\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-426\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-426<br \/><strong>Date: <\/strong>July\u00a029, 2024<\/p>\n\n<p>Between July\u00a022 and 28, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Energy AFS650\u00a0\u2013 version 9.1.08 and prior<\/li>\n\t<li>Hitachi Energy AFS660-C\u00a0\u2013 versions 7.1.05 and prior<\/li>\n\t<li>Hitachi Energy AFS665-B\u00a0\u2013 versions 7.1.05 and prior<\/li>\n\t<li>Hitachi Energy AFS670-V2\u00a0\u2013 versions 7.1.05 and prior<\/li>\n\t<li>Hitachi Energy AFS670\u00a0\u2013 versions 9.1.08 and prior<\/li>\n\t<li>Hitachi Energy AFS675\u00a0\u2013 versions 9.1.08 and prior<\/li>\n\t<li>Hitachi Energy AFS677\u00a0\u2013 versions 9.1.08 and prior<\/li>\n\t<li>Hitachi Energy AFR677\u00a0\u2013 versions 9.1.08 and prior<\/li>\n\t<li>National Instruments I\/O TRACE\u00a0\u2013 all versions<\/li>\n\t<li>National Instruments LabVIEW\u00a0\u2013 versions 24.1f0 and prior<\/li>\n\t<li>Positron S.R.L Broadcast Signal Processor TRA7005\u00a0\u2013 version v1.20<\/li>\n\t<li>Siemens CPCI85 Central Processing\/Communication\u00a0\u2013 versions prior to V5.40<\/li>\n\t<li>Siemens SICORE Base system\u00a0\u2013 versions prior to V1.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-426","alert_type":398,"serial_number":"AV24-426","subject":"ics","moderation_state":"published","external_url":null},{"nid":5407,"title":"Red Hat security advisory (AV24-427)","uuid":"a5f29b11-f3bc-4cbd-8cd2-6b0ae7744c32","banner":null,"lang":"en","date_modified":"2024-07-29","date_modified_ts":"2024-07-29T18:28:33Z","date_created":"2024-07-29T17:18:12Z","summary":null,"body":["<article data-history-node-id=\"5407\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-427\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-427<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><\/p>\n\n<p><strong>Date: <\/strong>July 29, 2024<\/p>\n\n<p>Between July 22 and 28, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-427","alert_type":396,"serial_number":"AV24-427","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5410,"title":"Apple security advisory (AV24-428)","uuid":"a476c675-088a-49de-86b1-3d8735190284","banner":null,"lang":"en","date_modified":"2024-07-30","date_modified_ts":"2024-07-30T12:54:30Z","date_created":"2024-07-30T12:49:09Z","summary":null,"body":["<article data-history-node-id=\"5410\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-428\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-428<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 30, 2024<\/p>\n\n<p>On July 29, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 15.8.3<\/li>\n\t<li>iOS and iPadOS \u2013 versions prior to iOS 16.7.9<\/li>\n\t<li>iOS and iPadOS \u2013 versions prior to 17.6<\/li>\n\t<li>macOS Monterey \u2013 versions prior to 12.7.6<\/li>\n\t<li>macOS Sonoma \u2013 versions prior to 14.6<\/li>\n\t<li>macOS Ventura \u2013 versions prior to 13.6.8<\/li>\n\t<li>Safari \u2013 versions prior to 17.6<\/li>\n\t<li>tvOS \u2013 versions prior to 17.6<\/li>\n\t<li>visionOS \u2013 versions prior to 1.3<\/li>\n\t<li>watchOS \u2013 versions prior to 10.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-428","alert_type":396,"serial_number":"AV24-428","subject":"apple","moderation_state":"published","external_url":null},{"nid":5414,"title":"HPE security advisory (AV24-429)","uuid":"da18d20f-48e1-428f-84d0-041ac1898319","banner":null,"lang":"en","date_modified":"2024-07-30","date_modified_ts":"2024-07-30T17:55:11Z","date_created":"2024-07-30T17:49:21Z","summary":null,"body":["<article data-history-node-id=\"5414\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-429\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-429<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 30, 2024<\/p>\n\n<p>On July 30, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ClearPass Policy Manager 6.12.x \u2013 version 6.12.1 and prior<\/li>\n\t<li>ClearPass Policy Manager 6.11.x \u2013 version 6.11.8 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04675en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbnw04675en_us <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US \">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-429","alert_type":396,"serial_number":"AV24-429","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5415,"title":"Google Chrome security advisory (AV24-430)","uuid":"17153d70-2828-4b8c-9887-e3c82891374a","banner":null,"lang":"en","date_modified":"2024-07-31","date_modified_ts":"2024-07-31T13:12:22Z","date_created":"2024-07-31T13:06:14Z","summary":null,"body":["<article data-history-node-id=\"5415\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-430\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-430<br \/><strong>Date: <\/strong>July 31, 2024<\/p>\n\n<p>On July 30, 2024, Google published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 127.0.6533.88\/89 (Windows and Mac) and 127.0.6533.88 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/07\/stable-channel-update-for-desktop_30.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-430","alert_type":396,"serial_number":"AV24-430","subject":"other","moderation_state":"published","external_url":null},{"nid":5417,"title":"HPE security advisory (AV24-431)","uuid":"e48b993b-741a-479d-8ff3-a37bd8740a21","banner":null,"lang":"en","date_modified":"2024-08-01","date_modified_ts":"2024-08-01T13:50:28Z","date_created":"2024-08-01T13:39:25Z","summary":null,"body":["<article data-history-node-id=\"5417\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-431\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-431<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 1, 2024<\/p>\n\n<p>On August 1, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy\u00a0\u2013 versions prior to v9.1.1d2, v9.2.0b1 and v9.2.1<\/li>\n\t<li>HPE SAN Director Switch\u00a0\u2013 multiple models and versions prior to v9.1.1d2, v9.2.0b1 and v9.2.1<\/li>\n\t<li>HPE B-series SN2600B SAN Extension Switch\u00a0\u2013 versions prior to v9.1.1d2, v9.2.0b1 and v9.2.1<\/li>\n\t<li>HPE B-series SN4700B SAN Extension Switch\u00a0\u2013 versions prior to v9.1.1d2, v9.2.0b1 and v9.2.1<\/li>\n\t<li>HPE B-series Fibre Channel Switch\u00a0\u2013 multiple models and versions prior to v9.1.1d2, v9.2.0b1 and v9.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04679en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbst04679en_us <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-431","alert_type":396,"serial_number":"AV24-431","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5418,"title":"Microsoft Edge security advisory (AV24-432)","uuid":"22fd0e70-5d25-4393-9ddc-0c2f9f8d0aeb","banner":null,"lang":"en","date_modified":"2024-08-02","date_modified_ts":"2024-08-02T15:33:15Z","date_created":"2024-08-02T15:12:41Z","summary":null,"body":["<article data-history-node-id=\"5418\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-432\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-432<br \/><strong>Date: <\/strong>August\u00a02, 2024<\/p>\n\n<p>On August\u00a01, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 127.0.2651.86<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 126.0.2592.132<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-1-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-432","alert_type":396,"serial_number":"AV24-432","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5419,"title":"Dell security advisory (AV24-433)","uuid":"f7f482eb-ca33-4c53-abe1-4765260c0b91","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T15:52:38Z","date_created":"2024-08-06T15:39:26Z","summary":null,"body":["<article data-history-node-id=\"5419\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-433\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-433<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2024<\/p>\n\n<p>Between July 29 and August 4, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following::<\/p>\n\n<ul><li>Dell Cyber Sense\u00a0\u2013 version 8.6 and prior<\/li>\n\t<li>Dell EMC XC Core XC7525\u00a0\u2013 versions prior to 2.16.2<\/li>\n\t<li>Dell Power Protect Data Manager\u00a0\u2013 versions prior to 19.17<\/li>\n\t<li>Dell PowerProtect Data Manager DM5500 Appliance\u00a0\u2013 version 5.16 and prior<\/li>\n\t<li>Dell SmartFabric OS10\u00a0\u2013 version 10.5.6.2<\/li>\n\t<li>Dell XC Core XC7625\u00a0\u2013 versions prior to 1.8.3<\/li>\n\t<li>PowerEdge\u00a0\u2013 multiple versions and models<\/li>\n\t<li>PowerFlex rack\u00a0\u2013 versions prior to 3.7.5.1<\/li>\n\t<li>PowerFlex rack\u00a0\u2013 versions prior to 3.8.0.1<\/li>\n\t<li>PowerProtect Cyber Recovery\u00a0\u2013 version 19.16.0.2 and prior<\/li>\n\t<li>PowerStore 1000X\u00a0\u2013 versions prior to 3.2.1.3-2334099<\/li>\n\t<li>PowerStore 3000X\u00a0\u2013 versions prior to 3.2.1.3-2334099<\/li>\n\t<li>PowerStore 5000X\u00a0\u2013 versions prior to 3.2.1.3-2334099<\/li>\n\t<li>PowerStore 7000X\u00a0\u2013 versions prior to 3.2.1.3-2334099<\/li>\n\t<li>PowerStore 9000X\u00a0\u2013 versions prior to 3.2.1.3-2334099<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-433","alert_type":396,"serial_number":"AV24-433","subject":"dell","moderation_state":"published","external_url":null},{"nid":5420,"title":"IBM security advisory (AV24-434)","uuid":"d35112e1-175a-4dc3-b1a8-5a5c1b5732b6","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T16:03:08Z","date_created":"2024-08-06T15:55:22Z","summary":null,"body":["<article data-history-node-id=\"5420\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-434\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-434<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2024<\/p>\n\n<p>Between July 29 and August 4, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak System\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM IBM Control Center\u00a0\u2013 versions 6.2.1 and 6.3.0<\/li>\n\t<li>IBM ICP\u00a0\u2013 Discovery\u00a0\u2013 versions 4.0.0 to 4.8.4<\/li>\n\t<li>IBM ICP\u00a0\u2013 Discovery\u00a0\u2013 versions 4.0.0 to 5.0.0<\/li>\n\t<li>IBM Integration Bus for z\/OS\u00a0\u2013 versions 10.1 to 10.1.0.4<\/li>\n\t<li>IBM MQ Appliance\u00a0\u2013 versions 9.3 LTS and 9.3 CD<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 version 8.9.3<\/li>\n\t<li>IBM Netcool Operations Insight\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Planning Analytics Local and Analytics Workspace\u00a0\u2013 versions 2.1 and 2.0<\/li>\n\t<li>IBM Storage Protect Plus Server\u00a0\u2013 versions 10.1.0\u00a0- 10.1.16.1<\/li>\n\t<li>IBM Total Storage Service Console (TSSC) \/ TS4500 IMC\u00a0\u2013 versions 9.2.11 to 9.5.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-434","alert_type":396,"serial_number":"AV24-434","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5421,"title":"Ubuntu security advisory (AV24-435)","uuid":"1146fb4f-3198-4b0c-a027-208c27084412","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T17:25:21Z","date_created":"2024-08-06T17:08:35Z","summary":null,"body":["<article data-history-node-id=\"5421\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-435\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-435<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2024<\/p>\n\n<p>Between July 29 and August 4, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-435","alert_type":396,"serial_number":"AV24-435","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5422,"title":"Android security advisory \u2013 August 2024 Monthly Rollup (AV24-436)","uuid":"600470d9-f7ce-4e87-990c-e643798c9144","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T17:54:05Z","date_created":"2024-08-06T17:49:12Z","summary":null,"body":["<article data-history-node-id=\"5422\" about=\"\/en\/alerts-advisories\/android-security-advisory-august-2024-monthly-rollup-av24-436\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-436<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2024<\/p>\n\n<p>On August 5, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-08-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-august-2024-monthly-rollup-av24-436","alert_type":396,"serial_number":"AV24-436","subject":"android","moderation_state":"published","external_url":null},{"nid":5423,"title":"[Control systems] CISA ICS security advisories (AV24-437) ","uuid":"0dac8cc7-4176-406c-b688-a1c7316b6120","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T18:06:44Z","date_created":"2024-08-06T17:49:17Z","summary":null,"body":["<article data-history-node-id=\"5423\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-437\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-437<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2024<\/p>\n\n<p>Between July 29 and August 4, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVTECH IP Camera\u00a0- AVM1203\u00a0\u2013 firmware version FullImg-1023-1007-1011-1009 and prior<\/li>\n\t<li>Johnson Controls exacqVision Client and exacqVision Server\u00a0\u2013 all versions<\/li>\n\t<li>Johnson Controls exacqVision Web Service\u00a0\u2013 version 22.12.1.0<\/li>\n\t<li>Rockwell Automation Logix Controllers\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Vonets WiFi Bridges\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and if available, apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-437","alert_type":398,"serial_number":"AV24-437","subject":"ics","moderation_state":"published","external_url":null},{"nid":5424,"title":"Red Hat security advisory (AV24-438)","uuid":"06acbd4c-0080-45c0-a39c-6b941188e0e4","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T18:18:58Z","date_created":"2024-08-06T17:49:18Z","summary":null,"body":["<article data-history-node-id=\"5424\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-438\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-438<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2024<\/p>\n\n<p>Between July 29 and August 4, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-438","alert_type":396,"serial_number":"AV24-438","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5425,"title":"Mozilla security advisory (AV24-439)","uuid":"4c3ff351-81f1-4a7a-bce0-b33c3d1f50dd","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T18:43:46Z","date_created":"2024-08-06T17:49:20Z","summary":null,"body":["<article data-history-node-id=\"5425\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-439\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-439<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2024<\/p>\n\n<p>On August 6, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 115.14<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.1<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 129<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 115.14<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 128.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-439","alert_type":396,"serial_number":"AV24-439","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5426,"title":"HPE security advisory (AV24-440)","uuid":"3eb9a3d5-f2b8-4673-8227-73afd255cd45","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T19:45:20Z","date_created":"2024-08-06T19:29:24Z","summary":null,"body":["<article data-history-node-id=\"5426\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-440\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-440<br \/><strong>Date: <\/strong>August\u00a06, 2024<\/p>\n\n<p>On August\u00a01, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telecommunication Management Information Platform\u00a0\u2013 versions 8.3.x and 8.4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04558en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbnw04558en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-440","alert_type":396,"serial_number":"AV24-440","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5427,"title":"Google Chrome security advisory (AV24-441)","uuid":"aeca8ac9-d786-4fc4-8c99-ea65cbe89aeb","banner":null,"lang":"en","date_modified":"2024-08-06","date_modified_ts":"2024-08-06T19:54:44Z","date_created":"2024-08-06T19:29:24Z","summary":null,"body":["<article data-history-node-id=\"5427\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-441\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-441<br \/><strong>Date: <\/strong>August\u00a06, 2024<\/p>\n\n<p>On August\u00a06, 2024, Google published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 127.0.6533.99\/.100 (Windows and Mac) and 127.0.6533.99 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/08\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-441","alert_type":396,"serial_number":"AV24-441","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5428,"title":"HPE security advisory (AV24-442)","uuid":"aca09fc6-7139-4708-a5ca-5c6f917959ee","banner":null,"lang":"en","date_modified":"2024-08-07","date_modified_ts":"2024-08-07T14:33:13Z","date_created":"2024-08-07T14:27:20Z","summary":null,"body":["<article data-history-node-id=\"5428\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-442\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-442<br \/><strong>Date: <\/strong>August 7, 2024<\/p>\n\n<p>On August 6, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Athonet Mobile Core\u00a0\u2013 versions 1.24.1.1 and prior and versions 1.23.4.2 and prior<\/li>\n\t<li>HPE Athonet IMS\u00a0\u2013 versions 1.24.1.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04674en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbnw04674en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-442","alert_type":396,"serial_number":"AV24-442","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5430,"title":"Cisco security advisory (AV24-443)","uuid":"5a791848-3b21-4ec4-b232-685945643e36","banner":null,"lang":"en","date_modified":"2024-08-07","date_modified_ts":"2024-08-07T18:18:51Z","date_created":"2024-08-07T18:15:04Z","summary":null,"body":["<article data-history-node-id=\"5430\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-443\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-443<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 7, 2024<\/p>\n\n<p>On August 7, 2024, Cisco published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Small Business SPA300 Series IP Phones\u00a0\u2013 all versions<\/li>\n\t<li>Cisco Small Business SPA500 Series IP Phones\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-spa-http-vulns-RJZmX2Xz\">Cisco Security Advisory \u2013 cisco-sa-spa-http-vulns-RJZmX2Xz <\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x \">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-443","alert_type":396,"serial_number":"AV24-443","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5431,"title":"Jenkins security advisory (AV24-444)","uuid":"199fb0b3-1cdf-4c8f-8d27-b0b6780eee8f","banner":null,"lang":"en","date_modified":"2024-08-08","date_modified_ts":"2024-08-08T15:14:29Z","date_created":"2024-08-08T15:10:39Z","summary":null,"body":["<article data-history-node-id=\"5431\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av24-444\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-444<br \/><strong>Date: <\/strong>August\u00a08, 2024<\/p>\n\n<p>On August\u00a07, 2024, Jenkins published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Jenkins (core)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2024-08-07\/\">Jenkins Security Advisory 2024-08-07<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av24-444","alert_type":396,"serial_number":"AV24-444","subject":"other","moderation_state":"published","external_url":null},{"nid":5432,"title":"Drupal security advisory (AV24-445)","uuid":"4b64f882-e602-4f3c-b291-60832b19a85f","banner":null,"lang":"en","date_modified":"2024-08-08","date_modified_ts":"2024-08-08T15:35:06Z","date_created":"2024-08-08T15:25:04Z","summary":null,"body":["<article data-history-node-id=\"5432\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-445\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-445<br \/><strong>Date: <\/strong>August\u00a08, 2024<\/p>\n\n<p>On August\u00a07, 2024, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Opigno group manager\u00a0\u2013 versions prior to 3.1.1<\/li>\n\t<li>Opigno Learning path\u00a0\u2013 versions prior to 3.1.2<\/li>\n\t<li>Opigno module\u00a0\u2013 versions prior to 3.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-029\">Opigno Learning path\u00a0- Critical\u00a0- Arbitrary PHP code execution\u00a0- SA-CONTRIB-2024-029<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-028\">Opigno module\u00a0- Critical\u00a0- Arbitrary PHP code execution\u00a0- SA-CONTRIB-2024-028<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-027\">Opigno group manager\u00a0- Critical\u00a0- Arbitrary PHP code execution\u00a0- SA-CONTRIB-2024-027<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-445","alert_type":396,"serial_number":"AV24-445","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5433,"title":"HPE security advisory (AV24-446)","uuid":"6521dde4-d79b-4cb0-8f0f-6ab446e8bbfc","banner":null,"lang":"en","date_modified":"2024-08-09","date_modified_ts":"2024-08-09T14:21:02Z","date_created":"2024-08-09T13:55:26Z","summary":null,"body":["<article data-history-node-id=\"5433\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-446\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-446<br \/><strong>Date: <\/strong>August 9, 2024<\/p>\n\n<p>On August 2, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>InstantOS\u00a0\u2013 versions prior to 12.x.x: 8.12.0.2<\/li>\n\t<li>InstantOS\u00a0\u2013 versions prior 10.x.x: 8.10.0.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04678en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbnw04678en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-446","alert_type":396,"serial_number":"AV24-446","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5434,"title":"F5 security advisory (AV24-447)","uuid":"a0c2c7da-6be6-4e12-be82-1f58c2fc329d","banner":null,"lang":"en","date_modified":"2024-08-09","date_modified_ts":"2024-08-09T14:32:22Z","date_created":"2024-08-09T14:26:41Z","summary":null,"body":["<article data-history-node-id=\"5434\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av24-447\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-447<br \/><strong>Date: <\/strong>August 9, 2024<\/p>\n\n<p>On August 8, 2024, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Traffix SDC\u00a0\u2013 versions 5.2.0 and 5.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000140620\">F5 Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av24-447","alert_type":396,"serial_number":"AV24-447","subject":"f5","moderation_state":"published","external_url":null},{"nid":5435,"title":"Microsoft Edge security advisory (AV24-448)","uuid":"d042b59c-827c-4a42-80bb-7b846dfb8f8d","banner":null,"lang":"en","date_modified":"2024-08-09","date_modified_ts":"2024-08-09T17:17:56Z","date_created":"2024-08-09T17:11:48Z","summary":null,"body":["<article data-history-node-id=\"5435\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-448\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-448<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 8, 2024<\/p>\n\n<p>On August 8, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft Edge Stable Channel<\/span>\u00a0\u2013 versions prior to 127.0.2651.98<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/deployedge\/microsoft-edge-relnotes-security#august-8-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-448","alert_type":396,"serial_number":"AV24-448","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5436,"title":"IBM security advisory (AV24-451)","uuid":"f0300a6c-afc0-4a78-a873-1364251e7e7e","banner":null,"lang":"en","date_modified":"2024-08-12","date_modified_ts":"2024-08-12T16:12:04Z","date_created":"2024-08-12T16:01:47Z","summary":null,"body":["<article data-history-node-id=\"5436\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-451\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-451<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 12, 2024<\/p>\n\n<p>Between August 5 and 11, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>HMC\u00a0\u2013 version OP940.00 to OP940.70<\/li>\n\t<li>IBM Business Automation Workflow containers\u00a0\u2013 version V24.0.0<\/li>\n\t<li>IBM Business Automation Workflow traditional\u00a0\u2013 version V24.0.0<\/li>\n\t<li>IBM CICS TX Advanced\u00a0\u2013 versions 10.1 and 11.1<\/li>\n\t<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 4.8.4<\/li>\n\t<li>IBM Common Licensing\u00a0\u2013 versions ART 9.0 and Agent 9.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 versions 8.1, 8.11 and 9.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\u00a0\u2013 versions 8.10, 8.10.12, 8.11, 8.11.9 and 9.0.0<\/li>\n\t<li>IBM Operational Decision Manager\u00a0\u2013 versions 8.11.0.1, 8.11.1.0 and 8.12.0.1<\/li>\n\t<li>IBM Security Verify Information Queue\u00a0\u2013 versions 10.0.5, 10.0.6, 10.0.7 and 10.0.8<\/li>\n\t<li>IBM Storage Ceph\u00a0\u2013 versions 5.3 to 5.3z6, 5.3z1 to z6, 6.1 to 6.1z4, 6.1 to 6.1z6, 7.0 to 7.0z1, 7.0 to 7.0z2 and version 6.0.<\/li>\n\t<li>IBM TXSeries for Multiplatforms\u00a0\u2013 versions 8.1, 8.2 and 9.1<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0 to 5.0<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 5.0.0<\/li>\n\t<li>OPENBMC\u00a0\u2013 versions FW1020.00 to FW1020.60, FW1030.00 to FW1030.50, FW1050.00 to FW1050.10, OP910.00 to OP910.80 and OP940.00 to OP940.60<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-451","alert_type":396,"serial_number":"AV24-451","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5437,"title":"Ubuntu security advisory (AV24-449)","uuid":"67f92f14-95f3-4f06-9231-11d354b11bff","banner":null,"lang":"en","date_modified":"2024-08-12","date_modified_ts":"2024-08-12T16:00:00Z","date_created":"2024-08-12T17:38:48Z","summary":null,"body":["<article data-history-node-id=\"5437\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-449\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-449<br \/><strong>Date: <\/strong>August\u00a012, 2024<\/p>\n\n<p>Between August\u00a05 and 11, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-449","alert_type":396,"serial_number":"AV24-449","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5438,"title":"Dell security advisory (AV24-450)","uuid":"896d156d-901b-48dd-84be-f2ea26fca36c","banner":null,"lang":"en","date_modified":"2024-08-12","date_modified_ts":"2024-08-12T16:01:01Z","date_created":"2024-08-12T17:38:49Z","summary":null,"body":["<article data-history-node-id=\"5438\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-450\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-450<br \/><strong>Date: <\/strong>August\u00a012, 2024<\/p>\n\n<p>Between August\u00a05 and 11, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Avamar NDMP Accelerator\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9, 19.10 and 19.10 sp1 running suse linux enterprise 12 sp5<\/li>\n\t<li>Dell Avamar Server Hardware Appliance Gen4T\/ Gen5A\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9, 19.10 and 19.10-sp1 running suse linux enterprise 12 sp5<\/li>\n\t<li>Dell Avamar Virtual Edition\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9, 19.10 and 19.10-sp1 running suse linux enterprise 12 sp5<\/li>\n\t<li>Dell Avamar VMware Image Proxy\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9, 19.10 and 19.10-sp1 running suse linux enterprise 12 sp5<\/li>\n\t<li>Dell Networker Virtual Edition (NVE)\u00a0\u2013 versions 19.10.x, 19.11.x running suse linux enterprise 12 sp5, 19.5.x, 19.6.x, 19.7.x, 19.8.x, 19.9.x and versions 19.4.x<\/li>\n\t<li>Dell Power Protect DP Series Appliance \/ Dell Integrated Data Protection Appliance (IDPA)\u00a0\u2013 version 2.7.x running sles12sp5 and version 2.7.6 and prior<\/li>\n\t<li>Dell Protection Advisor\u00a0\u2013 versions 19.7, 19.8 and 19.9<\/li>\n\t<li>XtremIO X2\u00a0\u2013 versions prior to 6.4.2-13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-450","alert_type":396,"serial_number":"AV24-450","subject":"dell","moderation_state":"published","external_url":null},{"nid":5439,"title":"Red Hat security advisory (AV24-452)","uuid":"79e513f6-34e4-4202-90ee-5fa93741eba3","banner":null,"lang":"en","date_modified":"2024-08-12","date_modified_ts":"2024-08-12T18:58:49Z","date_created":"2024-08-12T18:11:19Z","summary":null,"body":["<article data-history-node-id=\"5439\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-452\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-452<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 12, 2024<\/p>\n\n<p>Between August 5 and 11, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:5101\">RHSA-2024:5101\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:5102\">RHSA-2024:5102\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-452","alert_type":396,"serial_number":"AV24-452","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5440,"title":"[Control systems] CISA ICS security advisories (AV24-453)","uuid":"a666c97d-1710-4510-b4bb-e158293c0cd6","banner":null,"lang":"en","date_modified":"2024-08-12","date_modified_ts":"2024-08-12T20:15:43Z","date_created":"2024-08-12T19:40:17Z","summary":null,"body":["<article data-history-node-id=\"5440\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-453\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-453<br \/><strong>Date: <\/strong>August\u00a012, 2024<\/p>\n\n<p>Between August\u00a05 and 11, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics DIAScreen\u00a0\u2013 versions prior to 1.4.2<\/li>\n\t<li>Dorsett Controls InfoScan\u00a0\u2013 versions v1.32, v1.33, and v1.35<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-221-01\">CISA ICS Advisory\u00a0- ICSA-24-221-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-219-01\">CISA ICS Advisory\u00a0- ICSA-24-219-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-453","alert_type":398,"serial_number":"AV24-453","subject":"ics","moderation_state":"published","external_url":null},{"nid":5441,"title":"[Control systems] Schneider Electric security advisory (AV24-455)","uuid":"ad04f84a-2bcb-43d0-b578-558005f852a9","banner":null,"lang":"en","date_modified":"2024-08-13","date_modified_ts":"2024-08-13T15:03:28Z","date_created":"2024-08-13T14:32:52Z","summary":null,"body":["<article data-history-node-id=\"5441\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-455\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-455<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 13, 2024<\/p>\n\n<p>On August 13, 2024, Schneider Electric published security advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Accutech Manager\u00a0\u2013 version 2.8.0.0 and prior<\/li>\n\t<li>EcoStruxure Machine SCADA Expert\u00a0\u2013 versions prior to 2020 SP3 HF1<\/li>\n\t<li>Pro-face BLUE Open Studio\u00a0\u2013 versions prior to 2020 SP3 HF1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-226-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-226-01.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-226-01 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-226-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-226-02.pdf&#10;    \">Schneider Electric Security Notification\u00a0- SEVD-2024-226-02 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-455","alert_type":398,"serial_number":"AV24-455","subject":"other","moderation_state":"published","external_url":null},{"nid":5442,"title":"SAP security advisory \u2013 August 2024 monthly rollup (AV24-454)","uuid":"9436959f-64c0-4806-87ff-a6b2402b4efc","banner":null,"lang":"en","date_modified":"2024-08-13","date_modified_ts":"2024-08-13T15:00:00Z","date_created":"2024-08-13T15:53:20Z","summary":null,"body":["<article data-history-node-id=\"5442\" about=\"\/en\/alerts-advisories\/sap-security-advisory-august-2024-monthly-rollup-av24-454\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-454<br \/><strong>Date: <\/strong>August\u00a013, 2024<\/p>\n\n<p>On August\u00a013, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Build Apps\u00a0\u2013 versions prior to 4.11.130<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform\u00a0\u2013 versions ENTERPRISE 430 and 440<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/august-2024.html\">SAP Security Patch Day\u00a0- August 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-august-2024-monthly-rollup-av24-454","alert_type":396,"serial_number":"AV24-454","subject":"sap","moderation_state":"published","external_url":null},{"nid":5446,"title":"Ivanti security advisory (AV24-456)","uuid":"d94856d6-60a3-4a9b-9f79-47ee87616d72","banner":null,"lang":"en","date_modified":"2024-08-13","date_modified_ts":"2024-08-13T20:22:45Z","date_created":"2024-08-13T19:46:07Z","summary":null,"body":["<article data-history-node-id=\"5446\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-456\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-456<br \/><strong>Date: <\/strong>August\u00a013, 2024<\/p>\n\n<p>On August\u00a013, 2024, Ivanti published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Virtual Traffic Manager\u00a0\u2013 versions 22.2, 22.3, 22.3R2, 22.5R1, 22.6R1 and 22.7R1<\/li>\n\t<li>Ivanti Neurons for ITSM\u00a0\u2013 versions 2023.2, 2023.3 and 2023.4<\/li>\n\t<li>Ivanti Avalanche\u00a0\u2013 versions 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.4.0, 6.4.1, 6.4.2 and 6.4.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US\">Security Advisory: Ivanti Virtual Traffic Manager (vTM) (CVE-2024-7593)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2024-7569-CVE-2024-7570?language=en_US\">Security Advisory: Ivanti Neurons for ITSM (CVE-2024-7569, CVE-2024-7570)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Avalanche-6-4-4-CVE-2024-38652-CVE-2024-38653-CVE-2024-36136-CVE-2024-37399-CVE-2024-37373?language=en_US\">Security Advisory Ivanti Avalanche 6.4.4 (CVE-2024-38652, CVE-2024-38653, CVE-2024-36136, CVE-2024-37399, CVE-2024-37373)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-456","alert_type":396,"serial_number":"AV24-456","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5447,"title":"Adobe security advisory (AV24-457)","uuid":"5a6efb23-3d97-4d31-bcc3-95c3d2e5263a","banner":null,"lang":"en","date_modified":"2024-08-13","date_modified_ts":"2024-08-13T20:29:43Z","date_created":"2024-08-13T19:46:08Z","summary":null,"body":["<article data-history-node-id=\"5447\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-457\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-457<br \/><strong>Date: <\/strong>August\u00a013, 2024<\/p>\n\n<p>On August\u00a013, 2024, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat 2024\u00a0\u2013 version 24.001.30123 and prior<\/li>\n\t<li>Acrobat 2020\u00a0\u2013 version 20.005.30636 and prior (Windows), version 20.005.30635 and prior (MacOS)<\/li>\n\t<li>Acrobat DC\u00a0\u2013 version 24.002.20991 and prior (Windows), version 24.002.20964 and prior (MacOS)<\/li>\n\t<li>Acrobat Reader 2020\u00a0\u2013 version 20.005.30636 and prior (Windows), version 20.005.30635 and prior (MacOS)<\/li>\n\t<li>Acrobat Reader DC\u00a0\u2013 version 24.002.20991 and prior (Windows), version 24.002.20964 and prior (MacOS)<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 13.0.8 and prior, version 14.1.1 and prior<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 3.4.11 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 19.4 and prior, version 18.5.2 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.4 and prior, version ID18.5.2 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version 13.1.2 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler\u00a0\u2013 version 4.5 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.0.2 and prior<\/li>\n\t<li>Illustrator 2024\u00a0\u2013 version 28.5 and prior<\/li>\n\t<li>Illustrator 2023\u00a0\u2013 version 27.9.4 and prior<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n\t<li>Photoshop 2023\u00a0\u2013 version 24.7.3 and prior<\/li>\n\t<li>Photoshop 2024\u00a0\u2013 version 25.9.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-457","alert_type":396,"serial_number":"AV24-457","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5448,"title":"Microsoft security advisory \u2013 August 2024 monthly rollup (AV24-458)","uuid":"51d19d4c-c45d-467d-a96c-eda69906822b","banner":null,"lang":"en","date_modified":"2024-08-13","date_modified_ts":"2024-08-13T20:36:22Z","date_created":"2024-08-13T19:46:08Z","summary":null,"body":["<article data-history-node-id=\"5448\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2024-monthly-rollup-av24-458\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-458<br \/><strong>Date: <\/strong>August\u00a013, 2024<\/p>\n\n<p>On August\u00a013, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Azure Connected Machine Agent<\/li>\n\t<li>Azure Health Bot<\/li>\n\t<li>Azure Stack Hub<\/li>\n\t<li>Azure CycleCloud\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft 365 Apps for Enterprise\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Copilot Studio<\/li>\n\t<li>Microsoft Dynamics 365 (on-premises)\u00a0\u2013 version 9.1<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Outlook 2016<\/li>\n\t<li>Microsoft Project 2016\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Teams<\/li>\n\t<li>Microsoft Visual Studio\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>.NET\u00a0\u2013 version 8.0<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-38189, CVE-2024-38107, CVE-2024-38106, CVE-2024-38213, CVE-2024-38193 and CVE-2024-38178 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Aug\">August 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2024-monthly-rollup-av24-458","alert_type":396,"serial_number":"AV24-458","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5449,"title":"Intel security advisory (AV24-459)","uuid":"048cc839-a2a8-4b9f-bdb2-b5adbdaa701d","banner":null,"lang":"en","date_modified":"2024-08-13","date_modified_ts":"2024-08-13T20:40:42Z","date_created":"2024-08-13T20:22:47Z","summary":null,"body":["<article data-history-node-id=\"5449\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av24-459\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-459<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 13, 2024<\/p>\n\n<p>On August 13, 2024, Intel published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Intel Agilex FPGA 7 FPGA\u00a0\u2013 firmware versions prior to 24.1<\/li>\n\t<li>Intel Ethernet Complete Driver Pack\u00a0\u2013 versions prior to 28.3<\/li>\n\t<li>Intel Ethernet Controllers\u00a0\u2013 multiple versions<\/li>\n\t<li>Intel NUC X15 Laptop\u00a0\u2013 multiple models<\/li>\n\t<li>Intel Server Board S2600ST Family\u00a0\u2013 firmware versions prior to 02.01.0017<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av24-459","alert_type":396,"serial_number":"AV24-459","subject":"intel","moderation_state":"published","external_url":null},{"nid":5450,"title":"SolarWinds security advisory (AV24-460)","uuid":"cf43dd94-d8a1-4121-b72e-03db6385cf95","banner":null,"lang":"en","date_modified":"2024-08-14","date_modified_ts":"2024-08-14T17:26:21Z","date_created":"2024-08-14T17:11:39Z","summary":null,"body":["<article data-history-node-id=\"5450\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-460\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-460<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 14, 2024<\/p>\n\n<p>On August 14, 2024, SolarWinds published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>SolarWinds Web Help Desk (WHD)\u00a0\u2013 version 12.8.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/WHD-12-8-3-Hotfix-1\">SolarWinds\u00a0\u2013 WHD 12.8.3 Hotfix 1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-460","alert_type":396,"serial_number":"AV24-460","subject":"other","moderation_state":"published","external_url":null},{"nid":5451,"title":"Palo Alto Networks security advisory (AV24-461)","uuid":"41f68c0d-1197-4d34-807e-ba4531cfae0d","banner":null,"lang":"en","date_modified":"2024-08-15","date_modified_ts":"2024-08-15T16:08:55Z","date_created":"2024-08-15T16:05:31Z","summary":null,"body":["<article data-history-node-id=\"5451\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-461\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-461<br \/><strong>Date: <\/strong>August\u00a015, 2024<\/p>\n\n<p>On August\u00a014, 2024, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>Prisma Access Browser\u00a0\u2013 version prior to 127.100.2858.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2024-0007\">Palo Alto Networks Security Advisories\u00a0\u2013 PAN-SA-2024-0007<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-461","alert_type":396,"serial_number":"AV24-461","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5452,"title":"Microsoft Edge security advisory (AV24-462)","uuid":"741b6c8e-ccd0-4cfb-87eb-36c8db10ed69","banner":null,"lang":"en","date_modified":"2024-08-16","date_modified_ts":"2024-08-16T14:52:19Z","date_created":"2024-08-16T14:47:44Z","summary":null,"body":["<article data-history-node-id=\"5452\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-462\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-462<br \/><strong>Date: <\/strong>August 16, 2024<\/p>\n\n<p>On August 15, 2024, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 127.0.2651.105<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-15-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-462","alert_type":396,"serial_number":"AV24-462","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5455,"title":"F5 security advisory (AV24-463)","uuid":"3b3303fb-a449-4361-9ddf-237fa9612f0b","banner":null,"lang":"en","date_modified":"2024-08-19","date_modified_ts":"2024-08-19T17:32:46Z","date_created":"2024-08-19T17:20:36Z","summary":null,"body":["<article data-history-node-id=\"5455\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av24-463\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-463<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 19, 2024<\/p>\n\n<p>On August 14, 2024, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP (all modules)\u00a0\u2013 multiple versions and models<\/li>\n\t<li>BIG-IP Next Central Manager\u00a0\u2013 version 20.1.0<\/li>\n\t<li>NGINX Plus\u00a0\u2013 versions R30 to R32<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000140552\">F5 Security Advisory\u00a0\u2013 August 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av24-463","alert_type":396,"serial_number":"AV24-463","subject":"f5","moderation_state":"published","external_url":null},{"nid":5457,"title":"Dell security advisory (AV24-465)","uuid":"f9c55931-a008-4da5-973a-f866aeb45657","banner":null,"lang":"en","date_modified":"2024-08-19","date_modified_ts":"2024-08-19T18:19:59Z","date_created":"2024-08-19T17:37:45Z","summary":null,"body":["<article data-history-node-id=\"5457\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-465\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-465<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 19, 2024<\/p>\n\n<p>Between August 12 and 18, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell EMC VxRail Appliance\u00a0\u2013 8.0.x versions prior to 8.0.300<\/li>\n\t<li>Dell Power Protect DP Series Appliance \/ Dell Integrated Data Protection Appliance\u00a0\u2013 versions 2.7.0 to 2.7.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000227832\/dsa-2024-341-security-update-for-dell-vxrail-8-0-300-multiple-third-party-component-vulnerabilities\">Dell Security Update\u00a0- Dell EMC VxRail Appliance<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000227707\/dsa-2024-157-security-update-for-dell-powerprotect-dp-series-appliance-idpa-infrastructure-for-third-party-vulnerabilities\">Dell Security Update\u00a0- Dell PowerProtect DP Series Appliance<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-465","alert_type":396,"serial_number":"AV24-465","subject":"dell","moderation_state":"published","external_url":null},{"nid":5456,"title":"Ubuntu security advisory (AV24-464)","uuid":"69345ca8-7444-465a-ab96-7b04f16f0c0d","banner":null,"lang":"en","date_modified":"2024-08-19","date_modified_ts":"2024-08-19T17:54:22Z","date_created":"2024-08-19T17:37:46Z","summary":null,"body":["<article data-history-node-id=\"5456\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-464\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-464<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 19, 2024<\/p>\n\n<p>Between August 12 and 18, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-464","alert_type":396,"serial_number":"AV24-464","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5458,"title":"IBM security advisory (AV24-466)","uuid":"8f4984b4-22e1-4cc0-940c-eeffa1fd3872","banner":null,"lang":"en","date_modified":"2024-08-19","date_modified_ts":"2024-08-19T20:28:23Z","date_created":"2024-08-19T20:19:44Z","summary":null,"body":["<article data-history-node-id=\"5458\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-466\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-466\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 19, 2024\n<\/p>\n<p>Between August 12 and 18, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:\n<\/p>\n<ul><li>IBM App Connect Enterprise Certified Container\u00a0\u2013 multiple versions<\/li>\n  <li>IBM Cloud Pak for Security\u00a0\u2013 version 1.10.0.0 to 1.10.11.0<\/li>\n  <li>IBM Cognos Dashboards on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n  <li>IBM Observability with Instana OnPrem\u00a0\u2013 version Build 278<\/li>\n  <li>IBM Storage Defender\u00a0- Data Protect\u00a0\u2013 version 1.0.0 to 2.0.5<\/li>\n  <li>PowerVC\u00a0\u2013 versions 2.1.1, 2.1.1.1, 2.2.0 and 2.2.1<\/li>\n  <li>QRadar Suite Software\u00a0\u2013 version 1.10.12.0 to 1.10.23.0<\/li>\n  <li>data\u00a0\u2013 version 1.0.0 to 2.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-466","alert_type":396,"serial_number":"AV24-466","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5459,"title":"Red Hat security advisory (AV24-467)","uuid":"6bea19d8-ed65-4639-b239-fe859a9f868c","banner":null,"lang":"en","date_modified":"2024-08-19","date_modified_ts":"2024-08-19T20:41:18Z","date_created":"2024-08-19T20:19:49Z","summary":null,"body":["<article data-history-node-id=\"5459\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-467\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-467\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 19, 2024\n<\/p>\n<p>Between August 12 and 18, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:\n<\/p>\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-467","alert_type":396,"serial_number":"AV24-467","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5460,"title":"[Control systems] CISA ICS security advisories (AV24-468) ","uuid":"51147981-02b8-435c-84c1-e71384e80abc","banner":null,"lang":"en","date_modified":"2024-08-19","date_modified_ts":"2024-08-19T20:49:44Z","date_created":"2024-08-19T20:33:38Z","summary":null,"body":["<article data-history-node-id=\"5460\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-468\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-468<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 19, 2024<\/p>\n\n<p>Between August 12 and 18, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA Historian Web Server\u00a0\u2013 versions 2023 to 2023 P03, versions 2020 to 2020 R2 SP1 P01 and 2023 R2<\/li>\n\t<li>AVEVA Reports for Operations 2023\u00a0\u2013 version 23.0.17795.1010 and prior<\/li>\n\t<li>AVEVA SuiteLink Server\u00a0\u2013 multiple products and versions<\/li>\n\t<li>Ocean Data Systems Dream Report 2023\u00a0\u2013 version 23.0.17795.1010 and prior<\/li>\n\t<li>PTC Kepware ThingWorx Kepware Server\u00a0\u2013 multiple products and versions<\/li>\n\t<li>Rockwell Automation ControlLogix, GuardLogix, Compact Logix and Compact GuardLogix\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Rockwell Automation Micro850\/870\u00a0\u2013 versions prior to v22.01<\/li>\n\t<li>Rockwell Automation FactoryTalk View Site Edition\u00a0\u2013 version 13.0<\/li>\n\t<li>Rockwell Automation DataMosaix Private Cloud\u00a0\u2013 versions prior to 7.07<\/li>\n\t<li>Rockwell Automation Pavilion8\u00a0\u2013 versions 5.20 and later<\/li>\n\t<li>Rockwell Automation AADvance Standalone OPC-DA Server\u00a0\u2013 versions 2.01.510 and later<\/li>\n\t<li>Siemens SCALANCE M-800 Family\u00a0\u2013 multiple models and versions prior to V8.1<\/li>\n\t<li>Siemens RUGGEDCOM RM1224\u00a0\u2013 versions prior to V8.1<\/li>\n\t<li>Siemens NX\u00a0\u2013 versions prior to V2406.3000<\/li>\n\t<li>Siemens COMOS\u00a0\u2013 versions prior to V10.5<\/li>\n\t<li>Siemens Location Intelligence\u00a0\u2013 versions prior to V4.4<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V3.0<\/li>\n\t<li>Siemens LOGO! V8.3 BM Devices\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V3.0<\/li>\n\t<li>Siemens SINEC Traffic Analyzer\u00a0\u2013 versions prior to V2.0<\/li>\n\t<li>Siemens Teamcenter Visualization and JT2Go\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens INTRALOG WMS\u00a0\u2013 versions prior to 4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-468","alert_type":398,"serial_number":"AV24-468","subject":"ics","moderation_state":"published","external_url":null},{"nid":5463,"title":"Atlassian security advisory (AV24-469)","uuid":"7649409f-4f41-42c6-9225-1ee9a133a265","banner":null,"lang":"en","date_modified":"2024-08-21","date_modified_ts":"2024-08-21T14:26:23Z","date_created":"2024-08-21T14:08:36Z","summary":null,"body":["<article data-history-node-id=\"5463\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-469\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-469<br \/><strong>Date: <\/strong>August 21, 2024<\/p>\n\n<p>On August 20, 2024, Atlassian published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-august-20-2024-1431535667.html\">Atlassian August 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-469","alert_type":396,"serial_number":"AV24-469","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5475,"title":"GitHub security advisory (AV24-470)","uuid":"4a3cfceb-96b1-4051-98b4-f453a4277e3a","banner":null,"lang":"en","date_modified":"2024-08-21","date_modified_ts":"2024-08-21T20:38:09Z","date_created":"2024-08-21T20:06:45Z","summary":null,"body":["<article data-history-node-id=\"5475\" about=\"\/en\/alerts-advisories\/github-security-advisory-av24-470\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-470<br \/><strong>Date: <\/strong>August\u00a021, 2024<\/p>\n\n<p>On August\u00a020, 2024, GitHub published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.13.x prior to 3.13.3<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.12.x prior to 3.12.8<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.11.x prior to 3.11.14<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.10.x prior to 3.10.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.13\/admin\/release-notes#3.13.3\">GitHub Release Notes #3.13.3<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.12\/admin\/release-notes#3.12.8\">GitHub Release Notes #3.12.8<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.11\/admin\/release-notes#3.11.14\">GitHub Release Notes #3.11.14<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.10\/admin\/release-notes#3.10.16\">GitHub Release Notes #3.10.16<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av24-470","alert_type":396,"serial_number":"AV24-470","subject":"other","moderation_state":"published","external_url":null},{"nid":5476,"title":"Mitel security advisory (AV24-471)","uuid":"d2eaad69-e87a-4616-b8a1-837b965d4452","banner":null,"lang":"en","date_modified":"2024-08-21","date_modified_ts":"2024-08-21T20:42:59Z","date_created":"2024-08-21T20:06:46Z","summary":null,"body":["<article data-history-node-id=\"5476\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-471\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-471<br \/><strong>Date: <\/strong>August\u00a021, 2024<\/p>\n\n<p>On August\u00a021, 2024, Mitel published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>MiContact Center Business\u00a0\u2013 version 10.1.0.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-24-0024\">Mitel Security Advisory\u00a0- 24-0024<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-471","alert_type":396,"serial_number":"AV24-471","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5482,"title":"Cisco security advisory (AV24-472)","uuid":"3cfe226a-af56-4157-8768-c183f0c8720f","banner":null,"lang":"en","date_modified":"2024-08-22","date_modified_ts":"2024-08-22T17:35:43Z","date_created":"2024-08-22T17:11:11Z","summary":null,"body":["<article data-history-node-id=\"5482\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-472\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-472<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 22, 2024<\/p>\n\n<p>On August 21, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Unified CM\u00a0\u2013 versions 12.5(1), 14S and 15<\/li>\n\t<li>Cisco Unified CM SME\u00a0\u2013 versions 12.5(1), 14 and 15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cucm-dos-kkHq43We\">Cisco Security Advisory\u00a0\u2013 cisco-sa-cucm-dos-kkHq43We <\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-472","alert_type":396,"serial_number":"AV24-472","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5484,"title":"Drupal security advisory (AV24-473)","uuid":"de93e1f6-2a74-4df0-a9d6-fd7e76d2dc50","banner":null,"lang":"en","date_modified":"2024-08-22","date_modified_ts":"2024-08-22T18:07:35Z","date_created":"2024-08-22T17:45:36Z","summary":null,"body":["<article data-history-node-id=\"5484\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-473\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-473\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 21, 2024\n<\/p>\n<p>On August 21, 2024, Drupal published security advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Opigno module\u00a0\u2013 versions prior to 7.x-1.23<\/li>\n  <li>Opigno TinCan Question Type module\u00a0\u2013 versions prior to 7.x-1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-032\">Opigno\u00a0- Critical\u00a0- Arbitrary PHP code execution\u00a0- SA-CONTRIB-2024-032<\/a><\/li>\n  <li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-031\">Opigno TinCan Question Type\u00a0- Critical\u00a0- Arbitrary PHP code execution\u00a0- SA-CONTRIB-2024-031<\/a><\/li>\n  <li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-473","alert_type":396,"serial_number":"AV24-473","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5494,"title":"Google Chrome security advisory (AV24-474)","uuid":"37f5e97b-a217-47f5-98a6-16f324a36275","banner":null,"lang":"en","date_modified":"2024-08-22","date_modified_ts":"2024-08-22T19:45:51Z","date_created":"2024-08-22T19:41:09Z","summary":null,"body":["<article data-history-node-id=\"5494\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-474\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-474<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 22, 2024<\/p>\n\n<p>On August 21, 2024, Google published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 128.0.6613.84\/.85 (Windows and Mac) and 128.0.6613.84 (Linux)<\/li>\n<\/ul><p>Google has indicated that CVE-2024-7971 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/08\/stable-channel-update-for-desktop_21.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-474","alert_type":396,"serial_number":"AV24-474","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5495,"title":"SolarWinds security advisory (AV24-475)","uuid":"33103286-b099-4e17-838c-8e4f610297e4","banner":null,"lang":"en","date_modified":"2024-08-22","date_modified_ts":"2024-08-22T20:09:19Z","date_created":"2024-08-22T20:01:43Z","summary":null,"body":["<article data-history-node-id=\"5495\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-475\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-475<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 22, 2024<\/p>\n\n<p>On August 22, 2024, SolarWinds published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>SolarWinds Web Help Desk (WHD)\u00a0\u2013 version 12.8.3 HF1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.solarwinds.com\/SuccessCenter\/s\/article\/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2\">SolarWinds\u00a0\u2013 WHD 12.8.3 Hotfix 2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-475","alert_type":396,"serial_number":"AV24-475","subject":"other","moderation_state":"published","external_url":null},{"nid":5497,"title":"Microsoft Edge security advisory (AV24-476)","uuid":"7b42ccc5-4d80-4da6-ad6b-cb2974beec9a","banner":null,"lang":"en","date_modified":"2024-08-23","date_modified_ts":"2024-08-23T18:36:20Z","date_created":"2024-08-23T18:31:04Z","summary":null,"body":["<article data-history-node-id=\"5497\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-476\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-476<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 22, 2024<\/p>\n\n<p>On August 22, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 128.0.2739.42<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-7971 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-22-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-476","alert_type":396,"serial_number":"AV24-476","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5498,"title":"SonicWall security advisory (AV24-477)","uuid":"05899307-603d-4ab1-a71a-bc0f850f020a","banner":null,"lang":"en","date_modified":"2024-08-23","date_modified_ts":"2024-08-23T20:08:31Z","date_created":"2024-08-23T19:57:12Z","summary":null,"body":["<article data-history-node-id=\"5498\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-477\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-477<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 23, 2024<\/p>\n\n<p>On August 22, 2024, SonicWall published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>SonicWall SOHO (Gen 5)\u00a0\u2013 versions prior to 5.9.2.14-13o<\/li>\n\t<li>SonicWall SOHO (Gen 6)\u00a0\u2013 versions prior to 6.5.2.8-2n (SM9800, NSsp 12400, NSsp 12800) and 6.5.4.15.116n (other Gen6 Firewall appliances)<\/li>\n\t<li>SonicWall SOHO (Gen 7)\u00a0\u2013 versions 7.0.1-5035 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2024-0015\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2024-0015<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-477","alert_type":396,"serial_number":"AV24-477","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":5506,"title":"[Control systems] CISA ICS security advisories (AV24-478) ","uuid":"811cb1c5-dedb-4b82-8f3d-2eef199bfdb0","banner":null,"lang":"en","date_modified":"2024-08-26","date_modified_ts":"2024-08-26T18:21:10Z","date_created":"2024-08-26T18:03:33Z","summary":null,"body":["<article data-history-node-id=\"5506\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-478\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-478<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 26, 2024<\/p>\n\n<p>Between August 19 and 25, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Avtec Outpost 0810\u00a0\u2013 versions prior to v5.0.0<\/li>\n\t<li>Avtec Uploader Utility\u00a0\u2013 versions prior to v5.0.0<\/li>\n\t<li>MOBOTIX P3 and Mx6 Cameras\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Rockwell Automation 5015\u00a0- AENFTXT\u00a0\u2013 version 2.011<\/li>\n\t<li>Rockwell Automation Emulate3D\u00a0\u2013 version 17.00.00.13276<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-478","alert_type":398,"serial_number":"AV24-478","subject":"ics","moderation_state":"published","external_url":null},{"nid":5507,"title":"Ubuntu security advisory (AV24-479)","uuid":"2cf1ece6-d668-44ac-9c78-3670d11aa96c","banner":null,"lang":"en","date_modified":"2024-08-26","date_modified_ts":"2024-08-26T18:40:28Z","date_created":"2024-08-26T18:24:58Z","summary":null,"body":["<article data-history-node-id=\"5507\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-479\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-479<br \/><strong>Date: <\/strong>August\u00a026, 2024<\/p>\n\n<p>Between August\u00a019 and 25, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-479","alert_type":396,"serial_number":"AV24-479","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5510,"title":"Dell security advisory (AV24-480)","uuid":"4447c8bd-bc74-4e1e-962c-61ce62cc7214","banner":null,"lang":"en","date_modified":"2024-08-26","date_modified_ts":"2024-08-26T18:45:14Z","date_created":"2024-08-26T18:24:59Z","summary":null,"body":["<article data-history-node-id=\"5510\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-480\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-480<br \/><strong>Date: <\/strong>August\u00a026, 2024<\/p>\n\n<p>Between August\u00a019 and 25, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Dell NetWorker Runtime Environment (NRE)\u00a0\u2013 version 8.0.21<\/li>\n\t<li>PowerSwitch Z9664F-ON\u00a0\u2013 versions prior to v3.54.5.1-7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000227971\/dsa-2024-367-security-update-for-dell-networker-runtime-environment-nre-security-vulnerabilities\">Dell Security Update\u00a0- Dell NetWorker Runtime Environment (NRE)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000227962\/dsa-2024-366-security-update-for-powerswitch-z9664f-on-vulnerability\">Dell Security Update\u00a0- PowerSwitch Z9664F-ON<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-480","alert_type":396,"serial_number":"AV24-480","subject":"dell","moderation_state":"published","external_url":null},{"nid":5509,"title":"Red Hat security advisory (AV24-481)","uuid":"6eab2797-f9c3-4cd4-a199-f1a766231cb5","banner":null,"lang":"en","date_modified":"2024-08-26","date_modified_ts":"2024-08-26T18:50:04Z","date_created":"2024-08-26T18:36:46Z","summary":null,"body":["<article data-history-node-id=\"5509\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-481\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-481<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 26, 2024<\/p>\n\n<p>Between August 19 and 25, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-481","alert_type":396,"serial_number":"AV24-481","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5512,"title":"IBM security advisory (AV24-482)","uuid":"c2847666-fbfd-491a-a4b1-a60f00bdce4b","banner":null,"lang":"en","date_modified":"2024-08-26","date_modified_ts":"2024-08-26T20:06:49Z","date_created":"2024-08-26T19:38:26Z","summary":null,"body":["<article data-history-node-id=\"5512\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-482\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-482<br \/><strong>Date: <\/strong>August\u00a026, 2024<\/p>\n\n<p>Between August\u00a019 and 25, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cloud APM, Base Private and Advanced Private\u00a0\u2013 versions 8.1.4.0 to 8.1.4.0 IF15<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 version 1.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- AI Broker\u00a0\u2013 version 1.0.0<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP9 IF01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-482","alert_type":396,"serial_number":"AV24-482","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5513,"title":"Foxit security advisory (AV24-483)","uuid":"032fce15-707c-46a8-a7c4-b5d15747a48c","banner":null,"lang":"en","date_modified":"2024-08-27","date_modified_ts":"2024-08-27T14:59:28Z","date_created":"2024-08-27T14:33:28Z","summary":null,"body":["<article data-history-node-id=\"5513\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av24-483\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-483\n  <br \/><strong>Date: <\/strong>August\u00a027, 2024\n<\/p>\n<p>Between August\u00a03 and 9, 2024, Foxit published security advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Foxit PDF Editor for Windows\u00a0\u2013 multiple versions<\/li>\n  <li>Foxit PDF Reader for Windows\u00a0\u2013 versions 2024.2.2.25170 and prior<\/li>\n  <li>Foxit PDF Editor for Mac\u00a0\u2013 2024.2.2.64388, 2024.2.1.64379, 2024.2.0.64371, and 2024.1.0.63682<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av24-483","alert_type":396,"serial_number":"AV24-483","subject":"other","moderation_state":"published","external_url":null},{"nid":5515,"title":"[Control systems] B&R security advisory (AV24-484)","uuid":"9906ec99-27b3-4fc0-9f84-73d27c2bf8f7","banner":null,"lang":"en","date_modified":"2024-08-27","date_modified_ts":"2024-08-27T17:41:03Z","date_created":"2024-08-27T17:14:23Z","summary":null,"body":["<article data-history-node-id=\"5515\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-484\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-484<br \/><strong>Date: <\/strong>August\u00a027, 2024<\/p>\n\n<p>On August\u00a027, 2024, B&amp;R published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>B&amp;R APROL\u00a0\u2013 version R 4.2.-07P3 and prior, version R 4.4-00P3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA24P2014_Multiple_vulnerabilities_in_BR_APROL.pdf-367290ae.pdf\">B&amp;R cyber security advisory\u00a0- Multiple vulnerabilities in B&amp;R APROL (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av24-484","alert_type":398,"serial_number":"AV24-484","subject":"br-automation","moderation_state":"published","external_url":null},{"nid":5538,"title":"Fortra security advisory (AV24-486)","uuid":"3892ea94-42d5-4421-9a60-f0a775cb054a","banner":null,"lang":"en","date_modified":"2024-08-28","date_modified_ts":"2024-08-28T19:55:16Z","date_created":"2024-08-27T19:12:32Z","summary":null,"body":["<article data-history-node-id=\"5538\" about=\"\/en\/alerts-advisories\/fortra-security-advisory-av24-486\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-486<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 28, 2024<\/p>\n\n<p>On August 27, 2024, Fortra published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Fortra FileCatalyst Workflow\u00a0\u2013 version 5.1.6 Build 139 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\/fi-2024-011\">Fortra Security Advisories\u00a0- FI-2024-011<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortra.com\/security\">Fortra Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortra-security-advisory-av24-486","alert_type":396,"serial_number":"AV24-486","subject":"other","moderation_state":"published","external_url":null},{"nid":5544,"title":"Cisco security advisory (AV24-485)","uuid":"04b81e22-1f50-42b0-ac81-d62981eb2071","banner":null,"lang":"en","date_modified":"2024-08-28","date_modified_ts":"2024-08-28T19:14:51Z","date_created":"2024-08-28T19:08:54Z","summary":null,"body":["<article data-history-node-id=\"5544\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-485\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-485<br \/><strong>Date: <\/strong>August\u00a028, 2024<\/p>\n\n<p>On August\u00a028, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Nexus 3000, 7000 and 9000 Series Switches running Cisco NX-OS Software<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-dhcp6-relay-dos-znEAA6xn\">Cisco Security Advisory\u00a0\u2013 cisco-sa-nxos-dhcp6-relay-dos-znEAA6xn<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-485","alert_type":396,"serial_number":"AV24-485","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5568,"title":"Dell security advisory (AV24-488)","uuid":"fbead765-924f-4677-83be-180f1163514f","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T13:07:18Z","date_created":"2024-09-03T13:05:20Z","summary":null,"body":["<article data-history-node-id=\"5568\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-488\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-488<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 3, 2024<\/p>\n\n<p>Between August 26 and September 1, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APEX Cloud Platform Foundation Software\u00a0\u2013 versions prior to 03.01.00.00<\/li>\n\t<li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 4.14.31<\/li>\n\t<li>Dell Connectrix (Brocade)\u00a0\u2013 versions prior to 9.2.0<\/li>\n\t<li>Dell RecoverPoint for Virtual Machines\u00a0\u2013 version 6.0.sp1<\/li>\n\t<li>PowerScale OneFS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-488","alert_type":396,"serial_number":"AV24-488","subject":"dell","moderation_state":"published","external_url":null},{"nid":5565,"title":"IBM security advisory (AV24-489)","uuid":"59c3873e-3677-446f-aaaf-972407ed3783","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T14:07:48Z","date_created":"2024-09-03T14:13:20Z","summary":null,"body":["<article data-history-node-id=\"5565\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-489\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-489<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 3, 2024<\/p>\n\n<p>Between August 26 and September 1, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following product:<\/p>\n\n<ul><li>IBM Concert Software \u2013 versions 1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7166857\">IBM Security Bulletins - 7166857<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n\t<br \/><br \/><br \/><br \/><br \/>\n\t\u00a0\n\t<li>\u00a0<\/li>\n\t<li>\u00a0<\/li>\n\t<li>\u00a0<\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-489","alert_type":396,"serial_number":"AV24-489","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5569,"title":"Ubuntu security advisory (AV24-490)","uuid":"1dc1cbef-f6b1-4551-9c26-a17f79a09d07","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T16:08:48Z","date_created":"2024-09-03T16:00:17Z","summary":null,"body":["<article data-history-node-id=\"5569\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-490\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-490<br \/><strong>Date: <\/strong>September\u00a03, 2024<\/p>\n\n<p>Between August\u00a026 and September\u00a01, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6972-4\">Ubuntu Security Notice (USN-6972-4)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6973-3\">Ubuntu Security Notice (USN-6973-3)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-490","alert_type":396,"serial_number":"AV24-490","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5570,"title":"[Control systems] CISA ICS security advisories (AV24-491)","uuid":"6e5d6244-b7e5-45d3-bc42-a1228f6a3c3c","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T17:05:18Z","date_created":"2024-09-03T17:00:17Z","summary":null,"body":["<article data-history-node-id=\"5570\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-491\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-491<br \/><strong>Date: <\/strong>September\u00a03, 2024<\/p>\n\n<p>Between August\u00a026 and September\u00a01, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics DTN Soft\u00a0\u2013 version 2.0.1 and prior<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 versions 11.1.0 through 11.1.7<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 versions 11.2.0 through 11.2.8<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 versions 12.0.0 through 12.0.6<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 versions 12.1.0 through 12.1.7<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 versions 13.0.0 through 13.0.4<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 versions 13.1.0 through 13.1.2<\/li>\n\t<li>Rockwell Automation ThinManager ThinServer\u00a0\u2013 versions 13.2.0 through 13.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-491","alert_type":398,"serial_number":"AV24-491","subject":"ics","moderation_state":"published","external_url":null},{"nid":5567,"title":"VMware security advisory (AV24-494)","uuid":"669e94b3-4301-40e9-a53d-73755e38d5e6","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T19:10:59Z","date_created":"2024-09-03T17:32:36Z","summary":null,"body":["<article data-history-node-id=\"5567\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-494\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-494<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 3, 2024<\/p>\n\n<p>On September 3, 2024, VMware released a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Fusion \u2013 versions 13.x prior to 13.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24939  \">VMSA-2024-0018: VMware Fusion update addresses a code execution vulnerability (CVE-2024-38811)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories - VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-494","alert_type":396,"serial_number":"AV24-494","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5566,"title":"Red Hat security advisory (AV24-492)","uuid":"461f6996-3981-4be8-b5a3-2af55ef596ff","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T18:09:14Z","date_created":"2024-09-03T18:01:27Z","summary":null,"body":["<article data-history-node-id=\"5566\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-492\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-492<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 3, 2024<\/p>\n\n<p>Between August 26 and September 1, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:5928\">Red Hat Security Advisory \u2013 RHSA-2024:5928<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-492","alert_type":396,"serial_number":"AV24-492","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5571,"title":"HPE security advisory (AV24-495)","uuid":"d4e48615-7be2-4e63-aff6-b168e3cefb78","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T19:11:00Z","date_created":"2024-09-03T18:40:45Z","summary":null,"body":["<article data-history-node-id=\"5571\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-495\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-495<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 3, 2024<\/p>\n\n<p>On September 3, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console (UOC) \u2013 versions prior to v3.1.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04696en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbgn04696en_us <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-495","alert_type":396,"serial_number":"AV24-495","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5572,"title":"Mozilla security advisory (AV24-493)","uuid":"6cdc7f2d-df15-4ab4-b35a-03d1062deb27","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T19:10:23Z","date_created":"2024-09-03T19:37:21Z","summary":null,"body":["<article data-history-node-id=\"5572\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-493\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-493\n  <br \/><strong>Date: <\/strong>September\u00a03, 2024\n<\/p>\n<p>On September\u00a03, 2024, Mozilla published security advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Thunderbird \u2013 versions prior to 115.15<\/li>\n  <li>Thunderbird \u2013 versions prior to 128.2<\/li>\n  <li>Focus for iOS \u2013 versions prior to 130<\/li>\n  <li>Firefox ESR \u2013 versions prior to 115.15<\/li>\n  <li>Firefox ESR \u2013 versions prior to 128.2<\/li>\n  <li>Firefox \u2013 versions prior to 130<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-493","alert_type":396,"serial_number":"AV24-493","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5573,"title":"Android security advisory \u2013 September 2024 Monthly Rollup (AV24-496)","uuid":"b723b527-d20c-4bc4-9921-4b420e82de61","banner":null,"lang":"en","date_modified":"2024-09-03","date_modified_ts":"2024-09-03T19:56:41Z","date_created":"2024-09-03T19:43:31Z","summary":null,"body":["<article data-history-node-id=\"5573\" about=\"\/en\/alerts-advisories\/android-security-advisory-september-2024-monthly-rollup-av24-496\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-496<br \/><strong>Date: <\/strong>September 3, 2024<\/p>\n\n<p>On September 3, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-09-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-september-2024-monthly-rollup-av24-496","alert_type":396,"serial_number":"AV24-496","subject":"android","moderation_state":"published","external_url":null},{"nid":5582,"title":"Cisco security advisory (AV24-497)","uuid":"0a86b1b2-0a20-4565-ad44-e4d528deb943","banner":null,"lang":"en","date_modified":"2024-09-04","date_modified_ts":"2024-09-04T19:36:38Z","date_created":"2024-09-04T18:54:51Z","summary":null,"body":["<article data-history-node-id=\"5582\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-497\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-497<br \/><strong>Date: <\/strong>September\u00a04, 2024<\/p>\n\n<p>On September\u00a04, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Cisco Smart Licensing Utility\u00a0\u2013 versions 2.0.0, 2.1.0 and 2.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cslu-7gHMzWmw\">Cisco Security Advisory \u2013 cisco-sa-cslu-7gHMzWmw<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-497","alert_type":396,"serial_number":"AV24-497","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5583,"title":"Drupal security advisory (AV24-498)","uuid":"b82d98e8-94a6-45b2-a10d-fc6709553dbd","banner":null,"lang":"en","date_modified":"2024-09-04","date_modified_ts":"2024-09-04T20:06:54Z","date_created":"2024-09-04T19:42:13Z","summary":null,"body":["<article data-history-node-id=\"5583\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-498\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-498<br \/><strong>Date: <\/strong>September\u00a04, 2024<\/p>\n\n<p>On September\u00a04, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Paragraphs table\u00a0\u2013 versions prior to 8.x-1.23.0 and versions prior to 2.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-036\">Drupal Security Advisory\u00a0- SA-CONTRIB-2024-036<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-498","alert_type":396,"serial_number":"AV24-498","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5586,"title":"Veeam security advisory (AV24-499)","uuid":"891012bb-f6d2-44ce-8e2a-fae5233f1a25","banner":null,"lang":"en","date_modified":"2024-09-05","date_modified_ts":"2024-09-05T16:45:47Z","date_created":"2024-09-05T16:23:45Z","summary":null,"body":["<article data-history-node-id=\"5586\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av24-499\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-499<br \/><strong>Date: <\/strong>September\u00a05, 2024<\/p>\n\n<p>On September 4, 2024, Veeam published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2013 12.x version 12.1.2.172 and prior<\/li>\n\t<li>Veeam ONE\u00a0\u2013 12.x version 12.1.0.3208 and prior<\/li>\n\t<li>Veeam Service Provider Console\u00a0\u2013 8.x version 8.0.0.19552 and prior<\/li>\n\t<li>Veeam Agent for Linux\u00a0\u2013 6.x version 6.1.2.1781 and prior<\/li>\n\t<li>Veeam Backup for Nutanix AHV\u00a0\u2013 12.x version 12.5.1.8 and prior<\/li>\n\t<li>Veeam Backup for Oracle Linux Virtualization Manager\u00a0\u2013 12.x version 12.4.1.45 and prior<\/li>\n\t<li>Red Hat Virtualization\u00a0\u2013 12.x version 12.4.1.45 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4649\">Veeam Security Advisory\u00a0\u2013 kb4649<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av24-499","alert_type":396,"serial_number":"AV24-499","subject":"other","moderation_state":"published","external_url":null},{"nid":5588,"title":"[Control systems] CISA ICS security advisories (AV24-500) ","uuid":"bee3578f-589c-45a2-9265-902d24d0c69d","banner":null,"lang":"en","date_modified":"2024-09-09","date_modified_ts":"2024-09-09T14:28:02Z","date_created":"2024-09-09T14:13:18Z","summary":null,"body":["<article data-history-node-id=\"5588\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-500\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-500<br \/><strong>Date: <\/strong>September 9, 2024<\/p>\n\n<p>Between September 2 and 8, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Baxter Connex Health Portal\u00a0\u2013 versions prior to 8\/30\/2024<\/li>\n\t<li>Hughes Network Systems WL3000 Fusion Software\u00a0\u2013 versions prior to 2.7.0.10<\/li>\n\t<li>LOYTEC Electronics LINX Series\u00a0\u2013 all versions, multiple models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-500","alert_type":398,"serial_number":"AV24-500","subject":"ics","moderation_state":"published","external_url":null},{"nid":5589,"title":"Ubuntu security advisory (AV24-501)","uuid":"b1dfbbfe-e469-496c-a34b-17f56493db06","banner":null,"lang":"en","date_modified":"2024-09-09","date_modified_ts":"2024-09-09T14:56:19Z","date_created":"2024-09-09T14:43:04Z","summary":null,"body":["<article data-history-node-id=\"5589\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-501\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-501<br \/><strong>Date: <\/strong>September 9, 2024<\/p>\n\n<p>Between September 2 and 8, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-6973-4\">Ubuntu Security Notice (USN-6973-4)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-501","alert_type":396,"serial_number":"AV24-501","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5590,"title":"Red Hat security advisory (AV24-502)","uuid":"7283bb7e-e634-483a-92dc-4d2f1c9e2b18","banner":null,"lang":"en","date_modified":"2024-09-09","date_modified_ts":"2024-09-09T15:27:18Z","date_created":"2024-09-09T15:09:56Z","summary":null,"body":["<article data-history-node-id=\"5590\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-502\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-502<br \/><strong>Date: <\/strong>September 9, 2024<\/p>\n\n<p>Between September\u00a02\u00a0and\u00a08,\u00a02024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-502","alert_type":396,"serial_number":"AV24-502","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5591,"title":"Dell security advisory (AV24-503)","uuid":"d9f81d3e-1dc0-42e1-90c4-87eaeefb9cce","banner":null,"lang":"en","date_modified":"2024-09-09","date_modified_ts":"2024-09-09T15:54:52Z","date_created":"2024-09-09T15:33:41Z","summary":null,"body":["<article data-history-node-id=\"5591\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-503\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-503<br \/><strong>Date: <\/strong>September 9, 2024<\/p>\n\n<p>Between September\u00a02\u00a0and\u00a08,\u00a02024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>CloudBoost Virtual Appliance\u00a0\u2013 versions 19.7 to 19.11<\/li>\n\t<li>DELL EMC Metronode\u00a0\u2013 versions prior to 8.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000228280\/dsa-2024-362-security-update-for-dell-cloudboost-virtual-appliance-multiple-component-vulnerabilities\">Dell Security Update (CloudBoost Virtual Appliance)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000228339\/dsa-2024-380-security-update-for-dell-emc-metronode-for-multiple-third-party-components-vulnerabilities\">Dell Security Update (DELL EMC Metronode)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-503","alert_type":396,"serial_number":"AV24-503","subject":"dell","moderation_state":"published","external_url":null},{"nid":5599,"title":"Progress security advisory (AV24-504)","uuid":"723d3373-569d-4447-8335-e911014a6de8","banner":null,"lang":"en","date_modified":"2024-09-09","date_modified_ts":"2024-09-09T20:45:28Z","date_created":"2024-09-09T20:41:50Z","summary":null,"body":["<article data-history-node-id=\"5599\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av24-504\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-504<br \/><strong>Date: <\/strong>September\u00a09, 2024<\/p>\n\n<p>On September\u00a04, 2024, Progress published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>LoadMaster\u00a0- version 7.2.60.0 and prior<\/li>\n\t<li>Multi-Tenant Hypervisor\u00a0- version 7.1.35.11 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.kemptechnologies.com\/hc\/en-us\/articles\/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591\">Progress LoadMaster Security Vulnerability (CVE-2024-7591)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av24-504","alert_type":396,"serial_number":"AV24-504","subject":"other","moderation_state":"published","external_url":null},{"nid":5600,"title":"IBM security advisory (AV24-505)","uuid":"d27c961f-146e-466b-a677-ba72b0588e64","banner":null,"lang":"en","date_modified":"2024-09-09","date_modified_ts":"2024-09-09T20:49:46Z","date_created":"2024-09-09T20:41:51Z","summary":null,"body":["<article data-history-node-id=\"5600\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-505\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-505<br \/><strong>Date: <\/strong>September 9, 2024<\/p>\n\n<p>Between September 2 and September 8, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Transformation Advisor\u00a0\u2013 version 2.0.1 to 3.10.0<\/li>\n\t<li>IBM i Modernization Engine for Lifecycle Integration\u00a0\u2013 versions 1.0 to 1.4.8 and 2.0 to 2.0.2<\/li>\n\t<li>ICP\u00a0- Discovery\u00a0\u2013 versions 4.0.0 to 4.8.5 and version 5.0.0<\/li>\n\t<li>QRadar Suite Software\u00a0\u2013 version 1.10.12.0 to 1.10.24.0<\/li>\n\t<li>watsonx.data\u00a0\u2013 version 1.0.0 to 2.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-505","alert_type":396,"serial_number":"AV24-505","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5602,"title":"SAP security advisory \u2013 September 2024 monthly rollup (AV24-506)","uuid":"fadd36a9-a962-4c43-aab1-affe46eb4104","banner":null,"lang":"en","date_modified":"2024-09-10","date_modified_ts":"2024-09-10T14:12:37Z","date_created":"2024-09-10T13:59:57Z","summary":null,"body":["<article data-history-node-id=\"5602\" about=\"\/en\/alerts-advisories\/sap-security-advisory-september-2024-monthly-rollup-av24-506\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-506<br \/><strong>Date: <\/strong>September\u00a010,\u00a02024<\/p>\n\n<p>On September\u00a010,\u00a02024, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP BusinessObjects Business Intelligence Platform\u00a0\u2013 versions ENTERPRISE 430, 440<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/september-2024.html\">SAP Security Patch Day\u00a0- September\u00a02024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-september-2024-monthly-rollup-av24-506","alert_type":396,"serial_number":"AV24-506","subject":"sap","moderation_state":"published","external_url":null},{"nid":5603,"title":"[Control systems] Siemens security advisory (AV24\u2013507) ","uuid":"8c7ad1e8-9a8b-443f-941b-0d919e37dcab","banner":null,"lang":"en","date_modified":"2024-09-10","date_modified_ts":"2024-09-10T17:26:22Z","date_created":"2024-09-10T17:18:49Z","summary":null,"body":["<article data-history-node-id=\"5603\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-507\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-507<br \/><strong>Date: <\/strong>September 10, 2024<\/p>\n\n<p>On September 10, 2024, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Automation License Manager software\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Industrial Edge Management OS (IEM\u2013OS)\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SCALANCE W700 802.11 AX Family\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SICAM and SITIPE products\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC Batch V9.1\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC Information Server\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC PCS neo\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC S7\u2013200 SMART Devices\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC PCS7\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC Process Historian\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC SCADA and PCS 7 systems\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC WinCC\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC WinCC Runtime Professional\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SINEC NMS\u00a0\u2013 all versions<\/li>\n\t<li>SINEMA Remote Connect Server\u00a0\u2013 versions prior to V3.2 SP2<\/li>\n\t<li>SINEMA Remote Connect Client\u00a0\u2013 versions prior to V3.2 SP2<\/li>\n\t<li>SINUMERIK ONE\u00a0\u2013 versions prior to V6.24<\/li>\n\t<li>SINUMERIK 828D V4\u00a0\u2013 all versions<\/li>\n\t<li>SINUMERIK 828D V5\u00a0\u2013 versions prior to V5.24<\/li>\n\t<li>SINUMERIK 840D sl V4\u00a0\u2013 all versions<\/li>\n\t<li>Tecnomatix Plant Simulation\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Totally Integrated Automation Portal (TIA Portal)\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-507","alert_type":398,"serial_number":"AV24-507","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5604,"title":"[Control systems] Schneider Electric security advisory (AV24-508)","uuid":"990219b7-199c-4b4d-88ad-745c86396dd2","banner":null,"lang":"en","date_modified":"2024-09-10","date_modified_ts":"2024-09-10T17:32:17Z","date_created":"2024-09-10T17:27:10Z","summary":null,"body":["<article data-history-node-id=\"5604\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-508\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-508<br \/><strong>Date: <\/strong>September 10, 2024<\/p>\n\n<p>On September 10, 2024, Schneider Electric published security advisories to highlight vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Vijeo Designer\u00a0\u2013 version prior V6.3 SP1<\/li>\n\t<li>Vijeo Designer embedded in EcoStruxure\u2122 Machine Expert\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-254-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-254-01.pdf\">Schneider Electric Security Notification\u00a0- SEVD-2024-254-01 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-508","alert_type":398,"serial_number":"AV24-508","subject":"other","moderation_state":"published","external_url":null},{"nid":5613,"title":"Ivanti security advisory (AV24-509)","uuid":"c3b1982f-3e2a-46ce-bbc9-c7a48734db1e","banner":null,"lang":"en","date_modified":"2024-09-10","date_modified_ts":"2024-09-10T18:50:24Z","date_created":"2024-09-10T18:35:57Z","summary":null,"body":["<article data-history-node-id=\"5613\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-509\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-509<br \/><strong>Date: <\/strong>September 10, 2024<\/p>\n\n<p>On September 10, 2024, Ivanti published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti IWC\u00a0\u2013 versions 10.18.0.0 and prior<\/li>\n\t<li>Ivanti Cloud Services Appliance (CSA)\u00a0\u2013 version CSA 4.6 (versions prior to Patch 519)<\/li>\n\t<li>Ivanti Endpoint Manager\u00a0\u2013 version 2024 and versions 2022 SU5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Workspace-Control-IWC?language=en_US\">Security Advisory: Ivanti Workspace Control (IWC)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US\">Security Advisory: EPM September 2024 for EPM 2024 and EPM 2022<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US\">Security Advisory Ivanti Cloud Service Appliance (CSA) (CVE-2024-8190)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US&amp;sort=date%20descending&amp;f%3A%40sfkbknowledgearticletypec=%5BSecurity%20Advisory%5D%20#t=All&amp;sort=date%20descending\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-509","alert_type":396,"serial_number":"AV24-509","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5617,"title":"Microsoft security advisory \u2013 September 2024 monthly rollup (AV24-510)","uuid":"c47aaee8-d1ce-409d-989b-77e9da741a9c","banner":null,"lang":"en","date_modified":"2024-09-10","date_modified_ts":"2024-09-10T19:22:12Z","date_created":"2024-09-10T19:12:25Z","summary":null,"body":["<article data-history-node-id=\"5617\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2024-monthly-rollup-av24-510\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-510<br \/><strong>Date: <\/strong>September 10, 2024<\/p>\n\n<p>On September 10, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Azure Connected Machine Agent<\/li>\n\t<li>Azure CycleCloud\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Azure Health Bot<\/li>\n\t<li>Azure Network Watcher VM Extension for Windows<\/li>\n\t<li>Azure Stack Hub<\/li>\n\t<li>Azure Web Apps<\/li>\n\t<li>Microsoft 365 Apps for Enterprise\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft AutoUpdate for Mac<\/li>\n\t<li>Microsoft Dynamics 365 (on-premises)\u00a0\u2013 version 9.1<\/li>\n\t<li>Microsoft Dynamics 365 Business Central 2023 Release Wave 1<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Outlook 2016\u00a0- multiple platforms<\/li>\n\t<li>Microsoft Project 2016\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Publisher 2016<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SQL Server\u00a0- multiple versions and platforms<\/li>\n\t<li>Microsoft Teams for iOS<\/li>\n\t<li>Microsoft Visio 2016 multiple platforms<\/li>\n\t<li>Microsoft Visual Studio 2022\u00a0\u2013 multiple versions<\/li>\n\t<li>.NET\u00a0\u2013 version 8.0<\/li>\n\t<li>Power Automate for Desktop<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-38226, CVE-2024-43491, CVE-2024-38014 and CVE-2024-38217 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Sep\">September 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2024-monthly-rollup-av24-510","alert_type":396,"serial_number":"AV24-510","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5618,"title":"Adobe security advisory (AV24\u2013511)","uuid":"ebe8fd31-ad2c-42e7-9bcd-92cdac3e72a9","banner":null,"lang":"en","date_modified":"2024-09-10","date_modified_ts":"2024-09-10T19:33:30Z","date_created":"2024-09-10T19:29:21Z","summary":null,"body":["<article data-history-node-id=\"5618\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-511\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-511<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 10, 2024<\/p>\n\n<p>On September 10, 2024, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat DC \u2013 versions 24.003.20054\u00a0and prior (Windows), version 24.002.21005\u00a0and prior (MacOS)<\/li>\n\t<li>Acrobat Reader DC \u2013 version 24.003.20054\u00a0and prior (Windows), version 24.002.21005\u00a0and prior (MacOS)<\/li>\n\t<li>Acrobat 2024 \u2013 version 24.001.30159\u00a0and prior<\/li>\n\t<li>Acrobat 2020 \u2013 version 20.005.30655\u00a0and prior<\/li>\n\t<li>Adobe Audition \u2013 version 24.4.1 and prior, version 23.6.6 and prior\u00a0\u00a0\u00a0<\/li>\n\t<li>Adobe After Effects \u2013 version 24.5 and\u00a0prior, version 23.6.6 and\u00a0prior<\/li>\n\t<li>Adober Media Encoder \u2013 versions 24.6 and 23.6.9<\/li>\n\t<li>Adobe Premiere Pro \u2013 version 24.5 and prior, version 23.6.8 and prior<\/li>\n\t<li>Illustrator 2024 \u2013 version 28.6 and\u202fprior<\/li>\n\t<li>Illustrator 2023 \u2013 version 27.9.5 and prior<\/li>\n\t<li>Acrobat Reader 2020 \u2013 version 20.005.30655\u00a0and prior<\/li>\n\t<li>ColdFusion 2023 \u2013 version Update 9 and prior\u00a0\u00a0<\/li>\n\t<li>ColdFusion 2021 \u2013 version Update 15 and prior<\/li>\n\t<li>Photoshop 2023 \u2013 version 24.7.4 and prior<\/li>\n\t<li>Photoshop 2024 \u2013 version 25.11 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-511","alert_type":396,"serial_number":"AV24-511","subject":"other","moderation_state":"published","external_url":null},{"nid":5619,"title":"Google Chrome security advisory (AV24-512)","uuid":"8678a662-87ca-445c-ad56-de1346386fb9","banner":null,"lang":"en","date_modified":"2024-09-11","date_modified_ts":"2024-09-11T14:07:12Z","date_created":"2024-09-11T14:03:24Z","summary":null,"body":["<article data-history-node-id=\"5619\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-512\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-512<br \/><strong>Date: <\/strong>September11, 2024<\/p>\n\n<p>On September 10, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 128.0.6613.137\/.138 (Windows and Mac) and 128.0.6613.137 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/09\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-512","alert_type":396,"serial_number":"AV24-512","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5620,"title":"[Control systems] ABB security advisory (AV24-513)","uuid":"87710e8d-2204-4d25-b939-7e2568c4f924","banner":null,"lang":"en","date_modified":"2024-09-11","date_modified_ts":"2024-09-11T14:14:47Z","date_created":"2024-09-11T14:11:16Z","summary":null,"body":["<article data-history-node-id=\"5620\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-513\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-513<br \/><strong>Date: <\/strong>September 11, 2024<\/p>\n\n<p>On September 10, 2024, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB Relion 630 Series Protection Relays\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA002356&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Relion 630 Series Protection Relays IEC 61850 MMS Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-513","alert_type":398,"serial_number":"AV24-513","subject":"abb","moderation_state":"published","external_url":null},{"nid":5621,"title":"Intel security advisory (AV24-514) ","uuid":"d9ab4287-622b-4af3-a5d0-5c48cb011776","banner":null,"lang":"en","date_modified":"2024-09-11","date_modified_ts":"2024-09-11T18:08:00Z","date_created":"2024-09-11T18:03:46Z","summary":null,"body":["<article data-history-node-id=\"5621\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av24-514\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-514\n  <br \/><strong>Date: <\/strong>September 11, 2024\n<\/p>\n<p>On September 10, 2024, Intel published security advisories to address vulnerabilities in multiple products.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-01071.html\">Intel advisory UEFI Firmware Advisory INTEL-SA-01071 reports high-severity CVEs.<\/a><\/li>\n  <li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av24-514","alert_type":396,"serial_number":"AV24-514","subject":"intel","moderation_state":"published","external_url":null},{"nid":5624,"title":"Cisco security advisory (AV24-515)","uuid":"f895354d-5fbd-4f75-9824-a86b7f6de89e","banner":null,"lang":"en","date_modified":"2024-09-11","date_modified_ts":"2024-09-11T19:08:57Z","date_created":"2024-09-11T19:04:26Z","summary":null,"body":["<article data-history-node-id=\"5624\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-515\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-515<br \/><strong>Date: <\/strong>September 11, 2024<\/p>\n\n<p>On September 11, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Crosswork NSO\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Optical Site Manager\u00a0\u2013 versions prior to 24.3.1<\/li>\n\t<li>Cisco RV340 Dual WAN Gigabit VPN Routers\u00a0\u2013 all versions<\/li>\n\t<li>Cisco ConfD\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco IOS XR Software\u00a0\u2013 versions 7.7.1 to 7.11.2, 24.1.1 and later<\/li>\n\t<li>Cisco IOS XR 64-Bit Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Routed Passive Optical Network (PON) Controller Software\u00a0\u2013 multiple products and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-515","alert_type":396,"serial_number":"AV24-515","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5625,"title":"Palo Alto Networks security advisory (AV24-516)","uuid":"1996f628-5e3a-4112-9510-c8da1f5c92bb","banner":null,"lang":"en","date_modified":"2024-09-11","date_modified_ts":"2024-09-11T19:15:28Z","date_created":"2024-09-11T19:09:35Z","summary":null,"body":["<article data-history-node-id=\"5625\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-516\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-516<br \/><strong>Date: <\/strong>September 11, 2024<\/p>\n\n<p>On September 11, 2024, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Prisma Access Browser\u00a0\u2013 version 128.91.2869.7 and prior<\/li>\n\t<li>PAN-OS\u00a0\u2013 versions prior to 11.2.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-8686\">Palo Alto Networks Security Advisories\u00a0\u2013 CVE-2024-8686<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2024-0009\">Palo Alto Networks Security Advisories\u00a0\u2013 PAN-SA-2024-0009<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-516","alert_type":396,"serial_number":"AV24-516","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5626,"title":"GitLab security advisory (AV24-517)","uuid":"ec29486a-eb02-4ffe-90fb-e2ebfd7d27d0","banner":null,"lang":"en","date_modified":"2024-09-12","date_modified_ts":"2024-09-12T13:15:16Z","date_created":"2024-09-12T13:09:55Z","summary":null,"body":["<article data-history-node-id=\"5626\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-517\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-517<br \/><strong>Date:<\/strong> September 12, 2024<\/p>\n\n<p>On September\u00a011,\u00a02024, GitLab published security advisories to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 17.3.2, 17.2.5, and 17.1.7<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 17.3.2, 17.2.5, and 17.1.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/09\/11\/patch-release-gitlab-17-3-2-released\/\">GitLab Critical Patch Release: 17.3.2, 17.2.4 and 17.1.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-517","alert_type":396,"serial_number":"AV24-517","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5627,"title":"HPE security advisory (AV24-518)","uuid":"e7edb6c3-f678-4fb4-8edf-e4d90cd2f176","banner":null,"lang":"en","date_modified":"2024-09-12","date_modified_ts":"2024-09-12T14:25:02Z","date_created":"2024-09-12T14:23:29Z","summary":null,"body":["<article data-history-node-id=\"5627\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-518\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-518<br \/><strong>Date:<\/strong> September 12, 2024<\/p>\n\n<p>On September\u00a011,\u00a02024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Virtual Tape Repository (VTR) \u2013 versions T0964V01 and T0964V01^AAA to AAJ<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbns04698en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbns04698en_us <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-518","alert_type":396,"serial_number":"AV24-518","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5633,"title":"Microsoft Edge security advisory (AV24-519)","uuid":"4f40de5b-5501-45c6-8fdd-47245ee9dd48","banner":null,"lang":"en","date_modified":"2024-09-13","date_modified_ts":"2024-09-13T13:40:55Z","date_created":"2024-09-13T13:39:29Z","summary":null,"body":["<article data-history-node-id=\"5633\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-519\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-519<br \/><strong>Date:<\/strong> September 13, 2024<\/p>\n\n<p>On September 12, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 128.0.2739.79<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-12-2024\">Microsoft Edge Stable Channel Release Notes <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-519","alert_type":396,"serial_number":"AV24-519","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5634,"title":"SolarWinds security advisory (AV24-520)","uuid":"a036ed09-04ba-43fb-84bd-5e4e52a6979a","banner":null,"lang":"en","date_modified":"2024-09-13","date_modified_ts":"2024-09-13T13:45:42Z","date_created":"2024-09-13T13:44:00Z","summary":null,"body":["<article data-history-node-id=\"5634\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-520\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-520<br \/><strong>Date:<\/strong> September 13, 2024<\/p>\n\n<p>On September 12, 2024, SolarWinds published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>SolarWinds Access Rights Manager (ARM) \u2013 version 2024.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-28991\">SolarWinds Access Rights Manager (ARM) (CVE-2024-28991) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-520","alert_type":396,"serial_number":"AV24-520","subject":null,"moderation_state":"published","external_url":null},{"nid":5643,"title":"Ubuntu security advisory (AV24-521)","uuid":"7cd34960-f4f6-49e4-a087-b1c20bf7057b","banner":null,"lang":"en","date_modified":"2024-09-16","date_modified_ts":"2024-09-16T17:24:50Z","date_created":"2024-09-16T17:15:48Z","summary":null,"body":["<article data-history-node-id=\"5643\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-521\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-521<br \/><strong>Date: <\/strong>September 16, 2024<\/p>\n\n<p>Between September\u00a09 and 15,\u00a02024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-521","alert_type":396,"serial_number":"AV24-521","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5644,"title":"IBM security advisory (AV24-522)","uuid":"880d7470-b604-4df7-8eb6-df066bfb661e","banner":null,"lang":"en","date_modified":"2024-09-16","date_modified_ts":"2024-09-16T17:35:11Z","date_created":"2024-09-16T17:26:55Z","summary":null,"body":["<article data-history-node-id=\"5644\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-522\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-522<br \/><strong>Date: <\/strong>September 16, 2024<\/p>\n\n<p>Between September\u00a09 and 15,\u00a02024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following product:<\/p>\n\n<ul><li>IBM Watson Assistant for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.0 to 5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7167925\">IBM Security Bulletin\u00a0- 7167925<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-522","alert_type":396,"serial_number":"AV24-522","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5646,"title":"[Control systems] CISA ICS security advisories (AV24-523)","uuid":"74ca0316-44ed-41e5-b821-9ed4b9c04cf0","banner":null,"lang":"en","date_modified":"2024-09-16","date_modified_ts":"2024-09-16T18:26:06Z","date_created":"2024-09-16T17:45:33Z","summary":null,"body":["<article data-history-node-id=\"5646\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-523\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-523<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 16, 2024<\/p>\n\n<p>Between September 9 and 15, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AutomationDirect DirectLogic H2-DM1E\u00a0- version 2.8.0 and prior<\/li>\n\t<li>BPL Medical Technologies Be Well Android Application\u00a0- version 3.64 and prior<\/li>\n\t<li>BPL Medical Technologies PWS-01-BT\u00a0- all versions<\/li>\n\t<li>iniNet Solutions GmbH SpiderControl SCADA Web Server\u00a0- version v2.09 and prior<\/li>\n\t<li>Rockwell Automation 5015-U8IHFT\u00a0- version 1.012 and prior<\/li>\n\t<li>Rockwell Automation 1756-EN4\u00a0- version 2.001<\/li>\n\t<li>Rockwell Automation AADvance Trusted SIS Workstation\u00a0- version 2.00.01 and prior<\/li>\n\t<li>Rockwell Automation CompactLogix 5380\u00a0- version v.32.011<\/li>\n\t<li>Rockwell Automation CompactLogix 5380 Process\u00a0- version v.33.011<\/li>\n\t<li>Rockwell Automation Compact GuardLogix 5380 SIL 2\u00a0- version v.32.013<\/li>\n\t<li>Rockwell Automation Compact GuardLogix 5380 SIL 3\u00a0- version v.32.011<\/li>\n\t<li>Rockwell Automation CompactLogix 5480\u00a0- version v.32.011<\/li>\n\t<li>Rockwell Automation ControlLogix 5580\u00a0- version v.32.011<\/li>\n\t<li>Rockwell Automation ControlLogix 5580 Process\u00a0- version v.33.011<\/li>\n\t<li>Rockwell Automation GuardLogix 5580\u00a0- version v.32.011<\/li>\n\t<li>Rockwell Automation Embedded Edge Compute Module\u00a0- version 4.0.0.347<\/li>\n\t<li>Rockwell Automation FactoryTalk Batch View\u00a0- version 2.01.00 and prior<\/li>\n\t<li>Rockwell Automation FactoryTalk View Site Edition\u00a0- versions V12.0, V13.0 and V14.0<\/li>\n\t<li>Rockwell Automation 2800C OptixPanel Compact\u00a0- version 4.0.0.325<\/li>\n\t<li>Rockwell Automation 2800S OptixPanel Standard\u00a0- version 4.0.0.350<\/li>\n\t<li>Rockwell Automation Pavilion8\u00a0- versions prior to V5.20<\/li>\n\t<li>Rockwell Automation SequenceManager\u00a0- versions prior to 2.0<\/li>\n\t<li>Rockwell Automation ThinManager\u00a0- multiple versions<\/li>\n\t<li>Siemens AI Model Deployer\u00a0- versions prior to V1.1<\/li>\n\t<li>Siemens Automation License Manager V5\u00a0\u2013 All versions<\/li>\n\t<li>Siemens Automation License Manager V6.0\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Automation License Manager V6.2\u00a0- versions prior to V6.2 Upd3<\/li>\n\t<li>Siemens Data Flow Monitoring Industrial Edge Device User Interface (DFM IED UI)\u00a0- versions prior to V0.0.6<\/li>\n\t<li>Siemens Industrial Edge Management OS (IEM-OS)\u00a0- all versions<\/li>\n\t<li>Siemens Industrial Edge Management Pro\u00a0- versions prior to V1.9.5<\/li>\n\t<li>Siemens Industrial Edge Management Virtual\u00a0- versions prior to V2.3.1-1<\/li>\n\t<li>Siemens LiveTwin Industrial Edge app (6AV2170-0BL00-0AA0)\u00a0- versions prior to V2.4<\/li>\n\t<li>Siemens Mendix Runtime V8\u00a0- multiple versions<\/li>\n\t<li>Siemens Mendix Runtime V9\u00a0- multiple versions<\/li>\n\t<li>Siemens Mendix Runtime V10\u00a0- multiple versions<\/li>\n\t<li>Siemens Mendix Runtime V10.6\u00a0- multiple versions<\/li>\n\t<li>Siemens Mendix Runtime V10.12\u00a0- multiple versions<\/li>\n\t<li>Siemens Plant Simulation V2302\u00a0- versions prior to V2302.0015<\/li>\n\t<li>Siemens Plant Simulation V2404\u00a0- versions prior to V2404.0004<\/li>\n\t<li>Siemens SCALANCE W700\u00a0\u2013 multiple products and versions<\/li>\n\t<li>Siemens SICAM A8000 Device Firmware ETI5 Ethernet Int. 1x100TX IEC61850\u00a0- versions prior to V05.30<\/li>\n\t<li>Siemens SICAM EGS Device Firmware ETI5\u00a0- versions prior to V05.30<\/li>\n\t<li>Siemens SICAM 8 Software Solution ETI5\u00a0- versions prior to V05.30<\/li>\n\t<li>Siemens SICAM SCC\u00a0- versions prior to V10.0<\/li>\n\t<li>Siemens SIMATIC BATCH V9.1\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC CP 1242-7 V2 (incl. SIPLUS variants)\u00a0- versions prior to V3.5.20<\/li>\n\t<li>Siemens SIMATIC CP 1243-1 (incl. SIPLUS variants)\u00a0- versions prior to V3.5.20<\/li>\n\t<li>Siemens SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants)\u00a0- versions prior to V3.5.20<\/li>\n\t<li>Siemens SIMATIC CP 1243-1 IEC (incl. SIPLUS variants)\u00a0- versions prior to V3.5.20<\/li>\n\t<li>Siemens SIMATIC CP 1243-7 LTE\u00a0- versions prior to V3.5.20<\/li>\n\t<li>Siemens SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0)\u00a0- versions prior to V3.5.20<\/li>\n\t<li>Siemens SIMATIC HMI Comfort Panels (incl. SIPLUS variants)\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC IPC DiagBase\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC IPC DiagMonitor\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC Information Server 2020\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC Information Server 2022\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC Information Server 2024\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC PCS 7 V9.1\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC PCS neo V4.0\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC PCS neo V4.1\u00a0- versions prior to V4.1 Update 2<\/li>\n\t<li>Siemens SIMATIC PCS neo V5.0\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC Process Historian 2020\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC Process Historian 2022\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC RFID Readers\u00a0- multiple products and versions<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Professional V17\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Professional V18\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Professional V19\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Professional V20\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC WinCC V7.4\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC WinCC V7.5\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC WinCC V8.0\u00a0- all versions<\/li>\n\t<li>Siemens SIMATIC WinCC Runtime Advanced\u00a0- all versions<\/li>\n\t<li>Siemens SINEC NMS\u00a0- all versions<\/li>\n\t<li>Siemens SINEMA Remote Connect Client\u00a0- versions prior to V3.2 SP2<\/li>\n\t<li>Siemens SINEMA Remote Connect Server\u00a0- versions prior to V3.2 SP2<\/li>\n\t<li>Siemens SINUMERIK 828D V4\u00a0- multiple versions<\/li>\n\t<li>Siemens SINUMERIK 828D V5\u00a0- versions prior to V5.24<\/li>\n\t<li>Siemens SINUMERIK 840D sl V4\u00a0- multiple versions<\/li>\n\t<li>Siemens SINUMERIK ONE\u00a0- multiple versions<\/li>\n\t<li>Siemens SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)\u00a0- versions prior to V2.4.8<\/li>\n\t<li>Siemens SITIPE AT\u00a0- all versions<\/li>\n\t<li>Siemens TIA Administrator\u00a0- versions prior to V3.0 SP3<\/li>\n\t<li>Siemens TIM 1531 IRC (6GK7543-1MX00-0XE0)\u00a0- versions prior to V2.4.8<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V16\u00a0- all versions<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V17\u00a0- versions prior to V17 Update 8<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V18\u00a0- all versions<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V19\u00a0- all versions<\/li>\n\t<li>Viessmann Climate Solutions SE Viessmann Vitogate 300\u00a0- version 2.1.3.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-523","alert_type":398,"serial_number":"AV24-523","subject":"ics","moderation_state":"published","external_url":null},{"nid":5647,"title":"Dell security advisory (AV24-524)","uuid":"bbea5cb7-19b4-4e40-9d4c-2acf69e70026","banner":null,"lang":"en","date_modified":"2024-09-16","date_modified_ts":"2024-09-16T18:54:48Z","date_created":"2024-09-16T18:48:45Z","summary":null,"body":["<article data-history-node-id=\"5647\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-524\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-524<br \/><strong>Date: <\/strong>September\u00a016, 2024<\/p>\n\n<p>Between September\u00a09 and 15, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cyber Sense\u00a0\u2013 versions prior to 1.5.0-47<\/li>\n\t<li>Dell Avamar Data Store Switch S4128F\u00a0\u2013 version 10.5.4.1<\/li>\n\t<li>Dell Data Protection Central DPC-OSupdate\u00a0\u2013 versions prior to 1.1.19-1<\/li>\n\t<li>PowerProtect DP Series (Integrated Data Protection Appliance) DPC-OSupdate\u00a0\u2013 versions prior to 1.1.19-1<\/li>\n\t<li>PowerScale InsightIQ\u00a0\u2013 versions 5.0 to 5.1<\/li>\n\t<li>ThinOS\u00a0\u2013 cisco_jabber_14.3.0.308378.11 and liquidware_stratusphere_ux_connector_id_agent_6.7.0.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-524","alert_type":396,"serial_number":"AV24-524","subject":"dell","moderation_state":"published","external_url":null},{"nid":5649,"title":"Apple security advisory (AV24-525)","uuid":"243ff79c-a7b1-4b76-9b62-17248ba7d55a","banner":null,"lang":"en","date_modified":"2024-09-17","date_modified_ts":"2024-09-17T13:46:12Z","date_created":"2024-09-17T13:19:32Z","summary":null,"body":["<article data-history-node-id=\"5649\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-525\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-525<br \/><strong>Date: <\/strong>September 17, 2024<\/p>\n\n<p>On September\u00a016,\u00a02024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 17.7<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 18<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 version prior to 15<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.7<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.7<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 18<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 2<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-525","alert_type":396,"serial_number":"AV24-525","subject":"apple","moderation_state":"published","external_url":null},{"nid":5650,"title":"HPE security advisory (AV24-526)","uuid":"043f6e3f-9f58-41ee-9f6b-d0f20c5b43ad","banner":null,"lang":"en","date_modified":"2024-09-17","date_modified_ts":"2024-09-17T15:19:47Z","date_created":"2024-09-17T14:40:55Z","summary":null,"body":["<article data-history-node-id=\"5650\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-526\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-526<br \/><strong>Date: <\/strong>September 17, 2024<\/p>\n\n<p>On September\u00a016,\u00a02024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant DL110 Gen10 Plus Telco server\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE ProLiant DL360 Gen10 Plus server\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE ProLiant DL380 Gen10 Plus server\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE Synergy 480 Gen10 Plus Compute Module\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE Apollo 4200 Gen10 Plus System\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE ProLiant XL190r Gen9 Server\u00a0\u2013 versions prior to v3.32_08-29-2024<\/li>\n\t<li>HPE ProLiant XL170r Gen9 Server\u00a0\u2013 versions prior to v3.32_08-29-2024<\/li>\n\t<li>HPE ProLiant DL60 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL80 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL120 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL160 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL180 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL360 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL380 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL560 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant DL580 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant ML110 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant ML150 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE ProLiant ML350 Gen9 Server\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE Synergy 480 Gen9 Compute Module\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE Synergy 620 Gen9 Compute Module\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE Synergy 660 Gen9 Compute Module\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE Synergy 680 Gen9 Compute Module\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE Edgeline e920 Server Blade\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE Edgeline e920d Server Blade\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE Edgeline e920t Server Blade\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04699en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04699en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-526","alert_type":396,"serial_number":"AV24-526","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5653,"title":"Atlassian security advisory (AV24-527)","uuid":"c4c55b15-7601-4023-8734-558bb3edc011","banner":null,"lang":"en","date_modified":"2024-09-18","date_modified_ts":"2024-09-18T14:04:09Z","date_created":"2024-09-18T13:41:50Z","summary":null,"body":["<article data-history-node-id=\"5653\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-527\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-527<br \/><strong>Date: <\/strong>September 18, 2024<\/p>\n\n<p>On September\u00a017, 2024, Atlassian published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-september-17-2024-1431249025.html\">Atlassian Security Bulletin\u00a0- September\u00a017\u00a02024<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-527","alert_type":396,"serial_number":"AV24-527","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5654,"title":"VMware security advisory (AV24-528) \u2013 Update 1","uuid":"536b1ac5-50e9-4ddf-a83f-341e40672766","banner":null,"lang":"en","date_modified":"2024-10-22","date_modified_ts":"2024-10-22T19:07:29Z","date_created":"2024-09-18T15:06:28Z","summary":null,"body":["<article data-history-node-id=\"5654\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-528\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-528<br \/><strong>Date: <\/strong>September\u00a018, 2024<\/p>\n\n<p><strong>Updated:<\/strong> October\u00a022, 2024<\/p>\n\n<p>On September\u00a017,\u00a02024, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>vCenter Server\u00a0\u2013 versions 7.0 and 8.0<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 versions 5.x and 4.x<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On October\u00a021, 2024, VMware released updated vCenter patches to resolve issues in CVE-2024-38812 that were not fully addressed by the September\u00a017, 2024 release. Clients who installed the initial releases are advised to install these updated versions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24968\">VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-528","alert_type":396,"serial_number":"AV24-528","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5655,"title":"GitLab security advisory (AV24-529)","uuid":"35cbd221-8885-404d-8a75-66c51c64321d","banner":null,"lang":"en","date_modified":"2024-09-18","date_modified_ts":"2024-09-18T15:41:59Z","date_created":"2024-09-18T15:28:55Z","summary":null,"body":["<article data-history-node-id=\"5655\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-529\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-529<br \/><strong>Date: <\/strong>September 18, 2024<\/p>\n\n<p>On September\u00a017,\u00a02024, GitLab published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.3.3, 17.2.7, 17.1.8, 17.0.8 and 16.11.10<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.3.3, 17.2.7, 17.1.8, 17.0.8 and 16.11.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/09\/17\/patch-release-gitlab-17-3-3-released\/\">GitLab Critical Patch Release: 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10 <\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-529","alert_type":396,"serial_number":"AV24-529","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5656,"title":"Google Chrome security advisory (AV24-530)","uuid":"0fe40248-f1f3-488b-83c3-4badc85657a1","banner":null,"lang":"en","date_modified":"2024-09-18","date_modified_ts":"2024-09-18T16:04:59Z","date_created":"2024-09-18T15:50:13Z","summary":null,"body":["<article data-history-node-id=\"5656\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-530\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-530<br \/><strong>Date: <\/strong>September 18, 2024<\/p>\n\n<p>On September\u00a017,\u00a02024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 129.0.6668.58\/.59 (Windows and Mac) and 129.0.6668.58 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/09\/stable-channel-update-for-desktop_17.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-530","alert_type":396,"serial_number":"AV24-530","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5657,"title":"HPE security advisory (AV24-531)","uuid":"1c7082a6-4cfd-4f4e-8d50-2a579c8b2d97","banner":null,"lang":"en","date_modified":"2024-09-18","date_modified_ts":"2024-09-18T19:27:27Z","date_created":"2024-09-18T19:04:36Z","summary":null,"body":["<article data-history-node-id=\"5657\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-531\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-531<br \/><strong>Date: <\/strong>September\u00a018, 2024<\/p>\n\n<p>Between September\u00a017 and 18, 2024, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking AOS\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Aruba Networking SD-WAN\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE StoreEasy 1660 Storage\u00a0\u2013 versions prior to v2.20_08-07-2024 or prior to v3.30_07-31-2024<\/li>\n\t<li>HPE StoreEasy 1860 Storage\u00a0\u2013 versions prior to v2.20_08-07-2024 or prior to v3.30_07-31-2024<\/li>\n\t<li>HPE StoreEasy 1670 Expanded Storage\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE StoreEasy 1860 Expanded Storage\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE StoreEasy 1870 Expanded Storage\u00a0\u2013 versions prior to v2.20_08-07-2024<\/li>\n\t<li>HPE StoreEasy 1460 Storage\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE StoreEasy 1560 Storage\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE StoreEasy 1660 Expanded Storage\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE StoreEasy 1660 Performance Storage\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE StoreEasy 1860 Performance Storage\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE Storage File Controller\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE Storage Performance File Controller\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE StoreEasy 1450 Storage\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE StoreEasy 1550 Storage\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE StoreEasy 1650 Storage\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE StoreEasy 1850 Storage\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE StoreEasy 1650 Expanded Storage\u00a0\u2013 versions prior to v3.40_08-29-2024<\/li>\n\t<li>HPE StoreEasy 3850 Gateway Storage\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n\t<li>HPE 3PAR StoreServ File Controller v3 System\u00a0\u2013 versions prior to v3.30_07-31-2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04704en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04704en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04709en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbnw04709en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-531","alert_type":396,"serial_number":"AV24-531","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5658,"title":"Drupal security advisory (AV24-532)","uuid":"7758e405-a45f-4432-8638-19d1a1288c29","banner":null,"lang":"en","date_modified":"2024-09-18","date_modified_ts":"2024-09-18T19:38:10Z","date_created":"2024-09-18T19:04:37Z","summary":null,"body":["<article data-history-node-id=\"5658\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-532\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-532<br \/><strong>Date: <\/strong>September\u00a018, 2024<\/p>\n\n<p>On September\u00a018, 2024, Drupal published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Smart IP Ban\u00a0\u2013 versions prior to 7.x-1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-041\">Smart IP Ban\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2024-041<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-532","alert_type":396,"serial_number":"AV24-532","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5660,"title":"Microsoft Edge security advisory (AV24-533)","uuid":"eb57b39a-3129-4eb0-b968-06d09ce4fa65","banner":null,"lang":"en","date_modified":"2024-09-20","date_modified_ts":"2024-09-20T13:39:36Z","date_created":"2024-09-20T13:23:53Z","summary":null,"body":["<article data-history-node-id=\"5660\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-533\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-533<br \/><strong>Date: <\/strong>September 20, 2024<\/p>\n\n<p>On September\u00a019,\u00a02024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 129.0.2792.52<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 128.0.2739.90<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-533","alert_type":396,"serial_number":"AV24-533","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5661,"title":"Dell security advisory (AV24-534)","uuid":"594f6848-413b-406c-a9a6-84edfd96b197","banner":null,"lang":"en","date_modified":"2024-09-23","date_modified_ts":"2024-09-23T18:30:04Z","date_created":"2024-09-23T17:56:08Z","summary":null,"body":["<article data-history-node-id=\"5661\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-534\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-534<br \/><strong>Date: <\/strong>September\u00a023, 2024<\/p>\n\n<p>Between September\u00a016 and 22, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>PowerPath Managment Appliance\u00a0\u2013 versions prior to 3.4 sp2 p02 and versions prior to 4.0 p02<\/li>\n\t<li>Dell PowerStore\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-534","alert_type":396,"serial_number":"AV24-534","subject":"dell","moderation_state":"published","external_url":null},{"nid":5663,"title":"Ubuntu security advisory (AV24-536)","uuid":"4214acda-d9d7-4db6-b62d-4a2d8501949f","banner":null,"lang":"en","date_modified":"2024-09-23","date_modified_ts":"2024-09-23T18:53:16Z","date_created":"2024-09-23T17:56:09Z","summary":null,"body":["<article data-history-node-id=\"5663\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-536\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-536<br \/><strong>Date: <\/strong>September\u00a023, 2024<\/p>\n\n<p>Between September\u00a016 and 22, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-536","alert_type":396,"serial_number":"AV24-536","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5662,"title":"Red Hat security advisory (AV24-535)","uuid":"56beb4d8-f411-46d7-871d-b21aa12049c7","banner":null,"lang":"en","date_modified":"2024-09-23","date_modified_ts":"2024-09-23T18:44:01Z","date_created":"2024-09-23T17:56:09Z","summary":null,"body":["<article data-history-node-id=\"5662\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-535\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-535<br \/><strong>Date: <\/strong>September\u00a023, 2024<\/p>\n\n<p>Between September\u00a016 and 22, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-535","alert_type":396,"serial_number":"AV24-535","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5664,"title":"[Control systems] CISA ICS security advisories (AV24-537) ","uuid":"93ec43bf-2166-46f7-b777-efe38f51d81f","banner":null,"lang":"en","date_modified":"2024-09-23","date_modified_ts":"2024-09-23T20:37:06Z","date_created":"2024-09-23T20:17:26Z","summary":null,"body":["<article data-history-node-id=\"5664\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-537\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-537<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 23, 2024<\/p>\n\n<p>Between September 16 and 22, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Kastle Systems Access Control System\u00a0\u2013 firmware prior to May 1, 2024<\/li>\n\t<li>IDEC FC6A Series MICROSmart All-in-One CPU module\u00a0\u2013 version 2.60 and prior<\/li>\n\t<li>IDEC FC6B Series MICROSmart All-in-One CPU module\u00a0\u2013 version 2.60 and prior<\/li>\n\t<li>IDEC FC6A Series MICROSmart Plus CPU module\u00a0\u2013 version 2.40 and prior<\/li>\n\t<li>IDEC FC6B Series MICROSmart Plus CPU module\u00a0\u2013 version 2.60 and prior<\/li>\n\t<li>IDEC FT1A Series SmartAXIS Pro\/Lite\u00a0\u2013 version 2.41 and prior<\/li>\n\t<li>IDEC WindLDR\u00a0\u2013 version 9.1.0 and prior<\/li>\n\t<li>IDEC WindO\/I-NV4\u00a0\u2013 version 3.0.1 and prior<\/li>\n\t<li>MegaSys Computer Tech Telenium Online Web Application\u00a0\u2013 version 8.3 and prior<\/li>\n\t<li>Millbeck Communications Proroute H685t-w\u00a0\u2013 version 3.2.334<\/li>\n\t<li>Rockwell Automation RSLogix 500\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation RSLogix Micro Developer and starter\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation RSLogix 5\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC S7-200 SMART CPU\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Yokogawa Dual-redundant Platform for Computer (PC2CKM)\u00a0\u2013 versions R1.01.00 to R2.03.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-537","alert_type":398,"serial_number":"AV24-537","subject":"ics","moderation_state":"published","external_url":null},{"nid":5665,"title":"IBM security advisory (AV24-538)","uuid":"bcc53484-72ba-4b1b-9a94-2d269f011b2c","banner":null,"lang":"en","date_modified":"2024-09-23","date_modified_ts":"2024-09-23T20:48:13Z","date_created":"2024-09-23T20:41:03Z","summary":null,"body":["<article data-history-node-id=\"5665\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-538\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-538<br \/><strong>Date: <\/strong>September\u00a023, 2024<\/p>\n\n<p>Between September\u00a016 and 22, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM watsonx.data\u00a0\u2013 versions 1.0.0 to 1.1.3, 1.0.0 to 1.1.4, 1.0.0 to 2.0.0, 1.1.0, 1.1.0 to 1.1.4, 1.1.3 and 2.0.0<\/li>\n\t<li>Watsonx.data\u00a0\u2013 versions 1.0.0 to 2.0.0, 1.0.0 to 2.0.1 and 1.1.0 to 2.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-538","alert_type":396,"serial_number":"AV24-538","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5667,"title":"Google Chrome security advisory (AV24-539)","uuid":"a9c248e5-0214-4a15-b4dd-4ad4ef51c846","banner":null,"lang":"en","date_modified":"2024-09-24","date_modified_ts":"2024-09-24T20:26:49Z","date_created":"2024-09-24T20:09:02Z","summary":null,"body":["<article data-history-node-id=\"5667\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-539\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-539<br \/><strong>Date: <\/strong>September\u00a024, 2024<\/p>\n\n<p>On September\u00a024, 2024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 129.0.6668.70\/.71 (Windows and Mac) and 129.0.6668.70 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/09\/stable-channel-update-for-desktop_24.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-539","alert_type":396,"serial_number":"AV24-539","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5668,"title":"Cisco security advisory (AV24-540)","uuid":"9f76412f-a1b8-419e-a7b1-f4e8126a4f84","banner":null,"lang":"en","date_modified":"2024-09-25","date_modified_ts":"2024-09-25T20:22:05Z","date_created":"2024-09-25T20:16:07Z","summary":null,"body":["<article data-history-node-id=\"5668\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-540\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-540<br \/><strong>Date: <\/strong>September\u00a025, 2024<\/p>\n\n<p>On September\u00a025, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco 1000 Series Integrated Services Routers (ISRs)<\/li>\n\t<li>Cisco ASR 1000 Series Aggregation Service Routers<\/li>\n\t<li>Cisco Catalyst 8000v Edge Software<\/li>\n\t<li>Cisco Catalyst 8200 Series Edge Platforms<\/li>\n\t<li>Cisco Catalyst 8300 Series Edge Platforms<\/li>\n\t<li>Cisco Catalyst 8500L Edge Platforms<\/li>\n\t<li>Cisco Catalyst IR8300 Rugged Series Routers<\/li>\n\t<li>Cisco Catalyst Center<\/li>\n\t<li>Cisco cBR-8 Converged Broadband Routers<\/li>\n\t<li>Cisco Crosswork NSO<\/li>\n\t<li>Cisco IOS XE Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco IOS Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Optical Site Manager<\/li>\n\t<li>Cisco RV340 Dual WAN Gigabit VPN Routers<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-540","alert_type":396,"serial_number":"AV24-540","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5669,"title":"HPE security advisory (AV24-541)","uuid":"c504a047-6f02-4b15-bb79-591290685111","banner":null,"lang":"en","date_modified":"2024-09-25","date_modified_ts":"2024-09-25T20:58:46Z","date_created":"2024-09-25T20:16:08Z","summary":null,"body":["<article data-history-node-id=\"5669\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-541\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-541<br \/><strong>Date: <\/strong>September\u00a025, 2024<\/p>\n\n<p>On September\u00a024, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking Access Points running Instant AOS-8 and AOS-10\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04712en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbnw04712en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-541","alert_type":396,"serial_number":"AV24-541","subject":"other","moderation_state":"published","external_url":null},{"nid":5670,"title":"Foxit security advisory (AV24-542)","uuid":"78c8fef9-8229-4e95-a53e-8d816aabcb49","banner":null,"lang":"en","date_modified":"2024-09-26","date_modified_ts":"2024-09-26T17:47:22Z","date_created":"2024-09-26T17:18:30Z","summary":null,"body":["<article data-history-node-id=\"5670\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av24-542\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-542<br \/><strong>Date: <\/strong>September\u00a026, 2024<\/p>\n\n<p>On September\u00a026, 2024, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor for Windows\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader for Windows\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader for Mac\u00a0\u2013 version 2024.2.2.64388 and prior<\/li>\n\t<li>Foxit PDF Editor for Mac\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av24-542","alert_type":396,"serial_number":"AV24-542","subject":"other","moderation_state":"published","external_url":null},{"nid":5671,"title":"GitLab security advisory (AV24-543)","uuid":"03d2cefd-1dc2-4649-b318-93060fe76377","banner":null,"lang":"en","date_modified":"2024-09-26","date_modified_ts":"2024-09-26T18:02:38Z","date_created":"2024-09-26T17:18:31Z","summary":null,"body":["<article data-history-node-id=\"5671\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-543\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-543<br \/><strong>Date: <\/strong>September\u00a026, 2024<\/p>\n\n<p>On September\u00a025, 2024, GitLab published security advisories to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 4.1, 17.3.4, 17.2.8, 16.10.10, 16.9.11, 16.8.10, 16.7.10, 16.6.10, 16.5.10, 16.4.7, 16.3.9, 16.2.11, 16.1.8 and 16.0.10<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.4.1, 17.3.4, 17.2.8, 16.10.10, 16.9.11, 16.8.10, 16.7.10, 16.6.10, 16.5.10, 16.4.7, 16.3.9, 16.2.11, 16.1.8 and 16.0.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/09\/25\/patch-release-gitlab-16-10-10-released\/\">GitLab Critical Patch Release: 16.10.10, 16.9.11, 16.8.10, 16.7.10, 16.6.10, 16.5.10, 16.4.7, 16.3.9, 16.2.11, 16.1.8, 16.0.10<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/09\/25\/patch-release-gitlab-17-4-1-released\/\">GitLab Patch Release: 17.4.1, 17.3.4, 17.2.8<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-543","alert_type":396,"serial_number":"AV24-543","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5675,"title":"HPE security advisory (AV24-544)","uuid":"9b8fb3b5-9659-4bd2-a12a-06967a4ad931","banner":null,"lang":"en","date_modified":"2024-09-27","date_modified_ts":"2024-09-27T18:12:32Z","date_created":"2024-09-27T17:50:16Z","summary":null,"body":["<article data-history-node-id=\"5675\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-544\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-544\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 27, 2024\n<\/p>\n<p>On September 27, 2024, HPE published a security advisory to address vulnerabilities in the following products:\n<\/p>\n<ul><li>HPE Superdome Flex 280 Server\u00a0\u2013 versions prior to v1.90.12<\/li>\n  <li>HPE Superdome Flex Server\u00a0\u2013 versions prior to v4.0.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04703en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04703en_us<\/a><\/li>\n  <li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-544","alert_type":396,"serial_number":"AV24-544","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5676,"title":"Microsoft Edge security advisory (AV24-545)","uuid":"ba86a4b7-0524-46c5-ac17-1c90346061c7","banner":null,"lang":"en","date_modified":"2024-09-27","date_modified_ts":"2024-09-27T20:14:24Z","date_created":"2024-09-27T20:07:07Z","summary":null,"body":["<article data-history-node-id=\"5676\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-545\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-545<br \/><strong>Date: <\/strong>September\u00a027, 2024<\/p>\n\n<p>On September\u00a027, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 129.0.2792.65<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 128.0.2739.97<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-545","alert_type":396,"serial_number":"AV24-545","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5539,"title":"Google Chrome security advisory (AV24-487)","uuid":"b46378cc-b825-4d45-aef8-639ca214d26e","banner":null,"lang":"en","date_modified":"2024-08-28","date_modified_ts":"2024-08-28T19:56:31Z","date_created":"2024-09-27T20:15:14Z","summary":null,"body":["<article data-history-node-id=\"5539\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-487\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-487<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 28, 2024<\/p>\n\n<p>On August 28, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 128.0.6613.113\/.114 (Windows and Mac) and 128.0.6613.113 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/08\/stable-channel-update-for-desktop_28.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-487","alert_type":396,"serial_number":"AV24-487","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5682,"title":"Dell security advisory (AV24-546)","uuid":"9da0f38e-486f-4140-bda5-4757a0f46ab7","banner":null,"lang":"en","date_modified":"2024-10-01","date_modified_ts":"2024-10-01T15:50:53Z","date_created":"2024-10-01T15:37:08Z","summary":null,"body":["<article data-history-node-id=\"5682\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-546\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-546<br \/><strong>Date: <\/strong>October 1, 2024<\/p>\n\n<p>Between September\u00a023\u00a0and\u00a029,\u00a02024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 4.16.9<\/li>\n\t<li>APEX Cloud Platform Foundation Software\u00a0\u2013 versions prior to 03.02.00.00<\/li>\n\t<li>Connectrix\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell EMC VxRail Appliance\u00a0\u2013 7.0.x versions prior to 7.0.531<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 10.5.3.x, 10.5.4.x, 10.5.5.x and 10.5.6.x<\/li>\n\t<li>Dell PowerMax\u00a0\u2013 multiple versions and models<\/li>\n\t<li>PowerMaxOS\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Unisphere\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-546","alert_type":396,"serial_number":"AV24-546","subject":"dell","moderation_state":"published","external_url":null},{"nid":5683,"title":"IBM security advisory (AV24-547)","uuid":"78b4add3-9371-41fc-92e5-6dbdcc2c8c5d","banner":null,"lang":"en","date_modified":"2024-10-01","date_modified_ts":"2024-10-01T16:07:44Z","date_created":"2024-10-01T16:00:10Z","summary":null,"body":["<article data-history-node-id=\"5683\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-547\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-547<br \/><strong>Date: <\/strong>October 1, 2024<\/p>\n\n<p>Between September\u00a023\u00a0and\u00a029,\u00a02024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.0 to 4.8.5, 5.0.0 and 5.0.1<\/li>\n\t<li>IBM CP4MCM\u00a0\u2013 version 2.3 to 2.3 FP8<\/li>\n\t<li>IBM Storage Protect Plus\u00a0\u2013 versions 10.1.0 to 10.1.16.2<\/li>\n\t<li>IBM watsonx.data\u00a0\u2013 versions 1.0.0 to 2.0.0<\/li>\n\t<li>IBM watsonx.data\u00a0\u2013 versions 1.1.0 to 2.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-547","alert_type":396,"serial_number":"AV24-547","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5684,"title":"Ubuntu security advisory (AV24-548)","uuid":"341e4aeb-cb23-487b-a5d1-649e9f8f7475","banner":null,"lang":"en","date_modified":"2024-10-01","date_modified_ts":"2024-10-01T16:26:17Z","date_created":"2024-10-01T16:18:54Z","summary":null,"body":["<article data-history-node-id=\"5684\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-548\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-548<br \/><strong>Date: <\/strong>October 1, 2024<\/p>\n\n<p>Between September\u00a023\u00a0and\u00a029,\u00a02024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-548","alert_type":396,"serial_number":"AV24-548","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5686,"title":"[Control systems] CISA ICS security advisories (AV24-549)","uuid":"22019dcf-26fd-4f95-8b73-c1da5892ee8b","banner":null,"lang":"en","date_modified":"2024-10-01","date_modified_ts":"2024-10-01T19:43:51Z","date_created":"2024-10-01T19:31:58Z","summary":null,"body":["<article data-history-node-id=\"5686\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-549\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-549<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 1, 2024<\/p>\n\n<p>Between September 23 and 29, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Advantech ADAM 5550\u00a0\u2013 all versions<\/li>\n\t<li>Advantech ADAM-5630\u00a0\u2013 versions prior to v2.5.2<\/li>\n\t<li>Alisonic Sibylla\u00a0\u2013 all versions<\/li>\n\t<li>Atemio AM520 HD\u00a0\u2013 TitanNit version 2.01 and prior<\/li>\n\t<li>Dover Fueling Systems ProGauge MAGLINK LX CONSOLE\u00a0\u2013 version 3.4.2.2.6 and prior<\/li>\n\t<li>Dover Fueling Systems ProGauge MAGLINK LX4 CONSOLE\u00a0\u2013 version 4.17.9e and prior<\/li>\n\t<li>Franklin Fueling Systems TS-550 EVO\u00a0\u2013 versions prior to 2.26.4.8967<\/li>\n\t<li>goTenna Pro App\u00a0\u2013 version 1.6.1 and prior<\/li>\n\t<li>goTenna PRO ATAK Plugin\u00a0\u2013 version 1.9.12 and prior<\/li>\n\t<li>Moxa MXview One Central Manager Series\u00a0\u2013 version 1.0.0<\/li>\n\t<li>Moxa MXview One Series\u00a0\u2013 version 1.4.0 and prior<\/li>\n\t<li>OMNTEC Proteus Tank Monitoring\u00a0\u2013 OEL8000III series<\/li>\n\t<li>OPW Fuel Managements Systems SiteSentinel\u00a0\u2013 version prior to 17Q2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-549","alert_type":398,"serial_number":"AV24-549","subject":"ics","moderation_state":"published","external_url":null},{"nid":5687,"title":"Red Hat security advisory (AV24-550)","uuid":"0c6603d5-d6fa-4dfa-ae7a-d8420cc9f0e1","banner":null,"lang":"en","date_modified":"2024-10-01","date_modified_ts":"2024-10-01T19:54:48Z","date_created":"2024-10-01T19:47:00Z","summary":null,"body":["<article data-history-node-id=\"5687\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-550\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-550<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 1, 2024<\/p>\n\n<p>Between September 23 and 29, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-550","alert_type":396,"serial_number":"AV24-550","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5688,"title":"OpenPrinting CUPS security advisory (AV24-551)","uuid":"79c19208-e47b-4d44-b2e0-1c41cd964570","banner":null,"lang":"en","date_modified":"2024-10-01","date_modified_ts":"2024-10-01T20:28:38Z","date_created":"2024-10-01T19:58:05Z","summary":null,"body":["<article data-history-node-id=\"5688\" about=\"\/en\/alerts-advisories\/openprinting-cups-security-advisory-av24-551\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-551<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 1, 2024<\/p>\n\n<p>On September 26, 2024, OpenPrinting published security updates to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Common UNIX Printing Systems (CUPS)\u00a0\u2013 version 2.1b1 and prior, version 2.0.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/OpenPrinting\/cups-browsed\/security\/advisories\/GHSA-rj88-6mr5-rcw8\">Multiple bugs leading to info leak and remote code execution<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/OpenPrinting\/cups-filters\/security\/advisories\/GHSA-p9rh-jxmq-gq47\">Command injection via FoomaticRIPCommandLine<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/OpenPrinting\/libppd\/security\/advisories\/GHSA-7xfx-47qg-grp6\">ppdCreatePPDFromIPP2 does not sanitize IPP attributes when creating the PPD buffer<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/OpenPrinting\/libcupsfilters\/security\/advisories\/GHSA-w63j-6g73-wmg5\/\">cfGetPrinterAttributes5 does not validate IPP attributes returned from an IPP server<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/RHSB-2024-002\">RHSB-2024-002\u00a0- OpenPrinting cups-filters<\/a><\/li>\n\t<li><a href=\"https:\/\/www.redhat.com\/en\/blog\/red-hat-response-openprinting-cups-vulnerabilities\">Red Hat\u2019s response to OpenPrinting CUPS vulnerabilities: CVE-2024-47076, CVE-2024-47175, CVE-2024-47176 and CVE-2024-47177<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/blog\/cups-remote-code-execution-vulnerability-fix-available\">CUPS Remote Code Execution Vulnerability Fix Available<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openprinting-cups-security-advisory-av24-551","alert_type":396,"serial_number":"AV24-551","subject":"other","moderation_state":"published","external_url":null},{"nid":5689,"title":"Mozilla security advisory (AV24-552)","uuid":"ac97138a-ac21-4107-a497-f6f677e21b6a","banner":null,"lang":"en","date_modified":"2024-10-02","date_modified_ts":"2024-10-02T16:00:29Z","date_created":"2024-10-02T15:46:39Z","summary":null,"body":["<article data-history-node-id=\"5689\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-552\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-552<br \/><strong>Date: <\/strong>October 2, 2024<\/p>\n\n<p>On October\u00a01,\u00a02024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 131<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 128.3<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.16<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.3<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 131<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-50\/\">Mozilla Security Advisory (MFSA 2024-50)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-49\/\">Mozilla Security Advisory (MFSA 2024-49)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-48\/\">Mozilla Security Advisory (MFSA 2024-48)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-47\/\">Mozilla Security Advisory (MFSA 2024-47)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-46\/\">Mozilla Security Advisory (MFSA 2024-46)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-552","alert_type":396,"serial_number":"AV24-552","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5690,"title":"Google Chrome security advisory (AV24-553)","uuid":"dfc47cba-b88e-49c1-8eda-51388918a485","banner":null,"lang":"en","date_modified":"2024-10-02","date_modified_ts":"2024-10-02T16:11:52Z","date_created":"2024-10-02T16:04:57Z","summary":null,"body":["<article data-history-node-id=\"5690\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-553\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-553<br \/><strong>Date: <\/strong>October 2, 2024<\/p>\n\n<p>On October\u00a01,\u00a02024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 129.0.6668.89\/.90 (Windows and Mac) and 129.0.6668.89 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/10\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-553","alert_type":396,"serial_number":"AV24-553","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5691,"title":"Juniper Networks security advisory (AV24-554)","uuid":"9c49e373-61ee-449e-a086-7db219614822","banner":null,"lang":"en","date_modified":"2024-10-02","date_modified_ts":"2024-10-02T16:24:53Z","date_created":"2024-10-02T16:14:32Z","summary":null,"body":["<article data-history-node-id=\"5691\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-554\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-554<br \/><strong>Date: <\/strong>October 2, 2024<\/p>\n\n<p>On September\u00a030,\u00a02024, Juniper Networks published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Junos OS\u00a0\u2013 multiple versions<\/li>\n\t<li>Juno OS Evolved\u00a0\u2013 multiple versions<\/li>\n\t<li>Junos OS on cRPD\u00a0\u2013 versions 23.4 to versions prior to 23.4R3-S5, versions 24.2 to versions prior to 24.2R2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2024-09-30-Out-of-Cycle-Security-Advisory-Multiple-Products-RADIUS-protocol-susceptible-to-forgery-attacks-Blast-RADIUS-CVE-2024-3596?language=en_US\">Juniper Networks Security Advisories\u00a0\u2013 JSA88210<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy\">Juniper Networks Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/radius-protocol-susceptible-forgery-attacks\">RADIUS protocol susceptible to forgery attacks\u00a0- Update 1<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-554","alert_type":396,"serial_number":"AV24-554","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5692,"title":"HPE security advisory (AV24-555)","uuid":"377b3737-867e-47f5-9db6-3f847afb91b5","banner":null,"lang":"en","date_modified":"2024-10-02","date_modified_ts":"2024-10-02T17:36:50Z","date_created":"2024-10-02T17:14:02Z","summary":null,"body":["<article data-history-node-id=\"5692\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-555\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-555<br \/><strong>Date: <\/strong>October 2, 2024<\/p>\n\n<p>On September\u00a030,\u00a02024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE BackBox Software\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Nonstop QORESTOR Software T1137\u00a0\u2013 version T1137V01 and versions T1137V01^AAA to AAD<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbns04707en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbns04707en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-555","alert_type":396,"serial_number":"AV24-555","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5693,"title":"Jenkins security advisory (AV24-556)","uuid":"6b1ed918-44b0-46b1-bb24-ddc4bb70a9c6","banner":null,"lang":"en","date_modified":"2024-10-02","date_modified_ts":"2024-10-02T20:21:31Z","date_created":"2024-10-02T19:26:21Z","summary":null,"body":["<article data-history-node-id=\"5693\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av24-556\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-556<br \/><strong>Date: <\/strong>October\u00a02, 2024<\/p>\n\n<p>On October\u00a02, 2024, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins weekly\u00a0\u2013 version 2.478 and prior<\/li>\n\t<li>Jenkins LTS\u00a0\u2013 version 2.462.2 and prior<\/li>\n\t<li>Credentials Plugin\u00a0\u2013 version 1380.va_435002fa_924 and prior<\/li>\n\t<li>OpenId Connect Authentication Plugin\u00a0\u2013 version 4.354.v321ce67a_1de8 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2024-10-02\/\">Jenkins Security Advisory 2024-10-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av24-556","alert_type":396,"serial_number":"AV24-556","subject":"other","moderation_state":"published","external_url":null},{"nid":5694,"title":"Cisco security advisory (AV24-557)","uuid":"bdde026e-4c91-492d-8f72-c45df641bc69","banner":null,"lang":"en","date_modified":"2024-10-02","date_modified_ts":"2024-10-02T20:28:37Z","date_created":"2024-10-02T19:26:21Z","summary":null,"body":["<article data-history-node-id=\"5694\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-557\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-557<br \/><strong>Date: <\/strong>October\u00a02, 2024<\/p>\n\n<p>On October\u00a02, 2024, Cisco published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Meraki MX Firmware Release\u00a0\u2013 version 16.2 and later, version 17.0 and later, version 18.0 and later<\/li>\n\t<li>Cisco NDFC\u00a0\u2013 version 12.0<\/li>\n\t<li>Cisco RV340 Dual WAN Gigabit VPN Routers<\/li>\n\t<li>Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Routers<\/li>\n\t<li>Cisco RV345 Dual WAN Gigabit VPN Routers<\/li>\n\t<li>Cisco RV345P Dual WAN Gigabit PoE VPN Routers<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-meraki-mx-vpn-dos-QTRHzG2\">Cisco Security Advisory\u00a0\u2013 cisco-sa-meraki-mx-vpn-dos-QTRHzG2<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ndfc-cmdinj-UvYZrKfr#vp\">Cisco Security Advisory\u00a0\u2013 cisco-sa-ndfc-cmdinj-UvYZrKfr#vp <\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-rv34x-privesc-rce-qE33TCms\">Cisco Security Advisory\u00a0\u2013 cisco-sa-rv34x-privesc-rce-qE33TCms<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ndfc-ptrce-BUSHLbp\">Cisco Security Advisory\u00a0\u2013 cisco-sa-ndfc-ptrce-BUSHLbp<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-557","alert_type":396,"serial_number":"AV24-557","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5695,"title":"Zimbra security advisory (AV24-558)","uuid":"a6562904-6aa8-4848-9033-8c6483e16edc","banner":null,"lang":"en","date_modified":"2024-10-02","date_modified_ts":"2024-10-02T20:32:30Z","date_created":"2024-10-02T19:26:22Z","summary":null,"body":["<article data-history-node-id=\"5695\" about=\"\/en\/alerts-advisories\/zimbra-security-advisory-av24-558\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-558<br \/><strong>Date: <\/strong>October\u00a02, 2024<\/p>\n\n<p>On September\u00a04, 2024, Zimbra published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Zimbra Daffodil\u00a0\u2013 multiple versions<\/li>\n\t<li>Zimbra\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre has received reports that CVE-2024-45519 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.zimbra.com\/2024\/09\/patch-release-multiple-security-issues-related-to-cross-site-scripting-xss-addressed-and-resolved\/\">Patch Release: Multiple security issues related to Cross-Site Scripting (XSS) addressed and resolved<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zimbra-security-advisory-av24-558","alert_type":396,"serial_number":"AV24-558","subject":"other","moderation_state":"published","external_url":null},{"nid":5696,"title":"Drupal security advisory (AV24-559)","uuid":"a1a8b7a4-759c-4713-8936-3fa697d97153","banner":null,"lang":"en","date_modified":"2024-10-03","date_modified_ts":"2024-10-03T17:49:29Z","date_created":"2024-10-03T17:44:16Z","summary":null,"body":["<article data-history-node-id=\"5696\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-559\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-559<br \/><strong>Date: <\/strong>October\u00a03, 2024<\/p>\n\n<p>On October\u00a02, 2024, Drupal published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Two-factor Authentication (TFA) module\u00a0\u2013 versions prior to 1.8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-043\">Two-factor Authentication (TFA)\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2024-043<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-559","alert_type":396,"serial_number":"AV24-559","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5697,"title":"Apple security advisory (AV24-560)","uuid":"7989e4d7-e725-45b2-9f6d-ce65cd5c58e8","banner":null,"lang":"en","date_modified":"2024-10-04","date_modified_ts":"2024-10-04T15:06:54Z","date_created":"2024-10-04T15:03:35Z","summary":null,"body":["<article data-history-node-id=\"5697\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-560\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-560<br \/><strong>Date: <\/strong>October\u00a04, 2024<\/p>\n\n<p>On October\u00a03, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/121373\">About the security content of iOS 18.0.1 and iPadOS 18.0.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-560","alert_type":396,"serial_number":"AV24-560","subject":"apple","moderation_state":"published","external_url":null},{"nid":5698,"title":"Microsoft Edge security advisory (AV24-561)","uuid":"4d474738-bd50-441b-8300-f561ed2a9016","banner":null,"lang":"en","date_modified":"2024-10-04","date_modified_ts":"2024-10-04T15:10:37Z","date_created":"2024-10-04T15:03:36Z","summary":null,"body":["<article data-history-node-id=\"5698\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-561\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-561<br \/><strong>Date: <\/strong>October\u00a04, 2024<\/p>\n\n<p>On October\u00a03, 2024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 129.0.2792.79<\/li>\n\t<li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 128.0.2739.107<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-561","alert_type":396,"serial_number":"AV24-561","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5699,"title":"Dell security advisory (AV24-562)","uuid":"a4c36a23-ad6d-4bd9-a51b-02a8e4730551","banner":null,"lang":"en","date_modified":"2024-10-07","date_modified_ts":"2024-10-07T15:42:18Z","date_created":"2024-10-07T15:30:04Z","summary":null,"body":["<article data-history-node-id=\"5699\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-562\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-562<br \/><strong>Date: <\/strong>October 7, 2024<\/p>\n\n<p>Between September\u00a030 and October\u00a06,\u00a02024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware vCenter Server 7.0\u00a0\u2013 vcenter server versions prior to 7.0u3s<\/li>\n\t<li>VMware vCenter Server 8.0\u00a0\u2013 vcenter server versions prior to 8.0ub<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000232030\/dsa-2024-409-dell-powerstore-family-security-update-for-vmware-vulnerabilities\">DSA-2024-409: Dell PowerStore Family Security Update for VMware Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-562","alert_type":396,"serial_number":"AV24-562","subject":"dell","moderation_state":"published","external_url":null},{"nid":5700,"title":"IBM security advisory (AV24-563)","uuid":"83fa9ef0-ebf2-4772-8362-c7e121e126ea","banner":null,"lang":"en","date_modified":"2024-10-07","date_modified_ts":"2024-10-07T16:10:49Z","date_created":"2024-10-07T15:50:03Z","summary":null,"body":["<article data-history-node-id=\"5700\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-563\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-563<br \/><strong>Date: <\/strong>October 7, 2024<\/p>\n\n<p>Between September\u00a030\u00a0and\u00a0October\u00a06,\u00a02024 IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Business Automation Manager Open Editions\u00a0\u2013 versions 9.0.0, 9.0.1 and 9.1.0<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 versions Build 275 to 279<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.0 to 4.8.4<\/li>\n\t<li>IBM Db2\u00ae on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Db2\u00ae Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7171754\">IBM Security Bulletin (IBM Business Automation Manager Open Editions)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7171713\">IBM Security Bulletin (IBM Observability with Instana (OnPrem))<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7172125\">IBM Security Bulletin (IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7171677\">IBM Security Bulletin (IBM Db2\u00ae on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-563","alert_type":396,"serial_number":"AV24-563","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5701,"title":"Ubuntu security advisory (AV24-564)","uuid":"b520f305-0018-475f-a542-011a861e24f9","banner":null,"lang":"en","date_modified":"2024-10-07","date_modified_ts":"2024-10-07T16:32:50Z","date_created":"2024-10-07T16:20:27Z","summary":null,"body":["<article data-history-node-id=\"5701\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-564\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-564<br \/><strong>Date: <\/strong>October 7, 2024<\/p>\n\n<p>Between September\u00a030\u00a0and\u00a0October\u00a06,\u00a02024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7021-4\">Ubuntu Security Notice (USN-7021-4)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7003-5\">Ubuntu Security Notice (USN-7003-5)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-564","alert_type":396,"serial_number":"AV24-564","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5702,"title":" [Control systems] CISA ICS security advisories (AV24-565) ","uuid":"bdcb37eb-d1ee-4443-bceb-f28a2f5180b0","banner":null,"lang":"en","date_modified":"2024-10-07","date_modified_ts":"2024-10-07T17:44:55Z","date_created":"2024-10-07T16:54:29Z","summary":null,"body":["<article data-history-node-id=\"5702\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-565\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-565<br \/><strong>Date: <\/strong>October 7, 2024<\/p>\n\n<p>Between September\u00a030 and October\u00a06,\u00a02024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics DIAEnergie\u00a0\u2013 versions v1.10.01.008 and prior<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F FX5-OPC\u00a0\u2013 all versions<\/li>\n\t<li>Optigo Networks ONS-S8\u00a0- Spectra Aggregation Switch\u00a0\u2013 versions 1.3.7 and prior<\/li>\n\t<li>Subnet Solutions PowerSYSTEM Center\u00a0\u2013 versions PSC 2020 v5.21.x and prior<\/li>\n\t<li>TEM Opera Plus FM Family Transmitter\u00a0\u2013 version 35.45<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-565","alert_type":398,"serial_number":"AV24-565","subject":"ics","moderation_state":"published","external_url":null},{"nid":5703,"title":"Red Hat security advisory (AV24-566)","uuid":"bc2074c8-62a0-4a07-b723-6017e25a64f0","banner":null,"lang":"en","date_modified":"2024-10-07","date_modified_ts":"2024-10-07T18:22:09Z","date_created":"2024-10-07T17:56:28Z","summary":null,"body":["<article data-history-node-id=\"5703\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-566\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-566<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 7, 2024<\/p>\n\n<p>Between September\u00a030 and October\u00a06, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platform<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:7489\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:7489 <\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:7490\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:7490 <\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-566","alert_type":396,"serial_number":"AV24-566","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5704,"title":" Android security advisory \u2013 October 2024 Monthly Rollup (AV24-567)","uuid":"2204a1f2-d88e-4b10-ac99-d404100d4c02","banner":null,"lang":"en","date_modified":"2024-10-07","date_modified_ts":"2024-10-07T18:41:51Z","date_created":"2024-10-07T18:35:53Z","summary":null,"body":["<article data-history-node-id=\"5704\" about=\"\/en\/alerts-advisories\/android-security-advisory-october-2024-monthly-rollup-av24-567\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-567<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 7, 2024<\/p>\n\n<p>On October 7, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-10-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-october-2024-monthly-rollup-av24-567","alert_type":396,"serial_number":"AV24-567","subject":"android","moderation_state":"published","external_url":null},{"nid":5705,"title":"[Control systems] Schneider Electric security advisory (AV24-570)","uuid":"1a86090b-7ce6-48c1-9ca7-318aad43db7e","banner":null,"lang":"en","date_modified":"2024-10-08","date_modified_ts":"2024-10-08T18:59:09Z","date_created":"2024-10-08T16:16:19Z","summary":null,"body":["<article data-history-node-id=\"5705\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-570\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-570<br \/><strong>Date: <\/strong>October 8, 2024<\/p>\n\n<p>On October 8, 2024, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Data Center Expert\u00a0\u2013 versions 8.1.1.3 and prior<\/li>\n\t<li>Easergy Studio\u00a0\u2013 version 9.3.1 and prior<\/li>\n\t<li>EcoStruxure EV Charging Expert\u00a0\u2013 versions prior to V6.0.0<\/li>\n\t<li>EcoStruxure\u2122 Power Monitoring Expert (PME)\u00a0\u2013 versions 2022 and prior<\/li>\n\t<li>EVlink Home Smart\u00a0\u2013 versions prior to 2.0.6.0.0<\/li>\n\t<li>Harmony iPC\u00a0\u2013 HMIBSC IIoT Edge Box Core \u2013 all versions, multiple products<\/li>\n\t<li>Schneider Charge\u00a0\u2013 versions prior to 1.13.4<\/li>\n\t<li>System Monitor application in Harmony Industrial PC \u2013 all versions, multiple series<\/li>\n\t<li>System Monitor application in Pro-face Industrial PC PS5000 series\u00a0\u2013 all versions<\/li>\n\t<li>Zelio Soft 2\u00a0\u2013 versions prior to 5.4.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-570","alert_type":398,"serial_number":"AV24-570","subject":"other","moderation_state":"published","external_url":null},{"nid":5706,"title":"[Control systems] Siemens security advisory (AV24-568) ","uuid":"dbb8720a-39a1-4c7a-869c-4f281222eff1","banner":null,"lang":"en","date_modified":"2024-10-08","date_modified_ts":"2024-10-08T17:25:30Z","date_created":"2024-10-08T17:11:30Z","summary":null,"body":["<article data-history-node-id=\"5706\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-568\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-568<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 8, 2024<\/p>\n\n<p>On October 8, 2024, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HiMed Cockpit\u00a0\u2013 versions prior to V11.6.2<\/li>\n\t<li>JT2Go\u00a0\u2013 versions prior to V2406.0003<\/li>\n\t<li>PSS(R)SINCAL\u00a0\u2013 versions prior to V6.70<\/li>\n\t<li>Questa\/ModelSim\u00a0\u2013 versions prior to V2024.3<\/li>\n\t<li>RUGGEDCOM APE1808LNX CC\u00a0\u2013 versions prior to V24.3.1<\/li>\n\t<li>RUGGEDCOM APE1808LNX\u00a0\u2013 versions prior to V24.3.1<\/li>\n\t<li>SENTRON 7KM PAC3200\u00a0\u2013 all versions<\/li>\n\t<li>SENTRON Powercenter 1000\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC Drive Controller family\u00a0\u2013 versions prior to V3.1.4<\/li>\n\t<li>SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC ET 200SP Open Controller CPU 1515SP PC2\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-1200 CPU family V4\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-1500 CPU family\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-1500 Software Controller\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-PLCSIM Advanced\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINEC Security Monitor\u00a0\u2013 versions prior to V4.9.0<\/li>\n\t<li>Simcenter Nastran 2306\u00a0\u2013 all versions<\/li>\n\t<li>Simcenter Nastran 2312\u00a0\u2013 all versions<\/li>\n\t<li>Simcenter Nastran 2406\u00a0\u2013 versions prior to V2406.5000<\/li>\n\t<li>Teamcenter Visualization V14.2\u00a0\u2013 versions prior to V14.2.0.13<\/li>\n\t<li>Teamcenter Visualization V14.3\u00a0\u2013 versions prior to V14.3.0.11<\/li>\n\t<li>Teamcenter Visualization V2312\u00a0\u2013 versions prior to V2312.0008<\/li>\n\t<li>Teamcenter Visualization V2406\u00a0\u2013 versions prior to V2406.0003<\/li>\n\t<li>Tecnomatix Plant Simulation V2302\u00a0\u2013 versions prior to V2302.0016<\/li>\n\t<li>Tecnomatix Plant Simulation V2404\u00a0\u2013 versions prior to V2404.0005<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-568","alert_type":398,"serial_number":"AV24-568","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5707,"title":"SAP security advisory \u2013 October 2024 monthly rollup (AV24-569)","uuid":"b3a06692-86d3-4e8b-81fb-91eac7878d6d","banner":null,"lang":"en","date_modified":"2024-10-08","date_modified_ts":"2024-10-08T18:09:43Z","date_created":"2024-10-08T17:33:48Z","summary":null,"body":["<article data-history-node-id=\"5707\" about=\"\/en\/alerts-advisories\/sap-security-advisory-october-2024-monthly-rollup-av24-569\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-569<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 8, 2024<\/p>\n\n<p>On October 8, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Enterprise Project Connection\u00a0\u2013\u00a0version 3.0<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform (Web Intelligence)\u00a0\u2013 versions ENTERPRISE 420, 430, 2025, ENTERPRISECLIENTTOOLS 420, 430 and 2025<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/october-2024.html\">SAP Security Patch Day\u00a0\u2013 October 2024<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-october-2024-monthly-rollup-av24-569","alert_type":396,"serial_number":"AV24-569","subject":"sap","moderation_state":"published","external_url":null},{"nid":5708,"title":"Qualcomm security advisory (AV24-571)","uuid":"9ab3c569-5dd7-439c-9f9d-637fd09a741b","banner":null,"lang":"en","date_modified":"2024-10-08","date_modified_ts":"2024-10-08T19:13:43Z","date_created":"2024-10-08T19:01:36Z","summary":null,"body":["<article data-history-node-id=\"5708\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-av24-571\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-571<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 8, 2024<\/p>\n\n<p>On October 8, 2024, Qualcomm published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<p>Google has reported that vulnerability CVE-2024-43047 has been exploited.<\/p>\n\n<ul><li>Qualcomm\u00a0\u2013 multiple chipsets<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/october-2024-bulletin.html\">Qualcomm\u00a0\u2013 October 2024 Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-av24-571","alert_type":396,"serial_number":"AV24-571","subject":"other","moderation_state":"published","external_url":null},{"nid":5711,"title":"Adobe security advisory (AV24\u2013573)","uuid":"8d58c317-2db1-4490-8cc5-b932390d8569","banner":null,"lang":"en","date_modified":"2024-10-08","date_modified_ts":"2024-10-08T20:18:06Z","date_created":"2024-10-08T19:33:43Z","summary":null,"body":["<article data-history-node-id=\"5711\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-573\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-573<br \/><strong>Date: <\/strong>October\u00a08, 2024<\/p>\n\n<p>On October\u00a08, 2024, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Animate 2023\u00a0\u2013 versions 23.0.7 and prior (Windows and MacOS)<\/li>\n\t<li>Adobe Animate 2024\u00a0\u2013 versions 24.0.4 and prior (Windows and MacOS)<\/li>\n\t<li>Acrobat Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Acrobat Commerce B2B\u00a0\u2013 multiple versions<\/li>\n\t<li>Acrobat Dimension\u00a0\u2013 version 4.0.3 and prior (Windows and MacOS)<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 versions 18.5.3 and prior (Windows and MacOS), versions 19.4 and prior (Windows and MacOS)<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 versions ID18.5.3 and prior (Windows and MacOS), versions ID19.4 and prior (Windows and MacOS)<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 versions 2020 Release Update 6 and prior (Windows), versions 2022 Release Update 4 and prior (Windows)<\/li>\n\t<li>Adobe Lightroom\u00a0\u2013 versions 7.4.1 and prior<\/li>\n\t<li>Adobe Lightroom Classic\u00a0\u2013 versions 13.5 and prior<\/li>\n\t<li>Adobe Lightroom Classic (LTS)\u00a0\u2013 versions 12.5.1 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 versions 3.0.3 and prior (Windows and MacOS)<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-573","alert_type":396,"serial_number":"AV24-573","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5709,"title":"Ivanti security advisory (AV24-572)","uuid":"ff5e789a-5f75-49f6-a3a9-47a5c88b971d","banner":null,"lang":"en","date_modified":"2024-10-08","date_modified_ts":"2024-10-08T19:54:14Z","date_created":"2024-10-08T19:33:44Z","summary":null,"body":["<article data-history-node-id=\"5709\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-572\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-572<br \/><strong>Date: <\/strong>October\u00a08, 2024<\/p>\n\n<p>On October\u00a08, 2024, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Connect Secure\u00a0\u2013 versions prior to 22.7R2.1<\/li>\n\t<li>Ivanti Policy Secure\u00a0\u2013 versions prior to 22.7R1.1<\/li>\n\t<li>Ivanti Avalanche\u00a0\u2013 versions 6.4.2.313 and prior<\/li>\n\t<li>Ivanti EPMM (Core)\u00a0\u2013 versions 12.1.0.3 and prior<\/li>\n\t<li>Ivanti CSA (Cloud Services Appliance)\u00a0\u2013 versions 5.0.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Connect-Secure-and-Policy-Secure-CVE-2024-37404?language=en_US&amp;_gl=1*1jmonrh*_gcl_au*NTU0MDMzNjE4LjE3MjgzOTg2Mjg\">Ivanti\u00a0\u2013 Security patch release\u00a0- Ivanti Connect Secure 22.7R2.1 and 22.7R1.1<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Ivanti-Avalanche-6-4-5-Security-Advisory?language=en_US&amp;_gl=1*1jmonrh*_gcl_au*NTU0MDMzNjE4LjE3MjgzOTg2Mjg\">Ivanti\u00a0\u2013 Security patch release\u00a0\u2013 Ivanti Avalanche 6.4.2.313<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2024-7612?language=en_US&amp;_gl=1*af0zar*_gcl_au*NTU0MDMzNjE4LjE3MjgzOTg2Mjg\">Ivanti\u00a0\u2013 Security patch release\u00a0- Ivanti EPMM (Core)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-CSA-Cloud-Services-Appliance-CVE-2024-9379-CVE-2024-9380-CVE-2024-9381?language=en_US\">Security Advisory Ivanti CSA (Cloud Services Appliance) (CVE-2024-9379, CVE-2024-9380, CVE-2024-9381)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-572","alert_type":396,"serial_number":"AV24-572","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5712,"title":"Microsoft security advisory \u2013 October 2024 monthly rollup (AV24\u2013574)","uuid":"a572d251-25d3-4785-ba6a-f5506ec76658","banner":null,"lang":"en","date_modified":"2024-10-08","date_modified_ts":"2024-10-08T20:35:30Z","date_created":"2024-10-08T20:05:52Z","summary":null,"body":["<article data-history-node-id=\"5712\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2024-monthly-rollup-av24-574\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-574\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 8, 2024\n<\/p>\n<p>On October 8, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:\n<\/p>\n<ul><li>.NET 6.0<\/li>\n  <li>.NET 8.0<\/li>\n  <li>Azure CLI<\/li>\n  <li>Azure Monitor Agent<\/li>\n  <li>Azure Service Connector<\/li>\n  <li>Azure Service Fabric<\/li>\n  <li>Azure Stack HCI 22H2<\/li>\n  <li>Azure Stack HCI 23H2<\/li>\n  <li>DeepSpeed<\/li>\n  <li>Microsoft .NET Framework\u00a0\u2013 multiple versions<\/li>\n  <li>Microsoft .NET Framework<\/li>\n  <li>Microsoft 365 Apps for Enterprise<\/li>\n  <li>Microsoft Configuration Manager\u00a0\u2013 multiple versions<\/li>\n  <li>Microsoft Defender<\/li>\n  <li>Microsoft Excel 2016<\/li>\n  <li>Microsoft Office 2016<\/li>\n  <li>Microsoft Office 2019<\/li>\n  <li>Microsoft Office LTSC<\/li>\n  <li>Microsoft Outlook for Android<\/li>\n  <li>Microsoft SharePoint Enterprise Server 2016<\/li>\n  <li>Microsoft SharePoint Server 2019<\/li>\n  <li>Microsoft SharePoint Server<\/li>\n  <li>Microsoft Visual Studio 2015<\/li>\n  <li>Microsoft Visual Studio 2017<\/li>\n  <li>Microsoft Visual Studio 2019<\/li>\n  <li>Microsoft Visual Studio 2022\u00a0\u2013 multiple versions<\/li>\n  <li>Power BI Report Server<\/li>\n  <li>Remote Desktop client for Windows Desktop<\/li>\n  <li>Visual C++ Redistributable Installer<\/li>\n  <li>Visual Studio Code<\/li>\n  <li>Windows 10\u00a0\u2013 multiple versions<\/li>\n  <li>Windows 11\u00a0\u2013 multiple versions<\/li>\n  <li>Windows Server 2008\u00a0\u2013 multiple versions<\/li>\n  <li>Windows Server 2012\u00a0\u2013 multiple versions<\/li>\n  <li>Windows Server 2016\u00a0\u2013 multiple versions<\/li>\n  <li>Windows Server 2019\u00a0\u2013 multiple versions<\/li>\n  <li>Windows Server 2022\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-43572 and CVE-2024-43573 have been exploited.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Oct\">October 2024 Release Notes<\/a><\/li>\n  <li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-october-2024-monthly-rollup-av24-574","alert_type":396,"serial_number":"AV24-574","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5713,"title":"Google Chrome security advisory (AV24-575)","uuid":"4b860ff5-1b1d-4127-8e7e-17055315bf27","banner":null,"lang":"en","date_modified":"2024-10-09","date_modified_ts":"2024-10-09T13:30:01Z","date_created":"2024-10-09T13:23:26Z","summary":null,"body":["<article data-history-node-id=\"5713\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-575\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-575<br \/><strong>Date: <\/strong>October 9, 2024<\/p>\n\n<p>On October\u00a08,\u00a02024, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 129.0.6668.100\/.101 (Windows and Mac) and 129.0.6668.100 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/10\/stable-channel-update-for-desktop_8.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-575","alert_type":396,"serial_number":"AV24-575","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5714,"title":"Mozilla security advisory (AV24-576)","uuid":"0fcc600b-b0ca-41a8-b168-70e2abf60886","banner":null,"lang":"en","date_modified":"2024-10-09","date_modified_ts":"2024-10-09T15:59:32Z","date_created":"2024-10-09T15:49:11Z","summary":null,"body":["<article data-history-node-id=\"5714\" about=\"\/en\/alerts-advisories\/cyber-mozilla-security-advisory-av24-576\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-576<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 9, 2024<\/p>\n\n<p>On October 9, 2024, Mozilla published a security advisory to address a vulnerability in the following products::<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 131.0.2<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.16.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-51\/\">Mozilla Security Advisory (MFSA 2024-51)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cyber-mozilla-security-advisory-av24-576","alert_type":396,"serial_number":"AV24-576","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5716,"title":"Mitel security advisory (AV24-577)","uuid":"c00cf108-c109-4fab-94dc-39208a30651a","banner":null,"lang":"en","date_modified":"2024-10-09","date_modified_ts":"2024-10-09T18:21:38Z","date_created":"2024-10-09T18:15:48Z","summary":null,"body":["<article data-history-node-id=\"5716\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av24-577\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-577<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 9, 2024<\/p>\n\n<p>On October 9, 2024, Mitel published security advisories to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>MiCollab\u00a0\u2013 versions 9.8 SP1 FP2 (9.8.1.201) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-misa-2024-0028\">Mitel Security Advisory\u00a0- 2024-0028<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-misa-2024-0029\">Mitel Security Advisory\u00a0- 2024-0029<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av24-577","alert_type":396,"serial_number":"AV24-577","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5717,"title":"Palo Alto Networks security advisory (AV24-578)","uuid":"a832614d-556e-4337-924c-2ba499a22f95","banner":null,"lang":"en","date_modified":"2024-10-09","date_modified_ts":"2024-10-09T20:58:48Z","date_created":"2024-10-09T20:31:01Z","summary":null,"body":["<article data-history-node-id=\"5717\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-578\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-578<br \/><strong>Date: <\/strong>October\u00a09, 2024<\/p>\n\n<p>On October\u00a09, 2024, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Palo Alto Networks Expedition\u00a0\u2013 versions prior to 1.2.96<\/li>\n\t<li>Palo Alto Prisma Access Browser\u00a0\u2013 versions prior to 129.59.2896.5<\/li>\n\t<li>Palo Alto Networks PAN-OS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2024-0010\">Palo Alto Networks Security Advisories\u00a0\u2013 PAN-SA-2024-0010<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2024-0011\">Palo Alto Networks Security Advisories\u00a0\u2013 PAN-SA-2024-0011<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-9468\">Palo Alto Networks Security Advisories \u2013 CVE-2024-9468<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-578","alert_type":396,"serial_number":"AV24-578","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5719,"title":"GitLab security advisory (AV24-579)","uuid":"ab3a6122-5a15-4ab4-82c1-69c627e9cb93","banner":null,"lang":"en","date_modified":"2024-10-10","date_modified_ts":"2024-10-10T17:26:45Z","date_created":"2024-10-10T17:14:57Z","summary":null,"body":["<article data-history-node-id=\"5719\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-579\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-579<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 10, 2024<\/p>\n\n<p>On October 9, 2024, GitLab published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.4.2, 17.3.5 and 17.2.9<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.4.2, 17.3.5 and 17.2.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/10\/09\/patch-release-gitlab-17-4-2-released\/\">GitLab Critical Patch Release: 17.4.2, 17.3.5, 17.2.9<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-579","alert_type":396,"serial_number":"AV24-579","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5721,"title":"SonicWall security advisory (AV24-580)","uuid":"aae4a971-3940-4322-a526-506fd224eefe","banner":null,"lang":"en","date_modified":"2024-10-10","date_modified_ts":"2024-10-10T20:06:50Z","date_created":"2024-10-10T19:59:56Z","summary":null,"body":["<article data-history-node-id=\"5721\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-580\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-580<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 10, 2024<\/p>\n\n<p>On October 10, 2024, SonicWall published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SonicWall SMA1000 Connect Tunnel Windows (32 and 64-bit) Client\u00a0\u2013 version 12.4.3.271 and prior<\/li>\n\t<li>SonicWall SMA1000 Appliance firmware\u00a0\u2013 version 12.4.3-02676 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2024-0017\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2024-0017 <\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-580","alert_type":396,"serial_number":"AV24-580","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":5722,"title":"Mozilla security advisory (AV24-581)","uuid":"7604a432-19cd-4820-962f-59c8e73f3064","banner":null,"lang":"en","date_modified":"2024-10-11","date_modified_ts":"2024-10-11T15:34:41Z","date_created":"2024-10-11T15:26:03Z","summary":null,"body":["<article data-history-node-id=\"5722\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-581\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-581<br \/><strong>Date: <\/strong>October 11, 2024<\/p>\n\n<p>On October\u00a010,\u00a02024, Mozilla published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0- versions prior to 115.16<\/li>\n\t<li>Thunderbird\u00a0- versions prior to 128.3.1<\/li>\n\t<li>Thunderbird\u00a0- versions prior to 131.0.1<\/li>\n<\/ul><p>Mozilla is aware that an exploit for CVE-2024-9680 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-52\/\">Mozilla Security Advisory (MFSA 2024-52)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-581","alert_type":396,"serial_number":"AV24-581","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5723,"title":"Microsoft Edge security advisory (AV24-582)","uuid":"e74b558e-2dc8-4e8d-9cb7-fbadda657590","banner":null,"lang":"en","date_modified":"2024-10-11","date_modified_ts":"2024-10-11T15:47:19Z","date_created":"2024-10-11T15:41:11Z","summary":null,"body":["<article data-history-node-id=\"5723\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-582\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-582<br \/><strong>Date: <\/strong>October 11, 2024<\/p>\n\n<p>On October\u00a010,\u00a02024, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 129.0.2792.89<\/li>\n\t<li>Microsoft Edge Extended Stable\u00a0\u2013 versions prior to 128.0.2739.113<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-10-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-582","alert_type":396,"serial_number":"AV24-582","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5724,"title":"Juniper Networks security advisory (AV24-583)","uuid":"ccfb8469-6538-495b-a763-4d654c03ccb1","banner":null,"lang":"en","date_modified":"2024-10-11","date_modified_ts":"2024-10-11T20:34:04Z","date_created":"2024-10-11T20:21:18Z","summary":null,"body":["<article data-history-node-id=\"5724\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-583\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-583<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 11, 2024<\/p>\n\n<p>On October 9, 2024, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Junos OS\u00a0\u2013 multiple versions<\/li>\n\t<li>Juno OS Evolved\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av24-583","alert_type":396,"serial_number":"AV24-583","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5726,"title":"Dell security advisory (AV24-584)","uuid":"8edd0aea-80e9-4762-a5ef-2e3c113c1397","banner":null,"lang":"en","date_modified":"2024-10-15","date_modified_ts":"2024-10-15T14:18:07Z","date_created":"2024-10-15T14:09:13Z","summary":null,"body":["<article data-history-node-id=\"5726\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-584\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-584<br \/><strong>Date: <\/strong>October 15, 2024<\/p>\n\n<p>Between October\u00a07\u00a0and\u00a013,\u00a02024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>GeoDrive for Windows\u00a0\u2013 versions prior to 2.3.3<\/li>\n\t<li>NetWorker\u00a0\u2013 versions 19.10 to 19.10.0.4, versions 19.11 to 19.11.0.1, versions 19.8 to 19.8.0.4, versions 19.9 to 19.9.0.7 and versions prior to 19.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000233573\/dsa-2024-418-security-update-for-dell-geodrive-multiple-third-party-component-vulnerabilities\">DSA-2024-418: Security Update for Dell GeoDrive Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000235068\/dsa-2024-423-security-update-for-dell-networker-and-networker-management-console-nmc-multiple-component-vulnerabilities\">DSA-2024-423: Security Update for Dell NetWorker And NetWorker Management Console (NMC) Multiple Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-584","alert_type":396,"serial_number":"AV24-584","subject":"dell","moderation_state":"published","external_url":null},{"nid":5727,"title":"IBM security advisory (AV24-585)","uuid":"941959c7-412f-48fe-bf71-5164829539ad","banner":null,"lang":"en","date_modified":"2024-10-15","date_modified_ts":"2024-10-15T14:55:30Z","date_created":"2024-10-15T14:25:57Z","summary":null,"body":["<article data-history-node-id=\"5727\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-585\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-585<br \/><strong>Date: <\/strong>October 15, 2024<\/p>\n\n<p>Between October 7\u00a0and\u00a013,\u00a02024 IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cloud Pak for AIOps\u00a0\u2013 version 4.1.0 to 4.6.1<\/li>\n\t<li>IBM Engineering Systems Design Rhapsody\u00a0- Model Manager\u00a0- versions 7.0.2 and 7.0.3<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- AI Broker\u00a0- versions 9.0.1<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- IoT Component\u00a0- versions 8.7, 8.8 and 9.0<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager software component\u00a0- version ISVG 10.0.2<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager virtual appliance component\u00a0- version ISVG 10.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-585","alert_type":396,"serial_number":"AV24-585","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5728,"title":"Ubuntu security advisory (AV24-586)","uuid":"4a566d60-db39-4dfc-ad64-53689fd37fbf","banner":null,"lang":"en","date_modified":"2024-10-15","date_modified_ts":"2024-10-15T15:13:15Z","date_created":"2024-10-15T14:59:55Z","summary":null,"body":["<article data-history-node-id=\"5728\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-586\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-586<br \/><strong>Date: <\/strong>October 15, 2024<\/p>\n\n<p>Between October\u00a07\u00a0and\u00a013,\u00a02024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7020-4\">USN-7020-4: Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7022-3\">USN-7022-3: Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-586","alert_type":396,"serial_number":"AV24-586","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5729,"title":"[Control systems] CISA ICS security advisories (AV24\u2013587) ","uuid":"d80d49ea-3a9e-4d02-ab8c-61340a18c3e4","banner":null,"lang":"en","date_modified":"2024-10-15","date_modified_ts":"2024-10-15T16:01:36Z","date_created":"2024-10-15T15:47:00Z","summary":null,"body":["<article data-history-node-id=\"5729\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-587\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-587\n  <br \/><strong>Date: <\/strong>October 15, 2024\n<\/p>\n<p>Between October\u00a07\u00a0and\u00a013,\u00a02024, CISA published ICS advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Delta Electronics CNCSoft-G2\u00a0- version 2.1.0.10<\/li>\n  <li>Rockwell Automation ControlLogix\u00a0- multiple versions and products<\/li>\n  <li>Rockwell Automation DataMosaix Private Cloud\u00a0- versions 7.07 and prior<\/li>\n  <li>Rockwell Automation Logix Controllers\u00a0- multiple versions and products<\/li>\n  <li>Rockwell Automation PowerFlex 6000T\u00a0- versions 8.001, 8.002 and 9.001<\/li>\n  <li>Rockwell Automation Verve Asset Manager\u00a0- versions 1.38 and prior<\/li>\n  <li>Schneider Electric Zelio Soft 2\u00a0- versions prior to 5.4.2.2<\/li>\n  <li>Siemens SINEC Security Monitor\u00a0- versions prior to V4.9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-587","alert_type":398,"serial_number":"AV24-587","subject":"ics","moderation_state":"published","external_url":null},{"nid":5730,"title":"Mozilla security advisory (AV24-588)","uuid":"d0ba2669-17af-4e16-9976-7d6715c6fb03","banner":null,"lang":"en","date_modified":"2024-10-15","date_modified_ts":"2024-10-15T16:48:54Z","date_created":"2024-10-15T15:51:35Z","summary":null,"body":["<article data-history-node-id=\"5730\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-588\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-588<br \/><strong>Date: <\/strong>October\u00a015, 2024<\/p>\n\n<p>On October\u00a014, 2024, Mozilla published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 131.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-53\/\">Mozilla Security Advisory (MFSA 2024-53)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-588","alert_type":396,"serial_number":"AV24-588","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5732,"title":"Google Chrome security advisory (AV24-589)","uuid":"b90ae742-6d9e-4286-bb35-c6240717c036","banner":null,"lang":"en","date_modified":"2024-10-15","date_modified_ts":"2024-10-15T20:17:18Z","date_created":"2024-10-15T20:04:36Z","summary":null,"body":["<article data-history-node-id=\"5732\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-589\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-589<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2024<\/p>\n\n<p>On October 15, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 130.0.6723.58\/.59 (Windows and Mac) and 130.0.6723.58 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/10\/stable-channel-update-for-desktop_15.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-589","alert_type":396,"serial_number":"AV24-589","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5733,"title":"GitHub security advisory (AV24-590)","uuid":"9403ac5a-6791-4657-af77-8b5feaacb64a","banner":null,"lang":"en","date_modified":"2024-10-15","date_modified_ts":"2024-10-15T20:29:43Z","date_created":"2024-10-15T20:21:43Z","summary":null,"body":["<article data-history-node-id=\"5733\" about=\"\/en\/alerts-advisories\/github-security-advisory-av24-590\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-590<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2024<\/p>\n\n<p>On October 10, 2024, GitHub published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.2<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.13.x prior to 3.13.5<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.12.x prior to 3.12.10<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.11.x prior to 3.11.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">GitHub Release Notes #3.14.2<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.13\/admin\/release-notes\">GitHub Release Notes #3.13.5<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.12\/admin\/release-notes\">GitHub Release Notes #3.12.10<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.11\/admin\/release-notes\">GitHub Release Notes #3.11.16<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av24-590","alert_type":396,"serial_number":"AV24-590","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5736,"title":"Oracle security advisory \u2013 October 2024 quarterly rollup (AV24-591)","uuid":"f40666e5-1fdd-4f72-bb22-761f7a23a778","banner":null,"lang":"en","date_modified":"2024-10-16","date_modified_ts":"2024-10-16T15:14:48Z","date_created":"2024-10-16T15:02:32Z","summary":null,"body":["<article data-history-node-id=\"5736\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-october-2024-quarterly-rollup-av24-591\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-591<br \/><strong>Date: <\/strong>October 16, 2024<\/p>\n\n<p>On October\u00a015,\u00a02024, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Commerce<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle Hospitality Applications<\/li>\n\t<li>Oracle Systems<\/li>\n\t<li>Oracle SQL<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuoct2024.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 October\u00a02024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-october-2024-quarterly-rollup-av24-591","alert_type":396,"serial_number":"AV24-591","subject":"oracle","moderation_state":"published","external_url":null},{"nid":5737,"title":"[Control systems] ABB security advisory (AV24-592) ","uuid":"d0a8103f-50c9-4adb-84df-d2555f833862","banner":null,"lang":"en","date_modified":"2024-10-16","date_modified_ts":"2024-10-16T15:34:01Z","date_created":"2024-10-16T15:22:56Z","summary":null,"body":["<article data-history-node-id=\"5737\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-592\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-592<br \/><strong>Date: <\/strong>October 16, 2024<\/p>\n\n<p>On October\u00a010,\u00a02024, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>IRC5 RobotWare\u00a0\u2013 versions prior to 6.15.06 except 6.10.10 and 6.13.07<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=SI20337&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">IRC5 RobotWare\u00a0\u2013 PROFINET Stack Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-592","alert_type":398,"serial_number":"AV24-592","subject":"abb","moderation_state":"published","external_url":null},{"nid":5738,"title":"Atlassian security advisory (AV24-593)","uuid":"9c14d077-c0f7-46a5-8572-43ca272622bc","banner":null,"lang":"en","date_modified":"2024-10-16","date_modified_ts":"2024-10-16T15:57:24Z","date_created":"2024-10-16T15:48:32Z","summary":null,"body":["<article data-history-node-id=\"5738\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-593\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-593<br \/><strong>Date: <\/strong>October 16, 2024<\/p>\n\n<p>On October\u00a015,\u00a02024, Atlassian published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-october-15-2024-1442910972.html\">Atlassian Security Bulletin\u00a0\u2013 October 15 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-593","alert_type":396,"serial_number":"AV24-593","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5740,"title":"F5 security advisory (AV24-594)","uuid":"01568613-77f6-4a10-af48-40c2334cc71b","banner":null,"lang":"en","date_modified":"2024-10-16","date_modified_ts":"2024-10-16T17:31:43Z","date_created":"2024-10-16T17:24:08Z","summary":null,"body":["<article data-history-node-id=\"5740\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av24-594\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-594<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 16 2024<\/p>\n\n<p>On October 16, 2024, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP (all modules)\u00a0\u2013 versions 17.1.0 to 17.1.1, 16.1.0 to 16.1.4 and 15.1.0 to 15.1.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000141302\">F5 Security Advisory\u00a0\u2013 October 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av24-594","alert_type":396,"serial_number":"AV24-594","subject":"f5","moderation_state":"published","external_url":null},{"nid":5741,"title":"Cisco security advisory (AV24-595)","uuid":"e941fc84-a224-43e4-9f9d-64b09997544c","banner":null,"lang":"en","date_modified":"2024-10-16","date_modified_ts":"2024-10-16T17:42:09Z","date_created":"2024-10-16T17:34:49Z","summary":null,"body":["<article data-history-node-id=\"5741\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-595\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-595<br \/><strong>Date: <\/strong>October\u00a016, 2024<\/p>\n\n<p>On October\u00a016, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco ATA 191 Analog Telephone Adapter\u00a0\u2013 version 12.0.1 and prior<\/li>\n\t<li>Cisco ATA 191 and 192 Multiplatform Analog Telephone Adapter\u00a0\u2013 version 11.2.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ata19x-multi-RDTEqRsy\">Cisco Security Advisory \u2013 cisco-sa-ata19x-multi-RDTEqRsy<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-595","alert_type":396,"serial_number":"AV24-595","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5742,"title":"SolarWinds security advisory (AV24-596)","uuid":"4ae93a14-09ea-44a1-aa60-5346320f635c","banner":null,"lang":"en","date_modified":"2024-10-16","date_modified_ts":"2024-10-16T18:29:48Z","date_created":"2024-10-16T18:22:14Z","summary":null,"body":["<article data-history-node-id=\"5742\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-596\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-596<br \/><strong>Date: <\/strong>October\u00a016, 2024<\/p>\n\n<p>Between October\u00a015 and 16, 2024, SolarWinds published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Serv-U FTP\u00a0\u2013 version 15.4.2 and prior<\/li>\n\t<li>SolarWinds Platform\u00a0\u2013 version 2024.2.1 and prior<\/li>\n\t<li>SolarWinds Web Help Desk\u00a0\u2013 versions 12.8.3 HF2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-45711\">Serv-U FTP Service Directory Traversal Remote Code Execution Vulnerability (CVE-2024-45711)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-45710\">SolarWinds Platform Uncontrolled Search Path Element Local Privilege Escalation Vulnerability (CVE-2024-45710)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2024-28988\">SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability (CVE-2024-28988)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av24-596","alert_type":396,"serial_number":"AV24-596","subject":"other","moderation_state":"published","external_url":null},{"nid":5743,"title":"VMware security advisory (AV24-597)","uuid":"e790d555-da96-448a-837b-ae71f3ae2f24","banner":null,"lang":"en","date_modified":"2024-10-16","date_modified_ts":"2024-10-16T18:59:08Z","date_created":"2024-10-16T18:41:50Z","summary":null,"body":["<article data-history-node-id=\"5743\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-597\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-597<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 16, 2024<\/p>\n\n<p>On October 16, 2024, VMware released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>VMWare HCX\u00a0\u2013 versions 4.8.x, 4.9.x and 4.10.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25019\">VMSA-2024-0021: VMware HCX addresses an authenticated SQL injection vulnerability (CVE-2024-38814)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-597","alert_type":396,"serial_number":"AV24-597","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5745,"title":"Microsoft Edge security advisory (AV24-598)","uuid":"09d3f51a-fb81-457e-896e-66ab01aeae00","banner":null,"lang":"en","date_modified":"2024-10-18","date_modified_ts":"2024-10-18T13:17:29Z","date_created":"2024-10-18T13:06:59Z","summary":null,"body":["<article data-history-node-id=\"5745\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-598\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-598<br \/><strong>Date: <\/strong>October 18, 2024<\/p>\n\n<p>On October\u00a017,\u00a02024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 130.0.2849.46<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-17-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-598","alert_type":396,"serial_number":"AV24-598","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5746,"title":"HPE security advisory (AV24-599)","uuid":"26f42898-2ab8-4b5c-9096-cdcc7f79bf48","banner":null,"lang":"en","date_modified":"2024-10-18","date_modified_ts":"2024-10-18T18:46:22Z","date_created":"2024-10-18T18:22:13Z","summary":null,"body":["<article data-history-node-id=\"5746\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-599\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-599\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 18, 2024\n<\/p>\n<p>On October 18, 2024, HPE published security advisories to address a vulnerability in the following products:\n<\/p>\n<ul><li>HPE Cray EX235a Accelerator Blade\u00a0\u2013 versions prior to v1.9.0 (HFP 24.9)<\/li>\n  <li>HPE Cray EX235n Server\u00a0\u2013 versions prior to v1.5.0 (HFP 24.9)<\/li>\n  <li>HPE Cray EX255a Accelerator Blade\u00a0\u2013 versions prior to v1.1.0 (HFP 24.8.1)<\/li>\n  <li>HPE Cray EX425 Compute Blade\u00a0\u2013 versions prior to v1.7.5 (HFP 24.9)<\/li>\n  <li>HPE Cray EX4252 Compute Blade\u00a0\u2013 versions prior to v1.7.0 (HFP 24.8.1)<\/li>\n  <li>HPE ProLiant XL645d Gen10 Plus Server\u00a0\u2013 versions prior to v3.20_08-07-2024<\/li>\n  <li>HPE ProLiant XL675d Gen10 Plus Server\u00a0\u2013 versions prior to v3.20_08-07-2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04683en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04683en_us <\/a><\/li>\n  <li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US \">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-599","alert_type":396,"serial_number":"AV24-599","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5748,"title":"Ubuntu security advisory (AV24-600)","uuid":"5e826c03-d70f-4d47-a232-90447f9628c2","banner":null,"lang":"en","date_modified":"2024-10-21","date_modified_ts":"2024-10-21T17:22:23Z","date_created":"2024-10-21T17:17:23Z","summary":null,"body":["<article data-history-node-id=\"5748\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-600\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-600<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 21, 2024<\/p>\n\n<p>Between October 14 and 20, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-600","alert_type":396,"serial_number":"AV24-600","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5750,"title":"Dell security advisory (AV24-602)","uuid":"356f6b68-6956-403c-9a1e-49adbd3fc7e5","banner":null,"lang":"en","date_modified":"2024-10-21","date_modified_ts":"2024-10-21T18:22:31Z","date_created":"2024-10-21T17:36:22Z","summary":null,"body":["<article data-history-node-id=\"5750\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-602\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-602<br \/><strong>Date: <\/strong>October 21, 2024<\/p>\n\n<p>Between October 14 and 20, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Dell Policy Manager for Secure Connect Gateway\u00a0\u2013 version 5.24.00.14<\/li>\n\t<li>Dell Secure Connect Gateway\u00a0\u2013 version 5.24.00.14<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 5.0.2.0<\/li>\n\t<li>Dell Storage Resource Manager\u00a0\u2013 versions prior to 5.0.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000236839\/dsa-2024-406-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities\">DSA-2024-406: Security Update for Dell Secure Connect Gateway Policy Manager Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000237211\/dsa-2024-407-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities\">DSA-2024-407: Dell Secure Connect Gateway Security Update for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000235152\/dsa-2024-421-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">DSA-2024-421: Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR) Security Update for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-602","alert_type":396,"serial_number":"AV24-602","subject":"dell","moderation_state":"published","external_url":null},{"nid":5749,"title":"[Control systems] CISA ICS security advisories (AV24\u2013601)","uuid":"0efcbd71-dc52-4623-82ac-8948e7f249b4","banner":null,"lang":"en","date_modified":"2024-10-21","date_modified_ts":"2024-10-21T18:14:58Z","date_created":"2024-10-21T17:36:23Z","summary":null,"body":["<article data-history-node-id=\"5749\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-601\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-601<br \/><strong>Date: <\/strong>October\u00a021, 2024<\/p>\n\n<p>Between October\u00a014 and 20, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Elvaco M-Bus Metering Gateway CMe3100\u00a0\u2013 version 1.12.1<\/li>\n\t<li>HMS Networks EWON FLEXY 202\u00a0\u2013 firmware version 14.2s0<\/li>\n\t<li>Kieback&amp;Peter DDC4000 series\u00a0\u2013 multiple models and versions<\/li>\n\t<li>LCDS LAquis SCADA\u00a0\u2013 version 4.7.1.511<\/li>\n\t<li>Mitsubishi Electric CNC Series\u00a0\u2013 multiple models, all versions<\/li>\n\t<li>Schneider Electric Data Center Expert\u00a0\u2013 versions 8.1.1.3 and prior<\/li>\n\t<li>Siemens Siveillance Video Camera\u00a0\u2013 versions prior to V13.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-601","alert_type":398,"serial_number":"AV24-601","subject":"ics","moderation_state":"published","external_url":null},{"nid":5751,"title":"IBM security advisory (AV24-603)","uuid":"b04cd53d-0815-4a0a-922b-68c903a8c30f","banner":null,"lang":"en","date_modified":"2024-10-21","date_modified_ts":"2024-10-21T19:52:36Z","date_created":"2024-10-21T19:29:22Z","summary":null,"body":["<article data-history-node-id=\"5751\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-603\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-603<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 21, 2024<\/p>\n\n<p>Between October 14 and 20, 2024 IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Observability with Instana (OnPrem)\u00a0\u2013 version Build 277 (Self-Hosted Standard Edition 1.5.0)<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 version 7.5 to 7.5.0 UP9 IF03<\/li>\n\t<li>IBM QRadar Incident Forensics\u00a0\u2013 version 7.5 to 7.5.0 UP9 IF03<\/li>\n\t<li>IBM Rational ClearQuest\u00a0\u2013 versions 10.0 to 10.0.6 and 9.1 to 9.1.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7173200\">Security Bulletin: IBM Observability with Instana for Self-Hosted Standard Edition is affected by multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7173352\">Security Bulletin: A vulnerability has been identified in IBM HTTP Server used by IBM Rational ClearQuest due to the included Apache HTTP Server (CVE-2024-40898, CVE-2024-40725)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7173426\">Security Bulletin: Due to use of International Components for Unicode, IBM Rational ClearQuest is vulnerable to buffer overflow<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7173420\">Security Bulletin: IBM QRadar SIEM contains multiple vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-603","alert_type":396,"serial_number":"AV24-603","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5752,"title":"Foxit security advisory (AV24-604)","uuid":"73f859e0-8cf8-46dc-994e-62cacbfcfe3e","banner":null,"lang":"en","date_modified":"2024-10-21","date_modified_ts":"2024-10-21T20:12:11Z","date_created":"2024-10-21T20:01:25Z","summary":null,"body":["<article data-history-node-id=\"5752\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av24-604\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-604<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 21, 2024<\/p>\n\n<p>On October 18, 2024, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor for Windows\u00a0\u2013 version 11.2.10.53951 and prior<\/li>\n\t<li>Foxit PDF Editor for Mac\u00a0\u2013 version 11.1.9.0524 and prior, version 12.1.5.55449 and prior 12.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av24-604","alert_type":396,"serial_number":"AV24-604","subject":"other","moderation_state":"published","external_url":null},{"nid":5753,"title":"HPE security advisory (AV24-605)","uuid":"7e7d1185-58aa-47e8-86d8-bce880173b41","banner":null,"lang":"en","date_modified":"2024-10-23","date_modified_ts":"2024-10-23T12:42:12Z","date_created":"2024-10-23T12:30:52Z","summary":null,"body":["<article data-history-node-id=\"5753\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-605\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-605<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 23, 2024<\/p>\n\n<p>On October 18 and 20, 2024, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE OpenView Performance Mgt. T0684\u00a0\u2013 versions T0684V01^ABG, T0684V01^ABH, T0684V01^ABI, T0684V01^ABJ and T0684V01^ABK<\/li>\n\t<li>HPE Superdome Flex 280 Server\u00a0\u2013 versions prior to v1.90.12<\/li>\n\t<li>HPE Superdome Flex Server\u00a0\u2013 versions prior to v4.0.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-605","alert_type":396,"serial_number":"AV24-605","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5754,"title":"Google Chrome security advisory (AV24-606)","uuid":"e2f05a7f-5b45-4be9-b4a3-ca710f362fcb","banner":null,"lang":"en","date_modified":"2024-10-23","date_modified_ts":"2024-10-23T13:00:43Z","date_created":"2024-10-23T12:48:00Z","summary":null,"body":["<article data-history-node-id=\"5754\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-606\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-606<br \/><strong>Date: <\/strong>October 23, 2024<\/p>\n\n<p>On October 22, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 130.0.6723.69\/.70 (Windows and Mac) and 130.0.6723.69 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/10\/stable-channel-update-for-desktop_22.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-606","alert_type":396,"serial_number":"AV24-606","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5755,"title":"[Control systems] ABB security advisory (AV24-607) ","uuid":"00442e3e-d69a-4db2-81a7-91706824fb49","banner":null,"lang":"en","date_modified":"2024-10-23","date_modified_ts":"2024-10-23T19:56:36Z","date_created":"2024-10-23T19:15:56Z","summary":null,"body":["<article data-history-node-id=\"5755\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-607\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-607<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 23, 2024<\/p>\n\n<p>On October 21, 2024, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ABB Relion Protection Relays 611, 615, 620 and 630 series, REC\/RER615\/620, REX610, REX615 and REX640<\/li>\n\t<li>ABB Substation Merging Unit SMU615<\/li>\n\t<li>ABB Smart Substation Control and Protection SSC600<\/li>\n\t<li>ABB communication solution products ARG\/ARC\/ARR\/ARP600, RER\/REC601\/603, ARM600, and ARM600SW<\/li>\n\t<li>ABB digital substation products COM600, SPA ZC-400\/402<\/li>\n\t<li>SUE3000<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA001911&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Relion 611, 615, 620, 630 series, REX610, REX640, SMU615, SSC600, Arctic solution, COM600, SPA ZC-400, SUE3000 Guidelines to Prevent Unauthorized Modifications of Firmware and configuration<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-607","alert_type":398,"serial_number":"AV24-607","subject":"abb","moderation_state":"published","external_url":null},{"nid":5756,"title":"Fortinet security advisory (AV24-608)","uuid":"e5ec8e72-998c-4211-8c91-0381a1ea00fc","banner":null,"lang":"en","date_modified":"2024-10-23","date_modified_ts":"2024-10-23T20:10:34Z","date_created":"2024-10-23T20:03:02Z","summary":null,"body":["<article data-history-node-id=\"5756\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-608\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-608<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 23, 2024<\/p>\n\n<p>On October 23, 2024, Fortinet published security advisories to address a vulnerability in multiple products. Included was a critical update for the following products::<\/p>\n\n<ul><li>FortiManager 7.6\u00a0\u2013 versions prior to 7.6.1<\/li>\n\t<li>FortiManager 7.4\u00a0\u2013 versions prior to 7.4.5<\/li>\n\t<li>FortiManager 7.2\u00a0\u2013 versions prior to 7.2.8<\/li>\n\t<li>FortiManager 7.0\u00a0\u2013 versions prior to 7.0.13<\/li>\n\t<li>FortiManager 6.4\u00a0\u2013 versions prior to 6.4.15<\/li>\n\t<li>FortiManager 6.2\u00a0\u2013 versions prior to 6.2.13<\/li>\n\t<li>FortiManager Cloud 7.4\u00a0\u2013 versions prior to 7.4.5<\/li>\n\t<li>FortiManager Cloud 7.2\u00a0\u2013 versions prior to 7.2.8<\/li>\n\t<li>FortiManager Cloud0\u00a0\u2013 versions prior to 7.0.13<\/li>\n\t<li>FortiManager Cloud 6.4\u00a0\u2013 all versions<\/li>\n<\/ul><p>Fortinet has received reports that CVE-2024-47575 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-423\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-423<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-608","alert_type":396,"serial_number":"AV24-608","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":5757,"title":"Cisco security advisory (AV24-609)","uuid":"5638c947-d732-4b72-9bdf-40637b2d8af8","banner":null,"lang":"en","date_modified":"2024-10-23","date_modified_ts":"2024-10-23T20:25:56Z","date_created":"2024-10-23T20:22:17Z","summary":null,"body":["<article data-history-node-id=\"5757\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-609\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-609<br \/><strong>Date: <\/strong>October\u00a023, 2024<\/p>\n\n<p>On October\u00a023, 2024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Adaptive Security Appliance (ASA) Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Firepower Management Center (FMC) Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Firepower Threat Defense (FTD) Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Secure Firewall Management Center (FMC) Software\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-609","alert_type":396,"serial_number":"AV24-609","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5759,"title":"GitLab security advisory (AV24-610)","uuid":"4b82d7df-6ef6-44d9-b59f-5b9b9cd05281","banner":null,"lang":"en","date_modified":"2024-10-24","date_modified_ts":"2024-10-24T17:49:48Z","date_created":"2024-10-24T17:45:31Z","summary":null,"body":["<article data-history-node-id=\"5759\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-610\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-610<br \/><strong>Date: <\/strong>October\u00a024, 2024<\/p>\n\n<p>On October\u00a023, 2024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.5.1, 17.4.3 and 17.3.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.5.1, 17.4.3 and 17.3.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/10\/23\/patch-release-gitlab-17-5-1-released\/\">GitLab Critical Patch Release: 17.5.1, 17.4.3, 17.3.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-610","alert_type":396,"serial_number":"AV24-610","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5762,"title":"Drupal security advisory (AV24-611)","uuid":"44ab604f-fc70-40dd-88c6-37a130cb34a4","banner":null,"lang":"en","date_modified":"2024-10-24","date_modified_ts":"2024-10-24T20:05:59Z","date_created":"2024-10-24T19:57:56Z","summary":null,"body":["<article data-history-node-id=\"5762\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-611\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-611<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2024<\/p>\n\n<p>On October 23, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Monster Menus 9.4.x branch\u00a0\u2013 versions 9.4.0 to versions prior to 9.4.2<\/li>\n\t<li>Monster Menus 9.3.x branch\u00a0\u2013 versions prior to 9.3.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-052\">Monster Menus\u00a0- Critical\u00a0- Arbitrary PHP code execution\u00a0- SA-CONTRIB-2024-052<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-611","alert_type":396,"serial_number":"AV24-611","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5764,"title":"Microsoft Edge security advisory (AV24-612)","uuid":"c80ab6c0-42f8-42db-a4e9-ab2ede5603fa","banner":null,"lang":"en","date_modified":"2024-10-25","date_modified_ts":"2024-10-25T17:02:39Z","date_created":"2024-10-25T15:41:20Z","summary":null,"body":["<article data-history-node-id=\"5764\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-612\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-612<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 25, 2024<\/p>\n\n<p>On October 24, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 130.0.2849.46<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-24-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-612","alert_type":396,"serial_number":"AV24-612","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5765,"title":"HPE security advisory (AV24-613)","uuid":"71a79394-9c5d-4952-ab72-b6a6718a6db0","banner":null,"lang":"en","date_modified":"2024-10-25","date_modified_ts":"2024-10-25T17:28:45Z","date_created":"2024-10-25T17:07:05Z","summary":null,"body":["<article data-history-node-id=\"5765\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-613\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-613<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 25, 2024<\/p>\n\n<p>On October 25, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Common Internet File System (CIFS) Client\/Server Software\u00a0\u2013 versions prior to B.04.18.01.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04724en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbux04724en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Security Bulletin Library<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-613","alert_type":396,"serial_number":"AV24-613","subject":"other","moderation_state":"published","external_url":null},{"nid":5766,"title":"[Control systems] Siemens security advisory (AV24-614)","uuid":"9981016b-78f9-479e-9f23-848113b4deab","banner":null,"lang":"en","date_modified":"2024-10-25","date_modified_ts":"2024-10-25T20:41:14Z","date_created":"2024-10-25T20:33:44Z","summary":null,"body":["<article data-history-node-id=\"5766\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-614\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-614<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 25, 2024<\/p>\n\n<p>On October 23, 2024, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Siemens<\/span> published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>InterMesh 7177 Hybrid 2.0 Subscriber\u00a0\u2013 versions prior to V8.2.12<\/li>\n\t<li>InterMesh 7707 Fire Subscriber\u00a0\u2013 versions prior to V7.2.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-333468.html\">Siemens Security Advisory\u00a0- SSA-333468<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-614","alert_type":398,"serial_number":"AV24-614","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5767,"title":"Dell security advisory (AV24-615)","uuid":"71cd33a2-8f74-44d4-b6c4-5d8d8c827147","banner":null,"lang":"en","date_modified":"2024-10-28","date_modified_ts":"2024-10-28T15:56:48Z","date_created":"2024-10-28T15:35:37Z","summary":null,"body":["<article data-history-node-id=\"5767\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-614\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-615\n  <br \/><strong>Date: <\/strong>October 28, 2024\n<\/p>\n<p>Between October\u00a021 and 27\u00a02024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:\n<\/p>\n<ul><li>DELL Data Lakehouse System Software\u00a0\u2013 versions 1.0.0.0 and 1.1.0.0<\/li>\n  <li>Dell EMC VxRail Appliance\u00a0\u2013 versions prior to 8.0.310<\/li>\n  <li>PowerFlex appliance\u00a0\u2013 versions prior to 3.8.8 and versions prior to 4.6.0.1<\/li>\n  <li>PowerFlex rack\u00a0\u2013 versions prior to 3.8.8 and versions prior to 4.6.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000238943\/dsa-2024-413-security-update-for-a-dell-powerflex-manager-multiple-vulnerabilities\">DSA-2024-413: Security Update for a Dell PowerFlex Manager Cleartext Storage of Sensitive Information Vulnerability<\/a><\/li>\n  <li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000240535\/dsa-2024-419-security-update-for-dell-data-lakehouse-system-software-for-multiple-third-party-component-vulnerabilities\">DSA-2024-419: Security Update for Dell Data Lakehouse System Software for Multiple Component Vulnerabilities<\/a><\/li>\n  <li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000240575\/dsa-2024-393-security-update-for-dell-vxrail-hci-8-0-310-multiple-third-party-component-vulnerabilities\">DSA-2024-393: Security Update for Dell VxRail 8.0.310 Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n  <li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-614","alert_type":396,"serial_number":"AV24-615","subject":"dell","moderation_state":"published","external_url":null},{"nid":5768,"title":"IBM security advisory (AV24-616)","uuid":"05b091d4-325b-436a-af2e-8101a4b6de9d","banner":null,"lang":"en","date_modified":"2024-10-28","date_modified_ts":"2024-10-28T16:22:56Z","date_created":"2024-10-28T16:12:19Z","summary":null,"body":["<article data-history-node-id=\"5768\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-616\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-616<br \/><strong>Date: <\/strong>October 28, 2024<\/p>\n\n<p>Between October\u00a021 and 27,\u00a02024 IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>DataPower Operations Dashboard\u00a0\u2013 version 1.0.21.0<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 versions 11.2.0 to 11.2.3 FP3 and 12.0.0 to 12.0.3<\/li>\n\t<li>IBM Cognos Analytics Mobile (Android)\u00a0\u2013 version 1.1<\/li>\n\t<li>IBM Cognos Analytics Mobile (iOS)\u00a0\u2013 version 1.1<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 version 1.0.0 to 1.0.1<\/li>\n\t<li>IBM Security Guardium Key Lifecycle Manager (SKLM\/GKLM)\u00a0\u2013 version 4.1.1 and 4.2<\/li>\n\t<li>IBM Storage Protect Server\u00a0\u2013 version 8.1<\/li>\n\t<li>Server Firmware\u00a0\u2013 versions FW1030.00 to FW1030.61, FW1050.00 to FW1050.21, FW1060.00 to FW1060.10, FW860.00 to FW860.B3 and FW950.00 to FW950.C0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-616","alert_type":396,"serial_number":"AV24-616","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5770,"title":"Ubuntu security advisory (AV24-617)","uuid":"7f1ecd7c-524e-466b-96d6-53fead4c27b7","banner":null,"lang":"en","date_modified":"2024-10-28","date_modified_ts":"2024-10-28T17:31:45Z","date_created":"2024-10-28T17:22:07Z","summary":null,"body":["<article data-history-node-id=\"5770\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-617\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-617<br \/><strong>Date: <\/strong>October\u00a028, 2024<\/p>\n\n<p>Between October\u00a021 and 27, 2024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7072-2\">USN-7072-2: Linux kernel (GKE) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-617","alert_type":396,"serial_number":"AV24-617","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5771,"title":"Red Hat security advisory (AV24-618)","uuid":"36621871-70b2-49b4-a0ec-b61072426a57","banner":null,"lang":"en","date_modified":"2024-10-28","date_modified_ts":"2024-10-28T19:08:41Z","date_created":"2024-10-28T19:01:34Z","summary":null,"body":["<article data-history-node-id=\"5771\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-618\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-618<br \/><strong>Date: <\/strong>October\u00a028, 2024<\/p>\n\n<p>Between October\u00a021 and 27, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following product:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platform<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:8365\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:8365<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-618","alert_type":396,"serial_number":"AV24-618","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5772,"title":"[Control systems] CISA ICS security advisories (AV24\u2013619)","uuid":"ff8c939e-362f-4115-90ca-c3b2cd496e11","banner":null,"lang":"en","date_modified":"2024-10-28","date_modified_ts":"2024-10-28T19:16:20Z","date_created":"2024-10-28T19:01:34Z","summary":null,"body":["<article data-history-node-id=\"5772\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-619\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-619<br \/><strong>Date: <\/strong>October\u00a028, 2024<\/p>\n\n<p>Between October\u00a021 and 27, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Deep Sea Electronics DSE855\u00a0\u2013 version 1.0.26<\/li>\n\t<li>ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI\u00a0\u2013 version 10.97.3 and prior<\/li>\n\t<li>iniNet Solutions SpiderControl SCADA PC HMI Editor\u00a0\u2013 version 8.10.00.00<\/li>\n\t<li>Mitsubishi Electric MC Works64\u00a0\u2013 all versions<\/li>\n\t<li>VIMESA VHF\/FM Transmitter Blue Plus\u00a0\u2013 version v9.7.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-296-01\">CISA ICS Advisory\u00a0- ICSA-24-296-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-298-01\">CISA ICS Advisory\u00a0- ICSA-24-298-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-298-02\">CISA ICS Advisory\u00a0- ICSA-24-298-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-24-298-03\">CISA ICS Advisory\u00a0- ICSA-24-298-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-619","alert_type":398,"serial_number":"AV24-619","subject":"ics","moderation_state":"published","external_url":null},{"nid":5773,"title":" Apple security advisory (AV24-620)","uuid":"9b66916f-f015-46b1-83aa-a47fd7f64380","banner":null,"lang":"en","date_modified":"2024-10-28","date_modified_ts":"2024-10-28T21:30:20Z","date_created":"2024-10-28T21:21:30Z","summary":null,"body":["<article data-history-node-id=\"5773\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-620\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-620<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 28, 2024<\/p>\n\n<p>On October 28, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 17.7.1<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 18.1<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 version prior to 15.1<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.7.1<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.7.1<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 18.1<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 2.1<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 11.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-620","alert_type":396,"serial_number":"AV24-620","subject":"apple","moderation_state":"published","external_url":null},{"nid":5774,"title":"HPE security advisory (AV24-621)","uuid":"bed6076a-f237-498f-998c-820a9d6a9c34","banner":null,"lang":"en","date_modified":"2024-10-28","date_modified_ts":"2024-10-28T21:42:07Z","date_created":"2024-10-28T21:35:41Z","summary":null,"body":["<article data-history-node-id=\"5774\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-621\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-621\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 28, 2024\n<\/p>\n<p>On October 28, 2024, HPE published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>HP-UX 11i Secure Shell Software\u00a0\u2013 versions prior to A.09.30.007<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04725en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbux04725en_us<\/a><\/li>\n  <li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-621","alert_type":396,"serial_number":"AV24-621","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5776,"title":"Mozilla security advisory (AV24-622)","uuid":"23d01432-4a7f-4c5f-b46a-73c36fe00879","banner":null,"lang":"en","date_modified":"2024-10-29","date_modified_ts":"2024-10-29T15:14:49Z","date_created":"2024-10-29T15:07:46Z","summary":null,"body":["<article data-history-node-id=\"5776\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-622\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-622<br \/><strong>Date: <\/strong>October 29, 2024<\/p>\n\n<p>On October\u00a029,\u00a02024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 132<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 128.4<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.17<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.4<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 132<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-622","alert_type":396,"serial_number":"AV24-622","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5778,"title":"Apple security advisory (AV24-623)","uuid":"56103d92-b92c-4ef6-befc-2e77293a03bf","banner":null,"lang":"en","date_modified":"2024-10-30","date_modified_ts":"2024-10-30T14:18:11Z","date_created":"2024-10-30T14:10:47Z","summary":null,"body":["<article data-history-node-id=\"5778\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-623\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-623<br \/><strong>Date: <\/strong>October 30, 2024<\/p>\n\n<p>On October\u00a029,\u00a02024, Apple published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari\u00a0\u2013 versions prior to 18.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/121571\">About the security content of Safari 18.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-623","alert_type":396,"serial_number":"AV24-623","subject":"apple","moderation_state":"published","external_url":null},{"nid":5780,"title":"ServiceNow security advisory (AV24-624)","uuid":"0fcd563c-3d39-4ad3-acc9-54ac0f7aa883","banner":null,"lang":"en","date_modified":"2024-10-30","date_modified_ts":"2024-10-30T17:42:01Z","date_created":"2024-10-30T17:36:05Z","summary":null,"body":["<article data-history-node-id=\"5780\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av24-624\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-624<br \/><strong>Date: <\/strong>October\u00a030, 2024<\/p>\n\n<p>On October\u00a029, 2024, ServiceNow published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>ServiceNow Vancouver\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Washington DC\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Xanadu\u00a0\u2013 versions prior to GA<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1706070\">CVE-2024-8923\u00a0- Sandbox Escape in Now Platform<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1706072\">CVE-2024-8924\u00a0- Unauthenticated Blind SQL Injection in Core Platform<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av24-624","alert_type":396,"serial_number":"AV24-624","subject":"other","moderation_state":"published","external_url":null},{"nid":5781,"title":"Google Chrome security advisory (AV24-625)","uuid":"86fd0fdb-0fa8-457d-b836-f915a596909d","banner":null,"lang":"en","date_modified":"2024-10-31","date_modified_ts":"2024-10-31T14:48:40Z","date_created":"2024-10-31T14:42:40Z","summary":null,"body":["<article data-history-node-id=\"5781\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-625\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-625<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 31, 2024<\/p>\n\n<p>On October 29, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 130.0.6723.91\/.92 (Windows and Mac) and 130.0.6723.91 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/10\/stable-channel-update-for-desktop_29.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-French-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-625","alert_type":396,"serial_number":"AV24-625","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5784,"title":"Microsoft Edge security advisory (AV24-626)","uuid":"086f5602-7219-485f-97c9-d4ef050785f0","banner":null,"lang":"en","date_modified":"2024-11-01","date_modified_ts":"2024-11-01T19:41:24Z","date_created":"2024-11-01T19:10:40Z","summary":null,"body":["<article data-history-node-id=\"5784\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-626\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-626<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 1, 2024<\/p>\n\n<p>On October 31, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft Edge Stable Channel<\/span>\u00a0\u2013 versions prior to 130.0.2849.68<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-31-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-626","alert_type":396,"serial_number":"AV24-626","subject":"other","moderation_state":"published","external_url":null},{"nid":5786,"title":"Ubuntu security advisory (AV24-629)","uuid":"0d2e45fd-71fe-4c4b-898c-841e4f02c361","banner":null,"lang":"en","date_modified":"2024-11-04","date_modified_ts":"2024-11-04T17:03:41Z","date_created":"2024-11-04T16:56:51Z","summary":null,"body":["<article data-history-node-id=\"5786\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-629\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-629<br \/><strong>Date: <\/strong>November 4, 2024<\/p>\n\n<p>Between October\u00a028 and November\u00a03, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-629","alert_type":396,"serial_number":"AV24-629","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5785,"title":"Dell security advisory (AV24-627)","uuid":"97083693-8c12-414d-9504-f96e30800f63","banner":null,"lang":"en","date_modified":"2024-11-04","date_modified_ts":"2024-11-04T17:01:00Z","date_created":"2024-11-04T16:57:44Z","summary":null,"body":["<article data-history-node-id=\"5785\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-627\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-627<br \/><strong>Date: <\/strong>November\u00a04, 2024<\/p>\n\n<p>Between October\u00a028 and November\u00a03, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>PowerStore 1000X\u00a0\u2013 versions prior to 3.2.1.4-2386214<\/li>\n\t<li>PowerStore 3000X\u00a0\u2013 versions prior to 3.2.1.4-2386214<\/li>\n\t<li>PowerStore 5000X\u00a0\u2013 versions prior to 3.2.1.4-2386214<\/li>\n\t<li>PowerStore 7000X\u00a0\u2013 versions prior to 3.2.1.4-2386214<\/li>\n\t<li>PowerStore 9000X\u00a0\u2013 versions prior to 3.2.1.4-2386214<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000242275\/dsa-2024-432-dell-powerstore-x-security-update-for-multiple-vulnerabilities\">DSA-2024-432: Dell PowerStore X Security Update for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-627","alert_type":396,"serial_number":"AV24-627","subject":"dell","moderation_state":"published","external_url":null},{"nid":5789,"title":"Red Hat security advisory (AV24-630)","uuid":"a6217605-780b-48e5-bb74-1a24a6537d23","banner":null,"lang":"en","date_modified":"2024-11-04","date_modified_ts":"2024-11-04T18:00:37Z","date_created":"2024-11-04T16:57:44Z","summary":null,"body":["<article data-history-node-id=\"5789\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-630\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-630<br \/><strong>Date: <\/strong>November\u00a04, 2024<\/p>\n\n<p>Between October\u00a028 and November\u00a03, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platform<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:8617\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:8617<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:8616\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:8616<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:8614\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:8614<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:8613\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:8613<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-630","alert_type":396,"serial_number":"AV24-630","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5787,"title":"IBM security advisory (AV24-628)","uuid":"291620fc-2662-47ad-b76a-83d93d1c490b","banner":null,"lang":"en","date_modified":"2024-11-04","date_modified_ts":"2024-11-04T17:01:51Z","date_created":"2024-11-04T16:57:51Z","summary":null,"body":["<article data-history-node-id=\"5787\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-628\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-628<br \/><strong>Date: <\/strong>November\u00a04, 2024<\/p>\n\n<p>Between October\u00a028 and November\u00a03, 2024 IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Business Automation Insights\u00a0\u2013 version 24.0.0<\/li>\n\t<li>IBM Business Automation Workflow containers\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Workflow traditional\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM ICP\u00a0- Discovery\u00a0\u2013 versions 4.0.0 to 4.8.5 and 5.0.0<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 version 7.5 to 7.5.0 UP10<\/li>\n\t<li>IBM Storage Protect Server\u00a0\u2013 version 8.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-628","alert_type":396,"serial_number":"AV24-628","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5788,"title":"[Control systems] CISA ICS security advisories (AV24-631)","uuid":"4d5a7044-7b96-410f-8e8e-5a2627bff932","banner":null,"lang":"en","date_modified":"2024-11-04","date_modified_ts":"2024-11-04T18:05:12Z","date_created":"2024-11-04T17:08:27Z","summary":null,"body":["<article data-history-node-id=\"5788\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-631\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-631<br \/><strong>Date: <\/strong>November 4, 2024<\/p>\n\n<p>Between October\u00a028 and November\u00a03,\u00a02024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics InfraSuite Device Master\u00a0\u2013 versions 1.0.12 and prior<\/li>\n\t<li>Siemens InterMesh 7177 Hybrid 2.0 Subscriber\u00a0\u2013 versions prior to V8.2.12<\/li>\n\t<li>Siemens InterMesh 7707 Fire Subscriber\u00a0\u2013 versions prior to V7.2.12<\/li>\n\t<li>Solar-Log Base 15\u00a0\u2013 firmware version 6.0.1 Build 161<\/li>\n\t<li>Rockwell Automation FactoryTalk ThinManager\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-631","alert_type":398,"serial_number":"AV24-631","subject":"ics","moderation_state":"published","external_url":null},{"nid":5790,"title":"Android security advisory \u2013 November 2024 Monthly Rollup (AV24-632)","uuid":"b287e538-5493-429a-b6bb-56e3dabc5adf","banner":null,"lang":"en","date_modified":"2024-11-04","date_modified_ts":"2024-11-04T19:09:20Z","date_created":"2024-11-04T19:05:37Z","summary":null,"body":["<article data-history-node-id=\"5790\" about=\"\/en\/alerts-advisories\/android-security-advisory-november-2024-monthly-rollup-av24-632\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-632<br \/><strong>Date: <\/strong>November\u00a04, 2024<\/p>\n\n<p>On November\u00a04, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-11-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-november-2024-monthly-rollup-av24-632","alert_type":396,"serial_number":"AV24-632","subject":"android","moderation_state":"published","external_url":null},{"nid":5792,"title":"Google Chrome security advisory (AV24-633)","uuid":"62d867e2-c769-4aad-a28b-7f73bd142133","banner":null,"lang":"en","date_modified":"2024-11-05","date_modified_ts":"2024-11-05T19:39:14Z","date_created":"2024-11-05T19:36:23Z","summary":null,"body":["<article data-history-node-id=\"5792\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-633\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-633<br \/><strong>Date: <\/strong>November\u00a05, 2024<\/p>\n\n<p>On November\u00a05, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 130.0.6723.116\/.117 (Windows and Mac) and 130.0.6723.116 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/11\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-633","alert_type":396,"serial_number":"AV24-633","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5793,"title":"HPE security advisory (AV24-634)","uuid":"7a8689a4-8ec1-46e4-ba9b-28a3d2de935e","banner":null,"lang":"en","date_modified":"2024-11-06","date_modified_ts":"2024-11-06T15:26:34Z","date_created":"2024-11-06T15:17:02Z","summary":null,"body":["<article data-history-node-id=\"5793\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-634\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-634<br \/><strong>Date: <\/strong>November\u00a06, 2024<\/p>\n\n<p>On November\u00a05, 2024, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking Access Point\u00a0- version AOS-10.4.x.x\u00a0\u2013 10.4.1.4 and prior<\/li>\n\t<li>HPE Aruba Networking Access Point\u00a0- version Instant AOS-8.12.x.x\u00a0\u2013 8.12.0.2 and prior<\/li>\n\t<li>HPE Aruba Networking Access Point\u00a0- version Instant AOS-8.10.x.x\u00a0\u2013 8.10.0.13 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04722en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbnw04722en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-634","alert_type":396,"serial_number":"AV24-634","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5795,"title":"Cisco security advisory (AV24-635)","uuid":"e6976505-a682-4aeb-a7c1-0ee4c22f4586","banner":null,"lang":"en","date_modified":"2024-11-06","date_modified_ts":"2024-11-06T18:34:03Z","date_created":"2024-11-06T18:21:51Z","summary":null,"body":["<article data-history-node-id=\"5795\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av24-635\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-635<br \/><strong>Date: <\/strong>November 6, 2024<\/p>\n\n<p>On November\u00a06,\u00a02024, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Unified Industrial Wireless Software\u00a0\u2013 version 17.14 and prior<\/li>\n\t<li>Cisco Unified Industrial Wireless Software\u00a0\u2013 version 17.15<\/li>\n\t<li>Cisco Nexus Dashboard Fabric Controller (NDFC)\u00a0\u2013 versions 12.1.2 and 12.1.3<\/li>\n\t<li>Cisco Enterprise Chat and Email (ECE)\u00a0\u2013 versions 12.5 and prior<\/li>\n\t<li>Cisco Enterprise Chat and Email (ECE)\u00a0\u2013 version 12.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-backhaul-ap-cmdinj-R7E28Ecs\">Cisco Security Advisory\u00a0\u2013 cisco-sa-backhaul-ap-cmdinj-R7E28Ecs<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ndfc-sqli-CyPPAxrL\">Cisco Security Advisory\u00a0\u2013 cisco-sa-ndfc-sqli-CyPPAxrL<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ece-dos-Oqb9uFEv#fs\">Cisco Security Advisory\u00a0\u2013 cisco-sa-ece-dos-Oqb9uFEv<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av24-635","alert_type":396,"serial_number":"AV24-635","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5796,"title":"Drupal security advisory (AV24-636)","uuid":"86cd4f09-95a6-46a6-8be2-5c566fd97354","banner":null,"lang":"en","date_modified":"2024-11-06","date_modified_ts":"2024-11-06T20:01:21Z","date_created":"2024-11-06T19:54:28Z","summary":null,"body":["<article data-history-node-id=\"5796\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-636\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-636<br \/><strong>Date: <\/strong>November\u00a06, 2024<\/p>\n\n<p>On November\u00a06, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Basic HTTP Authentication\u00a0\u2013 versions prior to 7.x-1.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-057\">Drupal Security Advisory\u00a0- SA-CONTRIB-2024-057<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-636","alert_type":396,"serial_number":"AV24-636","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5801,"title":"Veeam security advisory (AV24-637)","uuid":"7416fdfd-a1e5-4452-890b-5042f3e4f92c","banner":null,"lang":"en","date_modified":"2024-11-08","date_modified_ts":"2024-11-08T14:08:06Z","date_created":"2024-11-08T13:57:07Z","summary":null,"body":["<article data-history-node-id=\"5801\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av24-637\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-637\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 8,\n<\/p>\n<p>On November 6, 2024, Veeam published security advisories to address a vulnerability in the following product:\n<\/p>\n<ul><li>Veeam Backup Enterprise Manager\u00a0\u2013 versions prior to 12.2.0.334<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4682\">Veeam Security Advisory\u00a0\u2013 kb4682<\/a><\/li>\n  <li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av24-637","alert_type":396,"serial_number":"AV24-637","subject":"other","moderation_state":"published","external_url":null},{"nid":5802,"title":"Microsoft Edge security advisory (AV24-638)","uuid":"758b6c5c-5a81-4324-98d7-e55d3b466600","banner":null,"lang":"en","date_modified":"2024-11-08","date_modified_ts":"2024-11-08T16:41:23Z","date_created":"2024-11-08T16:23:46Z","summary":null,"body":["<article data-history-node-id=\"5802\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-638\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-638<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 8, 2024<\/p>\n\n<p>On November 7, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 0.2849.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-7-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-638","alert_type":396,"serial_number":"AV24-638","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5804,"title":"IBM security advisory (AV24-639)","uuid":"8e051db4-0944-4db9-8e01-d9424b4d1feb","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T18:30:15Z","date_created":"2024-11-12T18:23:54Z","summary":null,"body":["<article data-history-node-id=\"5804\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-639\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-639<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>Between November 4 and 10, 2024 IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>AIX\u00a0\u2013 versions 7.2 and 7.3<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 versions 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Cloud Transformation Advisor\u00a0\u2013 versions 2.0.1 to 3.10.1<\/li>\n\t<li>QRadar Suite Software \u2013 versions 1.10.12.0 to 1.10.26.0<\/li>\n\t<li>VIOS\u00a0\u2013 versions 3.1 and 4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-639","alert_type":396,"serial_number":"AV24-639","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5805,"title":"[Control systems] CISA ICS security advisories (AV24-640) ","uuid":"e494d6af-482d-4483-96b2-ab45d56b5e41","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T18:39:59Z","date_created":"2024-11-12T18:33:52Z","summary":null,"body":["<article data-history-node-id=\"5805\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-640\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-640<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>Between November 4 and 10, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Beckhoff Automation TwinCAT Package Manager \u2013 versions prior to 1.0.603.0<\/li>\n\t<li>Bosch Rexroth IndraDrive FWA-INDRV*-MP* \u2013 versions 17VRS to versions prior to 20V36<\/li>\n\t<li>Delta Electronics DIAScreen \u2013 versions prior to v1.5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96 \">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-640","alert_type":398,"serial_number":"AV24-640","subject":"ics","moderation_state":"published","external_url":null},{"nid":5807,"title":"Ubuntu security advisory (AV24-641)","uuid":"fdf75715-63ea-460d-bbce-0d7ac6f4515a","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T18:50:21Z","date_created":"2024-11-12T18:43:06Z","summary":null,"body":["<article data-history-node-id=\"5807\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-641\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-641<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>Between November 4 and 10, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-641","alert_type":396,"serial_number":"AV24-641","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5808,"title":"Red Hat security advisory (AV24-642)","uuid":"4d8fbe80-8f32-4133-b422-1bd137c6d5af","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T18:57:21Z","date_created":"2024-11-12T18:51:57Z","summary":null,"body":["<article data-history-node-id=\"5808\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-642\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-642<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>Between November 4 and 10, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux for x86_64 8 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux for IBM z Systems 8 s390x<\/li>\n\t<li>Red Hat Enterprise Linux for Power, little endian 8 ppc64le<\/li>\n\t<li>Red Hat Enterprise Linux for ARM 64 8 aarch64<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time 8 x86_64<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time for NFV 8 x86_64<\/li>\n\t<li>Red Hat CodeReady Linux Builder for x86_64 8 x86_64<\/li>\n\t<li>Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le<\/li>\n\t<li>Red Hat CodeReady Linux Builder for ARM 64 8 aarch64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:8856 \">Red Hat Security Advisory \u2013 RHSA-2024:8856<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:8870\">Red Hat Security Advisory \u2013 RHSA-2024:8870<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\u2003\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-642","alert_type":396,"serial_number":"AV24-642","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5809,"title":"[Control systems] Siemens security advisory (AV24-643) ","uuid":"b8cd3302-c186-475a-9e2e-b6ee6e715f51","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T20:36:44Z","date_created":"2024-11-12T20:32:18Z","summary":null,"body":["<article data-history-node-id=\"5809\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-643\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-643<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>On November 12, 2024, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Mendix Runtime V8, V9, V10, V10.6 and V10.12 \u2013 multiple versions<\/li>\n\t<li>OZW671 and OZW772 \u2013 versions prior to V5.2<\/li>\n\t<li>RUGGEDCOM CROSSBOW Station Access Controller \u2013 versions prior to V5.6<\/li>\n\t<li>SCALANCE M-800 family \u2013 versions prior to V8.2<\/li>\n\t<li>SIMATIC CP 1543-1 V4.0 \u2013 versions prior to V4.0.50<\/li>\n\t<li>SIMATIC S7-PLCSIM V16 and V17 \u2013 all versions<\/li>\n\t<li>SINEC INS \u2013 versions prior to V1.0 SP2 Update 3<\/li>\n\t<li>SINEC NSM \u2013 versions prior to V3.0 SP1<\/li>\n\t<li>SIPORT \u2013 versions prior to V3.4.0<\/li>\n\t<li>Solid Edge Se2024 \u2013 versions prior to V224.0 Update 9<\/li>\n\t<li>Spectrum Power 7 \u2013 versions prior to V24Q3<\/li>\n\t<li>TeleControl Server Basic V3.1 \u2013 versions prior to V3.1.2.1<\/li>\n\t<li>Totally Integrated Automation Portal<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-643","alert_type":398,"serial_number":"AV24-643","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5810,"title":"Citrix security advisory (AV24-644)","uuid":"11a41b0c-ba12-42d0-9a3e-6c956ef1b015","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T20:46:30Z","date_created":"2024-11-12T20:40:58Z","summary":null,"body":["<article data-history-node-id=\"5810\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av24-644\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-644<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>On November 12, 2024, Citrix published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway\u202f14.1 \u2013 versions prior to 14.1-29.72<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway\u202f13.1\u202f\u2013 versions prior to 13.1-55.34<\/li>\n\t<li>NetScaler ADC 13.1-FIPS \u2013 versions prior to 13.1-37.207<\/li>\n\t<li>NetScaler ADC 12.1-FIPS \u2013 versions prior to 12.1-55.321<\/li>\n\t<li>NetScaler ADC 12.1-NDcPP \u2013 versions prior to 12.1-55.321<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/s\/article\/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US \">Citrix Security Advisory \u2013 CTX691608<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av24-644","alert_type":396,"serial_number":"AV24-644","subject":"citrix","moderation_state":"published","external_url":null},{"nid":5811,"title":"SAP security advisory \u2013 November 2024 monthly rollup (AV24-645)","uuid":"7f164d1f-7155-483b-a8ce-66f783ae855e","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T20:53:23Z","date_created":"2024-11-12T20:49:20Z","summary":null,"body":["<article data-history-node-id=\"5811\" about=\"\/en\/alerts-advisories\/sap-security-advisory-november-2024-monthly-rollup-av24-645\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-645<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>On November 12, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>SAP Web Dispatcher\u00a0\u2013 versions WEBDISP 7.77, 7.89, 7.93, KERNEL 7.77, 7.89, 7.93, 9.12 and 9.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/november-2024.html \">SAP Security Patch Day \u2013 November 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-november-2024-monthly-rollup-av24-645","alert_type":396,"serial_number":"AV24-645","subject":"sap","moderation_state":"published","external_url":null},{"nid":5812,"title":"[Control systems] Schneider Electric security advisory (AV24-646) ","uuid":"1eb1e4df-1af6-4910-91b7-a289e2938caf","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T21:20:26Z","date_created":"2024-11-12T21:15:27Z","summary":null,"body":["<article data-history-node-id=\"5812\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-646\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-646<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>On November 12, 2024, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure IT Gateway \u2013 versions 1.21.0.6, 1.22.0.3, 1.22.1.5 and 1.23.0.4<\/li>\n\t<li>Modicon M340 CPU, MC80 and Momentum Unity M1E Processor \u2013 all versions<\/li>\n\t<li>PowerLogic PM5320 \u2013 version 2.3.8 and prior<\/li>\n\t<li>PowerLogic PM5340 \u2013 version 2.3.8 and prior<\/li>\n\t<li>PowerLogic PM5341 \u2013 version 2.6.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/doc\/SEVD-2024-317-04\/SEVD-2024-317-04.pdf\">Schneider Electric Security Notification\u00a0- EcoStruxure IT Gateway<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/doc\/SEVD-2024-317-03\/SEVD-2024-317-03.pdf\">Schneider Electric Security Notification\u00a0- Modicon Controllers M340\u00a0\/\u00a0Momentum\u00a0\/\u00a0MC80<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/doc\/SEVD-2024-317-02\/SEVD-2024-317-02.pdf \">Schneider Electric Security Notification\u00a0- Modicon Controllers M340\u00a0\/\u00a0Momentum\u00a0\/\u00a0MC80<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/doc\/SEVD-2024-317-01\/SEVD-2024-317-01.pdf\">Schneider Electric Security Notification\u00a0- PowerLogic PM5300 Series<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp \">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-646","alert_type":396,"serial_number":"AV24-646","subject":"other","moderation_state":"published","external_url":null},{"nid":5813,"title":"HPE security advisory (AV24-647)","uuid":"3d91172b-c12c-45c0-8f9a-1db887896ac4","banner":null,"lang":"en","date_modified":"2024-11-12","date_modified_ts":"2024-11-12T21:35:53Z","date_created":"2024-11-12T21:26:59Z","summary":null,"body":["<article data-history-node-id=\"5813\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-647\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-647<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2024<\/p>\n\n<p>On November 12, 2024, HPE published a security advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HPE Alletra 4110 \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE Alletra 4120 \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE Alletra 4140 \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE Compute Edge Server e930t \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE Cray XD665 \u2013 versions prior to 1.50 (Cray SC XD665 Firmware Pack 2024.09.00)<\/li>\n\t<li>HPE Cray XD670 \u2013 versions prior to 2.01<\/li>\n\t<li>HPE Cray EX235a Accelerator Blade \u2013 versions prior to 1.9.0 (HFP 24.9.0)<\/li>\n\t<li>HPE Cray EX235n Server \u2013 versions prior to 1.4.0 (HFP 24.8.1)<\/li>\n\t<li>HPE Cray EX254n Accelerator Blade \u2013 versions prior to 1.9.0 (HFP 24.8.1)<\/li>\n\t<li>HPE Cray EX255a Accelerator Blade \u2013 versions prior to 1.1.1 (HFP 24.9.0)<\/li>\n\t<li>HPE Cray EX420 Compute Blade \u2013 versions prior to 1.3.2 (HFP 24.8.1)<\/li>\n\t<li>HPE Cray EX425 Compute Blade \u2013 versions prior to 1.7.4 (HFP 24.8.1)<\/li>\n\t<li>HPE Cray EX4252 Compute Blade \u2013 versions prior to 1.7.0 (HFP 24.9.0)<\/li>\n\t<li>HPE IP Meditation \u2013 versions prior to 8.5.1<\/li>\n\t<li>HPE ProLiant DL110 Gen11 \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant DL320 Gen11 Server \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant DL360 Gen11 Server \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant DL380 Gen11 Server \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant DL380a Gen11 \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant DL560 Gen11 \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant ML110 Gen11 \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant ML350 Gen11 Server \u2013 versions prior to 2.30_08-09-2024<\/li>\n\t<li>HPE ProLiant XL645d Gen10 Plus Server \u2013 versions prior to v3.10 (HFP 24.8.1)<\/li>\n\t<li>HPE ProLiant XL675d Gen10 Plus Server \u2013 versions prior to v3.10 (HFP 24.8.1)<\/li>\n\t<li>HPE Synergy 480 Gen11 Compute Module \u2013 versions prior to 2.30_08-09-2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US \">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-647","alert_type":396,"serial_number":"AV24-647","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5814,"title":"Adobe security advisory (AV24\u2013648)","uuid":"b10e1ef7-580a-414b-a3d0-a1c7ffced8a9","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T14:50:19Z","date_created":"2024-11-13T14:32:56Z","summary":null,"body":["<article data-history-node-id=\"5814\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-648\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-648<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 12, 2024, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe After Effects\u00a0\u2013 version 24.6.2 and prior, version 23.6.9 and prior<\/li>\n\t<li>Adobe Audition\u00a0\u2013 version 24.4.6 and prior, version 23.6.9 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 13.0.9 and prior, version 14.1.2 and prior<\/li>\n\t<li>Adobe Commerce and Magento Open Source\u00a0\u2013 version 3.2.5 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.5 and prior, version ID18.5.3 and prior and version ID18.5.2 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 10.1.0 and prior<\/li>\n\t<li>Illustrator 2024\u00a0\u2013 version 28.7.1 and prior<\/li>\n\t<li>Photoshop 2023\u00a0\u2013 version 24.7.3 and prior<\/li>\n\t<li>Photoshop 2024\u00a0\u2013 version 25.11 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-648","alert_type":396,"serial_number":"AV24-648","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5815,"title":"Microsoft security advisory \u2013 November 2024 monthly rollup (AV24\u2013649)","uuid":"17c2f31a-1e6f-4033-b1c8-a3c6f2119219","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T15:16:15Z","date_created":"2024-11-13T14:54:37Z","summary":null,"body":["<article data-history-node-id=\"5815\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-november-2024-monthly-rollup-av24-649\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-649<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 12, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>.NET 9.0<\/li>\n\t<li>Azure CycleCloud\u00a0\u2013 multiple versions<\/li>\n\t<li>Azure Database for PostgreSQL Flexible Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>LightGBM<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Defender for Endpoint<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft PC Manager<\/li>\n\t<li>Microsoft SQL Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft TorchGeo<\/li>\n\t<li>Microsoft Visual Studio 2022\u00a0\u2013 multiple versions<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Python extension for Visual Studio Code<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>microsoft.com<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-49039 and CVE-2024-43451 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Nov\">November 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-november-2024-monthly-rollup-av24-649","alert_type":396,"serial_number":"AV24-649","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5819,"title":"Ivanti security advisory (AV24-650)","uuid":"1f5a0e56-4623-40e7-9439-06189b3824c8","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T16:54:30Z","date_created":"2024-11-13T16:25:27Z","summary":null,"body":["<article data-history-node-id=\"5819\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-650\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-650<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 12, 2024, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Avalanche\u00a0\u2013 version 6.4.5 and prior<\/li>\n\t<li>Ivanti Connect Secure (ICS)\u00a0\u2013 version 22.7R2.2 and prior<\/li>\n\t<li>Ivanti Endpoint Manager (EPM)\u00a0\u2013 version 2024 September security update and prior, version 2022 SU6 September security update and prior<\/li>\n\t<li>Ivanti Policy Secure (IPS)\u00a0\u2013 version 22.7R1.1 and prior<\/li>\n\t<li>Ivanti Secure Access Client (ISAC)\u00a0\u2013 version 22.7R3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022?language=en_US\">Ivanti\u00a0\u2013 Security patch release\u00a0- Security Advisory EPM November 2024 for EPM 2024 and EPM 2022 SU6<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Avalanche-Multiple-CVEs-Q4-2024-Release?language=en_US\">Ivanti\u00a0\u2013 Security patch release\u00a0- Security Advisory Ivanti Avalanche (Multiple CVEs)\u00a0- Q4 2024 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US\">Ivanti\u00a0\u2013 Security patch release\u00a0- Security Advisory Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), Ivanti Secure Access Client (ISAC) (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-650","alert_type":396,"serial_number":"AV24-650","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5820,"title":"Google Chrome security advisory (AV24-651)","uuid":"5ed12579-725e-4569-8285-6e17bb90bd57","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T17:05:32Z","date_created":"2024-11-13T16:59:57Z","summary":null,"body":["<article data-history-node-id=\"5820\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-651\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-651<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 12, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 131.0.6778.69\/.70 (Windows and Mac) and 131.0.6778.69 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/11\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-651","alert_type":396,"serial_number":"AV24-651","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5821,"title":"Mozilla security advisory (AV24-652)","uuid":"b6aaeb8d-197c-4d4c-a714-6d0e42f58711","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T17:14:54Z","date_created":"2024-11-13T17:08:41Z","summary":null,"body":["<article data-history-node-id=\"5821\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-652\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-652<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 12, 2024, Mozilla published security advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 132.0.1<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 128.4.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-61\/\">Mozilla Security Advisory (MFSA 2024-61)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-62\/\">Mozilla Security Advisory (MFSA 2024-62)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-652","alert_type":396,"serial_number":"AV24-652","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5825,"title":"GitLab security advisory (AV24-653)","uuid":"8e7aa16d-02ad-45d6-ab29-995131ceb10d","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T18:37:11Z","date_created":"2024-11-13T18:04:48Z","summary":null,"body":["<article data-history-node-id=\"5825\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-653\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-653<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 13, 2024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.5.2, 17.4.4 and 17.3.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.5.2, 17.4.4 and 17.3.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/11\/13\/patch-release-gitlab-17-5-2-released\/\">GitLab Patch Release: 17.5.2, 17.4.4, 17.3.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-653","alert_type":396,"serial_number":"AV24-653","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5826,"title":"Drupal security advisory (AV24-654) ","uuid":"3ddee45d-3704-47f9-b7d2-76dd59e3aacb","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T18:48:38Z","date_created":"2024-11-13T18:44:40Z","summary":null,"body":["<article data-history-node-id=\"5826\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-654\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-654<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 13, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>POST File \u2013 versions prior to 1.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-060\">Drupal Security Advisory - SA-CONTRIB-2024-060 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-654","alert_type":396,"serial_number":"AV24-654","subject":"other","moderation_state":"published","external_url":null},{"nid":5827,"title":"Intel security advisory (AV24-655) ","uuid":"849342c6-0b6f-4a91-8979-582021d2d161","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T19:48:07Z","date_created":"2024-11-13T19:42:28Z","summary":null,"body":["<article data-history-node-id=\"5827\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av24-655\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-655<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 12, 2024, Intel published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Intel Neural Compressor software \u2013 versions prior to v3.0<\/li>\n\t<li>Intel Endpoint Management Assistant software \u2013 versions prior to 1.13.1.0<\/li>\n\t<li>Intel Computing Improvement Program software \u2013 versions prior to 2.4.10852<\/li>\n\t<li>Intel Atom, Celeron, Core, Pentium and XEON CPUs \u2013 multiple models<\/li>\n\t<li>Intel Server Board S2600ST, S2600BP, S2600BPBR, M20NTP, M10JPN2SB and M70KLP Families \u2013 all firmware versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html \">Intel Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av24-655","alert_type":396,"serial_number":"AV24-655","subject":"intel","moderation_state":"published","external_url":null},{"nid":5828,"title":"[Control systems] Siemens security advisory (AV24-656) ","uuid":"aaa92dff-018e-4671-bf02-5d6231beb4af","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T20:12:38Z","date_created":"2024-11-13T20:06:32Z","summary":null,"body":["<article data-history-node-id=\"5828\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-656\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-656<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 13, 2024, Siemens published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Siveillance Video<\/span>\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-472448.html\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Siemens Security Advisory<\/span>\u00a0- SSA-472448<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Siemens Security Advisories<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-656","alert_type":398,"serial_number":"AV24-656","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5829,"title":"Palo Alto Networks security advisory (AV24-657)","uuid":"8cd686c5-363d-4a43-b397-8f111efb0d1c","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T20:34:49Z","date_created":"2024-11-13T20:21:47Z","summary":null,"body":["<article data-history-node-id=\"5829\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-657\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-657<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 13, 2024, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Prisma Access Browser\u00a0\u2013 versions prior to 130.59.2920.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2024-0016\">Palo Alto Networks Security Advisories\u00a0\u2013 PAN-SA-2024-0016<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-657","alert_type":396,"serial_number":"AV24-657","subject":"other","moderation_state":"published","external_url":null},{"nid":5830,"title":"Jenkins security advisory (AV24-658)","uuid":"a5f0f4bb-692f-42fb-b653-8b261063d191","banner":null,"lang":"en","date_modified":"2024-11-13","date_modified_ts":"2024-11-13T21:15:49Z","date_created":"2024-11-13T21:10:38Z","summary":null,"body":["<article data-history-node-id=\"5830\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av24-658\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-658<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2024<\/p>\n\n<p>On November 13, 2024, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Authorize Project Plugin\u00a0\u2013 version 1.7.2 and prior<\/li>\n\t<li>IvyTrigger Plugin\u00a0\u2013 version 1.01 and prior<\/li>\n\t<li>OpenId Connect Authentication Plugin\u00a0\u2013 version 4.418.vccc7061f5b_6d and prior<\/li>\n\t<li>Pipeline: Declarative Plugin\u00a0\u2013 version 2.2214.vb_b_34b_2ea_9b_83 and prior<\/li>\n\t<li>Pipeline: Groovy Plugin\u00a0\u2013 version 3990.vd281dd77a_388 and prior<\/li>\n\t<li>Script Security Plugin\u00a0\u2013 version 1367.vdf2fc45f229c and prior<\/li>\n\t<li>Shared Library Version Override Plugin\u00a0\u2013 version 17.v786074c9fce7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2024-11-13\/\">Jenkins Security Advisory 2024-11-13<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av24-658","alert_type":396,"serial_number":"AV24-658","subject":"other","moderation_state":"published","external_url":null},{"nid":5838,"title":"Microsoft Edge security advisory (AV24-659)","uuid":"6a644e47-7fbf-4204-99ef-c7a0dd8083d2","banner":null,"lang":"en","date_modified":"2024-11-15","date_modified_ts":"2024-11-15T16:35:02Z","date_created":"2024-11-15T16:29:58Z","summary":null,"body":["<article data-history-node-id=\"5838\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-659\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-659<br \/><strong>Date: <\/strong>November 15, 2024<\/p>\n\n<p>On November\u00a014,\u00a02024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 130.2903.48<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-14-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-659","alert_type":396,"serial_number":"AV24-659","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5839,"title":"HPE security advisory (AV24-660)","uuid":"5d0c6d17-08a6-4085-8928-33f13102c698","banner":null,"lang":"en","date_modified":"2024-11-15","date_modified_ts":"2024-11-15T16:47:38Z","date_created":"2024-11-15T16:39:54Z","summary":null,"body":["<article data-history-node-id=\"5839\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-660\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-660<br \/><strong>Date: <\/strong>November 15, 2024<\/p>\n\n<p>On November\u00a014,\u00a02024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX OpenSSL Software\u00a0\u2013 versions prior to A.03.00.15.001<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04744en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbux04744<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-660","alert_type":396,"serial_number":"AV24-660","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5840,"title":"Securing Palo Alto management interfaces from exploitation - Update 1","uuid":"aa8e0b20-56ff-43a9-bee7-75b2940e987a","banner":null,"lang":"en","date_modified":"2024-11-19","date_modified_ts":"2024-11-19T21:59:49Z","date_created":"2024-11-15T19:59:17Z","summary":null,"body":["<article data-history-node-id=\"5840\" about=\"\/en\/alerts-advisories\/securing-palo-alto-management-interfaces-exploitation\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL24-011 Update 1<br \/><strong>Updated:<\/strong> November 19, 2024<br \/><strong>Date: <\/strong>November\u00a015, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Update 1<\/h2>\n\n<p>On November 18, 2024, Palo Alto Networks (PAN) updated advisory PAN-SA-2024-0015 to include more details about the affected products. PAN has also published CVE-2024-0012 PAN-OS to identify an authentication bypass in the Web Management Interface<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. In addition, the company published CVE-2024-9474 PAN-OS related to a privilege escalation (PE) vulnerability in the Web Management Interface<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre has included the details of the affected products under Suggested Actions below.<\/p>\n\n<p><abbr title=\"Cybersecurity and Infrastructure Security Agency\">CISA <\/abbr> added CVE-2024-0012 and CVE-2024-9474 to their Known Exploited Vulnerabilities (KEV) Catalog on the same date<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On November\u00a08, 2024, Palo Alto Networks (PAN) published an advisory (PAN-SA-2024-0015) regarding a claim of exploitation that the vendor was investigating. On November\u00a014, 2024, <abbr title=\"Palo Alto Networks\">PAN <\/abbr> updated the advisory to confirm that malicious activity has been observed targeting a limited number of <abbr title=\"Palo Alto Networks\">PAN <\/abbr> firewall management interfaces that are exposed to the Internet<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<p>The vendor confirms in the updated advisory that malicious actors have been observed exploiting an as-yet undisclosed unauthenticated remote command execution (RCE) vulnerability. It bears repeating that this is <strong>active exploitation<\/strong> by malicious actors.<\/p>\n\n<p>The Cyber Centre notes that the vendor has also updated advisory PAN-SA-2024-0010 (\"Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials\")<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>. The <abbr title=\"Palo Alto Networks\">PAN <\/abbr> advisory explicitly states that multiple vulnerabilities in Palo Alto Networks Expedition led to exposure of firewall credentials.<\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<h3>Update 1 November 19, 2024<\/h3>\n\n<p>The Cyber Centre strongly recommends that organizations patch affected devices to remediate these vulnerabilities. Consult the PAN \u201cbest practices\u201d deployment guide to ensure secure configuration for PAN devices.<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/p>\n\n<ul class=\"list-unstyled lst-spcd\"><li>Version: Cloud NGFW\n\t<ul><li>Affected: none<\/li>\n\t\t<li>Unaffected: all<\/li>\n\t<\/ul><\/li>\n\t<li>Version: PAN-OS 11.2\n\t<ul><li>Affected: &lt; 11.2.4-h1<\/li>\n\t\t<li>Unaffected: &gt;= 11.2.4-h1<\/li>\n\t<\/ul><\/li>\n\t<li>Version: PAN-OS 11.1\n\t<ul><li>Affected: &lt; 11.1.5-h1<\/li>\n\t\t<li>Unaffected: &gt;= 11.1.5-h1<\/li>\n\t<\/ul><\/li>\n\t<li>Version: PAN-OS 11.0\n\t<ul><li>Affected: &lt; 11.0.6-h1<\/li>\n\t\t<li>Unaffected: &gt;= 11.0.6-h1<\/li>\n\t<\/ul><\/li>\n\t<li>Version: PAN-OS 10.2\n\t<ul><li>Affected: &lt; 10.2.12-h1<\/li>\n\t\t<li>Unaffected: &gt;= 10.2.12-h1<\/li>\n\t<\/ul><\/li>\n\t<li>Version: PAN-OS 10.1\n\t<ul><li>Affected: none<\/li>\n\t\t<li>Unaffected: all<\/li>\n\t<\/ul><\/li>\n\t<li>Version: Cloud Prisma Access\n\t<ul><li>Affected: none<\/li>\n\t\t<li>Unaffected: all<\/li>\n\t<\/ul><\/li>\n<\/ul><p><strong>End of update 1<\/strong><\/p>\n\n<p>It is imperative that organizations review the inventory of <abbr title=\"Palo Alto Networks\">PAN <\/abbr> devices and applications in their networks and verify whether these products require patching and\/or further recommended mitigations.<\/p>\n\n<p>Organizations can verify whether they have any firewall management interfaces exposed to the Internet by consulting the Palo Alto Customer Support Portal (Products &gt; Assets &gt; All Assets &gt; Remediation Required)<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>.<\/p>\n\n<p>Devices and applications should then be configured according to the vendor's recommended best practices<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<p>Organizations should also review and implement the Cyber Centre's Top 10 IT Security Actions<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>consolidating, monitoring, and defending Internet gateways<\/li>\n\t<li>patching operating systems and applications<\/li>\n\t<li>isolating Web-facing applications<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><section><h2>Partner reporting<\/h2>\n\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2024\/11\/13\/palo-alto-networks-emphasizes-hardening-guidance\">Palo Alto Networks Emphasizes Hardening Guidance<\/a><\/p>\n<\/section><section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<p>Information provided by organizations not subject to the <em>Official Languages Act<\/em> is in the language(s) provided.<\/p>\n\n<p><strong>Update 1 November 19, 2024<\/strong><\/p>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-0012\">CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-9474\">CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/live.paloaltonetworks.com\/t5\/community-blogs\/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo\/ba-p\/46443\">Palo Alto Networks Best Practices Guide<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\"><abbr title=\"Cybersecurity and Infrastructure Security Agency\">CISA <\/abbr> Known Exploited Vulnerabilities Catalog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><p><strong>End of update 1<\/strong><\/p>\n\n<dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2024-0015\">PAN-SA-2024-0015 Critical Security Bulletin: Ensure Access to Management Interface is Secured<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2024-0010\">PAN-SA-2024-0010 Expedition: Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-578\">Palo Alto Networks security advisory (AV24-578)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/support.paloaltonetworks.com\/\">Palo Alto Customer Support Portal<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/live.paloaltonetworks.com\/t5\/community-blogs\/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo\/ba-p\/464431\">Tips &amp; Tricks: How to Secure the Management Access of Your Palo Alto Networks Device<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/securing-palo-alto-management-interfaces-exploitation","alert_type":397,"serial_number":"AL24-011","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5842,"title":"Ubuntu security advisory (AV24-663)","uuid":"6c199a2d-07fa-4759-9130-784361735abe","banner":null,"lang":"en","date_modified":"2024-11-18","date_modified_ts":"2024-11-18T18:40:55Z","date_created":"2024-11-18T18:19:03Z","summary":null,"body":["<article data-history-node-id=\"5842\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-663\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-663<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 18, 2024<\/p>\n\n<p>Between November 11 and 17, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 14.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-663","alert_type":396,"serial_number":"AV24-663","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5844,"title":"IBM security advisory (AV24-662)","uuid":"7dfd6d37-a973-48c0-82fb-23dde5e5ca17","banner":null,"lang":"en","date_modified":"2024-11-18","date_modified_ts":"2024-11-18T18:39:37Z","date_created":"2024-11-18T18:25:24Z","summary":null,"body":["<article data-history-node-id=\"5844\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-662\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-662<br \/><strong>Date: <\/strong>November\u00a018, 2024<\/p>\n\n<p>Between November\u00a011 and November\u00a017, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM App Connect Enterprise\u00a0\u2013 versions 12.0.1.0 to 12.0.12.7 and 13.0.1.0<\/li>\n\t<li>IBM CICS TX Advanced\u00a0\u2013 versions 10.1 and 11.1<\/li>\n\t<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM Cloud Pak for AIOps\u00a0\u2013 versions 4.1.0 to 4.7.0<\/li>\n\t<li>IBM DevOps Code ClearCase\u00a0\u2013 version 11.0<\/li>\n\t<li>IBM Event Streams\u00a0\u2013 versions 10.0.0 to 11.5.1<\/li>\n\t<li>IBM Integrated Analytics System\u00a0\u2013 version 1.0.0 to 1.0.30.0<\/li>\n\t<li>IBM Rational ClearCase\u00a0\u2013 versions 10.0.0 and 9.1<\/li>\n\t<li>IBM Sterling Secure Proxy\u00a0\u2013 versions 6.0.0.0 to 6.0.3.0 and 6.1.0.0<\/li>\n\t<li>IBM Tivoli Network Manager IP Edition\u00a0\u2013 version 4.2 GA to 4.2.0.19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-662","alert_type":396,"serial_number":"AV24-662","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5843,"title":"Dell security advisory (AV24-661)","uuid":"34064951-fb21-4e54-817e-8c0fdcf29c55","banner":null,"lang":"en","date_modified":"2024-11-18","date_modified_ts":"2024-11-18T18:35:19Z","date_created":"2024-11-18T18:25:24Z","summary":null,"body":["<article data-history-node-id=\"5843\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-661\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-661<br \/><strong>Date: <\/strong>November\u00a018, 2024<\/p>\n\n<p>Between November\u00a011 and November\u00a017, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>CyberSense\u00a0\u2013 versions 8.0 to 8.9<\/li>\n\t<li>Dell Connectrix Cisco MDS 9000 Series\u00a0\u2013 versions 12.0 to 12.2.1<\/li>\n\t<li>Dell NetWorker Server\u00a0\u2013 versions 19.10 to 19.10.0.5, versions 19.11 to 19.11.0.1, versions 19.8 to 19.8.0.4, versions 19.9 to 19.9.0.7 and versions prior to 19.8<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions 10.5.6.x, 10.5.5.x, and 10.5.4.x<\/li>\n\t<li>Dell Power Protect Data Manager\u00a0\u2013 versions prior to 19.17<\/li>\n\t<li>Dell PowerEdge Servers\u00a0\u2013 versions prior to 2.4.4<\/li>\n\t<li>Dell XC Core\u00a0\u2013 versions prior to 2.4.4<\/li>\n\t<li>PowerProtect Cyber Recovery\u00a0\u2013 versions prior to 19.17.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-661","alert_type":396,"serial_number":"AV24-661","subject":"dell","moderation_state":"published","external_url":null},{"nid":5845,"title":"Red Hat security advisory (AV24-664)","uuid":"3cbce2e6-c603-4117-b212-2c76e79e226b","banner":null,"lang":"en","date_modified":"2024-11-18","date_modified_ts":"2024-11-18T19:14:26Z","date_created":"2024-11-18T18:46:35Z","summary":null,"body":["<article data-history-node-id=\"5845\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-664\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-664<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 18, 2024<\/p>\n\n<p>Between November 11 and November 17, 2024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:9546\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:9546<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:9500\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:9500<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:9498\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:9498<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:9497\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:9497<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:9605\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:9605<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-664","alert_type":396,"serial_number":"AV24-664","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5847,"title":"[Control systems] Siemens security advisory (AV24-666)","uuid":"a4fcdb3b-e29e-468c-9e7c-5ae5985f0bcb","banner":null,"lang":"en","date_modified":"2024-11-19","date_modified_ts":"2024-11-19T12:41:50Z","date_created":"2024-11-18T19:20:41Z","summary":null,"body":["<article data-history-node-id=\"5847\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-666\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-666<br \/><strong>Date: <\/strong>November\u00a019, 2024<\/p>\n\n<p>On November\u00a018, 2024, Siemens published a security advisory to address vulnerabilities in the following products. Included were updates for the following:<\/p>\n\n<ul><li>Tecnomatix Plant Simulation\u00a0\u2013 versions prior to V2302.0018<\/li>\n\t<li>Tecnomatix Plant Simulation\u00a0\u2013 versions prior to V2404.0007<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-824503.html\">Siemens Security Advisories\u00a0- SSA-824503<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-666","alert_type":398,"serial_number":"AV24-666","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5846,"title":"[Control systems] CISA ICS security advisories (AV24\u2013665)","uuid":"eff4d5d4-ccba-4e76-a5c6-95c1f5cde42f","banner":null,"lang":"en","date_modified":"2024-11-18","date_modified_ts":"2024-11-18T20:08:14Z","date_created":"2024-11-18T19:24:33Z","summary":null,"body":["<article data-history-node-id=\"5846\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-665\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-665<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 18, 2024<\/p>\n\n<p>Between November 11 and November 17, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>2N Access Commander\u00a0\u2013 versions 3.1.1.2 and prior<\/li>\n\t<li>Baxter Life2000 Ventilation System\u00a0\u2013 version 06.08.00.00 and prior<\/li>\n\t<li>Hitachi Energy MSM\u00a0\u2013 versions 2.2.8 and prior<\/li>\n\t<li>Hitachi Energy TRO600 series firmware\u00a0\u2013 versions 9.0.1.0\u00a0\u2013 9.2.0.0<\/li>\n\t<li>Hitachi Energy TRO600 series firmware\u00a0\u2013 versions 9.1.0.0\u00a0\u2013 9.2.0.0<\/li>\n\t<li>Rockwell Automation Arena Input Analyzer\u00a0\u2013 version v16.20.03 and prior<\/li>\n\t<li>Rockwell Automation FactoryTalk Updater\u00a0- Web Client\u00a0\u2013 versions 4.00.00<\/li>\n\t<li>Rockwell Automation FactoryTalk Updater\u00a0- Client\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation FactoryTalk Updater\u00a0- Agent\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation FactoryTalk View ME\u00a0\u2013 version v14.0 and prior<\/li>\n\t<li>Rockwell Automation Verve Asset Manager\u00a0\u2013 versions 1.39 and prior<\/li>\n\t<li>Siemens SCALANCE M-800 Family \u2013 versions prior to V8.2<\/li>\n\t<li>Siemens SIMATIC S7-PLCSIM V16 &amp; V17\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC STEP 7 and WinCC family\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SIMOCODE ES V16, V18 and V18\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SIMOTION SCOUT TIA V5.4 SP1, SP3 and V5.5 SP1\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINAMICS Startdrive V16, V17 and V18\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIRIUS Safety ES V17 and V18\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SIRIUS Soft Starter ES V17 and V18\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Mendix Runtime\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens OZW672\u00a0\u2013 versions prior to V5.2<\/li>\n\t<li>Siemens OZW772\u00a0\u2013 versions prior to V5.2<\/li>\n\t<li>Siemens RUGGEDCOM CROSSBOW (SAC)\u00a0\u2013 versions prior to 5.6<\/li>\n\t<li>Siemens SIMATIC CP1543-1\u00a0\u2013 version V4.0 (6GK7543-1AX10-0XE0)<\/li>\n\t<li>Siemens SINEC INS\u00a0\u2013 versions prior to V1.0 SP2 Update 3<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V3.0 SP1<\/li>\n\t<li>Siemens SIPORT\u00a0\u2013 versions prior to V3.4.0<\/li>\n\t<li>Siemens Solid Edge SE2024\u00a0\u2013 versions prior to V224.0 Update 9<\/li>\n\t<li>Siemens Spectrum Power 7\u00a0\u2013 all versions prior to V24Q3<\/li>\n\t<li>Siemens TeleControl Server Basic V3.1\u00a0\u2013 versions prior to V3.1.2.1<\/li>\n\t<li>Siemens TIA Portal Cloud V16, V17 and V18\u00a0\u2013 multiple versions<\/li>\n\t<li>Subnet Solutions PowerSYSTEM Center PSC 2020\u00a0\u2013 versions v5.22.x and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-665","alert_type":398,"serial_number":"AV24-665","subject":"ics","moderation_state":"published","external_url":null},{"nid":5855,"title":"Google Chrome security advisory (AV24-667)","uuid":"932b9cef-0452-4f82-a2a6-a311eb0f3bb4","banner":null,"lang":"en","date_modified":"2024-11-19","date_modified_ts":"2024-11-19T19:20:18Z","date_created":"2024-11-19T19:15:54Z","summary":null,"body":["<article data-history-node-id=\"5855\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-667\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-667<br \/><strong>Date: <\/strong>November\u00a019, 2024<\/p>\n\n<p>On November\u00a019, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 131.0.6778.85\/.86 (Windows and Mac) and 131.0.6778.85 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/11\/stable-channel-update-for-desktop_19.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-667","alert_type":396,"serial_number":"AV24-667","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5863,"title":"Apple security advisory (AV24-668)","uuid":"4cefe33a-091f-445c-ac53-162c12062353","banner":null,"lang":"en","date_modified":"2024-11-19","date_modified_ts":"2024-11-19T21:23:25Z","date_created":"2024-11-19T20:57:25Z","summary":null,"body":["<article data-history-node-id=\"5863\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-668\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-668<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 19, 2024<\/p>\n\n<p>On November 19, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 17.7.2<\/li>\n\t<li>iOS iPadOS\u00a0\u2013 versions prior to 18.1.1<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.1.1<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 18.1.1<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 2.1.1<\/li>\n<\/ul><p>Apple is aware that CVE-2024-44308 and CVE-2024-44309 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-668","alert_type":396,"serial_number":"AV24-668","subject":"apple","moderation_state":"published","external_url":null},{"nid":5864,"title":"Atlassian security advisory (AV24-669)","uuid":"21df7369-1913-49aa-8721-b82c69f9628a","banner":null,"lang":"en","date_modified":"2024-11-19","date_modified_ts":"2024-11-19T21:43:25Z","date_created":"2024-11-19T21:31:08Z","summary":null,"body":["<article data-history-node-id=\"5864\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-669\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-669<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 19, 2024<\/p>\n\n<p>On November 19, 2024, Atlassian published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Sourcetree for Mac\u00a0\u2013 multiple versions<\/li>\n\t<li>Sourcetree for Windows\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-november-19-2024-1456179091.html\">Atlassian Novembre 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-669","alert_type":396,"serial_number":"AV24-669","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5867,"title":"Palo Alto Networks security advisory (AV24-670)","uuid":"5c5e3ac0-f9d4-4b9c-9098-d436d6b8c8d0","banner":null,"lang":"en","date_modified":"2024-11-20","date_modified_ts":"2024-11-20T14:55:00Z","date_created":"2024-11-20T14:47:58Z","summary":null,"body":["<article data-history-node-id=\"5867\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-670\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-670<br \/><strong>Date: <\/strong>November\u00a020, 2024<\/p>\n\n<p>On November\u00a018, 2024, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.4-h1<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.5-h1<\/li>\n\t<li>PAN-OS 11.0\u00a0\u2013 versions prior to 11.0.6-h1<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.12-h2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-0012\">Palo Alto Networks Security Advisories\u00a0\u2013 CVE-2024-0012<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-670","alert_type":396,"serial_number":"AV24-670","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5868,"title":"Oracle security advisory (AV24-671)","uuid":"4783723a-620e-4c94-a472-922ec60823fa","banner":null,"lang":"en","date_modified":"2024-11-20","date_modified_ts":"2024-11-20T19:47:27Z","date_created":"2024-11-20T19:42:21Z","summary":null,"body":["<article data-history-node-id=\"5868\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-av24-671\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-671<br \/><strong>Date: <\/strong>November\u00a020, 2024<\/p>\n\n<p>On November\u00a018, 2024, Oracle published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Oracle Agile PLM Framework\u00a0\u2013 version 9.3.6<\/li>\n<\/ul><p>Oracle has reported that vulnerability CVE-2024-21287 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2024-21287.html\">Oracle Security Alert Advisory\u00a0- CVE-2024-21287<\/a><\/li>\n\t<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/\">Oracle Security Alerts and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-av24-671","alert_type":396,"serial_number":"AV24-671","subject":"oracle","moderation_state":"published","external_url":null},{"nid":5869,"title":"Drupal security advisory (AV24-672) ","uuid":"daa4f10e-79be-419e-869a-a190a8208c11","banner":null,"lang":"en","date_modified":"2024-11-20","date_modified_ts":"2024-11-20T21:18:33Z","date_created":"2024-11-20T21:03:56Z","summary":null,"body":["<article data-history-node-id=\"5869\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-672\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-672<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 20, 2024<\/p>\n\n<p>On November 20, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Drupal core\u00a0\u2013 versions prior to 7.102<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-core-2024-005\">Drupal Security Advisory\u00a0- SA-CORE-2024-005<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-672","alert_type":396,"serial_number":"AV24-672","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5871,"title":"Microsoft Edge security advisory (AV24-673)","uuid":"367eb9b1-f8b7-4d8e-83ca-aa98898b849e","banner":null,"lang":"en","date_modified":"2024-11-22","date_modified_ts":"2024-11-22T16:27:27Z","date_created":"2024-11-22T16:00:05Z","summary":null,"body":["<article data-history-node-id=\"5871\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-673\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-673<br \/><strong>Date: <\/strong>November\u00a022, 2024<\/p>\n\n<p>On November\u00a021, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 131.0.2903.63<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-21-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-673","alert_type":396,"serial_number":"AV24-673","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5872,"title":"[Control systems] Siemens security advisory (AV24-674) ","uuid":"2aecc9d3-bba9-4644-bdbc-3f2631585255","banner":null,"lang":"en","date_modified":"2024-11-22","date_modified_ts":"2024-11-22T18:49:21Z","date_created":"2024-11-22T18:44:50Z","summary":null,"body":["<article data-history-node-id=\"5872\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-674\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-674<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 22, 2024<\/p>\n\n<p>On November 22, 2024, Siemens published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>RUGGEDCOM APE1808\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-354569.html\">Siemens Security Advisories\u00a0- SSA-354569<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-674","alert_type":398,"serial_number":"AV24-674","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5873,"title":"IBM security advisory (AV24-675)","uuid":"054ab68e-e895-4680-8339-540aec3b4937","banner":null,"lang":"en","date_modified":"2024-11-25","date_modified_ts":"2024-11-25T17:29:17Z","date_created":"2024-11-25T17:21:07Z","summary":null,"body":["<article data-history-node-id=\"5873\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-675\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-675<br \/><strong>Date: <\/strong>November 25, 2024<\/p>\n\n<p>Between November\u00a018 and November\u00a024,\u00a02024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Planning Analytics\u00a0\u2013 versions 2.0 and 2.1<\/li>\n\t<li>IBM Robotic Process Automation\u00a0\u2013 version 21.0.0 to 21.0.7.16, version 23.0.0 to 23.0.18<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak\u00a0\u2013 version 21.0.0 to 21.0.7.16, version 23.0.0 to 23.0.18<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services\u00a0\u2013 versions 6.1.0, 6.2.0 and 6.3.0<\/li>\n\t<li>IBM Sterling Secure Proxy\u00a0\u2013 version 6.0.0.0 to 6.0.30 and version 6.1.0.0<\/li>\n\t<li>QRadar User Behavior Analytics\u00a0\u2013 version 1.0.0 to 4.1.16<\/li>\n\t<li>SPSS Collaboration and Deployment Services\u00a0\u2013 version 8.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-675","alert_type":396,"serial_number":"AV24-675","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5874,"title":"Ubuntu security advisory (AV24-676)","uuid":"70291b8c-6b47-450c-a686-f99a2b8525e9","banner":null,"lang":"en","date_modified":"2024-11-25","date_modified_ts":"2024-11-25T17:41:01Z","date_created":"2024-11-25T17:34:14Z","summary":null,"body":["<article data-history-node-id=\"5874\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-676\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-676<br \/><strong>Date: <\/strong>November 25, 2024<\/p>\n\n<p>Between November\u00a018 and\u00a024,\u00a02024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-676","alert_type":396,"serial_number":"AV24-676","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5875,"title":"Red Hat security advisory (AV24-677)","uuid":"acd7bf43-59c2-4d4a-b822-0f1b82166882","banner":null,"lang":"en","date_modified":"2024-11-25","date_modified_ts":"2024-11-25T17:52:40Z","date_created":"2024-11-25T17:43:41Z","summary":null,"body":["<article data-history-node-id=\"5875\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av24-677\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-677\n  <br \/><strong>Date: <\/strong>November 25, 2024\n<\/p>\n<p>Between November\u00a018 and November\u00a024,\u00a02024, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:\n<\/p>\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n  <li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 Update Services for SAP Solutions 9.0 ppc64le<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:9942\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:9942<\/a><\/li>\n  <li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2024:9943\">Red Hat Security Advisory\u00a0\u2013 RHSA-2024:9943<\/a><\/li>\n  <li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av24-677","alert_type":396,"serial_number":"AV24-677","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5876,"title":"[Control systems] CISA ICS security advisories (AV24\u2013678) ","uuid":"81cf8212-aabc-4d0a-a2e3-8d755f9b0336","banner":null,"lang":"en","date_modified":"2024-11-25","date_modified_ts":"2024-11-25T18:35:54Z","date_created":"2024-11-25T18:13:56Z","summary":null,"body":["<article data-history-node-id=\"5876\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-678\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-678<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 25, 2024<\/p>\n\n<p>Between Novembre 18 and Novembre 24, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automated Logic Carrier i-Vu\u00a0\u2013 version 7.0<\/li>\n\t<li>Automated Logic SiteScan Web\u00a0\u2013 version 7.0<\/li>\n\t<li>Automated Logic WebCTRL Server\u00a0\u2013 version 7.0<\/li>\n\t<li>Automated Logic WebCTRL for OEMs\u00a0\u2013 version 7.0<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>mySCADA myPRO Manager\u00a0\u2013 versions prior to 1.3<\/li>\n\t<li>mySCADA myPRO Runtime\u00a0\u2013 versions prior to 9.2.1<\/li>\n\t<li>OSCAT CODESYS Basic Library\u00a0\u2013 version 3.3.5.0<\/li>\n\t<li>OSCAT oscat.de OSCAT Basic Library\u00a0\u2013 version 3.3.5 and prior<\/li>\n\t<li>OSCAT oscat.de OSCAT Basic Library\u00a0\u2013 version 335 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure IT Gateway\u00a0\u2013 multiple versions<\/li>\n\t<li>Schneider Electric Modicon M340 CPU (part numbers BMXP34*)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon MC80 (part numbers BMKC80)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Momentum Unity M1E Processor (171CBU*)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric PowerLogic PM5320\u00a0\u2013 version 2.3.8 and prior<\/li>\n\t<li>Schneider Electric PowerLogic PM5340\u00a0\u2013 version 2.3.8 and prior<\/li>\n\t<li>Schneider Electric PowerLogic PM5341\u00a0\u2013 version 2.6.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-678","alert_type":398,"serial_number":"AV24-678","subject":"ics","moderation_state":"published","external_url":null},{"nid":5877,"title":"HPE security advisory (AV24-679)","uuid":"4defe5aa-71d9-405a-ae58-2fee436775da","banner":null,"lang":"en","date_modified":"2024-11-25","date_modified_ts":"2024-11-25T19:15:45Z","date_created":"2024-11-25T18:58:48Z","summary":null,"body":["<article data-history-node-id=\"5877\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-679\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-679<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 25, 2024<\/p>\n\n<p>On November 25, 2024, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE AutoPass License Server (APLS)\u00a0\u2013 versions prior to 9.17<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04760en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbgn04760<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-679","alert_type":396,"serial_number":"AV24-679","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5878,"title":"Mozilla security advisory (AV24-680)","uuid":"db00ae26-a1cb-42a5-8443-a030e7357f48","banner":null,"lang":"en","date_modified":"2024-11-26","date_modified_ts":"2024-11-26T17:00:01Z","date_created":"2024-11-26T15:20:24Z","summary":null,"body":["<article data-history-node-id=\"5878\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-680\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-680<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 26, 2024<\/p>\n\n<p>On November 26, 2024, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 133<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 128.5<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.18<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.5<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 133<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-680","alert_type":396,"serial_number":"AV24-680","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5879,"title":"VMware security advisory (AV24-681)","uuid":"0041081e-2d57-4b0f-90ca-e7d61e462bbf","banner":null,"lang":"en","date_modified":"2024-11-26","date_modified_ts":"2024-11-26T17:19:01Z","date_created":"2024-11-26T17:06:31Z","summary":null,"body":["<article data-history-node-id=\"5879\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av24-681\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-681<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 26, 2024<\/p>\n\n<p>On November 26, 2024, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Aria Operations\u00a0\u2013 versions 8.x<\/li>\n\t<li>VMware Cloud Foundation (VMware Aria Operations)\u00a0\u2013 versions 5.x and 4.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25199\">VMware VMSA-2024-0022<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av24-681","alert_type":396,"serial_number":"AV24-681","subject":"vmware","moderation_state":"published","external_url":null},{"nid":5880,"title":"GitLab security advisory (AV24-682)","uuid":"1d2398e4-7f92-4eb8-8e9b-4fc8cfc4a686","banner":null,"lang":"en","date_modified":"2024-11-26","date_modified_ts":"2024-11-26T17:36:05Z","date_created":"2024-11-26T17:23:40Z","summary":null,"body":["<article data-history-node-id=\"5880\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-682\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-682<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 26, 2024<\/p>\n\n<p>On November 26, 2024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.4.5, 17.5.3 and 17.6.1<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.4.5, 17.5.3 and 17.6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/11\/26\/patch-release-gitlab-17-6-1-released\/\">GitLab Patch Release: 17.6.1, 17.5.3, 17.4.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-682","alert_type":396,"serial_number":"AV24-682","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5885,"title":"Jenkins security advisory (AV24-683)","uuid":"340f7bc9-227d-426f-beeb-8ee65649ceff","banner":null,"lang":"en","date_modified":"2024-11-27","date_modified_ts":"2024-11-27T21:14:29Z","date_created":"2024-11-27T21:09:45Z","summary":null,"body":["<article data-history-node-id=\"5885\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av24-683\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-683<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 27, 2024<\/p>\n\n<p>On November 27, 2024, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins weekly \u2013 version 2.486 and prior<\/li>\n\t<li>Jenkins LTS \u2013 version 2.479.1 and prior<\/li>\n\t<li>Filesystem List Parameter Plugin \u2013 version 0.0.14 and prior<\/li>\n\t<li>Simple Queue Plugin \u2013 version 1.4.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2024-11-27\/\">Jenkins Security Advisory 2024-11-27<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av24-683","alert_type":396,"serial_number":"AV24-683","subject":"other","moderation_state":"published","external_url":null},{"nid":5886,"title":"[Control systems] ABB security advisory (AV24-684)","uuid":"8607cfd5-bc43-47d0-8e6d-431ae514d325","banner":null,"lang":"en","date_modified":"2024-11-29","date_modified_ts":"2024-11-29T16:29:41Z","date_created":"2024-11-29T16:20:09Z","summary":null,"body":["<article data-history-node-id=\"5886\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-684\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-684<br \/><strong>Date: <\/strong>November 29, 2024<\/p>\n\n<p>On November\u00a029,\u00a02024, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ABB mapp Cockpit\u00a0\u2013 version 5.x<\/li>\n\t<li>ABB mapp View\u00a0\u2013 version 5.x<\/li>\n\t<li>ABB mapp Services (only if mpUserX or mpCodeBox is used)\u00a0\u2013 version 5.x<\/li>\n\t<li>ABB mapp Motion\u00a0\u2013 version 5.x<\/li>\n\t<li>ABB mapp Vision\u00a0\u2013 version 5.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA22P014-90c4aa35.pdf\">Authentication bypass flaw in several mapp components CVE ID: CVE-2024-10490 (PDF, 147 KB)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av24-684","alert_type":398,"serial_number":"AV24-684","subject":"abb","moderation_state":"published","external_url":null},{"nid":5888,"title":"Ubuntu security advisory (AV24-685)","uuid":"da090dcf-ddb3-4d63-8c1f-db6977341db6","banner":null,"lang":"en","date_modified":"2024-12-02","date_modified_ts":"2024-12-02T14:51:56Z","date_created":"2024-12-02T14:47:05Z","summary":null,"body":["<article data-history-node-id=\"5888\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-685\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-685<br \/><strong>Date: <\/strong>December 2, 2024<\/p>\n\n<p>Between November\u00a025 and December\u00a01,\u00a02024, Ubuntu published a security notice to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-685","alert_type":396,"serial_number":"AV24-685","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5890,"title":"Trellix security advisory (AV24-688)","uuid":"c2a41748-9309-4f7f-9e72-c8063253113b","banner":null,"lang":"en","date_modified":"2024-12-02","date_modified_ts":"2024-12-02T18:09:38Z","date_created":"2024-12-02T16:32:41Z","summary":null,"body":["<article data-history-node-id=\"5890\" about=\"\/en\/alerts-advisories\/trellix-security-advisory-av24-688\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-688<br \/><strong>Date: <\/strong>December 2, 2024<\/p>\n\n<p>On November\u00a022,\u00a02024, Trellix published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Trellix Enterprise Security Manager (ESM)\u00a0\u2013 versions prior to 11.6.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.trellix.com\/bundle\/enterprise-security-manager-v11-6-x-update-release-notes\/page\/UUID-7c47a1c9-ca82-42a2-8793-073286693f1e.html\">Trellix Enterprise Security Manager 11.6.13 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/thrive.trellix.com\/s\/?language=en_US\">Trellix Thrive<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trellix-security-advisory-av24-688","alert_type":396,"serial_number":"AV24-688","subject":"trellix","moderation_state":"published","external_url":null},{"nid":5891,"title":"IBM security advisory (AV24-686)","uuid":"060cdbab-da1d-47b7-917a-54138d29f41a","banner":null,"lang":"en","date_modified":"2024-12-02","date_modified_ts":"2024-12-02T17:11:40Z","date_created":"2024-12-02T17:04:45Z","summary":null,"body":["<article data-history-node-id=\"5891\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-686\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-686<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 2, 2024<\/p>\n\n<p>Between November 25 and December 1, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>CP4NA\u00a0\u2013 version 2.7.6<\/li>\n\t<li>IBM Analytics Content Hub\u00a0\u2013 version 2.0<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- AI Broker\u00a0\u2013 version 9.0.2<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 versions 1.15.0, 1.15.0 IF001, 1.15.0 IF002 and 1.15.0 IF003<\/li>\n\t<li>IBM Security Verify Access\u00a0\u2013 version 10.0.0 to 10.0.8 IF1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-686","alert_type":396,"serial_number":"AV24-686","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5892,"title":"[Control systems] CISA ICS security advisories (AV24\u2013687)","uuid":"91856318-fc61-4781-b688-5629b3772007","banner":null,"lang":"en","date_modified":"2024-12-02","date_modified_ts":"2024-12-02T17:22:49Z","date_created":"2024-12-02T17:14:02Z","summary":null,"body":["<article data-history-node-id=\"5892\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-687\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-687<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 2, 2024<\/p>\n\n<p>Between November 25 and December 1, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Energy MicroSCADA Pro\/X SYS600\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy RTU500 Scripting Interface\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric EcoStruxure Control Expert\u00a0\u2013 versions prior to v16.0<\/li>\n\t<li>Schneider Electric EcoStruxure Process Expert\u00a0\u2013 versions prior to v2023<\/li>\n\t<li>Schneider Electric Modicon M340 CPU (part numbers BMXP34*)\u00a0\u2013 versions prior to sv3.60<\/li>\n\t<li>Schneider Electric Modicon M580 CPU (part numbers BMEP* and BMEH* excluding M580 CPU Safety)\u00a0\u2013 versions prior to SV4.20<\/li>\n\t<li>Schneider Electric Modicon M580 CPU Safety\u00a0\u2013 versions prior to SV4.21<\/li>\n\t<li>Schneider Electric Modicon MC80 (part numbers BMKC80)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Momentum Unity M1E Processor (171CBU*)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric PowerLogic P5\u00a0\u2013 versions 01.500.104 and prior<\/li>\n\t<li>SchneiderPowerLogic PM5560\u00a0\u2013 versions prior to v2.7.8<\/li>\n\t<li>SchneiderPowerLogic PM5561\u00a0\u2013 versions prior to v10.7.3<\/li>\n\t<li>SchneiderPowerLogic PM5562\u00a0\u2013 versions prior to v2.5.4<\/li>\n\t<li>SchneiderPowerLogic PM5563\u00a0\u2013 versions prior to v2.7.8<\/li>\n\t<li>Schneider PowerLogic PM8ECC\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-687","alert_type":398,"serial_number":"AV24-687","subject":"ics","moderation_state":"published","external_url":null},{"nid":5894,"title":"Zyxel security advisory (AV24-689)","uuid":"be35d002-4e6f-44df-aff1-e3ebc5e8de22","banner":null,"lang":"en","date_modified":"2024-12-02","date_modified_ts":"2024-12-02T18:58:35Z","date_created":"2024-12-02T18:02:00Z","summary":null,"body":["<article data-history-node-id=\"5894\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av24-689\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-689<br \/><strong>Date: <\/strong>December\u00a02, 2024<\/p>\n\n<p>On November\u00a021, 2024, Zyxel published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Zyxel ZLD firewall\u00a0\u2013 firmware versions 5.00 through 5.38<\/li>\n<\/ul><p>Zyxel has reported that vulnerability CVE-2024-11667 has been exploited.<\/p>\n\n<p>CISA added CVE-2024-11667 to their Known Exploited (KEV) Catalog on December\u00a03, 2024.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024\">Zyxel security advisory: protecting against recent firewall threats (CVE-2024-11667)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">CISA Known Exploited Vulnerabilites Catalog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av24-689","alert_type":396,"serial_number":"AV24-689","subject":"other","moderation_state":"published","external_url":null},{"nid":5893,"title":"Android security advisory \u2013 December 2024 Monthly Rollup (AV24-690)","uuid":"2a18aa4b-2030-49bc-bb67-b6ae84cf2559","banner":null,"lang":"en","date_modified":"2024-12-02","date_modified_ts":"2024-12-02T19:00:45Z","date_created":"2024-12-02T20:10:34Z","summary":null,"body":["<article data-history-node-id=\"5893\" about=\"\/en\/alerts-advisories\/android-security-advisory-december-2024-monthly-rollup-av24-690\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-690<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December\u00a02, 2024<\/p>\n\n<p>On December\u00a02, 2024, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2024-12-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-december-2024-monthly-rollup-av24-690","alert_type":396,"serial_number":"AV24-690","subject":"android","moderation_state":"published","external_url":null},{"nid":5897,"title":"Google Chrome security advisory (AV24-691)","uuid":"fe4b3f67-0fd0-421c-b57e-a3c7ca2f100f","banner":null,"lang":"en","date_modified":"2024-12-04","date_modified_ts":"2024-12-04T14:10:37Z","date_created":"2024-12-04T14:07:57Z","summary":null,"body":["<article data-history-node-id=\"5897\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-691\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-691<br \/><strong>Date: <\/strong>December\u00a04, 2024<\/p>\n\n<p>On December\u00a03, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 131.0.6778.108\/.109 (Windows and Mac) and 131.0.6778.108 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/12\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-691","alert_type":396,"serial_number":"AV24-691","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5898,"title":"Veeam security advisory (AV24-692)","uuid":"2115cfa7-2220-4a7d-8ad5-b121af543949","banner":null,"lang":"en","date_modified":"2024-12-04","date_modified_ts":"2024-12-04T14:30:00Z","date_created":"2024-12-04T14:25:49Z","summary":null,"body":["<article data-history-node-id=\"5898\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av24-692\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-692<br \/><strong>Date: <\/strong>December\u00a04, 2024<\/p>\n\n<p>On December\u00a03, 2024, Veeam published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2013 version 12.2.0.334 and prior<\/li>\n\t<li>Veeam Service Provider Console\u00a0\u2013 version 8.1.0.21377 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4679\">Veeam Security Advisory\u00a0\u2013 kb4679<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4693\">Veeam Security Advisory\u00a0\u2013 kb4693<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av24-692","alert_type":396,"serial_number":"AV24-692","subject":"other","moderation_state":"published","external_url":null},{"nid":5902,"title":"SonicWall security advisory (AV24-693)","uuid":"cfeceaba-1bc2-4c4d-af2d-033ec7e85c77","banner":null,"lang":"en","date_modified":"2024-12-05","date_modified_ts":"2024-12-05T16:39:58Z","date_created":"2024-12-05T16:21:48Z","summary":null,"body":["<article data-history-node-id=\"5902\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-693\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-693<br \/><strong>Date: <\/strong>December\u00a05, 2024<\/p>\n\n<p>On December\u00a03, 2024, SonicWall published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SonicWall SMA SSL-VPN 100 Series\u00a0\u2013 version 10.2.1.13-72sv and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2024-0018\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2024-0018<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av24-693","alert_type":396,"serial_number":"AV24-693","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":5905,"title":"Microsoft Edge security advisory (AV24-694)","uuid":"09046697-222f-4a20-a6f1-72fa9146ffde","banner":null,"lang":"en","date_modified":"2024-12-06","date_modified_ts":"2024-12-06T19:34:01Z","date_created":"2024-12-06T19:31:14Z","summary":null,"body":["<article data-history-node-id=\"5905\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-694\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-694<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 6, 2024<\/p>\n\n<p>On December 5, 2024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 131.0.2903.86<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-5-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-694","alert_type":396,"serial_number":"AV24-694","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5906,"title":"IBM security advisory (AV24-695)","uuid":"f26b87ec-662c-4c6c-8dfa-fb27dd998aef","banner":null,"lang":"en","date_modified":"2024-12-09","date_modified_ts":"2024-12-09T19:30:53Z","date_created":"2024-12-09T19:06:03Z","summary":null,"body":["<article data-history-node-id=\"5906\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-695\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-695<br \/><strong>Date: <\/strong>December\u00a09, 2024<\/p>\n\n<p>Between December\u00a02 and 8, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 version Build 261 to 283<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7177986\">IBM Security Bulletin (App Connect Enterprise Certified Container)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7178059\">IBM Security Bulletin (IBM Observability with Instana (OnPrem))<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-695","alert_type":396,"serial_number":"AV24-695","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5908,"title":"[Control systems] CISA ICS security advisories (AV24\u2013697)","uuid":"b638e18e-05b2-4a3b-a382-e2319a2855e1","banner":null,"lang":"en","date_modified":"2024-12-09","date_modified_ts":"2024-12-09T20:04:16Z","date_created":"2024-12-09T19:06:04Z","summary":null,"body":["<article data-history-node-id=\"5908\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-697\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-697\n  <br \/><strong>Date: <\/strong>December\u00a09, 2024\n<\/p>\n<p>Between December\u00a02 and 8, 2024, CISA published ICS advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>AutomationDirect C-More EA9 Programming Software\u00a0\u2013 version 6.78 and prior<\/li>\n  <li>Fuji Electric Monitouch V-SFT\u00a0\u2013 version 6.2.3.0 and prior<\/li>\n  <li>Fuji Electric Tellus Lite\u00a0\u2013 version 4.0.20.0<\/li>\n  <li>ICONICS GENESIS64 AlarmWorX Multimedia\u00a0\u2013 versions prior to 10.97.3<\/li>\n  <li>ICONICS GENESIS64\u00a0\u2013 version 10.97.2, 10.97.2 CFR1, 10.97.2 CFR2, and 10.97.3<\/li>\n  <li>Mitsubishi Electric MC Works64\u00a0\u2013 all versions<\/li>\n  <li>Open Automation Software\u00a0\u2013 versions prior to V20.00.0076<\/li>\n  <li>Planet Technology Planet WGS-804HPT\u00a0\u2013 version v1.305b210531<\/li>\n  <li>Ruijie Reyee OS\u00a0\u2013 versions 2.206.x to prior to 2.320.x<\/li>\n  <li>Siemens RUGGEDCOM APE1808\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news\u2013events\/cybersecurity\u2013advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-697","alert_type":398,"serial_number":"AV24-697","subject":"ics","moderation_state":"published","external_url":null},{"nid":5907,"title":"Dell security advisory (AV24-696)","uuid":"719dbae5-736a-4afe-9af0-e684beafcdc1","banner":null,"lang":"en","date_modified":"2024-12-09","date_modified_ts":"2024-12-09T19:57:40Z","date_created":"2024-12-09T19:07:02Z","summary":null,"body":["<article data-history-node-id=\"5907\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-696\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-696<br \/><strong>Date: <\/strong>December\u00a09, 2024<\/p>\n\n<p>Between December\u00a02 and 8, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.01.01.00<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 versions 19.10 to 19.10.0.5, versions 19.11 to 19.11.0.1, versions 19.8 to 19.8.0.4, versions 19.9 to 19.9.0.7 and versions prior to 19.8<\/li>\n\t<li>Dell RecoverPoint Classic\u00a0\u2013 versions 5.1 sp4 p3, 5.1 sp4 p4 and versions 5.1 sp4 p2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000257154\/dsa-2024-454-security-update-for-dell-apex-cloud-platform-for-red-hat-openshift-and-dell-apex-cloud-platform-foundation-software-for-third-party-component-vulnerabilities\">Dell Security Update (APEX Cloud Platform for Red Hat OpenShift)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000255975\/dsa-2024-451-security-update-for-dell-networker-for-libxml2-2-9-0-vulnerabilities\">Dell Security Update (Dell NetWorker)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000257161\/dsa-2024-428-security-update-for-dell-recoverpoint-cl-for-third-party-component-vulnerabilities\">Dell Security Update (Dell RecoverPoint Classic)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-696","alert_type":396,"serial_number":"AV24-696","subject":"dell","moderation_state":"published","external_url":null},{"nid":5909,"title":"Drupal security advisory (AV24-698) ","uuid":"1c624490-6395-421a-b739-b4486264d36c","banner":null,"lang":"en","date_modified":"2024-12-09","date_modified_ts":"2024-12-09T20:34:48Z","date_created":"2024-12-09T20:25:04Z","summary":null,"body":["<article data-history-node-id=\"5909\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-698\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-698<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 9, 2024<\/p>\n\n<p>On December 4, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Drupal Download All Files\u00a0\u2013 versions prior to 2.0.2<\/li>\n\t<li>Drupal Pages Restriction Access\u00a0\u2013 versions 2.0.0 to prior to 2.0.3<\/li>\n\t<li>Drupal OAuth and OpenID Connect Single Sign On\u00a0- SSO (OAuth\/OIDC Client)\u00a0\u2013 versions 3.0.0 to prior to 3.44.0 and 4.0.0 to prior to 4.0.19<\/li>\n\t<li>Drupal Print Anything\u00a0\u2013 all versions<\/li>\n\t<li>Drupal Megamenu Framework\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-698","alert_type":396,"serial_number":"AV24-698","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5910,"title":"SAP security advisory \u2013 December 2024 monthly rollup (AV24-699)","uuid":"ee4bc293-ce16-4027-a0bd-5c7e8ed85c25","banner":null,"lang":"en","date_modified":"2024-12-10","date_modified_ts":"2024-12-10T14:16:23Z","date_created":"2024-12-10T14:03:25Z","summary":null,"body":["<article data-history-node-id=\"5910\" about=\"\/en\/alerts-advisories\/sap-security-advisory-december-2024-monthly-rollup-av24-699\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-699<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 10, 2024<\/p>\n\n<p>On December 10, 2024, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP NetWeaver AS for JAVA (Adobe Document Services)\u00a0\u2013 version ADSSSAP 7.50<\/li>\n\t<li>SAP NetWeaver Application Server ABAP\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89 and 7.93<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/december-2024.html \">SAP Security Patch Day \u2013 December 2024<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-december-2024-monthly-rollup-av24-699","alert_type":396,"serial_number":"AV24-699","subject":"sap","moderation_state":"published","external_url":null},{"nid":5912,"title":"[Control systems] Siemens security advisory (AV24-700)","uuid":"f014ca01-8ce2-41d4-9a15-fcdde4394521","banner":null,"lang":"en","date_modified":"2024-12-10","date_modified_ts":"2024-12-10T18:20:08Z","date_created":"2024-12-10T18:16:05Z","summary":null,"body":["<article data-history-node-id=\"5912\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-700\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-700\n  <br \/><strong>Date: <\/strong>December\u00a010, 2024\n<\/p>\n<p>On December\u00a010, 2024, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:\n<\/p>\n<ul><li>Parasolid\u00a0\u2013 multiple versions<\/li>\n\t<li>RUGGEDCOM ROX II family\u00a0\u2013 versions prior to V2.16.0<\/li>\n\t<li>SIMOTION SCOUT TIA V5.4 SP1\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-PLCSIM V16, V17\u00a0\u2013 all versions<\/li>\n\t<li>Simcenter Femap V2306, V2401 and V2406\u00a0\u2013 all versions<\/li>\n\t<li>Solid Edge SE2024\u00a0\u2013 all versions<\/li>\n\t<li>Teamcenter Visualization\u00a0\u2013 multiple versions<\/li>\n\t<li>Totally Integrated Automation Portal (TIA Portal)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-700","alert_type":398,"serial_number":"AV24-700","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5913,"title":"Microsoft security advisory \u2013 December 2024 monthly rollup (AV24\u2013701)","uuid":"f513e542-909a-4a76-9467-8de12dca43e4","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T13:55:52Z","date_created":"2024-12-11T13:43:48Z","summary":null,"body":["<article data-history-node-id=\"5913\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-december-2024-monthly-rollup-av24-701\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-701<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On December 10, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps for Enterprise\u00a0\u2013 multiple versions and platforms;<\/li>\n\t<li>Microsoft Access 2016<\/li>\n\t<li>Microsoft Defender for Endpoint<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft\/Muzic<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Project 2016\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>System Center Operations Manager 2019, 2022 and 2025<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2024-49138 and CVE-2023-44487* have been exploited.<\/p>\n\n<p>Microsoft has also published a blog post about defending against NTLM relay exploits associated with CVE-2024-21413, CVE-2023-23397, and CVE-2023-36563.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-Dec\">December 2024 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update\u2013guide\/en\u2013us\">Security Update Guide<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/12\/mitigating-ntlm-relay-attacks-by-default\/\">Mitigating NTLM Relay Attacks by Default<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/vulnerability-impacting-http2-rapid-reset \">* Alert\u00a0- Vulnerability impacting HTTP\/2\u00a0- Rapid Reset<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-december-2024-monthly-rollup-av24-701","alert_type":396,"serial_number":"AV24-701","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5914,"title":"Adobe security advisory (AV24\u2013702)","uuid":"9e3e2882-334b-4ea7-89eb-5df2dbc59156","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T14:32:55Z","date_created":"2024-12-11T14:15:25Z","summary":null,"body":["<article data-history-node-id=\"5914\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-702\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-702<br \/><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On December\u00a010,\u00a02024, Adobe published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Adobe Acrobat 2024\u00a0\u2013 version 24.001.30213 and prior (Windows), version 24.001.30193 and prior (MacOS)<\/li>\n\t<li>Adobe Acrobat 2020\u00a0\u2013 version 20.005.30730 and prior (Windows), version 20.005.30710 and prior (MacOS)<\/li>\n\t<li>Adobe Acrobat Reader 2020\u00a0\u2013 version 20.005.30730 and prior (Windows), version 20.005.30710 and prior (MacOS)<\/li>\n\t<li>Adobe Acrobat DC\u00a0\u2013 version 24.005.20307 and prior<\/li>\n\t<li>Adobe Acrobat Reader DC\u00a0\u2013 version 24.005.20307 and prior<\/li>\n\t<li>Adobe After Effects\u00a0\u2013 version 24.6.2 and prior, version 25.0.1 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0\u2013 version 24.0.5 and prior<\/li>\n\t<li>Adobe Animate 2023\u00a0\u2013 version 23.0.8 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 14.1.3 and prior, version 15.0 and prior<\/li>\n\t<li>Adobe Connect\u00a0\u2013 version 12.6 and prior, version 11.4.7 and prior<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 version 2020 Release Update 7 and prior, version 2022 Release Update 5 and prior<\/li>\n\t<li>Adobe Illustrator 2025\u00a0\u2013 version 29.0.0 and prior<\/li>\n\t<li>Adobe Illustrator 2024\u00a0\u2013 version 28.7.2 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.5 and prior, version ID18.5.4 and prior<\/li>\n\t<li>Adobe Media Encoder\u00a0\u2013 version 24.6.3 and prior, version 25.0 and prior<\/li>\n\t<li>Adobe PDFL Software Development Kit (SDK)\u00a0\u2013 version PDFL SDK 21.0.0.5 and prior<\/li>\n\t<li>Adobe Photoshop 2025\u00a0\u2013 version 26.0 and prior<\/li>\n\t<li>Adobe Premiere Pro\u00a0\u2013 version 25.0 and prior, version 24.6.3 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler\u00a0- version 1.14.1 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 10.1.1 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler\u00a0\u2013 version 4.5.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-702","alert_type":396,"serial_number":"AV24-702","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5915,"title":"Google Chrome security advisory (AV24-703)","uuid":"c02537e8-6cf5-4a17-a4e5-7b22a9c5849e","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T14:45:46Z","date_created":"2024-12-11T14:39:53Z","summary":null,"body":["<article data-history-node-id=\"5915\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-703\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-703<br \/><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On December\u00a010,\u00a02024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 131.0.6778.139\/.140 (Windows and Mac) and 131.0.6778.139 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/12\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-703","alert_type":396,"serial_number":"AV24-703","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5916,"title":"Vulnerability impacting all versions of Cleo VLTrader, Harmony, and LexiCom software","uuid":"a3339cb1-899d-476c-974a-0d242d51387a","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T17:41:50Z","date_created":"2024-12-11T16:48:21Z","summary":null,"body":["<article data-history-node-id=\"5916\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-all-versions-cleo-vltrader-harmony-and-lexicom-software\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL24-012<br \/><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On December 10, 2024, Cyber Centre became aware of reports<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn-1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> detailing the active exploitation of an unrestricted file upload and download vulnerability that could lead to remote code execution<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> affecting all versions of Cleo VLTrader, Harmony, and LexiCom software.<\/p>\n\n<p>Reporting indicates that systems running the initially released patches for this vulnerability are still exploitable.<\/p>\n\n<p>The vulnerability (CVE-2024-50623), along with an as-yet-unassigned CVE<sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn-3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, affects the following products:<\/p>\n\n<ul><li>Cleo Harmony\u00a0\u2013 version 5.8.0.23 and prior<\/li>\n\t<li>Cleo VLTrader\u00a0\u2013 version 5.8.0.23 and prior<\/li>\n\t<li>Cleo LexiCom\u00a0\u2013 version 5.8.0.23 and prior<\/li>\n<\/ul><\/section><section><h2>Suggested action<\/h2>\n\n<p>The Cyber Centre strongly recommends that you review research relevant to this vulnerability<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn-1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, perform suggested mitigations, investigate affected systems for compromise, and monitor Cleo announcements for patches<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn-3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>You should also review and implement our Top 10 IT Security Actions<span class=\"nowrap\"> <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/span> with an emphasis on the following topics:<\/p>\n\n<ul><li>Patching operating systems and applications.<\/li>\n\t<li>Isolating Web-facing applications.<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><!--************************************************* ENDNOTES SECTION - IF NEDDED *************************************************--><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn-1\">\n\t<p><a href=\"https:\/\/www.huntress.com\/blog\/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild\">Threat Advisory: Oh No Cleo! Cleo Software Actively Being Exploited in the Wild<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-50623\">CVE-2024-50623 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn-3\">\n\t<p><a href=\"https:\/\/support.cleo.com\/hc\/en-us\/sections\/360005127514-Announcements\">Cleo Solution Center: Announcements<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-all-versions-cleo-vltrader-harmony-and-lexicom-software","alert_type":397,"serial_number":"AL24-012","subject":"other","moderation_state":"published","external_url":null},{"nid":5917,"title":"Ivanti security advisory (AV24-704)","uuid":"1ac08515-ef61-4104-92b3-a9835fea1d47","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T18:38:30Z","date_created":"2024-12-11T18:30:18Z","summary":null,"body":["<article data-history-node-id=\"5917\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-704\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-704<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On December 10, 2024, Ivanti published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Ivanti Cloud Services Application (CSA)\u00a0\u2013 version 5.0.2 and prior<\/li>\n\t<li>Ivanti Connect Secure (ICS)\u00a0\u2013 version 22.7R2.3 and prior<\/li>\n\t<li>Ivanti Policy Secure (IPS)\u00a0\u2013 version 22.7R1.1 and prior<\/li>\n\t<li>Ivanti Sentry\u00a0\u2013 versions 9.20.1 and prior and 10.0.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/December-2024-Security-Advisory-Ivanti-Connect-Secure-ICS-and-Ivanti-Policy-Secure-IPS-Multiple-CVEs?language=en_US \">Ivanti \u2013 December 2024 Security Advisory Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US \">Ivanti \u2013 Security Advisory Ivanti Cloud Services Application (CSA)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Sentry-CVE-2024-8540?language=en_US \">Ivanti \u2013 Security Advisory Ivanti Sentry<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-704","alert_type":396,"serial_number":"AV24-704","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5918,"title":"Atlassian security advisory (AV24-705)","uuid":"c709c7ac-65fa-4d69-a085-cc55170f24ac","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T18:44:48Z","date_created":"2024-12-11T18:40:42Z","summary":null,"body":["<article data-history-node-id=\"5918\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av24-705\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-705<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On December 10, 2024, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-december-10-2024-1476624803.html\">Atlassian December 2024 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av24-705","alert_type":396,"serial_number":"AV24-705","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5919,"title":"GitLab security advisory (AV24-706)","uuid":"96a65ff6-a8d2-4a7d-9bd3-0d23b0b92aaa","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T18:50:37Z","date_created":"2024-12-11T18:46:27Z","summary":null,"body":["<article data-history-node-id=\"5919\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av24-706\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-706<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On December 11, 2024, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 17.6.2, 17.5.4 and 17.4.6<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 17.6.2, 17.5.4 and 17.4.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2024\/12\/11\/patch-release-gitlab-17-6-2-released\/ \">GitLab Patch Release: 17.6.2, 17.5.4, 17.4.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av24-706","alert_type":396,"serial_number":"AV24-706","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5920,"title":"[Control systems] Schneider Electric security advisory (AV24-707) ","uuid":"180264ca-81ca-4223-8888-c1d92528486a","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T19:47:01Z","date_created":"2024-12-11T19:40:49Z","summary":null,"body":["<article data-history-node-id=\"5920\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-707\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-707<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On December 10, 2024, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Harmony HMIST6, HMISTM6, HMIG3U, HMIG3U, HMIG3X and HMISTO7 series\u00a0\u2013 all versions<\/li>\n\t<li>Modicon M241, M251, M258 and LMC058 Controllers\u00a0\u2013 all versions<\/li>\n\t<li>PowerChute Serial Shutdown\u00a0\u2013 versions v1.2.0.301 and prior<\/li>\n\t<li>PFXST6000, PFXSTM6000, PFXSP5000 and PFXGP4100 series\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-345-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-345-02.pdf \">Schneider Electric Security Notification\u00a0- Harmony HMI and Pro-face HMI products (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-345-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-345-03.pdf \">Schneider Electric Security Notification\u00a0- Modicon M241\u00a0\/ M251\u00a0\/ M258\u00a0\/ LMC058 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2024-345-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2024-345-01.pdf \">Schneider Electric Security Notification\u00a0- PowerChute Serial Shutdown (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp \u2003\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av24-707","alert_type":398,"serial_number":"AV24-707","subject":"other","moderation_state":"published","external_url":null},{"nid":5921,"title":"Apache security advisory (AV24-708)","uuid":"62765853-8ff4-4188-b20b-e4eba1400d40","banner":null,"lang":"en","date_modified":"2024-12-11","date_modified_ts":"2024-12-11T20:47:20Z","date_created":"2024-12-11T20:42:29Z","summary":null,"body":["<article data-history-node-id=\"5921\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av24-708\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-708<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2024<\/p>\n\n<p>On November 26, 2024, Apache published a security advisory to address a critical vulnerability (CVE-2024-53677) in the following products:<\/p>\n\n<ul><li>Apache Struts\u00a0\u2013 versions 2.0.0 to 2.3.37 (EOL)<\/li>\n\t<li>Apache Struts\u00a0\u2013 versions 2.5.0 to 2.5.33<\/li>\n\t<li>Apache Struts\u00a0\u2013 versions 6.0.0 to 6.3.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-067\">Apache Security Bulletin S2-067<\/a><\/li>\n\t<li><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/Security+Bulletins\">Apache Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av24-708","alert_type":396,"serial_number":"AV24-708","subject":"other","moderation_state":"published","external_url":null},{"nid":5922,"title":"Apple security advisory (AV24-709)","uuid":"97c888bd-fd1a-47e7-a43e-174716c53add","banner":null,"lang":"en","date_modified":"2024-12-12","date_modified_ts":"2024-12-12T16:45:41Z","date_created":"2024-12-12T16:39:59Z","summary":null,"body":["<article data-history-node-id=\"5922\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av24-709\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-709<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 12, 2024<\/p>\n\n<p>On December 11, 2024, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.2<\/li>\n\t<li>iOS iPadOS\u00a0\u2013 versions prior to 17.7.3<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.2<\/li>\n\t<li>macOS Senoma\u00a0\u2013 versions prior to 14.7.2<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.7.2<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 18.2<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 18.2<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 2.2<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 11.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100 \">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av24-709","alert_type":396,"serial_number":"AV24-709","subject":"apple","moderation_state":"published","external_url":null},{"nid":5923,"title":"Drupal security advisory (AV24-710) ","uuid":"4d95d783-72f4-4bff-b6dd-e9b6e8af80db","banner":null,"lang":"en","date_modified":"2024-12-12","date_modified_ts":"2024-12-12T16:52:17Z","date_created":"2024-12-12T16:48:18Z","summary":null,"body":["<article data-history-node-id=\"5923\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av24-710\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-710<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 12, 2024<\/p>\n\n<p>On December 11, 2024, Drupal published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Drupal Login Disable\u00a0\u2013 versions 2.0.0 prior to 2.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2024-073 \">Drupal Login Disable\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2024-073<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av24-710","alert_type":396,"serial_number":"AV24-710","subject":"drupal","moderation_state":"published","external_url":null},{"nid":5924,"title":"Ivanti security advisory (AV24-711)","uuid":"4c9ba968-364c-4f98-89b1-35acc4f932d1","banner":null,"lang":"en","date_modified":"2024-12-12","date_modified_ts":"2024-12-12T18:13:10Z","date_created":"2024-12-12T18:06:13Z","summary":null,"body":["<article data-history-node-id=\"5924\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av24-711\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-711<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 12, 2024<\/p>\n\n<p>Between December 10 and 12, 2024, Ivanti published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Ivanti Application Control\u00a0\u2013 versions 2024.3, 2024.1 and 2023.3<\/li>\n\t<li>Ivanti Automation\u00a0\u2013 version 2024.4 and prior<\/li>\n\t<li>Ivanti Performance Manager\u00a0\u2013 versions 2024.3, 2024.1 and 2023.3<\/li>\n\t<li>Ivanti Security Control\u00a0\u2013 versions 2024 and prior<\/li>\n\t<li>Ivanti Workspace Control\u00a0\u2013 versions 10.18.30.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/December-2024-Security-Advisory-Ivanti-Application-Control-CVE-2024-11598?language=en_US \">Ivanti\u00a0\u2013 December 2024 Security Advisory Ivanti Application Control<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/December-2024-Security-Advisory-Ivanti-Automation-CVE-2024-9845?language=en_US\">Ivanti\u00a0\u2013 December 2024 Security Advisory Ivanti Automation<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/December-2024-Security-Advisory-Ivanti-Performance-Manager-CVE-2024-11597?language=en_US\">Ivanti\u00a0\u2013 December 2024 Security Advisory Ivanti Performance Manager<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Security-Controls-iSec-CVE-2024-10251?language=en_US \">Ivanti\u00a0\u2013 Security Advisory\u00a0- Ivanti Security Controls (ISeC)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/December-2024-Security-Advisory-Ivanti-Workspace-Control-IWC-CVE-2024-8496?language=en_US \">Ivanti\u00a0\u2013 December 2024 Security Advisory Ivanti Workspace Control (IWC)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory] \">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av24-711","alert_type":396,"serial_number":"AV24-711","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5925,"title":"Microsoft Edge security advisory (AV24-712)","uuid":"4850c583-7340-4ca7-b91f-e99e7e2c3d3c","banner":null,"lang":"en","date_modified":"2024-12-13","date_modified_ts":"2024-12-13T14:27:45Z","date_created":"2024-12-13T14:21:51Z","summary":null,"body":["<article data-history-node-id=\"5925\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-712\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-712<br \/><strong>Date: <\/strong>December 13, 2024<\/p>\n\n<p>On December\u00a012,\u00a02024, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 131.0.2903.99<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-12-2024\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av24-712","alert_type":396,"serial_number":"AV24-712","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5927,"title":"Mozilla security advisory (AV24-713)","uuid":"e34046f6-9e2c-4430-ac58-35a8a656b3d4","banner":null,"lang":"en","date_modified":"2024-12-13","date_modified_ts":"2024-12-13T21:24:40Z","date_created":"2024-12-13T21:18:18Z","summary":null,"body":["<article data-history-node-id=\"5927\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av24-713\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-713<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 13, 2024<\/p>\n\n<p>On December 11, 2024, Mozilla published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 115.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2024-70\/\">Mozilla Security Advisory (MFSA 2024-70)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av24-713","alert_type":396,"serial_number":"AV24-713","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":5928,"title":"HPE security advisory (AV24-714)","uuid":"429bc657-3bfe-4fca-ae89-c4d33c92fe5b","banner":null,"lang":"en","date_modified":"2024-12-16","date_modified_ts":"2024-12-16T14:11:48Z","date_created":"2024-12-13T21:29:41Z","summary":null,"body":["<article data-history-node-id=\"5928\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av24-714\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-714<br \/><strong>Date: <\/strong>December\u00a016, 2024<\/p>\n\n<p>Between December\u00a010 and 11, 2024, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>HPE Service Director\u00a0\u2013 versions prior to v5.1.2<\/li>\n\t<li>HPE SimpliVity 325 Gen10\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 325 Gen10 Plus\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 325 Gen11\u00a0\u2013 versions prior to HPE SimpliVity Gen11 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 380 Gen11\u00a0\u2013 versions prior to HPE SimpliVity Gen11 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 380 Gen10\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 380 Gen10 G\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 380 Gen10 H\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 190r Gen10 Server\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 170r Gen10 Server\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n\t<li>HPE SimpliVity 380 Gen10 Plus\u00a0\u2013 versions prior to HPE SimpliVity Gen10 Support Pack (SVTSP) v2024_1129<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04768en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbnw04768<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04686en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04686<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04756en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04756<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04753en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbhf04753<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av24-714","alert_type":396,"serial_number":"AV24-714","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5929,"title":"Dell security advisory (AV24-715)","uuid":"45b1a38a-c7bc-4c7f-91c3-14b064ec3095","banner":null,"lang":"en","date_modified":"2024-12-16","date_modified_ts":"2024-12-16T14:32:43Z","date_created":"2024-12-16T13:43:16Z","summary":null,"body":["<article data-history-node-id=\"5929\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av24-715\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-715<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 16, 2024<\/p>\n\n<p>Between December 9 and 15, 2024, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.02.02.00<\/li>\n\t<li>Avamar Data Store Gen5A, Gen4T\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9, 19.10 and 19.10SP1<\/li>\n\t<li>Avamar Server\u00a0\u2013 versions 19.4, 19.7, 19.8, 19.9, 19.10 and 19.10SP1<\/li>\n\t<li>Data Lakehouse Bundle\u00a0\u2013 versions prior to 1.2.0.0<\/li>\n\t<li>Cloud Tiering Appliance CTA, CTA-HA, CTA\/VE and CTA-HA\/VE\u00a0\u2013 versions prior to 13.2.0.2.32<\/li>\n\t<li>Connectrix B-Series FOS\u00a0\u2013 multiple versions<\/li>\n\t<li>InsightIQ Installation Package\u00a0\u2013 versions prior to 5.1.1<\/li>\n\t<li>PowerFlex appliance IC\u00a0\u2013 versions prior to IC 46.376.00 and versions prior to IC 46.381.00<\/li>\n\t<li>PowerFlex rack RCM\u00a0\u2013 versions prior to 3.8.1.0 and versions prior to 3.7.6.0<\/li>\n\t<li>PowerFlex Manager\u00a0\u2013 versions prior to 4.6.1.0<\/li>\n\t<li>RecoverPoint for Virtual Machines\u00a0\u2013 versions 6.0 SP1 and 6.0 SP1 P1<\/li>\n\t<li>VxRail VxVerify\u00a0\u2013 versions prior to x.40.405<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av24-715","alert_type":396,"serial_number":"AV24-715","subject":"dell","moderation_state":"published","external_url":null},{"nid":5930,"title":"[Control systems] CISA ICS security advisories (AV24\u2013716)","uuid":"e90496c6-c5af-4266-82a9-b88350c313b0","banner":null,"lang":"en","date_modified":"2024-12-16","date_modified_ts":"2024-12-16T17:35:00Z","date_created":"2024-12-16T17:12:38Z","summary":null,"body":["<article data-history-node-id=\"5930\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-716\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-716<br \/><strong>Date: <\/strong>December 16, 2024<\/p>\n\n<p>Between December\u00a09 and 15,\u00a02024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Horner Automation Cscape\u00a0\u2013 versions 10.0.363.1 and prior<\/li>\n\t<li>MOBATIME Network Master Clock\u00a0- DTS 4801\u00a0\u2013 FW version 00020419.01.02020154<\/li>\n\t<li>National Instruments LabVIEW 2024\u00a0\u2013 versions Q3 (24.3f0) and prior<\/li>\n\t<li>National Instruments LabVIEW 2023\u00a0\u2013 all versions<\/li>\n\t<li>National Instruments LabVIEW 2022\u00a0\u2013 all versions<\/li>\n\t<li>National Instruments LabVIEW 2021 and prior\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation Arena\u00a0\u2013 versions prior to V16.20.06<\/li>\n\t<li>Schneider Electric EcoStruxure Foxboro DCS Core Control Services\u00a0\u2013 versions 9.8 and prior<\/li>\n\t<li>Schneider Electric FoxRTU Station\u00a0\u2013 versions prior to 9.3.0<\/li>\n\t<li>Siemens COMOS V10.4.4.1\u00a0\u2013 versions prior to V10.4.4.1.21<\/li>\n\t<li>Siemens COMOS V10.4.4\u00a0\u2013 versions prior to V10.4.4.2<\/li>\n\t<li>Siemens COMOS V10.4.3\u00a0\u2013 versions prior to V10.4.3.0.47<\/li>\n\t<li>Siemens COMOS V10.4.2\u00a0\u2013 all versions<\/li>\n\t<li>Siemens COMOS V10.4.1\u00a0\u2013 all versions<\/li>\n\t<li>Siemens COMOS V10.4.0\u00a0\u2013 all versions<\/li>\n\t<li>Siemens COMOS V10.3\u00a0\u2013 versions prior to V10.3.3.5.8<\/li>\n\t<li>Siemens CPCI85 Central Processing\/Communication\u00a0\u2013 versions prior to V05.30<\/li>\n\t<li>Siemens Parasolid V37.1\u00a0\u2013 versions prior to V37.1.109<\/li>\n\t<li>Siemens Parasolid V37.0\u00a0\u2013 versions prior to V37.0.173<\/li>\n\t<li>Siemens Parasolid V36.1\u00a0\u2013 versions prior to V36.1.225<\/li>\n\t<li>Siemens RUGGEDCOM ROX II\u00a0\u2013 versions prior to V2.16.0, multiple platforms<\/li>\n\t<li>Siemens SENTRON PowerCenter 1000 (7KN1110-0MC00)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SENTRON Powercenter 1100 (7KN1111-0MC00)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Simcenter Femap V2406\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Simcenter Femap V2401\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Simcenter Femap V2306\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC, SIMOCODE, SIMOTION, SINAMICS, SIRIUS and TIA Portal Cloud Engineering Platforms\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Solid Edge SE2024\u00a0\u2013 versions prior to V224.0<\/li>\n\t<li>Siemens Teamcenter Visualization V2406\u00a0\u2013 versions prior to V2406.0005<\/li>\n\t<li>Siemens Teamcenter Visualization V2312\u00a0\u2013 versions prior to V2312.0008<\/li>\n\t<li>Siemens Teamcenter Visualization V14.3\u00a0\u2013 versions prior to V14.3.0.12<\/li>\n\t<li>Siemens Teamcenter Visualization V14.2\u00a0\u2013 versions prior to V14.2.0.14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-716","alert_type":398,"serial_number":"AV24-716","subject":"ics","moderation_state":"published","external_url":null},{"nid":5931,"title":"IBM security advisory (AV24-717)","uuid":"36e3c6b6-8808-45f5-a30b-d201a96df4d1","banner":null,"lang":"en","date_modified":"2024-12-16","date_modified_ts":"2024-12-16T17:59:26Z","date_created":"2024-12-16T17:50:27Z","summary":null,"body":["<article data-history-node-id=\"5931\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-717\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-717<br \/><strong>Date: <\/strong>December 16, 2024<\/p>\n\n<p>Between December\u00a09 and 15,\u00a02024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM App Connect Enterprise\u00a0\u2013 versions 13.0.1.0 to 13.0.1.1, versions 12.0.1.0 to 12.0.12.8<\/li>\n\t<li>IBM Cloud Pak for AIOps\u00a0\u2013 versions 4.1.0 to 4.7.1<\/li>\n\t<li>IBM Cognos Dashboards on Cloud Pak for Data\u00a0\u2013 versions 5.0.0 and 4.8.0<\/li>\n\t<li>IBM Guardium Data Security Center\u00a0\u2013 version 3.4.1<\/li>\n\t<li>IBM Operations Analytics\u00a0- Log Analysis\u00a0\u2013 version 1.3.8.0<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 versions 1.15.0 IF004, 1.15.0 IF003, 1.15.0 IF002, 1.15.0 IF001 and 1.15.0<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP10 IF01<\/li>\n\t<li>QRadar Incident Forensics\u00a0\u2013 versions 7.5 to 7.5.0 UP10 IF01<\/li>\n\t<li>IBM Security QRadar Log Management AQL Plugin\u00a0\u2013 version 1.0.0<\/li>\n\t<li>IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.0.0 to 5.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-717","alert_type":396,"serial_number":"AV24-717","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5932,"title":"Ubuntu security advisory (AV24-718)","uuid":"9615dcd1-70d4-4212-ba45-2e6cf588b019","banner":null,"lang":"en","date_modified":"2024-12-16","date_modified_ts":"2024-12-16T19:23:07Z","date_created":"2024-12-16T18:55:01Z","summary":null,"body":["<article data-history-node-id=\"5932\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-718\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-718<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 16, 2024<\/p>\n\n<p>Between December 9 and December 15, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-718","alert_type":396,"serial_number":"AV24-718","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5933,"title":"CVE-2024-53677 - Vulnerability impacting Apache Struts 2","uuid":"1a6f9541-1c5a-4e08-aeff-72d6324bf541","banner":null,"lang":"en","date_modified":"2024-12-16","date_modified_ts":"2024-12-16T19:44:20Z","date_created":"2024-12-16T19:03:25Z","summary":null,"body":["<article data-history-node-id=\"5933\" about=\"\/en\/alerts-advisories\/cve-2024-53677-vulnerability-impacting-apache-struts-2\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL24-013<br \/><strong>Date: <\/strong>December 16, 2024<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>On November 26 2024, the Apache Software Foundation released a security bulletin for CVE-2024-53677, a critical vulnerability affecting both end-of-life and current versions of Apache Struts 2<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>The vulnerability has been assigned a CVSS severity rating of 9.5 out of 10<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>A malicious actor can exploit this vulnerability to traverse system paths, upload malicious files, and perform remote code execution<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2b-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>The versions of Apache Struts 2 affected by this vulnerability are:<\/p>\n\n<ul><li>2.0.0 to 2.3.37<\/li>\n\t<li>2.5.0 to 2.5.33<\/li>\n\t<li>6.0.0 to 6.3.0.2<\/li>\n<\/ul><p>Note that only applications that use FileUploadInterceptor are vulnerable<sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. FileUploadInterceptor is deprecated as of Struts 6.4.0.<sup id=\"fn2c-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/p>\n\n<p>Apache Struts 2 is widely adopted in both the private and public sectors and past vulnerabilities have had significant business impact.<\/p>\n\n<p>The Cyber Centre is aware that a proof of concept (POC) exploit is available for this CVE. The existence of a published POC makes it imperative to take action to assess and mitigate this vulnerability.<\/p>\n<\/section><h2>Recommendations<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations patch the affected Apache Struts 2 systems to versions 6.4.0 or greater and remove the deprecated FileUploadInterceptor. Similar functionality is supported by ActionFileUploadInterceptor.<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/p>\n\n<p>Apache Struts versions 2.0.0 to 2.3.37 are vulnerable but are no longer supported and therefore present significant business risk. Impacted organizations should replace unsupported products with supported versions.<sup id=\"fn1d-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/p>\n\n<p>The Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Assess the inventory of Apache Struts on their hosts and monitor for signs of exploitation,<\/li>\n\t<li>Apply software patches to Apache Struts 2 without delay.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> with an emphasis on the following strategies:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-067\">Apache Struts 2 Security Bulletin - S2-067<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/struts.apache.org\/core-developers\/file-upload-interceptor\">File Upload Interceptor <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/apache-security-advisory-av24-708\">AV23-708 \u2013 Apache security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-53677\">CVE-2023-53677 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><section><h2>Partner reporting<\/h2>\n\n<p><a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/critical-security-vulnerability-affecting-apache-struts2-below-6-4-0\">ASCS \u2013 Critical security vulnerability affecting Apache Struts2 below 6.4.0<\/a><\/p>\n\n<h2>About The Cyber Centre<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security, and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses, and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n<\/section><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cve-2024-53677-vulnerability-impacting-apache-struts-2","alert_type":397,"serial_number":"AL24-013","subject":"other","moderation_state":"published","external_url":null},{"nid":5934,"title":"[Control systems] Siemens security advisory (AV24-719) ","uuid":"3b4e631c-0492-4e2e-9e12-3291f811d08e","banner":null,"lang":"en","date_modified":"2024-12-16","date_modified_ts":"2024-12-16T19:45:41Z","date_created":"2024-12-16T19:36:00Z","summary":null,"body":["<article data-history-node-id=\"5934\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-719\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-719<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 16, 2024<\/p>\n\n<p>On December 16, 2024, Siemens published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Opcenter Execution Foundation\u00a0\u2013 all versions<\/li>\n\t<li>Opcenter Intelligence\u00a0\u2013 all versions<\/li>\n\t<li>Opcenter Quality\u00a0\u2013 all versions<\/li>\n\t<li>Opcenter RDL\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC PCS neo<\/li>\n\t<li>SINEC NMS\u00a0\u2013 all versions<\/li>\n\t<li>Totally Integrated Automation Portal<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-928984.html?ste_sid=ee8ee88d412b10e86a45542d24a25db6\">SSA-928984: Heap-based Buffer Overflow Vulnerability in User Management Component (UMC)<\/a><\/li>\n\t<li><a href=\"https:\/\/new.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av24-719","alert_type":398,"serial_number":"AV24-719","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5935,"title":"Foxit security advisory (AV24-720)","uuid":"59e78b4e-4c97-4334-8438-4389832f12c1","banner":null,"lang":"en","date_modified":"2024-12-17","date_modified_ts":"2024-12-17T14:51:54Z","date_created":"2024-12-17T14:45:57Z","summary":null,"body":["<article data-history-node-id=\"5935\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av24-720\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-720<br \/><strong>Date: <\/strong>December 17, 2024<\/p>\n\n<p>On December 17, 2024, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor (Windows) \u2013 multiple versions<\/li>\n\t<li>Foxit PDF Editor for Mac \u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader (Windows) \u2013 version 2024.3.0.26795 and prior<\/li>\n\t<li>Foxit PDF Reader for Mac \u2013 version 2024.3.0.65538 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-French-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av24-720","alert_type":396,"serial_number":"AV24-720","subject":"other","moderation_state":"published","external_url":null},{"nid":5937,"title":" Fortinet security advisory (AV24-721)","uuid":"0b4a75ea-0090-441d-a987-0860c09a9620","banner":null,"lang":"en","date_modified":"2024-12-18","date_modified_ts":"2024-12-18T19:22:30Z","date_created":"2024-12-18T19:04:25Z","summary":null,"body":["<article data-history-node-id=\"5937\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av24-721\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-721<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 18, 2024<\/p>\n\n<p>On December 18, 2024, Fortinet published security advisories to address vulnerabilities the following products::<\/p>\n\n<ul><li>FortiClientLinux 7.4\u00a0\u2013 versions 7.4.0 to 7.4.2<\/li>\n\t<li>FortiClientLinux 7.2\u00a0\u2013 versions 7.2.0 to 7.2.7<\/li>\n\t<li>FortiClientLinux 7.0\u00a0\u2013 versions 7.0.0 to 7.0.13<\/li>\n\t<li>FortiClientWindows 7.4\u00a0\u2013 versions 7.4.0 to 7.4.1<\/li>\n\t<li>FortiClientWindows 7.2\u00a0\u2013 versions 7.2.0 to 7.2.6<\/li>\n\t<li>FortiClientWindows 7.0\u00a0\u2013 versions 7.0.0 to 7.0.13<\/li>\n\t<li>FortiManager 7.6\u00a0\u2013 version 7.6.0<\/li>\n\t<li>FortiManager 7.4\u00a0\u2013 versions 7.4.0 to 7.4.4 and versions Cloud 7.4.1 to 7.4.4<\/li>\n\t<li>FortiManager 7.2\u00a0\u2013 versions 7.2.3 to 7.2.7 and versions Cloud 7.2.1 to 7.2.7<\/li>\n\t<li>FortiManager 7.0\u00a0\u2013 version 7.0.5 to 7.0.12 and versions Cloud 7.0.1 to 7.0.12<\/li>\n\t<li>FortiManager 6.4\u00a0\u2013 versions 6.4.10 to 6.4.14<\/li>\n\t<li>FortiWLM 8.6\u00a0\u2013 versions 8.6.0 to 8.6.5<\/li>\n\t<li>FortiWLM 8.5\u00a0\u2013 versions 8.5.0 to 8.5.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-278\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-278<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-425\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-425<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-144\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-144<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av24-721","alert_type":396,"serial_number":"AV24-721","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":5938,"title":"Apache security advisory (AV24-722) - Update 1","uuid":"2fc2b089-9330-4e2c-ae57-d2aaf5d22d34","banner":null,"lang":"en","date_modified":"2024-12-23","date_modified_ts":"2024-12-23T21:32:50Z","date_created":"2024-12-18T20:45:08Z","summary":null,"body":["<article data-history-node-id=\"5938\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av24-722\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-722<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 18, 2024<\/p>\n\n<p>On December 17, 2024, Apache published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Apache Tomcat\u00a0\u2013 versions 11.0.0-M1 to 11.0.1<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 10.1.0-M1 to 10.1.33<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 9.0.0.M1 to 9.0.97<\/li>\n<\/ul><p><strong>Update 1<\/strong><\/p>\n\n<p>On December 20, 2024, Apache updated its advisory to address the incomplete mitigation for CVE-2024-50379, now being tracked as CVE-2024-56337. Full mitigation requires additional steps on top of the updates Apache released on December 17. These additional steps depend on the specific Java versions in use:<\/p>\n\n<ul><li>For Java 8 or 11, it is recommended to set the system property \u2018sun.io.useCanonCaches\u2019 to \u2018false\u2019 (default: true).<\/li>\n\t<li>For Java 17, ensure \u2018sun.io.useCanonCaches,\u2019 if set, is configured as false (default: false).<\/li>\n\t<li>For Java 21 and later, no configuration is needed. The property and problematic cache have been removed.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/y6lj6q1xnp822g6ro70tn19sgtjmr80r\">[SECURITY] CVE-2024-50379 Apache Tomcat\u00a0- RCE via write-enabled default servlet<\/a><\/li>\n\t<li><a href=\"https:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.98 \">Fixed in Apache Tomcat 9.0.98<\/a><\/li>\n\t<li><a href=\"https:\/\/tomcat.apache.org\/security-10.html#Fixed_in_Apache_Tomcat_10.1.34 \">Fixed in Apache Tomcat 10.1.34<\/a><\/li>\n\t<li><a href=\"https:\/\/tomcat.apache.org\/security-11.html#Fixed_in_Apache_Tomcat_11.0.2 \">Fixed in Apache Tomcat 11.0.2<\/a><\/li>\n\t<li><a href=\"https:\/\/tomcat.apache.org\/\">Apache Tomcat<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av24-722","alert_type":396,"serial_number":"AV24-722","subject":"other","moderation_state":"published","external_url":null},{"nid":5939,"title":"Google Chrome security advisory (AV24-723)","uuid":"ee99dde5-ee0b-4377-bf04-ba7defeee1f7","banner":null,"lang":"en","date_modified":"2024-12-19","date_modified_ts":"2024-12-19T14:08:50Z","date_created":"2024-12-19T13:53:06Z","summary":null,"body":["<article data-history-node-id=\"5939\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-723\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-723<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 19, 2024<\/p>\n\n<p>On December 18, 2024, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 131.0.6778.204\/.205 (Windows and Mac) and 131.0.6778.204 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2024\/12\/stable-channel-update-for-desktop_18.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av24-723","alert_type":396,"serial_number":"AV24-723","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":5940,"title":"BeyondTrust security advisory (AV24-724)","uuid":"15061d35-75ee-4fe2-8d9d-dc6ddcf3b7ec","banner":null,"lang":"en","date_modified":"2024-12-19","date_modified_ts":"2024-12-19T16:46:39Z","date_created":"2024-12-19T16:41:44Z","summary":null,"body":["<article data-history-node-id=\"5940\" about=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av24-724\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-724<br \/><strong>Date: <\/strong>December\u00a019, 2024<\/p>\n\n<p>On December\u00a016, 2024, BeyondTrust published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Privileged Remote Access (<abbr>PRA<\/abbr>)\u00a0\u2013 versions 24.3.1 and prior<\/li>\n\t<li>Remote Support (<abbr>RS<\/abbr>)\u00a0\u2013 versions 24.3.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt24-10\">BeyondTrust Security Advisory\u00a0- Advisory <abbr>ID<\/abbr>: BT24-10<\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\">BeyondTrust Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/beyondtrust-security-advisory-av24-724","alert_type":396,"serial_number":"AV24-724","subject":"other","moderation_state":"published","external_url":null},{"nid":5941,"title":"Sophos security advisory (AV24-725)","uuid":"b336ca69-910e-4303-ba17-917e7277165e","banner":null,"lang":"en","date_modified":"2024-12-20","date_modified_ts":"2024-12-20T19:00:41Z","date_created":"2024-12-20T18:47:02Z","summary":null,"body":["<article data-history-node-id=\"5941\" about=\"\/en\/alerts-advisories\/sophos-security-advisory-av24-725\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV24-725<br \/><strong>Date: <\/strong>December\u00a020, 2024<\/p>\n\n<p>On December\u00a019, 2024, Sophos published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Sophos Firewall\u00a0\u2013 version v21.0 GA (21.0.0) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sophos.com\/en-us\/security-advisories\/sophos-sa-20241219-sfos-rce\">Sophos Security Advisory\u00a0- Resolved Multiple Vulnerabilities in Sophos Firewall (CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.sophos.com\/en-us\/security-advisories\">Sophos Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sophos-security-advisory-av24-725","alert_type":396,"serial_number":"AV24-725","subject":"other","moderation_state":"published","external_url":null},{"nid":5942,"title":"Ubuntu security advisory (AV24-726)","uuid":"4a13596d-bfc4-4ae7-957c-4e8f30d0245e","banner":null,"lang":"en","date_modified":"2024-12-23","date_modified_ts":"2024-12-23T14:02:21Z","date_created":"2024-12-23T13:57:54Z","summary":null,"body":["<article data-history-node-id=\"5942\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-726\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-726<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 23, 2024<\/p>\n\n<p>Between December 16 and December 22, 2024, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av24-726","alert_type":396,"serial_number":"AV24-726","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5943,"title":"IBM security advisory (AV24-727)","uuid":"bdc16285-4fdd-43d5-977e-5af8f0509905","banner":null,"lang":"en","date_modified":"2024-12-23","date_modified_ts":"2024-12-23T14:13:06Z","date_created":"2024-12-23T14:08:23Z","summary":null,"body":["<article data-history-node-id=\"5943\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-727\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-727<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 23, 2024<\/p>\n\n<p>Between December 16 and 22, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>API Connect \u2013 version V10.0.0 to V10.0.8<\/li>\n\t<li>IBM Asset Data Dictionary Component \u2013 version 1.1<\/li>\n\t<li>IBM Cognos Analytics \u2013 versions 11.2.0 to 11.2.4 FP4 and 12.0.0 to 12.0.3<\/li>\n\t<li>IBM Planning Analytics \u2013 versions 2.0 and 2.1<\/li>\n\t<li>IBM Planning Analytics Local - IBM Planning Analytics Workspace \u2013 versions 2.0 and 2.1<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data \u2013 version 4.0.0 to 5.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-727","alert_type":396,"serial_number":"AV24-727","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5944,"title":"[Control systems] CISA ICS security advisories (AV24\u2013728) ","uuid":"23ff24bb-d3fe-47bf-8a99-b4a5517a2020","banner":null,"lang":"en","date_modified":"2024-12-23","date_modified_ts":"2024-12-23T14:27:00Z","date_created":"2024-12-23T14:15:36Z","summary":null,"body":["<article data-history-node-id=\"5944\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-728\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-728<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 23, 2024<\/p>\n\n<p>Between December 16 and 22, 2024, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BD Diagnostic Solutions BACTEC Blood Culture System\u00a0\u2013 all versions<\/li>\n\t<li>BD Diagnostic Solutions COR System\u00a0\u2013 all versions<\/li>\n\t<li>BD Diagnostic Solutions EpiCenter Microbiology Data Management System\u00a0\u2013 all versions<\/li>\n\t<li>BD Diagnostic Solutions MAX System\u00a0\u2013 all versions<\/li>\n\t<li>BD Diagnostic Solutions Phoenix M50 Automated Microbiology System\u00a0\u2013 all versions<\/li>\n\t<li>BD Diagnostic\u00a0\u2013 all versions<\/li>\n\t<li>Delta Electronics DTM Soft\u00a0\u2013 versions 1.30 and prior<\/li>\n\t<li>Hitachi Energy RTU400 series CMU Firmware\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy SDM600\u00a0\u2013 versions prior to 1.3.4<\/li>\n\t<li>Hitachi Energy TropOS devices series 1400\/2400\/6400\u00a0\u2013 versions prior to 8.9.6<\/li>\n\t<li>Ossur Mobile Logic Application\u00a0\u2013 versions prior to 1.5.5<\/li>\n\t<li>Rockwell Automation PowerMonitor 1000 Remove\u00a0\u2013 multiple models, versions prior to 4.020<\/li>\n\t<li>Schneider Electric Accutech Manager\u00a0\u2013 versions 2.08.01 and prior<\/li>\n\t<li>Schneider Electric Modicon Controllers M241\u00a0\u2013 versions prior to 5.2.11.24<\/li>\n\t<li>Schneider Electric Modicon Controllers M251\u00a0\u2013 versions prior to 5.2.11.24<\/li>\n\t<li>Schneider Electric Modicon Controllers M258\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Controllers M262\u00a0\u2013 versions prior to 5.2.8.26<\/li>\n\t<li>Schneider Electric Modicon Controllers LMC058\u00a0\u2013 all versions<\/li>\n\t<li>Siemens User Management Component\u00a0\u2013 multiple applications and versions<\/li>\n\t<li>ThreatQuotient ThreatQ\u00a0\u2013 versions prior to 5.29.3<\/li>\n\t<li>Tibbo AggreGate Network Manager\u00a0\u2013 versions 6.34.02 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av24-728","alert_type":398,"serial_number":"AV24-728","subject":"ics","moderation_state":"published","external_url":null},{"nid":5946,"title":"Adobe security advisory (AV24\u2013729)","uuid":"116896d0-6738-438f-b6f1-a99d9ed25424","banner":null,"lang":"en","date_modified":"2024-12-24","date_modified_ts":"2024-12-24T14:41:41Z","date_created":"2024-12-24T14:23:17Z","summary":null,"body":["<article data-history-node-id=\"5946\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av24-729\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-729<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 24, 2024<\/p>\n\n<p>On December 23, 2024, Adobe published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>ColdFusion 2021 \u2013 versions prior to Update 18<\/li>\n\t<li>ColdFusion 2023 \u2013 versions prior to Update 12<\/li>\n<\/ul><p>Adobe is aware that vulnerability CVE-2024-53961 has a known proof-of-concept.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-53961\">NVD\u00a0- CVE-2024-53961<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb24-107.html\">Adobe Security Bulletin\u00a0- APSB24-107<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av24-729","alert_type":396,"serial_number":"AV24-729","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5947,"title":"Palo Alto Networks security advisory (AV24-730)","uuid":"9785a9f8-b5ad-4810-a56d-27241ed8a52a","banner":null,"lang":"en","date_modified":"2024-12-27","date_modified_ts":"2024-12-27T15:00:51Z","date_created":"2024-12-27T14:55:25Z","summary":null,"body":["<article data-history-node-id=\"5947\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-730\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-730<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 27, 2024<\/p>\n\n<p>On December 26, 2024, Palo Alto Networks published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>PAN-OS 11.2 \u2013 versions prior to 11.2.3<\/li>\n\t<li>PAN-OS 11.1 \u2013 versions prior to 11.1.5<\/li>\n\t<li>PAN-OS 10.2 \u2013 versions 10.2.8 and later, versions prior to 10.2.10-h2 and versions prior to 10.2.13.h2<\/li>\n\t<li>PAN-OS 10.1 \u2013 versions 10.1.14 and later, versions prior to 10.1.14-h8<\/li>\n\t<li>Prisma Access \u2013 versions 10.2.8 on PAN-OS and later, versions prior to 11.2.3 on PAN-OS<\/li>\n<\/ul><p>Exploitation of this vulnerability could lead to denial of service (DoS). Palo Alto Networks has indicated that CVE-2024-3393 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2024-3393 \">Palo Alto Networks Security Advisories \u2013 CVE-2024-3393<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av24-730","alert_type":396,"serial_number":"AV24-730","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5948,"title":"Apache security advisory (AV24-731)","uuid":"335a6014-1bed-4052-9e20-0d7711f0f5d5","banner":null,"lang":"en","date_modified":"2024-12-27","date_modified_ts":"2024-12-27T15:13:09Z","date_created":"2024-12-27T15:09:38Z","summary":null,"body":["<article data-history-node-id=\"5948\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av24-731\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n<p><strong>Serial number: <\/strong>AV24-731\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 27, 2024\n<\/p>\n<p>Between December 23 and 25, 2024, Apache published  security advisories to address  critical vulnerabilities in the following products:\n<\/p>\n<ul><li>Apache MINA \u2013 versions 2.0.x prior to 2.0.27<\/li>\n  <li>Apache MINA \u2013 versions 2.1.x prior to 2.1.10<\/li>\n  <li>Apache MINA \u2013 versions 2.2.x prior to 2.2.4<\/li>\n  <li>Apache Traffic Control \u2013 version 8.0.0 to 8.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-45387\">CVE-2024-45387<\/a><\/li>\n  <li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-52046\">CVE-2024-52046<\/a><\/li>\n  <li><a href=\"https:\/\/lists.apache.org\/thread\/t38nk5n7t8w3pb66z7z4pqfzt4443trr\">Apache Security Bulletins<\/a><\/li>\n    <li><a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2024\/12\/25\/1\">Apache Security Bulletins (Openwall)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av24-731","alert_type":396,"serial_number":"AV24-731","subject":"other","moderation_state":"published","external_url":null},{"nid":5949,"title":"IBM security advisory (AV24-732)","uuid":"d6fc07aa-31d9-4ad9-9dee-6fbcf15b007b","banner":null,"lang":"en","date_modified":"2024-12-30","date_modified_ts":"2024-12-30T15:35:46Z","date_created":"2024-12-30T15:28:42Z","summary":null,"body":["<article data-history-node-id=\"5949\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av24-732\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV24-732<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 30, 2024<\/p>\n\n<p>Between December 23 and 29, 2024, IBM published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>IBM Content Collector for SAP Applications \u2013 version 4.0.0<\/li>\n\t<li>IBM Security QRadar Log Management AQL Plugin \u2013 version 1.0 to 1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7179733 \">IBM Security Bulletin (IBM Content Collector for SAP Applications)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7179757 \">IBM Security Bulletin (IBM Security QRadar Log Management AQL Plugin)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av24-732","alert_type":396,"serial_number":"AV24-732","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5951,"title":"Dell security advisory (AV25-001)","uuid":"34230153-69e8-461c-bd2f-d2ece251452a","banner":null,"lang":"en","date_modified":"2025-01-06","date_modified_ts":"2025-01-06T19:38:17Z","date_created":"2025-01-06T19:28:39Z","summary":null,"body":["<article data-history-node-id=\"5951\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-001\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-001<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 6, 2025<\/p>\n\n<p>Between December 30, 2024 and January 5, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Apache Tomcat on Dell OpenManage Server Administrator\u00a0\u2013 versions prior to 11.1.0.0<\/li>\n\t<li>Apache Tomcat on Dell Systems Management Tools and Documentation DVD ISO\u00a0\u2013 versions prior to 11.1.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000267482\/dsa-2025-031-dell-openmanage-server-administrator-omsa-security-update-for-apache-tomcat-unchecked-error-condition-vulnerability\">Dell Security Advisory DSA-2025-031<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-us\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-001","alert_type":396,"serial_number":"AV25-001","subject":"other","moderation_state":"published","external_url":null},{"nid":5952,"title":"HPE security advisory (AV25-002)","uuid":"62945b85-0633-4b67-a84e-8dd6a0d55b28","banner":null,"lang":"en","date_modified":"2025-01-06","date_modified_ts":"2025-01-06T20:26:24Z","date_created":"2025-01-06T19:42:53Z","summary":null,"body":["<article data-history-node-id=\"5952\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-002\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-002<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 6, 2025<\/p>\n\n<p>On January 6, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Brocade Fabric OS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04758en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbst04758<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-002","alert_type":396,"serial_number":"AV25-002","subject":"other","moderation_state":"published","external_url":null},{"nid":5953,"title":"IBM security advisory (AV25-003)","uuid":"f04764a4-bb0e-4896-9009-c9cb36c7f744","banner":null,"lang":"en","date_modified":"2025-01-06","date_modified_ts":"2025-01-06T21:20:22Z","date_created":"2025-01-06T20:29:41Z","summary":null,"body":["<article data-history-node-id=\"5953\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-003\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-003<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 6, 2024<\/p>\n\n<p>Between December 30, 2024 and January 5, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>API Big SQL on IBM Cloud Pak for Data\u00a0\u2013 versions IBM Big SQL 7.2, IBM Big SQL 7.3, IBM Big SQL 7.4 and IBM Big SQL 7.5<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\u00a0\u2013 versions 8.10.14, 8.11.12 and 9.0.4<\/li>\n\t<li>IBM\u00ae Db2\u00ae on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 versions v3.5 through refresh 10, v4.0 through refresh 9, v4.5 through refresh 3, v4.6 through refresh 6, v4.7 through refresh 4, v4.8 through refresh 6, v5.0 through refresh 2 and v5.0 through<\/li>\n\t<li>refresh 3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7180134\">IBM Security Bulletin (IBM Big SQL on IBM Cloud Pak for Data)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7180000\">IBM Security Bulletin (IBM Maximo Application Suite\u00a0- Monitor Component)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7180105\">IBM Security Bulletin (IBM\u00ae Db2\u00ae on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-003","alert_type":396,"serial_number":"AV25-003","subject":"other","moderation_state":"published","external_url":null},{"nid":5954,"title":"[Control Systems] Moxa security advisory (AV25-004)","uuid":"bb7fb0c1-7371-47cc-b98d-d1faee9138f6","banner":null,"lang":"en","date_modified":"2025-01-07","date_modified_ts":"2025-01-07T15:38:15Z","date_created":"2025-01-07T15:02:34Z","summary":null,"body":["<article data-history-node-id=\"5954\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av25-004\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-004<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 7, 2025<\/p>\n\n<p>On January 3, 2025, Moxa published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>EDR-810 Series\u00a0\u2013 firmware version 5.12.37 and prior<\/li>\n\t<li>EDR-8010 Series\u00a0\u2013 firmware version 3.13.1 and prior<\/li>\n\t<li>EDR-G902 Series\u00a0\u2013 firmware version 5.7.25 and prior<\/li>\n\t<li>EDR-G902 Series\u00a0\u2013 firmware version 5.7.25 and prior<\/li>\n\t<li>EDR-G9004 Series\u00a0\u2013 firmware version 3.13.1 and prior<\/li>\n\t<li>EDR-G9010 Series\u00a0\u2013 firmware version 3.13.1 and prior<\/li>\n\t<li>EDF-G1002-BP Series\u00a0\u2013 firmware version 3.13.1 and prior<\/li>\n\t<li>NAT-102 Series\u00a0\u2013 firmware version 1.0.5 and prior<\/li>\n\t<li>OnCell G4302-LTE4 Series\u00a0\u2013 firmware version 3.13 and prior<\/li>\n\t<li>TN-4900 Series\u00a0\u2013 firmware version 3.13 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo\">Moxa Security Advisory\u00a0- MPSA-241155<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av25-004","alert_type":398,"serial_number":"AV25-004","subject":"other","moderation_state":"published","external_url":null},{"nid":5955,"title":"Android security advisory \u2013 January 2025 Monthly Rollup (AV25-005)","uuid":"f89eb2b8-d7e7-46f0-99ac-17a5f6d774ad","banner":null,"lang":"en","date_modified":"2025-01-07","date_modified_ts":"2025-01-07T18:15:51Z","date_created":"2025-01-07T18:04:07Z","summary":null,"body":["<article data-history-node-id=\"5955\" about=\"\/en\/alerts-advisories\/android-security-advisory-january-2025-monthly-rollup-av25-005\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-005<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 7, 2024<\/p>\n\n<p>On January 6, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-01-01?hl=fr\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-january-2025-monthly-rollup-av25-005","alert_type":396,"serial_number":"AV25-005","subject":"android","moderation_state":"published","external_url":null},{"nid":5956,"title":" [Control systems] CISA ICS security advisories (AV25-006) ","uuid":"4d4d8899-0e50-4c71-9072-b25dec434850","banner":null,"lang":"en","date_modified":"2025-01-07","date_modified_ts":"2025-01-07T21:32:16Z","date_created":"2025-01-07T21:12:48Z","summary":null,"body":["<article data-history-node-id=\"5956\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-006\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-006<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 7, 2024<\/p>\n\n<p>On January 7, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB ASPECT-Enterprise ASP-ENT-x\u00a0\u2013 versions 3.07.02 and prior<\/li>\n\t<li>ABB NEXUS Series\u00a0\u2013 multiple models and versions<\/li>\n\t<li>ABB MATRIX Series\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Nedap Librix Ecoreader\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-006","alert_type":398,"serial_number":"AV25-006","subject":"ics","moderation_state":"published","external_url":null},{"nid":5958,"title":"SonicWall security advisory (AV25-007) - Update 1","uuid":"f4379881-73c0-497a-afc4-6c1505fc28c0","banner":null,"lang":"en","date_modified":"2025-02-19","date_modified_ts":"2025-02-19T16:50:36Z","date_created":"2025-01-08T16:57:08Z","summary":null,"body":["<article data-history-node-id=\"5958\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-007\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-007\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 8, 2025\n  <br \/><strong>Updated: <\/strong>February 19, 2025\n<\/p>\n<p>On January 7, 2025, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">SonicWall<\/span> published security advisories to address vulnerabilities in multiple products. Included were updates for the following:\n<\/p>\n<ul><li>SonicWall Gen6 Hardware Firewalls\u00a0\u2013 multiple models and version 6.5.4.15-117n and prior<\/li>\n  <li>SonicWall Gen7 Firewalls\u00a0\u2013 multiple models and versions<\/li>\n  <li>SonicWall Gen7 NSv\u00a0\u2013 multiple models and versions<\/li>\n  <li>SonicWall Gen7 Cloud Platform NSv\u00a0\u2013 multiple models and versions<\/li>\n  <li>SonicWall TZ80\u00a0\u2013 version 8.0.0-8035<\/li>\n<\/ul><h2>Update 1\n<\/h2>\n<p>On February 18, 2025, CISA added CVE-2024-53704 to their Known Exploited Vulnerabilities (KEV) Catalog.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0003\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2025-0003<\/a><\/li>\n  <li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n  <li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">CISA\u00a0- Known Exploited Vulnerabilities Catalog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-007","alert_type":396,"serial_number":"AV25-007","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":5959,"title":"Ivanti security advisory (AV25-008)","uuid":"bb83165c-c42a-491a-9509-7fa66780ac28","banner":null,"lang":"en","date_modified":"2025-01-08","date_modified_ts":"2025-01-08T19:16:58Z","date_created":"2025-01-08T18:19:32Z","summary":null,"body":["<article data-history-node-id=\"5959\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-008\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-008<br \/><strong>Date: <\/strong>January\u00a08, 2025<\/p>\n\n<p>On January\u00a08, 2025, Ivanti published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Ivanti Connect Secure\u00a0\u2013 versions prior to 22.7R2.5 and versions 9.1R18.9 and prior<\/li>\n\t<li>Ivanti Policy Secure\u00a0\u2013 versions prior to 22.7R1.2<\/li>\n\t<li>Ivanti Neurons for ZTA Gateways\u00a0\u2013 versions prior to 22.7R2.3<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an unauthenticated actor to execute remote code.<\/p>\n\n<p>Ivanti has reported that vulnerability CVE-2025-0282 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283?language=en_US\">Security Advisory Ivanti Connect Secure, Policy Secure &amp; ZTA Gateways<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-008","alert_type":396,"serial_number":"AV25-008","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5960,"title":"Palo Alto Networks security advisory (AV25-009)","uuid":"1b4bb792-bea9-4120-a693-9751d58ecd59","banner":null,"lang":"en","date_modified":"2025-01-08","date_modified_ts":"2025-01-08T19:32:18Z","date_created":"2025-01-08T19:01:17Z","summary":null,"body":["<article data-history-node-id=\"5960\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-009\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-009<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 8, 2024<\/p>\n\n<p>On January 8, 2025, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following\u00a0:<\/p>\n\n<ul><li>Expedition 1 migration tool\u00a0\u2013 versions prior to 1.2.101<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0001\">Palo Alto Networks Security Advisory\u00a0\u2013 PAN-SA-2025-0001<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-009","alert_type":396,"serial_number":"AV25-009","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":5961,"title":"[Control systems] ABB security advisory (AV25-010) ","uuid":"354061ce-31b3-4663-8d53-62915565ef74","banner":null,"lang":"en","date_modified":"2025-01-08","date_modified_ts":"2025-01-08T20:08:17Z","date_created":"2025-01-08T20:00:16Z","summary":null,"body":["<article data-history-node-id=\"5961\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-010\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-010\n  <br \/><strong>Date: <\/strong>January\u00a08, 2025\n<\/p>\n<p>On January\u00a07, 2025, ABB published a security advisory to address vulnerabilities in the following product:\n<\/p>\n<ul><li>ABB AC500 V3\u00a0\u2013 firmware versions prior to 3.8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011377&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Cyber Security Advisory\u00a0- 3ADR011377 (PDF)<\/a><\/li>\n  <li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-010","alert_type":398,"serial_number":"AV25-010","subject":"abb","moderation_state":"published","external_url":null},{"nid":5965,"title":"Juniper Networks security advisory (AV25-011)","uuid":"1f96dcc8-1ca1-428b-8cbb-343e5122f704","banner":null,"lang":"en","date_modified":"2025-01-10","date_modified_ts":"2025-01-10T14:09:08Z","date_created":"2025-01-10T14:04:12Z","summary":null,"body":["<article data-history-node-id=\"5965\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-011\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-011<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 10, 2025<\/p>\n\n<p>On January 8, 2025, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Junos OS \u2013 multiple versions<\/li>\n\t<li>Junos OS Evolved \u2013 multiple versions<\/li>\n\t<li>Junos Space \u2013 versions prior to 24.1R2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2025-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-When-BGP-traceoptions-are-configured-receipt-of-malformed-BGP-packets-causes-RPD-to-crash-CVE-2025-21598?language=en_US \">Juniper Networks Security\u00a0- JSA92867<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-011","alert_type":396,"serial_number":"AV25-011","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5966,"title":"IBM security advisory (AV25-012)","uuid":"edf46aa5-6f4b-4eed-9463-7f6cbf95c58f","banner":null,"lang":"en","date_modified":"2025-01-13","date_modified_ts":"2025-01-13T15:32:54Z","date_created":"2025-01-13T15:26:54Z","summary":null,"body":["<article data-history-node-id=\"5966\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-012\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-012<br \/><strong>Date: <\/strong>January\u00a013, 2025<\/p>\n\n<p>Between January\u00a06 and 12, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cloud APM, Base Private\u00a0\u2013 versions 8.1.4.0 to 8.1.4.0 IF16<\/li>\n\t<li>IBM Cloud APM, Advanced Private\u00a0\u2013 versions 8.1.4.0 to 8.1.4.0 IF16<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 versions 12.0.0 t0 12.03, 11.2.0 to 11.2.4 FP4<\/li>\n\t<li>IBM Engineering Requirements Management DOORS Next\u00a0\u2013 versions 7.02 and 7.03<\/li>\n\t<li>IBM Jazz Foundation\u00a0\u2013 versions 7.02, 7.03 and 7.1.0<\/li>\n\t<li>IBM Jazz Reporting Service\u00a0\u2013 versions 7.02 and 7.03<\/li>\n\t<li>IBM Netezza for Cloud Pak for Data (on Cloud)\u00a0\u2013 versions prior to 11.2.3.3<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP10<\/li>\n\t<li>IBM Spectrum Protect Plus\u00a0\u2013 versions 10.1.0 to 10.1.16.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-012","alert_type":396,"serial_number":"AV25-012","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5967,"title":"Ubuntu security advisory (AV25-013)","uuid":"10cfb6cf-d243-4006-9ab2-99906f11ff54","banner":null,"lang":"en","date_modified":"2025-01-13","date_modified_ts":"2025-01-13T15:46:49Z","date_created":"2025-01-13T15:26:54Z","summary":null,"body":["<article data-history-node-id=\"5967\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-013\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-013<br \/><strong>Date: <\/strong>January\u00a013, 2025<\/p>\n\n<p>Between January\u00a06 and 12, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-013","alert_type":396,"serial_number":"AV25-013","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5968,"title":"Dell security advisory (AV25-014)","uuid":"a2e7344c-3f79-4a65-9930-1555afdc850f","banner":null,"lang":"en","date_modified":"2025-01-13","date_modified_ts":"2025-01-13T16:08:36Z","date_created":"2025-01-13T15:26:54Z","summary":null,"body":["<article data-history-node-id=\"5968\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-014\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-014<br \/><strong>Date: <\/strong>January\u00a013, 2025<\/p>\n\n<p>Between January\u00a06 and 12, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Dell Networking SmartFabric Storage Sofware\u00a0\u2013 versions prior to 1.4.3<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 versions 8.0.000 to 8.0.311<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000269958\/dsa-2025-025-security-update-for-dell-vxrail-for-multiple-vulnerabilities\">Dell Security Advisory DSA-2025-025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000270413\/dsa-2025-032-security-update-for-dell-networking-smartfabric-storage-software-vulnerabilities\">Dell Security Advisory DSA-2025-032<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-014","alert_type":396,"serial_number":"AV25-014","subject":"dell","moderation_state":"published","external_url":null},{"nid":5969,"title":"[Control systems] CISA ICS security advisories (AV25\u2013015)","uuid":"7d127a37-2166-4c78-906f-7d729d60140c","banner":null,"lang":"en","date_modified":"2025-01-13","date_modified_ts":"2025-01-13T16:15:10Z","date_created":"2025-01-13T15:26:55Z","summary":null,"body":["<article data-history-node-id=\"5969\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-015\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-015<br \/><strong>Date: <\/strong>January\u00a013, 2025<\/p>\n\n<p>Between January\u00a06 and 12, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB ASPECT-Enterprise ASP-ENT-x\u00a0\u2013 versions 3.07.02 and prior<\/li>\n\t<li>ABB NEXUS Series\u00a0\u2013 multiple models and versions<\/li>\n\t<li>ABB MATRIX Series\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Delta Electronics DRASimuCAD\u00a0\u2013 version 1.02<\/li>\n\t<li>Nedap Librix Ecoreader\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Harmony HMI and Pro-face HMI products\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Schneider Electric PowerChute Serial Shutdown\u00a0\u2013 versions 1.2.0.301 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-015","alert_type":398,"serial_number":"AV25\u2013015","subject":"ics","moderation_state":"published","external_url":null},{"nid":5970,"title":"Red Hat security advisory (AV25-016)","uuid":"eb71b13a-fffd-434a-8ed7-64b1c63048e6","banner":null,"lang":"en","date_modified":"2025-01-13","date_modified_ts":"2025-01-13T18:49:41Z","date_created":"2025-01-13T18:00:28Z","summary":null,"body":["<article data-history-node-id=\"5970\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-016\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-016<br \/><strong>Date: <\/strong>January\u00a013, 2025<\/p>\n\n<p>Between January\u00a06 and 12, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-016","alert_type":396,"serial_number":"AV25-016","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5972,"title":"SAP security advisory \u2013 January 2025 monthly rollup (AV25-017)","uuid":"6d24fb51-7715-4800-beac-a098bdf8a5df","banner":null,"lang":"en","date_modified":"2025-01-14","date_modified_ts":"2025-01-14T15:29:20Z","date_created":"2025-01-14T15:11:09Z","summary":null,"body":["<article data-history-node-id=\"5972\" about=\"\/en\/alerts-advisories\/sap-security-advisory-january-2025-monthly-rollup-av25-017\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-017<br \/><strong>Date: <\/strong>January\u00a014, 2025<\/p>\n\n<p>On January\u00a014, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP BusinessObjects Business Intelligence Platform\u00a0\u2013 versions ENTERPRISE 420, 430 and 2025<\/li>\n\t<li>SAP NetWeaver Application Server ABAP and ABAP Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver AS for ABAP and ABAP Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Platform)\u00a0\u2013 multiple versions<\/li>\n\t<li>SAPSetup\u00a0\u2013 version LMSAPSETUP 9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/january-2025.html\">SAP Security Patch Day\u00a0\u2013 January 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-january-2025-monthly-rollup-av25-017","alert_type":396,"serial_number":"AV25-017","subject":"sap","moderation_state":"published","external_url":null},{"nid":5973,"title":"[Control systems] Siemens security advisory (AV25-018) ","uuid":"877a2f26-aee7-4db8-b279-0c606b505d2a","banner":null,"lang":"en","date_modified":"2025-01-14","date_modified_ts":"2025-01-14T16:50:09Z","date_created":"2025-01-14T15:59:18Z","summary":null,"body":["<article data-history-node-id=\"5973\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-018\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-018<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 14, 2025<\/p>\n\n<p>On January 14, 2025, Siemens published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Industrial Edge Management OS\u00a0\u2013 all versions<\/li>\n\t<li>Mendix LDAP\u00a0\u2013 versions prior to V1.1.2<\/li>\n\t<li>SIMATIC S7-1200 CPU family V4\u00a0\u2013 versions prior to V4.7<\/li>\n\t<li>SIPROTEC 5\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siveillance Video Device Pack\u00a0\u2013 versions prior to V13.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-018","alert_type":398,"serial_number":"AV25-018","subject":"siemens","moderation_state":"published","external_url":null},{"nid":5974,"title":"Zyxel security advisory (AV25-019)","uuid":"408f2a73-0f67-4cb0-8865-732c0b82be4c","banner":null,"lang":"en","date_modified":"2025-01-14","date_modified_ts":"2025-01-14T18:39:10Z","date_created":"2025-01-14T18:14:11Z","summary":null,"body":["<article data-history-node-id=\"5974\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av25-019\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-019<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 14, 2024<\/p>\n\n<p>On January 14, 2025, Zyxel published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Zyxel AP\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Zyxel Security Router USG LITE 60AX\u00a0\u2013 versions prior to 2.00(ACIP.4)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-improper-privilege-management-vulnerability-in-aps-and-security-router-devices-01-14-2025\">Zyxel security advisory for improper privilege management vulnerability in APs and security router devices (CVE-2024-12398)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av25-019","alert_type":396,"serial_number":"AV25-019","subject":"other","moderation_state":"published","external_url":null},{"nid":5975,"title":"Fortinet security advisory (AV25-020)","uuid":"5f2431e2-b96e-40d1-b473-065bb92faee7","banner":null,"lang":"en","date_modified":"2025-01-14","date_modified_ts":"2025-01-14T19:06:35Z","date_created":"2025-01-14T18:45:29Z","summary":null,"body":["<article data-history-node-id=\"5975\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-020\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-020<br \/><strong>Date: <\/strong>January\u00a014, 2025<\/p>\n\n<p>On January\u00a014, 2025, Fortinet published security advisories for multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>FortiAnalyzer Cloud 7.4\u00a0\u2013 versions 7.4.1 to 7.4.3<\/li>\n\t<li>FortiAnalyzer\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiManager\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiManager Cloud\u00a0\u2013 versions 7.4.1 to 7.4.3<\/li>\n\t<li>FortiOS\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiProxy\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiSandbox\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiSwitch\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Fortinet has reported that vulnerability CVE-2024-55591 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-535\">Fortinet PSIRT Advisory\u00a0- FG-IR-24-535<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-260\">Fortinet PSIRT Advisory\u00a0- FG-IR-23-260<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-020","alert_type":396,"serial_number":"AV25-020","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":5976,"title":"Microsoft security advisory \u2013 January 2025 monthly rollup (AV25\u2013021)","uuid":"10e14b51-d06f-49fc-b091-52209c7c2952","banner":null,"lang":"en","date_modified":"2025-01-14","date_modified_ts":"2025-01-14T21:06:18Z","date_created":"2025-01-14T20:50:33Z","summary":null,"body":["<article data-history-node-id=\"5976\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2025-monthly-rollup-av25-021\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-021<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 14, 2024<\/p>\n\n<p>On January 14, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul><li>.NET\u00a0\u2013 version 8.0<\/li>\n\t<li>.NET\u00a0\u2013 version 9.0<\/li>\n\t<li>Marketplace SaaS<\/li>\n\t<li>Microsoft 365 Apps for Enterprise\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Access 2016<\/li>\n\t<li>Microsoft Defender for Endpoint<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft\/Muzic<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Project 2016\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Purview<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft Update Catalog<\/li>\n\t<li>Microsoft Visual Studio\u00a0\u2013 multiple versions<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>System Center 2019, 2022 and 2025<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2025-21333, CVE-2025-21334 and CVE-2025-21335 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Jan\">January 2025 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-january-2025-monthly-rollup-av25-021","alert_type":396,"serial_number":"AV25-021","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":5977,"title":"Adobe security advisory (AV25\u2013023)","uuid":"19b0a7d6-6e39-41ce-a5e8-c900cadf15da","banner":null,"lang":"en","date_modified":"2025-01-15","date_modified_ts":"2025-01-15T17:21:56Z","date_created":"2025-01-15T16:01:57Z","summary":null,"body":["<article data-history-node-id=\"5977\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-023\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-023<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 15, 2024<\/p>\n\n<p>On January 14, 2025, Adobe published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Adobe Animate\u202f2023\u00a0\u2013 versions 23.0.9 and prior<\/li>\n\t<li>Adobe Animate\u202f2024\u00a0\u2013 versions 24.0.6 and prior<\/li>\n\t<li>Adobe Illustrator on iPad\u00a0\u2013 versions 3.0.7 and prior<\/li>\n\t<li>Adobe Photoshop 2024\u00a0\u2013 versions 25.12 and prior<\/li>\n\t<li>Adobe Photoshop 2025\u00a0\u2013 versions 26.1 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 versions 14.0 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 versions 3.0.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-023","alert_type":396,"serial_number":"AV25-023","subject":"adobe","moderation_state":"published","external_url":null},{"nid":5978,"title":"Ivanti security advisory (AV25-022)","uuid":"af68e3f8-1d86-43c1-a209-8a03c23d1cc2","banner":null,"lang":"en","date_modified":"2025-01-15","date_modified_ts":"2025-01-15T17:18:00Z","date_created":"2025-01-15T17:04:30Z","summary":null,"body":["<article data-history-node-id=\"5978\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-022\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-022<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 15, 2024<\/p>\n\n<p>Between January 9 and 14, 2025, Ivanti published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Ivanti Avalanche\u00a0\u2013 versions prior to 6.4.7<\/li>\n\t<li>Ivanti Application Control\u00a0\u2013 versions prior to 2024.3 HF1, 2024.1 HF4 and 2023.3 HF3<\/li>\n\t<li>Ivanti Endpoint Manager\u00a0\u2013 versions prior to EPM 2024 January-2025 Security Update, EPM 2022 SU6 January-2025 Security Update<\/li>\n\t<li>Ivanti Security Controls\u00a0\u2013 versions prior to 2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Application-Control-Engine-CVE-2024-10630?language=en_US\">Ivanti\u00a0\u2013 Security Advisory\u00a0- Ivanti Application Control Engine (CVE-2024-10630)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Avalanche-6-4-7-Multiple-CVEs?language=en_US\">Ivanti\u00a0\u2013 Security Advisory Ivanti Avalanche 6.4.7 (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US\">Ivanti\u00a0\u2013 Security Advisory EPM January 2025 for EPM 2024 and EPM 2022 SU6<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=%5BSecurity%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-022","alert_type":396,"serial_number":"AV25-022","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":5979,"title":"[Control systems] Schneider Electric security advisory (AV25-024)","uuid":"696c3be0-07c6-4447-9121-9a5599386d19","banner":null,"lang":"en","date_modified":"2025-01-15","date_modified_ts":"2025-01-15T18:33:22Z","date_created":"2025-01-15T18:21:39Z","summary":null,"body":["<article data-history-node-id=\"5979\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-024\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-024<br \/><strong>Date: <\/strong>January\u00a015, 2025<\/p>\n\n<p>On January\u00a014, 2025, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BMENOR2200H\u00a0\u2013 all versions<\/li>\n\t<li>BMXNOE0100\u00a0\u2013 all versions<\/li>\n\t<li>BMXNOE0110\u00a0\u2013 all versions<\/li>\n\t<li>BMXNOR0200H\u00a0\u2013 versions prior to SV1.70IR2<\/li>\n\t<li>EVLink Pro AC\u00a0\u2013 versions prior to v1.3.10<\/li>\n\t<li>EcoStruxure\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Modicon M340 processors\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Modicon M580 communication modules BMENOC\u00a0\u2013 BMENOC0321 versions prior to SV1.10<\/li>\n\t<li>Modicon M580 communication modules BMECRA\u00a0\u2013 BMECRA31210 all versions<\/li>\n\t<li>Modicon M580\/Quantum communication modules BMXCRA\u00a0\u2013 BMXCRA31200 All versions, BMXCRA31210 All versions<\/li>\n\t<li>Modicon Quantum communication modules 140CRA\u00a0\u2013 140CRA31200 all versions, 140CRA31908 All versions<\/li>\n\t<li>Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety)\u00a0\u2013 versions prior to SV4.30<\/li>\n\t<li>Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)\u00a0\u2013 versions prior to SV4.21<\/li>\n\t<li>PowerLogic HDPM6000\u00a0\u2013 version v0.62.7 and prior<\/li>\n\t<li>Pro-face GP-Pro EX\u00a0\u2013 all versions<\/li>\n\t<li>Pro-face Remote HMI\u00a0\u2013 all versions<\/li>\n\t<li>RemoteConnect and SCADAPackTM x70 Utilities\u00a0\u2013 all versions<\/li>\n\t<li>Revenera FlexNet Publisher\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Vijeo Designer\u00a0\u2013 versions prior to V6.3SP1 HF1<\/li>\n\t<li>Web Designer\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Zelio Soft 2\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-024","alert_type":398,"serial_number":"AV25-024","subject":"se","moderation_state":"published","external_url":null},{"nid":5980,"title":"[Control systems] B&R security advisory (AV25-025)","uuid":"4e85a904-53ce-433b-a659-7cf3f0e3c27d","banner":null,"lang":"en","date_modified":"2025-01-15","date_modified_ts":"2025-01-15T19:57:48Z","date_created":"2025-01-15T19:51:09Z","summary":null,"body":["<article data-history-node-id=\"5980\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av25-025\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-025<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 15, 2025<\/p>\n\n<p>On January 15, 2025, B and R published an ICS advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>B and R Automation Runtime \u2013 versions prior to 6.<\/li>\n\t<li>B and R mapp View \u2013 versions prior to 6.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P001-c478fad6.pdf\">B and R cyber security advisory - Automation Runtime and mapp View Use of insecure algorithm for self-signed certificates (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B and R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-French-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av25-025","alert_type":398,"serial_number":"AV25-025","subject":"other","moderation_state":"published","external_url":null},{"nid":5981,"title":"Dell security advisory (AV25-026)","uuid":"7453f5b6-09ce-4511-86e3-227331e06544","banner":null,"lang":"en","date_modified":"2025-01-20","date_modified_ts":"2025-01-20T16:12:06Z","date_created":"2025-01-20T16:00:29Z","summary":null,"body":["<article data-history-node-id=\"5981\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-026\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-026<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 20, 2025<\/p>\n\n<p>Between January 13 and 19, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included was an update for the following product:<\/p>\n\n<ul><li>Dell Open Manage Network Integration\u00a0\u2013 versions prior to 3.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000272375\/dsa-2025-035-security-update-for-dell-openmanage-network-integration-omni-vulnerabilities\">Dell Security Advisory DSA-2025-035<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-026","alert_type":396,"serial_number":"AV25-026","subject":"dell","moderation_state":"published","external_url":null},{"nid":5982,"title":"IBM security advisory (AV25-027)","uuid":"0a646633-8d06-4447-80a3-3275b84d19c5","banner":null,"lang":"en","date_modified":"2025-01-20","date_modified_ts":"2025-01-20T16:41:45Z","date_created":"2025-01-20T16:23:43Z","summary":null,"body":["<article data-history-node-id=\"5982\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-027\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-027<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 20, 2025<\/p>\n\n<p>Between January 13 and 19, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Maximo Application Suite\u00a0\u2013 versions 8.10, 8.11 and 9.0<\/li>\n\t<li>IBM Maximo Application Suite IoT Component\u00a0\u2013 versions 8.7, 8.8 and 9.0<\/li>\n\t<li>IBM Watson CP4D Data Stores\u00a0\u2013 versions 4.0.0 to 5.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7181126\">IBM Security Bulletin (IBM Maximo Application Suite and IBM Maximo Application Suite\u00a0- Iot Component)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7180629\">IBM Security Bulletin (IBM Watson CP4D Data Stores)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-027","alert_type":396,"serial_number":"AV25-027","subject":"ibm","moderation_state":"published","external_url":null},{"nid":5983,"title":"Ubuntu security advisory (AV25-028)","uuid":"300fe9ce-b605-4340-a385-87060254d8ac","banner":null,"lang":"en","date_modified":"2025-01-20","date_modified_ts":"2025-01-20T17:18:45Z","date_created":"2025-01-20T16:46:37Z","summary":null,"body":["<article data-history-node-id=\"5983\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-028\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-028<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 20, 2025<\/p>\n\n<p>Between January 13 and 19, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7195-2\">USN-7195-2: Linux kernel (Azure) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7173-3\">USN-7173-3: Linux kernel (Raspberry Pi) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-028","alert_type":396,"serial_number":"AV25-028","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":5984,"title":"[Control systems] CISA ICS security advisories (AV25\u2013029) ","uuid":"b2ba4582-476d-4d86-9356-9f4d202143e2","banner":null,"lang":"en","date_modified":"2025-01-20","date_modified_ts":"2025-01-20T19:34:39Z","date_created":"2025-01-20T19:30:38Z","summary":null,"body":["<article data-history-node-id=\"5984\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-029\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n<p><strong>Serial number: <\/strong>AV25-029\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 20, 2025\n<\/p>\n<p>Between January 13 and 19, 2025, CISA published ICS advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Belledonne Communications Linphone-Desktop \u2013 version 5.2.6<\/li>\n  <li>Fuji Electric Alpha5 SMART \u2013 version 4.5 and prior<\/li>\n  <li>Hitachi Energy FOX61x \u2013 versions prior to R16B, version R15A and prior, version R15B, version R16A and R16B Revision E<\/li>\n  <li>Hitachi Energy FOXCST \u2013 versions prior to 16.2.1<\/li>\n  <li>Hitachi Energy FOXMAN-UN \u2013 multiple models and versions<\/li>\n  <li>Schneider Electric Data Center Expert \u2013 versions 8.1.1.3 and prior<\/li>\n  <li>Schneider Electric EcoStruxure \u2013 multiple models and versions<\/li>\n  <li>Schneider Electric Vijeo Designer \u2013 versions prior to V6.3 SP1<\/li>\n  <li>Siemens Industrial Edge Management OS (IEM-OS) \u2013 all versions<\/li>\n  <li>Siemens Mendix LDAP \u2013 versions prior to 1.1.2<\/li>\n  <li>Siemens SIPROTEC 5 \u2013 multiple models and versions<\/li>\n  <li>Siemens Siveillance Video Device Pack \u2013 versions prior to V13.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96 \">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-029","alert_type":398,"serial_number":"AV24-029","subject":"other","moderation_state":"published","external_url":null},{"nid":5985,"title":"HPE security advisory (AV25-030)","uuid":"e8b74b43-5a9e-494b-b961-4817258ce7bb","banner":null,"lang":"en","date_modified":"2025-01-21","date_modified_ts":"2025-01-21T14:26:57Z","date_created":"2025-01-21T14:22:44Z","summary":null,"body":["<article data-history-node-id=\"5985\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-030\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-030<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 21, 2025<\/p>\n\n<p>On January 17, 2025, HPE published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX Apache-based Web Server \u2013 versions prior to B.2.4.62.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04773en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbux04773<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-030","alert_type":396,"serial_number":"AV25-030","subject":"hpe","moderation_state":"published","external_url":null},{"nid":5986,"title":"Oracle security advisory \u2013 January 2025 quarterly rollup (AV25-031)","uuid":"01168625-09d5-4e75-b0e1-6a273c6cd830","banner":null,"lang":"en","date_modified":"2025-01-22","date_modified_ts":"2025-01-22T14:31:08Z","date_created":"2025-01-22T14:27:29Z","summary":null,"body":["<article data-history-node-id=\"5986\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-january-2025-quarterly-rollup-av25-031\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-031<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 22, 2025<\/p>\n\n<p>On January 21, 2025, Oracle published a security advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Database Server<\/li>\n\t<li>Oracle E-Business Suite<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle GoldenGate<\/li>\n\t<li>Oracle Hospitality Applications<\/li>\n\t<li>Oracle JD Edwards<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle PeopleSoft<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Secure Backup<\/li>\n\t<li>Oracle Supply Chain Products<\/li>\n\t<li>Oracle Utilities Applications<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2025.html\">Oracle Critical Patch Update Advisory \u2013 January 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-january-2025-quarterly-rollup-av25-031","alert_type":396,"serial_number":"AV25-031","subject":"oracle","moderation_state":"published","external_url":null},{"nid":5987,"title":"[Control systems] ABB security advisory (AV25-032) ","uuid":"9deb1c13-3e98-4c02-a769-b1a16b82a49c","banner":null,"lang":"en","date_modified":"2025-01-22","date_modified_ts":"2025-01-22T15:48:39Z","date_created":"2025-01-22T15:45:19Z","summary":null,"body":["<article data-history-node-id=\"5987\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-032\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-032<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 22, 2025<\/p>\n\n<p>On January 21, 2025, ABB published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Drive Composer entry \u2013 versions 2.9.0.1 and prior<\/li>\n\t<li>ABB Drive Composer pro \u2013 versions 2.9.0.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108470A5466&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch \">ABB Cyber Security Advisory - 9AKK108470A5466<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-032","alert_type":398,"serial_number":"AV25-032","subject":"abb","moderation_state":"published","external_url":null},{"nid":5988,"title":"Cisco security advisory (AV25-033)","uuid":"d22218e2-edeb-49dd-9230-b77804c3e551","banner":null,"lang":"en","date_modified":"2025-01-22","date_modified_ts":"2025-01-22T19:09:01Z","date_created":"2025-01-22T19:00:21Z","summary":null,"body":["<article data-history-node-id=\"5988\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-033\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-033<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 22, 2025<\/p>\n\n<p>On January 22, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco BroadWorks \u2013 versions prior to RI.2024.11<\/li>\n\t<li>Cisco Meeting Management \u2013 versions prior to 3.9.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cmm-privesc-uy2Vf8pc\">Cisco Security Advisory \u2013 cisco-sa-cmm-privesc-uy2Vf8pc <\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-bw-sip-dos-mSySbrmt\">Cisco Security Advisory \u2013 cisco-sa- bw-sip-dos-mSySbrmt<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-033","alert_type":396,"serial_number":"AV25-033","subject":"cisco","moderation_state":"published","external_url":null},{"nid":5989,"title":"Jenkins security advisory (AV25-034)","uuid":"831e0d01-e4c1-406a-9577-0439cf299f0c","banner":null,"lang":"en","date_modified":"2025-01-23","date_modified_ts":"2025-01-23T14:04:02Z","date_created":"2025-01-23T13:47:28Z","summary":null,"body":["<article data-history-node-id=\"5989\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-034\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-034<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 23, 2025<\/p>\n\n<p>On January 22, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Azure Service Fabric Plugin\u00a0\u2013 version 1.6 and prior<\/li>\n\t<li>Bitbucket Server Integration Plugin\u00a0\u2013 version 4.1.3 and prior<\/li>\n\t<li>Eiffel Broadcaster Plugin\u00a0\u2013 version 2.10.2 and prior<\/li>\n\t<li>Folder-based Authorization Strategy Plugin\u00a0\u2013 version 17.vd5b_18537403e and prior<\/li>\n\t<li>GitLab Plugin\u00a0\u2013 version 1.9.6 and prior<\/li>\n\t<li>OpenId Connect Authentication Plugin\u00a0\u2013 version 4.452.v2849b_d3945fa_ and prior<\/li>\n\t<li>Zoom Plugin\u00a0\u2013 up to and including 1.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-01-22\/\">Jenkins Security Advisory 2025-01-22<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-034","alert_type":396,"serial_number":"AV25-034","subject":"other","moderation_state":"published","external_url":null},{"nid":5990,"title":"SonicWall security advisory (AV25-035)","uuid":"152f5539-2388-46cc-b1fc-fb865ef3539d","banner":null,"lang":"en","date_modified":"2025-01-23","date_modified_ts":"2025-01-23T14:43:14Z","date_created":"2025-01-23T14:29:16Z","summary":null,"body":["<article data-history-node-id=\"5990\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-035\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-035<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 23, 2025<\/p>\n\n<p>On January 22, 2025, SonicWall published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>SMA1000 Appliance Management Console (AMC)\u00a0\u2013 version 12.4.3-02804 (platform-hotfix) and prior<\/li>\n\t<li>Central Management Console (CMC)\u00a0\u2013 version 12.4.3-02804 (platform-hotfix) and prior<\/li>\n<\/ul><p>SonicWall has reported that vulnerability CVE-2025-23006 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sonicwall.com\/support\/knowledge-base\/product-notice-urgent-security-notification-sma-1000\/250120090802840\">Product Notice: Urgent Security Notification\u00a0\u2013 SMA 1000<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0002\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2025-0002<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/01\/24\/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Adds One Known Exploited Vulnerability to Catalog\u00a0|\u00a0CISA<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-035","alert_type":396,"serial_number":"AV25-035","subject":"other","moderation_state":"published","external_url":null},{"nid":5991,"title":"Atlassian security advisory (AV25-036)","uuid":"5445947c-4cd1-41f2-9008-0f789671deec","banner":null,"lang":"en","date_modified":"2025-01-23","date_modified_ts":"2025-01-23T16:39:37Z","date_created":"2025-01-23T16:24:07Z","summary":null,"body":["<article data-history-node-id=\"5991\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-036\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-036<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 13, 2025<\/p>\n\n<p>On January 21, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-january-21-2025-1489803942.html\">Atlassian Security Bulletin\u00a0- January 21 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-036","alert_type":396,"serial_number":"AV25-036","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":5992,"title":"GitLab security advisory (AV25-037)","uuid":"c53ecea4-614c-45f2-bb55-c72acf275e5a","banner":null,"lang":"en","date_modified":"2025-01-23","date_modified_ts":"2025-01-23T17:06:32Z","date_created":"2025-01-23T16:42:19Z","summary":null,"body":["<article data-history-node-id=\"5992\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-037\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-037<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 23, 2025<\/p>\n\n<p>On January 22, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.8.1, 17.7.3 and 17.6.4<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.8.1, 17.7.3 and 17.6.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/01\/22\/patch-release-gitlab-17-8-1-released\/\">GitLab Patch Release: 17.8.1, 17.7.3, 17.6.4<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-037","alert_type":396,"serial_number":"AV25-037","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":5993,"title":"Mitel security advisory (AV25-038)","uuid":"39050a59-7939-4d0f-97a1-5ea76857ce4e","banner":null,"lang":"en","date_modified":"2025-01-23","date_modified_ts":"2025-01-23T19:50:35Z","date_created":"2025-01-23T18:05:56Z","summary":null,"body":["<article data-history-node-id=\"5993\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av25-038\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-038<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 23, 2025<\/p>\n\n<p>On January 22, 2025, Mitel published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>MiContact Center Business\u00a0\u2013 multiple versions<\/li>\n\t<li>OpenScape 4000\u00a0\u2013 multiple versions<\/li>\n\t<li>OpenScape 4000 Manager\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-misa-2025-0001\">Mitel Security Advisory\u00a0- 2025-0001<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\/mitel-product-security-advisory-misa-2025-0002\">Mitel Security Advisory\u00a0- 2025-0002<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/en-gb\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av25-038","alert_type":396,"serial_number":"AV25-038","subject":"mitel","moderation_state":"published","external_url":null},{"nid":5994,"title":"Juniper Networks security advisory (AV25-039)","uuid":"eca3387b-92d7-45a3-93fe-c7f385ac1e1e","banner":null,"lang":"en","date_modified":"2025-01-24","date_modified_ts":"2025-01-24T19:20:17Z","date_created":"2025-01-24T19:17:17Z","summary":null,"body":["<article data-history-node-id=\"5994\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-039\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-039<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 24, 2025<\/p>\n\n<p>On January 24, 2025, Juniper Networks published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Juniper Secure Analytics \u2013 versions prior to 7.5.0 UP10 IF02<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP10-IF02?language=en_US\">Juniper Networks Security Advisories \u2013 JSA93839<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=relevancy\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-039","alert_type":396,"serial_number":"AV25-039","subject":"juniper","moderation_state":"published","external_url":null},{"nid":5997,"title":"Red Hat security advisory (AV25-041)","uuid":"986ae135-4cf6-4f01-84a5-3cc0b61aaff3","banner":null,"lang":"en","date_modified":"2025-01-27","date_modified_ts":"2025-01-27T14:42:49Z","date_created":"2025-01-27T13:40:44Z","summary":null,"body":["<article data-history-node-id=\"5997\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-041\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-041<br \/><strong>Date: <\/strong>January\u00a027, 2025<\/p>\n\n<p>Between January\u00a020 and 26, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-041","alert_type":396,"serial_number":"AV25-041","subject":"redhat","moderation_state":"published","external_url":null},{"nid":5995,"title":"Ubuntu security advisory (AV25-040)","uuid":"2f1b6e15-96f3-45c0-8fe1-f3b00c5d460c","banner":null,"lang":"en","date_modified":"2025-01-27","date_modified_ts":"2025-01-27T14:32:53Z","date_created":"2025-01-27T14:20:35Z","summary":null,"body":["<article data-history-node-id=\"5995\" about=\"\/en\/alerts-advisories\/security-advisory-ubuntu-av25-040\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV25-040<br \/><strong>Date:<\/strong> January 27, 2025<\/p>\n\n<p>Between January 20 and 26, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04\u00a0LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-advisory-ubuntu-av25-040","alert_type":396,"serial_number":"AV25-040","subject":"other","moderation_state":"published","external_url":null},{"nid":5996,"title":"IBM security advisory (AV25-042)","uuid":"815879dd-65c2-4279-861a-35da35fbda20","banner":null,"lang":"en","date_modified":"2025-01-27","date_modified_ts":"2025-01-27T14:46:27Z","date_created":"2025-01-27T14:41:55Z","summary":null,"body":["<article data-history-node-id=\"5996\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-042\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV25-042<br \/><strong>Date:<\/strong> January 27, 2025<\/p>\n\n<p>Between January 20 and 26, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>IBM App Connect Enterprise \u2013 versions 12.0.1.0 to 12.0.12.9 and versions 13.0.1.0 to 13.0.2.0<\/li>\n\t<li>IBM Observability with Instana (OnPrem) \u2013 versions 281 to 287<\/li>\n\t<li>IBM Engineering Lifecycle Optimization - PUB \u2013 versions 7.0.2 and 7.0.3<\/li>\n\t<li>IBM Storage Copy Data Management \u2013 versions 2.2.0.0 to 2.2.24.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7181570\">IBM Security Bulletin (IBM App Connect Enterprise)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7181251\">IBM Security Bulletin (IBM Observability with Instana (OnPrem))<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7181469\">IBM Security Bulletin (IBM Engineering Lifecycle Optimization - PUB)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7177315\">IBM Security Bulletin (IBM Storage Copy Data Management)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-042","alert_type":396,"serial_number":"AV25-042","subject":"other","moderation_state":"published","external_url":null},{"nid":5999,"title":"[Control systems] CISA ICS security advisories (AV25\u2013043)","uuid":"fe987c69-144a-40af-9c18-30534129c2d5","banner":null,"lang":"en","date_modified":"2025-01-27","date_modified_ts":"2025-01-27T15:04:23Z","date_created":"2025-01-27T15:03:54Z","summary":null,"body":["<article data-history-node-id=\"5999\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-043\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-043<br \/><strong>Date: <\/strong>January\u00a027, 2025<\/p>\n\n<p>Between January\u00a020 and 26, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hiitachi Energy RTU500 Series CMU Firmware\u00a0\u2013 multiple versions<\/li>\n\t<li>HMS Networks Ewon Flexy 202\u00a0\u2013 all versions<\/li>\n\t<li>mySCADA myPRO Manager\u00a0\u2013 versions prior to 1.3<\/li>\n\t<li>mySCADA myPRO Runtime\u00a0\u2013 versions prior to 9.2.1<\/li>\n\t<li>Schneider Electric Easergy Studio\u00a0\u2013 versions 9.3.1 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure Power Build Rapsody\u00a0\u2013 multiple versions<\/li>\n\t<li>Schneider Electric EVlink Home Smart\u00a0\u2013 versions prior to 2.0.6.0.0<\/li>\n\t<li>Schneider Electric Charge\u00a0\u2013 versions prior to 1.13.4<\/li>\n\t<li>Siemens SIMATIC S7-1200 CPUs\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SIPLUS S7-1200 CPUs\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Traffic Alert and Collision Avoidance System (TCAS) II\u00a0\u2013 versions 7.1 and prior<\/li>\n\t<li>ZF Roll Stability Support Plus (RSSPlus) 2M\u00a0\u2013 build dates 01\/08 to 01\/23<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-043","alert_type":398,"serial_number":"AV25-043","subject":"ics","moderation_state":"published","external_url":null},{"nid":5998,"title":"GitHub security advisory (AV25-044)","uuid":"6e32080d-53aa-43ec-8318-1a20b49cdead","banner":null,"lang":"en","date_modified":"2025-01-27","date_modified_ts":"2025-01-27T15:08:13Z","date_created":"2025-01-27T15:04:46Z","summary":null,"body":["<article data-history-node-id=\"5998\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-044\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-044<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 27, 2025<\/p>\n\n<p>On January 21, 2025, GitHub published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server \u2013 versions 3.15.x prior to 3.15.2<\/li>\n\t<li>GitHub Enterprise Server \u2013 versions 3.14.x prior to 3.14.7<\/li>\n\t<li>GitHub Enterprise Server \u2013 versions 3.13.x prior to 3.13.10<\/li>\n\t<li>GitHub Enterprise Server \u2013 versions 3.12.x prior to 3.12.14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes\">GitHub Release Notes #3.15.2<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">GitHub Release Notes #3.14.7<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.13\/admin\/release-notes\">GitHub Release Notes #3.13.10<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.12\/admin\/release-notes\">GitHub Release Notes #3.12.14<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-044","alert_type":396,"serial_number":"AV25-044","subject":"other","moderation_state":"published","external_url":null},{"nid":6000,"title":"Apple security advisory (AV25-045)","uuid":"77410fc2-ef6a-4b3d-b9d9-8927bd00d8c7","banner":null,"lang":"en","date_modified":"2025-01-27","date_modified_ts":"2025-01-27T20:03:31Z","date_created":"2025-01-27T19:55:26Z","summary":null,"body":["<article data-history-node-id=\"6000\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-045\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-045<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 27, 2025<\/p>\n\n<p>On January 27, 2025, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.3<\/li>\n\t<li>iOS iPadOS\u00a0\u2013 versions prior to 17.7.4<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.3<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.7.3<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.7.3<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 18.3<\/li>\n<\/ul><p>Apple has been advised that CVE-2025-24085 vulnerability may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-045","alert_type":396,"serial_number":"AV25-045","subject":"apple","moderation_state":"published","external_url":null},{"nid":6002,"title":"VMware security advisory (AV25-046)","uuid":"c0dbd986-66f2-4e93-8d16-00f7ee8a1510","banner":null,"lang":"en","date_modified":"2025-01-29","date_modified_ts":"2025-01-29T14:31:33Z","date_created":"2025-01-29T14:22:11Z","summary":null,"body":["<article data-history-node-id=\"6002\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-046\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-046<br \/><strong>Date: <\/strong>January\u00a029, 2025<\/p>\n\n<p>On January\u00a028, 2025, VMware released a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMWare Avi Load Balancer\u00a0\u2013 versions 30.1.1, 30.1.2, 30.2.1 and 30.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25346\">VMware VMSA-2025-002<\/a><\/li>\n\t<li><a href=\"https:\/\/www.broadcom.com\/support\/vmware-security-advisories\">VMware Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-046","alert_type":396,"serial_number":"AV25-046","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6003,"title":"TeamViewer security advisory (AV25-047)","uuid":"c3fe48b5-7e2f-4ec0-8976-8a1d765b1e75","banner":null,"lang":"en","date_modified":"2025-01-29","date_modified_ts":"2025-01-29T14:40:13Z","date_created":"2025-01-29T14:22:12Z","summary":null,"body":["<article data-history-node-id=\"6003\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-047\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-047<br \/><strong>Date: <\/strong>January\u00a029, 2025<\/p>\n\n<p>On January\u00a028, 2025, TeamViewer released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>TeamViewer Full Client (Windows)\u00a0\u2013 multiple versions<\/li>\n\t<li>TeamViewer Host (Windows)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/en\/resources\/trust-center\/security-bulletins\/tv-2025-1001\/?\">Improper Neutralization of Argument Delimiters in TeamViewer Clients\u00a0- TV-2025-1001<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">TeamViewer Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-047","alert_type":396,"serial_number":"AV25-047","subject":"other","moderation_state":"published","external_url":null},{"nid":6004,"title":"ISC BIND security advisory (AV25-048)","uuid":"4c09c8b3-f611-491e-ae89-22949558a07a","banner":null,"lang":"en","date_modified":"2025-01-29","date_modified_ts":"2025-01-29T19:34:31Z","date_created":"2025-01-29T19:11:02Z","summary":null,"body":["<article data-history-node-id=\"6004\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av25-048\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-048<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 29, 2025<\/p>\n\n<p>On January 29, 2025, ISC published a security advisory to address vulnerabilities in the following product::<\/p>\n\n<ul><li>ISC BIND 9\u00a0- versions 9.11.0 to 9.11.37, 9.16.0 to 9.16.50, 9.18.0 to 9.18.32, 9.20.0 to 9.20.4 and 9.21.0 to 9.21.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/v1\/docs\/cve-2024-12705\">ISC BIND security advisory\u00a0- CVE-2024-12705<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/v1\/docs\/cve-2024-11187\">ISC BIND security advisory\u00a0- CVE-2024-11187<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av25-048","alert_type":396,"serial_number":"AV25-048","subject":"other","moderation_state":"published","external_url":null},{"nid":6005,"title":"[Control systems] ABB security advisory (AV25-049) ","uuid":"c6e4f0cc-41f0-43ad-9493-c28b4ffd78ec","banner":null,"lang":"en","date_modified":"2025-01-30","date_modified_ts":"2025-01-30T15:23:12Z","date_created":"2025-01-30T15:17:04Z","summary":null,"body":["<article data-history-node-id=\"6005\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-049\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-049<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 30, 2025<\/p>\n\n<p>On January 29, 2025, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB FLXeon Controllers\u00a0\u2013 version 9.3.4 and prior, multiple models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108470A5684&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">ABB Cyber Security Advisory\u00a0- 9AKK108470A5684 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-049","alert_type":398,"serial_number":"AV25-049","subject":"abb","moderation_state":"published","external_url":null},{"nid":6006,"title":"VMware security advisory (AV25-050)","uuid":"d3d11554-33c8-4e51-a67c-d6204e1134d0","banner":null,"lang":"en","date_modified":"2025-01-30","date_modified_ts":"2025-01-30T18:19:33Z","date_created":"2025-01-30T18:08:43Z","summary":null,"body":["<article data-history-node-id=\"6006\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-050\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-050<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>January 30, 2025<\/p>\n\n<p>On January 30, 2025, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Aria Operations for logs\u00a0\u2013 versions 8.x prior to 8.18.3<\/li>\n\t<li>VMware Aria Operations\u00a0\u2013 versions 8.x prior to 8.18.3<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 versions 4.x and 5.x (KB 92148)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/knowledge.broadcom.com\/external\/article?legacyId=92148\">VMware KB92148<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25329\">VMware VMSA-2025-0003<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-050","alert_type":396,"serial_number":"AV25-050","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6009,"title":"Dell security advisory (AV25-051)","uuid":"68cbe945-db3a-40e4-bb1c-97b10d5ad846","banner":null,"lang":"en","date_modified":"2025-02-03","date_modified_ts":"2025-02-03T17:58:01Z","date_created":"2025-02-03T16:47:20Z","summary":null,"body":["<article data-history-node-id=\"6009\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-051\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-051<br \/><strong>Date: <\/strong>February\u00a03, 2025<\/p>\n\n<p>Between January\u00a027 and February\u00a02, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Data Protection Central\u00a0\u2013 versions prior to 19.10<\/li>\n\t<li>Dell Enterprise SONiC Distribution\u00a0\u2013 versions prior to 4.4.1 and 4.2.3<\/li>\n\t<li>Dell NetWorker Virtual Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerProtect DD\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerStore X OS\u00a0\u2013 versions prior to 3.2.1.5-2424458<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 versions 7.0.000 to 7.0.533<\/li>\n\t<li>PowerProtect DP Series Appliances\u00a0\u2013 versions prior to 2.7.8<\/li>\n\t<li>PowerProtect Data Protection Software\u00a0\u2013 versions prior to 2.7.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-051","alert_type":396,"serial_number":"AV25-051","subject":"dell","moderation_state":"published","external_url":null},{"nid":6010,"title":"IBM security advisory (AV25-052)","uuid":"b89cf498-d914-4c3c-a863-3cd8041f2596","banner":null,"lang":"en","date_modified":"2025-02-03","date_modified_ts":"2025-02-03T17:59:07Z","date_created":"2025-02-03T16:47:20Z","summary":null,"body":["<article data-history-node-id=\"6010\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-052\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-052<br \/><strong>Date: <\/strong>February\u00a03, 2025<\/p>\n\n<p>Between January\u00a027 and February\u00a02, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM CP4MCM\u00a0\u2013 version 2.3 to 2.3 FP9<\/li>\n\t<li>IBM Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Planning Analytics Local\u00a0- IBM Planning Analytics Workspace\u00a0\u2013 versions 2.1 and 2.0<\/li>\n\t<li>IBM Tivoli Network Manager IP Edition\u00a0\u2013 version 4.2 GA to 4.2.0.20<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0\u2013 version 4.0.0 to 4.8.7<\/li>\n\t<li>IBM\u00ae Db2\u00ae on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>ICP\u00a0- Discovery\u00a0\u2013 versions 4.0.0 to 4.8.7 and 5.0.0 to 5.0.3<\/li>\n\t<li>InfoSphere Information Server\u00a0\u2013 version 11.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-052","alert_type":396,"serial_number":"AV25-052","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6011,"title":"Ubuntu security advisory (AV25-053)","uuid":"e2add21c-0b23-48d3-a2ad-58c9596009d7","banner":null,"lang":"en","date_modified":"2025-02-03","date_modified_ts":"2025-02-03T18:00:47Z","date_created":"2025-02-03T16:47:21Z","summary":null,"body":["<article data-history-node-id=\"6011\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-053\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-053<br \/><strong>Date: <\/strong>February\u00a03, 2025<\/p>\n\n<p>Between January\u00a027 and February\u00a02, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-053","alert_type":396,"serial_number":"AV25-053","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6012,"title":"[Control systems] CISA ICS security advisories (AV25\u2013054) ","uuid":"93574af2-949d-427f-8611-ce6f0498f0a1","banner":null,"lang":"en","date_modified":"2025-02-03","date_modified_ts":"2025-02-03T19:47:27Z","date_created":"2025-02-03T19:20:59Z","summary":null,"body":["<article data-history-node-id=\"6012\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-054\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-054<br \/><strong>Date: <\/strong>February 3, 2025<\/p>\n\n<p>Between January 27 and February 2, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>B&amp;R Automation Runtime\u00a0\u2013 versions prior to 6.1<\/li>\n\t<li>B&amp;R mapp View\u00a0\u2013 versions prior to 6.1<\/li>\n\t<li>Contec Health CMS8000 Patient Monitor\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy UNEM\u00a0\u2013 multiple versions<\/li>\n\t<li>New Rock Technologies MX8G VoIP Gateway\u00a0\u2013 all versions<\/li>\n\t<li>New Rock Technologies NRP1302\/P Desktop IP Phone\u00a0\u2013 all versions<\/li>\n\t<li>New Rock Technologies OM500 IP-PBX\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation DataEdgePlatform DataMosaix Private Cloud\u00a0\u2013 version 7.11 and prior, version 7.09 and prior<\/li>\n\t<li>Rockwell Automation FactoryTalk AssetCentre\u00a0\u2013 versions prior to V15.00.001<\/li>\n\t<li>Rockwell Automation FactoryTalk View SE\u00a0\u2013 all versions prior to 15.0<\/li>\n\t<li>Rockwell Automation FactoryTalk\u00a0\u2013 all versions prior to 15.0<\/li>\n\t<li>Rockwell Automation KEPServer\u00a0\u2013 versions 6.0 to 6.14.263<\/li>\n\t<li>Schneider Electric Power Logic\u00a0\u2013 version v0.62.7 and prior<\/li>\n\t<li>Schneider Electric RemoteConnect\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric SCADAPackTM x70 Utilities\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric System Monitor application in Harmony Industrial PC\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric System Monitor application in Pro-face Industrial PC\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-054","alert_type":398,"serial_number":"AV25-054","subject":"ics","moderation_state":"published","external_url":null},{"nid":6013,"title":"Android security advisory \u2013 February 2025 monthly rollup (AV25-055)","uuid":"4312743f-f2df-4924-a22f-2450bd6ee000","banner":null,"lang":"en","date_modified":"2025-02-04","date_modified_ts":"2025-02-04T13:35:08Z","date_created":"2025-02-04T13:32:29Z","summary":null,"body":["<article data-history-node-id=\"6013\" about=\"\/en\/alerts-advisories\/android-security-advisory-february-2025-monthly-rollup-av25-055\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n<p><strong>Serial number: <\/strong>AV25-055\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 4, 2025\n<\/p>\n<p>On February 3, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.\n<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.\n<\/p>\n<p>Google has reported that vulnerability CVE-2024-53104 has been exploited.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-02-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-february-2025-monthly-rollup-av25-055","alert_type":396,"serial_number":"AV25-055","subject":"android","moderation_state":"published","external_url":null},{"nid":6014,"title":"Qualcomm security advisory \u2013 February 2025 monthly rollup (AV25-056)","uuid":"e952b293-66b4-44c0-85ed-434cf6cb5d03","banner":null,"lang":"en","date_modified":"2025-02-04","date_modified_ts":"2025-02-04T15:24:11Z","date_created":"2025-02-04T13:59:09Z","summary":null,"body":["<article data-history-node-id=\"6014\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-february-2025-monthly-rollup-av25-056\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-056<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 4, 2025<\/p>\n\n<p>On February 3, 2025, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/february-2025-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 February<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-february-2025-monthly-rollup-av25-056","alert_type":396,"serial_number":"AV25-056","subject":"other","moderation_state":"published","external_url":null},{"nid":6016,"title":"Veeam security advisory (AV25-057)","uuid":"f4951e93-0712-45e2-93a7-0451d888d40c","banner":null,"lang":"en","date_modified":"2025-02-05","date_modified_ts":"2025-02-05T15:19:50Z","date_created":"2025-02-05T15:13:02Z","summary":null,"body":["<article data-history-node-id=\"6016\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av25-057\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-057<br \/><strong>Date: <\/strong>February\u00a05, 2025<\/p>\n\n<p>On February\u00a04, 2025, Veeam published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Veeam Backup for Salesforce\u00a0\u2013 Veeam Updater component versions prior to 7.9.0.1124<\/li>\n\t<li>Veeam Backup for Nutanix AHV\u00a0\u2013 Veeam Updater component versions prior to 9.0.0.1125<\/li>\n\t<li>Veeam Backup for AWS\u00a0\u2013 Veeam Updater component versions prior to 9.0.0.1126<\/li>\n\t<li>Veeam Backup for Microsoft Azure\u00a0\u2013 Veeam Updater component versions prior to 9.0.0.1128<\/li>\n\t<li>Veeam Backup for Google Cloud\u00a0\u2013 Veeam Updater component versions prior to 9.0.0.1128<\/li>\n\t<li>Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization\u00a0\u2013 Veeam Updater component versions prior to 9.0.0.1127<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4712\">Veeam Security Advisory\u00a0\u2013 kb4712<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av25-057","alert_type":396,"serial_number":"AV25-057","subject":"other","moderation_state":"published","external_url":null},{"nid":6018,"title":"HPE security advisory (AV25-058)","uuid":"909d13ed-73ce-419a-8b7a-11de035bb22c","banner":null,"lang":"en","date_modified":"2025-02-05","date_modified_ts":"2025-02-05T21:08:10Z","date_created":"2025-02-05T21:05:00Z","summary":null,"body":["<article data-history-node-id=\"6018\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-058\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-058<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 5, 2025<\/p>\n\n<p>On February 4, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking ClearPass Policy Manager \u2013 6.12.x versions prior to 6.12.3 and 6.11.x versions prior to 6.11.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04784en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbnw04784en_us <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-058","alert_type":396,"serial_number":"AV25-058","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6019,"title":"Cisco security advisory (AV25-059)","uuid":"791acebd-47fa-400c-a301-2eb1d22ef309","banner":null,"lang":"en","date_modified":"2025-02-05","date_modified_ts":"2025-02-05T21:14:44Z","date_created":"2025-02-05T21:10:18Z","summary":null,"body":["<article data-history-node-id=\"6019\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-059\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-059<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 5, 2025<\/p>\n\n<p>On February 5, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco IOS \u2013 versions 15.2E, 15.5SY and 15.9M<\/li>\n\t<li>Cisco IOS XE \u2013 versions 3.11E, 16.12, 17.9, 17.12 and 17.15<\/li>\n\t<li>Cisco IOS XR \u2013 versions 24.2 and prior, 24.3, 24.4 and 25.2<\/li>\n\t<li>Cisco Identity Services Engine (ISE) \u2013 versions 3.0, 3.1, 3.2 and 3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-snmp-dos-sdxnSUcW\">Cisco Security Advisory \u2013 cisco-sa-snmp-dos-sdxnSUcW <\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-multivuls-FTW9AOXF\">Cisco Security Advisory \u2013 cisco-sa-ise-multivuls-FTW9AOXF<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-059","alert_type":396,"serial_number":"AV25-059","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6021,"title":"F5 security advisory (AV25-060)","uuid":"13ee5114-2536-4db7-ac3d-bc4a4ea3ea48","banner":null,"lang":"en","date_modified":"2025-02-06","date_modified_ts":"2025-02-06T16:36:25Z","date_created":"2025-02-06T16:19:23Z","summary":null,"body":["<article data-history-node-id=\"6021\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av25-060\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-060<br \/><strong>Date: <\/strong>February\u00a06, 2025<\/p>\n\n<p>On February\u00a05, 2025, F5 published security updates for multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP (all modules)\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IP Next SPK\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IP (PEM)\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IP (ASM)\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IP (APM)\u00a0\u2013 versions 16.1.3 to 16.1.4<\/li>\n\t<li>BIG-IP (AFM)\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IP Next CNF\u00a0\u2013 versions 1.1.0 to 1.3.3<\/li>\n<\/ul><p>Open-source reporting has indicated that proof-of-concept exploit code is available for some of these vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000149540\">F5 Quarterly Security Notification (February 2025)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av25-060","alert_type":396,"serial_number":"AV25-060","subject":"f5","moderation_state":"published","external_url":null},{"nid":6023,"title":"Trimble security advisory (AV25-061)","uuid":"6fdf8a39-1951-4d5f-911d-fe72217b364a","banner":null,"lang":"en","date_modified":"2025-02-06","date_modified_ts":"2025-02-06T19:06:39Z","date_created":"2025-02-06T18:56:02Z","summary":null,"body":["<article data-history-node-id=\"6023\" about=\"\/en\/alerts-advisories\/trimble-security-advisory-av25-061\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-061<br \/><strong>Date: <\/strong>February 6, 2025<\/p>\n\n<p>On February 5, 2025, Trimble released a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Trimble Cityworks\u00a0\u2013 15.x versions prior to 15.8.9 and 23.x versions prior to 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<p>Trimble has indicated that CVE-2025-0994 has been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cityworks.my.site.com\/s\/login\/\">Trimble Cityworks Support Portal<\/a><\/li>\n\t<li><a href=\"https:\/\/learn.assetlifecycle.trimble.com\/i\/1532182-cityworks-customer-communication-2025-02-05-docx\/0?\">Trimble Advisory\u00a0- Communication related to Cityworks deployments<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-037-04\">CISA ICS Advisory\u00a0- Trimble Cityworks<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trimble-security-advisory-av25-061","alert_type":396,"serial_number":"AV25-061","subject":"other","moderation_state":"published","external_url":null},{"nid":6024,"title":"[Control systems] ABB security advisory (AV25-062)","uuid":"c81cd085-65c1-4239-b76c-b205cbc9accd","banner":null,"lang":"en","date_modified":"2025-02-06","date_modified_ts":"2025-02-06T20:15:08Z","date_created":"2025-02-06T19:19:06Z","summary":null,"body":["<article data-history-node-id=\"6024\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-062\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-062<br \/><strong>Date: <\/strong>February\u00a06, 2025<\/p>\n\n<p>On February\u00a06, 2025, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ASPECT Enterprise ASP-ENT-x\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>NEXUS Series NEX-2x and NEXUS-3-x\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>MATRIX Series MAT-x\u00a0\u2013 version 3.08.03 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108470A6775&amp;LanguageCode=en&amp;DocumentPartId=pdf%20-%20Public%20Advisory&amp;Action=Launch \">ELSB\/BLBA, Hard-coded credentials in ASPECT Energy Management System (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-062","alert_type":398,"serial_number":"AV25-062","subject":"abb","moderation_state":"published","external_url":null},{"nid":6025,"title":"Mozilla security advisory (AV25-063)","uuid":"3674cba9-01cd-4b8a-97bf-f69d6821c055","banner":null,"lang":"en","date_modified":"2025-02-07","date_modified_ts":"2025-02-07T19:28:24Z","date_created":"2025-02-07T18:53:47Z","summary":null,"body":["<article data-history-node-id=\"6025\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-063\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-063<br \/><strong>Date: <\/strong>February\u00a07, 2025<\/p>\n\n<p>On February\u00a04, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 135<\/li>\n\t<li>Thunderbird ESR\u00a0\u2013 versions prior to 128.7<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.7<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.20<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 135<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-063","alert_type":396,"serial_number":"AV25-063","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6026,"title":"Microsoft Edge security advisory (AV25-064)","uuid":"cbf787bf-203d-4a01-a524-eea84d9e8891","banner":null,"lang":"en","date_modified":"2025-02-07","date_modified_ts":"2025-02-07T19:55:07Z","date_created":"2025-02-07T18:53:48Z","summary":null,"body":["<article data-history-node-id=\"6026\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-064\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-064<br \/><strong>Date: <\/strong>February\u00a07, 2025<\/p>\n\n<p>On February\u00a06, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 133.0.3065.51<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-6-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-064","alert_type":396,"serial_number":"AV25-064","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6027,"title":"Google Chrome security advisory (AV25-065)","uuid":"6f01246c-242e-4e79-bb38-47acecdb8d96","banner":null,"lang":"en","date_modified":"2025-02-07","date_modified_ts":"2025-02-07T20:22:30Z","date_created":"2025-02-07T20:06:03Z","summary":null,"body":["<article data-history-node-id=\"6027\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-065\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-065<br \/><strong>Date: <\/strong>February 7, 2025<\/p>\n\n<p>On February 4, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 133.0.6943.53\/54 (Windows and Mac) and 133.0.6943.53 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/02\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-065","alert_type":396,"serial_number":"AV25-065","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6028,"title":"Dell security advisory (AV25-069)","uuid":"b4d57c04-638e-4a8e-bf27-abb5e950dce8","banner":null,"lang":"en","date_modified":"2025-02-10","date_modified_ts":"2025-02-10T19:29:22Z","date_created":"2025-02-10T18:22:40Z","summary":null,"body":["<article data-history-node-id=\"6028\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-069\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-069<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 10, 2025<\/p>\n\n<p>Between February 3 and 9, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen5A, Gen4T \u2013 versions 19.4, 19.7, 19.8, 19.9, 19.10 and 19.10 SP1<\/li>\n\t<li>Dell Avamar Virtual Edition \u2013 multiple versions and platforms<\/li>\n\t<li>Dell Protection Advisor \u2013 versions 19.9, 19.10 and 19.11<\/li>\n\t<li>Dell VxRail Appliance \u2013 versions 0.000 to 8.0.320<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000280531\/dsa-2025-065-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisory DSA-2025-065<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000281275\/dsa-2025-071-security-update-for-dell-avamar-for-multiple-component-vulnerabilities\">Dell Security Advisory DSA-2025-071<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000281732\/dsa-2025-075-security-update-for-dell-data-protection-advisor-for-multiple-component-vulnerabilities\">Dell Security Advisory DSA-2025-075<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-069","alert_type":396,"serial_number":"AV25-069","subject":"dell","moderation_state":"published","external_url":null},{"nid":6030,"title":"Ubuntu security advisory (AV25-067)","uuid":"49c4462f-0da8-4fd4-a08c-9f2adc07885c","banner":null,"lang":"en","date_modified":"2025-02-10","date_modified_ts":"2025-02-10T19:04:23Z","date_created":"2025-02-10T18:24:04Z","summary":null,"body":["<article data-history-node-id=\"6030\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-067\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-067<br \/><strong>Date: <\/strong>February 10, 2025<\/p>\n\n<p>Between February 3 and 9, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7233-3\">USN-7233-3: Linux kernel (Azure) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7234-3\">USN-7234-3: Linux kernel (Azure) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7238-3\">USN-7238-3: Linux kernel (Low Latency) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-067","alert_type":396,"serial_number":"AV25-067","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6029,"title":"[Control systems] CISA ICS security advisories (AV25\u2013068)","uuid":"3135cb16-4d87-4e82-b8a0-10f2b23326e0","banner":null,"lang":"en","date_modified":"2025-02-10","date_modified_ts":"2025-02-10T19:10:34Z","date_created":"2025-02-10T18:25:05Z","summary":null,"body":["<article data-history-node-id=\"6029\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-068\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-068<br \/><strong>Date: <\/strong>February\u00a010, 2025<\/p>\n\n<p>Between February\u00a03 and 9, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Drive Composer entry\u00a0\u2013 version 2.9.0.1 and prior<\/li>\n\t<li>ABB Drive Composer pro\u00a0\u2013 version 2.9.0.1 and prior<\/li>\n\t<li>AutomationDirect C-more EA9 HMI\u00a0\u2013 versions v6.79 and prior for multiple models<\/li>\n\t<li>Elber Communications Cleber\/3 Broadcast Multi-Purpose Platform\u00a0\u2013 version 1.0<\/li>\n\t<li>Elber Communications ESE DVB-S\/S2 Satellite Receiver\u00a0\u2013 versions 1.5.179 and prior<\/li>\n\t<li>Elber Communications Reble610 M\/ODU XPIC IP-ASI-SDH\u00a0\u2013 version 0.01<\/li>\n\t<li>Elber Communications Signum DVB-S\/S2 IRD\u00a0\u2013 versions 1.999 and prior<\/li>\n\t<li>Elber Communications Wayber Analog\/Digital Audio STL\u00a0\u2013 version 4<\/li>\n\t<li>MicroDicom DICOM Viewer\u00a0\u2013 version 2024.03<\/li>\n\t<li>Orthanc server\u00a0\u2013 versions prior to 1.5.8<\/li>\n\t<li>Rockwell Automation 1756-L3zS3\u00a0\u2013 versions prior to V33.017, V34.014, V35.013 and V36.011<\/li>\n\t<li>Rockwell Automation 1756-L8zS3\u00a0\u2013 versions prior to V33.017, V34.014, V35.013 and V36.011<\/li>\n\t<li>Schneider Electric EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 versions 2022 and prior<\/li>\n\t<li>Schneider Electric BMENOR2200H\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric BMXNOE0100\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric BMXNOE0110\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric BMXNOR0200H\u00a0\u2013 versions prior to SV1.70IR26<\/li>\n\t<li>Schneider Electric EVLink Pro AC\u00a0\u2013 versions prior to v1.3.10<\/li>\n\t<li>Schneider Electric EcoStruxure Architecture Builder\u00a0\u2013 versions prior to V7.0.18<\/li>\n\t<li>Schneider Electric EcoStruxure Control Expert Asset Link\u00a0\u2013 versions prior to V4.0 SP1<\/li>\n\t<li>Schneider Electric EcoStruxure Control Expert\u00a0\u2013 versions prior to V16.1<\/li>\n\t<li>Schneider Electric EcoStruxure Machine Expert Twin\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric EcoStruxure Machine Expert including EcoStruxure Machine Expert Safety\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric EcoStruxure Machine SCADA Expert Asset Link\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric EcoStruxure OPC UA Server Expert\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric EcoStruxure Operator Terminal Expert\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon M340 processors (part numbers BMXP34*)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety)\u00a0\u2013 versions prior to SV4.30<\/li>\n\t<li>Schneider Electric Modicon M580 CPU Safety (part numbers BMEP58-S and BMEH58-S)\u00a0\u2013 versions prior to SV4.21<\/li>\n\t<li>Schneider Electric Pro-face GP-Pro EX\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Pro-face Remote HMI\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Vijeo Designer\u00a0\u2013 version prior to V6.3SP1 HF1<\/li>\n\t<li>Schneider Electric Web Designer for BMENOC0311(C)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Web Designer for BMENOC0321(C)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Web Designer for BMXNOE0110(H)\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Web Designer for BMXNOR0200H\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Zelio Soft 2\u00a0\u2013 all versions<\/li>\n\t<li>Schneider ElectricEcoStruxure Process Expert\u00a0\u2013 all versions<\/li>\n\t<li>Trimble Cityworks with office companion\u00a0\u2013 versions prior to 23.10<\/li>\n\t<li>Trimble Cityworks\u00a0\u2013 versions prior to 15.8.9<\/li>\n\t<li>Western Telematic Console Server (DSM Series)\u00a0\u2013 firmware version 6.62 and prior<\/li>\n\t<li>Western Telematic Console Server\u00a0+\u00a0PDU Combo Unit (CPM Series)\u00a0\u2013 firmware version 6.62 and prior<\/li>\n\t<li>Western Telematic Network Power Switch (NPS Series)\u00a0\u2013 firmware version 6.62 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-068","alert_type":398,"serial_number":"AV25-068","subject":"ics","moderation_state":"published","external_url":null},{"nid":6031,"title":"IBM security advisory (AV25-066)","uuid":"e617eb07-e5a3-471d-932f-d462c281393a","banner":null,"lang":"en","date_modified":"2025-02-10","date_modified_ts":"2025-02-10T18:59:49Z","date_created":"2025-02-10T18:46:19Z","summary":null,"body":["<article data-history-node-id=\"6031\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-066\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-066<br \/><strong>Date: <\/strong>February 10, 2025<\/p>\n\n<p>Between February 3 and 9, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>CP4NA\u00a0\u2013 version 2.7.6<\/li>\n\t<li>GDSC Platform On-prem\u00a0\u2013 version 3.6.1<\/li>\n\t<li>IBM Asset Data Dictionary Component\u00a0\u2013 version 1.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 versions 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM dashDB Local\u00a0\u2013 version 11.5.8.0 to refresh 8<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 build 281-287<\/li>\n\t<li>IBM Security QRadar EDR\u00a0\u2013 version 3.12<\/li>\n\t<li>IBM QRadar Suite Software\u00a0\u2013 version 1.10.12.0 to 1.10.24.0<\/li>\n\t<li>IBM watsonx.data\u00a0\u2013 version 1.0.0 to 2.0.0<\/li>\n\t<li>PUB\u00a0\u2013 version 7.0.2 and 7.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-066","alert_type":396,"serial_number":"AV25-066","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6032,"title":"Apple security advisory (AV25-070)","uuid":"751d7bb7-c784-47ff-946b-01430ae56527","banner":null,"lang":"en","date_modified":"2025-02-10","date_modified_ts":"2025-02-10T20:27:40Z","date_created":"2025-02-10T20:15:03Z","summary":null,"body":["<article data-history-node-id=\"6032\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-070\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-070<br \/><strong>Date: <\/strong>February 10, 2025<\/p>\n\n<p>On February 10, 2025, Apple published security updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.3.1<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 17.7.5<\/li>\n<\/ul><p>Apple has been advised that CVE-2025-24200 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-070","alert_type":396,"serial_number":"AV25-070","subject":"other","moderation_state":"published","external_url":null},{"nid":6033,"title":"Progress security advisory (AV25-071)","uuid":"e6448e7e-abe4-438a-b55a-8a1de5aca309","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T14:41:22Z","date_created":"2025-02-11T14:36:01Z","summary":null,"body":["<article data-history-node-id=\"6033\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av25-071\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-071<br \/><strong>Date: <\/strong>February\u00a011, 2025<\/p>\n\n<p>On February\u00a05, 2025, Progress published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>LoadMaster\u00a0\u2013 versions 7.2.55.0 to 7.2.60.1<\/li>\n\t<li>LoadMaster\u00a0\u2013 versions 7.2.49.0 to 7.2.54.12<\/li>\n\t<li>LoadMaster\u00a0\u2013 version 7.2.48.12 and prior<\/li>\n\t<li>Multi-Tenant LoadMaster\u00a0\u2013 versions 7.1.35.12 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/LoadMaster-Security-Vulnerability-CVE-2024-56131-CVE-2024-56132-CVE-2024-56133-CVE-2024-56134-CVE-2024-56135\">Progress LoadMaster Security Vulnerability (CVE-2024-56131-CVE-2024-56132-CVE-2024-56133-CVE-2024-56134-CVE-2024-56135)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av25-071","alert_type":396,"serial_number":"AV25-071","subject":"other","moderation_state":"published","external_url":null},{"nid":6034,"title":"[Control systems] Siemens security advisory (AV25-072) ","uuid":"b382f07b-3a4d-46ed-aeeb-529a6077de45","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T17:25:56Z","date_created":"2025-02-11T16:43:34Z","summary":null,"body":["<article data-history-node-id=\"6034\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-072\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-072<br \/><strong>Date: <\/strong>February 11, 2025<\/p>\n\n<p>On February 11, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APOGEE PXC Series (BACnet)\u00a0\u2013 all versions<\/li>\n\t<li>APOGEE PXC Series (P2 Ethernet)\u00a0\u2013 all versions<\/li>\n\t<li>Opcenter Intelligence\u00a0\u2013 versions prior to 2501<\/li>\n\t<li>OpenV2G\u00a0\u2013 versions prior to 0.9.6<\/li>\n\t<li>Questa\/ModelSim\u00a0\u2013 versions prior to 2025.1<\/li>\n\t<li>RUGGEDCOM APE1808\u00a0\u2013 versions prior to 7.4.5<\/li>\n\t<li>SCALANCE M-800 family (incl. S615, MUM-800 and RM1224)\u00a0\u2013 versions prior to 7.1.2<\/li>\n\t<li>SCALANCE W-700 IEEE 802.11ax family\u00a0\u2013 versions prior to 3.0.0<\/li>\n\t<li>SIMATIC Drive Controller family\u00a0\u2013 versions prior to 3.1.2<\/li>\n\t<li>SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC IPC DiagBase\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC IPC DiagMonitor\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC PCS neo\u00a0\u2013 multiple versions<\/li>\n\t<li>SIMATIC S7-1200 CPU family V4 (incl. SIPLUS variants)\u00a0\u2013 versions prior to 4.7<\/li>\n\t<li>SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)\u00a0\u2013 versions prior to 3.1.2<\/li>\n\t<li>SIMATIC S7-1500 Software Controller\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7-PLCSIM Advanced\u00a0\u2013 versions prior to 7.0<\/li>\n\t<li>SIPROTEC 5\u00a0- CP050 Devices\u00a0\u2013 versions prior to 9.90<\/li>\n\t<li>SIPROTEC 5\u00a0- CP100 Devices\u00a0\u2013 all versions<\/li>\n\t<li>SIPROTEC 5\u00a0- CP150 Devices\u00a0\u2013 versions prior to 9.90<\/li>\n\t<li>SIPROTEC 5\u00a0- CP200 Devices\u00a0\u2013 all versions<\/li>\n\t<li>SIPROTEC 5\u00a0- CP300 Devices\u00a0\u2013 versions prior to 9.90<\/li>\n\t<li>SIPROTEC 5 Communication Modules\u00a0\u2013 versions prior to 9.90<\/li>\n\t<li>TALON TC Series (BACnet)\u00a0\u2013 all versions<\/li>\n\t<li>Teamcenter\u00a0\u2013 versions prior to 14.3.0.0<\/li>\n\t<li>TIA Administrator\u00a0\u2013 versions prior to 3.0.4<\/li>\n\t<li>Totally Integrated Automation Portal (TIA Portal)\u00a0\u2013 versions prior to 19 Update 1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-072","alert_type":398,"serial_number":"AV25-072","subject":"other","moderation_state":"published","external_url":null},{"nid":6035,"title":"SAP security advisory \u2013 February 2025 monthly rollup (AV25-073)","uuid":"ee45594e-c11c-4e95-865a-71d0e30c0f70","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T18:15:57Z","date_created":"2025-02-11T18:10:46Z","summary":null,"body":["<article data-history-node-id=\"6035\" about=\"\/en\/alerts-advisories\/sap-security-advisory-february-2025-monthly-rollup-av25-073\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-073<br \/><strong>Date: <\/strong>February\u00a011, 2025<\/p>\n\n<p>On February\u00a011, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Library\u00a0- @sap\/approuter\u00a0\u2013 version 2.6.1 to 16.7.1<\/li>\n\t<li>SAP BusinessObjects Business Intelligence platform (Central Management Console)\u00a0\u2013 versions ENTERPRISE 430 and 2025<\/li>\n\t<li>SAP Enterprise Project Connection\u00a0\u2013 version 3.0<\/li>\n\t<li>SAP NetWeaver AS Java (User Admin Application) Version\u00a0\u2013 version 7.50<\/li>\n\t<li>SAP Supplier Relationship Management (Master Data Management Catalog)\u00a0\u2013 version SRM_MDM_CAT 7.52<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/february-2025.html\">SAP Security Patch Day\u00a0\u2013 February 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-february-2025-monthly-rollup-av25-073","alert_type":396,"serial_number":"AV25-073","subject":"sap","moderation_state":"published","external_url":null},{"nid":6036,"title":"Ivanti security advisory (AV25-074)","uuid":"1fdb714c-4f23-4c62-a5b6-391511a79a78","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T18:26:53Z","date_created":"2025-02-11T18:11:02Z","summary":null,"body":["<article data-history-node-id=\"6036\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-074\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-074<br \/><strong>Date: <\/strong>February\u00a011, 2025<\/p>\n\n<p>On February\u00a011, 2025, Ivanti published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Ivanti Connect Secure (ICS)\u00a0\u2013 version 22.7R2.5 and prior<\/li>\n\t<li>Ivanti CSA\u00a0\u2013 version 5.0.4 and prior<\/li>\n\t<li>Ivanti Policy Secure (IPS)\u00a0\u2013 version 22.7R1.2 and prior<\/li>\n\t<li>Ivanti Secure Access Client (ISAC)\u00a0\u2013 version 22.7R4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US&amp;_gl=1*19mding*_gcl_au*MjA5NzM0MjEzMy4xNzM5Mjg3OTMz\">Ivanti\u00a0\u2013 February Security Advisory Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS) and Ivanti Secure Access Client (ISAC) (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US\">Ivanti\u00a0\u2013 Security Advisory Ivanti Cloud Services Application (CSA) (CVE-2024-47908, CVE-2024-11771)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-074","alert_type":396,"serial_number":"AV25-074","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6037,"title":"Fortinet security advisory (AV25-075)","uuid":"f45d74d7-2c01-4244-ab14-f5cff741e0a0","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T18:51:37Z","date_created":"2025-02-11T18:30:08Z","summary":null,"body":["<article data-history-node-id=\"6037\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-075\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-075<br \/><strong>Date: <\/strong>February 11, 2025<\/p>\n\n<p>On February 11, 2025, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiOS 7.6\u00a0- version 7.6.0<\/li>\n\t<li>FortiOS 7.4\u00a0- versions 7.4.0 to 7.4.4<\/li>\n\t<li>FortiOS 7.2\u00a0- versions 7.2.0 to 7.2.9 and versions 7.2.4 to 7.2.8<\/li>\n\t<li>FortiOS 7.0\u00a0- versions 7.0.0 to 7.0.15<\/li>\n\t<li>FortiOS 6.4\u00a0- all versions<\/li>\n\t<li>FortiPortal 7.4\u00a0- version 7.4.0 to 7.4.2<\/li>\n\t<li>FortiPortal 7.2\u00a0- version 7.2.0 to 7.2.6<\/li>\n\t<li>FortiPortal 7.0\u00a0- version 7.0.0 to 7.0.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-015\">Fortinet PSIRT\u00a0- FG-IR-25-015<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-160\">Fortinet PSIRT\u00a0- FG-IR-24-160<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-302\">Fortinet PSIRT\u00a0- FG-IR-24-302<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-075","alert_type":396,"serial_number":"AV25-075","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6038,"title":"Microsoft security advisory \u2013 February 2025 monthly rollup (AV25\u2013076)","uuid":"4d1cf8cc-67da-4d7a-88b6-ce13cd335ff4","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T20:03:43Z","date_created":"2025-02-11T19:58:53Z","summary":null,"body":["<article data-history-node-id=\"6038\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-february-2025-monthly-rollup-av25-076\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-076<br \/><strong>Date: <\/strong>February\u00a011, 2025<\/p>\n\n<p>On February\u00a011, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Azure\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Dynamics 365 Sales<\/li>\n\t<li>Microsoft Excel 2016\u00a0\u2013 version 16.0.5487.1000<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft SharePoint\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Visual Studio\u00a0\u2013 multiple versions<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2025-21418, CVE-2025-21391 and CVE-2023-24932 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Feb\">February 2025 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-february-2025-monthly-rollup-av25-076","alert_type":396,"serial_number":"AV25-076","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6040,"title":"Adobe security advisory (AV25\u2013077)","uuid":"55e438cb-b8b9-4715-8e81-efc9d96fe3e0","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T20:35:17Z","date_created":"2025-02-11T20:21:29Z","summary":null,"body":["<article data-history-node-id=\"6040\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-077\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-077<br \/><strong>Date: <\/strong>February 11, 2025<\/p>\n\n<p>On February 11, 2025, Adobe published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe Commerce<\/span>\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe Commerce<\/span> B2B\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe Illustrator<\/span> 2024\u00a0\u2013 version 28.73 and prior<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe Illustrator<\/span> 2025\u00a0\u2013 version 29.1 and prior<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe InCopy<\/span>\u00a0\u2013 version 19.5.1 and prior, version 20.0 and prior<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe InDesign<\/span>\u00a0\u2013 version ID19.5.2 and prior, version ID20.1 and prior<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe Magento Open Source<\/span>\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Adobe Substance<\/span> 3D <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Designer<\/span>\u00a0\u2013 version 14.0.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-077","alert_type":396,"serial_number":"AV25-077","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6041,"title":"HPE security advisory (AV25-078)","uuid":"65a35085-aab4-4f2d-a91f-0ca3fa40b39a","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T21:38:15Z","date_created":"2025-02-11T21:19:42Z","summary":null,"body":["<article data-history-node-id=\"6041\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-078\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-078<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 11, 2025<\/p>\n\n<p>On February 11, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE ProLiant DL145 Gen11\u00a0- versions prior to v1.30_10-04-2024<\/li>\n\t<li>HPE ProLiant DL325 Gen10 Plus server\u00a0- versions prior to v3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant DL325 Gen10 Plus v2 server\u00a0- versions prior to 3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant DL325 Gen10 Server\u00a0- versions prior to 3.30_10-04-2024<\/li>\n\t<li>HPE ProLiant DL325 Gen11 Server\u00a0- versions prior to v1.70_09-06-2024<\/li>\n\t<li>HPE ProLiant DL345 Gen10 Plus server\u00a0- versions prior to 3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant DL345 Gen11 Server\u00a0- versions prior to v1.70_09-06-2024<\/li>\n\t<li>HPE ProLiant DL365 Gen10 Plus server\u00a0- versions prior to 3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant DL365 Gen11 Server\u00a0- versions prior to v1.70_09-06-2024<\/li>\n\t<li>HPE ProLiant DL385 Gen10 Plus server\u00a0- versions prior to 3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant DL385 Gen10 Plus v2 server\u00a0- versions prior to 3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant DL385 Gen10 Server\u00a0- versions prior to 3.30_10-04-2024<\/li>\n\t<li>HPE ProLiant DL385 Gen11 Server\u00a0- versions prior to v1.70_09-06-2024<\/li>\n\t<li>HPE ProLiant XL225n Gen10 Plus 1U Node\u00a0- versions prior to 3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant XL645d Gen10 Plus Server\u00a0- versions prior to 3.40_10-04-2024<\/li>\n\t<li>HPE ProLiant XL675d Gen10 Plus Server\u00a0- versions prior to v3.40_10-04-2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-078","alert_type":396,"serial_number":"AV25-078","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6042,"title":"Intel security advisory (AV25-079)","uuid":"928b40d9-eb18-4866-b9b5-bb4be0061013","banner":null,"lang":"en","date_modified":"2025-02-11","date_modified_ts":"2025-02-11T21:49:08Z","date_created":"2025-02-11T21:44:18Z","summary":null,"body":["<article data-history-node-id=\"6042\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av25-079\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-079<br \/><strong>Date: <\/strong>February 11, 2025<\/p>\n\n<p>On February 11, 2025, Intel published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Product Security Center Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av25-079","alert_type":396,"serial_number":"AV25-079","subject":"intel","moderation_state":"published","external_url":null},{"nid":6043,"title":"[Control systems] Schneider Electric security advisory (AV25-080)","uuid":"3aefa1c0-3869-4468-8106-2f6e74975153","banner":null,"lang":"en","date_modified":"2025-02-12","date_modified_ts":"2025-02-12T15:28:03Z","date_created":"2025-02-12T14:48:52Z","summary":null,"body":["<article data-history-node-id=\"6043\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-080\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-080<br \/><strong>Date: <\/strong>February\u00a012, 2025<\/p>\n\n<p>On February\u00a011, 2025, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ASCO 5310 Single-Channel Remote Annunciator\u00a0\u2013 all versions<\/li>\n\t<li>ASCO 5350 Eight Channel Remote Annunciator\u00a0\u2013 all versions<\/li>\n\t<li>EcoStruxure Process Expert\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Enerlin\u2019X IFE interface (LV434001)\u00a0\u2013 all versions<\/li>\n\t<li>Enerlin\u2019X eIFE (LV851001)\u00a0\u2013 all versions<\/li>\n\t<li>Uni-Telway driver\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-080","alert_type":398,"serial_number":"AV25-080","subject":"se","moderation_state":"published","external_url":null},{"nid":6044,"title":"Palo Alto Networks security advisory (AV25-081) - Update 1","uuid":"20fb91e0-eddc-4367-b844-073d6c52608a","banner":null,"lang":"en","date_modified":"2025-02-19","date_modified_ts":"2025-02-19T16:58:12Z","date_created":"2025-02-12T20:13:27Z","summary":null,"body":["<article data-history-node-id=\"6044\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-081\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-081<br \/><strong>Date: <\/strong>February 12, 2025<br \/><strong>Updated: <\/strong>February 19, 2025<\/p>\n\n<p>On February 12, 2025, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>PAN-OS 11.2 \u2013 versions prior to 11.2.4-h4<\/li>\n\t<li>PAN-OS 11.1 \u2013 versions prior to 11.1.6-h1<\/li>\n\t<li>PAN-OS 10.2 \u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.1 \u2013 versions prior to10.1.14-h9<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>On February 18 and 20, 2025, CISA added CVE-2025-0108 and CVE-2025-0111 to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>On February 19, 2025, Palo Alto updated their advisory to indicate that these vulnerabilities have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-0108\">Palo Alto Networks Security Advisories\u00a0\u2013 CVE-2025-0108<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-0111\">Palo Alto Networks Security Advisories\u00a0\u2013 CVE-2025-0111 <\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog \">CISA - Known Exploited Vulnerabilities Catalog <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-081","alert_type":396,"serial_number":"AV25-081","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6045,"title":"Google Chrome security advisory (AV25-082)","uuid":"29d91166-b249-4e48-8183-e9cab744c9f5","banner":null,"lang":"en","date_modified":"2025-02-12","date_modified_ts":"2025-02-12T20:32:40Z","date_created":"2025-02-12T20:25:45Z","summary":null,"body":["<article data-history-node-id=\"6045\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-082\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-082<br \/><strong>Date: <\/strong>February 12 2025<\/p>\n\n<p>On February 12, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0- versions prior to 133.0.6943.98\/.99 (Windows and Mac) and 133.0.6943.98 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/02\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-082","alert_type":396,"serial_number":"AV25-082","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6048,"title":"GitLab security advisory (AV25-083)","uuid":"5bed373f-5a6d-4b0d-ba09-13789c29be37","banner":null,"lang":"en","date_modified":"2025-02-13","date_modified_ts":"2025-02-13T19:27:27Z","date_created":"2025-02-13T19:18:24Z","summary":null,"body":["<article data-history-node-id=\"6048\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-083\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-083<br \/><strong>Date: <\/strong>February\u00a013, 2025<\/p>\n\n<p>On February\u00a012, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.8.2, 17.7.4 and 17.6.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.8.2, 17.7.4 and 17.6.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/02\/12\/patch-release-gitlab-17-8-2-released\/\">GitLab Patch Release: 17.8.2, 17.7.4, 17.6.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-083","alert_type":396,"serial_number":"AV25-083","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6050,"title":"PostgreSQL security advisory (AV25-084)","uuid":"88e45c1e-a9a3-49a6-b811-07d119fbaf3c","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T14:08:26Z","date_created":"2025-02-17T14:05:43Z","summary":null,"body":["<article data-history-node-id=\"6050\" about=\"\/en\/alerts-advisories\/postgresql-security-advisory-av25-084\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n<p><strong>Serial number: <\/strong>AV25-084\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025\n<\/p>\n<p>On February 13, 2025, PostgreSQL published a security advisory to address a vulnerability in the following product:\n<\/p>\n<ul><li>PostgreSQL \u2013 13.x versions prior to 13.19, 14.x versions prior to 14.16, 15.x versions prior to 15.11, 16.x versions prior to 16.7 and 17.x versions prior to 17.3<\/li>\n<\/ul><p>Open-source reporting has advised that CVE-2025-1094 may have been exploited.<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.postgresql.org\/support\/security\/CVE-2025-1094\/\">PostgreSQL Advisory - quoting APIs miss neutralizing quoting syntax in text that fails encoding validation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/postgresql-security-advisory-av25-084","alert_type":396,"serial_number":"AV25-084","subject":"other","moderation_state":"published","external_url":null},{"nid":6051,"title":"[Control systems] CISA ICS security advisories (AV25-085) ","uuid":"fe742c9c-ee9e-4cdd-a86d-7a34c7c4714b","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T16:55:28Z","date_created":"2025-02-17T16:48:49Z","summary":null,"body":["<article data-history-node-id=\"6051\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-085\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n<p><strong>Serial number: <\/strong>AV25-085\n  <br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025\n<\/p>\n<p>Between February 10 and 16, 2025, CISA published ICS advisories to address vulnerabilities in the following products:\n<\/p>\n<ul><li>Dingtian DT-R002 \u2013 version V3.1.3044A<\/li>\n  <li>Dingtian DT-R008 \u2013 version V3.1.1759A<\/li>\n  <li>Dingtian DT-R016 \u2013 version V3.1.2776A<\/li>\n  <li>Dingtian DT-R032 \u2013 version V3.1.3826A<\/li>\n  <li>mySCADA myPRO Manager \u2013 versions prior to 1.4<\/li>\n  <li>ORing IAP-20 \u2013 versions 2.01e and prior<\/li>\n  <li>Outback Power Mojave Inverter \u2013 all versions<\/li>\n  <li>Siemens APOGEE PXC Series (P2 Ethernet and BACnet) \u2013 all versions<\/li>\n  <li>Siemens ModelSim \u2013 versions prior to V2025.1<\/li>\n  <li>Siemens Opcenter Intelligence \u2013 versions prior to V2501<\/li>\n  <li>Siemens OpenV2G \u2013 versions prior to V0.9.6<\/li>\n  <li>Siemens Questa \u2013 versions prior to V2025.1<\/li>\n  <li>Siemens RUGGEDCOM APE1808 \u2013 all versions<\/li>\n  <li>Siemens SCALANCE W700 \u2013 multiple models, versions prior to v3.0.0<\/li>\n  <li>Siemens SIMATIC Drive Controller CPU 1507D TF - versions 3.1.0 to versions prior to V3.1.2<\/li>\n  <li>Siemens SIMATIC Drive Controller CPU 1504D TF - versions 3.1.0 to versions prior to V3.1.2<\/li>\n  <li>Siemens SIMATIC IPC DiagBase \u2013 all versions<\/li>\n  <li>Siemens SIMATIC IPC DiagMonitor \u2013 all versions<\/li>\n  <li>Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2 \u2013 versions 3.1.0 to versions prior to V3.1.2<\/li>\n  <li>Siemens SIMATIC S7-PLCSIM Advanced \u2013 versions V6.0 to versions prior to V7.0<\/li>\n  <li>Siemens SIMATIC S7-1200 CPU Family \u2013 multiple models, versions prior to V4.7<\/li>\n  <li>Siemens SIMATIC S7-1500 CPU \u2013 multiple models, versions 3.1.0 to versions prior to V3.1.2<\/li>\n  <li>Siemens SIMOCODE ES V19 \u2013 versions prior to V19 Update 1<\/li>\n  <li>Siemens SIMATIC PCS neo V5.0 \u2013 versions prior to V5.0 Update 1<\/li>\n  <li>Siemens SIMATIC PCS neo V4.1 \u2013 versions prior to V4.1 Update 2<\/li>\n  <li>Siemens SIMATIC PCS neo V4.0 \u2013 all versions<\/li>\n  <li>Siemens SIPLUS S7-1200 CPU \u2013 multiple models, versions prior to V4.7<\/li>\n  <li>Siemens SIPLUS S7-1500 CPU \u2013 multiple models, versions 3.1.0 to versions prior to V3.1.2<\/li>\n  <li>Siemens SIPROTEC 5 \u2013 multiple models, all versions<\/li>\n  <li>Siemens SIRIUS Safety ES V19 (TIA Portal) \u2013 versions prior to V19 Update 1<\/li>\n  <li>Siemens SIRIUS Soft Starter ES V19 (TIA Portal) \u2013 versions prior to V19 Update 1<\/li>\n  <li>Siemens TALON TC Series (BACnet) \u2013 all versions<\/li>\n  <li>Siemens Teamcenter \u2013 versions prior to V14.3.0.0<\/li>\n  <li>Siemens TIA Administrator \u2013 versions 3.0.4 and prior<\/li>\n  <li>QardioARM A100 \u2013 all versions<\/li>\n  <li>Qardio Heart Health IOS Mobile Application \u2013 version 2.7.4<\/li>\n  <li>Qardio Heart Health Android Mobile Application \u2013 version 2.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.\n<\/p>\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-085","alert_type":398,"serial_number":"AV25-085","subject":"other","moderation_state":"published","external_url":null},{"nid":6052,"title":"Ubuntu security advisory (AV25-086)","uuid":"1f14d146-40c2-4977-a8be-68b37a1cd1a9","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T17:00:34Z","date_created":"2025-02-17T16:57:35Z","summary":null,"body":["<article data-history-node-id=\"6052\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-086\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-086<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025<\/p>\n\n<p>Between February 10 and 16, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-086","alert_type":396,"serial_number":"AV25-086","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6053,"title":"Dell security advisory (AV25-087)","uuid":"1f725541-7dff-432d-94d7-740fdf089c04","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T17:07:26Z","date_created":"2025-02-17T17:02:00Z","summary":null,"body":["<article data-history-node-id=\"6053\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-087\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-087<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025<\/p>\n\n<p>Between February 10 and 16, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Dell Avamar NDMP Accelerator \u2013 multiple versions<\/li>\n\t<li>Dell Avamar Server Hardware Appliance Gen4T\/Gen5A \u2013 multiple versions<\/li>\n\t<li>Dell Avamar Virtual Edition \u2013 multiple versions<\/li>\n\t<li>Dell Avamar VMware Image Proxy \u2013 multiple versions<\/li>\n\t<li>Dell Networker Virtual Edition (NVE) \u2013 multiple versions<\/li>\n\t<li>Dell Power Protect DP Series Appliance \u2013 version 2.7.8 and prior running on SLES12SP5<\/li>\n\t<li>PowerPath Management Appliance \u2013 version 4.0 P02<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000283460\/dsa-2025-081-security-update-for-dell-avamar-dell-networker-virtual-edition-nve-and-dell-powerprotect-dp-series-appliance-dell-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities \">Dell Security Advisory DSA-2025-081<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000286224\/dsa-2025-094-security-update-for-dell-powerpath-management-appliance-is-methods-security-vulnerabilities\">Dell Security Advisory DSA-2025-094<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-087","alert_type":396,"serial_number":"AV25-087","subject":"dell","moderation_state":"published","external_url":null},{"nid":6054,"title":"IBM security advisory (AV25-088)","uuid":"7707d747-45ba-4bbc-a106-0d38bd904652","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T17:12:28Z","date_created":"2025-02-17T17:09:18Z","summary":null,"body":["<article data-history-node-id=\"6054\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-088\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-088<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025<\/p>\n\n<p>Between February 10 and 16, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Container \u2013 multiple versions<\/li>\n\t<li>IBM Operational Decision Manager \u2013 versions 8.11.0.1, 8.11.1.0, 8.12.0.1 and 9.0.0.1<\/li>\n\t<li>IBM QRadar Deployment Intelligence App \u2013 version 1.0.0 to 3.0.15<\/li>\n\t<li>IBM Watson Assistant for IBM Cloud Pak for Data \u2013 versions 4.0.0 to 4.8.7<\/li>\n\t<li>IBM Watson Studio on Cloud Pak for Data - Execution Engine for Apache Hadoop \u2013 version 5.0<\/li>\n\t<li>IBM watsonx.data \u2013 versions 1.1.0 to 2.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-088","alert_type":396,"serial_number":"AV25-088","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6055,"title":"Red Hat security advisory (AV25-089)","uuid":"60ee55a7-586e-4966-8a56-d28bee31e4a1","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T19:58:21Z","date_created":"2025-02-17T19:55:29Z","summary":null,"body":["<article data-history-node-id=\"6055\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-089\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-089<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025<\/p>\n\n<p>Red Hat security advisory (AV25-089) Between February 10 and 16, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products :<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-089","alert_type":396,"serial_number":"AV25-089","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6056,"title":"[Control systems] Siemens security advisory (AV25-090) ","uuid":"3b158d48-3de0-45e0-adb4-981f3ec36bba","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T20:03:08Z","date_created":"2025-02-17T20:00:09Z","summary":null,"body":["<article data-history-node-id=\"6056\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-090\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-090<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025<\/p>\n\n<p>On February 17, 2025, Siemens published an advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SiPass integrated V2.90 \u2013 versions prior to V2.90.3.19<\/li>\n\t<li>SiPass integrated V2.95 \u2013 versions prior to V2.95.3.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-992434.html\">Siemens Security Advisory - SSA-992434<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-090","alert_type":398,"serial_number":"AV25-090","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6057,"title":"Microsoft Edge security advisory (AV25-091)","uuid":"e824855c-d6d7-4e80-8e3e-917f06e2e901","banner":null,"lang":"en","date_modified":"2025-02-17","date_modified_ts":"2025-02-17T20:08:30Z","date_created":"2025-02-17T20:06:17Z","summary":null,"body":["<article data-history-node-id=\"6057\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-091\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-091<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 17, 2025<\/p>\n\n<p>On February 14, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 133.0.3065.69<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-14-2025  \">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-091","alert_type":396,"serial_number":"AV25-091","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6058,"title":"OpenSSH security advisory (AV25-092)","uuid":"73304269-4b3e-4876-a0b4-12e0e394c870","banner":null,"lang":"en","date_modified":"2025-02-18","date_modified_ts":"2025-02-18T13:10:28Z","date_created":"2025-02-18T13:07:21Z","summary":null,"body":["<article data-history-node-id=\"6058\" about=\"\/en\/alerts-advisories\/openssh-security-advisory-av25-092\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-092<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 18, 2025<\/p>\n\n<p>On February 18, 2025, OpenSSH published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSH \u2013 versions 6.8p1 to 9.9p1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.openssh.com\/releasenotes.html#9.9p2 \">OpenSSH 9.9p2 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.openssh.com\/\">OpenSSH<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssh-security-advisory-av25-092","alert_type":396,"serial_number":"AV25-092","subject":"other","moderation_state":"published","external_url":null},{"nid":6059,"title":"Juniper Networks security advisory (AV25-093)","uuid":"d0c0d5f8-785d-42f6-80ca-e74ad9d1db97","banner":null,"lang":"en","date_modified":"2025-02-18","date_modified_ts":"2025-02-18T15:17:28Z","date_created":"2025-02-18T15:03:11Z","summary":null,"body":["<article data-history-node-id=\"6059\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-093\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-093<br \/><strong>Date: <\/strong>February 18, 2025<\/p>\n\n<p>On February 11, 2025, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Session Smart Router\u00a0\u2013 multiple versions<\/li>\n\t<li>Session Smart Conductor\u00a0\u2013 multiple versions<\/li>\n\t<li>WAN Assurance Managed Routers\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US\">Juniper Networks Security\u00a0- JSA94663<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-093","alert_type":396,"serial_number":"AV25-093","subject":"juniper","moderation_state":"published","external_url":null},{"nid":6060,"title":"Citrix security advisory (AV25-094)","uuid":"e5d67dd8-6385-4efa-8979-1222682f3fb2","banner":null,"lang":"en","date_modified":"2025-02-18","date_modified_ts":"2025-02-18T15:58:42Z","date_created":"2025-02-18T15:39:42Z","summary":null,"body":["<article data-history-node-id=\"6060\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-094\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-094<br \/><strong>Date: <\/strong>February 18, 2025<\/p>\n\n<p>On February 18, 2025, Citrix published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>NetScaler Console 14.1\u00a0\u2013 versions prior to 14.1-38.53<\/li>\n\t<li>NetScaler Console 13.1\u00a0\u2013 versions prior to 13.1-56.18<\/li>\n\t<li>NetScaler Agent 14.1\u00a0\u2013 versions prior to 14.1-38.53<\/li>\n\t<li>NetScaler Agent 13.1\u00a0\u2013 versions prior 13.1-56.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/s\/article\/CTX692579-netscaler-console-and-netscaler-agent-security-bulletin-for-cve202412284?language=en_US\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Citrix Security Advisory<\/span>\u00a0\u2013 CTX692579<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-094","alert_type":396,"serial_number":"AV25-094","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6061,"title":"Mozilla security advisory (AV25-095)","uuid":"21c0852d-32d4-4f99-a151-ffea65b881bc","banner":null,"lang":"en","date_modified":"2025-02-18","date_modified_ts":"2025-02-18T16:25:28Z","date_created":"2025-02-18T16:11:02Z","summary":null,"body":["<article data-history-node-id=\"6061\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-095\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-095<br \/><strong>Date: <\/strong>February 18, 2025<\/p>\n\n<p>On February 18, 2025, Mozilla published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 135.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-12\/\">Mozilla Security Advisory (MFSA 2025-12)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-095","alert_type":396,"serial_number":"AV25-095","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6063,"title":"Google Chrome security advisory (AV25-096)","uuid":"2fb0291c-6dec-4bd8-b6a1-52077446bb1e","banner":null,"lang":"en","date_modified":"2025-02-19","date_modified_ts":"2025-02-19T13:49:19Z","date_created":"2025-02-19T13:46:19Z","summary":null,"body":["<article data-history-node-id=\"6063\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-096\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-096<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 19, 2025<\/p>\n\n<p>On February 18, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 133.0.6943.126\/127 (Windows and Mac) and 133.0.6943.126 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/02\/stable-channel-update-for-desktop_18.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-096","alert_type":396,"serial_number":"AV25-096","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6076,"title":"Atlassian security advisory (AV25-097)","uuid":"f52a9acb-9307-48d3-90da-6150b69af456","banner":null,"lang":"en","date_modified":"2025-02-19","date_modified_ts":"2025-02-19T20:00:52Z","date_created":"2025-02-19T19:52:59Z","summary":null,"body":["<article data-history-node-id=\"6076\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-097\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-097<br \/><strong>Date: <\/strong>February 19, 2025<\/p>\n\n<p>On February 18, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-february-18-2025-1510670627.html\">Atlassian Security Bulletin\u00a0- February 18 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-097","alert_type":396,"serial_number":"AV25-097","subject":"other","moderation_state":"published","external_url":null},{"nid":6113,"title":"Microsoft Edge security advisory (AV25-098)","uuid":"fd1ec7e3-1a01-47f4-b70c-b3d24c4f5cec","banner":null,"lang":"en","date_modified":"2025-02-21","date_modified_ts":"2025-02-21T14:24:52Z","date_created":"2025-02-21T14:18:59Z","summary":null,"body":["<article data-history-node-id=\"6113\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-098\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-098<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 21, 2025<\/p>\n\n<p>On February 20, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 132.0.2957.171<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-20-2025\">Microsoft Edge Extended Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-098","alert_type":396,"serial_number":"AV25-098","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6132,"title":"Signal security advisory (AV25-099)","uuid":"1fa4a6e9-581a-443e-8426-f44e12048caf","banner":null,"lang":"en","date_modified":"2025-02-21","date_modified_ts":"2025-02-21T19:44:11Z","date_created":"2025-02-21T19:38:58Z","summary":null,"body":["<article data-history-node-id=\"6132\" about=\"\/en\/alerts-advisories\/signal-security-advisory-av25-099\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-099<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>February 21, 2025<\/p>\n\n<p>On February 19, 2025, the Cyber Centre became aware of Signal updates containing hardened features to help protect against phishing campaigns affecting the following products:<\/p>\n\n<ul><li>Signal iOS\u00a0\u2013 as of today, versions prior to 7.47 (latest version)<\/li>\n\t<li>Signal Android\u00a0\u2013 as of today, versions prior to 7.33.2 (latest version)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/russia-targeting-signal-messenger\/\">Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger<\/a><\/li>\n\t<li><a href=\"https:\/\/support.signal.org\/hc\/en-us\/articles\/360007059212-How-do-I-ensure-Signal-is-up-to-date\">Updating Signal<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/security-considerations-qr-codes-itsap00141\">Security considerations for QR codes ITSAP.00.141<\/a><\/li>\n\t<li><a href=\"https:\/\/www.wired.com\/story\/russia-signal-qr-code-phishing-attack\/#:~:text=Google%20warns%20that%20hackers%20tied,has%20pushed%20out%20new%20safeguards\">A Signal Update Fends Off a Phishing Technique Used in Russian Espionage <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/signal-security-advisory-av25-099","alert_type":396,"serial_number":"AV25-099","subject":"other","moderation_state":"published","external_url":null},{"nid":6138,"title":"Ubuntu security advisory (AV25-100)","uuid":"ac582791-620d-4e57-84f4-51dd41edc6ae","banner":null,"lang":"en","date_modified":"2025-02-24","date_modified_ts":"2025-02-24T14:22:35Z","date_created":"2025-02-24T14:16:32Z","summary":null,"body":["<article data-history-node-id=\"6138\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-100\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-100<br \/><strong>Date: <\/strong>February\u00a024, 2025<\/p>\n\n<p>Between February\u00a017 and 23, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/LSN-0109-1\">Ubuntu Security Notice\u00a0- LSN-0109-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7277-1\">Ubuntu Security Notice\u00a0- USN-7277-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7276-1\">Ubuntu Security Notice\u00a0- USN-7276-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-100","alert_type":396,"serial_number":"AV25-100","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6139,"title":"[Control systems] CISA ICS security advisories (AV25\u2013101)","uuid":"feb3188e-9953-413c-8a43-7ae1d46b7e89","banner":null,"lang":"en","date_modified":"2025-02-24","date_modified_ts":"2025-02-24T14:31:49Z","date_created":"2025-02-24T14:16:33Z","summary":null,"body":["<article data-history-node-id=\"6139\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-101\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-101<br \/><strong>Date: <\/strong>February\u00a024, 2025<\/p>\n\n<p>Between February\u00a017 and 23, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB ASPECT-Enterprise ASP-ENT-x\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>ABB FLXEON Controllers FBXi, FBVi, FBTi and CBXi\u00a0\u2013 version 9.3.4 and prior<\/li>\n\t<li>ABB MATRIX Series MAT-x\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>ABB NEXUS Series NEX-2x\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>ABB NEXUS Series\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>Elseta Vinci Protocol Analyzer\u00a0\u2013 versions prior to 3.2.3.19<\/li>\n\t<li>Medixant RadiANT DICOM Viewer\u00a0\u2013 version 2024.02<\/li>\n\t<li>Mitsubishi Electric CNC Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Rapid Response Monitoring My Security Account App API\u00a0\u2013 versions prior to 7\/29\/24<\/li>\n\t<li>Siemens SiPass integrated V2.90\u00a0\u2013 versions prior to V2.90.3.19<\/li>\n\t<li>Siemens SiPass integrated V2.95\u00a0\u2013 versions prior to V2.95.3.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-101","alert_type":398,"serial_number":"AV25-101","subject":"ics","moderation_state":"published","external_url":null},{"nid":6140,"title":"IBM security advisory (AV25-102)","uuid":"8d87d292-8751-48ba-9da2-5ba357236450","banner":null,"lang":"en","date_modified":"2025-02-24","date_modified_ts":"2025-02-24T14:38:39Z","date_created":"2025-02-24T14:16:33Z","summary":null,"body":["<article data-history-node-id=\"6140\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-102\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-102<br \/><strong>Date: <\/strong>February\u00a024, 2025<\/p>\n\n<p>Between February\u00a017 and 23, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cognos Controller\u00a0\u2013 versions 11.0.0 to 11.0.1 FP3<\/li>\n\t<li>IBM Controller\u00a0\u2013 version 11.1.0<\/li>\n\t<li>IBM CP4MCM\u00a0\u2013 versions 2.3 to 2.3 FP9<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>Maas360 Configuration Utility\u00a0\u2013 versions 2.90.000 to 3.000.950<\/li>\n\t<li>Maas360 Mobile Enterprise Gateway\u00a0\u2013 versions 2.90.000 to 3.000.800<\/li>\n\t<li>IBM Watson Query on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>Watson Studio on Cloud Pak for Data\u00a0- Execution Engine for Apache Hadoop\u00a0\u2013 version 5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-102","alert_type":396,"serial_number":"AV25-102","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6141,"title":"Dell security advisory (AV25-103)","uuid":"c5cade93-11a2-4046-9497-d6a821203cee","banner":null,"lang":"en","date_modified":"2025-02-24","date_modified_ts":"2025-02-24T16:54:07Z","date_created":"2025-02-24T16:48:27Z","summary":null,"body":["<article data-history-node-id=\"6141\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-103\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-103<br \/><strong>Date: <\/strong>February 24, 2025<\/p>\n\n<p>Between February 17 and 23, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Networking S5448F-ON\u00a0\u2013 versions prior to 3.52.5.1-12<\/li>\n\t<li>Dell Networking Z9432F-ON\u00a0\u2013 versions prior to 3.51.5.1-21<\/li>\n\t<li>Dell Networking Z9664F-ON\u00a0\u2013 versions prior to 3.54.5.1-9<\/li>\n\t<li>Networker Management Console\u00a0\u2013 versions 19.11 to 19.11.0.3 and versions prior to 19.10.0.7<\/li>\n\t<li>PowerPath Management Appliance\u00a0\u2013 version 4.0 P02<\/li>\n\t<li>PowerStore 500T, 1000T, 1200T, 3000T, 3200Q, 3200T, 5000T, 5200T, 7000T, 9000T and 9200T\u00a0\u2013 versions prior to 4.1.0.0-2435323<\/li>\n\t<li>RecoverPoint for Virtual Machines\u00a0\u2013 versions 6.0 SP1, 6.0 SP1 P1 and 6.0 SP1 P2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-103","alert_type":396,"serial_number":"AV25-103","subject":"dell","moderation_state":"published","external_url":null},{"nid":6142,"title":"HPE security advisory (AV25-104)","uuid":"973866c7-45d3-4ad6-a8b0-c4560acef0cf","banner":null,"lang":"en","date_modified":"2025-02-25","date_modified_ts":"2025-02-25T18:56:46Z","date_created":"2025-02-25T18:26:58Z","summary":null,"body":["<article data-history-node-id=\"6142\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-104\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-104<br \/><strong>Date: <\/strong>February 25, 2025<\/p>\n\n<p>On February 23 and 24, 2025, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>CONSOLE CLIM UTILITIES T0697\u00a0\u2013 versions T0697H01^AAA and T0697H01^AAQ<\/li>\n\t<li>CLIM DVD Installation Software T0853\u00a0\u2013 versions T0853L03-T0853L03^DDA, T0989L03-T0989L03^DDA, T0976L03-T0976L03^DDA and T0853J03-T0853J03^CEE<\/li>\n\t<li>HPE Cray EX425 Compute Blade\u00a0\u2013 versions prior to v1.7.6 (HFP 24.11.0)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbns04778en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbns04778 <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04811en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04811 <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-104","alert_type":396,"serial_number":"AV25-104","subject":"other","moderation_state":"published","external_url":null},{"nid":6143,"title":"Google Chrome security advisory (AV25-105)","uuid":"d7ab4c5a-4c34-4790-a161-47efdee4d6c7","banner":null,"lang":"en","date_modified":"2025-02-25","date_modified_ts":"2025-02-25T19:58:11Z","date_created":"2025-02-25T19:41:30Z","summary":null,"body":["<article data-history-node-id=\"6143\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-105\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-105<br \/><strong>Date: <\/strong>February 25, 2025<\/p>\n\n<p>On February 25, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 133.0.6943.141\/142 (Windows and Mac) and 133.0.6943.141 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/02\/stable-channel-update-for-desktop_25.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-105","alert_type":396,"serial_number":"AV25-105","subject":"other","moderation_state":"published","external_url":null},{"nid":6145,"title":"GitLab security advisory (AV25-106)","uuid":"dcfea7d8-6e3b-4953-a6fe-da3f586f0732","banner":null,"lang":"en","date_modified":"2025-02-26","date_modified_ts":"2025-02-26T20:16:06Z","date_created":"2025-02-26T20:05:01Z","summary":null,"body":["<article data-history-node-id=\"6145\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-106\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-106<br \/><strong>Date: <\/strong>February 26, 2025<\/p>\n\n<p>On February 26, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.9.1, 17.8.4 and 17.7.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.9.1, 17.8.4 and 17.7.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/02\/26\/patch-release-gitlab-17-9-1-released\/\">GitLab Patch Release: 17.9.1, 17.8.4, 17.7.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-106","alert_type":396,"serial_number":"AV25-106","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6149,"title":"krpano security advisory (AV25-107)","uuid":"1f47ffc3-5aa0-4141-b794-a9f1c871f280","banner":null,"lang":"en","date_modified":"2025-02-28","date_modified_ts":"2025-02-28T16:47:28Z","date_created":"2025-02-28T16:33:34Z","summary":null,"body":["<article data-history-node-id=\"6149\" about=\"\/en\/alerts-advisories\/krpano-security-advisory-av25-107\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-107<br \/><strong>Date: <\/strong>February\u00a028, 2025<\/p>\n\n<p>On February\u00a024, 2025, krpano published a bulletin to address vulnerabilities in the following product:<\/p>\n\n<ul><li>krpano\u00a0\u2013 versions prior to 1.22.4<\/li>\n<\/ul><p>Cyber Centre has received reports that CVE-2020-24901 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/krpano.com\/docu\/releasenotes\/#krpano122_4\">krpano Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/krpano-security-advisory-av25-107","alert_type":396,"serial_number":"AV25-107","subject":"other","moderation_state":"published","external_url":null},{"nid":6150,"title":"Dell security advisory (AV25-108)","uuid":"55c1573b-48ff-4b64-a80d-e9e5b3287220","banner":null,"lang":"en","date_modified":"2025-03-03","date_modified_ts":"2025-03-03T20:15:53Z","date_created":"2025-03-03T20:05:24Z","summary":null,"body":["<article data-history-node-id=\"6150\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-108\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-108<br \/><strong>Date: <\/strong>March\u00a03, 2025<\/p>\n\n<p>Between February\u00a024 and March\u00a02, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Networking OS10\u00a0\u2013 version 10.5.4.x<\/li>\n\t<li>Dell Policy Manager for Secure Connect Gateway\u00a0\u2013 version 5.26.00.18<\/li>\n\t<li>Dell PowerScale OneFS\u00a0\u2013 versions 9.4.0.0 to 9.5.1.1<\/li>\n\t<li>Dell PowerScale OneFS\u00a0\u2013 versions 9.5.0.0 to 9.7.1.4<\/li>\n\t<li>Dell PowerScale OneFS\u00a0\u2013 versions 9.8.0.0 to 9.9.0.1<\/li>\n\t<li>Integrated System for Microsoft Azure Stack Hub 14G\u00a0\u2013 versions prior to 2407<\/li>\n\t<li>Integrated System for Microsoft Azure Stack Hub 14G\u00a0\u2013 versions prior to 2411<\/li>\n\t<li>Integrated System for Microsoft Azure Stack Hub 16G\u00a0\u2013 versions prior to 2411<\/li>\n\t<li>Dell PowerEdge R750XA\u00a0\u2013 versions prior to 1.0<\/li>\n\t<li>Dell PowerEdge R7515\u00a0\u2013 versions prior to 1.0<\/li>\n\t<li>Dell PowerEdge R7525\u00a0\u2013 versions prior to 1.0<\/li>\n\t<li>Dell PowerEdge R760XA\u00a0\u2013 versions prior to 1.0<\/li>\n\t<li>Dell PowerEdge R7615\u00a0\u2013 versions prior to 1.0<\/li>\n\t<li>Dell PowerEdge R7625\u00a0\u2013 versions prior to 1.0<\/li>\n\t<li>Dell PowerEdge XE9680\u00a0\u2013 versions prior to A00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-108","alert_type":396,"serial_number":"AV25-108","subject":"dell","moderation_state":"published","external_url":null},{"nid":6151,"title":"IBM security advisory (AV25-109)","uuid":"0c5802c4-dbb9-42fe-b20c-81115fe84d6c","banner":null,"lang":"en","date_modified":"2025-03-03","date_modified_ts":"2025-03-03T20:16:51Z","date_created":"2025-03-03T20:05:25Z","summary":null,"body":["<article data-history-node-id=\"6151\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-109\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-109<br \/><strong>Date: <\/strong>March\u00a03, 2025<\/p>\n\n<p>Between February\u00a024 and March\u00a02, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 versions 24.0.1, V24.0.0 to V24.0.0 to IF003 and unsupported versions<\/li>\n\t<li>IBM Cognos Analytics\u00a0\u2013 versions 11.2.0 to 11.2.4 FP5 and 12.0.0 to 12.0.4<\/li>\n\t<li>IBM Jazz Reporting Service\u00a0\u2013 versions 7.0.2 and 7.0.3<\/li>\n\t<li>IBM Software Support App (iOS)\u00a0\u2013 version 1.0.0<\/li>\n\t<li>IBM Software Support app (Android)\u00a0\u2013 version 1.0.0<\/li>\n\t<li>IBM Storage Virtualize\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM TXSeries for Multiplatforms\u00a0\u2013 versions 8.1, 8.2, 9.1 and 10.1<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0\u2013 version 4.0.0 to 5.1.0<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.8.4 to 4.8.5 and 5.0.0 to 5.1.0<\/li>\n\t<li>watsonx.data\u00a0\u2013 versions 2.0.2 to 2.1.0 and 2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-109","alert_type":396,"serial_number":"AV25-109","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6152,"title":"Ubuntu security advisory (AV25-110)","uuid":"dbb711a6-338b-46d2-8d88-496ba9de414c","banner":null,"lang":"en","date_modified":"2025-03-03","date_modified_ts":"2025-03-03T20:17:27Z","date_created":"2025-03-03T20:05:26Z","summary":null,"body":["<article data-history-node-id=\"6152\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-110\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-110<br \/><strong>Date: <\/strong>March\u00a03, 2025<\/p>\n\n<p>Between February\u00a024 and March\u00a02, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-110","alert_type":396,"serial_number":"AV25-110","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6153,"title":"[Control systems] CISA ICS security advisories (AV25\u2013111)","uuid":"87249fc8-9994-4e52-900c-9b5d9823afa3","banner":null,"lang":"en","date_modified":"2025-03-03","date_modified_ts":"2025-03-03T21:14:45Z","date_created":"2025-03-03T21:07:50Z","summary":null,"body":["<article data-history-node-id=\"6153\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-111\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-111<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 3, 2025<\/p>\n\n<p>Between February 24 and March 2, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dario Health Dario Application Database and Internet-based Server Infrastructure\u00a0\u2013 all versions<\/li>\n\t<li>Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Applications\u00a0\u2013 version 5.8.7.0.36 and prior<\/li>\n\t<li>Rockwell Automation PowerFlex 755\u00a0\u2013 version 16.002.279 and prior<\/li>\n\t<li>Schneider Electric Modicon M580 communication modules BMECRA BMECRA31210\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon M580 communication modules BMENOC BMENOC0321\u00a0\u2013 versions prior to SV1.10<\/li>\n\t<li>Schneider Electric Modicon M580\/Quantum communication modules BMXCRA BMXCRA31200\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon M580\/Quantum communication modules BMXCRA BMXCRA31210\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Quantum communication modules 140CRA 140CRA31200\u00a0\u2013 all version<\/li>\n\t<li>Schneider Electric Modicon Quantum communication modules 140CRA 140CRA31908\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-111","alert_type":398,"serial_number":"AV25-111","subject":null,"moderation_state":"published","external_url":null},{"nid":6154,"title":"Qualcomm security advisory \u2013 March 2025 monthly rollup (AV25-112)","uuid":"4da744dc-741d-464f-8a05-2aaf6aac940b","banner":null,"lang":"en","date_modified":"2025-03-03","date_modified_ts":"2025-03-03T21:21:32Z","date_created":"2025-03-03T21:16:55Z","summary":null,"body":["<article data-history-node-id=\"6154\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-march-2025-monthly-rollup-av25-112\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-112<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 3, 2025<\/p>\n\n<p>On March 3, 2025, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/march-2025-bulletin.html\">Qualcomm Security Bulletin \u2013 March<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-march-2025-monthly-rollup-av25-112","alert_type":396,"serial_number":"AV25-112","subject":"other","moderation_state":"published","external_url":null},{"nid":6155,"title":"Android security advisory \u2013 March 2025 monthly rollup (AV25-113)","uuid":"61a8e896-d1c2-42ac-9198-001ab959199b","banner":null,"lang":"en","date_modified":"2025-03-03","date_modified_ts":"2025-03-03T21:26:39Z","date_created":"2025-03-03T21:23:20Z","summary":null,"body":["<article data-history-node-id=\"6155\" about=\"\/en\/alerts-advisories\/android-security-advisory-march-2025-monthly-rollup-av25-113\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-113<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 3, 2025<\/p>\n\n<p>On March 3, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>Google has indicated that CVE-2024-43093 and CVE-2024-50302 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-03-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-march-2025-monthly-rollup-av25-113","alert_type":396,"serial_number":"AV25-113","subject":"android","moderation_state":"published","external_url":null},{"nid":6156,"title":"VMware security advisory (AV25-114)","uuid":"36a81004-cf42-4d05-892b-9c524a4f6128","banner":null,"lang":"en","date_modified":"2025-03-04","date_modified_ts":"2025-03-04T14:04:31Z","date_created":"2025-03-04T13:58:50Z","summary":null,"body":["<article data-history-node-id=\"6156\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-114\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-114<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 4, 2025<\/p>\n\n<p>On March 4, 2025, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware ESXi \u2013 versions 8.0 and 7.0<\/li>\n\t<li>VMware Workstation \u2013 version 17.x<\/li>\n\t<li>VMware Fusion \u2013 version 13.x<\/li>\n\t<li>VMware Cloud Foundation \u2013 versions 5.x and 4.5.x<\/li>\n\t<li>VMware Telco Cloud Platform \u2013 versions 5.x, 4.x, 3.x, 2.x<\/li>\n\t<li>VMware Telco Cloud Infrastructure \u2013 versions 3.x, 2.x<\/li>\n<\/ul><p>VMware is aware that an exploit for CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25390 \">VMSA-2025-0004: VMware ESXi, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-114","alert_type":396,"serial_number":"AV25-114","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6157,"title":"Mozilla security advisory (AV25-115)","uuid":"35b7983e-b23e-4190-b118-233d3fbe7fc2","banner":null,"lang":"en","date_modified":"2025-03-04","date_modified_ts":"2025-03-04T16:08:17Z","date_created":"2025-03-04T16:03:19Z","summary":null,"body":["<article data-history-node-id=\"6157\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-115\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-115<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 4, 2025<\/p>\n\n<p>On March 4, 2025, Mozilla published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR \u2013 versions prior to 128.8<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.21<\/li>\n\t<li>Firefox \u2013 versions prior to 136<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-16\/\">Mozilla Security Advisory (MFSA 2025-16)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-15\/\">Mozilla Security Advisory (MFSA 2025-15)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-14\/\">Mozilla Security Advisory (MFSA 2025-14)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/ \">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-115","alert_type":396,"serial_number":"AV25-115","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6158,"title":"Google Chrome security advisory (AV25-116)","uuid":"dc61baf8-bbbd-41d9-a0eb-5f61f6ee3230","banner":null,"lang":"en","date_modified":"2025-03-05","date_modified_ts":"2025-03-05T13:49:45Z","date_created":"2025-03-05T13:46:28Z","summary":null,"body":["<article data-history-node-id=\"6158\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-116\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-116<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 5, 2025<\/p>\n\n<p>On March 4, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 134.0.6998.35\/36 (Windows), 134.0.6998.44\/45 (Mac) and 134.0.6998.35 (Linux)<\/li>\n\t<li>Extended Stable Channel \u2013 versions prior to 134.0.6998.36 (Windows) and 134.0.6998.45 (Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/03\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-116","alert_type":396,"serial_number":"AV25-116","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6166,"title":"[Control systems] CISA ICS security advisories (AV25\u2013117) ","uuid":"d1171f68-f30f-4b5e-a4d9-7a133b12e05f","banner":null,"lang":"en","date_modified":"2025-03-10","date_modified_ts":"2025-03-10T15:36:19Z","date_created":"2025-03-10T15:35:40Z","summary":null,"body":["<article data-history-node-id=\"6166\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-117\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-117<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 10, 2025<\/p>\n\n<p>Between March 3 and 9, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Carrier Block Load \u2013 version 4.00 and versions v4.10 to 4.16<\/li>\n\t<li>Delta Electronics CNCSoft-G2 \u2013 versions V2.1.0.10 and prior<\/li>\n\t<li>Edimax IC-7100 IP Camera \u2013 all versions<\/li>\n\t<li>GMOD Apollo \u2013 versions prior to 2.8.0<\/li>\n\t<li>Hitachi Energy ECST \u2013 versions prior to 16.2.1<\/li>\n\t<li>Hitachi Energy MACH PS700 \u2013 version v2<\/li>\n\t<li>Hitachi Energy PCU400 \u2013 version 6.5K and prior and version 9.4.1 and prior<\/li>\n\t<li>Hitachi Energy PCULogger \u2013 version 1.1.0 and prior<\/li>\n\t<li>Hitachi Energy Relion 670, 650 and SAM600-IO series \u2013 multiple versions<\/li>\n\t<li>Hitachi Energy UNEM \u2013 multiple versions<\/li>\n\t<li>Hitachi Energy XMC20 \u2013 versions prior to R16B<\/li>\n\t<li>Keysight Ixia Vision Product Family \u2013 version 6.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-117","alert_type":398,"serial_number":"AV25-117","subject":"other","moderation_state":"published","external_url":null},{"nid":6167,"title":"Ubuntu security advisory (AV25-118)","uuid":"9367dc57-6d25-4260-9eee-1c6a7dc05dd0","banner":null,"lang":"en","date_modified":"2025-03-10","date_modified_ts":"2025-03-10T15:41:28Z","date_created":"2025-03-10T15:40:58Z","summary":null,"body":["<article data-history-node-id=\"6167\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-118\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-118<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 10, 2025<\/p>\n\n<p>Between March 3 and 9, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-118","alert_type":396,"serial_number":"AV25-118","subject":"other","moderation_state":"published","external_url":null},{"nid":6169,"title":"IBM security advisory (AV25-119)","uuid":"ec588f79-e0dd-4eb4-88b0-d5f05924c4f4","banner":null,"lang":"en","date_modified":"2025-03-10","date_modified_ts":"2025-03-10T15:47:07Z","date_created":"2025-03-10T15:46:40Z","summary":null,"body":["<article data-history-node-id=\"6169\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-119\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-119<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 10, 2025<\/p>\n\n<p>Between March 3 and 9, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>GSDC Platform On-prem \u2013 version 3.6.2<\/li>\n\t<li>IBM Aspera Shares \u2013 versions 1.9.9 to 1.10.0 PL7<\/li>\n\t<li>IBM Engineering Requirements Management DOORS Next \u2013 versions 7.0.2, 7.0.3 and 7.1<\/li>\n\t<li>IBM Instana Observability \u2013 build 1.0.287<\/li>\n\t<li>ICP - Discovery \u2013 versions 4.0.0 to 4.8.7 and versions 5.0.0 to 5.1.0<\/li>\n\t<li>SPSS Collaboration and Deployment Services \u2013 version 8.5<\/li>\n\t<li>Watson Studio on Cloud Pak for Data \u2013 versions 4.0.0 to 4.8.6 and versions 5.0.0 to 5.0.3<\/li>\n\t<li>watsonx.data \u2013 version 2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-119","alert_type":396,"serial_number":"AV25-119","subject":"other","moderation_state":"published","external_url":null},{"nid":6170,"title":"Red Hat security advisory (AV25-120)","uuid":"a4fd2264-a7b6-4620-a852-7b60081a2370","banner":null,"lang":"en","date_modified":"2025-03-10","date_modified_ts":"2025-03-10T17:07:43Z","date_created":"2025-03-10T17:01:52Z","summary":null,"body":["<article data-history-node-id=\"6170\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-120\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-120<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 10, 2025<\/p>\n\n<p>Between March 3 and 9, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-120","alert_type":396,"serial_number":"AV25-120","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6171,"title":"Dell security advisory (AV25-121)","uuid":"e2a13e87-2382-4113-9a5f-73f732095368","banner":null,"lang":"en","date_modified":"2025-03-10","date_modified_ts":"2025-03-10T17:15:01Z","date_created":"2025-03-10T17:08:54Z","summary":null,"body":["<article data-history-node-id=\"6171\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-121\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-121<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 10, 2025<\/p>\n\n<p>Between March 3 and 9, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Data Protection Search \u2013 versions 19.6.0, 19.6.1, 19.6.2, 19.6.3, 19.6.4 and 19.6.5<\/li>\n\t<li>Dell Integrated Data Protection Appliance \u2013 version 2.7.8 and prior<\/li>\n\t<li>Dell Secure Connect Gateway - Appliance \u2013 version 5.26.00.20<\/li>\n\t<li>PowerStore 500T, 1000T, 1200 T, 3000T, 3200Q, 3200T, 5000T, 5200T, 7000T, 9000T and 9200T \u2013 versions prior to 4.0.1.2-2445526<\/li>\n\t<li>PowerStore 1000X, 3000X, 5000X, 7000X and 9000X \u2013 versions prior to ESXi70U3s-24585291<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-121","alert_type":396,"serial_number":"AV25-121","subject":"dell","moderation_state":"published","external_url":null},{"nid":6172,"title":"[Control Systems] Moxa security advisory (AV25-122)","uuid":"6f4054cc-3e23-4a79-a1b4-5738e7005bd4","banner":null,"lang":"en","date_modified":"2025-03-10","date_modified_ts":"2025-03-10T18:54:22Z","date_created":"2025-03-10T18:53:50Z","summary":null,"body":["<article data-history-node-id=\"6172\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av25-122\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-122<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 10, 2025<\/p>\n\n<p>On March 6, 2025, Moxa published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>PT-508 Series \u2013 firmware version 3.8 and prior<\/li>\n\t<li>PT-510 Series \u2013 firmware version 3.8 and prior<\/li>\n\t<li>PT-7528 Series \u2013 firmware version 5.0 and prior<\/li>\n\t<li>PT-7728 Series \u2013 firmware version 3.9 and prior<\/li>\n\t<li>PT-7828 Series \u2013 firmware version 4.0 and prior<\/li>\n\t<li>PT-G503 Series \u2013 firmware version 5.3 and prior<\/li>\n\t<li>PT-G510 Series \u2013 firmware version 6.5 and prior<\/li>\n\t<li>PT-G7728 Series \u2013 firmware version 6.5 and prior<\/li>\n\t<li>PT-G7828 Series \u2013 firmware version 6.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches\">Moxa Security Advisory - MPSA-241408 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av25-122","alert_type":398,"serial_number":"AV25-122","subject":"other","moderation_state":"published","external_url":null},{"nid":6173,"title":"[Control systems] Siemens security advisory (AV25-123) ","uuid":"14431101-e5ab-46ab-93e6-45f2ddc344d5","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T13:00:00Z","date_created":"2025-03-11T13:00:02Z","summary":null,"body":["<article data-history-node-id=\"6173\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-123\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-123<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 11, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Industrial Edge for Machine Tools \u2013 all versions<\/li>\n\t<li>SCALANCE LPE9403 \u2013 versions prior to V4.0<\/li>\n\t<li>SCALANCE M-800 family \u2013 multiple platforms, versions prior to V8.2.1<\/li>\n\t<li>SCALANCE SC-600 family \u2013 all versions<\/li>\n\t<li>SIMATIC BRAUMAT \u2013 versions V8.0 SP1 to versions prior to V8.1<\/li>\n\t<li>SIMATIC Energy Manager PRO \u2013 multiple versions<\/li>\n\t<li>SIMATIC Field PG \u2013 all versions<\/li>\n\t<li>SIMATIC IPC family \u2013 multiple versions<\/li>\n\t<li>SIMATIC IPC DiagMonitor \u2013 all versions<\/li>\n\t<li>SIMATIC ITP1000 \u2013 all versions<\/li>\n\t<li>SIMATIC S7-1500 TM MFP - BIOS \u2013 all versions<\/li>\n\t<li>SIMATIC SISTAR \u2013 versions V8.0 SP1 to versions prior to V8.1<\/li>\n\t<li>SIMATIC WinCC V8.0 \u2013 versions prior to V8.0 Update 3<\/li>\n\t<li>SIMIT V11 \u2013 all versions<\/li>\n\t<li>SINAMICS S200 \u2013 multiple versions<\/li>\n\t<li>SINEMA Remote Connect Server \u2013 versions prior to V3.2 SP3<\/li>\n\t<li>SINEMA Remote Connect Client \u2013 versions prior to V3.2 AP3<\/li>\n\t<li>SiPass integrated AC5102 and ACC-AP \u2013 versions prior to 6.4.8<\/li>\n\t<li>Teamcenter Visualization \u2013 multiple versions<\/li>\n\t<li>Tecnomatic Plant Simulation \u2013 multiple versions<\/li>\n\t<li>Totally Integrated Automation Portal \u2013 versions V18 and V19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-123","alert_type":398,"serial_number":"AV25-123","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6175,"title":"Google Chrome security advisory (AV25-124)","uuid":"ee069fbf-a73b-4cb7-9d98-6822ecebb004","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T14:05:50Z","date_created":"2025-03-11T14:05:44Z","summary":null,"body":["<article data-history-node-id=\"6175\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-124\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-124<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 10, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable channel Chrome for desktop \u2013 versions prior to 134.0.6998.88\/89 (Windows and Mac) and 134.0.6998.88 (Linux)<\/li>\n\t<li>Extended stable channel \u2013 versions prior to 134.0.6998.89 (Windows and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/03\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-124","alert_type":396,"serial_number":"AV25-124","subject":null,"moderation_state":"published","external_url":null},{"nid":6174,"title":"[Control systems] Schneider Electric security advisory (AV25-125) ","uuid":"47167628-24f2-4798-b5fa-b745dccc36a7","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T14:28:27Z","date_created":"2025-03-11T14:28:04Z","summary":null,"body":["<article data-history-node-id=\"6174\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-125\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-125<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 11, 2025, Schneider Electric published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>EcoStruxure Panel Server \u2013 version v2.0 and prior<\/li>\n\t<li>EcoStruxure Power Automation System User Interface (EPAS-UI) - Secured Versions \u2013 versions v2.1 to v2.9<\/li>\n\t<li>WebHMI \u2013 version v4.1.0.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-125","alert_type":398,"serial_number":"AV25-125","subject":null,"moderation_state":"published","external_url":null},{"nid":6176,"title":"SAP security advisory \u2013 March 2025 monthly rollup (AV25-126)","uuid":"bb433ce2-2f27-455c-be2b-c52b640c7554","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T15:31:25Z","date_created":"2025-03-11T15:26:16Z","summary":null,"body":["<article data-history-node-id=\"6176\" about=\"\/en\/alerts-advisories\/sap-security-advisory-march-2025-monthly-rollup-av25-126\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-126<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 11, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Commerce Cloud \u2013 versions HY-COM 2205 and COM-CLOUD 2211<\/li>\n\t<li>SAP Commerce (Swagger UI) \u2013 version COM_CLOUD 2211<\/li>\n\t<li>SAP NetWeaver (ABAP Class Builder) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/march-2025.html\">SAP Security Patch Day \u2013 March 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-march-2025-monthly-rollup-av25-126","alert_type":396,"serial_number":"AV25-126","subject":"sap","moderation_state":"published","external_url":null},{"nid":6177,"title":"Apache Tomcat security advisory (AV25-127)","uuid":"b0c0bd4e-8071-4c54-bccd-05496829c052","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T15:37:31Z","date_created":"2025-03-11T15:33:22Z","summary":null,"body":["<article data-history-node-id=\"6177\" about=\"\/en\/alerts-advisories\/control-systems-apache-tomcat-security-advisory-av25-127\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-127<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 10, 2025, Apache published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Apache Tomcat \u2013 versions 11.0.0-M1 to 11.0.2<\/li>\n\t<li>Apache Tomcat \u2013 versions 10.1.0-M1 to 10.1.34<\/li>\n\t<li>Apache Tomcat \u2013 versions 9.0.0.M1 to 9.0.98<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/j5fkjv2k477os90nczf2v9l61fb0kkgq\">Apache Security Advisory - [SECURITY] CVE-2025-24813 Potential RCE and\/or information disclosure and\/or information corruption with partial PUT<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-apache-tomcat-security-advisory-av25-127","alert_type":396,"serial_number":"AV25-127","subject":"other","moderation_state":"published","external_url":null},{"nid":6178,"title":"Ivanti security advisory (AV25-128)","uuid":"1c9bb190-1bd0-47ae-becf-a96c3e4587aa","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T16:53:02Z","date_created":"2025-03-11T16:52:34Z","summary":null,"body":["<article data-history-node-id=\"6178\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-128\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-128<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 11, 2025, Ivanti published security advisories to address vulnerabilities in multiple products. Included was an update for the following product:<\/p>\n\n<ul><li>Ivanti Secure Access Client (ISAC) \u2013 version 22.7R3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/March-Security-Advisory-Ivanti-Secure-Access-Client-ISAC-CVE-2025-22454?language=en_US\">Ivanti Security Advisory - March security advisory Ivanti Secure Access Client (ISAC) (CVE-2025-22454)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-128","alert_type":396,"serial_number":"AV25-128","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6179,"title":"Fortinet security advisory (AV25-129)","uuid":"f14aff48-ef42-4c0b-9d0f-ab2083099d67","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T17:00:15Z","date_created":"2025-03-11T16:57:54Z","summary":null,"body":["<article data-history-node-id=\"6179\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-129\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV25-129<br \/><!-- DATES Pick one update the day xx, delete the rest --><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 11, 2025, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiADC \u2013 multiple versions<\/li>\n\t<li>FortiIsolator 2.4 \u2013 versions 2.4.0 to 2.4.5<\/li>\n\t<li>FortiSandbox \u2013 multiple versions<\/li>\n\t<li>FortiSIEM \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li>\n\t<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-117\">Fortinet PSIRT \u2013 FG-IR-23-117<\/a><\/li>\n\t\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-178\">Fortinet PSIRT \u2013 FG-IR-24-178<\/a><\/li>\n\t\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-216\">Fortinet PSIRT \u2013 FG-IR-23-216<\/a><\/li>\n\t\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-306\">Fortinet PSIRT \u2013 FG-IR-24-306<\/a><\/li>\n\t\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-327\">Fortinet PSIRT \u2013 FG-IR-24-327<\/a><\/li>\n\t\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<\/ul><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-129","alert_type":396,"serial_number":"AV25-129","subject":null,"moderation_state":"published","external_url":null},{"nid":6181,"title":"Microsoft security advisory \u2013 March 2025 monthly rollup (AV25\u2013130)","uuid":"eaa39ea3-179e-46b2-b7d0-2b57516f1b53","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T18:20:47Z","date_created":"2025-03-11T18:14:46Z","summary":null,"body":["<article data-history-node-id=\"6181\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-march-2025-monthly-rollup-av25-130\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-130<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 11, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps \u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Office \u2013 multiple versions and platforms<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows App Client for Windows Desktop<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993 and CVE-2025-26633 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Mar\">March 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-march-2025-monthly-rollup-av25-130","alert_type":396,"serial_number":"AV25-130","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6180,"title":"Adobe security advisory (AV25\u2013131)","uuid":"9d354156-6be2-486a-89e7-b17381fbcfe6","banner":null,"lang":"en","date_modified":"2025-03-11","date_modified_ts":"2025-03-11T18:37:20Z","date_created":"2025-03-11T18:37:02Z","summary":null,"body":["<article data-history-node-id=\"6180\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-131\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-131<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 11, 2025<\/p>\n\n<p>On March 11, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat 2024 \u2013 version 24.001.30225 and prior<\/li>\n\t<li>Acrobat 2020 \u2013 version 20.005.30748 and prior<\/li>\n\t<li>Acrobat Reader 2020 \u2013 version 20.005.30748 and prior<\/li>\n\t<li>Acrobat DC \u2013 version 25.001.20428 and prior<\/li>\n\t<li>Acrobat Reader DC \u2013 version 25.001.20428 and prior<\/li>\n\t<li>Adobe Illustrator 2024 \u2013 version 28.7.4 and prior<\/li>\n\t<li>Adobe Illustrator 2025 \u2013 version 29.2.1 and prior<\/li>\n\t<li>Adobe InDesign \u2013 version ID19.5.2 and prior, version ID20.1 and prior<\/li>\n\t<li>Adobe Substance 3D Designer \u2013 version 14.1 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler \u2013 version 1.15 and prior<\/li>\n\t<li>Adobe Substance 3D Painter \u2013 version 10.1.2 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler \u2013 version 4.5.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-131","alert_type":396,"serial_number":"AV25-131","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6183,"title":"HPE security advisory (AV25-132)","uuid":"ca1cecb6-cf63-4722-8097-1f467c96b902","banner":null,"lang":"en","date_modified":"2025-03-12","date_modified_ts":"2025-03-12T15:50:48Z","date_created":"2025-03-12T15:39:25Z","summary":null,"body":["<article data-history-node-id=\"6183\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-132\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-132<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 12, 2025<\/p>\n\n<p>On March 11, 2025, HPE published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following product::<\/p>\n\n<ul><li>HPE Cray XD670\u00a0\u2013 versions prior to BMC v1.19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04828en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04828<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-132","alert_type":396,"serial_number":"AV25-132","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6184,"title":"Apple security advisory (AV25-133)","uuid":"f530c60a-4be3-483a-b62c-dd1dc104a76f","banner":null,"lang":"en","date_modified":"2025-03-12","date_modified_ts":"2025-03-12T15:59:29Z","date_created":"2025-03-12T15:53:15Z","summary":null,"body":["<article data-history-node-id=\"6184\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-133\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-133<br \/><strong>Date: <\/strong>March\u00a012, 2025<\/p>\n\n<p>On March\u00a011, 2025, Apple published security updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.3.2<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.3.2<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 18.3.1<\/li>\n<\/ul><p>Apple has indicated that CVE-2025-24201 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided Web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/122281\">Apple security update\u00a0- iOS 18.3.2 and iPadOS 18.3.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/122283\">Apple security update\u00a0- macOS Sequoia 15.3.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/122285\">Apple security update\u00a0- Safari 18.3.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-133","alert_type":396,"serial_number":"AV25-133","subject":"apple","moderation_state":"published","external_url":null},{"nid":6186,"title":"Microsoft Edge security advisory (AV25-134)","uuid":"8561ed8d-2b84-47b5-8c26-33fe31de0aa3","banner":null,"lang":"en","date_modified":"2025-03-12","date_modified_ts":"2025-03-12T19:42:52Z","date_created":"2025-03-12T19:31:48Z","summary":null,"body":["<article data-history-node-id=\"6186\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-134\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-134<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 12, 2025<\/p>\n\n<p>On March 11 and 12, 2025, Microsoft published security updates to address vulnerabilities in the following product::<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 134.0.3124.66<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2025-24201 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-11-2025\">Microsoft Edge Extended Stable Channel Release Notes\u00a0- March 11, 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-12-2025\">Microsoft Edge Extended Stable Channel Release Notes\u00a0- March 12, 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-134","alert_type":396,"serial_number":"AV25-134","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6185,"title":"Palo Alto Networks security advisory (AV25-136)","uuid":"0e1f7442-5ecb-4da2-9ea9-8a510230dfe8","banner":null,"lang":"en","date_modified":"2025-03-12","date_modified_ts":"2025-03-12T20:12:22Z","date_created":"2025-03-12T19:34:14Z","summary":null,"body":["<article data-history-node-id=\"6185\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-136\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-136<br \/><strong>Date: <\/strong>March\u00a012, 2025<\/p>\n\n<p>On March\u00a012, 2025, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Prisma Access Browser\u00a0\u2013 versions prior to 133.16.4.99<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0007\">Palo Alto Networks Security Advisories\u00a0- PAN-SA-2025-0007<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-136","alert_type":396,"serial_number":"AV25-136","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6187,"title":"[Control systems] ABB security advisory (AV25-135) ","uuid":"fc08661e-79b3-4a1e-bbf9-cc46fd2c7606","banner":null,"lang":"en","date_modified":"2025-03-12","date_modified_ts":"2025-03-12T19:53:34Z","date_created":"2025-03-12T19:45:41Z","summary":null,"body":["<article data-history-node-id=\"6187\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-135\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-135<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 12, 2025<\/p>\n\n<p>On March 11, 2025, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>RMC-100\u00a0\u2013 versions 2105457 to 2105457-044<\/li>\n\t<li>RMC-100 LITE\u00a0\u2013 versions 2106229-010 to 2106229-016<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108470A8565&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Cyber Security Advisory\u00a0- Vulnerability in the Web UI (REST Interface) RMC-100 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-135","alert_type":398,"serial_number":"AV25-135","subject":"abb","moderation_state":"published","external_url":null},{"nid":6188,"title":"Mass Exploitation of Critical PHP-CGI Vulnerability (CVE-2024-4577)","uuid":"852992be-8344-4d99-84f5-f0b26d349a07","banner":null,"lang":"en","date_modified":"2025-03-12","date_modified_ts":"2025-03-12T21:31:33Z","date_created":"2025-03-12T21:17:58Z","summary":null,"body":["<article data-history-node-id=\"6188\" about=\"\/en\/alerts-advisories\/al25-001-mass-exploitation-critical-php-cgi-vulnerability-cve-2024-4577\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL25-001<br \/><strong>Date: <\/strong>March 12, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of reports of ongoing and increased exploitation of <span class=\"nowrap\">CVE-2024-4577 <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/span>, a critical remote code execution (RCE) vulnerability in the PHP-CGI implementation of PHP on Windows.<\/p>\n\n<p>Windows-based PHP installations configured to use PHP-CGI are specifically at risk as the vulnerability exploits Unicode processing in the CGI module.<\/p>\n\n<p>Threat actors are actively using this vulnerability. The Cyber Centre is not aware of any Canadian victims from this increased activity, but systems in Canada remain vulnerable despite the exploit proof-of-concept being available since June 2024.<\/p>\n\n<h2>Suggested Actions<\/h2>\n\n<p>Organizations should determine if they are at risk by verifying whether they are running vulnerable versions of PHP installed on Windows.<\/p>\n\n<p>Organizations are advised to update to the following versions of PHP<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>:<\/p>\n\n<ul><li>PHP 8.3 - update to 8.3.8 or later<\/li>\n\t<li>PHP 8.2 - update to 8.2.20 or later<\/li>\n\t<li>PHP 8.1 - update to 8.1.29 or later<\/li>\n<\/ul><p>Organizations should also review and implement the Cyber Centre\u2019s Top 10 IT Security <span class=\"nowrap\">Actions <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/span> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t<li>Patching operating systems and applications.<\/li>\n\t<li>Isolate web-facing applications.<\/li>\n<\/ul><p>Determine if associated malicious activity has occurred in potentially vulnerable systems. Should this be the case, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>Partner Reporting<\/h2>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cert.govt.nz\/advisories\/vulnerability-affecting-php-windows\/\">NCSC NZ \u2013 Vulnerability affecting PHP on Windows<\/a><\/li>\n<\/ul><p>Information provided by organizations not subject to the <i>Official Languages Act<\/i> is in the language(s) provided.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.greynoise.io\/blog\/mass-exploitation-critical-php-cgi-vulnerability-cve-2024-4577\">GreyNoise Detects Mass Exploitation of Critical PHP-CGI Vulnerability (CVE-2024-4577), Signaling Broad Campaign<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/blog.talosintelligence.com\/new-persistent-attacks-japan\/\">Unmasking the new persistent attacks on Japan<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/ciso2ciso.com\/experts-warn-of-mass-exploitation-of-critical-php-flaw-cve-2024-4577-source-securityaffairs-com\/\">Experts warn of mass exploitation of critical PHP flaw CVE-2024-4577<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.php.net\/ChangeLog-8.php\">CVE-2024-4577 - Primary and the most effective mitigation is to upgrade PHP to the latest versions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089) <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-001-mass-exploitation-critical-php-cgi-vulnerability-cve-2024-4577","alert_type":397,"serial_number":"AL25-001","subject":"other","moderation_state":"published","external_url":null},{"nid":6189,"title":"GitLab security advisory (AV25-137)","uuid":"18f80b40-c760-49e3-8fa9-061f63ca2bdb","banner":null,"lang":"en","date_modified":"2025-03-13","date_modified_ts":"2025-03-13T14:15:12Z","date_created":"2025-03-13T13:36:37Z","summary":null,"body":["<article data-history-node-id=\"6189\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-137\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-137<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 13, 2025<\/p>\n\n<p>On March 12, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.9.2, 17.8.5 and 17.7.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.9.2, 17.8.5 and 17.7.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/03\/12\/patch-release-gitlab-17-9-2-released\/\">GitLab Critical Patch Release: 17.9.2, 17.8.5, 17.7.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-137","alert_type":396,"serial_number":"AV25-137","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6191,"title":"[Control systems] Siemens security advisory (AV25-139)","uuid":"cac5c96c-603e-458b-b760-8da82b62bb4a","banner":null,"lang":"en","date_modified":"2025-03-13","date_modified_ts":"2025-03-13T14:47:33Z","date_created":"2025-03-13T13:46:44Z","summary":"On March\u00a013, 2025, Siemens published an advisory to address a vulnerability in the following product:\n\nSimcenter Femap V2401\u00a0\u2013 versions prior to V2401.0003\nSimcenter Femap V2406\u00a0\u2013 versions prior to V2406.0002\nThe Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.","body":["<article data-history-node-id=\"6191\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-139\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-139<br \/><strong>Date: <\/strong>March\u00a013, 2025<\/p>\n\n<p>On March\u00a013, 2025, Siemens published an advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Simcenter Femap V2401\u00a0\u2013 versions prior to V2401.0003<\/li>\n\t<li>Simcenter Femap V2406\u00a0\u2013 versions prior to V2406.0002<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-920092.html?ste_sid=53dc3f3a47a35738e8b0527554f65fce\">Siemens Security Advisory\u00a0- SSA-920092<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-139","alert_type":398,"serial_number":"AV25-139","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6190,"title":"HPE security advisory (AV25-138)","uuid":"6fb786d1-bb7a-4132-a760-7359b463a223","banner":null,"lang":"en","date_modified":"2025-03-13","date_modified_ts":"2025-03-13T14:42:09Z","date_created":"2025-03-13T14:18:46Z","summary":null,"body":["<article data-history-node-id=\"6190\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-138\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-138<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 13, 2025<\/p>\n\n<p>On March 12, 2025, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>HPE Cray EX235a Accelerator Blade\u00a0\u2013 versions prior to v2.1.0 (HFP 25.1.2)<\/li>\n\t<li>HPE Cray EX235n Server\u00a0\u2013 versions prior to v1.5.1 (HFP 24.10.1)<\/li>\n\t<li>HPE Cray EX255a Accelerator Blade\u00a0\u2013 versions prior to v1.4.0 (HFP 25.1.2)<\/li>\n\t<li>HPE Cray EX425 Compute Blade\u00a0\u2013 versions prior to v1.7.6 (HFP 24.10.1)<\/li>\n\t<li>HPE Cray EX4252 Compute Blade\u00a0\u2013 versions prior to v2.0.1 (HFP 25.1.2)<\/li>\n\t<li>HPE ProLiant XL225n Gen10 Plus 1U Node\u00a0\u2013 versions prior to v3.60_01-16-2025<\/li>\n\t<li>HPE ProLiant XL645d Gen10 Plus Server\u00a0\u2013 versions prior to v3.40_10-04-2024 (HFP 24.11.0)<\/li>\n\t<li>HPE ProLiant XL675d Gen10 Plus Server\u00a0\u2013 versions prior to v3.40_10-04-2024 (HFP 24.11.0)<\/li>\n\t<li>HPE Cray XD665\u00a0\u2013 versions prior to v1.50 On the Portal HPE Cray SC XD665 Firmware Pack 2024.09.00<\/li>\n\t<li>HPE Cray XD675\u00a0\u2013 versions prior to v3.1.5 (HPE Cray SC XD665 Firmware Pack 2024.09.00)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04827en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbcr04827<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-138","alert_type":396,"serial_number":"AV25-138","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6193,"title":"Cisco security advisory (AV25-140)","uuid":"41506226-9776-4f90-b1a6-a9680986d133","banner":null,"lang":"en","date_modified":"2025-03-13","date_modified_ts":"2025-03-13T18:39:32Z","date_created":"2025-03-13T18:25:58Z","summary":null,"body":["<article data-history-node-id=\"6193\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-140\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-140<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 13, 2025<\/p>\n\n<p>On March 12, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following product:<\/p>\n\n<ul><li>Cisco IOS XR\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories [Vulnerabilities on March 12, 2025 with medium and high severity and CVSS of 4.0+]<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-140","alert_type":396,"serial_number":"AV25-140","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6194,"title":"VMware security advisory (AV25-141)","uuid":"11714979-3b92-4bd4-ba7a-ac03889517ad","banner":null,"lang":"en","date_modified":"2025-03-14","date_modified_ts":"2025-03-14T14:05:18Z","date_created":"2025-03-14T13:36:46Z","summary":null,"body":["<article data-history-node-id=\"6194\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-141\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-141<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 14, 2025<\/p>\n\n<p>On March 13, 2025, VMware released a security advisory to address vulnerabilities in multiple products. Included was a critical update for the following product:<\/p>\n\n<ul><li>VMware Tanzu GemFire\u00a0\u2013 versions prior to 10.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25506\">VMware Security Advisory - Product Version Release Advisory VMware Tanzu GemFire 10.0.6<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-141","alert_type":396,"serial_number":"AV25-141","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6195,"title":"Juniper Networks security advisory (AV25-142)","uuid":"308b6ae7-9fc0-4a8b-9652-4d80d072b3ed","banner":null,"lang":"en","date_modified":"2025-03-14","date_modified_ts":"2025-03-14T14:31:59Z","date_created":"2025-03-14T14:09:57Z","summary":null,"body":["<article data-history-node-id=\"6195\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-142\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-142<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 14, 2025<\/p>\n\n<p>On March 12, 2025, Juniper Networks published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>JunoOS\u00a0\u2013 versions prior to 21.2R3-S9<\/li>\n\t<li>JunoOS 21.4\u00a0\u2013 versions prior to 21.4R3-S10<\/li>\n\t<li>JunoOS 22.2\u00a0\u2013 versions prior to 22.2R3-S6<\/li>\n\t<li>JunoOS 22.4\u00a0\u2013 versions prior to 22.4R3-S6<\/li>\n\t<li>JunoOS 23.2\u00a0\u2013 versions prior to 23.2R2-S3<\/li>\n\t<li>JunoOS 23.4\u00a0\u2013 versions prior to 23.4R2-S4<\/li>\n\t<li>JunoOS 24.2\u00a0\u2013 versions prior to 24.2R1-S2, 24.2R2<\/li>\n<\/ul><p>Juniper has received reports that CVE-2025-21590 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US\">Juniper Networks Security\u00a0- JSA93446<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-142","alert_type":396,"serial_number":"AV25-142","subject":"juniper","moderation_state":"published","external_url":null},{"nid":6197,"title":"IBM security advisory (AV25-143)","uuid":"e133f694-c2f2-4462-b775-37f4af090046","banner":null,"lang":"en","date_modified":"2025-03-17","date_modified_ts":"2025-03-17T13:12:54Z","date_created":"2025-03-17T13:05:30Z","summary":null,"body":["<article data-history-node-id=\"6197\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-143\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-143<br \/><strong>Date: <\/strong>March\u00a017, 2025<\/p>\n\n<p>Between March\u00a010 and 16, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM API Connect\u00a0\u2013 versions V10.0.5.0 to V10.0.5.8 and V10.0.8.0 to 10.0.8.1<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\u00a0\u2013 CD: 12.0.7.0-r4 to 12.0.12.5-r1, 13.0.1.0-r1 to 13.0.2.0-r1<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\u00a0\u2013 12.0 LTS: 12.0.12-r1 to 12.0.12-r7<\/li>\n\t<li>IBM App Connect Operator\u00a0\u2013 CD: 7.2.0-11.6.0, 12.1.0 to 12.7.0<\/li>\n\t<li>IBM App Connect Operator\u00a0\u2013 12.0 LTS: 12.0.0 to 12.0.7<\/li>\n\t<li>IBM DataStage on Cloud Pak for Data\u00a0\u2013 version 4.8.4<\/li>\n\t<li>IBM Jazz Foundation\u00a0\u2013 version 7.0.2<\/li>\n\t<li>IBM Netcool Operations Insight\u00a0\u2013 versions 1.4 to 1.4.12, 1.5 to 1.5.0.1 and 1.6 to 1.6.13<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 versions 1.0.287 to 1.0.290<\/li>\n\t<li>IBM Qiskit SDK\u00a0\u2013 versions 0.18.0 to 1.4.1<\/li>\n\t<li>IBM Total Storage Service Console (TSSC)\u00a0\/\u00a0TS4500 IMC\u00a0\u2013 versions 9.4.14, 9.4.21, 9.4.26, 9.4.31, 9.5.8, 9.6.10 and 9.6.15<\/li>\n\t<li>IBM watsonx Assistant Cartridge\u00a0\u2013 versions 4.0 to 5.1.0<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge\u00a0- Assistant Builder Component\u00a0\u2013 versions 5.0 to 5.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-143","alert_type":396,"serial_number":"AV25-143","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6198,"title":"Red Hat security advisory (AV25-144)","uuid":"1ecbffeb-98a6-4f7f-8837-ef0b6b30df9d","banner":null,"lang":"en","date_modified":"2025-03-17","date_modified_ts":"2025-03-17T13:16:30Z","date_created":"2025-03-17T13:05:30Z","summary":null,"body":["<article data-history-node-id=\"6198\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-144\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-144<br \/><strong>Date: <\/strong>March\u00a017, 2025<\/p>\n\n<p>Between March\u00a010 and 16, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-144","alert_type":396,"serial_number":"AV25-144","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6199,"title":"Ubuntu security advisory (AV25-145)","uuid":"1d3a4337-a5e0-40c1-b9ad-d1f36d28220e","banner":null,"lang":"en","date_modified":"2025-03-17","date_modified_ts":"2025-03-17T14:28:23Z","date_created":"2025-03-17T14:17:19Z","summary":null,"body":["<article data-history-node-id=\"6199\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-145\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-145<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 17, 2025<\/p>\n\n<p>Between March 10 and 16, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 14.04 ESM<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 16.04 ESM<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 18.04 ESM<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 20.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 22.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-145","alert_type":396,"serial_number":"AV25-145","subject":"other","moderation_state":"published","external_url":null},{"nid":6200,"title":"[Control systems] CISA ICS security advisories (AV25\u2013146)","uuid":"1fd7fc96-14b4-463b-b097-cac6be0d80b8","banner":null,"lang":"en","date_modified":"2025-03-17","date_modified_ts":"2025-03-17T15:43:14Z","date_created":"2025-03-17T15:22:57Z","summary":null,"body":["<article data-history-node-id=\"6200\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-146\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-146<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 17, 2025<\/p>\n\n<p>Between March 10 and 16, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Optigo Visual BACnet Capture Tool\u00a0\u2013 version 3.1.2rc11<\/li>\n\t<li>Optigo Visual Networks Capture Tool\u00a0\u2013 version 3.1.2rc11<\/li>\n\t<li>Phillips Intellispace Cardiovascular (ISCV)\u00a0\u2013 versions prior to 4.1 and versions prior to 5.1<\/li>\n\t<li>Schneider Electric Uni-Telway Driver\u00a0\u2013 multiple models and all versions<\/li>\n\t<li>Siemens BRAUMAT\u00a0\u2013 all versions from V8.0 SPU but not including V8.1<\/li>\n\t<li>Siemens Energy Manager Pro\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Industrial Edge for Machine Tools\u00a0\u2013 all versions<\/li>\n\t<li>Siemens IPC DiagMonitor\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Remote Connect Server\u00a0\u2013 versions prior to V3.2 SP3<\/li>\n\t<li>Siemens RUGGEDCOM RM1224 LTE(4G)\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SCALANCE\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SIMATIC Field PGs\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SIMATIC IPC\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SIMATIC ITP1000\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SIMATIC S7-1500 TM MFP\u00a0- BIOS\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMIT V11\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINAMICS S200\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINEMA Remove Connect Client\u00a0\u2013 versions prior to V3.2 SP3<\/li>\n\t<li>Siemens SISTAR\u00a0\u2013 all versions from V8.0 SPU but not including V8.1<\/li>\n\t<li>Siemens SiPass integrated AC5102 (ACC-G2)\u00a0\u2013 multiple models and all versions<\/li>\n\t<li>Siemens Teamcenter Visualization\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens Tecnomatix Plant Simulation\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens WinCC Unified V18\u00a0\u2013 all versions<\/li>\n\t<li>Siemens WinCC Unified V19\u00a0\u2013 versions prior to V19 Update 4<\/li>\n\t<li>Sungrow iSolarCloud Android App\u00a0\u2013 versions prior to 2.1.6<\/li>\n\t<li>Sungrow WiNet Firmware\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-146","alert_type":398,"serial_number":"AV25-146","subject":"other","moderation_state":"published","external_url":null},{"nid":6201,"title":"Dell security advisory (AV25-147)","uuid":"cdce69f9-0220-4f86-b307-38f767507b58","banner":null,"lang":"en","date_modified":"2025-03-17","date_modified_ts":"2025-03-17T17:58:24Z","date_created":"2025-03-17T17:33:27Z","summary":null,"body":["<article data-history-node-id=\"6201\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-147\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-147<br \/><strong>Date: <\/strong>March\u00a017, 2025<\/p>\n\n<p>Between March 10 and\u00a016, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.01.02.00<\/li>\n\t<li>Dell Cloud Tiering Appliance CTA and CTA-HA\u00a0\u2013 versions prior to 13.2.0.2.33<\/li>\n\t<li>Dell Cloud Tiering Appliance CTA\/VE and CTA-HA\/VE\u00a0\u2013 versions prior to 13.2.0.2.33<\/li>\n\t<li>Dell Connectrix B-Series and SANnav\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Dell Integrated System for Microsoft Azure Stack HCI\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 version 10.5.5.x and 10.5.6.x<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-147","alert_type":396,"serial_number":"AV25-147","subject":"dell","moderation_state":"published","external_url":null},{"nid":6204,"title":"GitHub security advisory (AV25-148)","uuid":"6e1fac56-e07c-40da-a890-88cfed499f26","banner":null,"lang":"en","date_modified":"2025-03-19","date_modified_ts":"2025-03-19T13:07:49Z","date_created":"2025-03-19T13:02:40Z","summary":null,"body":["<article data-history-node-id=\"6204\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-148\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-148<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 19, 2025<\/p>\n\n<p>On March 15, 2025, GitHub published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>tj-actions\/changed-files GitHub Actions\u00a0\u2013 versions 45.07 and prior<\/li>\n<\/ul><p>On March 18, 2025, CISA added CVE-2025-30066 to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/advisories\/GHSA-mrrh-fwg8-r2c3\">GHSA-mrrh-fwg8-r2c3<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/03\/18\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">CISA\u00a0- Known Exploited Vulnerabilities Catalog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-148","alert_type":396,"serial_number":"AV25-148","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6205,"title":"Vulnerability impacting Apache Tomcat (CVE-2025-24813)","uuid":"4ac03ff8-2425-4c05-9b63-9f8e3dea9e13","banner":null,"lang":"en","date_modified":"2025-03-19","date_modified_ts":"2025-03-19T14:02:34Z","date_created":"2025-03-19T13:38:20Z","summary":null,"body":["<article data-history-node-id=\"6205\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-apache-tomcat-cve-2025-24813\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL25-002<br \/><strong>Date: <\/strong>March 19, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On March 10, 2025, Apache published a security advisory<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> regarding vulnerability (CVE-2025-24813) impacting the Apache Tomcat web server software in the following versions:<\/p>\n\n<ul><li>Apache Tomcat\u00a0\u2013 versions 11.0.0-M1 to 11.0.2<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 10.1.0-M1 to 10.1.34<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 9.0.0.M1 to 9.0.98<\/li>\n<\/ul><p>This vulnerability could allow a malicious actor to view or inject arbitrary content to security-sensitive files or achieve remote code execution. The exploit does not require authentication and is caused by Tomcat accepting partial PUT requests and its default session persistence<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/p>\n\n<p>Additionally, Apache states that the following conditions are required for a malicious actor to <strong>view or inject<\/strong> content into security sensitive files<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>writes enabled for the default servlet (disabled by default)<\/li>\n\t<li>support for partial PUT (enabled by default)<\/li>\n\t<li>a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads<\/li>\n\t<li>attacker knowledge of the names of security sensitive files being uploaded<\/li>\n\t<li>the security sensitive files also being uploaded via partial PUT<\/li>\n<\/ul><p>Apache also states that the following conditions are required for a malicious actor to achieve <strong>remote code execution<\/strong><sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>writes enabled for the default servlet (disabled by default)<\/li>\n\t<li>support for partial PUT (enabled by default)<\/li>\n\t<li>application was using Tomcat's file based session persistence with the default storage location<\/li>\n\t<li>application included a library that may be leveraged in a deserialization attack<\/li>\n<\/ul><p>In response to this advisory, the Cyber Centre released advisory AV25-127 on March 10<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<h2>Suggested Actions<\/h2>\n\n<p>Organizations should review their configurations in determining their risk. They should also verify if they are running any vulnerable versions of Apache Tomcat.<\/p>\n\n<p>Organizations are advised to update to the following versions of Apache Tomcat<sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>Apache Tomcat\u00a0\u2013 version 11.0.3 or later<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 version 10.1.35 or later<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 version 9.0.99 or later<\/li>\n<\/ul><p>Organizations should also review and implement the Cyber Centre\u2019s Top 10 IT Security Actions <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways.<\/li>\n\t<li>Patch operating systems and applications.<\/li>\n\t<li>Isolate web-facing applications.<\/li>\n\t<li>Harden operating systems and applications.<\/li>\n<\/ul><p>Determine if associated malicious activity has occurred in potentially vulnerable systems. Should this be the case, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/lists.apache.org\/thread\/j5fkjv2k477os90nczf2v9l61fb0kkgq\">Apache Security Advisory\u00a0- [SECURITY] CVE-2025-24813 Potential RCE and\/or information disclosure and\/or information corruption with partial PUT<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/critical-rce-flaw-in-apache-tomcat-actively-exploited-in-attacks\/\">Critical RCE flaw in Apache Tomcat actively exploited in attacks<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.theregister.com\/2025\/03\/18\/apache_tomcat_java_rce_flaw\/\">'Dead simple' hijacking hole in Apache Tomcat 'now actively exploited in the wild'<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/control-systems-apache-tomcat-security-advisory-av25-127\">Apache Tomcat security advisory (AV25-127)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-apache-tomcat-cve-2025-24813","alert_type":397,"serial_number":"AL25-002","subject":"other","moderation_state":"published","external_url":null},{"nid":6206,"title":"Jenkins security advisory (AV25-149)","uuid":"944f35ae-0531-4d91-a45c-11b6a90a541c","banner":null,"lang":"en","date_modified":"2025-03-19","date_modified_ts":"2025-03-19T19:34:46Z","date_created":"2025-03-19T19:17:41Z","summary":null,"body":["<article data-history-node-id=\"6206\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-149\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-149<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 19, 2025<\/p>\n\n<p>On March 19, 2025, Jenkins published a security advisory to address vulnerabilities in the following products::<\/p>\n\n<ul><li>AnchorChain Plugin\u00a0\u2013 version 1.0 and prior<\/li>\n\t<li>EDDSA API Plugin\u00a0\u2013 version 3.0-13.v7cb_69ed68f00 and prior<\/li>\n\t<li>Zoho QEngine Plugin\u00a0\u2013 version 0.29.vfa_cc23396502 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-03-19\/\">Jenkins Security Advisory 2025-03-19<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-149","alert_type":396,"serial_number":"AV25-149","subject":"other","moderation_state":"published","external_url":null},{"nid":6207,"title":"Veeam security advisory (AV25-150)","uuid":"3cabb2a8-babb-4f29-b3e7-f3916596fcc8","banner":null,"lang":"en","date_modified":"2025-03-19","date_modified_ts":"2025-03-19T19:56:13Z","date_created":"2025-03-19T19:42:03Z","summary":null,"body":["<article data-history-node-id=\"6207\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av25-150\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-150<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 19, 2025<\/p>\n\n<p>On March 19, 2025, Veeam published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2014 all versions 12 prior to build 12.3.1.1139<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4724\">Veeam Security Advisory\u00a0\u2013 kb4724<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av25-150","alert_type":396,"serial_number":"AV25-150","subject":"other","moderation_state":"published","external_url":null},{"nid":6208,"title":"Google Chrome security advisory (AV25-151)","uuid":"0bfe0712-bbe0-4b8c-959e-4fed3350d6c6","banner":null,"lang":"en","date_modified":"2025-03-19","date_modified_ts":"2025-03-19T20:17:34Z","date_created":"2025-03-19T20:07:38Z","summary":null,"body":["<article data-history-node-id=\"6208\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-151\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-151<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 19, 2025<\/p>\n\n<p>On March 19, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable channel Chrome for desktop\u00a0\u2013 versions prior to 134.0.6998.117\/118 (Windows and Mac) and 134.0.6998.117 (Linux)<\/li>\n\t<li>Extended stable channel\u00a0\u2013 versions prior to 134.0.6998.89 (Windows and Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/03\/stable-channel-update-for-desktop_19.html\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Google Chrome Security Advisory<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-151","alert_type":396,"serial_number":"AV25-151","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6211,"title":"Atlassian security advisory (AV25-152)","uuid":"762494c0-0475-4c27-bbca-6248eccb3315","banner":null,"lang":"en","date_modified":"2025-03-20","date_modified_ts":"2025-03-20T19:03:48Z","date_created":"2025-03-20T18:59:00Z","summary":null,"body":["<article data-history-node-id=\"6211\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-152\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-152<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 20, 2025<\/p>\n\n<p>On March 18, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-march-18-2025-1527943363.html \">Atlassian Security Bulletin - March 18 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-152","alert_type":396,"serial_number":"AV25-152","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6212,"title":"HPE security advisory (AV25-153)","uuid":"5ff23886-5db7-4b62-8a78-16e170b2a5ba","banner":null,"lang":"en","date_modified":"2025-03-21","date_modified_ts":"2025-03-21T14:54:27Z","date_created":"2025-03-21T14:52:35Z","summary":null,"body":["<article data-history-node-id=\"6212\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-153\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-153<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 21, 2025<\/p>\n\n<p>On March 21, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Service Activator \u2013 versions prior to 10.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04833en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbnw04833<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-153","alert_type":396,"serial_number":"AV25-153","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6213,"title":"Microsoft Edge security advisory (AV25-154)","uuid":"5dfc449b-756a-4d26-9152-9ea52be4b6b6","banner":null,"lang":"en","date_modified":"2025-03-24","date_modified_ts":"2025-03-24T14:04:40Z","date_created":"2025-03-24T13:52:30Z","summary":null,"body":["<article data-history-node-id=\"6213\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-154\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-154<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 24, 2025<\/p>\n\n<p>On March 21, 2025, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel \u2013 versions prior to 134.0.3124.83<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-21-2025  \">Microsoft Edge Extended Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-154","alert_type":396,"serial_number":"AV25-154","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6214,"title":"Dell security advisory (AV25-155)","uuid":"e031a15b-6b86-443f-a8b2-e9956b29c131","banner":null,"lang":"en","date_modified":"2025-03-24","date_modified_ts":"2025-03-24T14:13:33Z","date_created":"2025-03-24T14:09:40Z","summary":null,"body":["<article data-history-node-id=\"6214\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-155\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-155<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 24, 2025<\/p>\n\n<p>Between March 17 and 23, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.01.02.00<\/li>\n\t<li>Dell Chassis Management Controller (CMC) for Dell PowerEdge FX2\u00a0\u2013 versions prior to 2.40.200.202101130302<\/li>\n\t<li>Dell Chassis Management Controller (CMC) for PowerEdge VRTX\u00a0\u2013 versions prior to 3.41.200.202209300499<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 versions 19.9.0 to 19.11.0-2<\/li>\n\t<li>Dell ECS\u00a0\u2013 versions prior to 3.8.1.4<\/li>\n\t<li>Dell SmartFabric Manager\u00a0\u2013 versions 1.0.0 and 1.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-155","alert_type":396,"serial_number":"AV25-155","subject":"dell","moderation_state":"published","external_url":null},{"nid":6215,"title":"Red Hat security advisory (AV25-156)","uuid":"5963d3a3-b9dc-4aba-997a-c1151aba0d56","banner":null,"lang":"en","date_modified":"2025-03-24","date_modified_ts":"2025-03-24T14:21:45Z","date_created":"2025-03-24T14:16:16Z","summary":null,"body":["<article data-history-node-id=\"6215\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-156\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-156<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 24, 2025<\/p>\n\n<p>Between March 17 and 23, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\u2003\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-156","alert_type":396,"serial_number":"AV25-156","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6216,"title":"IBM security advisory (AV25-157)","uuid":"49b953db-6d85-4c5a-9734-ce15b1d0b3a0","banner":null,"lang":"en","date_modified":"2025-03-24","date_modified_ts":"2025-03-24T14:29:27Z","date_created":"2025-03-24T14:23:38Z","summary":null,"body":["<article data-history-node-id=\"6216\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-157\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-157<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 24, 2025<\/p>\n\n<p>Between March 17 and 23, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>AIX \u2013 versions 7.2 and 7.3<\/li>\n\t<li>DataStage on Cloud Pak for Data \u2013 version 4.8.2 to 4.8.4<\/li>\n\t<li>FileNet Content Manager \u2013 versions 5.5.12.0, 5.5.8.0 and 5.6.0.0<\/li>\n\t<li>IBM CP4MCM \u2013 version 2.3 to 2.3 FP9<\/li>\n\t<li>IBM Maximo Application Suite IoT Component \u2013 versions 8.7, 8.8 and 9.0<\/li>\n\t<li>IBM Rapid Infrastructure Automation \u2013 version 1.1.4<\/li>\n\t<li>IBM watsonx Assistant Cartridge \u2013 version 4.0 to 5.1.0<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component \u2013 version 5.0 to 5.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-157","alert_type":396,"serial_number":"AV25-157","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6218,"title":"[Control systems] CISA ICS security advisories (AV25\u2013158) ","uuid":"35da15db-34d7-40cb-a946-08d739dc47d9","banner":null,"lang":"en","date_modified":"2025-03-24","date_modified_ts":"2025-03-24T18:06:43Z","date_created":"2025-03-24T18:00:08Z","summary":null,"body":["<article data-history-node-id=\"6218\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-158\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-158<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 24, 2025<\/p>\n\n<p>Between March 17 and 23, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Rockwell Automation Endpoint Protection Service with RA Proxy &amp; VMware only \u2013 all versions<\/li>\n\t<li>Rockwell Automation Engineered and Integrated Solutions with VMware \u2013 all versions<\/li>\n\t<li>Rockwell Automation Industrial Data Center (IDC) with VMware \u2013 Generations 1 to 4<\/li>\n\t<li>Rockwell Automation Threat Detection Managed Services (TDMS) with VMware \u2013 all versions<\/li>\n\t<li>Rockwell Automation VersaVirtual Appliance (VVA) with VMware \u2013 Series A and B<\/li>\n\t<li>Santesoft Sante DICOM Viewer Pro \u2013 version 14.1.2 and prior<\/li>\n\t<li>Schneider Electric ASCO 5310 Single-Channel Remote Annunciator \u2013 all versions<\/li>\n\t<li>Schneider Electric ASCO 5350 Eight Channel Remote Annunciator \u2013 all versions<\/li>\n\t<li>Schneider Electric EcoStruxure Panel Server \u2013 versions v2.0 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure Power Automation System \u2013 versions 2.6.30.19 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure Power Automation System User Interface (EPAS-UI) \u2013 version v2.1 to v2.9<\/li>\n\t<li>Schneider Electric EcoStruxure Process Expert \u2013 versions 2020R2, 2021 and 2023 (prior to v4.8.0.5715)<\/li>\n\t<li>Schneider Electric EcoStruxure Process Expert for AVEVA System Platform \u2013 versions 2020R2, 2021 and 2023<\/li>\n\t<li>Schneider Electric Enerlin'X eIFE \u2013 all versions<\/li>\n\t<li>Schneider Electric Enerlin'X IFE interface \u2013 all versions<\/li>\n\t<li>Siemens Simcenter Femap V2401 \u2013 versions prior to V2401.0003<\/li>\n\t<li>Siemens Simcenter Femap V2406 \u2013 versions prior to V2406.0002<\/li>\n\t<li>SMA Sunny Portal \u2013 all versions before December 19, 2024<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories \">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-158","alert_type":398,"serial_number":"AV25-158","subject":"other","moderation_state":"published","external_url":null},{"nid":6219,"title":"[Control systems] B&R security advisory (AV25-159) ","uuid":"19ac3ecc-96dc-4a6e-b3df-7ad8646b3543","banner":null,"lang":"en","date_modified":"2025-03-24","date_modified_ts":"2025-03-24T18:13:29Z","date_created":"2025-03-24T18:08:45Z","summary":null,"body":["<article data-history-node-id=\"6219\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av25-159\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-159<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 24, 2025<\/p>\n\n<p>On March 24, 2025, B&amp;R published an ICS advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>B&amp;R APROL \u2013 versions prior to R 4.4-00P1 and versions prior to R 4.4-00P5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA24P015-77573c08.pdf\">B&amp;R APROL Potential Privilege Escalation and Information Disclosure (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av25-159","alert_type":398,"serial_number":"AV25-159","subject":"br-automation","moderation_state":"published","external_url":null},{"nid":6220,"title":"HPE security advisory (AV25-160)","uuid":"aeda7e3e-990e-4e1d-bde9-81b3af06e527","banner":null,"lang":"en","date_modified":"2025-03-24","date_modified_ts":"2025-03-24T18:18:34Z","date_created":"2025-03-24T18:15:03Z","summary":null,"body":["<article data-history-node-id=\"6220\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-160\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-160<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 24, 2025<\/p>\n\n<p>On March 24, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE SANnav Management Software \u2013 versions prior to v2.3.1b and v2.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04817en_us&amp;docLocale=en_US\">HPE Security Bulletin - HPESBST04817<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04817en_us&amp;docLocale=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-160","alert_type":396,"serial_number":"AV25-160","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6221,"title":"Kubernetes security advisory (AV25-161) - Update 1","uuid":"aa1a7748-656f-4c1d-a030-d4ab0309c886","banner":null,"lang":"en","date_modified":"2025-03-27","date_modified_ts":"2025-03-27T18:39:41Z","date_created":"2025-03-24T20:33:19Z","summary":null,"body":["<article data-history-node-id=\"6221\" about=\"\/en\/alerts-advisories\/kubernetes-security-advisory-av25-161\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-161<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March\u00a024, 2025<br \/><strong>Updated:<\/strong> March\u00a027, 2025<\/p>\n\n<p>On March\u00a024, 2025, Kubernetes published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Kubernetes ingress-nginx controller\u00a0\u2014 versions prior to 1.11.5<\/li>\n\t<li>Kubernetes ingress-nginx controller\u00a0\u2014 versions prior to 1.12.1<\/li>\n<\/ul><p>This vulnerability allows unauthenticated RCE and wide access to secrets.<\/p>\n\n<p>The vulnerability is rated a <strong>CVSS 9.8<\/strong> and is tracked with the following identifiers: CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 and CVE-2025-1974.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On March\u00a024, 2025, open-source reporting has indicated that proof-of-concept exploit code is available for vulnerability CVE-2025-1974.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kubernetes.io\/blog\/2025\/03\/24\/ingress-nginx-cve-2025-1974\/\">Kubernetes\u00a0- Ingress-nginx CVE-2025-1974: What You Need to Know<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/kubernetes\/ingress-nginx\/releases\/tag\/controller-v1.11.5\">Kubernetes\u00a0- controller-v1.11.5<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/kubernetes\/ingress-nginx\/releases\/tag\/controller-v1.12.1\">Kubernetes\u00a0- controller-v1.12.1<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/kubernetes\/ingress-nginx\/releases\/tag\/controller-v1.11.5\">Kubernetes\u00a0- controller-v1.11.5<\/a><\/li>\n\t<li><a href=\"https:\/\/www.wiz.io\/blog\/ingress-nginx-kubernetes-vulnerabilities\">IngressNightmare: 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX<\/a><\/li>\n\t<li><a href=\"https:\/\/aws.amazon.com\/security\/security-bulletins\/AWS-2025-006\/\">AWS\u00a0- Issues with Kubernetes ingress-nginx controller (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-24514\">Microsoft\u00a0- Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller<\/a><\/li>\n\t<li><a href=\"https:\/\/cloud.google.com\/support\/bulletins\">Google Cloud\u00a0- Security Bulletins<\/a><\/li>\n\t<li><a href=\"https:\/\/thehackernews.com\/2025\/03\/critical-ingress-nginx-controller.html\">Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/kubernetes-security-advisory-av25-161","alert_type":396,"serial_number":"AV25-161","subject":"other","moderation_state":"published","external_url":null},{"nid":6224,"title":"Next.js security advisory (AV25-162)","uuid":"e32db2c8-84af-4f2c-8d7b-40115e15e551","banner":null,"lang":"en","date_modified":"2025-03-25","date_modified_ts":"2025-03-25T15:52:34Z","date_created":"2025-03-25T15:45:49Z","summary":null,"body":["<article data-history-node-id=\"6224\" about=\"\/en\/alerts-advisories\/nextjs-security-advisory-av25-162\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-162<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 25, 2025<\/p>\n\n<p>On March 22, 2025, Next.js published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Next.js\u00a0\u2013 15.x versions prior to 15.2.3<\/li>\n\t<li>Next.js\u00a0\u2013 14.x versions prior to 14.2.25<\/li>\n\t<li>Next.js\u00a0\u2013 13.x versions prior to 13.5.9<\/li>\n\t<li>Next.js\u00a0\u2013 12.x versions prior to 12.3.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided below and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nextjs.org\/blog\/cve-2025-29927\">CVE-2025-29927<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nextjs-security-advisory-av25-162","alert_type":396,"serial_number":"AV25-162","subject":"other","moderation_state":"published","external_url":null},{"nid":6226,"title":"VMware security advisory (AV25-163)","uuid":"8f11cdba-61a0-4671-b1c3-e89de02ead83","banner":null,"lang":"en","date_modified":"2025-03-25","date_modified_ts":"2025-03-25T17:37:42Z","date_created":"2025-03-25T17:24:25Z","summary":null,"body":["<article data-history-node-id=\"6226\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-163\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-163<br \/><strong>Date: <\/strong>March\u00a025, 2025<\/p>\n\n<p>On March\u00a025, 2025, VMware published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Tools\u00a0\u2013 versions 11.x.x and 12.x.x prior to 12.5.1 for Windows<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25518\">VMSA-2025-0005: VMware Tools for Windows update addresses an authentication bypass vulnerability (CVE-2025-22230)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-163","alert_type":396,"serial_number":"AV25-163","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6230,"title":"Google Chrome security advisory (AV25-164)","uuid":"ead74081-e436-498b-8efb-cf70912fad83","banner":null,"lang":"en","date_modified":"2025-03-26","date_modified_ts":"2025-03-26T14:17:19Z","date_created":"2025-03-26T14:12:03Z","summary":null,"body":["<article data-history-node-id=\"6230\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-164\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-164<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 26, 2025<\/p>\n\n<p>On March 25, 2025, Google published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Stable channel Chrome for desktop \u2013 versions prior to 134.0.6998.177\/178 (Windows)<\/li>\n\t<li>Extended Stable Channel \u2013 versions prior to 134.0.6998.178 (Windows)<\/li>\n<\/ul><p>Google has indicated that CVE-2025-2783 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/03\/stable-channel-update-for-desktop_25.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-164","alert_type":396,"serial_number":"AV25-164","subject":"other","moderation_state":"published","external_url":null},{"nid":6231,"title":"CrushFTP security advisory (AV25-165)","uuid":"b020cab9-bca5-4d9f-8245-b9c18c0e85de","banner":null,"lang":"en","date_modified":"2025-03-26","date_modified_ts":"2025-03-26T14:21:13Z","date_created":"2025-03-26T14:19:34Z","summary":null,"body":["<article data-history-node-id=\"6231\" about=\"\/en\/alerts-advisories\/crushftp-security-advisory-av25-165\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-165<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 26, 2025<\/p>\n\n<p>On March 21, 2025,CrushFTP published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>CrushFTP \u2013 versions 11.0.0 to 11.3.0 and versions 10.0.0 to 10.8.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.crushftp.com\/crush11wiki\/Wiki.jsp?page=Update\">CrushFTP Update <\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/crushftp-security-advisory-av25-165","alert_type":396,"serial_number":"AV25-165","subject":"other","moderation_state":"published","external_url":null},{"nid":6232,"title":"GitLab security advisory (AV25-166)","uuid":"d2808bbf-59a9-4990-a484-1ad527318064","banner":null,"lang":"en","date_modified":"2025-03-26","date_modified_ts":"2025-03-26T17:34:57Z","date_created":"2025-03-26T16:00:47Z","summary":null,"body":["<article data-history-node-id=\"6232\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-166\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-166<br \/><strong>Date:<\/strong> March\u00a026, 2025<\/p>\n\n<p>On March\u00a026, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.10.1, 17.9.3 and 17.8.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.10.1, 17.9.3 and 17.8.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/03\/26\/patch-release-gitlab-17-10-1-released\/\">GitLab Patch Release: 17.10.1, 17.9.3, 17.8.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-166","alert_type":396,"serial_number":"AV25-166","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6235,"title":"Microsoft Edge security advisory (AV25-167)","uuid":"8411de5a-a23b-4885-8297-d0709b42411b","banner":null,"lang":"en","date_modified":"2025-03-27","date_modified_ts":"2025-03-27T15:06:28Z","date_created":"2025-03-27T15:02:44Z","summary":null,"body":["<article data-history-node-id=\"6235\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-167\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-167<br \/><strong>Date: <\/strong>March\u00a027, 2025<\/p>\n\n<p>On March\u00a026, 2025, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Extended Stable Channel\u00a0\u2013 versions prior to 134.0.3124.93<\/li>\n<\/ul><p>This update contains a fix for CVE-2025-2783.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-26-2025\">Microsoft Edge Extended Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-167","alert_type":396,"serial_number":"AV25-167","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6236,"title":"Splunk security advisory (AV25-168)","uuid":"515c35ba-5a91-43be-8282-95d7b6443d8e","banner":null,"lang":"en","date_modified":"2025-03-27","date_modified_ts":"2025-03-27T15:13:19Z","date_created":"2025-03-27T15:02:44Z","summary":null,"body":["<article data-history-node-id=\"6236\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-168\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-168<br \/><strong>Date: <\/strong>March\u00a027, 2025<\/p>\n\n<p>On March\u00a026, 2025, Splunk published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Splunk Enterprise\u00a0\u2013 versions prior to 9.4.0, 9.3.3, 9.2.5 and 9.1.8<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 versions prior to 9.3.2408.104, 9.2.2406.108, 9.2.2403.114 and 9.1.2312.208<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0301\">Splunk\u00a0- Remote Code Execution through file upload to \u201c$SPLUNK_HOME\/var\/run\/splunk\/apptemp\u201d directory in Splunk Enterprise\u00a0- CVE-2025-20229<\/a><\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-168","alert_type":396,"serial_number":"AV25-168","subject":"other","moderation_state":"published","external_url":null},{"nid":6237,"title":"[Control systems] ABB security advisory (AV25-169)","uuid":"74b17eb8-e34d-4449-89fa-476c0d358b62","banner":null,"lang":"en","date_modified":"2025-03-27","date_modified_ts":"2025-03-27T17:47:03Z","date_created":"2025-03-27T17:03:57Z","summary":null,"body":["<article data-history-node-id=\"6237\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-169\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-169<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 27, 2025<\/p>\n\n<p>On March 27, 2025, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ACS880 Primary Control Program\u00a0\u2013 version AINLX prior to 3.47 and version YINLX prior to 1.30<\/li>\n\t<li>ACS880 IGBT Supply Control Program\u00a0\u2013 multiple versions<\/li>\n\t<li>ACS880 Position Control Program\u00a0\u2013 version APCLX 1.04.0.5 and prior.<\/li>\n\t<li>ACS880 Test Bench Control Program\u00a0\u2013 version ATBLX 3.44.0.0 and prior<\/li>\n\t<li>DCT880 memory unit incl. ABB Drive Application Builder license (IEC 61131-3)\u00a0\u2013 version 3ADT786242R0101<\/li>\n\t<li>DCT880 memory unit incl. Power Optimizer\u00a0\u2013 version 3ADT786242R0201<\/li>\n\t<li>DCS880 memory unit incl. ABB Drive Application Builder license (IEC 61131-3)\u00a0\u2013 version 3ADT786251R0101<\/li>\n\t<li>DCS880 memory unit incl. DEMag\u00a0\u2013 version 3ADT786251R0201<\/li>\n\t<li>DCS880 memory unit incl. DCC\u00a0\u2013 version 3ADT786251R0401<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108470A9491&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">ABB Cyber Security Advisory\u00a0- ABB ACS880 +N8010 Drives CODESYS RTS Vulnerabilities (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108470A9494&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">ABB Cyber Security Advisory\u00a0- Low Voltage DC Drives and Power Controllers CODESYS RTS Vulnerabilities<\/a> (PDF)<\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-169","alert_type":398,"serial_number":"AV25-169","subject":"other","moderation_state":"published","external_url":null},{"nid":6238,"title":"Mozilla security advisory (AV25-170)","uuid":"4cafc66c-671d-40eb-828f-70b484e49e22","banner":null,"lang":"en","date_modified":"2025-03-27","date_modified_ts":"2025-03-27T19:49:56Z","date_created":"2025-03-27T19:45:44Z","summary":null,"body":["<article data-history-node-id=\"6238\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-170\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-170<br \/><strong>Date: <\/strong>March\u00a027, 2025<\/p>\n\n<p>On March\u00a027, 2025, Mozilla published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 136.0.4<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.21.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.8.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-19\/\">Mozilla Security Advisory (MFSA 2025-19)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-170","alert_type":396,"serial_number":"AV25-170","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6239,"title":"Esri security advisory (AV25-171)","uuid":"e4c58f80-7cc6-4fdf-8372-0af37e69792c","banner":null,"lang":"en","date_modified":"2025-03-28","date_modified_ts":"2025-03-28T17:57:15Z","date_created":"2025-03-28T17:34:56Z","summary":null,"body":["<article data-history-node-id=\"6239\" about=\"\/en\/alerts-advisories\/esri-security-advisory-av25-171\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-171<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 28, 2025<\/p>\n\n<p>On March 13, 2025, Esri published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Portal for ArcGIS \u2013 versions 11.4, 11.3, 11.2, 11.1, and 10.9.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/portal-for-arcgis-security-2025-update-1-patch\">Portal for ArcGIS Security 2025 Update 1 Patch (CVE-2025-2538)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.esri.com\/en-us\/search?s=Relevance&amp;cardtype=support_patches_updates\">Esri Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/esri-security-advisory-av25-171","alert_type":396,"serial_number":"AV25-171","subject":"other","moderation_state":"published","external_url":null},{"nid":6241,"title":"Dell security advisory (AV25-172)","uuid":"752b2a7d-d902-44f0-8951-923ee9d79e9f","banner":null,"lang":"en","date_modified":"2025-03-31","date_modified_ts":"2025-03-31T15:03:28Z","date_created":"2025-03-31T14:59:23Z","summary":null,"body":["<article data-history-node-id=\"6241\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-172\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-172<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 31, 2025<\/p>\n\n<p>Between March 24 and 30, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Enterprise SONiC Distribution \u2013 versions prior to 4.4.2<\/li>\n\t<li>Dell ObjectScale \u2013 versions prior to ObjectScale 4.0<\/li>\n\t<li>Dell Storage Monitoring and Reporting \u2013 versions prior to 5.0.2.2<\/li>\n\t<li>Dell Storage Monitoring and Reporting \u2013 versions prior to 5.0.2.2<\/li>\n\t<li>Dell Storage Resource Manager \u2013 versions prior to 5.0.2.2<\/li>\n\t<li>Dell Unity \u2013 versions prior to 5.5.0.0.5.259<\/li>\n\t<li>PowerStore 1000T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 1200T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 3000T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 3200T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 5000T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 500T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 5200T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 7000T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 9000T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n\t<li>PowerStore 9200T \u2013 versions prior to 3.6.1.5-2456810<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-172","alert_type":396,"serial_number":"AV25-172","subject":"dell","moderation_state":"published","external_url":null},{"nid":6242,"title":"IBM security advisory (AV25-173)","uuid":"479ae730-277e-4baa-8550-80fb063202ac","banner":null,"lang":"en","date_modified":"2025-03-31","date_modified_ts":"2025-03-31T15:10:00Z","date_created":"2025-03-31T15:05:11Z","summary":null,"body":["<article data-history-node-id=\"6242\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-173\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-173<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 31, 2025<\/p>\n\n<p>Between March 24 and 30, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Automation Decision Services \u2013 version 24.0.0<\/li>\n\t<li>IBM Cloud Pak for AIOps \u2013 version 4.1.0 to 4.8.1<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM Maximo Application Suite - AI Broker Component \u2013 versions 9.0.5<\/li>\n\t<li>IBM Maximo Application Suite - AI Broker \u2013 version 9.0.4<\/li>\n\t<li>IBM Planning Analytics Cartridge for IBM Cloud Pak for Data \u2013 version 4.8.0 to 4.8.8<\/li>\n\t<li>IBM Planning Analytics Cartridge \u2013 version 5.0.0 to 5.1.0<\/li>\n\t<li>IBM Watson Query on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin \">IBM Product Security Incident Response<\/a><\/li>\n\t<li>\u00a0<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-173","alert_type":396,"serial_number":"AV25-173","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6243,"title":"Ubuntu security advisory (AV25-174)","uuid":"721ea59d-4710-4d04-9392-5b9e62c880bd","banner":null,"lang":"en","date_modified":"2025-03-31","date_modified_ts":"2025-03-31T15:14:31Z","date_created":"2025-03-31T15:11:39Z","summary":null,"body":["<article data-history-node-id=\"6243\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-174\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-174<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 31, 2025<\/p>\n\n<p>Between March 24 and 30, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-174","alert_type":396,"serial_number":"AV25-174","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6244,"title":"[Control systems] CISA ICS security advisories (AV25\u2013175)","uuid":"dc7dc581-f660-42e5-8d28-5673e4edeef6","banner":null,"lang":"en","date_modified":"2025-03-31","date_modified_ts":"2025-03-31T15:21:09Z","date_created":"2025-03-31T15:16:28Z","summary":null,"body":["<article data-history-node-id=\"6244\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-175\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-175<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 31, 2025<\/p>\n\n<p>Between March 24 and 30, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB RMC-100 LITE \u2013 versions 2106229-010 to 2106229-016<\/li>\n\t<li>ABB RMC-100 \u2013 versions 2105457-036 to 2105457-044<\/li>\n\t<li>Inaba Denki Sangyo Co., Ltd. CHOCO TEI WATCHER mini (IB-MCT001) \u2013 all versions<\/li>\n\t<li>Rockwell Automation 440G TLS-Z \u2013 version v6.001<\/li>\n\t<li>Rockwell Automation Verve Asset Manager \u2013 versions 1.39 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-175","alert_type":398,"serial_number":"AV25-175","subject":"other","moderation_state":"published","external_url":null},{"nid":6245,"title":"Red Hat security advisory (AV25-176)","uuid":"f33c9b26-861b-4b96-b3c0-e7079ff71fe2","banner":null,"lang":"en","date_modified":"2025-03-31","date_modified_ts":"2025-03-31T17:27:27Z","date_created":"2025-03-31T17:22:33Z","summary":null,"body":["<article data-history-node-id=\"6245\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-176\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-176<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 31, 2025<\/p>\n\n<p>Between March 24 and 30, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\u2003\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-176","alert_type":396,"serial_number":"AV25-176","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6246,"title":"Apple security advisory (AV25-177)","uuid":"cda80d1c-1f62-41da-925c-208ec03eb742","banner":null,"lang":"en","date_modified":"2025-03-31","date_modified_ts":"2025-03-31T19:24:18Z","date_created":"2025-03-31T19:19:48Z","summary":null,"body":["<article data-history-node-id=\"6246\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-177\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-177<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>March 31, 2025<\/p>\n\n<p>On March 31, 2025, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 18.4<\/li>\n\t<li>iPadOS \u2013 versions prior to 17.7.6<\/li>\n\t<li>iOS and iPadOS \u2013 versions prior to 16.7.11<\/li>\n\t<li>iOS and iPadOS \u2013 versions prior to 15.8.4<\/li>\n\t<li>macOS Sequoia \u2013 versions prior to 15.4<\/li>\n\t<li>macOS Sonoma \u2013 versions prior to 14.7.5<\/li>\n\t<li>macOS Ventura \u2013 versions prior to 13.7.5<\/li>\n  <li>Safari \u2013 versions prior to 18.4<\/li>\n  <li>Xcode \u2013 versions prior to 16.3<\/li>\n<\/ul><p>Apple has been advised that CVE-2025-24085, CVE-2025-24200, and CVE-2025-24201 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-177","alert_type":396,"serial_number":"AV25-177","subject":"apple","moderation_state":"published","external_url":null},{"nid":6247,"title":"Mozilla security advisory (AV25-178)","uuid":"0c1030b8-b464-4369-aa8f-f857a7364e1e","banner":null,"lang":"en","date_modified":"2025-04-01","date_modified_ts":"2025-04-01T14:03:56Z","date_created":"2025-04-01T14:00:52Z","summary":null,"body":["<article data-history-node-id=\"6247\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-178\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-178<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 1, 2025<\/p>\n\n<p>On April 1, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird ESR \u2013 versions prior to 128.9<\/li>\n\t<li>Thunderbird \u2013 versions prior to 137<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 128.9<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.22<\/li>\n\t<li>Firefox \u2013 versions prior to 137<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-178","alert_type":396,"serial_number":"AV25-178","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6248,"title":"Google Chrome security advisory (AV25-179)","uuid":"28ddd384-8ff0-4400-8aec-bc4e6050c8d8","banner":null,"lang":"en","date_modified":"2025-04-01","date_modified_ts":"2025-04-01T19:03:23Z","date_created":"2025-04-01T19:00:55Z","summary":null,"body":["<article data-history-node-id=\"6248\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-179\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-179<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 1, 2025<\/p>\n\n<p>On April 1, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 135.0.7049.41\/42 (Windows\/Mac), and 135.0.7049.52 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/04\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-179","alert_type":396,"serial_number":"AV25-179","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6249,"title":"VMware security advisory (AV25-180)","uuid":"57ab9c38-d3cb-4d4c-a583-40be6dd4588b","banner":null,"lang":"en","date_modified":"2025-04-01","date_modified_ts":"2025-04-01T19:08:57Z","date_created":"2025-04-01T19:04:58Z","summary":null,"body":["<article data-history-node-id=\"6249\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-180\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-180<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 1, 2025<\/p>\n\n<p>On April 1, 2025, VMware released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>VMware Aria Operations \u2013 version 8.x<\/li>\n\t<li>VMware Cloud Foundation \u2013 versions 5.x and 4.x<\/li>\n\t<li>VMware Telco Cloud Platform \u2013 versions 5.x, 4.x and 3.x<\/li>\n\t<li>VMware Telco Cloud Infrastructure \u2013 versions 3.x and 2.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25541  \">VMware Aria Operations updates address a local privilege escalation vulnerability (CVE-2025-22231)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories - VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-180","alert_type":396,"serial_number":"AV25-180","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6250,"title":"Vulnerability impacting CrushFTP","uuid":"90e505fb-77e0-45d8-93a8-b8ea90be9090","banner":null,"lang":"en","date_modified":"2025-04-02","date_modified_ts":"2025-04-02T13:55:18Z","date_created":"2025-04-02T13:10:41Z","summary":null,"body":["<article data-history-node-id=\"6250\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-crushftp\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL25-003<br \/><strong>Date: <\/strong>April 2, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On March 21, 2025, CrushFTP released a security bulletin for a critical vulnerability affecting versions v10 and v11 of CrushFTP. The issue is described as an unauthenticated HTTP(S) port access bypass vulnerability. The versions of CrushFTP affected are<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>10.0.0 to 10.8.3<\/li>\n\t<li>11.0.0 to 11.3.0<\/li>\n<\/ul><p>In response to this vulnerability, the Cyber Centre released AV25-165 on March 26, 2025<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre is aware that a proof of concept (POC) is available, and we are aware of reports of exploitation. The existence of a published POC makes it imperative to take action to assess and mitigate this vulnerability.<\/p>\n\n<p>On April 7, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-31161 to their Known Exploited Vulnerabilities (KEV) Database<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations update to CrushFTP versions 10.8.4+ or 11.3.1+.<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<p>The vendor states, the exploit does not work if you have the DMZ proxy instance of CrushFTP in place<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/p>\n\n<p>The Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Assess the installations of CrushFTP.<\/li>\n\t<li>Apply software update to CrushFTP without delay.<\/li>\n\t<li>Monitor affected systems for exploitation.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> with an emphasis on the following strategies:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.crushftp.com\/crush11wiki\/Wiki.jsp?page=Update\">CrushFTP Security Bulletin<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/crushftp-security-advisory-av25-165\">AV25-165\u00a0\u2013 CrushFTP security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.crushftp.com\/crush11wiki\/Wiki.jsp?page=DMZ\">CrushFTP\u00a0- DMZ<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information\u00a0- ITSM.10.089<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31161\">CISA KEV: CVE-2025-31161<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-crushftp","alert_type":397,"serial_number":"AL25-003","subject":"other","moderation_state":"published","external_url":null},{"nid":6251,"title":"[Control Systems] Moxa security advisory (AV25-181)","uuid":"895743d5-4c3a-46cc-a236-61571b8c1e54","banner":null,"lang":"en","date_modified":"2025-04-02","date_modified_ts":"2025-04-02T14:43:01Z","date_created":"2025-04-02T14:18:44Z","summary":null,"body":["<article data-history-node-id=\"6251\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av25-181\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-181<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 2, 2025<\/p>\n\n<p>On April 2, 2025, Moxa published security advisories to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>EDF-G1002-BP Series - firmware version 3.14 and prior<\/li>\n\t<li>EDR-810 Series - firmware version 5.12.39 and prior<\/li>\n\t<li>EDR-8010 Series - firmware version 3.14 and prior<\/li>\n\t<li>EDR-G9004 Series - firmware version 3.14 and prior<\/li>\n\t<li>EDR-G9010 Series - firmware version 3.14 and prior<\/li>\n\t<li>OnCell G4302-LTE4 Series - firmware version 3.14 and prior<\/li>\n\t<li>TN-4900 Series - firmware version 3.14 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-259491-cve-2025-0415-command-injection-leading-to-denial-of-service-(dos)\">Moxa Security Advisory - MPSA-259491<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-259491-cve-2025-0676-command-injection-leading-to-privilege-escalation\">Moxa Security Advisory - MPSA-251431 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av25-181","alert_type":398,"serial_number":"AV25-181","subject":"other","moderation_state":"published","external_url":null},{"nid":6253,"title":"Cisco security advisory (AV25-182)","uuid":"fea88daa-f7db-4f51-90bb-53ffb6b24f2b","banner":null,"lang":"en","date_modified":"2025-04-02","date_modified_ts":"2025-04-02T18:52:24Z","date_created":"2025-04-02T18:48:09Z","summary":null,"body":["<article data-history-node-id=\"6253\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-182\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-182<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 2, 2025<\/p>\n\n<p>On April 2, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Enterprise Chat and Email (ECE)\u00a0\u2013 versions prior to 12.6 ES 10<\/li>\n\t<li>Cisco Meraki MX and Cisco Meraki Z Series\u00a0\u2013 firmware versions 16.2, 17, 18.1, 18.2 and 19.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ece-dos-tC6m9GZ8\">Cisco Security Advisory\u00a0\u2013 cisco-sa-ece-dos-tC6m9GZ8 <\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-meraki-mx-vpn-dos-vNRpDvfb\">Cisco Security Advisory \u2013 cisco-sa-meraki-mx-vpn-dos-vNRpDvfb<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-182","alert_type":396,"serial_number":"AV25-182","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6254,"title":"Jenkins security advisory (AV25-183)","uuid":"682f9c05-4020-46fb-a53c-5dc08ab7b4d5","banner":null,"lang":"en","date_modified":"2025-04-02","date_modified_ts":"2025-04-02T18:59:48Z","date_created":"2025-04-02T18:53:56Z","summary":null,"body":["<article data-history-node-id=\"6254\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-183\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-183<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 2, 2025<\/p>\n\n<p>On April 2, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins weekly \u2013 version 2.503 and prior<\/li>\n\t<li>Jenkins LTS \u2013 version 2.492.2 and prior<\/li>\n\t<li>AsakusaSatellite Plugin \u2013 version 0.1.1 and prior<\/li>\n\t<li>Cadence vManager Plugin \u2013 version 4.0.0-282.v5096a_c2db_275 and prior<\/li>\n\t<li>monitor-remote-job Plugin \u2013 version 1.0 and prior<\/li>\n\t<li>Simple Queue Plugin \u2013 version 1.4.6 and prior<\/li>\n\t<li>Stack Hammer Plugin \u2013 version 1.0.6 and prior<\/li>\n\t<li>Templating Engine Plugin \u2013 version 2.5.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-04-02\/\">Jenkins Security Advisory 2025-04-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-183","alert_type":396,"serial_number":"AV25-183","subject":"other","moderation_state":"published","external_url":null},{"nid":6255,"title":"Ivanti security advisory (AV25-184)","uuid":"0ec93d69-4d65-4021-8583-3354b87f474f","banner":null,"lang":"en","date_modified":"2025-04-03","date_modified_ts":"2025-04-03T16:03:50Z","date_created":"2025-04-03T15:44:17Z","summary":null,"body":["<article data-history-node-id=\"6255\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-184\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-184<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 3, 2025<\/p>\n\n<p>On April 3, 2025, Ivanti published a security advisory to address a vulnerability in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Ivanti Connect Secure\u00a0\u2013 version 22.7R2.5 and prior<\/li>\n\t<li>Pulse Connect Secure (EoS)\u00a0\u2013 version 9.1R18.9 and prior<\/li>\n\t<li>Ivanti Policy Secure\u00a0\u2013 version 22.7R1.3 and prior<\/li>\n\t<li>ZTA Gateways\u00a0\u2013 version 22.8R2 and prior<\/li>\n<\/ul><p>Ivanti has indicated that CVE-2025-22457 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457?language=en_US\">April Security Advisory Ivanti Connect Secure, Policy Secure &amp; ZTA Gateways (CVE-2025-22457)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-184","alert_type":396,"serial_number":"AV25-184","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6257,"title":"Vulnerability impacting Ivanti Connect Secure, Policy Secure and ZTA Gateways","uuid":"ede950be-7236-4162-8186-b11157adb6d4","banner":null,"lang":"en","date_modified":"2025-04-04","date_modified_ts":"2025-04-04T16:46:32Z","date_created":"2025-04-04T16:18:38Z","summary":null,"body":["<article data-history-node-id=\"6257\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-ivanti-connect-secure-policy-secure-zta-gateways\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AL25-004<br \/><strong>Date: <\/strong>April 4, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On April 3, 2025, Ivanti released a security bulletin for Ivanti Connect Secure, Policy Secure, and ZTA Gateways addressing a critical vulnerability (CVE-2025-22457) affecting these products<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. The vulnerability has been assigned a CVSS severity rating of 9.0 out of 10<sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>CVE-2025-22457 is a stack-based buffer overflow vulnerability that could allow a remote unauthenticated attacker to achieve remote code execution.<\/p>\n\n<p>In response to this security bulletin, the Cyber Centre released AV25-184 on April 3, 2025<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>The following Ivanti products are affected by this vulnerability:<\/p>\n\n<ul><li>Ivanti Connect Secure\u00a0\u2013 version 22.7R2.5 and prior<\/li>\n\t<li>Pulse Connect Secure (EoS)\u00a0\u2013 version 9.1R18.9 and prior<\/li>\n\t<li>Ivanti Policy Secure\u00a0\u2013 version 22.7R1.3 and prior<\/li>\n\t<li>ZTA Gateways\u00a0\u2013 version 22.8R2 and prior<\/li>\n<\/ul><p>Note that customers have a significantly reduced risk from this vulnerability if they are running Ivanti appliances on supported versions and in accordance with Ivanti's guidance: Ivanti always encourages customers to remain on the latest version of a solution so they can benefit from important security and product enhancements<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre is aware of reports that this vulnerability has been exploited<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations patch the affected Ivanti instances to the following versions<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>Ivanti Connect Secure\u00a0\u2013 version 22.7R2.6 (released February 11, 2025)<\/li>\n\t<li>Pulse Connect Secure (EoS)\u00a0\u2013 version 22.7R2.6<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n\t<li>Ivanti Policy Secure\u00a0\u2013 version 22.7R1.4 (available April 21,2025)<\/li>\n\t<li>ZTA Gateways\u00a0\u2013 version 22.8R2 (available April 19, 2025)<\/li>\n<\/ul><p>Ivanti also recommends that customers monitor their external Integrity Checker Tool (ICT) and contact Ivanti Support if suspicious activity is identified.<\/p>\n\n<p>The Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Assess the installations of the affected Ivanti products and monitor for signs of exploitation.<\/li>\n\t<li>Apply software patches to affected Ivanti products as soon as they become available.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> with an emphasis on the following strategies:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways.<\/li>\n\t<li>Patch operating systems and applications.<\/li>\n\t<li>Isolate web-facing applications.<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457?language=en_US \">Ivanti Security Bulletin<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-184\">AV25-184\u00a0\u2013 Ivanti security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-22457\">CVE-2025-22457 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/china-nexus-exploiting-critical-ivanti-vulnerability?e=48754805\">Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Frequently-Asked-Questions-FAQ-for-Pulse-Secure-Appliance-PSA-to-Ivanti-Secure-Appliance-ISA-Migration?language=en_US\">Frequently Asked Questions (FAQ) for Pulse Secure Appliance (PSA) to Ivanti Secure Appliance (ISA) Migration<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><h2>Partner reporting<\/h2>\n\n<ul class=\"list-unstyled lst-spcd\"><li><a href=\"https:\/\/www.cert.govt.nz\/advisories\/cve-2025-22457-affecting-certain-ivanti-products\/\">CERT NZ - CVE-2025-22457 affecting certain Ivanti products<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ncsc.govt.nz\/news\/cve-ivanti-products\">NCSC NZ - Cyber Security Alert: CVE affecting certain Ivanti products<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cyber.gov.au\/about-us\/view-all-content\/alerts-and-advisories\/Pulse-Ivanti-Connect-Secure-Policy-Secure-and-Neurons-for-ZTA-gateways \">ASD - Critical vulnerability in Pulse\/Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways (CVE-2025-22457)<\/a><\/li>\n<\/ul><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-ivanti-connect-secure-policy-secure-zta-gateways","alert_type":397,"serial_number":"AL25-004","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6258,"title":"Apache security advisory (AV25-185)","uuid":"60b853aa-15dc-47e7-b99f-98f00d885a6e","banner":null,"lang":"en","date_modified":"2025-04-04","date_modified_ts":"2025-04-04T17:32:32Z","date_created":"2025-04-04T17:29:25Z","summary":null,"body":["<article data-history-node-id=\"6258\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av25-185\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-185<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 4, 2025<\/p>\n\n<p>On March 17, 2025, Apache published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Apache Parquet\u00a0\u2013 version 1.15.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/okzqb3kn479gqzxm21gg5vqr35om9gw5\">Apache Parquet Java 1.15.1<\/a><\/li>\n\t<li><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/Security+Bulletins\">Apache Security Bulletins<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-30065\">CVE-2025-30065<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av25-185","alert_type":396,"serial_number":"AV25-185","subject":"other","moderation_state":"published","external_url":null},{"nid":6259,"title":"Microsoft Edge security advisory (AV25-186)","uuid":"182e8220-6c75-47eb-a977-f991ee4d17cd","banner":null,"lang":"en","date_modified":"2025-04-04","date_modified_ts":"2025-04-04T18:49:35Z","date_created":"2025-04-04T18:44:45Z","summary":null,"body":["<article data-history-node-id=\"6259\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-186\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-186<br \/><strong>Date: <\/strong>April\u00a04, 2025<\/p>\n\n<p>On April\u00a03, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 135.0.3179.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-3-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-186","alert_type":396,"serial_number":"AV25-186","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6263,"title":"[Control systems] CISA ICS security advisories (AV25\u2013187)","uuid":"04f23dd5-1fa0-472f-b3be-a4c631b488b7","banner":null,"lang":"en","date_modified":"2025-04-07","date_modified_ts":"2025-04-07T16:15:01Z","date_created":"2025-04-07T16:06:31Z","summary":null,"body":["<article data-history-node-id=\"6263\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-187\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-187<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 7, 2025<\/p>\n\n<p>Between March 31 and April 6, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB ACS880 Drives ACS880 Primary Control Program AINLX\u00a0\u2013 versions prior to v3.47<\/li>\n\t<li>ABB ACS880 Drives ACS880 Primary Control Program YINLX\u00a0\u2013 versions prior to v1.30<\/li>\n\t<li>ABB ACS880 Drives ACS880 IGBT Supply Control Program AISLX\u00a0\u2013 versions prior to v3.43<\/li>\n\t<li>ABB ACS880 Drives ACS880 IGBT Supply Control Program ALHLX\u00a0\u2013 versions prior to v3.43<\/li>\n\t<li>ABB ACS880 Drives ACS880 IGBT Supply Control Program YISLX\u00a0\u2013 versions prior to v1.30<\/li>\n\t<li>ABB ACS880 Drives ACS880 IGBT Supply Control Program YLHLX\u00a0\u2013 versions prior to v1.30<\/li>\n\t<li>ABB ACS880 Drives ACS880 Position Control Program APCLX\u00a0\u2013 version v1.04.0.5 and prior<\/li>\n\t<li>ABB ACS880 Drives ACS880 Test Bench Control Program ATBLX\u00a0\u2013 version v3.44.0.0 and prior<\/li>\n\t<li>ABB DCT880 and DCS880 memory unit\u00a0\u2013 all versions<\/li>\n\t<li>B&amp;R APROL\u00a0\u2013 versions prior to 4.4-01, version 4.4-00P1 and prior and version 4.4-00P5 and prior<\/li>\n\t<li>Hitachi Energy RTU500 series CMU\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy TRMTracker\u00a0\u2013 versions 6.3.0, 6.3.01 and version 6.2.04 and prior<\/li>\n\t<li>Rockwell Automation Industrial Data Center (IDC) with Veeam\u00a0\u2013 generations 1 to 5<\/li>\n\t<li>Rockwell Automation Versavirtual Appliance with Veeam\u00a0\u2013 series A to C<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-187","alert_type":398,"serial_number":"AV25-187","subject":"ics","moderation_state":"published","external_url":null},{"nid":6264,"title":"Dell security advisory (AV25-188)","uuid":"d28c267b-0632-4c76-bc4a-dd3ee73c56d1","banner":null,"lang":"en","date_modified":"2025-04-07","date_modified_ts":"2025-04-07T16:27:26Z","date_created":"2025-04-07T16:20:01Z","summary":null,"body":["<article data-history-node-id=\"6264\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-188\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-188<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 7, 2025<\/p>\n\n<p>Between March 31 and April 6, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen5a\u00a0\u2013 version ADS Gen5A<\/li>\n\t<li>Dell PowerMax EEM 10.1.0.7\u00a0\u2013 version 10.1.0.5.10551 and prior<\/li>\n\t<li>Dell PowerMax EEM 10.2.0.1\u00a0\u2013 version 10.2.0.0<\/li>\n\t<li>Dell PowerMax EEM 5978\u00a0\u2013 version 5978.714.714.10632 and prior<\/li>\n\t<li>Dell PowerMax OS 10.1.0.7\u00a0\u2013 version 10.1.0.5.10551 and prior<\/li>\n\t<li>Dell PowerMax OS 10.2.0.1\u00a0\u2013 version 10.2.0.0<\/li>\n\t<li>Dell PowerMax OS 5978\u00a0\u2013 version 5978.714.714.10632 and prior<\/li>\n\t<li>PowerFlex Custom Node\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Solutions Enabler Virtual Appliance\u00a0\u2013 versions prior to 9.2.4.9<\/li>\n\t<li>Unisphere 360\u00a0\u2013 versions prior to 9.2.4.35<\/li>\n\t<li>Unisphere for PowerMax\u00a0\u2013 multiple versions<\/li>\n\t<li>VxFlex Ready Node\u00a0\u2013 multiple platforms, versions prior to 2.22.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-188","alert_type":396,"serial_number":"AV25-188","subject":"dell","moderation_state":"published","external_url":null},{"nid":6265,"title":"IBM security advisory (AV25-189)","uuid":"3d9f6039-4f69-46b2-abf6-9076c240d901","banner":null,"lang":"en","date_modified":"2025-04-07","date_modified_ts":"2025-04-07T18:23:41Z","date_created":"2025-04-07T17:16:30Z","summary":null,"body":["<article data-history-node-id=\"6265\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-189\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-189<br \/><strong>Date: <\/strong>April\u00a07, 2025<\/p>\n\n<p>Between March\u00a031 and April\u00a06, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Business Automation Manager Open Editions\u00a0\u2013 versions 9.0.0 to 9.1.1<\/li>\n\t<li>IBM API Connect\u00a0\u2013 versions V10.0.0.5.0 to V10.0.5.8 and versions V10.0.8.0 to 10.0.8.2<\/li>\n\t<li>IBM App Connect Enterprise\u00a0\u2013 versions 13.0.1.0 to 13.0.2.2 and versions 12.0.1.0 to 12.0.12.11<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0\u2013 versions 4.0.0 to 5.1.1<\/li>\n\t<li>InfoSphere Information Server\u00a0\u2013 version 11.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-189","alert_type":396,"serial_number":"AV25-189","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6266,"title":"Ubuntu security advisory (AV25-190)","uuid":"d5c6c693-1b19-4f5d-b5c3-dae68e0e385e","banner":null,"lang":"en","date_modified":"2025-04-07","date_modified_ts":"2025-04-07T18:27:30Z","date_created":"2025-04-07T17:17:11Z","summary":null,"body":["<article data-history-node-id=\"6266\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-190\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-190<br \/><strong>Date: <\/strong>April\u00a07, 2025<\/p>\n\n<p>Between March\u00a031 and April\u00a06, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-190","alert_type":396,"serial_number":"AV25-190","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6267,"title":"[Control systems] ABB security advisory (AV25-191)","uuid":"ebc0b699-ba8e-4664-a31f-9c3e7b6e0696","banner":null,"lang":"en","date_modified":"2025-04-07","date_modified_ts":"2025-04-07T19:07:29Z","date_created":"2025-04-07T19:00:37Z","summary":null,"body":["<article data-history-node-id=\"6267\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-191\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-191<br \/><strong>Date: <\/strong>April\u00a07, 2025<\/p>\n\n<p>On April\u00a07, 2025, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB M2M Gateway ARM600\u00a0\u2013 firmware versions 4.1.2 to 5.0.3<\/li>\n\t<li>ABB M2M Gateway SW\u00a0\u2013 versions 5.0.1 to 5.0.3<\/li>\n\t<li>Arctic Wireless Gateways ARG600, ARC600, ARR600 with Telit PLS62-W wireless modem module<\/li>\n\t<li>Arctic ARG600, ARC600, ARR600, ARP600\u00a0\u2013 firmware versions 3.4.10, 3.4.11, 3.4.12 and 3.4.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA002427&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">ABB Cyber Security Advisory - ABB Arctic ARG600, ARC600, ARR600, ARP600 Arctic Wireless Gateway Modem Module and OpenSSH vulnerabilities (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA002579&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">ABB Cyber Security Advisory - ABB Arctic communication solution ARM600 Vulnerabilities (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-191","alert_type":398,"serial_number":"AV25-191","subject":"abb","moderation_state":"published","external_url":null},{"nid":6268,"title":"SAP security advisory \u2013 April 2025 monthly rollup (AV25-192) \u2013 Update 1","uuid":"e0dcb72e-a336-430c-bfa3-4df3247f9ed4","banner":null,"lang":"en","date_modified":"2025-04-25","date_modified_ts":"2025-04-25T15:33:52Z","date_created":"2025-04-08T16:00:16Z","summary":null,"body":["<article data-history-node-id=\"6268\" about=\"\/en\/alerts-advisories\/sap-security-advisory-april-2025-monthly-rollup-av25-192\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-192<br \/><strong>Date: <\/strong>April\u00a08, 2025<br \/><strong>Updated:<\/strong> April 25, 2025<\/p>\n\n<p>On April\u00a08, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Capital Yield Tax Management\u00a0\u2013 versions CYTERP 420_700, CYT 800, IBS 7.0 and CYT4HANA 100<\/li>\n\t<li>SAP Commerce Cloud\u00a0\u2013 versions HY_COM 2205 and COM_CLOUD 2211<\/li>\n\t<li>SAP Financial Consolidation\u00a0\u2013 version 1010<\/li>\n\t<li>SAP Landscape Transformation DMIS\u00a0\u2013 versions 2011_1_700, 2011_1_710, 2011_1_730 and 2011_1_731<\/li>\n\t<li>SAP NetWeaver and ABAP Platform (Service Data Collection)\u00a0\u2013 versions ST-PI 2008_1_700, 2008_1_710 and 740<\/li>\n\t<li>SAP NetWeaver Application Server ABAP\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89 and 7.93<\/li>\n\t<li>SAP S\/4HANA S4CORE\u00a0\u2013 versions 102, 103, 104, 105, 106, 107 and 108<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On April 24, 2025, SAP updated their security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SAP NetWeaver (Visual Composer development server) \u2013 version VCFRAMEWORK 7.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/april-2025.html\">SAP Security Patch Day\u00a0\u2013 April 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-april-2025-monthly-rollup-av25-192","alert_type":396,"serial_number":"AV25-192","subject":"sap","moderation_state":"published","external_url":null},{"nid":6269,"title":"[Control systems] Schneider Electric security advisory (AV25-193)","uuid":"59954dac-80e2-4f71-93e9-9826026f2403","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T16:17:09Z","date_created":"2025-04-08T16:00:17Z","summary":null,"body":["<article data-history-node-id=\"6269\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-193\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-193<br \/><strong>Date: <\/strong>April\u00a08, 2025<\/p>\n\n<p>On April\u00a08, 2025, Schneider Electric published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>ConneXium Network Manager\u00a0\u2013 all versions<\/li>\n\t<li>Trio Q Licensed Data Radio\u00a0\u2013 versions prior to v2.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-098-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-098-01.pdf\">Schneider Electric Security Notification\u00a0- ConneXium Network Manager Software (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-098-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-098-02.pdf\">Schneider Electric Security Notification\u00a0- Trio Q Licensed Data Radios (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-193","alert_type":398,"serial_number":"AV25-193","subject":"se","moderation_state":"published","external_url":null},{"nid":6270,"title":"[Control systems] Siemens security advisory (AV25-194) ","uuid":"afe0a4ea-326d-4dff-a6de-352f2ec75d6f","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T17:34:48Z","date_created":"2025-04-08T17:03:53Z","summary":null,"body":["<article data-history-node-id=\"6270\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-194\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-194<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2025<\/p>\n\n<p>On April 8, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Industrial Edge Device Kit\u00a0- arm64 and x86-64\u00a0\u2013 multiple versions<\/li>\n\t<li>Industrial Edge Own Device\u00a0\u2013 versions prior to V1.21.1-1-a<\/li>\n\t<li>Industrial Edge Virtual Device\u00a0\u2013 versions prior to V1.21.1-1-a<\/li>\n\t<li>Insights Hub Private Cloud\u00a0\u2013 all versions<\/li>\n\t<li>Mendix Runtime V8\u00a0\u2013 all versions<\/li>\n\t<li>Mendix Runtime V9\u00a0\u2013 versions prior to V9.24.34<\/li>\n\t<li>Mendix Runtime V10\u00a0\u2013 versions prior to V10.21.0<\/li>\n\t<li>Mendix Runtime V10.6, V10.12 and V10.18\u00a0\u2013 all versions<\/li>\n\t<li>SCALANCE LPE9413\u00a0\u2013 all versions<\/li>\n\t<li>SENTRON 7KT PAC1260 Data Manager\u00a0\u2013 all versions<\/li>\n\t<li>SIDIS Prime\u00a0\u2013 versions prior to V4.0.700<\/li>\n\t<li>SIDOOR\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens License Server\u00a0\u2013 versions prior to V4.3<\/li>\n\t<li>SIMATIC CFU\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC ET\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC IPC Industrial Edge Device\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC PN\/PN Coupler\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC Power Line Booster Base Module and Modem Module ST\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC S7\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC TDC CP51M1 and CPU555\u00a0\u2013 all versions<\/li>\n\t<li>SIMOCODE pro V Ethernet\/IP and PROFINET\u00a0\u2013 all versions<\/li>\n\t<li>SINUMERIK 840D sl\u00a0\u2013 all versions<\/li>\n\t<li>SIPLUS HCS4200 and HCS4300\u00a0\u2013 all versions<\/li>\n\t<li>SIPLUS NET PN\/PN Coupler\u00a0\u2013 all versions<\/li>\n\t<li>SIWAREX\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Solid Edge SE2024\u00a0\u2013 versions prior to V224.0 Update 12<\/li>\n\t<li>Solid Edge SE2025\u00a0\u2013 versions prior to V225.0 Update 3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-194","alert_type":398,"serial_number":"AV25-194","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6271,"title":"Android security advisory \u2013 April 2025 monthly rollup (AV25-195)","uuid":"f1527993-e3c8-4cce-a208-04c82b360075","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T17:54:06Z","date_created":"2025-04-08T17:46:43Z","summary":null,"body":["<article data-history-node-id=\"6271\" about=\"\/en\/alerts-advisories\/android-security-advisory-april-2025-monthly-rollup-av25-195\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-195<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2025<\/p>\n\n<p>On April 7, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>Google has indicated that CVE-2024-53150 and CVE-2024-53197 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-04-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-april-2025-monthly-rollup-av25-195","alert_type":396,"serial_number":"AV25-195","subject":"android","moderation_state":"published","external_url":null},{"nid":6275,"title":"Ivanti security advisory (AV25-198)","uuid":"3a485b7d-85cf-41ac-a6eb-ce7251af06c8","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T19:08:19Z","date_created":"2025-04-08T18:17:19Z","summary":null,"body":["<article data-history-node-id=\"6275\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-198\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-198<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2025<\/p>\n\n<p>On April 8, 2025, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager\u00a0\u2013 version 2024 and version 2022 SU6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US\">Security Advisory April 2025 for Ivanti EPM 2024 and EPM 2022 SU6<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#t=All&amp;sort=date%20descending&amp;f:@sfkbknowledgearticletypec=[Security%20Advisory]\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-198","alert_type":396,"serial_number":"AV25-198","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6272,"title":"VMware security advisory (AV25-196)","uuid":"4279c484-d245-4466-9fe2-e4b0cdd43a1d","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T18:53:52Z","date_created":"2025-04-08T18:29:16Z","summary":null,"body":["<article data-history-node-id=\"6272\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-196\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-196<br \/><strong>Date: <\/strong>April\u00a08, 2025<\/p>\n\n<p>On April\u00a07, 2025, VMware released security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 6.29.0<\/li>\n\t<li>VMware Tanzu Greenplum Backup and Restore\u00a0\u2013 versions prior to 1.31.0<\/li>\n\t<li>VMware Tanzu Greenplum Platform Extension Framework\u00a0\u2013 versions prior to 6.11.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25580\">Product Release Advisory\u00a0- VMware Tanzu Greenplum Backup and Restore 1.31.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25581\">Product Release Advisory\u00a0- VMware Tanzu Greenplum 6.29.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-196","alert_type":396,"serial_number":"AV25-196","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6273,"title":"Fortinet security advisory (AV25-197)","uuid":"a256f872-a83c-449e-a982-a46b00b8308c","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T18:57:52Z","date_created":"2025-04-08T18:29:16Z","summary":null,"body":["<article data-history-node-id=\"6273\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-197\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-197<br \/><strong>Date: <\/strong>April\u00a08, 2025<\/p>\n\n<p>On April\u00a08, 2025, Fortinet published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>FortiSwitch 7.6\u00a0\u2013 version 7.6.0<\/li>\n\t<li>FortiSwitch 7.4\u00a0\u2013 versions 7.4.0 to 7.4.4<\/li>\n\t<li>FortiSwitch 7.2\u00a0\u2013 versions 7.2.0 to 7.2.8<\/li>\n\t<li>FortiSwitch 7.0\u00a0\u2013 versions 7.0.0 to 7.0.10<\/li>\n\t<li>FortiSwitch 6.4\u00a0\u2013 versions 6.4.0 to 6.4.14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-435\">Fortinet PSIRT\u00a0- FG-IR-24-435 (CVE-2024-48887)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-197","alert_type":396,"serial_number":"AV25-197","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6274,"title":"Adobe security advisory (AV25\u2013199)","uuid":"db23e31d-0a31-417a-a412-c18dad992fca","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T19:13:35Z","date_created":"2025-04-08T18:51:50Z","summary":null,"body":["<article data-history-node-id=\"6274\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-199\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-199<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2025<\/p>\n\n<p>On April 8, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe After Effects \u2013 version 24.6.4 and prior and version 25.1 and prior<\/li>\n\t<li>Adobe Animate 2024 \u2013 version 24.0.7 and prior<\/li>\n\t<li>Adobe Animate 2023 \u2013 version 23.0.10 and prior<\/li>\n\t<li>Adobe Bridge \u2013 version 14.1.5 and prior and version 15.0.2 and prior<\/li>\n\t<li>Adobe Commerce \u2013 multiple versions<\/li>\n\t<li>Adobe Commerce B2B \u2013 multiple versions<\/li>\n\t<li>Adobe Experience Manager Forms on JEE \u2013 version 6.5.22.0 (AEMForms-6.5.0-0093) and prior<\/li>\n\t<li>Adobe Experience Manager Screens \u2013 version AEM 6.5 Screens FP11.3 and prior<\/li>\n\t<li>Adobe FrameMaker \u2013 version 2022 Release Update 5 and prior<\/li>\n\t<li>Adobe FrameMaker \u2013 version 2020 Release Update 7 and prior<\/li>\n\t<li>Adobe Media Encoder \u2013 version 24.6.4 and prior and version 25.1 and prior<\/li>\n\t<li>Adobe Premiere Pro \u2013 version 25.1 and prior and version 24.6.4 and prior<\/li>\n\t<li>Adobe XMP-Toolkit-SDK \u2013 version 2023.12 and prior<\/li>\n\t<li>ColdFusion 2025 \u2013 version build 331385<\/li>\n\t<li>ColdFusion 2023 \u2013 version Update 12 and prior<\/li>\n\t<li>ColdFusion 2021 \u2013 version Update 18 and prior<\/li>\n\t<li>Magento Open Source \u2013 multiple versions<\/li>\n\t<li>Photoshop 2025 \u2013 version 26.4.1 and prior<\/li>\n\t<li>Photoshop 2024 \u2013 version 25.12.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-199","alert_type":396,"serial_number":"AV25-199","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6276,"title":"Google Chrome security advisory (AV25-200)","uuid":"fd398862-3704-4c0d-b5ee-0dcedb60e7f0","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T19:14:48Z","date_created":"2025-04-08T19:05:42Z","summary":null,"body":["<article data-history-node-id=\"6276\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-200\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-200<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2025<\/p>\n\n<p>On April 8, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 0.7049.84\/85 (Windows\/Mac), and 135.0.7049.84 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/04\/stable-channel-update-for-desktop_8.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-200","alert_type":396,"serial_number":"AV25-200","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6277,"title":"Microsoft security advisory - April 2025 monthly rollup (AV25-201)","uuid":"d3e51595-33e1-473b-8536-f92fc2fba542","banner":null,"lang":"en","date_modified":"2025-04-08","date_modified_ts":"2025-04-08T19:33:37Z","date_created":"2025-04-08T19:15:59Z","summary":null,"body":["<article data-history-node-id=\"6277\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2025-monthly-rollup-av25-201\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-201<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 8, 2025<\/p>\n\n<p>On April 8, 2025, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft<\/span> published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps\u00a0- multiple versions and platforms<\/li>\n\t<li>Microsoft Office\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 10\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0- multiple versions and platforms<\/li>\n\t<li>Windows Server\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2025-29824 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Apr\">April 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-april-2025-monthly-rollup-av25-201","alert_type":396,"serial_number":"AV25-201","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6278,"title":"Juniper Networks security advisory (AV25-202)","uuid":"afefabeb-9ee7-4e32-9bd9-188c297abf63","banner":null,"lang":"en","date_modified":"2025-04-09","date_modified_ts":"2025-04-09T18:52:25Z","date_created":"2025-04-09T18:48:56Z","summary":null,"body":["<article data-history-node-id=\"6278\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-202\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-202<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 9, 2025<\/p>\n\n<p>On April 9, 2025, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>CTP View \u2013 versions prior to 9.2R1<\/li>\n\t<li>Junos OS \u2013 multiple versions<\/li>\n\t<li>Junos OS Evolved \u2013 multiple versions<\/li>\n\t<li>Junos OS on EX and QFX5k Series \u2013 multiple versions<\/li>\n\t<li>Junos OS on MX Series \u2013 multiple versions<\/li>\n\t<li>Juno OS on SRX Series \u2013 multiple versions<\/li>\n\t<li>Junos Space \u2013 versions prior to 24.1R3<\/li>\n\t<li>Junos Space Security Director \u2013 versions prior to 24.1R3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-202","alert_type":396,"serial_number":"AV25-202","subject":"juniper","moderation_state":"published","external_url":null},{"nid":6279,"title":"Palo Alto Networks security advisory (AV25-203)","uuid":"5260f991-5808-45df-b4ee-7840b49ba2ac","banner":null,"lang":"en","date_modified":"2025-04-09","date_modified_ts":"2025-04-09T18:58:24Z","date_created":"2025-04-09T18:54:12Z","summary":null,"body":["<article data-history-node-id=\"6279\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-203\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-203<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 9, 2025<\/p>\n\n<p>On April 9, 2025, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Prisma Access Browser \u2013 versions prior to 132.83.3017.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0008\">Palo Alto Networks Security Advisories - PAN-SA-2025-0008<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-203","alert_type":396,"serial_number":"AV25-203","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6280,"title":"Drupal security advisory (AV25-204)","uuid":"3efd6069-b8b3-4e38-a541-fdf33ea2b646","banner":null,"lang":"en","date_modified":"2025-04-10","date_modified_ts":"2025-04-10T17:37:21Z","date_created":"2025-04-10T15:50:24Z","summary":null,"body":["<article data-history-node-id=\"6280\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-204\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-204<br \/><strong>Date: <\/strong>April\u00a010, 2025<\/p>\n\n<p>On April\u00a09, 2025, Drupal published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>ECA\u00a0: Event\u00a0- Condition\u00a0- Action\u00a0\u2013 versions 1.2.x, versions prior to 1.1.12, version 2.0.0 to versions prior to 2.0.16 and version 2.1.0 to versions prior to 2.1.7<\/li>\n\t<li>Panels\u00a0\u2013 versions prior to 4.9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-031\">ECA: Event\u00a0- Condition\u00a0- Action\u00a0- Critical\u00a0- Cross site request forgery\u00a0- SA-CONTRIB-2025-031<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-033\">Panels\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-033<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-204","alert_type":396,"serial_number":"AV25-204","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6281,"title":"HPE security advisory (AV25-205)","uuid":"4a60728f-ec50-4326-b271-31de000ac71e","banner":null,"lang":"en","date_modified":"2025-04-10","date_modified_ts":"2025-04-10T17:44:23Z","date_created":"2025-04-10T15:50:24Z","summary":null,"body":["<article data-history-node-id=\"6281\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-205\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-205<br \/><strong>Date: <\/strong>April 10, 2025<\/p>\n\n<p>On April 9, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Cray XD670 \u2013 versions prior to BMC v1.19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04848en_us&amp;docLocale=en_US\">HPE Security Bulletin - HPESBCR04848<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-205","alert_type":396,"serial_number":"AV25-205","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6283,"title":"Compromise and persistent access of Fortinet FortiOS products (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762)","uuid":"9158d8a0-bc84-471a-a6e9-4f818cab11ed","banner":null,"lang":"en","date_modified":"2025-04-14","date_modified_ts":"2025-04-14T14:41:17Z","date_created":"2025-04-14T14:32:47Z","summary":null,"body":["<article data-history-node-id=\"6283\" about=\"\/en\/alerts-advisories\/compromise-persistent-access-fortinet-fortios-products-cve-2022-42475-cve-2023-27997-cve-2024-21762\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><h2>Alert<\/h2>\n\n<p><strong>Number:<\/strong> AL25-005<br \/><strong>Date:<\/strong> April 14, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On April 10, 2025, Fortinet released a PSIRT blog<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> describing widespread exploitation of vulnerabilities in Fortinet FortiOS products going back to 2023. Threat actors have compromised vulnerable devices and maintained persistence even after patches were applied, potentially accessing sensitive files including credentials and key material.<\/p>\n\n<p>CVE-2022-42475<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>, CVE-2023-27997<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> and CVE-2024-21762<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> are all previous CVEs that have been exploited through this malicious activity. CCCS had published respective advisories for each one of them.<\/p>\n\n<p>The following Fortinet products are affected by this vulnerability:<\/p>\n\n<ul><li>FortiOS \u2013 versions 7.4, 7.2, 7.0 and 6.4<\/li>\n<\/ul><p>Note that customers who have not enabled SSL-VPN are not impacted by this vulnerability.<\/p>\n\n<h2>Suggested Actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations patch their FortiOS to the following versions:<\/p>\n\n<ul><li>FortiOS \u2013 versions 7.6.2, 7.4.7, 7.2.11 &amp; 7.0.17 or 6.4.16<\/li>\n<\/ul><p>It is imperative for organizations to identify and prioritize the patching of vulnerable systems promptly, using the following links:<\/p>\n\n<ul><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-398\">Fortinet PSIRT Advisory (FG-IR-22-398)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-23-097\">Fortinet PSIRT Advisory (FG-IR-23-097) <\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-015\">Fortinet PSIRT Advisory (FG-IR-24-015) <\/a><\/li>\n<\/ul><h2>Recommendations:<\/h2>\n\n<ul><li>Reset credentials: Assume compromise<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> and reset all credentials associated with SSL-VPN functionality, affected devices, user accounts, LDAP bind credentials, and pre-shared keys.<\/li>\n\t<li>Apply updates: Apply the latest updates to remove the malicious file and enable automatic updates for OS and AV\/IPS.<\/li>\n\t<li>Review and monitor: Review the vendor advisory <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. Review logging for unauthorized SSL VPN access, including configurations for any unauthorized changes, and review network logging for known indicators of compromise.<\/li>\n\t<li>Disable or limit access: Disable SSL-VPN functionality if not required, limit access to trusted IP ranges, and disable administrative access to any external (Internet-facing) interface.<\/li>\n<\/ul><p>The Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Assess the installations of the affected Fortinet products and monitor for signs of exploitation.<\/li>\n\t<li>Apply software patches to affected Fortinet products as soon as they become available.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> with an emphasis on the following strategies:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways.<\/li>\n\t<li>Patch operating systems and applications.<\/li>\n\t<li>Isolate web-facing applications.<\/li>\n<\/ul><p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>Partner Reporting<\/h2>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ncsc.govt.nz\/news\/cves-fortinet-products\">NCSC NZ \u2013 CVEs affecting Fortinet FortiOS products<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cert.govt.nz\/advisories\/malicious-activity-due-to-previously-exploited-vulnerabilities-in-fortinet-fortios-products\/\">CERT NZ \u2013 Malicious activity due to previously exploited vulnerabilities in Fortinet FortiOS products<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/04\/11\/fortinet-releases-advisory-new-post-exploitation-technique-known-vulnerabilities\">CISA \u2013 Fortinet releases advisory on new post-exploitation technique for known vulnerabilities<\/a><\/li>\n<\/ul><h2>About The Cyber Centre<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security, and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses, and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.fortinet.com\/blog\/psirt-blogs\/analysis-of-threat-actor-activity\">Fortinet - Analysis of Threat Actor Activity (CVE-2022-42475, CVE-2023-27997 and CVE-224-21762)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/fortinet-security-advisory-av22-693\">Fortinet security advisory (AV22-693) <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/fortinet-security-advisory-av23-330\">Fortinet security advisory (AV23-330) <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/fortinet-security-advisory-av24-074\">Fortinet security advisory (AV24-074) <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/community.fortinet.com\/t5\/FortiGate\/Technical-Tip-Recommended-steps-to-execute-in-case-of-a\/ta-p\/230694\">Fortinet - Technical Tip: Recommended steps to execute in case of a compromised host<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/compromise-persistent-access-fortinet-fortios-products-cve-2022-42475-cve-2023-27997-cve-2024-21762","alert_type":397,"serial_number":"AL25-005","subject":"other","moderation_state":"published","external_url":null},{"nid":6284,"title":"Ubuntu security advisory (AV25-206)","uuid":"d8b37cec-0c61-4548-856d-83f9301873fe","banner":null,"lang":"en","date_modified":"2025-04-14","date_modified_ts":"2025-04-14T15:51:27Z","date_created":"2025-04-14T15:26:52Z","summary":null,"body":["<article data-history-node-id=\"6284\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-206\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-206<br \/><strong>Date:<\/strong> April\u00a014, 2025<\/p>\n\n<p>Between April 7\u00a0and 13, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-206","alert_type":396,"serial_number":"AV25-206","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6285,"title":"[Control systems] CISA ICS security advisories (AV25\u2013207)","uuid":"2c2f061c-a8e7-4e05-9d5b-b6b4377663ad","banner":null,"lang":"en","date_modified":"2025-04-14","date_modified_ts":"2025-04-14T15:55:55Z","date_created":"2025-04-14T15:26:53Z","summary":null,"body":["<article data-history-node-id=\"6285\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-207\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-207<br \/><strong>Date: <\/strong>April\u00a014, 2025<\/p>\n\n<p>Between April\u00a07 and 13, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>INFINITT Healthcare PACS System Manager\u00a0\u2013 versions 3.0.11.5 BN9 and prior<\/li>\n\t<li>Rockwell Automation Arena\u00a0\u2013 versions 16.20.08 and prior<\/li>\n\t<li>Subnet Solutions PowerSYSTEM Center 2020\u00a0\u2013 versions 5.24.x and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-207","alert_type":398,"serial_number":"AV25-207","subject":"ics","moderation_state":"published","external_url":null},{"nid":6286,"title":"Dell security advisory (AV25-208)","uuid":"2b55274e-ded2-479a-b38f-00ed18516a97","banner":null,"lang":"en","date_modified":"2025-04-14","date_modified_ts":"2025-04-14T16:11:02Z","date_created":"2025-04-14T15:26:53Z","summary":null,"body":["<article data-history-node-id=\"6286\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-208\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV25-208<br \/><strong>Date:<\/strong> April\u00a014, 2025<\/p>\n\n<p>Between April\u00a07 and 13, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen5a\u00a0\u2013 version ADS Gen5A<\/li>\n\t<li>Dell Integrated System for Microsoft Azure Stack HCI\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell Integrated System for Microsoft Azure Stack Hub 16G\u00a0\u2013 versions prior to 2502<\/li>\n\t<li>Dell iDRAC9\u00a0\u2013 versions prior to 7.00.00.181 and 7.20.30.50<\/li>\n\t<li>Dell NetWorker Management Console\u00a0\u2013 versions prior to 19.11.04 and 19.12.0.1<\/li>\n\t<li>Dell PowerProtect Cyber Recovery Software\u00a0\u2013 versions prior to 19.18.0.2<\/li>\n\t<li>Dell PowerProtect Data Manager DM5500 Appliance Software\u00a0\u2013 versions prior to 5.19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-208","alert_type":396,"serial_number":"AV25-208","subject":"dell","moderation_state":"published","external_url":null},{"nid":6287,"title":"IBM security advisory (AV25-209)","uuid":"c501bb2a-ac87-4795-a471-2df15d5b8cbc","banner":null,"lang":"en","date_modified":"2025-04-14","date_modified_ts":"2025-04-14T16:15:40Z","date_created":"2025-04-14T15:26:53Z","summary":null,"body":["<article data-history-node-id=\"6287\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-209\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-209<br \/><strong>Date: <\/strong>April\u00a014, 2025<\/p>\n\n<p>Between April\u00a07 and 13, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Business Automation Manager Open Editions\u00a0\u2013 versions 8.0.0 to 8.0.6<\/li>\n\t<li>IBM Guardium Data Protection\u00a0\u2013 version 11.4, 12.0 and 12.1<\/li>\n\t<li>IBM Integration Bus for z\/OS\u00a0\u2013 versions 10.1.0.0 to 10.1.0.5<\/li>\n\t<li>IBM PCOMM\u00a0\u2013 versions v14.x and v15.x<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 versions 2.0.0 IF001 and 2.0.0<\/li>\n\t<li>IBM Storage Protect Plus\u00a0\u2013 versions 10.1.0. to 10.1.16<\/li>\n\t<li>IBM Storage Protect Server\u00a0\u2013 version 8.1<\/li>\n\t<li>IBM Storage Scale\u00a0\u2013 versions 5.1.7.0 to 5.1.9.8 and 5.2.0.0 to 5.2.2.0<\/li>\n\t<li>IBM Security Verify Governance\u00a0\u2013 version ISVG 10.02<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager Software Stack\u00a0\u2013 version ISVG 10.02<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager Virtual Appliance\u00a0\u2013 version ISVG 10.02<\/li>\n\t<li>IBM Security Verify Governance Identity Manager Container\u00a0\u2013 version ISVG 10.02<\/li>\n\t<li>IBM watsonx Code Assistant IDE Extensions\u00a0\u2013 version 0.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-209","alert_type":396,"serial_number":"AV25-209","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6288,"title":"Red Hat security advisory (AV25-210)","uuid":"63905184-efaf-46be-b963-13e52146694c","banner":null,"lang":"en","date_modified":"2025-04-14","date_modified_ts":"2025-04-14T16:20:23Z","date_created":"2025-04-14T15:26:53Z","summary":null,"body":["<article data-history-node-id=\"6288\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-210\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-210<br \/><strong>Date: <\/strong>April\u00a014, 2025<\/p>\n\n<p>Between April\u00a07 and 13, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:3832\">RHSA-2025:3832\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-210","alert_type":396,"serial_number":"AV25-210","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6289,"title":"Microsoft Edge security advisory (AV25-211)","uuid":"5d05117a-d9af-4548-a0be-ceb65593d3f9","banner":null,"lang":"en","date_modified":"2025-04-14","date_modified_ts":"2025-04-14T20:02:44Z","date_created":"2025-04-14T19:56:54Z","summary":null,"body":["<article data-history-node-id=\"6289\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-211\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-211<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 14, 2025<\/p>\n\n<p>On April 11, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 0.3179.73<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-11-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-211","alert_type":396,"serial_number":"AV25-211","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6290,"title":"Mozilla security advisory (AV25-212)","uuid":"9eb3bd4e-84e8-46e8-b5b2-ccbbdeebf375","banner":null,"lang":"en","date_modified":"2025-04-15","date_modified_ts":"2025-04-15T14:40:30Z","date_created":"2025-04-15T14:37:48Z","summary":null,"body":["<article data-history-node-id=\"6290\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-212\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-212<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 15, 2025<\/p>\n\n<p>On April 15, 2025, Mozilla published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 137.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-25\/\">Mozilla Security Advisory (MFSA 2025-25 \u2013 CVE-2025-3608)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-212","alert_type":396,"serial_number":"AV25-212","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6291,"title":"Apache security advisory (AV25-213)","uuid":"3e1c6ff8-f2a6-44de-a218-6508fb2777f5","banner":null,"lang":"en","date_modified":"2025-04-15","date_modified_ts":"2025-04-15T17:18:40Z","date_created":"2025-04-15T17:15:05Z","summary":null,"body":["<article data-history-node-id=\"6291\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av25-213\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-213<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 15, 2025<\/p>\n\n<p>On April 11, 2025, Apache published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Apache Roller \u2013 versions prior to 6.1.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/vxv52vdr8nhtjlj6v02w43fdvo0cxw23\">Apache Roller 6.1.5<\/a><\/li>\n\t<li><a href=\"https:\/\/lists.apache.org\/thread\/4j906k16v21kdx8hk87gl7663sw7lg7f\">Apache Security Bulletins<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-24859\">CVE-2025-24859<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av25-213","alert_type":396,"serial_number":"AV25-213","subject":"other","moderation_state":"published","external_url":null},{"nid":6292,"title":"Oracle security advisory \u2013 April 2025 quarterly rollup (AV25-214)","uuid":"af83b7a9-7885-4f48-8550-e868c5d7e964","banner":null,"lang":"en","date_modified":"2025-04-16","date_modified_ts":"2025-04-16T14:25:40Z","date_created":"2025-04-16T14:21:53Z","summary":null,"body":["<article data-history-node-id=\"6292\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-april-2025-quarterly-rollup-av25-214\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-214<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 16, 2025<\/p>\n\n<p>On April 15, 2025, Oracle published a security advisory to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Oracle Analytics<\/li>\n\t<li>Oracle Application Express<\/li>\n\t<li>Oracle Autonomous Health Framework<\/li>\n\t<li>Oracle Commerce<\/li>\n\t<li>Oracle Communications Applications<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Construction and Engineering<\/li>\n\t<li>Oracle E-Business Suite<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Food and Beverage Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle GoldenGate<\/li>\n\t<li>Oracle Hospitality Applications<\/li>\n\t<li>Oracle Hyperion<\/li>\n\t<li>Oracle Insurance Applications<\/li>\n\t<li>Oracle Java SE<\/li>\n\t<li>Oracle JD Edwards<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle PeopleSoft<\/li>\n\t<li>Oracle Policy Automation<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Siebel CRM<\/li>\n\t<li>Oracle Solaris<\/li>\n\t<li>Oracle SQL Developer<\/li>\n\t<li>Oracle Supply Chain<\/li>\n\t<li>Oracle Support Tools<\/li>\n\t<li>Oracle TimesTen In-Memory Database<\/li>\n\t<li>Oracle Utilities<\/li>\n\t<li>Oracle Virtualization<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2025.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 April 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-april-2025-quarterly-rollup-av25-214","alert_type":396,"serial_number":"AV25-214","subject":"oracle","moderation_state":"published","external_url":null},{"nid":6293,"title":"[Control systems] Siemens security advisory (AV25-215) ","uuid":"98d40a4a-8e50-42b4-b276-b08dc6d089c0","banner":null,"lang":"en","date_modified":"2025-04-16","date_modified_ts":"2025-04-16T14:30:37Z","date_created":"2025-04-16T14:27:21Z","summary":null,"body":["<article data-history-node-id=\"6293\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-215\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-215<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 16, 2025<\/p>\n\n<p>On April 16, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>TeleControl Server Basic \u2013 versions prior to V3.1.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-443402.html\">Siemens Security Advisory - SSA-443402<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-215","alert_type":398,"serial_number":"AV25-215","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6294,"title":"Google Chrome security advisory (AV25-216)","uuid":"e35faee4-656c-477b-9284-27264319bd6f","banner":null,"lang":"en","date_modified":"2025-04-16","date_modified_ts":"2025-04-16T14:35:19Z","date_created":"2025-04-16T14:32:52Z","summary":null,"body":["<article data-history-node-id=\"6294\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-216\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-216<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 16, 2025<\/p>\n\n<p>On April 15, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 135.0.7049.95\/96 (Windows\/Mac), and 135.0.7049.95 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/04\/stable-channel-update-for-desktop_15.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-216","alert_type":396,"serial_number":"AV25-216","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6295,"title":"Atlassian security advisory (AV25-217)","uuid":"2a5572cd-2a3f-4bdb-a280-1c8569784620","banner":null,"lang":"en","date_modified":"2025-04-16","date_modified_ts":"2025-04-16T17:37:38Z","date_created":"2025-04-16T17:30:31Z","summary":null,"body":["<article data-history-node-id=\"6295\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-217\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-217<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 16, 2025<\/p>\n\n<p>On April 15, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-april-15-2025-1540723536.html\">Atlassian Security Bulletin \u2013 April 15 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-217","alert_type":396,"serial_number":"AV25-217","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6296,"title":"Apple security advisory (AV25-218)","uuid":"1729ca38-f767-42d4-a74a-596c757d3cdf","banner":null,"lang":"en","date_modified":"2025-04-16","date_modified_ts":"2025-04-16T18:59:20Z","date_created":"2025-04-16T18:56:13Z","summary":null,"body":["<article data-history-node-id=\"6296\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-218\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-218<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 16, 2025<\/p>\n\n<p>On April 16, 2025, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS \u2013 versions prior to 18.4.1<\/li>\n\t<li>macOS Sequoia \u2013 versions prior to 15.4.1<\/li>\n<\/ul><p>Apple has been advised that CVE-2025-31200 and CVE-2025-31201 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100 \">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-218","alert_type":396,"serial_number":"AV25-218","subject":"apple","moderation_state":"published","external_url":null},{"nid":6297,"title":"Cisco security advisory (AV25-219)","uuid":"f66fcc8d-9252-4256-8cdb-6ea02ba5b830","banner":null,"lang":"en","date_modified":"2025-04-17","date_modified_ts":"2025-04-17T15:41:27Z","date_created":"2025-04-17T15:33:16Z","summary":null,"body":["<article data-history-node-id=\"6297\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-219\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-219<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 17, 2025<\/p>\n\n<p>On April 16, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>Cisco Webex App\u00a0\u2013 versions 44.6 and 44.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-webex-app-client-rce-ufyMMYLC\">Cisco Security Advisory\u00a0\u2013 cisco-sa-webex-app-client-rce-ufyMMYLC<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-219","alert_type":396,"serial_number":"AV25-219","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6301,"title":"IBM security advisory (AV25-223)","uuid":"9f9fa188-25e3-46ad-98ab-d3132647ba6d","banner":null,"lang":"en","date_modified":"2025-04-22","date_modified_ts":"2025-04-22T18:40:49Z","date_created":"2025-04-22T17:52:42Z","summary":null,"body":["<article data-history-node-id=\"6301\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-223\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-223<br \/><strong>Date: <\/strong>April\u00a022, 2025<\/p>\n\n<p>Between April\u00a014 and 20, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM App Connect Enterprise\u00a0\u2013 versions 12.0.1.0 to 12.0.12.12 and 13.0.1.0 to 13.0.2.2<\/li>\n\t<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 version 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 multiple versions<\/li>\n\t<li>PowerVC\u00a0\u2013 versions 2.1.1.2, 2.2.0, 2.2.1, 2.2.1.1 and 2.3.0<\/li>\n\t<li>QRadar Suite Software\u00a0\u2013 version 1.10.12.0 to 1.11.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-223","alert_type":396,"serial_number":"AV25-223","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6302,"title":"Dell security advisory (AV25-224)","uuid":"ef9b42eb-a387-454f-9563-d74260f5aaf2","banner":null,"lang":"en","date_modified":"2025-04-22","date_modified_ts":"2025-04-22T18:42:20Z","date_created":"2025-04-22T17:52:43Z","summary":null,"body":["<article data-history-node-id=\"6302\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-224\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-224<br \/><strong>Date:<\/strong> April\u00a022, 2025<\/p>\n\n<p>Between April\u00a014 and 20, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Dell Data Lakehouse\u00a0\u2013 versions prior to 1.4.0.0<\/li>\n\t<li>Dell Storage Resource Manager\u00a0\u2013 versions prior to 5.1.0.0<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 5.1.0.0<\/li>\n\t<li>PowerStore 1000X\u00a0\u2013 versions prior to 3.2.1.6-2476179<\/li>\n\t<li>PowerStore 3000X\u00a0\u2013 versions prior to 3.2.1.6-2476179<\/li>\n\t<li>PowerStore 5000X\u00a0\u2013 versions prior to 3.2.1.6-2476179<\/li>\n\t<li>PowerStore 7000X\u00a0\u2013 versions prior to 3.2.1.6-2476179<\/li>\n\t<li>PowerStore 9000X\u00a0\u2013 versions prior to 3.2.1.6-2476179<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000309323\/dsa-2025-165-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">DSA-2025-165: Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR) Security Update for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000308870\/dsa-2025-182-dell-powerstore-x-security-update-for-multiple-vulnerabilities\">DSA-2025-182: Dell PowerStore X Security Update for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000308929\/dsa-2025-184-security-update-for-dell-data-lakehouse-multiple-third-party-component-vulnerabilities\">DSA-2025-184: Security Update for Dell Data Lakehouse Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-224","alert_type":396,"serial_number":"AV25-224","subject":"dell","moderation_state":"published","external_url":null},{"nid":6303,"title":"[Control systems] CISA ICS security advisories (AV25\u2013225)","uuid":"d31e1626-fbf8-4187-9c0f-cf15dfeac58d","banner":null,"lang":"en","date_modified":"2025-04-22","date_modified_ts":"2025-04-22T18:43:04Z","date_created":"2025-04-22T17:52:49Z","summary":null,"body":["<article data-history-node-id=\"6303\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-225\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25\u2013225<br \/><strong>Date: <\/strong>April\u00a022, 2025<\/p>\n\n<p>Between April\u00a014 and 20, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB M2M Gateway ARM600\u00a0\u2013 versions 4.1.2 to 5.0.3<\/li>\n\t<li>ABB M2M Gateway SW\u00a0\u2013 versions 5.0.1 to 5.0.3<\/li>\n\t<li>Delta Electronics COMMGR (version 1 and versions 2)\u00a0\u2013 all versions<\/li>\n\t<li>Growatt cloud portal\u00a0\u2013 versions 3.6.0 and prior<\/li>\n\t<li>Lantronix Xport\u00a0\u2013 versions 6.5.0.7 to 7.0.0.3<\/li>\n\t<li>Mitsubishi Electric Europe B.V. smartRTU\u00a0\u2013 versions 3.37 and prior<\/li>\n\t<li>National Instruments LabVIEW\u00a0\u2013 versions 2025 Q1 and prior<\/li>\n\t<li>Schneider Electric ConneXium Network Manager\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Sage 1410\u00a0\u2013 versions C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Schneider Electric Sage 1430\u00a0\u2013 versions C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Schneider Electric Sage 1450\u00a0\u2013 versions C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Schneider Electric Sage 2400\u00a0\u2013 versions C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Schneider Electric Sage 3030 Magnum\u00a0\u2013 versions C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Schneider Electric Sage 4400\u00a0\u2013 versions C3414-500-S02K5_P8 and prior<\/li>\n\t<li>Schneider Electric Trio Q Licensed Data Radio\u00a0\u2013 versions prior to 2.7.2<\/li>\n\t<li>Siemens Industrial Edge Device Kit\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Mendix Runtime\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SIDOOR\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMATIC\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMOCODE\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SIPLUS\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SIWAREX\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Yokogawa CX1000\u00a0\/\u00a0CX2000 Paperless Recorders\u00a0\u2013 all version<\/li>\n\t<li>Yokogawa DX1000\u00a0\/\u00a0DX2000\u00a0\/\u00a0DX1000N Paperless Recorders\u00a0\u2013 versions R4.21 and prior<\/li>\n\t<li>Yokogawa DX1000T\u00a0\/\u00a0DX2000T Paperless Recorders\u00a0\u2013 all versions<\/li>\n\t<li>Yokogawa FX1000 Paperless Recorders\u00a0\u2013 versions R1.31 and prior<\/li>\n\t<li>Yokogawa GM Data Acquisition System\u00a0\u2013 versions R5.05.01 and prior<\/li>\n\t<li>Yokogawa GX10\u00a0\/\u00a0GX20 \/\u00a0GP10\u00a0\/\u00a0GP20 Paperless Recorders\u00a0\u2013 versions R5.04.01 and prior<\/li>\n\t<li>Yokogawa MW100 Data Acquisition Units\u00a0\u2013 all versions<\/li>\n\t<li>Yokogawa \u03bcR10000\u00a0\/\u00a0\u03bcR20000 Chart Recorders\u00a0\u2013 versions R1.51 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-225","alert_type":398,"serial_number":"AV25-225","subject":"ics","moderation_state":"published","external_url":null},{"nid":6298,"title":"Red Hat security advisory (AV25-221)","uuid":"8e786e8b-b54e-4798-954b-cb002d868984","banner":null,"lang":"en","date_modified":"2025-04-22","date_modified_ts":"2025-04-22T18:18:51Z","date_created":"2025-04-22T18:14:24Z","summary":null,"body":["<article data-history-node-id=\"6298\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-221\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-221<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 22, 2025<\/p>\n\n<p>Between April 14 and 20, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-221","alert_type":396,"serial_number":"AV25-221","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6299,"title":"Ubuntu security advisory (AV25-220)","uuid":"fb2057f8-28d7-4013-8759-e2ad8ead7e22","banner":null,"lang":"en","date_modified":"2025-04-22","date_modified_ts":"2025-04-22T17:18:42Z","date_created":"2025-04-22T18:21:49Z","summary":null,"body":["<article data-history-node-id=\"6299\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-220\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-220<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 22, 2025<\/p>\n\n<p>Between April 14 and 20, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-220","alert_type":396,"serial_number":"AV25-220","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6300,"title":"Microsoft Edge security advisory (AV25-222)","uuid":"2023cb33-d60c-44de-98d2-9d9ff3296fe9","banner":null,"lang":"en","date_modified":"2025-04-22","date_modified_ts":"2025-04-22T18:37:29Z","date_created":"2025-04-22T18:32:06Z","summary":null,"body":["<article data-history-node-id=\"6300\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-222\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-222<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 22, 2025<\/p>\n\n<p>On April 17, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 0.3179.85<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-17-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-222","alert_type":396,"serial_number":"AV25-222","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6304,"title":"HPE security advisory (AV25-226)","uuid":"d70c2551-e644-49d1-8760-a4d8af8b4f16","banner":null,"lang":"en","date_modified":"2025-04-22","date_modified_ts":"2025-04-22T19:19:42Z","date_created":"2025-04-22T18:59:35Z","summary":null,"body":["<article data-history-node-id=\"6304\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-226\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-226<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 22, 2025<\/p>\n\n<p>Between April 15 and 22, 2025, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>HPE Brocade Fabric OS\u00a0- versions prior to v9.1.1d7 and v9.2.0<\/li>\n\t<li>HPE Compute Scale-up Server 3200\u00a0- versions prior to v1.55.98<\/li>\n\t<li>HPE Performance Cluster Manager HPCM 1.12 and prior<\/li>\n\t<li>HPE Superdome Flex 280 Server\u00a0- versions prior to v2.00.12<\/li>\n\t<li>HPE Telco Unified OSS Console\u00a0- versions prior to v3.1.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-226","alert_type":396,"serial_number":"AV25-226","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6305,"title":"GitLab security advisory (AV25-228)","uuid":"9c59cd6a-171b-4f8b-b02c-b0330af41ee7","banner":null,"lang":"en","date_modified":"2025-04-23","date_modified_ts":"2025-04-23T15:36:12Z","date_created":"2025-04-23T15:28:54Z","summary":null,"body":["<article data-history-node-id=\"6305\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-228\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-228<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 23, 2025<\/p>\n\n<p>On April 23, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 17.11.1, 17.10.5 and 17.9.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 17.11.1, 17.10.5 and 17.9.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/04\/23\/patch-release-gitlab-17-11-1-released\/\">GitLab Patch Release: 17.11.1, 17.10.5, 17.9.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-228","alert_type":396,"serial_number":"AV25-228","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6306,"title":"Google Chrome security advisory (AV25-227)","uuid":"9c575a5f-6965-4bdc-9c01-aa09627457ba","banner":null,"lang":"en","date_modified":"2025-04-23","date_modified_ts":"2025-04-23T15:00:00Z","date_created":"2025-04-23T16:17:32Z","summary":null,"body":["<article data-history-node-id=\"6306\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-227\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-227<br \/><strong>Date: <\/strong>April\u00a023, 2025<\/p>\n\n<p>On April\u00a022, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 135.0.7049.114\/115 (Windows\/Mac), and 135.0.7049.114 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/04\/stable-channel-update-for-desktop_22.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-227","alert_type":396,"serial_number":"AV25-227","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6308,"title":"Cisco security advisory (AV25-229)","uuid":"4877c7d5-8995-4326-8a7a-425d8e8012a4","banner":null,"lang":"en","date_modified":"2025-04-24","date_modified_ts":"2025-04-24T14:48:18Z","date_created":"2025-04-24T14:32:25Z","summary":null,"body":["<article data-history-node-id=\"6308\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-229\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-229<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 24, 2025<\/p>\n\n<p>On April 23, 2025, Cisco published a security advisory to address a critical vulnerability in the following products::<\/p>\n\n<ul><li>ConfD<\/li>\n\t<li>ConfD Basic<\/li>\n\t<li>Intelligent Node Manager<\/li>\n\t<li>Network Services Orchestrator (NSO)<\/li>\n\t<li>Smart PHY<\/li>\n\t<li>Ultra Cloud Core\u00a0- Subscriber Microservices Infrastructure<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-erlang-otp-ssh-xyZZy\">Cisco Security Advisory\u00a0\u2013 cisco-sa-erlang-otp-ssh-xyZZy<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-229","alert_type":396,"serial_number":"AV25-229","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6309,"title":"Erlang security advisory (AV25-232)","uuid":"b9e8cb8d-f6c6-4dc1-b61e-c9be951734cb","banner":null,"lang":"en","date_modified":"2025-04-24","date_modified_ts":"2025-04-24T18:36:23Z","date_created":"2025-04-24T15:58:04Z","summary":null,"body":["<article data-history-node-id=\"6309\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av25-232\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-232<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 24, 2025<\/p>\n\n<p>On April 16, 2025, Erlang published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>OTP\u00a0\u2013 versions OTP-27.3.2 and prior<\/li>\n\t<li>OTP\u00a0\u2013 versions OTP-26.2.5.10 and prior<\/li>\n\t<li>OTP\u00a0\u2013 versions OTP-25.3.2.19 and prior<\/li>\n<\/ul><p>This vulnerability allows unauthenticated RCE.<\/p>\n\n<p>Open-source reporting has indicated that CVE-2025-32433 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-37cp-fgq5-7wc2\">Unauthenticated Remote Code Execution in Erlang\/OTP SSH<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av25-232","alert_type":396,"serial_number":"AV25-232","subject":"other","moderation_state":"published","external_url":null},{"nid":6310,"title":"HPE security advisory (AV25-230)","uuid":"884b1e29-8875-4d16-bca4-fd12ec45fda9","banner":null,"lang":"en","date_modified":"2025-04-24","date_modified_ts":"2025-04-24T18:24:31Z","date_created":"2025-04-24T17:53:35Z","summary":null,"body":["<article data-history-node-id=\"6310\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-230\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-230<br \/><strong>Date: <\/strong>April\u00a024, 2025<\/p>\n\n<p>On April\u00a024, 2025, HPE published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following product:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04854en_us&amp;docLocale=en_US\">HPESBNW04854 rev.1\u00a0- HPE Telco Service Orchestrator, Remote Code Execution<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-230","alert_type":396,"serial_number":"AV25-230","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6311,"title":"SonicWall security advisory (AV25-231)","uuid":"667e2c0a-034c-4148-8534-06bd613baa4c","banner":null,"lang":"en","date_modified":"2025-04-24","date_modified_ts":"2025-04-24T18:33:26Z","date_created":"2025-04-24T17:53:35Z","summary":null,"body":["<article data-history-node-id=\"6311\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-231\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-231<br \/><strong>Date: <\/strong>April\u00a024, 2025<\/p>\n\n<p>On April\u00a023, 2025, SonicWall published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SonicOS Gen7 NSv: NSv 270, NSv 470 and NSv 870\u00a0\u2013 version 7.1.1-7040 to 7.1.3-7015 (7.1.x only)<\/li>\n\t<li>SonicOS Gen7 Firewalls: TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570 and TZ570W\u00a0\u2013 version 7.1.1-7040 to 7.1.3-7015 (7.1.x only)<\/li>\n\t<li>SonicOS TZ570P, TZ670, NSa 2700, NSa 3700, NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700 and NSsp 15700\u00a0\u2013 version 7.1.1-7040 to 7.1.3-7015 (7.1.x only)<\/li>\n\t<li>SonicOS TZ80\u00a0\u2013 versions 8.0.0-8037 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0009\">SonicWall Security Advisory\u00a0\u2013 SNWLID-2025-0009<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-231","alert_type":396,"serial_number":"AV25-231","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":6312,"title":"Microsoft Edge security advisory (AV25-233)","uuid":"eaaafe0b-2070-49fa-b558-91677efd77f7","banner":null,"lang":"en","date_modified":"2025-04-25","date_modified_ts":"2025-04-25T17:05:51Z","date_created":"2025-04-25T17:00:35Z","summary":null,"body":["<article data-history-node-id=\"6312\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-233\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-233<br \/><strong>Date: <\/strong>April\u00a025, 2025<\/p>\n\n<p>On April\u00a024, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 135.0.3179.98<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-24-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-233","alert_type":396,"serial_number":"AV25-233","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6313,"title":"HPE security advisory (AV25-234)","uuid":"93793c78-99cd-4402-967a-d5cec4a7cb9e","banner":null,"lang":"en","date_modified":"2025-04-25","date_modified_ts":"2025-04-25T18:52:48Z","date_created":"2025-04-25T18:44:45Z","summary":null,"body":["<article data-history-node-id=\"6313\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-234\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-234<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 25, 2025<\/p>\n\n<p>On April 25, 2025, HPE published security advisories to address vulnerabilities in multiple products. Included was an update for the following product:<\/p>\n\n<ul><li>HPE Telco Service Activator\u00a0\u2013 versions prior to 10.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04839en_us&amp;docLocale=en_US\">HPESBNW04839 rev.1\u00a0- HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Telco Service Activator, Multiple Vulnerabilities<\/span><\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-234","alert_type":396,"serial_number":"AV25-234","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6314,"title":"Dell security advisory (AV25-235)","uuid":"3844f3bc-01f6-4f19-adfd-2660250fae58","banner":null,"lang":"en","date_modified":"2025-04-28","date_modified_ts":"2025-04-28T14:32:03Z","date_created":"2025-04-28T14:27:59Z","summary":null,"body":["<article data-history-node-id=\"6314\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-235\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-235<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 28, 2025<\/p>\n\n<p>Between April 21 and 27, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.02.04.00<\/li>\n\t<li>Dell Connectrix B-Series\u00a0\u2013 versions 9.1.0 to 9.1.1d6<\/li>\n\t<li>Dell PowerProtect Data Manager\u00a0\u2013 versions 19.15.0 to 19.18.0-23<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-235","alert_type":396,"serial_number":"AV25-235","subject":"dell","moderation_state":"published","external_url":null},{"nid":6315,"title":"IBM security advisory (AV25-236)","uuid":"79d2265f-eb8c-4e19-bb05-782fe0f1031a","banner":null,"lang":"en","date_modified":"2025-04-28","date_modified_ts":"2025-04-28T14:39:00Z","date_created":"2025-04-28T14:34:27Z","summary":null,"body":["<article data-history-node-id=\"6315\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-236\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-236<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 28, 2025<\/p>\n\n<p>Between April 21 and 27, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Power HMC V10.2.1030.0\u00a0\u2013 version V10.2.1030.0<\/li>\n\t<li>IBM Power HMC V10.3.1050.0\u00a0\u2013 version V10.3.1050.0<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 version 7.5 to 7.5.0 UP11 IF03<\/li>\n\t<li>IBM webMethods B2B (on-prem)\u00a0\u2013 versions 10.11, 10.15 and 11.1<\/li>\n\t<li>IBM webMethods Integration (on prem)\u00a0\u2013 versions 10.11, 10.15 and 11.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-236","alert_type":396,"serial_number":"AV25-236","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6316,"title":"Ubuntu security advisory (AV25-237)","uuid":"25062eb6-29b2-4885-80b0-752bc460b84b","banner":null,"lang":"en","date_modified":"2025-04-28","date_modified_ts":"2025-04-28T14:44:26Z","date_created":"2025-04-28T14:41:15Z","summary":null,"body":["<article data-history-node-id=\"6316\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-237\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-237<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 28, 2025<\/p>\n\n<p>Between April 21 and 27, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-237","alert_type":396,"serial_number":"AV25-237","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6317,"title":"[Control systems] CISA ICS security advisories (AV25\u2013238) ","uuid":"a71297c5-2d02-4f8a-b9db-6a74c7e38421","banner":null,"lang":"en","date_modified":"2025-04-28","date_modified_ts":"2025-04-28T14:53:17Z","date_created":"2025-04-28T14:46:01Z","summary":null,"body":["<article data-history-node-id=\"6317\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-238\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-238<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 28, 2025<\/p>\n\n<p>Between April 21 and 27, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB ACS5000 \u2013 versions LAAAB 4.03.0 to LAAAB 5.06.1<\/li>\n\t<li>ABB ACS6000 \u2013 versions LAAAA 2.10.0 to LAAAB 5.06.1<\/li>\n\t<li>ABB ACS6080 \u2013 versions LAAAA 2.10.0 to LAAAB 5.06.1<\/li>\n\t<li>ALBEDO Telecom Net.Time \u2013 PTP\/NTP clock (Serial No. NBC0081P) \u2013 software release 1.4.4<\/li>\n\t<li>Johnson Controls Inc. ICU \u2013 versions prior to 6.9.5<\/li>\n\t<li>Nice Linear eMerge E3 \u2013 versions 1.00-07 and prior<\/li>\n\t<li>Planet Technology NMS-1000V \u2013 all versions<\/li>\n\t<li>Planet Technology NMS-500 \u2013 all versions<\/li>\n\t<li>Planet Technology UNI-NMS-Lite \u2013 versions 1.0b211018 and prior<\/li>\n\t<li>Planet Technology WGS-4215-8T2S \u2013 versions 1.305b241115 and prior<\/li>\n\t<li>Planet Technology WGS-804HPT-V2 \u2013 versions 2.305b250121 and prior<\/li>\n\t<li>Schneider Electric Modicon M340 \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon M340 \u2013 versions prior to 3.10<\/li>\n\t<li>Schneider Electric Modicon M340 \u2013 versions prior to SV3.60<\/li>\n\t<li>Schneider Electric Modicon M580 \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon M580 \u2013 versions prior to 2.80<\/li>\n\t<li>Schneider Electric Modicon M580 \u2013 versions prior to 2.90<\/li>\n\t<li>Schneider Electric Modicon M580 \u2013 versions prior to sv4.20<\/li>\n\t<li>Schneider Electric Modicon MC80 BMKC80* \u2013 versions prior to 1.80<\/li>\n\t<li>Schneider Electric Modicon MC80 \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Momentum CPU (part numbers 171CBU*) \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Momentum M1E \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Momentum Unity M1E Processor (part numbers 171CBU*) \u2013 versions prior to SV2.6<\/li>\n\t<li>Schneider Electric Modicon Premium \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Premium \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Premium \u2013 versions prior to 3.20<\/li>\n\t<li>Schneider Electric Modicon Quantum Safety \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Quantum \u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Quantum \u2013 versions prior to 3.60<\/li>\n\t<li>Schneider Electric PLC Simulator for EcoStruxure Control Expert \u2013 versions prior to 15.1<\/li>\n\t<li>Schneider Electric Wiser Home Controller WHC-5918A \u2013 all versions<\/li>\n\t<li>Siemens TeleControl Server Basic SQL \u2013 versions prior to V3.1.2.2<\/li>\n\t<li>Siemens TeleControl Server Basic \u2013 versions prior to V3.1.2.2<\/li>\n\t<li>Vestel AC Charger EVC04 \u2013 version 3.75.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-238","alert_type":398,"serial_number":"AV25-238","subject":"other","moderation_state":"published","external_url":null},{"nid":6318,"title":"Apache Tomcat security advisory (AV25-239)","uuid":"54a28ad6-ad58-4c04-bab9-1986b57695b2","banner":null,"lang":"en","date_modified":"2025-04-29","date_modified_ts":"2025-04-29T14:20:11Z","date_created":"2025-04-29T14:15:25Z","summary":null,"body":["<article data-history-node-id=\"6318\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-advisory-av25-239\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-239<br \/><strong>Date: <\/strong>April\u00a029, 2025<\/p>\n\n<p>On April\u00a028, 2025, Apache published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apache Tomcat\u00a0\u2013 versions 11.0.0-M1 to 11.0.5<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 10.1.0-M1 to 10.1.39<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 9.0.0.M1 to 9.0.102<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.104\">Apache Tomcat\u00a0- 9.0.104<\/a><\/li>\n\t<li><a href=\"https:\/\/tomcat.apache.org\/security-10.html#Fixed_in_Apache_Tomcat_10.1.40\">Apache Tomcat\u00a0- 10.1.40<\/a><\/li>\n\t<li><a href=\"https:\/\/tomcat.apache.org\/security-11.html#Fixed_in_Apache_Tomcat_11.0.6\">Apache Tomcat\u00a0- 11.0.6<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-advisory-av25-239","alert_type":396,"serial_number":"AV25-239","subject":"other","moderation_state":"published","external_url":null},{"nid":6319,"title":"Mozilla security advisory (AV25-240)","uuid":"e60769ec-fad6-47f6-8a09-a37607d6db56","banner":null,"lang":"en","date_modified":"2025-04-29","date_modified_ts":"2025-04-29T14:26:39Z","date_created":"2025-04-29T14:15:25Z","summary":null,"body":["<article data-history-node-id=\"6319\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-240\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-240<br \/><strong>Date: <\/strong>April\u00a029, 2025<\/p>\n\n<p>On April\u00a029, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird ESR\u00a0\u2013 versions prior to 128.10<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 138<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.23<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.10<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 138<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-32\/\">Mozilla Security Advisory (MFSA 2025-32)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-31\/\">Mozilla Security Advisory (MFSA 2025-31)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-30\/\">Mozilla Security Advisory (MFSA 2025-30)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-29\/\">Mozilla Security Advisory (MFSA 2025-29)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-28\/\">Mozilla Security Advisory (MFSA 2025-28)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-240","alert_type":396,"serial_number":"AV25-240","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6320,"title":"[Control systems] ABB security advisory (AV25-241) ","uuid":"9122af7e-6fb6-4deb-af81-302079ce474d","banner":null,"lang":"en","date_modified":"2025-04-29","date_modified_ts":"2025-04-29T15:56:12Z","date_created":"2025-04-29T15:51:12Z","summary":null,"body":["<article data-history-node-id=\"6320\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-241\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-241<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 29, 2025<\/p>\n\n<p>On April 29 and 30, 2025, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ekip Com IEC61850\u00a0\u2013 versions prior to 3.08<\/li>\n\t<li>ABB Automation Builder\u00a0\u2013 all versions<\/li>\n\t<li>ANC\u00a0\u2013 versions prior to 1.1.4<\/li>\n\t<li>ANC-L\u00a0\u2013 versions prior to 1.1.4<\/li>\n\t<li>ANC-mini\u00a0\u2013 versions prior to 1.1.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2CRT000007&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">Ekip Com IEC61850 Vulnerability in third-party library (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011407&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Automation Builder Vulnerabilities in user management and access control (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2CRT000006&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch&amp;_gl=1*qfain5*_gcl_au*ODEwMTM2OTg1LjE3NDMwMDc5OTM.*_ga*NzkzNjIwNDAuMTcwMTg5MDYxMw..*_ga_46ZFBRSZNM*MTc0NjAzNTE0OC40OTQuMS4xNzQ2MDM1NDcxLjYwLjAuMA\">ANC\u00a0\u2013 ABB Network Card Multiple vulnerabilities in ANC<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-241","alert_type":398,"serial_number":"AV25-241","subject":"abb","moderation_state":"published","external_url":null},{"nid":6321,"title":"VMware security advisory (AV25-242)","uuid":"bab4dbab-ab37-4e57-ac75-e7136274b5f3","banner":null,"lang":"en","date_modified":"2025-04-29","date_modified_ts":"2025-04-29T17:39:58Z","date_created":"2025-04-29T17:26:08Z","summary":null,"body":["<article data-history-node-id=\"6321\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-242\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-242<br \/><strong>Date: <\/strong>April\u00a029, 2025<\/p>\n\n<p>On April\u00a028, 2025, VMware released security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu GemFire Vector Database\u00a0\u2013 versions prior to 1.2.0<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 7.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25665\">Product Release Advisory\u00a0- VMware Tanzu Gemfire 1.2.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25664\">Product Release Advisory\u00a0- VMware Tanzu Greenplum 7.4.1<\/a><\/li>\n\t<li><a href=\"https:\/\/tanzu.vmware.com\/security\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-242","alert_type":396,"serial_number":"AV25-242","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6322,"title":"Google Chrome security advisory (AV25-243)","uuid":"58db8f44-9be9-4f24-952e-dde9fad53863","banner":null,"lang":"en","date_modified":"2025-04-30","date_modified_ts":"2025-04-30T13:11:19Z","date_created":"2025-04-30T12:50:38Z","summary":null,"body":["<article data-history-node-id=\"6322\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-243\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-243<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>April 30, 2025<\/p>\n\n<p>On April 29, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 136.0.7103.48\/49 (Windows\/Mac), and 136.0.7103.59 (Linux)<\/li>\n\t<li>Extended Stable Channel\u00a0\u2013 versions prior to 136.0.7103.48\/49 (Windows\/Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/04\/stable-channel-update-for-desktop_29.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-243","alert_type":396,"serial_number":"AV25-243","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6324,"title":"Microsoft Edge security advisory (AV25-244)","uuid":"a1ebc526-9a2e-4ec3-85d4-2e351b5442db","banner":null,"lang":"en","date_modified":"2025-05-02","date_modified_ts":"2025-05-02T17:28:54Z","date_created":"2025-05-02T17:25:33Z","summary":null,"body":["<article data-history-node-id=\"6324\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-244\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-244<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 2, 2025<\/p>\n\n<p>On May 1, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 136.0.3240.50<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-1-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-244","alert_type":396,"serial_number":"AV25-244","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6326,"title":"Ubuntu security advisory (AV25-245)","uuid":"46a78299-570a-4d18-9d06-4b189194b381","banner":null,"lang":"en","date_modified":"2025-05-05","date_modified_ts":"2025-05-05T15:36:19Z","date_created":"2025-05-05T15:32:32Z","summary":null,"body":["<article data-history-node-id=\"6326\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-245\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-245<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 5, 2025<\/p>\n\n<p>Between April 28 and May 4, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 ESM<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-245","alert_type":396,"serial_number":"AV25-245","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6328,"title":"[Control systems] CISA ICS security advisories (AV25\u2013246)","uuid":"3de2996c-eac3-4cf2-bf0d-51d42c9d6be3","banner":null,"lang":"en","date_modified":"2025-05-05","date_modified_ts":"2025-05-05T15:47:46Z","date_created":"2025-05-05T15:41:07Z","summary":null,"body":["<article data-history-node-id=\"6328\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-246\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-246<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 5, 2025<\/p>\n\n<p>Between April 28 and May 4, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics ISPSoft\u00a0\u2013 version 3.19 and prior<\/li>\n\t<li>KUNBUS Revolution Pi OS Bookworm\u00a0\u2013 version 01\/2025 and prior<\/li>\n\t<li>KUNBUS Revolution Pi PiCtory\u00a0\u2013 versions 2.5.0 to 2.11.1 and version 2.11.1 and prior<\/li>\n\t<li>MicroDicom DICOM Viewer\u00a0\u2013 version 2025.1 (Build 3321) and prior<\/li>\n\t<li>Rockwell Automation ThinManager\u00a0\u2013 version 14.0.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-246","alert_type":398,"serial_number":"AV25-246","subject":"ics","moderation_state":"published","external_url":null},{"nid":6329,"title":"IBM security advisory (AV25-247)","uuid":"adff9031-2f5c-4224-8525-5b976a57e74b","banner":null,"lang":"en","date_modified":"2025-05-05","date_modified_ts":"2025-05-05T16:12:26Z","date_created":"2025-05-05T16:05:53Z","summary":null,"body":["<article data-history-node-id=\"6329\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-247\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-247<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 5, 2025<\/p>\n\n<p>Between April 28 and May 4, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>CP4NA\u00a0\u2013 version 2.7.7<\/li>\n\t<li>GDSC Platform On-prem\u00a0\u2013 version 3.7.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 versions V24.0.1 to V24.0.1-IF001 and versions 24.0.0 to 24.0.0-IF004<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 version 2.3.4.0 (Intel)<\/li>\n\t<li>IBM Planning Analytics Cartridge\u00a0\u2013 versions 5.0.0 to 5.1.0<\/li>\n\t<li>IBM Planning Analytics Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.8.0 to 4.8.8<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge\u00a0\u2013 versions 4.8.4 to 4.8.5 and versions 5.0.0 to 5.1.1<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0\u2013 versions 4.0.0 to 5.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-247","alert_type":396,"serial_number":"AV25-247","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6330,"title":"Android security advisory \u2013 May 2025 monthly rollup (AV25-250)","uuid":"86201bf2-d135-4073-ac5d-b17aae8d2d58","banner":null,"lang":"en","date_modified":"2025-05-05","date_modified_ts":"2025-05-05T19:53:12Z","date_created":"2025-05-05T19:12:40Z","summary":null,"body":["<article data-history-node-id=\"6330\" about=\"\/en\/alerts-advisories\/android-security-advisory-may-2025-monthly-rollup-av25-250\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-250<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 5, 2025<\/p>\n\n<p>On May 5, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>Google has indicated that CVE-2025-27363 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-05-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-may-2025-monthly-rollup-av25-250","alert_type":396,"serial_number":"AV25-250","subject":"android","moderation_state":"published","external_url":null},{"nid":6331,"title":"Commvault security advisory (AV25\u2013249)","uuid":"92097322-b2fb-49ec-93c4-ec6511b51569","banner":null,"lang":"en","date_modified":"2025-05-05","date_modified_ts":"2025-05-05T19:51:46Z","date_created":"2025-05-05T19:13:38Z","summary":null,"body":["<article data-history-node-id=\"6331\" about=\"\/en\/alerts-advisories\/commvault-security-advisory-av25-249\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-249<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 5, 2025<\/p>\n\n<p>On April 11, 2025, Commvault published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Commvault\u00a0\u2013 versions 11.38.0 to 11.38.19<\/li>\n<\/ul><p>Open-source reporting has indicated that CVE-2025-34028 may have been exploited.<\/p>\n\n<p>On May 2, 2025, CISA added CVE-2025-34028 to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/05\/02\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">CISA\u00a0- Known Exploited Vulnerabilities Catalog<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2025_04_1.html\">Commvault Security Advisories\u00a0- CV_2025_04_1<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/\">Commvault Cloud Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/commvault-security-advisory-av25-249","alert_type":396,"serial_number":"AV25-249","subject":"other","moderation_state":"published","external_url":null},{"nid":6332,"title":"Dell security advisory (AV25-248)","uuid":"8ba60ba4-1ae4-4738-960d-3dd545af81e7","banner":null,"lang":"en","date_modified":"2025-05-05","date_modified_ts":"2025-05-05T19:43:07Z","date_created":"2025-05-05T19:20:57Z","summary":null,"body":["<article data-history-node-id=\"6332\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-248\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-248<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>\u00a0May 5, 2025<\/p>\n\n<p>Between April 28 and May 4, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Microsoft Azure\u00a0\u2013 versions prior to 01.04.01.00<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 versions 8.0.000 to 8.0.322<\/li>\n\t<li>PowerFlex Appliance IC\u00a0\u2013 versions prior to IC 46.377.00 and versions prior to IC 46.382.00<\/li>\n\t<li>PowerFlex rack RCM\u00a0\u2013 versions prior to 6.7.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000315723\/dsa-2025-194-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities\">DSA-2025-194: Security Update for Dell PowerFlex Rack Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000315712\/dsa-2025-193-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities\">DSA-2025-193: Security Update for Dell PowerFlex Appliance Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000314560\/dsa-2025-152-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities\">DSA-2025-152: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000314062\/dsa-2025-170-security-update-for-dell-apex-cloud-platform-for-microsoft-azure-and-dell-apex-cloud-platform-foundation-software-multiple-third-party-component-vulnerabilities\">DSA-2025-170: Security Update for Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-248","alert_type":396,"serial_number":"AV25-248","subject":"dell","moderation_state":"published","external_url":null},{"nid":6334,"title":"Mitel security advisory (AV25-251)","uuid":"f1d16070-34b9-4d15-8179-7a432c1af63e","banner":null,"lang":"en","date_modified":"2025-05-07","date_modified_ts":"2025-05-07T15:26:01Z","date_created":"2025-05-07T15:11:57Z","summary":null,"body":["<article data-history-node-id=\"6334\" about=\"\/en\/alerts-advisories\/cyber-mitel-security-advisory-av25-251\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-251<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 7, 2025<\/p>\n\n<p>On May 7, 2025, Mitel published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitel 6800 Series SIP Phones\u00a0\u2013 version R6.4.0.SP4 and prior<\/li>\n\t<li>Mitel 6900 Series SIP Phones\u00a0\u2013 version R6.4.0.SP4 and prior<\/li>\n\t<li>Mitel 6900w Series SIP Phones\u00a0\u2013 version R6.4.0.SP4 and prior<\/li>\n\t<li>Mitel 6970 Conference Unit\u00a0\u2013 version R6.4.0.SP4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/mitel-product-security-advisory-misa-2025-0004\">Mitel Security Advisory\u00a0- 2025-0004<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cyber-mitel-security-advisory-av25-251","alert_type":396,"serial_number":"AV25-251","subject":"mitel","moderation_state":"published","external_url":null},{"nid":6336,"title":"F5 security advisory (AV25-252)","uuid":"6478a8cb-2d39-415a-aff1-0f37f324c50e","banner":null,"lang":"en","date_modified":"2025-05-07","date_modified_ts":"2025-05-07T17:16:47Z","date_created":"2025-05-07T17:08:23Z","summary":null,"body":["<article data-history-node-id=\"6336\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av25-252\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-252<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 7, 2025<\/p>\n\n<p>On May 7, 2025, F5 published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>BIG-IP (all modules)\u00a0\u2013 versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.5, and versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP (APM)\u00a0\u2013 versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.5, and versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP (PEM)\u00a0\u2013 versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.5, and versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP Next (all modules)\u00a0\u2013 versions 20.2.0 to 20.2.1<\/li>\n\t<li>BIG-IP Next SPK\u00a0\u2013 versions 1.8.0 to 1.9.2 and versions 1.7.0 to 1.9.2<\/li>\n\t<li>BIG-IP Next CNF\u00a0\u2013 versions 1.1.0 to 1.4.1<\/li>\n\t<li>F5OS-A\u00a0\u2013 versions 1.5.1 to 1.5.3<\/li>\n\t<li>F5OS-C\u00a0\u2013 versions 1.6.0 to 1.6.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000151008\">F5 Quarterly Security Notification (May 2025)<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av25-252","alert_type":396,"serial_number":"AV25-252","subject":"f5","moderation_state":"published","external_url":null},{"nid":6337,"title":"Cisco security advisory (AV25-253)","uuid":"1d106b00-19ce-4c25-8116-44b2eddd7e38","banner":null,"lang":"en","date_modified":"2025-05-07","date_modified_ts":"2025-05-07T20:51:52Z","date_created":"2025-05-07T20:39:07Z","summary":null,"body":["<article data-history-node-id=\"6337\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-253\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-253<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 8, 2025<\/p>\n\n<p>On May 7, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>1000 Series Integrated Services Routers<\/li>\n\t<li>1100 Series Integrated Services Routers (ISRs)<\/li>\n\t<li>4000 Series Integrated Services Routers<\/li>\n\t<li>Integrated access points (APs) in Integrated Service Routers (ISR)1100 (Wi-Fi 6)<\/li>\n\t<li>Catalyst 8200 Series Edge Platforms<\/li>\n\t<li>Catalyst 8300 Series Edge Platforms<\/li>\n\t<li>Catalyst 8500 Series Edge Platforms<\/li>\n\t<li>Catalyst 8500L Series Edge Platforms<\/li>\n\t<li>Catalyst 9800-CL Wireless Controllers for Cloud<\/li>\n\t<li>Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches<\/li>\n\t<li>Catalyst 9800 Series Wireless Controllers<\/li>\n\t<li>Embedded Wireless Controller on Catalyst 9100X Access Points<\/li>\n\t<li>Catalyst SD-WAN Manager\u00a0\u2013 versions 20.8 and prior, 20.9, 20.10, 20.11, 20.12, 20.13, 20.14, 20.15, and 20.16<\/li>\n\t<li>Wi-Fi 6 pluggable module for Catalyst IR1800 Rugged Series Routers<\/li>\n\t<li>Cisco Industrial Ethernet 2000, 4000, 4010, and 5000 Series Switches<\/li>\n\t<li>Cisco IOS, IOS XE, NX-OS and IOS XR Software<\/li>\n\t<li>Cisco Adaptive Security Appliance (ASA) Software<\/li>\n\t<li>Cisco Firepower Threat Defense (FTD) Software<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/viewErp.x?alertId=ERP-75279\">Cisco Event Response: May 2025 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-253","alert_type":396,"serial_number":"AV25-253","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6338,"title":"SonicWall security advisory (AV25-254)","uuid":"085eff6d-dda3-4787-84e5-57e4d338ed35","banner":null,"lang":"en","date_modified":"2025-05-07","date_modified_ts":"2025-05-07T21:02:53Z","date_created":"2025-05-07T20:56:15Z","summary":null,"body":["<article data-history-node-id=\"6338\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-254\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-254<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 8, 2025<\/p>\n\n<p>On May 7, 2025, SonicWall published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SMA 100 Series (SMA 200, 210, 400, 410, 500v)\u00a0\u2013 version 10.2.1.14-75sv and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0011\">SonicWall Security Advisory\u00a0- SNWLID-2025-0011<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-254","alert_type":396,"serial_number":"AV25-254","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":6339,"title":"Drupal security advisory (AV25-255)","uuid":"8d50c326-ebea-47f9-95b3-48cb4e507079","banner":null,"lang":"en","date_modified":"2025-05-07","date_modified_ts":"2025-05-07T21:18:18Z","date_created":"2025-05-07T21:07:50Z","summary":null,"body":["<article data-history-node-id=\"6339\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-255\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-255<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 8, 2025<\/p>\n\n<p>On May 7, 2025, Drupal published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Enterprise MFA\u00a0- TFA for Drupal\u00a0\u2013 versions prior to 4.7.0 and versions 5.0.0 to versions prior to 5.2.0<\/li>\n\t<li>Restrict route by IP\u00a0\u2013 versions prior to 1.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-047\">Restrict route by IP\u00a0- Critical\u00a0- Cross Site Request Forgery\u00a0- SA-CONTRIB-2025-047<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-054\">Enterprise MFA\u00a0- TFA for Drupal\u00a0- Critical\u00a0- Cross Site Request Forgery\u00a0- SA-CONTRIB-2025-054<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-055\">Enterprise MFA\u00a0- TFA for Drupal\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-0554<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-056\">Enterprise MFA\u00a0- TFA for Drupal\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-056<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-255","alert_type":396,"serial_number":"AV25-255","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6343,"title":"Microsoft Edge security advisory (AV25-256)","uuid":"23cc5a49-8958-42ff-8791-624ef20be225","banner":null,"lang":"en","date_modified":"2025-05-09","date_modified_ts":"2025-05-09T14:49:41Z","date_created":"2025-05-09T14:18:34Z","summary":null,"body":["<article data-history-node-id=\"6343\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-256\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-256<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 9, 2025<\/p>\n\n<p>On May 8, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 136.0.3240.64<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-8-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-256","alert_type":396,"serial_number":"AV25-256","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6344,"title":"Google Chrome security advisory (AV25-257)","uuid":"602b4221-7d05-48ba-9ad9-4c0798b50600","banner":null,"lang":"en","date_modified":"2025-05-09","date_modified_ts":"2025-05-09T18:03:55Z","date_created":"2025-05-09T17:56:46Z","summary":null,"body":["<article data-history-node-id=\"6344\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-257\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-257<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 9, 2025<\/p>\n\n<p>On May 6, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 136.0.7103.92\/.93 (Windows\/Mac), and 136.0.7103.92 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/05\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-257","alert_type":396,"serial_number":"AV25-257","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6345,"title":"Ubuntu security advisory (AV25-258)","uuid":"b816848a-3434-4146-8b1f-c566c49a57bc","banner":null,"lang":"en","date_modified":"2025-05-12","date_modified_ts":"2025-05-12T13:49:53Z","date_created":"2025-05-12T13:41:46Z","summary":null,"body":["<article data-history-node-id=\"6345\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-258\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-258<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 12, 2025<\/p>\n\n<p>Between May 5 and 11, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-258","alert_type":396,"serial_number":"AV25-258","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6346,"title":"Red Hat security advisory (AV25-259)","uuid":"198f16af-89de-4bcc-af10-49778d65332a","banner":null,"lang":"en","date_modified":"2025-05-12","date_modified_ts":"2025-05-12T13:57:38Z","date_created":"2025-05-12T13:51:34Z","summary":null,"body":["<article data-history-node-id=\"6346\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-259\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-259<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 12, 2025<\/p>\n\n<p>Between May 5 and 11, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-259","alert_type":396,"serial_number":"AV25-259","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6347,"title":"[Control systems] CISA ICS security advisories (AV25\u2013260)","uuid":"35ae93fd-53e3-4865-94f8-f48f4adbe320","banner":null,"lang":"en","date_modified":"2025-05-12","date_modified_ts":"2025-05-12T14:21:06Z","date_created":"2025-05-12T14:10:27Z","summary":null,"body":["<article data-history-node-id=\"6347\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-260\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-260<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 12, 2025<\/p>\n\n<p>Between May 5 and 11, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BrightSign OS Series 4 players\u00a0\u2013 versions prior to v8.5.53.1<\/li>\n\t<li>BrightSign OS Series 5 players\u00a0\u2013 versions prior to v9.0.166<\/li>\n\t<li>Hitachi Energy RTU500 Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Horner Automation Cscape\u00a0\u2013 version 10.0 (10.0.415.2) SP1<\/li>\n\t<li>Milesight UG65-868M-EA\u00a0\u2013 firmware versions prior to 60.0.0.46<\/li>\n\t<li>Mitsubishi Electric CC-Link IE TSN\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Optigo Networks ONS NC600\u00a0\u2013 versions 4.2.1-084 to 4.7.2-330<\/li>\n\t<li>Pixmeo OsiriX MD\u00a0\u2013 versions 14.0.1 (Build 2024-02-28) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-260","alert_type":398,"serial_number":"AV25-260","subject":"other","moderation_state":"published","external_url":null},{"nid":6348,"title":"Dell security advisory (AV25-261)","uuid":"1a848435-f08d-40bf-90f9-c1def1b29910","banner":null,"lang":"en","date_modified":"2025-05-12","date_modified_ts":"2025-05-12T14:37:23Z","date_created":"2025-05-12T14:25:18Z","summary":null,"body":["<article data-history-node-id=\"6348\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-261\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-261<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 12, 2025<\/p>\n\n<p>Between May 5 and 11, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Connectrix SANnav\u00a0\u2013 versions prior to 2.3.1a<\/li>\n\t<li>Dell Edge Gateway\u00a0\u2013 multiple models and versions prior to 2.00.10<\/li>\n\t<li>Dell EMC Networking VEP1425\/VEP1445\/VEP1485\u00a0\u2013 versions prior to 2.6<\/li>\n\t<li>Dell Networking VEP4600\u00a0\u2013 multiple models and versions prior to 4.3<\/li>\n\t<li>Dell PowerFlex rack\u00a0\u2013 versions prior to 3.7.7.0<\/li>\n\t<li>Dell PowerFlex rack\u00a0\u2013 versions prior to 3.8.2.0<\/li>\n\t<li>Dell PowerSwitch\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Dell SD-WAN Edge 600\u00a0\u2013 versions prior to 2.6<\/li>\n\t<li>Dell Storage Manager DSM\u00a0\u2013 versions prior to 2020 R1.21<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-261","alert_type":396,"serial_number":"AV25-261","subject":"dell","moderation_state":"published","external_url":null},{"nid":6349,"title":"IBM security advisory (AV25-262)","uuid":"502060ae-2f5f-4957-8398-94c19cce0216","banner":null,"lang":"en","date_modified":"2025-05-12","date_modified_ts":"2025-05-12T15:43:20Z","date_created":"2025-05-12T15:24:19Z","summary":null,"body":["<article data-history-node-id=\"6349\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-262\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-262<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 12, 2025<\/p>\n\n<p>Between May 5 and 11, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM App Connect Operator\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Application Modernization Accelerator\u00a0\u2013 versions 4.0.0 to 4.1.0<\/li>\n\t<li>IBM Business Automation Insights\u00a0\u2013 versions 24.0.0 and 24.0.1<\/li>\n\t<li>IBM CICS TX Advanced\u00a0\u2013 versions 10.1 and 11.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Data System 1.0\u00a0\u2013 versions 1.0.0.0 to 1.0.8.4<\/li>\n\t<li>IBM Cloud Transformation Advisor\u00a0\u2013 versions 2.0.1 to 4.1.0<\/li>\n\t<li>IBM Cognos Dashboards on Cloud Pak for Data\u00a0\u2013 versions 4.8.0 to 4.8.8 and versions 5.0.0 to 5.1.2<\/li>\n\t<li>IBM Content Collector for Email\u00a0\u2013 version 4.0.1<\/li>\n\t<li>IBM Content Collector for File Systems\u00a0\u2013 version 4.0.1<\/li>\n\t<li>IBM Content Collector for Microsoft\u00a0\u2013 version 4.0.1<\/li>\n\t<li>IBM Maximo AI Service\u00a0\u2013 version 9.0.5<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 versions 8.8, 8.9 and 9.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Location Service for Esri Component\u00a0\u2013 version 9.0<\/li>\n\t<li>IBM Operational Decision Manager\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Planning Analytics Local\u00a0\u2013 IBM Planning Analytics Workspace \u2013 versions 2.0 and 2.1<\/li>\n\t<li>IBM Storage Scale\u00a0\u2013 versions 1.7.0 to 5.1.9.8 and 5.2.2.0 to 5.2.2.1<\/li>\n\t<li>IBM Storage Virtualize vSphere Remote Plug-in\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM TXSeries for Multiplatforms\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Watson Knowledge Catalog on-prem\u00a0\u2013 versions 4.5.2, 4.6.6 to 4.8.6 and versions 5.0 to 5.0.3<\/li>\n\t<li>IBM Watson Machine Learning Accelerator on Cloud Pak for Data\u00a0\u2013 versions 4.8.2 to 4.8.6 and versions 5.0 to 5.0.2<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge\u00a0\u2013 versions 4.8.4 to 4.8.5<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge\u00a0\u2013 versions 5.0.0 to 5.1.2<\/li>\n\t<li>IBM watsonx.data\u00a0\u2013 version 2.1.2<\/li>\n\t<li>Red Hat OpenShift on IBM Cloud\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-262","alert_type":396,"serial_number":"AV25-262","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6350,"title":"VMware security advisory (AV25-263)","uuid":"bd44fe68-2ee5-4ca1-b0fd-0b71d93c6a42","banner":null,"lang":"en","date_modified":"2025-05-12","date_modified_ts":"2025-05-12T17:52:20Z","date_created":"2025-05-12T17:39:26Z","summary":null,"body":["<article data-history-node-id=\"6350\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-263\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-263<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 12, 2025<\/p>\n\n<p>On May 12, 2025, VMware released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>VMware Aria Automation\u00a0\u2013 version 8.18.x<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 version 4.x and 5.x<\/li>\n\t<li>VMware Telco Cloud Platform\u00a0\u2013 version 5.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25711\">MSA-2025-0008: VMware Aria automation updates address a DOM based Cross-site scripting vulnerability (CVE-2025-22249)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-263","alert_type":396,"serial_number":"AV25-263","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6352,"title":"Apple security advisory (AV25-264)","uuid":"1bd91a75-20fd-48a4-b22e-f91743fe01d0","banner":null,"lang":"en","date_modified":"2025-05-13","date_modified_ts":"2025-05-13T13:54:16Z","date_created":"2025-05-13T13:47:38Z","summary":null,"body":["<article data-history-node-id=\"6352\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-264\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-264<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2025<\/p>\n\n<p>On May 12, 2025, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.5<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 17.7.7<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.5<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.7.6<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.7.6<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 18.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-264","alert_type":396,"serial_number":"AV25-264","subject":"apple","moderation_state":"published","external_url":null},{"nid":6353,"title":"SAP security advisory \u2013 May 2025 monthly rollup (AV25-265)","uuid":"20665b3b-0f25-405e-9fe9-ff9233f6d0b0","banner":null,"lang":"en","date_modified":"2025-05-13","date_modified_ts":"2025-05-13T14:09:08Z","date_created":"2025-05-13T14:01:14Z","summary":null,"body":["<article data-history-node-id=\"6353\" about=\"\/en\/alerts-advisories\/sap-security-advisory-may-2025-monthly-rollup-av25-265\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-265<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2025<\/p>\n\n<p>On May 13, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Business Objects Business Intelligence Platform (PMW)\u00a0\u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP Landscape Transformation (PCL Basis)\u00a0\u2013 versions DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2018_1_752, 2020, S4CORE 102, 103, 104, 105, 106, 107 and 108<\/li>\n\t<li>SAP NetWeaver (Visual Composer development server)\u00a0\u2013 version VCFRAMEWORK 7.50<\/li>\n\t<li>SAP Supplier Relationship Management (Live Auction Cockpit)\u00a0\u2013 version SRM_SERVER 7.14<\/li>\n\t<li>SAP S\/4HANA S4CORE Cloud Private Edition or on Premise (SCM Master Data Layer (MDL))\u00a0\u2013 versions S4CORE 102, 103, 104, 105, 106, 107, 108, SCM_BASIS 700, 701, 702, 712, 713 and 714<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/may-2025.html\">SAP Security Patch Day\u00a0\u2013 May 2025<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-may-2025-monthly-rollup-av25-265","alert_type":396,"serial_number":"AV25-265","subject":"sap","moderation_state":"published","external_url":null},{"nid":6354,"title":"Fortinet security advisory (AV25-266)","uuid":"6e34aa9d-15f0-4872-a834-614411092f93","banner":null,"lang":"en","date_modified":"2025-05-13","date_modified_ts":"2025-05-13T17:25:38Z","date_created":"2025-05-13T17:20:56Z","summary":null,"body":["<article data-history-node-id=\"6354\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-266\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-266<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2025<\/p>\n\n<p>On May 13, 2025, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiCamera 1.1- all versions<\/li>\n\t<li>FortiCamera 2.0 \u2013 all versions<\/li>\n\t<li>FortiCamera 2.1- version 2.1.0 to 2.1.3<\/li>\n\t<li>FortiMail - version 7.0.0 to 7.0.8<\/li>\n\t<li>FortiMail - version 7.2.0 to 7.2.7<\/li>\n\t<li>FortiMail - version 7.4.0 to 7.4.4<\/li>\n\t<li>FortiMail - version 7.6.0 to 7.6.2<\/li>\n\t<li>FortiNDR - version 1.1 to 1.4<\/li>\n\t<li>FortiNDR - version 1.5.0 to 1.5.3<\/li>\n\t<li>FortiNDR - version 7.0.0 to 7.0.6<\/li>\n\t<li>FortiNDR - version 7.1.0 to 7.1.1<\/li>\n\t<li>FortiNDR - version 7.2.0 to 7.2.4<\/li>\n\t<li>FortiNDR - version 7.4.0 to 7.4.7<\/li>\n\t<li>FortiNDR - version 7.6.0<\/li>\n\t<li>FortiOS \u2013 version 7.4.4 to 7.4.6<\/li>\n\t<li>FortiOS \u2013 version 7.6.0<\/li>\n\t<li>FortiProxy \u2013 version 7.6.0 to 7.6.1<\/li>\n\t<li>FortiRecorder - version 6.4.0 to 6.4.5<\/li>\n\t<li>FortiRecorder - version 7.0.0 to 7.0.5<\/li>\n\t<li>FortiRecorder - version 7.2.0 to 7.2.3<\/li>\n\t<li>FortiSwitchManager \u2013 version 7.2.5<\/li>\n\t<li>FortiVoice - versions 6.4.0 to 6.4.10<\/li>\n\t<li>FortiVoice - versions 7.0.0 to 7.0.6<\/li>\n\t<li>FortiVoice \u2013 versions prior to 7.2.0<\/li>\n<\/ul><p>Fortinet has indicated that CVE-2025-32756 has been exploited in the wild on FortiVoice.<\/p>\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-254\">Fortinet PSIRT - FG-IR-25-254 (CVE-2025-32756)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-472\">Fortinet PSIRT - FG-IR-25-472 (CVE-2025-22252)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt \">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-266","alert_type":396,"serial_number":"AV25-266","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6355,"title":"Ivanti security advisory (AV25-267)","uuid":"78f7f5f3-f3c0-419c-9e45-f6244c14d65a","banner":null,"lang":"en","date_modified":"2025-05-13","date_modified_ts":"2025-05-13T17:33:05Z","date_created":"2025-05-13T17:27:26Z","summary":null,"body":["<article data-history-node-id=\"6355\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-267\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-267<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2025<\/p>\n\n<p>On May 13, 2025, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Cloud Services Application \u2013 version 5.0.4 and prior<\/li>\n\t<li>Ivanti Neurons for ITSM (on-prem only) \u2013 versions 2023.4, 2024.2 and 2024.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Cloud-Services-Application-CVE-2025-22460?language=en_US\">Security Advisory Ivanti Cloud Services Application (CVE-2025-22460) <\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Neurons-for-ITSM-on-premises-only-CVE-2025-22462?language=en_US\">Security Advisory Ivanti Neurons for ITSM (on-premises only) (CVE-2025-22462)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-267","alert_type":396,"serial_number":"AV25-267","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6356,"title":"Intel security advisory (AV25-268) ","uuid":"54a20a02-b9d4-43e8-a9dc-a1da304b0c50","banner":null,"lang":"en","date_modified":"2025-05-13","date_modified_ts":"2025-05-13T18:24:41Z","date_created":"2025-05-13T18:22:31Z","summary":null,"body":["<article data-history-node-id=\"6356\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av25-268\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-268<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2025<\/p>\n\n<p>On May 12 and 13, 2025, Intel published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Product Security Center Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av25-268","alert_type":396,"serial_number":"AV25-268","subject":"intel","moderation_state":"published","external_url":null},{"nid":6357,"title":"Microsoft security advisory \u2013 May 2025 monthly rollup (AV25-269)","uuid":"2e523d26-1da9-41e5-b0c1-f6a0cac14bd8","banner":null,"lang":"en","date_modified":"2025-05-13","date_modified_ts":"2025-05-13T18:33:05Z","date_created":"2025-05-13T18:26:42Z","summary":null,"body":["<article data-history-node-id=\"6357\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2025-monthly-rollup-av25-269\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-269<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 13, 2025<\/p>\n\n<p>On May 13, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps \u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Office \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 10 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11 \u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2025-30400, CVE-2025-32701, CVE-2025-32706, CVE-2025-30397 and CVE-2025-32709 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-May\">May 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us \">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-may-2025-monthly-rollup-av25-269","alert_type":396,"serial_number":"AV25-269","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6358,"title":"Ivanti security advisory (AV25-270)","uuid":"d1f20f04-0ed1-48e1-bb22-da882abfd684","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T13:37:15Z","date_created":"2025-05-14T13:25:42Z","summary":null,"body":["<article data-history-node-id=\"6358\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-270\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E-->\n\n<p><strong>Serial number: <\/strong>AV25-270<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 13, 2025, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 version 11.12.0.4 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 version 12.3.0.1 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 version 12.4.0.1 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 version 12.5.0.0 and prior<\/li>\n<\/ul><p>Ivanti is aware that CVE-2025-4427 and CVE-2025-4428 have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US\">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) May 2025 (CVE-2025-4427 and CVE-2025-4428)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-270","alert_type":396,"serial_number":"AV25-270","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6359,"title":"Adobe security advisory (AV25\u2013271)","uuid":"d3647352-6676-4acf-9667-b6f164672db2","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T15:37:23Z","date_created":"2025-05-14T14:45:26Z","summary":null,"body":["<article data-history-node-id=\"6359\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-271\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-271<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 13, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Animate 2023\u00a0\u2013 version 23.0.11 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0\u2013 version 24.0.8 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 14.1.6 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 15.0.3 and prior<\/li>\n\t<li>Adobe ColdFusion 2021\u00a0\u2013 version Update 19 and prior<\/li>\n\t<li>Adobe ColdFusion 2023\u00a0\u2013 version Update 13 and prior<\/li>\n\t<li>Adobe ColdFusion 2025\u00a0\u2013 version Update 1 and prior<\/li>\n\t<li>Adobe Connect\u00a0\u2013 version 12.8 and prior<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 4.1.1 and prior<\/li>\n\t<li>Adobe Dreamweaver\u00a0\u2013 version 21.4 and prior<\/li>\n\t<li>Adobe Illustrator 2024\u00a0\u2013 version 28.7.5 and prior<\/li>\n\t<li>Adobe Illustrator 2025\u00a0\u2013 version 29.3 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.5.2 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID20.2 and prior<\/li>\n\t<li>Adobe Lightroom\u00a0\u2013 version 8.2 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler\u00a0\u2013 version 1.21.0 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.1.1 and prior<\/li>\n\t<li>Photoshop 2024\u00a0\u2013 version 25.12.2 and prior<\/li>\n\t<li>Photoshop 2025\u00a0\u2013 version 26.5 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 11.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-271","alert_type":396,"serial_number":"AV25-271","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6360,"title":"[Control systems] Siemens security advisory (AV25-272)","uuid":"3c4e69c1-a48b-49e8-b602-d9b1f9e00f72","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T15:59:58Z","date_created":"2025-05-14T15:47:33Z","summary":null,"body":["<article data-history-node-id=\"6360\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-272\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-272<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 13, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Desigo CC\u00a0\u2013 all versions<\/li>\n\t<li>INTRALOG WMS\u00a0\u2013 versions prior to V5<\/li>\n\t<li>OZW672\u00a0\u2013 multiple models and versions<\/li>\n\t<li>RUGGEDCOM ROX II family\u00a0\u2013 multiple models and versions<\/li>\n\t<li>SCALANCE LPE9403(6GK5998-3GS00-2AC2)\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC IPC RS-828A\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC PCS neo\u00a0\u2013 versions V4.1 and V5.0<\/li>\n\t<li>SINEC NMS\u00a0\u2013 versions prior to V2.15.1.1<\/li>\n\t<li>SINEMA Remote Connect\u00a0\u2013 versions prior to UMC V2.15.1.1<\/li>\n\t<li>SIRIUS 3RK3 Modular Safety System (MSS)\u00a0\u2013 all versions<\/li>\n\t<li>SIRIUS Safety Relays 3SK2\u00a0\u2013 all versions<\/li>\n\t<li>Teamcenter Visualization\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Totally Integrated Automation Portal (TIA Portal)\u00a0\u2013 versions prior to UMCV2.15.1.1<\/li>\n\t<li>User Management Component (UMC)\u00a0\u2013 versions prior to UMC V2.15.1.1<\/li>\n\t<li>VersiCharge AC Series\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-272","alert_type":398,"serial_number":"AV25-272","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6361,"title":"Palo Alto Networks security advisory (AV25-273)","uuid":"d5d35d4e-7915-43ae-9a84-40d0e4eff3bb","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T17:25:09Z","date_created":"2025-05-14T17:22:11Z","summary":null,"body":["<article data-history-node-id=\"6361\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-273\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-273<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 14, 2025, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Prisma Access Browser \u2013 versions prior to 135.16.8.96<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0009\">Palo Alto Networks Security Advisories - PAN-SA-2025-0009<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-273","alert_type":396,"serial_number":"AV25-273","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6362,"title":"Google Chrome security advisory (AV25-274)","uuid":"5b21cb07-cd3b-4818-b94e-93bfb089f70d","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T17:29:37Z","date_created":"2025-05-14T17:26:31Z","summary":null,"body":["<article data-history-node-id=\"6362\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-274\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-274<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 14, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 136.0.7103.113\/114 (Windows\/Mac), and 136.0.7103.113 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/05\/stable-channel-update-for-desktop_14.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-274","alert_type":396,"serial_number":"AV25-274","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6363,"title":"Juniper Networks security advisory (AV25-275)","uuid":"77ff3b49-6146-4c30-b16f-ba1ae6e536ce","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T19:30:52Z","date_created":"2025-05-14T19:18:59Z","summary":null,"body":["<article data-history-node-id=\"6363\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-275\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-275<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 9 and 13, 2025, Juniper Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Juniper Secure Analytics\u00a0\u2013 versions 7.5.0 to versions prior to 7.5.0 UP11 IF02<\/li>\n\t<li>Junos OS\u00a0\u2013 versions 19.4R1 and later<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 versions 22.3R1 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US\">2024-05 Reference Advisory: Junos OS and Junos OS Evolved: Multiple CVEs reported in OpenSSH<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP11-IF03?language=en_US\">On Demand: JSA Series: Multiple vulnerabilities resolved in Juniper Secure Analytics in 7.5.0 UP11 IF03<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-275","alert_type":396,"serial_number":"AV25-275","subject":"juniper","moderation_state":"published","external_url":null},{"nid":6364,"title":"Jenkins security advisory (AV25-276)","uuid":"77a82424-77a9-4d72-972a-f10cd589ff63","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T19:45:29Z","date_created":"2025-05-14T19:36:55Z","summary":null,"body":["<article data-history-node-id=\"6364\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-276\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-276<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 14, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cadence vManager Plugin\u00a0\u2013 version 4.0.1-286.v9e25a_740b_a_48 and prior<\/li>\n\t<li>DingTalk Plugin\u00a0\u2013 version 2.7.3 and prior<\/li>\n\t<li>Health Advisor by CloudBees Plugin\u00a0\u2013 version 374.v194b_d4f0c8c8 and prior<\/li>\n\t<li>OpenID Connect Provider Plugin\u00a0\u2013 version 96.vee8ed882ec4d and prior<\/li>\n\t<li>WSO2 Oauth Plugin\u00a0\u2013 version 1.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-05-14\/\">Jenkins Security Advisory 2025-05-15<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-276","alert_type":396,"serial_number":"AV25-276","subject":"other","moderation_state":"published","external_url":null},{"nid":6365,"title":"[Control systems] Schneider Electric security advisory (AV25-277) ","uuid":"1dc459b2-e58c-4c7a-a602-cb067959aa39","banner":null,"lang":"en","date_modified":"2025-05-14","date_modified_ts":"2025-05-14T20:04:34Z","date_created":"2025-05-14T19:57:21Z","summary":null,"body":["<article data-history-node-id=\"6365\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-277\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-277<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 14, 2025<\/p>\n\n<p>On May 13, 2025, Schneider Electric published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Galaxy VS, VL and VXL \u2013 all versions<\/li>\n\t<li>Modicon Controllers M241 \/ M251\u2013 versions prior to v5.3.12.48<\/li>\n\t<li>Modicon Controllers M258 \/ LMC058 \u2013 all versions<\/li>\n\t<li>PrismaSeT Active - Wireless Panel Server \u2013 all versions<\/li>\n\t<li>Wiser AvatarOn 6K Freelocate \u2013 all versions<\/li>\n\t<li>Wiser Cuadro H 5P Socket \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-133-05&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-133-05.pdf\">Schneider Electric Security Notification - Galaxy VS, Galaxy VL, Galaxy VXL (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-133-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-133-01.pdf\">Schneider Electric Security Notification - Modicon Controllers M241\/M251\/M258\/LMC058 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-133-04&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-133-04.pdf\">Schneider Electric Security Notification - PrismaSeT Active - Wireless Panel Server (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-133-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-133-02.pdf\">Schneider Electric Security Notification - Wiser Home Automation (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-277","alert_type":398,"serial_number":"AV25-277","subject":"other","moderation_state":"published","external_url":null},{"nid":6367,"title":"Microsoft Edge security advisory (AV25-278)","uuid":"8939514e-ab24-4ecc-a12d-8381f28e166d","banner":null,"lang":"en","date_modified":"2025-05-16","date_modified_ts":"2025-05-16T14:46:17Z","date_created":"2025-05-16T14:43:51Z","summary":null,"body":["<article data-history-node-id=\"6367\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-278\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-278<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 16, 2025<\/p>\n\n<p>On May 15, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 136.0.3240.76<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-15-2025   \">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-278","alert_type":396,"serial_number":"AV25-278","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6368,"title":"Ubuntu security advisory (AV25-279)","uuid":"56712abd-2d09-4f53-affb-5b83e896aa55","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T13:40:16Z","date_created":"2025-05-20T13:30:38Z","summary":null,"body":["<article data-history-node-id=\"6368\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-279\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-279<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>Between May 12 and 18, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 ESM<\/li>\n\t<li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-279","alert_type":396,"serial_number":"AV25-279","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6369,"title":"Red Hat security advisory (AV25-280)","uuid":"c323189a-4fbb-4691-be62-e7ee2c430071","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T13:53:48Z","date_created":"2025-05-20T13:46:49Z","summary":null,"body":["<article data-history-node-id=\"6369\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-280\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-280<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>Between May 12 and 18, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-280","alert_type":396,"serial_number":"AV25-280","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6370,"title":"IBM security advisory (AV25-281)","uuid":"51529ccf-9249-4a13-99fa-e139e006a196","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T15:53:51Z","date_created":"2025-05-20T15:42:58Z","summary":null,"body":["<article data-history-node-id=\"6370\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-281\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-281<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>Between May 12 and 18, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Astronomer with IBM\u00a0\u2013 version 0.36.1<\/li>\n\t<li>IBM ApplinX\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM Business Automation Workflow Enterprise Service Bus\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Workflow traditional\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Event Streams\u00a0\u2013 version 11.3.0 to 11.6.1<\/li>\n\t<li>IBM Storage Copy Data Management\u00a0\u2013 version 2.2.0.0 to 2.2.25.0<\/li>\n\t<li>IBM watsonx Assistant for IBM Cloud Pak for Data\u00a0\u2013 version 4.0.0 to 4.8.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-281","alert_type":396,"serial_number":"AV25-281","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6371,"title":"Dell security advisory (AV25-282)","uuid":"b77d9e16-cd43-4626-84bb-2eb5a3858e47","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T16:35:24Z","date_created":"2025-05-20T15:59:07Z","summary":null,"body":["<article data-history-node-id=\"6371\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-282\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-282<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>Between May 12 and 18, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.04.01.00<\/li>\n\t<li>RecoverPoint for Virtual Machines\u00a0\u2013 versions 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2 and 6.0. SP2<\/li>\n\t<li>Dell EMC Networking VEP1425\/1445\/1485\u00a0\u2013 versions prior to 2.6<\/li>\n\t<li>Dell SD-WAN EDGE620\/640\/680\u00a0\u2013 versions prior to 3.50.0.9-21<\/li>\n\t<li>Dell SD-WAN EDGE610\/610-LTE\u00a0\u2013 versions prior to 3.43.0.9-24<\/li>\n\t<li>PowerFlex Appliance IC\u00a0\u2013 versions prior to IC-38.367.01<\/li>\n\t<li>PowerSwitch Z9664F-ON\u00a0\u2013 versions prior to 3.54.5.1-9<\/li>\n\t<li>PowerSwitch Z9432F-ON\u00a0\u2013 versions prior to 3.51.5.1-21<\/li>\n\t<li>PowerSwitch Z9264F-ON\u00a0\u2013 versions prior to 3.42.5.1-21<\/li>\n\t<li>PowerSwitch S5448F-ON\u00a0\u2013 versions prior to 3.52.5.1-12<\/li>\n\t<li>PowerSwitch E3200-ON Series\u00a0\u2013 versions prior to 3.57.5.1-5<\/li>\n\t<li>PowerSwitch N2200-ON Series\u00a0\u2013 versions prior to 3.45.5.1-31<\/li>\n\t<li>PowerSwitch N3200-ON Series\u00a0\u2013 versions prior to 3.45.5.1-31<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000321268\/dsa-2025-209-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-209<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000320811\/dsa-2025-202-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-202<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000321646\/dsa-2025-197-security-update-for-dell-networking-products-for-multiple-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-197<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000321006\/dsa-2025-196-security-update-for-dell-apex-cloud-platform-for-red-hat-openshift-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-196<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-us\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-282","alert_type":396,"serial_number":"AV25-282","subject":"dell","moderation_state":"published","external_url":null},{"nid":6372,"title":"[Control systems] CISA ICS security advisories (AV25\u2013283)","uuid":"5c6b3daa-dbeb-48fb-ba67-68a764a46b08","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T17:36:16Z","date_created":"2025-05-20T17:31:34Z","summary":null,"body":["<article data-history-node-id=\"6372\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-283\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-283<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>Between May 12 and 18, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Automation Builder\u00a0\u2013 all versions<\/li>\n\t<li>ECOVACS T10 Series\u00a0\u2013 versions prior to 1.11.0<\/li>\n\t<li>ECOVACS T20 Series\u00a0\u2013 versions prior to 1.25.0<\/li>\n\t<li>ECOVACS T30 Series\u00a0\u2013 versions prior to 1.100.0<\/li>\n\t<li>ECOVACS X1 OMNI\u00a0\u2013 versions prior to 2.4.45<\/li>\n\t<li>ECOVACS X1 PRO OMNI\u00a0\u2013 versions prior to 2.5.38<\/li>\n\t<li>ECOVACS X1 TURBO\u00a0\u2013 versions prior to 2.4.45<\/li>\n\t<li>ECOVACS X1S PRO\u00a0\u2013 versions prior to 2.5.38<\/li>\n\t<li>Hitachi Energy MACH GWS\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy Relion 670\/650\/SAM600-IO series\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy Service Suite\u00a0\u2013 versions 9.8.1.3 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure Power Build Rapsody\u00a0\u2013 version v2.7.12 FR and prior<\/li>\n\t<li>Siemens APOGEE PXC+TALON TC Series\u00a0\u2013 all versions<\/li>\n\t<li>Siemens BACnet ATEC\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens CPC80 Central Processing\/Communication\u00a0\u2013 all versions<\/li>\n\t<li>Siemens CPCI85 Central Processing\/Communication\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Desigo CC\u00a0\u2013 all versions<\/li>\n\t<li>Siemens IEC\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens INTRALOG WMS\u00a0\u2013 versions prior to v5<\/li>\n\t<li>Siemens Mendix OIDC SSO (Mendix 10 compatible)\u00a0\u2013 versions prior to V4.0.0<\/li>\n\t<li>Siemens Mendix OIDC SSO (Mendix 9 compatible)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens MS\/TP Point Pickup Module\u00a0\u2013 all versions<\/li>\n\t<li>Siemens OZW672\u00a0\u2013 versions prior to V6.0<\/li>\n\t<li>Siemens OZW672\u00a0\u2013 versions prior to V8.0<\/li>\n\t<li>Siemens OZW772\u00a0\u2013 versions prior to V6.0<\/li>\n\t<li>Siemens OZW772\u00a0\u2013 versions prior to V8.0<\/li>\n\t<li>Siemens Polarion\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens POWER METER SICAM Q100 family\u00a0\u2013 versions prior to V2.70<\/li>\n\t<li>Siemens POWER METER SICAM Q200 family\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Powerlink IP\u00a0\u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM APE1808\u00a0\u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM ROX\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SCALANCE LPE9403 (6GK5998-3GS00-2AC2)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SICAM GridPass\u00a0\u2013 versions prior to V2.50<\/li>\n\t<li>Siemens SICORE Base system\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC IPC RS-828A\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC PCS neo\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SIMATIC PCS neo V4.1\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIMATIC PCS neo V5.0\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINEMA Remote Connect\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIPROTEC 5\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SIRIUS 3RK3 Modular Safety System (MSS)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIRIUS Safety Relays 3SK2\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Teamcenter Visualization\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal)\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens UL\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens User Management Component (UMC)\u00a0\u2013 versions prior to V2.15.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-283","alert_type":398,"serial_number":"AV25-283","subject":"ics","moderation_state":"published","external_url":null},{"nid":6373,"title":"Atlassian security advisory (AV25-284)","uuid":"1b1fdc1d-1655-488c-a190-3c27ff8243a0","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T19:22:33Z","date_created":"2025-05-20T19:15:09Z","summary":null,"body":["<article data-history-node-id=\"6373\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-284\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-284<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>On May 20, 2025, Atlassian published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Fisheye\/Crucible\u00a0\u2013 version 4.9.0<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-may-20-2025-1561365992.html\">Atlassian Security Bulletin\u00a0\u2013 May 20 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-284","alert_type":396,"serial_number":"AV25-284","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6374,"title":"Mozilla security advisory (AV25-285)","uuid":"a2fd8e87-55d1-4c29-8758-00463cdf5d0c","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T19:22:37Z","date_created":"2025-05-20T19:17:22Z","summary":null,"body":["<article data-history-node-id=\"6374\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-285\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-285<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>On May 17 and 20, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 128.10.2<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 138.0.2<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.23.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.10.1<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 138.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-285","alert_type":396,"serial_number":"AV25-285","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6375,"title":"VMware security advisory (AV25-286)","uuid":"501d87cd-a6fb-4e45-8236-76fffda4e673","banner":null,"lang":"en","date_modified":"2025-05-20","date_modified_ts":"2025-05-20T19:50:42Z","date_created":"2025-05-20T19:36:13Z","summary":null,"body":["<article data-history-node-id=\"6375\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-286\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-286<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 20, 2025<\/p>\n\n<p>On May 20, 2025, VMware released security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>vCenter Server\u00a0\u2013 versions 7.0 and 8.0<\/li>\n\t<li>VMware ESXi\u00a0\u2013 versions 7.0 and 8.0<\/li>\n\t<li>VMware Cloud Foundation (vCenter)\u00a0\u2013 versions 4.5.x and 5.x<\/li>\n\t<li>VMware Cloud Foundation (ESXi)\u00a0\u2013 versions 4.5.x and 5.x<\/li>\n\t<li>VMware Fusion\u00a0\u2013 versions 13.x<\/li>\n\t<li>VMware Telco Cloud Platform (ESXi)\u00a0\u2013 versions 2.x, 3.x, 4.x and 5.x<\/li>\n\t<li>VMware Telco Cloud Infrastructure (ESXi)\u00a0\u2013 versions 2.x and 3.x<\/li>\n\t<li>VMware Telco Cloud Platform (vCenter)\u00a0\u2013 versions 2.x, 3.x, 4.x and 5.<\/li>\n\t<li>VMware Telco Cloud Infrastructure (vCenter)\u00a0\u2013 versions 2.x and 3.x<\/li>\n\t<li>VMware Workstation\u00a0\u2013 versions 13.x and 17.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25733\">VMSA-2025-0009\u00a0: VMware Cloud Foundation updates address multiple vulnerabilities (CVE-2025-41229, CVE-2025-41230, CVE-2025-41231)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25717\">VMSA-2025-0010\u00a0: VMware ESXi, vCenter Server, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2025-41225, CVE-2025-41226, CVE-2025-41227, CVE-2025-41228)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-286","alert_type":396,"serial_number":"AV25-286","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6376,"title":"Vulnerabilities impacting SAP NetWeaver (CVE-2025-31324 and CVE-2025-42999)","uuid":"bbabe13f-d29d-4d9b-8a1e-4d356a0f6991","banner":null,"lang":"en","date_modified":"2025-05-21","date_modified_ts":"2025-05-21T13:16:01Z","date_created":"2025-05-21T12:31:49Z","summary":null,"body":["<article data-history-node-id=\"6376\" about=\"\/en\/alerts-advisories\/vulnerabilities-impacting-sap-netweaver-cve-2025-31324-cve-2025-42999\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><h2>Alert<\/h2>\n\n<p><strong>Number:<\/strong> AL25-006<br \/><strong>Date:<\/strong> May 21, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On April 24, 2025, SAP released an emergency update for a critical vulnerability, CVE-2025-31324, affecting the following product<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>SAP NetWeaver (Visual Composer development server)\u00a0\u2013 version VCFRAMEWORK 7.50<\/li>\n<\/ul><p>This vulnerability can be exploited to allow an unauthenticated threat actor to upload arbitrary files to the affected system<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>On May 13, 2025, SAP released a security advisory addressing another critical vulnerability CVE-2025-42999. The patch for this vulnerability removes residual risk that remained after patching CVE-2025-31324<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. On May 15, 2025, CISA added CVE-2025-31324 and CVE-2025-42999 to their Known Exploited Vulnerabilities (KEV) Catalog<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre is aware of reports that CVE-2025-31324 has been actively exploited since March 2025<sup id=\"fn4a-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<h2>Indicators Of Compromise (IOCs)<\/h2>\n\n<p>The <abbr title=\"Indicators Of Compromise\">IOCs<\/abbr> reported in the following URLs are associated with exploitation of this vulnerability:<\/p>\n\n<p><a href=\"https:\/\/github.com\/Onapsis\/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment\">Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment<\/a><\/p>\n\n<p><a href=\"https:\/\/onapsis.com\/blog\/active-exploitation-of-sap-vulnerability-cve-2025-31324\/\">SAP NetWeaver Flaw Lets Threat Actors Take Full Control: CVE-2025-31324 and CVE-2025-42999 Explained<\/a><\/p>\n\n<p><a href=\"https:\/\/blog.eclecticiq.com\/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures\">China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures<\/a><\/p>\n\n<p><a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise\/\">ReliaQuest Uncovers New Critical Vulnerability in SAP NetWeaver <\/a><\/p>\n\n<p><a href=\"https:\/\/unit42.paloaltonetworks.com\/threat-brief-sap-netweaver-cve-2025-31324\/\">Threat Brief: CVE-2025-31324<\/a><\/p>\n\n<p><a href=\"https:\/\/redcanary.com\/blog\/threat-intelligence\/cve-2025-31324\/\">Critical vulnerability in SAP NetWeaver enables malicious file uploads<\/a><\/p>\n\n<h2>Suggested Actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations using SAP NetWeaver review the SAP Security Notes 3594142 and 3604119<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> and apply the necessary updates and mitigations to address these vulnerabilities.<\/p>\n\n<p>Restrict access to the \/developmentserver\/metadatauploader endpoint using firewall policies or SAP Web Dispatcher. Block unauthenticated or public network access and limit internal access to authorized administrators.<\/p>\n\n<p>Execute in-depth investigations in potentially exposed and vulnerable SAP systems, searching for known IoCs. Please consider that threat actors may have performed post-exploitation activity \u201cliving-off-the-land\u201d (LoTL), without the deployment of webshells.<\/p>\n\n<p>The indicators of compromise (IOCs) are being provided as is by the Cyber Centre for situational awareness and potential action. As some of the indicators provided may be legitimate software or infrastructure, or may be otherwise used for legitimate purposes, the detection or presence of activity related to these indicators does not necessarily imply a compromise. These indicators should be treated in an investigative, forensic or threat hunting context and used in conjunction with one another, particularly if evidence of the activity described in this alert is observed <sup id=\"fn4b-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5a-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>. It is important to verify business services and network environments before implementing any blocks based on these indicators.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/april-2025.html\">SAP Security Patch Day\u00a0- April 2025<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-31324\">CVE-2025-31324 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/may-2025.html\">SAP Security Patch Day\u00a0- May 2025<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/onapsis.com\/blog\/active-exploitation-of-sap-vulnerability-cve-2025-31324\/\">SAP NetWeaver Flaw Lets Threat Actors Take Full Control: CVE-2025-31324 Explained<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise\/\">ReliaQuest Uncovers New Critical Vulnerability in SAP NetWeaver<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/me.sap.com\/notes\/3594142\">SAP 3594142<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/me.sap.com\/notes\/3604119\">SAP 3604119<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=netweaver&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url=\">CISA Known Exploited Vulnerabilities Catalog<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-impacting-sap-netweaver-cve-2025-31324-cve-2025-42999","alert_type":397,"serial_number":"AL25-006","subject":"sap","moderation_state":"published","external_url":null},{"nid":6378,"title":"GitLab security advisory (AV25-287)","uuid":"ebdc86d8-08fb-4aa2-8db0-4fd7877b5aab","banner":null,"lang":"en","date_modified":"2025-05-21","date_modified_ts":"2025-05-21T20:07:21Z","date_created":"2025-05-21T20:01:39Z","summary":null,"body":["<article data-history-node-id=\"6378\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-287\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-287<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 21, 2025<\/p>\n\n<p>On May 21, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.0.1, 17.11.3 and 17.10.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.0.1, 17.11.3 and 17.10.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/05\/21\/patch-release-gitlab-18-0-1-released\/\">GitLab Patch Release: 18.0.1, 17.11.3, 17.10.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-287","alert_type":396,"serial_number":"AV25-287","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6379,"title":"Cisco security advisory (AV25-288)","uuid":"2b0dd775-b6d3-47c7-a17d-fb9e844eb5ac","banner":null,"lang":"en","date_modified":"2025-05-21","date_modified_ts":"2025-05-21T20:16:13Z","date_created":"2025-05-21T20:11:10Z","summary":null,"body":["<article data-history-node-id=\"6379\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-288\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-288<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 21, 2025<\/p>\n\n<p>On May 21, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included was an update for the following product:<\/p>\n\n<ul><li>Cisco Identity Services Engine (ISE)\u00a0\u2013 version 3.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-restart-ss-uf986G2Q\">Cisco Identity Services Engine RADIUS Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-288","alert_type":396,"serial_number":"AV25-288","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6380,"title":"HPE security advisory (AV25-289)","uuid":"e0b94fc0-cf6f-44dd-aced-2e2514784e69","banner":null,"lang":"en","date_modified":"2025-05-22","date_modified_ts":"2025-05-22T14:23:43Z","date_created":"2025-05-22T14:17:03Z","summary":null,"body":["<article data-history-node-id=\"6380\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-289\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-289<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 22, 2025<\/p>\n\n<p>On May 22, 2025, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE NonStop SSL (T0910)\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE MR-WIN6530 (T0819)\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE NonStop SSH Server (T0801)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbns04859en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- HPESBNS04859<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-289","alert_type":396,"serial_number":"AV25-289","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6381,"title":"[Control systems] ABB security advisory (AV25-290)","uuid":"81fde562-22f8-43cc-a9ef-81cfe8c7466c","banner":null,"lang":"en","date_modified":"2025-05-22","date_modified_ts":"2025-05-22T19:31:57Z","date_created":"2025-05-22T19:24:38Z","summary":null,"body":["<article data-history-node-id=\"6381\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-290\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-290<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 22, 2025<\/p>\n\n<p>On May 22, 2025, ABB published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>ASPECT-Enterprise ASP-ENT-x model\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>NEXUS Series NEX-2x and NEXUS-3-x model\u00a0\u2013 version 3.08.03 and prior<\/li>\n\t<li>MATRIX Series MAT-x model\u00a0\u2013 version 3.08.03 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A0021&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">ELSB\/BLBA ASPECT advisory several CVEs<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-290","alert_type":398,"serial_number":"AV25-290","subject":"abb","moderation_state":"published","external_url":null},{"nid":6383,"title":"[Control systems] Siemens security advisory (AV25-291)","uuid":"f502b98d-e8a5-44b1-82e0-d204272d610c","banner":null,"lang":"en","date_modified":"2025-05-23","date_modified_ts":"2025-05-23T20:15:15Z","date_created":"2025-05-23T20:05:46Z","summary":null,"body":["<article data-history-node-id=\"6383\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-291\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-291<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 23, 2025<\/p>\n\n<p>On May 23, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included was an update for the following:<\/p>\n\n<ul><li>SiPass integrated\u00a0\u2013 versions prior to V2.95.3.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-041082.html\">Siemens Security Advisory\u00a0- SSA-041082<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-291","alert_type":398,"serial_number":"AV25-291","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6384,"title":"Dell security advisory (AV25-292)","uuid":"ff8deb22-2cda-4396-b47f-d698f5cad066","banner":null,"lang":"en","date_modified":"2025-05-26","date_modified_ts":"2025-05-26T13:52:31Z","date_created":"2025-05-26T13:40:01Z","summary":null,"body":["<article data-history-node-id=\"6384\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-292\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-292<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 26, 2025<\/p>\n\n<p>Between May 19 and 25, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Networking OS10\u00a0\u2013 versions prior to 10.5.6.9<\/li>\n\t<li>CloudBoost Virtual Appliance\u00a0\u2013 versions prior to 19.12.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000322822\/dsa-2025-175-security-update-for-dell-cloudboost-virtual-multiple-third-party-component-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-175<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000322758\/dsa-2025-160-security-update-for-dell-networking-os10-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-160<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-us\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-292","alert_type":396,"serial_number":"AV25-292","subject":"dell","moderation_state":"published","external_url":null},{"nid":6385,"title":"IBM security advisory (AV25-293)","uuid":"3847bc43-98d2-4424-ae2c-77ec3c575144","banner":null,"lang":"en","date_modified":"2025-05-26","date_modified_ts":"2025-05-26T14:03:34Z","date_created":"2025-05-26T13:55:13Z","summary":null,"body":["<article data-history-node-id=\"6385\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-293\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-293<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 26, 2025<\/p>\n\n<p>Between May 19 and 25, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Integrated Analytics System\u00a0\u2013 versions 1.0.0.0 to 1.0.30.0<\/li>\n\t<li>IBM Integration Bus\u00a0\u2013 versions 10.1.0.0 to 10.1.0.5<\/li>\n\t<li>IBM MANTA Automated Data Lineage for IBM Cloud Pak for Data\u00a0\u2013 versions 5.0 to 5.1.2<\/li>\n\t<li>IBM Maximo AI Service\u00a0\u2013 version 9.0.5<\/li>\n\t<li>IBM Security QRadar EDR\u00a0\u2013 version 3.12<\/li>\n\t<li>IBM watsonx Assistant Cartridge\u00a0\u2013 versions 4.0 to 5.1.2<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge\u00a0- Assistant Builder Component\u00a0\u2013 versions 5.0 to 5.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-293","alert_type":396,"serial_number":"AV25-293","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6386,"title":"Ubuntu security advisory (AV25-294)","uuid":"5261ea4b-9216-46ee-bbdc-f37a371ef81a","banner":null,"lang":"en","date_modified":"2025-05-26","date_modified_ts":"2025-05-26T14:12:32Z","date_created":"2025-05-26T14:07:20Z","summary":null,"body":["<article data-history-node-id=\"6386\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-294\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-294<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 26, 2025<\/p>\n\n<p>Between May 19 and 25, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-294","alert_type":396,"serial_number":"AV25-294","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6387,"title":"[Control systems] CISA ICS security advisories (AV25\u2013295)","uuid":"db9dd9bf-0d54-4d2c-85cf-8ea9d498f231","banner":null,"lang":"en","date_modified":"2025-05-26","date_modified_ts":"2025-05-26T14:27:16Z","date_created":"2025-05-26T14:17:12Z","summary":null,"body":["<article data-history-node-id=\"6387\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-295\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25\u2013295<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 26, 2025<\/p>\n\n<p>Between May 19 and 25, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABUP IoT Cloud Platform\u00a0\u2013 all versions<\/li>\n\t<li>Assured Telematics Inc (ATI) Fleet Management System\u00a0\u2013 versions prior to February 6th, 2025<\/li>\n\t<li>AutomationDirect MB-Gateway\u00a0\u2013 all versions<\/li>\n\t<li>Danfoss AK-SM 8xxA Series\u00a0\u2013 versions prior to R4.2<\/li>\n\t<li>Lantronix Device Installer\u00a0\u2013 versions 4.4.0.7 and prior<\/li>\n\t<li>Mitsubishi Electric GENESIS64 AlarmWorX Multimedia (AlarmWorX64 MMX)\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric MC Works64 AlarmWorX Multimedia (AlarmWorX64 MMX)\u00a0\u2013 all versions<\/li>\n\t<li>National Instruments Circuit Design Suite\u00a0\u2013 versions 14.3.0 and prior<\/li>\n\t<li>Rockwell Automation 95057C-FTHTWXCT11\u00a0\u2013 versions v4.02.00 and prior<\/li>\n\t<li>Schneider Electric Galaxy VL\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Galaxy VS\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Galaxy VXL\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Controllers LMC058\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Controllers M241\u00a0\u2013 versions prior to 5.3.12.48<\/li>\n\t<li>Schneider Electric Modicon Controllers M251\u00a0\u2013 versions prior to 5.3.12.48<\/li>\n\t<li>Schneider Electric Modicon Controllers M258\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric PrismaSeT Active\u00a0- Wireless Panel Server\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Siveillance Video\u00a0\u2013 versions V24.1 and later<\/li>\n\t<li>Vertiv Liebert IS-UNITY\u00a0\u2013 versions 8.4.1.0 and prior<\/li>\n\t<li>Vertiv Liebert RDU101\u00a0\u2013 versions 1.9.0.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-295","alert_type":398,"serial_number":"AV25\u2013295","subject":"ics","moderation_state":"published","external_url":null},{"nid":6388,"title":"Red Hat security advisory (AV25-296)","uuid":"7ece2dba-57e1-4798-8592-d2ab63aed418","banner":null,"lang":"en","date_modified":"2025-05-26","date_modified_ts":"2025-05-26T19:17:03Z","date_created":"2025-05-26T19:07:03Z","summary":null,"body":["<article data-history-node-id=\"6388\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-296\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-296<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 26, 2025<\/p>\n\n<p>Between May 19 and 25, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for IBM\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Power\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:7937\">RHSA-2025:7937\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:8056\">RHSA-2025:8056\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:8057\">RHSA-2025:8057\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:8058\">RHSA-2025:8058\u00a0- Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-296","alert_type":396,"serial_number":"AV25-296","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6389,"title":"Mozilla security advisory (AV25-297)","uuid":"608deb84-b8e4-4992-ba31-e8dc54b0c62f","banner":null,"lang":"en","date_modified":"2025-05-27","date_modified_ts":"2025-05-27T14:16:21Z","date_created":"2025-05-27T14:09:33Z","summary":null,"body":["<article data-history-node-id=\"6389\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-297\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-297<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 27, 2025<\/p>\n\n<p>On May 27, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 128.11<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.24<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 139<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-44\/\">Mozilla Foundation Security Advisory 2025-44<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-43\/\">Mozilla Foundation Security Advisory 2025-43<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-42\/\">Mozilla Foundation Security Advisory 2025-42<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-297","alert_type":396,"serial_number":"AV25-297","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6391,"title":"Citrix security advisory (AV25-298)","uuid":"89dc2494-0130-4737-8fb8-3802910b1cae","banner":null,"lang":"en","date_modified":"2025-05-27","date_modified_ts":"2025-05-27T17:33:19Z","date_created":"2025-05-27T17:27:50Z","summary":null,"body":["<article data-history-node-id=\"6391\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-298\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-298<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 27, 2025<\/p>\n\n<p>On May 27, 2025, Citrix published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>XenServer VM Tools for Windows\u00a0\u2013 versions prior to 9.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/s\/article\/CTX692748-xenserver-and-citrix-hypervisor-security-update-for-cve202527462-cve202527463-cve202527464?language=en_US\">Citrix Security Advisory\u00a0\u2013 CTX692748<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/s\/?language=en_US#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-298","alert_type":396,"serial_number":"AV25-298","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6392,"title":"Google Chrome security advisory (AV25-299)","uuid":"e8cb1e0c-65a0-4e14-9faa-19e3c5a37111","banner":null,"lang":"en","date_modified":"2025-05-27","date_modified_ts":"2025-05-27T20:09:23Z","date_created":"2025-05-27T20:02:16Z","summary":null,"body":["<article data-history-node-id=\"6392\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-299\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-299<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 27, 2025<\/p>\n\n<p>On May 27, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 137.0.7151.55\/56 (Windows\/Mac), and 137.0.7151.55 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/05\/stable-channel-update-for-desktop_27.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-299","alert_type":396,"serial_number":"AV25-299","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6393,"title":"Craft CMS security advisory (AV25-300) \u2013 Update 1","uuid":"f5f2ae9d-87c0-45ee-a419-290b6c414eea","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T14:35:40Z","date_created":"2025-05-28T15:48:24Z","summary":null,"body":["<article data-history-node-id=\"6393\" about=\"\/en\/alerts-advisories\/craft-cms-security-advisory-av25-300\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-300<br \/><strong>Date: <\/strong>May\u00a028, 2025<br \/><strong>Updated:<\/strong> March\u00a023, 2026<\/p>\n\n<p>On April\u00a07, 2025, Craft CMS published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Craft CMS\u00a0\u2013 versions prior to 9.15, 4.14.15 and 5.6.17<\/li>\n<\/ul><p>Craft CMS has received reports that CVE-2025\u201132432 has been exploited.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On March\u00a020, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025\u201132432 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/craftcms.com\/knowledge-base\/craft-cms-cve-2025-32432\">Craft CMS and CVE-2025\u201132432<\/a><\/li>\n\t<li><a href=\"https:\/\/craftcms.com\/knowledge-base\/security\">Craft CMS Security Articles<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32432\">CISA KEV: CVE-2025\u201132432<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/craft-cms-security-advisory-av25-300","alert_type":396,"serial_number":"AV25-300","subject":"other","moderation_state":"published","external_url":null},{"nid":6394,"title":"ConnectWise security advisory (AV25-301)","uuid":"16a06697-33af-4c94-a107-7ce047587ed9","banner":null,"lang":"en","date_modified":"2025-05-30","date_modified_ts":"2025-05-30T14:39:18Z","date_created":"2025-05-30T14:29:22Z","summary":null,"body":["<article data-history-node-id=\"6394\" about=\"\/en\/alerts-advisories\/connectwise-security-advisory-av25-301\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-301<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 30, 2025<\/p>\n\n<p>On April 24, 2025, ConnectWise published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ConnectWise ScreenConnect\u00a0\u2013 version 25.2.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/screenconnect-security-patch-2025.4\">ScreenConnect 25.2.4 Security Patch<\/a><\/li>\n\t<li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/advisories\">ConnectWise\u00a0- Latest Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/connectwise-security-advisory-av25-301","alert_type":396,"serial_number":"AV25-301","subject":"other","moderation_state":"published","external_url":null},{"nid":6395,"title":"Microsoft Edge security advisory (AV25-302)","uuid":"706c7199-c778-423e-9a2f-06b6c22acae9","banner":null,"lang":"en","date_modified":"2025-05-30","date_modified_ts":"2025-05-30T14:49:55Z","date_created":"2025-05-30T14:44:55Z","summary":null,"body":["<article data-history-node-id=\"6395\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-302\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-302<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 30, 2025<\/p>\n\n<p>On May 29, 2025, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 137.0.3296.52<\/li>\n\t<li>Microsoft Extended Edge Stable Channel\u00a0\u2013 versions prior to 136.0.3240.104<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-29-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-302","alert_type":396,"serial_number":"AV25-302","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6396,"title":"HPE security advisory (AV25-303)","uuid":"3f2510c6-9697-4a7e-97be-609bbe51ba05","banner":null,"lang":"en","date_modified":"2025-05-30","date_modified_ts":"2025-05-30T15:00:12Z","date_created":"2025-05-30T14:53:44Z","summary":"On May 30, 2025, HPE published a security advisory to address vulnerabilities in the following product:\nHPE OneView\u00a0\u2013 versions prior to v10.00","body":["<article data-history-node-id=\"6396\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-303\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-303<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>May 30, 2025<\/p>\n\n<p>On May 30, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE OneView\u00a0\u2013 versions prior to v10.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04853en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- hpesbgn04853en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-303","alert_type":396,"serial_number":"AV25-303","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6397,"title":"Red Hat security advisory (AV25-304)","uuid":"4faf16d5-c605-4c38-9fcd-3ae17a0aac26","banner":null,"lang":"en","date_modified":"2025-06-02","date_modified_ts":"2025-06-02T14:36:33Z","date_created":"2025-06-02T14:29:00Z","summary":"Red Hat security advisory (AV25-304)","body":["<article data-history-node-id=\"6397\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-304\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-304<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June\u00a02, 2025<\/p>\n\n<p>Between May\u00a026 and June\u00a01, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Power LE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-304","alert_type":396,"serial_number":"AV25-304","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6398,"title":"Ubuntu security advisory (AV25-305)","uuid":"61802638-246a-461f-900e-5115cae158df","banner":null,"lang":"en","date_modified":"2025-06-02","date_modified_ts":"2025-06-02T14:54:59Z","date_created":"2025-06-02T14:49:14Z","summary":"Ubuntu security advisory (AV25-305)","body":["<article data-history-node-id=\"6398\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-305\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-305<br \/><strong>Date: <\/strong>June\u00a02, 2025<\/p>\n\n<p>Between May\u00a026 and June\u00a01, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 ESM<\/li>\n\t<li>Ubuntu 18.04 ESM<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-305","alert_type":396,"serial_number":"AV25-305","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6399,"title":"Dell security advisory (AV25-306)","uuid":"30b2f58e-cfb9-42fd-a42f-ddae751f4817","banner":null,"lang":"en","date_modified":"2025-06-02","date_modified_ts":"2025-06-02T15:38:06Z","date_created":"2025-06-02T15:28:23Z","summary":"Dell security advisory (AV25-306)","body":["<article data-history-node-id=\"6399\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-306\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-306<br \/><strong>Date: <\/strong>June\u00a02, 2025<\/p>\n\n<p>Between May\u00a026 and June\u00a01, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.03.01.00<\/li>\n\t<li>Dell Avamar\u00a0\u2013 multiple versions and products<\/li>\n\t<li>Dell Connectrix SANnav\u00a0\u2013 versions prior to 2.3.1a<\/li>\n\t<li>Dell NetWorker Runtime Environment\u00a0(NRE)\u00a0\u2013 version 8.0.24<\/li>\n\t<li>Dell NetWorker Virtual Edition\u00a0(NVE)\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerProtect DP Series Appliance\u00a0(IDPA)\u00a0\u2013 versions prior to 2.7.8<\/li>\n\t<li>Dell ThinOS\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 versions 7.0.000 to 7.0.541<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-306","alert_type":396,"serial_number":"AV25-306","subject":"dell","moderation_state":"published","external_url":null},{"nid":6400,"title":"IBM security advisory (AV25-307)","uuid":"75438942-3569-42cd-97a3-b70b330b90fb","banner":null,"lang":"en","date_modified":"2025-06-02","date_modified_ts":"2025-06-02T16:02:18Z","date_created":"2025-06-02T15:57:32Z","summary":"IBM security advisory (AV25-307)","body":["<article data-history-node-id=\"6400\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-307\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-307<br \/><strong>Date: <\/strong>June\u00a02, 2025<\/p>\n\n<p>Between May\u00a026 and June\u00a01, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Astronomer with IBM\u00a0\u2013 version 0.36.1<\/li>\n\t<li>IBM DataStage on Cloud Pak for Data\u00a0\u2013 versions 8.9 and 5.1.3<\/li>\n\t<li>IBM\u00ae Db2\u00ae\u00a0\u2013 version 1.0 to 11.1.4.7, 11.5.0 to 11.5.9 and 12.1.0 to 12.1.1<\/li>\n\t<li>IBM DS8900F and DS8A00\u00a0\u2013 multiple products and versions<\/li>\n\t<li>IBM Guardium Data Protection\u00a0\u2013 version 0<\/li>\n\t<li>IBM InfoSphere Information Server\u00a0\u2013 version 7<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Observability with Instana\u00a0(OnPrem)\u00a0\u2013 Build 1.0.292 to 1.0.295<\/li>\n\t<li>IBM Process Mining\u00a0\u2013 version 0.1<\/li>\n\t<li>IBM Rapid Infrastructure Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Guardium Data Protection\u00a0\u2013 version 0<\/li>\n\t<li>IBM SPSS Collaboration and Deployment Services\u00a0\u2013 version 5<\/li>\n\t<li>IBM Tivoli Monitoring\u00a0\u2013 versions 6.3.0.7 to 6.3.0.7 Service Pack 19<\/li>\n\t<li>IBM Watson Discovery Cartridge ICP\u00a0\u2013 Discovery\u00a0\u2013 version 0.0 to 5.0.3<\/li>\n\t<li>IBM Watson Knowledge Catalog on-prem\u00a0\u2013 Discovery\u00a0\u2013 versions 8.6 and 4.8.7<\/li>\n\t<li>IBM Watson Knowledge Catalog on-prem\u00a0\u2013 Discovery\u00a0\u2013 versions 0.2, 5.0.3 and 5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-307","alert_type":396,"serial_number":"AV25-307","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6401,"title":"[Control systems] CISA ICS security advisories (AV25\u2013308)","uuid":"b4430836-6c11-498a-9e78-d8167dc1fd7e","banner":null,"lang":"en","date_modified":"2025-06-02","date_modified_ts":"2025-06-02T17:30:59Z","date_created":"2025-06-02T17:15:16Z","summary":"[Control systems] CISA ICS security advisories (AV25\u2013308)","body":["<article data-history-node-id=\"6401\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-308\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25\u2013308<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 2, 2025<\/p>\n\n<p>Between May 26 and June 1, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Consilium Safety CS5000 Fire Panel\u00a0\u2013 all versions<\/li>\n\t<li>Instantel Micromate\u00a0\u2013 all versions<\/li>\n\t<li>Johnson Controls iSTAR Configuration Utility (ICU) Tool\u00a0\u2013 versions prior to 6.9.5<\/li>\n\t<li>Santesoft Sante DICOM Viewer Pro\u00a0\u2013 versions 14.2.1 and prior<\/li>\n\t<li>Siemens SiPass integrated\u00a0\u2013 versions prior to V2.95.3.18<\/li>\n\t<li>Siemens SiPass integrated AC5102 (ACC-G2)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SiPass integrated ACC-AP\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-308","alert_type":398,"serial_number":"AV25\u2013308","subject":"ics","moderation_state":"published","external_url":null},{"nid":6402,"title":"Roundcube security advisory (AV25-309) - Update 1","uuid":"b3285c48-8717-4fb7-98d4-0d523c52420a","banner":null,"lang":"en","date_modified":"2026-02-20","date_modified_ts":"2026-02-20T20:59:37Z","date_created":"2025-06-02T18:19:53Z","summary":"On June 1, 2025, Roundcube published security advisories to address vulnerabilities.","body":["<article data-history-node-id=\"6402\" about=\"\/en\/alerts-advisories\/roundcube-security-advisory-av25-309\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-309<br \/><strong>Date: <\/strong>June 2, 2025<br \/><strong>Updated: <\/strong>February 20, 2026<\/p>\n\n<p>On June 1, 2025, Roundcube published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Webmail\u00a0\u2013 versions prior to 1.5.10<\/li>\n\t<li>Webmail\u00a0\u2013 versions prior to 1.6.11<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On February 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-49113 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/roundcube.net\/news\/2025\/06\/01\/security-updates-1.6.11-and-1.5.10\">Security updates 1.6.11 and 1.5.10 released<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.6.11\">Roundcube Webmail 1.6.11<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.5.10 \">Roundcube Webmail 1.5.10<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113\">CISA KEV: CVE-2025-49113<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/roundcube-security-advisory-av25-309","alert_type":396,"serial_number":"AV25-309","subject":"other","moderation_state":"published","external_url":null},{"nid":6403,"title":"HPE security advisory (AV25-310)","uuid":"dfd70f47-ea43-48cb-ae02-b1abc8472a08","banner":null,"lang":"en","date_modified":"2025-06-02","date_modified_ts":"2025-06-02T19:52:42Z","date_created":"2025-06-02T19:43:29Z","summary":"HPE security advisory (AV25-310)","body":["<article data-history-node-id=\"6403\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-310\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-310<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 2, 2025<\/p>\n\n<p>On June 2, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE StoreOnce Software\u00a0\u2013 versions prior to 4.3.11<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04847en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- HPESBST04847<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-310","alert_type":396,"serial_number":"AV25-310","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6404,"title":"[Control systems] ABB security advisory (AV25-311)","uuid":"a8866fc3-c1ab-4864-984f-330a20dad23b","banner":null,"lang":"en","date_modified":"2025-06-03","date_modified_ts":"2025-06-03T14:22:02Z","date_created":"2025-06-03T14:16:01Z","summary":null,"body":["<article data-history-node-id=\"6404\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-311\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-311<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 3, 2025<\/p>\n\n<p>On June 2, 2025, ABB published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Welcome IP-Gateway\u00a0\u2013 version 6.20 and prior<\/li>\n\t<li>Welcome IP-Gateway (Welcome M)\u00a0\u2013 version 6.20 and prior<\/li>\n\t<li>Welcome IP-Gateway MDRC\u00a0\u2013 version 6.20 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108470A8948&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch&amp;_gl=1*womjy7*_gcl_au*NTQ3NzU3MjAzLjE3NDU5Mzc0MzM.*_ga*MTcwODEzMTk2MC4xNzIwMDkyNDk2*_ga_46ZFBRSZNM*czE3NDg4OTQzMTckbzUzJGcwJHQxNzQ4ODk0MzE3JGo2MCRsMCRoMA..\">ELSB\/Home Solutions Outdated SW Components in ABB Welcome IP-Gateway<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-311","alert_type":398,"serial_number":"AV25-311","subject":"abb","moderation_state":"published","external_url":null},{"nid":6405,"title":"SolarWinds security advisory (AV25-312)","uuid":"5f458a77-344c-4b60-a444-f945792d1b9a","banner":null,"lang":"en","date_modified":"2025-06-03","date_modified_ts":"2025-06-03T14:58:09Z","date_created":"2025-06-03T14:52:33Z","summary":null,"body":["<article data-history-node-id=\"6405\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-312\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-312<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 3, 2025<\/p>\n\n<p>On June 2, 2025, SolarWinds published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SolarWinds Platform\u00a0\u2013 version 12.3.1.20 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2025-26396\">SolarWinds DameWare Mini Remote Control Service Incorrect Permissions Local Privilege Escalation Vulnerability (CVE-2025-26396)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-312","alert_type":396,"serial_number":"AV25-312","subject":"other","moderation_state":"published","external_url":null},{"nid":6406,"title":"Splunk security advisory (AV25-313)","uuid":"d1622f87-3771-4be6-929e-abad0ce8d7ac","banner":null,"lang":"en","date_modified":"2025-06-03","date_modified_ts":"2025-06-03T15:14:04Z","date_created":"2025-06-03T15:02:53Z","summary":null,"body":["<article data-history-node-id=\"6406\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-313\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-313<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 3, 2025<\/p>\n\n<p>On June 2, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk Enterprise\u00a0\u2013 versions prior to 9.4.2, 9.3.4, 9.2.6 and 9.1.9<\/li>\n\t<li>Splunk Universal Forwarder\u00a0\u2013 versions prior to 9.4.2, 9.3.4, 9.2.6 and 9.1.9<\/li>\n\t<li>Splunk Universal Forwarder for Windows\u00a0\u2013 versions prior to 9.4.2, 9.3.4, 9.2.6 and 9.1.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0602\">Incorrect permission assignment on Universal Forwarder for Windows during new installation or upgrade<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0603\">Third-Party Package Updates in Splunk Enterprise\u00a0- June 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0604\">Third-Party Package Updates in Splunk Universal Forwarder\u00a0- June 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\">Splunk Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-313","alert_type":396,"serial_number":"AV25-313","subject":"other","moderation_state":"published","external_url":null},{"nid":6407,"title":"Google Chrome security advisory (AV25-314)","uuid":"e18e5a6d-6086-4d52-8e5f-36b000f0242c","banner":null,"lang":"en","date_modified":"2025-06-03","date_modified_ts":"2025-06-03T17:42:07Z","date_created":"2025-06-03T17:32:08Z","summary":null,"body":["<article data-history-node-id=\"6407\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-314\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-314<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 3, 2025<\/p>\n\n<p>On June 2, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 137.0.7151.68\/.69 (Windows\/Mac), and 137.0.7151.68 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2025-5419 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/06\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-314","alert_type":396,"serial_number":"AV25-314","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6408,"title":"Qualcomm security advisory \u2013 June 2025 monthly rollup (AV25-315)","uuid":"602f6d6f-ce58-4f1d-9e87-f609706d7562","banner":null,"lang":"en","date_modified":"2025-06-03","date_modified_ts":"2025-06-03T19:46:52Z","date_created":"2025-06-03T19:40:43Z","summary":null,"body":["<article data-history-node-id=\"6408\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-june-2025-monthly-rollup-av25-315\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-315<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 3, 2025<\/p>\n\n<p>On June 2, 2025, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>Qualcomm is aware that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/june-2025-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 June <\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-june-2025-monthly-rollup-av25-315","alert_type":396,"serial_number":"AV25-315","subject":"other","moderation_state":"published","external_url":null},{"nid":6409,"title":"HPE security advisory (AV25-316)","uuid":"0231163a-a7aa-4dcf-8daa-5e845b3a079c","banner":null,"lang":"en","date_modified":"2025-06-04","date_modified_ts":"2025-06-04T14:39:20Z","date_created":"2025-06-04T14:35:09Z","summary":null,"body":["<article data-history-node-id=\"6409\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-316\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-316<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 4, 2025<\/p>\n\n<p>On June 3, 2025, HPE published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.3.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04872en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- HPESBNW04872<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-316","alert_type":396,"serial_number":"AV25-316","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6410,"title":"Microsoft Edge security advisory (AV25-317)","uuid":"03331d01-d0bf-4be2-8598-b00a7cb6e5b2","banner":null,"lang":"en","date_modified":"2025-06-04","date_modified_ts":"2025-06-04T17:23:43Z","date_created":"2025-06-04T17:18:41Z","summary":null,"body":["<article data-history-node-id=\"6410\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-317\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-317<br \/><strong>Date: <\/strong>June\u00a04, 2025<\/p>\n\n<p>On June\u00a03, 2025, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 137.0.3296.62<\/li>\n<\/ul><p>The Chromium team is aware that an exploit for CVE-2025-5419 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-3-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-317","alert_type":396,"serial_number":"AV25-317","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6411,"title":"Cisco security advisory (AV25-318)","uuid":"f5e9915a-ab18-4a38-a190-511d8bc4a387","banner":null,"lang":"en","date_modified":"2025-06-04","date_modified_ts":"2025-06-04T19:51:43Z","date_created":"2025-06-04T19:41:55Z","summary":null,"body":["<article data-history-node-id=\"6411\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-318\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-318<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 4, 2025<\/p>\n\n<p>On June 4, 2025, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Cisco Identity Services Engine on Cloud Platforms (AWS)\u00a0\u2013 versions 3.1, 3.2, 3.3 and 3.4<\/li>\n\t<li>Cisco Identity Services Engine on Cloud Platforms (Azure)\u00a0\u2013 versions 3.2, 3.3 and 3.4<\/li>\n\t<li>Cisco Identity Services Engine on Cloud Platforms (OCI)\u00a0\u2013 versions 3.2, 3.3 and 3.4<\/li>\n\t<li>Cisco Integrated Management Controller\u00a0\u2013 UCS B-Series Blade Servers<\/li>\n\t<li>Cisco Integrated Management Controller\u00a0\u2013 UCS C-Series Rack Servers<\/li>\n\t<li>Cisco Integrated Management Controller\u00a0\u2013 UCS S-Series Storage Servers<\/li>\n\t<li>Cisco Integrated Management Controller\u00a0\u2013 UCS X-Series Modular System<\/li>\n\t<li>Cisco Nexus Dashboard Fabric Controller (NDFC)\u00a0\u2013 versions prior to 3.2(2f)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-aws-static-cred-FPMjUcm7\">Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ucs-ssh-priv-esc-2mZDtdjM\">Cisco Integrated Management Controller Privilege Escalation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ndfc-shkv-snQJtjrp\">Cisco Nexus Dashboard Fabric Controller SSH Host Key Validation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-318","alert_type":396,"serial_number":"AV25-318","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6412,"title":"VMware security advisory (AV25-319)","uuid":"7427a8fb-66e5-494c-b93f-49837c4e598f","banner":null,"lang":"en","date_modified":"2025-06-05","date_modified_ts":"2025-06-05T15:28:30Z","date_created":"2025-06-05T15:07:56Z","summary":null,"body":["<article data-history-node-id=\"6412\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-319\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-319<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 5, 2025<\/p>\n\n<p>On June 4, 2025, VMware released a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation\u00a0\u2013 versions 5.0.x, 5.1.x and 5.2.x<\/li>\n\t<li>VMware NSX\u00a0\u2013 versions 4.0.x, 4.1.x, 4.2.1.x and 4.2.x<\/li>\n\t<li>VMware Telco Cloud Infrastructure\u00a0\u2013 versions 2.x and 3.x<\/li>\n\t<li>VMware Telco Cloud Platform\u00a0\u2013 versions 3.x, 4.x and 5.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25738\">VMSA-2025-0012: VMware NSX updates address multiple vulnerabilities (CVE-2025-22243, CVE-2025-22244, CVE-2025-22245)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-319","alert_type":396,"serial_number":"AV25-319","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6413,"title":"HPE security advisory (AV25-320)","uuid":"8776324b-c077-4c47-a605-0276c8dac1e5","banner":null,"lang":"en","date_modified":"2025-06-06","date_modified_ts":"2025-06-06T14:53:17Z","date_created":"2025-06-06T14:47:01Z","summary":null,"body":["<article data-history-node-id=\"6413\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-320\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-320<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 6, 2025<\/p>\n\n<p>On June 4, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Insight Remote Support\u00a0\u2013 versions prior to 7.15.0.646<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04878en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- HPESBGN04878<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-320","alert_type":396,"serial_number":"AV25-320","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6414,"title":"Jenkins security advisory (AV25-321)","uuid":"8127648b-2523-4143-803c-3174ebbe0898","banner":null,"lang":"en","date_modified":"2025-06-06","date_modified_ts":"2025-06-06T15:03:18Z","date_created":"2025-06-06T14:57:11Z","summary":null,"body":["<article data-history-node-id=\"6414\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-321\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-321<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 6, 2025<\/p>\n\n<p>On June 6, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Gatling Plugin\u00a0\u2013 version 136.vb_9009b_3d33a_e and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-06-06\/\">Jenkins Security Advisory 2025-06-06<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-321","alert_type":396,"serial_number":"AV25-321","subject":"other","moderation_state":"published","external_url":null},{"nid":6417,"title":"Android security advisory \u2013 June 2025 monthly rollup (AV25-322)","uuid":"50863432-8ba6-419c-98b2-54de0b820c4a","banner":null,"lang":"en","date_modified":"2025-06-06","date_modified_ts":"2025-06-06T18:11:55Z","date_created":"2025-06-06T18:05:05Z","summary":null,"body":["<article data-history-node-id=\"6417\" about=\"\/en\/alerts-advisories\/android-security-advisory-june-2025-monthly-rollup-av25-322\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-322<br \/><strong>Date: <\/strong>June 6, 2025<\/p>\n\n<p>On June 2, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-06-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-june-2025-monthly-rollup-av25-322","alert_type":396,"serial_number":"AV25-322","subject":"android","moderation_state":"published","external_url":null},{"nid":6419,"title":"Ubuntu security advisory (AV25-323)","uuid":"51180dcf-4d67-457a-9f31-223498270d86","banner":null,"lang":"en","date_modified":"2025-06-09","date_modified_ts":"2025-06-09T13:56:45Z","date_created":"2025-06-09T13:51:27Z","summary":null,"body":["<article data-history-node-id=\"6419\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-323\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-323<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 9, 2025<\/p>\n\n<p>Between June 2 and 8, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-323","alert_type":396,"serial_number":"AV25-323","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6420,"title":"IBM security advisory (AV25-324)","uuid":"7ca77322-5d93-46a1-962e-90b0c2ec6203","banner":null,"lang":"en","date_modified":"2025-06-09","date_modified_ts":"2025-06-09T14:07:42Z","date_created":"2025-06-09T14:01:03Z","summary":null,"body":["<article data-history-node-id=\"6420\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-324\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-324<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 9, 2025<\/p>\n\n<p>Between June 2 and 8, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>GDSC Platform On-prem\u00a0\u2013 version 3.7.1<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 versions 1.0.0 to 1.0.5<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 versions 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Security Verify Governance\u00a0\u2013 version 10.0.2<\/li>\n\t<li>IBM Security Verify Governance\u00a0- Identity Manager Virtual Appliance\u00a0\u2013 version 10.0.2<\/li>\n\t<li>Maximo AI Service\u00a0\u2013 version 9.0.5<\/li>\n\t<li>QRadar Suite Software\u00a0\u2013 versions 1.10.12.0 to 1.11.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-324","alert_type":396,"serial_number":"AV25-324","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6421,"title":"Dell security advisory (AV25-325)","uuid":"346ab707-91a4-4e40-9630-74ad3aeb57ec","banner":null,"lang":"en","date_modified":"2025-06-09","date_modified_ts":"2025-06-09T14:51:31Z","date_created":"2025-06-09T14:36:22Z","summary":null,"body":["<article data-history-node-id=\"6421\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-325\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-325<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 9, 2025<\/p>\n\n<p>Between June 2 and 8, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell SD-WAN EDGE610\/610-LTE\u00a0\u2013 versions prior to 2.6<\/li>\n\t<li>Dell SD-WAN EDGE620\/640\/680\u00a0\u2013 versions prior to 2.6<\/li>\n\t<li>Dell SmartFabric Manager\u00a0\u2013 versions prior to 1.3.0<\/li>\n\t<li>PowerSwitch E3200-ON Series\u00a0\u2013 versions prior to 3.57.5.1-5<\/li>\n\t<li>PowerSwitch N2200 Series\u00a0\u2013 versions prior to 3.45.5.1-31<\/li>\n\t<li>PowerSwitch N3200-ON Series\u00a0\u2013 versions prior to 45.5.1-31<\/li>\n\t<li>PowerSwitch S5448F-ON\u00a0\u2013 versions prior to 3.52.5.1-12<\/li>\n\t<li>PowerSwitch Z9432F-ON\u00a0\u2013 versions prior to 3.51.5.1-21<\/li>\n\t<li>PowerSwitch Z9264F-ON\u00a0\u2013 versions prior to 3.42.5.1-21<\/li>\n\t<li>VEP1400 (VEP1425\/1445\/1485)\u00a0\u2013 versions prior to 2.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000328924\/dsa-2025-233-security-update-for-dell-smartfabric-manager-multiple-third-party-component-vulnerabilities\">Dell Security Advisories \u2013 DSA-2025-233<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000328454\/dsa-2025-216-security-update-for-dell-networking-products-for-multiple-vulnerabilities\">Dell Security Advisories \u2013 DSA-2025-216<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-French-******************************************************%2D%2D%3E--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-325","alert_type":396,"serial_number":"AV25-325","subject":"dell","moderation_state":"published","external_url":null},{"nid":6422,"title":"[Control systems] CISA ICS security advisories (AV25\u2013326)","uuid":"be87bd93-6d0c-42f0-b909-913d0b609c7f","banner":null,"lang":"en","date_modified":"2025-06-09","date_modified_ts":"2025-06-09T15:34:10Z","date_created":"2025-06-09T14:58:22Z","summary":null,"body":["<article data-history-node-id=\"6422\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-326\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-326<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 9, 2025<\/p>\n\n<p>Between June 2 and 8, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CyberData 011209 SIP Emergency Intercom\u00a0\u2013 versions prior to 22.0.1<\/li>\n\t<li>Hitachi Energy Relion 670, 650, and SAM600-IO series\u00a0\u2013 multiple versions<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F Series\u00a0\u2013 multiple products and versions<\/li>\n\t<li>Schneider Electric EcoStruxure Power Build Rapsody\u00a0\u2013 version v2.7.12 FR and prior<\/li>\n\t<li>Schneider Electric Wiser AvatarOn 6k Freelocate\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Wiser Cuadro H 5P Socket\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-155-01\">CISA ICS Advisory\u00a0- CyberData 011209 SIP Emergency Intercom<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-155-02\">CISA ICS Advisory\u00a0- Hitachi Energy Relion 670, 650 Series and SAM600-IO Product<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-153-03\">CISA ICS Advisory\u00a0- Mitsubishi Electric MELSEC iQ-F Series<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-153-02\">CISA ICS Advisory\u00a0- Schneider Electric EcoStruxure Power Build Rapsody<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-153-01\">CISA ICS Advisory\u00a0- Schneider Electric Wiser Home Automation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95&amp;f%5B1%5D=advisory_type%3A96\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-French-******************************************************%2D%2D%3E--><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-326","alert_type":398,"serial_number":"AV25-326","subject":"ics","moderation_state":"published","external_url":null},{"nid":6426,"title":"[Control systems] Siemens security advisory (AV25-327) ","uuid":"1ed06075-d2a4-4b34-810e-1b6510752c93","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T16:09:11Z","date_created":"2025-06-10T16:05:49Z","summary":null,"body":["<article data-history-node-id=\"6426\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-327\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-327<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Energy Services<\/li>\n\t<li>RUGGEDCOM APE1808<\/li>\n\t<li>RUGGEDCOM RST2428P (6GK6242-6PA00) \u2013 versions prior to V3.2<\/li>\n\t<li>SCALANCE XC-300 products \u2013 versions prior to V3.2<\/li>\n\t<li>SCALANE XC-400 products \u2013 versions prior to V3.2<\/li>\n\t<li>SCALANCE XCM-\/XRM-\/XCH-\/XRH-300 products \u2013 versions prior to V3.2<\/li>\n\t<li>SCALANCE XM-400\/XR-500 products \u2013 versions prior to V3.2<\/li>\n\t<li>SCALANCE XR-300 (6GK5334-xTSxx) products \u2013 versions prior to V3.2<\/li>\n\t<li>SIMATIC S7-1500 CPU products \u2013 version V3.1.5 and later<\/li>\n\t<li>Technomatix Plant Simulation V2404 \u2013 versions prior to V2404.0013<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-327","alert_type":398,"serial_number":"AV25-327","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6427,"title":"[Control systems] Schneider Electric security advisory (AV25-328) ","uuid":"fe4f9f18-8158-4253-8046-43615caa061a","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T16:17:08Z","date_created":"2025-06-10T16:10:39Z","summary":null,"body":["<article data-history-node-id=\"6427\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-328\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-328<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EVLink WallBox \u2013 all versions<\/li>\n\t<li>Insight Facility \u2013 all versions<\/li>\n\t<li>Insight Home \u2013 all versions<\/li>\n\t<li>Modicon Controllers M241\/M251 \u2013 versions prior to 5.3.12.51<\/li>\n\t<li>Modicon Controllers M262 \u2013 versions prior to 5.3.9.18<\/li>\n\t<li>Modicon Controllers M258\/LMC058 \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-161-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-161-03.pdf \">Schneider Electric Security Notifications - EVLink WallBox (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-161-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-161-01.pdf\">Schneider Electric Security Notifications - Insight Home and Insight Facility (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-161-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-161-02.pdf\">Schneider Electric Security Notifications - Modicon Controllers M241\/M251\/M258\/LMC058\/M262 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-328","alert_type":398,"serial_number":"AV25-328","subject":"other","moderation_state":"published","external_url":null},{"nid":6428,"title":"Ivanti security advisory (AV25-329)","uuid":"09eef2a8-b491-4743-945f-3c3441e34f6d","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T17:15:30Z","date_created":"2025-06-10T17:08:03Z","summary":null,"body":["<article data-history-node-id=\"6428\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-329\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-329<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, Ivanti published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Workspace Control (IWC)\u00a0\u2013 version 10.19.0.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Workspace-Control-CVE-2025-5353-CVE-CVE-2025-22463-CVE-2025-22455?language=en_US\">Security Advisory Ivanti Workspace Control (CVE-2025-5353, CVE- CVE-2025-22463, CVE-2025-22455<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-329","alert_type":396,"serial_number":"AV25-329","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6429,"title":"SAP security advisory \u2013 June 2025 monthly rollup (AV25-330)","uuid":"f435ecdf-bec3-4474-9735-f9d9cc717b81","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T17:36:42Z","date_created":"2025-06-10T17:21:25Z","summary":null,"body":["<article data-history-node-id=\"6429\" about=\"\/en\/alerts-advisories\/sap-security-advisory-june-2025-monthly-rollup-av25-330\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-330<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP NetWeaver Application Server for ABAP\u00a0\u2013 versions KERNEL 7.89, 7.93, 9.14 and 9.15<\/li>\n\t<li>SAP GRC (AC Plugin)\u00a0\u2013 versions GRCPINW V1100_700 and V1100_731<\/li>\n\t<li>SAP Business Warehouse and SAP Plug-In Basis\u00a0\u2013 versions PI_BASIS 2006_1_700, 701, 702, 731, 740, SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, 758, 914 and 915<\/li>\n\t<li>SAP BusinessObjects Business Intelligence (BI Workspace)\u00a0\u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP NetWeaver Visual Composer\u00a0\u2013 version VCBASE 7.50<\/li>\n\t<li>SAP MDM Server\u00a0\u2013 versions MDM_SERVER 710.750<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/june-2025.html\">SAP Security Patch Day\u00a0\u2013 June 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-june-2025-monthly-rollup-av25-330","alert_type":396,"serial_number":"AV25-330","subject":"sap","moderation_state":"published","external_url":null},{"nid":6431,"title":"HPE security advisory (AV25-331)","uuid":"f9b8a4b7-b908-4f8c-b2f1-2447cf6f14cc","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T18:02:34Z","date_created":"2025-06-10T17:58:37Z","summary":null,"body":["<article data-history-node-id=\"6431\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-331\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-331<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking Private 5G Core\u00a0\u2013 versions 1.24.1.0 to 1.25.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04883en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- HPESBGN04883<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-331","alert_type":396,"serial_number":"AV25-331","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6432,"title":"Mozilla security advisory (AV25-332)","uuid":"c432e8c7-3757-4cec-9ee9-9b836ee99823","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T18:20:29Z","date_created":"2025-06-10T18:11:51Z","summary":null,"body":["<article data-history-node-id=\"6432\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-332\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-332<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, Mozilla published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 139.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-47\/\">Mozilla Security Advisory\u00a0- Security Vulnerabilities fixed in Firefox 139.0.4<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-332","alert_type":396,"serial_number":"AV25-332","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6433,"title":"Microsoft security advisory \u2013 June 2025 monthly rollup (AV25-333) \u2013 Update 1","uuid":"6aebc11b-30b5-48f2-b1a0-e3668cf23001","banner":null,"lang":"en","date_modified":"2025-06-13","date_modified_ts":"2025-06-13T20:17:36Z","date_created":"2025-06-10T19:02:10Z","summary":null,"body":["<article data-history-node-id=\"6433\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-june-2025-monthly-rollup-av25-333\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-333<br \/><strong>Date: <\/strong>June 10, 2025<br \/><strong>Updated: <\/strong>June 13, 2025<\/p>\n\n<p>On June 10, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>.NET 8.0 and 9.0\u00a0\u2013 versions 8.0.17 and 9.0.6, multiple platforms<\/li>\n\t<li>Microsoft 365 Apps\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft AutoUpdate for Mac<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Office\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Outlook 2016<\/li>\n\t<li>Microsoft PowerPoint 2016<\/li>\n\t<li>Microsoft Sharepoint Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Visual Studio 2022\u00a0\u2013 versions 17.12.9, 17.8.22, 17.10.16, and 17.14.5<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Nuance Digital Engagement Platform<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows App Client for Windows Desktop<\/li>\n\t<li>Windows Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On June 10, 2025, open-source reporting indicated that the Microsoft Windows WebDAV 0-Day vulnerability CVE-2025-33053 and Windows SMB Client 0\u2013Day CVE-2025-33073 have been actively exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Jun \">June 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-june-2025-monthly-rollup-av25-333","alert_type":396,"serial_number":"AV25-333","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6434,"title":"Red Hat security advisory (AV25-334)","uuid":"273bf89a-fabb-46ae-bd5e-503a8636e29e","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T19:12:58Z","date_created":"2025-06-10T19:10:22Z","summary":null,"body":["<article data-history-node-id=\"6434\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-334\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-334<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>Between June 2 and 8, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-334","alert_type":396,"serial_number":"AV25-334","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6435,"title":"Adobe security advisory (AV25-335)","uuid":"edcef763-c731-4b12-b6dd-e0e15dcdbb1f","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T19:38:20Z","date_created":"2025-06-10T19:33:51Z","summary":null,"body":["<article data-history-node-id=\"6435\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-335\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-335<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat DC \u2013 version 25.001.20521 and prior<\/li>\n\t<li>Acrobat Reader DC \u2013 version 25.001.20521 and prior<\/li>\n\t<li>Acrobat 2024 \u2013 version 24.001.30235 and prior<\/li>\n\t<li>Acrobat 2020 \u2013 version 20.005.30763 and prior<\/li>\n\t<li>Acrobat Reader 2020 \u2013 version 20.005.30763 and prior<\/li>\n\t<li>Adobe Commerce and Commerce B2B \u2013 multiple versions<\/li>\n\t<li>Adobe Experience Manager (AEM) \u2013 version 6.5.22 and prior<\/li>\n\t<li>Adobe InCopy \u2013 version 20.2 and prior, and version 19.53 and prior<\/li>\n\t<li>Adobe InDesign \u2013 version ID20.2 and prior, and version ID19.5.3 and prior<\/li>\n\t<li>Adobe Substance 3D Painter \u2013 version 11.0.1 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler \u2013 version 5.0 and prior<\/li>\n\t<li>Magento Open Source \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-335","alert_type":396,"serial_number":"AV25-335","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6436,"title":"Google Chrome security advisory (AV25-336)","uuid":"5067a436-41c6-408c-b29d-641afdea4de0","banner":null,"lang":"en","date_modified":"2025-06-10","date_modified_ts":"2025-06-10T19:43:10Z","date_created":"2025-06-10T19:40:04Z","summary":null,"body":["<article data-history-node-id=\"6436\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-336\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-336<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 10, 2025<\/p>\n\n<p>On June 10, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 137.0.7151.103\/.104 (Windows\/Mac), and 137.0.7151.103 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/06\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-336","alert_type":396,"serial_number":"AV25-336","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6437,"title":"AL25-007 - Vulnerability impacting Roundcube Webmail \u2013 CVE-2025-49113 \u2013 Update 1","uuid":"0f9a5b7e-3690-464f-bcb4-004608d244f9","banner":null,"lang":"en","date_modified":"2026-07-10","date_modified_ts":"2026-07-10T19:12:59Z","date_created":"2025-06-11T13:11:43Z","summary":null,"body":["<article data-history-node-id=\"6437\" about=\"\/en\/alerts-advisories\/vulnerability-impacting-roundcube-webmail-cve-2025-49113\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-007<br \/><strong>Date:<\/strong> June\u00a011, 2025<br \/><strong>Updated:<\/strong> July\u00a010, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On June\u00a01, 2025, Roundcube released a security bulletin for a critical vulnerability affecting Webmail. The issue is described as a Post-Auth RCE via PHP Object Deserialization vulnerability (CVE-2025-49113)<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. The versions of Roundcube products affected are<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>:<\/p>\n\n<ul><li>Webmail\u00a0\u2013 versions prior to 1.5.10<\/li>\n\t<li>Webmail\u00a0\u2013 versions prior to 1.6.11<\/li>\n<\/ul><p>In response to this vulnerability, the Cyber Centre released AV25-309 on June 2, 2025<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>While the Cyber Centre has not received any reports of exploitation, the existence of a proof of concept (POC) significantly raises the likeness of abuse by malicious actors. The existence of a published <abbr title=\"proof of concept\">POC<\/abbr> makes it imperative to take action to assess and mitigate this vulnerability.<\/p>\n\n<p>The Cyber Centre is aware that exploitation of CVE-2024-42009 has been used to obtain valid credentials, which could lead to exploitation of CVE-2025-49113. CISA added CVE-2024-42009 to their Known Exploited Vulnerabilities (KEV) catalog<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> on June 9, 2025.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>The Cyber Centre is aware of open-source reporting indicating ongoing exploitation<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> of CVE-2024-42009<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> and CVE-2025-49113<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> related to Roundcube Webmail.<\/p>\n\n<p>The Cyber Centre strongly recommends that organizations upgrade to the latest Roundcube Webmail versions as per AV26-657<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>:<\/p>\n\n<ul><li>Webmail\u00a0\u2013 version 1.6.17<\/li>\n\t<li>Webmail\u00a0\u2013 version 1.7.2<\/li>\n<\/ul><p>On June 9, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-42009 to their Known Exploited Vulnerabilities (KEV) Database<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>.<\/p>\n\n<p>Also, on February 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-49113 to their Known Exploited Vulnerabilities (KEV) Database<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup>.<\/p>\n\n<p><strong>End of Update 1<\/strong><\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations update to Roundcube Webmail versions 1.5.10+ or 1.6.11+<span class=\"nowrap\"><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>,<\/span> which would mitigate issues reported by both CVEs mentioned here (CVE-2024-42009 and CVE-2025-49113).<\/p>\n\n<p>The Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Assess the installation of Roundcube Webmail.<\/li>\n\t<li>Apply updates to Roundcube Webmail without delay.<\/li>\n\t<li>Monitor affected systems for signs of exploitation.<\/li>\n\t<li>Monitor for brute-force attempts and if possible, implement rate limitation techniques.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> with an emphasis on the following strategies:<\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-49113\">CVE-2025-49113<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/roundcube.net\/news\/2025\/06\/01\/security-updates-1.6.11-and-1.5.10\">Security updates 1.6.11 and 1.5.10 released<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/alerts-advisories\/roundcube-security-advisory-av25-309\">AV25-309\u00a0\u2013 Roundcube security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">CISA KEV<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cert.pl\/en\/posts\/2025\/06\/unc1151-campaign-roundcube\/\">UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/one-email-closer-edge-unkmasstraction-physics-exploitation\">One Email Closer to the Edge: UNK_MassTraction &amp; the Physics of Exploitation<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-42009\">CVE-2024-42009 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"\/en\/alerts-advisories\/roundcube-security-advisory-av26-657\">AV25-657\u00a0\u2013 Roundcube security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-42009\">CISA KEV: CVE-2025-42009<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113\">CISA KEV: CVE-2025-49113<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerability-impacting-roundcube-webmail-cve-2025-49113","alert_type":397,"serial_number":"AL25-007","subject":"other","moderation_state":"published","external_url":null},{"nid":6438,"title":"Mitel security advisory (AV25-337)","uuid":"ad5d553a-1bbe-4cde-8344-ec33b01d6573","banner":null,"lang":"en","date_modified":"2025-06-11","date_modified_ts":"2025-06-11T15:21:00Z","date_created":"2025-06-11T15:15:51Z","summary":null,"body":["<article data-history-node-id=\"6438\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av25-337\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-337<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 11, 2025<\/p>\n\n<p>On June 11, 2025, Mitel published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>MiCollab\u00a0\u2013 version 9.8 SP2 (9.8.2.12) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/mitel-product-security-advisory-misa-2025-0007\">Mitel Security Advisory\u00a0- MISA-2025-0007<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av25-337","alert_type":396,"serial_number":"AV25-337","subject":"mitel","moderation_state":"published","external_url":null},{"nid":6439,"title":"Palo Alto Networks security advisory (AV25-338)","uuid":"126314fb-81de-4dab-99ad-b52e9e3a05cf","banner":null,"lang":"en","date_modified":"2025-06-11","date_modified_ts":"2025-06-11T19:29:13Z","date_created":"2025-06-11T19:14:31Z","summary":null,"body":["<article data-history-node-id=\"6439\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-338\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-338<br \/><strong>Date: <\/strong>June 11, 2025<\/p>\n\n<p>On June 11, 2025, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>GlobalProtect App 6.3 macOS\u00a0\u2013 versions prior to 6.3.3<\/li>\n\t<li>GlobalProtect App 6.2 macOS\u00a0\u2013 versions prior to 6.2.8-h2<\/li>\n\t<li>GlobalProtect App 6.1 macOS\u00a0\u2013 all versions<\/li>\n\t<li>GlobalProtect App 6.0 macOS\u00a0\u2013 all versions<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.6<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.10<\/li>\n\t<li>PAN-OS 11.0\u00a0\u2013 versions prior to 11.0.3<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.14<\/li>\n\t<li>PAN-OS 10.1\u00a0\u2013 all versions<\/li>\n\t<li>Prisma Access Browser\u00a0\u2013 versions prior to 136.24.1.93<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-4232\">Palo Alto Networks Security Advisories\u00a0- CVE-2025-4232 GlobalProtect: Authenticated Code Injection Through Wildcard on macOS<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-4231\">Palo Alto Networks Security Advisories\u00a0- CVE-2025-4231 PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-4230\">Palo Alto Networks Security Advisories\u00a0- CVE-2025-4230 PAN-OS: Authenticated Admin Command Injection Vulnerability Through CLI<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0011\">Palo Alto Networks Security Advisories\u00a0- PAN-SA-2025-0011<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-338","alert_type":396,"serial_number":"AV25-338","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6440,"title":"Apache ActiveMQ security advisory (AV25-340)","uuid":"cb932c38-1621-4ec3-81fb-c015ac3c3a2c","banner":null,"lang":"en","date_modified":"2025-06-11","date_modified_ts":"2025-06-11T19:58:14Z","date_created":"2025-06-11T19:30:09Z","summary":null,"body":["<article data-history-node-id=\"6440\" about=\"\/en\/alerts-advisories\/apache-activemq-security-advisory-av25-340\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-340<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 11, 2025<\/p>\n\n<p>On April 18, 2025, Apache published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Apache ActiveMQ NMS OpenWire Client\u00a0\u2013 versions prior to 2.1.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/vc1sj9y3056d3kkhcvrs9fyw5w8kpmlx\">CVE-2025-29953: Apache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-activemq-security-advisory-av25-340","alert_type":396,"serial_number":"AV25-340","subject":"other","moderation_state":"published","external_url":null},{"nid":6441,"title":"Apache CloudStack security advisory (AV25-339)","uuid":"7d9ef695-70d4-4bbc-b24a-4da7cbd41abb","banner":null,"lang":"en","date_modified":"2025-06-11","date_modified_ts":"2025-06-11T19:54:05Z","date_created":"2025-06-11T19:48:41Z","summary":null,"body":["<article data-history-node-id=\"6441\" about=\"\/en\/alerts-advisories\/apache-cloudstack-security-advisory-av25-339\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-339<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 11, 2025<\/p>\n\n<p>On June 10, 2025, Apache published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Apache CloudStack\u00a0\u2013 versions 4.0.0 to 4.20.0.0 and versions 4.0.0 to 4.19.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cloudstack.apache.org\/blog\/cve-advisories-4.19.3.0-4.20.1.0\/\">Security Improvements in Apache CloudStack 4.19.3.0 and 4.20.1.0<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-cloudstack-security-advisory-av25-339","alert_type":396,"serial_number":"AV25-339","subject":"other","moderation_state":"published","external_url":null},{"nid":6442,"title":"[Control systems] Siemens security advisory (AV25-341)","uuid":"835928a2-1151-4b5e-a53d-dcc85b5c28f6","banner":null,"lang":"en","date_modified":"2025-06-12","date_modified_ts":"2025-06-12T14:37:52Z","date_created":"2025-06-12T14:20:09Z","summary":null,"body":["<article data-history-node-id=\"6442\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-341\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-341<br \/><strong>Date: <\/strong>June 12, 2025<\/p>\n\n<p>On June 12, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Mendix Studio Pro 8\u00a0\u2013 versions prior to V8.18.35<\/li>\n\t<li>Mendix Studio Pro 9\u00a0\u2013 versions prior to V9.24.35<\/li>\n\t<li>Mendix Studio Pro 10\u00a0\u2013 versions prior to V10.23.0<\/li>\n\t<li>Mendix Studio Pro 10.6\u00a0\u2013 versions prior to V10.6.24<\/li>\n\t<li>Mendix Studio Pro 10.12\u00a0\u2013 versions prior to V10.12.17<\/li>\n\t<li>Mendix Studio Pro 10.18\u00a0\u2013 versions prior to V10.18.7<\/li>\n\t<li>Mendix Studio Pro 11\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-627195.html\">SSA-627195: Zip Path Traversal Vulnerability in Mendix Studio Pro's Module Installation Process<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-341","alert_type":398,"serial_number":"AV25-341","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6443,"title":"GitLab security advisory (AV25-342)","uuid":"99144edc-807d-45fd-8529-5b8dc00f5792","banner":null,"lang":"en","date_modified":"2025-06-12","date_modified_ts":"2025-06-12T14:55:12Z","date_created":"2025-06-12T14:48:38Z","summary":null,"body":["<article data-history-node-id=\"6443\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-342\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-342<br \/><strong>Date: <\/strong>June 12, 2025<\/p>\n\n<p>On June 11, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.0.2, 17.11.4, and 17.10.8<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.0.2, 17.11.4, and 17.10.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/06\/11\/patch-release-gitlab-18-0-2-released\/\">GitLab Patch Release: 18.0.2, 17.11.4, 17.10.8<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-342","alert_type":396,"serial_number":"AV25-342","subject":"other","moderation_state":"published","external_url":null},{"nid":6444,"title":"Trend Micro security advisory (AV25-343)","uuid":"f62055db-57fb-4bd6-89d7-57835bda9ae8","banner":null,"lang":"en","date_modified":"2025-06-13","date_modified_ts":"2025-06-13T19:39:04Z","date_created":"2025-06-13T19:18:05Z","summary":null,"body":["<article data-history-node-id=\"6444\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory-av25-343\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-343<br \/><strong>Date: <\/strong>June 13, 2025<\/p>\n\n<p>On June 9 and 10, 2025, Trend Micro published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apex Central\u00a0\u2013 version 2019 (On-prem)<\/li>\n\t<li>Apex Central as a Service<\/li>\n\t<li>Apex One\u00a0\u2013 version 2019 (On-prem)<\/li>\n\t<li>Apex One as a Service<\/li>\n\t<li>Trend Micro Endpoint Encryption (TMEE) PolicyServer\u00a0\u2013 versions prior to 6.0.0.4013<\/li>\n\t<li>Trend Micro Internet Security\u00a0\u2013 version 17.8<\/li>\n\t<li>Trend Micro Maximum Security\u00a0\u2013 version 17.8<\/li>\n\t<li>Worry-Free Business Security (WFBS)\u00a0\u2013 version 10.0 SP1<\/li>\n\t<li>Worry-Free Business Security Services (WFBSS)\u00a0\u2013 version 6.7 (SaaS)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpcenter.trendmicro.com\/en-us\/vulnerability\/?utm_source=producthelp\">Trend Micro Help Center Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/success.trendmicro.com\/en-US\/vulnerability-response\/\">Trend Micro Business Success Vulnerability Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory-av25-343","alert_type":396,"serial_number":"AV25-343","subject":"other","moderation_state":"published","external_url":null},{"nid":6445,"title":"Red Hat security advisory (AV25-344)","uuid":"f78f01ca-51de-40a4-a6d9-b3d65ebdb08f","banner":null,"lang":"en","date_modified":"2025-06-16","date_modified_ts":"2025-06-16T16:11:56Z","date_created":"2025-06-16T16:05:11Z","summary":null,"body":["<article data-history-node-id=\"6445\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-344\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-344<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 16, 2025<\/p>\n\n<p>Between June 9 and 15, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-344","alert_type":396,"serial_number":"AV25-344","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6446,"title":"Ubuntu security advisory (AV25-345)","uuid":"ca1eb9e3-c235-4ed0-a84a-771ea112ff56","banner":null,"lang":"en","date_modified":"2025-06-16","date_modified_ts":"2025-06-16T16:23:50Z","date_created":"2025-06-16T16:19:34Z","summary":null,"body":["<article data-history-node-id=\"6446\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-345\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-345<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 16, 2025<\/p>\n\n<p>Between June 9 and 15, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-345","alert_type":396,"serial_number":"AV25-345","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6447,"title":"IBM security advisory (AV25-346)","uuid":"3cb60608-b97b-4ca5-a11e-e4ce60a10537","banner":null,"lang":"en","date_modified":"2025-06-16","date_modified_ts":"2025-06-16T16:38:56Z","date_created":"2025-06-16T16:30:54Z","summary":null,"body":["<article data-history-node-id=\"6447\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-346\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-346<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 16, 2025<\/p>\n\n<p>Between June 9 and 15, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following product:<\/p>\n\n<ul><li>API Connect\u00a0\u2013 version V10.0.5.0 to V10.0.5.9<\/li>\n\t<li>API Connect\u00a0\u2013 version V10.0.8.0 to V10.0.8.2-iFix1<\/li>\n\t<li>IBM DataPower Gateway 10.6CD\u00a0\u2013 versions 10.6.1.0 to 10.6.3.0<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM MQ Operator\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Robotic Process Automation\u00a0\u2013 version 21.0.0 to 21.0.7.20 and version 23.0.0 to 23.0.20.1<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak\u00a0\u2013 version 21.0.0 to 21.0.7.20 and version 23.0.0 to 23.0.20.1<\/li>\n\t<li>IBM Security QRadar EDR\u00a0\u2013 version 3.12<\/li>\n\t<li>IBM supplied MQ Advanced container images\u00a0\u2013 multiple versions<\/li>\n\t<li>PowerVC\u00a0\u2013 version 2.2.0, 2.2.1, 2.2.1.1, 2.2.1.2 and 2.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-346","alert_type":396,"serial_number":"AV25-346","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6448,"title":"Dell security advisory (AV25-347)","uuid":"02346784-19c8-4c0b-8a0a-3e9e1ed2a82e","banner":null,"lang":"en","date_modified":"2025-06-16","date_modified_ts":"2025-06-16T16:47:40Z","date_created":"2025-06-16T16:42:44Z","summary":null,"body":["<article data-history-node-id=\"6448\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-347\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-347<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 16, 2025<\/p>\n\n<p>Between June 9 and 15, 2025, Dell published security advisories to address a vulnerability in the following product:<\/p>\n\n<ul><li>Dell iDRAC Tools\u00a0\u2013 versions prior to 11.3.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000323242\/dsa-2025-169-security-update-for-dell-idrac-tools-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-169<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-347","alert_type":396,"serial_number":"AV25-347","subject":"dell","moderation_state":"published","external_url":null},{"nid":6449,"title":"[Control systems] CISA ICS security advisories (AV25\u2013348)","uuid":"15e8a8ca-ce8d-4722-8aae-c72c1e9b5606","banner":null,"lang":"en","date_modified":"2025-06-16","date_modified_ts":"2025-06-16T20:11:44Z","date_created":"2025-06-16T20:05:10Z","summary":null,"body":["<article data-history-node-id=\"6449\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-348\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-348<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 16, 2025<\/p>\n\n<p>Between June 9 and 15, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA PI Connector for CygNet\u00a0\u2013 version 1.6.14 and prior<\/li>\n\t<li>AVEVA PI Data Archive\u00a0\u2013 multiple versions<\/li>\n\t<li>AVEVA PI Server\u00a0\u2013 multiple versions<\/li>\n\t<li>AVEVA PI Web API\u00a0\u2013 versions 2023 SP1 and prior<\/li>\n\t<li>Hitachi Energy Relion 670\u00a0\u2013 version 2.2.0<\/li>\n\t<li>Hitachi Relion 650\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Relion 670\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi SAM600-IO\u00a0\u2013 multiple versions<\/li>\n\t<li>multiCAM Systems Pan-Tilt-Zoom Cameras\u00a0\u2013 all versions<\/li>\n\t<li>PTZOptics\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens Energy Services\u00a0\u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM APE1808\u00a0\u2013 all versions (with Palo Alto Networks Virtual NGFW with an enabled GlobalProtect gateway or portal)<\/li>\n\t<li>Siemens RUGGEDCOM RST2428P (6GK6242-6PA00)\u00a0\u2013 versions prior to V3.1<\/li>\n\t<li>Siemens SCALANCE\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SIMATIC\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens Tecnomatix Plant Simulation V2404\u00a0\u2013 versions prior to V2404.0013<\/li>\n\t<li>SinoTrack IOT PC Platform\u00a0\u2013 all versions<\/li>\n\t<li>SMTAV Pan-Tilt-Zoom Cameras\u00a0\u2013 all versions<\/li>\n\t<li>ValueHD Pan-Tilt-Zoom Cameras\u00a0\u2013 all version<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-348","alert_type":398,"serial_number":"AV25-348","subject":"ics","moderation_state":"published","external_url":null},{"nid":6450,"title":"Grafana security advisory (AV25-349)","uuid":"072feab2-7fcb-4083-acd8-4100d23aa922","banner":null,"lang":"en","date_modified":"2025-06-16","date_modified_ts":"2025-06-16T20:18:47Z","date_created":"2025-06-16T20:14:16Z","summary":null,"body":["<article data-history-node-id=\"6450\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av25-349\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-349<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 16, 2025<\/p>\n\n<p>On May 21, 2025, Grafana published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Grafana\u00a0\u2013 versions prior to 11.2, 11.3, 11.4, 11.5, 11.6 and 12.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/blog\/2025\/05\/21\/grafana-security-release-high-severity-security-fix-for-cve-2025-4123\/\">Grafana Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av25-349","alert_type":396,"serial_number":"AV25-349","subject":"other","moderation_state":"published","external_url":null},{"nid":6451,"title":"Citrix security advisory (AV25-350)","uuid":"1b3af38a-fae3-410c-84de-48be51853aa4","banner":null,"lang":"en","date_modified":"2025-06-17","date_modified_ts":"2025-06-17T15:40:32Z","date_created":"2025-06-17T15:09:51Z","summary":null,"body":["<article data-history-node-id=\"6451\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-350\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-350<br \/><strong>Date: <\/strong>June 17, 2025<\/p>\n\n<p>On June 17, 2025, Citrix published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Secure Access Client for Windows\u00a0\u2013 versions prior to 25.5.1.15<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 14.1\u00a0\u2013 versions prior to 14.1-43.56<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.1\u00a0\u2013 versions prior to 13.1-58.32<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and NDcPP\u00a0\u2013 versions prior to 13.1-37.235-FIPS and NDcPP<\/li>\n\t<li>NetScaler ADC 12.1-FIPS\u00a0\u2013 versions prior to 12.1-55.328-FIPS<\/li>\n\t<li>NetScaler Console 14.1\u00a0\u2013 versions prior to 14.1.47.46<\/li>\n\t<li>NetScaler Console 13.1\u00a0\u2013 versions prior to 13.1.58.32<\/li>\n\t<li>NetScaler SDX (SVM) 14.1\u00a0\u2013 versions prior to 14.1.47.46<\/li>\n\t<li>NetScaler SDX (SVM) 13.1\u00a0\u2013 versions prior to 13.1.58.32<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694724&amp;articleURL=Citrix_Secure_Access_Client_for_Windows_Security_Bulletin_for_CVE_2025_0320\">Citrix Security Advisory\u00a0\u2013 CTX694724<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX693420&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_5349_and_CVE_2025_5777\">Citrix Security Advisory\u00a0\u2013 CTX693420<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694729&amp;articleURL=NetScaler_Console_and_NetScaler_SDX_SVM_Security_Bulletin_for_CVE_2025_4365\">Citrix Security Advisory\u00a0\u2013 CTX694729<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-350","alert_type":396,"serial_number":"AV25-350","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6452,"title":"BeyondTrust security advisory (AV25-351)","uuid":"30ab3a60-fc7f-4d2d-b5e8-4aa164142f21","banner":null,"lang":"en","date_modified":"2025-06-17","date_modified_ts":"2025-06-17T17:37:05Z","date_created":"2025-06-17T17:30:56Z","summary":null,"body":["<article data-history-node-id=\"6452\" about=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av25-351\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-351<br \/><strong>Date: <\/strong>June 17, 2025<\/p>\n\n<p>On June 16, 2025, BeyondTrust published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Remote Support\u00a0\u2013 version 24.2.2 to 24.2.4, 24.3.1 to 24.3.3, and 25.1.1<\/li>\n\t<li>Privileged Remote Access\u00a0\u2013 version 24.2.2 to 24.2.4, 24.3.1 to 24.3.3, and 25.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt25-04\">BeyondTrust Security Advisory\u00a0- Advisory ID: BT25-04<\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\">BeyondTrust Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/beyondtrust-security-advisory-av25-351","alert_type":396,"serial_number":"AV25-351","subject":"other","moderation_state":"published","external_url":null},{"nid":6453,"title":"Veeam security advisory (AV25-352)","uuid":"bb728832-e866-4b62-972a-b1bcdee940cf","banner":null,"lang":"en","date_modified":"2025-06-17","date_modified_ts":"2025-06-17T17:52:51Z","date_created":"2025-06-17T17:46:02Z","summary":null,"body":["<article data-history-node-id=\"6453\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av25-352\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-352<br \/><strong>Date: <\/strong>June 17, 2025<\/p>\n\n<p>On June 17, 2025, Veeam published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2013 version 12.3.1.1139 and prior<\/li>\n\t<li>Veeam Agent for Microsoft Windows\u00a0\u2013 version 6.3.1.1074 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4743\">Veeam Security Advisory\u00a0\u2013 KB4743<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av25-352","alert_type":396,"serial_number":"AV25-352","subject":"other","moderation_state":"published","external_url":null},{"nid":6454,"title":"Google Chrome security advisory (AV25-353)","uuid":"73f8204e-42bd-4a50-b7fe-f5c708776973","banner":null,"lang":"en","date_modified":"2025-06-17","date_modified_ts":"2025-06-17T18:52:03Z","date_created":"2025-06-17T18:48:44Z","summary":null,"body":["<article data-history-node-id=\"6454\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-353\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-353<br \/><strong>Date: <\/strong>June 17, 2025<\/p>\n\n<p>On June 17, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 137.0.7151.119\/.120 (Windows\/Mac), and 137.0.7151.119 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/06\/stable-channel-update-for-desktop_17.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-353","alert_type":396,"serial_number":"AV25-353","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6455,"title":"Apache Tomcat security advisory (AV25-354)","uuid":"8914bc50-d4dd-4470-ad01-b75e63c2d365","banner":null,"lang":"en","date_modified":"2025-06-18","date_modified_ts":"2025-06-18T11:55:48Z","date_created":"2025-06-18T11:49:37Z","summary":null,"body":["<article data-history-node-id=\"6455\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-advisory-av25-354\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-354<br \/><strong>Date: <\/strong>June\u00a018, 2025<\/p>\n\n<p>On June\u00a016, 2025, Apache published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Apache Tomcat\u00a0\u2013 versions 11.0.0-M1 to 11.0.7<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 10.1.0-M1 to 10.1.41<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 9.0.0.M1 to 9.0.105<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/nzkqsok8t42qofgqfmck536mtyzygp18\">Apache Security Advisory\u00a0- [SECURITY] CVE-2025-48988 Apache Tomcat\u00a0- DoS in multipart upload<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-advisory-av25-354","alert_type":396,"serial_number":"AV25-354","subject":"other","moderation_state":"published","external_url":null},{"nid":6457,"title":"Atlassian security advisory (AV25-355)","uuid":"ac84190d-8c09-4c21-850f-0b2fbf9ce528","banner":null,"lang":"en","date_modified":"2025-06-18","date_modified_ts":"2025-06-18T14:53:44Z","date_created":"2025-06-18T14:45:04Z","summary":null,"body":["<article data-history-node-id=\"6457\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-355\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-355<br \/><strong>Date: <\/strong>June 18, 2025<\/p>\n\n<p>On June 17, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-june-17-2025-1574012717.html\">Security Bulletin\u00a0- June 17 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-355","alert_type":396,"serial_number":"AV25-355","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6458,"title":"Cisco security advisory (AV25-356)","uuid":"bb106ed8-d5e4-462d-951d-03bb316dca39","banner":null,"lang":"en","date_modified":"2025-06-18","date_modified_ts":"2025-06-18T18:16:24Z","date_created":"2025-06-18T18:12:29Z","summary":null,"body":["<article data-history-node-id=\"6458\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-356\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-356<br \/><strong>Date: <\/strong>June 18, 2025<\/p>\n\n<p>On June 18, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway\u00a0\u2013 multiple models<\/li>\n\t<li>Secure Endpoint Connector for Linux\u00a0\u2013 versions prior to 1.26.1<\/li>\n\t<li>Secure Endpoint Connector for Mac\u00a0\u2013 versions prior to 1.26.1<\/li>\n\t<li>Secure Endpoint Connector for Windows\u00a0\u2013 versions prior to 7.5.21 and 8.4.5<\/li>\n\t<li>Secure Endpoint Private Cloud\u00a0\u2013 versions prior to 4.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-clamav-udf-hmwd9nDy\">ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-meraki-mx-vpn-dos-sM5GCfm7\">Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-356","alert_type":396,"serial_number":"AV25-356","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6459,"title":"VMware security advisory (AV25-357)","uuid":"2f271a85-3466-43a4-a98a-683d6a001f95","banner":null,"lang":"en","date_modified":"2025-06-19","date_modified_ts":"2025-06-19T14:53:55Z","date_created":"2025-06-19T14:27:29Z","summary":null,"body":["<article data-history-node-id=\"6459\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-357\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-357<br \/><strong>Date: <\/strong>June\u00a019, 2025<\/p>\n\n<p>On June 18, 2025, VMware released security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu Data Lake\u00a0\u2013 versions prior to 1.1.0<\/li>\n\t<li>VMware Tanzu for Postgres on Kubernetes\u00a0\u2013 versions prior to 4.1.0<\/li>\n\t<li>VMware Tanzu for Postgres on Kubernetes\u00a0\u2013 versions prior to 4.2.0<\/li>\n\t<li>VMware Tanzu for Valkey on Kubernetes\u00a0\u2013 versions prior to 1.1.0<\/li>\n\t<li>VMware Tanzu for Valkey on Kubernetes\u00a0\u2013 versions prior to 2.0.0<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 6.29.1<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 7.5.0<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to Backup and Restore 1.31.1<\/li>\n\t<li>VMware Tanzu Greenplum Command Center\u00a0\u2013 versions prior to 6.14.0<\/li>\n\t<li>VMware Tanzu Greenplum Command Center\u00a0\u2013 versions prior to 7.4.0<\/li>\n\t<li>VMware Tanzu Greenplum Data Copy Utility\u00a0\u2013 versions prior to 2.8.0<\/li>\n\t<li>VMware Tanzu Greenplum Streaming Server\u00a0\u2013 versions prior to 2.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-357","alert_type":396,"serial_number":"AV25-357","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6462,"title":"Microsoft Edge security advisory (AV25-358)","uuid":"f0310144-17e5-4d5d-8ca1-cc6dd1baa6ce","banner":null,"lang":"en","date_modified":"2025-06-20","date_modified_ts":"2025-06-20T20:54:45Z","date_created":"2025-06-20T20:48:17Z","summary":null,"body":["<article data-history-node-id=\"6462\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-358\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-358<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong> June 20, 2025<\/p>\n\n<p>On June 20, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 137.0.3296.93<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-20-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-358","alert_type":396,"serial_number":"AV25-358","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6463,"title":"Dell security advisory (AV25-359)","uuid":"f360e6dd-66ab-4f5a-a788-85ceee9e8ded","banner":null,"lang":"en","date_modified":"2025-06-23","date_modified_ts":"2025-06-23T16:27:50Z","date_created":"2025-06-23T16:22:44Z","summary":null,"body":["<article data-history-node-id=\"6463\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-359\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-359<br \/><strong>Date: <\/strong>June\u00a023, 2025<\/p>\n\n<p>Between June\u00a016 and 22, 2025, Dell published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Dell Connectrix B-Series\u00a0\u2013 versions 9.0.0 to 9.2.2<\/li>\n\t<li>Dell Connectrix B-Series\u00a0\u2013 versions prior to 2.4.0<\/li>\n\t<li>Dell Connectrix B-Series\u00a0\u2013 versions prior to 9.2.2<\/li>\n\t<li>Dell Container Storage Modules\u00a0\u2013 versions prior to 1.14<\/li>\n\t<li>Dell EMC XC Core XC7525\u00a0\u2013 versions prior to 2.14.1<\/li>\n\t<li>Dell Policy Manager for Secure Connect Gateway\u00a0\u2013 versions prior to 5.28.00.14<\/li>\n\t<li>Dell PowerEdge C6525\u00a0\u2013 versions prior to 2.14.1<\/li>\n\t<li>Dell PowerEdge R6515\u00a0\u2013 versions prior to 2.14.1<\/li>\n\t<li>Dell PowerEdge R6525\u00a0\u2013 versions prior to 2.14.1<\/li>\n\t<li>Dell PowerEdge R7515\u00a0\u2013 versions prior to 2.14.1<\/li>\n\t<li>Dell PowerEdge R7525\u00a0\u2013 versions prior to 2.14.1<\/li>\n\t<li>Dell PowerEdge XE8545\u00a0\u2013 versions prior to 2.14.1<\/li>\n\t<li>Dell PowerFlex Custom Node\u00a0\u2013 versions prior to 1.11.2<\/li>\n\t<li>Dell PowerFlex Custom Node\u00a0\u2013 versions prior to 1.16.2<\/li>\n\t<li>Dell PowerFlex Custom Node\u00a0\u2013 versions prior to 2.18.1<\/li>\n\t<li>Dell PowerFlex Custom Node\u00a0\u2013 versions prior to 2.5.4<\/li>\n\t<li>Dell VxFlex Ready Node\u00a0\u2013 versions prior to 2.23.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-359","alert_type":396,"serial_number":"AV25-359","subject":"dell","moderation_state":"published","external_url":null},{"nid":6464,"title":"IBM security advisory (AV25-360)","uuid":"32f1dcd5-2528-466c-8650-4c71b6552d1e","banner":null,"lang":"en","date_modified":"2025-06-23","date_modified_ts":"2025-06-23T16:47:51Z","date_created":"2025-06-23T16:42:21Z","summary":null,"body":["<article data-history-node-id=\"6464\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-360\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-360<br \/><strong>Date: <\/strong>June\u00a023, 2025<\/p>\n\n<p>Between June\u00a016 and 22, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>IBM Cloud Pak for Data\u00a0\u2013 versions 3.5 and 4.5<\/li>\n\t<li>IBM Cloud Pak for Data\u00a0\u2013 versions 4.8.0 to 4.8.9, 5.0.0 to 5.0.3 and 5.1.0 to 5.1.3<\/li>\n\t<li>IBM Cloudera Data Platform Private Cloud Base with IBM (CDP)\u00a0\u2013 versions 7.1.7 SP3 and 7.1.9 SP1<\/li>\n\t<li>IBM Cloudera Data Platform Private Cloud Data Services with IBM\u00a0\u2013 versions 1.5.3 and 1.5.4<\/li>\n\t<li>IBM Cloudera Data Platform Streaming with IBM\u00a0\u2013 versions 7.1.7 SP3 and 7.1.9 SP1<\/li>\n\t<li>IBM Cloudera Data Platform Streams Messaging Base with IBM Version\u00a0\u2013 versions 7.1.7 SP3 and 7.1.9 SP1<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data\u00a0\u2013 versions 3.1.0 to 3.1.2<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data\u00a0\u2013 versions 1.7.0 to 1.7.8<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data\u00a0\u2013 versions 1.8.0 to 1.8.3<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data\u00a0\u2013 versions 3.0.0 to 3.0.3<\/li>\n\t<li>IBM Edge Data Collector\u00a0\u2013 version 9.0.9<\/li>\n\t<li>IBM Event Processing\u00a0\u2013 versions 1.0.0 to 1.3.2<\/li>\n\t<li>IBM Fusion HCI for watsonx\u00a0\u2013 versions 2.8.2 to 2.9.0<\/li>\n\t<li>IBM Fusion HCI\u00a0\u2013 versions 2.2.0 to 2.9.0<\/li>\n\t<li>IBM Fusion\u00a0\u2013 versions 2.2.0 to 2.9.1<\/li>\n\t<li>IBM QRadar SIEM\u00a0\u2013 versions 7.5 to 7.5.0 UP12 IF01<\/li>\n\t<li>IBM Storage Fusion Data Foundation\u00a0\u2013 version 4.18.4<\/li>\n\t<li>IBM Watson Query on Cloud Pak for Data\u00a0\u2013 versions 2.0.0 to 2.0.4<\/li>\n\t<li>IBM Watson Query on Cloud Pak for Data\u00a0\u2013 versions 2.1.0 to 2.1.3<\/li>\n\t<li>IBM Watson Query on Cloud Pak for Data\u00a0\u2013 versions 2.2.0 to 2.2.8<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0\u2013 versions 4.0.0 to 5.1.3<\/li>\n\t<li>IBM watsonx Code Assistant On Prem\u00a0\u2013 versions 5.0 to 5.1.2<\/li>\n\t<li>IBM watsonx.data\u00a0\u2013 version 2.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-360","alert_type":396,"serial_number":"AV25-360","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6465,"title":"Ubuntu security advisory (AV25-361)","uuid":"af7b427d-322b-4cec-990c-7afe66e75638","banner":null,"lang":"en","date_modified":"2025-06-23","date_modified_ts":"2025-06-23T17:01:57Z","date_created":"2025-06-23T16:59:25Z","summary":null,"body":["<article data-history-node-id=\"6465\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-361\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-361<br \/><strong>Date: <\/strong>June\u00a023, 2025<\/p>\n\n<p>Between June\u00a016 and 22, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7585-1\">Ubuntu Security Notices\u00a0- USN-7585-1<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7585-2\">Ubuntu Security Notices\u00a0- USN-7585-2<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-361","alert_type":396,"serial_number":"AV25-361","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6466,"title":"Fortinet security advisory (AV25-362)","uuid":"5e3ae41b-cb10-440a-8f24-92827fa60b32","banner":null,"lang":"en","date_modified":"2025-06-23","date_modified_ts":"2025-06-23T17:34:44Z","date_created":"2025-06-23T17:30:18Z","summary":null,"body":["<article data-history-node-id=\"6466\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-362\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-362<br \/><strong>Date: <\/strong>June 23, 2025<\/p>\n\n<p>On June 23, 2025, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.3<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.7<\/li>\n\t<li>FortiOS 7.0\u00a0\u2013 versions 7.0.0 to 7.0.14<\/li>\n\t<li>FortiOS 6.4\u00a0\u2013 all versions<\/li>\n\t<li>FortiOS 6.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiOS 6.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiPAM 1.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiPAM 1.1\u00a0\u2013 all versions<\/li>\n\t<li>FortiPAM 1.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiProxy 7.4\u00a0\u2013 versions 7.4.0 to 7.4.3<\/li>\n\t<li>FortiProxy 7.2\u00a0\u2013 versions 7.2.0 to 7.2.9<\/li>\n\t<li>FortiProxy 7.0\u00a0\u2013 versions 7.0.0 to 7.0.16<\/li>\n\t<li>FortiProxy 2.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiProxy 1.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiProxy 1.1\u00a0\u2013 all versions<\/li>\n\t<li>FortiProxy 1.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiSwitchManager 7.2\u00a0\u2013 versions 7.2.0 to 7.2.3<\/li>\n\t<li>FortiSwitchManager 7.0\u00a0\u2013 versions 7.0.1 to 7.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-036\">Fortinet PSIRT\u00a0- FG-IR-24-036<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-362","alert_type":396,"serial_number":"AV25-362","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6467,"title":"[Control systems] CISA ICS security advisories (AV25\u2013363)","uuid":"5237f32f-5923-4dd6-806c-91c1ecea11de","banner":null,"lang":"en","date_modified":"2025-06-23","date_modified_ts":"2025-06-23T17:46:53Z","date_created":"2025-06-23T17:43:46Z","summary":null,"body":["<article data-history-node-id=\"6467\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-363\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-363<br \/><strong>Date: <\/strong>June\u00a023, 2025<\/p>\n\n<p>Between June\u00a016 and 22, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dover Fueling Solutions ProGauge MagLink LX 4\u00a0\u2013 versions prior to 4.20.3<\/li>\n\t<li>Dover Fueling Solutions ProGauge MagLink LX Plus\u00a0\u2013 versions prior to 4.20.3<\/li>\n\t<li>Dover Fueling Solutions ProGauge MagLink LX Ultimate\u00a0\u2013 versions prior to 5.20.3<\/li>\n\t<li>Fuji Electric Smart Editor\u00a0\u2013 version 1.0.1.0 and prior<\/li>\n\t<li>LS Electric GMWin 4\u00a0\u2013 version 4.18<\/li>\n\t<li>Siemens Mendix Studio Pro\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-363","alert_type":398,"serial_number":"AV25-363","subject":"ics","moderation_state":"published","external_url":null},{"nid":6468,"title":"Mattermost security advisory (AV25-364)","uuid":"03943576-9f15-4356-97c1-fa12c74d88a8","banner":null,"lang":"en","date_modified":"2025-06-23","date_modified_ts":"2025-06-23T17:59:29Z","date_created":"2025-06-23T17:53:41Z","summary":null,"body":["<article data-history-node-id=\"6468\" about=\"\/en\/alerts-advisories\/mattermost-security-advisory-av25-364\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-364<br \/><strong>Date: <\/strong>June\u00a023, 2025<\/p>\n\n<p>On May\u00a021, 2025, Mattermost published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Mattermost Server\u00a0(9.11.x)\u00a0\u2013 versions 9.11.15 and prior<\/li>\n\t<li>Mattermost Server\u00a0(10.5.x)\u00a0\u2013 versions 10.5.5 and prior<\/li>\n\t<li>Mattermost Server\u00a0(10.6.x)\u00a0\u2013 versions 10.6.5 and prior<\/li>\n\t<li>Mattermost Server\u00a0(10.7.x)\u00a0\u2013 versions 10.7.2 and prior<\/li>\n\t<li>Mattermost Server\u00a0(10.8.x)\u00a0\u2013 versions 10.8.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-4981\">CVE-2025-4981 Detail<\/a><\/li>\n\t<li><a href=\"https:\/\/mattermost.com\/security-updates\/\">Mattermost Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mattermost-security-advisory-av25-364","alert_type":396,"serial_number":"AV25-364","subject":"other","moderation_state":"published","external_url":null},{"nid":6469,"title":"HPE security advisory (AV25-365)","uuid":"b8a94eff-55ce-4d92-b16c-4f37d8c27a50","banner":null,"lang":"en","date_modified":"2025-06-23","date_modified_ts":"2025-06-23T20:04:10Z","date_created":"2025-06-23T20:00:23Z","summary":null,"body":["<article data-history-node-id=\"6469\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-365\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-365<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 23, 2025<\/p>\n\n<p>On June 23, 2025, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Telco Unified OSS Console \u2013 version prior to v3.1.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04885en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbnw04885en_us<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-365","alert_type":396,"serial_number":"AV25-365","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6470,"title":"HPE security advisory (AV25-366)","uuid":"d5120759-bbe2-4f97-a767-c279316e739d","banner":null,"lang":"en","date_modified":"2025-06-24","date_modified_ts":"2025-06-24T12:29:03Z","date_created":"2025-06-24T12:26:04Z","summary":null,"body":["<article data-history-node-id=\"6470\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-366\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-366<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 24, 2025<\/p>\n\n<p>On June 24, 2025, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE OneView for VMware vCenter with Operations Manager and Log Insight\u00a0\u2013 versions prior to v11.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04876en_us&amp;docLocale=en_US\">HPE Security Bulletin - hpesbgn04876en_us <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-366","alert_type":396,"serial_number":"AV25-366","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6472,"title":"Mozilla security advisory (AV25-367)","uuid":"07ff1b01-b413-4351-b173-8a5ce2f86afa","banner":null,"lang":"en","date_modified":"2025-06-24","date_modified_ts":"2025-06-24T14:46:34Z","date_created":"2025-06-24T14:42:56Z","summary":null,"body":["<article data-history-node-id=\"6472\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-367\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-367<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 24, 2025<\/p>\n\n<p>On June 24, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR \u2013 versions prior to 128.12<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.25<\/li>\n\t<li>Firefox \u2013 versions prior to 140<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-53\/\">Mozilla Foundation Security Advisory MFSA 2025-53 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-52\/\">Mozilla Foundation Security Advisory MFSA 2025-52 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-51\/\">Mozilla Foundation Security Advisory MFSA 2025-51<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-367","alert_type":396,"serial_number":"AV25-367","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6474,"title":"GitHub security advisory (AV25-368)","uuid":"d69acc23-c07f-42a5-901a-82e634920246","banner":null,"lang":"en","date_modified":"2025-06-24","date_modified_ts":"2025-06-24T16:20:48Z","date_created":"2025-06-24T16:16:53Z","summary":null,"body":["<article data-history-node-id=\"6474\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-368\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-368<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 24, 2025<\/p>\n\n<p>On June 18, 2025, GitHub published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.1<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.4<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.15.x prior to 3.15.8<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.13<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.13.x prior to 3.13.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">GitHub Release Notes #3.17.1<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">GitHub Release Notes # 3.16.4<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes\">GitHub Release Notes # 3.15.8<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">GitHub Release Notes # 3.14.13<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.13\/admin\/release-notes\">GitHub Release Notes # 3.13.16<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-368","alert_type":396,"serial_number":"AV25-368","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6475,"title":"Google Chrome security advisory (AV25-369)","uuid":"97779f43-b36d-4149-9bcc-43b2162bdd1a","banner":null,"lang":"en","date_modified":"2025-06-25","date_modified_ts":"2025-06-25T12:37:42Z","date_created":"2025-06-25T12:35:00Z","summary":null,"body":["<article data-history-node-id=\"6475\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-369\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-369<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 25, 2025<\/p>\n\n<p>On June 24, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to138.0.7204.49\/50 (Windows\/Mac), and 138.0.7204.49 (Linux)<\/li>\n\t<li>Extended Stable Channel \u2013 versions prior to 138.0.7204.50 (Windows\/Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/06\/stable-channel-update-for-desktop_24.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-369","alert_type":396,"serial_number":"AV25-369","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6476,"title":"GitLab security advisory (AV25-370)","uuid":"949c67a7-4c65-41e9-a4b8-e36dab2a8102","banner":null,"lang":"en","date_modified":"2025-06-25","date_modified_ts":"2025-06-25T12:48:29Z","date_created":"2025-06-25T12:39:47Z","summary":null,"body":["<article data-history-node-id=\"6476\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-370\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-370<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 25, 2025<\/p>\n\n<p>On June 25, 2025, GitLab published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 18.1.1, 18.0.3 and 17.11.5<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 18.1.1, 18.0.3 and 17.11.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/06\/25\/patch-release-gitlab-18-1-1-released\/\">GitLab Patch Release: 18.1.1, 18.0.3, 17.11.5 <\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-370","alert_type":396,"serial_number":"AV25-370","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6477,"title":"Splunk security advisory (AV25-371)","uuid":"da3b01a7-edd0-4266-a89d-b64617a1d56c","banner":null,"lang":"en","date_modified":"2025-06-25","date_modified_ts":"2025-06-25T15:06:23Z","date_created":"2025-06-25T14:42:29Z","summary":null,"body":["<article data-history-node-id=\"6477\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-371\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-371<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 25, 2025<\/p>\n\n<p>On June 23, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>splunk\/splunk \u2013 version 9.4.1<\/li>\n\t<li>splunk\/splunk \u2013 versions 9.3.0 to 9.3.3<\/li>\n\t<li>splunk\/splunk \u2013 versions 9.2.0 to 9.2.5<\/li>\n\t<li>splunk\/splunk \u2013 versions 9.1.0 to 9.1.8<\/li>\n\t<li>splunk\/universalforwarder \u2013 version 9.4.1<\/li>\n\t<li>splunk\/universalforwarder \u2013 versions 9.3.0 to 9.3.3<\/li>\n\t<li>splunk\/universalforwarder \u2013 versions 9.2.0 to 9.2.5<\/li>\n\t<li>splunk\/universalforwarder \u2013 versions 9.1.0 to 9.1.8<\/li>\n\t<li>Splunk Operator for Kubernetes \u2013 versions prior to 2.8.0<\/li>\n\t<li>Splunk AppDynamics Smart Agent \u2013 versions prior to 25.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0607\">Third-Party Package Updates in Splunk Enterprise - June 2025 - SVD-2025-0607 <\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0608\">Third-Party Package Updates in Splunk Enterprise - June 2025 - SVD-2025-0608<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0609 \">Third-Party Package Updates in Splunk Enterprise - June 2025 - SVD-2025-0609 <\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0610 \">Third-Party Package Updates in Splunk Enterprise - June 2025 - SVD-2025-0610 <\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-371","alert_type":396,"serial_number":"AV25-371","subject":"other","moderation_state":"published","external_url":null},{"nid":6479,"title":"TeamViewer security advisory (AV25-372)","uuid":"1201a340-aae5-4de8-b58e-5d52bc3a85eb","banner":null,"lang":"en","date_modified":"2025-06-25","date_modified_ts":"2025-06-25T15:15:30Z","date_created":"2025-06-25T15:09:00Z","summary":null,"body":["<article data-history-node-id=\"6479\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-372\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-372<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 25, 2025<\/p>\n\n<p>On June 24, 2025, TeamViewer released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>TeamViewer Remote Full Client (Windows) \u2013 multiple versions<\/li>\n\t<li>TeamViewer Remote Host (Windows) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/tv-2025-1002\/ \">Improper Neutralization of Argument Delimiters in TeamViewer Clients - TV-2025-1002<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">TeamViewer Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-372","alert_type":396,"serial_number":"AV25-372","subject":"other","moderation_state":"published","external_url":null},{"nid":6480,"title":"Trend Micro security advisory (AV25-373)","uuid":"040addd0-da97-4d5c-b6cd-f670b53bc161","banner":null,"lang":"en","date_modified":"2025-06-25","date_modified_ts":"2025-06-25T15:21:20Z","date_created":"2025-06-25T15:18:07Z","summary":null,"body":["<article data-history-node-id=\"6480\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory-av25-373\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-373<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 25, 2025<\/p>\n\n<p>On June 20, 2025, Trend Micro published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Trend Micro Password Manager \u2013 versions prior to 5.8.0.1327<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpcenter.trendmicro.com\/en-us\/article\/tmka-12946\">Trend Micro Password Manager Link Following Privilege Escalation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/success.trendmicro.com\/en-US\/vulnerability-response\/\">Trend Micro Business Success Vulnerability Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory-av25-373","alert_type":396,"serial_number":"AV25-373","subject":"other","moderation_state":"published","external_url":null},{"nid":6481,"title":"Citrix security advisory (AV25-374)","uuid":"aa742eee-4c16-4900-ada7-4879200f295a","banner":null,"lang":"en","date_modified":"2025-06-25","date_modified_ts":"2025-06-25T16:01:56Z","date_created":"2025-06-25T15:58:59Z","summary":null,"body":["<article data-history-node-id=\"6481\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-374\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-374<br \/><strong>Date: <\/strong>June\u00a025, 2025<\/p>\n\n<p>On June\u00a025, 2025, Citrix published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway 14.1\u00a0\u2013 versions prior to 14.1-47.46<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.1\u00a0\u2013 versions prior to 13.1-59.19<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and NDcPP\u00a0\u2013 versions prior to 13.1-37.236-FIPS and NDcPP<\/li>\n<\/ul><p>Citrix has reported that exploits of CVE-2025-6543 on unmitigated appliances have been observed.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694788&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_6543\">Citrix Security Advisory\u00a0\u2013 CTX694788<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-374","alert_type":396,"serial_number":"AV25-374","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6484,"title":"VMware security advisory (AV25-375)","uuid":"3bee408c-496f-46bc-bf98-0fcef127e808","banner":null,"lang":"en","date_modified":"2025-06-25","date_modified_ts":"2025-06-25T18:05:48Z","date_created":"2025-06-25T18:03:05Z","summary":null,"body":["<article data-history-node-id=\"6484\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-375\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-375<br \/><strong>Date: <\/strong>June\u00a025, 2025<\/p>\n\n<p>On June\u00a024, 2025, VMware published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Tanzu for Valkey\u00a0\u2013 versions 8.0.2, 7.2.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35857\">Security Advisories\u00a0\u2013 TNZ-2025-0038<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-375","alert_type":396,"serial_number":"AV25-375","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6485,"title":"Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2025-5349, CVE-2025-5777 and CVE-2025-6543 \u2013 Update 2","uuid":"686917bd-c410-46a8-abd0-4d1fcbb8633d","banner":null,"lang":"en","date_modified":"2025-07-18","date_modified_ts":"2025-07-18T03:28:14Z","date_created":"2025-06-25T19:18:19Z","summary":null,"body":["<article data-history-node-id=\"6485\" about=\"\/en\/alerts-advisories\/vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2025-5349-cve-2025-5777-cve-2025-6543\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-008<br \/><strong>Date:<\/strong> June 26, 2025<br \/><strong>Updated:<\/strong> July 17, 2025<\/p>\n\n<p>\u00a0<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On June 17 and 25, 2025, Citrix published security advisories for critical vulnerabilities, CVE-2025-5349, CVE-2025-5777 and CVE-2025-6543, affecting the following products<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>:<\/p>\n\n<ul><li>NetScaler ADC 12.1-FIPS \u2013 versions prior to 12.1-55.328-FIPS<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 14.1 \u2013 versions prior to 14.1-47.46<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.1 \u2013 versions prior to 13.1-59.19<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and NDcPP \u2013 versions prior to 13.1-37.236-FIPS and NDcPP<\/li>\n<\/ul><p>NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End-Of-Life (EOL) and are no longer supported.<\/p>\n\n<p>For CVE-2025-5777 and CVE-2025-6543: NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server for these vulnerabilities to be exploited.<\/p>\n\n<p>For CVE-2025-5349: An improper access control configured on NetScaler management interface would lead to an access to NSIP, to Cluster Management IP and to local GSLB Site IP.<\/p>\n\n<p>Citrix reports that exploitation of CVE-2025-6543 against unmitigated appliances has been observed. In response to these vulnerabilities, the Cyber Centre released AV25-350 on June 17<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> and AV25-374 on June 25, 2025<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre is aware of online interest and speculation about these vulnerabilities and is publishing this Alert out of an abundance of caution.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>The Cyber Centre has observed scanning by threat actors for CVE-2025-5777 and has received reports that it is being actively exploited <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>. Organizations should be aware that patching does not necessarily remove access to their system from threat actors who compromised the device while it was still vulnerable. The Cyber Centre recommends organizations complete a threat hunting exercise using the potential indicators of compromise below regardless of whether you have patched for the mentioned vulnerabilities or not.<\/p>\n\n<h2>Potential Indicators of Compromise<\/h2>\n\n<p>The following indicators of compromise (IoCs) have been shared by the cyber security research community as a starting point for compromise detection.<\/p>\n\n<ul><li>Depending on logging configurations, log entries with non-printable characters are a pretty good indicator that something is amiss <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/li>\n\t<li>The Citrix advisory recommends terminating existing ICA and PCoIP sessions, which leads us to believe that endpoints related to those features are being targeted. Entries for those logs may similarly contain contents of leaked memory, which may or may not include session tokens <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/li>\n\t<li>Auditing active sessions is also recommended. As an example, a single session being used from multiple client IP addresses could be an indicator that the session may have been compromised <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.\n\t<ul><li>Active sessions for NetScaler Gateway can be found in the WebUI via \u201cNetScaler Gateway\u00a0-&gt; Active User Sessions\u00a0-&gt; Select applicable context\u00a0-&gt; Continue\u201d<\/li>\n\t\t<li>Session information can also be viewed on the command line by running commands such as \u201cshow sessions\u201d or \u201cshow &lt;service&gt; session\u201d<\/li>\n\t<\/ul><\/li>\n\t<li>In Netscaler logs, look for:\n\t<ul><li>Repeated POST requests to *doAuthentication* which will each yield 126 bytes of RAM.<\/li>\n\t\t<li>Requests to doAuthentication.do with \u201cContent-Length: 5\u201d.<\/li>\n\t\t<li>Lines with *LOGOFF* and user = \u201c*#*\u201d (i.e. # symbol in the username)<\/li>\n\t<\/ul><\/li>\n\t<li>Monitor entries for endpoint logs for contents of leaked memory, which may or may not include session tokens.<\/li>\n\t<li>Monitor for the creation of new user accounts, dumping or modifying configuration files, and the installation of Remote Access Tools (RATs)<\/li>\n<\/ul><h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations using Citrix NetScaler ADC and NetScaler Gateway appliances review the Citrix security bulletins<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> and update or upgrade the affected systems to the following versions:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway 14.1-47.46 and later.<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.1-59.19 and later releases of 13.1.<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.236 and later releases of 13.1-FIPS and 13.1-NDcPP.<\/li>\n<\/ul><h3>Update 2<\/h3>\n\n<p>The Cyber Centre recommends:<\/p>\n\n<ul><li>That administrators review logs going back to the beginning of June 2025.<\/li>\n\t<li>As a precaution, all users who logged into Citrix Netscaler since the beginning of the month of June should reset their credentials and that all active user sessions should be invalidated.<\/li>\n\t<li>An <abbr title=\"indicator of compromise\">IOC<\/abbr> shell script is being provided by Citrix Support Services and can be run to help determine if organizations are potentially compromised. Please request the <abbr title=\"indicator of compromise\">IOC<\/abbr> Shell Script from Citrix Support line by opening a Severity 2 ticket through your Citrix support portal.<\/li>\n\t<li>That administrators should follow recommended next steps as highlighted in the referenced DoublePulsar <span class=\"nowrap\">article<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/span><\/li>\n<\/ul><h3>Update 1<\/h3>\n\n<p>Citrix has provided the steps to take if NetScaler ADC is suspected to be compromised <sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>, which includes:<\/p>\n\n<ul><li>Preserve evidence.<\/li>\n\t<li>If possible, avoid switching off the machine in order to preserve the traces needed for investigations.<\/li>\n\t<li>Completely isolate the machine concerned from the network, both from the Internet and from the internal network, in order to limit the risk of further unauthorized access and lateral movement.<\/li>\n\t<li>Revoke credentials and access.<\/li>\n\t<li>Examine all servers and systems to which the NetScaler ADC has connected for signs of compromise.<\/li>\n\t<li>Rebuild and restore.<\/li>\n\t<li>Rotate restored secrets.<\/li>\n\t<li>Harden the device.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX693420 \">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-5349 and CVE-2025-5777<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694788&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_6543 \">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-350 \">AV25-350\u00a0\u2013 Citrix security advisory <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-374\">AV25-374\u00a0\u2013 Citrix security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cert.ssi.gouv.fr\/alerte\/CERTFR-2025-ALE-009\/\"><span lang=\"fr\" xml:lang=\"fr\" xml:lang=\"fr\">Bulletin d'alerte du CERT-FR\u00a0- Objet: Multiples vuln\u00e9rabilit\u00e9s dans Citrix NetScaler ADC et NetScaler Gateway<\/span> (only in French)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/horizon3.ai\/attack-research\/attack-blogs\/cve-2025-5777-citrixbleed-2-write-up-maybe\/\">CVE-2025-5777: CitrixBleed 2 Write-Up\u2026 Maybe?<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694799\">Citrix\u00a0\u2013 Steps to Take if NetScaler ADC is Suspected to be Compromised<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/doublepulsar.com\/citrixbleed-2-situation-update-everybody-already-got-owned-503c6d06da9f\">CitrixBleed 2 situation update\u00a0\u2014 everybody already got owned<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2025-5349-cve-2025-5777-cve-2025-6543","alert_type":397,"serial_number":"AL25-008","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6486,"title":"Cisco security advisory (AV25-376) - Update 1","uuid":"1a23ff8c-dd28-4a69-af18-9382f9f21846","banner":null,"lang":"en","date_modified":"2025-07-22","date_modified_ts":"2025-07-22T17:33:41Z","date_created":"2025-06-25T19:22:17Z","summary":null,"body":["<article data-history-node-id=\"6486\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-376\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-376<br \/><strong>Date: <\/strong>June 25, 2025<br \/><strong>Updated: <\/strong>July 22, 2025<\/p>\n\n<p>On June 25, 2025, Cisco published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco ISE and ISE-PIC\u00a0\u2013 versions prior to 3.3 Patch 7<\/li>\n\t<li>Cisco ISE and ISE-PIC\u00a0\u2013 versions prior to 3.4 Patch 2<\/li>\n<\/ul><p>Cisco is aware that some of these vulnerabilities have been exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-unauth-rce-ZAd2GnJ6\">Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities <\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-376","alert_type":396,"serial_number":"AV25-376","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6487,"title":"VMware security advisory (AV25-377)","uuid":"a4e87cd9-56c9-4d16-b04c-0ad0b45ce60c","banner":null,"lang":"en","date_modified":"2025-06-26","date_modified_ts":"2025-06-26T12:51:33Z","date_created":"2025-06-26T12:48:14Z","summary":null,"body":["<article data-history-node-id=\"6487\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-377\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-377<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 26, 2025<\/p>\n\n<p>On June 25, 2025, VMware published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Tanzu for Postgres\u00a0\u2013 versions 17.4.0, 16.8.0, 15.12.0, 14.17.0, 13.20.0<\/li>\n\t<li>VMware Tanzu for Postgres\u00a0\u2013 versions 17.5.0, 16.9.0, 15.13.0, 14.18.0, 13.21.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35866\">Security Advisories\u00a0\u2013 TNZ-2025-0039<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35867\">Security Advisories\u00a0\u2013 TNZ-2025-0040<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-377","alert_type":396,"serial_number":"AV25-377","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6488,"title":"Microsoft Edge security advisory (AV25-378)","uuid":"d4d327b1-6375-498e-845b-982b74de35d7","banner":null,"lang":"en","date_modified":"2025-06-27","date_modified_ts":"2025-06-27T12:37:05Z","date_created":"2025-06-27T12:34:31Z","summary":null,"body":["<article data-history-node-id=\"6488\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-378\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-378<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 27, 2025<\/p>\n\n<p>On June 26, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 138.0.3351.55<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-26-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-378","alert_type":396,"serial_number":"AV25-378","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6489,"title":"VMware security advisory (AV25-379)","uuid":"b0824017-1c91-4b16-9388-5fbfe5e159f0","banner":null,"lang":"en","date_modified":"2025-06-27","date_modified_ts":"2025-06-27T12:42:30Z","date_created":"2025-06-27T12:39:40Z","summary":null,"body":["<article data-history-node-id=\"6489\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-379\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-379<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 27, 2025<\/p>\n\n<p>On June 26, 2025, VMware published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>RabbitMQ \u2013 version 3.13.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35875\">Security Advisories \u2013 TNZ-2025-0041<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories \u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-379","alert_type":396,"serial_number":"AV25-379","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6496,"title":"MongoDB security advisory (AV25-380)","uuid":"b210f792-b770-4a94-ab2b-305544d05687","banner":null,"lang":"en","date_modified":"2025-06-27","date_modified_ts":"2025-06-27T19:16:30Z","date_created":"2025-06-27T19:09:32Z","summary":null,"body":["<article data-history-node-id=\"6496\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory-av25-380\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-380<br \/><strong>Date: <\/strong>June 27, 2025<\/p>\n\n<p>On June 26, 2025, MongoDB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MongoDB Server v6.0\u00a0\u2013 versions prior to 6.0.21<\/li>\n\t<li>MongoDB Server v7.0\u00a0\u2013 versions prior to 7.0.17<\/li>\n\t<li>MongoDB Server v8.0\u00a0\u2013 versions prior to 8.0.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/jira.mongodb.org\/browse\/SERVER-106748\">Pre-auth denial of service when accepting OIDC authentication<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory-av25-380","alert_type":396,"serial_number":"AV25-380","subject":"other","moderation_state":"published","external_url":null},{"nid":6497,"title":"[Control systems] CISA ICS security advisories (AV25-381)","uuid":"6aa64cf3-1278-4f0b-8bfd-501957c7db84","banner":null,"lang":"en","date_modified":"2025-06-30","date_modified_ts":"2025-06-30T17:36:57Z","date_created":"2025-06-30T17:24:27Z","summary":null,"body":["<article data-history-node-id=\"6497\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-381\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-381<br \/><strong>Date: <\/strong>June 30, 2025<\/p>\n\n<p>Between June 23 and 29, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ControlID iDSecure On-premises\u00a0\u2013 version 4.7.48.0 and prior<\/li>\n\t<li>Delta Electronics CNCSoft\u00a0\u2013 version v1.01.34 and prior<\/li>\n\t<li>Kaleris Navis N4\u00a0\u2013 versions prior to 4.0<\/li>\n\t<li>MICROSENS NMP WEB+\u00a0\u2013 version 3.2.5 and prior<\/li>\n\t<li>Mitsubishi Electric Air conditioning systems\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Parsons Utility Enterprise Data Management\u00a0\u2013 versions 5.18, 5.03, 3.30, and versions 4.02 to 4.26<\/li>\n\t<li>Parsons AclaraONE Utility Portal\u00a0\u2013 versions prior to 1.22<\/li>\n\t<li>Schneider Electric EVLink WallBox\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Controllers M241\u00a0\u2013 versions prior to 5.3.12.51<\/li>\n\t<li>Schneider Electric Modicon Controllers M251\u00a0\u2013 versions prior to 5.3.12.51<\/li>\n\t<li>Schneider Electric Modicon Controllers M262\u00a0\u2013 versions prior to 5.3.9.18<\/li>\n\t<li>Schneider Electric Modicon Controllers M258\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Modicon Controllers LMC058\u00a0\u2013 all versions<\/li>\n\t<li>TrendMakers Sight Bulb Pro Firmware ZJ_CG32-2201\u00a0\u2013 version 8.57.83 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-381","alert_type":398,"serial_number":"AV25-381","subject":"ics","moderation_state":"published","external_url":null},{"nid":6498,"title":"IBM security advisory (AV25-383)","uuid":"83d214ff-da78-4fd3-9b2f-ae880abacbc2","banner":null,"lang":"en","date_modified":"2025-06-30","date_modified_ts":"2025-06-30T18:11:45Z","date_created":"2025-06-30T17:39:57Z","summary":null,"body":["<article data-history-node-id=\"6498\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-383\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-383<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 30, 2025<\/p>\n\n<p>Between June 23 and 29, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-383","alert_type":396,"serial_number":"AV25-383","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6499,"title":"Ubuntu security advisory (AV25-382)","uuid":"967cb482-3009-4b32-9f58-f28914f287ac","banner":null,"lang":"en","date_modified":"2025-06-30","date_modified_ts":"2025-06-30T17:50:41Z","date_created":"2025-06-30T17:43:06Z","summary":null,"body":["<article data-history-node-id=\"6499\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-382\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-382<br \/><strong>Date: <\/strong>June 30, 2025<\/p>\n\n<p>Between June 23 and 29, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 25.04<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-382","alert_type":396,"serial_number":"AV25-382","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6500,"title":"Dell security advisory (AV25-384)","uuid":"e80f3f35-db5a-46be-9a13-65f8bdce32cb","banner":null,"lang":"en","date_modified":"2025-06-30","date_modified_ts":"2025-06-30T18:12:26Z","date_created":"2025-06-30T17:47:59Z","summary":null,"body":["<article data-history-node-id=\"6500\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-384\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-384<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>June 30, 2025<\/p>\n\n<p>Between June 23 and 29, 2025, Dell published security advisories to address vulnerabilities for the following products:<\/p>\n\n<ul><li>iDRAC10\u00a0\u2013 versions prior to 1.20.50.50<\/li>\n\t<li>NetWorker\u00a0\u2013 versions 19.12 to 19.12.0.1 and versions prior to 19.11.0.5<\/li>\n\t<li>Dell Open Manage Network Integration\u00a0\u2013 versions prior to 3.7<\/li>\n\t<li>Dell PowerMax EEM 5978\u00a0\u2013 versions prior to 5978.714.714.10730<\/li>\n\t<li>Dell PowerMax EEM 10.2.0.1\u00a0\u2013 versions prior to 10.2.01 Patch 10732<\/li>\n\t<li>Dell PowerMaxOS 5978\u00a0\u2013 versions prior to 5978.714.714.10730<\/li>\n\t<li>Dell PowerMax OS 10.2.0.1\u00a0\u2013 versions prior to 10.2.0.1 Patch 10732<\/li>\n\t<li>PowerProtect Cyber Recovery\u00a0\u2013 versions prior to 19.20<\/li>\n\t<li>Dell Secure Connect Gateway\u00a0- Appliance \u2013 versions prior to 5.30.0.14<\/li>\n\t<li>Solutions Enabler\u00a0\u2013 versions prior to 9.2.4.11 and versions prior to 10.2.0.5<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 5.1.1.0<\/li>\n\t<li>Dell Storage Resource Manager (SRM)\u00a0\u2013 versions prior to 5.1.1.0<\/li>\n\t<li>Unisphere for PowerMax\u00a0\u2013 versions prior to 9.2.4.17 and versions prior to 10.2.0.12<\/li>\n\t<li>Unisphere 360\u00a0\u2013 versions prior to 9.2.4.37<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-384","alert_type":396,"serial_number":"AV25-384","subject":"dell","moderation_state":"published","external_url":null},{"nid":6501,"title":"Google Chrome security advisory (AV25-385)","uuid":"ccbd0c36-1515-4f41-92eb-04f3dc815686","banner":null,"lang":"en","date_modified":"2025-07-02","date_modified_ts":"2025-07-02T15:58:09Z","date_created":"2025-07-02T15:55:50Z","summary":null,"body":["<article data-history-node-id=\"6501\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-385\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-385<br \/><strong>Date: <\/strong>July\u00a02, 2025<\/p>\n\n<p>On June\u00a030, 2025, Google published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 138.0.7204.96\/97\u00a0(Windows), 138.0.7204.92\/93\u00a0(Mac), and 138.0.7204.92 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2025-6554 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/06\/stable-channel-update-for-desktop_30.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-385","alert_type":396,"serial_number":"AV25-385","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6502,"title":"Microsoft Edge security advisory (AV25-386)","uuid":"77f22c29-0bc9-4d47-8cf9-e20d329328e3","banner":null,"lang":"en","date_modified":"2025-07-02","date_modified_ts":"2025-07-02T16:05:01Z","date_created":"2025-07-02T16:02:42Z","summary":null,"body":["<article data-history-node-id=\"6502\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-386\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-386<br \/><strong>Date: <\/strong>July\u00a02, 2025<\/p>\n\n<p>On July\u00a01, 2025, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 138.0.3351.65<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2025-49713 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-1-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-386","alert_type":396,"serial_number":"AV25-386","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6503,"title":"Citrix security advisory (AV25-387)","uuid":"0b43f2ea-52f8-4c2e-a1cd-5e8b67b18e67","banner":null,"lang":"en","date_modified":"2025-07-02","date_modified_ts":"2025-07-02T17:30:53Z","date_created":"2025-07-02T17:26:51Z","summary":null,"body":["<article data-history-node-id=\"6503\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-387\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-387<br \/><strong>Date: <\/strong>July 2, 2025<\/p>\n\n<p>On July 2, 2025, Citrix published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>XenServer 8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694780&amp;articleURL=XenServer_Security_Update_for_CVE_2025_27465\">Citrix Security Advisory\u00a0\u2013 CTX694780<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-387","alert_type":396,"serial_number":"AV25-387","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6504,"title":"Cisco security advisory (AV25-388)","uuid":"7585574f-547b-466f-aeca-b3b1e78fd6af","banner":null,"lang":"en","date_modified":"2025-07-02","date_modified_ts":"2025-07-02T18:08:32Z","date_created":"2025-07-02T18:02:53Z","summary":null,"body":["<article data-history-node-id=\"6504\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-388\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-388<br \/><strong>Date: <\/strong>July\u00a02, 2025<\/p>\n\n<p>On July\u00a02, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco BroadWorks Application Delivery Platform\u00a0\u2013 versions prior to RI.2025.05<\/li>\n\t<li>Cisco Enterprise Chat and Email\u00a0\u2013 version 11 and versions prior to 12.6(1)_ES11<\/li>\n\t<li>Cisco Spaces Connector\u00a0\u2013 versions prior to Connector 3-Jun 2025<\/li>\n\t<li>Cisco Unified Communications Manager\u00a0\u2013 versions 15.0.1.13010-1 to 15.0.1.13017-1<\/li>\n\t<li>Cisco Unified Communications Manager Session Management Edition Engineering Special\u00a0(ES)\u00a0\u2013 versions 15.0.1.13010-1 to 15.0.1.13017-1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-broadworks-xss-O696ymRA\">Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ece-xss-CbtKtEYc\">Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-spaces-conn-privesc-kgD2CcDU\">Cisco Spaces Connector Privilege Escalation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cucm-ssh-m4UBdpE7\">Cisco Unified Communications Manager Static SSH Credentials Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-388","alert_type":396,"serial_number":"AV25-388","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6505,"title":"Drupal security advisory (AV25-389)","uuid":"094e7e99-f540-48e7-828a-5bbf2dec701e","banner":null,"lang":"en","date_modified":"2025-07-03","date_modified_ts":"2025-07-03T14:35:07Z","date_created":"2025-07-03T14:25:36Z","summary":null,"body":["<article data-history-node-id=\"6505\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-389\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-389<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 3, 2025<\/p>\n\n<p>On July 2, 2025, Drupal published security advisories to address vulnerabilities in the following products\u00a0:<\/p>\n\n<ul><li>Config Pages Viewer\u00a0\u2013 versions prior to 1.0.4<\/li>\n\t<li>Two-factor Authentication (TFA)\u00a0\u2013 versions prior to 1.11.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-086\">Config Pages Viewer\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-086<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-085\">Two-factor Authentication (TFA)\u00a0- Less critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-085<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-389","alert_type":396,"serial_number":"AV25-389","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6506,"title":"HPE security advisory (AV25-390)","uuid":"799dc262-adb4-466c-9a91-058c062e8dfe","banner":null,"lang":"en","date_modified":"2025-07-03","date_modified_ts":"2025-07-03T15:11:24Z","date_created":"2025-07-03T14:51:52Z","summary":null,"body":["<article data-history-node-id=\"6506\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-390\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-390<br \/><strong>Date: <\/strong>July 7, 2025<\/p>\n\n<p>On July 2, 2025, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04886en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- HPESBNW04886 rev.1\u00a0- HPE Telco Service Orchestrator Software, Server-Side Request Forgery (SSRF) Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-390","alert_type":396,"serial_number":"AV25-390","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6507,"title":"Wing FTP security advisory (AV25-391) - Update 2","uuid":"c19cf55f-e1ae-48bf-aa3c-777e2480c208","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T17:48:08Z","date_created":"2025-07-03T15:20:34Z","summary":null,"body":["<article data-history-node-id=\"6507\" about=\"\/en\/alerts-advisories\/wing-ftp-security-advisory-av25-391\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-391<br \/><strong>Date: <\/strong> July\u00a03, 2025<br \/><strong>Updated: <\/strong> March\u00a016, 2026<\/p>\n\n<p>On May\u00a014, 2025, Wing FTP a published an update to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Wing FTP Server\u00a0\u2013 version v7.4.3 and prior<\/li>\n<\/ul><p>Open-source reporting has indicated that proof-of-concept exploit code is available for CVE-2025-47812.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On July\u00a010, 2025, open-source reporting indicated that the Wing FTP Remote Code Execution vulnerability CVE-2025-47812 has been actively exploited in the wild. The vulnerability is rated a CVSS 10.0.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On March\u00a016, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-47813 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.wftpserver.com\/serverhistory.htm\">Wing FTP Server v7.4.4<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-47813\">CISA KEV: CVE-2025-47813<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wing-ftp-security-advisory-av25-391","alert_type":396,"serial_number":"AV25-391","subject":"other","moderation_state":"published","external_url":null},{"nid":6508,"title":"Brother security advisory (AV25-392)","uuid":"7d60a9a6-9156-4967-990b-d73d3e7267ad","banner":null,"lang":"en","date_modified":"2025-07-03","date_modified_ts":"2025-07-03T18:17:21Z","date_created":"2025-07-03T18:07:33Z","summary":null,"body":["<article data-history-node-id=\"6508\" about=\"\/en\/alerts-advisories\/brother-security-advisory-av25-392\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-392<br \/><strong>Date: <\/strong>July 3, 2025<\/p>\n\n<p>On June 19 and 25, 2025, Brother, Toshiba, Ricoh, Fujifilm and Konica Minolta released security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.brother.com\/g\/b\/faqend.aspx?c=us&amp;lang=en&amp;prod=group2&amp;faqid=faq00100846_000\">Brother FAQs and Troubleshooting - Addressing Security Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.toshibatec.com\/information\/20250625_02.html\">Toshiba - Response to vulnerability in some Toshiba Tec's digital multi-function peripherals<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ricoh.com\/products\/security\/vulnerabilities\/vul?id=ricoh-2025-000007\">Ricoh - Specific Ricoh MFP and Printer Products - Multiple vulnerabilities (CVE-2017-9765, CVE-2024-2169, CVE-2024-51977, CVE-2024-51979, CVE-2024-51980, CVE-2024-51981, CVE-2024-51982, CVE-2024-51983, CVE-2024-51984)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fujifilm.com\/fbglobal\/eng\/company\/news\/notice\/2025\/0625_announce.html\">Notice on Vulnerabilities in FUJIFILM Multifunction Devices and Printers<\/a><\/li>\n\t<li><a href=\"https:\/\/www.konicaminolta.com\/global-en\/security\/advisory\/pdf\/km-2025-0001.pdf\">Konica Minolta - Multiple vulnerabilities in B\/W small multifunction and single-function printers<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/brother-security-advisory-av25-392","alert_type":396,"serial_number":"AV25-392","subject":"other","moderation_state":"published","external_url":null},{"nid":6509,"title":"[Control systems] ABB security advisory (AV25-393)","uuid":"7b064ae5-5792-44b4-8936-e8b8052b79d6","banner":null,"lang":"en","date_modified":"2025-07-03","date_modified_ts":"2025-07-03T18:35:40Z","date_created":"2025-07-03T18:30:35Z","summary":null,"body":["<article data-history-node-id=\"6509\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-393\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-393<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 3, 2025<\/p>\n\n<p>On July 3, 2025, ABB published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>RMC-100\u00a0\u2013 versions 2105457-043 to 2105457-045<\/li>\n\t<li>RMC-100 LITE\u00a0\u2013 versions 2106229-015 to 2106229-016<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A3623&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">ABB Cyber Security Advisory\u00a0- Vulnerabilities in web UI (REST Interface) RMC-100<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-393","alert_type":398,"serial_number":"AV25-393","subject":"abb","moderation_state":"published","external_url":null},{"nid":6510,"title":"Grafana security advisory (AV25-394)","uuid":"3f387918-dadd-42d8-abdf-6571b5818c0d","banner":null,"lang":"en","date_modified":"2025-07-03","date_modified_ts":"2025-07-03T20:05:32Z","date_created":"2025-07-03T19:59:39Z","summary":null,"body":["<article data-history-node-id=\"6510\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av25-394\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-394<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 3, 2025<\/p>\n\n<p>On July 2, 2025, Grafana published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Grafana Image Renderer\u00a0\u2013 versions prior to 3.12.9<\/li>\n\t<li>Synthetic Monitoring Agent\u00a0\u2013 versions prior to 0.38.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/blog\/2025\/07\/02\/grafana-security-update-critical-severity-security-release-for-cve-2025-5959-cve-2025-6554-cve-2025-6191-and-cve-2025-6192-in-grafana-image-renderer-plugin-and-synthetic-monitoring-agent\/\">Grafana Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av25-394","alert_type":396,"serial_number":"AV25-394","subject":"other","moderation_state":"published","external_url":null},{"nid":6512,"title":"Ubuntu security advisory (AV25-395)","uuid":"713dd7f7-1704-4560-aad6-b5a3f2cfd63f","banner":null,"lang":"en","date_modified":"2025-07-07","date_modified_ts":"2025-07-07T14:22:10Z","date_created":"2025-07-07T13:58:43Z","summary":null,"body":["<article data-history-node-id=\"6512\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-395\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-395<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong> July 7, 2025<\/p>\n\n<p>Between June 30 and July 6, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-395","alert_type":396,"serial_number":"AV25-395","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6511,"title":"IBM security advisory (AV25-396)","uuid":"2fe85954-087a-4290-b48b-2c47613e6240","banner":null,"lang":"en","date_modified":"2025-07-07","date_modified_ts":"2025-07-07T14:23:53Z","date_created":"2025-07-07T14:15:53Z","summary":null,"body":["<article data-history-node-id=\"6511\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-396\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-396<br \/><strong>Date: <\/strong>July\u00a07, 2025<\/p>\n\n<p>Between June\u00a030 and July\u00a06, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-396","alert_type":396,"serial_number":"AV25-396","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6513,"title":"Qualcomm security advisory \u2013 July 2025 monthly rollup (AV25-397)","uuid":"fd4d2b08-d746-4b3f-8d3b-a187b047d267","banner":null,"lang":"en","date_modified":"2025-07-07","date_modified_ts":"2025-07-07T14:35:00Z","date_created":"2025-07-07T14:32:01Z","summary":null,"body":["<article data-history-node-id=\"6513\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-july-2025-monthly-rollup-av25-397\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-397<br \/><strong>Date: <\/strong>July\u00a07, 2025<\/p>\n\n<p>On July\u00a07, 2025, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/july-2025-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 July<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-july-2025-monthly-rollup-av25-397","alert_type":396,"serial_number":"AV25-397","subject":"other","moderation_state":"published","external_url":null},{"nid":6514,"title":"Red Hat security advisory (AV25-398)","uuid":"a42e496c-a9d2-4cf2-b57d-9a860b0d3957","banner":null,"lang":"en","date_modified":"2025-07-07","date_modified_ts":"2025-07-07T14:55:07Z","date_created":"2025-07-07T14:46:54Z","summary":null,"body":["<article data-history-node-id=\"6514\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-398\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-398<br \/><strong>Date: <\/strong>July 7, 2025<\/p>\n\n<p>Between June 30 and July 6, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-398","alert_type":396,"serial_number":"AV25-398","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6517,"title":"[Control systems] CISA ICS security advisories (AV25-400)","uuid":"9f22532f-9a60-4484-8912-4bccf72521c5","banner":null,"lang":"en","date_modified":"2025-07-07","date_modified_ts":"2025-07-07T17:57:33Z","date_created":"2025-07-07T15:41:05Z","summary":null,"body":["<article data-history-node-id=\"6517\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-400\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-400<br \/><strong>Date: <\/strong>July\u00a07, 2025<\/p>\n\n<p>Between June\u00a030 and July\u00a06, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FESTO Automation Suite, FluidDraw, and Festo Didactic Products\u00a0\u2013 multiple products and versions<\/li>\n\t<li>FESTO CODESYS Gateway Server V2\u00a0\u2013 all versions<\/li>\n\t<li>FESTO CODESYS Gateway Server V2\u00a0\u2013 versions prior to V2.3.9.38<\/li>\n\t<li>FESTO Didactic Firmware Siemens Simatic S7-1500 \/ ET200SP (&lt; V2.9.2) installed on FESTO Didactic CP including S7 PLC (All versions)\u00a0\u2013 all versions<\/li>\n\t<li>FESTO Didactic Firmware Siemens Simatic S7-1500 \/ ET200SP (&lt; V2.9.2) installed on FESTO Didactic MPS 200 Systems (All versions)\u00a0\u2013 all versions<\/li>\n\t<li>FESTO Didactic Firmware Siemens Simatic S7-1500 \/ ET200SP (&lt; V2.9.2) installed on FESTO Didactic MPS 400 Systems (All versions)\u00a0\u2013 all versions<\/li>\n\t<li>Festo Firmware installed on Festo Hardware Controller\u00a0\u2013 multiple products and versions<\/li>\n\t<li>Hitachi Energy MSM\u00a0\u2013 version 2.2.9 and prior<\/li>\n\t<li>Hitachi Energy Relion 650\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy Relion 670\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi MicroSCADA Pro\/X SYS600\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi SAM600-IO\u00a0\u2013 version 2.2.5.6<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M\u00a0\u2013 versions 1.000A to 1.012N<\/li>\n\t<li>Voltronic Power Viewpower\u00a0\u2013 version 1.04-24215 and prior<\/li>\n\t<li>Voltronic Power ViewPower Pro\u00a0\u2013 version 2.2165 and prior<\/li>\n\t<li>Voltronic Powershield NetGuard\u00a0\u2013 version 1.04-22119 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-400","alert_type":398,"serial_number":"AV25-400","subject":"ics","moderation_state":"published","external_url":null},{"nid":6516,"title":"Dell security advisory (AV25-399)","uuid":"4b9dcbf6-4dd1-470b-99e5-934f7cc56fce","banner":null,"lang":"en","date_modified":"2025-07-07","date_modified_ts":"2025-07-07T17:46:46Z","date_created":"2025-07-07T17:41:30Z","summary":null,"body":["<article data-history-node-id=\"6516\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-399\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number\u00a0: <\/strong>AV25-399<br \/><strong>Date\u00a0: <\/strong>July 7, 2025<\/p>\n\n<p>Between June 30 and July 6, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Apex Cloud Platform for Red Hat Openshift\u00a0\u2013 versions prior to 03.01.03.00<\/li>\n\t<li>Dell Enterprise SONiC Distribution\u00a0\u2013 versions prior to 4.5.0<\/li>\n\t<li>Dell Integrated System for Microsoft Azure Stack Hub 14G\u00a0\u2013 versions prior to 2504<\/li>\n\t<li>Dell Integrated System for Microsoft Azure Stack Hub 16G\u00a0\u2013 versions prior to 2504<\/li>\n\t<li>Dell ObjectScale 4.0.0.1\u00a0\u2013 versions prior to 4.0.0.1<\/li>\n\t<li>Dell Protection Advisor\u00a0\u2013 versions 19.9 to 19.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000339112\/dsa-2025-243-security-update-for-dell-objectscale-4-0-0-1-multiple-third-party-component-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-243<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000339094\/dsa-2025-265-security-update-for-dell-apex-cloud-platform-for-red-hat-openshift-for-multiple-third-party-component-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-265<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000340393\/dsa-2025-270-security-update-for-dell-integrated-system-for-microsoft-azure-stack-hub-multiple-third-party-component-vulnerabilities\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Dell Security Advisories<\/span>\u00a0\u2013 DSA-2025-270<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000340083\/dsa-2025-275-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-275<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000340538\/dsa-2025-276-security-update-for-data-protection-advisor-for-multiple-vulnerabilities\">Dell Security Advisories\u00a0\u2013 DSA-2025-276<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/fr-ca?lwp=rt\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-399","alert_type":396,"serial_number":"AV25-399","subject":"dell","moderation_state":"published","external_url":null},{"nid":6518,"title":"Splunk security advisory (AV25-401)","uuid":"93f5ddb9-8fe0-413f-9db7-b7ab931e487d","banner":null,"lang":"en","date_modified":"2025-07-07","date_modified_ts":"2025-07-07T19:23:03Z","date_created":"2025-07-07T19:15:51Z","summary":null,"body":["<article data-history-node-id=\"6518\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-401\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-401<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 7, 2025<\/p>\n\n<p>On July 7, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk Cloud Platform\u00a0\u2013 versions prior to 9.3.2411.103<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 versions prior to 9.3.2408.113<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 versions prior to 9.2.2406.119<\/li>\n\t<li>Splunk DB Connect\u00a0\u2013 versions prior to 4.0.0<\/li>\n\t<li>Splunk Enterprise\u00a0\u2013 versions 9.4.0 to 9.4.2<\/li>\n\t<li>Splunk Enterprise\u00a0\u2013 versions 9.3.0 to 9.3.4<\/li>\n\t<li>Splunk Enterprise\u00a0\u2013 versions 9.2.0 to 9.2.6<\/li>\n\t<li>Splunk Enterprise\u00a0\u2013 versions 9.1.0 to 9.1.9<\/li>\n\t<li>Splunk Enterprise Cloud\u00a0\u2013 versions prior to 9.3.2411.107<\/li>\n\t<li>Splunk Enterprise Cloud\u00a0\u2013 versions prior to 9.3.2408.117<\/li>\n\t<li>Splunk Enterprise Cloud\u00a0\u2013 versions prior to 9.2.2406.121<\/li>\n\t<li>splunk\/universalforwarder\u00a0\u2013 versions 9.4.0 to 9.4.2<\/li>\n\t<li>splunk\/universalforwarder\u00a0\u2013 versions 9.3.0 to 9.3.4<\/li>\n\t<li>splunk\/universalforwarder\u00a0\u2013 versions 9.2.0 to 9.2.6<\/li>\n\t<li>splunk\/universalforwarder\u00a0\u2013 versions 9.1.0 to 9.1.9<\/li>\n\t<li>Splunk SOAR\u00a0\u2013 versions prior to 6.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\">Splunk Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-401","alert_type":396,"serial_number":"AV25-401","subject":"other","moderation_state":"published","external_url":null},{"nid":6520,"title":"[Control systems] Schneider Electric security advisory (AV25-403)","uuid":"0ec6604d-366c-4119-904a-b8e2c37b3afc","banner":null,"lang":"en","date_modified":"2025-07-08","date_modified_ts":"2025-07-08T14:48:18Z","date_created":"2025-07-08T14:33:07Z","summary":null,"body":["<article data-history-node-id=\"6520\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-403\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-403<br \/><strong>Date: <\/strong>July\u00a08, 2025<\/p>\n\n<p>On July\u00a08, 2025, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure IT Data Center Expert\u00a0\u2013 version 8.3 and prior<\/li>\n\t<li>EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 multiple versions<\/li>\n\t<li>EcoStruxure Power Operation (EPO) 2022\u00a0\u2013 versions CU6 and prior<\/li>\n\t<li>EcoStruxure Power Operation (EPO) 2024\u00a0\u2013 versions CU1 and prior<\/li>\n\t<li>EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module\u00a0\u2013 version 2022 with Advanced Reporting Module and version 2024 with Advanced Reporting Module<\/li>\n\t<li>System Monitor application in Harmony Industrial PC HMIBMO\/HMIBMI\/ HMIPSO\/HMIBMP\/ HMIBMU\/HMIPSP\/HMIPEP series\u00a0\u2013 all versions<\/li>\n\t<li>System Monitor application in Pro-face Industrial PC PS5000 series\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-403","alert_type":398,"serial_number":"AV25-403","subject":"se","moderation_state":"published","external_url":null},{"nid":6519,"title":"SAP security advisory \u2013 July 2025 monthly rollup (AV25-402)","uuid":"9dc61d6d-db69-4fe4-9368-1ab942f9626c","banner":null,"lang":"en","date_modified":"2025-07-08","date_modified_ts":"2025-07-08T14:46:55Z","date_created":"2025-07-08T14:33:08Z","summary":null,"body":["<article data-history-node-id=\"6519\" about=\"\/en\/alerts-advisories\/sap-security-advisory-july-2025-monthly-rollup-av25-402\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-402<br \/><strong>Date: <\/strong>July\u00a08, 2025<\/p>\n\n<p>On July\u00a08, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP NetWeaver ABAP Server and ABAP\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver ABAP Server and ABAP Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver Visual Composer\u00a0\u2013 version VCBASE 7.50<\/li>\n\t<li>SAP Business Objects Business Intelligence Platform (CMC)\u00a0\u2013 version ENTERPRISE 430, 2025<\/li>\n\t<li>SAP Business Warehouse and SAP Plug-In Basis\u00a0\u2013 multiple versions<\/li>\n\t<li>SAP NetWeaver Enterprise Portal Federated Portal Administration\u00a0\u2013 version EP-RUNTIME 7.50<\/li>\n\t<li>SAP NetWeaver Enterprise Portal Federated Portal Network\u00a0\u2013 version EP-RUNTIME 7.50<\/li>\n\t<li>SAP NetWeaver SAP NetWeaver Application Server for Java (Log Viewer)\u00a0\u2013 version LMNWABASICAPPS 7.50<\/li>\n\t<li>SAP NetWeaver (XML Data Archiving Service)\u00a0\u2013 version J2EE-APPS 7.50<\/li>\n\t<li>SAP Supplier Relationship Management (Live Auction Cockpit)\u00a0\u2013 version SRM_SERVER 7.14<\/li>\n\t<li>SAP S\/4HANA and SAP SCM (Characteristic Propagation)\u00a0\u2013 versions SCMAPO 713, 714, S4CORE 102, 103, 104, S4COREOP 105, 106, 107, 108, SCM 700, 701, 702 and 712<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/july-2025.html\">SAP Security Patch Day\u00a0\u2013 July 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-july-2025-monthly-rollup-av25-402","alert_type":396,"serial_number":"AV25-402","subject":"sap","moderation_state":"published","external_url":null},{"nid":6522,"title":"[Control systems] Siemens security advisory (AV25-404)","uuid":"11626467-0adc-4502-b5d1-6d7e44cc281e","banner":null,"lang":"en","date_modified":"2025-07-08","date_modified_ts":"2025-07-08T16:14:23Z","date_created":"2025-07-08T16:00:16Z","summary":null,"body":["<article data-history-node-id=\"6522\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-404\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-404<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 8, 2025<\/p>\n\n<p>Between July 7 and 8, 2025, Siemens published advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-404","alert_type":398,"serial_number":"AV25-404","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6523,"title":"Ivanti security advisory (AV25-405)","uuid":"cdd0eeef-51ba-447f-9f96-cd097d4ade51","banner":null,"lang":"en","date_modified":"2025-07-08","date_modified_ts":"2025-07-08T16:36:52Z","date_created":"2025-07-08T16:26:21Z","summary":null,"body":["<article data-history-node-id=\"6523\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-405\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-405<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 8, 2025<\/p>\n\n<p>On July 8, 2025, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Connect Secure (ICS)\u00a0\u2013 version 22.7R2.7 and prior<\/li>\n\t<li>Ivanti Endpoint Manager\u00a0\u2013 version 2022 SU8 and prior<\/li>\n\t<li>Ivanti Endpoint Manager\u00a0\u2013 version 2024 SU2 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile\u00a0\u2013 version 12.5.0.1 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile\u00a0\u2013 version 12.4.0.2 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile\u00a0\u2013 version 12.3.0.2 and prior<\/li>\n\t<li>Ivanti Policy Secure (IPS)\u00a0\u2013 version 22.7R1.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2025-6770-CVE-2025-6771?language=en_US\">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2025-6770, CVE-2025-6771)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-July-2025-for-Ivanti-EPM-2024-SU2-and-EPM-2022-SU8?language=en_US\">Security Advisory July 2025 for Ivanti EPM 2024 SU2 and EPM 2022 SU8<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/July-Security-Advisory-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Multiple-CVEs?language=en_US\">July Security Advisory Ivanti Connect Secure and Ivanti Policy Secure (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-405","alert_type":396,"serial_number":"AV25-405","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6524,"title":"Fortinet security advisory (AV25-406) - Update 2","uuid":"0ee944ec-698b-40c1-a215-0c5d0ed2e892","banner":null,"lang":"en","date_modified":"2025-07-18","date_modified_ts":"2025-07-18T19:22:26Z","date_created":"2025-07-08T18:33:51Z","summary":null,"body":["<article data-history-node-id=\"6524\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-406\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-406<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong> July\u00a08, 2025<\/p>\n\n<p><strong>Updated:<\/strong> July\u00a018, 2025<\/p>\n\n<p>On July\u00a08, 2025, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiAnalyzer\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiAnalyzer Cloud\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiIsolator\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiManager\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiManager Cloud\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiOS 7.6\u00a0\u2013 versions 7.6.0 to 7.6.1<\/li>\n\t<li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.7<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiOS 7.0\u00a0\u2013 versions 7.0.1 to 7.0.16<\/li>\n\t<li>FortiProxy 7.6\u00a0\u2013 versions 7.6.0 to 7.6.1<\/li>\n\t<li>FortiProxy 7.4\u00a0\u2013 versions 7.4.0 to 7.4.8<\/li>\n\t<li>FortiProxy 7.2\u00a0\u2013 versions 7.2.0 to 7.2.13<\/li>\n\t<li>FortiProxy 7.0\u00a0\u2013 versions 7.0.0 to 7.0.20<\/li>\n\t<li>FortiSandbox\u00a0\u2013 multiple versions<\/li>\n\t<li>FortiVoice 6.4\u00a0\u2013 versions 6.4.0 to 6.4.10<\/li>\n\t<li>FortiVoice 7.0\u00a0\u2013 versions 7.0.0 to 7.0.6<\/li>\n\t<li>FortiVoice 7.2\u00a0\u2013 versions 7.2.0<\/li>\n\t<li>FortiWeb\u00a0\u2013 multiple versions<\/li>\n<\/ul><h2>Update 2<\/h2>\n\n<p>On July\u00a018, 2025, CISA added CVE-2025-25257 to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>On July\u00a018, 2025, Fortinet updated their advisory to indicate that this vulnerability has been exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/07\/18\/cisa-adds-one-known-exploited-vulnerability-catalog\">Known Exploited Vulnerabilities Catalog<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-151\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>CVE-2025-25257: Unauthenticated SQL injection in GUI affecting:<\/p>\n\n<ul><li>FortiWeb 7.6\u00a0\u2013 versions 7.6.0 to 7.6.3<\/li>\n\t<li>FortiWeb 7.4\u00a0\u2013 versions 7.4.0 to 7.4.7<\/li>\n\t<li>FortiWeb 7.2\u00a0\u2013 versions 7.2.0 to 7.2.10<\/li>\n\t<li>FortiWeb 7.0\u00a0\u2013 versions 7.0.0 to 7.0.10<\/li>\n<\/ul><ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-151\">Fortinet PSIRT\u00a0\u2013 FG-IR-25-151<\/a>\n\n\t<div class=\"clearfix\">\u00a0<\/div>\n\n\t<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n\t<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<\/ul><\/li>\n\t<!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E-->\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-406","alert_type":396,"serial_number":"AV25-406","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6525,"title":"Microsoft security advisory \u2013 July 2025 monthly rollup (AV25-407)","uuid":"de2e66ce-b1cf-4d81-9130-a1a218c49ac8","banner":null,"lang":"en","date_modified":"2025-07-08","date_modified_ts":"2025-07-08T19:47:24Z","date_created":"2025-07-08T19:38:37Z","summary":null,"body":["<article data-history-node-id=\"6525\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2025-monthly-rollup-av25-407\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-407<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong> July 8, 2025<\/p>\n\n<p>On July 8, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Microsoft Office 2016\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Office 2019\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft Office LTSC 2021\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Office LTSC 2024\u00a0\u2013 multiple platforms<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft Word 2016\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows 10\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows 11\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Windows Server 2008\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server 2012\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server 2016\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server 2019\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server 2022\u00a0\u2013 multiple platforms<\/li>\n\t<li>Windows Server 2025\u00a0\u2013 multiple platforms<\/li>\n  \t<li>Microsoft SQL Server\u00a0\u2013 multiple platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Jul\">July 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2025-monthly-rollup-av25-407","alert_type":396,"serial_number":"AV25-407","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6526,"title":"Adobe security advisory (AV25-408)","uuid":"0420b43d-b9c1-4e8e-98d2-df3c8e4aaecb","banner":null,"lang":"en","date_modified":"2025-07-08","date_modified_ts":"2025-07-08T20:06:30Z","date_created":"2025-07-08T19:57:52Z","summary":null,"body":["<article data-history-node-id=\"6526\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-408\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25\u2013408<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 8, 2025<\/p>\n\n<p>On July 8, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe After Effects\u00a0\u2013 version 24.6.6 and prior<\/li>\n\t<li>Adobe After Effects\u00a0\u2013 version 245.2 and prior<\/li>\n\t<li>Adobe Audition\u00a0\u2013 version 24.6.3 and prior<\/li>\n\t<li>Adobe Audition\u00a0\u2013 version 25.2 and prior<\/li>\n\t<li>Adobe ColdFusion\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Connect Windows App\u00a0\u2013 version 24 and prior<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 4.1.2 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM) Forms on JEE\u00a0\u2013 version 6.5.23.0 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM) Screens\u00a0\u2013 version AEM 6.5.22 Screens FP11.4<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 version FrameMaker 2020 Update 8 and prior<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 version FrameMaker 2022 Update 6 and prior<\/li>\n\t<li>Adobe Illustrator 2024\u00a0\u2013 version 28.7.6 and prior<\/li>\n\t<li>Adobe Illustrator 2025\u00a0\u2013 version 29.5.1 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 19.5.3 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 20.3 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID20.3 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.5.3 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.1.2 and prior<\/li>\n\t<li>Adobe Substance 3D Viewer\u00a0\u2013 version 0.22 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-408","alert_type":396,"serial_number":"AV25\u2013408","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6528,"title":"HPE security advisory (AV25-409)","uuid":"9c88ea7a-675e-4c0b-9228-ff831da44fbe","banner":null,"lang":"en","date_modified":"2025-07-09","date_modified_ts":"2025-07-09T15:58:42Z","date_created":"2025-07-09T15:43:00Z","summary":null,"body":["<article data-history-node-id=\"6528\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-409\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-409<br \/><strong>Date: <\/strong>July 9, 2025<\/p>\n\n<p>Between July 7 and 8, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy\u00a0\u2013 versions 9.1.0 to 9.2.2<\/li>\n\t<li>HPE B-series Fibre Channel Switch\u00a0\u2013 multiple versions and models<\/li>\n\t<li>HPE Compute Scale-up Server 3200\u00a0\u2013 versions prior to v1.60.88<\/li>\n\t<li>HPE Networking Instant On Access Point\u00a0\u2013 version 3.2.0.1 and prior<\/li>\n\t<li>HPE ProLiant Cray Servers **\u00a0\u2013 multiple versions and models<\/li>\n\t<li>HPE SANnav Management Software SANnav base OS (OVA deployment)\u00a0\u2013 versions prior to 2.4.0a<\/li>\n\t<li>HPE SN6750B 64Gb 48\/128 48-port 64Gb Short Wave SFP56 Port Side Intake Integrated FC Switch \u2013 versions 9.1.0 to 9.2.2<\/li>\n\t<li>HPE SN8600B 4-slot SAN Director Switch\u00a0\u2013 versions 9.1.0 to 9.2.2<\/li>\n\t<li>HPE SN8600B 8-slot SAN Director Switch\u00a0\u2013 versions 9.1.0 to 9.2.2<\/li>\n\t<li>HPE SN8700B 4-slot SAN Director Switch\u00a0\u2013 versions 9.1.0 to 9.2.2<\/li>\n\t<li>HPE SN8700B 8-slot SAN Director Switch\u00a0\u2013 versions 9.1.0 to 9.2.2<\/li>\n\t<li>HPE Storage Fibre Channel Switch B-series SN3700B\u00a0\u2013 version 22<\/li>\n\t<li>HPE Superdome Flex 280 Server\u00a0\u2013 versions prior to v2.00.12<\/li>\n\t<li>HPE Superdome Flex Server\u00a0\u2013 versions prior to v4.10.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-409","alert_type":396,"serial_number":"AV25-409","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6529,"title":"ServiceNow security advisory (AV25-410)","uuid":"e7b6d07e-6cb5-4d74-9628-ff88a76bc5a3","banner":null,"lang":"en","date_modified":"2025-07-09","date_modified_ts":"2025-07-09T17:52:41Z","date_created":"2025-07-09T17:46:25Z","summary":null,"body":["<article data-history-node-id=\"6529\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av25-410\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-410<br \/><strong>Date: <\/strong>July 9, 2025<\/p>\n\n<p>On July 8, 2025, ServiceNow published a Security Advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ServiceNow Now Platform\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB2139567\">CVE-2025-3648\u00a0- Data Inference in Now Platform via Conditional ACLs<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av25-410","alert_type":396,"serial_number":"AV25-410","subject":"other","moderation_state":"published","external_url":null},{"nid":6531,"title":"GitLab security advisory (AV25-412)","uuid":"1ec36f45-0a2d-4e5d-b828-4b0d878f9c0c","banner":null,"lang":"en","date_modified":"2025-07-09","date_modified_ts":"2025-07-09T18:12:59Z","date_created":"2025-07-09T17:46:44Z","summary":null,"body":["<article data-history-node-id=\"6531\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-412\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-412<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 9, 2025<\/p>\n\n<p>On July 9, 2025, GitLab published a security advisory to address vulnerabilities in the following:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.1.2, 18.0.4 and 17.11.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.1.2, 18.0.4 and 17.11.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/07\/09\/patch-release-gitlab-18-1-2-released\/\">GitLab Patch Release: 18.1.2, 18.0.4, 17.11.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-412","alert_type":396,"serial_number":"AV25-412","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6530,"title":"Citrix security advisory (AV25-411)","uuid":"25eba296-104a-42a4-85e8-58fc9e5e8b3b","banner":null,"lang":"en","date_modified":"2025-07-09","date_modified_ts":"2025-07-09T18:06:51Z","date_created":"2025-07-09T18:03:52Z","summary":null,"body":["<article data-history-node-id=\"6530\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-411\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-411<br \/><strong>Date: <\/strong>July 9, 2025<\/p>\n\n<p>On July 8, 2025, Citrix published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Current Release (CR): Citrix Virtual Apps and Desktops\u00a0\u2013 versions prior to 2503<\/li>\n\t<li>Long Term Service Release (LTSR): Citrix Virtual Apps and Desktops\u00a0\u2013 versions 2402 LTSR CU2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694820&amp;articleURL=Windows_Virtual_Delivery_Agent_for_CVAD_and_Citrix_DaaS_Security_Bulletin_CVE_2025_6759\">Citrix Security Advisory\u00a0\u2013 CTX694820<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-411","alert_type":396,"serial_number":"AV25-411","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6532,"title":"Jenkins security advisory (AV25-413)","uuid":"fd05e8cc-ad85-4131-b8d2-308a5b42a6c4","banner":null,"lang":"en","date_modified":"2025-07-09","date_modified_ts":"2025-07-09T18:14:55Z","date_created":"2025-07-09T18:07:48Z","summary":null,"body":["<article data-history-node-id=\"6532\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-413\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-413<br \/><strong>Date: <\/strong>July\u00a09, 2025<\/p>\n\n<p>On July\u00a09, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apica Loadtest Plugin\u00a0\u2013 version 1.10 and prior<\/li>\n\t<li>Applitools Eyes Plugin\u00a0\u2013 version 1.16.5 and prior<\/li>\n\t<li>Aqua Security Scanner Plugin\u00a0\u2013 version 3.2.8 and prior<\/li>\n\t<li>Credentials Binding Plugin\u00a0\u2013 version 687.v619cb_15e923f and prior<\/li>\n\t<li>Dead Man's Snitch Plugin\u00a0\u2013 version 0.1 and prior<\/li>\n\t<li>Git Parameter Plugin\u00a0\u2013 version 439.vb_0e46ca_14534 and prior<\/li>\n\t<li>HTML Publisher Plugin\u00a0\u2013 version 425 and prior<\/li>\n\t<li>IBM Cloud DevOps Plugin\u00a0\u2013 version 2.0.16 and prior<\/li>\n\t<li>IFTTT Build Notifier Plugin\u00a0\u2013 version 1.2 and prior<\/li>\n\t<li>Kryptowire Plugin\u00a0\u2013 version 0.2 and prior<\/li>\n\t<li>Nouvola DiveCloud Plugin\u00a0\u2013 version 1.08 and prior<\/li>\n\t<li>QMetry Test Management Plugin\u00a0\u2013 version 1.13 and prior<\/li>\n\t<li>ReadyAPI Functional Testing Plugin\u00a0\u2013 version 1.11 and prior<\/li>\n\t<li>Sensedia Api Platform tools Plugin\u00a0\u2013 version 1.0 and prior<\/li>\n\t<li>Statistics Gatherer Plugin\u00a0\u2013 version 2.0.3 and prior<\/li>\n\t<li>Testsigma Test Plan run Plugin\u00a0\u2013 version 1.6 and prior<\/li>\n\t<li>User1st uTester Plugin\u00a0\u2013 version 1.1 and prior<\/li>\n\t<li>VAddy Plugin\u00a0\u2013 version 1.2.8 and prior<\/li>\n\t<li>Warrior Framework Plugin\u00a0\u2013 version 1.2 and prior<\/li>\n\t<li>Xooa Plugin\u00a0\u2013 version 0.0.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-07-09\/\">Jenkins Security Advisory 2025-07-09<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-413","alert_type":396,"serial_number":"AV25-413","subject":"other","moderation_state":"published","external_url":null},{"nid":6533,"title":"Palo Alto Networks security advisory (AV25-414)","uuid":"c7e26692-cb94-413a-b817-5959c983f3e3","banner":null,"lang":"en","date_modified":"2025-07-09","date_modified_ts":"2025-07-09T19:25:02Z","date_created":"2025-07-09T18:50:43Z","summary":null,"body":["<article data-history-node-id=\"6533\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-414\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-414<br \/><strong>Date: <\/strong>July 9, 2025<\/p>\n\n<p>On July 9, 2025, Palo Alto Networks published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Autonomous Digital Experience Manager 5.6.0 macOS\u00a0\u2013 versions prior to 5.6.7<\/li>\n\t<li>GlobalProtect App 6.3 macOS\u00a0\u2013 versions prior to 6.3.3-h1 (6.3.3-c650)<\/li>\n\t<li>GlobalProtect App 6.2 macOS\u00a0\u2013 versions prior to 6.2.8-h2 (6.2.8-c243)<\/li>\n\t<li>GlobalProtect App 6.2 Linux\u00a0\u2013 versions prior to 6.2.8<\/li>\n\t<li>GlobalProtect App 6.1 macOS\u00a0\u2013 all versions<\/li>\n\t<li>GlobalProtect App 6.1 Linux\u00a0\u2013 all versions<\/li>\n\t<li>GlobalProtect App 6.0 macOS\u00a0\u2013 all versions<\/li>\n\t<li>GlobalProtect App 6.0 Linux\u00a0\u2013 all versions<\/li>\n\t<li>Prisma Access Browser\u00a0\u2013 versions prior to 137.16.6.120<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0013\">Palo Alto Networks Security Advisories\u00a0- PAN-SA-2025-0013 Chromium: Monthly Vulnerability Update (July 2025)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-0139\">Palo Alto Networks Security Advisories\u00a0- CVE-2025-0139 Autonomous Digital Experience Manager: Privilege Escalation (PE) Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-0140\">Palo Alto Networks Security Advisories\u00a0- CVE-2025-0140 GlobalProtect App: Non Admin User Can Disable the GlobalProtect App<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-0141\">Palo Alto Networks Security Advisories\u00a0- CVE-2025-0141 GlobalProtect App: Privilege Escalation (PE) Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-414","alert_type":396,"serial_number":"AV25-414","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6534,"title":"Juniper Networks security advisory (AV25-415)","uuid":"a7c958c9-c8d4-466b-9ed7-2436ff87b21f","banner":null,"lang":"en","date_modified":"2025-07-10","date_modified_ts":"2025-07-10T14:52:42Z","date_created":"2025-07-10T14:32:37Z","summary":null,"body":["<article data-history-node-id=\"6534\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-415\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-415<br \/><strong>Date: <\/strong>July 10, 2025<\/p>\n\n<p>On July 9 and 10, 2025, Juniper Networks published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sortCriteria=date%20descending&amp;f-sf_articletype=Security%20Advisories\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-415","alert_type":396,"serial_number":"AV25-415","subject":"juniper","moderation_state":"published","external_url":null},{"nid":6535,"title":"Drupal security advisory (AV25-416)","uuid":"0bba2189-f9af-404b-880d-9cf3bcf70525","banner":null,"lang":"en","date_modified":"2025-07-10","date_modified_ts":"2025-07-10T15:17:59Z","date_created":"2025-07-10T15:10:11Z","summary":null,"body":["<article data-history-node-id=\"6535\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-416\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-416<br \/><strong>Date: <\/strong>July 10, 2025<\/p>\n\n<p>On July 9, 2025, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cookies Addons\u00a0\u2013 versions prior to 1.2.4<\/li>\n\t<li>Mail_login 3.x\u00a0\u2013 versions prior to 3.2.0<\/li>\n\t<li>Mail_login 4.x\u00a0\u2013 versions prior to 4.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-087\">Cookies Addons\u00a0- Moderately critical\u00a0- Cross-site Scripting\u00a0- SA-CONTRIB-2025-087<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-088\">Mail Login\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-088<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-416","alert_type":396,"serial_number":"AV25-416","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6537,"title":"IBM security advisory (AV25-417)","uuid":"81a538a7-48a3-40f3-aaf6-0226a4bb9f1a","banner":null,"lang":"en","date_modified":"2025-07-14","date_modified_ts":"2025-07-14T14:42:26Z","date_created":"2025-07-14T14:40:10Z","summary":null,"body":["<article data-history-node-id=\"6537\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-417\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-417<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 14, 2025<\/p>\n\n<p>Between July 7 and 13, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-417","alert_type":396,"serial_number":"AV25-417","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6538,"title":"Dell security advisory (AV25-418)","uuid":"16d7e76b-a14d-4802-88ec-8c266311ff36","banner":null,"lang":"en","date_modified":"2025-07-14","date_modified_ts":"2025-07-14T14:48:23Z","date_created":"2025-07-14T14:44:13Z","summary":null,"body":["<article data-history-node-id=\"6538\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-418\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-418<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 14, 2025<\/p>\n\n<p>Between July 7 and 13, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerFlex Manager \u2013 version 4.6.2 and prior<\/li>\n\t<li>Dell UCC Edge \u2013 versions prior to 3.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000342158\/dsa-2025-279-security-update-for-dell-powerflex-manager-platform-pfmp-proprietary-code-vulnerability\">Dell Security Advisories \u2013 DSA-2025-279<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000343468\/dsa-2025-180-security-update-for-dell-ucc-edge-vulnerabilities\">Dell Security Advisories \u2013 DSA-2025-180<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-418","alert_type":396,"serial_number":"AV25-418","subject":"dell","moderation_state":"published","external_url":null},{"nid":6539,"title":"Ubuntu security advisory (AV25-419)","uuid":"15660658-1578-4580-b4c9-131b696bf6a2","banner":null,"lang":"en","date_modified":"2025-07-14","date_modified_ts":"2025-07-14T14:52:51Z","date_created":"2025-07-14T14:50:31Z","summary":null,"body":["<article data-history-node-id=\"6539\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-419\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-419<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 14, 2025<\/p>\n\n<p>Between July 7 and 13, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 24.10<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-419","alert_type":396,"serial_number":"AV25-419","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6540,"title":"[Control systems] CISA ICS security advisories (AV25\u2013420)","uuid":"6ef59597-873f-4e21-9fb3-ae7ae0d00daa","banner":null,"lang":"en","date_modified":"2025-07-14","date_modified_ts":"2025-07-14T15:00:39Z","date_created":"2025-07-14T14:54:31Z","summary":null,"body":["<article data-history-node-id=\"6540\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-420\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-420<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 14, 2025<\/p>\n\n<p>Between July 7 and 13, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Advantech iView \u2013 versions prior to 5.7.05 build 7057<\/li>\n\t<li>Delta Electronics DTM Soft \u2013 versions 1.6.0.0 and prior<\/li>\n\t<li>Emerson ValveLink DTM \u2013 versions prior to ValveLink 14.0<\/li>\n\t<li>Emerson ValveLink PRM \u2013 versions versions prior to ValveLink 14.0<\/li>\n\t<li>Emerson ValveLink SNAP-ON \u2013 versions prior to ValveLink 14.0<\/li>\n\t<li>Emerson ValveLink SOLO \u2013 versions prior to ValveLink 14.0<\/li>\n\t<li>End-of-Train and Head-of-Train remote linking protocol \u2013 all versions<\/li>\n\t<li>KUNBUS Revolution Pi OS Bullseye \u2013 version 02\/2024<\/li>\n\t<li>KUNBUS Revolution Pi OS Bullseye \u2013 version 04\/2024<\/li>\n\t<li>KUNBUS Revolution Pi OS Bullseye \u2013 version 06\/2023<\/li>\n\t<li>KUNBUS Revolution Pi OS Bullseye \u2013 version 07\/2023<\/li>\n\t<li>KUNBUS Revolution Pi OS Bullseye \u2013 version 09\/2023<\/li>\n\t<li>KUNBUS Revolution Pi Webstatus \u2013 versions 2.4.5 and prior<\/li>\n\t<li>Siemens SIMATIC CN 4100 \u2013 versions prior to V4.0<\/li>\n\t<li>Siemens SINEC NMS \u2013 version prior to V4.0<\/li>\n\t<li>Siemens SIPROTEC 5 \u2013 multiple versions and models<\/li>\n\t<li>Siemens Solid Edge SE2025 \u2013 version prior to V225.0 Update 5<\/li>\n\t<li>Siemens TIA Administrator \u2013 versions prior to V3.0.6<\/li>\n\t<li>Siemens TIA Project-Server V17 \u2013 all versions<\/li>\n\t<li>Siemens TIA Project-Server \u2013 versions prior to V2.1.1<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V17 \u2013 all versions<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V18 \u2013 all versions<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V19 \u2013 all versions<\/li>\n\t<li>Siemens Totally Integrated Automation Portal (TIA Portal) V20 \u2013 versions prior to V20 Update 3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-420","alert_type":398,"serial_number":"AV25-420","subject":"other","moderation_state":"published","external_url":null},{"nid":6541,"title":"Red Hat security advisory (AV25-421)","uuid":"4f04f56c-b75b-4633-afa4-c0a4a3ab5b26","banner":null,"lang":"en","date_modified":"2025-07-14","date_modified_ts":"2025-07-14T15:20:50Z","date_created":"2025-07-14T15:17:47Z","summary":null,"body":["<article data-history-node-id=\"6541\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-421\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-421<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 14, 2025<\/p>\n\n<p>Between July 7 and 13, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\u2003\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-421","alert_type":396,"serial_number":"AV25-421","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6542,"title":"VMware security advisory (AV25-422)","uuid":"a2143b4d-38e5-457f-a715-12a401c8fe7c","banner":null,"lang":"en","date_modified":"2025-07-14","date_modified_ts":"2025-07-14T18:02:03Z","date_created":"2025-07-14T17:57:19Z","summary":null,"body":["<article data-history-node-id=\"6542\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-422\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-422<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 14, 2025<\/p>\n\n<p>Between July 9 and 11, 2025, VMware published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu Greenplum \u2013 version 7.5.0<\/li>\n\t<li>VMware Tanzu GemFire \u2013 version 9.15.16<\/li>\n\t<li>VMware Tanzu Greenplum \u2013 version 6.30.0<\/li>\n\t<li>VMware Tanzu for Valkey \u2013 version 8.1.2<\/li>\n\t<li>VMware Tanzu for Postgres on Kubernetes \u2013 version 4.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35894\">Security Advisories \u2013 TNZ-2025-0031 <\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35929\">Security Advisories \u2013 TNZ-2025-0042 <\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35931\">Security Advisories \u2013 TNZ-2025-0043<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35934\">Security Advisories \u2013 TNZ-2025-0044<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35935\">Security Advisories \u2013 TNZ-2025-0045<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories \u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-422","alert_type":396,"serial_number":"AV25-422","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6544,"title":"Zyxel security advisory (AV25-423)","uuid":"4bbbc145-bdba-41e9-b27d-4c91e646c30f","banner":null,"lang":"en","date_modified":"2025-07-15","date_modified_ts":"2025-07-15T17:57:59Z","date_created":"2025-07-15T17:46:08Z","summary":null,"body":["<article data-history-node-id=\"6544\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av25-423\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-423<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 15, 2025<\/p>\n\n<p>On July 15, 2025, Zyxel published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>NWA50AX\u00a0\u2013 versions prior to 7.10(ABYW.1)<\/li>\n\t<li>NWA50AX PRO\u00a0\u2013 versions prior to 7.10(ACGE.2)<\/li>\n\t<li>NWA55AXE\u00a0\u2013 versions prior to 7.10(ABZL.1)<\/li>\n\t<li>NWA90AX\u00a0\u2013 versions prior to 7.10(ACCV.1)<\/li>\n\t<li>NWA90AX PRO\u00a0\u2013 versions prior to 7.10(ACGF.2)<\/li>\n\t<li>NWA110AX\u00a0\u2013 versions prior to 7.10(ABTG.1)<\/li>\n\t<li>NWA130BE\u00a0\u2013 versions prior to 7.10(ACIL.2)<\/li>\n\t<li>NWA210AX\u00a0\u2013 versions prior to 7.10(ABTD.1)<\/li>\n\t<li>NWA220AX-6E\u00a0\u2013 versions prior to 7.10(ACCO.1)<\/li>\n\t<li>NWA1123AC PRO\u00a0\u2013 versions prior to 6.28(ABHD.3)<\/li>\n\t<li>WAC500H\u00a0\u2013 versions prior to 6.70(ABWA.6)<\/li>\n\t<li>WAC5302D-Sv2\u00a0\u2013 versions prior to 6.25(ABVZ.9)<\/li>\n\t<li>WAC6103D-I\u00a0\u2013 versions prior to 6.28(AAXH.3)<\/li>\n\t<li>WAX300H\u00a0\u2013 versions prior to 7.10(ACHF.1)<\/li>\n\t<li>WAX510D\u00a0\u2013 versions prior to 7.10(ABTF.1)<\/li>\n\t<li>WAX610D\u00a0\u2013 versions prior to 7.10(ABTE.1)<\/li>\n\t<li>WAX620D-6E\u00a0\u2013 versions prior to 7.10(ACCN.1)<\/li>\n\t<li>WAX630S\u00a0\u2013 versions prior to 7.10(ABZD.1)<\/li>\n\t<li>WAX640S-6E\u00a0\u2013 versions prior to 7.10(ACCM.1)<\/li>\n\t<li>WAX650S\u00a0\u2013 versions prior to 7.10(ABRM.1)<\/li>\n\t<li>WAX655E\u00a0\u2013 versions prior to 7.10(ACDO.1)<\/li>\n\t<li>WBE530\u00a0\u2013 versions prior to 7.10(ACLE.2)<\/li>\n\t<li>WBE660S\u00a0\u2013 versions prior to 7.10(ACGG.2)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-path-traversal-vulnerability-in-aps-07-15-2025\">Zyxel security advisory for path traversal vulnerability in Aps (CVE-2025-6265)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av25-423","alert_type":396,"serial_number":"AV25-423","subject":"other","moderation_state":"published","external_url":null},{"nid":6545,"title":"VMware security advisory (AV25-424)","uuid":"0b32af16-5fd6-4473-afda-46148fb29b28","banner":null,"lang":"en","date_modified":"2025-07-15","date_modified_ts":"2025-07-15T20:27:44Z","date_created":"2025-07-15T20:15:42Z","summary":null,"body":["<article data-history-node-id=\"6545\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-424\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-424<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 15, 2025<\/p>\n\n<p>On July 15, 2025, VMware published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation\u00a0\u2013 version 9.0.0.0<\/li>\n\t<li>VMware vSphere Foundation\u00a0\u2013 version 9.0.0.0<\/li>\n\t<li>VMware ESXi\u00a0\u2013 version 8.0<\/li>\n\t<li>VMware ESXi\u00a0\u2013 version 8.0<\/li>\n\t<li>VMware ESXi\u00a0\u2013 version 7.0<\/li>\n\t<li>VMware Workstation\u00a0\u2013 version 17.x<\/li>\n\t<li>VMware Fusion\u00a0\u2013 version 13.x<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 version 5.x<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 version 4.5.x<\/li>\n\t<li>VMware Telco Cloud Platform\u00a0\u2013 versions 5.x and 4.x<\/li>\n\t<li>VMware Telco Cloud Platform\u00a0\u2013 versions 3.x and 2.x<\/li>\n\t<li>VMware Telco Cloud Infrastructure\u00a0\u2013 versions 3.x and 2.x<\/li>\n\t<li>VMware Tools [1]\u00a0\u2013 version 13.x.x<\/li>\n\t<li>VMware Tools [1]\u00a0\u2013 versions 12.x.x and 11.x.x<\/li>\n\t<li>VMware Tools\u00a0\u2013 versions 13.x.x, 12.x.x and 11.x.x<\/li>\n\t<li>VMware Tools\u00a0\u2013 versions 13.x.x, 12.x.x and 11.x.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35877\">VMSA-2025-0013: VMware ESXi, Workstation, Fusion, and Tools updates address multiple vulnerabilities (CVE-2025-41236, CVE-2025-41237, CVE-2025-41238, CVE-2025-41239)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-424","alert_type":396,"serial_number":"AV25-424","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6546,"title":"Oracle security advisory \u2013 July 2025 quarterly rollup (AV25-425)","uuid":"e79ffa1b-dd5a-4039-95d6-a56b98bd599f","banner":null,"lang":"en","date_modified":"2025-07-16","date_modified_ts":"2025-07-16T13:35:49Z","date_created":"2025-07-16T13:11:01Z","summary":null,"body":["<article data-history-node-id=\"6546\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-july-2025-quarterly-rollup-av25-425\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-425<br \/><strong>Date: <\/strong>July 16, 2025<\/p>\n\n<p>On July 15, 2025, Oracle published a security advisory to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2025.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 July 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-july-2025-quarterly-rollup-av25-425","alert_type":396,"serial_number":"AV25-425","subject":"other","moderation_state":"published","external_url":null},{"nid":6547,"title":"Google Chrome security advisory (AV25-426)","uuid":"d6de6065-3686-4c53-8a46-6b08c9f9e5e8","banner":null,"lang":"en","date_modified":"2025-07-16","date_modified_ts":"2025-07-16T14:15:04Z","date_created":"2025-07-16T14:09:22Z","summary":null,"body":["<article data-history-node-id=\"6547\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-426\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-426<br \/><strong>Date: <\/strong>July 16, 2025<\/p>\n\n<p>On July 15, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 138.0.7204.157\/.158 (Windows\/Mac) and 138.0.7204.157 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2025-6558 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/07\/stable-channel-update-for-desktop_15.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-426","alert_type":396,"serial_number":"AV25-426","subject":"other","moderation_state":"published","external_url":null},{"nid":6549,"title":"HPE security advisory (AV25-427)","uuid":"bc11c458-e951-443f-8a64-eeda5037be8a","banner":null,"lang":"en","date_modified":"2025-07-16","date_modified_ts":"2025-07-16T19:34:53Z","date_created":"2025-07-16T19:27:04Z","summary":null,"body":["<article data-history-node-id=\"6549\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-427\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-427<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2025<\/p>\n\n<p>On July 16, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.2.1<\/li>\n\t<li>HPE Cray XD670\u00a0\u2013 version prior to TPM Firmware v7.86<\/li>\n\t<li>HPE Cray XD675\u00a0\u2013 version prior to TPM Firmware v15.24<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04875en_us&amp;docLocale=en_US\">HPE Security Bulletin\u00a0- HPESBNW04875 rev.1\u00a0- HPE Telco Service Orchestrator Software, Authenticated SQL Injection<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04898en_us&amp;docLocale=en_US\">HPESBCR04898 rev.1\u00a0- Certain HPE Cray XD Servers Using Certain TPM 2.0, Local Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-427","alert_type":396,"serial_number":"AV25-427","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6550,"title":"Cisco security advisory (AV25-428)","uuid":"66ca1741-e7d6-429d-9807-aa8f86f817bf","banner":null,"lang":"en","date_modified":"2025-07-16","date_modified_ts":"2025-07-16T19:53:10Z","date_created":"2025-07-16T19:45:03Z","summary":null,"body":["<article data-history-node-id=\"6550\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-428\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-428<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 16, 2025<\/p>\n\n<p>On July 16, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Unified Intelligence Center\u00a0\u2013 versions 12.5, 12.6 and 15<\/li>\n\t<li>Cisco Unified CCX\u00a0\u2013 versions prior to 12.5(1)SU3<\/li>\n\t<li>Cisco Identity Services Engine (ISE)\u00a0\u2013 versions prior to 3.2, versions 3.3 and 3.4<\/li>\n\t<li>Cisco ISE Passive Identity Connector (ISE-PIC)\u00a0\u2013 versions prior to 3.2, versions 3.3 and 3.4<\/li>\n\t<li>Cisco Evolved Programmable Network Manager (EPNM)\u00a0\u2013 versions prior to 7.1, versions 8.0 and 8.1<\/li>\n\t<li>Cisco Prime Infrastructure\u00a0\u2013 versions prior to 3.9 and version 3.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cuis-file-upload-UhNEtStm\">Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-multi-3VpsXOxO\">Cisco Identity Services Engine Authenticated Remote Code Execution and Authorization Bypass Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-piepnm-bsi-25JJqsbb\">Cisco Prime Infrastructure and Evolved Programmable Network Manager Blind SQL Injection Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cuis-ssrf-JSuDjeV\">Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-428","alert_type":396,"serial_number":"AV25-428","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6551,"title":"HPE security advisory (AV25-429)","uuid":"f7aa1b5f-8b8a-420f-97ec-602d51a61a52","banner":null,"lang":"en","date_modified":"2025-07-17","date_modified_ts":"2025-07-17T13:18:25Z","date_created":"2025-07-17T13:09:10Z","summary":null,"body":["<article data-history-node-id=\"6551\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-429\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-429<br \/><strong>Date: <\/strong>July 17, 2025<\/p>\n\n<p>On July 16, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v4.2.4<\/li>\n\t<li>HPE AutoPass License Server\u00a0\u2013 versions prior to 9.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04900en_us&amp;docLocale=en_US\">HPESBNW04900 rev.1\u00a0- HPE Telco Service Orchestrator Software, Remote Denial of Service (DoS)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04877en_us&amp;docLocale=en_US\">HPESBGN04877 rev.1\u00a0- HPE AutoPass License Server (APLS), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-429","alert_type":396,"serial_number":"AV25-429","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6553,"title":"Microsoft Edge security advisory (AV25-430)","uuid":"64d9d245-94ae-4068-8d48-26ae3b38db66","banner":null,"lang":"en","date_modified":"2025-07-17","date_modified_ts":"2025-07-17T13:49:56Z","date_created":"2025-07-17T13:47:45Z","summary":null,"body":["<article data-history-node-id=\"6553\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-430\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-430<br \/><strong>Date: <\/strong>July 17, 2025<\/p>\n\n<p>On July 16, 2025, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 138.0.3351.95<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2025-6558 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-16-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-430","alert_type":396,"serial_number":"AV25-430","subject":"other","moderation_state":"published","external_url":null},{"nid":6555,"title":"Nodejs security advisory (AV25-431)","uuid":"924ce6e5-ea81-476c-b887-3237dda0ceb6","banner":null,"lang":"en","date_modified":"2025-07-18","date_modified_ts":"2025-07-18T14:54:45Z","date_created":"2025-07-18T14:47:28Z","summary":null,"body":["<article data-history-node-id=\"6555\" about=\"\/en\/alerts-advisories\/nodejs-security-advisory-av25-431\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-431<br \/><strong>Date: <\/strong>July 18, 2025<\/p>\n\n<p>On July 15, 2025, Nodejs published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Node.js 20\u00a0\u2013 versions prior to v20.19.4<\/li>\n\t<li>Node.js 22\u00a0\u2013 versions prior to v22.17.1<\/li>\n\t<li>Node.js 24\u00a0\u2013 versions prior to v24.4.1<\/li>\n<\/ul><p>Open-source reporting has indicated that proof-of-concept exploit code is available for the vulnerability CVE-2025-27210.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nodejs.org\/en\/blog\/vulnerability\/july-2025-security-releases\">Nodejs\u00a0- Tuesday, July 15, 2025 Security Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nodejs-security-advisory-av25-431","alert_type":396,"serial_number":"AV25-431","subject":"other","moderation_state":"published","external_url":null},{"nid":6557,"title":"AL25-009 - Vulnerability impacting Microsoft SharePoint Server (CVE-2025-53770, CVE-2025-49704, CVE-2025-53771, CVE-2025-49706 and CVE-2025-49712) \u2013 Update 4","uuid":"4fe888c5-7c7a-4cf8-b3a4-b6e75090775e","banner":null,"lang":"en","date_modified":"2025-08-19","date_modified_ts":"2025-08-19T18:51:02Z","date_created":"2025-07-20T12:33:32Z","summary":null,"body":["<article data-history-node-id=\"6557\" about=\"\/en\/alerts-advisories\/al25-009-vulnerability-impacting-microsoft-sharepoint-server-cve-2025-53770\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AL25-009<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 20, 2025<br \/><strong>Updated:<\/strong> August 19, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On July 19, Microsoft published a customer guidance for a critical SharePoint vulnerability CVE-2025-53770 that appears to be affecting all versions of on-premises SharePoint Server <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. SharePoint Online in Microsoft 365 is not impacted.<\/p>\n\n<p>CVE-2025-53770 involves the deserialization of untrusted data in on-premises Microsoft SharePoint Servers allowing an unauthorised attacker to execute code over a network.<\/p>\n\n<p>On July 22, 2025, Microsoft provided an update stating that CVE-2025-53770 is a patch bypass for CVE-2025-49704, and CVE-2025-53771 is a patch bypass for CVE-2025-49706 <sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<p>On August 12, 2025, Microsoft identified an additional vulnerability related to SharePoint CVE-2025-49712. This vulnerability also involves the deserialization of untrusted data in SharePoint Servers allowing an unauthorised attacker to execute code over the network <sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre is aware of exploitation happening in Canada.<\/p>\n\n<p><strong>On 21 July, 2025, Microsoft released emergency patches for the following versions of SharePoint:<\/strong><\/p>\n\n<ul><li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server 2016<\/li>\n<\/ul><h2>Potential indicators of compromise<\/h2>\n\n<p>The following indicators of compromise (IoCs) have been shared by the cyber security research community<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> as a starting point for compromise detection.<\/p>\n\n<ul><li>Verify the presence of the following file: C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\16\\TEMPLATE\\LAYOUTS\\spinstall0.aspx\n\t<ul><li>SHA256:92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514<\/li>\n\t<\/ul><\/li>\n\t<li>Monitor IIS logs for POST requests to \/_layouts\/15\/ToolPane.aspx?DisplayMode=Edit&amp;a=\/ToolPane.aspx with a HTTP referer of \/_layouts\/SignOut.aspx<\/li>\n\t<li>Verify network logs for scanning or exploitation attempts from IPs 107.191.58[.]76, 104.238.159[.]149, and 96.9.125[.]147, particularly since July 17, 2025.<\/li>\n\t<li>Check for presence of file hashes that may indicate compromise <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>:\n\t<ul><li>SHA256:4a02a72aedc3356d8cb38f01f0e0b9f26ddc5ccb7c0f04a561337cf24aa84030<\/li>\n\t\t<li>SHA256:b39c14becb62aeb55df7fd55c814afbb0d659687d947d917512fe67973100b70<\/li>\n\t\t<li>SHA256:fa3a74a6c015c801f5341c02be2cbdfb301c6ed60633d49fc0bc723617741af7<\/li>\n\t\t<li>SHA256:27c45b8ed7b8a7e5fff473b50c24028bd028a9fe8e25e5cea2bf5e676e531014<\/li>\n\t\t<li>SHA256:8d3d3f3a17d233bc8562765e61f7314ca7a08130ac0fb153ffd091612920b0f2<\/li>\n\t\t<li>SHA256:b336f936be13b3d01a8544ea3906193608022b40c28dd8f1f281e361c9b64e93<\/li>\n\t\t<li>SHA256:f917e0fd57784e40d9a41069f30b2b5cf83db29b52072c308ff030eaf1fcd764<\/li>\n\t<\/ul><\/li>\n<\/ul><h2>Suggested actions<\/h2>\n\n<p>If your SharePoint Server is accessible via the internet, it is recommended to assess potential security compromises and consider isolating the affected instance until patching and threat hunt exercises are complete.<br \/>\nIt is recommended to rotate any credentials and secrets used on impacted servers, including service accounts.<\/p>\n\n<p>Additionally, the Cyber Centre strongly recommends that organizations follow Microsoft customer guidance for mitigation advice:<\/p>\n\n<ul><li>Use or upgrade to supported versions of on-premises Microsoft SharePoint Server.<\/li>\n\t<li><strong>Apply the latest security updates from Microsoft<\/strong>.<\/li>\n\t<li>Enable Antimalware Scan Interface (AMSI) integration in SharePoint Server.<\/li>\n\t<li>integration was enabled by default in the September 2023 security update for SharePoint Server 2016\/2019 and the Version 23H2 feature update for SharePoint Server Subscription Edition <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/li>\n\t<li>Deploy a compatible AMSI-capable antivirus\/antimalware provider across all SharePoint servers.<\/li>\n\t<li><strong>Rotate SharePoint Server ASP.NET machine keys and restart IIS.<\/strong><\/li>\n<\/ul><p>Please note that the Cyber Center has identified evidence that AMSI may not consistently offer comprehensive protection against this form of exploitation, as threat actors frequently adapt their methods to evade detection.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/07\/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770\/\">Customer guidance for SharePoint vulnerability CVE-2025-53770\u00a0| MSRC Blog\u00a0| Microsoft Security Response Center<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available\/\">Microsoft SharePoint zero-day exploited in RCE attacks, no patch available<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2025-07-19-Microsoft-SharePoint-vulnerabilities-CVE-2025-49704-and-49706.txt\">PaloAltoNetworks\u00a0\/ Unit42-timely-threat-intel<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to <span>first<\/span> footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/x.com\/cyb3rops\/status\/1947032951486574672\">@cyb3rops<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-ca\/sharepoint\/security-for-sharepoint-server\/configure-amsi-integration\">Configure AMSI integration with SharePoint Server<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote <\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-av25-433\">Microsoft SharePoint security advisory (AV25-433)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote <\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/22\/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities\/#link={%22role%22:%22standard%22,%22href%22:%\">Microsoft Blog\u00a0- Disrupting active exploitation of on-premises SharePoint vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote <\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/07\/20\/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities\">CISA\u00a0- UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote <\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-49712\">Microsoft SharePoint Remote Code Execution Vulnerability\u00a0- CVE-2025-49712<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote <\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-009-vulnerability-impacting-microsoft-sharepoint-server-cve-2025-53770","alert_type":397,"serial_number":"AL25-009","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6558,"title":"CrushFTP security advisory (AV25-432)","uuid":"8b13f36c-f104-461c-9c95-a1e32e1f08d8","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T13:03:32Z","date_created":"2025-07-21T12:59:34Z","summary":null,"body":["<article data-history-node-id=\"6558\" about=\"\/en\/alerts-advisories\/crushftp-security-advisory-av25-432\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-432<br \/><strong>Date: <\/strong>July\u00a021, 2025<\/p>\n\n<p>On July\u00a018, 2025, CrushFTP published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>CrushFTP\u00a0\u2013 versions 10 prior to 10.8.5<\/li>\n\t<li>CrushFTP\u00a0\u2013 versions 11 prior to 11.3.4_23<\/li>\n<\/ul><p>CrushFTP is aware that an exploit for CVE-2025-54309 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, follow the recommended mitigation and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.crushftp.com\/crush11wiki\/Wiki.jsp?page=CompromiseJuly2025\">CrushFTP Update<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/crushftp-security-advisory-av25-432","alert_type":396,"serial_number":"AV25-432","subject":"other","moderation_state":"published","external_url":null},{"nid":6559,"title":"[Control systems] CISA ICS security advisories (AV25\u2013435)","uuid":"09a66cb1-6d43-4cb6-94b5-47b51313d428","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T17:08:42Z","date_created":"2025-07-21T14:47:20Z","summary":null,"body":["<article data-history-node-id=\"6559\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-435\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-435<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 21, 2025<\/p>\n\n<p>Between July 14 and 20, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB RMC-100 LITE\u00a0\u2013 versions 2106229-015 to 2106229-016<\/li>\n\t<li>ABB RMC-100\u00a0\u2013 versions 2105457-043 to 2105457-045<\/li>\n\t<li>Hitachi Asset Suite 9 series\u00a0\u2013 version 9.6.4.4<\/li>\n\t<li>Hitachi Asset Suite 9 series\u00a0\u2013 version 9.7<\/li>\n\t<li>Hitachi Asset Suite AnyWhere for Inventory (AWI) Android mobile app \u2013 versions 11.5 and prior<\/li>\n\t<li>LITEON IC48A\u00a0\u2013 firmware versions prior to 01.00.19r<\/li>\n\t<li>LITEON IC80A\u00a0\u2013 firmware versions prior to 01.01.12e<\/li>\n\t<li>Leviton AcquiSuite\u00a0\u2013 version A8810<\/li>\n\t<li>Leviton Energy Monitoring Hub\u00a0\u2013 version A8812<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-435","alert_type":398,"serial_number":"AV25-435","subject":"ics","moderation_state":"published","external_url":null},{"nid":6561,"title":"IBM security advisory (AV25-436)","uuid":"8fbfb97e-9c32-466f-a98a-a776dec8b0a0","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T17:10:09Z","date_created":"2025-07-21T15:27:49Z","summary":null,"body":["<article data-history-node-id=\"6561\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-436\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-436<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 21, 2025<\/p>\n\n<p>Between July 14 and 20, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-436","alert_type":396,"serial_number":"AV25-436","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6562,"title":"Dell security advisory (AV25-437)","uuid":"c1c0e30d-1e5c-4c7d-9ea0-4d403d35e3d2","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T17:29:03Z","date_created":"2025-07-21T15:30:33Z","summary":null,"body":["<article data-history-node-id=\"6562\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-437\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-437<br \/><strong>Date: <\/strong>July 21, 2025<\/p>\n\n<p>Between July 14 and 20, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell AMD-based PowerEdge Server\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell AppSync\u00a0\u2013 versions prior to 4.6.0.4<\/li>\n\t<li>Dell Connectrix B-Series\u00a0\u2013 versions 2.3.0 to 2.3.1a<\/li>\n\t<li>Dell Connectrix B-Series\u00a0\u2013 versions 9.1.0 to 9.2.2<\/li>\n\t<li>Dell Connectrix B-Series\u00a0\u2013 versions prior to 2.4.0<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 versions 19.8 to 19.12.1<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 versions prior to 19.12.0-2<\/li>\n\t<li>Dell EMC XC Core XC7525\u00a0\u2013 versions prior to 2.19.0<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions prior to 10.6.0.5<\/li>\n\t<li>Dell PowerEdge T40\u00a0\u2013 versions prior to 1.20.0<\/li>\n\t<li>Dell XC Core XC7625\u00a0\u2013 versions prior to 1.11.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-437","alert_type":396,"serial_number":"AV25-437","subject":"dell","moderation_state":"published","external_url":null},{"nid":6560,"title":"Microsoft SharePoint security advisory (AV25-433) \u2013 Update 1","uuid":"c5b1365b-442e-4c58-b10d-d08a415b7ca1","banner":null,"lang":"en","date_modified":"2025-07-22","date_modified_ts":"2025-07-22T12:32:13Z","date_created":"2025-07-21T15:31:16Z","summary":null,"body":["<article data-history-node-id=\"6560\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-av25-433\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-433<br \/><strong>Date: <\/strong>July\u00a021, 2025<br \/><strong>Updated: <\/strong>July\u00a022, 2025<\/p>\n\n<p>On July\u00a019, 2025, Microsoft published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Microsoft SharePoint Server Subscription Edition\u00a0\u2013 versions prior to KB5002768<\/li>\n\t<li>Microsoft SharePoint Server 2016\u00a0\u2013 versions prior to KB5002760<\/li>\n\t<li>Microsoft SharePoint Server 2019\u00a0\u2013 versions prior to KB5002754<\/li>\n<\/ul><p>Microsoft states that for SharePoint 2016 and 2019 \"Both the server and language pack updates should be installed\".<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/07\/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770\/\">Customer guidance for SharePoint vulnerability CVE-2025-53770<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/22\/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities\/\">Disrupting active exploitation of on-premises SharePoint vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-53770\">Microsoft SharePoint Server Remote Code Execution Vulnerability\u00a0- CVE-2025-53770<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-53771\">Microsoft SharePoint Server Spoofing Vulnerability\u00a0- CVE-2025-53771<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=108285\">Security Update for Microsoft SharePoint Server Subscription Edition (KB5002768)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=108288\">Security Update for Microsoft SharePoint Enterprise Server 2016 (KB5002760)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=108289\">Security Update for Microsoft SharePoint Enterprise Server 2016 Language Pack (KB5002759)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=108286\">Security Update for Microsoft SharePoint Server 2019 Core (KB5002754)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=108287\">Security Update for Microsoft SharePoint Server 2019 Language Pack (KB5002753)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-av25-433","alert_type":396,"serial_number":"AV25-433","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6563,"title":"Ubuntu security advisory (AV25-434)","uuid":"ff577b3f-d7aa-4483-bab3-d614a44183b3","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T15:54:24Z","date_created":"2025-07-21T15:49:56Z","summary":null,"body":["<article data-history-node-id=\"6563\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-434\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-434<br \/><strong>Date: <\/strong>July\u00a021, 2025<\/p>\n\n<p>Between July\u00a014 and 20, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-434","alert_type":396,"serial_number":"AV25-434","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6564,"title":"Red Hat security advisory (AV25-438)","uuid":"8d1c6e57-5c3c-4963-b558-66dfdbbf2a98","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T17:38:45Z","date_created":"2025-07-21T15:53:42Z","summary":null,"body":["<article data-history-node-id=\"6564\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-438\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-438<br \/><strong>Date: <\/strong>July 21, 2025<\/p>\n\n<p>Between July 14 and 20, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server for Power LE\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-438","alert_type":396,"serial_number":"AV25-438","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6565,"title":"Grafana security advisory (AV25-439)","uuid":"0ad7821e-1853-4d42-955c-0cf88de0d86c","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T18:32:37Z","date_created":"2025-07-21T18:19:50Z","summary":null,"body":["<article data-history-node-id=\"6565\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av25-439\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-439<br \/><strong>Date: <\/strong>July 21, 2025<\/p>\n\n<p>On July 17, 2025, Grafana published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Grafana\u00a0\u2013 version 12.0.x<\/li>\n\t<li>Grafana\u00a0\u2013 version 11.6.x<\/li>\n\t<li>Grafana\u00a0\u2013 version 11.5.x<\/li>\n\t<li>Grafana\u00a0\u2013 version 11.4.x<\/li>\n\t<li>Grafana\u00a0\u2013 version 11.3.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/blog\/2025\/07\/17\/grafana-security-release-medium-and-high-severity-fixes-for-cve-2025-6197-and-cve-2025-6023\/\">Grafana Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av25-439","alert_type":396,"serial_number":"AV25-439","subject":"other","moderation_state":"published","external_url":null},{"nid":6566,"title":"ISC BIND security advisory (AV25-440)","uuid":"0443c8e3-e520-4dc1-8784-91e529a75758","banner":null,"lang":"en","date_modified":"2025-07-21","date_modified_ts":"2025-07-21T19:05:07Z","date_created":"2025-07-21T18:55:13Z","summary":null,"body":["<article data-history-node-id=\"6566\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av25-440\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-440<br \/><strong>Date: <\/strong>July 21, 2025<\/p>\n\n<p>On July 16, 2025, <abbr title=\"Internet Systems Consortium\">ISC<\/abbr> published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li><abbr title=\"Internet Systems Consortium\">ISC<\/abbr> BIND 9\u00a0\u2013 versions 9.11.3-S1 to 9.16.50-S1<\/li>\n\t<li><abbr title=\"Internet Systems Consortium\">ISC<\/abbr> BIND 9\u00a0\u2013 versions 9.18.11-S1 to 9.18.37-S1<\/li>\n\t<li><abbr title=\"Internet Systems Consortium\">ISC<\/abbr> BIND 9\u00a0\u2013 versions 9.20.9-S1 to 9.20.10-S1<\/li>\n\t<li><abbr title=\"Internet Systems Consortium\">ISC<\/abbr> BIND 9\u00a0\u2013 versions 9.20.0 to 9.20.10<\/li>\n\t<li><abbr title=\"Internet Systems Consortium\">ISC<\/abbr> BIND 9\u00a0\u2013 versions 9.21.0 to 9.21.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2025-40776\"><abbr title=\"Internet Systems Consortium\">ISC<\/abbr> BIND security advisory\u00a0- CVE-2025-40776<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2025-40777\"><abbr title=\"Internet Systems Consortium\">ISC<\/abbr> BIND security advisory\u00a0- CVE-2025-40777<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av25-440","alert_type":396,"serial_number":"AV25-440","subject":"other","moderation_state":"published","external_url":null},{"nid":6567,"title":"[Control systems] ABB security advisory (AV25-441) ","uuid":"22fc0d67-156d-44b6-acd6-cef122dabf6c","banner":null,"lang":"en","date_modified":"2025-07-22","date_modified_ts":"2025-07-22T13:16:34Z","date_created":"2025-07-22T13:06:02Z","summary":null,"body":["<article data-history-node-id=\"6567\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-441\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-441<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 22, 2025<\/p>\n\n<p>On July 21, 2025, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ABB Switch Actuator 4 DU\u00a0\u2013 all versions<\/li>\n\t<li>ABB Switch actuator, door\/light 4 DU\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A4556&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch&amp;_gl=1*2jivkz*_gcl_au*NTAyODI0Njc3LjE3NTA3ODkyNjQ.*_ga*NzkzNjIwNDAuMTcwMTg5MDYxMw..*_ga_46ZFBRSZNM*czE3NTMxODE5NDIkbzYwMyRnMSR0MTc1MzE4MzA2NiRqNjAkbDAkaDA\">ABB Cyber Security Advisory\u00a0- Welcome 2 wire door opener actuator by default in compatibility mode\u00a0\u2013 CVE-2025-7705<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-441","alert_type":398,"serial_number":"AV25-441","subject":"abb","moderation_state":"published","external_url":null},{"nid":6568,"title":"Mozilla security advisory (AV25-442)","uuid":"69e48cbd-83a3-4a7f-b3dc-f39fea5b2de2","banner":null,"lang":"en","date_modified":"2025-07-22","date_modified_ts":"2025-07-22T14:32:21Z","date_created":"2025-07-22T14:01:17Z","summary":null,"body":["<article data-history-node-id=\"6568\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-442\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-442<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 22, 2025<\/p>\n\n<p>On July 22, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox for iOS\u00a0\u2013 versions prior to 141<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 140.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 128.13<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.26<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 141<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-60\/ \">Mozilla Foundation Security Advisory MFSA 2025-60<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-59\/ \">Mozilla Foundation Security Advisory MFSA 2025-59<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-58\/ \">Mozilla Foundation Security Advisory MFSA 2025-58<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-57\/ \">Mozilla Foundation Security Advisory MFSA 2025-57<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-56\/ \">Mozilla Foundation Security Advisory MFSA 2025-56<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-442","alert_type":396,"serial_number":"AV25-442","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6569,"title":"Sophos security advisory (AV25-443)","uuid":"1f283c13-1f53-4e92-a0f9-274eed9d9b5b","banner":null,"lang":"en","date_modified":"2025-07-22","date_modified_ts":"2025-07-22T15:37:36Z","date_created":"2025-07-22T15:26:23Z","summary":null,"body":["<article data-history-node-id=\"6569\" about=\"\/en\/alerts-advisories\/sophos-security-advisory-av25-443\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-443<br \/><strong>Date: <\/strong>July 22, 2025<\/p>\n\n<p>On July 21, 2025, Sophos published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Sophos Firewall\u00a0\u2013 version v21.0 GA (21.0.0) and prior<\/li>\n\t<li>Sophos Firewall\u00a0\u2013 version v21.5 GA (21.5.0) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sophos.com\/en-us\/security-advisories\/sophos-sa-20250721-sfos-rce\">Sophos Security Advisory - Resolved Multiple Vulnerabilities in Sophos Firewall (CVE-2025-6704, CVE-2025-7624, CVE-2025-7382, CVE-2024-13974, CVE-2024-13973)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.sophos.com\/en-us\/security-advisories\">Sophos Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sophos-security-advisory-av25-443","alert_type":396,"serial_number":"AV25-443","subject":"other","moderation_state":"published","external_url":null},{"nid":6571,"title":"Google Chrome security advisory (AV25-444)","uuid":"1f4174b6-4dcd-4ea1-9456-5ea153c093ba","banner":null,"lang":"en","date_modified":"2025-07-23","date_modified_ts":"2025-07-23T12:17:42Z","date_created":"2025-07-23T12:14:30Z","summary":null,"body":["<article data-history-node-id=\"6571\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-444\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-444<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 23, 2025<\/p>\n\n<p>On July 22, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to138.0.7204.168\/.169 (Windows\/Mac) and 138.0.7204.168 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/07\/stable-channel-update-for-desktop_22.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-444","alert_type":396,"serial_number":"AV25-444","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6572,"title":"GitLab security advisory (AV25-445)","uuid":"b96512f8-b4d4-476d-a735-edfc2da0568c","banner":null,"lang":"en","date_modified":"2025-07-23","date_modified_ts":"2025-07-23T12:22:32Z","date_created":"2025-07-23T12:19:23Z","summary":null,"body":["<article data-history-node-id=\"6572\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-445\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-445<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 23, 2025<\/p>\n\n<p>On July 23, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 18.2.1, 18.1.3 and 18.0.5<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 18.2.1, 18.1.3 and 18.0.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/07\/23\/patch-release-gitlab-18-2-1-released\/\">GitLab Patch Release: 18.2.1, 18.1.3, 18.0.5 <\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-445","alert_type":396,"serial_number":"AV25-445","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6573,"title":"HPE security advisory (AV25-446)","uuid":"4aac264c-f3fc-4dfa-90a2-ef60fa563005","banner":null,"lang":"en","date_modified":"2025-07-23","date_modified_ts":"2025-07-23T13:28:56Z","date_created":"2025-07-23T13:25:43Z","summary":null,"body":["<article data-history-node-id=\"6573\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-446\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-446<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 23, 2025<\/p>\n\n<p>On July 23, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX 11i Secure Shell Software\u00a0\u2013 versions prior to A.09.30.010<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04903en_us&amp;docLocale=en_US\">HPESBUX04903 rev.1 - HP-UX Secure Shell daemon (sshd), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-446","alert_type":396,"serial_number":"AV25-446","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6574,"title":"SonicWall security advisory (AV25-447)","uuid":"1c1166ab-a88d-4815-98fb-d85ff2c9596e","banner":null,"lang":"en","date_modified":"2025-07-23","date_modified_ts":"2025-07-23T14:38:54Z","date_created":"2025-07-23T14:36:12Z","summary":null,"body":["<article data-history-node-id=\"6574\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-447\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-447<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 23, 2025<\/p>\n\n<p>On July 23, 2025, SonicWall published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SMA 100 Series (SMA 210, 410, 500v) \u2013 version 10.2.1.15-81sv and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0014\">SonicWall Security Advisory - SNWLID-2025-0014<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-447","alert_type":396,"serial_number":"AV25-447","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":6575,"title":"JavaScript Form-Data security advisory (AV25-448)","uuid":"f564aace-fb45-4d60-8e86-8def33454138","banner":null,"lang":"en","date_modified":"2025-07-23","date_modified_ts":"2025-07-23T16:57:01Z","date_created":"2025-07-23T16:53:10Z","summary":null,"body":["<article data-history-node-id=\"6575\" about=\"\/en\/alerts-advisories\/javascript-form-data-security-advisory-av25-448\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-448<br \/><strong>Date: <\/strong>July\u00a023, 2025<\/p>\n\n<p>On July\u00a022, 2025, JavaScript published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Form-data library\u00a0\u2013 versions prior to 2.5.4<\/li>\n\t<li>Form-data library\u00a0\u2013 versions 3.0.0 to 3.0.3<\/li>\n\t<li>Form-data library\u00a0\u2013 versions 4.0.0 to 4.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/form-data\/form-data\/security\/advisories\/GHSA-fjxv-7rqg-78g4\">JavaScript form-data library Security Advisory <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/javascript-form-data-security-advisory-av25-448","alert_type":396,"serial_number":"AV25-448","subject":"other","moderation_state":"published","external_url":null},{"nid":6576,"title":"Mitel security advisory (AV25-449)","uuid":"877e153b-d3a5-4561-858b-c5ed8c1a6a56","banner":null,"lang":"en","date_modified":"2025-07-23","date_modified_ts":"2025-07-23T17:43:18Z","date_created":"2025-07-23T17:40:22Z","summary":null,"body":["<article data-history-node-id=\"6576\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av25-449\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-449<br \/><strong>Date: <\/strong>July\u00a023, 2025<\/p>\n\n<p>On July\u00a023, 2025, Mitel published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>MiVoice MX-ONE\u00a0\u2013 versions 3 (7.3.0.0.50) to 7.8 SP1 (7.8.1.0.14)<\/li>\n\t<li>MiCollab\u00a0\u2013 versions 10.0 (10.0.0.26) to 10.0 SP1 FP1 (10.0.1.101) and version 9.8 SP3 (9.8.3.1) and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2025-0009\">Mitel Security Advisory\u00a0- MISA-2025-0009<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2025-0008\">Mitel Security Advisory\u00a0- MISA-2025-0008<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av25-449","alert_type":396,"serial_number":"AV25-449","subject":"mitel","moderation_state":"published","external_url":null},{"nid":6589,"title":"[Control systems] ABB security advisory (AV25-450)","uuid":"68b4d566-0808-4d82-bc4e-34682fe0fb39","banner":null,"lang":"en","date_modified":"2025-07-24","date_modified_ts":"2025-07-24T15:22:34Z","date_created":"2025-07-24T15:02:53Z","summary":null,"body":["<article data-history-node-id=\"6589\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-450\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-450<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 24, 2025<\/p>\n\n<p>On July 23, 2025, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>AC500 V2 PLCs\u00a0\u2013 firmware versions 2.5.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011432&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">AC500 V2 Buffer overread on Modbus protocol\u00a0- CVE ID: CVE-2025-7745<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-450","alert_type":398,"serial_number":"AV25-450","subject":"abb","moderation_state":"published","external_url":null},{"nid":6590,"title":"VMware security advisory (AV25-451)","uuid":"0c1ec1ab-1d4e-497c-ab99-1810e2119a24","banner":null,"lang":"en","date_modified":"2025-07-24","date_modified_ts":"2025-07-24T17:16:13Z","date_created":"2025-07-24T17:03:31Z","summary":null,"body":["<article data-history-node-id=\"6590\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-451\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-451<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 24, 2025<\/p>\n\n<p>On July 24, 2025, VMware published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Tanzu Platform for Cloud Foundry\u00a0\u2013 version 4.0.38+LTS-T<\/li>\n\t<li>Tanzu Platform for Cloud Foundry\u00a0\u2013 version 6.0.18+LTS-T<\/li>\n\t<li>Tanzu Platform for Cloud Foundry\u00a0\u2013 version 10.0.8<\/li>\n\t<li>Tanzu Platform for Cloud Foundry\u00a0\u2013 version 10.2.1+LTS-T<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35966\">Product Release Advisory\u00a0- Tanzu Platform for Cloud Foundry 4.0.38+LTS-T<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35967\">Product Release Advisory\u00a0- Tanzu Platform for Cloud Foundry 6.0.18+LTS-T <\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35968\">Product Release Advisory\u00a0- Tanzu Platform for Cloud Foundry 10.0.8<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35969\">Product Release Advisory\u00a0- Tanzu Platform for Cloud Foundry 10.2.1+LTS-T<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory \">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-451","alert_type":396,"serial_number":"AV25-451","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6591,"title":"HPE security advisory (AV25-452)","uuid":"da2314ea-e665-4749-b01f-d4db517c639a","banner":null,"lang":"en","date_modified":"2025-07-24","date_modified_ts":"2025-07-24T19:03:18Z","date_created":"2025-07-24T18:55:17Z","summary":null,"body":["<article data-history-node-id=\"6591\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-452\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-452<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 24, 2025<\/p>\n\n<p>On July 24, 2025, HPE published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.0.2<\/li>\n\t<li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v4.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04901en_us&amp;docLocale=en_US\">HPESBNW04901 rev.1\u00a0- HPE Telco Service Orchestrator, Remote Denial of Service (DoS) Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04902en_us&amp;docLocale=en_US\">HPESBNW04902 rev.1\u00a0- HPE Telco Service Orchestrator, Exposure of Sensitive Information to an Unauthorized Actor Vulnerability <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-452","alert_type":396,"serial_number":"AV25-452","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6614,"title":"IBM security advisory (AV25-453)","uuid":"463b2739-9dd6-4182-a5f8-4e1c6a2cbcd1","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T13:43:51Z","date_created":"2025-07-28T13:31:51Z","summary":null,"body":["<article data-history-node-id=\"6614\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-453\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-453<br \/><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>Between July 21 and 27, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-453","alert_type":396,"serial_number":"AV25-453","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6615,"title":"Dell security advisory (AV25-454)","uuid":"94080b29-29bb-4e45-b551-0d01ac081ba2","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T14:31:53Z","date_created":"2025-07-28T13:57:53Z","summary":null,"body":["<article data-history-node-id=\"6615\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-454\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-454<br \/><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>Between July 21 and 27, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen4T\u00a0\u2013 version 19.12<\/li>\n\t<li>Dell Avamar Data Store Gen4T\u00a0\u2013 versions 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4<\/li>\n\t<li>Dell Avamar Data Store Gen5A\u00a0\u2013 version 19.12<\/li>\n\t<li>Dell Avamar Data Store Gen5A\u00a0\u2013 versions 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4<\/li>\n\t<li>Dell Avamar Virtual Edition for VMware ESXi and vSphere\u00a0\u2013 version 19.12<\/li>\n\t<li>Dell Avamar Virtual Edition for VMware ESXi and vSphere\u00a0\u2013 versions 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4<\/li>\n\t<li>Dell Avamar Virtual Edition for VMware vSphere only\u00a0\u2013 version 19.12<\/li>\n\t<li>Dell Avamar Virtual Edition for VMware vSphere only\u00a0\u2013 versions 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4<\/li>\n\t<li>Dell CyberSense\u00a0\u2013 versions prior to 8.12<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 version 19.7.x to 19.12<\/li>\n\t<li>Dell Intel E810 Adapters and Intel E823 LOM\u00a0\u2013 versions prior to 24.0.0<\/li>\n\t<li>Dell Intel I350 and X550 Adapters\u00a0- versions prior to 24.0.0<\/li>\n\t<li>Dell Intel X710, XXV710, and XL710 Adapters\u00a0- versions prior to 24.0.0<\/li>\n\t<li>Dell Networking OS10 \u2013 versions prior to 10.5.4.16<\/li>\n\t<li>Dell PowerProtect DP Series (Integrated Data Protection Appliance (IDPA) Appliance \u2013 versions prior to 2.7.8<\/li>\n\t<li>Dell SmartFabric Storage Software \u2013 version prior to 1.4.4<\/li>\n\t<li>Dell ThinOS 10 for Multiple Google Chrome \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-454","alert_type":396,"serial_number":"AV25-454","subject":"dell","moderation_state":"published","external_url":null},{"nid":6616,"title":"Red Hat security advisory (AV25-456)","uuid":"ddeeb7af-17aa-4e83-b41c-54cb9c47b0ba","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T15:23:55Z","date_created":"2025-07-28T14:50:41Z","summary":null,"body":["<article data-history-node-id=\"6616\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-456\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-456<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>Between July 21 and 27, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-456","alert_type":396,"serial_number":"AV25-456","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6617,"title":"Ubuntu security advisory (AV25-455)","uuid":"47a600ca-7556-4407-8bc0-f0f003f4be68","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T15:04:32Z","date_created":"2025-07-28T14:54:35Z","summary":null,"body":["<article data-history-node-id=\"6617\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-455\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-455<br \/><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>Between July 21 and 27, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-455","alert_type":396,"serial_number":"AV25-455","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6618,"title":"Atlassian security advisory (AV25-457)","uuid":"6518ebfc-7cde-4484-a019-7dd32c2fd993","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T15:27:18Z","date_created":"2025-07-28T15:07:47Z","summary":null,"body":["<article data-history-node-id=\"6618\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-457\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-457<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date\u00a0: <\/strong>July 28, 2025<\/p>\n\n<p>On July 15, 2025, Atlassian published a security advisory to address vulnerabilities in the following products\u00a0:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-july-15-2025-1590658642.html\">Security Bulletin\u00a0- July 15 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-457","alert_type":396,"serial_number":"AV25-457","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6619,"title":"Microsoft Edge security advisory (AV25-458)","uuid":"cc6343a0-c661-45d2-8b4f-ebd99395a260","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T15:45:59Z","date_created":"2025-07-28T15:30:59Z","summary":null,"body":["<article data-history-node-id=\"6619\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-458\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-458<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>On July 25, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 138.0.3351.109<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-25-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-458","alert_type":396,"serial_number":"AV25-458","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6620,"title":"[Control systems] CISA ICS security advisories (AV25-459)","uuid":"f8154cbc-8bba-4b2e-9db4-bc41a571e7f7","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T16:06:27Z","date_created":"2025-07-28T15:50:15Z","summary":null,"body":["<article data-history-node-id=\"6620\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-459\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-459<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>Between July 21 and 27, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>DuraComm SPM-500 DP-10iN-100-MU\u00a0\u2013 version 4.10 and prior<\/li>\n\t<li>Honeywell Experion PKS\u00a0\u2013 versions prior to R520.2 TCU9 Hot Fix 1<\/li>\n\t<li>Honeywell Experion PKS\u00a0\u2013 versions prior to R530 TCU3 Hot Fix 1<\/li>\n\t<li>LG Innotek Camera Model LNV5110R\u00a0\u2013 all versions<\/li>\n\t<li>Lantronix Provisioning Manager\u00a0\u2013 version 7.10.2 and prior<\/li>\n\t<li>Mitsubishi Electric CNC Series\u00a0\u2013 all versions<\/li>\n\t<li>Network Thermostat X-Series WiFi Thermostats\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Schneider Electric EcoStruxure IT Data Center Expert\u00a0\u2013 version v8.3 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 version 2023<\/li>\n\t<li>Schneider Electric EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 version 2023 R2<\/li>\n\t<li>Schneider Electric EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 version 2024<\/li>\n\t<li>Schneider Electric EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 version 2024 R2<\/li>\n\t<li>Schneider Electric EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module\u00a0\u2013 version 2022<\/li>\n\t<li>Schneider Electric EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module\u00a0\u2013 version 2024<\/li>\n\t<li>Schneider Electric EcoStruxure Power Operation (EPO)\u00a0\u2013 version 2022 CU6 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure Power Operation (EPO)\u00a0\u2013 version 2024 CU1 and prior<\/li>\n\t<li>Schneider Electric System Monitor application in Harmony Industrial PC series\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric System Monitor application in Pro-face Industrial PC series\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-459","alert_type":398,"serial_number":"AV25\u2013459","subject":"ics","moderation_state":"published","external_url":null},{"nid":6621,"title":"GitHub security advisory (AV25-460)","uuid":"80f86a57-f085-4d78-b66b-99d10c6e6529","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T17:17:54Z","date_created":"2025-07-28T16:57:46Z","summary":null,"body":["<article data-history-node-id=\"6621\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-460\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-460<br \/><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>On July 25, 2025, GitHub published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>tj-actions\/branch-names\u00a0\u2013 versions prior to 8.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/tj-actions\/branch-names\/security\/advisories\/GHSA-gq52-6phf-x2r6\">Command Injection Vulnerability\u00a0- GHSA-gq52-6phf-x2r6<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-460","alert_type":396,"serial_number":"AV25-460","subject":"other","moderation_state":"published","external_url":null},{"nid":6623,"title":"BeyondTrust security advisory (AV25-461)","uuid":"bebc3aea-649d-46d0-9817-99ddbc72d6c1","banner":null,"lang":"en","date_modified":"2025-07-28","date_modified_ts":"2025-07-28T19:45:08Z","date_created":"2025-07-28T19:37:19Z","summary":null,"body":["<article data-history-node-id=\"6623\" about=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av25-461\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-461<br \/><strong>Date: <\/strong>July 28, 2025<\/p>\n\n<p>On July 28, 2025, BeyondTrust published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Privilege Management for Windows\u00a0\u2013 versions prior to 25.4.270.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt25-05\">BeyondTrust Security Advisory\u00a0- Advisory ID: BT25-05<\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt25-06\">BeyondTrust Security Advisory\u00a0- Advisory ID: BT25-06<\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\">BeyondTrust Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/beyondtrust-security-advisory-av25-461","alert_type":396,"serial_number":"AV25-461","subject":"other","moderation_state":"published","external_url":null},{"nid":6624,"title":"SolarWinds security advisory (AV25-462)","uuid":"f19994e4-e04f-4c96-9595-090d6ca03167","banner":null,"lang":"en","date_modified":"2025-07-29","date_modified_ts":"2025-07-29T12:22:11Z","date_created":"2025-07-29T12:15:55Z","summary":null,"body":["<article data-history-node-id=\"6624\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-462\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-462<br \/><strong>Date: <\/strong>July 29, 2025<\/p>\n\n<p>On July 24 and 29, 2025, SolarWinds published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SolarWinds Observability Self-Hosted\u00a0\u2013 version SWOSH 2025.2 and prior<\/li>\n\t<li>SolarWinds Web Help Desk\u00a0\u2013 version 12.8.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2025-26397\">SolarWinds Observability Self-Hosted Deserialization of Untrusted Data Local Privilege Escalation Vulnerability (CVE-2025-26397)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2025-26400\">SolarWinds Web Help Desk XML External Entity Injection (XXE) Vulnerability (CVE-2025-26400)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-462","alert_type":396,"serial_number":"AV25-462","subject":"other","moderation_state":"published","external_url":null},{"nid":6629,"title":"VMware security advisory (AV25-463)","uuid":"be50afec-f699-4b9a-a517-01056a7523d8","banner":null,"lang":"en","date_modified":"2025-07-29","date_modified_ts":"2025-07-29T17:28:16Z","date_created":"2025-07-29T17:18:46Z","summary":null,"body":["<article data-history-node-id=\"6629\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-463\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-463<br \/><strong>Date: <\/strong>July 29, 2025<\/p>\n\n<p>On July 29, 2025, VMware published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation\u00a0\u2013 version 9.0.0.0<\/li>\n\t<li>VMware vSphere Foundation\u00a0\u2013 version 9.0.0.0<\/li>\n\t<li>VMware vCenter\u00a0\u2013 version 8.0<\/li>\n\t<li>VMware vCenter\u00a0\u2013 version 7.0<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 version 5.x<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 version 4.5.x<\/li>\n\t<li>VMware Telco Cloud Platform\u00a0\u2013 versions 5.x and 2.x<\/li>\n\t<li>VMware Telco Cloud Infrastructure\u00a0\u2013 version 2.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/35964\">Product Release Advisory\u00a0- VMSA-2025-0014: VMware vCenter updates address a denial-of-service vulnerability (CVE-2025-41241)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-463","alert_type":396,"serial_number":"AV25-463","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6631,"title":"Apple security advisory (AV25-464) \u2013 Update 1","uuid":"7c68d519-2cc4-4f93-bebb-ece48c1c19fc","banner":null,"lang":"en","date_modified":"2026-03-20","date_modified_ts":"2026-03-20T17:32:56Z","date_created":"2025-07-29T18:38:26Z","summary":null,"body":["<article data-history-node-id=\"6631\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-464\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-464<br \/><strong>Date: <\/strong>July 29, 2025<br \/><strong>Updated: <\/strong>March 20, 2026<\/p>\n\n<p>On July 29, 2025, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.6<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 17.7.9<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.6<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.7.7<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.7.7<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 18.6<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 2.6<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 11.6<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On March 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-31277 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-31277\">CISA KEV: CVE-2025-31277<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-464","alert_type":396,"serial_number":"AV25-464","subject":"apple","moderation_state":"published","external_url":null},{"nid":6632,"title":"Google Chrome security advisory (AV25-465)","uuid":"88050629-f052-4290-bc94-69d0838f51f1","banner":null,"lang":"en","date_modified":"2025-07-30","date_modified_ts":"2025-07-30T11:47:40Z","date_created":"2025-07-30T11:44:05Z","summary":null,"body":["<article data-history-node-id=\"6632\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-465\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-465<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 30, 2025<\/p>\n\n<p>On July 29, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 138.0.7204.183\/.184 (Windows\/Mac) and 138.0.7204.183 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/07\/stable-channel-update-for-desktop_29.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-465","alert_type":396,"serial_number":"AV25-465","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6642,"title":"SonicWall security advisory (AV25-466)","uuid":"0a177996-e145-4b5e-a99e-772ba5372638","banner":null,"lang":"en","date_modified":"2025-07-30","date_modified_ts":"2025-07-30T12:46:55Z","date_created":"2025-07-30T12:36:39Z","summary":null,"body":["<article data-history-node-id=\"6642\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-466\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-466<br \/><strong>Date: <\/strong>July 30, 2025<\/p>\n\n<p>On July 29, 2025, SonicWall published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Gen7 hardware Firewalls\u00a0\u2013 version 7.2.0-7015 and prior<\/li>\n\t<li>Gen7 virtual Firewalls (NSv)\u00a0\u2013 version 7.2.0-7015 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0013\">SonicWall Security Advisory\u00a0- SNWLID-2025-0013<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-466","alert_type":396,"serial_number":"AV25-466","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":6647,"title":"Palo Alto Networks security advisory (AV25-467)","uuid":"51c256be-9a08-4a66-854b-4d09c86074c2","banner":null,"lang":"en","date_modified":"2025-07-30","date_modified_ts":"2025-07-30T14:20:14Z","date_created":"2025-07-30T14:09:14Z","summary":null,"body":["<article data-history-node-id=\"6647\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-467\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-467<br \/><strong>Date: <\/strong>July 30, 2025<\/p>\n\n<p>On July 28, 2025, Palo Alto Networks published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>GlobalProtect App 6.2 Linux\u00a0\u2013 versions prior to 6.2.9<\/li>\n\t<li>GlobalProtect App 6.1 Linux\u00a0\u2013 all versions<\/li>\n\t<li>GlobalProtect App 6.0 Linux\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-2179\">Palo Alto Networks Security Advisories\u00a0- CVE-2025-2179 GlobalProtect App: Non-Admin User Can Disable the GlobalProtect App<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-467","alert_type":396,"serial_number":"AV25-467","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6648,"title":"HPE security advisory (AV25-468)","uuid":"eadec3a0-a6be-4b2c-b2f6-8d8d5d5bf66c","banner":null,"lang":"en","date_modified":"2025-07-30","date_modified_ts":"2025-07-30T18:41:02Z","date_created":"2025-07-30T18:35:29Z","summary":null,"body":["<article data-history-node-id=\"6648\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-468\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-468<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 30, 2025<\/p>\n\n<p>On July 30, 2025, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Telco Intelligent Assurance\u00a0\u2013 versions prior to FAS and PDO 4.2.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04905en_us&amp;docLocale=en_US\">HPESBNW04905 rev. 1\u00a0- HPE Telco Intelligent Assurance, CVE-2025-48738<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-468","alert_type":396,"serial_number":"AV25-468","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6649,"title":"Drupal security advisory (AV25-469) ","uuid":"b6db340f-f7cf-4890-aee6-604b881db9d1","banner":null,"lang":"en","date_modified":"2025-07-30","date_modified_ts":"2025-07-30T18:55:38Z","date_created":"2025-07-30T18:46:23Z","summary":null,"body":["<article data-history-node-id=\"6649\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-469\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-469<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 30, 2025<\/p>\n\n<p>On July 30, 2025, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Config Pages\u00a0\u2013 versions prior to 2.18.0<\/li>\n\t<li>GoogleTag Manager\u00a0\u2013 versions prior to 1.10.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-093\">Config Pages\u00a0- Moderately critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-093<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-094\">GoogleTag Manager\u00a0- Moderately critical\u00a0- Cross-site scripting\u00a0- SA-CONTRIB-2025-094<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-469","alert_type":396,"serial_number":"AV25-469","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6650,"title":"Splunk security advisory (AV25-470)","uuid":"de1e341f-2e2e-4954-b0ba-dd94008509e4","banner":null,"lang":"en","date_modified":"2025-07-30","date_modified_ts":"2025-07-30T19:47:50Z","date_created":"2025-07-30T19:37:35Z","summary":null,"body":["<article data-history-node-id=\"6650\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-470\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-470<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 30, 2025<\/p>\n\n<p>On July 30, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk User Behavior Analytics (UBA)\u00a0\u2013 versions prior to 5.4.3<\/li>\n\t<li>Enterprise Security\u00a0\u2013 versions prior to 7.3.4<\/li>\n\t<li>Enterprise Security\u00a0\u2013 versions prior to 8.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0713\">Third-Party Package Updates in Splunk User Behavior Analytics (UBA)\u00a0- July 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0714\">Third-Party Package Updates in Enterprise Security 7.3.4\u00a0- July 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0715\">Third-Party Package Updates in Enterprise Security 8.1.0\u00a0- July 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\">Splunk Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-470","alert_type":396,"serial_number":"AV25-470","subject":"other","moderation_state":"published","external_url":null},{"nid":6651,"title":"Node-SAML security advisory (AV25-471)","uuid":"0dc499ee-3ba3-4797-858e-324a2cd993cb","banner":null,"lang":"en","date_modified":"2025-07-30","date_modified_ts":"2025-07-30T19:59:58Z","date_created":"2025-07-30T19:53:12Z","summary":null,"body":["<article data-history-node-id=\"6651\" about=\"\/en\/alerts-advisories\/node-saml-security-advisory-av25-471\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-471<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 30, 2025<\/p>\n\n<p>On July 28, 2025, Node-SAML published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Node-SAML\u00a0\u2013 version 5.0.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/node-saml\/node-saml\/security\/advisories\/GHSA-4mxg-3p6v-xgq3\">Node-SAML SAML Signature Verification Vulnerability<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/node-saml-security-advisory-av25-471","alert_type":396,"serial_number":"AV25-471","subject":"other","moderation_state":"published","external_url":null},{"nid":6652,"title":"GitHub security advisory AV25-472","uuid":"212d958c-f4d5-456a-9600-e84055bf5ad7","banner":null,"lang":"en","date_modified":"2025-07-31","date_modified_ts":"2025-07-31T14:02:52Z","date_created":"2025-07-31T13:55:46Z","summary":null,"body":["<article data-history-node-id=\"6652\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-472\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-472<br \/><strong>Date: <\/strong>July 31, 2025<\/p>\n\n<p>On July 29, 2025, GitHub published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions prior to 3.17.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes#3.17.4\">GitHub Release Notes #3.17.4<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-472","alert_type":396,"serial_number":"AV25-472","subject":"other","moderation_state":"published","external_url":null},{"nid":6654,"title":"Apple security advisory (AV25-473)","uuid":"92a7180c-cb08-4bcd-aafe-371352a2297c","banner":null,"lang":"en","date_modified":"2025-07-31","date_modified_ts":"2025-07-31T15:50:06Z","date_created":"2025-07-31T15:46:40Z","summary":null,"body":["<article data-history-node-id=\"6654\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-473\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-473<br \/><strong>Date: <\/strong>July 31, 2025<\/p>\n\n<p>On July 30, 2025, Apple published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari\u00a0\u2013 versions prior to 18.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided Web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/124152\">Apple security update\u00a0- Safari 18.6<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-473","alert_type":396,"serial_number":"AV25-473","subject":"apple","moderation_state":"published","external_url":null},{"nid":6655,"title":"SUSE Linux security advisory (AV25-474)","uuid":"2c879b13-0093-4f37-a20b-fe0b7d720f35","banner":null,"lang":"en","date_modified":"2025-07-31","date_modified_ts":"2025-07-31T18:05:08Z","date_created":"2025-07-31T17:55:17Z","summary":null,"body":["<article data-history-node-id=\"6655\" about=\"\/en\/alerts-advisories\/suse-linux-security-advisory-av25-474\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-474<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>July 31, 2025<\/p>\n\n<p>On July 8, 2025, SUSE Linux published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>SUSE Linux Enterprise Micro 5.5<\/li>\n\t<li>SUSE Linux Enterprise Server 15 SP6<\/li>\n\t<li>SUSE Manager Proxy 5.0 Extension<\/li>\n\t<li>SUSE Manager Retail Branch Server 5.0 Extension<\/li>\n\t<li>SUSE Manager Server 5.0 Extensions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.suse.com\/support\/update\/announcement\/2025\/suse-su-202502478-1\/\">Security update for Multi-Linux Manager 5.0: Server, Proxy and Retail Server<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/suse-linux-security-advisory-av25-474","alert_type":396,"serial_number":"AV25-474","subject":"other","moderation_state":"published","external_url":null},{"nid":6656,"title":"HPE security advisory (AV25-475)","uuid":"b71f2cf3-7b32-460e-8dee-bf544d7dbc40","banner":null,"lang":"en","date_modified":"2025-08-01","date_modified_ts":"2025-08-01T13:07:33Z","date_created":"2025-08-01T13:01:01Z","summary":null,"body":["<article data-history-node-id=\"6656\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-475\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-475<br \/><strong>Date: <\/strong>August 1, 2025<\/p>\n\n<p>On July 30, 2025, HPE published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Service Activator\u00a0\u2013 versions prior to 10.3.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04887en_us&amp;docLocale=en_US\">HPESBNW04887 rev.1\u00a0- HPE Telco Service Activator, Protection Mechanism Failure<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-475","alert_type":396,"serial_number":"AV25-475","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6657,"title":"Microsoft Edge security advisory (AV25-476)","uuid":"946c9599-a632-4cf5-a141-5dda8a38df5e","banner":null,"lang":"en","date_modified":"2025-08-01","date_modified_ts":"2025-08-01T13:28:36Z","date_created":"2025-08-01T13:07:05Z","summary":null,"body":["<article data-history-node-id=\"6657\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-476\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-476<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 1, 2025<\/p>\n\n<p>On July 31, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 138.0.3351.121<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-31-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-476","alert_type":396,"serial_number":"AV25-476","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6659,"title":"HPE security advisory (AV25-477)","uuid":"e2d746a6-bb3e-418b-bb92-0db3f11ee531","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T12:16:44Z","date_created":"2025-08-05T12:03:40Z","summary":null,"body":["<article data-history-node-id=\"6659\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-477\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-477<br \/><strong>Date: <\/strong>August 5, 2025<\/p>\n\n<p>On August 1, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Private Cloud AI\u00a0\u2013 versions prior to v1.5<\/li>\n\t<li>HPE Telco IP Mediation\u00a0\u2013 versions prior to 8.5.1-0B<\/li>\n\t<li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.3.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04904en_us&amp;docLocale=en_US\">HPESBGN04904 rev.1\u00a0- HPE Private Cloud AI, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04906en_us&amp;docLocale=en_US\">HPESBNW04906 rev.1\u00a0- HPE Telco IP Mediation, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04907en_us&amp;docLocale=en_US\">HPESBNW04907 rev.1\u00a0- HPE Telco Service Orchestrator Software, Remote Command Execution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-477","alert_type":396,"serial_number":"AV25-477","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6660,"title":"IBM security advisory (AV25-478)","uuid":"ad4f5ade-c1c0-4f5f-964c-6d35deb404e2","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T13:12:17Z","date_created":"2025-08-05T13:07:23Z","summary":null,"body":["<article data-history-node-id=\"6660\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-478\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-478<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 5, 2025<\/p>\n\n<p>Between July 28 and August 3, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-478","alert_type":396,"serial_number":"AV25-478","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6661,"title":"Dell security advisory (AV25-479)","uuid":"fc228133-2253-4bb4-ac3b-ede71989f9e9","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T15:52:20Z","date_created":"2025-08-05T15:46:32Z","summary":null,"body":["<article data-history-node-id=\"6661\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-479\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-479<br \/><strong>Date: <\/strong>August\u00a05, 2025<\/p>\n\n<p>Between July\u00a028 and August\u00a03, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.02.05.00<\/li>\n\t<li>Dell Avamar Data Store Gen4T, Gen5A\u00a0\u2013 versions 19.10, 19.10-SP1, 19.12, 19.7, 19.8 and 19.9<\/li>\n\t<li>Dell Avamar Network Data Management Protocol\u00a0(NDMP) Accelerator\u00a0\u2013 versions 19.10, 19.10-SP1, 19.12, 19.7, 19.8 and 19.9<\/li>\n\t<li>Dell Avamar VMware Image Backup Proxy\u00a0\u2013 versions 19.10, 19.10-SP1, 19.12, 19.7, 19.8 and 19.9<\/li>\n\t<li>Dell Avamar Virtual Edition\u00a0\u2013 versions 19.10, 19.10-SP1, 19.12, 19.7, 19.8 and 19.9<\/li>\n\t<li>Dell Networker Virtual Edition\u00a0(NVE)\u00a0 versions 19.5, 19.6, 19.7, 19.8, 19.9, 19.10, 19.11 and 19.12<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions prior to 10.5.5.15<\/li>\n\t<li>Dell PowerProtect DP Series Appliance\u00a0(IDPA)\u00a0\u2013 versions prior to 2.7.8<\/li>\n\t<li>Dell PowerStore 1000X, 3000X, 5000X, 7000X, 9000X\u00a0\u2013 versions prior to ESXi70U3w-24784741<\/li>\n\t<li>Dell Unity Operating Environment\u00a0(OE)\u00a0\u2013 versions prior to 5.5.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-479","alert_type":396,"serial_number":"AV25-479","subject":"dell","moderation_state":"published","external_url":null},{"nid":6662,"title":"Ubuntu security advisory (AV25-480)","uuid":"7bfd8575-feba-48cf-adc7-0b3235bcb519","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T16:10:37Z","date_created":"2025-08-05T16:07:46Z","summary":null,"body":["<article data-history-node-id=\"6662\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-480\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-480<br \/><strong>Date: <\/strong>August\u00a05, 2025<\/p>\n\n<p>Between July\u00a028 and August\u00a03, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-480","alert_type":396,"serial_number":"AV25-480","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6663,"title":"[Control systems] CISA ICS security advisories (AV25-481)","uuid":"b325485e-efdf-4e5c-a707-95bc8d57121c","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T18:54:56Z","date_created":"2025-08-05T18:50:16Z","summary":null,"body":["<article data-history-node-id=\"6663\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-481\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-481<br \/><strong>Date: <\/strong>August\u00a05, 2025<\/p>\n\n<p>Between July\u00a028 and August\u00a03, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics DTN Soft\u00a0\u2013 versions 2.1.0 and prior<\/li>\n\t<li>G\u00fcralp FMUS Series Seismic Monitoring Devices\u00a0\u2013 all versions<\/li>\n\t<li>National Instruments LabVIEW\u00a0\u2013 version 2025 Q1 and prior<\/li>\n\t<li>Rockwell Automation Endpoint Protection Service with Rockwell Automation Proxy &amp; VMware only\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation Engineered and Integrated Solutions with VMware\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation Industrial Data Center\u00a0(IDC) with VMware\u00a0\u2013 Generations 1\u00a0\u2013 4<\/li>\n\t<li>Rockwell Automation Threat Detection Managed Services\u00a0(TDMS) with VMware\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation VersaVirtual Appliance\u00a0(VVA) with VMware\u00a0\u2013 Series A &amp; B<\/li>\n\t<li>Samsung HVAC DMS\u00a0\u2013 versions 2.0.0 to 2.3.13.0, versions 2.5.0.17 to 2.6.14.0 and versions 2.7.0.15 to 2.9.3.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-481","alert_type":398,"serial_number":"AV25-481","subject":"ics","moderation_state":"published","external_url":null},{"nid":6664,"title":"Android security advisory \u2013 August 2025 monthly rollup (AV25-482)","uuid":"22db98b7-327a-40b2-9bdf-96ba65feadb8","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T19:20:01Z","date_created":"2025-08-05T19:12:15Z","summary":null,"body":["<article data-history-node-id=\"6664\" about=\"\/en\/alerts-advisories\/android-security-advisory-august-2025-monthly-rollup-av25-482\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-482<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 5, 2025<\/p>\n\n<p>On August 4, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-08-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-august-2025-monthly-rollup-av25-482","alert_type":396,"serial_number":"AV25-482","subject":"android","moderation_state":"published","external_url":null},{"nid":6667,"title":"SSL VPN vulnerability impacting Gen 7 SonicWall Firewalls (CVE-2024-40766) \u2013 Update 1","uuid":"e5204f03-3a21-48ac-88f4-33d392b63a7a","banner":null,"lang":"en","date_modified":"2025-08-07","date_modified_ts":"2025-08-07T14:58:21Z","date_created":"2025-08-05T19:13:42Z","summary":null,"body":["<article data-history-node-id=\"6667\" about=\"\/en\/alerts-advisories\/potential-ssl-vpn-zero-day-vulnerability-impacting-gen-7-sonicwall-firewalls\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:\u00a0<\/strong>AL25-010<br \/><strong>Date:\u00a0<\/strong>August\u00a05, 2025<br \/><strong>Updated:\u00a0<\/strong>August 7, 2025<\/p>\n\n<section><h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers of notified organizations.<\/p>\n<\/section><section><h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n<\/section><section><h2>Details<\/h2>\n\n<p>Open-source reporting has indicated that a possible Zero-Day vulnerability in SonicWall <abbr title=\"Secure Sockets Layer virtual private network\">SSL VPN<\/abbr> is actively being exploited to bypass <abbr title=\"multi-factor authentication\">MFA<\/abbr> and deploy ransomware (e.g.,\u00a0Akira <span class=\"nowrap\">Ransomware)<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/span><\/p>\n\n<h3>Update 1<\/h3>\n\n<p>The vendor has reported that the recent <abbr title=\"Secure Sockets Layer virtual private network\">SSL VPN<\/abbr> activity is not connected to a zero-day vulnerability but instead correlated to CVE-2024-40766<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. This vulnerability relates to migrations from Gen 6 to Gen 7 <span class=\"nowrap\">firewalls<sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/span><\/p>\n<\/section><section><h2>Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs)<\/h2>\n\n<p>For more details on <abbr title=\"open-source intelligence\">OSINT<\/abbr> conveyed Tactics, Techniques and Procedures (TTPs) and Indicators of Compromise (IOCs), please refer to reports referenced <span class=\"nowrap\">below<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2b-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/span><\/p>\n<\/section><section><h2>Suggested actions<\/h2>\n\n<ul><li>Update firmware to version 7.3.0<\/li>\n\t<li>Reset all local user account passwords for any accounts with <abbr title=\"Secure Sockets Layer virtual private network\">SSL VPN<\/abbr> access, especially if they were carried over during migration from Gen 6 to Gen 7<\/li>\n\t<li>Continue applying the previously recommended best practices:\n\t<ul><li>Enable Botnet Protection and Geo-IP Filtering<\/li>\n\t\t<li>Remove unused or inactive user accounts<\/li>\n\t\t<li>Enforce <abbr title=\"multi-factor authentication\">MFA<\/abbr> and strong password policies<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Assess the installations of SonicWall Firewalls<\/li>\n\t<li>Apply updates to SonicWall Firewalls without delay<\/li>\n\t<li>Monitor the vendor security KB for updated <span class=\"nowrap\">guidance<sup id=\"fn3b-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/span><\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> with an emphasis on the following strategies:<\/p>\n\n<ul><li>Consolidate, monitor, and defend internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n\t<li>Implement application allow lists<\/li>\n<\/ul><p>Review the Cyber Centre's Playbook on Ransomware (ITSM.00.099) and apply recommended security <span class=\"nowrap\">controls<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/span><\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<\/section><aside class=\"wb-fnote\" role=\"note\"><h2 id=\"fn\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.huntress.com\/blog\/exploitation-of-sonicwall-vpn\">Huntress Threat Advisory: Active Exploitation of SonicWall <abbr title=\"virtual private networks\">VPNs<\/abbr><\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote <\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/arcticwolf.com\/resources\/blog\/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn\/\">Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall <abbr title=\"Secure Sockets Layer\">SSL<\/abbr> <abbr title=\"virtual private network\">VPN<\/abbr><\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote <\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.sonicwall.com\/support\/notices\/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity\/250804095336430\">Gen 7 SonicWall Firewalls\u00a0\u2013 <abbr title=\"Secure Sockets Layer virtual private network\">SSLVPN<\/abbr> Recent Threat Activity<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote <\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote <\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/ransomware-playbook-itsm00099\">Ransomware playbook (ITSM.00.099)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote <\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/potential-ssl-vpn-zero-day-vulnerability-impacting-gen-7-sonicwall-firewalls","alert_type":397,"serial_number":"AL25-010","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":6665,"title":"Red Hat security advisory (AV25-483)","uuid":"b9b2d1af-bde1-4afc-aec9-f52a77f0e437","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T19:36:49Z","date_created":"2025-08-05T19:29:08Z","summary":null,"body":["<article data-history-node-id=\"6665\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-483\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-483<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 5, 2025<\/p>\n\n<p>Between July 28 and August 3, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-483","alert_type":396,"serial_number":"AV25-483","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6666,"title":"Google Chrome security advisory (AV25-484)","uuid":"14fa70e0-091d-4515-89a7-3f58b547b2e3","banner":null,"lang":"en","date_modified":"2025-08-05","date_modified_ts":"2025-08-05T19:49:50Z","date_created":"2025-08-05T19:41:35Z","summary":null,"body":["<article data-history-node-id=\"6666\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-484\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-484<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 5, 2025<\/p>\n\n<p>On August 5, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 139.0.7258.66\/67 (Windows\/Mac) and 139.0.7258.66 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/08\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-484","alert_type":396,"serial_number":"AV25-484","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6668,"title":"Adobe security advisory (AV25-485) \u2013 Update 1","uuid":"92efaed4-6fa7-4054-b59d-341bd765da53","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T16:07:40Z","date_created":"2025-08-06T12:01:41Z","summary":null,"body":["<article data-history-node-id=\"6668\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-485\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-485<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2025<br \/><strong>Updated: <\/strong>October 20, 2025<\/p>\n\n<p>On August 5, 2025, Adobe published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Adobe Experience Manager (AEM) Forms on JEE \u2013 version 6.5.23.0 and prior<\/li>\n<\/ul><p>Adobe is aware that an exploit for CVE-2025-54253 and CVE-2025-54254 exists in the wild.<\/p>\n\n<h5>Update 1<\/h5>\n\n<p>On October 15, 2025, CISA released a statement indicating that CVE-2025-54253 is being actively exploited in the wild and added it to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/10\/15\/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Adds One Known Exploited Vulnerability to Catalog<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/aem-forms\/apsb25-82.html \">Security updates available for Adobe Experience Manager Forms\u00a0|\u00a0APSB25-82<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-485","alert_type":396,"serial_number":"AV25-485","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6669,"title":"HPE security advisory (AV25-486)","uuid":"090fc52a-155a-4668-859d-eb08e1d69c3a","banner":null,"lang":"en","date_modified":"2025-08-06","date_modified_ts":"2025-08-06T13:45:07Z","date_created":"2025-08-06T13:41:02Z","summary":null,"body":["<article data-history-node-id=\"6669\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-486\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-486<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 6, 2025<\/p>\n\n<p>On August 5, 2025, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Brocade SANnav Management Portal \u2013 version prior to 2.4.0a<\/li>\n\t<li>Brocade Fabric OS \u2013 versions 9.1.0 to 9.2.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04890en_us&amp;docLocale=en_US\">HPESBST04890 rev.2 - HPE SANnav Management Portal and Fabric OS, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-486","alert_type":396,"serial_number":"AV25-486","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6670,"title":"Trend Micro security advisory (AV25-487)","uuid":"e581483e-092b-465d-a297-35601e3f8ccf","banner":null,"lang":"en","date_modified":"2025-08-06","date_modified_ts":"2025-08-06T15:42:29Z","date_created":"2025-08-06T15:39:41Z","summary":null,"body":["<article data-history-node-id=\"6670\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory-av25-487\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-487<br \/><strong>Date: <\/strong>August\u00a06, 2025<\/p>\n\n<p>On August\u00a05, 2025, Trend Micro published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Trend Micro Apex One\u00a0(on-prem) Management Server\u00a0\u2013 version 14039 and prior<\/li>\n<\/ul><p>\n  Trend Micro has indicated that some of these vulnerabilities have been actively exploited.\n<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/success.trendmicro.com\/en-US\/solution\/KA-0020652\">Trend Micro Apex One\u2122\u00a0(On-Premise) Management Console Command Injection RCE Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/success.trendmicro.com\/en-US\/vulnerability-response\/\">Trend Micro Business Success Vulnerability Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory-av25-487","alert_type":396,"serial_number":"AV25-487","subject":"other","moderation_state":"published","external_url":null},{"nid":6671,"title":"Cisco security advisory (AV25-488)","uuid":"b40dbac2-fb8a-4f50-bda7-28ec39dfb4a9","banner":null,"lang":"en","date_modified":"2025-08-06","date_modified_ts":"2025-08-06T17:33:52Z","date_created":"2025-08-06T17:31:38Z","summary":null,"body":["<article data-history-node-id=\"6671\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-488\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-488<br \/><strong>Date: <\/strong>August\u00a06, 2025<\/p>\n\n<p>On August\u00a06, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Identity Services Engine\u00a0(ISE)\u00a0\u2013 versions prior to 3.0, versions 3.1, 3.2 and 3.3<\/li>\n\t<li>Cisco ISE Passive Identity Connector\u00a0(ISE-PIC)\u00a0\u2013 versions prior to 3.0, versions 3.1, 3.2 and 3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise_xss_acc_cont-YsR4uT4U\">Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities <\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-488","alert_type":396,"serial_number":"AV25-488","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6672,"title":"Splunk security advisory (AV25-489)","uuid":"3df8b1c4-9ecd-403e-be8c-d580e09a963d","banner":null,"lang":"en","date_modified":"2025-08-06","date_modified_ts":"2025-08-06T17:43:40Z","date_created":"2025-08-06T17:40:53Z","summary":null,"body":["<article data-history-node-id=\"6672\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-489\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-489<br \/><strong>Date: <\/strong>August\u00a06, 2025<\/p>\n\n<p>On August\u00a06, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk AppDynamics On-Premises Enterprise Console\u00a0\u2013 versions prior to 25.4.0<\/li>\n\t<li>Splunk AppDynamics Cluster Agent\u00a0\u2013 versions prior to 25.6.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0801\">Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console\u00a0- August 2025 <\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-0802\">Third-Party Package Updates in Splunk AppDynamics Cluster Agent\u00a0- August 2025 <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-489","alert_type":396,"serial_number":"AV25-489","subject":"other","moderation_state":"published","external_url":null},{"nid":6673,"title":"Microsoft Exchange security advisory (AV25-490)","uuid":"54a9aa21-b696-4507-99eb-74991876566c","banner":null,"lang":"en","date_modified":"2025-08-07","date_modified_ts":"2025-08-07T12:58:19Z","date_created":"2025-08-07T12:55:31Z","summary":null,"body":["<article data-history-node-id=\"6673\" about=\"\/en\/alerts-advisories\/microsoft-exchange-security-advisory-av25-490\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-490<br \/><strong>Date: <\/strong>August\u00a07, 2025<\/p>\n\n<p>On August\u00a06, 2025, Microsoft published a security update to address a vulnerability in the following products:<\/p>\n\n<ul><li>Exchange Server 2016 CU23\u00a0\u2013 (KB5050674)<\/li>\n\t<li>Exchange Server 2019 CU14\u00a0\u2013 (KB5050673)<\/li>\n\t<li>Exchange Server 2019 CU15\u00a0\u2013 (KB5050672)<\/li>\n\t<li>Exchange Server Subscription Edition RTM\u00a0\u2013 (KB5047155)<\/li>\n<\/ul><p>Exploitation of this vulnerability could allow an attacker to cause an elevation of privilege.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-53786\">Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/08\/06\/microsoft-releases-guidance-high-severity-vulnerability-cve-2025-53786-hybrid-exchange-deployments\">Microsoft Releases Guidance on High-Severity Vulnerability (CVE-2025-53786) in Hybrid Exchange Deployments<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-exchange-security-advisory-av25-490","alert_type":396,"serial_number":"AV25-490","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6674,"title":"Juniper Networks security advisory (AV25-491)","uuid":"4117ef63-f67b-42d2-b003-80087c45c74a","banner":null,"lang":"en","date_modified":"2025-08-08","date_modified_ts":"2025-08-08T12:58:53Z","date_created":"2025-08-08T12:53:56Z","summary":null,"body":["<article data-history-node-id=\"6674\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-491\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-491<br \/><strong>Date: <\/strong>August 8, 2025<\/p>\n\n<p>On August 7, 2025, Juniper Networks published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Juniper Secure Analytics (JSA)\u00a0\u2013 versions 7.5.0 to versions prior to 7.5.0 UP12 IF03<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-U12-IF03?language=en_US\">On Demand: JSA Series: Multiple vulnerabilities resolved in Juniper Secure Analytics in 7.5.0 UP12 IF03<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.juniper.net\/InfoCenter\/index?page=content&amp;channel=SECURITY_ADVISORIES\">Juniper Network Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-491","alert_type":396,"serial_number":"AV25-491","subject":"juniper","moderation_state":"published","external_url":null},{"nid":6675,"title":"Microsoft Edge security advisory (AV25-492)","uuid":"b49884ac-ecd7-4821-9c4d-1e9e01a3a736","banner":null,"lang":"en","date_modified":"2025-08-08","date_modified_ts":"2025-08-08T13:16:08Z","date_created":"2025-08-08T13:12:05Z","summary":null,"body":["<article data-history-node-id=\"6675\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-492\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-492<br \/><strong>Date: <\/strong>August 8, 2025<\/p>\n\n<p>On August 7, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 139.0.3405.86<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-7-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-492","alert_type":396,"serial_number":"AV25-492","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6677,"title":"IBM security advisory (AV25-493)","uuid":"8b845c1c-33b6-4e9a-9583-90c0336fa7f0","banner":null,"lang":"en","date_modified":"2025-08-11","date_modified_ts":"2025-08-11T13:16:28Z","date_created":"2025-08-11T13:11:47Z","summary":null,"body":["<article data-history-node-id=\"6677\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-493\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-493<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 11, 2025<\/p>\n\n<p>Between August 4 and 10, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-493","alert_type":396,"serial_number":"AV25-493","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6678,"title":"Dell security advisory (AV25-494)","uuid":"d9a8837d-05a5-46eb-ad9c-1ccfb5b54a16","banner":null,"lang":"en","date_modified":"2025-08-11","date_modified_ts":"2025-08-11T13:49:02Z","date_created":"2025-08-11T13:29:06Z","summary":null,"body":["<article data-history-node-id=\"6678\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-494\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-494<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 11, 2025<\/p>\n\n<p>Between August 4 and 10, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Networking OS10\u00a0\u2013 versions prior to 10.5.6.10<\/li>\n\t<li>Dell SupportAssist OS Recovery\u00a0\u2013 versions prior to 5.5.14.0<\/li>\n\t<li>PowerScale OneFS\u00a0\u2013 version 9.11.0.0<\/li>\n\t<li>PowerScale OneFS\u00a0\u2013 versions 9.5.0.0 to 9.10.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000353631\/dsa-2025-283-security-update-for-dell-networking-os10-vulnerabilities\">DSA-2025-283: Security Update for Dell Networking OS10 Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000353093\/dsa-2025-315\">DSA-2025-315: Security Update for Dell SupportAssist OS Recovery for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000353080\/dsa-2025-272-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities\">DSA-2025-272: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-494","alert_type":396,"serial_number":"AV25-494","subject":"dell","moderation_state":"published","external_url":null},{"nid":6679,"title":"Ubuntu security advisory (AV25-495)","uuid":"701b4ba8-6397-4647-9ebe-2bbbba6a9e0d","banner":null,"lang":"en","date_modified":"2025-08-11","date_modified_ts":"2025-08-11T14:13:18Z","date_created":"2025-08-11T13:56:40Z","summary":null,"body":["<article data-history-node-id=\"6679\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-495\" class=\"cccs-threats is-unpublished full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-495<br \/><strong>Date: <\/strong>August 11, 2025<\/p>\n\n<p>Between August 4 and 10, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-495","alert_type":396,"serial_number":"AV25-495","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6680,"title":"Red Hat security advisory (AV25-496)","uuid":"530facdb-2483-4d7c-9d7e-05459b592c37","banner":null,"lang":"en","date_modified":"2025-08-11","date_modified_ts":"2025-08-11T14:22:54Z","date_created":"2025-08-11T14:13:34Z","summary":null,"body":["<article data-history-node-id=\"6680\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-496\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-496<br \/><strong>Date: <\/strong>August 11, 2025<\/p>\n\n<p>Between August 4 and 10, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-496","alert_type":396,"serial_number":"AV25-496","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6681,"title":"[Control systems] CISA ICS security advisories (AV25\u2013497)","uuid":"070c8e72-e7fc-4d0b-bccf-7bd232f2a5c8","banner":null,"lang":"en","date_modified":"2025-08-11","date_modified_ts":"2025-08-11T15:22:16Z","date_created":"2025-08-11T15:09:08Z","summary":null,"body":["<article data-history-node-id=\"6681\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-497\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25\u2013497<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 11, 2025<\/p>\n\n<p>Between August 4 and 10, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Burk Technology ARC Solo\u00a0\u2013 versions prior to v1.0.62<\/li>\n\t<li>Delta Electronics DIAView\u00a0\u2013 versions 4.2.0.0<\/li>\n\t<li>Dreame Technology Dreamehome Android app\u00a0\u2013 versions 2.1.8.8 and prior<\/li>\n\t<li>Dreame Technology Dreamehome iOS app\u00a0\u2013 versions 2.3.4 and prior<\/li>\n\t<li>Dreame Technology MOVAhome iOS app\u00a0\u2013 versions 1.2.3 and prior<\/li>\n\t<li>EG4 Electronics EG4 Inverters\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Johnson Controls FX80, FX90\u00a0\u2013 versions FX 14.10.10 and FX 14.14.1<\/li>\n\t<li>Mitsubishi Electric GENESIS\u00a0\u2013 version 11.00<\/li>\n\t<li>Mitsubishi Electric GENESIS64\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric MC Works64\u00a0\u2013 all versions<\/li>\n\t<li>Packet Power EG and EMX\u00a0\u2013 versions prior to 4.1.0<\/li>\n\t<li>Rockwell Automation Arena\u00a0\u2013 version 16.20.09 and prior<\/li>\n\t<li>Tigo Energy Cloud Connect Advanced\u00a0\u2013 version 4.0.1 and prior<\/li>\n\t<li>Yealink IP Phonesv\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Yealink RPS (Redirect and Provisioning Service)\u00a0\u2013 all builds prior to 05-26-2025<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-497","alert_type":398,"serial_number":"AV25\u2013497","subject":"ics","moderation_state":"published","external_url":null},{"nid":6683,"title":"[Control systems] ABB security advisory (AV25-498)","uuid":"78866f31-6b5e-427a-9649-39f653d135f8","banner":null,"lang":"en","date_modified":"2025-08-11","date_modified_ts":"2025-08-11T19:38:05Z","date_created":"2025-08-11T19:33:51Z","summary":null,"body":["<article data-history-node-id=\"6683\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-498\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-498<br \/><strong>Date: <\/strong>August 11, 2025<\/p>\n\n<p>On August 11, 2025, ABB published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ASPECT-Enterprise\u00a0\u2013 firmware versions prior to 3.08.04-s01<\/li>\n\t<li>NEXUS Series\u00a0\u2013 firmware versions prior to 3.08.04-s01<\/li>\n\t<li>MATRIX Series\u00a0\u2013 firmware versions prior to 3.08.04-s01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A4462&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">ELSB\/BLBA ASPECT advisory several CVEs (CSAF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-498","alert_type":398,"serial_number":"AV25-498","subject":"abb","moderation_state":"published","external_url":null},{"nid":6684,"title":"WinRAR security advisory (AV25-499)","uuid":"220f904c-0b5d-4c8a-92ca-bd761798d5b3","banner":null,"lang":"en","date_modified":"2025-08-11","date_modified_ts":"2025-08-11T20:00:37Z","date_created":"2025-08-11T19:46:11Z","summary":null,"body":["<article data-history-node-id=\"6684\" about=\"\/en\/alerts-advisories\/winrar-security-advisory-av25-499\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-499<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 11, 2025<\/p>\n\n<p>On July 30, 2025, WinRAR published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>WinRAR\u00a0\u2013 versions prior to 7.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.win-rar.com\/singlenewsview.html?&amp;L=0&amp;tx_ttnews%5Btt_news%5D=283&amp;cHash=a64b4a8f662d3639dec8d65f47bc93c5\">WinRAR 7.13 Final released<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/winrar-security-advisory-av25-499","alert_type":396,"serial_number":"AV25-499","subject":"other","moderation_state":"published","external_url":null},{"nid":6686,"title":"SAP security advisory \u2013 August 2025 monthly rollup (AV25-500)","uuid":"68e5650f-e11b-4cec-9669-66c7b0c1fedf","banner":null,"lang":"en","date_modified":"2025-08-12","date_modified_ts":"2025-08-12T13:52:17Z","date_created":"2025-08-12T13:35:44Z","summary":null,"body":["<article data-history-node-id=\"6686\" about=\"\/en\/alerts-advisories\/sap-security-advisory-august-2025-monthly-rollup-av25-500\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-500<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 12, 2025<\/p>\n\n<p>On August 12, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP S\/4HANA (Private Cloud or On-Premise)\u00a0\u2013 versions S4CORE 102, 103, 104, 105, 106, 107 and 108<\/li>\n\t<li>SAP Landscape Transformation (Analysis Platform)\u00a0\u2013 versions DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731 and 2011_1_752, 2020<\/li>\n\t<li>SAP Business One (SLD)\u00a0\u2013 versions B1_ON_HANA 10.0 and SAP-M-BO 10.0<\/li>\n\t<li>SAP S\/4HANA (Bank Communication Management)\u00a0\u2013 versions SAP_APPL 606, SAP_FIN 617, 618, 720, 730, S4CORE 102, 103, 104, 105, 106, 107 and 108<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SAP NetWeaver ABAP Platform\u00a0\u2013 versions S4CRM 100, 200, 204, 205, 206, S4CEXT 107, 108, 109, BBPCRM 713 and 714<\/li>\n\t<li>SAP NetWeaver Enterprise Portal (OBN component)\u00a0\u2013 version EP-RUNTIME 7.50<\/li>\n\t<li>ABAP Platform\u00a0\u2013 versions SAP_BASIS 758, SAP_BASIS 816 and SAP_BASIS 916<\/li>\n\t<li>SAP GUI for Windows\u00a0\u2013 version BC-FES-GUI 8.00<\/li>\n\t<li>SAP S\/4HANA (Supplier invoice)\u00a0\u2013 versions S4CORE 102, 103, 104, 105, 106, 107, 108 and 109<\/li>\n\t<li>SAP NetWeaver\u00a0\u2013 versions SAP_ABA 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H and 75I<\/li>\n\t<li>SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Manager)\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.14, 9.15 and 9.16<\/li>\n\t<li>SAP Cloud Connector\u00a0\u2013 version SAP_CLOUD_CONNECTOR 2.0<\/li>\n\t<li>SAP Fiori (Launchpad)\u00a0\u2013 version SAP_UI 754<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/august-2025.html\">SAP Security Patch Day\u00a0\u2013 August 2025<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-august-2025-monthly-rollup-av25-500","alert_type":396,"serial_number":"AV25-500","subject":"sap","moderation_state":"published","external_url":null},{"nid":6688,"title":"[Control systems] Schneider Electric security advisory (AV25-501) ","uuid":"6884bf57-95ad-4a6e-838f-e7ca2eebdd12","banner":null,"lang":"en","date_modified":"2025-08-12","date_modified_ts":"2025-08-12T20:07:02Z","date_created":"2025-08-12T19:49:05Z","summary":null,"body":["<article data-history-node-id=\"6688\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-501\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-501<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 12, 2025<\/p>\n\n<p>Le 12 ao\u00fbt 2025, Schneider Electric a publi\u00e9 des bulletins de s\u00e9curit\u00e9 visant \u00e0 corriger des vuln\u00e9rabilit\u00e9s li\u00e9es aux produits suivants\u00a0:<\/p>\n\n<ul><li>BMXNGD0100: M580 Global Data module\u00a0\u2013 all versions<\/li>\n\t<li>BMXNOC0401: Modicon M340 X80 Ethernet Communication modules\u00a0\u2013 all versions<\/li>\n\t<li>BMXNOE0100: Modbus\/TCP Ethernet Modicon M340 module\u00a0\u2013 multiple versions and models<\/li>\n\t<li>BMXNOR0200H: Ethernet \/ Serial RTU Module\u00a0\u2013 all versions<\/li>\n\t<li>EcoStruxure Building Operation Enterprise Server and Central\u00a0\u2013 versions prior to 7.0.1<\/li>\n\t<li>EcoStruxure Enterprise Server\u00a0\u2013 versions prior to 7.0.1<\/li>\n\t<li>EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 versions 2022, 2023, 2024 and 2024 R2<\/li>\n\t<li>EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module\u00a0\u2013 versions 2022 w\/ Advanced Reporting Module and 2024 w\/ Advanced Reporting Module<\/li>\n\t<li>EcoStruxure Workstation\u00a0\u2013 versions prior to 7.0.1<\/li>\n\t<li>Modicon Controller\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Modicon M580 communication modules\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SESU\u00a0\u2013 versions prior to v3.0.12<\/li>\n\t<li>Saitel DR RTU\u00a0\u2013 version 11.06.29 and prior, version 11.06.34 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-501","alert_type":398,"serial_number":"AV25-501","subject":"other","moderation_state":"published","external_url":null},{"nid":6687,"title":"[Control systems] Siemens security advisory (AV25-502)","uuid":"c7d5f1b8-423d-45d7-8f55-d70b38fb127f","banner":null,"lang":"en","date_modified":"2025-08-12","date_modified_ts":"2025-08-12T20:13:46Z","date_created":"2025-08-12T19:52:25Z","summary":null,"body":["<article data-history-node-id=\"6687\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-502\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-502<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 12, 2025<\/p>\n\n<p>Between August 12, 2025, Siemens published advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-502","alert_type":398,"serial_number":"AV25-502","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6689,"title":"Ivanti security advisory (AV25-503)","uuid":"e481b87b-5826-4195-b5b8-30b75ec38427","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T13:03:10Z","date_created":"2025-08-13T12:42:08Z","summary":null,"body":["<article data-history-node-id=\"6689\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-503\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-503<br \/><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 12, 2025, Ivanti published security advisories to address vulnerabilities in the following products. Included was a critical update for the following:<\/p>\n\n<ul><li>Ivanti Virtual Application Delivery Controller (vADC)\u00a0\u2013 version 22.8R2 and prior<\/li>\n\t<li>Ivanti Connect Secure (ICS)\u00a0\u2013 version 22.7R2.7 and prior<\/li>\n\t<li>Ivanti Policy Secure (IPS)\u00a0\u2013 version 22.7R1.4 and prior<\/li>\n\t<li>Ivanti ZTA Gateway\u00a0\u2013 version 22.8R2.2<\/li>\n\t<li>Ivanti Neurons for Secure Access\u00a0\u2013 version 22.8R1.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/August-Security-Advisory-Ivanti-Virtual-Application-Delivery-Controller-vADC-previously-vTM-CVE-2025-8310?language=en_US\">August Security Advisory Ivanti Virtual Application Delivery Controller (vADC previously vTM) (CVE-2025-8310)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/August-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-Multiple-CVEs?language=en_US\">August Security Advisory Ivanti Connect Secure, Policy Secure &amp; ZTA Gateways (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-503","alert_type":396,"serial_number":"AV25-503","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6690,"title":"Microsoft security advisory \u2013 August 2025 monthly rollup (AV25-504)","uuid":"333b7b7a-1fd7-4278-aef1-8cf46765661b","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T14:00:45Z","date_created":"2025-08-13T13:47:28Z","summary":null,"body":["<article data-history-node-id=\"6690\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2025-monthly-rollup-av25-504\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-504<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 12, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Azure File Sync<\/li>\n\t<li>Azure Open AI<\/li>\n\t<li>Azure Portal<\/li>\n\t<li>Azure Stack Hub<\/li>\n\t<li>DCadsv5-series Azure VM<\/li>\n\t<li>DCasv5-series Azure VM<\/li>\n\t<li>DCesv5-series\u00a0- Azure VM<\/li>\n\t<li>DCesv6-series Azure VM<\/li>\n\t<li>ECadsv5-series Azure VM<\/li>\n\t<li>ECedsv5-series Azure VM<\/li>\n\t<li>Ecesv6-series Azure VM<\/li>\n\t<li>Microsoft 365<\/li>\n\t<li>Microsoft Dynamics 365<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Server<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Microsoft PowerPoint<\/li>\n\t<li>Microsoft SQL Server<\/li>\n\t<li>Microsoft SharePoint<\/li>\n\t<li>Microsoft Teams<\/li>\n\t<li>Microsoft Visual Studio 2022 version 17.14<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>NCCadsH100v5-series Azure VM<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Teams Panels<\/li>\n\t<li>Teams Phones<\/li>\n\t<li>Web Deploy 4.0<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Security App<\/li>\n\t<li>Windows Server<\/li>\n\t<li>Windows Subsystem for Linux<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2025-53779 and CVE-2025-49719 have available exploits.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Aug\">August 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2025-monthly-rollup-av25-504","alert_type":396,"serial_number":"AV25-504","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6691,"title":"Adobe security advisory (AV25-505)","uuid":"ef526faa-97d1-4bf4-a10e-3e3f30e62768","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T14:17:52Z","date_created":"2025-08-13T14:06:15Z","summary":null,"body":["<article data-history-node-id=\"6691\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-505\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-505<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 12, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Animate 2023\u00a0\u2013 version 23.0.12 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0\u2013 version 24.0.9 and prior<\/li>\n\t<li>Adobe Commerce B2B\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 4.1.3 and prior<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 version FrameMaker 2020 Update 8 and prior<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 version FrameMaker 2022 Update 6 and prior<\/li>\n\t<li>Adobe Illustrator 2024\u00a0\u2013 version 28.7.8 and prior<\/li>\n\t<li>Adobe Illustrator 2025\u00a0\u2013 version 29.6.1 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 20.4 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 19.5.4 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.5.4 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID20.4 and prior<\/li>\n\t<li>Adobe Magento Open Source\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Photoshop 2024\u00a0\u2013 version 25.12.3 and prior<\/li>\n\t<li>Adobe Photoshop 2025\u00a0\u2013 version 26.8 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler\u00a0\u2013 version 1.22.0 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 11.0.2 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler\u00a0\u2013 version 5.0.3 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.1.3 and prior<\/li>\n\t<li>Adobe Substance 3D Viewer\u00a0\u2013 version 0.25 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-505","alert_type":396,"serial_number":"AV25-505","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6692,"title":"Fortinet security advisory (AV25-506)","uuid":"cae71a83-b2be-4806-9b1e-055f49b16fd0","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T16:42:52Z","date_created":"2025-08-13T16:37:47Z","summary":null,"body":["<article data-history-node-id=\"6692\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-506\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-506<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 12, 2025, Fortinet published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>Fortinet is aware that an exploit for CVE-2025-25256 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-25-152\">Remote unauthenticated command injection in FortiSIEM<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-506","alert_type":396,"serial_number":"AV25-506","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6693,"title":"GitLab security advisory (AV25-507)","uuid":"1ce9bcf9-2f9a-44e1-9632-2228b566e16a","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T16:50:04Z","date_created":"2025-08-13T16:42:13Z","summary":null,"body":["<article data-history-node-id=\"6693\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-507\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-507<br \/><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 13, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.2.2, 18.1.4 and 18.0.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.2.2, 18.1.4 and 18.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/08\/13\/patch-release-gitlab-18-2-2-released\/\">GitLab Patch Release: 18.2.2, 18.1.4, 18.0.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-507","alert_type":396,"serial_number":"AV25-507","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6694,"title":"HPE security advisory (AV25-508)","uuid":"8446b19b-9520-4134-aa54-6c633b35afe7","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T19:34:58Z","date_created":"2025-08-13T19:30:56Z","summary":null,"body":["<article data-history-node-id=\"6694\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-508\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-508<br \/><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>Between August 6 and 13, 2025, HPE published security advisories to address vulnerabilities in the multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates. Please refer to the list of vulnerabilities dated for the past week, and especially the ones that have high and critical severity.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-508","alert_type":396,"serial_number":"AV25-508","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6695,"title":"F5 security advisory (AV25-509)","uuid":"c47c6740-2194-4955-811f-8fc225cdcf11","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T19:49:14Z","date_created":"2025-08-13T19:39:55Z","summary":null,"body":["<article data-history-node-id=\"6695\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av25-509\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-509<br \/><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 13, 2025, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>APM Clients\u00a0\u2013 version 7.2.5<\/li>\n\t<li>BIG-IP (APM)\u00a0\u2013 versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.5 and versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP (APM)\u00a0\u2013 versions 17.5.0 to 17.5.1, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.6 and versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP (all modules)\u00a0\u2013 versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.5 and versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP (all modules)\u00a0\u2013 versions 17.5.0 to 17.5.1, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.6 and versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP Next (all modules)\u00a0\u2013 versions 20.3.0<\/li>\n\t<li>BIG-IP Next CNF\u00a0\u2013 versions 2.0.0 to 2.0.2 and versions 1.1.0 to 1.4.1<\/li>\n\t<li>BIG-IP Next SPK\u00a0\u2013 versions 2.0.0 to 2.0.2 and versions 1.7.0 to 1.9.2<\/li>\n\t<li>BIG-IP Next for Kubernetes\u00a0\u2013 version 2.0.0<\/li>\n\t<li>F5 Access for Android\u00a0\u2013 versions 3.1.0 to 3.1.1<\/li>\n\t<li>F5 Silverline in HTTP\/2 enabled proxy servers (all services)<\/li>\n\t<li>NGINX Open Source\u00a0\u2013 versions 0.7.22 to 1.29.0<\/li>\n\t<li>NGINX Plus\u00a0\u2013 versions R30 to R34<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000152635\">F5 Quarterly Security Notification (August 2025)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av25-509","alert_type":396,"serial_number":"AV25-509","subject":"f5","moderation_state":"published","external_url":null},{"nid":6696,"title":"Foxit security advisory (AV25-510)","uuid":"204d53f8-a346-4a48-9fcb-01153d240271","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T20:20:35Z","date_created":"2025-08-13T20:13:30Z","summary":null,"body":["<article data-history-node-id=\"6696\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av25-510\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-510<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 13, 2025, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor (Windows)\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Editor for Mac\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader (Windows)\u00a0\u2013 version 2025.1.0.27937 and prior<\/li>\n\t<li>Foxit PDF Reader for Mac\u00a0\u2013 version 2025.1.0.66692 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av25-510","alert_type":396,"serial_number":"AV25-510","subject":"other","moderation_state":"published","external_url":null},{"nid":6697,"title":"Intel security advisory (AV25-511) ","uuid":"6c8de896-88e1-4d0f-9777-e27d8ad071f8","banner":null,"lang":"en","date_modified":"2025-08-13","date_modified_ts":"2025-08-13T20:32:59Z","date_created":"2025-08-13T20:28:11Z","summary":null,"body":["<article data-history-node-id=\"6697\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av25-511\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-511<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 13, 2025<\/p>\n\n<p>On August 12, 2025, Intel published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Product Security Center Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av25-511","alert_type":396,"serial_number":"AV25-511","subject":"intel","moderation_state":"published","external_url":null},{"nid":6698,"title":"SolarWinds security advisory (AV25-512)","uuid":"63f1da02-24ee-4f3e-b523-5ec5463f032a","banner":null,"lang":"en","date_modified":"2025-08-14","date_modified_ts":"2025-08-14T15:04:45Z","date_created":"2025-08-14T14:57:08Z","summary":null,"body":["<article data-history-node-id=\"6698\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-512\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-512<br \/><strong>Date: <\/strong>August 14, 2025<\/p>\n\n<p>On August 12, 2025, SolarWinds published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SolarWinds Database Performance Analyzer\u00a0\u2013 version 2025.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2025-26398\">SolarWinds Database Performance Analyzer Hard-coded Cryptographic Key Vulnerability (CVE-2025-26398)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-512","alert_type":396,"serial_number":"AV25-512","subject":"other","moderation_state":"published","external_url":null},{"nid":6699,"title":"[Control systems] ABB security advisory (AV25-513) ","uuid":"f8dcd7f2-ce7d-4402-bec3-98eb01d5d9fc","banner":null,"lang":"en","date_modified":"2025-08-14","date_modified_ts":"2025-08-14T15:17:54Z","date_created":"2025-08-14T15:12:25Z","summary":null,"body":["<article data-history-node-id=\"6699\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-513\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-513<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 14, 2025<\/p>\n\n<p>On August 12, 2025, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB Ability zenon\u00a0\u2013 versions 7.50, 7.60, 8.00, 8.20, 11, 12 and 14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA002743&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB AbilityTM zenon Remote Transport Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-513","alert_type":398,"serial_number":"AV25-513","subject":"other","moderation_state":"published","external_url":null},{"nid":6701,"title":"Drupal security advisory (AV25-514)","uuid":"80d76a6d-e302-43e3-8795-4491c3aa5c76","banner":null,"lang":"en","date_modified":"2025-08-14","date_modified_ts":"2025-08-14T15:32:46Z","date_created":"2025-08-14T15:29:27Z","summary":null,"body":["<article data-history-node-id=\"6701\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-514\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-514<br \/><strong>Date: <\/strong>August 14, 2025<\/p>\n\n<p>On August 13, 2025, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Authenticator Login (Alogin)\u00a0\u2013 versions prior to 2.1.4<\/li>\n\t<li>Layout Builder Advanced Permissions\u00a0\u2013 version 2.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-096\">Authenticator Login\u00a0- Highly critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-096<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-097\">Layout Builder Advanced Permissions\u00a0- Moderately critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-097<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-514","alert_type":396,"serial_number":"AV25-514","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6702,"title":"Palo Alto Networks security advisory (AV25-515)","uuid":"ba31a5f6-1e10-4275-b031-d36192c9eb3c","banner":null,"lang":"en","date_modified":"2025-08-14","date_modified_ts":"2025-08-14T17:18:00Z","date_created":"2025-08-14T16:21:44Z","summary":null,"body":["<article data-history-node-id=\"6702\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-515\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-515<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 14, 2025<\/p>\n\n<p>On August 13, 2025, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Checkov by Prisma Cloud 3.2.0\u00a0\u2013 versions prior to 3.2.449<\/li>\n\t<li>Cortex XDR Broker VM 28.0.0\u00a0\u2013 versions prior to 28.0.52<\/li>\n\t<li>GlobalProtect App 6.3 Linux\u00a0\u2013 versions prior to 6.3.3<\/li>\n\t<li>GlobalProtect App 6.3 Windows\u00a0\u2013 versions prior to 6.3.3-h2 (6.3.3-c676)<\/li>\n\t<li>GlobalProtect App 6.2 Linux\u00a0\u2013 all versions<\/li>\n\t<li>GlobalProtect App 6.2 Windows\u00a0\u2013 versions prior to 6.2.8-h3 (6.2.8-c263)<\/li>\n\t<li>GlobalProtect App 6.1 Linux\/Windows\u00a0\u2013 all versions<\/li>\n\t<li>GlobalProtect App 6.0 Linux\/Windows\u00a0\u2013 all versions<\/li>\n\t<li>PAN-OS 11.2 (On PA-7500)\u00a0\u2013 versions prior to 11.2.8<\/li>\n\t<li>PAN-OS 11.1 (On PA-7500)\u00a0\u2013 versions prior to 11.1.10<\/li>\n\t<li>Prisma Access Browser\u00a0\u2013 versions prior to 138.69.4.184<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-515","alert_type":396,"serial_number":"AV25-515","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6703,"title":"ServiceNow security advisory (AV25-516)","uuid":"5c3474a6-5c55-40fb-93e0-ab94054cb4ac","banner":null,"lang":"en","date_modified":"2025-08-14","date_modified_ts":"2025-08-14T19:05:36Z","date_created":"2025-08-14T18:48:49Z","summary":null,"body":["<article data-history-node-id=\"6703\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av25-516\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-516<br \/><strong>Date: <\/strong>August 14, 2025<\/p>\n\n<p>On August 12, 2025, ServiceNow published a Security Advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ServiceNow Washington\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Xanadu\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Yokohama\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Zurich\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB2264930\">CVE-2025-3089\u00a0- Broken Access Control in ServiceNow AI Platform<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av25-516","alert_type":396,"serial_number":"AV25-516","subject":"other","moderation_state":"published","external_url":null},{"nid":6704,"title":"N-able security advisory (AV25-517)","uuid":"087df502-886f-4f58-94e2-c903741bad49","banner":null,"lang":"en","date_modified":"2025-08-14","date_modified_ts":"2025-08-14T20:44:32Z","date_created":"2025-08-14T20:33:01Z","summary":null,"body":["<article data-history-node-id=\"6704\" about=\"\/en\/alerts-advisories\/n-able-security-advisory-av25-517\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-517<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 14, 2025<\/p>\n\n<p>On August 14, 2025, N-able published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>N-central\u00a0\u2013 versions prior to 2025.3.1<\/li>\n<\/ul><p>On August 13, 2025, CISA added CVE-2025-8875 and CVE-2025-8876 to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/08\/13\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">KEV\u00a0- CISA Adds Two Known Exploited Vulnerabilities to Catalog<\/a><\/li>\n\t<li><a href=\"https:\/\/status.n-able.com\/2025\/08\/13\/announcing-the-ga-of-n-central-2025-3-1\/\">Announcing the GA of N-central 2025.3.1<\/a><\/li>\n\t<li><a href=\"https:\/\/status.n-able.com\/\">N-able Status<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n-able-security-advisory-av25-517","alert_type":396,"serial_number":"AV25-517","subject":"other","moderation_state":"published","external_url":null},{"nid":6706,"title":"[Control systems] Siemens security advisory (AV25-518) ","uuid":"24dcf6c2-a2f3-456f-9fce-1324bc5304d2","banner":null,"lang":"en","date_modified":"2025-08-15","date_modified_ts":"2025-08-15T15:44:51Z","date_created":"2025-08-15T15:35:03Z","summary":null,"body":["<article data-history-node-id=\"6706\" about=\"\/en\/alerts-advisories\/cyber-control-systems-siemens-security-advisory-av25-518\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-518<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 15, 2025<\/p>\n\n<p>On August 14, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Mendix SAML (Mendix 9.24 compatible)\u00a0\u2013 versions prior to V3.6.21<\/li>\n\t<li>Mendix SAML (Mendix 10.12 compatible)\u00a0\u2013 versions prior to V4.0.3<\/li>\n\t<li>Mendix SAML (Mendix 10.21 compatible)\u00a0\u2013 versions prior to V4.1.2<\/li>\n\t<li>Desigo CC family\u00a0\u2013 all versions<\/li>\n\t<li>SENTRON Powermanager\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-395458.html\">SSA-395458: Account Hijacking Vulnerability in Mendix SAML Module<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-201595.html\">SSA-201595: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting the Desigo CC Product Family and SENTRON Powermanager<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cyber-control-systems-siemens-security-advisory-av25-518","alert_type":398,"serial_number":"AV25-518","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6707,"title":"Cisco security advisory (AV25-519)","uuid":"c0dd35fc-5711-4a1b-ad04-0b772fabba41","banner":null,"lang":"en","date_modified":"2025-08-15","date_modified_ts":"2025-08-15T16:01:40Z","date_created":"2025-08-15T15:41:46Z","summary":null,"body":["<article data-history-node-id=\"6707\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-519\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-519<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 15, 2025<\/p>\n\n<p>On August 14, 2025, Cisco published security advisories to address vulnerabilities in the multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-519","alert_type":396,"serial_number":"AV25-519","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6708,"title":"Google Chrome security advisory (AV25-520)","uuid":"fea03784-3a46-49cd-a0c4-abd1d953faaf","banner":null,"lang":"en","date_modified":"2025-08-15","date_modified_ts":"2025-08-15T18:03:59Z","date_created":"2025-08-15T17:56:50Z","summary":null,"body":["<article data-history-node-id=\"6708\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-520\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-520<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 15, 2025<\/p>\n\n<p>On August 12, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 139.0.7258.127\/128 (Windows\/Mac) and 139.0.7258.127 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/08\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-520","alert_type":396,"serial_number":"AV25-520","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6709,"title":"VMware security advisory (AV25-521)","uuid":"91bf7845-8117-4b82-8aa8-41c5796006ad","banner":null,"lang":"en","date_modified":"2025-08-15","date_modified_ts":"2025-08-15T18:13:00Z","date_created":"2025-08-15T18:06:16Z","summary":null,"body":["<article data-history-node-id=\"6709\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-521\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-521<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 15, 2025<\/p>\n\n<p>On August 14, 2025, VMware published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu for Valkey\u00a0\u2013 version 7.2.9<\/li>\n\t<li>VMware Tanzu for Valkey\u00a0\u2013 version 8.0.3<\/li>\n\t<li>VMware Tanzu for Valkey\u00a0\u2013 version 8.1.2<\/li>\n\t<li>VMware Tanzu for Valkey on Kubernetes\u00a0\u2013 version 2.1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36035\">Product Release Advisory\u00a0- VMware Tanzu for Valkey 7.2.10<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36036\">Product Release Advisory\u00a0- VMware Tanzu for Valkey 8.0.4<\/a><\/li>\n  \t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36037\">Product Release Advisory\u00a0- VMware Tanzu for Valkey 8.1.3<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36038\">Product Release Advisory\u00a0- VMware Tanzu for Valkey on Kubernetes 3.0.0<\/a><\/li>\n  \t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-521","alert_type":396,"serial_number":"AV25-521","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6711,"title":"Dell security advisory (AV25-522)","uuid":"63a5bb6f-b125-426f-90ca-a372fad78b82","banner":null,"lang":"en","date_modified":"2025-08-18","date_modified_ts":"2025-08-18T14:48:51Z","date_created":"2025-08-18T14:36:49Z","summary":null,"body":["<article data-history-node-id=\"6711\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-522\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-522<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 18, 2025<\/p>\n\n<p>Between August 11 and 17, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Microsoft Azure\u00a0\u2013 versions prior to 01.05.01.01<\/li>\n\t<li>Dell CloudLink\u00a0\u2013 versions 8.0 to 8.1.1<\/li>\n\t<li>Dell Data Lakehouse\u00a0\u2013 versions prior to 1.5.0.0<\/li>\n\t<li>Dell EMC XC Core XC7525\u00a0- version prior to 2.20.0<\/li>\n\t<li>Dell Intel E810 Adapters and Intel E823 LOM\u00a0\u2013 versions prior to 24.0.0<\/li>\n\t<li>Dell Intel I350 and X550 Adapters\u00a0\u2013 versions prior to 24.0.0<\/li>\n\t<li>Dell Intel X710, XXV710, and XL710 Adapters\u00a0\u2013 versions prior to 24.0.0<\/li>\n\t<li>Dell OpenManage Enterprise\u00a0\u2013 versions 3.10, 4.0, 4.1 and 4.2<\/li>\n\t<li>Dell PowerEdge R770, R670, R570, R470\u00a0\u2013 version prior to 1.3.2<\/li>\n\t<li>Dell PowerEdge Servers\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell PowerEdge T40\u00a0\u2013 versions prior to 1.19.0<\/li>\n\t<li>Dell PowerEdge XE7740\u00a0\u2013 versions prior to 1.2.2<\/li>\n\t<li>Dell PowerProtect DM5500\u00a0\u2013 versions prior to 5.19.1.0<\/li>\n\t<li>Dell SupportAssist for Business PCs\u00a0\u2013 version 4.5.3 and prior<\/li>\n\t<li>Dell SupportAssist for Home PCs\u00a0\u2013 version 4.8.2.29006 and prior<\/li>\n\t<li>Dell XC Core XC660, XC760, XC660xs, XC760xa\u00a0\u2013 versions prior to 2.5.4<\/li>\n\t<li>Dell XC Core XC7625\u00a0\u2013 versions prior to 1.13.1<\/li>\n<\/ul><p>TThe Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-522","alert_type":396,"serial_number":"AV25-522","subject":"dell","moderation_state":"published","external_url":null},{"nid":6712,"title":"[Control systems] CISA ICS security advisories (AV25-523)","uuid":"03e071bf-6e89-43b1-81f3-d9a1798659d7","banner":null,"lang":"en","date_modified":"2025-08-18","date_modified_ts":"2025-08-18T14:59:42Z","date_created":"2025-08-18T14:55:33Z","summary":null,"body":["<article data-history-node-id=\"6712\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-523\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-523<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 18, 2025<\/p>\n\n<p>Between August 11 and 17, 2025, CISA published ICS advisories to highlight vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-523","alert_type":398,"serial_number":"AV25-523","subject":"ics","moderation_state":"published","external_url":null},{"nid":6713,"title":"Ubuntu security advisory (AV25-524)","uuid":"3edf10ea-a97a-433f-9a37-16a72e271a15","banner":null,"lang":"en","date_modified":"2025-08-18","date_modified_ts":"2025-08-18T17:33:46Z","date_created":"2025-08-18T17:11:15Z","summary":null,"body":["<article data-history-node-id=\"6713\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-524\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-524<br \/><strong>Date: <\/strong>August 18, 2025<\/p>\n\n<p>Between August 11 and 17, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7685-5\">USN-7685-5: Linux kernel (Oracle) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7682-5\">USN-7682-5: Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7681-3\">USN-7681-3: Linux kernel (Oracle) vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-524","alert_type":396,"serial_number":"AV25-524","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6714,"title":"Microsoft Edge security advisory (AV25-526)","uuid":"37a4e20e-088f-4b71-aa45-95895262117f","banner":null,"lang":"en","date_modified":"2025-08-18","date_modified_ts":"2025-08-18T18:42:44Z","date_created":"2025-08-18T18:15:52Z","summary":null,"body":["<article data-history-node-id=\"6714\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-526\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-526<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 18, 2025<\/p>\n\n<p>On August 15, 2025, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 139.0.3405.102<\/li>\n\t<li>Microsoft Extended Edge Stable Channel\u00a0\u2013 versions prior to 138.0.3351.140<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-15-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-526","alert_type":396,"serial_number":"AV25-526","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6715,"title":"IBM security advisory (AV25-525)","uuid":"2851c26e-1139-42dd-94d8-a46560e65f7a","banner":null,"lang":"en","date_modified":"2025-08-18","date_modified_ts":"2025-08-18T18:28:52Z","date_created":"2025-08-18T18:18:51Z","summary":null,"body":["<article data-history-node-id=\"6715\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-525\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-525<br \/><strong>Date: <\/strong>August 18, 2025<\/p>\n\n<p>Between August 11 and 17, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-525","alert_type":396,"serial_number":"AV25-525","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6716,"title":"Red Hat security advisory (AV25-527)","uuid":"afca691e-7605-48bf-8e33-fdc8273e4f87","banner":null,"lang":"en","date_modified":"2025-08-18","date_modified_ts":"2025-08-18T18:44:27Z","date_created":"2025-08-18T18:25:32Z","summary":null,"body":["<article data-history-node-id=\"6716\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-527\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-527<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 18, 2025<\/p>\n\n<p>Between August 11 and 17, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-527","alert_type":396,"serial_number":"AV25-527","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6718,"title":"HPE security advisory (AV25-528)","uuid":"e1132b96-5054-45c1-9a79-5da49a0215f2","banner":null,"lang":"en","date_modified":"2025-08-19","date_modified_ts":"2025-08-19T14:03:12Z","date_created":"2025-08-19T13:25:17Z","summary":null,"body":["<article data-history-node-id=\"6718\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-528\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-528<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 19, 2025<\/p>\n\n<p>On August 19, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE IceWall Identity Manager\u00a0\u2013 versions prior to v6.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbmu04921en_us&amp;docLocale=en_US#hpesbmu04921-rev-1-hpe-icewall-identity-manager-de-0\">HPESBMU04921 rev.1\u00a0- HPE IceWall Identity Manager, Denial of Service<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-528","alert_type":396,"serial_number":"AV25-528","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6719,"title":"Mozilla security advisory (AV25-529)","uuid":"eff41b73-45c1-4b9f-9cf0-dce6378f5d18","banner":null,"lang":"en","date_modified":"2025-08-19","date_modified_ts":"2025-08-19T18:47:21Z","date_created":"2025-08-19T18:42:04Z","summary":null,"body":["<article data-history-node-id=\"6719\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-529\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-529<br \/><strong>Date: <\/strong>August 19, 2025<\/p>\n\n<p>On August 19, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Focus for iOS\u00a0- versions prior to 142<\/li>\n\t<li>Firefox for iOS\u00a0- versions prior to 142<\/li>\n\t<li>Firefox ESR\u00a0- versions prior to 140.2<\/li>\n\t<li>Firefox ESR\u00a0- versions prior to 128.14<\/li>\n\t<li>Firefox ESR\u00a0- versions prior to 115.27<\/li>\n\t<li>Firefox\u00a0- versions prior to 142<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-529","alert_type":396,"serial_number":"AV25-529","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6721,"title":"Google Chrome security advisory (AV25-530)","uuid":"d53a50d5-aea0-42fd-80e4-85a7d1920c36","banner":null,"lang":"en","date_modified":"2025-08-20","date_modified_ts":"2025-08-20T13:59:42Z","date_created":"2025-08-20T13:53:43Z","summary":null,"body":["<article data-history-node-id=\"6721\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-530\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-530<br \/><strong>Date: <\/strong>August\u00a020, 2025<\/p>\n\n<p>On August\u00a019, 2025, Google published security advisories to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0- versions prior to 139.0.7258.138\/.139 (Windows\/Mac) and 139.0.7258.138 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/08\/stable-channel-update-for-desktop_19.html\">Google Chrome Security Advisory <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-530","alert_type":396,"serial_number":"AV25-530","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6722,"title":"Commvault security advisory (AV25-531)","uuid":"68da9e57-816f-4098-8c1e-f1650437b9e2","banner":null,"lang":"en","date_modified":"2025-08-20","date_modified_ts":"2025-08-20T14:12:48Z","date_created":"2025-08-20T14:05:18Z","summary":null,"body":["<article data-history-node-id=\"6722\" about=\"\/en\/alerts-advisories\/commvault-security-advisory-av25-531\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-531<br \/><strong>Date: <\/strong>August\u00a020, 2025<\/p>\n\n<p>On August\u00a019, 2025, Commvault published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Commvault\u00a0- versions 11.32.0 to 11.32.101<\/li>\n\t<li>Commvault\u00a0- versions 11.36.0 to 11.36.59<\/li>\n<\/ul><p>Open-source reporting has indicated that proof-of-concept exploit code exists for these vulnerabilities CVE-2025-57788, CVE-2025-57789, CVE-2025-57790 and CVE-2025-57791.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2025_08_1.html\">CV_2025_08_1: Argument Injection Vulnerability in CommServe<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2025_08_2.html\">CV_2025_08_2: Path Traversal Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2025_08_3.html\">CV_2025_08_3: Unauthorized API Access Risk<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2025_08_4.html\">CV_2025_08_4: Vulnerability in Initial Administrator Login Process <\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/\">Commvault Cloud Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/commvault-security-advisory-av25-531","alert_type":396,"serial_number":"AV25-531","subject":"other","moderation_state":"published","external_url":null},{"nid":6724,"title":"Cisco security advisory (AV25-532)","uuid":"9bf610b8-a5bd-4454-ae0e-8b66e337a5bd","banner":null,"lang":"en","date_modified":"2025-08-20","date_modified_ts":"2025-08-20T19:07:28Z","date_created":"2025-08-20T18:48:46Z","summary":null,"body":["<article data-history-node-id=\"6724\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-532\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-532<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 20, 2025<\/p>\n\n<p>On August 20, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Duo Authentication Proxy\u00a0\u2013 version 5.8.2 and prior and version 6.5.1 and prior<\/li>\n\t<li>Cisco Evolved Programmable Network Manager (EPNM)\u00a0\u2013 version 7.1 and prior, versions 8.0 and 8.1<\/li>\n\t<li>Cisco Prime Infrastructure\u00a0\u2013 version 3.9 and prior and version 3.10<\/li>\n\t<li>Cisco Identity Services Engine (ISE)\u00a0\u2013 version 3.1 and prior, versions 3.2 and 3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-authproxlog-SxczXQ63\">Cisco Duo Authentication Proxy Information Disclosure Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-pi-epnm-TET4GxBX\">Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Sensitive Information Disclosure Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-file-upload-qksX6C8g\">Cisco Identity Services Engine Arbitrary File Upload Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-532","alert_type":396,"serial_number":"AV25-532","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6725,"title":"Apple security advisory (AV25-533)","uuid":"c51ed4d1-b109-477a-b900-871cab22c938","banner":null,"lang":"en","date_modified":"2025-08-20","date_modified_ts":"2025-08-20T19:19:16Z","date_created":"2025-08-20T19:12:00Z","summary":null,"body":["<article data-history-node-id=\"6725\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-533\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-533<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 20, 2025<\/p>\n\n<p>On August 20, 2025, Apple published security updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.6.2<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 17.7.10<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.6.1<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.7.8<\/li>\n\t<li>macOS Ventura\u00a0\u2013 versions prior to 13.7.8<\/li>\n<\/ul><p>Apple has indicated that CVE-2025-43300 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-533","alert_type":396,"serial_number":"AV25-533","subject":"apple","moderation_state":"published","external_url":null},{"nid":6726,"title":"HPE security advisory (AV25-534)","uuid":"be9329a9-7dca-4ce8-aaa8-3ad5051c6902","banner":null,"lang":"en","date_modified":"2025-08-20","date_modified_ts":"2025-08-20T19:42:39Z","date_created":"2025-08-20T19:33:40Z","summary":null,"body":["<article data-history-node-id=\"6726\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-534\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-534<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 20, 2025<\/p>\n\n<p>On August 20, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Unified OSS Console\u00a0\u2013 version 3.1.16<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04941en_us&amp;docLocale=en_US\">HPESBNW04941 Rev. 1\u00a0- HPE Telco Unified OSS Console, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-534","alert_type":396,"serial_number":"AV25-534","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6727,"title":"Microsoft Edge security advisory (AV25-535)","uuid":"3fa92421-e785-429b-a6e7-23a198e98502","banner":null,"lang":"en","date_modified":"2025-08-22","date_modified_ts":"2025-08-22T13:35:27Z","date_created":"2025-08-22T13:32:45Z","summary":null,"body":["<article data-history-node-id=\"6727\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-535\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-535<br \/><strong>Date: <\/strong>August\u00a022, 2025<\/p>\n\n<p>On August\u00a021, 2025, Microsoft published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0- versions prior to 139.0.3405.111<\/li>\n\t<li>Microsoft Extended Edge Stable Channel\u00a0- versions prior to 138.0.3351.144<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-21-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-535","alert_type":396,"serial_number":"AV25-535","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6729,"title":"Ubuntu security advisory (AV25-536)","uuid":"ac855161-ac98-4490-be9e-a5cf39770ddb","banner":null,"lang":"en","date_modified":"2025-08-25","date_modified_ts":"2025-08-25T15:31:13Z","date_created":"2025-08-25T15:25:20Z","summary":null,"body":["<article data-history-node-id=\"6729\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-536\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-536<\/p>\n\n<p><strong>Date: <\/strong>August 25, 2025<\/p>\n\n<p>Between August 18 and 24, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-536","alert_type":396,"serial_number":"AV25-536","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6730,"title":"CISA ICS security advisories (AV25-537)","uuid":"08099da9-20fa-4dfb-ba5b-c216ccb351b6","banner":null,"lang":"en","date_modified":"2025-08-25","date_modified_ts":"2025-08-25T15:41:09Z","date_created":"2025-08-25T15:35:54Z","summary":null,"body":["<article data-history-node-id=\"6730\" about=\"\/en\/alerts-advisories\/cisa-ics-security-advisories-av25-537\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-537<br \/><strong>Date: <\/strong>August 25, 2025<\/p>\n\n<p>Between August 18 and 24, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitsubishi Electric Corporation MELSEC iQ-F Series CPU Module\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Desigo CC family\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Mendix SAML (Mendix 10.12 compatible)\u00a0\u2013 versions prior to V4.0.3<\/li>\n\t<li>Siemens Mendix SAML (Mendix 10.21 compatible)\u00a0\u2013 versions prior to V4.1.2<\/li>\n\t<li>Siemens Mendix SAML (Mendix 9.24 compatible)\u00a0\u2013 versions prior to V3.6.21<\/li>\n\t<li>Siemens SENTRON Powermanager V5, V6, V7, V8\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisa-ics-security-advisories-av25-537","alert_type":398,"serial_number":"AV25-537","subject":"ics","moderation_state":"published","external_url":null},{"nid":6731,"title":"Dell security advisory (AV25-538)","uuid":"e01ce9ff-c399-4995-aec0-145da72bab5e","banner":null,"lang":"en","date_modified":"2025-08-25","date_modified_ts":"2025-08-25T15:53:36Z","date_created":"2025-08-25T15:48:11Z","summary":null,"body":["<article data-history-node-id=\"6731\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-538\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-538<br \/><strong>Date: <\/strong>August 25, 2025<\/p>\n\n<p>Between August 18 and 24, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell RecoverPoint for Virtual Machines (Debian)\u00a0\u2013 versions prior to 6.0.SP3<\/li>\n\t<li>Dell RecoverPoint for Virtual Machines (Linux)\u00a0\u2013 versions prior to 6.0.SP3<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 versions 8.0.000 to 8.0.361<\/li>\n\t<li>Dell iDRAC Service Module\u00a0\u2013 versions prior to 6.0.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000359617\/dsa-2025-311-security-update-for-dell-idrac-service-module-vulnerabilities\">DSA-2025-311: Security Update for Dell iDRAC Service Module Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000358419\/dsa-2025-317-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities\">DSA-2025-317: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000358406\/dsa-2025-308-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities\">DSA-2025-308: Security Update for Dell RecoverPoint for Virtual Machines Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-538","alert_type":396,"serial_number":"AV25-538","subject":"dell","moderation_state":"published","external_url":null},{"nid":6732,"title":"IBM security advisory (AV25-539)","uuid":"5ddd8b4e-ee89-43c2-84df-40ce69ff28b3","banner":null,"lang":"en","date_modified":"2025-08-25","date_modified_ts":"2025-08-25T15:59:21Z","date_created":"2025-08-25T15:55:45Z","summary":null,"body":["<article data-history-node-id=\"6732\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-539\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-539<\/p>\n\n<p><strong>Date: <\/strong>August 25, 2025<\/p>\n\n<p>Between August 18 and 24, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-539","alert_type":396,"serial_number":"AV25-539","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6733,"title":"Red Hat security advisory (AV25-540)","uuid":"74302744-1f27-44f0-afa4-3c88ac50ee11","banner":null,"lang":"en","date_modified":"2025-08-25","date_modified_ts":"2025-08-25T16:06:05Z","date_created":"2025-08-25T16:01:44Z","summary":null,"body":["<article data-history-node-id=\"6733\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-540\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-540<br \/><strong>Date: <\/strong>August 25, 2025<\/p>\n\n<p>Between August 18 and 24, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-540","alert_type":396,"serial_number":"AV25-540","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6734,"title":"HPE security advisory (AV25-541)","uuid":"8dd49001-f6ab-41d5-8fc8-22fffba04166","banner":null,"lang":"en","date_modified":"2025-08-26","date_modified_ts":"2025-08-26T12:16:41Z","date_created":"2025-08-26T12:11:59Z","summary":null,"body":["<article data-history-node-id=\"6734\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-541\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-541<br \/><strong>Date: <\/strong>August\u00a026, 2025<\/p>\n\n<p>On August\u00a025, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX 11i v3 PAM RADIUS\u00a0\u2013 versions prior to A.03.00.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04931en_us&amp;docLocale=en_US\">HPESBUX04931 rev.1\u00a0- HP-UX PAM RADIUS, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-541","alert_type":396,"serial_number":"AV25-541","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6735,"title":"TeamViewer security advisory (AV25-542)","uuid":"a65a55c2-db78-4717-b5e5-ae2c66e960c1","banner":null,"lang":"en","date_modified":"2025-08-26","date_modified_ts":"2025-08-26T15:16:24Z","date_created":"2025-08-26T15:11:28Z","summary":null,"body":["<article data-history-node-id=\"6735\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-542\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-542<br \/><strong>Date: <\/strong>August 26, 2025<\/p>\n\n<p>On August 26, 2025, TeamViewer released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>TeamViewer Remote Full Client (Windows)\u00a0\u2013 versions prior to 15.69<\/li>\n\t<li>TeamViewer Remote Host (Windows)\u00a0\u2013 versions prior to 15.69<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/tv-2025-1003\/\">Arbitrary File Creation via Symbolic Link Leading to Denial-of-Service\u00a0- TV-2025-1003<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">TeamViewer Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-542","alert_type":396,"serial_number":"AV25-542","subject":"other","moderation_state":"published","external_url":null},{"nid":6736,"title":"Citrix security advisory (AV25-543)","uuid":"e61caf42-35a2-4859-ba35-3e73c50ae080","banner":null,"lang":"en","date_modified":"2025-08-26","date_modified_ts":"2025-08-26T15:23:41Z","date_created":"2025-08-26T15:18:05Z","summary":null,"body":["<article data-history-node-id=\"6736\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-543\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-543<br \/><strong>Date: <\/strong>August 26, 2025<\/p>\n\n<p>On August 26, 2025, Citrix published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway\u202f14.1\u00a0\u2013 versions prior to 14.1-47.48<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway\u202f13.1\u00a0\u2013 versions prior to 13.1-59.22<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and NDcPP\u00a0\u2013 versions prior to 13.1-37.241-FIPS and NDcPP<\/li>\n\t<li>NetScaler ADC 12.1-FIPS and NDcPP\u00a0\u2013 versions prior to 12.1-55.330-FIPS and NDcPP<\/li>\n<\/ul><p>Citrix has reported that exploits of CVE-2025-7775 on unmitigated appliances have been observed.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694938&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424\">Citrix Security Advisory\u00a0\u2013 CTX694938<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-543","alert_type":396,"serial_number":"AV25-543","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6737,"title":"HPE security advisory (AV25-544)","uuid":"1936dddd-8dcd-49af-98bc-2a64cd52a879","banner":null,"lang":"en","date_modified":"2025-08-26","date_modified_ts":"2025-08-26T17:20:18Z","date_created":"2025-08-26T17:14:23Z","summary":null,"body":["<article data-history-node-id=\"6737\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-544\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-544<br \/><strong>Date: <\/strong>August 26, 2025<\/p>\n\n<p>On August 26, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Compute Scale-up Server 3200\u00a0\u2013 versions prior to v1.60.88<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04911en_us&amp;docLocale=en_US#hpesbhf04911-rev-1-hpe-compute-scale-up-server-320-0\">HPESBHF04911 rev.1\u00a0- HPE Compute Scale-up Server 3200 Platform Servers using Certain Intel Processors, INTEL-SA-01313, 2025.3 IPU, Intel Xeon Processor Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-544","alert_type":396,"serial_number":"AV25-544","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6738,"title":"Google Chrome security advisory (AV25-545)","uuid":"89bfe0df-08cf-46c0-ad29-1b8fe85a8ad2","banner":null,"lang":"en","date_modified":"2025-08-26","date_modified_ts":"2025-08-26T20:18:56Z","date_created":"2025-08-26T20:08:25Z","summary":null,"body":["<article data-history-node-id=\"6738\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-545\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-545<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 26, 2025<\/p>\n\n<p>On August 26, 2025, Google published security advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 139.0.7258.154\/.155 (Windows\/Mac) and 139.0.7258.154 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/08\/stable-channel-update-for-desktop_26.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-545","alert_type":396,"serial_number":"AV25-545","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6739,"title":"Docker security advisory (AV25\u2013546)","uuid":"07f667ca-3c9f-4038-8877-a2bca22d98f2","banner":null,"lang":"en","date_modified":"2025-08-27","date_modified_ts":"2025-08-27T15:25:36Z","date_created":"2025-08-27T15:21:26Z","summary":null,"body":["<article data-history-node-id=\"6739\" about=\"\/en\/alerts-advisories\/docker-security-advisory-av25-546\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-546<br \/><strong>Date: <\/strong>August 27, 2025<\/p>\n\n<p>On August 20, 2025, Docker published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Docker Desktop\u00a0\u2013 versions prior to 4.44.3<\/li>\n<\/ul><p>Open-source reporting has indicated that proof-of-concept exploit code exists for the vulnerability CVE-2025-9074.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.docker.com\/desktop\/release-notes\/#4443\">Docker Desktop release notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/docker-security-advisory-av25-546","alert_type":396,"serial_number":"AV25-546","subject":"other","moderation_state":"published","external_url":null},{"nid":6740,"title":"Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424","uuid":"85a31b1c-049f-423e-9d55-4145ea63ad2a","banner":null,"lang":"en","date_modified":"2025-08-27","date_modified_ts":"2025-08-27T15:46:11Z","date_created":"2025-08-27T15:37:07Z","summary":null,"body":["<article data-history-node-id=\"6740\" about=\"\/en\/alerts-advisories\/vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2025-7775-cve-2025-7776-cve-2025-8424\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-011<br \/><strong>Date:<\/strong> August\u00a027, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On August\u00a026, 2025, Citrix published security advisories for critical vulnerabilities, CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424, affecting the following products<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway\u202f14.1\u00a0\u2013 versions prior to 14.1-47.48<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway\u202f13.1\u00a0\u2013 versions prior to 13.1-59.22<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and NDcPP\u00a0\u2013 versions prior to 13.1-37.241-FIPS and NDcPP<\/li>\n\t<li>NetScaler ADC 12.1-FIPS and NDcPP\u00a0\u2013 versions prior to 12.1-55.330-FIPS and NDcPP<\/li>\n<\/ul><p>CVE-2025-7775 is a memory overflow vulnerability that could lead to remote code execution and\/or a denial of service in NetScaler ADC and NetScaler Gateway.<\/p>\n\n<p>Further information about the impacted configurations of your appliance can be found in the Citrix advisory<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>CVE-2025-7776 is a memory overflow vulnerability leading to unpredictable or erroneous behaviour and Denial of Service when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>CVE-2025-8424 is an improper access control vulnerability on the NetScaler Management Interface in NetScaler ADC\u202fand NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access <sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>Secure Private Access on-prem or Secure Private Access Hybrid deployments using NetScaler instances are also affected by these vulnerabilities.<\/p>\n\n<p>NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End-Of-Life (EOL) and no longer supported<sup id=\"fn1d-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>Citrix reports that exploitation of CVE-2025-7775 against unmitigated appliances has been observed<sup id=\"fn1e-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>In response to these vulnerabilities, the Cyber Centre released AV25-543 on August\u00a026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. CISA added CVE-2025-7775 to their Known Exploited Vulnerabilities (KEV) catalog<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> on August\u00a026, 2025.<\/p>\n\n<p>The Cyber Centre is aware of online interest and speculation about these vulnerabilities and is publishing this Alert out of an abundance of caution.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations using Citrix NetScaler ADC and NetScaler Gateway appliances review the Citrix security bulletins<sup id=\"fn1f-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and update or upgrade the affected systems to the following versions:<\/p>\n\n<ul><li>NetScaler ADC\u202fand NetScaler Gateway 14.1-47.48 and later releases<\/li>\n\t<li>NetScaler ADC\u202fand NetScaler Gateway 13.1-59.22 and later releases of 13.1<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.241 and later releases of 13.1-FIPS and 13.1-NDcPP<\/li>\n\t<li>NetScaler ADC 12.1-FIPS and 12.1-NDcPP 12.1-55.330 and later releases of 12.1-FIPS and 12.1-NDcPP<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> as well as reviewing the Protecting your organization against denial-of-service attacks guidance<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694938\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-543\">AV25-543\u00a0\u2013 Citrix security advisory <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/08\/26\/cisa-adds-one-known-exploited-vulnerability-catalog\">Known Exploited Vulnerabilities Catalog\u00a0|\u00a0<abbr title=\"Cybersecurity and Infrastructure Security Agency\">CISA<\/abbr><\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\">Protecting your organization against denial of service attacks\u00a0- ITSAP.80.100<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2025-7775-cve-2025-7776-cve-2025-8424","alert_type":397,"serial_number":"AL25-011","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6742,"title":"Cisco security advisory (AV25-547)","uuid":"ab446310-0d12-4834-a7a8-47473ca1f238","banner":null,"lang":"en","date_modified":"2025-08-27","date_modified_ts":"2025-08-27T19:41:15Z","date_created":"2025-08-27T19:25:55Z","summary":null,"body":["<article data-history-node-id=\"6742\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-547\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-547<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 27, 2025<\/p>\n\n<p>On August 27, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco UCS 6300 Series Fabric Interconnects<\/li>\n\t<li>Cisco Catalyst 8300 Series Edge uCPE<\/li>\n\t<li>Cisco UCS Manager Software<\/li>\n\t<li>Cisco UCS B-Series Blade Servers<\/li>\n\t<li>Cisco UCS C-Series M6, M7, and M8 Rack Servers<\/li>\n\t<li>Cisco UCS E-Series Servers M6<\/li>\n\t<li>Cisco UCS X-Series Modular System<\/li>\n\t<li>Cisco MDS 9000 Series Multilayer Switches<\/li>\n\t<li>Cisco Nexus 1000 Virtual Edge for VMware vSphere<\/li>\n\t<li>Cisco Nexus 3000 Series Switches<\/li>\n\t<li>Cisco Nexus 5500 Platform Switches<\/li>\n\t<li>Cisco Nexus 5600 Platform Switches<\/li>\n\t<li>Cisco Nexus 6000 Series Switches<\/li>\n\t<li>Cisco Nexus 7000 Series Switches<\/li>\n\t<li>Cisco Nexus 9000 Series Fabric Switches in ACI mode<\/li>\n\t<li>Cisco Nexus 9000 Series Switches in standalone NX-OS mode<\/li>\n\t<li>Cisco UCS 6400 Series Fabric Interconnects<\/li>\n\t<li>Cisco UCS 6500 Series Fabric Interconnects<\/li>\n\t<li>Cisco UCS X-Series Direct Fabric Interconnect 9108 100G<\/li>\n\t<li>Cisco Nexus Dashboard 3.2 and earlier<\/li>\n\t<li>Cisco Nexus Dashboard 4.1<\/li>\n\t<li>Cisco Nexus Dashboard Fabric Controller (NDFC)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-547","alert_type":396,"serial_number":"AV25-547","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6743,"title":"Drupal security advisory (AV25-548) ","uuid":"0815aac0-d86c-4423-b9ed-d09a1ff3efcc","banner":null,"lang":"en","date_modified":"2025-08-27","date_modified_ts":"2025-08-27T19:56:05Z","date_created":"2025-08-27T19:46:45Z","summary":null,"body":["<article data-history-node-id=\"6743\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-548\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-548<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 27, 2025<\/p>\n\n<p>On August 27, 2025, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>API Key manager\u00a0\u2013 all versions<\/li>\n\t<li>Authenticator Login\u00a0\u2013 versions prior to 2.1.8<\/li>\n\t<li>Facets\u00a0\u2013 versions prior to 2.0.10, version 3.0.0 to versions prior to 3.0.1<\/li>\n\t<li>Owl Carousel 2\u00a0\u2013 all versions<\/li>\n\t<li>Protected Pages\u00a0\u2013 version 1.8.0<\/li>\n\t<li>Synchronize composer.json with Contrib Modules\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-548","alert_type":396,"serial_number":"AV25-548","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6745,"title":"GitLab security advisory (AV25-549)","uuid":"bbed7b0b-c884-494a-963d-5a5207f630e3","banner":null,"lang":"en","date_modified":"2025-08-28","date_modified_ts":"2025-08-28T13:20:26Z","date_created":"2025-08-28T13:15:27Z","summary":null,"body":["<article data-history-node-id=\"6745\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-549\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-549<br \/><strong>Date: <\/strong>August\u00a028, 2025<\/p>\n\n<p>On August\u00a027, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.3.1, 18.2.5 and 18.1.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.3.1, 18.2.5 and 18.1.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/08\/27\/patch-release-gitlab-18-3-1-released\/\">GitLab Patch Release: 18.3.1, 18.2.5, 18.1.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-549","alert_type":396,"serial_number":"AV25-549","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6746,"title":"Sangoma FreePBX security advisory (AV25\u2013550)","uuid":"d599bfc7-50df-4e90-a280-c92df415626d","banner":null,"lang":"en","date_modified":"2025-08-29","date_modified_ts":"2025-08-29T14:06:02Z","date_created":"2025-08-29T13:50:06Z","summary":null,"body":["<article data-history-node-id=\"6746\" about=\"\/en\/alerts-advisories\/sangoma-freepbx-security-advisory-av25-550\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-550<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 29, 2025<\/p>\n\n<p>On August 28, 2025, Sangoma FreePBX published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>FreePBX\u00a0\u2013 versions 15 prior to 15.0.66<\/li>\n\t<li>FreePBX\u00a0\u2013 versions 16 prior to 16.0.89<\/li>\n\t<li>FreePBX\u00a0\u2013 versions 17 prior to 17.0.3<\/li>\n<\/ul><p>Open-source reporting has indicated that CVE-2025-57819 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-m42g-xg4c-5f3h\">GitHub - Authentication Bypass Leading to SQL Injection and RCE<\/a><\/li>\n\t<li><a href=\"https:\/\/community.freepbx.org\/t\/security-advisory-please-lock-down-your-administrator-access\/107203\">Security Advisory: Please Lock Down Your Administrator Access<\/a><\/li>\n\t<li><a href=\"https:\/\/community.freepbx.org\/t\/endpointmanager-aug-2025-zero-day\/107215\">Endpointmanager Aug 2025 zero-day<\/a><\/li>\n\t<li><a href=\"https:\/\/gist.github.com\/jfinstrom\/60011630ed586a79f5b9c78313e0d708#file-freepbx-vulnerability-aug-2026-md\">FreePBX Endpoint Zero-Day \u2014 incident note, detection and remediation checklist<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sangoma-freepbx-security-advisory-av25-550","alert_type":396,"serial_number":"AV25-550","subject":"other","moderation_state":"published","external_url":null},{"nid":6747,"title":"Microsoft Edge security advisory (AV25-551)","uuid":"070cb873-5ec6-469d-b9a3-ee9bc32d51f2","banner":null,"lang":"en","date_modified":"2025-08-29","date_modified_ts":"2025-08-29T14:18:20Z","date_created":"2025-08-29T14:09:06Z","summary":null,"body":["<article data-history-node-id=\"6747\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-551\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-551<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>August 29, 2025<\/p>\n\n<p>On August 28, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 139.0.3405.125<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-28-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-551","alert_type":396,"serial_number":"AV25-551","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6748,"title":"Ubuntu security advisory (AV25-552)","uuid":"55ebf420-03ec-4f56-ae7e-231019296f76","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T13:53:36Z","date_created":"2025-09-02T13:45:58Z","summary":null,"body":["<article data-history-node-id=\"6748\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-552\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-552<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 2, 2025<\/p>\n\n<p>Between August 25 to 31, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-552","alert_type":396,"serial_number":"AV25-552","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6750,"title":"[Control systems] CISA ICS security advisories (AV25-554)","uuid":"a203beb3-e2d3-4a56-a345-20255a660783","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T14:38:24Z","date_created":"2025-09-02T14:15:15Z","summary":null,"body":["<article data-history-node-id=\"6750\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-554\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-554<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 2, 2025<\/p>\n\n<p>Between August 25 and 31, 2025, CISA published ICS advisories to highlight vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics COMMGR\u00a0- versions v2.9.0 and prior<\/li>\n\t<li>Delta Electronics CNCSoft-G2\u00a0- versions v2.1.0.20 and prior<\/li>\n\t<li>GE Vernova CIMPLICITY\u00a0\u2013 versions 2024, 2023, 2022, 11.0<\/li>\n\t<li>INVT HMITool\u00a0\u2013 version 7.1.011<\/li>\n\t<li>INVT VT-Designer\u00a0\u2013 version 2.1.13<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F Series CPU Module\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Schneider Electric Modicon M340 Controller and Communication Modules\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Schneider Electric Saitel DR Remote Terminal Unit\u00a0\u2013 versions 11.06.29 and prior<\/li>\n\t<li>Schneider Electric Saitel DP Remote Terminal Unit\u00a0\u2013 versions 11.06.34 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-554","alert_type":398,"serial_number":"AV25-554","subject":"ics","moderation_state":"published","external_url":null},{"nid":6749,"title":"Red Hat security advisory (AV25-553)","uuid":"f09e728d-fd71-4e4e-8916-75a19f3569f0","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T14:20:32Z","date_created":"2025-09-02T14:16:45Z","summary":null,"body":["<article data-history-node-id=\"6749\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-553\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-553<br \/><strong>Date: <\/strong>September\u00a02, 2025<\/p>\n\n<p>Between August\u00a025 and 31, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-553","alert_type":396,"serial_number":"AV25-553","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6752,"title":"HashiCorp security advisory (AV25-555)","uuid":"25c3a572-597a-4522-ae21-026e9854a3cb","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T15:22:24Z","date_created":"2025-09-02T15:18:08Z","summary":null,"body":["<article data-history-node-id=\"6752\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av25-555\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-555<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 2, 2025<\/p>\n\n<p>On August 28, 2025, HashiCorp published a security bulletin to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Vault Community\u00a0\u2013 versions 1.15.0 to 1.20.2, 1.19.8, 1.18.13 and 1.16.24<\/li>\n\t<li>Vault Enterprise\u00a0\u2013 versions 1.15.0 to 1.20.2, 1.19.8, 1.18.13 and 1.16.24<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads\/76393\">HCSEC-2025-24\u00a0- Vault Denial of Service Though Complex JSON Payloads<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av25-555","alert_type":396,"serial_number":"AV25-555","subject":"other","moderation_state":"published","external_url":null},{"nid":6754,"title":"IBM security advisory (AV25-557)","uuid":"4b2711b9-f1dc-4559-b914-fc59bccb9f1a","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T15:40:49Z","date_created":"2025-09-02T15:19:39Z","summary":null,"body":["<article data-history-node-id=\"6754\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-557\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-557<br \/><strong>Date: <\/strong>September\u00a02, 2025<\/p>\n\n<p>Between August\u00a025 and 31, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-557","alert_type":396,"serial_number":"AV25-557","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6755,"title":"Dell security advisory (AV25-558)","uuid":"a39c476e-8e67-4899-aeae-4282818cadeb","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T15:41:53Z","date_created":"2025-09-02T15:19:40Z","summary":null,"body":["<article data-history-node-id=\"6755\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-558\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-558<br \/><strong>Date: <\/strong>September\u00a02, 2025<\/p>\n\n<p>Between August\u00a025 and 31, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Avamar Data Store Ge5A\u00a0\u2013 versions prior to 2.24.0<\/li>\n\t<li>Dell Avamar Data Store Ge5A\u00a0\u2013 versions prior to 7.00.00.181<\/li>\n\t<li>Dell ObjectScale\u00a0\u2013 versions prior to 4.1.0.0<\/li>\n\t<li>Dell Networking Products\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Dell NetWorker Runtime Environment (NRE)\u00a0\u2013 versions prior to 17.0.2<\/li>\n\t<li>Dell Private Cloud VMWare\u00a0\u2013 versions prior to 01.01.00.00<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-558","alert_type":396,"serial_number":"AV25-558","subject":"dell","moderation_state":"published","external_url":null},{"nid":6753,"title":"Qualcomm security advisory \u2013 September 2025 monthly rollup (AV25-556)","uuid":"20a3fbcb-967c-439d-b577-5d1d06f0970c","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T15:34:39Z","date_created":"2025-09-02T15:29:53Z","summary":null,"body":["<article data-history-node-id=\"6753\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-september-2025-monthly-rollup-av25-556\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-556<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 2, 2025<\/p>\n\n<p>On September 1, 2025, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/september-2025-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 September<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-september-2025-monthly-rollup-av25-556","alert_type":396,"serial_number":"AV25-556","subject":"other","moderation_state":"published","external_url":null},{"nid":6756,"title":"WhatsApp security advisory (AV25-559)","uuid":"8d91869f-b6cf-4a5d-9920-5ad5ca22155c","banner":null,"lang":"en","date_modified":"2025-09-02","date_modified_ts":"2025-09-02T17:18:47Z","date_created":"2025-09-02T17:05:21Z","summary":null,"body":["<article data-history-node-id=\"6756\" about=\"\/en\/alerts-advisories\/whatsapp-security-advisory-av25-559\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-559<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 2, 2025<\/p>\n\n<p>On August 29, 2025, WhatsApp published a security bulletin to address a vulnerability in the following products:<\/p>\n\n<ul><li>WhatsApp for IoS\u00a0\u2013 versions prior to v2.25.21.73<\/li>\n\t<li>WhatsApp Business for IoS\u00a0\u2013 versions prior to v2.25.21.78<\/li>\n\t<li>WhatsApp for MAC\u00a0\u2013 versions prior to v2.25.21.78<\/li>\n<\/ul><p>The advisory publisher referenced CVE-2025-43300 which Apple has indicated may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.whatsapp.com\/security\/advisories\/2025\/\">WhatsApp Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/whatsapp-security-advisory-av25-559","alert_type":396,"serial_number":"AV25-559","subject":"other","moderation_state":"published","external_url":null},{"nid":6760,"title":"Android security advisory \u2013 September 2025 monthly rollup (AV25-560)","uuid":"4252e75d-e815-46e8-91e8-fb2973538f8f","banner":null,"lang":"en","date_modified":"2025-09-03","date_modified_ts":"2025-09-03T17:54:55Z","date_created":"2025-09-03T17:47:38Z","summary":null,"body":["<article data-history-node-id=\"6760\" about=\"\/en\/alerts-advisories\/android-security-advisory-september-2025-monthly-rollup-av25-560\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-560<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 3, 2025<\/p>\n\n<p>On September 2, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>Google has indicated that CVE-2025-38352 and CVE-2025-48543 may be under limited, targeted exploitation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-09-01?hl=fr\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-september-2025-monthly-rollup-av25-560","alert_type":396,"serial_number":"AV25-560","subject":"android","moderation_state":"published","external_url":null},{"nid":6761,"title":"Google Chrome security advisory (AV25-561)","uuid":"73a2a7d3-8a99-4899-a8d9-b7401b63ab0b","banner":null,"lang":"en","date_modified":"2025-09-03","date_modified_ts":"2025-09-03T18:29:12Z","date_created":"2025-09-03T18:23:34Z","summary":null,"body":["<article data-history-node-id=\"6761\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-561\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-561<br \/><strong>Date: <\/strong>September\u00a03, 2025<\/p>\n\n<p>On September\u00a02, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 140.0.7339.80\/81 (Windows\/Mac) and 140.0.7339.80 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/09\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-561","alert_type":396,"serial_number":"AV25-561","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6762,"title":"Cisco security advisory (AV25-562)","uuid":"42d56db3-f145-46a8-b152-8c45a07bc801","banner":null,"lang":"en","date_modified":"2025-09-03","date_modified_ts":"2025-09-03T19:13:10Z","date_created":"2025-09-03T19:00:02Z","summary":null,"body":["<article data-history-node-id=\"6762\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-562\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-562<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 3, 2025<\/p>\n\n<p>On September 3, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Desk Phone 9800 Series<\/li>\n\t<li>Cisco EPNM<\/li>\n\t<li>Cisco IP Phone 7800 Series<\/li>\n\t<li>Cisco IP Phone 8800 Series<\/li>\n\t<li>Cisco Prime Infrastructure<\/li>\n\t<li>Cisco Unified CM IM&amp;P<\/li>\n\t<li>Cisco Unified CM SME<\/li>\n\t<li>Cisco Unified CM<\/li>\n\t<li>Cisco Video Phone 8875<\/li>\n\t<li>Cisco Webex Meetings<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-562","alert_type":396,"serial_number":"AV25-562","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6763,"title":"Drupal security advisory (AV25-563)","uuid":"0d23c3f0-9bff-4edf-940e-775ba3fec4cb","banner":null,"lang":"en","date_modified":"2025-09-04","date_modified_ts":"2025-09-04T12:58:51Z","date_created":"2025-09-04T12:52:34Z","summary":null,"body":["<article data-history-node-id=\"6763\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-563\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-563<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 4, 2025<\/p>\n\n<p>On September 3, 2025, Drupal published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Acquia DAM\u00a0\u2013 versions prior to 1.1.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-105\">Acquia DAM\u00a0- Moderately critical\u00a0- Access bypass, Information Disclosure - SA-CONTRIB-2025-105<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-563","alert_type":396,"serial_number":"AV25-563","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6764,"title":"Jenkins security advisory (AV25-564)","uuid":"33148b54-8110-4352-bb0f-2cefa3f3112d","banner":null,"lang":"en","date_modified":"2025-09-04","date_modified_ts":"2025-09-04T13:12:39Z","date_created":"2025-09-04T13:06:11Z","summary":null,"body":["<article data-history-node-id=\"6764\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-564\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-564<br \/><strong>Date: <\/strong>September\u00a04, 2025<\/p>\n\n<p>On September\u00a03, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Git Client Plugin\u00a0\u2013 version 6.3.2 and prior<\/li>\n\t<li>Jakarta Mail API Plugin\u00a0\u2013 version 2.1.3-2 and prior<\/li>\n\t<li>Global-build-stats Plugin\u00a0\u2013 version 322.v22f4db_18e2dd and prior<\/li>\n\t<li>OpenTelemetry Plugin\u00a0\u2013 version 3.1543.v8446b_92b_cd64 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-09-03\/\">Jenkins Security Advisory 2025-09-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-564","alert_type":396,"serial_number":"AV25-564","subject":"other","moderation_state":"published","external_url":null},{"nid":6765,"title":"VMware security advisory (AV25-565)","uuid":"5fa663eb-eee2-41db-9438-ba0c6afc332a","banner":null,"lang":"en","date_modified":"2025-09-04","date_modified_ts":"2025-09-04T14:11:30Z","date_created":"2025-09-04T13:59:49Z","summary":null,"body":["<article data-history-node-id=\"6765\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-565\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-565<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 4, 2025<\/p>\n\n<p>Between September 2 and 3, 2025, VMware published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Tanzu Greenplum\u00a0\u2013 version prior to 7.5.4<\/li>\n\t<li>Tanzu Platform for Cloud Foundry\u00a0\u2013 version prior to 10.0.9<\/li>\n\t<li>Tanzu Platform for Cloud Foundry\u00a0\u2013 version prior to 10.2.2+LTS-T<\/li>\n\t<li>Tanzu Platform for Cloud Foundry\u00a0\u2013 version prior to 6.0.19+LTS-T<\/li>\n\t<li>VMware Tanzu GemFire Management Console\u00a0\u2013 version prior to 4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36075\">Product Release Advisory\u00a0- Tanzu Platform for Cloud Foundry 10.0.9<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36076\">Product Release Advisory\u00a0- Tanzu Platform for Cloud Foundry 10.2.2+LTS-T<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36077\">Product Release Advisory\u00a0- Tanzu Platform for Cloud Foundry 6.0.19+LTS-T<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36085\">Product Release Advisory\u00a0- VMware Tanzu GemFire Management Console 1.4.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36086\">Product Release Advisory\u00a0- VMware Tanzu Greenplum 7.5.4<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-565","alert_type":396,"serial_number":"AV25-565","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6766,"title":"Atlassian security advisory (AV25-566)","uuid":"e4d1a5ae-0997-4e70-bc4e-31163072627b","banner":null,"lang":"en","date_modified":"2025-09-04","date_modified_ts":"2025-09-04T14:22:41Z","date_created":"2025-09-04T14:17:52Z","summary":null,"body":["<article data-history-node-id=\"6766\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-566\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-566<br \/><strong>Date: <\/strong>September\u00a04, 2025<\/p>\n\n<p>On August\u00a019, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-august-19-2025-1621491738.html\">Security Bulletin\u00a0- August 19 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-566","alert_type":396,"serial_number":"AV25-566","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6767,"title":"HPE security advisory (AV25-567)","uuid":"54c77e62-5a29-4b8c-a641-97c8d5b87a11","banner":null,"lang":"en","date_modified":"2025-09-04","date_modified_ts":"2025-09-04T15:26:59Z","date_created":"2025-09-04T15:15:15Z","summary":null,"body":["<article data-history-node-id=\"6767\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-567\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-567<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 4, 2025<\/p>\n\n<p>On September 3, 2025, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE M-Series Switches Using NVIDIA Cumulus\u00a0\u2013 versions prior to 5.9.2 and 5.11.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docLocale=en_US&amp;docId=hpesbst04945en_us#hpesbst04945-rev-1-hpe-m-series-switches-using-nvi-0\">HPESBST04945 rev.1\u00a0- HPE M-Series Switches Using NVIDIA Cumulus Software, Local Escalation of Privilege Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-567","alert_type":396,"serial_number":"AV25-567","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6769,"title":"Sitecore security advisory (AV25-568)","uuid":"db29209b-9f24-4fdb-a847-62b4925756b1","banner":null,"lang":"en","date_modified":"2025-09-05","date_modified_ts":"2025-09-05T13:11:28Z","date_created":"2025-09-05T12:50:05Z","summary":null,"body":["<article data-history-node-id=\"6769\" about=\"\/en\/alerts-advisories\/sitecore-security-advisory-av25-568\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-568<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 5, 2025<\/p>\n\n<p>On September 3, 2025, Sitecore published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Sitecore Experience Manager (XM)\u00a0\u2013 version 9.0 and prior<\/li>\n\t<li>Sitecore Experience Platform (XP)\u00a0\u2013 version 9.0 and prior<\/li>\n\t<li>Sitecore Experience Commerce (XC)\u00a0\u2013 version 9.0 and prior<\/li>\n\t<li>Sitecore Managed Cloud\u00a0\u2013 version 9.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sitecore.com\/kb?id=kb_article_view&amp;sysparm_article=KB1003865\">Security Bulletin SC2025-005<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sitecore-security-advisory-av25-568","alert_type":396,"serial_number":"AV25-568","subject":"other","moderation_state":"published","external_url":null},{"nid":6775,"title":"Dell security advisory (AV25-570)","uuid":"22d633e5-f5c8-4b20-b79c-45261abab83f","banner":null,"lang":"en","date_modified":"2025-09-08","date_modified_ts":"2025-09-08T14:26:50Z","date_created":"2025-09-08T14:10:18Z","summary":null,"body":["<article data-history-node-id=\"6775\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-570\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-570<br \/><strong>Date: <\/strong>September\u00a08, 2025<\/p>\n\n<p>Between September\u00a01 and 7, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Enterprise SONiC Distribution\u00a0\u2013 versions prior to 4.4.3<\/li>\n\t<li>Dell Inspiron 14 5441 and 14 7441\u00a0\u2013 versions prior to 31.0.114.0<\/li>\n\t<li>Dell Latitude 5455 and 7455\u00a0\u2013 versions prior to 31.0.114.0<\/li>\n\t<li>Dell PowerEdge Server\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell PowerStore T\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell ThinOS\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell XPS 13 9345\u00a0\u2013 versions prior to 31.0.114.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000363985\/dsa-2025-280-security-update-for-dell-client-platform-for-qualcomm-adreno-gpu-display-driver-vulnerability\">DSA-2025-280: Security Update for Dell Client Platform for Qualcomm Adreno GPU Display Driver Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000364434\/dsa-2025-341\">DSA-2025-341: Security Update for Dell ThinOS for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000364547\/dsa-2025-342-dell-powerstore-t-security-update-for-multiple-vulnerabilities\">DSA-2025-342: Dell PowerStore T Security Update for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000364903\/dsa-2025-337-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities\">DSA-2025-337: Security Update for Dell Enterprise SONiC Distribution Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000364913\/dsa-2025-297-security-update-for-dell-poweredge-server-for-intel-2025-security-advisories-2025-3-ipu\">DSA-2025-297: Security Update for Dell PowerEdge Server for Intel 2025 Security Advisories (2025.3 IPU)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-570","alert_type":396,"serial_number":"AV25-570","subject":"dell","moderation_state":"published","external_url":null},{"nid":6774,"title":"IBM security advisory (AV25-569)","uuid":"96a1127d-dfd7-4e8d-b4c5-446a7ca5a695","banner":null,"lang":"en","date_modified":"2025-09-08","date_modified_ts":"2025-09-08T14:14:06Z","date_created":"2025-09-08T14:10:18Z","summary":null,"body":["<article data-history-node-id=\"6774\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-569\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-569<br \/><strong>Date:<\/strong> September\u00a08, 2025<\/p>\n\n<p>Between September\u00a01 and 7, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-569","alert_type":396,"serial_number":"AV25-569","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6776,"title":"Ubuntu security advisory (AV25-571)","uuid":"e59407b0-dcba-4bab-9b05-ccad680eeec9","banner":null,"lang":"en","date_modified":"2025-09-08","date_modified_ts":"2025-09-08T15:40:11Z","date_created":"2025-09-08T15:22:55Z","summary":null,"body":["<article data-history-node-id=\"6776\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-571\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-571<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><\/p>\n\n<p><strong>Date: <\/strong>September 8, 2025<\/p>\n\n<p>Between September 1 and 7, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7727-3\">USN-7727-3: Linux kernel (AWS) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7726-4\">USN-7726-4: Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7725-2\">USN-7725-2: Linux kernel (Real-time) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-571","alert_type":396,"serial_number":"AV25-571","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6777,"title":"Red Hat security advisory (AV25-572)","uuid":"ade2bee7-4bc5-4ee0-901d-6ae7901e5636","banner":null,"lang":"en","date_modified":"2025-09-08","date_modified_ts":"2025-09-08T16:07:32Z","date_created":"2025-09-08T15:49:58Z","summary":null,"body":["<article data-history-node-id=\"6777\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-572\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-572<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 8, 2025<\/p>\n\n<p>Between September 1 and 7, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-572","alert_type":396,"serial_number":"AV25-572","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6778,"title":"Microsoft Edge security advisory (AV25-573)","uuid":"a8177d18-073a-42e9-8142-b472635e258d","banner":null,"lang":"en","date_modified":"2025-09-08","date_modified_ts":"2025-09-08T16:32:30Z","date_created":"2025-09-08T16:13:37Z","summary":null,"body":["<article data-history-node-id=\"6778\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-573\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-573<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 8, 2025<\/p>\n\n<p>On September 5, 2025, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft<\/span> published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 140.0.3485.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-5-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-573","alert_type":396,"serial_number":"AV25-573","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6779,"title":"[Control systems] CISA ICS security advisories (AV25\u2013574)","uuid":"c2992f98-05a8-4908-8947-78df023ee249","banner":null,"lang":"en","date_modified":"2025-09-08","date_modified_ts":"2025-09-08T17:22:17Z","date_created":"2025-09-08T16:36:08Z","summary":null,"body":["<article data-history-node-id=\"6779\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-574\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-574<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 8, 2025<\/p>\n\n<p>Between September 1 and 7, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics EIP Builder\u00a0\u2013 versions prior to 1.11<\/li>\n\t<li>Fuji Electric FRENIC-Loader 4\u00a0\u2013 versions prior to 1.4.0.1<\/li>\n\t<li>Honeywell OneWireless WDM\u00a0\u2013 versions prior to R322.5<\/li>\n\t<li>Honeywell OneWireless WDM\u00a0\u2013 versions prior to R331.1<\/li>\n\t<li>SunPower PVS6\u00a0\u2013 version 2025.06 build 61839 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-245-01\">Delta Electronics EIP Builder<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-245-02\">Fuji Electric FRENIC-Loader 4<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-245-03\">SunPower PVS6<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-25-247-01\">Honeywell OneWireless Wireless Device Manager (WDM)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-574","alert_type":398,"serial_number":"AV25-574","subject":"ics","moderation_state":"published","external_url":null},{"nid":6780,"title":"VMware security advisory (AV25-575)","uuid":"44abe562-815d-422f-b3b5-5c1185a5da38","banner":null,"lang":"en","date_modified":"2025-09-08","date_modified_ts":"2025-09-08T19:39:40Z","date_created":"2025-09-08T19:32:36Z","summary":null,"body":["<article data-history-node-id=\"6780\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-575\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-575<br \/><strong>Date: <\/strong>September 8, 2025<\/p>\n\n<p>Between September 3 and 4, 2025, VMware published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-575","alert_type":396,"serial_number":"AV25-575","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6781,"title":"SAP security advisory \u2013 September 2025 monthly rollup (AV25-576)","uuid":"37f9c541-4e34-46b4-84d7-2720e565ddf8","banner":null,"lang":"en","date_modified":"2025-09-09","date_modified_ts":"2025-09-09T13:59:18Z","date_created":"2025-09-09T13:35:49Z","summary":null,"body":["<article data-history-node-id=\"6781\" about=\"\/en\/alerts-advisories\/sap-security-advisory-september-2025-monthly-rollup-av25-576\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-576<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 9, 2025<\/p>\n\n<p>On September 9, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP NetWeaver (RMI-P4)\u00a0\u2013 version SERVERCORE 7.50<\/li>\n\t<li>SAP NetWeaver AS Java (Deploy Web Service)\u00a0\u2013 version J2EE-APPS 7.50<\/li>\n\t<li>SAP NetWeaver AS for ABAP and ABAP Platform\u00a0\u2013 versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756 and 757<\/li>\n\t<li>SAP NetWeaver\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53 and 7.54<\/li>\n\t<li>SAP Business One (SLD)\u00a0\u2013 versions B1_ON_HANA 10.0 and SAP-M-BO 10.0<\/li>\n\t<li>SAP Landscape Transformation Replication Server\u00a0\u2013 versions DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731 and 2011_1_752, 2020<\/li>\n\t<li>SAP S\/4HANA (Private Cloud or On-Premise)\u00a0\u2013 versions S4CORE 102, 103, 104, 105, 106, 107 and 108<\/li>\n\t<li>SAP NetWeaver and ABAP Platform (Service Data Collection)\u00a0\u2013 versions ST-PI 2008_1_700, 2008_1_710 et 740<\/li>\n\t<li>SAP Commerce Cloud and SAP Datahub\u00a0\u2013 versions HY_COM 2205, HY_DHUB 2205, COM_CLOUD 2211 and DHUB_CLOUD 2211<\/li>\n\t<li>SAP Business Planning and Consolidation\u00a0\u2013 versions BPC4HANA 200, 300, SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 914 and CPMBPC 810<\/li>\n\t<li>SAP HCM (My Timesheet Fiori 2.0 application)\u00a0\u2013 version GBX01HR5 605<\/li>\n\t<li>SAP HCM (Approve Timesheets Fiori 2.0 application)\u00a0\u2013 version GBX01HR5 605<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform\u00a0\u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP Supplier Relationship Management\u00a0\u2013 versions SRM_SERVER 700, 701, 702, 713 and 714<\/li>\n\t<li>SAP NetWeaver ABAP Platform\u00a0\u2013 versions S4CRM 100, 200, 204, 205, 206, S4CEXT 109, BBPCRM 713 and 714<\/li>\n\t<li>Fiori app (Manage Payment Blocks)\u00a0\u2013 versions S4CORE 107 and 108<\/li>\n\t<li>SAP NetWeaver Application Server Java\u00a0\u2013 version WD-RUNTIME 7.50<\/li>\n\t<li>SAP NetWeaver (Service Data Download)\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SAP NetWeaver AS Java (IIOP Service)\u00a0\u2013 version SERVERCORE 7.50<\/li>\n\t<li>SAP Fiori App (F4044 Manage Work Center Groups)\u00a0\u2013 versions UIS4HOP1 600, 700, 800 and 900<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP (Background Processing)\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>SAP Fiori (Launchpad)\u00a0\u2013 version SAP_UI 754<\/li>\n\t<li>SAP NetWeaver AS Java (Adobe Document Service)\u00a0\u2013 version ADSSAP 7.50<\/li>\n\t<li>SAP Commerce Cloud\u00a0\u2013 versions HY_COM 2205 and COM_CLOUD 2211<\/li>\n<\/ul><p>The Cyber Centre is aware of reports that CVE-2025-42957 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-42957\">NVD\u00a0- CVE-2025-42957<\/a><\/li>\n\t<li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/september-2025.html\">SAP Security Patch Day\u00a0- September 2025<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-september-2025-monthly-rollup-av25-576","alert_type":396,"serial_number":"AV25-576","subject":"sap","moderation_state":"published","external_url":null},{"nid":6782,"title":"HPE security advisory (AV25-577)","uuid":"a7221713-881b-4043-a42a-cc90901851f8","banner":null,"lang":"en","date_modified":"2025-09-09","date_modified_ts":"2025-09-09T14:15:43Z","date_created":"2025-09-09T14:04:36Z","summary":null,"body":["<article data-history-node-id=\"6782\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-577\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-577<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 9, 2025<\/p>\n\n<p>On September 8, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Telco Intelligent Assurance FAS and PDO\u00a0\u2013 versions prior to 4.2.8<\/li>\n\t<li>HPE Intelligent Assurance Telco INT-A FAS and PDO\u00a0\u2013 versions prior to v4.2.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04832en_us&amp;docLocale=en_US#hpesbnw04832-rev-1-hpe-telco-intelligent-assurance-0\">HPESBNW04832 rev.1\u00a0- HPE Telco Intelligent Assurance, Multiple Netty Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04767en_us&amp;docLocale=en_US#hpesbnw04767-rev-1-hpe-intelligent-assurance-using-0\">HPESBNW04767 rev.1\u00a0- HPE Intelligent Assurance Using Apache, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-577","alert_type":396,"serial_number":"AV25-577","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6783,"title":"[Control systems] Schneider Electric security advisory (AV25-578)","uuid":"6037e3c4-dc05-450f-acbd-61c5149686c7","banner":null,"lang":"en","date_modified":"2025-09-09","date_modified_ts":"2025-09-09T14:35:33Z","date_created":"2025-09-09T14:21:44Z","summary":null,"body":["<article data-history-node-id=\"6783\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-578\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-578<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 9, 2025<\/p>\n\n<p>On September 9, 2025, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ATS490 Altivar Soft Starter\u00a0\u2013 all versions<\/li>\n\t<li>ATS490 Altivar Soft Starter\u00a0\u2013 all versions<\/li>\n\t<li>ATV340E Altivar Machine Drives\u00a0\u2013 all versions<\/li>\n\t<li>ATV340E Altivar Machine Drives\u00a0\u2013 all versions<\/li>\n\t<li>ATV6000 Medium Voltage Altivar Process Drives\u00a0\u2013 all versions<\/li>\n\t<li>ATV6000 Medium Voltage Altivar Process Drives\u00a0\u2013 all versions<\/li>\n\t<li>ATV630\/650\/660\/680\/6A0\/6B0\/6L0 Altivar Process Drives\u00a0\u2013 all versions<\/li>\n\t<li>ATV630\/650\/660\/680\/6A0\/6B0\/6L0 Altivar Process Drives\u00a0\u2013 all versions<\/li>\n\t<li>ATV930\/950\/955\/960\/980\/9A0\/9B0\/9L0\/991\/992\/993 Altivar Process Drives\u00a0\u2013 all versions<\/li>\n\t<li>ATV930\/950\/955\/960\/980\/9A0\/9B0\/9L0\/991\/992\/993 Altivar Process Drives\u00a0\u2013 all versions<\/li>\n\t<li>ILC992 InterLink Converter\u00a0\u2013 all versions<\/li>\n\t<li>ILC992 InterLink Converter\u00a0\u2013 all versions<\/li>\n\t<li>Saitel DP RTU\u00a0\u2013 versions 11.06.33 and prior<\/li>\n\t<li>Saitel DR RTU\u00a0\u2013 versions 11.06.29 and prior<\/li>\n\t<li>VW3A3530D: ATVdPAC module\u00a0\u2013 versions prior to v25.0<\/li>\n\t<li>VW3A3530D: ATVdPAC module\u00a0\u2013 versions prior to v25.0<\/li>\n\t<li>VW3A3720 &amp; VW3A3721 Altivar Process Communication Modules\u00a0\u2013 all versions<\/li>\n\t<li>VW3A3720 &amp; VW3A3721 Altivar Process Communication Modules\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-252-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-252-01.pdf\">Multiple Altivar Process Drives and Communication Modules<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-252-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-252-02.pdf\">Saitel DR &amp; Saitel DP Remote Terminal Unit<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-252-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-252-01.pdf\">Multiple Altivar Process Drives and Communication Modules<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-578","alert_type":398,"serial_number":"AV25-578","subject":"other","moderation_state":"published","external_url":null},{"nid":6784,"title":"[Control systems] Siemens security advisory (AV25-579) ","uuid":"7ad5b959-6777-444e-9d55-d61cd1cacc7f","banner":null,"lang":"en","date_modified":"2025-09-09","date_modified_ts":"2025-09-09T14:51:08Z","date_created":"2025-09-09T14:42:00Z","summary":null,"body":["<article data-history-node-id=\"6784\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-579\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-579<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 9, 2025<\/p>\n\n<p>On September 9, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>APOGEE PXC Series (BACnet)\u00a0\u2013 all versions<\/li>\n\t<li>APOGEE PXC Series (P2 Ethernet)\u00a0\u2013 all versions<\/li>\n\t<li>Industrial Edge Management OS (IEM-OS)\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC Technology Package TPCamGen (6ES7823-0FE30-1AA0)\u00a0\u2013 all versions<\/li>\n\t<li>SIMATIC Virtualization as a Service (SIVaaS)\u00a0\u2013 all versions<\/li>\n\t<li>SIMOTION OA MIIF (6AU1820-3DA20-0AB0)\u00a0\u2013 all versions<\/li>\n\t<li>SIMOTION OACAMGEN (6AU1820-3EA20-0AB0)\u00a0\u2013 all versions<\/li>\n\t<li>SIMOTION OALECO (6AU1820-3HA20-0AB0)\u00a0\u2013 all versions<\/li>\n\t<li>SIMOTION OAVIBX (6AU1820-3CA20-0AB0)\u00a0\u2013 all versions<\/li>\n\t<li>SINAMICS G220 V6.4\u00a0\u2013 all versions<\/li>\n\t<li>SINAMICS S200 V6.4\u00a0\u2013 all versions<\/li>\n\t<li>SINAMICS S210 V6.4\u00a0- all versions<\/li>\n\t<li>TALON TC Series (BACnet)\u00a0\u2013 all versions<\/li>\n\t<li>User Management Component (UMC)\u00a0\u2013 versions prior to V2.15.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-579","alert_type":398,"serial_number":"AV25-579","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6785,"title":"Fortinet security advisory (AV25-580)","uuid":"d0aa24f2-1dfe-4728-bc32-981da69ef27d","banner":null,"lang":"en","date_modified":"2025-09-09","date_modified_ts":"2025-09-09T18:28:31Z","date_created":"2025-09-09T18:04:06Z","summary":null,"body":["<article data-history-node-id=\"6785\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-580\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-580<br \/><strong>Date: <\/strong>September\u00a09, 2025<\/p>\n\n<p>On September\u00a09, 2025, Fortinet published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>FortiWeb 7.6\u00a0\u2013 versions 7.6.0 to 7.6.4<\/li>\n\t<li>FortiWeb 7.4\u00a0\u2013 versions 7.4.0 to 7.4.8<\/li>\n\t<li>FortiWeb 7.2\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiWeb 7.0\u00a0\u2013 versions 7.0.2 to 7.0.11<\/li>\n\t<li>FortiDDoS-F 7.0\u00a0\u2013 versions 7.0.0 to 7.0.2<\/li>\n\t<li>FortiDDoS-F 6.1, 6.2, 6.3, 6.4, 6.5, 6.6\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-512\">Fortinet PSIRT\u00a0- FG-IR-25-512<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-24-344\">Fortinet PSIRT\u00a0- FG-IR-24-344<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-580","alert_type":396,"serial_number":"AV25-580","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6786,"title":"Ivanti security advisory (AV25-581)","uuid":"f8c2621c-17da-4626-a45d-45e86fa68924","banner":null,"lang":"en","date_modified":"2025-09-09","date_modified_ts":"2025-09-09T19:09:03Z","date_created":"2025-09-09T18:04:07Z","summary":null,"body":["<article data-history-node-id=\"6786\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-581\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-581<br \/><strong>Date: <\/strong>September\u00a09, 2025<\/p>\n\n<p>On September\u00a09, 2025, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Endpoint Manager\u00a0\u2013 version 2022 SU8 Security Update 1 and prior<\/li>\n\t<li>Ivanti Endpoint Manager\u00a0\u2013 version 2024 SU3 and prior<\/li>\n\t<li>Ivanti Connect Secure\u00a0\u2013 version 22.7R2.8 and prior<\/li>\n\t<li>Ivanti Policy Secure\u00a0\u2013 version 22.7R1.4 and prior<\/li>\n\t<li>ZTA Gateways\u00a0\u2013 version 22.8R2.2<\/li>\n\t<li>Neurons for Secure Access\u00a0\u2013 version 22.8R1.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/kA1UL0000006Har0AE\">Security Advisory September 2025 for Ivanti EPM 2024 SU3 and EPM 2022 SU8<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/kA1UL0000006G8X0AU\">September Security Advisory Ivanti Connect Secure, Policy Secure, ZTA Gateways and Neurons for Secure Access (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-581","alert_type":396,"serial_number":"AV25-581","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6787,"title":"Microsoft security advisory \u2013 September 2025 monthly rollup (AV25-582)","uuid":"579dac3d-1bf9-4432-bfae-dc12265ed72b","banner":null,"lang":"en","date_modified":"2025-09-09","date_modified_ts":"2025-09-09T20:31:42Z","date_created":"2025-09-09T20:15:26Z","summary":null,"body":["<article data-history-node-id=\"6787\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2025-monthly-rollup-av25-582\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-582<br \/><strong>Date: <\/strong>September 9, 2025<\/p>\n\n<p>On September 9, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Azure Bot Service<\/li>\n\t<li>Azure Connected Machine Agent<\/li>\n\t<li>Azure Networking<\/li>\n\t<li>Dynamics 365<\/li>\n\t<li>Microsoft 365<\/li>\n\t<li>Microsoft AutoUpdate for Mac<\/li>\n\t<li>Microsoft Entra ID<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft HPC<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Microsoft OfficePLUS<\/li>\n\t<li>Microsoft PowerPoint<\/li>\n\t<li>Microsoft SQL Server<\/li>\n\t<li>Microsoft SharePoint<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Server 2008<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Sep\">September 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2025-monthly-rollup-av25-582","alert_type":396,"serial_number":"AV25-582","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6788,"title":"Adobe security advisory (AV25-583) - Update 1","uuid":"24c95c26-b091-4093-9c59-31bf068d1279","banner":null,"lang":"en","date_modified":"2025-10-23","date_modified_ts":"2025-10-23T15:13:39Z","date_created":"2025-09-10T15:46:16Z","summary":null,"body":["<article data-history-node-id=\"6788\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-583\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-583<br \/><strong>Date: <\/strong>September 10, 2025<br \/><strong>Updated: <\/strong>October 23, 2025<\/p>\n\n<p>On September\u00a09, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat DC\u00a0\u2013 version Win\u00a0\u2013 25.001.20672, Mac\u00a0\u2013 25.001.20668 and prior<\/li>\n\t<li>Acrobat Reader DC\u00a0\u2013 version Win\u00a0\u2013 25.001.20672, Mac\u00a0\u2013 25.001.20668 and prior<\/li>\n\t<li>Acrobat 2024\u00a0\u2013 version Win &amp; Mac\u00a0\u2013 24.001.30254 and prior<\/li>\n\t<li>Acrobat 2020\u00a0\u2013 version Win &amp; Mac\u00a0\u2013 20.005.30774 and prior<\/li>\n\t<li>Acrobat Reader 2020\u00a0\u2013 version Win &amp; Mac\u00a0\u2013 20.005.30774 and prior<\/li>\n\t<li>Adobe After Effects\u00a0\u2013 version 24.6.7 and prior<\/li>\n\t<li>Adobe After Effects\u00a0\u2013 version 25.3 and prior<\/li>\n\t<li>Adobe Premiere Pro\u00a0\u2013 version 25.3 and prior<\/li>\n\t<li>Adobe Premiere Pro\u00a0\u2013 version 24.6.5 and prior<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Commerce B2B\u00a0\u2013 multiple versions<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Substance 3D Viewer\u00a0\u2013 version 0.25.1 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 version AEM Cloud Service (CS)<\/li>\n\t<li>Adobe Experience Manager (AEM) version 6.5 LTS SP1 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 version 6.5.23 and prior<\/li>\n\t<li>Adobe Dreamweaver\u00a0\u2013 version 21.5 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler\u00a0\u2013 version 1.22.2 and prior<\/li>\n\t<li>ColdFusion 2025\u00a0\u2013 version Update 3 and prior<\/li>\n\t<li>ColdFusion 2023\u00a0\u2013 version Update 15 and prior<\/li>\n\t<li>ColdFusion 2021\u00a0\u2013 version Update 21 and prior<\/li>\n<\/ul><p><strong>Update 1<\/strong><\/p>\n\n<p>On October 22, 2025, the Cyber Centre became aware of open-source reporting that CVE-2025-54236 affecting Adobe Commerce is being actively exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sansec.io\/research\/sessionreaper-exploitation\">SessionReaper attacks have started, 3 in 5 stores still vulnerable<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb25-88.html\">Adobe Commerce\u00a0|\u00a0APSB25-88<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb25-93.html\">Adobe ColdFusion\u00a0|\u00a0APSB25-93<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-583","alert_type":396,"serial_number":"AV25-583","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6789,"title":"GitLab security advisory (AV25-584)","uuid":"19cffbdb-7ef6-493e-a0b3-75f81246ef6c","banner":null,"lang":"en","date_modified":"2025-09-10","date_modified_ts":"2025-09-10T16:05:58Z","date_created":"2025-09-10T15:46:17Z","summary":null,"body":["<article data-history-node-id=\"6789\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-584\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-584<br \/><strong>Date: <\/strong>September\u00a010, 2025<\/p>\n\n<p>On September\u00a010, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.3.2, 18.2.6 and 18.1.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.3.2, 18.2.6 and 18.1.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/09\/10\/patch-release-gitlab-18-3-2-released\/\">GitLab Patch Release: 18.3.2, 18.2.6, 18.1.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-584","alert_type":396,"serial_number":"AV25-584","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6793,"title":"Palo Alto Networks security advisory (AV25-587)","uuid":"e94f44a6-d05c-4a63-98e8-a118f8710bfb","banner":null,"lang":"en","date_modified":"2025-09-11","date_modified_ts":"2025-09-11T13:16:39Z","date_created":"2025-09-11T12:26:25Z","summary":null,"body":["<article data-history-node-id=\"6793\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-587\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-587<br \/><strong>Date: <\/strong>September\u00a011, 2025<\/p>\n\n<p>On September\u00a010, 2025, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cortex XDR Microsoft 365 Defender Pack 4.6.0 windows\u00a0\u2013 versions prior to 4.6.5<\/li>\n\t<li>User-ID Credential Agent 11.0.0 Windows\u00a0\u2013 versions prior to 11.0.2-133<\/li>\n\t<li>User-ID Credential Agent 11.0.0 Windows\u00a0\u2013 versions prior to 11.0.3<\/li>\n\t<li>Prisma Access Browser\u00a0\u2013 version prior to 139.12.4.128<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-4234\">CVE-2025-4234 Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-4235\">CVE-2025-4235 User-ID Credential Agent: Cleartext Exposure of Service Account password<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0015\">PAN-SA-2025-0015 Chromium: Monthly Vulnerability Update (September 2025)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-587","alert_type":396,"serial_number":"AV25-587","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6792,"title":"GitHub security advisory (AV25-586)","uuid":"3ce7fa21-0733-46f8-8d9e-5ed43568dbaf","banner":null,"lang":"en","date_modified":"2025-09-11","date_modified_ts":"2025-09-11T13:10:31Z","date_created":"2025-09-11T12:26:25Z","summary":null,"body":["<article data-history-node-id=\"6792\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-586\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-586<br \/><strong>Date: <\/strong>September\u00a011, 2025<\/p>\n\n<p>On September\u00a09, 2025, GitHub published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.6<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.9<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.15.x prior to 3.15.13<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.6<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.9<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes\">Enterprise Server 3.15.13<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">Enterprise Server 3.14.18<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-586","alert_type":396,"serial_number":"AV25-586","subject":"other","moderation_state":"published","external_url":null},{"nid":6791,"title":"Cisco security advisory (AV25-585)","uuid":"9e024219-235d-4c2a-931b-f7d37411f459","banner":null,"lang":"en","date_modified":"2025-09-11","date_modified_ts":"2025-09-11T12:50:45Z","date_created":"2025-09-11T12:26:26Z","summary":null,"body":["<article data-history-node-id=\"6791\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-585\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\">\t\n<p><strong>Serial number: <\/strong>AV25-585<br \/><strong>Date: <\/strong>September\u00a011, 2025<\/p>\n\n<p>On September\u00a010, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco IOS XR Software\u00a0\u2013 version 7.10 and prior<\/li>\n\t<li>Cisco IOS XR Software\u00a0\u2013 version 7.11, 24.2, 24.3, 24.4 and 25.1<\/li>\n\t<li>Cisco IOS XR ARP\u00a0\u2013 version 7.11 and prior<\/li>\n\t<li>Cisco IOS XR ARP\u00a0\u2013 version 24.1, 24.2, 24.3, 24.4, 25.1 and 25.2<\/li>\n\t<li>Cisco 8000 Series Routers\u00a0\u2013 all versions<\/li>\n\t<li>Cisco ASR 9000 Series Aggregation Services Routers\u00a0\u2013 version 24.1.1 and prior<\/li>\n\t<li>Cisco IOS XR White box (IOSXRWBD)\u00a0\u2013 version 7.9.1 and prior<\/li>\n\t<li>Cisco OS XRd vRouters\u00a0\u2013 all version<\/li>\n\t<li>Cisco IOS XRv 9000 Routers\u00a0\u2013 version 24.1.1 and prior<\/li>\n\t<li>Cisco Network Convergence Series (NCS) 540 Series Routers (NCS540-iosxr base image)\u00a0\u2013 version 7.9.1 and prior<\/li>\n\t<li>Cisco NCS 540 Series Routers (NCS540L-iosxr base image)\u00a0\u2013 all versions<\/li>\n\t<li>Cisco NCS 560 Series Routers\u00a0\u2013 version 24.2.1 and prior<\/li>\n\t<li>Cisco NCS 1010 Platforms\u00a0\u2013 all versions<\/li>\n\t<li>Cisco NCS 1014 Platforms\u00a0\u2013 all versions<\/li>\n\t<li>Cisco NCS 5500 Series Routers\u00a0\u2013 version 7.9.1 and prior<\/li>\n\t<li>Cisco NCS 5700 Series Routers\u00a0\u2013 version NCS5700 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-acl-packetio-Swjhhbtz\">Cisco IOS XR Software Management Interface ACL Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxr-arp-storm-EjUU55yM\">Cisco IOS XR ARP Broadcast Storm Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-xrsig-UY4zRUCG\">Cisco IOS XR Software Image Verification Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\" https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-585","alert_type":396,"serial_number":"AV25-585","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6797,"title":"Microsoft Edge security advisory (AV25-588)","uuid":"692be70a-17a2-4371-85ab-49998cb51055","banner":null,"lang":"en","date_modified":"2025-09-12","date_modified_ts":"2025-09-12T18:09:00Z","date_created":"2025-09-12T18:01:58Z","summary":null,"body":["<article data-history-node-id=\"6797\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-588\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-588<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 12, 2025<\/p>\n\n<p>On September 11, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 140.0.3485.66<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-11-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-588","alert_type":396,"serial_number":"AV25-588","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6798,"title":"IBM security advisory (AV25-589)","uuid":"a25dda47-038d-4138-bb05-6b367098b745","banner":null,"lang":"en","date_modified":"2025-09-15","date_modified_ts":"2025-09-15T15:11:26Z","date_created":"2025-09-15T14:58:43Z","summary":null,"body":["<article data-history-node-id=\"6798\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-589\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-589<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 15, 2025<\/p>\n\n<p>Between September 8 and 14, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-589","alert_type":396,"serial_number":"AV25-589","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6799,"title":"Dell security advisory (AV25-590)","uuid":"bef005ea-28bb-4c09-a010-5cadfb4322b2","banner":null,"lang":"en","date_modified":"2025-09-15","date_modified_ts":"2025-09-15T15:34:08Z","date_created":"2025-09-15T15:15:23Z","summary":null,"body":["<article data-history-node-id=\"6799\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-590\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-590<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 15, 2025<\/p>\n\n<p>Between September 8 and 14, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Latitude 12 Rugged Extreme 7214 \u2013 versions prior to 1.52.0<\/li>\n\t<li>Dell Latitude 5420 Rugged \u2013 versions prior to 1.40.0<\/li>\n\t<li>Dell Latitude 5424 Rugged \u2013 versions prior to 1.40.0<\/li>\n\t<li>Dell Latitude 7212 Rugged Extreme Tablet \u2013 versions prior to 1.58.0<\/li>\n\t<li>Dell Latitude 7424 Rugged Extreme \u2013 versions prior to 1.40.0<\/li>\n\t<li>Dell PowerProtect Data Manager \u2013 versions prior to 19.21<\/li>\n\t<li>Dell PowerProtect Data Protection Hardware \u2013 versions prior to 2.7.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000367347\/dsa-2025-295-security-update-for-dell-client-platform-for-an-ami-bios-vulnerability\">DSA-2025-295: Security Update for Dell Client Platform for an AMI BIOS Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000367456\/dsa-2025-326-security-update-for-dell-powerprotect-data-manager-multiple-security-vulnerabilities\">DSA-2025-326: Security Update for Dell PowerProtect Data Manager Multiple Security Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000368282\/dsa-2025-300-security-update-for-dell-powerprotect-dp-series-appliance-idpa-multiple-third-party-component-vulnerabilities \">DSA-2025-300: Security Update for Dell PowerProtect DP Series Appliance (IDPA) Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-590","alert_type":396,"serial_number":"AV25-590","subject":"dell","moderation_state":"published","external_url":null},{"nid":6800,"title":"[Control systems] CISA ICS security advisories (AV25\u2013591)","uuid":"6dcdbeeb-85e6-407f-af3d-523bd67cd578","banner":null,"lang":"en","date_modified":"2025-09-15","date_modified_ts":"2025-09-15T15:55:57Z","date_created":"2025-09-15T15:42:24Z","summary":null,"body":["<article data-history-node-id=\"6800\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-591\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-591<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 15, 2025<\/p>\n\n<p>Between September 8 and 14, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB ASPECT-Enterprise ASP-ENT-x \u2013 versions prior to 3.08.04-s01<\/li>\n\t<li>ABB MATRIX Series MAT-x \u2013 versions prior to 3.08.04-s01<\/li>\n\t<li>ABB NEXUS Series NEX-2x \u2013 versions prior to 3.08.04-s01<\/li>\n\t<li>ABB NEXUS Series NEXUS-3-x \u2013 versions prior to 3.08.04-s01<\/li>\n\t<li>Daikin Security Gateway \u2013 version App 100, Frm 214<\/li>\n\t<li>Rockwell Automation 1783-NATR \u2013 versions prior to 1.007<\/li>\n\t<li>Rockwell Automation Analytics LogixAI \u2013 versions 3.00 and 3.01<\/li>\n\t<li>Rockwell Automation CompactLogix 5480 \u2013 version 32-37.011 with Windows package (2.1.0) Win10 v1607<\/li>\n\t<li>Rockwell Automation ControlLogix 5580 \u2013 version 35.013<\/li>\n\t<li>Rockwell Automation FactoryTalk Activation Manager \u2013 version 5.00<\/li>\n\t<li>Rockwell Automation FactoryTalk Optix \u2013 versions 1.5.0 to 1.5.7<\/li>\n\t<li>Rockwell Automation Stratix IOS \u2013 versions 15.2(8)E5 and prior<\/li>\n\t<li>Rockwell Automation ThinManager \u2013 version 13.0 to 14.0<\/li>\n\t<li>Schneider Electric EcoStruxure Server\/workstation \u2013 multiple versions and platforms<\/li>\n\t<li>Schneider Electric Modbus\/TCP Ethernet Modicon M340 FactoryCast module \u2013 versions prior to SV6.80<\/li>\n\t<li>Schneider Electric Modbus\/TCP Ethernet Modicon M340 module \u2013 all versions prior to SV3.60<\/li>\n\t<li>Schneider Electric Modicon M340 \u2013 all versions<\/li>\n\t<li>Siemens APOGEE PXC Series (BACnet), (P2 Ethernet) \u2013 all versions<\/li>\n\t<li>Siemens Industrial Edge Management OS (IEM-OS) \u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM RST2428P (6GK6242-6PA00) \u2013 all versions<\/li>\n\t<li>Siemens SIMATIC PCS neo V4.1, neo V5.0 \u2013 all versions<\/li>\n\t<li>Siemens SIMATIC Technology Package TPCamGen (6ES7823-0FE30-1AA0) \u2013 all versions<\/li>\n\t<li>Siemens SIMATIC Virtualization as a Service (SIVaaS) \u2013 all versions<\/li>\n\t<li>Siemens SIMOTION OA MIIF (6AU1820-3DA20-0AB0) \u2013 all versions<\/li>\n\t<li>Siemens SIMOTION OACAMGEN (6AU1820-3EA20-0AB0) \u2013 all versions<\/li>\n\t<li>Siemens SIMOTION OALECO (6AU1820-3HA20-0AB0) \u2013 all versions<\/li>\n\t<li>Siemens SIMOTION OAVIBX (6AU1820-3CA20-0AB0) \u2013 all versions<\/li>\n\t<li>Siemens SINAMICS G220 V6.4 \u2013 versions prior to V6.4 HF2<\/li>\n\t<li>Siemens SINAMICS S200 V6.4 \u2013 all versions<\/li>\n\t<li>Siemens SINAMICS S210 V6.4 \u2013 versions prior to V6.4 HF2<\/li>\n\t<li>Siemens TALON TC Series (BACnet) \u2013 all versions<\/li>\n\t<li>Siemens User Management Component (UMC) \u2013 versions prior to 2.15.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-591","alert_type":398,"serial_number":"AV25-591","subject":"other","moderation_state":"published","external_url":null},{"nid":6801,"title":"Red Hat security advisory (AV25-592)","uuid":"955cd74e-600f-4799-9ffd-af82e33d52be","banner":null,"lang":"en","date_modified":"2025-09-15","date_modified_ts":"2025-09-15T16:13:19Z","date_created":"2025-09-15T16:01:49Z","summary":null,"body":["<article data-history-node-id=\"6801\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-592\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-592<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 15, 2025<\/p>\n\n<p>Between September 8 and 14, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-592","alert_type":396,"serial_number":"AV25-592","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6802,"title":"Apple security advisory (AV25-593)","uuid":"2647c01f-d421-4c9c-8490-60cf89fbcc27","banner":null,"lang":"en","date_modified":"2025-09-15","date_modified_ts":"2025-09-15T19:03:45Z","date_created":"2025-09-15T18:52:10Z","summary":null,"body":["<article data-history-node-id=\"6802\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-593\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-593<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><\/p>\n\n<p><strong>Date: <\/strong>September 15, 2025<\/p>\n\n<p>On September 15, 2025, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 26<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 18.7<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 16.7.12<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 15.8.5<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.7<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.8<\/li>\n\t<li>tvOS 26\u00a0\u2013 versions prior to 26<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 26<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 26<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-593","alert_type":396,"serial_number":"AV25-593","subject":"apple","moderation_state":"published","external_url":null},{"nid":6803,"title":"Mozilla security advisory (AV25-594)","uuid":"b51936be-642e-4f61-bd6b-e4c78bf3ee52","banner":null,"lang":"en","date_modified":"2025-09-16","date_modified_ts":"2025-09-16T15:25:18Z","date_created":"2025-09-16T15:19:32Z","summary":null,"body":["<article data-history-node-id=\"6803\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-594\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-594<br \/><strong>Date: <\/strong>September\u00a016, 2025<\/p>\n\n<p>On September\u00a016, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Focus for iOS\u00a0\u2013 versions prior to 143.0<\/li>\n\t<li>Firefox \u2013 versions prior to 143<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.28<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 140.3<\/li>\n\t<li>Thunderbird \u2013 versions prior to 143<\/li>\n\t<li>Thunderbird \u2013 versions prior to 140.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-594","alert_type":396,"serial_number":"AV25-594","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6804,"title":"HPE security advisory (AV25-595)","uuid":"d1241289-15f1-4618-a7c4-1a81633aba5c","banner":null,"lang":"en","date_modified":"2025-09-16","date_modified_ts":"2025-09-16T19:49:30Z","date_created":"2025-09-16T19:34:25Z","summary":null,"body":["<article data-history-node-id=\"6804\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-595\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-595<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 16, 2025<\/p>\n\n<p>On September 16, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Service Activator\u00a0\u2013 9.1 versions prior to 9.1.32<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04948en_us&amp;&amp;docLocale=en_US\">HPESBNW04948 rev.1\u00a0- HPE Telco Service Activator, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-595","alert_type":396,"serial_number":"AV25-595","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6806,"title":"Atlassian security advisory (AV25-596)","uuid":"fb8d424b-42d4-4101-8160-4c0a41345eda","banner":null,"lang":"en","date_modified":"2025-09-17","date_modified_ts":"2025-09-17T14:01:58Z","date_created":"2025-09-17T13:19:14Z","summary":null,"body":["<article data-history-node-id=\"6806\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-596\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-596<br \/><strong>Date: <\/strong>September\u00a017, 2025<\/p>\n\n<p>On September\u00a016, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Confluence Data Center and server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-september-16-2025-1627098357.html\">Security Bulletin\u00a0\u2013 September\u00a016 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-596","alert_type":396,"serial_number":"AV25-596","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6807,"title":"HPE security advisory (AV25-597)","uuid":"e27410d8-97bd-4149-9660-5a03f2986627","banner":null,"lang":"en","date_modified":"2025-09-17","date_modified_ts":"2025-09-17T15:46:14Z","date_created":"2025-09-17T15:35:34Z","summary":null,"body":["<article data-history-node-id=\"6807\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-597\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-597<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September\u00a017, 2025<\/p>\n\n<p>On September 16, 2025, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking EdgeConnect SD-WAN Release Stream\u00a0\u2013 versions 9.5.x.x to 9.5.3.x<\/li>\n\t<li>HPE Aruba Networking EdgeConnect SD-WAN Release Stream\u00a0\u2013 versions 9.4.x.x to 9.4.3.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04943en_us&amp;docLocale=en_US\">HPESBNW04943 rev.1\u00a0- HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Aruba Networking EdgeConnect<\/span> SD-WAN <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Gateways, Multiple Vulnerabilities<\/span><\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-597","alert_type":396,"serial_number":"AV25-597","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6808,"title":"Jenkins security advisory (AV25-598)","uuid":"31d3b583-239d-47c3-89d7-0ef00eedbe3a","banner":null,"lang":"en","date_modified":"2025-09-17","date_modified_ts":"2025-09-17T16:00:44Z","date_created":"2025-09-17T15:52:58Z","summary":null,"body":["<article data-history-node-id=\"6808\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-598\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-598<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 17, 2025<\/p>\n\n<p>On September 17, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins weekly\u00a0\u2013 version 2.528 and prior<\/li>\n\t<li>Jenkins LTS\u00a0\u2013 version 2.516.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-09-17\/\">Jenkins Security Advisory 2025-09-17<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-598","alert_type":396,"serial_number":"AV25-598","subject":"other","moderation_state":"published","external_url":null},{"nid":6809,"title":"Microsoft Edge security advisory (AV25-599)","uuid":"60e5a5eb-d59c-4d14-b457-cc0c1c87c817","banner":null,"lang":"en","date_modified":"2025-09-17","date_modified_ts":"2025-09-17T16:09:29Z","date_created":"2025-09-17T16:04:53Z","summary":null,"body":["<article data-history-node-id=\"6809\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-599\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-599<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 17, 2025<\/p>\n\n<p>On September 16, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 140.0.3485.71<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-16-2025\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft Edge Stable Channel Release Notes<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-599","alert_type":396,"serial_number":"AV25-599","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6810,"title":"Google Chrome security advisory (AV25-600)","uuid":"981d140d-3ccd-476c-9031-cd261203f495","banner":null,"lang":"en","date_modified":"2025-09-18","date_modified_ts":"2025-09-18T13:44:53Z","date_created":"2025-09-18T13:37:47Z","summary":null,"body":["<article data-history-node-id=\"6810\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-600\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-600<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 18, 2025<\/p>\n\n<p>On September 17, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 140.0.7339.185\/186 (Windows\/Mac) and 140.0.7339.185 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2025-10585 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/09\/stable-channel-update-for-desktop_17.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-600","alert_type":396,"serial_number":"AV25-600","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6811,"title":"HPE security advisory (AV25-601)","uuid":"365b19da-f882-48c6-b097-4221408f9e4a","banner":null,"lang":"en","date_modified":"2025-09-18","date_modified_ts":"2025-09-18T13:56:26Z","date_created":"2025-09-18T13:49:08Z","summary":null,"body":["<article data-history-node-id=\"6811\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-601\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-601<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 18, 2025<\/p>\n\n<p>On September 17, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Intelligent Assurance\u00a0\u2013 version 5.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04940en_us&amp;docLocale=en_US\">HPESBNW04940 rev.1\u00a0- HPE Telco Intelligent Assurance, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-601","alert_type":396,"serial_number":"AV25-601","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6812,"title":"Nokia security advisory (AV25-602)","uuid":"463ec019-d644-4730-b6e7-c9553d6f6ac6","banner":null,"lang":"en","date_modified":"2025-09-18","date_modified_ts":"2025-09-18T17:11:33Z","date_created":"2025-09-18T17:06:26Z","summary":null,"body":["<article data-history-node-id=\"6812\" about=\"\/en\/alerts-advisories\/nokia-security-advisory-av25-602\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-602<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 18, 2025<\/p>\n\n<p>On September 18, 2025, Nokia published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CloudBand Infrastructure Software (CBIS)\u00a0\u2013 version CBIS 22<\/li>\n\t<li>Nokia Container Service (NCS)\u00a0\u2013 versions NCS 22.12 and NCS 23.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.nokia.com\/about-us\/security-and-privacy\/product-security-advisory\/CVE-2023-49564\/\">CVE-2025-49564 Authentication Bypass<\/a><\/li>\n\t<li><a href=\"https:\/\/www.nokia.com\/about-us\/security-and-privacy\/product-security-advisory\/CVE-2023-49565\/\">CVE-2023-49565 Remote Code Execution<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nokia-security-advisory-av25-602","alert_type":396,"serial_number":"AV25-602","subject":"other","moderation_state":"published","external_url":null},{"nid":6813,"title":"SonicWall security advisory (AV25-603) - Update 1","uuid":"53599a45-49e0-41bd-be1a-f7cc13e5d37d","banner":null,"lang":"en","date_modified":"2025-10-09","date_modified_ts":"2025-10-09T17:12:15Z","date_created":"2025-09-18T19:46:00Z","summary":null,"body":["<article data-history-node-id=\"6813\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-603\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-603<br \/><strong>Date: <\/strong>September 18, 2025<br \/><strong>Update: <\/strong>October 9, 2025<\/p>\n\n<p>On September 17, 2025, SonicWall published a security incident report describing suspicious activity targeting their cloud backup service for firewalls. Customer firewall preference files stored in the cloud were accessed by threat actors. These files contain information that could make the exploitation of customer firewalls significantly easier.<\/p>\n\n<p>The vendor is not aware of these files being leaked online by threat actors.<\/p>\n\n<p>Affected products:<\/p>\n\n<ul><li>SonicWall Firewalls with preference files backed up in MySonicWall.com<\/li>\n<\/ul><h2 class=\"h4\">Update 1<\/h2>\n\n<p>On October 8, 2025, SonicWall confirmed that an unauthorized party accessed firewall configuration backup files for all customers using SonicWall\u2019s cloud backup service.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sonicwall.com\/support\/knowledge-base\/mysonicwall-cloud-backup-file-incident\/250915160910330\">MySonicWall Cloud Backup File Incident<\/a><\/li>\n\t<li><a href=\"https:\/\/www.sonicwall.com\/support\/knowledge-base\/essential-credential-reset\/250909151701590\">Essential Credential Reset<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-603","alert_type":396,"serial_number":"AV25-603","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":6815,"title":"Fortra security advisory (AV25-604)","uuid":"c2c85f58-aed6-491c-925b-d2c03b0ae99d","banner":null,"lang":"en","date_modified":"2025-09-19","date_modified_ts":"2025-09-19T17:18:34Z","date_created":"2025-09-19T17:10:49Z","summary":null,"body":["<article data-history-node-id=\"6815\" about=\"\/en\/alerts-advisories\/fortra-security-advisory-av25-604\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-604<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 19, 2025<\/p>\n\n<p>On September 18, 2025, Fortra published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>GoAnywhere MFT\u00a0\u2013 versions prior to 7.8.4<\/li>\n\t<li>GoAnywhere MFT\u00a0\u2013 versions prior to Sustain Release 7.6.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\/fi-2025-012\">Deserialization Vulnerability in GoAnywhere MFT's License Servlet<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\">Fortra Product CVEs<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortra-security-advisory-av25-604","alert_type":396,"serial_number":"AV25-604","subject":"other","moderation_state":"published","external_url":null},{"nid":6816,"title":"[Control systems] ABB security advisory (AV25-605) ","uuid":"e1c37f92-e47a-4761-9bc1-79c0d6e7d645","banner":null,"lang":"en","date_modified":"2025-09-19","date_modified_ts":"2025-09-19T17:39:27Z","date_created":"2025-09-19T17:33:28Z","summary":null,"body":["<article data-history-node-id=\"6816\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-605\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-605<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 19, 2025<\/p>\n\n<p>On August 18, 2025, ABB published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB FLXeon Controllers\u00a0\u2013 multiple models and version 9.3.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A7121&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">ABB FLXeon Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-605","alert_type":398,"serial_number":"AV25-605","subject":"abb","moderation_state":"published","external_url":null},{"nid":6818,"title":"[Control systems] CISA ICS security advisories (AV25\u2013610)","uuid":"8c77b156-fef5-40ed-9228-62ddb450cebc","banner":null,"lang":"en","date_modified":"2025-09-22","date_modified_ts":"2025-09-22T14:11:04Z","date_created":"2025-09-22T13:40:51Z","summary":null,"body":["<article data-history-node-id=\"6818\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-610\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-610<br \/><strong>Date: <\/strong>September 22, 2025<\/p>\n\n<p>Between September 15 and 21, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cognex In-Sight 2000, 7000, 8000 and 9000 series\u00a0\u2013 versions 5.x to 6.5.1<\/li>\n\t<li>Cognex In-Sight Explorer\u00a0\u2013 versions 5.x to 6.5.1<\/li>\n\t<li>Delta Electronics DIALink\u00a0\u2013 versions V1.6.0.0 and prior<\/li>\n\t<li>Dover Fueling Solutions ProGauge MagLink LX 4 and LX Plus\u00a0\u2013 versions prior to 4.20.3<\/li>\n\t<li>Dover Fueling Solutions ProGauge MagLink LX Ultimate\u00a0\u2013 versions prior to 5.20.3<\/li>\n\t<li>Hitachi Energy Asset Suite\u00a0\u2013 version 9.6.4.5 and prior<\/li>\n\t<li>Hitachi Energy RTU500 Series\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Hitachi Energy Service Suite\u00a0\u2013 versions prior to 9.6.0.4 EP4<\/li>\n\t<li>Schneider Electric ATVdPAC module\u00a0\u2013 versions prior to 25.0<\/li>\n\t<li>Schneider Electric Altivar Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Schneider Electric ILC992 InterLink Converter\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Saitel DP RTU\u00a0\u2013 version 11.06.33 and prior<\/li>\n\t<li>Schneider Electric Saitel DR RTU\u00a0\u2013 version 11.06.29 and prior<\/li>\n\t<li>Siemens INDUSTRIAL EDGE\u00a0- multiple versions and platforms<\/li>\n\t<li>Siemens Industrial Edge\u00a0- Machine Insight App \u2013 all versions<\/li>\n\t<li>Siemens OpenPCS\u00a0- multiple versions and platforms<\/li>\n\t<li>Siemens RUGGEDCOM NMS \u2013 all versions<\/li>\n\t<li>Siemens RUGGEDCOM\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SIMATIC NET CP, SINEMA, and SCALANCE\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SIMATIC\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SIMOTION\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SINAUT\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V1.0.3<\/li>\n\t<li>Siemens SINEC\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SINEMA Remote Connect Server\u00a0\u2013 version V3.1<\/li>\n\t<li>Siemens SINEMA Server V14\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINEMA\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SINUMERIK Operate\u00a0\u2013 versions prior to V4.95 SP1<\/li>\n\t<li>Siemens SIPLUS\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens TIA Administrator\u00a0\u2013 versions prior to 1.0 SP7<\/li>\n\t<li>Westermo Network Technologies WeOS 5\u00a0\u2013 version 5.23.0 and prior<\/li>\n\t<li>Westermo Network Technologies WeOS 5\u00a0\u2013 version 5.24 and later<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-610","alert_type":398,"serial_number":"AV25-610","subject":"ics","moderation_state":"published","external_url":null},{"nid":6817,"title":"IBM security advisory (AV25-606)","uuid":"17ca0754-d072-49d5-be5a-8f8e96d1a3fa","banner":null,"lang":"en","date_modified":"2025-09-22","date_modified_ts":"2025-09-22T13:49:13Z","date_created":"2025-09-22T13:42:20Z","summary":null,"body":["<article data-history-node-id=\"6817\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-606\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-606<br \/><strong>Date: <\/strong>September\u00a022, 2025<\/p>\n\n<p>Between September\u00a015 and 21, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-606","alert_type":396,"serial_number":"AV25-606","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6820,"title":"Dell security advisory (AV25-607)","uuid":"6e0e642c-4619-4599-b66a-7280722ac7d3","banner":null,"lang":"en","date_modified":"2025-09-22","date_modified_ts":"2025-09-22T13:55:02Z","date_created":"2025-09-22T13:42:21Z","summary":null,"body":["<article data-history-node-id=\"6820\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-607\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-607<br \/><strong>Date: <\/strong>September\u00a022, 2025<\/p>\n\n<p>Between September\u00a015 and 21, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerProtect Cyber Recovery\u00a0\u2013 versions prior to 19.20.0.1, 15.4.0-9 and 1.5.0-63<\/li>\n\t<li>Dell CyberSense\u00a0\u2013 versions prior to 8.13<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000369807\/dsa-2025-346-security-update-for-dell-powerprotect-cyber-recovery-multiple-third-party-component-vulnerabilities\">DSA-2025-346: Security Update for Dell PowerProtect Cyber Recovery Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000369848\/dsa-2025-344-security-update-for-dell-cybersense-multiple-third-party-component-vulnerabilities\">DSA-2025-344: Security Update for Dell CyberSense Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-607","alert_type":396,"serial_number":"AV25-607","subject":"dell","moderation_state":"published","external_url":null},{"nid":6819,"title":"Ubuntu security advisory (AV25-608)","uuid":"addfbd17-7285-4b71-80f3-ed4c26fcada0","banner":null,"lang":"en","date_modified":"2025-09-22","date_modified_ts":"2025-09-22T13:58:45Z","date_created":"2025-09-22T13:44:12Z","summary":null,"body":["<article data-history-node-id=\"6819\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-608\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-608<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 22, 2025<\/p>\n\n<p>Between September 15 and 21, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-608","alert_type":396,"serial_number":"AV25-608","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6821,"title":"Microsoft Edge security advisory (AV25-611)","uuid":"8cd4ae6c-41b1-4a58-aec9-98fefd61d015","banner":null,"lang":"en","date_modified":"2025-09-22","date_modified_ts":"2025-09-22T14:11:38Z","date_created":"2025-09-22T13:53:46Z","summary":null,"body":["<article data-history-node-id=\"6821\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-611\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-611<br \/><strong>Date: <\/strong>September 22, 2025<\/p>\n\n<p>On September 19, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 140.0.3485.81<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-19-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-611","alert_type":396,"serial_number":"AV25-611","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6822,"title":"Red Hat security advisory (AV25-609)","uuid":"ad022e8c-d414-4d87-83c4-b8d6549c95cd","banner":null,"lang":"en","date_modified":"2025-09-22","date_modified_ts":"2025-09-22T14:04:43Z","date_created":"2025-09-22T13:59:20Z","summary":null,"body":["<article data-history-node-id=\"6822\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-609\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-609<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 22, 2025<\/p>\n\n<p>Between September 15 and 21, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-609","alert_type":396,"serial_number":"AV25-609","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6824,"title":"SonicWall security advisory (AV25-612)","uuid":"3af8a8d7-0c6c-4d79-9e56-d7a410090763","banner":null,"lang":"en","date_modified":"2025-09-23","date_modified_ts":"2025-09-23T12:58:40Z","date_created":"2025-09-23T12:51:50Z","summary":null,"body":["<article data-history-node-id=\"6824\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-612\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-612<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 23, 2025<\/p>\n\n<p>On September 22, 2025, SonicWall published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SMA 100 Series (SMA 210, 410, 500v)\u00a0\u2013 version 10.2.1.15-81sv and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0015\">SonicWall SMA100 10.2.2.2-92sv With Additional File Checking<\/a><\/li>\n\t<li><a href=\"https:\/\/www.sonicwall.com\/support\/notices\/urgent-advisory-for-addressing-rootkits-and-other-critical-vulnerabilities-in-sonicwall-sma-100-series-appliances\/250730071322160\">Urgent Advisory for Addressing Rootkits and Other Critical Vulnerabilities in SonicWall SMA 100 Series Appliances<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-612","alert_type":396,"serial_number":"AV25-612","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":6825,"title":"SolarWinds security advisory (AV25-613) \u2013 Update 1","uuid":"3e05d567-0ad3-439b-ae14-41a818ea3d29","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T18:48:18Z","date_created":"2025-09-23T14:24:07Z","summary":null,"body":["<article data-history-node-id=\"6825\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-613\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-613<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 23, 2025<br \/><strong>Updated: <\/strong>March 9, 2026<\/p>\n\n<p>On September 17, 2025, SolarWinds published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>SolarWinds Web Help Desk\u00a0\u2013 version 12.8.7 and prior<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On March 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-26399 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2025-26399\">SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-26399)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-26399\">CISA KEV: CVE-2025-26399<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-613","alert_type":396,"serial_number":"AV25-613","subject":"other","moderation_state":"published","external_url":null},{"nid":6827,"title":"Citrix security advisory (AV25-614)","uuid":"7333eb16-2d02-484c-9f75-e12af4298706","banner":null,"lang":"en","date_modified":"2025-09-23","date_modified_ts":"2025-09-23T19:29:39Z","date_created":"2025-09-23T18:59:31Z","summary":null,"body":["<article data-history-node-id=\"6827\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-614\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-614<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 23, 2025<\/p>\n\n<p>On September 9, 2025, Citrix published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>XenServer\u00a0\u2013 version 8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX695195&amp;&amp;articleURL=XenServer_Security_Update_for_CVE_2025_27466_CVE_2025_58142_CVE_2025_58143_and_CVE_2025_58146\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Citrix Security Advisory<\/span>\u00a0\u2013 CTX695195<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Citrix Security Advisories<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-614","alert_type":396,"serial_number":"AV25-614","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6828,"title":"Google Chrome security advisory (AV25-615)","uuid":"3cc0d457-fc21-4980-b630-184bd42e1a55","banner":null,"lang":"en","date_modified":"2025-09-24","date_modified_ts":"2025-09-24T12:20:59Z","date_created":"2025-09-24T12:15:06Z","summary":null,"body":["<article data-history-node-id=\"6828\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-615\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-615<br \/><strong>Date: <\/strong>September\u00a024, 2025<\/p>\n\n<p>On September\u00a023, 2025, Google published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 140.0.7339.207\/.208 (Windows\/Mac) and 140.0.7339.207 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/09\/stable-channel-update-for-desktop_23.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-615","alert_type":396,"serial_number":"AV25-615","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6829,"title":"Cisco security advisory (AV25-616) \u2013 Update 1","uuid":"b9a7718f-aed6-4a77-b4cd-c56ce3830502","banner":null,"lang":"en","date_modified":"2025-10-17","date_modified_ts":"2025-10-17T12:47:20Z","date_created":"2025-09-24T18:47:12Z","summary":null,"body":["<article data-history-node-id=\"6829\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-616\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-616<br \/><strong>Date: <\/strong>September\u00a024, 2025<br \/><strong>Updated: <\/strong>October\u00a017, 2025<\/p>\n\n<p>On September 24, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Access Point Software\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Catalyst 9500X and 9600X Series Switches\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco IOS XE Software for Catalyst 9XXX Series Switches\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco IOS and IOS XE Software\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Industrial Ethernet (IE) Series Switches\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco SD-WAN vEdge Routers\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco SD-WAN vEdge Software Release\u00a0\u2013 versions prior to 20.8, 20.9 and 20.10<\/li>\n\t<li>Cisco Wireless Access Point (AP) Software\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Cisco Wireless LAN Controller (WLC) IOS XE Software\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p><strong>Update 1 <\/strong><\/p>\n\n<p>On September 29, 2025, CISA released a statement indicating that CVE-2025-20352 is being actively exploited in the wild and added it to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-snmpwred-x3MJyf5M\">Cisco IOS XE Software Simple Network Management Protocol Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-snmp-x4LPhte\">Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-616","alert_type":396,"serial_number":"AV25-616","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6830,"title":"Drupal security advisory (AV25-617)","uuid":"fb0028c3-0bf9-4e44-82b8-313ece279284","banner":null,"lang":"en","date_modified":"2025-09-24","date_modified_ts":"2025-09-24T19:02:27Z","date_created":"2025-09-24T18:47:12Z","summary":null,"body":["<article data-history-node-id=\"6830\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-617\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-617<br \/><strong>Date: <\/strong>September\u00a024, 2025<\/p>\n\n<p>On September\u00a024, 2025, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>JSON Field\u00a0\u2013 versions prior to 1.5<\/li>\n\t<li>Plausible tracking\u00a0\u2013 versions prior to 1.0.2<\/li>\n\t<li>Access code\u00a0\u2013 versions prior to 2.0.5<\/li>\n\t<li>Umami Analytics\u00a0\u2013 version prior to 1.0.1<\/li>\n\t<li>Currency\u00a0\u2013 versions prior to 3.5.0<\/li>\n\t<li>Reverse Proxy Header\u00a0\u2013 version prior to 1.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-617","alert_type":396,"serial_number":"AV25-617","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6831,"title":"HPE security advisory (AV25-618)","uuid":"2d54aa93-43ff-4625-96dc-a3d38a82442e","banner":null,"lang":"en","date_modified":"2025-09-24","date_modified_ts":"2025-09-24T19:50:18Z","date_created":"2025-09-24T19:43:44Z","summary":null,"body":["<article data-history-node-id=\"6831\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-618\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-618<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 24, 2025<\/p>\n\n<p>On September 23, 2025, HPE published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE Compute Scale-up Server 3200\u00a0\u2013 versions prior to v1.60.88<\/li>\n\t<li>HPE Superdome Flex Server\u00a0\u2013 versions prior to v4.10.18<\/li>\n\t<li>HPE Superdome Flex 280 Server\u00a0\u2013 versions prior to v2.05.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04857en_us&amp;docLocale=en_US\">HPESBHF04857 rev.1\u00a0- HPE Superdome Flex and Compute Scale-up Server 3200, Local Buffer Overflow<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-618","alert_type":396,"serial_number":"AV25-618","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6833,"title":"AL25-012 - Vulnerabilities impacting Cisco ASA and FTD devices \u2013 CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363 \u2013 Update 2","uuid":"0594ba8c-7337-46bf-b42f-e2761f463f06","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T14:15:28Z","date_created":"2025-09-25T12:07:30Z","summary":null,"body":["<article data-history-node-id=\"6833\" about=\"\/en\/alerts-advisories\/al25-012-vulnerabilities-impacting-cisco-asa-ftd-devices-cve-2025-20333-cve-2025-20362-cve-2025-20363\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-012<br \/><strong>Date:<\/strong> September\u00a025, 2025<br \/><strong>Updated:<\/strong> May\u00a011, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers of notified organizations.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of exploitation targeting Cisco Adaptive Security Appliance (ASA) 5500-X Series devices that are running Cisco Secure Firewall ASA Software with VPN web services enabled.<\/p>\n\n<p>On September 25, 2025, Cisco published security advisories for critical vulnerabilities, CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363, affecting the following ASA and Cisco Secure Firewall Threat Defense (FTD) software release products:<\/p>\n\n<ul><li>Cisco ASA software release 9.12\u00a0\u2013 versions prior to 9.12.4.72<\/li>\n\t<li>Cisco ASA software release 9.14\u00a0\u2013 versions prior to 9.14.4.28<\/li>\n\t<li>Cisco ASA software release 9.16\u00a0\u2013 versions prior to 9.16.4.85<\/li>\n\t<li>Cisco ASA software release 9.17\u00a0\u2013 versions prior to 9.17.1.45<\/li>\n\t<li>Cisco ASA software release 9.18\u00a0\u2013 versions prior to 9.18.4.67<\/li>\n\t<li>Cisco ASA software release 9.19\u00a0\u2013 versions prior to 9.19.1.42<\/li>\n\t<li>Cisco ASA software release 9.20\u00a0\u2013 versions prior to 9.20.4.10<\/li>\n\t<li>Cisco ASA software release 9.22\u00a0\u2013 versions prior to 9.22.2.14<\/li>\n\t<li>Cisco ASA software release 9.23\u00a0\u2013 versions prior to 9.23.1.19<br \/>\n\t\u00a0<\/li>\n\t<li>Cisco FTD software release 7.0\u00a0\u2013 versions prior to 7.0.8.1<\/li>\n\t<li>Cisco FTD software release 7.1\u00a0\u2013 all versions<\/li>\n\t<li>Cisco FTD software release 7.2\u00a0\u2013 versions prior to 7.2.10.2<\/li>\n\t<li>Cisco FTD software release 7.3\u00a0\u2013 all versions<\/li>\n\t<li>Cisco FTD software release 7.4\u00a0\u2013 versions prior to 7.4.2.4<\/li>\n\t<li>Cisco FTD software release 7.6\u00a0\u2013 versions prior to 7.6.2.1<\/li>\n\t<li>Cisco FTD software release 7.7\u00a0\u2013 versions prior to 7.7.10.1<\/li>\n<\/ul><p>For further details on affected versions and available fixed releases, please refer to the following Cisco advisories<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>CVE-2025-20333 is a vulnerability affecting the ASA and FTD software, that could allow an authenticated remote threat actor to execute arbitrary code on affected devices<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>CVE-2025-20362 is a vulnerability affecting the ASA and FTD software, that could allow an unauthenticated remote threat actor to access URL endpoints that should otherwise be inaccessible without authentication<sup id=\"fn2a-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>CVE-2025-20363 is a vulnerability affecting the ASA, FTD, Cisco IOS, Cisco IOS XE and Cisco IOS XR software, that could allow an unauthenticated remote threat actor (ASA and FTD) or authenticated remote one (Cisco IOS, IOS XE and IOS XR) with low user privileges to execute arbitrary code on affected devices<sup id=\"fn3a-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>All these vulnerabilities are due to improper validation of user supplied input in HTTP(S) requests.<\/p>\n\n<p>In response to these vulnerabilities, the Cyber Centre released AV25-619 on September 25<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<h3>Update 1<\/h3>\n\n<p>On April 23, 2026, Cisco Talos released a blog post <sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> and Cisco published a security advisory <sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup> identifying a previously unknown persistence method that remains intact even after upgrading to a patched version released in September 2025. The persistence mechanism is embedded in the Cisco Firepower eXtensible Operating System (FXOS) Software base operating system for Cisco Secure Firewall ASA Software and Cisco Secure FTD Software installations on the affected hardware.<\/p>\n\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) created the Emergency Directive document V1: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices <sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup> and along with the United Kingdom National Cyber Security Centre (NCSC), published a FIRESTARTER Backdoor Malware Analysis Report <sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup> on April 23, 2026.<\/p>\n\n<p>The Cyber Centre recommends organizations review the Cisco advisory, identify if indicators of compromise are present on their devices, and apply the identified workarounds, including reimaging the device to a known fixed version.<\/p>\n\n<p>Affected products and versions:<\/p>\n\n<p>Secure Firewall ASA Software<\/p>\n\n<ul><li>Cisco ASA software release 9.16\u00a0\u2013 versions prior to 9.16.4.92<\/li>\n\t<li>Cisco ASA software release 9.18\u00a0\u2013 versions prior to 9.18.4.135<\/li>\n\t<li>Cisco ASA software release 9.20\u00a0\u2013 versions prior to 9.20.4.30<\/li>\n\t<li>Cisco ASA software release 9.22\u00a0\u2013 versions prior to 9.22.3.5<\/li>\n\t<li>Cisco ASA software release 9.23\u00a0\u2013 versions prior to 9.23.1.195<\/li>\n\t<li>Cisco ASA software release 9.24\u00a0\u2013 versions prior to 9.24.1.155<\/li>\n<\/ul><p>Secure FTD Software<\/p>\n\n<ul><li>Cisco FTD software release 7.0\u00a0\u2013 versions prior to 7.0.9 Hotfix FZ-7.0.9.1-3<\/li>\n\t<li>Cisco FTD software release 7.2\u00a0\u2013 versions prior to 7.2.11 Hotfix HI-7.2.11.1-1<\/li>\n\t<li>Cisco FTD software release 7.4\u00a0\u2013 versions prior to 7.4.7<\/li>\n\t<li>Cisco FTD software release 7.6\u00a0\u2013 versions prior to 7.6.4 Hotfix CC-7.6.4.1-1<\/li>\n\t<li>Cisco FTD software release 7.7\u00a0\u2013 versions prior to 7.7.11 Hotfix AE-7.7.11.1-4<\/li>\n\t<li>Cisco FTD software release 10\u00a0\u2013 versions prior to 10.0.0 Hot Fix <strong>(Target 4\/30\/2026)<\/strong><\/li>\n<\/ul><p>Firepower 4100 and 9300 Security Appliance<\/p>\n\n<ul><li>Cisco Firepower 4100 and 9300 Security Appliance 2.10\u00a0\u2013 versions prior to 2.10.1.383<\/li>\n\t<li>Cisco Firepower 4100 and 9300 Security Appliance 2.12\u00a0\u2013 versions prior to 2.12.1.117<\/li>\n\t<li>Cisco Firepower 4100 and 9300 Security Appliance 2.14\u00a0\u2013 versions prior to 2.14.3.125<\/li>\n\t<li>Cisco Firepower 4100 and 9300 Security Appliance 2.16\u00a0\u2013 versions prior to 2.16.2.119<\/li>\n\t<li>Cisco Firepower 4100 and 9300 Security Appliance 2.17\u00a0\u2013 versions prior to 2.17.0.549<\/li>\n\t<li>Cisco Firepower 4100 and 9300 Security Appliance 2.18\u00a0\u2013 versions prior to 2.18.0.535<\/li>\n<\/ul><p>End of Update 1<\/p>\n\n<h3>Update 2<\/h3>\n\n<p>Additional Affected Products and versions:<\/p>\n\n<p>Cisco Secure Firewall ASA and Cisco Secure FTD platforms<\/p>\n\n<ul><li>Cisco Firepower 1000 Series<\/li>\n\t<li>Cisco Firepower 2100 Series<\/li>\n\t<li>Cisco Firepower 4100 Series<\/li>\n\t<li>Cisco Firepower 9300 Series<\/li>\n\t<li>Cisco Secure Firewall 1200 Series<\/li>\n\t<li>Cisco Secure Firewall 3100 Series<\/li>\n\t<li>Cisco Secure Firewall 4200 Series<\/li>\n<\/ul><p>End of Update 2<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations running Cisco ASA and FTD products upgrading to a fixed release software version<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<p>Organizations upgrading an ASA 5500-X Series model to 9.12.4.72 or 9.14.4.28 should refer to Cisco\u2019s Bootloader and\/or ROMMON Verification Failure procedures<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>. If the \u201cfirmware-update.log\u201d file is found on \u201cdisk0:\u201d after upgrading to a fixed release, organizations are encouraged to preserve the log file and notify the Cyber Centre using the contact information below. Instructions regarding transfer of the log file will be provided as part of the follow-up engagement.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<p>If activity matching the content of this alert is discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-webvpn-z5xP8EUB\">Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-webvpn-YROOTUW\">Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software and IOS XR Software HTTP Server Remote Code Execution Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-http-code-exec-WmfP3h3O\">Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-619\">AV25-619 Cisco Security Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/resources\/asa_ftd_continued_attacks\">Cisco Event Response: Continued Attacks Against Cisco Firewalls<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/resources\/detection_guide_for_continued_attacks\">Detection Guide for Continued Attacks against Cisco Firewalls by the Threat Actor behind ArcaneDoor<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"79b2a2c3-ad1e-49b5-9ca5-5f2f54757b2e\" href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/blog.talosintelligence.com\/uat-4356-firestarter\/\">UAT-4356's Targeting of Cisco Firepower Devices<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-persist-CISAED25-03\">Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices\">V1: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/analysis-reports\/ar26-113a\">CISA\u00a0\u2013 Malware Analysis Report\u00a0\u2013 FIRESTARTER Backdoor<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-012-vulnerabilities-impacting-cisco-asa-ftd-devices-cve-2025-20333-cve-2025-20362-cve-2025-20363","alert_type":397,"serial_number":"AL25-012","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6836,"title":"Cisco security advisory (AV25-619) \u2013 Update 1","uuid":"cd17a5c1-7289-4cfd-b5eb-d434993b77d2","banner":null,"lang":"en","date_modified":"2025-11-06","date_modified_ts":"2025-11-06T18:18:46Z","date_created":"2025-09-25T16:30:56Z","summary":null,"body":["<article data-history-node-id=\"6836\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-619\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-619<br \/><strong>Date: <\/strong>September 25, 2025<br \/><strong>Updated: <\/strong>November 6, 2025<\/p>\n\n<p>On September 25, 2025, Cisco published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco ASA software release 9.12\u00a0\u2013 versions prior to 9.12.4.72<\/li>\n\t<li>Cisco ASA software release 9.14\u00a0\u2013 versions prior to 9.14.4.28<\/li>\n\t<li>Cisco ASA software release 9.16\u00a0\u2013 versions prior to 9.16.4.85<\/li>\n\t<li>Cisco ASA software release 9.17\u00a0\u2013 versions prior to 9.17.1.45<\/li>\n\t<li>Cisco ASA software release 9.18\u00a0\u2013 versions prior to 9.18.4.67<\/li>\n\t<li>Cisco ASA software release 9.19\u00a0\u2013 versions prior to 9.19.1.42<\/li>\n\t<li>Cisco ASA software release 9.20\u00a0\u2013 versions prior to 9.20.4.10<\/li>\n\t<li>Cisco ASA software release 9.22\u00a0\u2013 versions prior to 9.22.2.14<\/li>\n\t<li>Cisco ASA software release 9.23\u00a0\u2013 versions prior to 9.23.1.19<br \/>\n\t\u00a0<\/li>\n\t<li>Cisco FTD software release 7.0\u00a0\u2013 versions prior to 7.0.8.1<\/li>\n\t<li>Cisco FTD software release 7.1\u00a0\u2013 all versions<\/li>\n\t<li>Cisco FTD software release 7.2\u00a0\u2013 versions prior to 7.2.10.2<\/li>\n\t<li>Cisco FTD software release 7.3\u00a0\u2013 all versions<\/li>\n\t<li>Cisco FTD software release 7.4\u00a0\u2013 versions prior to 7.4.2.4<\/li>\n\t<li>Cisco FTD software release 7.6\u00a0\u2013 versions prior to 7.6.2.1<\/li>\n\t<li>Cisco FTD software release 7.7\u00a0\u2013 versions prior to 7.7.10.1<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On November 5, 2025, Cisco updated their security advisory to raise awareness of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This new attack variant may impact unpatched devices, causing them to unexpectedly reload leading to denial of service (DoS) conditions.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/protecting-your-organization-against-denial-service-attacks-itsap80100\">Protecting your organization against denial of service attacks\u00a0- ITSAP.80.100<\/a><br \/>\n\t\u00a0<\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-webvpn-z5xP8EUB \">Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability<\/a><br \/>\n\t\u00a0<\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-http-code-exec-WmfP3h3O \">Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software and IOS XR Software HTTP Server Remote Code Execution Vulnerability<\/a><br \/>\n\t\u00a0<\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-webvpn-YROOTUW\">Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability<\/a><br \/>\n\t\u00a0<\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-619","alert_type":396,"serial_number":"AV25-619","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6837,"title":"GitLab security advisory (AV25-620)","uuid":"dee89db5-1007-4b52-bf11-50f903c83664","banner":null,"lang":"en","date_modified":"2025-09-26","date_modified_ts":"2025-09-26T17:11:29Z","date_created":"2025-09-26T17:04:57Z","summary":null,"body":["<article data-history-node-id=\"6837\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-620\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-620<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 26, 2025<\/p>\n\n<p>On September 25, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.4.1, 18.3.3 and 18.2.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.4.1, 18.3.3 and 18.2.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/09\/25\/patch-release-gitlab-18-4-1-released\/\">GitLab Patch Release: 18.4.1, 18.3.3, 18.2.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-620","alert_type":396,"serial_number":"AV25-620","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6838,"title":"Microsoft Edge security advisory (AV25-621)","uuid":"0d9aa61f-ca4d-494f-84d3-59245d7df4d8","banner":null,"lang":"en","date_modified":"2025-09-26","date_modified_ts":"2025-09-26T17:21:41Z","date_created":"2025-09-26T17:16:01Z","summary":null,"body":["<article data-history-node-id=\"6838\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-621\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-621<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 26, 2025<\/p>\n\n<p>On September 25, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 140.0.3485.94<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#september-25-2025\">Microsoft Edge Stable Channel Release Notes <\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-621","alert_type":396,"serial_number":"AV25-621","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6839,"title":"Google Chrome security advisory (AV25-622)","uuid":"b67ac2c5-2a50-420b-9679-040375e89896","banner":null,"lang":"en","date_modified":"2025-09-26","date_modified_ts":"2025-09-26T17:31:39Z","date_created":"2025-09-26T17:27:05Z","summary":null,"body":["<article data-history-node-id=\"6839\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-622\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-622<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 26, 2025<\/p>\n\n<p>On September 25, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 140.0.7339.213\/.214 (Mac)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/09\/stable-channel-update-for-desktop_25.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-622","alert_type":396,"serial_number":"AV25-622","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6840,"title":"Foxit security advisory (AV25-623)","uuid":"a54b306f-fe1d-443b-b6dc-cbe81000eee4","banner":null,"lang":"en","date_modified":"2025-09-26","date_modified_ts":"2025-09-26T18:50:22Z","date_created":"2025-09-26T18:42:03Z","summary":null,"body":["<article data-history-node-id=\"6840\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av25-623\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-623<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 26, 2025<\/p>\n\n<p>On September 25, 2025, Foxit published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Foxit PDF Editor (Windows)\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Editor for Mac\u00a0\u2013 multiple versions<\/li>\n\t<li>Foxit PDF Reader (Windows)\u00a0\u2013 version 2025.2.0.33046 and prior<\/li>\n\t<li>Foxit PDF Reader for Mac\u00a0\u2013 version 2025.2.0.68868 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Foxit Security Bulletins<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av25-623","alert_type":396,"serial_number":"AV25-623","subject":"other","moderation_state":"published","external_url":null},{"nid":6841,"title":"IBM security advisory (AV25-624)","uuid":"07c17407-7f98-4d83-be0d-8a810f77253e","banner":null,"lang":"en","date_modified":"2025-09-29","date_modified_ts":"2025-09-29T15:10:40Z","date_created":"2025-09-29T15:06:23Z","summary":null,"body":["<article data-history-node-id=\"6841\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-624\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-624<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 29, 2025<\/p>\n\n<p>Between September 22 and 28, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-624","alert_type":396,"serial_number":"AV25-624","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6842,"title":"Dell security advisory (AV25-625)","uuid":"1b010699-7c4e-4b02-9099-a87cb5e69a47","banner":null,"lang":"en","date_modified":"2025-09-29","date_modified_ts":"2025-09-29T15:28:59Z","date_created":"2025-09-29T15:15:23Z","summary":null,"body":["<article data-history-node-id=\"6842\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-625\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-625<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 29, 2025<\/p>\n\n<p>Between September 22 and 28, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Cloud Disaster Recovery\u00a0\u2013 versions prior to 19.20<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 version 19.8 to 19.12 with Data Protection Central OS Update prior to dpc-osupdate-1.1.24-1<\/li>\n\t<li>Dell Latitude 5350, 5450, 5550, 7350, 7450 and 7650\u00a0\u2013 versions prior to 3.2.0.22<\/li>\n\t<li>Dell Latitude 7030 Rugged Extreme Tablet\u00a0\u2013 versions prior to 3.2.0.22<\/li>\n\t<li>Dell Latitude 7350 Detachable\u00a0\u2013 versions prior to 3.2.0.22<\/li>\n\t<li>Dell Latitude 9450 2-in-1\u00a0\u2013 versions prior to 3.2.0.22<\/li>\n\t<li>Dell Mobile Precision 3591\u00a0\u2013 versions prior to 3.2.0.22<\/li>\n\t<li>Dell PowerEdge Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Dell Precision 3490 and 3590\u00a0\u2013 versions prior to 3.2.0.22<\/li>\n\t<li>Dell Pro Rugged 13 RA13250 and RB14250\u00a0\u2013 versions prior to 3.2.0.22<\/li>\n\t<li>Dell SmartFabric Manager\u00a0\u2013 versions prior to 1.4.1<\/li>\n\t<li>Dell VMware ESXi\u00a0\u2013 versions prior to 9.0.0.0100<\/li>\n\t<li>Dell VMware ESXi\u00a0\u2013 versions prior to ESXi 8.0 Update 3f<\/li>\n\t<li>Dell iDRAC9\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>PowerProtect DP Series (Integrated Data Protection Appliance (IDPA) Appliance)\u00a0\u2013 version 2.7.9 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-625","alert_type":396,"serial_number":"AV25-625","subject":"dell","moderation_state":"published","external_url":null},{"nid":6843,"title":"Ubuntu security advisory (AV25-626)","uuid":"da9e7a8a-4141-44b8-b4a7-df4d9f2c7732","banner":null,"lang":"en","date_modified":"2025-09-29","date_modified_ts":"2025-09-29T15:40:32Z","date_created":"2025-09-29T15:33:08Z","summary":null,"body":["<article data-history-node-id=\"6843\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-626\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-626<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 29, 2025<\/p>\n\n<p>Between September 22 and 28, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-626","alert_type":396,"serial_number":"AV25-626","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6844,"title":"[Control systems] CISA ICS security advisories (AV25\u2013627)","uuid":"7a66ce32-bda3-430a-8a7a-9df8604a6818","banner":null,"lang":"en","date_modified":"2025-09-29","date_modified_ts":"2025-09-29T15:56:39Z","date_created":"2025-09-29T15:43:56Z","summary":null,"body":["<article data-history-node-id=\"6844\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-627\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-627<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 29, 2025<\/p>\n\n<p>Between September 22 and 28, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AutomationDirect CLICK PLUS C0-0x, C0-1x, C2-x CPU firmware\u00a0\u2013 versions prior to v3.71<\/li>\n\t<li>Dingtian DT-R002\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric MELSEC-Q Series CPU Modules\u00a0\u2013 first five digits of serial number '24082' to '27081'<\/li>\n\t<li>Schneider Electric SESU\u00a0\u2013 multiple models and versions prior to 3.0.12<\/li>\n\t<li>Viessmann Vitogate 300\u00a0\u2013 versions prior to 3.1.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-627","alert_type":398,"serial_number":"AV25-627","subject":"ics","moderation_state":"published","external_url":null},{"nid":6845,"title":"Red Hat security advisory (AV25-628)","uuid":"0cd7366e-6f17-4c3f-b619-d2e9b31c07ad","banner":null,"lang":"en","date_modified":"2025-09-29","date_modified_ts":"2025-09-29T16:30:52Z","date_created":"2025-09-29T15:59:23Z","summary":null,"body":["<article data-history-node-id=\"6845\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-628\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-628<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 29, 2025<\/p>\n\n<p>Between September 22 and 28, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-628","alert_type":396,"serial_number":"AV25-628","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6846,"title":"Apple security advisory (AV25-630)","uuid":"061334d6-f0d0-4b7b-8eda-c050eab59029","banner":null,"lang":"en","date_modified":"2025-09-29","date_modified_ts":"2025-09-29T20:22:04Z","date_created":"2025-09-29T20:00:09Z","summary":null,"body":["<article data-history-node-id=\"6846\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-629\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-630<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 29, 2025<\/p>\n\n<p>On September 29, 2025, Apple published security updates to address a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 26.0.1<\/li>\n\t<li>iOS 18.7.1 and iPadOS 18.7.1\u00a0\u2013 versions prior to iOS 18.7.1<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26.0.1<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.7.1<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.8.1<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 26.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-629","alert_type":396,"serial_number":"AV25-630","subject":"apple","moderation_state":"published","external_url":null},{"nid":6847,"title":"VMware security advisory (AV25-629) \u2013 Update 1","uuid":"8d71bfd8-3b5f-4e7e-b683-0825e047ea29","banner":null,"lang":"en","date_modified":"2025-10-30","date_modified_ts":"2025-10-30T19:05:03Z","date_created":"2025-09-29T20:11:38Z","summary":null,"body":["<article data-history-node-id=\"6847\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-629\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-629<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>September 29, 2025<br \/><strong>Updated:<\/strong> October 30, 2025<\/p>\n\n<p>On September 29, 2025, VMware published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Aria Operations\u00a0\u2013 versions 8.x<\/li>\n\t<li>VMware Cloud Foundation\u00a0\u2013 versions 4.x, 4.5.x, 5.x and 9.x.x.x<\/li>\n\t<li>VMware NSX\u00a0- versions 4.2.x, 4.1.x and 4.0.x<\/li>\n\t<li>VMware NSX-T\u00a0- version 3.x<\/li>\n\t<li>VMware Telco Cloud Infrastructure\u00a0\u2013 versions 3.x and 2.x<\/li>\n\t<li>VMware Telco Cloud Platform\u00a0\u2013 versions 5.x, 4.x, 3.x and 2.x<\/li>\n\t<li>VMware Tools\u00a0\u2013 versions 13.x.x, 12.x.x and 11.x.x<\/li>\n\t<li>VMware vCenter\u00a0\u2013 version 7.0 and 8.0<\/li>\n\t<li>VMware vSphere Foundation\u00a0\u2013 versions 9.x.x.x and 13.x.x.x<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn October 30, 2025, CISA released a statement indicating that CVE-2025-41244 is being actively exploited in the wild and added it to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36149\">VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244, CVE-2025-41245, CVE-2025-41246)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36150\">VMSA-2025-0016: VMware vCenter and NSX updates address multiple vulnerabilities (CVE-2025-41250, CVE-2025-41251, CVE-2025-41252)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/10\/30\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">CISA Adds Two Known Exploited Vulnerabilities to Catalog<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-629","alert_type":396,"serial_number":"AV25-629","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6849,"title":"Sudo security advisory (AV25-631)","uuid":"72e4f5ec-5dc1-474c-8999-12c98f5933a1","banner":null,"lang":"en","date_modified":"2025-10-01","date_modified_ts":"2025-10-01T17:34:23Z","date_created":"2025-10-01T17:25:37Z","summary":null,"body":["<article data-history-node-id=\"6849\" about=\"\/en\/alerts-advisories\/sudo-security-advisory-av25-631\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-631<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 1, 2025<\/p>\n\n<p>On June 30, 2025, Sudo published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SUDO\u00a0\u2013 versions 1.9.14 to version prior to 1.9.17p1<\/li>\n<\/ul><p>On September 29, 2025, CISA added CVE-2025-32463 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.sudo.ws\/security\/advisories\/chroot_bug\/\">Sudo Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/09\/29\/cisa-adds-five-known-exploited-vulnerabilities-catalog\">CVE-2025-32463<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sudo-security-advisory-av25-631","alert_type":396,"serial_number":"AV25-631","subject":"other","moderation_state":"published","external_url":null},{"nid":6852,"title":"[Control systems] ABB security advisory (AV25-632) ","uuid":"d158e1fb-f4bd-4465-bea8-4e2278a7c14c","banner":null,"lang":"en","date_modified":"2025-10-02","date_modified_ts":"2025-10-02T15:17:20Z","date_created":"2025-10-02T13:52:57Z","summary":null,"body":["<article data-history-node-id=\"6852\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-632\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-632<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 2, 2025<\/p>\n\n<p>On September 28, 2025, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Terra AC wallbox (JP)\u00a0\u2013 version 1.8.33 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A8107&amp;&amp;LanguageCode=en&amp;&amp;DocumentPartId=&amp;&amp;Action=Launch\">Terra AC Wallbox Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-632","alert_type":398,"serial_number":"AV25-632","subject":"abb","moderation_state":"published","external_url":null},{"nid":6853,"title":"Cisco security advisory (AV25-633)","uuid":"c2664a3b-ab42-4e64-840a-fc486f52cd49","banner":null,"lang":"en","date_modified":"2025-10-02","date_modified_ts":"2025-10-02T16:21:05Z","date_created":"2025-10-02T16:11:55Z","summary":null,"body":["<article data-history-node-id=\"6853\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-633\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-633<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 2, 2025<\/p>\n\n<p>On October 1, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Cyber Vision Center\u00a0\u2013 versions 5.1 and 5.2 and prior<\/li>\n\t<li>Cisco Unified CM, Unified CM SME\u00a0\u2013 versions 12.5, 14 and versions prior to 15SU3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cv-xss-rwRAKAJ9\">Cisco Cyber Vision Center Stored Cross-Site Scripting Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cucm-stored-xss-Fnj66YLy\">Cisco Unified Communications Manager Stored Cross-Site Scripting Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-633","alert_type":396,"serial_number":"AV25-633","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6854,"title":"Google Chrome security advisory (AV25-634)","uuid":"da340a98-aeed-4b10-a504-e27dee10e340","banner":null,"lang":"en","date_modified":"2025-10-02","date_modified_ts":"2025-10-02T16:37:14Z","date_created":"2025-10-02T16:32:18Z","summary":null,"body":["<article data-history-node-id=\"6854\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-634\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-634<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 2, 2025<\/p>\n\n<p>On September 30, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 141.0.7390.54\/55 (Windows and Mac) and 141.0.7390.54\/ (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/09\/stable-channel-update-for-desktop_30.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-634","alert_type":396,"serial_number":"AV25-634","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6857,"title":"TeamViewer security advisory (AV25-638)","uuid":"20bd2b7d-765a-4fce-8b61-3e5d31ece8c1","banner":null,"lang":"en","date_modified":"2025-10-02","date_modified_ts":"2025-10-02T18:33:52Z","date_created":"2025-10-02T16:58:41Z","summary":null,"body":["<article data-history-node-id=\"6857\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-638\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-638<br \/><strong>Date: <\/strong>October\u00a02, 2025<\/p>\n\n<p>On September\u00a030, 2025, TeamViewer released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>TeamViewer Remote Full Client (Windows)\u00a0\u2013 versions prior to 15.70<\/li>\n\t<li>TeamViewer Remote Host (Windows)\u00a0\u2013 versions prior to 15.70<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/tv-2025-1004\/\">Privilege Escalation via Symbolic Link Spoofing in TeamViewer Client\u00a0- TV-2025-1004<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">TeamViewer Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-638","alert_type":396,"serial_number":"AV25-638","subject":"other","moderation_state":"published","external_url":null},{"nid":6855,"title":"[Control systems] SSL security advisory (AV25-636)","uuid":"b38f5a8c-0781-4d53-a142-3e094d0fb5d6","banner":null,"lang":"en","date_modified":"2025-10-02","date_modified_ts":"2025-10-02T18:30:25Z","date_created":"2025-10-02T16:58:41Z","summary":null,"body":["<article data-history-node-id=\"6855\" about=\"\/en\/alerts-advisories\/control-systems-ssl-security-advisory-av25-636\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-636<br \/><strong>Date: <\/strong>October\u00a025, 2025<\/p>\n\n<p>On September\u00a030, 2025, OpenSSL published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSL\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html#CVE-2025-9230\">CVE-2025-9230<\/a><\/li>\n\t<li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html#CVE-2025-9231\">CVE-2025-9231<\/a><\/li>\n\t<li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html#CVE-2025-9232\">CVE-2025-9232<\/a><\/li>\n\t<li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html\">OpenSSL<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-ssl-security-advisory-av25-636","alert_type":398,"serial_number":"AV25-636","subject":"other","moderation_state":"published","external_url":null},{"nid":6856,"title":"Splunk security advisory (AV25-637)","uuid":"ffc5a510-fcbb-4d9d-a958-9732dcc55e30","banner":null,"lang":"en","date_modified":"2025-10-02","date_modified_ts":"2025-10-02T18:32:16Z","date_created":"2025-10-02T16:58:41Z","summary":null,"body":["<article data-history-node-id=\"6856\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-637\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-637<br \/><strong>Date: <\/strong>October\u00a02, 2025<\/p>\n\n<p>On October\u00a01, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk Enterprise\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-637","alert_type":396,"serial_number":"AV25-637","subject":"other","moderation_state":"published","external_url":null},{"nid":6858,"title":"Mozilla security advisory (AV25-635)","uuid":"b98f6fc8-47b1-47e0-be8a-05ce7618a57c","banner":null,"lang":"en","date_modified":"2025-10-02","date_modified_ts":"2025-10-02T18:08:45Z","date_created":"2025-10-02T17:48:13Z","summary":null,"body":["<article data-history-node-id=\"6858\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-635\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-635<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 2, 2025<\/p>\n\n<p>Between September 28 and 30, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 143.0.3<\/li>\n\t<li>Firefox for iOS\u00a0\u2013 versions prior to 143.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-80\/\">Security Vulnerabilities fixed in Firefox 143.0.3<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-79\/\">Security Vulnerabilities fixed in Firefox for iOS 143.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-635","alert_type":396,"serial_number":"AV25-635","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6860,"title":"Microsoft Edge security advisory (AV25-639)","uuid":"9dae7508-e744-466e-a1b0-784018ebe736","banner":null,"lang":"en","date_modified":"2025-10-03","date_modified_ts":"2025-10-03T13:49:21Z","date_created":"2025-10-03T13:15:17Z","summary":null,"body":["<article data-history-node-id=\"6860\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-639\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-639<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 3, 2025<\/p>\n\n<p>On October 2, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 141.0.3537.57<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-2-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-639","alert_type":396,"serial_number":"AV25-639","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6861,"title":"Oracle security advisory (AV25-640) \u2013 Update 1","uuid":"84008287-1425-4057-8be2-1c88acc6965d","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T18:21:00Z","date_created":"2025-10-06T12:37:58Z","summary":null,"body":["<article data-history-node-id=\"6861\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-av25-640\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-640<br \/><strong>Date: <\/strong>October 6, 2025<br \/><strong>Updated: <\/strong>October 20, 2025<\/p>\n\n<p>On October 4, 2025, Oracle published an out-of-band security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Oracle E-Business Suite\u00a0\u2013 versions 12.2.3 to 12.2.14<\/li>\n<\/ul><p>The Oracle advisory includes indicators of compromise (IOCs) to aid in the detection of malicious activity.<\/p>\n\n<h5>Update 1<\/h5>\n\n<p>On October 11, 2025, Oracle published an out-of-band security advisory to address a critical vulnerability CVE-2025-61884.<\/p>\n\n<p>As well, on October 20, 2025, CISA released a statement indicating that CVE-2025-61884 is being actively exploited in the wild and added it to their Known Exploited Vulnerabilities (KEV) Catalog.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2025-61882.html\">Oracle Security Alert Advisory\u00a0- CVE-2025-61882<\/a><\/li>\n\t<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2025-61884.html\">Oracle Security Alert Advisory\u00a0- CVE-2025-61884<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-61882\">CVE-2025-61882<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-61884\">CVE-2025-61884<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/10\/15\/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Adds One Known Exploited Vulnerability to Catalog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-av25-640","alert_type":396,"serial_number":"AV25-640","subject":"oracle","moderation_state":"published","external_url":null},{"nid":6862,"title":"IBM security advisory (AV25-641)","uuid":"e2e4cb3c-eb0a-43d2-81c9-286602a277c5","banner":null,"lang":"en","date_modified":"2025-10-06","date_modified_ts":"2025-10-06T12:59:47Z","date_created":"2025-10-06T12:54:32Z","summary":null,"body":["<article data-history-node-id=\"6862\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-641\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-641<br \/><strong>Date: <\/strong>October 6, 2025<\/p>\n\n<p>Between September 29 and October 5, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-641","alert_type":396,"serial_number":"AV25-641","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6863,"title":"Dell security advisory (AV25-642)","uuid":"a3c0f96c-dfe5-46a6-b3a5-93242324039c","banner":null,"lang":"en","date_modified":"2025-10-06","date_modified_ts":"2025-10-06T13:16:20Z","date_created":"2025-10-06T13:11:29Z","summary":null,"body":["<article data-history-node-id=\"6863\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-642\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-642<br \/><strong>Date: <\/strong>October 6, 2025<\/p>\n\n<p>Between September 29 and October 5, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.05.00.00<\/li>\n\t<li>Dell PowerProtect DP Series Appliance (Integrated Data Protection Appliance)\u00a0\u2013 versions 2.7.9 and prior<\/li>\n\t<li>Dell PowerProtect Data Domain\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerScale OneFS\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Repository Manager\u00a0\u2013 version 3.4.7 and 3.4.8<\/li>\n\t<li>Dell XtremIO X2\u00a0\u2013 versions prior to 6.4.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-642","alert_type":396,"serial_number":"AV25-642","subject":"dell","moderation_state":"published","external_url":null},{"nid":6864,"title":"Ubuntu security advisory (AV25-643)","uuid":"7bd30546-b229-4f66-a1c8-5ace0ea2c4b8","banner":null,"lang":"en","date_modified":"2025-10-06","date_modified_ts":"2025-10-06T13:20:55Z","date_created":"2025-10-06T13:17:14Z","summary":null,"body":["<article data-history-node-id=\"6864\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-643\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-643<br \/><strong>Date: <\/strong>October 6, 2025<\/p>\n\n<p>Between September 29 and October 5, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-643","alert_type":396,"serial_number":"AV25-643","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6865,"title":"[Control systems] CISA ICS security advisories (AV25\u2013644)","uuid":"29718151-b394-400e-8faa-607c207088b2","banner":null,"lang":"en","date_modified":"2025-10-06","date_modified_ts":"2025-10-06T13:30:34Z","date_created":"2025-10-06T13:21:49Z","summary":null,"body":["<article data-history-node-id=\"6865\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-644\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-644<br \/><strong>Date: <\/strong>October 6, 2025<\/p>\n\n<p>Between September 29 and October 5, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Festo CPX-CEC-C1\u00a0\u2013 version 2.0.12 and prior<\/li>\n\t<li>Festo CPX-CMXX\u00a0\u2013 version 1.2.34 rev.404 and prior<\/li>\n\t<li>Festo Controller CECC-S, -LK, -D Family Firmware\u00a0\u2013 all versions<\/li>\n\t<li>Festo SBRD-Q\/SBOC-Q\/SBOI-Q\u00a0\u2013 all versions<\/li>\n\t<li>Festo SET CPX-CEC-C1\u00a0\u2013 version 1.2.34 rev.404 and prior<\/li>\n\t<li>HEIDENHAIN Controller TNC 640 NC Software\u00a0\u2013 version 340590 07 SP5<\/li>\n\t<li>Hitachi Energy MSM\u00a0\u2013 versions 2.2.10 and prior<\/li>\n\t<li>Keysight Ixia Vision Product Family\u00a0\u2013 version 6.3.1<\/li>\n\t<li>LG Innotek Camera LND7210\u00a0\u2013 all versions<\/li>\n\t<li>LG Innotek Camera LNV7210R\u00a0\u2013 all versions<\/li>\n\t<li>MegaSys Enterprises Telenium Online Web Application\u00a0\u2013 versions prior to 8.4.21<\/li>\n\t<li>National Instruments Circuit Design Suite\u00a0\u2013 version v14.3.1 and prior<\/li>\n\t<li>OpenPLC_V3\u00a0\u2013 versions prior to pull request #292<\/li>\n\t<li>Raise3D Pro2 Series\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation 5094-IF8\u00a0\u2013 version V2.011<\/li>\n\t<li>Rockwell Automation 5094-IY8\u00a0\u2013 version V2.011<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-644","alert_type":398,"serial_number":"AV25-644","subject":"ics","moderation_state":"published","external_url":null},{"nid":6866,"title":"Red Hat security advisory (AV25-645)","uuid":"cf85b577-3be6-4773-bc74-e3c12b29bbe2","banner":null,"lang":"en","date_modified":"2025-10-06","date_modified_ts":"2025-10-06T13:36:15Z","date_created":"2025-10-06T13:32:35Z","summary":null,"body":["<article data-history-node-id=\"6866\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-645\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-645<br \/><strong>Date: <\/strong>October 6, 2025<\/p>\n\n<p>Between September 29 and October 5, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-645","alert_type":396,"serial_number":"AV25-645","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6869,"title":"Redis security advisory (AV25-646)","uuid":"af6d3fe4-295d-4a4d-aa0e-96b8c12061cf","banner":null,"lang":"en","date_modified":"2025-10-06","date_modified_ts":"2025-10-06T18:25:02Z","date_created":"2025-10-06T18:19:00Z","summary":null,"body":["<article data-history-node-id=\"6869\" about=\"\/en\/alerts-advisories\/redis-security-advisory-av25-646\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-646<br \/><strong>Date: <\/strong>October\u00a06, 2025<\/p>\n\n<p>On October\u00a03, 2025, Redis published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Redis Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Redis OSS\/CE\/Stack releases with Lua scripting\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/redis\/redis\/releases\/tag\/8.2.2\">Redis Security Advisory: CVE-2025-49844<\/a><\/li>\n\t<li><a href=\"https:\/\/redis.io\/blog\/security-advisory-cve-2025-49844\/\">Redis\u00a0- Releases<\/a><\/li>\n\t<li><a href=\"https:\/\/redis.io\/blog\/\">Redis Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/redis-security-advisory-av25-646","alert_type":396,"serial_number":"AV25-646","subject":"other","moderation_state":"published","external_url":null},{"nid":6870,"title":"AL25-013 \u2013 Vulnerability impacting Oracle E-Business Suite - CVE-2025-61882","uuid":"947dc2c8-a59d-41be-9235-29377d7cca39","banner":null,"lang":"en","date_modified":"2025-10-07","date_modified_ts":"2025-10-07T13:39:11Z","date_created":"2025-10-07T11:50:26Z","summary":null,"body":["<article data-history-node-id=\"6870\" about=\"\/en\/alerts-advisories\/al25-013-vulnerability-impacting-oracle-e-business-suite-cve-2025-61882\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-013<br \/><strong>Date:<\/strong>\u00a0October 7, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for IT professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On October 4, 2025, Oracle released a security alert advisory for Oracle E-Business Suite addressing a critical vulnerability that allows attackers to perform an unauthenticated remote code execution (CVE-2025-61882) affecting the following product<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>:<\/p>\n\n<ul><li>Oracle E-Business Suite\u00a0\u2013 versions 12.2.3 to 12.2.14<\/li>\n<\/ul><p>The vulnerability is within the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration) and has been assigned a CVSS severity rating of 9.8 out of 10<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>In response to this vulnerability, the Cyber Centre released AV25-640 on October 6, 2025<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. CISA has added CVE-2025-61882 to their Known Exploited Vulnerabilities (KEV) catalog<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> on October 6, 2025.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations patch the affected Oracle instances to the vendor recommended versions<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>You should also review and implement our Top 10 IT Security Actions<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Patching operating systems and applications.<\/li>\n\t<li>Isolating Web-facing applications.<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<p>Information provided by organizations not subject to the <em>Official Languages Act<\/em> is in the language(s) provided.<\/p>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2025-61882.html\">Oracle Security Alert Advisory\u00a0- CVE-2025-61882<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-61882\">CVE-2025-61882<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/alerts-advisories\/oracle-security-advisory-av25-640\">AV25-640\u00a0\u2013 Oracle security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities Catalog\u00a0| CISA <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-013-vulnerability-impacting-oracle-e-business-suite-cve-2025-61882","alert_type":397,"serial_number":"AL25-013","subject":"other","moderation_state":"published","external_url":null},{"nid":6871,"title":"Android security advisory \u2013 October 2025 monthly rollup (AV25-647)","uuid":"0cdcd412-cb08-4db6-a19d-0fdf04add560","banner":null,"lang":"en","date_modified":"2025-10-07","date_modified_ts":"2025-10-07T14:02:02Z","date_created":"2025-10-07T13:59:03Z","summary":null,"body":["<article data-history-node-id=\"6871\" about=\"\/en\/alerts-advisories\/android-security-advisory-october-2025-monthly-rollup-av25-647\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-647<br \/><strong>Date: <\/strong>October 6, 2025<\/p>\n\n<p>On October 6, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-10-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-october-2025-monthly-rollup-av25-647","alert_type":396,"serial_number":"AV25-647","subject":"android","moderation_state":"published","external_url":null},{"nid":6872,"title":"[Control systems] ABB security advisory (AV25-648) ","uuid":"92ede2ef-5730-4183-9392-f491b2baa298","banner":null,"lang":"en","date_modified":"2025-10-07","date_modified_ts":"2025-10-07T14:07:52Z","date_created":"2025-10-07T14:03:55Z","summary":null,"body":["<article data-history-node-id=\"6872\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-648\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-648<br \/><strong>Date: <\/strong>October 7, 2025<\/p>\n\n<p>On October 7, 2025, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>EIBPORT V3 KNX\u00a0\u2013 versions prior to 3.9.2<\/li>\n\t<li>EIBPORT V3 KNX GSM\u00a0\u2013 versions prior to 3.9.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A7808&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">EIBPORT Reflected XSS - CVE ID: CVE-2021-22291<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-648","alert_type":398,"serial_number":"AV25-648","subject":"abb","moderation_state":"published","external_url":null},{"nid":6873,"title":"Google Chrome security advisory (AV25-649)","uuid":"ff09d15f-b433-4df3-8bb4-089df4e5d46d","banner":null,"lang":"en","date_modified":"2025-10-08","date_modified_ts":"2025-10-08T12:39:22Z","date_created":"2025-10-08T12:34:19Z","summary":null,"body":["<article data-history-node-id=\"6873\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-649\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-649<br \/><strong>Date: <\/strong>October 8, 2025<\/p>\n\n<p>On October 7, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 141.0.7390.65\/.66 (Windows and Mac) and 141.0.7390.65 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/10\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-649","alert_type":396,"serial_number":"AV25-649","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6874,"title":"GitLab security advisory (AV25-650)","uuid":"48274787-8640-42ae-ac44-c28f0e1b75a4","banner":null,"lang":"en","date_modified":"2025-10-08","date_modified_ts":"2025-10-08T19:33:38Z","date_created":"2025-10-08T19:29:22Z","summary":null,"body":["<article data-history-node-id=\"6874\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-650\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-650<br \/><strong>Date: <\/strong>October 8, 2025<\/p>\n\n<p>On October 8, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.4.2, 18.3.4 and 18.2.8<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.4.2, 18.3.4 and 18.2.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/10\/08\/patch-release-gitlab-18-4-2-released\/\">GitLab Patch Release: 18.4.2, 18.3.4, 18.2.8<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-650","alert_type":396,"serial_number":"AV25-650","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6875,"title":"Juniper Networks security advisory (AV25-651)","uuid":"54d2418b-902f-4f5b-939a-a31f62e469c6","banner":null,"lang":"en","date_modified":"2025-10-09","date_modified_ts":"2025-10-09T12:55:35Z","date_created":"2025-10-09T12:49:42Z","summary":null,"body":["<article data-history-node-id=\"6875\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-651\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-651<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 9, 2025<\/p>\n\n<p>On October 8, 2025, Juniper Networks published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri#sortCriteria=date%20descending&amp;f-sf_primarysourcename=Knowledge&amp;f-sf_articletype=Security%20Advisories&amp;numberOfResults=25\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av25-651","alert_type":396,"serial_number":"AV25-651","subject":"juniper","moderation_state":"published","external_url":null},{"nid":6876,"title":"Esri security advisory (AV25-652)","uuid":"4eb2c07b-9cf2-4102-8338-3ccc979c06b4","banner":null,"lang":"en","date_modified":"2025-10-09","date_modified_ts":"2025-10-09T19:50:00Z","date_created":"2025-10-09T19:44:40Z","summary":null,"body":["<article data-history-node-id=\"6876\" about=\"\/en\/alerts-advisories\/esri-security-advisory-av25-652\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-652<br \/><strong>Date: <\/strong>October\u00a09, 2025<\/p>\n\n<p>On October\u00a06, 2025, Esri published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>ArcGIS Server\u00a0\u2013 versions 11.3, 11.4 and 11.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.esri.com\/arcgis-blog\/products\/trust-arcgis\/administration\/arcgis-server-feature-services-security-patch\">ArcGIS Server Feature Services Security Patch<\/a><\/li>\n\t<li><a href=\"https:\/\/support.esri.com\/en-us\/search?s=Newest&amp;cardtype=support_patches_updates\">Esri Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/esri-security-advisory-av25-652","alert_type":396,"serial_number":"AV25-652","subject":"other","moderation_state":"published","external_url":null},{"nid":6879,"title":"ServiceNow security advisory (AV25-655)","uuid":"213ecc27-2a3c-4062-9527-5de4a134836c","banner":null,"lang":"en","date_modified":"2025-10-10","date_modified_ts":"2025-10-10T15:01:03Z","date_created":"2025-10-10T13:35:03Z","summary":null,"body":["<article data-history-node-id=\"6879\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av25-655\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-655<br \/><strong>Date: <\/strong>October\u00a010, 2025<\/p>\n\n<p>On October\u00a09, 2025, ServiceNow published a Security Advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ServiceNow Washington DC\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Xanadu\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Yokohama\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Zurich\u00a0\u2013 multiple versions<\/li>\n\t<li>ServiceNow Australia\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB2552817\">CVE-2025-11449 &amp; CVE-2025-11450\u00a0- Reflected Cross Site Scripting in ServiceNow AI Platform<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av25-655","alert_type":396,"serial_number":"AV25-655","subject":"other","moderation_state":"published","external_url":null},{"nid":6877,"title":"Google Chrome security advisory (AV25-653)","uuid":"b05bf06a-0de5-4890-940b-f787e51d018f","banner":null,"lang":"en","date_modified":"2025-10-10","date_modified_ts":"2025-10-10T14:13:43Z","date_created":"2025-10-10T13:35:03Z","summary":null,"body":["<article data-history-node-id=\"6877\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-653\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-653<br \/><strong>Date: <\/strong>October\u00a010, 2025<\/p>\n\n<p>On October\u00a09, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 141.0.7390.76\/.77 (Windows and Mac) and 141.0.7390.76 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/10\/stable-channel-update-for-desktop_9.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-653","alert_type":396,"serial_number":"AV25-653","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6878,"title":"Microsoft Edge security advisory (AV25-654)","uuid":"7c5f95fc-e771-472d-a4eb-bd3a5ad7be62","banner":null,"lang":"en","date_modified":"2025-10-10","date_modified_ts":"2025-10-10T14:54:42Z","date_created":"2025-10-10T13:35:03Z","summary":null,"body":["<article data-history-node-id=\"6878\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-654\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-654<br \/><strong>Date: <\/strong>October\u00a010, 2025<\/p>\n\n<p>On October\u00a09, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 141.0.3537.71<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-9-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-654","alert_type":396,"serial_number":"AV25-654","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6882,"title":"Ubuntu security advisory (AV25-658)","uuid":"8f57cff6-4a06-496f-a090-564c89e0ea5d","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T13:14:53Z","date_created":"2025-10-14T12:51:55Z","summary":null,"body":["<article data-history-node-id=\"6882\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-658\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-658<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 6, 2025<\/p>\n\n<p>Between October 6 and 12, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7795-3\">USN-7795-3: Linux kernel (AWS FIPS) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7811-1\">USN-7811-1: Linux kernel (NVIDIA Tegra IGX) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7809-1\">USN-7809-1: Linux kernel (Azure, N-Series) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7789-2\">USN-7789-2: Linux kernel (Raspberry Pi) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-658","alert_type":396,"serial_number":"AV25-658","subject":"other","moderation_state":"published","external_url":null},{"nid":6880,"title":"IBM security advisory (AV25-656)","uuid":"56ea838a-6a3f-46ce-8d63-51a183266439","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T13:00:25Z","date_created":"2025-10-14T12:54:07Z","summary":null,"body":["<article data-history-node-id=\"6880\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-656\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-656<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>Between October 6 and 12, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-656","alert_type":396,"serial_number":"AV25-656","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6881,"title":"Dell security advisory (AV25-657)","uuid":"b2154181-a851-44e8-a740-d4ca6d5b010e","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T13:11:26Z","date_created":"2025-10-14T13:04:16Z","summary":null,"body":["<article data-history-node-id=\"6881\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-657\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-657<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>Between October 6 and 12, 2025, Dell published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>SupportAssist for Home PCs\u00a0\u2013 version prior to 4.8.2.29006<\/li>\n\t<li>SupportAssist for Business PCs\u00a0\u2013 version prior to 4.5.3.25254<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000378367\/dsa-2025-362-security-update-for-dell-supportassist-for-home-pcs-and-dell-supportassist-for-business-pcs-vulnerabilities\">DSA-2025-362: Security Update for Dell SupportAssist for Home PCs and Dell SupportAssist for Business PCs vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-657","alert_type":396,"serial_number":"AV25-657","subject":"dell","moderation_state":"published","external_url":null},{"nid":6883,"title":"Red Hat security advisory (AV25-659)","uuid":"44fde2f9-05e9-4158-91db-fe394547339c","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T14:06:31Z","date_created":"2025-10-14T13:58:48Z","summary":null,"body":["<article data-history-node-id=\"6883\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-659\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-659<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>Between October 6 and 12, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-659","alert_type":396,"serial_number":"AV25-659","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6884,"title":"[Control systems] CISA ICS security advisories (AV25\u2013660)","uuid":"0865e53c-4cdd-4c77-9cbb-31c9df7c9cb0","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T14:38:59Z","date_created":"2025-10-14T14:11:08Z","summary":null,"body":["<article data-history-node-id=\"6884\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-660\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25\u2013660<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>Between October 6 and 12, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics DIAScreen\u00a0\u2013 version 1.6.0 and prior<\/li>\n\t<li>Hitachi Energy Asset Suite\u00a0\u2013 version 9.7 and prior<\/li>\n\t<li>Rockwell Automation Firewall-Managed Support contract with Cisco firewall\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation IDC-Managed Support contract with Cisco Switching\u00a0\u2013 version Generations 1\u00a0- 5<\/li>\n\t<li>Rockwell Automation Industrial Data Center (IDC) with Cisco Switching\u00a0\u2013 version Generations 1\u00a0- 5<\/li>\n\t<li>Rockwell Automation Network-Managed Support contract with Cisco network switch\u00a0\u2013 all versions<\/li>\n\t<li>Rockwell Automation Stratix 5200, 5800\u00a0\u2013 version v17.17.01 and prior<\/li>\n\t<li>Rockwell Automation Stratix 5700, 5400, 5410\u00a0\u2013 version v15.2(8)E7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-660","alert_type":398,"serial_number":"AV25\u2013660","subject":"ics","moderation_state":"published","external_url":null},{"nid":6885,"title":"Ivanti security advisory (AV25-661)","uuid":"c3563986-b9be-4dbb-b36a-8bbef53a21b9","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T15:11:02Z","date_created":"2025-10-14T15:02:56Z","summary":null,"body":["<article data-history-node-id=\"6885\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-661\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-661<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>Between October 13 and 14, 2025, Ivanti published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Endpoint Manager\u00a0\u2013 version 2024 SU3 SR1 and prior<\/li>\n\t<li>Ivanti Endpoint Manager\u00a0\u2013 version 2022 SU8 SR2 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile\u00a0\u2013 versions 12.6.0.1, 12.5.0.2 and 12.4.0.3<\/li>\n\t<li>Ivanti Neurons for MDM\u00a0\u2013 version R118 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US\">Security Advisory Ivanti Endpoint Manager (EPM) October 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/October-2025-Security-Advisory-Ivanti-Neurons-for-MDM?language=en_US\">October 2025 Security Advisory Ivanti Neurons for MDM<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Endpoint-Manager-Mobile-EPMM-10-2025-Multiple-CVEs?language=en_US\">Security Advisory Endpoint Manager Mobile (EPMM) 10\/2025 (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-661","alert_type":396,"serial_number":"AV25-661","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":6886,"title":"SAP security advisory \u2013 October 2025 monthly rollup (AV25-662)","uuid":"5a5c04c9-4fb8-4fd9-85dc-358dbf31bbff","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T15:29:15Z","date_created":"2025-10-14T15:17:58Z","summary":null,"body":["<article data-history-node-id=\"6886\" about=\"\/en\/alerts-advisories\/sap-security-advisory-october-2025-monthly-rollup-av25-662\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-662<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>On October 14, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP NetWeaver AS Java\u00a0\u2013 version SERVERCORE 7.50<\/li>\n\t<li>SAP Print Service\u00a0\u2013 versions SAPSPRINT 8.00 and 8.10<\/li>\n\t<li>SAP Supplier Relationship Management\u00a0\u2013 versions SRMNXP01 100 and 150<\/li>\n\t<li>SAP Commerce Cloud\u00a0\u2013 versions HY_COM 2205, COM_CLOUD 2211 and 2211-JDK21<\/li>\n\t<li>SAP Data Hub Integration Suite\u00a0\u2013 versions CX_DATAHUB_INT_PACK 2205<\/li>\n\t<li>SAP Application Server for ABAP\u00a0\u2013 versions SAP_BASIS 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758 and 816<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP\u00a0\u2013 versions KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93 and 9.16<\/li>\n\t<li>SAP Commerce Cloud\u00a0\u2013 version COM_CLOUD 2211<\/li>\n\t<li>SAP NetWeaver AS ABAP and ABAP Platform\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.14, 9.15 and 9.16<\/li>\n\t<li>SAP S\/4HANA\u00a0\u2013 versions S4CORE 104, 105, 106, 107, 108 and 109<\/li>\n\t<li>SAP Financial Service Claims Management\u00a0\u2013 versions INSURANCE 803, 804, 805, 806, S4CEXT 107, 108 and 109<\/li>\n\t<li>SAP BusinessObjects\u00a0\u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP Cloud Appliance Library Appliances\u00a0\u2013 version TITANIUM_WEBAPP 4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/october-2025.html\">SAP Security Patch Day\u00a0\u2013 October 2025<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-october-2025-monthly-rollup-av25-662","alert_type":396,"serial_number":"AV25-662","subject":"sap","moderation_state":"published","external_url":null},{"nid":6887,"title":"HPE security advisory (AV25-663)","uuid":"6f934fe2-a699-4603-b681-92d21a9107b3","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T17:32:38Z","date_created":"2025-10-14T17:21:05Z","summary":null,"body":["<article data-history-node-id=\"6887\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-663\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-663<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>On October 13, 2025, HPE published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Compute Scale-up Server<\/span> 3200\u00a0\u2013 versions prior to v1.65.60<\/li>\n\t<li>HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Superdome Flex<\/span> 280 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Server<\/span>\u00a0- versions prior to v2.05.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04954en_us&amp;docLocale=en_US#hpesbhf04954-rev-1-hpe-compute-scale-up-server-320-0\">HPESBHF04954 rev.1\u00a0- HPE Compute Scale-up Server 3200 Platform and Superdome Flex 280 servers, Security Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-663","alert_type":396,"serial_number":"AV25-663","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6888,"title":"Qualcomm security advisory \u2013 October 2025 monthly rollup (AV25-664)","uuid":"297583e8-25ba-4454-96db-aab80da2e6c3","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T17:40:06Z","date_created":"2025-10-14T17:36:11Z","summary":null,"body":["<article data-history-node-id=\"6888\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-october-2025-monthly-rollup-av25-664\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-664<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>On October 6, 2025, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/october-2025-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 October<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-october-2025-monthly-rollup-av25-664","alert_type":396,"serial_number":"AV25-664","subject":"other","moderation_state":"published","external_url":null},{"nid":6889,"title":"VMware security advisory (AV25-665)","uuid":"f0962017-0927-483d-bc12-aa8a6808448e","banner":null,"lang":"en","date_modified":"2025-10-14","date_modified_ts":"2025-10-14T18:39:50Z","date_created":"2025-10-14T18:26:18Z","summary":null,"body":["<article data-history-node-id=\"6889\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-665\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-665<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 14, 2025<\/p>\n\n<p>On October 10, 2025, VMware published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Tanzu for MySQL on Kubernetes\u00a0\u2013 versions prior to 2.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36208\">Product Release Advisory\u00a0- VMware Tanzu for MySQL on Kubernetes 2.0.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT \">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-665","alert_type":396,"serial_number":"AV25-665","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6890,"title":"Microsoft security advisory \u2013 October 2025 monthly rollup (AV25-666) \u2013 Update 1","uuid":"62f4b446-27dd-457e-9ffe-d9ebda83b504","banner":null,"lang":"en","date_modified":"2025-10-24","date_modified_ts":"2025-10-24T16:05:25Z","date_created":"2025-10-15T12:11:04Z","summary":null,"body":["<article data-history-node-id=\"6890\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2025-monthly-rollup-av25-666\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-666<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2025<br \/><strong>Updated:<\/strong> October 24, 2025<\/p>\n\n<p>On October 14, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>.NET 8.0<\/li>\n\t<li>ASP.NET<\/li>\n\t<li>Arc Enabled Servers<\/li>\n\t<li>Azure Cache for Redis Enterprise<\/li>\n\t<li>Azure Compute Gallery<\/li>\n\t<li>Azure Confidential Compute VM<\/li>\n\t<li>Azure Managed Redis<\/li>\n\t<li>Azure Monitor<\/li>\n\t<li>Azure Monitor Agent<\/li>\n\t<li>Azure PlayFab<\/li>\n\t<li>DOOM<\/li>\n\t<li>Fallout Shelter<\/li>\n\t<li>Microsoft .NET Framework<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft 365 Copilot's Business Chat<\/li>\n\t<li>Microsoft 365 Word Copilot<\/li>\n\t<li>Microsoft Access 2016<\/li>\n\t<li>Microsoft Configuration Manager<\/li>\n\t<li>Microsoft Defender for Endpoint for Linux<\/li>\n\t<li>Microsoft Entra ID<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Server<\/li>\n\t<li>Microsoft Exchange Server 2016<\/li>\n\t<li>Microsoft Exchange Server 2019<\/li>\n\t<li>Microsoft JDBC<\/li>\n\t<li>Microsoft Mesh PC Applications<\/li>\n\t<li>Microsoft Mesh for Meta Quest<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft PowerPoint 2016<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Visual Studio 2017<\/li>\n\t<li>Microsoft Visual Studio 2019<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>PowerShell 7.4<\/li>\n\t<li>PowerShell 7.5<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Starfield Companion App<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows App Client for Windows Desktop<\/li>\n\t<li>Windows Server 2008<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2025-47827, CVE-2025-59230 and CVE-2025-24990 have available exploits.<\/p>\n\n<p><strong>Update 1<\/strong><br \/>\nOn October 23, 2025, Microsoft stated that Proof of Concept (PoC) exploit for critical vulnerability CVE-2025-59287 affecting their WSUS is now available online.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Oct\">October 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-october-2025-monthly-rollup-av25-666","alert_type":396,"serial_number":"AV25-666","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6891,"title":"Adobe security advisory (AV25-667)","uuid":"43e9cfd2-d6a9-41bb-b0fc-fb9fa00a2e45","banner":null,"lang":"en","date_modified":"2025-10-15","date_modified_ts":"2025-10-15T12:50:24Z","date_created":"2025-10-15T12:38:35Z","summary":null,"body":["<article data-history-node-id=\"6891\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-667\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-667<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2025<\/p>\n\n<p>On October 14, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Animate 2023\u00a0\u2013 version 23.0.13 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0\u2013 version 24.0.10 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 14.1.8 (LTS) and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 15.1.1 and prior<\/li>\n\t<li>Adobe Commerce B2B\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Connect\u00a0\u2013 version 12.9 and prior<\/li>\n\t<li>Adobe Dimension\u00a0\u2013 version 4.1.4 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM) Screens\u00a0\u2013 version AEM 6.5.22 Screens FP11.6<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 version 2020 Release Update 9 and prior<\/li>\n\t<li>Adobe FrameMaker\u00a0\u2013 version 2022 Release Update 7 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler\u00a0\u2013 version 1.22.3 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.1.4 and prior<\/li>\n\t<li>Adobe Substance 3D Viewer\u00a0\u2013 version 0.25.2 and prior<\/li>\n\t<li>Creative Cloud Desktop Application\u00a0\u2013 version 6.7.0.278 and prior<\/li>\n\t<li>Illustrator 2024\u00a0\u2013 version 28.7.9 and prior<\/li>\n\t<li>Illustrator 2025\u00a0\u2013 version 29.7 and prior<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-667","alert_type":396,"serial_number":"AV25-667","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6892,"title":"Fortinet security advisory (AV25-668)","uuid":"8550bbbd-d1cc-47f0-9409-31760a237cc6","banner":null,"lang":"en","date_modified":"2025-10-15","date_modified_ts":"2025-10-15T13:26:08Z","date_created":"2025-10-15T12:55:17Z","summary":null,"body":["<article data-history-node-id=\"6892\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-668\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-688<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2025<\/p>\n\n<p>On October 14, 2025, Fortinet published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-668","alert_type":396,"serial_number":"AV25-688","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":6893,"title":"F5 security advisory (AV25-669) - Update 1","uuid":"18661865-48c1-476b-8486-e2700319aca0","banner":null,"lang":"en","date_modified":"2026-03-27","date_modified_ts":"2026-03-27T19:56:34Z","date_created":"2025-10-15T15:32:02Z","summary":null,"body":["<article data-history-node-id=\"6893\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av25-669\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-669<br \/><strong>Date: <\/strong>October 15, 2025<br \/><strong>Updated: <\/strong>March 27, 2026<\/p>\n\n<p>On October 15, 2025, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP (all modules)\u00a0\u2013 versions 17.5.0 to 17.5.1, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.6, versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP AFM\u00a0\u2013 version 17.5.0, versions 17.1.0 to 17.1.2, versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP APM\u00a0\u2013 versions 17.5.0 to 17.5.1, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.6, versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP APM, APM with SWG, SSL Orchestrator, SSL Orchestrator with SWG\u00a0\u2013 version 17.5.0, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.6, versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP ASM\u00a0\u2013 versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.5<\/li>\n\t<li>BIG-IP Advanced WAF\/ASM\u00a0\u2013 versions 17.5.0 to 17.5.1, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.6, versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP Next CNF\u00a0\u2013 versions 2.0.0 to 2.1.0, versions 1.1.0 to 1.4.1<\/li>\n\t<li>BIG-IP Next SPK\u00a0\u2013 versions 2.0.0 to 2.1.0, versions 1.7.0 to 1.9.2<\/li>\n\t<li>BIG-IP Next for Kubernetes\u00a0\u2013 versions 2.0.0 to 2.1.0<\/li>\n\t<li>BIG-IP PEM\u00a0\u2013 version 17.5.0, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.6, versions 15.1.0 to 15.1.10<\/li>\n\t<li>BIG-IP SSL Orchestrator\u00a0\u2013 version 17.5.0, versions 17.1.0 to 17.1.2, versions 16.1.0 to 16.1.5, versions 15.1.0 to 15.1.10<\/li>\n\t<li>F5OS-A\u00a0\u2013 versions 1.8.0 to 1.8.1, versions 1.5.1 to 1.5.3<\/li>\n\t<li>F5OS-C\u00a0\u2013 version 1.8.0 to 1.8.1, versions 1.6.0 to 1.6.2<\/li>\n\t<li>NGINX App Protect WAF\u00a0\u2013 versions 4.5.0 to 4.6.0<\/li>\n<\/ul><p>On October 15, 2025, F5 also published security incident K000154696 advising that threat actors exfiltrated files from BIG-IP products and they are not aware of active exploitation of any undisclosed F5 vulnerabilities.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>F5 indicates that CVE-2025-53521 has been exploited.<\/p>\n\n<p>On March 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-53521 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg\">The Cyber Centre encourages users\/administrators to review the links provided below, to identify F5 BIG-IP products, evaluate and address any potential compromise on any networked managed interface exposed to the public internet and apply F5 security updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000156741\">K000156741: BIG-IP APM vulnerability CVE-2025-53521<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000160486\">K000160486: Indicators of Compromise for c05d5254<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-53521\">CISA KEV: CVE-2025-53521<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000154696\">K000154696: F5 Security Incident<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K53108777\">K53108777: Hardening your F5 system<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000156572\">F5 Quarterly Security Notification (October 2025)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av25-669","alert_type":396,"serial_number":"AV25-669","subject":"f5","moderation_state":"published","external_url":null},{"nid":6894,"title":"[Control systems] ABB security advisory (AV25-670)","uuid":"3fc7307c-4ec8-4c5b-8722-f31b5c0e0f67","banner":null,"lang":"en","date_modified":"2025-10-15","date_modified_ts":"2025-10-15T16:00:01Z","date_created":"2025-10-15T15:52:01Z","summary":null,"body":["<article data-history-node-id=\"6894\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-670\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-670<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2025<\/p>\n\n<p>Between October 7 and 14, 2025, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automation Runtime\u00a0\u2013 versions prior to 6.4 and versions prior to Q4.93<\/li>\n\t<li>MConfig\u00a0\u2013 version V1.4.9.21 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P002-f6a69e61.pdf\">B&amp;R Automation Runtime DoS Vulnerability in SDM\u00a0- CVE ID: CVE-2025-3450 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=4TZ00000006008&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch \">LVS MConfig Insecure memory handling\u00a0- CVE ID: CVE-2025-9970<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P003-178b6a20.pdf\">B&amp;R Automation Runtime Vulnerabilities in (SDM)\u00a0- CVE ID: CVE-2025-3449, CVE-2025-3448, CVE-2025-11498 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-670","alert_type":398,"serial_number":"AV25-670","subject":"abb","moderation_state":"published","external_url":null},{"nid":6895,"title":"Google Chrome security advisory (AV25-671)","uuid":"7b94f5a8-cc2d-412b-85c9-5fde5505f716","banner":null,"lang":"en","date_modified":"2025-10-15","date_modified_ts":"2025-10-15T19:51:08Z","date_created":"2025-10-15T19:46:16Z","summary":null,"body":["<article data-history-node-id=\"6895\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-671\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-671<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2025<\/p>\n\n<p>On October 14, 2025, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to0.7390.107\/.108 (Windows and Mac) and 141.0.7390.107 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/10\/stable-channel-update-for-desktop_14.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-671","alert_type":396,"serial_number":"AV25-671","subject":"other","moderation_state":"published","external_url":null},{"nid":6897,"title":"AL25-014 Security Incident impacting F5","uuid":"ad2dc03f-1362-4ebd-b081-26486bd38aca","banner":null,"lang":"en","date_modified":"2025-10-15","date_modified_ts":"2025-10-15T20:21:43Z","date_created":"2025-10-15T19:58:40Z","summary":null,"body":["<article data-history-node-id=\"6897\" about=\"\/en\/alerts-advisories\/al25-014-security-incident-impacting-f5\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-014<br \/><strong>Date:<\/strong> October\u00a015, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On October 15, 2025, F5 published security incident K000154696, advising that a highly sophisticated nation-state threat actor maintained long-term, persistent access to, and downloaded files from, certain F5 systems <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, including the BIG-IP product development environment and engineering knowledge management platforms, as well as configuration or implementation information for a small percentage of customers.<\/p>\n\n<p>In response to this security incident, and the release of the F5 Quarterly Security Notification, the Cyber Centre released AV25-669 on October 15, 2025 <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. The purpose of this alert is to increase awareness of this reported incident.<\/p>\n\n<p>The Cyber Centre is aware of online interest and speculation about this security incident and is publishing this Alert out of an abundance of caution.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre suggests the following actions:<\/p>\n\n<ul><li>Perform a thorough inventory of all F5 assets<\/li>\n\t<li>Isolate F5 management interfaces that are facing the public internet<\/li>\n\t<li>Assess systems for potential compromise, and apply recommended mitigations<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/li>\n\t<li>Patch F5 assets to latest versions<\/li>\n\t<li>Decommission End-of-Life F5 products<\/li>\n<\/ul><p>F5 Support has released a threat hunting guide intended to enhance detection and monitoring within customer environments. However, the Cyber Centre has received feedback indicating that the document may be primarily focused on the specific incident involving F5 and thus may have limited applicability to broader customer contexts.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000154696\">K000154696: F5 Security Incident<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/f5-security-advisory-av25-669\">AV25-669\u00a0\u2013 F5 security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000156572\">F5 Quarterly Security Notification (October 2025)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/ed-26-01-mitigate-vulnerabilities-f5-devices\">CISA ED 26-01: Mitigate Vulnerabilities in F5 Devices<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/10\/15\/cisa-directs-federal-agencies-mitigate-vulnerabilities-f5-devices\">CISA Directs Federal Agencies to Mitigate Vulnerabilities in F5 Devices<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-014-security-incident-impacting-f5","alert_type":397,"serial_number":"AL25-014","subject":"other","moderation_state":"published","external_url":null},{"nid":6896,"title":"Cisco security advisory (AV25-672)","uuid":"b24782d7-9e95-4a20-80e0-0bb6c6612c35","banner":null,"lang":"en","date_modified":"2025-10-15","date_modified_ts":"2025-10-15T20:10:49Z","date_created":"2025-10-15T19:59:19Z","summary":null,"body":["<article data-history-node-id=\"6896\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-672\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-672<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 15, 2025<\/p>\n\n<p>On October 15, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco TelePresence CE on-premises\u00a0\u2013 versions 9, 10 and versions prior to 11.32.2.1<\/li>\n\t<li>Cisco RoomOS Release on-premises\u00a0\u2013 versions 9, 10 and versions prior to 11.32.2.1<\/li>\n\t<li>Cisco RoomOS Release cloud-aware\u00a0\u2013 versions prior to July 2025<\/li>\n\t<li>Cisco Open Source Snort 3\u00a0\u2013 versions prior to 3.9.3.0<\/li>\n\t<li>Cisco Desk Phone 9800 Series\u00a0\u2013 versions prior to 3.3(1)<\/li>\n\t<li>Cisco IP Phone 7800 and 8800 Series\u00a0\u2013 versions prior to 14.4(1)<\/li>\n\t<li>Cisco IP Phone 8821\u00a0\u2013 versions prior to 11.0(6)SR7<\/li>\n\t<li>Cisco Video Phone 8875\u00a0\u2013 versions prior to 3.3(1)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-roomos-inf-disc-qGgsbxAm\">Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-snort3-mime-vulns-tTL8PgVH#fs\">Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-phone-dos-FPyjLV7A\">Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-672","alert_type":396,"serial_number":"AV25-672","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6898,"title":"HPE security advisory (AV25-673)","uuid":"8d3291eb-200b-41b3-8944-5f5cdabae3bb","banner":null,"lang":"en","date_modified":"2025-10-16","date_modified_ts":"2025-10-16T13:56:15Z","date_created":"2025-10-16T13:45:12Z","summary":null,"body":["<article data-history-node-id=\"6898\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-673\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-673<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 16, 2025<\/p>\n\n<p>Between October 13 and 15, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant RL300 Gen11\u00a0\u2013 versions prior to v1.78<\/li>\n\t<li>HPE ProLiant AMD Servers\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Aruba Networking\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04952en_us&amp;docLocale=en_US\">HPESBHF04952 rev.1\u00a0- HPE ProLiant RL300 Gen11 Server, Out-of-Bound Reads Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04956en_us&amp;docLocale=en_US\">HPESBHF04956 rev.1\u00a0- Certain HPE ProLiant AMD Servers Using Certain AMD EPYC Processors, AMD-SB-3020: SEV-SNP RMP Initialization Vulnerability, Local Unauthorized Access Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04957en_us&amp;docLocale=en_US\">HPESBNW04957 rev.1\u00a0- HPE Aruba Networking AOS-10 and AOS-8 Mobility Conductor, Controllers, and Gateways, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04958en_us&amp;docLocale=en_US\">HPESBNW04958 rev.1\u00a0- HPE Aruba Networking AOS-8 Instant AP and AOS-10 AP, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-673","alert_type":396,"serial_number":"AV25-673","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6899,"title":"Mozilla security advisory (AV25-674)","uuid":"5651002b-d988-48f3-bdf3-73c0f70e19ad","banner":null,"lang":"en","date_modified":"2025-10-16","date_modified_ts":"2025-10-16T14:37:14Z","date_created":"2025-10-16T14:26:04Z","summary":null,"body":["<article data-history-node-id=\"6899\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-674\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-674<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 16, 2025<\/p>\n\n<p>On October 14, 2025, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Mozilla<\/span> published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0- versions prior to 144<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.29<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 140.4<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 144<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 140.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-674","alert_type":396,"serial_number":"AV25-674","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6900,"title":"[Control systems] Schneider Electric security advisory (AV25-675) ","uuid":"055ff97b-4082-4c87-b6ed-c4d254661b62","banner":null,"lang":"en","date_modified":"2025-10-16","date_modified_ts":"2025-10-16T19:44:46Z","date_created":"2025-10-16T19:34:01Z","summary":null,"body":["<article data-history-node-id=\"6900\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-675\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-675<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 16, 2025<\/p>\n\n<p>On October 14, 2025, Schneider Electric published advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>EcoStruxure\u2122 OPC UA Server Expert\u00a0\u2013 versions prior to SV2.01 SP3<\/li>\n\t<li>EcoStruxureTM Modicon Communication Server\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-287-01&amp;&amp;p_enDocType=Security+and+Safety+Notice&amp;&amp;p_File_Name=SEVD-2025-287-01.pdf\">EcoStruxure\u2122 OPC UA Server Expert and EcoStruxureTM Modicon Communication Server<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-675","alert_type":398,"serial_number":"AV25-675","subject":"se","moderation_state":"published","external_url":null},{"nid":6902,"title":"[Control systems] Siemens security advisory (AV25-676)","uuid":"f18736cd-bef2-4ee8-96a1-ea028f89cdad","banner":null,"lang":"en","date_modified":"2025-10-16","date_modified_ts":"2025-10-16T20:29:51Z","date_created":"2025-10-16T20:22:29Z","summary":null,"body":["<article data-history-node-id=\"6902\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-676\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-676<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 16, 2025<\/p>\n\n<p>On October 14, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>TeleControl Server Basic V3.1\u00a0\u2013 versions V3.1.2.2 to versions prior to V3.1.2.3<\/li>\n\t<li>SINEC NMS\u00a0\u2013 versions prior to V4.0 SP1<\/li>\n\t<li>Industrial Edge App Publisher\u00a0\u2013 versions prior to V1.23.5<\/li>\n\t<li>SIMATIC ET 200SP communication processors\u00a0\u2013 versions prior to V2.4.24<\/li>\n\t<li>Solid Edge SE2024\u00a0\u2013 versions prior to V224.0 Update 14<\/li>\n\t<li>Solid Edge SE2025\u00a0\u2013 versions prior to V225.0 Update 6<\/li>\n\t<li>SiPass integrated\u00a0\u2013 versions prior to V3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-062309.html\">SSA-062309: Information Disclosure Vulnerability in TeleControl Server Basic V3.1<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-318832.html\">SSA-318832: SQL Injection Vulnerability in SINEC NMS<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-365200.html\">SSA-365200: Google Chrome Type Confusion Vulnerability in Siemens Products<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-486936.html\">SSA-486936: Authentication Vulnerability in SIMATIC ET 200SP Communication Processors<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-541582.html\">SSA-541582: Multiple File Parsing Vulnerabilities in Solid Edge<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-676","alert_type":398,"serial_number":"AV25-676","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6903,"title":"WatchGuard security advisory (AV25-677) \u2013 Update 1","uuid":"7303d9e1-a952-4bbc-b4fc-007cbeb1fe4b","banner":null,"lang":"en","date_modified":"2025-11-10","date_modified_ts":"2025-11-10T20:01:16Z","date_created":"2025-10-16T20:32:03Z","summary":null,"body":["<article data-history-node-id=\"6903\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av25-677\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-677<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 16, 2025<br \/><strong>Updated: <\/strong>November 10, 2025<\/p>\n\n<p>On September 17, 2025, WatchGuard published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Fireware OS\u00a0\u2013 version 11.10.2 to 11.12.4_Update1, version 12.0 to 12.11.3, and version 2025.1.<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>WatchGuard has advised that vulnerability CVE-2025-9242 is under active exploitation.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2025-00015\">WatchGuard Firebox iked Out of Bounds Write Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av25-677","alert_type":396,"serial_number":"AV25-677","subject":"other","moderation_state":"published","external_url":null},{"nid":6905,"title":"Zimbra security advisory (AV25-678)","uuid":"bedb232c-aced-4e58-9f14-0bd3571092c5","banner":null,"lang":"en","date_modified":"2025-10-17","date_modified_ts":"2025-10-17T15:57:39Z","date_created":"2025-10-17T15:54:12Z","summary":null,"body":["<article data-history-node-id=\"6905\" about=\"\/en\/alerts-advisories\/zimbra-security-advisory-av25-678\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-678<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 17, 2025<\/p>\n\n<p>On October 16, 2025, Zimbra published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Zimbra Daffodil\u00a0\u2013 versions prior to v10.1.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Releases\/10.1.12#Zimbra_Daffodil_(v10.1.12)_Patch_Release\">Zimbra Daffodil (v10.1.12) Patch Release<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zimbra-security-advisory-av25-678","alert_type":396,"serial_number":"AV25-678","subject":"other","moderation_state":"published","external_url":null},{"nid":6906,"title":"IBM security advisory (AV25-679)","uuid":"411f9b9c-a93a-4a10-ab67-b9fbabc82e92","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T13:16:11Z","date_created":"2025-10-20T13:11:35Z","summary":null,"body":["<article data-history-node-id=\"6906\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-679\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-679<br \/><strong>Date: <\/strong>October 20, 2025<\/p>\n\n<p>Between October 13 and 19, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-679","alert_type":396,"serial_number":"AV25-679","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6907,"title":"Dell security advisory (AV25-680)","uuid":"654cdaa8-29fa-4c04-8764-52451df48175","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T13:28:26Z","date_created":"2025-10-20T13:23:18Z","summary":null,"body":["<article data-history-node-id=\"6907\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-680\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-680<br \/><strong>Date: <\/strong>October 20, 2025<\/p>\n\n<p>Between October 13 and 19, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell AMD-based PowerEdge Server\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell AX System for Azure\u00a0\u2013 versions prior to 2509<\/li>\n\t<li>Dell Connectrix MDS\u00a0\u2013 versions prior to 9.4 (3a)<\/li>\n\t<li>Dell Integrated System for Microsoft Azure Stack Hub 16G and 14G\u00a0\u2013 versions prior to 2508<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions prior to 10.6.0.6<\/li>\n\t<li>Dell PowerEdge T40\u00a0\u2013 versions prior to 1.21.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-680","alert_type":396,"serial_number":"AV25-680","subject":"dell","moderation_state":"published","external_url":null},{"nid":6909,"title":"Ubuntu security advisory (AV25-681)","uuid":"5411c8c5-eacc-4cdf-b249-bf5ab30896de","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T15:21:22Z","date_created":"2025-10-20T15:11:27Z","summary":null,"body":["<article data-history-node-id=\"6909\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-681\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-681<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 20, 2025<\/p>\n\n<p>Between October\u00a013 and 19, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-681","alert_type":396,"serial_number":"AV25-681","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6910,"title":"[Control systems] CISA ICS security advisories (AV25\u2013682)","uuid":"71188dbf-5935-4bdc-8a22-32f4ae933814","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T15:41:56Z","date_created":"2025-10-20T15:25:56Z","summary":null,"body":["<article data-history-node-id=\"6910\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-682\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25\u2013682<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 20, 2025<\/p>\n\n<p>Between October 13 and 19, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics CNCSoft-G2\u00a0\u2013 multiple versions<\/li>\n\t<li>Hitachi Energy MACH GWS\u00a0\u2013 versions 3.0.0.0 to 3.4.0.0<\/li>\n\t<li>Rockwell Automation 1715 EtherNet\/IP\u00a0\u2013 version 3.003 and prior<\/li>\n\t<li>Rockwell Automation ArmorStart AOP\u00a0\u2013 version V2.05.07 and prior<\/li>\n\t<li>Rockwell Automation FactoryTalk Linx\u00a0\u2013 version 6.40 and prior<\/li>\n\t<li>Rockwell Automation FactoryTalk View Machine Edition\u00a0\u2013 versions prior to V15.00 (CVE-2025-9064)<\/li>\n\t<li>Rockwell Automation PanelView Plus 7 Terminal\u00a0\u2013 version 14 and prior<\/li>\n\t<li>Rockwell Automation PanelView Plus 7\u00a0\u2013 versions V14.100 (CVE-2025-9063)<\/li>\n\t<li>Schneider Electric Advanced Reporting and Dashboards Module optional component of EcoStruxure Power Operation (EPO) installed with EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Schneider Electric EcoStruxure Power Monitoring Expert (PME): version 2022, 2023, 2024 and 2024 R2<\/li>\n\t<li>Siemens HyperLynx\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Industrial Edge App Publisher\u00a0\u2013 versions prior to 1.23.5<\/li>\n\t<li>Siemens SIMATIC ET 200SP Communication Processors\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V4.0 SP1<\/li>\n\t<li>Siemens SiPass Integrated\u00a0\u2013 versions prior to V3.0<\/li>\n\t<li>Siemens Solid Edge SE2024\u00a0\u2013 versions prior to V224.0 Update 14<\/li>\n\t<li>Siemens Solid Edge SE2025\u00a0\u2013 versions prior to V225.0 Update 6<\/li>\n\t<li>Siemens TeleControl Server Basic V3.1\u00a0\u2013 version V3.1.2.2 and up to but not including V3.1.2.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-682","alert_type":398,"serial_number":"AV25\u2013682","subject":"ics","moderation_state":"published","external_url":null},{"nid":6911,"title":"Microsoft Edge security advisory (AV25-683)","uuid":"ca963668-250b-4cbc-b0e0-a646a42e3426","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T15:52:27Z","date_created":"2025-10-20T15:47:30Z","summary":null,"body":["<article data-history-node-id=\"6911\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-683\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-683<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 20, 2025<\/p>\n\n<p>On October\u00a017, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 141.0.3537.85<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#october-17-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-683","alert_type":396,"serial_number":"AV25-683","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6912,"title":"Red Hat security advisory (AV25-684)","uuid":"f26a1961-7d7e-4285-b390-4a8e835c214e","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T16:18:53Z","date_created":"2025-10-20T16:12:57Z","summary":null,"body":["<article data-history-node-id=\"6912\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-684\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-684<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 20, 2025<\/p>\n\n<p>Between October 13 and 19, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-684","alert_type":396,"serial_number":"AV25-684","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6913,"title":"ConnectWise security advisory (AV25-685)","uuid":"76ff6595-5db5-45da-8b81-8120bf78456b","banner":null,"lang":"en","date_modified":"2025-10-20","date_modified_ts":"2025-10-20T16:26:22Z","date_created":"2025-10-20T16:21:40Z","summary":null,"body":["<article data-history-node-id=\"6913\" about=\"\/en\/alerts-advisories\/connectwise-security-advisory-av25-685\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-685<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 20, 2025<\/p>\n\n<p>On October 16, 2025, ConnectWise published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ConnectWise Automate\u00a0\u2013 versions prior to 2025.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/connectwise-automate-2025.9-security-fix\">ConnectWise Automate 2025.9 Security Fix<\/a><\/li>\n\t<li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/advisories\">ConnectWise\u00a0- Latest Advisories <\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/connectwise-security-advisory-av25-685","alert_type":396,"serial_number":"AV25-685","subject":"other","moderation_state":"published","external_url":null},{"nid":6914,"title":"Zyxel security advisory (AV25-686)","uuid":"0aa5a0e3-1a55-4d81-9d65-71f98ce42432","banner":null,"lang":"en","date_modified":"2025-10-21","date_modified_ts":"2025-10-21T17:54:43Z","date_created":"2025-10-21T17:44:36Z","summary":null,"body":["<article data-history-node-id=\"6914\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av25-686\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-686<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 21, 2025<\/p>\n\n<p>On October 21, 2025, Zyxel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ATP\u00a0\u2013 versions ZLD V4.32 to V5.40<\/li>\n\t<li>USG FLEX\u00a0\u2013 versions ZLD V4.50 to V5.40<\/li>\n\t<li>USG FLEX 50(W)\/ USG20(W)-VPN\u00a0\u2013 versions ZLD V4.16 to V5.40<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-post-authentication-command-injection-and-missing-authorization-vulnerabilities-in-zld-firewalls-10-21-2025\">Zyxel security advisory for post-authentication command injection and missing authorization vulnerabilities in ZLD firewalls<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av25-686","alert_type":396,"serial_number":"AV25-686","subject":"other","moderation_state":"published","external_url":null},{"nid":6915,"title":"[Control systems] ABB security advisory (AV25-687)","uuid":"64dcd450-3532-4003-9daa-b051efd8f209","banner":null,"lang":"en","date_modified":"2025-10-21","date_modified_ts":"2025-10-21T19:51:42Z","date_created":"2025-10-21T19:24:44Z","summary":null,"body":["<article data-history-node-id=\"6915\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-687\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-687<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 21, 2025<\/p>\n\n<p>On October 20, 2025, ABB published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Terra AC wallbox (UL40\/80A)\u00a0\u2013 versions 1.8.32 and prior<\/li>\n\t<li>Terra AC wallbox (UL32A)\u00a0\u2013 versions 1.8.2 and prior<\/li>\n\t<li>Terra AC wallbox (CE)\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Terra AC wallbox (JP)\u00a0\u2013 versions 1.8.2 and prior<\/li>\n\t<li>ALS-mini-S4\/S8 IP\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108471A8948&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">Terra AC wallbox Heap Memory Corruption Vulnerability\u00a0- CVE ID: CVE-2025-5517 <\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=4TZ00000006007&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">ALS-mini-S4\/S8 IP Missing Authentication Vulnerability and its Mitigations <\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-687","alert_type":398,"serial_number":"AV25-687","subject":"abb","moderation_state":"published","external_url":null},{"nid":6916,"title":"Oracle security advisory \u2013 October 2025 quarterly rollup (AV25-688) \u2013 Update 2","uuid":"5fccc73e-ef77-4d6a-8971-a4db886ba731","banner":null,"lang":"en","date_modified":"2025-11-21","date_modified_ts":"2025-11-21T21:38:07Z","date_created":"2025-10-22T12:45:17Z","summary":null,"body":["<article data-history-node-id=\"6916\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-october-2025-quarterly-rollup-av25-688\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-688<br \/><strong>Date: <\/strong>October 22, 2025<br \/><strong>Updated:<\/strong> November 21, 2025<\/p>\n\n<p>On October 21, 2025, Oracle published a security advisory to address vulnerabilities in multiple products.<\/p>\n\n<p>Included were security advisories for critical vulnerabilities CVE-2025-53072 and CVE-2025-62481 affecting Oracle E-Business products.<\/p>\n\n<p><strong>Update 1<\/strong><br \/>\nOn November 20, 2025, a proof of concept (PoC) for CVE-2025-61757 has been made available and open-source reporting indicated that exploitation has been observed since August 30, 2025.<\/p>\n\n<p><strong>Update 2<\/strong><br \/>\nOn November 21, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-61757 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/11\/21\/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Adds One Known Exploited Vulnerability to Catalog<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-61757\">CVE-2025-61757<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-53072\">CVE-2025-53072<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-62481\">CVE-2025-62481<\/a><\/li>\n\t<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuoct2025.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 October 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-october-2025-quarterly-rollup-av25-688","alert_type":396,"serial_number":"AV25-688","subject":"oracle","moderation_state":"published","external_url":null},{"nid":6917,"title":"GitLab security advisory (AV25-689)","uuid":"3948f78e-47a5-414c-a2d4-a591e7f4c914","banner":null,"lang":"en","date_modified":"2025-10-22","date_modified_ts":"2025-10-22T12:56:54Z","date_created":"2025-10-22T12:52:35Z","summary":null,"body":["<article data-history-node-id=\"6917\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-689\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-689<br \/><strong>Date: <\/strong>October 22, 2025<\/p>\n\n<p>On October 22, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.5.1, 18.4.3 and 18.3.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.5.1, 18.4.3 and 18.3.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/10\/22\/patch-release-gitlab-18-5-1-released\/\">GitLab Patch Release: 18.5.1, 18.4.3, 18.3.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-689","alert_type":396,"serial_number":"AV25-689","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6918,"title":"SolarWinds security advisory (AV25-690)","uuid":"54d635d0-bf0e-4812-b3a5-cf74978797fe","banner":null,"lang":"en","date_modified":"2025-10-22","date_modified_ts":"2025-10-22T15:57:04Z","date_created":"2025-10-22T15:51:05Z","summary":null,"body":["<article data-history-node-id=\"6918\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-690\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-690<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 22, 2025<\/p>\n\n<p>On October 21, 2025, SolarWinds published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SolarWinds Observability Self-Hoste\u00a0\u2013 version 2025.2.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2025-26392\">SolarWinds Observability Self-Hosted SQL Injection Vulnerability (CVE-2025-26392)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-690","alert_type":396,"serial_number":"AV25-690","subject":"other","moderation_state":"published","external_url":null},{"nid":6919,"title":"Ericsson security advisory (AV25-691)","uuid":"894e18ad-28d3-4e01-81e4-7098b3402efa","banner":null,"lang":"en","date_modified":"2025-10-22","date_modified_ts":"2025-10-22T16:16:02Z","date_created":"2025-10-22T16:01:30Z","summary":null,"body":["<article data-history-node-id=\"6919\" about=\"\/en\/alerts-advisories\/ericsson-security-advisory-av25-691\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-691<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 22, 2025<\/p>\n\n<p>Between September 25 and October 13, 2025, Ericsson published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ericsson Indoor Connect<\/span> 8855\u00a0\u2013 versions prior to 2025.Q2<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ericcson Network Manager<\/span>\u00a0\u2013 versions prior to 25.1 and 25.2<\/li>\n\t<li>RAN <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Compute<\/span> (all BB versions)\u00a0\u2013 versions prior to 24.Q1.C5<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Site Controller<\/span> 6610\u00a0\u2013 versions prior to S24.Q2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/psirt\/e2025-09-25\">Security Bulletin\u00a0\u2013 Ericsson Indoor Connect 8855, September 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/psirt\/cve-2025-0636\">Security Bulletin\u00a0\u2013 Ericsson High Severity Vulnerability in EMCLI included in Ericsson RAN Compute and Site Controller, October 2025 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/psirt\/security-bulletin-enm-october-2025\">Security Bulletin\u00a0\u2013 Ericsson Network Manager (ENM), October 2025 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/security-bulletins\">Ericsson Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ericsson-security-advisory-av25-691","alert_type":396,"serial_number":"AV25-691","subject":"other","moderation_state":"published","external_url":null},{"nid":6920,"title":"Google Chrome security advisory (AV25-692)","uuid":"d3db5858-1239-4a4f-9f42-3dcfe419ae19","banner":null,"lang":"en","date_modified":"2025-10-22","date_modified_ts":"2025-10-22T18:07:42Z","date_created":"2025-10-22T18:03:36Z","summary":null,"body":["<article data-history-node-id=\"6920\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-692\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-692<br \/><strong>Date: <\/strong>October 22, 2025<\/p>\n\n<p>On October 21, 2025, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 141.0.7390.122\/.123 (Windows and Mac) and 141.0.7390.122 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/10\/stable-channel-update-for-desktop_21.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-692","alert_type":396,"serial_number":"AV25-692","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6921,"title":"ISC BIND security advisory (AV25-693) \u2013 Update 1","uuid":"8d6d2bdd-7b49-441b-9052-e35939087afa","banner":null,"lang":"en","date_modified":"2025-10-29","date_modified_ts":"2025-10-29T19:43:30Z","date_created":"2025-10-22T18:58:51Z","summary":null,"body":["<article data-history-node-id=\"6921\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av25-693\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-693<br \/><strong>Date: <\/strong>October 22, 2025<br \/><strong>Updated:<\/strong> October 29, 2025<\/p>\n\n<p>On October 22, 2025, ISC published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ISC BIND 9\u00a0\u2013 versions 9.11.3-S1 to 9.16.50-S1<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.18.11-S1 to 9.18.39-S1<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.20.9-S1 to 9.20.13-S1<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.11.0 to 9.16.50<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.18.0 to 9.18.39<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.20.0 to 9.20.13<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.21.0 to 9.21.12<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn October 29, 2025, the Cyber Centre is aware that a proof of concept (PoC) for vulnerability CVE-2025-40778 publicly exists.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2025-8677\">ISC BIND security advisory\u00a0- CVE-2025-8677<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2025-40778\">ISC BIND security advisory\u00a0- CVE-2025-40778<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2025-40780\">ISC BIND security advisory\u00a0- CVE-2025-40780<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av25-693","alert_type":396,"serial_number":"AV25-693","subject":"other","moderation_state":"published","external_url":null},{"nid":6922,"title":"Drupal security advisory (AV25-694)","uuid":"66f88956-b487-4f82-8c82-511c5b1fd288","banner":null,"lang":"en","date_modified":"2025-10-22","date_modified_ts":"2025-10-22T19:13:46Z","date_created":"2025-10-22T19:07:55Z","summary":null,"body":["<article data-history-node-id=\"6922\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-694\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-694<br \/><strong>Date: <\/strong>October 22, 2025<\/p>\n\n<p>On October 22, 2025, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CivicTheme Design System\u00a0\u2013 version prior to 1.12.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-112\">CivicTheme Design System\u00a0- Moderately critical\u00a0- Information disclosure\u00a0- SA-CONTRIB-2025-112<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-113\">CivicTheme Design System\u00a0- Moderately critical\u00a0- Cross-site Scripting\u00a0- SA-CONTRIB-2025-113<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-694","alert_type":396,"serial_number":"AV25-694","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6926,"title":"Atlassian security advisory (AV25-695)","uuid":"6cca6dcb-5b83-42ab-b29d-186b5c6028ae","banner":null,"lang":"en","date_modified":"2025-10-23","date_modified_ts":"2025-10-23T16:10:05Z","date_created":"2025-10-23T16:04:43Z","summary":null,"body":["<article data-history-node-id=\"6926\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-695\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-695<br \/><strong>Date: <\/strong>October 23, 2025<\/p>\n\n<p>On October 21, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Fisheye\/Crucible\u00a0\u2013 versions 4.9.0 to 4.9.2 and 4.8.14 to 4.8.16<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-october-21-2025-1652920034.html\">Security Bulletin - October 21 2025<\/a><\/li>\n\t<li><a href=\"#https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-695","alert_type":396,"serial_number":"AV25-695","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":6928,"title":"AL25-015 - Vulnerability impacting Microsoft Windows Server Update Services - CVE-2025-59287","uuid":"9b99bfa1-7e31-44f4-8096-66866bfeb882","banner":null,"lang":"en","date_modified":"2025-10-24","date_modified_ts":"2025-10-24T18:31:30Z","date_created":"2025-10-24T18:13:37Z","summary":null,"body":["<article data-history-node-id=\"6928\" about=\"\/en\/alerts-advisories\/al25-015-vulnerability-impacting-microsoft-windows-server-update-services-cve-2025-59287\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-015<br \/><strong>Date:<\/strong> October\u00a024, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On October 24, 2025, Microsoft published an out-of-band security update to a critical vulnerability in the Windows Server Update Service (WSUS)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>CVE-2025-59287 involves the deserialization of untrusted data in WSUS, allowing an unauthorized attacker to execute code over a network.<\/p>\n\n<p>The WSUS Server Role is not enabled by default on Windows servers, and Windows servers that do not have this role enabled are not vulnerable. In response to Microsoft\u2019s disclosure, the Cyber Centre released an update to AV25-666 on October 24, 2025<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre is aware of active exploitation <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations follow Microsoft customer guidance for mitigation advice:<\/p>\n\n<ul><li>Apply the recommended update. If this is not possible, apply the following mitigations:<\/li>\n\t<li>If the WSUS Server Role is enabled on your server, disable it. Note that clients will no longer receive updates from the server if WSUS is disabled.<\/li>\n\t<li>Block inbound traffic to Ports 8530 and 8531 on the host firewall (as opposed to blocking only at the network\/perimeter firewall) in order to render WSUS non-operational.<\/li>\n<\/ul><p>Microsoft adds that this update is cumulative, so organizations do not need to apply any previous updates before installing this one, as it supersedes all previous updates for affected versions. They suggest that if the October 2025 Windows security update has not been applied, that this out-of-band update should be applied. After installation, a reboot will be required.<\/p>\n\n<p>In addition, the Cyber Centre also strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions with an emphasis on the following topics<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<ul><li>Patching operating systems and applications<\/li>\n\t<li>Isolating Web-Facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-59287\">Windows Server Update Service (WSUS) Remote Code Execution Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-october-2025-monthly-rollup-av25-666\">Microsoft security advisory (AV25-666)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.huntress.com\/blog\/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability\">Exploitation of Windows Server Update Services Remote Code Execution Vulnerability (CVE-2025-59287)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-015-vulnerability-impacting-microsoft-windows-server-update-services-cve-2025-59287","alert_type":397,"serial_number":"AL25-015","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6929,"title":"Dell security advisory (AV25-697)","uuid":"cd34bb87-a3f3-4eb5-84b9-378895cacbeb","banner":null,"lang":"en","date_modified":"2025-10-27","date_modified_ts":"2025-10-27T12:36:09Z","date_created":"2025-10-27T12:18:35Z","summary":null,"body":["<article data-history-node-id=\"6929\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-697\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-697<br \/><strong>Date: <\/strong>October 27, 2025<\/p>\n\n<p>Between October 20 and 26, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Storage Manager\u00a0\u2013 versions prior to 2020 R1.22<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000382899\/dsa-2025-393-security-update-for-storage-center---dell-storage-manager-vulnerabilities\">DSA-2025-393: Security Update for Storage Center\u00a0- Dell Storage Manager Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-697","alert_type":396,"serial_number":"AV25-697","subject":"dell","moderation_state":"published","external_url":null},{"nid":6930,"title":"IBM security advisory (AV25-696)","uuid":"1a8d97f4-9c32-4aa3-bdbe-304f54a22cda","banner":null,"lang":"en","date_modified":"2025-10-27","date_modified_ts":"2025-10-27T12:27:11Z","date_created":"2025-10-27T12:20:04Z","summary":null,"body":["<article data-history-node-id=\"6930\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-696\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-696<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 27, 2025<\/p>\n\n<p>Between October 20 and 26, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-696","alert_type":396,"serial_number":"AV25-696","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6931,"title":"Ubuntu security advisory (AV25-698)","uuid":"2394c08c-a12f-4d59-aa82-5949ca53427a","banner":null,"lang":"en","date_modified":"2025-10-27","date_modified_ts":"2025-10-27T12:56:45Z","date_created":"2025-10-27T12:31:26Z","summary":null,"body":["<article data-history-node-id=\"6931\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-698\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-698<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 27, 2025<\/p>\n\n<p>Between October 20 and 26, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-698","alert_type":396,"serial_number":"AV25-698","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6932,"title":"[Control systems] CISA ICS security advisories (AV25\u2013699)","uuid":"7b7239c2-10b5-49ec-9fdc-1c7380ede38b","banner":null,"lang":"en","date_modified":"2025-10-27","date_modified_ts":"2025-10-27T18:49:08Z","date_created":"2025-10-27T18:38:40Z","summary":null,"body":["<article data-history-node-id=\"6932\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-699\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25\u2013699<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 27, 2025<\/p>\n\n<p>Between October 20 and 26, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ASKI Energy ALS-mini-s4 IP (serial number from 2000 to 5166)\u00a0\u2013 all versions<\/li>\n\t<li>ASKI Energy ALS-mini-s8 IP (serial number from 2000 to 5166)\u00a0\u2013 all versions<\/li>\n\t<li>AutomationDirect Productivity 3000\/2000\/1000 series CPU\u00a0\u2013 version v4.4.1.19 and prior<\/li>\n\t<li>AutomationDirect Productivity Suite\u00a0\u2013 version v4.4.1.19 and prior<\/li>\n\t<li>CloudEdge Online Cameras and App\u00a0\u2013 version 4.4.2<\/li>\n\t<li>Delta Electronics ASDA-Soft\u00a0\u2013 version 7.0.2.0 and prior<\/li>\n\t<li>RAX701-GC-WP-01 P200R002C52\u00a0\u2013 firmware version 5.5.27_20190111<\/li>\n\t<li>RAX701-GC-WP-01 P200R002C53\u00a0\u2013 firmware version 5.5.13_20180720 and version 5.5.36_20190709<\/li>\n\t<li>Rockwell Automation 1783-NATR\u00a0\u2013 versions prior to 1.006<\/li>\n\t<li>Rockwell Automation Compact GuardLogix 5370\u00a0\u2013 versions prior to 30.012<\/li>\n\t<li>Siemens RUGGEDCOM ROS Devices\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens SIMATIC S7-1200 CPU V1\/V2 Devices\u00a0\u2013 versions prior to 2.0.3 (CVE-2011-20001) and 2.0.2 (CVE-2011-20002)<\/li>\n\t<li>Veeder-Root TLS4B Automatic Tank Gauge System\u00a0\u2013 versions prior to 11.A<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-699","alert_type":398,"serial_number":"AV25\u2013699","subject":"ics","moderation_state":"published","external_url":null},{"nid":6933,"title":"HashiCorp security advisory (AV25-701)","uuid":"e8d0bec4-220f-4ab5-b0be-674fade654e9","banner":null,"lang":"en","date_modified":"2025-10-28","date_modified_ts":"2025-10-28T12:28:12Z","date_created":"2025-10-27T18:55:15Z","summary":null,"body":["<article data-history-node-id=\"6933\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av25-701\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-701<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 28, 2025<\/p>\n\n<p>On October 23, 2025, HashiCorp published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Vault Community\u00a0\u2013 versions prior to 1.21.0<\/li>\n\t<li>Vault Enterprise\u00a0\u2013 versions prior to 1.21.0, 1.20.5, 1.19.11 and 1.16.27<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2025-31-vault-vulnerable-to-denial-of-service-due-to-rate-limit-regression\/76710\">HCSEC-2025-31\u00a0- Vault Vulnerable to Denial of Service Due to Rate Limit Regression<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2025-30-vault-aws-auth-method-authentication-bypass-through-mishandling-of-cache-entries\/76709\">HCSEC-2025-30\u00a0- Vault AWS Auth Method Authentication Bypass Through Mishandling of Cache Entries<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av25-701","alert_type":396,"serial_number":"AV25-701","subject":"other","moderation_state":"published","external_url":null},{"nid":6934,"title":"Red Hat security advisory (AV25-700)","uuid":"35758f62-e04c-4254-ba64-098bcce23068","banner":null,"lang":"en","date_modified":"2025-10-27","date_modified_ts":"2025-10-27T19:08:50Z","date_created":"2025-10-27T19:02:10Z","summary":null,"body":["<article data-history-node-id=\"6934\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-700\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-700<br \/><strong>Date: <\/strong>October\u00a027, 2025<\/p>\n\n<p>Between October\u00a020 and 26, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-700","alert_type":396,"serial_number":"AV25-700","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6935,"title":"Apache Tomcat security advisory (AV25-702)","uuid":"6fa0137c-7ca5-43d3-afe7-0f17aa9b4aac","banner":null,"lang":"en","date_modified":"2025-10-28","date_modified_ts":"2025-10-28T12:59:26Z","date_created":"2025-10-28T12:47:48Z","summary":null,"body":["<article data-history-node-id=\"6935\" about=\"\/en\/alerts-advisories\/apache-tomcat-security-advisory-av25-702\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-702<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 28, 2025<\/p>\n\n<p>On October 27, 2025, Apache published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apache Tomcat\u00a0\u2013 versions 11.0.0-M1 to 11.0.10<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 10.1.0-M1 to 10.1.44<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 9.0.0.M11 to 9.0.108<\/li>\n\t<li>Apache Tomcat\u00a0\u2013 versions 9.0.0.40 to 9.0.108<\/li>\n\t<li>Older, EOL versions may also be affected<\/li>\n<\/ul><p>The Cyber Centre is aware that a proof of concept (PoC) for vulnerability CVE-2025-55752 publicly exists.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/j7w54hqbkfcn0xb9xy0wnx8w5nymcbqd\">[SECURITY] CVE-2025-55754 Apache Tomcat\u00a0- Console manipulation via escape sequences in log messages<\/a><\/li>\n\t<li><a href=\"https:\/\/lists.apache.org\/thread\/n05kjcwyj1s45ovs8ll1qrrojhfb1tog\">[SECURITY] CVE-2025-55752 Apache Tomcat\u00a0- Directory traversal via rewrite with possible RCE if PUT is enabled<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-tomcat-security-advisory-av25-702","alert_type":396,"serial_number":"AV25-702","subject":"other","moderation_state":"published","external_url":null},{"nid":6937,"title":"Veeam security advisory (AV25-703)","uuid":"6684fe6f-c55d-4b2a-8438-001c707ed40e","banner":null,"lang":"en","date_modified":"2025-10-28","date_modified_ts":"2025-10-28T17:04:38Z","date_created":"2025-10-28T16:58:58Z","summary":null,"body":["<article data-history-node-id=\"6937\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av25-703\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-703<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 28, 2025<\/p>\n\n<p>On October 14, 2025, Veeam published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2013 version 12.3.2.3617 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4771\">Vulnerabilities Resolved in Veeam Backup &amp; Replication 12.3.2.4165 Patch<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av25-703","alert_type":396,"serial_number":"AV25-703","subject":"other","moderation_state":"published","external_url":null},{"nid":6938,"title":"AL25-016 Internet-accessible industrial control systems (ICS) abused by hacktivists","uuid":"61a524f3-e838-4acf-927d-74bced3d9e8d","banner":null,"lang":"en","date_modified":"2025-10-29","date_modified_ts":"2025-10-29T14:01:33Z","date_created":"2025-10-28T17:28:30Z","summary":null,"body":["<article data-history-node-id=\"6938\" about=\"\/en\/alerts-advisories\/al25-016-internet-accessible-industrial-control-systems-ics-abused-hacktivists\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-016<br \/><strong>Date:<\/strong> October\u00a029, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for Chief Information Security Officers (CISO) and decision makers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>In recent weeks, the Cyber Centre and the Royal Canadian Mounted Police have received multiple reports of incidents involving internet-accessible <abbr title=\"industrial control systems\">ICS<\/abbr>. One incident affected a water facility, tampering with water pressure values and resulting in degraded service for its community. Another involved a Canadian oil and gas company, where an Automated Tank Gauge (ATG) was manipulated, triggering false alarms. A third one involved a grain drying silo on a Canadian farm, where temperature and humidity levels were manipulated, resulting in potentially unsafe conditions if not caught on time.<\/p>\n\n<p>While individual organizations may not be direct targets of adversaries, they may become victims of opportunity as hacktivists are increasingly exploiting internet-accessible <abbr title=\"industrial control systems\">ICS<\/abbr> devices to gain media attention, discredit organizations, and undermine Canada's reputation.<\/p>\n\n<p>Exposed <abbr title=\"industrial control systems\">ICS<\/abbr> components, including Programmable Logic Controllers (PLCs), Remote Terminal Units (RTUs), Human-Machine Interfaces (HMIs), Supervisory Control and Data Acquisition (SCADA) systems, Safety Instrumented Systems (SIS), Building Management Systems (BMS), and Industrial Internet of Things (IIoT) devices, pose significant risks to organizations, their clients, and the broader Canadian public.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>Unclear division of roles and responsibilities often creates gaps leaving critical systems unprotected. Effective communication and collaboration are essential to ensuring safety and security.<\/p>\n\n<p>Provincial and territorial governments are encouraged to coordinate with municipalities and organizations within their jurisdictions to ensure all services are properly inventoried, documented, and protected. This is especially true for sectors where regulatory oversight does not cover cyber security, such as Water, Food, or Manufacturing.<\/p>\n\n<p>Municipalities and organizations should work closely with their service providers to ensure that managed services are implemented securely, maintained throughout their lifecycle and based on clearly defined requirements. Vendor recommendations and guidelines should be followed to secure devices and services from deployment through decommissioning. Cyber Centre guidance referenced below can greatly assist organizations in providing frameworks for securing these systems. The Cyber Security Readiness Goals (CRGs)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> are a recommended minimum set of cyber security practices an organization can take to bolster their cyber security posture.<\/p>\n\n<p>Organizations are advised to conduct a comprehensive inventory of all internet-accessible <abbr title=\"industrial control systems\">ICS<\/abbr> devices and assess their necessity. Where possible, alternative solutions\u2014such as Virtual Private Networks (VPNs) with two-factor authentication\u2014should be implemented to avoid direct exposure to the internet.<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> If such alternatives are not feasible, enhanced monitoring practices should be adopted. This includes active threat detection measures such as Intrusion Prevention Systems (IPS), regular penetration testing, and continuous vulnerability management.<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> Technical measures should thoroughly be tested for compatibility issues and to prevent service degradation.<\/p>\n\n<p>Additionally, organizations should regularly conduct tabletop exercises to evaluate and improve their response capabilities and help define roles and responsibilities in the event of a cyber incident.<\/p>\n\n<p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<p>The <abbr title=\"Royal Canadian Mounted Police\">RCMP<\/abbr> supports the Government of Canada's strategy to ensure cyber resiliency for critical infrastructure. Combatting cybercrime requires a whole-of-society approach\u2014one that depends on strong partnerships and coordinated efforts between law enforcement, government agencies, and both the public and private sectors.<\/p>\n\n<p>In addition to reporting to the Cyber Centre, recipients are encouraged to report to your police of jurisdiction. Early contact allows police to coordinate investigation(s) with your organization's legal team and\/or to assist with mitigation actions. Although not every complaint will result in an active criminal investigation, your reporting and cooperation will contribute to efforts by law enforcement to investigate and disrupt cybercriminal activities impacting the safety and security of Canadians.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"\/en\/cyber-security-readiness\">Cyber Security Readiness Goals<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/guidance\/security-considerations-industrial-control-systems-itsap00050\">Security considerations for industrial control systems (ITSAP.00.050)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/guidance\/national-cyber-threat-assessment-2025-2026\">National Cyber Threat Assessment 2025-2026<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/security-considerations-critical-infrastructure-itsap10100\">Security considerations for critical infrastructure (ITSAP.10.100)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-016-internet-accessible-industrial-control-systems-ics-abused-hacktivists","alert_type":397,"serial_number":"AL25-016","subject":"ics","moderation_state":"published","external_url":null},{"nid":6939,"title":"Mozilla security advisory (AV25-704)","uuid":"da621e3f-6b52-4a78-9640-a32489a5864f","banner":null,"lang":"en","date_modified":"2025-10-28","date_modified_ts":"2025-10-28T19:22:31Z","date_created":"2025-10-28T19:11:52Z","summary":null,"body":["<article data-history-node-id=\"6939\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-704\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-704<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 28, 2025<\/p>\n\n<p>On October 28, 2025, Mozilla published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 144.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-86\/\">Mozilla Foundation Security Advisory 2025-86<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-704","alert_type":396,"serial_number":"AV25-704","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6941,"title":"VMware security advisory (AV25-705)","uuid":"66aa321c-f462-4fff-9e95-5495e025b741","banner":null,"lang":"en","date_modified":"2025-10-29","date_modified_ts":"2025-10-29T13:04:17Z","date_created":"2025-10-29T12:35:16Z","summary":null,"body":["<article data-history-node-id=\"6941\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-705\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-705<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 30, 2025<\/p>\n\n<p>On October 28 and 29, 2025, VMware published security advisories to address vulnerabilities in the following products. Included were critical updates for the following\u00a0:<\/p>\n\n<ul><li>VMware Tanzu GemFire Management Console\u00a0\u2013 versions prior to 1.4.1<\/li>\n\t<li>VMware Tanzu for Valkey\u00a0\u2013 versions prior to 7.2.11<\/li>\n\t<li>VMware Tanzu for Valkey\u00a0\u2013 versions prior to 8.0.5<\/li>\n\t<li>VMware Tanzu for Valkey\u00a0\u2013 versions prior to 8.0.6<\/li>\n\t<li>VMware Tanzu for Valkey\u00a0\u2013 versions prior to 8.1.4<\/li>\n\t<li>VMware Tanzu for Valkey on Kubernetes\u00a0\u2013 versions prior to 3.2.0<\/li>\n\t<li>VMware Tanzu GemFire\u00a0\u2013 versions prior to 10.2.0<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 7.6.0<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 6.31.0<\/li>\n\t<li>VMware Tanzu for Postgres on Kubernetes\u00a0\u2013 versions prior to 4.2.4<\/li>\n\t<li>VMware Tanzu for Postgres on Kubernetes\u00a0\u2013 versions prior to 4.3.1<\/li>\n\t<li>VMware Tanzu for Postgres\u00a0\u2013 versions prior to 18.0.0, 17.6.0, 16.10.0, 15.14.0, 14.19.0 and 13.22.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-705","alert_type":396,"serial_number":"AV25-705","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6942,"title":"Google Chrome security advisory (AV25-706)","uuid":"997f9ce1-0284-4e63-8c4d-03f846a01590","banner":null,"lang":"en","date_modified":"2025-10-29","date_modified_ts":"2025-10-29T13:38:56Z","date_created":"2025-10-29T13:33:31Z","summary":null,"body":["<article data-history-node-id=\"6942\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-706\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-706<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 29, 2025<\/p>\n\n<p>On October 28, 2025, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 142.0.7444.59\/60 (Windows and Mac) and 142.0.7444.59 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/10\/stable-channel-update-for-desktop_28.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-706","alert_type":396,"serial_number":"AV25-706","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6943,"title":"Jenkins security advisory (AV25-707)","uuid":"170566bc-872a-480a-ac08-89ea5f5b14a9","banner":null,"lang":"en","date_modified":"2025-10-29","date_modified_ts":"2025-10-29T17:26:15Z","date_created":"2025-10-29T17:14:28Z","summary":null,"body":["<article data-history-node-id=\"6943\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-707\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-707<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 29, 2025<\/p>\n\n<p>On October 29, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SAML Plugin\u00a0\u2013 version 4.583.vc68232f7018a_ and prior<\/li>\n\t<li>MCP Server Plugin\u00a0\u2013 0.84.v50ca_24ef83f2 and prior<\/li>\n\t<li>Extensible Choice Parameter Plugin \u2013 239.v5f5c278708cf and prior<\/li>\n\t<li>JDepend Plugin\u00a0\u2013 1.3.1 and prior<\/li>\n\t<li>Eggplant Runner Plugin\u00a0\u2013 0.0.1.301.v963cffe8ddb_8 and prior<\/li>\n\t<li>Themis Plugin\u00a0\u2013 1.4.1 and prior<\/li>\n\t<li>Start Windocks Containers Plugin\u00a0\u2013 1.4 and prior<\/li>\n\t<li>azure-cli Plugin\u00a0\u2013 0.9 and prior<\/li>\n\t<li>Nexus Task Runner Plugin\u00a0\u2013 0.9.2 and prior<\/li>\n\t<li>OpenShift Pipeline Plugin\u00a0\u2013 1.0.57 and prior<\/li>\n\t<li>ByteGuard Build Actions Plugin\u00a0\u2013 1.0 and prior<\/li>\n\t<li>Curseforge Publisher Plugin\u00a0\u2013 1.0 and prior<\/li>\n\t<li>Publish to Bitbucket Plugin\u00a0\u2013 version 0.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-10-29\/\">Jenkins Security Advisory 2025-10-29<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-707","alert_type":396,"serial_number":"AV25-707","subject":"other","moderation_state":"published","external_url":null},{"nid":6944,"title":"Docker security advisory (AV25\u2013708) ","uuid":"117bd4f8-e86c-4652-b31b-5caca6d35711","banner":null,"lang":"en","date_modified":"2025-10-29","date_modified_ts":"2025-10-29T18:32:49Z","date_created":"2025-10-29T18:28:03Z","summary":null,"body":["<article data-history-node-id=\"6944\" about=\"\/en\/alerts-advisories\/docker-security-advisory-av25-708\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-708<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 29, 2025<\/p>\n\n<p>On October 27, 2025, Docker published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Docker Compose\u00a0\u2013 versions prior to v2.40.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/docker\/compose\/security\/advisories\/GHSA-gv8h-7v7w-r22q\">Path Traversal via OCI Artifact Layer Annotations\u00a0- CVE-2025-62725<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/docker-security-advisory-av25-708","alert_type":396,"serial_number":"AV25-708","subject":"other","moderation_state":"published","external_url":null},{"nid":6945,"title":"Drupal security advisory (AV25-709)","uuid":"e3e90152-c2f2-413d-bb94-f7dab5d7ec44","banner":null,"lang":"en","date_modified":"2025-10-30","date_modified_ts":"2025-10-30T13:21:42Z","date_created":"2025-10-30T13:05:38Z","summary":null,"body":["<article data-history-node-id=\"6945\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-709\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-709<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 30, 2025<\/p>\n\n<p>On October 29, 2025, Drupal published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Simple OAuth (OAuth2) &amp; OpenID Connect\u00a0\u2013 versions 6.0.0 to versions prior to 6.0.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-114\">Simple OAuth (OAuth2) &amp; OpenID Connect\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-114 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-709","alert_type":396,"serial_number":"AV25-709","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6946,"title":"Splunk security advisory (AV25-710)","uuid":"7488644f-3cd5-44f8-ae52-ab114d6676ee","banner":null,"lang":"en","date_modified":"2025-10-30","date_modified_ts":"2025-10-30T14:19:45Z","date_created":"2025-10-30T13:59:40Z","summary":null,"body":["<article data-history-node-id=\"6946\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-710\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-710<br \/><strong>Date: <\/strong>October\u00a030, 2025<\/p>\n\n<p>On October\u00a029, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk AppDynamics Machine Agent\u00a0\u2013 versions prior to 25.7.0<\/li>\n\t<li>Splunk AppDynamics Private Synthetic Agent\u00a0\u2013 versions prior to 25.7.0<\/li>\n\t<li>Splunk AppDynamics Analytics Agent\u00a0\u2013 versions prior to 25.7.0<\/li>\n\t<li>Splunk Operator for Kubernetes Add-on\u00a0\u2013 versions prior to 3.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1008\">Third-Party Package Updates in Splunk AppDynamics Machine Agent\u00a0- October 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1009\">Third-Party Package Updates in Splunk AppDynamics Private Synthetic Agent\u00a0- October 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1010\">Third-Party Package Updates in Splunk AppDynamics Analytics Agent\u00a0- October 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1011\">Third-Party Package Updates in Splunk Operator for Kubernetes Add-on\u00a0- October 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-710","alert_type":396,"serial_number":"AV25-710","subject":"other","moderation_state":"published","external_url":null},{"nid":6948,"title":"SonicWall security advisory (AV25-711)","uuid":"153df111-d401-4df2-8263-fe8500c7c5e1","banner":null,"lang":"en","date_modified":"2025-10-31","date_modified_ts":"2025-10-31T16:01:34Z","date_created":"2025-10-31T15:47:51Z","summary":null,"body":["<article data-history-node-id=\"6948\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-711\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-711<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 31, 2025<\/p>\n\n<p>On October 30, 2025, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">SonicWall<\/span> published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SMA 100 Series (SMA 210, 410, 500v)\u00a0\u2013 version 10.2.2.2-92sv and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0017\">SonicWall SMA100 Potential Exposure of Sensitive Information in Log File<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-711","alert_type":396,"serial_number":"AV25-711","subject":"other","moderation_state":"published","external_url":null},{"nid":6950,"title":"Progress security advisory (AV25-712)","uuid":"f7e6956b-05ee-4bd6-9e41-5eb2d1ae2435","banner":null,"lang":"en","date_modified":"2025-10-31","date_modified_ts":"2025-10-31T18:59:47Z","date_created":"2025-10-31T18:53:36Z","summary":null,"body":["<article data-history-node-id=\"6950\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av25-712\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-712<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>October 31, 2025<\/p>\n\n<p>On October 29, 2025, Progress published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>MOVEit Transfer\u00a0\u2013 version 2025.0.2 (17.0.2) and prior<\/li>\n\t<li>MOVEit Transfer\u00a0\u2013 version 2024.1. 6 (16.1.6) and prior<\/li>\n\t<li>MOVEit Transfer\u00a0\u2013 version 2023.1.15 (15.1.15) and prior<\/li>\n\t<li>MOVEit Transfer\u00a0\u2013 version 2023.1.15 (15.1.15) and prior<\/li>\n\t<li>MOVEit Transfer\u00a0\u2013 version 2023.0 and prior<\/li>\n\t<li>MOVEit Transfer\u00a0\u2013 version 2024.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025\">MOVEit Transfer Vulnerability\u00a0\u2013 CVE-2025-10932 (October 29, 2025)<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av25-712","alert_type":396,"serial_number":"AV25-712","subject":"other","moderation_state":"published","external_url":null},{"nid":6951,"title":"HPE security advisory (AV25-713)","uuid":"ca6d1a70-3d8f-4e23-853e-66a03c449e13","banner":null,"lang":"en","date_modified":"2025-10-31","date_modified_ts":"2025-10-31T19:41:15Z","date_created":"2025-10-31T19:36:01Z","summary":null,"body":["<article data-history-node-id=\"6951\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-713\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-713<br \/><strong>Date: <\/strong>October 31, 2025<\/p>\n\n<p>On October 30, 2025, HPE published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:<\/p>\n\n<ul><li>HPE Private Cloud AI\u00a0\u2013 versions prior to 1.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbpc04960en_us&amp;docLocale=en_US#hpesbpc04960-rev-1-hpe-private-cloud-ai-multiple-v-0\">HPESBPC04960 rev.1\u00a0- HPE Private Cloud AI, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-713","alert_type":396,"serial_number":"AV25-713","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6952,"title":"IBM security advisory (AV25-714)","uuid":"f4a3609b-7d44-481a-9da4-ef04d4d87bb4","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T14:03:39Z","date_created":"2025-11-03T14:01:36Z","summary":null,"body":["<article data-history-node-id=\"6952\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-714\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-714<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 3, 2025<\/p>\n\n<p>Between October 27 and November 2, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/ \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-714","alert_type":396,"serial_number":"AV25-714","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6953,"title":"Dell security advisory (AV25-715)","uuid":"b6cc0ff6-1f7a-4a7b-b897-3c3b650e96ec","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T14:10:17Z","date_created":"2025-11-03T14:04:56Z","summary":null,"body":["<article data-history-node-id=\"6953\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-715\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-715<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 3, 2025<\/p>\n\n<p>Between October 27 and November 2, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Microsoft Azure \u2013 versions prior to 01.06.01.00<\/li>\n\t<li>Dell Avamar Data Store Gen4T \u2013 versions 19.12, 19.10-SP1, 19.10, 19.9, 19.8 and 19.7<\/li>\n\t<li>Dell Avamar Data Store Gen5A \u2013 versions 19.12, 19.10-SP1, 19.10, 19.9, 19.8 and 19.7<\/li>\n\t<li>Dell Avamar Network Data Management Protocol (NDMP) Accelerator \u2013 versions 19.12, 19.10-SP1, 19.10, 19.9, 19.8 and 19.7<\/li>\n\t<li>Dell Avamar VMware Image Backup Proxy \u2013 versions 19.12, 19.10-SP1, 19.10, 19.9, 19.8 and 19.7<\/li>\n\t<li>Dell Avamar Virtual Edition \u2013 versions 19.12, 19.10-SP1, 19.10, 19.9, 19.8 and 19.7<\/li>\n\t<li>Dell CloudLink \u2013 versions 8.0 to 8.1.2<\/li>\n\t<li>Dell CloudLink \u2013 versions prior to 8.1.1<\/li>\n\t<li>Dell CloudLink \u2013 versions prior to 8.2<\/li>\n\t<li>Dell Networker Virtual Edition (NVE) \u2013 versions 19.5, 19.6, 19.7, 19.8, 19.9, 19.10, 19.11 and 19.12<\/li>\n\t<li>Dell Policy Manager for Secure Connect Gateway \u2013 Appliance \u2013 versions prior to 5.32.00.18<\/li>\n\t<li>Dell PowerProtect DP Series Appliance (IDPA) \u2013 versions prior to 2.7.9<\/li>\n\t<li>Dell PowerSwitch Z9264F-ON \u2013 versions prior to 3.42.5.1-21<\/li>\n\t<li>Dell Protection Advisor \u2013 versions 19.11 to 19.12 SP1<\/li>\n\t<li>Dell Secure Connect Gateway-Appliance \u2013 versions 5.26.00 to 5.30.00<\/li>\n\t<li>Dell Secure Connect Gateway-Application \u2013 versions 5.26.00 to 5.30.00<\/li>\n\t<li>Dell Unity \u2013 versions prior to 5.5.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-715","alert_type":396,"serial_number":"AV25-715","subject":"dell","moderation_state":"published","external_url":null},{"nid":6954,"title":"Ubuntu security advisory (AV25-716)","uuid":"89a170f5-8464-44a8-8213-1f5eb48c8e9f","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T14:14:54Z","date_created":"2025-11-03T14:12:21Z","summary":null,"body":["<article data-history-node-id=\"6954\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-716\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-716<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 3, 2025<\/p>\n\n<p>Between October 27 and November 2, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-716","alert_type":396,"serial_number":"AV25-716","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6956,"title":"Red Hat security advisory (AV25-717)","uuid":"e7de3c12-b54f-4544-9ed5-38294d271a80","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T14:32:06Z","date_created":"2025-11-03T14:29:46Z","summary":null,"body":["<article data-history-node-id=\"6956\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-717\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-717<br \/><strong>Date: <\/strong>November 3, 2025<\/p>\n\n<p>Between October 27 and November 2, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-717","alert_type":396,"serial_number":"AV25-717","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6957,"title":"[Control systems] CISA ICS security advisories (AV25\u2013718)","uuid":"a09c1be6-200e-473b-9d54-2bbf51eac106","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T14:46:11Z","date_created":"2025-11-03T14:40:01Z","summary":null,"body":["<article data-history-node-id=\"6957\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-718\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-718<br \/><strong>Date: <\/strong>November 3, 2025<\/p>\n\n<p>Between October 27 and November 2, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Energy TropOS 4th Gen Firmware\u00a0\u2013 versions 8.9.6.0 and prior<\/li>\n\t<li>Hitachi Energy TropOS 4th Gen Firmware\u00a0\u2013 versions prior to 8.9.6.0<\/li>\n\t<li>ISO 15118 standard\u00a0\u2013 Part 15118-2 Network and Application Protocol Requirements<\/li>\n\t<li>Schneider Electric EcoStruxure Modicon Communication Server\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric EcoStruxure OPC UA Server Expert\u00a0\u2013 versions prior to SV2.01 SP3<\/li>\n\t<li>Vertikal Systems Hospital Manager Backend Services\u00a0\u2013 September 19, 2025 and prior.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories?f%5B0%5D=advisory_type%3A95\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-718","alert_type":398,"serial_number":"AV25-718","subject":"ics","moderation_state":"published","external_url":null},{"nid":6959,"title":"Microsoft Edge security advisory (AV25-720)","uuid":"0fb4880b-11e1-47a9-abb6-c2253b6fe80f","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T15:48:18Z","date_created":"2025-11-03T14:57:41Z","summary":null,"body":["<article data-history-node-id=\"6959\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-720\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-720<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 3, 2025<\/p>\n\n<p>On October 31, 2025, Microsoft published a security update to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 142.0.3595.53<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-720","alert_type":396,"serial_number":"AV25-720","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6958,"title":"[Control systems] ABB security advisory (AV25-719)","uuid":"76880ad1-232b-4900-8a2c-4b8616f801de","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T15:23:54Z","date_created":"2025-11-03T15:19:06Z","summary":null,"body":["<article data-history-node-id=\"6958\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-719\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-719<br \/><strong>Date: <\/strong>November\u00a03, 2025<\/p>\n\n<p>On November\u00a03, 2025, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB Protection and control IED manager PCM600\u00a0\u2013 versions 1.5 to 2.13.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2NGA002813&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch\">PCM600 SharpZip library vulnerability\u00a0- CVE ID: CVE-2018-1002208 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-719","alert_type":398,"serial_number":"AV25-719","subject":"abb","moderation_state":"published","external_url":null},{"nid":6960,"title":"Ubiquiti security advisory (AV25-721)","uuid":"b49ac405-056c-4541-80c4-5b17b6adfa9f","banner":null,"lang":"en","date_modified":"2025-11-03","date_modified_ts":"2025-11-03T16:57:22Z","date_created":"2025-11-03T16:44:24Z","summary":null,"body":["<article data-history-node-id=\"6960\" about=\"\/en\/alerts-advisories\/ubiquiti-security-advisory-av25-721\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-721<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 3, 2025<\/p>\n\n<p>On October 23, 2025, Ubiquiti published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>UniFi Access Application\u00a0\u2013 version 3.3.22 to 3.4.31<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.ui.com\/releases\/Security-Advisory-Bulletin-056-056\/ce97352d-91cd-40a7-a2f4-2c73b3b30191\">Ubiquiti UniFi\u00a0- Security Advisory Bulletin 056 (CVE-2025-52665)<\/a><\/li>\n\t<li><a href=\"https:\/\/community.ui.com\/releases\/UniFi-Access-Application-4-0-21\/f3b63db6-6e51-442e-b5a6-24b67fe82f44\">Ubiquiti\u00a0- UniFi Access Application 4.0.21<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubiquiti-security-advisory-av25-721","alert_type":396,"serial_number":"AV25-721","subject":"other","moderation_state":"published","external_url":null},{"nid":6962,"title":"Apple security advisory (AV25-722) \u2013 Update 1","uuid":"7838dc4c-4257-4c83-91a4-1938fc0e27c1","banner":null,"lang":"en","date_modified":"2026-03-20","date_modified_ts":"2026-03-20T18:07:07Z","date_created":"2025-11-04T14:11:04Z","summary":null,"body":["<article data-history-node-id=\"6962\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-722\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-722<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 4, 2025<br \/><strong>Updated: <\/strong>March 20, 2025<\/p>\n\n<p>On November 3, 2025, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Safari\u00a0\u2013 versions prior to 26.1<\/li>\n\t<li>Xcode\u00a0\u2013 versions prior to 26.1<\/li>\n\t<li>iOS and iPadOS\u00a0\u2013 versions prior to 26.1<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.7.2<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.8.2<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26.1<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 26.1<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 26.1<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 26.1<\/li>\n<\/ul><h2 class=\"h3\">\n  Update 1\n<\/h2>\n<p>\n  On March 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-43510 and CVE-2025-43520 to their Known Exploited Vulnerabilities (KEV) Database.\n<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n  \t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-43510\">CISA KEV: CVE-2025-43510<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-43520\">CISA KEV: CVE-2025-43520<\/a><\/li>\n\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-722","alert_type":396,"serial_number":"AV25-722","subject":"apple","moderation_state":"published","external_url":null},{"nid":6963,"title":"Android security advisory \u2013 November 2025 monthly rollup (AV25-723)","uuid":"5d65f775-3737-4dd5-b20c-9b3f0ce0ebbb","banner":null,"lang":"en","date_modified":"2025-11-04","date_modified_ts":"2025-11-04T14:37:46Z","date_created":"2025-11-04T14:31:43Z","summary":null,"body":["<article data-history-node-id=\"6963\" about=\"\/en\/alerts-advisories\/android-security-advisory-november-2025-monthly-rollup-av25-723\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-723<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 4, 2025<\/p>\n\n<p>On November 3, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-11-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-november-2025-monthly-rollup-av25-723","alert_type":396,"serial_number":"AV25-723","subject":"android","moderation_state":"published","external_url":null},{"nid":6964,"title":"VMware security advisory (AV25-724) \u2013 Update 1","uuid":"a46c32bf-7817-4dd0-ba3f-0a92c53ac03e","banner":null,"lang":"en","date_modified":"2025-11-05","date_modified_ts":"2025-11-05T18:08:43Z","date_created":"2025-11-04T15:22:39Z","summary":null,"body":["<article data-history-node-id=\"6964\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-724\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-724<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 4, 2025<br \/><strong>Updated:<\/strong> November 10, 2025<\/p>\n\n<p>Between November 3 and 4, 2025, VMware published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cloud Service Broker for AWS for VMware Tanzu Platform\u00a0\u2013 versions prior to 1.15.0<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes\u00a0\u2013 versions 3.13.10, 4.0.15, 4.1.4 and 4.2.0<\/li>\n\t<li>VMware Tanzu Greenplum Backup and Restore\u00a0\u2013 versions prior to 1.32.1<\/li>\n\t<li>VMware Tanzu Greenplum Upgrade\u00a0\u2013 versions prior to 1.10.1<\/li>\n\t<li>VMware Tanzu Greenplum Streaming Server\u00a0\u2013 versions prior to 2.2.0<\/li>\n\t<li>VMware Tanzu Greenplum Data Copy Utility\u00a0\u2013 versions prior to 2.9.0<\/li>\n\t<li>VMware Tanzu Greenplum SQL Editor\u00a0\u2013 versions prior to 1.2.0<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Between November 5 and 6, 2025, VMware published additional security advisories to address critical vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-724","alert_type":396,"serial_number":"AV25-724","subject":"vmware","moderation_state":"published","external_url":null},{"nid":6966,"title":"Tenable security advisory (AV25-725)","uuid":"be66352a-b92c-4a8e-8f62-64cfce741368","banner":null,"lang":"en","date_modified":"2025-11-04","date_modified_ts":"2025-11-04T18:27:10Z","date_created":"2025-11-04T18:16:19Z","summary":null,"body":["<article data-history-node-id=\"6966\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av25-725\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-725<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 4, 2025<\/p>\n\n<p>On November 3, 2025, Tenable published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:<\/p>\n\n<ul><li>Tenable Identity Exposure\u00a0- On-premises LTS\u00a0\u2013 version prior to 3.77.14<\/li>\n<\/ul><p>Vulnerability CVE-2025-55315 has a critical CVSS score of 9.9.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2025-23\">Tenable\u00a0- [R1] Tenable Identity Exposure Version 3.77.14 Fixes Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/downloads\/identity-exposure#tenable-identity-exposure-v3.77.14-on-premises-lts\">Tenable Identity Exposure v3.77.14\u00a0- On-premises LTS<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av25-725","alert_type":396,"serial_number":"AV25-725","subject":"other","moderation_state":"published","external_url":null},{"nid":6967,"title":"Cisco security advisory (AV25-726)","uuid":"5f2ece7c-8d61-49dc-b4e3-a2d96602c932","banner":null,"lang":"en","date_modified":"2025-11-05","date_modified_ts":"2025-11-05T19:51:20Z","date_created":"2025-11-05T19:12:22Z","summary":null,"body":["<article data-history-node-id=\"6967\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-726\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-726<br \/><strong>Date: <\/strong>November\u00a0<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">5, 2025<\/span><\/p>\n\n<p>On November\u00a05, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Identity Services Engine\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Contact Center Express\u00a0\u2013 versions 12.5 SU3 and prior<\/li>\n\t<li>Cisco Unified Contact Center Express\u00a0\u2013 version 15.0<\/li>\n\t<li>Cisco Unified Intelligence Center\u00a0\u2013 versions 12.6 and prior<\/li>\n\t<li>Cisco Unified Intelligence Center\u00a0\u2013 version 15.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cc-unauth-rce-QeN8h7mQ\">Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-radsupress-dos-8YF3JThh\">Cisco Identity Services Engine RADIUS Suppression Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-multiple-vulns-O9BESWJH\">Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cc-mult-vuln-gK4TFXSn\">Multiple Cisco Contact Center Products Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-726","alert_type":396,"serial_number":"AV25-726","subject":"cisco","moderation_state":"published","external_url":null},{"nid":6968,"title":" Apple security advisory (AV25-727)","uuid":"3da82f7b-6deb-44ec-b1d7-a08d72cb36e7","banner":null,"lang":"en","date_modified":"2025-11-07","date_modified_ts":"2025-11-07T14:12:09Z","date_created":"2025-11-07T13:57:25Z","summary":null,"body":["<article data-history-node-id=\"6968\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-727\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-727<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 7, 2025<\/p>\n\n<p>On November 5, 2025, Apple published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 18.7.2<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 18.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/125633\">About the security content of iOS 18.7.2 and iPadOS 18.7.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-727","alert_type":396,"serial_number":"AV25-727","subject":"apple","moderation_state":"published","external_url":null},{"nid":6969,"title":"Google Chrome security advisory (AV25-728)","uuid":"4fbddc86-0807-4e15-9cba-b1cd47c18364","banner":null,"lang":"en","date_modified":"2025-11-07","date_modified_ts":"2025-11-07T14:28:44Z","date_created":"2025-11-07T14:19:43Z","summary":null,"body":["<article data-history-node-id=\"6969\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-728\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-728<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 7, 2025<\/p>\n\n<p>On November 5, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 142.0.7444.134\/.135 (Windows and Mac) and 142.0.7444.134 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/11\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-728","alert_type":396,"serial_number":"AV25-728","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6970,"title":"Drupal security advisory (AV25-729)","uuid":"262772b2-f151-4545-8fe9-88eb84e1de62","banner":null,"lang":"en","date_modified":"2025-11-07","date_modified_ts":"2025-11-07T15:59:01Z","date_created":"2025-11-07T15:48:02Z","summary":null,"body":["<article data-history-node-id=\"6970\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-729\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-729<br \/><strong>Date: <\/strong>November\u00a07, 2025<\/p>\n\n<p>On November\u00a05, 2025, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Email TFA\u00a0\u2013 versions prior to 2.0.6<\/li>\n\t<li>Simple multi step form\u00a0\u2013 versions prior to 2.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-115\">Email TFA\u00a0- Moderately critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2025-115<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-116\">Simple multi step form\u00a0- Moderately critical\u00a0- Cross-site Scripting\u00a0- SA-CONTRIB-2025-116<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-729","alert_type":396,"serial_number":"AV25-729","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6971,"title":"Microsoft Edge security advisory (AV25-730)","uuid":"a48e6cd3-60aa-41c6-b46c-f1b559ab6e5f","banner":null,"lang":"en","date_modified":"2025-11-07","date_modified_ts":"2025-11-07T16:09:33Z","date_created":"2025-11-07T15:54:31Z","summary":null,"body":["<article data-history-node-id=\"6971\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-730\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-730<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 7, 2025<\/p>\n\n<p>On November 6, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 142.0.3595.65<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-730","alert_type":396,"serial_number":"AV25-730","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6972,"title":"Qualcomm security advisory \u2013 November 2025 monthly rollup (AV25-731)","uuid":"8ab83772-d2f2-4b58-867f-f6bd9740e974","banner":null,"lang":"en","date_modified":"2025-11-07","date_modified_ts":"2025-11-07T18:22:37Z","date_created":"2025-11-07T18:13:20Z","summary":null,"body":["<article data-history-node-id=\"6972\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-november-2025-monthly-rollup-av25-731\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-731<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 7, 2025<\/p>\n\n<p>On November 3, 2025, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/november-2025-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 November<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-november-2025-monthly-rollup-av25-731","alert_type":396,"serial_number":"AV25-731","subject":"other","moderation_state":"published","external_url":null},{"nid":6973,"title":"IBM security advisory (AV25-732)","uuid":"0e4befd6-e3db-41d4-aa89-b386c6bc7b42","banner":null,"lang":"en","date_modified":"2025-11-10","date_modified_ts":"2025-11-10T14:22:38Z","date_created":"2025-11-10T14:13:14Z","summary":null,"body":["<article data-history-node-id=\"6973\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-732\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-732<br \/><strong>Date: <\/strong>November 10, 2025<\/p>\n\n<p>Between November 3 and 9, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-732","alert_type":396,"serial_number":"AV25-732","subject":"ibm","moderation_state":"published","external_url":null},{"nid":6974,"title":"Dell security advisory (AV25-733)","uuid":"486b69df-602c-43e5-80f3-01f8cf125143","banner":null,"lang":"en","date_modified":"2025-11-10","date_modified_ts":"2025-11-10T14:35:30Z","date_created":"2025-11-10T14:27:16Z","summary":null,"body":["<article data-history-node-id=\"6974\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-733\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-733<br \/><strong>Date: <\/strong>November 10, 2025<\/p>\n\n<p>Between November 3 and 9, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.04.02.00<\/li>\n\t<li>Dell Enterprise SONiC Distribution\u00a0\u2013 versions prior to 4.5.1<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 versions prior to 19.12.0.3<\/li>\n\t<li>Dell PowerSwitch S5448F-ON\u00a0\u2013 versions prior to v3.52.5.1-12<\/li>\n\t<li>Dell PowerSwitch Z9264F-ON\u00a0\u2013 versions prior to 3.42.5.1-21<\/li>\n\t<li>Dell PowerSwitch Z9432F-ON\u00a0\u2013 versions prior to 3.51.5.1-21<\/li>\n\t<li>Dell iDRAC10\u00a0\u2013 versions prior to 1.20.25.00<\/li>\n\t<li>Dell iDRAC9\u00a0\u2013 versions 6.10.80.00 to 7.20.10.50<\/li>\n\t<li>Dell iDRAC9\u00a0\u2013 versions prior to 7.00.00.181<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-733","alert_type":396,"serial_number":"AV25-733","subject":"dell","moderation_state":"published","external_url":null},{"nid":6975,"title":"Ubuntu security advisory (AV25-734)","uuid":"549fb815-693b-400a-ac82-d53eb664bcd4","banner":null,"lang":"en","date_modified":"2025-11-10","date_modified_ts":"2025-11-10T14:44:30Z","date_created":"2025-11-10T14:40:35Z","summary":null,"body":["<article data-history-node-id=\"6975\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-734\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-734<br \/><strong>Date: <\/strong>November 10, 2025<\/p>\n\n<p>Between November 3 and 9, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-734","alert_type":396,"serial_number":"AV25-734","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":6977,"title":"[Control systems] CISA ICS security advisories (AV25\u2013736)","uuid":"e73e58b9-1bc2-40bc-aa93-68b5ebc41e58","banner":null,"lang":"en","date_modified":"2025-11-10","date_modified_ts":"2025-11-10T15:34:02Z","date_created":"2025-11-10T14:54:53Z","summary":null,"body":["<article data-history-node-id=\"6977\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-736\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-736<br \/><strong>Date: <\/strong>November\u00a010, 2025<\/p>\n\n<p>Between November\u00a03 and 9, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB FLXeon Controllers (FBXi, FBVi, FBTi, CBXi)\u00a0\u2013 version 9.3.5 and prior<\/li>\n\t<li>Advantech DeviceOn\/iEdge\u00a0\u2013 version 2.0.2 and prior<\/li>\n\t<li>Delta Electronics CNCSoft-G2\u00a0\u2013 version 2.1.0.27 and prior<\/li>\n\t<li>Fuji Electric Monitouch V-SFT-6\u00a0\u2013 version 6.2.7.0<\/li>\n\t<li>IDIS ICM Viewer\u00a0\u2013 version v1.6.0.10<\/li>\n\t<li>Radiometrics VizAir\u00a0\u2013 versions prior to 08\/2025<\/li>\n\t<li>Survision License Plate Recognition LPR Camera\u00a0\u2013 all versions<\/li>\n\t<li>Ubia Ubox\u00a0\u2013 version v1.1.124<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-736","alert_type":398,"serial_number":"AV25-736","subject":"ics","moderation_state":"published","external_url":null},{"nid":6976,"title":"Red Hat security advisory (AV25-735)","uuid":"d0cc8a6e-45ec-42ea-a850-e43b9a6e1f2f","banner":null,"lang":"en","date_modified":"2025-11-10","date_modified_ts":"2025-11-10T15:21:41Z","date_created":"2025-11-10T14:54:53Z","summary":null,"body":["<article data-history-node-id=\"6976\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-735\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-735<br \/><strong>Date: <\/strong>November\u00a010, 2025<\/p>\n\n<p>Between November\u00a03 and 9, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-735","alert_type":396,"serial_number":"AV25-735","subject":"redhat","moderation_state":"published","external_url":null},{"nid":6978,"title":"GitHub security advisory (AV25-737)","uuid":"f878d3ad-71b2-4e1f-8cf7-43d5d5465e75","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T15:15:37Z","date_created":"2025-11-12T14:56:19Z","summary":null,"body":["<article data-history-node-id=\"6978\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-737\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-737<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 10, 2025, GitHub published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.1<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.7<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.10<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.15.x prior to 3.15.14<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.19<\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2025-11892 may have been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">Enterprise Server 3.14.19<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes\">Enterprise Server 3.15.14<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.10<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.7<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.1<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-737","alert_type":396,"serial_number":"AV25-737","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6979,"title":"SAP security advisory \u2013 November 2025 monthly rollup (AV25-738)","uuid":"c03e0d78-6cac-4323-9109-dcdb7c32c539","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T15:40:41Z","date_created":"2025-11-12T15:21:20Z","summary":null,"body":["<article data-history-node-id=\"6979\" about=\"\/en\/alerts-advisories\/sap-security-advisory-november-2025-monthly-rollup-av25-738\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-738<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 11, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SQL Anywhere Monitor (Non-Gui)\u00a0\u2013 version SYBASE_SQL_ANYWHERE_SERVER 17.0;<\/li>\n\t<li>SAP Solution Manager\u00a0\u2013 version ST 720;<\/li>\n\t<li>SAP CommonCryptoLib\u00a0\u2013 version CRYPTOLIB 8;<\/li>\n\t<li>SAP HANA JDBC Client\u00a0\u2013 version HDB_CLIENT 2.0;<\/li>\n\t<li>SAP Business Connector\u00a0\u2013 version SAP BC 4.8;<\/li>\n\t<li>SAP NetWeaver Enterprise Portal\u00a0\u2013 versions EP-BASIS 7.50 et EP-RUNTIME 7.50;<\/li>\n\t<li>SAP S\/4HANA landscape (SAP E-Recruiting BSP)\u00a0\u2013 versions S4ERECRT 100, 200, ERECRUIT 600, 603, 604, 605, 606, 616, 617, 800, 801 et 802;<\/li>\n\t<li>SAP HANA 2.0 (hdbrss)\u00a0\u2013 version HDB 2.00;<\/li>\n\t<li>SAP GUI for Windows\u00a0\u2013 versions BC-FES-GUI 8.00 et 8.10;<\/li>\n\t<li>SAP Starter Solution (PL SAFT)\u00a0\u2013 versions SAP_APPL 600, 602, 603, 604, 605, 606, 616, SAP_FIN 617, 618, 700, 720, 730, S4CORE 100, 101, 102, 103 et 104;<\/li>\n\t<li>SAP NetWeaver Application Server Java\u00a0\u2013 versions ENGINEAPI 7.50 et EP-BASIS 7.50;<\/li>\n\t<li>SAP Business One (SLD)\u00a0\u2013 versions B1_ON_HANA 10.0 et SAP-M-BO 10.0;<\/li>\n\t<li>SAP S4CORE (Manage Journal Entries)\u00a0\u2013 versions S4CORE 104, 105, 106, 107 et 108;<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP\u00a0\u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 et SAP_BASIS 816;<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP (Migration Workbench)\u00a0\u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 et SAP_BASIS 816.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/november-2025.html\">SAP <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Security Patch Day<\/span>\u00a0\u2013 November 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-november-2025-monthly-rollup-av25-738","alert_type":396,"serial_number":"AV25-738","subject":"sap","moderation_state":"published","external_url":null},{"nid":6980,"title":"Microsoft security advisory \u2013 November 2025 monthly rollup (AV25-739)","uuid":"a2fa3d5d-a6c5-4e3c-bfaa-8e2a46599977","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T15:58:11Z","date_created":"2025-11-12T15:44:53Z","summary":null,"body":["<article data-history-node-id=\"6980\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-november-2025-monthly-rollup-av25-739\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-739<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 11, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Azure Monitor<\/li>\n\t<li>Microsoft Configuration Manager 2403<\/li>\n\t<li>Microsoft Configuration Manager 2409<\/li>\n\t<li>Microsoft Configuration Manager 2503<\/li>\n\t<li>Microsoft Dynamics 365 (on-premises)<\/li>\n\t<li>Microsoft Dynamics 365 Field Service (online)<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft OneDrive for Android<\/li>\n\t<li>Microsoft SQL Server 2016<\/li>\n\t<li>Microsoft SQL Server 2017<\/li>\n\t<li>Microsoft SQL Server 2019<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Visual Studio<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Nuance PowerScribe 360<\/li>\n\t<li>Nuance PowerScribe One<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>PowerScribe One<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Server 2008<\/li>\n\t<li>Windows Server 2008 R2<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n\t<li>Windows Subsystem for Linux GUI<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2025-62215 has been exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Nov\">November 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-november-2025-monthly-rollup-av25-739","alert_type":396,"serial_number":"AV25-739","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":6982,"title":"Adobe security advisory (AV25-741)","uuid":"8c284e36-a60a-4d61-9d82-4ba9fd673e7e","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T16:35:40Z","date_created":"2025-11-12T16:26:11Z","summary":null,"body":["<article data-history-node-id=\"6982\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-741\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-741<br \/><strong>Date: <\/strong>November\u00a012, 2025<\/p>\n\n<p>On November\u00a011, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Format Plugins\u00a0\u2013 version 1.1.1 and prior<\/li>\n\t<li>Adobe Illustrator on iPad\u00a0\u2013 version 3.0.9 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 19.5.5 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 20.5 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.5.5 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID20.5 and prior<\/li>\n\t<li>Adobe Pass Authentication Android SDK\u00a0\u2013 version 3.7.3 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.1.5 and prior<\/li>\n\t<li>Illustrator 2024\u00a0\u2013 version 28.7.10 and prior<\/li>\n\t<li>Illustrator 2025\u00a0\u2013 version 29.8.2 and prior<\/li>\n\t<li>Photoshop 2025\u00a0\u2013 version 26.8.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-741","alert_type":396,"serial_number":"AV25-741","subject":"adobe","moderation_state":"published","external_url":null},{"nid":6981,"title":"Citrix security advisory (AV25-740)","uuid":"18726d31-60fc-4d18-bf99-23be49107fdc","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T16:33:12Z","date_created":"2025-11-12T16:26:11Z","summary":null,"body":["<article data-history-node-id=\"6981\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-740\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-740<br \/><strong>Date: <\/strong>November\u00a012, 2025<\/p>\n\n<p>On November\u00a011, 2025, Citrix published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway\u202f14.1\u00a0\u2013 versions prior to 1-56.73<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway\u202f13.1\u00a0\u2013 versions prior to 1-60.32<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and NDcPP\u00a0\u2013 versions prior to 1-37.250-FIPS and NDcPP<\/li>\n\t<li>NetScaler ADC 12.1-FIPS and NDcPP\u00a0\u2013 versions prior to 1-55.333-FIPS and NDcPP<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX695486&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_12101\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-12101<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/knowledge-center#\/?ct=Security%20Bulletins&amp;searchText=&amp;sortBy=Created%20date&amp;pageIndex=1\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-740","alert_type":396,"serial_number":"AV25-740","subject":"citrix","moderation_state":"published","external_url":null},{"nid":6983,"title":"Google Chrome security advisory (AV25-742)","uuid":"227b9b58-b520-4c1b-887b-3cb33a7ffcee","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T16:49:08Z","date_created":"2025-11-12T16:26:13Z","summary":null,"body":["<article data-history-node-id=\"6983\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-742\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-742<br \/><strong>Date: <\/strong>November\u00a012, 2025<\/p>\n\n<p>On November\u00a011, 2025, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 142.0.7444.162\/.163 Windows and 142.0.7444.162 (Mac and Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/11\/stable-channel-update-for-desktop_11.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-742","alert_type":396,"serial_number":"AV25-742","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":6984,"title":"HPE security advisory (AV25-743)","uuid":"e895758c-f709-41bb-9375-5d531f36c565","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T17:02:17Z","date_created":"2025-11-12T16:50:16Z","summary":null,"body":["<article data-history-node-id=\"6984\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-743\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-743<br \/><strong>Date: <\/strong>November\u00a012, 2025<\/p>\n\n<p>On November\u00a011, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant DL\/XL servers\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE ProLiant DL, and Synergy Servers\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04962en_us&amp;docLocale=en_US#hpesbhf04962-rev-1-certain-hpe-proliant-dl-xl-serv-0\">HPESBHF04962 rev.1\u00a0- Certain HPE ProLiant DL\/XL servers Using Certain AMD EPYC Processors. AMD-SB-3029: Stale Translation Lookaside Buffer (TLB) Entry Vulnerability, Local Unauthorized Access Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04965en_us&amp;docLocale=en_US#hpesbhf04965-rev-1-certain-hpe-proliant-dl-and-syn-0\">HPESBHF04965 rev.1\u00a0- Certain HPE ProLiant DL, and Synergy Servers Using Certain Intel Processor BIOS, INTEL-SA-01378, UPLR1 \u2013 Intel UEFI Server Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-743","alert_type":396,"serial_number":"AV25-743","subject":"hpe","moderation_state":"published","external_url":null},{"nid":6985,"title":"Intel security advisory (AV25-744)","uuid":"1e0976a1-c530-4b41-9457-987a1ef32ff4","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T18:51:37Z","date_created":"2025-11-12T18:34:54Z","summary":null,"body":["<article data-history-node-id=\"6985\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av25-744\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-744<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 11, 2025, Intel published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Product Security Center Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av25-744","alert_type":396,"serial_number":"AV25-744","subject":"intel","moderation_state":"published","external_url":null},{"nid":6986,"title":"Microsoft Edge security advisory (AV25-745)","uuid":"46583733-9b4e-45cb-b6ff-018c36bf2631","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T19:12:32Z","date_created":"2025-11-12T19:04:52Z","summary":null,"body":["<article data-history-node-id=\"6986\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-745\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-745<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 11, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 142.0.3595.76<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-11-2025\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft Edge Stable Channel Release Notes<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-745","alert_type":396,"serial_number":"AV25-745","subject":"other","moderation_state":"published","external_url":null},{"nid":6987,"title":"Ivanti security advisory (AV25-746)","uuid":"93711620-21e1-4298-b6a9-f6a449460c49","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T19:31:33Z","date_created":"2025-11-12T19:20:03Z","summary":null,"body":["<article data-history-node-id=\"6987\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-746\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-746<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 10, 2025, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager\u00a0\u2013 version 2024 SU3 SR1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US\">Security Advisory EPM November 2025 for EPM 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-746","alert_type":396,"serial_number":"AV25-746","subject":"other","moderation_state":"published","external_url":null},{"nid":6989,"title":"Mozilla security advisory (AV25-747)","uuid":"828951d2-c7d6-4e11-ae1c-86266947f8d0","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T20:53:35Z","date_created":"2025-11-12T20:43:53Z","summary":null,"body":["<article data-history-node-id=\"6989\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-747\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-747<br \/><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 11, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 145<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 140.5<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.30<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-87\/\">Mozilla Foundation Security Advisory 2025-87<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-88\/\">Mozilla Foundation Security Advisory 2025-88<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-89\/\">Mozilla Foundation Security Advisory 2025-89<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-747","alert_type":396,"serial_number":"AV25-747","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":6990,"title":"Palo Alto Networks security advisory (AV25-748)","uuid":"d8ec28e7-75b8-407e-946d-63899be6d901","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T21:17:22Z","date_created":"2025-11-12T21:08:31Z","summary":null,"body":["<article data-history-node-id=\"6990\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-748\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-748<br \/><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 12, 2025, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PAN-OS 11.2\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 multiple versions<\/li>\n\t<li>Prisma Access\u00a0\u2013 multiple versions<\/li>\n\t<li>Prisma Browser\u00a0\u2013 version prior to 142.15.2.60<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2025-4619\">CVE-2025-4619 PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Packets<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2025-0018\">PAN-SA-2025-0018 Chromium and Prisma Browser: Monthly Vulnerability Update (November 2025)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av25-748","alert_type":396,"serial_number":"AV25-748","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":6991,"title":"[Control systems] Siemens security advisory (AV25-749)","uuid":"e4da81ea-c3db-499a-a5a3-925f671a1e34","banner":null,"lang":"en","date_modified":"2025-11-12","date_modified_ts":"2025-11-12T21:36:47Z","date_created":"2025-11-12T21:29:17Z","summary":null,"body":["<article data-history-node-id=\"6991\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-749\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-749<br \/><strong>Date: <\/strong>November 12, 2025<\/p>\n\n<p>On November 11, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>SICAM P850 family\u00a0\u2013 versions prior to V3.11<\/li>\n\t<li>SICAM P855 family\u00a0\u2013 versions prior to V3.11<\/li>\n\t<li>LOGO! V8.4 BM\u00a0\u2013 all versions<\/li>\n\t<li>SIPLUS LOGO! V8.4 BM\u00a0\u2013 all versions<\/li>\n\t<li>Spectrum Power 4\u00a0\u2013 versions prior to V4.70 SP12 Update 2<\/li>\n\t<li>Siemens Software Center\u00a0\u2013 versions prior to V3.5<\/li>\n\t<li>Solid Edge SE2025\u00a0\u2013 versions prior to V225.0 Update 10<\/li>\n\t<li>Altair Grid Engine\u00a0\u2013 versions prior to V2026.0.0<\/li>\n\t<li>Solid Edge SE2025\u00a0\u2013 versions prior to V225.0 Update 11<\/li>\n\t<li>COMOS\u00a0\u2013 versions prior to V10.4.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-749","alert_type":398,"serial_number":"AV25-749","subject":"siemens","moderation_state":"published","external_url":null},{"nid":6992,"title":"Drupal security advisory (AV25-750)","uuid":"ea73278d-303c-4931-82ed-1b212cfacd95","banner":null,"lang":"en","date_modified":"2025-11-13","date_modified_ts":"2025-11-13T14:16:01Z","date_created":"2025-11-13T14:06:36Z","summary":null,"body":["<article data-history-node-id=\"6992\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-750\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-750<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2025<\/p>\n\n<p>On November 12, 2025, Drupal published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Drupal core\u00a0\u2013 version 8.0.0 to versions prior to 10.4.9, version 10.5.0 to versions prior to 10.5.6, version 11.0.0 to versions prior to 11.1.9 and version 11.2.0 to versions prior to 11.2.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-core-2025-008\">Drupal core\u00a0- Moderately critical\u00a0- Information disclosure\u00a0- SA-CORE-2025-008<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-core-2025-005\">Drupal core\u00a0- Moderately critical\u00a0- Denial of Service\u00a0- SA-CORE-2025-005<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-core-2025-006\">Drupal core\u00a0- Moderately critical\u00a0- Gadget chain\u00a0- SA-CORE-2025-006<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-core-2025-007\">Drupal core\u00a0- Moderately critical\u00a0- Defacement\u00a0- SA-CORE-2025-007<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-750","alert_type":396,"serial_number":"AV25-750","subject":"drupal","moderation_state":"published","external_url":null},{"nid":6993,"title":"GitLab security advisory (AV25-751)","uuid":"be661432-b0ff-4d67-a7d5-d3dc2444a2a4","banner":null,"lang":"en","date_modified":"2025-11-13","date_modified_ts":"2025-11-13T16:12:21Z","date_created":"2025-11-13T16:03:41Z","summary":null,"body":["<article data-history-node-id=\"6993\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-751\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-751<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2025<\/p>\n\n<p>On November 12, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.5.2, 18.4.4 and 18.3.6<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 18.5.2, 18.4.4 and 18.3.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/11\/12\/patch-release-gitlab-18-5-2-released\/\">GitLab Patch Release: 18.5.2, 18.4.4, 18.3.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-751","alert_type":396,"serial_number":"AV25-751","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":6994,"title":"[Control systems] Schneider Electric security advisory (AV25-752)","uuid":"9270fba2-d56b-41c7-9e2d-c2c428df69cc","banner":null,"lang":"en","date_modified":"2025-11-13","date_modified_ts":"2025-11-13T20:59:38Z","date_created":"2025-11-13T19:53:12Z","summary":null,"body":["<article data-history-node-id=\"6994\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-752\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-752<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2025<\/p>\n\n<p>On November 11, 2025, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Machine SCADA Expert\u00a0\u2013 versions prior to 2023.1 Patch 1<\/li>\n\t<li>Pro-face BLUE Open Studio\u00a0\u2013 versions prior to 2023.1 Patch 1<\/li>\n\t<li>PowerChute Serial Shutdown\u00a0\u2013 versions v1.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-315-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-315-02.pdf\">EcoStruxure Machine SCADA Expert &amp; Pro-face BLUE Open Studio (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-315-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-315-01.pdf\">PowerChute Serial Shutdown (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-752","alert_type":398,"serial_number":"AV25-752","subject":"se","moderation_state":"published","external_url":null},{"nid":6995,"title":"[Control systems] Rockwell Automation security advisory (AV25-753)","uuid":"2ac9bdb3-8ba9-43d0-a140-66780e567802","banner":null,"lang":"en","date_modified":"2025-11-13","date_modified_ts":"2025-11-13T21:03:08Z","date_created":"2025-11-13T20:58:23Z","summary":null,"body":["<article data-history-node-id=\"6995\" about=\"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av25-753\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-753<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 13, 2025<\/p>\n\n<p>On November 11, 2025, Rockwell Automation published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Verve Asset Manager\u00a0\u2013 versions 1.33 to 1.41.3.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories\/advisory.SD1759.html\">Rockwell Automation\u00a0\u2013 Verve Asset Manager Access Control Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories.html\">Rockwell Automation Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-French-%20%20******************************************************%2D%2D%3E--><!--{C}%3C!%2D%2D%20%20%3Cspan%20lang%3D%22en%22%3E%3C%2Fspan%3E%20%20%20%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-rockwell-automation-security-advisory-av25-753","alert_type":398,"serial_number":"AV25-753","subject":"other","moderation_state":"published","external_url":null},{"nid":6996,"title":"Splunk security advisory (AV25-754)","uuid":"4eecd4bb-ed94-490e-829f-e59d74f4086d","banner":null,"lang":"en","date_modified":"2025-11-14","date_modified_ts":"2025-11-14T13:43:32Z","date_created":"2025-11-14T13:36:38Z","summary":null,"body":["<article data-history-node-id=\"6996\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-754\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-754<br \/><strong>Date: <\/strong>November\u00a014, 2025<\/p>\n\n<p>On November\u00a012, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk Enterprise\u00a0\u2013 multiple versions<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1101\">Open Redirect on Web Login endpoint in Splunk Enterprise<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1102\">Risky command safeguards bypass using the \u201c\/services\/streams\/search\u201d REST endpoint through \u201cq\u201d parameter in Splunk Enterprise<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1103\">Third-Party Package Updates in Splunk Enterprise\u00a0- November 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-754","alert_type":396,"serial_number":"AV25-754","subject":"other","moderation_state":"published","external_url":null},{"nid":6997,"title":"Microsoft Edge security advisory (AV25-755)","uuid":"180ab99d-b50c-49e9-a35c-abd2ee7ae893","banner":null,"lang":"en","date_modified":"2025-11-14","date_modified_ts":"2025-11-14T13:49:50Z","date_created":"2025-11-14T13:36:39Z","summary":null,"body":["<article data-history-node-id=\"6997\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-755\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-755<br \/><strong>Date: <\/strong>November\u00a014, 2025<\/p>\n\n<p>On November\u00a013, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 142.0.3595.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-13-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-755","alert_type":396,"serial_number":"AV25-755","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7002,"title":"Samsung mobile security advisory (AV25-757)","uuid":"6f965492-2f94-47ad-9d4c-89ab4e1c82a8","banner":null,"lang":"en","date_modified":"2025-11-14","date_modified_ts":"2025-11-14T16:56:53Z","date_created":"2025-11-14T16:46:44Z","summary":null,"body":["<article data-history-node-id=\"7002\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av25-757\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-757<br \/><strong>Date: <\/strong>November\u00a014, 2025<\/p>\n\n<p>On November 4, 2025, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices \u2013 versions prior to SMR-NOV-2025<\/li>\n<\/ul><p>The most recent security update resolves multiple identified vulnerabilities. Furthermore, on November 10, 2025, CISA added CVE-2025-21042 to its Known Exploited Vulnerabilities (KEV) Catalog. Keeping mobile devices updated with the latest security release is essential to maintaining protection against emerging threats.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2025&amp;month=11\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av25-757","alert_type":396,"serial_number":"AV25-757","subject":"other","moderation_state":"published","external_url":null},{"nid":7001,"title":"HPE security advisory (AV25-756)","uuid":"3f95f624-b222-456e-8ba3-69834c1c95d3","banner":null,"lang":"en","date_modified":"2025-11-14","date_modified_ts":"2025-11-14T16:52:23Z","date_created":"2025-11-14T16:46:44Z","summary":null,"body":["<article data-history-node-id=\"7001\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-756\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-756<br \/><strong>Date: <\/strong>November\u00a014, 2025<\/p>\n\n<p>On November\u00a013, 2025, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE SimpliVity 325 Gen10 Plus\u00a0\u2013 version prior to HPE SimpliVity Gen10 Support Pack (SVTSP) 2025_0630<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04963en_us&amp;docLocale=en_US#hpesbhf04963-rev-1-certain-hpe-simplivity-servers-0\">HPESBHF04963 rev.1\u00a0- Certain HPE SimpliVity servers Using Certain AMD EPYC Processors. AMD-SB-3029: Stale Translation Lookaside Buffer (TLB) Entry Vulnerability, Local Unauthorized Access Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-756","alert_type":396,"serial_number":"AV25-756","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7003,"title":"Fortinet security advisory (AV25-758)","uuid":"d14c4c0d-fea3-4b39-a2de-ffb888f106f5","banner":null,"lang":"en","date_modified":"2025-11-14","date_modified_ts":"2025-11-14T17:02:10Z","date_created":"2025-11-14T16:46:44Z","summary":null,"body":["<article data-history-node-id=\"7003\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-758\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-758<br \/><strong>Date: <\/strong>November\u00a014, 2025<\/p>\n\n<p>On November\u00a014, 2025, Fortinet published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>FortiWeb\u00a0\u2013 versions 8.0.0 to 8.0.1<\/li>\n\t<li>FortiWeb\u00a0\u2013 versions 7.6.0 to 7.6.4<\/li>\n\t<li>FortiWeb\u00a0\u2013 versions 7.4.0 to 7.4.9<\/li>\n\t<li>FortiWeb\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiWeb\u00a0\u2013 versions 7.0.0 to 7.0.11<\/li>\n<\/ul><p>Fortinet is aware that an exploit for CVE-2025-64446 exists and is currently being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-910\">PSIRT Advisory: FG-IR-25-910<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-758","alert_type":396,"serial_number":"AV25-758","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7004,"title":"AL25-017 - Vulnerability impacting Fortinet FortiWeb \u2013 CVE-2025-64446","uuid":"d22922fa-70bf-4ae9-b7f2-764a94d080f9","banner":null,"lang":"en","date_modified":"2025-11-14","date_modified_ts":"2025-11-14T19:04:48Z","date_created":"2025-11-14T18:08:27Z","summary":null,"body":["<article data-history-node-id=\"7004\" about=\"\/en\/alerts-advisories\/al25-017-vulnerability-impacting-fortinet-fortiweb-cve-2025-64446\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-017<br \/><strong>Date:<\/strong> November\u00a014, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On November 13, 2025, the Cyber Centre became aware of a critical path traversal vulnerability impacting the Web UI of Fortinet's FortiWeb that can result in root access to the device<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. The Cyber Centre has observed open-source reporting which indicates that the vulnerability is being exploited in the wild.<\/p>\n\n<p>CVE-2025-64446<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> is a relative path traversal vulnerability in the Common Gateway Interface (CGI) [CWE-23]<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> of FortiWeb that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.<\/p>\n\n<p>In response to this vulnerability, the Cyber Centre, on November 14, 2025, released AV25-758<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. CISA has added CVE-2025-64446 to their Known Exploited Vulnerabilities (KEV) <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> catalog on November 14, 2025.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>Cyber Centre recommends that organizations patch their FortiWeb to the following versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Version<\/th>\n\t\t\t<th scope=\"col\">Affected Products<\/th>\n\t\t\t<th scope=\"col\">Solutions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>FortiWeb 8.0<\/td>\n\t\t\t<td>8.0.0 through 8.0.1<\/td>\n\t\t\t<td>FortiWeb\u00a0\u2013 version 8.0.2 or later<\/td>\n\t\t<\/tr><tr><td>FortiWeb 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.4<\/td>\n\t\t\t<td>FortiWeb\u00a0\u2013 version 7.6.5 or later<\/td>\n\t\t<\/tr><tr><td>FortiWeb 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.9<\/td>\n\t\t\t<td>FortiWeb\u00a0\u2013 version 7.4.10 or later<\/td>\n\t\t<\/tr><tr><td>FortiWeb 7.2<\/td>\n\t\t\t<td>7.2.0 through 7.2.11<\/td>\n\t\t\t<td>FortiWeb\u00a0\u2013 version 7.2.12 or later<\/td>\n\t\t<\/tr><tr><td>FortiWeb 7.0<\/td>\n\t\t\t<td>7.0.0 through 7.0.11<\/td>\n\t\t\t<td>FortiWeb\u00a0\u2013 version 7.0.12 or later<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>It is imperative for organizations to identify and prioritize the patching of vulnerable systems promptly, using guidance provided by the vendor<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre strongly recommends that organizations follow Fortinet customer guidance for mitigation advice:<\/p>\n\n<ul><li>Apply the recommended update. If this is not possible, apply the following workaround:\n\t<ul><li>Disable HTTP or HTTPS for internet facing interfaces. Fortinet recommend taking this action until an upgrade can be performed.<\/li>\n\t<\/ul><\/li>\n\t<li>Post Upgrade Steps:\n\t<ul><li>It is recommended that customers review their configurations and logs for unexpected modifications, including the addition of unauthorized administrator accounts.<\/li>\n\t<\/ul><\/li>\n<\/ul><p>In addition, the Cyber Centre also strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions with an emphasis on the following topics <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<ul><li>Patching operating systems and applications<\/li>\n\t<li>Segment and separate information<\/li>\n\t<li>Isolating Web-Facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via the <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-910\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Fortinet<\/span> PSIRT <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Advisory<\/span> (FG-IR-25-910)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-64446\">CVE-2025-64446 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/23.html\">CWE-23: Relative Path Traversal<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-758\">Fortinet security advisory (AV25-758)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/11\/14\/cisa-adds-one-known-exploited-vulnerability-catalog\">Known Exploited Vulnerabilities Catalog | CISA<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-017-vulnerability-impacting-fortinet-fortiweb-cve-2025-64446","alert_type":397,"serial_number":"AL25-017","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7005,"title":"Cisco security advisory (AV25-759)","uuid":"84c18cf8-543f-42ef-ac53-d722994d199a","banner":null,"lang":"en","date_modified":"2025-11-14","date_modified_ts":"2025-11-14T20:27:37Z","date_created":"2025-11-14T20:20:46Z","summary":null,"body":["<article data-history-node-id=\"7005\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-759\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-759<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 14, 2025<\/p>\n\n<p>On November 13, 2025, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Catalyst Center Hardware Appliance\u00a0\u2013 versions prior to 2.3.7.10<\/li>\n\t<li>Cisco Catalyst Center Virtual Appliance\u00a0\u2013 versions prior to 2.3.7.10-VA<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-759","alert_type":396,"serial_number":"AV25-759","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7006,"title":"IBM security advisory (AV25-760)","uuid":"6b206f9e-7340-4195-ba2d-1ebe0ac95b12","banner":null,"lang":"en","date_modified":"2025-11-17","date_modified_ts":"2025-11-17T13:37:05Z","date_created":"2025-11-17T13:31:40Z","summary":null,"body":["<article data-history-node-id=\"7006\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-760\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-760<br \/><strong>Date: <\/strong>November 17, 2025<\/p>\n\n<p>Between November 10 and 16, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-760","alert_type":396,"serial_number":"AV25-760","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7007,"title":"Dell security advisory (AV25-761)","uuid":"e92e6f4e-ba48-4b68-a04a-714d3ddb7adb","banner":null,"lang":"en","date_modified":"2025-11-17","date_modified_ts":"2025-11-17T13:54:26Z","date_created":"2025-11-17T13:42:51Z","summary":null,"body":["<article data-history-node-id=\"7007\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-761\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-761<br \/><strong>Date: <\/strong>November 17, 2025<\/p>\n\n<p>Between November 10 and 16, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell AMD-based PowerEdge Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Alienware X16 R2\u00a0\u2013 versions prior to 32.0.100.4239<\/li>\n\t<li>Dell Data Lakehouse\u00a0\u2013 versions prior to 1.6.0.0<\/li>\n\t<li>Dell Inspiron 14 Plus 7440\u00a0\u2013 versions prior to 32.0.100.4239<\/li>\n\t<li>Dell Inspiron 16 7640 2-in-1\u00a0\u2013 versions prior to 32.0.100.4239<\/li>\n\t<li>Dell Inspiron 16 Plus 7640\u00a0\u2013 versions prior to 32.0.100.4239<\/li>\n\t<li>Dell Intel E810 Adapters and Intel E823 LOM\u00a0\u2013 versions prior to 24.0.0<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 versions prior to 19.12.0.3<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions prior to 10.6.1.0<\/li>\n\t<li>Dell PowerFlex Appliance\u00a0\u2013 versions prior to IC 48.378.00 and IC 48.383.00<\/li>\n\t<li>Dell PowerFlex Software\u00a0\u2013 versions prior to 4.8.0<\/li>\n\t<li>Dell PowerFlex rack\u00a0\u2013 versions prior to 3.7.7.0 and 3.8.2.0<\/li>\n\t<li>Dell PowerScale OneFS\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Pro Max Slim FCS1250\u00a0\u2013 versions prior to 32.0.100.4239<\/li>\n\t<li>Dell Pro Slim Plus QBS1250\/Dell Pro Slim QCS1250\u00a0\u2013 versions prior to 32.0.100.4239<\/li>\n\t<li>Dell Slim ECS1250\u00a0\u2013 versions prior to 32.0.100.4239<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-761","alert_type":396,"serial_number":"AV25-761","subject":"dell","moderation_state":"published","external_url":null},{"nid":7008,"title":"Ubuntu security advisory (AV25-762)","uuid":"2126fe39-0a0a-4af9-a388-bcee09618965","banner":null,"lang":"en","date_modified":"2025-11-17","date_modified_ts":"2025-11-17T14:04:44Z","date_created":"2025-11-17T13:58:41Z","summary":null,"body":["<article data-history-node-id=\"7008\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-762\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-762<br \/><strong>Date: <\/strong>November 17, 2025<\/p>\n\n<p>Between November 10 and 16, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7865-1\">USN-7865-1: Linux kernel (FIPS) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7862-2\">USN-7862-2: Linux kernel vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7861-3\">USN-7861-3: Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-762","alert_type":396,"serial_number":"AV25-762","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7009,"title":"Red Hat security advisory (AV25-763)","uuid":"cd459128-e138-4571-8213-36817f2ab77d","banner":null,"lang":"en","date_modified":"2025-11-17","date_modified_ts":"2025-11-17T14:17:21Z","date_created":"2025-11-17T14:12:39Z","summary":null,"body":["<article data-history-node-id=\"7009\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-763\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-763<br \/><strong>Date: <\/strong>November 17, 2025<\/p>\n\n<p>Between November 10 and 16, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-763","alert_type":396,"serial_number":"AV25-763","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7010,"title":"[Control systems] CISA ICS security advisories (AV25\u2013764)","uuid":"0b3d6da0-d82c-4ccb-8475-44eb768d8e0f","banner":null,"lang":"en","date_modified":"2025-11-17","date_modified_ts":"2025-11-17T16:08:23Z","date_created":"2025-11-17T15:15:48Z","summary":null,"body":["<article data-history-node-id=\"7010\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-764\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-764<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 17, 2025<\/p>\n\n<p>Between November 10 and 16, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA Application Server IDE\u00a0\u2013 version 2023 R2SP1 PO2 and prior<\/li>\n\t<li>AVEVA Edge\u00a0\u2013 version 2023 R2 and prior<\/li>\n\t<li>Brightpick Mission Control \/ Internal Logic Control\u00a0\u2013 All versions<\/li>\n\t<li>Festo Hardware Controller\u00a0\u2013 multiple models and firmware versions<\/li>\n\t<li>General Industrial Controls Lynx+ Gateway\u00a0\u2013 versions R08, V03, V05 and V18<\/li>\n\t<li>Mitsubishi MELSEC iQ-F Series\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Rockwell Automation AADvance-Trusted SIS Workstation\u00a0\u2013 versions 2.00.00 to 2.00.04<\/li>\n\t<li>Rockwell Automation FactoryTalk DataMosaix Private Cloud\u00a0\u2013 versions 7.11, 8.00 and<\/li>\n\t<li>8.01<\/li>\n\t<li>Rockwell Automation FactoryTalk Policy Manager\u00a0\u2013 version 6.51.00 and prior<\/li>\n\t<li>Rockwell Automation Studio 5000 Simulation Interface\u00a0\u2013 version 2.02 and prior<\/li>\n\t<li>Rockwell Automation Verve Asset Manager\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Altair Grid Engine\u00a0\u2013 versions prior to V2026.0.0<\/li>\n\t<li>Siemens COMOS with COMOS Web deployed\u00a0\u2013 versions prior to 10.4.5<\/li>\n\t<li>Siemens COMOS using COMOS Snapshots component\u00a0\u2013 versions prior to 10.4.5<\/li>\n\t<li>Siemens LOGO! 8 BM Devices\u00a0\u2013 multiple models and all versions<\/li>\n\t<li>Siemens SICAM P850 family and SICAM P855 family\u00a0\u2013 multiple models and versions<\/li>\n\t<li>prior to 3.11<\/li>\n\t<li>Siemens Software Center\u00a0\u2013 versions prior to 3.5<\/li>\n\t<li>Siemens Solid Edge SE2025\u00a0\u2013 versions prior to V225.0 Update 11<\/li>\n\t<li>Siemens Spectrum Power 4\u00a0\u2013 versions prior to V4.70 SP12 Update 2<\/li>\n\t<li>Ubia Ubox\u00a0\u2013 version v1.1.124<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-764","alert_type":398,"serial_number":"AV25-764","subject":"other","moderation_state":"published","external_url":null},{"nid":7011,"title":"[Control systems] Siemens security advisory (AV25-765) ","uuid":"8c0c9945-ba80-48d0-bfe5-3eff2dc8424c","banner":null,"lang":"en","date_modified":"2025-11-17","date_modified_ts":"2025-11-17T18:43:46Z","date_created":"2025-11-17T18:19:20Z","summary":null,"body":["<article data-history-node-id=\"7011\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-765\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-765<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 17, 2025<\/p>\n\n<p>On November 17, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Mendix RichText\u00a0\u2013 versions prior to V4.6.1<\/li>\n\t<li>PS\/IGES Parasolid Translator Component\u00a0\u2013 versions prior to V29.0.258<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-190588.html\">SSA-190588: Cross-Site Scripting Vulnerability in Mendix Rich Text Widget<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-241605.html\">SSA-241605: Out of Bounds Read in PS\/IGES Parasolid Translator Component Before V29.0.258<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-765","alert_type":398,"serial_number":"AV25-765","subject":"other","moderation_state":"published","external_url":null},{"nid":7015,"title":"Google Chrome security advisory (AV25-766) - Update 1","uuid":"30f3b4b3-10d2-485c-ae6b-fdb71b2dff64","banner":null,"lang":"en","date_modified":"2025-11-19","date_modified_ts":"2025-11-19T20:19:02Z","date_created":"2025-11-18T13:49:17Z","summary":null,"body":["<article data-history-node-id=\"7015\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-766\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-766<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 18, 2025<br \/><strong>Updated: <\/strong>November 19, 2025<\/p>\n\n<p>On November 17, 2025, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 142.0.7444.175\/.176 (Windows\/Mac) and 142.0.7444.175 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2025-13223 exists in the wild.<\/p>\n\n<p><strong>Update 1<\/strong><br \/>\nOn November 19, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-13223 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities Catalog | CISA<\/a><\/li>\n\t<li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/11\/stable-channel-update-for-desktop_17.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-766","alert_type":396,"serial_number":"AV25-766","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7016,"title":"Zyxel security advisory (AV25-767)","uuid":"e0887b73-5fc5-4ea3-8f7b-1697092db09f","banner":null,"lang":"en","date_modified":"2025-11-18","date_modified_ts":"2025-11-18T14:47:40Z","date_created":"2025-11-18T14:05:23Z","summary":null,"body":["<article data-history-node-id=\"7016\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av25-767\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-767<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 18, 2025<\/p>\n\n<p>On November 18, 2025, Zyxel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>4G LTE\/5G NR CPE\u00a0\u2013 multiple versions and models<\/li>\n\t<li>DSL\/Ethernet CPE\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Fiber ONTs\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Security Routers\u00a0\u2013 version 1.10(ACGN.3)C0 and prior<\/li>\n\t<li>Wireless Extenders\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-uncontrolled-resource-consumption-and-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-security-routers-and-wireless-extenders-11-18-2025\">Zyxel security advisory for uncontrolled resource consumption and command injection vulnerabilities in certain 4G LTE\/5G NR CPE, DSL\/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av25-767","alert_type":396,"serial_number":"AV25-767","subject":"other","moderation_state":"published","external_url":null},{"nid":7017,"title":"HPE security advisory (AV25-768)","uuid":"184f42d4-9ff6-4515-89d6-c9950d2fa1a3","banner":null,"lang":"en","date_modified":"2025-11-18","date_modified_ts":"2025-11-18T21:02:07Z","date_created":"2025-11-18T20:46:30Z","summary":null,"body":["<article data-history-node-id=\"7017\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-768\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-768<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 18, 2025<\/p>\n\n<p>On November 18, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking AOS-CX\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Aruba Networking Management Software (AirWave)\u00a0\u2013 versions 8.3.0.4 and prior<\/li>\n\t<li>HPE Aruba Networking 100 Series Cellular Bridge AOS-10.7.1.x\u00a0\u2013 versions 10.7.1.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04888en_us&amp;docLocale=en_US#hpesbnw04888-rev-1-hpe-aruba-networking-aos-cx-mul-0\">HPESBNW04888 rev.1\u00a0- HPE Aruba Networking AOS-CX Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04971en_us&amp;docLocale=en_US#hpesbnw04971-rev-1-hpe-aruba-networking-management-0\">HPESBNW04971 rev.1\u00a0- HPE Aruba Networking Management Software (AirWave), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04970en_us&amp;docLocale=en_US#hpesbnw04970-rev-1-hpe-aruba-networking-100-series-0\">HPESBNW04970 rev.1\u00a0- HPE Aruba Networking 100 Series Cellular Bridge, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-768","alert_type":396,"serial_number":"AV25-768","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7018,"title":" Fortinet security advisory (AV25-769)","uuid":"5a4adc4b-0d73-491e-a46d-f42b6d3430f8","banner":null,"lang":"en","date_modified":"2025-11-18","date_modified_ts":"2025-11-18T21:22:18Z","date_created":"2025-11-18T21:16:51Z","summary":null,"body":["<article data-history-node-id=\"7018\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-769\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-769<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 18, 2025<\/p>\n\n<p>On November 18, 2025, Fortinet published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>Fortinet is aware that an exploit for CVE-2025-58034 exists in the wild.<\/p>\n\n<p>On November 18, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-58034 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/11\/18\/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Adds One Known Exploited Vulnerability to Catalog<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-513\">PSIRT Advisory: FG-IR-25-513<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Fortinet<\/span> PSIRT <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Advisories<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-769","alert_type":396,"serial_number":"AV25-769","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7021,"title":"Atlassian security advisory (AV25-770)","uuid":"bac07d2f-712f-4f63-b550-cc9bf0e822b2","banner":null,"lang":"en","date_modified":"2025-11-19","date_modified_ts":"2025-11-19T16:40:21Z","date_created":"2025-11-19T16:32:30Z","summary":null,"body":["<article data-history-node-id=\"7021\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-770\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-770<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 19, 2025<\/p>\n\n<p>On November 18, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-november-18-2025-1671463469.html\">Security Bulletin\u00a0- November 18 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-770","alert_type":396,"serial_number":"AV25-770","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":7022,"title":"Microsoft Edge security advisory (AV25-771)","uuid":"a08c2013-8d69-46fd-b44e-0f7d0c68ba74","banner":null,"lang":"en","date_modified":"2025-11-19","date_modified_ts":"2025-11-19T18:20:23Z","date_created":"2025-11-19T16:49:43Z","summary":null,"body":["<article data-history-node-id=\"7022\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-771\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-771<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 19, 2025<\/p>\n\n<p>On November 18, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 142.0.3595.90<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#november-18-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-771","alert_type":396,"serial_number":"AV25-771","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7023,"title":"SolarWinds security advisory (AV25-772)","uuid":"304859a8-631d-4737-838b-4493b4aecf73","banner":null,"lang":"en","date_modified":"2025-11-19","date_modified_ts":"2025-11-19T19:42:28Z","date_created":"2025-11-19T19:06:31Z","summary":null,"body":["<article data-history-node-id=\"7023\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-772\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-772<br \/><strong>Date: <\/strong>November\u00a019, 2025<\/p>\n\n<p>On November\u00a018, 2025, SolarWinds published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>SolarWinds Serv-U\u00a0\u2013 version 15.5.2.2.102<\/li>\n\t<li>SolarWinds Serv-U Broken Access Control\u00a0\u2013 version 15.5.2.2.102<\/li>\n\t<li>SolarWinds Observability Self-Hosted\u00a0\u2013 version 2025.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av25-772","alert_type":396,"serial_number":"AV25-772","subject":"other","moderation_state":"published","external_url":null},{"nid":7024,"title":"VMware security advisory (AV25-773)","uuid":"c0eb8518-e98e-4288-aedf-b2dba7f82899","banner":null,"lang":"en","date_modified":"2025-11-19","date_modified_ts":"2025-11-19T19:45:27Z","date_created":"2025-11-19T19:39:46Z","summary":null,"body":["<article data-history-node-id=\"7024\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-773\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-773<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 19, 2025<\/p>\n\n<p>Between November 18 and 19, 2025, VMware published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu GemFire\u00a0\u2013 versions prior to 10.1.5<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 6.31.1<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 7.6.1<\/li>\n\t<li>VMware Tanzu Data Flow on Tanzu Platform\u00a0\u2013 versions prior to 2.0.1<\/li>\n\t<li>VMware Tanzu Kubernetes Runtime .NET Core Buildpack\u00a0\u2013 versions prior to 2.4.67 and 2.4.68<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-773","alert_type":396,"serial_number":"AV25-773","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7025,"title":"SonicWall security advisory (AV25-774)","uuid":"83b2a5da-a9da-45a7-bfeb-75f5ed117335","banner":null,"lang":"en","date_modified":"2025-11-20","date_modified_ts":"2025-11-20T13:40:09Z","date_created":"2025-11-20T13:31:02Z","summary":null,"body":["<article data-history-node-id=\"7025\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-774\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-774<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 20, 2025<\/p>\n\n<p>On November 19, 2025, SonicWall published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Email Security (multiple models)\u00a0\u2013 version 10.0.33.8195 and prior<\/li>\n\t<li>Gen7 hardware Firewalls (multiple models)\u00a0\u2013 version 7.3.0-7012 and prior<\/li>\n\t<li>Gen7 virtual Firewalls (NSv) (multiple models)\u00a0\u2013 version 7.3.0-7012 and prior<\/li>\n\t<li>Gen8 Firewalls (multiple models)\u00a0\u2013 version 8.0.2-8011 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0018\">SonicWall Email Security Affected By Multiple Vulnerabilities 7.2<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0016\">SonicOS SSLVPN Pre-Auth Stack-Based Buffer Overflow Vulnerability 7.5<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-774","alert_type":396,"serial_number":"AV25-774","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":7026,"title":"VMware security advisory (AV25-775)","uuid":"2778cb54-de98-4b02-a07c-9d5e454c3521","banner":null,"lang":"en","date_modified":"2025-11-20","date_modified_ts":"2025-11-20T16:11:09Z","date_created":"2025-11-20T16:06:35Z","summary":null,"body":["<article data-history-node-id=\"7026\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-775\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-775<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 20, 2025<\/p>\n\n<p>On November 20, 2025, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-775","alert_type":396,"serial_number":"AV25-775","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7027,"title":"[Control systems] ABB security advisory (AV25-776)","uuid":"b5da152c-8d38-4778-8d5c-25e75f7cbbc6","banner":null,"lang":"en","date_modified":"2025-11-21","date_modified_ts":"2025-11-21T14:32:07Z","date_created":"2025-11-21T13:49:43Z","summary":null,"body":["<article data-history-node-id=\"7027\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-776\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-776<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 21, 2025<\/p>\n\n<p>On November 20, 2025, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ABB Ability Edgenius\u00a0\u2013 versions 3.2.0.0 and 3.2.1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA022088&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">Edgenius Management Portal Authentication Bypass ABB Ability Edgenius\u00a0- CVE ID: CVE-2025-10571<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-776","alert_type":398,"serial_number":"AV25-776","subject":"abb","moderation_state":"published","external_url":null},{"nid":7028,"title":"HPE security advisory (AV25-777)","uuid":"3c97ebc5-5967-418e-8200-b20a1e0efd28","banner":null,"lang":"en","date_modified":"2025-11-21","date_modified_ts":"2025-11-21T15:08:26Z","date_created":"2025-11-21T14:51:24Z","summary":null,"body":["<article data-history-node-id=\"7028\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-777\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-777<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 21, 2025<\/p>\n\n<p>On November 20, 2025, HPE published a security advisory to address vulnerabilities in the following product\u00a0:<\/p>\n\n<ul><li>HPE Telco Service Activator\u00a0\u2013 versions 10.3.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04973en_us&amp;&amp;docLocale=en_US\">HPESBNW04973 rev.1\u00a0- HPE Telco Service Activator, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-777","alert_type":396,"serial_number":"AV25-777","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7029,"title":"Grafana security advisory (AV25-778)","uuid":"3fb797bd-27f5-4c19-99a1-bfe6563baed5","banner":null,"lang":"en","date_modified":"2025-11-21","date_modified_ts":"2025-11-21T15:30:05Z","date_created":"2025-11-21T15:10:54Z","summary":null,"body":["<article data-history-node-id=\"7029\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av25-778\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-778<br \/><strong>Date: <\/strong>November\u00a021, 2025<\/p>\n\n<p>On November\u00a019, 2025, Grafana published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Grafana Enterprise\u00a0\u2013 versions prior to 12.3.0, 12.2.1, 12.1.3 and 12.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/blog\/2025\/11\/19\/grafana-enterprise-security-update-critical-severity-security-fix-for-cve-2025-41115\/\">Grafana Enterprise security update: critical severity security fix for CVE-2025-41115<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av25-778","alert_type":396,"serial_number":"AV25-778","subject":"other","moderation_state":"published","external_url":null},{"nid":7030,"title":"Dell security advisory (AV25-779)","uuid":"988bd8d0-8b9c-4bfb-9da5-ff649df96e43","banner":null,"lang":"en","date_modified":"2025-11-24","date_modified_ts":"2025-11-24T16:31:06Z","date_created":"2025-11-24T16:24:07Z","summary":null,"body":["<article data-history-node-id=\"7030\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-779\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-779<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 24, 2025<\/p>\n\n<p>Between November 17 and 23, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell ObjectScale\u00a0\u2013 versions prior to 4.1.0.1<\/li>\n\t<li>Dell PowerProtect Cyber Recovery\u00a0\u2013 version 19.21.0.1 and prior<\/li>\n\t<li>Dell PowerProtect Cyber Recovery SLES\u00a0\u2013 versions prior to 15.4.0-10<\/li>\n\t<li>Dell PowerProtect Data Manager\u00a0\u2013 versions prior to 19.22<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 5.1.1.1 and versions prior to 6.0.0.0<\/li>\n\t<li>Dell Storage Resource Manager\u00a0\u2013 versions prior to 5.1.1.1 and versions prior to 6.0.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\/\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-779","alert_type":396,"serial_number":"AV25-779","subject":"dell","moderation_state":"published","external_url":null},{"nid":7031,"title":" IBM security advisory (AV25-780)","uuid":"837733fb-ef3e-4b2b-b7a9-eeab5a9ce0ae","banner":null,"lang":"en","date_modified":"2025-11-24","date_modified_ts":"2025-11-24T16:42:54Z","date_created":"2025-11-24T16:34:21Z","summary":null,"body":["<article data-history-node-id=\"7031\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-780\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-780<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 24, 2025<\/p>\n\n<p>Between November 17 and 23, 2025, IBM published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-780","alert_type":396,"serial_number":"AV25-780","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7032,"title":"Ubuntu security advisory (AV25-781)","uuid":"bceaed4b-b611-4c62-8325-d7cafe90a569","banner":null,"lang":"en","date_modified":"2025-11-24","date_modified_ts":"2025-11-24T16:56:29Z","date_created":"2025-11-24T16:49:59Z","summary":null,"body":["<article data-history-node-id=\"7032\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-781\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-781<br \/><strong>Date: <\/strong>November\u00a024, 2025<\/p>\n\n<p>Between November\u00a017 and 23, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-781","alert_type":396,"serial_number":"AV25-781","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7033,"title":"[Control systems] CISA ICS security advisories (AV25-782)","uuid":"fa138287-c9e5-476e-b90f-c65e4aa0c25b","banner":null,"lang":"en","date_modified":"2025-11-24","date_modified_ts":"2025-11-24T17:10:30Z","date_created":"2025-11-24T16:50:00Z","summary":null,"body":["<article data-history-node-id=\"7033\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-782\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-782<br \/><strong>Date: <\/strong>November\u00a024, 2025<\/p>\n\n<p>Between November\u00a017 and 23, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automated Logic Carrier i-Vu\u00a0\u2013 multiple versions<\/li>\n\t<li>Automated Logic SiteScan Web\u00a0\u2013 multiple versions<\/li>\n\t<li>Automated Logic WebCTRL Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Automated Logic WebCTRL for OEMs\u00a0\u2013 multiple versions<\/li>\n\t<li>Emerson Appleton UPSMON-PRO\u00a0\u2013 versions 2.6 and prior<\/li>\n\t<li>Festo Didactic Siemens TIA-Portal V15\/V18 prior to V17\/V18 Update 6\/1 installed on Festo Hardware MES PC\u00a0\u2013 all versions<\/li>\n\t<li>Festo Didactic Siemens TIA-Portal V15\/V18 prior to V17\/V18 Update 6\/1 installed on Festo Hardware TP260 (&lt;June2023)\u00a0\u2013 all versions<\/li>\n\t<li>Festo MSE6-C2M\/D2M\/E2M (multiple models)\u00a0\u2013 all versions<\/li>\n\t<li>ICAM365 Night Vision Camera QC021\u00a0\u2013 versions 43.4.0.0 and prior<\/li>\n\t<li>ICAM365 ROBOT PT Camera P201\u00a0\u2013 versions 43.4.0.0 and prior<\/li>\n\t<li>METZ CONNECT EWIO2 (multiple models)\u00a0\u2013 all versions<\/li>\n\t<li>Opto 22 GRV-EPIC-PR1\/GRV-EPIC-PR2 Firmware\u00a0\u2013 versions prior to 4.0.3<\/li>\n\t<li>Opto 22 groov RIO GRV-R7-MM1001-10\/ GRV-R7-MM2001-10\/GRV-R7-I1VAPM-3 Firmware\u00a0\u2013 versions prior to 4.0.3<\/li>\n\t<li>Schneider Electric EcoStruxure Machine SCADA Expert\u00a0\u2013 versions prior to 2023.1 Patch 1<\/li>\n\t<li>Schneider Electric PowerChute Serial Shutdown\u00a0\u2013 versions 1.3 and prior<\/li>\n\t<li>Schneider Electric Pro-face BLUE Open Studio\u00a0\u2013 versions prior to 2023.1 Patch 1<\/li>\n\t<li>Shelly Pro 3EM\u00a0\u2013 all versions<\/li>\n\t<li>Shelly Pro 4PM\u00a0\u2013 version prior to v1.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-782","alert_type":398,"serial_number":"AV25-782","subject":"ics","moderation_state":"published","external_url":null},{"nid":7035,"title":"Red Hat security advisory (AV25-783)","uuid":"27c8a0b7-2d48-4175-9780-8bddf4c84954","banner":null,"lang":"en","date_modified":"2025-11-24","date_modified_ts":"2025-11-24T18:22:22Z","date_created":"2025-11-24T18:11:37Z","summary":null,"body":["<article data-history-node-id=\"7035\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-783\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-738<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 24, 2025<\/p>\n\n<p>Between November 17 and 23, 2025, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Red Hat<\/span> published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-783","alert_type":396,"serial_number":"AV25-783","subject":"other","moderation_state":"published","external_url":null},{"nid":7034,"title":"VMware security advisory (AV25-784)","uuid":"2842d208-c7a0-4bb1-86df-ad87e6d4e7e1","banner":null,"lang":"en","date_modified":"2025-11-24","date_modified_ts":"2025-11-24T18:18:46Z","date_created":"2025-11-24T18:17:02Z","summary":null,"body":["<article data-history-node-id=\"7034\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-784\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-784<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 24, 2025<\/p>\n\n<p>Between November 23 and 24, 2025, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-784","alert_type":396,"serial_number":"AV25-784","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7036,"title":"HashiCorp security advisory (AV25-785)","uuid":"625bd8c0-028a-4bc7-af83-8f6c07c65074","banner":null,"lang":"en","date_modified":"2025-11-25","date_modified_ts":"2025-11-25T13:02:24Z","date_created":"2025-11-25T12:58:11Z","summary":null,"body":["<article data-history-node-id=\"7036\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av25-785\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-785<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 25, 2025<\/p>\n\n<p>On November 21, 2025, HashiCorp published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Vault Terraform Provider \u2013 versions v4.2.0 to v5.4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2025-33-vault-terraform-provider-applied-incorrect-defaults-for-ldap-auth-method\/76822 \">HCSEC-2025-33\u00a0- Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av25-785","alert_type":396,"serial_number":"AV25-785","subject":"other","moderation_state":"published","external_url":null},{"nid":7037,"title":"GitLab security advisory (AV25-786)","uuid":"52fbe050-1c54-4d12-8b88-80cd4e326c8e","banner":null,"lang":"en","date_modified":"2025-11-26","date_modified_ts":"2025-11-26T18:24:53Z","date_created":"2025-11-26T18:21:31Z","summary":null,"body":["<article data-history-node-id=\"7037\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-786\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-786<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 26, 2025<\/p>\n\n<p>On November 26, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 18.6.1, 18.5.3 and 18.4.5<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 18.6.1, 18.5.3 and 18.4.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/11\/26\/patch-release-gitlab-18-6-1-released\/ \">GitLab Patch Release: 18.6.1, 18.5.3, 18.4.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/ \">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-786","alert_type":396,"serial_number":"AV25-786","subject":"other","moderation_state":"published","external_url":null},{"nid":7038,"title":"Splunk security advisory (AV25-787)","uuid":"d544b36f-0bf3-4d3d-91ae-a095c167eacb","banner":null,"lang":"en","date_modified":"2025-11-26","date_modified_ts":"2025-11-26T19:06:51Z","date_created":"2025-11-26T19:01:59Z","summary":null,"body":["<article data-history-node-id=\"7038\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-787\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-787<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 26, 2025<\/p>\n\n<p>On November 26, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk SOAR \u2013 versions prior to 7.0.0<\/li>\n\t<li>Splunk Add-on for Palo Alto Networks \u2013 versions prior to 2.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1104 \">Third-Party Package Updates in Splunk SOAR - November 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2025-1105 \">Sensitive Information Disclosure in \u201c_internal\u201c index through Splunk Add-On for Palo Alto Networks<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-787","alert_type":396,"serial_number":"AV25-787","subject":"other","moderation_state":"published","external_url":null},{"nid":7046,"title":"[Control systems] ABB security advisory (AV25-788)","uuid":"8285a2bf-df60-4eb7-8db3-2440967729c9","banner":null,"lang":"en","date_modified":"2025-11-27","date_modified_ts":"2025-11-27T19:01:36Z","date_created":"2025-11-27T18:57:50Z","summary":null,"body":["<article data-history-node-id=\"7046\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-788\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-788<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 27, 2025<\/p>\n\n<p>On November 27, 2025, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB Ability Camera Connect \u2013 version 1.5.0.14 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=4HZM000603&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (VLC)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av25-788","alert_type":398,"serial_number":"AV25-788","subject":"abb","moderation_state":"published","external_url":null},{"nid":7047,"title":"GeoServer security advisory (AV25-789) - Update 1","uuid":"a4c3d48d-167d-424f-99af-e5754a872fe9","banner":null,"lang":"en","date_modified":"2025-12-12","date_modified_ts":"2025-12-12T14:11:25Z","date_created":"2025-11-28T17:16:14Z","summary":null,"body":["<article data-history-node-id=\"7047\" about=\"\/en\/alerts-advisories\/geoserver-security-advisory-av25-789\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-789<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>November 28, 2025<br \/><strong>Updated: <\/strong>December 12, 2025<\/p>\n\n<p>On November 25, 2025, GeoServer published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GeoServer\u00a0\u2013 versions prior to 2.28.1<\/li>\n\t<li>GeoTools\u00a0\u2013 versions prior to 34.1<\/li>\n\t<li>GeoWebCache\u00a0\u2013 versions prior to 1.28<\/li>\n<\/ul><p>Open-source reporting indicates that an exploit for CVE-2025-58360 exists in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On December 11, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-58360 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/geoserver.org\/announcements\/vulnerability\/2025\/11\/25\/geoserver-2-28-1-released.html\">GeoServer 2.28.1 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/geoserver.org\/\">GeoServer<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/12\/11\/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Adds One Known Exploited Vulnerability to Catalog<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/geoserver-security-advisory-av25-789","alert_type":396,"serial_number":"AV25-789","subject":"other","moderation_state":"published","external_url":null},{"nid":7050,"title":"Ubuntu security advisory (AV25-792)","uuid":"bd5efc43-c4c1-42e6-bca4-5b387809b99a","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T16:23:13Z","date_created":"2025-12-01T15:37:48Z","summary":null,"body":["<article data-history-node-id=\"7050\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-792\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-792<br \/><strong>Date: <\/strong>December\u00a01, 2025<\/p>\n\n<p>Between November\u00a024 and 30, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7889-1\">USN-7889-1: Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7887-2\">USN-7887-2: Linux kernel (Raspberry Pi) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7889-3\">USN-7889-3: Linux kernel (Real-time) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7889-2\">USN-7889-2: Linux kernel (FIPS) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7879-3\">USN-7879-3: Linux kernel vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-792","alert_type":396,"serial_number":"AV25-792","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7051,"title":"[Control systems] CISA ICS security advisories (AV25-793)","uuid":"69e1c788-3ead-4709-ae7f-83948ed5d928","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T16:28:51Z","date_created":"2025-12-01T15:37:49Z","summary":null,"body":["<article data-history-node-id=\"7051\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-793\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-793<br \/><strong>Date: <\/strong>December\u00a01, 2025<\/p>\n\n<p>Between November\u00a024 and 30, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ashlar-Vellum Argon\u00a0\u2013 versions 12.6.1204.207 and prior<\/li>\n\t<li>Ashlar-Vellum Cobalt Share\u00a0\u2013 versions 12.6.1204.207 and prior<\/li>\n\t<li>Ashlar-Vellum Cobalt\u00a0\u2013 versions 12.6.1204.207 and prior<\/li>\n\t<li>Ashlar-Vellum Lithium\u00a0\u2013 versions 12.6.1204.207 and prior<\/li>\n\t<li>Ashlar-Vellum Xenon\u00a0\u2013 versions 12.6.1204.207 and prior<\/li>\n\t<li>Festo Software Compact Vision System SBO-Q\u00a0\u2013 all versions<\/li>\n\t<li>Festo Software Control block\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Festo Software Controller\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Festo Software Operator unit\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Opto 22 GRV-EPIC-PR1 Firmware\u00a0\u2013 versions prior to 4.0.3<\/li>\n\t<li>Opto 22 GRV-EPIC-PR2 Firmware\u00a0\u2013 versions prior to 4.0.3<\/li>\n\t<li>Opto 22 groov View Server for Windows\u00a0\u2013 versions R1.0a to R4.5d<\/li>\n\t<li>Rockwell Automation Arena Simulation\u00a0\u2013 version 16.20.10 and prior<\/li>\n\t<li>SiRcom SMART Alert (SiSA)\u00a0\u2013 version 3.0.48<\/li>\n\t<li>Zenitel TCIV-3+\u00a0- versions prior to 9.3.3.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-793","alert_type":398,"serial_number":"AV25-793","subject":"ics","moderation_state":"published","external_url":null},{"nid":7048,"title":"IBM security advisory (AV25-790)","uuid":"08ec9b74-a4b7-447d-949f-05070e3e87a8","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T16:00:31Z","date_created":"2025-12-01T15:45:38Z","summary":null,"body":["<article data-history-node-id=\"7048\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-790\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-790<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 1, 2025<\/p>\n\n<p>Between November 24 and 30, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Astronomer with IBM\u00a0\u2013 versions 1.0.0 to 1.0.1<\/li>\n\t<li>IBM QRadar Deployment Intelligence App\u00a0\u2013 versions 1.0.0 to 3.0.18<\/li>\n\t<li>IBM Spectrum Control\u00a0\u2013 versions 5.4 to 5.4.13.1<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0\u2013 versions 1.4.0 to 1.12.0<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0\u2013 versions 1.4.0 to 1.14.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-790","alert_type":396,"serial_number":"AV25-790","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7049,"title":"Dell security advisory (AV25-791)","uuid":"7a59a177-0b89-4bbc-a4ed-25def64b44a3","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T16:12:55Z","date_created":"2025-12-01T16:05:52Z","summary":null,"body":["<article data-history-node-id=\"7049\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-791\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-791<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 12, 2025<\/p>\n\n<p>Between November 24 and 30, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Microsoft Azure\u00a0\u2013 versions prior to 01.05.02.00<\/li>\n\t<li>Dell CloudBoost Virtual Appliance\u00a0\u2013 versions prior to 19.13.0.2<\/li>\n\t<li>Dell CyberSense\u00a0\u2013 versions prior to 8.15<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 versions 17.0.2 and 8.0.26<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 versions prior to 19.13.0.2<\/li>\n\t<li>Dell PowerEdge T40\u00a0\u2013 versions prior to 1.22.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-791","alert_type":396,"serial_number":"AV25-791","subject":"other","moderation_state":"published","external_url":null},{"nid":7052,"title":"HPE security advisory (AV25-794)","uuid":"8c218c9c-f8e8-4e33-a037-d853ce573986","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T16:41:23Z","date_created":"2025-12-01T16:35:04Z","summary":null,"body":["<article data-history-node-id=\"7052\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-794\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-794<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 1, 2025<\/p>\n\n<p>On November 30, 2025, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Superdome Flex 280 Server\u00a0\u2013 versions prior to 2.05.12<\/li>\n\t<li>HPE Compute Scale-up Server 3200\u00a0\u2013 versions prior to 1.60.88<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US&amp;archive=false#sort=%40hpescuniversaldate%20descending&amp;layout=table&amp;numberOfResults=25&amp;f:@kmdoclanguagecode=[cv1871440]&amp;hpe=1\">HPESBHF04944 rev.1\u00a0- HPE Superdome Flex 280 and Compute Scale-up Server 3200 Platform Servers<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-794","alert_type":396,"serial_number":"AV25-794","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7053,"title":"Red Hat security advisory (AV25-795)","uuid":"3819b596-3701-4144-ad1e-aa5fef7e9fc1","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T18:27:35Z","date_created":"2025-12-01T18:18:53Z","summary":null,"body":["<article data-history-node-id=\"7053\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-795\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-795<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 1, 2025<\/p>\n\n<p>Between November 24 and 30, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-795","alert_type":396,"serial_number":"AV25-795","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7054,"title":"VMware security advisory (AV25-796)","uuid":"5c74b688-78d3-4c99-8072-59dab39385b4","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T18:43:36Z","date_created":"2025-12-01T18:34:36Z","summary":null,"body":["<article data-history-node-id=\"7054\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-796\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-796<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 1, 2025<\/p>\n\n<p>Between November 30 and December 1, 2025, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<ul><li>Foundation Core for VMware Tanzu Platform\u00a0\u2013 versions prior to 3.1.5-build.398<\/li>\n\t<li>Foundation Core for VMware Tanzu Platform\u00a0\u2013 versions prior to 3.2.1-build.271<\/li>\n\t<li>Stemcells (Ubuntu Jammy)\u00a0\u2013 versions prior to 1.954.x<\/li>\n\t<li>Stemcells (Ubuntu Noble)\u00a0\u2013 versions prior to 1.134.x<\/li>\n\t<li>Tanzu Hub\u00a0\u2013 versions prior to 10.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-796","alert_type":396,"serial_number":"AV25-796","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7055,"title":"Qualcomm security advisory \u2013 December 2025 monthly rollup (AV25-797)","uuid":"2594e3a9-eb16-4ec8-97d7-25429aeae095","banner":null,"lang":"en","date_modified":"2025-12-01","date_modified_ts":"2025-12-01T20:23:41Z","date_created":"2025-12-01T20:18:51Z","summary":null,"body":["<article data-history-node-id=\"7055\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-december-2025-monthly-rollup-av25-797\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-797<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 1, 2025<\/p>\n\n<p>On December 1, 2025, Qualcomm published a security bulletin to address critical vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>Qualcomm has stated that CVE-2025-47372 is rated critical.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/december-2025-bulletin.html\">Qualcomm Security Bulletin \u2013 December<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-december-2025-monthly-rollup-av25-797","alert_type":396,"serial_number":"AV25-797","subject":"other","moderation_state":"published","external_url":null},{"nid":7056,"title":"OpenVPN security advisory (AV25-798)","uuid":"aaae0a97-651d-4e72-bef1-e306384f67a7","banner":null,"lang":"en","date_modified":"2025-12-02","date_modified_ts":"2025-12-02T13:33:12Z","date_created":"2025-12-02T13:24:39Z","summary":null,"body":["<article data-history-node-id=\"7056\" about=\"\/en\/alerts-advisories\/openvpn-security-advisory-av25-798\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-798<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 2, 2025<\/p>\n\n<p>On November 18, 2025, OpenVPN published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenVPN\u00a0\u2013 versions 2.7_alpha1 to 2.7_rc1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.openvpn.net\/Security Announcements\/CVE-2025-12106#cve-2025-12106-ipv6-address-parsing-fix-buffer-overread-on-invalid-input\">CVE-2025-12106\u00a0- IPv6 address parsing: fix buffer overread on invalid input<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mail-archive.com\/openvpn-announce@lists.sourceforge.net\/msg00152.html\">[Openvpn-announce] OpenVPN 2.7_rc2 released<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openvpn-security-advisory-av25-798","alert_type":396,"serial_number":"AV25-798","subject":"other","moderation_state":"published","external_url":null},{"nid":7060,"title":"Android security advisory \u2013 December 2025 monthly rollup (AV25-799)","uuid":"14db0626-fc7b-4a83-be71-cbf446a55875","banner":null,"lang":"en","date_modified":"2025-12-02","date_modified_ts":"2025-12-02T16:10:29Z","date_created":"2025-12-02T16:02:38Z","summary":null,"body":["<article data-history-node-id=\"7060\" about=\"\/en\/alerts-advisories\/android-security-advisory-december-2025-monthly-rollup-av25-799\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-799<br \/><strong>Date: <\/strong>December\u00a02, 2025<\/p>\n\n<p>On December\u00a01, 2025, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>On December\u00a02, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-48572 and CVE-2025-48633 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-12-01\">Android Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/12\/02\/cisa-adds-two-known-exploited-vulnerabilities-catalog\">Known Exploit Vulnerability Catalog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-december-2025-monthly-rollup-av25-799","alert_type":396,"serial_number":"AV25-799","subject":"android","moderation_state":"published","external_url":null},{"nid":7061,"title":"Apache Struts security advisory (AV25-800)","uuid":"62335ca3-6462-4fd3-b6b2-58aade59cd00","banner":null,"lang":"en","date_modified":"2025-12-02","date_modified_ts":"2025-12-02T18:31:22Z","date_created":"2025-12-02T18:23:14Z","summary":null,"body":["<article data-history-node-id=\"7061\" about=\"\/en\/alerts-advisories\/apache-struts-security-advisory-av25-800\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-800<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 2, 2025<\/p>\n\n<p>On November 11, 2025, Apache published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Apache Struts\u00a0\u2013 versions Struts 2.0.0 to Struts 2.3.37 (EOL)<\/li>\n\t<li>Apache Struts\u00a0\u2013 versions Struts 2.5.0 to Struts 2.5.33 (EOL)<\/li>\n\t<li>Apache Struts\u00a0\u2013 versions Struts 6.0.0 to Struts 6.7.0<\/li>\n\t<li>Apache Struts\u00a0\u2013 versions Struts 7.0.0 to Struts 7.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-068\">Apache Struts Security Advisory\u00a0- S2-068<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-struts-security-advisory-av25-800","alert_type":396,"serial_number":"AV25-800","subject":"other","moderation_state":"published","external_url":null},{"nid":7062,"title":"HPE security advisory (AV25-801)","uuid":"1d4aafe4-0765-4090-89a4-775b69024852","banner":null,"lang":"en","date_modified":"2025-12-02","date_modified_ts":"2025-12-02T20:18:43Z","date_created":"2025-12-02T20:12:59Z","summary":null,"body":["<article data-history-node-id=\"7062\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-801\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-801<br \/><strong>Date: <\/strong>December\u00a02, 2025<\/p>\n\n<p>On December\u00a02, 2025, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE TeMIP\u00a0\u2013 version 8.5.0<\/li>\n\t<li>HPE Telco Unified OSS Console\u00a0\u2013 versions prior to v3.1.17<\/li>\n\t<li>HPE Telco Network Function Virtual Orchestrator\u00a0\u2013 versions v7.4.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04976en_us&amp;docLocale=en_US#hpesbnw04976-rev-1-hpe-virtualized-telecommunicati-0\">HPESBNW04976 rev.1\u00a0- HPE Virtualized Telecommunication Management Information Platform (vTeMIP), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04974en_us&amp;docLocale=en_US#hpesbnw04974-rev-1-hpe-unified-oss-console-assuran-0\">HPESBNW04974 rev.1\u00a0- HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04972en_us&amp;docLocale=en_US#hpesbnw04972-rev-1-hpe-telco-network-function-virt-0\">HPESBNW04972 Rev. 1\u00a0- HPE Telco Network Function Virtual Orchestrator, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-801","alert_type":396,"serial_number":"AV25-801","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7064,"title":"GitHub security advisory (AV25-803)","uuid":"18ad9f64-e011-4935-80c6-0176787dc9f2","banner":null,"lang":"en","date_modified":"2025-12-03","date_modified_ts":"2025-12-03T15:27:08Z","date_created":"2025-12-03T15:16:11Z","summary":null,"body":["<article data-history-node-id=\"7064\" about=\"\/en\/alerts-advisories\/github-security-advisory-av25-803\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-803<br \/><strong>Date: <\/strong>December\u00a03, 2025<\/p>\n\n<p>On December\u00a02, 2025, GitHub published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 version 3.19.0-rc.1<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.2<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.8<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.11<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.15.x prior to 3.15.15<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.0-rc.1<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.2<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.8<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.11<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes\">Enterprise Server 3.15.15<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">Enterprise Server 3.14.20<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av25-803","alert_type":396,"serial_number":"AV25-803","subject":"other","moderation_state":"published","external_url":null},{"nid":7063,"title":"Google Chrome security advisory (AV25-802)","uuid":"5116f24c-d2ac-4637-b438-381a510f1227","banner":null,"lang":"en","date_modified":"2025-12-03","date_modified_ts":"2025-12-03T15:21:01Z","date_created":"2025-12-03T15:16:11Z","summary":null,"body":["<article data-history-node-id=\"7063\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-802\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-802<br \/><strong>Date: <\/strong>December\u00a03, 2025<\/p>\n\n<p>On December\u00a02, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 143.0.7499.40\/41 (Windows\/Mac) and 143.0.7499.40 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/12\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-802","alert_type":396,"serial_number":"AV25-802","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7068,"title":"Splunk security advisory (AV25-805)","uuid":"162eafaa-0816-4bec-b490-d891bcb408e7","banner":null,"lang":"en","date_modified":"2025-12-03","date_modified_ts":"2025-12-03T20:24:25Z","date_created":"2025-12-03T20:15:36Z","summary":null,"body":["<article data-history-node-id=\"7068\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av25-805\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-805<br \/><strong>Date: <\/strong>December\u00a03, 2025<\/p>\n\n<p>On December\u00a03, 2025, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk Enterprise\u00a0\u2013 multiple versions<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>Splunk Secure Gateway\u00a0\u2013 multiple versions<\/li>\n\t<li>Splunk MCP Server\u00a0\u2013 versions prior to 0.2.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av25-805","alert_type":396,"serial_number":"AV25-805","subject":"other","moderation_state":"published","external_url":null},{"nid":7067,"title":"React security advisory (AV25-804) \u2013 Update 1","uuid":"3b8d6e15-6f27-4346-9bbd-badcf951a8b8","banner":null,"lang":"en","date_modified":"2025-12-05","date_modified_ts":"2025-12-05T16:58:47Z","date_created":"2025-12-03T20:15:36Z","summary":null,"body":["<article data-history-node-id=\"7067\" about=\"\/en\/alerts-advisories\/react-security-advisories-av25-804\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-804<br \/><strong>Date: <\/strong>December\u00a03, 2025<br \/><strong>Updated: <\/strong>December\u00a05, 2025<\/p>\n\n<p>On December\u00a03, 2025, React Foundation published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>CVE-2025-55182 affecting:\n\t<ul><li>React-server-dom-webpack\u00a0\u2013 versions 19.0.0, 19.1.0, 19.1.1 and 19.2.0<\/li>\n\t\t<li>React-server-dom-parcel\u00a0\u2013 versions 19.0.0, 19.1.0, 19.1.1 and 19.2.0<\/li>\n\t\t<li>React-server-dom-turbopack\u00a0\u2013 versions 19.0.0, 19.1.0, 19.1.1 and 19.2.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Libraries and frameworks bundling react-server implementations are likely to be affected. Common examples include:<\/p>\n\n<ul><li>Next.js<\/li>\n\t<li>Vite RSC plugin<\/li>\n\t<li>Parcel RSC plugin<\/li>\n\t<li>React Router RSC preview<\/li>\n\t<li>RedwoodSDK<\/li>\n\t<li>Waku<\/li>\n<\/ul><p>No proof of exploitation has been recorded yet but multiple Proofs of Concept (PoC) have been released. Due to the CVSS score of 10.0 rating and network accessibility, this vulnerability must be treated as easily exploitable, and mitigations should be applied as soon as possible.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On December\u00a04, 2025, open-source reporting indicates that active exploitation is being observed in the wild.<\/p>\n\n<p>On December\u00a05, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-55182 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/react.dev\/blog\/2025\/12\/03\/critical-security-vulnerability-in-react-server-components\">Critical Security Vulnerability in React Server Components<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/12\/05\/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Adds One Known Exploited Vulnerability to Catalog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/react-security-advisories-av25-804","alert_type":396,"serial_number":"AV25-804","subject":"other","moderation_state":"published","external_url":null},{"nid":7069,"title":"Drupal security advisory (AV25-806)","uuid":"f7f87368-b6dc-489d-8b5e-c50cb6b7a339","banner":null,"lang":"en","date_modified":"2025-12-04","date_modified_ts":"2025-12-04T13:45:26Z","date_created":"2025-12-04T13:40:41Z","summary":null,"body":["<article data-history-node-id=\"7069\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-806\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-806<br \/><strong>Date: <\/strong>December\u00a04, 2025<\/p>\n\n<p>On December\u00a03, 2025, Drupal published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Mini site\u00a0\u2013 versions prior to 3.0.2<\/li>\n\t<li>CKEditor 5 Premium Features\u00a0\u2013 multiple versions<\/li>\n\t<li>AI (Artificial Intelligence)\u00a0\u2013 multiple versions<\/li>\n\t<li>Login Time Restriction\u00a0\u2013 versions prior to 1.0.3<\/li>\n\t<li>Tagify\u00a0\u2013 versions prior to 1.2.44<\/li>\n\t<li>Next.js\u00a0\u2013 versions prior to 1.6.4, version 2.0.0 to version prior to 2.0.1<\/li>\n\t<li>Entity Share\u00a0\u2013 versions prior to 3.x-3.13, versions prior to 3.13.0<\/li>\n\t<li>Disable Login Page\u00a0\u2013 versions prior to 1.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-806","alert_type":396,"serial_number":"AV25-806","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7070,"title":"HPE security advisory (AV25-807)","uuid":"90ce408d-567d-40d6-875d-4a6923ef1152","banner":null,"lang":"en","date_modified":"2025-12-04","date_modified_ts":"2025-12-04T13:54:05Z","date_created":"2025-12-04T13:40:42Z","summary":null,"body":["<article data-history-node-id=\"7070\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-807\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-807<br \/><strong>Date: <\/strong>December\u00a04, 2025<\/p>\n\n<p>On December\u00a04, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HP-UX OpenSSL Software\u00a0\u2013 versions prior to A.03.00.17.001<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbux04977en_us&amp;docLocale=en_US#hpesbux04977-rev-1-hp-ux-using-openssl-memory-corr-0\">HPESBUX04977 rev.1\u00a0- HP-UX Using OpenSSL, Memory Corruption and Remote Code Execution Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-807","alert_type":396,"serial_number":"AV25-807","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7071,"title":"AL25-018 - Vulnerability affecting React Server Components - CVE-2025-55182","uuid":"5dce9753-fe78-4124-8d0f-6cf041f62f58","banner":null,"lang":"en","date_modified":"2025-12-04","date_modified_ts":"2025-12-04T16:50:47Z","date_created":"2025-12-04T16:22:46Z","summary":null,"body":["<article data-history-node-id=\"7071\" about=\"\/en\/alerts-advisories\/al25-018-vulnerability-affecting-react-server-components-cve-2025-55182\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-018<br \/><strong>Date:<\/strong> December\u00a04, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On December\u00a03, 2025, the Cyber Centre became aware of a critical pre-authentication remote code execution (RCE) vulnerability<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, tracked as CVE-2025-55182<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>, in the React Server Components (RSC) \"Flight\" protocol affecting React 19 ecosystems and frameworks that implement it, most notably Next.js. This vulnerability stems from insecure deserialization, exploiting a flaw in how React decodes payloads from <abbr title=\"Hypertext Transfer Protocol\">HTTP<\/abbr> requests and sends them to React Server Function endpoints, potentially allowing unauthenticated <abbr title=\"remote code execution\">RCE<\/abbr> on the server.<\/p>\n\n<p>The Cyber Centre has observed open-source reporting indicating that multiple Proofs of Concept (PoC) are available and that the vulnerability can easily be exploited in the wild<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>On December 3, 2025, and in response to this vulnerability, the Cyber Centre released AV25-804<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations patch their React instances to the following versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Component<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>React-server-dom-webpack<\/td>\n\t\t\t<td>19.0.0, 19.1.0, 19.1.1 and 19.2.0<\/td>\n\t\t\t<td>19.0.1, 19.1.2 and 19.2.1<\/td>\n\t\t<\/tr><tr><td>React-server-dom-parcel<\/td>\n\t\t\t<td>19.0.0, 19.1.0, 19.1.1 and 19.2.0<\/td>\n\t\t\t<td>19.0.1, 19.1.2 and 19.2.1<\/td>\n\t\t<\/tr><tr><td>React-server-dom-turbopack<\/td>\n\t\t\t<td>19.0.0, 19.1.0, 19.1.1 and 19.2.0<\/td>\n\t\t\t<td>19.0.1, 19.1.2 and 19.2.1<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>Libraries and frameworks that bundle react-server implementations are likely to be affected. Common examples include:<\/p>\n\n<ul><li>Next.js (versions 15.x, 16.x and 14.3.0-canary.77 and later versions)\n\t<ul><li>CVE-2025-66478<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> has been declared as a duplicate of CVE-2025-55182<\/li>\n\t<\/ul><\/li>\n\t<li>Vite <abbr title=\"React Server Components\">RSC<\/abbr> plugin<\/li>\n\t<li>Parcel <abbr title=\"React Server Components\">RSC<\/abbr> plugin<\/li>\n\t<li>React Router <abbr title=\"React Server Components\">RSC<\/abbr> preview<\/li>\n\t<li>RedwoodSDK<\/li>\n\t<li>Waku<\/li>\n<\/ul><p>It is imperative that organizations identify and prioritize the patching of vulnerable systems promptly, following vendor provided guidance<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p><strong>If immediate patching isn't possible, reduce exposure by:<\/strong><\/p>\n\n<ol><li><strong>Enabling <abbr title=\"Web Application Firewall\">WAF<\/abbr>:<\/strong> Configure your Web Application Firewall to block malicious or malformed requests targeting React Server Function endpoints.<\/li>\n\t<li><strong>Restricting Access:<\/strong> Use network <abbr title=\"Access Control Lists\">ACLs<\/abbr> or firewalls to limit access to trusted <abbr title=\"Internet protocols\">IPs<\/abbr> or networks.<\/li>\n\t<li><strong>Disabling <abbr title=\"React Server Components\">RSC<\/abbr>:<\/strong> Temporarily remove Server Components and Server Functions; applications without <abbr title=\"React Server Components\">RSC<\/abbr> are not affected by this vulnerability.<\/li>\n<\/ol><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<ul><li>Patching operating systems and applications<\/li>\n\t<li>Segment and separate information<\/li>\n\t<li>Isolating Web-Facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/react.dev\/blog\/2025\/12\/03\/critical-security-vulnerability-in-react-server-components\">React Foundation Advisories<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-55182\">NVD\u00a0- CVE-2025-55182<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.wiz.io\/blog\/critical-vulnerability-in-react-cve-2025-55182\">Critical Vulnerabilities in React and Next.js: everything you need to know<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/react-security-advisories-av25-804\">React security advisory (AV25-804)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-66478\">NVD\u00a0- CVE-2025-66478<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-018-vulnerability-affecting-react-server-components-cve-2025-55182","alert_type":397,"serial_number":"AL25-018","subject":"other","moderation_state":"published","external_url":null},{"nid":7072,"title":"Samsung mobile security advisory (AV25-808)","uuid":"4ae51efa-8253-4324-ba91-e1686f07080c","banner":null,"lang":"en","date_modified":"2025-12-04","date_modified_ts":"2025-12-04T20:53:07Z","date_created":"2025-12-04T20:46:10Z","summary":null,"body":["<article data-history-node-id=\"7072\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av25-808\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-808<br \/><strong>Date: <\/strong>December\u00a04, 2025<\/p>\n\n<p>On December\u00a04, 2025, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices\u00a0\u2013 versions prior to SMR-DEC-2025<\/li>\n<\/ul><p>The most recent security update resolves multiple identified vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2025&amp;month=12\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av25-808","alert_type":396,"serial_number":"AV25-808","subject":"other","moderation_state":"published","external_url":null},{"nid":7073,"title":"HPE security advisory (AV25-809)","uuid":"b34301ef-8b2c-49f6-ae51-7995b16f4774","banner":null,"lang":"en","date_modified":"2025-12-05","date_modified_ts":"2025-12-05T14:24:16Z","date_created":"2025-12-05T14:10:02Z","summary":null,"body":["<article data-history-node-id=\"7073\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-809\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-809<br \/><strong>Date: <\/strong>December\u00a05, 2025<\/p>\n\n<p>On December\u00a05, 2025, HPE published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Cray XD670\u00a0\u2013 versions prior to v2.06<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04979en_us&amp;docLocale=en_US#hpesbcr04979-rev-1-hpe-cray-xd670-server-using-cer-0\">HPESBCR04979 rev.1\u00a0- HPE Cray XD670 Server Using Certain Intel Processors, INTEL-SA-01280, 2025.3 IPU, Intel Chipset Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04980en_us&amp;docLocale=en_US#hpesbcr04980-rev-1-hpe-cray-xd670-server-using-cer-0\">HPESBCR04980 rev.1\u00a0- HPE Cray XD670 Server Using Certain Intel Processors, INTEL-SA-01312, Intel TDX Module Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04981en_us&amp;docLocale=en_US#hpesbcr04981-rev-1-hpe-cray-xd670-server-using-cer-0\">HPESBCR04981 rev.1\u00a0- HPE Cray XD670 Server Using Certain Intel Processors, INTEL-SA-01313, 2025.3 IPU, Intel Xeon Processor Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr04982en_us&amp;docLocale=en_US#hpesbcr04982-rev-1-hpe-cray-xd670-server-using-uef-0\">HPESBCR04982 rev.1\u00a0- HPE Cray XD670 Server Using UEFI, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-809","alert_type":396,"serial_number":"AV25-809","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7074,"title":"Microsoft Edge security advisory (AV25-810)","uuid":"629544d6-5b59-4ec1-93e6-d94d741475eb","banner":null,"lang":"en","date_modified":"2025-12-05","date_modified_ts":"2025-12-05T14:28:20Z","date_created":"2025-12-05T14:10:03Z","summary":null,"body":["<article data-history-node-id=\"7074\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-810\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-810<br \/><strong>Date: <\/strong>December\u00a05, 2025<\/p>\n\n<p>On December\u00a04, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 143.0.3650.66<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-4-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-810","alert_type":396,"serial_number":"AV25-810","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7075,"title":"IBM security advisory (AV25-811)","uuid":"fa380502-86c0-429d-844d-09704d19cf64","banner":null,"lang":"en","date_modified":"2025-12-08","date_modified_ts":"2025-12-08T14:38:52Z","date_created":"2025-12-08T14:34:38Z","summary":null,"body":["<article data-history-node-id=\"7075\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-811\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-811<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 8, 2025<\/p>\n\n<p>Between December 1 and 7, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM AIX \u2013 versions 7.2 and 7.3<\/li>\n\t<li>IBM Aspera Shares \u2013 versions 1.9.9 to 1.10.1<\/li>\n\t<li>IBM Business Automation Workflow \u2013 version 24.0.1<\/li>\n\t<li>IBM Cloud Pak System \u2013 version 2.3.6.0<\/li>\n\t<li>IBM Controller \u2013 versions 11.1.0 to 11.1.1<\/li>\n\t<li>IBM Guardium Data Security Center \u2013 version 3.8.5<\/li>\n\t<li>IBM Jazz Reporting Service \u2013 multiple versions<\/li>\n\t<li>IBM Maximo Application Suite Monitor Component \u2013 multiple versions<\/li>\n\t<li>IBM Process Mining \u2013 version 2.0.3 IF001 and 2.0.3<\/li>\n\t<li>IBM Use Case Manager App \u2013 versions 1.0.0 to 4.0.0<\/li>\n\t<li>IBM VIOS \u2013 versions 3.1 and 4.1<\/li>\n\t<li>IBM Watson Studio on Cloud Pak for Data \u2013 versions 4.0.0 to 4.8.9 and versions 5.0.0 to 5.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/ \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-811","alert_type":396,"serial_number":"AV25-811","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7076,"title":"Dell security advisory (AV25-812)","uuid":"87a9dc5d-6484-42b2-af81-896a6f67f1fc","banner":null,"lang":"en","date_modified":"2025-12-08","date_modified_ts":"2025-12-08T14:47:00Z","date_created":"2025-12-08T14:41:18Z","summary":null,"body":["<article data-history-node-id=\"7076\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-812\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-812<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 8, 2025<\/p>\n\n<p>Between December 1 and 7, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Microsoft Azure \u2013 versions prior to 01.06.02.00<\/li>\n\t<li>Dell APEX Cloud Platform for Red Hat OpenShift \u2013 versions prior to 03.02.06.00<\/li>\n\t<li>Dell BSAFE SSL-J \u2013 versions prior to 7.4<\/li>\n\t<li>Dell NetWorker \u2013 versions 19.13 to 19.13.0.1<\/li>\n\t<li>Dell NetWorker \u2013 versions prior to 19.12.0.4<\/li>\n\t<li>Dell Networking OS10 \u2013 versions prior to 10.5.5.16<\/li>\n\t<li>Dell Networking OS10 \u2013 versions prior to 10.5.6.11<\/li>\n\t<li>Dell PowerEdge XE9680\/XE7740 \u2013 versions prior to 1.21.0<\/li>\n\t<li>Dell PowerFlex Custom Node \u2013 multiple versions and models<\/li>\n\t<li>Dell PowerStore T Security \u2013 multiple versions and models<\/li>\n\t<li>Dell VxFlex Ready Node \u2013 versions prior to 2.24.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-812","alert_type":396,"serial_number":"AV25-812","subject":"dell","moderation_state":"published","external_url":null},{"nid":7077,"title":"Ubuntu security advisory (AV25-813)","uuid":"d9a77f68-9bab-4b2f-bd5e-34417db89170","banner":null,"lang":"en","date_modified":"2025-12-08","date_modified_ts":"2025-12-08T14:54:09Z","date_created":"2025-12-08T14:51:28Z","summary":null,"body":["<article data-history-node-id=\"7077\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-813\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-813<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 8, 2025<\/p>\n\n<p>Between December 1 and 7, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-813","alert_type":396,"serial_number":"AV25-813","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7078,"title":"Red Hat security advisory (AV25-814)","uuid":"3fdf7663-ece1-4c88-81c6-7f8372b8d567","banner":null,"lang":"en","date_modified":"2025-12-08","date_modified_ts":"2025-12-08T18:42:29Z","date_created":"2025-12-08T18:31:12Z","summary":null,"body":["<article data-history-node-id=\"7078\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-814\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-814<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 8, 2025<\/p>\n\n<p>Between December 1 and 7, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-814","alert_type":396,"serial_number":"AV25-814","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7079,"title":"[Control systems] CISA ICS security advisories (AV25\u2013815)","uuid":"e6db4026-eb66-4af3-a079-ee239174450c","banner":null,"lang":"en","date_modified":"2025-12-08","date_modified_ts":"2025-12-08T19:06:41Z","date_created":"2025-12-08T19:02:35Z","summary":null,"body":["<article data-history-node-id=\"7079\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-815\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-815<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 8, 2025<\/p>\n\n<p>Between December 1 and 7, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Advantech iView \u2013 version 5.7.05.7057<\/li>\n\t<li>Industrial Video &amp; Control Longwatch \u2013 versions 6.309 to 6.334<\/li>\n\t<li>Iskra iHUB and iHUB Lite \u2013 all versions<\/li>\n\t<li>Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace \u2013 version 2025.1.2 and prior<\/li>\n\t<li>Johnson Controls iSTAR (multiple models) \u2013 versions prior to TLS 1.2<\/li>\n\t<li>MAXHUB Pivot client application \u2013 versions prior to v1.36.2<\/li>\n\t<li>Mitsubishi Electric GX Works2 \u2013 all versions<\/li>\n\t<li>SolisCloud Monitoring Platform (Cloud API &amp; Device Control API) \u2013 versions API v1 and API v2<\/li>\n\t<li>Sunbird DCIM dcTrack and Power IQ \u2013 versions v9.2.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories  \">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-815","alert_type":398,"serial_number":"AV25-815","subject":"other","moderation_state":"published","external_url":null},{"nid":7080,"title":" WatchGuard security advisory (AV25-816)","uuid":"c3f91742-ce6d-40a5-a28a-efda85818763","banner":null,"lang":"en","date_modified":"2025-12-08","date_modified_ts":"2025-12-08T19:16:50Z","date_created":"2025-12-08T19:14:15Z","summary":null,"body":["<article data-history-node-id=\"7080\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av25-816\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-816<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 8, 2025<\/p>\n\n<p>On December 4, 2025, WatchGuard published security advisories to address vulnerability in the following product:<\/p>\n\n<ul><li>Fireware OS 2025.1 \u2013 versions prior to 2025.1.3<\/li>\n\t<li>Fireware OS 12.x \u2013 versions prior to 12.11.5<\/li>\n\t<li>Fireware OS 12.5.x \u2013 versions prior to 12.5.14<\/li>\n\t<li>Fireware OS 11.x \u2013 end of life<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av25-816","alert_type":396,"serial_number":"AV25-816","subject":"other","moderation_state":"published","external_url":null},{"nid":7081,"title":"[Control systems] Siemens security advisory (AV25-817) ","uuid":"2d0854b7-6dcf-41cf-bf2b-2d624e5e11df","banner":null,"lang":"en","date_modified":"2025-12-09","date_modified_ts":"2025-12-09T20:28:33Z","date_created":"2025-12-09T20:24:06Z","summary":null,"body":["<article data-history-node-id=\"7081\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-817\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-817<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 9, 2025<\/p>\n\n<p>On December 9, 2025, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Building X - Security Manager Edge Controller (ACC-AP) \u2013 all versions<\/li>\n\t<li>COMOS V10.6 \u2013 all versions<\/li>\n\t<li>COMOS \u2013 multiple versions<\/li>\n\t<li>Energy Services G5DFR \u2013 versions prior to G5DFR to V1.2.3.13<\/li>\n\t<li>Gridscale X Prepay \u2013 versions prior to V4.2.1<\/li>\n\t<li>Interniche IP-Stack - multiple versions and platforms<\/li>\n\t<li>JT Bi-Directional Translator for STEP \u2013 all versions<\/li>\n\t<li>NX V2412 \u2013 versions prior to V2412.8700<\/li>\n\t<li>NX V2412 \u2013 versions prior to V2506.6000<\/li>\n\t<li>NX V2506 \u2013 versions prior to V2506.6000<\/li>\n\t<li>RUGGEDCOM ROS V5.X family \u2013 versions prior to V5.10.1<\/li>\n\t<li>RUGGEDCOM ROX II family \u2013 versions prior to V2.17.0<\/li>\n\t<li>SICAM T \u2013 versions prior to V3.0<\/li>\n\t<li>SIMATIC CN 4100 \u2013 versions prior to V4.0.1<\/li>\n\t<li>SINEC Security Monitor \u2013 versions prior to V4.10.0<\/li>\n\t<li>SINEMA Remote Connect Server \u2013 versions prior to V3.2 SP4<\/li>\n\t<li>Simcenter 3D \u2013 versions prior to V2506.6000<\/li>\n\t<li>Simcenter Femap \u2013 versions prior to V2506.0002<\/li>\n\t<li>Simcenter Studio \u2013 all versions<\/li>\n\t<li>Simcenter System Architect \u2013 all versions<\/li>\n\t<li>Solid Edge SE2025 \u2013 versions prior to V225.0 Update 10<\/li>\n\t<li>Solid Edge SE2026 \u2013 versions prior to V226.0 Update 1<\/li>\n\t<li>Tecnomatix Plant Simulation \u2013 versions prior to V2504.0007<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av25-817","alert_type":398,"serial_number":"AV25-817","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7082,"title":"SAP security advisory \u2013 December 2025 monthly rollup (AV25-818)","uuid":"4c80fc9f-1661-4a7f-ab53-2f114c3ca775","banner":null,"lang":"en","date_modified":"2025-12-09","date_modified_ts":"2025-12-09T20:36:13Z","date_created":"2025-12-09T20:29:44Z","summary":null,"body":["<article data-history-node-id=\"7082\" about=\"\/en\/alerts-advisories\/sap-security-advisory-december-2025-monthly-rollup-av25-818\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-818<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 9, 2025<\/p>\n\n<p>On December 9, 2025, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Solution Manager \u2013 version ST 720<\/li>\n\t<li>SAP Commerce Cloud \u2013 versions HY_COM 2205, COM_CLOUD 2211 and COM_CLOUD 2211-JDK21<\/li>\n\t<li>SAP jConnect - SDK for ASE \u2013 versions SYBASE_SOFTWARE_DEVELOPER_KIT 16.0.4 and 16.1<\/li>\n\t<li>SAP Web Dispatcher and Internet Communication Manager (ICM) \u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, WEBDISP 7.22_EXT, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93 and 9.16<\/li>\n\t<li>SAP NetWeaver (remote service for Xcelsius) \u2013 versions BI-BASE-E 7.50, BI-BASE-B 7.50, BI-IBC 7.50, BI-BASE-S 7.50 and BIWEBAPP 7.50<\/li>\n\t<li>SAP Business Objects \u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP Web Dispatcher, Internet Communication Manager and SAP Content Server \u2013 versions KRNL64UC 7.53, WEBDISP 7.53, 7.54, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, CONTSERV 7.53, 7.54, KERNEL 7.53 and 7.54<\/li>\n\t<li>SAP S\/4 HANA Private Cloud (Financials General Ledger) \u2013 versions S4CORE 104, 105, 106, 107, 108 and 109<\/li>\n\t<li>SAP NetWeaver Internet Communication Framework \u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757 and SAP_BASIS 758<\/li>\n\t<li>Application Server ABAP \u2013 versions KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.16 and 9.17<\/li>\n\t<li>SAP NetWeaver Enterprise Portal \u2013 version EP-RUNTIME 7.50<\/li>\n\t<li>SAPUI5 framework (Markdown-it component) \u2013 versions SAP_UI 755, 756, 757 and 758<\/li>\n\t<li>SAP Enterprise Search for ABAP \u2013 versions SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 and SAP_BASIS 816<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform \u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/december-2025.html \">SAP Security Patch Day - December 2025<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-december-2025-monthly-rollup-av25-818","alert_type":396,"serial_number":"AV25-818","subject":"sap","moderation_state":"published","external_url":null},{"nid":7083,"title":"Mozilla security advisory (AV25-819)","uuid":"645ce474-b525-487d-8cc7-6c08fd31867a","banner":null,"lang":"en","date_modified":"2025-12-09","date_modified_ts":"2025-12-09T20:40:37Z","date_created":"2025-12-09T20:37:26Z","summary":null,"body":["<article data-history-node-id=\"7083\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-819\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-819<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2025<\/p>\n\n<p>On December 9, 2025, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 146<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.31<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 140.6<\/li>\n\t<li>Thunderbird \u2013 versions prior to 146<\/li>\n\t<li>Thunderbird \u2013 versions prior to 140.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-819","alert_type":396,"serial_number":"AV25-819","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7084,"title":"VMware security advisory (AV25-820)","uuid":"7df3ccb1-66a9-4ca5-a8d1-1a017bb59798","banner":null,"lang":"en","date_modified":"2025-12-09","date_modified_ts":"2025-12-09T20:45:35Z","date_created":"2025-12-09T20:41:49Z","summary":null,"body":["<article data-history-node-id=\"7084\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-820\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-820<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 9, 2025<\/p>\n\n<p>On December 8, 2025, VMware published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>VMware Tanzu RabbitMQ on Kubernetes \u2013 versions prior to 4.1.6 and 4.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36589\">Product Release Advisory - VMware Tanzu RabbitMQ on Kubernetes 4.1.6<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36590\">Product Release Advisory - VMware Tanzu RabbitMQ on Kubernetes 4.2.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories - Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-820","alert_type":396,"serial_number":"AV25-820","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7085,"title":"Fortinet security advisory (AV25-821) \u2013 Update 1","uuid":"c515f25b-e95f-4716-b69a-35c5657c3d70","banner":null,"lang":"en","date_modified":"2025-12-16","date_modified_ts":"2025-12-16T19:31:35Z","date_created":"2025-12-09T20:49:39Z","summary":null,"body":["<article data-history-node-id=\"7085\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-821\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-821<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 9, 2025<br \/><strong>Updated: <\/strong>December 16, 2025<\/p>\n\n<p>On December 9, 2025, Fortinet published security advisories to address vulnerabilities in multiple products including two critical vulnerabilities (CVE-2025-59718, CVE-2025-59719):<\/p>\n\n<ul><li>FortiOS 7.6\u00a0\u2013 versions prior to 7.6.4<\/li>\n\t<li>FortiOS 7.4\u00a0\u2013 versions prior to 7.4.9<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 versions prior to 7.2.12<\/li>\n\t<li>FortiOS 7.0\u00a0\u2013 versions prior to 7.0.18<\/li>\n\t<li>FortiProxy 7.6\u00a0\u2013 versions prior to 7.6.4<\/li>\n\t<li>FortiProxy 7.4\u00a0\u2013 versions prior to 7.4.11<\/li>\n\t<li>FortiProxy 7.2\u00a0\u2013 versions prior to 7.2.15<\/li>\n\t<li>FortiProxy 7.0\u00a0\u2013 versions prior to 7.0.22<\/li>\n\t<li>FortiSwitchManager 7.2\u00a0\u2013 versions prior to 7.2.7<\/li>\n\t<li>FortiSwitchManager 7.0\u00a0\u2013 versions prior to 7.0.6<\/li>\n\t<li>FortiWeb 8.0\u00a0\u2013 versions prior to 8.0.1<\/li>\n\t<li>FortiWeb 7.6\u00a0\u2013 versions prior to 7.6.5<\/li>\n\t<li>FortiWeb 7.4\u00a0\u2013 versions prior to 7.4.10<\/li>\n<\/ul><p>The FortiCloud SSO Login Authentication feature must be enabled on the affected products for these vulnerabilities to be exploited.<\/p>\n\n<p><strong>Update 1<\/strong><\/p>\n\n<p>On December 16, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-59718 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>Open-source reporting indicates that CVE-2025-59718 is being exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-25-647\">Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=59718&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url=\">CISA KEV\u00a0: CVE-2025-59718<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av25-821","alert_type":396,"serial_number":"AV25-821","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7086,"title":"Microsoft security advisory \u2013 December 2025 monthly rollup (AV25-822)","uuid":"7f25db72-0cce-435d-829e-4962d0ea5c21","banner":null,"lang":"en","date_modified":"2025-12-09","date_modified_ts":"2025-12-09T21:00:57Z","date_created":"2025-12-09T20:55:35Z","summary":null,"body":["<article data-history-node-id=\"7086\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-december-2025-monthly-rollup-av25-822\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-822<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 9, 2025<\/p>\n\n<p>On December 9, 2025, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Azure App Gateway<\/li>\n\t<li>Azure Bastion Developer<\/li>\n\t<li>Azure Monitor<\/li>\n\t<li>Azure Monitor Control Service<\/li>\n\t<li>Dynamics 365 Field Service (online)<\/li>\n\t<li>Dynamics OmniChannel SDK Storage Containers<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft 365 Defender Portal<\/li>\n\t<li>Microsoft Configuration Manager 2403<\/li>\n\t<li>Microsoft Configuration Manager 2409<\/li>\n\t<li>Microsoft Configuration Manager 2503<\/li>\n\t<li>Microsoft Dynamics 365<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft SQL Server 2016<\/li>\n\t<li>Microsoft SQL Server 2017<\/li>\n\t<li>Microsoft SQL Server 2019<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Online<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Visual Studio 2022 version 17.14<\/li>\n\t<li>Microsoft Visual Studio Code CoPilot Chat Extension<\/li>\n\t<li>Nuance PowerScribe 360<\/li>\n\t<li>Nuance PowerScribe One<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>OneDrive for Android<\/li>\n\t<li>PowerScribe One version 2023.1 SP2 Patch 7<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 10 Version 1607<\/li>\n\t<li>Windows 10 Version 1809<\/li>\n\t<li>Windows 10 Version 21H2<\/li>\n\t<li>Windows 10 Version 22H2<\/li>\n\t<li>Windows 11 Version 22H2<\/li>\n\t<li>Windows 11 Version 23H2<\/li>\n\t<li>Windows 11 Version 24H2<\/li>\n\t<li>Windows 11 Version 25H2<\/li>\n\t<li>Windows Server 2008<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n\t<li>Windows Server 2025 (Server Core installation)<\/li>\n\t<li>Windows Subsystem for Linux GUI<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2025-62221 is being exploited.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2025-Dec\">December 2025 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-december-2025-monthly-rollup-av25-822","alert_type":396,"serial_number":"AV25-822","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7087,"title":"Adobe security advisory (AV25-823)","uuid":"075d74a4-e088-417f-b32b-e4aa2c22a1a1","banner":null,"lang":"en","date_modified":"2025-12-10","date_modified_ts":"2025-12-10T14:17:43Z","date_created":"2025-12-10T14:08:48Z","summary":null,"body":["<article data-history-node-id=\"7087\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av25-823\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-823<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 10, 2025<\/p>\n\n<p>On December 9, 2025, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ColdFusion 2025 \u2013 version Update 4 and prior<\/li>\n\t<li>ColdFusion 2023 \u2013 version Update 16 and prior<\/li>\n\t<li>ColdFusion 2021 \u2013 version Update 22 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM) \u2013 version AEM Cloud Service (CS)<\/li>\n\t<li>Adobe Experience Manager (AEM) \u2013 version 6.5 LTS, version 6.5.23 and prior<\/li>\n\t<li>Adobe DNG Software Development Kit (SDK) \u2013 version DNG SDK 1.7.0 and prior<\/li>\n\t<li>Acrobat DC \u2013 version 25.001.20982 and prior<\/li>\n\t<li>Acrobat Reader DC \u2013 version 25.001.20982 and prior<\/li>\n\t<li>Acrobat 2024 (Windows) \u2013 version 24.001.30264 and prior<\/li>\n\t<li>Acrobat 2024 (Mac) \u2013 version 24.001.30273 and prior<\/li>\n\t<li>Acrobat 2020 (Windows) \u2013 version 20.005.30793 and prior<\/li>\n\t<li>Acrobat 2020 (Mac) \u2013 version 20.005.30803 and prior<\/li>\n\t<li>Acrobat Reader 2020 (Windows) \u2013 version 20.005.30793 and prior<\/li>\n\t<li>Acrobat Reader 2020 (Mac) \u2013 version 20.005.30803 and prior<\/li>\n\t<li>Creative Cloud Desktop Application \u2013 version 6.4.0.361 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av25-823","alert_type":396,"serial_number":"AV25-823","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7088,"title":"Ivanti security advisory (AV25-824)","uuid":"b5afe230-f753-46a2-8dbf-ce6b22302538","banner":null,"lang":"en","date_modified":"2025-12-10","date_modified_ts":"2025-12-10T14:25:32Z","date_created":"2025-12-10T14:22:03Z","summary":null,"body":["<article data-history-node-id=\"7088\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av25-824\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-824<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 10, 2025<\/p>\n\n<p>On December 9, 2025, Ivanti published a security advisory to address vulnerabilities in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>Ivanti Endpoint Manager \u2013 version 2024 SU4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US\">Security Advisory EPM December 2025 for EPM 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av25-824","alert_type":396,"serial_number":"AV25-824","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7089,"title":"[Control systems] Schneider Electric security advisory (AV25-825) ","uuid":"4804bd56-453a-4f9e-a29b-7bfcc7072605","banner":null,"lang":"en","date_modified":"2025-12-10","date_modified_ts":"2025-12-10T16:33:11Z","date_created":"2025-12-10T16:24:24Z","summary":null,"body":["<article data-history-node-id=\"7089\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-825\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-825<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 10, 2025<\/p>\n\n<p>On December 9, 2025, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure\u2122 Foxboro DCS \u2013 version EcoStruxure\u2122 Foxboro DCS and prior<\/li>\n\t<li>V91 DCS Virtualization Server and H92 DCS Standard Workstation \u2013 version Intel Xeon W-2123 and prior<\/li>\n\t<li>EcoStruxure\u2122 Foxboro DCS Advisor services with Windows Server Update Services application running on MS Server 2016 \u2013 version Microsoft updates KB5066836<\/li>\n\t<li>EcoStruxure\u2122 Foxboro DCS Advisor services with Windows Server Update Services application running on MS Server 2022 \u2013 version Microsoft updates KB5066782<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-343-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-343-01.pdf\">EcoStruxure\u2122 Foxboro DCS (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2025-343-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2025-343-02.pdf\">EcoStruxure\u2122 Foxboro DCS Advisor (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av25-825","alert_type":398,"serial_number":"AV25-825","subject":"other","moderation_state":"published","external_url":null},{"nid":7090,"title":"Jenkins security advisory (AV25-826)","uuid":"c2cca2ef-3b91-48f7-8cb4-0ad807e5d99a","banner":null,"lang":"en","date_modified":"2025-12-10","date_modified_ts":"2025-12-10T18:49:20Z","date_created":"2025-12-10T18:46:09Z","summary":null,"body":["<article data-history-node-id=\"7090\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av25-826\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-826<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 10, 2025<\/p>\n\n<p>On December 10, 2025, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>BlazeMeter \u2013 version 4.27<\/li>\n\t<li>Coverage \u2013 version 2.3054.ve1ff7b_a_a_123b_ and prior<\/li>\n\t<li>Git client \u2013 version 6.4.0 and prior<\/li>\n\t<li>HashiCorp Vault \u2013 version 371.v884a_4dd60fb_6 and prior<\/li>\n\t<li>Redpen - Pipeline Reporter for Jira \u2013 version 1.054.v7b_9517b_6b_202 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2025-12-10\/\">Jenkins Security Advisory 2025-12-10<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av25-826","alert_type":396,"serial_number":"AV25-826","subject":"other","moderation_state":"published","external_url":null},{"nid":7091,"title":"GitLab security advisory (AV25-827)","uuid":"f3914dc8-0482-4de4-8ba1-6bc6d51bfd53","banner":null,"lang":"en","date_modified":"2025-12-11","date_modified_ts":"2025-12-11T15:11:06Z","date_created":"2025-12-11T15:07:21Z","summary":null,"body":["<article data-history-node-id=\"7091\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av25-827\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-827<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2025<\/p>\n\n<p>On December 10, 2025, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 18.6.2, 18.5.4 and 18.4.6<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 18.6.2, 18.5.4 and 18.4.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2025\/12\/10\/patch-release-gitlab-18-6-2-released\/\">GitLab Patch Release: 18.6.2, 18.5.4, 18.4.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av25-827","alert_type":396,"serial_number":"AV25-827","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7092,"title":"Drupal security advisory (AV25-828) ","uuid":"8a0bfea4-3874-41c1-a1e7-f727d8404363","banner":null,"lang":"en","date_modified":"2025-12-11","date_modified_ts":"2025-12-11T15:16:36Z","date_created":"2025-12-11T15:13:29Z","summary":null,"body":["<article data-history-node-id=\"7092\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-828\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-828<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2025<\/p>\n\n<p>On December 10, 2025, Drupal published security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Acquia Content Hub \u2013 versions 3.6.x prior to 3.6.4<\/li>\n\t<li>Acquia Content Hub \u2013 versions 3.7.x prior to 3.7.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-125\">Acquia Content Hub\u00a0- Moderately critical\u00a0- Cross-Site Request Forgery\u00a0- SA-CONTRIB-2025-125<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-828","alert_type":396,"serial_number":"AV25-828","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7093,"title":"Google Chrome security advisory (AV25-829)","uuid":"6b063fb2-4f67-4bcb-8ef2-ef82dfffab68","banner":null,"lang":"en","date_modified":"2025-12-11","date_modified_ts":"2025-12-11T15:21:14Z","date_created":"2025-12-11T15:18:27Z","summary":null,"body":["<article data-history-node-id=\"7093\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-829\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-829<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 11, 2025<\/p>\n\n<p>On December 10, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 143.0.7499.109\/.110 (Windows\/Mac) and 143.0.7499.109 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/12\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-829","alert_type":396,"serial_number":"AV25-829","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7094,"title":"Atlassian security advisory (AV25-830)","uuid":"e1bf9224-25e9-4a27-a4bb-32c7f419bdb4","banner":null,"lang":"en","date_modified":"2025-12-12","date_modified_ts":"2025-12-12T14:08:48Z","date_created":"2025-12-12T14:01:08Z","summary":null,"body":["<article data-history-node-id=\"7094\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av25-830\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-830<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 12, 2025<\/p>\n\n<p>On December 11, 2025, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Fisheye\/Crucible \u2013 versions 4.9.0 to 4.9.5, versions 4.8.14 to 4.8.16<\/li>\n\t<li>Jira Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-december-11-2025-1689616574.html\">Security Bulletin - December 11 2025<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av25-830","alert_type":396,"serial_number":"AV25-830","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":7095,"title":"FreePBX security advisory (AV25\u2013831) ","uuid":"9bda2ea1-cf87-4f1e-a76f-690527650968","banner":null,"lang":"en","date_modified":"2025-12-12","date_modified_ts":"2025-12-12T16:41:18Z","date_created":"2025-12-12T16:37:58Z","summary":null,"body":["<article data-history-node-id=\"7095\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av25-831\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--><\/p>\n\n<p><strong>Serial number: <\/strong>AV25-831<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 12, 2025<\/p>\n\n<p>On December 9, 2025, FreePBX published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>FreePBX Security-Reporting framework (FreePBX 16\/17) \u2013 versions 16.0.44 and prior<\/li>\n\t<li>FreePBX Security-Reporting framework (FreePBX 16\/17) \u2013 versions 17.0.23 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-9jvh-mv6x-w698\">Authenticated Activation of Webserver Authentication Method in Advanced Settings Allows Subsequent Unauthenticated Logins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av25-831","alert_type":396,"serial_number":"AV25-831","subject":"other","moderation_state":"published","external_url":null},{"nid":7096,"title":"AL25-019 - Vulnerabilities impacting Fortinet products - FortiCloud SSO Login Authentication Bypass - CVE-2025-59718 and CVE-2025-59719 - Update 2","uuid":"8569777d-9973-48f2-8b41-86f1759f74d8","banner":null,"lang":"en","date_modified":"2026-01-28","date_modified_ts":"2026-01-28T18:09:38Z","date_created":"2025-12-15T13:53:25Z","summary":null,"body":["<article data-history-node-id=\"7096\" about=\"\/en\/alerts-advisories\/al25-019-vulnerabilities-impacting-fortinet-products-forticloud-sso-login-authentication-bypass-cve-2025-59718-cve-2025-59719\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-019<br \/><strong>Date:<\/strong> December\u00a015, 2025<br \/><strong>Updated:<\/strong> January\u00a028, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of critical FortiCloud <abbr title=\"single sign-on\">SSO<\/abbr> Login Authentication Bypass vulnerabilities<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> affecting Fortinet products with this login feature enabled. Following the vendor advisory, the Cyber Centre issued AV25-821<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> on December 9, 2025.<\/p>\n\n<p>CVE-2025-59718<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> and CVE-2025-59719<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> allow an improper verification of cryptographic signature vulnerability (CWE-347)<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> which may allow an unauthenticated attacker to bypass the FortiCloud <abbr title=\"single sign-on\">SSO<\/abbr> login authentication via a crafted <abbr title=\"security assertion markup language\">SAML<\/abbr> response message.<\/p>\n\n<h3>Update 1<\/h3>\n\n<p>On January 22, 2026, Fortinet released an emergency blog post <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> regarding new instances of exploitation on devices with the FortiCloud SSO login feature enabled. Although the original patch had been installed, some Fortinet customers reported unexpected login activity on their devices that appeared similar to the previously observed issue. Fortinet's product security team has identified the root cause and is currently working on a fix to remediate this occurrence; however, organizations are advised to block administrative access to the SAML devices from the Internet and restrict access only to the local IP addresses and disabling the FortiCloud SSO feature.<\/p>\n\n<p>It is important to note that, while exploitation has so far only been observed involving FortiCloud SSO, the issue is applicable to all SAML SSO implementations in Fortinet products.<\/p>\n\n<p>Indicators of Compromise (IOCs) have been provided in Fortinet's blog post.<\/p>\n\n<p><strong>End of Update 1<\/strong><\/p>\n\n<h3>Update 2<\/h3>\n\n<p>On January\u00a027, 2026, Fortinet updated their PSIRT website to include a new CVE-2026-24858<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup> to include additional affected products, versions and Indicators of Compromise<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>.<\/p>\n\n<p>On January\u00a027, 2026, in response to the vendor advisory, the Cyber Centre released AV26-059<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup>.<\/p>\n\n<p>On January\u00a027, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-24858 to their Known Exploited Vulnerabilities (KEV)<sup id=\"fn12-rf\"><a class=\"fn-lnk\" href=\"#fn12\"><span class=\"wb-inv\">Footnote <\/span>12<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre recommends that organizations patch their Fortinet products to the following versions that are affected by CVE-2026-24858:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected version<\/th>\n\t\t\t<th scope=\"col\">Solution<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>FortiAnalyzer 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.5<\/td>\n\t\t\t<td>Upgrade to upcoming 7.6.6 or above<\/td>\n\t\t<\/tr><tr><td>FortiAnalyzer 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.9<\/td>\n\t\t\t<td>Upgrade to 7.4.10 or above<\/td>\n\t\t<\/tr><tr><td>FortiAnalyzer 7.2<\/td>\n\t\t\t<td>7.2.0 through 7.2.11<\/td>\n\t\t\t<td>Upgrade to upcoming 7.2.12 or above<\/td>\n\t\t<\/tr><tr><td>FortiAnalyzer 7.0<\/td>\n\t\t\t<td>7.0.0 through 7.0.15<\/td>\n\t\t\t<td>Upgrade to upcoming 7.0.16 or above<\/td>\n\t\t<\/tr><tr><td>FortiManager 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.5<\/td>\n\t\t\t<td>Upgrade to upcoming 7.6.6 or above<\/td>\n\t\t<\/tr><tr><td>FortiManager 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.9<\/td>\n\t\t\t<td>Upgrade to 7.4.10 or above<\/td>\n\t\t<\/tr><tr><td>FortiManager 7.2<\/td>\n\t\t\t<td>7.2.0 through 7.2.11<\/td>\n\t\t\t<td>Upgrade to upcoming 7.2.13 or above<\/td>\n\t\t<\/tr><tr><td>FortiManager 7.0<\/td>\n\t\t\t<td>7.0.0 through 7.0.15<\/td>\n\t\t\t<td>Upgrade to upcoming 7.0.16 or above<\/td>\n\t\t<\/tr><tr><td>FortiOS 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.5<\/td>\n\t\t\t<td>Upgrade to upcoming 7.6.6 or above<\/td>\n\t\t<\/tr><tr><td>FortiOS 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.10<\/td>\n\t\t\t<td>Upgrade to 7.4.11 or above<\/td>\n\t\t<\/tr><tr><td>FortiOS 7.2<\/td>\n\t\t\t<td>7.2.0 through 7.2.12<\/td>\n\t\t\t<td>Upgrade to upcoming 7.2.13 or above<\/td>\n\t\t<\/tr><tr><td>FortiOS 7.0<\/td>\n\t\t\t<td>7.0.0 through 7.0.18<\/td>\n\t\t\t<td>Upgrade to upcoming 7.0.19 or above<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.4<\/td>\n\t\t\t<td>Upgrade to upcoming 7.6.6 or above<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.12<\/td>\n\t\t\t<td>Upgrade to upcoming 7.4.13 or above<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.2<\/td>\n\t\t\t<td>7.2 all versions<\/td>\n\t\t\t<td>Migrate to a fixed release<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.0<\/td>\n\t\t\t<td>7.0 all versions<\/td>\n\t\t\t<td>Migrate to a fixed release<\/td>\n\t\t<\/tr><\/tbody><\/table><\/div>\n\n<p><strong>End of Update 2<\/strong><\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations patch their Fortinet products to the following versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected version<\/th>\n\t\t\t<th scope=\"col\">Solution<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>FortiOS 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.3<\/td>\n\t\t\t<td>Upgrade to 7.6.4 or above<\/td>\n\t\t<\/tr><tr><td>FortiOS 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.8<\/td>\n\t\t\t<td>Upgrade to 7.4.9 or above<\/td>\n\t\t<\/tr><tr><td>FortiOS 7.2<\/td>\n\t\t\t<td>7.2.0 through 7.2.11<\/td>\n\t\t\t<td>Upgrade to 7.2.12 or above<\/td>\n\t\t<\/tr><tr><td>FortiOS 7.0<\/td>\n\t\t\t<td>7.0.0 through 7.0.17<\/td>\n\t\t\t<td>Upgrade to 7.0.18 or above<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.3<\/td>\n\t\t\t<td>Upgrade to 7.6.4 or above<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.10<\/td>\n\t\t\t<td>Upgrade to 7.4.11 or above<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.2<\/td>\n\t\t\t<td>7.2.0 through 7.2.14<\/td>\n\t\t\t<td>Upgrade to 7.2.15 or above<\/td>\n\t\t<\/tr><tr><td>FortiProxy 7.0<\/td>\n\t\t\t<td>7.0.0 through 7.0.21<\/td>\n\t\t\t<td>Upgrade to 7.0.22 or above<\/td>\n\t\t<\/tr><tr><td>FortiSwitchManager 7.2<\/td>\n\t\t\t<td>7.2.0 through 7.2.6<\/td>\n\t\t\t<td>Upgrade to 7.2.7 or above<\/td>\n\t\t<\/tr><tr><td>FortiSwitchManager 7.0<\/td>\n\t\t\t<td>7.0.0 through 7.0.5<\/td>\n\t\t\t<td>Upgrade to 7.0.6 or above<\/td>\n\t\t<\/tr><tr><td>FortiWeb 8.0<\/td>\n\t\t\t<td>8.0.0<\/td>\n\t\t\t<td>Upgrade to 8.0.1 or above<\/td>\n\t\t<\/tr><tr><td>FortiWeb 7.6<\/td>\n\t\t\t<td>7.6.0 through 7.6.4<\/td>\n\t\t\t<td>Upgrade to 7.6.5 or above<\/td>\n\t\t<\/tr><tr><td>FortiWeb 7.4<\/td>\n\t\t\t<td>7.4.0 through 7.4.9<\/td>\n\t\t\t<td>Upgrade to 7.4.10 or above<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>If patching is not possible at this time, the Cyber Centre strongly recommends that organizations follow Fortinet customer guidance for mitigation advice<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, which involves turning off the FortiCloud login feature (if enabled) temporarily until upgrading to a non-affected version.<\/p>\n\n<p>In addition, the Cyber Centre also strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<ul><li>Patching operating systems and applications<\/li>\n\t<li>Segment and separate information<\/li>\n\t<li>Isolating Web-Facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert is discovered, recipients are encouraged to report via <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h3>Update 1<\/h3>\n\n<p>Recommended mitigation measures:<\/p>\n\n<ul><li>Disable FortiCloud SSO on all Fortinet devices if you do not require this feature.<\/li>\n\t<li>Prevent unrestricted remote administrative access to any internet exposed edge network devices.<\/li>\n\t<li>Use out of band access or apply a local-in policy to restrict IP addresses accessing the administrative interface.<\/li>\n\t<li>Analyze logs and configurations for signs of compromise using the IOCs provided in the blog post.<\/li>\n\t<li>Review Fortinet's blog post\u202f<sup id=\"fn7a-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> for additional details if signs of compromise are detected.<\/li>\n<\/ul><p>Fortinet will update the blog post once a full advisory is available. It is recommended to monitor the Fortinet PSIRT webpage\u202f<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> for updates.<\/p>\n\n<p><strong>End of Update 1<\/strong><\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-25-647\">Fortinet PSIRT Advisories<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/fortinet-security-advisory-av25-821\">Fortinet security advisory (AV25-821)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-59718\">CVE-2025-59718 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-59719\">CVE-2025-59719 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/347.html\">CWE347: Improper Verification of Cryptographic Signature<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.fortinet.com\/blog\/psirt-blogs\/analysis-of-sso-abuse-on-fortios\">Analysis of Single Sign-On Abuse on FortiOS<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\">PSIRT Advisories\u00a0\u2013 FortiGuard Labs<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-24858\">CVE-2026-24858 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-060\">Fortinet\u00a0- Administrative FortiCloud SSO authentication bypass<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"\/en\/alerts-advisories\/cyber-fortinet-security-advisory-av26-059\">Fortinet security advisory (AV26-059)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 12<\/dt>\n\t<dd id=\"fn12\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-24858\">CISA KEV: CVE-2026-24858<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn12-rf\"><span class=\"wb-inv\">Return to footnote<\/span>12<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-019-vulnerabilities-impacting-fortinet-products-forticloud-sso-login-authentication-bypass-cve-2025-59718-cve-2025-59719","alert_type":397,"serial_number":"AL25-019","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7098,"title":"Microsoft Edge security advisory (AV25-832)","uuid":"9a6eacce-fda1-4343-ac3a-80ad36c5cd81","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T16:42:33Z","date_created":"2025-12-15T16:32:19Z","summary":null,"body":["<article data-history-node-id=\"7098\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-832\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-832<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 15, 2025<\/p>\n\n<p>On December 11, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 143.0.3650.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<p>Microsoft has indicated that CVE-2025-14174 has an available exploit.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-11-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-832","alert_type":396,"serial_number":"AV25-832","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7099,"title":"HPE security advisory (AV25-833)","uuid":"609a7881-9ac5-49ff-a56e-bb9a7dfdfd85","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T16:53:30Z","date_created":"2025-12-15T16:44:35Z","summary":null,"body":["<article data-history-node-id=\"7099\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-833\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-833<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 15, 2025<\/p>\n\n<p>On December 12, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE ProLiant DL\/ML\/XD Alletra and Synergy Servers (multiple models)\u00a0\u2013 Intel QuickAssist Technology (QAT) software drivers for MS Windows versions prior to v2.6.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesb3p04984en_us&amp;docLocale=en_US\">HPESB3P04984 rev.1\u00a0- HPE ProLiant DL\/ML\/XD Alletra and Synergy Servers Using Intel QuickAssist Technology Software Drivers, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-833","alert_type":396,"serial_number":"AV25-833","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7100,"title":"React security advisory (AV25-834)","uuid":"c5977e69-986b-4b02-a08d-85fe615e7e1c","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T17:10:44Z","date_created":"2025-12-15T16:49:18Z","summary":null,"body":["<article data-history-node-id=\"7100\" about=\"\/en\/alerts-advisories\/react-security-advisory-av25-834\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-834<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 15, 2025<\/p>\n\n<p>On December 11, 2025, React Foundation published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CVE-2025-55183 and CVE-2025-55184 affecting:\n\t<ul><li>React-server-dom-webpack\u00a0\u2013 versions 19.0.0 to 19.0.1, 19.1.0 to 19.1.2 and 19.2.0 to 9.2.1<\/li>\n\t\t<li>React-server-dom-parcel\u00a0\u2013 versions 19.0.0 to 19.0.1, 19.1.0 to 19.1.2 and 19.2.0 to 9.2.1<\/li>\n\t\t<li>React-server-dom-turbopack\u00a0\u2013 versions 19.0.0 to 19.0.1, 19.1.0 to 19.1.2 and 19.2.0 to 9.2.1<\/li>\n\t<\/ul><\/li>\n\t<li>CVE-2025-67779 affecting:\n\t<ul><li>React-server-dom-webpack\u00a0\u2013 versions 19.0.2, 19.1.3 and 19.2.2<\/li>\n\t\t<li>React-server-dom-parcel\u00a0\u2013 19.0.2, 19.1.3 and 19.2.2<\/li>\n\t\t<li>React-server-dom-turbopack\u00a0\u2013 versions 19.0.2, 19.1.3 and 19.2.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Libraries and frameworks bundling react-server implementations are likely to be affected. Common examples include:<\/p>\n\n<ul><li>Next.js<\/li>\n\t<li>Vite RSC plugin<\/li>\n\t<li>Parcel RSC plugin<\/li>\n\t<li>React Router RSC preview<\/li>\n\t<li>RedwoodSDK<\/li>\n\t<li>Waku<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/react.dev\/blog\/2025\/12\/11\/denial-of-service-and-source-code-exposure-in-react-server-components\">Denial of Service and Source Code Exposure in React Server Components<\/a><\/li>\n\t<li><a href=\"https:\/\/vercel.com\/kb\/bulletin\/security-bulletin-cve-2025-55184-and-cve-2025-55183\">Security Bulletin: CVE-2025-55184 and CVE-2025-55183<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/react-security-advisory-av25-834","alert_type":396,"serial_number":"AV25-834","subject":"other","moderation_state":"published","external_url":null},{"nid":7101,"title":"IBM security advisory (AV25-835)","uuid":"5aa6f47d-1134-4512-9375-8bbb83fe5bac","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T17:25:10Z","date_created":"2025-12-15T17:16:47Z","summary":null,"body":["<article data-history-node-id=\"7101\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-835\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-835<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 15, 2025<\/p>\n\n<p>Between December 8 and 14, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Storage Defender\u00a0- Resiliency Service\u00a0\u2013 versions 2.0.0 to 2.0.18<\/li>\n\t<li>IBM Guardium Data Protection\u00a0\u2013 version 11.5<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\u00a0\u2013 versions 9.1, 9.0, 8.11 and 8.10<\/li>\n\t<li>IBM Edge Data Collector\u00a0\u2013 versions 9.1, 9.0 and 8.11<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 versions Build 1.0.283 to 1.0.307<\/li>\n\t<li>IBM OmniFind Text Search Server for DB2 for I\u00a0\u2013 versions 1.7, 1.6 and 1.5<\/li>\n\t<li>IBM Storage Defender\u00a0- Data Protect\u00a0\u2013 versions 2.0.0 to 2.0.18<\/li>\n\t<li>IBM Business Automation Manager Open Editions\u00a0\u2013 versions 9.0.0 to 9.3.0<\/li>\n\t<li>IBM Storage Defender Copy Data Management\u00a0\u2013 versions 2.2.0.0 to 2.2.27.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-835","alert_type":396,"serial_number":"AV25-835","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7102,"title":"Ubuntu security advisory (AV25-836)","uuid":"60978165-e3c7-4cc0-9e67-f4e192754380","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T19:18:26Z","date_created":"2025-12-15T19:14:28Z","summary":null,"body":["<article data-history-node-id=\"7102\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-836\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV25-836<br \/><strong>Date:<\/strong> December\u00a015, 2025<\/p>\n\n<p>Between December\u00a08 and 14, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-836","alert_type":396,"serial_number":"AV25-836","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7103,"title":"Apple security advisory (AV25-837)","uuid":"4f7a3937-34d2-4cbe-aad0-fd659e74f7b8","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T19:28:09Z","date_created":"2025-12-15T19:14:29Z","summary":null,"body":["<article data-history-node-id=\"7103\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av25-837\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-837<br \/><strong>Date:<\/strong> December\u00a015, 2025<\/p>\n\n<p>On December\u00a012, 2025, Apple published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 26.2<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 26.2<\/li>\n\t<li>iOS\u00a0\u2013 versions prior to 18.7.3<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 18.7.3<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26.2<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.7.3<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.8.3<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 26.2<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 26.2<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 26.2<\/li>\n\t<li>Safari\u00a0\u2013 versions prior to 26.2<\/li>\n<\/ul><p>Apple is aware that CVE-2025-14174 and CVE-2025-43529 are being exploited.<\/p>\n\n<p>On December\u00a012, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-14174 to their Known Exploited Vulnerabilities (KEV) Database. CISA added CVE-2025-43529 to the KEV on December\u00a015, 2025.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities Catalog\u00a0| CISA<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av25-837","alert_type":396,"serial_number":"AV25-837","subject":"apple","moderation_state":"published","external_url":null},{"nid":7104,"title":"[Control systems] CISA ICS security advisories (AV25\u2013838)","uuid":"1f46c881-b65f-4571-bb45-89d1830905e4","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T19:36:43Z","date_created":"2025-12-15T19:21:25Z","summary":null,"body":["<article data-history-node-id=\"7104\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-838\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25\u2013838<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 15, 2025<\/p>\n\n<p>Between December 8 and 14, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AzeoTech DAQFactory\u00a0\u2013 release 20.7 (Build 2555) and prior<\/li>\n\t<li>Festo Software LX Appliance\u00a0\u2013 versions prior to June 2023<\/li>\n\t<li>Grassroots DICOM (GDCM)\u00a0\u2013 versions 3.0.24 and prior<\/li>\n\t<li>Grassroots Simple TK\u00a0\u2013 versions 2.5.2 and prior<\/li>\n\t<li>Grassroots medlnria\u00a0\u2013 versions 4.0 and prior<\/li>\n\t<li>Johnson Controls iSTAR\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Multiple India-based CCTV Cameras\u00a0\u2013 D-Link DCS-F5614-L1, Sparsh Securitech and Securus<\/li>\n\t<li>OpenPLC_V3\u00a0\u2013 versions prior to pull request #310<\/li>\n\t<li>Siemens Advanced Licensing (SALT) Toolkit\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens Building X\u00a0- Security Manager Edge Controller (ACC-AP)\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Energy Services\u00a0\u2013 all versions with G5DFR<\/li>\n\t<li>Siemens Gridscale X Prepay\u00a0\u2013 versions prior to 4.2.1<\/li>\n\t<li>Siemens IAM Client\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens SINEMA Remote Connect Server\u00a0\u2013 versions prior to V3.2 SP4<\/li>\n\t<li>U-Boot\u00a0\u2013 versions prior to 2017.11 on multiple Qualcomm chips<\/li>\n\t<li>Varex Imaging Panoramic Dental Imaging Software\u00a0\u2013 versions prior to 6.6.1.490<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-838","alert_type":398,"serial_number":"AV25\u2013838","subject":"ics","moderation_state":"published","external_url":null},{"nid":7105,"title":"VMware security advisory (AV25-839)","uuid":"f065f6fe-fcc8-414a-88d0-6c59ce2e6dfe","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T19:49:08Z","date_created":"2025-12-15T19:41:32Z","summary":null,"body":["<article data-history-node-id=\"7105\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-839\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-839<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 15, 2025<\/p>\n\n<p>Between December 8 and 14, 2025, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<ul><li>VMware Tanzu RabbitMQ on Kubernetes\u00a0\u2013 versions prior to 4.1.6<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes\u00a0\u2013 versions prior to 4.2.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36589\">Product Release Advisory\u00a0- VMware Tanzu RabbitMQ on Kubernetes 4.1.6<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36590\">Product Release Advisory\u00a0- VMware Tanzu RabbitMQ on Kubernetes 4.2.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-839","alert_type":396,"serial_number":"AV25-839","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7106,"title":"ConnectWise security advisory (AV25-840)","uuid":"857569de-d799-4ff4-9e45-6685af38443a","banner":null,"lang":"en","date_modified":"2025-12-15","date_modified_ts":"2025-12-15T19:56:49Z","date_created":"2025-12-15T19:51:42Z","summary":null,"body":["<article data-history-node-id=\"7106\" about=\"\/en\/alerts-advisories\/connectwise-security-advisory-av25-840\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-840<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 15, 2025<\/p>\n\n<p>On December 11, 2025, ConnectWise published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ConnectWise ScreenConnect\u00a0\u2013 versions prior to 25.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/screenconnect-2025.8-security-patch\">ScreenConnect 25.8 Security Patch<\/a><\/li>\n\t<li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/advisories\">ConnectWise\u00a0- Latest Advisories <\/a><\/li>\n<\/ul><!--{C}%3C!%2D%2D***************************************************%20END%20ADVISORY%20-English-******************************************************%2D%2D%3E--><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/connectwise-security-advisory-av25-840","alert_type":396,"serial_number":"AV25-840","subject":"other","moderation_state":"published","external_url":null},{"nid":7107,"title":"Red Hat security advisory (AV25-841)","uuid":"1427b79a-c998-412f-b928-edaf9e119cd5","banner":null,"lang":"en","date_modified":"2025-12-16","date_modified_ts":"2025-12-16T17:02:46Z","date_created":"2025-12-16T16:57:04Z","summary":null,"body":["<article data-history-node-id=\"7107\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-841\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-841<br \/><strong>Date: <\/strong>December\u00a016, 2025<\/p>\n\n<p>Between December\u00a08 and 14, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:22997\">Red Hat Security Updates\u00a0- RHSA-2025:22997<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:22995\">Red Hat Security Updates\u00a0- RHSA-2025:22995<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:23009\">Red Hat Security Updates\u00a0- RHSA-2025:23009<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/errata\/RHSA-2025:22854\">Red Hat Security Updates\u00a0- RHSA-2025:22854<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-841","alert_type":396,"serial_number":"AV25-841","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7108,"title":"Tenable security advisory (AV25-842)","uuid":"897f819e-21f9-42cf-ba6b-74aa5bfe1206","banner":null,"lang":"en","date_modified":"2025-12-17","date_modified_ts":"2025-12-17T14:34:22Z","date_created":"2025-12-17T14:26:40Z","summary":null,"body":["<article data-history-node-id=\"7108\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av25-842\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-842<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 17, 2025<\/p>\n\n<p>On December 15, 2025, Tenable published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:<\/p>\n\n<ul><li>Tenable Nessus\u00a0\u2013 versions prior to 10.9.6 and 10.11.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2025-24\">[R1] Nessus Versions 10.11.1 and 10.9.6 Fix Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av25-842","alert_type":396,"serial_number":"AV25-842","subject":"other","moderation_state":"published","external_url":null},{"nid":7109,"title":"Google Chrome security advisory (AV25-843)","uuid":"3c84ab31-e83a-4898-b479-36623eef4698","banner":null,"lang":"en","date_modified":"2025-12-17","date_modified_ts":"2025-12-17T15:25:20Z","date_created":"2025-12-17T15:00:06Z","summary":null,"body":["<article data-history-node-id=\"7109\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-843\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-843<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 17, 2025<\/p>\n\n<p>On December 16, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 143.0.7499.146\/.147 (Windows\/Mac) and 143.0.7499.146 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/12\/stable-channel-update-for-desktop_16.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-843","alert_type":396,"serial_number":"AV25-843","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7110,"title":"HPE security advisory (AV25-844) \u2013 Update 1","uuid":"12aefbe5-ec0c-4e67-b3d1-8f50285119d1","banner":null,"lang":"en","date_modified":"2026-01-08","date_modified_ts":"2026-01-08T13:42:11Z","date_created":"2025-12-17T15:28:52Z","summary":null,"body":["<article data-history-node-id=\"7110\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-844\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-844<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 17, 2025<br \/><strong>Updated:<\/strong> January 8, 2026<\/p>\n\n<p>On December 16, 2025, HPE published security advisories to address vulnerabilities in the following products. Included was a critical update for the following\u00a0:<\/p>\n\n<ul><li>HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">OneView<\/span>\u00a0\u2013 versions prior to v11.00<\/li>\n\t<li>HPE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Telco Service Activator<\/span>\u00a0\u2013 version 10.3.2 and prior<\/li>\n<\/ul><p><strong>Update 1 <\/strong><br \/>\nOn January 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-37164 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn04985en_us&amp;docLocale=en_US\">HPESBGN04985 rev.1\u00a0- Hewlett Packard Enterprise OneView Software, Remote Code Execution - Critical<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04986en_us&amp;docLocale=en_US\">HPESBNW04986 rev.1\u00a0- HPE Telco Service Activator, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-37164\">CISA KEV: CVE-2025-37164<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-844","alert_type":396,"serial_number":"AV25-844","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7111,"title":"SonicWall security advisory (AV25-845) \u2013 Update 1","uuid":"a11fc31c-0427-41ba-b2cb-544108e30a1a","banner":null,"lang":"en","date_modified":"2025-12-17","date_modified_ts":"2025-12-17T16:54:30Z","date_created":"2025-12-17T16:37:29Z","summary":null,"body":["<article data-history-node-id=\"7111\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-845\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-845<br \/><strong>Date: <\/strong>December 17, 2025<br \/><strong>Updated:<\/strong> December 17, 2025<\/p>\n\n<p class=\"mrgn-bttm-md\">On December 17, 2025, SonicWall published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SMA1000\u00a0\u2013 versions 12.4.3-03093 (platform-hotfix) and prior<\/li>\n\t<li>SMA1000\u00a0\u2013 versions 12.5.0-02002 (platform-hotfix) and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p><strong>Update 1<\/strong><\/p>\n\n<p>On December 17, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-40602 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">Open-source reporting indicates that CVE-2025-40602 is being exploited.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2025-0019\">SonicWall SMA1000 appliance local privilege escalation vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-40602\">CISA KEV\u00a0: CVE-2025-40602<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av25-845","alert_type":396,"serial_number":"AV25-845","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":7112,"title":"Mozilla security advisory (AV25-846)","uuid":"0e7ce1e0-92c8-4c7d-a51c-3dabe4880312","banner":null,"lang":"en","date_modified":"2025-12-17","date_modified_ts":"2025-12-17T17:18:01Z","date_created":"2025-12-17T17:11:41Z","summary":null,"body":["<article data-history-node-id=\"7112\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-846\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-846<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 17, 2025<\/p>\n\n<p>On December 15, 2025, Mozilla published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Firefox for iOS\u00a0\u2013 versions prior to 144.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-97\/\">Mozilla Foundation Security Advisory 2025-97<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-846","alert_type":396,"serial_number":"AV25-846","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7113,"title":" Drupal security advisory (AV25-847) ","uuid":"c1a72dad-98ba-4da9-95f8-decf7d4e703e","banner":null,"lang":"en","date_modified":"2025-12-17","date_modified_ts":"2025-12-17T20:01:56Z","date_created":"2025-12-17T19:50:24Z","summary":null,"body":["<article data-history-node-id=\"7113\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av25-847\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-847<br \/><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: <\/strong>December 17, 2025<\/p>\n\n<p>On December 17, 2025, Drupal published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HTTP Client Manager\u00a0\u2013 version 9.3.13<\/li>\n\t<li>HTTP Client Manager\u00a0\u2013 versions 10.0.x prior to 10.0.2<\/li>\n\t<li>HTTP Client Manager\u00a0\u2013 version 11.0.x prior to 11.0.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2025-126\">HTTP Client Manager\u00a0- Less critical\u00a0- Information disclosure\u00a0- SA-CONTRIB-2025-126<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av25-847","alert_type":396,"serial_number":"AV25-847","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7114,"title":"Cisco security advisory (AV25-848) \u2013 Update 1","uuid":"99bba8e2-0131-4df4-a0c0-20826f61601c","banner":null,"lang":"en","date_modified":"2025-12-17","date_modified_ts":"2025-12-17T20:49:24Z","date_created":"2025-12-17T20:34:38Z","summary":null,"body":["<article data-history-node-id=\"7114\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av25-848\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV25-848<br \/><strong>Date:<\/strong> December\u00a017, 2025<br \/><strong>Updated:<\/strong> December\u00a017, 2025<\/p>\n\n<p>On December\u00a017, 2025, Cisco published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Cisco Secure Email Gateway\u00a0\u2013 all versions of AsyncOS with Spam Quarantine feature enabled and exposed on the internet<\/li>\n\t<li>Cisco Secure Email and Web Manager\u00a0\u2013 all versions of AsyncOS with Spam Quarantine feature enabled and exposed on the internet<\/li>\n<\/ul><p><strong>Update 1<\/strong><\/p>\n\n<p>On December 17, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-20393 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sma-attack-N9bf4\">Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-20393\">CISA KEV\u00a0: CVE-2025-20393<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av25-848","alert_type":396,"serial_number":"AV25-848","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7115,"title":"Mozilla security advisory (AV25-849)","uuid":"12986a29-b187-4f3d-967c-bd601d77d56d","banner":null,"lang":"en","date_modified":"2025-12-18","date_modified_ts":"2025-12-18T20:16:53Z","date_created":"2025-12-18T19:59:41Z","summary":null,"body":["<article data-history-node-id=\"7115\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av25-849\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-849<br \/><strong>Date: <\/strong>December 18, 2025<\/p>\n\n<p>On December 18, 2025, Mozilla published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>\u00a0Firefox\u00a0\u2013 versions prior to 146.0.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2025-98\/\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Mozilla Foundation Security Advisory<\/span> 2025-98<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Mozilla Security Advisories<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av25-849","alert_type":396,"serial_number":"AV25-849","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7116,"title":"WatchGuard security advisory (AV25-850) \u2013 Update 1","uuid":"ab824678-9456-4ee7-b2a2-2cf6997f4ff2","banner":null,"lang":"en","date_modified":"2025-12-19","date_modified_ts":"2025-12-19T20:55:26Z","date_created":"2025-12-19T15:14:17Z","summary":null,"body":["<article data-history-node-id=\"7116\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av25-850\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-850<br \/><strong>Date: <\/strong>December 19, 2025<\/p>\n\n<p>On December 18, 2025, WatchGuard published a security advisory to address a critical vulnerability in the following product. Included was an update for the following:<\/p>\n\n<ul><li>Fireware OS\u00a0\u2013 versions prior to 2025.1.4<\/li>\n\t<li>Fireware OS\u00a0\u2013 versions prior to 12.11.6<\/li>\n\t<li>Fireware OS\u00a0\u2013 versions prior to 12.5.15<\/li>\n\t<li>Fireware OS\u00a0\u2013 versions prior to 12.3.1_Update4 (FIPS) (B728352)<\/li>\n<\/ul><p><strong>Update 1<\/strong><\/p>\n\n<p>On December 19, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-14733 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2025-00027\">WatchGuard Firebox iked Out of Bounds Write Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-14733\">CISA KEV: CVE-2025-14733<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av25-850","alert_type":396,"serial_number":"AV25-850","subject":"other","moderation_state":"published","external_url":null},{"nid":7117,"title":"Google Chrome security advisory (AV25-851)","uuid":"5ef48764-6512-4604-9c9e-5d1a3994f1b5","banner":null,"lang":"en","date_modified":"2025-12-19","date_modified_ts":"2025-12-19T15:35:34Z","date_created":"2025-12-19T15:31:56Z","summary":null,"body":["<article data-history-node-id=\"7117\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-851\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-851<br \/><strong>Date: <\/strong>December 19, 2025<\/p>\n\n<p>On December 18, 2025, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 143.0.7499.169\/.170 (Windows\/Mac) and 143.0.7499.169 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2025\/12\/stable-channel-update-for-desktop_18.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av25-851","alert_type":396,"serial_number":"AV25-851","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7118,"title":"Microsoft Edge security advisory (AV25-852)","uuid":"7a931b84-8f98-48de-84e3-0326878a4c02","banner":null,"lang":"en","date_modified":"2025-12-19","date_modified_ts":"2025-12-19T15:43:43Z","date_created":"2025-12-19T15:35:33Z","summary":null,"body":["<article data-history-node-id=\"7118\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-852\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-852<br \/><strong>Date: <\/strong>December 19, 2025<\/p>\n\n<p>On December 18, 2025, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 143.0.3650.96<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#december-18-2025\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av25-852","alert_type":396,"serial_number":"AV25-852","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7119,"title":"HPE security advisory (AV25-853)","uuid":"a4e7107c-ef62-4341-9e94-564ecb45fbc0","banner":null,"lang":"en","date_modified":"2025-12-19","date_modified_ts":"2025-12-19T20:41:30Z","date_created":"2025-12-19T20:37:02Z","summary":null,"body":["<article data-history-node-id=\"7119\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av25-853\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-853<br \/><strong>Date: <\/strong>December 19, 2025<\/p>\n\n<p>On December 19, 2025, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console Assurance Monitoring (UOCAM)\u00a0\u2013 versions prior to UOCAM Version 3.1.19<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04989en_us&amp;docLocale=en_US#hpesbnw04989-rev-1-hpe-unified-oss-console-assuran-0\">HPESBNW04989 rev.1\u00a0- HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av25-853","alert_type":396,"serial_number":"AV25-853","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7121,"title":"[Control systems] CISA ICS security advisories (AV25\u2013854)","uuid":"21ecce3f-e6f7-4e11-a188-6489468603b6","banner":null,"lang":"en","date_modified":"2025-12-22","date_modified_ts":"2025-12-22T16:08:22Z","date_created":"2025-12-22T16:01:09Z","summary":null,"body":["<article data-history-node-id=\"7121\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-854\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-854<br \/><strong>Date: <\/strong>December 22, 2025<\/p>\n\n<p>Between December 15 and 21, 2025, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Advantech \u2013 WebAccess\/SCADA<\/li>\n\t<li>Axis Communications \u2013 Camera Station Device Manager<\/li>\n\t<li>Axis Communications \u2013 Camera Station Pro<\/li>\n\t<li>Axis Communications \u2013 Camera Station Station<\/li>\n\t<li>G\u00fcralp Systems \u2013 Fortimus Series, Minimus Series, and Certimus Series<\/li>\n\t<li>Hitachi Energy \u2013 AFS, AFR and AFF Series<\/li>\n\t<li>Inductive Automation Ignition \u2013 Ignition<\/li>\n\t<li>Johnson Controls \u2013 PowerG, IQPanel and IQHub<\/li>\n\t<li>Mitsubishi Electric \u2013 GT Designer3<\/li>\n\t<li>Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electrics \u2013 GENESIS64<\/li>\n\t<li>Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electrics \u2013 ICONICS Suite<\/li>\n\t<li>Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electrics \u2013 MobileHMI<\/li>\n\t<li>Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electrics \u2013 MC Works64<\/li>\n\t<li>National Instruments \u2013 LabVIEW<\/li>\n\t<li>Rockwell Automation \u2013 Micro820<\/li>\n\t<li>Rockwell Automation \u2013 Micro850<\/li>\n\t<li>Rockwell Automation \u2013 Micro870<\/li>\n\t<li>Schneider Electric \u2013 EcoStruxure Foxboro DCS Advisor<\/li>\n\t<li>Siemens Interniche IP-Stack:SIDOOR \u2013 multiple models and versions<\/li>\n\t<li>Siemens Interniche IP-Stack:SIMATIC \u2013 multiple models and versions<\/li>\n\t<li>Siemens Interniche IP-Stack:SIMOCODE \u2013 multiple models and versions<\/li>\n\t<li>Siemens Interniche IP-Stack:SINUMERIK \u2013 multiple models and versions<\/li>\n\t<li>Siemens Interniche IP-Stack:SIPLUS \u2013 multiple models and versions<\/li>\n\t<li>Siemens Interniche IP-Stack:SIWARX \u2013 multiple models and versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av25-854","alert_type":398,"serial_number":"AV25-854","subject":"other","moderation_state":"published","external_url":null},{"nid":7122,"title":"IBM security advisory (AV25-855)","uuid":"cf90f838-7cd6-4b47-aee3-0ae6663cc095","banner":null,"lang":"en","date_modified":"2025-12-22","date_modified_ts":"2025-12-22T16:43:04Z","date_created":"2025-12-22T16:33:02Z","summary":null,"body":["<article data-history-node-id=\"7122\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-855\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-855<br \/><strong>Date: <\/strong>December 22, 2025<\/p>\n\n<p>Between December 15 and 21, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM API Connect\u00a0\u2013 version 10.0.8.0 to 10.0.8.5 and V10.0.11.0<\/li>\n\t<li>IBM CloudPak for AIOps\u00a0\u2013 versions 4.1.0 to 4.11.1<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 version 1.0.0 to 2.1.0<\/li>\n\t<li>IBM DataPower Gateway\u00a0\u2013 version 10.6.6.0<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data\u00a0\u2013 versions 3.0, 3.1 and 3.2<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data versions\u00a0\u2013 versions v4.8, v5.0, v5.1, v5.2 and v5.3<\/li>\n\t<li>IBM Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 versions v4.8, v5.0, v5.1, v5.2 and v5.3<\/li>\n\t<li>IBM DS8A00\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Edge Data Collector\u00a0\u2013 version 8.11<\/li>\n\t<li>IBM Fusion\u00a0\u2013 versions 2.2.0 to 2.11.1<\/li>\n\t<li>IBM Fusion HCI\u00a0\u2013 versions 2.2.0 to 2.11.1<\/li>\n\t<li>IBM Fusion HCI for watson\u00a0\u2013 versions 2.2.0 to 2.11.1<\/li>\n\t<li>IBM Library Support for Spring\u00a0- Spring-boot\u00a0\u2013 versions 2.7.0 to 2.7.18<\/li>\n\t<li>IBM Library Support for Spring\u00a0- Spring-framework\u00a0\u2013 versions 5.3.0 to 5.3.39<\/li>\n\t<li>IBM Library Support for Struts\u00a0\u2013 versions 1.1.1 to 1.1.3<\/li>\n\t<li>IBM MANTA Automated Data Lineage for IBM Cloud Pak for Data\u00a0\u2013 version 4.5.0 to 5.3.0<\/li>\n\t<li>IBM QRadar Suite Software\u00a0\u2013 versions 1.11.0.0 to 1.11.7.0<\/li>\n\t<li>IBM QRadar Suite Software\u00a0\u2013 versions 4.1.15 to 5.0.2<\/li>\n\t<li>IBM Rhapsody Systems Engineering\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Security QRadar Analyst Wrokflow for IBM QRadar SIEM\u00a0\u2013 versions 2.32.0 to 3.0.0<\/li>\n\t<li>IBM Sterling Partner Engagement Manager\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Watson Query on Cloud Pak for Data\u00a0\u2013 version 2.2<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0\u2013 versions 4.0.0\u00a0- 5.2.2<\/li>\n\t<li>IBM watsonx Code Assistant On Prem\u00a0\u2013 version 5.1.1, 5.1.2, 5.1.3, 5.2, 5.2.1 and 5.2.2<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0\u2013 versions 1.4.0\u00a0- 1.15.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-855","alert_type":396,"serial_number":"AV25-855","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7123,"title":"Dell security advisory (AV25-856)","uuid":"03a1926d-9198-46da-9029-d81c4741dacc","banner":null,"lang":"en","date_modified":"2025-12-22","date_modified_ts":"2025-12-22T17:04:31Z","date_created":"2025-12-22T16:59:38Z","summary":null,"body":["<article data-history-node-id=\"7123\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-856\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-856<br \/><strong>Date: <\/strong>December 22, 2025<\/p>\n\n<p class=\"mrgn-bttm-md\">Between December 15 and 21, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Metro node \u2013 version mn-114, mn-215 and mn-216<\/li>\n\t<li>Dell PowerEdge \u2013 multiple versions and models<\/li>\n\t<li>Dell PowerProtect Data Domain \u2013 multiple versions<\/li>\n\t<li>Dell RecoverPoint for Virtual Machines \u2013 Debian 12 \u2013 versions prior to 6.0 SP3 P1<\/li>\n\t<li>Dell RecoverPoint for Virtual Machines - SUSE Linux Enterprise 12 SP6 \u2013 versions prior to 6.0 SP3 P1<\/li>\n\t<li>Dell Storage Resource Manager (SRM) \u2013 version prior to 6.0.0.1<\/li>\n\t<li>Dell Storage Monitoring and Reporting (SMR) \u2013 version prior to 6.0.0.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-856","alert_type":396,"serial_number":"AV25-856","subject":"dell","moderation_state":"published","external_url":null},{"nid":7124,"title":"n8n security advisory (AV25-857) \u2013 Update 1","uuid":"dbbcf2b6-bed1-4636-bf87-6b6fcd943ec8","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T20:31:35Z","date_created":"2025-12-22T18:13:00Z","summary":null,"body":["<article data-history-node-id=\"7124\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av25-857\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-857<br \/><strong>Date: <\/strong>December 22, 2025<br \/><strong>Updated: <\/strong>March 11, 2026<\/p>\n\n<p>On December 19, 2025, n8n published a security update to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>n8n workflow automation\u00a0\u2013 versions 0.211.0 to versions prior to 1.120.4<\/li>\n<\/ul><h2 class=\"h3\">\n  Update 1\n<\/h2>\n\n<p>\n  On March 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-68613 to their Known Exploited Vulnerabilities (KEV) Database.\n<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/n8n.io\/\">n8n website<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-v98v-ff95-f3cp\">n8n\u00a0\u2013 Remote Code Execution via Expression Injection (CVE-2025-68613)<\/a><\/li>\n  \n  <li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-68613\">CISA KEV: CVE-2025-68613<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av25-857","alert_type":396,"serial_number":"AV25-857","subject":"other","moderation_state":"published","external_url":null},{"nid":7125,"title":"AL25-020 \u2013 Vulnerability Impacting WatchGuard Fireware OS - CVE-2025-14733","uuid":"0fbc3aa2-b8db-4d5a-ab1e-b744d587da43","banner":null,"lang":"en","date_modified":"2025-12-22","date_modified_ts":"2025-12-22T19:37:15Z","date_created":"2025-12-22T19:32:20Z","summary":null,"body":["<article data-history-node-id=\"7125\" about=\"\/en\/alerts-advisories\/al25-020-vulnerability-impacting-watchguard-fireware-os-cve-2025-14733\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-020<br \/><strong>Date:<\/strong> December\u00a022, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a critical WatchGuard Fireware OS Out-of-Bounds Write vulnerability affecting WatchGuard products<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. In response to the vendor advisory released on December 18, 2025, the Cyber Centre issued AV25-850<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> on December 19, 2025.<\/p>\n\n<p>CVE-2025-14733<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> is an Out-of-Bounds Write vulnerability (CWE-787)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> within the iked (Internet Key Exchange Daemon) process used for <abbr title=\"internet key exchange version 2\">IKEv2<\/abbr> <abbr title=\"virtual private network\">VPN<\/abbr> connections. This flaw could allow a remote, unauthenticated attacker to execute arbitrary code on vulnerable Firebox devices. The vulnerability impacts both Mobile User <abbr title=\"virtual private network\">VPN<\/abbr> with <abbr title=\"internet key exchange version 2\">IKEv2<\/abbr> and Branch Office <abbr title=\"virtual private network\">VPN<\/abbr> configurations using <abbr title=\"internet key exchange version 2\">IKEv2<\/abbr> when a dynamic gateway peer is enabled or was previously enabled.<\/p>\n\n<p>Open-source reporting indicates that CVE-2025-14733 is being exploited.<\/p>\n\n<p>On December 19, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-14733 to their Known Exploited Vulnerabilities (KEV) Database<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations patch their WatchGuard Fireware <abbr title=\"operating system\">OS<\/abbr> to the following versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Vulnerable version<\/th>\n\t\t\t<th scope=\"col\">Resolved version<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>2025.1<\/td>\n\t\t\t<td>2025.1.4<\/td>\n\t\t<\/tr><tr><td>12.x<\/td>\n\t\t\t<td>12.11.6<\/td>\n\t\t<\/tr><tr><td>12.5.x (T15 &amp; T35 models)<\/td>\n\t\t\t<td>12.5.15<\/td>\n\t\t<\/tr><tr><td>12.3.1 (FIPS-certified release)<\/td>\n\t\t\t<td>12.3.1_Update4 (B728352)<\/td>\n\t\t<\/tr><tr><td>11.x<\/td>\n\t\t\t<td>End of Life<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>The Cyber Centre strongly advises organizations to take the following actions:<\/p>\n\n<ul><li>Immediately update Firebox appliances to the latest patched Fireware OS versions<\/li>\n\t<li>Review system logs and network traffic for any indicators of compromise (IOCs), as outlined in the vendor\u2019s advisory<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/li>\n\t<li>Implement temporary mitigations\/workarounds if patching cannot be performed right away<\/li>\n\t<li>Rotate all credentials and secrets on vulnerable devices that may have been exposed<\/li>\n<\/ul><p>If patching is not feasible at this time, organizations should follow WatchGuard\u2019s security <span class=\"nowrap\">advisory<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/span>, which includes the following temporary workarounds<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>:<\/p>\n\n<ul><li>Disable dynamic peer Branch Office <abbr title=\"virtual private network\">VPN<\/abbr> (BOVPN) configurations<\/li>\n\t<li>Create aliases and apply new firewall policies to restrict exposure<\/li>\n\t<li>Disable default <abbr title=\"virtual private network\">VPN<\/abbr> policies to reduce attack surface<\/li>\n<\/ul><p>In addition, the Cyber Centre also strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>:<\/p>\n\n<ul><li>Patching operating systems and applications<\/li>\n\t<li>Segment and separate information<\/li>\n\t<li>Isolating Web-Facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert is discovered, recipients are encouraged to report via <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2025-00027\">WatchGuard Firebox iked Out of Bounds Write Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/watchguard-security-advisory-av25-850\">WatchGuard security advisory (AV25-850)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-14733\">CVE-2025-14733 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/787.html\">CWE-787: Out-of-bounds Write<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-14733\">CISA KEV: CVE-2025-14733<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/techsearch.watchguard.com\/KB?type=Article&amp;SFDCID=kA1Vr000000DMXNKA4&amp;lang=en_US\">WatchGuard\u00a0- Secure Access to Branch Office VPNs that Use IPSec and IKEv2<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-020-vulnerability-impacting-watchguard-fireware-os-cve-2025-14733","alert_type":397,"serial_number":"AL25-020","subject":"other","moderation_state":"published","external_url":null},{"nid":7126,"title":"Red Hat security advisory (AV25-858)","uuid":"7c797979-dd49-43d2-82c4-898d05aa751c","banner":null,"lang":"en","date_modified":"2025-12-23","date_modified_ts":"2025-12-23T14:21:20Z","date_created":"2025-12-23T14:16:19Z","summary":null,"body":["<article data-history-node-id=\"7126\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av25-858\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV25-858<br \/><strong>Date:<\/strong> December\u00a023, 2025<\/p>\n\n<p>Between December\u00a015 and 21, 2025, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av25-858","alert_type":396,"serial_number":"AV25-858","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7127,"title":"Ubuntu security advisory (AV25-859)","uuid":"048ddd63-9bcc-4396-828b-5b58b84d7b45","banner":null,"lang":"en","date_modified":"2025-12-23","date_modified_ts":"2025-12-23T14:27:19Z","date_created":"2025-12-23T14:16:19Z","summary":null,"body":["<article data-history-node-id=\"7127\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-859\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV25-859<br \/><strong>Date:<\/strong> December\u00a023, 2025<\/p>\n\n<p>Between December\u00a015 and 21, 2025, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.04<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av25-859","alert_type":396,"serial_number":"AV25-859","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7128,"title":"VMware security advisory (AV25-860)","uuid":"b82bfd3a-500d-4cfc-85dc-0de50fcf16d4","banner":null,"lang":"en","date_modified":"2025-12-23","date_modified_ts":"2025-12-23T16:19:21Z","date_created":"2025-12-23T16:15:45Z","summary":null,"body":["<article data-history-node-id=\"7128\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-860\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-860<br \/><strong>Date: <\/strong>December 23, 2025<\/p>\n\n<p>Between December 15 and 21, 2025, VMware published security advisories to address vulnerabilities in multiple Tanzu products:<\/p>\n\n<ul><li>.NET Core Tanzu Buildpack \u2013 version prior to 2.4.71 and 2.4.72<\/li>\n\t<li>Cloud Native Buildpacks for VMware Tanzu Platform \u2013 versions prior to 0.6.1<\/li>\n\t<li>Elastic Application Runtime for VMware Tanzu Platform \u2013 versions prior to 10.2.6+LTS-T, 10.3.2 and 6.0.23+LTS-T<\/li>\n\t<li>Extended App Support for Tanzu Platform \u2013 version prior to 1.0.11<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-860","alert_type":396,"serial_number":"AV25-860","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7129,"title":"TeamViewer security advisory (AV25-861)","uuid":"fc1f5a0b-54eb-4d2c-b78d-1b29d70efb42","banner":null,"lang":"en","date_modified":"2025-12-23","date_modified_ts":"2025-12-23T18:56:58Z","date_created":"2025-12-23T18:51:41Z","summary":null,"body":["<article data-history-node-id=\"7129\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-861\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-861<br \/><strong>Date: <\/strong>December 23, 2025<\/p>\n\n<p>On December 11, 2025, TeamViewer published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>TeamViewer DEX Client \u2013 NomadBranch.exe \u2013 versions prior to 1E Client 25.11.0.29<\/li>\n\t<li>TeamViewer DEX Client \u2013 NomadBranch.exe \u2013 versions prior to 1E Client 25.9.0.46 - HF-PLTPKG-524 (Hotfix)<\/li>\n\t<li>TeamViewer DEX Client \u2013 NomadBranch.exe \u2013 versions prior to 1E Client 25.5.0.53 - HF-PLTPKG-526 (Hotfix)<\/li>\n\t<li>TeamViewer DEX Client \u2013 NomadBranch.exe \u2013 versions prior to 1E Client 24.5.0.69 - HF-PLTPKG-525 (Hotfix)<\/li>\n\t<li>TeamViewer DEX \u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/tv-2025-1005\/\">Improper input validation in TeamViewer<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/tv-2025-1006\/\">Command Injection and Privilege Escalation vulnerabilities in TeamViewer<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">TeamViewer Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av25-861","alert_type":396,"serial_number":"AV25-861","subject":"other","moderation_state":"published","external_url":null},{"nid":7130,"title":"MongoDB security advisory (AV25-862) - Update 1","uuid":"8933fe0b-cd54-421f-a427-1aeb308da028","banner":null,"lang":"en","date_modified":"2025-12-24","date_modified_ts":"2025-12-24T15:54:36Z","date_created":"2025-12-24T15:49:22Z","summary":null,"body":["<article data-history-node-id=\"7130\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory-av25-862\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV25-862<br \/><strong>Date:<\/strong> December\u00a024, 2025<br \/><strong>Updated:<\/strong> December\u00a029, 2025<\/p>\n\n<p>On December\u00a015, 2025, MongoDB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>MongoDB\u00a0\u2013 versions 8.2.0 to 8.2.2<\/li>\n\t<li>MongoDB\u00a0\u2013 versions 8.0.0 to 8.0.16<\/li>\n\t<li>MongoDB\u00a0\u2013 versions 7.0.0 to 7.0.26<\/li>\n\t<li>MongoDB\u00a0\u2013 versions 6.0.0 to 6.0.26<\/li>\n\t<li>MongoDB\u00a0\u2013 versions 5.0.0 to 5.0.31<\/li>\n\t<li>MongoDB\u00a0\u2013 versions 4.4.0 to 4.4.29<\/li>\n\t<li>MongoDB Server v4.2\u00a0\u2013 all versions<\/li>\n\t<li>MongoDB Server v4.0\u00a0\u2013 all versions<\/li>\n\t<li>MongoDB Server v3.6\u00a0\u2013 all versions<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>On December 29, 2025, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-14847 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/jira.mongodb.org\/browse\/SERVER-115508\">MongoDB\u00a0- Make minimally sized buffers for uncompressed Messages (CVE-2025-14847)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-14847\">CISA KEV\u00a0: CVE-2025-14847<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory-av25-862","alert_type":396,"serial_number":"AV25-862","subject":"other","moderation_state":"published","external_url":null},{"nid":7131,"title":"AL25-021 - Vulnerability affecting MongoDB - CVE-2025-14847","uuid":"90112e79-7236-45ad-9bb7-ecf209d3b189","banner":null,"lang":"en","date_modified":"2025-12-29","date_modified_ts":"2025-12-29T15:49:54Z","date_created":"2025-12-29T15:48:38Z","summary":null,"body":["<article data-history-node-id=\"7131\" about=\"\/en\/alerts-advisories\/al25-021-vulnerability-affecting-mongodb-cve-2025-14847\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL25-021<br \/><strong>Date:<\/strong> December\u00a029, 2025<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a high-severity vulnerability in MongoDB Server<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. In response to the vendor advisory released on December 19, 2025, the Cyber Centre issued AV25-862<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> on December 24, 2025.<\/p>\n\n<p>Tracked as CVE-2025-14847<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability allows an unauthenticated remote attacker to read uninitialized heap memory due to mismatched length fields (CWE-130)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> in zlib-compressed protocol headers. The vulnerability occurs prior to authentication and affects multiple supported and legacy MongoDB versions.<\/p>\n\n<p>The Cyber Centre has observed open-source reporting indicating that multiple Proofs of Concept (PoC) are available and that this vulnerability is being exploited in the wild<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected MongoDB Server(s) to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected version<\/th>\n\t\t\t<th scope=\"col\">Fixed version<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>MongoDB 8.2<\/td>\n\t\t\t<td>8.2.0\u00a0\u2013\u00a08.2.2<\/td>\n\t\t\t<td>8.2.3<\/td>\n\t\t<\/tr><tr><td>MongoDB 8.0<\/td>\n\t\t\t<td>8.0.0\u00a0\u2013\u00a08.0.16<\/td>\n\t\t\t<td>8.0.17<\/td>\n\t\t<\/tr><tr><td>MongoDB 7.0<\/td>\n\t\t\t<td>7.0.0\u00a0\u2013\u00a07.0.27<\/td>\n\t\t\t<td>7.0.28<\/td>\n\t\t<\/tr><tr><td>MongoDB 6.0<\/td>\n\t\t\t<td>6.0.0\u00a0\u2013\u00a06.0.26<\/td>\n\t\t\t<td>6.0.27<\/td>\n\t\t<\/tr><tr><td>MongoDB 5.0<\/td>\n\t\t\t<td>5.0.0\u00a0\u2013\u00a05.0.31<\/td>\n\t\t\t<td>5.0.32<\/td>\n\t\t<\/tr><tr><td>MongoDB 4.4<\/td>\n\t\t\t<td>4.4.0\u00a0\u2013\u00a04.4.29<\/td>\n\t\t\t<td>4.4.30<\/td>\n\t\t<\/tr><tr><td>MongoDB 4.2<\/td>\n\t\t\t<td>All versions<\/td>\n\t\t\t<td>No vendor fix; upgrade to fixed version<\/td>\n\t\t<\/tr><tr><td>MongoDB 4.0<\/td>\n\t\t\t<td>All versions<\/td>\n\t\t\t<td>No vendor fix; upgrade to fixed version<\/td>\n\t\t<\/tr><tr><td>MongoDB 3.6<\/td>\n\t\t\t<td>All versions<\/td>\n\t\t\t<td>No vendor fix; upgrade to fixed version<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>If immediate patching is not possible, reduce exposure by:<\/p>\n\n<ul><li>Disabling zlib compression by starting mongod\/mongos with networkMessageCompressors or net.compression.compressors options that omit zlib (use snappy or zstd).<\/li>\n\t<li>Restricting network access to MongoDB to trusted <abbr title=\"internet protocols\">IPs<\/abbr>; avoid direct internet exposure.<\/li>\n<\/ul><p class=\"mrgn-tp-lg\">As a precaution, it is recommended that organizations review their logs for potential signs of compromise including:<\/p>\n\n<ul><li>Monitor MongoDB logs for anomalous pre-authentication connections or unexpected errors.<\/li>\n<\/ul><p class=\"mrgn-tp-lg\">In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p class=\"mrgn-tp-lg\">Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"https:\/\/www.cyber.gc.ca\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/jira.mongodb.org\/browse\/SERVER-115508\">MongoDB Jira (SERVER-115508) vendor advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/mongodb-security-advisory-av25-862\">MongoDB security advisory (AV25-862)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-14847\">NVD\u00a0- CVE-2025-14847 <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/130.html\">CWE130: Improper Handling of Length Parameter Inconsistency<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.wiz.io\/blog\/mongobleed-cve-2025-14847-exploited-in-the-wild-mongodb\">MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al25-021-vulnerability-affecting-mongodb-cve-2025-14847","alert_type":397,"serial_number":"AL25-021","subject":"other","moderation_state":"published","external_url":null},{"nid":7132,"title":"IBM security advisory (AV25-863)","uuid":"76224ba2-559d-4ae2-873f-91fe7644c1c5","banner":null,"lang":"en","date_modified":"2025-12-29","date_modified_ts":"2025-12-29T19:42:17Z","date_created":"2025-12-29T18:59:40Z","summary":null,"body":["<article data-history-node-id=\"7132\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av25-863\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-863<br \/><strong>Date: <\/strong>December 29, 2025<\/p>\n\n<p>Between December 22 and 28, 2025, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM API Connect\u00a0\u2013 versions 10.0.8.0 to 10.0.8.5 and V10.0.11.0<\/li>\n\t<li>IBM API Connect Enterprise\u00a0\u2013 versions 13.0.1.0 to 13.0.5.2 and 12.0.1.0 to 12.0.12.20<\/li>\n\t<li>IBM Big SQL on IBM Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Insights\u00a0\u2013 versions 25.0.0, 24.0.1 and 24.0.0<\/li>\n\t<li>IBM CICS TX Advanced\u00a0\u2013 versions 10.1 and 11.1<\/li>\n\t<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM CICS Transaction Gateway Desktop Edition\u00a0\u2013 versions 9.1, 9.2, 9.3 and 10.1<\/li>\n\t<li>IBM CICS Transaction Gateway for Multiplatforms\u00a0\u2013 versions 9.1, 9.2, 9.3 and 10.1<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 version 1.0.0 to 2.1.0<\/li>\n\t<li>IBM DataPower Gateway 10.6CD\u00a0\u2013 versions 10.6.1.0 to 10.6.5.0<\/li>\n\t<li>IBM Edge Data Collector\u00a0\u2013 versions 9.1, 9.0 and 8.11<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\u00a0\u2013 versions 9.1, 9.0, 8.11 and 8.10<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 AI Service\u00a0\u2013 version 9.1<\/li>\n\t<li>IBM Netezza Appliance\u00a0\u2013 version 1.0.0.0<\/li>\n\t<li>IBM Sterling Connect:Direct File Agent\u00a0\u2013 versions 1.4.0.0 to 1.4.0.5_iFix001 on Solaris SPARC<\/li>\n\t<li>IBM Sterling Connect:Direct File Agent\u00a0\u2013 versions 1.4.0. to 1.4.0.5 with bundles JRE on AIX, Linux X64, Linux PPC and Windows<\/li>\n\t<li>IBM StreamSets Data Collector\u00a0\u2013 versions 5.0.0 to 6.4.1<\/li>\n\t<li>IBM Tivoli Application Dependency Discovery Manager\u00a0\u2013 versions 7.3.0.0 to 7.3.0.11<\/li>\n\t<li>IBM Total Storage Service Console (TSSC) \/ TS4500 IMC \u2013 multiple versions<\/li>\n\t<li>IBM TXSeries for Mutiplatforms\u00a0\u2013 versions 8.2, 9.1, 10.1 and 11.1<\/li>\n\t<li>IBM webMethods Managed File Transfer (on-prem)\u00a0\u2013 version 11.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av25-863","alert_type":396,"serial_number":"AV25-863","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7133,"title":"VMware security advisory (AV25-864)","uuid":"8cdca2e3-767a-435b-aa20-30f96beef242","banner":null,"lang":"en","date_modified":"2025-12-29","date_modified_ts":"2025-12-29T19:55:14Z","date_created":"2025-12-29T19:47:53Z","summary":null,"body":["<article data-history-node-id=\"7133\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av25-864\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-864<br \/><strong>Date: <\/strong>December 29, 2025<\/p>\n\n<p>Between December 22 and 28, 2025, VMware published security advisories to address critical vulnerabilities in multiple Tanzu products:<\/p>\n\n<ul><li>AI Services for VMware Tanzu Platform\u00a0\u2013 versions prior to 10.3.2<\/li>\n\t<li>Application Services for VMware Tanzu Platform\u00a0\u2013 versions prior to 3.3.13<\/li>\n\t<li>Elastic Application Runtime Windows add-on for VMware Tanzu Platform\u00a0\u2013 versions prior to 10.2.6+LTS-T, 10.3.2 and 6.0.23+LTS-T<\/li>\n\t<li>Healthwatch\u00a0\u2013 versions prior to 2.3.4<\/li>\n\t<li>Isolation Segmentation for VMware Tanzu Platform\u00a0\u2013 versions prior to 10.2.6+LTS-T, 10.3.2 and 6.0.23+LTS-T<\/li>\n\t<li>Java Buildpack\u00a0\u2013 versions prior to 4.86.0<\/li>\n\t<li>Stemcells (Windows)\u00a0\u2013 versions prior to 2019.93.x<\/li>\n\t<li>Tanzu Hub\u00a0\u2013 versions prior to 10.3.2<\/li>\n\t<li>VMware Tanzu for Postgres on Tanzu Platform\u00a0\u2013 versions prior to 10.2.2<\/li>\n\t<li>VMware Tanzu GemFire on Tanzu Platform\u00a0\u2013 versions prior to 2.2.1<\/li>\n\t<li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 7.7.0<\/li>\n\t<li>VMware Tanzu Greenplum SQL Editor\u00a0\u2013 versions prior to 1.2.1<\/li>\n\t<li>VMware Tanzu RabbitMQ on Tanzu Platform\u00a0\u2013 versions prior to 10.1.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av25-864","alert_type":396,"serial_number":"AV25-864","subject":"other","moderation_state":"published","external_url":null},{"nid":7134,"title":"Dell security advisory (AV25-865)","uuid":"006b1f8c-bb3e-4bf6-9e15-2b920021e463","banner":null,"lang":"en","date_modified":"2025-12-29","date_modified_ts":"2025-12-29T20:34:34Z","date_created":"2025-12-29T20:21:40Z","summary":null,"body":["<article data-history-node-id=\"7134\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av25-865\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-865<br \/><strong>Date: <\/strong>December 29, 2025<\/p>\n\n<p>Between December 22 and 28, 2025, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Storage Resource Manager (SRM)\u00a0\u2013 version prior to 6.0.0.1<\/li>\n\t<li>Dell Storage Monitoring and Reporting (SMR)\u00a0\u2013 version prior to 6.0.0.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000405611\/dsa-2025-455-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities?lang=en\">Dell DSA-2025-455<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Dell Security advisories and notices<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av25-865","alert_type":396,"serial_number":"AV25-865","subject":"dell","moderation_state":"published","external_url":null},{"nid":7135,"title":"SmarterTools security advisory (AV25-866) \u2013 Update 1","uuid":"14d26a49-9fb3-4ddc-9e44-c82ce7a94382","banner":null,"lang":"en","date_modified":"2026-01-27","date_modified_ts":"2026-01-27T15:18:22Z","date_created":"2025-12-30T21:03:52Z","summary":null,"body":["<article data-history-node-id=\"7135\" about=\"\/en\/alerts-advisories\/smartertools-security-advisory-av25-866\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV25-866<br \/><strong>Date: <\/strong>December\u00a030, 2025<br \/><strong>Updated:<\/strong> January\u00a027, 2026<\/p>\n\n<p>On October\u00a09, 2025, SmarterTools published a security update to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>SmarterMail\u00a0\u2013 version Build 9406 and prior<\/li>\n<\/ul><p>Users and administrators of affected product versions are advised to update immediately to SmarterMail version Build 9413 or greater.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On January\u00a026, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-52691 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.smartertools.com\/smartermail\/release-notes\/current\">SmarterTools\u00a0- SmarterMail Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.smartertools.com\/smartermail\/downloads\">SmarterTools\u00a0- Download SmarterMail<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691\">CISA KEV: CVE-2025-52691<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/smartertools-security-advisory-av25-866","alert_type":396,"serial_number":"AV25-866","subject":"other","moderation_state":"published","external_url":null},{"nid":7136,"title":"IBM security advisory (AV26-001)","uuid":"5e2fd234-5c9a-4b9d-929b-88c957902615","banner":null,"lang":"en","date_modified":"2026-01-05","date_modified_ts":"2026-01-05T13:51:16Z","date_created":"2026-01-05T13:34:03Z","summary":null,"body":["<article data-history-node-id=\"7136\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-001\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-001<br \/><strong>Date: <\/strong>January 5, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between December 29, 2025, and January 4, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise Certified Containers Operands\u00a0\u2013 versions 12.0 LTS: 12.0.12-r1 to 12.0.12-r18<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\u00a0\u2013 versions CD: 12.0.10.0-r3 to 12.0.12.5-r1, 13.0.1.0-r1 to 13.0.5.2-r1<\/li>\n\t<li>IBM App Connect Operator\u00a0\u2013 versions 12.0 LTS: 12.0.0 to 12.0.18<\/li>\n\t<li>IBM App Connect Operator\u00a0\u2013 versions CD: 11.1.0 to 11.6.0, 12.1.0 to 12.18.0<\/li>\n\t<li>IBM Event Processing\u00a0\u2013 versions 1.0.0 to 1.4.4<\/li>\n\t<li>IBM Maximo Application Suite - Monitor Component\u00a0\u2013 versions 9.1,9.0,8.11 and 8.10<\/li>\n\t<li>IBM Storage Ceph\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM watsonx Assistant Cartridge\u00a0\u2013 versions 4.0 to 5.2.2<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge\u00a0- Assistant Builder Component\u00a0\u2013 versions 5.0 to 5.2.2<\/li>\n\t<li>Maximo AI Service\u00a0\u2013 version 9.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">TThe Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-001","alert_type":396,"serial_number":"AV26-001","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7137,"title":"Google Chrome security advisory (AV26-002)","uuid":"00a4f62c-2a98-46e7-9a2f-b66874d6564e","banner":null,"lang":"en","date_modified":"2026-01-07","date_modified_ts":"2026-01-07T14:46:07Z","date_created":"2026-01-07T14:39:33Z","summary":null,"body":["<article data-history-node-id=\"7137\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-002\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-002<br \/><strong>Date:<\/strong> January\u00a07, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On January\u00a06, 2026, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 143.0.7499.192\/.193 (Windows\/Mac) and 143.0.7499.192 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/01\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-002","alert_type":396,"serial_number":"AV26-002","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7138,"title":"GitHub security advisory (AV26-003)","uuid":"9cab470a-19f1-4bd3-b2d7-7f3907df169b","banner":null,"lang":"en","date_modified":"2026-01-07","date_modified_ts":"2026-01-07T14:59:54Z","date_created":"2026-01-07T14:44:19Z","summary":null,"body":["<article data-history-node-id=\"7138\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-003\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-003<br \/><strong>Date: <\/strong>January 7, 2026<\/p>\n\n<p>On January 6, 2026, GitHub published security advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.1<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.4<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.10<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.13<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.15.x prior to 3.15.17<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.22<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.1<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.4<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.10<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.13<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes\">Enterprise Server 3.15.17<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">Enterprise Server 3.14.22<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-003","alert_type":396,"serial_number":"AV26-003","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7139,"title":"n8n security advisory (AV26-004)","uuid":"ef6e0354-43e4-48c3-9e90-0b374ea3b74f","banner":null,"lang":"en","date_modified":"2026-01-07","date_modified_ts":"2026-01-07T15:35:09Z","date_created":"2026-01-07T15:03:04Z","summary":null,"body":["<article data-history-node-id=\"7139\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-004\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-004<br \/><strong>Date: <\/strong>January 7, 2026<\/p>\n\n<p>On January 6, 2026, n8n published security updates to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>n8n\u00a0\u2013 versions 0.123.0 to versions prior to 1.121.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-v364-rw7m-3263\">RCE <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">via Arbitrary File Write<\/span> (CVE-2026-21877)<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-v4pr-fm98-w9pg\">Unauthenticated File Access via Improper Webhook Request Handling (CVE-2026-21858)<\/a><\/li>\n\t<li><a href=\"https:\/\/n8n.io\/\">n8n website<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-004","alert_type":396,"serial_number":"AV26-004","subject":"other","moderation_state":"published","external_url":null},{"nid":7140,"title":"Android security advisory \u2013 January 2026 monthly rollup (AV26-005)","uuid":"c4bd778a-fb98-4dd9-a3d8-ca2512d2eac9","banner":null,"lang":"en","date_modified":"2026-01-07","date_modified_ts":"2026-01-07T15:51:49Z","date_created":"2026-01-07T15:46:03Z","summary":null,"body":["<article data-history-node-id=\"7140\" about=\"\/en\/alerts-advisories\/android-security-advisory-january-2026-monthly-rollup-av26-005\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-005<br \/><strong>Date: <\/strong>January\u00a07, 2026<\/p>\n\n<p>On January\u00a06, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-01-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-january-2026-monthly-rollup-av26-005","alert_type":396,"serial_number":"AV26-005","subject":"android","moderation_state":"published","external_url":null},{"nid":7141,"title":"Qualcomm security advisory \u2013 January 2026 monthly rollup (AV26-006)","uuid":"89d7fe80-af05-4d92-8da2-0517e8c9d6d7","banner":null,"lang":"en","date_modified":"2026-01-07","date_modified_ts":"2026-01-07T16:50:20Z","date_created":"2026-01-07T15:46:04Z","summary":null,"body":["<article data-history-node-id=\"7141\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-january-2026-monthly-rollup-av26-006\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-006<br \/><strong>Date: <\/strong>January\u00a07, 2026<\/p>\n\n<p>On January\u00a05, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/january-2026-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 January<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-january-2026-monthly-rollup-av26-006","alert_type":396,"serial_number":"AV26-006","subject":"other","moderation_state":"published","external_url":null},{"nid":7142,"title":"Samsung mobile security advisory (AV26-007)","uuid":"d813db0c-918b-4bfa-b744-11ed51eb8b6c","banner":null,"lang":"en","date_modified":"2026-01-07","date_modified_ts":"2026-01-07T16:58:18Z","date_created":"2026-01-07T16:12:02Z","summary":null,"body":["<article data-history-node-id=\"7142\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-007\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-007<br \/><strong>Date:<\/strong> January\u00a07, 2026<\/p>\n\n<p>On January\u00a06, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices\u00a0\u2013 versions prior to SMR-JAN-2026<\/li>\n<\/ul><p>The most recent security update resolves multiple identified vulnerabilities.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=01\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-007","alert_type":396,"serial_number":"AV26-007","subject":"other","moderation_state":"published","external_url":null},{"nid":7143,"title":"Veeam security advisory (AV26-008)","uuid":"55dd7e19-0356-49ab-ab96-2f83daa3557b","banner":null,"lang":"en","date_modified":"2026-01-07","date_modified_ts":"2026-01-07T18:58:32Z","date_created":"2026-01-07T18:49:53Z","summary":null,"body":["<article data-history-node-id=\"7143\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-008\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-008<br \/><strong>Date:<\/strong> January\u00a07, 2026<\/p>\n\n<p>On January\u00a06, 2026, Veeam published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2013 versions prior to 13.0.1.1071<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4792\">Vulnerabilities Resolved in Veeam Backup &amp; Replication 13.0.1.1071<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-008","alert_type":396,"serial_number":"AV26-008","subject":"other","moderation_state":"published","external_url":null},{"nid":7144,"title":"GitLab security advisory (AV26-009)","uuid":"27c78b33-822b-439a-987c-db9e82e64cee","banner":null,"lang":"en","date_modified":"2026-01-08","date_modified_ts":"2026-01-08T17:00:25Z","date_created":"2026-01-08T16:40:48Z","summary":null,"body":["<article data-history-node-id=\"7144\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-009\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-009<br \/><strong>Date: <\/strong>January 8, 2025<\/p>\n\n<p>On January 7, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.7.1, 18.6.3 and 18.5.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.7.1, 18.6.3 and 18.5.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/01\/07\/patch-release-gitlab-18-7-1-released\/\">GitLab Patch Release: 18.7.1, 18.6.3, 18.5.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-009","alert_type":396,"serial_number":"AV26-009","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7145,"title":"Tenable security advisory (AV26-010)","uuid":"41041bb1-84ec-4ce9-804c-8efe127ee0a6","banner":null,"lang":"en","date_modified":"2026-01-08","date_modified_ts":"2026-01-08T18:45:20Z","date_created":"2026-01-08T18:14:44Z","summary":null,"body":["<article data-history-node-id=\"7145\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-010\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-010<br \/><strong>Date:<\/strong> January\u00a08, 2026<\/p>\n\n<p>On January\u00a07, 2026, Tenable published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Tenable Nessus\u00a0\u2013 versions prior to 10.9.3<\/li>\n\t<li>Tenable Nessus\u00a0\u2013 versions 11.0.0 to 11.0.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-01\">[R1] Nessus Agent Versions 11.0.3 and 10.9.3 Fix One Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-010","alert_type":396,"serial_number":"AV26-010","subject":"other","moderation_state":"published","external_url":null},{"nid":7147,"title":"Trend Micro security advisory (AV26-012)","uuid":"161e9bca-4682-4c91-ba63-544baf668f6b","banner":null,"lang":"en","date_modified":"2026-01-08","date_modified_ts":"2026-01-08T20:15:51Z","date_created":"2026-01-08T19:58:52Z","summary":null,"body":["<article data-history-node-id=\"7147\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory-av26-012\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-012<br \/><strong>Date: <\/strong>January\u00a08, 2026<\/p>\n\n<p>On January\u00a07, 2026, Trend Micro published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Apex Central (on-premise)\u00a0\u2013 versions prior to Build 7190<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/success.trendmicro.com\/en-US\/solution\/KA-0022071\">CRITICAL SECURITY BULLETIN: Trend Micro Apex Central (on-premise) January 2026 Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/success.trendmicro.com\/en-US\/vulnerability-response\/\">Trend Micro Business Success Vulnerability Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory-av26-012","alert_type":396,"serial_number":"AV26-012","subject":"other","moderation_state":"published","external_url":null},{"nid":7146,"title":"[Control systems] ABB security advisory (AV26-011)","uuid":"49f58933-b65c-4235-abad-0f6f5a7505df","banner":null,"lang":"en","date_modified":"2026-01-08","date_modified_ts":"2026-01-08T20:06:02Z","date_created":"2026-01-08T19:59:03Z","summary":null,"body":["<article data-history-node-id=\"7146\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-011\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV26-011<br \/><strong>Date:<\/strong> January\u00a08, 2026<\/p>\n\n<p>On January\u00a07, 2026, ABB published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>WebPro SNMP Card PowerValue\u00a0\u2013 version 1.1.8.k and prior<\/li>\n\t<li>WebPro SNMP Card PowerValue UL\u00a0\u2013 version 1.1.8.k and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=2CRT000009&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">WebPro SNMP Card PowerValue Multiple Vulnerabilities CVE IDs: CVE-2025-4675, CVE-2025-4676, CVE2025-4677<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-011","alert_type":398,"serial_number":"AV26-011","subject":"abb","moderation_state":"published","external_url":null},{"nid":7149,"title":"[Control Systems] Moxa security advisory (AV26-013)","uuid":"2cc03701-128b-4062-9519-751f3de59818","banner":null,"lang":"en","date_modified":"2026-01-09","date_modified_ts":"2026-01-09T20:22:58Z","date_created":"2026-01-09T20:14:52Z","summary":null,"body":["<article data-history-node-id=\"7149\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-013\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-013<br \/><strong>Date: <\/strong>January\u00a09, 2026<\/p>\n\n<p>On January\u00a09, 2026, Moxa published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>EDS-G4000 Series\u00a0\u2013 firmware version v4.1 and prior<\/li>\n\t<li>RKS-G4000 Series\u00a0\u2013 firmware version v5.0 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-256261-cve-2023-38408-openssh-vulnerability-in-ethernet-switches\">CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-013","alert_type":398,"serial_number":"AV26-013","subject":"other","moderation_state":"published","external_url":null},{"nid":7151,"title":"IBM security advisory (AV26-014)","uuid":"5f3297d6-1fc2-431c-aa24-e5d386aba696","banner":null,"lang":"en","date_modified":"2026-01-12","date_modified_ts":"2026-01-12T15:54:07Z","date_created":"2026-01-12T15:44:43Z","summary":null,"body":["<article data-history-node-id=\"7151\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-014\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-014<br \/><strong>Date: <\/strong>January 12, 2026<\/p>\n\n<p>Between January 5 and 11, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 versions V24.0.1 to V24.0.1-IF005<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 versions V25.0.0 to V25.0.0-IF002<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 versions 1.0.0 to 2.1.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\u00a0\u2013 versions 9.1, 9.0, 8.11 and 8.10<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.8.4 to 4.8.5<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 5.0.0 to 5.2.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-014","alert_type":396,"serial_number":"AV26-014","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7153,"title":"Dell security advisory (AV26-015)","uuid":"a8189c13-e311-4e46-9703-075105cec293","banner":null,"lang":"en","date_modified":"2026-01-12","date_modified_ts":"2026-01-12T16:04:04Z","date_created":"2026-01-12T15:55:57Z","summary":null,"body":["<article data-history-node-id=\"7153\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-015\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-015<br \/><strong>Date: <\/strong>January 12, 2026<\/p>\n\n<p>Between January 5 and 11, 2026, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerStore T Security Family OS\u00a0\u2013 versions prior to 4.1.0.4-2633110<\/li>\n\t<li>Dell Client Platform\u00a0\u2013 multiple applications and versions<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 versions 8.0.000 to 8.0.361<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000412340\/dsa-2026-039-dell-powerstore-t-security-update-for-multiple-vulnerabilities\">DSA-2026-039: Dell PowerStore T Security Update for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000412345\/dsa-2025-422-security-update-for-dell-client-platform-for-an-insyde-bios-vulnerability\">DSA-2025-422: Security Update for Dell Client Platform for an INSYDE BIOS Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000412375\/dsa-2026-028-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities\">DSA-2026-028: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-015","alert_type":396,"serial_number":"AV26-015","subject":"dell","moderation_state":"published","external_url":null},{"nid":7154,"title":"Ubuntu security advisory (AV26-016)","uuid":"cb3b0848-a744-4d46-aa6c-bccacb54ebaf","banner":null,"lang":"en","date_modified":"2026-01-12","date_modified_ts":"2026-01-12T16:13:29Z","date_created":"2026-01-12T16:05:36Z","summary":null,"body":["<article data-history-node-id=\"7154\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-016\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-016<br \/><strong>Date: <\/strong>January 12, 2026<\/p>\n\n<p>Between January 5 and 11, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-016","alert_type":396,"serial_number":"AV26-016","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7155,"title":"Microsoft Edge security advisory (AV26-017)","uuid":"785d1cd3-4186-4205-9fc8-5812ecaefc61","banner":null,"lang":"en","date_modified":"2026-01-12","date_modified_ts":"2026-01-12T16:26:23Z","date_created":"2026-01-12T16:20:46Z","summary":null,"body":["<article data-history-node-id=\"7155\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-017\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-017<br \/><strong>Date: <\/strong>January 12, 2026<\/p>\n\n<p>On January 9, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 143.0.3650.139<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-9-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-017","alert_type":396,"serial_number":"AV26-017","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7156,"title":"VMware security advisory (AV26-018)","uuid":"b6ab321f-dcca-44af-b4ca-90197e96aa5e","banner":null,"lang":"en","date_modified":"2026-01-12","date_modified_ts":"2026-01-12T16:34:53Z","date_created":"2026-01-12T16:28:41Z","summary":null,"body":["<article data-history-node-id=\"7156\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-018\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-018<br \/><strong>Date: <\/strong>January 12, 2026<\/p>\n\n<p>Between January 5 and 11, 2026, VMware published security advisory to address vulnerabilities in Tanzu product.<\/p>\n\n<ul><li>VMware Tanzu Greenplum Backup and Restore\u00a0\u2013 versions prior to 1.32.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36755\">Product Release Advisory\u00a0- VMware Tanzu Greenplum Backup and Restore 1.32.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-018","alert_type":396,"serial_number":"AV26-018","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7157,"title":"[Control systems] CISA ICS security advisories (AV26\u2013019)","uuid":"a718860d-0e80-4633-b719-0fd6dad2e237","banner":null,"lang":"en","date_modified":"2026-01-12","date_modified_ts":"2026-01-12T17:17:30Z","date_created":"2026-01-12T17:11:04Z","summary":null,"body":["<article data-history-node-id=\"7157\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-019\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013019<br \/><strong>Date: <\/strong>January 12, 2026<\/p>\n\n<p>Between January 5 and 11, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Columbia Weather Systems MicroServer firmware\u00a0\u2013 versions prior to MS_4.1_14142<\/li>\n\t<li>Hitachi Energy Asset Suite\u00a0\u2013 versions 9.7 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-006-01\">Columbia Weather Systems MicroServer<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-008-01\">Hitachi Energy Asset Suite<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-019","alert_type":398,"serial_number":"AV26\u2013019","subject":"ics","moderation_state":"published","external_url":null},{"nid":7158,"title":"AL26-001 \u2013 Vulnerabilities affecting n8n \u2013 CVE-2026-21858, CVE-2026-21877 and CVE-2025-68613","uuid":"06acaca1-6ac9-4e84-a935-adebd3398b8b","banner":null,"lang":"en","date_modified":"2026-01-12","date_modified_ts":"2026-01-12T18:45:54Z","date_created":"2026-01-12T18:44:35Z","summary":null,"body":["<article data-history-node-id=\"7158\" about=\"\/en\/alerts-advisories\/al26-001-vulnerabilities-affecting-n8n-cve-2026-21858-cve-2026-21877-cve-2025-68613\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-001<br \/><strong>Date:<\/strong> January\u00a012, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On January\u00a07, 2026, The Cyber Centre became aware of multiple high-severity vulnerabilities in n8n, a popular workflow automation software. CVE-2026-21858<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, is an Improper Input Validation vulnerability that may allow an unauthenticated remote attacker to execute arbitrary code (CWE-20)<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. The primary issue stems from how the n8n webhook processes incoming data and manages file handling. Webhooks, used to ingest data from external applications, are triggered after requests are parsed by the parseRequestBody() function, where insufficient validation creates an attack vector<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>CVE-2026-21877<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>, is an Improper Control of Generation of Code ('Code Injection') vulnerability that may allow a remote, privileged attacker to execute arbitrary code (CWE-94)<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>, and may be chained with the unauthenticated vulnerability CVE-2026-21858 to achieve code execution or arbitrary file writes on certain vulnerable versions of n8n software.<\/p>\n\n<p>CVE\u20112025\u201168613<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> is a critical remote code execution vulnerability resulting from insufficient isolation of user-supplied expressions in workflow configurations. This flaw enables authenticated attackers to run arbitrary code with the same privileges as the n8n process, potentially leading to complete compromise of the instance.<\/p>\n\n<p>On January\u00a07, 2026, in response to the vendor advisory, the Cyber Centre released AV26-004<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre has observed open-source reporting that multiple Proof-of-Concepts (PoCs) are publicly available, including one that chains CVE\u20112026\u201121858 and CVE\u20112025\u201168613<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>. This exploit sequence enables unauthenticated <abbr title=\"Remote Code Execution\">RCE<\/abbr> by first extracting sensitive data and then executing arbitrary commands on the affected server.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected instances of n8n to the latest supported version. The table below shows affected and patched versions for each CVE:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">CVE<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Patched versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>n8n<\/td>\n\t\t\t<td>CVE-2025-68613<\/td>\n\t\t\t<td>version 0.211.0 to versions prior to 1.120.4, 1.121.1 and 1.122.0<\/td>\n\t\t\t<td>1.120.4, 1.121.1, and 1.122.0<\/td>\n\t\t<\/tr><tr><td>n8n<\/td>\n\t\t\t<td>CVE-2026-21858<\/td>\n\t\t\t<td>version 1.65.0 to versions prior to 1.121.0<\/td>\n\t\t\t<td>1.121.0<\/td>\n\t\t<\/tr><tr><td>n8n<\/td>\n\t\t\t<td>CVE-2026-21877<\/td>\n\t\t\t<td>versions prior to 0.121.2<\/td>\n\t\t\t<td>1.121.3<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>Note: n8n 1.X version will reach end of life (EOL) by beginning of March 2026<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<p>If patching is not immediately possible, the vendor suggests that users may restrict or disable publicly accessible webhook and form endpoints until upgrading is complete<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-21858\">NVD\u00a0- CVE-2026-21858<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/20.html\">CWE20: Improper Input Validation<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/critical-n8n-vulnerability-cvss-100.html\">Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-21877\">NVD\u00a0- CVE-2026-21877<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/94.html\">CWE94: Improper Control of Generation of Code ('Code Injection')<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-68613\">NVD\u00a0\u2013 CVE-2025-68613<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-004\">n8n security advisory (AV26-004)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/www.databreachtoday.com\/no-rest-in-2026-as-patch-alerts-amass-for-cisco-hpe-n8n-a-30482\">No Rest in 2026 as Patch Alerts Amass for Cisco, HPE and n8n<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/blog.n8n.io\/introducing-n8n-2-0\/\">Introducing n8n 2.0<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-v4pr-fm98-w9pg\">Unauthenticated File Access via Improper Webhook Request Handling (CVE-2026-21858)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-001-vulnerabilities-affecting-n8n-cve-2026-21858-cve-2026-21877-cve-2025-68613","alert_type":397,"serial_number":"AL26-001","subject":"other","moderation_state":"published","external_url":null},{"nid":7159,"title":"[Control systems] Siemens security advisory (AV26-020)","uuid":"4ad5410e-87df-4c4d-bfbe-b3ede84553c3","banner":null,"lang":"en","date_modified":"2026-01-13","date_modified_ts":"2026-01-13T15:26:26Z","date_created":"2026-01-13T15:13:15Z","summary":null,"body":["<article data-history-node-id=\"7159\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-020\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV26-020<br \/><strong>Date:<\/strong> January\u00a013, 2026<\/p>\n\n<p>On January\u00a013, 2026, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>Industrial Edge Device Kit\u00a0\u2013 x86-64 V1.24\u00a0\u2013 version V1.24.2 and prior<\/li>\n\t<li>Industrial Edge Device Kit\u00a0\u2013 x86-64 V1.25\u00a0\u2013 version V1.25.1 and prior<\/li>\n\t<li>RUGGEDCOM APE1808\u00a0\u2013 contact customer support to receive patch and update information<\/li>\n\t<li>SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants)\u00a0\u2013 version V1.3 and prior<\/li>\n\t<li>SIMATIC ET 200SP IM 155-6 PN R1 (6ES7155-6AU00-0HM0)\u00a0\u2013 version V6.0.1 and prior<\/li>\n\t<li>SIMATIC ET 200SP IM 155-6 PN\/3 HF (6ES7155-6AU30-0CN0)\u00a0\u2013 version V4.2.2 and prior<\/li>\n\t<li>SIMATIC PN\/PN Coupler (6ES7158-3AD10-0XA0)\u00a0\u2013 version V6.0.0 and prior<\/li>\n\t<li>SIMATIC PN\/MF Coupler (6ES7158-3MU10-0XA0)\u00a0\u2013 all versions<\/li>\n\t<li>SIPLUS NET PN\/PN Coupler (6AG2158-3AD10-4XA0)\u00a0\u2013 version V6.0.0 and prior<\/li>\n\t<li>Siemens Industrial Edge Devices\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>TeleControl Server Basic\u00a0\u2013 versions V3.1.2.4 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-020","alert_type":398,"serial_number":"AV26-020","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7160,"title":"SAP security advisory \u2013 January 2026 monthly rollup (AV26-021)","uuid":"245a0aa8-2242-4ac3-88b8-c1047ef0ba70","banner":null,"lang":"en","date_modified":"2026-01-13","date_modified_ts":"2026-01-13T16:32:22Z","date_created":"2026-01-13T15:13:15Z","summary":null,"body":["<article data-history-node-id=\"7160\" about=\"\/en\/alerts-advisories\/sap-security-advisory-january-2026-monthly-rollup-av26-021\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV26-021<br \/><strong>Date:<\/strong> January\u00a013, 2026<\/p>\n\n<p>On January\u00a013, 2026, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Business Server Pages Application (Product Designer Web UI)\u00a0\u2013 versions SAP_APPL 618, S4CORE 102, 103, 104, 105, 106, 107, 108, 109, EA-APPL 600, 602, 603, 604, 605, 606 and 617<\/li>\n\t<li>NW AS Java UME User Mapping\u00a0\u2013 versions ENGINEAPI 7.50, SERVERCORE 7.50 and UMEADMIN 7.50<\/li>\n\t<li>SAP Application Server for ABAP and SAP NetWeaver RFCSDK\u00a0\u2013 versions KRNL64UC 7.53, NWRFCSDK 7.50, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93 and 9.16<\/li>\n\t<li>SAP Business Connector\u00a0\u2013 version SAP BC 4.8<\/li>\n\t<li>SAP ERP Central Component and SAP S\/4HANA (SAP EHS Management)\u00a0\u2013 versions SAP_APPL 618, S4CORE 102, 103, 104, 105, 106, 107, 108, 109, EA-APPL 605, 606 and 617<\/li>\n\t<li>SAP Fiori App (Intercompany Balance Reconciliation)\u00a0\u2013 versions UIAPFI70 500, 600, 700, 800, 900, 901, 902 and UIS4H 109<\/li>\n\t<li>SAP Fiori App (Intercompany Balance Reconciliation)\u00a0\u2013 versions UIAPFI70 500, 600, 700, 800, 900, 901, 902, S4CORE 102, 103, 104, 105, 106, 107 and 108<\/li>\n\t<li>SAP Fiori App (Intercompany Balance Reconciliation)\u00a0\u2013 versions UIAPFI70 500, 600, 700, 800, 900, 901, 902, S4CORE 102, 103, 104, 105, 106, 107, 108, 109 and UIS4H 109<\/li>\n\t<li>SAP HANA database\u00a0\u2013 version HDB 2.00<\/li>\n\t<li>SAP Identity Management\u00a0\u2013 versions IDM_CLM_REST_API 8.0 and IDMIC 8.0<\/li>\n\t<li>SAP Landscape Transformation\u00a0\u2013 versions DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2018_1_752 and 2020<\/li>\n\t<li>SAP NetWeaver Application Server ABAP and ABAP Platform\u00a0\u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 and SAP_BASIS 816<\/li>\n\t<li>SAP NetWeaver Enterprise Portal\u00a0\u2013 version EP-RUNTIME 7.50<\/li>\n\t<li>SAP S\/4HANA (Private Cloud and On-Premise)\u00a0\u2013 versions S4CORE 102, 103, 104, 105, 106, 107, 108 and 109<\/li>\n\t<li>SAP S\/4HANA Private Cloud and On-Premise (Financials\u00a0\u2013 General Ledger)\u00a0\u2013 versions S4CORE 102, 103, 104, 105, 106, 107, 108 and 109<\/li>\n\t<li>SAP Supplier Relationship Management (SICF Handler in SRM Catalog)\u00a0\u2013 versions SRM_SERVER 700, 701, 702, 713 and 714<\/li>\n\t<li>SAP Wily Introscope Enterprise Manager (WorkStation)\u00a0\u2013 version WILY_INTRO_ENTERPRISE 10.8<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/january-2026.html\">SAP Security Patch Day\u00a0- January 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-january-2026-monthly-rollup-av26-021","alert_type":396,"serial_number":"AV26-021","subject":"sap","moderation_state":"published","external_url":null},{"nid":7161,"title":"ServiceNow security advisory (AV26-022)","uuid":"f6097435-693e-4b2b-8956-1aee760fff0a","banner":null,"lang":"en","date_modified":"2026-01-13","date_modified_ts":"2026-01-13T16:48:53Z","date_created":"2026-01-13T15:13:15Z","summary":null,"body":["<article data-history-node-id=\"7161\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av26-022\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV26-022<br \/><strong>Date:<\/strong> January\u00a013, 2026<\/p>\n\n<p>On January\u00a012, 2026, ServiceNow published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Now Assist AI Agents (sn_aia)\u00a0\u2013 versions prior to 5.1.18<\/li>\n\t<li>Now Assist AI Agents (sn_aia)\u00a0\u2013 versions prior to 5.2.19<\/li>\n\t<li>Virtual Agent API (sn_va_as_service)\u00a0\u2013 versions prior to 3.15.2<\/li>\n\t<li>Virtual Agent API (sn_va_as_service)\u00a0\u2013 versions prior to 4.0.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB2587329\">[Security Advisory] CVE-2025-12420\u00a0- Privilege Escalation in ServiceNow AI Platform<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av26-022","alert_type":396,"serial_number":"AV26-022","subject":"other","moderation_state":"published","external_url":null},{"nid":7162,"title":"Fortinet security advisory (AV26-023) - Update 1","uuid":"e448ddd1-2a1a-4ecf-aa8b-64035e998e0b","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T19:57:35Z","date_created":"2026-01-13T20:06:54Z","summary":null,"body":["<article data-history-node-id=\"7162\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-023\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-023<br \/><strong>Date: <\/strong>January\u00a013, 2026<br \/><strong>Updated:<\/strong> September 9, 2026<\/p>\n\n<p>On January\u00a013, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiFone 7.0\u00a0\u2013 versions 7.0.0 to 7.0.1<\/li>\n\t<li>FortiFone 3.0\u00a0\u2013 versions 3.0.13 to 3.0.23<\/li>\n\t<li>FortiOS 7.6\u00a0\u2013 versions 7.6.0 to 7.6.3<\/li>\n\t<li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.8<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiOS 7.0\u00a0\u2013 versions 7.0.0 to 7.0.17<\/li>\n\t<li>FortiOS 6.4\u00a0\u2013 versions 6.4.0 to 6.4.16<\/li>\n\t<li>FortiSASE 25.2\u00a0\u2013 version 25.2.b<\/li>\n\t<li>FortiSASE 25.1.a\u00a0\u2013 version 25.1.a.2<\/li>\n\t<li>FortiSIEM 7.4\u00a0\u2013 version 7.4.0<\/li>\n\t<li>FortiSIEM 7.3\u00a0\u2013 versions 7.3.0 to 7.3.4<\/li>\n\t<li>FortiSIEM 7.2\u00a0\u2013 versions 7.2.0 to 7.2.6<\/li>\n\t<li>FortiSIEM 7.1\u00a0\u2013 versions 7.1.0 to 7.1.8<\/li>\n\t<li>FortiSIEM 7.0\u00a0\u2013 versions 7.0.0 to 7.0.4<\/li>\n\t<li>FortiSIEM 6.7\u00a0\u2013 versions 6.7.0 to 6.7.10<\/li>\n\t<li>FortiSwitchManager 7.2\u00a0\u2013 versions 7.2.0 to 7.2.6<\/li>\n\t<li>FortiSwitchManager 7.0\u00a0\u2013 versions 7.0.0 to 7.0.5<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-25249 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-084\">Heap-based buffer overflow in cw_acd daemon\u00a0\u2013 CVE-2025-25249<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-260\">Unauthenticated access to local configuration\u00a0\u2013 CVE-2025-47855<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-772\">Unauthenticated remote command injection\u00a0\u2013 CVE-2025-64155<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249\">CISA KEV: CVE-2025-25249<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-023","alert_type":396,"serial_number":"AV26-023","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7163,"title":"Microsoft security advisory \u2013 January 2026 monthly rollup (AV26-024) \u2013 Update 2","uuid":"45db9006-f77c-46dd-9831-b276ef769dfb","banner":null,"lang":"en","date_modified":"2026-03-19","date_modified_ts":"2026-03-19T14:31:24Z","date_created":"2026-01-13T20:06:55Z","summary":null,"body":["<article data-history-node-id=\"7163\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2026-monthly-rollup-av26-024\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-024<br \/><strong>Date: <\/strong>January\u00a013, 2026<br \/><strong>Updated:<\/strong> March\u00a018, 2026<\/p>\n\n<p>On January\u00a013, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>Azure Connected Machine Agent<\/li>\n\t<li>Azure Core shared client library for Python<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office Deployment Tool<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SQL Server 2025<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Admin Center in Azure Portal<\/li>\n\t<li>Windows SDK<\/li>\n\t<li>Windows Server 2008<\/li>\n\t<li>Windows Server 2008 R2<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn January 26, 2026, Microsoft published an out-of-band security advisory to address an important vulnerability CVE-2026-21509.<\/p>\n\n<p>As well, on January 26, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21509 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>Microsoft has received reports that CVE-2026-20805 and CVE-2026-21509 are being exploited.<\/p>\n\n<p><strong>Update 2<\/strong><br \/>\nOn March 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20963 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Jan\">January 2026 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-21509\">Microsoft Office Security Feature Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-21509 \">CISA KEV: CVE-2026-21509<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-20963\">CISA KEV: CVE-2026-20963<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-january-2026-monthly-rollup-av26-024","alert_type":396,"serial_number":"AV26-024","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7164,"title":"HPE security advisory (AV26-025)","uuid":"d4bb9a0c-a2ff-4fbf-aad1-8b3630256604","banner":null,"lang":"en","date_modified":"2026-01-13","date_modified_ts":"2026-01-13T21:14:21Z","date_created":"2026-01-13T20:40:38Z","summary":null,"body":["<article data-history-node-id=\"7164\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-025\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-025<br \/><strong>Date: <\/strong>January 13, 2026<\/p>\n\n<p>On January 13, 2026, HPE published security advisories to address vulnerabilities in the following products\u00a0:<\/p>\n\n<ul><li>HPE Networking Instant\u00a0\u2013 versions 3.3.1.0 and prior<\/li>\n\t<li>HPE Aruba Networking AOS-8 and AOS-10 for Mobility Conductors, Controllers, and Gateways\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Aruba Networking Virtual Intranet Access (VIA) Client for Linux\u00a0\u2013 versions 4.7.5 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04988en_us&amp;docLocale=en_US#hpesbnw04988-rev-1-hpe-networking-instant-on-multi-0\">HPESBNW04988 rev.1\u00a0- HPE Networking Instant On, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04987en_us&amp;docLocale=en_US#hpesbnw04987-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW04987 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking AOS-8 and AOS-10 for Mobility Conductors, Controllers, and Gateways.<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04994en_us&amp;docLocale=en_US\">HPESBNW04994 rev.1\u00a0- Local Privilege Escalation Vulnerability in HPE Aruba Networking Virtual Intranet Access (VIA) Client for Linux<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-025","alert_type":396,"serial_number":"AV26-025","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7165,"title":"Google Chrome security advisory (AV26-026)","uuid":"613d2bea-0f72-445c-9b93-91e01d4abb19","banner":null,"lang":"en","date_modified":"2026-01-14","date_modified_ts":"2026-01-14T15:16:28Z","date_created":"2026-01-14T15:07:58Z","summary":null,"body":["<article data-history-node-id=\"7165\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-026\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-026<br \/><strong>Date: <\/strong>January 14, 2026<\/p>\n\n<p>On January 13, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 144.0.7559.59\/60 (Windows\/Mac) and 144.0.7559.59 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/01\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-026","alert_type":396,"serial_number":"AV26-026","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7166,"title":"Adobe security advisory (AV26-027)","uuid":"93cf093b-b8b6-403d-8431-328f3b4f8206","banner":null,"lang":"en","date_modified":"2026-01-14","date_modified_ts":"2026-01-14T15:30:26Z","date_created":"2026-01-14T15:18:37Z","summary":null,"body":["<article data-history-node-id=\"7166\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-027\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-027<br \/><strong>Date: <\/strong>January 14, 2026<\/p>\n\n<p>On January 13, 2026, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Dreamweaver\u00a0\u2013 version 21.6 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID21.0 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID19.5.5 and prior<\/li>\n\t<li>Illustrator 2025\/2026\u00a0\u2013 version 29.8.3 and prior<\/li>\n\t<li>Illustrator 2025\/2026\u00a0\u2013 version 30.0 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 21.0 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 19.5.5 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 15.1.2 (LTS) and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version 16.0 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler\u00a0\u2013 version 1.22.4 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.1.5 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 11.0.3 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler\u00a0\u2013 version 5.1.0 and prior<\/li>\n\t<li>ColdFusion 2025\/2023\u00a0\u2013 version Update 5 and prior<\/li>\n\t<li>ColdFusion 2025\/2023\u00a0\u2013 version Update 17 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version 15.0.3 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-027","alert_type":396,"serial_number":"AV26-027","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7167,"title":"Mozilla security advisory (AV26-028)","uuid":"98ecebb2-8213-4d59-80c2-99cf117be877","banner":null,"lang":"en","date_modified":"2026-01-14","date_modified_ts":"2026-01-14T15:43:47Z","date_created":"2026-01-14T15:32:21Z","summary":null,"body":["<article data-history-node-id=\"7167\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-028\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-028<br \/><strong>Date: <\/strong>January 14, 2026<\/p>\n\n<p>On January 13, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 140.7<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.32<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 147<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-03\/\">Mozilla Foundation Security Advisory 2026-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-02\/\">Mozilla Foundation Security Advisory 2026-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-01\/\">Mozilla Foundation Security Advisory 2026-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-028","alert_type":396,"serial_number":"AV26-028","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7168,"title":"[Control systems] Schneider Electric security advisory (AV26-029)","uuid":"823d50ae-5734-4c3f-8966-a82053a57722","banner":null,"lang":"en","date_modified":"2026-01-14","date_modified_ts":"2026-01-14T15:57:06Z","date_created":"2026-01-14T15:45:48Z","summary":null,"body":["<article data-history-node-id=\"7168\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-029\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-029<br \/><strong>Date: <\/strong>January 14, 2026<\/p>\n\n<p>On January 13, 2026, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Power Build Rapsody software\u00a0\u2013 multiple versions<\/li>\n\t<li>Wiser iTRV2 Version Wiser iTRV3, Wiser RTR2, Wiser UFH, Wiser 16A Electrical Heat Switch, Wiser Boiler Relay, Exxact cFMT 16a, Elko cFMT 16a, Odace cFMT 2a, Merten cFMT 16a, Merten cFMT 2a, Wiser Power Micromodule, Wiser FIP Micromodule, Iconic, Wiser Connected Smart Dimmer, Iconic, Wiser Connected Smart Switch, 2AX, Iconic, Wiser Connected Smart Switch, 10AX, Iconic, Connected AC Fan Controller Iconic, Connected Smart Socket, Wiser Connected Application Module 1-Gang, Wiser Connected Application Module 2-Gang, Wiser Connected Push Button Dimmer, Wiser Connected Push Button Switch, Wiser Connected Push Button Shutter, Wiser Connected Motion Dimmer, Wiser Connected Motion Switch, Wiser Connected Rotary Dimmer, Connected Wireless Switch, Micromodule Switch, Micromodule Dimmer, Micromodule Shutter, Connected Single Socket Outlet, Connected Double Socket Outlet, Fuga Connected Socket Outlet, Mureva EV Link\u00a0\u2013 all versions<\/li>\n\t<li>EcoStruxure\u2122 Process Expert\u00a0\u2013 versions prior to 2025<\/li>\n\t<li>EcoStruxure\u2122 Process Expert for AVEVA System Platform\u00a0\u2013 all versions<\/li>\n\t<li>Plant iT\/Brewmaxx\u00a0\u2013 version v9.60 and later<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-013-04&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-04.pdf\">Multiple Vulnerabilities on EcoStruxure Power Build Rapsody<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-013-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-03.pdf\">Multiple Third-Party Vulnerabilities on Zigbee Products<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-013-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-02.pdf\">Incorrect Default Permissions Vulnerability on EcoStruxure\u2122 Process Expert<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-013-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-013-01.pdf\">Multiple Third-Party Vulnerabilities on ProLeiT Plant iT\/Brewmaxx<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-029","alert_type":398,"serial_number":"AV26-029","subject":"other","moderation_state":"published","external_url":null},{"nid":7169,"title":"Drupal security advisory (AV26-030)","uuid":"66134a80-ea29-46b5-941c-fa1d698c266c","banner":null,"lang":"en","date_modified":"2026-01-14","date_modified_ts":"2026-01-14T19:53:37Z","date_created":"2026-01-14T19:43:46Z","summary":null,"body":["<article data-history-node-id=\"7169\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-030\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-030<br \/><strong>Date:<\/strong> January\u00a014, 2026<\/p>\n\n<p>On January\u00a014, 2026, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Group invite\u00a0\u2013 versions prior to 2.3.9, version 3.0.0 to versions prior to 3.0.4, version 4.0.0 to versions prior to 4.0.4<\/li>\n\t<li>Role Delegation\u00a0\u2013 version 1.3.0 to versions prior to 1.5.0<\/li>\n\t<li>AT Internet SmartTag\u00a0\u2013 versions prior to 1.0.1<\/li>\n\t<li>AT Internet Piano Analytics\u00a0\u2013 versions prior to 1.0.1, version 2.0.0 to versions prior to 2.3.1<\/li>\n\t<li>Microsoft Entra ID SSO Login\u00a0\u2013 versions prior to 1.0.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-030","alert_type":396,"serial_number":"AV26-030","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7170,"title":"Red Hat security advisory (AV26-031)","uuid":"cb1c84df-fd6d-4676-93b3-90f6a569ae60","banner":null,"lang":"en","date_modified":"2026-01-14","date_modified_ts":"2026-01-14T20:00:56Z","date_created":"2026-01-14T19:43:46Z","summary":null,"body":["<article data-history-node-id=\"7170\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-031\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-031<br \/><strong>Date: <\/strong>January\u00a014, 2026<\/p>\n\n<p>Between January\u00a05 and 11, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-031","alert_type":396,"serial_number":"AV26-031","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7171,"title":"Palo Alto Networks security advisory (AV26-032)","uuid":"54015d5b-bc00-48ba-a731-672c817468b9","banner":null,"lang":"en","date_modified":"2026-01-14","date_modified_ts":"2026-01-14T20:58:13Z","date_created":"2026-01-14T20:44:24Z","summary":null,"body":["<article data-history-node-id=\"7171\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-032\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-032<br \/><strong>Date: <\/strong>January 14, 2026<\/p>\n\n<p>On January 14, 2026, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Palo Alto Networks<\/span> published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Prisma Browser\u00a0\u2013 versions prior to 142.21.4.163<\/li>\n\t<li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.3-h3<\/li>\n\t<li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.4<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.1\u00a0\u2013 versions prior to 10.1.14-h20<\/li>\n\t<li>Prisma Access 11.2\u00a0\u2013 versions prior to 11.2.7-h8<\/li>\n\t<li>Prisma Access 10.2\u00a0\u2013 versions prior to 10.2.10-h29<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2026-0001\">PAN-SA-2026-0001 Chromium: Monthly Vulnerability Update (January 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0227\">CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-032","alert_type":396,"serial_number":"AV26-032","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7174,"title":"IBM security advisory (AV26-033)","uuid":"e67ec097-5036-41f3-8ee6-688465b79b6c","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T17:08:39Z","date_created":"2026-01-19T17:01:49Z","summary":null,"body":["<article data-history-node-id=\"7174\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-033\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-033<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>Between January 12 and 18, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak for Business Automation\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 versions 1.0.0 to 2.1.0<\/li>\n\t<li>IBM Datacap Navigator\u00a0\u2013 versions 9.1.7, 9.1.8 and 9.1.9<\/li>\n\t<li>IBM Datacap\u00a0\u2013 versions 9.1.7, 9.1.8 and 9.1.9<\/li>\n\t<li>IBM Library Support for Struts\u00a0\u2013 version 2.5.37<\/li>\n\t<li>IBM Operations Analytics\u00a0- Log Analysis\u00a0\u2013 versions 1.3.7.0, 1.3.7.1 and 1.3.7.2<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak\u00a0\u2013 versions 23.0.0 to 23.0.20.4, versions 30.0.0 to 30.0.0.2<\/li>\n\t<li>IBM Robotic Process Automation\u00a0\u2013 versions 23.0.0 to 23.0.20.4, versions 30.0.0 to 30.0.0.2<\/li>\n\t<li>IBM Security Verify Access Container\u00a0\u2013 versions 10.0 to 10.0.9<\/li>\n\t<li>IBM Sterling External Authentication Server\u00a0\u2013 versions 6.1.1.0 to 6.1.1.1<\/li>\n\t<li>IBM Terracotta\u00a0\u2013 versions 11.1.0.0 to 11.1.0.10<\/li>\n\t<li>IBM Verify Identity Access Container\u00a0\u2013 versions 11.0 to 11.0.1<\/li>\n\t<li>IBM Verify Identity Access\u00a0\u2013 versions 10.0 to 10.0.9<\/li>\n\t<li>IBM Verify Identity Access\u00a0\u2013 versions 11.0 to 11.0.1<\/li>\n\t<li>IBM i Access Family\u00a0\u2013 versions 1.1.9.8 to 1.1.9.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-033","alert_type":396,"serial_number":"AV26-033","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7175,"title":"Dell security advisory (AV26-034)","uuid":"9bb69606-3e8d-4f59-aa83-eb37930673dc","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T17:23:30Z","date_created":"2026-01-19T17:10:31Z","summary":null,"body":["<article data-history-node-id=\"7175\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-034\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-034<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>Between January 12 and 18, 2026, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Elastic Cloud Storage (ECS)\u00a0\u2013 versions 3.8.1.0 to 3.8.1.7<\/li>\n\t<li>Dell ObjectScale\u00a0\u2013 versions prior to 4.2.0.0<\/li>\n\t<li>Dell PowerScale OneFS\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000415586\/dsa-2026-049-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities\">DSA-2026-049: Security Update for Dell PowerScale OneFS Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000415880\/dsa-2026-047-security-update-for-dell-ecs-and-objectscale-multiple-vulnerabilities\">DSA-2026-047: Security update for Dell ECS and ObjectScale Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-034","alert_type":396,"serial_number":"AV26-034","subject":"dell","moderation_state":"published","external_url":null},{"nid":7176,"title":"Ubuntu security advisory (AV26-035)","uuid":"39a7dddc-dc0b-4bdb-a3f2-1185dbc140f4","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T17:30:23Z","date_created":"2026-01-19T17:24:39Z","summary":null,"body":["<article data-history-node-id=\"7176\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-035\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-035<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>Between January 12 and 18, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7922-5\">USN-7922-5: Linux kernel (IoT) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-035","alert_type":396,"serial_number":"AV26-035","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7177,"title":"[Control systems] CISA ICS security advisories (AV26\u2013036)","uuid":"4a19c939-00f3-4d5b-bc28-2734f40a7547","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T17:41:10Z","date_created":"2026-01-19T17:32:16Z","summary":null,"body":["<article data-history-node-id=\"7177\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-036\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013036<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>Between January 12 and 18, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA Process Optimization\u00a0\u2013 versions prior to 2024.1<\/li>\n\t<li>Festo Firmware\u00a0\u2013 multiple applications and all versions<\/li>\n\t<li>Rockwell Automation 432ES-IG3 Series A\u00a0\u2013 version V1.001<\/li>\n\t<li>Rockwell Automation FactoryTalk DataMosaix Private Cloud\u00a0\u2013 version 7.11<\/li>\n\t<li>Rockwell Automation FactoryTalk DataMosaix Private Cloud\u00a0\u2013 version 8.00<\/li>\n\t<li>Rockwell Automation FactoryTalk DataMosaix Private Cloud\u00a0\u2013 version 8.01<\/li>\n\t<li>Schneider Electric EcoStruxure Power Build Rapsody\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens Industrial Edge Device Kit\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Industrial Edge Devices\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens RUGGEDCOM APE1808 Devices\u00a0\u2013 contact customer support to receive patch and update information<\/li>\n\t<li>Siemens RUGGEDCOM ROS\u00a0\u2013 versions prior to V5.10.1<\/li>\n\t<li>Siemens SIMATIC and SIPLUS\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens SINEC Security Monitor\u00a0\u2013 version prior to V4.10.0<\/li>\n\t<li>Siemens TeleControl Server Basic\u00a0\u2013 versions prior to V3.1.2.4<\/li>\n\t<li>YoSmart YoLink Mobile Appication\u00a0\u2013 version v1.40.45<\/li>\n\t<li>YoSmart YoLink Smart Hub\u00a0\u2013 version 0382<\/li>\n\t<li>YoSmart server\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-036","alert_type":398,"serial_number":"AV26\u2013036","subject":"ics","moderation_state":"published","external_url":null},{"nid":7178,"title":"Microsoft Edge security advisory (AV26-037)","uuid":"bde024e4-3356-41d6-af5d-3c8339538ae2","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T18:14:00Z","date_created":"2026-01-19T18:05:50Z","summary":null,"body":["<article data-history-node-id=\"7178\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-037\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-037<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>On January 14, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 144.0.3719.82<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-14-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-037","alert_type":396,"serial_number":"AV26-037","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7179,"title":" VMware security advisory (AV26-038)","uuid":"f6144b32-355c-4696-8861-b2c784544ebb","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T18:38:32Z","date_created":"2026-01-19T18:25:15Z","summary":null,"body":["<article data-history-node-id=\"7179\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-038\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-038<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>Between January 12 and 18, 2026, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<ul><li>VM<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">ware Tanzu GemFire<\/span>\u00a0\u2013 versions prior to 10.1.6<\/li>\n\t<li>VM<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">ware Tanzu GemFire<\/span>\u00a0\u2013 versions prior to 10.2.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36758\">Product Release Advisory\u00a0- VMware Tanzu GemFire 10.1.6<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36759\">Product Release Advisory\u00a0- VMware Tanzu GemFire 10.2.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-038","alert_type":396,"serial_number":"AV26-038","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7180,"title":"[Control systems] ABB security advisory (AV26-039)","uuid":"c4e3e342-b081-464a-8e28-86aeb485da9c","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T20:26:52Z","date_created":"2026-01-19T20:18:57Z","summary":null,"body":["<article data-history-node-id=\"7180\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-039\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-039<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>On January 19, 2026, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automation Studio\u00a0\u2013 versions prior to 6.5<\/li>\n\t<li>Automation Runtime\u00a0\u2013 version 6.5.0 and prior<\/li>\n\t<li>Automation Runtime\u00a0\u2013 version R4.93 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P004-4f45197f.pdf\">Automation Studio Insufficient Server Certificate Validation CVE ID: CVE-2025-11043<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P005-26597bd0.pdf\">B&amp;R Automation Runtime Improper Handling of Flooding conditions on ANSL Server CVE ID: CVE-2025-11044<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-039","alert_type":398,"serial_number":"AV26-039","subject":"abb","moderation_state":"published","external_url":null},{"nid":7181,"title":"GitLab security advisory (AV26-040)","uuid":"9f3e84c7-c8c9-4600-901f-40855876c28b","banner":null,"lang":"en","date_modified":"2026-01-19","date_modified_ts":"2026-01-19T20:34:06Z","date_created":"2026-01-19T20:29:03Z","summary":null,"body":["<article data-history-node-id=\"7181\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-040\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-040<br \/><strong>Date: <\/strong>January 19, 2026<\/p>\n\n<p>On January 16, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.8.1<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.8.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/01\/19\/gitlab-18-8-1-released\/\">GitLab Patch Release: 18.8.1<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-040","alert_type":396,"serial_number":"AV26-040","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7182,"title":"Juniper Networks security advisory (AV26-041)","uuid":"1a97044c-e1d7-4b91-8790-40ebf74c3b45","banner":null,"lang":"en","date_modified":"2026-01-20","date_modified_ts":"2026-01-20T14:12:42Z","date_created":"2026-01-20T14:06:22Z","summary":null,"body":["<article data-history-node-id=\"7182\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-041\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-041<br \/><strong>Date: <\/strong>January 20, 2026<\/p>\n\n<p>On January 14, 2026, Juniper Networks published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Juniper Networks Policy Enforcer \u2013 versions prior to 24.1R3<\/li>\n\t<li>Juniper Networks Paragon Automation \u2013 versions prior to 24.1.1<\/li>\n\t<li>Junos OS Evolved \u2013 multiple versions<\/li>\n\t<li>Junos OS on EX4000 \u2013 versions prior to 24.4R2<\/li>\n\t<li>Junos OS on EX4000 \u2013 versions prior to 25.2R1-S2 and 25.2R2<\/li>\n\t<li>Junos OS on MX Series \u2013 multiple versions<\/li>\n\t<li>Junos OS on QFX5k Series \u2013 multiple versions<\/li>\n\t<li>Junos OS on SRX Series \u2013 multiple versions<\/li>\n\t<li>Junos OS on EX Series \u2013 multiple versions<\/li>\n\t<li>Junos OS \u2013 multiple versions<\/li>\n\t<li>Junos Space \u2013 versions prior to 24.1R5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-041","alert_type":396,"serial_number":"AV26-041","subject":"juniper","moderation_state":"published","external_url":null},{"nid":7185,"title":"Oracle security advisory \u2013 January 2026 quarterly rollup (AV26-042) \u2013 Update 2","uuid":"2366cb9f-4744-46cc-9da4-dcf8997e4028","banner":null,"lang":"en","date_modified":"2026-08-24","date_modified_ts":"2026-08-24T18:42:49Z","date_created":"2026-01-21T13:02:41Z","summary":null,"body":["<article data-history-node-id=\"7185\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-january-2026-quarterly-rollup-av26-042\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-042<br \/><strong>Date: <\/strong>January\u00a021, 2026<br \/><strong>Updated: <\/strong>August\u00a024, 2026<\/p>\n\n<p>On January\u00a020, 2026, Oracle published a security advisory to address vulnerabilities in multiple products.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p class=\"mrgn-bttm-md\">On January\u00a021, 2026, a proof of concept (PoC) for the vulnerability CVE-2026-21962 became publicly available.<\/p>\n\n<p class=\"mrgn-bttm-md\">CVE-2026-21962 is a vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware which may allow a remote attacker to obtain unauthorized access.<\/p>\n\n<h2>Update 2<\/h2>\n\n<p class=\"mrgn-bttm-md\">On August\u00a024, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujan2026.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 January 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21962\">CISA KEV: CVE-2026-21962<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-january-2026-quarterly-rollup-av26-042","alert_type":396,"serial_number":"AV26-042","subject":"oracle","moderation_state":"published","external_url":null},{"nid":7186,"title":"Google Chrome security advisory (AV26-043)","uuid":"c91ed871-31ff-40ad-976c-75cb7916ccfa","banner":null,"lang":"en","date_modified":"2026-01-21","date_modified_ts":"2026-01-21T13:11:31Z","date_created":"2026-01-21T13:08:11Z","summary":null,"body":["<article data-history-node-id=\"7186\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-043\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-043<br \/><strong>Date: <\/strong>January 21, 2026<\/p>\n\n<p>On January 20, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 144.0.7559.96\/.97 (Windows\/Mac) and 144.0.7559.96 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/01\/stable-channel-update-for-desktop_20.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-043","alert_type":396,"serial_number":"AV26-043","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7187,"title":"GitLab security advisory (AV26-044)","uuid":"48b4573d-3207-42ab-aa00-80a55a0fc88a","banner":null,"lang":"en","date_modified":"2026-01-21","date_modified_ts":"2026-01-21T13:20:51Z","date_created":"2026-01-21T13:16:40Z","summary":null,"body":["<article data-history-node-id=\"7187\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-044\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-044<br \/><strong>Date: <\/strong>January 21, 2026<\/p>\n\n<p>On January 21, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE) \u2013 versions prior to 18.8.2, 18.7.2 and 18.6.4<\/li>\n\t<li>GitLab Enterprise Edition (EE) \u2013 versions prior to 18.8.2, 18.7.2 and 18.6.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/01\/21\/patch-release-gitlab-18-8-2-released\/\">GitLab Patch Release: 18.8.2, 18.7.2, 18.6.4<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-044","alert_type":396,"serial_number":"AV26-044","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7188,"title":"Atlassian security advisory (AV26-045)","uuid":"a1f5c5cb-211a-4a06-9ff6-981480a793bf","banner":null,"lang":"en","date_modified":"2026-01-21","date_modified_ts":"2026-01-21T17:00:02Z","date_created":"2026-01-21T16:54:25Z","summary":null,"body":["<article data-history-node-id=\"7188\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-045\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-045<br \/><strong>Date: <\/strong>January 21, 2026<\/p>\n\n<p>On January 20, 2026, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server \u2013 versions 7.1.0 to 7.1.2, versions 6.3.0 to 6.3.3<\/li>\n\t<li>Jira Data Center and Server \u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server \u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-january-20-2026-1712324819.html\">Security Bulletin\u00a0- January 20 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-045","alert_type":396,"serial_number":"AV26-045","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":7189,"title":"HPE security advisory (AV26-046)","uuid":"6ab6aeac-6ed8-4ec8-979b-df2e312c1b46","banner":null,"lang":"en","date_modified":"2026-01-21","date_modified_ts":"2026-01-21T17:06:13Z","date_created":"2026-01-21T17:02:16Z","summary":null,"body":["<article data-history-node-id=\"7189\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-046\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-046<br \/><strong>Date: <\/strong>January 22, 2026<\/p>\n\n<p>Between January 20 and 21, 2026, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Alletra 6000 \u2013 versions prior to 6.1.2.800, version 6.1.3 versions prior to 6.1.3.300<\/li>\n\t<li>HPE Nimble Storage Hybrid Flash Arrays \u2013 versions prior to 6.1.2.800, version 6.1.3 versions prior to 6.1.3.300<\/li>\n\t<li>Nimble Storage All Flash Arrays \u2013 versions prior to 6.1.2.800, version 6.1.3 versions prior to 6.1.3.300<\/li>\n\t<li>HPE Alletra 5000 \u2013 versions prior to 6.1.2.800, version 6.1.3 versions prior to 6.1.3.300<\/li>\n\t<li>HPE ONMS Adapter \u2013 versions prior to 4.4.0-0C patch 00002<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst04995en_us&amp;docLocale=en_US#hpesbst04995-rev-1-hpe-alletra-6000-hpe-alletra-50-0\">HPESBST04995 rev.1 - HPE Alletra 6000, HPE Alletra 5000 and HPE Nimble Storage Array OS, Remote Privilege Elevation<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04990en_us&amp;docLocale=en_US#hpesbnw04990-rev-1-hpe-telco-ip-remote-stack-overf-0\">HPESBNW04990 rev.1 - HPE Telco IP, Remote Stack Overflow<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-046","alert_type":396,"serial_number":"AV26-046","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7190,"title":"GNU security advisory (AV26-047) \u2013 Update 1","uuid":"bafc81bc-f8b2-4910-8c52-5490b0bacd69","banner":null,"lang":"en","date_modified":"2026-01-27","date_modified_ts":"2026-01-27T13:57:52Z","date_created":"2026-01-21T17:08:25Z","summary":null,"body":["<article data-history-node-id=\"7190\" about=\"\/en\/alerts-advisories\/gnu-security-advisory-av26-047\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-047<br \/><strong>Date: <\/strong>January 21, 2026<br \/><strong>Updated:<\/strong> January 26, 2026<\/p>\n\n<p>On January 21, 2026, GNU published a security advisory to address a vulnerability in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>GNU InetUtils\u00a0\u2013 versions 1.9.3 to 2.7<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn January 26, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-24061 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">Open-source reporting indicates that an exploit for CVE-2026-24061 exists in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-24061\">NVD\u00a0- CVE-2026-24061<\/a><\/li>\n\t<li><a href=\"https:\/\/www.gnu.org\/software\/inetutils\/\">Inetutils\u00a0- GNU network utilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24061\">CISA KEV: CVE-2026-24061<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gnu-security-advisory-av26-047","alert_type":396,"serial_number":"AV26-047","subject":"other","moderation_state":"published","external_url":null},{"nid":7191,"title":"Cisco security advisory (AV26-048)","uuid":"76ad9d45-ffc1-43bf-8b38-04237d8277b8","banner":null,"lang":"en","date_modified":"2026-01-21","date_modified_ts":"2026-01-21T19:28:13Z","date_created":"2026-01-21T19:23:56Z","summary":null,"body":["<article data-history-node-id=\"7191\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-048\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-048<br \/><strong>Date: <\/strong>January 22, 2026<\/p>\n\n<p>On January 21, 2026, Cisco published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Cisco Unified CM \u2013 versions prior to 12.5, 14 and 15<\/li>\n\t<li>Unified CM IM&amp;P \u2013 versions prior to 12.5, 14 and 15<\/li>\n\t<li>Unified CM SME \u2013 versions prior to 12.5, 14 and 15<\/li>\n\t<li>Webex Calling Dedicated Instance \u2013 versions prior to 12.5, 14 and 15<\/li>\n\t<li>Cisco Unity Connection Release \u2013 versions prior to 12.5, 14 and 15<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">On January 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20045 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-20045\">CISA KEV: CVE-2026-20045<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-voice-rce-mORhqY4b\">Cisco Unified Communications Products Remote Code Execution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-048","alert_type":396,"serial_number":"AV26-048","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7192,"title":"AL26-002 -Vulnerability affecting GNU Inetutils Telnetd - CVE-2026-24061","uuid":"96ce8469-4a9e-4a63-b421-a1a7841b53f1","banner":null,"lang":"en","date_modified":"2026-01-22","date_modified_ts":"2026-01-22T13:18:29Z","date_created":"2026-01-22T13:04:13Z","summary":null,"body":["<article data-history-node-id=\"7192\" about=\"\/en\/alerts-advisories\/al26-002-vulnerability-affecting-gnu-inetutils-telnetd-cve-2026-24061\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-002<br \/><strong>Date:<\/strong> January\u00a022, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a critical vulnerability in GNU InetUtils telnetd service<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. In response to the security advisory released on January 20, 2026, the Cyber Centre issued AV26-047 on January 21, 2026.<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/p>\n\n<p>Tracked as CVE-2026-24061<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability allows Argument Injection (CWE-88: Improper Neutralization of Argument Delimiters in a Command)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> where telnetd passes the USER environment variable to the system login process without sanitizing arguments. This allows an attacker to send a value like -f root, which bypasses authentication and grants remote root access on the affected server.<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/p>\n\n<p>This vulnerability affects many Linux\/UNIX distributions or appliances that ship or enable GNU Inetutils telnetd, especially those with telnet enabled for legacy or embedded use.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected instances of GNU InetUtils to a fixed version when available.<\/p>\n\n<p>The table below shows affected and patched versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Patched versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>GNU Inetutils telnetd<\/td>\n\t\t\t<td>Version 1.9.3 up to and including 2.7<\/td>\n\t\t\t<td>Fixed version beyond 2.7 (no patch available yet for Inetutils network utilities package)<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>Patches are available to fix the vulnerability in telnetd. However, these must be incorporated into the packages of the various distributions before they can be implemented. Until then, the patches can only be implemented by modifying them in the code (in telnetd\/utility.c) and then compiling them independently.<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/p>\n\n<p>If patching is not immediately possible:<\/p>\n\n<ul><li>Disable or do not run telnetd server, or<\/li>\n\t<li>Restrict access to the telnet ports to authorized users (eg: firewall rules, network segmentation)<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics.<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.gnu.org\/software\/inetutils\/\">Inetutils\u00a0- GNU network utilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/gnu-security-advisory-av26-047\">GNU security advisory (AV26-047)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-24061\">NVD\u00a0- CVE-2026-24061 <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/88.html\">CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2026\/01\/20\/2\">GNU InetUtils Security Advisory: remote authentication by-pass in telnetd<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/codeberg.org\/inetutils\/inetutils\/commit\/ccba9f748aa8d50a38d7748e2e60362edd6a32cc\">telnetd: Sanitize all variable expansions<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-002-vulnerability-affecting-gnu-inetutils-telnetd-cve-2026-24061","alert_type":397,"serial_number":"AL26-002","subject":"other","moderation_state":"published","external_url":null},{"nid":7193,"title":"ISC BIND security advisory (AV26-049)","uuid":"041b7267-1c31-43d9-8201-d10eb927414c","banner":null,"lang":"en","date_modified":"2026-01-22","date_modified_ts":"2026-01-22T14:23:01Z","date_created":"2026-01-22T14:19:56Z","summary":null,"body":["<article data-history-node-id=\"7193\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-049\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-049<br \/><strong>Date: <\/strong>January 22, 2026<\/p>\n\n<p>On January 21, 2026, ISC published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ISC BIND 9 \u2013 versions 9.18.40 to 9.18.43<\/li>\n\t<li>ISC BIND 9 \u2013 versions 9.20.13 to 9.20.17<\/li>\n\t<li>ISC BIND 9 \u2013 versions 9.21.12 to 9.21.16<\/li>\n\t<li>BIND Supported Preview Edition \u2013 versions 9.18.40-S1 to 9.18.43-S1<\/li>\n\t<li>BIND Supported Preview Edition \u2013 versions 9.20.13-S1 to 9.20.17-S1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2025-13878\">CVE-2025-13878: Malformed BRID\/HHIT records can cause named to terminate unexpectedly<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-049","alert_type":396,"serial_number":"AV26-049","subject":"other","moderation_state":"published","external_url":null},{"nid":7197,"title":"IBM security advisory (AV26-050)","uuid":"a3350719-b110-4ea1-bb0a-0eea4f4d9526","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T17:11:50Z","date_created":"2026-01-26T17:05:40Z","summary":null,"body":["<article data-history-node-id=\"7197\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-050\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-050<br \/><strong>Date: <\/strong>January 26, 2026<\/p>\n\n<p>Between January 19 and 25, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Big SQL on IBM Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 versions 1.0.0 to 2.1.0<\/li>\n\t<li>IBM DataStax Hyper-Convergence Database\u00a0\u2013 version 1.2.3<\/li>\n\t<li>IBM Guardium Data Security Center\u00a0\u2013 version 3.8.5<\/li>\n\t<li>IBM Watsonx Orchastrate with watsonx Assistant Chartridge UAB Component\u00a0\u2013 versions 5.1.0 to 5.2.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-050","alert_type":396,"serial_number":"AV26-050","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7198,"title":"[Control systems] CISA ICS security advisories (AV26\u2013051)","uuid":"9803a023-5b60-4d48-abd8-2d14c30c5f1e","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T17:24:14Z","date_created":"2026-01-26T17:15:32Z","summary":null,"body":["<article data-history-node-id=\"7198\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-051\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013051<br \/><strong>Date: <\/strong>January 26, 2026<\/p>\n\n<p>Between January 19 and 25, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AutomationDirect CLICK Programmable Logic Controller\u00a0\u2013 version C0-0x<\/li>\n<li>AutomationDirect CLICK Programmable Logic Controller\u00a0\u2013 version C0-1x<\/li>\n<li>AutomationDirect CLICK Programmable Logic Controller\u00a0\u2013 version C2-x<\/li>\n<li>Delta Electronics DIAView\u00a0\u2013 version 4.2.0<\/li>\n<li>EVMAPA EVMAPA\u00a0\u2013 all versions<\/li>\n<li>Hubitat Elevation C3\/C4\/C5\/C7\/C8\/C8 pro\u00a0\u2013 firmware versions prior to firmware_2.4.2.157<\/li>\n<li>Johnson Controls Inc. iSTAR Configuration Utility (ICU) tool\u00a0\u2013 version 6.9.7 and prior<\/li>\n<li>Rockwell Automation CompactLogix 5370\u00a0\u2013 version 34.013 and prior<\/li>\n<li>Rockwell Automation CompactLogix 5370\u00a0\u2013 version 35.012 and prior<\/li>\n<li>Rockwell Automation CompactLogix 5370\u00a0\u2013 version 36.011<\/li>\n<li>Rockwell Automation Verve Asset Manager\u00a0- multiple versions and models<\/li> \n<li>Schneider Electric EcoStruxure Foxboro DCS\u00a0\u2013 multiple versions<\/li>\n<li>Schneider Electric EcoStruxure Process Expert\u00a0\u2013 all versions<\/li>\n<li>Schneider Electric devices using CODESYS Runtime\u00a0\u2013 multiple versions and models<\/li>\n<li>Weintek cMT X Series HMI EasyWeb Service\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-051","alert_type":398,"serial_number":"AV26\u2013051","subject":"ics","moderation_state":"published","external_url":null},{"nid":7199,"title":"HPE security advisory (AV26-052)","uuid":"ff3a425f-fbab-4bec-b000-4311b3f627c6","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T18:47:36Z","date_created":"2026-01-26T18:41:06Z","summary":null,"body":["<article data-history-node-id=\"7199\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-052\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-052<br \/><strong>Date: <\/strong>January\u00a026, 2026<\/p>\n\n<p>On January\u00a023, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Universal SLA Management\u00a0\u2013 version 4.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04997en_us&amp;docLocale=en_US#hpesbnw04997-rev-1-hpe-telco-universal-sla-managem-0\">HPESBNW04997 rev.1\u00a0- HPE Telco Universal SLA Management, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-052","alert_type":396,"serial_number":"AV26-052","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7200,"title":"Red Hat security advisory (AV26-053)","uuid":"1cd2e142-36bb-4ef0-8bf5-d20d65d0f1fd","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T18:51:55Z","date_created":"2026-01-26T18:41:06Z","summary":null,"body":["<article data-history-node-id=\"7200\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-053\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-053<br \/><strong>Date: <\/strong>January\u00a026, 2026<\/p>\n\n<p>Between January\u00a019 and 25, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-053","alert_type":396,"serial_number":"AV26-053","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7201,"title":"VMware security advisory (AV26-054)","uuid":"3c246246-9db6-4011-94f3-bd0d7909fd29","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T19:46:06Z","date_created":"2026-01-26T19:37:08Z","summary":null,"body":["<article data-history-node-id=\"7201\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-054\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-054<br \/><strong>Date: <\/strong>January 26, 2026<\/p>\n\n<p>Between January 19 and 25, 2026, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<ul><li>AI Services for VMware Tanzu Platform\u00a0\u2013 versions prior to 10.3.3<\/li>\n\t<li>Elastic Application Runtime for VMware Tanzu Platform\u00a0\u2013 versions prior to 6.0.24+LTS-T<\/li>\n\t<li>Elastic Application Runtime for VMware Tanzu Platform\u00a0\u2013 versions prior to 10.3.4<\/li>\n\t<li>Elastic Application Runtime for VMware Tanzu Platform\u00a0\u2013 versions prior to 10.2.7+LTS-T<\/li>\n\t<li>Extended App Support for Tanzu Platform\u00a0\u2013 versions prior to 1.0.12<\/li>\n\t<li>PHP Buildpack\u00a0\u2013 versions prior to 4.6.62<\/li>\n\t<li>VMware Tanzu Cloud Native Buildpack\u00a0\u2013 versions prior to 0.6.3<\/li>\n\t<li>VMware Tanzu Greenplum Backup and Restore\u00a0\u2013 versions prior to 1.32.30<\/li>\n\t<li>VMware Tanzu .NET Core Buildpack\u00a0\u2013 versions prior to 2.4.73, 2.4.76 and 2.4.77<\/li>\n\t<li>VMware Tanzu NodeJS Buildpack\u00a0\u2013 versions prior to 1.8.73<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-054","alert_type":396,"serial_number":"AV26-054","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7202,"title":"[Control systems] ABB security advisory (AV26-055)","uuid":"10aa88ab-0617-4c84-b826-c278f599f25f","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T19:54:31Z","date_created":"2026-01-26T19:47:36Z","summary":null,"body":["<article data-history-node-id=\"7202\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-055\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-055<br \/><strong>Date: <\/strong>January 26, 2026<\/p>\n\n<p>On January 23, 2026, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ABB 800xA Base\u00a0\u2013 version 6.0.3-9 and prior<\/li>\n\t<li>ABB 800xA Base\u00a0\u2013 version 6.1.1-2 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA013309&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">System 800xA SECURITY Advisory\u00a0- ABB 800xA Base 6.0.x, 6.1.x CSLib communication DoS vulnerability CVE ID: CVE-2024-3036<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-055","alert_type":398,"serial_number":"AV26-055","subject":"abb","moderation_state":"published","external_url":null},{"nid":7203,"title":"[Control systems] B&R security advisory (AV26-056)","uuid":"e7af8f29-3702-4387-8cf9-3e83d6507f7f","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T20:03:27Z","date_created":"2026-01-26T19:56:39Z","summary":null,"body":["<article data-history-node-id=\"7203\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av26-056\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-056<br \/><strong>Date: <\/strong>January 26, 2026<\/p>\n\n<p>On January 19, 2026, B&amp;R published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automation Runtime 6 versions\u00a0\u2013 versions prior to 6.5<\/li>\n\t<li>Automation Runtime 4 versions\u00a0\u2013 versions prior to R4.93<\/li>\n\t<li>Automation Studio\u00a0\u2013 versions prior to 6.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P005-26597bd0.pdf\">SA25P005: Improper Handling of Flooding conditions on ANSL Server<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P004-4f45197f.pdf\">SA25P004: Automation Studio Insufficient Server Certificate Validation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/cyber-security-advisories-and-notices\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av26-056","alert_type":398,"serial_number":"AV26-056","subject":"br-automation","moderation_state":"published","external_url":null},{"nid":7204,"title":"Microsoft Edge security advisory (AV26-057)","uuid":"79a80c4a-e076-4ab8-b15c-fe044a4cda8c","banner":null,"lang":"en","date_modified":"2026-01-26","date_modified_ts":"2026-01-26T20:47:46Z","date_created":"2026-01-26T20:43:09Z","summary":null,"body":["<article data-history-node-id=\"7204\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-057\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-057<br \/><strong>Date: <\/strong>January 26, 2026<\/p>\n\n<p>On January 23, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 144.0.3719.92<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-23-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-057","alert_type":396,"serial_number":" AV26-057","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7205,"title":" OpenSSL security advisory (AV26-058)","uuid":"796c44a9-f01e-4991-af65-4f09339a6518","banner":null,"lang":"en","date_modified":"2026-01-27","date_modified_ts":"2026-01-27T20:11:50Z","date_created":"2026-01-27T19:45:15Z","summary":null,"body":["<article data-history-node-id=\"7205\" about=\"\/en\/alerts-advisories\/openssl-security-advisory-av26-058\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-058<br \/><strong>Date: <\/strong>January 27, 2026<\/p>\n\n<p>On January 27, 2026, OpenSSL published security advisories to address vulnerabilities in multiple products. Included were updates for the following products:<\/p>\n\n<ul><li>OpenSSL\u00a0\u2013 versions 3.6.0 to versions prior to 3.6.1<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.5.0 to versions prior to 3.5.5<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.4.0 to versions prior to 3.4.4<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.3.0 to versions prior to 3.3.6<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.0.0 to versions prior to 3.0.19<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html#CVE-2025-15467\">CVE-2025-15467<\/a><\/li>\n\t<li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html#CVE-2025-11187\">CVE-2025-11187<\/a><\/li>\n\t<li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html\">OpenSSL Vulnerabilities<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory-av26-058","alert_type":396,"serial_number":"AV26-058","subject":"other","moderation_state":"published","external_url":null},{"nid":7206,"title":"Fortinet security advisory (AV26-059) \u2013 Update 1","uuid":"046437bf-f98f-420d-8858-b0d6efcd0002","banner":null,"lang":"en","date_modified":"2026-01-28","date_modified_ts":"2026-01-28T14:33:40Z","date_created":"2026-01-27T21:30:20Z","summary":null,"body":["<article data-history-node-id=\"7206\" about=\"\/en\/alerts-advisories\/cyber-fortinet-security-advisory-av26-059\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-059<br \/><strong>Date: <\/strong>January 27, 2026<br \/><strong>Updated: <\/strong>January 28, 2026<\/p>\n\n<p>On January 27, 2026, Fortinet published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>FortiAnalyzer 7.6\u00a0\u2013 versions 7.6.0 to 7.6.5<\/li>\n\t<li>FortiAnalyzer 7.4\u00a0\u2013 versions 7.4.0 to 7.4.9<\/li>\n\t<li>FortiAnalyzer 7.2\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiAnalyzer 7.0\u00a0\u2013 versions 7.0.0 to 7.0.15<\/li>\n\t<li>FortiManager 7.6\u00a0\u2013 versions 7.6.0 to 7.6.5<\/li>\n\t<li>FortiManager 7.4\u00a0\u2013 versions 7.4.0 to 7.4.9<\/li>\n\t<li>FortiManager 7.2\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiManager 7.0\u00a0\u2013 versions 7.0.0 to 7.0.15<\/li>\n\t<li>FortiOS 7.6\u00a0\u2013 versions 7.6.0 to 7.6.5<\/li>\n\t<li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.10<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.12<\/li>\n\t<li>FortiOS 7.0\u00a0\u2013 versions 7.0.0 to 7.0.18<\/li>\n\t<li>FortiProxy 7.6\u00a0\u2013 versions 7.6.0 to 7.6.4<\/li>\n\t<li>FortiProxy 7.4\u00a0\u2013 versions 7.4.0 to 7.4.12<\/li>\n\t<li>FortiProxy 7.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiProxy 7.0\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">Fortinet has stated that this vulnerability has been exploited in the wild. Fortinet has disabled FortiCloud SSO from devices running vulnerable versions. Clients must upgrade to the latest versions for the FortiCloud SSO authentication to function.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p class=\"mrgn-bttm-md\">On January 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-24858 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-060\">Administrative FortiCloud SSO authentication bypass\u00a0\u2013 CVE-2026-24858<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24858\">CISA KEV: CVE-2026-24858<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cyber-fortinet-security-advisory-av26-059","alert_type":396,"serial_number":"AV26-059","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7207,"title":"Google Chrome security advisory (AV26-060)","uuid":"4cb6f4d3-785f-4350-88f0-50a74aaf72a8","banner":null,"lang":"en","date_modified":"2026-01-28","date_modified_ts":"2026-01-28T14:44:29Z","date_created":"2026-01-28T14:39:00Z","summary":null,"body":["<article data-history-node-id=\"7207\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-060\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-060<br \/><strong>Date: <\/strong>January 28, 2026<\/p>\n\n<p>On January 27, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 144.0.7559.109\/.110 (Windows\/Mac) and 144.0.7559.109 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/01\/stable-channel-update-for-desktop_27.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-060","alert_type":396,"serial_number":"AV26-060","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7209,"title":"HPE security advisory (AV26-061)","uuid":"9d958276-3008-4dd8-a816-7d16cf877ea6","banner":null,"lang":"en","date_modified":"2026-01-28","date_modified_ts":"2026-01-28T18:42:28Z","date_created":"2026-01-28T18:35:39Z","summary":null,"body":["<article data-history-node-id=\"7209\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-061\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-061<br \/><strong>Date: <\/strong>January 28, 2026<\/p>\n\n<p>On January 27, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking Fabric Composer\u00a0\u2013 versions 7.x.x: versions 7.2.3 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04996en_us&amp;docLocale=en_US#hpesbnw04996-rev-1-aruba-fabric-composer-multiple-0\">HPESBNW04996 rev.1\u00a0- Aruba Fabric Composer, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-061","alert_type":396,"serial_number":"AV26-061","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7210,"title":"[Control systems] Siemens security advisory (AV26-062)","uuid":"4b3459f7-32f9-4dcd-ac79-c5c7f82ae751","banner":null,"lang":"en","date_modified":"2026-01-28","date_modified_ts":"2026-01-28T18:51:25Z","date_created":"2026-01-28T18:46:01Z","summary":null,"body":["<article data-history-node-id=\"7210\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-062\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-062<br \/><strong>Date: <\/strong>January 28, 2026<\/p>\n\n<p>On January 28, 2026, Siemens published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>RUGGEDCOM RST2428P (6GK6242-6PA00)\u00a0\u2013 versions prior to V3.3<\/li>\n\t<li>Siemens SCALANCE XCM-\/XRM-\/XCH-\/XRH-300 family\u00a0\u2013 versions prior to V3.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-089022.html?ste_sid=99ddf3824c2231b7428bb6c846568445\">SSA-089022: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.3<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-062","alert_type":398,"serial_number":"AV26-062","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7211,"title":"SolarWinds security advisory (AV26-063) - Update 2","uuid":"a26749cc-e9da-4fa5-a4dd-43477222e221","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T13:29:01Z","date_created":"2026-01-28T18:54:10Z","summary":null,"body":["<article data-history-node-id=\"7211\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-063-update-1\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-063<br \/><strong>Date: <\/strong>January 28, 2026<br \/><strong>Date: <\/strong>February 13, 2026<\/p>\n\n<p>On January 28, 2026, SolarWinds published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>SolarWinds Web Help Desk\u00a0\u2013 versions prior to 2026.1<\/li>\n\t<li>SolarWinds Web Help Desk\u00a0\u2013 version 12.8.8 HF1 and prior<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On February 3, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-40551 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On February 12, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-40536 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-40551\">CISA KEV: CVE-2025-40551<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-40536\">CISA KEV: CVE-2025-40536<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-063-update-1","alert_type":396,"serial_number":"AV26-063","subject":"other","moderation_state":"published","external_url":null},{"nid":7212,"title":"Tenable security advisory (AV26-064)","uuid":"8261af5f-4d6c-4fea-a1bb-77bbbe791aa6","banner":null,"lang":"en","date_modified":"2026-01-28","date_modified_ts":"2026-01-28T20:24:58Z","date_created":"2026-01-28T20:17:26Z","summary":null,"body":["<article data-history-node-id=\"7212\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-064\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-064<br \/><strong>Date: <\/strong>January 28, 2026<\/p>\n\n<p>On January 27, 2026, Tenable published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Tenable Network Monitor\u00a0\u2013 versions prior to 6.5.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-02\">[R1] Tenable Network Monitor Version 6.5.3 Fixes Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-064","alert_type":396,"serial_number":"AV26-064","subject":"other","moderation_state":"published","external_url":null},{"nid":7213,"title":"Drupal security advisory (AV26-065)","uuid":"ce2a982d-ab33-4d8a-bb59-99d9a1b47cbb","banner":null,"lang":"en","date_modified":"2026-01-28","date_modified_ts":"2026-01-28T20:45:23Z","date_created":"2026-01-28T20:36:33Z","summary":null,"body":["<article data-history-node-id=\"7213\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-065\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-065<br \/><strong>Date: <\/strong>January 28, 2026<\/p>\n\n<p>On January 28, 2026, Drupal published security advisories to address vulnerabilities in the following products\u00a0:<\/p>\n\n<ul><li>Drupal Canvas\u00a0\u2013 versions prior to 1.0.4<\/li>\n\t<li>Central Authentication System (CAS) Server\u00a0\u2013 versions prior to 2.0.3, version 2.1.0 to versions prior to 2.1.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-006\">Drupal Canvas\u00a0- Access bypass\u00a0- SA-CONTRIB-2026-006<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-007\">Central Authentication System (CAS) Server\u00a0- XML Element Injection\u00a0- SA-CONTRIB-2026-007<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-065","alert_type":396,"serial_number":"AV26-065","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7215,"title":" [Control systems] B&R security advisory (AV26-066) ","uuid":"64fb6ee5-1afb-45ae-acd6-fce19f34af90","banner":null,"lang":"en","date_modified":"2026-01-29","date_modified_ts":"2026-01-29T19:35:12Z","date_created":"2026-01-29T18:52:02Z","summary":null,"body":["<article data-history-node-id=\"7215\" about=\"\/en\/alerts-advisories\/control-systems-br-security-advisory-av26-066\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-066<br \/><strong>Date: <\/strong>January 29, 2026<\/p>\n\n<p>On January 29, 2026, B&amp;R published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PVI\u00a0\u2013 versions prior to 6.5.0<\/li>\n\t<li>B&amp;R PCs\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA24P003-bb9ea116.pdf\">SA24P003: B&amp;R PCs vulnerable to PixieFail attack (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA26P001-2862434c.pdf\">SA26P001: Insertion of sensitive Information into PVI Logfile (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.br-automation.com\/en\/service\/cyber-security\/cyber-security-advisories-and-notices\/\">B&amp;R Cyber Security Advisories and Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-br-security-advisory-av26-066","alert_type":398,"serial_number":"AV26-066","subject":"br-automation","moderation_state":"published","external_url":null},{"nid":7216,"title":"Citrix security advisory (AV25-067)","uuid":"090cd186-7465-4cc4-a370-1e5add42dcd6","banner":null,"lang":"en","date_modified":"2026-01-29","date_modified_ts":"2026-01-29T20:16:14Z","date_created":"2026-01-29T20:11:30Z","summary":null,"body":["<article data-history-node-id=\"7216\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av25-067\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-067<br \/><strong>Date: <\/strong>January 27, 2026<\/p>\n\n<p>On January 27, 2026, Citrix published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>XenServer\u00a0\u2013 version 8.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX695997&amp;articleURL=XenServer_Security_Update_for_CVE_2025_58151_and_CVE_2026_23553\">Citrix Security Advisory\u00a0\u2013 CTX695997<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\">Citrix Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av25-067","alert_type":396,"serial_number":"AV26-067","subject":"citrix","moderation_state":"published","external_url":null},{"nid":7217,"title":"Ivanti security advisory (AV26-068) \u2013 Update 2","uuid":"331b6b85-9f24-4a66-ad38-5a9d7b9e56fc","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T17:58:01Z","date_created":"2026-01-29T20:45:35Z","summary":null,"body":["<article data-history-node-id=\"7217\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-068\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-068<br \/><strong>Date: <\/strong>January 29, 2026<br \/><strong>Updated: <\/strong>April 8, 2026<\/p>\n\n<p>On January 29, 2026, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ivanti<\/span> published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 version 12.5.0.0 and prior, 12.6.0.0 and prior, 12.7.0.0 and prior, version 12.5.1.0 and prior and 12.6.1.0 and prior<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p class=\"mrgn-bttm-md\">On January 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1281 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2>Update 2<\/h2>\n\n<p>On April 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1340 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>Ivanti has stated that vulnerabilities CVE-2026-1281 &amp; CVE-2026-1340 have been exploited in the wild.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US\">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp; CVE-2026-1340)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US\">Analysis Guidance Ivanti Endpoint Manager Mobile (EPMM) CVE-2026-1281 &amp; CVE-2026-1340<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-1281\">CISA KEV: CVE-2026-1281<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-1340\">CISA KEV: CVE-2026-1340<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-068","alert_type":396,"serial_number":"AV26-068","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7219,"title":"WatchGuard security advisory (AV26-069)","uuid":"e97d0bf7-7e42-4f5d-ad9d-4a80ce4b73a8","banner":null,"lang":"en","date_modified":"2026-01-30","date_modified_ts":"2026-01-30T16:38:46Z","date_created":"2026-01-30T16:32:43Z","summary":null,"body":["<article data-history-node-id=\"7219\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-069\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-069<br \/><strong>Date: <\/strong>January 30, 2026<\/p>\n\n<p>On January 29, 2026, WatchGuard published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Fireware OS\u00a0\u2013 versions prior to 2026.1<\/li>\n\t<li>Fireware OS\u00a0\u2013 versions prior to 12.11.7<\/li>\n\t<li>Fireware OS\u00a0\u2013 versions prior to 12.5.16<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00001\">WatchGuard Firebox LDAP Injection\u00a0- CVE-2026-1498<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-069","alert_type":396,"serial_number":"AV26-069","subject":"other","moderation_state":"published","external_url":null},{"nid":7220,"title":"Microsoft Edge security advisory (AV26-070)","uuid":"8c07ffe9-85da-4dc1-8229-dd4909a2f40e","banner":null,"lang":"en","date_modified":"2026-01-30","date_modified_ts":"2026-01-30T16:46:16Z","date_created":"2026-01-30T16:42:01Z","summary":null,"body":["<article data-history-node-id=\"7220\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-070\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-070<br \/><strong>Date: <\/strong>January 30, 2026<\/p>\n\n<p>On January 29, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 144.0.3719.104<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#january-29-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-070","alert_type":396,"serial_number":"AV26-070","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7221,"title":"Mozilla security advisory (AV26-071)","uuid":"48f27495-ddbd-44c4-9cc7-3a0771563d8b","banner":null,"lang":"en","date_modified":"2026-01-30","date_modified_ts":"2026-01-30T19:19:22Z","date_created":"2026-01-30T19:13:46Z","summary":null,"body":["<article data-history-node-id=\"7221\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-071\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-071<br \/><strong>Date: <\/strong>January 30, 2026<\/p>\n\n<p>On January 27, 2026, Mozilla published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 147.0.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-06\/\">Mozilla Foundation Security Advisory 2026-06<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-071","alert_type":396,"serial_number":"AV26-071","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7222,"title":"IBM security advisory (AV26-072)","uuid":"ec2d258b-f76d-40c7-bef1-c2274e958eb9","banner":null,"lang":"en","date_modified":"2026-02-02","date_modified_ts":"2026-02-02T17:10:11Z","date_created":"2026-02-02T16:52:51Z","summary":null,"body":["<article data-history-node-id=\"7222\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-072\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-072<br \/><strong>Date: <\/strong>February 2, 2026<\/p>\n\n<p>Between January 26 and February 1, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>API Connect\u00a0\u2013 versions V10.0.8.0 to 10.0.8.5<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 versions V24.0.0 to V24.0.0-IF007<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 versions V24.0.1 to V24.0.1-IF005<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0\u2013 versions V25.0.0 to V25.0.0-IF002<\/li>\n\t<li>IBM DB2 Data Management Console\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Db2 Big SQL on Cloud Pak for Data\u00a0\u2013 version IBM Db2 Big SQL 7.6 on Cloud Pak for Data 4.8<\/li>\n\t<li>IBM Db2 Big SQL on Cloud Pak for Data\u00a0\u2013 version IBM Db2 Big SQL 7.7 on Cloud Pak for Data 5.0<\/li>\n\t<li>IBM Db2 Big SQL on Cloud Pak for Data\u00a0\u2013 version IBM Db2 Big SQL 7.8.0 on Cloud Pak for Data 5.1.0<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 versions 8.10, 8.11, 9.0 and 9.1<\/li>\n\t<li>IBM OS Image for Red Hat Linux Systems\u00a0\u2013 versions 4.0.4.0, 4.0.5.0, 4.0.6.0 and 4.0.7.0<\/li>\n\t<li>IBM OS Image for Red Hat Linux Systems\u00a0\u2013 versions 5.0.0.0 and 5.0.1.0<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0\u2013 versions Build 1.0.283 to 1.0.309<\/li>\n\t<li>Maximo AI Service\u00a0\u2013 version 9.1.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-072","alert_type":396,"serial_number":"AV26-072","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7223,"title":"Dell security advisory (AV26-073)","uuid":"bdf94e82-d112-4399-ae6b-a4d97d30d998","banner":null,"lang":"en","date_modified":"2026-02-02","date_modified_ts":"2026-02-02T17:29:53Z","date_created":"2026-02-02T17:12:41Z","summary":null,"body":["<article data-history-node-id=\"7223\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-073\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-073<br \/><strong>Date: <\/strong>February 2, 2026<\/p>\n\n<p>Between January 26 and February 1, 2026, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 versions prior to 03.04.03.00<\/li>\n\t<li>Dell CloudBoost Virtual Appliance\u00a0\u2013 versions prior to 19.14.0.0<\/li>\n\t<li>Dell EMC Networking VEP1425\/VEP1445\/VEP1485\u00a0- versions prior to 2.6<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 versions 19.8 to 19.13.0.2<\/li>\n\t<li>Dell Networking VEP4600\u00a0- versions prior to 4.3<\/li>\n\t<li>Dell OpenManage Network Integration\u00a0\u2013 versions prior to 3.9<\/li>\n\t<li>Dell PowerSwitch E3200-ON Series\u00a0- versions prior to 3.57.5.1-5<\/li>\n\t<li>Dell PowerSwitch N2200-ON Series\u00a0- versions prior to 3.45.5.1-31<\/li>\n\t<li>Dell PowerSwitch N3200-ON Series\u00a0- versions prior to 3.45.5.1-31<\/li>\n\t<li>Dell PowerSwitch S5448F-ON\u00a0- versions prior to 3.52.5.1-12<\/li>\n\t<li>Dell PowerSwitch Z9264F-ON\u00a0- versions prior to 3.42.5.1-21<\/li>\n\t<li>Dell PowerSwitch Z9432F-ON\u00a0- versions prior to 3.51.5.1-21<\/li>\n\t<li>Dell PowerSwitch Z9664F-ON\u00a0- versions prior to 3.54.5.1-9<\/li>\n\t<li>Dell SD-WAN EDGE610\/610-LTE\u00a0- versions prior to 3.43.0.9-24<\/li>\n\t<li>Dell SD-WAN EDGE620\/640\/680\u00a0- versions prior to 3.50.0.9-21<\/li>\n\t<li>Dell Unity Operating Environment (OE)\u00a0\u2013 versions prior to 5.5.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-073","alert_type":396,"serial_number":"AV26-073","subject":"dell","moderation_state":"published","external_url":null},{"nid":7224,"title":"[Control systems] CISA ICS security advisories (AV26\u2013074)","uuid":"a4db496a-327f-41fe-9ef7-862b72e5d337","banner":null,"lang":"en","date_modified":"2026-02-02","date_modified_ts":"2026-02-02T17:46:49Z","date_created":"2026-02-02T17:34:25Z","summary":null,"body":["<article data-history-node-id=\"7224\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-074\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-074<br \/><strong>Date: <\/strong>February 2, 2026<\/p>\n\n<p>Between January 26 and February 1, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Festo Didactic SE MES PC\u00a0\u2013 version shipped with Windows 10<\/li>\n\t<li>Johnson Controls Metasys Application and Data Server (ADS)\u00a0\u2013 version 14.1 and prior<\/li>\n\t<li>Johnson Controls Metasys Controller Configuration Tool (CCT)\u00a0\u2013 version 17.0 and prior<\/li>\n\t<li>Johnson Controls Metasys Extended Application and Data Server (ADX)\u00a0\u2013 version 14.1 and prior<\/li>\n\t<li>Johnson Controls Metasys LCS8500\u00a0\u2013 version 12.0 to version 14.1 and prior<\/li>\n\t<li>Johnson Controls Metasys NAE8500\u00a0\u2013 version 12.0 to version 14.1 and prior<\/li>\n\t<li>Johnson Controls Metasys System Configuration Tool (SCT)\u00a0\u2013 version 17.1 and prior<\/li>\n\t<li>KiloView Encoder Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Rockwell Automation ArmorStart LT 290D\/291D\/294D\u00a0\u2013 version V2.002 and prior<\/li>\n\t<li>Rockwell Automation ControlLogix\u00a0\u2013 all versions<\/li>\n\t<li>Schneider Electric Zigbee Products\u00a0\u2013 multiple versions and models<\/li>\n\t<li>iba Systems ibaPDA\u00a0\u2013 version 8.12.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-074","alert_type":398,"serial_number":"AV26-074","subject":"ics","moderation_state":"published","external_url":null},{"nid":7225,"title":"VMware security advisory (AV26-075)","uuid":"c45e2c96-3598-4543-9516-f575cb27890c","banner":null,"lang":"en","date_modified":"2026-02-02","date_modified_ts":"2026-02-02T17:58:38Z","date_created":"2026-02-02T17:49:56Z","summary":null,"body":["<article data-history-node-id=\"7225\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-075\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-075<br \/><strong>Date: <\/strong>February 2, 2026<\/p>\n\n<p>Between January 26 and February 1, 2026, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<ul><li>Platform Services for VMware Tanzu Platform \u2013 versions prior to 10.3.4<\/li>\n\t<li>Python Buildpack\u00a0\u2013 versions prior to 1.8.71 and 1.8.75<\/li>\n\t<li>Ruby Buildpack\u00a0\u2013 versions prior to 1.10.53<\/li>\n\t<li>Service Publisher for VMware Tanzu Platform\u00a0\u2013 versions prior to 10.3.4<\/li>\n\t<li>Stemcells (Ubuntu Jammy FIPS)\u00a0\u2013 versions prior to 1.1016.x<\/li>\n\t<li>Stemcells (Ubuntu Noble)\u00a0\u2013 versions prior to 1.188.x<\/li>\n\t<li>Stemcells (Windows)\u00a0\u2013 versions prior to 2019.94.x<\/li>\n\t<li>Tanzu Hub\u00a0\u2013 versions prior to 10.3.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-075","alert_type":396,"serial_number":"AV26-075","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7226,"title":"Ubuntu security advisory (AV26-076)","uuid":"6c92ed38-b30c-4a85-b104-457d568a0251","banner":null,"lang":"en","date_modified":"2026-02-02","date_modified_ts":"2026-02-02T19:40:06Z","date_created":"2026-02-02T19:31:00Z","summary":null,"body":["<article data-history-node-id=\"7226\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-076\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-076<br \/><strong>Date: <\/strong>February 2, 2026<\/p>\n\n<p>Between January 26 and February 1, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following product:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-076","alert_type":396,"serial_number":"AV26-076","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7227,"title":"BeyondTrust security advisory (AV26-077)","uuid":"25832139-ae9b-4cc7-8f5f-75abfdef8b59","banner":null,"lang":"en","date_modified":"2026-02-02","date_modified_ts":"2026-02-02T19:49:12Z","date_created":"2026-02-02T19:42:39Z","summary":null,"body":["<article data-history-node-id=\"7227\" about=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-077\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-077<br \/><strong>Date: <\/strong>February 2, 2026<\/p>\n\n<p>On February 2, 2026, BeyondTrust published security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Privilege Management for Windows\u00a0\u2013 versions prior to 25.8<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt26-01\">BeyondTrust Security Advisory\u00a0- Advisory ID: BT26-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\">BeyondTrust Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-077","alert_type":396,"serial_number":"AV26-077","subject":"other","moderation_state":"published","external_url":null},{"nid":7228,"title":"Kubernetes security advisory (AV26-078)","uuid":"a641f3a5-79fa-48dc-8308-6d0641a4d82c","banner":null,"lang":"en","date_modified":"2026-02-03","date_modified_ts":"2026-02-03T14:30:02Z","date_created":"2026-02-03T14:23:23Z","summary":null,"body":["<article data-history-node-id=\"7228\" about=\"\/en\/alerts-advisories\/kubernetes-security-advisory-av26-078\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-078<br \/><strong>Date: <\/strong>February 3, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On February 2, 2026, Kubernetes published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Kubernetes ingress-nginx\u00a0- versions prior to v1.13.7<\/li>\n\t<li>Kubernetes ingress-nginx\u00a0- versions prior to v1.14.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.kubernetes.io\/t\/security-advisory-multiple-issues-in-ingress-nginx\/34115\">Kubernetes Security Advisory\u00a0- Multiple issues in ingress-nginx<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/kubernetes-security-advisory-av26-078","alert_type":396,"serial_number":"AV26-078","subject":"other","moderation_state":"published","external_url":null},{"nid":7229,"title":"Samsung mobile security advisory (AV26-079)","uuid":"8b3acfb2-ea1f-48c8-8717-a9a2e404c820","banner":null,"lang":"en","date_modified":"2026-02-03","date_modified_ts":"2026-02-03T18:45:28Z","date_created":"2026-02-03T18:40:53Z","summary":null,"body":["<article data-history-node-id=\"7229\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-079\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-079<br \/><strong>Date: <\/strong>February 3, 2026<\/p>\n\n<p>On February 3, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices\u00a0\u2013 versions prior to SMR-FEB-2026<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The most recent security update resolves multiple identified vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=02\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-079","alert_type":396,"serial_number":"AV26-079","subject":"other","moderation_state":"published","external_url":null},{"nid":7230,"title":"Tenable security advisory (AV26-080)","uuid":"41c2bf3f-a4eb-4c33-8a40-96f0a55cec06","banner":null,"lang":"en","date_modified":"2026-02-03","date_modified_ts":"2026-02-03T20:27:08Z","date_created":"2026-02-03T20:09:00Z","summary":null,"body":["<article data-history-node-id=\"7230\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-080\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-080<br \/><strong>Date: <\/strong>February 3, 2026<\/p>\n\n<p>On February 3, 2026, Tenable published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Tenable Identity Exposure \u2013 versions 3.77.15 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-03\">[R1] Tenable Identity Exposure Version 3.77.16 Fixes Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-080","alert_type":396,"serial_number":"AV26-080","subject":"other","moderation_state":"published","external_url":null},{"nid":7232,"title":"Google Chrome security advisory (AV26-081)","uuid":"c4210482-b82a-46e6-a413-fa520944fad4","banner":null,"lang":"en","date_modified":"2026-02-04","date_modified_ts":"2026-02-04T13:50:42Z","date_created":"2026-02-04T13:35:11Z","summary":null,"body":["<article data-history-node-id=\"7232\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-081\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number:<\/strong> AV26-081<br \/><strong>Date:<\/strong> February\u00a04, 2026<\/p>\n\n<p>On February\u00a03, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 144.0.7559.132\/.133 (Windows\/Mac) and 144.0.7559.132 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li>\n\t<p><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/02\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/p>\n\t<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-081","alert_type":396,"serial_number":"AV26-081","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7233,"title":"Android security advisory \u2013 February 2026 monthly rollup (AV26-082)","uuid":"1ac8bd9c-8c4d-451d-a305-dacaac16743a","banner":null,"lang":"en","date_modified":"2026-02-04","date_modified_ts":"2026-02-04T13:56:11Z","date_created":"2026-02-04T13:35:11Z","summary":null,"body":["<article data-history-node-id=\"7233\" about=\"\/en\/alerts-advisories\/android-security-advisory-february-2026-monthly-rollup-av26-082\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-082<br \/><strong>Date: <\/strong>February\u00a04, 2026<\/p>\n\n<p>On February\u00a02, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-02-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-february-2026-monthly-rollup-av26-082","alert_type":396,"serial_number":"AV26-082","subject":"android","moderation_state":"published","external_url":null},{"nid":7234,"title":"Qualcomm security advisory \u2013 February 2026 monthly rollup (AV26-083)","uuid":"9e6dff12-adef-486e-bd15-252007b7e65b","banner":null,"lang":"en","date_modified":"2026-02-04","date_modified_ts":"2026-02-04T14:01:26Z","date_created":"2026-02-04T13:35:12Z","summary":null,"body":["<article data-history-node-id=\"7234\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-february-2026-monthly-rollup-av26-083\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-083<br \/><strong>Date: <\/strong>February\u00a04, 2026<\/p>\n\n<p>On February\u00a02, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/february-2026-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 February<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-february-2026-monthly-rollup-av26-083","alert_type":396,"serial_number":"AV26-083","subject":"other","moderation_state":"published","external_url":null},{"nid":7235,"title":"Django security advisory (AV26-084) \u2013 Update 1","uuid":"47d3a790-d9aa-45fa-bed8-c70ac8d2c393","banner":null,"lang":"en","date_modified":"2026-07-09","date_modified_ts":"2026-07-09T19:45:45Z","date_created":"2026-02-04T14:58:31Z","summary":null,"body":["<article data-history-node-id=\"7235\" about=\"\/en\/alerts-advisories\/django-security-advisory-av26-084\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-084<br \/><strong>Date:<\/strong> February\u00a04, 2026<br \/><strong>Updated:<\/strong> July\u00a09, 2026<\/p>\n\n<p>On February\u00a03, 2026, Django published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Django 4.2\u00a0\u2013 versions prior to 4.2.28<\/li>\n\t<li>Django 5.2\u00a0\u2013 versions prior to 5.2.11<\/li>\n\t<li>Django 6.0\u00a0\u2013 versions prior to 6.0.2<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-1207 is being exploited.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.djangoproject.com\/weblog\/2026\/feb\/03\/security-releases\/\">Django Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/django-security-advisory-av26-084","alert_type":396,"serial_number":"AV26-084","subject":"other","moderation_state":"published","external_url":null},{"nid":7236,"title":"[Control Systems] Moxa security advisory (AV26-085)","uuid":"f1e95f1c-33e1-45da-9898-cf1dab3b9232","banner":null,"lang":"en","date_modified":"2026-02-04","date_modified_ts":"2026-02-04T16:40:27Z","date_created":"2026-02-04T16:31:01Z","summary":null,"body":["<article data-history-node-id=\"7236\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-085\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-085<br \/><strong>Date: <\/strong>February 4, 2026<\/p>\n\n<p>On February 4, 2026, Moxa published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>TN-A Series\u00a0\u2013 firmware version v4.1 and prior<\/li>\n\t<li>TN-G Series\u00a0\u2013 firmware version v5.5 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-241409-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-in-ethernet-switches\">CVE-2024-12297: Frontend Authorization Logic Disclosure Vulnerability in Ethernet Switches<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-085","alert_type":398,"serial_number":"AV26-085","subject":"other","moderation_state":"published","external_url":null},{"nid":7237,"title":"F5 security advisory (AV26-086)","uuid":"60eccdd1-f0b7-498d-90c2-570ef0df05f0","banner":null,"lang":"en","date_modified":"2026-02-04","date_modified_ts":"2026-02-04T16:53:14Z","date_created":"2026-02-04T16:42:32Z","summary":null,"body":["<article data-history-node-id=\"7237\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-086\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-086<br \/><strong>Date: <\/strong>February 4, 2026<\/p>\n\n<p>On February 4, 2026, F5 published security updates for multiple products. Included were updates for the following:<\/p>\n\n<ul><li>APM Clients\u00a0\u2013 versions 7.2.5 to 7.2.6.1<\/li>\n\t<li>BIG-IP (all modules)\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IP APM\u00a0\u2013 multiple versions<\/li>\n\t<li>BIG-IP Advanced WAF\/ASM\u00a0\u2013 versions 17.1.0 to 17.1.2<\/li>\n\t<li>BIG-IP Container Ingress Services for Kubernetes and OpenShift\u00a0\u2013 versions 2.0.0 to 2.20.1, versions 1.0.0 to 1.14.0<\/li>\n\t<li>NGINX Gateway Fabric\u00a0\u2013 versions 2.0.0 to 2.4.0, versions 1.2.0 to 1.6.2<\/li>\n\t<li>NGINX Ingress Controller\u00a0\u2013 multiple versions<\/li>\n\t<li>NGINX Instance Manager\u00a0\u2013 versions 2.15.1 to 2.21.0<\/li>\n\t<li>NGINX Open Source\u00a0\u2013 versions 1.3.0 to 1.29.4<\/li>\n\t<li>NGINX Plus\u00a0\u2013 versions R32 to R36 P1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000159076\">K000159076: Quarterly Security Notification (February 2026)<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-086","alert_type":396,"serial_number":"AV26-086","subject":"f5","moderation_state":"published","external_url":null},{"nid":7238,"title":"Cisco security advisory (AV26-087)","uuid":"cd7c990c-a0ce-40e4-86af-85cb17ffd58a","banner":null,"lang":"en","date_modified":"2026-02-04","date_modified_ts":"2026-02-04T20:37:07Z","date_created":"2026-02-04T20:30:14Z","summary":null,"body":["<article data-history-node-id=\"7238\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-087\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-087<br \/><strong>Date: <\/strong>February 4, 2026<\/p>\n\n<p>On February 4, 2026, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco AsyncOS for Cisco Secure Web Appliance\u00a0- versions prior to 15.2.5-011<\/li>\n\t<li>Cisco Evolved Programmable Network Manager (EPNM)\u00a0\u2013 versions prior to 8.1.1<\/li>\n\t<li>Cisco Meeting Management Release\u00a0\u2013 versions prior to 3.12.1 MR<\/li>\n\t<li>Cisco Prime Infrastructure\u00a0\u2013 versions prior to 3.10.6 Security Update 2<\/li>\n\t<li>Cisco TelePresence CE Software in Cloud-Aware Operation\u00a0\u2013 versions prior to RoomOS October 2025 Release<\/li>\n\t<li>Cisco TelePresence CE Software in Cloud-Aware Operation\u00a0\u2013 versions prior to RoomOS December 2025 Release<\/li>\n\t<li>Cisco RoomOS Software in Cloud-Aware Operation\u00a0\u2013 versions prior to RoomOS October 2025 Release<\/li>\n\t<li>Cisco RoomOS Software in Cloud-Aware Operation\u00a0\u2013 versions prior to RoomOS December 2025 Release<\/li>\n\t<li>Cisco TelePresence CE Software in On-Premises Operation\u00a0\u2013 versions prior to 11.27.5.0 and 11.32.3.0<\/li>\n\t<li>Cisco RoomOS Software in On-Premises Operation\u00a0\u2013 versions prior to 11.27.5.0 and 11.32.3.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-087","alert_type":396,"serial_number":"AV26-087","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7239,"title":"Splunk security advisory (AV26-088)","uuid":"a5045790-4dea-4892-a2d5-90faacee5ae6","banner":null,"lang":"en","date_modified":"2026-02-04","date_modified_ts":"2026-02-04T20:53:34Z","date_created":"2026-02-04T20:48:46Z","summary":null,"body":["<article data-history-node-id=\"7239\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-088\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-088<br \/><strong>Date: <\/strong>February 4, 2026<\/p>\n\n<p>On February 4, 2026, Splunk published security advisories to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Splunk SOAR\u00a0\u2013 versions prior to 7.1.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0201\">Third-Party Package Updates in Splunk SOAR\u00a0- February 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-088","alert_type":396,"serial_number":"AV26-088","subject":"other","moderation_state":"published","external_url":null},{"nid":7241,"title":"TeamViewer security advisory (AV26-090)","uuid":"7cfdbb35-48e3-465c-b074-615a4b87a23e","banner":null,"lang":"en","date_modified":"2026-02-05","date_modified_ts":"2026-02-05T16:47:30Z","date_created":"2026-02-05T15:41:46Z","summary":null,"body":["<article data-history-node-id=\"7241\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av26-090\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-090<br \/><strong>Date:<\/strong> February\u00a05, 2026<\/p>\n\n<p>On February\u00a05, 2026, TeamViewer released a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>TeamViewer Full Client (Windows)\u00a0\u2013 versions prior to 15.74.5<\/li>\n\t<li>TeamViewer Full Client (macOS)\u00a0\u2013 versions prior to 15.74.5<\/li>\n\t<li>TeamViewer Full Client (Linux)\u00a0\u2013 versions prior to 15.74.5<\/li>\n\t<li>TeamViewer Host (Windows)\u00a0\u2013 versions prior to 15.74.5<\/li>\n\t<li>TeamViewer Host (macOS)\u00a0\u2013 versions prior to 15.74.5<\/li>\n\t<li>TeamViewer Host (Linux)\u00a0\u2013 versions prior to 15.74.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/tv-2026-1003\/\">Access control vulnerability in TeamViewer Full and Host clients\u00a0- TV-2026-1003<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">TeamViewer Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av26-090","alert_type":396,"serial_number":"AV26-090","subject":"other","moderation_state":"published","external_url":null},{"nid":7240,"title":"GitLab security advisory (AV26-089)","uuid":"9fc76f90-01e0-4ebb-8491-1c6d74fbe6a1","banner":null,"lang":"en","date_modified":"2026-02-05","date_modified_ts":"2026-02-05T16:32:13Z","date_created":"2026-02-05T15:41:46Z","summary":null,"body":["<article data-history-node-id=\"7240\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-089\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-089<br \/><strong>Date:<\/strong> February\u00a05, 2026<\/p>\n\n<p>On February\u00a04, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.8.3, 18.7.3 and 18.6.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.8.3, 18.7.3 and 18.6.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/02\/04\/gitlab-18-8-3-released\/\">GitLab Patch Release: 18.8.3, 18.7.3, 18.6.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-089","alert_type":396,"serial_number":"AV26-089","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7242,"title":"n8n security advisory (AV26-091)","uuid":"7be3fdb9-a46b-4f65-9007-74c3a58e7657","banner":null,"lang":"en","date_modified":"2026-02-05","date_modified_ts":"2026-02-05T16:56:30Z","date_created":"2026-02-05T15:41:47Z","summary":null,"body":["<article data-history-node-id=\"7242\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-091\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-091<br \/><strong>Date:<\/strong> February\u00a05, 2026<\/p>\n\n<p>On February\u00a04, 2026, n8n published security updates to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>n8n (Merge Node)\u00a0\u2013 versions prior to 1.118.0 and versions prior to 2.4.0<\/li>\n\t<li>n8n (Git Node)\u00a0\u2013 versions prior to 1.123.10 and versions prior to 2.5.0<\/li>\n\t<li>n8n (SSH Node)\u00a0\u2013 versions prior to 1.123.12 and versions prior to 2.4.0<\/li>\n\t<li>n8n (Workflow UI)\u00a0\u2013 versions prior to 1.23.9 and versions prior to 2.2.1<\/li>\n\t<li>n8n\u00a0\u2013 versions prior to 1.123.17 and versions prior to 2.5.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-6cqr-8cfr-67f8\">Expression Escape Vulnerability Leading to RCE\u00a0- (CVE-2025-68613) (CVE-2026-25049)<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-hv53-3329-vmrm\">Arbitrary File Write leading to RCE in n8n Merge Node<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-9g95-qf3f-ggrw\">OS Command Injection in Git Node<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-m82q-59gv-mcr9\">Arbitrary File Write on Remote Systems via SSH Node<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-qpq4-pw7f-pp8w\">Stored Cross-Site Scripting via Markdown Rendering in Workflow UI<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-091","alert_type":396,"serial_number":"AV26-091","subject":"other","moderation_state":"published","external_url":null},{"nid":7243,"title":"Zyxel security advisory (AV26-092)","uuid":"1729dd14-1d96-4f16-a71b-596faf5b4b1f","banner":null,"lang":"en","date_modified":"2026-02-05","date_modified_ts":"2026-02-05T19:08:58Z","date_created":"2026-02-05T18:35:39Z","summary":null,"body":["<article data-history-node-id=\"7243\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av26-092\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-092<br \/><strong>Date: <\/strong>February\u00a05, 2026<\/p>\n\n<p>On February\u00a05, 2026, Zyxel published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ATP\u00a0\u2013 versions ZLD V5.35 to V5.41<\/li>\n\t<li>USG FLEX\u00a0\u2013 versions ZLD V5.35 to V5.41<\/li>\n\t<li>USG FLEX 50(W)\/ USG20(W)-VPN\u00a0\u2013 versions ZLD V5.35 to V5.41<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-the-ddns-configuration-cli-command-of-zld-firewalls-02-05-2026\">Zyxel security advisory for post-authentication command injection vulnerability in the DDNS configuration CLI command of ZLD firewalls<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av26-092","alert_type":396,"serial_number":"AV26-092","subject":"other","moderation_state":"published","external_url":null},{"nid":7245,"title":"Microsoft Edge security advisory (AV26-093)","uuid":"849dd5bc-db38-4abe-9572-9d09f07b906e","banner":null,"lang":"en","date_modified":"2026-02-06","date_modified_ts":"2026-02-06T14:10:25Z","date_created":"2026-02-06T14:07:26Z","summary":null,"body":["<article data-history-node-id=\"7245\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-093\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-093<br \/><strong>Date: <\/strong>February 6, 2026<\/p>\n\n<p>On February 5, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 144.0.3719.115<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-5-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-093","alert_type":396,"serial_number":"AV26-093","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7246,"title":"[Control Systems] Moxa security advisory (AV26-094)","uuid":"c07727e9-bdce-499f-8563-1d0d42a29718","banner":null,"lang":"en","date_modified":"2026-02-06","date_modified_ts":"2026-02-06T14:26:19Z","date_created":"2026-02-06T14:13:37Z","summary":null,"body":["<article data-history-node-id=\"7246\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-094\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-094<br \/><strong>Date: <\/strong>February 6, 2026<\/p>\n\n<p>On February 6, 2026, Moxa published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>UC Series\u00a0\u2013 version OS image (MIL v3.4.1) and prior<\/li>\n\t<li>V Series\u00a0\u2013 version OS image (MIL3) and prior<\/li>\n\t<li>V2406C Series\u00a0\u2013 version OS image (MIL2) and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-255121-cve-2026-0714-cve-2026-0715-multiple-vulnerabilities-in-industrial-computers\">CVE-2026-0714, CVE-2026-0715: Multiple Vulnerabilities in Industrial Computers<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-094","alert_type":398,"serial_number":"AV26-094","subject":"other","moderation_state":"published","external_url":null},{"nid":7247,"title":"Tenable security advisory (AV26-095)","uuid":"ecec4240-9e97-46da-9de3-5cfa5a880150","banner":null,"lang":"en","date_modified":"2026-02-06","date_modified_ts":"2026-02-06T14:38:07Z","date_created":"2026-02-06T14:28:22Z","summary":null,"body":["<article data-history-node-id=\"7247\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-095\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-095<br \/><strong>Date: <\/strong>February 6, 2026<\/p>\n\n<p>On February 5, 2026, Tenable published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Nessus\u00a0\u2013 version 10.10.1 and prior<\/li>\n\t<li>Nessus\u00a0\u2013 versions 10.11.0 to 10.11.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-04\">[R1] Nessus Versions 10.10.2 and 10.11.2 Fix Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-095","alert_type":396,"serial_number":"AV26-095","subject":"other","moderation_state":"published","external_url":null},{"nid":7248,"title":"Fortinet security advisory (AV26-096) \u2013 Update 2","uuid":"60ca61dc-7677-4a2e-bb27-7c8f73c66c78","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T18:50:26Z","date_created":"2026-02-09T14:17:02Z","summary":null,"body":["<article data-history-node-id=\"7248\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-096\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-096<br \/><strong>Date: <\/strong>February 9, 2026<br \/><strong>Updated: <\/strong>April 13, 2026<\/p>\n\n<p>On February 6, 2026, Fortinet published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>FortiClientEMS 7.4 \u2013 version 7.4.4<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p class=\"mrgn-bttm-md\">Open-source reporting indicates that CVE-2026-21643 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p class=\"mrgn-bttm-md\">On April 13, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21643 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-25-1142\">SQLi in administrative interface \u2013 FG-IR-25-1142 (CVE-2026-21643)<\/a><\/li>\n\t<li><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/89.html\">CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-21643\">CISA KEV: CVE-2026-21643<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-096","alert_type":396,"serial_number":"AV26-096","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7249,"title":"BeyondTrust security advisory (AV26-097) - Update 2","uuid":"4752195b-03c4-40fe-9f0f-514d3921a1e3","banner":null,"lang":"en","date_modified":"2026-02-16","date_modified_ts":"2026-02-16T14:55:46Z","date_created":"2026-02-09T14:35:14Z","summary":null,"body":["<article data-history-node-id=\"7249\" about=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-097\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-097<br \/><strong>Date: <\/strong>February 9, 2026<br \/><strong>Updated: <\/strong>February 16, 2026<\/p>\n\n<p>On February 6, 2026, BeyondTrust published security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Remote Support\u00a0\u2013 version 25.3.1 and prior<\/li>\n\t<li>Privileged Remote Access\u00a0\u2013 version 24.3.4 and prior<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-1731 vulnerability is being exploited.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On February 13, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1731 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt26-02\">BeyondTrust Security Advisory\u00a0- Advisory ID: BT26-02 (CVE-2026-1731)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\">BeyondTrust Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1731\">CISA KEV: CVE-2026-1731<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-097","alert_type":396,"serial_number":"AV26-097","subject":"other","moderation_state":"published","external_url":null},{"nid":7250,"title":"Red Hat security advisory (AV26-098)","uuid":"5835a4a4-5048-4e94-9cde-a8500ea8858b","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T14:50:54Z","date_created":"2026-02-09T14:43:46Z","summary":null,"body":["<article data-history-node-id=\"7250\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-098\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-098<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>Between February 2 and 8, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-098","alert_type":396,"serial_number":"AV26-098","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7251,"title":"Ubuntu security advisory (AV26-099)","uuid":"847666e9-04eb-4f6c-9a89-4c9e6e0ebfc8","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T15:01:29Z","date_created":"2026-02-09T14:52:45Z","summary":null,"body":["<article data-history-node-id=\"7251\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-099\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-099<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>Between February 2 and 8, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-099","alert_type":396,"serial_number":"AV26-099","subject":"other","moderation_state":"published","external_url":null},{"nid":7252,"title":"IBM security advisory (AV26-100)","uuid":"38da0697-115a-41f8-9b80-870bc34f48ed","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T15:09:07Z","date_created":"2026-02-09T15:05:13Z","summary":null,"body":["<article data-history-node-id=\"7252\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-100\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-100<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>Between February 2 and 8, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM webMethods Integration \u2013 versions 10.15 to 10.15 Fix 13<\/li>\n\t<li>IBM webMethods Integration \u2013 versions 11.1 to 11.1 Fix 1<\/li>\n\t<li>IBM webMethods Integration (on prem) \u2013 versions 10.11, 10.15 and 11.1<\/li>\n\t<li>IBM InfoSphere Information Server \u2013 versions 11.7.0.0 to 11.7.1.6<\/li>\n\t<li>IBM Watson Discovery Cartridge \u2013 versions 5.0.0 to 5.2.2<\/li>\n\t<li>IBM API Connect V12 (on prem) \u2013 version 12.1.0.0<\/li>\n\t<li>IBM OpenPages for Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM OpenPages Cloud Pak for Data Service \u2013 multiple versions<\/li>\n\t<li>IBM Common Cryptographic Architecture (CCA) 7 MTM for 4769 \u2013 version 7.5.52<\/li>\n\t<li>IBM Common Cryptographic Architecture (CCA) 8 MTM for 47770 \u2013 version 8.4.82<\/li>\n\t<li>IBM Common Cryptographic Architecture (CCA) 4769 Developers Toolkit \u2013 version 7.5.52<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-100","alert_type":396,"serial_number":"AV26-100","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7253,"title":"VMware security advisory (AV26-101)","uuid":"9f823650-9673-494b-a8f8-91ffcf4cf7d0","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T16:28:07Z","date_created":"2026-02-09T16:22:29Z","summary":null,"body":["<article data-history-node-id=\"7253\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-101\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-101<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>Between February 2 and 8, 2026, VMware published security advisories to address vulnerabilities in multiple Tanzu products:<\/p>\n\n<ul><li>Foundation Core for VMware Tanzu Platform \u2013 versions prior to 3.1.7<\/li>\n\t<li>Foundation Core for VMware Tanzu Platform \u2013 versions prior to 3.2.3<\/li>\n\t<li>Isolation Segmentation for VMware Tanzu Platform \u2013 versions prior to 10.2.7+LTS-T<\/li>\n\t<li>Isolation Segmentation for VMware Tanzu Platform \u2013 versions prior to 10.3.4<\/li>\n\t<li>NodeJS Buildpack \u2013 versions prior to 1.8.74<\/li>\n\t<li>Platform Automation Toolkit \u2013 versions prior to 5.4.0<\/li>\n\t<li>Tanzu Kubernetes Grid Integrated Edition (TKGi) CLI &amp; Tile \u2013 versions prior to 1.24.0<\/li>\n\t<li>Telemetry for VMware Tanzu Platform \u2013 versions prior to 2.4.0<\/li>\n\t<li>VMware Harbor Registry \u2013 versions prior to 2.14.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories \u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-101","alert_type":396,"serial_number":"AV26-101","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7254,"title":"[Control systems] CISA ICS security advisories (AV26\u2013102)","uuid":"533e8407-7718-4999-a14a-d2f8607d53ca","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T16:39:27Z","date_created":"2026-02-09T16:34:40Z","summary":null,"body":["<article data-history-node-id=\"7254\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-102\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-102<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>Between February 2 and 8, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Aviation Light Engine Pro \u2013 all versions<\/li>\n\t<li>Hitachi Energy FOX61x \u2013 versions R18 and R17A and prior<\/li>\n\t<li>Hitachi Energy XMC20 \u2013 versions R17A and prior<\/li>\n\t<li>Ilevia EVE X1 Server \u2013 versions prior to 4.7.18.0<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-R R08\/16\/32\/120PCPU \u2013 firmware version 48 and prior<\/li>\n\t<li>Mitsubishi Electric FREQSHIP-mini for Windows \u2013 versions 8.0.0 to 8.0.2<\/li>\n\t<li>o6 Automation GmbH Open62541 \u2013 versions 1.5-rc1 to versions prior to 1.5-rc2<\/li>\n\t<li>RISS SRL MOMA Seismic Station \u2013 versions 2.4.2520 and prior<\/li>\n\t<li>Synectix LAN 232 TRIO \u2013 all versions<\/li>\n\t<li>TP-Link Systems Inc. VIGI Series IP Camera \u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-102","alert_type":398,"serial_number":"AV26-102","subject":"other","moderation_state":"published","external_url":null},{"nid":7255,"title":"GitLab security advisory (AV26-103)","uuid":"a80031a4-b2b9-4bff-b4e2-acad3dd73069","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T16:45:08Z","date_created":"2026-02-09T16:42:18Z","summary":null,"body":["<article data-history-node-id=\"7255\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-103\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-103<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>On February 6, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Duo Self-Hosted AI Gateway \u2013 versions prior to 18.8.1, 18.7.1 and 18.6.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/02\/06\/patch-release-gitlab-ai-gateway-18-8-1-released\/\">GitLab AI Gateway Critical Patch Release: 18.6.2, 18.7.1, and 18.8.1<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-103","alert_type":396,"serial_number":"AV26-103","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7256,"title":"Dell security advisory (AV26-104)","uuid":"22d42657-2288-4626-91ea-f6570f674462","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T16:50:24Z","date_created":"2026-02-09T16:47:37Z","summary":null,"body":["<article data-history-node-id=\"7256\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-104\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-104<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>Between February 2 and 8, 2026, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell SmartFabric Manager \u2013 versions prior to 2.0.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000422842\/security-update-for-dell-smartfabric-manager-multiple-third-party-component-vulnerabilities\">DSA-2026-070: Security Update for Dell SmartFabric Manager Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-104","alert_type":396,"serial_number":"AV26-104","subject":"dell","moderation_state":"published","external_url":null},{"nid":7257,"title":"JetBrains security advisory (AV26-105)","uuid":"1cad33d9-e03c-4693-88d7-1536c9e52eab","banner":null,"lang":"en","date_modified":"2026-02-09","date_modified_ts":"2026-02-09T19:11:12Z","date_created":"2026-02-09T19:04:04Z","summary":null,"body":["<article data-history-node-id=\"7257\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-105\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-105<br \/><strong>Date: <\/strong>February 9, 2026<\/p>\n\n<p>On February 9, 2026, JetBrains published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>JetBrains Hub\u00a0\u2013 versions prior to 2025.3.119807<\/li>\n\t<li>JetBrains PyCharm\u00a0\u2013 versions prior to 2025.3.2<\/li>\n\t<li>JetBrains YouTrack\u00a0\u2013 versions prior to 2025.3.119033<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-105","alert_type":396,"serial_number":"AV26-105","subject":"other","moderation_state":"published","external_url":null},{"nid":7258,"title":"[Control systems] Siemens security advisory (AV26-106)\u00a0","uuid":"486f024f-7cad-4231-86ed-8f185dc9f59b","banner":null,"lang":"en","date_modified":"2026-02-10","date_modified_ts":"2026-02-10T17:12:56Z","date_created":"2026-02-10T16:53:46Z","summary":null,"body":["<article data-history-node-id=\"7258\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-106\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-106<br \/><strong>Date:<\/strong> February\u00a010, 2026<\/p>\n\n<p>On February\u00a010, 2026, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Simcenter Femap, Simcenter Nastran\u00a0\u2013 versions prior to V2512<\/li>\n\t<li>Siveillance Video Management Servers\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Siemens NX\u00a0\u2013 versions prior to V2512<\/li>\n\t<li>Desigo CC V6, V7 and V8\u00a0\u2013 multiple versions<\/li>\n\t<li>SENTRON Powermanager V6, V7 and V8\u00a0\u2013 multiple versions<\/li>\n\t<li>SIPORT Desktop Client Application\u00a0\u2013 all versions<\/li>\n\t<li>Solid Edge\u00a0\u2013 versions prior to\u00a0\u2013 V226.00 Update 03<\/li>\n\t<li>SINEC NMS\u00a0\u2013 all versions<\/li>\n\t<li>SINEC NMS User Management Component (UMC)\u00a0\u2013 versions prior to V2.15.2.1<\/li>\n\t<li>Polarion V2404\u00a0\u2013 versions prior to V2404.5<\/li>\n\t<li>Polarion V2410\u00a0\u2013 versions prior to V2410.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-106","alert_type":398,"serial_number":"AV26-106","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7259,"title":"SAP security advisory \u2013 February 2026 monthly rollup (AV26-107)","uuid":"322d2712-c935-479c-9ad6-8468510965bd","banner":null,"lang":"en","date_modified":"2026-02-10","date_modified_ts":"2026-02-10T17:32:16Z","date_created":"2026-02-10T16:53:47Z","summary":null,"body":["<article data-history-node-id=\"7259\" about=\"\/en\/alerts-advisories\/sap-security-advisory-february-2026-monthly-rollup-av26-107\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-107<br \/><strong>Date: <\/strong>February\u00a010, 2026<\/p>\n\n<p>On February\u00a010, 2026, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP CRM and SAP S\/4HANA (Scripting Editor)\u00a0\u2013 versions S4FND 102, 103, 104, 105, 106, 107, 108, 109, SAP_ABA 700, WEBCUIF 700, 701, 730, 731, 746, 747, 748, 800 and 801<\/li>\n\t<li>SAP NetWeaver Application Server ABAP and ABAP Platform\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18 and 9.19<\/li>\n\t<li>SAP NetWeaver AS ABAP and ABAP Platform\u00a0\u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 804, SAP_BASIS 916, SAP_BASIS 917 and SAP_BASIS 918<\/li>\n\t<li>SAP Supply Chain Management\u00a0\u2013 versions SCMAPO 713, 714, SCM 700, 701, 702 and 712<\/li>\n\t<li>SAP Solution Tools Plug-In (ST-PI)\u00a0\u2013 versions ST-PI 2008_1_700, 2008_1_710, 740 and 758<\/li>\n\t<li>SAP BusinessObjects BI Platform\u00a0\u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP Commerce Cloud\u00a0\u2013 versions HY_COM 2205, COM_CLOUD 2211 and COM_CLOUD 2211-JDK21<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform\u00a0\u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0488\">CVE-2026-0488 Detail<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0509\">CVE-2026-0509 Detail<\/a><\/li>\n\t<li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/february-2026.html\">SAP Security Patch Day\u00a0- February\u00a02026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-february-2026-monthly-rollup-av26-107","alert_type":396,"serial_number":"AV26-107","subject":"sap","moderation_state":"published","external_url":null},{"nid":7260,"title":"Rapid7 security advisory (AV26-108)","uuid":"af806fc9-663f-4891-8dda-acbcb959257e","banner":null,"lang":"en","date_modified":"2026-02-10","date_modified_ts":"2026-02-10T20:29:41Z","date_created":"2026-02-10T20:22:08Z","summary":null,"body":["<article data-history-node-id=\"7260\" about=\"\/en\/alerts-advisories\/rapid7-security-advisory-av26-108\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-108<br \/><strong>Date:<\/strong> February\u00a010, 2026<\/p>\n\n<p>On February\u00a09, 2026, Rapid7 published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>InsightVM and Nexpose\u00a0\u2013 versions prior to 8.36.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.rapid7.com\/blog\/post\/ve-insightvm-nexpose-vulnerability-cve-2026-1814-fixed\/\">Vulnerability Found in InsightVM &amp; Nexpose: CVE-2026-1814 (FIXED)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rapid7-security-advisory-av26-108","alert_type":396,"serial_number":"AV26-108","subject":"other","moderation_state":"published","external_url":null},{"nid":7262,"title":"HPE security advisory (AV26-110)","uuid":"68d83c52-b1cf-459c-843a-0bea68941062","banner":null,"lang":"en","date_modified":"2026-02-10","date_modified_ts":"2026-02-10T21:24:57Z","date_created":"2026-02-10T20:22:08Z","summary":null,"body":["<article data-history-node-id=\"7262\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-110\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-110<br \/><strong>Date: <\/strong>February\u00a010, 2026<\/p>\n\n<p>On February\u00a010, 2026, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking Private 5G Core\u00a0\u2013 versions 1.24.3.0, 1.24.3.1, 1.24.3.2 and 1.24.3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05002en_us&amp;docLocale=en_US\">HPESBNW05002 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-110","alert_type":396,"serial_number":"AV26-110","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7263,"title":"Microsoft security advisory \u2013 February 2026 monthly rollup (AV26-111) - Update 1","uuid":"e964c6c8-1ad8-45dc-a46e-1d5207e8b518","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T19:19:22Z","date_created":"2026-02-10T20:22:08Z","summary":null,"body":["<article data-history-node-id=\"7263\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-february-2026-monthly-rollup-av26-111\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-111<br \/><strong>Date: <\/strong>February\u00a010, 2026<br \/><strong>Updated: <\/strong>February\u00a013, 2026<\/p>\n\n<p>On February\u00a010, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>.NET 10.0<\/li>\n\t<li>.NET 8.0<\/li>\n\t<li>.NET 9.0<\/li>\n\t<li>Azure AI Language Authoring<\/li>\n\t<li>Azure ARC<\/li>\n\t<li>Azure DevOps Server 2022<\/li>\n\t<li>Azure Front Door<\/li>\n\t<li>Azure Functions<\/li>\n\t<li>Azure HDInsight<\/li>\n\t<li>Azure IoT Explorer<\/li>\n\t<li>Azure Local<\/li>\n\t<li>GitHub Copilot Plugin for JetBrains IDEs<\/li>\n\t<li>Microsoft 365<\/li>\n\t<li>Microsoft ACI Confidential Containers<\/li>\n\t<li>Microsoft Defender for Endpoint for Linux<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Server 2016<\/li>\n\t<li>Microsoft Exchange Server 2019<\/li>\n\t<li>Microsoft Exchange Server Subscription Edition RTM<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office LTSC<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Outlook 2016<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SQL Server 2025<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Power BI Report Server<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows App for Mac<\/li>\n\t<li>Windows Notepad<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2026-21525, CVE-2026-21514, CVE-2026-21510, CVE-2026-21513, CVE-2026-21533 and CVE-2026-21519 are being exploited.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On February 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21525, CVE-2026-21514, CVE-2026-21510, CVE-2026-21513, CVE-2026-21533 and CVE-2026-21519 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Feb\">February 2026 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21510\">CISA KEV: CVE-2026-21510<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21513\">CISA KEV: CVE-2026-21513<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21514\">CISA KEV: CVE-2026-21514<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21519\">CISA KEV: CVE-2026-21519<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21525\">CISA KEV: CVE-2026-21525<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21533\">CISA KEV: CVE-2026-21533<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-february-2026-monthly-rollup-av26-111","alert_type":396,"serial_number":"AV26-111","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7261,"title":"Fortinet security advisory (AV26-109) \u2013 Update 1","uuid":"2b89ab86-b8cc-4c50-9a9c-4072011eda88","banner":null,"lang":"en","date_modified":"2026-07-27","date_modified_ts":"2026-07-27T18:14:46Z","date_created":"2026-02-10T20:22:08Z","summary":null,"body":["<article data-history-node-id=\"7261\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-109\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-109<br \/><strong>Date: <\/strong>February\u00a010, 2026<br \/><strong>Updated:<\/strong> July 27, 2026<\/p>\n\n<p>On February\u00a010, 2026, Fortinet published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FortiAuthenticator 6.6\u00a0\u2013 versions 6.6.0 to\u00a06.6.6<\/li>\n\t<li>FortiAuthenticator 6.5\u00a0\u2013 all versions<\/li>\n\t<li>FortiAuthenticator 6.4\u00a0\u2013 all versions<\/li>\n\t<li>FortiAuthenticator 6.3\u00a0\u2013 all versions<\/li>\n\t<li>FortiClientWindows 7.4\u00a0\u2013 versions 7.4.0 to\u00a07.4.4<\/li>\n\t<li>FortiClientWindows 7.2\u00a0\u2013 versions 7.2.0 to\u00a07.2.12<\/li>\n\t<li>FortiClientWindows 7.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiOS 7.6\u00a0\u2013 versions 7.6.0 to\u00a07.6.4<\/li>\n\t<li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to\u00a07.4.10<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiOS 7.0\u00a0\u2013 all versions<\/li>\n\t<li>FortiOS 6.4\u00a0\u2013 all versions<\/li>\n\t<li>FortiSandbox 5.0\u00a0\u2013 version\u00a05.0 to\u00a05.1<\/li>\n\t<li>FortiSandbox 4.4\u00a0\u2013 version\u00a04.4.0 to\u00a04.4.7<\/li>\n\t<li>FortiSandbox 4.2\u00a0\u2013 all versions<\/li>\n\t<li>FortiSandbox 4.0\u00a0\u2013 all versions<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On July 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-68686 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686\">CISA KEV: CVE-2025-68686<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-109","alert_type":396,"serial_number":"AV26-109","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7264,"title":"Intel security advisory (AV26-112)","uuid":"a50c53a1-9da3-4595-8df2-5bb7f898f894","banner":null,"lang":"en","date_modified":"2026-02-10","date_modified_ts":"2026-02-10T21:50:36Z","date_created":"2026-02-10T21:39:21Z","summary":null,"body":["<article data-history-node-id=\"7264\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av26-112\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-112<br \/><strong>Date: <\/strong>February 10, 2026<\/p>\n\n<p>On February 10, 2026, Intel published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Product Security Center Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av26-112","alert_type":396,"serial_number":"AV26-112","subject":"intel","moderation_state":"published","external_url":null},{"nid":7265,"title":"Ivanti security advisory (AV26-113) \u2013 Update 1","uuid":"e18865ef-9f1a-4f7f-8ca4-f52621dc5f17","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T18:31:18Z","date_created":"2026-02-10T21:44:57Z","summary":null,"body":["<article data-history-node-id=\"7265\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-113\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-113<br \/><strong>Date: <\/strong>February 10, 2026<br \/><strong>Updated: <\/strong>March 9, 2026<\/p>\n\n<p>On February 9, 2026, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager (EPM)\u00a0\u2013 version 2024 SU4 SR1 and prior<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p class=\"mrgn-bttm-md\">On March 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1603 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US\">Security Advisory EPM February 2026 for EPM 2024<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-1603\">CISA KEV: CVE-2026-1603<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-113","alert_type":396,"serial_number":"AV26-113","subject":"other","moderation_state":"published","external_url":null},{"nid":7266,"title":"GitLab security advisory (AV26-114)","uuid":"7fdce573-cd5a-495f-8126-bd57d7b93683","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T12:59:11Z","date_created":"2026-02-11T12:53:25Z","summary":null,"body":["<article data-history-node-id=\"7266\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-114\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-114<br \/><strong>Date:<\/strong> February\u00a011, 2026<\/p>\n\n<p>On February\u00a010, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.8.4, 18.7.4 and 18.6.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.8.4, 18.7.4 and 18.6.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/02\/10\/patch-release-gitlab-18-8-4-released\/\">GitLab Patch Release: 18.8.4, 18.7.4, 18.6.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-114","alert_type":396,"serial_number":"AV26-114","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7267,"title":"Adobe security advisory (AV26-115)","uuid":"ab42fcec-b5be-417a-8434-ee658cf872b7","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T13:16:49Z","date_created":"2026-02-11T13:12:41Z","summary":null,"body":["<article data-history-node-id=\"7267\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-115\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26\u2013115<br \/><strong>Date: <\/strong>February\u00a011, 2026<\/p>\n\n<p>On February\u00a010, 2026, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe After Effects\u00a0\u2013 version\u00a025.6 and prior<\/li>\n\t<li>Adobe Audition\u00a0\u2013 version\u00a025.3 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID21.1 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID20.5.1 and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version\u00a015.1.3 (LTS) and prior<\/li>\n\t<li>Adobe Bridge\u00a0\u2013 version\u00a016.0.1 and prior<\/li>\n\t<li>Adobe Substance 3D Modeler\u00a0\u2013 version\u00a01.22.5 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version\u00a03.1.6 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version\u00a015.1.0 and prior<\/li>\n\t<li>Adobe Lightroom Classic\u00a0\u2013 version\u00a015.1 and prior<\/li>\n\t<li>Adobe\u202fDNG Software Development Kit (SDK) \u2013 version\u00a01.7.1 build 2410 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe PSIRT\u00a0\u2013 Latest Product Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-115","alert_type":396,"serial_number":"AV26-115","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7268,"title":"Google Chrome security advisory (AV26-116)","uuid":"45ba93a9-363a-41b7-95f8-34e741684455","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T19:44:18Z","date_created":"2026-02-11T19:37:54Z","summary":null,"body":["<article data-history-node-id=\"7268\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-116\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-116<br \/><strong>Date: <\/strong>February 11, 2026<\/p>\n\n<p>On February 10, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 145.0.7632.45\/46 (Windows\/Mac) and 145.0.7632.45 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/02\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-116","alert_type":396,"serial_number":"AV26-116","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7269,"title":"Palo Alto Networks security advisory (AV26-118)","uuid":"a9104972-b449-48bc-b217-128f13bb6d37","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T20:17:01Z","date_created":"2026-02-11T19:58:41Z","summary":null,"body":["<article data-history-node-id=\"7269\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-118\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-118<br \/><strong>Date: <\/strong>February 11, 2026<\/p>\n\n<p>On February 11, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.4<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.8<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.10<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.11<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.17<\/li>\n\t<li>Prisma Access\u00a0\u2013 versions prior to 11.2.7-h10 on PAN-OS<\/li>\n\t<li>Prisma Access\u00a0\u2013 versions prior to 10.2.10-h28 on PAN-OS<\/li>\n\t<li>Prisma Browser\u00a0\u2013 versions prior to 144.27.7.133<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2026-0002\">PAN-SA-2026-0002 Chromium: Monthly Vulnerability Update (February 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0228\">CVE-2026-0228 PAN-OS: Improper Validation of Terminal Server Agent Certificate<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0229\">CVE-2026-0229 PAN-OS: Denial of Service in Advanced DNS Security Feature<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-118","alert_type":396,"serial_number":"AV26-118","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7270,"title":"HPE security advisory (AV26-117)","uuid":"31e069d3-fd99-4064-9e8b-194dc1baecd9","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T20:15:22Z","date_created":"2026-02-11T20:08:49Z","summary":null,"body":["<article data-history-node-id=\"7270\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-117\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-117<br \/><strong>Date: <\/strong>February 11, 2026<\/p>\n\n<p>On February 10, 2026, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant compute DL\/ML\/XD\u00a0\u2013 multiple models and versions<\/li>\n\t<li>HPE ProLiant DL\/ML\/XL\u00a0\u2013 multiple models and versions<\/li>\n\t<li>HPE Synergy 480 Gen12 Compute Module\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Synergy 480 Gen11 Compute Module\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Alletra Storage Server 4210\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Alletra 4110, 4120 and 4140\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Compute Edge Server e930t\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Intel E810 Series Ethernet Controllers prior to v30.3\u00a0\u2013 firmware versions prior to v4.90<\/li>\n\t<li>HPE Aruba Networking EdgeConnect SD-WAN Orchestrator\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE StoreEasy\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-117","alert_type":396,"serial_number":"AV26-117","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7271,"title":"[Control systems] Schneider Electric security advisory (AV26-119) ","uuid":"621dd85e-aac6-405b-9ecc-ce17db2de6f2","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T20:25:27Z","date_created":"2026-02-11T20:18:32Z","summary":null,"body":["<article data-history-node-id=\"7271\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-119\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-119<br \/><strong>Date: <\/strong>February 11, 2026<\/p>\n\n<p>On February 10, 2026, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Building Operation Workstation and WebStation\u00a0\u2013 7.0.x versions prior to 7.0.3.2000 (CP1)<\/li>\n\t<li>EcoStruxure Building Operation Workstation and WebStation\u00a0\u2013 6.x versions prior to 6.0.4.14001 (CP10)<\/li>\n\t<li>SCADAPack 47x\/47xi\u00a0\u2013 versions prior to R3.4.2 (Firmware version prior to 9.12.2)<\/li>\n\t<li>SCADAPack 57x\u00a0\u2013 all versions<\/li>\n\t<li>RemoteConnect\u00a0\u2013 versions prior to R3.4.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-041-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-041-02.pdf\">Multiple Vulnerabilities on EcoStruxure Building Operation Workstation and EcoStruxureTM Building Operation Webstation<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-041-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-041-01.pdf\">Improper Check for Unusual or Exceptional Conditions on Multiple Products<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-119","alert_type":398,"serial_number":"AV26-119","subject":"other","moderation_state":"published","external_url":null},{"nid":7272,"title":"Commvault security advisory (AV26-120)","uuid":"092fe64e-524b-499b-bc09-8b904bca3ee7","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T20:34:47Z","date_created":"2026-02-11T20:31:05Z","summary":null,"body":["<article data-history-node-id=\"7272\" about=\"\/en\/alerts-advisories\/commvault-security-advisory-av26-120\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-120<br \/><strong>Date: <\/strong>February 11, 2026<\/p>\n\n<p>On February 10, 2026, Commvault published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Commvault Windows\u00a0\u2013 versions 11.32.0 to 11.32.128<\/li>\n\t<li>Commvault Windows\u00a0\u2013 versions 11.36.0 to 11.36.89<\/li>\n\t<li>Commvault Windows\u00a0\u2013 versions 11.40.0 to 11.40.136<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2026_02_1.html\">CV_2026_02_1: MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/\">Commvault Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/commvault-security-advisory-av26-120","alert_type":396,"serial_number":"AV26-120","subject":"other","moderation_state":"published","external_url":null},{"nid":7273,"title":"Drupal security advisory (AV26-121)","uuid":"089b2ca2-3c76-4aed-8b31-bb5f70e4c5a4","banner":null,"lang":"en","date_modified":"2026-02-11","date_modified_ts":"2026-02-11T21:26:19Z","date_created":"2026-02-11T21:19:44Z","summary":null,"body":["<article data-history-node-id=\"7273\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-121\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-121<br \/><strong>Date: <\/strong>February 11, 2026<\/p>\n\n<p>On February 11, 2026, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>QuickEdit\u00a0\u2013 versions prior to 1.0.5 and versions 2.0.0 to versions prior to 2.0.1<\/li>\n\t<li>UI Icons\u00a0\u2013 versions prior to 1.0.1 and version 1.1.0 to versions prior to 1.1.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-009\">Quick Edit\u00a0- Moderately critical\u00a0- Cross-site Scripting\u00a0- SA-CONTRIB-2026-009<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-010\">UI Icons\u00a0- Moderately critical\u00a0- Cross-site Scripting\u00a0- SA-CONTRIB-2026-010<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-121","alert_type":396,"serial_number":"AV26-121","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7274,"title":"Apple security advisory (AV26-122) - Update 1","uuid":"0fda9a8e-c17f-465b-aa37-e514a49a3eef","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T19:26:20Z","date_created":"2026-02-11T21:35:13Z","summary":null,"body":["<article data-history-node-id=\"7274\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-122\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-122<br \/><strong>Date: <\/strong>February 11, 2026<br \/><strong>Updated: <\/strong>February 13, 2026<\/p>\n\n<p>On February 11, 2026, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 26.3<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 26.3<\/li>\n\t<li>iOS\u00a0\u2013 versions prior to 18.7.5<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 18.7.5<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26.3<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.7.4<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.8.4<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 26.3<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 26.3<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 26.3<\/li>\n<\/ul><p>Apple has indicated that CVE-2026-20700 may have been exploited.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On February 12, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20700 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-20700\">CISA KEV: CVE-2026-20700<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-122","alert_type":396,"serial_number":"AV26-122","subject":"apple","moderation_state":"published","external_url":null},{"nid":7275,"title":"React security advisory (AV26-123)","uuid":"af7b8f07-fefc-4564-9c27-1515540d8e9a","banner":null,"lang":"en","date_modified":"2026-02-12","date_modified_ts":"2026-02-12T16:25:34Z","date_created":"2026-02-12T16:22:54Z","summary":null,"body":["<article data-history-node-id=\"7275\" about=\"\/en\/alerts-advisories\/react-security-advisory-av26-123\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-123<br \/><strong>Date: <\/strong>February 12, 2026<\/p>\n\n<p>On February 11, 2026, Hashicorp published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>next-mdx-remote \u2013 versions 4.3.0 to 5.0.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-01-arbitrary-code-execution-in-react-server-side-rendering-of-untrusted-mdx-content\/77155\">HCSEC-2026-01\u00a0- Arbitrary code execution in React server-side rendering of untrusted MDX content<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/react-security-advisory-av26-123","alert_type":396,"serial_number":"AV26-123","subject":"other","moderation_state":"published","external_url":null},{"nid":7276,"title":"AMD security advisory (AV26-124)","uuid":"001103cb-69b2-4fea-95b0-76364227ce32","banner":null,"lang":"en","date_modified":"2026-02-12","date_modified_ts":"2026-02-12T16:36:40Z","date_created":"2026-02-12T16:32:50Z","summary":null,"body":["<article data-history-node-id=\"7276\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-124\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-124<br \/><strong>Date: <\/strong>February 12, 2026<\/p>\n\n<p>On February 10, 2026, AMD published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AMD Athlon and AMD Ryzen Processors \u2013 multiple models and versions<\/li>\n\t<li>AMD Graphic Drivers \u2013 multiple models and versions<\/li>\n\t<li>AMD \u00b5Prof performance analysis tool-suite \u2013 versions prior to 5.2.431<\/li>\n\t<li>AMD Vivado Design Suite installation \u2013 versions prior to 2025.2<\/li>\n\t<li>AMD Documentation Navigator installation \u2013 tool being retired<\/li>\n\t<li>AMD EPYC and AMD EPYC Embedded Series Processors \u2013 multiple models and versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-124","alert_type":396,"serial_number":"AV26-124","subject":"other","moderation_state":"published","external_url":null},{"nid":7278,"title":"PostgreSQL security advisory (AV26-125)","uuid":"1bb2503b-e70c-4bac-a482-6111a10d25ac","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T14:01:58Z","date_created":"2026-02-13T13:35:28Z","summary":null,"body":["<article data-history-node-id=\"7278\" about=\"\/en\/alerts-advisories\/postgresql-security-advisory-av26-125\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-125<br \/><strong>Date: <\/strong>February 13, 2026<\/p>\n\n<p>On February 12, 2026, PostgreSQL published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PostgreSQL \u2013 14.x versions prior to 14.21<\/li>\n\t<li>PostgreSQL \u2013 15.x versions prior to 15.16<\/li>\n\t<li>PostgreSQL \u2013 16.x versions prior to 16.12<\/li>\n\t<li>PostgreSQL \u2013 17.x versions prior to 17.8<\/li>\n\t<li>PostgreSQL \u2013 18.x versions prior to 18.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.postgresql.org\/about\/news\/postgresql-182-178-1612-1516-and-1421-released-3235\/\">PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 Released!<\/a><\/li>\n\t<li><a href=\"https:\/\/www.postgresql.org\/support\/security\/\">PostgreSQL Security Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/postgresql-security-advisory-av26-125","alert_type":396,"serial_number":"AV26-125","subject":"other","moderation_state":"published","external_url":null},{"nid":7279,"title":"Google Chrome security advisory (AV26-126)","uuid":"adecf02c-9e0d-4c54-b615-0c498cc27fc1","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T15:50:53Z","date_created":"2026-02-13T15:45:39Z","summary":null,"body":["<article data-history-node-id=\"7279\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-126\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-126<br \/><strong>Date: <\/strong>February 13, 2026<\/p>\n\n<p>On February 12, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 145.0.7632.68 (Windows\/Mac) and 144.0.7559.67 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/02\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-126","alert_type":396,"serial_number":"AV26-126","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7280,"title":"HPE security advisory (AV26-127)","uuid":"1ad65033-b794-4a19-a55e-3d51ea9eef54","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T16:02:27Z","date_created":"2026-02-13T15:53:09Z","summary":null,"body":["<article data-history-node-id=\"7280\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-127\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-127<br \/><strong>Date: <\/strong>February 13, 2026<\/p>\n\n<p>On February 12, 2026, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE SimpliVity 380 Gen11\u00a0\u2013 versions prior to SimpliVity Support Pack Gen11 (SVTSPGen11) 2026_0116<\/li>\n\t<li>HPE SimpliVity 380 Gen10 Plus\u00a0\u2013 versions prior to SimpliVity Support Pack Gen10 (SVTSPGen10) 2026_0116<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04937en_us&amp;docLocale=en_US\">HPESBHF04937 rev.1\u00a0- Certain HPE SimpliVity Servers Using Certain Intel Processors, INTEL-SA-01280, 2025.3 IPU, Intel Chipset Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04938en_us&amp;docLocale=en_US\">PESBHF04938 rev.1\u00a0- Certain HPE SimpliVity Servers Using Certain Intel Processors, INTEL-SA-01313, 2025.3 IPU, Intel Xeon Processor Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04939en_us&amp;docLocale=en_US\">HPESBHF04939 rev.1\u00a0- Certain HPE SimpliVity Servers Using Certain Intel Processors, INTEL-SA-01312, Intel TDX Module Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-127","alert_type":396,"serial_number":"AV26-127","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7282,"title":"Juniper Networks security advisory (AV26-128)","uuid":"bd3b2130-ec09-4561-b030-aece78b9f1e7","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T19:35:38Z","date_created":"2026-02-13T19:32:53Z","summary":null,"body":["<article data-history-node-id=\"7282\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-128\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-128<br \/><strong>Date: <\/strong>February 13, 2026<\/p>\n\n<p>On February 12, 2026, Juniper Networks published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:<\/p>\n\n<ul><li>Juniper Secure Analytics (JSA) 7.5.0 \u2013 versions prior to 7.5.0 UP14 IF01<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP14-IF01\">On Demand: JSA Series: Multiple vulnerabilities resolved in Juniper Secure Analytics in 7.5.0 UP14 IF01<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending\">Juniper Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-128","alert_type":396,"serial_number":"AV26-128","subject":"juniper","moderation_state":"published","external_url":null},{"nid":7283,"title":"Tenable security advisory (AV26-129)","uuid":"a41a7484-b59b-4a05-ac1d-ceaa729e2dae","banner":null,"lang":"en","date_modified":"2026-02-13","date_modified_ts":"2026-02-13T20:15:48Z","date_created":"2026-02-13T20:10:40Z","summary":null,"body":["<article data-history-node-id=\"7283\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-129\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-129<br \/><strong>Date: <\/strong>February 13, 2026<\/p>\n\n<p>On February 12, 2026, Tenable published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Nessus Agent\u00a0\u2013 versions 11.1.0 to 11.1.1<\/li>\n\t<li>Nessus Agent\u00a0\u2013 versions 11.0.3 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-05\">[R1] Nessus Agent Versions 11.0.4 and 11.1.2 Fix One Vulnerability (CVE-2026-2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-129","alert_type":396,"serial_number":"AV26-129","subject":"other","moderation_state":"published","external_url":null},{"nid":7284,"title":"Google Chrome security advisory (AV26-130) - Update 1","uuid":"4de14031-fe3d-4eda-b521-6774ccac12c0","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T21:11:52Z","date_created":"2026-02-16T14:53:07Z","summary":null,"body":["<article data-history-node-id=\"7284\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-130\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-130<br \/><strong>Date: <\/strong>February 16, 2026<br \/><strong>Updated: <\/strong>February 17, 2026<\/p>\n\n<p>On February 13, 2026, Google published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 145.0.7632.75\/76 (Windows\/Mac) and 144.0.7559.75 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2026-2441 exists in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On February 17, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-2441 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/02\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory<\/a><\/li>\n\t<li><a href=\" https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-2441  \">CISA KEV: CVE-2026-2441<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-130","alert_type":396,"serial_number":"AV26-130","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7285,"title":"AL26-003 - Vulnerability affecting BeyondTrust - CVE-2026-1731","uuid":"74748091-c0e3-408f-992f-5fc085671d8d","banner":null,"lang":"en","date_modified":"2026-02-16","date_modified_ts":"2026-02-16T19:05:58Z","date_created":"2026-02-16T19:05:30Z","summary":null,"body":["<article data-history-node-id=\"7285\" about=\"\/en\/alerts-advisories\/al26-003-vulnerability-affecting-beyondtrust-cve-2026-1731\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-003<br \/><strong>Date:<\/strong> February\u00a016, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a high-severity vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. BeyondTrust Remote Support is an enterprise-level, security-focused remote assistance solution that enables <abbr title=\"information technology\">IT<\/abbr> teams to access and control systems and devices remotely to help provide technical support. In response to the vendor advisory released on February\u00a06, 2026, the Cyber Centre issued AV26-097<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> on February\u00a09, 2026.<\/p>\n\n<p>Tracked as CVE-2026-1731<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is a critical pre-authentication remote code execution vulnerability and allows an unauthenticated remote attacker to execute Operating System commands (CWE-78)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> in the context of the site user and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.<\/p>\n\n<p>The Cyber Centre has observed open-source reporting indicating that the vulnerability is being exploited in the wild<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected BeyondTrust instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed version<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Remote Support<\/td>\n\t\t\t<td>25.3.1 and prior<\/td>\n\t\t\t<td>Patch BT26-02-RS (v21.3\u00a0- 25.3.1)<\/td>\n\t\t<\/tr><tr><td>Remote Support<\/td>\n\t\t\t<td>25.3.1 and prior<\/td>\n\t\t\t<td>25.3.2 and greater<\/td>\n\t\t<\/tr><tr><td>Privileged Remote Access<\/td>\n\t\t\t<td>24.3.4 and prior<\/td>\n\t\t\t<td>Patch BT26-02-PRA (v22.1\u00a0- 24.X)<\/td>\n\t\t<\/tr><tr><td>Privileged Remote Access<\/td>\n\t\t\t<td>24.3.4 and prior<\/td>\n\t\t\t<td>25.1 and greater<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>BeyondTrust has confirmed that a patch has been applied to all Remote Support SaaS and Privileged Remote Access SaaS customers as of <strong>February\u00a02, 2026<\/strong> that remediates this vulnerability.<\/p>\n\n<p>For the self-hosted instances of Remote Support and Privileged Remote Access, organizations should apply the patch manually if their instance is not subscribed to automatic updates.<\/p>\n\n<p>The Cyber Centre also recommends that organizations review their logs to detect anomalies and unauthorized access.<\/p>\n\n<p>If immediate patching is not possible, reduce exposure by:<\/p>\n\n<ul><li>Restrict management interfaces via firewall or <abbr title=\"Internet Protocol\">IP<\/abbr> allowlists<\/li>\n\t<li>Remove externally exposed instances from Internet until patch is applied<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt26-02\">BeyondTrust BT26-02 Security Advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-097\">BeyondTrust security advisory (AV26-097)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-1731\">NVD\u00a0- CVE-2026-1731<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/78.html\">CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.greynoise.io\/blog\/reconnaissance-beyondtrust-rce-cve-2026-1731\">Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-003-vulnerability-affecting-beyondtrust-cve-2026-1731","alert_type":397,"serial_number":"AL26-003","subject":"other","moderation_state":"published","external_url":null},{"nid":7286,"title":"IBM security advisory (AV26-131)","uuid":"1c5a6878-a021-487d-bee7-2dc4be3813e0","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T16:56:53Z","date_created":"2026-02-17T15:58:40Z","summary":null,"body":["<article data-history-node-id=\"7286\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-131\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-131<\/p>\n\n<p class=\"mrgn-bttm-md\"><strong>Date: <\/strong>February 17, 2026<\/p>\n\n<p>Between February 9 and 15, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Business Automation Workflow\u00a0\u2013 versions 24.0.1.0 and 25.0.0.0<\/li>\n\t<li>IBM Business Automation Workflow Enterprise Service Bus\u00a0\u2013 versions V24.0.0 to V24.0.1<\/li>\n\t<li>IBM Business Automation Workflow traditional\u00a0\u2013 versions V25.0.0 to V25.0.1<\/li>\n\t<li>IBM Concert Software\u00a0\u2013 versions 1.0.0 to 2.1.0<\/li>\n\t<li>IBM Financial Transaction Manager for ACH and Check Services\u00a0\u2013 versions 3.0.0.0 to 3.0.5.4 iFix 27<\/li>\n\t<li>IBM Financial Transaction Manager for RehHat OpenShift\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Operational Decision Manager\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Sterling External Authentication Server\u00a0\u2013 versions 6.1.0.0 to 6.1.0.3<\/li>\n\t<li>IBM Sterling Secure Proxy\u00a0\u2013 versions 6.1.0.0 to 6.1.0.2, versions 6.2.0.0 to 6.2.0.2<\/li>\n\t<li>IBM webMethods Adapter 10.3 for Cmis\u00a0- multiple versions<\/li>\n\t<li>IBM webMethods Adapter 10.5 for Alfresco\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM webMethods Adapter 10.5 for Documentum\u00a0- multiple versions<\/li>\n\t<li>IBM webMethods Adapter 8.2 for Salesforce\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM webMethods Adapter 9.8 for HDFS\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM webMethods Integration (on prem)\u00a0\u2013 versions 11.1 to IS_11.1_Core_Fix8<\/li>\n\t<li>z\/Transaction Processing Facility\u00a0\u2013 version 1.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-131","alert_type":396,"serial_number":"AV26-131","subject":"other","moderation_state":"published","external_url":null},{"nid":7287,"title":"Dell security advisory (AV26-132)","uuid":"24386548-7720-445f-a983-1a32eb28ad4d","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T19:07:37Z","date_created":"2026-02-17T18:53:06Z","summary":null,"body":["<article data-history-node-id=\"7287\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-132\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-132<br \/><strong>Date: <\/strong>February 17, 2026<\/p>\n\n<p>Between February 9 and 15, 2026, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen4T\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar Data Store Gen5A\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar Network Data Management Protocol (NDMP) Accelerator\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar VMware Image Backup Proxy\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Avamar Virtual Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell EMC XC Core XC7525\u00a0\u2013 versions prior to 2.21.1<\/li>\n\t<li>Dell Networker Virtual Edition (NVE)\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell PowerEdge\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell PowerProtect DP Series Appliance (IDPA)\u00a0\u2013 versions prior to 2.7.9<\/li>\n\t<li>Dell Private Cloud \u00a0Red Hat\u00a0\u2013 versions prior to 01.02.00.00<\/li>\n\t<li>Dell Private Cloud\u00a0-VMware\u00a0\u2013 versions prior to 01.03.00.00<\/li>\n\t<li>Dell Update Package (DUP) Framework\u00a0\u2013 versions 23.12.00 to 24.12.00<\/li>\n\t<li>Dell XC Core\u00a0\u2013 multiple versions and models<\/li>\n\t<li>NetWorker\u00a0\u2013 versions 19.9 to 19.13.0.2<\/li>\n\t<li>iDRAC Service Module for Linux\u00a0\u2013 versions prior to 5.4.1.1<\/li>\n\t<li>iDRAC Service Module for Windows\u00a0\u2013 versions prior to 5.4.1.1<\/li>\n\t<li>iDRAC Service Module for Windows\u00a0\u2013 versions prior to 6.0.3.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-132","alert_type":396,"serial_number":"AV26-132","subject":"dell","moderation_state":"published","external_url":null},{"nid":7289,"title":"[Control systems] CISA ICS security advisories (AV26-134)","uuid":"10c14ffc-e1f5-4fbc-96b7-d6165c4710fd","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T19:54:30Z","date_created":"2026-02-17T19:42:09Z","summary":null,"body":["<article data-history-node-id=\"7289\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-134\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-134<br \/><strong>Date: <\/strong>February\u00a017, 2026<\/p>\n\n<p>Between February\u00a09 and 15, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA PI Data Archive PI Server\u00a0\u2013 multiple versions<\/li>\n\t<li>AVEVA PI to CONNECT Agent\u00a0\u2013 versions prior to v2.4.2520<\/li>\n\t<li>Airleader GmbH Airleader Master\u00a0\u2013 version 6.381 and prior<\/li>\n\t<li>Hitachi Energy SuprOS\u00a0\u2013 versions 9.2.1 and prior and 9.2.2.0<\/li>\n\t<li>Siemens COMOS V10.4\u00a0\u2013 versions prior to 10.4.5<\/li>\n\t<li>Siemens COMOS V10.4.5\u00a0\u2013 versions prior to 10.4.5.0.2<\/li>\n\t<li>Siemens COMOS V10.5\u00a0\u2013 versions prior to 10.5.2<\/li>\n\t<li>Siemens COMOS V10.6\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Desigo CC family V6\/V7 vers\u00a0\u2013 all versions<\/li>\n\t<li>Siemens Desigo CC family V8\u00a0\u2013 versions prior to V8.0 QU2<\/li>\n\t<li>Siemens NX\u00a0\u2013 versions prior to V2512<\/li>\n\t<li>Siemens Polarion V2404\u00a0\u2013 versions prior to 2404.5<\/li>\n\t<li>Siemens Polarion V2410\u00a0\u2013 versions prior to 2410.2<\/li>\n\t<li>Siemens SENTRON Powermanager V6\/V7 vers\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SENTRON Powermanager V8\u00a0\u2013 versions prior to V8.0 QU2<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 all versions (CVE-2026-25655)<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 versions prior to V4.0 SP2 (CVE-2026-25656)<\/li>\n\t<li>Siemens SINEC OS\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Siemens Siveillance Video Management Servers\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens Solid Edge\u00a0\u2013 versions prior to V226.00 Update 03<\/li>\n\t<li>Yokogawa FAST\/TOOLS\u00a0\u2013 versions R9.01 to R10.04<\/li>\n\t<li>ZLAN Information Technology Co. ZLAN5143D\u00a0\u2013 version v1.600<\/li>\n\t<li>ZOLL ePCR IOS Mobile Application\u00a0\u2013 version 2.6.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-134","alert_type":398,"serial_number":"AV26-134","subject":"ics","moderation_state":"published","external_url":null},{"nid":7288,"title":"Ubuntu security advisory (AV26-133)","uuid":"455d4c7a-ed66-4940-855d-afffc3f51125","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T19:44:58Z","date_created":"2026-02-17T19:42:09Z","summary":null,"body":["<article data-history-node-id=\"7288\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-133\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-133<br \/><strong>Date:<\/strong> February\u00a017, 2026<\/p>\n\n<p>Between February\u00a09 and 15, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-133","alert_type":396,"serial_number":"AV26-133","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7290,"title":"Red Hat security advisory (AV26-135)","uuid":"d961fbb6-533e-4741-9235-b046185fa940","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T20:01:56Z","date_created":"2026-02-17T19:44:59Z","summary":null,"body":["<article data-history-node-id=\"7290\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-135\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-135<br \/><strong>Date: <\/strong>February 17, 2026<\/p>\n\n<p>Between February 9 and 15, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-135","alert_type":396,"serial_number":"AV26-135","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7292,"title":"Mozilla security advisory (AV26-136)","uuid":"801b5bba-6476-4b83-8e37-01fa22d2ed10","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T20:27:14Z","date_created":"2026-02-17T20:22:22Z","summary":null,"body":["<article data-history-node-id=\"7292\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-136\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-136<br \/><strong>Date: <\/strong>February 17, 2026<\/p>\n\n<p>On February 16, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 147.0.2 and 140.7.2<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 147.0.4<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.32.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 140.7.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-11\/\">Mozilla Foundation Security Advisory 2026-11<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-10\/\">Mozilla Foundation Security Advisory 2026-10<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-136","alert_type":396,"serial_number":"AV26-136","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7293,"title":"Tenable security advisory (AV26-137)","uuid":"d578b3c3-edc9-4c1f-b53e-8a6551a5b225","banner":null,"lang":"en","date_modified":"2026-02-17","date_modified_ts":"2026-02-17T20:39:49Z","date_created":"2026-02-17T20:35:41Z","summary":null,"body":["<article data-history-node-id=\"7293\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-137\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-137<br \/><strong>Date: <\/strong>February 17, 2026<\/p>\n\n<p>On February 17, 2026, Tenable published a security advisory to address vulnerabilities in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>Tenable Security Center\u00a0\u2013 version 6.7.2 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-06\">[R2] Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2: SC-202602.1 + SC-202602.2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-137","alert_type":396,"serial_number":"AV26-137","subject":"other","moderation_state":"published","external_url":null},{"nid":7294,"title":"Dell security advisory (AV26-138) \u2013 Update 1","uuid":"f70e9169-e958-4e33-8444-91dfe90de522","banner":null,"lang":"en","date_modified":"2026-02-18","date_modified_ts":"2026-02-18T19:09:36Z","date_created":"2026-02-18T13:44:48Z","summary":null,"body":["<article data-history-node-id=\"7294\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-138\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-138<br \/><strong>Date: <\/strong>February 18, 2026<br \/><strong>Updated: <\/strong>February 18, 2026<\/p>\n\n<p>On February 17, 2026, Dell published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>RecoverPoint for Virtual Machines\u00a0\u2013 versions prior to 5.3 SP4 P1<\/li>\n\t<li>RecoverPoint for Virtual Machines\u00a0\u2013 versions 6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3 and 6.0 SP3 P1<\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-22769 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>\n  On February 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22769 to their Known Exploited Vulnerabilities (KEV) Database.\n<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000426773\/dsa-2026-079\">DSA-2026-079: Security Update for RecoverPoint for Virtual Machines Hardcoded Credential Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n  \t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22769\">CISA KEV: CVE-2026-22769<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-138","alert_type":396,"serial_number":"AV26-138","subject":"dell","moderation_state":"published","external_url":null},{"nid":7296,"title":"HPE security advisory (AV26-139)","uuid":"c4e839dc-d45a-4eb4-acea-f16ea46aae9f","banner":null,"lang":"en","date_modified":"2026-02-18","date_modified_ts":"2026-02-18T14:49:07Z","date_created":"2026-02-18T14:40:29Z","summary":null,"body":["<article data-history-node-id=\"7296\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-139\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-139<br \/><strong>Date: <\/strong>February 18, 2026<\/p>\n\n<p>On February 17, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking ClearPass Policy Manager 6.12.x\u00a0\u2013 version 6.12.7 and prior<\/li>\n\t<li>HPE Aruba Networking ClearPass Policy Manager 6.11.x\u00a0\u2013 version 6.11.13 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05012en_us&amp;docLocale=en_US#hpesbnw05012-rev-1-local-privilege-escalation-vuln-0\">HPESBNW05012 rev.1\u00a0- Local Privilege Escalation Vulnerability in HPE Aruba Networking ClearPass Policy Manager (CPPM) OnGuard Software for Linux<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-139","alert_type":396,"serial_number":"AV26-139","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7297,"title":"[Control systems] ABB security advisory (AV26-140)","uuid":"0a382fb8-aace-4dcb-83ff-fb45aa8574bb","banner":null,"lang":"en","date_modified":"2026-02-18","date_modified_ts":"2026-02-18T15:13:49Z","date_created":"2026-02-18T14:47:00Z","summary":null,"body":["<article data-history-node-id=\"7297\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-140\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-140<\/p>\n\n<p class=\"mrgn-bttm-md\"><strong>Date: <\/strong>February 18, 2026<\/p>\n\n<p>On February 18, 2026, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>B&amp;R Automation Studio\u00a0\u2013 versions prior to 6.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.br-automation.com\/fileadmin\/SA25P007-097a386d.pdf\">B&amp;R Automation Studio Update of SQLite version (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-140","alert_type":398,"serial_number":"AV26-140","subject":"abb","moderation_state":"published","external_url":null},{"nid":7298,"title":"Atlassian security advisory (AV26-141)","uuid":"e147f170-f6b0-4981-aeb7-339252d25c98","banner":null,"lang":"en","date_modified":"2026-02-18","date_modified_ts":"2026-02-18T15:22:42Z","date_created":"2026-02-18T15:08:17Z","summary":null,"body":["<article data-history-node-id=\"7298\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-141\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-141<br \/><strong>Date: <\/strong>February 18, 2026<\/p>\n\n<p>On February 17, 2026, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/spaces\/SECURITY\/pages\/1722256046\/Security+Bulletin+-+February+17+2026\">Security Bulletin\u00a0- February 17 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-141","alert_type":396,"serial_number":"AV26-141","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":7299,"title":"Jenkins security advisory (AV26-142)","uuid":"a6b752d3-cc86-407f-92bd-d8aade735249","banner":null,"lang":"en","date_modified":"2026-02-18","date_modified_ts":"2026-02-18T15:32:25Z","date_created":"2026-02-18T15:25:00Z","summary":null,"body":["<article data-history-node-id=\"7299\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-142\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-142<br \/><strong>Date: <\/strong>February 18, 2026<\/p>\n\n<p>On February 18, 2026, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins weekly\u00a0\u2013 version 2.550 and prior<\/li>\n\t<li>Jenkins LTS\u00a0\u2013 versions 2.541.1 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-02-18\/#jenkins-security-advisory-2026-02-18\">Jenkins Security Advisory 2026-02-18<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-142","alert_type":396,"serial_number":"AV26-142","subject":"other","moderation_state":"published","external_url":null},{"nid":7300,"title":"Microsoft Edge security advisory (AV26-143)","uuid":"f98300cc-fa05-463e-a380-7e3da436ca81","banner":null,"lang":"en","date_modified":"2026-02-18","date_modified_ts":"2026-02-18T16:37:17Z","date_created":"2026-02-18T16:31:14Z","summary":null,"body":["<article data-history-node-id=\"7300\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-143\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-143<br \/><strong>Date: <\/strong>February 18, 2026<\/p>\n\n<p>On February 14, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 145.0.3800.58<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">Microsoft has indicated that CVE-2026-2441 has an available exploit.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-14-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-143","alert_type":396,"serial_number":"AV26-143","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7301,"title":"F5 security advisory (AV26-144)","uuid":"7e1e6aa9-9adf-44dd-93c7-69f3083d7185","banner":null,"lang":"en","date_modified":"2026-02-18","date_modified_ts":"2026-02-18T19:18:49Z","date_created":"2026-02-18T19:09:44Z","summary":null,"body":["<article data-history-node-id=\"7301\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-144\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-144<br \/><strong>Date: <\/strong>February 18, 2026<\/p>\n\n<p>On February 18, 2026, F5 published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>BIG-IP AFM and DDoS Hybrid Defender 17.x\u00a0\u2013 version 17.5.1.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000160003\">K000160003: BIG-IP TMM vulnerability CVE-2026-2507<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-144","alert_type":396,"serial_number":"AV26-144","subject":"f5","moderation_state":"published","external_url":null},{"nid":7302,"title":"Google Chrome security advisory (AV26-145)","uuid":"7f8c3b2e-d594-4c6e-9fea-397de5a95b00","banner":null,"lang":"en","date_modified":"2026-02-19","date_modified_ts":"2026-02-19T14:49:46Z","date_created":"2026-02-19T14:45:15Z","summary":null,"body":["<article data-history-node-id=\"7302\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-145\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-145<br \/><strong>Date: <\/strong>February 19, 2026<\/p>\n\n<p>On February 18, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 145.0.7632.109\/110 (Windows\/Mac) and 144.0.7559.109 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/02\/stable-channel-update-for-desktop_18.html \">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-145","alert_type":396,"serial_number":"AV26-145","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7303,"title":"GitHub security advisory (AV26-146)","uuid":"192ff0e6-6e74-4473-a35a-b9a1c68d7d6d","banner":null,"lang":"en","date_modified":"2026-02-19","date_modified_ts":"2026-02-19T15:45:39Z","date_created":"2026-02-19T15:23:11Z","summary":null,"body":["<article data-history-node-id=\"7303\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-146\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-146<br \/><strong>Date: <\/strong>February 19, 2026<\/p>\n\n<p>On February 10, 2026, GitHub published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.2<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.5<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.11<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.14<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.15.x prior to 3.15.18<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.23<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes \">Enterprise Server 3.19.2Enterprise Server 3.19.2<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes \">Enterprise Server 3.18.5<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes \">Enterprise Server 3.17.11<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes \">Enterprise Server 3.16.14<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes \">Enterprise Server 3.15.18<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes  \u2003\">Enterprise Server 3.14.23<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-146","alert_type":396,"serial_number":"AV26-146","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7304,"title":"Splunk security advisory (AV26-147)","uuid":"0840ac5d-214d-4c64-9e9d-e9994b784d29","banner":null,"lang":"en","date_modified":"2026-02-19","date_modified_ts":"2026-02-19T16:06:34Z","date_created":"2026-02-19T15:58:24Z","summary":null,"body":["<article data-history-node-id=\"7304\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-147\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-147<br \/><strong>Date: <\/strong>February 19, 2026<\/p>\n\n<p>On February 18, 2026, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Splunk Enterprise<\/span>\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Splunk Cloud Platform<\/span>\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Splunk Universal Forwarder<\/span>\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Splunk<\/span> DB <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Connect<\/span>\u00a0\u2013 versions prior to 4.2.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-147","alert_type":396,"serial_number":"AV26-147","subject":"other","moderation_state":"published","external_url":null},{"nid":7305,"title":"IceWarp security advisory (AV26-148)","uuid":"0c5ca859-796d-4642-aee1-07153c60560d","banner":null,"lang":"en","date_modified":"2026-02-19","date_modified_ts":"2026-02-19T16:20:32Z","date_created":"2026-02-19T16:11:24Z","summary":null,"body":["<article data-history-node-id=\"7305\" about=\"\/en\/alerts-advisories\/icewarp-security-advisory-av26-148\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-148<br \/><strong>Date: <\/strong>February 19, 2026<\/p>\n\n<p>On February 19, 2026, IceWarp published security advisories to address vulnerabilities in multiple products. Included was a critical vulnerability affecting the following products:<\/p>\n\n<ul><li>IceWarp Epos Update 2\u00a0\u2013 versions prior to 14.2.0.12<\/li>\n\t<li>IceWarp Epos Update 1\u00a0\u2013 versions prior to 14.1.0.20<\/li>\n\t<li>IceWarp Epos (1st generation)\u00a0\u2013 versions prior to 14.0.0.18<\/li>\n\t<li>Deep Castle and older versions\u00a0\u2013 versions prior to 13.0.3.13<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.icewarp.com\/hc\/en-us\/articles\/39702252317713-IceWarp-Security-Update\">IceWarp Security Update<\/a><\/li>\n\t<li><a href=\"https:\/\/support.icewarp.com\/hc\/en-us\/articles\/43185223566609-IceWarp-Security-Update-for-EPOS\">IceWarp Security Update for EPOS<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/icewarp-security-advisory-av26-148","alert_type":396,"serial_number":"AV26-148","subject":"other","moderation_state":"published","external_url":null},{"nid":7306,"title":"Tenable security advisory (AV26-149)","uuid":"3273340e-9443-4080-a5c4-1feb4e76b49e","banner":null,"lang":"en","date_modified":"2026-02-19","date_modified_ts":"2026-02-19T20:02:31Z","date_created":"2026-02-19T19:49:02Z","summary":null,"body":["<article data-history-node-id=\"7306\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-149\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-149<br \/><strong>Date: <\/strong>February 19, 2026<\/p>\n\n<p>On February 18, 2026, Tenable published a security advisory to address vulnerabilities in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>Tenable Security Center\u00a0\u2013 version 6.7.2 w\/ Patch SC-202602.1 and Patch SC-202602.2 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-07\">[R1] Security Center Version 6.8.0 Fixes Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-149","alert_type":396,"serial_number":"AV26-149","subject":"other","moderation_state":"published","external_url":null},{"nid":7307,"title":"HPE security advisory (AV26-150)","uuid":"ce7860f4-ee01-46eb-bbda-4cd44840def0","banner":null,"lang":"en","date_modified":"2026-02-19","date_modified_ts":"2026-02-19T20:29:09Z","date_created":"2026-02-19T20:06:42Z","summary":null,"body":["<article data-history-node-id=\"7307\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-150\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-150<br \/><strong>Date: <\/strong>February 19, 2026<\/p>\n\n<p>On February 19, 2026, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Telco Service Activator\u00a0\u2013 versions prior to 10.5.0<\/li>\n\t<li>HPE SimpliVity 380 servers\u00a0\u2013 versions prior to SimpliVity Support Pack (SVTSP) Gen10 and Gen11<\/li>\n\t<li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.5.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05011en_us&amp;docLocale=en_US#hpesbnw05011-rev-1-telco-service-activator-imprope-0\">HPESBNW05011 rev.1\u00a0- Telco Service Activator, Improper Input Validation<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04967en_us&amp;docLocale=en_US#hpesbhf04967-rev-1-certain-hpe-simplivity-servers-0\">HPESBHF04967 rev.1\u00a0- Certain HPE SimpliVity Servers Using Certain Intel Processor BIOS, INTEL-SA-01234, 2025.3 IPU, UEFI Reference Firmware Advisory., Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw04983en_us&amp;docLocale=en_US#hpesbnw04983-rev-1-hpe-telco-service-orchestrator-0\">HPESBNW04983 rev.1\u00a0- HPE Telco Service Orchestrator software, Prototype Pollution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US \">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-150","alert_type":396,"serial_number":"AV26-150","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7311,"title":"[Control systems] CISA ICS security advisories (AV26\u2013151)","uuid":"9943010c-1d50-4442-b4d6-8726c5eddcce","banner":null,"lang":"en","date_modified":"2026-02-23","date_modified_ts":"2026-02-23T15:57:15Z","date_created":"2026-02-23T15:26:37Z","summary":null,"body":["<article data-history-node-id=\"7311\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-151\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-151<br \/><strong>Date: <\/strong>February 23, 2026<\/p>\n\n<p>Between February 16 and 22, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Delta Electronics<\/span> ASDA-<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Soft<\/span>\u00a0\u2013 version 7.2.0.0 and prior<\/li>\n\t<li>En<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ocean SmartServer<\/span> IoT\u00a0\u2013 version 4.60.009 and prior<\/li>\n\t<li>GE Vernova Enervista UR Setup\u00a0\u2013 versions prior to 8.7<\/li>\n\t<li>Honeywell CCTV Products\u00a0\u2013 version I-HIB2PI-UL 2MP IP 6.1.22.1216<\/li>\n\t<li>Honeywell CCTV Products\u00a0\u2013 version SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0<\/li>\n\t<li>Honeywell CCTV Products\u00a0\u2013 version PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0<\/li>\n\t<li>Honeywell CCTV Products\u00a0\u2013 version 25M IPC WDR_2MP_32M_PTZ_v2.0<\/li>\n\t<li>Jinan USR IOT Technology Limited (PUSR) USR-W610\u00a0\u2013 version 3.1.1.0 and prior<\/li>\n\t<li>Siemens Simcenter Femap and Nastran\u00a0\u2013 versions prior to 2512<\/li>\n\t<li>Valmet DNA Engineering Web Tools\u00a0\u2013 version C2022 and prior<\/li>\n\t<li>Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-151","alert_type":398,"serial_number":"AV26-151","subject":"ics","moderation_state":"published","external_url":null},{"nid":7310,"title":"IBM security advisory (AV26-152)","uuid":"660b9079-a1d7-4698-bdd5-635e05711f54","banner":null,"lang":"en","date_modified":"2026-02-23","date_modified_ts":"2026-02-23T16:12:21Z","date_created":"2026-02-23T15:43:13Z","summary":null,"body":["<article data-history-node-id=\"7310\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-152\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-152<br \/><strong>Date: <\/strong>February 23, 2026<\/p>\n\n<p>Between February 16 and 22, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Aspera Enterprise WebApps\u00a0\u2013 version 1.0.0<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Storage Defender\u00a0- Resiliency Service\u00a0\u2013 versions 2.0.0 to 2.1.0<\/li>\n\t<li>IBM SPSS Analytic Server\u00a0\u2013 versions 3.5, 3.4, 4.0.0.0 and 3.6<\/li>\n\t<li>IBM OS Image for Red Hat Linux Systems\u00a0\u2013 versions 5.0.1.0, 4.0.7.0 and 4.0.5.0<\/li>\n\t<li>IBM Tivoli Monitoring\u00a0\u2013 versions 6.3.0.7 to 6.3.0.7 Service Pack 22<\/li>\n\t<li>IBM Watson Machine Learning Accelerator on Cloud Pak for Data\u00a0\u2013 versions 5.0.0 to 5.0.2<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0\u2013 versions 1.4.0 to 2.3.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-152","alert_type":396,"serial_number":"AV26-152","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7312,"title":"Red Hat security advisory (AV26-153)","uuid":"1f4c907e-7f65-4bf5-90ad-85dae5f89b4b","banner":null,"lang":"en","date_modified":"2026-02-23","date_modified_ts":"2026-02-23T16:13:50Z","date_created":"2026-02-23T15:59:44Z","summary":null,"body":["<article data-history-node-id=\"7312\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-153\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-153<br \/><strong>Date: <\/strong>February 23, 2026<\/p>\n\n<p>Between February 16 and 22, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-153","alert_type":396,"serial_number":"AV26-153","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7313,"title":"Ubuntu security advisory (AV26-154)","uuid":"864d2f53-b9ea-4f39-89f7-0e74513ea034","banner":null,"lang":"en","date_modified":"2026-02-23","date_modified_ts":"2026-02-23T16:24:21Z","date_created":"2026-02-23T16:15:47Z","summary":null,"body":["<article data-history-node-id=\"7313\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-154\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-154<br \/><strong>Date: <\/strong>February 23, 2026<\/p>\n\n<p>Between February 16 and 22, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-154","alert_type":396,"serial_number":"AV26-154","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7314,"title":"Microsoft Edge security advisory (AV26-155)","uuid":"d0175f93-09b2-494a-aa2f-2ae70513e802","banner":null,"lang":"en","date_modified":"2026-02-23","date_modified_ts":"2026-02-23T16:51:40Z","date_created":"2026-02-23T16:26:33Z","summary":null,"body":["<article data-history-node-id=\"7314\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-155\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-155<br \/><strong>Date: <\/strong>February 23, 2026<\/p>\n\n<p>On February 20, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 145.0.3800.70<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-20-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-155","alert_type":396,"serial_number":"AV26-155","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7315,"title":"Dell security advisory (AV26-156)","uuid":"86ca099a-b290-4d4a-a26b-2d946369acd7","banner":null,"lang":"en","date_modified":"2026-02-23","date_modified_ts":"2026-02-23T19:41:11Z","date_created":"2026-02-23T19:31:38Z","summary":null,"body":["<article data-history-node-id=\"7315\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-156\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-156<br \/><strong>Date: <\/strong>February 23, 2026<\/p>\n\n<p>Between February 16 and 22, 2026, Dell published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerEdge NVIDIA DOCA-Host\u00a0\u2013 versions prior to 3.2.1-044000<\/li>\n\t<li>Dell PowerEdge Server\u00a0\u2013 Multiple models and versions<\/li>\n\t<li>Dell PowerMax EEM\u00a0\u2013 versions prior to 10.3.0.1<\/li>\n\t<li>Dell PowerProtect Data Manager\u00a0\u2013 versions prior to 19.22.0-24<\/li>\n\t<li>Dell Repository Manager\u00a0\u2013 versions prior to 3.4.8<\/li>\n\t<li>Dell Unisphere for PowerMax\u00a0\u2013 versions prior to 10.3.0.1<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions prior to 10.5.6.12<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions prior to 10.5.5.17<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-156","alert_type":396,"serial_number":"AV26-156","subject":"dell","moderation_state":"published","external_url":null},{"nid":7316,"title":"HPE security advisory (AV26-157)","uuid":"1769c9d3-88ca-49c3-b603-904fb8f4981c","banner":null,"lang":"en","date_modified":"2026-02-23","date_modified_ts":"2026-02-23T19:54:53Z","date_created":"2026-02-23T19:42:54Z","summary":null,"body":["<article data-history-node-id=\"7316\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-157\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-157<br \/><strong>Date: <\/strong>February 23, 2026<\/p>\n\n<p>On February 20, 2026, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE SimpliVity 380 Gen11\u00a0\u2013 versions prior to SimpliVity Support Pack (SVTSP) Gen11 v2025_1001<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf04864en_us&amp;docLocale=en_US\">HPESBHF04864 rev.1\u00a0- Certain HPE SimpiVity Servers Using Certain Intel Processors, INTEL-SA-01244, 2025.2 IPU, Intel Processor Advisory, Local Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-157","alert_type":396,"serial_number":"AV26-157","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7317,"title":"Docker security advisory (AV26\u2013158)","uuid":"74a24683-d6f9-4eac-bec7-a8cca05d5d7c","banner":null,"lang":"en","date_modified":"2026-02-24","date_modified_ts":"2026-02-24T13:35:17Z","date_created":"2026-02-24T13:16:09Z","summary":null,"body":["<article data-history-node-id=\"7317\" about=\"\/en\/alerts-advisories\/docker-security-advisory-av26-158\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-158<br \/><strong>Date: <\/strong>February 24, 2026<\/p>\n\n<p>On February 23, 2026, Docker published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Docker Desktop\u00a0\u2013 versions prior to 4.62.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.docker.com\/desktop\/release-notes\/#4620\">Docker Desktop release notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/docker-security-advisory-av26-158","alert_type":396,"serial_number":"AV26-158","subject":"other","moderation_state":"published","external_url":null},{"nid":7318,"title":"Google Chrome security advisory (AV26-159)","uuid":"318f2236-3bda-4da9-aa8f-b49a5095196f","banner":null,"lang":"en","date_modified":"2026-02-24","date_modified_ts":"2026-02-24T13:53:52Z","date_created":"2026-02-24T13:44:35Z","summary":null,"body":["<article data-history-node-id=\"7318\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-159\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-159<br \/><strong>Date: <\/strong>February 24, 2026<\/p>\n\n<p>On February 23, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 145.0.7632.116\/117 (Windows\/Mac) and 144.0.7559.116 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/02\/stable-channel-update-for-desktop_23.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-159","alert_type":396,"serial_number":"AV26-159","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7319,"title":"Mozilla security advisory (AV26-160)","uuid":"8be293c9-74e5-4fa8-988a-c9eee05863ea","banner":null,"lang":"en","date_modified":"2026-02-24","date_modified_ts":"2026-02-24T16:29:36Z","date_created":"2026-02-24T16:16:22Z","summary":null,"body":["<article data-history-node-id=\"7319\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-160\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-160<br \/><strong>Date: <\/strong>February 24, 2026<\/p>\n\n<p>On February 24, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\u00a0\u2013 versions prior to 140.8<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.33<\/li>\n\t<li>Firefox\u00a0\u2013 versions prior to 148<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-15\/\">Mozilla Foundation Security Advisory 2026-15<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-14\/\">Mozilla Foundation Security Advisory 2026-14<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-13\/\">Mozilla Foundation Security Advisory 2026-13<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-160","alert_type":396,"serial_number":"AV26-160","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7320,"title":"SonicWall security advisory (AV26-161)","uuid":"e6b61ee2-1deb-4be1-ac11-980fad49f4fd","banner":null,"lang":"en","date_modified":"2026-02-24","date_modified_ts":"2026-02-24T16:55:13Z","date_created":"2026-02-24T16:37:15Z","summary":null,"body":["<article data-history-node-id=\"7320\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-161\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-161<br \/><strong>Date: <\/strong>February 24, 2026<\/p>\n\n<p>On February 24, 2026, SonicWall published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Gen7 hardware Firewalls\u00a0\u2013 version 7.0.1-5169 and prior<\/li>\n\t<li>Gen7 virtual Firewalls (NSv)\u00a0\u2013 version 7.3.1-7013 and prior<\/li>\n\t<li>Gen8 Firewalls\u00a0\u2013 version 8.1.0-8017 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0001\">SonicOS multiple post-authentication vulnerabilities\u00a0- SNWLID-2026-0001<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-161","alert_type":396,"serial_number":"AV26-161","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":7321,"title":"VMware security advisory (AV26-162) \u2013 Update 1 ","uuid":"b71b55e9-2956-47a3-9d36-c17096591643","banner":null,"lang":"en","date_modified":"2026-03-03","date_modified_ts":"2026-03-03T19:53:27Z","date_created":"2026-02-24T17:02:15Z","summary":null,"body":["<article data-history-node-id=\"7321\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-162\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-162<br \/><strong>Date: <\/strong>February 24, 2026<br \/><strong>Updated:<\/strong> March 3, 2026<\/p>\n\n<p>On February 24, 2026, VMware published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<p><strong>Update 1<\/strong><br \/>\nOn March 3, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22719 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul><li>VMware Cloud Foundation\u00a0\u2013 versions prior to 9.0.2.0<\/li>\n\t<li>VMware vSphere Foundation\u00a0\u2013 versions prior to 9.0.2.0<\/li>\n\t<li>VMware Aria Operations\u00a0\u2013 versions prior to 8.18.6<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/36947\">VMSA-2026-0001: VMware Aria Operations updates address multiple vulnerabilities (CVE-2026-22719, CVE-2026-22720 and CVE-2026-22721)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-22719\">CISA KEV: CVE-2026-22719<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-162","alert_type":396,"serial_number":"AV26-162","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7322,"title":"[Control systems] ABB security advisory (AV26-163)","uuid":"36120761-c918-489c-83bc-ff1dcd67c8be","banner":null,"lang":"en","date_modified":"2026-02-24","date_modified_ts":"2026-02-24T20:30:01Z","date_created":"2026-02-24T20:20:23Z","summary":null,"body":["<article data-history-node-id=\"7322\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-163\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-163<br \/><strong>Date: <\/strong>February 24, 2026<\/p>\n\n<p>On February 24, 2026, ABB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AC500 V3 firmware\u00a0\u2013 versions prior to 3.9.0<\/li>\n\t<li>Automation Builder\u00a0\u2013 versions prior to 2.9.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011524&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">AC500 V3 Multiple vulnerabilities\u00a0- CVE IDs: CVE-2025-2595, CVE-2025-41659, CVE-2025-41691<\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011525&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Automation Builder Gateway for Windows with insecure defaults CVE ID: CVE-2024-41975<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-163","alert_type":398,"serial_number":"AV26-163","subject":"abb","moderation_state":"published","external_url":null},{"nid":7323,"title":"HPE security advisory (AV26-164)","uuid":"9eb455fb-3888-4c92-ab9a-032b4d592ec2","banner":null,"lang":"en","date_modified":"2026-02-24","date_modified_ts":"2026-02-24T20:47:04Z","date_created":"2026-02-24T20:42:36Z","summary":null,"body":["<article data-history-node-id=\"7323\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-164\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-164<br \/><strong>Date: <\/strong>February 24, 2026<\/p>\n\n<p>On February 24, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE ProLiant AMD DL\/XL Servers\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf05021en_us&amp;docLocale=en_US#hpesbhf05021-rev-1-certain-hpe-proliant-amd-dl-xl-0\">HPESBHF05021 rev.1 - Certain HPE ProLiant AMD DL\/XL Servers Using Certain AMD EPYC Processors, AMD-SB-7059: Guest Initiated Machine Check Errors, Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-164","alert_type":396,"serial_number":"AV26-164","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7324,"title":"SolarWinds security advisory (AV26-165)","uuid":"41fc5e9f-f3d6-4875-8b4d-8ff57511ad82","banner":null,"lang":"en","date_modified":"2026-02-24","date_modified_ts":"2026-02-24T21:04:36Z","date_created":"2026-02-24T20:59:27Z","summary":null,"body":["<article data-history-node-id=\"7324\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-165\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-165<br \/><strong>Date: <\/strong>February 24, 2026<\/p>\n\n<p>On February 24, 2026, SolarWinds published security advisories to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>SolarWinds Serv-U\u00a0- versions prior to 15.5.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2025-40538\">SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability (CVE-2025-40538)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-165","alert_type":396,"serial_number":"AV26-165","subject":"other","moderation_state":"published","external_url":null},{"nid":7325,"title":"Cisco security advisory (AV26-166) \u2013 Update 3","uuid":"69f1bd2e-3b90-491c-b1d5-46201630065a","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T19:43:40Z","date_created":"2026-02-25T14:21:30Z","summary":null,"body":["<article data-history-node-id=\"7325\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-166\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-166<br \/><strong>Date:<\/strong> February\u00a025, 2026<br \/><strong>Updated:<\/strong> April\u00a020, 2026<\/p>\n\n<p>On February\u00a025, 2026, Cisco published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Catalyst SD-WAN Controller\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Catalyst SD-WAN Manager\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Nexus 3600 and 9500-R Switching Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Nexus 9000 Series Fabric Switches\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco UCS Software (UCS Manager Mode)\u00a0\u2013 versions prior to 4.3(6e)<\/li>\n\t<li>Cisco UCS Software (Intersight Managed Mode)\u00a0\u2013 versions prior to 4.3(6.260003)<\/li>\n<\/ul><p>Cisco has indicated that CVE-2026-20127 has been exploited.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On February 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20127 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>Cisco has indicated that CVE-2026-20128 and CVE-2026-20122 are being actively exploited.<\/p>\n\n<h2 class=\"h3\">Update 3<\/h2>\n\n<p>On April 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-rpa-EHchtZk\">Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-authbp-qwCX8D4v\">Cisco Catalyst SD-WAN Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-ether-dos-Kv8YNWZ4\">Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-dsnmp-cNN39Uh\">Cisco Nexus 9000 Series Fabric Switches in ACI Mode SNMP Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nxos-cpdos-qLsv6pFD\">Cisco Nexus 9000 Series Fabric Switches in ACI Mode Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-n3kn9k_aci_lldp_dos-NdgRrrA3\">Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-20127\">CISA KEV\u00a0: CVE-2026-20127<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20122\">CISA KEV: CVE-2026-20122<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20128\">CISA KEV: CVE-2026-20128<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20133\">CISA KEV: CVE-2026-20133<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-166","alert_type":396,"serial_number":"AV26-166","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7326,"title":"AL26-004 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20127","uuid":"a7742d24-6906-4d41-932f-88b586906233","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T16:07:47Z","date_created":"2026-02-25T14:26:15Z","summary":null,"body":["<article data-history-node-id=\"7326\" about=\"\/en\/alerts-advisories\/al26-004-critical-vulnerability-affecting-cisco-catalyst-sd-wan-cve-2026-20127\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-004<br \/><strong>Date:<\/strong> February\u00a025, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) devices<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. In response to the Cisco security advisory released on February\u00a025,\u00a02026<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, the Cyber Centre issued AV26-166<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\">4<\/a><\/sup> on February\u00a025,\u00a02026.<\/p>\n\n<p>Tracked as CVE-2026-20127<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>, this vulnerability is a critical Improper Authentication vulnerability (CWE-287)<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> affecting the peering authentication process of Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> Controller (formerly <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> vSmart) and Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> Manager (formerly <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> vManage). It could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.<\/p>\n\n<p>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> Controller systems that have internet-exposed management or control planes and have ports exposed are at risk of compromise.<\/p>\n\n<p>This vulnerability affects the following deployment types:<\/p>\n\n<ul><li>On-Prem Deployment<\/li>\n\t<li>Cisco Hosted <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> Cloud\u00a0- Cisco Managed<\/li>\n\t<li>Cisco Hosted <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> Cloud\u00a0- FedRAMP Environment<\/li>\n\t<li>Cisco Hosted <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> Cloud<\/li>\n<\/ul><p>The Cyber Centre is aware of incidents involving CVE-2026-20127. The reports indicate that malicious rogue peers were added to the configuration of affected organization\u2019s <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr>. This allowed multiple follow-up actions including administrative access, persistence and long-term access to <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> networks.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td>Earlier than <span class=\"nowrap\">20.9<sup id=\"fn*a-rf\"><a class=\"fn-lnk\" href=\"#fn*\"><span class=\"wb-inv\">Footnote <\/span>*<\/a><\/sup><\/span><\/td>\n\t\t\t<td>Migrate to a fixed release.<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td>20.9<\/td>\n\t\t\t<td>20.9.8.2 (Estimated release February\u00a027,\u00a02026)<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td><span class=\"nowrap\">20.11<sup id=\"fn*b-rf\"><a class=\"fn-lnk\" href=\"#fn*\"><span class=\"wb-inv\">Footnote <\/span>*<\/a><\/sup><\/span><\/td>\n\t\t\t<td>20.12.6.1<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td>20.12.5<\/td>\n\t\t\t<td>20.12.5.3<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td>20.12.6<\/td>\n\t\t\t<td>20.12.6.1<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td><span class=\"nowrap\">20.13<sup id=\"fn*c-rf\"><a class=\"fn-lnk\" href=\"#fn*\"><span class=\"wb-inv\">Footnote <\/span>*<\/a><\/sup><\/span><\/td>\n\t\t\t<td>20.15.4.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td><span class=\"nowrap\">20.14<sup id=\"fn*d-rf\"><a class=\"fn-lnk\" href=\"#fn*\"><span class=\"wb-inv\">Footnote <\/span>*<\/a><\/sup><\/span><\/td>\n\t\t\t<td>20.15.4.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td>20.15<\/td>\n\t\t\t<td>20.15.4.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td><span class=\"nowrap\">20.16<sup id=\"fn*e-rf\"><a class=\"fn-lnk\" href=\"#fn*\"><span class=\"wb-inv\">Footnote <\/span>*<\/a><\/sup><\/span><\/td>\n\t\t\t<td>20.18.2.1<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD_WAN<\/abbr> Release<\/td>\n\t\t\t<td>20.18<\/td>\n\t\t\t<td>20.18.2.1<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>The Cyber Centre also recommends organizations to:<\/p>\n\n<ul><li>Collect artifacts, including virtual snapshots and logs from <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> technology<\/li>\n\t<li>Fully patch <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> technology including those that are affected by <span class=\"nowrap\">CVE-2026-20127<\/span><\/li>\n\t<li>Hunt for evidence of compromise as detailed in the Hunt Guide<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>; and<\/li>\n\t<li>Implement Cisco\u2019s <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> hardening guidance<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><\/li>\n<\/ul><p>Cisco\u2019s Catalyst <abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> hardening guidance should be reviewed in full and includes advice on the following:<\/p>\n\n<ul><li>Network perimeter controls: Ensure control components are behind a firewall, isolate <abbr title=\"virtual private network\">VPN<\/abbr> 512 (management) interfaces, and use <abbr title=\"internet protocol\">IP<\/abbr> blocks for manually provisioned edge <abbr title=\"internet protocol\">IP<\/abbr>s.<\/li>\n\t<li><abbr title=\"Software-Defined Wide Area Network\">SD-WAN<\/abbr> Manager access: Replace the self-signed certificate for the web user interface<\/li>\n\t<li>Control and data plane security: Use pairwise keying<\/li>\n\t<li>Session timeout: Limit to the shortest period possible<\/li>\n\t<li>Logging: Forward to a remote syslog server<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<ul><li>Consolidating, monitoring, and defending internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>*<\/dt>\n\t<dd id=\"fn*\">\n\t<p>These releases have reached End of Software Maintenance.<\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn*-rf\"><span class=\"wb-inv\">Return to footnote<\/span>*<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/topics\/networking\/what-is-sd-wan.html\">What is SD-WAN? Software-Defined WAN (SDWAN)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/blog.talosintelligence.com\/uat-8616-sd-wan\/\">Active exploitation of Cisco Catalyst SD-WAN by UAT-8616<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-rpa-EHchtZk\">Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-166\">Cisco security advisory (AV26-166)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-20127\">NVD\u00a0- CVE-2026-20127<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/287.html\">CWE-287: Improper Authentication<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.cyber.gov.au\/sites\/default\/files\/2026-02\/ACSC-led%20Cisco%20SD-WAN%20Hunt%20Guide.pdf\">CISCO SD-WAN <span class=\"text-uppercase\">THREAT HUNT GUIDE<\/span><\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/resources\/Cisco-Catalyst-SD-WAN-HardeningGuide\">Cisco Catalyst SD-WAN Hardening Guide<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-004-critical-vulnerability-affecting-cisco-catalyst-sd-wan-cve-2026-20127","alert_type":397,"serial_number":"AL26-004","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7327,"title":"Zyxel security advisory (AV26-167)","uuid":"a1d09be8-a742-45a3-b10a-1b54fc70d32f","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T18:26:30Z","date_created":"2026-02-25T18:10:19Z","summary":null,"body":["<article data-history-node-id=\"7327\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av26-167\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-167<br \/><strong>Date: <\/strong>February 25, 2026<\/p>\n\n<p>On February 24, 2026, Zyxel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>4G LTE\/5G NR CPE\u00a0\u2013 multiple models and versions<\/li>\n\t<li>DSL\/Ethernet CPE\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Fiber ONTs\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Security Routers\u00a0\u2013 multiple models and versions<\/li>\n\t<li>Wireless Extenders\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-null-pointer-dereference-and-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-security-routers-and-wireless-extenders-02-24-2026\">Zyxel security advisory for null pointer dereference and command injection vulnerabilities in certain 4G LTE\/5G NR CPE, DSL\/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av26-167","alert_type":396,"serial_number":"AV26-167","subject":"other","moderation_state":"published","external_url":null},{"nid":7328,"title":"GitLab security advisory (AV26-170)","uuid":"cd8d5c7d-465c-41c4-ba45-c7faad97ff2c","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T19:16:00Z","date_created":"2026-02-25T18:27:58Z","summary":null,"body":["<article data-history-node-id=\"7328\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-170\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-170<br \/><strong>Date: <\/strong>February 25, 2026<\/p>\n\n<p>On February 25, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.9.1, 18.8.5 and 18.7.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.9.1, 18.8.5 and 18.7.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/02\/25\/patch-release-gitlab-18-9-1-released\/\">GitLab Patch Release: 18.9.1, 18.8.5, 18.7.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-170","alert_type":396,"serial_number":"AV26-170","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7329,"title":"Trend Micro security advisory (AV26-168)","uuid":"f0cc74ee-7967-4219-9835-947da5a258d0","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T18:36:46Z","date_created":"2026-02-25T18:29:26Z","summary":null,"body":["<article data-history-node-id=\"7329\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory-av26-168\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-168<br \/><strong>Date: <\/strong>February 25, 2026<\/p>\n\n<p>On February 24, 2026, Trend Micro published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Apex One (on-premise)\u00a0\u2013 versions prior to 2019 (on-prem)<\/li>\n\t<li>Apex One as a service\u00a0\u2013 SaaS<\/li>\n\t<li>Trend Vision One Endpoint\u00a0- Standard Endpoint Protection\u00a0\u2013 Saas<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/success.trendmicro.com\/en-US\/solution\/KA-0022458\"><span class=\"text-uppercase\">security bulletin<\/span>: Apex One and Apex One (Mac)\u00a0- February 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/success.trendmicro.com\/en-US\/vulnerability-response\/\">Trend Micro Business Success Vulnerability Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory-av26-168","alert_type":396,"serial_number":"AV26-168","subject":"other","moderation_state":"published","external_url":null},{"nid":7330,"title":"JetBrains security advisory (AV26-171)","uuid":"64981461-3bfc-4bb6-9f4e-54ef1f5e7e77","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T19:16:48Z","date_created":"2026-02-25T18:37:43Z","summary":null,"body":["<article data-history-node-id=\"7330\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-171\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-171<br \/><strong>Date: <\/strong>February 25, 2026<\/p>\n\n<p>On February 25, 2026, JetBrains published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>JetBrains TeamCity\u00a0\u2013 versions prior to 2025.11.3<\/li>\n\t<li>JetBrains YouTrack\u00a0\u2013 versions prior to 2025.3.121962<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-171","alert_type":396,"serial_number":"AV26-171","subject":"other","moderation_state":"published","external_url":null},{"nid":7331,"title":"AMD security advisory (AV26-169)","uuid":"fda3d9e9-d2fe-43e2-acea-7a34a3cff9c1","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T19:08:43Z","date_created":"2026-02-25T18:42:42Z","summary":null,"body":["<article data-history-node-id=\"7331\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-169\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-19<br \/><strong>Date: <\/strong>February 25, 2026<\/p>\n\n<p>On February 24, 2026, AMD published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Athlon and<\/span> AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen Processors<\/span>\u00a0\u2013 multiple models and versions<\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen Embedded Processors<\/span>\u00a0\u2013 multiple models and versions<\/li>\n\t<li>AMD EPYC <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">and<\/span> AMD EPYC <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Embedded Series Processors<\/span>\u00a0\u2013 multiple models and versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7059.html\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Guest Initiated Machine Check Errors<\/span> AMD-SB-7059<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Product Security<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-169","alert_type":396,"serial_number":"AV26-169","subject":"other","moderation_state":"published","external_url":null},{"nid":7332,"title":"Juniper Networks security advisory (AV26-172)","uuid":"6f3db6cb-cf58-4d90-ada7-e164dacc1d41","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T20:28:47Z","date_created":"2026-02-25T20:12:46Z","summary":null,"body":["<article data-history-node-id=\"7332\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-172\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-172<br \/><strong>Date: <\/strong>February 25, 2026<\/p>\n\n<p>On February 25, 2026, Juniper Networks published a security advisory to address vulnerabilities in the following products. Included was a critical update for the following:<\/p>\n\n<ul><li>Junos OS Evolved on PTX Series\u00a0\u2013 25.4 versions prior to 25.4R1-S1-EVO, 25.4R2-EVO<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2026-02-Out-of-Cycle-Security-Bulletin-Junos-OS-Evolved-PTX-Series-A-vulnerability-allows-a-unauthenticated-network-based-attacker-to-execute-code-as-root-CVE-2026-21902\">2026-02 Out-of-Cycle Security Bulletin: Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root (CVE-2026-21902)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri#sort=relevancy&amp;f:ctype=[Security%20Advisories\">Juniper Networks<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-172","alert_type":396,"serial_number":"AV26-172","subject":"juniper","moderation_state":"published","external_url":null},{"nid":7333,"title":"VMware security advisory (AV26-173)","uuid":"393b31dc-8579-4713-8408-735658cfd0f0","banner":null,"lang":"en","date_modified":"2026-02-25","date_modified_ts":"2026-02-25T21:02:56Z","date_created":"2026-02-25T20:58:34Z","summary":null,"body":["<article data-history-node-id=\"7333\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-173\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-173<br \/><strong>Date: <\/strong>February 25, 2026<\/p>\n\n<p>Between February 24 and 25, 2026, VMware published security advisories to address critical vulnerabilities in multiple products:<\/p>\n\n<ul><li>VMware Tanzu\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-173","alert_type":396,"serial_number":"AV26-173","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7334,"title":"ServiceNow security advisory (AV26-174)","uuid":"8f3c13cd-27a4-4fba-8451-2ca2f7180fb4","banner":null,"lang":"en","date_modified":"2026-02-26","date_modified_ts":"2026-02-26T18:23:14Z","date_created":"2026-02-26T18:04:05Z","summary":null,"body":["<article data-history-node-id=\"7334\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av26-174\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-174<br \/><strong>Date: <\/strong>February 26, 2026<\/p>\n\n<p>On February 25, 2026, ServiceNow published a Security Advisory to address vulnerabilities in the following products. Included was a critical update for the following:<\/p>\n\n<ul><li>ServiceNow Australia\u00a0\u2013 versions prior to Australia<\/li>\n\t<li>ServiceNow Xanadu\u00a0\u2013 versions prior to Xanadu Patch 11 Hot Fix 1a<\/li>\n\t<li>ServiceNow Yokohama\u00a0\u2013 versions prior to Yokohama Patch 12 and Patch 10 Hot Fix 1b<\/li>\n\t<li>ServiceNow Zurich\u00a0\u2013 versions prior to Zurich Patch 5 and Patch 4 Hot Fix 3b<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB2693566\">[Security Advisory] CVE-2026-0542\u00a0- Remote Code Execution in ServiceNow AI Platform<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av26-174","alert_type":396,"serial_number":"AV26-174","subject":"other","moderation_state":"published","external_url":null},{"nid":7335,"title":"Drupal security advisory (AV26-175)","uuid":"87c21e54-fda0-4ab8-958a-3a4d953951cb","banner":null,"lang":"en","date_modified":"2026-02-26","date_modified_ts":"2026-02-26T18:48:19Z","date_created":"2026-02-26T18:28:54Z","summary":null,"body":["<article data-history-node-id=\"7335\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-175\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-175<br \/><strong>Date: <\/strong>February 26, 2026<\/p>\n\n<p>On February 25, 2026, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Material Icons\u00a0\u2013 versions prior to 2.0.4<\/li>\n\t<li>Theme Negotiation by Rules\u00a0\u2013 versions prior to 1.2.1<\/li>\n\t<li>Tagify\u00a0\u2013 versions prior to 1.2.49<\/li>\n\t<li>Anti-Spam by CleanTalk\u00a0\u2013 versions prior to 9.7.0<\/li>\n\t<li>CAPTCHA\u00a0\u2013 versions prior to 1.17.0, version 2.0.0 to versions prior to 2.0.10<\/li>\n\t<li>Islandora\u00a0\u2013 versions prior to 2.17.5<\/li>\n\t<li>Drupal Canvas\u00a0\u2013 versions prior to 1.1.1<\/li>\n\t<li>SAML SSO\u00a0- Service Provider\u00a0\u2013 versions prior to 3.1.3<\/li>\n\t<li>Responsive Favicons\u00a0\u2013 versions prior to 2.0.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-175","alert_type":396,"serial_number":"AV26-175","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7336,"title":"n8n security advisory (AV26-176)","uuid":"7b1a7028-e491-4d64-9aaf-8e3c241f0797","banner":null,"lang":"en","date_modified":"2026-02-26","date_modified_ts":"2026-02-26T19:09:12Z","date_created":"2026-02-26T18:52:04Z","summary":null,"body":["<article data-history-node-id=\"7336\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-176\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-176<br \/><strong>Date: <\/strong>February 26, 2026<\/p>\n\n<p>On February 25, 2026, n8n published security updates to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>n8n (Merge Node)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Expression Sandbox)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Task Runner Sandbox)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Form Node)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Form Trigger\/Chat Trigger\/Send &amp; Wait\/Webhook\/Chat Nodes)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-wxx7-mcgf-j869\">Remote Code Execution via Merge Node<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-vpcf-gvg4-6qwr\">Expression Sandbox Escape Leading to RCE<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-jjpj-p2wh-qf23\">Sandbox Escape in JavaScript Task Runner<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-75g8-rv7v-32f7\">Unauthenticated Expression Evaluation via Form Node<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-2p9h-rqjw-gm92\">Stored XSS via Various Nodes<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-176","alert_type":396,"serial_number":"AV26-176","subject":"other","moderation_state":"published","external_url":null},{"nid":7337,"title":"Microsoft Edge security advisory (AV26-177)","uuid":"4492437f-366a-4450-8c6a-810232b9ae90","banner":null,"lang":"en","date_modified":"2026-02-27","date_modified_ts":"2026-02-27T17:05:23Z","date_created":"2026-02-27T17:00:44Z","summary":null,"body":["<article data-history-node-id=\"7337\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-177\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-177<br \/><strong>Date: <\/strong>February 27, 2026<\/p>\n\n<p>On February 26, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 145.0.3800.82<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#february-26-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-177","alert_type":396,"serial_number":"AV26-177","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7338,"title":"VMware security advisory (AV26-178)","uuid":"eb8ab337-c536-40cf-8786-ff8ff6b3bcea","banner":null,"lang":"en","date_modified":"2026-02-27","date_modified_ts":"2026-02-27T17:13:46Z","date_created":"2026-02-27T17:07:19Z","summary":null,"body":["<article data-history-node-id=\"7338\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-178\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-178<br \/><strong>Date: <\/strong>February 27, 2026<\/p>\n\n<p>On February 26, 2026, VMware published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu for Postgres\u00a0\u2013 versions prior to 18.2.0, 17.8.0, 16.12.0, 15.16.0 and 14.21.0<\/li>\n\t<li>VMware Tanzu for Postgres on Kubernetes\u00a0\u2013 versions prior to 4.3.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37110\">Product Release Advisory\u00a0- VMware Tanzu for Postgres 18.2.0, 17.8.0, 16.12.0, 15.16.0, 14.21.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37109\">Product Release Advisory\u00a0- VMware Tanzu for Postgres on Kubernetes 4.3.2<\/a><\/li>\n  <li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-178","alert_type":396,"serial_number":"AV26-178","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7339,"title":"FreeBSD security advisory (AV26-179)","uuid":"b2f7c06a-a6d0-42f0-96e9-82b93822f724","banner":null,"lang":"en","date_modified":"2026-02-27","date_modified_ts":"2026-02-27T17:51:02Z","date_created":"2026-02-27T17:45:23Z","summary":null,"body":["<article data-history-node-id=\"7339\" about=\"\/en\/alerts-advisories\/freebsd-security-advisory-av26-179\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-179<br \/><strong>Date: <\/strong>February 27, 2026<\/p>\n\n<p>On February 24, 2026, FreeBSD published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>FreeBSD\u00a0\u2013 version 14.3<\/li>\n  \t<li>FreeBSD\u00a0\u2013 version 13.5<\/li><\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:04.jail.asc\">Jail chroot escape via fd exchange with a different jail (CVE-2025-15576)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:05.route.asc\">Local DoS and possible privilege escalation via routing sockets (CVE-2026-3038)<\/a><\/li>\t\n  <li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/\">FreeBSD Security Advisories<\/a><\/li>\n\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freebsd-security-advisory-av26-179","alert_type":396,"serial_number":"AV26-179","subject":"other","moderation_state":"published","external_url":null},{"nid":7341,"title":"IBM security advisory (AV26-180)","uuid":"e325aade-4e45-417d-a046-4a9084396377","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T16:00:01Z","date_created":"2026-03-02T15:37:58Z","summary":null,"body":["<article data-history-node-id=\"7341\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-180\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-180<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>Between February 23 and March 1, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>DataStage on Cloud Pak for Data\u00a0\u2013 version 5.3.0<\/li>\n\t<li>IBM App Connect Enterprise\u00a0\u2013 versions 13.0.1.0 to 13.0.6.1, versions 12.0.1.0 to 12.0.12.22<\/li>\n\t<li>IBM Automation Decision Services\u00a0\u2013 versions 25.0.0, 24.0.0 and 24.0.1<\/li>\n\t<li>IBM Business Automation Insights\u00a0\u2013 versions 25.0.0, 24.0.1 and 24.0.0<\/li>\n\t<li>IBM CICS TX Advanced\u00a0\u2013 version 10.1<\/li>\n\t<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n\t<li>IBM Cognos Command Center\u00a0\u2013 versions 10.2.5 to 10.2.5 FP1 IF2, versions 10.2.4.1 to 10.2.4.1 IF19<\/li>\n\t<li>IBM DevOps Solutions Workbench\u00a0\u2013 versions 5.0.0.0 and 5.1.0.0<\/li>\n\t<li>IBM License Metric Tool\u00a0\u2013 versions 9.2.0 to 9.2.41<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- IoT Component\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Security Verify Governance\u00a0\u2013 version ISVG 10.0.2<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager\u00a0- Software component\u00a0\u2013 version ISVG 10.0.2<\/li>\n\t<li>IBM Security Verify Governance, Identity Manager\u00a0- Virtual Appliance component\u00a0\u2013 version ISVG 10.0.2<\/li>\n\t<li>IBM Sterling Secure Proxy\u00a0\u2013 multiple version<\/li>\n\t<li>IBM TXSeries for Multiplatforms\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Terracotta\u00a0\u2013 versions 11.1 to 11.1.0.10<\/li>\n\t<li>IBM Tivoli Netcool\/OMNIbus_GUI\u00a0\u2013 versions 8.1.0 to 8.1.0.39<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0\u2013 versions 4.0.0 to 5.3.0<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.8.4 to 4.8.5<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data \u2013 versions 5.0.0 to 5.3<\/li>\n\t<li>ICP\u00a0\u2013 Discovery\u00a0\u2013 versions 5.0.0 to 5.3.0<\/li>\n\t<li>MongoDB Enterprise Advanced with IBM (Ops Manager)\u00a0\u2013 versions 7.0.0 to 7.0.17, versions 8.0.0 to 8.0.12<\/li>\n\t<li>QRadar\u00a0\u2013 versions 7.5.0 to 7.5.0 UP14 IF04<\/li>\n\t<li>Total Storage Service Console (TSSC) \/ TS4500 IMC\u00a0\u2013 multiple version<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-180","alert_type":396,"serial_number":"AV26-180","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7342,"title":"Dell security advisory (AV26-181)","uuid":"1074ca08-bb87-4773-bbd3-d8009c591d48","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T16:17:24Z","date_created":"2026-03-02T16:02:14Z","summary":null,"body":["<article data-history-node-id=\"7342\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-181\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-181<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>Between February 23 and March 1, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell PowerStore T Security\u00a0\u2013 versions prior to 4.3.1.0-2662695<\/li>\n\t<li>Dell AMD-based PowerEdge Server\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell PowerEdge\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000432173\/dsa-2026-115-dell-powerstore-t-security-update-for-multiple-vulnerabilities\">DSA-2026-115: Dell PowerStore T Security Update for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000432584\/dsa-2026-075-security-update-for-dell-amd-based-poweredge-server-vulnerability\">DSA-2026-075: Security Update for Dell AMD-based PowerEdge Server Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000433020\/dsa-2026-119-security-update-for-nvidia-bluefield-connectx-and-doca-vulnerabilities\">DSA-2026-119: Security Update for NVIDIA Bluefield, ConnectX and DOCA Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-181","alert_type":396,"serial_number":"AV26-181","subject":"dell","moderation_state":"published","external_url":null},{"nid":7343,"title":"Ubuntu security advisory (AV26-182)","uuid":"d51d985e-aff5-4738-ad1b-26bf0a2509ad","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T16:26:11Z","date_created":"2026-03-02T16:20:53Z","summary":null,"body":["<article data-history-node-id=\"7343\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-182\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-182<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>Between February 23 and March 1, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-182","alert_type":396,"serial_number":"AV26-182","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7344,"title":"[Control systems] CISA ICS security advisories (AV26\u2013183)","uuid":"fd13d119-577e-49c4-bda4-04ad09dc047d","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T16:37:27Z","date_created":"2026-03-02T16:28:48Z","summary":null,"body":["<article data-history-node-id=\"7344\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-183\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-183<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>Between February 23 and March 1, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Chargemap chargemap.com<\/span>\u00a0\u2013 all versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">CloudCharge cloudcharge.se<\/span>\u00a0\u2013 all versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Copeland XWEB and XWEB Pro<\/span>\u00a0\u2013 versions prior to 1.12.1<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">EV Energy ev.energy<\/span>\u00a0\u2013 all versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">EV2GO ev2go.io<\/span>\u00a0\u2013 all versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Gardyn Home Kit Firmware<\/span>\u00a0\u2013 versions prior to master.619<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">InSAT MasterSCADA BUK-TS<\/span>\u00a0\u2013 all versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Johnson Controls, Inc. Frick Controls Quantum HD<\/span>\u00a0\u2013 versions prior to 10.22<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Mobility46 mobility46.se<\/span>\u00a0\u2013 all versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Pelco, Inc. Sarix Pro 3 Series IP Cameras<\/span>\u00a0\u2013 multiple versions and models<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">SWITCH EV swtchenergy.com<\/span>\u00a0\u2013 all versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Schneider Electric EcoStruxure Building Operation Workstation<\/span>\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Yokogawa CENTUM VP R6, R7<\/span>\u00a0\u2013 versions prior to R1.07.00<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-183","alert_type":398,"serial_number":"AV26-183","subject":"ics","moderation_state":"published","external_url":null},{"nid":7345,"title":"Red Hat security advisory (AV26-184)","uuid":"7aabeccb-c985-49e5-95c0-bd1f202272c9","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T16:54:36Z","date_created":"2026-03-02T16:45:37Z","summary":null,"body":["<article data-history-node-id=\"7345\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-184\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-184<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>Between February 23 and March 1, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-184","alert_type":396,"serial_number":"AV26-184","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7346,"title":"HPE security advisory (AV26-185)","uuid":"2dfa1f1f-83d8-4df4-b405-bc744af094be","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T17:03:36Z","date_created":"2026-03-02T16:55:52Z","summary":null,"body":["<article data-history-node-id=\"7346\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-185\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-185<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>On February 27, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE AutoPass License Server (APLS)\u00a0\u2013 versions prior to 9.19<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbgn05003en_us&amp;docLocale=en_US\">HPESBGN05003 rev.1\u00a0- HPE AutoPass License Server (APLS), Remote Authentication Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-185","alert_type":396,"serial_number":"AV26-185","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7347,"title":"VMware security advisory (AV26-186)","uuid":"31f9336b-a923-4bcd-be54-1b44d1a96caa","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T17:12:25Z","date_created":"2026-03-02T17:06:01Z","summary":null,"body":["<article data-history-node-id=\"7347\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-186\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-186<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n\n<p>On February 27, 2026, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<ul><li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 7.7.1<\/li>\n  <li>VMware Tanzu Greenplum\u00a0\u2013 versions prior to 6.32.1<\/li>\n  <li>VMware Tanzu Greenplum Upgrade\u00a0\u2013 versions prior to 1.10.3<\/li>\n  <li>VMware Tanzu Greenplum Backup and Restore\u00a0\u2013 versions prior to 1.32.4<\/li>\n<li>VMware Tanzu RabbitMQ on Kubernetes\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-186","alert_type":396,"serial_number":"AV26-186","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7348,"title":"Android security advisory \u2013 March 2026 monthly rollup (AV26-187)","uuid":"903012f8-e278-4d0b-be40-c4a47e4f9cbb","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T20:27:20Z","date_created":"2026-03-02T20:24:32Z","summary":null,"body":["<article data-history-node-id=\"7348\" about=\"\/en\/alerts-advisories\/android-security-advisory-march-2026-monthly-rollup-av26-187\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-187<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>On March 2, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>Android has advised that CVE-2026-21385 is being exploited.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-03-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-march-2026-monthly-rollup-av26-187","alert_type":396,"serial_number":"AV26-187","subject":"android","moderation_state":"published","external_url":null},{"nid":7349,"title":"Veeam security advisory (AV26-188)","uuid":"c126377e-465c-4b80-ae2c-060e040bcf79","banner":null,"lang":"en","date_modified":"2026-03-02","date_modified_ts":"2026-03-02T20:36:31Z","date_created":"2026-03-02T20:30:19Z","summary":null,"body":["<article data-history-node-id=\"7349\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-188\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-188<br \/><strong>Date: <\/strong>March 2, 2026<\/p>\n\n<p>On March 2, 2026, Veeam published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Veeam Kasten for Kubernetes \u2013 multiple versions<\/li>\n\t<li>Kasten K10 by Veeam \u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4825\">List of Security Fixes and Improvements in Veeam Kasten for Kubernetes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-188","alert_type":396,"serial_number":"AV26-188","subject":"other","moderation_state":"published","external_url":null},{"nid":7351,"title":"WatchGuard security advisory (AV26-189)","uuid":"615ab518-f19c-424b-86dc-7902d38c2591","banner":null,"lang":"en","date_modified":"2026-03-03","date_modified_ts":"2026-03-03T14:49:00Z","date_created":"2026-03-03T14:19:07Z","summary":null,"body":["<article data-history-node-id=\"7351\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-189\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-189<\/p>\n\n<p class=\"mrgn-bttm-md\"><strong>Date: <\/strong>March 3, 2026<\/p>\n\n<p>On March 3, 2026, WatchGuard published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Fireware OS\u00a0\u2013 versions prior to 11.12.4_Update1<\/li>\n\t<li>Fireware OS\u00a0\u2013 versions prior to 12.11.8<\/li>\n\t<li>Fireware OS\u00a0\u2013 versions prior to 2026.1.2<\/li>\n\t<li>Fireware OS\u00a0- versions prior to 12.5.17<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00003\">WatchGuard Firebox Out of Bounds Write Vulnerability (CVE-2026-3342)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00004\">WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI (CVE-2026-3343)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00005\">WatchGuard Firebox System Integrity Check Bypass (CVE-2026-3344)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-189","alert_type":396,"serial_number":"AV26-189","subject":"other","moderation_state":"published","external_url":null},{"nid":7352,"title":"Qualcomm security advisory \u2013 March 2026 monthly rollup (AV26-190) \u2013 Update 1","uuid":"692673bc-1623-4515-9be8-6632ccf02aa0","banner":null,"lang":"en","date_modified":"2026-03-03","date_modified_ts":"2026-03-03T20:13:15Z","date_created":"2026-03-03T14:53:26Z","summary":null,"body":["<article data-history-node-id=\"7352\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-march-2026-monthly-rollup-av26-190\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-190<br \/><strong>Date: <\/strong>March 3, 2026<br \/><strong>Updated:<\/strong> March 3, 2026<\/p>\n\n<p>On March 2, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p><strong>Update 1<\/strong><br \/>\nOn March 3, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21385 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/march-2026-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 March<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-21385\">CISA KEV: CVE-2026-21385<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-march-2026-monthly-rollup-av26-190","alert_type":396,"serial_number":"AV26-190","subject":"other","moderation_state":"published","external_url":null},{"nid":7353,"title":"[Control systems] Mitsubishi Electric security advisory (AV26-191)","uuid":"8df2e21b-3725-4d2b-aa46-ba55f0033749","banner":null,"lang":"en","date_modified":"2026-03-03","date_modified_ts":"2026-03-03T15:27:32Z","date_created":"2026-03-03T15:14:34Z","summary":null,"body":["<article data-history-node-id=\"7353\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av26-191\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-191<br \/><strong>Date: <\/strong>March 3, 2026<\/p>\n\n<p>On March 2, 2026, Mitsubishi Electric published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>MELSEC iQ-F Series FX5-ENET\/IP Ethernet Module FX5-ENET\/IP\u00a0\u2013 all versions<\/li>\n\t<li>MELSEC iQ-F Series FX5-EIP EtherNet\/IP Module FX5-EIP\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitsubishielectric.com\/psirt\/vulnerability\/pdf\/2025-021_en.pdf\">Multiple denial-of-service (DoS) vulnerabilities in Ethernet function of MELSEC iQ-F Series EtherNet\/IP module and Ethernet module (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av26-191","alert_type":398,"serial_number":"AV26-191","subject":"other","moderation_state":"published","external_url":null},{"nid":7354,"title":"Samsung mobile security advisory (AV26-192)","uuid":"ab0baf53-de97-4129-8779-de914214d783","banner":null,"lang":"en","date_modified":"2026-03-03","date_modified_ts":"2026-03-03T15:37:11Z","date_created":"2026-03-03T15:30:41Z","summary":null,"body":["<article data-history-node-id=\"7354\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-192\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-192<br \/><strong>Date: <\/strong>March 3, 2026<\/p>\n\n<p>On March 3, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices\u00a0\u2013 versions prior to SMR-MAR-2026<\/li>\n<\/ul><p>The most recent security update resolves multiple identified vulnerabilities.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=03\">Samsung Security Updates<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-192","alert_type":396,"serial_number":"AV26-192","subject":"other","moderation_state":"published","external_url":null},{"nid":7355,"title":"Django security advisory (AV26-193)","uuid":"7a720179-4b2f-4165-9e2c-4ecb8d4cd555","banner":null,"lang":"en","date_modified":"2026-03-03","date_modified_ts":"2026-03-03T18:20:18Z","date_created":"2026-03-03T18:10:28Z","summary":null,"body":["<article data-history-node-id=\"7355\" about=\"\/en\/alerts-advisories\/django-security-advisory-av26-193\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-193<br \/><strong>Date: <\/strong>March 3, 2026<\/p>\n\n<p>On March 3, 2026, Django published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Django 4.2\u00a0\u2013 versions prior to 4.2.29<\/li>\n\t<li>Django 5.2\u00a0\u2013 versions prior to 5.2.12<\/li>\n\t<li>Django 6.0\u00a0\u2013 versions prior to 6.0.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.djangoproject.com\/weblog\/2026\/mar\/03\/security-releases\/\">Django Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/django-security-advisory-av26-193","alert_type":396,"serial_number":"AV26-193","subject":"other","moderation_state":"published","external_url":null},{"nid":7356,"title":"Google Chrome security advisory (AV26-194)","uuid":"07f42f3f-e3a9-45c5-92ea-4cbf5c0c892d","banner":null,"lang":"en","date_modified":"2026-03-04","date_modified_ts":"2026-03-04T14:11:47Z","date_created":"2026-03-04T14:03:13Z","summary":null,"body":["<article data-history-node-id=\"7356\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-194\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-194<br \/><strong>Date: <\/strong>March 4, 2026<\/p>\n\n<p>On March 3, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 145.0.7632.159\/160 (Windows\/Mac) and 145.0.7632.159 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-194","alert_type":396,"serial_number":"AV26-194","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7357,"title":"Tenable security advisory (AV26-195)","uuid":"381b60bf-1d68-4d22-901b-1933c94aca68","banner":null,"lang":"en","date_modified":"2026-03-04","date_modified_ts":"2026-03-04T14:19:12Z","date_created":"2026-03-04T14:12:51Z","summary":null,"body":["<article data-history-node-id=\"7357\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-195\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-195<br \/><strong>Date: <\/strong>March 4, 2026<\/p>\n\n<p>On March 3, 2026, Tenable published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Nessus Manager\u00a0\u2013 version 10.10.2 and prior<\/li>\n\t<li>Nessus Manager\u00a0\u2013 versions 10.11.0 to 10.11.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-08\">[R1] Nessus Manager Versions 10.10.3 and 10.11.3 Fix One Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-195","alert_type":396,"serial_number":"AV26-195","subject":"other","moderation_state":"published","external_url":null},{"nid":7358,"title":"HPE security advisory (AV26-196)","uuid":"20d3ba9c-9799-4af8-bfda-f42385c96915","banner":null,"lang":"en","date_modified":"2026-03-04","date_modified_ts":"2026-03-04T17:06:08Z","date_created":"2026-03-04T16:52:54Z","summary":null,"body":["<article data-history-node-id=\"7358\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-196\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-196<br \/><strong>Date: <\/strong>March 4, 2026<\/p>\n\n<p>On March 4, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05026en_us&amp;docLocale=en_US#hpesbnw05026-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW05026 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking Wireless Operating Systems (AOS-8 and AOS-10) for Mobility Conductors, Controllers, Gateways, and Access Points.<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-196","alert_type":396,"serial_number":"AV26-196","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7359,"title":"Cisco security advisory (AV26-197) \u2013 Update 3","uuid":"dfb8ead8-cb00-40c5-9b0b-d46b6dd255d9","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T20:04:27Z","date_created":"2026-03-04T19:24:53Z","summary":null,"body":["<article data-history-node-id=\"7359\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-197\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-197<br \/><strong>Date: <\/strong>March\u00a05, 2026<br \/><strong>Updated:<\/strong> September 9, 2026<\/p>\n\n<p>On March\u00a04, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Security Cloud Control (SCC) Firewall Management\u00a0\u2013 all versions<\/li>\n\t<li>Cisco Secure Firewall Management Center (FMC)\u00a0\u2013 all versions<\/li>\n\t<li>Cisco Secure Firewall Adaptive Security Appliance (ASA)\u00a0\u2013 versions prior to 9.20.4.14<\/li>\n\t<li>Cisco Secure Firewall Threat Defense (FTD)\u00a0\u2013 all versions<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On March\u00a018, 2026, Cisco stated that CVE-2026-20131 is being actively exploited.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 3<\/h2>\n\n<p>On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-onprem-fmc-authbypass-5JPp45V2\">Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-fmc-rce-NKhnULJh\">Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asa-dos-FCvLD6vR\">Cisco Secure Firewall Adaptive Security Appliance Software TCP Flood Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-esp-dos-uv7yD8P5\">Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20131\">CISA KEV: CVE-2026-20131<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20079\">CISA KEV: CVE-2026-20079<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-197","alert_type":396,"serial_number":"AV26-197","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7360,"title":"Drupal security advisory (AV26-198)","uuid":"0b905c52-03f4-43a8-b299-69fb8f7f4ddb","banner":null,"lang":"en","date_modified":"2026-03-04","date_modified_ts":"2026-03-04T20:12:25Z","date_created":"2026-03-04T19:42:58Z","summary":null,"body":["<article data-history-node-id=\"7360\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-198\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-198<br \/><strong>Date: <\/strong>March 4, 2026<\/p>\n\n<p>On March 4, 2026, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>File Access Fix (deprecated)\u00a0\u2013 versions prior to 1.2.0<\/li>\n<li>AJAX Dashboard\u00a0\u2013 versions prior to 3.1.0<\/li>\n<li>Calculation Fields\u00a0\u2013 versions prior to 1.0.4<\/li>\n<li>Google Analytics GA4\u00a0\u2013 versions prior to 1.1.13<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-021\">File Access Fix (deprecated)\u00a0- Moderately critical - Access bypass - SA-CONTRIB-2026-021<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-022\">AJAX Dashboard\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2026-022<\/a><\/li>\n  \t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-023\">Calculation Fields\u00a0- Moderately critical\u00a0- Cross-site Scripting - SA-CONTRIB-2026-023<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-024\">Google Analytics GA4\u00a0- Moderately critical\u00a0- Cross-site Scripting - SA-CONTRIB-2026-024<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-198","alert_type":396,"serial_number":"AV26-198","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7361,"title":"OpenText security advisory (AV26-199)","uuid":"445fb2ce-8da7-409a-86b1-40ae471cc677","banner":null,"lang":"en","date_modified":"2026-03-05","date_modified_ts":"2026-03-05T13:24:09Z","date_created":"2026-03-05T13:21:14Z","summary":null,"body":["<article data-history-node-id=\"7361\" about=\"\/en\/alerts-advisories\/opentext-security-advisory-av26-199\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-199<br \/><strong>Date: <\/strong>March 5, 2026<\/p>\n\n<p>On February 27, 2026, OpenText published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Filr \u2013 versions up to 25.1.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/portal.microfocus.com\/s\/article\/KM000045579?language=en_US\">Improper access control vulnerability has been discovered in OpenText Filr\u00a0- (CVE-2026-3266)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/opentext-security-advisory-av26-199","alert_type":396,"serial_number":"AV26-199","subject":"other","moderation_state":"published","external_url":null},{"nid":7362,"title":"IBM security advisory (AV26-200)","uuid":"a46172fa-974d-46f5-94a2-f40866e219b5","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T14:04:28Z","date_created":"2026-03-09T13:31:17Z","summary":null,"body":["<article data-history-node-id=\"7362\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-200\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-200<br \/><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>Between March 2 and 8, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cloudera Data Platform Private Cloud Base with IBM (CDP)\u00a0\u2013 version 7.1.9 and 7.3.1<\/li>\n\t<li>DS8A00 (R10.0-R10.1)\u00a0\u2013 versions 10.1.3.0 to 10.10.106.1<\/li>\n\t<li>DS8900F (R9.4)\u00a0\u2013 versions 89.40.83.0 to 89.44.5.0<\/li>\n\t<li>IBM API Connect\u00a0\u2013 versions V10.0.8.0 to 10.0.8.6<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\u00a0- multiple versions<\/li>\n\t<li>IBM App Connect Operator\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM DB2 Data Management Console\u00a0\u2013 versions 3.1.11 and 3.1.12<\/li>\n\t<li>IBM DevOps Build\u00a0\u2013 versions 7.0.0 to 7.1.0.1<\/li>\n\t<li>IBM Engineering Requirements Management DOORS and DOORS Web Access\u00a0\u2013 versions 9.7.2.1 to 9.7.2.10, versions 9.6.1.1 to 9.6.1.13<\/li>\n\t<li>IBM Observability with Instana (Agent)\u00a0\u2013 versions Build 1.0.301 to 1.0.312<\/li>\n\t<li>IBM Tivoli Netcool\/OMNIbus GUI\u00a0\u2013 version 8.1.0<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0\u2013 versions 1.4.0 to 2.4.0<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data\u00a0\u2013 multiple versions<\/li>\n\t<li>InfoSphere Data Architect\u00a0\u2013 versions 9.0.0 and 9.2.1<\/li>\n\t<li>UCB\u00a0- IBM UrbanCode Build\u00a0\u2013 versions 6.1.7 to 6.1.7.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-200","alert_type":396,"serial_number":"AV26-200","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7363,"title":"Red Hat security advisory (AV26-202)","uuid":"06050259-40b7-4644-8b11-1b9a09cc0174","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T14:41:02Z","date_created":"2026-03-09T13:55:58Z","summary":null,"body":["<article data-history-node-id=\"7363\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-202\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-202<br \/><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>Between March 2 and 8, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-202","alert_type":396,"serial_number":"AV26-202","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7364,"title":"Dell security advisory (AV26-203)","uuid":"623f4a79-43ff-4faf-851b-d114335e7f8d","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T14:42:15Z","date_created":"2026-03-09T14:14:28Z","summary":null,"body":["<article data-history-node-id=\"7364\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-203\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-203<br \/><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>Between March 2 and 8, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell NetWorker\u00a0\u2013 version 8.0.27<\/li>\n\t<li>Dell NetWorker\u00a0\u2013 versions prior to 17.0.4<\/li>\n\t<li>Dell PowerScale F210\/ F710\/F910\/PA110\u00a0\u2013 versions prior to 13.2.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000434554\/dsa-2026-100-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities\">DSA-2026-100: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000435907\/dsa-2026-101-security-update-for-dell-networker-runtime-environment-multiple-third-party-component-vulnerabilities\">DSA-2026-101: Security Update for Dell NetWorker Runtime Environment Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-203","alert_type":396,"serial_number":"AV26-203","subject":"dell","moderation_state":"published","external_url":null},{"nid":7365,"title":"Ubuntu security advisory (AV26-201)","uuid":"c0b5cacf-833c-459b-82d4-9b123f3e97aa","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T14:36:41Z","date_created":"2026-03-09T14:19:42Z","summary":null,"body":["<article data-history-node-id=\"7365\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-201\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-201<br \/><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>Between March 2 and 8, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices \">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-201","alert_type":396,"serial_number":"AV26-201","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7366,"title":"[Control systems] CISA ICS security advisories (AV26\u2013204)","uuid":"e27f627a-d418-42ea-8141-e68d8741c1e6","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T14:45:54Z","date_created":"2026-03-09T14:27:46Z","summary":null,"body":["<article data-history-node-id=\"7366\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-204\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-204<br \/><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>Between March 2 and 8, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Delta Electronics CNCSoft-G2\u00a0\u2013 versions prior to V2.1.0.39<\/li>\n\t<li>ePower epower.ie\u00a0\u2013 all versions<\/li>\n\t<li>Everon OCPP Backends api.everon.io\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Energy Relion REB500 Product\u00a0\u2013 version 8.3.3.0 and prior<\/li>\n\t<li>Hitachi Energy RTU500 Product\u00a0\u2013 multiple versions<\/li>\n\t<li>Labkotec LID-3300IP\u00a0\u2013 all versions<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F FX5-ENET\/IP Ethernet Module FX5-ENET\/IP\u00a0\u2013 version 1.106 and prior<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F FX5-EIP EtherNet\/IP Module FX5-EIP\u00a0\u2013 all versions<\/li>\n\t<li>Mobiliti e-mobi.hu\u00a0\u2013 all versions<\/li>\n\t<li>Portwell Engineering Toolkits\u00a0\u2013 version 4.8.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-204","alert_type":398,"serial_number":"AV26-204","subject":"ics","moderation_state":"published","external_url":null},{"nid":7367,"title":"[Control Systems] Moxa security advisory (AV26-205)","uuid":"37752976-a5f5-443b-a144-8d9f4a82f03c","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T15:31:46Z","date_created":"2026-03-09T15:07:46Z","summary":null,"body":["<article data-history-node-id=\"7367\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-205\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-205<\/p>\n\n<p class=\"mrgn-bttm-md\"><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>On March 9, 2026, Moxa published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>DA Series\u00a0\u2013 all BIOS versions<\/li>\n\t<li>DA-682C Series\u00a0\u2013 version BIOS v1.5 and prior<\/li>\n\t<li>DA-820C Series\u00a0\u2013 version BIOS v1.2 and earlier<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-256821-security-enhancement-intel%C2%AE-bios-firmware-dos-(intel-sa-00813) \">Security Enhancement: Intel\u00ae BIOS Firmware DoS (INTEL-SA-00813)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-256822-security-enhancement-intel%C2%AE-converged-security-management-engine-(csme)-active-management-technology-(amt)\">Security Enhancement: Intel\u00ae Converged Security Management Engine (CSME) Active Management Technology (AMT) Multiple Vulnerabilities (INTEL-SA-00391)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-256823-security-enhancement-intel%C2%AE-active-management-technology-(amt)-multiple-vulnerabilities-(intel-sa-00709)\">Security Enhancement: Intel\u00ae Active Management Technology (AMT) Multiple Vulnerabilities (INTEL-SA-00709)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-205","alert_type":398,"serial_number":"AV26-205","subject":"other","moderation_state":"published","external_url":null},{"nid":7368,"title":"Microsoft Edge security advisory (AV26-206)","uuid":"c54dc6e7-3f63-4f6d-b907-3643bc351207","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T15:42:09Z","date_created":"2026-03-09T15:37:29Z","summary":null,"body":["<article data-history-node-id=\"7368\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-206\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-206<br \/><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>On March 6, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft Edge Stable Channel<\/span>\u00a0\u2013 versions prior to 145.0.3800.97<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-6-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-206","alert_type":396,"serial_number":"AV26-206","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7369,"title":"Mozilla security advisory (AV26-207)","uuid":"0bc379b9-1bfb-46b5-8d9b-11723e0f57d1","banner":null,"lang":"en","date_modified":"2026-03-09","date_modified_ts":"2026-03-09T15:49:25Z","date_created":"2026-03-09T15:44:24Z","summary":null,"body":["<article data-history-node-id=\"7369\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-207\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-207<br \/><strong>Date: <\/strong>March 9, 2026<\/p>\n\n<p>On March 2, 2026, Mozilla published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Focus for iOS\u00a0\u2013 versions prior to 148.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-18\/\">Mozilla Foundation Security Advisory 2026-18<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-207","alert_type":396,"serial_number":"AV26-207","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7370,"title":"Kubernetes security advisory (AV26-208)","uuid":"e5432d42-e966-470e-b5d1-c8d313132ec1","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T15:35:26Z","date_created":"2026-03-10T15:25:54Z","summary":null,"body":["<article data-history-node-id=\"7370\" about=\"\/en\/alerts-advisories\/kubernetes-security-advisory-av26-208\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-208<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 9, 2026, Kubernetes published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Kubernetes ingress-nginx\u00a0\u2013 versions prior to 1.13.8<\/li>\n\t<li>Kubernetes ingress-nginx\u00a0\u2014 versions prior to 1.14.4<\/li>\n\t<li>Kubernetes ingress-nginx\u00a0\u2013 versions prior to 1.15.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.kubernetes.io\/t\/security-advisory-cve-2026-3288-ingress-nginx-rewrite-target-nginx-configuration-injection\/34289\">[Security Advisory] CVE-2026-3288: ingress-nginx rewrite-target nginx configuration injection<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/kubernetes-security-advisory-av26-208","alert_type":396,"serial_number":"AV26-208","subject":"other","moderation_state":"published","external_url":null},{"nid":7371,"title":" SAP security advisory \u2013 March 2026 monthly rollup (AV26-209)","uuid":"d27f8a33-2550-45dc-91f9-71ca599a121b","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T15:56:21Z","date_created":"2026-03-10T15:25:54Z","summary":null,"body":["<article data-history-node-id=\"7371\" about=\"\/en\/alerts-advisories\/sap-security-advisory-march-2026-monthly-rollup-av26-209\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-209<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, SAP published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP NetWeaver Enterprise Portal Administration\u00a0\u2013 version EP-RUNTIME 7.50<\/li>\n\t<li>SAP Quotation Management Insurance Application (FS-QUO)\u00a0\u2013 version FS-QUO 800<\/li>\n\t<li>SAP Supply Chain Management\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/me.sap.com\/notes\/3698553  \">[CVE-2019-17571] Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO)<\/a><\/li>\n\t<li><a href=\"https:\/\/me.sap.com\/notes\/3714585\">[CVE-2026-27685] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration<\/a><\/li>\n\t<li><a href=\"https:\/\/me.sap.com\/notes\/3719502\">[CVE-2026-27689] Denial of service (DOS) in SAP Supply Chain Management<\/a><\/li>\n\t<li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/march-2026.html\">SAP Security Patch Day\u00a0- March 2026<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-march-2026-monthly-rollup-av26-209","alert_type":396,"serial_number":"AV26-209","subject":"sap","moderation_state":"published","external_url":null},{"nid":7372,"title":" [Control systems] Schneider Electric security advisory (AV26-210) ","uuid":"c63de89d-435e-43df-8cd2-fdc5eeac1571","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T16:07:45Z","date_created":"2026-03-10T15:25:54Z","summary":null,"body":["<article data-history-node-id=\"7372\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-210\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-210<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure Foxboro DCS\u00a0\u2013 versions prior to CS8.1<\/li>\n\t<li>EcoStruxure Automation Expert\u00a0\u2013 versions prior to v25.0.1<\/li>\n\t<li>EcoStruxure IT Data Center Expert\u00a0\u2013 versions v9.0 and prior<\/li>\n\t<li>EcoStruxure Power Monitoring Expert (PME)\u00a0\u2013 versions 2022, 2023, 2023 R2, 2024 and 2024 R2<\/li>\n\t<li>EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module\u00a0\u2013 versions 2022 and 2024<\/li>\n\t<li>Modicon M241\/M251\u00a0\u2013 versions prior to 5.4.13.12<\/li>\n\t<li>Modicon M262\u00a0\u2013 versions prior to 5.4.10.12<\/li>\n\t<li>Modicon M258\/LM058\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Schneider Electric Security Notifications<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-210","alert_type":398,"serial_number":"AV26-210","subject":"se","moderation_state":"published","external_url":null},{"nid":7373,"title":"Mozilla security advisory (AV26-211)","uuid":"06ac087b-789e-42b3-8593-2b896c07c6c2","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T17:59:03Z","date_created":"2026-03-10T17:49:10Z","summary":null,"body":["<article data-history-node-id=\"7373\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-211\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-211<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, Mozilla published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 148.0.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-19\/\">Security Vulnerabilities fixed in Firefox 148.0.2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-211","alert_type":396,"serial_number":"AV26-211","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7374,"title":"[Control systems] Siemens security advisory (AV26-212) ","uuid":"da6bc236-abc8-436b-a545-9fe984e2d679","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T18:13:32Z","date_created":"2026-03-10T18:04:40Z","summary":null,"body":["<article data-history-node-id=\"7374\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-212\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-212<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, Siemens published advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Heliox Flex 180 kW EV Charging Station\u00a0\u2013 versions prior to F4.11.1<\/li>\n\t<li>Heliox Mobile DC 40 kW EV Charging Station\u00a0\u2013 versions prior to L4.10.1<\/li>\n\t<li>Mendix Applications\u00a0\u2013 all versions<\/li>\n\t<li>RUGGEDCOM APE1808\u00a0\u2013 all versions with Fortigate NGFW prior to V7.4.11<\/li>\n\t<li>RUGGEDCOM APE1808\u00a0\u2013 all versions with Fortigate NGFW prior to V7.4.10<\/li>\n\t<li>SIDIS Prime\u00a0\u2013 versions prior to V4.0.800<\/li>\n\t<li>SICAM SIAPP SDK\u00a0\u2013 versions prior to V2.1.7<\/li>\n\t<li>SIMATIC S7-1500\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-212","alert_type":398,"serial_number":"AV26-212","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7375,"title":"Microsoft security advisory \u2013 March 2026 monthly rollup (AV26-213)","uuid":"3dea9c08-639b-4745-95e8-3aa33e6311e7","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T19:50:19Z","date_created":"2026-03-10T18:45:13Z","summary":null,"body":["<article data-history-node-id=\"7375\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-march-2026-monthly-rollup-av26-213\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-213<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>ASP.NET Core 10.0<\/li>\n\t<li>ASP.NET Core 8.0<\/li>\n\t<li>ASP.NET Core 9.0<\/li>\n\t<li>.NET 10.0<\/li>\n\t<li>.NET 9.0<\/li>\n\t<li>Azure AD SSH Login extension for Linux<\/li>\n\t<li>Azure Automation Hybrid Worker Windows Extension<\/li>\n\t<li>Azure ARC Enabled Servers\u00a0\u2013 Azure Connected Machine Agent<\/li>\n\t<li>Azure IoT Explorer<\/li>\n\t<li>Azure Linux Virtual Machines with Azure Diagnostics extension<\/li>\n\t<li>Azure MCP Server Tools<\/li>\n\t<li>Azure Windows Extension<\/li>\n\t<li>GitHub Repo: Zero Shot scFoundation<\/li>\n\t<li>Microsoft 365<\/li>\n\t<li>Microsoft ACI Confidential Containers<\/li>\n\t<li>Microsoft Authenticator for Android<\/li>\n\t<li>Microsoft Authenticator for IOS<\/li>\n\t<li>Microsoft.Bcl.Memory 10.0<\/li>\n\t<li>Microsoft.Bcl.Memory 9.0<\/li>\n\t<li>Microsoft Devices Pricing Program<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for MAC 2021<\/li>\n\t<li>Microsoft Office LTSC for MAC 2024<\/li>\n\t<li>Microsoft Office Online Server<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft SQL Server 2025, 2022, 2019, 2017 and 2016<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Payment Orchestrator Service<\/li>\n\t<li>System Center Operations Manager 2019, 2022 and 2025<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Admin Center in Azure Portal<\/li>\n\t<li>Windows App Client for Windows Desktop<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Mar\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">March<\/span> 2026 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Security Updates<\/span><\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Security Update Guide<\/span><\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-march-2026-monthly-rollup-av26-213","alert_type":396,"serial_number":"AV26-213","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7376,"title":"Ivanti security advisory (AV26-214)","uuid":"07650237-94a5-4c08-baf0-0ee95126f79c","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T20:08:12Z","date_created":"2026-03-10T20:03:03Z","summary":null,"body":["<article data-history-node-id=\"7376\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-214\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-214<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, Ivanti published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ivanti Desktop and Server Management<\/span> (DSM)\u00a0\u2013 version DSM 2026.1 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-DSM-CVE-2026-3483?language=en_US\">Security Advisory Ivanti DSM (CVE-2026-3483)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-214","alert_type":396,"serial_number":"AV26-214","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7377,"title":"Adobe security advisory (AV26-215)","uuid":"05e7da3d-4966-4858-b428-ccc9dbfeb4eb","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T20:41:27Z","date_created":"2026-03-10T20:37:48Z","summary":null,"body":["<article data-history-node-id=\"7377\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-215\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-215<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Commerce B2B\u00a0\u2013 multiple versions<\/li>\n\t<li>Magento Open Source\u00a0- multiple versions<\/li>\n\t<li>Illustrator 2025\u00a0\u2013 version 29.8.4 and prior<\/li>\n\t<li>Illustrator 2025\u00a0\u2013 version 30.1 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 11.1.2 and prior<\/li>\n\t<li>Acrobat DC\u00a0\u2013 version 25.001.21265 and prior<\/li>\n\t<li>Acrobat Reader DC\u00a0\u2013 version 25.001.21265 and prior<\/li>\n\t<li>Acrobat 2024 (Win)\u00a0\u2013 version 24.001.30307 and prior<\/li>\n\t<li>Acrobat 2024 (Mac)\u00a0\u2013 version 24.001.30308 and prior<\/li>\n\t<li>Adobe Premiere Pro\u00a0\u2013 version 25.5 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 version AEM Cloud Service (CS)<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 versions 6.5 LTS SP1 and 6.5.SP23 and prior<\/li>\n\t<li>Adobe Substance 3D Stager\u00a0\u2013 version 3.1.7 and prior<\/li>\n\t<li>Adobe DNG Software Development Kit (SDK)\u00a0\u2013 version DNG SDK 1.7.1 build 2471 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-215","alert_type":396,"serial_number":"AV26-215","subject":"other","moderation_state":"published","external_url":null},{"nid":7378,"title":"Fortinet security advisory (AV26-216)","uuid":"545e9f74-f451-487d-8df5-31496640fb73","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T20:51:06Z","date_created":"2026-03-10T20:46:17Z","summary":null,"body":["<article data-history-node-id=\"7378\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-216\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-216<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 10, 2026, Fortinet published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FortiClientLinux 7.4\u00a0\u2013 versions 7.4.0 to 7.4.4<\/li>\n\t<li>FortiClientLinux 7.2\u00a0\u2013 versions 7.2.2 to 7.2.12<\/li>\n\t<li>FortiManager 7.4\u00a0\u2013 versions 7.4.0 to 7.4.2<\/li>\n\t<li>FortiManager 7.2\u00a0\u2013 versions 7.2.0 to 7.2.10<\/li>\n\t<li>FortiManager 6.4\u00a0\u2013 all versions<\/li>\n\t<li>FortiSwitchAXFixed 1.0\u00a0\u2013 versions 1.0.0 to 1.0.1<\/li>\n\t<li>FortiWeb 8.0\u00a0\u2013 versions 8.0.0 to 8.0.2<\/li>\n\t<li>FortiWeb 7.6\u00a0\u2013 versions 7.6.0 to 7.6.5<\/li>\n\t<li>FortiWeb 7.4\u00a0\u2013 versions 7.4.0 to 7.4.10<\/li>\n\t<li>FortiWeb 7.2\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiWeb 7.0\u00a0\u2013 versions 7.0.0 to 7.0.11<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-216","alert_type":396,"serial_number":"AV26-216","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7379,"title":"HPE security advisory (AV26-217)","uuid":"688cdd0e-eee0-4675-922a-9195ee413888","banner":null,"lang":"en","date_modified":"2026-03-10","date_modified_ts":"2026-03-10T20:56:39Z","date_created":"2026-03-10T20:52:26Z","summary":null,"body":["<article data-history-node-id=\"7379\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-217\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-217<br \/><strong>Date: <\/strong>March 10, 2026<\/p>\n\n<p>On March 9, 2026, HPE published security advisories to address vulnerabilities in the following products. Included was a critical update for the following:<\/p>\n\n<ul><li>HPE Aruba Networking AOS-CX\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Telco Intelligent Assurance\u00a0\u2013 versions prior to FAS 4.2.14<\/li>\n\t<li>HPE Telco Intelligent Assurance\u00a0\u2013 versions prior to PDO 4.2.14<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05027en_us&amp;docLocale=en_US\">HPESBNW05027 rev.1\u00a0- HPE Aruba Networking AOS-CX, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05022en_us&amp;docLocale=en_US\">HPESBNW05022 rev.1\u00a0- HPE Telco Intelligent Assurance, Improper Control of Generation of Code vulnerability (AOS-8 and AOS-10) for Mobility Conductors, Controllers, Gateways, and Access Points.<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-217","alert_type":396,"serial_number":"AV26-217","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7380,"title":"Google Chrome security advisory (AV26-220)","uuid":"a5a8c69b-09d8-4e59-802c-015a3e6e9547","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T17:31:14Z","date_created":"2026-03-11T14:30:33Z","summary":null,"body":["<article data-history-node-id=\"7380\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-220\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-220<br \/><strong>Date: <\/strong>March 11, 2026<\/p>\n\n<p>On March 10, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 146.0.7680.71\/72 (Windows\/Mac) and 146.0.7680.71 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_10.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-220","alert_type":396,"serial_number":"AV26-220","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7381,"title":"VMware security advisory (AV26-221)","uuid":"3e9e174e-61d8-412b-b1a9-8011aecbb667","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T17:32:21Z","date_created":"2026-03-11T14:43:43Z","summary":null,"body":["<article data-history-node-id=\"7381\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-221\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-221<br \/><strong>Date: <\/strong>March 11, 2026<\/p>\n\n<p>On March 11, 2026, VMware published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu Valkey on Kubernetes\u00a0\u2013 version 3.3.2<\/li>\n\t<li>VMware Tanzu Valkey\u00a0\u2013 version 7.2.11<\/li>\n\t<li>VMware Tanzu Valkey\u00a0\u2013 version 8.0.6<\/li>\n\t<li>VMware Tanzu Valkey\u00a0\u2013 version 8.1.5<\/li>\n\t<li>VMware Tanzu Valkey\u00a0\u2013 version 9.0.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-221","alert_type":396,"serial_number":"AV26-221","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7382,"title":"[Control systems] Hitachi security advisory (AV26-218)","uuid":"0f130647-b487-4937-a52d-1341c55a4f56","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T17:21:24Z","date_created":"2026-03-11T17:15:29Z","summary":null,"body":["<article data-history-node-id=\"7382\" about=\"\/en\/alerts-advisories\/control-systems-hitachi-security-advisory-av26-218\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-218<br \/><strong>Date: <\/strong>March\u00a011, 2026<\/p>\n\n<p>On March\u00a010, 2026, Hitachi published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Hitachi Device Manager (Windows\/Linux)\u00a0\u2013 versions prior to 8.8.8-02<\/li>\n\t<li>Hitachi Tuning Manager (Windows\/Linux)\u00a0\u2013 versions prior to 8.8.8-02<\/li>\n\t<li>Hitachi Compute Systems Manager (Windows\/Linux)\u00a0\u2013 versions prior to 8.8.8-01<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-112\/index.html\">Vulnerability in Hitachi Command Suite\u00a0- hitachi-sec-2026-112 (CVE-2025-48976)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-hitachi-security-advisory-av26-218","alert_type":398,"serial_number":"AV26-218","subject":"other","moderation_state":"published","external_url":null},{"nid":7383,"title":"Intel security advisory (AV26-219)","uuid":"d146c9fd-d594-4340-8bec-df3d05a0dcda","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T17:26:23Z","date_created":"2026-03-11T17:15:29Z","summary":null,"body":["<article data-history-node-id=\"7383\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av26-219\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-219<br \/><strong>Date: <\/strong>March\u00a011, 2026<\/p>\n\n<p>On March\u00a010, 2026, Intel published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html \">Intel Product Security Center Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av26-219","alert_type":396,"serial_number":"AV26-219","subject":"intel","moderation_state":"published","external_url":null},{"nid":7384,"title":"GitLab security advisory (AV26-222)","uuid":"c1cc7fb2-a546-4050-944b-53225d010813","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T19:42:38Z","date_created":"2026-03-11T19:35:48Z","summary":null,"body":["<article data-history-node-id=\"7384\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-222\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-222<br \/><strong>Date: <\/strong>March 11, 2026<\/p>\n\n<p>On March 11, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.9.2, 18.8.6 and 18.7.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.9.2, 18.8.6 and 18.7.6<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/03\/11\/patch-release-gitlab-18-9-2-released\/\">GitLab Patch Release: 18.9.2, 18.8.6, 18.7.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-222","alert_type":396,"serial_number":"AV26-222","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7385,"title":"Cisco security advisory (AV26-223)","uuid":"b28ee110-8fc2-450c-9fd6-177e2f5f4bf3","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T20:00:23Z","date_created":"2026-03-11T19:49:29Z","summary":null,"body":["<article data-history-node-id=\"7385\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-223\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-223<br \/><strong>Date: <\/strong>March 11, 2026<\/p>\n\n<p>On March 11, 2026, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco NCS 5700 Series line cards\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco NCS 5700 Series Fixed Chassis\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco IOS XR Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Unified Intelligence Center\u00a0\u2013 all versions<\/li>\n\t<li>Cisco Finesse\u00a0\u2013 all versions<\/li>\n\t<li>Cisco Packaged CCE\u00a0\u2013 all versions<\/li>\n\t<li>Cisco Unified CCE\u00a0\u2013 all versions<\/li>\n\t<li>Cisco Unified CCX\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-xrncs-epni-int-dos-TWMffUsN\">Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-isis-dos-kDMxpSzK\">Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxr-privesc-bF8D5U4W\">Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cc-xss-MrNAH5Jh\">Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-223","alert_type":396,"serial_number":"AV26-223","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7386,"title":"HPE security advisory (AV26-224)","uuid":"bd54c6ac-00e3-4825-a98a-6fd0d890a5a4","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T20:10:12Z","date_created":"2026-03-11T20:02:27Z","summary":null,"body":["<article data-history-node-id=\"7386\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-224\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-224<br \/><strong>Date: <\/strong>March 11, 2026<\/p>\n\n<p>On March 11, 2026, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE ProLiant DL\/ML\/XD\/XL Servers\u00a0\u2013 multiple versions<\/li>\n<li>HPE Alletra Servers\u00a0\u2013 multiple versions<\/li>\n<li>HPE Apollo Servers\u00a0\u2013 multiple versions<\/li>\n<li>HPE Synergy Servers\u00a0\u2013 multiple versions<\/li>\n<li>HPE Microserver Servers\u00a0\u2013 multiple versions<\/li>\n<li>HPE Edgeline Servers\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf05028en_us&amp;docLocale=en_US\">HPESBHF05028 rev.1\u00a0- Certain HPE ProLiant DL\/ML\/XD\/XL, Alletra, Apollo, Synergy, Microserver and Edgeline Servers Using Certain Intel Processor BIOS, INTEL-SA-01234, 2025.3 IPU, UEFI Reference Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-224","alert_type":396,"serial_number":"AV26-224","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7387,"title":"Drupal security advisory (AV26-225)","uuid":"734cdbc6-c05e-4c95-b7d6-89057fbf6938","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T20:18:33Z","date_created":"2026-03-11T20:11:42Z","summary":null,"body":["<article data-history-node-id=\"7387\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-225\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-225<br \/><strong>Date: <\/strong>March 11, 2026<\/p>\n\n\n<p>On March 11, 2026, Drupal published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Unpublished Node Permissions\u00a0\u2013 versions prior to 1.7.0<\/li>\n<li>AI (Artificial Intelligence)\u00a0\u2013 versions prior to 1.1.11 and 1.2.x versions prior to 1.2.12<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-029\">Unpublished Node Permissions\u00a0- Critical\u00a0- Access bypass\u00a0- SA-CONTRIB-2026-029 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-028\">AI (Artificial Intelligence)\u00a0- Moderately critical\u00a0- Information Disclosure\u00a0- SA-CONTRIB-2026-028 <\/a><\/li>\n  \t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-225","alert_type":396,"serial_number":"AV26-225","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7388,"title":"JetBrains security advisory (AV26-226)","uuid":"44723c22-ace1-4a1d-a20e-b711140d2468","banner":null,"lang":"en","date_modified":"2026-03-11","date_modified_ts":"2026-03-11T20:29:48Z","date_created":"2026-03-11T20:26:08Z","summary":null,"body":["<article data-history-node-id=\"7388\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-226\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-226<br \/><strong>Date: <\/strong>March 11, 2026<\/p>\n\n<p>On March 11, 2026, JetBrains published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>JetBrains Hub\u00a0\u2013 versions prior to 2026.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-226","alert_type":396,"serial_number":"AV26-226","subject":"other","moderation_state":"published","external_url":null},{"nid":7389,"title":"Splunk security advisory (AV26-227)","uuid":"66dddd34-bec0-4e62-a320-f9e01d44f264","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T12:58:21Z","date_created":"2026-03-12T12:39:20Z","summary":null,"body":["<article data-history-node-id=\"7389\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-227\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-227<br \/><strong>Date: <\/strong>March 12, 2026<\/p>\n\n<p>On March 11, 2026, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk Enterprise\u00a0\u2013 multiple versions<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 multiple versions<\/li>\n\t<li>Splunk AppDynamics On-Premises Enterprise Console\u00a0\u2013 versions prior to 26.1.1<\/li>\n\t<li>Splunk AppDynamics Machine Agent\u00a0\u2013 versions prior to 26.1.0<\/li>\n\t<li>Splunk AppDynamics Private Synthetic Agent\u00a0\u2013 versions prior to 26.1.0<\/li>\n\t<li>Splunk AppDynamics Java Agent\u00a0\u2013 versions prior to 26.1.0<\/li>\n\t<li>Splunk AppDynamics NodeJS Agent\u00a0\u2013 versions prior to 25.12.1<\/li>\n\t<li>Splunk AppDynamics Database Agent\u00a0\u2013 versions prior to 26.1.0<\/li>\n\t<li>Splunk AppDynamics Analytics Agent\u00a0\u2013 versions prior to 26.1.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-227","alert_type":396,"serial_number":"AV26-227","subject":"other","moderation_state":"published","external_url":null},{"nid":7391,"title":"Palo Alto Networks security advisory (AV26-228)","uuid":"18008279-7784-41b1-9bb0-ae237f80dbef","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T16:08:38Z","date_created":"2026-03-12T15:52:09Z","summary":null,"body":["<article data-history-node-id=\"7391\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-228\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-228<br \/><strong>Date: <\/strong>March 12, 2026<\/p>\n\n<p>On March 11, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cortex XDR Broker VM 30.0.0\u00a0\u2013 versions prior to 30.0.49<\/li>\n\t<li>Cortex XDR Agent 8.7-CE\u00a0\u2013 versions prior to 8.7.101-CE on macOS<\/li>\n\t<li>Cortex XDR Agent 8.3-CE\u00a0\u2013 versions prior to 8.3.102-CE on macOS<\/li>\n\t<li>Prisma Browser\u00a0\u2013 versions prior to 145.7.9.76<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0231 \">CVE-2026-0231 Cortex XDR Broker VM: Sensitive Information Disclosure Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0230 \">CVE-2026-0230 Cortex XDR Agent: Local Administrator can disable the agent on macOS <\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2026-0003\">PAN-SA-2026-0003 Chromium: Monthly Vulnerability Update (March 2026) <\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-228","alert_type":396,"serial_number":"AV26-228","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7392,"title":"Veeam security advisory (AV26-229)","uuid":"93a586ab-7486-4f9f-8f79-14bc7d222d08","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T16:28:27Z","date_created":"2026-03-12T16:23:22Z","summary":null,"body":["<article data-history-node-id=\"7392\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-229\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-229<\/p>\n\n<p class=\"mrgn-bttm-md\"><strong>Date: <\/strong>March 12, 2026<\/p>\n\n<p>On March 12, 2026, Veeam published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2013 12 versions prior to 12.3.2.4165<\/li>\n\t<li>Veeam Backup &amp; Replication\u00a0\u2013 13 versions prior to 13.0.1.2067<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4830 \">Vulnerabilities Resolved in Veeam Backup &amp; Replication 12.3.2.4465<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4831\">Vulnerabilities Resolved in Veeam Backup &amp; Replication 13.0.1.2067<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-229","alert_type":396,"serial_number":"AV26-229","subject":"other","moderation_state":"published","external_url":null},{"nid":7393,"title":"GitHub security advisory (AV26-230)","uuid":"67eceae4-b158-4ef7-8ef2-629d536a0df6","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T17:35:21Z","date_created":"2026-03-12T17:18:45Z","summary":null,"body":["<article data-history-node-id=\"7393\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-230\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-230<br \/><strong>Date:<\/strong> March\u00a012, 2026<\/p>\n\n<p>On March\u00a010, 2026, GitHub published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.3<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.6<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.12<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.15<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.15.x prior to 3.15.19<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.14.x prior to 3.14.24<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.3<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.6<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.12<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.15<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.15\/admin\/release-notes\">Enterprise Server 3.15.19<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.14\/admin\/release-notes\">Enterprise Server 3.14.24<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-230","alert_type":396,"serial_number":"AV26-230","subject":"other","moderation_state":"published","external_url":null},{"nid":7394,"title":"Zoom security advisory (AV26-231)","uuid":"52ca161d-02c8-48d0-a243-e018e6c562ec","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T17:44:51Z","date_created":"2026-03-12T17:18:46Z","summary":null,"body":["<article data-history-node-id=\"7394\" about=\"\/en\/alerts-advisories\/zoom-security-advisory-av26-231\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-231<br \/><strong>Date:<\/strong> March\u00a012, 2026<\/p>\n\n<p>On March\u00a010, 2026, Zoom published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Zoom Meeting SDK for Windows\u00a0\u2013 versions prior to 6.6.11<\/li>\n\t<li>Zoom Rooms for Windows\u00a0\u2013 versions prior to 6.6.5<\/li>\n\t<li>Zoom Workplace for Windows\u00a0\u2013 versions prior to 6.6.11<\/li>\n\t<li>Zoom Workplace VDI Client for Windows\u00a0\u2013 versions prior to 6.4.17, 6.5.15 and 6.6.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26005\/\">Zoom Workplace for Windows\u00a0- External Control of File Name or Path<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26004\/\">Zoom Clients for Windows\u00a0- Improper Privilege Management<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26003\/\">Zoom Rooms for Windows\u00a0- Improper Input Validation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26002\/\">Zoom Workplace Clients for Windows\u00a0- Improper Check<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/\">Zoom Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zoom-security-advisory-av26-231","alert_type":396,"serial_number":"AV26-231","subject":"other","moderation_state":"published","external_url":null},{"nid":7395,"title":"[Control systems] ABB security advisory (AV26-232)","uuid":"506931ea-80c0-4f10-a487-bb6f3e2758cc","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T17:53:44Z","date_created":"2026-03-12T17:18:47Z","summary":null,"body":["<article data-history-node-id=\"7395\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-232\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-232<br \/><strong>Date: <\/strong>March\u00a012, 2026<\/p>\n\n<p>On March\u00a012, 2026, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>AC500 V3\u00a0\u2013 firmware version 3.9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=3ADR011536&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">AC500 V3 Stack buffer overflow in Cryptographic Message Syntax (CVE-2025-15467) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-232","alert_type":398,"serial_number":"AV26-232","subject":"abb","moderation_state":"published","external_url":null},{"nid":7396,"title":"Apple security advisory (AV26-233)","uuid":"fbdc916a-6595-4247-b3b8-9034e154ef27","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T18:58:35Z","date_created":"2026-03-12T18:51:24Z","summary":null,"body":["<article data-history-node-id=\"7396\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-233\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-233<br \/><strong>Date: <\/strong>March 12, 2026<\/p>\n\n<p>On March 11, 2026, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 16.7.15<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 16.7.15<\/li>\n\t<li>iOS\u00a0\u2013 versions prior to 15.8.7<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 15.8.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-233","alert_type":396,"serial_number":"AV26-233","subject":"apple","moderation_state":"published","external_url":null},{"nid":7397,"title":"HPE security advisory (AV26-234)","uuid":"18d26df2-2669-4eb7-a464-cc7372765c04","banner":null,"lang":"en","date_modified":"2026-03-12","date_modified_ts":"2026-03-12T19:16:53Z","date_created":"2026-03-12T19:07:02Z","summary":null,"body":["<article data-history-node-id=\"7397\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-234\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-234<br \/><strong>Date: <\/strong>March 12, 2026<\/p>\n\n<p>On March 12, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Compute Scale-up Server 3200\u00a0\u2013 versions prior to v1.70.74<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf05024en_us&amp;docLocale=en_US\">HPESBHF05024 rev.1\u00a0- HPE Compute Scale-up Server 3200 Platform Using Certain Intel Processors, INTEL-SA-01396, 2026.1 IPU, Intel Processor Firmware Advisory, Local Escalation of Privilege Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US \">HPE Security Bulletin Library <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-234","alert_type":396,"serial_number":"AV26-234","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7398,"title":"Google Chrome security advisory (AV26-235) \u2013 Update 1","uuid":"8ec412dd-3189-43fe-adbe-f514889ff603","banner":null,"lang":"en","date_modified":"2026-03-13","date_modified_ts":"2026-03-13T18:55:20Z","date_created":"2026-03-13T13:11:47Z","summary":null,"body":["<article data-history-node-id=\"7398\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-235\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-235<br \/><strong>Date: <\/strong>March\u00a013, 2026<br \/><strong>Updated:<\/strong> March\u00a013, 2026<\/p>\n\n<p>On March\u00a012, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 146.0.7680.75\/76 (Windows\/Mac) and 146.0.7680.75 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">Google is aware that an exploit for CVE-2026-3910 exists in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On March\u00a013, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-3910 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-3910 \">CISA KEV: CVE-2026-3910<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-235","alert_type":396,"serial_number":"AV26-235","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7399,"title":"[Control systems] ABB security advisory (AV26-236)","uuid":"1483f4ee-8c1d-4216-b355-aec04176ecc1","banner":null,"lang":"en","date_modified":"2026-03-13","date_modified_ts":"2026-03-13T17:47:37Z","date_created":"2026-03-13T17:21:29Z","summary":null,"body":["<article data-history-node-id=\"7399\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-236\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p class=\"mrgn-bttm-md\"><strong>Serial number: <\/strong>AV26-236<br \/><strong>Date: <\/strong>March\u00a013, 2026<\/p>\n\n<p>On March\u00a011, 2026, ABB published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AWIN GW100 rev.2\u00a0\u2013 versions 2.0-0 to 2.0-1<\/li>\n\t<li>AWIN GW120\u00a0\u2013 versions 1.2-0 to 1.2-1.<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=4JNO000329&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">AWIN Gateways Vulnerabilities in Embedded Webserver (CVE-2025-13777, CVE-2025-13778, CVE-2025-13779) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-236","alert_type":398,"serial_number":"AV26-236","subject":"abb","moderation_state":"published","external_url":null},{"nid":7400,"title":"IBM security advisory (AV26-237)","uuid":"4b440cf3-ca37-4e1c-aec6-38bdba1f3d13","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T14:00:37Z","date_created":"2026-03-16T13:52:32Z","summary":null,"body":["<article data-history-node-id=\"7400\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-237\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-237<br \/><strong>Date:<\/strong> March\u00a016, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between March\u00a09 and 15, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cloudera Data Platform Private Cloud Base with IBM (CDP)\u00a0\u2013 version 7.1.9<\/li>\n\t<li>Cloudera Data Platform Private Cloud Base with IBM (CDP)\u00a0\u2013 version 7.3.1<\/li>\n\t<li>ELM on Hybrid Cloud\u00a0\u2013 versions 1.2.0, 1.1.0 and 1.0.0<\/li>\n\t<li>IBM AIX\u00a0\u2013 versions 7.2 and 7.3<\/li>\n\t<li>IBM CICS Transaction Gateway Desktop Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM CICS Transaction Gateway for Multiplatforms\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Security\u00a0\u2013 versions 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Knowledge Catalog Premium Cartridge\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Library Support for Struts\u00a0\u2013 version 1.2<\/li>\n\t<li>IBM MQ (LTS\/CD)\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Maximo Application Suite - Visual Inspection Component\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Observability with Instana (Agent)\u00a0\u2013 versions Build 1.0.303 to 1.0.313<\/li>\n\t<li>IBM Security SOAR\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Security Verify Directory (Container)\u00a0\u2013 versions 10.0.0 to 10.0.4<\/li>\n\t<li>IBM Sterling Connect:Direct File Agent\u00a0\u2013 versions 1.4.0.3 to 1.4.0.5_iFix005 with bundled JRE on AIX, Linux x64, Linux PPC and Windows<\/li>\n\t<li>IBM Sterling Connect:Direct for Microsoft Windows\u00a0\u2013 versions 6.3.0.3 to 6.3.0.6_iFix038<\/li>\n\t<li>IBM Sterling Connect:Direct for Microsoft Windows\u00a0\u2013 versions 6.4.0.0 to 6.4.0.4_iFix009<\/li>\n\t<li>IBM Sterling Partner Engagement Manager (Essentials Edition\/Standard Edition)\u00a0\u2013 versions 6.2.3.0 to 6.2.3.5, versions 6.2.4.0 to 6.2.4.2<\/li>\n\t<li>IBM Verify Directory (Container)\u00a0\u2013 version 11.0.0.0<\/li>\n\t<li>IBM Verify Identity Governance (ISVG)\u00a0\u2013 version ISVG 10.0.2<\/li>\n\t<li>IBM Verify Identity Governance (IVIG)\u00a0\u2013 version IVIG 11.0.0<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.8.4 to 4.8.5<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 5.0.0 to 5.3<\/li>\n\t<li>IBM watsonx Orchestrate with watsonx Assistant Cartridge\u00a0\u2013 UAB Component\u00a0\u2013 versions 5.1.0 to 5.2.1<\/li>\n\t<li>IBM\u00a0\u2013 VIOS versions 3.1 and 4.1<\/li>\n\t<li>QRadar Suite Software\u00a0\u2013 versions 1.10.12.0 to 1.11.8.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-237","alert_type":396,"serial_number":"AV26-237","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7401,"title":"Dell security advisory (AV26-238)","uuid":"7904b13c-5a7f-441d-9fe5-cada08910a23","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T14:08:49Z","date_created":"2026-03-16T13:52:32Z","summary":null,"body":["<article data-history-node-id=\"7401\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-238\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-238<br \/><strong>Date:<\/strong> March\u00a016, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between March\u00a09 and 15, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Avamar Data Store Gen5A\u00a0\u2013 versions prior to 2.25.0 and 24.0.0<\/li>\n\t<li>Dell Connectrix B-Series FOS and SANnav\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell Connectrix B-Series SANnav\u00a0\u2013 versions prior to 2.4.0a and 3.0.0<\/li>\n\t<li>PowerSwitch E3200-ON Series\u00a0\u2013 versions prior to 3.57.5.1-6<\/li>\n\t<li>PowerSwitch Z9664F-ON\u00a0\u2013 versions prior to 3.54.5.1-11<\/li>\n\t<li>Secure Connect Gateway-Appliance\u00a0\u2013 versions between v5.28.00.00 and v5.32.00.00<\/li>\n\t<li>Secure Connect Gateway-Application\u00a0\u2013 versions between v5.28.00.00 and v5.32.00.00<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-238","alert_type":396,"serial_number":"AV26-238","subject":"dell","moderation_state":"published","external_url":null},{"nid":7402,"title":"Ubuntu security advisory (AV26-239)","uuid":"989e6d1a-15e1-4ff6-9e06-283ff6c6fa58","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T15:10:57Z","date_created":"2026-03-16T14:56:08Z","summary":null,"body":["<article data-history-node-id=\"7402\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-239\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-239<br \/><strong>Date: <\/strong>March 16, 2026<\/p>\n\n\n<p>Between March 9 and 15, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8060-7\">USN-8060-7: Linux kernel (NVIDIA) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8059-8\">USN-8059-8: Linux kernel (NVIDIA) vulnerabilities<\/a><\/li>\n  \t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-239","alert_type":396,"serial_number":"AV26-239","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7403,"title":"Google Chrome security advisory (AV26-240)","uuid":"755826a4-e1ef-4ffd-86e6-785339f977df","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T15:31:33Z","date_created":"2026-03-16T15:12:14Z","summary":null,"body":["<article data-history-node-id=\"7403\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-240\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-240<br \/><strong>Date: <\/strong>March 16, 2026<\/p>\n\n<p>On March 13, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Stable Channel Chrome for Desktop<\/span>\u00a0\u2013 versions prior to 146.0.7680.80 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">(Windows\/Mac)<\/span> and 146.0.7680.80 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">(Linux)<\/span><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">On March 13, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-3909 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n  \n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_13.html\">Google Chrome Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-3909\">CISA KEV: CVE-2026-3909<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-240","alert_type":396,"serial_number":"AV26-240","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7404,"title":"[Control systems] CISA ICS security advisories (AV26\u2013241) \u2013 Update 1","uuid":"0aa58cec-9c85-46de-acb6-c369c743d500","banner":null,"lang":"en","date_modified":"2026-06-23","date_modified_ts":"2026-06-23T20:23:46Z","date_created":"2026-03-16T16:08:14Z","summary":null,"body":["<article data-history-node-id=\"7404\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-241\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-241<br \/><strong>Date: <\/strong>March 16, 2026<br \/><strong>Updated:<\/strong> June 23, 2026<\/p>\n\n<p>Between March 9 and 15, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apeman Cameras ID71\u00a0\u2013 all versions<\/li>\n\t<li>Ceragon Siklu MultiHaul and EtherHaul Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Honeywell IQ4x BMS Controller\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Inductive Automation Ignition Software\u00a0\u2013 versions prior to 8.3.0<\/li>\n\t<li>Lantronix EDS3000PS\u00a0\u2013 version 3.1.0.0R2<\/li>\n\t<li>Lantronix EDS5000\u00a0\u2013 version 2.1.0.0R3<\/li>\n\t<li>Siemens Heliox EV Chargers\u00a0\u2013 version Heliox Mobile DC 40 kW EV Charging Station<\/li>\n\t<li>Siemens Heliox EV Chargers\u00a0\u2013 version Heliox Flex 180 kW EV Charging Station<\/li>\n\t<li>Siemens RUGGEDCOM APE1808 Devices\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SIDIS Prime\u00a0\u2013 versions prior to V4.0.800<\/li>\n\t<li>Siemens SIMATIC\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Trane Tracer Concierge\u00a0\u2013 versions prior to v6.3.2310<\/li>\n\t<li>Trane Tracer SC\u00a0\u2013 versions prior to v4.4_SP7<\/li>\n\t<li>Trane Tracer SC+\u00a0\u2013 versions prior to v6.3.2310<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn June 23, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-67038 affecting Lantronix EDS5000 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038\">CISA KEV: CVE-2025-67038<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-241","alert_type":398,"serial_number":"AV26-241","subject":"ics","moderation_state":"published","external_url":null},{"nid":7405,"title":"Red Hat security advisory (AV26-242)","uuid":"cf25a2c1-c407-4ef5-8050-3087c08eac07","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T16:25:10Z","date_created":"2026-03-16T16:19:01Z","summary":null,"body":["<article data-history-node-id=\"7405\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-242\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-242<br \/><strong>Date: <\/strong>March 16, 2026<\/p>\n\n<p>Between March 9 and 15, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-242","alert_type":396,"serial_number":"AV26-242","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7406,"title":"Microsoft Edge security advisory (AV26-243)","uuid":"a71aec73-1e60-4287-8ac0-57ee559510a9","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T17:11:23Z","date_created":"2026-03-16T17:05:30Z","summary":null,"body":["<article data-history-node-id=\"7406\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-243\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-243<br \/><strong>Date:<\/strong> March\u00a016, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March\u00a013, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 146.0.3856.59<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2026-3910 has an available exploit.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-13-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-243","alert_type":396,"serial_number":"AV26-243","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7407,"title":"HPE security advisory (AV26-244)","uuid":"f0f0b870-e14d-43d3-bbd6-4e2e2ceb9b7b","banner":null,"lang":"en","date_modified":"2026-03-16","date_modified_ts":"2026-03-16T19:18:53Z","date_created":"2026-03-16T19:12:16Z","summary":null,"body":["<article data-history-node-id=\"7407\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-244\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-244<br \/><strong>Date: <\/strong>March\u00a017, 2026<\/p>\n\n<p>Between March\u00a016 and 17, 2026, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v4.2.12<\/li>\n\t<li>HPE Brocade Fabric OS \u2013 versions prior to 9.2.1c3 and 9.2.2c<\/li>\n\t<li>HPE SANnav Management Software \u2013 versions prior to v2.4.0b<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05029en_us&amp;docLocale=en_US#hpesbnw05029-rev-1-hpe-telco-service-orchestrator-0\">HPESBNW05029 rev.1\u00a0- HPE Telco Service Orchestrator, Remote Buffer Overflow<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst05001en_us&amp;docLocale=en_US#hpesbst05001-rev-1-hpe-san-switches-with-brocade-f-0\">HPESBST05001 rev.1 - HPE SAN Switches with Brocade Fabric OS (FOS), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbst05000en_us&amp;docLocale=en_US#hpesbst05000-rev-1-hpe-b-series-sannav-management-0\">HPESBST05000 rev.1 - HPE B-Series SANnav Management Portal, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-244","alert_type":396,"serial_number":"AV26-244","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7408,"title":"Spring security advisory (AV26-245)","uuid":"1e76bdb3-a3f4-4198-ab10-e838ba5077ca","banner":null,"lang":"en","date_modified":"2026-03-17","date_modified_ts":"2026-03-17T15:13:42Z","date_created":"2026-03-17T15:05:28Z","summary":null,"body":["<article data-history-node-id=\"7408\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-245\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-245<\/p>\n\n<p class=\"mrgn-bttm-md\"><strong>Date: <\/strong>March 17, 2026<\/p>\n\n<p>On March 17, 2026, Spring published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Spring AI\u00a0\u2013 1.0.x versions prior to 1.0.4<\/li>\n\t<li>Spring AI\u00a0\u2013 1.1.x versions prior to 1.1.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-22730\">CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-22729\">CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-245","alert_type":396,"serial_number":"AV26-245","subject":"other","moderation_state":"published","external_url":null},{"nid":7409,"title":"GitHub security advisory (AV26-246)","uuid":"233db349-5a1c-4032-9941-16775c16b07e","banner":null,"lang":"en","date_modified":"2026-03-17","date_modified_ts":"2026-03-17T18:20:40Z","date_created":"2026-03-17T18:05:43Z","summary":null,"body":["<article data-history-node-id=\"7409\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-246\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-246<br \/><strong>Date: <\/strong>March 17, 2026<\/p>\n\n<p>On March 12, 2026, GitHub published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.4<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.7<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.13<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.16<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.4<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.7<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.13<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.16<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-246","alert_type":396,"serial_number":"AV26-246","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7410,"title":"[Control Systems] Phoenix Contact Security Advisory (AV26-247)","uuid":"168f280d-81a9-4380-978f-d9b67ecb2a34","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T14:13:11Z","date_created":"2026-03-18T14:09:44Z","summary":null,"body":["<article data-history-node-id=\"7410\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-247\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-247<br \/><strong>Date:<\/strong> March\u00a018, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March\u00a018, 2026, Phoenix Contact published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FL SWITCH 2xxx\u00a0\u2013 3.50 firmware versions prior to 3.53<\/li>\n\t<li>FL SWITCH TSN 23xx\u00a0\u2013 3.50 firmware versions prior to 3.53<\/li>\n\t<li>FL SWITCH 59xx\u00a0\u2013 3.50 firmware versions prior to 3.53<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/assets.phoenixcontact.com\/file\/6ef12bd6-c4f3-4361-9f1d-7e89a389b541\/media\/original?pcsa-2025-00022_vde-2025-104.pdf\">VDE-2025-104: Phoenix Contact: Multiple Vulnerabilities in FL SWITCH 2xxx, FL SWITCH TSN 23xx and FL SWITCH 59xx Firmware (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.phoenixcontact.com\/en-pc\/service-and-support\/psirt\">Phoenix Contact Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-247","alert_type":398,"serial_number":"AV26-247","subject":"other","moderation_state":"published","external_url":null},{"nid":7411,"title":"Apple security advisory (AV26-248)","uuid":"89f7df97-beff-4084-95cf-962ec1b533fc","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T14:23:13Z","date_created":"2026-03-18T14:09:44Z","summary":null,"body":["<article data-history-node-id=\"7411\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-248\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-248<br \/><b>Date:<\/b> March\u00a018, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March\u00a017, 2026, Apple published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 26.3.1<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 26.3.1<\/li>\n\t<li>macOS\u00a0\u2013 versions prior to 26.3.1<\/li>\n\t<li>macOS\u00a0\u2013 versions prior to 26.3.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/126604\">About the security content of Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-248","alert_type":396,"serial_number":"AV26-248","subject":"apple","moderation_state":"published","external_url":null},{"nid":7412,"title":"GNU security advisory (AV26-249)","uuid":"50dee54c-5984-41f0-b3fe-7ddd738a5d79","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T14:34:59Z","date_created":"2026-03-18T14:09:45Z","summary":null,"body":["<article data-history-node-id=\"7412\" about=\"\/en\/alerts-advisories\/gnu-security-advisory-av26-249\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-249<br \/><strong>Date: <\/strong>March\u00a018, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March\u00a011, 2026, GNU published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>GNU InetUtils telnetd\u00a0\u2013 version 2.7 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.gnu.org\/archive\/html\/bug-inetutils\/2026-03\/msg00031.html\">Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.gnu.org\/software\/inetutils\/\">Inetutils\u00a0- GNU network utilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gnu-security-advisory-av26-249","alert_type":396,"serial_number":"AV26-249","subject":"other","moderation_state":"published","external_url":null},{"nid":7413,"title":"Mitel security advisory (AV26-250)","uuid":"f332dba7-2790-4269-821c-78450916f252","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T14:43:24Z","date_created":"2026-03-18T14:38:57Z","summary":null,"body":["<article data-history-node-id=\"7413\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av26-250\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-250<br \/><strong>Date: <\/strong>March\u00a018, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March\u00a018, 2026, Mitel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitel CX\u00a0\u2013 version 2.0.0.1 and prior<\/li>\n\t<li>MiContact Center Business\u00a0\u2013 version 10.2.0.11 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2026-0001\">Mitel Product Security Advisory MISA-2026-0001<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av26-250","alert_type":396,"serial_number":"AV26-250","subject":"mitel","moderation_state":"published","external_url":null},{"nid":7414,"title":"Atlassian security advisory (AV26-251)","uuid":"fb145444-f827-4e34-ba18-b238954a1e34","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T17:30:11Z","date_created":"2026-03-18T17:23:28Z","summary":null,"body":["<article data-history-node-id=\"7414\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-251\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-251<br \/><strong>Date: <\/strong>March\u00a018, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March\u00a017, 2026, Atlassian published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server- version 9.4.16 (LTS), versions 10.1.1 to 10.1.4<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Fisheye\/Crucible\u00a0\u2013 version 4.8.16, versions 4.9.0 to 4.9.7<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-march-17-2026-1721271371.html\">Security Bulletin - March 17 2026<\/a><\/li>\n\t<li><a href=\" https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-251","alert_type":396,"serial_number":"AV26-251","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":7415,"title":"VMware security advisory (AV26-252)","uuid":"aa7c56ee-2790-47b1-933d-dea8bd8c3138","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T17:34:50Z","date_created":"2026-03-18T17:23:28Z","summary":null,"body":["<article data-history-node-id=\"7415\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-252\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-252<br \/><strong>Date: <\/strong>March\u00a018, 2026<\/p>\n\n<p>On March\u00a018, 2026, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-252","alert_type":396,"serial_number":"AV26-252","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7416,"title":"Citrix security advisory (AV26-253)","uuid":"2865a067-8635-47a9-bb0c-5a6a488ffccc","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T18:00:23Z","date_created":"2026-03-18T17:54:17Z","summary":null,"body":["<article data-history-node-id=\"7416\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-253\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-253<br \/><strong>Date: <\/strong>March\u00a018, 2026<\/p>\n\n<p>On March\u00a017, 2026, Citrix published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>XenServer\u00a0\u2013 version 8.4.<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696350&amp;articleURL=XenServer_Security_Update_for_CVE_2026_23554\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">XenServer Security Update for<\/span> CVE-2026-23554<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Citrix Security Advisories<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av26-253","alert_type":396,"serial_number":"AV26-253","subject":"citrix","moderation_state":"published","external_url":null},{"nid":7417,"title":"Roundcube security advisory (AV26-254)","uuid":"0e51095a-28a4-4805-a9aa-afdf100d6823","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T18:16:57Z","date_created":"2026-03-18T18:02:33Z","summary":null,"body":["<article data-history-node-id=\"7417\" about=\"\/en\/alerts-advisories\/roundcube-security-advisory-av26-254\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-254<br \/><strong>Date: <\/strong>March 18, 2026<\/p>\n\n<p>On March 18, 2026, Roundcube published a security advisory to address vulnerabilities in the following product\u00a0:<\/p>\n\n<ul><li>Webmail\u00a0\u2013 versions prior to 1.6.14<\/li>\n\t<li>Webmail\u00a0\u2013 versions prior to 1.5.14<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.6.14\">Roundcube Webmail 1.6.14<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.5.14\">Roundcube Webmail 1.5.14<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/roundcube-security-advisory-av26-254","alert_type":396,"serial_number":"AV26-254","subject":"other","moderation_state":"published","external_url":null},{"nid":7418,"title":"Jenkins security advisory (AV26-255)","uuid":"e4be579f-20fb-433c-9d1c-4732eaef26f5","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T18:52:35Z","date_created":"2026-03-18T18:20:22Z","summary":null,"body":["<article data-history-node-id=\"7418\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-255\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-255<br \/><strong>Date: <\/strong>March 18, 2026<\/p>\n\n<p>On March 18, 2026, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins weekly\u00a0\u2013 version 2.554 and prior<\/li>\n\t<li>Jenkins LTS\u00a0\u2013 versions 2.541.2 and prior<\/li>\n\t<li>LoadNinja Plugin\u00a0\u2013 versions 2.1 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-03-18\/\">Jenkins Security Advisory 2026-03-18<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-255","alert_type":396,"serial_number":"AV26-255","subject":"other","moderation_state":"published","external_url":null},{"nid":7419,"title":"Google Chrome security advisory (AV26-256)","uuid":"eb2a6f35-ad72-444e-89af-459597142588","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T19:04:37Z","date_created":"2026-03-18T18:55:17Z","summary":null,"body":["<article data-history-node-id=\"7419\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-256\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-256<br \/><strong>Date: <\/strong>March 18, 2026<\/p>\n\n<p>On March 18, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 146.0.7680.153\/154 (Windows\/Mac) and 146.0.7680.153 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_18.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-256","alert_type":396,"serial_number":"AV26-256","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7420,"title":"ConnectWise security advisory (AV26-257)","uuid":"6845a2ec-945a-4d15-8b3e-8546288cd3b1","banner":null,"lang":"en","date_modified":"2026-03-18","date_modified_ts":"2026-03-18T19:27:36Z","date_created":"2026-03-18T19:20:57Z","summary":null,"body":["<article data-history-node-id=\"7420\" about=\"\/en\/alerts-advisories\/connectwise-security-advisory-av26-257\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-257<br \/><strong>Date: <\/strong>March 17, 2026<\/p>\n\n<p>On March 17, 2026, ConnectWise published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ConnectWise ScreenConnect\u00a0\u2013 versions prior to 26.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/2026-03-17-screenconnect-bulletin\">ScreenConnect 26.1 Security Hardening<\/a><\/li>\n\t<li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/advisories\">ConnectWise\u00a0- Latest Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/connectwise-security-advisory-av26-257","alert_type":396,"serial_number":"AV26-257","subject":"other","moderation_state":"published","external_url":null},{"nid":7421,"title":"Ubiquiti security advisory (AV26-258)","uuid":"c37f0d82-85d9-48a0-8911-6c51207adb33","banner":null,"lang":"en","date_modified":"2026-03-19","date_modified_ts":"2026-03-19T14:33:36Z","date_created":"2026-03-19T14:16:17Z","summary":null,"body":["<article data-history-node-id=\"7421\" about=\"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-258\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-258<br \/><strong>Date: <\/strong>March 18, 2026<\/p>\n\n<p>On March 18, 2026, Ubiquiti published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>UniFi Network application\u00a0\u2013 version 10.1.85 and prior<\/li>\n\t<li>UniFi Network application\u00a0\u2013 version 10.2.93 and prior<\/li>\n\t<li>UniFi Network application\u00a0\u2013 version 9.0.114 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.ui.com\/releases\/Security-Advisory-Bulletin-062-062\/c29719c0-405e-4d4a-8f26-e343e99f931b\">Ubiquiti UniFi\u00a0- Security Advisory Bulletin 062<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-258","alert_type":396,"serial_number":"AV26-258","subject":"other","moderation_state":"published","external_url":null},{"nid":7422,"title":"Spring security advisory (AV26-259)","uuid":"0a191b71-f07d-4a62-adac-98712cb0ebc6","banner":null,"lang":"en","date_modified":"2026-03-19","date_modified_ts":"2026-03-19T19:03:42Z","date_created":"2026-03-19T18:36:20Z","summary":null,"body":["<article data-history-node-id=\"7422\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-259\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-259<br \/><strong>Date: <\/strong>March 19, 2026<\/p>\n\n<p>On March 19, 2026, Spring published security advisories to address vulnerabilities in the following products. Included was a critical update for the following:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Spring Boot<\/span>\u00a0\u2013 multiple versions<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Spring Security<\/span>\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-22731\">CVE-2026-22731: Authentication Bypass under Actuator Health groups paths<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-22732\">CVE-2026-22718: Under Some Conditions Spring Security HTTP Headers Are not Written<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-22733\">CVE-2026-22733: Authentication Bypass under Actuator CloudFoundry endpoints<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-259","alert_type":396,"serial_number":"AV26-259","subject":"other","moderation_state":"published","external_url":null},{"nid":7423,"title":"Kubernetes security advisory (AV26-260)","uuid":"bd792f44-3a38-402b-9304-4fac249b7959","banner":null,"lang":"en","date_modified":"2026-03-19","date_modified_ts":"2026-03-19T19:14:01Z","date_created":"2026-03-19T19:08:03Z","summary":null,"body":["<article data-history-node-id=\"7423\" about=\"\/en\/alerts-advisories\/kubernetes-security-advisory-av26-260\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-260<br \/><strong>Date: <\/strong>March 19, 2026<\/p>\n\n<p>On March 19, 2026, Kubernetes published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Kubernetes ingress-nginx\u00a0\u2013 versions prior to 1.13.9<\/li>\n\t<li>Kubernetes ingress-nginx\u00a0\u2014 versions prior to 1.14.5<\/li>\n\t<li>Kubernetes ingress-nginx\u00a0\u2013 versions prior to 1.15.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.kubernetes.io\/t\/security-advisory-cve-2026-4342-ingress-nginx-comment-based-nginx-configuration-injection\/34349\">[Security Advisory] CVE-2026-4342: ingress-nginx comment-based nginx configuration injection<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.kubernetes.io\/c\/announcements\/5\">Kubernetes\u00a0- Announcements<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/kubernetes-security-advisory-av26-260","alert_type":396,"serial_number":"AV26-260","subject":"other","moderation_state":"published","external_url":null},{"nid":7425,"title":"Oracle security advisory (AV26-261)","uuid":"92774df6-22dc-41f6-8082-eb4fe93df8c6","banner":null,"lang":"en","date_modified":"2026-03-20","date_modified_ts":"2026-03-20T15:34:42Z","date_created":"2026-03-20T15:28:09Z","summary":null,"body":["<article data-history-node-id=\"7425\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-av26-261\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-261<br \/><strong>Date: <\/strong>March 20, 2026<\/p>\n\n<p>On March 19, 2026, Oracle published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Oracle Identity Manager\u00a0\u2013 versions 12.2.1.4.0 and 14.1.2.1.0<\/li><li>\nOracle Web Services Manager\u00a0\u2013 versions 12.2.1.4.0 and 14.1.2.1.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2026-21992.html\">Oracle Security Alert Advisory\u00a0- CVE-2026-21992<\/a><\/li>\n\t<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/\">Oracle Critical Patch Updates, Security Alerts and Bulletins<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-av26-261","alert_type":396,"serial_number":"AV26-261","subject":"oracle","moderation_state":"published","external_url":null},{"nid":7426,"title":"AL26-005 \u2013 Critical vulnerability impacting Microsoft SharePoint Server \u2013 CVE-2026-20963","uuid":"2310e2f6-daa1-451e-baeb-ca6f044b5856","banner":null,"lang":"en","date_modified":"2026-03-20","date_modified_ts":"2026-03-20T18:23:30Z","date_created":"2026-03-20T17:18:03Z","summary":null,"body":["<article data-history-node-id=\"7426\" about=\"\/en\/alerts-advisories\/al26-005-critical-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-20963\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-005<br \/><strong>Date:<\/strong> March\u00a020, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint Server. In response to the Microsoft security advisory, released on January\u00a013, 2026<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, the Cyber Centre issued AV26-024<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> on January\u00a013, 2026. The Advisory was updated on March\u00a018, 2026 to include additional details.<\/p>\n\n<p>Tracked as CVE-2026-20963<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is a critical Deserialization of Untrusted Data (CWE-502)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> vulnerability affecting multiple versions of Microsoft SharePoint Server and could allow an unauthenticated remote attacker to execute code over the network.<\/p>\n\n<p>The Cyber Centre has observed exploitation of this vulnerability, and organizations are urged to take immediate action.<\/p>\n\n<p>This vulnerability was added to CISA's Known Exploited Vulnerabilities (KEV) catalog<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> on March\u00a018, 2026.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Microsoft SharePoint Enterprise Server 2016<\/td>\n\t\t\t<td>16.0.0 before 16.0.5535.1001<\/td>\n\t\t\t<td>16.0.5535.1001<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server 2019<\/td>\n\t\t\t<td>16.0.0 before 16.0.10417.20083<\/td>\n\t\t\t<td>16.0.10417.20083<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server Subscription Edition<\/td>\n\t\t\t<td>16.0.0 before 16.0.19127.20442<\/td>\n\t\t\t<td>16.0.19127.20442<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>Open-source reporting indicates that other legacy versions are affected by this vulnerability but are now considered end of support\/life and should be decommissioned or upgraded.<\/p>\n\n<p>The Cyber Centre recommends organizations to:<\/p>\n\n<ul><li>Identify all on-premises SharePoint Server instances, particularly those exposed to the internet.<\/li>\n\t<li>Use or upgrade to supported versions of on-premises Microsoft SharePoint Server.<\/li>\n\t<li>Apply the latest security updates from Microsoft.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-20963\">Microsoft Security Update Guide<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-january-2026-monthly-rollup-av26-024\">Microsoft security advisory (AV26-024)\u00a0\u2013 Update 2<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-20963\">NVD\u00a0\u2013 CVE-2026-20963<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/502.html\">CWE-502: Deserialization of Untrusted Data<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20963\">CISA KEV<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-005-critical-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-20963","alert_type":397,"serial_number":"AL26-005","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7427,"title":"IBM security advisory (AV26-262)","uuid":"3b44b785-60f3-491d-a34f-1727287ed72f","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T12:56:28Z","date_created":"2026-03-23T12:47:46Z","summary":null,"body":["<article data-history-node-id=\"7427\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-262\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-262<br \/><strong>Date: <\/strong>March 23, 2026<\/p>\n\n<p>Between March 16 and 22, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM App Connect Enterprise \u2013 versions 13.0.1.0 to 13.0.6.1<\/li>\n\t<li>IBM App Connect Enterprise \u2013 versions 12.0.1.0 to 12.0.12.23<\/li>\n\t<li>IBM Application Modernization Accelerator \u2013 versions 4.0.0 to 4.5.2<\/li>\n\t<li>IBM Cloud Pak for Business Automation \u2013 versions V24.0.0 to V24.0.0-IF007<\/li>\n\t<li>IBM Control Center \u2013 multiple versions<\/li>\n\t<li>IBM Informix Dynamic Server \u2013 version 12.10.x<\/li>\n\t<li>IBM Maximo Application Suite - Visual Inspection Component \u2013 version 9.1.x<\/li>\n\t<li>IBM Observability with Instana (OnPrem) \u2013 versions Build 1.0.285 to 1.0.311<\/li>\n\t<li>IBM Rhapsody Systems Engineering \u2013 versions 1.5.0 to 1.5.4 and 1.6.0<\/li>\n\t<li>IBM Sterling Connect:Direct for UNIX \u2013 versions 6.3.0.3 to 6.3.0.6.iFix032<\/li>\n\t<li>IBM Sterling Connect:Direct for UNIX \u2013 versions 6.4.0.0 to 6.4.0.4.iFix016<\/li>\n\t<li>IBM Sterling ITXA (fka Standards Processing Engine) \u2013 versions Transformation Extender Advanced 10.0.1.0 to 10.0.1.11<\/li>\n\t<li>IBM Sterling ITXA (fka Standards Processing Engine) \u2013 versions Transformation Extender Advanced 10.0.2.0 to 10.0.2.1<\/li>\n\t<li>IBM Transformation Advisor \u2013 versions 2.0.1 to 4.5.2<\/li>\n\t<li>IBM i \u2013 multiple versions<\/li>\n\t<li>IBM watsonx Code Assistant On Prem \u2013 multiple versions<\/li>\n\t<li>QRadar \u2013 versions 7.5.0 to 7.5.0 UP14 IF05<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-262","alert_type":396,"serial_number":"AV26-262","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7428,"title":"Dell security advisory (AV26-263)","uuid":"676978bc-dbcb-477d-8271-0528bd581926","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T13:54:35Z","date_created":"2026-03-23T12:58:27Z","summary":null,"body":["<article data-history-node-id=\"7428\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-263\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-263<br \/><strong>Date: <\/strong>March 23, 2026<\/p>\n\n<p>Between March 16 and 22, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Policy Manager for Secure Connect Gateway \u2013 Appliance \u2013 versions prior to 5.32.00.18<\/li>\n\t<li>NetWorker \u2013 version 19.14<\/li>\n\t<li>NetWorker \u2013 versions 19.9 to 19.13.0.2<\/li>\n\t<li>PowerSwitch Z9664F-ON \u2013 versions prior to 3.54.5.1-11<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000440823\/dsa-2026-057-security-update-for-dell-networker-apache-tomcat-vulnerabilities\">DSA-2026-057: Security Update for Dell NetWorker Apache Tomcat Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000441046\/dsa-2026-140-security-update-for-dell-networking-products-for-rsync-vulnerabilities\">DSA-2026-140: Security Update for Dell Networking Products for rsync Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000441138\/dsa-2026-120-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-third-party-component-vulnerabilities\">DSA-2026-120: Security Update for Dell Secure Connect Gateway Policy Manager Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-263","alert_type":396,"serial_number":"AV26-263","subject":"dell","moderation_state":"published","external_url":null},{"nid":7429,"title":"Ubuntu security advisory (AV26-264)","uuid":"10739de2-df68-41fe-bedb-c4d554a2a4c6","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T14:02:37Z","date_created":"2026-03-23T13:59:15Z","summary":null,"body":["<article data-history-node-id=\"7429\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-264\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-264<br \/><strong>Date: <\/strong>March 23, 2026<\/p>\n\n<p>Between March 16 and 22, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-264","alert_type":396,"serial_number":"AV26-264","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7430,"title":"[Control systems] CISA ICS security advisories (AV26\u2013265)","uuid":"a3121466-a8f4-4250-b80e-5b57a446caeb","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T14:14:20Z","date_created":"2026-03-23T14:08:09Z","summary":null,"body":["<article data-history-node-id=\"7430\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-265\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-265<br \/><strong>Date: <\/strong>March 23, 2026<\/p>\n\n<p>Between March 16 and 22, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Automated Logic WebCTRL Premium Server \u2013 versions prior to v8.5<\/li>\n\t<li>CODESYS in Festo Automation Suite \u2013 multiple versions<\/li>\n\t<li>CTEK Chargeportal \u2013 all versions<\/li>\n\t<li>IGL-Technologies eParking.fi \u2013 all versions<\/li>\n\t<li>Mitsubishi Electric CNC Series \u2013 multiple versions<\/li>\n\t<li>Schneider Electric EcoStruxure Automation Expert \u2013 versions prior to v25.0.1<\/li>\n\t<li>Schneider Electric EcoStruxure Data Center Expert \u2013 version v9.0 and prior<\/li>\n\t<li>Schneider Electric EcoStruxure PME and EPO \u2013 multiple versions<\/li>\n\t<li>Schneider Electric Modicon Controllers M241\/M251\/M258\/LMC058 \u2013 multiple versions<\/li>\n\t<li>Schneider Electric Modicon M241\/M251 \u2013 versions prior to 5.4.13.12<\/li>\n\t<li>Schneider Electric Modicon M262 \u2013 versions prior to 5.4.10.12<\/li>\n\t<li>Schneider Electric SCADAPack and RemoteConnect \u2013 versions prior to R3.4.2<\/li>\n\t<li>Siemens SICAM SIAPP SDK \u2013 version prior to V2.1.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories \">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-265","alert_type":398,"serial_number":"AV26-265","subject":"other","moderation_state":"published","external_url":null},{"nid":7431,"title":"Red Hat security advisory (AV26-266)","uuid":"d54999f8-617b-471b-9cf2-fb3be8f195ce","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T14:22:23Z","date_created":"2026-03-23T14:17:42Z","summary":null,"body":["<article data-history-node-id=\"7431\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-266\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-266<br \/><strong>Date: <\/strong>March 23, 2026<\/p>\n\n<p>Between March 16 and 22, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-266","alert_type":396,"serial_number":"AV26-266","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7432,"title":"Citrix security advisory (AV26-267) \u2013 Update 1","uuid":"2896341e-cf29-4666-8b08-2cd2330d4880","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T20:20:39Z","date_created":"2026-03-23T14:24:03Z","summary":null,"body":["<article data-history-node-id=\"7432\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-267\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-267<br \/><strong>Date: <\/strong>March 23, 2026<br \/><strong>Updated: <\/strong>March 30, 2026<br \/><\/p>\n\n<p>On March 23, 2026, Citrix published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway 14.1 \u2013 versions prior to 14.1-60.58<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.1 \u2013 versions prior to 13.1-62.23<\/li>\n\t<li>NetScaler ADC FIPS and NDcPP \u2013 versions prior to 13.1-37.262<\/li>\n<\/ul><h2 class=\"h3\">\n  Update 1\n<\/h2>\n<p class=\"mrgn-bttm-md\">On March 30, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-3055 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696300&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\">Citrix Security Advisories<\/a><\/li>\n  \n  \t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3055\">CISA KEV: CVE-2026-3055<\/a><\/li>\n  \n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av26-267","alert_type":396,"serial_number":"AV26-267","subject":"citrix","moderation_state":"published","external_url":null},{"nid":7433,"title":"Microsoft Edge security advisory (AV26-268)","uuid":"527166ec-09d8-4931-a1d1-ccd2ce72c29e","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T14:36:39Z","date_created":"2026-03-23T14:33:22Z","summary":null,"body":["<article data-history-node-id=\"7433\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-268\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-268<br \/><strong>Date: <\/strong>March 23, 2026<\/p>\n\n<p>On March 20, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 146.0.3856.72<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-20-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-268","alert_type":396,"serial_number":"AV26-268","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7434,"title":"VMware security advisory (AV26-269)","uuid":"bdf5db53-2f7b-4634-a143-db89f902686c","banner":null,"lang":"en","date_modified":"2026-03-23","date_modified_ts":"2026-03-23T14:47:04Z","date_created":"2026-03-23T14:38:43Z","summary":null,"body":["<article data-history-node-id=\"7434\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-269\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-269<br \/><strong>Date: <\/strong>March 23, 2026<\/p>\n\n<p>On March 20, 2026, VMware published security advisories to address vulnerabilities in multiple Tanzu products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories - Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-269","alert_type":396,"serial_number":"AV26-269","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7435,"title":"Google Chrome security advisory (AV26-270)","uuid":"0eb40fee-bd08-4447-b81d-3aa8b09ddbcc","banner":null,"lang":"en","date_modified":"2026-03-24","date_modified_ts":"2026-03-24T15:49:08Z","date_created":"2026-03-24T15:44:59Z","summary":null,"body":["<article data-history-node-id=\"7435\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-270\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-270<br \/><strong>Date: <\/strong>March 24, 2026<\/p>\n\n<p>On March 23, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 146.0.7680.164\/165 (Windows\/Mac) and 146.0.7680.164 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_23.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-270","alert_type":396,"serial_number":"AV26-270","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7436,"title":"Mozilla security advisory (AV26-271)","uuid":"c7bbaef7-fb5c-4af5-a00a-81d6af097fc0","banner":null,"lang":"en","date_modified":"2026-03-24","date_modified_ts":"2026-03-24T15:54:34Z","date_created":"2026-03-24T15:50:56Z","summary":null,"body":["<article data-history-node-id=\"7436\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-271\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-271<br \/><strong>Date: <\/strong>March 24, 2026<\/p>\n\n<p>On March 24, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 149<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.34<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 140.9<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-20\/\">Security Vulnerabilities fixed in Firefox 149<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-21\/\">Security Vulnerabilities fixed in Firefox ESR 115.34<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-22\/\">Security Vulnerabilities fixed in Firefox ESR 140.9<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-271","alert_type":396,"serial_number":"AV26-271","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7437,"title":"VMware security advisory (AV26-272)","uuid":"50c26058-39f9-443a-a21e-f9738a5c9774","banner":null,"lang":"en","date_modified":"2026-03-24","date_modified_ts":"2026-03-24T16:01:17Z","date_created":"2026-03-24T15:57:47Z","summary":null,"body":["<article data-history-node-id=\"7437\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-272\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-272<br \/><strong>Date: <\/strong>March 24, 2026<\/p>\n\n<p>On March 24, 2026, VMware published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu for Postgres \u2013 versions prior to 18.3.0<\/li>\n\t<li>VMware Tanzu for Postgres \u2013 versions prior to 17.9.0<\/li>\n\t<li>VMware Tanzu for Postgres \u2013 versions prior to 16.13.0<\/li>\n\t<li>VMware Tanzu for Postgres \u2013 versions prior to 15.17.0<\/li>\n\t<li>VMware Tanzu for Postgres \u2013 versions prior to 14.22.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37294\">Product Release Advisory - VMware Tanzu for Postgres 18.3.0, 17.9.0, 16.13.0, 15.17.0, 14.22.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories \u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-272","alert_type":396,"serial_number":"AV26-272","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7438,"title":"F5 security advisory (AV26-273)","uuid":"c1312eb1-68b5-432f-9916-aae04a83ce5e","banner":null,"lang":"en","date_modified":"2026-03-24","date_modified_ts":"2026-03-24T16:11:18Z","date_created":"2026-03-24T16:03:31Z","summary":null,"body":["<article data-history-node-id=\"7438\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-273\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-273<br \/><strong>Date: <\/strong>March 24, 2026<\/p>\n\n<p>On March 24, 2026, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NGINX Plus \u2013 versions R32 to R36<\/li>\n\t<li>NGINX Open Source \u2013 versions 1.0.0 to 1.29.6 and 0.5.13 to 0.9.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000160336\">K000160336: Out-of-band Security Notification (March 24, 2026) <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-273","alert_type":396,"serial_number":"AV26-273","subject":"f5","moderation_state":"published","external_url":null},{"nid":7439,"title":"[Control systems] Helmholz security advisory (AV26-274) ","uuid":"98412dd3-354b-4d04-b491-2c5cbeb68c80","banner":null,"lang":"en","date_modified":"2026-03-24","date_modified_ts":"2026-03-24T16:22:48Z","date_created":"2026-03-24T16:15:26Z","summary":null,"body":["<article data-history-node-id=\"7439\" about=\"\/en\/alerts-advisories\/control-systems-helmholz-security-advisory-av26-274\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-274<br \/><strong>Date: <\/strong>March 24, 2026<\/p>\n\n<p>On March 23, 2026, CERT@VDE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Helmholz myREX24V2 \u2013 firmware versions 2.19.3 and prior<\/li>\n\t<li>Helmholz myREX24V2.virtual \u2013 firmware versions 2.19.3 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/certvde.com\/en\/advisories\/VDE-2026-025\/\">Helmholz: Multiple Vulnerabilities in myREX24V2 \/ myREX24V2.virtual<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-helmholz-security-advisory-av26-274","alert_type":398,"serial_number":"AV26-274","subject":"other","moderation_state":"published","external_url":null},{"nid":7440,"title":"Apple security advisory (AV26-275) - Update 1","uuid":"dc71dbb3-414a-4c9f-8ea1-c7a0bb9b1bec","banner":null,"lang":"en","date_modified":"2026-04-02","date_modified_ts":"2026-04-02T15:11:10Z","date_created":"2026-03-24T19:05:47Z","summary":null,"body":["<article data-history-node-id=\"7440\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-275\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-275<br \/><strong>Date:<\/strong> March 24, 2026<br \/><strong>Updated:<\/strong> April 2, 2026<\/p>\n\n<p>On March 24, 2026, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 18.7.7 and versions prior to 26.4<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 18.7.7 and versions prior to 26.4<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.7.5<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.8.5<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26.4<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 26.4<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 26.4<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 26.4<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn April 1, 2026 Apple expanded the availability of iOS 18.7.7 for more devices to protect from DarkSword iOS exploit kit web attacks.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/126793\">About the security content of iOS 18.7.7 and iPadOS 18.7.7<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-275","alert_type":396,"serial_number":"AV26-275","subject":"apple","moderation_state":"published","external_url":null},{"nid":7441,"title":"GitLab security advisory (AV26-276)","uuid":"f802f759-a59c-43dd-a0e7-6c9a815ece6a","banner":null,"lang":"en","date_modified":"2026-03-25","date_modified_ts":"2026-03-25T16:02:41Z","date_created":"2026-03-25T15:56:49Z","summary":null,"body":["<article data-history-node-id=\"7441\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-276\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-276<br \/><strong>Date: <\/strong>March 25, 2026<\/p>\n\n<p>On March 25, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.10.1, 18.9.3 and 18.8.7<\/li>\n<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.10.1, 18.9.3 and 18.8.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/03\/25\/patch-release-gitlab-18-10-1-released\/\">GitLab Patch GitLab Patch Release: 18.10.1, 18.9.3, 18.8.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-276","alert_type":396,"serial_number":"AV26-276","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7442,"title":"Nodejs security advisory (AV26-277)","uuid":"e4f6fa31-a6c4-48d9-a670-8b117f2f1a60","banner":null,"lang":"en","date_modified":"2026-03-25","date_modified_ts":"2026-03-25T16:12:16Z","date_created":"2026-03-25T16:03:56Z","summary":null,"body":["<article data-history-node-id=\"7442\" about=\"\/en\/alerts-advisories\/nodejs-security-advisory-av26-277\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-277<br \/><strong>Date: <\/strong>March 25, 2026<\/p>\n\n<p>On March 24, 2026, Nodejs published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Node.js 20\u00a0\u2013 versions prior to v20.20.2 (LTS)<\/li>\n<li>Node.js 22\u00a0\u2013 versions prior to v22.22.2 (LTS)<\/li>\n    <li>Node.js 24\u00a0\u2013 versions prior to v24.14.1 (LTS)<\/li>\n<li>Node.js 25\u00a0\u2013 versions prior to v25.8.2 (Current)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nodejs.org\/en\/blog\/release\/v20.20.2\">Node.js 20.20.2 (LTS)<\/a><\/li>\n\t<li><a href=\"https:\/\/nodejs.org\/en\/blog\/release\/v22.22.2\">Node.js 22.22.2 (LTS)<\/a><\/li>\n  \t<li><a href=\"https:\/\/nodejs.org\/en\/blog\/release\/v24.14.1\">Node.js 24.14.1 (LTS)<\/a><\/li>\n\t<li><a href=\"https:\/\/nodejs.org\/en\/blog\/release\/v25.8.2\">Node.js 25.8.2 (Current)<\/a><\/li>\n\t<li><a href=\"https:\/\/nodejs.org\/en\/blog\/release\/\">Nodejs Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nodejs-security-advisory-av26-277","alert_type":396,"serial_number":"AV26-277","subject":"other","moderation_state":"published","external_url":null},{"nid":7443,"title":"n8n security advisory (AV26-278)","uuid":"ad6072fd-2809-4979-b86c-bec074f9e822","banner":null,"lang":"en","date_modified":"2026-03-25","date_modified_ts":"2026-03-25T16:26:02Z","date_created":"2026-03-25T16:14:11Z","summary":null,"body":["<article data-history-node-id=\"7443\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-278\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-278<br \/><strong>Date: <\/strong>March 25, 2026<\/p>\n\n\n<p>On March 25, 2026, n8n published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>n8n (Merge Node)\u00a0\u2013 multiple versions<\/li>\n<li>n8n (Community Edition)\u00a0\u2013 multiple versions<\/li>\n<li>n8n (Binary Data Inline HTML Rendering)\u00a0\u2013 multiple versions<\/li>\n<li>n8n (GSuiteAdmin Node)\u00a0\u2013 multiple versions<\/li>\n<li>n8n (Form Trigger\/Chat Trigger Nodes)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-278","alert_type":396,"serial_number":"AV26-278","subject":"other","moderation_state":"published","external_url":null},{"nid":7444,"title":"Hitachi security advisory (AV26-279) ","uuid":"1e05754b-7d8e-45df-b1aa-b2b143b366b6","banner":null,"lang":"en","date_modified":"2026-03-25","date_modified_ts":"2026-03-25T18:14:51Z","date_created":"2026-03-25T18:09:41Z","summary":null,"body":["<article data-history-node-id=\"7444\" about=\"\/en\/alerts-advisories\/hitachi-security-advisory-av26-279\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-279<br \/><strong>Date: <\/strong>March 25, 2026<\/p>\n\n<p>On March 25, 2026, Hitachi published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Ops Center Administrator (Linux) \u2013 versions 10.2.0 to versions prior to 11.0.8<\/li>\n\t<li>Hitachi Infrastructure Analytics Advisor (English version, Linux) \u2013 all versions<\/li>\n\t<li>Hitachi Ops Center Analyzer (English version, Linux) \u2013 versions 10.0.0-00 to versions prior to 11.0.5-00<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-113\/index.html\">Open Redirect Vulnerability in Hitachi Ops Center Administrator (CVE-2026-1166)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-114\/index.html\">Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer (CVE-2026-2072)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/index.html\">Hitachi Vulnerability Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hitachi-security-advisory-av26-279","alert_type":396,"serial_number":"AV26-279","subject":"other","moderation_state":"published","external_url":null},{"nid":7445,"title":"ISC BIND security advisory (AV26-280)","uuid":"534642b5-86d4-44bb-9d85-86bf8a9e236a","banner":null,"lang":"en","date_modified":"2026-03-25","date_modified_ts":"2026-03-25T18:23:28Z","date_created":"2026-03-25T18:17:13Z","summary":null,"body":["<article data-history-node-id=\"7445\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-280\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-280<br \/><strong>Date: <\/strong>March 25, 2026<\/p>\n\n<p>On March 25, 2026, ISC published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ISC BIND 9 \u2013 versions 9.11.0 to 9.16.50<\/li>\n\t<li>ISC BIND 9 \u2013 versions 9.18.0 to 9.18.46<\/li>\n\t<li>ISC BIND 9 \u2013 versions 9.20.0 to 9.20.20<\/li>\n\t<li>ISC BIND 9 \u2013 versions 9.21.0 to 9.21.19<\/li>\n\t<li>BIND Supported Preview Edition \u2013 versions 9.11.3-S1 to 9.16.50-S1<\/li>\n\t<li>BIND Supported Preview Edition \u2013 versions 9.18.11-S1 to 9.18.46-S1<\/li>\n\t<li>BIND Supported Preview Edition \u2013 versions 9.20.9-S1 to 9.20.20-S1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-1519\">CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-3104\">CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-3119\">CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-3591\">CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-280","alert_type":396,"serial_number":"AV26-280","subject":"other","moderation_state":"published","external_url":null},{"nid":7446,"title":"Cisco security advisory (AV26-281)","uuid":"d18efaa7-89c8-43f6-aba4-d0361856444f","banner":null,"lang":"en","date_modified":"2026-03-25","date_modified_ts":"2026-03-25T19:11:31Z","date_created":"2026-03-25T19:07:19Z","summary":null,"body":["<article data-history-node-id=\"7446\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-281\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-281<br \/><strong>Date: <\/strong>March 25, 2026<\/p>\n\n<p>On March 25, 2026, Cisco published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Catalyst 9300 Series Switches<\/li>\n\t<li>Cisco Catalyst 9200 Series Switches<\/li>\n\t<li>Cisco Catalyst 9000 Series Switches<\/li>\n\t<li>Cisco Catalyst ESS9300 Embedded Series Switches<\/li>\n\t<li>Cisco IOS Software<\/li>\n\t<li>Cisco IOS XE Software<\/li>\n\t<li>Cisco Secure Firewall ASA Software<\/li>\n\t<li>Cisco Secure FTD Software<\/li>\n\t<li>Cisco Catalyst IE9310 and IE9320 Rugged Series Switches<\/li>\n\t<li>Cisco IE3500 and IE3505 Rugged Series Switches<\/li>\n\t<li>Cisco Catalyst CW9800H Wireless Controllers<\/li>\n\t<li>Cisco Catalyst CW9800M Wireless Controllers<\/li>\n\t<li>Cisco Catalyst CW9800H1 Wireless Controllers<\/li>\n\t<li>Cisco Meraki MS390<\/li>\n\t<li>Cisco Catalyst SD-WAN Manager<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/viewErp.x?alertId=ERP-75297\">Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-281","alert_type":396,"serial_number":"AV26-281","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7447,"title":"PTC security advisory (AV26-282)","uuid":"3f5fc1b6-4ae0-4c36-9edb-6e04b0f16812","banner":null,"lang":"en","date_modified":"2026-03-26","date_modified_ts":"2026-03-26T15:50:00Z","date_created":"2026-03-26T15:46:32Z","summary":null,"body":["<article data-history-node-id=\"7447\" about=\"\/en\/alerts-advisories\/ptc-security-advisory-av26-282\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-282<br \/><strong>Date: <\/strong>March 26, 2026<\/p>\n\n<p>On March 23, 2026, PTC published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PTC Windchill PDMLink \u2013 multiple versions<\/li>\n\t<li>PTC FlexPLM \u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ptc.com\/en\/about\/trust-center\/advisory-center\/active-advisories\/windchill-flexplm-critical-vulnerability?srsltid=AfmBOop3e7Nthx5-BsrjKdpZi50wL6l6Bt21Fz0gUub2cIPgdPGV5bNl\">Critical RCE vulnerability reported in Windchill<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ptc.com\/en\/about\/trust-center\/advisory-center\/\">PTC Advisory Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ptc-security-advisory-av26-282","alert_type":396,"serial_number":"AV26-282","subject":"other","moderation_state":"published","external_url":null},{"nid":7448,"title":"Aqua Security security advisory (AV26-283) \u2013 Update 1","uuid":"362469fb-a816-4597-84cc-adbb28aa90a0","banner":null,"lang":"en","date_modified":"2026-03-26","date_modified_ts":"2026-03-26T19:20:45Z","date_created":"2026-03-26T15:51:19Z","summary":null,"body":["<article data-history-node-id=\"7448\" about=\"\/en\/alerts-advisories\/aqua-security-security-advisory-av26-283\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-283<br \/><strong>Date: <\/strong>March 26, 2026<br \/><strong>Updated:<\/strong> March 26, 2026<\/p>\n\n<p>On March 22, 2026, Aqua Security published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>trivy \u2013 version v0.69.4<\/li>\n\t<li>trivy dockerhub images \u2013 versions v0.69.5 and v0.69.6<\/li>\n\t<li>setup-trivy \u2013 versions prior to v0.2.6<\/li>\n\t<li>trivy-action \u2013 versions prior to v0.35.0<\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-33634 has been exploited.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On 26 March 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026\u201133634 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/aquasecurity\/trivy\/security\/advisories\/GHSA-69fq-xp46-6x23\">Trivy ecosystem supply chain temporarily compromised<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/aquasecurity\/trivy\/security\/advisories\/\">Aqua Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33634\">CISA KEV:CVE-2026-33634<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/aqua-security-security-advisory-av26-283","alert_type":396,"serial_number":"AV26-283","subject":"other","moderation_state":"published","external_url":null},{"nid":7449,"title":"Squid security advisory (AV26-284)","uuid":"b2c921e3-1db0-4542-bec9-82fd47f2d74c","banner":null,"lang":"en","date_modified":"2026-03-26","date_modified_ts":"2026-03-26T19:14:49Z","date_created":"2026-03-26T18:10:14Z","summary":null,"body":["<article data-history-node-id=\"7449\" about=\"\/en\/alerts-advisories\/squid-security-advisory-av26-284\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-284<br \/><strong>Date: <\/strong>March 26, 2026<\/p>\n\n<p>On March 25, 2026, Squid published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Squid\u00a0\u2013 versions prior to 7.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/squid-cache\/squid\/security\/advisories\/GHSA-hpfx-h48q-gvwg\">SQUID-2026:1 Denial of Service in ICP Request handling<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/squid-cache\/squid\/security\/advisories\/GHSA-f9p7-3jqg-hhvq\">SQUID-2026:2 Denial of Service in ICP Request handling<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/squid-cache\/squid\/security\/advisories\/GHSA-84p4-hcx7-jj7c\">SQUID-2026:3 Out of Bounds Read in ICP message handling<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/squid-cache\/squid\/security\/advisories\/\">Squid Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/squid-security-advisory-av26-284","alert_type":396,"serial_number":"AV26-284","subject":"other","moderation_state":"published","external_url":null},{"nid":7450,"title":"Grafana security advisory (AV26-285)","uuid":"df285e9c-bc52-4ef4-969a-4bd73dfc6310","banner":null,"lang":"en","date_modified":"2026-03-26","date_modified_ts":"2026-03-26T19:34:03Z","date_created":"2026-03-26T19:20:11Z","summary":null,"body":["<article data-history-node-id=\"7450\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av26-285\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--CUT & PASTE the French version info -->\n<p><strong>Serial number: <\/strong>AV26-285<br \/><strong>Date: <\/strong>March 26, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March 25, 2026, Grafana published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Grafana \u2013 versions prior to 12.4.2, 12.3.6, 12.2.8, 12.1.10 and 11.6.14<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/blog\/grafana-security-release-critical-and-high-severity-security-fixes-for-cve-2026-27876-and-cve-2026-27880\/\">Grafana security release: Critical and high severity security fixes for CVE-2026-27876 and CVE-2026-27880 <\/a><\/li>\n\t<li><a href=\"https:\/\/grafana.com\/blog\/\">Grafana Blog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av26-285","alert_type":396,"serial_number":"AV26-285","subject":"other","moderation_state":"published","external_url":null},{"nid":7451,"title":" [Control systems] ABB security advisory (AV26-286)","uuid":"20ef7f7a-6bc8-4125-9453-74c0203360f9","banner":null,"lang":"en","date_modified":"2026-03-26","date_modified_ts":"2026-03-26T19:48:24Z","date_created":"2026-03-26T19:37:53Z","summary":null,"body":["<article data-history-node-id=\"7451\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-286\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-286<br \/><strong>Date: <\/strong>March 26, 2026<\/p>\n\n<p>On March 26, 2026, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB Ability Camera Connect\u00a0\u2013 version 2.0.0.42 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=4HZM000604&amp;LanguageCode=en&amp;DocumentPartId=PDF&amp;Action=Launch\">ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (SQLite 3.2.4)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-286","alert_type":398,"serial_number":"AV26-286","subject":"abb","moderation_state":"published","external_url":null},{"nid":7452,"title":"HPE security advisory (AV26-287)","uuid":"868bcd27-e6c0-4e45-8944-b072fcd6690a","banner":null,"lang":"en","date_modified":"2026-03-26","date_modified_ts":"2026-03-26T19:59:55Z","date_created":"2026-03-26T19:56:50Z","summary":null,"body":["<article data-history-node-id=\"7452\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-287\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-287<br \/><strong>Date: <\/strong>March 26, 2026<\/p>\n\n<p>On March 26, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator \u2013 versions prior to v5.5.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05031en_us&amp;docLocale=en_US\">HPESBNW05031 rev.1 - HPE Telco Service Orchestrator, Multiple Vulnerabilities <\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-287","alert_type":396,"serial_number":"AV26-287","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7453,"title":"Spring security advisory (AV26-288)","uuid":"9ee0e53f-2b4a-44d3-831f-6271c65cf50a","banner":null,"lang":"en","date_modified":"2026-03-26","date_modified_ts":"2026-03-26T20:05:49Z","date_created":"2026-03-26T20:01:40Z","summary":null,"body":["<article data-history-node-id=\"7453\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-288\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-288<br \/><strong>Date: <\/strong>March 26, 2026<\/p>\n\n<p>Between March 23 and 26, 2026, Spring published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Spring Cloud Config \u2013 versions prior to 3.1.3, 4.1.9, 4.2.6, 4.3.2 and 5.0.2<\/li>\n\t<li>Spring AI \u2013 versions prior to 1.0.5 and 1.1.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-22739\">CVE-2026-22739: Spring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable SSRF Attacks<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-22743\">CVE-2026-22743: Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-22744\">CVE-2026-22744: RediSearch Query via Unescaped TAG Filter Values in RedisVectorStore<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-22742\">CVE-2026-22742: Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-22738\">CVE-2026-22738: SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-288","alert_type":396,"serial_number":"AV26-288","subject":"other","moderation_state":"published","external_url":null},{"nid":7454,"title":"WatchGuard security advisory (AV26-289)","uuid":"25580ee0-83ec-405e-a2f7-c032c245dbad","banner":null,"lang":"en","date_modified":"2026-03-27","date_modified_ts":"2026-03-27T14:39:45Z","date_created":"2026-03-27T14:36:52Z","summary":null,"body":["<article data-history-node-id=\"7454\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-289\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-289<br \/><strong>Date: <\/strong>March 27, 2026<\/p>\n\n<p>On March 26, 2026, WatchGuard published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Fireware OS \u2013 versions prior to 2026.2<\/li>\n\t<li>Fireware OS \u2013 versions prior to 12.12<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00007\">WatchGuard Firebox Insecure Deserialization in Fireware Access Portal (CVE-2026-4266)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-289","alert_type":396,"serial_number":"AV26-289","subject":"other","moderation_state":"published","external_url":null},{"nid":7455,"title":"[Control systems] Siemens security advisory (AV26-290) ","uuid":"02295b37-bb98-4ade-a029-7f13bc5e6364","banner":null,"lang":"en","date_modified":"2026-03-27","date_modified_ts":"2026-03-27T14:44:21Z","date_created":"2026-03-27T14:41:08Z","summary":null,"body":["<article data-history-node-id=\"7455\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-290\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-290<br \/><strong>Date: <\/strong>March 27, 2026<\/p>\n\n<p>On March 26, 2026, Siemens published a security advisory to address vulnerabilities in the following products. Included were updates for the following products:<\/p>\n\n<ul><li>CPCI85 Central Processing\/Communication \u2013 versions prior to V26.10<\/li>\n\t<li>RTUM85 RTU Base \u2013 versions prior to V26.10<\/li>\n\t<li>SICORE Base system \u2013 versions prior to V26.10.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-246443.html\">SSA-246443: Multiple Vulnerabilities in SICAM 8 Products<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-290","alert_type":398,"serial_number":"AV26-290","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7456,"title":"FreeBSD security advisory (AV26-291)","uuid":"0877afe8-544e-49a3-930f-3abd404b2336","banner":null,"lang":"en","date_modified":"2026-03-27","date_modified_ts":"2026-03-27T14:50:17Z","date_created":"2026-03-27T14:46:05Z","summary":null,"body":["<article data-history-node-id=\"7456\" about=\"\/en\/alerts-advisories\/freebsd-security-advisory-av26-291\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-291<br \/><strong>Date: <\/strong>March 27, 2026<\/p>\n\n<p>Between March 25 and 26, 2026, FreeBSD published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FreeBSD \u2013 version 14.x<\/li>\n\t<li>FreeBSD \u2013 version 15.0<\/li>\n\t<li>FreeBSD \u2013 version 13.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:06.tcp.asc\">TCP: remotely exploitable DoS vector (mbuf leak) (CVE-2026-4247)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:07.nvmf.asc\">Remote denial of service via null pointer dereference (CVE-2026-4652)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:08.rpcsec_gss.asc\">Remote code execution via RPCSEC_GSS packet validation (CVE-2026-4747)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:09.pf.asc\">pf silently ignores certain rules (CVE-2026-4748)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/\">FreeBSD Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freebsd-security-advisory-av26-291","alert_type":396,"serial_number":"AV26-291","subject":"other","moderation_state":"published","external_url":null},{"nid":7457,"title":"Ericsson security advisory (AV26-292)","uuid":"ce9b1797-e123-4565-8713-520195b5b61f","banner":null,"lang":"en","date_modified":"2026-03-27","date_modified_ts":"2026-03-27T14:54:54Z","date_created":"2026-03-27T14:52:03Z","summary":null,"body":["<article data-history-node-id=\"7457\" about=\"\/en\/alerts-advisories\/ericsson-security-advisory-av26-292\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-292<br \/><strong>Date: <\/strong>March 27, 2026<\/p>\n\n<p>On March 25, 2026, Ericsson published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ericsson Indoor Connect 8855 \u2013 versions prior to 2025.Q3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/psirt\/security-bulletin-indoorconnect-march-2026\">Security Bulletin \u2013 Ericsson Indoor Connect 8855, March, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/security-bulletins\">Ericsson Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ericsson-security-advisory-av26-292","alert_type":396,"serial_number":"AV26-292","subject":"other","moderation_state":"published","external_url":null},{"nid":7458,"title":"Microsoft Edge security advisory (AV26-293)","uuid":"416a9fa3-4249-45e8-9dad-5f11f9c55499","banner":null,"lang":"en","date_modified":"2026-03-27","date_modified_ts":"2026-03-27T18:20:56Z","date_created":"2026-03-27T18:18:15Z","summary":null,"body":["<article data-history-node-id=\"7458\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-293\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-293<br \/><strong>Date: <\/strong>March 27, 2026<\/p>\n\n<p>On March 26, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 146.0.3856.84<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#march-26-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-293","alert_type":396,"serial_number":"AV26-293","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7460,"title":"AL26-006 - Vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-3055","uuid":"ba796f88-b17d-4867-92f5-7c39333e830f","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T15:06:04Z","date_created":"2026-03-30T12:00:05Z","summary":null,"body":["<article data-history-node-id=\"7460\" about=\"\/en\/alerts-advisories\/al26-006-vulnerability-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-3055\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-006<br \/><strong>Date:<\/strong> March\u00a030, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a critical vulnerability impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>NetScaler ADC is an application delivery and security platform designed to optimize the performance, security, and scalability of applications.<\/p>\n\n<p>NetScaler Gateway is a secure remote access solution developed by Citrix that provides single sign-on (SSO) capabilities for applications, enhancing user experience and security.<\/p>\n\n<p>In response to the vendor advisory released on March 23, 2026, the Cyber Centre released AV26-267 on March 23, <span class=\"nowrap\">2026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/span><\/p>\n\n<p>Tracked as CVE-2026-3055<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is an insufficient input validation vulnerability (CWE-125)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> leading to a memory overread allowing a remote, unauthenticated attacker to access sensitive information stored in memory. Pre-conditions for this vulnerability are that the NetScaler ADC or NetScaler Gateway must be configured as a SAML IdP (Security Assertion Markup Language Identity Provider).<\/p>\n\n<p>Further information about the impacted configurations of your appliance can be found in the Citrix advisory<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>This Alert only applies to customer-managed NetScaler ADC and NetScaler Gateway. The Citrix Cloud Software Group has already upgraded Citrix-managed cloud services and Citrix-managed Adaptive Authentication instances with the necessary software updates related to these vulnerabilities.<\/p>\n\n<p>The Cyber Centre has observed open-source reporting indicating that the vulnerability is being exploited in the wild since March 27, 2026<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations using Citrix NetScaler ADC and NetScaler Gateway appliances (particularly for SAML IDP-configured appliances), review the Citrix security bulletin<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and update or upgrade the affected systems to the following versions:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway 14.1-60.58 and later releases of 14.1<\/li>\n\t<li>NetScaler ADC\u202fand NetScaler Gateway 13.1-62.23 and later releases of 13.1<\/li>\n\t<li>NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.262 and later releases of 13.1-FIPS and 13.1-NDcPP<\/li>\n<\/ul><p>Citrix has provided steps to take if NetScaler ADC or NetScaler Gateway are suspected to be compromised<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>, which includes:<\/p>\n\n<ul><li>Preserve evidence.<\/li>\n\t<li>If possible, avoid switching off the machine in order to preserve the traces needed for investigations.<\/li>\n\t<li>Completely isolate the machine concerned from the network, both from the Internet and from the internal network, in order to limit the risk of further unauthorized access and lateral movement.<\/li>\n\t<li>Revoke credentials and access.<\/li>\n\t<li>Examine all servers and systems to which the NetScaler ADC had connected for signs of compromise.<\/li>\n\t<li>Rebuild and restore.<\/li>\n\t<li>Rotate restored secrets.<\/li>\n\t<li>Harden the device.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.citrix.com\/external\/article\/CTX696300\/netscaler-adc-and-netscaler-gateway-secu.html\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-267\">AV26-267\u00a0\u2013 Citrix security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-3055\">CVE-2026-3055 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/125.html\">CWE-125: Out-of-bounds Read<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/labs.watchtowr.com\/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2\/\">Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part\u00a02)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694799\">Citrix\u00a0\u2013 Steps to Take if NetScaler ADC is Suspected to be Compromised<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-006-vulnerability-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-3055","alert_type":397,"serial_number":"AL26-006","subject":"other","moderation_state":"published","external_url":null},{"nid":7461,"title":"IBM security advisory (AV26-294)","uuid":"92fd33cb-3952-48d7-bf3f-0e53f5e6932c","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T14:38:59Z","date_created":"2026-03-30T14:13:35Z","summary":null,"body":["<article data-history-node-id=\"7461\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-294\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-294<br \/><strong>Date: <\/strong>March 30, 2026<\/p>\n\n<p>Between March 23 and 29, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Communications Server for AIX\u00a0\u2013 version 6.4<\/li>\n<li>Communications Server for Data Center Deployment\u00a0\u2013 versions 7.0 to 7.1<\/li>\n<li>Communications Server for Linux on System z\u00a0\u2013 version 6.4<\/li>\n<li>Communications Server for Linux\u00a0\u2013 version 6.4<\/li>\n<li>DataPower Operations Dashboard\u00a0\u2013 versions 1.0.23.1 to 1.0.23.2<\/li>\n<li>DataStage on Cloud Pak for Data\u00a0\u2013 version 5.3.1<\/li>\n<li>IBM App Connect Enterprise Certified Containers Operands\u00a0\u2013 multiple versions<\/li>\n<li>IBM App Connect Enterprise\u00a0\u2013 versions 12.0.1.0 to 12.0.12.23<\/li>\n<li>IBM App Connect Enterprise\u00a0\u2013 versions 13.0.1.0 to 13.0.6.2<\/li>\n<li>IBM App Connect Operator\u00a0\u2013 multiple versions<\/li>\n<li>IBM CICS TX Standard\u00a0\u2013 version 11.1<\/li>\n<li>IBM Common Licensing\u00a0\u2013 multiple versions<\/li>\n<li>IBM DevOps Release\u00a0\u2013 versions 7.0.0 to 7.0.0.5<\/li>\n<li>IBM Event Endpoint Management\u00a0\u2013 versions 11.0.0 to 11.7.2<\/li>\n<li>IBM Industry Solutions Workbench\u00a0\u2013 version 5.0.0.0 and 5.1.0.0<\/li>\n<li>IBM InfoSphere Optim Archive Viewer\u00a0\u2013 versions 11.7 FixPack09 to 11.7 FixPack12<\/li>\n<li>IBM Knowledge Catalog Standard Cartridge\u00a0\u2013 multiple versions<\/li>\n<li>IBM MQ Operator\u00a0\u2013 multiple versions<\/li>\n<li>IBM Security QRadar Log Management AQL Plugin\u00a0\u2013 versions 1.0.0 to 1.1.3<\/li>\n<li>IBM SPSS Modeler\u00a0\u2013 multiple versions<\/li>\n<li>IBM Storage Protect Operations Center\u00a0\u2013 version 8.2.0<\/li>\n<li>IBM WebSphere Automation\u00a0\u2013 versions 1.11.0 to 1.11.1<\/li>\n<li>IBM supplied MQ Advanced container images\u00a0\u2013 multiple versions<\/li>\n<li>IBM watsonx Code Assistant On Prem\u00a0\u2013 multiple versions<\/li>\n<li>IBM webMethods BPM\u00a0\u2013 version 11.1 and 10.15<\/li>\n<li>InfoSphere Information Server\u00a0\u2013 versions 11.7.0.0 to 11.7.1.6<\/li>\n<li>SOAR App Host\u00a0\u2013 multiple versions<\/li>\n<li>Sterling Connect:Direct FTP+\u00a0\u2013 versions 1.3.0.0 to 1.3.0.3<\/li>\n<li>UCB\u00a0- IBM UrbanCode Build\u00a0\u2013 version 6.1.7 to 6.1.7.9<\/li>\n<li>UCR\u00a0- IBM UrbanCode Release\u00a0\u2013 versions 6.2.5 to 6.2.5.11<\/li>\n<li>WebSphere Extreme Scale\u00a0\u2013 version 8.6.1.0 to 8.6.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-294","alert_type":396,"serial_number":"AV26-294","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7464,"title":"[Control systems] CISA ICS security advisories (AV26-297)","uuid":"0e20e09b-f0c9-4820-803e-e8d537ec7e43","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T15:17:40Z","date_created":"2026-03-30T14:22:07Z","summary":null,"body":["<article data-history-node-id=\"7464\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-297\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-297<br \/><strong>Date: <\/strong>March\u00a030, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between March\u00a023 and 29, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Grassroots DICOM (GDCM)\u00a0\u2013 version 3.2.2<\/li>\n\t<li>Pharos Controls Mosaic Show Controller\u00a0\u2013 firmware version 2.15.3<\/li>\n\t<li>OpenCode Systems OC Messaging and USSD Gateway\u00a0\u2013 version 6.32.2<\/li>\n\t<li>PTC Windchill Product Lifecycle Management\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Schneider Electric EcoStruxure Foxboro DCS\u00a0\u2013 versions prior to CS8.1<\/li>\n\t<li>Schneider Electric Plant iT\/Brewmaxx\u00a0\u2013 version 9.60_and_above<\/li>\n\t<li>WAGO GmbH &amp; Co. KG Industrial Managed Switches\u00a0\u2013 multiple firmware version<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-297","alert_type":398,"serial_number":"AV26-297","subject":"ics","moderation_state":"published","external_url":null},{"nid":7466,"title":"Red Hat security advisory (AV26-298)","uuid":"e253cd9f-d581-467f-b72e-ae76842cee49","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T15:18:59Z","date_created":"2026-03-30T14:22:07Z","summary":null,"body":["<article data-history-node-id=\"7466\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-298\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-298<br \/><strong>Date: <\/strong>March\u00a030, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between March\u00a023 and 29, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-298","alert_type":396,"serial_number":"AV26-298","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7467,"title":"Hitachi security advisory (AV26-299)","uuid":"74604700-f500-4398-962e-3df9df6be905","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T15:20:43Z","date_created":"2026-03-30T14:22:08Z","summary":null,"body":["<article data-history-node-id=\"7467\" about=\"\/en\/alerts-advisories\/hitachi-security-advisory-av26-299\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-299<br \/><strong>Date:<\/strong> March\u00a030, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On March\u00a027, 2026, Hitachi published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Hitachi Disk Array Systems\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.hitachi.com\/products\/it\/storage-solutions\/sec_info\/2026\/2026_307.html\">Security information for Hitachi Disk Array Systems<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/index.html\">Hitachi Vulnerability Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hitachi-security-advisory-av26-299","alert_type":396,"serial_number":"AV26-299","subject":"other","moderation_state":"published","external_url":null},{"nid":7462,"title":"Dell security advisory (AV26-295)","uuid":"d8584c2e-b316-4acf-a955-e0ba297a9f40","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T14:59:12Z","date_created":"2026-03-30T14:42:34Z","summary":null,"body":["<article data-history-node-id=\"7462\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-295\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-295<br \/><strong>Date: <\/strong>March 30, 2026<\/p>\n\n<p>Between March 23 and 29, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift\u00a0\u2013 multiple versions<\/li>\n<li>APEX Cloud Platforms Solution Offerings\u00a0\u2013 multiple versions<\/li>\n<li>APEX\u00a0\u2013 multiple versions<\/li>\n<li>Dell Secure Connect Gateway Appliance\u00a0\u2013 versions prior to 5.34.00.16<\/li>\n<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 6.0.0.2<\/li>\n<li>Dell Storage Resource Manager\u00a0\u2013 versions prior to 6.0.0.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000443243\/dsa-2026-152-dell-secure-connect-gateway-security-update-for-multiple-third-party-component-vulnerabilities\">DSA-2026-152: Dell Secure Connect Gateway Security Update for Multiple Third-Party Component Vulnerabilities.<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000443791\/dsa-2026-111-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">DSA-2026-111: Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR) Security Update for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n  \t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000444451\/dsa-2026-151-security-update-for-dell-apex-cloud-platform-for-red-hat-openshift-for-multiple-third-party-component-vulnerabilities\">DSA-2026-151: Security Update for Dell APEX Cloud Platform for Red Hat OpenShift for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-295","alert_type":396,"serial_number":"AV26-295","subject":"dell","moderation_state":"published","external_url":null},{"nid":7465,"title":"Roundcube security advisory (AV26-300)","uuid":"d4eb8089-96e0-466f-8fa7-c413f010ed10","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T15:26:13Z","date_created":"2026-03-30T14:53:09Z","summary":null,"body":["<article data-history-node-id=\"7465\" about=\"\/en\/alerts-advisories\/roundcube-security-advisory-av26-300\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-300<br \/><strong>Date: <\/strong>March 30, 2026<\/p>\n\n<p>On March 29, 2026, Roundcube published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Webmail\u00a0\u2013 versions prior to 1.6.15<\/li>\n\t<li>Webmail\u00a0\u2013 versions prior to 1.5.15<\/li>\n\t<li>Webmail\u00a0\u2013 versions prior to 1.7 RC6<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.6.15\">Roundcube Webmail 1.6.15<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.5.15\">Roundcube Webmail 1.5.15<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.7-rc6\">Roundcube Webmail 1.7 RC6<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/roundcube-security-advisory-av26-300","alert_type":396,"serial_number":"AV26-300","subject":"other","moderation_state":"published","external_url":null},{"nid":7463,"title":"Ubuntu security advisory (AV26-296)","uuid":"8bcd8ba1-d56a-4d40-b7f2-81e259bab88a","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T15:09:27Z","date_created":"2026-03-30T15:00:02Z","summary":null,"body":["<article data-history-node-id=\"7463\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-296\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-296<br \/><strong>Date: <\/strong>March 30, 2026<\/p>\n\n<p>Between March 23 and 29, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-296","alert_type":396,"serial_number":"AV26-296","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7468,"title":"Docker security advisory (AV26\u2013301)","uuid":"4dda9f5f-6e9a-44ef-a532-2960501361a9","banner":null,"lang":"en","date_modified":"2026-03-30","date_modified_ts":"2026-03-30T15:39:55Z","date_created":"2026-03-30T15:21:06Z","summary":null,"body":["<article data-history-node-id=\"7468\" about=\"\/en\/alerts-advisories\/docker-security-advisory-av26-301\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-301<br \/><strong>Date: <\/strong>March 30, 2026<\/p>\n\n<p>On March 30, 2026, Docker published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Docker Desktop\u00a0\u2013 versions prior to 4.67.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.docker.com\/security\/security-announcements\/#docker-desktop-4670-security-update-cve-2026-33990\">Docker Desktop 4.67.0 security update: CVE-2026-33990<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/docker-security-advisory-av26-301","alert_type":396,"serial_number":"AV26-301","subject":"other","moderation_state":"published","external_url":null},{"nid":7469,"title":"Nokia security advisory (AV26-302)","uuid":"ed23d5cb-0e88-4871-8b04-86c34b01af3e","banner":null,"lang":"en","date_modified":"2026-03-31","date_modified_ts":"2026-03-31T13:33:16Z","date_created":"2026-03-31T13:05:27Z","summary":null,"body":["<article data-history-node-id=\"7469\" about=\"\/en\/alerts-advisories\/nokia-security-advisory-av26-302\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-302<br \/><strong>Date: <\/strong>March 31, 2026<\/p>\n\n<p>On March 30, 2026, Nokia published security advisories to address a vulnerability in the following products:<\/p>\n\n<ul><li>Nokia GX G42, GX G31, GX G32, GX G34\u00a0\u2013 versions prior to GX r9.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.nokia.com\/we-are-nokia\/security\/product-security-advisory\/cve-2026-34485\/\">CVE-2026-34485\u00a0- CLI ACL Bypass in GX G42<\/a><\/li>\n\t<li><a href=\"https:\/\/www.nokia.com\/we-are-nokia\/security\/product-security-advisory\/\">Nokia Product Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nokia-security-advisory-av26-302","alert_type":396,"serial_number":"AV26-302","subject":"other","moderation_state":"published","external_url":null},{"nid":7470,"title":"[Control systems] ABB security advisory (AV26-303)","uuid":"7a7f1996-3b30-4176-9834-505e2a89a98f","banner":null,"lang":"en","date_modified":"2026-03-31","date_modified_ts":"2026-03-31T18:09:53Z","date_created":"2026-03-31T18:06:07Z","summary":null,"body":["<article data-history-node-id=\"7470\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-303\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-303<br \/><strong>Date: <\/strong>March\u00a031, 2026<\/p>\n\n<p>On March\u00a031, 2026, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB 800xA History\u00a0\u2013 version 7.0 and prior<\/li>\n\t<li>ABB Batch Management\u00a0\u2013 version 6.2 and prior<\/li>\n\t<li>ABB Production Response Batch History\u00a0\u2013 version 6.2 and prior<\/li>\n\t<li>ABB 800xA for Symphony Plus Harmony\u00a0\u2013 version 6.2 and prior<\/li>\n\t<li>ABB 800xA for AC 870P Melody\u00a0\u2013 version 6.2 and prior<\/li>\n\t<li>ABB Application Change Management\u00a0\u2013 version 6.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA023732&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">System 800xA affected by 3rd party component Vulnerabilities (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-303","alert_type":398,"serial_number":"AV26-303","subject":"abb","moderation_state":"published","external_url":null},{"nid":7471,"title":"Symantec security advisory (AV26-304)","uuid":"db8f580e-e9b4-4502-934f-982878862ba6","banner":null,"lang":"en","date_modified":"2026-03-31","date_modified_ts":"2026-03-31T18:16:56Z","date_created":"2026-03-31T18:06:08Z","summary":null,"body":["<article data-history-node-id=\"7471\" about=\"\/en\/alerts-advisories\/symantec-security-advisory-av26-304\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-304<br \/><strong>Date: <\/strong>March\u00a031, 2026<\/p>\n\n<p>On March\u00a030, 2026, Symantec published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Symantec Data Loss Prevention (DLP) Windows Endpoint\u00a0\u2013 versions prior to DLP 16.1 MP2 and DLP 25.1 MP1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37306\">Symantec Data Loss Prevention Security Update<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/symantec-security-advisory-av26-304","alert_type":396,"serial_number":"AV26-304","subject":"other","moderation_state":"published","external_url":null},{"nid":7474,"title":"HPE security advisory (AV26-305)","uuid":"af0eeacc-ff4f-45fd-8a05-91441cfb37ee","banner":null,"lang":"en","date_modified":"2026-03-31","date_modified_ts":"2026-03-31T18:33:50Z","date_created":"2026-03-31T18:21:55Z","summary":null,"body":["<article data-history-node-id=\"7474\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-305\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-305<br \/><strong>Date: <\/strong>March 31, 2026<\/p>\n\n<p>On March 31, 2026, HPE published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>HPE Telco Network Function Virtualization Orchestrator\u00a0\u2013 version v7.5.0 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05033en_us&amp;docLocale=en_US#hpesbnw05033-rev-1-hpe-telco-network-function-virt-0\">HPESBNW05033 rev.1\u00a0- HPE Telco Network Function Virtual Orchestrator, Improper Input Validation in the Undertow HTTP Server Core<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-305","alert_type":396,"serial_number":"AV26-305","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7499,"title":"Google Chrome security advisory (AV26-306) \u2013 Update 1","uuid":"41d56a99-846a-4d6b-863f-4189142157a3","banner":null,"lang":"en","date_modified":"2026-04-01","date_modified_ts":"2026-04-01T20:25:32Z","date_created":"2026-04-01T12:57:30Z","summary":null,"body":["<article data-history-node-id=\"7499\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-306\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-306<br \/><strong>Date: <\/strong>April\u00a01, 2026<br \/><strong>Updated:<\/strong> April 1, 2026<\/p>\n\n<p>On March\u00a031, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 146.0.7680.177\/178 (Windows\/Mac) and 146.0.7680.177 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2026-5281 exists in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On April 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-5281 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_31.html\">Google Chrome Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-5281\">CISA KEV: CVE-2026-5281<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-306","alert_type":396,"serial_number":"AV26-306","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7500,"title":"Cisco security advisory (AV26-307)","uuid":"f06f147c-b9ba-4d0b-b6d4-24db18ef2813","banner":null,"lang":"en","date_modified":"2026-04-01","date_modified_ts":"2026-04-01T19:28:35Z","date_created":"2026-04-01T19:16:10Z","summary":null,"body":["<article data-history-node-id=\"7500\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-307\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-307<br \/><strong>Date:<\/strong> April 1, 2026<\/p>\n\n<p>On April 1, 2026, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco NFVIS Release\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco IMC Release\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco Telemetry Broker Appliances\u00a0\u2013 version 6.0(2.260044) (M6) and prior<\/li>\n\t<li>IEC6400 Edge Compute Appliances\u00a0\u2013 version 4.3(6.260017) (M6) and prior<\/li>\n\t<li>Secure Endpoint Private Cloud Appliances\u00a0\u2013 versions 4.3(2.260007) (M5) and 4.3(6.260017) (M6)<\/li>\n\t<li>Secure Firewall Management Center Appliances\u00a0\u2013 versions 4.3(2.260007) (M5) and 4.3(6.260017) (M6)<\/li>\n\t<li>Secure Malware Analytics Appliances\u00a0\u2013 versions 4.3(2.260007) (M5) and 4.3(6.260017) (M6)<\/li>\n\t<li>Secure Network Analytics Appliances\u00a0\u2013 versions 4.3(2.260007) (M5) and 6.0(2.260044) (M6)<\/li>\n\t<li>Secure Network Server Appliances\u00a0\u2013 multiple versions<\/li>\n\t<li>Cisco SSM On-Prem Release\u00a0\u2013 versions 9-202502 to 9-202510<\/li>\n\t<li>Cisco EPNM Release\u00a0\u2013 versions 8.0 and prior, version 8.1 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cimc-cmd-inj-3hKN3bVt\">Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cssm-priv-esc-xRAnOuO8\">Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-epnm-improp-auth-mUwFWUU3\">Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cimc-auth-bypass-AgG2BxTn\">Cisco Integrated Management Controller Authentication Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ssm-cli-execution-cHUcWuNr\">Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-307","alert_type":396,"serial_number":"AV26-307","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7501,"title":"Drupal security advisory (AV26-308)","uuid":"f12e9e84-faa3-4c2a-9c5f-8ee7d0b4f4b5","banner":null,"lang":"en","date_modified":"2026-04-01","date_modified_ts":"2026-04-01T19:43:45Z","date_created":"2026-04-01T19:37:03Z","summary":null,"body":["<article data-history-node-id=\"7501\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-308\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-308<br \/><strong>Date: <\/strong>April 1, 2026<\/p>\n\n<p>On April 1, 2026, Drupal published a security advisory to address a critical vulnerability in the following product\u00a0:<\/p>\n\n<ul><li>SAML SSO\u00a0- Service Provider\u00a0\u2013 versions prior to 3.1.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-031\">SAML SSO\u00a0- Service Provider\u00a0- Critical\u00a0- Authentication bypass\u00a0- SA-CONTRIB-2026-031<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-308","alert_type":396,"serial_number":"AV26-308","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7503,"title":"WatchGuard security advisory (AV26-309)","uuid":"78dad0e4-cc91-4113-bb0e-915d8826f15e","banner":null,"lang":"en","date_modified":"2026-04-02","date_modified_ts":"2026-04-02T15:27:55Z","date_created":"2026-04-02T15:22:43Z","summary":null,"body":["<article data-history-node-id=\"7503\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-309\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-309<br \/><strong>Date:<\/strong> April 2, 2026<\/p>\n\n<p>On April 1, 2026, WatchGuard published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>\n\t<p>Fireware OS 2025-1\u00a0- versions 2025.1 to 2026.1.2<\/p>\n\t<\/li>\n\t<li>\n\t<p>Fireware OS 12.x\u00a0- versions 12.6.1 to 12.11.8<\/p>\n\t<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00009\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web<\/span> UI<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">WatchGuard Security Advisories<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-309","alert_type":396,"serial_number":"AV26-309","subject":"other","moderation_state":"published","external_url":null},{"nid":7504,"title":"Progress security advisory (AV26-310)","uuid":"ff70e77c-c9c0-4107-b9ee-1c344bcbd83a","banner":null,"lang":"en","date_modified":"2026-04-02","date_modified_ts":"2026-04-02T18:37:57Z","date_created":"2026-04-02T18:30:52Z","summary":null,"body":["<article data-history-node-id=\"7504\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-310\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-310<br \/><strong>Date:<\/strong> April 2, 2026<\/p>\n\n<p>On April 2, 2026, Progress published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Progress ShareFile\u00a0- versions prior to v5.12.4 and versions prior to v6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.sharefile.com\/en-us\/storage-zones-controller\/5-0\/security-vulnerability-feb26 \">Security Vulnerability Fix For ShareFile Storage Zones Controller 5.x (February 2026)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-310","alert_type":396,"serial_number":"AV26-310","subject":"other","moderation_state":"published","external_url":null},{"nid":7505,"title":"Cesanta security advisory (AV26-311)","uuid":"8cd1f0a2-c36b-445e-94c9-44a7565e0bf7","banner":null,"lang":"en","date_modified":"2026-04-02","date_modified_ts":"2026-04-02T18:49:23Z","date_created":"2026-04-02T18:41:18Z","summary":null,"body":["<article data-history-node-id=\"7505\" about=\"\/en\/alerts-advisories\/cesanta-security-advisory-av26-311\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-311<br \/><strong>Date:<\/strong> April 2, 2026<\/p>\n\n<p>On April 2, 2026, Cesanta published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Mongoose\u00a0- versions 7.0 to 7.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/cesanta\/mongoose\">Cesanta Mongoose<\/a><\/li>\n\t<li><a href=\"https:\/\/mongoose.ws\/\">Mongoose.ws<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cesanta-security-advisory-av26-311","alert_type":396,"serial_number":"AV26-311","subject":"other","moderation_state":"published","external_url":null},{"nid":7507,"title":"OpenSSH security advisory (AV26-312)","uuid":"06d93431-3fcf-4314-b36e-79054e060c55","banner":null,"lang":"en","date_modified":"2026-04-02","date_modified_ts":"2026-04-02T19:53:07Z","date_created":"2026-04-02T19:45:59Z","summary":null,"body":["<article data-history-node-id=\"7507\" about=\"\/en\/alerts-advisories\/openssh-security-advisory-av26-312\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-312<br \/><strong>Date:<\/strong> April 2, 2026<\/p>\n\n<p>On April 2, 2026, OpenSSH published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSH\u00a0- versions prior to 10.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.openssh.org\/releasenotes.html\">OpenSSH 10.3 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.openssh.com\/\">OpenSSH<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssh-security-advisory-av26-312","alert_type":396,"serial_number":"AV26-312","subject":"other","moderation_state":"published","external_url":null},{"nid":7508,"title":"Fortinet security advisory (AV26-313)","uuid":"efe6e601-afca-47c1-a8d0-60665db71174","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T12:02:51Z","date_created":"2026-04-07T11:55:56Z","summary":null,"body":["<article data-history-node-id=\"7508\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-313\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-313<br \/><strong>Date: <\/strong>April\u00a07, 2026<\/p>\n\n<p>On April\u00a04, 2026, Fortinet published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>FortiClientEMS 7.4\u00a0\u2013 version 7.4.5 to 7.4.6<\/li>\n<\/ul><p>On April\u00a06, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-35616 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-099\">API authentication and authorization bypass<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-35616\">CISA KEV: CVE-2026-35616<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-313","alert_type":396,"serial_number":"AV26-313","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7509,"title":"Android security advisory \u2013 April 2026 monthly rollup (AV26-314)","uuid":"e9c40c9a-74c0-4119-830f-74d7583b5665","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T15:15:50Z","date_created":"2026-04-07T14:36:56Z","summary":null,"body":["<article data-history-node-id=\"7509\" about=\"\/en\/alerts-advisories\/android-security-advisory-april-2026-monthly-rollup-av26-314\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-314<br \/><strong>Date:<\/strong> April 7, 2026<\/p>\n\n<p>On April 6, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-04-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-april-2026-monthly-rollup-av26-314","alert_type":396,"serial_number":"AV26-314","subject":"android","moderation_state":"published","external_url":null},{"nid":7510,"title":"Microsoft Edge security advisory (AV26-315)","uuid":"5c15d02c-6240-4a23-b844-541f30e15260","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T15:28:53Z","date_created":"2026-04-07T15:21:47Z","summary":null,"body":["<article data-history-node-id=\"7510\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-315\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-315<br \/><strong>Date:<\/strong> April 7, 2026<\/p>\n\n<p>On April 1, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0- versions prior to 146.0.3856.97<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2026-5281 has an available exploit.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-1-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-315","alert_type":396,"serial_number":"AV26-315","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7511,"title":"AL26-007 - Vulnerability impacting Fortinet FortiClientEMS - CVE-2026-35616","uuid":"54f0aeb5-f968-4229-b511-9d2525e2c610","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T18:07:26Z","date_created":"2026-04-07T17:03:51Z","summary":null,"body":["<article data-history-node-id=\"7511\" about=\"\/en\/alerts-advisories\/al26-007-vulnerability-impacting-fortinet-forticlientems-cve-2026-35616\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-007<br \/><strong>Date:<\/strong> April\u00a07, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a critical vulnerability impacting Fortinet FortiClient Endpoint Management Server <span class=\"nowrap\">(EMS)<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\">1<\/a><\/sup>.<\/span> In response to the vendor advisory released on April\u00a04, 2026, the Cyber Centre released AV26-313 on April\u00a07, <span class=\"nowrap\">2026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/span><\/p>\n\n<p>Tracked as CVE-2026-35616<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is an improper access control vulnerability (CWE-284)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> in Fortinet FortiClientEMS 7.4.5 through 7.4.6 that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.<\/p>\n\n<p>Fortinet FortiClientEMS is a centralized security management solution for Fortinet's endpoint agents (FortiClient). It enables administrators to manage, deploy, and monitor security policies, Zero Trust Network Access (ZTNA) tags, and vulnerability scanning for Windows, macOS, and mobile endpoints, primarily designed for enterprise security.<\/p>\n\n<p>Further information about the impacted versions of Fortinet instances can be found in the Fortinet advisory<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>This vulnerability was added to CISA's Known Exploited Vulnerabilities (KEV) catalog<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> on April\u00a06, 2026.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations using Fortinet FortiClientEMS, review the Fortinet security bulletin<sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and update or upgrade the affected instances to the following versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected version<\/th>\n\t\t\t<th scope=\"col\">Solution<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>FortiClientEMS\u00a07.4<\/td>\n\t\t\t<td>7.4.5<\/td>\n\t\t\t<td>Install hotfix<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> or upgrade to upcoming 7.4.7 or above<\/td>\n\t\t<\/tr><tr><td>FortiClientEMS\u00a07.4<\/td>\n\t\t\t<td>7.4.6<\/td>\n\t\t\t<td>Install hotfix<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> or upgrade to upcoming 7.4.7 or above<\/td>\n\t\t<\/tr><tr><td>FortiClientEMS\u00a07.2<\/td>\n\t\t\t<td>Not affected<\/td>\n\t\t\t<td>Not affected<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-099\">API authentication and authorization bypass<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-313\">AV26-313\u00a0\u2013 Fortinet security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-35616\">CVE-2026-35616 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/284\">CWE-284: Improper Access Control<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35616\">CISA KEV: CVE-2026-35616<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/docs.fortinet.com\/document\/forticlient\/7.4.5\/ems-release-notes\/832484\">Installing an EMS hotfix\u00a0| FortiClient 7.4.5\u00a0| Fortinet Document Library<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/docs.fortinet.com\/document\/forticlient\/7.4.6\/ems-release-notes\/832484\">Installing an EMS hotfix\u00a0| FortiClient 7.4.6\u00a0| Fortinet Document Library<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-007-vulnerability-impacting-fortinet-forticlientems-cve-2026-35616","alert_type":397,"serial_number":"AL26-007","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7512,"title":"IBM security advisory (AV26-316)","uuid":"2d232663-2388-4083-af68-825c7ec62dc5","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T18:47:37Z","date_created":"2026-04-07T18:23:46Z","summary":null,"body":["<article data-history-node-id=\"7512\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-316\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-316<br \/><strong>Date:<\/strong> April 7, 2026<\/p>\n\n<p>Between March 30 and April 5, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>API Connect V12 OnPrem\u00a0- versions 12.1.0.0 and 12.1.0.1<\/li>\n\t<li>Automation Assets in IBM Cloud Pak for Integration (CP4I)\u00a0- multiple versions<\/li>\n\t<li>DB2 Client and Server\u00a0- versions 12.1.0 to 12.1.4<\/li>\n\t<li>EDB PGAI AI Factory\u00a0- version 1.3.0.0<\/li>\n\t<li>EDB PGAI Analytics Accelarator\u00a0- version 1.3.0.0<\/li>\n\t<li>EDB PGAI Hybrid Data Management\u00a0- version 1.3.0.<\/li>\n\t<li>EDB PostgreSQL with IBM for IBM Cloud Pak for Data\u00a0- version 5.3.0<\/li>\n\t<li>HMC\u00a0- versions V10.3.1050.0 to V10.3.1063.1<\/li>\n\t<li>HMC\u00a0- versions V11.1.1110.0 to V11.1.1111.4<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\u00a0- versions 13.0.6.0-r1 to 13.0.6.2-r1<\/li>\n\t<li>IBM App Connect Operator\u00a0- versions 12.19.0 to 12.21.0<\/li>\n\t<li>IBM Business Automation Manager Open Editions\u00a0- versions 9.0.0 to 9.3.1<\/li>\n\t<li>IBM Content Navigator\u00a0- version 3.0.15, 3.1.0 and 3.2.0<\/li>\n\t<li>IBM DataPower Gateway\u00a0- multiple versions<\/li>\n\t<li>IBM Guardium Data Security Center Platform On-prem\u00a0- version 3.8.7<\/li>\n\t<li>IBM Guardium Unified Discovery and Classification (GUDC)\u00a0- versions 1.0.0 to 1.1.0<\/li>\n\t<li>IBM Library Support for Spring\u00a0- versions 3.4, 3.2.19 and 2.7.31<\/li>\n\t<li>IBM Maximo Application Suite IoT Component\u00a0- version 9.1, 9.0, 8.8 and 8.7<\/li>\n\t<li>IBM OpenAPI SDK Generator (Node.js)\u00a0- version 5.4.9<\/li>\n\t<li>IBM Process Mining\u00a0- versions 2.1.0 IF002, 2.1.0 IF001 and 2.1.0<\/li>\n\t<li>IBM Rational Build Forge\u00a0- versions 8.0.0 to 8.0.0.29<\/li>\n\t<li>IBM Security Verify Access\u00a0- versions 10.0 to 10.0.9.1<\/li>\n\t<li>IBM Security Verify Access Container\u00a0- versions 10.0 to 10.0.9.1<\/li>\n\t<li>IBM Storage Protect Plus Server\u00a0-\u00a0- versions 10.1.0 to 10.1.17<\/li>\n\t<li>IBM Tivoli Netcool Impact\u00a0- versions 7.1.0.0 to 7.1.0.37<\/li>\n\t<li>IBM Verify Identity Access\u00a0- versions 11.0 to 11.0.2<\/li>\n\t<li>IBM Verify Identity Access Container\u00a0- versions 11.0 to 11.0.2<\/li>\n\t<li>IBM Verify Identity Access Digital Credentials\u00a0- versions 24.06 to 25.12<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0- versions 1.4.0 to 2.6.0<\/li>\n\t<li>InfoSphere Information Server\u00a0- versions 11.7.0.0 to 11.7.1.6<\/li>\n\t<li>Maximo AI Service\u00a0- version 9.1<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (CP4I)\u00a0- multiple versions<\/li>\n\t<li>UCR IBM DevOps Release\u00a0- versions 7.0.0 to 7.0.0.6<\/li>\n\t<li>UCR IBM UrbanCode Release\u00a0- versions 6.2.5 to 6.2.5.11<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-316","alert_type":396,"serial_number":"AV26-316","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7513,"title":"Ubuntu security advisory (AV26-317)","uuid":"966c0081-3247-4d66-bd3f-a98e8408f2b0","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T19:04:46Z","date_created":"2026-04-07T18:54:05Z","summary":null,"body":["<article data-history-node-id=\"7513\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-317\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-317<br \/><strong>Date:<\/strong> April 7, 2026<\/p>\n\n<p>Between March 30 and April 5, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-317","alert_type":396,"serial_number":"AV26-317","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7514,"title":"Red Hat security advisory (AV26-318)","uuid":"fc5c4803-cdf1-4354-95b3-a0d40d7b623b","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T19:28:54Z","date_created":"2026-04-07T19:23:07Z","summary":null,"body":["<article data-history-node-id=\"7514\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-318\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-318<br \/><strong>Date:<\/strong> April 7, 2026<\/p>\n\n<p>Between March 30 and April 5, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-318","alert_type":396,"serial_number":"AV26-318","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7515,"title":"VMware security advisory (AV26-319)","uuid":"b9760e81-6940-4dc8-a683-10fa6a21f386","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T19:40:52Z","date_created":"2026-04-07T19:34:35Z","summary":null,"body":["<article data-history-node-id=\"7515\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-319\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-319<br \/><strong>Date:<\/strong> April 7, 2026<\/p>\n\n<p>On April 2, 2026, VMware published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu Data Intelligence\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>VMware Tanzu Data Services\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>VMware Tanzu Data Services Pack\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>VMware Tanzu Data Services Solutions\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>VMware Tanzu Data Suite\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>VMware Tanzu for MySQL\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>VMware Tanzu Platform\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>Vmware Tanzu Platform SM\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n\t<li>VMware Tanzu SQL\u00a0\u2013 versions prior to MySQL for Kubernetes 2.0.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37340\">Product Release Advisory\u00a0- VMware Tanzu for MySQL on Kubernetes 2.0.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT \">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-319","alert_type":396,"serial_number":"AV26-319","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7516,"title":"Erlang security advisory (AV26-320)","uuid":"6a8cc40d-6baf-4801-bd4a-63f0df200157","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T19:52:40Z","date_created":"2026-04-07T19:44:32Z","summary":null,"body":["<article data-history-node-id=\"7516\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av26-320\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-320<br \/><strong>Date: <\/strong>April 7, 2026<\/p>\n\n<p>On April 7, 2026, Erlang published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>inets (OTP)\u00a0\u2013 versions prior to 9.1.0.6, 9.3.2.4 and 9.6.2<\/li>\n\t<li>OTP\u00a0\u2013 versions prior to 28.4.2, 27.3.4.10, and 26.2.5.19<\/li>\n\t<li>Public_key (OTP)\u00a0\u2013 versions prior to 1.17.1.2 and 1.20.3<\/li>\n\t<li>ssl (OTP)\u00a0\u2013 versions prior to 11.2.12.7 and 11.5.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-gxrm-pf64-99xm\">OCSP designated-responder authorization bypass\u00a0\u2014 missing signature verification (RFC 6960 \u00a74.2.2.2)<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-3vhp-h532-mc3f\">ScriptAlias CGI targets bypass `directory` auth (mod_auth vs mod_cgi path mismatch)<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\">Erlang Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av26-320","alert_type":396,"serial_number":"AV26-320","subject":"other","moderation_state":"published","external_url":null},{"nid":7517,"title":"Hitachi security advisory (AV26-321)","uuid":"df85fb99-a5fd-4d9b-b60d-eb15db39e05a","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T20:10:16Z","date_created":"2026-04-07T19:58:58Z","summary":null,"body":["<article data-history-node-id=\"7517\" about=\"\/en\/alerts-advisories\/hitachi-security-advisory-av26-321\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-321<br \/><strong>Date: <\/strong>April 7, 2026<\/p>\n\n<p>On April 7, 2026, Hitachi published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Hitachi Ops Center Common Services (Japanese version)\u00a0\u2013 versions prior to 11.0.8-00<\/li>\n\t<li>Hitachi Ops Center Common Services (English version)\u00a0\u2013 versions prior to 11.0.8-00<\/li>\n\t<li>Hitachi Ops Center Viewpoint (Japanese version)\u00a0\u2013 versions 11.0.2-00 to versions prior to 11.0.8-00<\/li>\n\t<li>Hitachi Ops Center Viewpoint data center proxy (Japanese version)\u00a0\u2013 versions 11.0.2-00 to versions prior to 11.0.8-00<\/li>\n\t<li>JP1\/IT Desktop Management (Manager)\u00a0\u2013 multiple versions<\/li>\n\t<li>Job Management Partner 1\/IT Desktop Management (Manager)\u00a0\u2013 multiple versions<\/li>\n\t<li>JP1\/IT Desktop Management 2 (Manager)\u00a0\u2013 multiple versions<\/li>\n\t<li>JP1\/IT Desktop Management 2 (Operations Director)\u00a0\u2013 multiple versions<\/li>\n\t<li>Job Management Partner 1\/IT Desktop Management 2 (Manager)\u00a0\u2013 versions 10-50 to 10-50-11<\/li>\n\t<li>JP1\/NETM\/DM (Manager)\u00a0\u2013 multiple versions<\/li>\n\t<li>JP1\/NETM\/DM (Client)\u00a0\u2013 multiple versions<\/li>\n\t<li>Job Management Partner 1\/Software Distribution (Manager)\u00a0\u2013 multiple versions<\/li>\n\t<li>Job Management Partner 1\/Software Distribution (Client)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-118\/index.html\">Multiple Vulnerabilities in JP1\/IT Desktop Management 2 and JP1\/NETM\/DM<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-117\/index.html\">Multiple Vulnerabilities in Hitachi Ops Center Common Services<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-115\/index.html\">Multiple Vulnerabilities in Hitachi Ops Center Viewpoint<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/index.html\">Hitachi Vulnerability Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hitachi-security-advisory-av26-321","alert_type":396,"serial_number":"AV26-321","subject":"other","moderation_state":"published","external_url":null},{"nid":7521,"title":"Dell security advisory (AV26-322)","uuid":"7c6a0e4b-e8cd-41ae-8f0f-c35472b0122b","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T20:27:07Z","date_created":"2026-04-07T20:26:41Z","summary":null,"body":["<article data-history-node-id=\"7521\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-322\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-322<br \/><strong>Date:<\/strong> April 7, 2026<\/p>\n\n<p>Between March 30 and April 5, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Networking OS10\u00a0\u2013 versions prior to 10.6.11<\/li>\n\t<li>Connectrix Switches and Directors\u00a0\u2013 versions prior to sannav_ova_9x_os_02_2026<\/li>\n\t<li>Elastic Cloud Storage\u00a0\u2013 versions prior to 3.8.1.7<\/li>\n\t<li>ObjectScale - versions prior to 4.1.0.3 and 4.2.00<\/li>\n\t<li>Dell Data Protection Central\u00a0\u2013 versions 19.9 to 19.12 with Data Protection Central OS Update prior to dpc-osupdate-1.1.26-1<\/li>\n\t<li>Dell PowerProtect DP Series Appliance\u00a0\u2013 versions prior to 2.7.9 with Data Protection Central OS Update prior to dpc-osupdate-1.1.26-1<\/li>\n\t<li>Dell PowerProtect Data Manager\u00a0\u2013 versions prior to 20.1.0.0<\/li>\n\t<li>Dell AppSync\u00a0\u2013 versions prior to 4.6.0.4<\/li>\n\t<li>Dell APEX Cloud Platform for Microsoft Azure\u00a0\u2013 versions prior to 01.07.01.00<\/li>\n\t<li>Unisphere for PowerMax Virtual Appliance\u00a0\u2013 versions prior to 9.2.4.20<\/li>\n\t<li>Solutions Enabler\u00a0\u2013 versions prior to 10.3.0.1 and 9.2.4.9<\/li>\n\t<li>Solutions Enabler Virtual Appliance\u00a0\u2013 versions prior to 9.2.4.9<\/li>\n\t<li>Dell PowerMax EEM 5978\u00a0\u2013 versions prior to 5978.720.720.11249<\/li>\n\t<li>Dell PowerMax EEM 10.3.1.0\u00a0\u2013 versions prior to 10.3.1.0 patch 11248<\/li>\n\t<li>Dell PowerMaxOS 5978\u00a0\u2013 versions prior to 5978.720.720.11249<\/li>\n\t<li>Dell PowerMaxOS 10.3.0.1\u00a0\u2013 versions prior to 10.3.0.1 patch 11248<\/li>\n\t<li>PowerSwitch Z9664F-ON\u00a0\u2013 versions prior to 3.54.5.1-11<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-322","alert_type":396,"serial_number":"AV26-322","subject":"dell","moderation_state":"published","external_url":null},{"nid":7518,"title":"Mozilla security advisory (AV26-323)","uuid":"1c4cfb13-bb06-45ca-9855-3c03aca3c560","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T20:44:55Z","date_created":"2026-04-07T20:38:14Z","summary":null,"body":["<article data-history-node-id=\"7518\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-323\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-323<br \/><strong>Date: <\/strong>April 7, 2026<\/p>\n\n<p>On April 7, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 149.0.2<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 34.1<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 9.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-27\/\">Security Vulnerabilities fixed in Firefox ESR 140.9.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-26\/\">Security Vulnerabilities fixed in Firefox ESR 115.34.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-25\/\">Security Vulnerabilities fixed in Firefox 149.0.2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-323","alert_type":396,"serial_number":"AV26-323","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7520,"title":"[Control systems] CISA ICS security advisories (AV26\u2013324)","uuid":"ddfe62d8-ca20-430b-83b7-9098e2f21971","banner":null,"lang":"en","date_modified":"2026-04-07","date_modified_ts":"2026-04-07T20:46:24Z","date_created":"2026-04-07T20:40:20Z","summary":null,"body":["<article data-history-node-id=\"7520\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-324\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013324<br \/><strong>Date: <\/strong>April 7, 2026<\/p>\n\n<p>Between March 30 and April 5, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Anritsu Remote Spectrum Monitor MS27100\u00a0\u2013 all versions<\/li>\n\t<li>Anritsu Remote Spectrum Monitor MS27101A\u00a0\u2013 all versions<\/li>\n\t<li>Anritsu Remote Spectrum Monitor MS27102A\u00a0\u2013 all versions<\/li>\n\t<li>Anritsu Remote Spectrum Monitor MS27103A\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Energy Ellipse\u00a0\u2013 version 9.0.50 and prior<\/li>\n\t<li>PX4 Autopilot\u00a0\u2013 v1.16.0_SITL_latest_stable (CVE-2026-1579)<\/li>\n\t<li>Siemens CPCI85 Central Processing\/Communication RTUM85 RTU Base\u00a0\u2013 versions prior to V26.10<\/li>\n\t<li>Siemens CPCI85 Central Processing\/Communication SICORE Base system\u00a0\u2013 versions prior to V26.10<\/li>\n\t<li>Yokogawa CENTUM VP\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-324","alert_type":398,"serial_number":"AV26-324","subject":"ics","moderation_state":"published","external_url":null},{"nid":7523,"title":"HPE security advisory (AV26-325)","uuid":"7f154ef3-8876-41a7-ba45-b8f5afeb142c","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T15:23:58Z","date_created":"2026-04-08T15:06:51Z","summary":null,"body":["<article data-history-node-id=\"7523\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-325\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-325<br \/><strong>Date:<\/strong> April 8, 2026<\/p>\n\n<p>On April 7, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking Private 5G Core\u00a0- version 1.25.3.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05032en_us&amp;docLocale=en_US#hpesbnw05032-rev-1-hpe-aruba-networking-private-5g-0\">HPESBNW05032 rev.1\u00a0- HPE Aruba Networking Private 5G Core On-Prem, Open Redirect Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-325","alert_type":396,"serial_number":"AV26-325","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7524,"title":"CUPS security advisory (AV26-326)","uuid":"2c40b774-e0bd-4c12-9361-73fbebf9a2b7","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T15:35:11Z","date_created":"2026-04-08T15:26:46Z","summary":null,"body":["<article data-history-node-id=\"7524\" about=\"\/en\/alerts-advisories\/cups-security-advisory-av26-326\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-326<br \/><strong>Date:<\/strong> April 8, 2026<\/p>\n\n<p>On April 5, 2026, OpenPrinting published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Common UNIX Printing Systems (CUPS)\u00a0- version 2.4.16 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates once available.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/heyitsas.im\/posts\/cups\/\">Spooler Alert: Remote Unauth'd RCE-to-root Chain in CUPS<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/OpenPrinting\/cups\/security\/advisories\/GHSA-c54j-2vqw-wpwp\">Local print admin token disclosure using temporary printers (CVE-2026-34990)<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/OpenPrinting\/cups\/security\/advisories\/GHSA-4852-v58g-6cwf\">Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (CVE-2026-34980)<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cups-security-advisory-av26-326","alert_type":396,"serial_number":"AV26-326","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7526,"title":"GitLab security advisory (AV26-327)","uuid":"1bb7ff5e-8cef-4f66-aadd-0f3f68ebef53","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T15:48:45Z","date_created":"2026-04-08T15:43:22Z","summary":null,"body":["<article data-history-node-id=\"7526\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-327\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-327<br \/><strong>Date:<\/strong> April 8, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 8, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0- versions prior to 18.10.3, 18.9.5 and 18.8.9<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0- versions prior to 18.10.3, 18.9.5 and 18.8.9<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/about.gitlab.com\/releases\/2026\/04\/08\/patch-release-gitlab-18-10-3-released\/\">GitLab Patch GitLab Patch Release: 18.10.3, 18.9.5, 18.8.9<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/ \">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-327","alert_type":396,"serial_number":"AV26-327","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7527,"title":"Mitel security advisory (AV26-328)","uuid":"c26ee928-32db-4976-8c77-153e953a5eb5","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T17:35:55Z","date_created":"2026-04-08T17:30:01Z","summary":null,"body":["<article data-history-node-id=\"7527\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av26-328\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-328<br \/><strong>Date:<\/strong> April 8, 2026<\/p>\n\n<p>On April 7, 2026, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Mitel<\/span> published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MiCollab\u00a0- version 10.2.0.24 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2026-0002\">Mitel Product Security Advisory MISA-2026-0002<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av26-328","alert_type":396,"serial_number":"AV26-328","subject":"mitel","moderation_state":"published","external_url":null},{"nid":7528,"title":"OpenSSL security advisory (AV26-329)","uuid":"7ef25827-88fd-4868-b665-6a4bfd1fd3df","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T17:46:30Z","date_created":"2026-04-08T17:40:53Z","summary":null,"body":["<article data-history-node-id=\"7528\" about=\"\/en\/alerts-advisories\/openssl-security-advisory-av26-329\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-329<br \/><strong>Date:<\/strong> April 8, 2026<\/p>\n\n<p>On April 7, 2026, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Open<\/span>SSL published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>OpenSSL\u00a0- versions 3.6.0 to versions prior to 3.6.2<\/li>\n\t<li>OpenSSL\u00a0- versions 3.5.0 to versions prior to 3.5.6<\/li>\n\t<li>OpenSSL\u00a0- versions 3.4.0 to versions prior to 3.4.5<\/li>\n\t<li>OpenSSL\u00a0- versions 3.3.0 to versions prior to 3.3.7<\/li>\n\t<li>OpenSSL\u00a0- versions 3.0.0 to versions prior to 3.0.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html\">OpenSSL Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory-av26-329","alert_type":396,"serial_number":"AV26-329","subject":"other","moderation_state":"published","external_url":null},{"nid":7529,"title":"Apache ActiveMQ security advisory (AV26-330) - Update 1","uuid":"9a4e77d5-017e-4a9a-bbd0-db3cdd9ae5c2","banner":null,"lang":"en","date_modified":"2026-04-16","date_modified_ts":"2026-04-16T17:59:30Z","date_created":"2026-04-08T19:06:27Z","summary":null,"body":["<article data-history-node-id=\"7529\" about=\"\/en\/alerts-advisories\/apache-activemq-security-advisory-av26-330\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-330<br \/><strong>Date:<\/strong> April 8, 2026<br \/><strong>Update:<\/strong> April 16, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 8, 2026, Apache published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Apache ActiveMQ Broker\u00a0- versions prior to 5.19.4<\/li>\n\t<li>Apache ActiveMQ Broker\u00a0- 6.0.0 versions prior to 6.2.3<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On April 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-34197 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/activemq.apache.org\/security-advisories.data\/CVE-2026-34197-announcement.txt\">CVE-2026-34197<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-34197\">CISA KEV: CVE-2026-34197<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-activemq-security-advisory-av26-330","alert_type":396,"serial_number":"AV26-330","subject":"other","moderation_state":"published","external_url":null},{"nid":7530,"title":"SonicWall security advisory (AV26-332)","uuid":"a12a029a-7deb-4140-8888-8f473e03d289","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T20:27:35Z","date_created":"2026-04-08T19:41:49Z","summary":null,"body":["<article data-history-node-id=\"7530\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-332\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-332<br \/><strong>Date: <\/strong>April 8, 2026<\/p>\n\n<p>On April 8, 2026, SonicWall published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SMA1000\u00a0\u2013 version 12.4.3-03245 (platform-hotfix) and prior<\/li>\n\t<li>SMA1000\u00a0\u2013 version 12.5.0-02283 (platform-hotfix) and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0003\">SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-332","alert_type":396,"serial_number":"AV26-332","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":7532,"title":"Palo Alto Networks security advisory (AV26-331)","uuid":"cf1ac369-95bb-4f7d-8821-ffa846735e92","banner":null,"lang":"en","date_modified":"2026-04-08","date_modified_ts":"2026-04-08T20:04:52Z","date_created":"2026-04-08T19:55:33Z","summary":null,"body":["<article data-history-node-id=\"7532\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-331\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-331<br \/><strong>Date: <\/strong>April 8, 2026<\/p>\n\n<p>On April 8, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Autonomous Digital Experience Manager 5.11.0\u00a0\u2013 versions prior to 5.11.4<\/li>\n\t<li>Cortex XDR Agent 9.0\u00a0\u2013 versions prior to 9.0.1 without CU-2120 on Windows<\/li>\n\t<li>Cortex XDR Agent 8.9\u00a0\u2013 versions prior to 8.9.1 without CU-2120 on Windows<\/li>\n\t<li>Cortex XDR Agent 8.7-CE\u00a0\u2013 versions prior to 8.7.101-CE without CU-2120 on Windows<\/li>\n\t<li>Cortex XDR Agent 8.3-CE\u00a0\u2013 all without CI-2120 on Windows<\/li>\n\t<li>Cortex XDR Agent 7.9-CE\u00a0\u2013 all without CI-2120 on Windows<\/li>\n\t<li>Cortex XSIAM Microsoft Teams Marketplace 1.5.0\u00a0\u2013 versions prior to 1.5.52<\/li>\n\t<li>Cortex XSOAR Microsoft Teams Marketplace 1.5.0\u00a0\u2013 versions prior to 1.5.52<\/li>\n\t<li>Prisma Browser\u00a0\u2013 versions prior to 145.16.12.110<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0234\">CVE-2026-0234 Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2026-0004\">PAN-SA-2026-0004 Chromium: Monthly Vulnerability Update (April 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0233\">CVE-2026-0233 Autonomous Digital Experience Manager: Improper validation of ADEM certificate<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0232\">CVE-2026-0232 Cortex XDR Agent: Local Administrator can disable the agent on Windows<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-331","alert_type":396,"serial_number":"AV26-331","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7533,"title":"HPE security advisory (AV26-333)","uuid":"cfb4bc7a-35fd-4998-b3b8-4c2a656256a7","banner":null,"lang":"en","date_modified":"2026-04-09","date_modified_ts":"2026-04-09T18:27:37Z","date_created":"2026-04-09T17:46:33Z","summary":null,"body":["<article data-history-node-id=\"7533\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-333\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-333<br \/><strong>Date: <\/strong>April 9, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 8, 2026, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Superdome Flex server\u00a0\u2013 versions prior to v4.10.18<\/li>\n\t<li>HPE Superdome Flex 280 server\u00a0\u2013 versions prior to v2.05.12<\/li>\n\t<li>HPE Compute Scale-Up Server 3200 Platform\u00a0\u2013 versions prior to v1.60.88<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf05030en_us&amp;docLocale=en_US\">HPESBHF05030 rev.1\u00a0- HPE Superdome Flex, Superdome Flex 280 and Compute Scale-up Server 3200 Platform Using Certain Intel Processor BIOS, INTEL-SA-01234, 2025.3 IPU, UEFI Reference Firmware Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-333","alert_type":396,"serial_number":"AV26-333","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7534,"title":"Juniper Networks security advisory (AV26-334)","uuid":"f6910fbc-0e7b-4216-b901-5233abeb5075","banner":null,"lang":"en","date_modified":"2026-04-09","date_modified_ts":"2026-04-09T18:39:39Z","date_created":"2026-04-09T18:30:59Z","summary":null,"body":["<article data-history-node-id=\"7534\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-334\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-334<br \/><strong>Date:<\/strong> April 9, 2026<\/p>\n\n<p>Between April 8 and 9, 2026, Juniper Networks published security advisories to address vulnerabilities in the multiple products. Included were updates for the following:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Apstra<\/span>\u00a0\u2013 versions prior to 6.1.1<\/li>\n\t<li>JSI vLWC\u00a0\u2013 versions prior to 3.0.94<\/li>\n\t<li>Junos OS\u00a0\u2013 versions prior to 21.2R3-S10 on SRX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 all 21.3 versions on SRX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 21.4 versions prior to 21.4R3-S12 on SRX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 all 22.1 versions on SRX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 22.2 versions prior to 22.2R3-S8 on SRX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 all 22.4 versions on SRX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 22.4 versions prior to 22.4R3-S9 on MX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 23.2 versions prior to 23.2R2-S6 on SRX and MX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 23.4 versions prior to 23.4R2-S7 on SRX and MX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 24.2 versions prior to 24.2R2-S3 on SRX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 24.2 versions prior to 24.2R2-S4 on MX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 24.4 versions prior to 24.4R2-S3 on SRX and MX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 25.2 versions prior to 25.2R1-S2, 25.2R2 on SRX and MX Series<\/li>\n\t<li>Junos OS\u00a0\u2013 versions prior to 22.4R3-S7<\/li>\n\t<li>Junos OS\u00a0- 23.2 versions prior to 23.2R2-S4<\/li>\n\t<li>Junos OS\u00a0\u2013 23.4 versions prior to 23.4R2-S7<\/li>\n\t<li>Junos OS\u00a0\u2013 24.2 versions prior to 24.2R1-S2, 24.2R2-S4<\/li>\n\t<li>Junos OS\u00a0\u2013 24.4 versions prior to 24.4R1-S2, 24.4R2-S3<\/li>\n\t<li>Junos OS\u00a0\u2013 25.2 versions prior to 25.2R1-S2, 25.2R2<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 versions prior to 21.2R3-S8-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0- 21.4 versions prior to 21.4R3-S7-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0- 22.2 versions prior to 22.2R3-S4-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0- 22.3 versions prior to 22.3R3-S3-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0- 22.4 versions prior to 22.4R3-S2-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0- 23.2 versions prior to 23.2R2-S4-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 23.4 versions prior to 23.4R2-S8-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 24.2 versions prior to 24.2R2-S4-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 24.4 versions prior to 24.4R1-S1-EVO, 24.4R2-S3-EVO<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 25.2 versions prior to 25.2R1-S2-EVO, 25.2R2-EVO<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri#sort=relevancy&amp;f:ctype=[Security%20Advisories]\">Juniper Networks<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-334","alert_type":396,"serial_number":"AV26-334","subject":"juniper","moderation_state":"published","external_url":null},{"nid":7535,"title":"Qualcomm security advisory \u2013 April 2026 monthly rollup (AV26-335)","uuid":"16fc2668-b816-489b-8289-03df97afa488","banner":null,"lang":"en","date_modified":"2026-04-09","date_modified_ts":"2026-04-09T19:14:10Z","date_created":"2026-04-09T19:08:44Z","summary":null,"body":["<article data-history-node-id=\"7535\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-april-2026-monthly-rollup-av26-335\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-335<br \/><strong>Date: <\/strong>April 9, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 6, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/april-2026-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 April<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-april-2026-monthly-rollup-av26-335","alert_type":396,"serial_number":"AV26-335","subject":"other","moderation_state":"published","external_url":null},{"nid":7536,"title":"Tenable security advisory (AV26-336) \u2013 Update 1","uuid":"84197287-c384-4850-aa6b-ef456eb68a0f","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T17:57:21Z","date_created":"2026-04-09T19:29:28Z","summary":null,"body":["<article data-history-node-id=\"7536\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-336\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-336<br \/><strong>Date:<\/strong> April 9, 2026<br \/><strong>Updated:<\/strong> April 13, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 9, 2026, Tenable published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Tenable Security Center\u00a0\u2013 version 6.5.0 to 6.8.0<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn April 13, 2026, Tenable updated affected products reflected above.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-10\">[R2] Stand-alone Security Patch Available for Tenable Security Center Versions 6.5.1, 6.6.0, 6.7.2 and 6.8.0: SC202604.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-336","alert_type":396,"serial_number":"AV26-336","subject":"trellix","moderation_state":"published","external_url":null},{"nid":7537,"title":"Google Chrome security advisory (AV26-337)","uuid":"f5780cfc-0e53-41b8-a027-ee1ef4adde2a","banner":null,"lang":"en","date_modified":"2026-04-10","date_modified_ts":"2026-04-10T13:18:48Z","date_created":"2026-04-10T13:11:47Z","summary":null,"body":["<article data-history-node-id=\"7537\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-337\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-337<br \/><strong>Date: <\/strong>April 10, 2026<\/p>\n\n<p>On April 7, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 147.0.7727.55\/56 (Windows\/Mac) and 147.0.7727.55 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/04\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-337","alert_type":396,"serial_number":" AV26-337","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7539,"title":"Ubuntu security advisory (AV26-338)","uuid":"e73028df-342e-48a6-be33-94c2b6fca1dd","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T13:56:13Z","date_created":"2026-04-13T13:53:47Z","summary":null,"body":["<article data-history-node-id=\"7539\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-338\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-338<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>Between April 6 and 12, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-338","alert_type":396,"serial_number":"AV26-338","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7540,"title":"[Control systems] CISA ICS security advisories (AV26\u2013339)","uuid":"0d8d0231-26ea-4b42-b3a9-a2b0dd40a732","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T14:07:43Z","date_created":"2026-04-13T14:02:39Z","summary":null,"body":["<article data-history-node-id=\"7540\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-339\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-339<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>Between April 6 and 12, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Contemporary Controls BASC 2OT \u2013 BASControl20 3.1<\/li>\n\t<li>GPL Odorizers GPL750 \u2013 multiple versions and models<\/li>\n\t<li>Mitsubishi Electric GENESIS64 and ICONICS \u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-339","alert_type":398,"serial_number":"AV26-339","subject":"other","moderation_state":"published","external_url":null},{"nid":7541,"title":"Adobe Acrobat security advisory (AV26-340) \u2013 Update 1","uuid":"e06ae784-8236-449d-8920-051ad0e2ec78","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T18:56:15Z","date_created":"2026-04-13T14:17:08Z","summary":null,"body":["<article data-history-node-id=\"7541\" about=\"\/en\/alerts-advisories\/adobe-acrobat-security-advisory-av26-340\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-340<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>On April 12, 2026, Adobe published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Acrobat Mac \u2013 versions prior to 24.001.30360<\/li>\n\t<li>Acrobat Windows \u2013 versions prior to 24.001.30362<\/li>\n\t<li>Acrobat DC \u2013 versions prior to 26.001.21411<\/li>\n\t<li>Acrobat Reader DC \u2013 versions prior to 26.001.21411<\/li>\n<\/ul><p>Adobe is aware of CVE-2026-34621 being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">\n  Update 1\n<\/h2>\n\n<p>\n  On April 13, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-34621 to their Known Exploited Vulnerabilities (KEV) Database.\n<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb26-43.html\">Security update available for Adobe Acrobat Reader - APSB26-43<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n  \n  <li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-34621\">CISA KEV: CVE-2026-34621<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-acrobat-security-advisory-av26-340","alert_type":396,"serial_number":"AV26-340","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7542,"title":"Red Hat security advisory (AV26-341)","uuid":"1a399577-674d-41d7-9331-2dab7265d179","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T14:29:50Z","date_created":"2026-04-13T14:27:24Z","summary":null,"body":["<article data-history-node-id=\"7542\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-341\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-341<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>Between April 6 and 12, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-341","alert_type":396,"serial_number":"AV26-341","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7543,"title":"IBM security advisory (AV26-342)","uuid":"f4a851b0-ece2-4094-997d-cb69a0c51e45","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T14:35:41Z","date_created":"2026-04-13T14:31:19Z","summary":null,"body":["<article data-history-node-id=\"7543\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-342\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-342<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>Between April 6 and 12, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>DevOps Test Performance \u2013 versions 11.0 to 11.0.7<\/li>\n\t<li>EDB PGAI \u2013 multiple versions and models<\/li>\n\t<li>EDB PGAI Databases \u2013 version 18.0<\/li>\n\t<li>IBM App Connect Operator \u2013 multiple versions<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands \u2013 multiple versions<\/li>\n\t<li>IBM ApplinX \u2013 version 11.1<\/li>\n\t<li>IBM Cloud Pak for AIOps \u2013 versions 4.1.0 to 4.12.0<\/li>\n\t<li>IBM DataPower Gateway \u2013 multiple versions and models<\/li>\n\t<li>IBM Knowledge Catalog Premium Cartridge \u2013 multiple versions<\/li>\n\t<li>IBM Planning Analytics Local \u2013 versions 2.1.0 to 2.1.18<\/li>\n\t<li>IBM OpenAPI SDK Generator (Node.js) \u2013 version 5.4.9<\/li>\n\t<li>IBM Operations Analytics - Log Analysis \u2013 multiple versions<\/li>\n\t<li>IBM Storage Defender Copy Data Management \u2013 versions 2.2.0.0 to 2.2.28.1<\/li>\n\t<li>IBM Storage Sentinel Anomaly Scan Engine \u2013 versions 1.1.0 to 1.1.11<\/li>\n\t<li>IBM Tivoli Business Service Manager \u2013 version 6.2.0<\/li>\n\t<li>IBM Tivoli Business Netcool Impact \u2013 version 7.1.1<\/li>\n\t<li>IBM Tivoli Network Manager IP Edition \u2013 versions 4.2 GA to 4.2.0.23<\/li>\n\t<li>ITCAM for Transactions \u2013 version 7.4.0.2<\/li>\n\t<li>Rational Performance Tester \u2013 multiple versions<\/li>\n\t<li>watsonx.data \u2013 version 2.3<\/li>\n\t<li>watsonx Code Assistant On Prem \u2013 multiple versions<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition \u2013 versions 1.4.0 to 2.6.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/ \">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-342","alert_type":396,"serial_number":"AV26-342","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7545,"title":"Dell security advisory (AV26-343)","uuid":"5b1137fd-d6e6-4249-9066-7225aa6be3ea","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T17:24:32Z","date_created":"2026-04-13T16:00:06Z","summary":null,"body":["<article data-history-node-id=\"7545\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-343\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-343<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>Between April 6 and 12, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Connectrix Switches and Directors \u2013 versions prior to sannav_ova_9x_os_02_2026<\/li>\n\t<li>Data Protection Advisor \u2013 versions 19.9 to 19.12 SP2<\/li>\n\t<li>Dell AX System \u2013 multiple versions and models<\/li>\n\t<li>Dell Data Protection Central \u2013 versions 19.9 to 19.12 with Data Protection Central OS Update prior to dpc-osupdate-1.1.26-1<\/li>\n\t<li>Dell EMC Isilon OneFS \u2013 versions 8.2.2 and prior<\/li>\n\t<li>Dell EMC PowerScale \u2013 version 9.0.0<\/li>\n\t<li>Dell Integrated System for Microsoft Azure Stack Hub 16G \u2013 versions prior to 2603<\/li>\n\t<li>Dell Networking OS10 \u2013 versions prior to 10.6.1.1<\/li>\n\t<li>Dell PowerProtect DP Series Appliance \u2013 versions prior to 2.7.9 with Data Protection Central OS Update prior to dpc-osupdate-1.1.26-1<\/li>\n\t<li>Dell PowerScale OneFS \u2013 multiple versions<\/li>\n\t<li>Elastic Cloud Storage \u2013 versions prior to 3.8.1.7<\/li>\n\t<li>ObjectScale - versions prior to 4.1.0.3 and 4.2.00<\/li>\n\t<li>PowerSwitch Z9664F-ON \u2013 versions prior to 3.54.5.1-11<\/li>\n\t<li>PowerSwitch S5448F-ON \u2013 versions prior to 3.54.5.1-14<\/li>\n\t<li>PowerSwitch S9664F-ON \u2013 versions prior to 3.54.5.1-11<\/li>\n\t<li>PowerSwitch E3200-ON \u2013 versions prior to 3.57.5.1-6<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-343","alert_type":396,"serial_number":"AV26-343","subject":"dell","moderation_state":"published","external_url":null},{"nid":7546,"title":"wolfSSL security advisory (AV26-344)","uuid":"2f0691e3-6014-499a-aa9e-a15021246cea","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T17:32:55Z","date_created":"2026-04-13T17:27:55Z","summary":null,"body":["<article data-history-node-id=\"7546\" about=\"\/en\/alerts-advisories\/wolfssl-security-advisory-av26-344\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-344<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>On April 9, 2026, wolfSSL published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>wolfSSL \u2013 versions 3.12.0 to versions prior to 5.9.1<\/li>\n<\/ul><p>CVE-2026-5194 is listed as critical with a CVSS score of 9.3.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/wolfSSL\/wolfssl\/releases\">wolfssl<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/advisories\/GHSA-f5h9-5q52-qrx7\">Missing hash\/digest size and OID checks allow digests...<\/a><\/li>\n\t<li><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/295.html\">CWE-295 Improper Certificate Validation<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-5194\">CVE-2026-5194<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wolfssl-security-advisory-av26-344","alert_type":396,"serial_number":"AV26-344","subject":"other","moderation_state":"published","external_url":null},{"nid":7547,"title":"Microsoft Edge security advisory (AV26-345)","uuid":"7af9df70-0a04-4b6e-8b03-2e8f8cba3a8d","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T19:28:22Z","date_created":"2026-04-13T19:08:31Z","summary":null,"body":["<article data-history-node-id=\"7547\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-345\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-345<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>On April 10, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 147.0.3912.60<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-10-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-345","alert_type":396,"serial_number":"AV26-345","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7548,"title":"[Control systems] ABB security advisory (AV26-346)","uuid":"820bb8f2-e8e2-48e5-9542-18d5909817ad","banner":null,"lang":"en","date_modified":"2026-04-13","date_modified_ts":"2026-04-13T19:44:04Z","date_created":"2026-04-13T19:33:41Z","summary":null,"body":["<article data-history-node-id=\"7548\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-346\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-346<br \/><strong>Date: <\/strong>April 13, 2026<\/p>\n\n<p>On April 13, 2026, ABB published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB CI868 AC800M product line (System 800xA) for IEC 61850\u00a0- multiple firmware versions<\/li>\n\t<li>ABB CI850 Symphony Plus SD Series product line for IEC 61850\u00a0- multiple firmware versions<\/li>\n\t<li>ABB PM 877 Symphony Plus MR (Melody Rack) product line for IEC 61850\u00a0\u2013 firmware version 3.10 to 3.52<\/li>\n\t<li>ABB S+ Operations using IEC 61850\u00a0- multiple versions<\/li>\n\t<li>ABB Ability Symphony Plus\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA020125&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">Denial of Service Vulnerabilities in System 800xA, Symphony Plus IEC 61850 communication stack CVE ID: CVE-2025-3756 <\/a><\/li>\n\t<li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA017341&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">PostgreSQL vulnerabilities in ABB Ability Symphony Plus Engineering CVE ID: CVE-2023-5869, CVE-2023-39417, CVE-2024-7348, CVE-2024-0985 <\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-346","alert_type":398,"serial_number":"AV26-346","subject":"abb","moderation_state":"published","external_url":null},{"nid":7550,"title":"[Control systems] Siemens security advisory (AV26-347)","uuid":"e2a2ccf3-ab45-42d2-aacb-40095e75e00d","banner":null,"lang":"en","date_modified":"2026-04-14","date_modified_ts":"2026-04-14T13:44:28Z","date_created":"2026-04-14T13:38:08Z","summary":null,"body":["<article data-history-node-id=\"7550\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-347\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-347<br \/><strong>Date: <\/strong>April 14, 2026<\/p>\n\n<p>On April 14, 2026, Siemens published a security advisory to address vulnerabilities in the following products. Included were updates for the following products:<\/p>\n\n<ul><li>Siemens Software Center \u2013 versions prior to V3.5.8.2<\/li>\n\t<li>Simcenter 3D \u2013 versions prior to V2506.6000<\/li>\n\t<li>Simcenter Femap \u2013 versions prior to V2506.0002<\/li>\n\t<li>Simcenter STAR-CCM+ \u2013 versions prior to V2602<\/li>\n\t<li>Solid Edge SE2025 \u2013 versions prior to V225.0 Update 13<\/li>\n\t<li>Solid Edge SE2026 \u2013 versions prior to V226.0 Update 04<\/li>\n\t<li>Tecnomatix Plant Simulation \u2013 versions prior to V2504.0008<\/li>\n\t<li>SINEC NMS \u2013 versions prior to V4.0 SP3 with UMC<\/li>\n\t<li>RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) \u2013 versions prior to V5.8<\/li>\n\t<li>SIPROTEC 5 - CP300 Devices \u2013 multiple versions and models<\/li>\n\t<li>SIPROTEC 5 Communication Modules \u2013 multiple versions and models<\/li>\n\t<li>SIPROTEC 5 Compact 7SX800 (CP050) \u2013 versions V8.70 to V9.30<\/li>\n\t<li>SIMATIC CN 4100 \u2013 hardware versions prior to FS 05<\/li>\n\t<li>SIMATIC Field PG \u2013 all versions<\/li>\n\t<li>SIMATIC IPC family \u2013 all versions<\/li>\n\t<li>SIMATIC IPC MD-57A \u2013 versions prior to V30.01.10<\/li>\n\t<li>SIMATIC ITP1000 \u2013 all versions<\/li>\n\t<li>Industrial Edge Management Pro V1 \u2013 versions V1.7.6 to V1.15.17<\/li>\n\t<li>Industrial Edge Management Pro V2 \u2013 versions V2.0.0 to V2.1.1<\/li>\n\t<li>Industrial Edge Management Virtual \u2013 versions V2.2.0 to V2.8.0<\/li>\n\t<li>SINEC NMS \u2013 versions prior to V4.0 SP3<\/li>\n\t<li>RUGGEDCOM CROSSBOW Station Access Controller (SAC) \u2013 versions prior to V5.8<\/li>\n\t<li>SCALANCE W-700 IEEE 802.11n family \u2013 versions prior to V6.6.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-347","alert_type":398,"serial_number":"AV26-347","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7551,"title":"Samsung mobile security advisory (AV26-348)","uuid":"b200498f-d645-4d06-ba43-1e142a1ca9f1","banner":null,"lang":"en","date_modified":"2026-04-14","date_modified_ts":"2026-04-14T13:54:27Z","date_created":"2026-04-14T13:51:10Z","summary":null,"body":["<article data-history-node-id=\"7551\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-348\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-348<br \/><strong>Date: <\/strong>April 14, 2026<\/p>\n\n<p>On April 7, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices \u2013 versions prior to SMR-APR-2026 Release 1<\/li>\n<\/ul><p>The most recent security update resolves multiple identified vulnerabilities.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=04\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-348","alert_type":396,"serial_number":"AV26-348","subject":"other","moderation_state":"published","external_url":null},{"nid":7552,"title":"SAP security advisory \u2013 April 2026 monthly rollup (AV26-349)","uuid":"4c63f09e-8b99-461a-aabe-33c8c0c9055c","banner":null,"lang":"en","date_modified":"2026-04-14","date_modified_ts":"2026-04-14T14:06:43Z","date_created":"2026-04-14T13:57:41Z","summary":null,"body":["<article data-history-node-id=\"7552\" about=\"\/en\/alerts-advisories\/sap-security-advisory-april-2026-monthly-rollup-av26-349\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-349<br \/><strong>Date: <\/strong>April 14, 2026<\/p>\n\n<p>On April 14, 2026, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP Business Planning and Consolidation and SAP Business Warehouse \u2013 versions HANABPC 810, BPC4HANA 300, SAP_BW 750, 752, 753, 754, 755, 756, 757, 758 and 816<\/li>\n\t<li>SAP ERP and SAP S\/4 HANA (Private Cloud and On-Premise) \u2013 versions SAP_FIN 618, 720, 730, EA-FIN 617, 700, SAPSCORE 135, S4CORE 102, 103, 104, 105, 106, 107, 108, 109, EA-APPL 600, 602, 603, 604, 605 and 606<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform \u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP Human Capital Management for SAP S\/4HANA \u2013 versions S4HCMRXX 100, 101, 102, SAP_HRRXX 600, 604 and 608<\/li>\n\t<li>SAP Business Analytics and SAP Content Management \u2013 versions S4HCMRXX 100, 101, 102, SAP_HRRXX 600, 604 and 608<\/li>\n\t<li>SAP S\/4HANA OData Service (Manage Reference Equipment) \u2013 version S4CORE 109<\/li>\n\t<li>SAP S\/4HANA Backend OData Service (Manage Reference Structures) \u2013 version S4CORE 109<\/li>\n\t<li>SAP S\/4HANA Frontend OData Service (Manage Reference Structures) \u2013 version UIS4H 109<\/li>\n\t<li>SAP Supplier Relationship Management (SICF Handler in SRM Catalog) \u2013 versions SRM_SERVER 702, 713 and 714<\/li>\n\t<li>SAP NetWeaver Application Server Java (Web Dynpro Java) \u2013 version WD-RUNTIME 7.50<\/li>\n\t<li>SAP NetWeaver Application Server ABAP \u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 and SAP_BASIS 816<\/li>\n\t<li>SAP HANA Cockpit and HANA Database Explorer \u2013 version SAP_HANA_COCKPIT 2.0<\/li>\n\t<li>SAP S\/4HANA (Private Cloud and On-Premise) \u2013 versions S4CORE 105, 106, 107, 108, 109, FI-CA 606, 616, 617 and 618<\/li>\n\t<li>Material Master Application \u2013 versions S4CORE 102, 103, 104, 105, 106, 107, 108, 109, SCM_BASIS 700, SCM_BASIS 701, SCM_BASIS 702, SCM_BASIS 712, SCM_BASIS 713 and SCM_BASIS 714<\/li>\n\t<li>SAP S\/4HANA OData Service (Manage Technical Object Structures) \u2013 version S4CORE 109<\/li>\n\t<li>SAP S4CORE (Manage Journal Entries) \u2013 versions S4CORE 104, 105, 106, 107 and 108<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform \u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP NetWeaver Application Server ABAP \u2013 versions SAP_UI 758 and 816<\/li>\n\t<li>SAP Landscape Transformation \u2013 versions DMIS 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020, S4CORE 102, 103, 104, 105, 106, 107, 108 and 109<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/april-2026.html\">SAP Security Patch Day - April 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-april-2026-monthly-rollup-av26-349","alert_type":396,"serial_number":"AV26-349","subject":"sap","moderation_state":"published","external_url":null},{"nid":7555,"title":"[Control systems] Schneider Electric security advisory (AV26-350) ","uuid":"5235da84-2df1-4de9-a091-794c1c1cdc6d","banner":null,"lang":"en","date_modified":"2026-04-14","date_modified_ts":"2026-04-14T17:28:55Z","date_created":"2026-04-14T17:09:38Z","summary":null,"body":["<article data-history-node-id=\"7555\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-350\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-350<br \/><strong>Date: <\/strong>April 14, 2026<\/p>\n\n<p>On April 14, 2026, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Easergy MiCOM Px40 Series \u2013 multiple versions and models<\/li>\n\t<li>Connexium Managed Switches TCSESM \u2013 all versions<\/li>\n\t<li>Modicon Managed Switches MCSESM, MCSESP \u2013 all versions<\/li>\n\t<li>Modicon Redundancy Switches MCSESR \u2013 all versions<\/li>\n\t<li>PowerChute Serial Shutdown \u2013 version 1.4 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-104-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-104-03.pdf\">Use of Hard-coded Credentials vulnerability on Easergy MiCOM Px40 Series (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-104-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-104-02.pdf\">Third-Party vulnerability on Modicon Networking Managed Switches (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-104-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-104-01.pdf\">Multiple Vulnerabilities on PowerChute\u2122 Serial Shutdown (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-350","alert_type":398,"serial_number":"AV26-350","subject":"other","moderation_state":"published","external_url":null},{"nid":7556,"title":"Fortinet security advisory (AV26-351) \u2013 Update 2","uuid":"2c458fca-225b-45ba-9aa4-e2b34de782fb","banner":null,"lang":"en","date_modified":"2026-07-16","date_modified_ts":"2026-07-16T19:18:11Z","date_created":"2026-04-14T17:34:05Z","summary":null,"body":["<article data-history-node-id=\"7556\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-351\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-351<br \/><strong>Date: <\/strong>April 14, 2026<br \/><strong>Updated:<\/strong> July 16, 2026<\/p>\n\n<p>On April 14, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiSandbox 4.4 \u2013 versions 4.4.0 to 4.4.8<\/li>\n\t<li>FortiSandbox 5.0 \u2013 versions 5.0.0 to 5.0.5<\/li>\n\t<li>FortiAnalyzer Cloud 7.6 \u2013 versions 7.6.2 to 7.6.4<\/li>\n\t<li>FortiManager Cloud 7.6 \u2013 versions 7.6.2 to 7.6.4<\/li>\n\t<li>FortiDDoS-F 7.2 \u2013 versions 7.2.1 to 7.2.2<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 have been exploited.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-39808 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-100\">OS Command Injection through API endpoint<\/a><\/li>\n\t<li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-112\">Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox<\/a><\/li>\n\t<li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-121\">Heap-based buffer overflow in oftpd daemon<\/a><\/li>\n\t<li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-119\">SQL Injection via API<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808\">CISA KEV\u00a0: CVE-2026-39808<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-351","alert_type":396,"serial_number":"AV26-351","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7557,"title":"Microsoft security advisory \u2013 April 2026 monthly rollup (AV26-352) - Update 3","uuid":"dd9be573-bb0e-432c-a1da-306041074653","banner":null,"lang":"en","date_modified":"2026-04-28","date_modified_ts":"2026-04-28T17:39:01Z","date_created":"2026-04-14T18:44:45Z","summary":null,"body":["<article data-history-node-id=\"7557\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-april-2026-monthly-rollup-av26-352\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-352<br \/><strong>Date: <\/strong>April 14, 2026<br \/><strong>Updated: <\/strong>April 28, 2026<\/p>\n\n<p>On April 14, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>.NET 10.0 installed on Linux<\/li>\n\t<li>.NET 10.0 installed on Mac OS<\/li>\n\t<li>.NET 10.0 installed on Windows<\/li>\n\t<li>.NET 8.0 installed on Linux<\/li>\n\t<li>.NET 8.0 installed on Mac OS<\/li>\n\t<li>.NET 8.0 installed on Windows<\/li>\n\t<li>.NET 9.0 installed on Linux<\/li>\n\t<li>.NET 9.0 installed on Mac OS<\/li>\n\t<li>.NET 9.0 installed on Windows<\/li>\n\t<li>Azure Logic Apps<\/li>\n\t<li>Azure Monitor Agent<\/li>\n\t<li>Microsoft .NET Framework<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.8.1<\/li>\n\t<li>Microsoft .NET Framework 4.6.2\/4.7\/4.7.1\/4.7.2<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Defender Antimalware Platform<\/li>\n\t<li>Microsoft Dynamics 365<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft HPC Pack 2019<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft Power Apps<\/li>\n\t<li>Microsoft PowerPoint 2016<\/li>\n\t<li>Microsoft SQL Server 2016<\/li>\n\t<li>Microsoft SQL Server 2017<\/li>\n\t<li>Microsoft SQL Server 2019<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SQL Server 2025<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Microsoft Visual Studio Code CoPilot Chat Extension<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>PowerShell<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Admin Center<\/li>\n\t<li>Windows App Client for Windows Desktop<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p>Microsoft has received reports that CVE-2026-32201 has been exploited.<\/p>\n\n<p>On April 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-32201 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that the CVE-2026-33825 vulnerability is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On April 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-33825 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 3<\/h2>\n\n<p>On April 28, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-32202 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Apr\">April 2026 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-32201\">CISA KEV: CVE-2026-32201<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-33825\">CVE-2026-33825 Detail<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33825\">CISA KEV: CVE-2026-33825<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32202\">CISA KEV: CVE-2026-32202<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-april-2026-monthly-rollup-av26-352","alert_type":396,"serial_number":"AV26-352","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7558,"title":"Adobe security advisory (AV26-353)","uuid":"6052c571-ec4a-4ec7-9eb1-c8811491eff8","banner":null,"lang":"en","date_modified":"2026-04-14","date_modified_ts":"2026-04-14T18:57:46Z","date_created":"2026-04-14T18:52:58Z","summary":null,"body":["<article data-history-node-id=\"7558\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-353\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-353<br \/><strong>Date: <\/strong>April 14, 2026<\/p>\n\n<p>On April 14, 2026, Adobe published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Acrobat 2024 \u2013 version Win: 24.001.30362 and prior, Mac: 24.001.30360 and prior<\/li>\n\t<li>Acrobat DC \u2013 version 26.001.21411 and prior<\/li>\n\t<li>Acrobat Reader DC \u2013 version 26.001.21411 and prior<\/li>\n\t<li>Adobe Bridge \u2013 version 15.1.4 (LTS) and prior, version 16.0.2 and prior<\/li>\n\t<li>Adobe Connect Desktop Application \u2013 version 2025.3 and prior<\/li>\n\t<li>Adobe Connect \u2013 version 12.10 and prior<\/li>\n\t<li>Adobe DNG Software Development Kit (SDK) \u2013 versions DNG SDK 1.7.1 build 2502 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM) Screens \u2013 version 6.5 Service Pack 24 and prior, version Feature Pack 11.7 and prior<\/li>\n\t<li>Adobe FrameMaker \u2013 version 2022 Release Update 8 and prior<\/li>\n\t<li>Adobe InCopy \u2013 version 21.2 and prior, version 20.5.2 and prior<\/li>\n\t<li>Adobe InDesign \u2013 version ID21.22 and prior, version ID20.5.2 and prior<\/li>\n\t<li>ColdFusion 2023 \u2013 version Update 18 and prior<\/li>\n\t<li>ColdFusion 2025 \u2013 version Update 6 and prior<\/li>\n\t<li>Illustrator 2025 \u2013 version 29.8.5 and prior<\/li>\n\t<li>Illustrator 2026 \u2013 version 30.2 and prior<\/li>\n\t<li>Photoshop 2026 \u2013 version 27.4 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-353","alert_type":396,"serial_number":"AV26-353","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7560,"title":"Tenable security advisory (AV26-354)","uuid":"279426b1-a111-4523-ac59-2e789272aaf8","banner":null,"lang":"en","date_modified":"2026-04-14","date_modified_ts":"2026-04-14T19:51:27Z","date_created":"2026-04-14T19:49:00Z","summary":null,"body":["<article data-history-node-id=\"7560\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-354\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-354<br \/><strong>Date: <\/strong>April 14, 2026<\/p>\n\n<p>On April 14, 2026, Tenable published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Tenable Identity Exposure \u2013 versions prior to 3.77.17<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-11\">[R2] Tenable Identity Exposure Version 3.77.17 Fixes Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-354","alert_type":396,"serial_number":"AV26-354","subject":"other","moderation_state":"published","external_url":null},{"nid":7562,"title":"AMD security advisory (AV26-355)","uuid":"c11e7fea-4eba-4558-a3f5-b37b50f3a787","banner":null,"lang":"en","date_modified":"2026-04-15","date_modified_ts":"2026-04-15T16:17:44Z","date_created":"2026-04-15T16:07:53Z","summary":null,"body":["<article data-history-node-id=\"7562\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-355\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-355<br \/><strong>Date: <\/strong>April 15, 2026<\/p>\n\n<p>On April 14, 2026, AMD published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AMD EPYC Processors\u00a0\u2013 multiple versions and models<\/li>\n\t<li>AMD Ryzen Processors\u00a0\u2013 multiple versions and models<\/li>\n\t<li>AMD Ryzen Embedded Processors\u00a0\u2013 multiple versions and models<\/li>\n\t<li>AMD EPYC Embedded Processors\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7054.html\">Incorrect use of LocateProtocol Service of the EFI_BOOT_Services table in SMI Handler\u00a0- AMD-SB-7054<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-3016.html\">IOMMU Write Buffer Vulnerability\u00a0- AMD-SB-3016<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-3034.html\">SEV-SNP Routing Misconfiguration\u00a0- AMD-SB-3034<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD Product Security<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-355","alert_type":396,"serial_number":"AV26-355","subject":"other","moderation_state":"published","external_url":null},{"nid":7563,"title":"Splunk security advisory (AV26-356)","uuid":"ff7f6b52-3c12-451c-a50f-d3f59eace375","banner":null,"lang":"en","date_modified":"2026-04-15","date_modified_ts":"2026-04-15T16:27:08Z","date_created":"2026-04-15T16:19:41Z","summary":null,"body":["<article data-history-node-id=\"7563\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-356\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-356<br \/><strong>Date: <\/strong>April 15, 2026<\/p>\n\n<p>On April 15, 2026, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk Operator for Kubernetes Add-on\u00a0\u2013 versions prior to 3.1.0<\/li>\n<li>Splunk MCP Server\u00a0\u2013 versions prior to 1.0.3<\/li>\n<li>Splunk IT Service Intelligence (ITSI)\u00a0\u2013 versions prior to 4.21.2<\/li>\n<li>Splunk Enterprise\u00a0\u2013 multiple versions<\/li>\n<li>Splunk Cloud Platform\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\">Splunk Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-356","alert_type":396,"serial_number":"AV26-356","subject":"other","moderation_state":"published","external_url":null},{"nid":7564,"title":"Cisco security advisory (AV26-357)","uuid":"c876fd50-ec30-41dd-9f86-738aa4d4b2fa","banner":null,"lang":"en","date_modified":"2026-04-15","date_modified_ts":"2026-04-15T17:26:27Z","date_created":"2026-04-15T17:17:17Z","summary":null,"body":["<article data-history-node-id=\"7564\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-357\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-357<br \/><strong>Date: <\/strong>April 15, 2026<\/p>\n\n<p>On April 15, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>Cisco Identity Services Engine (ISE)\u00a0\u2013 multiple versions<\/li>\n  <li>Cisco ISE Passive Identity Connector (ISE-PIC)\u00a0\u2013 multiple versions<\/li>\n<li>Cisco Webex Services (cloud-based, configured to use SSO integration with Control Hub)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-rce-traversal-8bYndVrZ\">Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-rce-4fverepv\">Cisco Identity Services Engine Remote Code Execution Vulnerabilities<\/a><\/li>\n  \t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-webex-cui-cert-8jSZYhWL\">Cisco Webex Services Certificate Validation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-357","alert_type":396,"serial_number":"AV26-357","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7565,"title":"Google Chrome security advisory (AV26-358)","uuid":"79310f29-3ac0-47f8-9522-1b9fe7d91850","banner":null,"lang":"en","date_modified":"2026-04-15","date_modified_ts":"2026-04-15T19:39:20Z","date_created":"2026-04-15T19:35:49Z","summary":null,"body":["<article data-history-node-id=\"7565\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-358\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-358<br \/><strong>Date: <\/strong>April 15, 2026<\/p>\n\n<p>On April 15, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 147.0.7727.101\/102 (Windows\/Mac) and 147.0.7727.101 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/04\/stable-channel-update-for-desktop_15.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-358","alert_type":396,"serial_number":"AV26-358","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7566,"title":"Drupal security advisory (AV26-359)","uuid":"45bdcc20-83b5-4865-8e4c-6d752396aaad","banner":null,"lang":"en","date_modified":"2026-04-16","date_modified_ts":"2026-04-16T12:48:41Z","date_created":"2026-04-16T12:38:25Z","summary":null,"body":["<article data-history-node-id=\"7566\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-359\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-359<br \/><strong>Date: <\/strong>April 16, 2026<\/p>\n\n<p>On April 15, 2026, Drupal published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Drupal core \u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-core-2026-001\">Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-359","alert_type":396,"serial_number":"AV26-359","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7567,"title":"Nginx UI security advisory (AV26-360)","uuid":"47670533-8ac8-4cfa-913f-21cc611ecae6","banner":null,"lang":"en","date_modified":"2026-04-16","date_modified_ts":"2026-04-16T15:06:47Z","date_created":"2026-04-16T15:04:20Z","summary":null,"body":["<article data-history-node-id=\"7567\" about=\"\/en\/alerts-advisories\/nginx-ui-security-advisory-av26-360\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-360<br \/><strong>Date: <\/strong>April 16, 2026<\/p>\n\n<p>On April 10, 2026, Nginx UI published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Nginx UI \u2013 version v2.3.5 and prior<\/li>\n<\/ul><p>Open-source reporting indicates that the CVE-2026-33032 vulnerability is being exploited in the wild.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/0xJacky\/nginx-ui\/releases\/tag\/v2.3.6\">Nginx UI - CVE-2026-33032<\/a><\/li>\n\t<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-33032\">NVD - CVE-2026-33032 Detail<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nginx-ui-security-advisory-av26-360","alert_type":396,"serial_number":"AV26-360","subject":"other","moderation_state":"published","external_url":null},{"nid":7568,"title":"HPE security advisory (AV26-361)","uuid":"607f39fc-9451-442d-830a-edc879dd1b68","banner":null,"lang":"en","date_modified":"2026-04-16","date_modified_ts":"2026-04-16T17:46:04Z","date_created":"2026-04-16T17:25:26Z","summary":null,"body":["<article data-history-node-id=\"7568\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-361\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-361<br \/><strong>Date: <\/strong>April 16, 2026<\/p>\n\n<p>On April 16, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Cray Supercomputing EX420 Compute Blade \u2013 versions prior to 1.91<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbcr05043en_us&amp;docLocale=en_US#hpesbcr05043-rev-1-hpe-cray-supercomputing-ex-serv-0\">HPESBCR05043 rev.1 - HPE Cray Supercomputing EX Servers Using Intel Processors, INTEL-SA-01397, 2026.1 IPU, Intel Trust Domain Extensions (Intel TDX) module Advisory, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-361","alert_type":396,"serial_number":"AV26-361","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7569,"title":"Microsoft Edge security advisory (AV26-362)","uuid":"7c165544-817b-4a68-9768-bbd18de859d4","banner":null,"lang":"en","date_modified":"2026-04-17","date_modified_ts":"2026-04-17T13:06:02Z","date_created":"2026-04-17T12:50:32Z","summary":null,"body":["<article data-history-node-id=\"7569\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-362\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-362<br \/><strong>Date: <\/strong>April 17, 2026<\/p>\n\n<p>On April 16, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 147.0.3912.72<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-16-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-362","alert_type":396,"serial_number":"AV26-362","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7570,"title":"HashiCorp security advisory (AV26-363)","uuid":"0e1804f1-56d7-4a63-a66c-42a251161df5","banner":null,"lang":"en","date_modified":"2026-04-17","date_modified_ts":"2026-04-17T13:20:40Z","date_created":"2026-04-17T13:09:46Z","summary":null,"body":["<article data-history-node-id=\"7570\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-363\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-363<br \/><strong>Date: <\/strong>April 17, 2026<\/p>\n\n<p>On April 16, 2026, HashiCorp published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Vault Community Edition \u2013 multiple versions<\/li>\n\t<li>Vault Enterprise Edition \u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-05-vault-kvv2-metadata-and-secret-deletion-policy-bypass-denial-of-service\/77342\">HCSEC-2026-05 - Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-06-vault-vulnerable-to-server-side-request-forgery-in-acme-challenge-validation-via-attacker-controlled-dns\/77343\">HCSEC-2026-06 - Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/c\/security\/52\">HashiCorp Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-363","alert_type":396,"serial_number":"AV26-363","subject":"other","moderation_state":"published","external_url":null},{"nid":7571,"title":"JetBrains security advisory (AV26-364)","uuid":"82b07b07-2f8d-4fcb-a43a-f620968e4d58","banner":null,"lang":"en","date_modified":"2026-04-17","date_modified_ts":"2026-04-17T13:30:37Z","date_created":"2026-04-17T13:24:29Z","summary":null,"body":["<article data-history-node-id=\"7571\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-364\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-364<br \/><strong>Date: <\/strong>April 17, 2026<\/p>\n\n<p>On April 17, 2026, JetBrains published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>JetBrains Youtrack \u2013 versions prior to 2025.3.131383<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains \u2013 Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-364","alert_type":396,"serial_number":"AV26-364","subject":"other","moderation_state":"published","external_url":null},{"nid":7573,"title":"IBM security advisory (AV26-365)","uuid":"56d5e676-70c1-4d83-a85c-707367f324e4","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T13:05:43Z","date_created":"2026-04-20T12:55:35Z","summary":null,"body":["<article data-history-node-id=\"7573\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-365\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-365<br \/><strong>Date:<\/strong> April 20, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between April 13 and 19, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>API Connect\u00a0- versions V10.0.8.0 to V10.0.8.7<\/li>\n\t<li>Aspera Faspex 5\u00a0- versions 5.0.0 to 5.0.15<\/li>\n\t<li>DevOps Test Performance\u00a0- versions 11.0 to 11.0.7<\/li>\n\t<li>IBM App Connect Enterprise\u00a0- multiple versions<\/li>\n\t<li>IBM Aspera Console\u00a0- versions 3.3.0 to 3.4.9<\/li>\n\t<li>IBM Aspera Orchestrator\u00a0- versions 3.0.0 to 4.1.3<\/li>\n\t<li>IBM Business Automation Manager Open Editions\u00a0- versions 8.0.0 to 8.0.8<\/li>\n\t<li>IBM Data Product Hub\u00a0- versions 5.0.0 to 5.3.1<\/li>\n\t<li>IBM Event Processing\u00a0- versions 1.0.0 to 1.4.7<\/li>\n\t<li>IBM Guardium Data Protection\u00a0- versions 12.0, 12.1 and 12.2<\/li>\n\t<li>IBM Maximo Application Suite - Monitor Component\u00a0- multiple versions<\/li>\n\t<li>IBM Netezza Appliance\u00a0- versions 1.0.0.0 and 1.0.0.1<\/li>\n\t<li>IBM SPSS Modeler\u00a0- multiple versions<\/li>\n\t<li>IBM Tivoli Network Configuration Manager (ITNCM)\u00a0- versions 6.4.2 to 6.4.2 Fix Pack 23<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0- versions 4.0.0 to 5.3.1<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0- multiple versions<\/li>\n\t<li>Performance Tester (RPT)\u00a0- versions 11.0 to 11.0.7<\/li>\n\t<li>Rational Performance Tester\u00a0- multiple versions<\/li>\n\t<li>SPSS Collaboration and Deployment Services\u00a0- version 9.0.0.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-365","alert_type":396,"serial_number":"AV26-365","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7574,"title":"Dell security advisory (AV26-366)","uuid":"eb3b4674-6097-4196-84c4-c39aaf6bf0bc","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T18:44:11Z","date_created":"2026-04-20T13:08:35Z","summary":null,"body":["<article data-history-node-id=\"7574\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-366\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><b>Serial number:<\/b> AV26-366<br \/><b>Date:<\/b> April 20, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between April 13 and 19, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Connectrix Switches and Directors\u00a0\u2013 multiple versions<\/li>\n\t<li>Dell AMD-based PowerEdge Server\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell Command| Update\u00a0\u2013 versions prior to 5.7.0<\/li>\n\t<li>Dell PowerProtect Data Domain\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell Storage Manager\u00a0- Replay Manager for Microsoft Servers\u00a0\u2013 versions prior to 8.0.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000452216\/dsa-2026-041-security-update-for-dell-amd-based-poweredge-server-vulnerability\">DSA-2026-041: Security Update for Dell AMD-based PowerEdge Server Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000453015\/dsa-2026-171-security-update-for-dell-connectrix-b-series-sannav-vulnerabilities\">DSA-2026-171: Security Update for Dell Connectrix B-Series SANnav Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000453020\/dsa-2026-058-security-update-for-dell-storage-manager---replay-manager-for-microsoft-servers-vulnerabilities\">DSA-2026-058: Security Update for Dell Storage Manager\u00a0- Replay Manager for Microsoft Servers Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000451008\/dsa-2026-190-security-update-for-dell-command-update-for-a-revenera-installshield-vulnerability\">DSA-2026-190: Security Update for Dell Command | Update for a Revenera InstallShield Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000450699\/dsa-2026-060-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities\">DSA-2026-060: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-366","alert_type":396,"serial_number":"AV26-366","subject":"dell","moderation_state":"published","external_url":null},{"nid":7575,"title":"Ubuntu security advisory (AV26-367)","uuid":"1b0d3cbc-f2cc-42ff-bdb9-2cae581aa22b","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T13:55:19Z","date_created":"2026-04-20T13:47:19Z","summary":null,"body":["<article data-history-node-id=\"7575\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-367\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-367<br \/><strong>Date:<\/strong> April 20, 2026<\/p>\n\n<p>Between April 13 and 19, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 14.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 16.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 18.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 20.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 22.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 24.04 LTS<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ubuntu<\/span> 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-367","alert_type":396,"serial_number":"AV26-367","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7576,"title":"[Control systems] CISA ICS security advisories (AV26-368)","uuid":"9d44b292-558b-4096-9184-45be8a1d3da1","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T14:11:48Z","date_created":"2026-04-20T14:01:43Z","summary":null,"body":["<article data-history-node-id=\"7576\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-368\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-368<br \/><strong>Date: <\/strong>April\u00a020, 2026<\/p>\n\n<p>Between April\u00a013 and 19, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AVEVA Pipeline Simulation\u00a0\u2013 version 2025_SP1_build_7.1.9497.6351 and prior<\/li>\n\t<li>Anviz Multiple Products CX2 Lite Firmware\/CX7 Firmware\/CrossChex Standard\u00a0\u2013 all versions<\/li>\n\t<li>Delta Electronics ASDA-Soft\u00a0\u2013 version V7.2.2.0 and prior<\/li>\n\t<li>Horner Automation Cscape\u00a0\u2013 version v10.0<\/li>\n\t<li>Horner Automation XL4 PLC\u00a0\u2013 version v15.60<\/li>\n\t<li>Horner Automation XL7 PLC\u00a0\u2013 version v16.32.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-368","alert_type":398,"serial_number":"AV26-368","subject":"ics","moderation_state":"published","external_url":null},{"nid":7577,"title":"Red Hat security advisory (AV26-369)","uuid":"329eef17-8471-4bbe-8656-ebbd13130677","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T14:29:00Z","date_created":"2026-04-20T14:01:43Z","summary":null,"body":["<article data-history-node-id=\"7577\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-369\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-369<br \/><strong>Date: <\/strong>April\u00a020, 2026<\/p>\n\n<p>Between April\u00a013 and 19, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-369","alert_type":396,"serial_number":"AV26-369","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7578,"title":"[Control Systems] Moxa security advisory (AV26-370)","uuid":"d9195e6a-683b-4f9a-b537-0b4195863965","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T14:53:59Z","date_created":"2026-04-20T14:48:09Z","summary":null,"body":["<article data-history-node-id=\"7578\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-370\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-370<\/p>\n\n<p><strong>Date: <\/strong>April<strong> <\/strong>20, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 20, 2026, Moxa published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>PT-508 Series\u00a0\u2013 firmware version 3.8 and prior<\/li>\n\t<li>PT-510 Series\u00a0\u2013 firmware version 3.8 and prior<\/li>\n\t<li>PT-7528 Series\u00a0\u2013 firmware version 5.0 and prior<\/li>\n\t<li>PT-7728 Series\u00a0\u2013 firmware version 3.9 and prior<\/li>\n\t<li>PT-7828 Series\u00a0\u2013 firmware version 4.0 and prior<\/li>\n\t<li>PT-G503 Series\u00a0\u2013 firmware version 5.3 and prior<\/li>\n\t<li>PT-G510 Series\u00a0\u2013 firmware version 6.5 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-258681-cve-2020-11868-ntp-vulnerability-in-ethernet-switches\">CVE-2020-11868: NTP Vulnerability in Ethernet Switches\u00a0\u2013 MPSA-258681<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-370","alert_type":398,"serial_number":"AV26-370","subject":"other","moderation_state":"published","external_url":null},{"nid":7579,"title":"Progress security advisory (AV26-371)","uuid":"5ad5c7a1-34c2-4ba9-8627-94ab78ba694c","banner":null,"lang":"en","date_modified":"2026-04-20","date_modified_ts":"2026-04-20T18:13:25Z","date_created":"2026-04-20T18:09:29Z","summary":null,"body":["<article data-history-node-id=\"7579\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-371\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-371<br \/><strong>Date: <\/strong>April 20, 2026<\/p>\n\n<p>On April 20, 2026, Progress published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Progress Kemp LoadMaster \u2013 version GA v7.2.62.2 and prior<\/li>\n\t<li>Progress Kemp LoadMaster \u2013 version LTSF v7.2.54.16 and prior<\/li>\n\t<li>Progress MOVEit WAF \u2013 version GA v7.2.62.2 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/LoadMaster-Security-Vulnerabilites-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876\">LoadMaster Security Vulnerabilites: CVE-2026-3517\u00a0\/ CVE-2026-3518\u00a0\/ CVE-2026-3519\u00a0\/ CVE-2026-4048\u00a0\/ CVE-2026-21876<\/a><\/li>\n\t<li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876\">MOVEit WAF Critical Security Bulletin \u2013 April 2026 \u2013 (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-371","alert_type":396,"serial_number":"AV26-371","subject":"other","moderation_state":"published","external_url":null},{"nid":7582,"title":"Mozilla security advisory (AV26-372)","uuid":"10813ef9-964b-46a4-b234-3d4247148efd","banner":null,"lang":"en","date_modified":"2026-04-21","date_modified_ts":"2026-04-21T15:22:50Z","date_created":"2026-04-21T15:10:37Z","summary":null,"body":["<article data-history-node-id=\"7582\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-372\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-372<br \/><strong>Date:<\/strong> April 21, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 21, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 150<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 35<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-32\/\">Security Vulnerabilities fixed in Firefox ESR 140.10<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-31\/\">Security Vulnerabilities fixed in Firefox ESR 115.35<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-30\/\">Security Vulnerabilities fixed in Firefox 150<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-372","alert_type":396,"serial_number":"AV26-372","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7583,"title":"Spring security advisory (AV26-373)","uuid":"22a17b3c-464c-44e9-9f8e-efad0b04cbd1","banner":null,"lang":"en","date_modified":"2026-04-21","date_modified_ts":"2026-04-21T19:07:06Z","date_created":"2026-04-21T18:57:44Z","summary":null,"body":["<article data-history-node-id=\"7583\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-373\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-373<br \/><strong>Date:<\/strong> April 21, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">Between April 9 and 21, 2026, Spring published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Spring Cloud Gateway\u00a0\u2013 version 4.2.0<\/li>\n\t<li>Spring Security\u00a0\u2013 versions 5.7.0 to 5.7.22, 5.8.0 to 5.8.24, 6.3.0 to 6.3.15, 6.4.0 to 6.4.15, 6.5.0 to 6.5.9 and 7.0.0 to 7.0.4<\/li>\n\t<li>Spring Authorization Server\u00a0\u2013 versions 1.3.0 to 1.3.10, 1.4.0 to 1.4.9 and 1.5.0 to 1.5.6<\/li>\n\t<li>Spring Framework\u00a0\u2013 versions 5.3.0 to 5.3.47, 6.1.0 to 6.1.26, 6.2.0 to 6.2.17 and 7.0.0 to 7.0.6<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-373","alert_type":396,"serial_number":"AV26-373","subject":"other","moderation_state":"published","external_url":null},{"nid":7584,"title":"Fortra security advisory (AV26-374)","uuid":"d1261abc-f62a-4efb-b581-bd695d185160","banner":null,"lang":"en","date_modified":"2026-04-21","date_modified_ts":"2026-04-21T19:14:27Z","date_created":"2026-04-21T19:08:58Z","summary":null,"body":["<article data-history-node-id=\"7584\" about=\"\/en\/alerts-advisories\/fortra-security-advisory-av26-374\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-374<br \/><strong>Date:<\/strong> April 21, 2026<\/p>\n\n<p>On April 21, 2026, Fortra published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Fortra's GoAnywhere MFT\u00a0\u2013 versions prior to 7.10.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\/fi-2026-002\">FI-2026-002\u00a0- GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\/fi-2026-004\">FI-2026-004\u00a0- GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\">Fortra Product CVEs<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortra-security-advisory-av26-374","alert_type":396,"serial_number":"AV26-374","subject":"other","moderation_state":"published","external_url":null},{"nid":7585,"title":"Atlassian security advisory (AV26-375)","uuid":"d1c3b1b0-8e3c-48a9-a705-047df9198459","banner":null,"lang":"en","date_modified":"2026-04-21","date_modified_ts":"2026-04-21T20:38:05Z","date_created":"2026-04-21T20:32:21Z","summary":null,"body":["<article data-history-node-id=\"7585\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-375\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-375<br \/><strong>Date:<\/strong> April 21, 2026<\/p>\n\n<p>On April 21, 2026, Atlassian published a security advisory to address vulnerabilities, including some critical ones, in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-april-21-2026-1770913890.html\">Security Bulletin\u00a0\u2013 April 21 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-375","alert_type":396,"serial_number":"AV26-375","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":7587,"title":"Microsoft security advisory (AV26-377)","uuid":"60d44360-2216-4d2f-95dc-043e4294a586","banner":null,"lang":"en","date_modified":"2026-04-22","date_modified_ts":"2026-04-22T14:16:27Z","date_created":"2026-04-22T13:45:03Z","summary":null,"body":["<article data-history-node-id=\"7587\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-av26-377\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-377<br \/><strong>Date: <\/strong>April\u00a022, 2026<\/p>\n\n<p>On April\u00a021, 2026, Microsoft published an out-of-band (OOB) security update to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>.NET 10.0.0\u00a0\u2013 versions 10.0.0 to 10.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/devblogs.microsoft.com\/dotnet\/dotnet-10-0-7-oob-security-update\/\">.NET 10.0.7 Out-of-Band Security Update<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-40372\">ASP.NET Core Elevation of Privilege Vulnerability\u00a0- CVE-2026-40372<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-av26-377","alert_type":396,"serial_number":"AV26-377","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7586,"title":"GitLab security advisory (AV26-376)","uuid":"87bfa4a2-398c-44ec-a209-7a021af1de02","banner":null,"lang":"en","date_modified":"2026-04-22","date_modified_ts":"2026-04-22T14:03:15Z","date_created":"2026-04-22T13:45:03Z","summary":null,"body":["<article data-history-node-id=\"7586\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-376\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-376<br \/><strong>Date: <\/strong>April\u00a022, 2026<\/p>\n\n<p>On April\u00a022, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.11.1, 18.10.4 and 18.9.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.11.1, 18.10.4 and 18.9.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-18-11-1-released\/\">GitLab Patch Release: 18.11.1, 18.10.4, 18.9.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-376","alert_type":396,"serial_number":"AV26-376","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7588,"title":"[Control Systems] Phoenix Contact Security Advisory (AV26-378)","uuid":"3926947c-dd5b-4dcf-8c45-72771e2ada1b","banner":null,"lang":"en","date_modified":"2026-04-22","date_modified_ts":"2026-04-22T16:28:53Z","date_created":"2026-04-22T16:17:18Z","summary":null,"body":["<article data-history-node-id=\"7588\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-378\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AV26-378<br \/><strong>Date:<\/strong> April 22, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 22, 2026, Phoenix Contact published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AXC\u00a0\u2013 multiple versions<\/li>\n\t<li>BCP\u00a0\u2013 multiple versions<\/li>\n\t<li>CATAN C1 EN\u00a0\u2013 versions prior to1.12.3<\/li>\n\t<li>CELLULINK\u00a0\u2013 versions prior to 2025.6.3<\/li>\n\t<li>CHARX SEC-3XXX\u00a0\u2013 versions prior to 1.9.0<\/li>\n\t<li>CLOUD CLIENT 101T-TX\/TX\u00a0\u2013versions prior to 3.7.8<\/li>\n\t<li>Energy AXC PU\u00a0\u2013\u00a0\u2013 versions prior to V04.27.00.00<\/li>\n\t<li>FL MGUARD\u00a0\u2013 versions prior to 10.6.0<\/li>\n\t<li>FL NAT\u00a0\u2013 multiple versions<\/li>\n\t<li>FL SWITCH\u00a0\u2013 multiple versions<\/li>\n\t<li>FL TIMESERVER NTP\u00a0\u2013 versions prior to 5.0.71.101<\/li>\n\t<li>FL WLAN\u00a0\u2013 multiple versions<\/li>\n\t<li>GTC\u00a0\u2013 multiple versions<\/li>\n\t<li>ILC 2xxx\u00a0\u2013 multiple versions<\/li>\n\t<li>NFC\u00a0\u2013 multiple versions<\/li>\n\t<li>PLCnext Control\u00a0\u2013 versions prior to 3.53<\/li>\n\t<li>RFC\u00a0\u2013 multiple versions<\/li>\n\t<li>SMART RTU AXC\u00a0\u2013\u00a0\u2013 multiple versions<\/li>\n\t<li>TC CLOUD CLIENT\u00a0\u2013 multiple versions<\/li>\n\t<li>TC ROUTER\u00a0\u2013 multiple versions<\/li>\n\t<li>TC TIMESERVER NTP\u00a0\u2013 versions prior to 5.0.71.101<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/assets.phoenixcontact.com\/file\/929de711-0bf5-461d-8560-b918341524cd\/media\/original?pcsa-2026-00001_vde-2026-023.pdf\">VDE-2026-023: Several products are affected by vulnerabilities found in OpenSSL<\/a><\/li>\n\t<li><a href=\"https:\/\/www.phoenixcontact.com\/en-pc\/service-and-support\/psirt\">Phoenix Contact Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-378","alert_type":398,"serial_number":"AV26-378","subject":"other","moderation_state":"published","external_url":null},{"nid":7589,"title":"Oracle security advisory \u2013 April 2026 quarterly rollup (AV26-380)","uuid":"b19f14c2-dfca-4d36-9645-91187efe20b5","banner":null,"lang":"en","date_modified":"2026-04-22","date_modified_ts":"2026-04-22T17:50:39Z","date_created":"2026-04-22T17:34:31Z","summary":null,"body":["<article data-history-node-id=\"7589\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-april-2026-quarterly-rollup-av26-380\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-380<br \/><strong>Date:<\/strong> April 22, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 21, 2026, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>MySQL Enterprise Backup<\/li>\n\t<li>MySQL Server<\/li>\n\t<li>MySQL Workbench<\/li>\n\t<li>Oracle Advanced Inbound Telephony<\/li>\n\t<li>Oracle Banking Origination<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition<\/li>\n\t<li>Oracle Communications Cloud Native Core Network Exposure Function<\/li>\n\t<li>Oracle Communications EAGLE<\/li>\n\t<li>Oracle Communications EAGLE Application Processor<\/li>\n\t<li>Oracle Communications EAGLE LNP Application Processor<\/li>\n\t<li>Oracle Communications LSMS<\/li>\n\t<li>Oracle Communications Messaging Serve<\/li>\n\t<li>Oracle Communications Operations Monitor<\/li>\n\t<li>Oracle Communications Policy Management<\/li>\n\t<li>Oracle Communications Unified Assurance<\/li>\n\t<li>Oracle Managed File Transfer<\/li>\n\t<li>Oracle Tuxedo<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpuapr2026.html\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Oracle Critical Patch Update Advisory\u00a0\u2013 April<\/span> 2026<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-april-2026-quarterly-rollup-av26-380","alert_type":396,"serial_number":"AV26-380","subject":"oracle","moderation_state":"published","external_url":null},{"nid":7590,"title":"n8n security advisory (AV26-379)","uuid":"954029d8-2688-4e8b-9e1b-08263ae4b62e","banner":null,"lang":"en","date_modified":"2026-04-22","date_modified_ts":"2026-04-22T17:45:00Z","date_created":"2026-04-22T17:51:29Z","summary":null,"body":["<article data-history-node-id=\"7590\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-379\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-379<br \/><strong>Date: <\/strong>April\u00a022, 2026<\/p>\n\n<p>On April\u00a022, 2026, n8n published security advisories to address vulnerabilities, including some critical ones, in the following products:<\/p>\n\n<ul><li>n8n (MCP Client Registration)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (dynamic-node-parameters)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (XML Node Prototype Pollution)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (XML Webhook)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (SQL Mode of Merge Node)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (MCP OAuth client)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Python Task Runner)\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-379","alert_type":396,"serial_number":"AV26-379","subject":"other","moderation_state":"published","external_url":null},{"nid":7591,"title":"Apple security advisory (AV26-381)","uuid":"e44b429f-3176-414a-b742-68d9c5467ef4","banner":null,"lang":"en","date_modified":"2026-04-22","date_modified_ts":"2026-04-22T19:30:55Z","date_created":"2026-04-22T19:24:50Z","summary":null,"body":["<article data-history-node-id=\"7591\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-381\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-381<br \/><strong>Date:<\/strong> April 22, 2026<\/p>\n\n<p>On April 22, 2026, Apple published security updates to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 18.7.8 and versions prior to 26.4.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/127002\">About the security content of iOS 26.4.2 and iPadOS 26.4.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/127003\">About the security content of iOS 18.7.8 and iPadOS 18.7.8<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-381","alert_type":396,"serial_number":"AV26-381","subject":"apple","moderation_state":"published","external_url":null},{"nid":7593,"title":"Google Chrome security advisory (AV26-382)","uuid":"7b775d30-f4c9-4a6a-bad4-9700cda63ff5","banner":null,"lang":"en","date_modified":"2026-04-23","date_modified_ts":"2026-04-23T14:55:13Z","date_created":"2026-04-23T14:48:34Z","summary":null,"body":["<article data-history-node-id=\"7593\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-382\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-382<br \/><strong>Date:<\/strong> April 23, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 22, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Stable Channel Chrome for Desktop<\/span>\u00a0\u2013 versions prior to 147.0.7727.116\/117 (Windows\/Mac) and 147.0.7727.116 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"#https:\/\/chromereleases.googleblog.com\/2026\/04\/stable-channel-update-for-desktop_22.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-382","alert_type":396,"serial_number":"AV26-382","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7594,"title":"GitHub security advisory (AV26-383)","uuid":"a3a8782e-1bc8-4801-8fa8-e83e0b7fa6da","banner":null,"lang":"en","date_modified":"2026-04-23","date_modified_ts":"2026-04-23T15:52:03Z","date_created":"2026-04-23T15:10:01Z","summary":null,"body":["<article data-history-node-id=\"7594\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-383\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-383<br \/><strong>Date:<\/strong> April 23, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 21, 2026, GitHub published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.20.x prior to 3.20.1<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.5<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.8<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.14<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.17<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.20\/admin\/release-notes\">Enterprise Server 3.20.1<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.5<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.8<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.14<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.17<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-383","alert_type":396,"serial_number":"AV26-383","subject":"other","moderation_state":"published","external_url":null},{"nid":7595,"title":"CrowdStrike security advisory (AV26-384)","uuid":"888c17cc-ec5a-48ef-8d7c-393a41c60bcf","banner":null,"lang":"en","date_modified":"2026-04-23","date_modified_ts":"2026-04-23T16:03:35Z","date_created":"2026-04-23T15:56:25Z","summary":null,"body":["<article data-history-node-id=\"7595\" about=\"\/en\/alerts-advisories\/crowdstrike-security-advisory-av26-384\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-384<br \/><strong>Date:<\/strong> April 23, 2026<\/p>\n\n<p><strong>CrowdStrike security<\/strong><strong> advisory (AV26-384)<\/strong><\/p>\n\n<p class=\"mrgn-bttm-md\">On April 21, 2026, CrowdStrike published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>LogScale Self-Hosted\u00a0\u2013 GA versions 1.224.0 to 1.234.0 (inclusive)<\/li>\n\t<li>LogScale Self-Hosted LTS\u00a0\u2013 versions 1.228.0 and 1.228.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.crowdstrike.com\/en-us\/security-advisories\/cve-2026-40050\/\">CVE-2026-40050\u00a0\u2014 CrowdStrike LogScale Unauthenticated Path Traversal<\/a><\/li>\n\t<li><a href=\"https:\/\/www.crowdstrike.com\/en-us\/security-advisories\/\">Crowdstrike Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/crowdstrike-security-advisory-av26-384","alert_type":396,"serial_number":"AV26-384","subject":"other","moderation_state":"published","external_url":null},{"nid":7596,"title":"Spring security advisory (AV26-386)","uuid":"805db63a-c6e8-4f40-8c7e-1a589f68feb6","banner":null,"lang":"en","date_modified":"2026-04-23","date_modified_ts":"2026-04-23T19:41:34Z","date_created":"2026-04-23T19:30:05Z","summary":null,"body":["<article data-history-node-id=\"7596\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-386\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-386<br \/><strong>Date: <\/strong>April 23, 2026<\/p>\n\n<p>On April 23, 2026, Spring published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Spring Boot\u00a0\u2013 4.0.x versions prior to 4.0.6<\/li>\n\t<li>Spring Boot\u00a0\u2013 3.5.x versions prior to 3.5.14<\/li>\n\t<li>Spring Boot\u00a0\u2013 3.4.x versions prior to 3.4.16<\/li>\n\t<li>Spring Boot\u00a0\u2013 3.3.x versions prior to 3.3.19<\/li>\n\t<li>Spring Boot\u00a0\u2013 2.7.x versions prior to 2.7.33<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-386","alert_type":396,"serial_number":"AV26-386","subject":"other","moderation_state":"published","external_url":null},{"nid":7597,"title":"Tenable security advisory (AV26-387)","uuid":"d384ca0c-d5cd-4ae5-8a89-62f4623b505f","banner":null,"lang":"en","date_modified":"2026-04-23","date_modified_ts":"2026-04-23T19:54:03Z","date_created":"2026-04-23T19:45:26Z","summary":null,"body":["<article data-history-node-id=\"7597\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-387\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-387<br \/><strong>Date:<\/strong> April 23, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 23, 2026, Tenable published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Nessus Agent\u00a0\u2013 versions prior to 11.1.3<\/li>\n\t<li>Nessus\u00a0\u2013 versions prior to 10.11.4 and versions prior to 10.12.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-12\">[R1] Nessus Agent Version 11.1.3 Fixes Arbitrary File Deletion<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-13\">[R1] Nessus Versions 10.11.4 and 10.12.0 Fixes Arbitrary File Deletion<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-387","alert_type":396,"serial_number":"AV26-387","subject":"other","moderation_state":"published","external_url":null},{"nid":7600,"title":"IBM security advisory (AV26-388)","uuid":"51477860-0e97-46fe-8a76-25adbca5cb0b","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T13:56:02Z","date_created":"2026-04-27T13:30:30Z","summary":null,"body":["<article data-history-node-id=\"7600\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-388\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-388<br \/><strong>Date: <\/strong>April 27, 2026<\/p>\n\n<p>Between April 20 and 26, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>DataStax Hyper-Converged Database\u00a0\u2013 version 1.2.4<\/li>\n\t<li>Enterprise Content Management System Monitor\u00a0\u2013 version 5.5<\/li>\n\t<li>IBM App Connect Enterprise\u00a0\u2013 versions 12.0.1.0 to 12.0.12.24<\/li>\n\t<li>IBM App Connect Enterprise\u00a0\u2013 versions 13.0.1.0 to 13.0.6.2<\/li>\n\t<li>IBM App Connect Enterprise\u00a0\u2013 versions 13.0.1.0 to 13.0.7.0<\/li>\n\t<li>IBM Big Replicate LiveData Migrator\u00a0\u2013 versions 1.13.0 to 3.3<\/li>\n\t<li>IBM Business Automation Manager Open Editions\u00a0\u2013 versions 9.0.0 to 9.4.0<\/li>\n\t<li>IBM Cloud APM, Advanced Private\u00a0\u2013 versions 8.1.4.0 to 8.1.4.0 IF18<\/li>\n\t<li>IBM Cloud APM, Base Private\u00a0\u2013 versions 8.1.4.0 to 8.1.4.0 IF18<\/li>\n\t<li>IBM Data Product Hub\u00a0\u2013 versions 5.0.0 to 5.3.1 Patch 2<\/li>\n\t<li>IBM Edge Application Manager\u00a0\u2013 versions 5.0.0, 5.0.1 and 5.0.2<\/li>\n\t<li>IBM Guardium Data Protection\u00a0\u2013 versions 12.0, 12.1 and 12.2<\/li>\n\t<li>IBM Netezza Appliance\u00a0\u2013 versions 1.0.0.0 and 1.0.0.1<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services\u00a0\u2013 versions 6.3.0 to 6.3.0.17<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services\u00a0\u2013 versions 6.4.0 to 6.4.0.6<\/li>\n\t<li>IBM Storage Protect Operations Center\u00a0\u2013 version 8.2.0<\/li>\n\t<li>InfoSphere Data Architect\u00a0\u2013 version 9.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-388","alert_type":396,"serial_number":"AV26-388","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7601,"title":"Dell security advisory (AV26-389)","uuid":"fb5c83ff-98fd-4448-9d71-4fcc2a70010a","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T14:10:43Z","date_created":"2026-04-27T14:00:00Z","summary":null,"body":["<article data-history-node-id=\"7601\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-389\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-389<br \/><strong>Date:<\/strong> April 27, 2026<\/p>\n\n<p>Between April 20 and 26, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Networking OS10\u00a0\u2013 versions prior to 10.6.0.8<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 6.1.0.0<\/li>\n\t<li>Dell Storage Resource Manager\u00a0\u2013 versions prior to 6.1.0.0<\/li>\n\t<li>Dell VxRail Appliance\u00a0\u2013 versions 8.0.000 to 8.0.370<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000455955\/dsa-2026-160-security-update-for-dell-networking-os10-vulnerabilities\">DSA-2026-160: Security Update for Dell Networking OS10 Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000456372\/dsa-2026-126-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities\">DSA-2026-126: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000456382\/dsa-2026-196-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities\">DSA-2026-196: Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR) Security Update for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-389","alert_type":396,"serial_number":"AV26-389","subject":"dell","moderation_state":"published","external_url":null},{"nid":7602,"title":"Ubuntu security advisory (AV26-390)","uuid":"b52e5656-cd8d-418e-9984-7446c0800a8d","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T14:17:44Z","date_created":"2026-04-27T14:14:52Z","summary":null,"body":["<article data-history-node-id=\"7602\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-390\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-390<br \/><strong>Date:<\/strong> April 27, 2026<\/p>\n\n<p>Between April 20 and 26, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-390","alert_type":396,"serial_number":"AV26-390","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7603,"title":"[Control systems] CISA ICS security advisories (AV26\u2013391)","uuid":"8b0b1f5d-d1f1-48ed-9c9b-f7a9b99c7730","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T14:28:27Z","date_created":"2026-04-27T14:23:54Z","summary":null,"body":["<article data-history-node-id=\"7603\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-391\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013391<br \/><strong>Date: <\/strong>April 27, 2026<\/p>\n\n<p>Between April 20 and 26, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Carlson Software VASCO-B GNSS Receiver\u00a0\u2013 versions prior to 1.4.0<\/li>\n\t<li>Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera\u00a0\u2013 firmware version V5.00.R02.000807D8.10010.346624.S.ONVIF_21.06<\/li>\n\t<li>Hardy Barth Salia EV Charge Controller\u00a0\u2013 firmware version 2.3.81 and prior<\/li>\n\t<li>Intrado 911 Emergency Gateway (EGW)\u00a0\u2013 versions 7.x, 6.x and 5.x<\/li>\n\t<li>Milesight Cameras\u00a0\u2013 multiple versions and models<\/li>\n\t<li>RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P)\u00a0\u2013 versions prior to 5.8<\/li>\n\t<li>SenseLive X3050\u00a0\u2013 version V1.523<\/li>\n\t<li>Siemens Analytics Toolkit\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Industrial Edge Management\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Siemens RUGGEDCOM CROSSBOW Station Access Controller (SAC)\u00a0\u2013 version prior to V5.8<\/li>\n\t<li>Siemens SCALANCE\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 version prior to V4.0 SP3<\/li>\n\t<li>Siemens SINEC NMS\u00a0\u2013 version V4.0 SP3 with UMC and prior<\/li>\n\t<li>Siemens TPM 2.0\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Silex Technology AMC Manager\u00a0\u2013 versions prior to 5.0.2<\/li>\n\t<li>Silex Technology SD-330AC\u00a0\u2013 version 1.42 and prior<\/li>\n\t<li>SpiceJet Online Booking System\u00a0\u2013 all versions<\/li>\n\t<li>Yadea T5 Electric Bicycle\u00a0\u2013 all versions<\/li>\n\t<li>Zero Motorcycles Firmware\u00a0\u2013 version prior to 44<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-391","alert_type":398,"serial_number":"AV26-391","subject":"ics","moderation_state":"published","external_url":null},{"nid":7604,"title":"Red Hat security advisory (AV26-392)","uuid":"0afbc61f-afcc-4051-a84d-00e3c7c70161","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T14:36:38Z","date_created":"2026-04-27T14:34:26Z","summary":null,"body":["<article data-history-node-id=\"7604\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-392\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-392<br \/><strong>Date: <\/strong>April 27, 2026<\/p>\n\n<p>Between April 20 and 26, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-392","alert_type":396,"serial_number":"AV26-392","subject":"other","moderation_state":"published","external_url":null},{"nid":7605,"title":"[Control Systems] Moxa security advisory (AV26-393)","uuid":"99cd45be-ce4e-456a-882e-33e7c3b12f07","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T14:42:57Z","date_created":"2026-04-27T14:38:53Z","summary":null,"body":["<article data-history-node-id=\"7605\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-393\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-393<br \/><strong>Date: <\/strong>April<strong> <\/strong>27, 2026<\/p>\n\n<p>On April 27, 2026, Moxa published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>TN-4900 Series\u00a0\u2013 firmware version v3.22 and prior<\/li>\n\t<li>EDR-8010 Series\u00a0\u2013 firmware version v3.23 and prior<\/li>\n\t<li>EDR-G9010 Series\u00a0\u2013 firmware version v3.23.1 and prior<\/li>\n\t<li>OnCell G4302-LTE4 Series - firmware version v3.23.0 and prior<\/li>\n\t<li>OnCell G4308-LTE4 Series\u00a0\u2013 firmware version v3.23.0 and prior<\/li>\n\t<li>EDF-G1002-BP Series\u00a0\u2013 firmware version v3.23 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-261521-cve-2026-3867-cve-2026-3868-improper-ownership-management-and-improper-handling-of-length-parameter-incons\">CVE-2026-3867, CVE-2026-3868: Improper Ownership Management and Improper Handling of Length Parameter Inconsistency Vulnerabilities in Secure Router<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-393","alert_type":396,"serial_number":"AV26-393","subject":"other","moderation_state":"published","external_url":null},{"nid":7606,"title":"Broadcom VMware security advisory (AV26-394)","uuid":"a2524197-42cc-45e1-8c3c-4055718b9535","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T14:50:27Z","date_created":"2026-04-27T14:45:56Z","summary":null,"body":["<article data-history-node-id=\"7606\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-394\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-394<br \/><strong>Date: <\/strong>April 27, 2026<\/p>\n\n<p>On April 24, 2026, Broadcom published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Tanzu Data Lake\u00a0\u2013 versions prior to 4.0.0<\/li>\n\t<li>VMware Tanzu Greenplum Platform Extension Framework\u00a0\u2013 versions prior to 8.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37404\">Product Release Advisory - VMware Tanzu Data Lake 4.0.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37405\">Product Release Advisory - VMware Tanzu Greenplum Platform Extension Framework 8.0.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0\u2013 Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-394","alert_type":396,"serial_number":"AV26-394","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7607,"title":"Notepad++ security advisory (AV26-395)","uuid":"4b9b2cac-d59f-4426-b683-3ed750b1a0b3","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T14:56:42Z","date_created":"2026-04-27T14:51:36Z","summary":null,"body":["<article data-history-node-id=\"7607\" about=\"\/en\/alerts-advisories\/notepad-security-advisory-av26-395\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-395<br \/><strong>Date:<\/strong> April 27, 2026<\/p>\n\n<p>On April 26, 2026, Notepad++ published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Notepad++\u00a0\u2013 version 8.9.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.notepad-plus-plus.org\/topic\/27512\/notepad-release-8-9-4\">Notepad++ release 8.9.4<\/a><\/li>\n\t<li><a href=\"https:\/\/community.notepad-plus-plus.org\/category\/1\/announcements\">Notepad++ community<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/notepad-security-advisory-av26-395","alert_type":396,"serial_number":"AV26-395","subject":"other","moderation_state":"published","external_url":null},{"nid":7608,"title":"Microsoft Edge security advisory (AV26-396)","uuid":"a51ffef7-52e5-4d46-97ab-622d6f15d5b1","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T15:02:49Z","date_created":"2026-04-27T14:58:51Z","summary":null,"body":["<article data-history-node-id=\"7608\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-396\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-396<br \/><strong>Date:<\/strong> April 27, 2026<\/p>\n\n<p>On April 24, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 147.0.3912.86<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-24-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-396","alert_type":396,"serial_number":"AV26-396","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7609,"title":"Spring security advisory (AV26-397)","uuid":"b12fcf4c-7555-4434-b399-10bf06c8fe2e","banner":null,"lang":"en","date_modified":"2026-04-27","date_modified_ts":"2026-04-27T18:57:47Z","date_created":"2026-04-27T18:55:18Z","summary":null,"body":["<article data-history-node-id=\"7609\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-397\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-397<br \/><strong>Date: <\/strong>April 27, 2026<\/p>\n\n<p>On April 27, 2026, Spring published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Spring AI\u00a0\u2013 1.0.x versions prior to 1.0.6<\/li>\n\t<li>Spring AI\u00a0\u2013 1.1.x versions prior to 1.1.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-40967\">CVE-2026-40967: VectorStore FilterExpression Converter injection<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-40978\">CVE-2026-40978: SQL Injection in CosmosDBVectorStore.doDelete()<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-397","alert_type":396,"serial_number":"AV26-397","subject":"other","moderation_state":"published","external_url":null},{"nid":7611,"title":"SmarterTools security advisory (AV26-398)","uuid":"babbd3bb-150a-4ca0-a4bb-38e13d1b6885","banner":null,"lang":"en","date_modified":"2026-04-28","date_modified_ts":"2026-04-28T13:31:59Z","date_created":"2026-04-28T13:26:01Z","summary":null,"body":["<article data-history-node-id=\"7611\" about=\"\/en\/alerts-advisories\/smartertools-security-advisory-av26-398\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-398<br \/><strong>Date:<\/strong> April 28, 2026<\/p>\n\n<p>On April 24, 2026, SmarterTools published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>SmarterMail \u2013 versions prior to Build 9610<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.smartertools.com\/smartermail\/downloads\">Download SmarterMail<\/a><\/li>\n\t<li><a href=\"https:\/\/www.smartertools.com\/smartermail\/release-notes\/current\">SmarterMail Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/smartertools-security-advisory-av26-398","alert_type":396,"serial_number":"AV26-398","subject":"other","moderation_state":"published","external_url":null},{"nid":7612,"title":"Zyxel security advisory (AV26-399)","uuid":"81f1f6f1-1533-4efb-bf66-7b63d13353c1","banner":null,"lang":"en","date_modified":"2026-04-28","date_modified_ts":"2026-04-28T13:39:41Z","date_created":"2026-04-28T13:34:20Z","summary":null,"body":["<article data-history-node-id=\"7612\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av26-399\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-399<br \/><strong>Date: <\/strong>April 28, 2026<\/p>\n\n<p>On April 28, 2026, Zyxel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>4G LTE\/5G NR CPE \u2013 multiple versions and models<\/li>\n\t<li>DSL\/Ethernet CPE \u2013 multiple versions and models<\/li>\n\t<li>Fiber ONTs \u2013 multiple versions and models<\/li>\n\t<li>Wireless Extenders \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-04-28-2026\">Zyxel security advisory for command injection vulnerabilities in certain 4G LTE\/5G NR CPE, DSL\/Ethernet CPE, Fiber ONTs, and Wireless Extenders<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av26-399","alert_type":396,"serial_number":"AV26-399","subject":"other","moderation_state":"published","external_url":null},{"nid":7613,"title":"Citrix security advisory (AV26-400)","uuid":"b3a0f673-35db-4315-915b-97ae2b0fcd3e","banner":null,"lang":"en","date_modified":"2026-04-28","date_modified_ts":"2026-04-28T13:46:25Z","date_created":"2026-04-28T13:41:35Z","summary":null,"body":["<article data-history-node-id=\"7613\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-400\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-400<br \/><strong>Date:<\/strong> April 28, 2026<\/p>\n\n<p>On April 28, 2026, Citrix published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>XenServer \u2013 versions prior to 8.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696527&amp;articleURL=XenServer_Security_Update_for_Multiple_Issues\">XenServer Security Update for Multiple Issues<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av26-400","alert_type":396,"serial_number":"AV26-400","subject":"citrix","moderation_state":"published","external_url":null},{"nid":7614,"title":"Mozilla security advisory (AV26-401)","uuid":"2ba7506c-c21c-4abe-85e4-c4765d5abe5a","banner":null,"lang":"en","date_modified":"2026-04-28","date_modified_ts":"2026-04-28T15:16:14Z","date_created":"2026-04-28T15:11:13Z","summary":null,"body":["<article data-history-node-id=\"7614\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-401\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-401<br \/><strong>Date: <\/strong>April 28, 2026<\/p>\n\n<p>On April 28, 2026, Mozilla published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 150.0.1<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 140.10.1<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.35.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-35\/\">Mozilla Foundation Security Advisory 2026-35<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-36\/\">Mozilla Foundation Security Advisory 2026-36<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-37\/\">Mozilla Foundation Security Advisory 2026-37<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-401","alert_type":396,"serial_number":"AV26-401","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7616,"title":"Google Chrome security advisory (AV26-402)","uuid":"31cf10f3-4a05-466a-ba7a-7e9c72a1b8e9","banner":null,"lang":"en","date_modified":"2026-04-29","date_modified_ts":"2026-04-29T11:43:30Z","date_created":"2026-04-29T11:39:38Z","summary":null,"body":["<article data-history-node-id=\"7616\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-402\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-402<br \/><strong>Date:<\/strong> April\u00a029, 2026<\/p>\n\n<p>On April\u00a028, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 147.0.7727.137\/138 (Windows\/Mac) and 147.0.7727.137 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/04\/stable-channel-update-for-desktop_28.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-402","alert_type":396,"serial_number":"AV26-402","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7617,"title":"Jenkins security advisory (AV26-403)","uuid":"315a3113-809a-4a99-8ee4-7d72f7d951e5","banner":null,"lang":"en","date_modified":"2026-04-29","date_modified_ts":"2026-04-29T14:40:42Z","date_created":"2026-04-29T14:26:41Z","summary":null,"body":["<article data-history-node-id=\"7617\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-403\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-403<br \/><strong>Date: <\/strong>April\u00a029, 2026<\/p>\n\n<p>On April\u00a029, 2026, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Credentials Binding Plugin\u00a0\u2013 version 719.v80e905ef14eb_ and prior<\/li>\n\t<li>GitHub Plugin\u00a0\u2013 version 1.46.0 and prior<\/li>\n\t<li>GitHub Branch Source Plugin\u00a0\u2013 version 1967.vdea_d580c1a_b_a_ and prior<\/li>\n\t<li>HTML Publisher Plugin\u00a0\u2013 version 427 and prior<\/li>\n\t<li>Matrix Authorization Strategy Plugin\u00a0\u2013 versions 2.0-beta-1 to 3.2.9<\/li>\n\t<li>Microsoft Entra ID (previously Azure AD) Plugin\u00a0\u2013 version 666.v6060de32f87d and prior<\/li>\n\t<li>Script Security Plugin\u00a0\u2013 version 1399.ve6a_66547f6e1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-04-29\/#jenkins-security-advisory-2026-04-29\">Jenkins Security Advisory 2026-04-29<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-403","alert_type":396,"serial_number":"AV26-403","subject":"other","moderation_state":"published","external_url":null},{"nid":7618,"title":"cPanel security advisory (AV26-404) \u2013 Update 1","uuid":"b07f9acc-acf2-4287-b476-78c8e9bb0b36","banner":null,"lang":"en","date_modified":"2026-04-30","date_modified_ts":"2026-04-30T18:04:58Z","date_created":"2026-04-29T17:13:58Z","summary":null,"body":["<article data-history-node-id=\"7618\" about=\"\/en\/alerts-advisories\/cpanel-security-advisory-av26-404\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-404<br \/><strong>Date:<\/strong> April\u00a029, 2026<br \/><strong>Updated:<\/strong> April\u00a030, 2026<\/p>\n\n<p>On April\u00a028, 2026, cPanel published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>cPanel &amp; WebHost Manager (WHM) software\u00a0\u2013 versions prior to 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.136.0.5, 11.134.0.20 and WP Squared 11.136.1.7<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On April 30, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-41940 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40073787579671-cPanel-WHM-Security-Update-04-28-2026\">cPanel &amp; WHM Security Update 04\/28\/2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360008753193-Support-Topics\">cPanel Support Topics<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940\">CISA KEV: CVE-2026-41940<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cpanel-security-advisory-av26-404","alert_type":396,"serial_number":"AV26-404","subject":"other","moderation_state":"published","external_url":null},{"nid":7619,"title":"SonicWall security advisory (AV26-405)","uuid":"a5874d48-57cf-43ec-99ab-e029f0c370d0","banner":null,"lang":"en","date_modified":"2026-04-29","date_modified_ts":"2026-04-29T17:23:02Z","date_created":"2026-04-29T17:21:02Z","summary":null,"body":["<article data-history-node-id=\"7619\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-405\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-405<br \/><strong>Date: <\/strong>April\u00a029, 2026<\/p>\n\n<p>On April\u00a029, 2026, SonicWall published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Gen6 Hardware Firewalls\u00a0\u2013 firmware version 6.5.5.1-6n and prior<\/li>\n\t<li>Gen7 NSv\u00a0\u2013 firmware version 7.0.1-5169 and prior, firmware version 7.3.1-7013 and prior<\/li>\n\t<li>Gen7 Firewalls\u00a0\u2013 firmware version 7.0.1-5169 and prior, firmware version 7.3.1-7013 and prior<\/li>\n\t<li>Gen8 Firewalls\u00a0\u2013 firmware version 8.1.0-8017 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0004\">SonicOS affected by multiple vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-405","alert_type":396,"serial_number":"AV26-405","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":7620,"title":"AL26-008 - Vulnerability affecting cPanel and WebHost Manager (WHM) - CVE-2026-41940","uuid":"8b7e632b-608e-413d-aa1d-d041f1caec80","banner":null,"lang":"en","date_modified":"2026-04-29","date_modified_ts":"2026-04-29T18:21:48Z","date_created":"2026-04-29T18:00:21Z","summary":null,"body":["<article data-history-node-id=\"7620\" about=\"\/en\/alerts-advisories\/al26-008-vulnerability-affecting-cpanel-webhost-manager-whm-cve-2026-41940\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-008<br \/><strong>Date:<\/strong> April\u00a029, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a critical vulnerability impacting cPanel and WebHost Manager (WHM)<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. In response to the vendor advisory released on April\u00a029, 2026, the Cyber Centre released AV26-404 on April\u00a029, 2026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>Tracked as CVE-2026-41940<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is a missing authentication for critical function vulnerability (CWE-306)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\">4<\/a><\/sup> affecting cPanel and WebHost Manager (WHM), the widely used web hosting control panel that simplifies server and website management. This vulnerability allows unauthenticated remote attackers to gain access to administrative interfaces.<\/p>\n\n<p>Exploitation of CVE\u20112026\u201141940 can allow attackers to:<\/p>\n\n<ul><li>Access cPanel and WebHost Manager (WHM) administrative interfaces.<\/li>\n\t<li>Take control of hosted websites, databases, and email accounts.<\/li>\n\t<li>Modify server configurations.<\/li>\n\t<li>Potentially compromise thousands of downstream sites on shared hosting servers.<\/li>\n<\/ul><p>Based on available information at the time of release, exploitation is highly probable. Immediate action is required.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations using cPanel and WebHost Manager (WHM), review the cPanel security bulletin<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and update or upgrade the affected instances to the following versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.86.0.41<\/td>\n\t\t\t<td>11.86.0.41<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.110.0.97<\/td>\n\t\t\t<td>11.110.0.97<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.118.0.63<\/td>\n\t\t\t<td>11.118.0.63<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.126.0.54<\/td>\n\t\t\t<td>11.126.0.54<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.130.0.19<\/td>\n\t\t\t<td>11.130.0.19<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.132.0.29<\/td>\n\t\t\t<td>11.132.0.29<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.134.0.20<\/td>\n\t\t\t<td>11.134.0.20<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to 11.136.0.5<\/td>\n\t\t\t<td>11.136.0.5<\/td>\n\t\t<\/tr><tr><td>cPanel &amp; <abbr title=\"WebHost Manager\">WHM<\/abbr><\/td>\n\t\t\t<td>Versions prior to WP squared 11.136.1.7<\/td>\n\t\t\t<td>WP squared 11.136.1.7<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>cPanel emphasizes that users on unsupported software must transition to a supported server environment at once, because legacy releases will not receive any security patches.<\/p>\n\n<ul><li>Update cPanel and WebHost Manager (WHM) to a patched version listed above.<\/li>\n\t<li>Server operators can manually enforce the update process using the command-line interface, along with confirming installed version<sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/li>\n\t<li>Restrict network access to cPanel\/<abbr title=\"WebHost Manager\">WHM<\/abbr> interfaces (e.g.,\u00a0firewall IP allowlists) until patched.<\/li>\n\t<li>Review logs for suspicious login activity or unauthorized access.<\/li>\n\t<li>Follow official cPanel security advisories and monitoring guidance.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Enforce the management of administrative privileges<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n\t<li>Implement application allow lists<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40073787579671-cPanel-WHM-Security-Update-04-28-2026\">cPanel and <abbr title=\"WebHost Manager\">WHM<\/abbr> Security Update 04\/28\/2026<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/cpanel-security-advisory-av26-404\">AV26-404\u00a0\u2013 cPanel security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-41940\">CVE-2026-41940 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/306\">CWE-306: Missing Authentication for Critical Function<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-008-vulnerability-affecting-cpanel-webhost-manager-whm-cve-2026-41940","alert_type":397,"serial_number":"AL26-008","subject":"other","moderation_state":"published","external_url":null},{"nid":7624,"title":"AL26-010 \u2013 Cyber Criminals Social\u2011Engineering\u2011Enabled Compromise of Enterprise SaaS Environments","uuid":"edd14890-f828-4c81-8115-f02d1007d3c5","banner":null,"lang":"en","date_modified":"2026-04-30","date_modified_ts":"2026-04-30T15:28:27Z","date_created":"2026-04-30T12:15:37Z","summary":null,"body":["<article data-history-node-id=\"7624\" about=\"\/en\/alerts-advisories\/al26-010-cyber-criminals-social-engineering-enabled-compromise-enterprise-saas-environments\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-010<br \/><strong>Date:<\/strong> May\u00a01, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Summary<\/h2>\n\n<p>The Cyber Centre is aware of ongoing malicious cyber activity attributed to the financially motivated threat actors. Since mid\u20112025, this activity has demonstrated a marked shift toward social\u2011engineering\u2011driven initial access, targeting enterprise identity services and software\u2011as\u2011a\u2011service (SaaS) platforms.<\/p>\n\n<p>Rather than exploiting software vulnerabilities, these campaigns rely on voice phishing (vishing), brand impersonation, credential harvesting, and abuse of help\u2011desk processes to compromise user identities and gain access to cloud\u2011hosted data and services. Once access is achieved, actors focus on data exfiltration and extortion, often without deploying malware, complicating detection and response efforts.<\/p>\n\n<h2>Technical Details<\/h2>\n\n<h3>Initial Access<\/h3>\n\n<p>Recent campaigns reveal that these actors gain initial access through direct interaction with targeted employees and support personnel. Common techniques include:<\/p>\n\n<h4>Voice phishing (vishing) and social engineering:<\/h4>\n\n<p>Threat actors impersonate internal IT staff, identity providers, or trusted vendors, contacting employees by phone and claiming urgent account or Multi-factor Authentication (MFA) changes are required. Victims are instructed to authenticate to attacker-controlled portals.<\/p>\n\n<p>Signs Vishing was used:<\/p>\n\n<ul><li>User reports of unsolicited IT support calls involving platform troubleshooting.<\/li>\n\t<li>OAuth token created at a time aligned with a suspicious or unverifiable call.<\/li>\n\t<li>A new connected app appears in audit logs with vague names such as \u201cSupport Tool\u201d or \u201cData Loader.\u201d<\/li>\n\t<li>User session history shows an OAuth authorization the user does not recognize.<\/li>\n\t<li>Immediate token use from foreign IPs, Virtual Private Network (VPN) endpoints, or TOR nodes seconds to minutes after creation.<\/li>\n\t<li>Identity verification logs show no MFA challenge because authorization bypassed<\/li>\n<\/ul><h4>Credential harvesting and MFA interception:<\/h4>\n\n<p>Victim branded phishing pages are used to capture Single Sign-On (SSO) credentials and one time MFA codes. In several campaigns, adversary in the middle (AiTM) frameworks capture valid sessions in real time.<\/p>\n\n<p>Signs this vector was used:<\/p>\n\n<ul><li>SSO logs show session creation without a corresponding interactive MFA challenge.<\/li>\n\t<li>Concurrent sessions for the same user from different IPs or regions within minutes.<\/li>\n\t<li>Email or web proxy alerts indicate visits to brand\u2011impersonation domains.<\/li>\n\t<li>Unusual user agents or proxy headers observed in authentication events.<\/li>\n<\/ul><h4>Domain and subdomain impersonation:<\/h4>\n\n<p>Actors increasingly use impersonated subdomains (for example, &lt;organization&gt;sso[.]com) rather than newly registered look alike domains, enabling lures to bypass basic domain reputation and \u201cnewly registered domain\u201d controls.<\/p>\n\n<p>Signs this vector was used:<\/p>\n\n<ul><li>DNS or proxy logs show access to look\u2011alike domains or impersonated subdomains resembling corporate or SSO portals.<\/li>\n\t<li>Email security tools flag messages with links to these domains or domain display mismatches.<\/li>\n\t<li>SIEM alerts for newly observed domains closely matching corporate domains.<\/li>\n\t<li>Authentication attempts with referral URLs tied to impersonated sites.<\/li>\n<\/ul><h4>Abuse of help\u2011desk and recovery workflows:<\/h4>\n\n<p>In several recent incidents, actors successfully convince support staff to reset MFA or enroll attacker-controlled devices, resulting in persistent authenticated access. These techniques exploit human trust and identity processes, not technical vulnerabilities in SaaS platforms.<\/p>\n\n<p>Signs this vector was used:<\/p>\n\n<ul><li>MFA resets, recovery changes, or device enrollments approved without enhanced verification or outside normal procedures.<\/li>\n\t<li>Support tickets or call logs show identity validation gaps or policy deviations.<\/li>\n\t<li>Sudden addition of new authentication devices or methods to privileged accounts.<\/li>\n\t<li>Admin audit logs show identity changes initiated from unusual locations or times.<\/li>\n<\/ul><h4>Supply chain compromise (SaaS\u2011to\u2011SaaS \u201cgolden token\u201d theft):<\/h4>\n\n<p>Threat actors breach a third\u2011party vendor and steal OAuth refresh tokens that customers previously authorized for that vendor\u2019s connected application. Stolen refresh tokens are used to mint valid session tokens that bypass MFA and appear indistinguishable from normal integration activity.<\/p>\n\n<p>Signs this vector was used:<\/p>\n\n<ul><li>The primary sign is a mismatch between the origin of the API call and the vendor's known infrastructure.<\/li>\n\t<li>API activity originating from IP ranges or ASNs not associated to the vendor<\/li>\n\t<li>Sightings of unauthorized repo access, CI\/CD compromise, or credential leaks at the vendor, often reported publicly before customers detect abuse.<\/li>\n\t<li>Unexpected elevation of capabilities by an integration that normally performs limited, predictable tasks.<\/li>\n\t<li>A sudden surge in bulk API 2.0 or Rest API queries targeting high\u2011value objects like Account, Contact, Lead, or Case.<\/li>\n\t<li>The application suddenly performs \"<span class=\"text-uppercase\">select<\/span> *\" queries on entire database tables it rarely touched before.<\/li>\n<\/ul><h3>Post\u2011Compromise Activity<\/h3>\n\n<p>After obtaining valid credentials or authenticated sessions, the actors typically:<\/p>\n\n<p>Pivot laterally across SaaS applications using a single SSO identity to access email, document repositories, CRM systems, HR platforms, and analytics tools.<\/p>\n\n<p>Exfiltrate large volumes of sensitive data using legitimate application programming interfaces (APIs) and export functions, blending malicious activity with normal user behaviour.<\/p>\n\n<p>Exploit trusted third\u2011party SaaS integrations, including stored authentication tokens, to access downstream systems without triggering endpoint\u2011based security controls.<\/p>\n\n<p>Conduct aggressive extortion operations, threatening public disclosure or sale of stolen data on leak sites or underground forums if ransom demands are not met.<\/p>\n\n<p>Malware is not typically deployed, limiting the effectiveness of traditional endpoint\u2011centric detection approaches.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends organizations implement the following mitigations to reduce the risk associated with this activity:<\/p>\n\n<h3>Identity and Access Controls<\/h3>\n\n<p>Deploy phishing\u2011resistant MFA (for example, FIDO2 security keys or passkeys), particularly for administrators and users with access to sensitive SaaS data.<\/p>\n\n<p>Restrict and closely monitor MFA reset, recovery, and device re\u2011enrolment processes, requiring enhanced verification and approval.<\/p>\n\n<h3>User Awareness and Procedures<\/h3>\n\n<p>Train employees and support staff to recognize voice phishing and impersonation tactics, emphasizing that legitimate IT staff should not request MFA codes or passwords.<\/p>\n\n<p>Implement out\u2011of\u2011band verification procedures for identity\u2011related requests received by phone or messaging platforms.<\/p>\n\n<p>Implement Dedicated Administrative Workstations (DAWs) for all privileged access using hardened, isolated devices with MFA that are restricted from internet browsing and email, in line with CCCS guidance (ITSP.60.100).<\/p>\n\n<h3>SaaS and Cloud Security<\/h3>\n\n<p>Monitor identity provider and SaaS logs for anomalous sign\u2011ins, unusual API activity, and high\u2011volume data exports.<\/p>\n\n<p>Review and minimize third\u2011party SaaS integrations, rotating credentials and revoking unused tokens.<\/p>\n\n<p>Enforce conditional access policies using device posture, location, and risk scoring.<\/p>\n\n<h3>Incident Preparedness<\/h3>\n\n<p>Ensure sufficient log retention to support investigation of identity compromise and SaaS data theft incidents.<\/p>\n\n<p>Develop and test response playbooks for data extortion scenarios, including legal, communications, and stakeholder notification considerations<\/p>\n\n<h2>References<\/h2>\n\n<ul><li><a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"b56a7834-c2e2-44db-82d6-f12730291ad7\" href=\"\/en\/what-voice-phishing-vishing-itsap00102\">What is voice phishing (vishing)?\u00a0- ITSAP.00.102<\/a><\/li>\n\t<li><a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"8d072457-288e-4bd1-a076-da037de9ad03\" href=\"\/en\/guidance\/dont-take-bait-recognize-and-avoid-phishing-attacks\">Don't take the bait: Recognize and avoid phishing attacks\u00a0- ITSAP.00.101<\/a><\/li>\n\t<li><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/expansion-shinyhunters-saas-data-theft\">Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft<\/a><\/li>\n\t<li><a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-shinyhunters-fast-tracks-saas-access-subdomain-impersonation\/\">ShinyHunters Fast-Tracks SaaS Access with Subdomain Impersonation<\/a><\/li>\n\t<li><a href=\"https:\/\/krebsonsecurity.com\/2025\/10\/shinyhunters-wage-broad-corporate-extortion-spree\/\">ShinyHunters Wage Broad Corporate Extortion Spree<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/developing-your-incident-response-plan-itsap40003\">Developing your incident response plan (ITSAP.40.003)<\/a><\/li>\n\t<li><a data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"79b2a2c3-ad1e-49b5-9ca5-5f2f54757b2e\" href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-010-cyber-criminals-social-engineering-enabled-compromise-enterprise-saas-environments","alert_type":397,"serial_number":"AL26-010","subject":"other","moderation_state":"published","external_url":null},{"nid":7622,"title":"GitLab security advisory (AV26-406)","uuid":"49d97a96-e3ea-4305-b627-bf55d45e85e9","banner":null,"lang":"en","date_modified":"2026-04-30","date_modified_ts":"2026-04-30T13:57:41Z","date_created":"2026-04-30T13:48:17Z","summary":null,"body":["<article data-history-node-id=\"7622\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-406\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-406<br \/><strong>Date: <\/strong>April 30, 2026<\/p>\n\n<p>On April 29, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.11.2 and 18.10.5<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.11.2 and 18.10.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-18-11-2-released\/\">GitLab Patch Release: 18.11.2, 18.10.5<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-406","alert_type":396,"serial_number":"AV26-406","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7623,"title":"GNU security advisory (AV26-407)","uuid":"da0a5d9e-7963-44c1-99f8-ddfa3ec35f91","banner":null,"lang":"en","date_modified":"2026-04-30","date_modified_ts":"2026-04-30T14:52:00Z","date_created":"2026-04-30T14:43:17Z","summary":null,"body":["<article data-history-node-id=\"7623\" about=\"\/en\/alerts-advisories\/gnu-security-advisory-av26-407\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-407<br \/><strong>Date:<\/strong> April 30, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 29, 2026, GNU published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>GNU InetUtils\u00a0\u2013 version prior to 2.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/seclists.org\/oss-sec\/2026\/q2\/289\">inetutils-2.8 released with 2 CVE fixes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.gnu.org\/software\/inetutils\/\">Inetutils\u00a0- GNU network utilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gnu-security-advisory-av26-407","alert_type":396,"serial_number":"AV26-407","subject":"other","moderation_state":"published","external_url":null},{"nid":7626,"title":"AL26-009 - Vulnerability Affecting Linux - CVE-2026-31431 \u2013 Update 1","uuid":"2e7de64c-f0b9-44b3-924e-1ff67bc3b2d0","banner":null,"lang":"en","date_modified":"2026-05-01","date_modified_ts":"2026-05-01T18:42:43Z","date_created":"2026-04-30T18:03:06Z","summary":null,"body":["<article data-history-node-id=\"7626\" about=\"\/en\/alerts-advisories\/al26-009-vulnerability-affecting-linux-cve-2026-31431\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-009<br \/><strong>Date:<\/strong> April\u00a030, 2026<br \/><strong>Updated:<\/strong> May 1, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert upon request.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a security vulnerability affecting Linux-based operating systems, identified as CVE-2026-31431<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>Tracked as CVE-2026-31431, this vulnerability is an Incorrect Resource Transfer Between Spheres vulnerability <span class=\"nowrap\">(CWE-669)<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>,<\/span> a weakness that may allow resources or privileges to be improperly transferred between security domains.<\/p>\n\n<p>Public reporting and Linux kernel security advisories<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> indicate that this vulnerability originates in the Linux kernel and may, under certain conditions, allow privilege escalation to root or bypass of isolation mechanisms<sup id=\"fn8a-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><sup id=\"fn9a-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<p>Chained with a remote code execution vulnerability, this vulnerability is even more significant and needs to be prioritized for patching.<\/p>\n\n<h3>Update 1<\/h3>\n\n<p>On May 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-31431 to their Known Exploited Vulnerabilities (KEV) Database<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations identify and remediate affected systems as soon as possible.<\/p>\n\n<p>Affected environments include, but are not limited to:<\/p>\n\n<ul class=\"mrgn-bttm-lg\"><li>Enterprise Linux distributions (Red Hat Enterprise Linux, Rocky Linux, AlmaLinux, Oracle Linux);<\/li>\n\t<li>Debian-based distributions (Debian, Ubuntu);<\/li>\n\t<li>SUSE-based distributions (SUSE Linux Enterprise, openSUSE);<\/li>\n\t<li>Other Linux systems running vulnerable kernel versions.<\/li>\n<\/ul><p>Organizations should consult their respective distribution maintainers for version-specific impact and patching guidance. Organizations can determine whether systems may be affected by CVE-2026-31431 in:<\/p>\n\n<ul class=\"mrgn-bttm-lg\"><li>Identifying the running Linux kernel version using the uname\u00a0-r command;<\/li>\n\t<li>Reviewing distribution-specific security advisories, noting that fixes may be backported without visible version changes<sup id=\"fn8b-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><sup id=\"fn9b-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>;<\/li>\n\t<li>Assessing exposure on systems that allow local users, host containerized workloads, or execute untrusted code;<\/li>\n\t<li>Verifying that vendor-provided kernel or security updates are installed and in use, and rebooting systems if required.<\/li>\n<\/ul><p>In addition to applying vendor patches, the Cyber Centre recommends that organizations:<\/p>\n\n<ul class=\"mrgn-bttm-lg\"><li>Reboot systems after kernel updates to ensure fixes are fully applied;<\/li>\n\t<li>Restrict local and remote access to affected systems, particularly in shared or multi-tenant environments;<\/li>\n\t<li>Enforce kernel-level security controls such as SELinux, AppArmor, and seccomp where supported;<\/li>\n\t<li>Review and limit administrative privileges, including sudo and role-based access;<\/li>\n\t<li>Monitor authentication, system, and kernel logs for signs of privilege escalation or abnormal activity;<\/li>\n\t<li>Isolate high-risk or Internet-facing workloads using segmentation or containment technologies.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions with an emphasis on the following topics<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>.<\/p>\n\n<ul class=\"mrgn-bttm-lg\"><li>Patch operating systems and applications<\/li>\n\t<li>Enforce the management of administrative privileges<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Segment and separate information<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-31431\">CVE-2026-31431 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/669.html\">CWE-669: Incorrect Resource Transfer Between Spheres<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/explore.alas.aws.amazon.com\/CVE-2026-31431.html\">Amazon Linux Security Center\u00a0- CVE-2026-31431<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2026-31431\">Debian\u00a0- CVE-2026-31431<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2026-31431\">Red Hat Customer Portal\u00a0- CVE-2026-31431<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2026-31431.html\">SUSE Common Vulnerabilities and Exposures - CVE-2026-31431<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/ubuntu.com\/security\/CVE-2026-31431\">Ubuntu\u00a0- CVE-2026-31431<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/www.kernel.org\">Linux kernel project<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/\">oss-security mailing list<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431\">CISA KEV: CVE-2026-31431<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-009-vulnerability-affecting-linux-cve-2026-31431","alert_type":397,"serial_number":"AL26-009","subject":"other","moderation_state":"published","external_url":null},{"nid":7627,"title":"HPE security advisory (AV26-408)","uuid":"5d7c457b-3087-4fd7-b41a-5f32c97a2bea","banner":null,"lang":"en","date_modified":"2026-04-30","date_modified_ts":"2026-04-30T19:28:55Z","date_created":"2026-04-30T19:08:40Z","summary":null,"body":["<article data-history-node-id=\"7627\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-408\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-408<br \/><strong>Date: <\/strong>May 1, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">On April 30, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.6.0<\/li>\n\t<li>HPE Telco Service Activator\u00a0\u2013 versions 10.5.0 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05047en_us&amp;docLocale=en_US#hpesbnw05047-rev-1-hpe-telco-service-orchestrator-0\">HPESBNW05047 rev.1\u00a0- HPE Telco Service Orchestrator Software, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05051en_us&amp;docLocale=en_US#hpesbnw05051-rev-1-hpe-telco-service-activator-mul-0\">HPESBNW05051 rev.1\u00a0- HPE Telco Service Activator, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-408","alert_type":396,"serial_number":"AV26-408","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7628,"title":"Mozilla security advisory (AV26-409)","uuid":"9b317a1a-0f66-4e2e-9eda-66f123203508","banner":null,"lang":"en","date_modified":"2026-04-30","date_modified_ts":"2026-04-30T19:42:15Z","date_created":"2026-04-30T19:31:27Z","summary":null,"body":["<article data-history-node-id=\"7628\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-409\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-409<br \/><strong>Date: <\/strong>April 30, 2026<\/p>\n\n<p>On April 30, 2026, Mozilla published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Thunderbird\u00a0\u2013 versions prior to 150.0.1<\/li>\n\t<li>Thunderbird ESR\u00a0\u2013 versions prior to 140.10.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-38\/\">Mozilla Foundation Security Advisory 2026-38<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-39\/\">Mozilla Foundation Security Advisory 2026-38<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-409","alert_type":396,"serial_number":"AV26-409","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7629,"title":"Progress security advisory (AV26-410)","uuid":"39d1e8f3-74b7-4a42-bac0-32e8e2e89c08","banner":null,"lang":"en","date_modified":"2026-04-30","date_modified_ts":"2026-04-30T19:52:32Z","date_created":"2026-04-30T19:45:10Z","summary":null,"body":["<article data-history-node-id=\"7629\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-410\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-410<br \/><strong>Date:<\/strong> April 30, 2026<\/p>\n\n<p>On April 30, 2026, Progress published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Progress MOVEit Automation\u00a0\u2013 version 2025.1.4 and prior<\/li>\n\t<li>Progress MOVEit Automation\u00a0\u2013 version 2025.0.8 and prior<\/li>\n\t<li>Progress MOVEit Automation\u00a0\u2013 version 2024.1.7 and prior<\/li>\n\t<li>Progress MOVEit Automation\u00a0\u2013 version 2024.0.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174 \">MOVE<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">it Automation Critical Security Alert Bulletin\u00a0\u2013 April<\/span> 2026\u00a0\u2013 (CVE-2026-4670, CVE-2026-5174)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-410","alert_type":396,"serial_number":"AV26-410","subject":"other","moderation_state":"published","external_url":null},{"nid":7630,"title":"Microsoft Edge security advisory (AV26-411)","uuid":"919bbb67-7ac7-46f6-badb-560914f45f21","banner":null,"lang":"en","date_modified":"2026-05-01","date_modified_ts":"2026-05-01T14:22:01Z","date_created":"2026-05-01T14:16:42Z","summary":null,"body":["<article data-history-node-id=\"7630\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-411\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-411<br \/><strong>Date: <\/strong>May 1, 2026<\/p>\n\n<p>On April 30, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 147.0.3912.98<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#april-30-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-411","alert_type":396,"serial_number":"AV26-411","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7638,"title":"JetBrains security advisory (AV26-412)","uuid":"97978481-4985-445f-b2a6-41b3a976d34a","banner":null,"lang":"en","date_modified":"2026-05-01","date_modified_ts":"2026-05-01T17:09:46Z","date_created":"2026-05-01T17:04:39Z","summary":null,"body":["<article data-history-node-id=\"7638\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-412\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-412<br \/><strong>Date: <\/strong>May 1, 2026<\/p>\n\n<p>On April 30, 2026, JetBrains published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>JetBrains IntelliJ IDEA\u00a0\u2013 versions prior to 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1 and 2026.1.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-412","alert_type":396,"serial_number":"AV26-412","subject":"other","moderation_state":"published","external_url":null},{"nid":7639,"title":"IBM security advisory (AV26-413)","uuid":"f0357824-262a-4989-a7fb-fb8e5b718593","banner":null,"lang":"en","date_modified":"2026-05-04","date_modified_ts":"2026-05-04T13:29:04Z","date_created":"2026-05-04T13:23:31Z","summary":null,"body":["<article data-history-node-id=\"7639\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-413\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-413<br \/><strong>Date: <\/strong>May 4, 2026<\/p>\n\n<p>Between April 27 and May 3, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Carbon Charts lodash-es \u2013 versions 0.4.0 to 1.27.3<\/li>\n\t<li>Decision Optimization for Cloud Pak for Data \u2013 versions 5.0 to 5.3.1 releases<\/li>\n\t<li>IBM Application Modernization Accelerator \u2013 versions 4.0.0 to 4.6.0<\/li>\n\t<li>IBM Business Automation Workflow containers and traditional \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for AIOps \u2013 versions 4.1.0 to 4.13.0<\/li>\n\t<li>IBM Cloud Pak for Business Automation \u2013 multiple versions and models<\/li>\n\t<li>IBM Industry Solutions Workbench \u2013 versions prior to 5.0.0.0, 5.1.0.0 and 5.1.1.0<\/li>\n\t<li>IBM Maximo Application Suite \u2013 multiple versions<\/li>\n\t<li>IBM PowerVM Novalink \u2013 multiple versions<\/li>\n\t<li>IBM Process Mining \u2013 version 2.1.1<\/li>\n\t<li>IBM Rapid Infrastructure Automation \u2013 version 1.1.5<\/li>\n\t<li>IBM Rapid Network Automation \u2013 version 1.1.4<\/li>\n\t<li>IBM Transformation Advisor \u2013 versions 2.0.1 to 4.6.0<\/li>\n\t<li>IBM voice-gateway\/media-relay \u2013 version 1.0.8.30<\/li>\n\t<li>IBM voice-gateway\/tts-adapter \u2013 version 1.0.8.19<\/li>\n\t<li>IBM watsonx.data intelligence \u2013 versions prior to 5.2.0, 5.2.1, 5.3.0 and 5.3.1<\/li>\n\t<li>ICP \u2013 Discovery \u2013 versions 5.0.0 to 5.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-413","alert_type":396,"serial_number":"AV26-413","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7640,"title":"Dell security advisory (AV26-414)","uuid":"95932f77-1585-4152-8d08-562370c68a2d","banner":null,"lang":"en","date_modified":"2026-05-04","date_modified_ts":"2026-05-04T13:35:29Z","date_created":"2026-05-04T13:31:16Z","summary":null,"body":["<article data-history-node-id=\"7640\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-414\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-414<br \/><strong>Date:<\/strong> May 4, 2026<\/p>\n\n<p>Between April 27 and May 3, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>APEX Cloud Platform for Red Hat OpenShift \u2013 versions prior to 03.04.04.00<\/li>\n\t<li>Dell Automation Platform \u2013 versions prior to 2.0.0.0<\/li>\n\t<li>Dell Command | Monitor \u2013 version 10.13.0<\/li>\n\t<li>Dell CyberSense \u2013 versions prior to 8.16<\/li>\n\t<li>Dell NativeEdge Orchestrator \u2013 version 3.1.0.0<\/li>\n\t<li>Dell SmartFabric Manager \u2013 versions prior to 2.1.0<\/li>\n\t<li>Dell iDRAC10 \u2013 multiple versions<\/li>\n\t<li>Dell iDRAC9 \u2013 versions prior to 7.00.00.184<\/li>\n\t<li>Dell iDRAC9 \u2013 versions prior to 7.30.10.50<\/li>\n\t<li>Disk Library for mainframe DLm8700\/DLm2700 \u2013 versions prior to 7.0.1.0<\/li>\n\t<li>PowerProtect Cyber Recovery \u2013 versions prior to 20.1<\/li>\n<\/ul><p><br \/>\nThe Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-414","alert_type":396,"serial_number":"AV26-414","subject":"dell","moderation_state":"published","external_url":null},{"nid":7641,"title":"FreeBSD security advisory (AV26-415)","uuid":"3b794e08-0b2a-4519-9619-3d7806fadc9f","banner":null,"lang":"en","date_modified":"2026-05-04","date_modified_ts":"2026-05-04T13:44:59Z","date_created":"2026-05-04T13:38:43Z","summary":null,"body":["<article data-history-node-id=\"7641\" about=\"\/en\/alerts-advisories\/freebsd-security-advisory-av26-415\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-415<br \/><strong>Date: <\/strong>May 4, 2026<\/p>\n\n<p>On April 29, 2026, FreeBSD published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>FreeBSD \u2013 all supported versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:17.libnv.asc\">Heap overflow in libnv (CVE-2026-35547)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:14.pf.asc\">pf can overflow the stack parsing crafted SCTP packets (CVE-2026-7164)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:13.exec.asc\">Local privilege escalation via execve() (CVE-2026-7270)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-26:12.dhclient.asc\">Remote code execution via malicious DHCP options (CVE-2026-42511)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/\">FreeBSD Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freebsd-security-advisory-av26-415","alert_type":396,"serial_number":"AV26-415","subject":"other","moderation_state":"published","external_url":null},{"nid":7642,"title":"Ubuntu security advisory (AV26-416)","uuid":"9e9c2a03-c774-46f7-a177-dc1289f02970","banner":null,"lang":"en","date_modified":"2026-05-04","date_modified_ts":"2026-05-04T13:53:59Z","date_created":"2026-05-04T13:50:15Z","summary":null,"body":["<article data-history-node-id=\"7642\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-416\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-416<br \/><strong>Date:<\/strong> May 4, 2026<\/p>\n\n<p>Between April 27 and May 3, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8185-2\">USN-8185-2: Linux kernel (Low Latency NVIDIA) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8224-1\">USN-8224-1: Linux kernel (BlueField) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-416","alert_type":396,"serial_number":"AV26-416","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7643,"title":"[Control systems] CISA ICS security advisories (AV26\u2013417)","uuid":"919811ce-7806-401e-92b0-379c334eed76","banner":null,"lang":"en","date_modified":"2026-05-04","date_modified_ts":"2026-05-04T14:13:38Z","date_created":"2026-05-04T13:56:36Z","summary":null,"body":["<article data-history-node-id=\"7643\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-417\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013417<br \/><strong>Date: <\/strong>May 4, 2026<\/p>\n\n<p>Between April 27 and May 3, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB AWIN Gateways \u2013 multiple firmware versions<\/li>\n\t<li>ABB Ability OPTIMAX \u2013 multiple versions and models<\/li>\n\t<li>ABB Ability Symphony Plus Engineering \u2013 multiple versions and models<\/li>\n\t<li>ABB Edgenius Management Portal \u2013 versions 3.2.0.0 and 3.2.1.1<\/li>\n\t<li>ABB PCM600 \u2013 versions 1.5 to 2.13<\/li>\n\t<li>ABB System 800xA, Symphony Plus IEC 61850 \u2013 multiple firmware versions<\/li>\n\t<li>NSA GRASSMARLIN \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-417","alert_type":398,"serial_number":"AV26-417","subject":"other","moderation_state":"published","external_url":null},{"nid":7644,"title":"Red Hat security advisory (AV26-418)","uuid":"8df3fc3a-03d5-4d55-8c4b-56e7127d9498","banner":null,"lang":"en","date_modified":"2026-05-04","date_modified_ts":"2026-05-04T14:17:57Z","date_created":"2026-05-04T14:15:38Z","summary":null,"body":["<article data-history-node-id=\"7644\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-418\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-418<br \/><strong>Date: <\/strong>May 4, 2026<\/p>\n\n<p>Between April 27 and May 3, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-418","alert_type":396,"serial_number":"AV26-418","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7645,"title":"Broadcom VMware security advisory (AV26-419)","uuid":"d90d939b-769b-4805-90c4-2c09846169ac","banner":null,"lang":"en","date_modified":"2026-05-04","date_modified_ts":"2026-05-04T17:13:34Z","date_created":"2026-05-04T17:09:24Z","summary":null,"body":["<article data-history-node-id=\"7645\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-419\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-419<br \/><strong>Date: <\/strong>May 4, 2026<\/p>\n\n<p>On May 1, 2026, Broadcom published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Tanzu Jammy Stemcell \u2013 versions prior to 1.1193<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37431\">Tanzu Security Advisory CVE-2026-341431<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VA\">Security Advisories - Application Networking and Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-419","alert_type":396,"serial_number":"AV26-419","subject":"other","moderation_state":"published","external_url":null},{"nid":7646,"title":"Qualcomm security advisory \u2013 May 2026 monthly rollup (AV26-420)","uuid":"95e7db77-3d65-4600-bf94-1c57df6bce7d","banner":null,"lang":"en","date_modified":"2026-05-05","date_modified_ts":"2026-05-05T12:58:43Z","date_created":"2026-05-05T12:51:42Z","summary":null,"body":["<article data-history-node-id=\"7646\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-may-2026-monthly-rollup-av26-420\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-420<br \/><strong>Date: <\/strong>May 5, 2026<\/p>\n\n<p>On May 4, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p class=\"mrgn-bttm-md\">\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/may-2026-bulletin.html\">Qualcomm Security Bulletin\u00a0\u2013 May<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-may-2026-monthly-rollup-av26-420","alert_type":396,"serial_number":"AV26-420","subject":"other","moderation_state":"published","external_url":null},{"nid":7647,"title":"Android security advisory \u2013 May 2026 monthly rollup (AV26-421)","uuid":"1a3be91d-5156-4769-9efd-e548d4a583e4","banner":null,"lang":"en","date_modified":"2026-05-05","date_modified_ts":"2026-05-05T13:09:14Z","date_created":"2026-05-05T13:04:37Z","summary":null,"body":["<article data-history-node-id=\"7647\" about=\"\/en\/alerts-advisories\/android-security-advisory-may-2026-monthly-rollup-av26-421\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-421<br \/><strong>Date: <\/strong>May 5, 2026<\/p>\n\n<p>On May 4, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-05-01\">Android Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-may-2026-monthly-rollup-av26-421","alert_type":396,"serial_number":"AV26-421","subject":"android","moderation_state":"published","external_url":null},{"nid":7648,"title":"Apache security advisory (AV26-422)","uuid":"2870bda0-755f-4e11-8366-29f9eb17617c","banner":null,"lang":"en","date_modified":"2026-05-05","date_modified_ts":"2026-05-05T13:51:15Z","date_created":"2026-05-05T13:29:26Z","summary":null,"body":["<article data-history-node-id=\"7648\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av26-422\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-422<br \/><strong>Date:<\/strong> May 5, 2026<\/p>\n\n<p>On May 4, 2026, Apache published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Apache HTTP Server\u00a0\u2013 version 2.4.66 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html\">Apache HTTP Server 2.4 vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/httpd.apache.org\/\">Apache http Server Project<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av26-422","alert_type":396,"serial_number":"AV26-422","subject":"other","moderation_state":"published","external_url":null},{"nid":7649,"title":"Redis security advisory (AV26-423)","uuid":"7e81919f-8c48-4070-ace4-d7a2072dddbd","banner":null,"lang":"en","date_modified":"2026-05-05","date_modified_ts":"2026-05-05T19:03:10Z","date_created":"2026-05-05T18:57:24Z","summary":null,"body":["<article data-history-node-id=\"7649\" about=\"\/en\/alerts-advisories\/redis-security-advisory-av26-423\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-423<br \/><strong>Date:<\/strong> May 5, 2026<\/p>\n\n<p>On May 5, 2026, Redis published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Redis Software\u00a0\u2013 multiple versions<\/li>\n\t<li>Redis OSS\/CE releases\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/redis.io\/blog\/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631\/\">Redis Security advisory: [CVE\u20112026\u201123479] [CVE\u20112026\u201125243] [CVE-2026-25588] [CVE\u20112026\u201125589] [CVE-2026-23631]<\/a><\/li>\n\t<li><a href=\"https:\/\/redis.io\/blog\/\">Redis Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/redis-security-advisory-av26-423","alert_type":396,"serial_number":"AV26-423","subject":"other","moderation_state":"published","external_url":null},{"nid":7650,"title":"Juniper Networks security advisory (AV26-424)","uuid":"77d3095f-dd0b-4296-bb8a-db99618b9fcb","banner":null,"lang":"en","date_modified":"2026-05-05","date_modified_ts":"2026-05-05T20:34:17Z","date_created":"2026-05-05T20:14:48Z","summary":null,"body":["<article data-history-node-id=\"7650\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-424\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-424<br \/><strong>Date:<\/strong> May 5, 2026<strong>\u00a0<\/strong><\/p>\n\n<p><strong>Juniper Networks security<\/strong><strong> advisory (AV26-424)<\/strong><\/p>\n\n<p>On May 5, 2026, Juniper Networks published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Juniper Secure Analytics\u00a0\u2013 versions prior to 7.5.0 UP15 IF01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP15-IF01\">Multiple vulnerabilities resolved in Juniper Secure Analytics in 7.5.0 UP15 IF01<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri#sort=relevancy&amp;f:ctype=[Security%20Advisories\">Juniper Support Portal<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-424","alert_type":396,"serial_number":"AV26-424","subject":"juniper","moderation_state":"published","external_url":null},{"nid":7653,"title":"Broadcom VMware security advisory (AV26-427)","uuid":"37143eaa-72cd-484c-a070-8040101641ed","banner":null,"lang":"en","date_modified":"2026-05-06","date_modified_ts":"2026-05-06T13:44:41Z","date_created":"2026-05-06T13:25:25Z","summary":null,"body":["<article data-history-node-id=\"7653\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-427\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-427<br \/><strong>Date: <\/strong>May\u00a06, 2026<\/p>\n\n<p>On May\u00a05, 2026, Broadcom published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Tanzu GemFire Management Console\u00a0\u2013 versions prior to 1.4.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37439\">Product Release Advisory\u00a0- VMware Tanzu GemFire Management Console 1.4.4<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VA\">Security Advisories\u00a0- Application Networking and Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-427","alert_type":396,"serial_number":"AV26-427","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7652,"title":"Google Chrome security advisory (AV26-426)","uuid":"9597ff3a-c36e-40f9-ab55-5ca40f1a4c29","banner":null,"lang":"en","date_modified":"2026-05-06","date_modified_ts":"2026-05-06T13:37:09Z","date_created":"2026-05-06T13:25:25Z","summary":null,"body":["<article data-history-node-id=\"7652\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-426\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-426<br \/><strong>Date:<\/strong> May\u00a06, 2026<\/p>\n\n<p>On May\u00a05, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 148.0.7778.96\/97 (Windows\/Mac) and 148.0.7778.96 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/05\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-426","alert_type":396,"serial_number":"AV26-426","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7651,"title":"Palo Alto Networks security advisory (AV26-425) \u2013 Update 1","uuid":"f593466f-f127-4695-b01c-c3829d026688","banner":null,"lang":"en","date_modified":"2026-05-06","date_modified_ts":"2026-05-06T18:03:36Z","date_created":"2026-05-06T13:25:25Z","summary":null,"body":["<article data-history-node-id=\"7651\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-425\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-425<br \/><strong>Date: <\/strong>May\u00a06, 2026<\/p>\n\n<p>On May\u00a05, 2026, Palo Alto Networks published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.4-h5<\/li>\n\t<li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.7<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 11.1\u00a0- multiple versions<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>Palo Alto has received reports that CVE-2026-0300 is being actively exploited.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On May\u00a06, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0300 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0300\">CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID\u2122 Authentication Portal<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0300\">CISA KEV: CVE-2026-0300<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-425","alert_type":396,"serial_number":"AV26-425","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7654,"title":"WatchGuard security advisory (AV26-428)","uuid":"4682a77b-258c-4abf-ae15-54f21239eb2c","banner":null,"lang":"en","date_modified":"2026-05-06","date_modified_ts":"2026-05-06T17:24:20Z","date_created":"2026-05-06T17:18:39Z","summary":null,"body":["<article data-history-node-id=\"7654\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-428\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-428<br \/><strong>Date:<\/strong> May\u00a06, 2026<\/p>\n\n<p>On May\u00a06, 2026, WatchGuard published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>WatchGuard Agent on Windows\u00a0\u2013 version 1.25.02.0000 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00013\">(CVE-2026-6787 &amp; CVE-2026-6788) WatchGuard Agent on Windows Local Privilege Escalation to SYSTEM via Chained Agent Service Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00012\">(CVE-2026-41288) WatchGuard Agent on Windows Privilege Escalation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00011\">(CVE-2026-41286) Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service\u00a0- Variant B<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00010\">(CVE-2026-41287) Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Service\u00a0- Variant A<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-428","alert_type":396,"serial_number":"AV26-428","subject":"other","moderation_state":"published","external_url":null},{"nid":7655,"title":"Samsung mobile security advisory (AV26-429)","uuid":"c99cf787-adef-45cd-b3d7-07a073785f9e","banner":null,"lang":"en","date_modified":"2026-05-06","date_modified_ts":"2026-05-06T17:28:06Z","date_created":"2026-05-06T17:18:39Z","summary":null,"body":["<article data-history-node-id=\"7655\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-429\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-429<br \/><strong>Date:<\/strong> May\u00a06, 2026<\/p>\n\n<p>On May\u00a06, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices\u00a0\u2013 versions prior to SMR-MAY-2026 Release 1<\/li>\n<\/ul><p>The most recent security update resolves multiple identified vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=05\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-429","alert_type":396,"serial_number":"AV26-429","subject":"other","moderation_state":"published","external_url":null},{"nid":7656,"title":"Cisco security advisory (AV26-430)","uuid":"02fa0547-7613-4a3a-b8a0-90a9ffe3700e","banner":null,"lang":"en","date_modified":"2026-05-06","date_modified_ts":"2026-05-06T19:25:00Z","date_created":"2026-05-06T19:14:48Z","summary":null,"body":["<article data-history-node-id=\"7656\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-430\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-430<br \/><strong>Date:<\/strong> May 6, 2026<\/p>\n\n<p>On May 6, 2026, Cisco published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>Cisco Crosswork Network Controller (CNC) \u2013 version 7.1 and prior<\/li>\n\t<li>Cisco IoT Field Network Director (FND) \u2013 version 4 and prior<\/li>\n\t<li>Cisco IoT Field Network Director (FND) \u2013 versions prior to 5.0.0-117<\/li>\n\t<li>Cisco Network Services Orchestrator (NSO) \u2013 version 6.3 and prior<\/li>\n\t<li>Cisco Network Services Orchestrator (NSO) \u2013 versions prior to 6.4.1.3<\/li>\n\t<li>Cisco SG350 and SG350X Managed Switch \u2013 multiple versions and models<\/li>\n\t<li>Cisco Unity Connection \u2013 versions prior to 12.5<\/li>\n\t<li>Cisco Unity Connection \u2013 versions prior to 14SU5<\/li>\n\t<li>Cisco Unity Connection \u2013 versions prior to 15SU4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-unity-rce-ssrf-hENhuASy\">Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sg350-snmp-dos-GEFZr2Tj\">Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-nso-dos-7Egqyc\">Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Connection Exhaustion Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iot-fnd-dos-n8N26Q4u\">Cisco IoT Field Network Director Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-430","alert_type":396,"serial_number":"AV26-430","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7657,"title":"Spring security advisory (AV26-431)","uuid":"9d6adb53-ec5c-4c06-bda9-5e978a48c310","banner":null,"lang":"en","date_modified":"2026-05-07","date_modified_ts":"2026-05-07T13:48:23Z","date_created":"2026-05-07T13:37:46Z","summary":null,"body":["<article data-history-node-id=\"7657\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-431\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-431<br \/><strong>Date: <\/strong>May 7, 2026<\/p>\n\n<p>On May 6, 2026, Spring published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Spring Cloud Config\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-40981\">CVE-2026-40981: Spring Cloud Config Clients Can Access Secrets From Any Project The Config Server Has Access To On Google Secrets Manager Server Has Access To On Google Secrets Manager<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-40982\">CVE-2026-40982: Directory Traversal with spring-cloud-config-server<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-41002\">CVE-2026-41002: Spring Cloud Config Server Susceptible To TOCTOU Attack<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security \">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-431","alert_type":396,"serial_number":"AV26-431","subject":"other","moderation_state":"published","external_url":null},{"nid":7658,"title":"VM2 Node.js Library security advisory (AV26-432)","uuid":"bca02761-6283-4b9f-82e9-612d16ed6a12","banner":null,"lang":"en","date_modified":"2026-05-07","date_modified_ts":"2026-05-07T13:54:19Z","date_created":"2026-05-07T13:37:56Z","summary":null,"body":["<article data-history-node-id=\"7658\" about=\"\/en\/alerts-advisories\/vm2-nodejs-library-security-advisory-av26-432\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-432<br \/><strong>Date: <\/strong>May 7, 2026<\/p>\n\n<p>On May 4, 2026, Patrik Simek published security advisories to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>VM2 Node.js sandboxing library\u00a0\u2013 versions prior to 3.11.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/patriksimek\/vm2\/releases\/tag\/v3.11.2\">VM2 v3.11.2<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/patriksimek\/vm2\/security\/advisories?page=1\">VM2 security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vm2-nodejs-library-security-advisory-av26-432","alert_type":396,"serial_number":"AV26-432","subject":"other","moderation_state":"published","external_url":null},{"nid":7659,"title":"Mozilla security advisory (AV26-433)","uuid":"1c1c37a4-d8d1-4dd1-b62a-575bf1aa7366","banner":null,"lang":"en","date_modified":"2026-05-07","date_modified_ts":"2026-05-07T14:00:58Z","date_created":"2026-05-07T13:37:58Z","summary":null,"body":["<article data-history-node-id=\"7659\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-433\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-433<br \/><strong>Date: <\/strong>May 7, 2026<\/p>\n\n<p>On May 7, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0 \u2013 versions prior to 150.0.2<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 140.10.2<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.35.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-40\/\">Mozilla Foundation Security Advisory 2026-40<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-41\/\">Mozilla Foundation Security Advisory 2026-41<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-42\/\">Mozilla Foundation Security Advisory 2026-42<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-433","alert_type":396,"serial_number":"AV26-433","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7660,"title":"Broadcom VMware security advisory (AV26-434)","uuid":"11c0b50f-b894-4676-91c8-f1fd36b21edf","banner":null,"lang":"en","date_modified":"2026-05-07","date_modified_ts":"2026-05-07T15:30:27Z","date_created":"2026-05-07T15:26:05Z","summary":null,"body":["<article data-history-node-id=\"7660\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-434\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-434<br \/><strong>Date: <\/strong>May 7, 2026<\/p>\n\n<p>Between May 6 and 7, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Tanzu Greenplum Command Center\u00a0\u2013 versions prior to 6.17.0<\/li>\n\t<li>Tanzu Greenplum Command Center\u00a0\u2013 versions prior to 7.7.0<\/li>\n\t<li>Tanzu Greenplum Data Copy Utility\u00a0\u2013 versions prior to 2.9.3<\/li>\n\t<li>Tanzu for MySQL on Kubernetes\u00a0\u2013 versions prior to 2.0.3<\/li>\n\t<li>Tanzu Greenplum Streaming Server for Kubernetes\u00a0\u2013 versions prior to 1.3.0<\/li>\n\t<li>Tanzu Greenplum Streaming Server\u00a0\u2013 versions prior to 2.3.0<\/li>\n\t<li>Tanzu Greenplum Streaming on Kubernetes\u00a0\u2013 versions prior to 1.1.0<\/li>\n\t<li>Tanzu Greenplum Text\u00a0\u2013 versions prior to 4.0.0<\/li>\n\t<li>Tanzu for Valkey on Kubernetes\u00a0\u2013 versions prior to 3.3.4<\/li>\n\t<li>Tanzu for Valkey on Kubernetes\u00a0\u2013 versions prior to 3.4.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-434","alert_type":396,"serial_number":"AV26-434","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7661,"title":"Ivanti security advisory (AV26-435)","uuid":"11be76a8-921e-421d-b79a-94b8a0f0d351","banner":null,"lang":"en","date_modified":"2026-05-07","date_modified_ts":"2026-05-07T15:35:50Z","date_created":"2026-05-07T15:31:31Z","summary":null,"body":["<article data-history-node-id=\"7661\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-435\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-435<br \/><strong>Date: <\/strong>May 7, 2026<\/p>\n\n<p>On May 7, 2026, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 versions prior to 12.6.1.1<\/li>\n\t<li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 versions prior to 12.7.0.1<\/li>\n\t<li>Ivanti Endpoint Manager Mobile (EPMM)\u00a0\u2013 versions prior to 12.8.0.1<\/li>\n<\/ul><p>Ivanti has indicated that CVE-2026-6973 has been exploited.<\/p>\n\n<p>On May 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-6973 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US\">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-6973\">CISA KEV: CVE-2026-6973<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-435","alert_type":396,"serial_number":"AV26-435","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7664,"title":"Microsoft Edge security advisory (AV26-436)","uuid":"4a9e5a37-fc5d-4be7-ba25-20cee7c6f63e","banner":null,"lang":"en","date_modified":"2026-05-08","date_modified_ts":"2026-05-08T16:08:21Z","date_created":"2026-05-08T16:04:59Z","summary":null,"body":["<article data-history-node-id=\"7664\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-436\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-436<br \/><strong>Date:<\/strong> May 8, 2026<\/p>\n\n<p>On May 7, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 148.0.3967.54<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-7-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-436","alert_type":396,"serial_number":"AV26-436","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7665,"title":"AL26-011 - Vulnerabilities affecting Linux - CVE-2026-43284 and CVE-2026-43500","uuid":"74698bb9-62ea-44c9-ab28-5d8a2f7a5201","banner":null,"lang":"en","date_modified":"2026-05-08","date_modified_ts":"2026-05-08T17:39:10Z","date_created":"2026-05-08T17:37:42Z","summary":null,"body":["<article data-history-node-id=\"7665\" about=\"\/en\/alerts-advisories\/al26-011-vulnerabilities-affecting-linux-cve-2026-43284-cve-2026-43500\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-011<br \/><strong>Date:<\/strong> May 8, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert upon request.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of security vulnerabilities affecting Linux-based operating systems, identified as CVE-2026-43284<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and CVE-2026-43500<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>Tracked as CVE-2026-43284, this is a Linux kernel Write-what-where Condition vulnerability (CWE-123)<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> that may allow a local attacker to execute arbitrary code.<\/p>\n\n<p>CVE-2026-43500 is a Linux kernel local privilege escalation (LPE) vulnerability in the RxRPC subsystem that may allow a local attacker to escalate privileges.<\/p>\n\n<p>Public reporting and Linux kernel security advisories<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup><sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup> indicate that these vulnerabilities originate in the Linux kernel and may, under certain conditions, allow privilege escalation to root or bypass of isolation mechanisms.<\/p>\n\n<p>Publicly referred to as \u201cDirty Frag\u201d, CVE-2026-43284 and CVE-2026-43500 can be chained to allow for a local unprivileged user to gain root access<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>. Chained with a remote code execution vulnerability, these vulnerabilities are even more significant and need to be prioritized for patching.<\/p>\n\n<p>The Cyber Centre is aware of working publicly available Proof of Concepts (POC) exploiting these vulnerabilities<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>As of May 8, 2026, no universal fix has been released across all stable kernels for CVE-2026-43284 and CVE-2026-43500.<\/p>\n\n<p>The Cyber Centre recommends that organizations identify and apply the recommended mitigations until patches become available.<\/p>\n\n<p>Affected environments include, but are not limited to:<\/p>\n\n<ul><li>Enterprise Linux distributions (Red Hat Enterprise Linux, Rocky Linux, AlmaLinux, Oracle Linux, Fedora and CentOS Stream)<\/li>\n\t<li>Debian-based distributions (Debian, Ubuntu)<\/li>\n\t<li>SUSE-based distributions (SUSE Linux Enterprise, openSUSE)<\/li>\n\t<li>Other Linux systems running vulnerable kernel versions<\/li>\n<\/ul><p>Organizations should consult their respective distribution maintainers for version-specific impact and mitigation guidance. Organizations can determine whether systems may be affected by CVE-2026-43284 and CVE-2026-43500 in:<\/p>\n\n<ul><li>Identifying the running Linux kernel version using the <strong>uname\u00a0-r<\/strong> command that include:\n\n\t<ul><li>ESP\/XFRM IPsec support<\/li>\n\t\t<li>UDP ESP\u2011in\u2011UDP receive paths<\/li>\n\t\t<li>RXRPC enabled<\/li>\n\t<\/ul><\/li>\n\t<li>Checking whether the affected kernel modules are currently loaded by running <strong>lsmod\u00a0| egrep\u00a0'^(esp4|esp6|rxrpc)\\b'\u00a0or grep -qE '^(esp4|esp6|rxrpc)\u00a0' \/proc\/modules; <\/strong>no output indicates the modules are not currently loaded, but organizations should also confirm whether the modules are available to load and review vendor guidance, as module availability and default exposure vary by distribution.<\/li>\n<\/ul><p>Until vendor patches are available, the Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Disable vulnerable kernel modules (esp, esp6 and rxpc) if not required by running <strong>sh -c \"printf 'install esp4 \/bin\/false\\ninstall esp6 \/bin\/false\\ninstall rxrpc \/bin\/false\\n'\u00a0&gt; \/etc\/modprobe.d\/dirtyfrag.conf;\u00a0rmmod\u00a0esp4 esp6\u00a0rxrpc 2&gt;\/dev\/null;\u00a0true\"<\/strong> or distro-specific guidance when available<sup id=\"fn9a-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup><sup id=\"fn12-rf\"><a class=\"fn-lnk\" href=\"#fn12\"><span class=\"wb-inv\">Footnote <\/span>12<\/a><\/sup>. <strong>Note:<\/strong> Disabling esp4, esp6 may break IPsec. Disabling rxrpc may impact AFS-based systems. Regenerate the initramfs images to prevent the modules from being loaded during early boot by running <strong>sudo update-initramfs\u00a0-u\u00a0-k\u00a0all<\/strong> or follow vendor-specific guidance when available<\/li>\n\t<li>Restrict local and remote access to affected systems, particularly in shared or multi-tenant environments<\/li>\n\t<li>Review and limit administrative privileges, including sudo and role-based access<\/li>\n\t<li>Monitor authentication, system, and kernel logs for signs of privilege escalation or abnormal activity<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn13-rf\"><a class=\"fn-lnk\" href=\"#fn13\"><span class=\"wb-inv\">Footnote <\/span>13<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Enforce the management of administrative privileges<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Segment and separate information<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43284\">CVE-2026-43284 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-43500\">CVE-2026-43500<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/123.html\">CWE-123: Write-what-where Condition<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/aws.amazon.com\/security\/security-bulletins\/rss\/2026-027-aws\/\">\"Dirty Frag\" and other issues in Amazon Linux kernels<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2026-43284\">Debian\u00a0- CVE-2026-43284<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2467771\">Red Hat Bugzilla\u00a0\u2013 Bug 2467771<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2026-43284.html\">SUSE Common Vulnerabilities and Exposures\u00a0- CVE-2026-43284<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/ubuntu.com\/security\/CVE-2026-43284\">Ubuntu\u00a0- CVE-2026-43284<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/almalinux.org\/blog\/2026-05-07-dirty-frag\/\">Dirty Frag (CVE-2026-43284, CVE-2026-43500) vulnerability fix is ready for testing<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.wiz.io\/blog\/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc\">Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-linux-dirty-frag-zero-day-with-poc-exploit-gives-root-privileges\/\">New Linux 'Dirty Frag' zero-day gives root on all major distros<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 12<\/dt>\n\t<dd id=\"fn12\">\n\t<p><a href=\"https:\/\/ubuntu.com\/blog\/dirty-frag-linux-vulnerability-fixes-available\">Dirty Frag Linux kernel local privilege escalation vulnerability mitigations<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn12-rf\"><span class=\"wb-inv\">Return to footnote<\/span>12<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 13<\/dt>\n\t<dd id=\"fn13\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn13-rf\"><span class=\"wb-inv\">Return to footnote<\/span>13<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-011-vulnerabilities-affecting-linux-cve-2026-43284-cve-2026-43500","alert_type":397,"serial_number":"AL26-011","subject":"other","moderation_state":"published","external_url":null},{"nid":7666,"title":"cPanel security advisory (AV26-437)\u00a0","uuid":"b75317c6-a667-42a8-bad2-3fd3dedacfb5","banner":null,"lang":"en","date_modified":"2026-05-08","date_modified_ts":"2026-05-08T18:49:02Z","date_created":"2026-05-08T18:38:03Z","summary":null,"body":["<article data-history-node-id=\"7666\" about=\"\/en\/alerts-advisories\/cpanel-security-advisory-av26-437\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-437<br \/><strong>Date:<\/strong> May 8, 2026<\/p>\n\n<p>On May 8, 2026, cPanel published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>cPanel &amp; WebHost Manager (WHM) software \u2013 versions prior to 11.136.0.9, 11.134.0.25, 11.132.0.31, 11.130.0.22, 11.126.0.58, 11.124.0.37, 11.118.0.66, 11.110.0.116, 11.110.0.117, 11.102.0.41, 11.94.0.30, 11.86.0.43 and WP Squared 11.136.1.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40311033698327-Security-CVE-2026-29201-cPanel-WHM-WP2-Security-Update-May-08-2026\">Security: CVE-2026-29201\u00a0- cPanel &amp; WHM\u00a0\/ WP2 Security Update\u00a0- May 08, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40311426610327-Security-CVE-2026-29202-cPanel-WHM-WP2-Security-Update-May-08-2026\">Security: CVE-2026-29202\u00a0- cPanel &amp; WHM\u00a0\/ WP2 Security Update\u00a0- May 08, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40311543760407-Security-CVE-2026-29203-cPanel-WHM-WP2-Security-Update-May-08-2026\">Security: CVE-2026-29203\u00a0- cPanel &amp; WHM\u00a0\/ WP2 Security Update\u00a0- May 08, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360008753193-Support-Topics\">cPanel Support Topics<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cpanel-security-advisory-av26-437","alert_type":396,"serial_number":"AV26-437","subject":"other","moderation_state":"published","external_url":null},{"nid":7667,"title":"IBM security advisory (AV26-438)","uuid":"283f736c-80cb-4a42-b8bb-cf34bfe268b7","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T14:36:29Z","date_created":"2026-05-11T13:46:34Z","summary":null,"body":["<article data-history-node-id=\"7667\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-438\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-438<br \/><strong>Date:<\/strong> May 11, 2026<\/p>\n\n<p>Between May\u00a04 and 10, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Aspera Faspex 5\u00a0\u2013 versions 5.0.0 to 5.0.15.1<\/li>\n\t<li>Automation Assets in IBM Cloud Pak for Integration (CP4I)\u00a0\u2013 multiple versions<\/li>\n\t<li>Automation Assets in IBM Cloud Pak for Integration\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM App Connect Enterprise\u00a0- versions 12.0.1.0 to 12.0.12.25<\/li>\n\t<li>IBM App Connect Enterprise\u00a0- versions 13.0.1.0 to 13.0.7.1<\/li>\n\t<li>IBM App Connect Operator\u00a0- multiple versions<\/li>\n\t<li>IBM Automation Decision Services\u00a0- multiple versions<\/li>\n\t<li>IBM Business Automation Insights\u00a0- multiple versions<\/li>\n\t<li>IBM CICS TX Advanced\u00a0- version 10.1<\/li>\n\t<li>IBM Cloud Pak for Business Automation\u00a0- multiple versions<\/li>\n\t<li>IBM Content Navigator\u00a0- multiple versions<\/li>\n\t<li>IBM Edge Data Collector\u00a0- versions 9.1, 9.0 and 8.11<\/li>\n\t<li>IBM Engineering AI Hub\u00a0- versions 1.0.0 and 1.1.0<\/li>\n\t<li>IBM Industry Solutions Workbench\u00a0- multiple versions<\/li>\n\t<li>IBM MQ\u00a0- multiple versions and models<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- IoT Component\u00a0- multiple versions<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Optimizer Component\u00a0- all versions<\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Visual Inspection Component\u00a0- multiple versions<\/li>\n\t<li>IBM Netezza Analytics for NPS\u00a0- versions 11.2.0.0 to 11.2.29<\/li>\n\t<li>IBM Observability with Instana (OnPrem)\u00a0- versions Build 1.0.285 to 1.0.315<\/li>\n\t<li>IBM Quantum Safe Explorer\u00a0- versions 2.2.2 to 2.3.0<\/li>\n\t<li>IBM Quantum Safe Remediator\u00a0- versions 1.0.1 to 1.1.1<\/li>\n\t<li>IBM SOAR QRadar Plugin App\u00a0- version 3.1<\/li>\n\t<li>IBM SPSS Statistics Client and Server\u00a0- multiple versions<\/li>\n\t<li>IBM TXSeries for Multiplatforms\u00a0- multiple versions<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0- versions 1.4.0 to 2.6.0<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (CP4I)\u00a0- multiple versions<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration\u00a0- multiple versions<\/li>\n\t<li>PowerVC\u00a0- versions 2.2.1.2, 2.3.0, 2.3.1 and 2.3.2<\/li>\n\t<li>QRadar AI Assistant\u00a0- versions 1.0.0 to 1.4.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-438","alert_type":396,"serial_number":"AV26-438","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7668,"title":"Dell security advisory (AV26-439)","uuid":"64a3e410-870a-4a25-982d-cdfe7bbc6abc","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T14:50:47Z","date_created":"2026-05-11T13:46:34Z","summary":null,"body":["<article data-history-node-id=\"7668\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-439\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-439<br \/><strong>Date:<\/strong> May 11, 2026<\/p>\n\n<p>Between May 4 and 10, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>PowerScale A300\/A3000\/H700\/H7000\u00a0\u2013 versions prior to 13.2.3<\/li>\n\t<li>Elastic Cloud Storage (ECS)\u00a0\u2013 versions 3.8.1.0 to 3.8.1.7<\/li>\n\t<li>ObjectScale\u00a0\u2013 versions prior to 4.3.0.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000461405\/dsa-2026-127-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities\">DSA-2026-127: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000462117\/dsa-2026-047-security-update-for-dell-ecs-and-objectscale-multiple-vulnerabilities-1\">DSA-2026-019: Security update for Dell ECS and ObjectScale Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-439","alert_type":396,"serial_number":"AV26-439","subject":"dell","moderation_state":"published","external_url":null},{"nid":7672,"title":"Spring security advisory (AV26-443)","uuid":"d0d6a980-6823-4639-bbeb-cd6e6cbff275","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T16:04:11Z","date_created":"2026-05-11T13:46:34Z","summary":null,"body":["<article data-history-node-id=\"7672\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-443\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-443<br \/><strong>Date: <\/strong>May 11, 2026<\/p>\n\n<p>On May 8, 2026, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Spring<\/span> published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Spring<\/span> AI\u00a0\u2013 1.0.x versions prior to 1.0.7<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Spring<\/span> AI\u00a0\u2013 1.1.x versions prior to 1.1.6<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-41705\">CVE-2026-41705: Expression injection in MilvusVectorStore doDelete allows data destruction<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-41713\">CVE-2026-41713: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-41712\">CVE-2026-41712: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-443","alert_type":396,"serial_number":"AV26-443","subject":"other","moderation_state":"published","external_url":null},{"nid":7670,"title":"[Control systems] CISA ICS security advisories (AV26\u2013441)","uuid":"7b322cb0-8c0f-4b35-86fd-9d8b1d0f60a2","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T15:43:52Z","date_created":"2026-05-11T14:53:54Z","summary":null,"body":["<article data-history-node-id=\"7670\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-441\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013441<br \/><strong>Date: <\/strong>May 11, 2026<\/p>\n\n<p>Between May 4 and 10, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB B&amp;R Automation Runtime\u00a0\u2013 versions prior to 6.5 and prior to R4.93<\/li>\n\t<li>ABB B&amp;R Automation Studio\u00a0\u2013 versions prior to 6.5<\/li>\n\t<li>ABB B&amp;R PVI\u00a0\u2013 versions prior to 6.5.0<\/li>\n\t<li>Hitachi Energy PCM600\u00a0\u2013 multiple versions<\/li>\n\t<li>Johnson Controls CEM AC2000\u00a0\u2013 versions 12.0, 11.0 and 10.6<\/li>\n\t<li>MAXHUB Pivot Client Application\u00a0\u2013 versions prior to v1.36.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-441","alert_type":398,"serial_number":"AV26-441","subject":"ics","moderation_state":"published","external_url":null},{"nid":7671,"title":"Red Hat security advisory (AV26-442)","uuid":"1c77d3d3-87d2-483b-98c7-1db5183346b2","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T15:53:47Z","date_created":"2026-05-11T14:53:54Z","summary":null,"body":["<article data-history-node-id=\"7671\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-442\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-442<br \/><strong>Date: <\/strong>May 11, 2026<\/p>\n\n<p>Between May 4 and 10, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Red Hat CodeReady Linux Builder<\/span>\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Red Hat Enterprise Linux<\/span>\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Red Hat Enterprise Linux Server<\/span>\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Red Hat Enterprise Linux for Real Time<\/span>\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-442","alert_type":396,"serial_number":"AV26-422","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7669,"title":"Ubuntu security advisory (AV26-440)","uuid":"ebdea481-7cad-4613-bc4c-c360ddd4b534","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T15:17:54Z","date_created":"2026-05-11T14:53:54Z","summary":null,"body":["<article data-history-node-id=\"7669\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-440\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-440<br \/><strong>Date:<\/strong> May 11, 2026<\/p>\n\n<p>Between May 4 and 10, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8257-1\">USN-8257-1: Linux kernel (Raspberry Pi) vulnerabilities (25.01)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8255-1\">USN-8255-1: Linux kernel vulnerabilities (22.04, 20.04)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8258-1\">USN-8258-1: Linux kernel (Azure) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-440","alert_type":396,"serial_number":"AV26-440","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7673,"title":"Broadcom VMware security advisory (AV26-444)","uuid":"72119723-a665-4ec7-bc1e-0410addfa5f0","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T17:31:18Z","date_created":"2026-05-11T17:22:59Z","summary":null,"body":["<article data-history-node-id=\"7673\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-444\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-444<br \/><strong>Date:<\/strong> May 11, 2026<\/p>\n\n<p>On May 8, 2026, Broadcom published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware Tanzu RabbitMQ on Kubernetes\u00a0\u2013 versions prior to 4.3.0, 4.2.6, 4.1.11, 4.0.20 and 3.13.15<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37468\">Product Release Advisory\u00a0- VMware Tanzu RabbitMQ on Kubernetes 4.3.0, 4.2.6, 4.1.11, 4.0.20, 3.13.15<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-444","alert_type":396,"serial_number":"AV26-444","subject":"other","moderation_state":"published","external_url":null},{"nid":7674,"title":"JetBrains security advisory (AV26-445)","uuid":"94f3ae00-a1ec-4c2b-a0eb-715a26cf143c","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T19:39:08Z","date_created":"2026-05-11T19:23:18Z","summary":null,"body":["<article data-history-node-id=\"7674\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-445\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-445<br \/><strong>Date: <\/strong>May 11, 2026<\/p>\n\n<p>On May 11, 2026, JetBrains published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>JetBrains TeamCity\u00a0\u2013 versions prior to 2026.1 and 2025.11.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-445","alert_type":396,"serial_number":"AV26-445","subject":"other","moderation_state":"published","external_url":null},{"nid":7675,"title":"Apple security advisory (AV26-446)","uuid":"acd131b8-b61f-4553-a161-f11578037103","banner":null,"lang":"en","date_modified":"2026-05-11","date_modified_ts":"2026-05-11T20:02:12Z","date_created":"2026-05-11T19:47:34Z","summary":null,"body":["<article data-history-node-id=\"7675\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-446\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-446<br \/><strong>Date:<\/strong> May 11, 2026<\/p>\n\n<p>On May 11, 2026, Apple published a security update to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS\u00a0\u2013 versions prior to 26.5<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 26.5<\/li>\n\t<li>iOS\u00a0\u2013 versions prior to 18.7.9<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 18.7.9<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 17.7.11<\/li>\n\t<li>iOS\u00a0\u2013 versions prior to 16.7.16<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 16.7.16<\/li>\n\t<li>iOS\u00a0\u2013 versions prior to 15.8.8<\/li>\n\t<li>iPadOS\u00a0\u2013 versions prior to 15.8.8<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26.5<\/li>\n\t<li>macOS Sequoia\u00a0\u2013 versions prior to 15.7.7<\/li>\n\t<li>macOS Sonoma\u00a0\u2013 versions prior to 14.8.7<\/li>\n\t<li>tvOS\u00a0\u2013 versions prior to 26.5<\/li>\n\t<li>watchOS\u00a0\u2013 versions prior to 26.5<\/li>\n\t<li>visionOS\u00a0\u2013 versions prior to 26.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-446","alert_type":396,"serial_number":"AV26-446","subject":"apple","moderation_state":"published","external_url":null},{"nid":7676,"title":"SAP security advisory \u2013 May 2026 monthly rollup (AV26-447)","uuid":"75743870-0cdb-44ee-91a5-dcea9b16cec2","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T14:22:53Z","date_created":"2026-05-12T12:31:51Z","summary":null,"body":["<article data-history-node-id=\"7676\" about=\"\/en\/alerts-advisories\/sap-security-advisory-may-2026-monthly-rollup-av26-447\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-447<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2026, SAP published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>SAP S\/4HANA (SAP Enterprise Search for ABAP)\u00a0\u2013 versions SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 and SAP_BASIS 816<\/li>\n\t<li>SAP Commerce cloud\u00a0\u2013 versions HY_COM 2205, COM_CLOUD 2211 and 2211-JDK21<\/li>\n\t<li>SAP Forecasting and Replenishment\u00a0\u2013 versions SCM 702, 712, 713 and 714<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP and ABAP Platform\u00a0\u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 and SAP_BASIS 816<\/li>\n\t<li>SAP S\/4HANA Condition Maintenance \u2013 versions S4CORE 102, 103, 104, 105, 106, 107, 108 and 109<\/li>\n\t<li>Business Server Pages Application (TAF_APPLAUNCHER)\u00a0\u2013 versions ST-PI 740 and 758<\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform\u00a0\u2013 versions ENTERPRISE 430, 2025 and 2027<\/li>\n\t<li>SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard) \u2013 versions SEM-BW 605, 700, 736, 746, 747, 748, 749 and 800<\/li>\n\t<li>SAP Commerce Cloud (Apache Log4j)\u00a0\u2013 versions HY_COM 2205, COM_CLOUD 2211 and 2211-JDK21<\/li>\n\t<li>SAPUI5 (Search UI) \u2013 versions SAPUI5 1.108, 1.120, 1.136, 1.142, 1.71, 1.84 and 1.96<\/li>\n\t<li>SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)\u00a0\u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816 and SAP_BASIS 918<\/li>\n\t<li>SAP Financial Consolidation \u2013 version FINANCE 1010<\/li>\n\t<li>SAP Incentive and Commission Management\u00a0\u2013 versions SAP_APPL 618, S4CORE 102, 103, 104, 105, 106, 107, 108, 109, EA-APPL 600, 604, 605, 606 and 617<\/li>\n\t<li>SAP Application Server ABAP for SAP NetWeaver and ABAP Platform\u00a0\u2013 versions SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 and SAP_BASIS 816<\/li>\n\t<li>SAP HANA Deployment Infrastructure (HDI) deploy library\u00a0\u2013 version XS_HDI_DEPLOYER 1.00<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/may-2026.html\">SAP Security Patch Day\u00a0- May 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-may-2026-monthly-rollup-av26-447","alert_type":396,"serial_number":"AV26-447","subject":"sap","moderation_state":"published","external_url":null},{"nid":7677,"title":"[Control systems] Siemens security advisory (AV26-448)","uuid":"903a2043-727d-417b-b68f-99398f8225d2","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T14:31:23Z","date_created":"2026-05-12T12:34:33Z","summary":null,"body":["<article data-history-node-id=\"7677\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-448\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-448<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2026, Siemens published a security advisory to address vulnerabilities in the following products. Included were updates for the following products:<\/p>\n\n<ul><li>RUGGEDCOM ROX II family\u00a0\u2013 versions prior to V2.17.1<\/li>\n\t<li>RUGGEDCOM APE1808\u00a0\u2013 contact customer support to receive patch and update information<\/li>\n\t<li>RUGGEDCOM RM1224 LTE(4G) EU\u00a0\u2013 versions prior to V8.3<\/li>\n\t<li>SCALANCE\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Solid Edge SE2026\u00a0\u2013 versions prior to V226.0 Update 5<\/li>\n\t<li>gWAP\u00a0\u2013 versions prior to V3.1.1<\/li>\n\t<li>Simcenter Femap\u00a0\u2013 versions prior to V2512.0003<\/li>\n\t<li>Teamcenter\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIPROTEC 5\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SENTRON 7KT PAC1261 Data Manager\u00a0\u2013 versions prior to V2.1.0<\/li>\n\t<li>SIMATIC Drive Controller family\u00a0\u2013 versions prior to V3.1.6<\/li>\n\t<li>SIMATIC Drive Controller CPU 1504D TF\u00a0\u2013 versions prior to V3.1.6<\/li>\n\t<li>SIMATIC ET 200SP CPU\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC S7-1500 CPU\u00a0\u2013 versions prior to V2.9.9<\/li>\n\t<li>KACO blueplanet Inverters\u00a0\u2013 versions prior to V6.1.4.9<\/li>\n\t<li>Industrial Edge Devices\u00a0\u2013 multiple versions and models<\/li>\n\t<li>SIMATIC HMI Unified Comfort Panels Hygienic family\u00a0\u2013 versions prior to V21<\/li>\n\t<li>SIMATIC HMI Unified Comfort Panels Standard family\u00a0\u2013 versions prior to V21<\/li>\n\t<li>ROS#\u00a0\u2013 versions prior to V2.2.2<\/li>\n\t<li>Opcenter RDnL\u00a0\u2013 versions prior to V2.52.0<\/li>\n\t<li>SIMATIC CN 4100\u00a0\u2013 versions prior to V5.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-448","alert_type":398,"serial_number":"AV26-448","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7678,"title":"[Control systems] Schneider Electric security advisory (AV26-449)","uuid":"5f756924-8dd2-477a-89d7-536547bbe086","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T14:41:02Z","date_created":"2026-05-12T12:35:20Z","summary":null,"body":["<article data-history-node-id=\"7678\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-449\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-449<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2026, Schneider Electric published advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ecostruxure Machine Expert HVAC\u00a0\u2013 versions prior to 1.10.0<\/li>\n\t<li>Easergy MiCOM C264\u00a0\u2013 version D6.x and version D7.33 and prior<\/li>\n\t<li>Easergy C5\u00a0\u2013 version 1.1.17 and prior<\/li>\n\t<li>Easergy MiCOM P30\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Easergy MiCOM P40\u00a0\u2013 multiple versions and models<\/li>\n\t<li>EcoStruxure Power Automation System \u2013 multiple versions and models<\/li>\n\t<li>iPMFLS\u00a0\u2013 version 64.2025.0.13 and prior<\/li>\n\t<li>PowerLogic\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Saitel DP\u00a0\u2013 version 11.06.36 and prior<\/li>\n\t<li>EasyLogic T150 (formerly Saitel DR)\u00a0\u2013 version 11.06.30 and prior<\/li>\n\t<li>EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit and Controller\u00a0\u2013 version 11.06.31 and prior<\/li>\n\t<li>Saitel DP Remote Terminal Unit and Controller\u00a0\u2013 version 11.06.36 and prior<\/li>\n\t<li>EcoStruxure Panel Server PAS400, PAS600, PAS600V2, PAS800, PAS800V2\u00a0\u2013 version 002.005.000 and prior<\/li>\n\t<li>Easergy MiCOM Px40 Series\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-132-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-132-01.pdf\">Clear Text Storage of Sensitive Information on EcoStruxure Machine Expert HVAC (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-132-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-132-02.pdf\">Insufficient Entropy vulnerability on Multiple Products (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-132-03&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-132-03.pdf\">Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple Products (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/download.schneider-electric.com\/files?p_Doc_Ref=SEVD-2026-132-04&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-132-04.pdf\">Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure Panel Server (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-449","alert_type":398,"serial_number":"AV26-449","subject":"other","moderation_state":"published","external_url":null},{"nid":7679,"title":"Ivanti security advisory (AV26-450)","uuid":"0e7519b6-8d18-4f26-a043-309502903cd8","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T15:27:11Z","date_created":"2026-05-12T14:42:43Z","summary":null,"body":["<article data-history-node-id=\"7679\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-450\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-450<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2026, Ivanti published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Ivanti Xtraction\u00a0\u2013 version 2026.1 and prior<\/li>\n\t<li>Ivanti Endpoint Manager (EPM)\u00a0\u2013 version 2024 SU5 and prior<\/li>\n\t<li>Ivanti Virtual Traffic Manager (vTM)\u00a0\u2013 version 22.9r3 and prior<\/li>\n\t<li>Ivanti Secure Access Client (Windows)\u00a0\u2013 version 22.8R5 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/kA1UL0000008mU50AI\">Security Advisory\u00a0- Ivanti Xtraction (CVE-2026-8043)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/kA1UL0000008mPF0AY\">Security Advisory Ivanti Endpoint Manager (EPM) May 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/kA1UL0000008mST0AY\">May 2026 Security Advisory Ivanti Virtual Traffic Manager (vTM) (CVE-2026-8051)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/article\/kA1UL0000008mQr0AI\">May 2026 Security Advisory Ivanti Secure Access Client (CVE-2026-7431, CVE-2026-7432)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-450","alert_type":396,"serial_number":"AV26-450","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7680,"title":"Mozilla security advisory (AV26-451)","uuid":"688c403d-82c9-47d5-b861-f284cf6b332e","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T15:31:36Z","date_created":"2026-05-12T15:28:23Z","summary":null,"body":["<article data-history-node-id=\"7680\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-451\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-451<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2026, Mozilla published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 150.0.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-45\/\">Mozilla Foundation Security Advisory 2026-45<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-451","alert_type":396,"serial_number":"AV26-451","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7682,"title":"Adobe security advisory (AV26-452)","uuid":"eca10064-269e-4404-8149-53f1af648793","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T18:47:10Z","date_created":"2026-05-12T18:40:02Z","summary":null,"body":["<article data-history-node-id=\"7682\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-452\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-452<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2026, Adobe published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Premiere\u00a0\u2013 version 26.0.2 and prior<\/li>\n\t<li>Adobe Premiere Pro\u00a0\u2013 version 25.6.4 and prior<\/li>\n\t<li>Adobe Media Encoder\u00a0\u2013 version 25.6.4 and prior, version 26.0.2 and prior<\/li>\n\t<li>Adobe After Effects\u00a0\u2013 version 25.6.4 and\u202fprior, version 26.0 and\u202fprior<\/li>\n\t<li>Adobe Commerce\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Commerce B2B\u00a0\u2013 multiple versions<\/li>\n\t<li>Magento Open Source\u00a0\u2013 multiple versions<\/li>\n\t<li>Adobe Connect Desktop Application \u00a0\u2013 version 2025.9.15 (Windows) and version 2025.8.157 (macOS)<\/li>\n\t<li>Illustrator 2025\u00a0\u2013 version 29.8.6 and prior<\/li>\n\t<li>Illustrator 2026\u00a0\u2013 version 30.3 and prior<\/li>\n\t<li>Adobe Substance 3D Designer\u00a0\u2013 version 15.1.0 and prior<\/li>\n\t<li>Content Authenticity JS SDK\u00a0\u2013 version @contentauth\/c2pa-web@0.7.0<\/li>\n\t<li>Content Authenticity Rust SDK\u00a0\u2013 version c2pa-v0.78.2<\/li>\n\t<li>Adobe Substance 3D Sampler\u00a0\u2013 version 5.1.3 and prior<\/li>\n\t<li>Adobe Substance 3D Painter\u00a0\u2013 version 12.0.2 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-452","alert_type":396,"serial_number":"AV26-452","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7683,"title":"Intel security advisory (AV26-453)","uuid":"0dc9cf84-1ebf-488d-951e-b6bd491a1e9a","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T18:52:54Z","date_created":"2026-05-12T18:41:22Z","summary":null,"body":["<article data-history-node-id=\"7683\" about=\"\/en\/alerts-advisories\/intel-security-advisory-av26-453\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-453<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2025, Intel published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Display Virtualization for Windows OS driver software\u00a0\u2013 versions prior to 2119<\/li>\n\t<li>Intel EMA software\u00a0\u2013 versions prior to 1.14.5<\/li>\n\t<li>AI Playground software\u00a0\u2013 versions prior to 3.0.0 alpha<\/li>\n\t<li>Intel Vision software\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-01430.html\">Display Virtualization for Windows OS Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-01434.html\">Intel EMA Software Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-01438.html\">AI Playground Software Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/advisory\/intel-sa-01457.html\">Intel Vision Software Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/security-center\/default.html\">Intel Product Security Center Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/intel-security-advisory-av26-453","alert_type":396,"serial_number":"AV26-453","subject":"intel","moderation_state":"published","external_url":null},{"nid":7684,"title":"Fortinet security advisory (AV26-454)","uuid":"469af74c-8b5e-4ae2-a5af-71f420db8c20","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T19:00:30Z","date_created":"2026-05-12T18:41:47Z","summary":null,"body":["<article data-history-node-id=\"7684\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-454\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-454<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiAuthenticator 8.0\u00a0\u2013 version 8.0.2<\/li>\n\t<li>FortiAuthenticator 8.0\u00a0\u2013 version 8.0.0<\/li>\n\t<li>FortiAuthenticator 6.6\u00a0\u2013 versions 6.6.0 to 6.6.8<\/li>\n\t<li>FortiAuthenticator 6.5\u00a0\u2013 versions 6.5.0 to 6.5.6<\/li>\n\t<li>FortiOS 7.6\u00a0\u2013 versions 7.6.0 to 7.6.3<\/li>\n\t<li>FortiOS 7.4\u00a0\u2013 versions 7.4.0 to 7.4.8<\/li>\n\t<li>FortiOS 7.2\u00a0\u2013 versions 7.2.0 to 7.2.11<\/li>\n\t<li>FortiSandbox 5.0\u00a0\u2013 versions 5.0.0 to 5.0.1<\/li>\n\t<li>FortiSandbox 4.4\u00a0\u2013 versions 4.4.0 to 4.4.8<\/li>\n\t<li>FortiSandbox Cloud 24\u00a0\u2013 all versions<\/li>\n\t<li>FortiSandbox Cloud 23\u00a0\u2013 all versions<\/li>\n\t<li>FortiSandbox Cloud 5.0\u00a0\u2013 versions 5.0.2 to 5.0.5<\/li>\n\t<li>FortiSandbox PaaS 23.4\u00a0\u2013 23.4 all versions<\/li>\n\t<li>FortiSandbox PaaS 23.3\u00a0\u2013 23.3 all versions<\/li>\n\t<li>FortiSandbox PaaS 23.1\u00a0\u2013 23.1 all versions<\/li>\n\t<li>FortiSandbox PaaS 22.2\u00a0\u2013 22.2 all versions<\/li>\n\t<li>FortiSandbox PaaS 22.1\u00a0\u2013 22.1 all versions<\/li>\n\t<li>FortiSandbox PaaS 21.4\u00a0\u2013 21.4 all versions<\/li>\n\t<li>FortiSandbox PaaS 21.3 \u2013 21.3 all versions<\/li>\n\t<li>FortiSandbox PaaS 5.0\u00a0\u2013 versions 5.0.0 to 5.0.1<\/li>\n\t<li>FortiSandbox PaaS 4.4\u00a0\u2013 versions 4.4.5 to 4.4.8<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-128\">Improper access control on API endpoints<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-136\">Incorrect global authorization<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-123\">Out-of-bounds access in CAPWAP daemon<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-454","alert_type":396,"serial_number":"AV26-454","subject":"other","moderation_state":"published","external_url":null},{"nid":7685,"title":"AMD security advisory (AV26-455)","uuid":"95674962-cb9c-4a76-91df-318f90848b69","banner":null,"lang":"en","date_modified":"2026-05-12","date_modified_ts":"2026-05-12T19:04:15Z","date_created":"2026-05-12T18:42:16Z","summary":null,"body":["<article data-history-node-id=\"7685\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-455\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-455<br \/><strong>Date: <\/strong>May 12, 2026<\/p>\n\n<p>On May 12, 2025, AMD published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-455","alert_type":396,"serial_number":"AV26-455","subject":"other","moderation_state":"published","external_url":null},{"nid":7686,"title":"Microsoft security advisory \u2013 May 2026 monthly rollup (AV26-456) \u2013 Update 3","uuid":"611e2996-804b-4ac5-962f-64e6edd91326","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T12:34:39Z","date_created":"2026-05-12T18:42:46Z","summary":null,"body":["<article data-history-node-id=\"7686\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-may-2026-monthly-rollup-av26-456\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-456<br \/><strong>Date: <\/strong>May 12, 2026<br \/><strong>Updated:<\/strong>\u00a0July 2, 2026<\/p>\n\n<p>On May 12, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>.NET 10.0 installed on Linux<\/li>\n\t<li>.NET 10.0 installed on Mac OS<\/li>\n\t<li>.NET 10.0 installed on Windows<\/li>\n\t<li>.NET 8.0 installed on Linux<\/li>\n\t<li>.NET 8.0 installed on Mac OS<\/li>\n\t<li>.NET 8.0 installed on Windows<\/li>\n\t<li>.NET 9.0 installed on Linux<\/li>\n\t<li>.NET 9.0 installed on Mac OS<\/li>\n\t<li>.NET 9.0 installed on Windows<\/li>\n\t<li>Azure AI Foundry<\/li>\n\t<li>Azure Cloud Shell<\/li>\n\t<li>Azure Connected Machine Agent<\/li>\n\t<li>Azure DevOps<\/li>\n\t<li>Azure Logic Apps<\/li>\n\t<li>Azure Machine Learning<\/li>\n\t<li>Azure Managed Instance for Apache Cassandra<\/li>\n\t<li>Azure Monitor Action Group notification system<\/li>\n\t<li>Azure Monitor Agent<\/li>\n\t<li>Azure Monitor Agent Metrics Extension<\/li>\n\t<li>Azure SDK for Java<\/li>\n\t<li>Copilot Chat (Microsoft Edge)<\/li>\n\t<li>Dynamics 365 Customer Insights<\/li>\n\t<li>M365 Copilot for Desktop<\/li>\n\t<li>Microsoft .NET Framework 3.5<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.7.2<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.8<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.8.1<\/li>\n\t<li>Microsoft .NET Framework 4.6.2\/4.7\/4.7.1\/4.7.2<\/li>\n\t<li>Microsoft .NET Framework 4.8<\/li>\n\t<li>Microsoft 365<\/li>\n\t<li>Microsoft 365 Copilot for Android<\/li>\n\t<li>Microsoft 365 Copilot's Business Chat<\/li>\n\t<li>Microsoft Confluence SAML SSO plugin<\/li>\n\t<li>Microsoft Data Formulator<\/li>\n\t<li>Microsoft Dynamics 365<\/li>\n\t<li>Microsoft Dynamics 365 Business Central<\/li>\n\t<li>Microsoft Edge (Chromium-based)<\/li>\n\t<li>Microsoft Enterprise Security Token Service (ESTS)<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Excel for Android<\/li>\n\t<li>Microsoft JIRA SAML SSO plugin<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft Outlook for iOS<\/li>\n\t<li>Microsoft Partner Center<\/li>\n\t<li>Microsoft PowerPoint for Android<\/li>\n\t<li>Microsoft SQL Server 2016<\/li>\n\t<li>Microsoft SQL Server 2017<\/li>\n\t<li>Microsoft SQL Server 2019<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SQL Server 2025<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Teams<\/li>\n\t<li>Microsoft Teams for Android<\/li>\n\t<li>Microsoft Visual Studio 2017<\/li>\n\t<li>Microsoft Visual Studio 2019<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Microsoft Visual Studio 2026<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Microsoft Word for Android<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Power Automate for Desktop<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Visual Studio Code\u00a0- Live Preview extension<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Admin Center<\/li>\n\t<li>Windows Admin Center in Azure Portal<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>On May 21, 2026, Microsoft published an out-of-band (OOB) security update to address CVE-2026-45659, an additional vulnerability impacting Microsoft SharePoint Enterprise Server 2019, Microsoft SharePoint Server 2016 and Microsoft SharePoint Server Subscription Edition. The CVE was inadvertently omitted from the May 2026 Security Updates.<\/p>\n\n<h2>Update 2<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-41089 is being exploited in the wild.<\/p>\n\n<h2>Update 3<\/h2>\n\n<p>On July 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45659 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-May\">May 2026 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45659\">Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-41089\">Windows Netlogon Remote Code Execution Vulnerability CVE-2026-41089<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659\">CISA KEV\u00a0\u2013 CVE-2026-45659<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-may-2026-monthly-rollup-av26-456","alert_type":396,"serial_number":"AV26-456","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7688,"title":"HPE security advisory (AV26-457)","uuid":"1104021d-aabc-4a2b-864e-427d8c9e7c4d","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T12:26:05Z","date_created":"2026-05-13T12:19:27Z","summary":null,"body":["<article data-history-node-id=\"7688\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-457\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-457<br \/><strong>Date:<\/strong> May 13, 2026<\/p>\n\n<p>On May 12, 2026, HPE published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ArubaOS AOS-10.8.x.x\u00a0\u2013 version 10.8.0.0 and prior<\/li>\n\t<li>ArubaOS AOS-10.7.x.x\u00a0\u2013 version 10.7.2.2 and prior<\/li>\n\t<li>ArubaOS AOS-10.4.x.x\u00a0\u2013 version 10.4.1.10 and prior<\/li>\n\t<li>ArubaOS AOS-8.13.x.x\u00a0\u2013 version 8.13.1.1 and prior<\/li>\n\t<li>ArubaOS AOS-8.12.x.x\u00a0\u2013 version 8.12.0.6 and prior<\/li>\n\t<li>ArubaOS AOS-8.10.x.x\u00a0\u2013 version 8.10.0.21 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05048en_us&amp;docLocale=en_US \">HPESBNW05048 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking Operating Systems AOS-8 &amp; AOS-10.<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05049en_us&amp;docLocale=en_US\">HPESBNW05049 rev.1\u00a0- HPE Aruba Networking AOS-8 Instant AP and AOS-10 AP, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-457","alert_type":396,"serial_number":"AV26-457","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7689,"title":"Google Chrome security advisory (AV26-458)","uuid":"3457f346-75cf-4a6a-9d67-cf8f91854917","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T12:31:25Z","date_created":"2026-05-13T12:27:55Z","summary":null,"body":["<article data-history-node-id=\"7689\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-458\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-458<br \/><strong>Date:<\/strong> May 13, 2026<\/p>\n\n<p>On May 12, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 148.0.7778.167\/168 (Windows\/Mac) and 148.0.7778.167 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"http:\/\/chromereleases.googleblog.com\/2026\/05\/stable-channel-update-for-desktop_12.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-458","alert_type":396,"serial_number":"AV26-458","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7690,"title":"n8n security advisory (AV26-459)","uuid":"43531266-95f9-4c45-a98a-853ded8188a5","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T13:11:54Z","date_created":"2026-05-13T13:09:17Z","summary":null,"body":["<article data-history-node-id=\"7690\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-459\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-459<br \/><strong>Date:<\/strong> May 13, 2026<strong> <\/strong><\/p>\n\n<p>On May 13, 2026, n8n published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>n8n (Pagination Prototype Pollution)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Dynamic Credential OAuth Endpoints)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Source Control)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (XML Node Prototype Pollution)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Git Node)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-459","alert_type":396,"serial_number":"AV26-459","subject":"other","moderation_state":"published","external_url":null},{"nid":7691,"title":"Exim security advisory (AV26-460)","uuid":"e3954b6b-8422-49c0-882a-02c0fdc936f7","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T14:58:00Z","date_created":"2026-05-13T14:55:25Z","summary":null,"body":["<article data-history-node-id=\"7691\" about=\"\/en\/alerts-advisories\/exim-security-advisory-av26-460\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-460<br \/><strong>Date:<\/strong> May 13, 2026<\/p>\n\n<p>On May 12, 2026, Exim published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Exim\u00a0\u2013 version 4.97 to 4.99.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.exim.org\/static\/doc\/security\/EXIM-Security-2026-05-01.1\/EXIM-Security-2026-05-01.1.txt\">Exim Security Advisory for EXIM-Security-2026-05-01.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.exim.org\/download.html\">Download sites for Exim<\/a><\/li>\n\t<li><a href=\"https:\/\/www.exim.org\/\">Exim Internet Mailer<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-av26-460","alert_type":396,"serial_number":"AV26-460","subject":"other","moderation_state":"published","external_url":null},{"nid":7693,"title":"F5 security advisory (AV26-461)","uuid":"b0ebb9f2-7f38-4c56-9c75-42ae1199ad2e","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T17:44:55Z","date_created":"2026-05-13T17:40:29Z","summary":null,"body":["<article data-history-node-id=\"7693\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-461\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-461<br \/><strong>Date: <\/strong>May 13, 2026<\/p>\n\n<p>On May 13, 2026, F5 published security updates for multiple products. Included were updates for the following:<\/p>\n\n<ul><li>BIG-IP (all modules) \u2013 multiple versions<\/li>\n\t<li>BIG-IP APM \u2013 multiple versions<\/li>\n\t<li>BIG-IP Advanced WAF\/ASM \u2013 multiple versions<\/li>\n\t<li>BIG-IP BIG-IP Advanced WAF\/ASM and BIG-IP DDoS Hybrid Defender \u2013 multiple versions<\/li>\n\t<li>BIG-IP Next CNF \u2013 multiple versions<\/li>\n\t<li>BIG-IP Next CNF \u2013 versions 2.0.0 to 2.0.2, versions 1.1.0 to 1.4.0<\/li>\n\t<li>BIG-IP Next CNF \u2013 versions 2.0.0 to 2.2.1, versions 1.1.0 to 1.4.1<\/li>\n\t<li>BIG-IP Next SPK \u2013 versions 2.0.0 to 2.0.2, versions 1.7.0 to 1.7.15<\/li>\n\t<li>BIG-IP Next SPK \u2013 versions 2.0.0 to 2.0.2, versions 1.7.0 to 1.7.16<\/li>\n\t<li>BIG-IP Next SPK \u2013 versions 2.0.0 to 2.0.3, versions 1.7.0 to 1.9.2<\/li>\n\t<li>BIG-IP Next for Kubernetes \u2013 version 2.0.0<\/li>\n\t<li>BIG-IP Next for Kubernetes \u2013 versions 2.0.0 to 2.1.0<\/li>\n\t<li>BIG-IP Next for Kubernetes \u2013 versions 2.0.0 to 2.1.1<\/li>\n\t<li>BIG-IP PEM \u2013 multiple versions<\/li>\n\t<li>BIG-IQ Centralized Management \u2013 version 8.4.0<\/li>\n\t<li>F5 DoS for NGINX \u2013 version 4.8.0<\/li>\n\t<li>F5 WAF for NGINX \u2013 versions 5.9.0 to 5.12.1<\/li>\n\t<li>NGINX App Protect DoS \u2013 versions 4.3.0 to 4.7.0<\/li>\n\t<li>NGINX App Protect WAF \u2013 versions 5.1.0 to 5.8.0, versions 4.9.0 to 4.16.0<\/li>\n\t<li>NGINX Gateway Fabric \u2013 versions 2.0.0 to 2.5.1, versions 1.3.0 to 1.6.2<\/li>\n\t<li>NGINX Ingress Controller \u2013 multiple versions<\/li>\n\t<li>NGINX Instance Manager \u2013 versions 2.16.0 to 2.21.1<\/li>\n\t<li>NGINX Open Source \u2013 versions 1.0.0 to 1.30.0, versions 0.6.27 to 0.9.7<\/li>\n\t<li>NGINX Plus \u2013 versions R32 to R36<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000160932\">K000160932: Quarterly Security Notification (May 2026)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-461","alert_type":396,"serial_number":"AV26-461","subject":"f5","moderation_state":"published","external_url":null},{"nid":7694,"title":"Palo Alto Networks security advisory (AV26-462) \u2013 Update 1","uuid":"eb9e35c6-e4e8-4786-b196-323fb407870f","banner":null,"lang":"en","date_modified":"2026-05-29","date_modified_ts":"2026-05-29T20:10:00Z","date_created":"2026-05-13T17:46:42Z","summary":null,"body":["<article data-history-node-id=\"7694\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-462\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-462<br \/><strong>Date: <\/strong>May 13, 2026<br \/><strong>Updated:<\/strong> May 29, 2026<\/p>\n\n<p>On May 13, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.4-h5<\/li>\n\t<li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.7<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 multiple versions<\/li>\n<\/ul><p><strong>Update 1<\/strong><\/p>\n\n<p>On May 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>Impacted products for CVE-2026-0257:<\/p>\n\n<ul><li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.4-h6<\/li>\n\t<li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.7<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 multiple versions<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 multiple versions<\/li>\n\t<li>Prisma Access 11.2.0\u00a0\u2013 versions prior to 11.2.7-h13<\/li>\n\t<li>Prisma Access 10.2.0\u00a0\u2013 versions prior to 10.2.10-h36<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0265\">CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0264\">CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0263\">CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0257\">CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257\">CISA KEV: CVE-2026-0257<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-462","alert_type":396,"serial_number":"AV26-462","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7695,"title":"Drupal security advisory (AV26-463)","uuid":"51550859-477c-490a-9785-bc6083cc82a2","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T18:30:45Z","date_created":"2026-05-13T18:24:27Z","summary":null,"body":["<article data-history-node-id=\"7695\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-463\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-463<br \/><strong>Date:<\/strong> May 13, 2026<\/p>\n\n<p>On May 13, 2026, Drupal published security updates for multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Date iCal \u2013 versions prior to 4.0.15<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-037\">Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-463","alert_type":396,"serial_number":"AV26-463","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7696,"title":"cPanel security advisory (AV26-464)","uuid":"dcc2a7a2-6ffd-4ab7-92c9-c22547528606","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T18:39:13Z","date_created":"2026-05-13T18:34:06Z","summary":null,"body":["<article data-history-node-id=\"7696\" about=\"\/en\/alerts-advisories\/cpanel-security-advisory-av26-464\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-464<br \/><strong>Date:<\/strong> May 13, 2026<\/p>\n\n<p>On May 13, 2026, cPanel published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>cPanel &amp; WebHost Manager (WHM) software \u2013 versions prior to 11.86.0.44, 11.94.0.31, 11.102.0.42, 11.110.0.118, 11.118.0.67, 11.124.0.38, 11.126.0.59, 11.130.0.23, 11.132.0.32, 11.134.0.26, 11.136.0.10 and WP Squared 11.136.1.12<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360007088193-Security\">cPanel Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cpanel-security-advisory-av26-464","alert_type":396,"serial_number":"AV26-464","subject":"other","moderation_state":"published","external_url":null},{"nid":7697,"title":"HPE security advisory (AV26-465)","uuid":"89c2985f-639c-4674-9252-f8f8f722a71a","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T19:26:44Z","date_created":"2026-05-13T19:22:56Z","summary":null,"body":["<article data-history-node-id=\"7697\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-465\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-465<br \/><strong>Date: <\/strong>May 13, 2026<\/p>\n\n<p>On May 12, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Intelligent Assurance \u2013 version 4.2.14<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05045en_us&amp;docLocale=en_US\">HPESBNW05045 rev.1 - Telco Intelligent Assurance, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-465","alert_type":396,"serial_number":"AV26-465","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7698,"title":"Apple security advisory (AV26-466)","uuid":"ca5740a5-20f8-464c-a1d1-4ffe37ffd6ee","banner":null,"lang":"en","date_modified":"2026-05-13","date_modified_ts":"2026-05-13T19:31:08Z","date_created":"2026-05-13T19:28:12Z","summary":null,"body":["<article data-history-node-id=\"7698\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-466\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-466<br \/><strong>Date:<\/strong> May 13, 2026<\/p>\n\n<p>On May 13, 2026, Apple published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Safari \u2013 versions prior to 26.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/127121\">About the security content of Safari 26.5<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-466","alert_type":396,"serial_number":"AV26-466","subject":"apple","moderation_state":"published","external_url":null},{"nid":7699,"title":"GitLab security advisory (AV26-467)","uuid":"8f0ad1f2-c9a7-4ea8-9720-174f1d6d53b9","banner":null,"lang":"en","date_modified":"2026-05-14","date_modified_ts":"2026-05-14T13:22:06Z","date_created":"2026-05-14T13:03:56Z","summary":null,"body":["<article data-history-node-id=\"7699\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-467\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-467<br \/><strong>Date:<\/strong> May\u00a014, 2026<\/p>\n\n<p>On May\u00a013, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 18.11.3, 18.10.6 and 18.9.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 18.11.3, 18.10.6 and 18.9.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-18-11-3-released\/\">GitLab Patch Release: 18.11.3, 18.10.6, 18.9.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-467","alert_type":396,"serial_number":"AV26-467","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7700,"title":"MongoDB security advisory (AV26-468)","uuid":"082cdfc6-6f45-44f7-ac04-af3e0393d258","banner":null,"lang":"en","date_modified":"2026-05-14","date_modified_ts":"2026-05-14T15:43:38Z","date_created":"2026-05-14T15:15:51Z","summary":null,"body":["<article data-history-node-id=\"7700\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory-av26-468\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-468<br \/><strong>Date: <\/strong>May\u00a014, 2026<\/p>\n\n<p>On May\u00a012, 2026, MongoDB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>MongoDB\u00a0\u2013 version 8.3.0 to 8.3.1<\/li>\n\t<li>MongoDB\u00a0\u2013 version 8.2.0 to 8.2.8<\/li>\n\t<li>MongoDB\u00a0\u2013 version 8.0.0 to 8.0.22<\/li>\n\t<li>MongoDB\u00a0\u2013 version 7.0.0 to 7.0.33<\/li>\n\t<li>MongoDB\u00a0\u2013 version 6.0.0 to 6.0.27<\/li>\n\t<li>MongoDB\u00a0\u2013 version 5.0.0 to 5.0.32<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/jira.mongodb.org\/browse\/SERVER-126021\">MongoDB\u00a0- (CVE-2026-8053) Undefined behavior when inserting data with duplicate field names into timeseries collections<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory-av26-468","alert_type":396,"serial_number":"AV26-468","subject":"other","moderation_state":"published","external_url":null},{"nid":7701,"title":"Broadcom VMware security advisory (AV26-469)","uuid":"042cd75c-832d-418a-bc6f-95c524c8c084","banner":null,"lang":"en","date_modified":"2026-05-14","date_modified_ts":"2026-05-14T15:48:40Z","date_created":"2026-05-14T15:15:52Z","summary":null,"body":["<article data-history-node-id=\"7701\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-469\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-469<br \/><strong>Date: <\/strong>May\u00a014, 2026<\/p>\n\n<p>On May\u00a014, 2026, Broadcom published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>VMware Fusion\u00a0\u2013 versions prior to 26H1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37454\">VMSA-2026-0003: VMware Fusion updates address privilege escalation vulnerability (CVE-2026-41702)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-469","alert_type":396,"serial_number":"AV26-469","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7702,"title":"PostgreSQL security advisory (AV26-470)","uuid":"dda9a729-69bf-4a27-9556-f1fc9dece4b7","banner":null,"lang":"en","date_modified":"2026-05-14","date_modified_ts":"2026-05-14T16:00:15Z","date_created":"2026-05-14T15:15:52Z","summary":null,"body":["<article data-history-node-id=\"7702\" about=\"\/en\/alerts-advisories\/postgresql-security-advisory-av26-470\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-470<br \/><strong>Date:<\/strong> May\u00a014, 2026<\/p>\n\n<p>On May\u00a014, 2026, PostgreSQL published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PostgreSQL\u00a0\u2013 14.x versions prior to 14.23<\/li>\n\t<li>PostgreSQL\u00a0\u2013 15.x versions prior to 15.18<\/li>\n\t<li>PostgreSQL\u00a0\u2013 16.x versions prior to 16.14<\/li>\n\t<li>PostgreSQL\u00a0\u2013 17.x versions prior to 17.10<\/li>\n\t<li>PostgreSQL\u00a0\u2013 18.x versions prior to 18.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.postgresql.org\/about\/news\/postgresql-184-1710-1614-1518-and-1423-released-3297\/\">PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 Released!<\/a><\/li>\n\t<li><a href=\"https:\/\/www.postgresql.org\/support\/security\/\">PostgreSQL Security Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/postgresql-security-advisory-av26-470","alert_type":396,"serial_number":"AV26-470","subject":"other","moderation_state":"published","external_url":null},{"nid":7703,"title":"Cisco security advisory (AV26-471)","uuid":"b5ebe38f-876a-41ca-a65f-97e4de4ddb04","banner":null,"lang":"en","date_modified":"2026-05-14","date_modified_ts":"2026-05-14T18:33:33Z","date_created":"2026-05-14T18:19:36Z","summary":null,"body":["<article data-history-node-id=\"7703\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-471\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-471<br \/><strong>Date:<\/strong> May\u00a014, 2026<\/p>\n\n<p>On May\u00a014, 2026, Cisco published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.9 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.10 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.11 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.12 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.13 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.14 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.15 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.16 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 20.18 and prior<\/li>\n\t<li>Cisco Catalyst SD-WAN Release\u00a0\u2013 versions 26.1 and prior<\/li>\n<\/ul><p>Cisco is aware of limited exploitation of CVE-2026-20182.<\/p>\n\n<p>On May\u00a014, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20182 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-rpa2-v69WY2SW\">Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-mltvnps2-JxpWm7R\">Cisco Catalyst SD-WAN Manager Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20182\">CISA KEV: CVE-2026-20182<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-471","alert_type":396,"serial_number":"AV26-471","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7704,"title":"  Tenable security advisory (AV26-472)","uuid":"3e7ee67d-ab5b-4657-9095-a24b0487b6d3","banner":null,"lang":"en","date_modified":"2026-05-14","date_modified_ts":"2026-05-14T20:03:36Z","date_created":"2026-05-14T19:59:18Z","summary":null,"body":["<article data-history-node-id=\"7704\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-472\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number<\/strong>: AV26-472<br \/><strong>Date:<\/strong> May 14, 2026<\/p>\n\n<p>On May 14, 2026, Tenable published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Tenable Network Monitor\u00a0\u2013 versions prior to 6.5.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-14\">[R1] Tenable Network Monitor 6.5.4 Fixes Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-472","alert_type":396,"serial_number":"AV26-472","subject":"other","moderation_state":"published","external_url":null},{"nid":7705,"title":"AL26-012 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20182","uuid":"1061eb0b-2569-473e-b095-9eb34dcd0e87","banner":null,"lang":"en","date_modified":"2026-05-15","date_modified_ts":"2026-05-15T13:03:19Z","date_created":"2026-05-15T12:02:38Z","summary":null,"body":["<article data-history-node-id=\"7705\" about=\"\/en\/alerts-advisories\/al26-012-critical-vulnerability-affecting-cisco-catalyst-sd-wan-cve-2026-20182\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-012<br \/><strong>Date:<\/strong> May\u00a015, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\">1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> of Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) devices <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>. In response to the Cisco security advisory released on May 14, 2026<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>, the Cyber Centre issued AV26-471<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> on May 14, 2026.<\/p>\n\n<p>Tracked as CVE-2026-20182 <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>, this vulnerability is a critical Improper authentication vulnerability (CWE-287)<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> affecting the peering authentication process of Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). It could allow an unauthenticated, remote attacker to bypass authentication, elevate privileges, and obtain administrative privileges on affected systems.<\/p>\n\n<p>Cisco Catalyst SD-WAN Controller systems accessible from the internet, particularly those with exposed network ports, are at risk of exposure to compromise.<\/p>\n\n<p>This vulnerability affects Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, regardless of device configuration. The vulnerability affects all deployment types, including:<\/p>\n\n<ul><li>On-Prem Deployment<\/li>\n\t<li>Cisco SD-WAN Cloud-Pro<\/li>\n\t<li>Cisco SD-WAN Cloud\u00a0- Cisco Managed<\/li>\n\t<li>Cisco SD-WAN for Government\u00a0- FedRAMP Environment<\/li>\n<\/ul><p>The Cyber Centre is aware of incidents involving CVE-2026-20182; with reported attempts of SSH keys being added, NETCONF configurations being modified and escalation to root privileges. This allowed multiple follow-up actions including administrative access, persistence and long-term access to SD-WAN networks.<\/p>\n\n<p>Cisco has also noted the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 previously reported in February 2026 <sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>. The Cyber Centre released AL26-004 <sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup> at that time highlighting the issue.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected Cisco Catalyst SD-WAN instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected version<\/th>\n\t\t\t<th scope=\"col\">Solution<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>Earlier than 20.9<sup id=\"fn*-rf\"><a class=\"fn-lnk\" href=\"#fn*\">*<\/a><\/sup><\/td>\n\t\t\t<td>Migrate to a fixed release.<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.9<\/td>\n\t\t\t<td>20.9.9.1<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.10<\/td>\n\t\t\t<td>20.12.7.1<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.11<sup id=\"fn*a-rf\"><a class=\"fn-lnk\" href=\"#fn*\">*<\/a><\/sup><\/td>\n\t\t\t<td>20.12.7.1<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.12<\/td>\n\t\t\t<td>20.12.5.4<br \/>\n\t\t\t20.12.6.2<br \/>\n\t\t\t20.12.7.1<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.13<sup id=\"fn*b-rf\"><a class=\"fn-lnk\" href=\"#fn*\">*<\/a><\/sup><\/td>\n\t\t\t<td>20.15.5.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.14<sup id=\"fn*c-rf\"><a class=\"fn-lnk\" href=\"#fn*\">*<\/a><\/sup><\/td>\n\t\t\t<td>20.15.5.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.15<\/td>\n\t\t\t<td>20.15.4.4<br \/>\n\t\t\t20.15.5.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.16<sup id=\"fn*d-rf\"><a class=\"fn-lnk\" href=\"#fn*\">*<\/a><\/sup><\/td>\n\t\t\t<td>20.18.2.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>20.18<sup id=\"fn*e-rf\"><a class=\"fn-lnk\" href=\"#fn*\">*<\/a><\/sup><\/td>\n\t\t\t<td>20.18.2.2<\/td>\n\t\t<\/tr><tr><td>Cisco Catalyst SD-WAN<\/td>\n\t\t\t<td>26.1<\/td>\n\t\t\t<td>26.1.1.1<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>Cisco has also addressed this vulnerability in Cisco SD-WAN Cloud (Cisco Managed) Release 20.15.506, which is cloud based. No user action is required. Customers can determine the current remediation status or software version by using the Help function in the service GUI<sup id=\"fn4a-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre also recommends organizations to:<\/p>\n\n<ul><li>Review the Cisco advisory<sup id=\"fn4b-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> and the Talos Intelligence article<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> to identify if indicators of compromise are present on their devices.<\/li>\n\t<li>Cisco states to preserve possible indicators of compromise, customers should issue the <strong>request admin-tech<\/strong> command from each of the control components in the SD-WAN deployment before upgrading<sup id=\"fn4c-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup>.<\/li>\n\t<li>Collect artifacts, including virtual snapshots and logs from SD-WAN technology.<\/li>\n\t<li>Fully patch SD-WAN technology including those that are affected by CVE-2026-20182.<\/li>\n\t<li>Implement recommendations from the Cisco SD-WAN hardening guide<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup>.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions with an emphasis on the following topics<sup id=\"fn12-rf\"><a class=\"fn-lnk\" href=\"#fn12\"><span class=\"wb-inv\">Footnote <\/span>12<\/a><\/sup>.<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt id=\"fn*-dt\">*<\/dt>\n\t<dd id=\"fn*\" tabindex=\"-1\">\n\t<p>These releases have reached End of Software Maintenance.<\/p>\n\n\t<p class=\"fn-rtn\"><a data-wb-fnote=\"true\" href=\"#fn*b-rf\"><span class=\"wb-inv\">Return to footnote<\/span>*<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/blog.talosintelligence.com\/sd-wan-ongoing-exploitation\/\">Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.rapid7.com\/blog\/post\/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed\/\">Rapid7 CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/topics\/networking\/what-is-sd-wan.html\">What is SD-WAN? Software-Defined WAN (SDWAN)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-rpa2-v69WY2SW\">Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-471\">Cisco security advisory (AV26-471)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-20182\">cve.org\u00a0- CVE-2026-20182<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/287.html\">CWE-287: Improper Authentication<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-authbp-qwCX8D4v\">Cisco Catalyst SD-WAN Vulnerabilities<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"\/en\/alerts-advisories\/al26-004-critical-vulnerability-affecting-cisco-catalyst-sd-wan-cve-2026-20127\">AL26-004\u00a0- Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20127<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/routers\/sd-wan\/225842-remediate-catalyst-sd-wan-security.html\">Remediate Catalyst SD-WAN Security Advisory\u00a0- May 2026<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/resources\/Cisco-Catalyst-SD-WAN-HardeningGuide\">Cisco Catalyst SD-WAN Hardening Guide<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 12<\/dt>\n\t<dd id=\"fn12\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn12-rf\"><span class=\"wb-inv\">Return to footnote<\/span>12<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><dl><\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-012-critical-vulnerability-affecting-cisco-catalyst-sd-wan-cve-2026-20182","alert_type":397,"serial_number":"AL26-012","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7706,"title":"Microsoft security advisory (AV26-473) \u2013 Update 1","uuid":"2a6736be-07ad-49d1-af45-d4c13708a22a","banner":null,"lang":"en","date_modified":"2026-05-15","date_modified_ts":"2026-05-15T17:42:44Z","date_created":"2026-05-15T13:38:21Z","summary":null,"body":["<article data-history-node-id=\"7706\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-av26-473\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-473<br \/><strong>Date:<\/strong> May 15, 2026<strong> <\/strong><\/p>\n\n<p>On May 14, 2026, Microsoft published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Microsoft Exchange Server 2016 on premises versions (any update level)<\/li>\n\t<li>Microsoft Exchange Server 2019 on premises versions (any update level)<\/li>\n\t<li>Exchange Server Subscription Edition (SE) on premises versions (any update level)<\/li>\n<\/ul><p>Microsoft is aware of limited exploitation of CVE-2026-42897.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On May 15, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-42897 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-42897\">Microsoft Exchange Server Spoofing Vulnerability CVE-2026-42897 Security Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/exchange\/plan-and-deploy\/post-installation-tasks\/security-best-practices\/exchange-emergency-mitigation-service\">Exchange Emergency Mitigation (EM) service<\/a><\/li>\n\t<li><a href=\"https:\/\/techcommunity.microsoft.com\/blog\/exchange\/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897\/4518498\">Exchange Team Blog - Addressing Exchange Server May 2026 vulnerability CVE-2026-42897<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42897\">CISA KEV: CVE-2026-42897<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-av26-473","alert_type":396,"serial_number":"AV26-473","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7707,"title":"FreePBX security advisory (AV26\u2013474)","uuid":"00e590bb-ecd7-4586-b4bc-b5b46b886a29","banner":null,"lang":"en","date_modified":"2026-05-15","date_modified_ts":"2026-05-15T19:15:37Z","date_created":"2026-05-15T19:06:49Z","summary":null,"body":["<article data-history-node-id=\"7707\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-474\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013474<br \/><strong>Date: <\/strong>May 15, 2026<\/p>\n\n<p>On May 15, 2026, FreePBX published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>FreePBX Security-Reporting userman (FreePBX 16)\u00a0\u2013 versions 16.0.45 and prior<\/li>\n\t<li>FreePBX Security-Reporting userman (FreePBX 17)\u00a0\u2013 versions 17.0.7 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-m55x-h47x-v3gx\">Unauthenticated Use of Hard-Coded Credentials Vulnerability in Free PBX UCP Interface<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories?state=published\">FreePBX Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-474","alert_type":396,"serial_number":"AV26-474","subject":"other","moderation_state":"published","external_url":null},{"nid":7708,"title":"[Control systems] CISA ICS security advisories (AV26\u2013475)","uuid":"ed2286f2-f8e6-43ed-86d9-75aac4972930","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T14:52:09Z","date_created":"2026-05-19T14:38:29Z","summary":null,"body":["<article data-history-node-id=\"7708\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-475\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-475<br \/><strong>Date:<\/strong> May 19, 2026<\/p>\n\n<p>Between May 11 and 17, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB AC500 V3\u00a0- firmware version PM5xxx 3.9.0 and 3.9.0_HF1<\/li>\n\t<li>ABB AC500 V3\u00a0- versions prior to 3.9.0<\/li>\n\t<li>ABB Automation Builder Gateway\u00a0- versions prior to 2.9.0<\/li>\n\t<li>ABB WebPro SNMP Card PowerValue\u00a0- versions prior to 1.1.8.k and 1.1.8.p<\/li>\n\t<li>Fuji Electric Tellus\u00a0- version 5.0.2<\/li>\n\t<li>Siemens Industrial Devices\u00a0- multiple models and versions<\/li>\n\t<li>Siemens Opcenter RDnL\u00a0- all versions<\/li>\n\t<li>Siemens Ruggedcom Rox MX\/RX models\u00a0- versions prior to 2.17.1<\/li>\n\t<li>Siemens SENTRON 7KT PAC1261 Data Manager\u00a0- versions prior to 2.1.0<\/li>\n\t<li>Siemens SIMATIC CN 4100\u00a0- versions prior to 5.0<\/li>\n\t<li>Siemens SIMATIC S7 PLC Web Server\u00a0- multiple versions and models<\/li>\n\t<li>Siemens SIMATIC\u00a0- multiple versions and models<\/li>\n\t<li>Siemens SIPROTEC 5\u00a0- multiple versions and models<\/li>\n\t<li>Siemens Siemens ROS#\u00a0- versions prior to 2.2.2<\/li>\n\t<li>Siemens Simcenter Femap\u00a0- versions prior to 2512.0003<\/li>\n\t<li>Siemens Solid Edge\u00a0- versions prior to 226.0.5<\/li>\n\t<li>Siemens Teamcenter\u00a0- multiple versions and models<\/li>\n\t<li>Siemens gWAP\u00a0- versions prior to 3.1.1<\/li>\n\t<li>Subnet Solutions PowerSYSTEM Center\u00a0- multiple versions and models<\/li>\n\t<li>Universal Robots Polyscope 5\u00a0- versions prior to 5.25.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-475","alert_type":398,"serial_number":"AV26-475","subject":"other","moderation_state":"published","external_url":null},{"nid":7709,"title":"Microsoft Edge security advisory (AV26-476)","uuid":"4649655b-64b8-4cae-a1df-a7264378568b","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T15:37:28Z","date_created":"2026-05-19T15:19:05Z","summary":null,"body":["<article data-history-node-id=\"7709\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-476\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-476<br \/><strong>Date:<\/strong> May 19, 2026<\/p>\n\n<p>On May 15, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0- versions prior to 148.0.3967.70<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-15-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-476","alert_type":396,"serial_number":"AV26-476","subject":"other","moderation_state":"published","external_url":null},{"nid":7710,"title":"HPE security advisory (AV26-477)","uuid":"39724211-3e3c-4de0-af44-92fdb9c13d0b","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T16:15:28Z","date_created":"2026-05-19T15:58:53Z","summary":null,"body":["<article data-history-node-id=\"7710\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-477\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-477<br \/><strong>Date:<\/strong> May 19, 2026<\/p>\n\n<p>HPE security advisory (AV26-477) On May 18, 2026, HPE published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>HPE Unified OSS Console (UOC)\u00a0\u2013 version 3.1.20 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05056en_us&amp;docLocale=en_US\">HPESBNW05056 rev.1\u00a0- HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-477","alert_type":396,"serial_number":"AV26-475","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7711,"title":"Mozilla security advisory (AV26-478)","uuid":"6faff271-223f-4cd5-bf82-37a779c2ef62","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T19:15:25Z","date_created":"2026-05-19T19:04:13Z","summary":null,"body":["<article data-history-node-id=\"7711\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-478\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-478<br \/><strong>Date: <\/strong>May 19, 2026<\/p>\n\n<p>On May 19, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Firefox<\/span>\u00a0- versions prior to 151<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Firefox<\/span> ESR\u00a0- versions prior to 115.36<\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Firefox<\/span> ESR\u00a0- versions prior to 140.11<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-48\/\">Mozilla Foundation Security Advisory 2026-46<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-47\/\">Mozilla Foundation Security Advisory 2026-47<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-48\/\">Mozilla Foundation Security Advisory 2026-48<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-478","alert_type":396,"serial_number":"AV26-478","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7712,"title":"IBM security advisory (AV26-479)","uuid":"264803ed-89d1-4d71-997e-a9d9b1464fbf","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T19:34:39Z","date_created":"2026-05-19T19:20:07Z","summary":null,"body":["<article data-history-node-id=\"7712\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-479\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-479<br \/><strong>Date: <\/strong>May 19, 2026<\/p>\n\n<p>Between May 11 and 17, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Robotic Process Automation for Cloud Pak\u00a0- versions 23.0.0 to 23.0.20.5<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak\u00a0- versions 30.0.0 to 30.0.1<\/li>\n\t<li>IBM Operator for Apache Flink\u00a0- versions 1.0.0 to 1.5.1<\/li>\n\t<li>IBM App Connect Enterprise\u00a0- versions 13.0.1.0 to 13.0.7.1<\/li>\n\t<li>IBM App Connect Enterprise\u00a0- versions 12.0.1.0 to 12.0.12.25<\/li>\n\t<li>ICP Discovery\u00a0- versions 5.0.0 to 5.3.1<\/li>\n\t<li>IBM Operational Decision Manager\u00a0- multiple versions<\/li>\n\t<li>IBM Cloudera Data Platform Private Could Base\u00a0- versions 7.1.9, 7.3.1 and 7.3.2<\/li>\n\t<li>IBM Data Virtualization on Cloud Pak for Data\u00a0- multiple versions<\/li>\n\t<li>IBM Fusion\u00a0- versions 2.9.0 to 2.12.1<\/li>\n\t<li>IBM Fusion HCI\u00a0- versions 2.10.0 to 2.12.1<\/li>\n\t<li>Content-Aware Storage\u00a0- versions 1.1.2 to 1.1.3<\/li>\n\t<li>IBM Engineering AI Hub\u00a0- versions 1.0.0 and 1.1.0<\/li>\n\t<li>IBM Integration Bus for z\/OS\u00a0- versions 10.1.0.0 to 10.1.0.7<\/li>\n\t<li>IBM MQ Operator\u00a0- multiple versions and models<\/li>\n\t<li>IBM supplied MQ Advanced container images\u00a0- multiple versions and models<\/li>\n\t<li>IBM Open SDK for Rust on AIX\u00a0- versions 1.90.0.0, 1.90.0.1, 1.92.0.0 and 1.92.0.1<\/li>\n\t<li>IBM Watson Knowledge Catalog on prem\u00a0- versions 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1.0, 5.1.1, 5.1.2 and 5.1.3<\/li>\n\t<li>IBM Watson Query on Cloud Pak for Data\u00a0- version 2.2<\/li>\n\t<li>IBM Big SQL on Cloud Pak for data\u00a0- multiple versions<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (CP4I)\u00a0- multiple versions<\/li>\n\t<li>Automation Assets in IBM Cloud Pak for Integration (CP4I)\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-479","alert_type":396,"serial_number":"AV26-479","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7713,"title":"Dell security advisory (AV26-480)","uuid":"643a7866-b752-4d49-a383-801414eeb526","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T19:48:07Z","date_created":"2026-05-19T19:38:23Z","summary":null,"body":["<article data-history-node-id=\"7713\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-480\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-480<br \/><strong>Date:<\/strong> May 19, 2026<\/p>\n\n<p>Between May 11 and 17, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Enterprise Sonic Distribution\u00a0- versions prior to 4.5.3<\/li>\n\t<li>Dell Live Optics Collector)\u00a0- versions prior to 27.1.10.1<\/li>\n\t<li>Intel 800 Series Ethernet Adapters\u00a0- versions prior to 30.5.0.13<\/li>\n\t<li>Dell PowerEdge with AMD Graphics\u00a0- multiple models and versions<\/li>\n\t<li>PowerScale InsightIQ\u00a0- versions 5.0.0 to 6.2.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-480","alert_type":396,"serial_number":"AV26-480","subject":"dell","moderation_state":"published","external_url":null},{"nid":7714,"title":"Red Hat security advisory (AV26-481)","uuid":"c701a9c0-7f85-4a10-8f55-c6cddc39407f","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T20:05:57Z","date_created":"2026-05-19T19:52:48Z","summary":null,"body":["<article data-history-node-id=\"7714\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-481\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-481<br \/><strong>Date: <\/strong>May 19, 2026<\/p>\n\n<p>Between May 11 and 17, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-481","alert_type":396,"serial_number":"AV26-481","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7715,"title":"Ubuntu security advisory (AV26-482)","uuid":"99c08910-3b66-4635-be9a-f6ecdb7e9863","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T20:17:38Z","date_created":"2026-05-19T20:09:32Z","summary":null,"body":["<article data-history-node-id=\"7715\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-482\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-482<br \/><strong>Date:<\/strong> May 19, 2026<\/p>\n\n<p>Between May 11 and 17, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8257-1\">USN-8257-1: Linux kernel (Raspberry Pi) vulnerabilities (25.01)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8255-1\">USN-8255-1: Linux kernel vulnerabilities (22.04, 20.04)<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8258-1\">USN-8258-1: Linux kernel (Azure) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-482","alert_type":396,"serial_number":"AV26-482","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7716,"title":"Atlassian security advisory (AV26-483)","uuid":"c41fd6a5-97f8-4b60-a3a9-5b64302acef1","banner":null,"lang":"en","date_modified":"2026-05-19","date_modified_ts":"2026-05-19T20:31:52Z","date_created":"2026-05-19T20:26:17Z","summary":null,"body":["<article data-history-node-id=\"7716\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-483\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-483<br \/><strong>Date:<\/strong> May 19, 2026<\/p>\n\n<p>On May 19, 2026, Atlassian published a security advisory to address vulnerabilities, including some critical ones, in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Fisheye\/Crucible\u00a0- versions 4.9.0 to 4.9.9<\/li>\n\t<li>Jira Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-may-19-2026-1786839142.html\">Security Bulletin\u00a0- May 19 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-483","alert_type":396,"serial_number":"AV26-483","subject":"other","moderation_state":"published","external_url":null},{"nid":7717,"title":"FreePBX security advisory (AV26-484)","uuid":"b4a3d5cf-e39f-432a-9eba-ef9d54cb7b49","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T15:10:43Z","date_created":"2026-05-20T14:59:27Z","summary":null,"body":["<article data-history-node-id=\"7717\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-484\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-484<br \/><strong>Date: <\/strong>May\u00a020, 2026<\/p>\n\n<p>On May\u00a019, 2026, FreePBX published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FreePBX Security-Reporting cdr (FreePBX 16)\u00a0\u2013 versions 16.0.50 and prior<\/li>\n\t<li>FreePBX Security-Reporting cdr (FreePBX 17)\u00a0\u2013 versions 17.0.11 and prior<\/li>\n\t<li>FreePBX Security-Reporting dashboard (FreePBX 16)\u00a0\u2013 versions 16.0.22 and prior<\/li>\n\t<li>FreePBX Security-Reporting dashboard (FreePBX 17)\u00a0\u2013 versions 17.0.5 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-p9fq-fmpw-2h9x\">Authenticated SQL Injection via ORDER BY in CDR Reports<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-hw7v-v2jp-wc4v\">Authenticated Local File Inclusion in Dashboard Module<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories?state=published\">FreePBX Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-484","alert_type":396,"serial_number":"AV26-484","subject":"other","moderation_state":"published","external_url":null},{"nid":7721,"title":"cPanel security advisory (AV26-488)","uuid":"8bbdb2cf-225f-40f2-9d81-20172907739a","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T15:35:04Z","date_created":"2026-05-20T14:59:28Z","summary":null,"body":["<article data-history-node-id=\"7721\" about=\"\/en\/alerts-advisories\/cpanel-security-advisory-av26-488\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-488<br \/><strong>Date:<\/strong> May\u00a020, 2026<\/p>\n\n<p>On May\u00a019, 2026, cPanel published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>cPanel &amp; WebHost Manager (WHM) software\u00a0\u2013 version 11.86.0.45, 11.94.0.32, 11.102.0.43, 11.110.0.120 (cl6110), 11.110.0.121, 11.118.0.68, 11.124.0.41, 11.126.0.62, 11.130.0.26, 11.132.0.35, 11.134.0.29, 11.136.0.13 and WP Squared 11.136.1.16 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40555378241943-Security-SEC-73728-cPanel-WHM-WP2-Security-Update-May-19-2026\">Security: SEC-73728 cPanel &amp; WHM \/ WP2 Security Update\u00a0- May\u00a019, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40555594160023-Security-SEC-73755-cPanel-WHM-WP2-Security-Update-May-19-2026\">Security: SEC-73755 cPanel &amp; WHM \/ WP2 Security Update\u00a0- May\u00a019, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360008753193-Support-Topics\">cPanel Support Topics<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cpanel-security-advisory-av26-488","alert_type":396,"serial_number":"AV26-488","subject":"other","moderation_state":"published","external_url":null},{"nid":7720,"title":"HPE security advisory (AV26-487)","uuid":"841f5f40-0c32-4f7b-9b52-ca9a40974d54","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T15:29:08Z","date_created":"2026-05-20T14:59:28Z","summary":null,"body":["<article data-history-node-id=\"7720\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-487\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-487<br \/><strong>Date: <\/strong>May\u00a020, 2026<\/p>\n\n<p>On May\u00a019, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Aruba Networking Management Software (Airwave)\u00a0\u2013 version 8.3.0.6 and prior<\/li>\n\t<li>HPE Aruba Networking AOS-CX\u00a0\u2013 multiple versions<\/li>\n\t<li>HPE Aruba Networking EdgeConnect Orchestrator\u00a0\u2013 all versions<\/li>\n\t<li>HPE Aruba Networking Analytics and Location Engine (ALE)\u00a0\u2013 all versions<\/li>\n\t<li>HPE Aruba Networking Meridian Asset Tracking\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05059en_us&amp;docLocale=en_US\">HPESBNW05059 rev.1\u00a0- Status of Copy Fail Vulnerability on HPE Aruba Networking Products (CVE-2026-31431)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-487","alert_type":396,"serial_number":"AV26-487","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7719,"title":"Google Chrome security advisory (AV26-486)","uuid":"388b111f-4e47-4deb-9c5a-269630708d4d","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T15:24:06Z","date_created":"2026-05-20T14:59:28Z","summary":null,"body":["<article data-history-node-id=\"7719\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-486\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-486<br \/><strong>Date:<\/strong> May\u00a020, 2026<\/p>\n\n<p>On May\u00a019, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 148.0.7778.178\/179 (Windows\/Mac) and 148.0.7778.178 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/05\/stable-channel-update-for-desktop_0841193308.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-486","alert_type":396,"serial_number":"AV26-486","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7718,"title":"F5 security advisory (AV26-485)","uuid":"817a74f8-b2c8-4099-a167-888a1c1e2e12","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T15:19:32Z","date_created":"2026-05-20T14:59:28Z","summary":null,"body":["<article data-history-node-id=\"7718\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-485\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-485<br \/><strong>Date: <\/strong>May\u00a020, 2026<\/p>\n\n<p>On May\u00a019, 2026, F5 published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>NGINX JavaScript (njs)\u00a0\u2013 versions 0.9.4 to 0.9.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161307\">K000161307: NGINX ngx_http_js_module vulnerability CVE-2026-8711<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/new-updated-articles#f-f5_document_type=Security%20Advisory\">MyF5<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-485","alert_type":396,"serial_number":"AV26-485","subject":"f5","moderation_state":"published","external_url":null},{"nid":7722,"title":"Microsoft security advisory (AV26-489)","uuid":"3f827af5-ffce-4124-b513-f0eae20e778d","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T17:16:09Z","date_created":"2026-05-20T17:09:34Z","summary":null,"body":["<article data-history-node-id=\"7722\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-av26-489\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-489<br \/><strong>Date:<\/strong> May\u00a020, 2026<\/p>\n\n<p>On May\u00a018 and 19, 2026, Microsoft published security advisories to address vulnerabilities, including some critical ones, in the following products:<\/p>\n\n<ul><li>Microsoft Azure Local<\/li>\n\t<li>Microsoft Azure Resource Manager<\/li>\n\t<li>Microsoft Azure Portal Windows Admin Center<\/li>\n\t<li>Microsoft Bitlocker<\/li>\n\t<li>Microsoft Malware Protection Engine\u00a0\u2013 versions prior to 1.1.26040.8<\/li>\n\t<li>Microsoft Defender\u00a0\u2013 versions prior to 4.18.26040.7<\/li>\n<\/ul><p>On May\u00a020, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-41091 and CVE-2026-45498 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-42822\">Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45584\">Microsoft Defender Remote Code Execution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-41091\">Microsoft Defender Elevation of Privilege Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41091\">CISA KEV: CVE-2026-41091<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45498\">CISA KEV: CVE-2026-45498<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-av26-489","alert_type":396,"serial_number":"AV26-489","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7723,"title":"ISC BIND security advisory (AV26-490)","uuid":"6725fdf9-b6f8-472f-b4fc-914db3dfdeaa","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T17:23:00Z","date_created":"2026-05-20T17:09:34Z","summary":null,"body":["<article data-history-node-id=\"7723\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-490\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-490<br \/><strong>Date: <\/strong>May\u00a020, 2026<\/p>\n\n<p>On May\u00a020, 2026, ISC published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ISC BIND 9\u00a0\u2013 versions 9.0.0 to 9.16.50<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.18.0 to 9.18.48<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.20.0 to 9.20.22<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.21.0 to 9.21.21<\/li>\n\t<li>BIND Supported Preview Edition\u00a0\u2013 versions 9.9.3-S1 to 9.16.50-S1<\/li>\n\t<li>BIND Supported Preview Edition\u00a0\u2013 versions 9.18.11-S1 to 9.18.48-S1<\/li>\n\t<li>BIND Supported Preview Edition\u00a0\u2013 versions 9.20.9-S1 to 9.20.22-S1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-3039\">CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-5947\">CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-5946\">CVE-2026-5946: Invalid handling of CLASS != IN<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-3593\">CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation<\/a><\/li>\n\t<li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-490","alert_type":396,"serial_number":"AV26-490","subject":"other","moderation_state":"published","external_url":null},{"nid":7724,"title":"Cisco security advisory (AV26-491)","uuid":"76507fcc-19e6-448b-b12d-aa5d701923a6","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T19:06:36Z","date_created":"2026-05-20T19:03:23Z","summary":null,"body":["<article data-history-node-id=\"7724\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-491\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-491<br \/><strong>Date:<\/strong> May\u00a020, 2026<\/p>\n\n<p>On May\u00a020, 2026, Cisco published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Cisco Secure Workload\u00a0\u2013 version 3.9 and prior<\/li>\n\t<li>Cisco Secure Workload\u00a0\u2013 versions prior to 3.10.8.3<\/li>\n\t<li>Cisco Secure Workload\u00a0\u2013 versions prior to 4.0.3.17<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-csw-pnbsa-g8WEnuy\">Cisco Secure Workload Unauthorized API Access Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-491","alert_type":396,"serial_number":"AV26-491","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7725,"title":"Drupal security advisory (AV26-492) - Update 2","uuid":"aef67cb1-c660-401a-970c-dde11c8f54e3","banner":null,"lang":"en","date_modified":"2026-05-22","date_modified_ts":"2026-05-22T19:39:54Z","date_created":"2026-05-20T19:03:23Z","summary":null,"body":["<article data-history-node-id=\"7725\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-492\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-492<br \/><strong>Date:<\/strong> May\u00a020, 2026<br \/><strong>Updated:<\/strong> May 22, 2026<\/p>\n\n<p>On May\u00a020, 2026, Drupal published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Drupal Core\u00a0\u2013 multiple versions<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Drupal has indicated that exploit attempts for CVE-2026-9082 are now being detected in the wild.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On May 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-9082 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-core-2026-004\">Drupal core\u00a0- Highly critical\u00a0- SQL injection\u00a0- SA-CORE-2026-004<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n  <li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9082\">CISA KEV: CVE-2026-9082<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-492","alert_type":396,"serial_number":"AV26-492","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7726,"title":"Splunk security advisory (AV26-493)","uuid":"a1aaf37e-b37c-4b75-8705-47942816524f","banner":null,"lang":"en","date_modified":"2026-05-20","date_modified_ts":"2026-05-20T19:24:03Z","date_created":"2026-05-20T19:19:48Z","summary":null,"body":["<article data-history-node-id=\"7726\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-493\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-493<br \/><strong>Date: <\/strong>May\u00a020, 2026<\/p>\n\n<p>On May\u00a020, 2026, Splunk published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>Splunk User Behavior Analytics\u00a0\u2013 versions prior to 5.4.5<\/li>\n\t<li>Splunk AppDynamics Machine Agent\u00a0\u2013 versions prior to 26.4.0<\/li>\n\t<li>Splunk AppDynamics Java Agent\u00a0\u2013 versions prior to 26.4.0<\/li>\n\t<li>Splunk AppDynamics Private Synthetic Agent\u00a0\u2013 versions prior to 26.4.0<\/li>\n\t<li>Splunk AppDynamics Python Agent\u00a0\u2013 versions prior to 26.4.1<\/li>\n\t<li>Splunk AppDynamics Cluster Agent\u00a0\u2013 versions prior to 26.4.0<\/li>\n\t<li>Splunk AppDynamics Database Agent\u00a0\u2013 versions prior to 26.4.0<\/li>\n\t<li>Splunk AppDynamics Analytics Agent\u00a0\u2013 versions prior to 26.4.0<\/li>\n\t<li>Splunk AppDynamics Apache Web Server Agent\u00a0\u2013 versions prior to 25.11.1<\/li>\n\t<li>Splunk Universal Forwarder\u00a0\u2013 versions 9.4.0 to 9.4.10<\/li>\n\t<li>Splunk Enterprise\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Splunk AI Toolkit\u00a0\u2013 versions prior to 5.7.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-493","alert_type":396,"serial_number":"AV26-493","subject":"other","moderation_state":"published","external_url":null},{"nid":7727,"title":"Trend Micro security advisory (AV26-494) \u2013 Update 1","uuid":"f489091c-eaed-4f6f-97ec-731b07b31bf6","banner":null,"lang":"en","date_modified":"2026-05-21","date_modified_ts":"2026-05-21T19:40:00Z","date_created":"2026-05-21T13:47:21Z","summary":null,"body":["<article data-history-node-id=\"7727\" about=\"\/en\/alerts-advisories\/trend-micro-security-advisory-av26-494\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-494<br \/><strong>Date: <\/strong>May 21, 2026<\/p>\n\n<p>On May 21, 2026, Trend Micro published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apex One (on-premise)\u00a0\u2013 server\/agent builds prior to 2019 (on-prem) build 17079<\/li>\n\t<li>Apex One as a service\u00a0\u2013 SaaS<\/li>\n\t<li>Trend Vision One Endpoint\u00a0- SEP\u00a0\u2013 agent builds prior to 14.0.20731<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>On May\u00a021, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-34926 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/success.trendmicro.com\/en-US\/solution\/KA-0023430\">ITW SECURITY BULLETIN: Apex One and Vision One\u00a0\u2013 Standard Endpoint Protection (SEP) May 2026 Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/success.trendmicro.com\/en-US\/vulnerability-response\/\">Trend Micro Business Success Vulnerability Response<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926\">CISA KEV: CVE-2026-34926<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trend-micro-security-advisory-av26-494","alert_type":396,"serial_number":"AV26-494","subject":"other","moderation_state":"published","external_url":null},{"nid":7728,"title":"FreeBSD security advisory (AV26-495)","uuid":"b04b3374-3063-4e0d-8a84-06e74b74ffc4","banner":null,"lang":"en","date_modified":"2026-05-21","date_modified_ts":"2026-05-21T13:56:55Z","date_created":"2026-05-21T13:52:09Z","summary":null,"body":["<article data-history-node-id=\"7728\" about=\"\/en\/alerts-advisories\/freebsd-security-advisory-av26-495\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-495<br \/><strong>Date: <\/strong>May 21, 2026<\/p>\n\n<p>On May 20, 2026, FreeBSD published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>FreeBSD\u00a0\u2013 all supported versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/\">FreeBSD Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freebsd-security-advisory-av26-495","alert_type":396,"serial_number":"AV26-495","subject":"other","moderation_state":"published","external_url":null},{"nid":7729,"title":"ConnectWise security advisory (AV26-496)","uuid":"81047f29-29b0-414e-aaf3-78677d1f3738","banner":null,"lang":"en","date_modified":"2026-05-21","date_modified_ts":"2026-05-21T17:42:51Z","date_created":"2026-05-21T17:37:36Z","summary":null,"body":["<article data-history-node-id=\"7729\" about=\"\/en\/alerts-advisories\/connectwise-security-advisory-av26-496\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-496<br \/><strong>Date: <\/strong>May 21, 2026<\/p>\n\n<p>On May 21, 2026, ConnectWise published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>ConnectWise Automate\u00a0\u2013 versions prior to 2026.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/2026-05-21-connectwise-automate-bulletin\">ConnectWise Automat 2026.5 Security Update<\/a><\/li>\n\t<li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\">ConnectWise\u00a0- Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/connectwise-security-advisory-av26-496","alert_type":396,"serial_number":"AV26-496","subject":"other","moderation_state":"published","external_url":null},{"nid":7730,"title":"Microsoft Edge security advisory (AV26-497)","uuid":"becdfdb2-57a4-4abc-acec-33d8a3ee33e4","banner":null,"lang":"en","date_modified":"2026-05-22","date_modified_ts":"2026-05-22T15:31:23Z","date_created":"2026-05-22T15:27:53Z","summary":null,"body":["<article data-history-node-id=\"7730\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-497\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-497<br \/><strong>Date:<\/strong> May 22, 2026<\/p>\n\n<p>On May 21, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 148.0.3967.83<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-21st-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-497","alert_type":396,"serial_number":"AV26-497","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7731,"title":"Ubiquiti security advisory (AV26-498) \u2013 Update 1","uuid":"14edbd16-ada9-4659-bdee-6d1b109c59ab","banner":null,"lang":"en","date_modified":"2026-06-23","date_modified_ts":"2026-06-23T20:14:02Z","date_created":"2026-05-22T15:33:27Z","summary":null,"body":["<article data-history-node-id=\"7731\" about=\"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-498\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-498<br \/><strong>Date:<\/strong> May 22, 2026<br \/><strong>Updated:<\/strong> June 23, 2026<\/p>\n\n<p>On May 21, 2026, Ubiquiti published a security advisory to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>Express\u00a0- version 4.0.13 and prior<\/li>\n\t<li>UCG-Industrial\u00a0- version 5.0.13 and prior<\/li>\n\t<li>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, Express 7, UNVR, UNVR-Pro, UNVR-Instant, ENVR, UCG-Ultra, UCG-Max and UCG-Fiber\u00a0- version 5.0.16 and prior<\/li>\n\t<li>UDM-Beast, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8\u00a0- version 5.1.8 and prior<\/li>\n\t<li>UDR-5G, ENVR-Core, UCKP, UCK and UCK-Enterprise\u00a0- version 5.0.17 and prior<\/li>\n\t<li>UNVR-G2 and UNVR-G2-Pro\u00a0- version 5.1.11 and prior<\/li>\n\t<li>UniFi OS Server\u00a0- version 5.0.6 and prior<\/li>\n<\/ul><p><strong>Update 1<\/strong><br \/>\nOn June 23, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.ui.com\/releases\/Security-Advisory-Bulletin-064-064\/84811c09-4cf4-42ab-bd61-cc994445963b\">Ubiquiti UniFi\u00a0- Security Advisory Bulletin 064<\/a><\/li>\n\t<li><a href=\"https:\/\/community.ui.com\/releases\">Ubiquiti UniFi Security Releases<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908\">CISA KEV: CVE-2026-34908<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909\">CISA KEV: CVE-2026-34909<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910\">CISA KEV: CVE-2026-34910<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-498","alert_type":396,"serial_number":"AV26-498","subject":"other","moderation_state":"published","external_url":null},{"nid":7732,"title":"cPanel security advisory (AV26-499)","uuid":"1005f02a-e392-493a-bda2-d4aa5dc20833","banner":null,"lang":"en","date_modified":"2026-05-22","date_modified_ts":"2026-05-22T15:44:53Z","date_created":"2026-05-22T15:40:09Z","summary":null,"body":["<article data-history-node-id=\"7732\" about=\"\/en\/alerts-advisories\/cpanel-security-advisory-av26-499\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-499<br \/><strong>Date:<\/strong> May 22, 2026<\/p>\n\n<p>On May 21, 2026, cPanel published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>cPanel &amp; WebHost Manager (WHM) software \u2013 version 11.126.0.63 and later, version 11.134.0.30 and later, version 11.136.0.14 and later, WP Squared 11.138.1.1 and later<\/li>\n\t<li>EasyApache4 \u2013 versions prior to v25.62<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40646746647703-Security-CVE-2026-33278-cpanel-unbound-1-25-1-Security-Release-May-21-2026\">Security: CVE-2026-33278 cpanel-unbound 1.25.1 Security Release - May 21, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40646970590999-Security-EasyApache4-v25-62-Security-Release-May-21-2026\">Security: EasyApache4 v25.62 Security Release - May 21, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360007088193-Security\">cPanel Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cpanel-security-advisory-av26-499","alert_type":396,"serial_number":"AV26-499","subject":"other","moderation_state":"published","external_url":null},{"nid":7733,"title":"HPE security advisory (AV26-500)","uuid":"491b6fef-47ec-402b-b2c4-bff1ba94be2d","banner":null,"lang":"en","date_modified":"2026-05-22","date_modified_ts":"2026-05-22T15:55:49Z","date_created":"2026-05-22T15:52:54Z","summary":null,"body":["<article data-history-node-id=\"7733\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-500\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-500<br \/><strong>Date: <\/strong>May 22, 2026<\/p>\n\n<p>On May 22, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Universal SLA Management \u2013 version 4.6 and prior.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05058en_us&amp;docLocale=en_US#hpesbnw05058-rev-1-hpe-telco-universal-sla-managem-0\">HPESBNW05058 rev.1 - HPE Telco Universal SLA Management, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-500","alert_type":396,"serial_number":"AV26-500","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7734,"title":"F5 security advisory (AV26-501)","uuid":"43333577-f0db-4a80-9110-b4c3e49a620b","banner":null,"lang":"en","date_modified":"2026-05-22","date_modified_ts":"2026-05-22T16:02:13Z","date_created":"2026-05-22T15:57:22Z","summary":null,"body":["<article data-history-node-id=\"7734\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-501\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-501<br \/><strong>Date: <\/strong>May 22, 2026<\/p>\n\n<p>On May 22, 2026, F5 published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>NGINX Plus \u2013 multiple versions<\/li>\n\t<li>NGINX Open Source \u2013 multiple versions<\/li>\n\t<li>NGINX Instance Manager \u2013 versions 2.17.0 to 2.22.0<\/li>\n\t<li>F5 WAF for NGINX \u2013 versions 5.9.0 to 5.13.0<\/li>\n\t<li>NGINX App Protect WAF \u2013 multiple versions<\/li>\n\t<li>F5 DoS for NGINX \u2013 version 4.9.0<\/li>\n\t<li>NGINX App Protect DoS \u2013 versions 4.3.0 to 4.7.0<\/li>\n\t<li>NGINX Gateway Fabric \u2013 multiple versions<\/li>\n\t<li>NGINX Ingress Controller \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161377\">K000161377: NGINX ngx_http_rewrite_module vulnerability CVE-2026-9256<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/new-updated-articles#f-f5_document_type=Security%20Advisory\">MyF5<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-501","alert_type":396,"serial_number":"AV26-501","subject":"f5","moderation_state":"published","external_url":null},{"nid":7736,"title":"IBM security advisory (AV26-502)","uuid":"cea23659-51f6-4c29-83ed-308336668718","banner":null,"lang":"en","date_modified":"2026-05-25","date_modified_ts":"2026-05-25T13:49:45Z","date_created":"2026-05-25T13:37:14Z","summary":null,"body":["<article data-history-node-id=\"7736\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-502-0\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-502<br \/><strong>Date: <\/strong>May 25, 2026<\/p>\n\n<p>Between May 18 and 24, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>API Connect \u2013 versions V10.0.8.0 to 10.0.8.8<\/li>\n\t<li>Analyst Workflow \u2013 versions 2.0.0 to 3.0.0<\/li>\n\t<li>Data Cataloging \u2013 versions 2.1.8 to 2.5.1<\/li>\n\t<li>DevOps Test Performance \u2013 versions 11.0 to 11.0.6<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands \u2013 multiple versions<\/li>\n\t<li>IBM App Connect Enterprise \u2013 versions 12.0.1.0 to 12.0.12.25<\/li>\n\t<li>IBM App Connect Enterprise \u2013 versions 13.0.1.0 to 13.0.7.1<\/li>\n\t<li>IBM App Connect Operator \u2013 multiple versions<\/li>\n\t<li>IBM App Connect for Manufacturing \u2013 versions 13.0.0.0 to 13.0.1.0<\/li>\n\t<li>IBM Aspera High-Speed Transfer Endpoint \u2013 versions 3.7.4 to 4.4.7 Fix Pack 1<\/li>\n\t<li>IBM Aspera High-Speed Transfer Server \u2013 versions 3.7.4 to 4.4.7 Fix Pack 1<\/li>\n\t<li>IBM Cognos Analytics Mobile \u2013 versions 1.1.0 to 1.1.25<\/li>\n\t<li>IBM Data Studio client \u2013 version 4.2.2<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM DevOps Code ClearCase \u2013 version 11.0<\/li>\n\t<li>IBM Fusion HCI \u2013 versions 2.10.0 to 2.12.1<\/li>\n\t<li>IBM Fusion \u2013 versions 2.9.0 to 2.12.1<\/li>\n\t<li>IBM Guardium Data Protection \u2013 versions 12.0, 12.1 and 12.2<\/li>\n\t<li>IBM Library Support for Spring \u2013 versions 3.2 to 3.2.25<\/li>\n\t<li>IBM Library Support for Spring \u2013 version 3.4 to 3.4.16<\/li>\n\t<li>IBM MQ Agent \u2013 version v1.0.0<\/li>\n\t<li>IBM Rational ClearCase \u2013 version 10.0.0<\/li>\n\t<li>IBM Rational ClearCase \u2013 version 9.1<\/li>\n\t<li>IBM SPSS Analytic Server \u2013 multiple versions<\/li>\n\t<li>IBM Security Verify Access OIDC Provider \u2013 versions 22.09 to 26.03<\/li>\n\t<li>IBM Sterling Transformation Extender \u2013 versions 11.0.1.1 and 11.0.2.0<\/li>\n\t<li>IBM Storage Defender - Data Protect \u2013 versions 2.0.0 to 2.1.3<\/li>\n\t<li>IBM Storage Defender - Resiliency Service \u2013 versions 2.0.0 to 2.1.3<\/li>\n\t<li>IBM Watson Speech Services Cartridge \u2013 versions 4.0.0 to 5.3.1<\/li>\n\t<li>IBM voice-gateway\/media-relay \u2013 version 1.0.8.31<\/li>\n\t<li>IBM voice-gateway\/sip-orchestrator \u2013 version 1.0.8.25<\/li>\n\t<li>IBM voice-gateway\/sms-gateway \u2013 version 1.0.8.19<\/li>\n\t<li>IBM voice-gateway\/stt-adapter \u2013 version 1.0.8.20<\/li>\n\t<li>IBM voice-gateway\/tts-adapter \u2013 version 1.0.8.20<\/li>\n\t<li>IBM watsonx Code Assistant On Prem \u2013 multiple versions<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data \u2013 versions 4.8.4 to 4.8.5<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data \u2013 versions 5.0.0 to 5.3.1<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition \u2013 versions 1.4.0 to 2.9.0<\/li>\n\t<li>Langflow OSS \u2013 versions 1.0.0 to 1.9.1<\/li>\n\t<li>Rational Business Developer (RBD) \u2013 versions 9.6 to 9.6.1.1<\/li>\n\t<li>Rational Business Developer (RBD) \u2013 versions 9.7 to 9.7.1<\/li>\n\t<li>Rational Performance Tester \u2013 multiple versions<\/li>\n\t<li>SPSS Collaboration and Deployment Services \u2013 multiple versions<\/li>\n\t<li>z\/Transaction Processing Facility \u2013 version 1.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><u> <\/u><u> <\/u><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-502-0","alert_type":396,"serial_number":"AV26-502","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7737,"title":"Roundcube security advisory (AV26-503) \u2013 Update 1","uuid":"69a1ccca-241d-426c-905e-6f17a2d1381f","banner":null,"lang":"en","date_modified":"2026-09-21","date_modified_ts":"2026-09-21T20:20:59Z","date_created":"2026-05-25T13:51:03Z","summary":null,"body":["<article data-history-node-id=\"7737\" about=\"\/en\/alerts-advisories\/roundcube-security-advisory-av26-503\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-503<br \/><strong>Date:<\/strong> May 25, 2026<br \/><strong>Updated:<\/strong> September 21, 2026<\/p>\n\n<p>On May 24, 2026, Roundcube published security advisories to address vulnerabilities in the following product:\u00a0<\/p>\n\n<ul><li>Roundcube Webmail \u2013 versions prior to 1.6.16<\/li>\n\t<li>Roundcube Webmail \u2013 versions prior to 1.7.1<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p class=\"mrgn-bttm-lg\">Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.6.16\">Roundcube Webmail 1.6.16<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.7.1\">Roundcube Webmail 1.71<\/a><\/li>\n\t<li><a href=\"https:\/\/roundcube.net\/\">Roundcube Open Source Webmail Software<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/roundcube-security-advisory-av26-503","alert_type":396,"serial_number":"AV26-503","subject":"other","moderation_state":"published","external_url":null},{"nid":7738,"title":"Dell security advisory (AV26-504)","uuid":"602eec82-48e4-4db9-803c-87c1648d1702","banner":null,"lang":"en","date_modified":"2026-05-25","date_modified_ts":"2026-05-25T14:04:42Z","date_created":"2026-05-25T14:03:26Z","summary":null,"body":["<article data-history-node-id=\"7738\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-504\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-504<br \/><strong>Date:<\/strong> May 25, 2026<strong>\u00a0<\/strong><\/p>\n\n<p>Between May 18 and 24, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Networking OS10 \u2013 versions prior to 10.5.6.13<\/li>\n\t<li>SmartFabric Storage Software \u2013 versions prior to 1.4.5<\/li>\n\t<li>Dell Container Storage Modules \u2013 versions 1.6.0 to 1.16.3<\/li>\n\t<li>Dell Container Storage Modules \u2013 versions 1.11.0 to 1.16.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000466930\/dsa-2026-161-security-update-for-dell-networking-os10-vulnerabilities\">DSA-2026-161: Security Update for Dell Networking OS10 Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000466942\/dsa-2026-235-security-update-for-dell-networking-smartfabric-storage-software-vulnerabilities\">DSA-2026-235: Security Update for Dell Networking SmartFabric Storage Software Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000467149\/dsa-2026-234-security-update-for-dell-container-storage-modules-hard-coded-credentials-vulnerability\">DSA-2026-234: Security Update for Dell Container Storage Modules Hard-coded Credentials Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-504","alert_type":396,"serial_number":"AV26-504","subject":"dell","moderation_state":"published","external_url":null},{"nid":7739,"title":"Ubuntu security advisory (AV26-505)","uuid":"559ad912-5c97-4a17-80a9-ef31617acc8e","banner":null,"lang":"en","date_modified":"2026-05-25","date_modified_ts":"2026-05-25T14:10:56Z","date_created":"2026-05-25T14:09:21Z","summary":null,"body":["<article data-history-node-id=\"7739\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-505\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-505<br \/><strong>Date:<\/strong> May 25, 2026<\/p>\n\n<p>Between May 18 and 24, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-505","alert_type":396,"serial_number":"AV26-505","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7740,"title":"[Control systems] CISA ICS security advisories (AV26\u2013506)","uuid":"be97fa25-da5e-4446-8c3e-ea668abe7fc1","banner":null,"lang":"en","date_modified":"2026-05-25","date_modified_ts":"2026-05-25T14:16:16Z","date_created":"2026-05-25T14:12:53Z","summary":null,"body":["<article data-history-node-id=\"7740\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-506\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013506<br \/><strong>Date: <\/strong>May 25, 2026<\/p>\n\n<p><strong>[Control systems] CISA ICS security advisories (AV26\u2013506)<\/strong><\/p>\n\n<p>Between May 18 and 24, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB B&amp;R Automation Runtime \u2013 versions prior to 6.4<\/li>\n\t<li>ABB B&amp;R Automation Studio \u2013 versions prior to 6.5<\/li>\n\t<li>ABB B&amp;R PCs \u2013 multiple versions and models<\/li>\n\t<li>ABB CoreSense HM \u2013 version 2.3.1 and prior<\/li>\n\t<li>ABB CoreSense M10 \u2013 version 1.4.1.12 and prior<\/li>\n\t<li>ABB Terra AC Wallbox (JP) \u2013 versions 1.8.33 and prior<\/li>\n\t<li>Abb B&amp;R Automation Studio \u2013 versions prior to 6.5<\/li>\n\t<li>Hitachi Energy GMS600 \u2013 versions 1.3.0 to 1.3.1<\/li>\n\t<li>Kieback &amp; Peter DDC Building Controllers \u2013 multiple versions and models<\/li>\n\t<li>ScadaBR \u2013 version 1.2.0<\/li>\n\t<li>Siemens RUGGEDCOM APE1808 \u2013 all versions<\/li>\n\t<li>ZKTeco CCTV Cameras \u2013 firmware version prior to V5.0.1.2.20260421<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-506","alert_type":398,"serial_number":"AV26-506","subject":"ics","moderation_state":"published","external_url":null},{"nid":7741,"title":"Red Hat security advisory (AV26-507)","uuid":"16fc3d2b-6dd3-44f5-9da4-d243bbf8ba5d","banner":null,"lang":"en","date_modified":"2026-05-25","date_modified_ts":"2026-05-25T14:26:13Z","date_created":"2026-05-25T14:24:19Z","summary":null,"body":["<article data-history-node-id=\"7741\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-507\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-507<br \/><strong>Date: <\/strong>May 25, 2026<\/p>\n\n<p>Between May 18 and 24, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-507","alert_type":396,"serial_number":"AV26-507","subject":"other","moderation_state":"published","external_url":null},{"nid":7742,"title":"cPanel security advisory (AV26-508)","uuid":"428a4cfb-ae60-494c-a2c6-d87666678a24","banner":null,"lang":"en","date_modified":"2026-05-25","date_modified_ts":"2026-05-25T14:30:43Z","date_created":"2026-05-25T14:30:06Z","summary":null,"body":["<article data-history-node-id=\"7742\" about=\"\/en\/alerts-advisories\/cpanel-security-advisory-av26-508\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-508<br \/><strong>Date:<\/strong> May 25, 2026<strong>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0<\/strong><br \/><br \/>\nOn May 22, 2026, cPanel published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>ea-nginx \u2013 version v1.31.0<\/li>\n\t<li>ea-nginx-passenger \u2013 version v6.1.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40670279527831-Security-CVE-2026-9256-ea-nginx-v1-31-1-Security-Release-May-22-2026\">Security: CVE-2026-9256 ea-nginx v1.31.1 Security Release - May 22, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360007088193-Security\">cPanel Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cpanel-security-advisory-av26-508","alert_type":396,"serial_number":"AV26-508","subject":"other","moderation_state":"published","external_url":null},{"nid":7743,"title":"[Control Systems] Moxa security advisory (AV26-509)","uuid":"76f5c78d-eab0-4d68-904c-51aabbe563b7","banner":null,"lang":"en","date_modified":"2026-05-26","date_modified_ts":"2026-05-26T12:59:13Z","date_created":"2026-05-26T12:52:03Z","summary":null,"body":["<article data-history-node-id=\"7743\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-509\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:\u00a0<\/strong>AV26-509<br \/><strong>Date:\u00a0<\/strong>May\u00a026, 2026<\/p>\n\n<p>On May 26, 2026, Moxa published\u00a0a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>UC-1200A\/2200A\/3400A\/4400A\/8600A\/8200 Series \u2013 multiple versions and models<\/li>\n\t<li>V1200 Series \u2013 version MIL3 v1.2.0 and prior<\/li>\n\t<li>V3200 Series \u2013 version MIL3 v1.1 and prior<\/li>\n\t<li>V3400 Series \u2013 version MIL3 v1.1 and prior<\/li>\n\t<li>VM-1220 Series \u2013 version MIL3 v1.1.0 and prior<\/li>\n\t<li>ioThinx 4530 Series \u2013 version MIL3 v2.1 and prior<\/li>\n\t<li>AIG-302 Series \u2013 version v1.4.0 and prior<\/li>\n\t<li>AIG-502 Series \u2013 version v1.0.0<\/li>\n\t<li>BXP-A100 Series \u2013 version Debian 11 V1.0<\/li>\n\t<li>BXP-A101 Series \u2013 version Debian 12 V1.0<\/li>\n\t<li>DRP-A100 Series \u2013 version Debian 11 V1.0<\/li>\n\t<li>RKP-A110 Series \u2013 version Debian 11 V1.0<\/li>\n\t<li>RKP-C110 Series \u2013 version Debian 12 V1.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-263140-cve-2026-31431,-cve-2026-43284,-cve-2026-43500-copy-fail-and-dirty-frag-vulnerabilities-in-linux-kernel\">CVE-2026-31431, CVE-2026-43284, CVE-2026-43500: Copy Fail and Dirty Frag Vulnerabilities in Linux Kernel<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-509","alert_type":398,"serial_number":"AV26-509","subject":"other","moderation_state":"published","external_url":null},{"nid":7744,"title":"[Control systems] ABB security advisory (AV26-510)","uuid":"6de1bc1f-2c96-4003-bc24-47ba8a4b7302","banner":null,"lang":"en","date_modified":"2026-05-26","date_modified_ts":"2026-05-26T14:33:00Z","date_created":"2026-05-26T14:30:06Z","summary":null,"body":["<article data-history-node-id=\"7744\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-510\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-510<br \/><strong>Date: <\/strong>May 26, 2026<\/p>\n\n<p>On May 26, 2026, ABB published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>PPT30 Operating System \u2013 versions prior to 1.8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/br-cws-assets.de-fra-1.linodeobjects.com\/SA25P006-0eec719c.pdf\">PPT30 OPC-UA Server has issues handling concurrent connections (CVE-2025-11482) (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-510","alert_type":398,"serial_number":"AV26-510","subject":"abb","moderation_state":"published","external_url":null},{"nid":7745,"title":"Hitachi security advisory (AV26-511)","uuid":"84f9a108-49e5-4a11-8f73-139fa0b64093","banner":null,"lang":"en","date_modified":"2026-05-27","date_modified_ts":"2026-05-27T16:04:09Z","date_created":"2026-05-27T15:56:24Z","summary":null,"body":["<article data-history-node-id=\"7745\" about=\"\/en\/alerts-advisories\/hitachi-security-advisory-av26-511\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-511<br \/><strong>Date: <\/strong>May\u00a027, 2026<\/p>\n\n<p>On May\u00a026, 2026, Hitachi published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cosminexus Developer's Kit for Java<\/li>\n\t<li>Hitachi Automation Director\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Configuration Manager\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Compute Systems Manager\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Developer's Kit for Java<\/li>\n\t<li>Hitachi Device Manager\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Dynamic Link Manager\u00a0\u2013 versions prior to 9.0.0-00<\/li>\n\t<li>Hitachi Global Link Manager\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Infrastructure Analytics Advisor (English version)\u00a0\u2013 multiple components and versions<\/li>\n\t<li>Hitachi Ops Center Administrator (English version)\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Ops Center Analyzer (English Version)\u00a0\u2013 multiple components and versions<\/li>\n\t<li>Hitachi Ops Center Analyzer Common Services\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Ops Center Analyzer Viewpoint (English version)\u00a0\u2013 versions 10.8.1-00 to versions prior to 11.0.8-00<\/li>\n\t<li>Hitachi Ops Center API Configuration Manager\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Ops Center Automator\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Ops Center Viewpoint (Japanese version)\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Replication Manager\u00a0\u2013 versions prior to 9.0.0-00<\/li>\n\t<li>Hitachi Tiered Storage Manager\u00a0\u2013 all versions<\/li>\n\t<li>Hitachi Tuning Manager\u00a0\u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-120\/index.html\">Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-121\/index.html\">Multiple Vulnerabilities in Cosminexus<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-122\/index.html\">Multiple Vulnerabilities in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/index.html\">Hitachi Vulnerability Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hitachi-security-advisory-av26-511","alert_type":396,"serial_number":"AV26-511","subject":"other","moderation_state":"published","external_url":null},{"nid":7746,"title":"GitHub security advisory (AV26-512)","uuid":"b8c0211f-8d02-4407-9118-0dec470b068f","banner":null,"lang":"en","date_modified":"2026-05-27","date_modified_ts":"2026-05-27T17:18:33Z","date_created":"2026-05-27T15:56:24Z","summary":null,"body":["<article data-history-node-id=\"7746\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-512\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-512<br \/><strong>Date:<\/strong> May\u00a027, 2026<\/p>\n\n<p>On May\u00a026, 2026, GitHub published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.20.x prior to 3.20.3<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.7<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.10<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.16<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.16.x prior to 3.16.19<\/li>\n<\/ul><p><strong>GitHub has stated that future patches and releases will be signed with a new public key, and customers will need to rotate to the new key before those patches and releases can be installed.<\/strong><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.20\/admin\/release-notes\">Enterprise Server 3.20.3<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.7<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.10<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.16<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.16\/admin\/release-notes\">Enterprise Server 3.16.19<\/a><\/li>\n\t<li><a href=\"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/\">Investigation update: GitHub Enterprise Server signing key rotation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-512","alert_type":396,"serial_number":"AV26-512","subject":"other","moderation_state":"published","external_url":null},{"nid":7747,"title":"Veeam security advisory (AV26-513) \u2013 Update 1","uuid":"f3ec407a-a869-4298-8791-0f65f2c17495","banner":null,"lang":"en","date_modified":"2026-09-21","date_modified_ts":"2026-09-21T19:24:49Z","date_created":"2026-05-27T17:29:54Z","summary":null,"body":["<article data-history-node-id=\"7747\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-513\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-513<br \/><strong>Date:<\/strong> May\u00a027, 2026<br \/><strong>Updated:<\/strong> September 21, 2026<\/p>\n\n<p>On May\u00a027, 2026, Veeam published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Veeam Backup &amp; Replication\u00a0\u2013 13 versions prior to 13.0.2.29<\/li>\n\t<li>Veeam ONE\u00a0\u2013 versions prior to 13.0.2.6723<\/li>\n\t<li>Veeam Service Provider Console\u00a0\u2013 9.2 versions prior to 9.2.1.33875<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-32996 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4852\">Vulnerabilities Resolved in Veeam Backup &amp; Replication 13.0.2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4856\">List of Security Fixes and Improvements in Veeam Service Provider Console<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4858\">List of Security Fixes and Improvements in Veeam ONE<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4853\">Vulnerability Resolved in Veeam Service Provider Console 9.2.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-513","alert_type":396,"serial_number":"AV26-513","subject":"other","moderation_state":"published","external_url":null},{"nid":7748,"title":"[Control Systems] Phoenix Contact Security Advisory (AV26-514)","uuid":"550a958a-94ae-4b5f-931f-0d1e1f03a787","banner":null,"lang":"en","date_modified":"2026-05-27","date_modified_ts":"2026-05-27T17:43:26Z","date_created":"2026-05-27T17:29:55Z","summary":null,"body":["<article data-history-node-id=\"7748\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-514\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-514<br \/><strong>Date:<\/strong> May\u00a027, 2026<\/p>\n\n<p>On May\u00a027, 2026, Phoenix Contact published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>AXC F\u00a0\u2013 multiple models and versions prior to 2026.0.3<\/li>\n\t<li>BCP 9102S\u00a0\u2013 versions prior to 2026.0.3<\/li>\n\t<li>EPC 1522\u00a0\u2013 versions prior to 2026.0.3<\/li>\n\t<li>RFC 4072R\u00a0\u2013 versions prior to 2026.0.3<\/li>\n\t<li>RFC 4072S\u00a0\u2013 versions prior to 2026.0.3<\/li>\n\t<li>VL3 UPC 2440 EDGE\u00a0\u2013 versions prior to 2026.0.3<\/li>\n\t<li>VPLCNEXT CONTROL\u00a0\u2013 multiple models and versions prior to 2026.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/assets.phoenixcontact.com\/file\/a9721fd9-1ad4-495c-b341-15d3a5f363a9\/media\/original?pcsa-2026-00005_vde-2026-050.pdf\">VDE-2026-050: Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.phoenixcontact.com\/en-pc\/service-and-support\/psirt\">Phoenix Contact Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-514","alert_type":398,"serial_number":"AV26-514","subject":"other","moderation_state":"published","external_url":null},{"nid":7749,"title":"Jenkins security advisory (AV26-515)","uuid":"c15350b4-e641-4b8c-bb60-51738c74247d","banner":null,"lang":"en","date_modified":"2026-05-27","date_modified_ts":"2026-05-27T19:02:51Z","date_created":"2026-05-27T18:53:22Z","summary":null,"body":["<article data-history-node-id=\"7749\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-515\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-515<br \/><strong>Date: <\/strong>May\u00a027, 2026<\/p>\n\n<p>On May\u00a027, 2026, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Active Directory Plugin\u00a0\u2013 version 2.4.1 and prior<\/li>\n\t<li>AppSpider Plugin\u00a0\u2013 version 1.0.17 and prior<\/li>\n\t<li>Bitbucket OAuth Plugin\u00a0\u2013 version 0.17 and prior<\/li>\n\t<li>buildgraph-view Plugin\u00a0\u2013 version 1.8 and prior<\/li>\n\t<li>Credentials Binding Plugin\u00a0\u2013 version 720.v3f6decef43ea_ and prior<\/li>\n\t<li>Email Extension Plugin\u00a0\u2013 version 1933.v45cec755423f and prior<\/li>\n\t<li>GitHub Integration Plugin\u00a0\u2013 version 0.7.3 and prior<\/li>\n\t<li>Job Import Plugin\u00a0\u2013 version 143.v044a_2e819b_27 and prior<\/li>\n\t<li>LDAP Plugin\u00a0\u2013 version 807.v7d7de30930cf and prior<\/li>\n\t<li>Pipeline: Groovy Libraries Plugin\u00a0\u2013 version 797.v90ea_a_9b_e45a_0 and prior<\/li>\n\t<li>Multijob Plugin\u00a0\u2013 version 662.vd2e0001f6b_b_d and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-05-27\/\">Jenkins Security Advisory 2026-05-27<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-515","alert_type":396,"serial_number":"AV26-515","subject":"other","moderation_state":"published","external_url":null},{"nid":7750,"title":"GitLab security advisory (AV26-516)","uuid":"b41954d9-028f-4db8-a281-aa15dafc5909","banner":null,"lang":"en","date_modified":"2026-05-27","date_modified_ts":"2026-05-27T19:05:04Z","date_created":"2026-05-27T18:53:22Z","summary":null,"body":["<article data-history-node-id=\"7750\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-516\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-516<br \/><strong>Date:<\/strong> May\u00a027, 2026<\/p>\n\n<p>On May\u00a027, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 19.0.1, 18.11.4, 18.10.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 19.0.1, 18.11.4, 18.10.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-0-1-released\/\">GitLab Patch Release: 19.0.1, 18.11.4, 18.10.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-516","alert_type":396,"serial_number":"AV26-516","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7751,"title":"Google Chrome security advisory (AV26-517)","uuid":"69a4936a-c0cd-497a-b20e-a16de5a33ee4","banner":null,"lang":"en","date_modified":"2026-05-27","date_modified_ts":"2026-05-27T19:38:08Z","date_created":"2026-05-27T19:34:29Z","summary":null,"body":["<article data-history-node-id=\"7751\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-517\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-517<br \/><strong>Date:<\/strong> May 27, 2026<\/p>\n\n<p>On May 27, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to0.7778.216\/217 (Windows), 148.0.7778.215\/216 (Mac) and 148.0.7778.215 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/05\/stable-channel-update-for-desktop_0877304591.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-517","alert_type":396,"serial_number":"AV26-517","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7752,"title":"Drupal security advisory (AV26-518)","uuid":"20a141a2-be05-425f-bfaa-f6be5fb8c04e","banner":null,"lang":"en","date_modified":"2026-05-28","date_modified_ts":"2026-05-28T14:00:49Z","date_created":"2026-05-28T13:56:41Z","summary":null,"body":["<article data-history-node-id=\"7752\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-518\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-518<br \/><strong>Date:\u00a0<\/strong>May 28, 2026<\/p>\n\n<p>On May 27, 2026, Drupal published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Drupal AlternativeCommerce (Basket)\u00a0\u2013 versions prior to 2.1.17<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-038 \">Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-518","alert_type":396,"serial_number":"AV26-518","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7753,"title":"Veeam security advisory (AV26-519)","uuid":"bdaa2dc6-1cfc-48dc-899d-5230c8f5f73a","banner":null,"lang":"en","date_modified":"2026-05-28","date_modified_ts":"2026-05-28T14:08:11Z","date_created":"2026-05-28T14:01:50Z","summary":null,"body":["<article data-history-node-id=\"7753\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-519\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-519<br \/><strong>Date:\u00a0<\/strong>May 28, 2026<\/p>\n\n<p>On May 27, 2026, Veeam published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Veeam Backup for AWS 10.1\u00a0\u2013 versions prior to 10.1.0.40<\/li>\n\t<li>Veeam Backup for Google Cloud 7.0.1\u00a0\u2013 versions prior to 7.0.1.4<\/li>\n\t<li>Veeam Backup for Microsoft Azure 8.1 Patch 2\u00a0\u2013 versions prior to 8.0.236<\/li>\n\t<li>Veeam Recovery Orchestrator\u00a0\u2013 versions prior to 13.0.2.27<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4857\">List of Security Fixes and Improvements in Veeam Recovery Orchestrator<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4851\">Release Information for Veeam Backup for AWS 10.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4859\">Release Information for Veeam Backup for Google Cloud 7.0.1 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4850\">Release Information for Veeam Backup for Microsoft Azure 8.1 Patch 2 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-519","alert_type":396,"serial_number":"AV26-519","subject":"other","moderation_state":"published","external_url":null},{"nid":7754,"title":"Zimbra security advisory (AV26-520)","uuid":"c1e546f4-70a6-4246-9fdb-0cde1e70dbc7","banner":null,"lang":"en","date_modified":"2026-05-28","date_modified_ts":"2026-05-28T14:16:49Z","date_created":"2026-05-28T14:09:24Z","summary":null,"body":["<article data-history-node-id=\"7754\" about=\"\/en\/alerts-advisories\/zimbra-security-advisory-av26-520\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-520<br \/><strong>Date:\u00a0<\/strong>May 28, 2026<\/p>\n\n<p>On May 28, 2026, Zimbra published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Zimbra Daffodil\u00a0\u2013 versions prior to v10.1.17<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Releases\/10.1.17\">Zimbra Daffodil (v10.1.17) Patch Release<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.zimbra.com\/\">Zimbra Patch Release Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zimbra-security-advisory-av26-520","alert_type":396,"serial_number":"AV26-520","subject":"other","moderation_state":"published","external_url":null},{"nid":7755,"title":"Notepad++ security advisory (AV26-521)","uuid":"07e7c07b-3751-4fa2-a27f-b66ae6dd4723","banner":null,"lang":"en","date_modified":"2026-05-28","date_modified_ts":"2026-05-28T14:21:59Z","date_created":"2026-05-28T14:17:46Z","summary":null,"body":["<article data-history-node-id=\"7755\" about=\"\/en\/alerts-advisories\/notepad-security-advisory-av26-521\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-521<br \/><strong>Date:<\/strong>\u00a0May 28, 2026<\/p>\n\n<p>On May 26, 2026, Notepad++ published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Notepad++\u00a0\u2013 versions prior to v8.9.6.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/notepad-plus-plus.org\/news\/v8961-released\/\">Notepad++ v8.9.6.1 release<\/a><\/li>\n\t<li><a href=\"https:\/\/community.notepad-plus-plus.org\/category\/1\/announcements\">Notepad++ community<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/notepad-security-advisory-av26-521","alert_type":396,"serial_number":"AV26-521","subject":"other","moderation_state":"published","external_url":null},{"nid":7757,"title":"Erlang security advisory (AV26-522)","uuid":"f87d75ae-5f57-44f2-ac17-e5c46794d6dd","banner":null,"lang":"en","date_modified":"2026-05-28","date_modified_ts":"2026-05-28T17:45:46Z","date_created":"2026-05-28T17:40:48Z","summary":null,"body":["<article data-history-node-id=\"7757\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av26-522\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-522<br \/><strong>Date:\u00a0<\/strong>May 28, 2026<\/p>\n\n<p>On May 27, 2026, Erlang published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>OTP\u00a0\u2013 versions prior to 29.0.1, 28.5.0.1, 27.3.4.12 and 26.2.5.21<\/li>\n\t<li>Public_key (OTP)\u00a0\u2013 versions prior to 1.21.1, 1.20.3.1, 1.17.1.3 and 1.15.1.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-22cw-4ph4-6447\">Name Constraints and Subject CommonName Fallback in TLS hostname Verification<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-c99q-jmpx-v8qq\">public_key Accepts non-CA Certificate as Intermediate Issuer, Enabling Chain Forgery<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-cjxj-wj6x-3fff\">OCSP Responder Certificate Accepted After Expiry in public_key<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\">Erlang Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av26-522","alert_type":396,"serial_number":"AV26-522","subject":"other","moderation_state":"published","external_url":null},{"nid":7758,"title":"Tanium security advisory (AV26-523)","uuid":"51a73bbc-3bdf-4be9-ae07-83c78c1074fd","banner":null,"lang":"en","date_modified":"2026-05-28","date_modified_ts":"2026-05-28T17:50:23Z","date_created":"2026-05-28T17:46:25Z","summary":null,"body":["<article data-history-node-id=\"7758\" about=\"\/en\/alerts-advisories\/tanium-security-advisory-av26-523\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-523<br \/><strong>Date:\u00a0<\/strong>May 28, 2026<\/p>\n\n<p>On May 27, 2026, Tanium published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Connect 2024H2\u00a0\u2013 versions prior to Update 25 (v5.26.191)<\/li>\n\t<li>Connect 2025H1\u00a0\u2013 versions prior to Update 19 (v5.29.237)<\/li>\n\t<li>Connect 2025H2\u00a0\u2013 versions prior to Update 9 (v5.37.140)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.tanium.com\/TAN-2026-015\/ \">Tanium Security Advisories\u00a0- TAN-2026-015<\/a><\/li>\n\t<li><a href=\"https:\/\/security.tanium.com\/TAN-2026-014\/\">Tanium Security Advisories\u00a0- TAN-2026-014<\/a><\/li>\n\t<li><a href=\"https:\/\/security.tanium.com\/\">Tanium Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tanium-security-advisory-av26-523","alert_type":396,"serial_number":"AV26-523","subject":"other","moderation_state":"published","external_url":null},{"nid":7759,"title":"Mitel security advisory (AV26-524)","uuid":"4b330bd2-90bb-46e3-ba8f-240194408948","banner":null,"lang":"en","date_modified":"2026-05-28","date_modified_ts":"2026-05-28T19:10:15Z","date_created":"2026-05-28T19:03:12Z","summary":null,"body":["<article data-history-node-id=\"7759\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av26-524\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-524<br \/><strong>Date:\u00a0<\/strong>May 28, 2026<\/p>\n\n<p>On May 28, 2026, Mitel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Mitel Standard Linux\u00a0\u2013 versions 12.x and prior<\/li>\n\t<li>MiVoice 5000\u00a0\u2013 versions 8.x and prior<\/li>\n\t<li>MiVoice Border Gateway\u00a0\u2013 versions 11.6.x, 12.x and prior<\/li>\n\t<li>MiVoice Business\u00a0\u2013 versions 10.1.x to 10.5.x<\/li>\n\t<li>MiVoice Business Solution Virtual Instance\u00a0\u2013 versions 2.x and prior<\/li>\n\t<li>MiVoice MX-ONE\u00a0\u2013 versions 7.3 to 7.8 and version 8.x and prior<\/li>\n\t<li>OpenScape 4000\u00a0\u2013 versions V10 R1.x, V11 R0.22, V11 R1.26 and prior<\/li>\n\t<li>OpenScape Branch\u00a0\u2013 versions V10.3 and V11.x and prior<\/li>\n\t<li>OpenScape SBC\u00a0\u2013 versions V10.3 and V11.x and prior<\/li>\n\t<li>OpenScape Voice Server\u00a0\u2013 versions V9R3 JITC, V10, V11 and prior<\/li>\n\t<li>MiCollab\u00a0\u2013 versions 10.x and prior<\/li>\n\t<li>MiCloud Management Portal\u00a0\u2013 versions 6.3.x and prior<\/li>\n\t<li>Mitel Open Integration Gateway\u00a0\u2013 versions 4.3.x and prior<\/li>\n\t<li>Mitel Performance Analytics MPA\u00a0\u2013 versions 3.6x and prior<\/li>\n\t<li>OpenScape Contact Media Service (used by Mitel CX and OpenScape Contact Center) \u2013 versions V12Rx and prior<\/li>\n\t<li>Mitel SIP DECT\u00a0\u2013 versions 9.1, 9.2, 10.0, 10.1 and prior<\/li>\n\t<li>OpenScape Xpert Clients 6010P\u00a0\u2013 versions V7, V8 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2026-0004\">Linux Kernel Local Privilege Escalation Vulnerabilities \"Dirty Frag\" (CVE-2026-43284, CVE-2026-43500)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av26-524","alert_type":396,"serial_number":"AV26-524","subject":"mitel","moderation_state":"published","external_url":null},{"nid":7760,"title":"Microsoft Edge security advisory (AV26-525)","uuid":"8ffcef83-c9f5-4e31-8f04-333041e1e913","banner":null,"lang":"en","date_modified":"2026-05-29","date_modified_ts":"2026-05-29T13:12:50Z","date_created":"2026-05-29T13:05:26Z","summary":null,"body":["<article data-history-node-id=\"7760\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-525\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-525<br \/><strong>Date:<\/strong> May 29, 2026<\/p>\n\n<p>On May 28, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 148.0.3967.96<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#may-28-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-525","alert_type":396,"serial_number":"AV26-525","subject":"other","moderation_state":"published","external_url":null},{"nid":7761,"title":"Oracle security advisory (AV26-526) \u2013 Update 2","uuid":"a3cd2cb8-0c1b-4aa9-82ee-5bf7a1cbb198","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T19:12:30Z","date_created":"2026-05-29T13:15:32Z","summary":null,"body":["<article data-history-node-id=\"7761\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-av26-526\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-526<br \/><strong>Date:<\/strong> May\u00a029, 2026<br \/><strong>Updated:<\/strong> July\u00a015, 2026<\/p>\n\n<p>On May\u00a028, 2026, Oracle published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Oracle Communications Unified Assurance\u00a0- versions 6.1.1 to 7.0.0<\/li>\n\t<li>Oracle Database Server\u00a0- versions 23.4.0 to 23.26.2<\/li>\n\t<li>Oracle E-Business Suite\u00a0- versions 12.2.3 to 12.2.15<\/li>\n\t<li>Oracle Hospitality OPERA 5 Property Services\u00a0- versions 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28<\/li>\n\t<li>Oracle REST Data Services\u00a0- versions 24.2.0 to 26.1.0<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-46817 is being exploited.<\/p>\n\n<h2>Update 2<\/h2>\n\n<p>On July 15, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-46817 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cspumay2026.html\">Oracle Critical Security Patch Update Advisory\u00a0- May 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/\">Oracle Critical Patch Updates, Security Alerts and Bulletins<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-46817\">CISA KEV: CVE-2026-46817<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-av26-526","alert_type":396,"serial_number":"AV26-526","subject":"oracle","moderation_state":"published","external_url":null},{"nid":7763,"title":"AL26-013 Security incident impacting GitHub internal repositories","uuid":"fab0e0a2-c3b2-47e8-99f5-42aca8ca7148","banner":null,"lang":"en","date_modified":"2026-05-29","date_modified_ts":"2026-05-29T16:11:50Z","date_created":"2026-05-29T16:10:43Z","summary":null,"body":["<article data-history-node-id=\"7763\" about=\"\/en\/alerts-advisories\/al26-013-security-incident-impacting-github-internal-repositories\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-013<br \/><strong>Date:<\/strong> May 29, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On <span class=\"nowrap\">May 18, 2026<\/span>, GitHub detected unauthorized access to its internal systems originating from a compromised employee device<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. The intrusion was facilitated by a maliciously modified version of the Nx Console Visual Studio Code extension (version 18.95.0)<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. The attacker successfully exfiltrated approximately <span class=\"nowrap\">3,800<\/span> internal GitHub repositories, containing proprietary source code and internal configuration data. GitHub Enterprise Server customers are advised to follow vendors recommendations. No action is required for GitHub Enterprise Cloud clients.<\/p>\n\n<p>In response to this security incident, and the release of the GitHub Security Notification, the Cyber Centre released <span class=\"nowrap\">AV26-512<\/span> on <span class=\"nowrap\">May 27, 2026<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/span>.<\/p>\n\n<p>The purpose of this alert is to increase awareness of the reported incident and to take necessary measures.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre suggests the following actions:<\/p>\n\n<ul><li>Monitor for compromise by reviewing CI\/CD (Continuous Integration\/Continuous Deployment) logs for unexpected repository access\/cloning, unauthorized admin actions, authentication\/access control changes, unauthorized pushes or orphan commits, and suspicious commits after May\u00a018,\u00a02026\u00a0\u2014 especially from bot\/service accounts (e.g., ci-bot, build-bot).<\/li>\n\t<li>Remove Nx Console v18.95.0 from all environments and downgrade\/upgrade to a known good version (18.94.0 or 18.96.0+).<\/li>\n\t<li>If the malicious version of Nx Console is present:\n\t<ul><li>Check macOS systems for <code>~\/.local\/share\/kitty\/cat.py<\/code> and related persistence (launch agents)<\/li>\n\t\t<li>Immediately rotate all credentials (AWS, GCP, Azure, GitHub, npm) exposed on developer machines between <span class=\"nowrap\">May 11\u201320, 2026.<\/span><\/li>\n\t<\/ul><\/li>\n\t<li>Strengthen controls by disabling IDE extension auto-updates in high-security environments and enforcing an approved allowlist of developer tools.<\/li>\n\t<li>Rotate GitHub Enterprise Server GPG (GNU Privacy Guard) public keys per vendor guidance, as future patches\/releases require the new key before installation.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/github.blog\/security\/investigating-unauthorized-access-to-githubs-internal-repositories\/\">Investigation update: GitHub Enterprise Server signing key rotation<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/nx.dev\/blog\/nx-console-v18-95-0-postmortem\">Postmortem: Nx Console v18.95.0 supply-chain compromise<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/alerts-advisories\/github-security-advisory-av26-512\">AV26-512\u00a0\u2013 GitHub security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-013-security-incident-impacting-github-internal-repositories","alert_type":397,"serial_number":"AL26-013","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7765,"title":"IBM security advisory (AV26-527)","uuid":"b79bffe0-76c5-42e4-be9b-a204bdafe729","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T12:52:02Z","date_created":"2026-06-01T12:41:42Z","summary":null,"body":["<article data-history-node-id=\"7765\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-527\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-527<br \/><strong>Date: <\/strong>June 1, 2026<\/p>\n\n<p>Between May 25 and 31, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Aspera Enterprise WebApps \u2013 versions 1.0.0 to 1.0.2.1<\/li>\n\t<li>IBM Business Automation Workflow containers and traditional \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Business Automation \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Security \u2013 versions 1.10.0.0 to 1.10.11.0<\/li>\n\t<li>IBM Control Center \u2013 multiple versions<\/li>\n\t<li>IBM DataStax Enterprise \u2013 versions 5.1, 6.7, 6.8 and 6.9<\/li>\n\t<li>IBM Edge Application Manager \u2013 multiple versions<\/li>\n\t<li>IBM Engineering Lifecycle Management - Jazz Foundation \u2013 multiple versions<\/li>\n\t<li>IBM Library Support for Spring \u2013 version 3.3<\/li>\n\t<li>IBM License Metric Tool \u2013 versions 9.2.0 to 9.2.43<\/li>\n\t<li>IBM Maximo Application Suite - Monitor Component \u2013 version 9.1.0.0<\/li>\n\t<li>IBM Observability with Instana (Agent) \u2013 versions Build 1.0.303 to 1.0.318<\/li>\n\t<li>IBM Process Mining \u2013 versions 2.0.0 to 2.1.1 IF001<\/li>\n\t<li>IBM Security SOAR \u2013 multiple versions<\/li>\n\t<li>IBM Tivoli Application Dependency Discovery Manager \u2013 versions 7.3.0.0 to 7.3.0.12<\/li>\n\t<li>QRadar Suite Software \u2013 versions 1.10.12.0 to 1.11.10.0<\/li>\n\t<li>WebSphere Service Registry and Repository \u2013 version 8.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-527","alert_type":396,"serial_number":"AV26-527","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7766,"title":"Dell security advisory (AV26-528)","uuid":"12b4e78a-da1a-4ce7-92c0-3da12ad4b80e","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T13:01:54Z","date_created":"2026-06-01T12:54:06Z","summary":null,"body":["<article data-history-node-id=\"7766\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-528\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-528<br \/><strong>Date:<\/strong> June 1, 2026<\/p>\n\n<p>Between May 25 and 31, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>PowerEdge Server Chipset Driver \u2013 multiple applications and versions<\/li>\n\t<li>Data Lakehouse \u2013 versions prior to 1.8.0.0<\/li>\n\t<li>Dell Enterprise SONiC Distribution \u2013 versions prior to 4.5.2<\/li>\n\t<li>Dell Unity \u2013 versions prior to 5.5.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000469673\/dsa-2026-232-security-update-for-amd-based-poweredge-server-chipset-driver-vulnerabilities\">DSA-2026-232: Security Update for AMD-based PowerEdge Server Chipset Driver Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000469911\/dsa-2026-199-security-update-for-dell-data-lakehouse-multiple-third-party-component-vulnerabilities\">DSA-2026-199: Security Update for Dell Data Lakehouse Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000470137\/dsa-2026-241-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities\">DSA-2026-241: Security Update for Dell Enterprise SONiC Distribution Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000470814\/dsa-2026-211---security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities\">DSA-2026-211 -: Security Update for Dell Unity, Dell UnityVSA and Dell Unity XT Security Update for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-528","alert_type":396,"serial_number":"AV26-528","subject":"dell","moderation_state":"published","external_url":null},{"nid":7767,"title":"Ubuntu security advisory (AV26-529)","uuid":"690d1d1a-a9f9-4c59-9af0-6c38175bf621","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T13:07:31Z","date_created":"2026-06-01T13:03:39Z","summary":null,"body":["<article data-history-node-id=\"7767\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-529\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-529<br \/><strong>Date:<\/strong> June 1, 2026<\/p>\n\n<p>Between May 25 and 31, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8305-2\">USN-8305-2: Linux kernel (Low Latency) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8305-1\">USN-8305-1: Linux kernel (Intel IoTG Real-time) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-8310-1\">USN-8310-1: Linux kernel (Azure) vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-529","alert_type":396,"serial_number":"AV26-529","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7768,"title":"[Control systems] CISA ICS security advisories (AV26\u2013530)","uuid":"3d1c4280-1ae4-43cc-8771-ccabc689be26","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T13:15:12Z","date_created":"2026-06-01T13:10:45Z","summary":null,"body":["<article data-history-node-id=\"7768\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-530\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26\u2013530<br \/><strong>Date:<\/strong> June 1, 2026<\/p>\n\n<p>Between May 25 and 31, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB AC500 V2 \u2013 versions prior to 2.5.2 and 2.5.3<\/li>\n\t<li>ABB Ability Camera Connect \u2013 versions prior to 1.5.0.14 and 1.5.0.15<\/li>\n\t<li>ABB Ability Zenon \u2013 versions 7.50 to 14<\/li>\n\t<li>ABB B&amp;R Automation Runtime \u2013 versions prior to 6.3 and Q4.93<\/li>\n\t<li>ABB EIBPORT V3 KNX (2CLA963710W1001) \/ (2CSM256242R2001) \u2013 versions prior to 3.9.2<\/li>\n\t<li>ABB EIBPORT V3 KNX GSM (2CLA963720W1001) \u2013 versions prior to 3.9.2<\/li>\n\t<li>ABB LVS MConfig \u2013 versions 1.4.9.21 and prior<\/li>\n\t<li>CP Plus 8 Ch. Network Video Recorder \u2013 multiple versions<\/li>\n\t<li>Eppendorf BioFlo 320 \u2013 all versions<\/li>\n\t<li>Frontier X Android application \u2013 versions prior to v15.0.0<\/li>\n\t<li>Frontier X IOS application\u2013 versions prior to v25.0.0<\/li>\n\t<li>Frontier X2 \u2013 all versions<\/li>\n\t<li>Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232\/485 to Wi-Fi\/Ethernet Converter \u2013 version 7.03T.07<\/li>\n\t<li>KMW CCTV Security Cameras \u2013 versions KM-IP521 IPCAM_V4.04.91.230307 and KM-IP421 IPCAM_V4.04.53.210416<\/li>\n\t<li>MacGregor Voyage Data Recorder (VDR) G4e \u2013 versions prior to V5.250<\/li>\n\t<li>Schneider Electric EcoStruxure Machine Expert HVAC \u2013 versions prior to 1.10.0<\/li>\n\t<li>Switch Actuator 4 DU \u2013 all versions<\/li>\n\t<li>Switch Actuator, door\/light 4 DU \u2013 all versions<\/li>\n\t<li>Terra AC Wallbox \u2013 multiple versions and models<\/li>\n\t<li>XCharge C6 \u2013 version C6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-530","alert_type":398,"serial_number":"AV26-530","subject":"other","moderation_state":"published","external_url":null},{"nid":7769,"title":"Red Hat security advisory (AV26-531)","uuid":"a88466e6-7751-4af7-bdd1-a01d7b4a8c14","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T13:19:43Z","date_created":"2026-06-01T13:16:56Z","summary":null,"body":["<article data-history-node-id=\"7769\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-531\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-531<br \/><strong>Date: <\/strong>June 1, 2026<\/p>\n\n<p>Between May 25 and 31, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-531","alert_type":396,"serial_number":"AV26-531","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7770,"title":"Mozilla security advisory (AV26-532)","uuid":"0189f120-6aee-4663-88fe-285bd100cefe","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T13:25:32Z","date_created":"2026-06-01T13:22:27Z","summary":null,"body":["<article data-history-node-id=\"7770\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-532\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-532<br \/><strong>Date: <\/strong>June 1, 2026<\/p>\n\n<p>On June 1, 2026, Mozilla published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Firefox for iOS \u2013 versions prior to 151.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-53\/\">Mozilla Foundation Security Advisory 2026-53<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-532","alert_type":396,"serial_number":"AV26-532","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7771,"title":"Ivanti security advisory (AV26-533)","uuid":"0e3d964a-c450-4588-836a-70d2df8c90aa","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T14:50:50Z","date_created":"2026-06-01T14:47:20Z","summary":null,"body":["<article data-history-node-id=\"7771\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-533\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-533<br \/><strong>Date: <\/strong>June 1, 2026<\/p>\n\n<p>On June 1, 2026, Ivanti published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Ivanti Neurons for ITSM (On-Premises) \u2013 version 2025.4 and prior<\/li>\n\t<li>Ivanti Neurons for ITSM (Cloud) \u2013 version 2026.1 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US\">Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-533","alert_type":396,"serial_number":"AV26-533","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7772,"title":"Plesk security advisory (AV26-534)","uuid":"f3ccc37a-e253-4080-860b-34cb0f2a93af","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T14:56:27Z","date_created":"2026-06-01T14:52:19Z","summary":null,"body":["<article data-history-node-id=\"7772\" about=\"\/en\/alerts-advisories\/plesk-security-advisory-av26-534\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-534<br \/><strong>Date:<\/strong> June 1, 2026<\/p>\n\n<p>On May 27, 2026, Plesk published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Plesk for Linux \u2013 versions prior to 18.0.75.1<\/li>\n\t<li>Plesk for Linux \u2013 versions prior to 18.0.76.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/38633651286679-Vulnerability-CVE-2026-44962-in-Plesk-s-APS-Catalog\">Vulnerability CVE-2026-44962 in Plesk's APS Catalog<\/a><\/li>\n\t<li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\">Plesk Support<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/plesk-security-advisory-av26-534","alert_type":396,"serial_number":"AV26-534","subject":"other","moderation_state":"published","external_url":null},{"nid":7774,"title":"Qualcomm security advisory \u2013 June 2026 monthly rollup (AV26-535)","uuid":"6a3345d1-ac14-4c82-b3ff-eb359dc8c511","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T18:27:07Z","date_created":"2026-06-01T18:24:47Z","summary":null,"body":["<article data-history-node-id=\"7774\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-june-2026-monthly-rollup-av26-535\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-535<br \/><strong>Date: <\/strong>June 1, 2026<\/p>\n\n<p>On June 1, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/june-2026-bulletin.html\">Qualcomm Security Bulletin \u2013 June<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-june-2026-monthly-rollup-av26-535","alert_type":396,"serial_number":"AV26-535","subject":"other","moderation_state":"published","external_url":null},{"nid":7775,"title":"Broadcom VMware security advisory (AV26-536)","uuid":"b6d07c0b-e910-4725-9d56-148ad7cfc87b","banner":null,"lang":"en","date_modified":"2026-06-01","date_modified_ts":"2026-06-01T18:31:58Z","date_created":"2026-06-01T18:28:57Z","summary":null,"body":["<article data-history-node-id=\"7775\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-536\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-536<br \/><strong>Date: <\/strong>June 1, 2026<\/p>\n\n<p>On May 29, 2026, Broadcom published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware Tanzu for Valkey \u2013 versions prior to 7.2.13<\/li>\n\t<li>VMware Tanzu for Valkey \u2013 versions prior to 8.0.9<\/li>\n\t<li>VMware Tanzu for Valkey \u2013 versions prior to 8.1.7<\/li>\n\t<li>VMware Tanzu for Valkey \u2013 versions prior to 9.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37556\">Product Release Advisory - VMware Tanzu for Valkey 7.2.13, 8.0.9, 8.1.7, 9.0.4<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories - VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-536","alert_type":396,"serial_number":"AV26-536","subject":"other","moderation_state":"published","external_url":null},{"nid":7776,"title":"Samsung mobile security advisory (AV26-537)","uuid":"12a2b097-6c09-4d21-a03f-077c8ba209e4","banner":null,"lang":"en","date_modified":"2026-06-02","date_modified_ts":"2026-06-02T15:09:15Z","date_created":"2026-06-02T15:02:43Z","summary":null,"body":["<article data-history-node-id=\"7776\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-537\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-537<br \/><strong>Date:<\/strong> June 2, 2026<\/p>\n\n<p>On June 2, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices \u2013 versions prior to SMR-JUN-2026<\/li>\n<\/ul><p>The most recent security update resolves multiple identified vulnerabilities.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=06\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-537","alert_type":396,"serial_number":"AV26-537","subject":"other","moderation_state":"published","external_url":null},{"nid":7777,"title":"Android security advisory \u2013 June 2026 monthly rollup (AV26-538) \u2013 Update 1","uuid":"70d73a97-8075-4069-aef1-3cff9187e8ca","banner":null,"lang":"en","date_modified":"2026-06-02","date_modified_ts":"2026-06-02T17:58:26Z","date_created":"2026-06-02T15:11:05Z","summary":null,"body":["<article data-history-node-id=\"7777\" about=\"\/en\/alerts-advisories\/android-security-advisory-june-2026-monthly-rollup-av26-538\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-538<br \/><strong>Date: <\/strong>June 2, 2026<\/p>\n\n<p>On June 1, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The vendor indicates that CVE-2025-48595 may be under limited, targeted exploitation.<\/p>\n\n<p><strong>Update 1<\/strong><br \/>\nOn June 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-48595 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-06-01\">Android Security Bulletin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48595\">CISA KEV: CVE-2025-48595<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-june-2026-monthly-rollup-av26-538","alert_type":396,"serial_number":"AV26-538","subject":"android","moderation_state":"published","external_url":null},{"nid":7778,"title":"HP security advisory (AV26-539)","uuid":"006245bf-51bd-4747-838c-aa3fd2b3271c","banner":null,"lang":"en","date_modified":"2026-06-02","date_modified_ts":"2026-06-02T15:24:01Z","date_created":"2026-06-02T15:20:21Z","summary":null,"body":["<article data-history-node-id=\"7778\" about=\"\/en\/alerts-advisories\/hp-security-advisory-av26-539\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-539<br \/><strong>Date: <\/strong>June 2, 2026<\/p>\n\n<p>On June 1, 2026, HP published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>HP Poly VVX\u00a0\u2013 versions prior to UCS 6.4.8\u00a0\u2013 Pending<\/li>\n\t<li>HP Poly Trio 8300\u00a0\u2013 versions prior to UCS 8.1.7<\/li>\n\t<li>HP Poly Trio 8500\u00a0\u2013 versions prior to UCS 7.2.8<\/li>\n\t<li>HP Poly Trio 8800\u00a0\u2013 versions prior to UCS 7.2.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, once available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hp.com\/us-en\/document\/ish_15052661-15052687-16\/hpsbpy04083\">Poly Voice\u00a0\u2013 Possible Remote Control of Certain Poly Devices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hp-security-advisory-av26-539","alert_type":396,"serial_number":"AV26-539","subject":"other","moderation_state":"published","external_url":null},{"nid":7779,"title":"[Control systems] Siemens security advisory (AV26-540)","uuid":"b9086e3e-225c-4734-9004-f2be54764527","banner":null,"lang":"en","date_modified":"2026-06-02","date_modified_ts":"2026-06-02T18:07:51Z","date_created":"2026-06-02T17:59:32Z","summary":null,"body":["<article data-history-node-id=\"7779\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-540\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-540<br \/><strong>Date:<\/strong> June 2, 2026<\/p>\n\n<p>On June 2, 2026, Siemens published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>RUGGEDCOM RST2428P (6GK6242-6PA00)\u00a0\u2013 versions prior to V4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-253495.html\">SSA-253495: <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Multiple Vulnerabilities in<\/span> SINEC OS <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">before<\/span> V4.0<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-540","alert_type":396,"serial_number":"AV26-540","subject":"other","moderation_state":"published","external_url":null},{"nid":7780,"title":"JetBrains security advisory (AV26-541)","uuid":"fac00974-f6e0-4ff8-a753-5698995581b7","banner":null,"lang":"en","date_modified":"2026-06-02","date_modified_ts":"2026-06-02T18:22:12Z","date_created":"2026-06-02T18:12:30Z","summary":null,"body":["<article data-history-node-id=\"7780\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-541\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-541<br \/><strong>Date: <\/strong>June 2, 2026<\/p>\n\n<p>On May 29, 2026, JetBrains published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>JetBrains IntelliJ IDEA\u00a0\u2013 versions prior to 2026.1.1<\/li>\n\t<li>JetBrains TeamCity\u00a0\u2013 versions prior to 2026.1.1 and 2025.11.5<\/li>\n\t<li>JetBrains YouTrack\u00a0\u2013 versions prior to 2026.1.13162<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p class=\"mrgn-bttm-md\">\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">JetBrains\u00a0\u2013 Fixed security issues<\/span><\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-541","alert_type":396,"serial_number":"AV26-541","subject":"other","moderation_state":"published","external_url":null},{"nid":7781,"title":"Mozilla security advisory (AV26-542)","uuid":"55b9ce54-01b0-4f7a-9392-8c7238510760","banner":null,"lang":"en","date_modified":"2026-06-02","date_modified_ts":"2026-06-02T18:35:44Z","date_created":"2026-06-02T18:28:14Z","summary":null,"body":["<article data-history-node-id=\"7781\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-542\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-542<br \/><strong>Date: <\/strong>June 2, 2026<\/p>\n\n<p>On June 2, 2026, Mozilla published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 151.0.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-54\/\">Mozilla Foundation Security Advisory 2026-54 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-542","alert_type":396,"serial_number":"AV26-542","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7782,"title":"HPE security advisory (AV26-543)","uuid":"4502e1a6-0260-4d09-beb0-6bd7673c8b4a","banner":null,"lang":"en","date_modified":"2026-06-02","date_modified_ts":"2026-06-02T20:02:25Z","date_created":"2026-06-02T20:01:46Z","summary":null,"body":["<article data-history-node-id=\"7782\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-543\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-543<br \/><strong>Date: <\/strong>June 2, 2026<\/p>\n\n<p>On June 2, 2026, HPE published security advisories to address vulnerabilities, including some critical ones, in the following products:<\/p>\n\n<ul><li>HPE Telco Network Function Virtualization Orchestrator\u00a0\u2013 version 7.6.0 and prior<\/li>\n\t<li>HPE Aruba Networking ArubaOS-CX Switches\u00a0\u2013 version 10.16.1000 and prior<\/li>\n\t<li>HPE Aruba Networking ArubaOS-CX Switches\u00a0\u2013 version 10.15.0005 and prior<\/li>\n\t<li>HPE Aruba Networking ArubaOS-CX Switches\u00a0\u2013 version 10.13.1080 and prior<\/li>\n\t<li>HPE Aruba Networking ArubaOS-CX Switches\u00a0\u2013 version 10.16.1000 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05062en_us&amp;docLocale=en_US \">HPESBNW05062 rev.1\u00a0- Status of OpenSSH Keystroke Obfuscation Bypass (CVE-2024-39894) on Aruba OS-CX<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05060en_us&amp;docLocale=en_US\">HPESBNW05060 rev.1\u00a0- HPE Telco Network Function Virtualization Orchestrator, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US \">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-543","alert_type":396,"serial_number":"AV26-543","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7784,"title":"[Control systems] ABB security advisory (AV26-545)","uuid":"6b5e8556-dac4-4ae7-8675-b201ad92c9a2","banner":null,"lang":"en","date_modified":"2026-06-03","date_modified_ts":"2026-06-03T13:01:01Z","date_created":"2026-06-03T12:40:20Z","summary":null,"body":["<article data-history-node-id=\"7784\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-545\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-545<br \/><strong>Date: <\/strong>June 3, 2026<\/p>\n\n<p>On June 3, 2026, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>T-MAC <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Plus<\/span>\u00a0\u2013 versions prior to 4.0-24.<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108472A7840&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">Vulnerabilities in T-MAC Plus (CVE-2025-14771, CVE-2025-14772, CVE2025-14773, CVE-2025-14774)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-545","alert_type":398,"serial_number":"AV26-545","subject":"abb","moderation_state":"published","external_url":null},{"nid":7783,"title":"Google Chrome security advisory (AV26-544)","uuid":"fd71d700-7a44-49d5-b24e-bd8a246d53e5","banner":null,"lang":"en","date_modified":"2026-06-03","date_modified_ts":"2026-06-03T12:49:19Z","date_created":"2026-06-03T12:40:20Z","summary":null,"body":["<article data-history-node-id=\"7783\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-544\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-544<br \/><strong>Date:<\/strong> June 3, 2026<\/p>\n\n<p>On June 2, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 149.0.7827.53\/54 (Windows\/Mac), and 149.0.7827.53 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-544","alert_type":396,"serial_number":"AV26-544","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7785,"title":"[Control Systems] Phoenix Contact\u00a0Security Advisory (AV26-546)","uuid":"59affe9e-33c2-4fd8-af36-6ccb8a15c0f9","banner":null,"lang":"en","date_modified":"2026-06-03","date_modified_ts":"2026-06-03T15:39:58Z","date_created":"2026-06-03T15:33:18Z","summary":null,"body":["<article data-history-node-id=\"7785\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-546\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number: <\/strong>AV26-546<br \/><strong>Date: <\/strong>June 3, 2026<\/p>\n\n<p>On June 3, 2026, Phoenix Contact published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>CHARX SEC-3150\u00a0\u2013 firmware version prior to 1.9.0<\/li>\n\t<li>CHARX SEC-3050\u00a0\u2013 firmware version prior to 1.9.0<\/li>\n\t<li>CHARX SEC-3000\u00a0\u2013 firmware version prior to 1.9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/assets.phoenixcontact.com\/file\/53de810a-f3f1-454e-b444-d215626d266c\/media\/original?pcsa-2026-00007_vde-2026-060.pdf \">VDE-2026-060: Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.phoenixcontact.com\/en-pc\/service-and-support\/psirt\">Phoenix Contact Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-546","alert_type":398,"serial_number":"AV26-546","subject":"other","moderation_state":"published","external_url":null},{"nid":7786,"title":"Cisco security advisory (AV26-547) \u2013 Update 1","uuid":"55ca4a28-609d-4470-b234-54018d677d37","banner":null,"lang":"en","date_modified":"2026-06-25","date_modified_ts":"2026-06-25T19:37:20Z","date_created":"2026-06-03T19:08:33Z","summary":null,"body":["<article data-history-node-id=\"7786\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-547\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-547<br \/><strong>Date:<\/strong> June 3, 2026<br \/><strong>Updated:<\/strong> June 25, 2026<\/p>\n\n<p>On June 3, 2026, Cisco published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Cisco Unified Communications Manager (CM) Release 14\u00a0\u2013 versions prior to 14SU6<\/li>\n\t<li>Cisco Unified Communications Manager (CM) Release 15\u00a0\u2013 versions prior to 15SU5 (Sep 2026) or COP<\/li>\n\t<li>Cisco Unified Communications Manager Session Management Edition (CM SME) release 14\u00a0\u2013 versions prior to 14SU6<\/li>\n\t<li>Cisco Unified Communications Manager Session Management Edition (CM SME) release 15\u00a0\u2013 versions prior to 15SU5 (Sep 2026) or COP<\/li>\n<\/ul><p>Cisco has indicated that a proof-of-concept exploit code is available for CVE-2026-20230.<\/p>\n\n<p><strong>Update 1<\/strong><br \/>\nOn June 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20230 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cucm-ssrf-cXPnHcW\">Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230\">CISA KEV: CVE-2026-20230<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-547","alert_type":396,"serial_number":"AV26-547","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7787,"title":"Broadcom VMware security advisory (AV26-548)","uuid":"65e0d510-4284-436c-af78-4792c6dbdb74","banner":null,"lang":"en","date_modified":"2026-06-03","date_modified_ts":"2026-06-03T19:49:24Z","date_created":"2026-06-03T19:35:35Z","summary":null,"body":["<article data-history-node-id=\"7787\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-548\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-548<br \/><strong>Date: <\/strong>June 3, 2026<\/p>\n\n<p>On June 2, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware Tanzu GemFire Management Console\u00a0- versions prior to 1.4.5<\/li>\n\t<li>VMware Tanzu Data Lake\u00a0- versions prior to 4.1.0<\/li>\n\t<li>VMware Tanzu for Postgres\u00a0- versions prior to 18.4.0<\/li>\n\t<li>VMware Tanzu for Postgres\u00a0- versions prior to 17.10.0<\/li>\n\t<li>VMware Tanzu for Postgres\u00a0- versions prior to 16.14.0<\/li>\n\t<li>VMware Tanzu for Postgres\u00a0- versions prior to 15.18.0<\/li>\n\t<li>VMware Tanzu for Postgres\u00a0- versions prior to 14.23.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37582\">Product Release Advisory\u00a0- VMware Tanzu GemFire Management Console<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37581\">Product Release Advisory\u00a0- VMware Tanzu Data Lake 4.1.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37580\">Product Release Advisory\u00a0- VMware Tanzu for Postgres 18.4.0, 17.10.0, 16.14.0, 15.18.0, 14.23.0<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-548","alert_type":396,"serial_number":"AV26-548","subject":"other","moderation_state":"published","external_url":null},{"nid":7788,"title":"SolarWinds security advisory (AV26-549) - Update 1","uuid":"6040f9de-fdbc-433f-a79c-6a1078c1c0dd","banner":null,"lang":"en","date_modified":"2026-06-05","date_modified_ts":"2026-06-05T18:02:32Z","date_created":"2026-06-04T18:49:26Z","summary":null,"body":["<article data-history-node-id=\"7788\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-549\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-549<br \/><strong>Date: <\/strong>June\u00a04, 2026<br \/><strong>Updated: <\/strong>June\u00a05, 2026<\/p>\n\n<p>Between June\u00a02 and 3, 2026, SolarWinds published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SolarWinds Serv-U\u00a0\u2013 versions prior to 15.5.4 HF1<\/li>\n\t<li>SolarWinds Web Help Desk\u00a0\u2013 versions prior to 2026.2<\/li>\n<\/ul><h2 class=\"h4\">Update 1<\/h2>\n\n<p>On June 5, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-28318 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2026-28299\">SolarWinds Web Help Desk Denial-of-Service Vulnerability (CVE-2026-28299)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2026-28318\">SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability (CVE-2026-28318)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318\">CISA KEV: CVE-2026-28318<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-549","alert_type":396,"serial_number":"AV26-549","subject":"other","moderation_state":"published","external_url":null},{"nid":7789,"title":"Docker security advisory (AV26-550)","uuid":"d4ff6dd8-51d9-41ef-b44e-3ce9330e1d84","banner":null,"lang":"en","date_modified":"2026-06-04","date_modified_ts":"2026-06-04T19:31:30Z","date_created":"2026-06-04T19:27:51Z","summary":null,"body":["<article data-history-node-id=\"7789\" about=\"\/en\/alerts-advisories\/docker-security-advisory-av26-550\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013550<br \/><strong>Date: <\/strong>June\u00a04, 2026<\/p>\n\n<p>On June\u00a01, 2026, Docker published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Docker Desktop\u00a0\u2013 versions prior to 4.76.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.docker.com\/desktop\/release-notes\/#4760\">Docker Desktop Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.docker.com\/security\/security-announcements\/\">Docker security announcements<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/docker-security-advisory-av26-550","alert_type":396,"serial_number":"AV26-550","subject":"other","moderation_state":"published","external_url":null},{"nid":7790,"title":"Cisco security advisory (AV26-551) - Update 1","uuid":"7010e9af-69a6-4a47-ba3a-7f481934995d","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T19:28:10Z","date_created":"2026-06-05T12:58:18Z","summary":null,"body":["<article data-history-node-id=\"7790\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-551\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-551<br \/><strong>Date:\u00a0<\/strong>June 5, 2026<br \/><strong>Updated:<\/strong> June 9, 2026<\/p>\n\n<p>On June 4, 2026, Cisco published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cisco Catalyst SD-WAN Manager<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On June 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20245 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-privesc-4uxFrdzx\">Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability (CVE-2026-20245)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20245\">CISA KEV: CVE-2026-20245<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-551","alert_type":396,"serial_number":"AV26-551","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7791,"title":"Progress security advisory (AV26-552) \u2013 Update 2","uuid":"25907d07-1c0a-4502-abfc-87ccec025f9f","banner":null,"lang":"en","date_modified":"2026-08-07","date_modified_ts":"2026-08-07T17:12:30Z","date_created":"2026-06-05T17:12:52Z","summary":null,"body":["<article data-history-node-id=\"7791\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-552\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-552<br \/><strong>Date: <\/strong>June 5, 2026<br \/><strong>Updated: <\/strong> Auguest 7, 2026<\/p>\n\n<p>Between June 2 and 4, 2026, Progress published security advisories to address vulnerabilities in the following products. Included was a critical update for the following:<\/p>\n\n<ul><li>Sitefinity CMS and Sitefinity Insight\u00a0\u2013 multiple versions<\/li>\n\t<li>Progress Kemp LoadMaster\u00a0\u2013 version GA v7.2.63.1 and prior<\/li>\n\t<li>Progress Kemp LoadMaster\u00a0- version LTSF v7.2.54.17 and prior<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-8037 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On August 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026\">Sitefinity Security Advisory for Addressing Security Vulnerabilities CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, May 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/community.progress.com\/s\/article\/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691\">LoadMaster Critical Security Bulletin \u2013 June 2026\u202f\u2013 (CVE-2026-8037, CVE-2026-33691)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.progress.com\/trust-center\">Progress Trust Center<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037\">CISA KEV: CVE-2026-8037<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-552","alert_type":396,"serial_number":"AV26-552","subject":"other","moderation_state":"published","external_url":null},{"nid":7792,"title":"IBM security advisory (AV26-553)","uuid":"5ccff8a8-f203-4099-9438-8a04f690e9fb","banner":null,"lang":"en","date_modified":"2026-06-08","date_modified_ts":"2026-06-08T13:50:54Z","date_created":"2026-06-08T13:44:38Z","summary":null,"body":["<article data-history-node-id=\"7792\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-553\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-553<br \/><strong>Date: <\/strong>June 8, 2026<\/p>\n\n<p>Between June 1 and 7, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Decision Optimization for Cloud Pak for Data \u2013 version 5.0 to 5.3.1 - Patch 2 releases<\/li>\n\t<li>DevOps Test UI (Test UI) \u2013 versions Test UI 11.0 to 11.0.6<\/li>\n\t<li>DevOps Test UI (Test UI) \u2013 versions Test UI 11.0 to 11.0.7<\/li>\n\t<li>FileNet Content Manager \u2013 multiple versions<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands - multiple versions<\/li>\n\t<li>IBM App Connect Operator \u2013 multiple versions<\/li>\n\t<li>IBM Automation Assets in IBM Cloud Pak for Integration (CP4I) \u2013 multiple versions<\/li>\n\t<li>IBM Big SQL on Cloud Pak for Data \u2013 multiple versions<\/li>\n\t<li>IBM Bob \u2013 versions 1.0.0, 1.0.1 and 1.0.2<\/li>\n\t<li>IBM Business Automation Insights \u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Workflow traditional and IBM Business Automation Workflow Enterprise Service Bus \u2013 multiple versions<\/li>\n\t<li>IBM Enterprise Content Management Text Search \u2013 multiple versions<\/li>\n\t<li>IBM ICP \u2013 Discovery \u2013 version 5.0.0 to 5.3.1<\/li>\n\t<li>IBM InfoSphere Optim Archive Viewer \u2013 versions 11.7.0.0 to 11.7.0.13<\/li>\n\t<li>IBM Maximo Application Suite - Visual Inspection Component \u2013 multiple versions<\/li>\n\t<li>IBM Maximo Application Suite \u2013 versions 9.0 and 9.1<\/li>\n\t<li>IBM Netezza Appliance \u2013 versions 1.0.0.0 and 1.0.0.1<\/li>\n\t<li>IBM Observability with Instana (OnPrem) \u2013 all versions<\/li>\n\t<li>IBM Platform Navigator in IBM Cloud Pak for Integration (CP4I) \u2013 multiple versions;<\/li>\n\t<li>IBM Security QRadar EDR \u2013 versions 3.12 to 3.12.24<\/li>\n\t<li>IBM Security SOAR \u2013 multiple versions<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services \u2013 versions 6.3.0 to 6.3.0.18<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services \u2013 versions 6.4.0 to 6.4.0.7<\/li>\n\t<li>IBM Sterling Connect:Direct for Microsoft Windows \u2013 versions 6.3.0.0 to 6.3.0.6_iFix050<\/li>\n\t<li>IBM Sterling Connect:Direct for Microsoft Windows \u2013 versions 6.4.0.0 to 6.4.0.4_iFix021<\/li>\n\t<li>IBM Storage Scale \u2013 versions 6.0.0.0 to 6.0.0.2<\/li>\n\t<li>IBM Storage Scale \u2013 versions 5.2.0.0 to 5.2.3.7<\/li>\n\t<li>IBM Verify Antenna \u2013 versions 25.05.0 to 26.03.0<\/li>\n\t<li>IBM Verify Identity Access Container \u2013 multiple versions<\/li>\n\t<li>IBM Verify Identity Access \u2013 multiple versions<\/li>\n\t<li>IBM WebSphere Application Server \u2013 versions 9.0 and 8.5<\/li>\n\t<li>IBM WebSphere Remote Server \u2013 versions 8.5, 9.0 and 9.1<\/li>\n\t<li>Jazz for Service Management \u2013 version 1.1.3 to 1.1.3.27<\/li>\n\t<li>Maximo AI Service \u2013 version 9.1.0<\/li>\n\t<li>QRadar AI Assistant \u2013 versions 1.0.0 to 1.5.0<\/li>\n\t<li>QRadar Log Source Management App \u2013 versions 1.0.0 to 7.0.14<\/li>\n\t<li>Rational Functional Tester (RFT) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-553","alert_type":396,"serial_number":"AV26-553","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7793,"title":"Dell security advisory (AV26-554)","uuid":"65875819-b495-4724-871d-baf8c8d88bf2","banner":null,"lang":"en","date_modified":"2026-06-08","date_modified_ts":"2026-06-08T13:58:08Z","date_created":"2026-06-08T13:53:07Z","summary":null,"body":["<article data-history-node-id=\"7793\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-554\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-554<br \/><strong>Date:<\/strong> June 8, 2026<\/p>\n\n<p>Between June 1 and 7, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Private Cloud -VMware \u2013 versions prior to 01.04.00.00<\/li>\n\t<li>PowerSwitch Z9864F-ON \u2013 versions prior to v3.5.0<\/li>\n\t<li>Dell Automation Platform \u2013 versions prior to 2.1.0.0<\/li>\n\t<li>Dell VxRail Appliance \u2013 versions prior to 8.0.390<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000472451\/dsa-2026-242-security-update-for-dell-private-cloud---vmware-for-multiple-third-party-component-vulnerabilities\">DSA-2026-242: Security Update for Dell Private Cloud - VMware for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000472774\/dsa-2026-252-security-update-for-dell-networking-products-for-ami-megarac-spx13\">DSA-2026-252: Security Update for Dell Networking Products for AMI MegaRAC SPx13<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000473583\/dsa-2026-244-security-update-for-dell-automation-platform-for-multiple-third-party-component-vulnerabilities\">DSA-2026-244: Security Update for Dell Automation Platform for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000473635\/dsa-2026-245-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities\">DSA-2026-245: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-554","alert_type":396,"serial_number":"AV26-554","subject":"dell","moderation_state":"published","external_url":null},{"nid":7794,"title":"Ubuntu security advisory (AV26-555)","uuid":"fb994023-3773-4280-a97a-ec70a0f0c7ab","banner":null,"lang":"en","date_modified":"2026-06-08","date_modified_ts":"2026-06-08T14:01:50Z","date_created":"2026-06-08T13:59:45Z","summary":null,"body":["<article data-history-node-id=\"7794\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-555\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-555<br \/><strong>Date:<\/strong> June 8, 2026<\/p>\n\n<p>Between June 1 and 7, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n\t<li>Ubuntu 26.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-555","alert_type":396,"serial_number":"AV26-555","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7795,"title":"[Control systems] CISA ICS security advisories (AV26\u2013556)","uuid":"45ca20e6-eea2-43a8-ab5a-dee3c5cf06bd","banner":null,"lang":"en","date_modified":"2026-06-08","date_modified_ts":"2026-06-08T14:06:51Z","date_created":"2026-06-08T14:03:04Z","summary":null,"body":["<article data-history-node-id=\"7795\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-556\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013556<br \/><strong>Date: <\/strong>June 8, 2026<\/p>\n\n<p>Between June 1 and 7, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>B&amp;R Industrial Automation GmbH PPT30 Operating System \u2013 versions prior to 1.8.0<\/li>\n\t<li>Hitachi Energy ITT600 Explorer \u2013 version prior to 2.1 SP6<\/li>\n\t<li>Hitachi Energy MACH HiDraw \u2013 version 9.22 and prior<\/li>\n\t<li>Hitachi Energy RTU500 \u2013 multiple versions<\/li>\n\t<li>NAVTOR NavBox \u2013 version 4.16.1.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-556","alert_type":398,"serial_number":"AV26-556","subject":"other","moderation_state":"published","external_url":null},{"nid":7796,"title":"Red Hat security advisory (AV26-557)","uuid":"713438d3-2ecf-45bb-ab0b-b57980daaeaa","banner":null,"lang":"en","date_modified":"2026-06-08","date_modified_ts":"2026-06-08T14:12:47Z","date_created":"2026-06-08T14:09:52Z","summary":null,"body":["<article data-history-node-id=\"7796\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-557\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-557<br \/><strong>Date:<\/strong> June 8, 2026<\/p>\n\n<p>Between June 1 and 7, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a class=\"external-link\" href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\" rel=\"nofollow noopener\" target=\"_blank\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-557","alert_type":396,"serial_number":"AV26-557","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7797,"title":"Spring security advisory (AV26-558)","uuid":"217c3437-8b1b-40eb-9a99-c13b556b4719","banner":null,"lang":"en","date_modified":"2026-06-08","date_modified_ts":"2026-06-08T14:18:37Z","date_created":"2026-06-08T14:13:45Z","summary":null,"body":["<article data-history-node-id=\"7797\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-558\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-558<br \/><strong>Date: <\/strong>June 9, 2026<\/p>\n\n<p>On June 8, 2026, Spring published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Micrometer\u00a0\/ Micrometer-core\u00a0\/ jetty11\u00a0\/ jetty12\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring LDAP\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Framework\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-40984\">CVE-2026-40984: Micrometer HTTP server instrumentations DoS vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-40983\">CVE-2026-40983: Micrometer gRPC server instrumentation DoS vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-41720\">CVE-2026-41720: Authentication Bypass with Empty Password in Spring LDAP<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-41842\">CVE-2026-41842: Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-558","alert_type":396,"serial_number":"AV26-558","subject":"other","moderation_state":"published","external_url":null},{"nid":7798,"title":"Check Point security advisory (AV26-559) - Update 1","uuid":"c47f5eb3-702f-4030-a1b7-9c1380eea990","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T12:06:36Z","date_created":"2026-06-08T14:19:58Z","summary":null,"body":["<article data-history-node-id=\"7798\" about=\"\/en\/alerts-advisories\/check-point-security-advisory-av26-559\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-559<br \/><strong>Date:<\/strong> June 8, 2026<br \/><strong>Updated:<\/strong> June 9, 2026<\/p>\n\n<p>On June 8, 2026, Check Point published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Mobile Access \/ SSL VPN, Remote Access VPN, Spark Firewall \u2013 multiple versions<\/li>\n\t<li>Security Gateways, Spark Firewall \u2013 multiple versions<\/li>\n<\/ul><p>Check Point has observed active exploitation of this vulnerability.<\/p>\n\n<h2 class=\"h4\">Update 1<\/h2>\n\n<p>On June 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-50751 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.checkpoint.com\/security\/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol\/\">Security Advisory \u2013 Action Required \u2013 Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/\">Check Point Security<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751\">CISA KEV: CVE-2026-50751<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/check-point-security-advisory-av26-559","alert_type":396,"serial_number":"AV26-559","subject":"other","moderation_state":"published","external_url":null},{"nid":7799,"title":"Broadcom VMware security advisory (AV26-560)","uuid":"f18652b5-4a2a-4ba1-aee0-2f4b6e84183f","banner":null,"lang":"en","date_modified":"2026-06-08","date_modified_ts":"2026-06-08T17:24:16Z","date_created":"2026-06-08T17:18:15Z","summary":null,"body":["<article data-history-node-id=\"7799\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-560\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-560<br \/><strong>Date: <\/strong>June 8, 2026<\/p>\n\n<p>On June 8, 2026, Broadcom published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>VMware Cloud Foundation \u2013 versions prior to 9.1.0.0<\/li>\n\t<li>VMware vSphere Foundation \u2013 versions prior to 9.1.0.0<\/li>\n\t<li>VMware Cloud Foundation \u2013 versions prior to 9.0.2.0 EP2<\/li>\n\t<li>VMware vSphere Foundation \u2013 versions prior to 9.0.2.0 EP2<\/li>\n\t<li>VMware Aria Operations \u2013 versions prior to 8.18.7<\/li>\n\t<li>VMware Aria Operations \u2013 versions prior to 8.18.6<\/li>\n\t<li>VMware Cloud Foundation \u2013 versions prior to 5.x<\/li>\n\t<li>VMware Telco Cloud Platform \u2013 versions prior to 5.x<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37513\">VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VC\">Security Advisories - VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-560","alert_type":396,"serial_number":"AV26-560","subject":"other","moderation_state":"published","external_url":null},{"nid":7801,"title":"Google Chrome security advisory (AV26-561) \u2013 Update 1","uuid":"be91d1c2-b088-427c-a719-13bdc1c7326f","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T17:51:05Z","date_created":"2026-06-09T12:12:31Z","summary":null,"body":["<article data-history-node-id=\"7801\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-561\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-561<br \/><strong>Date:<\/strong> June 9, 2026<\/p>\n\n<p>On June 8, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 149.0.7827.102\/.103 (Windows\/Mac), and 149.0.7827.102 (Linux)<\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2026-11645 exists in the wild.<\/p>\n\n<h2 class=\"h4\">Update 1<\/h2>\n\n<p>On June 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-11645 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_0153744567.html\">Google Chrome Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-11645 \">CISA KEV: CVE-2026-11645<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-561","alert_type":396,"serial_number":"AV26-561","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7802,"title":"SAP security advisory \u2013 June 2026 monthly rollup (AV26-562)","uuid":"0958319e-50ba-4524-865f-180e0d7be429","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T12:49:53Z","date_created":"2026-06-09T12:43:56Z","summary":null,"body":["<article data-history-node-id=\"7802\" about=\"\/en\/alerts-advisories\/sap-security-advisory-june-2026-monthly-rollup-av26-562\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-562<br \/><strong>Date:<\/strong> June 9, 2026<\/p>\n\n<p>On June 9, 2026, SAP published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>SAP NetWeaver AS ABAP and ABAP Platform\u00a0\u2013 versions SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 919<\/li>\n\t<li>SAP NetWeaver AS ABAP and ABAP Platform\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 722EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 91.9<\/li>\n\t<li>SAP Commerce Cloud and SAP Data Hub\u00a0\u2013 versions HY_COM 2205, HY_DHUB 2205, COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211<\/li>\n\t<li>SAP NetWeaver Application Server Java (Web Container)\u00a0\u2013 version ENGINEAPI 7.50<\/li>\n\t<li>SAP Commerce Cloud\u00a0\u2013 versions HY_COM 2205, COM_CLOUD 2211, 2211-JDK21<\/li>\n\t<li>SAP NetWeaver AS ABAP and ABAP Platform\u00a0\u2013 versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816<\/li>\n\t<li>ODP Data Replication APIs\u00a0\u2013 versions DW4CORE 200, 300, 400, PI_BASIS 2006_1_700, 701, 702, 731, 740, SAP_BW 750, 816<\/li>\n\t<li>SAP S\/4HANA\u00a0\u2013 versions S4FND 102, 103, 104, 105, 106, 107, 108, 109<\/li>\n\t<li>SAP NetWeaver AS Java (JDBC Test Servlet)\u00a0\u2013 version BI_UDI 7.50<\/li>\n\t<li>SAP Wily Introscope Enterprise Manager\u00a0\u2013 version WILY_INTRO_ENTERPRISE 10.8<\/li>\n\t<li>SAP MDG (Review Match Groups Application)\u00a0\u2013 versions S4CORE 108, SAP_BASIS 916, SAP_BASIS 917, SAP_ABA 816<\/li>\n\t<li>SAP Business Objects Business Intelligence Platform\u00a0\u2013 versions ENTERPRISE 430, 2025, 2027<\/li>\n\t<li>SAP Fiori (launchpad)\u00a0\u2013 versions SAP_UI 754, 755, 756, 757, 758, 816<\/li>\n\t<li>SAP Business Objects\u00a0\u2013 versions ENTERPRISE 430, 2025, 2027<\/li>\n\t<li>SAP NetWeaver AS Java\u00a0\u2013 versions SERVERCORE 7.50, CORE-TOOLS 7.50, J2EE-APPS 7.50<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/june-2026.html\">SAP Security Patch Day\u00a0- June 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-june-2026-monthly-rollup-av26-562","alert_type":396,"serial_number":"AV26-562","subject":"other","moderation_state":"published","external_url":null},{"nid":7803,"title":"Apache security advisory (AV26-563)","uuid":"37f65e6b-3e2c-4054-a636-2c1a593d1b09","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T12:54:52Z","date_created":"2026-06-09T12:51:20Z","summary":null,"body":["<article data-history-node-id=\"7803\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av26-563\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-563<br \/><strong>Date: <\/strong>June 9, 2026<\/p>\n\n<p>On June 8, 2026, Apache published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Apache HTTP Server\u00a0\u2013 versions prior to 2.4.68<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/httpd.apache.org\/security\/vulnerabilities_24.html\">Apache HTTP Server 2.4 vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/httpd.apache.org\/\">Apache http Server Project<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av26-563","alert_type":396,"serial_number":"AV26-563","subject":"other","moderation_state":"published","external_url":null},{"nid":7804,"title":"Veeam security advisory (AV26-564)","uuid":"a3762c6c-fbb7-401d-84c9-13ca538e77c9","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T12:59:00Z","date_created":"2026-06-09T12:55:29Z","summary":null,"body":["<article data-history-node-id=\"7804\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-564\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-564<br \/><strong>Date: <\/strong>June 9, 2026<\/p>\n\n<p>On June 9, 2026, Veeam published a security advisor to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Veeam Backup and Replication\u00a0\u2013 versions prior to 12.3.2.4854<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4869\">Vulnerability Resolved in Veeam Backup and Replication 12.3.2.4854<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html\">Veeam Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-564","alert_type":396,"serial_number":"AV26-564","subject":"other","moderation_state":"published","external_url":null},{"nid":7805,"title":"MISP security advisory (AV26-565)","uuid":"6a621f18-3198-4672-95da-c3a51268c799","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T13:03:17Z","date_created":"2026-06-09T12:59:34Z","summary":null,"body":["<article data-history-node-id=\"7805\" about=\"\/en\/alerts-advisories\/misp-security-advisory-av26-565\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-565<br \/><strong>Date: <\/strong>June 9, 2026<\/p>\n\n<p>On June 4, 2026, MISP published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MISP (Malware Information Sharing Platform)\u00a0\u2013 versions prior to v2.5.39<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/MISP\/MISP\/commit\/1be8c413b7104a889dfd30c5b1986e3ab17238e8\">MISP<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/MISP\/MISP\/releases\/tag\/v2.5.39\">MISP 2.5.39: New Dashboard Experience, Stronger STIX, Sharper Analyst Workflows<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/misp-security-advisory-av26-565","alert_type":396,"serial_number":"AV26-565","subject":"other","moderation_state":"published","external_url":null},{"nid":7806,"title":"[Control systems] Siemens security advisory (AV26-566)","uuid":"3ac25c84-0593-4ab2-a4b0-c1c7ab832a2a","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T14:18:59Z","date_created":"2026-06-09T14:14:00Z","summary":null,"body":["<article data-history-node-id=\"7806\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-566\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-566<br \/><strong>Date:<\/strong> June 9, 2026<\/p>\n\n<p>On June 9, 2026, Siemens published a security advisory to address vulnerabilities in the following products. Included were updates for the following products:<\/p>\n\n<ul><li>SINEC INS \u2013 versions prior to V1.0 SP2 Update 6<\/li>\n\t<li>Siemens Products \u2013 multiple versions and models<\/li>\n\t<li>SIPROTEC 5 - CP100 \/ CP150 \/ CP200 \/ CP300 \/ Devices \u2013 all versions<\/li>\n\t<li>SIPROTEC 5 Compact 7SX800 (CP050) \u2013 all versions<\/li>\n\t<li>Totally Integrated Automation Portal (TIA Portal) \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-860189.html\">SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-434797.html\">SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-139483.html\">SSA-139483: File Upload Vulnerability in SIPROTEC 5 Using DIGSI5 Protocol<\/a><\/li>\n\t<li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-063511.html\">SSA-063511: Insufficient protection of key material in WinCC Certificate Manager<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-566","alert_type":398,"serial_number":"AV26-566","subject":"siemens","moderation_state":"published","external_url":null},{"nid":7807,"title":"Ivanti security advisory (AV26-567) \u2013 Update 1","uuid":"c4868d2a-a797-43d3-85a9-00417b8665d7","banner":null,"lang":"en","date_modified":"2026-06-11","date_modified_ts":"2026-06-11T19:07:06Z","date_created":"2026-06-09T15:25:07Z","summary":null,"body":["<article data-history-node-id=\"7807\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-567\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-567<br \/><strong>Date: <\/strong>June 9, 2026<br \/><strong>Updated: <\/strong>June 11, 2026<\/p>\n\n<p>On June 9, 2026, Ivanti published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Ivanti Sentry \u2013 versions 10.5.1, 10.6.1, 10.7.0 and prior<\/li>\n\t<li>Ivanti Endpoint Manager Mobile \u2013 versions 12.9.0, 12.8.0.2, 12.7.0.1 and prior<\/li>\n<\/ul><h2 class=\"h4\">Update 1<\/h2>\n\n<p>On June 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-10520 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US\">Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)<\/a><\/li>\n\t<li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-6973-CVE-2026-10727?language=en_US\">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-6973 and CVE-2026-10727)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 \">CISA KEV: CVE-2026-10520<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-567","alert_type":396,"serial_number":"AV26-567","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7809,"title":"Fortinet security advisory (AV26-568) \u2013 Update 1","uuid":"8bb0623f-903b-40dd-8ac5-c67257267c8d","banner":null,"lang":"en","date_modified":"2026-07-16","date_modified_ts":"2026-07-16T19:01:50Z","date_created":"2026-06-09T15:26:08Z","summary":null,"body":["<article data-history-node-id=\"7809\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-568\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-568<br \/><strong>Date: <\/strong>June 9, 2026<br \/><strong>Updated: <\/strong>July 16, 2026<\/p>\n\n<p>On June 9, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>FortiSandbox 5.0 \u2013 versions 5.0.0 to 5.0.5<\/li>\n\t<li>FortiSandbox 4.4 \u2013 versions 4.4.0 to 4.4.8<\/li>\n\t<li>FortiSandbox Cloud 5.0 \u2013 versions 5.0.4 to 5.0.5<\/li>\n\t<li>FortiSandbox PaaS 5.0 \u2013 versions 5.0.4 through 5.0.5<\/li>\n<\/ul><h2 class=\"h3\">\n  Update 1\n<\/h2>\n\n<p>\n  On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-25089 to their Known Exploited Vulnerabilities (KEV) Database.\n<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-141\">Second-Order OS Command Injection via JSON Input on start vnc feature<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n  <li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089\">CISA KEV: CVE-2026-25089<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-568","alert_type":396,"serial_number":"AV26-568","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7816,"title":"Microsoft security advisory \u2013 June 2026 monthly rollup (AV26-569)","uuid":"85e86c94-231c-4cf2-86c9-ef5eecea6c22","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T18:53:14Z","date_created":"2026-06-09T18:41:41Z","summary":null,"body":["<article data-history-node-id=\"7816\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-june-2026-monthly-rollup-av26-569\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-569<br \/><strong>Date: <\/strong>June 9, 2026<\/p>\n\n<p>On June 9, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>.NET 10.0<\/li>\n\t<li>.NET 8.0<\/li>\n\t<li>.NET 9.0<\/li>\n\t<li>ASP.NET<\/li>\n\t<li>Azure Connected Machine Agent<\/li>\n\t<li>Azure HorizonDB<\/li>\n\t<li>Azure Kubernetes Service<\/li>\n\t<li>Azure Local<\/li>\n\t<li>Azure Logic Apps<\/li>\n\t<li>Azure Machine Learning<\/li>\n\t<li>Azure Monitor Agent<\/li>\n\t<li>Azure Monitor Agent Metrics Extension<\/li>\n\t<li>Azure Orbital Spatio<\/li>\n\t<li>Azure Privileged Identity Management (PIM)<\/li>\n\t<li>Azure Resource Manager<\/li>\n\t<li>Azure SDK<\/li>\n\t<li>Azure Stack Edge<\/li>\n\t<li>Azure Stack HCI<\/li>\n\t<li>Azure Virtual Network Gateway<\/li>\n\t<li>Copilot Chat<\/li>\n\t<li>Linux kernel\u00a0- Microsoft MANA Network Driver<\/li>\n\t<li>M365 Copilot for Desktop<\/li>\n\t<li>Microsoft .NET Framework<\/li>\n\t<li>Microsoft 365<\/li>\n\t<li>Microsoft 365 Copilot<\/li>\n\t<li>Microsoft Authenticator<\/li>\n\t<li>Microsoft Bing<\/li>\n\t<li>Microsoft Confluence SAML SSO plugin<\/li>\n\t<li>Microsoft Data Formulator<\/li>\n\t<li>Microsoft Defender for Endpoint for Mac<\/li>\n\t<li>Microsoft Dynamics 365<\/li>\n\t<li>Microsoft Edge<\/li>\n\t<li>Microsoft Entra ID<\/li>\n\t<li>Microsoft Excel<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Online<\/li>\n\t<li>Microsoft Exchange Server<\/li>\n\t<li>Microsoft Global Secure Access (GSA)<\/li>\n\t<li>Microsoft Graph<\/li>\n\t<li>Microsoft JIRA SAML SSO plugin<\/li>\n\t<li>Microsoft Live Share Canvas SDK<\/li>\n\t<li>Microsoft Malware Protection Engine<\/li>\n\t<li>Microsoft Office<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office 365<\/li>\n\t<li>Microsoft Office LTSC<\/li>\n\t<li>Microsoft Outlook for iOS<\/li>\n\t<li>Microsoft PC Manager<\/li>\n\t<li>Microsoft Planetary Computer Pro (GeoCatalog)<\/li>\n\t<li>Microsoft Power Pages<\/li>\n\t<li>Microsoft PowerPoint for Android<\/li>\n\t<li>Microsoft PowerToys<\/li>\n\t<li>Microsoft SQL Server 2016<\/li>\n\t<li>Microsoft SQL Server 2017<\/li>\n\t<li>Microsoft SQL Server 2019<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SQL Server 2025<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft Teams<\/li>\n\t<li>Microsoft Visual Studio<\/li>\n\t<li>Microsoft Visual Studio 2026<\/li>\n\t<li>Microsoft Word<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Nuance PowerScribe 360<\/li>\n\t<li>Nuance PowerScribe One<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Power Automate for Desktop<\/li>\n\t<li>PowerScribe One<\/li>\n\t<li>Remote Desktop client<\/li>\n\t<li>Visual Studio<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Admin Center<\/li>\n\t<li>Windows Admin Center in Azure Portal<\/li>\n\t<li>Windows App Client<\/li>\n\t<li>Windows Narrator Braille<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Jun \">June 2026 Security Updates<\/a><\/li>\n<\/ul><p>&lt;<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-june-2026-monthly-rollup-av26-569","alert_type":396,"serial_number":"AV26-569","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7817,"title":"Adobe security advisory (AV26-570)","uuid":"53026a18-cbdb-470b-967a-ca5c6becf6b9","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T18:59:15Z","date_created":"2026-06-09T18:53:58Z","summary":null,"body":["<article data-history-node-id=\"7817\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-570\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-570<br \/><strong>Date: <\/strong>June 9, 2026<\/p>\n\n<p>On June 9, 2026, Adobe published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Experience Manager (AEM)\u00a0\u2013 version AEM Cloud Service (CS)<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 version 6.5 LTS SP1 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0\u2013 version SP24 and prior<\/li>\n\t<li>Adobe Experience Manager 6.5 LTS\u00a0\u2013 version SP1 and prior<\/li>\n\t<li>Adobe Experience Manager 6.5\u00a0\u2013 version 6.5.24.0 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID21.3 and prior<\/li>\n\t<li>Adobe InDesign\u00a0\u2013 version ID20.5.3 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 21.3 and prior<\/li>\n\t<li>Adobe InCopy\u00a0\u2013 version 20.5.3 and prior<\/li>\n\t<li>Adobe Substance 3D Sampler\u00a0\u2013 version 6.0.0 and prior<\/li>\n\t<li>Content Credentials JS SDK\u00a0\u2013 version @contentauth\/c2pa-web@0.8.3 and prior<\/li>\n\t<li>Content Credentials Rust SDK\u00a0\u2013 version c2pa-v0.85.1 and prior<\/li>\n\t<li>Adobe Dreamweaver\u00a0\u2013 version 21.7 and prior<\/li>\n\t<li>Adobe Acrobat\u00a0\u2013 version 26.001.21651 and prior<\/li>\n\t<li>Adobe Reader\u00a0\u2013 version 26.001.21651 and prior<\/li>\n\t<li>Adobe 2024\u00a0\u2013 version 24.001.30365 and prior<\/li>\n\t<li>Adobe ColdFusion 2025\u00a0\u2013 Update 8 and prior<\/li>\n\t<li>Adobe ColdFusion 2023\u00a0\u2013 Update 19 and prior<\/li>\n\t<li>Adobe Format Plugins\u00a0\u2013 version 1.1.52 and prior<\/li>\n\t<li>Adobe Campaign Classic\u00a0\u2013 version ACC v7: 7.4.3 build 9394 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-570","alert_type":396,"serial_number":"AV26-570","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7818,"title":"HPE security advisory (AV26-571)","uuid":"fd7280ef-77c8-4c5f-b3c1-1a691bea8e9a","banner":null,"lang":"en","date_modified":"2026-06-09","date_modified_ts":"2026-06-09T19:03:41Z","date_created":"2026-06-09T18:59:59Z","summary":null,"body":["<article data-history-node-id=\"7818\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-571\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-571<br \/><strong>Date: <\/strong>June 9, 2026<\/p>\n\n<p>On June 9, 2026, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Aruba Networking Management Software (Airwave)\u00a0\u2013 version 8.3.0.6 and prior<\/li>\n\t<li>HPE Aruba Networking Private 5G Management Dashboard\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05064en_us&amp;docLocale=en_US#hpesbnw05064-rev-1-status-of-nginx-ngx_http_rewrit-0\">HPESBNW05064 rev.1\u00a0- Status of NGINX ngx_http_rewrite_module Vulnerability (CVE-2026-42945) in HPE Aruba Networking Products<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-571","alert_type":396,"serial_number":"AV26-571","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7830,"title":"Spring security advisory (AV26-574)","uuid":"81189165-251e-46b9-bbb4-4e46e3f64e45","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T14:29:05Z","date_created":"2026-06-10T13:51:14Z","summary":null,"body":["<article data-history-node-id=\"7830\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-574\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-574<br \/><strong>Date: <\/strong>June\u00a010, 2026<\/p>\n\n<p>Between June\u00a09 and 10, 2026, Spring published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Spring AMQP\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Authorization Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Web Services\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Web Flow\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring REST Docs\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data Commons\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data Relational\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Security\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data MongoDB\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data JDBC\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data KeyValue\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data R2DBC\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data Redis\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data REST\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring for Apache Kafka\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring for Apache Pulsar\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Data Commons (transitively affects all Spring Data store modules)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-574","alert_type":396,"serial_number":"AV26-574","subject":"other","moderation_state":"published","external_url":null},{"nid":7829,"title":"HPE security advisory (AV26-573)","uuid":"66bc2478-a487-4e82-8030-11ea9343148e","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T14:23:28Z","date_created":"2026-06-10T13:51:14Z","summary":null,"body":["<article data-history-node-id=\"7829\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-573\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-573<br \/><strong>Date: <\/strong>June\u00a010, 2026<\/p>\n\n<p>On June\u00a09, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE ProLiant RL300 Gen11\u00a0\u2013 versions prior to 1.84_04-02-2026<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf05057en_us&amp;docLocale=en_US\">HPESBHF05057 rev.1\u00a0- HPE RL300 Server Using Arm Processors, Local Disclosure of Privileged Information<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-573","alert_type":396,"serial_number":"AV26-573","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7828,"title":"OpenSSL security advisory (AV26-572)","uuid":"c95cc4a4-2b0f-488c-94bf-a54a00fc8423","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T14:18:42Z","date_created":"2026-06-10T13:51:14Z","summary":null,"body":["<article data-history-node-id=\"7828\" about=\"\/en\/alerts-advisories\/openssl-security-advisory-av26-572\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-572<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a09, 2026, OpenSSL published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSL\u00a0\u2013 versions 4.0.0 to versions prior to 4.0.1<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.6.0 to versions prior to 3.6.3<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.5.0 to versions prior to 3.5.7<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.4.0 to versions prior to 3.4.6<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 3.0.0 to versions prior to 3.0.21<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 1.1.1 to versions prior to 1.1.1zh<\/li>\n\t<li>OpenSSL\u00a0\u2013 versions 1.0.2 to versions prior to 1.0.2zq<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/index.html\">OpenSSL Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory-av26-572","alert_type":396,"serial_number":"AV26-572","subject":"other","moderation_state":"published","external_url":null},{"nid":7831,"title":"Mozilla security advisory (AV26-575)","uuid":"5a214f68-eaf5-4858-aec8-13675e9cc86c","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T14:34:58Z","date_created":"2026-06-10T13:51:14Z","summary":null,"body":["<article data-history-node-id=\"7831\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-575\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-575<br \/><strong>Date: <\/strong>June\u00a010, 2026<\/p>\n\n<p>On June\u00a09, 2026, Mozilla published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Focus for iOS\u00a0\u2013 versions prior to 151.3.1<\/li>\n\t<li>Klar for iOS\u00a0\u2013 versions prior to 151.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-55\/\">Mozilla Foundation Security Advisory 2026-55<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-575","alert_type":396,"serial_number":"AV26-575","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7833,"title":"AMD security advisory (AV26-577)","uuid":"326de16f-cba5-45fc-b4de-3ea714533991","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T14:54:16Z","date_created":"2026-06-10T13:51:15Z","summary":null,"body":["<article data-history-node-id=\"7833\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-577\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-577<br \/><strong>Date: <\/strong>June\u00a010, 2026<\/p>\n\n<p>On June\u00a09, 2025, AMD published security advisories to address vulnerabilities in multiple products.<\/p>\n\n<ul><li>Versal Prime Series Gen 2<\/li>\n\t<li>Versal AI Edge Series Gen 2<\/li>\n\t<li>AMD Management Console (AMC)\u00a0\u2013 versions prior to 14.0.0<\/li>\n\t<li>AMD Ryzen Master\u00a0\u2013 versions prior to 2.14.3<\/li>\n\t<li>AMD \u00b5Prof\u00a0\u2013 versions prior to 5.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-8021.html\">ARM CPU Vulnerability: Bypass of Stage 1 translation, Stage-2 translation, or GPT Protection<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-9027.html\">AMD Auto Updater Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-577","alert_type":396,"serial_number":"AV26-577","subject":"other","moderation_state":"published","external_url":null},{"nid":7832,"title":"FreeBSD security advisory (AV26-576)","uuid":"5cf94a8b-c93b-4d65-a259-de48c4467fd6","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T14:43:44Z","date_created":"2026-06-10T13:51:15Z","summary":null,"body":["<article data-history-node-id=\"7832\" about=\"\/en\/alerts-advisories\/freebsd-security-advisory-av26-576\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-576<br \/><strong>Date: <\/strong>June\u00a010, 2026<\/p>\n\n<p>On June\u00a09, 2026, FreeBSD published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>FreeBSD\u00a0\u2013 all supported versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.freebsd.org\/security\/advisories\/\">FreeBSD Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freebsd-security-advisory-av26-576","alert_type":396,"serial_number":"AV26-576","subject":"other","moderation_state":"published","external_url":null},{"nid":7843,"title":"[Control systems] ABB security advisory (AV26-580)","uuid":"399c583f-8ce3-4481-ae28-4ac45e669b16","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T17:29:34Z","date_created":"2026-06-10T17:17:30Z","summary":null,"body":["<article data-history-node-id=\"7843\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-580\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-580<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a010, 2026, ABB published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>PPC3100\u00a0\u2013 versions prior to 1.8.1<\/li>\n\t<li>C50\u00a0\u2013 versions prior to 1.8.0<\/li>\n\t<li>C80\u00a0\u2013 versions prior to 1.8.0<\/li>\n\t<li>FT50\u00a0\u2013 versions prior to 1.8.1<\/li>\n\t<li>MT50\u00a0\u2013 versions prior to 1.8.1<\/li>\n\t<li>T30\u00a0\u2013 versions prior to 1.8.0<\/li>\n\t<li>T80\u00a0\u2013 versions prior to 1.8.0<\/li>\n\t<li>T50\u00a0\u2013 versions prior to 1.8.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/br-cws-assets.de-fra-1.linodeobjects.com\/SA26P009-b2b4dd6d.pdf\">XZ Utils vulnerability impacting B&amp;R Products CVE ID: CVE-2025-31115 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-580","alert_type":398,"serial_number":"AV26-580","subject":"abb","moderation_state":"published","external_url":null},{"nid":7842,"title":"FreePBX security advisory (AV26\u2013579)","uuid":"66694feb-1ae2-43f0-bb7c-1a1aeff0ae65","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T17:24:19Z","date_created":"2026-06-10T17:17:30Z","summary":null,"body":["<article data-history-node-id=\"7842\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-579\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26\u2013579<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a010, 2026, FreePBX published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>FreePBX Security-Reporting music (FreePBX 16)\u00a0\u2013 versions 16.0.4 and prior<\/li>\n\t<li>FreePBX Security-Reporting music (FreePBX 17)\u00a0\u2013 versions 17.0.6 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-4g6v-whq9-944g\">Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories?state=published\">FreePBX Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-579","alert_type":396,"serial_number":"AV26-579","subject":"other","moderation_state":"published","external_url":null},{"nid":7841,"title":"Jenkins security advisory (AV26-578)","uuid":"81516abd-b4b9-4306-ae83-354e29689bc8","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T17:20:18Z","date_created":"2026-06-10T17:17:30Z","summary":null,"body":["<article data-history-node-id=\"7841\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-578\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-578<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a010, 2026, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins weekly\u00a0\u2013 version 2.567 and prior<\/li>\n\t<li>Jenkins LTS\u00a0\u2013 version 2.555.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-06-10\/\">Jenkins Security Advisory 2026-06-10<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-578","alert_type":396,"serial_number":"AV26-578","subject":"other","moderation_state":"published","external_url":null},{"nid":7844,"title":"Erlang security advisory (AV26-581)","uuid":"74f7d30b-c0c6-4b23-99fe-313eb82e0816","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T17:39:07Z","date_created":"2026-06-10T17:17:34Z","summary":null,"body":["<article data-history-node-id=\"7844\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av26-581\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-581<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a010, 2026, Erlang published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>OTP\u00a0\u2013 versions prior to 27.3.4.13, 28.5.0.2 and 29.0.2<\/li>\n\t<li>erts (OTP)\u00a0\u2013 versions prior to 15.2.7.9, 16.4.0.2 and 17.0.2<\/li>\n\t<li>inets (otp)\u00a0\u2013 versions prior to 9.7.1, 9.6.2.2 and 9.3.2.6<\/li>\n\t<li>ssl (OTP)\u00a0\u2013 versions prior to 11.7.2, 11.6.0.2 and 11.2.12.9<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-6f4f-chj5-5g97\">Unbounded Stack Buffer Overflow in SCTP Error Cause Parsing in inet_drv<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-gp7x-mfv6-52cv\">Distribution-over-TLS LAN Allowlist is Silently Bypassed<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-m75x-4vwg-ggjh\">httpc leaks Authorization header to cross-origin redirect targets<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\">Erlang Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av26-581","alert_type":396,"serial_number":"AV26-581","subject":"other","moderation_state":"published","external_url":null},{"nid":7854,"title":"n8n security advisory (AV26-584)","uuid":"5341efe6-d06d-4a44-aac2-60f2bdefed03","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T18:12:08Z","date_created":"2026-06-10T17:45:50Z","summary":null,"body":["<article data-history-node-id=\"7854\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-584\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-584<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a010, 2026, n8n published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>n8n (Credential Exfiltration)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (Cross-Tenant Credential)\u00a0\u2013 multiple versions<\/li>\n\t<li>n8n (n8n MCP Browser)\u00a0\u2013 versions 2.26.2 to 2.25.7<\/li>\n\t<li>n8n(SecurityScorecard Node)\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-pmqw-72cg-wx85\">Credential Exfiltration via Permission Bypass<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-2j5h-858j-5mpf\">Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-qrx8-25qr-5r7v\">n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-rm2v-h48j-895m\">SecurityScorecard Node Leaks API Token to User-Controlled Host<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-584","alert_type":396,"serial_number":"AV26-584","subject":"other","moderation_state":"published","external_url":null},{"nid":7853,"title":"Palo Alto Networks security advisory (AV26-583)","uuid":"2e8d4c00-14d3-4d15-9bd2-907012c86b41","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T18:06:32Z","date_created":"2026-06-10T17:45:50Z","summary":null,"body":["<article data-history-node-id=\"7853\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-583\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-483<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a010, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cortex XSIAM CommvaultSecurityIQ Marketplace 1.1.0\u00a0\u2013 versions prior to 1.2.0<\/li>\n\t<li>Cortex XSOAR CommvaultSecurityIQ Marketplace 1.1.0\u00a0\u2013 versions prior to 1.2.0<\/li>\n\t<li>Prisma Browser\u00a0\u2013 versions prior to 148.18.4.217<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0274\">CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2026-0008\">PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June\u00a02026)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-583","alert_type":396,"serial_number":"AV26-583","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7852,"title":"HPE security advisory (AV26-582)","uuid":"b7fb68f0-5960-4122-b5b2-1a4dedc4c42f","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T18:01:52Z","date_created":"2026-06-10T17:45:50Z","summary":null,"body":["<article data-history-node-id=\"7852\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-582\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-582<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a010, 2026, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Telco Suite\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05061en_us&amp;docLocale=en_US\">HPESBNW05061 rev.1\u00a0- HPE Telco Suite, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-582","alert_type":396,"serial_number":"AV26-582","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7855,"title":"Broadcom VMware security advisory (AV26-585)","uuid":"5b78f2fd-bc2b-4336-ba21-23e7b742b90b","banner":null,"lang":"en","date_modified":"2026-06-10","date_modified_ts":"2026-06-10T18:41:12Z","date_created":"2026-06-10T18:37:04Z","summary":null,"body":["<article data-history-node-id=\"7855\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-585\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-585<br \/><strong>Date:<\/strong> June\u00a010, 2026<\/p>\n\n<p>On June\u00a09, 2026, Broadcom published a security advisory to address vulnerabilities in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>VMware Tanzu for Valkey on Kubernetes\u00a0\u2013 versions prior to 3.4.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37636\">Product Release Advisory\u00a0- VMware Tanzu for Valkey on Kubernetes 3.4.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-585","alert_type":396,"serial_number":"AV26-585","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7857,"title":"Splunk security advisory (AV26-586) \u2013 Update 1","uuid":"d5f541a1-40d0-4c7a-b57b-b586cf354f27","banner":null,"lang":"en","date_modified":"2026-06-18","date_modified_ts":"2026-06-18T17:15:42Z","date_created":"2026-06-10T19:09:10Z","summary":null,"body":["<article data-history-node-id=\"7857\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-586\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-586<br \/><strong>Date: <\/strong>June\u00a010, 2026<br \/><strong>Updated: <\/strong>June\u00a018, 2026<\/p>\n\n<p>On June\u00a010, 2026, Splunk published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Splunk SOAR\u00a0\u2013 versions prior to 8.5.0<\/li>\n\t<li>Splunk Enterprise\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On June 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20253 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/\">Splunk Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20253\">CISA KEV: CVE-2026-20253<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-586","alert_type":396,"serial_number":"AV26-586","subject":"other","moderation_state":"published","external_url":null},{"nid":7858,"title":"Oracle security advisory (AV26-587) \u2013 Update 1","uuid":"7d688794-f783-496f-819b-40f23ca15a5a","banner":null,"lang":"en","date_modified":"2026-06-12","date_modified_ts":"2026-06-12T18:03:41Z","date_created":"2026-06-11T13:43:04Z","summary":null,"body":["<article data-history-node-id=\"7858\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-av26-587\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-587<br \/><strong>Date:<\/strong> June\u00a011, 2026<br \/><strong>Updated:<\/strong> June 12, 2026<\/p>\n\n<p>On June\u00a010, 2026, Oracle published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>PeopleSoft Enterprise PeopleTools\u00a0\u2013 versions 8.61 and 8.62<\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-35273 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On June 12, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-35273 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-tp-lg\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/alert-cve-2026-35273.html\">Oracle Security Alert Advisory\u00a0- CVE-2026-35273<\/a><\/li>\n\t<li><a href=\"https:\/\/www.oracle.com\/security-alerts\/\">Oracle Critical Patch Updates, Security Alerts and Bulletins<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273\">CISA KEV: CVE-2026-35273<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-av26-587","alert_type":396,"serial_number":"AV26-587","subject":"oracle","moderation_state":"published","external_url":null},{"nid":7859,"title":"GitLab security advisory (AV26-588)","uuid":"10a49c5d-0506-4b26-958d-6a0252871441","banner":null,"lang":"en","date_modified":"2026-06-11","date_modified_ts":"2026-06-11T14:11:00Z","date_created":"2026-06-11T13:43:05Z","summary":null,"body":["<article data-history-node-id=\"7859\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-588\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-588<br \/><strong>Date:<\/strong> June\u00a011, 2026<\/p>\n\n<p>On June\u00a010, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 19.0.2, 18.11.5 and 18.10.8<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 19.0.2, 18.11.5 and 18.10.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-0-2-released\/\">GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-588","alert_type":396,"serial_number":"AV26-588","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7860,"title":"Ubiquiti security advisory (AV26-589)","uuid":"710cc4bb-f75a-4720-9ec6-72f595f9276d","banner":null,"lang":"en","date_modified":"2026-06-11","date_modified_ts":"2026-06-11T18:28:15Z","date_created":"2026-06-11T18:23:40Z","summary":null,"body":["<article data-history-node-id=\"7860\" about=\"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-589\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-589<br \/><strong>Date: <\/strong>June 11, 2026<\/p>\n\n<p>On June 10, 2026, Ubiquiti published a security advisory to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>UID Enterprise Agent\u00a0\u2013 version 1.61.3 and prior<\/li>\n\t<li>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber\u00a0\u2013 version 5.1.12 and prior<\/li>\n\t<li>UniFi OS Server\u00a0\u2013 version 5.0.8 and prior<\/li>\n\t<li>UDM-Beast\u00a0\u2013 version 5.1.11 and prior<\/li>\n\t<li>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8\u00a0\u2013 version 5.1.10 and prior<\/li>\n\t<li>Express\u00a0\u2013 version 4.0.14 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.ui.com\/releases\/Security-Advisory-Bulletin-065-065\/aa46a22b-fc43-4eae-9382-6fc8feda967a\">Ubiquiti UniFi\u00a0- Security Advisory Bulletin 065<\/a><\/li>\n\t<li><a href=\"https:\/\/community.ui.com\/releases\">Ubiquiti UniFi Security Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-589","alert_type":396,"serial_number":"AV26-589","subject":"other","moderation_state":"published","external_url":null},{"nid":7861,"title":"Check Point security advisory (AV26-590)","uuid":"8402e22c-c8cd-40d2-a5da-6f8706dc100d","banner":null,"lang":"en","date_modified":"2026-06-11","date_modified_ts":"2026-06-11T18:32:02Z","date_created":"2026-06-11T18:29:05Z","summary":null,"body":["<article data-history-node-id=\"7861\" about=\"\/en\/alerts-advisories\/check-point-security-advisory-av26-590\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-590<br \/><strong>Date: <\/strong>June 11, 2026<\/p>\n\n<p>On June 11, 2026, Check Point published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Identity Agent\u00a0\u2013 versions prior to 81.087.0000<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185052\">Check Point Response to CVE-2026-10847- Identity Agent Local Privilege Escalation Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/\">Check Point Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/check-point-security-advisory-av26-590","alert_type":396,"serial_number":"AV26-590","subject":"other","moderation_state":"published","external_url":null},{"nid":7862,"title":"Microsoft Edge security advisory (AV26-591)","uuid":"8f22e98c-7428-40cb-adc0-578863481eb8","banner":null,"lang":"en","date_modified":"2026-06-12","date_modified_ts":"2026-06-12T13:37:46Z","date_created":"2026-06-12T13:36:16Z","summary":null,"body":["<article data-history-node-id=\"7862\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-591\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-591<br \/><strong>Date:<\/strong> June 12, 2026<\/p>\n\n<p>On June 9, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 149.0.4022.62<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2026-11645 has an available exploit.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-9-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-591","alert_type":396,"serial_number":"AV26-591","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7863,"title":"Spring security advisory (AV26-592)","uuid":"a997535a-15b3-4a7f-a5e5-d7001e71c008","banner":null,"lang":"en","date_modified":"2026-06-12","date_modified_ts":"2026-06-12T13:46:17Z","date_created":"2026-06-12T13:43:12Z","summary":null,"body":["<article data-history-node-id=\"7863\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-592\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-592<br \/><strong>Date: <\/strong>June 12, 2026<\/p>\n\n<p>Between June 10 and 11, 2026, Spring published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Spring Cloud Sleuth\u00a0\u2013 versions 3.1.0 to 3.1.13<\/li>\n\t<li>Spring Statemachine\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Cloud Gateway\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring Integration\u00a0\u2013 multiple versions<\/li>\n\t<li>Spring for GraphQL\u00a0\u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\">Spring Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-592","alert_type":396,"serial_number":"AV26-592","subject":"other","moderation_state":"published","external_url":null},{"nid":7864,"title":"Google Chrome security advisory (AV26-593)","uuid":"da1d62cd-d891-43b5-b8a2-191473a86a63","banner":null,"lang":"en","date_modified":"2026-06-12","date_modified_ts":"2026-06-12T13:55:51Z","date_created":"2026-06-12T13:53:42Z","summary":null,"body":["<article data-history-node-id=\"7864\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-593\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-593<br \/><strong>Date:<\/strong> June 12, 2026<\/p>\n\n<p>On June 11, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 149.0.7827.114\/115\u00a0(Windows\/Mac), and 149.0.7827.114 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_01962725236.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-593","alert_type":396,"serial_number":"AV26-593","subject":"other","moderation_state":"published","external_url":null},{"nid":7865,"title":"[Control Systems] Moxa security advisory (AV26-594)","uuid":"3c13cb89-3b35-4e47-8fe6-e8e58d7edcb3","banner":null,"lang":"en","date_modified":"2026-06-12","date_modified_ts":"2026-06-12T14:09:11Z","date_created":"2026-06-12T14:06:13Z","summary":null,"body":["<article data-history-node-id=\"7865\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-594\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-594<br \/><strong>Date: <\/strong>June 12, 2026<\/p>\n\n<p>On June 12, 2026, Moxa published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>UC-1200A\u00a0\/ UC-2200A \/UC-3400A \/UC-4400A \/UC-8200 series\u2013 multiple versions and models<\/li>\n\t<li>V1200 Series\u00a0\u2013 version v1.2.0 and prior<\/li>\n\t<li>V3200\u00a0\/ V3400 series\u00a0\u2013 version v1.1 and prior<\/li>\n\t<li>V2406C WL Models\u00a0\u2013 version v1.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-266240-cve-2026-9266-missing-required-cryptographic-step-vulnerability-in-industrial-computers\">CVE-2026-9266: Missing Required Cryptographic Step Vulnerability in Industrial Computers<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-594","alert_type":398,"serial_number":"AV26-594","subject":"other","moderation_state":"published","external_url":null},{"nid":7866,"title":"GeoServer security advisory (AV26-595)","uuid":"131283ac-5bd1-4e4a-9633-c4007232ab57","banner":null,"lang":"en","date_modified":"2026-06-12","date_modified_ts":"2026-06-12T19:12:40Z","date_created":"2026-06-12T19:10:43Z","summary":null,"body":["<article data-history-node-id=\"7866\" about=\"\/en\/alerts-advisories\/geoserver-security-advisory-av26-595\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-595<br \/><strong>Date: <\/strong>June 12, 2026<\/p>\n\n<p>On June 11, 2026, GeoServer published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GeoServer\u00a0\u2013 versions prior to 3.0.0<\/li>\n\t<li>GeoTools\u00a0\u2013 versions prior to 35.0<\/li>\n\t<li>GeoWebCache\u00a0\u2013 versions prior to 2.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/geoserver.org\/announcements\/vulnerability\/2026\/06\/11\/geoserver-3-0-0-released.html\">GeoServer 3.0.0 Release <\/a><\/li>\n\t<li><a href=\"https:\/\/geoserver.org\/\">GeoServer<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/geoserver-security-advisory-av26-595","alert_type":396,"serial_number":"AV26-595","subject":"other","moderation_state":"published","external_url":null},{"nid":7867,"title":"FreePBX security advisory (AV26\u2013596)","uuid":"d206aa74-f560-4edd-aaf4-66e220256006","banner":null,"lang":"en","date_modified":"2026-06-12","date_modified_ts":"2026-06-12T19:27:44Z","date_created":"2026-06-12T19:19:10Z","summary":null,"body":["<article data-history-node-id=\"7867\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-596\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013596<br \/><strong>Date: <\/strong>June 12, 2026<\/p>\n\n<p>On June 12, 2026, FreePBX published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FreePBX Security-Reporting ucp (FreePBX 16)\u00a0\u2013 versions prior to 0.39<\/li>\n\t<li>FreePBX Security-Reporting ucp (FreePBX 17)\u00a0\u2013 versions prior to 0.7<\/li>\n\t<li>FreePBX Security-Reporting superfecta (FreePBX 16)\u00a0\u2013 versions prior to 16.0.40<\/li>\n\t<li>FreePBX Security-Reporting superfecta (FreePBX 17)\u00a0\u2013 versions prior to 17.0.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-4jjr-8g5r-wv66\">Authenticated Command Injection in FreePBX UCP Interface<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-j53p-5m8r-j3p6\">Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories?state=published\">FreePBX Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-596","alert_type":396,"serial_number":"AV26-596","subject":"other","moderation_state":"published","external_url":null},{"nid":7868,"title":"IBM security advisory (AV26-597)","uuid":"481f70ae-ed13-4ffd-aa56-0ec290d21b13","banner":null,"lang":"en","date_modified":"2026-06-15","date_modified_ts":"2026-06-15T12:59:55Z","date_created":"2026-06-15T12:54:23Z","summary":null,"body":["<article data-history-node-id=\"7868\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-597\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-597<br \/><strong>Date:<\/strong> June 15, 2026<\/p>\n\n<p>Between June 8 and 14, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Aspera Shares \u2013 versions 1.9.9 to 1.11.2<\/li>\n\t<li>IBM Automation Decision Services \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Applications \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Data System (CPDS) \u2013 versions 1.0.0.0 to 1.0.10.0<\/li>\n\t<li>IBM DevOps Code ClearCase \u2013 version 11.0<\/li>\n\t<li>IBM Enterprise Application Runtimes \u2013 versions 1.0 and 1.1<\/li>\n\t<li>IBM Enterprise Build of Quarkus \u2013 versions 3.27.0 to 3.27.3.SP2<\/li>\n\t<li>IBM Event Processing \u2013 versions 1.5.0 to 1.5.2<\/li>\n\t<li>IBM Guardium Key Lifecycle Manager (SKLM\/GKLM) \u2013 version 4.1<\/li>\n\t<li>IBM Maximo Scheduler Optimization \u2013 multiple versions<\/li>\n\t<li>IBM Observability with Instana (OnPrem) \u2013 versions Build 1.0.285 to 1.0.317<\/li>\n\t<li>IBM Process Automation Manager Open Edition Starter Kit for Banking \u2013 version 9.3.1<\/li>\n\t<li>IBM Rational ClearCase \u2013 version 10.0.0<\/li>\n\t<li>IBM Rational ClearCase \u2013 version 9.1<\/li>\n\t<li>IBM Rational ClearQuest \u2013 versions 9.1 to 9.1.0.11, versions 10.0 to 10.0.10<\/li>\n\t<li>IBM Rational Developer for i (RDi) \u2013 version 9.9<\/li>\n\t<li>IBM Software Support App (iOS) \u2013 versions 4.0.0 to 4.0.1<\/li>\n\t<li>IBM Software Support app (Android) \u2013 versions 4.0.0 to 4.0.1<\/li>\n\t<li>IBM Tivoli Monitoring \u2013 versions 6.3.0.7 to 6.3.0.7 Service Pack 22<\/li>\n\t<li>IBM Tivoli Network Manager IP Edition \u2013 versions 4.2 GA to 4.2.0.24<\/li>\n\t<li>IBM Verify Identity Access Digital Credentials \u2013 versions 24.06 to 26.03<\/li>\n\t<li>IBM WebSphere Application Server Liberty \u2013 versions 17.0.0.3 to 26.0.0.5<\/li>\n\t<li>IBM WebSphere Application Server \u2013 multiple versions<\/li>\n\t<li>IBM WebSphere Hybrid Edition \u2013 version 5.1<\/li>\n\t<li>IBM i \u2013 multiple versions<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data \u2013 versions 4.8.4 to 4.8.5<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data \u2013 versions 5.0.0 to 5.3.2<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition \u2013 versions 1.4.0 to 2.10.0<\/li>\n\t<li>ICP \u2013 Discovery \u2013 versions 5.0.0 to 5.3.1<\/li>\n\t<li>Langflow OSS \u2013 versions 1.0.0 to 1.8.4<\/li>\n\t<li>SPSS Collaboration and Deployment Services \u2013 multiple versions<\/li>\n\t<li>Technical Support Appliance \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-597","alert_type":396,"serial_number":"AV26-597","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7869,"title":"Dell security advisory (AV26-598)","uuid":"b6be7b65-1d8b-4aa6-a654-4a214e8f3a13","banner":null,"lang":"en","date_modified":"2026-06-15","date_modified_ts":"2026-06-15T13:09:14Z","date_created":"2026-06-15T13:03:26Z","summary":null,"body":["<article data-history-node-id=\"7869\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-598\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-598<br \/><strong>Date:<\/strong> June 15, 2026<\/p>\n\n<p>Between June 8 and 14, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell NativeEdge Orchestrator \u2013 versions prior to 4.2.0.0<\/li>\n\t<li>iDRAC Tools \u2013 versions prior to 11.4.1.0<\/li>\n\t<li>PowerEdge \u2013 multiple versions<\/li>\n\t<li>PowerScale \u2013 multiple versions<\/li>\n\t<li>PowerStore \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000476054\/dsa-2026-273-dell-powerstore-t-security-update-for-multiple-vulnerabilities\">DSA-2026-273: Dell PowerStore T Security Update for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000475534\/dsa-2026-256-security-update-for-dell-native-edge-orchestrator-eo\">DSA-2026-256: Security Update for Dell Native Edge Orchestrator (EO)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000474822\/dsa-2026-237-security-update-for-dell-powerscale-onefs-multiple-third-party-component-vulnerabilities\">DSA-2026-237: Security Update for Dell PowerScale OneFS Multiple Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-598","alert_type":396,"serial_number":"AV26-598","subject":"dell","moderation_state":"published","external_url":null},{"nid":7870,"title":"Ubuntu security advisory (AV26-599)","uuid":"3a24daec-1209-462b-9d68-918caccf5aba","banner":null,"lang":"en","date_modified":"2026-06-15","date_modified_ts":"2026-06-15T13:16:16Z","date_created":"2026-06-15T13:11:15Z","summary":null,"body":["<article data-history-node-id=\"7870\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-599\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-599<br \/><strong>Date:<\/strong> June 15, 2026<\/p>\n\n<p>Between June 8 and 14, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-599","alert_type":396,"serial_number":"AV26-599","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7871,"title":"[Control systems] CISA ICS security advisories (AV26\u2013600)","uuid":"3c501487-dada-4ac1-9c2f-46510b6908cb","banner":null,"lang":"en","date_modified":"2026-06-15","date_modified_ts":"2026-06-15T13:35:09Z","date_created":"2026-06-15T13:17:51Z","summary":null,"body":["<article data-history-node-id=\"7871\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-600\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26\u2013600<br \/><strong>Date:<\/strong> June 15, 2026<\/p>\n\n<p>Between June 8 and 14, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Schneider Electric Modicon Network Managed Switches \u2013 all versions<\/li>\n\t<li>Siemens KACO Blueplanet Inverters \u2013 multiple versions and models<\/li>\n\t<li>Schneider Electric EcoStruxure Panel Servers \u2013 multiple versions and models<\/li>\n\t<li>Yarbo Android\/IOS mobile application \u2013 versions prior to v3.17.4<\/li>\n\t<li>Yarbo Cloud MQTT infrastructure \u2013 all versions<\/li>\n\t<li>Naxclow IoT Platform \u2013 all versions<\/li>\n\t<li>Brickcom Cameras \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-600","alert_type":398,"serial_number":"AV26-600","subject":"other","moderation_state":"published","external_url":null},{"nid":7872,"title":"Red Hat security advisory (AV26-601)","uuid":"75a8b075-1567-4d8c-82e8-15da61722049","banner":null,"lang":"en","date_modified":"2026-06-15","date_modified_ts":"2026-06-15T13:40:01Z","date_created":"2026-06-15T13:36:48Z","summary":null,"body":["<article data-history-node-id=\"7872\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-601\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-601<br \/><strong>Date:<\/strong> June 15, 2026<\/p>\n\n<p>Between June 8 and 14, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-601","alert_type":396,"serial_number":"AV26-601","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7874,"title":"Cisco security advisory (AV26-602)","uuid":"6e13ea93-a443-4d72-bcb4-5539234c0722","banner":null,"lang":"en","date_modified":"2026-06-16","date_modified_ts":"2026-06-16T12:26:38Z","date_created":"2026-06-16T12:19:18Z","summary":null,"body":["<article data-history-node-id=\"7874\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-602\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-602<br \/><strong>Date:<\/strong> June 15, 2026<\/p>\n\n<p>On June 15, 2026, Cisco published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Cisco Catalyst SD-WAN Manager\u00a0\u2013 multiple versions and all deployment types<\/li>\n<\/ul><p>Cisco is aware of exploitation of this vulnerability.<\/p>\n\n<p>On June 15, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20262 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sdwan-arbfw-c2rZvQ\">Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability (CVE-2026-20262)<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20262\">CISA KEV: CVE-2026-20262<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-602","alert_type":396,"serial_number":"AV26-602","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7875,"title":"Zyxel security advisory (AV26-603) \u2013 Update 1","uuid":"f6cd1177-6847-4ba3-be22-b2f44e66ea28","banner":null,"lang":"en","date_modified":"2026-09-21","date_modified_ts":"2026-09-21T20:12:57Z","date_created":"2026-06-16T13:41:24Z","summary":null,"body":["<article data-history-node-id=\"7875\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av26-603\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-603<br \/><strong>Date: <\/strong>June\u00a016, 2026<br \/><strong>Updated:<\/strong> September 21, 2026<\/p>\n\n<p>On June\u00a016, 2026, Zyxel published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GS1900 series switches\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p class=\"mrgn-bttm-lg\">On September 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026\">Zyxel security advisory for stack-based buffer overflow vulnerability in GS1900 series switches<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7273\">CISA KEV: CVE-2026-7273<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av26-603","alert_type":396,"serial_number":"AV26-603","subject":"other","moderation_state":"published","external_url":null},{"nid":7876,"title":"Mozilla security advisory (AV26-604)","uuid":"1b19dcb8-ff42-4323-8d2d-bba3b6b2a430","banner":null,"lang":"en","date_modified":"2026-06-16","date_modified_ts":"2026-06-16T17:44:57Z","date_created":"2026-06-16T17:40:15Z","summary":null,"body":["<article data-history-node-id=\"7876\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-604\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-604<br \/><strong>Date: <\/strong>June\u00a016, 2026<\/p>\n\n<p>On June\u00a016, 2026, Mozilla published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 152<\/li>\n\t<li>Firefox for iOS\u00a0\u2013 versions prior to 152<\/li>\n\t<li>Firefox EST\u00a0\u2013 versions prior to 140.12<\/li>\n\t<li>Firefox ESR\u00a0\u2013 versions prior to 115.37<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-59\/\">Mozilla Foundation Security Advisory 2026-59<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-58\/\">Mozilla Foundation Security Advisory 2026-58<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-57\/\">Mozilla Foundation Security Advisory 2026-57<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-56\/\">Mozilla Foundation Security Advisory 2026-56<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-604","alert_type":396,"serial_number":"AV26-604","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7877,"title":"Oracle security advisory \u2013 June 2026 quarterly rollup (AV26-605)","uuid":"678c863d-08b3-43be-a08f-95fbfb6ff934","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T13:04:37Z","date_created":"2026-06-17T12:38:41Z","summary":null,"body":["<article data-history-node-id=\"7877\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-june-2026-quarterly-rollup-av26-605\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-605<br \/><strong>Date:<\/strong> June 17, 2026<\/p>\n\n<p>On June 16, 2026, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>APM\u00a0- Application Performance Management<\/li>\n\t<li>Identity Manager<\/li>\n\t<li>Identity Manager Connector<\/li>\n\t<li>JD Edwards EnterpriseOne Accounts Payable<\/li>\n\t<li>JD Edwards EnterpriseOne General Ledger<\/li>\n\t<li>JD Edwards EnterpriseOne Human Resources Management<\/li>\n\t<li>JD Edwards EnterpriseOne Order Promising<\/li>\n\t<li>JD Edwards EnterpriseOne Project Costing<\/li>\n\t<li>JD Edwards EnterpriseOne Tools<\/li>\n\t<li>MySQL Cluster<\/li>\n\t<li>MySQL NDB Cluster<\/li>\n\t<li>MySQL Router<\/li>\n\t<li>MySQL Server<\/li>\n\t<li>MySQL Shell<\/li>\n\t<li>Oracle Access Manager<\/li>\n\t<li>Oracle Agile PLM<\/li>\n\t<li>Oracle Application Development Framework (ADF)<\/li>\n\t<li>Oracle Coherence<\/li>\n\t<li>Oracle Communications Convergent Charging Controller<\/li>\n\t<li>Oracle Communications Network Charging and Control<\/li>\n\t<li>Oracle Communications Network Integrity<\/li>\n\t<li>Oracle Data Integrator<\/li>\n\t<li>Oracle E-Business Suite<\/li>\n\t<li>Oracle Enterprise Manager Base Platform<\/li>\n\t<li>Oracle GoldenGate<\/li>\n\t<li>Oracle Solaris<\/li>\n\t<li>Oracle Unified Directory<\/li>\n\t<li>Oracle VM VirtualBox<\/li>\n\t<li>Oracle Virtual Directory<\/li>\n\t<li>Oracle WebCenter Content<\/li>\n\t<li>Oracle WebCenter Enterprise Capture<\/li>\n\t<li>Oracle WebCenter Portal<\/li>\n\t<li>Oracle WebCenter Sites<\/li>\n\t<li>PeopleSoft Enterprise CS Campus Community<\/li>\n\t<li>PeopleSoft Enterprise CS Student Financials<\/li>\n\t<li>PeopleSoft Enterprise PT PeopleTools<\/li>\n\t<li>Siebel Applications<\/li>\n\t<li>WebCenter Content: Imaging<\/li>\n\t<li>WebLogic Server<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cspujun2026.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 June 2026<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-june-2026-quarterly-rollup-av26-605","alert_type":396,"serial_number":"AV26-605","subject":"oracle","moderation_state":"published","external_url":null},{"nid":7878,"title":"JetBrains security advisory (AV26-606)","uuid":"a84c6bbe-8c12-4fdb-9af7-4dff065004f3","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T14:00:53Z","date_created":"2026-06-17T13:25:05Z","summary":null,"body":["<article data-history-node-id=\"7878\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-606\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-606<br \/><strong>Date:<\/strong> June 17, 2026<\/p>\n\n<p>On June 16, 2026, JetBrains published a security advisory to address vulnerability in the following product:<\/p>\n\n<ul><li>JetBrains GoLand\u00a0\u2013 versions prior to 2026.1.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-606","alert_type":396,"serial_number":"AV26-606","subject":"other","moderation_state":"published","external_url":null},{"nid":7879,"title":"Microsoft security advisory (AV26-607)","uuid":"f9acf6bd-dbda-4249-a054-a599d6c840b0","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T15:36:55Z","date_created":"2026-06-17T15:22:47Z","summary":null,"body":["<article data-history-node-id=\"7879\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-av26-607\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-607<br \/><strong>Date:<\/strong> June 17, 2026<\/p>\n\n<p>On June 16, 2026, Microsoft published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Malware Protection Engine<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-50656\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft Defender Elevation of Privilege Vulnerability<\/span> (CVE-2026-50656)<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-av26-607","alert_type":396,"serial_number":"AV26-607","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7880,"title":"Atlassian security advisory (AV26-608)","uuid":"1febcbad-dee3-469e-b5d3-4dbda28c9b69","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T16:12:02Z","date_created":"2026-06-17T15:58:45Z","summary":null,"body":["<article data-history-node-id=\"7880\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-608\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-608<br \/><strong>Date:<\/strong> June 17, 2026<\/p>\n\n<p>On June 16, 2026, Atlassian published a security advisory to address vulnerabilities, including some critical ones, in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Fisheye\/Crucible\u00a0- versions 4.9.0 to 4.9.10<\/li>\n\t<li>Jira Data Center and Server\u00a0- multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/spaces\/SECURITY\/pages\/1796309326\/Security+Bulletin+-+June+16+2026\">Security Bulletin\u00a0- June 16 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-608","alert_type":396,"serial_number":"AV26-608","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":7881,"title":"Google Chrome security advisory (AV26-609)","uuid":"5a5a3469-e351-4a40-a890-2a4756e132cf","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T17:23:55Z","date_created":"2026-06-17T17:11:43Z","summary":null,"body":["<article data-history-node-id=\"7881\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-609\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-609<br \/><strong>Date:<\/strong> June 17, 2026<\/p>\n\n<p>On June 16, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to0.7827.155\/.156 (Windows\/Mac), and 149.0.7827.155 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_01750511403.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-609","alert_type":396,"serial_number":"AV26-609","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7882,"title":"[Control Systems] Moxa security advisory (AV26-610)","uuid":"f566a3c4-f3cf-4d0d-b191-283b107d969d","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T17:39:36Z","date_created":"2026-06-17T17:27:55Z","summary":null,"body":["<article data-history-node-id=\"7882\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-610\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-610<br \/><strong>Date: <\/strong>June<strong> <\/strong>17, 2026<\/p>\n\n<p>On June 16, 2026, Moxa published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NPort 6000-G2 Series\u00a0- version v1.1.0 and prior<\/li>\n\t<li>NPort W2150A-W4\/W2250A-W4 Series\u00a0- firmware version v1.5 and prior<\/li>\n\t<li>NPort W2150A\/W2250A Series\u00a0- firmware version v2.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-268270-cve-2026-10825-improper-validation-of-input-vulnerability-in-serial-device-servers\">CVE-2026-10825: Improper Validation of Input Vulnerability in Serial Device Servers<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-261910-cve-2026-10828,-cve-2026-10829-use-of-externally-controlled-format-string-and-stack-based-buffer-overflow-v\">CVE-2026-10828, CVE-2026-10829: Use of Externally-Controlled Format String and Stack-based Buffer Overflow Vulnerabilities in Serial Device Servers<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories (en anglais seulement)<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-610","alert_type":398,"serial_number":"AV26-610","subject":"other","moderation_state":"published","external_url":null},{"nid":7883,"title":"Mitel security advisory (AV26-611)","uuid":"2bcbfbd7-9f70-4d2e-868e-ff499dc835ec","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T18:00:01Z","date_created":"2026-06-17T17:49:59Z","summary":null,"body":["<article data-history-node-id=\"7883\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av26-611\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-611<br \/><strong>Date: <\/strong>June 17, 2026<\/p>\n\n<p>On June 17, 2026, Mitel published a security advisory to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>MiCollab\u00a0- multiple versions<\/li>\n\t<li>MiVoice Business Solution Virtual Instance (MiVB SVI)\u00a0- version 2.1.0.9-2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2026-0005\">Mitel Product Security Advisory MISA-2026-0005<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av26-611","alert_type":396,"serial_number":"AV26-611","subject":"mitel","moderation_state":"published","external_url":null},{"nid":7884,"title":"F5 security advisory (AV26-612)","uuid":"f76cc570-e719-4cad-bff9-aaa4f73bab3e","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T18:14:07Z","date_created":"2026-06-17T18:06:39Z","summary":null,"body":["<article data-history-node-id=\"7884\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-612\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-612<br \/><strong>Date: <\/strong>June 17, 2026<\/p>\n\n<p>On June 17, 2026, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>F5 DoS for NGINX\u00a0- version 4.9.0<\/li>\n\t<li>F5 WAF for NGINX Instance Manager\u00a0- versions 5.9.0 to 5.13.1<\/li>\n\t<li>NGINX App Protect DoS\u00a0- versions 4.3.0 to 4.7.0<\/li>\n\t<li>NGINX App Protect WAF\u00a0- versions 5.2.0 to 5.8.0 and 4.10.0 to 4.16.0<\/li>\n\t<li>NGINX Open Source\u00a0- versions 1.30.0 to 1.30.2 and 1.31.0 to 1.31.1<\/li>\n\t<li>NGINX Instance Manager\u00a0- versions 2.17.0 to 2.22.0<\/li>\n\t<li>NGINX Gateway Fabric\u00a0- multiple versions<\/li>\n\t<li>NGINX Ingress Controller\u00a0- multiple versions<\/li>\n\t<li>NGINX Plus\u00a0- version 37.0.0 R33 to 37.01 R36<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161614\">K000161614: Out-of-band Security Notification (June 17, 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K12201527\">MyF5<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-612","alert_type":396,"serial_number":"AV26-612","subject":"f5","moderation_state":"published","external_url":null},{"nid":7885,"title":"Cisco security advisory (AV26-613)","uuid":"eada2645-49dd-4e5d-98b2-1c2fc4147f07","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T18:44:15Z","date_created":"2026-06-17T18:29:02Z","summary":null,"body":["<article data-history-node-id=\"7885\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-613\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-613<br \/><strong>Date:<\/strong> June 17, 2026<\/p>\n\n<p>On June 17, 2026, Cisco published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following product:<\/p>\n\n<p>Cisco ISE (Identity Services Engine) and Cisco ISE-PIC (Passive Identity Connector)<\/p>\n\n<ul><li>Cisco ISE and ISE-PIC Releases prior to 3.3\u00a0- all versions<\/li>\n\t<li>Cisco ISE and ISE-PIC Release 3.3\u00a0- versions prior to 3.3 Patch 11<\/li>\n\t<li>Cisco ISE and ISE-PIC Release 3.4\u00a0- versions prior to 3.4 Patch 6<\/li>\n\t<li>Cisco ISE and ISE-PIC Release 3.5\u00a0- versions prior to 3.5 Patch 4 (August 2026)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-multi-G5WP8vv\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities<\/span><\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Cisco Security Advisories<\/span><\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-613","alert_type":396,"serial_number":"AV26-613","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7886,"title":"Splunk security advisory (AV26-614)","uuid":"38eb8814-f0a8-45aa-973a-3cb0cf8898ac","banner":null,"lang":"en","date_modified":"2026-06-17","date_modified_ts":"2026-06-17T19:19:26Z","date_created":"2026-06-17T19:04:59Z","summary":null,"body":["<article data-history-node-id=\"7886\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-614\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-614<br \/><strong>Date: <\/strong>June 17, 2026<\/p>\n\n<p>On June 17, 2026, Splunk published security advisories to address vulnerabilities in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>Splunk AI Toolkit\u00a0\u2013 versions prior to 5.7.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0614\">OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\">Splunk Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-614","alert_type":396,"serial_number":"AV26-614","subject":"other","moderation_state":"published","external_url":null},{"nid":7887,"title":"AL26-014 \u2013 FortiBleed leak of thousands of compromised credentials impacting Fortinet devices","uuid":"5c403168-71ec-49dc-b820-1976f31bbd83","banner":null,"lang":"en","date_modified":"2026-06-18","date_modified_ts":"2026-06-18T13:52:14Z","date_created":"2026-06-18T13:29:22Z","summary":null,"body":["<article data-history-node-id=\"7887\" about=\"\/en\/alerts-advisories\/al26-014-fortibleed-leak-thousands-compromised-credentials-impacting-fortinet-devices\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-014<br \/><strong>Date:<\/strong> June 18, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>On June 17, 2026, the Canadian Centre for Cyber Security (Cyber Centre) became aware of open-source reporting<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> describing a widespread malicious campaign, known as \u201cFortiBleed,\u201d involving exposed credentials affecting Fortinet firewalls and VPN gateways. Exploitation of these credentials could allow malicious actors to gain remote access to affected devices and connected networks, as well as modify various system settings, including critical security controls.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations\u00a0:<\/p>\n\n<ul><li>Inventory all accounts on Fortinet devices, identify unauthorized or suspicious accounts (e.g., <code>forticloud-sync<\/code>, <code>forticloud-tech<\/code>) and disable\/remove suspected or unneeded accounts.<\/li>\n\t<li>Restrict access to management interfaces to trusted networks and hosts only.<\/li>\n\t<li>Terminate all active SSL VPN and administrative sessions.<\/li>\n\t<li>Reset passwords for all Fortinet VPN and administrative accounts.<\/li>\n\t<li>Enforce Multi-Factor Authentication (MFA) across all external gateways and admin interfaces.<\/li>\n\t<li>Ensure all Fortinet devices are running the latest firmware. Specifically, check for patches related to CVE-2024-55591 (obtain high privileges) <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> and, CVE-2025-59718<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> and CVE-2025-59719<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> (authentication bypass)<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions with an emphasis on the following topics<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<ul><li>Consolidate, monitor and defend Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Enforce the management of administrative privileges<\/li>\n\t<li>Harden operating systems and applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/doublepulsar.com\/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8\">FortiBleed\u00a0- 75k Fortinet firewalls have admin passwords cracked<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.infostealers.com\/article\/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure\/\">FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed\u00a0\u2013 Claim Your Ethical Disclosure<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.hudsonrock.com\/fortinet\">FortiBleed<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.fortinet.com\/blog\/psirt-blogs\/analysis-of-reported-credential-compromise-of-fortigate-devices\">Analysis of Reported Credential Compromise of FortiGate Devices<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-55591\">CVE-2024-55591 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-59718\">CVE-2025-59718 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-59719\">CVE-2025-59719 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"\/en\/alerts-advisories\/al25-019-vulnerabilities-impacting-fortinet-products-forticloud-sso-login-authentication-bypass-cve-2025-59718-cve-2025-59719\">Alert\u00a0- AL25-019\u00a0- Vulnerabilities impacting Fortinet products\u00a0- FortiCloud SSO Login Authentication Bypass\u00a0- CVE-2025-59718 and CVE-2025-59719<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-014-fortibleed-leak-thousands-compromised-credentials-impacting-fortinet-devices","alert_type":397,"serial_number":"AL26-014","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7888,"title":"Drupal security advisory (AV26-615)","uuid":"971cbb55-ceff-4459-b3bc-fdcffafa072a","banner":null,"lang":"en","date_modified":"2026-06-18","date_modified_ts":"2026-06-18T17:26:18Z","date_created":"2026-06-18T17:22:54Z","summary":null,"body":["<article data-history-node-id=\"7888\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-615\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-615<br \/><strong>Date: <\/strong>June 18, 2026<\/p>\n\n<p>On June 17, 2026, Drupal published security advisories to address vulnerabilities in a number of products. Included were critical updates for the following:<\/p>\n\n<ul><li>Drupal core\u00a0\u2013 multiple versions<\/li>\n\t<li>Plotly.js Graphing\u00a0\u2013 versions prior to 3.0.2<\/li>\n\t<li>Flag attendance field\u00a0\u2013 versions prior to 8.x-1.2<\/li>\n\t<li>Formatter Field\u00a0\u2013 versions prior to 2.0.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-615","alert_type":396,"serial_number":"AV26-615","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7890,"title":"[Control systems] Mitsubishi Electric security advisory (AV26-616)","uuid":"a21de19f-bb86-44df-a093-1361e697a5cc","banner":null,"lang":"en","date_modified":"2026-06-19","date_modified_ts":"2026-06-19T18:53:39Z","date_created":"2026-06-19T18:46:35Z","summary":null,"body":["<article data-history-node-id=\"7890\" about=\"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av26-616\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-616<br \/><strong>Date: <\/strong>June 19, 2026<\/p>\n\n<p>On June 18, 2026, Mitsubishi Electric published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FX5-EIP EtherNet\/IP Module FX5-EIP \u2013 version 1.000 and prior<\/li>\n\t<li>FX5-ENET\/IP Ethernet Module FX5-ENET\/IP \u2013 all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitsubishielectric.com\/psirt\/vulnerability\/pdf\/2026-002_en.pdf\">Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet\/IP module (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitsubishielectric.com\/psirt\/vulnerability\/pdf\/2026-003_en.pdf\">Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET\/IP Ethernet module (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitsubishielectric.com\/psirt\/vulnerability\/pdf\/2025-021_en.pdf\">Multiple denial-of-service (DoS) vulnerabilities in Ethernet function of MELSEC iQ-F Series EtherNet\/IP module and Ethernet module (PDF)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-mitsubishi-electric-security-advisory-av26-616","alert_type":398,"serial_number":"AV26-616","subject":"other","moderation_state":"published","external_url":null},{"nid":7891,"title":"IBM security advisory (AV26-617)","uuid":"321a908c-39a9-4d65-acea-2c4e37d54c24","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T13:38:40Z","date_created":"2026-06-22T13:27:47Z","summary":null,"body":["<article data-history-node-id=\"7891\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-617\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-617<br \/><strong>Date: <\/strong>June 22, 2026<\/p>\n\n<p>Between June 15 and 21, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Content-Aware Storage\u00a0- versions 1.0.0 to 1.1.3<\/li>\n\t<li>DataStage on Cloud Pak for Data\u00a0- versions prior to 5.3.1.0<\/li>\n\t<li>Decision Optimization for Cloud Pak for Data\u00a0- versions 5.0 to 5.3.1 - Patch 4 releases<\/li>\n\t<li>Host On-Demand (HOD)\u00a0- versions 16.0 to 16.0.1, versions 15.0 to 15.0.4<\/li>\n\t<li>IBM ApplinX\u00a0- versions prior to 11.1 and 12.1<\/li>\n\t<li>IBM Cloud Pak for Data System (CPDS)\u00a0- versions 1.0.0.0 to 1.0.10.0<\/li>\n\t<li>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data\u00a0- multiple versions<\/li>\n\t<li>IBM Engineering Lifecycle Management on Hybrid Cloud\u00a0- versions 1.0.0 to 1.3.0<\/li>\n\t<li>IBM Enterprise Build of Quarkus\u00a0- versions 3.27.1 to 3.27.4, versions 3.33.1 to 3.33.2<\/li>\n\t<li>IBM EntireX\u00a0- versions prior to 11.1<\/li>\n\t<li>IBM Fusion HCI\u00a0- versions 2.10.0 to 2.12.1<\/li>\n\t<li>IBM Fusion\u00a0- versions 2.9.0 to 2.12.1<\/li>\n\t<li>IBM Guardium Key Lifecycle Manager (SKLM\/GKLM)\u00a0- versions prior to 4.1<\/li>\n\t<li>IBM HTTP Server\u00a0- versions prior to 9.0 and 8.5<\/li>\n\t<li>IBM MQ Operator\u00a0- multiple versions<\/li>\n\t<li>IBM Netezza Software\u00a0- versions prior to 11.3.0.3-IF2<\/li>\n\t<li>IBM Operational Decision Manager\u00a0- multiple versions<\/li>\n\t<li>IBM Planning Analytics Local\u00a0- versions 2.1.0 to 2.1.20<\/li>\n\t<li>IBM Robotic Process Automation for Cloud Pak\u00a0- multiple versions<\/li>\n\t<li>IBM Security QRadar Log Management AQL Plugin\u00a0- versions 1.0.0 to 1.1.5<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services\u00a0- versions 6.3.0 to 6.3.0.18<\/li>\n\t<li>IBM Sterling Connect:Direct Web Services\u00a0- versions 6.4.0 to 6.4.0.7<\/li>\n\t<li>IBM Tivoli Netcool Configuration Manager\u00a0- versions 6.4.2 GA to 6.4.2.24<\/li>\n\t<li>IBM Watson Speech Services Cartridge\u00a0- versions 4.0.0 to 5.3.1<\/li>\n\t<li>IBM supplied MQ Advanced container images\u00a0- multiple versions<\/li>\n\t<li>IBM webMethods BPM\u00a0- versions prior to 12.1 and 11.1<\/li>\n\t<li>ICP\u00a0- Discovery\u00a0- versions 5.0.0 to 5.3.1<\/li>\n\t<li>Langflow OSS\u00a0- versions 1.0.0 to 1.9.3<\/li>\n\t<li>MongoDB Enterprise Advanced with IBM\u00a0- versions Ops-Manager 8.0.0 to 8.0.21<\/li>\n\t<li>MongoDB Enterprise Advanced with IBM\u00a0- versions migrator 1.0.0 to 1.15.9<\/li>\n\t<li>QRadar\u00a0- versions prior to 7.5.0<\/li>\n\t<li>UCD - IBM DevOps Deploy\u00a0- versions 8.0 to 8.0.1.13, versions 8.1 to 8.1.2.6<\/li>\n\t<li>UCD - IBM UrbanCode Deploy\u00a0- versions 7.2 to 7.2.3.23, versions 7.3 to 7.3.2.18<\/li>\n\t<li>WebSphere Application Server\u00a0- versions prior to v9.0.5.5<\/li>\n\t<li>voice-gateway\/sip-orchestrator\u00a0- versions prior to 1.0.8.26<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-617","alert_type":396,"serial_number":"AV26-617","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7892,"title":"Ubuntu security advisory (AV26-618)","uuid":"2ec56611-2c3e-48d4-94b4-b628bbfb6708","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T13:44:52Z","date_created":"2026-06-22T13:41:57Z","summary":null,"body":["<article data-history-node-id=\"7892\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-618\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-618<br \/><strong>Date:<\/strong> June 22, 2026<\/p>\n\n<p>Between June 15 and 21, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-618","alert_type":396,"serial_number":"AV26-618","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7893,"title":"Dell security advisory (AV26-619)","uuid":"800009c5-af79-4524-af8f-c77bde7b1dad","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T13:55:58Z","date_created":"2026-06-22T13:47:22Z","summary":null,"body":["<article data-history-node-id=\"7893\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-619\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-619<br \/><strong>Date:<\/strong> June 22, 2026<\/p>\n\n<p>Between June 15 and 21, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Container Storage Modules\u00a0- multiple versions<\/li>\n\t<li>Dell Data Protection Central\u00a0- versions 19.10 to 19.12 with Data Protection Central OS Update prior to dpc-osupdate-1.1.27-1<\/li>\n\t<li>Dell PowerFlex Custom Node\u00a0- multiple versions<\/li>\n\t<li>Dell PowerFlex Software\u00a0- versions prior to 4.5.5.2<\/li>\n\t<li>Dell PowerFlex Software\u00a0- versions prior to 5.1.0.1<\/li>\n\t<li>Dell Private Cloud\u00a0- Red Hat\u00a0- versions prior to 01.04.00.00<\/li>\n\t<li>Dell VxFlex Ready Node\u00a0- versions prior to 2.25.0<\/li>\n\t<li>Dell VxRail Appliance\u00a0- versions prior to 9.1.000<\/li>\n\t<li>PowerProtect DB\u00a0- versions prior to 2.7.9 with Data Protection Central OS Update prior to dpc-osupdate-1.1.27-1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-619","alert_type":396,"serial_number":"AV26-619","subject":"dell","moderation_state":"published","external_url":null},{"nid":7894,"title":"[Control systems] CISA ICS security advisories (AV26\u2013620)","uuid":"a66472fc-fb0e-4d6e-8d34-290a38ee9781","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T14:09:43Z","date_created":"2026-06-22T14:01:48Z","summary":null,"body":["<article data-history-node-id=\"7894\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-620\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013620<br \/><strong>Date: <\/strong>June 22, 2026<\/p>\n\n<p>Between June 15 and 21, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT\u00a0- version 0x0110_v1.1.0<\/li>\n\t<li>AVer PTC cameras PTC500S \/ PTC115 \/ PTC500+ \/ PTC115+\u00a0- all versions<\/li>\n\t<li>AzeoTech DAQFactory\u00a0- versions prior to 21.1<\/li>\n\t<li>Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET\/IP Ethernet Module\u00a0- all versions<\/li>\n\t<li>Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet\/IP Module FX5-EIP\u00a0- versions prior to 1.000<\/li>\n\t<li>Rockwell Automation 1794-AENTR\u00a0- versions prior to V2.012<\/li>\n\t<li>Rockwell Automation 1794-AENTRXT\u00a0- versions prior to V2.012<\/li>\n\t<li>Rockwell Automation CompactLogix\u00a0- multiple versions and models<\/li>\n\t<li>Rockwell Automation FactoryTalk Analytics PavilionX\u00a0- versions prior to 7.01<\/li>\n\t<li>Rockwell Automation FactoryTalk Historian Site Edition (SE)\u00a0- versions prior to 11 and 11.00<\/li>\n\t<li>Rockwell Automation Logix 5370 &amp; 5570\u00a0- multiple versions and models<\/li>\n\t<li>Rockwell Automation RSLinx Classic\u00a0- versions prior to 4.50.00<\/li>\n\t<li>Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products\u00a0- multiple versions and models<\/li>\n\t<li>Schneider Electric EasyLogic T150 and Saitel DP\u00a0- versions prior to 11.06.31 and 11.06.36<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-620","alert_type":398,"serial_number":"AV26-620","subject":"ics","moderation_state":"published","external_url":null},{"nid":7895,"title":"Red Hat security advisory (AV26-621)","uuid":"7f031657-1b04-44ae-8d2c-1c7e221f2551","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T14:24:29Z","date_created":"2026-06-22T14:19:04Z","summary":null,"body":["<article data-history-node-id=\"7895\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-621\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-621<br \/><strong>Date: <\/strong>June 22, 2026<\/p>\n\n<p>Between June 15 and 21, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0- multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-621","alert_type":396,"serial_number":"AV26-621","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7896,"title":"Microsoft Edge security advisory (AV26-622)","uuid":"938a3f3d-d8bf-4491-9674-fc27389857ea","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T17:33:19Z","date_created":"2026-06-22T17:27:15Z","summary":null,"body":["<article data-history-node-id=\"7896\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-622\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-622<br \/><strong>Date:<\/strong> June 22, 2026<\/p>\n\n<p>On June 18, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 149.0.4022.80<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-9-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-622","alert_type":396,"serial_number":"AV26-622","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7897,"title":"JetBrains security advisory (AV26-623)","uuid":"32cad5d4-3a06-4ce3-aa62-6f30adaee69e","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T17:41:48Z","date_created":"2026-06-22T17:36:28Z","summary":null,"body":["<article data-history-node-id=\"7897\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-623\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-623<br \/><strong>Date: <\/strong>June 22, 2026<\/p>\n\n<p>On June 19, 2026, JetBrains published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>JetBrains YouTrack\u00a0- multiple versions<\/li>\n\t<li>JetBrains Hub\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-623","alert_type":396,"serial_number":"AV26-623","subject":"other","moderation_state":"published","external_url":null},{"nid":7898,"title":"Nodejs security advisory (AV26-624)","uuid":"f5293c7b-7320-4d5d-9db4-595bb99fc758","banner":null,"lang":"en","date_modified":"2026-06-22","date_modified_ts":"2026-06-22T17:50:22Z","date_created":"2026-06-22T17:44:15Z","summary":null,"body":["<article data-history-node-id=\"7898\" about=\"\/en\/alerts-advisories\/nodejs-security-advisory-av26-624\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--CUT & PASTE the French version info -->\n<p><strong>Serial number: <\/strong>AV26-624<br \/><strong>Date:<\/strong> June 22, 2026<br \/>\nOn June 18, 2026, Nodejs published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>js 22\u00a0- versions prior to v22.23.0<\/li>\n\t<li>js 24\u00a0- versions prior to v24.17.0<\/li>\n\t<li>js 26\u00a0- versions prior to v26.3.1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nodejs.org\/en\/blog\/vulnerability\/june-2026-security-releases\">Nodejs\u00a0- Thursday, June 18, 2026 Security Releases<\/a><\/li>\n\t<li><a href=\"https:\/\/nodejs.org\/en\/blog\/release\/\">Nodejs Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nodejs-security-advisory-av26-624","alert_type":396,"serial_number":"AV26-624","subject":"other","moderation_state":"published","external_url":null},{"nid":7900,"title":"Broadcom VMware security advisory (AV26-625)","uuid":"b2656ff7-c127-40b1-9afa-eba00df753a4","banner":null,"lang":"en","date_modified":"2026-06-23","date_modified_ts":"2026-06-23T15:00:13Z","date_created":"2026-06-23T14:57:49Z","summary":null,"body":["<article data-history-node-id=\"7900\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-625\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-625<br \/><strong>Date: <\/strong>June 23, 2026<\/p>\n\n<p>Between June 22 and 23, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware Tanzu Data Flow on Kubernetes \u2013 versions prior to 2.1.3<\/li>\n\t<li>VMware Tanzu Greenplum Backup and Restore \u2013 versions prior to 1.33.2<\/li>\n\t<li>VMware Tanzu Greenplum Platform Extension Framework \u2013 versions prior to 8.0.1<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes \u2013 versions prior to 3.13.17<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes \u2013 versions prior to 4.0.22<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes \u2013 versions prior to 4.1.13<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes \u2013 versions prior to 4.2.8<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes \u2013 versions prior to 4.3.2<\/li>\n\t<li>VMware Tanzu GemFire \u2013 versions prior to 10.1.8<\/li>\n\t<li>VMware Tanzu RabbitMQ \u2013 versions prior to 3.13.17<\/li>\n\t<li>VMware Tanzu RabbitMQ \u2013 versions prior to 4.0.22<\/li>\n\t<li>VMware Tanzu RabbitMQ \u2013 versions prior to 4.1.13<\/li>\n\t<li>VMware Tanzu RabbitMQ \u2013 versions prior to 4.2.8<\/li>\n\t<li>VMware Tanzu RabbitMQ \u2013 versions prior to 4.3.2<\/li>\n\t<li>VMware Tanzu Greenplum \u2013 versions prior to 6.33.2<\/li>\n\t<li>VMware Tanzu Greenplum \u2013 versions prior to 7.8.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- Tanzu<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-625","alert_type":396,"serial_number":"AV26-625","subject":"other","moderation_state":"published","external_url":null},{"nid":7902,"title":"Tenable security advisory (AV26-627)","uuid":"cda3bafe-59f8-4ab6-8adc-ad8544d7fa6b","banner":null,"lang":"en","date_modified":"2026-06-24","date_modified_ts":"2026-06-24T13:23:35Z","date_created":"2026-06-24T13:05:48Z","summary":null,"body":["<article data-history-node-id=\"7902\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-627\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number<\/strong>: AV26-627<br \/><strong>Date:<\/strong> June\u00a024, 2026<\/p>\n\n<p>On June\u00a023, 2026, Tenable published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Tenable Identity Exposure\u00a0\u2013 versions prior to 3.93.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-16\">[R1] Tenable Identity Exposure Version 3.93.5 Fixes Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-627","alert_type":396,"serial_number":"AV26-627","subject":"other","moderation_state":"published","external_url":null},{"nid":7901,"title":"Google Chrome security advisory (AV26-626)","uuid":"92579eaa-f788-4770-8658-a20fad8a336f","banner":null,"lang":"en","date_modified":"2026-06-24","date_modified_ts":"2026-06-24T13:16:58Z","date_created":"2026-06-24T13:05:48Z","summary":null,"body":["<article data-history-node-id=\"7901\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-626\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-626<br \/><strong>Date:<\/strong> June\u00a024, 2026<\/p>\n\n<p>On June\u00a023, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 149.0.7827.196\/197 (Windows\/Mac), and 149.0.7827.196 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_0482630350.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-626","alert_type":396,"serial_number":"AV26-626","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7903,"title":"n8n security advisory (AV26-628)","uuid":"77e7b290-9c82-44ec-b022-fbe62cad3411","banner":null,"lang":"en","date_modified":"2026-06-24","date_modified_ts":"2026-06-24T18:16:01Z","date_created":"2026-06-24T17:45:20Z","summary":null,"body":["<article data-history-node-id=\"7903\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-628\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-628<br \/><strong>Date:<\/strong> June\u00a024, 2026<\/p>\n\n<p>On June\u00a024, 2026, n8n published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>n8n\u00a0\u2013 versions prior to 2.28.1<\/li>\n\t<li>n8n\u00a0\u2013 versions prior to 2.27.4<\/li>\n\t<li>n8n\u00a0\u2013 versions prior to 1.123.61<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-h44j-f5r5-ph73\">\"Allowed HTTP Request Domains\" Restriction Bypass via AI Agents MCP Connector<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-75qm-gp28-rcq9\">Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-mq3m-f8x3-579w\">Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-q3j5-8vrg-4p9q\">Shared Credential Header Leak via HTTP Request Pagination Expression<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-628","alert_type":396,"serial_number":"AV26-628","subject":"other","moderation_state":"published","external_url":null},{"nid":7904,"title":"Jenkins security advisory (AV26-629)","uuid":"ca64bd09-3119-46ab-bee0-2470b02974a1","banner":null,"lang":"en","date_modified":"2026-06-24","date_modified_ts":"2026-06-24T18:26:27Z","date_created":"2026-06-24T18:17:37Z","summary":null,"body":["<article data-history-node-id=\"7904\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-629\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-629<br \/><strong>Date: <\/strong>June\u00a024, 2026<\/p>\n\n<p>On June\u00a024, 2026, Jenkins published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Assembla Plugin\u00a0\u2013 versions prior to 1.4<\/li>\n\t<li>External Workspace Manager Plugin\u00a0\u2013 versions prior to 1.3.2<\/li>\n\t<li>OWASP ZAP Plugin\u00a0\u2013 versions prior to 1.0.7<\/li>\n\t<li>Script Security Plugin\u00a0\u2013 versions prior to 1402.v94c9ce464861<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-06-24\/#SECURITY-3692%20(1)\">XXE vulnerability in Assembla Plugin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-06-24\/#SECURITY-3777\">Path traversal vulnerability in External Workspace Manager Plugin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-06-24\/#SECURITY-3649\">Builds executed on the Jenkins controller by OWASP ZAP Plugin can lead to RCE<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-06-24\/#SECURITY-3793\">Script security bypass vulnerability in Script Security Plugin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-06-24\/#SECURITY-3792\">Sandbox bypass vulnerability in Script Security Plugin<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Jenkins Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-629","alert_type":396,"serial_number":"AV26-629","subject":"other","moderation_state":"published","external_url":null},{"nid":7905,"title":"GitLab security advisory (AV26-630)","uuid":"546a2ad7-f2e1-4b76-bf55-b8f019b467e5","banner":null,"lang":"en","date_modified":"2026-06-24","date_modified_ts":"2026-06-24T18:33:22Z","date_created":"2026-06-24T18:17:43Z","summary":null,"body":["<article data-history-node-id=\"7905\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-630\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-630<br \/><strong>Date:<\/strong> June\u00a024, 2026<\/p>\n\n<p>On June\u00a024, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 19.1.1, 19.0.3 and 18.11.6<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 19.1.1, 19.0.3 and 18.11.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-1-1-released\/\">GitLab Patch Release: 19.1.1, 19.0.3, 18.11.6<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-630","alert_type":396,"serial_number":"AV26-630","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7906,"title":"Drupal security advisory (AV26-631)","uuid":"5a004f94-6d48-4388-99ac-6e08897c71a2","banner":null,"lang":"en","date_modified":"2026-06-25","date_modified_ts":"2026-06-25T11:46:41Z","date_created":"2026-06-25T11:37:59Z","summary":null,"body":["<article data-history-node-id=\"7906\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-631\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-631<br \/><strong>Date:<\/strong> June\u00a025, 2026<\/p>\n\n<p>On June\u00a024, 2026, Drupal published security advisories to address vulnerabilities in a number of products. Included were critical updates for the following:<\/p>\n\n<ul><li>Geolocation Field\u00a0\u2013 versions prior to 3.15.0<\/li>\n\t<li>WissKI\u00a0\u2013 versions prior to 4.2.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-062\">Geolocation Field\u00a0- Critical\u00a0- SQL Injection\u00a0- SA-CONTRIB-2026-062<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-059\">WissKI\u00a0- Critical\u00a0- Access bypass - SA-CONTRIB-2026-059<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-631","alert_type":396,"serial_number":"AV26-631","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7907,"title":"HPE security advisory (AV26-632)","uuid":"67631c44-4e79-481e-ba16-3c1c96296586","banner":null,"lang":"en","date_modified":"2026-06-25","date_modified_ts":"2026-06-25T11:47:51Z","date_created":"2026-06-25T11:44:22Z","summary":null,"body":["<article data-history-node-id=\"7907\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-632\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-632<br \/><strong>Date: <\/strong>June 25, 2026<\/p>\n\n<p>On June 24, 2026, HPE published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>HPE Unified Correlation Analyzer (UCA)\u00a0\u2013 versions prior to 4.4.10<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05073en_us&amp;docLocale=en_US#hpesbnw05073-rev-1-hpe-telco-unified-correlation-a-0\">HPESBNW05073 rev.1\u00a0- HPE Telco Unified Correlation and Automation (UCA), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-632","alert_type":396,"serial_number":"AV26-632","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7909,"title":"HPE security advisory (AV26-633)","uuid":"ed1fc7f7-4467-421e-9c7d-5d2a6267391d","banner":null,"lang":"en","date_modified":"2026-06-25","date_modified_ts":"2026-06-25T15:31:48Z","date_created":"2026-06-25T15:28:39Z","summary":null,"body":["<article data-history-node-id=\"7909\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-633\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-633<br \/><strong>Date: <\/strong>June 25, 2026<\/p>\n\n<p>On June 25, 2026, HPE published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>HPE Telco Service Orchestrator\u00a0\u2013 versions prior to v5.6.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05070en_us&amp;docLocale=en_US#hpesbnw05070-rev-1-hpe-telco-service-orchestrator-0\">HPESBNW05070 rev.1\u00a0- HPE Telco Service Orchestrator Software, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-633","alert_type":396,"serial_number":"AV26-633","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7910,"title":"Google Chrome security advisory (AV26-634)","uuid":"45b91fb3-b547-44b1-b330-cebed96dd2bc","banner":null,"lang":"en","date_modified":"2026-06-26","date_modified_ts":"2026-06-26T12:47:53Z","date_created":"2026-06-26T12:43:36Z","summary":null,"body":["<article data-history-node-id=\"7910\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-634\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-634<br \/><strong>Date:<\/strong> June 26, 2026<\/p>\n\n<p>On June 25, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to 149.0.7827.200\/201 (Windows\/Mac), and 149.0.7827.200 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_01245939337.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-634","alert_type":396,"serial_number":"AV26-634","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7911,"title":"Ubuntu security advisory (AV26-635)","uuid":"48505a05-bd17-4355-b572-1d70051b1f80","banner":null,"lang":"en","date_modified":"2026-06-29","date_modified_ts":"2026-06-29T13:30:52Z","date_created":"2026-06-29T13:23:31Z","summary":null,"body":["<article data-history-node-id=\"7911\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-635\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-635<br \/><strong>Date:<\/strong> June\u00a029, 2026<\/p>\n\n<p>Between June\u00a022 and 28, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 26.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-635","alert_type":396,"serial_number":"AV26-635","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7913,"title":"[Control systems] CISA ICS security advisories (AV26-637)","uuid":"2fae2a1b-fc98-420d-a2f2-e2811a89813a","banner":null,"lang":"en","date_modified":"2026-06-29","date_modified_ts":"2026-06-29T13:44:45Z","date_created":"2026-06-29T13:23:32Z","summary":null,"body":["<article data-history-node-id=\"7913\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-637\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-637<br \/><strong>Date:<\/strong> June\u00a029, 2026<\/p>\n\n<p>Between June\u00a022 and 28, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB Freelance Security Lock\u00a0\u2013 all versions<\/li>\n\t<li>B&amp;R Industrial Automation GmbH APROL\u00a0\u2013 versions prior to APROL-AutoYaST-DVD- V4.4-010.10.260602<\/li>\n\t<li>B&amp;R Industrial Automation GmbH Linux for B&amp;R\u00a0\u2013 versions prior to 12<\/li>\n\t<li>B&amp;R Industrial Automation GmbH X20EDS410\u00a0\u2013 all versions<\/li>\n\t<li>Daktronics Controller Firmware VFC-DMP-5000 \/ DMP-8000\u00a0\u2013 multiple versions<\/li>\n\t<li>Delta Electronics DTMSoft\u00a0\u2013 all versions<\/li>\n\t<li>EVoke Systems Charging Station Management System (CSMS)\u00a0\u2013 all versions<\/li>\n\t<li>VIEW HV-500S6 IP Camera\u00a0\u2013 versions prior to IPCAM_V4.06.88.251229<\/li>\n\t<li>Horner Automation Cscape\u00a0\u2013 versions prior to 10.2_SP3<\/li>\n\t<li>Hubbell Aclara Metrum Cellular Web Interface\u00a0\u2013 versions prior to v2.1.0.105<\/li>\n\t<li>OHIF DICOM Web Viewer Framework\u00a0\u2013 versions prior to v3.12.0<\/li>\n\t<li>PowerLogic P7\u00a0\u2013 versions 0.2.003.001.000 and prior<\/li>\n\t<li>pydicom pynetdicom Library\u00a0\u2013 version v1.0.0 to versions prior to v3.0.4<\/li>\n\t<li>Schneider Electric PowerLogic P7\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens Products using OpenSSL\u00a0\u2013 all versions<\/li>\n\t<li>Siemens SINEC INS\u00a0\u2013 versions prior to 1.0.2.6<\/li>\n\t<li>Siemens SIPROTEC 5 Using DIGSI5 Protocol\u00a0\u2013 all versions<\/li>\n\t<li>Siemens WinCC Certificate Manager\u00a0\u2013 all versions<\/li>\n\t<li>Yokogawa Collaborative Information Server (CI Server)\u00a0\u2013 versions R1.01 to R1.04<\/li>\n\t<li>Yokogawa FAST\/TOOLS\u00a0\u2013 versions R9.01 to R10.04<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-637","alert_type":398,"serial_number":"AV26-637","subject":"ics","moderation_state":"published","external_url":null},{"nid":7912,"title":"Red Hat security advisory (AV26-636)","uuid":"318d753c-a771-470b-b676-7f5f5e9c40d1","banner":null,"lang":"en","date_modified":"2026-06-29","date_modified_ts":"2026-06-29T13:34:52Z","date_created":"2026-06-29T13:23:32Z","summary":null,"body":["<article data-history-node-id=\"7912\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-636\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-636<br \/><strong>Date:<\/strong> June\u00a029, 2026<\/p>\n\n<p>Between June\u00a022 and 28, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-636","alert_type":396,"serial_number":"AV26-636","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7916,"title":"IBM security advisory (AV26-639)","uuid":"8f597e0d-9567-4ba4-a99f-d580515ebf0f","banner":null,"lang":"en","date_modified":"2026-06-29","date_modified_ts":"2026-06-29T17:18:19Z","date_created":"2026-06-29T17:07:27Z","summary":null,"body":["<article data-history-node-id=\"7916\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-639\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-639<br \/><strong>Date:<\/strong> June\u00a029, 2026<\/p>\n\n<p>Between June\u00a022 and 28, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Cloud Pak System\u00a0\u2013 version 2.3.5.0<\/li>\n\t<li>IBM Observability with Instana (Agent)\u00a0\u2013 versions Build 1.0.303 to 1.0.319<\/li>\n\t<li>IBM Db2 Big SQL on Cloud Pak for Data\u00a0\u2013 version 5.0<\/li>\n\t<li>IBM Db2 Big SQL on IBM Software Hub\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Engineering Workflow Management\u00a0\u2013 version 7.2, 7.1 and 7.0.3<\/li>\n\t<li>IBM Engineering Requirements Management DOORS Next\u00a0\u2013 version 7.2, 7.1 and 7.0.3<\/li>\n\t<li>Global Configuration Management\u00a0\u2013 version 7.2, 7.1 and 7.0.3<\/li>\n\t<li>Jazz Foundation\u00a0\u2013 version 7.2, 7.1 and 7.0.3<\/li>\n\t<li>Langflow OSS\u00a0\u2013 version 1.0.0 to 1.10.0<\/li>\n\t<li>IBM Engineering Test Management\u00a0\u2013 version 7.2, 7.1 and 7.0.3<\/li>\n\t<li>IBM InfoSphere Information Server\u00a0\u2013 version 11.7.0.0 to 11.7.1.6<\/li>\n\t<li>IBM Operator for PostgreSQL\u00a0\u2013 version v28.3.0 to v28.3.2<\/li>\n\t<li>IBM Spectrum Control\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Sterling Partner Engagement Manager Essentials Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Sterling Partner Engagement Manager Standard Edition\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Storage Defender Copy Data Management\u00a0\u2013 version 2.2.0.0 to 2.3.0.1<\/li>\n\t<li>IBM Storage Protect Plus File Systems Agent\u00a0\u2013 version 10.1.6 to 10.1.18<\/li>\n\t<li>IBM Storage Protect Plus Guest Applications\u00a0\u2013 version 10.1.6 to 10.1.18<\/li>\n\t<li>IBM Storage Protect Plus vSnap\u00a0\u2013 version 10.1 to 10.1.18<\/li>\n\t<li>IBM Storage Protect Plus Server\u00a0\u2013 version 10.1 to 10.1.18<\/li>\n\t<li>IBM Storage Sentinel Anomaly Scan Engine\u00a0\u2013 version 1.1.0 to 2.3.0<\/li>\n\t<li>IBM watsonx Orchestrate Developer Edition\u00a0\u2013 version 1.4.0 to 2.11.0<\/li>\n\t<li>WatsonX BI\u00a0\u2013 version 5.0 to 5.3<\/li>\n\t<li>WebSphere Service Registry and Repository\u00a0\u2013 version 8.5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-639","alert_type":396,"serial_number":"AV26-639","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7915,"title":"Dell security advisory (AV26-638)","uuid":"5204913e-fa5c-4075-81ea-e96e55bb80b4","banner":null,"lang":"en","date_modified":"2026-06-29","date_modified_ts":"2026-06-29T17:12:47Z","date_created":"2026-06-29T17:07:27Z","summary":null,"body":["<article data-history-node-id=\"7915\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-638\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-638<br \/><strong>Date:<\/strong> June\u00a029, 2026<\/p>\n\n<p>Between June\u00a022 and 28, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell PowerProtect Data Manager Appliance DM5510\u00a0\u2013 versions prior to 20.1.0.0<\/li>\n\t<li>Dell Networking OS10\u00a0\u2013 versions prior to 10.6.1.2<\/li>\n\t<li>Dell Private Cloud, Nutanix\u00a0\u2013 versions prior to 01.02.00.00<\/li>\n\t<li>PowerSwitch Z9864F-ON\u00a0\u2013 versions prior to 3.5.0<\/li>\n\t<li>Dell AX System for Azure\u00a0\u2013 versions prior to 2606<\/li>\n\t<li>Dell OpenManage Enterprise Modular\u00a0\u2013 versions prior to 2.20.20<\/li>\n\t<li>Dell iDRAC10\u00a0\u2013 versions prior to 1.30.10.51<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-638","alert_type":396,"serial_number":"AV26-638","subject":"dell","moderation_state":"published","external_url":null},{"nid":7917,"title":"Microsoft Edge security advisory (AV26-640)","uuid":"5db54eb5-6a24-4c93-917a-8226cade97c6","banner":null,"lang":"en","date_modified":"2026-06-29","date_modified_ts":"2026-06-29T17:26:07Z","date_created":"2026-06-29T17:07:28Z","summary":null,"body":["<article data-history-node-id=\"7917\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-640\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-640<br \/><strong>Date:<\/strong> June\u00a029, 2026<\/p>\n\n<p>On June\u00a026, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 149.0.4022.98<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#june-26-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-640","alert_type":396,"serial_number":"AV26-640","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7918,"title":"Apple security advisory (AV26-641)","uuid":"60bd420e-cefc-4084-a0e1-8211bff2032b","banner":null,"lang":"en","date_modified":"2026-06-29","date_modified_ts":"2026-06-29T19:08:08Z","date_created":"2026-06-29T19:03:39Z","summary":null,"body":["<article data-history-node-id=\"7918\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-641\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-641<br \/><strong>Date:<\/strong> June\u00a029, 2026<\/p>\n\n<p>On June\u00a029, 2026, Apple published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\u00a0\u2013 versions prior to 26.5.2<\/li>\n\t<li>macOS Tahoe\u00a0\u2013 versions prior to 26.5.2<\/li>\n\t<li>Safari \u2013 versions prior to 26.5.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/127594\">About the security content of iOS 26.5.2 and iPadOS 26.5.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/127595\">About the security content of macOS Tahoe 26.5.2<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-641","alert_type":396,"serial_number":"AV26-641","subject":"apple","moderation_state":"published","external_url":null},{"nid":7919,"title":"SimpleHelp security advisory (AV26-642)","uuid":"fd4df467-79f5-41d7-83f7-025529f21520","banner":null,"lang":"en","date_modified":"2026-06-30","date_modified_ts":"2026-06-30T12:28:47Z","date_created":"2026-06-30T12:24:09Z","summary":null,"body":["<article data-history-node-id=\"7919\" about=\"\/en\/alerts-advisories\/simplehelp-security-advisory-av26-642\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-642<br \/><strong>Date:<\/strong> June 30, 2026<\/p>\n\n<p>On May 26, 2026, SimpleHelp published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>SimpleHelp \u2013 versions 5.5.0 to versions prior to 5.5.16<\/li>\n\t<li>SimpleHelp \u2013 versions 6.0 to versions prior to 6.0 RC2<\/li>\n<\/ul><p>On June 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-48558 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/simple-help.com\/security\/simplehelp-security-update-2026-05\">SimpleHelp 5.5 and 6.0 Security Fix<\/a><\/li>\n\t<li><a href=\"https:\/\/simple-help.com\/release-news\">SimpleHelp Release News<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48558\">CISA KEV: CVE-2026-48558<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/simplehelp-security-advisory-av26-642","alert_type":396,"serial_number":"AV26-642","subject":"other","moderation_state":"published","external_url":null},{"nid":7920,"title":"wolfSSL security advisory (AV26-643)","uuid":"4bee0c28-fbc6-4cba-b7a7-da90b7d2fc96","banner":null,"lang":"en","date_modified":"2026-06-30","date_modified_ts":"2026-06-30T14:24:25Z","date_created":"2026-06-30T12:31:52Z","summary":null,"body":["<article data-history-node-id=\"7920\" about=\"\/en\/alerts-advisories\/wolfssl-security-advisory-av26-643\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-643<br \/><strong>Date:<\/strong> June 30, 2026<\/p>\n\n<p>On June 23, 2026, wolfSSL published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>wolfSSL \u2013 versions prior to 5.9.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/wolfSSL\/wolfssl\/releases\/tag\/v5.9.2-stable\">wolfSSL Release 5.9.2 (June 23, 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/wolfSSL\/wolfssl\/releases\">wolfSSL<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wolfssl-security-advisory-av26-643","alert_type":396,"serial_number":"AV26-643","subject":"other","moderation_state":"published","external_url":null},{"nid":7921,"title":"Mozilla security advisory (AV26-644)","uuid":"e3ab4da6-83fb-4f7e-943c-3339b0f7a1c3","banner":null,"lang":"en","date_modified":"2026-06-30","date_modified_ts":"2026-06-30T17:38:29Z","date_created":"2026-06-30T17:31:20Z","summary":null,"body":["<article data-history-node-id=\"7921\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-644\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-644<br \/><strong>Date: <\/strong>June 30, 2026<\/p>\n\n<p>On June 30, 2026, Mozilla published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Firefox\u00a0\u2013 versions prior to 152.04<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 140.12.1<\/li>\n\t<li>Thunderbird\u00a0\u2013 versions prior to 152.01<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-62\/\">Mozilla Foundation Security Advisory 2026-62<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-644","alert_type":396,"serial_number":"AV26-644","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7922,"title":"Citrix security advisory (AV26-645) \u2013 Update 3","uuid":"a96d4289-e5f2-4f48-b4c9-790d692d59db","banner":null,"lang":"en","date_modified":"2026-08-26","date_modified_ts":"2026-08-26T18:27:03Z","date_created":"2026-06-30T17:44:47Z","summary":null,"body":["<article data-history-node-id=\"7922\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-645\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-645<br \/><strong>Date:<\/strong> June\u00a030, 2026<br \/><strong>Updated:<\/strong> August\u00a026, 2026<\/p>\n\n<p>On June\u00a030, 2026, Citrix published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway\u00a0- versions 14.1\u202fbefore 14.1-72.61<\/li>\n\t<li>NetScaler ADC and NetScaler Gateway\u00a0- versions 13.1\u202fbefore 13.1-63.18<\/li>\n\t<li>NetScaler ADC FIPS\u00a0\u2013 versions before 14.1-72.61 FIPS<\/li>\n\t<li>NetScaler ADC FIPS and NDcPP\u00a0\u2013 versions before 13.1-37.272<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-8451 is being exploited.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-8452 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 3<\/h2>\n\n<p>On August\u00a026, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8452 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696604\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\">Citrix Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8452\">CISA KEV: CVE-2026-8452<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av26-645","alert_type":396,"serial_number":"AV26-645","subject":"citrix","moderation_state":"published","external_url":null},{"nid":7924,"title":"AL26-015 - Critical vulnerability impacting Microsoft SharePoint Server \u2013 CVE-2026-45659","uuid":"9b7b08db-ac74-46a1-b382-77115fd02d49","banner":null,"lang":"en","date_modified":"2026-07-02","date_modified_ts":"2026-07-02T14:37:55Z","date_created":"2026-07-02T14:07:29Z","summary":null,"body":["<article data-history-node-id=\"7924\" about=\"\/en\/alerts-advisories\/al26-015-critical-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-45659\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-015<br \/><strong>Date:<\/strong> July 2, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint Server. In response to the Microsoft security advisory, released on May 21, 2026<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, the Cyber Centre issued AV26-456<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> Update 1 on May 21, 2026.<\/p>\n\n<p>Tracked as CVE-2026-45659<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is a critical Deserialization of Untrusted Data (CWE-502)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> vulnerability affecting multiple versions of Microsoft SharePoint Server and could allow a low privileged remote attacker to execute remote code.<\/p>\n\n<p>This vulnerability was added to the Cybersecurity and Infrastructure Security Agency\u2019s (CISA) Known Exploited Vulnerabilities (KEV) catalog<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> on July 1, 2026.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th>Affected Product<\/th>\n\t\t\t<th>Affected Versions<\/th>\n\t\t\t<th>Fixed Versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Microsoft SharePoint Enterprise Server 2016<\/td>\n\t\t\t<td>16.0.0 before 16.0.5552.1002<\/td>\n\t\t\t<td>16.0.5552.1002<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server 2019<\/td>\n\t\t\t<td>16.0.0 before 16.0.10417.20128<\/td>\n\t\t\t<td>16.0.10417.20128<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server Subscription Edition<\/td>\n\t\t\t<td>16.0.0 before 16.0.19725.20280<\/td>\n\t\t\t<td>16.0.19725.20280<\/td>\n\t\t<\/tr><\/tbody><\/table><\/div>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Identify all on-premises SharePoint Server instances, particularly those exposed to the internet.<\/li>\n\t<li>Use or upgrade to supported versions of on-premises Microsoft SharePoint Server.<\/li>\n\t<li>Apply the latest security updates from Microsoft.<\/li>\n<\/ul><p><strong>Important note:<\/strong> Microsoft SharePoint Enterprise Server 2016<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> and Server 2019<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> will be <strong>end of life<\/strong> on <strong>July 14, 2026<\/strong>. Organizations are urged to migrate to a supported version.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions with an emphasis on the following topics<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45659\">Microsoft SharePoint Remote Code Execution Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/microsoft-security-advisory-may-2026-monthly-rollup-av26-456\">Microsoft security advisory\u00a0\u2013 May 2026 monthly rollup (AV26-456)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-45659\">NVD\u00a0\u2013 CVE-2026-45659<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/502.html\">CWE-502: Deserialization of Untrusted Data<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659\">CISA KEV\u00a0\u2013 CVE-2026-45659<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2016\">SharePoint Server 2016\u00a0- Microsoft Lifecycle<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2019\">SharePoint Server 2019\u00a0- Microsoft Lifecycle<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-015-critical-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-45659","alert_type":397,"serial_number":"AL26-015","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7925,"title":"Cisco security advisory (AV26-646)","uuid":"c45e100b-769b-496d-91ba-76b5ba3f4930","banner":null,"lang":"en","date_modified":"2026-07-02","date_modified_ts":"2026-07-02T17:07:37Z","date_created":"2026-07-02T16:54:40Z","summary":null,"body":["<article data-history-node-id=\"7925\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-646\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-646<br \/><strong>Date:<\/strong> July 2, 2026<\/p>\n\n<p>On July 1, 2026, Cisco published security advisories to address vulnerabilities in the following:<\/p>\n\n<ul><li>Cisco Catalyst Center Release 2.3.7\u00a0\u2013 versions prior to 2.3.7.11-VA GSMU100<\/li>\n\t<li>Cisco Catalyst Center Release 3.1\u00a0- versions prior to 3.1.6 GSMU200<\/li>\n\t<li>Secure Endpoint Connector\u00a0- multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-catc-file-read-wLH2vf8X\">Cisco Catalyst Center Arbitrary File Read Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-clamav-88cFYyxR\">ClamAV Vulnerabilities Affecting Cisco Products: July 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-646","alert_type":396,"serial_number":"AV26-646","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7926,"title":"Adobe security advisory (AV26-647) \u2013 Update 2","uuid":"34d3cdd2-32ec-4e63-ab73-89f941c3c4c8","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T19:49:45Z","date_created":"2026-07-02T17:17:16Z","summary":null,"body":["<article data-history-node-id=\"7926\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-647\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26\u2013647<br \/><strong>Date:<\/strong> July 2, 2026<br \/><strong>Updated:<\/strong> July 7, 2026<\/p>\n\n<p>On June 30, 2026, Adobe published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe ColdFusion 2025\u00a0\u2013 Update 9 and prior<\/li>\n\t<li>Adobe ColdFusion 2023\u00a0\u2013 Update 20 and prior<\/li>\n\t<li>Adobe Campaign Classic\u00a0\u2013 version ACC v7: 7.4.3 build 9396 and prior<\/li>\n<\/ul><h2>Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-48282 is being exploited.<\/p>\n\n<h2>Update 2<\/h2>\n\n<p>On July 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-48282 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb26-68.html\">Security update available for Adobe ColdFusion | APSB26-68<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-69.html\">Security updates available for Adobe Campaign Classic | APSB26-69<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282\">CISA KEV: CVE-2026-48282<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-647","alert_type":396,"serial_number":"AV26-647","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7927,"title":"Google Chrome security advisory (AV26-648)","uuid":"e4e15b22-0334-45b3-b72a-5acf199624da","banner":null,"lang":"en","date_modified":"2026-07-02","date_modified_ts":"2026-07-02T17:49:35Z","date_created":"2026-07-02T17:44:13Z","summary":null,"body":["<article data-history-node-id=\"7927\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-648\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-648<br \/><strong>Date:<\/strong> July 2, 2026<\/p>\n\n<p>On June 30, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 150.0.7871.46\/47 (Windows\/Mac), and 150.0.7871.46 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_0175352312.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-648","alert_type":396,"serial_number":"AV26-648","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7928,"title":"AL26-016 - Vulnerability impacting Citrix NetScaler CVE-2026-8451","uuid":"325a69d2-85e5-40c2-a662-c8daee4811c0","banner":null,"lang":"en","date_modified":"2026-07-02","date_modified_ts":"2026-07-02T19:04:51Z","date_created":"2026-07-02T18:19:28Z","summary":null,"body":["<article data-history-node-id=\"7928\" about=\"\/en\/alerts-advisories\/al26-016-vulnerability-impacting-citrix-netscaler-cve-2026-8451\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-016<br \/><strong>Date:<\/strong> July 2, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of a vulnerability impacting NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS (Federal Information Processing Standards)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. In response to the vendor advisory released on June\u00a030,\u00a02026, the Cyber Centre released AV26-645 on June\u00a030,\u00a02026<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>.<\/p>\n\n<p>Tracked as CVE-2026-8451<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>, this vulnerability is an insufficient input validation (CWE-125)<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> vulnerability affecting many NetScaler ADC and NetScaler Gateway versions. If exploited, this vulnerability can lead to memory overread, if NetScaler ADC or NetScaler Gateway is configured as a Security Assertion Markup Language (SAML) Identity Provider (idP).<\/p>\n\n<p>The vulnerability only impacts customer-managed NetScaler ADC and NetScaler Gateway. The cloud services managed by Citrix have been upgraded with the necessary software updates related to this vulnerability.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations using Citrix NetScaler ADC, NetScaler Gateway, NetScaler ADC FIPS and NFcPP<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> appliances update or upgrade the affected systems to the following versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected Product<\/th>\n\t\t\t<th scope=\"col\">Affected Versions<\/th>\n\t\t\t<th scope=\"col\">Fixed Versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>NetScaler ADC and NetScaler Gateway 14.1<\/td>\n\t\t\t<td>14.1 before 14.1-72.61<\/td>\n\t\t\t<td>14.1-72.61<\/td>\n\t\t<\/tr><tr><td>NetScaler ADC and NetScaler Gateway 13.1<\/td>\n\t\t\t<td>13.1 before 13.1-63.18<\/td>\n\t\t\t<td>13.1-63.18<\/td>\n\t\t<\/tr><tr><td>NetScaler ADC FIPS<\/td>\n\t\t\t<td>versions prior to 14.1-72.61 FIPS<\/td>\n\t\t\t<td>14.1-72.61<\/td>\n\t\t<\/tr><tr><td>NetScaler ADC FIPS and NDcPP<\/td>\n\t\t\t<td>versions prior to 13.1-37.272<\/td>\n\t\t\t<td>13.1-37.272<\/td>\n\t\t<\/tr><\/tbody><\/table><\/div>\n\n<p>The Cyber Centre recommends following Citrix guidance if NetScaler ADC or NetScaler Gateway are suspected to be compromised<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696604\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/community.citrix.com\/techzone-blogs\/110_security-updates\/security-update-for-citrix-netscaler-and-netscaler-gateway-customers-r1570\/\">Security update for Citrix NetScaler and NetScaler Gateway customers\u00a0- Security Updates<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-645\">AV26-645 \u2013 Citrix security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-8451\">CVE-2026-8451 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/125.html\">CWE-125: Out-of-bounds Read<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694799\">Citrix\u00a0\u2013 Steps to Take if NetScaler ADC is Suspected to be Compromised<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-016-vulnerability-impacting-citrix-netscaler-cve-2026-8451","alert_type":397,"serial_number":"AL26-016","subject":"citrix","moderation_state":"published","external_url":null},{"nid":7929,"title":"WatchGuard security advisory (AV26-649)","uuid":"297df359-eccd-4a1f-9462-83722053cc4c","banner":null,"lang":"en","date_modified":"2026-07-03","date_modified_ts":"2026-07-03T14:26:17Z","date_created":"2026-07-03T14:20:22Z","summary":null,"body":["<article data-history-node-id=\"7929\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-649\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-649<br \/><strong>Date:<\/strong> July\u00a03, 2026<\/p>\n\n<p>On July\u00a02, 2026, WatchGuard published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Fireware OS 2025.1\u00a0\u2013 version 2026.2 and prior<\/li>\n\t<li>Fireware OS 11.x\u00a0- version 11.12.4_Update1 and prior<\/li>\n\t<li>Fireware OS 12.0\u00a0\u2013 version 12.12 and prior<\/li>\n\t<li>Fireware OS 12.5\u00a0\u2013 version 12.5.18 and prior<\/li>\n\t<li>Mobile VPN with SSL client for Windows\u00a0\u2013 version 2026.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00023\">WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2026-00027\">WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-649","alert_type":396,"serial_number":"AV26-649","subject":"other","moderation_state":"published","external_url":null},{"nid":7930,"title":"GitHub security advisory (AV26-650)","uuid":"e2b86e72-f96a-4ca7-90f8-d6a41d0ddf35","banner":null,"lang":"en","date_modified":"2026-07-03","date_modified_ts":"2026-07-03T18:36:09Z","date_created":"2026-07-03T18:22:26Z","summary":null,"body":["<article data-history-node-id=\"7930\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-650\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-650<br \/><strong>Date:<\/strong> July\u00a03, 2026<\/p>\n\n<p>On June\u00a030, 2026, GitHub published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.21.x prior to 3.21.2<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.20.x prior to 3.20.4<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.8<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.11<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.17<\/li>\n<\/ul><p><strong>GitHub has stated that future patches and releases will be signed with a new public key, and customers will need to rotate to the new key before those patches and releases can be installed.<\/strong><\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.21\/admin\/release-notes\">Enterprise Server 3.21.2<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.20\/admin\/release-notes\">Enterprise Server 3.20.4<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.8<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.11<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.17<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-650","alert_type":396,"serial_number":"AV26-650","subject":"other","moderation_state":"published","external_url":null},{"nid":7931,"title":"Erlang security advisory (AV26-651)","uuid":"e1772ba6-3f06-4c87-8b88-365c98bbbc34","banner":null,"lang":"en","date_modified":"2026-07-03","date_modified_ts":"2026-07-03T18:41:41Z","date_created":"2026-07-03T18:22:27Z","summary":null,"body":["<article data-history-node-id=\"7931\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av26-651\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-651<br \/><strong>Date:<\/strong> July\u00a03, 2026<\/p>\n\n<p>On July\u00a02, 2026, Erlang published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>OTP\u00a0\u2013 versions prior to 27.3.4.14, 28.5.0.3 and 29.0.3<\/li>\n\t<li>SSL (OTP)\u00a0\u2013 versions prior to 11.7.3, 11.6.0.3 and 11.2.12.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-8c57-44c9-pc59\">Denial-of-Service for TLS-1.3 server Using Session Tickets<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/GHSA-hwfc-5hf4-gvr3\">DTLS Denial of Service<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\">Erlang Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av26-651","alert_type":396,"serial_number":"AV26-651","subject":"other","moderation_state":"published","external_url":null},{"nid":7932,"title":"Red Hat security advisory (AV26-652)","uuid":"76496ee4-c772-459d-af47-76ec06bc068a","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T13:05:14Z","date_created":"2026-07-06T13:01:25Z","summary":null,"body":["<article data-history-node-id=\"7932\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-652\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-652<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>Between June 29 and July 5, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux \u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server \u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-652","alert_type":396,"serial_number":"AV26-652","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7933,"title":"Ubuntu security advisory (AV26-653)","uuid":"ee1c5f63-9fe1-4beb-ae13-6a81e6dab16f","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T13:10:41Z","date_created":"2026-07-06T13:07:57Z","summary":null,"body":["<article data-history-node-id=\"7933\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-653\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-653<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>Between June 29 and July 5, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n\t<li>Ubuntu 26.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-653","alert_type":396,"serial_number":"AV26-653","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7934,"title":"Dell security advisory (AV26-654)","uuid":"9a6390fd-cc8d-4591-b6ba-6a77e599c65a","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T13:16:37Z","date_created":"2026-07-06T13:12:04Z","summary":null,"body":["<article data-history-node-id=\"7934\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-654\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-654<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>Between June 29 and July 5, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Cyber Recovery \u2013 versions prior to 20.1.0.0<\/li>\n\t<li>Dell Data Protection Advisor \u2013 versions 19.9 to 19.12 SP2<\/li>\n\t<li>Dell Networker \u2013 versions prior to 8.0.29<\/li>\n\t<li>Dell Networker \u2013 versions prior to 17.0.5<\/li>\n\t<li>Dell OpenManage Enterprise Modular \u2013 versions prior to 20.20.20<\/li>\n\t<li>Dell PowerProtect Cyber Recovery \u2013 versions prior to cyber-recovery-osupdate-15.4.0-18.bin<\/li>\n\t<li>Dell PowerProtect Data Manager Appliance DM5500 \u2013 versions prior to 5.20.1.0<\/li>\n\t<li>SupportAssist for Business PCs \u2013 versions prior to 5.1.1.3567<\/li>\n\t<li>SupportAssist for Home PCs \u2013 versions prior to 5.0.2.2900<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-654","alert_type":396,"serial_number":"AV26-654","subject":"dell","moderation_state":"published","external_url":null},{"nid":7935,"title":"[Control systems] CISA ICS security advisories (AV26\u2013655)","uuid":"3d3bc744-247f-4cb4-9124-ae99849c987e","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T13:26:59Z","date_created":"2026-07-06T13:18:43Z","summary":null,"body":["<article data-history-node-id=\"7935\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-655\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26\u2013655<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>Between June 29 and July 5, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>CubeSpace CW0057 Reaction Wheel \u2013 CW0057 Reaction Wheel<\/li>\n\t<li>Delta Electronics DVP12SE PLC \u2013 all versions<\/li>\n\t<li>Frangoteam FUXA SCADA\/HMI \u2013 versions 1.3.1 and prior<\/li>\n\t<li>Gardyn IoT Hub \u2013 versions prior to 2.12.2026<\/li>\n\t<li>Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M \u2013 versions 1.000A to versions 1.014Q and prior<\/li>\n\t<li>OFFIS DCMTK Toolkit \u2013 versions 3.7.0 and prior<\/li>\n\t<li>Schneider Electric EasyLogic T150 and Saitel DP RTU \u2013 multiple versions<\/li>\n\t<li>Schneider Electric EcoStruxure IT Data Center Expert \u2013 versions 9.1.1 and prior, 9,12<\/li>\n\t<li>ST Engineering iDirect iQ-Series Terminals \u2013 multiple versions<\/li>\n\t<li>StoneFly Storage Concentrator \u2013 multiple versions<\/li>\n\t<li>XZ Utils vulnerability impacting B&amp;R Products \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-655","alert_type":398,"serial_number":"AV26-655","subject":"other","moderation_state":"published","external_url":null},{"nid":7936,"title":"IBM security advisory (AV26-656)","uuid":"aa38ee9b-dd52-46f1-81c5-6ee28194e3fd","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T13:38:12Z","date_created":"2026-07-06T13:32:19Z","summary":null,"body":["<article data-history-node-id=\"7936\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-656\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-656<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>Between June 29 and July 5, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Automation Assets in IBM Cloud Pak for Integration (CP4I) \u2013 multiple versions<\/li>\n\t<li>HMC V10.3.1050.0 \u2013 versions V10.3.1050.0 to V10.3.1064.0<\/li>\n\t<li>HMC V11.1.1110.0 \u2013 versions V11.1.1110.0 to V11.1.1111.5<\/li>\n\t<li>IBM Bob \u2013 versions 1.0.0, 1.0.1 and 1.0.2<\/li>\n\t<li>IBM App Connect Operator \u2013 multiple versions<\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands \u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Insights \u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Manager Open Editions \u2013 versions 9.0.0 to 9.4.2<\/li>\n\t<li>IBM Business Automation Workflow traditional \u2013 multiple versions<\/li>\n\t<li>IBM Business Automation Workflow Enterprise Service Bus \u2013 multiple versions<\/li>\n\t<li>IBM Cloud Pak for Business Automation \u2013 multiple versions<\/li>\n\t<li>IBM DataPower Gateway \u2013 multiple models and versions<\/li>\n\t<li>IBM DataStax Enterprise \u2013 versions 6.9.0 to 6.9.22<\/li>\n\t<li>IBM Db2 Genius Hub \u2013 versions 1.1, 1.1.1 and 1.1.2<\/li>\n\t<li>IBM EntireX \u2013 version 11.1<\/li>\n\t<li>IBM Event Endpoint Management \u2013 versions 11.0.0 to 11.7.4<\/li>\n\t<li>IBM Integrated Analytics System \u2013 versions 1.0.0.0 to 1.0.30.0<\/li>\n\t<li>IBM Library Support for Spring \u2013 version 2.7<\/li>\n\t<li>IBM Quantum Safe Remediator \u2013 versions 1.1 to 1.1.2<\/li>\n\t<li>IBM Rational ClearQuest \u2013 versions 9.1 to 9.1.0.11 and 10.0 to 10.0.10<\/li>\n\t<li>IBM SPSS Modeler \u2013 version 19.0.0.0<\/li>\n\t<li>IBM Tivoli Monitoring \u2013 versions 6.3.0.7 to 6.3.0.7 Service Pack 22<\/li>\n\t<li>IBM Tivoli Netcool Configuration Impact \u2013 version 7.1.1<\/li>\n\t<li>IBM Tivoli Netcool Configuration Manager \u2013 versions 6.4.2 GA to 6.4.2.24<\/li>\n\t<li>IBM Tivoli System Automation Application Manager \u2013 version 4.1<\/li>\n\t<li>IBM webMethods Integration (on prem) \u2013 versions 10.15 and 10.11<\/li>\n\t<li>Langflow OSS \u2013 versions 1.0.0 to 1.10.0<\/li>\n\t<li>Maximo AI Service \u2013 version 9.1.0<\/li>\n\t<li>Platform Navigator in IBM Cloud Pak for Integration (CP4I) \u2013 multiple versions<\/li>\n\t<li>PowerVM Novalink \u2013 multiple versions<\/li>\n\t<li>WebSphere Application Server \u2013 versions 8.5 and 9.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-656","alert_type":396,"serial_number":"AV26-656","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7937,"title":"Roundcube security advisory (AV26-657)","uuid":"3a0393ef-d5fa-442d-ac20-81178ba6eda9","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T13:45:28Z","date_created":"2026-07-06T13:40:16Z","summary":null,"body":["<article data-history-node-id=\"7937\" about=\"\/en\/alerts-advisories\/roundcube-security-advisory-av26-657\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-657<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>On July 5, 2026, Roundcube published security advisories to address vulnerabilities in the following product:\u00a0<\/p>\n\n<ul><li>Roundcube Webmail \u2013 versions prior to 1.6.17<\/li>\n\t<li>Roundcube Webmail \u2013 versions prior to 1.7.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/roundcube.net\/news\/2026\/07\/05\/security-updates-1.6.17-and-1.7.2\">Security updates 1.6.17 and 1.7.2 released<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.6.17\">Roundcube Webmail 1.6.17<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.7.2\">Roundcube Webmail 1.7.2<\/a><\/li>\n\t<li><a href=\"https:\/\/roundcube.net\/\">Roundcube Open Source Webmail Software<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/roundcube-security-advisory-av26-657","alert_type":396,"serial_number":"AV26-657","subject":"other","moderation_state":"published","external_url":null},{"nid":7938,"title":"OpenSSH security advisory (AV26-658)","uuid":"32cba620-2ecb-4f58-9632-d5305791f0d9","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T13:51:57Z","date_created":"2026-07-06T13:47:33Z","summary":null,"body":["<article data-history-node-id=\"7938\" about=\"\/en\/alerts-advisories\/openssh-security-advisory-av26-658\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-658<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>On July 6, 2026, OpenSSH published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSH \u2013 versions prior to 10.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.openssh.org\/releasenotes.html\">OpenSSH 10.4 Release Notes<\/a> \u00a0<\/li>\n\t<li><a href=\"https:\/\/www.openssh.com\/\">OpenSSH<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssh-security-advisory-av26-658","alert_type":396,"serial_number":"AV26-658","subject":"other","moderation_state":"published","external_url":null},{"nid":7939,"title":"Microsoft Edge security advisory (AV26-659)","uuid":"336d3a5e-9c69-49d6-a748-ad03f1454979","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T15:14:40Z","date_created":"2026-07-06T15:10:35Z","summary":null,"body":["<article data-history-node-id=\"7939\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-659\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-659<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>On July 2, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel \u2013 versions prior to 150.0.4078.48<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-2-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-659","alert_type":396,"serial_number":"AV26-659","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7940,"title":"BeyondTrust security advisory (AV26-660)","uuid":"47762838-ae26-4ff1-9499-332fed1edfaa","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T17:50:31Z","date_created":"2026-07-06T17:46:30Z","summary":null,"body":["<article data-history-node-id=\"7940\" about=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-660\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-660<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>On June 21, 2026, BeyondTrust published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Remote Support \u2013 version 25.3.2 and prior<\/li>\n\t<li>Privileged Remote Access \u2013 version 25.3.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt26-03\">BeyondTrust Security Advisory - Advisory ID: BT26-03<\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\">BeyondTrust Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-660","alert_type":396,"serial_number":"AV26-660","subject":"other","moderation_state":"published","external_url":null},{"nid":7941,"title":"Qualcomm security advisory \u2013 July 2026 monthly rollup (AV26-661)","uuid":"c8699a9a-68e0-4cd5-9d35-5dec603ef936","banner":null,"lang":"en","date_modified":"2026-07-06","date_modified_ts":"2026-07-06T18:46:42Z","date_created":"2026-07-06T18:44:02Z","summary":null,"body":["<article data-history-node-id=\"7941\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-july-2026-monthly-rollup-av26-661\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-661<br \/><strong>Date:<\/strong> July 6, 2026<\/p>\n\n<p>On July 6, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/july-2026-bulletin.html\">July 2026 Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-july-2026-monthly-rollup-av26-661","alert_type":396,"serial_number":"AV26-661","subject":"other","moderation_state":"published","external_url":null},{"nid":7945,"title":"[Control systems] ABB security advisory (AV26-664)","uuid":"99ab12e6-8595-44cc-909a-93a35a590c6e","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T15:32:18Z","date_created":"2026-07-07T13:12:26Z","summary":null,"body":["<article data-history-node-id=\"7945\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-664\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-664<br \/><strong>Date: <\/strong>July\u00a07, 2026<\/p>\n\n<p>On July\u00a06, 2026, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ABB Ability zenon\u00a0\u2013 all versions<\/li>\n\t<li>APROL\u00a0\u2013 versions prior to R 4.4-01P5<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=9AKK108472A7840&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">ABB Ability zenon Remote Transport Vulnerability (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/br-cws-assets.de-fra-1.linodeobjects.com\/SA26P011-661853b7.pdf\">Security Issues addressed in APROL R 4.4-01P5 (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-664","alert_type":398,"serial_number":"AV26-664","subject":"abb","moderation_state":"published","external_url":null},{"nid":7944,"title":"Broadcom VMware security advisory (AV26-663)","uuid":"768a59d1-1eb8-45ff-966f-5b15f4213162","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T15:31:37Z","date_created":"2026-07-07T13:12:26Z","summary":null,"body":["<article data-history-node-id=\"7944\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-663\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-633<br \/><strong>Date: <\/strong>July\u00a07, 2026<\/p>\n\n<p>On July\u00a06, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>VMware Tanzu for MySQL on Kubernetes\u00a0\u2013 versions prior to 2.0.4<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37858\">Product Release Advisory\u00a0- VMware Tanzu for MySQL on Kubernetes 2.0.4<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-663","alert_type":396,"serial_number":"AV26-663","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7943,"title":"Android security advisory \u2013 July 2026 monthly rollup (AV26-662)","uuid":"a4af5223-0cb9-4e6c-b44d-70a520c5e0ce","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T15:30:22Z","date_created":"2026-07-07T13:12:26Z","summary":null,"body":["<article data-history-node-id=\"7943\" about=\"\/en\/alerts-advisories\/android-security-advisory-july-2026-monthly-rollup-av26-662\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-662<br \/><strong>Date: <\/strong>July\u00a07, 2026<\/p>\n\n<p>On July\u00a06, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-07-01\">Android Security Bulletin\u00a0\u2014 July 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-july-2026-monthly-rollup-av26-662","alert_type":396,"serial_number":"AV26-662","subject":"android","moderation_state":"published","external_url":null},{"nid":7946,"title":"Samsung mobile security advisory (AV26-665)","uuid":"3f8515a1-d3d4-4310-b29a-014f7028f134","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T15:37:11Z","date_created":"2026-07-07T15:32:53Z","summary":null,"body":["<article data-history-node-id=\"7946\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-665\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-665<br \/><strong>Date:<\/strong> July\u00a07, 2026<\/p>\n\n<p>On July\u00a07, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices\u00a0\u2013 versions prior to SMR-JUL-2026 Release 1<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=07\">Samsung Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-665","alert_type":396,"serial_number":"AV26-665","subject":"other","moderation_state":"published","external_url":null},{"nid":7948,"title":"Zimbra security advisory (AV26-667)","uuid":"a9c22345-ed49-4657-af81-8126310be9a0","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T15:44:00Z","date_created":"2026-07-07T15:32:53Z","summary":null,"body":["<article data-history-node-id=\"7948\" about=\"\/en\/alerts-advisories\/zimbra-security-advisory-av26-667\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-667<br \/><strong>Date: <\/strong>July\u00a07, 2026<\/p>\n\n<p>On July\u00a07, 2026, Zimbra published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Zimbra Collaboration Suite (ZCS) Classic Web Client\u00a0\u2013 versions prior to v10.1.19<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.zimbra.com\/2026\/07\/patch-release-update-zimbra-10-1-19\/\">Patch Release Update: Zimbra 10.1.19<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.zimbra.com\/\">Zimbra Patch Release Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zimbra-security-advisory-av26-667","alert_type":396,"serial_number":"AV26-667","subject":"other","moderation_state":"published","external_url":null},{"nid":7947,"title":"Django security advisory (AV26-666)","uuid":"8f4adb8a-1196-4dca-a104-af4440c6c827","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T15:40:38Z","date_created":"2026-07-07T15:32:53Z","summary":null,"body":["<article data-history-node-id=\"7947\" about=\"\/en\/alerts-advisories\/django-security-advisory-av26-666\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-666<br \/><strong>Date:<\/strong> July\u00a07, 2026<\/p>\n\n<p>On July\u00a07, 2026, Django published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Django 5.2\u00a0\u2013 versions prior to 5.2.16<\/li>\n\t<li>Django 6.0\u00a0\u2013 versions prior to 6.0.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.djangoproject.com\/weblog\/2026\/jul\/07\/security-releases\/\">Django Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/django-security-advisory-av26-666","alert_type":396,"serial_number":"AV26-666","subject":"other","moderation_state":"published","external_url":null},{"nid":7950,"title":"HPE security advisory (AV26-668)","uuid":"a9ac16bf-1488-4c07-b18b-85adcc136c5c","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T19:35:43Z","date_created":"2026-07-07T19:29:58Z","summary":null,"body":["<article data-history-node-id=\"7950\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-668\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-668<br \/><strong>Date:<\/strong> July 7, 2026<\/p>\n\n<p>On July 7, 2026, HPE published security advisories to address vulnerabilities in multiple products. Included were updates for the following:<\/p>\n\n<ul><li>HPE Aruba Networking Private 5G Core \u2013 1.26.1.0 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05077en_us&amp;docLocale=en_US\">HPESBNW05077 rev.1 - HPE Networking Private 5G Core, Multiple vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-668","alert_type":396,"serial_number":"AV26-668","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7951,"title":"Google Chrome security advisory (AV26-669)","uuid":"38fb2ce4-735b-47b0-bdd0-bbc4a7c6ff54","banner":null,"lang":"en","date_modified":"2026-07-07","date_modified_ts":"2026-07-07T19:47:13Z","date_created":"2026-07-07T19:39:38Z","summary":null,"body":["<article data-history-node-id=\"7951\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-669\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-669<br \/><strong>Date:<\/strong> July 7, 2026<\/p>\n\n<p>On July 7, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop \u2013 versions prior to0.7871.100\/101 (Windows\/Mac), and 150.0.7871.100 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop.html\" rel=\"nofollow noopener\" target=\"_blank\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-669","alert_type":396,"serial_number":"AV26-669","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7952,"title":"Langflow security advisory (AV26-670)","uuid":"5a873eec-b986-46fc-a60c-4fac8656f8eb","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T13:05:23Z","date_created":"2026-07-08T13:00:49Z","summary":null,"body":["<article data-history-node-id=\"7952\" about=\"\/en\/alerts-advisories\/langflow-security-advisory-av26-670\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-670<br \/><strong>Date: <\/strong>July 8, 2026<\/p>\n\n<p>On July 7, 2026, Langflow updated a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Langflow\u00a0\u2013 versions prior to 1.9.1<\/li>\n<\/ul><p>On July 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisories.gitlab.com\/pypi\/langflow\/CVE-2026-55255\/\">CVE-2026-55255: Langflow: IDOR Vulnerability in `\/api\/v1\/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55255\">CISA KEV: CVE-2026-55255<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/langflow-security-advisory-av26-670","alert_type":396,"serial_number":"AV26-670","subject":"other","moderation_state":"published","external_url":null},{"nid":7953,"title":"Ubiquiti security advisory (AV26-671)","uuid":"872a4ec3-efaa-407d-98f2-c0e346cbe0ef","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T15:16:36Z","date_created":"2026-07-08T15:07:33Z","summary":null,"body":["<article data-history-node-id=\"7953\" about=\"\/en\/alerts-advisories\/cyber-n8n-security-advisory-av26-672\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-671<br \/><strong>Date: <\/strong>July 8, 2026<\/p>\n\n<p>On July 2, 2026, Ubiquiti published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>EF-Core\u00a0\u2013 version 5.1.18 and prior<\/li>\n\t<li>EFG\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>ENVR\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>ENVR-Core\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>Express 7\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UCG-Fiber\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UCG-Industrial\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UCG-Max\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UCG-Ultra\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UCK\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UCK-Enterprise\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UCKP\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDM\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDM-Beast\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDM-Pro\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDM-Pro\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDM-Pro-Max\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDM-SE\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDR\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDR-5G\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDR7\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UDW\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UNAS-2\u00a0\u2013 version 5.1.16 and prior<\/li>\n\t<li>UNAS-4\u00a0\u2013 version 5.1.16 and prior<\/li>\n\t<li>UNAS-Pro\u00a0\u2013 version 5.1.16 and prior<\/li>\n\t<li>UNAS-Pro-4\u00a0\u2013 version 5.1.16 and prior<\/li>\n\t<li>UNAS-Pro-8\u00a0\u2013 version 5.1.16 and prior<\/li>\n\t<li>UniFi Access Application\u00a0\u2013 version 4.2.28 and prior<\/li>\n\t<li>UniFi Network Application\u00a0\u2013 version 10.3.58 and prior<\/li>\n\t<li>UniFi OS Server\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UniFi Protect Application\u00a0\u2013 version 7.1.77 and prior<\/li>\n\t<li>UniFi Protect Floodlight\u00a0\u2013 version 1.13.4 and prior<\/li>\n\t<li>UniFi Talk Application\u00a0\u2013 version 5.1.2 and prior<\/li>\n\t<li>UNVR\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UNVR-G2\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UNVR-G2-Pro\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UNVR-Instant\u00a0\u2013 version 5.1.15 and prior<\/li>\n\t<li>UNVR-Pro\u00a0\u2013 version 5.1.15 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.ui.com\/releases\/Security-Advisory-Bulletin-066-066\/984eceb3-49c8-4227-942d-671c289b3afc\">Ubiquiti UniFi\u00a0- Security Advisory Bulletin 066<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cyber-n8n-security-advisory-av26-672","alert_type":396,"serial_number":"AV26-671","subject":"other","moderation_state":"published","external_url":null},{"nid":7954,"title":"n8n security advisory (AV26-672)","uuid":"b678db2a-1dcc-4aad-ac3f-d1f0648dd6fe","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T15:22:10Z","date_created":"2026-07-08T15:18:04Z","summary":null,"body":["<article data-history-node-id=\"7954\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-672\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-672<br \/><strong>Date: <\/strong>July 8, 2026<\/p>\n\n<p>On July 8, 2026, n8n published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>n8n\u00a0\u2013 versions prior to 1.123.64<\/li>\n\t<li>n8n\u00a0\u2013 versions prior to 2.30.1<\/li>\n\t<li>n8n\u00a0\u2013 versions prior to 2.29.8<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-672","alert_type":396,"serial_number":"AV26-672","subject":"other","moderation_state":"published","external_url":null},{"nid":7955,"title":"Tanium security advisory (AV26-673)","uuid":"a108dcde-4926-42da-a1e4-7906922449c7","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T15:50:04Z","date_created":"2026-07-08T15:45:57Z","summary":null,"body":["<article data-history-node-id=\"7955\" about=\"\/en\/alerts-advisories\/tanium-security-advisory-av26-673\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-673<br \/><strong>Date: <\/strong>July 8, 2026<\/p>\n\n<p>On July 7, 2026, Tanium published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>Tanium Server 2025H1 Release\u00a0\u2013 versions prior to Update MR21 (v7.7.3.8298)<\/li>\n\t<li>Tanium Server 2025H2 Release\u00a0\u2013 versions prior to Update MR11 (v7.8.2.1198)<\/li>\n\t<li>Tanium Server 2026H1 Release\u00a0\u2013 versions prior to Update MR3 (v7.8.4.1327)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.tanium.com\/TAN-2026-016\/\">Tanium Security Advisories\u00a0- TAN-2026-016<\/a><\/li>\n\t<li><a href=\"https:\/\/security.tanium.com\/\">Tanium Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tanium-security-advisory-av26-673","alert_type":396,"serial_number":"AV26-673","subject":"other","moderation_state":"published","external_url":null},{"nid":7956,"title":"Palo Alto Networks security advisory (AV26-674)","uuid":"08571d68-1c86-4f0b-b593-92c19269ff6b","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T17:34:16Z","date_created":"2026-07-08T17:26:56Z","summary":null,"body":["<article data-history-node-id=\"7956\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-674\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-674<br \/><strong>Date: <\/strong>July 8, 2026<\/p>\n\n<p>On July 8, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.4-h8<\/li>\n\t<li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.7-h2<\/li>\n\t<li>PAN-OS 12.1\u00a0\u2013 versions prior to 12.1.8<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.4-h20<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.7-h18<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.10-h12<\/li>\n\t<li>PAN-OS 11.2\u00a0\u2013 versions prior to 11.2.13<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.4-h35<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.6-h35<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.7.h8<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.10-h30<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.13-h9<\/li>\n\t<li>PAN-OS 11.1\u00a0\u2013 versions prior to 11.1.16<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.7-h36<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.10-h39<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.13-h23<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.16-h9<\/li>\n\t<li>PAN-OS 10.2\u00a0\u2013 versions prior to 10.2.18-h8<\/li>\n\t<li>Prisma Access 11.20.0\u00a0\u2013 versions prior to 11.2.7-h18<\/li>\n\t<li>Prisma Access 10.2.0\u00a0\u2013 versions prior to 10.2.10-h39<\/li>\n\t<li>Prisma Browser\u00a0\u2013 versions prior to 149.10.3.53<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2026-0010\">PAN-SA-2026-0010 Chromium: Monthly Vulnerability Update (July 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0288\">CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Network Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-674","alert_type":396,"serial_number":"AV26-674","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":7957,"title":"Juniper Networks security advisory (AV26-675)","uuid":"6384a275-9f92-4c36-8e76-d49183e6e3cc","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T17:57:34Z","date_created":"2026-07-08T17:50:13Z","summary":null,"body":["<article data-history-node-id=\"7957\" about=\"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-675\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-675<br \/><strong>Date: <\/strong>July 8, 2026<\/p>\n\n<p>On July 8, 2026, Juniper Networks published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Juniper cRPD\u00a0\u2013 all versions<\/li>\n\t<li>Juniper CTPView\u00a0\u2013 all versions<\/li>\n\t<li>Juniper Network Director\u00a0\u2013 versions prior to 7.1R3<\/li>\n\t<li>Junos OS\u00a0\u2013 multiple versions<\/li>\n\t<li>Junos OS Evolved\u00a0\u2013 all versions<\/li>\n\t<li>Junos OS on MX Series with SPC3 and SRX Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Junos Space\u00a0\u2013 all versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2026-07-Security-Bulletin-CTPView-Multiple-vulnerabilities-resolved-in-9-3R2-3-Release\">2026-07 Security Bulletin: CTPView: Multiple vulnerabilities resolved in 9.3R2-3 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2026-07-Security-Bulletin-Junos-Space-Multiple-vulnerabilities-resolved-in-26-1R1-Patch-V1-Release\">2026-07 Security Bulletin: Junos Space: Multiple vulnerabilities resolved in 26.1R1 Patch V1 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2026-07-Security-Bulletin-Junos-OS-Evolved-URL-handling-vulnerability-in-libfetch-results-in-heap-buffer-overflow-CVE-2020-7450\">2026-07 Security Bulletin: Junos OS Evolved: URL handling vulnerability in libfetch results in heap buffer overflow (CVE-2020-7450)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/article\/2026-07-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Receipt-of-a-specific-SNMPv3-request-results-in-memory-leak-and-eventual-snmpd-crash-CVE-2026-33799\">2026-07 Security Bulletin: Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash (CVE-2026-33799)<\/a><\/li>\n\t<li><a href=\"https:\/\/supportportal.juniper.net\/s\/global-search\/%40uri#f-sf_primarysourcename=Knowledge\">Juniper Support Portal<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/juniper-networks-security-advisory-av26-675","alert_type":396,"serial_number":"AV26-675","subject":"juniper","moderation_state":"published","external_url":null},{"nid":7958,"title":"Drupal security advisory (AV26-676) ","uuid":"9d41ca79-8c3d-4dee-81c2-abcdedaa5cf7","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T19:00:23Z","date_created":"2026-07-08T18:56:18Z","summary":null,"body":["<article data-history-node-id=\"7958\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-676\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-676<br \/><strong>Date: <\/strong>July 8, 2026<\/p>\n\n<p>On July 8, 2026, Drupal published security updates for multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>Location Selector\u00a0\u2013 versions prior to 1.3.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-072\">Location Selector\u00a0- Critical\u00a0- SQL Injection\u00a0- SA-CONTRIB-2026-072<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-676","alert_type":396,"serial_number":"AV26-676","subject":"drupal","moderation_state":"published","external_url":null},{"nid":7959,"title":"GitLab security advisory (AV26-677)","uuid":"abc5370b-2eb0-4669-8e38-60b47b1cbc6b","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T19:04:15Z","date_created":"2026-07-08T18:56:23Z","summary":null,"body":["<article data-history-node-id=\"7959\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-677\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:\u00a0<\/strong>AV26-677<br \/><strong>Date:\u00a0<\/strong>July 8, 2026<\/p>\n\n<p>On July 8, 2026, GitLab published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitLab Community Edition (CE)\u00a0\u2013 versions prior to 19.1.2, 19.0.4 and 18.11.7<\/li>\n\t<li>GitLab Enterprise Edition (EE)\u00a0\u2013 versions prior to 19.1.2, 19.0.4 and 18.11.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-1-2-released\/?nav=19.1.2 \">GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7<\/a><\/li>\n\t<li><a href=\"https:\/\/about.gitlab.com\/releases\/categories\/releases\/\">GitLab Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-677","alert_type":396,"serial_number":"AV26-677","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":7960,"title":"Progress security advisory (AV26-678)","uuid":"d6fa3e30-81a5-4d58-9b20-5ac38da9c211","banner":null,"lang":"en","date_modified":"2026-07-08","date_modified_ts":"2026-07-08T20:01:04Z","date_created":"2026-07-08T19:57:08Z","summary":null,"body":["<article data-history-node-id=\"7960\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-678\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-678<br \/><strong>Date:<\/strong> July 8, 2026<\/p>\n\n<p>On July 8, 2026, Progress published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MOVEit Transfer \u2013 version 2024.1.8 and prior<\/li>\n\t<li>MOVEit Transfer \u2013 version 2025.0.0 to 2025.0.7<\/li>\n\t<li>MOVEit Transfer \u2013 version 2025.1.0 to 2025.1.3<\/li>\n\t<li>MOVEit Transfer \u2013 version 2026.0.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Security-Bulletin-June-2026\">MOVEit Transfer Critical Security Bulletin \u2013 June 2026\u202f\u2013 (CVE-2026-10699, CVE-2026-10698, CVE-2026-11903)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.progress.com\/trust-center\">Progress Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-678","alert_type":396,"serial_number":"AV26-678","subject":"other","moderation_state":"published","external_url":null},{"nid":7962,"title":"Google Chrome security advisory (AV26-679)","uuid":"1a0340b0-3371-4555-b14d-c0bb562d081c","banner":null,"lang":"en","date_modified":"2026-07-09","date_modified_ts":"2026-07-09T17:34:07Z","date_created":"2026-07-09T17:30:21Z","summary":null,"body":["<article data-history-node-id=\"7962\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-679\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-679<br \/><strong>Date: <\/strong>July 9, 2026<\/p>\n\n<p>On July 8, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 150.0.7871.114\/115 (Windows\/Mac), and 150.0.7871.114 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_01162222768.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-679","alert_type":396,"serial_number":"AV26-679","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7963,"title":"FreePBX security advisory (AV26-680)","uuid":"4956a3ea-d4fd-4ccd-a649-826515dbf63d","banner":null,"lang":"en","date_modified":"2026-07-09","date_modified_ts":"2026-07-09T18:02:14Z","date_created":"2026-07-09T17:51:04Z","summary":null,"body":["<article data-history-node-id=\"7963\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-680\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-680<br \/><strong>Date: <\/strong>July 9, 2026<\/p>\n\n<p>On July 9, 2026, FreePBX published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>FreePBX API (FreePBX 17)\u00a0\u2013 versions prior to 17.0.9<\/li>\n\t<li>FreePBX Backup (FreePBX 17)\u00a0\u2013 versions prior to 17.0.11<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-79rg-3xp6-rqq6\">Authenticated API generatedocs Host Command Injection<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-24w6-hpg3-rwfg\">Authenticated Arbitrary SSH Key Injection via Backup Module<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories?state=published\">FreePBX Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-680","alert_type":396,"serial_number":"AV26-680","subject":"other","moderation_state":"published","external_url":null},{"nid":7964,"title":"Broadcom VMware security advisory (AV26-681)","uuid":"15930978-a82e-4994-9337-16760e94b624","banner":null,"lang":"en","date_modified":"2026-07-10","date_modified_ts":"2026-07-10T17:59:53Z","date_created":"2026-07-10T17:36:39Z","summary":null,"body":["<article data-history-node-id=\"7964\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-681\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-681<br \/><strong>Date: <\/strong>July 10, 2026<\/p>\n\n<p>Between July 8 and 10, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Open Source RabbitMQ\u00a0- multiple versions<\/li>\n\t<li>VMware Tanzu Greenplum Command Center\u00a0- multiple versions<\/li>\n\t<li>VMware Tanzu Greenplum Data Copy Utility\u00a0- versions prior to 2.9.5<\/li>\n\t<li>VMware Tanzu Greenplum on Kubernetes\u00a0- versions prior to 1.1.2<\/li>\n\t<li>VMware Tanzu Greenplum MCP Server\u00a0- version prior to 1.0.2<\/li>\n\t<li>VMware Tanzu Greenplum Streaming Server\u00a0- multiple versions<\/li>\n\t<li>VMware Tanzu Greenplum Text\u00a0- versions prior to 4.0.2<\/li>\n\t<li>VMware Tanzu RabbitMQ\u00a0- multiple versions<\/li>\n\t<li>VMware Tanzu RabbitMQ on Kubernetes\u00a0- multiple versions<\/li>\n\t<li>VMware Tanzu RabbitMQ on Tanzu Platform\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<p class=\"mrgn-bttm-md\">\u00a0<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VT\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-681","alert_type":396,"serial_number":"AV26-681","subject":"vmware","moderation_state":"published","external_url":null},{"nid":7965,"title":"Microsoft Edge security advisory (AV26-682)","uuid":"37001d9b-c1ac-4e4f-93de-a446d0ac5b17","banner":null,"lang":"en","date_modified":"2026-07-10","date_modified_ts":"2026-07-10T18:06:59Z","date_created":"2026-07-10T18:02:24Z","summary":null,"body":["<article data-history-node-id=\"7965\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-682\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-682<br \/><strong>Date:<\/strong> July 10, 2026<\/p>\n\n<p>On July 9, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Microsoft Edge Stable Channel<\/span>\u00a0\u2013 versions prior to 150.0.4078.65<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-9-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-682","alert_type":396,"serial_number":"AV26-682","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7966,"title":"BitWarden security advisory (AV26-683)","uuid":"9dbcdc5f-a3e2-4dd9-bcd4-e8a7ef81b82f","banner":null,"lang":"en","date_modified":"2026-07-10","date_modified_ts":"2026-07-10T19:57:14Z","date_created":"2026-07-10T19:49:40Z","summary":null,"body":["<article data-history-node-id=\"7966\" about=\"\/en\/alerts-advisories\/bitwarden-security-advisory-av26-683\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-683<br \/><strong>Date:<\/strong> July 10, 2026<\/p>\n\n<p>On July 8, 2026, BitWarden published security advisories to address a vulnerability in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Bitwarden Server<\/span>\u00a0\u2013 versions prior to 2026.6.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/bitwarden\/server\/releases\/tag\/v2026.6.2\">BitWarden Server<\/a><\/li>\n\t<li><a href=\"https:\/\/bitwarden.com\/\">BitWarden Home<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/bitwarden-security-advisory-av26-683","alert_type":396,"serial_number":"AV26-683","subject":"other","moderation_state":"published","external_url":null},{"nid":7967,"title":"IBM security advisory (AV26-684)","uuid":"fd1f5775-0983-4c2a-8947-f729a03bc086","banner":null,"lang":"en","date_modified":"2026-07-13","date_modified_ts":"2026-07-13T12:53:49Z","date_created":"2026-07-13T12:32:31Z","summary":null,"body":["<article data-history-node-id=\"7967\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-684\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-684<br \/><strong>Date: <\/strong>July\u00a013, 2026<\/p>\n\n<p>Between July\u00a06 and 12, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM Aspera Enterprise WebApps\u00a0\u2013 versions 1.0.0 to 1.0.3<\/li>\n\t<li>IBM Cloud Pak System\u00a0\u2013 versions prior to 2.3.5.0<\/li>\n\t<li>IBM Cloud Pak for Data System (CPDS)\u00a0\u2013 versions 1.0.0.0 to 1.0.10.0<\/li>\n\t<li>IBM Guardium Data Protection\u00a0\u2013 versions prior to 12.2<\/li>\n\t<li>IBM Library Support for Spring\u00a0\u2013 versions 3.2 to 3.2.26 and 3.4 to 3.4.18<\/li>\n\t<li>IBM Maximo Application Suite\u00a0\u2013 Monitor Component\u00a0\u2013 versions prior to 9.1 and 9.0<\/li>\n\t<li>IBM Operational Decision Manager\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Planning Analytics Local\u00a0\u2013 versions 2.1.0 to 2.1.21<\/li>\n\t<li>IBM RDi\u00a0\u2013 version 9.9<\/li>\n\t<li>IBM SPSS Modeler\u00a0\u2013 versions prior to 19.0.0.0<\/li>\n\t<li>IBM Software Support App (iOS) \/ (Android)\u00a0\u2013 versions 4.0.1 to 4.1.0<\/li>\n\t<li>IBM Storage Protect Snapshot For Windows\u00a0\u2013 versions 8.1.0.0 to 8.2.1.0<\/li>\n\t<li>IBM Tivoli Network Manager IP Edition\u00a0\u2013 versions 4.2 GA to 4.2.0.24<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-684","alert_type":396,"serial_number":"AV26-684","subject":"ibm","moderation_state":"published","external_url":null},{"nid":7970,"title":"[Control systems] CISA ICS security advisories (AV26\u2013687)","uuid":"9a879389-dd4f-4c5d-9f14-517ceaf9e951","banner":null,"lang":"en","date_modified":"2026-07-13","date_modified_ts":"2026-07-13T12:56:34Z","date_created":"2026-07-13T12:32:32Z","summary":null,"body":["<article data-history-node-id=\"7970\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-687\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013687<br \/><strong>Date: <\/strong>July\u00a013, 2026<\/p>\n\n<p>Between July\u00a06 and 12, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Digi International PortServer TS\u00a0\u2013 multiple versions<\/li>\n\t<li>Digi One SP IA\u00a0\u2013 multiple versions<\/li>\n\t<li>Hydro-<span lang=\"fr\" xml:lang=\"fr\" xml:lang=\"fr\">Qu\u00e9bec Le Circuit Electrique<\/span> charging station backend\u00a0\u2013 versions prior to June_2026<\/li>\n\t<li>Hitachi Energy e-mesh EMS\u00a0\u2013 versions 4.1.6, 4.4.2 and 4.7.0<\/li>\n\t<li>Hitachi Energy PROMOD V\u00a0\u2013 versions 1.0.10 and prior<\/li>\n\t<li>Labcenter Proteus 9\u00a0\u2013 version Proteus 9.1_SP4_Build_42914<\/li>\n\t<li>OpenPLC v3\u00a0\u2013 version OpenPLC v3<\/li>\n\t<li>Schneider Electric Easergy MiCOM Px40 Series\u00a0\u2013 multiple versions<\/li>\n\t<li>Schneider Electric PowerChute Serial Shutdown\u00a0\u2013 versions 1.4 and prior<\/li>\n\t<li>Siemens Mendix Studio Pro\u00a0\u2013 multiple versions<\/li>\n\t<li>Siemens SINEC OS\u00a0\u2013 version RUGGEDCOM RST2428P (6GK6242-6PA00)\u00a0\u2013 versions prior to 4.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-687","alert_type":398,"serial_number":"AV26-687","subject":"ics","moderation_state":"published","external_url":null},{"nid":7968,"title":"Dell security advisory (AV26-685)","uuid":"255f114a-9433-457c-a1d5-2177e41c2a80","banner":null,"lang":"en","date_modified":"2026-07-13","date_modified_ts":"2026-07-13T12:54:36Z","date_created":"2026-07-13T12:32:32Z","summary":null,"body":["<article data-history-node-id=\"7968\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-685\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-685<br \/><strong>Date:<\/strong> July\u00a013, 2026<\/p>\n\n<p>Between July\u00a06 and 12, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell Data Lakehouse\u00a0\u2013 versions prior to 1.8.0.1<\/li>\n\t<li>Dell Enterprise SONiC Distribution\u00a0\u2013 versions prior to 4.6.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000487165\/dsa-2026-291-security-update-for-dell-data-lakehouse-third-party-component-vulnerabilities\">DSA-2026-291: Security Update for Dell Data Lakehouse Third-Party Component Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000486907\/dsa-2026-290-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities\">DSA-2026-290: Security Update for Dell Enterprise SONiC Distribution Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-685","alert_type":396,"serial_number":"AV26-685","subject":"dell","moderation_state":"published","external_url":null},{"nid":7969,"title":"Ubuntu security advisory (AV26-686)","uuid":"77981505-a4f7-4109-8bed-6dbd897a7bcc","banner":null,"lang":"en","date_modified":"2026-07-13","date_modified_ts":"2026-07-13T12:55:49Z","date_created":"2026-07-13T12:32:32Z","summary":null,"body":["<article data-history-node-id=\"7969\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-686\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-686<br \/><strong>Date:<\/strong> July\u00a013, 2026<\/p>\n\n<p>Between July\u00a06 and 12, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 18.04 LTS<\/li>\n\t<li>Ubuntu 22.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n\t<li>Ubuntu 26.04 LTS<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-686","alert_type":396,"serial_number":"AV26-686","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":7971,"title":"Red Hat security advisory (AV26-688)","uuid":"adc21f40-0450-4549-9841-3ac074581fff","banner":null,"lang":"en","date_modified":"2026-07-13","date_modified_ts":"2026-07-13T12:59:13Z","date_created":"2026-07-13T12:32:35Z","summary":null,"body":["<article data-history-node-id=\"7971\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-688\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-688<br \/><strong>Date: <\/strong>July\u00a013, 2026<\/p>\n\n<p>Between July\u00a06 and 12, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-688","alert_type":396,"serial_number":"AV26-688","subject":"redhat","moderation_state":"published","external_url":null},{"nid":7973,"title":"[Control systems] Siemens security advisory (AV26-689)","uuid":"9ae7d99c-d7ea-46cb-aae5-626023180409","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T13:33:00Z","date_created":"2026-07-14T13:12:58Z","summary":null,"body":["<article data-history-node-id=\"7973\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-689\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-689<br \/><strong>Date:<\/strong> July 14, 2026<\/p>\n\n<p>On July 14, 2026, Siemens published security advisories to address vulnerabilities in the following products. Included were updates for the following products:<\/p>\n\n<ul><li>CADRA\u00a0- versions prior to V2511<\/li>\n\t<li>Desigo CC family V7\/V8\u00a0- all versions<\/li>\n\t<li>Desigo CC family V9\u00a0- versions prior to V9.0 QU1<\/li>\n\t<li>IAM Client\u00a0- multiple versions and models<\/li>\n\t<li>Mendix Runtime\u00a0- all versions<\/li>\n\t<li>Opcenter X\u00a0- versions prior to V2604<\/li>\n\t<li>Palo Alto Networks PAN-OS on RUGGEDCOM APE1808\u00a0- all versions<\/li>\n\t<li>SIDIS Secured SmartPlug\u00a0- versions prior to V7.26.0310<\/li>\n\t<li>SIMATIC S7-1500 CPU family\u00a0- versions prior to V3.1.6<\/li>\n\t<li>SIMATIC S7-PLCSIM Advanced\u00a0- all versions<\/li>\n\t<li>Simcenter STAR-CCM+\u00a0- all versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/global\/en\/products\/services\/cert.html#SecurityPublications\">Siemens Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-689","alert_type":398,"serial_number":"AV26-689","subject":"other","moderation_state":"published","external_url":null},{"nid":7974,"title":"SAP security advisory \u2013 July 2026 monthly rollup (AV26-690)","uuid":"6d9781bb-2d1c-42dc-80d6-e93e76576627","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T13:54:12Z","date_created":"2026-07-14T13:38:03Z","summary":null,"body":["<article data-history-node-id=\"7974\" about=\"\/en\/alerts-advisories\/sap-security-advisory-july-2026-monthly-rollup-av26-690\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-690<br \/><strong>Date: <\/strong>July 14, 2026<\/p>\n\n<p>On July 14, 2026, SAP published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>SAP Approuter node.js package\u00a0- versions prior to 20.10.0<\/li>\n\t<li>SAP Approuter node.js package\u00a0- versions prior to 21.2.0<\/li>\n\t<li>SAP Change and Transport System Attach Tool (ctsattach)\u00a0- version CTS_UPLOAD_CLT 1<\/li>\n\t<li>SAP Commerce Cloud\u00a0- versions HY_COM 2205, COM_CLOUD 2211 and 2211-JDK21<\/li>\n\t<li>SAP CRM (WebClient UI)\u00a0- versions S4FND 104, 105 and 106<\/li>\n\t<li>SAP Fiori (launchpad)\u00a0- versions SAP_UI 754, 755, 756, 757, 758 and 816<\/li>\n\t<li>SAP Integration Suite (Edge Integration Cell)\u00a0- versions prior to 8.43.11<\/li>\n\t<li>SAP HANA Extended Application Services classic model (User Self Service)\u00a0- version HDB 2.00<\/li>\n\t<li>SAP NetWeaver Application Server ABAP\u00a0- versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53. 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19 and 9.20<\/li>\n\t<li>SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)\u00a0- multiple versions<\/li>\n\t<li>SAP NetWeaver Application Server Java (Configuration Wizard)\u00a0- version ENGINEAPI 7.50<\/li>\n\t<li>SAP NetWeaver Application Server Java (Web Container)\u00a0- version LMCTC 7.50<\/li>\n\t<li>SAP NetWeaver AS Java\u00a0- versions SERVERCORE 7.50, CORE-TOOLS 7.50 and J2EE-APPS 7.50<\/li>\n\t<li>SAP NetWeaver Enterprise Portal\u00a0- version EP-RUNTIME 7.50<\/li>\n\t<li>SAProuter on Microsoft Windows\u00a0- versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, SAP_ROUTER 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.17 and 9.18<\/li>\n\t<li>SAP S\/4 HANA (Create Single Payment)\u00a0- versions S4CORE 102, 103, 104, 105, 106, 107, 108 and 109<\/li>\n\t<li>SAP S\/4HANA (Draft operation)\u00a0- version S4CORE 108<\/li>\n\t<li>SAP S\/4HANA Project Management (PPM-PRO)\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/july-2026.html\">SAP Security Patch Day\u00a0- July 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-july-2026-monthly-rollup-av26-690","alert_type":396,"serial_number":"AV26-690","subject":"sap","moderation_state":"published","external_url":null},{"nid":7975,"title":"HPE security advisory (AV26-691)","uuid":"e9dc6701-3061-4f19-b0f0-400c856d40b2","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T14:12:52Z","date_created":"2026-07-14T14:00:39Z","summary":null,"body":["<article data-history-node-id=\"7975\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-691\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-691<br \/><strong>Date: <\/strong>July 14, 2026<strong>\u00a0<\/strong><\/p>\n\n<p>On July 14, 2026, HPE published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Compute Scale-up Server 3200\u00a0- versions prior to v1.76.44<\/li>\n\t<li>HPE Compute Scale-up Server 3250\u00a0- versions prior to v1.02.48<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbhf05079en_us&amp;docLocale=en_US#hpesbhf05079-rev-1-hpe-compute-scale-up-server-320-0\">HPESBHF05079 rev.1\u00a0- HPE Compute Scale-up Server 3200 and 3250 platforms, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-691","alert_type":396,"serial_number":"AV26-691","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7976,"title":"Mozilla security advisory (AV26-692)","uuid":"3481e5a5-1812-4bcf-821c-9f0f51e2ef9f","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T14:23:33Z","date_created":"2026-07-14T14:17:01Z","summary":null,"body":["<article data-history-node-id=\"7976\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-692\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-692<br \/><strong>Date: <\/strong>July 14, 2026<\/p>\n\n<p>On July 14, 2026, Mozilla published a security advisory to address vulnerabilities in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>Firefox \u2013 versions prior to 152.0.6<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-67\/\">Mozilla Foundation Security Advisory 2026-67<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-692","alert_type":396,"serial_number":"AV26-692","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":7977,"title":"ServiceNow security advisory (AV26-693) \u2013 Update 1","uuid":"54710ace-ec8a-4edf-9a11-f8c2cf337e4a","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:57:13Z","date_created":"2026-07-14T14:27:13Z","summary":null,"body":["<article data-history-node-id=\"7977\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av26-693\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-693<br \/><strong>Date: <\/strong>July 14, 2026<br \/><strong>Updated:<\/strong> July 20, 2026<\/p>\n\n<p>On July 13, 2026, ServiceNow published a security advisory to address a critical vulnerability in the following products:<\/p>\n\n<ul><li>Brazil\u00a0- versions prior to Brazil EA and Brazil GA<\/li>\n\t<li>Australia\u00a0- versions prior to Australia Patch 2<\/li>\n\t<li>Zurich\u00a0- versions prior to Zurich Patch 7b and Zurich Patch 9<\/li>\n\t<li>Yokohama\u00a0- versions prior to Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13<\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-6875 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB3137947\">[Security Advisory] CVE-2026-6875\u00a0- Sandbox Escape in ServiceNow AI Platform<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av26-693","alert_type":396,"serial_number":"AV26-693","subject":"other","moderation_state":"published","external_url":null},{"nid":7978,"title":"Veeam security advisory (AV26-694)","uuid":"51520303-4788-40cc-a772-b2bca148f546","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T15:44:38Z","date_created":"2026-07-14T15:39:57Z","summary":null,"body":["<article data-history-node-id=\"7978\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-694\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-694<br \/><strong>Date:<\/strong> July 14, 2026<\/p>\n\n<p>On July 14, 2026, Veeam published a security advisor to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Veeam Software Appliance Updater Component \u2013 versions prior to 12.3.0.65<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4879 \">Veeam Software Appliance\u00a0- Updater Component Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html \">Veeam Knowledge Base<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-694","alert_type":396,"serial_number":"AV26-694","subject":"other","moderation_state":"published","external_url":null},{"nid":7980,"title":"Fortinet security advisory (AV26-695)","uuid":"b1e60159-af0e-4396-abf9-a60182653cfb","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T18:38:50Z","date_created":"2026-07-14T18:24:40Z","summary":null,"body":["<article data-history-node-id=\"7980\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-695\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-695<br \/><strong>Date: <\/strong>July 14, 2026<\/p>\n\n<p>On July 14, 2026, Fortinet published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>FortiAuthenticator 6.6\u00a0- versions 6.6.0 to 6.6.2<\/li>\n\t<li>FortiAuthenticator 6.5\u00a0- versions 6.5.0 to 6.5.7<\/li>\n\t<li>FortiSandbox 5.0\u00a0- versions 5.0.0 to 5.0.2<\/li>\n\t<li>FortiSandbox 4.4\u00a0- versions 4.4.3 to 4.4.8<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-146\">Out of bounds read in GUI<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-145\">Unauthenticated VNC access exposed on all interfaces<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-695","alert_type":396,"serial_number":"AV26-695","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":7981,"title":"Ivanti security advisory (AV26-696)","uuid":"ff3401f0-33f8-4312-8858-b98ff66f257b","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T19:07:39Z","date_created":"2026-07-14T18:53:10Z","summary":null,"body":["<article data-history-node-id=\"7981\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-696\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-696<br \/><strong>Date: <\/strong>July 14, 2026<\/p>\n\n<p>On July 14, 2026, Ivanti published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Ivanti Xtraction\u00a0\u2013 version 2026.2 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Xtraction-CVE-2026-14902-CVE-2026-14903?language=en_US\">Security Advisory Ivanti Xtraction (CVE-2026-14902, CVE-2026-14903)<\/a><\/li>\n\t<li><a href=\"https:\/\/forums.ivanti.com\/s\/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory\">Ivanti Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-696","alert_type":396,"serial_number":"AV26-696","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":7982,"title":"Adobe security advisory (AV26-697)","uuid":"a7620038-e2b2-458e-b9c2-f3a2b51cb168","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T19:25:40Z","date_created":"2026-07-14T19:13:14Z","summary":null,"body":["<article data-history-node-id=\"7982\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-697\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013697<br \/><strong>Date: <\/strong>July 14, 2026<\/p>\n\n<p>On July 14, 2026, Adobe published security advisories to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe After Effects\u00a0- version 25.6.5 and prior<\/li>\n\t<li>Adobe After Effects\u00a0- version 26.2.1 and prior<\/li>\n\t<li>Adobe Animate 2023\u00a0- version 23.0.15 and prior<\/li>\n\t<li>Adobe Animate 2024\u00a0- version 24.0.13 and prior<\/li>\n\t<li>Adobe Audition\u00a0- version 25.6.4 and prior<\/li>\n\t<li>Adobe Audition\u00a0- version 26.0 and prior<\/li>\n\t<li>Adobe Bridge\u00a0- version 15.1.5 (LTS) and prior<\/li>\n\t<li>Adobe Bridge\u00a0- version 16.0.3 and prior<\/li>\n\t<li>Adobe Commerce B2B\u00a0- multiple versions<\/li>\n\t<li>Adobe Commerce\u00a0- multiple versions<\/li>\n\t<li>Adobe Commerce Events\u00a0- version 1.6.0 to 1.20.0<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0- version AEM Cloud Service (CS) Release 2026.5.0 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0- version 6.5 LTS Service Pack 1 and prior<\/li>\n\t<li>Adobe Experience Manager (AEM)\u00a0- version 6.5 Service Pack 24 and prior<\/li>\n\t<li>Adobe Media Encoder\u00a0- version 25.6.5 and prior<\/li>\n\t<li>Adobe Media Encoder\u00a0- version 26.2.2 and prior<\/li>\n\t<li>Adobe Premiere\u00a0- version 26.2.2 and prior<\/li>\n\t<li>Adobe Premiere Pro\u00a0- version 25.6.5 and prior<\/li>\n\t<li>ColdFusion 2025 Update 10 and earlier versions<\/li>\n\t<li>ColdFusion 2023 Update 21 and earlier versions<\/li>\n\t<li>ColdFusion 2021\u00a0- version 2021.0.0.323925 and prior<\/li>\n\t<li>ColdFusion 2023\u00a0- version 2023.0.0.330468 and prior<\/li>\n\t<li>ColdFusion 2025\u00a0- version 2023.0.0.331385 and prior<\/li>\n\t<li>Content Credentials Command-Line Tool\u00a0- version c2patool-v0.17.0 and prior<\/li>\n\t<li>Content Credentials JS SDK\u00a0- version @contentauth\/c2pa-web@0.7.0 and prior<\/li>\n\t<li>Content Credentials Rust SDK\u00a0- version c2pa-v0.84.0 and prior<\/li>\n\t<li>Creative Cloud Desktop Application\u00a0- version 6.9.1.1 and prior<\/li>\n\t<li>Illustrator 2025\u00a0- version 29.8.7 and prior<\/li>\n\t<li>Illustrator 2026\u00a0- version 30.5 and prior<\/li>\n\t<li>Magento Open Source\u00a0- multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security.html\">Adobe Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-697","alert_type":396,"serial_number":"AV26-697","subject":"adobe","moderation_state":"published","external_url":null},{"nid":7983,"title":"Microsoft security advisory \u2013 July 2026 monthly rollup (AV26-698) \u2013 Update 3","uuid":"055db229-9462-4828-8e40-5690c68bcab6","banner":null,"lang":"en","date_modified":"2026-07-23","date_modified_ts":"2026-07-23T12:51:19Z","date_created":"2026-07-14T19:33:12Z","summary":null,"body":["<article data-history-node-id=\"7983\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2026-monthly-rollup-av26-698\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013698<br \/><strong>Date: <\/strong>July 14, 2026<br \/><strong>Updated: <\/strong>July 23, 2026<\/p>\n\n<p>On July 14, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>.NET 10.0 installed on Linux<\/li>\n\t<li>.NET 10.0 installed on Mac OS<\/li>\n\t<li>.NET 10.0 installed on Windows<\/li>\n\t<li>.NET 8.0 installed on Linux<\/li>\n\t<li>.NET 8.0 installed on Mac OS<\/li>\n\t<li>.NET 8.0 installed on Windows<\/li>\n\t<li>.NET 9.0 installed on Linux<\/li>\n\t<li>.NET 9.0 installed on Mac OS<\/li>\n\t<li>.NET 9.0 installed on Windows<\/li>\n\t<li>Age of Empires II: Definitive Edition Game<\/li>\n\t<li>Azure Active Directory<\/li>\n\t<li>Azure CycleCloud 8.9.1<\/li>\n\t<li>Azure Monitor Agent Metrics Extension<\/li>\n\t<li>Azure Open AI<\/li>\n\t<li>Azure Spring Apps<\/li>\n\t<li>Azure Synapse<\/li>\n\t<li>Fabric Data Warehouse<\/li>\n\t<li>GitHub Copilot Plugin for JetBrains IDEs<\/li>\n\t<li>Microsoft .NET Framework<\/li>\n\t<li>Microsoft .NET Framework 3.5<\/li>\n\t<li>Microsoft .NET Framework 4.8.1<\/li>\n\t<li>Microsoft 365 Apps<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft 365 Copilot<\/li>\n\t<li>Microsoft 365 Copilot for Android<\/li>\n\t<li>Microsoft 365 Copilot for iOS<\/li>\n\t<li>Microsoft Bing Search for iOS<\/li>\n\t<li>Microsoft Defender for Endpoint for Mac<\/li>\n\t<li>Microsoft Dynamics NAV 2018<\/li>\n\t<li>Microsoft Edge (Chromium-based)<\/li>\n\t<li>Microsoft Entra Provisioning Service<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Online<\/li>\n\t<li>Microsoft Exchange Server 2016<\/li>\n\t<li>Microsoft Exchange Server 2019<\/li>\n\t<li>Microsoft Exchange Server Subscription Edition RTM<\/li>\n\t<li>Microsoft Malware Protection Engine<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office 365 for Mac<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft PC Manager<\/li>\n\t<li>Microsoft PowerPoint 2016<\/li>\n\t<li>Microsoft SQL Server 2016<\/li>\n\t<li>Microsoft SQL Server 2017<\/li>\n\t<li>Microsoft SQL Server 2019<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SQL Server 2025<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Surface Go 2<\/li>\n\t<li>Microsoft Surface Go 3<\/li>\n\t<li>Microsoft Surface Hub<\/li>\n\t<li>Microsoft Surface Hub 2S<\/li>\n\t<li>Microsoft Surface Hub 3<\/li>\n\t<li>Microsoft Surface Laptop Go<\/li>\n\t<li>Microsoft Surface Laptop Go 2<\/li>\n\t<li>Microsoft Surface Laptop Go 3<\/li>\n\t<li>Microsoft Surface Pro 7+<\/li>\n\t<li>Microsoft Surface Pro 8<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Microsoft Visual Studio 2026<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>AspNet.OData<\/li>\n\t<li>AspNetCore.OData<\/li>\n\t<li>Minecraft Bedrock Dedicated Server<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Power BI Report Server<\/li>\n\t<li>Surface Laptop 4 with AMD Processor<\/li>\n\t<li>Surface Laptop 4 with Intel Processor<\/li>\n\t<li>Surface Windows Dev Kit<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows 11 Version<\/li>\n\t<li>Windows Admin Center<\/li>\n\t<li>Windows Remote Help<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n\t<li>Windows Subsystem for Linux (WSL2)<\/li>\n\t<li>Windows Terminal for Windows 10<\/li>\n\t<li>Windows Terminal for Windows 11<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2026-56164 and CVE-2026-56155 are being exploited.<\/p>\n\n<p>On July 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-56164 and CVE-2026-56155 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-50522 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 3<\/h2>\n\n<p>On July 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-50522 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Jul\">July 2026 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\">Security Update Guide<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164\">CISA KEV: CVE-2026-56164<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155 \">CISA KEV: CVE-2026-56155<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644\">CISA KEV: CVE-2026-58644<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522\">CISA KEV: CVE-2026-50522<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-july-2026-monthly-rollup-av26-698","alert_type":396,"serial_number":"AV26-698","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7984,"title":"SonicWall security advisory (AV26-699) \u2013 Update 1","uuid":"de998070-2084-47d2-a525-9a5009ab9b4c","banner":null,"lang":"en","date_modified":"2026-07-14","date_modified_ts":"2026-07-14T20:27:13Z","date_created":"2026-07-14T20:08:23Z","summary":null,"body":["<article data-history-node-id=\"7984\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-699\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-699<br \/><strong>Date: <\/strong>July 14, 2026<\/p>\n\n<p>On July 14, 2026, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">SonicWall<\/span> published a security advisory to address critical vulnerabilities in the following products:<\/p>\n\n<ul><li>SMA1000 Models (6210, 7210 &amp; 8200v)\u00a0- version 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">platform-hotfix<\/span>)<\/li>\n\t<li>SMA1000 Models (6210, 7210 &amp; 8200v)\u00a0- version 12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">platform-hotfix<\/span>)<\/li>\n<\/ul><p>SonicWall indicates that CVE-2026-15409 and CVE-2026-15410 are being exploited.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On July 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-15409 and CVE-2026-15410 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0008\"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">SonicWall<\/span> SMA1000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Appliances Affected By Multiple Vulnerabilities<\/span><\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list \"><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">SonicWall Security Advisories<\/span><\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409\">CISA KEV: CVE-2026-15409<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410\">CISA KEV: CVE-2026-15410<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-699","alert_type":396,"serial_number":"AV26-699","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":7985,"title":"HPE security advisory (AV26-700)","uuid":"3e57ab6a-4f3d-4d6c-af1d-21dffcd7abe9","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T14:56:58Z","date_created":"2026-07-15T14:51:48Z","summary":null,"body":["<article data-history-node-id=\"7985\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-700\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-700<br \/><strong>Date:<\/strong> July 15, 2026<\/p>\n\n<p>On July 14, 2026, HPE published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>HPE Telco Intelligent Assurance (FAS and PDO) \u2013 versions 4.2.15 and prior<\/li>\n\t<li>HPE Unified OSS Console (UOC) \u2013 versions 3.1.21 and prior<\/li>\n\t<li>HPE Unified OSS Console Assurance Monitoring (UOCAM) \u2013 versions 3.1.21 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05076en_us&amp;docLocale=en_US#hpesbnw05076-rev-1-hpe-telco-intelligent-assurance-0\">HPESBNW05076 rev.1 - HPE Telco Intelligent Assurance, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05080en_us&amp;docLocale=en_US#hpesbnw05080-rev-1-hpe-unified-oss-console-uoc-and-0\">HPESBNW05080 rev.1 - HPE Unified OSS Console (UOC) and HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-700","alert_type":396,"serial_number":"AV26-700","subject":"hpe","moderation_state":"published","external_url":null},{"nid":7986,"title":"Google Chrome security advisory (AV26-701)","uuid":"a836ad65-491e-4942-aed2-7ab37db4d93d","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T15:12:44Z","date_created":"2026-07-15T14:59:11Z","summary":null,"body":["<article data-history-node-id=\"7986\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-701\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-701<br \/><strong>Date:<\/strong> July 14, 2026<\/p>\n\n<p>On July 14, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 150.7871.124\/125 (Windows\/Mac), and 150.0.7871.124 (Linux)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_0353146366.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-701","alert_type":396,"serial_number":"AV26-701","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":7987,"title":"Citrix security advisory (AV26-702)","uuid":"a6b9c3ee-ad52-4619-8855-29b0e0e0a2f7","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T15:22:04Z","date_created":"2026-07-15T15:15:36Z","summary":null,"body":["<article data-history-node-id=\"7987\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-702\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-702<br \/><strong>Date:<\/strong> July 15, 2026<\/p>\n\n<p>On July 14, 2026, Citrix published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Citrix Secure Access Client for Windows \u2013 versions prior to 26.6.1.20<\/li>\n\t<li>Citrix Endpoint Analysis Client for Windows \u2013 versions prior to 26.5.1.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696734&amp;articleURL=Citrix_Secure_Access_Client_for_Windows_and_Citrix_Endpoint_Analysis_Client_for_Windows_Security_Bulletin_for_CVE_2026_53565_and_CVE_2026_53566\">Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows Security Bulletin for CVE-2026-53565 and CVE-2026-53566<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\">Citrix Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av26-702","alert_type":396,"serial_number":"AV26-702","subject":"citrix","moderation_state":"published","external_url":null},{"nid":7988,"title":"Notepad++ security advisory (AV26-703)","uuid":"2b8c4bba-a6f1-43fc-ae8d-43e20c18fc8d","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T15:30:53Z","date_created":"2026-07-15T15:24:59Z","summary":null,"body":["<article data-history-node-id=\"7988\" about=\"\/en\/alerts-advisories\/notepad-security-advisory-av26-703\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-703<br \/><strong>Date:<\/strong> July 15, 2026<\/p>\n\n<p>On July 14, 2026, Notepad++ published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Notepad++ \u2013 version prior to v8.9.7<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.notepad-plus-plus.org\/topic\/27604\/notepad-release-8.9.7\">Notepad++ v8.9.7 release<\/a><\/li>\n\t<li><a href=\"https:\/\/community.notepad-plus-plus.org\/category\/1\/announcements\">Notepad++ community<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/notepad-security-advisory-av26-703","alert_type":396,"serial_number":"AV26-703","subject":"other","moderation_state":"published","external_url":null},{"nid":7989,"title":"F5 security advisory (AV26-704)","uuid":"d244668b-727e-4415-8c48-884a50180dd6","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T15:46:09Z","date_created":"2026-07-15T15:32:28Z","summary":null,"body":["<article data-history-node-id=\"7989\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-704\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-704<br \/><strong>Date:<\/strong> July 15, 2026<\/p>\n\n<p>On July 15, 2026, F5 published a security advisory to address vulnerabilities in the following products:<\/p>\n\n<ul><li>NGINX Agent \u2013 versions 2.37.0 to 2.46.5<\/li>\n\t<li>NGINX Instance Manager \u2013 versions 2.17.1 to 2.22.1<\/li>\n\t<li>NGINX Plus \u2013 versions 37.0.0.1 to 37.0.2.1<\/li>\n\t<li>NGINX Plus \u2013 versions R33 to R36<\/li>\n\t<li>NGINX Open Source \u2013 multiple versions<\/li>\n\t<li>NGINX Instance Manager \u2013 versions 2.17.0 to 2.22.1<\/li>\n\t<li>F5 WAF for NGINX \u2013 versions 5.9.0 to 5.13.3<\/li>\n\t<li>NGINX App Protect WAF \u2013 versions 5.2.0 to 5.8.0<\/li>\n\t<li>NGINX App Protect WAF \u2013 versions 4.11.0 to 4.16.0<\/li>\n\t<li>NGINX Gateway Fabric \u2013 versions 2.0.0 to 2.6.6<\/li>\n\t<li>NGINX Gateway Fabric \u2013 versions 1.3.0 to 1.6.2<\/li>\n\t<li>NGINX Ingress Controller \u2013 multiple versions<\/li>\n\t<li>BIG-IP Next SPK \u2013 multiple versions<\/li>\n\t<li>BIG-IP Next CNF \u2013 multiple versions<\/li>\n\t<li>BIG-IP Next for Kubernetes \u2013 versions 2.0.0 to 2.3.1<\/li>\n\t<li>BIG-IP (all modules) \u2013 multiple versions<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000161837\">K000161837: Out-of-band Security Notification (July 15, 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K12201527\">MyF5<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-704","alert_type":396,"serial_number":"AV26-704","subject":"f5","moderation_state":"published","external_url":null},{"nid":7990,"title":"Tenable security advisory (AV26-705)","uuid":"e49a5960-27f1-4178-a76f-f4fa41606cbd","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T17:06:52Z","date_created":"2026-07-15T17:03:11Z","summary":null,"body":["<article data-history-node-id=\"7990\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-705\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number<\/strong>: AV26-705<br \/><strong>Date:<\/strong> July 15, 2026<\/p>\n\n<p>On July 14, 2026, Tenable published a security advisory to address a critical vulnerability in the following product:<\/p>\n\n<ul><li>Nessus Agent \u2013 versions 11.2.0 and prior<\/li>\n\t<li>Nessus Agent \u2013 versions 11.1.3 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-18\">[R1] Tenable Agent Versions 11.2.1 and 11.1.4 Fix a Path Traversal Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-705","alert_type":396,"serial_number":"AV26-705","subject":"other","moderation_state":"published","external_url":null},{"nid":7991,"title":"AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server \u2013 CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644","uuid":"994e6ce3-76d6-4828-9101-0eba5279fb63","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T18:09:31Z","date_created":"2026-07-15T17:40:00Z","summary":null,"body":["<article data-history-node-id=\"7991\" about=\"\/en\/alerts-advisories\/al26-017-critical-vulnerabilities-impacting-microsoft-sharepoint-server-cve-2026-56164-cve-2026-55040-cve-2026-58644\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-017<br \/><strong>Date:<\/strong> July\u00a015, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert upon request.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Microsoft SharePoint Server. In response to the Microsoft security advisory, released on July\u00a014, 2026<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>, the Cyber Centre issued AV26-698<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> on July\u00a014, 2026.<\/p>\n\n<p>Tracked as CVE-2026-55164<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is a Missing Authentication for Critical Function (CWE-306)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to elevate privileges over a network.<\/p>\n\n<p>Tracked as CVE-2026-55040<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>, this vulnerability is a Weak Authentication (CWE-1390)<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup> vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to bypass a security feature over a network.<\/p>\n\n<p>Tracked as CVE-2026-58644<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>, this vulnerability is a Deserialization of Untrusted Data (CWE-502)<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup> vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to execute code over a network.<\/p>\n\n<p>Microsoft is aware of exploitation of CVE-2026-56164 and other previously released SharePoint related vulnerabilities. CVE-2026-56164 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup> on July\u00a014, 2026.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Microsoft SharePoint Enterprise Server 2016<\/td>\n\t\t\t<td>16.0.0 before 16.0.5561.1001<\/td>\n\t\t\t<td>16.0.5561.1001<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server 2019<\/td>\n\t\t\t<td>16.0.0 before 16.0.10417.20175<\/td>\n\t\t\t<td>16.0.10417.20175<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server Subscription Edition<\/td>\n\t\t\t<td>16.0.0 before 16.0.19725.20434<\/td>\n\t\t\t<td>16.0.19725.20434<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Identify all on-premises SharePoint Server instances, particularly those exposed to the internet<\/li>\n\t<li>Use or upgrade to supported versions of on-premises Microsoft SharePoint Server<\/li>\n\t<li>Apply the latest security updates from Microsoft to all affected SharePoint Servers including (Subscription Edition, 2019, and 2016)<\/li>\n\t<li>Monitor SharePoint servers for suspicious activity, including unusual requests, web shells, malicious processes, unauthorized access attempts, and machine key theft indicators<\/li>\n\t<li>Harden SharePoint Deployments:\n\t<ul><li>Enable Antimalware Scan Interface (AMSI) integration for SharePoint web applications<\/li>\n\t\t<li>Configure AMSI Request Body Scan Mode to Full Mode where operationally feasible<\/li>\n\t\t<li>Restrict or eliminate direct Internet exposure of SharePoint servers whenever possible<\/li>\n\t\t<li>Limit access to SharePoint Central Administration and management interfaces<\/li>\n\t<\/ul><\/li>\n\t<li>Monitor for Indicators of Compromise:\n\t<ul><li>Organizations should closely monitor SharePoint environments for:\n\t\t<ul><li>Unexpected privilege escalation activity<\/li>\n\t\t\t<li>Unauthorized authentication attempts<\/li>\n\t\t\t<li>Suspicious IIS machine key access<\/li>\n\t\t\t<li>Evidence of deserialization attacks or web shell deployment<\/li>\n\t\t\t<li>Microsoft Defender and AMSI detections related to SharePoint exploitation activity<\/li>\n\t\t<\/ul><\/li>\n\t<\/ul><\/li>\n<\/ul><p><strong>Important note: <\/strong>Microsoft SharePoint Enterprise Server 2016<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup> and Server 2019<sup id=\"fn12-rf\"><a class=\"fn-lnk\" href=\"#fn12\"><span class=\"wb-inv\">Footnote <\/span>12<\/a><\/sup> are <strong>end of life<\/strong>\u00a0as of\u00a0<strong>July\u00a014, 2026<\/strong>. Organizations are urged to migrate to a supported version.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn13-rf\"><a class=\"fn-lnk\" href=\"#fn13\"><span class=\"wb-inv\">Footnote <\/span>13<\/a><\/sup>.<\/p>\n\n<ul><li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Jul\">July 2026 Security Updates<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-july-2026-monthly-rollup-av26-698\">Microsoft security advisory\u00a0\u2013 July 2026 monthly rollup (AV26-698)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-56164\">CVE-2026-55164<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/306.html\">CWE-306: Missing Authentication for Critical Function<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-55040\">CVE-2026-55040<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.rapid7.com\/blog\/post\/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed\/\">CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/1390.html\">CWE-1390: Weak Authentication<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58644\">CVE-2026-58644<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/502.html\">CWE-502: Deserialization of Untrusted Data<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164\">CISA KEV: CVE-2026-56164<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2016\">SharePoint Server 2016\u00a0- Microsoft Lifecycle<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 12<\/dt>\n\t<dd id=\"fn12\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2019\">SharePoint Server 2019\u00a0- Microsoft Lifecycle<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn12-rf\"><span class=\"wb-inv\">Return to footnote<\/span>12<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 13<\/dt>\n\t<dd id=\"fn13\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn13-rf\"><span class=\"wb-inv\">Return to footnote<\/span>13<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-017-critical-vulnerabilities-impacting-microsoft-sharepoint-server-cve-2026-56164-cve-2026-55040-cve-2026-58644","alert_type":397,"serial_number":"AL26-017","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":7993,"title":"Cisco security advisory (AV26-706)","uuid":"b8e051b3-a1e5-47d8-b601-f95e4bec7ebc","banner":null,"lang":"en","date_modified":"2026-07-15","date_modified_ts":"2026-07-15T19:20:48Z","date_created":"2026-07-15T19:15:55Z","summary":null,"body":["<article data-history-node-id=\"7993\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-706\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-706<br \/><strong>Date:<\/strong> July 15, 2026<\/p>\n\n<p>On July 15, 2026, Cisco published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco RoomOS Release 11 and earlier On-Premises Operation \u2013 versions prior to 11.32.6.0<\/li>\n\t<li>Cisco RoomOS Release 11 and earlier Cloud-Aware Operation \u2013 versions prior to RoomOS 11.39.1.1<\/li>\n\t<li>Cisco RoomOS Release 26 On-Premises Operation \u2013 versions prior to 26.5.2.2<\/li>\n\t<li>Cisco RoomOS Release 26 Cloud-Aware Operation \u2013 versions prior to RoomOS June 2026 (26.7.1.7)<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-roomos-AqNMbEq\">Cisco RoomOS Security Hardening Release: July 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-706","alert_type":396,"serial_number":"AV26-706","subject":"cisco","moderation_state":"published","external_url":null},{"nid":7994,"title":"Zoom security advisory (AV26-707)","uuid":"5c30e521-b342-474f-be29-0cfe8b1be4c9","banner":null,"lang":"en","date_modified":"2026-07-16","date_modified_ts":"2026-07-16T12:40:09Z","date_created":"2026-07-16T12:25:24Z","summary":null,"body":["<article data-history-node-id=\"7994\" about=\"\/en\/alerts-advisories\/zoom-security-advisory-av26-707\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-707<br \/><strong>Date: <\/strong>July 16, 2026<\/p>\n\n<p>On July 14, 2026, Zoom published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Remote Control for Zoom Contact Center for Windows\u00a0\u2013 versions prior to 7.0.0<\/li>\n\t<li>Zoom Meeting SDK for Windows\u00a0\u2013 versions prior to 6.6.11<\/li>\n\t<li>Zoom Rooms for Windows\u00a0\u2013 versions prior to 7.1.0<\/li>\n\t<li>Zoom Workplace for Windows\u00a0\u2013 versions prior to 7.0.0<\/li>\n\t<li>Zoom Workplace VDI Client for Windows\u00a0\u2013 versions prior to 7.0.10, 6.5.18 and 6.6.15<\/li>\n\t<li>Zoom Workplace VDI Client for Windows\u00a0\u2013 versions prior to 6.5.17 and 6.6.14<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26014\/\">Zoom Workplace for Windows\u00a0- Improper Input Validation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26011\/\">Zoom Rooms for Windows\u00a0- Improper Privilege Management<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26013\/\">Zoom Workplace VDI Plugin for Windows\u00a0- Improper Input Validation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/zsb-26012\/\">Zoom Clients for Windows\u00a0- Race Condition<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zoom.com\/en\/trust\/security-bulletin\/\">Zoom Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zoom-security-advisory-av26-707","alert_type":396,"serial_number":"AV26-707","subject":"other","moderation_state":"published","external_url":null},{"nid":7995,"title":"Splunk security advisory (AV26-708)","uuid":"878374e9-64ef-4edd-8c25-f3dc80f7d859","banner":null,"lang":"en","date_modified":"2026-07-16","date_modified_ts":"2026-07-16T13:05:56Z","date_created":"2026-07-16T12:56:01Z","summary":null,"body":["<article data-history-node-id=\"7995\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-708\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-708<br \/><strong>Date: <\/strong>July 16, 2026<\/p>\n\n<p>On July 15, 2026, Splunk published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>Splunk Enterprise\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Splunk Cloud Platform\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0702\">SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0703\">Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0705\">Third-Party Package Updates in Splunk Enterprise\u00a0- July 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/advisory.splunk.com\/advisories\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-708","alert_type":396,"serial_number":"AV26-708","subject":"other","moderation_state":"published","external_url":null},{"nid":7996,"title":"JetBrains security advisory (AV26-709)","uuid":"4f69fc3c-c80b-4c20-b928-fe941791b98d","banner":null,"lang":"en","date_modified":"2026-07-16","date_modified_ts":"2026-07-16T15:07:51Z","date_created":"2026-07-16T14:58:11Z","summary":null,"body":["<article data-history-node-id=\"7996\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-709\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-709<br \/><strong>Date: <\/strong>July 16, 2026<\/p>\n\n<p>On July 14, 2026, JetBrains published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:<\/p>\n\n<ul><li>JetBrains TeamCity\u00a0\u2013 versions prior to 2026.1.2<\/li>\n\t<li>JetBrains YouTrack\u00a0\u2013 multiple versions<\/li>\n\t<li>JetBrains IntelliJ IDEA\u00a0\u2013 versions prior to 2026.1.4 and 2026.2<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-709","alert_type":396,"serial_number":"AV26-709","subject":"other","moderation_state":"published","external_url":null},{"nid":7997,"title":"Grafana security advisory (AV26-710)","uuid":"51a20f61-b866-4f2b-97b8-8169df908014","banner":null,"lang":"en","date_modified":"2026-07-16","date_modified_ts":"2026-07-16T18:13:25Z","date_created":"2026-07-16T18:09:21Z","summary":null,"body":["<article data-history-node-id=\"7997\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av26-710\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-710<br \/><strong>Date: <\/strong>July 16, 2026<\/p>\n\n<p>On July 15, 2026, Grafana published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Grafana MCP Server\u00a0\u2013 version 0.17.1 and prior<\/li>\n\t<li>Grafana Loki\u00a0\u2013 version 3.7.0 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/security\/security-advisories\/cve-2026-15583\/\">Grafana MCP server-side request forgery via X-Grafana-URL header<\/a><\/li>\n\t<li><a href=\"https:\/\/grafana.com\/security\/security-advisories\/cve-2026-21729\/\">Loki detected_fields query limits results in unbounded memory allocation<\/a><\/li>\n\t<li><a href=\"https:\/\/grafana.com\/blog\/\">Grafana Blog<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av26-710","alert_type":396,"serial_number":"AV26-710","subject":"other","moderation_state":"published","external_url":null},{"nid":7998,"title":"FreePBX security advisory (AV26\u2013711)","uuid":"21b68b78-2be8-474c-a983-86beaf6e19df","banner":null,"lang":"en","date_modified":"2026-07-17","date_modified_ts":"2026-07-17T14:16:09Z","date_created":"2026-07-17T13:55:33Z","summary":null,"body":["<article data-history-node-id=\"7998\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-711\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-711<br \/><strong>Date: <\/strong>July 17, 2026<\/p>\n\n<p>On July 17, 2026, FreePBX published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>FreePBX Security-Reporting ucp (FreePBX 17)\u00a0\u2013 versions prior to 17.0.9<\/li>\n\t<li>FreePBX Security-Reporting missedcall (FreePBX 16)\u00a0\u2013 versions prior to 16.0.11<\/li>\n\t<li>FreePBX Security-Reporting missedcall (FreePBX 16)\u00a0\u2013 versions prior to 17.0.6<\/li>\n\t<li>FreePBX Security-Reporting tts (FreePBX 17)\u00a0\u2013 versions prior to 17.0.6<\/li>\n\t<li>FreePBX Security-Reporting tts (FreePBX 16)\u00a0\u2013 versions prior to 16.0.6<\/li>\n\t<li>FreePBX Security-Reporting music (FreePBX 17)\u00a0\u2013 versions prior to 17.0.7<\/li>\n\t<li>FreePBX Security-Reporting framework (FreePBX 16)\u00a0\u2013 versions prior to 16.0.47<\/li>\n\t<li>FreePBX Security-Reporting framework (FreePBX 17)\u00a0\u2013 versions prior to 17.0.30<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-37j8-fhxx-9vhp \">Unauthenticated remote code execution in FreePBX UCP via socket.io namespace auth bypass and AMI action injection<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-g27h-xf3q-h3rm \">Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-hg3v-m857-mvw9 \">Authenticated TTS AGI Command Injection Through TTS Name<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-p97w-rq48-p8q2 \">Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/GHSA-f6hc-rqxg-ch86 \">Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories?state=published\">FreePBX Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-711","alert_type":396,"serial_number":"AV26-711","subject":"other","moderation_state":"published","external_url":null},{"nid":7999,"title":"Broadcom VMware security advisory (AV26-712)","uuid":"679f66fc-0e14-4eb3-968d-fdc273510029","banner":null,"lang":"en","date_modified":"2026-07-17","date_modified_ts":"2026-07-17T15:04:24Z","date_created":"2026-07-17T14:58:06Z","summary":null,"body":["<article data-history-node-id=\"7999\" about=\"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-712\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-712<br \/><strong>Date: <\/strong>July 17, 2026<\/p>\n\n<p>On July 14, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:<\/p>\n\n<ul><li>VMware Avi Load Balancer\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/37926\">VMSA-2026-0005: VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871) <\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory?segment=VA\">Security Advisories\u00a0- Application Networking and Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/broadcom-vmware-security-advisory-av26-712","alert_type":396,"serial_number":"AV26-712","subject":"vmware","moderation_state":"published","external_url":null},{"nid":8000,"title":"Google Chrome security advisory (AV26-713)","uuid":"fced7393-66ba-4040-b26d-51c63f470a97","banner":null,"lang":"en","date_modified":"2026-07-17","date_modified_ts":"2026-07-17T15:21:55Z","date_created":"2026-07-17T15:15:59Z","summary":null,"body":["<article data-history-node-id=\"8000\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-713\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-713<br \/><strong>Date: <\/strong>July 17, 2026<\/p>\n\n<p>On July 16, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 150.0.7871.128\/.129 (Windows\/Mac), and 150.0.7871.128 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_049796704.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-713","alert_type":396,"serial_number":"AV26-713","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8001,"title":"Microsoft Edge security advisory (AV26-714)","uuid":"0d249bfa-de59-4358-a8c8-6ce5e9c3b573","banner":null,"lang":"en","date_modified":"2026-07-17","date_modified_ts":"2026-07-17T18:33:47Z","date_created":"2026-07-17T18:30:30Z","summary":null,"body":["<article data-history-node-id=\"8001\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-714\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-714<br \/><strong>Date: <\/strong>July 17, 2026<\/p>\n\n<p>On July 16, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 150.0.4078.80<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-16-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-714","alert_type":396,"serial_number":"AV26-714","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":8005,"title":"[Control systems] CISA ICS security advisories (AV26-718)","uuid":"fbf5d0a8-efc2-42bf-9258-8f38c9a66d97","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:23:54Z","date_created":"2026-07-20T14:22:02Z","summary":null,"body":["<article data-history-node-id=\"8005\" about=\"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-718\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26\u2013718<br \/><strong>Date: <\/strong>July\u00a020, 2026<\/p>\n\n<p>Between July\u00a013 and 19, 2026, CISA published ICS advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ABB 800xA for Advant Master\u00a0\u2013 multiple versions<\/li>\n\t<li>ABB Ability Edgenius\u00a0\u2013 multiple versions and models<\/li>\n\t<li>ABB Control Builder A\u00a0\u2013 version 1.4\/4 and prior<\/li>\n\t<li>ABB T-MAC Plus\u00a0\u2013 version 4.0-24<\/li>\n\t<li>AutomationDirect Productivity Suite\u00a0\u2013 version v4.6.2.2 and prior<\/li>\n\t<li>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application\u00a0\u2013 versions prior to v7.0.1<\/li>\n\t<li>Rockwell Automation 1715-AENTR EtherNet\/IP Adapter\u00a0\u2013 version 3.003 and prior<\/li>\n\t<li>Rockwell Automation 1756-EN2\u00a0\u2013 version V12.001 and prior<\/li>\n\t<li>Rockwell Automation 1756-EN3\u00a0\u2013 version V12.001 and prior<\/li>\n\t<li>Rockwell Automation 1756-ENBT\u00a0\u2013 version V6.006<\/li>\n\t<li>Rockwell Automation Arena\u00a0\u2013 version V17.00.00 and prior<\/li>\n\t<li>Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Rockwell Automation FactoryTalk DataMosaix Private Cloud\u00a0\u2013 version 8.02 and prior<\/li>\n\t<li>Rockwell Automation Flex 5000 Adapter\u00a0\u2013 version 6.011<\/li>\n\t<li>SALTO ProAccess Space\u00a0\u2013 versions prior to 6.13<\/li>\n\t<li>Siemens SICAM 8 CPCI85 Central Processing\/Communication\u00a0\u2013 versions prior to 26.20<\/li>\n\t<li>Siemens SICAM 8 SICORE Base system\u00a0\u2013 versions prior to 26.20.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates if available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\">CISA ICS Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-ics-security-advisories-av26-718","alert_type":398,"serial_number":"AV26-718","subject":"ics","moderation_state":"published","external_url":null},{"nid":8002,"title":"IBM security advisory (AV26-715)","uuid":"30ac084a-ca3d-4de2-8263-4d430eab1e2f","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:14:31Z","date_created":"2026-07-20T14:22:02Z","summary":null,"body":["<article data-history-node-id=\"8002\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-715\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-715<br \/><strong>Date: <\/strong>July\u00a020, 2026<\/p>\n\n<p>Between July\u00a013 and 19, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>IBM API Connect V12 OnPrem\u00a0\u2013 versions v12.1.0.0 to v12.1.1.0<\/li>\n\t<li>IBM Automation Decision Services\u00a0\u2013 versions 24.0.0, 24.0.1 and 25.0.0<\/li>\n\t<li>IBM CICS Transaction Gateway Desktop Edition\u00a0\u2013 versions prior to 10.1<\/li>\n\t<li>IBM CICS Transaction Gateway for Multiplatforms\u00a0\u2013 versions prior to 10.1<\/li>\n\t<li>IBM Cloud Object Storage System\u00a0\u2013 versions 3.20.0.0 to 3.20.1.66<\/li>\n\t<li>IBM Cloud Object Storage System\u00a0\u2013 versions 3.8.1.54 to 3.19.5.56<\/li>\n\t<li>IBM Datacap Navigator\u00a0\u2013 versions 9.1.7, 9.1.8 and 9.1.9<\/li>\n\t<li>IBM Datacap\u00a0\u2013 versions 9.1.7, 9.1.8 and 9.1.9<\/li>\n\t<li>IBM Engineering AI Hub\u00a0\u2013 versions 1.0.0, 1.1.0 and 1.2.0<\/li>\n\t<li>IBM Guardium Data Protection\u00a0\u2013 version 12.1 and 12.2<\/li>\n\t<li>IBM Guardium Unified Discovery and Classification (GUDC)\u00a0\u2013 versions 1.0.0 to 1.2.0<\/li>\n\t<li>IBM Installation Manager\u00a0\u2013 versions prior to 1.10.1.4<\/li>\n\t<li>IBM Jazz Reporting Service\u00a0\u2013 multiple versions<\/li>\n\t<li>IBM Packaging Utility\u00a0\u2013 versions prior to 1.10.1.4<\/li>\n\t<li>IBM Process Automation Manager Open Edition Starter Kit for Banking\u00a0\u2013 versions 9.3.1 to 9.4.1<\/li>\n\t<li>IBM QRadar Data Synchronization App\u00a0\u2013 versions 1.0.0 to 3.3.0<\/li>\n\t<li>IBM QRadar User Behavior Analytics\u00a0\u2013 versions 1.0.0 to 5.1.0<\/li>\n\t<li>IBM Rapid Network Automation\u00a0\u2013 versions prior to 1.1.4 and 1.1.5<\/li>\n\t<li>IBM Sterling Secure Proxy\u00a0\u2013 versions 6.1.0.0 to 6.1.0.4<\/li>\n\t<li>IBM Sterling Secure Proxy\u00a0\u2013 versions 6.2.1.0 to 6.2.1.2 iFix01<\/li>\n\t<li>IBM Tivoli Netcool Configuration Manager\u00a0\u2013 versions 6.4.2 GA to 6.4.2.24<\/li>\n\t<li>IBM WebSphere Service Registry and Repository\u00a0\u2013 versions prior to 8.5<\/li>\n\t<li>IBM i\u00a0\u2013 versions 7.6, 7.5, 7.4 and 7.3<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 4.8.4 to 4.8.5<\/li>\n\t<li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data\u00a0\u2013 versions 5.0.0 to 5.3.3<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-715","alert_type":396,"serial_number":"AV26-715","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8003,"title":"Dell security advisory (AV26-716)","uuid":"711444d0-482d-4f82-87f1-0d7cdbe2a522","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:18:34Z","date_created":"2026-07-20T14:22:02Z","summary":null,"body":["<article data-history-node-id=\"8003\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-716\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-716<br \/><strong>Date:<\/strong> July\u00a020, 2026<\/p>\n\n<p>Between July\u00a013 and 19, 2026, Dell published security advisories to address vulnerabilities in multiple products:<\/p>\n\n<ul><li>Dell DRAC9\u00a0\u2013 versions prior to 7.00.00.184<\/li>\n\t<li>Dell PowerEdge Server\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell PowerProtect Data Manager\u00a0\u2013 versions prior to 20.2.0.0<\/li>\n\t<li>Dell SmartFabric Manager\u00a0\u2013 versions prior to 2.2.1<\/li>\n\t<li>Dell Storage Monitoring and Reporting\u00a0\u2013 versions prior to 6.1.1.0<\/li>\n\t<li>Dell Storage Resource Manager\u00a0\u2013 versions prior to 6.1.1.0<\/li>\n\t<li>Dell ThinOS 10\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Dell iDRAC9\u00a0\u2013 versions prior to 7.30.30.51<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca\">Dell Security advisories and notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-716","alert_type":396,"serial_number":"AV26-716","subject":"dell","moderation_state":"published","external_url":null},{"nid":8004,"title":"Ubuntu security advisory (AV26-717)","uuid":"72a48163-685b-4359-8993-d0cd381695f2","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:21:45Z","date_created":"2026-07-20T14:22:02Z","summary":null,"body":["<article data-history-node-id=\"8004\" about=\"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-717\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-717<br \/><strong>Date:<\/strong> July\u00a020, 2026<\/p>\n\n<p>Between July\u00a013 and 19, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:<\/p>\n\n<ul><li>Ubuntu 14.04 LTS<\/li>\n\t<li>Ubuntu 16.04 LTS<\/li>\n\t<li>Ubuntu 20.04 LTS<\/li>\n\t<li>Ubuntu 24.04 LTS<\/li>\n\t<li>Ubuntu 25.10<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubuntu-security-advisory-av26-717","alert_type":396,"serial_number":"AV26-717","subject":"ubuntu","moderation_state":"published","external_url":null},{"nid":8007,"title":"GitHub security advisory (AV26-720)","uuid":"785ce9e6-2280-4198-9f0d-3f06780bbc20","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:31:37Z","date_created":"2026-07-20T14:22:03Z","summary":null,"body":["<article data-history-node-id=\"8007\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-720\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-720<br \/><strong>Date:<\/strong> July\u00a020, 2026<\/p>\n\n<p>On July\u00a016, 2026, GitHub published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>GitHub Enterprise Server\u00a0\u2013 versions 3.21.x prior to 3.21.3<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.20.x prior to 3.20.5<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.19.x prior to 3.19.9<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.18.x prior to 3.18.12<\/li>\n\t<li>GitHub Enterprise Server\u00a0\u2013 versions 3.17.x prior to 3.17.18<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.21\/admin\/release-notes\">Enterprise Server 3.21.3<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.20\/admin\/release-notes\">Enterprise Server 3.20.5<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Enterprise Server 3.19.9<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Enterprise Server 3.18.12<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Enterprise Server 3.17.18<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-720","alert_type":396,"serial_number":"AV26-720","subject":"other","moderation_state":"published","external_url":null},{"nid":8006,"title":"Red Hat security advisory (AV26-719)","uuid":"46576b48-af7a-4976-8ac7-17340eb3fd61","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:28:07Z","date_created":"2026-07-20T14:22:03Z","summary":null,"body":["<article data-history-node-id=\"8006\" about=\"\/en\/alerts-advisories\/red-hat-security-advisory-av26-719\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-719<br \/><strong>Date: <\/strong>July\u00a020, 2026<\/p>\n\n<p>Between July\u00a013 and 19, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:<\/p>\n\n<ul><li>Red Hat CodeReady Linux Builder\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux Server\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>Red Hat Enterprise Linux for Real Time\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Red Hat Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/red-hat-security-advisory-av26-719","alert_type":396,"serial_number":"AV26-719","subject":"redhat","moderation_state":"published","external_url":null},{"nid":8009,"title":"Zimbra security advisory (AV26-721)","uuid":"2eef6662-cc54-4c43-b51d-dba447650a9f","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T15:36:07Z","date_created":"2026-07-20T15:34:26Z","summary":null,"body":["<article data-history-node-id=\"8009\" about=\"\/en\/alerts-advisories\/zimbra-security-advisory-av26-721\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-721<br \/><strong>Date:<\/strong> July\u00a020, 2026<\/p>\n\n<p>On July\u00a020, 2026, Zimbra published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Zimbra Collaboration Suite (ZCS) Classic Web Client\u00a0\u2013 versions prior to v10.1.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.zimbra.com\/2026\/07\/patch-release-update-zimbra-10-1-20\/\">Patch Release Update: Zimbra 10.1.20<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.zimbra.com\/\">Zimbra Patch Release Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zimbra-security-advisory-av26-721","alert_type":396,"serial_number":"AV26-721","subject":"other","moderation_state":"published","external_url":null},{"nid":8010,"title":"HPE security advisory (AV26-722)","uuid":"1026ca5f-022d-4ef1-b2e4-47b3b5be06cb","banner":null,"lang":"en","date_modified":"2026-07-20","date_modified_ts":"2026-07-20T16:02:47Z","date_created":"2026-07-20T15:53:55Z","summary":null,"body":["<article data-history-node-id=\"8010\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-722\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-722<br \/><strong>Date:<\/strong> July\u00a020, 2026<\/p>\n\n<p>On July\u00a020, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Telco Automated Assurance\u00a0\u2013 version v1.4 and prior<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05082en_us&amp;docLocale=en_US\">HPESBNW05082 rev.1\u00a0- HPE Telco Automated Assurance, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-722","alert_type":396,"serial_number":"AV26-722","subject":"hpe","moderation_state":"published","external_url":null},{"nid":8011,"title":"WordPress security advisory (AV26-723) - Update 1","uuid":"707cae16-f38e-41b2-bd86-22d57a9941eb","banner":null,"lang":"en","date_modified":"2026-07-21","date_modified_ts":"2026-07-21T15:35:54Z","date_created":"2026-07-20T18:41:39Z","summary":null,"body":["<article data-history-node-id=\"8011\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-av26-723\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-723<br \/><strong>Date:<\/strong> July\u00a020, 2026<br \/><strong>Date:<\/strong> July\u00a021, 2026<\/p>\n\n<p>On July\u00a017, 2026, WordPress published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>WordPress 7.0\u00a0\u2013 versions prior to 7.0.2<\/li>\n\t<li>WordPress 6.9\u00a0\u2013 versions prior to 6.9.5<\/li>\n\t<li>WordPress 6.8\u00a0\u2013 versions prior to 6.8.6<\/li>\n\t<li>WordPress 7.1 beta\u00a0\u2013 versions prior to 7.1 beta2<\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-60137 and CVE-2026-63030 are being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n<p>On July 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60137 and CVE-2026-63030 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-fpp7-x2x2-2mjf\">Facilitated SQL injection vulnerability in the `author__not_in` parameter of `WP_Query`<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-ff9f-jf42-662q\">REST API batch-route confusion and SQL injection issue leading to Remote Code Execution<\/a><\/li>\n\t<li><a href=\"https:\/\/wordpress.org\/news\/2026\/07\/wordpress-7-0-2-release\/\">WordPress 7.0.2 Release<\/a><\/li>\n\t<li><a href=\"https:\/\/wordpress.org\/news\/category\/releases\/\">WordPress Releases<\/a><\/li>\n  <li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137\">CISA KEV: CVE-2026-60137<\/a><\/li>\n  <li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030\">CISA KEV: CVE-2026-63030<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-av26-723","alert_type":396,"serial_number":"AV26-723","subject":"other","moderation_state":"published","external_url":null},{"nid":8013,"title":"Tenable security advisory (AV26-724)","uuid":"e1a0dcea-7e47-4435-9dc4-2d7a9aaea59e","banner":null,"lang":"en","date_modified":"2026-07-21","date_modified_ts":"2026-07-21T13:56:14Z","date_created":"2026-07-21T13:50:50Z","summary":null,"body":["<article data-history-node-id=\"8013\" about=\"\/en\/alerts-advisories\/tenable-security-advisory-av26-724\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-724<br \/><strong>Date:<\/strong> July 21, 2026<\/p>\n\n<p>On July 20, 2026, Tenable published a security advisory to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Tenable Security Center \u2013 version 6.6.0 to 6.8.0<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-19\">[R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-security-advisory-av26-724","alert_type":396,"serial_number":"AV26-724","subject":"other","moderation_state":"published","external_url":null},{"nid":8014,"title":"Zyxel security advisory (AV26-725)","uuid":"8535cfef-eea5-4718-80ef-f0c5f7fd15da","banner":null,"lang":"en","date_modified":"2026-07-21","date_modified_ts":"2026-07-21T14:02:40Z","date_created":"2026-07-21T13:59:35Z","summary":null,"body":["<article data-history-node-id=\"8014\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av26-725\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-725<br \/><strong>Date:<\/strong> July 21, 2026<\/p>\n\n<p>On July 21, 2026, Zyxel published a security advisory to address a vulnerability in the following products:<\/p>\n\n<ul><li>DSL\/Ethernet CPE \u2013 multiple versions and models<\/li>\n\t<li>Fiber ONTs \u2013 multiple versions and models<\/li>\n\t<li>Wireless Extenders \u2013 multiple versions and models<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-certain-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-07-21-2026\">Zyxel security advisory for post-authentication command injection vulnerability in certain DSL\/Ethernet CPE, Fiber ONTs, and Wireless Extenders<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\">Zyxel Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av26-725","alert_type":396,"serial_number":"AV26-725","subject":"other","moderation_state":"published","external_url":null},{"nid":8015,"title":"Mozilla security advisory (AV26-726)","uuid":"6aa74506-917f-4efd-8624-3df75fa7310b","banner":null,"lang":"en","date_modified":"2026-07-21","date_modified_ts":"2026-07-21T14:12:40Z","date_created":"2026-07-21T14:09:10Z","summary":null,"body":["<article data-history-node-id=\"8015\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-726\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-726<br \/><strong>Date:<\/strong> July 21, 2026<\/p>\n\n<p>On July 21, 2026, Mozilla published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:<\/p>\n\n<ul><li>Firefox ESR \u2013 versions prior to 140.13<\/li>\n\t<li>Firefox ESR \u2013 versions prior to 115.38<\/li>\n\t<li>Firefox \u2013 versions prior to 153<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-70\/\">Mozilla Foundation Security Advisory 2026-70<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-69\/\">Mozilla Foundation Security Advisory 2026-69<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-68\/\">Mozilla Foundation Security Advisory 2026-68<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-726","alert_type":396,"serial_number":"AV26-726","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":8016,"title":"HPE security advisory (AV26-727)","uuid":"aef86368-e2eb-4056-8e5c-0080c6c2f522","banner":null,"lang":"en","date_modified":"2026-07-21","date_modified_ts":"2026-07-21T18:35:00Z","date_created":"2026-07-21T18:29:05Z","summary":null,"body":["<article data-history-node-id=\"8016\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-727\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-727<br \/><strong>Date:<\/strong> July 22, 2026<\/p>\n\n<p>On July 21, 2026, HPE published security advisories to address vulnerabilities in the following products. Include was a critical update for the following:<\/p>\n\n<ul><li>HPE Aruba Networking Private 5G Core\u00a0\u2013 versions 1.26.1.1 and prior<\/li>\n\t<li>HPE Aruba Networking EdgeConnect SD-WAN Gateways\u00a0\u2013 multiple versions and platforms<\/li>\n\t<li>HPE Aruba Networking AOS-CX\u00a0\u2013 multiple versions and platforms<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05083en_us&amp;docLocale=en_US#hpesbnw05083-rev-1-private-5g-core-traefik-strippr-0\">HPESBNW05083 rev.1\u00a0- Private 5G Core, Traefik StripPrefix Route-Level Auth Bypass via Path Normalization (CVE-2026-48020)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05013en_us&amp;docLocale=en_US#hpesbnw05013-rev-1-hpe-aruba-networking-edgeconnec-0\">HPESBNW05013 rev.1\u00a0- HPE Aruba Networking EdgeConnect SD-WAN Gateways, Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05081en_us&amp;docLocale=en_US#hpesbnw05081-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW05081 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking AOS-CX<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-727","alert_type":396,"serial_number":"AV26-727","subject":"hpe","moderation_state":"published","external_url":null},{"nid":8018,"title":"SolarWinds security advisory (AV26-728)","uuid":"7e42dfe4-de5a-4ac6-a753-8ef5b3cdd7d1","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T12:11:16Z","date_created":"2026-07-22T12:07:20Z","summary":null,"body":["<article data-history-node-id=\"8018\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-728\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-728<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a021, 2026, SolarWinds published security advisories to address critical vulnerabilities in the following product:<\/p>\n\n<ul><li>SolarWinds Serv-U\u00a0\u2013 version 15.5.4 HF1 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-728","alert_type":396,"serial_number":"AV26-728","subject":"other","moderation_state":"published","external_url":null},{"nid":8019,"title":"Oracle security advisory \u2013 July 2026 quarterly rollup (AV26-729)","uuid":"b4fd7954-2fba-41bd-9fa4-209c86a11238","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T14:58:18Z","date_created":"2026-07-22T14:33:17Z","summary":null,"body":["<article data-history-node-id=\"8019\" about=\"\/en\/alerts-advisories\/oracle-security-advisory-july-2026-quarterly-rollup-av26-729\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-729<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a021, 2026, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:<\/p>\n\n<ul><li>Oracle Database Server<\/li>\n\t<li>Oracle APEX<\/li>\n\t<li>Oracle Autonomous Health Framework<\/li>\n\t<li>Oracle Essbase<\/li>\n\t<li>Oracle Global Lifecycle Management<\/li>\n\t<li>Oracle GoldenGate<\/li>\n\t<li>Oracle NoSQL Database<\/li>\n\t<li>Oracle Spatial Studio<\/li>\n\t<li>Oracle SQL Developer<\/li>\n\t<li>Oracle TimesTen In-Memory Database<\/li>\n\t<li>Oracle Application Testing Suite<\/li>\n\t<li>Oracle Commerce<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Construction and Engineering<\/li>\n\t<li>Oracle E-Business Suite<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Food and Beverage Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle Analytics<\/li>\n\t<li>Oracle HealthCare Applications<\/li>\n\t<li>Oracle Hospitality Applications<\/li>\n\t<li>Oracle Java SE<\/li>\n\t<li>Oracle JD Edwards<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle PeopleSoft<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Siebel CRM<\/li>\n\t<li>Oracle Supply Chain<\/li>\n\t<li>Oracle Systems<\/li>\n\t<li>Oracle Utilities Applications<\/li>\n\t<li>Oracle Virtualization<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cpujul2026.html\">Oracle Critical Patch Update Advisory\u00a0\u2013 July 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-security-advisory-july-2026-quarterly-rollup-av26-729","alert_type":396,"serial_number":"AV26-729","subject":"oracle","moderation_state":"published","external_url":null},{"nid":8020,"title":"Google Chrome security advisory (AV26-730)","uuid":"d1a74480-6157-48c3-a403-9ba79ba7898e","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T15:14:05Z","date_created":"2026-07-22T15:10:52Z","summary":null,"body":["<article data-history-node-id=\"8020\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-730\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-730<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a021, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 150.0.7871.181\/.182 (Windows\/Mac), and 150.0.7871.181 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_0256605430.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-730","alert_type":396,"serial_number":"AV26-730","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8021,"title":"Atlassian security advisory (AV26-731)","uuid":"25710073-a436-4cee-a767-f8bcc77f17b6","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T15:48:29Z","date_created":"2026-07-22T15:35:08Z","summary":null,"body":["<article data-history-node-id=\"8021\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-731\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-731<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a021, 2026, Atlassian published a security advisory to address vulnerabilities, including some critical ones, in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Bitbucket Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Confluence Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Crowd Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Fisheye\/Crucible\u00a0\u2013 versions 4.9.0 to 4.9.11<\/li>\n\t<li>Jira Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Jira Service Management Data Center and Server\u00a0\u2013 multiple versions<\/li>\n\t<li>Sourcetree for Mac\u00a0\u2013 all versions from 3.4.11 to 3.4.12<\/li>\n\t<li>Sourcetree for Windows\u00a0\u2013 all versions from 3.4.11 to 3.4.12<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/spaces\/SECURITY\/pages\/1821999345\/Security+Bulletin+-+July+21+2026\">Security Bulletin\u00a0- July 21 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.atlassian.com\/trust\/security\/advisories\">Atlassian Security Advisories and Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-731","alert_type":396,"serial_number":"AV26-731","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":8022,"title":"ISC BIND security advisory (AV26-732)","uuid":"548b5736-74c6-4305-b5ea-a52e9a518d30","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T17:44:57Z","date_created":"2026-07-22T17:34:19Z","summary":null,"body":["<article data-history-node-id=\"8022\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-732\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-732<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a022, 2026, ISC published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>ISC BIND 9\u00a0\u2013 versions 9.11.0 to 9.18.50<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.20.0 to 9.20.24<\/li>\n\t<li>ISC BIND 9\u00a0\u2013 versions 9.21.0 to 9.21.23<\/li>\n\t<li>BIND Supported Preview Edition\u00a0\u2013 versions 9.11.3-S1 to 9.18.50-S1<\/li>\n\t<li>BIND Supported Preview Edition\u00a0\u2013 versions 9.16.8-S1 to 9.18.50-S1<\/li>\n\t<li>BIND Supported Preview Edition\u00a0\u2013 versions 9.18.11-S1 to 9.18.50-S1<\/li>\n\t<li>BIND Supported Preview Edition\u00a0\u2013 versions 9.20.9-S1 to 9.20.24-S1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Security Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-732","alert_type":396,"serial_number":"AV26-732","subject":"other","moderation_state":"published","external_url":null},{"nid":8023,"title":"n8n security advisory (AV26-733)","uuid":"10f49c93-2fdb-4cd5-a383-77e2c5958fd4","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T17:53:53Z","date_created":"2026-07-22T17:48:55Z","summary":null,"body":["<article data-history-node-id=\"8023\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-733\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-733<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a022, 2026, n8n published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>n8n\u00a0\u2013 versions prior to 1.123.67<\/li>\n\t<li>n8n\u00a0\u2013 versions prior to 2.32.1<\/li>\n\t<li>n8n\u00a0\u2013 versions prior to 2.31.5<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-rcv6-pvrj-4xcg\">Authenticated code execution in the n8n Git node<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-733","alert_type":396,"serial_number":"AV26-733","subject":"other","moderation_state":"published","external_url":null},{"nid":8024,"title":"Mitel security advisory (AV26-734)","uuid":"00acf6ce-0f0b-48a8-9f00-45a19214b5f9","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T18:07:41Z","date_created":"2026-07-22T18:03:12Z","summary":null,"body":["<article data-history-node-id=\"8024\" about=\"\/en\/alerts-advisories\/mitel-security-advisory-av26-734\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-734<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a022, 2026, Mitel published security advisories to address vulnerabilities in the following products. Included were critical updates for the following::<\/p>\n\n<ul><li>MiCollab\u00a0\u2013 multiple versions<\/li>\n\t<li>OpenScape UC\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2026-0006\">Mitel Product Security Advisory MISA-2026-0006\u00a0- MiCollab Command Injection Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\/mitel-product-security-advisory-misa-2026-0007\">Mitel Product Security Advisory MISA-2026-0007\u00a0- OpenScape UC Cross Reflected Site Scripting (XSS) Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mitel.com\/support\/security-advisories\">Mitel Security Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mitel-security-advisory-av26-734","alert_type":396,"serial_number":"AV26-734","subject":"mitel","moderation_state":"published","external_url":null},{"nid":8025,"title":"Check Point security advisory (AV26-735)  \u2013 Update 1","uuid":"a47d6d70-9e84-49ea-9201-49577bf746e7","banner":null,"lang":"en","date_modified":"2026-07-23","date_modified_ts":"2026-07-23T12:26:51Z","date_created":"2026-07-22T18:12:02Z","summary":null,"body":["<article data-history-node-id=\"8025\" about=\"\/en\/alerts-advisories\/check-point-security-advisory-av26-735\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-735<br \/><strong>Date: <\/strong>July\u00a022, 2026<br \/><strong>Updated: <\/strong>July\u00a023, 2026<\/p>\n\n<p>On July\u00a022, 2026, Check Point published a security advisory to address vulnerabilities in the following products. Included was a critical update for the following\u00a0:<\/p>\n\n<ul><li>Security Management, Multi-Domain Management\u00a0\u2013 multiple versions<\/li>\n\t<li>Firewall, Multi-Domain Management, Multi-Domain Log Server\u00a0\u2013 multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">Check Point is aware that CVE-2026-16232 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On July\u00a022, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16232 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.checkpoint.com\/security\/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232\/\">Security Advisory\u00a0\u2013 Action Required\u00a0\u2013 July 2026 Security Update<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/\">Check Point Security<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232\">CISA KEV: CVE-2026-16232<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/check-point-security-advisory-av26-735","alert_type":396,"serial_number":"AV26-735","subject":"other","moderation_state":"published","external_url":null},{"nid":8026,"title":"Progress security advisory (AV26-736)","uuid":"40f0fa6a-da14-40d0-a0d7-14d7b9485764","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T18:27:51Z","date_created":"2026-07-22T18:24:25Z","summary":null,"body":["<article data-history-node-id=\"8026\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-736\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-736<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a021, 2026, Progress published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>ShareFile Storage Zones Controller v5\u00a0\u2013 versions prior to 5.12.4<\/li>\n\t<li>ShareFile Storage Zones Controller v6\u00a0\u2013 versions prior to 6.0.1<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sharefile.com\/s\/article\/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information\">ShareFile Storage Zones Controller (SZC) Service Disruption Guidance, Login Issues, and Access Information<\/a><\/li>\n\t<li><a href=\"https:\/\/www.progress.com\/trust-center\">Progress Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-736","alert_type":396,"serial_number":"AV26-736","subject":"other","moderation_state":"published","external_url":null},{"nid":8027,"title":"Exim security advisory (AV26-737)","uuid":"befe9252-e393-415c-b476-ca2765d6540e","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T18:47:05Z","date_created":"2026-07-22T18:39:30Z","summary":null,"body":["<article data-history-node-id=\"8027\" about=\"\/en\/alerts-advisories\/exim-security-advisory-av26-737\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-737<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a022, 2026, Exim published a security advisory to address a vulnerability in the following product:<\/p>\n\n<ul><li>Exim\u00a0\u2013 version 4.88 to 4.99.4<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.exim.org\/static\/doc\/security\/EXIM-Security-2026-06-22.1\/EXIM-Security-2026-06-22.1.txt\">Exim Security Advisory for EXIM-Security-2026-06-22.1 \/ GCVE-25-2026-07-45-1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.exim.org\/\">Exim Internet Mailer<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-av26-737","alert_type":396,"serial_number":"AV26-737","subject":"other","moderation_state":"published","external_url":null},{"nid":8028,"title":"Drupal security advisory (AV26-738)","uuid":"96d2026a-efdf-4cbb-8d77-0c33625cd408","banner":null,"lang":"en","date_modified":"2026-07-22","date_modified_ts":"2026-07-22T18:56:34Z","date_created":"2026-07-22T18:52:55Z","summary":null,"body":["<article data-history-node-id=\"8028\" about=\"\/en\/alerts-advisories\/drupal-security-advisory-av26-738\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-738<br \/><strong>Date: <\/strong>July\u00a022, 2026<\/p>\n\n<p>On July\u00a022, 2026, Drupal published security advisories to address a vulnerability in the following product. Included was a critical update for the following:<\/p>\n\n<ul><li>Internationalization Single Sign-On\u00a0\u2013 versions prior to 1.8.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates or perform the suggested mitigations.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.drupal.org\/sa-contrib-2026-081\">Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081<\/a><\/li>\n\t<li><a href=\"https:\/\/www.drupal.org\/security\">Drupal Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/drupal-security-advisory-av26-738","alert_type":396,"serial_number":"AV26-738","subject":"drupal","moderation_state":"published","external_url":null},{"nid":8029,"title":"JetBrains security advisory (AV26-739)","uuid":"5ac8b4f0-eeb8-40ab-a023-6a02fbdd1e43","banner":null,"lang":"en","date_modified":"2026-07-23","date_modified_ts":"2026-07-23T14:32:58Z","date_created":"2026-07-23T14:18:55Z","summary":null,"body":["<article data-history-node-id=\"8029\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-739\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-739<br \/><strong>Date: <\/strong>July\u00a023, 2026<\/p>\n\n<p>On July\u00a023, 2026, JetBrains published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>JetBrains GoLand\u00a0- versions prior to 2026.2<\/li>\n\t<li>JetBrains IntelliJ IDEA\u00a0- version prior to 2026.2<\/li>\n\t<li>JetBrains PhpStorm\u00a0- version prior to 2026.2<\/li>\n  \t<li>JetBrains PyCharm\u00a0\u2013 version prior to 2026.1.4 and 2026.2<\/li>\n  \t<li>JetBrains TeamCity\u00a0\u2013 version prior to 2026.1.2 and 2025.11.6 <\/li>\n  \t<li>JetBrains WebStorm\u00a0\u2013 version prior to 2026.2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/ \">JetBrains\u00a0\u2013 Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-739","alert_type":396,"serial_number":"AV26-739","subject":"other","moderation_state":"published","external_url":null},{"nid":8030,"title":"Microsoft Edge security advisory (AV26-740)","uuid":"bf36f2fb-5b41-4ae4-9f73-e0711a226e0c","banner":null,"lang":"en","date_modified":"2026-07-24","date_modified_ts":"2026-07-24T13:58:29Z","date_created":"2026-07-24T13:52:05Z","summary":null,"body":["<article data-history-node-id=\"8030\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-740\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-740<br \/><strong>Date: <\/strong>July\u00a024, 2026<\/p>\n\n<p>On July\u00a023, 2026, Microsoft published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge Stable Channel\u00a0\u2013 versions prior to 150.0.4078.96<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#july-23-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-740","alert_type":396,"serial_number":"AV26-740","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":8031,"title":"Google Chrome security advisory (AV26-741)","uuid":"ad47f67d-a64b-4da8-b487-50a6dd871bcf","banner":null,"lang":"en","date_modified":"2026-07-24","date_modified_ts":"2026-07-24T14:22:21Z","date_created":"2026-07-24T14:07:24Z","summary":null,"body":["<article data-history-node-id=\"8031\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-741\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-741<br \/><strong>Date: <\/strong>July\u00a024, 2026<\/p>\n\n<p>On July\u00a023, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\u00a0\u2013 versions prior to 150.0.7871.186\/.187 (Windows\/Mac), and 150.0.7871.186 (Linux)<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_01320465736.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-741","alert_type":396,"serial_number":"AV26-741","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8033,"title":"[Control Systems] Moxa security advisory (AV26-742)","uuid":"72617174-37ca-4c6b-ac6d-bfba6a1c30d1","banner":null,"lang":"en","date_modified":"2026-07-24","date_modified_ts":"2026-07-24T14:46:28Z","date_created":"2026-07-24T14:31:53Z","summary":null,"body":["<article data-history-node-id=\"8033\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-742\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-742<br \/><strong>Date: <\/strong>July\u00a024, 2026<\/p>\n\n<p>On July\u00a024, 2026, Moxa published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>Moxa UC Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Moxa V Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Moxa VM-1220 Series\u00a0\u2013 version MIL3 v1.1.0 and prior<\/li>\n\t<li>Moxa ioThinx 4530 Series\u00a0\u2013 version MIL3 v2.1 and prior<\/li>\n\t<li>Moxa AIG Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Moxa BXP Series\u00a0\u2013 multiple versions and models<\/li>\n\t<li>Moxa DRP-A100 Series \/ DRP-C100 Series\u00a0\u2013 version Debian 11 V1.0<\/li>\n\t<li>Moxa RKP Series\u00a0\u2013 multiple versions and models<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-267410-cve-2026-46333-ssh-keysign-pwn-vulnerability-in-linux-kernel\">CVE-2026-46333: ssh-keysign-pwn Vulnerability in Linux Kernel<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\">Moxa Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-742","alert_type":398,"serial_number":"AV26-742","subject":"other","moderation_state":"published","external_url":null},{"nid":8034,"title":"Ericsson security advisory (AV26-743)","uuid":"32003928-c9bd-4d42-9631-f51984e81a1a","banner":null,"lang":"en","date_modified":"2026-07-24","date_modified_ts":"2026-07-24T17:11:58Z","date_created":"2026-07-24T17:05:04Z","summary":null,"body":["<article data-history-node-id=\"8034\" about=\"\/en\/alerts-advisories\/ericsson-security-advisory-av26-743\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-743<br \/><strong>Date: <\/strong>July\u00a024, 2026<\/p>\n\n<p>On July\u00a024, 2026, Ericsson published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Packet Core Controller (PCC)\u00a0\u2013 versions prior to 1.38<\/li>\n\t<li>Packet Core Controller (PCC)\u00a0\u2013 versions prior to 1.39<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/psirt\/security-bulletin-pcc-july-2026\">Security Bulletin\u00a0\u2013 Ericsson Packet Core Controller (PCC), July 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ericsson.com\/en\/about-us\/security\/security-bulletins\">Ericsson Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ericsson-security-advisory-av26-743","alert_type":396,"serial_number":"AV26-743","subject":"other","moderation_state":"published","external_url":null},{"nid":8035,"title":"MongoDB security advisory (AV26-744)","uuid":"c47671b4-0e97-4b7a-bc5c-326335f9148e","banner":null,"lang":"en","date_modified":"2026-07-24","date_modified_ts":"2026-07-24T17:29:02Z","date_created":"2026-07-24T17:22:12Z","summary":null,"body":["<article data-history-node-id=\"8035\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory-av26-744\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-744<br \/><strong>Date: <\/strong>July\u00a024, 2026<\/p>\n\n<p>On July\u00a022, 2026, MongoDB published security advisories to address vulnerabilities in the following products:<\/p>\n\n<ul><li>MongoDB Compass\u00a0\u2013 versions prior to 1.49.7<\/li>\n\t<li>MongoDB Server\u00a0\u2013 versions prior to 7.0.39<\/li>\n\t<li>MongoDB Server\u00a0\u2013 versions prior to 8.0.28<\/li>\n\t<li>MongoDB Server\u00a0\u2013 versions prior to 8.2.12<\/li>\n\t<li>MongoDB Server\u00a0\u2013 versions prior to 8.3.7<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mongodb.com\/resources\/products\/alerts#security\">Security Related: Common Vulnerabilities and Exposures (CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mongodb.com\/resources\/products\/alerts\">MongoDB Alerts<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory-av26-744","alert_type":396,"serial_number":"AV26-744","subject":"other","moderation_state":"published","external_url":null},{"nid":8036,"title":"HPE security advisory (AV26-745)","uuid":"61affd15-c593-41e7-8cfb-888de21ce7c7","banner":null,"lang":"en","date_modified":"2026-07-24","date_modified_ts":"2026-07-24T19:03:10Z","date_created":"2026-07-24T18:57:01Z","summary":null,"body":["<article data-history-node-id=\"8036\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-745\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-745<br \/><strong>Date: <\/strong>July\u00a024, 2026<\/p>\n\n<p>On July\u00a024, 2026, HPE published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>HPE Unified Correlation Analyzer (UCA)\u00a0\u2013 versions 4.4.11 and prior<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05085en_us&amp;docLocale=en_US#hpesbnw05085-rev-1-hpe-unified-correlation-analyze-0\">HPESBNW05085 rev.1\u00a0- HPE Unified Correlation Analyzer (UCA), Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-745","alert_type":396,"serial_number":"AV26-745","subject":"other","moderation_state":"published","external_url":null},{"nid":8037,"title":"Progress security advisory (AV26-746)","uuid":"01d4d026-8851-4f4e-9b05-55ae7d3041c8","banner":null,"lang":"en","date_modified":"2026-07-24","date_modified_ts":"2026-07-24T19:38:17Z","date_created":"2026-07-24T19:31:48Z","summary":null,"body":["<article data-history-node-id=\"8037\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-746\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-746<br \/><strong>Date: <\/strong>July\u00a024, 2026<\/p>\n\n<p>On July\u00a023, 2026, Progress published security advisories to address vulnerabilities in the following product:<\/p>\n\n<ul><li>MOVEit Transfer\u00a0\u2013 versions prior to 2025.1.5<\/li>\n\t<li>MOVEit Transfer\u00a0\u2013 versions prior to 2026.0.3<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.progress.com\/bundle\/moveit-transfer-release-notes-2026\/page\/Fixed-Issues-in-2026.0.3.html\">MOVEit Transfer 2026 Release Notes\u00a0- Fixed Issues in 2026.0.3<\/a><\/li>\n\t<li><a href=\"https:\/\/www.progress.com\/trust-center\">Progress Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-746","alert_type":396,"serial_number":"AV26-746","subject":"other","moderation_state":"published","external_url":null},{"nid":8038,"title":"Microsoft security advisory (AV26-747)","uuid":"ad32728c-938d-454a-afd9-c1a351b61fa5","banner":null,"lang":"en","date_modified":"2026-07-27","date_modified_ts":"2026-07-27T17:58:33Z","date_created":"2026-07-27T17:46:14Z","summary":null,"body":["<article data-history-node-id=\"8038\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-av26-747\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-747<br \/><strong>Date: <\/strong>July 27 2026<\/p>\n\n<p><strong>Microsoft security advisory (AV26-747)<\/strong><\/p>\n\n<p>As of July 26, 2026, Microsoft is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based)<\/li>\n\t<li>Prior to 150.0.4078.99<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-57978\">Security Update Guide\u00a0- Microsoft Security Response Center<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-57989\">Security Update Guide\u00a0- Microsoft Security Response Center (1)<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-57990\">Security Update Guide\u00a0- Microsoft Security Response Center (2)<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\">Security Update Guide\u00a0- Microsoft Security Response Center (3)<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-av26-747","alert_type":396,"serial_number":"AV26-747","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":8039,"title":"Redis security advisory (AV26-748)","uuid":"c9be7229-7235-428c-a9b0-f9698272b2d5","banner":null,"lang":"en","date_modified":"2026-07-27","date_modified_ts":"2026-07-27T18:12:06Z","date_created":"2026-07-27T18:01:22Z","summary":null,"body":["<article data-history-node-id=\"8039\" about=\"\/en\/alerts-advisories\/redis-security-advisory-av26-748\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-748<br \/><strong>Date: <\/strong>July 27, 2026<\/p>\n\n<p>As of July 25, 2026, Redis is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Redis<\/li>\n\t<li>Versions prior to 8.8.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/redis\/redis\/compare\/8.6.4...8.8.0\">Comparing 8.6.4...8.8.0<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/redis\/redis\/pull\/15081\">Reject corrupt stream RDB with shared NACK across consumers #15081<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/redis\/redis\/releases\">Releases \u00b7 redis\/redis \u00b7 GitHub<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/redis-security-advisory-av26-748","alert_type":396,"serial_number":"AV26-748","subject":"other","moderation_state":"published","external_url":null},{"nid":8040,"title":"Erlang security advisory (AV26-750)","uuid":"fe0b95f0-8c5e-483c-aade-6f4580a948fa","banner":null,"lang":"en","date_modified":"2026-07-27","date_modified_ts":"2026-07-27T19:52:49Z","date_created":"2026-07-27T19:48:33Z","summary":null,"body":["<article data-history-node-id=\"8040\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av26-750\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-750<br \/><strong>Date: <\/strong>July 27, 2026<\/p>\n\n<p>As of July 27, 2026, Erlang is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>OTP\n\t<ul><li>10.2 Prior to 11.7.4<\/li>\n\t\t<li>6.0 Prior to 17.0.4<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/\">Security Advisories \u00b7 erlang\/otp \u00b7 GitHub <\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av26-750","alert_type":396,"serial_number":"AV26-750","subject":"other","moderation_state":"published","external_url":null},{"nid":8042,"title":"Arista Networks security advisory (AV26-751)","uuid":"bafd8893-24e1-4815-83ff-8fac1296894e","banner":null,"lang":"en","date_modified":"2026-07-28","date_modified_ts":"2026-07-28T14:34:26Z","date_created":"2026-07-28T13:26:16Z","summary":null,"body":["<article data-history-node-id=\"8042\" about=\"\/en\/alerts-advisories\/arista-networks-security-advisory-av26-751\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-751<br \/><strong>Date: <\/strong>July\u00a028, 2026<\/p>\n\n<p>As of July\u00a027, 2026, Arista Networks is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>VeloCloud Orchestrator On-Prem\n\t<ul><li>from 5.2.0 to versions prior to 5.2.3.14<\/li>\n\t\t<li>from 6.1.0 to versions prior to 6.1.3.4<\/li>\n\t\t<li>from 6.4.0 to versions prior to 6.4.2.4<\/li>\n\t\t<li>from 7.0.0 to versions prior to 7.0.0.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>On July\u00a027, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16812 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\/security-advisory\/24364-security-advisory-0144\">Security Advisory 0144<\/a><\/li>\n\t<li><a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\/security-advisory\/24365-security-advisory-0145\">Security Advisory 0145<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16812\">CISA KEV: CVE-2026-16812<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/arista-networks-security-advisory-av26-751","alert_type":396,"serial_number":"AV26-751","subject":"other","moderation_state":"published","external_url":null},{"nid":8043,"title":"JetBrains security advisory (AV26-752) \u2013 Update 1","uuid":"9469dfc5-a4cd-4f7a-b35c-1ad51741d1af","banner":null,"lang":"en","date_modified":"2026-08-05","date_modified_ts":"2026-08-05T18:44:01Z","date_created":"2026-07-28T13:26:16Z","summary":null,"body":["<article data-history-node-id=\"8043\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-752\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-752<br \/><strong>Date:<\/strong> July\u00a028, 2026<br \/><strong>Updated:<\/strong> August\u00a05, 2026<\/p>\n\n<p>As of July\u00a027, 2026, JetBrains is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>TeamCity\n\t<ul><li>Prior to 2026.1.3, 2025.11.7<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On August\u00a05, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-63077 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">Fixed security issues<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.jetbrains.com\/security\/\">Security\u00a0- The JetBrains Blog<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077\">CISA KEV: CVE-2026-63077<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-752","alert_type":396,"serial_number":"AV26-752","subject":"other","moderation_state":"published","external_url":null},{"nid":8041,"title":"Apache security advisory (AV26-749)","uuid":"48f696f6-e481-4386-82d9-00e21896a71a","banner":null,"lang":"en","date_modified":"2026-07-28","date_modified_ts":"2026-07-28T14:32:14Z","date_created":"2026-07-28T13:26:16Z","summary":null,"body":["<article data-history-node-id=\"8041\" about=\"\/en\/alerts-advisories\/apache-security-advisory-av26-749\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-749<br \/><strong>Date: <\/strong>July\u00a028, 2026<\/p>\n\n<p>As of July\u00a027, 2026, Apache is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Apache Thrift\n\t<ul><li>Prior to 0.24.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.apache.org\/thread\/p008svsjf9p6bj47wyyf5dgglq5z7xoq\">CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit<\/a><\/li>\n\t<li><a href=\"https:\/\/lists.apache.org\/thread\/fmjl8l415tj9zwlob8v2dr5hq1d0hts7\">CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb<\/a><\/li>\n\t<li><a href=\"https:\/\/lists.apache.org\/thread\/xmkgd107k795hyrg5kf97mny30sgl5bo\">CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()<\/a><\/li>\n\t<li><a href=\"https:\/\/lists.apache.org\/thread\/z2myopbovxngfvchdz8hddots9p5ffbt\">CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apache-security-advisory-av26-749","alert_type":396,"serial_number":"AV26-749","subject":"other","moderation_state":"published","external_url":null},{"nid":8044,"title":"Apple security advisory (AV26-753)","uuid":"621def85-0fe6-4ff3-99a6-437ec7ddb94a","banner":null,"lang":"en","date_modified":"2026-07-28","date_modified_ts":"2026-07-28T14:37:10Z","date_created":"2026-07-28T13:26:17Z","summary":null,"body":["<article data-history-node-id=\"8044\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-753\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-753<br \/><strong>Date:<\/strong> July\u00a028, 2026<\/p>\n\n<p>As of July\u00a027, 2026, Apple is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\n\t<ul><li>Prior to 26.6<\/li>\n\t<\/ul><\/li>\n\t<li>macOS\n\t<ul><li>Prior to 14.8.8<\/li>\n\t\t<li>Prior to 15.7.8<\/li>\n\t\t<li>Prior to 26.6<\/li>\n\t<\/ul><\/li>\n\t<li>tvOS\n\t<ul><li>Prior to 26.6<\/li>\n\t<\/ul><\/li>\n\t<li>visionOS\n\t<ul><li>Prior to 26.6<\/li>\n\t<\/ul><\/li>\n\t<li>Safari\n\t<ul><li>Prior to 26.6<\/li>\n\t<\/ul><\/li>\n\t<li>watchOS\n\t<ul><li>Prior to 26.6<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases\u00a0- Apple Support<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-753","alert_type":396,"serial_number":"AV26-753","subject":"apple","moderation_state":"published","external_url":null},{"nid":8045,"title":"Vercel security advisory (AV26-754)","uuid":"3474db2b-0c01-4c83-8071-daa40b2beccd","banner":null,"lang":"en","date_modified":"2026-07-28","date_modified_ts":"2026-07-28T14:40:27Z","date_created":"2026-07-28T13:26:18Z","summary":null,"body":["<article data-history-node-id=\"8045\" about=\"\/en\/alerts-advisories\/vercel-security-advisory-av26-754\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-754<br \/><strong>Date:<\/strong> July\u00a028, 2026<\/p>\n\n<p>As of July\u00a027, 2026, Vercel is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>next.js\n\t<ul><li>Prior to 15.5.21<\/li>\n\t\t<li>Prior to 16.2.11<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/vercel\/next.js\/releases\/tag\/v15.5.21\">Release v15.5.21<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/vercel\/next.js\/releases\/tag\/v16.2.11\">Release v16.2.11<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vercel-security-advisory-av26-754","alert_type":396,"serial_number":"AV26-754","subject":"other","moderation_state":"published","external_url":null},{"nid":8046,"title":"Progress security advisory (AV26-755)","uuid":"a69f932f-6905-4d5e-abed-ef07a87e6393","banner":null,"lang":"en","date_modified":"2026-07-28","date_modified_ts":"2026-07-28T18:14:11Z","date_created":"2026-07-28T18:09:58Z","summary":null,"body":["<article data-history-node-id=\"8046\" about=\"\/en\/alerts-advisories\/progress-software-security-advisory-av26-755\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-755<br \/><strong>Date: <\/strong>July\u00a028, 2026<\/p>\n\n<p>As of July\u00a027, 2026, Progress Software is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>ECS Connection Manager\n\t<ul><li>Prior to 7.2.63.3<\/li>\n\t<\/ul><\/li>\n\t<li>LoadMaster\n\t<ul><li>Prior to 7.2.54.19<\/li>\n\t\t<li>Prior to 7.2.63.3<\/li>\n\t<\/ul><\/li>\n\t<li>MOVEit WAF\n\t<ul><li>Prior to 7.2.63.3<\/li>\n\t<\/ul><\/li>\n\t<li>Multi Tenant\n\t<ul><li>Prior to 7.1.35.16<\/li>\n\t<\/ul><\/li>\n\t<li>Object Scale Connection Manager\n\t<ul><li>Prior to 7.2.63.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690\">LoadMaster Critical Security Bulletin \u2013 July 2026\u202f\u2013 (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690) <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-software-security-advisory-av26-755","alert_type":396,"serial_number":"AV26-755","subject":"other","moderation_state":"published","external_url":null},{"nid":8048,"title":"Adobe security advisory (AV26-756)","uuid":"1af9e658-3c84-4487-9384-858f8d0fbd74","banner":null,"lang":"en","date_modified":"2026-07-29","date_modified_ts":"2026-07-29T14:33:45Z","date_created":"2026-07-29T14:22:20Z","summary":null,"body":["<article data-history-node-id=\"8048\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-756\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-756<br \/><strong>Date:<\/strong> July 29, 2026<\/p>\n\n<p>As of July 28, 2026, Adobe is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Bridge\n\t<ul><li>Prior to 15.1.7<\/li>\n\t\t<li>Prior to 16.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>Format Plugins\n\t<ul><li>Prior to 2026.07<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/formatplugins\/apsb26-87.html\">Security updates available for Adobe Format Plugins | APSB26-87<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb26-89.html\">Security Updates Available for Adobe Bridge | APSB26-89<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Product Security Incident Response Team<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-756","alert_type":396,"serial_number":"AV26-756","subject":"adobe","moderation_state":"published","external_url":null},{"nid":8049,"title":"Cisco security advisory (AV26-757)","uuid":"b71c7ddf-765e-48e0-92d4-65c2fb48e9f1","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T12:45:49Z","date_created":"2026-07-30T12:31:03Z","summary":null,"body":["<article data-history-node-id=\"8049\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-757\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-757<br \/><strong>Date: <\/strong>July\u00a029, 2026<\/p>\n\n<p>As of July\u00a029, 2026, Cisco is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Cisco Secure Firewall Management Center (FMC)\n\t<ul><li>Prior to 7.0.9.1<\/li>\n\t\t<li>Prior to 7.2.11.1<\/li>\n\t\t<li>Prior to 7.4.7.1<\/li>\n\t\t<li>Prior to 7.6.5.1<\/li>\n\t\t<li>Prior to 7.7.12.1<\/li>\n\t\t<li>Prior to 10.0.1.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">Cisco has indicated that CVE-2026-20316 is being exploited.<\/p>\n\n<p class=\"mrgn-bttm-md\">On July 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20316 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-fmc-static-cred-BET3Cjh\">Cisco Secure Firewall Management Center Software Static Credential Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316\">CISA KEV\u00a0: CVE-2026-20316<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-757","alert_type":396,"serial_number":"AV26-757","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8050,"title":"GitLab security advisory (AV26-758)","uuid":"629ea080-7b78-4f22-b494-56ae4135f5a8","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T13:11:52Z","date_created":"2026-07-30T13:01:17Z","summary":null,"body":["<article data-history-node-id=\"8050\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-758\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-758<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of July\u00a029, 2026, GitLab is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>GitLab\n\t<ul><li>Prior to 19.0.5<\/li>\n\t\t<li>Prior to 19.1.3<\/li>\n\t\t<li>Prior to 19.2.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-2-1-released\/\">GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.gitlab.com\/releases\/\">GitLab release notes<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-758","alert_type":396,"serial_number":"AV26-758","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":8051,"title":"Spring security advisory (AV26-759)","uuid":"6ea3e617-63e7-470c-95fa-9e5f875f7e49","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T13:50:36Z","date_created":"2026-07-30T13:32:02Z","summary":null,"body":["<article data-history-node-id=\"8051\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-759\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-759<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of July\u00a030, 2026, Spring is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Spring Tools for Eclipse\n\t<ul><li>Prior to or equal to 5.2.0<\/li>\n\t<\/ul><\/li>\n\t<li>Spring Tools for VSCode \/ Cursor \/ Theia\n\t<ul><li>Prior to or equal to 2.2.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/cve-2026-47858\/\">CVE-2026-47858: live information startup mode is vulnerable for remote code execution<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-47873\/\">CVE-2026-47873: Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces <\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-47882\/\">CVE-2026-47882: Spring Boot DevTools remote secret generated with a non-cryptographic PRNG<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-59326\/\">CVE-2026-59326: HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-59327\/\">CVE-2026-59327: Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations <\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/cve-2026-59328\/\">CVE-2026-59328: Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips<\/a><\/li>\n\t<li><a href=\"https:\/\/spring.io\/security\/\">Spring | Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-759","alert_type":396,"serial_number":"AV26-759","subject":"other","moderation_state":"published","external_url":null},{"nid":8053,"title":"Adobe security advisory (AV26-760)","uuid":"53dcf274-f262-4889-92db-02c6ea77eae1","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T14:18:55Z","date_created":"2026-07-30T14:10:57Z","summary":null,"body":["<article data-history-node-id=\"8053\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-760\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-760<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of July\u00a029, 2026, Adobe is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Adobe Campaign Classic\n\t<ul><li>ALL except 7.4.3 build 9398<\/li>\n\t\t<li>Prior to or equal to 7.4.3 build 9397<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-114.html\">Security update available for Adobe Campaign Classic | APSB26-114<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Product Security Incident Response Team<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-760","alert_type":396,"serial_number":"AV26-760","subject":"adobe","moderation_state":"published","external_url":null},{"nid":8054,"title":"WebPros security advisory (AV26-761)","uuid":"8e583bd9-6d9b-49f5-9752-9f264d225b1a","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T14:36:27Z","date_created":"2026-07-30T14:33:10Z","summary":null,"body":["<article data-history-node-id=\"8054\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-761\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-761<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of July\u00a030, 2026, WebPros is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Plesk\n\t<ul><li>Prior to 18.0.79.4<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/42139500580119-Vulnerability-CVE-2026-58046-Blind-SQL-injection-in-Plesk-s-XML-RPC-API\">Vulnerability CVE-2026-58046: Blind SQL injection in Plesk's XML-RPC API\u00a0\u2013 Plesk<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-761","alert_type":396,"serial_number":"AV26-761","subject":"other","moderation_state":"published","external_url":null},{"nid":8055,"title":"[Control Systems] Phoenix Contact security advisory (AV26-762)","uuid":"5d2358d2-c06e-4e11-a025-47ea530c4cef","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T14:49:52Z","date_created":"2026-07-30T14:44:03Z","summary":null,"body":["<article data-history-node-id=\"8055\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-762\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-762<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of July\u00a030, 2026, Phoenix Contact is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>CHARX SEC-3000\n\t<ul><li>Prior to 1.9.1<\/li>\n\t<\/ul><\/li>\n\t<li>CHARX SEC-3050\n\t<ul><li>Prior to 1.9.1<\/li>\n\t<\/ul><\/li>\n\t<li>CHARX SEC-3100\n\t<ul><li>Prior to 1.9.1<\/li>\n\t<\/ul><\/li>\n\t<li>CHARX SEC-3150\n\t<ul><li>Prior to 1.9.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.certvde.com\/en\/advisories\/VDE-2026-008\/\">Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-762","alert_type":398,"serial_number":"AV26-762","subject":"other","moderation_state":"published","external_url":null},{"nid":8056,"title":"VMware security advisory (AV26-763) \u2013 Update 1","uuid":"526cb4cf-7f41-45e1-96ea-57882573daa2","banner":null,"lang":"en","date_modified":"2026-08-18","date_modified_ts":"2026-08-18T18:01:05Z","date_created":"2026-07-30T17:34:29Z","summary":null,"body":["<article data-history-node-id=\"8056\" about=\"\/en\/alerts-advisories\/vmware-security-advisory-av26-763\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-763<br \/><strong>Date: <\/strong>July\u00a030, 2026<br \/><strong>Updated:<\/strong> August 18, 2026<\/p>\n\n<p>As of July\u00a030, 2026, VMware is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cloud Foundation\n\t<ul><li>5.x<\/li>\n\t\t<li>9.0.x.x<\/li>\n\t\t<li>9.1.x.x<\/li>\n\t\t<li>Prior to 5.2.3<\/li>\n\t<\/ul><\/li>\n\t<li>ESX\n\t<ul><li>Prior to ESXi-9.0.2.0100-25595025<\/li>\n\t\t<li>Prior to ESXi-9.1.0.0-25370933<\/li>\n\t\t<li>Prior to ESXi-9.1.0.0200-25557999<\/li>\n\t\t<li>Prior to ESXi80U3i-25205845<\/li>\n\t\t<li>Prior to ESXi80U3k-25595708<\/li>\n\t<\/ul><\/li>\n\t<li>Fusion\n\t<ul><li>Prior to 26H1<\/li>\n\t<\/ul><\/li>\n\t<li>Telco Cloud Infrastructure\n\t<ul><li>3.0<\/li>\n\t<\/ul><\/li>\n\t<li>Telco Cloud Platform\n\t<ul><li>4.x<\/li>\n\t\t<li>5.0.x<\/li>\n\t\t<li>5.1.x<\/li>\n\t<\/ul><\/li>\n\t<li>Workstation\n\t<ul><li>Prior to 26H1<\/li>\n\t<\/ul><\/li>\n\t<li>vCenter\n\t<ul><li>Prior to 8.0 U3k<\/li>\n\t\t<li>Prior to 9.0.2.0100<\/li>\n\t\t<li>Prior to 9.1.0.0300<\/li>\n\t<\/ul><\/li>\n\t<li>vSphere Foundation\n\t<ul><li>9.0.x.x<\/li>\n\t\t<li>9.1.x.x<\/li>\n\t<\/ul><\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On August 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-59310 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/38017\">VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/security-advisory\">Security Advisories\u00a0- VMware Cloud Foundation<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310\">CISA KEV: CVE-2026-59310<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/vmware-security-advisory-av26-763","alert_type":396,"serial_number":"AV26-763","subject":"vmware","moderation_state":"published","external_url":null},{"nid":8057,"title":"PHP Group security advisory (AV26-764)","uuid":"60d5e811-1fea-4433-815b-564026bec5ba","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T18:11:55Z","date_created":"2026-07-30T18:06:39Z","summary":null,"body":["<article data-history-node-id=\"8057\" about=\"\/en\/alerts-advisories\/php-group-security-advisory-av26-764\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-764<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of\u00a0July 30, 2026, PHP Group is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>PHP\n\t<ul><li>Prior to 8.2.33<\/li>\n\t\t<li>Prior to 8.3.33<\/li>\n\t\t<li>Prior to 8.4.24<\/li>\n\t\t<li>Prior to 8.5.9<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/php\/php-src\/security\/advisories\/GHSA-7qpv-r5mr-78m4\">SQL injection in ext-pgsql via E'...' backslash breakout<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/php\/php-src\/security\/advisories\/GHSA-x692-q9x7-8c3f\">Out-of-bounds write in bccomp() via crafted operand and scale<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/php-group-security-advisory-av26-764","alert_type":396,"serial_number":"AV26-764","subject":"other","moderation_state":"published","external_url":null},{"nid":8058,"title":"Gladinet security advisory (AV26-765)","uuid":"b34ae943-3fa7-4973-a5d4-d082ac7bab0b","banner":null,"lang":"en","date_modified":"2026-07-30","date_modified_ts":"2026-07-30T18:24:27Z","date_created":"2026-07-30T18:20:14Z","summary":null,"body":["<article data-history-node-id=\"8058\" about=\"\/en\/alerts-advisories\/gladinet-security-advisory-av26-765\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-765<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of July\u00a030, 2026, Gladinet is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>CentreStack\n\t<ul><li>Prior to 17.5<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.centrestack.com\/\">CentreStack<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gladinet-security-advisory-av26-765","alert_type":396,"serial_number":"AV26-765","subject":"other","moderation_state":"published","external_url":null},{"nid":8060,"title":"SolarWinds security advisory (AV26-766)","uuid":"87566cf1-9760-4970-a371-2ba82367a2fd","banner":null,"lang":"en","date_modified":"2026-07-31","date_modified_ts":"2026-07-31T13:00:19Z","date_created":"2026-07-31T12:49:48Z","summary":null,"body":["<article data-history-node-id=\"8060\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-766\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-766<br \/><strong>Date: <\/strong>July\u00a030, 2026<\/p>\n\n<p>As of July\u00a030, 2026, SolarWinds is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Web Help Desk (WHD)\n\t<ul><li>Prior to 2026.2.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.solarwinds.com\/en\/success_center\/whd\/content\/release_notes\/whd_2026-2-1_release_notes.htm\">WHD 2026.2.1 release notes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2026-28323\">SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability (CVE-2026-28323)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-766","alert_type":396,"serial_number":"AV26-766","subject":"other","moderation_state":"published","external_url":null},{"nid":8061,"title":"Rails security advisory (AV26-767)","uuid":"fab466b9-83c4-4e73-9dde-67acbfdab232","banner":null,"lang":"en","date_modified":"2026-07-31","date_modified_ts":"2026-07-31T13:17:03Z","date_created":"2026-07-31T13:11:47Z","summary":null,"body":["<article data-history-node-id=\"8061\" about=\"\/en\/alerts-advisories\/rails-security-advisory-av26-767\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-767<br \/><strong>Date:<\/strong> July\u00a031, 2026<\/p>\n\n<p>As of July\u00a030, 2026, Rails is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Rails\n\t<ul><li>Prior to 8.0.5.1<\/li>\n\t\t<li>Prior to 8.1.3.1<\/li>\n\t\t<li>Prior to 7.2.3.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/rails\/rails\/releases\/tag\/v7.2.3.2\">Release 7.2.3.2 \u00b7 rails\/rails\u00a0- GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/rails\/rails\/releases\/tag\/v8.0.5.1\">Release 8.0.5.1 \u00b7 rails\/rails\u00a0- GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/rails\/rails\/releases\/tag\/v8.1.3.1\">Release 8.1.3.1 \u00b7 rails\/rails\u00a0- GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.rubyonrails.org\/t\/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing\/91432\">[CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/rails\/rails\/releases\">Release list - rails\/rails<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rails-security-advisory-av26-767","alert_type":396,"serial_number":"AV26-767","subject":"other","moderation_state":"published","external_url":null},{"nid":8062,"title":"Google security advisory (AV26-768)","uuid":"04ac44f1-54b7-4455-a7e0-b452a379ce17","banner":null,"lang":"en","date_modified":"2026-07-31","date_modified_ts":"2026-07-31T14:23:37Z","date_created":"2026-07-31T14:17:57Z","summary":null,"body":["<article data-history-node-id=\"8062\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-768\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-768<br \/><strong>Date: <\/strong> July 31, 2026<\/p>\n\n<p>As of July 30, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\u00a0- Prior to 151.0.7922.72<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_0887107924.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-768","alert_type":396,"serial_number":"AV26-768","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8063,"title":"N-able security advisory (AV26-769) - Update 2","uuid":"785f33d8-b956-4eaf-bfec-20eeaf92d4c3","banner":null,"lang":"en","date_modified":"2026-08-07","date_modified_ts":"2026-08-07T14:37:42Z","date_created":"2026-08-04T13:04:16Z","summary":null,"body":["<article data-history-node-id=\"8063\" about=\"\/en\/alerts-advisories\/n-able-security-advisory-av26-769\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-769<br \/><strong>Date: <\/strong>August\u00a04, 2026<br \/><strong>Updated: <\/strong>August 7, 2026<\/p>\n\n<p>As of August\u00a02, 2026, N-able is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>N-central\n\t<ul><li>Prior to 2026.3.1.10<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<p>On August\u00a03, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On August\u00a04, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18556 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On August 6, 2026, N-able released Hotfix 2 to further mitigate these vulnerabilities.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.n-able.com\/N-central\/Release_Notes\/GA\/Content\/N-central_2026.3_HF1_Release_Notes.htm\">2026.3 HF1 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/status.n-able.com\/2026\/08\/02\/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577\/\">N-central 2026.3\u00a0Hotfix\u00a01\u00a0\u2013\u00a0Mitigation for CVE-2026-18577\u00a0| N-able Status<\/a><\/li>\n\t<li><a href=\"https:\/\/status.n-able.com\/2026\/08\/06\/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577\/\">N-central 2026.3 Hotfix 2&amp;nsp;\u2013 Additional Mitigation for CVE-2026-18577<\/a><\/li>\n\t<li><a href=\"https:\/\/status.n-able.com\/release-notes\/\">Release Notes | N-able Status<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577\">CISA KEV:CVE-2026-18577<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556\">CISA KEV: CVE-2026-18556<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n-able-security-advisory-av26-769","alert_type":396,"serial_number":"AV26-769","subject":"other","moderation_state":"published","external_url":null},{"nid":8064,"title":"IBM security advisory (AV26-770)","uuid":"9e5b4426-cb44-43aa-9319-48772e5dc01d","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T15:06:33Z","date_created":"2026-08-04T14:25:25Z","summary":null,"body":["<article data-history-node-id=\"8064\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-770\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-770<br \/><strong>Date: <\/strong>August 4, 2026<\/p>\n\n<p>As of July 30, 2026, IBM is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>App Connect Enterprise\n\t<ul><li>Prior to or equal to 12.0.12.27<\/li>\n\t\t<li>Prior to or equal to 13.0.7.2<\/li>\n\t<\/ul><\/li>\n\t<li>DataPower Gateway 10.5.0\n\t<ul><li>Prior to or equal to 10.5.0.21<\/li>\n\t<\/ul><\/li>\n\t<li>DataPower Gateway 10.6.0\n\t<ul><li>Prior to or equal to 10.6.0.9<\/li>\n\t<\/ul><\/li>\n\t<li>DataPower Gateway 10.6CD\n\t<ul><li>Prior to or equal to 10.6.6<\/li>\n\t<\/ul><\/li>\n\t<li>DataPower Gateway 11.0.0\n\t<ul><li>Prior to or equal to 11.0.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>Db2\n\t<ul><li>Prior to or equal to 11.5.9<\/li>\n\t\t<li>Prior to or equal to 12.1.4<\/li>\n\t<\/ul><\/li>\n\t<li>Engineering Requirements Management DOORS and DOORS Web Access\n\t<ul><li>Prior to or equal to 9.6.1.13<\/li>\n\t\t<li>Prior to or equal to 9.7.2.11<\/li>\n\t<\/ul><\/li>\n\t<li>Enterprise Build of Quarkus\n\t<ul><li>Prior to or equal to 3.27.4.SP2<\/li>\n\t\t<li>Prior to or equal to 3.33.2.SP2<\/li>\n\t<\/ul><\/li>\n\t<li>HMC V10.3.1050.0\n\t<ul><li>Prior to or equal to 10.3.1064.0<\/li>\n\t<\/ul><\/li>\n\t<li>HMC V11.1.1110.0\n\t<ul><li>Prior to or equal to 11.1.1112.0<\/li>\n\t<\/ul><\/li>\n\t<li>Langflow OSS\n\t<ul><li>Prior to or equal to 1.10.0<\/li>\n\t\t<li>Prior to or equal to 1.10.1<\/li>\n\t\t<li>Prior to or equal to 1.8.4<\/li>\n\t<\/ul><\/li>\n\t<li>Operations Analytics - Log Analysis\n\t<ul><li>1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3<\/li>\n\t\t<li>1.3.6.0, 1.3.6.1<\/li>\n\t\t<li>1.3.7.0, 1.3.7.1, 1.3.7.2<\/li>\n\t\t<li>1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4<\/li>\n\t<\/ul><\/li>\n\t<li>Planning Analytics Local\n\t<ul><li>Prior to or equal to 2.1.21<\/li>\n\t<\/ul><\/li>\n\t<li>PowerVM Hypervisor\n\t<ul><li>Prior to or equal to FW1060.71<\/li>\n\t\t<li>Prior to or equal to FW1110.20<\/li>\n\t\t<li>Prior to or equal to FW950.H1<\/li>\n\t<\/ul><\/li>\n\t<li>Security Verify Access\n\t<ul><li>Prior to or equal to 10.0.9.1<\/li>\n\t<\/ul><\/li>\n\t<li>Security Verify Access Container\n\t<ul><li>Prior to or equal to 10.0.9.1<\/li>\n\t<\/ul><\/li>\n\t<li>UCD - IBM DevOps Deploy\n\t<ul><li>Prior to or equal to 8.0.1.13<\/li>\n\t\t<li>Prior to or equal to 8.1.2.6<\/li>\n\t\t<li>Prior to or equal to 8.2.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>UCD - IBM UrbanCode Deploy\n\t<ul><li>Prior to or equal to 7.2.3.23<\/li>\n\t\t<li>Prior to or equal to 7.3.2.18<\/li>\n\t<\/ul><\/li>\n\t<li>Verify Identity Access\n\t<ul><li>Prior to or equal to 11.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>Verify Identity Access Container\n\t<ul><li>Prior to or equal to 11.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>WebSphere Application Server\n\t<ul><li>8.5<\/li>\n\t\t<li>9.0<\/li>\n\t<\/ul><\/li>\n\t<li>WebSphere Application Server - Liberty\n\t<ul><li>Prior to or equal to 26.0.0.7<\/li>\n\t<\/ul><\/li>\n\t<li>webMethods Integration (on prem)\n\t<ul><li>10.15, 10.11<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<p>On August 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-9198 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198\">CISA KEV: CVE-2026-9198<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-770","alert_type":396,"serial_number":"AV26-770","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8065,"title":"Dell security advisory (AV26-771)","uuid":"01c0c4d1-f0f5-4237-8fd8-2476e1311944","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T15:23:08Z","date_created":"2026-08-04T15:17:49Z","summary":null,"body":["<article data-history-node-id=\"8065\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-771\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-771<br \/><strong>Date: <\/strong>August 4, 2026<\/p>\n\n<p>As of August 4, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Display and Peripheral Manager (DDPM Mac)\n\t<ul><li>Prior to 2.3.0.1005<\/li>\n\t<\/ul><\/li>\n\t<li>Monitor driver\n\t<ul><li>Prior to 1.0.0.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000481265\/dsa-2026-295\">DSA-2026-295: Security Update for Dell Monitor Driver for an Improper Link Resolution Before File Access ('Link Following') Vulnerability | Dell US<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000490035\/dsa-2026-319-security-updates-for-dell-display-and-peripheral-manager-ddpm-mac-for-multiple-vulnerabilities\">DSA-2026-319 Security Updates for Dell Display and Peripheral Manager (DDPM Mac) for Multiple Vulnerabilities | Dell US<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources | Dell Canada<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-771","alert_type":396,"serial_number":"AV26-771","subject":"dell","moderation_state":"published","external_url":null},{"nid":8066,"title":"WebPros security advisory (AV26-772)","uuid":"5a16b8b0-5401-4d13-9972-a6426bc64e77","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T15:31:21Z","date_created":"2026-08-04T15:24:51Z","summary":null,"body":["<article data-history-node-id=\"8066\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-772\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-772<br \/><strong>Date:<\/strong> August 4, 2026<\/p>\n\n<p>As of July 31, 2026, WebPros is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>WP Squared\n\t<ul><li>Prior to 11.138.1.6<\/li>\n\t<\/ul><\/li>\n\t<li>cPanel\n\t<ul><li>Prior to 11.110.0.137<\/li>\n\t\t<li>Prior to 11.118.0.71<\/li>\n\t\t<li>Prior to 11.126.0.78<\/li>\n\t\t<li>Prior to 11.134.0.48<\/li>\n\t\t<li>Prior to 11.136.0.32<\/li>\n\t\t<li>Prior to 138.1.6 ( WP2 )<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/42285024734743-Security-CVE-2026-58047-HTTP-Request-Smuggling\">Security: CVE-2026-58047 HTTP Request Smuggling \u2013 cPanel<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/42285745783703-Security-CVE-2026-58048-Database-Privilege-Escalation\">Security: CVE-2026-58048 Database Privilege Escalation \u2013 cPanel<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360007088193-Security\">cPanel Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-772","alert_type":396,"serial_number":"AV26-772","subject":"other","moderation_state":"published","external_url":null},{"nid":8067,"title":"Tenable, Inc. security advisory (AV26-773)","uuid":"bd210022-e5b0-4a3d-9de7-73d5a76246a2","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T15:36:27Z","date_created":"2026-08-04T15:32:52Z","summary":null,"body":["<article data-history-node-id=\"8067\" about=\"\/en\/alerts-advisories\/tenable-inc-security-advisory-av26-773\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-773<br \/><strong>Date: <\/strong>August 4, 2026<\/p>\n\n<p>As of August 3, 2026, Tenable, Inc. is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Sensor Proxy\n\t<ul><li>Prior to 1.4.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-21\">[R1] Sensor Proxy Version 1.4.2 Fixes One Vulnerability - Security Advisory | Tenable\u00ae<\/a><\/li>\n\t<li><a href=\"https:\/\/www.tenable.com\/security\">Tenable Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-inc-security-advisory-av26-773","alert_type":396,"serial_number":"AV26-773","subject":"other","moderation_state":"published","external_url":null},{"nid":8068,"title":"Checkpoint security advisory (AV26-774)","uuid":"260776a3-ba88-49f2-84f7-3777e3f3ee1c","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T15:44:42Z","date_created":"2026-08-04T15:38:38Z","summary":null,"body":["<article data-history-node-id=\"8068\" about=\"\/en\/alerts-advisories\/checkpoint-security-advisory-av26-774\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-774<br \/><strong>Date: <\/strong>August 3, 2026<\/p>\n\n<p>As of August 3, 2026, checkpoint is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>Multi-Domain Security Management Server (MDS)\n\t<ul><li>R80<\/li>\n\t\t<li>R80.10<\/li>\n\t\t<li>R80.20<\/li>\n\t\t<li>R80.30<\/li>\n\t\t<li>R80.40<\/li>\n\t\t<li>R81<\/li>\n\t\t<li>R81.10<\/li>\n\t\t<li>R81.20 with Jumbo Hotfix Accumulator Take 160 or below<\/li>\n\t\t<li>R82 with Jumbo Hotfix Accumulator Take 121 or below<\/li>\n\t\t<li>R82.10 with Jumbo Hotfix Accumulator Take 39 or below<\/li>\n\t<\/ul><\/li>\n\t<li>Security Management Server\n\t<ul><li>R80<\/li>\n\t\t<li>R80.10<\/li>\n\t\t<li>R80.20<\/li>\n\t\t<li>R80.30<\/li>\n\t\t<li>R80.40<\/li>\n\t\t<li>R81<\/li>\n\t\t<li>R81.10<\/li>\n\t\t<li>R81.20 with Jumbo Hotfix Accumulator Take 160 or below<\/li>\n\t\t<li>R82 with Jumbo Hotfix Accumulator Take 121 or below<\/li>\n\t\t<li>R82.10 with Jumbo Hotfix Accumulator Take 39 or below<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185222\">sk185222 - CVE-2026-18574 - Management Authentication Bypass<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/\">Check Point Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/checkpoint-security-advisory-av26-774","alert_type":396,"serial_number":"AV26-774","subject":"other","moderation_state":"published","external_url":null},{"nid":8069,"title":"MISP security advisory (AV26-775)","uuid":"c9c1e19a-526b-4021-a778-337f4d598d98","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T17:31:23Z","date_created":"2026-08-04T17:24:13Z","summary":null,"body":["<article data-history-node-id=\"8069\" about=\"\/en\/alerts-advisories\/misp-security-advisory-av26-775\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-775<br \/><strong>Date: <\/strong>August 4, 2026<\/p>\n\n<p>As of August 3, 2026, Malware Information Sharing Platform (MISP) is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>cti-transmute\n\t<ul><li>Prior to or equal to 1.4.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/MISP\/cti-transmute\/commit\/20f35307bcb706c8dd8ca3884a88fb36b05b5244\">fix: [website] Block file and network fetches in the evaluation PDF r\u2026 \u00b7 MISP\/cti-transmute@20f3530 \u00b7 GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/MISP\/cti-transmute\/commit\/321892d26b82c8a5af1e210ee30735abb109fac2\">fix: [website] Cap the activity-timeline day range \u00b7 MISP\/cti-transmute@321892d \u00b7 GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/MISP\/cti-transmute\/commit\/4f0d051ec5f1d45894c26987d409411728b2d82c\">fix: [website] Require POST to delete a user \u00b7 MISP\/cti-transmute@4f0d051 \u00b7 GitHub<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/misp-security-advisory-av26-775","alert_type":396,"serial_number":"AV26-775","subject":"other","moderation_state":"published","external_url":null},{"nid":8070,"title":"Adobe security advisory (AV26-776)","uuid":"90d3a926-226b-4804-a22b-2a120ae2feba","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T19:46:09Z","date_created":"2026-08-04T19:35:39Z","summary":null,"body":["<article data-history-node-id=\"8070\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-776\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-776<br \/><strong>Date:<\/strong> August\u00a04, 2026<\/p>\n\n<p>As of August\u00a03, 2026, Adobe is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Campaign Classic\n\t<ul><li>ACC v7: 7.4.3 build 9398 and prior<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Premiere\n\t<ul><li>26.2.2 and prior<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Premiere Pro\n\t<ul><li>25.6.5 and prior<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-120.html\">Security update available for Adobe Campaign Classic | APSB26-120<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/premiere_pro\/apsb26-76.html\">Security Updates Available for Adobe Premiere Pro | APSB26-76<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Product Security Incident Response Team<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-776","alert_type":396,"serial_number":"AV26-776","subject":"adobe","moderation_state":"published","external_url":null},{"nid":8071,"title":"Veeam security advisory (AV26-777)","uuid":"90fafb93-26b2-4a01-a5e5-960c7f7cacb1","banner":null,"lang":"en","date_modified":"2026-08-04","date_modified_ts":"2026-08-04T20:03:24Z","date_created":"2026-08-04T19:58:10Z","summary":null,"body":["<article data-history-node-id=\"8071\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-777\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-777<br \/><strong>Date:<\/strong> August 4, 2026<\/p>\n\n<p>As of August 4, 2026, Veeam is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>ONE\n\t<ul><li>Prior to or equal to 13.1.0.7034<\/li>\n\t<\/ul><\/li>\n\t<li>Service Provider Console\n\t<ul><li>Prior to 9.3.0.35057<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4893\">KB4893: Vulnerabilities Resolved in Veeam Service Provider Console 9.3<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4892\">KB4892: Vulnerabilities Resolved in Veeam ONE 13.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html?type=security\">Veeam Support Knowledge Base<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-777","alert_type":396,"serial_number":"AV26-777","subject":"other","moderation_state":"published","external_url":null},{"nid":8072,"title":"Hewlett Packard Enterprise (HPE) security advisory (AV26-778)","uuid":"a1ac48f7-d1b0-4e71-a55d-a3da384d2172","banner":null,"lang":"en","date_modified":"2026-08-05","date_modified_ts":"2026-08-05T12:53:05Z","date_created":"2026-08-05T12:46:33Z","summary":null,"body":["<article data-history-node-id=\"8072\" about=\"\/en\/alerts-advisories\/hewlett-packard-enterprise-hpe-security-advisory-av26-778\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-778<br \/><strong>Date: <\/strong>August\u00a05, 2026<\/p>\n\n<p>As of August\u00a04, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>EdgeConnect SD-WAN Orchestrator\n\t<ul><li>Prior to or equal to 9.6.2.40208<\/li>\n\t\t<li>Prior to or equal to 9.6.3.40137<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05100en_us&amp;docLocale=en_US#hpesbnw05100-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW05100 rev.1\u00a0- Multiple Vulnerabilities in HPE Networking EdgeConnect Orchestrator 9.6 branch<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hewlett-packard-enterprise-hpe-security-advisory-av26-778","alert_type":396,"serial_number":"AV26-778","subject":"other","moderation_state":"published","external_url":null},{"nid":8073,"title":"Zbtlink security advisory (AV26-779)","uuid":"c6641d90-42c2-43ea-81a1-19237b5cba72","banner":null,"lang":"en","date_modified":"2026-08-05","date_modified_ts":"2026-08-05T17:55:38Z","date_created":"2026-08-05T17:26:30Z","summary":null,"body":["<article data-history-node-id=\"8073\" about=\"\/en\/alerts-advisories\/zbtlink-security-advisory-av26-779\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-779<br \/><strong>Date: <\/strong>August\u00a05, 2026<\/p>\n\n<p>As of August\u00a05, 2026, Zbtlink is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>CPE2801 Firmware\n\t<ul><li>22.10.09<\/li>\n\t<\/ul><\/li>\n\t<li>WE1026-5G-WD Firmware\n\t<ul><li>21.04.07<\/li>\n\t<\/ul><\/li>\n\t<li>WE1326 Firmware\n\t<ul><li>22.02.18_1<\/li>\n\t<\/ul><\/li>\n\t<li>WE2007 Firmware\n\t<ul><li>23.08.12<\/li>\n\t<\/ul><\/li>\n\t<li>WE2008-DSIM Firmware\n\t<ul><li>23.08.11<\/li>\n\t<\/ul><\/li>\n\t<li>WE2416 Firmware\n\t<ul><li>21.03.22_1<\/li>\n\t<\/ul><\/li>\n\t<li>WE3326 Firmware\n\t<ul><li>20.09.30<\/li>\n\t<\/ul><\/li>\n\t<li>WE5927 Firmware\n\t<ul><li>22.08.10<\/li>\n\t<\/ul><\/li>\n\t<li>WE5931 Firmware\n\t<ul><li>22.05.31<\/li>\n\t<\/ul><\/li>\n\t<li>WE5931AC Firmware\n\t<ul><li>22.05.31<\/li>\n\t<\/ul><\/li>\n\t<li>WE826-T3-DSIM Firmware\n\t<ul><li>21.12.21<\/li>\n\t<\/ul><\/li>\n\t<li>WG108 Firmware\n\t<ul><li>21.08.06_1<\/li>\n\t<\/ul><\/li>\n\t<li>WG1602 Firmware\n\t<ul><li>23.10.11<\/li>\n\t<\/ul><\/li>\n\t<li>WG1608-DSIM Firmware\n\t<ul><li>23.03.16<\/li>\n\t<\/ul><\/li>\n\t<li>WG209 Firmware\n\t<ul><li>21.07.28<\/li>\n\t<\/ul><\/li>\n\t<li>WG2105 Firmware\n\t<ul><li>22.05.30<\/li>\n\t<\/ul><\/li>\n\t<li>WG2107 Firmware\n\t<ul><li>22.09.08<\/li>\n\t<\/ul><\/li>\n\t<li>WG259 Firmware\n\t<ul><li>21.03.23<\/li>\n\t<\/ul><\/li>\n\t<li>WG3526 Firmware\n\t<ul><li>22.11.01<\/li>\n\t<\/ul><\/li>\n\t<li>ZBT-Z8102AX-2SIM Firmware\n\t<ul><li>7.6.7.2-25.0814_114432<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/ycsunjane\/rctl\">GitHub\u00a0- ycsunjane\/rctl: remote linux control | GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/www.vulncheck.com\/advisories\/zbt-endlessdoors\">ENDLESSDOORS: Zbtlink Router rctl\/kworker Phone-Home Root Implant | Advisories | VulnCheck<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zbtlink.com\/pages\/zbt-router-firmware-download\">Zbtlink\u00a0- Firmware Download<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zbtlink-security-advisory-av26-779","alert_type":396,"serial_number":"AV26-779","subject":"other","moderation_state":"published","external_url":null},{"nid":8074,"title":"Zyxel security advisory (AV26-780)","uuid":"2e2ed0f1-d294-4663-90ec-280aedff9ebc","banner":null,"lang":"en","date_modified":"2026-08-06","date_modified_ts":"2026-08-06T11:58:54Z","date_created":"2026-08-06T11:45:43Z","summary":null,"body":["<article data-history-node-id=\"8074\" about=\"\/en\/alerts-advisories\/zyxel-security-advisory-av26-780\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-780<br \/><strong>Date: <\/strong>August\u00a05, 2026<\/p>\n\n<p>As of August\u00a04, 2026, Zyxel is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>ATP series firmware\n\t<ul><li>from V4.32 through V5.42 Patch 1<\/li>\n\t<\/ul><\/li>\n\t<li>USG FLEX 50(W) series firmware\n\t<ul><li>from V4.16 through V5.42 Patch 1<\/li>\n\t<\/ul><\/li>\n\t<li>USG FLEX series firmware\n\t<ul><li>from V4.50 through V5.42 Patch 1<\/li>\n\t<\/ul><\/li>\n\t<li>USG20(W)-VPN series firmware\n\t<ul><li>from V4.16 through V5.42 Patch 1<\/li>\n\t<\/ul><\/li>\n\t<li>WAX650S firmware\n\t<ul><li>Prior to or equal to 7.10(ABRM.4)C0<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-path-traversal-vulnerability-in-the-configuration-file-execution-cli-command-of-zld-firewalls-08-04-2026 \">Zyxel security advisory for path traversal vulnerability in the configuration file execution CLI command of ZLD firewalls<\/a><\/li>\n\t<li><a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026\">Zyxel security advisory for command injection and improper authentication vulnerabilities in certain APs, FWA7, and Security Routers | Zyxel Networks<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zyxel-security-advisory-av26-780","alert_type":396,"serial_number":"AV26-780","subject":"other","moderation_state":"published","external_url":null},{"nid":8075,"title":"Progress security advisory (AV26-781)","uuid":"e2339087-c44b-4a93-99ed-6b9feac224ce","banner":null,"lang":"en","date_modified":"2026-08-06","date_modified_ts":"2026-08-06T12:16:24Z","date_created":"2026-08-06T12:08:38Z","summary":null,"body":["<article data-history-node-id=\"8075\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-781\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-781<br \/><strong>Date: <\/strong>August\u00a05, 2026<\/p>\n\n<p>As of August\u00a05, 2026, Progress Software Corporation is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>MarkLogic Server\n\t<ul><li>Prior to 11.3.6<\/li>\n\t\t<li>Prior to 12.0.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/Marklogic-Critical-Security-Alert-Bulletin-August-2026\">Marklogic Critical Security Alert Bulletin\u00a0\u2013 August 2026\u00a0\u2013 (CVE-2026-7326, CVE-2026-7327, CVE-2026-7329, CVE-2026-7557, CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, CVE-2026-9203)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.progress.com\/trust-center \">Progress Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-781","alert_type":396,"serial_number":"AV26-781","subject":"other","moderation_state":"published","external_url":null},{"nid":8076,"title":"Jenkins security advisory (AV26-782)","uuid":"8db41ffe-f102-49a0-a5bb-8c48425cb06f","banner":null,"lang":"en","date_modified":"2026-08-06","date_modified_ts":"2026-08-06T12:39:37Z","date_created":"2026-08-06T12:24:44Z","summary":null,"body":["<article data-history-node-id=\"8076\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-782\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-782<br \/><strong>Date: <\/strong>August 6, 2026<\/p>\n\n<p>As of August 5, 2026, Jenkins Project is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins\n\t<ul><li>ALL except 2.568.2<\/li>\n\t\t<li>ALL except 2.576<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins AWS CodeBuild Plugin\n\t<ul><li>Prior to or equal to 0.59<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins CodeSonar Plugin\n\t<ul><li>Prior to or equal to 3.6.0<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins Google Chat Notification Plugin\n\t<ul><li>Prior to or equal to 166.ve6b_de280f2e8<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins Horreum Plugin\n\t<ul><li>Prior to or equal to 0.16.162.v33b_4a_a_b_5f828<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins Ivy Report Plugin\n\t<ul><li>Prior to or equal to 1.2<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins Multijob Plugin\n\t<ul><li>Prior to or equal to 669.v9d96a_d9c71b_0<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins Violation Comments to GitLab Plugin\n\t<ul><li>Prior to or equal to 2.62.0<\/li>\n\t<\/ul><\/li>\n\t<li>Jenkins XML Job to Job DSL Plugin\n\t<ul><li>Prior to or equal to 0.1.13<\/li>\n\t<\/ul><\/li>\n\t<li>Remoting\n\t<ul><li>ALL except 3355.3357.v931d3c992987<\/li>\n\t\t<li>ALL except 3385.vf1123fb_515da_<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-08-05\/\">Jenkins Security Advisory 2026-08-05 <\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-782","alert_type":396,"serial_number":"AV26-782","subject":"other","moderation_state":"published","external_url":null},{"nid":8077,"title":"GitHub security advisory (AV26-783)","uuid":"f9192653-e47a-4359-864a-e01d95e00d07","banner":null,"lang":"en","date_modified":"2026-08-06","date_modified_ts":"2026-08-06T12:47:42Z","date_created":"2026-08-06T12:40:26Z","summary":null,"body":["<article data-history-node-id=\"8077\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-783\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-783<br \/><strong>Date: <\/strong>August 6, 2026<\/p>\n\n<p>As of August 5, 2026, GitHub is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Enterprise Server\n\t<ul><li>3.17.0 Prior to 3.17.16<\/li>\n\t\t<li>3.17.0 Prior to 3.17.19<\/li>\n\t\t<li>3.18.0 Prior to 3.18.10<\/li>\n\t\t<li>3.18.0 Prior to 3.18.13<\/li>\n\t\t<li>3.19.0 Prior to 3.19.10<\/li>\n\t\t<li>3.19.0 Prior to 3.19.7<\/li>\n\t\t<li>3.20.0 Prior to 3.20.3<\/li>\n\t\t<li>3.20.0 Prior to 3.20.6<\/li>\n\t\t<li>3.21.0 Prior to 3.21.4<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.17 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.18 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.19 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.20\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.20 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.21\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.21 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/all-releases\">GitHub Enterprise Server releases\u00a0- GitHub Enterprise Server 3.19 Docs<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-783","alert_type":396,"serial_number":"AV26-783","subject":"other","moderation_state":"published","external_url":null},{"nid":8078,"title":"Foxit security advisory (AV26-784)","uuid":"8d08dbd9-0305-4b8e-b0b8-b7ce306ffbd1","banner":null,"lang":"en","date_modified":"2026-08-06","date_modified_ts":"2026-08-06T13:29:24Z","date_created":"2026-08-06T13:25:43Z","summary":null,"body":["<article data-history-node-id=\"8078\" about=\"\/en\/alerts-advisories\/foxit-security-advisory-av26-784\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-784<br \/><strong>Date: <\/strong>August 6, 2026<\/p>\n\n<p>As of August 6, 2026, Foxit is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Foxit PDF Services API\n\t<ul><li>before 2026-07-27<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.foxit.com\/support\/security-bulletins.html\">Security Bulletins | Foxit<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/foxit-security-advisory-av26-784","alert_type":396,"serial_number":"AV26-784","subject":"other","moderation_state":"published","external_url":null},{"nid":8079,"title":"Cisco security advisory (AV26-785)","uuid":"25be6ad6-f6b9-4776-93b4-7b7bb6af14e1","banner":null,"lang":"en","date_modified":"2026-08-06","date_modified_ts":"2026-08-06T14:00:41Z","date_created":"2026-08-06T13:33:15Z","summary":null,"body":["<article data-history-node-id=\"8079\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-785\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-785<br \/><strong>Date: <\/strong>August 6, 2026<\/p>\n\n<p>As of August 5, 2026, Cisco is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Catalyst SD-WAN Release\n\t<ul><li>prior to 20.9.10<\/li>\n\t\t<li>prior to 20.12.8.1<\/li>\n\t\t<li>prior to 20.15.6<\/li>\n\t\t<li>prior to 20.18.4<\/li>\n\t\t<li>prior to 26.1.2<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco IOS XE Software Release\n\t<ul><li>prior to 17.9.10<\/li>\n\t\t<li>prior to 17.12.8<\/li>\n\t\t<li>prior to 17.15.6<\/li>\n\t\t<li>prior to 17.18.4 and 17.18.4a<\/li>\n\t\t<li>prior to 26.1.2<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Secure FMC Software Release\n\t<ul><li>prior to Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar<\/li>\n\t\t<li>prior to Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar<\/li>\n\t\t<li>prior to Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar<\/li>\n\t\t<li>prior to Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar<\/li>\n\t\t<li>prior to Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar<\/li>\n\t\t<li>prior to Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco IOS XE Software with SNMPv1<\/li>\n\t<li>Cisco IOS XE Software with SNMPv2c<\/li>\n\t<li>Cisco IOS XE Software with SNMPv3<\/li>\n\t<li>Cisco IOS XE Software with BEEP feature enabled<\/li>\n\t<li>Cisco IOS Software or IOS XE Software with XMCP Server feature enabled<\/li>\n\t<li>Cisco NFVIS Release\n\t<ul><li>prior to 4.12<\/li>\n\t\t<li>prior to 4.13<\/li>\n\t\t<li>prior to 4.14<\/li>\n\t\t<li>prior to 4.15<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco UCS Server Software Release\n\t<ul><li>prior to 4.2<\/li>\n\t\t<li>prior to 4.3<\/li>\n\t\t<li>prior to 6.0<\/li>\n\t\t<li>prior to 3.2<\/li>\n\t\t<li>prior to 4.15<\/li>\n\t\t<li>prior to 4.3<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Telemetry Broker Appliances\n\t<ul><li>prior to 6.0(2.260143)<\/li>\n\t<\/ul><\/li>\n\t<li>IEC6400 Edge Compute Appliances\n\t<ul><li>prior to 4.3(6.260054)<\/li>\n\t<\/ul><\/li>\n\t<li>IOS XRv 9000 M7 Appliances\n\t<ul><li>prior to 6.0(2.260143)<\/li>\n\t<\/ul><\/li>\n\t<li>Secure Endpoint Private Cloud Appliances\n\t<ul><li>prior to 4.3(2.260020) (M5)<\/li>\n\t\t<li>prior to 4.3(6.260054) (M6)<\/li>\n\t<\/ul><\/li>\n\t<li>Secure Firewall Management (FMC) Center Appliances\n\t<ul><li>prior to 4.3(2.260020) (M5)<\/li>\n\t\t<li>prior to 6.0(2.260143) (M6, M8)<\/li>\n\t<\/ul><\/li>\n\t<li>Secure Malware Analytics Appliances\n\t<ul><li>prior to 4.3(2.260020) (M5)<\/li>\n\t\t<li>prior to 4.3(6.260054) (M6)<\/li>\n\t<\/ul><\/li>\n\t<li>Secure Network Analytics Appliances\n\t<ul><li>prior to 4.3(2.260020) (M5)<\/li>\n\t\t<li>prior to 6.0(2.260143) (M6)<\/li>\n\t<\/ul><\/li>\n\t<li>Secure Network Server (ISE SNS) Appliances\n\t<ul><li>prior to 4.3(2.260020) (M5)<\/li>\n\t\t<li>prior to 6.0(2.260143) (M6, M8)<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-sdwan-faLcR3K\">Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-iosxe-V8NMuMZJ\">Cisco IOS XE Software Security Hardening Release: August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-onprem-fmc-authbypass-5JPp45V2\">Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-iosxe-snmp-dos-ZAqNm4MD\">Cisco IOS XE Software SNMP Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-785","alert_type":396,"serial_number":"AV26-785","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8080,"title":"Django security advisory (AV26-786)","uuid":"09a0c968-8a46-4c3c-8f8b-951c6589c7a7","banner":null,"lang":"en","date_modified":"2026-08-06","date_modified_ts":"2026-08-06T15:39:19Z","date_created":"2026-08-06T15:35:48Z","summary":null,"body":["<article data-history-node-id=\"8080\" about=\"\/en\/alerts-advisories\/django-security-advisory-av26-786\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-786<br \/><strong>Date: <\/strong>August 6, 2026<\/p>\n\n<p>As of August 4, 2026, Django is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Django\n\t<ul><li>before 6.0.8<\/li>\n\t\t<li>before 5.2.17<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.djangoproject.com\/weblog\/2026\/aug\/04\/security-releases\/\">Django security releases issued: 6.0.8 and 5.2.17<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/django-security-advisory-av26-786","alert_type":396,"serial_number":"AV26-786","subject":"other","moderation_state":"published","external_url":null},{"nid":8081,"title":"Google security advisory (AV26-787)","uuid":"d0252bdd-ab0c-4627-9d2e-133813bcb1f5","banner":null,"lang":"en","date_modified":"2026-08-07","date_modified_ts":"2026-08-07T15:02:30Z","date_created":"2026-08-07T14:57:08Z","summary":null,"body":["<article data-history-node-id=\"8081\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-787\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-787<br \/><strong>Date: <\/strong>August 7, 2026<\/p>\n\n<p>As of August 6, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>versions prior to 151.0.7922.109<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/08\/stable-channel-update-for-desktop_01193673229.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-787","alert_type":396,"serial_number":"AV26-787","subject":"other","moderation_state":"published","external_url":null},{"nid":8083,"title":"Dell security advisory (AV26-788)","uuid":"da774b65-4df0-4b48-9bce-59bb62156ccd","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T12:38:31Z","date_created":"2026-08-10T12:33:34Z","summary":null,"body":["<article data-history-node-id=\"8083\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-788\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-788<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>As of August\u00a07, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell OpenManage Server Administrator Managed Node (Patch) for Windows\n\t<ul><li>Prior to 11.1.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>Dell OpenManage Server Administrator Managed Node for RHEL 8.10\n\t<ul><li>Prior to 11.1.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>Dell OpenManage Server Administrator Managed Node for RHEL 9.4\n\t<ul><li>Prior to 11.1.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>Dell OpenManage Server Administrator Managed Node for SLES 15\n\t<ul><li>Prior to 11.1.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>OpenManage Server Administrator Managed Node (Patch) for Windows\n\t<ul><li>Prior to 11.1.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>RVTools\n\t<ul><li>Prior to 4.8.1<\/li>\n\t<\/ul><\/li>\n\t<li>Virtual Storage Integrator for VMware vSphere Client\n\t<ul><li>Prior to 10.11.1.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000496035\/dsa-2026-335-security-update-for-dell-virtual-storage-integrator-for-vmware-vsphere-client-multiple-vulnerabilities?lwp=rt\">DSA-2026-335: Security Update for Dell Virtual Storage Integrator for VMware vSphere Client Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000494958\/dsa-2026-326-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilities?lwp=rt\">DSA-2026-326: Security Update for Dell OpenManage Server Administrator (OMSA) Network Access Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000494748\/dsa-2026-325-security-update-for-dell-rvtools-vulnerability\">DSA-2026-325: Security Update for Dell RVtools Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources\u00a0| Dell Canada<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-788","alert_type":396,"serial_number":"AV26-788","subject":"dell","moderation_state":"published","external_url":null},{"nid":8084,"title":"IBM security advisory (AV26-789)","uuid":"2389555d-36e1-4773-a590-6da8e8d8db38","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T13:56:51Z","date_created":"2026-08-10T13:53:47Z","summary":null,"body":["<article data-history-node-id=\"8084\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-789\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-789<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>As of August\u00a07, 2026, IBM is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Application Gateway Operator\n\t<ul><li>Prior to or equal to 26.06<\/li>\n\t<\/ul><\/li>\n\t<li>Big SQL on IBM Cloud Pak for Data\n\t<ul><li>Version Big SQL 7.7 on Cloud Pak for Data 5.0<\/li>\n\t<\/ul><\/li>\n\t<li>Big SQL on IBM Software Hub\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Business Automation Workflow containers and traditional\n\t<ul><li>26.0.0<\/li>\n\t\t<li>Prior to or equal to 24.0.0 Interim Fix 009<\/li>\n\t\t<li>Prior to or equal to 24.0.1 Interim Fix 007<\/li>\n\t\t<li>Prior to or equal to 25.0.0 Interim Fix 005<\/li>\n\t<\/ul><\/li>\n\t<li>Cloud APM, Advanced\/Base Private\n\t<ul><li>Prior to or equal to 8.1.4<\/li>\n\t<\/ul><\/li>\n\t<li>Cloud Pak For Business Automation\n\t<ul><li>24.0.0<\/li>\n\t\t<li>24.0.1<\/li>\n\t\t<li>25.0.0<\/li>\n\t\t<li>26.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Event Streams version\n\t<ul><li>13.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>Langflow OSS\n\t<ul><li>Prior to or equal to 1.10.3<\/li>\n\t<\/ul><\/li>\n\t<li>Maximo Application Suite\n\t<ul><li>9.0<\/li>\n\t\t<li>9.1<\/li>\n\t\t<li>9.2<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Netezza Appliance\n\t<ul><li>1.0.2.0<\/li>\n\t<\/ul><\/li>\n\t<li>Operational Decision Manager\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>PowerVC\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Process Automation Manager Open Edition Starter Kit for Banking\n\t<ul><li>Prior to or equal to 9.4.1<\/li>\n\t<\/ul><\/li>\n\t<li>SevOne Network Performance Management (Data Insight)\n\t<ul><li>Prior to or equal to 8.2.2<\/li>\n\t<\/ul><\/li>\n\t<li>QRadar\n\t<ul><li>Prior to or equal to 7.5.0 UP 15 Interim Fix 005<\/li>\n\t\t<li>Prior to or equal to 7.6.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>Security Verify Information Queue\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Storage Protect Operations Center\n\t<ul><li>Versions prior or equal to 8.1 and 8.2<\/li>\n\t<\/ul><\/li>\n\t<li>webMethods Managed File Transfer (on-prem)\n\t<ul><li>Prior to or equal to 11.1 and 12.1<\/li>\n\t<\/ul><\/li>\n\t<li>WebSphere Application Server\n\t<ul><li>8.5<\/li>\n\t\t<li>9.0<\/li>\n\t<\/ul><\/li>\n\t<li>WebSphere Application Server\u00a0- Liberty\n\t<ul><li>Continuous delivery<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-789","alert_type":396,"serial_number":"AV26-789","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8085,"title":"WebPros security advisory (AV26-790)","uuid":"65509b1f-b962-4e01-a17a-7a86cb4f0654","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T14:04:20Z","date_created":"2026-08-10T13:53:47Z","summary":null,"body":["<article data-history-node-id=\"8085\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-790\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-790<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>As of August\u00a07, 2026, WebPros is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Plesk Obsidian\n\t<ul><li>Prior to 18.0.80.1 and 18.0.79.5<\/li>\n\t<\/ul><\/li>\n<\/ul><ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/42431868205079-CVE-2026-64636-Vulnerability-in-Plesk-blind-SQL-injection\">CVE-2026-64636 Vulnerability in Plesk: blind SQL injection<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-790","alert_type":396,"serial_number":"AV26-790","subject":"other","moderation_state":"published","external_url":null},{"nid":8086,"title":"HashiCorp security advisory (AV26-791)","uuid":"9f3799e3-c9c6-4dc1-862b-0705ee538372","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T14:09:21Z","date_created":"2026-08-10T13:53:47Z","summary":null,"body":["<article data-history-node-id=\"8086\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-791\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-791<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>As of August\u00a07, 2026, HashiCorp is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Consul Community Edition\n\t<ul><li>Prior to 2.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>Consul Enterprise\n\t<ul><li>Prior to 2.0.3<\/li>\n\t\t<li>Prior to 1.22.11<\/li>\n\t\t<li>Prior to 1.21.17<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-25-multiple-vulnerabilities-impacting-hashicorp-consul\/77629\">HCSEC-2026-25\u00a0- Multiple vulnerabilities impacting HashiCorp Consul\u00a0- Security\u00a0- HashiCorp Discuss<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/c\/security\/52\">Security\u00a0- HashiCorp Discuss<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-791","alert_type":396,"serial_number":"AV26-791","subject":"other","moderation_state":"published","external_url":null},{"nid":8087,"title":"WordPress security advisory (AV26-792)","uuid":"57d6134a-2715-4ff2-a3f6-c1c74b92bf4a","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T14:14:38Z","date_created":"2026-08-10T13:53:48Z","summary":null,"body":["<article data-history-node-id=\"8087\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-av26-792\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-792<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>As of August\u00a07, 2026, WordPress is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>WordPress\n\t<ul><li>prior to 7.0.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-64638 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/wordpress.org\/news\/2026\/08\/wordpress-7-0-3-release\/\">WordPress 7.0.3 release\u00a0\u2013 WordPress News<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-av26-792","alert_type":396,"serial_number":"AV26-792","subject":"other","moderation_state":"published","external_url":null},{"nid":8088,"title":"Roundcube security advisory (AV26-793)","uuid":"43c3adca-4c3f-43a2-a988-fbbbd97e12d1","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T15:15:08Z","date_created":"2026-08-10T15:10:33Z","summary":null,"body":["<article data-history-node-id=\"8088\" about=\"\/en\/alerts-advisories\/roundcube-security-advisory-av26-793\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-793<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>On August\u00a09, 2026, Roundcube is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Roundcube Webmail\n\t<ul><li>prior to 1.6.18<\/li>\n\t\t<li>prior to 1.7.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/roundcube.net\/news\/2026\/08\/09\/security-updates-1.6.18-and-1.7.3\">Security updates 1.6.18 and 1.7.3 released<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.6.18\">Roundcube Webmail 1.6.18<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/roundcube\/roundcubemail\/releases\/tag\/1.7.3\">Roundcube Webmail 1.7.3<\/a><\/li>\n\t<li><a href=\"https:\/\/roundcube.net\/\">Roundcube Open Source Webmail Software<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/roundcube-security-advisory-av26-793","alert_type":396,"serial_number":"AV26-793","subject":"other","moderation_state":"published","external_url":null},{"nid":8089,"title":"Cisco security advisory (AV26-794)","uuid":"4e5446c3-463a-47bf-b5b1-08e756e66f5c","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T16:02:17Z","date_created":"2026-08-10T15:59:10Z","summary":null,"body":["<article data-history-node-id=\"8089\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-794\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-794<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>As of August\u00a07, 2026, Cisco is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Secure Endpoint Connector for Linux<\/li>\n\t<li>Secure Endpoint Connector for Mac<\/li>\n\t<li>Secure Endpoint Connector for Windows<\/li>\n\t<li>Cisco Secure Endpoint Private Cloud\n\t<ul><li>Prior to 8.4.5.30483<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-clamav-WuuvVd26\">ClamAV Vulnerabilities Affecting Cisco Products: August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-794","alert_type":396,"serial_number":"AV26-794","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8090,"title":"Qualcomm security advisory (AV26-795)","uuid":"b8ed930c-6d14-4f1d-8cca-a233d9f03044","banner":null,"lang":"en","date_modified":"2026-08-10","date_modified_ts":"2026-08-10T18:06:03Z","date_created":"2026-08-10T18:04:09Z","summary":null,"body":["<article data-history-node-id=\"8090\" about=\"\/en\/alerts-advisories\/qualcomm-security-advisory-av26-795\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-795<br \/><strong>Date:<\/strong> August\u00a010, 2026<\/p>\n\n<p>As of August\u00a03, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.qualcomm.com\/securitybulletin\/august-2026-bulletin.html\">August 2026 Security Bulletin<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/qualcomm-security-advisory-av26-795","alert_type":396,"serial_number":"AV26-795","subject":"other","moderation_state":"published","external_url":null},{"nid":8092,"title":"Grafana security advisory (AV26-796)","uuid":"7cdc9f22-c1f4-4431-a1ef-7649caef535b","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T13:17:59Z","date_created":"2026-08-11T12:53:55Z","summary":null,"body":["<article data-history-node-id=\"8092\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av26-796\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-796<br \/><strong>Date:<\/strong> August 11, 2026<\/p>\n\n<p>As of August 11, 2026, Grafana is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>Grafana MCP Server\n\t<ul><li>Prior to or equal to 1.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>mcp-grafana\n\t<ul><li>Prior to or equal to 1.0.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/tags\/security\/\">Grafana: The open and composable observability platform | Grafana Labs<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-19516\">CVE-2026-19516 CVE Record<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av26-796","alert_type":396,"serial_number":"AV26-796","subject":"other","moderation_state":"published","external_url":null},{"nid":8094,"title":"SAP security advisory \u2013 August 2026 monthly rollup (AV26-798) \u2013 Update 1","uuid":"6c7d355a-3ce7-4baf-8770-db61a3aa9ca5","banner":null,"lang":"en","date_modified":"2026-08-17","date_modified_ts":"2026-08-17T15:57:16Z","date_created":"2026-08-11T13:21:33Z","summary":null,"body":["<article data-history-node-id=\"8094\" about=\"\/en\/alerts-advisories\/sap-security-advisory-august-2026-monthly-rollup-av26-798\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-798<br \/><strong>Date:<\/strong> August\u00a011, 2026<br \/><strong>Updated:<\/strong> August\u00a017, 2026<\/p>\n\n<p>As of August\u00a011, 2026, SAP is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>SAP Commerce Cloud (Data Hub Adapter)\n\t<ul><li>Versions COM_CLOUD 2211 and 2211-JDK21<\/li>\n\t<\/ul><\/li>\n\t<li>SAP Manufacturing Integration and Intelligence\n\t<ul><li>Versions XMII 15.4, 15.5, MII_ADMIN 15.4 and 15.5<\/li>\n\t<\/ul><\/li>\n\t<li>SAP NetWeaver and ABAP Platform\n\t<ul><li>Versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18 and 9.19<\/li>\n\t<\/ul><\/li>\n\t<li>SAP Manufacturing Integration and Intelligence\n\t<ul><li>Version MII 15.4, 15.5<\/li>\n\t<\/ul><\/li>\n\t<li>SAP Change and Transport System Attach Tool (ctsattach)\n\t<ul><li>Version CTS_UPLOAD_CLT 1<\/li>\n\t<\/ul><\/li>\n\t<li>SAP ABAP Developer Tools\n\t<ul><li>Versions AP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816 and SAP_BASIS 918, SAP_BASIS 920<\/li>\n\t<\/ul><\/li>\n\t<li>SAP Commerce Cloud\n\t<ul><li>Versions OM_CLOUD 2211, 2211-JDK21 and DHUB_CLOUD 2211, 2211-JDK21<\/li>\n\t<\/ul><\/li>\n\t<li>SAP BusinessObjects Business Intelligence Platform (Central Management Server)\n\t<ul><li>Versions AP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920, ENTERPRISE 430, 2025 and 2027<\/li>\n\t<\/ul><\/li>\n\t<li>SAP Manufacturing Integration and Intelligence\n\t<ul><li>Versions MII 15.4 and 15.5<\/li>\n\t<\/ul><\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-58231 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/august-2026.html?isu_page=1\">SAP Security Patch Day\u00a0- August 2026<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><p>\u00a0<\/p>\n<\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-august-2026-monthly-rollup-av26-798","alert_type":396,"serial_number":"AV26-798","subject":"other","moderation_state":"published","external_url":null},{"nid":8093,"title":"HashiCorp security advisory (AV26-797)","uuid":"b9fa35e4-d345-472c-9567-ec8cce0dd994","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T13:52:59Z","date_created":"2026-08-11T13:21:37Z","summary":null,"body":["<article data-history-node-id=\"8093\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-797\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-797<br \/><strong>Date:<\/strong> August 11, 2026<\/p>\n\n<p>As of August 10, 2026, HashiCorp is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Vault\n\t<ul><li>Prior to 2.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>Vault Enterprise\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-27-vault-enterprise-vulnerable-to-cross-namespace-entity-deletion\/77634\">HCSEC-2026-27\u00a0- Vault Enterprise vulnerable to cross-namespace entity deletion\u00a0- Security\u00a0- HashiCorp Discuss<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/c\/security\/52\">Security\u00a0- HashiCorp Discuss<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-797","alert_type":396,"serial_number":"AV26-797","subject":"other","moderation_state":"published","external_url":null},{"nid":8095,"title":"AMD security advisory (AV26-800)","uuid":"8a5e5690-28c5-4b64-bc20-c43f94e57c54","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T15:42:33Z","date_created":"2026-08-11T15:37:21Z","summary":null,"body":["<article data-history-node-id=\"8095\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-800\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-800<br \/><strong>Date:<\/strong> August 11, 2026<\/p>\n\n<p>As of August 10, 2026, AMD is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>AMD EPYC Series Processors<\/li>\n\t<li>AMD EPYC Embedded Series Processors<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-3032.html\">Extracting VM Secrets through Power Side Channels on AMD SEV-ES and SEV-SNP<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD Product Security<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-800","alert_type":396,"serial_number":"AV26-800","subject":"other","moderation_state":"published","external_url":null},{"nid":8096,"title":"Commvault security advisory (AV26-799)","uuid":"ee095338-78b9-4f2f-b07a-124f45985144","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T15:06:02Z","date_created":"2026-08-11T15:51:03Z","summary":null,"body":["<article data-history-node-id=\"8096\" about=\"\/en\/alerts-advisories\/commvault-security-advisory-av26-799\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-799<br \/><strong>Date:<\/strong> August 11, 2026<\/p>\n\n<p>As of August 11, 2026, Commvault is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Commvault Cloud\n\t<ul><li>11.36.0 Prior to 11.36.114<\/li>\n\t\t<li>11.40.0 Prior to 11.40.63<\/li>\n\t\t<li>11.44.0 Prior to 11.44.11<\/li>\n\t\t<li>11.46.0 Prior to 11.46.10<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2026_07_8.html\">CV_2026_07_8<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2026_07_9.html\">CV_2026_07_9<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2026_07_5.html\">CV_2026_07_5<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/\">Commvault Cloud Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/commvault-security-advisory-av26-799","alert_type":396,"serial_number":"AV26-799","subject":"other","moderation_state":"published","external_url":null},{"nid":8097,"title":"Rapid7 security advisory (AV26-801)","uuid":"133941d9-c959-44eb-bf31-306e683563a6","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T17:33:13Z","date_created":"2026-08-11T17:25:11Z","summary":null,"body":["<article data-history-node-id=\"8097\" about=\"\/en\/alerts-advisories\/rapid7-security-advisory-av26-801\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-801<br \/><strong>Date:<\/strong> August 11, 2026<\/p>\n\n<p>As of August 11, 2026, Rapid7 is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Velociraptor\n\t<ul><li>Prior to 0.77.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.velociraptor.app\/announcements\/advisories\/cve-2026-18972\/\">CVE-2026-18972 Velociraptor authenticated identity-spoofing \u2026<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rapid7-security-advisory-av26-801","alert_type":396,"serial_number":"AV26-801","subject":"other","moderation_state":"published","external_url":null},{"nid":8098,"title":"[Control systems] Siemens security advisory (AV26-802)","uuid":"fb1294bd-84a2-4e71-9227-82d7936d78e7","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T18:03:23Z","date_created":"2026-08-11T17:44:03Z","summary":null,"body":["<article data-history-node-id=\"8098\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-802\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-802<br \/><strong>Date:<\/strong> August 11, 2026<\/p>\n\n<p>As of August 11, 2026, Siemens is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Desigo DXR2\n\t<ul><li>Prior to V01.21.233.16-7862<\/li>\n\t<\/ul><\/li>\n\t<li>Desigo PXC3\n\t<ul><li>Prior to V01.21.233.16-7862<\/li>\n\t<\/ul><\/li>\n\t<li>Desigo PXC4\n\t<ul><li>Prior to V02.21.194.36-2715<\/li>\n\t<\/ul><\/li>\n\t<li>Desigo PXC5.E003\n\t<ul><li>Prior to V02.21.194.36-2715<\/li>\n\t<\/ul><\/li>\n\t<li>Desigo PXC5.E24\n\t<ul><li>Prior to V02.21.194.36-2715<\/li>\n\t<\/ul><\/li>\n\t<li>Desigo PXC7\n\t<ul><li>Prior to V02.21.194.36-2715<\/li>\n\t<\/ul><\/li>\n\t<li>LOGO! Soft Comfort\n\t<ul><li>Prior to V9<\/li>\n\t<\/ul><\/li>\n\t<li>Parasolid V38.0\n\t<ul><li>Prior to V38.0.235<\/li>\n\t<\/ul><\/li>\n\t<li>Parasolid V38.1\n\t<ul><li>Prior to V38.1.230<\/li>\n\t<\/ul><\/li>\n\t<li>SIMATIC IoT2050 Advanced\n\t<ul><li>Prior to V4.3.4.1<\/li>\n\t<\/ul><\/li>\n\t<li>Siemens License Server (SLS)\n\t<ul><li>Prior to V5.1<\/li>\n\t\t<li>Prior to V5.3<\/li>\n\t<\/ul><\/li>\n\t<li>Simcenter Femap\n\t<ul><li>Prior to V2606.0001<\/li>\n\t<\/ul><\/li>\n\t<li>Simcenter Nastran\n\t<ul><li>Prior to V2606<\/li>\n\t<\/ul><\/li>\n\t<li>Solid Edge SE2025\n\t<ul><li>Prior to V225.0 Update 15<\/li>\n\t<\/ul><\/li>\n\t<li>Solid Edge SE2026\n\t<ul><li>Prior to V226.0 Update 7<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/en-us\/content\/cert-services\/\">CERT Services | Siemens<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-802","alert_type":398,"serial_number":"AV26-802","subject":"siemens","moderation_state":"published","external_url":null},{"nid":8099,"title":"Red Hat security advisory (AV26-803)","uuid":"e91e7d76-f8b2-4cd1-b200-f0cab719ef3e","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T19:22:24Z","date_created":"2026-08-11T18:10:57Z","summary":null,"body":["<article data-history-node-id=\"8099\" about=\"\/en\/alerts-advisories\/security-bulletin-red-hat-av26-803\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><!--CUT & PASTE the French version info -->\n<p><strong>Serial Number: <\/strong>AV26-803<br \/><strong>Date: <\/strong>August 11, 2026<\/p>\n\n<p>As of August 5, 2026, Red Hat is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Red Hat Advanced Cluster Management for Kubernetes 2<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2026-10090\">CVE-2026-10090\u00a0- Red Hat Customer Portal<\/a><\/li>\n\t<li><a href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2483292\">2483292\u00a0\u2013 (CVE-2026-10090) CVE-2026-10090 multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription<\/a><\/li>\n\t<li><a href=\"https:\/\/access.redhat.com\/security\/security-updates\/security-advisories\">Security Updates<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/security-bulletin-red-hat-av26-803","alert_type":396,"serial_number":"AV26-803","subject":"redhat","moderation_state":"published","external_url":null},{"nid":8100,"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 4","uuid":"66c068f8-fbfb-4e82-a460-da68b3b5a8d5","banner":null,"lang":"en","date_modified":"2026-09-25","date_modified_ts":"2026-09-25T15:55:30Z","date_created":"2026-08-11T19:35:05Z","summary":null,"body":["<article data-history-node-id=\"8100\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2026-monthly-rollup-av26-804\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-804<br \/><strong>Date:<\/strong> August\u00a011, 2026<br \/><strong>Updated:<\/strong>September\u00a025, 2026<\/p>\n\n<p>As of August\u00a011, 2026, Microsoft is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>.NET 10.0 installed on Linux<\/li>\n\t<li>.NET 10.0 installed on Mac OS<\/li>\n\t<li>.NET 10.0 installed on Windows<\/li>\n\t<li>.NET 8.0 installed on Linux<\/li>\n\t<li>.NET 8.0 installed on Mac OS<\/li>\n\t<li>.NET 8.0 installed on Windows<\/li>\n\t<li>.NET 9.0 installed on Linux<\/li>\n\t<li>.NET 9.0 installed on Mac OS<\/li>\n\t<li>.NET 9.0 installed on Windows<\/li>\n\t<li>App Installer<\/li>\n\t<li>Application Insights Profiler<\/li>\n\t<li>Azure Active Directory<\/li>\n\t<li>Azure Confidential Ledger<\/li>\n\t<li>Azure CycleCloud<\/li>\n\t<li>Azure Kubernetes Service<\/li>\n\t<li>Azure Logic Apps<\/li>\n\t<li>Azure Monitor Agent Linux Extension<\/li>\n\t<li>Azure SQL Database<\/li>\n\t<li>Azure SQL Managed Instance<\/li>\n\t<li>Azure SRE Agent<\/li>\n\t<li>Azure Service Bus<\/li>\n\t<li>Azure Storage Explorer<\/li>\n\t<li>Microsoft .NET Framework 3.5<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.6.2\/4.7\/4.7.1\/4.7.2<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.7.2<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.8<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.8.1<\/li>\n\t<li>Microsoft .NET Framework 4.6.2\/4.7\/4.7.1\/4.7.2<\/li>\n\t<li>Microsoft .NET Framework 4.8<\/li>\n\t<li>Microsoft .NET Framework 4.8.1<\/li>\n\t<li>Microsoft 365 Admin Center<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Access 2016<\/li>\n\t<li>Microsoft Defender for Endpoint for Mac<\/li>\n\t<li>Microsoft Dynamics 365 (on-premises)<\/li>\n\t<li>Microsoft Dynamics 365 Business Central 2024<\/li>\n\t<li>Microsoft Dynamics 365 Business Central 2026<\/li>\n\t<li>Microsoft Dynamics 365 Business Central Release Wave 1 2025<\/li>\n\t<li>Microsoft Dynamics 365 Business Central Release Wave 2 2025<\/li>\n\t<li>Microsoft Entra Connect<\/li>\n\t<li>Microsoft Entra ID<\/li>\n\t<li>Microsoft Entra Provisioning Service<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Server 2016<\/li>\n\t<li>Microsoft Exchange Server 2019<\/li>\n\t<li>Microsoft Exchange Server Subscription Edition RTM<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office 365 for Mac<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac 2021<\/li>\n\t<li>Microsoft Office LTSC for Mac 2024<\/li>\n\t<li>Microsoft Outlook 2016<\/li>\n\t<li>Microsoft Planetary Computer Pro (GeoCatalog)<\/li>\n\t<li>Microsoft Power Apps<\/li>\n\t<li>Microsoft PowerPoint 2016<\/li>\n\t<li>Microsoft Purview eDiscovery<\/li>\n\t<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n\t<li>Microsoft SharePoint Online<\/li>\n\t<li>Microsoft SharePoint Server 2019<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Teams<\/li>\n\t<li>Microsoft Teams for Android<\/li>\n\t<li>Microsoft Teams for iOS<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Microsoft Visual Studio 2026<\/li>\n\t<li>Microsoft Visual Studio Code CoPilot Chat Extension<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>OneDrive for MacOS<\/li>\n\t<li>Power BI Report Server<\/li>\n\t<li>PowerShell 7.4<\/li>\n\t<li>PowerShell 7.5<\/li>\n\t<li>PowerShell 7.6<\/li>\n\t<li>Python extension for Visual Studio Code<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows App Client for Windows Desktop<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2012 R2<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations, and apply the necessary updates.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On August\u00a018, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-33824 and CVE-2026-55040 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-63520 related to Microsoft SharePoint Server is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 3<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-65660 related to Microsoft SharePoint Server is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 4<\/h2>\n\n<p>On September\u00a025, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65660 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Aug\">August 2026 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824\">CISA KEV: CVE-2026-33824<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040\">CISA KEV: CVE-2026-55040<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660 \">CISA KEV: CVE-2026-65660<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","alert_type":396,"serial_number":"AV26-804","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":8101,"title":"Ivanti security advisory (AV26-805)","uuid":"a3b2472a-92bb-4f69-960f-d6af6b903bd9","banner":null,"lang":"en","date_modified":"2026-08-11","date_modified_ts":"2026-08-11T20:09:48Z","date_created":"2026-08-11T20:01:59Z","summary":null,"body":["<article data-history-node-id=\"8101\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-805\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-805<br \/><strong>Date:<\/strong> August 11, 2026<\/p>\n\n<p>As of August 11, 2026, Ivanti is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Endpoint Manager\n\t<ul><li>Prior to or equal to 2024 SU6<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Endpoint-Manager-EPM-August-2026?language=en_US\">Ivanti Innovators Hub<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-805","alert_type":396,"serial_number":"AV26-805","subject":"other","moderation_state":"published","external_url":null},{"nid":8102,"title":"Google security advisory (AV26-806)","uuid":"3adc1fb5-a13c-4b52-9c9e-fe67d5473f66","banner":null,"lang":"en","date_modified":"2026-08-12","date_modified_ts":"2026-08-12T12:33:55Z","date_created":"2026-08-12T12:28:58Z","summary":null,"body":["<article data-history-node-id=\"8102\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-806\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-806<br \/><strong>Date: <\/strong>August\u00a012, 2026<\/p>\n\n<p>As of August\u00a011, 2026, Google is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>versions prior to 151.0.7922.138<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/08\/stable-channel-update-for-desktop_01815628406.html \">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-806","alert_type":396,"serial_number":"AV26-806","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8103,"title":"Cisco security advisory (AV26-807)","uuid":"5eea4c35-5920-475a-a00d-1599e5d4867a","banner":null,"lang":"en","date_modified":"2026-08-12","date_modified_ts":"2026-08-12T12:43:46Z","date_created":"2026-08-12T12:38:52Z","summary":null,"body":["<article data-history-node-id=\"8103\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-807\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-807<br \/><strong>Date: <\/strong>August\u00a012, 2026<\/p>\n\n<p>As of August\u00a011, 2026, Cisco is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>Cisco Secure Firewall Adaptive Security Appliance (ASA) Software\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Secure Firewall Threat Defense (FTD) Software\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<p class=\"mrgn-bttm-md\">On August 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20349 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-vpn-dos-dzv4mQFF\">Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20349\">CISA KEV: CVE-2026-20349<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-807","alert_type":396,"serial_number":"AV26-807","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8104,"title":"Adobe security advisory (AV26-808) \u2013 Update 2","uuid":"9c1d48c3-44f0-4264-acf6-5d303889f109","banner":null,"lang":"en","date_modified":"2026-09-24","date_modified_ts":"2026-09-24T20:04:25Z","date_created":"2026-08-12T14:14:25Z","summary":null,"body":["<article data-history-node-id=\"8104\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-808\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-808<br \/><strong>Date: <\/strong>August\u00a012, 2026<br \/><strong>Updated: <\/strong> September 24, 2026<\/p>\n\n<p>As of August\u00a011, 2026, Adobe is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Campaign Classic\n\t<ul><li>Prior to or equal to ACC v7: 7.4.3 build 9399<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Commerce\n\t<ul><li>Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Commerce B2B\n\t<ul><li>Prior to or equal to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul<\/li>\n\t<\/ul><\/li>\n\t<li>ColdFusion 2023\n\t<ul><li>Prior to or equal to 2023.0.22<\/li>\n\t<\/ul><\/li>\n\t<li>ColdFusion 2025\n\t<ul><li>Prior to or equal to 2025.0.11<\/li>\n\t<\/ul><\/li>\n\t<li>Content Credentials Command-Line Tool\n\t<ul><li>Prior to or equal to c2patool-v0.27.5<\/li>\n\t<\/ul><\/li>\n\t<li>Content Credentials JS SDK\n\t<ul><li>Prior to or equal to @contentauth\/c2pa-web@0.12.0<\/li>\n\t<\/ul><\/li>\n\t<li>Content Credentials Rust SDK\n\t<ul><li>Prior to or equal to c2pa-v0.90.5<\/li>\n\t<\/ul><\/li>\n\t<li>Lightroom Classic\n\t<ul><li>Prior to or equal to 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1<\/li>\n\t<\/ul><\/li>\n\t<li>Magento Open Source\n\t<ul><li>Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul<\/li>\n\t<\/ul><\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-71362 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On September 24, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-71362 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-92.html\">Security\u202fupdate\u202favailable\u202ffor\u202fAdobe Commerce\u202f|\u202fAPSB26-92<\/a><\/li>\n\t<li><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Product Security Incident Response Team<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-71362\">CISA KEV: CVE-2026-71362<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-808","alert_type":396,"serial_number":"AV26-808","subject":"adobe","moderation_state":"published","external_url":null},{"nid":8105,"title":"SonicWall security advisory (AV26-809)","uuid":"3ce1a73a-597d-4aa3-8395-3e17a2787c6b","banner":null,"lang":"en","date_modified":"2026-08-12","date_modified_ts":"2026-08-12T15:05:28Z","date_created":"2026-08-12T14:57:36Z","summary":null,"body":["<article data-history-node-id=\"8105\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-809\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-809<br \/><strong>Date: <\/strong>August\u00a012, 2026<\/p>\n\n<p>As of August\u00a011, 2026, SonicWall is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Email Security\n\t<ul><li>10.0.35.8405 and earlier versions<\/li>\n\t<\/ul><\/li>\n\t<li>GMS\n\t<ul><li>9.5.1 and earlier versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0011\">Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0012\">Security Advisory (1)<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/\">Security Advisory (2)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-809","alert_type":396,"serial_number":"AV26-809","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":8106,"title":"MongoDB security advisory (AV26-810)","uuid":"a58aeaed-8851-4234-893b-8b4faaf6137c","banner":null,"lang":"en","date_modified":"2026-08-12","date_modified_ts":"2026-08-12T15:41:48Z","date_created":"2026-08-12T15:34:19Z","summary":null,"body":["<article data-history-node-id=\"8106\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory-av26-810\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-810<br \/><strong>Date: <\/strong>August\u00a012, 2026<\/p>\n\n<p>As of August\u00a011, 2026, MongoDB is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>MongoDB Driver\n\t<ul><li>Prior to 5.9.2<\/li>\n\t<\/ul><\/li>\n\t<li>MongoDB Server\n\t<ul><li>Prior to 7.0.40<\/li>\n\t\t<li>Prior to 8.0.29<\/li>\n\t\t<li>Prior to 8.2.13<\/li>\n\t\t<li>Prior to 8.3.8<\/li>\n\t\t<li>Prior to 9.0.0-rc2<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/jira.mongodb.org\/browse\/SERVER-130264\">[SERVER-130264] Intra-cluster SASL mechanism allow list missing in egress connection setup, enabling PLAIN downgrade and cleartext keyfile disclosure\u00a0- MongoDB Jira <\/a><\/li>\n\t<li><a href=\"https:\/\/jira.mongodb.org\/browse\/JAVA-6266\">[JAVA-6266] Mask proxy password in ProxySettings toString\u00a0- MongoDB Jira <\/a><\/li>\n\t<li><a href=\"https:\/\/www.mongodb.com\/resources\/products\/alerts\">Alerts | MongoDB<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory-av26-810","alert_type":396,"serial_number":"AV26-810","subject":"other","moderation_state":"published","external_url":null},{"nid":8107,"title":"[Control Systems] Phoenix Contact security advisory (AV26-811)","uuid":"712d9e0d-c8dd-4673-942e-f0f76f24d252","banner":null,"lang":"en","date_modified":"2026-08-12","date_modified_ts":"2026-08-12T16:09:00Z","date_created":"2026-08-12T15:55:30Z","summary":null,"body":["<article data-history-node-id=\"8107\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-811\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-811<br \/><strong>Date: <\/strong>August\u00a012, 2026<\/p>\n\n<p>As of August\u00a012, 2026, Phoenix Contact is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>AXC F 1152\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>AXC F 1252\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>AXC F 2000 EA\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>AXC F 2152\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>AXC F 3152\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>BPC 9102S\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>BPC 9202S\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>Catan C1\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>EPC 1502\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>EPC 1522\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>RFC 4072R\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>RFC 4072S\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>VL3 UPC 2440 EDGE\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>VPLCNEXT CONTROL 1000\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>VPLCNEXT CONTROL 2000\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>VPLCNEXT CONTROL 3000\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>VPLCNEXT CONTROL 500\n\t<ul><li>Prior to 2026.0.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.certvde.com\/en\/advisories\/VDE-2025-056\/ \">Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware<\/a><\/li>\n\t<li><a href=\"https:\/\/www.certvde.com\/en\/advisories\/ \">Phoenix Contact Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-811","alert_type":398,"serial_number":"AV26-811","subject":"other","moderation_state":"published","external_url":null},{"nid":8108,"title":"Fortinet security advisory (AV26-812)","uuid":"9acf4299-84c4-4c7b-ba16-33f14e73a1b9","banner":null,"lang":"en","date_modified":"2026-08-12","date_modified_ts":"2026-08-12T17:38:07Z","date_created":"2026-08-12T17:28:09Z","summary":null,"body":["<article data-history-node-id=\"8108\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-812\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-812<br \/><strong>Date: <\/strong>August\u00a012, 2026<\/p>\n\n<p>As of August\u00a012, 2026, Fortinet is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>FortiClientWindows\n\t<ul><li>Prior to or equal to 7.2.11<\/li>\n\t\t<li>Prior to or equal to 7.4.3<\/li>\n\t<\/ul><\/li>\n\t<li>FortiManager\n\t<ul><li>Prior to or equal to 7.61<\/li>\n\t\t<li>Prior to or equal to 7.4.5<\/li>\n\t\t<li>Prior to or equal to 7.2.9<\/li>\n\t<\/ul><\/li>\n\t<li>FortiManager Cloud\n\t<ul><li>Prior to or equal to 7.61<\/li>\n\t\t<li>Prior to or equal to 7.4.5<\/li>\n\t\t<li>Prior to or equal to 7.2.9<\/li>\n\t<\/ul><\/li>\n  \t<li>FortiWeb\n\t<ul><li>Prior to or equal to 8.0.2<\/li>\n\t\t<li>Prior to or equal to 7.6.6<\/li>\n\t\t<li>Prior to or equal to 7.4.11<\/li>\n\t\t<li>Prior to or equal to 7.2.12<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-156\">PSIRT | FortiGuard Labs<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-160\">PSIRT | FortiGuard Labs<\/a><\/li>\n  <li><a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-26-158\">PSIRT | FortiGuard Labs<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-812","alert_type":396,"serial_number":"AV26-812","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":8110,"title":"AL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349","uuid":"ce51c9e0-0fef-4ef4-bac2-a829c21e6b30","banner":null,"lang":"en","date_modified":"2026-08-13","date_modified_ts":"2026-08-13T13:14:19Z","date_created":"2026-08-13T12:46:03Z","summary":null,"body":["<article data-history-node-id=\"8110\" about=\"\/en\/alerts-advisories\/al26-018-vulnerability-affecting-cisco-asa-secure-firewall-threat-defense-software-remote-access-ssl-vpn-cve-2026-20349\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-018<br \/><strong>Date:<\/strong> August\u00a013, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> of a high-severity vulnerability affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>. Cisco disclosed this vulnerability on August 11, 2026, and has confirmed active exploitation in the wild.<\/p>\n\n<p>In response to the Cisco security advisory released on August 11, 2026, the Cyber Centre issued AV26-807<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup> on August 12, 2026.<\/p>\n\n<p>Tracked as CVE-2026-20349<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>, this vulnerability is an Improper Clearing of Heap Memory Before Release ('Heap Inspection') (CWE-244)<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> vulnerability that may allow a remote attacker to cause a denial-of-service (DoS) condition. The vulnerability is caused by insufficient error checking when processing HTTP requests. An unauthenticated remote attacker could exploit the issue by sending a specially crafted HTTP request to an affected SSL VPN service. Successful exploitation could cause the firewall to reload unexpectedly, resulting in a denial of service (DoS) condition.<\/p>\n\n<p>Cisco Secure Firewall ASA and Secure Firewall Threat Defense SSL VPN Services that are accessible from the internet, particularly those with the vulnerable SSL VPN-Related services enabled, are at risk of being impacted.<\/p>\n\n<p>This vulnerability affects Cisco devices if they are running affected ASA or FTD software releases and have one or more of the following features enabled, which expose SSL listen sockets:<\/p>\n\n<ul><li>IKEv2 Remote Access VPN with client services<\/li>\n\t<li>SSL VPN (WebVPN)<\/li>\n\t<li>Zero Trust Network Access (ZTNA) (FTD only)<\/li>\n<\/ul><p>Cisco has confirmed that Cisco Secure Firewall Management Center (FMC) Software is not affected by this vulnerability.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations:<\/p>\n\n<ul><li>Identify internet-accessible Cisco Secure Firewall ASA and FTD systems that provide Remote Access SSL VPN services.<\/li>\n\t<li>Determine whether WebVPN, IKEv2 Remote Access VPN (with client services), or Zero Trust Network Access features are enabled.<\/li>\n\t<li>Review firewall and VPN logs for evidence of unexpected reloads, service interruptions, or suspicious HTTP requests targeting SSL VPN services.<\/li>\n\t<li>Review whether SSL VPN, Remote Access VPN, or ZTNA services are enabled.<\/li>\n\t<li>Prioritize remediation of internet-facing systems.<\/li>\n<\/ul><p>Upgrade affected Cisco ASA instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Cisco ASA<\/td>\n\t\t\t<td>9.16.x<\/td>\n\t\t\t<td>89.16.4.50<\/td>\n\t\t<\/tr><tr><td>Cisco ASA<\/td>\n\t\t\t<td>9.18.x<\/td>\n\t\t\t<td>89.18.4.50<\/td>\n\t\t<\/tr><tr><td>Cisco ASA<\/td>\n\t\t\t<td>9.20.x<\/td>\n\t\t\t<td>9.20.4.235<\/td>\n\t\t<\/tr><tr><td>Cisco ASA<\/td>\n\t\t\t<td>9.22.x<\/td>\n\t\t\t<td>9.22.3.191<\/td>\n\t\t<\/tr><tr><td>Cisco ASA<\/td>\n\t\t\t<td>9.23.x<\/td>\n\t\t\t<td>9.23.1.211<\/td>\n\t\t<\/tr><tr><td>Cisco ASA<\/td>\n\t\t\t<td>9.24.x<\/td>\n\t\t\t<td>9.24.1.221<\/td>\n\t\t<\/tr><tr><td>Cisco Secure Firewall FTD Software<\/td>\n\t\t\t<td>7.0.x<\/td>\n\t\t\t<td>7.0.9.1 Hotfix<\/td>\n\t\t<\/tr><tr><td>Cisco Secure Firewall FTD Software<\/td>\n\t\t\t<td>7.2.x<\/td>\n\t\t\t<td>7.2.11.1 Hotfix<\/td>\n\t\t<\/tr><tr><td>Cisco Secure Firewall FTD Software<\/td>\n\t\t\t<td>7.4.x<\/td>\n\t\t\t<td>7.4.7.1 Hotfix<\/td>\n\t\t<\/tr><tr><td>Cisco Secure Firewall FTD Software<\/td>\n\t\t\t<td>7.6.x<\/td>\n\t\t\t<td>7.6.4.1 Hotfix<\/td>\n\t\t<\/tr><tr><td>Cisco Secure Firewall FTD Software<\/td>\n\t\t\t<td>7.7.x<\/td>\n\t\t\t<td>7.7.11.1 Hotfix<\/td>\n\t\t<\/tr><tr><td>Cisco Secure Firewall FTD Software<\/td>\n\t\t\t<td>10.0.x<\/td>\n\t\t\t<td>10.0.0.1 Hotfix<\/td>\n\t\t<\/tr><\/tbody><\/table><\/div>\n\n<p>The Cyber Centre recommends organizations:<\/p>\n\n<ul><li>Review the Cisco advisory and evaluate exposure using the Cisco Software Checker.<\/li>\n\t<li>Ensure perimeter devices and VPN gateways are included in vulnerability management and patch management programs.<\/li>\n\t<li>Monitor network infrastructure for service disruptions and indicators of attempted exploitation.<\/li>\n\t<li>Consolidate, monitor, and defend Internet gateways.<\/li>\n\t<li>Patch operating systems, applications, and network infrastructure in a timely manner.<\/li>\n\t<li>Harden exposed services and minimize unnecessary internet-facing management interfaces.<\/li>\n\t<li>Follow Cisco\u2019s remediation guidance and CISA KEV recommendations.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following topics<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/thehackernews.com\/2026\/08\/cisco-asa-and-ftd-flaw-exploited-in.html\">Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-vpn-dos-dzv4mQFF\">Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/cisco-security-advisory-av26-807\">Cisco security advisory (AV26-807)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-20349\">cve.org\u00a0- CVE-2026-20349<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/244.html\">CWE-244: Improper Clearing of Heap Memory Before Release ('Heap Inspection')<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/securely-deploying-ai-network-edge-itsp80101\">Securely deploying AI at the network edge (ITSP.80.101)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-018-vulnerability-affecting-cisco-asa-secure-firewall-threat-defense-software-remote-access-ssl-vpn-cve-2026-20349","alert_type":397,"serial_number":"AL26-018","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8111,"title":"AMD security advisory (AV26-813)","uuid":"c8317458-e894-4963-bd23-757146ad50e0","banner":null,"lang":"en","date_modified":"2026-08-13","date_modified_ts":"2026-08-13T13:38:50Z","date_created":"2026-08-13T13:27:20Z","summary":null,"body":["<article data-history-node-id=\"8111\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-813\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-813<br \/><strong>Date:<\/strong> August 13, 2026<\/p>\n\n<p>\u00a0<\/p>\n\n<p>As of August 11, 2026, AMD is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>AMD Power Design Manager (PDM) Software Installer for Windows\n\t<ul><li><strong>all<\/strong> except 2026.1<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Power Design Manager (PDM) Software Un-Installer\n\t<ul><li><strong>all<\/strong> except 2026.1<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen Master\n\t<ul><li><strong>all<\/strong> except 3.0.0.4199<\/li>\n\t\t<li><strong>all<\/strong> except 3.1.1.5502<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen Master (AMD Ryzen 3000 Series Processors)\n\t<ul><li><strong>all<\/strong> except 2.14.3.5040<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen Master Monitoring SDK\n\t<ul><li><strong>all<\/strong> except 3.1.1.5478<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen Master SDK\n\t<ul><li><strong>all<\/strong> except 3.0.1.4732<\/li>\n\t<\/ul><\/li>\n\t<li>Vitis Libraries - Security Module\n\t<ul><li><strong>all<\/strong> except 2026.1<\/li>\n\t<\/ul><\/li>\n\t<li>Vitis Embedded Single File Download (SFD) for Windows\n\t<ul><li><strong>all<\/strong> except 2026.1<\/li>\n\t<\/ul><\/li>\n\t<li>Vitis Unified Installer for FPGAs &amp; Adaptive SoCs in Windows\n\t<ul><li><strong>all<\/strong> except 2026.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/AMD-SB-8015.html\">Vitis Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/AMD-SB-8016.html\">AMD Power Design Manager (PDM) Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/AMD-SB-9020.html\">AMD Ryzen Master Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-813","alert_type":396,"serial_number":"AV26-813","subject":"other","moderation_state":"published","external_url":null},{"nid":8112,"title":"GitLab security advisory (AV26-814)","uuid":"0c8db04a-f973-496f-8b50-a91e1ecf5701","banner":null,"lang":"en","date_modified":"2026-08-13","date_modified_ts":"2026-08-13T13:54:04Z","date_created":"2026-08-13T13:42:25Z","summary":null,"body":["<article data-history-node-id=\"8112\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-814\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-814<br \/><strong>Date:<\/strong> August 13, 2026<\/p>\n\n<p>As of August 12, 2026, GitLab is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>GitLab\n\t<ul><li>Prior to 19.0.6<\/li>\n\t\t<li>Prior to 19.1.4<\/li>\n\t\t<li>Prior to 19.2.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-2-2-released\/\">GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6 | GitLab Docs<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-814","alert_type":396,"serial_number":"AV26-814","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":8113,"title":"WebPros security advisory (AV26-815)","uuid":"e960f5ef-4fe7-4edf-9990-e9765cea9ce3","banner":null,"lang":"en","date_modified":"2026-08-13","date_modified_ts":"2026-08-13T15:17:54Z","date_created":"2026-08-13T15:14:40Z","summary":null,"body":["<article data-history-node-id=\"8113\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-815\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-815<br \/><strong>Date:<\/strong> August 13, 2026<\/p>\n\n<p>As of August 12, 2026, WebPros is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Plesk (Windows\/Linux)\n\t<ul><li>Prior to 18.0.79.6<\/li>\n\t\t<li>Prior to 18.0.80.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/42521305418903-Vulnerability-CVE-2026-64639-Privilege-Escalation-via-Database-Cloning-in-Plesk\">Vulnerability CVE-2026-64639: Privilege Escalation via Database Cloning in Plesk<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-815","alert_type":396,"serial_number":"AV26-815","subject":"other","moderation_state":"published","external_url":null},{"nid":8114,"title":"Zimbra security advisory (AV26-816) \u2013 Update 1","uuid":"50af9b9e-e1fd-418a-b410-534d3de02f8d","banner":null,"lang":"en","date_modified":"2026-08-21","date_modified_ts":"2026-08-21T19:11:47Z","date_created":"2026-08-14T13:05:51Z","summary":null,"body":["<article data-history-node-id=\"8114\" about=\"\/en\/alerts-advisories\/zimbra-security-advisory-av26-816\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-816<br \/><strong>Date: <\/strong>August 14, 2026<br \/><strong>Updated:<\/strong> August 21, 2026<\/p>\n\n<p>As of August 13, 2026, Zimbra is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Collaboration\u00a0- Prior to 10.1.20<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<h2 class=\"h3 mrgn-tp-lg\">Update 1<\/h2>\n\n<p>On August 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul class=\"list-unstyled mrgn-tp-lg\"><li><a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Security_Advisories\">Zimbra Security Advisories\u00a0- Zimbra: Tech Center<\/a><\/li>\n\t<li><a href=\"https:\/\/wiki.zimbra.com\/wiki\/Zimbra_Responsible_Disclosure_Policy\">Zimbra Responsible Disclosure Policy\u00a0- Zimbra: Tech Center<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.zimbra.com\/\">Zimbra: Blog\u00a0- All Things Zimbra<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570\">CISA KEV: CVE-2026-73570<\/a> \u2003<\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zimbra-security-advisory-av26-816","alert_type":396,"serial_number":"AV26-816","subject":"other","moderation_state":"published","external_url":null},{"nid":8115,"title":"HashiCorp security advisory (AV26-817)","uuid":"ef14df24-573a-400f-99bf-1aaa74058dac","banner":null,"lang":"en","date_modified":"2026-08-14","date_modified_ts":"2026-08-14T15:54:46Z","date_created":"2026-08-14T15:51:18Z","summary":null,"body":["<article data-history-node-id=\"8115\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-817\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-817<br \/><strong>Date: <\/strong>August 14, 2026<\/p>\n\n<p>As of August 13, 2026, HashiCorp is affected by a vulnerability in the following product<\/p>\n\n<ul><li>Vault Secrets Operator\u00a0- Prior to 1.5.0<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-28-vault-secrets-operator-vulnerable-to-arbitrary-file-read-via-approle-secretidpath\/77645\">HCSEC-2026-28\u00a0- Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/c\/security\/52\">Security\u00a0- HashiCorp Discuss<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-817","alert_type":396,"serial_number":"AV26-817","subject":"other","moderation_state":"published","external_url":null},{"nid":8116,"title":"FreePBX security advisory (AV26-818)","uuid":"986f7903-50c7-46fd-941c-e8f04d852427","banner":null,"lang":"en","date_modified":"2026-08-14","date_modified_ts":"2026-08-14T16:06:16Z","date_created":"2026-08-14T15:55:29Z","summary":null,"body":["<article data-history-node-id=\"8116\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-818\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-818<br \/><strong>Date: <\/strong>August 14, 2026<\/p>\n\n<p>As of August 13, 2026, FreePBX is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>backup\n\t<ul><li>After or equal to 17.0.5.34, Prior to 17.0.11<\/li>\n\t<\/ul><\/li>\n\t<li>framework\n\t<ul><li>After or equal to 17.0.1, Prior to 17.0.30<\/li>\n\t\t<li>Prior to 16.0.47<\/li>\n\t<\/ul><\/li>\n\t<li>missedcall\n\t<ul><li>After or equal to 17.0.1, Prior to 17.0.4<\/li>\n\t\t<li>Prior to 16.0.11<\/li>\n\t<\/ul><\/li>\n\t<li>music\n\t<ul><li>Prior to 17.0.7<\/li>\n\t<\/ul><\/li>\n\t<li>tts\n\t<ul><li>After or equal to 17.0.1, Prior to 17.0.5.4<\/li>\n\t\t<li>Prior to 16.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>ucp\n\t<ul><li>Prior to 17.0.9<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/\">FreePBX Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-818","alert_type":396,"serial_number":"AV26-818","subject":"other","moderation_state":"published","external_url":null},{"nid":8117,"title":"IBM security advisory (AV26-819)","uuid":"9e951ad3-d0f5-454f-a7d2-14925322fda8","banner":null,"lang":"en","date_modified":"2026-08-17","date_modified_ts":"2026-08-17T12:49:08Z","date_created":"2026-08-17T12:33:32Z","summary":null,"body":["<article data-history-node-id=\"8117\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-819\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-819<br \/><strong>Date: <\/strong>August\u00a017, 2026<\/p>\n\n<p>As of August\u00a014, 2026, IBM is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>IBM App Connect Operator\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM App Connect Enterprise Certified Containers Operands\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Total Storage Service Console (TSSC) \/ TS4500 IMC\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Tivoli Network Manager IP Edition\n\t<ul><li>Prior to or equal to 4.2.0.24 IF1<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Tivoli Monitoring\n\t<ul><li>Prior to or equal to 6.3.0.7 Service Pack 23<\/li>\n\t<\/ul><\/li>\n\t<li>PowerVC\n\t<ul><li>Prior to or equal to 2.3.1, 2.3.2 and 2.3.3<\/li>\n\t<\/ul><\/li>\n\t<li>Total Storage Service Console (TSSC) \/ TS4500 IMC\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Storage Scale\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Netezza Appliance\n\t<ul><li>Prior to or equal to 1.0.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>Tooling Community Edition\n\t<ul><li>Prior to or equal to 1.5.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Documentation Offline\n\t<ul><li>Prior to or equal to 1.4.1<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Industry Solutions Workbench\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Rational Developer for i (RDi)\n\t<ul><li>Prior to or equal to 9.9<\/li>\n\t<\/ul><\/li>\n\t<li>Langflow OSS\n\t<ul><li>Prior to or equal to 1.10.0<\/li>\n\t<\/ul><\/li>\n\t<li>Network Threat Analytics App\n\t<ul><li>Prior to or equal to 2.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM AIX\n\t<ul><li>Prior to or equal to 7.2 and 7.3<\/li>\n\t<\/ul><\/li>\n\t<li>IBM PowerVM VIOS\n\t<ul><li>Prior to or equal to 4.1<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Server Firmware\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-819","alert_type":396,"serial_number":"AV26-819","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8118,"title":"Tenable, Inc. security advisory (AV26-820)","uuid":"dd0e7c44-ea7c-4e7a-9eaa-85113a555a60","banner":null,"lang":"en","date_modified":"2026-08-17","date_modified_ts":"2026-08-17T13:03:29Z","date_created":"2026-08-17T12:58:47Z","summary":null,"body":["<article data-history-node-id=\"8118\" about=\"\/en\/alerts-advisories\/tenable-inc-security-advisory-av26-820\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-820<br \/><strong>Date: <\/strong>August\u00a017, 2026<\/p>\n\n<p>As of August\u00a014, 2026, Tenable, Inc. is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Security Center\n\t<ul><li>Prior to 6.9.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-22\">[R1] Security Center Version 6.9.0 Fixes Multiple Vulnerabilities\u00a0- Security Advisory | Tenable\u00ae<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tenable-inc-security-advisory-av26-820","alert_type":396,"serial_number":"AV26-820","subject":"other","moderation_state":"published","external_url":null},{"nid":8119,"title":"Dell security advisory (AV26-821)","uuid":"9f07ee81-6f44-4736-bcad-6f88e82b5f03","banner":null,"lang":"en","date_modified":"2026-08-17","date_modified_ts":"2026-08-17T13:23:00Z","date_created":"2026-08-17T13:17:26Z","summary":null,"body":["<article data-history-node-id=\"8119\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-821\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-821<br \/><strong>Date: <\/strong>August\u00a017, 2026<\/p>\n\n<p>As of August\u00a014, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>PowerFlex appliance\n\t<ul><li>Prior to 51.391.02 and 51.384.02<\/li>\n\t<\/ul><\/li>\n\t<li>PowerFlex Rack\n\t<ul><li>Prior to 3.9.1.2 and 3.8.4.2<\/li>\n\t<\/ul><\/li>\n\t<li>PowerFlex Software\n\t<ul><li>Prior to 5.1.0.2 and 4.5.6<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Client Platform for Multiple AMD BIOS\n\t<ul><li>multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Client Platform BIOS for 2026.3 IPU\n\t<ul><li>multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Dell VPlex\n\t<ul><li>Prior to 6.2.2.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources | Dell Canada (en anglais seulement)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-821","alert_type":396,"serial_number":"AV26-821","subject":"dell","moderation_state":"published","external_url":null},{"nid":8120,"title":"Microsoft Edge security advisory (AV26-822)","uuid":"cb35f048-6362-4aec-9f7f-caec539467bb","banner":null,"lang":"en","date_modified":"2026-08-17","date_modified_ts":"2026-08-17T13:49:25Z","date_created":"2026-08-17T13:42:29Z","summary":null,"body":["<article data-history-node-id=\"8120\" about=\"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-822\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-822<br \/><strong>Date: <\/strong>August\u00a017, 2026<\/p>\n\n<p>As of August\u00a014, 2026, Microsoft is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Microsoft Edge (Chromium-based)\n\t<ul><li>Prior to 151.0.4129.86<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/learn.microsoft.com\/en-us\/DeployEdge\/microsoft-edge-relnotes-security#august-14-2026\">Microsoft Edge Stable Channel Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72970\">Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CVE-2026-72970 (en anglais seulement)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-edge-security-advisory-av26-822","alert_type":396,"serial_number":"AV26-822","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":8121,"title":"Apple security advisory (AV26-823) \u2013 Update 1","uuid":"bdb70a64-acb8-4935-91fb-01bb9a8b9afe","banner":null,"lang":"en","date_modified":"2026-08-18","date_modified_ts":"2026-08-18T18:26:40Z","date_created":"2026-08-17T15:10:48Z","summary":null,"body":["<article data-history-node-id=\"8121\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-823\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-823<br \/><strong>Date: <\/strong>August\u00a017, 2026<br \/><strong>Updated:<\/strong> August 18, 2026<\/p>\n\n<p>As of August\u00a06, 2026, Apple is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>macOS Tahoe\n\t<ul><li>Prior to 26.6.1<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Sequoia\n\t<ul><li>Prior to 15.7.9<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Sonoma\n\t<ul><li>Prior to 14.8.9<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-65400 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On August 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65400 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/148170\">About the security content of macOS Tahoe 26.6.1<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/148171\">About the security content of macOS Sequoia 15.7.9<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/148172\">About the security content of macOS Sonoma 14.8.9<\/a><\/li>\n\t<li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases\u00a0- Apple Support<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400\">CISA KEV: CVE-2026-65400<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-823","alert_type":396,"serial_number":"AV26-823","subject":"apple","moderation_state":"published","external_url":null},{"nid":8122,"title":"Progress security advisory (AV26-824)","uuid":"bf27aed6-154a-4158-906c-a9116544d23e","banner":null,"lang":"en","date_modified":"2026-08-17","date_modified_ts":"2026-08-17T18:01:58Z","date_created":"2026-08-17T17:49:00Z","summary":null,"body":["<article data-history-node-id=\"8122\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-824\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-824<br \/><strong>Date: <\/strong>August\u00a017, 2026<\/p>\n\n<p>As of August\u00a017, 2026, Progress is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>ShareFile Storage Zones Controller\n\t<ul><li>Prior to or equal to 5.12.5<\/li>\n\t\t<li>Prior to or equal to 6.0.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sharefile.com\/s\/article\/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information\">ShareFile Storage Zones Controller (SZC) Service Disruption Guidance, Login Issues, and Access Information<\/a><\/li>\n\t<li><a href=\"https:\/\/www.progress.com\/trust-center\">Progress Trust Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-824","alert_type":396,"serial_number":"AV26-824","subject":"other","moderation_state":"published","external_url":null},{"nid":8123,"title":"JetBrains security advisory (AV26-825)","uuid":"b24e6cbb-ca7f-4394-bc0d-1016f60ef96e","banner":null,"lang":"en","date_modified":"2026-08-18","date_modified_ts":"2026-08-18T13:04:57Z","date_created":"2026-08-18T13:00:55Z","summary":null,"body":["<article data-history-node-id=\"8123\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-825\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-825<br \/><strong>Date: <\/strong>August\u00a018, 2026<\/p>\n\n<p>As of August\u00a017, 2026, JetBrains is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>IntelliJ IDEA\n\t<ul><li>Prior to 2026.1.5<\/li>\n\t\t<li>Prior to 2026.2.1<\/li>\n\t<\/ul><\/li>\n\t<li>Ktor\n\t<ul><li>Prior to 3.4.1<\/li>\n\t<\/ul><\/li>\n\t<li>PyCharm\n\t<ul><li>Prior to 2026.2.1<\/li>\n\t<\/ul><\/li>\n\t<li>YouTrack\n\t<ul><li>Prior to 2025.3.156085<\/li>\n\t\t<li>Prior to 2026.1.13901<\/li>\n\t\t<li>Prior to 2026.1.13903<\/li>\n\t\t<li>Prior to 2026.1.13913<\/li>\n\t\t<li>Prior to 2026.1.13914<\/li>\n\t\t<li>Prior to 2026.2.17917<\/li>\n\t\t<li>Prior to 2026.2.17950<\/li>\n\t\t<li>Prior to 2026.2.18068<\/li>\n\t\t<li>Prior to 2026.2.18095<\/li>\n      \t<li>Prior to 2026.2.18112<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-825","alert_type":396,"serial_number":"AV26-825","subject":"other","moderation_state":"published","external_url":null},{"nid":8124,"title":"BeyondTrust security advisory (AV26-826)","uuid":"85d8b7f8-de76-40c5-b36a-3ffc072f85fc","banner":null,"lang":"en","date_modified":"2026-08-18","date_modified_ts":"2026-08-18T13:38:16Z","date_created":"2026-08-18T13:33:32Z","summary":null,"body":["<article data-history-node-id=\"8124\" about=\"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-826\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-826<br \/><strong>Date: <\/strong>August\u00a018, 2026<\/p>\n\n<p>As of August\u00a017, 2026, BeyondTrust is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Endpoint Privilege Management (Windows deployment)\n\t<ul><li>Prior to 26.1.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\/bt26-04\">BT26-04 | BeyondTrust <\/a><\/li>\n\t<li><a href=\"https:\/\/www.beyondtrust.com\/trust-center\/security-advisories\">BeyondTrust Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/beyondtrust-security-advisory-av26-826","alert_type":396,"serial_number":"AV26-826","subject":"other","moderation_state":"published","external_url":null},{"nid":8125,"title":"GitLab security advisory (AV26-827) \u2013 Update 1","uuid":"9253ef8a-4711-486a-bbc9-f351425c1490","banner":null,"lang":"en","date_modified":"2026-08-21","date_modified_ts":"2026-08-21T21:04:28Z","date_created":"2026-08-18T13:51:50Z","summary":null,"body":["<article data-history-node-id=\"8125\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-827\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-827<br \/><strong>Date: <\/strong>August\u00a018, 2026<br \/><strong>Updated:<\/strong> August 21, 2026<\/p>\n\n<p>As of August\u00a017, 2026, GitLab is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>GitLab\n\t<ul><li>Prior to 18.11.11<\/li>\n\t\t<li>Prior to 19.0.8<\/li>\n\t\t<li>Prior to 19.1.6<\/li>\n\t\t<li>Prior to 19.2.4<\/li>\n\t<\/ul><\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-19478 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-2-4-released\/\">GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11 | GitLab Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.gitlab.com\/releases\/\">GitLab release notes | GitLab Docs<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-827","alert_type":396,"serial_number":"AV26-827","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":8126,"title":"Mattermost security advisory (AV26-828)","uuid":"0bfea836-453c-4f8c-bb59-5039fb330b78","banner":null,"lang":"en","date_modified":"2026-08-18","date_modified_ts":"2026-08-18T14:14:17Z","date_created":"2026-08-18T14:10:51Z","summary":null,"body":["<article data-history-node-id=\"8126\" about=\"\/en\/alerts-advisories\/mattermost-security-advisory-av26-828\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-828<br \/><strong>Date: <\/strong>August\u00a018, 2026<\/p>\n\n<p>As of August\u00a017, 2026, Mattermost is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Mattermost\n\t<ul><li>Prior to or equal to 10.11.21<\/li>\n\t\t<li>Prior to or equal to 11.7.6<\/li>\n\t\t<li>Prior to or equal to 11.8.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-9816\">CVE-2026-9816 Detail<\/a><\/li>\n\t<li><a href=\"https:\/\/mattermost.com\/security-updates\/\">Mattermost Security Updates <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mattermost-security-advisory-av26-828","alert_type":396,"serial_number":"AV26-828","subject":"other","moderation_state":"published","external_url":null},{"nid":8127,"title":"Atlassian security advisory (AV26-829)","uuid":"89e6e431-f606-4dc2-852f-266bfd7fdcfe","banner":null,"lang":"en","date_modified":"2026-08-19","date_modified_ts":"2026-08-19T12:49:25Z","date_created":"2026-08-19T12:39:53Z","summary":null,"body":["<article data-history-node-id=\"8127\" about=\"\/en\/alerts-advisories\/atlassian-security-advisory-av26-829\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-829<br \/><strong>Date: <\/strong>August\u00a019, 2026<\/p>\n\n<p>As of August\u00a018, 2026, Atlassian is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Bamboo Data Center and Server\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Bitbucket Data Center and Server\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Confluence Data Center and Server\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Crowd Data Center and Server\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Fisheye\/Crucible\n\t<ul><li>all versions from 4.9.0 to 4.9.12<\/li>\n\t<\/ul><\/li>\n\t<li>Jira Data Center and Server\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Jira Service Management Data Center and Server\n\t<ul><li>multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-bulletin-august-18-2026-1821999768.html\">Security Bulletin\u00a0- August 18 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/confluence.atlassian.com\/security\/security-advisories-bulletins-1236937381.html\">Security Advisories &amp; Bulletins<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/atlassian-security-advisory-av26-829","alert_type":396,"serial_number":"AV26-829","subject":"atlassian","moderation_state":"published","external_url":null},{"nid":8128,"title":"NVIDIA security advisory (AV26-830)","uuid":"a06b8c11-f87d-428d-a28d-44fffd5bc4f7","banner":null,"lang":"en","date_modified":"2026-08-19","date_modified_ts":"2026-08-19T17:03:25Z","date_created":"2026-08-19T16:17:04Z","summary":null,"body":["<article data-history-node-id=\"8128\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-av26-830\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-830<br \/><strong>Date: <\/strong>August\u00a019, 2026<\/p>\n\n<p>As of August\u00a018, 2026, NVIDIA is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Triton Inference Server\n\t<ul><li>Versions prior to 0.0-26.05<\/li>\n\t<\/ul><\/li>\n\t<li>Cumulus Linux GA\/LTS\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>NVOS\n\t<ul><li>Versions prior to 25.0.2.4438 and 25.0.2.6077<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/NVIDIA\/product-security\/tree\/main\/2026\/5865\">product-security\/2026\/5865 at main \u00b7 NVIDIA\/product-security \u00b7 GitHub <\/a><\/li>\n\t<li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5865\">Security Bulletin: NVIDIA Triton Inference Server\u00a0- August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5817\">Security Bulletin: NVIDIA Cumulus Linux and NVOS\u00a0- August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.nvidia.com\/en-us\/security\/\">NVIDIA Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-av26-830","alert_type":396,"serial_number":"AV26-830","subject":"nvidia","moderation_state":"published","external_url":null},{"nid":8129,"title":"Oracle Corporation security advisory (AV26-831)","uuid":"314b577b-817e-4eb3-9399-aab168691163","banner":null,"lang":"en","date_modified":"2026-08-19","date_modified_ts":"2026-08-19T18:24:05Z","date_created":"2026-08-19T18:10:30Z","summary":null,"body":["<article data-history-node-id=\"8129\" about=\"\/en\/alerts-advisories\/oracle-corporation-security-advisory-av26-831\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-831<br \/><strong>Date: <\/strong>August 19, 2026<\/p>\n\n<p>As of August 18, 2026, Oracle Corporation is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Oracle Database Server<\/li>\n\t<li>Oracle Autonomous Health Framework<\/li>\n\t<li>Oracle Essbase<\/li>\n\t<li>Oracle Application Testing Suite<\/li>\n\t<li>Oracle Commerce<\/li>\n\t<li>Oracle Communications<\/li>\n\t<li>Oracle Construction and Engineering<\/li>\n\t<li>Oracle E\u2011Business Suite<\/li>\n\t<li>Oracle Enterprise Manager<\/li>\n\t<li>Oracle Financial Services Applications<\/li>\n\t<li>Oracle Food and Beverage Applications<\/li>\n\t<li>Oracle Fusion Middleware<\/li>\n\t<li>Oracle Analytics<\/li>\n\t<li>Oracle Hospitality Applications<\/li>\n\t<li>Oracle Hyperion<\/li>\n\t<li>Oracle Java SE<\/li>\n\t<li>Oracle JD Edwards<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle MySQL<\/li>\n\t<li>Oracle Retail Applications<\/li>\n\t<li>Oracle Siebel CRM<\/li>\n\t<li>Oracle Supply Chain<\/li>\n\t<li>Oracle Virtualization<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cspuaug2026.html\">Oracle Critical Security Patch Update Advisory\u00a0- August 2026<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-corporation-security-advisory-av26-831","alert_type":396,"serial_number":"AV26-831","subject":"oracle","moderation_state":"published","external_url":null},{"nid":8130,"title":"MLflow security advisory (AV26-832)","uuid":"65ac050d-8771-4950-a5ac-440fd7e9b1ae","banner":null,"lang":"en","date_modified":"2026-08-19","date_modified_ts":"2026-08-19T18:28:55Z","date_created":"2026-08-19T18:23:46Z","summary":null,"body":["<article data-history-node-id=\"8130\" about=\"\/en\/alerts-advisories\/mlflow-security-advisory-av26-832\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-832<br \/><strong>Date: <\/strong>August 19, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">As of August 17, 2026, MLflow is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>MLflow\n\t<ul><li>Prior to 3.15.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/mlflow\/mlflow\/releases\/tag\/v3.15.0\">Release v3.15.0 \u00b7 mlflow\/mlflow \u00b7 GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/mlflow\/mlflow\/security\/advisories\/GHSA-7gwp-5pfp-969j\">Unauthenticated full-read SSRF in MLflow webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) \u00b7 Advisory \u00b7 mlflow\/mlflow \u00b7 GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-64849\">CISA KEV: CVE-2026-64849<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mlflow-security-advisory-av26-832","alert_type":396,"serial_number":"AV26-832","subject":"other","moderation_state":"published","external_url":null},{"nid":8131,"title":"Citrix security advisory (AV26-833) - Update 1","uuid":"578d4f94-b9d9-4896-b040-60a01c4f18fd","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T20:10:50Z","date_created":"2026-08-19T18:35:48Z","summary":null,"body":["<article data-history-node-id=\"8131\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-833\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-833<br \/><strong>Date: <\/strong>August 19, 2026<br \/><strong>Updated:<\/strong> September 9, 2026<\/p>\n\n<p class=\"mrgn-bttm-md\">As of August 19, 2026, Citrix is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler\n\t<ul><li>Version 13.1 prior to 13.1-63.21<\/li>\n\t\t<li>Version 14.1 prior to 14.1-73.32<\/li>\n\t<\/ul><\/li>\n\t<li>NetScaler ADC FIPS\n\t<ul><li>Prior to 14.1-73.32 FIPS<\/li>\n\t<\/ul><\/li>\n\t<li>NetScaler ADC FIPS and NDcPP\n\t<ul><li>Prior to 13.1-37.277<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696939\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\">Citrix Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490\">CISA KEV: CVE-2026-19490<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av26-833","alert_type":396,"serial_number":"AV26-833","subject":"citrix","moderation_state":"published","external_url":null},{"nid":8132,"title":"Cisco security advisory (AV26-834)","uuid":"bd75136b-8451-4155-b134-da5c454e78ed","banner":null,"lang":"en","date_modified":"2026-08-20","date_modified_ts":"2026-08-20T13:22:00Z","date_created":"2026-08-20T13:08:38Z","summary":null,"body":["<article data-history-node-id=\"8132\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-834\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-834<br \/><strong>Date: <\/strong>August\u00a020, 2026<\/p>\n\n<p>As of August\u00a019, 2026, Cisco is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>BroadWorks Application Delivery Platform\n\t<ul><li>Prior to RI.2026.07<\/li>\n\t<\/ul><\/li>\n\t<li>BroadWorks Application Server\n\t<ul><li>Prior to RI.2026.07<\/li>\n\t<\/ul><\/li>\n\t<li>BroadWorks Profile Server\n\t<ul><li>Prior to RI.2026.07<\/li>\n\t<\/ul><\/li>\n\t<li>BroadWorks Xtended Services Platform\n\t<ul><li>Prior to RI.2026.07<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Crosswork Planning\n\t<ul><li>Prior to 7.2.1-SP<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Crosswork Data Gateway\n\t<ul><li>Prior to 7.2.1-SP<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Crosswork Network Controller\n\t<ul><li>Prior to 7.2.1-SP<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Secure Workload\n\t<ul><li>Version 3.10 prior to 3.10.9.1<\/li>\n\t\t<li>Version 4.0 prior to 4.0.4.16<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-csw1-shSvndWP\">Cisco Secure Workload Software Security Hardening Release: August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-crosswork-UzDTU9Vh\">Cisco Crosswork Security Hardening Release: August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-bworks-xxe-uwUd7CEt\">Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-834","alert_type":396,"serial_number":"AV26-834","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8133,"title":"TrueConf security advisory (AV26-835)","uuid":"3dcabe9a-65ae-4de7-8652-d5c0593a8f98","banner":null,"lang":"en","date_modified":"2026-08-20","date_modified_ts":"2026-08-20T19:35:16Z","date_created":"2026-08-20T19:28:18Z","summary":null,"body":["<article data-history-node-id=\"8133\" about=\"\/en\/alerts-advisories\/trueconf-security-advisory-av26-835\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-835<br \/><strong>Date: <\/strong>August\u00a020, 2026<\/p>\n\n<p>As of August\u00a019, 2026, TrueConf is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>TrueConf Server\n\t<ul><li>5.3.x versions prior to 5.3.9<\/li>\n\t\t<li>5.4.x versions prior to 5.4.9<\/li>\n\t\t<li>5.5.x versions prior to 5.5.5<\/li>\n\t<\/ul><\/li>\n<\/ul><p>On August 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-72529 and CVE-2026-72530 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/trueconf.com\/blog\/news\/security-fixes-updates-and-advisories\">TrueConf Security Vulnerabilities, Fixes and Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529    \">CISA KEV: CVE-2026-72529<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72530  \">CISA KEV: CVE-2026-72530<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/trueconf-security-advisory-av26-835","alert_type":396,"serial_number":"AV26-835","subject":"other","moderation_state":"published","external_url":null},{"nid":8134,"title":"n8n security advisory (AV26-836)","uuid":"0b7251e2-8fb6-49c8-9e73-855d08f19cda","banner":null,"lang":"en","date_modified":"2026-08-20","date_modified_ts":"2026-08-20T19:42:21Z","date_created":"2026-08-20T19:39:01Z","summary":null,"body":["<article data-history-node-id=\"8134\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-836\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-836<br \/><strong>Date: <\/strong>August\u00a020, 2026<\/p>\n\n<p>As of August\u00a020, 2026, n8n is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>n8n\n\t<ul><li>Prior to 1.123.69<\/li>\n\t\t<li>Prior to 2.33.4<\/li>\n\t\t<li>Prior to 2.34.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-6h4x-896x-fw5m\">RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\/advisories\/GHSA-r4j2-j3wm-q689\">Snowflake Node Arbitrary File Read and Write via Client-Side Commands<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security \">n8n Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-836","alert_type":396,"serial_number":"AV26-836","subject":"other","moderation_state":"published","external_url":null},{"nid":8135,"title":"[Control Systems] Johnson Controls security advisory (AV26-837)","uuid":"fbf1ea87-ad24-4386-b122-f413b8f54903","banner":null,"lang":"en","date_modified":"2026-08-20","date_modified_ts":"2026-08-20T19:53:15Z","date_created":"2026-08-20T19:44:10Z","summary":null,"body":["<article data-history-node-id=\"8135\" about=\"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av26-837\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-837<br \/><strong>Date: <\/strong>August 19, 2026<\/p>\n\n<p>As of August 13, 2026, Johnson Controls is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Airwall\n\t<ul><li>Prior to 4.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>Metasys 12\n\t<ul><li>all versions<\/li>\n\t<\/ul><\/li>\n\t<li>Metasys 13\n\t<ul><li>all versions<\/li>\n\t<\/ul><\/li>\n\t<li>Metasys 14\n\t<ul><li>all versions prior to v14.1.5<\/li>\n\t<\/ul><\/li>\n\t<li>Metasys 15\n\t<ul><li>all versions prior to v15.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>TL280\n\t<ul><li>Prior to v5.62<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.johnsoncontrols.com\/trust-center\/cybersecurity\/security-advisories\">Johnson Controls\u00a0- Product Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-johnson-controls-security-advisory-av26-837","alert_type":398,"serial_number":"AV26-837","subject":"juniper","moderation_state":"published","external_url":null},{"nid":8136,"title":"Splunk security advisory (AV26-838)","uuid":"0190eb5c-7643-4459-91f9-a99a95697535","banner":null,"lang":"en","date_modified":"2026-08-21","date_modified_ts":"2026-08-21T13:08:58Z","date_created":"2026-08-21T12:59:49Z","summary":null,"body":["<article data-history-node-id=\"8136\" about=\"\/en\/alerts-advisories\/splunk-security-advisory-av26-838\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-838<br \/><strong>Date: <\/strong>August\u00a021, 2026<\/p>\n\n<p>As of August\u00a019, 2026, Splunk is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Talos Intelligence for Enterprise Security Cloud\n\t<ul><li>Prior to 1.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>Splunk Enterprise\n\t<ul><li>Prior to 10.0.9<\/li>\n\t\t<li>Prior to 10.2.6<\/li>\n\t\t<li>Prior to 10.4.1<\/li>\n\t\t<li>Prior to 10.4.2<\/li>\n\t\t<li>Prior to 9.4.14<\/li>\n\t<\/ul><\/li>\n\t<li>Splunk MCP Server app\n\t<ul><li>Prior to 1.2.1<\/li>\n\t<\/ul><\/li>\n\t<li>Splunk Universal Forwarder\n\t<ul><li>Prior to 10.4.2<\/li>\n\t\t<li>Prior to 10.2.6<\/li>\n\t\t<li>Prior to 10.0.9<\/li>\n\t\t<li>Prior to 9.4.14<\/li>\n\t<\/ul><\/li>\n\t<li>Splunk SOAR\n\t<ul><li>Prior to 8.6.0<\/li>\n\t<\/ul><\/li>\n\t<li>Splunk SOAR Connectors\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Splunk Enterprise Security\n\t<ul><li>Prior to 8.6.1<\/li>\n\t<\/ul><\/li>\n\t<li>Splunk Apps and Add-ons\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advisory.splunk.com\/advisories\">Splunk Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/splunk-security-advisory-av26-838","alert_type":396,"serial_number":"AV26-838","subject":"other","moderation_state":"published","external_url":null},{"nid":8137,"title":"Apple security advisory (AV26-839)","uuid":"5b553015-9804-4b41-9033-2765486a5c15","banner":null,"lang":"en","date_modified":"2026-08-21","date_modified_ts":"2026-08-21T13:32:22Z","date_created":"2026-08-21T13:24:02Z","summary":null,"body":["<article data-history-node-id=\"8137\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-839\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-839<br \/><strong>Date: <\/strong>August\u00a021, 2026<\/p>\n\n<p>As of August\u00a018, 2026, Apple is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Safari\n\t<ul><li>Prior to 26.6.1<\/li>\n\t<\/ul><\/li>\n\t<li>iOS and iPadOS\n\t<ul><li>Prior to 18.7.10<\/li>\n\t\t<li>Prior to 26.6.1<\/li>\n\t<\/ul><\/li>\n\t<li>MacOS Tahoe\n\t<ul><li>Prior to 26.6.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases\u00a0- Apple Support <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-839","alert_type":396,"serial_number":"AV26-839","subject":"apple","moderation_state":"published","external_url":null},{"nid":8138,"title":"Mozilla security advisory (AV26-840)","uuid":"4afed4f1-0c28-4277-af12-b674ee3b40c2","banner":null,"lang":"en","date_modified":"2026-08-21","date_modified_ts":"2026-08-21T14:52:28Z","date_created":"2026-08-21T14:45:52Z","summary":null,"body":["<article data-history-node-id=\"8138\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-840\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-840<br \/><strong>Date: <\/strong>August\u00a021, 2026<\/p>\n\n<p>As of August\u00a018, 2026, Mozilla is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox\n\t<ul><li>versions prior to 154<\/li>\n\t<\/ul><\/li>\n\t<li>Firefox ESR\n\t<ul><li>versions prior to 115.39<\/li>\n\t\t<li>versions prior to 140.14<\/li>\n\t\t<li>versions prior to 153.1<\/li>\n\t<\/ul><\/li>\n\t<li>Thunderbird\n\t<ul><li>versions prior to 140.14<\/li>\n\t\t<li>versions prior to 153.1<\/li>\n\t\t<li>versions prior to 154<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Foundation Security Advisories\u00a0\u2014 Mozilla <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-840","alert_type":396,"serial_number":"AV26-840","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":8139,"title":"[Control Systems] CISA ICS security advisory (AV26-841)","uuid":"a6bb31a8-633b-4fd3-b624-218b4e6fb9f4","banner":null,"lang":"en","date_modified":"2026-08-21","date_modified_ts":"2026-08-21T19:41:02Z","date_created":"2026-08-21T19:36:40Z","summary":null,"body":["<article data-history-node-id=\"8139\" about=\"\/en\/alerts-advisories\/control-systems-cisa-security-advisory-av26-841\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-841<br \/><strong>Date: <\/strong>August\u00a021, 2026<\/p>\n\n<p>As of August\u00a018, 2026, Malcolm is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Malcolm\n\t<ul><li>Prior to 26.06.1 (CVE-2026-55676)<\/li>\n\t\t<li>Prior to 26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)<\/li>\n\t\t<li>Prior to or equal to 26.07.1 (CVE-2026-19670, CVE-2026-19671)<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-230-01\">CISA Malcolm | CISA<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\">ICS Advisories | CISA<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-cisa-security-advisory-av26-841","alert_type":398,"serial_number":"AV26-841","subject":"other","moderation_state":"published","external_url":null},{"nid":8140,"title":"Spring security advisory (AV26-842)","uuid":"9a35033c-c412-4bf7-9f81-fa7ea77f013b","banner":null,"lang":"en","date_modified":"2026-08-21","date_modified_ts":"2026-08-21T20:52:54Z","date_created":"2026-08-21T20:41:17Z","summary":null,"body":["<article data-history-node-id=\"8140\" about=\"\/en\/alerts-advisories\/spring-security-advisory-av26-842\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-842<br \/><strong>Date: <\/strong>August 21, 2026<\/p>\n\n<p>As of August 20, 2026, Spring is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Spring AI\n\t<ul><li>Prior to or equal to 2.0.0<\/li>\n\t\t<li>Prior to or equal to 1.0.9<\/li>\n\t\t<li>Prior to or equal to 1.1.8<\/li>\n\t<\/ul><\/li>\n\t<li>Spring Security\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Spring Cloud Config\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Spring Data REST\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Spring Cloud Gateway\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Spring Cloud Commons\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Spring for GraphQL\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Spring Integration\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Spring Authorization Server\n\t<ul><li>Prior to or equal to 1.5.8<\/li>\n\t\t<li>Prior to or equal to 1.4.11<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/spring.io\/security\/\">Spring | Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/spring-security-advisory-av26-842","alert_type":396,"serial_number":"AV26-842","subject":"other","moderation_state":"published","external_url":null},{"nid":8141,"title":"Dell security advisory (AV26-843)","uuid":"1710e28e-50a6-479c-b71d-27e3d28260d3","banner":null,"lang":"en","date_modified":"2026-08-24","date_modified_ts":"2026-08-24T13:12:11Z","date_created":"2026-08-24T13:11:16Z","summary":null,"body":["<article data-history-node-id=\"8141\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-843\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-843<br \/><strong>Date: <\/strong>August\u00a024, 2026<\/p>\n\n<p>As of August\u00a017, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Alienware Command Center (AWCC)\n\t<ul><li>Prior to 6.14.20.0<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Command Update (DCU)\n\t<ul><li>Prior to 5.7.1<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Cyber Detect OVA\n\t<ul><li>Prior to 20.3.0<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Networking OS10\n\t<ul><li>Prior to 10.5.6.14<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Device Management Agent (DDMA)\n\t<ul><li>Prior to 26.06<\/li>\n\t<\/ul><\/li>\n\t<li>Dell ThinOS10\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Metro Node\n\t<ul><li>Prior to 4.6.0.4<\/li>\n\t<\/ul><\/li>\n\t<li>ObjectScale\n\t<ul><li>Prior to 4.3.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>OpenManage Enterprise\n\t<ul><li>Prior to 4.7.0<\/li>\n\t<\/ul><\/li>\n\t<li>PowerPath for Windows\n\t<ul><li>Prior to 8.0 SP2<\/li>\n\t<\/ul><\/li>\n\t<li>PowerScale OneFS\n\t<ul><li>Prior to 14.1<\/li>\n\t<\/ul><\/li>\n\t<li>Power Protect Cyber Recovery\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>PowerStoreT OS (multiple models)\n\t<ul><li>Prior to 5.0.0.2-2761110<\/li>\n\t<\/ul><\/li>\n\t<li>RecoverPoint for Virtual Machines\n\t<ul><li>Prior to 6.1<\/li>\n\t<\/ul><\/li>\n\t<li>UCC Edge\n\t<ul><li>Prior to 3.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>Watchdog Timer Driver\n\t<ul><li>Prior to 2.0.0.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources | Dell Canada<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-843","alert_type":396,"serial_number":"AV26-843","subject":"dell","moderation_state":"published","external_url":null},{"nid":8142,"title":"Google security advisory (AV26-844)","uuid":"b3c678b8-dc31-4050-98b1-f878c16e4edb","banner":null,"lang":"en","date_modified":"2026-08-24","date_modified_ts":"2026-08-24T19:03:22Z","date_created":"2026-08-24T19:00:50Z","summary":null,"body":["<article data-history-node-id=\"8142\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-844\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-844<br \/><strong>Date: <\/strong>August\u00a024, 2026<\/p>\n\n<p>As of August\u00a020, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>Prior to 151.0.7922.173<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/08\/stable-channel-update-for-desktop_0404570826.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-844","alert_type":396,"serial_number":"AV26-844","subject":"other","moderation_state":"published","external_url":null},{"nid":8143,"title":"Gitea security advisory (AV26-845)","uuid":"d38a20d1-d3f1-4a45-be78-829b6ca08034","banner":null,"lang":"en","date_modified":"2026-08-25","date_modified_ts":"2026-08-25T18:29:34Z","date_created":"2026-08-25T18:25:23Z","summary":null,"body":["<article data-history-node-id=\"8143\" about=\"\/en\/alerts-advisories\/gitea-security-advisory-av26-845\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-845<br \/><strong>Date: <\/strong>August\u00a025, 2026<\/p>\n\n<p>As of August\u00a014, 2026, Gitea is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Gitea\n\t<ul><li>Prior to 1.27.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>On August\u00a025, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/go-gitea\/gitea\/security\/advisories\/GHSA-rcr6-4jqh-j84m\">Remote Code Execution via diffpatch Git Hook Installation<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.gitea.com\/release-of-1.27.1\/\">Gitea 1.27.1 is released<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.gitea.com\/release-of-1.27.2\/\">Gitea 1.27.2 is released<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60004\">CISA KEV: CVE-2026-60004<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitea-security-advisory-av26-845","alert_type":396,"serial_number":"AV26-845","subject":"other","moderation_state":"published","external_url":null},{"nid":8144,"title":"OpenSSL security advisory (AV26-846)","uuid":"8cdabca7-1c3b-4f81-84c4-0fe610d084b6","banner":null,"lang":"en","date_modified":"2026-08-25","date_modified_ts":"2026-08-25T18:55:13Z","date_created":"2026-08-25T18:37:22Z","summary":null,"body":["<article data-history-node-id=\"8144\" about=\"\/en\/alerts-advisories\/openssl-security-advisory-av26-846\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-846<br \/><strong>Date: <\/strong>August 25, 2026<\/p>\n\n<p>As of August 25, 2026, OpenSSL is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenSSL\n\t<ul><li>Prior to 1.0.2zr<\/li>\n\t\t<li>Prior to 1.1.1zi<\/li>\n\t\t<li>Prior to 3.0.22<\/li>\n\t\t<li>Prior to 3.4.7<\/li>\n\t\t<li>Prior to 3.5.8<\/li>\n\t\t<li>Prior to 3.6.4<\/li>\n\t\t<li>Prior to 4.0.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/openssl-library.org\/news\/vulnerabilities\/\">Vulnerabilities | OpenSSL Library<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openssl-security-advisory-av26-846","alert_type":396,"serial_number":"AV26-846","subject":"other","moderation_state":"published","external_url":null},{"nid":8145,"title":"WatchGuard security advisory (AV26-847)","uuid":"59cd86a0-5dee-4939-802a-1f5d499b328f","banner":null,"lang":"en","date_modified":"2026-08-25","date_modified_ts":"2026-08-25T19:09:53Z","date_created":"2026-08-25T19:05:06Z","summary":null,"body":["<article data-history-node-id=\"8145\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-847\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-847<br \/><strong>Date: <\/strong>August\u00a025, 2026<\/p>\n\n<p>As of August\u00a019, 2026, WatchGuard is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>WatchGuard Agent\n\t<ul><li>Prior to 1.25.13.0000<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.watchguard.com\/support\/release-notes\/Cloud\/Content\/en-US\/Endpoint-Security\/Endpoint-Security-Prime-resolved_issues.html\">WatchGuard Endpoint Security Prime Enhancements and Resolved Issues<\/a><\/li>\n\t<li><a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisories\">Security Advisories | WatchGuard Technologies <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-847","alert_type":396,"serial_number":"AV26-847","subject":"other","moderation_state":"published","external_url":null},{"nid":8146,"title":"Adobe security advisory (AV26-848)","uuid":"74d347b0-d5a9-4ef3-8095-a0ff1e420e33","banner":null,"lang":"en","date_modified":"2026-08-26","date_modified_ts":"2026-08-26T13:56:44Z","date_created":"2026-08-26T13:52:27Z","summary":null,"body":["<article data-history-node-id=\"8146\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-848\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-848<br \/><strong>Date: <\/strong>August\u00a026, 2026<\/p>\n\n<p>As of August\u00a025, 2026, Adobe is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Adobe Campaign Classic\n\t<ul><li>Prior to or equal to ACC v7: 7.4.4 build 9400<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Substance 3D Designer\n\t<ul><li>Prior to or equal to 16.0.4<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Substance 3D Painter\n\t<ul><li>Prior to or equal to 12.1.2<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Substance 3D Sampler\n\t<ul><li>Prior to or equal to 6.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe XD\n\t<ul><li>Prior to or equal to 60<\/li>\n\t<\/ul><\/li>\n\t<li>C2PA Tool\n\t<ul><li>Prior to or equal to c2patool-v0.26.70<\/li>\n\t<\/ul><\/li>\n\t<li>Content Credentials Rust SDK\n\t<ul><li>Prior to or equal to c2pa-v0.89.0<\/li>\n\t<\/ul><\/li>\n\t<li>Illustrator 2025\n\t<ul><li>Prior to or equal to 29.8.9<\/li>\n\t<\/ul><\/li>\n\t<li>Illustrator 2026\n\t<ul><li>Prior to or equal to 30.6<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Product Security Incident Response Team<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-848","alert_type":396,"serial_number":"AV26-848","subject":"adobe","moderation_state":"published","external_url":null},{"nid":8147,"title":"NVIDIA security advisory (AV26-849)","uuid":"fbd3f43d-0e33-4e8b-be47-6d58904da5bc","banner":null,"lang":"en","date_modified":"2026-08-26","date_modified_ts":"2026-08-26T14:17:01Z","date_created":"2026-08-26T14:08:20Z","summary":null,"body":["<article data-history-node-id=\"8147\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-av26-849\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-849<br \/><strong>Date: <\/strong>August\u00a026, 2026<\/p>\n\n<p>As of August\u00a025, 2026, NVIDIA is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>NVIDIA <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">NemoClaw and OpenShell<\/span>\n\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>NVIDIA <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Unified Fabric Manager<\/span>\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>NVIDIA DGX <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Spark<\/span>\n\t<ul><li>Versions prior to 1.110.13<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5872\">Security Bulletin: NVIDIA NemoClaw and OpenShell\u00a0- August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5809\">Security Bulletin: NVIDIA Unified Fabric Manager\u00a0- August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5867\">Security Bulletin: NVIDIA DGX Spark\u00a0- August 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/NVIDIA\/product-security\/tree\/main\/2026\/5872\">product-security\/2026\/5872 at main \u00b7 NVIDIA\/product-security \u00b7 GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/www.nvidia.com\/en-us\/security\/\">NVIDIA Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-av26-849","alert_type":396,"serial_number":"AV26-849","subject":"nvidia","moderation_state":"published","external_url":null},{"nid":8148,"title":"Next.js security advisory (AV26-851)","uuid":"7e94e4d0-895e-4c81-933d-25124a35fa4f","banner":null,"lang":"en","date_modified":"2026-08-26","date_modified_ts":"2026-08-26T17:13:59Z","date_created":"2026-08-26T15:26:53Z","summary":null,"body":["<article data-history-node-id=\"8148\" about=\"\/en\/alerts-advisories\/nextjs-security-advisory-av26-851\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-851<br \/><strong>Date: <\/strong>August\u00a026, 2026<\/p>\n\n<p>As of August 25, 2026, Next.js is affected by critical vulnerabilities in the following product:<\/p>\n\n<ul><li>Next.js\n\t<ul><li>Version 15.5 prior to 15.5.24<\/li>\n\t\t<li>Version 16.3 prior to 16.3.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nextjs.org\/blog\/august-2026-security-release\">August 2026 Security Release<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nextjs-security-advisory-av26-851","alert_type":396,"serial_number":"AV26-851","subject":"other","moderation_state":"published","external_url":null},{"nid":8149,"title":"Ubiquiti security advisory (AV26-850)","uuid":"ad507230-4014-477f-aa3f-f9750faa9ffa","banner":null,"lang":"en","date_modified":"2026-08-26","date_modified_ts":"2026-08-26T17:11:47Z","date_created":"2026-08-26T17:07:25Z","summary":null,"body":["<article data-history-node-id=\"8149\" about=\"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-850\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-850<br \/><strong>Date: <\/strong>August\u00a026, 2026<\/p>\n\n<p>As of August\u00a026, 2026, Ubiquiti is affected by critical vulnerabilities in the following products:<\/p>\n\n<ul><li>UniFi OS Server\n\t<ul><li>Prior to or equal to 5.1.21<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Connect Application\n\t<ul><li>Prior to or equal to 3.24.20<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Network Application\n\t<ul><li>Prior to or equal to 10.4.57<\/li>\n\t<\/ul><\/li>\n\t<li>UID Enterprise Agent\n\t<ul><li>Prior to or equal to 1.61.8<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Access Application\n\t<ul><li>Prior to or equal to 4.3.3<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Protect Application\n\t<ul><li>Prior to or equal to 7.1.87<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Connect Display Cast Pro\n\t<ul><li>Prior to or equal to 1.0.108<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Enterprise Audio\/Video Bridge\n\t<ul><li>Prior to or equal to 1.0.10<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Talk Application\n\t<ul><li>Prior to or equal to 5.2.7<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Protect AI Key\n\t<ul><li>Prior to or equal to 2.1.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.ui.com\/releases\/Security-Advisory-Bulletin-067\/fc4a3488-7c43-4628-8bab-f715e96dbfc9\">Ubiquiti UniFi\u00a0- Security Advisory Bulletin 067<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-850","alert_type":396,"serial_number":"AV26-850","subject":"other","moderation_state":"published","external_url":null},{"nid":8150,"title":"TeamViewer security advisory (AV26-852)","uuid":"6d95a0b7-91d3-4c46-96f7-d41868983929","banner":null,"lang":"en","date_modified":"2026-08-26","date_modified_ts":"2026-08-26T17:33:37Z","date_created":"2026-08-26T17:23:49Z","summary":null,"body":["<article data-history-node-id=\"8150\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av26-852\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-852<br \/><strong>Date: <\/strong>August 26, 2026<\/p>\n\n<p>As of August 26, 2026, TeamViewer is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>TeamViewer Full Client\n\t<ul><li>Multiple versions and platforms<\/li>\n\t<\/ul><\/li>\n\t<li>TeamViewer Host\n\t<ul><li>Multiple versions and platforms<\/li>\n\t<\/ul><\/li>\n\t<li>TeamViewer Portable\n\t<ul><li>Prior to version 15.64.7<\/li>\n\t<\/ul><\/li>\n\t<li>TeamViewer QuickSupport\n\t<ul><li>Multiple versions and platforms<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/de\/resources\/trust-center\/security-bulletins\/tv-2026-1008\/\">TV-2026-1008<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en\/resources\/trust-center\/security-bulletins\/tv-2026-1009\/\">TV-2026-1009<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">Security bulletins | TeamViewer<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av26-852","alert_type":396,"serial_number":"AV26-852","subject":"other","moderation_state":"published","external_url":null},{"nid":8151,"title":"SonicWall security advisory (AV26-853)","uuid":"e60201e2-0d47-4f6a-b1fe-1387c79cdfb4","banner":null,"lang":"en","date_modified":"2026-08-27","date_modified_ts":"2026-08-27T12:44:22Z","date_created":"2026-08-27T12:32:13Z","summary":null,"body":["<article data-history-node-id=\"8151\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-853\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-853<br \/><strong>Date: <\/strong>August 26, 2026<\/p>\n\n<p>As of August 25, 2026, SonicWall is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>NetExtender Linux Client\n\t<ul><li>3.5 and earlier versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0013\">Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-list\">SonicWall Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-853","alert_type":396,"serial_number":"AV26-853","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":8152,"title":"WebPros security advisory (AV26-854)","uuid":"a397b1c8-be29-438a-96ba-9c838d52ca17","banner":null,"lang":"en","date_modified":"2026-08-27","date_modified_ts":"2026-08-27T12:57:33Z","date_created":"2026-08-27T12:50:11Z","summary":null,"body":["<article data-history-node-id=\"8152\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-854\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-854<br \/><strong>Date: <\/strong>August\u00a027, 2026<\/p>\n\n<p>As of August\u00a026, 2026, WebPros is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Plesk\n\t<ul><li>Prior to 18.0.79.8<\/li>\n\t\t<li>Prior to 18.0.80.4<\/li>\n\t<\/ul><\/li>\n\t<li>Plesk Migrator\n\t<ul><li>Prior to 2.36.0<\/li>\n\t<\/ul><\/li>\n\t<li>Plesk Site Import\n\t<ul><li>Prior to 1.12.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/42844242102679-Vulnerability-CVE-2026-65642-in-Plesk-s-database-management-interface\">Vulnerability CVE-2026-65642 in Plesk's database management interface<\/a><\/li>\n\t<li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/42871001389207-Vulnerability-CVE-2026-65647-in-Plesk-s-Site-Import-and-Migrator-extensions \">Vulnerability CVE-2026-65647 in Plesk's Site Import and Migrator extensions<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-854","alert_type":396,"serial_number":"AV26-854","subject":"other","moderation_state":"published","external_url":null},{"nid":8153,"title":"Veeam security advisory (AV26-855)","uuid":"1f9604f7-34f8-451d-a673-c28ba4d1f8c5","banner":null,"lang":"en","date_modified":"2026-08-27","date_modified_ts":"2026-08-27T14:03:14Z","date_created":"2026-08-27T13:56:15Z","summary":null,"body":["<article data-history-node-id=\"8153\" about=\"\/en\/alerts-advisories\/veeam-security-advisory-av26-855\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-855<br \/><strong>Date: <\/strong>August 27, 2026<\/p>\n\n<p>As of August 25, 2026, Veeam is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Backup and Replication\n\t<ul><li>Prior to 13.0.3 (build 13.0.3.63)<\/li>\n\t\t<li>Prior to 13.1 (build 13.1.0.411)<\/li>\n\t<\/ul><\/li>\n\t<li>ONE\n\t<ul><li>Prior to or equal to 13.0.2.6723<\/li>\n\t\t<li>Prior to or equal to 13.1.0.7034<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.veeam.com\/kb4902\">KB4902: Vulnerability Resolved in Veeam Backup &amp; Replication 13.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/kb4905\">KB4905: Vulnerability Resolved in Veeam ONE 13.1 Patch 0<\/a><\/li>\n\t<li><a href=\"https:\/\/www.veeam.com\/knowledge-base.html?type=security\">Veeam Support Knowledge Base<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/veeam-security-advisory-av26-855","alert_type":396,"serial_number":"AV26-855","subject":"other","moderation_state":"published","external_url":null},{"nid":8154,"title":"[Control Systems] National Instruments security advisory (AV26-856)","uuid":"d904be5c-5176-406a-9b57-d5ab0ef2d57f","banner":null,"lang":"en","date_modified":"2026-08-28","date_modified_ts":"2026-08-28T12:16:59Z","date_created":"2026-08-28T11:54:02Z","summary":null,"body":["<article data-history-node-id=\"8154\" about=\"\/en\/alerts-advisories\/control-systems-national-instruments-security-advisory-av26-856\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-856<br \/><strong>Date: <\/strong>August\u00a028, 2026<\/p>\n\n<p>As of August\u00a025, 2026, National Instruments is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>LabVIEW\n\t<ul><li>Prior to 23.0.0<\/li>\n\t\t<li>Prior to 23.3.10<\/li>\n\t\t<li>Prior to 24.3.7<\/li>\n\t\t<li>Prior to 25.3.5<\/li>\n\t\t<li>Prior to 26.3.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ni.com\/en\/support\/security\/available-critical-and-security-updates-for-ni-software\/2026\/memory-corruption-vulnerabilities-ni-labview.html\">Memory Corruption Vulnerabilities in NI LabVIEW\u00a0- NI<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ni.com\/en\/support\/security\/available-critical-and-security-updates-for-ni-software\/2026\/integer-conversion-vulnerability-resulting-in-an-out-of-bounds-read-in-ni-labview.html\">Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW\u00a0- NI<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ni.com\/en\/support\/security\/available-critical-and-security-updates-for-ni-software\/2026\/integer-overflow-vulnerability-resulting-in-an-out-of-bounds-write-in-ni-labview.html\">Integer Overflow Vulnerability Resulting in an Out of Bounds Write in NI LabVIEW - NI<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ni.com\/en\/support\/security\/available-critical-and-security-updates-for-ni-software\/2026.html\">Available Security Updates for NI Software: 2026\u00a0- NI<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-national-instruments-security-advisory-av26-856","alert_type":396,"serial_number":"AV26-856","subject":"other","moderation_state":"published","external_url":null},{"nid":8155,"title":"ServiceNow security advisory (AV26-857)","uuid":"56c8dad5-e70b-466d-a3db-f677c3f9d7e6","banner":null,"lang":"en","date_modified":"2026-08-28","date_modified_ts":"2026-08-28T13:43:29Z","date_created":"2026-08-28T13:28:47Z","summary":null,"body":["<article data-history-node-id=\"8155\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av26-857\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-857<br \/><strong>Date: <\/strong>August\u00a028, 2026<\/p>\n\n<p>As of August\u00a027, 2026, ServiceNow is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Xanadu\n\t<ul><li>Versions prior to Patch 11 Hot Fix 7a<\/li>\n\t<\/ul><\/li>\n\t<li>Yokohama\n\t<ul><li>Versions prior to Yokohama Patch 12 Hot Fix 3b<\/li>\n\t\t<li>Versions prior to Yokohama Patch 13 Hot Fix 4<\/li>\n\t<\/ul><\/li>\n\t<li>Zurich\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Australia\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB3152242\">August 2026 CVE Advisory Notification<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB1226057 \">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av26-857","alert_type":396,"serial_number":"AV26-857","subject":"other","moderation_state":"published","external_url":null},{"nid":8157,"title":"Redis security advisory (AV26-859)","uuid":"c36ceb13-add4-4741-ba8a-e3cf6f8a4c01","banner":null,"lang":"en","date_modified":"2026-08-28","date_modified_ts":"2026-08-28T14:34:41Z","date_created":"2026-08-28T13:36:29Z","summary":null,"body":["<article data-history-node-id=\"8157\" about=\"\/en\/alerts-advisories\/redis-security-advisory-av26-859\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-859<br \/><strong>Date: <\/strong>August 28, 2026<\/p>\n\n<p>As of August 27, 2026, <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Redis<\/span> is affected by a vulnerability in the following product:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Redis<\/span>\n\n\t<ul><li>8.0<\/li>\n\t\t<li>All except 8.10.1<\/li>\n\t\t<li>All except 8.2.9<\/li>\n\t\t<li>All except 8.4.6<\/li>\n\t\t<li>All except 8.6.6<\/li>\n\t\t<li>All except 8.8.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/redis\/redis\/commit\/6d088c335d5c3ec49a6c28486140b498e70b7834\">Fix use-after-free in tlsProcessPendingData() pending-list iteration<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/redis\/redis\/releases\">GitHub Releases<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/redis-security-advisory-av26-859","alert_type":396,"serial_number":"AV26-589","subject":"other","moderation_state":"published","external_url":null},{"nid":8156,"title":"PaperCut security advisory (AV26-858) \u2013 Update 2","uuid":"ff824b2c-bfdb-4579-b69e-28c51a26c1f2","banner":null,"lang":"en","date_modified":"2026-08-31","date_modified_ts":"2026-08-31T16:00:58Z","date_created":"2026-08-28T14:04:25Z","summary":null,"body":["<article data-history-node-id=\"8156\" about=\"\/en\/alerts-advisories\/papercut-security-advisory-av26-858\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-858<br \/><strong>Date: <\/strong>August\u00a028, 2026<br \/><strong>Updated:<\/strong> August\u00a031, 2026<\/p>\n\n<p>As of August\u00a027, 2026, PaperCut is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>PaperCut MF\n\t<ul><li>Prior to v24 Emergency Patch Release 2<\/li>\n\t\t<li>Prior to v25 Emergency Patch Release 2<\/li>\n\t\t<li>Prior to v26 Emergency Patch Release 2<\/li>\n\t<\/ul><\/li>\n\t<li>PaperCut NG\n\t<ul><li>Prior to v24 Emergency Patch Release 2<\/li>\n\t\t<li>Prior to v25 Emergency Patch Release 2<\/li>\n\t\t<li>Prior to v26 Emergency Patch Release 2<\/li>\n\t<\/ul><\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-81578 and CVE-2026-82078 are related to PaperCut MF and PaperCut NG are being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On August\u00a031, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.papercut.com\/kb\/Main\/security-bulletin-27-aug-2026-urgent-security-advisory\/\">URGENT Security Advisory: PaperCut NG\/MF Security Bulletin (27\u00a0Aug 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578\">CISA KEV: CVE-2026-81578<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078\">CISA KEV: CVE-2026-82078<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/papercut-security-advisory-av26-858","alert_type":396,"serial_number":"AV26-858","subject":"other","moderation_state":"published","external_url":null},{"nid":8158,"title":"Grafana security advisory (AV26-860)","uuid":"5f5416e6-128b-4c03-9073-a515e32b118b","banner":null,"lang":"en","date_modified":"2026-08-28","date_modified_ts":"2026-08-28T14:58:34Z","date_created":"2026-08-28T14:39:43Z","summary":null,"body":["<article data-history-node-id=\"8158\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av26-860\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-860<br \/><strong>Date: <\/strong>August 28, 2026<\/p>\n\n<p>As of August 27, 2026, Grafana is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Alloy\n\t<ul><li>Prior to or equal to 1.18.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/tags\/security\/\">Grafana: The open and composable observability platform | Grafana Labs<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-75889\">CVE-2026-19516 CVE Record<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av26-860","alert_type":396,"serial_number":"AV26-860","subject":"other","moderation_state":"published","external_url":null},{"nid":8159,"title":"WebPros security advisory (AV26-861)","uuid":"5128bbcc-7e78-4a24-8f50-77b79a302ba3","banner":null,"lang":"en","date_modified":"2026-08-28","date_modified_ts":"2026-08-28T15:10:37Z","date_created":"2026-08-28T14:39:43Z","summary":null,"body":["<article data-history-node-id=\"8159\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-861\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-861<br \/><strong>Date: <\/strong>August\u00a028, 2026<\/p>\n\n<p>As of August\u00a027, 2026, WebPros is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>cPanel &amp; WebHost Manager (WHM) software\n\t<ul><li>Prior to 11.110.0.141<\/li>\n\t\t<li>Prior to 11.134.0.53<\/li>\n\t\t<li>Prior to 11.136.0.37<\/li>\n\t\t<li>Prior to 11.138.0.2<\/li>\n\t\t<li>Prior to WP2: 11.138.1.7<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/42959571221527-Security-CVE-2026-65643-Vulnerability-in-cPanel-s-Domain-Parking-Functionality-August-27-2026\">Security: CVE-2026-65643 Vulnerability in cPanel\u2019s Domain Parking Functionality\u00a0- August 27, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360007088193-Security\">cPanel Security<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-861","alert_type":396,"serial_number":"AV26-861","subject":"other","moderation_state":"published","external_url":null},{"nid":8161,"title":"IBM security advisory (AV26-862)","uuid":"85176eb3-d8b4-4cc9-bb6c-1c1b13b44e88","banner":null,"lang":"en","date_modified":"2026-08-31","date_modified_ts":"2026-08-31T15:52:14Z","date_created":"2026-08-31T15:45:48Z","summary":null,"body":["<article data-history-node-id=\"8161\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-862\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-862<br \/><strong>Date:<\/strong> August\u00a031, 2026<\/p>\n\n<p>As of August\u00a028, 2026, IBM is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>SPSS Collaboration and Deployment Services\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM SPSS Analytic Server\n\t<ul><li>Multiple version<\/li>\n\t<\/ul><\/li>\n\t<li>IBM MQ Agent\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Monitor Component\n\t<ul><li>Prior to or equal to 9.2, 9.1 and 9.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Observability with Instana (Agent)\n\t<ul><li>Prior to or equal to 1.0.323<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Financial Transaction Manager (FTM) for RedHat OpenShift\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Engineering Test Management\n\t<ul><li>Prior to equal to 7.2, 7.1 and 7.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Control Center\n\t<ul><li>Prior to or equal to v6.3.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Concert Software\n\t<ul><li>Prior to or equal to 2.3.1<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Tivoli System Automation Application Manager 4.1\n\t<ul><li>Versions WebSphere Application Server 8.5 and 9.0<\/li>\n\t<\/ul><\/li>\n\t<li>SPSS Collaboration and Deployment Services\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Sovereign Core\n\t<ul><li>Prior to or equal to 1.1<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Maximo Application Suite\u00a0- Cluster Performance Insights\n\t<ul><li>Prior to or equal to 9.2<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Transformation Advisor\n\t<ul><li>Prior to or equal to 5.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Application Modernization Accelerator\n\t<ul><li>Prior to or equal to 5.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM webMethods Integration (on prem)\n\t<ul><li>Prior to or equal to 10.15,11.1 and 12.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-862","alert_type":396,"serial_number":"AV26-862","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8162,"title":"Dell security advisory (AV26-863)","uuid":"ae0a8a72-3ce0-44b2-9be9-4e06b8c92c1c","banner":null,"lang":"en","date_modified":"2026-08-31","date_modified_ts":"2026-08-31T15:55:51Z","date_created":"2026-08-31T15:45:48Z","summary":null,"body":["<article data-history-node-id=\"8162\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-863\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-863<br \/><strong>Date:<\/strong> August 31, 2026<\/p>\n\n<p>As of August 28, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell PowerEdge Server for Intel Processor Firmware\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Dell AppSync\n\t<ul><li>Prior to or equal to 4.6.0.4 and 4.6.1.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000502468\/dsa-2026-356-security-update-for-dell-poweredge-server-for-intel-processor-firmware-vulnerability\">DSA-2026-356: Security Update for Dell PowerEdge Server for Intel\u00ae Processor Firmware Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000502484\/dsa-2026-165-security-update-for-dell-appsync-vulnerabilities\">DSA-2026-165: Security Update for Dell AppSync Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources | Dell Canada<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-863","alert_type":396,"serial_number":"AV26-863","subject":"dell","moderation_state":"published","external_url":null},{"nid":8163,"title":"[Control Systems] Siemens security advisory (AV26-864)","uuid":"441a4538-8363-435e-951b-1ebaa0c82680","banner":null,"lang":"en","date_modified":"2026-08-31","date_modified_ts":"2026-08-31T15:59:15Z","date_created":"2026-08-31T15:45:48Z","summary":null,"body":["<article data-history-node-id=\"8163\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-864\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-864<br \/><strong>Date:<\/strong> August\u00a031, 2026<\/p>\n\n<p>As of August\u00a027, 2026, Siemens is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>Element maps-ng V47\n\t<ul><li>Prior to V47.12.3<\/li>\n\t<\/ul><\/li>\n\t<li>Element maps-ng V48\n\t<ul><li>Prior to V48.11.3<\/li>\n\t<\/ul><\/li>\n\t<li>Element maps-ng V49\n\t<ul><li>Prior to V49.16.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-682041.html\">SSA-682041<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/en-us\/content\/cert-services\/\">CERT Services\u00a0| Siemens<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-864","alert_type":398,"serial_number":"AV26-864","subject":"siemens","moderation_state":"published","external_url":null},{"nid":8164,"title":"WatchGuard security advisory (AV26-865)","uuid":"e9ef345c-d155-4ee6-ae46-34aea205d15c","banner":null,"lang":"en","date_modified":"2026-08-31","date_modified_ts":"2026-08-31T19:00:31Z","date_created":"2026-08-31T18:58:01Z","summary":null,"body":["<article data-history-node-id=\"8164\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-865\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-865<br \/><strong>Date:<\/strong> August\u00a031, 2026<\/p>\n\n<p>As of August\u00a027, 2026, WatchGuard is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Dimension\n\t<ul><li>Prior to 2.3.1<\/li>\n\t<\/ul><\/li>\n\t<li>Fireware OS\n\t<ul><li>Prior to 12.12.2<\/li>\n\t\t<li>Prior to 12.5.20<\/li>\n\t\t<li>Prior to 2026.2.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.watchguard.com\/\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-865","alert_type":396,"serial_number":"AV26-865","subject":"other","moderation_state":"published","external_url":null},{"nid":8165,"title":"WebPros security advisory (AV26-866)","uuid":"51bb8766-648f-4d2b-94e0-beb5416d923a","banner":null,"lang":"en","date_modified":"2026-09-01","date_modified_ts":"2026-09-01T13:34:50Z","date_created":"2026-09-01T13:31:13Z","summary":null,"body":["<article data-history-node-id=\"8165\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-866\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-866<br \/><strong>Date: <\/strong>September 1, 2026<\/p>\n\n<p>As of September 1, 2026, WebPros is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Plesk\n\t<ul><li>Prior to 18.0.79.9<\/li>\n\t\t<li>Prior to 18.0.80.5<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/42968165026967-CVE-2026-67394-Vulnerability-in-Plesk-allows-privilege-escalation-to-root\">CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-866","alert_type":396,"serial_number":"AV26-866","subject":"other","moderation_state":"published","external_url":null},{"nid":8166,"title":"JFrog security advisory (AV26-867) \u2013 Update 2","uuid":"3fccc869-36f2-4b92-be02-64b2423da309","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T20:11:45Z","date_created":"2026-09-01T17:33:29Z","summary":null,"body":["<article data-history-node-id=\"8166\" about=\"\/en\/alerts-advisories\/jfrog-security-advisory-av26-867\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-867<br \/><strong>Date: <\/strong>September\u00a01, 2026<br \/><strong>Updated: <\/strong>September\u00a011, 2026<\/p>\n\n<p>As of August\u00a028, 2026, JFrog is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Artifactory\n\t<ul><li>Prior to 7.111.21<\/li>\n\t\t<li>Prior to 7.117.28<\/li>\n\t\t<li>Prior to 7.125.20<\/li>\n\t\t<li>Prior to 7.133.29<\/li>\n\t\t<li>Prior to 7.146.38<\/li>\n\t\t<li>Prior to 7.161.20<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a02, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-42016 and CVE-2026-42018 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.jfrog.com\/releases\/docs\/artifactory-self-managed-releases\">Artifactory Self-Managed Releases<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.jfrog.com\/releases\/docs\/jfrog-security-advisories\">JFrog Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329\">CISA KEV: CVE-2026-82329<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016\">CISA KEV: CVE-2026-42016<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018\">CISA KEV: CVE-2026-42018<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jfrog-security-advisory-av26-867","alert_type":396,"serial_number":"AV26-867","subject":"other","moderation_state":"published","external_url":null},{"nid":8167,"title":"Mozilla security advisory (AV26-868)","uuid":"de14ba9c-7e89-40e7-9bbe-eec91e46b773","banner":null,"lang":"en","date_modified":"2026-09-01","date_modified_ts":"2026-09-01T18:14:12Z","date_created":"2026-09-01T18:07:56Z","summary":null,"body":["<article data-history-node-id=\"8167\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-868\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-868<br \/><strong>Date: <\/strong>September 1, 2026<\/p>\n\n<p>As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\n\t<ul><li>Versions prior to 115.40<\/li>\n\t\t<li>Versions prior to 140.15<\/li>\n\t\t<li>Versions prior to 153.2<\/li>\n\t<\/ul><\/li>\n\t<li>Firefox\n\t<ul><li>Versions prior to 155<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-83\/\">Security Vulnerabilities fixed in Firefox ESR 115.40\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-84\/\">Security Vulnerabilities fixed in Firefox ESR 140.15\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-85\/\">Security Vulnerabilities fixed in Firefox ESR 153.2\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-82\/\">Security Vulnerabilities fixed in Firefox 155\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Foundation Security Advisories\u00a0\u2014 Mozilla<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-868","alert_type":396,"serial_number":"AV26-868","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":8168,"title":"Rockwell Automation security advisory (AV26-869)","uuid":"ccef3e68-9f03-40c1-b835-58c215f99fd2","banner":null,"lang":"en","date_modified":"2026-09-01","date_modified_ts":"2026-09-01T18:45:58Z","date_created":"2026-09-01T18:37:36Z","summary":null,"body":["<article data-history-node-id=\"8168\" about=\"\/en\/alerts-advisories\/rockwell-automation-security-advisory-av26-869\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-869<br \/><strong>Date: <\/strong>September 1, 2026<\/p>\n\n<p>As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>1756-ENBT Module\n\t<ul><li>All versions<\/li>\n\t<\/ul><\/li>\n\t<li>ArmorStart LT\n\t<ul><li>Prior to or equal to v2.001<\/li>\n\t<\/ul><\/li>\n\t<li>CompactLogix 5380 \/ ControlLogix 5580\n\t<ul><li>Prior to or equal to V33<\/li>\n\t\t<li>V34.011 to V34.014<\/li>\n\t\t<li>V35.011 to V35.013<\/li>\n\t\t<li>V36.011 to V36.012<\/li>\n\t<\/ul><\/li>\n\t<li>RSLinx Classic\n\t<ul><li>Prior to or equal to V4.50<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories\/advisory.SD1797.html\">SD1797\u00a0| Security Advisory\u00a0| Rockwell Automation\u00a0| US<\/a><\/li>\n\t<li><a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories\/advisory.SD1798.html\">SD1798\u00a0| Security Advisory\u00a0| Rockwell Automation\u00a0| US<\/a><\/li>\n\t<li><a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories\/advisory.SD1794.html\">SD1794\u00a0| Security Advisory\u00a0| Rockwell Automation\u00a0| US<\/a><\/li>\n\t<li><a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories\/advisory.SD1792.html\">SD1792\u00a0| Security Advisory\u00a0| Rockwell Automation\u00a0| US<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/rockwell-automation-security-advisory-av26-869","alert_type":398,"serial_number":"AV26-869","subject":"other","moderation_state":"published","external_url":null},{"nid":8169,"title":"Erlang security advisory (AV26-870)","uuid":"5ed7870a-f842-42f4-a64f-fae98cd90b08","banner":null,"lang":"en","date_modified":"2026-09-01","date_modified_ts":"2026-09-01T18:50:12Z","date_created":"2026-09-01T18:47:10Z","summary":null,"body":["<article data-history-node-id=\"8169\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av26-870\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-870<br \/><strong>Date: <\/strong>September 1, 2026<\/p>\n\n<p>As of September 1, 2026, Erlang is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>OTP\u00a0- Multiple versions<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/\">Erlang Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av26-870","alert_type":396,"serial_number":"AV26-870","subject":"other","moderation_state":"published","external_url":null},{"nid":8170,"title":"[Control systems] Schneider Electric security advisory (AV26-871)","uuid":"dc2eef0b-2065-437a-a7b2-0d5bac81fb23","banner":null,"lang":"en","date_modified":"2026-09-02","date_modified_ts":"2026-09-02T12:28:12Z","date_created":"2026-09-02T12:21:02Z","summary":null,"body":["<article data-history-node-id=\"8170\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-871\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-871<br \/><strong>Date: <\/strong>September\u00a02, 2026<\/p>\n\n<p>As of September\u00a01, 2026, Schneider Electric is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>NetBotz 5\u00a0- 750\/755\n\t<ul><li>Versions prior to or equal to 5.5.2<\/li>\n\t<\/ul><\/li>\n\t<li>PowerChute Serial Shutdown\n\t<ul><li>Versions prior to or equal to 1.5<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.se.com\/files?p_Doc_Ref=SEVD-2026-223-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-223-02.pdf\">Multiple Vulnerabilities on NetBotz 5\u00a0- 750\/755 Products<\/a><\/li>\n\t<li><a href=\"https:\/\/download.se.com\/files?p_Doc_Ref=SEVD-2026-223-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-223-01.pdf \">Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute\u2122 Serial Shutdown<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-871","alert_type":396,"serial_number":"AV26-871","subject":"other","moderation_state":"published","external_url":null},{"nid":8171,"title":"SonicWall security advisory (AV26-872) \u2013 Update 1","uuid":"071a8008-52f6-456e-9777-a4157529a92e","banner":null,"lang":"en","date_modified":"2026-09-02","date_modified_ts":"2026-09-02T18:44:56Z","date_created":"2026-09-02T12:40:09Z","summary":null,"body":["<article data-history-node-id=\"8171\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-872\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-872<br \/><strong>Date: <\/strong>September\u00a02, 2026<\/p>\n\n<p>As of September\u00a01, 2026, SonicWall is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>SMA1000\u00a0- 6210, 7210, 8200v\n\t<ul><li>12.4.3-03453 (platform-hotfix) and older versions<\/li>\n\t\t<li>12.5.0-02835 (platform-hotfix) and older versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>SonicWall indicates that CVE-2026-83548 and CVE-2026-83549 are being exploited.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a02, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 and CVE-2026-83549 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0016\">Security Advisory<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/\">SonicWall Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548\">CISA KEV: CVE-2026-83548<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549\">CISA KEV: CVE-2026-83549<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-872","alert_type":396,"serial_number":"AV26-872","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":8172,"title":"HPE security advisory (AV26-873)","uuid":"a9544b64-5838-4250-91ea-8220ea87f241","banner":null,"lang":"en","date_modified":"2026-09-02","date_modified_ts":"2026-09-02T13:38:08Z","date_created":"2026-09-02T13:27:28Z","summary":null,"body":["<article data-history-node-id=\"8172\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-873\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-873<br \/><strong>Date: <\/strong>September\u00a02, 2026<\/p>\n\n<p>As of September\u00a01, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Networking AOS-CX\n\t<ul><li>Prior to or equal to 10.10.1180<\/li>\n\t\t<li>Prior to or equal to 10.13.1180<\/li>\n\t\t<li>Prior to or equal to 10.16.1051<\/li>\n\t\t<li>Prior to or equal to 10.17.1021<\/li>\n\t\t<li>Prior to or equal to 10.18.0001<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>HPE Networking Fabric Composer\n\t<ul><li>Prior to or equal to 7.3.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05133en_us&amp;docLocale=en_US#hpesbnw05133-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW05133 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05134en_us&amp;docLocale=en_US#hpesbnw05134-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW05134 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-873","alert_type":396,"serial_number":"AV26-873","subject":"hpe","moderation_state":"published","external_url":null},{"nid":8173,"title":"Google security advisory (AV26-874)","uuid":"cb667ba0-95ca-48dc-9208-a1b628ecc256","banner":null,"lang":"en","date_modified":"2026-09-02","date_modified_ts":"2026-09-02T14:27:54Z","date_created":"2026-09-02T14:20:10Z","summary":null,"body":["<article data-history-node-id=\"8173\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-874\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-874<br \/><strong>Date: <\/strong>September\u00a02, 2026<\/p>\n\n<p>As of September\u00a02, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>Prior to 152.0.7977.75<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop.html\">Stable Channel Update for Desktop<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-874","alert_type":396,"serial_number":"AV26-874","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8175,"title":"Progress Software security advisory (AV26-875)","uuid":"c0955705-9e7e-4fb1-a1d3-94b9e80d25dc","banner":null,"lang":"en","date_modified":"2026-09-02","date_modified_ts":"2026-09-02T15:33:28Z","date_created":"2026-09-02T15:28:04Z","summary":null,"body":["<article data-history-node-id=\"8175\" about=\"\/en\/alerts-advisories\/progress-software-security-advisory-av26-875\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-875<br \/><strong>Date: <\/strong>September\u00a02, 2026<\/p>\n\n<p>As of September\u00a02, 2026, Progress Software is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Telerik UI for ASP.NET AJAX\n\t<ul><li>Prior to 2026.3.812<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.telerik.com\/products\/aspnet-ajax\/documentation\/knowledge-base\/kb-security-rie-path-traversal-cve-2026-18672\">Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.telerik.com\/products\/aspnet-ajax\/documentation\/knowledge-base\/kb-security-dialoghandler-uploadpaths-tampering-cve-2026-19219\">Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026-19219)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-software-security-advisory-av26-875","alert_type":396,"serial_number":"AV26-875","subject":"other","moderation_state":"published","external_url":null},{"nid":8176,"title":"Cisco security advisory (AV26-876)","uuid":"e26dc853-64c8-4474-a402-2483dbdea28c","banner":null,"lang":"en","date_modified":"2026-09-03","date_modified_ts":"2026-09-03T13:13:34Z","date_created":"2026-09-03T12:46:44Z","summary":null,"body":["<article data-history-node-id=\"8176\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-876\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-876<br \/><strong>Date: <\/strong>September 3, 2026<\/p>\n\n<p>As of September 2, 2026, Cisco is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco IOS XR Software\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Cisco Nexus 9000 Series Switches\n\t<ul><li>Multiple products<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Cisco Desk Phone 9800 Series and Video Phone 8875\n\t<ul><li>Prior to 5.0(1)<\/li>\n\t<\/ul><\/li>\n\t<li>IP Phone 7800 and 8800\n\t<ul><li>Prior to 14.4(1)SR3<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>IP Phone 8845 and 8865\n\t<ul><li>Prior to14.4(1)SR4<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Wireless IP Phone 8821\n\t<ul><li>Prior to 11.0(6)SR8<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-n9k-s1-rce-EH8dEtr\">Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-iosxr-qg64NcM\">Cisco IOS XR Software Security Hardening Release: September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-phone-dos-txMYNRzv\">Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories <\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-876","alert_type":396,"serial_number":"AV26-876","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8177,"title":"Jenkins security advisory (AV26-877)","uuid":"a30709cd-204b-4442-9f11-5b197cffe089","banner":null,"lang":"en","date_modified":"2026-09-03","date_modified_ts":"2026-09-03T13:54:40Z","date_created":"2026-09-03T13:20:52Z","summary":null,"body":["<article data-history-node-id=\"8177\" about=\"\/en\/alerts-advisories\/jenkins-security-advisory-av26-877\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-877<br \/><strong>Date: <\/strong>September 3, 2026<\/p>\n\n<p>As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Jenkins\n\t<ul><li>ALL except 2.568.3<\/li>\n\t\t<li>ALL except 2.580<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins Allure Plugin\n\t<ul><li>Prior to or equal to 2.35.2<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins Customizable Header Plugin\n\t<ul><li>Prior to or equal to 295.v2544b_ca_19b_97<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins File Parameter Plugin\n\t<ul><li>Prior to or equal to 425.v3fa_801681b_5e<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins GitLab Plugin\n\t<ul><li>Prior to or equal to 1.9.16<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins LDAP Plugin\n\t<ul><li>Prior to or equal to 807.809.vd3a_4e5e4ec98<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins Microsoft Entra ID (previously Azure AD) Plugin\n\t<ul><li>Prior to or equal to 710.v0b_ff8e9cc2d2<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins Parameterized Remote Trigger Plugin\n\t<ul><li>Prior to or equal to 3.2.2<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins Performance Plugin\n\t<ul><li>Prior to or equal to 1015.v09ca_52b_3370e<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins Pipeline: Build Step Plugin\n\t<ul><li>Prior to or equal to 599.v4b_67ea_11b_152<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins SAML Plugin\n\t<ul><li>Prior to or equal to 4.618.v441a_27fa_46d2<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins Script Security Plugin\n\t<ul><li>Prior to or equal to 1412.v7737b_3405f86<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins TICS Plugin\n\t<ul><li>Prior to or equal to 2025.1.1<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins ThinBackup Plugin\n\t<ul><li>Prior to or equal to 2.1.4<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins XebiaLabs XL Deploy Plugin\n\t<ul><li>Prior to or equal to 26.1.0<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>Jenkins update-center2\n\t<ul><li>Prior to or equal to 3.18.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jenkins.io\/security\/advisory\/2026-09-02\/\">Jenkins Security Advisory 2026-09-02<\/a><\/li>\n\t<li><a href=\"https:\/\/www.jenkins.io\/security\/advisories\/\">Security Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jenkins-security-advisory-av26-877","alert_type":396,"serial_number":"AV26-877","subject":"other","moderation_state":"published","external_url":null},{"nid":8178,"title":"F5 security advisory (AV26-878)","uuid":"036d6fde-b149-4a4d-beae-fc620ffbb71e","banner":null,"lang":"en","date_modified":"2026-09-03","date_modified_ts":"2026-09-03T14:05:53Z","date_created":"2026-09-03T14:01:14Z","summary":null,"body":["<article data-history-node-id=\"8178\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-878\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-878<br \/><strong>Date: <\/strong>September 3, 2026<\/p>\n\n<p>As of September 2, 2026, F5 is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>BIG-IP (all modules)\n\t<ul><li>Prior to 17.1.3.4<\/li>\n\t\t<li>Prior to 17.5.1.8<\/li>\n\t\t<li>Prior to 21.0.0.3<\/li>\n\t\t<li>Prior to 21.1.0.1<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>BIG-IQ\n\t<ul><li>Prior to 8.4.2.1<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>NGINX Gateway Fabric\n\t<ul><li>Prior to 2.6.8<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>NGINX Ingress Controller\n\t<ul><li>Prior to 2026-lts-r5<\/li>\n\t\t<li>Prior to 5.6.0<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>NGINX JavaScript\n\t<ul><li>9.9<\/li>\n\t\t<li>Prior to 1.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>APM Clients\n\t<ul><li>Prior to 7.2.6<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>BIG-IP APM\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000162872\">K000162872: Out-of-band Security Notification (September 2, 2026)<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-878","alert_type":396,"serial_number":"AV26-878","subject":"f5","moderation_state":"published","external_url":null},{"nid":8179,"title":"AMD security advisory (AV26-879)","uuid":"846319ba-36d4-422a-b537-2b182173cd6b","banner":null,"lang":"en","date_modified":"2026-09-03","date_modified_ts":"2026-09-03T15:05:51Z","date_created":"2026-09-03T14:09:50Z","summary":null,"body":["<article data-history-node-id=\"8179\" about=\"\/en\/alerts-advisories\/amd-security-advisory-av26-879\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-879<br \/><strong>Date: <\/strong>September 3, 2026<\/p>\n\n<p>As of September 2, 2026, AMD is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>2nd Gen AMD EPYC\u2122 Processors\n\t<ul><li>all except RomePI 1.0.0.H<\/li>\n\t<\/ul><\/li>\n\t<li>3rd Gen AMD EPYC\u2122 Processors\n\t<ul><li>all except MilanPI 1.0.0.C<\/li>\n\t<\/ul><\/li>\n\t<li>4th Gen AMD EPYC\u2122 Processors\n\t<ul><li>all except GenoaPI 1.0.0.8<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Athlon\u2122 3000 Series Desktop Processors with Radeon\u2122 Graphics\n\t<ul><li>all except ComboAM4 1.0.0.B<\/li>\n\t\t<li>all except ComboAM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Athlon\u2122 3000 Series Mobile Processors with Radeon\u2122 Graphics\n\t<ul><li>all except PicassoPI-FP5 1.0.1.0<\/li>\n\t\t<li>all except PollockPI-FT5 1.0.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122 Embedded 3000\n\t<ul><li>all except Snowyowl PI 1.1.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122 Embedded 7002\n\t<ul><li>all except EmbRomePI-SP3 1.0.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122 Embedded 7003\n\t<ul><li>all except EmbMilanPI-SP3 1.0.0.8<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122 Embedded 9003\n\t<ul><li>all except EmbGenoaPI-SP5 1.0.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Instinct\u2122 MI300A\n\t<ul><li>all except MI300 SR5 PI 1.0.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Radeon\u2122 PRO V620 Graphics Products\n\t<ul><li>all except Contact your AMD Customer Engineering representative<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 3000 Series Desktop Processors\n\t<ul><li>all except ComboAM4 1.0.0.B<\/li>\n\t\t<li>all except ComboAM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 3000 Series Mobile Processor with Radeon\u2122 Graphics\n\t<ul><li>all except PicassoPI-FP5 1.0.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 3000 Series Processors with Radeon\u2122 Graphics\n\t<ul><li>all except CezannePI-FP6 1.0.0.F<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 4000 Series Desktop Processors with Radeon\u2122 Graphics\n\t<ul><li>all except ComboAM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 4000 Series Mobile Processors with Radeon\u2122 Graphics\n\t<ul><li>all except RenoirPI-FP6 1.0.0.D<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 5000 Series Desktop Processors\n\t<ul><li>all except ComboAM4v2 1.2.0.B<\/li>\n\t\t<li>all except ComboAM4v2v 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 5000 Series Desktop Processors with Radeon\u2122 Graphics\n\t<ul><li>all except ComboAM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 5000 Series Mobile Processors with Radeon\u2122 Graphics\n\t<ul><li>all except CezannePI-FP6 1.0.0.F<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 5000 Series Processors with Radeon\u2122 Graphics\n\t<ul><li>all except CezannePI-FP6 1.0.0.F<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 6000 Series Processors with Radeon\u2122 Graphics\n\t<ul><li>all except RembrandtPI-FP7 1.0.0.9b<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 7000 Series Processors\n\t<ul><li>all except ComboAM5 1.0.0.7b<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 7020 Series Processors with Radeon\u2122 Graphics\n\t<ul><li>all except MendocinoPI-FT6 1.0.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 7035 Series Processors with Radeon\u2122 Graphics\n\t<ul><li>all except RembrandtPI-FP7 1.0.0.9b<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 7040 Series Processors with Radeon\u2122 Graphics\n\t<ul><li>all except PhoenixPI-FP8-FP7 1.0.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 7045 Series Mobile Processors\n\t<ul><li>all except DragonRangeFL1PI 1.0.0.3a<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Embedded 5000\n\t<ul><li>all except EmbAM4PI 1.0.0.4<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Embedded R1000\n\t<ul><li>all except EmbeddedPI-FP5 1.2.0.A<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Embedded R2000\n\t<ul><li>all except EmbeddedPI-FP5 1.0.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Embedded V1000\n\t<ul><li>all except EmbeddedPI-FP5 1.2.0.A<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Embedded V2000\n\t<ul><li>all except EmbeddedPI-FP6 1.0.0.9<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Embedded V3000\n\t<ul><li>all except EmbeddedPI-FP7r2 1.0.0.8<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Threadripper\u2122 3000 Series Processors\n\t<ul><li>all except CastlePeakPI-SP3r3 1.0.0.A<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Threadripper\u2122 PRO 3000WX Series Processors\n\t<ul><li>all except CastlePeakWSPI-sWRX8 1.0.0.C<\/li>\n\t\t<li>all except ChagallWSPI-sWRX8 1.0.0.7<\/li>\n\t<\/ul><\/li>\n\t<li>AMD Ryzen\u2122 Threadripper\u2122 PRO 5000WX Processors\n\t<ul><li>all except ChagallWSPI-sWRX8 1.0.0.7<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7009.html\">AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Processor Vulnerabilities<\/span><\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Product Security<\/span><\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><p><strong>Num\u00e9ro de s\u00e9rie\u00a0: <\/strong>AV26-879<br \/><strong>Date\u00a0: <\/strong>3 septembre 2026<\/p>\n\n<p>En date du 2 septembre 2026, AMD est touch\u00e9 par des vuln\u00e9rabilit\u00e9s dans les produits suivants\u00a0:<\/p>\n\n<ul><li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">2nd Gen<\/span> AMD EPYC\u2122 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Processors<\/span>\n\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Rome<\/span>PI 1.0.0.H<\/li>\n\t<\/ul><\/li>\n\t<li>3<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">rd Gen<\/span> AMD EPYC\u2122 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Milan<\/span>PI 1.0.0.C<\/li>\n\t<\/ul><\/li>\n\t<li><span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">4th Gen<\/span> AMD EPYC\u2122 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Genoa<\/span>PI 1.0.0.8<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Athlon<\/span>\u2122 3000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Desktop Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4 1.0.0.B<\/li>\n\t\t<li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Athlon<\/span>\u2122 3000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Mobile Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Picasso<\/span>PI-FP5 1.0.1.0<\/li>\n\t\t<li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Pollock<\/span>PI-FT5 1.0.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Embedded<\/span> 3000\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Snowyowl<\/span> PI 1.1.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Embedded<\/span> 7002\n\t<ul><li>TOUS sauf E<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">mbRome<\/span>PI-SP3 1.0.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122<span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\"> Embedded<\/span> 7003\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">EmbMilan<\/span>PI-SP3 1.0.0.8<\/li>\n\t<\/ul><\/li>\n\t<li>AMD EPYC\u2122 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Embedded<\/span> 9003\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">EmbGenoa<\/span>PI-SP5 1.0.0.3<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Instinct<\/span>\u2122 MI300A\n\t<ul><li>TOUS sauf MI300 SR5 PI 1.0.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Radeon<\/span>\u2122 PRO V620 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Graphics Products<\/span>\n\t<ul><li>TOUS <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">sauf Contact your<\/span> AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">\\Customer Engineering representative<\/span><\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen<\/span>\u2122 3000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Desktop Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4 1.0.0.B<\/li>\n\t\t<li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen<\/span>\u2122 3000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Mobile Processor with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Picasso<\/span>PI-FP5 1.0.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen<\/span>\u2122 3000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Cezanne<\/span>PI-FP6 1.0.0.F<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen<\/span>\u2122 4000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Desktop Processors with Radeon<\/span>\u2122 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 4000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Mobile Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">sauf Renoir<\/span>PI-FP6 1.0.0.D<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 5000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Desktop Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4v2 1.2.0.B<\/li>\n\t\t<li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4v2v 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 5000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Desktop Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM4v2 1.2.0.B<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 5000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Mobile Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Cezanne<\/span>PI-FP6 1.0.0.F<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 5000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Cezanne<\/span>PI-FP6 1.0.0.F<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 6000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Rembrandt<\/span>PI-FP7 1.0.0.9b<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 7000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Combo<\/span>AM5 1.0.0.7b<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 7020 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Mendocino<\/span>PI-FT6 1.0.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 7035 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Rembrandt<\/span>PI-FP7 1.0.0.9b<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 7040 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors with Radeon\u2122 Graphics<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Phoenix<\/span>PI-FP8-FP7 1.0.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122<\/span> 7045 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Mobile Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">DragonRange<\/span>FL1PI 1.0.0.3a<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Embedded<\/span> 5000\n\t<ul><li>TOUS sauf EmbAM4PI 1.0.0.4<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Embedded<\/span> R1000\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Embedded<\/span>PI-FP5 1.2.0.A<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Embedded<\/span> R2000\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Embedded<\/span>PI-FP5 1.0.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Embedded<\/span> V1000\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Embedded<\/span>PI-FP5 1.2.0.A<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Embedded<\/span> V2000\n\t<ul><li>TOUS sauf EmbeddedPI-FP6 1.0.0.9<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Embedded<\/span> V3000\n\t<ul><li>TOUS sauf EmbeddedPI-FP7r2 1.0.0.8<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Threadripper\u2122<\/span> 3000 <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">CastlePeak<\/span>PI-SP3r3 1.0.0.A<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Threadripper\u2122<\/span> PRO 3000WX <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Series Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">CastlePeak<\/span>WSPI-sWRX8 1.0.0.C<\/li>\n\t\t<li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Chagall<\/span>WSPI-sWRX8 1.0.0.7<\/li>\n\t<\/ul><\/li>\n\t<li>AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Ryzen\u2122 Threadripper\u2122<\/span> PRO 5000WX <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Processors<\/span>\n\t<ul><li>TOUS sauf <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Chagall<\/span>WSPI-sWRX8 1.0.0.7<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Le Centre pour la cybers\u00e9curit\u00e9 encourage les utilisateurs et les administrateurs \u00e0 consulter les liens fournis et \u00e0 installer les mises \u00e0 jour n\u00e9cessaires, d\u00e8s qu'elles sont disponibles.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7009.html\">AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Processor Vulnerabilities<\/span> (en anglais seulement)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.amd.com\/en\/resources\/product-security.html\">AMD <span lang=\"en\" xml:lang=\"en\" xml:lang=\"en\">Product Security<\/span> (en anglais seulement)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/amd-security-advisory-av26-879","alert_type":396,"serial_number":"AV26-879","subject":"other","moderation_state":"published","external_url":null},{"nid":8180,"title":"n8n security advisory (AV26-880)","uuid":"7d7ed90a-9619-44b1-98c2-b75cdf65f8e2","banner":null,"lang":"en","date_modified":"2026-09-03","date_modified_ts":"2026-09-03T18:59:03Z","date_created":"2026-09-03T18:45:51Z","summary":null,"body":["<article data-history-node-id=\"8180\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-880\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-880<br \/><strong>Date: <\/strong>September 3, 2026<\/p>\n\n<p>As of September 3, 2026, n8n is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>n8n\n\t<ul><li>Prior to 1.123.76<\/li>\n\t\t<li>Prior to 2.35.4<\/li>\n\t\t<li>Prior to 2.36.2<\/li>\n\t\t<li>Prior to 2.37.7<\/li>\n\t\t<li>Prior to 2.38.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">Overview\u00a0\u00b7 n8n-io\/n8n\u00a0\u00b7 GitHub <\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-880","alert_type":396,"serial_number":"AV26-880","subject":"other","moderation_state":"published","external_url":null},{"nid":8181,"title":"[Control Systems] Siemens security advisory (AV26-881)","uuid":"5b878fca-7a03-4e5b-9a2c-582e1e8dcecb","banner":null,"lang":"en","date_modified":"2026-09-03","date_modified_ts":"2026-09-03T19:32:38Z","date_created":"2026-09-03T19:23:36Z","summary":null,"body":["<article data-history-node-id=\"8181\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-881\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-881<br \/><strong>Date: <\/strong>September 3, 2026<\/p>\n\n<p>As of September 3, 2026, Siemens is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>Mendix SAML (Mendix 10 compatible)\n\t<ul><li>Prior to V4.2.3<\/li>\n\t<\/ul><\/li>\n\t<li>Mendix SAML (Mendix 11 compatible)\n\t<ul><li>Prior to V4.2.3<\/li>\n\t<\/ul><\/li>\n\t<li>Mendix SAML (Mendix 9.24 compatible)\n\t<ul><li>Prior to V3.6.27<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-887643.html\">SSA-887643: Account Hijacking Vulnerability in Mendix SAML module<\/a><\/li>\n\t<li><a href=\"https:\/\/www.siemens.com\/en-us\/content\/cert-services\/\">CERT Services | Siemens<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-881","alert_type":398,"serial_number":"AV26-881","subject":"siemens","moderation_state":"published","external_url":null},{"nid":8182,"title":"SUSE Linux security advisory (AV26-882)","uuid":"3ebd4fc4-7bfe-4bc6-a427-54ced2c451f9","banner":null,"lang":"en","date_modified":"2026-09-03","date_modified_ts":"2026-09-03T19:47:27Z","date_created":"2026-09-03T19:41:21Z","summary":null,"body":["<article data-history-node-id=\"8182\" about=\"\/en\/alerts-advisories\/suse-linux-security-advisory-av26-882\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-882<br \/><strong>Date: <\/strong>September 3, 2026<\/p>\n\n<p>As of September 3, 2026, SUSE is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Rancher\n\t<ul><li>Prior to 2.15.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/rancher\/rancher\/releases\/tag\/v2.15.1\">Release v2.15.1\u00a0\u00b7 rancher\/rancher\u00a0\u00b7 GitHub <\/a><\/li>\n\t<li><a href=\"https:\/\/www.suse.com\/support\/update\/\">SUSE Update Advisories<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/suse-linux-security-advisory-av26-882","alert_type":396,"serial_number":"AV26-882","subject":"other","moderation_state":"published","external_url":null},{"nid":8185,"title":"Google security advisory (AV26-883) \u2013 Update 1","uuid":"58e0ad0c-9f03-48b1-a6fc-acd91be7753e","banner":null,"lang":"en","date_modified":"2026-09-04","date_modified_ts":"2026-09-04T17:21:27Z","date_created":"2026-09-04T14:16:34Z","summary":null,"body":["<article data-history-node-id=\"8185\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-883\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-883<br \/><strong>Date:<\/strong> September\u00a04, 2026<\/p>\n\n<p>As of September\u00a03, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>Prior to 152.0.7977.82<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2026-85046 exists in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a04, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_01882797386.html\">Stable Channel Update for Desktop<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046\">CISA KEV: CVE-2026-85046<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-883","alert_type":396,"serial_number":"AV26-883","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8187,"title":"AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 - Update 1","uuid":"b75b48c1-8e4a-4ada-b6a3-4c7c6bffba08","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T20:20:15Z","date_created":"2026-09-04T18:05:21Z","summary":null,"body":["<article data-history-node-id=\"8187\" about=\"\/en\/alerts-advisories\/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-019<br \/><strong>Date:<\/strong> September\u00a04, 2026<br \/><strong>Updated:<\/strong> September\u00a09, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway)<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. \u00a0<\/p>\n\n<p>In response to the vendor advisory released on August\u00a019, 2026, the Cyber Centre released AV26-833 on August\u00a019, 2026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>Tracked as CVE-2026-19490<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.<\/p>\n\n<p>Tracked as CVE-2026-19489<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>, this vulnerability is a Classic Buffer Overflow vulnerability (CWE-120)<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>. This vulnerability may allow memory overflow leading to unpredictable behavior or Denial of Service conditions.<\/p>\n\n<p>Pre-conditions for these vulnerabilities are that the NetScaler ADC or NetScaler Gateway 14.1-43.56 and later, as well as 13.1-61.28 and later, must be configured as a SAML IdP (Security Assertion Markup Language Identity Provider).<\/p>\n\n<p>Earlier builds with Gateway or AAA configuration are also vulnerable.<\/p>\n\n<p>To determine if organizations are impacted, it is recommended to check if the appliance meets the precondition by inspecting the NetScaler configuration for the specified strings:<\/p>\n\n<h3>For CVE-2026-19489:<\/h3>\n\n<p>\"<code>add lsn group.*sipalg.*<\/code>\"<\/p>\n\n<h3>For CVE-2026-19490:<\/h3>\n\n<h4>SAML action configuration:<\/h4>\n\n<p>\"<code>add authentication samlAction.*<\/code>\"<\/p>\n\n<h3>Auth or <abbr title=\"virtual private network\">VPN<\/abbr> vserver:<\/h3>\n\n<p>\"<code>add authentication vserver .*<\/code>\" or \"<code>add vpn vserver .*<\/code>\"<\/p>\n\n<p class=\"mrgn-tp-lg\">Further information about the impacted configurations can be found in the Citrix advisory<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<h2>Update 1<\/h2>\n\n<p>On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) <span class=\"nowrap\">Database.<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup><\/span><\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations using Citrix NetScaler ADC and NetScaler Gateway appliances (particularly for SAML IDP-configured appliances), review the Citrix security bulletin<sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and update\/upgrade the affected systems to the following vendor-supported fixed versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>NetScaler ADC and NetScaler Gateway 14.1<\/td>\n\t\t\t<td>versions prior to 14.1-73.32<\/td>\n\t\t\t<td>version 14.1-73.32 and later<\/td>\n\t\t<\/tr><tr><td>NetScaler ADC and NetScaler Gateway 13.1<\/td>\n\t\t\t<td>versions prior to 13.1-63.21<\/td>\n\t\t\t<td>version 13.1-63.21 and later<\/td>\n\t\t<\/tr><tr><td>NetScaler ADC FIPS<\/td>\n\t\t\t<td>versions prior to 14.1-73.32 FIPS<\/td>\n\t\t\t<td>version 14.1-73.32 FIPS and later<\/td>\n\t\t<\/tr><tr><td>NetScaler ADC FIPS and NDcPP<\/td>\n\t\t\t<td>versions prior to 13.1-37.277<\/td>\n\t\t\t<td>version 13.1-37.277 and later<\/td>\n\t\t<\/tr><\/tbody><\/table><\/div>\n\n<p>The Cyber Centre also recommends organizations to:<\/p>\n\n<ul><li>determine the current version of software on each appliance<\/li>\n\t<li>identify NetScaler appliances configured as Gateway services or AAA virtual servers<\/li>\n\t<li>review configurations for SAML authentication deployments, where applicable<\/li>\n\t<li>prioritize patching affected systems on an emergency basis<\/li>\n\t<li>monitor authentication logs and network activity for indications of unauthorized access<\/li>\n\t<li>follow Citrix incident response guidance if compromise is suspected<\/li>\n\t<li>after patching, verify the appliance is running the updated version and review logs for unusual activity<\/li>\n<\/ul><p>Citrix has provided steps to take if NetScaler ADC or NetScaler Gateway are suspected to be compromised<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>patch operating systems and applications<\/li>\n\t<li>harden operating systems and applications<\/li>\n\t<li>isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n<!--FOOTNOTE SECTION EN-->\n\n<aside class=\"wb-fnote\" role=\"note\"><h2 id=\"reference\">References<\/h2>\n\n<dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696939\">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-833\">AV26-833\u00a0\u2013 Citrix security advisory <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-19490\">CVE-2026-19490 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/288.html\">CWE-288: Authentication Bypass Using an Alternate Path or Channel<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-19489\">CVE-2026-19489 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/120.html\">CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX694799\">Citrix\u00a0\u2013 Steps to Take if NetScaler ADC is Suspected to be Compromised<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490\">CISA KEV: CVE-2026-19490<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489","alert_type":397,"serial_number":"AL26-019","subject":"other","moderation_state":"published","external_url":null},{"nid":8193,"title":"Mikrotik security advisory (AV26-887) \u2013 Update 2","uuid":"98ce64a6-58c3-4655-8710-40ac98c665b5","banner":null,"lang":"en","date_modified":"2026-09-25","date_modified_ts":"2026-09-25T15:33:02Z","date_created":"2026-09-08T12:48:35Z","summary":null,"body":["<article data-history-node-id=\"8193\" about=\"\/en\/alerts-advisories\/mikrotik-security-advisory-av26-887\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-887<br \/><strong>Date:<\/strong> September\u00a08, 2026<br \/><strong>Updated:<\/strong> September 25, 2026<\/p>\n\n<p>As of September\u00a03, 2026, Mikrotik is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>RouterOS\n\t<ul><li>Prior to 6.49.21<\/li>\n\t\t<li>Prior to 7.23.4<\/li>\n\t\t<li>Prior to 7.24.2<\/li>\n\t\t<li>Prior to 7.25 beta 3<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 related to MikroTik are being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a010, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>On September\u00a025, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67279 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cert.pl\/en\/posts\/2026\/09\/mikrotik-routeros-cve\/\">Vulnerabilities in Mikrotik RouterOS software<\/a><\/li>\n\t<li><a href=\"https:\/\/mikrotik.com\/supportsec\/september-2026-vulnerability\/\">September 2026 vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277\">CISA KEV: CVE-2026-67277<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060\">CISA KEV: CVE-2026-86060<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67279\">CISA KEV: CVE-2026-67279<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mikrotik-security-advisory-av26-887","alert_type":396,"serial_number":"AV26-887","subject":"other","moderation_state":"published","external_url":null},{"nid":8190,"title":"SonicWall security advisory (AV26-884)","uuid":"dd229b49-a39d-491d-8108-a0ea40ce9ea5","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T14:01:45Z","date_created":"2026-09-08T12:48:35Z","summary":null,"body":["<article data-history-node-id=\"8190\" about=\"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-884\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-884<br \/><strong>Date: <\/strong>September\u00a04, 2026<\/p>\n\n<p>As of September\u00a04, 2026, SonicWall is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Network Security Manager (NSM) On-Prem (VMWare, Hyper-V, Azure and KVM)\n\t<ul><li>4.3.0 and earlier versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0015\">SonicWall NSM On-Prem Affected By Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.global.sonicwall.com\/\">Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sonicwall-security-advisory-av26-884","alert_type":396,"serial_number":"AV26-884","subject":"sonicwall","moderation_state":"published","external_url":null},{"nid":8192,"title":"Dell security advisory (AV26-886)","uuid":"70b54a6a-b2f2-44bb-877f-40bd245bf6db","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T14:07:47Z","date_created":"2026-09-08T12:48:35Z","summary":null,"body":["<article data-history-node-id=\"8192\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-886\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-886<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September\u00a07, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell OpenManage Network Integration\n\t<ul><li>Prior to 3.10 or later<\/li>\n\t<\/ul><\/li>\n\t<li>Dell iDRAC9\n\t<ul><li>Versions prior to 7.30.10.50 and 7.00.00.184<\/li>\n\t<\/ul><\/li>\n\t<li>Dell iDRAC10\n\t<ul><li>Prior to 1.30.30.50 or later<\/li>\n\t<\/ul><\/li>\n\t<li>Dell PowerEdge Server for Intel 2026\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Open Manage Python SDK (omsdk)\n\t<ul><li>Prior to 1.2.519 or later<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Avamar\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Networker Virtual Edition (NVE)\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Dell PowerProtect DP Series Appliance\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Integrated Data Protection Appliance (IDPA)\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Dell PowerScale OneFS\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources\u00a0| Dell Canada<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-886","alert_type":396,"serial_number":"AV26-886","subject":"dell","moderation_state":"published","external_url":null},{"nid":8191,"title":"N-able security advisory (AV26-885) \u2013 Update 2","uuid":"e20d1e59-5b9d-417d-8780-120dc886b195","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T19:22:35Z","date_created":"2026-09-08T12:48:35Z","summary":null,"body":["<article data-history-node-id=\"8191\" about=\"\/en\/alerts-advisories\/n-able-security-advisory-av26-885\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-885<br \/><strong>Date:<\/strong> September\u00a08, 2026<br \/><strong>Updated:<\/strong> September\u00a09, 2026<\/p>\n\n<p>As of September\u00a06, 2026, N-able is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>N-central\n\t<ul><li>Prior to 2026.3.1.14<\/li>\n\t<\/ul><\/li>\n<\/ul><p>N-able indicates that CVE-2026-86218 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a08, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p>Open-source reporting indicates that CVE-2026-86207 is being exploited in the wild.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/status.n-able.com\/2026\/09\/06\/n-central-2026-3-hotfix-4-cve-2026-86218\/\">N-central 2026.3 Hotfix 4\u00a0\u2013 CVE-2026-86218<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.n-able.com\/N-central\/Release_Notes\/GA\/Content\/N-central_2026.3_HF4_Release_Notes.htm\">2026.3 HF4 Release Notes<\/a><\/li>\n\t<li><a href=\"https:\/\/status.n-able.com\/release-notes\/\">Release Notes\u00a0| N-able Status\u00a0| N-able Status Page<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86218\">CISA KEV: CVE-2026-86218<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n-able-security-advisory-av26-885","alert_type":396,"serial_number":"AV26-885","subject":"other","moderation_state":"published","external_url":null},{"nid":8194,"title":"Adobe security advisory (AV26-888) \u2013 Update 1","uuid":"c5158867-f9bf-45bb-a8d3-ca3eae992fe1","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T18:57:38Z","date_created":"2026-09-08T12:48:36Z","summary":null,"body":["<article data-history-node-id=\"8194\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-888\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-888<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September 8, 2026, Adobe is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>Adobe Acrobat\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Animate 2023\n\t<ul><li>Prior to or equal to 2023.0.16<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Animate 2024\n\t<ul><li>Prior to or equal to 0.14\u00a0<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Campaign Classic\n\t<ul><li>Prior to or equal to ACC v7: 7.4.4 build 9401<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe ColdFusion 2023\n\t<ul><li>Prior to or equal to 2023.0.23<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe ColdFusion 2025\n\t<ul><li>Prior to or equal to 0.12\u00a0<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Commerce\n\t<ul><li>All except Hotfix for CVE-2026-7565<\/li>\n\t\t<li>Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Commerce B2B\n\t<ul><li>All except Hotfix for CVE-2026-7565<\/li>\n\t\t<li>Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Experience Manager (AEM)\n\t<ul><li>Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0<\/li>\n\t\t<li>Prior to or equal to 5 LTS Service Pack 2<\/li>\n\t\t<li>Prior to or equal to 5 Service Pack 24 and earlier<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Illustrator 2025\n\t<ul><li>Prior to or equal to 8.10<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Illustrator 2026\n\t<ul><li>Prior to or equal to 7<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Photoshop 2025\n\t<ul><li>Prior to or equal to 11.6<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Photoshop 2026\n\t<ul><li>Prior to or equal to 6<\/li>\n\t<\/ul><\/li>\n\t<li>Magento Open Source\n\t<ul><li>All except Hotfix for CVE-2026-7565<\/li>\n\t\t<li>Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Adobe indicates that CVE-2026-75650 is exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a08, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-75650 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Product Security Incident Response Team<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650\">CISA KEV: CVE-2026-75650<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-888","alert_type":396,"serial_number":"AV26-888","subject":"adobe","moderation_state":"published","external_url":null},{"nid":8195,"title":"OpenVPN security advisory (AV26-889)","uuid":"5d6dd0d1-0b02-462e-97d6-06e2eb950d82","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T15:19:11Z","date_created":"2026-09-08T13:56:03Z","summary":null,"body":["<article data-history-node-id=\"8195\" about=\"\/en\/alerts-advisories\/openvpn-security-advisory-av26-889\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-889<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September\u00a07, 2026, OpenVPN is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>OpenVPN\n\t<ul><li>Prior to or equal to 2.6.22<\/li>\n\t\t<li>Prior to or equal to 2.7.6<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.openvpn.net\/Security%20Announcements\/CVE-2026-84732#cve-2026-84732-reliability-layer-unbounded-tls-timeout-and-acks-for-non-outstanding-packets\">CVE-2026-84732\u00a0- Reliability layer unbounded TLS timeout and acks for non-outstanding packets<\/a><\/li>\n\t<li><a href=\"https:\/\/openvpn.net\/security-advisories\/\">Security Advisories &amp; Updates\u00a0| OpenVPN<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/openvpn-security-advisory-av26-889","alert_type":396,"serial_number":"AV26-889","subject":"other","moderation_state":"published","external_url":null},{"nid":8197,"title":"JetBrains security advisory (AV26-891)","uuid":"b472562b-f32c-4c9b-963c-c334d6e39295","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T17:27:37Z","date_created":"2026-09-08T13:56:03Z","summary":null,"body":["<article data-history-node-id=\"8197\" about=\"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-891\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-891<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September\u00a07, 2026, JetBrains is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>GoLand\n\t<ul><li>Prior to 2026.2.2.1<\/li>\n\t<\/ul><\/li>\n\t<li>Hub\n\t<ul><li>Prior to 2026.2.52442<\/li>\n\t<\/ul><\/li>\n\t<li>IntelliJ IDEA\n\t<ul><li>Prior to 2026.2.2<\/li>\n\t<\/ul><\/li>\n\t<li>YouTrack\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.jetbrains.com\/privacy-security\/issues-fixed\/\">Fixed security issues<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/jetbrains-security-advisory-av26-891","alert_type":396,"serial_number":"AV26-891","subject":"other","moderation_state":"published","external_url":null},{"nid":8198,"title":"[Control Systems] Inductive Automation security advisory (AV26-892)","uuid":"d98eace9-b9f8-4413-bf41-8a6421b5130f","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T17:28:19Z","date_created":"2026-09-08T13:56:04Z","summary":null,"body":["<article data-history-node-id=\"8198\" about=\"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-av26-892\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-892<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September\u00a04, 2026, Inductive Automation is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Ignition\n\t<ul><li>Prior to or equal to 8.1.53<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/cisagov\/CSAF\/blob\/develop\/csaf_files\/OT\/white\/2026\/icsa-26-246-06.json\">CSAF\/csaf_files\/OT\/white\/2026\/icsa-26-246-06.json at develop\u00a0\u00b7 cisagov\/CSAF\u00a0\u00b7 GitHub<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-26-246-06\">Inductive Automation Ignition\u00a0| CISA<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-inductive-automation-security-advisory-av26-892","alert_type":398,"serial_number":"AV26-892","subject":"other","moderation_state":"published","external_url":null},{"nid":8199,"title":"Hitachi security advisory (AV26-893)","uuid":"051e3812-1434-463e-9ac3-ec52af45e3e9","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T17:29:15Z","date_created":"2026-09-08T13:56:04Z","summary":null,"body":["<article data-history-node-id=\"8199\" about=\"\/en\/alerts-advisories\/hitachi-security-advisory-av26-893\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-893<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September\u00a08, 2026, Hitachi is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Cosminexus Component Container\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/info\/vuls\/hitachi-sec-2026-132\/index.html\">Vulnerability in Cosminexus<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/index.html\">Hitachi Vulnerability Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hitachi-security-advisory-av26-893","alert_type":396,"serial_number":"AV26-893","subject":"other","moderation_state":"published","external_url":null},{"nid":8196,"title":"[Control Systems] Siemens security advisory (AV26-890)","uuid":"e48c1c76-27f2-40b4-9dfb-2a49705917c1","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T17:27:02Z","date_created":"2026-09-08T14:45:34Z","summary":null,"body":["<article data-history-node-id=\"8196\" about=\"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-890\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-890<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September\u00a08, 2026, Siemens is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Reyrolle 7SR5\n\t<ul><li>Versions prior to V2.70<\/li>\n\t<\/ul><\/li>\n\t<li>Teamcenter\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Siveillance Control\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>SIMATIC AX Runtime\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Desigo CC Product Family\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Industrial Edge Management\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>SIMOVE Fleetmanager and SIPLANT\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.siemens.com\/en-us\/content\/cert-services\/\">CERT Services\u00a0| Siemens<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-siemens-security-advisory-av26-890","alert_type":398,"serial_number":"AV26-890","subject":"siemens","moderation_state":"published","external_url":null},{"nid":8200,"title":"SAP security advisory \u2013 September 2026 monthly rollup (AV26-894)","uuid":"73bfd3bc-ee4e-463d-a04e-224dc9416125","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T18:03:37Z","date_created":"2026-09-08T17:56:55Z","summary":null,"body":["<article data-history-node-id=\"8200\" about=\"\/en\/alerts-advisories\/sap-security-advisory-september-2026-monthly-rollup-av26-894\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-894<br \/><strong>Date: <\/strong>September\u00a08, 2026<\/p>\n\n<p>As of September\u00a08, 2026, SAP_SE is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>SAP Extended Passport (EPP) Processing\u00a0\u2013 KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20<\/li>\n\t<li>SAP NetWeaver (Message Server)\u00a0- versions KERNEL 9.16, 9.18, 9.19, and 9.20<\/li>\n\t<li>SAP Cloud Application Programming Model (CAP)\n\t<ul><li>prior or equal to 1.183<\/li>\n\t\t<li>prior or equal to 2.7.6<\/li>\n\t\t<li>prior or equal to 3.9.6<\/li>\n\t\t<li>prior or equal to 4.0.2<\/li>\n\t<\/ul><\/li>\n\t<li>SAP NetWeaver (SAP GUI for Java)\u00a0- version BC-FES-JAV 8.10<\/li>\n\t<li>SAP Integration Suite\n\t<ul><li>Version Cloud Integration\u00a0- Trading Partner Management V2 2.9.2,<\/li>\n\t\t<li>Version B2B Integration Factory\u00a0- Cloud Integration\u00a0- Trading Partner Management 1.10.0<\/li>\n\t<\/ul><\/li>\n\t<li>SAP NetWeaver Business Client\u00a0\u2013 versions BC-WD-CLT-BUS 8.00 and 8.10<\/li>\n\t<li>SAP NetWeaver Application Server for ABAP and ABAP Platform\u00a0\u2013 versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20<\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/september-2026.html?isu_page=1\">SAP Security Patch Day\u00a0\u2013 September 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/sap-security-advisory-september-2026-monthly-rollup-av26-894","alert_type":396,"serial_number":"AV26-894","subject":"sap","moderation_state":"published","external_url":null},{"nid":8201,"title":"Commvault security advisory (AV26-895)","uuid":"29cf1d3c-ca4f-4ba7-857b-4abab192cad3","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T18:11:59Z","date_created":"2026-09-08T17:56:55Z","summary":null,"body":["<article data-history-node-id=\"8201\" about=\"\/en\/alerts-advisories\/commvault-security-advisory-av26-895\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-895<br \/><strong>Date: <\/strong>September\u00a08, 2026<\/p>\n\n<p>As of September\u00a08, 2026, Commvault is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Commvault Cloud\n\t<ul><li>11.36.0 Prior to 11.36.123<\/li>\n\t\t<li>11.40.0 Prior to 11.40.72<\/li>\n\t\t<li>11.44.0 Prior to 11.44.20<\/li>\n\t\t<li>11.46.0 Prior to 11.46.20<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/CV_2026_07_1.html\">CV_2026_07_1: Command Center API Authentication Bypass<\/a><\/li>\n\t<li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/\">Commvault Cloud Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/commvault-security-advisory-av26-895","alert_type":396,"serial_number":"AV26-895","subject":"other","moderation_state":"published","external_url":null},{"nid":8202,"title":"Microsoft security advisory \u2013 September 2026 monthly rollup (AV26-896) \u2013 Update 1","uuid":"fc918510-7ed6-48f6-a8d8-d90043f6b762","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T19:03:11Z","date_created":"2026-09-08T19:00:53Z","summary":null,"body":["<article data-history-node-id=\"8202\" about=\"\/en\/alerts-advisories\/microsoft-security-advisory-september-2026-monthly-rollup-av26-896\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-896<br \/><strong>Date: <\/strong>September\u00a08, 2026<\/p>\n\n<p>As of September\u00a08, 2026, Microsoft is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>.NET 10.0 installed on Linux<\/li>\n\t<li>.NET 10.0 installed on Mac OS<\/li>\n\t<li>.NET 10.0 installed on Windows<\/li>\n\t<li>.NET 11.0 installed on Linux<\/li>\n\t<li>.NET 11.0 installed on Mac OS<\/li>\n\t<li>.NET 11.0 installed on Windows<\/li>\n\t<li>.NET 8.0 installed on Linux<\/li>\n\t<li>.NET 8.0 installed on Mac OS<\/li>\n\t<li>.NET 8.0 installed on Windows<\/li>\n\t<li>.NET 9.0 installed on Linux<\/li>\n\t<li>.NET 9.0 installed on Mac OS<\/li>\n\t<li>.NET 9.0 installed on Windows<\/li>\n\t<li>ASP.NET Core 10.0<\/li>\n\t<li>ASP.NET Core 11.0<\/li>\n\t<li>ASP.NET Core 8.0<\/li>\n\t<li>ASP.NET Core 9.0<\/li>\n\t<li>Azure AI Language Authoring<\/li>\n\t<li>Azure Arc SQL Server Extension<\/li>\n\t<li>Azure Cosmos DB<\/li>\n\t<li>Azure CycleCloud<\/li>\n\t<li>Azure HDInsight<\/li>\n\t<li>HEIF Image Extension<\/li>\n\t<li>HEVC Video Extensions<\/li>\n\t<li>HEVC Video Extensions for Licensed Applications<\/li>\n\t<li>HEVC Video Extensions from Device Manufacturer<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.6.2\/4.7\/4.7.1\/4.7.2<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.7.2<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.8<\/li>\n\t<li>Microsoft .NET Framework 3.5 AND 4.8.1<\/li>\n\t<li>Microsoft .NET Framework 4.6.2\/4.7\/4.7.1\/4.7.2<\/li>\n\t<li>Microsoft .NET Framework 4.8<\/li>\n\t<li>Microsoft .NET Framework 4.8.1<\/li>\n\t<li>Microsoft 365 Apps for Enterprise<\/li>\n\t<li>Microsoft Access 2016<\/li>\n\t<li>Microsoft Authentication Library (MSAL)<\/li>\n\t<li>Microsoft Authenticator for Android<\/li>\n\t<li>Microsoft Azure Active Directory B2C<\/li>\n\t<li>Microsoft Azure CLI<\/li>\n\t<li>Microsoft Copilot Studio<\/li>\n\t<li>Microsoft Discovery Studio<\/li>\n\t<li>Microsoft Dynamics 365 (on-premises)<\/li>\n\t<li>Microsoft Dynamics 365 Customer Engagement<\/li>\n\t<li>Microsoft Entra ID<\/li>\n\t<li>Microsoft Excel 2016<\/li>\n\t<li>Microsoft Exchange Server 2016<\/li>\n\t<li>Microsoft Exchange Server 2019<\/li>\n\t<li>Microsoft Exchange Server Subscription Edition RTM<\/li>\n\t<li>Microsoft Fabric<\/li>\n\t<li>Microsoft Office 2016<\/li>\n\t<li>Microsoft Office 2019<\/li>\n\t<li>Microsoft Office 365 for Mac<\/li>\n\t<li>Microsoft Office LTSC 2021<\/li>\n\t<li>Microsoft Office LTSC 2024<\/li>\n\t<li>Microsoft Office LTSC for Mac<\/li>\n\t<li>Microsoft Office for Android<\/li>\n\t<li>Microsoft Outlook 2016<\/li>\n\t<li>Microsoft Power Platform<\/li>\n\t<li>Microsoft PowerPoint 2016<\/li>\n\t<li>Microsoft Publisher 2016<\/li>\n\t<li>Microsoft SQL Server 2017<\/li>\n\t<li>Microsoft SQL Server 2019<\/li>\n\t<li>Microsoft SQL Server 2022<\/li>\n\t<li>Microsoft SQL Server 2025<\/li>\n\t<li>Microsoft SharePoint Server Subscription Edition<\/li>\n\t<li>Microsoft Teams for Android<\/li>\n\t<li>Microsoft Visual Studio 2022<\/li>\n\t<li>Microsoft Visual Studio 2026<\/li>\n\t<li>Microsoft Word 2016<\/li>\n\t<li>Microsoft.AspNetCore.OData<\/li>\n\t<li>Microsoft.Diagnostics.Runtime<\/li>\n\t<li>Office Online Server<\/li>\n\t<li>Power Automate agent for virtual desktops<\/li>\n\t<li>Power Automate for Desktop<\/li>\n\t<li>Raw Image Extension<\/li>\n\t<li>Remote Desktop client for Windows Desktop<\/li>\n\t<li>SQL Server Management Studio 22<\/li>\n\t<li>Skype for Business Server 2015<\/li>\n\t<li>Skype for Business Server 2019<\/li>\n\t<li>Skype for Business Server Subscription Edition CU1<\/li>\n\t<li>Spring Cloud Azure<\/li>\n\t<li>Visual Studio Code<\/li>\n\t<li>Web Media Extensions<\/li>\n\t<li>WebP Image Extension<\/li>\n\t<li>Windows 10<\/li>\n\t<li>Windows 11<\/li>\n\t<li>Windows Server 2012<\/li>\n\t<li>Windows Server 2016<\/li>\n\t<li>Windows Server 2019<\/li>\n\t<li>Windows Server 2022<\/li>\n\t<li>Windows Server 2025<\/li>\n<\/ul><p>Microsoft has indicated that CVE-2026-81963 and CVE-2026-85880 have been exploited.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a08, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81963 and CVE-2026-85880 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Sep\">September 2026 Security Updates<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963\">CISA KEV: CVE-2026-81963<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880\">CISA KEV: CVE-2026-85880<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/microsoft-security-advisory-september-2026-monthly-rollup-av26-896","alert_type":396,"serial_number":"AV26-896","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":8203,"title":"Ivanti security advisory (AV26-897)","uuid":"66316431-910b-4e94-99a1-e81217d5a1c0","banner":null,"lang":"en","date_modified":"2026-09-08","date_modified_ts":"2026-09-08T19:22:23Z","date_created":"2026-09-08T19:00:53Z","summary":null,"body":["<article data-history-node-id=\"8203\" about=\"\/en\/alerts-advisories\/ivanti-security-advisory-av26-897\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-897<br \/><strong>Date:<\/strong> September\u00a08, 2026<\/p>\n\n<p>As of September\u00a08, 2026, Ivanti is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Endpoint Manager Mobile\n\t<ul><li>Prior to 12.10.0.0<\/li>\n\t\t<li>Prior to 12.9.0.2<\/li>\n\t\t<li>Prior to 12.8.0.4<\/li>\n\t<\/ul><\/li>\n\t<li>Neurons for ITSM (Cloud\/SaaS)\n\t<ul><li>Prior to mo2026.2<\/li>\n\t<\/ul><\/li>\n\t<li>Neurons for ITSM On-Prem\n\t<ul><li>Prior to 2025.2 Sept 2026 Security Patch<\/li>\n\t\t<li>Prior to 2025.3 Sept 2026 Security Patch<\/li>\n\t\t<li>Prior to 2025.4 Sept 2026 Security Patch<\/li>\n\t\t<li>Prior to 2026.1 Sept 2026 Security Patch<\/li>\n\t\t<li>Prior to 2026.2<\/li>\n\t<\/ul><\/li>\n\t<li>Sentry\n\t<ul><li>Prior to R10.8.2<\/li>\n\t\t<li>Prior to R10.7.3<\/li>\n\t\t<li>Prior to R10.6.4<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US\">Security Advisory Ivanti Neurons for ITSM (Multiple CVEs)<\/a><\/li>\n\t<li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory---Ivanti-Endpoint-Manager-Mobile-CVE-2026-18851?language=en_US\">Security Advisory\u00a0- Ivanti Endpoint Manager Mobile (CVE-2026-18851)<\/a><\/li>\n\t<li><a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Sentry-CVE-2026-83527?language=en_US\">Security Advisory Ivanti Sentry (CVE-2026-83527)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ivanti.com\/blog\/september-2026-security-update\">September 2026 Security Update<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ivanti-security-advisory-av26-897","alert_type":396,"serial_number":"AV26-897","subject":"ivanti","moderation_state":"published","external_url":null},{"nid":8205,"title":"Fortinet security advisory (AV26-898)","uuid":"3329a0cc-9384-423b-86ec-c098bcb5c4ec","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T13:48:46Z","date_created":"2026-09-09T13:39:07Z","summary":null,"body":["<article data-history-node-id=\"8205\" about=\"\/en\/alerts-advisories\/fortinet-security-advisory-av26-898\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-898<br \/><strong>Date:<\/strong> September 9, 2026<\/p>\n\n<p>As of September 8, 2026, Fortinet is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>FortiOS 7.6\n\t<ul><li>Versions 7.6.1 to 7.6.6<\/li>\n\t<\/ul><\/li>\n\t<li>FortiProxy 7.6\n\t<ul><li>Versions 7.6.2 to 7.6.6<\/li>\n\t<\/ul><\/li>\n\t<li>FortiPAM Chrome Extension 8.0\n\t<ul><li>All versions<\/li>\n\t<\/ul><\/li>\n\t<li>FortiPAM Chrome Extension 7.4\n\t<ul><li>All versions<\/li>\n\t<\/ul><\/li>\n\t<li>FortiSandbox 5.0\n\t<ul><li>Versions 5.0.0 to 5.0.5<\/li>\n\t<\/ul><\/li>\n\t<li>FortiSandbox 4.4\n\t<ul><li>Versions 4.4.0 to 4.4.8<\/li>\n\t<\/ul><\/li>\n\t<li>FortiSandbox Cloud 5.0\n\t<ul><li>Versions 5.0.4 to 5.0.5<\/li>\n\t<\/ul><\/li>\n\t<li>FortiSandbox PaaS 5.0\n\t<ul><li>Versions 5.0.4 to 5.0.5<\/li>\n\t<\/ul><\/li>\n\t<li>FortiMonitorOnSight 7.2\n\t<ul><li>Versions 7.2.4 to 7.2.7<\/li>\n\t<\/ul><\/li>\n\t<li>FortiMonitorOnSight 7.2\n\t<ul><li>Versions 7.2.0 to 7.2.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortiguard.com\/psirt?filter=1&amp;severity=2&amp;severity=3&amp;severity=4&amp;severity=5&amp;version=\">Fortinet PSIRT Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortinet-security-advisory-av26-898","alert_type":396,"serial_number":"AV26-898","subject":"fortiguard","moderation_state":"published","external_url":null},{"nid":8206,"title":"Commvault security advisory (AV26-899)","uuid":"852b17b2-9432-4649-a698-d1b8e6192163","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T13:59:24Z","date_created":"2026-09-09T13:53:35Z","summary":null,"body":["<article data-history-node-id=\"8206\" about=\"\/en\/alerts-advisories\/commvault-security-advisory-av26-899\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-899<br \/><strong>Date:<\/strong> September 9, 2026<\/p>\n\n<p><strong>Commvault security advisory (AV26-899)<\/strong><\/p>\n\n<p>As of September 8, 2026, Commvault is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Commvault Cloud\n\t<ul><li>36.0 Prior to 11.36.123<\/li>\n\t\t<li>40.0 Prior to 11.40.72<\/li>\n\t\t<li>44.0 Prior to 11.44.20<\/li>\n\t\t<li>46.0 Prior to 11.46.20<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/documentation.commvault.com\/securityadvisories\/\">Commvault Cloud Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/commvault-security-advisory-av26-899","alert_type":396,"serial_number":"AV26-899","subject":"other","moderation_state":"published","external_url":null},{"nid":8207,"title":"NVIDIA security advisory (AV26-900)","uuid":"176743cc-5a38-4820-8ee8-9ec6b5f0f77b","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T15:47:38Z","date_created":"2026-09-09T15:43:11Z","summary":null,"body":["<article data-history-node-id=\"8207\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-av26-900\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-900<br \/><strong>Date:<\/strong> September 9, 2026<\/p>\n\n<p>As of September 8, 2026, <span class=\"text-uppercase\">NVIDIA<\/span> is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Triton Inference Server\n\t<ul><li>Versions 0.0 to 26.03<\/li>\n\t\t<li>Versions 0.0 to 26.06<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5875\">Security Bulletin: Triton Inference Server - September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.nvidia.com\/en-us\/security\/\">NVIDIA Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-av26-900","alert_type":396,"serial_number":"AV26-900","subject":"nvidia","moderation_state":"published","external_url":null},{"nid":8208,"title":"MISP security advisory (AV26-901)","uuid":"06cef6d5-44d2-4655-97c0-ff7c1c13ecd6","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T15:51:52Z","date_created":"2026-09-09T15:48:50Z","summary":null,"body":["<article data-history-node-id=\"8208\" about=\"\/en\/alerts-advisories\/misp-security-advisory-av26-901\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-901<br \/><strong>Date:<\/strong> September 9, 2026<\/p>\n\n<p>As of September 4, 2026, misp is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>misp\n\t<ul><li>Prior to or equal to 2.5.45<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/MISP\/MISP\/commit\/9b1363955\">Authorise the sharing group whenever one is submitted<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/misp-security-advisory-av26-901","alert_type":396,"serial_number":"AV26-901","subject":"other","moderation_state":"published","external_url":null},{"nid":8210,"title":"Check Point security advisory (AV26-902) \u2013 Update 2","uuid":"5c4d9755-f9ef-4d92-bc50-bed2d93d3c24","banner":null,"lang":"en","date_modified":"2026-09-22","date_modified_ts":"2026-09-22T20:32:13Z","date_created":"2026-09-09T19:25:36Z","summary":null,"body":["<article data-history-node-id=\"8210\" about=\"\/en\/alerts-advisories\/check-point-security-advisory-av26-902\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-902<br \/><strong>Date:<\/strong> September 9, 2026<br \/><strong>Updated:<\/strong> September 22, 2026<\/p>\n\n<p>As of September 9, 2026, Check Point is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Security Gateway\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Check Point Spark Firewall using Site to Site VPN or Remote Access VPN\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Security Management Server\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Check Point Spark Firewall\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p class=\"mrgn-bttm-lg\">Check Point has reported that CVE-2026-85102 and CVE-2026-93616 are being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 2<\/h2>\n\n<p class=\"mrgn-bttm-lg\">On September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) CVE-2026-85102 and CVE-2026-93616 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk1000117\/\">CVE-2026-85102\u00a0- Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN<\/a><\/li>\n\t<li><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk1000118\/\">CVE-2026-85103\u00a0- ASN.1 decoding heap overflow leading to a remote code execution<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/\">Check Point Security<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616\/\">Security Advisory\u00a0\u2013 Action Required\u00a0\u2013 Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85102\">CISA KEV: CVE-2026-85102<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616\">CISA KEV: CVE-2026-93616<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/check-point-security-advisory-av26-902","alert_type":396,"serial_number":"AV26-902","subject":"other","moderation_state":"published","external_url":null},{"nid":8211,"title":"ConnectWise security advisory (AV26-903) \u2013 Update 1","uuid":"6640462a-6105-4080-8ce3-546258f8cda5","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T19:25:59Z","date_created":"2026-09-09T19:42:55Z","summary":null,"body":["<article data-history-node-id=\"8211\" about=\"\/en\/alerts-advisories\/connectwise-security-advisory-av26-903\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number:<\/strong> AV26-903<br \/><strong>Date:<\/strong> September\u00a09, 2026<br \/><strong>Updated:<\/strong> September\u00a011, 2026<\/p>\n\n<p>As of September\u00a08, 2026, ConnectWise is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>ScreenConnect\n\t<ul><li>versions prior to 26.6.5<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a011, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-84869 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/2026-09-08-screenconnect-bulletin\">ScreenConnect 26.6.5 Security Patch<\/a><\/li>\n\t<li><a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\">ConnectWise\u00a0- Security Bulletins<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869\">CISA KEV: CVE-2026-84869<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/connectwise-security-advisory-av26-903","alert_type":396,"serial_number":"AV26-903","subject":"other","moderation_state":"published","external_url":null},{"nid":8212,"title":"Google security advisory (AV26-904)","uuid":"42650c1f-63a6-4875-90be-2f4d6caa1359","banner":null,"lang":"en","date_modified":"2026-09-09","date_modified_ts":"2026-09-09T19:52:18Z","date_created":"2026-09-09T19:49:08Z","summary":null,"body":["<article data-history-node-id=\"8212\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-904\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-904<br \/><strong>Date:<\/strong> September 9, 2026<\/p>\n\n<p>As of September 8, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>Prior to 153.0.8010.37<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Google is aware that an exploit for CVE-2026-87491 exists in the wild.<\/p>\n\n<p>On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87491 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_0808145027.html\">Stable Channel Update for Desktop<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87491\">CISA KEV: CVE-2026-87491<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-904","alert_type":396,"serial_number":"AV26-904","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8213,"title":"Palo Alto Networks security advisory (AV26-905)","uuid":"592b8503-cc76-4bc9-9036-62cb86b7affd","banner":null,"lang":"en","date_modified":"2026-09-10","date_modified_ts":"2026-09-10T12:10:13Z","date_created":"2026-09-10T11:53:56Z","summary":null,"body":["<article data-history-node-id=\"8213\" about=\"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-905\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-905<br \/><strong>Date: <\/strong>September\u00a010, 2026<\/p>\n\n<p>As of September\u00a010, 2026, Palo Alto Networks is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cloud NGFW\n\t<ul><li>All on AWS*, All on Azure*<\/li>\n\t<\/ul><\/li>\n\t<li>PAN-OS\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Prisma Access\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>Prisma Browser\n\t<ul><li>Prior to 151.26.5.170<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0310\">CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/PAN-SA-2026-0012\">PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026)<\/a><\/li>\n\t<li><a href=\"https:\/\/security.paloaltonetworks.com\/\">Palo Alto Networks Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/palo-alto-networks-security-advisory-av26-905","alert_type":396,"serial_number":"AV26-905","subject":"paloaltonetworks","moderation_state":"published","external_url":null},{"nid":8214,"title":"Fortra security advisory (AV26-906)","uuid":"103cd017-908c-4e22-a78b-c1750aa3a1f9","banner":null,"lang":"en","date_modified":"2026-09-10","date_modified_ts":"2026-09-10T12:38:00Z","date_created":"2026-09-10T12:20:38Z","summary":null,"body":["<article data-history-node-id=\"8214\" about=\"\/en\/alerts-advisories\/fortra-security-advisory-av26-906\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-906<br \/><strong>Date: <\/strong>September\u00a010, 2026<\/p>\n\n<p>As of September\u00a09, 2026, Fortra is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>GoAnywhere MFT Endpoint\n\t<ul><li>Prior to 7.10.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\/fi-2026-011\">Path Traversal in Fortra's GoAnywhere MFT Endpoint<\/a><\/li>\n\t<li><a href=\"https:\/\/www.fortra.com\/security\/advisories\/product-security\">Product Security Advisories | Fortra<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/fortra-security-advisory-av26-906","alert_type":396,"serial_number":"AV26-906","subject":"other","moderation_state":"published","external_url":null},{"nid":8215,"title":"[Control systems] Advantech security advisory (AV26-907)","uuid":"b478e343-73d7-4eea-92cb-6f0eba092c79","banner":null,"lang":"en","date_modified":"2026-09-10","date_modified_ts":"2026-09-10T13:50:38Z","date_created":"2026-09-10T13:40:27Z","summary":null,"body":["<article data-history-node-id=\"8215\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av26-907\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-907<br \/><strong>Date: <\/strong>September\u00a010, 2026<\/p>\n\n<p>As of September\u00a010, 2026, Advantech is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Advantech WISE-6610 industrial gateway\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advcloudfiles.advantech.com\/cms\/c904bb34-b255-41b5-badc-e850edeffd05\/Security%20Advisory%20PDF%20File\/SECURITY_ADVISORY_WISE-6610.pdf\">Vulnerabilities Identified in WISE-6610<\/a><\/li>\n\t<li><a href=\"https:\/\/www.advantech.com\/en\/security-advisory\">Security Advisories\u00a0- Advantech<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av26-907","alert_type":398,"serial_number":"AV26-907","subject":"other","moderation_state":"published","external_url":null},{"nid":8216,"title":"WebPros security advisory (AV26-908)","uuid":"562d73cc-7ad9-4f38-988f-bf8f185a4d79","banner":null,"lang":"en","date_modified":"2026-09-10","date_modified_ts":"2026-09-10T17:38:55Z","date_created":"2026-09-10T17:24:51Z","summary":null,"body":["<article data-history-node-id=\"8216\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-908\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-908<br \/><strong>Date: <\/strong>September\u00a010, 2026<\/p>\n\n<p>As of September\u00a010, 2026, WebPros is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>cPanel &amp; WebHost Manager (WHM) software\n\t<ul><li>Prior to 11.110.0.143<\/li>\n\t\t<li>Prior to 11.134.0.55<\/li>\n\t\t<li>Prior to 11.136.0.39<\/li>\n\t\t<li>Prior to 11.138.0.4<\/li>\n\t\t<li>Prior to WP2: 11.138.1.9<\/li>\n\t<\/ul><\/li>\n<\/ul><ul><li>ConfigServer Security &amp; Firewall (CSF) software\n\t<ul><li>Versions 14.00 to 16.29 (CVE-2026-65638)<\/li>\n\t\t<li>Versions 2.15 to 16.29 (CVE-2026-65639)<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026\">Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality\u00a0- September 8, 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43387915588375-Security-CVE-2026-65638-CSF-Security-Release\">Security: CVE-2026-65638 CSF Security Release<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43387923160343-Security-CVE-2026-65639-CSF-Security-Release\">Security: CVE-2026-65639 CSF Security Release<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/sections\/360007088193-Security\">cPanel Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-908","alert_type":396,"serial_number":"AV26-908","subject":"other","moderation_state":"published","external_url":null},{"nid":8217,"title":"HPE security advisory (AV26-909)","uuid":"81ca99d9-a20e-4652-a8ef-32541c7b00b6","banner":null,"lang":"en","date_modified":"2026-09-10","date_modified_ts":"2026-09-10T18:13:41Z","date_created":"2026-09-10T17:55:26Z","summary":null,"body":["<article data-history-node-id=\"8217\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-909\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-909<br \/><strong>Date: <\/strong>September\u00a010, 2026<\/p>\n\n<p>As of September\u00a09, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>ClearPass Policy Manager (CPPM)\n\t<ul><li>Prior to or equal to 6.11.14<\/li>\n\t\t<li>Prior to or equal to 6.12.8<\/li>\n\t<\/ul><\/li>\n\t<li>HPE IceWall products\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05130en_us&amp;docLocale=en_US#hpesbnw05130-rev-1-multiple-vulnerabilities-in-hpe-0 \">HPESBNW05130 rev.1\u00a0- Multiple Vulnerabilities in HPE Aruba Networking ClearPass Policy Manager (CPPM)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbmu05142en_us&amp;docLocale=en_US#hpesbmu05142-rev-1-hpe-icewall-products-remote-byp-0\">HPESBMU05142 rev.1\u00a0- HPE IceWall products, Remote Bypass of Security Restrictions<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbmu05147en_us&amp;docLocale=en_US\">HPESBMU05147 rev.1\u00a0- HPE IceWall products, Denial of Service vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-909","alert_type":396,"serial_number":"AV26-909","subject":"other","moderation_state":"published","external_url":null},{"nid":8218,"title":"AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060","uuid":"e1adc728-96cc-4ef0-9c43-feacad029b4f","banner":null,"lang":"en","date_modified":"2026-09-10","date_modified_ts":"2026-09-10T19:50:46Z","date_created":"2026-09-10T19:26:31Z","summary":null,"body":["<article data-history-node-id=\"8218\" about=\"\/en\/alerts-advisories\/al26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-020<br \/><strong>Date:<\/strong> September 10, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>Tracked as CVE-2026-67277<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> that may allow a remote attacker to obtain potentially sensitive information.<\/p>\n\n<p>Tracked as CVE-2026-86060<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>, this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88)<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> that may allow a remote attacker to escalate privileges.<\/p>\n\n<p>Tracked as CVE-2026-67276<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>, this vulnerability is an Improper Verification of Cryptographic Signature (CWE-347)<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> that may allow an attacker to forge a valid signature and open an SSH command channel as the target user without the private key.<\/p>\n\n<p>On September 10, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-67277 and CVE-2026-86060 to their Known Exploited Vulnerabilities (KEV) Database. <sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup><sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup><\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations using MikroTik RouterOS, review the MikroTik security bulletin<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and update\/upgrade the affected devices to the following vendor-supported fixed versions:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>RouterOS 6.x<\/td>\n\t\t\t<td>Versions prior to 6.49.21<\/td>\n\t\t\t<td>Version 6.49.21<\/td>\n\t\t<\/tr><tr><td>RouterOS 7.x Long-Term<\/td>\n\t\t\t<td>Versions prior to 7.23.4<\/td>\n\t\t\t<td>Version 7.23.4<\/td>\n\t\t<\/tr><tr><td>RouterOS 7.x Stable<\/td>\n\t\t\t<td>Versions prior to 7.24.2<\/td>\n\t\t\t<td>Version 7.24.2<\/td>\n\t\t<\/tr><tr><td>RouterOS Development Branch<\/td>\n\t\t\t<td>Versions prior to 7.25 beta 3<\/td>\n\t\t\t<td>Version 7.25 beta 3<\/td>\n\t\t<\/tr><\/tbody><\/table><\/div>\n\n<p>The Cyber Centre recommends following guidance provided by MikroTik<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and CERT Polska <sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup> to immediately update RouterOS, along with checking logs for possible device compromise. If the logs have a critical entry saying device has been \u201cFlagged\u201d, MikroTik recommends following the instructions provided by the status site<sup id=\"fn12-rf\"><a class=\"fn-lnk\" href=\"#fn12\"><span class=\"wb-inv\">Footnote <\/span>12<\/a><\/sup>.<\/p>\n\n<p>The Cyber Centre also recommends organizations to:<\/p>\n\n<ul><li>Determine the current version of software on each appliance.<\/li>\n\t<li>Prioritize patching for systems exposing SSH to the internet.<\/li>\n\t<li>Monitor authentication logs and network activity for indications of unauthorized access.<\/li>\n\t<li>After patching, verify that the appliance is running the updated version and review logs for unusual activity.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn13-rf\"><a class=\"fn-lnk\" href=\"#fn13\"><span class=\"wb-inv\">Footnote <\/span>13<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a> or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/mikrotik.com\/supportsec\/september-2026-vulnerability\/\">MikroTik\u00a0- September 2026 vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/mikrotik-security-advisory-av26-887\">AV26-887\u00a0\u2013 MikroTik security advisory <\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-67277\">CVE-2026-67277 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/306.html\">CWE-306: Missing Authentication for Critical Function<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-86060\">CVE-2026-86060 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/88.html\">CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-67276\">CVE-2026-67276 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/347.html\">CWE-347: Improper Verification of Cryptographic Signature<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277\">CISA KEV: CVE-2026-67277<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060\">CISA KEV: CVE-2026-86060<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"https:\/\/cert.pl\/en\/posts\/2026\/09\/vulnerabilities-in-mikrotik-routeros-actively-exploited\/\">CERT.PL: Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 12<\/dt>\n\t<dd id=\"fn12\">\n\t<p><a href=\"https:\/\/manual.mikrotik.com\/docs\/system-information-and-utilities\/device-mode\/#flagged-status\">MikroTik\u00a0- Flagged status<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn12-rf\"><span class=\"wb-inv\">Return to footnote<\/span>12<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 13<\/dt>\n\t<dd id=\"fn13\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 IT security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn13-rf\"><span class=\"wb-inv\">Return to footnote<\/span>13<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-020-vulnerabilities-impacting-mikrotik-routeros-cve-2026-67276-cve-2026-67277-cve-2026-86060","alert_type":397,"serial_number":"AL26-20","subject":"other","moderation_state":"published","external_url":null},{"nid":8219,"title":"HashiCorp security advisory (AV26-910)","uuid":"e20bd6a1-5c00-4301-873a-a654de83f222","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T13:10:01Z","date_created":"2026-09-11T12:54:06Z","summary":null,"body":["<article data-history-node-id=\"8219\" about=\"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-910\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-910<br \/><strong>Date: <\/strong>September 11, 2026<\/p>\n\n<p>As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Consul\n\t<ul><li>Prior to 2.0.4<\/li>\n\t<\/ul><\/li>\n\t<li>Consul Enterprise\n\t<ul><li>1.0 Prior to 1.21.18<\/li>\n\t\t<li>21.0 Prior to 1.21.18<\/li>\n\t\t<li>9.0 Prior to 1.21.18<\/li>\n\t<\/ul><\/li>\n\t<li>consul-template\n\t<ul><li>Prior to 0.43.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-34-consul-vulnerable-to-an-authorization-bypass-in-the-catalog-node-write-path\/77736\">HCSEC-2026-34\u00a0- Consul vulnerable to an authorization bypass in the catalog node-write path<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-38-consul-template-vulnerable-to-an-information-disclosure-issue-in-error-handling\/77740\">HCSEC-2026-38\u00a0- Consul-template vulnerable to an information disclosure issue in error handling<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/t\/hcsec-2026-37-consul-vulnerable-to-an-authorization-bypass-in-the-connect-service-mesh\/77739\">HCSEC-2026-37\u00a0- Consul vulnerable to an authorization bypass in the Connect service mesh<\/a><\/li>\n\t<li><a href=\"https:\/\/discuss.hashicorp.com\/c\/security\/52\">Security\u00a0- HashiCorp Discuss <\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hashicorp-security-advisory-av26-910","alert_type":396,"serial_number":"AV26-910","subject":"other","moderation_state":"published","external_url":null},{"nid":8220,"title":"MongoDB security advisory (AV26-911)","uuid":"b7a3e6b3-489b-4c5a-be34-adc0a8625757","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T13:38:57Z","date_created":"2026-09-11T13:17:41Z","summary":null,"body":["<article data-history-node-id=\"8220\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory-av26-911\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-911<br \/><strong>Date: <\/strong>September 11, 2026<\/p>\n\n<p>As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Java Driver\n\t<ul><li>Prior to 5.11.1<\/li>\n\t<\/ul><\/li>\n\t<li>Laravel MongoDB (PHP)\n\t<ul><li>Prior to 5.11.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/jira.mongodb.org\/browse\/PHPLARA-260\">[PHPLARA-260] Query builder: force literal equality when 3-arg where uses '=' with an array value<\/a><\/li>\n\t<li><a href=\"https:\/\/jira.mongodb.org\/browse\/JAVA-6276\">[JAVA-6276] Native heap use-after-free via cancellation racing KMS credential fetch in reactive encryption<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mongodb.com\/resources\/products\/alerts\">Alerts | MongoDB<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory-av26-911","alert_type":396,"serial_number":"AV26-911","subject":"other","moderation_state":"published","external_url":null},{"nid":8221,"title":"[Control systems] Schneider Electric security advisory (AV26-912)","uuid":"6720ea40-7215-458d-b952-a8385f906c9d","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T15:09:27Z","date_created":"2026-09-11T15:01:27Z","summary":null,"body":["<article data-history-node-id=\"8221\" about=\"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-912\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-912<br \/><strong>Date: <\/strong>September\u00a011, 2026<\/p>\n\n<p>As of September\u00a09, 2026, Schneider Electric is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>EcoStruxure\u2122 IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)\n\t<ul><li>Versions 9.1.2 and prior<\/li>\n\t<\/ul><\/li>\n\t<li>PowerLogic T300\n\t<ul><li>Versions 2.9.8-5620 and prior<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/download.se.com\/files?p_Doc_Ref=SEVD-2026-251-01&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-251-01.pdf\">Multiple Vulnerabilities on EcoStruxure\u2122 IT Data Center Expert<\/a><\/li>\n\t<li><a href=\"https:\/\/download.se.com\/files?p_Doc_Ref=SEVD-2026-251-02&amp;p_enDocType=Security+and+Safety+Notice&amp;p_File_Name=SEVD-2026-251-02.pdf\">Improper Neutralization of Special Elements used in an OS Command vulnerability on PowerLogic T300<\/a><\/li>\n\t<li><a href=\"https:\/\/www.se.com\/ww\/en\/work\/support\/cybersecurity\/security-notifications.jsp\">Schneider Electric Security Notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-schneider-electric-security-advisory-av26-912","alert_type":398,"serial_number":"AV26-912","subject":"other","moderation_state":"published","external_url":null},{"nid":8222,"title":"[Control systems] GeoVision security advisory (AV26-913)","uuid":"fe042efa-3156-4f91-b646-4b805c299170","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T15:38:24Z","date_created":"2026-09-11T15:33:40Z","summary":null,"body":["<article data-history-node-id=\"8222\" about=\"\/en\/alerts-advisories\/control-systems-geovision-security-advisory-av26-913\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-913<br \/><strong>Date: <\/strong>Septembre\u00a011, 2026<\/p>\n\n<p>As of September\u00a010, 2026, GeoVision is affected by vulnerabilities in the following product::<\/p>\n\n<ul><li>GV-LPC2011\/LPC2211\n\t<ul><li>Firmware version 1.13<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/dlcdn.geovision.com.tw\/TechNotice\/CyberSecurity\/2026\/Security_Advisory_GV-LPC2011-2211-2026-09-01.pdf\">GeoVision Security Advisory\u00a0- GV-LPC-2026-09-01<\/a><\/li>\n\t<li><a href=\"https:\/\/www.geovision.com.tw\/cyber_security.php\">Cyber Security\u00a0- GeoVision<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-geovision-security-advisory-av26-913","alert_type":398,"serial_number":"AV26-913","subject":"other","moderation_state":"published","external_url":null},{"nid":8223,"title":"[Control Systems] National Instruments security advisory (AV26-914)","uuid":"8192edea-c05c-42d9-bbdf-03e505a3d8a3","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T15:56:24Z","date_created":"2026-09-11T15:50:53Z","summary":null,"body":["<article data-history-node-id=\"8223\" about=\"\/en\/alerts-advisories\/control-systems-national-instruments-security-advisory-av26-914\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-914<br \/><strong>Date: <\/strong>September\u00a011, 2026<\/p>\n\n<p>As of September\u00a010, 2026, National Instruments is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>SystemLink\n\t<ul><li>Prior to or equal to 2026 Q3 Patch 1<\/li>\n\t<\/ul><\/li>\n\t<li>SystemLink Server\n\t<ul><li>Prior to or equal to 2026 Q3 Patch 1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.\/p&gt;<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ni.com\/en\/support\/security\/available-critical-and-security-updates-for-ni-software\/2026\/improper-access-controls-in-ni-systemlink.html\">Improper Access Controls in NI SystemLink<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ni.com\/en\/support\/security\/available-critical-and-security-updates-for-ni-software\/2026\/storage-of-sensitive-information-in-cleartext-in-ni-systemlink.html\">Storage of Sensitive Information in Cleartext in NI SystemLink<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ni.com\/en\/support\/security\/available-critical-and-security-updates-for-ni-software\/2026.html\">Available Security Updates for NI Software: 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-national-instruments-security-advisory-av26-914","alert_type":398,"serial_number":"AV26-914","subject":"other","moderation_state":"published","external_url":null},{"nid":8224,"title":"Progress security advisory (AV26-915)","uuid":"a4a8f806-3e86-47e5-82f5-7db759238b24","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T19:04:13Z","date_created":"2026-09-11T18:48:47Z","summary":null,"body":["<article data-history-node-id=\"8224\" about=\"\/en\/alerts-advisories\/progress-security-advisory-av26-915\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-915<br \/><strong>Date: <\/strong>September 11, 2026<\/p>\n\n<p>As of September 11, 2026, Progress Software is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Chef Automate\n\t<ul><li>Prior to 4.13.520<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.progress.com\/s\/article\/Critical-Security-Bulletin---August-2026---Chef-Automate-Security-Vulnerability\">Critical Security Bulletin\u00a0- August 2026 - Chef Automate Security Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.progress.com\/trust-center \">Progress Trust Center<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/progress-security-advisory-av26-915","alert_type":396,"serial_number":"AV26-915","subject":"other","moderation_state":"published","external_url":null},{"nid":8225,"title":"n8n security advisory (AV26-916)","uuid":"3c3ab881-89de-4309-9b40-65f0ed36fa45","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T19:32:09Z","date_created":"2026-09-11T19:14:59Z","summary":null,"body":["<article data-history-node-id=\"8225\" about=\"\/en\/alerts-advisories\/n8n-security-advisory-av26-916\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-916<br \/><strong>Date: <\/strong>September 11, 2026<\/p>\n\n<p>As of September 8, 2026, n8n is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>n8n\n\t<ul><li>Prior to 2.37.7<\/li>\n\t\t<li>Prior to 2.38.2<\/li>\n\t\t<li>Prior to 1.123.76<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/releases\/tag\/n8n@1.123.76\">Release n8n@1.123.76<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/releases\/tag\/n8n@2.37.7\">Release n8n@2.37.7<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/releases\/tag\/n8n@2.38.2\">Release n8n@2.38.2<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/n8n-io\/n8n\/security\">Overview\u00a0- n8n-io\/n8n\u00a0- GitHub <\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/n8n-security-advisory-av26-916","alert_type":396,"serial_number":"AV26-916","subject":"other","moderation_state":"published","external_url":null},{"nid":8227,"title":"GitLab security advisory (AV26-917)","uuid":"8d1662be-c1d1-4325-9ccc-96ee5268e7d8","banner":null,"lang":"en","date_modified":"2026-09-11","date_modified_ts":"2026-09-11T20:35:56Z","date_created":"2026-09-11T20:26:16Z","summary":null,"body":["<article data-history-node-id=\"8227\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-917\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-917<br \/><strong>Date: <\/strong>September 11, 2026<\/p>\n\n<p>As of September 10, 2026, GitLab is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>GitLab\n\t<ul><li>Prior to 19.1.8<\/li>\n\t\t<li>Prior to 19.2.6<\/li>\n\t\t<li>Prior to 19.3.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>On September\u00a011, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-3-2-released\">GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 | GitLab Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.gitlab.com\/releases\/\">GitLab release notes | GitLab Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706\">CISA KEV: CVE-2026-85706<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-917","alert_type":396,"serial_number":"AV26-917","subject":"other","moderation_state":"published","external_url":null},{"nid":8228,"title":"MongoDB security advisory (AV26-918)","uuid":"c98f2ed5-80ff-45f6-9ed9-fd558f1092dd","banner":null,"lang":"en","date_modified":"2026-09-14","date_modified_ts":"2026-09-14T14:30:08Z","date_created":"2026-09-14T14:18:47Z","summary":null,"body":["<article data-history-node-id=\"8228\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory-av26-918\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-918<br \/><strong>Date: <\/strong>September\u00a014, 2026<\/p>\n\n<p>As of September\u00a011, 2026, MongoDB is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>MongoDB Server\n\t<ul><li>Prior to 7.0.43<\/li>\n\t\t<li>Prior to 8.0.32<\/li>\n\t\t<li>Prior to 8.3.11<\/li>\n\t\t<li>Prior to 9.1.0-rc0<\/li>\n\t\t<li>Prior to 9.0.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/jira.mongodb.org\/browse\/SERVER-134063\">Shred collection validator constants during parsing<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mongodb.com\/resources\/products\/alerts\">Alerts\u00a0| MongoDB<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory-av26-918","alert_type":396,"serial_number":"AV26-918","subject":"other","moderation_state":"published","external_url":null},{"nid":8229,"title":"Samsung mobile security advisory (AV26-919)","uuid":"4acaad6a-cfdc-43b1-90d4-3dfc233d6f3b","banner":null,"lang":"en","date_modified":"2026-09-14","date_modified_ts":"2026-09-14T15:11:49Z","date_created":"2026-09-14T14:52:16Z","summary":null,"body":["<article data-history-node-id=\"8229\" about=\"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-919\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-919<br \/><strong>Date: <\/strong>September\u00a014, 2026<\/p>\n\n<p>As of September\u00a08, 2026, Samsung published a security update to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Samsung mobile devices\u00a0\u2013 versions prior to SMR-SEP-2026<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The most recent security update resolves multiple identified vulnerabilities. The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb?year=2026&amp;month=09\">Samsung Security Updates<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/samsung-mobile-security-advisory-av26-919","alert_type":396,"serial_number":"AV26-919","subject":"other","moderation_state":"published","external_url":null},{"nid":8230,"title":"Android security advisory \u2013 September 2026 monthly rollup (AV26-920) \u2013 Update 1","uuid":"fd64cf23-8782-47aa-9c3f-b08274c7f403","banner":null,"lang":"en","date_modified":"2026-09-16","date_modified_ts":"2026-09-16T17:10:06Z","date_created":"2026-09-14T17:25:25Z","summary":null,"body":["<article data-history-node-id=\"8230\" about=\"\/en\/alerts-advisories\/android-security-advisory-september-2026-monthly-rollup-av26-920\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-920<br \/><strong>Date:<\/strong> September\u00a014, 2026<br \/><strong>Updated:<\/strong> September 16, 2026<\/p>\n\n<p>As of September\u00a08, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.<\/p>\n\n<p>Open-source reporting indicates that CVE-2026-58704 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September\u00a016, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58704 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-09-01\">Android Security Bulletin\u2014September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704\">CISA KEV: CVE-2026-58704<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/android-security-advisory-september-2026-monthly-rollup-av26-920","alert_type":396,"serial_number":"AV26-920","subject":"android","moderation_state":"published","external_url":null},{"nid":8231,"title":"Cisco security advisory (AV26-921)","uuid":"5472924d-c488-4fa6-882f-3b55a7ce8ef2","banner":null,"lang":"en","date_modified":"2026-09-14","date_modified_ts":"2026-09-14T19:23:22Z","date_created":"2026-09-14T19:17:49Z","summary":null,"body":["<article data-history-node-id=\"8231\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-921\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-921<br \/><strong>Date:<\/strong> September\u00a014, 2026<\/p>\n\n<p>As of September\u00a014, 2026, Cisco is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco AsyncOS for Cisco Secure Email Gateway\n\t<ul><li>Prior to 15.5.5-014<\/li>\n\t\t<li>Prior to 16.0.4-302<\/li>\n\t\t<li>Prior to 16.5.0-780<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Secure Email Gateway\n\t<ul><li>Prior to 15.5.5-014<\/li>\n\t\t<li>Prior to 16.5.0-780<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Secure Email and Web Manager\n\t<ul><li>Prior to 15.5.5-006<\/li>\n\t\t<li>Prior to 16.5.0-429<\/li>\n\t<\/ul><\/li>\n<\/ul><p>On September\u00a014, 2026, Cisco stated that CVE-2026-76461 is being actively exploited.<\/p>\n\n<p>On September\u00a014, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-esa-inj-2bLVGmhX\">Cisco Secure Email Gateway SQL Injection Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-esa-dfCrfXkm\">Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461\">CISA KEV: CVE-2026-76461<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-921","alert_type":396,"serial_number":"AV26-921","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8232,"title":"IBM security advisory (AV26-922)","uuid":"48aa437b-43f8-4c2b-957e-16f18bd1f27f","banner":null,"lang":"en","date_modified":"2026-09-15","date_modified_ts":"2026-09-15T14:29:59Z","date_created":"2026-09-15T14:09:04Z","summary":null,"body":["<article data-history-node-id=\"8232\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-922\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-922<br \/><strong>Date: <\/strong>September 15, 2026<\/p>\n\n<p>As of September\u00a014, 2026, IBM is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Langflow OSS\n\t<ul><li>Prior to or equal to 1.10.0<\/li>\n\t\t<li>Prior to or equal to 1.10.2<\/li>\n\t\t<li>Prior to or equal to 1.11.2<\/li>\n\t\t<li>Prior to or equal to 1.11.5<\/li>\n\t<\/ul><\/li>\n\t<li>MQ\n\t<ul><li>10.0.0.0<\/li>\n\t\t<li>Prior to or equal to 9.1.0.37 LTS<\/li>\n\t\t<li>Prior to or equal to 9.2.0.43 LTS<\/li>\n\t\t<li>Prior to or equal to 9.3.0.41 LTS<\/li>\n\t\t<li>Prior to or equal to 9.3.5.1 CD<\/li>\n\t\t<li>Prior to or equal to 9.4.0.25 LTS<\/li>\n\t\t<li>Prior to or equal to 9.4.5.1 CD<\/li>\n\t<\/ul><\/li>\n\t<li>Sterling File Gateway\n\t<ul><li>Prior to or equal to 6.2.0.6_1, 6.2.1.0\u00a0- 6.2.1.2, 6.2.2.0\u00a0- 6.2.2.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7278919\">Incomplete Security Scanner Blocklist Enables Network-Based Code Execution<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7284896\">IBM MQ Java messaging is vulnerable to remote code execution (CVE-2026-13293)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7287180\">IBM Sterling File Gateway is Vulnerable to Improper Access Control (CVE-2026-19290)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-922","alert_type":396,"serial_number":"AV26-922","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8233,"title":"GNU security advisory (AV26-923)","uuid":"215cf30e-fb46-45eb-a9f6-18f1b560ed7d","banner":null,"lang":"en","date_modified":"2026-09-15","date_modified_ts":"2026-09-15T15:10:16Z","date_created":"2026-09-15T15:00:57Z","summary":null,"body":["<article data-history-node-id=\"8233\" about=\"\/en\/alerts-advisories\/gnu-security-advisory-av26-923\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-923<br \/><strong>Date: <\/strong>September\u00a015, 2026<\/p>\n\n<p>As of September\u00a015, 2026, GNU is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>libextractor\n\t<ul><li>Prior to v1.15<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/git.gnunet.org\/gnunet\/libextractor\/commit\/2781c7e9095f4ddaff4f535d69342f3903b18422.html\">libextractor<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/Haitam-lazaar\/libextractor-ole2-rce#cve-2026-91752-gnu-libextractor-stack-overflow-via-ole2\">CVE-2026-91752: GNU libextractor Stack Overflow via OLE2<\/a><\/li>\n\t<li><a href=\"https:\/\/www.gnu.org\/software\/libextractor\/\">GNU Libextractor<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gnu-security-advisory-av26-923","alert_type":396,"serial_number":"AV26-923","subject":"other","moderation_state":"published","external_url":null},{"nid":8235,"title":"Docker security advisory (AV26-925)","uuid":"d070c93a-21c9-4c13-822a-4da479743a23","banner":null,"lang":"en","date_modified":"2026-09-15","date_modified_ts":"2026-09-15T18:59:34Z","date_created":"2026-09-15T18:48:28Z","summary":null,"body":["<article data-history-node-id=\"8235\" about=\"\/en\/alerts-advisories\/docker-security-advisory-av26-925\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-925<br \/><strong>Date:<\/strong> September 15, 2026<\/p>\n\n<p>As of September 15, 2026, Docker is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Docker Sandboxes\n\t<ul><li>Prior to 0.43.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/docker\/sbx-releases\/releases\/#release-v0.43.0\">Docker sbx-releases<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.docker.com\/security\/security-announcements\/\">Docker security announcements<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/docker-security-advisory-av26-925","alert_type":396,"serial_number":"AV26-925","subject":"other","moderation_state":"published","external_url":null},{"nid":8234,"title":"Mozilla security advisory (AV26-924)","uuid":"78a8dce1-c3a9-4076-92b3-c1ed290d5900","banner":null,"lang":"en","date_modified":"2026-09-15","date_modified_ts":"2026-09-15T18:54:45Z","date_created":"2026-09-15T18:48:29Z","summary":null,"body":["<article data-history-node-id=\"8234\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-924\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-924<br \/><strong>Date:<\/strong> September 15, 2026<\/p>\n\n<p>As of September 15, 2026, Mozilla is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\n\t<ul><li>Versions prior to 115.41<\/li>\n\t\t<li>Versions prior to 140.16<\/li>\n\t\t<li>Versions prior to 153.3<\/li>\n\t<\/ul><\/li>\n\t<li>Firefox\n\t<ul><li>Versions prior to 156<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-90\/\">Security Vulnerabilities fixed in Firefox 156\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-91\/\">Security Vulnerabilities fixed in Firefox ESR 115.41\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-92\/\">Security Vulnerabilities fixed in Firefox ESR 140.16\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-93\/\">Security Vulnerabilities fixed in Firefox ESR 153.3\u00a0\u2014 Mozilla<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Foundation Security Advisories\u00a0\u2014 Mozilla<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-924","alert_type":396,"serial_number":"AV26-924","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":8236,"title":"Google security advisory (AV26-926)","uuid":"af4dcf82-873a-46ab-a2e4-078697c10b74","banner":null,"lang":"en","date_modified":"2026-09-16","date_modified_ts":"2026-09-16T17:13:25Z","date_created":"2026-09-16T15:44:20Z","summary":null,"body":["<article data-history-node-id=\"8236\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-926\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-926<br \/><strong>Date:<\/strong> September 16, 2026<\/p>\n\n<p>As of September 15, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>Prior to 153.0.8010.48<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_0541751186.html\">Stable Channel Update for Desktop<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-926","alert_type":396,"serial_number":"AV26-926","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8237,"title":"[Control Systems] Phoenix Contact security advisory (AV26-927)","uuid":"c3ea68db-ec96-46c8-9531-e27d9dd3c8b5","banner":null,"lang":"en","date_modified":"2026-09-16","date_modified_ts":"2026-09-16T18:00:17Z","date_created":"2026-09-16T17:19:00Z","summary":null,"body":["<article data-history-node-id=\"8237\" about=\"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-927\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-927<br \/><strong>Date: <\/strong>September\u00a016, 2026<\/p>\n\n<p>As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>ICE2-8IOL-G65L-V1D\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE2-8IOL-K45P-RJ45\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE2-8IOL-K45S-RJ45\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE2-8IOL1-G65L-V1D\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE3-8IOL-G65L-V1D\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE3-8IOL-G65L-V1D-Y\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE3-8IOL-K45P-RJ45\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE3-8IOL-K45S-RJ45\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>ICE3-8IOL1-G65L-V1D\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>IOL MA8 EIP DI8\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>IOL MA8 PN DI8\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>YL212CEI8M1IO\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>YL212CPN8M1IO\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>YN115CEI8RPIO\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n\t<li>YN115CPN8RPIO\n\t<ul><li>Prior to 1.7.4<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/certvde.com\/en\/advisories\/VDE-2026-014\/\">Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/certvde.com\/en\/advisories\/VDE-2026-027\/\">Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices<\/a><\/li>\n\t<li><a href=\"https:\/\/certvde.com\/en\/advisories\/VDE-2026-028\/\">Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.certvde.com\/en\/advisories\/\">Phoenix Contact Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-phoenix-contact-security-advisory-av26-927","alert_type":398,"serial_number":"AV26-927","subject":"other","moderation_state":"published","external_url":null},{"nid":8238,"title":"HPE security advisory (AV26-928)","uuid":"89c26241-857d-4714-922f-24d0ca8f60f7","banner":null,"lang":"en","date_modified":"2026-09-16","date_modified_ts":"2026-09-16T18:35:21Z","date_created":"2026-09-16T18:12:06Z","summary":null,"body":["<article data-history-node-id=\"8238\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-928\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-928<br \/><strong>Date: <\/strong>September\u00a016, 2026<\/p>\n\n<p>As of September 15, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>HPE Networking EdgeConnect SD-WAN Gateways\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>HPE Networking EdgeConnect SD-WAN Orchestrator\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05135en_us&amp;docLocale=en_US#hpesbnw05135-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW05135 rev.1\u00a0- Multiple Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways &amp; Orchestrator<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-928","alert_type":396,"serial_number":"AV26-928","subject":"hpe","moderation_state":"published","external_url":null},{"nid":8239,"title":"Oracle Corporation security advisory (AV26-929)","uuid":"ab4960b9-8718-45c7-8c92-61764b171816","banner":null,"lang":"en","date_modified":"2026-09-16","date_modified_ts":"2026-09-16T19:29:43Z","date_created":"2026-09-16T18:48:29Z","summary":null,"body":["<article data-history-node-id=\"8239\" about=\"\/en\/alerts-advisories\/oracle-corporation-security-advisory-av26-929\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-929<br \/><strong>Date: <\/strong>September 16, 2026<\/p>\n\n<p>As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Helidon<\/li>\n\t<li>Oracle Access Manager<\/li>\n\t<li>Oracle Agile Engineering Data Management<\/li>\n\t<li>Oracle Agile PLM<\/li>\n\t<li>Oracle Agile PLM MCAD Connector<\/li>\n\t<li>Oracle Application Testing Suite<\/li>\n\t<li>Oracle Autonomous Health Framework<\/li>\n\t<li>Oracle Banking Branch<\/li>\n\t<li>Oracle Banking Corporate Lending<\/li>\n\t<li>Oracle Banking Corporate Lending Process Management<\/li>\n\t<li>Oracle Banking Origination<\/li>\n\t<li>Oracle Banking Treasury Management<\/li>\n\t<li>Oracle BI Publisher<\/li>\n\t<li>Oracle Business Intelligence Enterprise Edition<\/li>\n\t<li>Oracle Coherence<\/li>\n\t<li>Oracle Commerce Guided Search \/ Oracle Commerce Experience Manager<\/li>\n\t<li>Oracle Communications Cloud Native Core Security Edge Protection Proxy<\/li>\n\t<li>Oracle Communications MetaSolv Solution Module\u00a0- ASR<\/li>\n\t<li>Oracle Communications Operations Monitor<\/li>\n\t<li>Oracle Communications Service Catalog and Design<\/li>\n\t<li>Oracle Communications Unified Assurance<\/li>\n\t<li>Oracle Data Integrator<\/li>\n\t<li>Oracle Database Server<\/li>\n\t<li>Oracle E-Business Suite<\/li>\n\t<li>Oracle Enterprise Manager Base Platform<\/li>\n\t<li>Oracle Enterprise Manager for Fusion Middleware<\/li>\n\t<li>Oracle Enterprise Manager for Oracle Database<\/li>\n\t<li>Oracle Forms<\/li>\n\t<li>Oracle Fusion Middleware Control<\/li>\n\t<li>Oracle GraalVM Enterprise Edition<\/li>\n\t<li>Oracle GraalVM for JDK 17<\/li>\n\t<li>Oracle GraalVM for JDK 21<\/li>\n\t<li>Oracle Hyperion Data Relationship Management<\/li>\n\t<li>Oracle Hyperion Financial Management<\/li>\n\t<li>Oracle Identity Manager<\/li>\n\t<li>Oracle Identity Manager Connector<\/li>\n\t<li>Oracle Internet Directory<\/li>\n\t<li>Oracle Jdeveloper<\/li>\n\t<li>Oracle Managed File Transfer<\/li>\n\t<li>Oracle Middleware Common Libraries and Tools<\/li>\n\t<li>Oracle Platform Security for Java<\/li>\n\t<li>Oracle Product Lifecycle Analytics<\/li>\n\t<li>Oracle Utilities Network Management System<\/li>\n\t<li>Oracle VM VirtualBox<\/li>\n\t<li>Oracle Web Services Manager<\/li>\n\t<li>Oracle WebCenter Content<\/li>\n\t<li>Oracle WebCenter Enterprise Capture<\/li>\n\t<li>Oracle WebCenter Portal<\/li>\n\t<li>Oracle WebCenter Sites<\/li>\n\t<li>Oracle WebLogic Server<\/li>\n\t<li>PeopleSoft Enterprise CC Common Application Objects<\/li>\n\t<li>PeopleSoft Enterprise PeopleTools<\/li>\n\t<li>PeopleSoft Enterprise PRTL Interaction Hub<\/li>\n\t<li>Service Delivery Platform<\/li>\n\t<li>Siebel Applications<\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.oracle.com\/security-alerts\/cspusep2026.html\">Oracle Critical Security Patch Update Advisory\u00a0- September 2026<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/oracle-corporation-security-advisory-av26-929","alert_type":396,"serial_number":"AV26-929","subject":"oracle","moderation_state":"published","external_url":null},{"nid":8240,"title":"Apple security advisory (AV26-930)","uuid":"b62422ec-2298-421b-830f-bc02c9138597","banner":null,"lang":"en","date_modified":"2026-09-16","date_modified_ts":"2026-09-16T19:42:16Z","date_created":"2026-09-16T18:49:31Z","summary":null,"body":["<article data-history-node-id=\"8240\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-930\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-930<br \/><strong>Date:<\/strong> September 16, 2026<\/p>\n\n<p>As of September\u00a014, 2026, Apple is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\n\t<ul><li>Prior to 27<\/li>\n\t\t<li>Prior to 26.7<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Golden Gate\n\t<ul><li>Prior to 27<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Tahoe\n\t<ul><li>Prior to 26.7<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Sequoia\n\t<ul><li>Prior to 15.8<\/li>\n\t<\/ul><\/li>\n\t<li>tvOS\n\t<ul><li>Prior to 27<\/li>\n\t<\/ul><\/li>\n\t<li>watchOS\n\t<ul><li>Prior to 27<\/li>\n\t<\/ul><\/li>\n\t<li>visionOS 27\n\t<ul><li>Prior to 27<\/li>\n\t<\/ul><\/li>\n\t<li>Safari\n\t<ul><li>Prior to 27<\/li>\n\t<\/ul><\/li>\n\t<li>Xcode\n\t<ul><li>Prior to 27<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases\u00a0- Apple Support<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-930","alert_type":396,"serial_number":"AV26-930","subject":"apple","moderation_state":"published","external_url":null},{"nid":8241,"title":"ISC BIND security advisory (AV26-931)","uuid":"72fef3af-a3f5-440c-bf99-55fec2b1e313","banner":null,"lang":"en","date_modified":"2026-09-16","date_modified_ts":"2026-09-16T19:43:29Z","date_created":"2026-09-16T19:08:20Z","summary":null,"body":["<article data-history-node-id=\"8241\" about=\"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-931\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-931<br \/><strong>Date:<\/strong> September 16, 2026<\/p>\n\n<p>As of September\u00a016, 2026, ISC is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>ISC BIND 9\n\t<ul><li>Prior to or equal to 9.18.50<\/li>\n\t\t<li>Prior to or equal to 9.18.50-S1<\/li>\n\t\t<li>Prior to or equal to 9.20.27<\/li>\n\t\t<li>Prior to or equal to 9.20.27-S1<\/li>\n\t\t<li>Prior to or equal to 9.21.25<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\">BIND 9 Software Vulnerability Matrix<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/isc-bind-security-advisory-av26-931","alert_type":396,"serial_number":"AV26-931","subject":"other","moderation_state":"published","external_url":null},{"nid":8242,"title":"Cisco security advisory (AV26-932)","uuid":"42ce3ee9-0401-40eb-9a45-19423ff6511b","banner":null,"lang":"en","date_modified":"2026-09-17","date_modified_ts":"2026-09-17T15:34:44Z","date_created":"2026-09-17T15:08:15Z","summary":null,"body":["<article data-history-node-id=\"8242\" about=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-932\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-932<br \/><strong>Date: <\/strong>September\u00a017, 2026<\/p>\n\n<p>As of September 16, 2026, Cisco is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cisco Secure Firewall Threat Defense (FTD) Software\n\t<ul><li>Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Secure Firewall Management Center (FMC) Software\n\t<ul><li>Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Identity Services Engine (ISE) Software\n\t<ul><li>Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco ISE Passive Identity Connector (ISE-PIC) Software\n\t<ul><li>Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Nexus Dashboard\n\t<ul><li>Prior to 4.3.1.175<\/li>\n\t<\/ul><\/li>\n\t<li>Cisco Secure Firewall Adaptive Security Appliance (ASA) Software\n\t<ul><li>Prior to 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47 and 9.24.1.26<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">On September 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ISE-ABP-VNSW7Tn5\">Cisco Identity Services Engine Authentication Bypass Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-ise-XU5EwX5T\">Cisco Identity Services Engine Hardening Release: September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-asaftdfmc-uvpPROhN\">Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/publicationListing.x\">Cisco Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460\">CISA KEV: CVE-2026-76460<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/cisco-security-advisory-av26-932","alert_type":396,"serial_number":"AV26-932","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8243,"title":"AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460","uuid":"a189caa2-6c3e-4694-b564-3a587b333e60","banner":null,"lang":"en","date_modified":"2026-09-17","date_modified_ts":"2026-09-17T17:32:01Z","date_created":"2026-09-17T15:12:18Z","summary":null,"body":["<article data-history-node-id=\"8243\" about=\"\/en\/alerts-advisories\/al26-021-vulnerabilities-impacting-cisco-identity-services-engine-ise-cisco-ise-passive-identity-connector-ise-pic-cve-2026-20192-cve-2026-76423-cve-2026-76460\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-021<br \/><strong>Date:<\/strong> September\u00a017, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of multiple vulnerabilities impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/p>\n\n<p>Successful exploitation could allow unauthenticated attackers to bypass authentication controls, gain administrative access, access or modify sensitive data, and potentially compromise affected systems.<\/p>\n\n<p>In response to the vendor advisory released on September 16, 2026, the Cyber Centre released AV26-932 on September 17, 2026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>.<\/p>\n\n<p>Tracked as CVE-2026-20192<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is an Improper Access Control vulnerability (CWE-284)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup> that may allow an unauthenticated attacker to bypass security controls, access sensitive information, modify system configurations, and impact system availability.<\/p>\n\n<p>Tracked as CVE-2026-76423<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>, this vulnerability is an Authentication Bypass by Spoofing vulnerability (CWE-290)<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> that may enable the attacker to read and modify ISE configuration and identity data with administrative privileges.<\/p>\n\n<p>Tracked as CVE-2026-76460<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>, this vulnerability is an Incorrect Use of Privileged APIs vulnerability (CWE-648)<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> that may allow an attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has confirmed active exploitation of this vulnerability.<\/p>\n\n<p>On September 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026\u201376460 to their Known Exploited Vulnerabilities (KEV) Database<sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations running Cisco ISE and ISE-PIC upgrade to the vendor-supported fixed software versions identified below.<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected releases<\/th>\n\t\t\t<th scope=\"col\">Fixed releases<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Cisco Identity Services Engine (ISE) or ISE-PIC<\/td>\n\t\t\t<td>releases prior to 3.0<\/td>\n\t\t\t<td>Migrate to a fixed release<\/td>\n\t\t<\/tr><tr><td>Cisco Identity Services Engine (ISE) or ISE-PIC<\/td>\n\t\t\t<td>release 3.1<\/td>\n\t\t\t<td>3.1 Patch 12<\/td>\n\t\t<\/tr><tr><td>Cisco Identity Services Engine (ISE) or ISE-PIC<\/td>\n\t\t\t<td>release 3.2<\/td>\n\t\t\t<td>3.2 Patch 11<\/td>\n\t\t<\/tr><tr><td>Cisco Identity Services Engine (ISE) or ISE-PIC<\/td>\n\t\t\t<td>release 3.3<\/td>\n\t\t\t<td>3.3 Patch 12<\/td>\n\t\t<\/tr><tr><td>Cisco Identity Services Engine (ISE) or ISE-PIC<\/td>\n\t\t\t<td>release 3.4<\/td>\n\t\t\t<td>3.4 Patch 7<\/td>\n\t\t<\/tr><tr><td>Cisco Identity Services Engine (ISE) or ISE-PIC<\/td>\n\t\t\t<td>release 3.5<\/td>\n\t\t\t<td>3.5 Patch 4<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>The Cyber Centre also recommends organizations to:<\/p>\n\n<ul><li>Apply vendor-provided security updates immediately. Cisco has released fixes for all three vulnerabilities.<\/li>\n\t<li>Prioritize remediation of CVE-2026-76460 due to confirmed in-the-wild exploitation.<\/li>\n\t<li>Review access logs for indicators of compromise (IoC), particularly suspicious usernames and unexpected API activity.<\/li>\n\t<li>Restrict access to management interfaces through access control lists (ACL), network segmentation, and trusted administration networks where feasible.<\/li>\n\t<li>If compromise is suspected, re-image affected nodes and restore from known-good backups, as attackers may obtain elevated privileges and remove evidence of exploitation.<\/li>\n\t<li>Monitor firewall, network, and authentication logs for anomalous activity associated with affected systems.<\/li>\n<\/ul><p>Note: Organizations operating Common Criteria<sup id=\"fn10-rf\"><a class=\"fn-lnk\" href=\"#fn10\"><span class=\"wb-inv\">Footnote <\/span>10<\/a><\/sup> evaluated configurations should review Cisco's advisory and apply the recommended updates in accordance with their change management and certification requirements.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions<sup id=\"fn11-rf\"><a class=\"fn-lnk\" href=\"#fn11\"><span class=\"wb-inv\">Footnote <\/span>11<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-hardening-ise-XU5EwX5T\">Cisco Identity Services Engine Hardening Release: September 2026<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/cisco-security-advisory-av26-932 \">AV26-932\u00a0\u2013 Cisco security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-20192\">CVE-2026-20192 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/284.html\">CWE-284: Improper Access Control<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-76423\">CVE-2026-76423 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/290.html\">CWE-290: Authentication Bypass by Spoofing<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-76460\">CVE-2026-76460 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/648.html\">CWE-648: Incorrect Use of Privileged APIs<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460\">CISA KEV: CVE-2026-76460<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 10<\/dt>\n\t<dd id=\"fn10\">\n\t<p><a href=\"\/en\/tools-services\/common-criteria\">Common Criteria\u00a0\u2013 Canadian Centre for Cyber Security<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn10-rf\"><span class=\"wb-inv\">Return to footnote<\/span>10<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 11<\/dt>\n\t<dd id=\"fn11\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn11-rf\"><span class=\"wb-inv\">Return to footnote<\/span>11<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-021-vulnerabilities-impacting-cisco-identity-services-engine-ise-cisco-ise-passive-identity-connector-ise-pic-cve-2026-20192-cve-2026-76423-cve-2026-76460","alert_type":397,"serial_number":"AL26-021","subject":"cisco","moderation_state":"published","external_url":null},{"nid":8244,"title":"Check Point security advisory (AV26-933)","uuid":"f93af40e-7229-47c3-9b34-2e54fd7466b1","banner":null,"lang":"en","date_modified":"2026-09-17","date_modified_ts":"2026-09-17T18:21:48Z","date_created":"2026-09-17T18:00:15Z","summary":null,"body":["<article data-history-node-id=\"8244\" about=\"\/en\/alerts-advisories\/check-point-security-advisory-av26-933\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-933<br \/><strong>Date: <\/strong>September\u00a017, 2026<\/p>\n\n<p>As of September 16, 2026, Check Point is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server\n\t<ul><li>R81.20 with Jumbo Hotfix Take 166 and prior<\/li>\n\t\t<li>R82 with Jumbo Hotfix Take 126 and prior<\/li>\n\t\t<li>R82.10 with Jumbo Hotfix Take 44 and prior<\/li>\n\t\t<li>R82.20<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk1000155\">Check Point\u00a0- sk1000155\u00a0- CVE-2026-91843\u00a0- Stack overflow in login process to the Security Management and Log Servers<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.checkpoint.com\/security\/\">Check Point Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/check-point-security-advisory-av26-933","alert_type":396,"serial_number":"AV26-933","subject":"other","moderation_state":"published","external_url":null},{"nid":8245,"title":"Dell security advisory (AV26-934)","uuid":"a8a9d9c3-475e-42ca-b61c-841d26dafbe7","banner":null,"lang":"en","date_modified":"2026-09-17","date_modified_ts":"2026-09-17T19:46:03Z","date_created":"2026-09-17T19:07:27Z","summary":null,"body":["<article data-history-node-id=\"8245\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-934\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-934<br \/><strong>Date: <\/strong>September 17, 2026<\/p>\n\n<p>As of September 17, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Networking OS10\n\t<ul><li>Prior to 10.6.1.3<\/li>\n\t<\/ul><\/li>\n\t<li>Dell OpenManage Server Administrator (OMSA)\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n\t<li>Elastic Cloud Storage (ECS)\n\t<ul><li>Prior to 4.4.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>ObjectScale\n\t<ul><li>Prior to 4.4.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Update Package (DUP) Framework\n\t<ul><li>Prior to 26.07.03<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Wyse Management Suite\n\t<ul><li>Prior to 2605.0.3.683<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Repository Manager (DRM)\n\t<ul><li>Prior to 3.5.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000507473\/dsa-2026-343-security-update-for-dell-networking-os10-vulnerabilities\">DSA-2026-343: Security Update for Dell Networking OS10 Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000506586\/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv\">DSA-2026-403: Security Update for Dell OpenManage Server Administrator (OMSA) Network Access Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-in\/000505935\/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities\">DSA-2026-393: Security update for Dell ObjectScale Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000509455\/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities\">DSA-2026-417: Security update for Dell Update Package (DUP) Framework Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000502744\/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities\">DSA-2026-387: Security Update for Dell Wyse Management Suite (WMS) for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000509459\/dsa-2026-419-security-update-for-dell-repository-manager-drm-vulnerability\">DSA-2026-419: Security Update for Dell Repository Manager (DRM) Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-934","alert_type":396,"serial_number":"AV26-934","subject":"dell","moderation_state":"published","external_url":null},{"nid":8246,"title":"Tanium security advisory (AV26-935)","uuid":"c00715fa-a124-4a06-9e17-4c1a6c2b983a","banner":null,"lang":"en","date_modified":"2026-09-17","date_modified_ts":"2026-09-17T19:52:03Z","date_created":"2026-09-17T19:45:22Z","summary":null,"body":["<article data-history-node-id=\"8246\" about=\"\/en\/alerts-advisories\/tanium-security-advisory-av26-935\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-935<br \/><strong>Date: <\/strong>September 17, 2026<\/p>\n\n<p>As of September 16, 2026, Tanium is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Threat Response\n\t<ul><li>Prior to Update 15 (v4.12.317)<\/li>\n\t\t<li>Prior to Update 8 (v4.17.289)<\/li>\n\t\t<li>Prior to Update 25 (v4.9.447)<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/security.tanium.com\/TAN-2026-047\">TAN-2026-047\u00a0- Tanium Security Advisories <\/a><\/li>\n\t<li><a href=\"https:\/\/security.tanium.com\/\">All Advisories\u00a0- Tanium Security Advisories <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/tanium-security-advisory-av26-935","alert_type":396,"serial_number":"AV26-935","subject":"other","moderation_state":"published","external_url":null},{"nid":8248,"title":"Grafana security advisory (AV26-936)","uuid":"79d04bcb-19e0-431b-acc5-bdd0276a2938","banner":null,"lang":"en","date_modified":"2026-09-18","date_modified_ts":"2026-09-18T13:46:15Z","date_created":"2026-09-18T13:33:15Z","summary":null,"body":["<article data-history-node-id=\"8248\" about=\"\/en\/alerts-advisories\/grafana-security-advisory-av26-936\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-936<br \/><strong>Date: <\/strong>September 18, 2026<\/p>\n\n<p>As of September 17, 2026, Grafana is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Grafana OSS\n\t<ul><li>Version 12.3.0 to 12.4.10<\/li>\n\t\t<li>Version 13.0.0 to 13.08<\/li>\n\t\t<li>Version 13.1.0 to 13.1.5<\/li>\n\t\t<li>Version 13.2.0 to 13.2.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/grafana.com\/security\/security-advisories\/cve-2026-76154\/\">Geomap MapLibre XSS<\/a><\/li>\n\t<li><a href=\"https:\/\/grafana.com\/security\/security-advisories\/\">Grafana Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/grafana-security-advisory-av26-936","alert_type":396,"serial_number":"AV26-936","subject":"other","moderation_state":"published","external_url":null},{"nid":8249,"title":"[Control systems] Advantech security advisory (AV26-937)","uuid":"bb0ca06e-8ecf-49cb-9923-1b83a5e53b99","banner":null,"lang":"en","date_modified":"2026-09-18","date_modified_ts":"2026-09-18T14:09:49Z","date_created":"2026-09-18T13:58:11Z","summary":null,"body":["<article data-history-node-id=\"8249\" about=\"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av26-937\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-937<br \/><strong>Date: <\/strong>September 18, 2026<\/p>\n\n<p>As of September\u00a04, 2026, Advantech is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>EKI-1242EIMS\n\t<ul><li>Prior to or equal to V2.00.01<\/li>\n\t<\/ul><\/li>\n\t<li>EKI-1242IEIMS\n\t<ul><li>Prior to or equal to V2.00.01<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/advcloudfiles.advantech.com\/cms\/5dafee28-ad53-4d07-a328-7896fcc24b6e\/Security%20Advisory%20PDF%20File\/SECURITY-ADVISORY----EKI-1242IEIMS-updated-20260904.pdf\">Vulnerabilities Identified in EKI-1242EIMS\/EKI-1242IEIMS (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.advantech.com\/en\/security-advisory\">Advantech Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-advantech-security-advisory-av26-937","alert_type":398,"serial_number":"AV26-937","subject":"other","moderation_state":"published","external_url":null},{"nid":8250,"title":"[Control Systems] Moxa security advisory (AV26-938)","uuid":"6082a9b5-94f5-49fc-be8c-2538e04d5211","banner":null,"lang":"en","date_modified":"2026-09-18","date_modified_ts":"2026-09-18T15:24:19Z","date_created":"2026-09-18T15:16:07Z","summary":null,"body":["<article data-history-node-id=\"8250\" about=\"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-938\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-938<br \/><strong>Date: <\/strong>September 18, 2026<\/p>\n\n<p>As of September\u00a018, 2026, Moxa is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>TN-4500B Series\n\t<ul><li>Prior to or equal to v2.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.moxa.com\/en\/support\/product-support\/security-advisory\/mpsa-252620-cve-2026-15579-out-of-bounds-write-vulnerability-in-ethernet-switch\">CVE-2026-15579: Out-of-bounds Write Vulnerability in Ethernet Switch<\/a><\/li>\n\t<li><a href=\"https:\/\/www.moxa.com\/en\/rss\/moxa-security-advisory\">Moxa Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-moxa-security-advisory-av26-938","alert_type":398,"serial_number":"AV26-938","subject":"other","moderation_state":"published","external_url":null},{"nid":8251,"title":"Google security advisory (AV26-939)","uuid":"b7613929-a6dc-4c19-8c81-40c0c9a9c547","banner":null,"lang":"en","date_modified":"2026-09-18","date_modified_ts":"2026-09-18T15:40:56Z","date_created":"2026-09-18T15:37:08Z","summary":null,"body":["<article data-history-node-id=\"8251\" about=\"\/en\/alerts-advisories\/google-security-advisory-av26-939\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-939<br \/><strong>Date: <\/strong>September 18, 2026<\/p>\n\n<p>As of September 17, 2026, Google is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Chrome\n\t<ul><li>Prior to 153.0.8010.53<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_0194356994.html\">Stable Channel Update for Desktop<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-security-advisory-av26-939","alert_type":396,"serial_number":"AV26-939","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8252,"title":"Arista Networks security advisory (AV26-940)","uuid":"c923a4e8-e618-40dc-aca7-aab2f5f14c0a","banner":null,"lang":"en","date_modified":"2026-09-18","date_modified_ts":"2026-09-18T17:29:31Z","date_created":"2026-09-18T17:09:13Z","summary":null,"body":["<article data-history-node-id=\"8252\" about=\"\/en\/alerts-advisories\/arista-networks-security-advisory-av26-940\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-940<br \/><strong>Date: <\/strong>September 18, 2026<\/p>\n\n<p>As of September 9, 2026, Arista Networks is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>EOS\n\t<ul><li>Multiple versions and platforms<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\/security-advisory\/24730-security-advisory-0174\">Security Advisory 0174<\/a><\/li>\n\t<li><a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\">Arista Networks Advisories &amp; Notices<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/arista-networks-security-advisory-av26-940","alert_type":396,"serial_number":"AV26-940","subject":"other","moderation_state":"published","external_url":null},{"nid":8253,"title":"SolarWinds security advisory (AV26-941)","uuid":"18351136-78bc-420a-8629-44a71e1cc671","banner":null,"lang":"en","date_modified":"2026-09-18","date_modified_ts":"2026-09-18T17:40:52Z","date_created":"2026-09-18T17:35:20Z","summary":null,"body":["<article data-history-node-id=\"8253\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-941\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-941<br \/><strong>Date: <\/strong>September 18, 2026<\/p>\n\n<p>As of September 17, 2026, SolarWinds is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>SolarWinds Access Rights Manager\n\t<ul><li>Prior to 2026.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2026-28326\">SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28326)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-941","alert_type":396,"serial_number":"AV26-941","subject":"other","moderation_state":"published","external_url":null},{"nid":8254,"title":"[Control systems] ABB security advisory (AV26-942)","uuid":"af65ed35-d4de-4c6a-a41e-d23d171eafd5","banner":null,"lang":"en","date_modified":"2026-09-18","date_modified_ts":"2026-09-18T17:52:31Z","date_created":"2026-09-18T17:47:11Z","summary":null,"body":["<article data-history-node-id=\"8254\" about=\"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-942\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-942<br \/><strong>Date: <\/strong>September 18, 2026<\/p>\n\n<p>As of September 18, 2026, ABB published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Freelance Controller\n\t<ul><li>Multiple versions and models<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/search.abb.com\/library\/Download.aspx?DocumentID=7PAA010706&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">Freelance SECURITY\u00a0- Missing Length Check CVE ID: CVE-2023-5778<\/a><\/li>\n\t<li><a href=\"https:\/\/global.abb\/group\/en\/technology\/cyber-security\/alerts-and-notifications\">ABB Cyber security alerts and notifications<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/control-systems-abb-security-advisory-av26-942","alert_type":398,"serial_number":"AV26-942","subject":"abb","moderation_state":"published","external_url":null},{"nid":8255,"title":"IBM security advisory (AV26-943)","uuid":"46ba9a26-04bd-4972-a091-8bf87bd60e26","banner":null,"lang":"en","date_modified":"2026-09-21","date_modified_ts":"2026-09-21T14:36:37Z","date_created":"2026-09-21T14:22:12Z","summary":null,"body":["<article data-history-node-id=\"8255\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-943\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-943<br \/><strong>Date: <\/strong>September 21, 2026<\/p>\n\n<p>As of September 18, 2026, IBM is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>CICS TX Advanced\n\t<ul><li>Version 10.1<\/li>\n\t<\/ul><\/li>\n\t<li>Guardium Data Protection\n\t<ul><li>Version 12.2<\/li>\n\t<\/ul><\/li>\n\t<li>IBM MQ\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>IBM MQ for HPE NonStop\n\t<ul><li>Versions 8.1.0 to 8.1.0.40<\/li>\n\t<\/ul><\/li>\n\t<li>Sterling File Gateway\n\t<ul><li>Prior to or equal to 6.2.0.6_1, 6.2.1.0 to 6.2.1.2 and 6.2.2.0 to 6.2.2.1<\/li>\n\t<\/ul><\/li>\n\t<li>WebSphere Application Server\n\t<ul><li>Versions 8.5 and 9.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM i\n\t<ul><li>Versions 7.3, 7.4, 7.5 and 7.6<\/li>\n\t<\/ul><\/li>\n\t<li>spectrum-lsf IBM Platform RTM\n\t<ul><li>Versions 10.2.0.15 and 10.2.0.16<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-943","alert_type":396,"serial_number":"AV26-943","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8256,"title":"Exim security advisory (AV26-944)","uuid":"d6942918-53ed-4dd9-95e3-03c9ca46926b","banner":null,"lang":"en","date_modified":"2026-09-21","date_modified_ts":"2026-09-21T14:51:36Z","date_created":"2026-09-21T14:44:35Z","summary":null,"body":["<article data-history-node-id=\"8256\" about=\"\/en\/alerts-advisories\/exim-security-advisory-av26-944\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-944<br \/><strong>Date: <\/strong>September 21, 2026<\/p>\n\n<p>As of September\u00a018, 2026, Exim is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Exim\n\t<ul><li>Prior to 4.100.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/lists.exim.org\/lurker\/message\/20260918.121220.0f87338e.en.html\">Exim Security Release\u00a0- 4.100.1<\/a><\/li>\n\t<li><a href=\"https:\/\/www.exim.org\/\">Exim Internet Mailer<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/exim-security-advisory-av26-944","alert_type":396,"serial_number":"AV26-944","subject":"other","moderation_state":"published","external_url":null},{"nid":8258,"title":"MongoDB Security Advisory (AV26-945)","uuid":"0415304e-eee2-4631-9fba-b8ff6dcb6a1d","banner":null,"lang":"en","date_modified":"2026-09-21","date_modified_ts":"2026-09-21T17:21:24Z","date_created":"2026-09-21T17:16:45Z","summary":null,"body":["<article data-history-node-id=\"8258\" about=\"\/en\/alerts-advisories\/mongodb-security-advisory\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-945<br \/><strong>Date: <\/strong>September 21, 2026<\/p>\n\n<p>As of September 17, 2026, MongoDB is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Mongoid\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n\t<li>C Driver\n\t<ul><li>Multiple versions<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mongodb.com\/resources\/products\/alerts#security\">Security Related: Common Vulnerabilities and Exposures (CVEs)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mongodb-security-advisory","alert_type":396,"serial_number":"AV26-945","subject":"other","moderation_state":"published","external_url":null},{"nid":8259,"title":"MISP security advisory (AV26-946)","uuid":"86da37ee-4c8b-486f-bcff-8e1fd65f6807","banner":null,"lang":"en","date_modified":"2026-09-21","date_modified_ts":"2026-09-21T18:29:06Z","date_created":"2026-09-21T18:21:24Z","summary":null,"body":["<article data-history-node-id=\"8259\" about=\"\/en\/alerts-advisories\/misp-security-advisory-av26-946\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-946<br \/><strong>Date: <\/strong>September 21, 2026<\/p>\n\n<p>As of September 21, 2026, MISP is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>MISP\n\t<ul><li>Prior to 2.5.47<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/MISP\/MISP\/commit\/4c1a03b20\">Strip the client id from module-result event reports<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/MISP\/MISP\/commit\/fd27e592a\">Read only api keys can regain full role powers<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/MISP\/MISP\/commit\/d5f247b91\">Refuse a MISP export upload whose content is a path or URL<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/misp-security-advisory-av26-946","alert_type":396,"serial_number":"AV26-946","subject":"other","moderation_state":"published","external_url":null},{"nid":8260,"title":"Arista Networks security advisory (AV26-947) \u2013 Update 1 ","uuid":"382ef576-282a-4767-8a43-8c61a936eae9","banner":null,"lang":"en","date_modified":"2026-09-22","date_modified_ts":"2026-09-22T20:02:58Z","date_created":"2026-09-22T13:01:37Z","summary":null,"body":["<article data-history-node-id=\"8260\" about=\"\/en\/alerts-advisories\/arista-networks-security-advisory-av26-947\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-947<br \/><strong>Date: <\/strong>September 22, 2026<\/p>\n\n<p>As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>VeloCloud Orchestrator (VCO) On-Prem\n\t<ul><li>Versions 5.2.0 to 5.2.3.15<\/li>\n\t\t<li>Versions 6.1.0 to 6.1.3.7<\/li>\n\t\t<li>Versions 6.4.0 to 6.4.2.7<\/li>\n\t\t<li>Versions 7.0.0 to 7.0.0.2<\/li>\n\t<\/ul><\/li>\n<\/ul><h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-93952 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p>Open-source reporting indicates that CVE-2026-93952 is being exploited in the wild.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\/security-advisory\/24765-security-advisory-0183\">Security Advisory 0183<\/a><\/li>\n\t<li><a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\">Arista Networks Advisories &amp; Notices<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93952\">CISA KEV: CVE-2026-93952<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/arista-networks-security-advisory-av26-947","alert_type":396,"serial_number":"AV26-947","subject":"other","moderation_state":"published","external_url":null},{"nid":8262,"title":"Erlang security advisory (AV26-948)","uuid":"39a4f0bd-539d-405c-aced-28168a6b9e06","banner":null,"lang":"en","date_modified":"2026-09-22","date_modified_ts":"2026-09-22T15:30:00Z","date_created":"2026-09-22T15:20:00Z","summary":null,"body":["<article data-history-node-id=\"8262\" about=\"\/en\/alerts-advisories\/erlang-security-advisory-av26-948\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-948<br \/><strong>Date: <\/strong>September 22, 2026<\/p>\n\n<p>As of September\u00a022, 2026, Erlang is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>OTP\n\t<ul><li>17.0 Prior to 27.3.4.18<\/li>\n\t\t<li>21b8a1b Prior to afec515, 98c66c8 and fd1d9d0<\/li>\n\t\t<li>22.2 Prior to 27.3.4.18, 28.5.0.7 and 29.1.1<\/li>\n\t\t<li>4.1.1 Prior to 5.2.11.13, 5.5.2.6 and 6.0.6<\/li>\n\t\t<li>9.5 Prior to 11.2.12.13, 11.6.0.6 and 11.7.7<\/li>\n\t\t<li>Versions Prior to 84adefa<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/cna.erlef.org\/cves\/CVE-2026-65634.html\">CVE-2026-65634<\/a><\/li>\n\t<li><a href=\"https:\/\/cna.erlef.org\/cves\/CVE-2026-89422.html\">CVE-2026-89422<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/erlang\/otp\/security\/advisories\/\">Security Advisories\u00a0\u00b7 erlang\/otp\u00a0\u00b7 GitHub<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/erlang-security-advisory-av26-948","alert_type":396,"serial_number":"AV26-948","subject":"other","moderation_state":"published","external_url":null},{"nid":8261,"title":"F5 security advisory (AV26-949) - Update 1","uuid":"6219ad1b-5cfa-4689-8af2-2a09cbdceebf","banner":null,"lang":"en","date_modified":"2026-09-22","date_modified_ts":"2026-09-22T20:10:20Z","date_created":"2026-09-22T15:27:47Z","summary":null,"body":["<article data-history-node-id=\"8261\" about=\"\/en\/alerts-advisories\/f5-security-advisory-av26-949\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-949<br \/><strong>Date: <\/strong>September 22, 2026<\/p>\n\n<p>As of September 22, 2026, F5 is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>BIG-IP APM\n\t<ul><li>Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG<\/li>\n\t\t<li>Versions 17.5.0 prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG<\/li>\n\t\t<li>Versions 17.1.0 prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG<\/li>\n\t<\/ul><\/li>\n<\/ul><p>F5 has reported that CVE-2026-94127 is being exploited in the wild.<\/p>\n\n<p class=\"mrgn-bttm-md\"><strong>Update 1<\/strong><br \/>\nOn September 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000162605\">K000162605: BIG-IP APM vulnerability CVE-2026-94127<\/a><\/li>\n\t<li><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K12201527#currentyear\">2026 security notifications<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127\">CISA KEV: CVE-2026-94127<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/f5-security-advisory-av26-949","alert_type":396,"serial_number":"AV26-949","subject":"f5","moderation_state":"published","external_url":null},{"nid":8263,"title":"AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) \u2013 CVE-2026-94127","uuid":"7179f9b3-3637-4950-931e-6f214253414b","banner":null,"lang":"en","date_modified":"2026-09-22","date_modified_ts":"2026-09-22T19:10:40Z","date_created":"2026-09-22T18:32:52Z","summary":null,"body":["<article data-history-node-id=\"8263\" about=\"\/en\/alerts-advisories\/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-022<br \/><strong>Date:<\/strong> September\u00a022, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of a critical vulnerability affecting F5 BIG IP Access Policy Manager <span class=\"nowrap\">(APM)<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/span>.<\/p>\n\n<p>In response to the vendor advisory released on September 22, 2026, the Cyber Centre released AV26-949 on <span class=\"nowrap\">September\u00a022,\u00a02026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup><\/span>.<\/p>\n\n<p>Tracked as CVE-2026-94127<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is a Heap-based Buffer Overflow <span class=\"nowrap\">(CWE-122)<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup><\/span> and it affects F5 BIG-IP systems where an <abbr title=\"access policy manager\">APM<\/abbr> access policy and an OAuth profile are configured on the same virtual server. Under these conditions, specially crafted malicious traffic may allow an unauthenticated attacker to execute arbitrary code on the affected device, potentially resulting in remote code execution and full system compromise.<\/p>\n\n<p>F5 has indicated that CVE-2026-94127 is being exploited in the wild.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre strongly recommends that organizations running affected F5 BIG\u2011IP <abbr title=\"access policy manager\">APM<\/abbr> deployments upgrade to the following vendor-supported fixed hotfix releases:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th class=\"col-sm-1\" scope=\"col\">Affected product<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed Versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>BIG IP APM<\/td>\n\t\t\t<td>Versions 17.1.0 prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG<\/td>\n\t\t\t<td>Version 17.1.0 Hotfix-BIGIP-17.1.3.5.0.41.14-ENG<\/td>\n\t\t<\/tr><tr><td>BIG IP APM<\/td>\n\t\t\t<td>Versions 17.5.0 prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG<\/td>\n\t\t\t<td>Version 17.5.0 Hotfix-BIGIP-17.5.1.9.0.160.12-ENG<\/td>\n\t\t<\/tr><tr><td>BIG IP APM<\/td>\n\t\t\t<td>Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG<\/td>\n\t\t\t<td>Version 21.1.0 Hotfix-BIGIP-21.1.0.2.0.30.22-ENG<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p>The Cyber Centre also recommends organizations to:<\/p>\n\n<ul><li>Identify vulnerable BIG IP systems that have both an APM access policy and an OAuth profile configured on a virtual server.<\/li>\n\t<li>Apply the vendor-provided iRule (contact F5 Support to obtain the <span class=\"nowrap\">iRule)<sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup><\/span>.<\/li>\n\t<li>Review access logs for indicators of compromise (IoC), particularly OAuth authentication failures especially in rapid succession or large volume<sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>. Also review administrative accounts, access policies for any signs of suspicious activity.<\/li>\n\t<li>Upgrade to a vendor-supported fixed software version as soon as possible.<\/li>\n\t<li>Ensure management interfaces are restricted to trusted administrative networks.<\/li>\n\t<li>Follow F5 guidance for vulnerability remediation and validation following patch deployment.<\/li>\n<\/ul><p>Note: Organizations operating Common Criteria<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup> evaluated configurations should review F5's advisory<sup id=\"fn1c-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and apply the recommended updates in accordance with their change management and certification requirements.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup> with an emphasis on the following topics:<\/p>\n\n<ul><li>Consolidating, monitoring, and defending Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000162605?mkt_tok=NjUzLVNNQy03ODMAAAGkaH9tY0pWFGTgbkfrn8IlvT_E6baL4ymX-DK7rLfkiiYFE1IAxqFM2yZoeJsJbm6PioQMu-OSrQYlik3Fhleu0HoNYXaFidrr86aWtle4pz1bg8n4-Lc\">K000162605: BIG-IP APM vulnerability CVE-2026-94127<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"\/en\/alerts-advisories\/f5-security-advisory-av26-949\">AV26-949 \u2013 F5 security advisory<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-94127\">CVE-2026-94127 Detail<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/122.html\">CWE-122: Heap-based Buffer Overflow<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"\/en\/tools-services\/common-criteria\">Common Criteria\u00a0\u2013 Canadian Centre for Cyber Security<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127","alert_type":397,"serial_number":"AL26-022","subject":"f5","moderation_state":"published","external_url":null},{"nid":8264,"title":"SolarWinds security advisory (AV26-950)","uuid":"6ff5ce10-bf2c-45d8-9956-0b3a4f059628","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T14:45:56Z","date_created":"2026-09-23T14:20:27Z","summary":null,"body":["<article data-history-node-id=\"8264\" about=\"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-950\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-950<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, SolarWinds is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>SolarWinds Observability Self-Hosted\n\t<ul><li>Prior to 2026.2.3<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2026-28325\">SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28325)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/cve-2026-28324\">SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability (CVE-2026-28324)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\">SolarWinds Security Vulnerabilities<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/solarwinds-security-advisory-av26-950","alert_type":396,"serial_number":"AV26-950","subject":"other","moderation_state":"published","external_url":null},{"nid":8265,"title":"GitHub security advisory (AV26-956)","uuid":"62e9dd27-9144-4d80-b91b-68e6ca2969e8","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T17:49:55Z","date_created":"2026-09-23T14:25:51Z","summary":null,"body":["<article data-history-node-id=\"8265\" about=\"\/en\/alerts-advisories\/github-security-advisory-av26-956\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number: <\/strong>AV26-956<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, GitHub is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Enterprise Server\n\t<ul><li>3.17.0 Prior to 3.17.21<\/li>\n\t\t<li>3.18.0 Prior to 3.18.15<\/li>\n\t\t<li>3.19.0 Prior to 3.19.12<\/li>\n\t\t<li>3.20.0 Prior to 3.20.8<\/li>\n\t\t<li>3.21.0 Prior to 3.21.6<\/li>\n\t\t<li>3.22.0 Prior to 3.22.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.17\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.17 Docs\u00a0<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.18\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.18 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.19 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.20\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.20 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.21\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.21 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.22\/admin\/release-notes\">Release notes\u00a0- GitHub Enterprise Server 3.22 Docs<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.19\/admin\/all-releases\">GitHub Enterprise Server releases\u00a0- GitHub Enterprise Server 3.19 Docs<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/github-security-advisory-av26-956","alert_type":396,"serial_number":"AV26-956","subject":"other","moderation_state":"published","external_url":null},{"nid":8266,"title":"HPE security advisory (AV26-951)","uuid":"9e31d7d6-42b6-405d-b7fc-b52e06a9b3ec","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T15:13:27Z","date_created":"2026-09-23T14:42:18Z","summary":null,"body":["<article data-history-node-id=\"8266\" about=\"\/en\/alerts-advisories\/hpe-security-advisory-av26-951\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-951<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Analytics and Location Engine (ALE)\n\t<ul><li>Prior to or equal to 5.0.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>HPE Telco Service Orchestrator\n\t<ul><li>Prior to or equal to 5.6.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05137en_us&amp;docLocale=en_US#hpesbnw05137-rev-1-multiple-vulnerabilities-in-hpe-0\">HPESBNW05137 rev.1\u00a0- Multiple Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05151en_us&amp;docLocale=en_US#hpesbnw05151-rev-1-remote-dos-in-remote-telco-serv-0\">HPESBNW05151 rev.1\u00a0- Remote DoS in remote Telco service Orchestrator<\/a><\/li>\n\t<li><a href=\"https:\/\/support.hpe.com\/connect\/s\/securitybulletinlibrary?language=en_US\">HPE Security Bulletin Library<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hpe-security-advisory-av26-951","alert_type":396,"serial_number":"AV26-951","subject":"hpe","moderation_state":"published","external_url":null},{"nid":8267,"title":"WordPress security advisory (AV26-952) \u2013 Update 1","uuid":"58760afa-8d74-4d80-962d-c9db882be1ed","banner":null,"lang":"en","date_modified":"2026-09-25","date_modified_ts":"2026-09-25T20:33:21Z","date_created":"2026-09-23T15:19:19Z","summary":null,"body":["<article data-history-node-id=\"8267\" about=\"\/en\/alerts-advisories\/wordpress-security-advisory-av26-952\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-952<br \/><strong>Date: <\/strong>September 23, 2026<br \/><strong>Updated:<\/strong> September 25, 2026<\/p>\n\n<p>As of September 22, 2026, WordPress is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>WordPress\n\t<ul><li>Prior to 7.1.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild.<\/p>\n\n<h2 class=\"h3\">Update 1<\/h2>\n\n<p>On September 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87902 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-7hp8-65ch-5whp\">Unauthenticated path traversal in page-template resolution leading to conditional RCE\u00a0\u00b7 Advisory\u00a0\u00b7 WordPress\/wordpress-develop<\/a><\/li>\n\t<li><a href=\"https:\/\/wordpress.org\/news\/category\/releases\/\">WordPress Releases<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87902\">CISA KEV: CVE-2026-87902<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wordpress-security-advisory-av26-952","alert_type":396,"serial_number":"AV26-952","subject":"other","moderation_state":"published","external_url":null},{"nid":8268,"title":"Adobe security advisory (AV26-953)","uuid":"cc01b7ca-1cc7-4247-96ff-fb33e108e80c","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T17:37:47Z","date_created":"2026-09-23T15:41:55Z","summary":null,"body":["<article data-history-node-id=\"8268\" about=\"\/en\/alerts-advisories\/adobe-security-advisory-av26-953\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-953<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, Adobe is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>AEM 6.5 Forms JEE\n\t<ul><li>Prior to or equal to 6.5.25<\/li>\n\t<\/ul><\/li>\n\t<li>AEM 6.5 LTS Forms JEE\n\t<ul><li>Prior to or equal to 6.5 LTS SP2<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Bridge\n\t<ul><li>Prior to or equal to 15.1.7 (LTS)<\/li>\n\t\t<li>Prior to or equal to 16.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Connect\n\t<ul><li>Prior to or equal to 12.11<\/li>\n\t<\/ul><\/li>\n\t<li>Adobe Connect Android Mobile App\n\t<ul><li>Prior to or equal to 4.4<\/li>\n\t<\/ul><\/li>\n\t<li>C2PA Tool\n\t<ul><li>Prior to or equal to c2patool-v0.26.70<\/li>\n\t<\/ul><\/li>\n\t<li>Content Credentials Rust SDK\n\t<ul><li>Prior to or equal to c2pa-v0.89.2<\/li>\n\t<\/ul><\/li>\n\t<li>InDesign Desktop\n\t<ul><li>Prior to or equal to ID20.5.4<\/li>\n\t\t<li>Prior to or equal to ID21.5<\/li>\n\t<\/ul><\/li>\n\t<li>Premiere\n\t<ul><li>Prior to or equal to 25.6.5<\/li>\n\t\t<li>Prior to or equal to 26.3.2<\/li>\n\t<\/ul><\/li>\n\t<li>Substance3D\u00a0- Modeler\n\t<ul><li>Prior to or equal to 1.22.6<\/li>\n\t<\/ul><\/li>\n<\/ul><ul class=\"list-unstyled\"><li><a href=\"https:\/\/helpx.adobe.com\/security\/Home.html\">Adobe Product Security Incident Response Team<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/adobe-security-advisory-av26-953","alert_type":396,"serial_number":"AV26-953","subject":"adobe","moderation_state":"published","external_url":null},{"nid":8269,"title":"Ubiquiti security advisory (AV26-954)","uuid":"1fa9d880-17e2-4d40-926f-638ce1629889","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T17:46:25Z","date_created":"2026-09-23T17:17:05Z","summary":null,"body":["<article data-history-node-id=\"8269\" about=\"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-954\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-954<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, Ubiquiti Inc is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Cloud Gateways\n\t<ul><li>Prior to 5.1.31<\/li>\n\t<\/ul><\/li>\n\t<li>Dream Machines\n\t<ul><li>Prior to 5.1.31<\/li>\n\t<\/ul><\/li>\n\t<li>Dream Routers\n\t<ul><li>Prior to 5.1.31<\/li>\n\t<\/ul><\/li>\n\t<li>Dream Wall\n\t<ul><li>Prior to 5.1.31<\/li>\n\t<\/ul><\/li>\n\t<li>Enterprise Firewalls\n\t<ul><li>Prior to 5.1.31<\/li>\n\t<\/ul><\/li>\n\t<li>Express\n\t<ul><li>Prior to 4.0.21<\/li>\n\t<\/ul><\/li>\n\t<li>Express 7\n\t<ul><li>Prior to 5.1.31<\/li>\n\t<\/ul><\/li>\n\t<li>UniFi Gateways\n\t<ul><li>Prior to 5.1.26<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/community.ui.com\/releases\/Security-Advisory-Bulletin-069-069\/07e367a7-edec-4d85-a058-f97e5ce9ac9c\">Security Advisory Bulletin 069<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ubiquiti-security-advisory-av26-954","alert_type":396,"serial_number":"AV26-954","subject":"other","moderation_state":"published","external_url":null},{"nid":8270,"title":"Google Chrome security advisory (AV26-955)","uuid":"3403ae03-3897-491a-af96-06b7b506d3bc","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T17:47:42Z","date_created":"2026-09-23T17:29:38Z","summary":null,"body":["<article data-history-node-id=\"8270\" about=\"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-955\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-955<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, Google published a security advisory to address vulnerabilities in the following product:<\/p>\n\n<ul><li>Stable Channel Chrome for Desktop\n\t<ul><li>Versions prior to 154.0.8037.57\/.58 (Windows\/Mac), and 54.0.8037.57 (Linux)<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_0856730748.html\">Google Chrome Security Advisory<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/google-chrome-security-advisory-av26-955","alert_type":396,"serial_number":"AV26-955","subject":"chromereleases","moderation_state":"published","external_url":null},{"nid":8271,"title":"NVIDIA security advisory (AV26-957)","uuid":"2d038a7d-3986-499f-a14f-616e119f713a","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T18:07:07Z","date_created":"2026-09-23T17:52:08Z","summary":null,"body":["<article data-history-node-id=\"8271\" about=\"\/en\/alerts-advisories\/nvidia-security-advisory-av26-957\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-957<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, NVIDIA is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Infrastructure Controller\n\t<ul><li>Versions 0 to 1.9<\/li>\n\t<\/ul><\/li>\n\t<li>NeMo Speech\n\t<ul><li>Versions 0.0 to 2.9<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5879\">Security Bulletin: NVIDIA Infrastructure Controller\u00a0- September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5885\">Security Bulletin: NVIDIA NeMo Speech\u00a0- September 2026<\/a><\/li>\n\t<li><a href=\"https:\/\/www.nvidia.com\/en-us\/security\/\">NVIDIA Product Security<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/nvidia-security-advisory-av26-957","alert_type":396,"serial_number":"AV26-957","subject":"nvidia","moderation_state":"published","external_url":null},{"nid":8272,"title":"MikroTik security advisory (AV26-958)","uuid":"591f66b0-4344-4d65-b195-eff436e9f669","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T18:33:57Z","date_created":"2026-09-23T18:11:49Z","summary":null,"body":["<article data-history-node-id=\"8272\" about=\"\/en\/alerts-advisories\/mikrotik-security-advisory-av26-958\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-958<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 22, 2026, MikroTik is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>RouterOS\n\t<ul><li>Prior to 7.25beta5<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/forum.mikrotik.com\/t\/7-25beta-development-is-released\/272788\">7.25beta [development] is released!<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mikrotik-security-advisory-av26-958","alert_type":396,"serial_number":"AV26-958","subject":"other","moderation_state":"published","external_url":null},{"nid":8273,"title":"Dell security advisory (AV26-959)","uuid":"60266034-d561-4709-87a6-0745445ec315","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T19:10:58Z","date_created":"2026-09-23T18:41:39Z","summary":null,"body":["<article data-history-node-id=\"8273\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-959\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-959<br \/><strong>Date: <\/strong>September 23, 2026<\/p>\n\n<p>As of September 21, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Dell Command Powershell Provider (DCPP)\n\t<ul><li>Prior to 2.10.2<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Command Monitor (DCM)\n\t<ul><li>Prior to 10.13.2<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Inventory Collector Client\n\t<ul><li>Prior to 15.0.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000502472\/dsa-2026-379-security-update-for-dell-command-powershell-provider-dcpp-for-a-credential-theft-via-powershell-event-log-vulnerability\">DSA-2026-379: Security Update for Dell Command\u00a0| PowerShell Provider (DCPP) for a Credential Theft via PowerShell Event Log Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000502473\/dsa-2026-380-security-update-for-dell-command-monitor-dcm-for-an-incorrect-permission-assignment-for-critical-resource-vulnerability\">DSA-2026-380: Security Update for Dell Command\u00a0| Monitor (DCM) for an Incorrect Permission Assignment for Critical Resource Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000502474\/dsa-2026-381-security-update-for-dell-supportassist-for-pcs-home-and-business-dell-optimizer-dell-trusted-device-dell-command-update-for-an-unquoted-search-path-or-element-vulnerability\">DSA-2026-381: Security Update for Dell SupportAssist for PCs (Home and Business), Dell Optimizer, Dell Trusted Device, Dell Command\u00a0| Update for an Unquoted Search Path or Element Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-959","alert_type":396,"serial_number":"AV26-959","subject":"dell","moderation_state":"published","external_url":null},{"nid":8274,"title":"Forcepoint security advisory (AV26-960)","uuid":"cd928b3c-4367-4e03-8f5b-e0c6ca32a5db","banner":null,"lang":"en","date_modified":"2026-09-23","date_modified_ts":"2026-09-23T19:11:24Z","date_created":"2026-09-23T19:02:43Z","summary":null,"body":["<article data-history-node-id=\"8274\" about=\"\/en\/alerts-advisories\/forcepoint-security-advisory-av26-960\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-960<br \/><strong>Date:<\/strong> September 23, 2026<\/p>\n\n<p>As of September 23, 2026, Forcepoint is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Forcepoint Security Engine (NGFW)\n\t<ul><li>Versions 7.1.0 to 7.1.13<\/li>\n\t\t<li>Versions 7.3.0 to 7.3.1<\/li>\n\t\t<li>Version 7.33<\/li>\n\t\t<li>Version 7.4.0 to 7.4.1<\/li>\n\t\t<li>Version 7.5.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.forcepoint.com\/s\/article\/Security-Advisory-Security-Policy-Bypass-in-Forcepoint-Security-Engine-NGFW-CVE-2026-12974\">Forcepoint Hub<\/a><\/li>\n\t<li><a href=\"https:\/\/support.forcepoint.com\/s\/knowledge-base#q=security%20advisory&amp;sortCriteria=date%20descending&amp;f-sfrecordtypename=Security%20Advisory\">Forcepoint Help and Resource Center<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/forcepoint-security-advisory-av26-960","alert_type":396,"serial_number":"AV26-960","subject":"other","moderation_state":"published","external_url":null},{"nid":8275,"title":"WebPros security advisory (AV26-961)","uuid":"1abc16a1-971f-4755-b930-b4de08ef88ab","banner":null,"lang":"en","date_modified":"2026-09-24","date_modified_ts":"2026-09-24T14:43:22Z","date_created":"2026-09-24T14:10:52Z","summary":null,"body":["<article data-history-node-id=\"8275\" about=\"\/en\/alerts-advisories\/webpros-security-advisory-av26-961\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-961<br \/><strong>Date: <\/strong>September 24, 2026<\/p>\n\n<p>As of September 23, 2026, WebPros is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Plesk\n\t<ul><li>Versions 18.0.34 to 18.0.80.7<\/li>\n\t\t<li>Version 18.0.81.0<\/li>\n\t<\/ul><\/li>\n\t<li>Plesk extension \"Plesk RESTful API\"\n\t<ul><li>Versions 2.4.2 to 2.4.6<\/li>\n\t<\/ul><\/li>\n\t<li>Plesk extension \"Site Import\"\n\t<ul><li>Prior to or equal to 1.12.1<\/li>\n\t<\/ul><\/li>\n\t<li>WP Toolkit for cPanel\n\t<ul><li>Prior to or equal to 6.11.2-10794<\/li>\n\t<\/ul><\/li>\n\t<li>cPanel\/WHM\n\t<ul><li>Prior to 11.134.0.57<\/li>\n\t\t<li>Prior to 11.136.0.41<\/li>\n\t\t<li>Prior to 11.138.0.8<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/43644058632983-Vulnerability-CVE-2026-68492-Arbitrary-code-execution-as-root-in-Plesk-via-the-Plesk-RESTful-API-extension\">Vulnerability CVE-2026-68492: Arbitrary code execution as root in Plesk via the Plesk RESTful API extension<\/a><\/li>\n\t<li><a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/43641151026583-Vulnerability-CVE-2026-87898-Arbitrary-code-execution-as-root-in-Plesk-s-Site-Import-extension\">Vulnerability CVE-2026-87898: Arbitrary code execution as root in Plesk's Site Import extension<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026\">Security: CVE-2026-87899 Vulnerability in cPanel's CalDAV\/CardDAV\u00a0- September 22, 2026\u00a0\u2013 cPanel<\/a><\/li>\n\t<li><a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43597969409943-Security-CVE-2026-87900-Vulnerability-in-WP-Toolkit-Database-Creation-September-22-2026\">Security: CVE-2026-87900 Vulnerability in WP Toolkit Database Creation\u00a0- September 22, 2026\u00a0\u2013 cPanel<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/webpros-security-advisory-av26-961","alert_type":396,"serial_number":"AV26-961","subject":"other","moderation_state":"published","external_url":null},{"nid":8276,"title":"AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660","uuid":"2593a008-11b9-4032-a3c1-f0c908c2ff9f","banner":null,"lang":"en","date_modified":"2026-09-24","date_modified_ts":"2026-09-24T17:12:45Z","date_created":"2026-09-24T16:17:49Z","summary":null,"body":["<article data-history-node-id=\"8276\" about=\"\/en\/alerts-advisories\/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-023<br \/><strong>Date:<\/strong> September\u00a024, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint <span class=\"nowrap\">Server<sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup>.<\/span> In response to the Microsoft security advisory, released on <span class=\"nowrap\">August\u00a011,\u00a02026<sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup>,<\/span> the Cyber Centre issued AV26-804 <span class=\"nowrap\">Update 3<sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup><\/span> on September\u00a024,\u00a02026.<\/p>\n\n<p>Tracked as CVE-2026-<span class=\"nowrap\">65660<sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>,<\/span> this vulnerability is an Improper Control of Generation of Code ('Code Injection') <span class=\"nowrap\">(CWE-94)<sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup><\/span> vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers.<\/p>\n\n<p>Chained with other SharePoint vulnerabilities, this vulnerability can achieve pre-authentication remote code execution on SharePoint servers configured to permit anonymous access. Organizations that have not fully applied prior SharePoint security updates may therefore face an elevated risk of compromise.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version:<\/p>\n\n<div class=\"table-responsive\">\n<table class=\"table\"><thead><tr><th scope=\"col\">Affected products<\/th>\n\t\t\t<th scope=\"col\">Affected versions<\/th>\n\t\t\t<th scope=\"col\">Fixed Versions<\/th>\n\t\t<\/tr><\/thead><tbody><tr><td>Microsoft SharePoint Enterprise Server 2016<\/td>\n\t\t\t<td>All versions prior to 16.0.5565.1001<\/td>\n\t\t\t<td>Version 16.0.5565.1001<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server 2019<\/td>\n\t\t\t<td>All Versions prior to 16.0.10417.20198<\/td>\n\t\t\t<td>Version 16.0.10417.20198<\/td>\n\t\t<\/tr><tr><td>Microsoft SharePoint Server Subscription Edition<\/td>\n\t\t\t<td>All versions prior to 16.0.19725.20522<\/td>\n\t\t\t<td>Version 16.0.19725.20522<\/td>\n\t\t<\/tr><\/tbody><thead><\/thead><\/table><\/div>\n\n<p><strong>Important note:<\/strong> Microsoft SharePoint Enterprise Server <span class=\"nowrap\">2016<sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup><\/span> and Server <span class=\"nowrap\">2019<sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup><\/span> are <strong>end of life<\/strong> as of <strong>July\u00a015,\u00a02026<\/strong>. Organizations are urged to migrate to a supported version.<\/p>\n\n<p>The Cyber Centre also recommends organizations to:<\/p>\n\n<ul><li>Identify all on-premises SharePoint Server instances, particularly those exposed to the Internet, and ensure they are running supported versions of Microsoft SharePoint Server.<\/li>\n\t<li>Apply the latest Microsoft security updates to all affected SharePoint Server deployments, including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.<\/li>\n\t<li>Reduce the attack surface by restricting or eliminating direct internet exposure of SharePoint servers where possible, limiting access to SharePoint Central Administration and other management interfaces.<\/li>\n\t<li>Strengthen access controls by reviewing SharePoint environments for unnecessary or inactive accounts, removing unused accounts, and enforcing multi-factor authentication (MFA) for administrators and other privileged users.<\/li>\n\t<li>Harden SharePoint deployments by enabling Antimalware Scan Interface (AMSI) integration for SharePoint web applications and configuring <abbr title=\"Antimalware Scan Interface\">AMSI<\/abbr> Request Body Scan Mode to Full Mode where operationally feasible.<\/li>\n\t<li>Monitor for indicators of compromise and exploitation activity, including:\n\t<ul><li>unusual administrative activity or suspicious authenticated access attempts<\/li>\n\t\t<li>unexpected web part modifications or unauthorized configuration changes<\/li>\n\t\t<li>unauthorized authentication attempts and privilege escalation activity<\/li>\n\t\t<li>suspicious access to IIS machine keys<\/li>\n\t\t<li>evidence of deserialization attacks, web shell deployment, or malicious process execution<\/li>\n\t\t<li>unusual requests targeting SharePoint services<\/li>\n\t\t<li>Microsoft Defender or <abbr title=\"Antimalware Scan Interface\">AMSI<\/abbr> detections related to SharePoint exploitation activity<\/li>\n\t<\/ul><\/li>\n\t<li>Conduct ongoing log and security monitoring of SharePoint, IIS, endpoint security, and authentication logs to detect and investigate suspicious activity.<\/li>\n<\/ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions with an emphasis on the following <span class=\"nowrap\">topics<sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup>:<\/span><\/p>\n\n<ul><li>patch operating systems and applications<\/li>\n\t<li>harden operating systems and applications<\/li>\n\t<li>isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/blog.previdian.com\/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts\/\">CVE-2026-65660 - Previdian observes two stage SharePoint exploitation attempts<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-65660\">Microsoft SharePoint Server Remote Code Execution Vulnerability<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"\/en\/alerts-advisories\/microsoft-security-advisory-august-2026-monthly-rollup-av26-804\">Microsoft security advisory\u00a0\u2013 August 2026 monthly rollup (AV26-804)\u00a0\u2013 Update 3<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65660\">CVE-2026-65660<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/94.html\">CWE-94: Improper Control of Generation of Code ('Code Injection')<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2016\">SharePoint Server 2016\u00a0- Microsoft Lifecycle<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2019\">SharePoint Server 2019\u00a0- Microsoft Lifecycle<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660","alert_type":397,"serial_number":"AL26-023","subject":"microsoft","moderation_state":"published","external_url":null},{"nid":8278,"title":"GitLab security advisory (AV26-962)","uuid":"df7a453e-4542-4055-b431-2297191e16fd","banner":null,"lang":"en","date_modified":"2026-09-25","date_modified_ts":"2026-09-25T12:35:05Z","date_created":"2026-09-25T12:25:23Z","summary":null,"body":["<article data-history-node-id=\"8278\" about=\"\/en\/alerts-advisories\/gitlab-security-advisory-av26-962\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-962<br \/><strong>Date: <\/strong>September 25, 2026<\/p>\n\n<p>As of September 23, 2026, GitLab is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>GitLab\n\t<ul><li>Prior to 19.2.7<\/li>\n\t\t<li>Prior to 19.3.3<\/li>\n\t\t<li>Prior to 19.4.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-4-1-released\/\">GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7<\/a><\/li>\n\t<li><a href=\"https:\/\/docs.gitlab.com\/releases\/\">GitLab release notes | GitLab Docs <\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/gitlab-security-advisory-av26-962","alert_type":396,"serial_number":"AV26-962","subject":"gitlab","moderation_state":"published","external_url":null},{"nid":8279,"title":"ServiceNow security advisory (AV26-963)","uuid":"8911c74f-1cc2-47a9-9d37-3d9b1837cc70","banner":null,"lang":"en","date_modified":"2026-09-25","date_modified_ts":"2026-09-25T12:56:31Z","date_created":"2026-09-25T12:43:26Z","summary":null,"body":["<article data-history-node-id=\"8279\" about=\"\/en\/alerts-advisories\/servicenow-security-advisory-av26-963\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-963<br \/><strong>Date: <\/strong>September 25, 2026<\/p>\n\n<p>As of September 24, 2026, ServiceNow is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>ServiceNow AI Platform\n\t<ul><li>Versions prior to Australia Patch 2 Hot Fix 4b W32<\/li>\n\t\t<li>Versions prior to Australia Patch 4 Hot Fix 3<\/li>\n\t\t<li>Versions prior to Australia Patch 5<\/li>\n\t\t<li>Versions prior to Yokohama Patch 13 Hot Fix 5a<\/li>\n\t\t<li>Versions prior to Zurich Patch 10 Hot Fix 3b<\/li>\n\t\t<li>Versions prior to Zurich Patch 10 Hot Fix 4a W32<\/li>\n\t\t<li>Versions prior to Zurich Patch 11 Hot Fix 3<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB3159623\">September 2026 CVE Advisory Notification<\/a><\/li>\n\t<li><a href=\"https:\/\/support.servicenow.com\/now\">ServiceNow security advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/servicenow-security-advisory-av26-963","alert_type":396,"serial_number":"AV26-963","subject":"other","moderation_state":"published","external_url":null},{"nid":8286,"title":"Zimbra security advisory (AV26-964)","uuid":"df9b0040-0c65-4d8d-bac9-e3915c026ecb","banner":null,"lang":"en","date_modified":"2026-09-25","date_modified_ts":"2026-09-25T18:40:08Z","date_created":"2026-09-25T18:34:59Z","summary":null,"body":["<article data-history-node-id=\"8286\" about=\"\/en\/alerts-advisories\/zimbra-security-advisory-av26-964\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-964<br \/><strong>Date:<\/strong> September 25, 2026<\/p>\n\n<p>As of September 25, 2026, Zimbra is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Zimbra Collaboration Suite (ZCS) (Daffodil)\n\t<ul><li>Prior to 10.1.21<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/blog.zimbra.com\/2026\/09\/whats-new-in-zimbra-10-1-21-daffodil\/\">What\u2019s New in Zimbra 10.1.21 (Daffodil)<\/a><\/li>\n\t<li><a href=\"https:\/\/blog.zimbra.com\/\">Zimbra Blog\u00a0- All Things Zimbra<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/zimbra-security-advisory-av26-964","alert_type":396,"serial_number":"AV26-964","subject":"other","moderation_state":"published","external_url":null},{"nid":8288,"title":"AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway \u2013 CVE-2026-88771 and CVE-2026-88772","uuid":"2d8c65a7-bae7-4794-8def-10df609f8bdf","banner":null,"lang":"en","date_modified":"2026-09-27","date_modified_ts":"2026-09-27T18:02:05Z","date_created":"2026-09-27T18:01:18Z","summary":null,"body":["<article data-history-node-id=\"8288\" about=\"\/en\/alerts-advisories\/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Number:<\/strong> AL26-024<br \/><strong>Date:<\/strong> September\u00a027, 2026<\/p>\n\n<h2>Audience<\/h2>\n\n<p>This Alert is intended for <abbr title=\"information technology\">IT<\/abbr> professionals and managers.<\/p>\n\n<h2>Purpose<\/h2>\n\n<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (\"Cyber Centre\") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.<\/p>\n\n<h2>Details<\/h2>\n\n<p>The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. In response to the vendor security bulletin <sup id=\"fn1a-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and blog <sup id=\"fn2-rf\"><a class=\"fn-lnk\" href=\"#fn2\"><span class=\"wb-inv\">Footnote <\/span>2<\/a><\/sup> released on September 27, 2026, the Cyber Centre is issuing this alert to raise awareness of the vulnerabilities and associated reports of active exploitation.<\/p>\n\n<p>Tracked as CVE-2026-88771 <sup id=\"fn3-rf\"><a class=\"fn-lnk\" href=\"#fn3\"><span class=\"wb-inv\">Footnote <\/span>3<\/a><\/sup>, this vulnerability is an Improper Input Validation vulnerability (CWE-20) <sup id=\"fn4-rf\"><a class=\"fn-lnk\" href=\"#fn4\"><span class=\"wb-inv\">Footnote <\/span>4<\/a><\/sup>. The vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable NetScaler appliance. Successful exploitation could result in complete compromise of the appliance, unauthorized access to applications and services, credential theft, lateral movement, and further compromise of internal systems.<\/p>\n\n<p>Tracked as CVE-2026-88772 <sup id=\"fn5-rf\"><a class=\"fn-lnk\" href=\"#fn5\"><span class=\"wb-inv\">Footnote <\/span>5<\/a><\/sup>, this vulnerability is a Buffer Overflow vulnerability (CWE-119) <sup id=\"fn6-rf\"><a class=\"fn-lnk\" href=\"#fn6\"><span class=\"wb-inv\">Footnote <\/span>6<\/a><\/sup>. Successful exploitation may allow arbitrary code execution, memory corruption, denial of service conditions, or other unintended behaviour on affected appliances.<\/p>\n\n<p>Reports indicate that these vulnerabilities are being exploited and have been observed across multiple Citrix customer environments worldwide, although the full extent of this activity remains unknown at this time.<\/p>\n\n<h2>Suggested actions<\/h2>\n\n<p>Organizations should review the Citrix security bulletin <sup id=\"fn1b-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> to determine whether their deployments are affected, prioritize remediation of Internet-facing systems, and investigate for signs of compromise, particularly where evidence of suspicious activity predates the release of vendor fixes<\/p>\n\n<p>The Cyber Centre also recommends that organizations:<\/p>\n\n<ul><li>contact Citrix or their authorized support provider as soon as possible to obtain the latest security guidance and patch availability information<\/li>\n\t<li>Preserve forensic evidence before shutting down, rebooting, patching, rebuilding, or otherwise modifying affected appliances, where feasible.<\/li>\n\t<li>Preserve appliance logs, remote syslog records, and NetScaler Console logs.<\/li>\n\t<li>Collect support bundles and other diagnostic information that may assist future investigations.<\/li>\n\t<li>Review running processes and active network connections for suspicious or unexplained activity.<\/li>\n\t<li>Examine startup scripts, scheduled tasks, web application directories, and crash dump locations for unauthorized modifications or indicators of persistence.<\/li>\n\t<li>Preserve suspicious files and configurations before changing or removing them.<\/li>\n\t<li>Correlate findings with firewall, DNS, authentication, endpoint, and other supporting telemetry sources.<\/li>\n\t<li>Investigate unexpected outbound connections, unusual administrative access, and suspicious activity on connected systems.<\/li>\n\t<li>Review the attached list of indicators of compromise and investigate to find matching patterns.<\/li>\n\t<li>Follow Citrix guidance for suspected compromises, including isolation of affected appliances and assessment of credential exposure <sup id=\"fn7-rf\"><a class=\"fn-lnk\" href=\"#fn7\"><span class=\"wb-inv\">Footnote <\/span>7<\/a><\/sup>.<\/li>\n\t<li>Conduct an organization-specific risk assessment based on the criticality of affected NetScaler deployments, any suspicious findings, and the limited information currently available.<\/li>\n\t<li>Where operationally feasible and justified by the organization's risk assessment, consider temporarily disabling or shutting down Internet-facing NetScaler appliances until vendor guidance and security updates become available; organizations should carefully weigh the cybersecurity risks of continued operation against the operational and business impacts of service disruption before taking this action.<\/li>\n\t<li>Prepare to reset credentials, invalidate active sessions, and replace certificates if compromise is suspected<\/li>\n\t<li>Be prepared to rebuild or replace compromised appliances from trusted software and known-good configurations.<\/li>\n<\/ul><p>Note: Organizations operating Common Criteria <sup id=\"fn8-rf\"><a class=\"fn-lnk\" href=\"#fn8\"><span class=\"wb-inv\">Footnote <\/span>8<\/a><\/sup> evaluated configurations should review Citrix's advisory <sup id=\"fn1-rf\"><a class=\"fn-lnk\" href=\"#fn1\"><span class=\"wb-inv\">Footnote <\/span>1<\/a><\/sup> and apply the recommended updates in accordance with their change management and certification requirements.<\/p>\n\n<p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 <abbr title=\"information technology\">IT<\/abbr> Security Actions <sup id=\"fn9-rf\"><a class=\"fn-lnk\" href=\"#fn9\"><span class=\"wb-inv\">Footnote <\/span>9<\/a><\/sup>.<\/p>\n\n<ul><li>Consolidate, monitor, and defend Internet gateways<\/li>\n\t<li>Patch operating systems and applications<\/li>\n\t<li>Harden operating systems and applications<\/li>\n\t<li>Isolate web-facing applications<\/li>\n<\/ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href=\"\/en\/incident-management\">My Cyber Portal<\/a>, or email <a href=\"mailto:contact@cyber.gc.ca\">contact@cyber.gc.ca<\/a>.<\/p>\n\n<h2>References<\/h2>\n\n<aside class=\"wb-fnote\" role=\"note\"><dl><dt>Footnote 1<\/dt>\n\t<dd id=\"fn1\">\n\t<p><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX697096&amp;articleURL=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778\">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn1-rf\"><span class=\"wb-inv\">Return to footnote<\/span>1<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 2<\/dt>\n\t<dd id=\"fn2\">\n\t<p><a href=\"https:\/\/community.citrix.com\/techzone-blogs\/110_security-updates\/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778\/?utm_id=cid2026-0806&amp;utm_source=facebook&amp;utm_medium=social%20media%20organic&amp;utm_campaign=citrix%20organic&amp;utm_content=1790523126\">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn2-rf\"><span class=\"wb-inv\">Return to footnote<\/span>2<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 3<\/dt>\n\t<dd id=\"fn3\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88771\">CVE-2026-88771<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn3-rf\"><span class=\"wb-inv\">Return to footnote<\/span>3<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 4<\/dt>\n\t<dd id=\"fn4\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/20.html\">CWE-20: Improper Input Validation<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn4-rf\"><span class=\"wb-inv\">Return to footnote<\/span>4<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 5<\/dt>\n\t<dd id=\"fn5\">\n\t<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-88772\">CVE-2026-88772<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn5-rf\"><span class=\"wb-inv\">Return to footnote<\/span>5<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 6<\/dt>\n\t<dd id=\"fn6\">\n\t<p><a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/119.html\">CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn6-rf\"><span class=\"wb-inv\">Return to footnote<\/span>6<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 7<\/dt>\n\t<dd id=\"fn7\">\n\t<p><a href=\"https:\/\/support.citrix.com\/external\/article\/CTX694799\/steps-to-take-if-netscaler-adc-is-suspec.html\">Steps to Take if NetScaler ADC is Suspected to be Compromised\u00a0- Citrix<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn7-rf\"><span class=\"wb-inv\">Return to footnote<\/span>7<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 8<\/dt>\n\t<dd id=\"fn8\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/tools-services\/common-criteria\">Common Criteria\u00a0\u2013 Canadian Centre for Cyber Security<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn8-rf\"><span class=\"wb-inv\">Return to footnote<\/span>8<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n\t<dt>Footnote 9<\/dt>\n\t<dd id=\"fn9\">\n\t<p><a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089\">Top 10 <abbr title=\"information technology\">IT<\/abbr> security actions to protect Internet connected networks and information (ITSM.10.089)<\/a><\/p>\n\n\t<p class=\"fn-rtn\"><a href=\"#fn9-rf\"><span class=\"wb-inv\">Return to footnote<\/span>9<span class=\"wb-inv\"> referrer<\/span><\/a><\/p>\n\t<\/dd>\n<\/dl><\/aside><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772","alert_type":397,"serial_number":"AL26-024","subject":"citrix","moderation_state":"published","external_url":null},{"nid":8289,"title":"Citrix security advisory (AV26-965)","uuid":"beff07d2-7bc5-4473-9505-14e453193bda","banner":null,"lang":"en","date_modified":"2026-09-28","date_modified_ts":"2026-09-28T12:16:20Z","date_created":"2026-09-28T11:57:33Z","summary":null,"body":["<article data-history-node-id=\"8289\" about=\"\/en\/alerts-advisories\/citrix-security-advisory-av26-965\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-965<br \/><strong>Date: <\/strong>September 28, 2026<\/p>\n\n<p>As of September 27, 2026, Citrix is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>NetScaler ADC and NetScaler Gateway 14.1\n\t<ul><li>Prior to 14.1-73.37<\/li>\n\t<\/ul><\/li>\n\t<li>NetScaler ADC and NetScaler Gateway 13.1\n\t<ul><li>Prior to 13.1-64.23<\/li>\n\t<\/ul><\/li>\n\t<li>NetScaler ADC FIPS\n\t<ul><li>Prior to 14.1-73.37 FIPS<\/li>\n\t<\/ul><\/li>\n\t<li>NetScaler ADC FIPS and NDcPP\n\t<ul><li>Prior to 13.1-37.279<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited Vulnerabilities (KEV) Database.<br \/><br \/>\nThe Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX697096\">Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778<\/a><\/li>\n\t<li><a href=\"https:\/\/support.citrix.com\/support-home\/topic-article-list?trendingCategory=20&amp;trendingTopicName=Security%20Bulletin\">Citrix Security Advisories<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771\">CISA KEV: CVE-2026-88771<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772\">CISA KEV: CVE-2026-88772<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/citrix-security-advisory-av26-965","alert_type":396,"serial_number":"AV26-965","subject":"citrix","moderation_state":"published","external_url":null},{"nid":8290,"title":"Dell security advisory (AV26-966)","uuid":"13fa4053-3fa5-478b-a790-d64be15d28f6","banner":null,"lang":"en","date_modified":"2026-09-28","date_modified_ts":"2026-09-28T17:53:00Z","date_created":"2026-09-28T17:36:34Z","summary":null,"body":["<article data-history-node-id=\"8290\" about=\"\/en\/alerts-advisories\/dell-security-advisory-av26-966\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-966<br \/><strong>Date:<\/strong> September 28, 2026<\/p>\n\n<p>As of September 24, 2026, Dell is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Rugged Control Center (RCC)\n\t<ul><li>Prior to 5.2.206<\/li>\n\t<\/ul><\/li>\n\t<li>Secure Connect Gateway (SCG) Policy Manager\n\t<ul><li>Prior to 5.36.00.16<\/li>\n\t<\/ul><\/li>\n\t<li>ThinOS 10\n\t<ul><li>Prior to SecurityAddon_2605.10.2766_T10<\/li>\n\t<\/ul><\/li>\n\t<li>Dell Trusted Device Client\n\t<ul><li>Prior to 8.1.359.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000506924\/dsa-2026-410-security-update-for-dell-rugged-control-center-rcc-multiple-vulnerabilities\">DSA-2026-410: Security Update for Dell Rugged Control Center (RCC) Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-ca\/000503592\/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities\">DSA-2026-385: Security Update for Dell Secure Connect Gateway Policy Manager Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000506503\/dsa-2026-404-security-update-for-dell-thinos-10-for-multiple-vulnerabilities\">DSA-2026-404: Security Update for Dell ThinOS 10 for Multiple Vulnerabilities<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000506918\/dsa-2026-408-security-update-for-dell-trusted-device-client-for-an-incorrect-permission-assignment-for-critical-resource-vulnerability\">DSA-2026-408: Security Update for Dell Trusted Device Client for an Incorrect Permission Assignment for Critical Resource Vulnerability<\/a><\/li>\n\t<li><a href=\"https:\/\/www.dell.com\/support\/security\/en-ca?lwp=rt\">Security Advisories, Notices and Resources<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/dell-security-advisory-av26-966","alert_type":396,"serial_number":"AV26-966","subject":"dell","moderation_state":"published","external_url":null},{"nid":8291,"title":"IBM security advisory (AV26-967)","uuid":"942f33ba-b1f0-4157-9a24-c722d950d876","banner":null,"lang":"en","date_modified":"2026-09-28","date_modified_ts":"2026-09-28T18:16:27Z","date_created":"2026-09-28T18:06:10Z","summary":null,"body":["<article data-history-node-id=\"8291\" about=\"\/en\/alerts-advisories\/ibm-security-advisory-av26-967\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-967<br \/><strong>Date:<\/strong> September 28, 2026<\/p>\n\n<p>As of September 25, 2026, IBM is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>IBM Big Replicate LiveData Migrator\n\t<ul><li>Prior to or equal to 3.3<\/li>\n\t<\/ul><\/li>\n\t<li>IBM App Connect Enterprise\n\t<ul><li>Prior to or equal to version 13.0.1.0 to 13.0.8.2<\/li>\n\t<\/ul><\/li>\n\t<li>DataStage on Cloud Pak for Data\n\t<ul><li>Prior to or equal to 5.4.0.0<\/li>\n\t<\/ul><\/li>\n\t<li>Analyst Workflow\n\t<ul><li>Prior to or equal to version 1.0.0 - 3.1.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM QRadar Deployment Intelligence App\n\t<ul><li>Prior to or equal to version 1.0.0 - 3.0.19<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Rhapsody Systems Engineering\n\t<ul><li>Prior to or equal to version 1.6.0-1.8.0<\/li>\n\t<\/ul><\/li>\n\t<li>IBM Concert\n\t<ul><li>Prior to or equal to version 1.0.0 to 3.0.0<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.ibm.com\/support\/pages\/bulletin\/\">IBM Product Security Incident Response<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/ibm-security-advisory-av26-967","alert_type":396,"serial_number":"AV26-967","subject":"ibm","moderation_state":"published","external_url":null},{"nid":8292,"title":"SUSE Linux security advisory (AV26-968)","uuid":"2600c62a-1e04-45d6-a4fa-7ec10787896e","banner":null,"lang":"en","date_modified":"2026-09-28","date_modified_ts":"2026-09-28T18:26:48Z","date_created":"2026-09-28T18:19:45Z","summary":null,"body":["<article data-history-node-id=\"8292\" about=\"\/en\/alerts-advisories\/suse-linux-security-advisory-av26-968\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-968<br \/><strong>Date:<\/strong> September 28, 2026<\/p>\n\n<p>As of September 28, 2026, SUSE is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>NeuVector\n\t<ul><li>Prior to 5.4.11<\/li>\n\t\t<li>Prior to 5.5.4<\/li>\n\t\t<li>Prior to 5.6.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/neuvector\/neuvector\/security\/advisories\/GHSA-vr77-8vmq-qfmj\">OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes<\/a><\/li>\n\t<li><a href=\"https:\/\/www.suse.com\/support\/update\/\">SUSE Update Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/suse-linux-security-advisory-av26-968","alert_type":396,"serial_number":"AV26-968","subject":"other","moderation_state":"published","external_url":null},{"nid":8293,"title":"wolfSSL security advisory (AV26-969)","uuid":"97f959a2-768f-444d-9911-32bfeece2917","banner":null,"lang":"en","date_modified":"2026-09-28","date_modified_ts":"2026-09-28T18:35:48Z","date_created":"2026-09-28T18:30:16Z","summary":null,"body":["<article data-history-node-id=\"8293\" about=\"\/en\/alerts-advisories\/wolfssl-security-advisory-av26-969\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial Number:<\/strong> AV26-969<br \/><strong>Date:<\/strong> September 28, 2026<\/p>\n\n<p>As of September 25, 2026, wolfSSL is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>wolfSSL\n\t<ul><li>Prior to or equal to 5.9.4<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/wolfSSL\/wolfssl\/releases\">wolfSSL Release 5.9.4 (September 25, 2026)<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/wolfssl-security-advisory-av26-969","alert_type":396,"serial_number":"AV26-969","subject":"other","moderation_state":"published","external_url":null},{"nid":8294,"title":"Linux security advisory (AV26-970)","uuid":"ae759eda-241a-4eed-9032-c8873392e5dc","banner":null,"lang":"en","date_modified":"2026-09-28","date_modified_ts":"2026-09-28T19:44:37Z","date_created":"2026-09-28T19:29:41Z","summary":null,"body":["<article data-history-node-id=\"8294\" about=\"\/en\/alerts-advisories\/linux-security-advisory-av26-970\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><!-- x-tinymce\/html --><\/p>\n\n<p><strong>Serial Number:<\/strong> AV26-970<br \/><strong>Date:<\/strong> September 28, 2026<\/p>\n\n<p><strong>Linux security advisory (AV26-970)<\/strong><\/p>\n\n<p>As of September 25, 2026, Linux is affected by a vulnerability in the following product:<\/p>\n\n<ul><li>Linux Kernel\n\t<ul><li>Version prior to 4.7<\/li>\n\t\t<li>Version 5.10 prior to 5.10.270<\/li>\n\t\t<li>Version 5.15 prior to 5.15.221<\/li>\n\t\t<li>Version 6.1 prior to 6.1.188<\/li>\n\t\t<li>Version 6.12 prior to 6.12.110<\/li>\n\t\t<li>Version 6.18 prior to 6.18.52<\/li>\n\t\t<li>Version 6.6 prior to 6.6.157<\/li>\n\t\t<li>Version 7.2 prior to 7.2.6<\/li>\n\t<\/ul><\/li>\n<\/ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/git.kernel.org\/stable\/c\/717ab4d0614e9446bf8e2de6229464499e4008d6\">Kernel\/git\/stable\/linux.git _ 1<\/a><\/li>\n\t<li><a href=\"https:\/\/git.kernel.org\/stable\/c\/af00051dbc9f467d4840ec709680660a3f8990fa\">Kernel\/git\/stable\/linux.git _ 2<\/a><\/li>\n\t<li><a href=\"https:\/\/git.kernel.org\/stable\/c\/af073bd245180393bcb15d33d3990a6bdc32593a\">Kernel\/git\/stable\/linux.git _ 3<\/a><\/li>\n\t<li><a href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/stable\/linux.git\">Linux Kernel Stable Tree<\/a><\/li>\n<\/ul><!--CUT & PASTE the French version info --><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/linux-security-advisory-av26-970","alert_type":396,"serial_number":"AV26-970","subject":"other","moderation_state":"published","external_url":null},{"nid":8295,"title":"WatchGuard security advisory (AV26-972)","uuid":"03fd0e34-18cf-419e-8af2-5721432e91a1","banner":null,"lang":"en","date_modified":"2026-09-29","date_modified_ts":"2026-09-29T12:52:20Z","date_created":"2026-09-29T12:24:35Z","summary":null,"body":["<article data-history-node-id=\"8295\" about=\"\/en\/alerts-advisories\/watchguard-security-advisory-av26-972\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-972<br \/><strong>Date: <\/strong>September 29, 2026<\/p>\n\n<p>As of September 28, 2026, WatchGuard is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>WatchGuard AP\n\t<ul><li>Prior to 3.4.8<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/psirt.watchguard.com\/CVE-2026-101891\">CVE-2026-101891\u00a0\u2014 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.watchguard.com\/CVE-2026-86102\">CVE-2026-86102\u00a0\u2014 WatchGuard AP Command Injection in Internal Management API Allows Command Execution<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.watchguard.com\/CVE-2026-87969\">CVE-2026-87969\u00a0\u2014 WatchGuard AP Authenticated Command Injection in Diagnostic CLI<\/a><\/li>\n\t<li><a href=\"https:\/\/psirt.watchguard.com\/\">WatchGuard Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/watchguard-security-advisory-av26-972","alert_type":396,"serial_number":"AV26-972","subject":"other","moderation_state":"published","external_url":null},{"nid":8296,"title":"Apple security advisory (AV26-971)","uuid":"ce09c63f-ab93-4ce3-a061-d8571bb7338a","banner":null,"lang":"en","date_modified":"2026-09-29","date_modified_ts":"2026-09-29T12:30:57Z","date_created":"2026-09-29T12:57:08Z","summary":null,"body":["<article data-history-node-id=\"8296\" about=\"\/en\/alerts-advisories\/apple-security-advisory-av26-971\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-971<br \/><strong>Date: <\/strong>September 29, 2026<\/p>\n\n<p>As of September 28, 2026, Apple is affected by a vulnerability in the following products:<\/p>\n\n<ul><li>iOS and iPadOS\n\t<ul><li>Prior to 27.0.1<\/li>\n\t\t<li>Prior to 26.7.1<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Golden Gate\n\t<ul><li>Prior to 27.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Tahoe\n\t<ul><li>Prior to 26.7.1<\/li>\n\t<\/ul><\/li>\n\t<li>macOS Sequoia\n\t<ul><li>Prior to 15.8.1<\/li>\n\t<\/ul><\/li>\n\t<li>watchOS\n\t<ul><li>Prior to 27.0.1<\/li>\n\t<\/ul><\/li>\n\t<li>visionOS 27\n\t<ul><li>Prior to 27.0.1<\/li>\n\t<\/ul><\/li>\n<\/ul><p>Apple has indicated that CVE-2026-86950 may have been exploited.<\/p>\n\n<p>On September 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86950 to their Known Exploited Vulnerabilities (KEV) Database.<\/p>\n\n<p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/support.apple.com\/en-us\/100100\">Apple security releases\u00a0- Apple Support<\/a><\/li>\n\t<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950\">CISA KEV: CVE-2026-86950<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/apple-security-advisory-av26-971","alert_type":396,"serial_number":"AV26-971","subject":"apple","moderation_state":"published","external_url":null},{"nid":8297,"title":"FreePBX security advisory (AV26-973)","uuid":"35bed6d1-d5a8-467d-b164-2d0e1e0416d3","banner":null,"lang":"en","date_modified":"2026-09-29","date_modified_ts":"2026-09-29T13:35:31Z","date_created":"2026-09-29T13:28:16Z","summary":null,"body":["<article data-history-node-id=\"8297\" about=\"\/en\/alerts-advisories\/freepbx-security-advisory-av26-973\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-973<br \/><strong>Date: <\/strong>September 29, 2026<\/p>\n\n<p>As of September 28, 2026, FreePBX is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>music\n\t<ul><li>Prior to 16.0.4<\/li>\n\t\t<li>Prior to 17.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>ucp\n\t<ul><li>Prior to 16.0.39<\/li>\n\t\t<li>Prior to 17.0.6<\/li>\n\t<\/ul><\/li>\n\t<li>soundlang\n\t<ul><li>Prior to 17.0.5<\/li>\n\t\t<li>Prior to 16.0.10<\/li>\n\t<\/ul><\/li>\n\t<li>backup\n\t<ul><li>Prior to 16.0.72<\/li>\n\t\t<li>Prior to 17.0.7<\/li>\n\t<\/ul><\/li>\n\t<li>superfecta\n\t<ul><li>Prior to 16.0.40<\/li>\n\t\t<li>Prior to 17.0.7<\/li>\n\t<\/ul><\/li>\n\t<li>api\n\t<ul><li>Prior to 17.0.9<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/FreePBX\/security-reporting\/security\/advisories\/\">FreePBX Security Advisories<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/freepbx-security-advisory-av26-973","alert_type":396,"serial_number":"AV26-973","subject":"other","moderation_state":"published","external_url":null},{"nid":8298,"title":"SUSE Linux security advisory (AV26-974)","uuid":"bdc696d9-86e5-4359-905d-32d93beb47da","banner":null,"lang":"en","date_modified":"2026-09-29","date_modified_ts":"2026-09-29T14:33:43Z","date_created":"2026-09-29T14:20:38Z","summary":null,"body":["<article data-history-node-id=\"8298\" about=\"\/en\/alerts-advisories\/suse-linux-security-advisory-av26-974\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-974<br \/><strong>Date: <\/strong>September 29, 2026<\/p>\n\n<p>As of September 28, 2026, SUSE is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>Rancher\n\t<ul><li>Prior to 0.12.19<\/li>\n\t\t<li>Prior to 0.13.15<\/li>\n\t\t<li>Prior to 0.13.16<\/li>\n\t\t<li>Prior to 0.14.10<\/li>\n\t\t<li>Prior to 0.14.10<\/li>\n\t\t<li>Prior to 0.15.6<\/li>\n\t\t<li>Prior to 0.15.7<\/li>\n\t\t<li>Prior to 0.16.1<\/li>\n\t\t<li>Prior to 0.16.2<\/li>\n\t\t<li>Prior to 2.11.18<\/li>\n\t\t<li>Prior to 2.12.14<\/li>\n\t\t<li>Prior to 2.13.10<\/li>\n\t\t<li>Prior to 2.14.6<\/li>\n\t\t<li>Prior to 2.15.2<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/github.com\/rancher\/rancher\/security\/advisories\/GHSA-992f-xh8r-jg2f\">Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/rancher\/rancher\/security\/advisories\/GHSA-6vpq-mf48-9794\">Session Not Revoked Server-Side on Logout in Rancher<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/rancher\/fleet\/security\/advisories\/GHSA-q9v4-358v-r8q5\">Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters<\/a><\/li>\n\t<li><a href=\"https:\/\/github.com\/rancher\/fleet\/security\/advisories\/GHSA-h9p5-fp5h-qpqr\">Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet<\/a><\/li>\n\t<li><a href=\"https:\/\/www.suse.com\/support\/update\/\">SUSE:Update Advisories | SUSE<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/suse-linux-security-advisory-av26-974","alert_type":396,"serial_number":"AV26-974","subject":"other","moderation_state":"published","external_url":null},{"nid":8299,"title":"[Control systems] Hitachi security advisory (AV26-975)","uuid":"9e06829b-6596-4cc6-864e-29a87ad452f3","banner":null,"lang":"en","date_modified":"2026-09-29","date_modified_ts":"2026-09-29T19:50:59Z","date_created":"2026-09-29T15:40:28Z","summary":null,"body":["<article data-history-node-id=\"8299\" about=\"\/en\/alerts-advisories\/hitachi-security-advisory-av26-975\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-975<br \/><strong>Date: <\/strong>September 29, 2026<\/p>\n\n<p>As of September 29, 2026, Hitachi is affected by vulnerabilities in the following product:<\/p>\n\n<ul><li>RTU500 series CMU firmware\n\t<ul><li>Prior to 12.7.8, 13.9.1 or later<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/publisher.hitachienergy.com\/preview?DocumentID=8DBD000251&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch\">Vulnerabilities in Hitachi Energy RTU500 End-of-Life versions (PDF)<\/a><\/li>\n\t<li><a href=\"https:\/\/www.hitachi.com\/products\/it\/software\/security\/index.html \">Hitachi Vulnerability Information<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/hitachi-security-advisory-av26-975","alert_type":398,"serial_number":"AV26-975","subject":"other","moderation_state":"published","external_url":null},{"nid":8300,"title":"Mozilla security advisory (AV26-976)","uuid":"51f0ff75-c666-4626-b4e6-d8cda75af294","banner":null,"lang":"en","date_modified":"2026-09-29","date_modified_ts":"2026-09-29T19:17:55Z","date_created":"2026-09-29T18:22:19Z","summary":null,"body":["<article data-history-node-id=\"8300\" about=\"\/en\/alerts-advisories\/mozilla-security-advisory-av26-976\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-976<br \/><strong>Date: <\/strong>September 29, 2026<\/p>\n\n<p>As of September 29, 2026, Mozilla is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>Firefox ESR\n\t<ul><li>Versions prior to 153.4<\/li>\n\t\t<li>Versions prior to 140.17<\/li>\n\t\t<li>Versions prior to 115.42<\/li>\n\t<\/ul><\/li>\n\t<li>Firefox\n\t<ul><li>Versions prior to 157<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-97\/\">Security Vulnerabilities fixed in Firefox 157<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-100\/\">Security Vulnerabilities fixed in Firefox ESR 153.4<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-98\/\">Security Vulnerabilities fixed in Firefox ESR 115.42<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-99\/\">Security Vulnerabilities fixed in Firefox ESR 140.17<\/a><\/li>\n\t<li><a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/\">Mozilla Foundation Security Advisories\u00a0\u2014 Mozilla<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/mozilla-security-advisory-av26-976","alert_type":396,"serial_number":"AV26-976","subject":"mozilla","moderation_state":"published","external_url":null},{"nid":8301,"title":"TeamViewer security advisory (AV26-977)","uuid":"7f2c803c-d72f-404f-b3fd-6224be82b148","banner":null,"lang":"en","date_modified":"2026-09-29","date_modified_ts":"2026-09-29T19:34:21Z","date_created":"2026-09-29T19:22:15Z","summary":null,"body":["<article data-history-node-id=\"8301\" about=\"\/en\/alerts-advisories\/teamviewer-security-advisory-av26-977\" class=\"cccs-threats full clearfix\">\n\n  \n    \n\n  \n  <div class=\"content\">\n      <div class=\"layout layout--onecol\">\n    <div  class=\"layout__region layout__region--content\">\n      \n<div data-block-plugin-id=\"extra_field_block:node:cccs_threats:links\" class=\"block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix\">\n  \n    \n\n      \n  <\/div>\n\n<div data-block-plugin-id=\"field_block:node:cccs_threats:body\" class=\"block block-layout-builder block-field-blocknodecccs-threatsbody clearfix\">\n  \n    \n\n      \n            <div class=\"field field--name-body field--type-text-with-summary field--label-hidden field--item\"><p><strong>Serial number: <\/strong>AV26-977<br \/><strong>Date: <\/strong>September 29, 2026<\/p>\n\n<p>As of September 29, 2026, TeamViewer is affected by vulnerabilities in the following products:<\/p>\n\n<ul><li>TeamViewer Full Client (Windows\/Linux\/MacOS)\n\t<ul><li>Multiple versions and Platforms<\/li>\n\t<\/ul><\/li>\n\t<li>TeamViewer Host (Windows\/Linux\/MacOS)\n\t<ul><li>Multiple versions and Platforms<\/li>\n\t<\/ul><\/li>\n<\/ul><p class=\"mrgn-bttm-md\">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.<\/p>\n\n<ul class=\"list-unstyled\"><li><a href=\"https:\/\/www.teamviewer.com\/en\/resources\/trust-center\/security-bulletins\/tv-2026-1010\/\">Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services<\/a><\/li>\n\t<li><a href=\"https:\/\/www.teamviewer.com\/en-ca\/resources\/trust-center\/security-bulletins\/\">Security bulletins\u00a0| TeamViewer<\/a><\/li>\n<\/ul><\/div>\n      \n  <\/div>\n\n    <\/div>\n  <\/div>\n\n  <\/div>\n\n<\/article>\n"],"url":"\/en\/alerts-advisories\/teamviewer-security-advisory-av26-977","alert_type":396,"serial_number":"AV26-977","subject":"other","moderation_state":"published","external_url":null}]}